FCC Customer Proprietary Network Information (CPNI) and Data Breach Rules (47 CFR 64.2001-2011)
FCC CPNI: Basis, Purpose and Definitions (64.2001-64.2003)

FCC Customer Proprietary Network Information (CPNI) and Data Breach Rules (47 CFR 64.2001-2011) CPNI-64.2001_2003: Basis, purpose and definitions (47 CFR 64.2001 + 64.2003)

Section 64.2001 (Basis and purpose): the rules in this subpart implement Section 222 of the Communications Act of 1934 + provide standards governing telecommunications carriers' use + disclosure of customer proprietary network information (CPNI). Section 64.2003 (Definitions): (a) ACCOUNT INFORMATION = information that is specifically connected to the customer's service relationship with the carrier (account number + telephone number + service-related information that is publicly available); (b) AFFILIATE = a person that owns or controls + is owned or controlled by + is under common ownership or control with another person; (c) CALL DETAIL INFORMATION = any information that pertains to the transmission of specific telephone calls including originating + terminating telephone number + time of call + length of call; (d) COMMUNICATIONS-RELATED SERVICES = telecommunications + information + commercial mobile + interconnected VoIP services; (e) CPNI = the broader definition including call detail + service plan + technical configuration + location information; (f) OPT-IN APPROVAL = a method for obtaining customer approval that requires a customer to give affirmative express consent; (g) OPT-OUT APPROVAL = a method for obtaining customer approval that gives the customer the right to deny access by failing to take an action to disapprove the use within a reasonable period (typically 30 days); (h) TELECOMMUNICATIONS CARRIER = providers of telecommunications services + interconnected VoIP providers (per the 2007 CPNI Order).

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 62 controls across 28 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

ISO/IEC 27011:2024 · 7 controls

ISO/IEC 27400:2022 · 4 controls

  • 1.2 Operating System Privileged Account Control
  • 1.3 Virtualisation Platform Protection
  • 3.3 Configure Data Access Control Lists

ISO/IEC 27004:2016 · 3 controls

ISO/IEC 27014:2020 · 3 controls

ISO/IEC 29100:2024 · 3 controls

ISO/IEC 29134:2023 · 3 controls

ISO/IEC 29147:2018 · 3 controls

ISO/IEC 30111:2019 · 3 controls

  • 6.5 Preparing and Distributing Audit Report
  • 6.7 Conducting Audit Follow-up

ISO 19011 · 2 controls

  • 6.5 Preparing and Distributing Audit Report
  • 6.7 Conducting Audit Follow-up
  • 4.4.1 Resources, Roles, Responsibility, and Authority
  • R.16-VATR.Unhosted Unhosted (self-hosted / non-custodial) wallet transfers - 2024 Targeted Update

ISO 31000:2018 · 1 control

  • 6.7 Conducting Audit Follow-up

ISO/IEC 27007:2020 · 1 control

ISO/IEC 27031:2011 · 1 control

  • 3.3 Configure Data Access Control Lists

PCI DSS 4.0 · 1 control

  • 2.2.2 Vendor default accounts are managed as follows: • If the vendor default account(s) will be used, the default password is changed per Requirement 8.3.6. • If the vendor default account(s) will not be used,

SWIFT CSCF · 1 control

  • SWIFTCSCF-1 Restrict Internet Access and Protect Critical Systems (Objective 1)

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in FCC CPNI: Basis, Purpose and Definitions (64.2001-64.2003)

Query this from an agent

The graph holds this control, the 62 it maps to, and the evidence behind each claim, over MCP and REST.