Frameworks / NIST Privacy Framework / NISTPF-2 NIST Privacy Framework
Govern-P
NIST Privacy Framework NISTPF-2: Govern-P - Governance Policies, Risk Management Strategy, Awareness Training, and Monitoring Apply Govern-P function including: Governance Policies (GV.PO-P) covering policies + responsibilities + roles + legal/regulatory requirements + privacy risk in governance; Risk Management Strategy (GV.RM-P) covering risk tolerance + ecosystem-informed risk; Awareness and Training (GV.AT-P) covering workforce training + role-based + privileged user + third-party awareness; and Monitoring and Review (GV.MT-P) covering programme monitoring + effectiveness review + privacy values incorporated + workforce informed + processes improvements. Integrate with NIST CSF 2.0 GOVERN function.
Maintained by Gerard Blokdyk · Verified against the published standard 31 May 2026 · Control text last updated 21 May 2026 What else in your programme already covers this This control maps to 123 controls across 65 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
27557-1 Scope 27557-3 Terms and definitions 27557-6.4 Privacy risk treatment 27557-6.6 Recording and reporting 27557-7.3 Risk-based privacy program implementation CPS230-16 Internal Audit Review of the Business Continuity Plan CPS230-37 Service Provider Management Policy CPS230-46 Ongoing Risk Management of Each Material Arrangement IS.D.OR.210 Information Security Risk Treatment IS.I.OR.210 Information Security Risk Treatment IS.I.OR.220 Information Security Risk Management FFIEC-03 Risk appetite and tolerance for IT risk FFIEC-18 Ongoing monitoring and assessment FFIEC-20 Exit strategy and transition planning 60601-1.4.1 General requirements 60601-1.4.2 Risk management process 60601-1.5.1 General requirements for testing IEC62304-4.1 Quality Management System IEC62304-5.1 Software Development Planning IEC62304-7.4 Risk Management of Software Changes ISO23894-5.1 Leadership and Commitment ISO23894-5.2 AI Risk Management Integration ISO23894-5.5 Framework Evaluation JP-AIG-Continuous-Monitoring-Lifecycle-Model-Evaluation-Performance-Drift-Post-Deployment Japan AI Guidelines Continuous Monitoring + AI System Lifecycle Management + Model Evaluation + Performance Drift + Concept Drift + Post-Deployment + Retraining Triggers + Safe Update + Decommissioning + Model Card Versioning JP-AIG-Fairness-Bias-Detection-Mitigation-Inclusive-AI-Discrimination-Prevention-10-Principles-2019-Heritage Japan AI Guidelines Fairness + Bias Detection + Mitigation + Inclusive AI + Discrimination Prevention + 10 Principles 2019 Heritage + Protected Attributes + Disparate Impact + Statistical Parity + Counterfactual Fairness JP-AIG-Safety-Validation-Testing-Robustness-AISI-AI-Safety-Institute-Pre-Deployment-Evaluation-Red-Teaming Japan AI Guidelines Safety + Validation + Testing + Robustness + AISI AI Safety Institute (14 Feb 2024) + Pre-Deployment Evaluation + Red Teaming + Capability Evaluations + AI Incident Database + Safe Deployment + AI Safety Reports NIST-CSF-GV.RM-03 Cybersecurity risk management activities and outcomes are included in enterprise risk management processes NIST-CSF-GV.RM-04 Strategic direction that describes appropriate risk response options is established and communicated NIST-CSF-GV.SC-01 A cybersecurity supply chain risk management program, strategy, objectives, policies, and processes are established and agreed to by organizational stakeholders NISTSP30-1 Risk Management Strategy and Risk Assessment Programme Establishment NISTSP30-2 Three-Tier Risk Assessment Scoping (Organisation, Mission/Business, Information System) NISTSP30-8 Risk Assessment Maintenance, Continuous Monitoring, and Integration with the RMF PCI-P2PE-16 Due diligence and onboarding PCI-P2PE-18 Ongoing monitoring and assessment PCI-P2PE-19 Concentration risk management PCI-PIN-16 Due diligence and onboarding PCI-PIN-18 Ongoing monitoring and assessment PCI-PIN-19 Concentration risk management PCI-SSF-03 Risk appetite and tolerance for IT risk PCI-SSF-16 Due diligence and onboarding PCI-SSF-17 Contractual security requirements CPS234-16 Assessment of Related Party and Third Party Capability CPS234-20 Information Asset Classification BS65000-RM-01 Resilience Journey BS65000-RM-02 Integrated Approach CAT-D1-2 Risk management CAT-ML-2 Evolving ICP-16 Enterprise Risk Management for Solvency Purposes ICP-8 Risk Management and Internal Controls ICAO-ANX17-Chap2-ThreatAssessment-RiskManagement-Cyber-GASeP ICAO Annex 17 Chapter 2 - Threat Assessment + Risk Management + Cyber Threats to Critical Aviation Systems (Amendment 17/18) ICAO-ANX17-Chap4-Cargo-Mail-Catering-Stores-Supplies-RegulatedAgent-KnownConsignor ICAO Annex 17 Chapter 4 - Cargo + Mail + Catering + Stores + Supplies Security + Regulated Agent + Known Consignor + Supply Chain IEEE7000-EthicalRisk-Identification-Analysis-Treatment-ValidationOutcomes IEEE 7000 Clauses 8 + 8.1 + 8.2 - Ethical Risk Identification + Analysis + Treatment + Validation of Ethical Outcomes + AI Safety + Robustness + Adversarial Protection IEEE7000-Values-Elicitation-Prioritisation-IEEE7000Family-Bias-Privacy-Transparency IEEE 7000 Clauses 6 + 6.1 - Ethical Values Elicitation + Prioritisation + IEEE 7000 Family Integration (Bias + Privacy + Transparency + Wellbeing) ISO27003-6.1 Actions to address risks and opportunities ISO27003-8.3 Information security risk treatment NISTSP37-1 RMF Prepare Step: Organisation-Level and System-Level Preparation NISTSP37-7 RMF Monitor Step: Continuous Monitoring and Ongoing Authorisation NISTSP39-4 Risk Responding: Identify, Evaluate, Decide, Implement NISTSP39-5 Risk Monitoring: Effectiveness, Changes, Compliance, and Reassessment Triggers NRFCS-1 Retail Cybersecurity Governance, Policy, and Regulatory Change Management NRFCS-2 Risk Assessment, Customer Data Inventory, Classification, and Retail Threat Model OCCHS-3 Risk Appetite Statement, Risk Limits, Concentration Risk, and Limit Breach Protocols OCCHS-7 Risk Data Aggregation, Reporting, Talent, Compensation, and Strategic Planning OECDAI-3 Robustness, Security, Safety, and Adversarial Attack Protection OECDAI-5 Data Governance, Training Data Quality, Privacy, and Bias Mitigation OSFIB13-1 Governance, Risk Management, and Three Lines of Defense OSFIB13-4 Third-Party Risk Management and Cloud AMLCTF-82 Part A Compliance API1164-21 TSA Pipeline Security Directive Alignment AS9100D-8.1 Operational Planning and Control P1-S2 Risk-Management Systems CJIS-19 Supply Chain Risk Management HKMA-SPM-OR-RR-SA-OperationalResilience HKMA SPM Operational Risk (OR-1), Operational Resilience (OR-2), Recovery Planning (RR-1), Outsourcing (SA-2) ICMM-MP-P3-P4-HumanRights-RiskMgmt-UNGP-DueDiligence ICMM Mining Principles 3 + 4 - Human Rights (UNGPs Alignment) + Risk Management + Due Diligence IEC62443-21 Supply chain risk management for critical components IEEE1686-SupplyChain-Documentation-Procurement-ComplianceTable-Physical IEEE 1686 Section 6 IED Security Documentation + Supply Chain + Procurement Specification + Appendix A Compliance Table + Physical and Tamper IMO-MSC-FAL-Identify-AssetInventory-ThreatsVulnerabilities-CyberRiskAssessment-RolesResponsibilities IMO MSC-FAL Identify Function - OT/IT Asset Inventory + Threats + Vulnerabilities + Cyber Risk Assessment + Roles and Responsibilities + Crew + CSO + DPA IRM-Process-Identification-Analysis-Evaluation-Treatment-Monitoring-Review-ISO31000-Aligned IRM Risk Management Process - 5-Stage Cycle + Identification + Analysis (Inherent/Residual) + Evaluation + Treatment (4Ts Tolerate/Treat/Transfer/Terminate) + Monitoring + Review + Communication + Risk Register ISO-15189-5.6 Risk management ISO-20400-4.5 Key considerations for sustainable procurement ISO-22320-4.3 Risk-based approach ISO28001-SA-04 Security Risk Treatment Planning ISO27019-21 Supply chain risk management for critical components LLOYDS-CI-Risk-Selection-Cyber-Hygiene-Underwriting-Criteria-Pre-Bind-Risk-Engineering-MFA-Backup-EDR Lloyds Cyber Insurance Risk Selection + Hygiene + Pre-Bind Engineering MTCS-Governance-ISMS-Risk-HR-Lifecycle-Compliance-Cloud-Strategy-Roles-Responsibilities MTCS Governance + ISMS + Risk Management + HR Security + Cloud Service Lifecycle + Compliance + Roles MAS-TRM-Third-Party-IT-Audit-Chapters-14-15-Outsourcing-Notice-658-Concentration-Risk-Exit-Strategy MAS TRM Third Party + IT Audit + Chapters 14-15 + Outsourcing + Notice 658 + Concentration Risk + Exit Strategy NERCCIP-8 Supply Chain Risk Management (CIP-013) NISTSP82-1 OT Security Program Governance, Policy, Roles, and Safety-Security Integration NZISM-1 NZISM Governance, Documentation, and Classification System ORANWG11-1 O-RAN Threat Model, Risk Management, and Security Architecture OECDAI24-3 Frontier Model Risk Management, Capability Disclosure, and Independent Evaluation OPENBANK-4 Third Party Provider (TPP) Onboarding, Directory Integration, Due Diligence ORSA-S1 Guidance Manual Section 1: Description of the insurer's risk management framework PSPF24-1 Security Culture, Governance, Risk Management AIGF-1.1 Risk Management and Internal Controls IM8-TPM.4 Supply Chain Risk Management ISMSP-MS-02 Risk Management CRM-3 Risk Management Framework Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Query this from an agent The graph holds this control, the 123 it maps to, and the evidence behind each claim, over MCP and REST.