Frameworks / NIST SP 800-122 / NISTSP122-5 NIST SP 800-122
Security Controls
NIST SP 800-122 NISTSP122-5: PII Security Controls - Encryption, Access Control, Storage, Audit Apply Section 5 PII security controls aligned with NIST SP 800-53 PII-related controls: access control (AC family) including least privilege + role-based access + separation of duties; encryption of PII at rest (FIPS 140-3 + AES-256 + PQC migration per FIPS 203/204/205) and in transit (TLS 1.3); storage confidentiality including secure cloud + encrypted databases + tokenisation; auditing and accountability (AU family) including logging + monitoring + log retention; media protection (MP family) including secure handling + disposal + sanitisation per NIST SP 800-88.
Maintained by Gerard Blokdyk · Verified against the published standard 31 May 2026 · Control text last updated 21 May 2026 What else in your programme already covers this This control maps to 260 controls across 81 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
ISO27043-11 Access control policy and enforcement ISO27043-14 Privileged access management ISO27043-15 Access review and recertification ISO27043-17 Encryption of data at rest ISO27043-18 Encryption of data in transit ISO27043-19 Certificate management ISO27043-20 Key lifecycle management ISO21434-12 User access management and provisioning ISO21434-14 Privileged access management ISO21434-15 Access review and recertification ISO21434-16 Cryptographic policy and key management ISO21434-17 Encryption of data at rest ISO21434-18 Encryption of data in transit ISO21434-19 Certificate management APPI-A23 Security Control Measures APPI-A24 Supervision of Employees APPI-A26 Report of Leakage to the Commission and Notification to the Person APPI-A33 Request for Disclosure of Retained Personal Data APPI-A34 Request for Correction, Addition or Deletion GDPR-Art.10 Processing of personal data relating to criminal convictions GDPR-Art.11 Processing which does not require identification GDPR-Art.15 Right of access by the data subject GDPR-Art.19 Notification obligation regarding rectification, erasure or restriction GDPR-Art.9 Processing of special categories of personal data ISO27799-01 ePHI access controls and authorization ISO27799-02 ePHI encryption at rest and in transit ISO27799-08 Information access management ISO27799-16 Transmission security and encryption ISO27799-17 Facility access controls ISMSP-AC-01 Access Control Policy ISMSP-AC-04 Network Access Control ISMSP-PI-01 Personal Information Collection ISMSP-PI-04 Cross-Border Transfer ISMSP-SYS-02 Encryption Implementation AWWA-2.1 User Access Management AWWA-2.4 Physical Access Controls AWWA-3.2 Remote Access Security AWWA-3.4 Encryption and Data Protection BSI-03 Multi-factor authentication requirements BSI-04 Remote access controls BSI-05 Wireless access restrictions BSI-08 Cryptographic protection of data UAE-PDPL-Art.10 Data Protection Officer (DPO) (UAE PDPL Article 10) UAE-PDPL-Art.18_19_20_21 Security measures, controller/processor relationship, DPIA (UAE PDPL Articles 18-21) UAE-PDPL-Art.4_5 Lawful basis and principles for processing personal data (UAE PDPL Articles 4-5) UAE-PDPL-Art.6_7 Sensitive personal data and children's data (UAE PDPL Articles 6-7) NISTPF-3 Control-P - Privacy Controls, Data Management, and Disassociated Processing NISTPF-4 Communicate-P - Privacy Notice, Transparency, and Individual Awareness NISTPF-5 Protect-P Access Control (PR.AC-P) NISTPF-7 Protect-P Maintenance and Protective Technology (PR.MA-P, PR.PT-P) NGOB-1 Open Banking Registry Participation, Tiered Categorisation, and KYP NGOB-2 Customer Consent Management and Lifecycle NGOB-3 API Security Standards, mTLS, and Encryption NGOB-5 Fraud Monitoring, Incident Notification, and Reporting to CBN API1164-06 Access Control API1164-07 Remote Access API1164-09 Patch and Vulnerability Management APP-1 APP 1 - Open and transparent management of personal information APP-3 APP 3 - Collection of solicited personal information APP-5 APP 5 - Notification of the collection of personal information AT-DSG-11 Sections 42-45 - Data subject rights (law enforcement) AT-DSG-13 Section 36 - Scope of law enforcement processing AT-DSG-14 Section 38 - Lawfulness of law enforcement processing AZ-DPA-12 Article 13 - Cross-border transfer AZ-DPA-14 Article 16 - Liability for violations AZ-DPA-15 Article 17 - Dispute resolution BB-DPA-14 Section 15 - Right to Data Portability BB-DPA-16 Section 22 - General Principle for Transfers BB-DPA-21 Sections 61-69 - Data Privacy Officer FEDRAMP-SC-13 Cryptographic Protection FEDRAMP-SC-28 Protection of Information at Rest FEDRAMP-SC-8 Transmission Confidentiality and Integrity IEC62443-07 Personnel risk assessment IEC62443-08 Electronic access perimeter management IEC62443-10 Revocation of access procedures 23837-1.2 Normative references 23837-1.5.2 Cryptographic module requirements 23837-1.5.3 Network device testing requirements 27010-10.1 Cryptographic Protection 27010-9.1 Access Control to Shared Information 27010-9.2 Authentication of Sources 27011-5.3 Segregation of duties 27011-8.1 User Endpoint Devices 27011-8.3 Cryptography and key management ISO27019-07 Personnel risk assessment ISO27019-08 Electronic access perimeter management ISO27019-10 Revocation of access procedures 27400-5.4 Data and privacy risks 27400-6.2 Device Identity and Authentication 27400-7.3 Data minimization and purpose limitation 29100-6.10 Information security 29100-6.5 Use, retention and disclosure limitation 29100-6.9 Accountability 29134-1 Scope 29134-3 Terms and definitions 29134-9.1 PIA report structure NJDPA-2 Consumer Rights - Access, Correct, Delete, Portability, Appeal NJDPA-7 Data Protection Assessments and Processor Contracts NJDPA-8 AG Platkin Enforcement, 18-Month Cure Sunset, and Division of Consumer Affairs OWASPTOP10-1 A01:2025 Broken Access Control OWASPTOP10-2 A02:2025 Cryptographic Failures and Secret Management OWASPTOP10-4 A04:2025 Insecure Design and Business Logic (incl. A11 API Abuse) DSO-2 Data Security DSO-3 Data Access Management CJIS-8 Media Protection CJIS-9 System and Communications Protection CAT-D3-1 Preventative controls CAT-D4-3 Third-party access controls FTC-Safeguards-9-Elements 9 Safeguard Elements - Access, Inventory, Encryption, Secure-Dev, MFA, Disposal, Change-Mgmt, Monitoring, Pen-Test (16 CFR 314.4(c)) FTC-Safeguards-Scope-Defs Scope, Definitions and Financial Institution Applicability (16 CFR 314.1, 314.2) FDBR-ControllerObligations-DPA-Notice Controller + Processor Obligations + Data Protection Assessments (Fla. Stat. 501.707, 501.708, 501.71, 501.711) FDBR-Scope-Defs Scope, Applicability Thresholds and Definitions (Fla. Stat. 501.701, 501.702, 501.703, 501.704) 62351-8 Role-based access control (RBAC) 62351-9 Cyber security key management 27557-3 Terms and definitions 27557-4.3 Individual impact consideration OWASPAPI-1 Broken Object Level Authorization (BOLA) and BFLA OWASPAPI-6 Security Misconfiguration and Secure API Design AUPRV-4 APP 10-11 Quality, Security of Personal Information AUPRV-7 Notifiable Data Breaches (NDB) Scheme, Incident Response PSPF24-2 Information Security, Cybersecurity Maturity, Essential Eight PSPF24-4 Physical Security RUSPD-1 Scope, Definitions, Principles under 152-FZ RUSPD-4 Special Categories, Biometric Data IM8-CLD.2 Cloud Security Controls IM8-SEC.2 Access Control PIPA-Cross-Border-Transfer-Articles-28-8-28-9-Adequacy-Standard-Contract-Certification-EU Korea PIPA Cross-Border Transfer + Articles 28-8 + 28-9 + Adequacy + EU 2021 PIPA-Data-Subject-Rights-Access-Correction-Erasure-Portability-Automated-Decisions-Articles-35-37-2 Korea PIPA Data Subject Rights + Access + Correction + Erasure + Portability + Article 35-37 USMCADIGITAL-1 Cross-Border Data Flows and Localisation USMCADIGITAL-2 Personal Information Protection and Consumer Protection VIETNAMCYBER-2 Prohibited Acts (Access, Interception, Forgery, Content) VIETNAMCYBER-4 Incident Reporting and Cooperation ASD37-17 TLS encryption between email servers (Limited) AL-DPA-12 International Data Transfers DS-2 Ensure software supply chain security CA-10 Selects and Develops Control Activities CA-ITSG33-SC-01 Security Control Catalogue FFIEC-09 Encryption and key management IATA-IOSA-Section8-SEC-SecurityManagement-AVSEC IATA IOSA Section 8 - SEC Security Management + Aviation Security Programme (AVSEC) + ICAO Annex 17 Alignment ICAO-ANX17-Chap2-ThreatAssessment-RiskManagement-Cyber-GASeP ICAO Annex 17 Chapter 2 - Threat Assessment + Risk Management + Cyber Threats to Critical Aviation Systems (Amendment 17/18) ISO28001-PS-01 Facility Security ISO20000-15 Access management for services ISO23894-A.5 Privacy and Data Protection in AI 29115-7.4 Level of Assurance 4 (LoA4) ITIL4-15 Access management for services STANAG-2 STANAG 4778 Metadata Binding Mechanism and Cryptographic Binding NISTSP34-3 Preventive Controls and Recovery Strategies: Backup, Alternate Sites, Equipment NZISM-3 Personnel Security, Physical Security, and Cryptography AUNDB-A3 Eligible Data Breach Determination and Serious Harm Threshold DSOMM-3 Build, Deployment, Infrastructure Hardening, and Secrets Management OWASPLLM-3 Sensitive Information Disclosure and Privacy (LLM02) PAKPDPB-8 Enforcement, Penalties, Complaints, Retention, Training RIDTPPA-2 Consumer Rights (Access, Correction, Deletion, Portability, Opt-Out) TEFCAREC-1 Common Agreement Conformance and Onboarding TURKEYKVKK-2 Information Notice and Data Subject Rights CPSC-CS.2 Authentication and Access Controls USSDWA-2 Cybersecurity Practices (Assessment, Access, Network, IR) VERMONTAICDA-3 Bias Testing, Discrimination Prevention, Transparency Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Query this from an agent The graph holds this control, the 260 it maps to, and the evidence behind each claim, over MCP and REST.