NIST SP 800-63-4
Privacy, Records, User-Controlled Wallets

NIST SP 800-63-4 NISTSP63R4-7: Privacy, Records Retention, and User-Controlled Wallets

Apply privacy and records management per NIST SP 800-63-4. Privacy requirements per Section 7 of each Volume require (a) purpose limitation + minimisation + storage limitation + lawful basis per applicable jurisdiction, (b) Privacy Impact Assessment per agency obligations, (c) Privacy Act + GDPR + state law + sectoral compliance, (d) subscriber notice + consent + redress, (e) limits on biometric retention and reuse beyond original purpose. Records retention per Volume A Section 4.8 + Volume B Section 6.7 + Volume C Section 10 covering chain of custody for evidence + biometrics + transcripts + lifecycle events as required by agency policy + statute. User-controlled wallets (NEW in Rev 4) per emerging guidance: when issuing or accepting credentials held in user-controlled wallets (mDL + verifiable credentials + decentralised identifiers) (a) define the trust framework + revocation mechanism + binding to subscriber + privacy properties + recovery model, (b) align with NIST SP 800-63-4 attribute model and federation patterns where applicable, (c) preserve user control over disclosure.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 33 controls across 21 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • CFR211-G-122 Section 211.122 - Materials Examination and Usage Criteria
  • CFR211-G-125 Section 211.125 - Labeling Issuance
  • CFR211-G-130 Section 211.130 - Packaging and Labeling Operations

ISO/IEC 27043:2015 · 3 controls

  • ISO27043-06 Asset inventory and ownership
  • ISO27043-08 Information classification and labeling
  • ISO27043-10 Media management and disposal

ISO/SAE 21434 · 3 controls

  • ISO21434-07 Acceptable use of assets
  • ISO21434-08 Information classification and labeling
  • ISO21434-09 Asset handling procedures
  • CPG-2.A Asset Inventory
  • CPG-2.B Prohibit Connection of Unauthorized Devices

ISO/IEC 27010:2015 · 2 controls

  • 27010-8.1 Membership Onboarding
  • 27010-8.2 Membership Termination

API 1164 · 1 control

  • API1164-02 Risk Management Framework

BSI IT-Grundschutz · 1 control

  • BSI-15 Security categorization
  • QMSR-820.45 Device labelling and packaging controls (§820.45)
  • 60601-1.7.1 Equipment identification and marking

IEC 62443 · 1 control

  • IEC62443-02 System security categorization
  • ISO-14064-1-5.4 Categorization of indirect GHG emissions

ISO/IEC 27019:2024 · 1 control

  • ISO27019-02 System security categorization

NIST SP 1800-32 · 1 control

NIST SP 800-190 · 1 control

OWASP ASVS · 1 control

OWASP MASVS · 1 control

  • PSPF24-2 Information Security, Cybersecurity Maturity, Essential Eight

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 33 it maps to, and the evidence behind each claim, over MCP and REST.