NRF Cybersecurity and Data Privacy Framework (National Retail Federation)
Retail Cyber Governance

NRF Cybersecurity and Data Privacy Framework (National Retail Federation) NRFCS-1: Retail Cybersecurity Governance, Policy, and Regulatory Change Management

Establish cybersecurity governance and policy structures appropriate to retail industry characteristics per the NRF Cybersecurity and Data Privacy Framework guidance and supporting NIST CSF alignment. Governance must (a) name accountable executives (CISO + Chief Privacy Officer + Chief Risk Officer + Chief Operating Officer + Chief Marketing Officer + Chief Digital Officer where applicable) with documented decision authority, (b) maintain cyber and privacy policies covering acceptable use + access control + data classification + incident response + breach notification + third-party risk + PCI DSS scope + e-commerce + mobile + in-store technology + supply chain + retail-specific peak-season operations + fraud prevention, (c) align to NIST Cybersecurity Framework 2.0 functions (Govern + Identify + Protect + Detect + Respond + Recover) with retail-specific implementation tier targets, (d) regulatory change management covering PCI DSS + state breach notification laws (50 states + territories + jurisdictions) + state and federal privacy laws (CCPA + CPRA + VCDPA + CTDPA + UCPA + TIPA + similar) + sectoral obligations (CAN-SPAM + TCPA + COPPA + FCRA + FACTA + Sarbanes-Oxley for public retailers + SEC cyber disclosure + FTC Act 5(a) unfair/deceptive + DOJ + Treasury sanctions where applicable + international (GDPR + UK GDPR + LGPD + PIPEDA + Australian Privacy Act + Japan APPI + similar)). Review the programme annually + after material change to retail operations (new store formats + e-commerce launches + acquisitions + brand extensions + payment innovations).

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 201 controls across 81 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • CH-FADP-19 Transparency and proactive information
  • CH-FADP-21 Data protection impact assessments
  • CH-FADP-25 Compliance monitoring and auditing
  • FADP-16 FDPIC Independence and Functions
  • FADP-7 Data Protection Impact Assessment (Articles 9-10)
  • FADP-9 Data Protection Advisor (Articles 14-15)
  • IEC62304-4.1 Quality Management System
  • IEC62304-5.1 Software Development Planning
  • IEC62304-7.4 Risk Management of Software Changes
  • IEC62304-8.2 Change Control
  • IEC62304-9.4 Use Change Control Process
  • 27557-1 Scope
  • 27557-3 Terms and definitions
  • 27557-6.4 Privacy risk treatment
  • 27557-6.6 Recording and reporting
  • 27557-7.3 Risk-based privacy program implementation

NIST SP 800-190 · 5 controls

ISO/IEC 23894:2023 · 4 controls

  • ISO23894-5.1 Leadership and Commitment
  • ISO23894-5.2 AI Risk Management Integration
  • ISO23894-5.5 Framework Evaluation
  • ISO23894-A.5 Privacy and Data Protection in AI
  • NISTPF-2 Govern-P - Governance Policies, Risk Management Strategy, Awareness Training, and Monitoring
  • NISTPF-4 Communicate-P - Privacy Notice, Transparency, and Individual Awareness
  • NISTPF-7 Protect-P Maintenance and Protective Technology (PR.MA-P, PR.PT-P)
  • NISTPF-8 Protect-P Information Protection Processes (PR.PO-P)

NIST SP 800-53 Rev 5 · 4 controls

  • CPS230-16 Internal Audit Review of the Business Continuity Plan
  • CPS230-37 Service Provider Management Policy
  • CPS230-46 Ongoing Risk Management of Each Material Arrangement
  • AT-DSG-10 Section 29 - Liability and right to compensation / civil jurisdiction
  • AT-DSG-12 Section 62 - Administrative penalties
  • AT-DSG-7 Section 18 - Establishment of the Data Protection Authority

Bahrain PDPL · 3 controls

  • IS.D.OR.210 Information Security Risk Treatment
  • IS.I.OR.210 Information Security Risk Treatment
  • IS.I.OR.220 Information Security Risk Management
  • FFIEC-03 Risk appetite and tolerance for IT risk
  • FFIEC-18 Ongoing monitoring and assessment
  • FFIEC-20 Exit strategy and transition planning
  • UAE-PDPL-Art.10 Data Protection Officer (DPO) (UAE PDPL Article 10)
  • UAE-PDPL-Art.18_19_20_21 Security measures, controller/processor relationship, DPIA (UAE PDPL Articles 18-21)
  • UAE-PDPL-Status UAE PDPL status, executive regulations, UAE Data Office guidance evolution

GDPR · 3 controls

  • 60601-1.4.1 General requirements
  • 60601-1.4.2 Risk management process
  • 60601-1.5.1 General requirements for testing

ISO 27799:2025 · 3 controls

  • ISO27799-03 Minimum necessary standard enforcement
  • ISO27799-04 Patient data de-identification procedures
  • ISO27799-05 Audit trail for ePHI access

ISO/IEC 27011:2024 · 3 controls

  • 27011-5.2 Information Security Roles in Telecoms
  • 27011-6.3 Awareness and Training
  • 27011-8.6 Data protection and backup
  • NIST-CSF-GV.RM-03 Cybersecurity risk management activities and outcomes are included in enterprise risk management processes
  • NIST-CSF-GV.RM-04 Strategic direction that describes appropriate risk response options is established and communicated
  • NIST-CSF-GV.SC-01 A cybersecurity supply chain risk management program, strategy, objectives, policies, and processes are established and agreed to by organizational stakeholders
  • AUPRV-1 APP 1 Open and Transparent Management + Privacy Management Framework
  • AUPRV-6 Sensitive Information, PIA, Privacy by Design, Children
  • AUPRV-8 OAIC Cooperation, Vendor Management, Training, Complaints, Enforcement
  • IM8-DAT.2 Data Protection
  • IM8-DAT.4 Data Retention and Disposal
  • IM8-TPM.4 Supply Chain Risk Management

API 1164 · 2 controls

  • API1164-21 TSA Pipeline Security Directive Alignment
  • API1164-23 Change management procedures

APRA CPS 234 · 2 controls

  • CPS234-16 Assessment of Related Party and Third Party Capability
  • CPS234-20 Information Asset Classification
  • AZ-DPA-15 Article 17 - Dispute resolution
  • AZ-DPA-6 Article 6 - State regulation in personal data protection
  • BS65000-RM-01 Resilience Journey
  • BS65000-RM-02 Integrated Approach
  • BB-DPA-1 Section 1 - Short Title
  • BB-DPA-4 Section 4 - Principles Relating to Processing
  • CAT-D1-2 Risk management
  • CAT-ML-2 Evolving
  • ICP-16 Enterprise Risk Management for Solvency Purposes
  • ICP-8 Risk Management and Internal Controls
  • ICAO-ANX17-Chap2-ThreatAssessment-RiskManagement-Cyber-GASeP ICAO Annex 17 Chapter 2 - Threat Assessment + Risk Management + Cyber Threats to Critical Aviation Systems (Amendment 17/18)
  • ICAO-ANX17-Chap4-Cargo-Mail-Catering-Stores-Supplies-RegulatedAgent-KnownConsignor ICAO Annex 17 Chapter 4 - Cargo + Mail + Catering + Stores + Supplies Security + Regulated Agent + Known Consignor + Supply Chain

IEC 62443 · 2 controls

  • IEC62443-21 Supply chain risk management for critical components
  • IEC62443-23 Change management procedures

ISO/IEC 27003:2017 · 2 controls

  • ISO27003-6.1 Actions to address risks and opportunities
  • ISO27003-8.3 Information security risk treatment

ISO/IEC 27019:2024 · 2 controls

  • ISO27019-21 Supply chain risk management for critical components
  • ISO27019-23 Change management procedures

ISO/IEC 27400:2022 · 2 controls

  • 27400-7.1 Network Security for IoT
  • 27400-7.4 Data retention and deletion

NIST SP 1800-32 · 2 controls

  • NDPA-1 Applicability, Scope, and Carve-Outs
  • NDPA-4 Sensitive Data Processing Consent and Childrens Protections
  • OCCHS-3 Risk Appetite Statement, Risk Limits, Concentration Risk, and Limit Breach Protocols
  • OCCHS-7 Risk Data Aggregation, Reporting, Talent, Compensation, and Strategic Planning

OECD AI Principles · 2 controls

  • OECDAI-5 Data Governance, Training Data Quality, Privacy, and Bias Mitigation
  • OECDAI-8 AI Incident Reporting, Regulatory Compliance, Public Reporting, and International Cooperation
  • PAKPDPB-6 Cross-Border Transfer and Data Localization
  • PAKPDPB-7 NCPDP, Registration, Records, Processor Contracts, DPO
  • NORWAY-4 DPIA, Privacy by Design, Records of Processing
  • NORWAY-7 DPO, Cooperation with Datatilsynet, Retention, Marketing, Training

Privacy Act 2020 · 2 controls

  • NZPRV-6 IPP 13 Unique Identifiers, Privacy Impact Assessment, Privacy by Design
  • NZPRV-8 Privacy Officer, OPC Cooperation, Compliance Notices, Complaints, Training

South Korea PIPA · 2 controls

  • PIPA-CPO-DPO-Privacy-Officer-PIA-Personal-Information-Impact-Assessment-Articles-31-33 Korea PIPA CPO + DPO + Privacy Officer + PIA + Personal Information Impact Assessment + Articles 31-33
  • PIPA-Pseudonymisation-Article-28-2-3-Enforcement-PIPC-Investigation-Surcharges-3-Percent-Revenue-Article64-2 Korea PIPA Pseudonymisation + Article 28-2 + Enforcement + PIPC + Surcharges 3% + Article 63 + 64-2
  • D.1 Incident Response Planning
  • UKDEFSTD-1 Cyber Defence Cyber Risk Profile (CRP)
  • VERMONTAICDA-3 Bias Testing, Discrimination Prevention, Transparency
  • VERMONTAICDA-4 Vermont AG Enforcement and Cure
  • AMLCTF-82 Part A Compliance
  • AS9100D-8.1 Operational Planning and Control
  • ASD37-27 Outbound data loss prevention (Very Good)
  • ACQS-8-4 Risk Management
  • AL-DPA-14 Direct Marketing

BSI IT-Grundschutz · 1 control

  • BSI-24 Configuration change control
  • CJIS-19 Supply Chain Risk Management
  • FTC-Safeguards-9-Elements 9 Safeguard Elements - Access, Inventory, Encryption, Secure-Dev, MFA, Disposal, Change-Mgmt, Monitoring, Pen-Test (16 CFR 314.4(c))

FedRAMP High · 1 control

  • AC-2 Account Management

FedRAMP Moderate · 1 control

  • AC-2 Account Management
  • FDBR-ControllerObligations-DPA-Notice Controller + Processor Obligations + Data Protection Assessments (Fla. Stat. 501.707, 501.708, 501.71, 501.711)
  • ISO-20400-4.5 Key considerations for sustainable procurement

ISO 22320:2018 · 1 control

  • ISO-22320-4.3 Risk-based approach

ISO 26000:2010 · 1 control

  • ISO-26000-6.7 Consumer issues
  • ISO-26262-8-8 Change management
  • ISO28001-SA-04 Security Risk Treatment Planning

ISO 30401 · 1 control

  • ISO30401-18 Innovation and change management
  • ISO20000-06 Change management processes

ITIL 4 · 1 control

  • ITIL4-06 Change management processes
  • NZISM-1 NZISM Governance, Documentation, and Classification System
  • DSOMM-6 Metrics, Maturity Measurement, and Continuous Improvement
  • PSPF24-1 Security Culture, Governance, Risk Management
  • EHDSREG-5 Cross-Border Health Data Flows
  • RUSPD-4 Special Categories, Biometric Data
  • AIGF-1.1 Risk Management and Internal Controls

South Korea ISMS-P · 1 control

  • ISMSP-MS-02 Risk Management

Turkey KVKK · 1 control

  • TURKEYKVKK-3 Special Categories and Sensitive Data
  • CRM-3 Risk Management Framework
  • CPSC-CS.3 Data Protection for Safety Systems
  • VIETNAMCYBER-4 Incident Reporting and Cooperation

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 201 it maps to, and the evidence behind each claim, over MCP and REST.