NIST SP 800-92
Privacy + Cloud/SaaS Logs

NIST SP 800-92 NISTSP92-7: Privacy in Logs, Sensitive Content Handling, Cloud and SaaS Log Considerations

Handle privacy and sensitive content in logs + cloud/SaaS log considerations per NIST SP 800-92 Section 5.11 (Confidentiality and Privacy) + updates aligned with modern cloud-era practice + GDPR + CCPA + sectoral privacy law + HIPAA Privacy Rule. Privacy and data minimisation: review what is captured by each log source + scrub or redact unnecessary personal data + pseudonymise where analytical value justifies retention + document the legal basis for log content under applicable privacy regimes + provide subject access pathways where required + apply data subject rights honoring deletion + correction + portability requests with logs scoped to investigative-necessity carve-outs where applicable + document the carve-out rationale. Sensitive content handling: never log passwords + tokens + cryptographic keys + cardholder data + clinical data + classified content + with technical enforcement (redaction filters + masking + sample-screened log reviews) + investigation when sensitive content is observed in logs + retroactive cleanup. Cloud and SaaS log considerations: enumerate consumer-controlled vs provider-controlled logs per service + understand provider retention and access constraints + plan for log export to consumer-controlled storage where regulatory or investigative continuity demands it + consider provider audit log SKU upgrades where richer detail is required + document the gap between desired and available logs per service + accept residual risk explicitly where the gap is unavoidable.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 34 controls across 22 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • CFR211-G-122 Section 211.122 - Materials Examination and Usage Criteria
  • CFR211-G-125 Section 211.125 - Labeling Issuance
  • CFR211-G-130 Section 211.130 - Packaging and Labeling Operations

ISO/IEC 27043:2015 · 3 controls

  • ISO27043-06 Asset inventory and ownership
  • ISO27043-08 Information classification and labeling
  • ISO27043-10 Media management and disposal

ISO/SAE 21434 · 3 controls

  • ISO21434-07 Acceptable use of assets
  • ISO21434-08 Information classification and labeling
  • ISO21434-09 Asset handling procedures
  • CPG-2.A Asset Inventory
  • CPG-2.B Prohibit Connection of Unauthorized Devices

ISO/IEC 27010:2015 · 2 controls

  • 27010-8.1 Membership Onboarding
  • 27010-8.2 Membership Termination

API 1164 · 1 control

  • API1164-02 Risk Management Framework

BSI IT-Grundschutz · 1 control

  • BSI-15 Security categorization
  • QMSR-820.45 Device labelling and packaging controls (§820.45)
  • 60601-1.7.1 Equipment identification and marking

IEC 62443 · 1 control

  • IEC62443-02 System security categorization
  • ISO-14064-1-5.4 Categorization of indirect GHG emissions

ISO/IEC 27019:2024 · 1 control

  • ISO27019-02 System security categorization

NIST SP 1800-32 · 1 control

NIST SP 800-190 · 1 control

OWASP ASVS · 1 control

OWASP MASVS · 1 control

  • PSPF24-2 Information Security, Cybersecurity Maturity, Essential Eight

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 34 it maps to, and the evidence behind each claim, over MCP and REST.