Frameworks / NIST SP 800-122 / 5 NIST SP 800-122
Security Controls
NIST SP 800-122 5: PII Security Controls - Encryption, Access Control, Storage, Audit Apply Section 5 PII security controls aligned with NIST SP 800-53 PII-related controls: access control (AC family) including least privilege + role-based access + separation of duties; encryption of PII at rest (FIPS 140-3 + AES-256 + PQC migration per FIPS 203/204/205) and in transit (TLS 1.3); storage confidentiality including secure cloud + encrypted databases + tokenisation; auditing and accountability (AU family) including logging + monitoring + log retention; media protection (MP family) including secure handling + disposal + sanitisation per NIST SP 800-88.
What else in your programme already covers this This control maps to 284 controls across 94 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
APPI-A23 Security Control Measures APPI-A24 Supervision of Employees APPI-A26 Report of Leakage to the Commission and Notification to the Person APPI-A33 Request for Disclosure of Retained Personal Data APPI-A34 Request for Correction, Addition or Deletion GDPR-Art.10 Processing of personal data relating to criminal convictions GDPR-Art.11 Processing which does not require identification GDPR-Art.15 Right of access by the data subject GDPR-Art.19 Notification obligation regarding rectification, erasure or restriction GDPR-Art.9 Processing of special categories of personal data BSI-03 Multi-factor authentication requirements BSI-04 Remote access controls BSI-05 Wireless access restrictions BSI-08 Cryptographic protection of data UAE-PDPL-Art.10 Data Protection Officer (DPO) (UAE PDPL Article 10) UAE-PDPL-Art.18_19_20_21 Security measures, controller/processor relationship, DPIA (UAE PDPL Articles 18-21) UAE-PDPL-Art.4_5 Lawful basis and principles for processing personal data (UAE PDPL Articles 4-5) UAE-PDPL-Art.6_7 Sensitive personal data and children's data (UAE PDPL Articles 6-7) NISTPF-3 Control-P - Privacy Controls, Data Management, and Disassociated Processing NISTPF-4 Communicate-P - Privacy Notice, Transparency, and Individual Awareness NISTPF-5 Protect-P Access Control (PR.AC-P) NISTPF-7 Protect-P Maintenance and Protective Technology (PR.MA-P, PR.PT-P) NGOB-1 Open Banking Registry Participation, Tiered Categorisation, and KYP NGOB-2 Customer Consent Management and Lifecycle NGOB-3 API Security Standards, mTLS, and Encryption NGOB-5 Fraud Monitoring, Incident Notification, and Reporting to CBN APP-1 APP 1 - Open and transparent management of personal information APP-3 APP 3 - Collection of solicited personal information APP-5 APP 5 - Notification of the collection of personal information AT-DSG-11 Sections 42-45 - Data subject rights (law enforcement) AT-DSG-13 Section 36 - Scope of law enforcement processing AT-DSG-14 Section 38 - Lawfulness of law enforcement processing BB-DPA-14 Section 15 - Right to Data Portability BB-DPA-16 Section 22 - General Principle for Transfers BB-DPA-21 Sections 61-69 - Data Privacy Officer NJDPA-2 Consumer Rights - Access, Correct, Delete, Portability, Appeal NJDPA-7 Data Protection Assessments and Processor Contracts NJDPA-8 AG Platkin Enforcement, 18-Month Cure Sunset, and Division of Consumer Affairs OWASPTOP10-1 A01:2025 Broken Access Control OWASPTOP10-2 A02:2025 Cryptographic Failures and Secret Management OWASPTOP10-4 A04:2025 Insecure Design and Business Logic (incl. A11 API Abuse) CJIS-8 Media Protection CJIS-9 System and Communications Protection FTC-Safeguards-9-Elements 9 Safeguard Elements - Access, Inventory, Encryption, Secure-Dev, MFA, Disposal, Change-Mgmt, Monitoring, Pen-Test (16 CFR 314.4(c)) FTC-Safeguards-Scope-Defs Scope, Definitions and Financial Institution Applicability (16 CFR 314.1, 314.2) FDBR-ControllerObligations-DPA-Notice Controller + Processor Obligations + Data Protection Assessments (Fla. Stat. 501.707, 501.708, 501.71, 501.711) FDBR-Scope-Defs Scope, Applicability Thresholds and Definitions (Fla. Stat. 501.701, 501.702, 501.703, 501.704) 62351-8 Role-based access control (RBAC) 62351-9 Cyber security key management 6.6 Confidentiality or non-disclosure agreements 6.7 Conducting Audit Follow-up 6.6 Confidentiality or non-disclosure agreements 6.7 Conducting Audit Follow-up 9.1 Risk communication and consultation ISO20000-15 Access management for services 6.6 Confidentiality or non-disclosure agreements 6.7 Conducting Audit Follow-up OWASPAPI-1 Broken Object Level Authorization (BOLA) and BFLA OWASPAPI-6 Security Misconfiguration and Secure API Design AUPRV-4 APP 10-11 Quality, Security of Personal Information AUPRV-7 Notifiable Data Breaches (NDB) Scheme, Incident Response PSPF24-2 Information Security, Cybersecurity Maturity, Essential Eight PSPF24-4 Physical Security RUSPD-1 Scope, Definitions, Principles under 152-FZ RUSPD-4 Special Categories, Biometric Data 9.1 Risk communication and consultation ASD37-17 TLS encryption between email servers (Limited) DS-2 Ensure software supply chain security CA-10 Selects and Develops Control Activities 9.1 Risk communication and consultation STANAG-2 STANAG 4778 Metadata Binding Mechanism and Cryptographic Binding NISTSP34-3 Preventive Controls and Recovery Strategies: Backup, Alternate Sites, Equipment NZISM-3 Personnel Security, Physical Security, and Cryptography AUNDB-A3 Eligible Data Breach Determination and Serious Harm Threshold DSOMM-3 Build, Deployment, Infrastructure Hardening, and Secrets Management OWASPLLM-3 Sensitive Information Disclosure and Privacy (LLM02) PAKPDPB-8 Enforcement, Penalties, Complaints, Retention, Training RIDTPPA-2 Consumer Rights (Access, Correction, Deletion, Portability, Opt-Out) TEFCAREC-1 Common Agreement Conformance and Onboarding USCOPPA-3 Data Minimisation, Retention, Erasure (Eraser Button) USSDWA-2 Cybersecurity Practices (Assessment, Access, Network, IR) Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Query this from an agent The graph holds this control, the 284 it maps to, and the evidence behind each claim, over MCP and REST.