Liechtenstein DPA
Security + Breach + Articles 25-31

Liechtenstein DPA LIDPA-Security-Processor-Engagement-Breach-Notification-Articles-25-31-72-Hour-DSS-FMA-Coordination: Liechtenstein DPA Security + Processor + Breach + Articles 25-31 + 72-Hour + FMA

Liechtenstein DSG Articles 25-31 Security + Processor + Breach Notification. Article 25 Security of Processing (Sicherheit der Verarbeitung) - controllers and processors must implement appropriate technical and organisational measures proportionate to risk + state-of-the-art + including encryption (at rest + in transit) + pseudonymisation + access control + RBAC + MFA + logging + monitoring + secure SDLC + vulnerability management + Liechtenstein financial sector ISO 27001 + ISO 27701 + Banking Act information security requirements + FMA Circular on IT and Cyber Risk Management + DLT/Blockchain Act security requirements for Token Service Providers. Article 26 Processor Engagement (Auftragsverarbeiter) - written contract specifying categories + purposes + duration + obligations including process only on documented instructions + confidentiality + security + sub-processor authorisation + Data Subject Rights support + breach notification + return or deletion at termination + audit rights + flow-down. Article 27 Joint Controllership. Articles 28-29 Personal Data Breach Notification (Meldung von Verletzungen des Schutzes personenbezogener Daten) - controller must notify DSS within 72 hours + notify affected data subjects without undue delay where likely high-risk + content (nature + categories + approximate number + likely consequences + measures taken + DPO contact). Article 30 Records of all breaches. Liechtenstein financial sector additional breach reporting to FMA (Financial Market Authority) under Banking Act + Insurance Supervision Act + parallel to DSS notification + cybersecurity sectoral coordination + Liechtenstein Cyber Security Coordination Centre (CSCC) + EU NIS2 Directive transposition pending. Article 31 Incident response coordination with DSS + FMA + Liechtenstein Police + Federal Office for IT Security (Switzerland - BIT/MELANI coordination via Customs Union arrangements).

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 233 controls across 68 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

BSI IT-Grundschutz · 7 controls

  • BSI-03 Multi-factor authentication requirements
  • BSI-04 Remote access controls
  • BSI-05 Wireless access restrictions
  • BSI-08 Cryptographic protection of data
  • BSI-18 Incident response planning and testing
  • BSI-20 Incident reporting and notification
  • BSI-21 Forensic analysis capabilities

ISO/IEC 27043:2015 · 7 controls

  • ISO27043-11 Access control policy and enforcement
  • ISO27043-14 Privileged access management
  • ISO27043-15 Access review and recertification
  • ISO27043-17 Encryption of data at rest
  • ISO27043-18 Encryption of data in transit
  • ISO27043-19 Certificate management
  • ISO27043-20 Key lifecycle management

ISO/SAE 21434 · 7 controls

  • ISO21434-12 User access management and provisioning
  • ISO21434-14 Privileged access management
  • ISO21434-15 Access review and recertification
  • ISO21434-16 Cryptographic policy and key management
  • ISO21434-17 Encryption of data at rest
  • ISO21434-18 Encryption of data in transit
  • ISO21434-19 Certificate management

API 1164 · 6 controls

  • API1164-06 Access Control
  • API1164-07 Remote Access
  • API1164-09 Patch and Vulnerability Management
  • API1164-17 Wireless and Field Communications
  • API1164-18 Field Device Security
  • API1164-19 Safety Instrumented Systems Interface

IEC 62443 · 6 controls

  • IEC62443-07 Personnel risk assessment
  • IEC62443-08 Electronic access perimeter management
  • IEC62443-10 Revocation of access procedures
  • IEC62443-16 Incident response plan for operational disruptions
  • IEC62443-17 Recovery plan for critical systems
  • IEC62443-20 Exercises and drills for OT incidents

ISO/IEC 27019:2024 · 6 controls

  • ISO27019-07 Personnel risk assessment
  • ISO27019-08 Electronic access perimeter management
  • ISO27019-10 Revocation of access procedures
  • ISO27019-16 Incident response plan for operational disruptions
  • ISO27019-18 Reporting obligations to authorities
  • ISO27019-20 Exercises and drills for OT incidents

APPI · 5 controls

  • APPI-A26 Report of Leakage to the Commission and Notification to the Person
  • APPI-A31 Provision of Personally Referable Information
  • APPI-A34 Request for Correction, Addition or Deletion
  • APPI-A41 Preparation and Handling of Pseudonymized Personal Information
  • APPI-A43 Preparation of Anonymized Personal Information

Bahrain PDPL · 5 controls

  • FFIEC-08 Application security controls
  • FFIEC-09 Encryption and key management
  • FFIEC-23 Regulatory reporting requirements
  • FFIEC-24 Customer notification procedures
  • FFIEC-25 Post-incident review and improvement
  • UAE-PDPL-Art.10 Data Protection Officer (DPO) (UAE PDPL Article 10)
  • UAE-PDPL-Art.18_19_20_21 Security measures, controller/processor relationship, DPIA (UAE PDPL Articles 18-21)
  • UAE-PDPL-Art.25_26_27_28_29 UAE Data Office establishment, powers, penalties, complaints (UAE PDPL Articles 25-29)
  • UAE-PDPL-Art.4_5 Lawful basis and principles for processing personal data (UAE PDPL Articles 4-5)
  • UAE-PDPL-Art.6_7 Sensitive personal data and children's data (UAE PDPL Articles 6-7)

ISO 27799:2025 · 5 controls

  • ISO27799-01 ePHI access controls and authorization
  • ISO27799-02 ePHI encryption at rest and in transit
  • ISO27799-08 Information access management
  • ISO27799-16 Transmission security and encryption
  • ISO27799-17 Facility access controls
  • AWWA-2.1 User Access Management
  • AWWA-2.4 Physical Access Controls
  • AWWA-3.2 Remote Access Security
  • AWWA-3.4 Encryption and Data Protection

ISO/IEC 27010:2015 · 4 controls

  • 27010-10.1 Cryptographic Protection
  • 27010-16.1 Continuity of Sharing
  • 27010-9.1 Access Control to Shared Information
  • 27010-9.2 Authentication of Sources
  • PQC-2 FIPS 203 ML-KEM Implementation - Module-Lattice Key-Encapsulation Mechanism
  • PQC-5 Cryptographic Inventory and PQC Migration Roadmap
  • PQC-7 FIPS Validated Modules, HSM Readiness, and Algorithm Validation
  • PQC-8 Implementation Requirements - RNG, Side-Channel, Key Management, Operations, Incident Response

OWASP ASVS · 4 controls

  • DSOMM-1 Culture, Organization, Education, and Governance
  • DSOMM-2 Implementation Practices, Secure Coding, and Threat Modelling
  • DSOMM-3 Build, Deployment, Infrastructure Hardening, and Secrets Management
  • DSOMM-4 Test and Verification - SAST, DAST, IAST, SCA, Penetration Testing

OWASP Top 10:2025 · 4 controls

  • OWASPTOP10-1 A01:2025 Broken Access Control
  • OWASPTOP10-2 A02:2025 Cryptographic Failures and Secret Management
  • OWASPTOP10-4 A04:2025 Insecure Design and Business Logic (incl. A11 API Abuse)
  • OWASPTOP10-9 A09:2025 Security Logging and Monitoring Failures
  • IM8-CLD.2 Cloud Security Controls
  • IM8-DSS.3 Secure Development Practices
  • IM8-RES.3 Incident Response
  • IM8-SEC.2 Access Control

South Korea ISMS-P · 4 controls

  • ISMSP-AC-01 Access Control Policy
  • ISMSP-AC-04 Network Access Control
  • ISMSP-SYS-02 Encryption Implementation
  • ISMSP-SYS-05 Incident Response
  • ASD37-17 TLS encryption between email servers (Limited)
  • ASD37-31 Hunt to discover incidents (Very Good)
  • ASD37-33 Capture network traffic (Limited)
  • IS.AR.215 Information Security Incident Response
  • IS.D.OR.225 External Reporting of Information Security Events
  • IS.I.OR.225 External Reporting
  • CAT-D3-1 Preventative controls
  • CAT-D4-3 Third-party access controls
  • CAT-D5-1 Incident planning and strategy

FedRAMP Rev 5 · 3 controls

  • FEDRAMP-SC-13 Cryptographic Protection
  • FEDRAMP-SC-28 Protection of Information at Rest
  • FEDRAMP-SC-8 Transmission Confidentiality and Integrity

ISO 22320:2018 · 3 controls

  • ISO-22320-5.2 Incident management process
  • ISO-22320-B Annex B: Incident management plan structure
  • ISO-22320-C Annex C: Incident management task examples

ISO/IEC 23837:2023 · 3 controls

  • 23837-1.2 Normative references
  • 23837-1.5.2 Cryptographic module requirements
  • 23837-1.5.3 Network device testing requirements

ISO/IEC 27011:2024 · 3 controls

  • 27011-5.3 Segregation of duties
  • 27011-8.1 User Endpoint Devices
  • 27011-8.3 Cryptography and key management

ISO/IEC 27400:2022 · 3 controls

  • 27400-6.2 Device Identity and Authentication
  • 27400-6.3 Secure Update Mechanism
  • 27400-6.5 Security monitoring and incident response
  • PSPF24-1 Security Culture, Governance, Risk Management
  • PSPF24-2 Information Security, Cybersecurity Maturity, Essential Eight
  • PSPF24-4 Physical Security

South Korea PIPA · 3 controls

  • PIPA-CPO-DPO-Privacy-Officer-PIA-Personal-Information-Impact-Assessment-Articles-31-33 Korea PIPA CPO + DPO + Privacy Officer + PIA + Personal Information Impact Assessment + Articles 31-33
  • PIPA-Cross-Border-Transfer-Articles-28-8-28-9-Adequacy-Standard-Contract-Certification-EU Korea PIPA Cross-Border Transfer + Articles 28-8 + 28-9 + Adequacy + EU 2021
  • PIPA-Sensitive-Information-Unique-ID-Resident-Registration-Numbers-CCTV-Articles-23-24-25 Korea PIPA Sensitive Information + Unique ID + RRN + CCTV + Articles 23-25

APRA CPS 234 · 2 controls

  • CPS234-21 Implementation of Information Security Controls
  • CPS234-25 Internal Audit Review of Information Security Controls
  • DSO-2 Data Security
  • DSO-3 Data Access Management
  • CJIS-8 Media Protection
  • CJIS-9 System and Communications Protection
  • FTC-Safeguards-9-Elements 9 Safeguard Elements - Access, Inventory, Encryption, Secure-Dev, MFA, Disposal, Change-Mgmt, Monitoring, Pen-Test (16 CFR 314.4(c))
  • FTC-Safeguards-IR-Plan-BoardReporting-FTC-Notification Written Incident Response Plan + Board Reporting + FTC Breach Notification (16 CFR 314.4(h), (i), (j))
  • 62351-8 Role-based access control (RBAC)
  • 62351-9 Cyber security key management
  • ISO28001-PC-04 Supply Chain Continuity Planning
  • ISO28001-PS-01 Facility Security

ISO/IEC 20000-1:2018 · 2 controls

  • ISO20000-11 Incident management
  • ISO20000-15 Access management for services

ISO/IEC 30111:2019 · 2 controls

  • 30111-3 Terms and definitions
  • 30111-5.2 Vulnerability handling team

ITIL 4 · 2 controls

  • ITIL4-11 Incident management
  • ITIL4-15 Access management for services
  • OWASPAPI-1 Broken Object Level Authorization (BOLA) and BFLA
  • OWASPAPI-6 Security Misconfiguration and Secure API Design
  • AUPRV-4 APP 10-11 Quality, Security of Personal Information
  • AUPRV-7 Notifiable Data Breaches (NDB) Scheme, Incident Response
  • D.1 Incident Response Planning
  • D.2 Incident Reporting
  • CYB-5 Cyber Incident Response Plan
  • USMTSA-2 Cybersecurity Assessment and CSO Designation
  • CPS230-13 Board Accountability for Operational Risk Management
  • 4.4.7 Emergency and Incident Response
  • BB-DPA-20 Sections 50-60 - Registration and Responsibilities
  • CA-12 Deploys Through Policies and Procedures
  • CA-ITSG33-SC-01 Security Control Catalogue

FIDO2 / WebAuthn · 1 control

  • IATA-IOSA-Section8-SEC-SecurityManagement-AVSEC IATA IOSA Section 8 - SEC Security Management + Aviation Security Programme (AVSEC) + ICAO Annex 17 Alignment
  • ICAO-ANX17-Chap2-ThreatAssessment-RiskManagement-Cyber-GASeP ICAO Annex 17 Chapter 2 - Threat Assessment + Risk Management + Cyber Threats to Critical Aviation Systems (Amendment 17/18)
  • 29115-7.4 Level of Assurance 4 (LoA4)

MITRE D3FEND · 1 control

  • NISTSP34-3 Preventive Controls and Recovery Strategies: Backup, Alternate Sites, Equipment
  • NGCB-6 Incident Response, 72-Hour NGCB Notification, and Independent Investigation
  • PAKPDPB-5 Security of Processing and Personal Data Breach Notification
  • SGCYBER-1 Critical Information Infrastructure (CII) Designation and Registration
  • TEFCAREC-1 Common Agreement Conformance and Onboarding

Turkey KVKK · 1 control

  • TURKEYKVKK-2 Information Notice and Data Subject Rights
  • CPSC-CS.2 Authentication and Access Controls
  • USSDWA-2 Cybersecurity Practices (Assessment, Access, Network, IR)
  • VIETNAMCYBER-2 Prohibited Acts (Access, Interception, Forgery, Content)
  • VPSHR-3 Implementation Guidance and Reporting

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 233 it maps to, and the evidence behind each claim, over MCP and REST.