NIST SP 1800-32
NIST SP 1800-32: Access Management

NIST SP 1800-32 NIST1800-32-07: Personnel risk assessment

Personnel risk assessment. Control from NIST SP 1800-32 framework, domain: NIST SP 1800-32: Access Management.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 281 controls across 121 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

BSI IT-Grundschutz · 6 controls

  • BSI-03 Multi-factor authentication requirements
  • BSI-04 Remote access controls
  • BSI-05 Wireless access restrictions
  • BSI-13 Risk assessment procedures
  • BSI-15 Security categorization
  • BSI-17 Continuous monitoring strategy

NIST SP 800-53 Rev 5 · 6 controls

API 1164 · 4 controls

  • API1164-06 Access Control
  • API1164-07 Remote Access
  • API1164-09 Patch and Vulnerability Management
  • API1164-24 Vulnerability assessment for critical systems

IEC 62443 · 4 controls

  • IEC62443-07 Personnel risk assessment
  • IEC62443-08 Electronic access perimeter management
  • IEC62443-10 Revocation of access procedures
  • IEC62443-24 Vulnerability assessment for critical systems

ISO 27799:2025 · 4 controls

  • ISO27799-01 ePHI access controls and authorization
  • ISO27799-06 Security management process and risk analysis
  • ISO27799-08 Information access management
  • ISO27799-17 Facility access controls

ISO/IEC 27019:2024 · 4 controls

  • ISO27019-07 Personnel risk assessment
  • ISO27019-08 Electronic access perimeter management
  • ISO27019-10 Revocation of access procedures
  • ISO27019-24 Vulnerability assessment for critical systems

NIST SP 800-66 · 4 controls

  • NISTSP66-1 Security Management Process: Risk Analysis and Risk Management for ePHI
  • NISTSP66-2 Workforce Security, Information Access Management, and Awareness Training
  • NISTSP66-5 Physical Safeguards: Facility Access, Workstation Use and Security, Device and Media Controls
  • NISTSP66-6 Technical Safeguards: Access Control, Audit Controls, Integrity, Person Authentication

South Korea ISMS-P · 4 controls

  • ISMSP-AC-01 Access Control Policy
  • ISMSP-AC-04 Network Access Control
  • ISMSP-MS-02 Risk Management
  • ISMSP-SYS-04 Vulnerability Management
  • AWWA-1.2 Risk Assessment
  • AWWA-2.1 User Access Management
  • AWWA-2.4 Physical Access Controls

ISO/IEC 23894:2023 · 3 controls

  • ISO23894-6.3 AI Risk Assessment
  • ISO23894-6.3.1 AI Risk Identification
  • ISO23894-6.3.3 AI Risk Evaluation

ISO/IEC 27043:2015 · 3 controls

  • ISO27043-11 Access control policy and enforcement
  • ISO27043-14 Privileged access management
  • ISO27043-15 Access review and recertification

ISO/IEC 29134:2023 · 3 controls

  • 29134-1 Scope
  • 29134-3 Terms and definitions
  • 29134-9.1 PIA report structure

ISO/SAE 21434 · 3 controls

  • ISO21434-12 User access management and provisioning
  • ISO21434-14 Privileged access management
  • ISO21434-15 Access review and recertification

NIST SP 800-30 · 3 controls

  • NISTSP30-3 Threat Source and Threat Event Identification
  • NISTSP30-4 Vulnerability and Predisposing Condition Identification
  • NISTSP30-6 Risk Determination, Uncertainty, and Sensitivity Analysis
  • RMI-DD-2 Supply Chain Information Collection
  • RMI-SEG-2 Environmental Standards
  • RMI-SEG-3 OHS and Governance
  • SSAE18-CC3.1 CC3.1 - COSO Principle 6: Risk Identification
  • SSAE18-CC3.2 CC3.2 - COSO Principle 7: Risk Analysis
  • SSAE18-SOC1-02 Risk Assessment
  • CH-FADP-15 Cooperation with the FDPIC
  • CH-FADP-21 Data protection impact assessments
  • FADP-7 Data Protection Impact Assessment (Articles 9-10)

Bahrain PDPL · 2 controls

  • DSO-2 Data Security
  • DSO-3 Data Access Management
  • IS.D.OR.205 Information Security Risk Assessment
  • IS.I.OR.205 Information Security Risk Assessment
  • CAT-D3-1 Preventative controls
  • CAT-D4-3 Third-party access controls
  • UAE-PDPL-Art.18_19_20_21 Security measures, controller/processor relationship, DPIA (UAE PDPL Articles 18-21)
  • UAE-PDPL-Art.6_7 Sensitive personal data and children's data (UAE PDPL Articles 6-7)
  • Sapin2-Pillar3-Risk-Mapping Pillar 3 - Corruption Risk Mapping (Cartographie des Risques)
  • Sapin2-Pillar4-ThirdParty-DueDiligence Pillar 4 - Third-Party Due Diligence (Clients, Suppliers, Intermediaries, M&A)
  • ICAO-ANX17-Chap2-ThreatAssessment-RiskManagement-Cyber-GASeP ICAO Annex 17 Chapter 2 - Threat Assessment + Risk Management + Cyber Threats to Critical Aviation Systems (Amendment 17/18)
  • ICAO-ANX17-Chap4-Cargo-Mail-Catering-Stores-Supplies-RegulatedAgent-KnownConsignor ICAO Annex 17 Chapter 4 - Cargo + Mail + Catering + Stores + Supplies Security + Regulated Agent + Known Consignor + Supply Chain

ISO/IEC 27003:2017 · 2 controls

  • ISO27003-6.1 Actions to address risks and opportunities
  • ISO27003-8.2 Information security risk assessment

ISO/IEC 27010:2015 · 2 controls

  • 27010-9.1 Access Control to Shared Information
  • 27010-9.2 Authentication of Sources

ISO/IEC 27011:2024 · 2 controls

  • 27011-5.3 Segregation of duties
  • 27011-8.1 User Endpoint Devices
  • 27557-4.3 Individual impact consideration
  • 27557-6.3 Privacy risk assessment
  • NIST-CSF-GV.RM-07 Strategic opportunities (i.e., positive risks) are characterized and are included in organizational cybersecurity risk discussions
  • NIST-CSF-ID.RA-09 The authenticity and integrity of hardware and software are assessed prior to acquisition and use

NIST SP 800-37 · 2 controls

  • NISTSP37-2 RMF Categorize Step: Information and System Categorisation
  • NISTSP37-3 RMF Select Step: Security and Privacy Control Selection
  • NISTSP82-2 OT Risk Assessment and Threat/Vulnerability Identification
  • NISTSP82-4 OT Access Control, Identity, Authentication, and Remote Access
  • NJDPA-2 Consumer Rights - Access, Correct, Delete, Portability, Appeal
  • NJDPA-7 Data Protection Assessments and Processor Contracts
  • NZISM-1 NZISM Governance, Documentation, and Classification System
  • NZISM-3 Personnel Security, Physical Security, and Cryptography
  • ORSA-S1 Guidance Manual Section 1: Description of the insurer's risk management framework
  • ORSA-S2 Guidance Manual Section 2: Insurer's assessment of risk exposures

PDPA Singapore · 2 controls

  • PDPASG-4 Children's Data, DPIA, and Privacy by Design
  • PDPASG-5 Protection, Accuracy, and Security of Personal Data

PDPA Thailand · 2 controls

  • PDPATH-4 DPIA, Privacy by Design, Children's Data
  • PDPATH-5 Security Measures and Data Protection

POPIA · 2 controls

  • POPIASA-4 Special Personal Information, Children, Information Quality, Documentation
  • POPIASA-5 Security Safeguards, Encryption, Access Control, Operator Obligations
  • NORWAY-4 DPIA, Privacy by Design, Records of Processing
  • NORWAY-5 Security of Processing, Encryption, Pseudonymization, Access Control

Privacy Act 2020 · 2 controls

  • NZPRV-2 IPP 5 Storage and Security of Personal Information
  • NZPRV-6 IPP 13 Unique Identifiers, Privacy Impact Assessment, Privacy by Design

Qatar DPL · 2 controls

  • QATAR-5 Security of Processing
  • QATAR-7 DPO, Records, Retention, Marketing, Training

SLSA · 2 controls

  • SUPCHAIN-1 Build Integrity - Source, Build, Provenance
  • SUPCHAIN-2 Source Integrity - Branch Protection, Code Review, Two-Person Rule
  • SOC-CY-DC5 Risk Assessment Process
  • SOC-CY-S1 Logical and Physical Access Controls
  • 2.4.4 Hazard Analysis and Risk Assessment
  • 2.7.2 Food Fraud Plan

Saudi Arabia PDPL · 2 controls

  • SA-PDPL-15 Access control for personal data
  • SA-PDPL-21 Data protection impact assessments
  • IM8-SEC.2 Access Control
  • IM8-SEC.4 Vulnerability Management

South Korea PIPA · 2 controls

  • PIPA-CPO-DPO-Privacy-Officer-PIA-Personal-Information-Impact-Assessment-Articles-31-33 Korea PIPA CPO + DPO + Privacy Officer + PIA + Personal Information Impact Assessment + Articles 31-33
  • PIPA-Cross-Border-Transfer-Articles-28-8-28-9-Adequacy-Standard-Contract-Certification-EU Korea PIPA Cross-Border Transfer + Articles 28-8 + 28-9 + Adequacy + EU 2021
  • TSAPIPE-1 Cybersecurity Implementation Plan and Coordinator
  • TSAPIPE-2 OT/IT Network Segmentation and Access Control
  • TEXASTDPSA-2 Consumer Rights
  • TEXASTDPSA-3 Sensitive Data, Children, Sale Notice
  • CRM-1 AML/CFT Compliance
  • CRM-4 Business Risk Assessment
  • SEMD-PS-2 Site Security Measures
  • SEMD-SP-2 Risk Identification and Assessment
  • UNESCO-AI-PA1 Ethical Impact Assessment
  • UNESCOAI-1 Principles 1-3: Proportionality, Safety, Fairness
  • CPSC-CS.2 Authentication and Access Controls
  • CPSC-RA.3 Lifecycle Risk Assessment

Uruguay DPL · 2 controls

  • URUGUAY-3 Sensitive Data, Health Data, Children
  • URUGUAY-5 Database Registration with AGESIC URCDP

Vietnam PDPD · 2 controls

  • VIETNAMPDP-2 Consent and Notice
  • VIETNAMPDP-3 Data Subject Rights
  • AMLCTF-PartA-RiskAssess ML/TF Risk Assessment

APPI · 1 control

  • APPI-A26 Report of Leakage to the Commission and Notification to the Person
  • CPS230-11 Identification, Assessment and Management of Operational Risk
  • SPS220-22 Framework Enabling Strategies, Policies, Procedures and Controls
  • 4.3.1 Risk Assessment and Impact Analysis
  • BB-DPA-20 Sections 50-60 - Registration and Responsibilities
  • CA-ITSG33-SC-01 Security Control Catalogue
  • CJIS-17 Risk Assessment
  • FTC-Safeguards-9-Elements 9 Safeguard Elements - Access, Inventory, Encryption, Secure-Dev, MFA, Disposal, Change-Mgmt, Monitoring, Pen-Test (16 CFR 314.4(c))

FedRAMP High · 1 control

  • RA-1 Policy and Procedures

FedRAMP Moderate · 1 control

  • RA-1 Policy and Procedures

GDPR · 1 control

  • IATA-IOSA-Section8-SEC-SecurityManagement-AVSEC IATA IOSA Section 8 - SEC Security Management + Aviation Security Programme (AVSEC) + ICAO Annex 17 Alignment
  • 62351-8 Role-based access control (RBAC)
  • ISO-22313-8.2 Business impact analysis and risk assessment
  • ISO-26262-3-7 Hazard analysis and risk assessment (HARA)
  • ISO28001-PS-01 Facility Security
  • ISO20000-15 Access management for services

ISO/IEC 27031:2011 · 1 control

  • 27031-7.2 Resource Requirements

ISO/IEC 29147:2018 · 1 control

  • 29147-5.11 Researcher Safe Harbour and Legal Posture

ITIL 4 · 1 control

  • ITIL4-15 Access management for services
  • NISTPF-5 Protect-P Access Control (PR.AC-P)

NIST SP 800-190 · 1 control

NIST SP 800-39 · 1 control

  • NISTSP39-3 Risk Assessing: Organisation, Mission, and System Level Assessments
  • NISTSP61-5 Containment, Eradication, and Recovery

NIST SP 800-63-4 · 1 control

  • NISTSP63R4-3 Authentication: Authenticator Types, MFA, Phishing-Resistance, and Syncable Authenticators

NIST SP 800-88 · 1 control

  • NISTSP88-1 Media Sanitization Policy, Roles, and Decision Framework

NIST SP 800-92 · 1 control

  • NISTSP92-4 Log Management: Time Synchronisation, Parsing, Storage, Integrity, Access Control
  • NRFCS-2 Risk Assessment, Customer Data Inventory, Classification, and Retail Threat Model
  • NGOB-1 Open Banking Registry Participation, Tiered Categorisation, and KYP
  • ORANWG11-2 O-RAN Interface Security: E2, A1, O1, O2, Open Fronthaul

OECD AI Principles · 1 control

  • OECDAI-3 Robustness, Security, Safety, and Adversarial Attack Protection

OWASP SAMM · 1 control

  • OWASPSAMM-2 Design: Threat Assessment, Security Requirements, Security Architecture
  • OMANCS-3 Identity and Access Management, Authentication, Privileged Access

OpenSSF Scorecard · 1 control

  • OSSFSC-3 Build, CI/CD Security, Workflow Permissions, Dangerous Patterns
  • OREGONCPA-5 Data Protection Assessments, Privacy by Design, Security Practices
  • PASONE-4 Technical Security: CDE Configuration, BIM Tools, Encryption, Aggregation, Mobile Working

PTES · 1 control

  • PTESPHASE-2 Intelligence Gathering (OSINT)

Peru DPL · 1 control

  • PERU-7 DPO, Records, Retention, Marketing, Training
  • PICERL-P2 Risk Assessment
  • SECCLIM-2 Risk Management: Identification, Assessment, Integration
  • SHAREASSESS-2 Access Control, Identity, Authentication

SOC 2 · 1 control

  • SOC2-CC6.3 CC6.3 Role-based access, least privilege and segregation of duties
  • SOCI-S30CU Vulnerability assessments
  • SIGSTORE-2 Transparency Log (Rekor) and Verification
  • SCA-S10 Annual Risk Assessment

Taiwan PDPA · 1 control

  • TAIWAN-3 Data Subject Rights
  • UKAI-1 Risk-Based Approach and Pro-Innovation Principles
  • Standard 2 Data Protection Impact Assessments
  • UKOPRES-3 Self-Assessment and Board Engagement
  • UKGDPRREG-3 Controller and Processor (Articles 24-43)
  • UKGAMBLE-4 Resilience and Incident Response
  • s.54(5) Statement Content Requirements
  • UK-TSA-NET-02 Access Control and Authentication
  • UNICEFAI-4 Transparency, Explanation, Adult Capacity
  • US-ITAR-EAR-DS-03 Access Controls

Virginia CDPA · 1 control

  • VIRGINIAVCDPA-3 Sensitive Data Consent and Children

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in NIST SP 1800-32: Access Management

Query this from an agent

The graph holds this control, the 281 it maps to, and the evidence behind each claim, over MCP and REST.