Frameworks / NIST Privacy Framework / NISTPF-5 NIST Privacy Framework
Protect-P Access
NIST Privacy Framework NISTPF-5: Protect-P Access Control (PR.AC-P) Apply Protect-P Identity Management Authentication and Access Control (PR.AC-P) including: identity proofing + lifecycle management + credentials issued + revoked + physical access managed + remote access managed + access permissions managed (least privilege + separation of duties) + network integrity protected + individuals and devices proofed and authenticated to manage privacy risks. Implement MFA + zero trust architecture + RBAC + ABAC + PAM + JIT access aligned with NIST SP 800-63 + 800-207.
Maintained by Gerard Blokdyk · Verified against the published standard 31 May 2026 · Control text last updated 21 May 2026 What else in your programme already covers this This control maps to 262 controls across 103 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
AWWA-1.3 Security Awareness and Training AWWA-2.1 User Access Management AWWA-2.2 Authentication Mechanisms AWWA-2.3 Account Management AWWA-2.4 Physical Access Controls AWWA-3.1 Network Segmentation 27011-5.3 Segregation of duties 27011-6.3 Awareness and Training 27011-7.1 Physical security perimeters 27011-7.3 Equipment protection 27011-8.1 User Endpoint Devices 27011-8.2 Network security and segregation ISO27043-11 Access control policy and enforcement ISO27043-12 User access management and provisioning ISO27043-13 Authentication and password management ISO27043-14 Privileged access management ISO27043-15 Access review and recertification ISO27043-27 Network security management ASD37-18 Restrict administrative privileges (Essential) ASD37-20 Multi-factor authentication (Essential) ASD37-22 Network segmentation (Excellent) ASD37-23 Protect authentication credentials (Excellent) ASD37-25 Software firewall - inbound (Very Good) BSI-01 Account management and provisioning BSI-02 Access enforcement and least privilege BSI-03 Multi-factor authentication requirements BSI-04 Remote access controls BSI-05 Wireless access restrictions CPG-1.A Changing Default Passwords CPG-1.C Unique Credentials CPG-1.D Revoking Credentials for Departing Employees CPG-4.C Basic Cybersecurity Training CPG-8.A Network Segmentation ISO21434-12 User access management and provisioning ISO21434-13 Authentication and password management ISO21434-14 Privileged access management ISO21434-15 Access review and recertification ISO21434-27 Network security management API1164-06 Access Control API1164-07 Remote Access API1164-09 Patch and Vulnerability Management API1164-13 Business Continuity and Recovery IEC62443-07 Personnel risk assessment IEC62443-08 Electronic access perimeter management IEC62443-10 Revocation of access procedures IEC62443-13 Network security monitoring ISO27799-01 ePHI access controls and authorization ISO27799-08 Information access management ISO27799-12 Unique user identification and authentication ISO27799-17 Facility access controls 27010-11.1 Physical Protection 27010-13.1 Communications Security 27010-9.1 Access Control to Shared Information 27010-9.2 Authentication of Sources ISO27019-07 Personnel risk assessment ISO27019-08 Electronic access perimeter management ISO27019-10 Revocation of access procedures ISO27019-13 Network security monitoring NIST-CSF-PR.AA-01 Identities and credentials for authorized users, services, and hardware are managed by the organization NIST-CSF-PR.AA-02 Identities are proofed and bound to credentials based on the context of interactions NIST-CSF-PR.AA-05 Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties NIST-CSF-PR.AA-06 Physical access to assets is managed, monitored, and enforced commensurate with risk OWASPLLM-1 Prompt Injection and System Prompt Leakage (LLM01 + LLM07) OWASPLLM-2 Improper Output Handling and Misinformation (LLM05 + LLM09) OWASPLLM-3 Sensitive Information Disclosure and Privacy (LLM02) OWASPLLM-6 Excessive Agency and Unbounded Consumption (LLM06 + LLM10) ISMSP-AC-01 Access Control Policy ISMSP-AC-02 User Account Management ISMSP-AC-03 Authentication Mechanisms ISMSP-AC-04 Network Access Control CAT-D3-1 Preventative controls CAT-D4-3 Third-party access controls CAT-IRP-4 Organizational characteristics 29115-11 Mapping other authentication schemes 29115-12.1 Exchanging authentication results 29115-12.2 Controls for mitigating threats NISTSP63R4-3 Authentication: Authenticator Types, MFA, Phishing-Resistance, and Syncable Authenticators NISTSP63R4-4 Authenticator Lifecycle: Binding, Recovery, Replacement, Suspension, Revocation NISTSP63R4-5 Federation: Assertions, Trust Agreements, RP Validation, Pseudonymous Identifiers NISTSP66-2 Workforce Security, Information Access Management, and Awareness Training NISTSP66-5 Physical Safeguards: Facility Access, Workstation Use and Security, Device and Media Controls NISTSP66-6 Technical Safeguards: Access Control, Audit Controls, Integrity, Person Authentication OWASPAPI-1 Broken Object Level Authorization (BOLA) and BFLA OWASPAPI-2 Broken Authentication and Token Management OWASPAPI-3 Broken Object Property Level Authorization (BOPLA) DSOMM-1 Culture, Organization, Education, and Governance DSOMM-3 Build, Deployment, Infrastructure Hardening, and Secrets Management DSOMM-4 Test and Verification - SAST, DAST, IAST, SCA, Penetration Testing OB-CX.3 Strong Customer Authentication OB-DIR.1 Open Banking Directory OB-SEC.4 Certificate Management DSO-2 Data Security DSO-3 Data Access Management FDBR-Scope-Defs Scope, Applicability Thresholds and Definitions (Fla. Stat. 501.701, 501.702, 501.703, 501.704) FDBR-SensitiveData-Children-VoiceFacial Sensitive Data, Children's Privacy and Voice/Facial Recognition (Fla. Stat. 501.711, 501.1735) 27400-5.2 IoT Risk Assessment 27400-6.1 Secure Device Design BIPA-SEC5-1 Biometric Identifier Definition BIPA-SEC5-2 Biometric Information Definition NISTSP123-3 Authentication, Access Control, and Account Management NISTSP123-6 Network Security and Server Communications NISTSP144-1 Cloud Governance, Risk Assessment, and Provider Trust Evaluation NISTSP144-2 Cloud Architecture, Service Selection, and Tenant Isolation NISTSP145-6 Deployment Model Classification (Private, Community, Public, Hybrid) NISTSP145-8 Governance, Reporting, and Stakeholder Education on Cloud Definition NISTSP146-4 IaaS Operational Recommendations and Workload Hardening NISTSP146-6 Cloud Security and Privacy Recommendations NISTSP61-4 Detection and Analysis: Sources, Triage, Categorisation, Prioritisation NISTSP61-5 Containment, Eradication, and Recovery NISTSP82-2 OT Risk Assessment and Threat/Vulnerability Identification NISTSP82-4 OT Access Control, Identity, Authentication, and Remote Access NISTSP88-1 Media Sanitization Policy, Roles, and Decision Framework NISTSP88-8 Cloud-Resident Data, Hosted Storage, and Scope Boundaries NISTSP92-3 Log Infrastructure: Architecture, Centralisation, Transport Security, SIEM Governance NISTSP92-4 Log Management: Time Synchronisation, Parsing, Storage, Integrity, Access Control ORANWG11-2 O-RAN Interface Security: E2, A1, O1, O2, Open Fronthaul ORANWG11-3 Cryptography, TLS, SSH, IPsec, and PKI Lifecycle Management OMANCS-3 Identity and Access Management, Authentication, Privileged Access OMANCS-5 Network, Endpoint, System Development, and Configuration Security PSPF24-2 Information Security, Cybersecurity Maturity, Essential Eight PSPF24-4 Physical Security IM8-SEC.2 Access Control IM8-SEC.3 Network Security CPSC-CS.1 Network Security for Connected Products CPSC-CS.2 Authentication and Access Controls CYB-2 Account Security Measures USMTSA-1 Facility Security Assessment and Plan 58.43 Animal Care Facilities AMLCTF-35 Identity Verification Standard APPI-A26 Report of Leakage to the Commission and Notification to the Person AT-DSG-6 Sections 12-13 - Image processing (video surveillance/CCTV) CA-ITSG33-SC-01 Security Control Catalogue CJIS-14 Physical Protection FFIEC-06 Network security and segmentation FTC-Safeguards-9-Elements 9 Safeguard Elements - Access, Inventory, Encryption, Secure-Dev, MFA, Disposal, Change-Mgmt, Monitoring, Pen-Test (16 CFR 314.4(c)) UAE-PDPL-Art.6_7 Sensitive personal data and children's data (UAE PDPL Articles 6-7) IATA-IOSA-Section8-SEC-SecurityManagement-AVSEC IATA IOSA Section 8 - SEC Security Management + Aviation Security Programme (AVSEC) + ICAO Annex 17 Alignment ICAO-ANX17-Chap2-ThreatAssessment-RiskManagement-Cyber-GASeP ICAO Annex 17 Chapter 2 - Threat Assessment + Risk Management + Cyber Threats to Critical Aviation Systems (Amendment 17/18) 62351-8 Role-based access control (RBAC) ISO-19650-2-5.7 Information model delivery ISO28001-PS-01 Facility Security ISO20000-15 Access management for services 23837-1.7.3 Authentication and classical post-processing ITIL4-15 Access management for services NISTSP115-8 Operational Considerations - Tools, Reporting Templates, ISMS Integration, Annex Material NISTSP122-5 PII Security Controls - Encryption, Access Control, Storage, Audit NISTSP137-6 Malware, Identity Access, and Network Boundary Monitoring OSFIB13-3 Cyber Security: Identification, Protection, Detection, Response, Recovery OPENBANK-3 Mutual TLS, Token Binding, Request Signing (JWS), Key Management OSSFSC-3 Build, CI/CD Security, Workflow Permissions, Dangerous Patterns OREGONCPA-5 Data Protection Assessments, Privacy by Design, Security Practices PASONE-4 Technical Security: CDE Configuration, BIM Tools, Encryption, Aggregation, Mobile Working PCI-P2PE-06 Network security and segmentation PCI-PIN-06 Network security and segmentation PCI-SSF-06 Network security and segmentation PDPASG-5 Protection, Accuracy, and Security of Personal Data PDPATH-5 Security Measures and Data Protection POPIASA-5 Security Safeguards, Encryption, Access Control, Operator Obligations NORWAY-5 Security of Processing, Encryption, Pseudonymization, Access Control PERU-7 DPO, Records, Retention, Marketing, Training AUPRV-4 APP 10-11 Quality, Security of Personal Information NZPRV-2 IPP 5 Storage and Security of Personal Information EHDSREG-6 Phased Application and Enforcement RUSPD-2 Lawful Basis, Consent, Notice PIPA-Cross-Border-Transfer-Articles-28-8-28-9-Adequacy-Standard-Contract-Certification-EU Korea PIPA Cross-Border Transfer + Articles 28-8 + 28-9 + Adequacy + EU 2021 GT-2 Physical Security Threats TEFCAREC-1 Common Agreement Conformance and Onboarding TURKEYKVKK-2 Information Notice and Data Subject Rights ACE-CR-4 Cargo Release Authorization USSDWA-2 Cybersecurity Practices (Assessment, Access, Network, IR) USMCADIGITAL-2 Personal Information Protection and Consumer Protection VERMONTAICDA-3 Bias Testing, Discrimination Prevention, Transparency VIETNAMPDP-2 Consent and Notice Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Query this from an agent The graph holds this control, the 262 it maps to, and the evidence behind each claim, over MCP and REST.