Azure Security Benchmark
DevOps Security

Azure Security Benchmark DS-2: Ensure software supply chain security

Maintain inventory of open source and third party components in code using Software Composition Analysis tools.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 381 controls across 126 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

CIS Controls v8 · 6 controls

  • CIS-16.11 Leverage Vetted Modules or Services for Application Security Components
  • CIS-16.4 Establish and Manage an Inventory of Third-Party Software Components
  • CIS-16.5 Use Up-to-Date and Trusted Third-Party Software Components
  • CIS-2.1 Establish and Maintain a Software Inventory
  • CIS-2.4 Utilize Automated Software Inventory Tools
  • CIS-2.6 Allowlist Authorized Libraries

GDPR · 6 controls

  • GDPR-Art.10 Processing of personal data relating to criminal convictions
  • GDPR-Art.11 Processing which does not require identification
  • GDPR-Art.15 Right of access by the data subject
  • GDPR-Art.19 Notification obligation regarding rectification, erasure or restriction
  • GDPR-Art.20 Right to data portability
  • GDPR-Art.9 Processing of special categories of personal data

NIST SP 800-161 Rev 1 · 6 controls

  • NISTPF-1 Identify-P - Business Environment, Data Processing Inventory, Ecosystem, and Risk Assessment
  • NISTPF-3 Control-P - Privacy Controls, Data Management, and Disassociated Processing
  • NISTPF-4 Communicate-P - Privacy Notice, Transparency, and Individual Awareness
  • NISTPF-7 Protect-P Maintenance and Protective Technology (PR.MA-P, PR.PT-P)
  • NISTPF-8 Protect-P Information Protection Processes (PR.PO-P)
  • NDPA-1 Applicability, Scope, and Carve-Outs
  • NDPA-2 Consumer Rights - Access, Correct, Delete, Portability, Appeal
  • NDPA-4 Sensitive Data Processing Consent and Childrens Protections
  • NDPA-5 Privacy Notice, Data Minimisation, and Purpose Limitation
  • NDPA-7 Data Protection Assessments and Processor Contracts
  • NG-NDPA-1 Scope, Applicability, and Establishment of Nigeria Data Protection Commission
  • NG-NDPA-2 Lawful Basis, Consent, and Data Protection Principles
  • NG-NDPA-4 Data Subject Rights and Automated Decision-Making
  • NG-NDPA-5 Security of Processing, Breach Notification, and DPIA
  • NG-NDPA-7 Cross-Border Data Transfers and International Cooperation
  • Standard 13 Nudge Techniques
  • Standard 14 Connected Toys and Devices
  • Standard 5 Detrimental Use of Data
  • Standard 8 Data Minimisation
  • Standard 9 Data Sharing

APPI · 4 controls

  • APPI-A23 Security Control Measures
  • APPI-A24 Supervision of Employees
  • APPI-A27 Restriction on Provision to Third Parties
  • APPI-A33 Request for Disclosure of Retained Personal Data

Bahrain PDPL · 4 controls

C5 (Germany) · 4 controls

  • C5-DEV-02 Outsourcing of the development
  • C5-PSS-02 Identification of Vulnerabilities of the Cloud Service
  • C5-SSO-02 Risk assessment of service providers and suppliers
  • C5-SSO-03 Directory of service providers and suppliers
  • UAE-PDPL-Art.10 Data Protection Officer (DPO) (UAE PDPL Article 10)
  • UAE-PDPL-Art.18_19_20_21 Security measures, controller/processor relationship, DPIA (UAE PDPL Articles 18-21)
  • UAE-PDPL-Art.4_5 Lawful basis and principles for processing personal data (UAE PDPL Articles 4-5)
  • UAE-PDPL-Art.8 Records of processing activities (UAE PDPL Article 8)

Malaysia PDPA 2010 · 4 controls

  • MY-PDPA-Cross-Border-Transfer-Section-129-Whitelist-Abolition-2024-Adequacy-SCC-BCR-Processor-Direct-Marketing Malaysia PDPA Cross-Border + Section 129 + Whitelist Abolition 2024 + Adequacy + SCC + BCR + Processor + Marketing
  • MY-PDPA-Data-Subject-Rights-Access-Correction-Portability-Withdraw-Consent-Prevent-Marketing-Sections-30-43 Malaysia PDPA Subject Rights + Access + Correction + Portability + Withdraw Consent + Prevent Marketing + Sections 30 to 43
  • MY-PDPA-Security-Principle-Retention-Data-Integrity-Breach-Notification-72-Hour-Section-12B-2024-Amendment Malaysia PDPA Security + Retention + Data Integrity + Breach Notification 72 Hour + Section 12B + 2024 Amendment
  • MY-PDPA-Seven-Personal-Data-Protection-Principles-General-Notice-Choice-Disclosure-Security-Retention-Data-Integrity-Access Malaysia PDPA Seven Principles + General + Notice and Choice + Disclosure + Security + Retention + Data Integrity + Access

NIST SP 800-122 · 4 controls

  • NISTSP122-3 PII Data Subject Rights and Automated Decision-Making
  • NISTSP122-4 PII Minimisation, Purpose Limitation, and Pseudonymisation
  • NISTSP122-5 PII Security Controls - Encryption, Access Control, Storage, Audit
  • NISTSP122-6 PII Breach Response and Incident Handling

NIST SP 800-218 · 4 controls

NIST SP 800-53 Rev 5 · 4 controls

  • NHPA-4 Sensitive Data, Children, and Minors 13-16 Opt-In Consent
  • NHPA-5 Privacy Notice, Data Minimisation, and Purpose Limitation
  • NHPA-6 Reasonable Data Security and Breach Response
  • NHPA-7 Data Protection Assessments and Processor Contracts
  • OREGONCPA-2 Consumer Rights: Access, Correction, Deletion, Portability, Opt-Out
  • OREGONCPA-3 Consent, Sensitive Data, Children and Teen Protections
  • OREGONCPA-5 Data Protection Assessments, Privacy by Design, Security Practices
  • OREGONCPA-7 Processor Contracts, Cross-Border Transfers, DPAs

SOC 2 · 4 controls

  • SOC2-CC9.2 CC9.2 Assessing and managing vendor and business partner risk
  • SOC2-P3.1 P3.1 Collecting personal information consistent with objectives
  • SOC2-P4.3 P4.3 Securely disposing of personal information
  • SOC2-P6.1 P6.1 Disclosure to third parties with consent

Saudi Arabia PDPL · 4 controls

  • SA-PDPL-09 Right to data portability
  • SA-PDPL-13 Encryption of personal data
  • SA-PDPL-15 Access control for personal data
  • SA-PDPL-22 Privacy by design and default
  • TANZANIA-1 Scope, Registration, Lawful Basis
  • TANZANIA-3 Data Subject Rights
  • TANZANIA-4 Security and Cross-Border
  • TANZANIA-5 DPO, Governance, Breach
  • TRINIDAD-1 Scope, Definitions, Commission
  • TRINIDAD-3 Data Subject Rights
  • TRINIDAD-4 Security, Accuracy
  • TRINIDAD-5 Enforcement and Sanctions
  • SEC06-BP04 Validate software integrity
  • SEC11-BP02 Automate testing throughout the development and release lifecycle
  • SEC11-BP05 Centralize services for packages and dependencies
  • APP-1 APP 1 - Open and transparent management of personal information
  • APP-3 APP 3 - Collection of solicited personal information
  • APP-5 APP 5 - Notification of the collection of personal information
  • AT-DSG-11 Sections 42-45 - Data subject rights (law enforcement)
  • AT-DSG-13 Section 36 - Scope of law enforcement processing
  • AT-DSG-14 Section 38 - Lawfulness of law enforcement processing
  • AZ-DPA-12 Article 13 - Cross-border transfer
  • AZ-DPA-14 Article 16 - Liability for violations
  • AZ-DPA-15 Article 17 - Dispute resolution
  • BB-DPA-14 Section 15 - Right to Data Portability
  • BB-DPA-16 Section 22 - General Principle for Transfers
  • BB-DPA-21 Sections 61-69 - Data Privacy Officer
  • CA-10 Selects and Develops Control Activities
  • P1 Demonstrates Commitment to Integrity and Ethical Values
  • P7 Identifies and Analyzes Risk

FedRAMP High · 3 controls

  • RA-3(1) Risk Assessment | Supply Chain Risk Assessment (RA-3(1))
  • RA-5 Vulnerability Monitoring and Scanning
  • SR-3 Supply Chain Controls and Processes (SR-3)

FedRAMP Moderate · 3 controls

  • RA-3(1) Risk Assessment | Supply Chain Risk Assessment (RA-3(1))
  • RA-5 Vulnerability Monitoring and Scanning
  • SR-3 Supply Chain Controls and Processes (SR-3)
  • FDBR-ControllerObligations-DPA-Notice Controller + Processor Obligations + Data Protection Assessments (Fla. Stat. 501.707, 501.708, 501.71, 501.711)
  • FDBR-Scope-Defs Scope, Applicability Thresholds and Definitions (Fla. Stat. 501.701, 501.702, 501.703, 501.704)
  • FDBR-SensitiveData-Children-VoiceFacial Sensitive Data, Children's Privacy and Voice/Facial Recognition (Fla. Stat. 501.711, 501.1735)

ISO/IEC 29100:2024 · 3 controls

  • 29100-6.10 Information security
  • 29100-6.5 Use, retention and disclosure limitation
  • 29100-6.9 Accountability

ISO/IEC 29134:2023 · 3 controls

  • 29134-1 Scope
  • 29134-3 Terms and definitions
  • 29134-9.1 PIA report structure
  • IsraelPPL-CrossBorder-Transfer-Sec36-EU-Adequacy-Israel-Adequacy-SCCs-Reciprocity-Foreign-Recipient Israel POPL Cross-Border Transfer + Section 36 + Privacy Protection (Transfer of Data to Databases Abroad) Regulations 5761-2001 + EU Adequacy Decision (2011) + SCCs + Foreign Recipient Obligations + Reciprocity
  • IsraelPPL-DataSubjectRights-Access-Correction-Information-Delivery-Sec13-14-23A-23C-Subject-Notification Israel POPL Data Subject Rights - Section 13 Right of Access + Section 14 Right of Correction + Section 23A-C Prohibition on Information Delivery + Notice Obligation + Right to Object + Amendment 13 Enhancements
  • IsraelPPL-Database-Registration-Definition-Document-Security-Level-Classification-Sec7-8-PPA-Registry Israel POPL Database Registration + Section 7 Database Definitions + Section 8 Registration Requirement + Database Definition Document + Security Level Classification + PPA Public Registry + Amendment 13 Threshold Changes

Liechtenstein DPA · 3 controls

Mexico LFPDPPP · 3 controls

  • MX-LFPDPPP-ARCO-Rights-Articles-22-25-Acceso-Rectificacion-Cancelacion-Oposicion-Reglamento-89-103 Mexico LFPDPPP ARCO Rights + Articles 22-25 + Acceso + Rectificacion + Cancelacion + Oposicion + Reglamento 89-103
  • MX-LFPDPPP-Governance-Officer-Reglamento-47-50-Security-Manual-57-Risk-Assessment-61-Self-Regulation-Parameters-2014 Mexico LFPDPPP Governance + Officer + Reglamento 47 + Security Manual 50 + Risk Assessment 57 + Self-Regulation Parameters 2014
  • MX-LFPDPPP-Sensitive-Article-3-VI-Genetic-Health-Sexual-Religious-Article-9-Minors-18-Parental-Consent Mexico LFPDPPP Sensitive Data + Article 3 Section VI + Genetic + Health + Sexual + Religious + Article 9 Minors + Parental Consent
  • MN-CDPA-Consumer-Rights-Section-325O-04-Access-Correct-Delete-Portability-List-Third-Parties-Opt-Out-Appeal-AIQUEST-Profile Minnesota CDPA Consumer Rights + Section 325O.04 + Access + Correct + Delete + Portability + List of Third Parties + Opt-Out + Appeal + AI Question Profile
  • MN-CDPA-Enforcement-AG-Ellison-Section-325O-10-USD-7500-Per-Violation-Data-Broker-Registration-325O-13-Sunset-25-Jan-2026 Minnesota CDPA Enforcement + AG Ellison + Section 325O.10 + USD 7,500 Per Violation + Data Broker Registration + Sunset 25 January 2026
  • MN-CDPA-Processor-Contract-Security-Section-325O-08-Pseudonymisation-Section-325O-09-De-Identification Minnesota CDPA Processor + Section 325O.08 + Security + Pseudonymisation + Section 325O.09 + De-Identification
  • MT-CDPA-Consumer-Rights-MCA-30-14-2807-Access-Correct-Delete-Portability-Opt-Out-Appeal-AG-Referral Montana CDPA Consumer Rights + MCA 30-14-2807 + Access + Correct + Delete + Portability + Opt-Out + Appeal + AG Referral
  • MT-CDPA-Privacy-Notice-MCA-30-14-2806-Categories-Purposes-Rights-Email-Online-Mechanism-Appeal Montana CDPA Privacy Notice + MCA 30-14-2806 + Categories + Purposes + Rights + Online Mechanism + Appeal
  • MT-CDPA-Scope-SB-384-Gianforte-19-May-2023-Effective-1-October-2024-MCA-30-14-2801-AG-Knudsen-50K-Threshold Montana CDPA Scope + SB 384 + Gianforte 19 May 2023 + Effective 1 October 2024 + MCA 30-14-2801 + AG Knudsen + 50K Threshold
  • NIST-CSF-GV.SC-04 Suppliers are known and prioritized by criticality
  • NIST-CSF-ID.AM-02 Inventories of software, services, and systems managed by the organization are maintained
  • NIST-CSF-ID.RA-01 Vulnerabilities in assets are identified, validated, and recorded
  • NJDPA-2 Consumer Rights - Access, Correct, Delete, Portability, Appeal
  • NJDPA-4 Sensitive Data, Children, and Adolescents 13-17 Opt-In
  • NJDPA-8 AG Platkin Enforcement, 18-Month Cure Sunset, and Division of Consumer Affairs
  • NGOB-1 Open Banking Registry Participation, Tiered Categorisation, and KYP
  • NGOB-2 Customer Consent Management and Lifecycle
  • NGOB-5 Fraud Monitoring, Incident Notification, and Reporting to CBN

PDPA Singapore · 3 controls

  • PDPASG-2 Notification, Consent, Purpose Limitation, and Lawful Basis
  • PDPASG-3 Access, Correction, Data Portability, and Individual Rights
  • PDPASG-5 Protection, Accuracy, and Security of Personal Data

PDPA Thailand · 3 controls

  • PDPATH-3 Data Subject Rights, Automated Decisions, Accuracy
  • PDPATH-5 Security Measures and Data Protection
  • PDPATH-8 Data Breach Notification, Complaints, Compliance, Enforcement
  • NORWAY-2 Data Subject Rights and Automated Decision-Making
  • NORWAY-5 Security of Processing, Encryption, Pseudonymization, Access Control
  • NORWAY-8 Breach Notification, Complaints, Compliance, Enforcement

Privacy Act 2020 · 3 controls

  • NZPRV-2 IPP 5 Storage and Security of Personal Information
  • NZPRV-3 IPP 6-8 Access, Correction, Accuracy
  • NZPRV-6 IPP 13 Unique Identifiers, Privacy Impact Assessment, Privacy by Design

SASB Standards · 3 controls

  • SASB-4 Social Capital (SC)
  • SASB-SC-1 Customer Privacy and Data Security
  • SASB-SOC-2 Customer Privacy

South Korea ISMS-P · 3 controls

  • ISMSP-PI-01 Personal Information Collection
  • ISMSP-PI-04 Cross-Border Transfer
  • ISMSP-SYS-02 Encryption Implementation
  • SWE-1 Scope and Purpose
  • SWE-11 Integritetsskyddsmyndigheten (IMY)
  • SWE-2 Relationship to GDPR
  • UK-DPA18-GEN-04 UK-Specific Exemptions
  • UK-DPA18-LE-02 Data Subject Rights (Law Enforcement)
  • UK-DPA18-LE-03 International Transfers (Law Enforcement)

Uruguay DPL · 3 controls

  • URUGUAY-1 Scope, Lawful Basis, Consent
  • URUGUAY-2 Data Subject Rights (ARCO + Habeas Data)
  • URUGUAY-5 Database Registration with AGESIC URCDP
  • SO2.3 Open-source health data standards
  • SO3.2 Regulatory frameworks for digital health
  • SO3.4 Standards and interoperability governance
  • AEO-7 Trading Partner Security
  • P3-S3 Cooperative Arrangements/Procedures
  • LOPDP-EC-Data-Subject-Rights-Access-Rectification-Erasure-Object-Portability-Automated-Decisions-Articles-16-27 Ecuador LOPDP Data Subject Rights + Access + Rectification + Erasure + Articles 16-27
  • LOPDP-EC-Security-Processor-Breach-Notification-Articles-37-45-Encryption-72-Hour-SPDP-Notification-CSIRT Ecuador LOPDP Security + Processor + Breach Notification + Articles 37-45 + 72-Hour

HITECH Act · 2 controls

  • HITECH-Scope-ARRA-XIII-42USC-Ch156-Subtitles HITECH Act Statutory Scope, ARRA Title XIII Origin and 42 USC Chapter 156 Structure (Subtitles A through D)
  • HITECH-SubtitleA-ONC-HIT-Standards-EHR-MU-PI HITECH Subtitle A - ONC, HIT Standards Committee, EHR Certification, Meaningful Use / Promoting Interoperability

ISO 27001:2022 · 2 controls

  • 5.21 Managing information security in the information and communication technology (ICT) supply chain
  • 8.8 Management of technical vulnerabilities

ISO 27002:2022 · 2 controls

  • 5.21 Managing information security in the ICT supply chain
  • 8.8 Management of technical vulnerabilities

ISO/IEC 27400:2022 · 2 controls

  • 27400-5.4 Data and privacy risks
  • 27400-7.3 Data minimization and purpose limitation
  • 27557-3 Terms and definitions
  • 27557-4.3 Individual impact consideration
  • INCDPA-ConsumerRights-Access-Correction-Deletion-Portability-OptOut-TargetedAd-Sale-Profiling-Appeal-45Day Indiana CDPA Consumer Rights - Access + Correction + Deletion + Portability + Opt-Out of Targeted Advertising/Sale/Profiling + 45-Day Response + 45-Day Extension + Authorised Agent + Appeal Process
  • INCDPA-Controller-PrivacyNotice-PurposeLimitation-DataMinimisation-Transparency-LawfulBasis Indiana CDPA Controller Obligations - Privacy Notice + Purpose Limitation + Data Minimisation + Transparency + Lawful Basis + Reasonable + Adequate + Relevant + Limited to What is Necessary

Indonesia PDP Law · 2 controls

LGPD · 2 controls

  • LGPD-BR-Data-Subject-Rights-Article-18-Confirmation-Access-Correction-Anonymization-Portability-Revoke-Sharing Brazil LGPD Data Subject Rights + Article 18 + 9 Rights + Confirmation + Anonymization
  • LGPD-BR-Security-Article-46-48-Breach-Notification-ANPD-Reasonable-Time-Incident-Response-CSIRT Brazil LGPD Security + Article 46-48 + Breach Notification + ANPD + Incident Response

Mauritius DPA · 2 controls

  • MU-DPA-Data-Subject-Rights-Sections-26-33-Access-Rectification-Erasure-Restriction-Portability-Objection Mauritius DPA Subject Rights + Sections 26 to 33 + Access + Rectification + Erasure + Restriction + Portability + Objection
  • MU-DPA-Seven-Principles-Section-21-Lawfulness-Purpose-Minimisation-Accuracy-Storage-Integrity-Accountability Mauritius DPA Seven Principles + Section 21 + Lawfulness + Purpose + Minimisation + Accuracy + Storage + Integrity + Accountability

NIST SP 800-171 Rev 3 · 2 controls

  • 03.11.02 Vulnerability Monitoring and Scanning
  • 03.17.03 Supply Chain Requirements and Processes

NIST SP 800-172 · 2 controls

  • 3.11.6e Supply Chain Risk Assessment, Response, and Monitoring
  • 3.14.3e Include Systems in Scope of Enhanced Requirements or Segregate into Purpose-Specific Networks
  • NRFCS-4 Consumer Privacy Rights, Consent, Marketing, and Loyalty Data
  • NRFCS-7 Detection, Logging, Incident Response, Breach Notification, and Fraud Detection
  • NGNDPR-2 Governing Principles, Lawful Basis, and Consent under NDPR Section 2.1-2.3
  • NGNDPR-4 Data Subject Rights and Automated Decision-Making

PCI DSS 4.0 · 2 controls

  • 6.3.1 6.3.1 Vulnerability identification and risk ranking
  • 6.3.2 6.3.2 Inventory of bespoke software and components

POPIA · 2 controls

  • POPIASA-3 Data Subject Rights (Access, Correction, Objection), Automated Decisions
  • POPIASA-4 Special Personal Information, Children, Information Quality, Documentation

Peru DPL · 2 controls

  • PERU-2 Consent, Privacy Notice, Sensitive Data
  • PERU-5 Security of Personal Data and Processor Agreements

Qatar DPL · 2 controls

  • QATAR-3 Data Subject Rights
  • QATAR-7 DPO, Records, Retention, Marketing, Training
  • SSAE18-P1.1 P1.1 - Privacy Notice
  • SSAE18-P1.2 P1.2 - Choice and Consent
  • 502 Interoperability with Assistive Technology
  • 707 Real-Time Text Functionality

Taiwan PDPA · 2 controls

  • TAIWAN-2 Consent, Notice, Sensitive Data
  • TAIWAN-3 Data Subject Rights
  • TEXASTDPSA-1 Scope, Applicability, Exemptions
  • TEXASTDPSA-3 Sensitive Data, Children, Sale Notice

Turkey KVKK · 2 controls

  • TURKEYKVKK-1 VERBIS Registration and Lawful Basis
  • TURKEYKVKK-2 Information Notice and Data Subject Rights
  • UKGDPRREG-2 Data Subject Rights (Articles 12-22)
  • UKGDPRREG-3 Controller and Processor (Articles 24-43)
  • OB-API.2 Open Data API Specification
  • OB-CX.2 Granular Consent Management
  • UGA-13 Unlawful Obtaining or Disclosure
  • UGA-15 Unauthorized Sale of Data

Virginia CDPA · 2 controls

  • VIRGINIAVCDPA-1 Scope, Applicability, Definitions
  • VIRGINIAVCDPA-2 Consumer Rights
  • ANSSI-HYG-35 Anticipate the End of Maintenance of Software and Systems
  • AL-DPA-12 International Data Transfers
  • CFTC-SS-30 Outsourcing with Retention of Complete Responsibility

CMMC 2.0 · 1 control

  • CTDPA-1 Definitions
  • DIQ-1 Data Integration and Interoperability
  • FTC-Safeguards-Scope-Defs Scope, Definitions and Financial Institution Applicability (16 CFR 314.1, 314.2)

FedRAMP Rev 5 · 1 control

  • FedRAMP-PII-Privacy FedRAMP PII processing + privacy controls (NIST 800-53 Rev 5 PT family + Privacy Act)

IEEE 7000 · 1 control

  • IEEE7000-Values-Elicitation-Prioritisation-IEEE7000Family-Bias-Privacy-Transparency IEEE 7000 Clauses 6 + 6.1 - Ethical Values Elicitation + Prioritisation + IEEE 7000 Family Integration (Bias + Privacy + Transparency + Wellbeing)
  • ISO8000-MDG-01 Master Data Quality

ISO/IEC 23894:2023 · 1 control

  • ISO23894-A.5 Privacy and Data Protection in AI

Japan AI Guidelines · 1 control

  • JP-AIG-Data-Governance-Training-Data-Quality-Provenance-Lineage-Copyright-APPI-Personal-Information-Protection Japan AI Guidelines Data Governance + Training Data Quality + Provenance + Lineage + Copyright Act 2018 Article 30-4 Text Data Mining Exception + APPI 2022 Amendment + Personal Information Protection + Privacy Principle
  • LV-PDPL-Data-Subject-Rights-Access-Correction-Erasure-Restriction-Portability-Objection-Sec18-Sec38 Latvia PDPL Data Subject Rights + Access + Correction + Erasure + Portability + Section 18 + 38

MARS-E · 1 control

  • NAIC-6 Cybersecurity Event Investigation and Notification - Sections 6 and 7
  • NISTAI600-7 Confabulation, Bias, Information Integrity, Privacy, IP (Risks 2, 4, 5, 6, 7, 8, 10, 11)
  • NGCB-7 Patron and Employee Data Protection + Data Inventory + Vendor Management
  • AUNDB-A3 Eligible Data Breach Determination and Serious Harm Threshold

OECD AI Principles · 1 control

  • OECDAI-5 Data Governance, Training Data Quality, Privacy, and Bias Mitigation
  • OWASPLLM-3 Sensitive Information Disclosure and Privacy (LLM02)
  • OMANCS-4 Data Protection, Cryptography, and Privacy Alignment
  • RCEPEC-1 Online Personal Information Protection (12.13)
  • RIDTPPA-11 Data Minimisation and Purpose Limitation
  • SOC-CY-DC2 Nature of Sensitive Information
  • IM8-DAT.3 Data Sharing and Transfer
  • SAPAIA-4 Information Regulator Cooperation and Appeals

South Korea PIPA · 1 control

  • PIPA-Data-Subject-Rights-Access-Correction-Erasure-Portability-Automated-Decisions-Articles-35-37-2 Korea PIPA Data Subject Rights + Access + Correction + Erasure + Portability + Article 35-37
  • STUDPRV-2 Data Subject Rights for Students and Parents
  • TISAXASS-3 Prototype Protection and Confidentiality
  • UKAI-2 Sector-Specific Regulator Engagement
  • UNICEFAI-4 Transparency, Explanation, Adult Capacity
  • CPSC-STD.4 Interoperability Safety

Vietnam PDPD · 1 control

  • VIETNAMPDP-1 Scope, Categorisation, Lawful Basis

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in DevOps Security

You are reading one control. How much of Azure Security Benchmark have you already done?

Azure Security Benchmark DS-2 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of Azure Security Benchmark your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 71 of 85 Azure Security Benchmark controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 0 were rejected on the NIST SP 800-53 Rev 5 pair alone.

Query this from an agent

The graph holds this control, the 381 it maps to, and the evidence behind each claim, over MCP and REST.