Frameworks / Armenia Law on Protection of Personal Data (2015) / AM-DPA-10 What else in your programme already covers this This control maps to 139 controls across 90 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
ASD37-20 Multi-factor authentication (Essential) ASD37-23 Protect authentication credentials (Excellent) 6.4 Logging and Monitoring ISO13485-12 Unique user identification and authentication 6.4 Logging and Monitoring 6.5 Preparing and Distributing Audit Report 6.4 Logging and Monitoring 6.5 Preparing and Distributing Audit Report NIST-CSF-PR.AA-01 Identities and credentials for authorized users, services, and hardware are managed by the organization NIST-CSF-PR.AA-02 Identities are proofed and bound to credentials based on the context of interactions 3.7 Establish and Maintain a Data Classification Scheme 3.7.1 Key-management policies and procedures are implemented to include generation of strong cryptographic keys used to protect stored account data NISTSP82-2 OT Risk Assessment and Threat/Vulnerability Identification NISTSP82-4 OT Access Control, Identity, Authentication, and Remote Access OWASPLLM-1 Prompt Injection and System Prompt Leakage (LLM01 + LLM07) OWASPLLM-3 Sensitive Information Disclosure and Privacy (LLM02) VP-2 Holder Binding W3CVCDM-4 Accessibility, Internationalization, Security BSI-03 Multi-factor authentication requirements BE-CF-03 Multi-factor authentication requirements DSO-3 Data Access Management Part11.300 Controls for identification codes and passwords (21 CFR §11.300) FTC-Safeguards-9-Elements 9 Safeguard Elements - Access, Inventory, Encryption, Secure-Dev, MFA, Disposal, Change-Mgmt, Monitoring, Pen-Test (16 CFR 314.4(c)) GDPR-Art.5 Principles relating to processing of personal data ISO27799-12 Unique user identification and authentication 23837-1.7.3 Authentication and classical post-processing NAIC-1 NAIC Model Law Adoption, Scope, and Licensee Definitions NIS2I-6 Access Control, Asset Management, and Physical Security NISTPF-5 Protect-P Access Control (PR.AC-P) NISTSP115-8 Operational Considerations - Tools, Reporting Templates, ISMS Integration, Annex Material NISTSP123-3 Authentication, Access Control, and Account Management NISTSP137-6 Malware, Identity Access, and Network Boundary Monitoring NISTSP144-1 Cloud Governance, Risk Assessment, and Provider Trust Evaluation NISTSP145-8 Governance, Reporting, and Stakeholder Education on Cloud Definition NISTSP63R4-3 Authentication: Authenticator Types, MFA, Phishing-Resistance, and Syncable Authenticators NISTSP66-6 Technical Safeguards: Access Control, Audit Controls, Integrity, Person Authentication NISTSP88-1 Media Sanitization Policy, Roles, and Decision Framework NISTSP92-4 Log Management: Time Synchronisation, Parsing, Storage, Integrity, Access Control ORANWG11-2 O-RAN Interface Security: E2, A1, O1, O2, Open Fronthaul OWASPAPI-2 Broken Authentication and Token Management OWASPASVS-2 Authentication and Credential Storage (V2 + V2.4) DSOMM-4 Test and Verification - SAST, DAST, IAST, SCA, Penetration Testing OWASPSAMM-2 Design: Threat Assessment, Security Requirements, Security Architecture OMANCS-3 Identity and Access Management, Authentication, Privileged Access OSSFSC-3 Build, CI/CD Security, Workflow Permissions, Dangerous Patterns PASONE-4 Technical Security: CDE Configuration, BIM Tools, Encryption, Aggregation, Mobile Working RCEPEC-1 Online Personal Information Protection (12.13) SUPCHAIN-1 Build Integrity - Source, Build, Provenance SSAE18-CC6.2 CC6.2 - New User Registration and Authorization CISABD-1 Take Ownership of Customer Security Outcomes SIGSTORE-2 Transparency Log (Rekor) and Verification TEFCAREC-1 Common Agreement Conformance and Onboarding TSAPIPE-2 OT/IT Network Segmentation and Access Control USSDWA-2 Cybersecurity Practices (Assessment, Access, Network, IR) CYB-2 Account Security Measures USMCADIGITAL-2 Personal Information Protection and Consumer Protection Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Query this from an agent The graph holds this control, the 139 it maps to, and the evidence behind each claim, over MCP and REST.