Frameworks / Bahrain PDPL / BH-PDPL-18 Bahrain PDPL
Bahrain PDPL: Data Security
Bahrain PDPL BH-PDPL-18: Regular security testing and assessment Regular security testing and assessment. Control from Bahrain PDPL framework, domain: Bahrain PDPL: Data Security.
Maintained by Gerard Blokdyk · Verified against the published standard 31 May 2026 · Control text last updated 21 May 2026 What else in your programme already covers this This control maps to 76 controls across 63 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
NDPA-1 Applicability, Scope, and Carve-Outs NDPA-6 Reasonable Security Practices and Incident Response NG-NDPA-1 Scope, Applicability, and Establishment of Nigeria Data Protection Commission NG-NDPA-6 Data Protection Officer, DPCO, and Processor Agreements DSOMM-2 Implementation Practices, Secure Coding, and Threat Modelling DSOMM-4 Test and Verification - SAST, DAST, IAST, SCA, Penetration Testing PMF-SP.3 Security Testing and Monitoring APPI-A31 Provision of Personally Referable Information LOPDP-EC-Security-Processor-Breach-Notification-Articles-37-45-Encryption-72-Hour-SPDP-Notification-CSIRT Ecuador LOPDP Security + Processor + Breach Notification + Articles 37-45 + 72-Hour FFIEC-08 Application security controls FTC-Safeguards-9-Elements 9 Safeguard Elements - Access, Inventory, Encryption, Secure-Dev, MFA, Disposal, Change-Mgmt, Monitoring, Pen-Test (16 CFR 314.4(c)) FERPA-Safeguards-PTAC Data Security Safeguards for PII in Education Records (PTAC Best Practices, SPPO Guidance) UAE-PDPL-Art.25_26_27_28_29 UAE Data Office establishment, powers, penalties, complaints (UAE PDPL Articles 25-29) GLBA-Subordinate-Rules-Operationalisation GLBA Operationalisation through FTC Safeguards Rule, Privacy Rule, SEC Reg S-P and Banking-Agency Guidelines HKMA-CRAF-Domain3-4-Protection-Detection HKMA C-RAF Domain 3 (Protection) + Domain 4 (Detection) - Access, Data, Infrastructure, Application, Monitoring, Testing, Threat Intel HKMA-SPM-TM-Technology-TM-G-1-CRAF-Coord HKMA SPM Technology Management Modules (TM-G-1 to TM-G-4, TM-E-1) + Coordination with C-RAF 27400-6.3 Secure Update Mechanism INCDPA-Security-ReasonablePractices-Breach-Notification-Records-Encryption-Pseudonymisation Indiana CDPA Security + Reasonable Practices + Breach Notification + Indiana Breach Notification Law (IC 24-4.9) + Records + Encryption + Pseudonymisation + De-Identification LGPD-BR-Security-Article-46-48-Breach-Notification-ANPD-Reasonable-Time-Incident-Response-CSIRT Brazil LGPD Security + Article 46-48 + Breach Notification + ANPD + Incident Response DOM172-Security-Measures-Article-25-Encryption-Pseudonymization-Access-Control-Incident-Handling-Breach-Notification-Article-22 Dominican Republic Law 172-13 Security Measures + Article 25 + Encryption + Breach Notification MY-PDPA-DPO-Designation-Class-Data-User-Registration-DPIA-Code-Practice-Section-43A-2024-Amendment Malaysia PDPA Governance + DPO Section 43A + Class of Data User Registration + DPIA + Code of Practice MU-DPA-Governance-DPO-Designation-Section-25-DPO-ROPA-DPIA-Codes-Section-38-Commissioner-Registration Mauritius DPA Governance + DPO + ROPA + DPIA + Codes Section 38 + Commissioner Registration MX-LFPDPPP-Governance-Officer-Reglamento-47-50-Security-Manual-57-Risk-Assessment-61-Self-Regulation-Parameters-2014 Mexico LFPDPPP Governance + Officer + Reglamento 47 + Security Manual 50 + Risk Assessment 57 + Self-Regulation Parameters 2014 MN-CDPA-Chief-Privacy-Officer-Section-325O-06-MN-UNIQUE-Designation-Privacy-Programme-Training Minnesota CDPA Chief Privacy Officer + Section 325O.06 + MINNESOTA-UNIQUE Designation + Privacy Programme + Training MAS-TRM-Access-Cryptography-Network-Security-Chapters-9-10-MFA-PKI-Encryption-Network-Segmentation MAS TRM Access Control + Cryptography + Network + Chapters 9-10 + MFA + PKI + Encryption + Network Segmentation MT-CDPA-Sensitive-Data-MCA-30-14-2802-Opt-In-Children-13-Parental-Consent-Minors-13-16-Opt-In Montana CDPA Sensitive Data + MCA 30-14-2802 + Affirmative Opt-In + Children Under 13 Parental + Minors 13-16 Opt-In NAIC-2 Information Security Program (ISP) - Section 4 NIST-CSF-PR.PS-06 Secure software development practices are integrated, and their performance is monitored throughout the software development life cycle NISTSP122-8 Continuous Monitoring, Training, and Privacy Programme Governance NHPA-6 Reasonable Data Security and Breach Response NJDPA-6 Reasonable Data Security and Incident Response NGNDPR-5 Security of Personal Data, Breach Notification, and DPIA under NDPR Section 2.6-Security ORANWG11-8 Supply Chain, Secure Development Lifecycle, Privacy, Multi-Vendor Trust OSFIB13-3 Cyber Security: Identification, Protection, Detection, Response, Recovery OPENBANK-3 Mutual TLS, Token Binding, Request Signing (JWS), Key Management OREGONCPA-4 Universal Opt-Out, Targeted Advertising, Profiling PCI-P2PE-08 Application security controls PCI-PIN-08 Application security controls PCI-SSF-08 Application security controls PDPASG-5 Protection, Accuracy, and Security of Personal Data PDPATH-5 Security Measures and Data Protection POPIASA-5 Security Safeguards, Encryption, Access Control, Operator Obligations PSDTWO-1 Strong Customer Authentication (SCA) Core Requirements NORWAY-5 Security of Processing, Encryption, Pseudonymization, Access Control PERU-4 Children's Data, Privacy Impact, Sensitive Categories NZPRV-2 IPP 5 Storage and Security of Personal Information QATAR-5 Security of Processing SA-PDPL-18 Regular security testing and assessment SBD-DEV-05 Secure Software Development Framework IM8-DSS.3 Secure Development Practices PIPA-CPO-DPO-Privacy-Officer-PIA-Personal-Information-Impact-Assessment-Articles-31-33 Korea PIPA CPO + DPO + Privacy Officer + PIA + Personal Information Impact Assessment + Articles 31-33 TAIWAN-3 Data Subject Rights TEXASTDPSA-2 Consumer Rights TURKEYKVKK-2 Information Notice and Data Subject Rights URUGUAY-4 Security and Cross-Border VIETNAMPDP-2 Consent and Notice VIRGINIAVCDPA-3 Sensitive Data Consent and Children Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Other controls in Bahrain PDPL: Data Security Query this from an agent The graph holds this control, the 76 it maps to, and the evidence behind each claim, over MCP and REST.