Frameworks / NIST SP 800-144 / NISTSP144-5 NIST SP 800-144
Identity and Access
NIST SP 800-144 NISTSP144-5: Identity and Access in Cloud, Federation, and Privileged Access Apply Section 7.3 identity and access in cloud including: federated identity (SAML 2.0 + OAuth 2.0 + OIDC + WS-Federation) with an identity provider (IdP) + MFA (FIDO2 + WebAuthn + TOTP + biometric) + Single Sign-On (SSO) + risk-based authentication. Implement privileged access (PAM + JIT access + bastion hosts + session recording + just-enough-access JEA) + secrets management + service accounts + managed identities + RBAC + ABAC + policy-as-code.
Maintained by Gerard Blokdyk · Verified against the published standard 31 May 2026 · Control text last updated 21 May 2026 What else in your programme already covers this This control maps to 176 controls across 62 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
CH-FADP-13 Right to object and request blocking CH-FADP-19 Transparency and proactive information CH-FADP-21 Data protection impact assessments FADP-16 FDPIC Independence and Functions FADP-7 Data Protection Impact Assessment (Articles 9-10) FADP-9 Data Protection Advisor (Articles 14-15) ISO27799-02 ePHI encryption at rest and in transit ISO27799-03 Minimum necessary standard enforcement ISO27799-04 Patient data de-identification procedures ISO27799-05 Audit trail for ePHI access ISO27799-16 Transmission security and encryption ISO27043-08 Information classification and labeling ISO27043-17 Encryption of data at rest ISO27043-18 Encryption of data in transit ISO27043-19 Certificate management ISO27043-20 Key lifecycle management ISO21434-08 Information classification and labeling ISO21434-16 Cryptographic policy and key management ISO21434-17 Encryption of data at rest ISO21434-18 Encryption of data in transit ISO21434-19 Certificate management 27011-5.2 Information Security Roles in Telecoms 27011-6.3 Awareness and Training 27011-8.3 Cryptography and key management 27011-8.6 Data protection and backup IM8-CLD.2 Cloud Security Controls IM8-DAT.1 Data Classification IM8-DAT.2 Data Protection IM8-DAT.4 Data Retention and Disposal CFR211-G-122 Section 211.122 - Materials Examination and Usage Criteria CFR211-G-125 Section 211.125 - Labeling Issuance CFR211-G-130 Section 211.130 - Packaging and Labeling Operations AT-DSG-10 Section 29 - Liability and right to compensation / civil jurisdiction AT-DSG-12 Section 62 - Administrative penalties AT-DSG-7 Section 18 - Establishment of the Data Protection Authority FEDRAMP-SC-13 Cryptographic Protection FEDRAMP-SC-28 Protection of Information at Rest FEDRAMP-SC-8 Transmission Confidentiality and Integrity UAE-PDPL-Art.10 Data Protection Officer (DPO) (UAE PDPL Article 10) UAE-PDPL-Art.18_19_20_21 Security measures, controller/processor relationship, DPIA (UAE PDPL Articles 18-21) UAE-PDPL-Art.4_5 Lawful basis and principles for processing personal data (UAE PDPL Articles 4-5) 23837-1.2 Normative references 23837-1.5.2 Cryptographic module requirements 23837-1.5.3 Network device testing requirements 27400-6.2 Device Identity and Authentication 27400-7.1 Network Security for IoT 27400-7.4 Data retention and deletion NISTPF-4 Communicate-P - Privacy Notice, Transparency, and Individual Awareness NISTPF-7 Protect-P Maintenance and Protective Technology (PR.MA-P, PR.PT-P) NISTPF-8 Protect-P Information Protection Processes (PR.PO-P) AUPRV-1 APP 1 Open and Transparent Management + Privacy Management Framework AUPRV-4 APP 10-11 Quality, Security of Personal Information AUPRV-6 Sensitive Information, PIA, Privacy by Design, Children ASD37-17 TLS encryption between email servers (Limited) ASD37-27 Outbound data loss prevention (Very Good) AWWA-3.2 Remote Access Security AWWA-3.4 Encryption and Data Protection AZ-DPA-15 Article 17 - Dispute resolution AZ-DPA-6 Article 6 - State regulation in personal data protection BSI-08 Cryptographic protection of data BSI-15 Security categorization BB-DPA-1 Section 1 - Short Title BB-DPA-4 Section 4 - Principles Relating to Processing CJIS-8 Media Protection CJIS-9 System and Communications Protection 27010-10.1 Cryptographic Protection 27010-8.2 Membership Termination NDPA-1 Applicability, Scope, and Carve-Outs NDPA-4 Sensitive Data Processing Consent and Childrens Protections NJDPA-7 Data Protection Assessments and Processor Contracts NJDPA-8 AG Platkin Enforcement, 18-Month Cure Sunset, and Division of Consumer Affairs OWASPTOP10-2 A02:2025 Cryptographic Failures and Secret Management OWASPTOP10-4 A04:2025 Insecure Design and Business Logic (incl. A11 API Abuse) PAKPDPB-6 Cross-Border Transfer and Data Localization PAKPDPB-7 NCPDP, Registration, Records, Processor Contracts, DPO TURKEYKVKK-2 Information Notice and Data Subject Rights TURKEYKVKK-3 Special Categories and Sensitive Data VERMONTAICDA-3 Bias Testing, Discrimination Prevention, Transparency VERMONTAICDA-4 Vermont AG Enforcement and Cure API1164-02 Risk Management Framework APPI-A34 Request for Correction, Addition or Deletion AL-DPA-14 Direct Marketing QMSR-820.45 Device labelling and packaging controls (§820.45) FFIEC-09 Encryption and key management FTC-Safeguards-9-Elements 9 Safeguard Elements - Access, Inventory, Encryption, Secure-Dev, MFA, Disposal, Change-Mgmt, Monitoring, Pen-Test (16 CFR 314.4(c)) FDBR-ControllerObligations-DPA-Notice Controller + Processor Obligations + Data Protection Assessments (Fla. Stat. 501.707, 501.708, 501.71, 501.711) 60601-1.7.1 Equipment identification and marking 62351-9 Cyber security key management IEC62443-02 System security categorization ISO-14064-1-5.4 Categorization of indirect GHG emissions ISO-26000-6.7 Consumer issues ISO23894-A.5 Privacy and Data Protection in AI ISO27019-02 System security categorization 29115-7.4 Level of Assurance 4 (LoA4) STANAG-2 STANAG 4778 Metadata Binding Mechanism and Cryptographic Binding NISTSP34-3 Preventive Controls and Recovery Strategies: Backup, Alternate Sites, Equipment NZISM-3 Personnel Security, Physical Security, and Cryptography NGOB-3 API Security Standards, mTLS, and Encryption OWASPAPI-6 Security Misconfiguration and Secure API Design PSPF24-2 Information Security, Cybersecurity Maturity, Essential Eight RUSPD-4 Special Categories, Biometric Data ISMSP-SYS-02 Encryption Implementation PIPA-CPO-DPO-Privacy-Officer-PIA-Personal-Information-Impact-Assessment-Articles-31-33 Korea PIPA CPO + DPO + Privacy Officer + PIA + Personal Information Impact Assessment + Articles 31-33 D.1 Incident Response Planning CPSC-CS.3 Data Protection for Safety Systems VIETNAMCYBER-4 Incident Reporting and Cooperation Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Query this from an agent The graph holds this control, the 176 it maps to, and the evidence behind each claim, over MCP and REST.