API 1164
API 1164: Supply Chain & Configuration

API 1164 API1164-24: Vulnerability assessment for critical systems

Vulnerability assessment for critical systems. Control from API 1164 framework, domain: API 1164: Supply Chain & Configuration.

What else in your programme already covers this

This control maps to 254 controls across 156 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

BSI IT-Grundschutz · 3 controls

  • BSI-13 Risk assessment procedures
  • BSI-15 Security categorization
  • BSI-17 Continuous monitoring strategy

FISMA · 3 controls

ISO 27005 · 3 controls

ISO 31000 · 3 controls

ISO/IEC 23894:2023 · 3 controls

ISO/IEC 29134:2023 · 3 controls

NIST SP 800-30 · 3 controls

  • NISTSP30-3 Threat Source and Threat Event Identification
  • NISTSP30-4 Vulnerability and Predisposing Condition Identification
  • NISTSP30-6 Risk Determination, Uncertainty, and Sensitivity Analysis

NIST SP 800-53 Rev 5 · 3 controls

  • NGCB-1 Regulation 5.260 Scope, Applicability, and Licensee Categories
  • NGCB-5 Technical Security Controls - Access + Network + Encryption + Vulnerability + Logging
  • NGCB-8 Annual Independent Cybersecurity Assessment + Reporting + Board Oversight

FedRAMP High · 2 controls

  • IR-2 Incident Response Training
  • RA-1 Policy and Procedures

FedRAMP Moderate · 2 controls

  • IR-2 Incident Response Training
  • RA-1 Policy and Procedures

IEC 62443 · 2 controls

IEEE 1686 · 2 controls

ISO 27019 · 2 controls

ISO/IEC 27003:2017 · 2 controls

ISO/IEC 27014:2020 · 2 controls

  • NAIC-1 NAIC Model Law Adoption, Scope, and Licensee Definitions
  • NAIC-2 Information Security Program (ISP) - Section 4
  • NIST-CSF-GV.RM-07 Strategic opportunities (i.e., positive risks) are characterized and are included in organizational cybersecurity risk discussions
  • NIST-CSF-ID.RA-09 The authenticity and integrity of hardware and software are assessed prior to acquisition and use
  • NISTPF-1 Identify-P - Business Environment, Data Processing Inventory, Ecosystem, and Risk Assessment
  • NISTPF-8 Protect-P Information Protection Processes (PR.PO-P)

NIST SP 1800-32 · 2 controls

NIST SP 800-37 · 2 controls

  • NISTSP37-2 RMF Categorize Step: Information and System Categorisation
  • NISTSP37-3 RMF Select Step: Security and Privacy Control Selection
  • IR-2 Incident Response Training
  • RA-1 Policy and Procedures
  • IR-2 Incident Response Training
  • RA-1 Policy and Procedures
  • IR-2 Incident Response Training
  • RA-1 Policy and Procedures
  • NISTSP82-2 OT Risk Assessment and Threat/Vulnerability Identification
  • NISTSP82-5 OT Configuration Management, Patching, Vulnerability Management, and Malware Protection
  • NDPA-1 Applicability, Scope, and Carve-Outs
  • NDPA-7 Data Protection Assessments and Processor Contracts
  • NZISM-1 NZISM Governance, Documentation, and Classification System
  • NZISM-3 Personnel Security, Physical Security, and Cryptography
  • NG-NDPA-1 Scope, Applicability, and Establishment of Nigeria Data Protection Commission
  • NG-NDPA-7 Cross-Border Data Transfers and International Cooperation
  • ORSA-S1 ORSA Manual Section 1: Description of Insurer's Risk Management Framework
  • ORSA-S2 ORSA Manual Section 2: Insurer's Assessment of Risk Exposure
  • ASTWO-1 Audit Planning, Scaling, Risk Assessment, and Integration
  • ASTWO-3 Entity-Level Controls and Period-End Financial Reporting Process
  • 2.4.4 Hazard Analysis and Risk Assessment
  • 2.7.2 Food Fraud Plan

South Korea ISMS-P · 2 controls

  • CH-FADP-21 Data protection impact assessments
  • FADP-7 Data Protection Impact Assessment (Articles 9-10)
  • CRM-1 AML/CFT Compliance
  • CRM-4 Business Risk Assessment
  • CPS230-11 Identification, Assessment and Management of Operational Risk
  • SPS220-22 Framework Enabling Strategies, Policies, Procedures and Controls
  • 4.3.1 Risk Assessment and Impact Analysis

Bahrain PDPL · 1 control

  • BB-DPA-20 Sections 50-60 - Registration and Responsibilities
  • R.16-VATR.Unhosted Unhosted (self-hosted / non-custodial) wallet transfers - 2024 Targeted Update

FDA 21 CFR Part 11 · 1 control

  • Part11.CSV Computer system validation + risk-based approach (21 CFR §11.10(a) + 2003 FDA Scope and Application Guidance + 2023 CSA draft)
  • FERPA-Safeguards-PTAC Data Security Safeguards for PII in Education Records (PTAC Best Practices, SPPO Guidance)

FedRAMP Rev 5 · 1 control

GDPR · 1 control

IEEE 7000 · 1 control

ISMAP (Japan) · 1 control

ISO 13485 · 1 control

  • ISO13485-06 Security management process and risk analysis

ISO 22000 · 1 control

ISO 27017 · 1 control

ISO 27018 · 1 control

ISO 27799 · 1 control

  • ISO27799-06 Security management process and risk analysis

ISO 45001 · 1 control

ISO/IEC 27031:2011 · 1 control

ISO/IEC 29147:2018 · 1 control

  • 29147-5.11 Researcher Safe Harbour and Legal Posture

India DPDP Act · 1 control

Indonesia PDP Law · 1 control

Japan AI Guidelines · 1 control

LGPD · 1 control

Liechtenstein DPA · 1 control

MARS-E · 1 control

MTCS (Singapore) · 1 control

Malaysia PDPA 2010 · 1 control

Mauritius DPA · 1 control

Mexico LFPDPPP · 1 control

NERC CIP · 1 control

  • NERCCIP-5 System Security Management + Configuration Change Management and Vulnerability Assessments (CIP-007 + CIP-010)

NIST SP 800-122 · 1 control

  • NISTSP122-8 Continuous Monitoring, Training, and Privacy Programme Governance

NIST SP 800-144 · 1 control

  • NISTSP144-1 Cloud Governance, Risk Assessment, and Provider Trust Evaluation

NIST SP 800-145 · 1 control

  • NISTSP145-7 Cloud Procurement Standards Aligned to NIST SP 800-145 Definition

NIST SP 800-146 · 1 control

  • NISTSP146-1 Cloud Adoption Strategy, Workload Suitability, and Decision Framework
  • 3.11 Encrypt Sensitive Data at Rest

NIST SP 800-190 · 1 control

NIST SP 800-39 · 1 control

  • NISTSP39-3 Risk Assessing: Organisation, Mission, and System Level Assessments

NIST SP 800-66 · 1 control

  • NISTSP66-1 Security Management Process: Risk Analysis and Risk Management for ePHI
  • NRFCS-2 Risk Assessment, Customer Data Inventory, Classification, and Retail Threat Model
  • NHPA-7 Data Protection Assessments and Processor Contracts
  • NJDPA-7 Data Protection Assessments and Processor Contracts
  • NGNDPR-5 Security of Personal Data, Breach Notification, and DPIA under NDPR Section 2.6-Security
  • NGOB-1 Open Banking Registry Participation, Tiered Categorisation, and KYP

OECD AI Principles · 1 control

  • OECDAI-3 Robustness, Security, Safety, and Adversarial Attack Protection
  • OREGONCPA-5 Data Protection Assessments, Privacy by Design, Security Practices

PDPA Singapore · 1 control

  • PDPASG-4 Children's Data, DPIA, and Privacy by Design

PDPA Thailand · 1 control

  • PDPATH-4 DPIA, Privacy by Design, Children's Data

POPIA · 1 control

  • POPIASA-4 Special Personal Information, Children, Information Quality, Documentation
  • NORWAY-4 DPIA, Privacy by Design, Records of Processing

Privacy Act 2020 · 1 control

  • NZPRV-6 IPP 13 Unique Identifiers, Privacy Impact Assessment, Privacy by Design

Qatar DPL · 1 control

  • QATAR-7 DPO, Records, Retention, Marketing, Training
  • SECCLIM-2 Risk Management: Identification, Assessment, Integration

Saudi Arabia PDPL · 1 control

South Korea PIPA · 1 control

  • TSAPIPE-1 Cybersecurity Implementation Plan and Coordinator

Taiwan PDPA · 1 control

Turkey KVKK · 1 control

  • UKAI-1 Risk-Based Approach and Pro-Innovation Principles
  • UKOPRES-3 Self-Assessment and Board Engagement
  • s.54(5) Statement Content Requirements
  • UNICEFAI-4 Transparency, Explanation, Adult Capacity

Uruguay DPL · 1 control

  • URUGUAY-5 Database Registration with AGESIC URCDP

Vietnam PDPD · 1 control

Virginia CDPA · 1 control

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in API 1164: Supply Chain & Configuration

Query this from an agent

The graph holds this control, the 254 it maps to, and the evidence behind each claim, over MCP and REST.