NIST Privacy Framework
Protect-P Data Security

NIST Privacy Framework NISTPF-6: Protect-P Data Security (PR.DS-P)

Apply Protect-P Data Security (PR.DS-P) including: data-at-rest protected + data-in-transit protected + systems managed during removal/transfer/disposition + adequate capacity to ensure availability + data leak protections + integrity verification for software/firmware/information + development/test separated from production + hardware integrity verified. Implement encryption (AES-256 + TLS 1.3 + PQC migration per FIPS 203/204/205) + DLP + secure software/hardware supply chain.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 64 controls across 29 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • 4.3.2 Legal and Other Requirements
  • 4.4.1 Resources, Roles, Responsibility, and Authority
  • 4.4.2 Competence, Training, and Awareness
  • FFIEC-11 Business continuity planning and testing
  • FFIEC-12 Disaster recovery procedures
  • FFIEC-14 Critical service identification
  • NIST-CSF-PR.DS-10 The confidentiality, integrity, and availability of data-in-use are protected
  • NIST-CSF-PR.IR-03 Mechanisms are implemented to achieve resilience requirements in normal and adverse situations
  • NIST-CSF-PR.IR-04 Adequate resource capacity to ensure availability is maintained

PCI P2PE · 3 controls

  • PCI-P2PE-11 Business continuity planning and testing
  • PCI-P2PE-12 Disaster recovery procedures
  • PCI-P2PE-14 Critical service identification

PCI PIN Security · 3 controls

  • PCI-PIN-13 Third-party dependency management
  • PCI-PIN-14 Critical service identification
  • PCI-PIN-15 Communication and escalation procedures

PCI SSF · 3 controls

  • PCI-SSF-12 Disaster recovery procedures
  • PCI-SSF-14 Critical service identification
  • PCI-SSF-15 Communication and escalation procedures
  • IM8-DAT.2 Data Protection
  • IM8-DSS.2 Service Reliability Standards
  • IM8-RES.4 Resilience Testing

APRA CPS 234 · 2 controls

  • CPS234-14 Definition of Information Security Roles and Responsibilities
  • CPS234-15 Information Security Capability
  • 62351-12 Resilience and security recommendations for DER
  • 62351-13 Cyber-physical generation and storage resilience

ISO/IEC 27031:2011 · 2 controls

  • 27031-8.1 Exercising and Testing
  • 27031-B High availability embedded systems
  • NISTSP82-1 OT Security Program Governance, Policy, Roles, and Safety-Security Integration
  • NISTSP82-5 OT Configuration Management, Patching, Vulnerability Management, and Malware Protection

OSFI B-13 · 2 controls

  • OSFIB13-4 Third-Party Risk Management and Cloud
  • OSFIB13-7 Incident Reporting to OSFI and Regulatory Coordination

Open Banking Security · 2 controls

  • OPENBANK-4 Third Party Provider (TPP) Onboarding, Directory Integration, Due Diligence
  • OPENBANK-8 Incident Detection, Response, Customer Notification, Post-Incident Review, BCM
  • OB-API.4 MI Reporting Specification
  • OB-OPS.1 API Availability Requirements
  • ASD37-20 Multi-factor authentication (Essential)
  • BS65000-RM-03 Leadership and Culture

COBIT 2019 · 1 control

  • COBIT-BAI04 Managed availability and capacity
  • CAT-D5-4 Resilience planning and testing
  • ISO20000-03 Capacity and availability management
  • ISO-25012-4.13 Availability

ISO/IEC 27007:2020 · 1 control

  • 27007-5.4 Establishing the Programme Resources

ITIL 4 · 1 control

  • ITIL4-03 Capacity and availability management
  • ORANWG11-2 O-RAN Interface Security: E2, A1, O1, O2, Open Fronthaul

OECD AI Principles · 1 control

  • OECDAI-3 Robustness, Security, Safety, and Adversarial Attack Protection
  • PSPF24-2 Information Security, Cybersecurity Maturity, Essential Eight
  • SAPAIA-2 Right of Access and Request Processes
  • KRCSAP-1 CSAP Certification Tiers (IaaS, SaaS, DaaS, AI)
  • CERT-1 RRA Certification to EPA

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 64 it maps to, and the evidence behind each claim, over MCP and REST.