Frameworks / NIST SP 800-190 / NIST190-11 NIST SP 800-190
NIST SP 800-190: Data Protection in Cloud
NIST SP 800-190 NIST190-11: Data classification for cloud Data classification for cloud. Control from NIST SP 800-190 framework, domain: NIST SP 800-190: Data Protection in Cloud.
Maintained by Gerard Blokdyk · Verified against the published standard 31 May 2026 · Control text last updated 21 May 2026 What else in your programme already covers this This control maps to 193 controls across 86 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
CH-FADP-19 Transparency and proactive information CH-FADP-21 Data protection impact assessments FADP-16 FDPIC Independence and Functions FADP-7 Data Protection Impact Assessment (Articles 9-10) FADP-9 Data Protection Advisor (Articles 14-15) CFR211-G-122 Section 211.122 - Materials Examination and Usage Criteria CFR211-G-125 Section 211.125 - Labeling Issuance CFR211-G-130 Section 211.130 - Packaging and Labeling Operations AT-DSG-10 Section 29 - Liability and right to compensation / civil jurisdiction AT-DSG-12 Section 62 - Administrative penalties AT-DSG-7 Section 18 - Establishment of the Data Protection Authority ISO27799-03 Minimum necessary standard enforcement ISO27799-04 Patient data de-identification procedures ISO27799-05 Audit trail for ePHI access 27011-5.2 Information Security Roles in Telecoms 27011-6.3 Awareness and Training 27011-8.6 Data protection and backup NISTPF-4 Communicate-P - Privacy Notice, Transparency, and Individual Awareness NISTPF-7 Protect-P Maintenance and Protective Technology (PR.MA-P, PR.PT-P) NISTPF-8 Protect-P Information Protection Processes (PR.PO-P) IM8-DAT.1 Data Classification IM8-DAT.2 Data Protection IM8-DAT.4 Data Retention and Disposal TRINIDAD-1 Scope, Definitions, Commission TRINIDAD-4 Security, Accuracy TRINIDAD-5 Enforcement and Sanctions UGA-3 Accountability Principle UGA-6 Personal Data Protection Office UGA-7 Data Protection Officer AZ-DPA-15 Article 17 - Dispute resolution AZ-DPA-6 Article 6 - State regulation in personal data protection BB-DPA-1 Section 1 - Short Title BB-DPA-4 Section 4 - Principles Relating to Processing UAE-PDPL-Art.10 Data Protection Officer (DPO) (UAE PDPL Article 10) UAE-PDPL-Art.18_19_20_21 Security measures, controller/processor relationship, DPIA (UAE PDPL Articles 18-21) 27400-7.1 Network Security for IoT 27400-7.4 Data retention and deletion NDPA-1 Applicability, Scope, and Carve-Outs NDPA-4 Sensitive Data Processing Consent and Childrens Protections NJDPA-7 Data Protection Assessments and Processor Contracts NJDPA-8 AG Platkin Enforcement, 18-Month Cure Sunset, and Division of Consumer Affairs OECDAI-3 Robustness, Security, Safety, and Adversarial Attack Protection OECDAI-5 Data Governance, Training Data Quality, Privacy, and Bias Mitigation OREGONCPA-5 Data Protection Assessments, Privacy by Design, Security Practices OREGONCPA-8 Cure Period, Attorney General Enforcement, Training, Compliance Monitoring PDPASG-1 Accountability, Records, DPO Appointment, and Training PDPASG-4 Children's Data, DPIA, and Privacy by Design PDPATH-4 DPIA, Privacy by Design, Children's Data PDPATH-7 DPO, Records of Processing, Retention, Marketing, Training POPIASA-4 Special Personal Information, Children, Information Quality, Documentation POPIASA-7 Information Officer, Records of Processing, Notification, Training NORWAY-4 DPIA, Privacy by Design, Records of Processing NORWAY-7 DPO, Cooperation with Datatilsynet, Retention, Marketing, Training NZPRV-6 IPP 13 Unique Identifiers, Privacy Impact Assessment, Privacy by Design NZPRV-8 Privacy Officer, OPC Cooperation, Compliance Notices, Complaints, Training SA-PDPL-19 Data protection officer designation SA-PDPL-21 Data protection impact assessments SWE-1 Scope and Purpose SWE-2 Relationship to GDPR UKAI-1 Risk-Based Approach and Pro-Innovation Principles UKAI-2 Sector-Specific Regulator Engagement Standard 15 Online Tools Standard 2 Data Protection Impact Assessments UKGDPRREG-2 Data Subject Rights (Articles 12-22) UKGDPRREG-3 Controller and Processor (Articles 24-43) URUGUAY-4 Security and Cross-Border URUGUAY-5 Database Registration with AGESIC URCDP API1164-02 Risk Management Framework ASD37-27 Outbound data loss prevention (Very Good) AWWA-3.4 Encryption and Data Protection AL-DPA-14 Direct Marketing BSI-15 Security categorization CPG-3.C Strong and Agile Encryption QMSR-820.45 Device labelling and packaging controls (§820.45) FTC-Safeguards-9-Elements 9 Safeguard Elements - Access, Inventory, Encryption, Secure-Dev, MFA, Disposal, Change-Mgmt, Monitoring, Pen-Test (16 CFR 314.4(c)) FDBR-ControllerObligations-DPA-Notice Controller + Processor Obligations + Data Protection Assessments (Fla. Stat. 501.707, 501.708, 501.71, 501.711) 60601-1.7.1 Equipment identification and marking IEC62443-02 System security categorization ISO-14064-1-5.4 Categorization of indirect GHG emissions ISO-26000-6.7 Consumer issues ISO23894-A.5 Privacy and Data Protection in AI 27010-8.2 Membership Termination ISO27019-02 System security categorization ISO27043-08 Information classification and labeling ISO21434-08 Information classification and labeling NISTSP61-4 Detection and Analysis: Sources, Triage, Categorisation, Prioritisation NISTSP63R4-7 Privacy, Records Retention, and User-Controlled Wallets NISTSP66-6 Technical Safeguards: Access Control, Audit Controls, Integrity, Person Authentication NISTSP88-1 Media Sanitization Policy, Roles, and Decision Framework NISTSP92-7 Privacy in Logs, Sensitive Content Handling, Cloud and SaaS Log Considerations NRFCS-1 Retail Cybersecurity Governance, Policy, and Regulatory Change Management QRCM-1.3 Data Classification for Migration OWASPSAMM-2 Design: Threat Assessment, Security Requirements, Security Architecture OMANCS-4 Data Protection, Cryptography, and Privacy Alignment OSSFSC-2 Dependency Management, Pinning, Updates, Vulnerability Tracking PASONE-1 Security Triage Process, Asset Sensitivity Classification, and Threat Assessment PTESPHASE-1 Pre-Engagement Interactions and Scoping PARAGUAY-5 Security of Processing, Data Integrity, Information Security PERU-3 Data Subject Rights (ARCO), Habeas Data, Automated Decisions QATAR-7 DPO, Records, Retention, Marketing, Training SASB-SOC-7 Selling Practices and Product Labeling SHAREASSESS-2 Access Control, Identity, Authentication SUPCHAIN-1 Build Integrity - Source, Build, Provenance SOC-CY-C2 Encryption and Data Protection PIPA-CPO-DPO-Privacy-Officer-PIA-Personal-Information-Impact-Assessment-Articles-31-33 Korea PIPA CPO + DPO + Privacy Officer + PIA + Personal Information Impact Assessment + Articles 31-33 STUDPRV-2 Data Subject Rights for Students and Parents TEF-2 Openness and Transparency TISAXASS-3 Prototype Protection and Confidentiality TAIWAN-3 Data Subject Rights TANZANIA-1 Scope, Registration, Lawful Basis TSSR-INFO-1 Network Data Protection TEXASTDPSA-3 Sensitive Data, Children, Sale Notice D.1 Incident Response Planning UNESCOAI-2 Principles 4-7: Sustainability, Privacy, Human Oversight, Transparency UNICEFAI-4 Transparency, Explanation, Adult Capacity CPSC-CS.3 Data Protection for Safety Systems US-ITAR-EAR-DS-01 Technical Data Protection VIETNAMPDP-3 Data Subject Rights VIRGINIAVCDPA-3 Sensitive Data Consent and Children Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Other controls in NIST SP 800-190: Data Protection in Cloud Query this from an agent The graph holds this control, the 193 it maps to, and the evidence behind each claim, over MCP and REST.