NIST SP 800-122
Governance and Continuous Monitoring

NIST SP 800-122 NISTSP122-8: Continuous Monitoring, Training, and Privacy Programme Governance

Apply Section 8 continuous monitoring of PII controls per NIST SP 800-137 + Information Security Continuous Monitoring (ISCM) + privacy continuous monitoring (PCM) integration. Conduct training and awareness programmes including role-based privacy training + annual refreshers + management body training. Designate Privacy Officer (Federal Chief Privacy Officer or Senior Agency Official for Privacy SAOP) per OMB M-22-09. Maintain Records of Processing Activities + Data Protection Impact Assessments + regulatory reporting + compliance monitoring + privacy budget + accountability per OMB Circular A-130.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 215 controls across 73 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

Bahrain PDPL · 6 controls

  • UAE-PDPL-Art.10 Data Protection Officer (DPO) (UAE PDPL Article 10)
  • UAE-PDPL-Art.18_19_20_21 Security measures, controller/processor relationship, DPIA (UAE PDPL Articles 18-21)
  • UAE-PDPL-Art.25_26_27_28_29 UAE Data Office establishment, powers, penalties, complaints (UAE PDPL Articles 25-29)
  • UAE-PDPL-FreeZones Coordination with DIFC, ADGM and sectoral data protection regimes
  • UAE-PDPL-Status UAE PDPL status, executive regulations, UAE Data Office guidance evolution

ISO/IEC 23894:2023 · 5 controls

  • ISO23894-6.3 AI Risk Assessment
  • ISO23894-6.3.1 AI Risk Identification
  • ISO23894-6.3.3 AI Risk Evaluation
  • ISO23894-A.1 Data Quality and Representativeness
  • ISO23894-A.5 Privacy and Data Protection in AI

ISO 27799:2025 · 4 controls

  • ISO27799-03 Minimum necessary standard enforcement
  • ISO27799-04 Patient data de-identification procedures
  • ISO27799-05 Audit trail for ePHI access
  • ISO27799-06 Security management process and risk analysis
  • AUPRV-1 APP 1 Open and Transparent Management + Privacy Management Framework
  • AUPRV-4 APP 10-11 Quality, Security of Personal Information
  • AUPRV-6 Sensitive Information, PIA, Privacy by Design, Children
  • AUPRV-8 OAIC Cooperation, Vendor Management, Training, Complaints, Enforcement
  • IM8-DAT.2 Data Protection
  • IM8-DAT.4 Data Retention and Disposal
  • IM8-DSS.3 Secure Development Practices
  • IM8-SEC.4 Vulnerability Management
  • AT-DSG-10 Section 29 - Liability and right to compensation / civil jurisdiction
  • AT-DSG-12 Section 62 - Administrative penalties
  • AT-DSG-7 Section 18 - Establishment of the Data Protection Authority

BSI IT-Grundschutz · 3 controls

  • BSI-13 Risk assessment procedures
  • BSI-15 Security categorization
  • BSI-17 Continuous monitoring strategy
  • BB-DPA-1 Section 1 - Short Title
  • BB-DPA-20 Sections 50-60 - Registration and Responsibilities
  • BB-DPA-4 Section 4 - Principles Relating to Processing

GDPR · 3 controls

  • ISO-25012-5.1 Establishing data quality requirements
  • ISO-25012-5.2 Defining data quality measures
  • ISO-25012-5.3 Planning and performing data quality evaluations

ISO/IEC 27011:2024 · 3 controls

  • 27011-5.2 Information Security Roles in Telecoms
  • 27011-6.3 Awareness and Training
  • 27011-8.6 Data protection and backup

ISO/IEC 27400:2022 · 3 controls

  • 27400-6.3 Secure Update Mechanism
  • 27400-7.1 Network Security for IoT
  • 27400-7.4 Data retention and deletion

ISO/IEC 29134:2023 · 3 controls

  • 29134-1 Scope
  • 29134-3 Terms and definitions
  • 29134-9.1 PIA report structure
  • NIST-CSF-GV.RM-07 Strategic opportunities (i.e., positive risks) are characterized and are included in organizational cybersecurity risk discussions
  • NIST-CSF-ID.RA-09 The authenticity and integrity of hardware and software are assessed prior to acquisition and use
  • NIST-CSF-PR.PS-06 Secure software development practices are integrated, and their performance is monitored throughout the software development life cycle
  • NISTPF-4 Communicate-P - Privacy Notice, Transparency, and Individual Awareness
  • NISTPF-7 Protect-P Maintenance and Protective Technology (PR.MA-P, PR.PT-P)
  • NISTPF-8 Protect-P Information Protection Processes (PR.PO-P)
  • NJDPA-6 Reasonable Data Security and Incident Response
  • NJDPA-7 Data Protection Assessments and Processor Contracts
  • NJDPA-8 AG Platkin Enforcement, 18-Month Cure Sunset, and Division of Consumer Affairs
  • NZISM-1 NZISM Governance, Documentation, and Classification System
  • NZISM-2 Certification and Accreditation (C&A) for Government Systems
  • NZISM-3 Personnel Security, Physical Security, and Cryptography
  • DSOMM-2 Implementation Practices, Secure Coding, and Threat Modelling
  • DSOMM-4 Test and Verification - SAST, DAST, IAST, SCA, Penetration Testing
  • DSOMM-6 Metrics, Maturity Measurement, and Continuous Improvement

South Korea PIPA · 3 controls

  • PIPA-CPO-DPO-Privacy-Officer-PIA-Personal-Information-Impact-Assessment-Articles-31-33 Korea PIPA CPO + DPO + Privacy Officer + PIA + Personal Information Impact Assessment + Articles 31-33
  • PIPA-Cross-Border-Transfer-Articles-28-8-28-9-Adequacy-Standard-Contract-Certification-EU Korea PIPA Cross-Border Transfer + Articles 28-8 + 28-9 + Adequacy + EU 2021
  • PIPA-Pseudonymisation-Article-28-2-3-Enforcement-PIPC-Investigation-Surcharges-3-Percent-Revenue-Article64-2 Korea PIPA Pseudonymisation + Article 28-2 + Enforcement + PIPC + Surcharges 3% + Article 63 + 64-2

API 1164 · 2 controls

  • API1164-07 Remote Access
  • API1164-24 Vulnerability assessment for critical systems
  • AWWA-1.2 Risk Assessment
  • AWWA-3.4 Encryption and Data Protection
  • AL-DPA-14 Direct Marketing
  • AL-DPA-7 Right of Access
  • AZ-DPA-15 Article 17 - Dispute resolution
  • AZ-DPA-6 Article 6 - State regulation in personal data protection
  • DIQ-2 Data Quality Management
  • DIQ-3 Metadata Management
  • IS.D.OR.205 Information Security Risk Assessment
  • IS.I.OR.205 Information Security Risk Assessment
  • Sapin2-Pillar3-Risk-Mapping Pillar 3 - Corruption Risk Mapping (Cartographie des Risques)
  • Sapin2-Pillar4-ThirdParty-DueDiligence Pillar 4 - Third-Party Due Diligence (Clients, Suppliers, Intermediaries, M&A)
  • ICAO-ANX17-Chap2-ThreatAssessment-RiskManagement-Cyber-GASeP ICAO Annex 17 Chapter 2 - Threat Assessment + Risk Management + Cyber Threats to Critical Aviation Systems (Amendment 17/18)
  • ICAO-ANX17-Chap4-Cargo-Mail-Catering-Stores-Supplies-RegulatedAgent-KnownConsignor ICAO Annex 17 Chapter 4 - Cargo + Mail + Catering + Stores + Supplies Security + Regulated Agent + Known Consignor + Supply Chain

IEC 62443 · 2 controls

  • IEC62443-07 Personnel risk assessment
  • IEC62443-24 Vulnerability assessment for critical systems

ISO/IEC 27003:2017 · 2 controls

  • ISO27003-6.1 Actions to address risks and opportunities
  • ISO27003-8.2 Information security risk assessment

ISO/IEC 27019:2024 · 2 controls

  • ISO27019-07 Personnel risk assessment
  • ISO27019-24 Vulnerability assessment for critical systems
  • 27557-4.3 Individual impact consideration
  • 27557-6.3 Privacy risk assessment
  • NDPA-1 Applicability, Scope, and Carve-Outs
  • NDPA-4 Sensitive Data Processing Consent and Childrens Protections
  • ASTWO-1 Audit Planning, Scaling, Risk Assessment, and Integration
  • ASTWO-3 Entity-Level Controls and Period-End Financial Reporting Process
  • PAKPDPB-6 Cross-Border Transfer and Data Localization
  • PAKPDPB-7 NCPDP, Registration, Records, Processor Contracts, DPO
  • EHDS-HOLD-3 Dataset Descriptions and Catalogues
  • EHDSREG-5 Cross-Border Health Data Flows
  • 2.4.4 Hazard Analysis and Risk Assessment
  • 2.7.2 Food Fraud Plan

South Korea ISMS-P · 2 controls

  • ISMSP-MS-02 Risk Management
  • ISMSP-SYS-04 Vulnerability Management

Turkey KVKK · 2 controls

  • TURKEYKVKK-2 Information Notice and Data Subject Rights
  • TURKEYKVKK-3 Special Categories and Sensitive Data
  • CRM-1 AML/CFT Compliance
  • CRM-4 Business Risk Assessment
  • D.1 Incident Response Planning
  • UKDEFSTD-1 Cyber Defence Cyber Risk Profile (CRP)
  • CPSC-CS.3 Data Protection for Safety Systems
  • CPSC-RA.3 Lifecycle Risk Assessment
  • VERMONTAICDA-3 Bias Testing, Discrimination Prevention, Transparency
  • VERMONTAICDA-4 Vermont AG Enforcement and Cure
  • AMLCTF-PartA-RiskAssess ML/TF Risk Assessment

APPI · 1 control

  • APPI-A31 Provision of Personally Referable Information
  • CPS230-11 Identification, Assessment and Management of Operational Risk
  • ASD37-27 Outbound data loss prevention (Very Good)
  • 4.3.1 Risk Assessment and Impact Analysis
  • CJIS-17 Risk Assessment
  • FFIEC-08 Application security controls
  • FTC-Safeguards-9-Elements 9 Safeguard Elements - Access, Inventory, Encryption, Secure-Dev, MFA, Disposal, Change-Mgmt, Monitoring, Pen-Test (16 CFR 314.4(c))

FedRAMP High · 1 control

  • AC-2 Account Management

FedRAMP Moderate · 1 control

  • AC-2 Account Management
  • FDBR-ControllerObligations-DPA-Notice Controller + Processor Obligations + Data Protection Assessments (Fla. Stat. 501.707, 501.708, 501.71, 501.711)
  • ISO-22313-8.2 Business impact analysis and risk assessment

ISO 26000:2010 · 1 control

  • ISO-26000-6.7 Consumer issues
  • ISO-26262-3-7 Hazard analysis and risk assessment (HARA)

ISO/IEC 27031:2011 · 1 control

  • 27031-7.2 Resource Requirements

ISO/IEC 29147:2018 · 1 control

  • 29147-5.11 Researcher Safe Harbour and Legal Posture
  • NISTSP34-1 Contingency Planning Policy, Programme, and Plan Coordination
  • NGOB-1 Open Banking Registry Participation, Tiered Categorisation, and KYP
  • RUSPD-4 Special Categories, Biometric Data
  • AIGF-1.3 Data Management
  • VIETNAMCYBER-4 Incident Reporting and Cooperation

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 215 it maps to, and the evidence behind each claim, over MCP and REST.