NIST Privacy Framework
Protect-P Access

NIST Privacy Framework NISTPF-5: Protect-P Access Control (PR.AC-P)

Apply Protect-P Identity Management Authentication and Access Control (PR.AC-P) including: identity proofing + lifecycle management + credentials issued + revoked + physical access managed + remote access managed + access permissions managed (least privilege + separation of duties) + network integrity protected + individuals and devices proofed and authenticated to manage privacy risks. Implement MFA + zero trust architecture + RBAC + ABAC + PAM + JIT access aligned with NIST SP 800-63 + 800-207.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 262 controls across 103 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

NIST SP 800-53 Rev 5 · 12 controls

  • AWWA-1.3 Security Awareness and Training
  • AWWA-2.1 User Access Management
  • AWWA-2.2 Authentication Mechanisms
  • AWWA-2.3 Account Management
  • AWWA-2.4 Physical Access Controls
  • AWWA-3.1 Network Segmentation

ISO/IEC 27011:2024 · 6 controls

  • 27011-5.3 Segregation of duties
  • 27011-6.3 Awareness and Training
  • 27011-7.1 Physical security perimeters
  • 27011-7.3 Equipment protection
  • 27011-8.1 User Endpoint Devices
  • 27011-8.2 Network security and segregation

ISO/IEC 27043:2015 · 6 controls

  • ISO27043-11 Access control policy and enforcement
  • ISO27043-12 User access management and provisioning
  • ISO27043-13 Authentication and password management
  • ISO27043-14 Privileged access management
  • ISO27043-15 Access review and recertification
  • ISO27043-27 Network security management
  • ASD37-18 Restrict administrative privileges (Essential)
  • ASD37-20 Multi-factor authentication (Essential)
  • ASD37-22 Network segmentation (Excellent)
  • ASD37-23 Protect authentication credentials (Excellent)
  • ASD37-25 Software firewall - inbound (Very Good)

BSI IT-Grundschutz · 5 controls

  • BSI-01 Account management and provisioning
  • BSI-02 Access enforcement and least privilege
  • BSI-03 Multi-factor authentication requirements
  • BSI-04 Remote access controls
  • BSI-05 Wireless access restrictions
  • CPG-1.A Changing Default Passwords
  • CPG-1.C Unique Credentials
  • CPG-1.D Revoking Credentials for Departing Employees
  • CPG-4.C Basic Cybersecurity Training
  • CPG-8.A Network Segmentation

ISO/SAE 21434 · 5 controls

  • ISO21434-12 User access management and provisioning
  • ISO21434-13 Authentication and password management
  • ISO21434-14 Privileged access management
  • ISO21434-15 Access review and recertification
  • ISO21434-27 Network security management

API 1164 · 4 controls

  • API1164-06 Access Control
  • API1164-07 Remote Access
  • API1164-09 Patch and Vulnerability Management
  • API1164-13 Business Continuity and Recovery

IEC 62443 · 4 controls

  • IEC62443-07 Personnel risk assessment
  • IEC62443-08 Electronic access perimeter management
  • IEC62443-10 Revocation of access procedures
  • IEC62443-13 Network security monitoring

ISO 27799:2025 · 4 controls

  • ISO27799-01 ePHI access controls and authorization
  • ISO27799-08 Information access management
  • ISO27799-12 Unique user identification and authentication
  • ISO27799-17 Facility access controls

ISO/IEC 27010:2015 · 4 controls

  • 27010-11.1 Physical Protection
  • 27010-13.1 Communications Security
  • 27010-9.1 Access Control to Shared Information
  • 27010-9.2 Authentication of Sources

ISO/IEC 27019:2024 · 4 controls

  • ISO27019-07 Personnel risk assessment
  • ISO27019-08 Electronic access perimeter management
  • ISO27019-10 Revocation of access procedures
  • ISO27019-13 Network security monitoring
  • NIST-CSF-PR.AA-01 Identities and credentials for authorized users, services, and hardware are managed by the organization
  • NIST-CSF-PR.AA-02 Identities are proofed and bound to credentials based on the context of interactions
  • NIST-CSF-PR.AA-05 Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties
  • NIST-CSF-PR.AA-06 Physical access to assets is managed, monitored, and enforced commensurate with risk

NIST SP 1800-32 · 4 controls

NIST SP 800-190 · 4 controls

  • OWASPLLM-1 Prompt Injection and System Prompt Leakage (LLM01 + LLM07)
  • OWASPLLM-2 Improper Output Handling and Misinformation (LLM05 + LLM09)
  • OWASPLLM-3 Sensitive Information Disclosure and Privacy (LLM02)
  • OWASPLLM-6 Excessive Agency and Unbounded Consumption (LLM06 + LLM10)

OWASP Top 10:2025 · 4 controls

South Korea ISMS-P · 4 controls

  • ISMSP-AC-01 Access Control Policy
  • ISMSP-AC-02 User Account Management
  • ISMSP-AC-03 Authentication Mechanisms
  • ISMSP-AC-04 Network Access Control
  • CAT-D3-1 Preventative controls
  • CAT-D4-3 Third-party access controls
  • CAT-IRP-4 Organizational characteristics
  • 29115-11 Mapping other authentication schemes
  • 29115-12.1 Exchanging authentication results
  • 29115-12.2 Controls for mitigating threats

NIST SP 800-63-4 · 3 controls

  • NISTSP63R4-3 Authentication: Authenticator Types, MFA, Phishing-Resistance, and Syncable Authenticators
  • NISTSP63R4-4 Authenticator Lifecycle: Binding, Recovery, Replacement, Suspension, Revocation
  • NISTSP63R4-5 Federation: Assertions, Trust Agreements, RP Validation, Pseudonymous Identifiers

NIST SP 800-66 · 3 controls

  • NISTSP66-2 Workforce Security, Information Access Management, and Awareness Training
  • NISTSP66-5 Physical Safeguards: Facility Access, Workstation Use and Security, Device and Media Controls
  • NISTSP66-6 Technical Safeguards: Access Control, Audit Controls, Integrity, Person Authentication
  • OWASPAPI-1 Broken Object Level Authorization (BOLA) and BFLA
  • OWASPAPI-2 Broken Authentication and Token Management
  • OWASPAPI-3 Broken Object Property Level Authorization (BOPLA)

OWASP ASVS · 3 controls

  • DSOMM-1 Culture, Organization, Education, and Governance
  • DSOMM-3 Build, Deployment, Infrastructure Hardening, and Secrets Management
  • DSOMM-4 Test and Verification - SAST, DAST, IAST, SCA, Penetration Testing
  • OB-CX.3 Strong Customer Authentication
  • OB-DIR.1 Open Banking Directory
  • OB-SEC.4 Certificate Management
  • DSO-2 Data Security
  • DSO-3 Data Access Management
  • FDBR-Scope-Defs Scope, Applicability Thresholds and Definitions (Fla. Stat. 501.701, 501.702, 501.703, 501.704)
  • FDBR-SensitiveData-Children-VoiceFacial Sensitive Data, Children's Privacy and Voice/Facial Recognition (Fla. Stat. 501.711, 501.1735)

ISO/IEC 27400:2022 · 2 controls

  • 27400-5.2 IoT Risk Assessment
  • 27400-6.1 Secure Device Design
  • BIPA-SEC5-1 Biometric Identifier Definition
  • BIPA-SEC5-2 Biometric Information Definition

NIST SP 800-123 · 2 controls

  • NISTSP123-3 Authentication, Access Control, and Account Management
  • NISTSP123-6 Network Security and Server Communications

NIST SP 800-144 · 2 controls

  • NISTSP144-1 Cloud Governance, Risk Assessment, and Provider Trust Evaluation
  • NISTSP144-2 Cloud Architecture, Service Selection, and Tenant Isolation

NIST SP 800-145 · 2 controls

  • NISTSP145-6 Deployment Model Classification (Private, Community, Public, Hybrid)
  • NISTSP145-8 Governance, Reporting, and Stakeholder Education on Cloud Definition

NIST SP 800-146 · 2 controls

  • NISTSP146-4 IaaS Operational Recommendations and Workload Hardening
  • NISTSP146-6 Cloud Security and Privacy Recommendations

NIST SP 800-61 Rev. 3 · 2 controls

  • NISTSP61-4 Detection and Analysis: Sources, Triage, Categorisation, Prioritisation
  • NISTSP61-5 Containment, Eradication, and Recovery
  • NISTSP82-2 OT Risk Assessment and Threat/Vulnerability Identification
  • NISTSP82-4 OT Access Control, Identity, Authentication, and Remote Access

NIST SP 800-88 · 2 controls

  • NISTSP88-1 Media Sanitization Policy, Roles, and Decision Framework
  • NISTSP88-8 Cloud-Resident Data, Hosted Storage, and Scope Boundaries

NIST SP 800-92 · 2 controls

  • NISTSP92-3 Log Infrastructure: Architecture, Centralisation, Transport Security, SIEM Governance
  • NISTSP92-4 Log Management: Time Synchronisation, Parsing, Storage, Integrity, Access Control
  • ORANWG11-2 O-RAN Interface Security: E2, A1, O1, O2, Open Fronthaul
  • ORANWG11-3 Cryptography, TLS, SSH, IPsec, and PKI Lifecycle Management

OWASP MASVS · 2 controls

  • OMANCS-3 Identity and Access Management, Authentication, Privileged Access
  • OMANCS-5 Network, Endpoint, System Development, and Configuration Security
  • PSPF24-2 Information Security, Cybersecurity Maturity, Essential Eight
  • PSPF24-4 Physical Security
  • IM8-SEC.2 Access Control
  • IM8-SEC.3 Network Security
  • CPSC-CS.1 Network Security for Connected Products
  • CPSC-CS.2 Authentication and Access Controls
  • CYB-2 Account Security Measures
  • USMTSA-1 Facility Security Assessment and Plan
  • 58.43 Animal Care Facilities
  • AMLCTF-35 Identity Verification Standard

APPI · 1 control

  • APPI-A26 Report of Leakage to the Commission and Notification to the Person
  • AT-DSG-6 Sections 12-13 - Image processing (video surveillance/CCTV)

Bahrain PDPL · 1 control

  • CA-ITSG33-SC-01 Security Control Catalogue
  • CJIS-14 Physical Protection
  • FFIEC-06 Network security and segmentation

FIDO2 / WebAuthn · 1 control

  • FTC-Safeguards-9-Elements 9 Safeguard Elements - Access, Inventory, Encryption, Secure-Dev, MFA, Disposal, Change-Mgmt, Monitoring, Pen-Test (16 CFR 314.4(c))
  • UAE-PDPL-Art.6_7 Sensitive personal data and children's data (UAE PDPL Articles 6-7)
  • IATA-IOSA-Section8-SEC-SecurityManagement-AVSEC IATA IOSA Section 8 - SEC Security Management + Aviation Security Programme (AVSEC) + ICAO Annex 17 Alignment
  • ICAO-ANX17-Chap2-ThreatAssessment-RiskManagement-Cyber-GASeP ICAO Annex 17 Chapter 2 - Threat Assessment + Risk Management + Cyber Threats to Critical Aviation Systems (Amendment 17/18)
  • 62351-8 Role-based access control (RBAC)
  • ISO28001-PS-01 Facility Security
  • ISO20000-15 Access management for services

ISO/IEC 23837:2023 · 1 control

  • 23837-1.7.3 Authentication and classical post-processing

ITIL 4 · 1 control

  • ITIL4-15 Access management for services
  • NISTSP115-8 Operational Considerations - Tools, Reporting Templates, ISMS Integration, Annex Material

NIST SP 800-122 · 1 control

  • NISTSP122-5 PII Security Controls - Encryption, Access Control, Storage, Audit

NIST SP 800-137 · 1 control

  • NISTSP137-6 Malware, Identity Access, and Network Boundary Monitoring

OSFI B-13 · 1 control

  • OSFIB13-3 Cyber Security: Identification, Protection, Detection, Response, Recovery
  • OPENBANK-3 Mutual TLS, Token Binding, Request Signing (JWS), Key Management

OpenSSF Scorecard · 1 control

  • OSSFSC-3 Build, CI/CD Security, Workflow Permissions, Dangerous Patterns
  • OREGONCPA-5 Data Protection Assessments, Privacy by Design, Security Practices
  • PASONE-4 Technical Security: CDE Configuration, BIM Tools, Encryption, Aggregation, Mobile Working

PCI P2PE · 1 control

  • PCI-P2PE-06 Network security and segmentation

PCI PIN Security · 1 control

  • PCI-PIN-06 Network security and segmentation

PCI SSF · 1 control

  • PCI-SSF-06 Network security and segmentation

PDPA Singapore · 1 control

  • PDPASG-5 Protection, Accuracy, and Security of Personal Data

PDPA Thailand · 1 control

  • PDPATH-5 Security Measures and Data Protection

POPIA · 1 control

  • POPIASA-5 Security Safeguards, Encryption, Access Control, Operator Obligations
  • NORWAY-5 Security of Processing, Encryption, Pseudonymization, Access Control

Peru DPL · 1 control

  • PERU-7 DPO, Records, Retention, Marketing, Training
  • AUPRV-4 APP 10-11 Quality, Security of Personal Information

Privacy Act 2020 · 1 control

  • NZPRV-2 IPP 5 Storage and Security of Personal Information
  • EHDSREG-6 Phased Application and Enforcement
  • RUSPD-2 Lawful Basis, Consent, Notice

SWIFT CSCF · 1 control

South Korea PIPA · 1 control

  • PIPA-Cross-Border-Transfer-Articles-28-8-28-9-Adequacy-Standard-Contract-Certification-EU Korea PIPA Cross-Border Transfer + Articles 28-8 + 28-9 + Adequacy + EU 2021
  • TEFCAREC-1 Common Agreement Conformance and Onboarding

Turkey KVKK · 1 control

  • TURKEYKVKK-2 Information Notice and Data Subject Rights
  • ACE-CR-4 Cargo Release Authorization
  • USSDWA-2 Cybersecurity Practices (Assessment, Access, Network, IR)
  • USMCADIGITAL-2 Personal Information Protection and Consumer Protection
  • VERMONTAICDA-3 Bias Testing, Discrimination Prevention, Transparency

Vietnam PDPD · 1 control

  • VIETNAMPDP-2 Consent and Notice

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 262 it maps to, and the evidence behind each claim, over MCP and REST.