Frameworks / CISA Cross-Sector Cybersecurity Performance Goals (CPG) 2.0 / CPG-1.C What else in your programme already covers this This control maps to 213 controls across 103 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
ASD37-18 Restrict administrative privileges (Essential) ASD37-20 Multi-factor authentication (Essential) ASD37-23 Protect authentication credentials (Excellent) ASD37-37 Personnel management (Very Good) OWASPLLM-1 Prompt Injection and System Prompt Leakage (LLM01 + LLM07) OWASPLLM-2 Improper Output Handling and Misinformation (LLM05 + LLM09) OWASPLLM-3 Sensitive Information Disclosure and Privacy (LLM02) OWASPLLM-6 Excessive Agency and Unbounded Consumption (LLM06 + LLM10) AWWA-1.3 Security Awareness and Training AWWA-2.1 User Access Management AWWA-2.2 Authentication Mechanisms Part11.10 Controls for closed systems (21 CFR §11.10) Part11.300 Controls for identification codes and passwords (21 CFR §11.300) Part11.AccessAndAuth Access control + authority + device checks (21 CFR §11.10(d) + (f) + (g) + (h)) ISO27799-01 ePHI access controls and authorization ISO27799-09 Security awareness and training program ISO27799-12 Unique user identification and authentication 29115-11 Mapping other authentication schemes 29115-12.1 Exchanging authentication results 29115-12.2 Controls for mitigating threats MDS2-PHI-Data-Handling-DATA-Storage-STCF-Transmission-TXCF-TXIG-Encryption-FIPS MDS2 PHI Handling + DATA + STCF Storage + TXCF Transmission + TXIG Integrity + Encryption + FIPS MDS2-Person-Node-Authentication-Authorization-Auto-Logoff-AUTH-PAUT-NAUT MDS2 Authentication + Authorization + Auto Logoff + PAUT + NAUT + AUTH + Identity Management MDS2-Roadmap-Third-Party-RDMP-Security-Guidance-SGUD-SBOM-Vulnerability-Disclosure-Programme MDS2 Roadmap + RDMP + Third Party + Security Guidance + SGUD + SBOM + Vulnerability Disclosure + Coordinated NIST-CSF-PR.AA-01 Identities and credentials for authorized users, services, and hardware are managed by the organization NIST-CSF-PR.AA-02 Identities are proofed and bound to credentials based on the context of interactions NIST-CSF-PR.AA-05 Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties NISTPF-3 Control-P - Privacy Controls, Data Management, and Disassociated Processing NISTPF-5 Protect-P Access Control (PR.AC-P) NISTPF-8 Protect-P Information Protection Processes (PR.PO-P) NISTSP82-1 OT Security Program Governance, Policy, Roles, and Safety-Security Integration NISTSP82-2 OT Risk Assessment and Threat/Vulnerability Identification NISTSP82-4 OT Access Control, Identity, Authentication, and Remote Access DSOMM-1 Culture, Organization, Education, and Governance DSOMM-3 Build, Deployment, Infrastructure Hardening, and Secrets Management DSOMM-4 Test and Verification - SAST, DAST, IAST, SCA, Penetration Testing CISABD-1 Take Ownership of Customer Security Outcomes CISABD-3 Build Organizational Structure and Leadership for Secure Outcomes SBD-DEV-04 Phishing-Resistant Authentication OB-CX.3 Strong Customer Authentication OB-DIR.1 Open Banking Directory OB-SEC.4 Certificate Management BSI-02 Access enforcement and least privilege BSI-03 Multi-factor authentication requirements CAT-D1-4 Training and culture CAT-IRP-4 Organizational characteristics FTC-Safeguards-9-Elements 9 Safeguard Elements - Access, Inventory, Encryption, Secure-Dev, MFA, Disposal, Change-Mgmt, Monitoring, Pen-Test (16 CFR 314.4(c)) FTC-Safeguards-ServiceProvider-Evaluation Service Provider Oversight + Program Evaluation + Personnel Training (16 CFR 314.4(d-g)) FDBR-Scope-Defs Scope, Applicability Thresholds and Definitions (Fla. Stat. 501.701, 501.702, 501.703, 501.704) FDBR-SensitiveData-Children-VoiceFacial Sensitive Data, Children's Privacy and Voice/Facial Recognition (Fla. Stat. 501.711, 501.1735) 27011-6.3 Awareness and Training 27011-8.1 User Endpoint Devices ISO27043-13 Authentication and password management ISO27043-14 Privileged access management ISO21434-13 Authentication and password management ISO21434-14 Privileged access management ITAR-Part123-125-ExportLicensing-DSP-5-DSP-73-DSP-61-MLA-TAA-Classified-Information-Routed ITAR Parts 123-125 Export Licensing - DSP-5 Permanent Export + DSP-73 Temporary Export + DSP-61 Temporary Import + DSP-83 + Manufacturing License Agreements (MLA) + Technical Assistance Agreements (TAA) + Classified Information + Routed Export Transactions ITAR-TechnicalData-DefenseServices-DeemedExport-ForeignPerson-Access-USPersons-FOC-AUKUS-Exemptions ITAR Technical Data + Defense Services + Deemed Export Rule + Foreign Person Access + US Persons Only + FOCI Foreign Ownership Control Influence + AUKUS Pillar 2 Exemptions + DD-2345 MCTL BIPA-SEC5-1 Biometric Identifier Definition BIPA-SEC5-2 Biometric Information Definition NAIC-1 NAIC Model Law Adoption, Scope, and Licensee Definitions NAIC-6 Cybersecurity Event Investigation and Notification - Sections 6 and 7 NISTSP66-2 Workforce Security, Information Access Management, and Awareness Training NISTSP66-6 Technical Safeguards: Access Control, Audit Controls, Integrity, Person Authentication OMANCS-3 Identity and Access Management, Authentication, Privileged Access OMANCS-8 Third-Party + Supply Chain Risk, Awareness Training, Physical Security, Compliance Audit PASONE-3 Personnel Security, Vetting, Awareness, and Training PASONE-4 Technical Security: CDE Configuration, BIM Tools, Encryption, Aggregation, Mobile Working SUPCHAIN-1 Build Integrity - Source, Build, Provenance SUPCHAIN-2 Source Integrity - Branch Protection, Code Review, Two-Person Rule SOC2-CC6.2 CC6.2 Registering and authorising users before issuing credentials SOC2-CC6.3 CC6.3 Role-based access, least privilege and segregation of duties SSAE18-CC6.2 CC6.2 - New User Registration and Authorization SSAE18-SOC1-06 Transaction Processing Controls SAM-1 Customer Information Confidentiality (Section 48) SAM-6 Legal Authorization Requirements ISMSP-AC-01 Access Control Policy ISMSP-AC-03 Authentication Mechanisms VP-2 Holder Binding W3CVCDM-4 Accessibility, Internationalization, Security AMLCTF-35 Identity Verification Standard DSO-3 Data Access Management CJIS-2 Security Awareness Training FISMA-CIRCIA-ZTA-EO14028 CIRCIA, Zero Trust Architecture, EO 14028 + 14110 + OMB Memoranda FedRAMP-Boundary Authorization Boundary, SSP, SAR, POA&M documentation GLI33-PAM-KYC-AML-Payments GLI-33 Player Account Management, KYC, AML, Payment Processing and Account Lifecycle GhCSA-CII-Designation-Plan-Audit-Risk CII Designation, Registration, Cybersecurity Plan, Audit and Risk Assessment HITECH-SubtitleD-StrengthIndividualRights HITECH Subtitle D - Strengthened Individual Rights (Electronic Access, Accounting of Disclosures, Restrictions, Sale Prohibition) HKMA-CRAF-Domain3-4-Protection-Detection HKMA C-RAF Domain 3 (Protection) + Domain 4 (Detection) - Access, Data, Infrastructure, Application, Monitoring, Testing, Threat Intel IACS-UR-E27-Equipment-UserAuth-Authentication-Authorization IACS UR E27 - Equipment User Authentication + Authorization + Session Management + Privileged Access IATA-IOSA-Section8-SEC-SecurityManagement-AVSEC IATA IOSA Section 8 - SEC Security Management + Aviation Security Programme (AVSEC) + ICAO Annex 17 Alignment 62351-8 Role-based access control (RBAC) IMO-MSC-FAL-Protect-AccessControl-NetworkSegmentation-MalwareDefence-Patch-Awareness-DataSecurity IMO MSC-FAL Protect Function - Access Control + Network Segmentation + Malware Defence + Patch Management + Awareness Training + Data Security + Crew BYOD + Removable Media ISO-19650-2-5.7 Information model delivery ISO28001-PI-02 Security Awareness and Training 23837-1.7.3 Authentication and classical post-processing 27400-6.1 Secure Device Design MTCS-Asset-IAM-Cryptography-Multi-Tier-Asset-Inventory-RBAC-MFA-PAM-FIPS-HSM-Quantum-Safe MTCS Asset Mgmt + IAM + Cryptography + Asset Inventory + RBAC + MFA + PAM + FIPS + HSM + Quantum-Safe NISTSP115-8 Operational Considerations - Tools, Reporting Templates, ISMS Integration, Annex Material NISTSP123-3 Authentication, Access Control, and Account Management NISTSP137-6 Malware, Identity Access, and Network Boundary Monitoring NISTSP144-1 Cloud Governance, Risk Assessment, and Provider Trust Evaluation NISTSP145-8 Governance, Reporting, and Stakeholder Education on Cloud Definition NISTSP61-5 Containment, Eradication, and Recovery NISTSP63R4-3 Authentication: Authenticator Types, MFA, Phishing-Resistance, and Syncable Authenticators NISTSP88-1 Media Sanitization Policy, Roles, and Decision Framework NISTSP92-4 Log Management: Time Synchronisation, Parsing, Storage, Integrity, Access Control NZISM-1 NZISM Governance, Documentation, and Classification System ORANWG11-2 O-RAN Interface Security: E2, A1, O1, O2, Open Fronthaul OWASPSAMM-2 Design: Threat Assessment, Security Requirements, Security Architecture OSSFSC-3 Build, CI/CD Security, Workflow Permissions, Dangerous Patterns PTESPHASE-2 Intelligence Gathering (OSINT) RCEPEC-1 Online Personal Information Protection (12.13) EHDSREG-6 Phased Application and Enforcement SHAREASSESS-2 Access Control, Identity, Authentication SOCI-CIRMP-SUPPLY CIRMP hazard vector: Supply chain SIGSTORE-2 Transparency Log (Rekor) and Verification GT-4 Social Engineering Attacks TSAPIPE-2 OT/IT Network Segmentation and Access Control UKGAMBLE-4 Resilience and Incident Response UK-TSA-NET-02 Access Control and Authentication ACE-CR-4 Cargo Release Authorization CPSC-CS.2 Authentication and Access Controls USSDWA-2 Cybersecurity Practices (Assessment, Access, Network, IR) CYB-2 Account Security Measures UGA-10 Sensitive Personal Data Prohibition WCAGREC-3 Principle 3: Understandable Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Other controls in Account Security Query this from an agent The graph holds this control, the 213 it maps to, and the evidence behind each claim, over MCP and REST.