Frameworks / ISO 22320:2018 / ISO-22320-B What else in your programme already covers this This control maps to 221 controls across 112 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
NDPA-1 Applicability, Scope, and Carve-Outs NDPA-2 Consumer Rights - Access, Correct, Delete, Portability, Appeal NDPA-5 Privacy Notice, Data Minimisation, and Purpose Limitation NDPA-6 Reasonable Security Practices and Incident Response NG-NDPA-1 Scope, Applicability, and Establishment of Nigeria Data Protection Commission NG-NDPA-2 Lawful Basis, Consent, and Data Protection Principles NG-NDPA-5 Security of Processing, Breach Notification, and DPIA NG-NDPA-6 Data Protection Officer, DPCO, and Processor Agreements BSI-18 Incident response planning and testing BSI-20 Incident reporting and notification BSI-21 Forensic analysis capabilities FFIEC-23 Regulatory reporting requirements FFIEC-24 Customer notification procedures FFIEC-25 Post-incident review and improvement NIST-CSF-ID.IM-04 Incident response plans and other cybersecurity plans that affect operations are established, communicated, maintained, and improved NIST-CSF-RC.RP-01 The recovery portion of the incident response plan is executed once initiated from the incident response process NIST-CSF-RS.MA-01 The incident response plan is executed in coordination with relevant third parties once an incident is declared OSFIB13-3 Cyber Security: Identification, Protection, Detection, Response, Recovery OSFIB13-7 Incident Reporting to OSFI and Regulatory Coordination OSFIB13-8 Metrics, Monitoring, Continuous Improvement, Maturity APPI-A41 Preparation and Handling of Pseudonymized Personal Information APPI-A43 Preparation of Anonymized Personal Information CPS234-21 Implementation of Information Security Controls CPS234-25 Internal Audit Review of Information Security Controls ASD37-31 Hunt to discover incidents (Very Good) ASD37-33 Capture network traffic (Limited) 3.6 Encrypt Data on End-User Devices 3.6.1 Procedures are defined and implemented to protect cryptographic keys used to protect stored account data against disclosure and misuse that include: • Access to keys is restricted to the fewest number of custodians necessary. NJDPA-2 Consumer Rights - Access, Correct, Delete, Portability, Appeal NJDPA-6 Reasonable Data Security and Incident Response OPENBANK-7 Logging, Monitoring, Regulatory Reporting, SLA, Availability OPENBANK-8 Incident Detection, Response, Customer Notification, Post-Incident Review, BCM PSDTWO-3 Common and Secure Communication, API Access for AISPs and PISPs PSDTWO-4 Fraud Reporting and Incident Management PERU-7 DPO, Records, Retention, Marketing, Training PERU-8 Breach Notification, ANPD Cooperation, Sanctions, Compliance QATAR-5 Security of Processing QATAR-8 Breach Notification, Compliance, Enforcement SOC2-CC7.4 Responds to identified security incidents through defined procedures SOC2-CC7.5 Identifies the root cause of security incidents D.1 Incident Response Planning D.2 Incident Reporting PMF-M.4 Privacy Incident Management CPS230-13 Board Accountability for Operational Risk Management 4.4.7 Emergency and Incident Response BB-DPA-20 Sections 50-60 - Registration and Responsibilities CA-12 Deploys Through Policies and Procedures 27400-6.5 Security monitoring and incident response NERCCIP-6 Incident Reporting and Response Planning + Recovery Plans (CIP-008 + CIP-009) NIS2I-3 Incident Handling Policy, Reporting Significance Criteria, and Business Continuity NISTSP144-8 Monitoring, Incident Response, Exit Strategy, and Compliance NISTSP145-8 Governance, Reporting, and Stakeholder Education on Cloud Definition 3.6.1 Procedures are defined and implemented to protect cryptographic keys used to protect stored account data against disclosure and misuse that include: • Access to keys is restricted to the fewest number of custodians necessary. NISTSP82-7 OT Incident Response, Forensics, Recovery, and Continuity NRFCS-7 Detection, Logging, Incident Response, Breach Notification, and Fraud Detection NGCB-6 Incident Response, 72-Hour NGCB Notification, and Independent Investigation NHPA-6 Reasonable Data Security and Breach Response NGNDPR-5 Security of Personal Data, Breach Notification, and DPIA under NDPR Section 2.6-Security NGOB-5 Fraud Monitoring, Incident Notification, and Reporting to CBN OMANCS-6 Security Monitoring, Detection, Incident Response, and OmanCERT Notification OREGONCPA-3 Consent, Sensitive Data, Children and Teen Protections PASONE-6 Incident Management, Audit, Handover, Operational Phase, Decommissioning PDPASG-8 Data Breach Notification, Incident Response, and Enforcement PDPATH-8 Data Breach Notification, Complaints, Compliance, Enforcement POPIASA-5 Security Safeguards, Encryption, Access Control, Operator Obligations PNGCYBER-4 Incident Response, Investigation, Evidence Preservation, Data Retention NORWAY-8 Breach Notification, Complaints, Compliance, Enforcement NZPRV-7 Notifiable Privacy Breach Scheme TSAPIPE-2 OT/IT Network Segmentation and Access Control CYB-5 Cyber Incident Response Plan Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Other controls in Annexes: Guidance on Incident Management Planning Query this from an agent The graph holds this control, the 221 it maps to, and the evidence behind each claim, over MCP and REST.