Frameworks / NIST SP 800-190 / NIST190-12 NIST SP 800-190
NIST SP 800-190: Data Protection in Cloud
NIST SP 800-190 NIST190-12: Encryption of cloud-stored data Encryption of cloud-stored data. Control from NIST SP 800-190 framework, domain: NIST SP 800-190: Data Protection in Cloud.
Maintained by Gerard Blokdyk · Verified against the published standard 31 May 2026 · Control text last updated 21 May 2026 What else in your programme already covers this This control maps to 281 controls across 102 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
CH-FADP-13 Right to object and request blocking CH-FADP-19 Transparency and proactive information CH-FADP-21 Data protection impact assessments FADP-16 FDPIC Independence and Functions FADP-7 Data Protection Impact Assessment (Articles 9-10) FADP-9 Data Protection Advisor (Articles 14-15) ISO27799-02 ePHI encryption at rest and in transit ISO27799-03 Minimum necessary standard enforcement ISO27799-04 Patient data de-identification procedures ISO27799-05 Audit trail for ePHI access ISO27799-16 Transmission security and encryption 27011-5.2 Information Security Roles in Telecoms 27011-6.3 Awareness and Training 27011-8.3 Cryptography and key management 27011-8.6 Data protection and backup ISO27043-17 Encryption of data at rest ISO27043-18 Encryption of data in transit ISO27043-19 Certificate management ISO27043-20 Key lifecycle management ISO21434-16 Cryptographic policy and key management ISO21434-17 Encryption of data at rest ISO21434-18 Encryption of data in transit ISO21434-19 Certificate management AT-DSG-10 Section 29 - Liability and right to compensation / civil jurisdiction AT-DSG-12 Section 62 - Administrative penalties AT-DSG-7 Section 18 - Establishment of the Data Protection Authority FEDRAMP-SC-13 Cryptographic Protection FEDRAMP-SC-28 Protection of Information at Rest FEDRAMP-SC-8 Transmission Confidentiality and Integrity UAE-PDPL-Art.10 Data Protection Officer (DPO) (UAE PDPL Article 10) UAE-PDPL-Art.18_19_20_21 Security measures, controller/processor relationship, DPIA (UAE PDPL Articles 18-21) UAE-PDPL-Art.4_5 Lawful basis and principles for processing personal data (UAE PDPL Articles 4-5) 23837-1.2 Normative references 23837-1.5.2 Cryptographic module requirements 23837-1.5.3 Network device testing requirements 27400-6.2 Device Identity and Authentication 27400-7.1 Network Security for IoT 27400-7.4 Data retention and deletion NISTPF-4 Communicate-P - Privacy Notice, Transparency, and Individual Awareness NISTPF-7 Protect-P Maintenance and Protective Technology (PR.MA-P, PR.PT-P) NISTPF-8 Protect-P Information Protection Processes (PR.PO-P) QRCM-1.2 Quantum-Vulnerable Identification QRCM-3.1 Hybrid Solution Deployment (2025-2030) QRCM-4.2 TLS 1.3 Adoption OREGONCPA-5 Data Protection Assessments, Privacy by Design, Security Practices OREGONCPA-7 Processor Contracts, Cross-Border Transfers, DPAs OREGONCPA-8 Cure Period, Attorney General Enforcement, Training, Compliance Monitoring PDPASG-1 Accountability, Records, DPO Appointment, and Training PDPASG-4 Children's Data, DPIA, and Privacy by Design PDPASG-5 Protection, Accuracy, and Security of Personal Data PDPATH-4 DPIA, Privacy by Design, Children's Data PDPATH-5 Security Measures and Data Protection PDPATH-7 DPO, Records of Processing, Retention, Marketing, Training POPIASA-4 Special Personal Information, Children, Information Quality, Documentation POPIASA-5 Security Safeguards, Encryption, Access Control, Operator Obligations POPIASA-7 Information Officer, Records of Processing, Notification, Training NORWAY-4 DPIA, Privacy by Design, Records of Processing NORWAY-5 Security of Processing, Encryption, Pseudonymization, Access Control NORWAY-7 DPO, Cooperation with Datatilsynet, Retention, Marketing, Training NZPRV-2 IPP 5 Storage and Security of Personal Information NZPRV-6 IPP 13 Unique Identifiers, Privacy Impact Assessment, Privacy by Design NZPRV-8 Privacy Officer, OPC Cooperation, Compliance Notices, Complaints, Training SA-PDPL-13 Encryption of personal data SA-PDPL-19 Data protection officer designation SA-PDPL-21 Data protection impact assessments IM8-CLD.2 Cloud Security Controls IM8-DAT.2 Data Protection IM8-DAT.4 Data Retention and Disposal TRINIDAD-1 Scope, Definitions, Commission TRINIDAD-4 Security, Accuracy TRINIDAD-5 Enforcement and Sanctions UGA-3 Accountability Principle UGA-6 Personal Data Protection Office UGA-7 Data Protection Officer URUGUAY-3 Sensitive Data, Health Data, Children URUGUAY-4 Security and Cross-Border URUGUAY-5 Database Registration with AGESIC URCDP ASD37-17 TLS encryption between email servers (Limited) ASD37-27 Outbound data loss prevention (Very Good) AWWA-3.2 Remote Access Security AWWA-3.4 Encryption and Data Protection AZ-DPA-15 Article 17 - Dispute resolution AZ-DPA-6 Article 6 - State regulation in personal data protection BB-DPA-1 Section 1 - Short Title BB-DPA-4 Section 4 - Principles Relating to Processing CJIS-8 Media Protection CJIS-9 System and Communications Protection NISTSP92-3 Log Infrastructure: Architecture, Centralisation, Transport Security, SIEM Governance NISTSP92-4 Log Management: Time Synchronisation, Parsing, Storage, Integrity, Access Control NDPA-1 Applicability, Scope, and Carve-Outs NDPA-4 Sensitive Data Processing Consent and Childrens Protections NJDPA-7 Data Protection Assessments and Processor Contracts NJDPA-8 AG Platkin Enforcement, 18-Month Cure Sunset, and Division of Consumer Affairs PTESPHASE-2 Intelligence Gathering (OSINT) PTESPHASE-3 Threat Modeling PERU-3 Data Subject Rights (ARCO), Habeas Data, Automated Decisions PERU-7 DPO, Records, Retention, Marketing, Training QATAR-5 Security of Processing QATAR-7 DPO, Records, Retention, Marketing, Training CISABD-1 Take Ownership of Customer Security Outcomes SBD-DEV-04 Phishing-Resistant Authentication SWE-1 Scope and Purpose SWE-2 Relationship to GDPR TAIWAN-2 Consent, Notice, Sensitive Data TAIWAN-3 Data Subject Rights TEXASTDPSA-2 Consumer Rights TEXASTDPSA-3 Sensitive Data, Children, Sale Notice Standard 15 Online Tools Standard 2 Data Protection Impact Assessments UKGDPRREG-2 Data Subject Rights (Articles 12-22) UKGDPRREG-3 Controller and Processor (Articles 24-43) OB-SEC.2 Transport Layer Security OB-SEC.4 Certificate Management US-ITAR-EAR-DS-01 Technical Data Protection US-ITAR-EAR-DS-02 Cloud and Storage VIETNAMPDP-2 Consent and Notice VIETNAMPDP-3 Data Subject Rights VIRGINIAVCDPA-2 Consumer Rights VIRGINIAVCDPA-3 Sensitive Data Consent and Children APPI-A34 Request for Correction, Addition or Deletion AL-DPA-14 Direct Marketing BSI-08 Cryptographic protection of data FFIEC-09 Encryption and key management FTC-Safeguards-9-Elements 9 Safeguard Elements - Access, Inventory, Encryption, Secure-Dev, MFA, Disposal, Change-Mgmt, Monitoring, Pen-Test (16 CFR 314.4(c)) FDBR-ControllerObligations-DPA-Notice Controller + Processor Obligations + Data Protection Assessments (Fla. Stat. 501.707, 501.708, 501.71, 501.711) 62351-9 Cyber security key management ISO-26000-6.7 Consumer issues ISO23894-A.5 Privacy and Data Protection in AI 27010-10.1 Cryptographic Protection 29115-7.4 Level of Assurance 4 (LoA4) STANAG-2 STANAG 4778 Metadata Binding Mechanism and Cryptographic Binding NISTSP61-3 Preparation: Communications, Toolkits, Training, Exercises, Threat Intelligence NISTSP63R4-5 Federation: Assertions, Trust Agreements, RP Validation, Pseudonymous Identifiers NISTSP66-6 Technical Safeguards: Access Control, Audit Controls, Integrity, Person Authentication NISTSP82-2 OT Risk Assessment and Threat/Vulnerability Identification NISTSP88-4 Cryptographic Erase, Key Management, and Verification of Erase NRFCS-1 Retail Cybersecurity Governance, Policy, and Regulatory Change Management NZISM-3 Personnel Security, Physical Security, and Cryptography NGOB-3 API Security Standards, mTLS, and Encryption ORANWG11-3 Cryptography, TLS, SSH, IPsec, and PKI Lifecycle Management OECDAI-5 Data Governance, Training Data Quality, Privacy, and Bias Mitigation OSFIB13-3 Cyber Security: Identification, Protection, Detection, Response, Recovery OWASPSAMM-2 Design: Threat Assessment, Security Requirements, Security Architecture OMANCS-4 Data Protection, Cryptography, and Privacy Alignment OPENBANK-3 Mutual TLS, Token Binding, Request Signing (JWS), Key Management OSSFSC-6 Signed Releases, Provenance, Trusted Publishing, Binary Artifacts PASONE-4 Technical Security: CDE Configuration, BIM Tools, Encryption, Aggregation, Mobile Working PCI-P2PE-09 Encryption and key management PCI-PIN-09 Encryption and key management PCI-SSF-09 Encryption and key management PSDTWO-2 SCA Exemptions and Risk-Based Authentication PARAGUAY-5 Security of Processing, Data Integrity, Information Security SHAREASSESS-3 Network Security, Endpoint, Data Protection SUPCHAIN-2 Source Integrity - Branch Protection, Code Review, Two-Person Rule SOC-CY-C2 Encryption and Data Protection ISMSP-SYS-02 Encryption Implementation PIPA-CPO-DPO-Privacy-Officer-PIA-Personal-Information-Impact-Assessment-Articles-31-33 Korea PIPA CPO + DPO + Privacy Officer + PIA + Personal Information Impact Assessment + Articles 31-33 STUDPRV-2 Data Subject Rights for Students and Parents TEF-2 Openness and Transparency TANZANIA-1 Scope, Registration, Lawful Basis TSSR-INFO-1 Network Data Protection UKAI-2 Sector-Specific Regulator Engagement D.1 Incident Response Planning UNESCOAI-2 Principles 4-7: Sustainability, Privacy, Human Oversight, Transparency UNICEFAI-4 Transparency, Explanation, Adult Capacity CPSC-CS.3 Data Protection for Safety Systems Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Other controls in NIST SP 800-190: Data Protection in Cloud Query this from an agent The graph holds this control, the 281 it maps to, and the evidence behind each claim, over MCP and REST.