Frameworks / Family Educational Rights and Privacy Act (FERPA) / FERPA-Safeguards-PTAC Family Educational Rights and Privacy Act (FERPA)
FERPA: Data Security Safeguards (PTAC Best Practices and SPPO Guidance)
Family Educational Rights and Privacy Act (FERPA) FERPA-Safeguards-PTAC: Data Security Safeguards for PII in Education Records (PTAC Best Practices, SPPO Guidance) 34 CFR 99.31(a)(6)(iii)(D) safeguards requirement + the PTAC Best Practices Guidance + SPPO Guidance. The 2011 final rule explicitly requires APPROPRIATE METHODS to PROTECT PII when disclosed under the studies + audit + evaluation exceptions. While FERPA itself does not prescribe specific security controls, the SPPO + PTAC + state-law (e.g. SOPIPA + CCPA-derived state student privacy laws + the 2018 Connecticut Act Concerning Student Data Privacy) impose the following safeguards on educational institutions + vendors processing student PII: (a) ACCESS CONTROL - need-to-know basis + role-based access + login authentication + just-in-time access + multi-factor authentication for sensitive PII; (b) ENCRYPTION - in-transit (TLS 1.2+) + at-rest (AES-256) + key management; (c) NETWORK + INFRASTRUCTURE SECURITY - firewall + IDS/IPS + segmentation + vulnerability management; (d) DATA RETENTION + DESTRUCTION - retention only as long as needed + verifiable destruction (NIST SP 800-88 sanitization); (e) INCIDENT RESPONSE + BREACH NOTIFICATION - written IR plan + tabletop testing + breach notification per state laws (no FERPA-specific breach notification timeline but state laws apply incl. all 50 states + DC); (f) VENDOR + CLOUD MANAGEMENT - written agreements + due diligence + direct control + audit rights + subprocessor controls; (g) WORKFORCE TRAINING - annual FERPA + security training + role-specific training for IT + privacy staff; (h) PRIVACY BY DESIGN - data minimisation + purpose limitation + edtech vendor evaluation matrix per PTAC; (i) COMPLIANCE MONITORING - annual audit + risk assessment + program review aligned with NIST SP 800-53 + NIST CSF 2.0 + FERPA-specific control mapping. The PTAC Best Practices Guidance includes detailed checklists for edtech vendors + cloud providers + administrative practices.
Maintained by Gerard Blokdyk · Verified against the published standard 31 May 2026 · Control text last updated 21 May 2026 What else in your programme already covers this This control maps to 352 controls across 82 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
BSI-03 Multi-factor authentication requirements BSI-04 Remote access controls BSI-05 Wireless access restrictions BSI-08 Cryptographic protection of data BSI-13 Risk assessment procedures BSI-15 Security categorization BSI-17 Continuous monitoring strategy BSI-18 Incident response planning and testing BSI-20 Incident reporting and notification BSI-21 Forensic analysis capabilities APPI-A23 Security Control Measures APPI-A24 Supervision of Employees APPI-A26 Report of Leakage to the Commission and Notification to the Person APPI-A31 Provision of Personally Referable Information APPI-A33 Request for Disclosure of Retained Personal Data APPI-A34 Request for Correction, Addition or Deletion APPI-A41 Preparation and Handling of Pseudonymized Personal Information APPI-A43 Preparation of Anonymized Personal Information API1164-06 Access Control API1164-07 Remote Access API1164-09 Patch and Vulnerability Management API1164-17 Wireless and Field Communications API1164-18 Field Device Security API1164-19 Safety Instrumented Systems Interface API1164-24 Vulnerability assessment for critical systems 27400-5.4 Data and privacy risks 27400-6.2 Device Identity and Authentication 27400-6.3 Secure Update Mechanism 27400-6.5 Security monitoring and incident response 27400-7.1 Network Security for IoT 27400-7.3 Data minimization and purpose limitation 27400-7.4 Data retention and deletion AT-DSG-10 Section 29 - Liability and right to compensation / civil jurisdiction AT-DSG-11 Sections 42-45 - Data subject rights (law enforcement) AT-DSG-12 Section 62 - Administrative penalties AT-DSG-13 Section 36 - Scope of law enforcement processing AT-DSG-14 Section 38 - Lawfulness of law enforcement processing AT-DSG-7 Section 18 - Establishment of the Data Protection Authority BB-DPA-1 Section 1 - Short Title BB-DPA-14 Section 15 - Right to Data Portability BB-DPA-16 Section 22 - General Principle for Transfers BB-DPA-20 Sections 50-60 - Registration and Responsibilities BB-DPA-21 Sections 61-69 - Data Privacy Officer BB-DPA-4 Section 4 - Principles Relating to Processing UAE-PDPL-Art.10 Data Protection Officer (DPO) (UAE PDPL Article 10) UAE-PDPL-Art.18_19_20_21 Security measures, controller/processor relationship, DPIA (UAE PDPL Articles 18-21) UAE-PDPL-Art.25_26_27_28_29 UAE Data Office establishment, powers, penalties, complaints (UAE PDPL Articles 25-29) UAE-PDPL-Art.4_5 Lawful basis and principles for processing personal data (UAE PDPL Articles 4-5) UAE-PDPL-Art.6_7 Sensitive personal data and children's data (UAE PDPL Articles 6-7) UAE-PDPL-FreeZones Coordination with DIFC, ADGM and sectoral data protection regimes 27011-5.2 Information Security Roles in Telecoms 27011-5.3 Segregation of duties 27011-6.3 Awareness and Training 27011-8.1 User Endpoint Devices 27011-8.3 Cryptography and key management 27011-8.6 Data protection and backup AWWA-1.2 Risk Assessment AWWA-2.1 User Access Management AWWA-2.4 Physical Access Controls AWWA-3.2 Remote Access Security AWWA-3.4 Encryption and Data Protection IACS-UR-E26-Identify-Plan-Risk-Survey-Documentation IACS UR E26 Identify Goal - Ship Cyber Resilience Plan + CBS Risk Assessment + Survey + Documentation IACS-UR-E26-Protect-AccessControl-Authentication-IAM-Roles IACS UR E26 Protect Goal - Access Control + Identity + Authentication + Authorization + User Management IACS-UR-E26-Protect-RemoteAccess-Wireless-Physical-Boundary IACS UR E26 Protect Goal - Remote Access + Wireless + Physical Security + Boundary Protection IACS-UR-E26-Respond-Recover-IncidentResponse-Recovery-Backup-Lessons IACS UR E26 Respond + Recover Goals - Incident Response + Communication + Recovery + Backup + Lessons Learned IACS-UR-E27-Logging-Forensics-EventCapture IACS UR E27 - Equipment Logging + Forensic Readiness + Event Capture + Tamper Detection AUPRV-1 APP 1 Open and Transparent Management + Privacy Management Framework AUPRV-4 APP 10-11 Quality, Security of Personal Information AUPRV-6 Sensitive Information, PIA, Privacy by Design, Children AUPRV-7 Notifiable Data Breaches (NDB) Scheme, Incident Response AUPRV-8 OAIC Cooperation, Vendor Management, Training, Complaints, Enforcement ASD37-17 TLS encryption between email servers (Limited) ASD37-27 Outbound data loss prevention (Very Good) ASD37-31 Hunt to discover incidents (Very Good) ASD37-33 Capture network traffic (Limited) AZ-DPA-12 Article 13 - Cross-border transfer AZ-DPA-14 Article 16 - Liability for violations AZ-DPA-15 Article 17 - Dispute resolution AZ-DPA-6 Article 6 - State regulation in personal data protection DIQ-2 Data Quality Management DIQ-3 Metadata Management DSO-2 Data Security DSO-3 Data Access Management 27010-10.1 Cryptographic Protection 27010-16.1 Continuity of Sharing 27010-9.1 Access Control to Shared Information 27010-9.2 Authentication of Sources DSOMM-1 Culture, Organization, Education, and Governance DSOMM-2 Implementation Practices, Secure Coding, and Threat Modelling DSOMM-3 Build, Deployment, Infrastructure Hardening, and Secrets Management DSOMM-4 Test and Verification - SAST, DAST, IAST, SCA, Penetration Testing OWASPTOP10-1 A01:2025 Broken Access Control OWASPTOP10-2 A02:2025 Cryptographic Failures and Secret Management OWASPTOP10-4 A04:2025 Insecure Design and Business Logic (incl. A11 API Abuse) OWASPTOP10-9 A09:2025 Security Logging and Monitoring Failures PAKPDPB-5 Security of Processing and Personal Data Breach Notification PAKPDPB-6 Cross-Border Transfer and Data Localization PAKPDPB-7 NCPDP, Registration, Records, Processor Contracts, DPO PAKPDPB-8 Enforcement, Penalties, Complaints, Retention, Training AL-DPA-12 International Data Transfers AL-DPA-14 Direct Marketing AL-DPA-7 Right of Access APP-1 APP 1 - Open and transparent management of personal information APP-3 APP 3 - Collection of solicited personal information APP-5 APP 5 - Notification of the collection of personal information LOPDP-EC-Cross-Border-Transfers-Articles-59-65-Adequacy-SCC-BCR-EU-Schrems-LatAm-CBPR-Andean-Community Ecuador LOPDP Cross-Border + Articles 59-65 + Adequacy + Andean Community + LatAm LOPDP-EC-Governance-DPO-ROPA-DPIA-Privacy-by-Design-Training-Articles-46-58-Compliance-Monitoring Ecuador LOPDP Governance + DPO + ROPA + DPIA + Privacy by Design + Training LOPDP-EC-Security-Processor-Breach-Notification-Articles-37-45-Encryption-72-Hour-SPDP-Notification-CSIRT Ecuador LOPDP Security + Processor + Breach Notification + Articles 37-45 + 72-Hour CJIS-17 Risk Assessment CJIS-8 Media Protection CJIS-9 System and Communications Protection CAT-D3-1 Preventative controls CAT-D4-3 Third-party access controls CAT-D5-1 Incident planning and strategy FEDRAMP-SC-13 Cryptographic Protection FEDRAMP-SC-28 Protection of Information at Rest FEDRAMP-SC-8 Transmission Confidentiality and Integrity HKMA-CRAF-Domain1-2-Governance-Identification HKMA C-RAF Domain 1 (Governance) + Domain 2 (Identification) - Cyber Strategy, Risk Management, Asset Management, Threat Assessment HKMA-CRAF-Domain3-4-Protection-Detection HKMA C-RAF Domain 3 (Protection) + Domain 4 (Detection) - Access, Data, Infrastructure, Application, Monitoring, Testing, Threat Intel HKMA-CRAF-Domain5-6-Response-Recovery-SitAwareness HKMA C-RAF Domain 5 (Response and Recovery) + Domain 6 (Situational Awareness) - Incident Response, Recovery, Threat Landscape, Information Sharing 23837-1.2 Normative references 23837-1.5.2 Cryptographic module requirements 23837-1.5.3 Network device testing requirements 27557-3 Terms and definitions 27557-4.3 Individual impact consideration 27557-6.3 Privacy risk assessment 29100-6.10 Information security 29100-6.5 Use, retention and disclosure limitation 29100-6.9 Accountability 29134-1 Scope 29134-3 Terms and definitions 29134-9.1 PIA report structure ItalyCodice-Garante-Enforcement-AdministrativeSanctions-Criminal-Art166-167-170-20MEUR-Coord-EDPB Italy Codice Garante Authority + Article 140-bis + Article 144 Complaints + Article 166 Administrative Sanctions up to EUR 20M/4% + Article 167 Criminal Offences + Article 170 Failure to Comply with Garante Orders + EDPB Coordination ItalyCodice-SpecialCategories-Health-Workplace-Education-ScientificResearch-HistoricalResearch-Art75-92-96-99-101 Italy Codice Special Categories + Article 75 Administrative Fines + Article 92 Medical Records + Article 96 Education + Article 99 Scientific Research + Article 101 Historical Research + Workplace Privacy + Worker Monitoring Article 4 Workers Statute ItalyCodice-ePrivacy-Cookies-ElectronicCommunications-Telemarketing-PublicOpposition-TrafficDataRetention-Art121-122-130-132 Italy Codice ePrivacy - Article 121 Electronic Communications + Article 122 Cookies and Tracking + Article 130 Unsolicited Direct Marketing + Article 132 Traffic Data Retention + Italian Public Opposition Register (Registro delle Opposizioni) DOM172-Lawful-Basis-Consent-Notice-Information-Duty-Articles-4-12-Quality-Principle-Purpose-Limitation-Minimisation Dominican Republic Law 172-13 Lawful Basis + Consent + Notice + Information Duty + Articles 4-12 DOM172-Security-Measures-Article-25-Encryption-Pseudonymization-Access-Control-Incident-Handling-Breach-Notification-Article-22 Dominican Republic Law 172-13 Security Measures + Article 25 + Encryption + Breach Notification DOM172-Supervisory-Authority-Cooperation-Sanctions-Penalties-Articles-77-79-Awareness-Training-Retention-DPO-Designation Dominican Republic Law 172-13 Supervisory Authority + Sanctions + Articles 77-79 + DPO + Awareness PSPF24-1 Security Culture, Governance, Risk Management PSPF24-2 Information Security, Cybersecurity Maturity, Essential Eight PSPF24-4 Physical Security D.1 Incident Response Planning D.2 Incident Reporting UKDEFSTD-1 Cyber Defence Cyber Risk Profile (CRP) CPSC-CS.2 Authentication and Access Controls CPSC-CS.3 Data Protection for Safety Systems CPSC-RA.3 Lifecycle Risk Assessment CPS230-11 Identification, Assessment and Management of Operational Risk CPS230-13 Board Accountability for Operational Risk Management CPS234-21 Implementation of Information Security Controls CPS234-25 Internal Audit Review of Information Security Controls 4.3.1 Risk Assessment and Impact Analysis 4.4.7 Emergency and Incident Response CA-10 Selects and Develops Control Activities CA-12 Deploys Through Policies and Procedures FDBR-ControllerObligations-DPA-Notice Controller + Processor Obligations + Data Protection Assessments (Fla. Stat. 501.707, 501.708, 501.71, 501.711) FDBR-SensitiveData-Children-VoiceFacial Sensitive Data, Children's Privacy and Voice/Facial Recognition (Fla. Stat. 501.711, 501.1735) 62351-8 Role-based access control (RBAC) 62351-9 Cyber security key management 30111-3 Terms and definitions 30111-5.2 Vulnerability handling team OWASPAPI-1 Broken Object Level Authorization (BOLA) and BFLA OWASPAPI-6 Security Misconfiguration and Secure API Design ASTWO-1 Audit Planning, Scaling, Risk Assessment, and Integration ASTWO-3 Entity-Level Controls and Period-End Financial Reporting Process RUSPD-1 Scope, Definitions, Principles under 152-FZ RUSPD-4 Special Categories, Biometric Data 2.4.4 Hazard Analysis and Risk Assessment 2.7.2 Food Fraud Plan PIPA-CPO-DPO-Privacy-Officer-PIA-Personal-Information-Impact-Assessment-Articles-31-33 Korea PIPA CPO + DPO + Privacy Officer + PIA + Personal Information Impact Assessment + Articles 31-33 PIPA-Pseudonymisation-Article-28-2-3-Enforcement-PIPC-Investigation-Surcharges-3-Percent-Revenue-Article64-2 Korea PIPA Pseudonymisation + Article 28-2 + Enforcement + PIPC + Surcharges 3% + Article 63 + 64-2 CRM-1 AML/CFT Compliance CRM-4 Business Risk Assessment CYB-5 Cyber Incident Response Plan USMTSA-2 Cybersecurity Assessment and CSO Designation USMCADIGITAL-1 Cross-Border Data Flows and Localisation USMCADIGITAL-2 Personal Information Protection and Consumer Protection VERMONTAICDA-3 Bias Testing, Discrimination Prevention, Transparency VERMONTAICDA-4 Vermont AG Enforcement and Cure VIETNAMCYBER-2 Prohibited Acts (Access, Interception, Forgery, Content) VIETNAMCYBER-4 Incident Reporting and Cooperation AMLCTF-PartA-RiskAssess ML/TF Risk Assessment DS-2 Ensure software supply chain security CA-ITSG33-SC-01 Security Control Catalogue CBPR-9-APEC-Privacy-Principles Global CBPR Forum: 9 APEC Privacy Principles (Notice + Collection + Uses + Choice + Integrity + Security + Access + Accountability + Preventing Harm) ICAO-ANX17-Chap4-AccessControl-AirsideRestricted-Personnel-Background ICAO Annex 17 Chapter 4 - Access Control + Airside + Security Restricted Area + Personnel Background Checks + Vetting 27031-7.2 Resource Requirements 29115-7.4 Level of Assurance 4 (LoA4) 29147-5.11 Researcher Safe Harbour and Legal Posture RBI-AA-ConsentArchitecture-ConsentArtefact-ExplicitConsent-PurposeLimitation-CustomerDashboard-ORS-CMP RBI AA Consent Architecture - Consent Artefact + Explicit Customer Consent + Purpose Limitation + Customer Consent Dashboard + Online Revocation Service + Consent Management Provider NISTSP34-3 Preventive Controls and Recovery Strategies: Backup, Alternate Sites, Equipment EHDS-HOLD-3 Dataset Descriptions and Catalogues RIDTPPA-2 Consumer Rights (Access, Correction, Deletion, Portability, Opt-Out) SGCYBER-1 Critical Information Infrastructure (CII) Designation and Registration TEFCAREC-1 Common Agreement Conformance and Onboarding USSDWA-2 Cybersecurity Practices (Assessment, Access, Network, IR) Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Query this from an agent The graph holds this control, the 352 it maps to, and the evidence behind each claim, over MCP and REST.