NIST Privacy Framework
Protect-P Processes

NIST Privacy Framework NISTPF-8: Protect-P Information Protection Processes (PR.PO-P)

Apply Protect-P Information Protection Processes and Procedures (PR.PO-P) including: baseline configuration management + configuration change control + backups conducted and tested + physical operating environment policy + protection processes improved + effectiveness of protection technologies shared + response and recovery plans established + response and recovery plans tested + privacy in HR practices + vulnerability management plan. Integrate with NIST CSF Protective Processes + RESPOND function.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 709 controls across 158 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

BSI IT-Grundschutz · 15 controls

  • BSI-01 Account management and provisioning
  • BSI-03 Multi-factor authentication requirements
  • BSI-04 Remote access controls
  • BSI-05 Wireless access restrictions
  • BSI-08 Cryptographic protection of data
  • BSI-13 Risk assessment procedures
  • BSI-14 Vulnerability scanning and management
  • BSI-15 Security categorization
  • BSI-17 Continuous monitoring strategy
  • BSI-23 Baseline configuration establishment
  • BSI-24 Configuration change control
  • BSI-26 System component inventory
  • BSI-28 Audit event logging and storage
  • BSI-29 Audit record review and analysis
  • BSI-31 Audit log protection and retention

South Korea ISMS-P · 12 controls

  • ISMSP-AC-01 Access Control Policy
  • ISMSP-AC-02 User Account Management
  • ISMSP-AC-04 Network Access Control
  • ISMSP-MS-02 Risk Management
  • ISMSP-PI-01 Personal Information Collection
  • ISMSP-PI-04 Cross-Border Transfer
  • ISMSP-PI-06 Personal Information Destruction
  • ISMSP-SYS-01 System Hardening and Patch Management
  • ISMSP-SYS-02 Encryption Implementation
  • ISMSP-SYS-03 Security Monitoring and Log Management
  • ISMSP-SYS-04 Vulnerability Management
  • ISMSP-SYS-06 Business Continuity and Disaster Recovery

API 1164 · 11 controls

  • API1164-06 Access Control
  • API1164-07 Remote Access
  • API1164-09 Patch and Vulnerability Management
  • API1164-14 Physical Security
  • API1164-17 Wireless and Field Communications
  • API1164-18 Field Device Security
  • API1164-19 Safety Instrumented Systems Interface
  • API1164-21 TSA Pipeline Security Directive Alignment
  • API1164-22 Configuration management for OT systems
  • API1164-23 Change management procedures
  • API1164-24 Vulnerability assessment for critical systems

IEC 62443 · 11 controls

  • IEC62443-07 Personnel risk assessment
  • IEC62443-08 Electronic access perimeter management
  • IEC62443-10 Revocation of access procedures
  • IEC62443-14 System security hardening
  • IEC62443-16 Incident response plan for operational disruptions
  • IEC62443-17 Recovery plan for critical systems
  • IEC62443-20 Exercises and drills for OT incidents
  • IEC62443-21 Supply chain risk management for critical components
  • IEC62443-22 Configuration management for OT systems
  • IEC62443-23 Change management procedures
  • IEC62443-24 Vulnerability assessment for critical systems

ISO/IEC 27019:2024 · 11 controls

  • ISO27019-07 Personnel risk assessment
  • ISO27019-08 Electronic access perimeter management
  • ISO27019-10 Revocation of access procedures
  • ISO27019-14 System security hardening
  • ISO27019-16 Incident response plan for operational disruptions
  • ISO27019-18 Reporting obligations to authorities
  • ISO27019-20 Exercises and drills for OT incidents
  • ISO27019-21 Supply chain risk management for critical components
  • ISO27019-22 Configuration management for OT systems
  • ISO27019-23 Change management procedures
  • ISO27019-24 Vulnerability assessment for critical systems

ISO/IEC 27043:2015 · 11 controls

  • ISO27043-11 Access control policy and enforcement
  • ISO27043-12 User access management and provisioning
  • ISO27043-14 Privileged access management
  • ISO27043-15 Access review and recertification
  • ISO27043-17 Encryption of data at rest
  • ISO27043-18 Encryption of data in transit
  • ISO27043-19 Certificate management
  • ISO27043-20 Key lifecycle management
  • ISO27043-23 Backup and recovery procedures
  • ISO27043-24 Logging and monitoring
  • ISO27043-25 Technical vulnerability management

NIST SP 800-53 Rev 5 · 11 controls

ISO 27799:2025 · 10 controls

  • ISO27799-01 ePHI access controls and authorization
  • ISO27799-02 ePHI encryption at rest and in transit
  • ISO27799-03 Minimum necessary standard enforcement
  • ISO27799-04 Patient data de-identification procedures
  • ISO27799-05 Audit trail for ePHI access
  • ISO27799-06 Security management process and risk analysis
  • ISO27799-08 Information access management
  • ISO27799-09 Security awareness and training program
  • ISO27799-16 Transmission security and encryption
  • ISO27799-17 Facility access controls

ISO/SAE 21434 · 10 controls

  • ISO21434-12 User access management and provisioning
  • ISO21434-14 Privileged access management
  • ISO21434-15 Access review and recertification
  • ISO21434-16 Cryptographic policy and key management
  • ISO21434-17 Encryption of data at rest
  • ISO21434-18 Encryption of data in transit
  • ISO21434-19 Certificate management
  • ISO21434-23 Backup and recovery procedures
  • ISO21434-24 Logging and monitoring
  • ISO21434-25 Technical vulnerability management
  • ASD37-04 User application hardening (Essential)
  • ASD37-10 Server application hardening (Very Good)
  • ASD37-11 Operating system hardening (Very Good)
  • ASD37-17 TLS encryption between email servers (Limited)
  • ASD37-27 Outbound data loss prevention (Very Good)
  • ASD37-34 Regular backups (Essential)
  • ASD37-35 Business continuity and disaster recovery plans (Very Good)
  • ASD37-36 System recovery capabilities (Very Good)
  • ASD37-37 Personnel management (Very Good)
  • AWWA-1.2 Risk Assessment
  • AWWA-1.3 Security Awareness and Training
  • AWWA-2.1 User Access Management
  • AWWA-2.3 Account Management
  • AWWA-2.4 Physical Access Controls
  • AWWA-3.2 Remote Access Security
  • AWWA-3.4 Encryption and Data Protection
  • AWWA-4.3 Configuration Management
  • AWWA-4.4 Audit Logging and Monitoring
  • NIST-CSF-GV.RM-03 Cybersecurity risk management activities and outcomes are included in enterprise risk management processes
  • NIST-CSF-GV.RM-04 Strategic direction that describes appropriate risk response options is established and communicated
  • NIST-CSF-GV.RM-07 Strategic opportunities (i.e., positive risks) are characterized and are included in organizational cybersecurity risk discussions
  • NIST-CSF-GV.SC-01 A cybersecurity supply chain risk management program, strategy, objectives, policies, and processes are established and agreed to by organizational stakeholders
  • NIST-CSF-ID.RA-09 The authenticity and integrity of hardware and software are assessed prior to acquisition and use
  • NIST-CSF-PR.PS-01 Configuration management practices are established and applied
  • NIST-CSF-RC.RP-01 The recovery portion of the incident response plan is executed once initiated from the incident response process
  • NIST-CSF-RC.RP-06 The end of incident recovery is declared based on criteria, and incident-related documentation is completed
  • NIST-CSF-RS.MA-05 The criteria for initiating incident recovery are applied

NIST SP 800-190 · 9 controls

GDPR · 8 controls

  • GDPR-Art.10 Processing of personal data relating to criminal convictions
  • GDPR-Art.11 Processing which does not require identification
  • GDPR-Art.15 Right of access by the data subject
  • GDPR-Art.19 Notification obligation regarding rectification, erasure or restriction
  • GDPR-Art.25 Data protection by design and by default
  • GDPR-Art.35 Data protection impact assessment
  • GDPR-Art.38 Position of the data protection officer
  • GDPR-Art.9 Processing of special categories of personal data

ISO/IEC 27011:2024 · 8 controls

  • 27011-5.2 Information Security Roles in Telecoms
  • 27011-5.3 Segregation of duties
  • 27011-6.3 Awareness and Training
  • 27011-8.1 User Endpoint Devices
  • 27011-8.3 Cryptography and key management
  • 27011-8.4 Logging and monitoring
  • 27011-8.5 Vulnerability and malware management
  • 27011-8.6 Data protection and backup
  • IM8-CLD.2 Cloud Security Controls
  • IM8-DAT.2 Data Protection
  • IM8-DAT.4 Data Retention and Disposal
  • IM8-RES.2 Disaster Recovery
  • IM8-RES.4 Resilience Testing
  • IM8-SEC.2 Access Control
  • IM8-SEC.4 Vulnerability Management
  • IM8-TPM.4 Supply Chain Risk Management

Bahrain PDPL · 7 controls

  • CAT-D1-2 Risk management
  • CAT-D1-4 Training and culture
  • CAT-D3-1 Preventative controls
  • CAT-D3-2 Detective controls
  • CAT-D3-3 Corrective controls
  • CAT-D4-3 Third-party access controls
  • CAT-ML-2 Evolving

ISO/IEC 23894:2023 · 7 controls

  • ISO23894-5.1 Leadership and Commitment
  • ISO23894-5.2 AI Risk Management Integration
  • ISO23894-5.5 Framework Evaluation
  • ISO23894-6.3 AI Risk Assessment
  • ISO23894-6.3.1 AI Risk Identification
  • ISO23894-6.3.3 AI Risk Evaluation
  • ISO23894-A.5 Privacy and Data Protection in AI
  • 27557-1 Scope
  • 27557-3 Terms and definitions
  • 27557-4.3 Individual impact consideration
  • 27557-6.3 Privacy risk assessment
  • 27557-6.4 Privacy risk treatment
  • 27557-6.6 Recording and reporting
  • 27557-7.3 Risk-based privacy program implementation

OWASP ASVS · 7 controls

  • AT-DSG-10 Section 29 - Liability and right to compensation / civil jurisdiction
  • AT-DSG-11 Sections 42-45 - Data subject rights (law enforcement)
  • AT-DSG-12 Section 62 - Administrative penalties
  • AT-DSG-13 Section 36 - Scope of law enforcement processing
  • AT-DSG-14 Section 38 - Lawfulness of law enforcement processing
  • AT-DSG-7 Section 18 - Establishment of the Data Protection Authority
  • BB-DPA-1 Section 1 - Short Title
  • BB-DPA-14 Section 15 - Right to Data Portability
  • BB-DPA-16 Section 22 - General Principle for Transfers
  • BB-DPA-20 Sections 50-60 - Registration and Responsibilities
  • BB-DPA-21 Sections 61-69 - Data Privacy Officer
  • BB-DPA-4 Section 4 - Principles Relating to Processing
  • CJIS-17 Risk Assessment
  • CJIS-19 Supply Chain Risk Management
  • CJIS-2 Security Awareness Training
  • CJIS-7 Configuration Management
  • CJIS-8 Media Protection
  • CJIS-9 System and Communications Protection
  • FFIEC-03 Risk appetite and tolerance for IT risk
  • FFIEC-09 Encryption and key management
  • FFIEC-10 Secure configuration standards
  • FFIEC-12 Disaster recovery procedures
  • FFIEC-18 Ongoing monitoring and assessment
  • FFIEC-20 Exit strategy and transition planning

FedRAMP Rev 5 · 6 controls

  • FEDRAMP-CM-1 Configuration Management Policy
  • FEDRAMP-CM-2 Baseline Configuration
  • FEDRAMP-CP-9 System Backup
  • FEDRAMP-SC-13 Cryptographic Protection
  • FEDRAMP-SC-28 Protection of Information at Rest
  • FEDRAMP-SC-8 Transmission Confidentiality and Integrity

ISO/IEC 27400:2022 · 6 controls

  • 27400-5.4 Data and privacy risks
  • 27400-6.2 Device Identity and Authentication
  • 27400-6.4 Default Configuration Security
  • 27400-7.1 Network Security for IoT
  • 27400-7.3 Data minimization and purpose limitation
  • 27400-7.4 Data retention and deletion

NIST SP 1800-32 · 6 controls

OWASP MASVS · 6 controls

APPI · 5 controls

  • APPI-A23 Security Control Measures
  • APPI-A24 Supervision of Employees
  • APPI-A26 Report of Leakage to the Commission and Notification to the Person
  • APPI-A33 Request for Disclosure of Retained Personal Data
  • APPI-A34 Request for Correction, Addition or Deletion
  • IS.D.OR.205 Information Security Risk Assessment
  • IS.D.OR.210 Information Security Risk Treatment
  • IS.I.OR.205 Information Security Risk Assessment
  • IS.I.OR.210 Information Security Risk Treatment
  • IS.I.OR.220 Information Security Risk Management
  • IEC62304-4.1 Quality Management System
  • IEC62304-5.1 Software Development Planning
  • IEC62304-7.4 Risk Management of Software Changes
  • IEC62304-8.2 Change Control
  • IEC62304-9.4 Use Change Control Process

NIST SP 800-144 · 5 controls

  • NISTSP144-3 Data Classification, Handling, and Sovereignty
  • NISTSP144-5 Identity and Access in Cloud, Federation, and Privileged Access
  • NISTSP144-6 Availability, Resilience, BCP/DR, and SLA Management
  • NISTSP144-7 Cloud Workload Protection, Containers, Serverless, and Configuration
  • NISTSP144-8 Monitoring, Incident Response, Exit Strategy, and Compliance
  • CPS230-11 Identification, Assessment and Management of Operational Risk
  • CPS230-16 Internal Audit Review of the Business Continuity Plan
  • CPS230-37 Service Provider Management Policy
  • CPS230-46 Ongoing Risk Management of Each Material Arrangement
  • AZ-DPA-12 Article 13 - Cross-border transfer
  • AZ-DPA-14 Article 16 - Liability for violations
  • AZ-DPA-15 Article 17 - Dispute resolution
  • AZ-DPA-6 Article 6 - State regulation in personal data protection
  • UAE-PDPL-Art.10 Data Protection Officer (DPO) (UAE PDPL Article 10)
  • UAE-PDPL-Art.18_19_20_21 Security measures, controller/processor relationship, DPIA (UAE PDPL Articles 18-21)
  • UAE-PDPL-Art.4_5 Lawful basis and principles for processing personal data (UAE PDPL Articles 4-5)
  • UAE-PDPL-Art.6_7 Sensitive personal data and children's data (UAE PDPL Articles 6-7)

ISO/IEC 27031:2011 · 4 controls

  • 27031-7.2 Resource Requirements
  • 27031-8.1 Exercising and Testing
  • 27031-8.2 Maintaining IRBC
  • 27031-9.3 Management Review

ISO/IEC 29134:2023 · 4 controls

  • 29134-1 Scope
  • 29134-3 Terms and definitions
  • 29134-9.1 PIA report structure
  • 29134-9.2 Report findings and recommendations
  • NISTSP82-1 OT Security Program Governance, Policy, Roles, and Safety-Security Integration
  • NISTSP82-5 OT Configuration Management, Patching, Vulnerability Management, and Malware Protection
  • NISTSP82-6 OT Audit, Monitoring, Anomaly Detection, and OT-Specific SOC
  • NISTSP82-7 OT Incident Response, Forensics, Recovery, and Continuity
  • NGOB-1 Open Banking Registry Participation, Tiered Categorisation, and KYP
  • NGOB-2 Customer Consent Management and Lifecycle
  • NGOB-3 API Security Standards, mTLS, and Encryption
  • NGOB-5 Fraud Monitoring, Incident Notification, and Reporting to CBN

OWASP Top 10:2025 · 4 controls

  • OWASPTOP10-1 A01:2025 Broken Access Control
  • OWASPTOP10-2 A02:2025 Cryptographic Failures and Secret Management
  • OWASPTOP10-4 A04:2025 Insecure Design and Business Logic (incl. A11 API Abuse)
  • OWASPTOP10-9 A09:2025 Security Logging and Monitoring Failures
  • AUPRV-1 APP 1 Open and Transparent Management + Privacy Management Framework
  • AUPRV-4 APP 10-11 Quality, Security of Personal Information
  • AUPRV-6 Sensitive Information, PIA, Privacy by Design, Children
  • AUPRV-7 Notifiable Data Breaches (NDB) Scheme, Incident Response
  • APP-1 APP 1 - Open and transparent management of personal information
  • APP-3 APP 3 - Collection of solicited personal information
  • APP-5 APP 5 - Notification of the collection of personal information
  • DIQ-1 Data Integration and Interoperability
  • DSO-2 Data Security
  • DSO-3 Data Access Management
  • FTC-Safeguards-9-Elements 9 Safeguard Elements - Access, Inventory, Encryption, Secure-Dev, MFA, Disposal, Change-Mgmt, Monitoring, Pen-Test (16 CFR 314.4(c))
  • FTC-Safeguards-Scope-Defs Scope, Definitions and Financial Institution Applicability (16 CFR 314.1, 314.2)
  • FTC-Safeguards-ServiceProvider-Evaluation Service Provider Oversight + Program Evaluation + Personnel Training (16 CFR 314.4(d-g))
  • 60601-1.4.1 General requirements
  • 60601-1.4.2 Risk management process
  • 60601-1.5.1 General requirements for testing
  • 62351-14 Cyber security event logging
  • 62351-8 Role-based access control (RBAC)
  • 62351-9 Cyber security key management
  • ISO-26262-3-7 Hazard analysis and risk assessment (HARA)
  • ISO-26262-8-7 Configuration management
  • ISO-26262-8-8 Change management
  • ISO28001-PI-02 Security Awareness and Training
  • ISO28001-PS-01 Facility Security
  • ISO28001-SA-04 Security Risk Treatment Planning

ISO/IEC 20000-1:2018 · 3 controls

  • ISO20000-06 Change management processes
  • ISO20000-10 Configuration management
  • ISO20000-15 Access management for services

ISO/IEC 23837:2023 · 3 controls

  • 23837-1.2 Normative references
  • 23837-1.5.2 Cryptographic module requirements
  • 23837-1.5.3 Network device testing requirements

ISO/IEC 27003:2017 · 3 controls

  • ISO27003-6.1 Actions to address risks and opportunities
  • ISO27003-8.2 Information security risk assessment
  • ISO27003-8.3 Information security risk treatment

ISO/IEC 27010:2015 · 3 controls

  • 27010-10.1 Cryptographic Protection
  • 27010-9.1 Access Control to Shared Information
  • 27010-9.2 Authentication of Sources

ISO/IEC 29100:2024 · 3 controls

  • 29100-6.10 Information security
  • 29100-6.5 Use, retention and disclosure limitation
  • 29100-6.9 Accountability

ISO/IEC 29147:2018 · 3 controls

  • 29147-5.11 Researcher Safe Harbour and Legal Posture
  • 29147-5.6 Advisory Content and Quality
  • 29147-7.8 Remediation information

ISO/IEC 30111:2019 · 3 controls

  • 30111-1 Scope
  • 30111-3 Terms and definitions
  • 30111-8.1 Post-release monitoring

ITIL 4 · 3 controls

  • ITIL4-06 Change management processes
  • ITIL4-10 Configuration management
  • ITIL4-15 Access management for services
  • NFPA1600-5.1 Risk Assessment
  • NFPA1600-5.3 Resource Needs Assessment
  • NFPA1600-6.4 Continuity and Recovery
  • NISTSP115-2 Review Techniques - Documentation, Logs, Rulesets, Configurations
  • NISTSP115-3 Target Identification and Analysis - Network Discovery, Port and Service ID, Vuln Scanning
  • NISTSP115-8 Operational Considerations - Tools, Reporting Templates, ISMS Integration, Annex Material

NIST SP 800-137 · 3 controls

  • NISTSP137-4 Security Status Reporting and Risk Score Aggregation
  • NISTSP137-5 Vulnerability + Patch + Configuration Status Monitoring
  • NISTSP137-7 Incident Response Integration and Ongoing Authorization

NIST SP 800-145 · 3 controls

  • NISTSP145-3 Rapid Elasticity Characteristic and Capacity Management
  • NISTSP145-7 Cloud Procurement Standards Aligned to NIST SP 800-145 Definition
  • NISTSP145-8 Governance, Reporting, and Stakeholder Education on Cloud Definition

NIST SP 800-146 · 3 controls

  • NISTSP146-4 IaaS Operational Recommendations and Workload Hardening
  • NISTSP146-6 Cloud Security and Privacy Recommendations
  • NISTSP146-7 Service Level, Performance, Reliability, Interoperability, and Portability
  • NISTSP34-2 Business Impact Analysis (BIA): Critical Resources, Recovery Priorities
  • NISTSP34-3 Preventive Controls and Recovery Strategies: Backup, Alternate Sites, Equipment
  • NISTSP34-4 Information System Contingency Plan (ISCP) Development
  • NJDPA-2 Consumer Rights - Access, Correct, Delete, Portability, Appeal
  • NJDPA-7 Data Protection Assessments and Processor Contracts
  • NJDPA-8 AG Platkin Enforcement, 18-Month Cure Sunset, and Division of Consumer Affairs
  • OMANCS-4 Data Protection, Cryptography, and Privacy Alignment
  • OMANCS-5 Network, Endpoint, System Development, and Configuration Security
  • OMANCS-7 Business Continuity, Disaster Recovery, and Resilience

OpenSSF Scorecard · 3 controls

  • OSSFSC-2 Dependency Management, Pinning, Updates, Vulnerability Tracking
  • OSSFSC-7 Webhook Authentication, Contributors Diversity, Aggregate Score
  • OSSFSC-8 Project Maintenance, Sustainability, Integration with Supply Chain Security
  • PAKPDPB-6 Cross-Border Transfer and Data Localization
  • PAKPDPB-7 NCPDP, Registration, Records, Processor Contracts, DPO
  • PAKPDPB-8 Enforcement, Penalties, Complaints, Retention, Training
  • PSPF24-1 Security Culture, Governance, Risk Management
  • PSPF24-2 Information Security, Cybersecurity Maturity, Essential Eight
  • PSPF24-4 Physical Security

South Korea PIPA · 3 controls

  • PIPA-CPO-DPO-Privacy-Officer-PIA-Personal-Information-Impact-Assessment-Articles-31-33 Korea PIPA CPO + DPO + Privacy Officer + PIA + Personal Information Impact Assessment + Articles 31-33
  • PIPA-Cross-Border-Transfer-Articles-28-8-28-9-Adequacy-Standard-Contract-Certification-EU Korea PIPA Cross-Border Transfer + Articles 28-8 + 28-9 + Adequacy + EU 2021
  • PIPA-Data-Subject-Rights-Access-Correction-Erasure-Portability-Automated-Decisions-Articles-35-37-2 Korea PIPA Data Subject Rights + Access + Correction + Erasure + Portability + Article 35-37
  • CRM-1 AML/CFT Compliance
  • CRM-3 Risk Management Framework
  • CRM-4 Business Risk Assessment
  • D.1 Incident Response Planning
  • D.3 Backup and Recovery
  • UKDEFSTD-1 Cyber Defence Cyber Risk Profile (CRP)
  • CPSC-CS.2 Authentication and Access Controls
  • CPSC-CS.3 Data Protection for Safety Systems
  • CPSC-RA.3 Lifecycle Risk Assessment
  • AMLCTF-82 Part A Compliance
  • AMLCTF-PartA-RiskAssess ML/TF Risk Assessment

APRA CPS 234 · 2 controls

  • CPS234-16 Assessment of Related Party and Third Party Capability
  • CPS234-20 Information Asset Classification
  • 4.3.1 Risk Assessment and Impact Analysis
  • 4.4.8 Business Continuity and Recovery
  • AL-DPA-12 International Data Transfers
  • AL-DPA-14 Direct Marketing
  • BS65000-RM-01 Resilience Journey
  • BS65000-RM-02 Integrated Approach
  • FDBR-ControllerObligations-DPA-Notice Controller + Processor Obligations + Data Protection Assessments (Fla. Stat. 501.707, 501.708, 501.71, 501.711)
  • FDBR-Scope-Defs Scope, Applicability Thresholds and Definitions (Fla. Stat. 501.701, 501.702, 501.703, 501.704)
  • Sapin2-Pillar3-Risk-Mapping Pillar 3 - Corruption Risk Mapping (Cartographie des Risques)
  • Sapin2-Pillar4-ThirdParty-DueDiligence Pillar 4 - Third-Party Due Diligence (Clients, Suppliers, Intermediaries, M&A)
  • ICP-16 Enterprise Risk Management for Solvency Purposes
  • ICP-8 Risk Management and Internal Controls
  • ICAO-ANX17-Chap2-ThreatAssessment-RiskManagement-Cyber-GASeP ICAO Annex 17 Chapter 2 - Threat Assessment + Risk Management + Cyber Threats to Critical Aviation Systems (Amendment 17/18)
  • ICAO-ANX17-Chap4-Cargo-Mail-Catering-Stores-Supplies-RegulatedAgent-KnownConsignor ICAO Annex 17 Chapter 4 - Cargo + Mail + Catering + Stores + Supplies Security + Regulated Agent + Known Consignor + Supply Chain

ISO 22316 · 2 controls

  • ISO22316-08 Recovery time and point objectives
  • ISO22316-12 Recovery strategy for critical activities

ISO 22320:2018 · 2 controls

  • ISO-22320-4.3 Risk-based approach
  • ISO-22320-5.2 Incident management process

ISO/TS 22317:2021 · 2 controls

  • ISO22317-08 Recovery time and point objectives
  • ISO22317-12 Recovery strategy for critical activities

ISO/TS 22318:2021 · 2 controls

  • ISO22318-08 Recovery time and point objectives
  • ISO22318-12 Recovery strategy for critical activities

NIST SP 800-61 Rev. 3 · 2 controls

  • NISTSP61-4 Detection and Analysis: Sources, Triage, Categorisation, Prioritisation
  • NISTSP61-5 Containment, Eradication, and Recovery

NIST SP 800-63-4 · 2 controls

  • NISTSP63R4-4 Authenticator Lifecycle: Binding, Recovery, Replacement, Suspension, Revocation
  • NISTSP63R4-8 Operational Audit, Session Management, Recovery, and Cross-cutting Controls

NIST SP 800-88 · 2 controls

  • NISTSP88-5 Media Inventory, Tracking, Chain of Custody, and Sanitization Records
  • NISTSP88-7 Verification, Audit, Training, and Environmental/Safety Controls

NIST SP 800-92 · 2 controls

  • NISTSP92-5 Log Analysis: Correlation, Baselining, Anomaly Detection, Alerting, Manual Review
  • NISTSP92-6 Log Retention: Policy, Tiered Storage, Backup, Secure Disposal, Legal Hold
  • NRFCS-1 Retail Cybersecurity Governance, Policy, and Regulatory Change Management
  • NRFCS-2 Risk Assessment, Customer Data Inventory, Classification, and Retail Threat Model
  • NDPA-1 Applicability, Scope, and Carve-Outs
  • NDPA-4 Sensitive Data Processing Consent and Childrens Protections
  • NZISM-1 NZISM Governance, Documentation, and Classification System
  • NZISM-3 Personnel Security, Physical Security, and Cryptography
  • ORANWG11-1 O-RAN Threat Model, Risk Management, and Security Architecture
  • ORANWG11-7 Logging, Monitoring, Incident Response, and Denial-of-Service Resilience
  • OCCHS-3 Risk Appetite Statement, Risk Limits, Concentration Risk, and Limit Breach Protocols
  • OCCHS-7 Risk Data Aggregation, Reporting, Talent, Compensation, and Strategic Planning
  • OWASPAPI-1 Broken Object Level Authorization (BOLA) and BFLA
  • OWASPAPI-6 Security Misconfiguration and Secure API Design
  • DSOMM-1 Culture, Organization, Education, and Governance
  • DSOMM-3 Build, Deployment, Infrastructure Hardening, and Secrets Management
  • OWASPLLM-3 Sensitive Information Disclosure and Privacy (LLM02)
  • OWASPLLM-6 Excessive Agency and Unbounded Consumption (LLM06 + LLM10)

Open Banking Security · 2 controls

  • OPENBANK-3 Mutual TLS, Token Binding, Request Signing (JWS), Key Management
  • OPENBANK-8 Incident Detection, Response, Customer Notification, Post-Incident Review, BCM
  • OREGONCPA-5 Data Protection Assessments, Privacy by Design, Security Practices
  • OREGONCPA-8 Cure Period, Attorney General Enforcement, Training, Compliance Monitoring
  • PASONE-4 Technical Security: CDE Configuration, BIM Tools, Encryption, Aggregation, Mobile Working
  • PASONE-6 Incident Management, Audit, Handover, Operational Phase, Decommissioning
  • ASTWO-1 Audit Planning, Scaling, Risk Assessment, and Integration
  • ASTWO-3 Entity-Level Controls and Period-End Financial Reporting Process

PCI P2PE · 2 controls

  • PCI-P2PE-10 Secure configuration standards
  • PCI-P2PE-12 Disaster recovery procedures

PCI PIN Security · 2 controls

  • PCI-PIN-10 Secure configuration standards
  • PCI-PIN-12 Disaster recovery procedures

PCI SSF · 2 controls

  • PCI-SSF-10 Secure configuration standards
  • PCI-SSF-12 Disaster recovery procedures

PDPA Singapore · 2 controls

  • PDPASG-1 Accountability, Records, DPO Appointment, and Training
  • PDPASG-4 Children's Data, DPIA, and Privacy by Design

PDPA Thailand · 2 controls

  • PDPATH-4 DPIA, Privacy by Design, Children's Data
  • PDPATH-7 DPO, Records of Processing, Retention, Marketing, Training

POPIA · 2 controls

  • POPIASA-4 Special Personal Information, Children, Information Quality, Documentation
  • POPIASA-7 Information Officer, Records of Processing, Notification, Training
  • NORWAY-4 DPIA, Privacy by Design, Records of Processing
  • NORWAY-7 DPO, Cooperation with Datatilsynet, Retention, Marketing, Training

Privacy Act 2020 · 2 controls

  • NZPRV-6 IPP 13 Unique Identifiers, Privacy Impact Assessment, Privacy by Design
  • NZPRV-8 Privacy Officer, OPC Cooperation, Compliance Notices, Complaints, Training
  • RUSPD-1 Scope, Definitions, Principles under 152-FZ
  • RUSPD-4 Special Categories, Biometric Data
  • 2.4.4 Hazard Analysis and Risk Assessment
  • 2.7.2 Food Fraud Plan

Turkey KVKK · 2 controls

  • TURKEYKVKK-2 Information Notice and Data Subject Rights
  • TURKEYKVKK-3 Special Categories and Sensitive Data
  • USMCADIGITAL-1 Cross-Border Data Flows and Localisation
  • USMCADIGITAL-2 Personal Information Protection and Consumer Protection
  • VERMONTAICDA-3 Bias Testing, Discrimination Prevention, Transparency
  • VERMONTAICDA-4 Vermont AG Enforcement and Cure
  • VIETNAMCYBER-2 Prohibited Acts (Access, Interception, Forgery, Content)
  • VIETNAMCYBER-4 Incident Reporting and Cooperation
  • AS9100D-8.1 Operational Planning and Control
  • ACQS-8-4 Risk Management
  • DS-2 Ensure software supply chain security
  • CA-10 Selects and Develops Control Activities
  • CA-ITSG33-SC-01 Security Control Catalogue
  • CTDPA-1 Definitions

FIDO2 / WebAuthn · 1 control

  • IATA-IOSA-Section8-SEC-SecurityManagement-AVSEC IATA IOSA Section 8 - SEC Security Management + Aviation Security Programme (AVSEC) + ICAO Annex 17 Alignment
  • ISO-20400-4.5 Key considerations for sustainable procurement
  • ISO-22313-8.2 Business impact analysis and risk assessment

ISO 26000:2010 · 1 control

  • ISO-26000-6.7 Consumer issues

ISO 30401 · 1 control

  • ISO30401-18 Innovation and change management
  • ISO-25012-4.11 Traceability
  • 29115-7.4 Level of Assurance 4 (LoA4)
  • STANAG-2 STANAG 4778 Metadata Binding Mechanism and Cryptographic Binding

NIST SP 800-122 · 1 control

  • NISTSP122-8 Continuous Monitoring, Training, and Privacy Programme Governance

NIST SP 800-123 · 1 control

  • NISTSP123-5 Server Operations - Patching, Malware, Logging, Backup

NIST SP 800-66 · 1 control

  • NISTSP66-6 Technical Safeguards: Access Control, Audit Controls, Integrity, Person Authentication
  • AUNDB-A3 Eligible Data Breach Determination and Serious Harm Threshold

OECD AI Principles · 1 control

  • OECDAI-5 Data Governance, Training Data Quality, Privacy, and Bias Mitigation

OSFI B-13 · 1 control

  • OSFIB13-3 Cyber Security: Identification, Protection, Detection, Response, Recovery

Peru DPL · 1 control

  • PERU-3 Data Subject Rights (ARCO), Habeas Data, Automated Decisions
  • RIDTPPA-2 Consumer Rights (Access, Correction, Deletion, Portability, Opt-Out)
  • AIGF-1.1 Risk Management and Internal Controls
  • TEFCAREC-1 Common Agreement Conformance and Onboarding
  • UNGPBHR-2 Pillar II: Corporate Responsibility to Respect Human Rights
  • USSDWA-2 Cybersecurity Practices (Assessment, Access, Network, IR)

Vietnam PDPD · 1 control

  • VIETNAMPDP-3 Data Subject Rights

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 709 it maps to, and the evidence behind each claim, over MCP and REST.