NRF Cybersecurity and Data Privacy Framework (National Retail Federation)
Risk Assessment and Data Inventory

NRF Cybersecurity and Data Privacy Framework (National Retail Federation) NRFCS-2: Risk Assessment, Customer Data Inventory, Classification, and Retail Threat Model

Conduct retail-tailored risk assessment + customer data inventory + classification per the NRF framework + NIST SP 800-30 Rev 1 + adaptation to retail threat model. Customer data inventory must enumerate (a) data types collected (loyalty + transaction + browsing + clickstream + mobile location + in-store sensor + camera + payment + employee + supplier + business operations data), (b) sources (POS + e-commerce site + mobile app + email signup + in-store kiosk + loyalty programme + customer service interaction + supplier portal + third-party data brokers + warranty / registration data + market research), (c) processing locations (data centres + cloud + retail stores + warehouses + distribution centres + supplier facilities + third-party processors + cross-border transfers), (d) retention periods + deletion procedures + data subject rights compliance per applicable jurisdiction. Classification must apply data-type + sensitivity + regulatory triggers (cardholder data per PCI DSS + personal information per state privacy laws + sensitive personal information including health from over-the-counter pharmacy + biometric from in-store technology + children data from children product lines + financial information). Retail threat model must address (a) point-of-sale malware + skimmers + e-commerce site skimmers (Magecart + form-jacking), (b) account takeover via credential stuffing + phishing + SIM swap, (c) supply chain compromise via vendor breach + counterfeit goods + return fraud, (d) insider threat including loss prevention + temporary peak-season workforce + contractors, (e) ransomware targeting retail during peak shopping periods.

What else in your programme already covers this

This control maps to 222 controls across 94 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

NIST SP 800-53 Rev 5 · 8 controls

ISO 27005 · 6 controls

ISO 31000 · 6 controls

ISO/IEC 23894:2023 · 6 controls

ISO/IEC 29147:2018 · 5 controls

  • NIST-CSF-GV.RM-03 Cybersecurity risk management activities and outcomes are included in enterprise risk management processes
  • NIST-CSF-GV.RM-04 Strategic direction that describes appropriate risk response options is established and communicated
  • NIST-CSF-GV.RM-07 Strategic opportunities (i.e., positive risks) are characterized and are included in organizational cybersecurity risk discussions
  • NIST-CSF-GV.SC-01 A cybersecurity supply chain risk management program, strategy, objectives, policies, and processes are established and agreed to by organizational stakeholders
  • NIST-CSF-ID.RA-09 The authenticity and integrity of hardware and software are assessed prior to acquisition and use
  • CPS230-11 Identification, Assessment and Management of Operational Risk
  • CPS230-16 Internal Audit Review of the Business Continuity Plan
  • CPS230-37 Service Provider Management Policy
  • CPS230-46 Ongoing Risk Management of Each Material Arrangement

BSI IT-Grundschutz · 4 controls

  • BSI-13 Risk assessment procedures
  • BSI-14 Vulnerability scanning and management
  • BSI-15 Security categorization
  • BSI-17 Continuous monitoring strategy

ISO/IEC 29134:2023 · 4 controls

API 1164 · 3 controls

  • FFIEC-03 Risk appetite and tolerance for IT risk
  • FFIEC-18 Ongoing monitoring and assessment
  • FFIEC-20 Exit strategy and transition planning

IEC 62443 · 3 controls

ISO 27019 · 3 controls

ISO/IEC 27003:2017 · 3 controls

ISO/IEC 30111:2019 · 3 controls

NIST SP 1800-32 · 3 controls

  • 3.11 Encrypt Sensitive Data at Rest
  • 3.16 System and Services Acquisition
  • 3.17 Supply Chain Risk Management
  • CRM-1 AML/CFT Compliance
  • CRM-3 Risk Management Framework
  • CRM-4 Business Risk Assessment

APRA CPS 234 · 2 controls

  • CPS234-16 Assessment of Related Party and Third Party Capability
  • CPS234-20 Information Asset Classification
  • ICP-16 Enterprise Risk Management for Solvency Purposes
  • ICP-8 Risk Management and Internal Controls

ISO 27017 · 2 controls

ISO 27018 · 2 controls

ISO/IEC 27014:2020 · 2 controls

  • NISTPF-2 Govern-P - Governance Policies, Risk Management Strategy, Awareness Training, and Monitoring
  • NISTPF-8 Protect-P Information Protection Processes (PR.PO-P)

NIST SP 800-190 · 2 controls

  • NZISM-1 NZISM Governance, Documentation, and Classification System
  • NZISM-3 Personnel Security, Physical Security, and Cryptography
  • OCCHS-3 Risk Appetite Statement, Risk Limits, Concentration Risk, and Limit Breach Protocols
  • OCCHS-7 Risk Data Aggregation, Reporting, Talent, Compensation, and Strategic Planning

OECD AI Principles · 2 controls

  • OECDAI-3 Robustness, Security, Safety, and Adversarial Attack Protection
  • OECDAI-5 Data Governance, Training Data Quality, Privacy, and Bias Mitigation
  • ASTWO-1 Audit Planning, Scaling, Risk Assessment, and Integration
  • ASTWO-3 Entity-Level Controls and Period-End Financial Reporting Process
  • 2.4.4 Hazard Analysis and Risk Assessment
  • 2.7.2 Food Fraud Plan

South Korea ISMS-P · 2 controls

  • CH-FADP-21 Data protection impact assessments
  • FADP-7 Data Protection Impact Assessment (Articles 9-10)
  • 4.3.1 Risk Assessment and Impact Analysis

Bahrain PDPL · 1 control

  • BB-DPA-20 Sections 50-60 - Registration and Responsibilities
  • CPG-5.A Vulnerability Disclosure Program

GDPR · 1 control

ISO 13485 · 1 control

  • ISO13485-06 Security management process and risk analysis

ISO 22000 · 1 control

ISO 22320:2018 · 1 control

ISO 27043 · 1 control

ISO 27799 · 1 control

  • ISO27799-06 Security management process and risk analysis

ISO 45001 · 1 control

ISO/IEC 27011:2024 · 1 control

  • 27011-8.5 Vulnerability and malware management

ISO/IEC 27031:2011 · 1 control

ISO/SAE 21434 · 1 control

  • OECDAI24-3 Frontier Model Risk Management, Capability Disclosure, and Independent Evaluation

OWASP ASVS · 1 control

  • DSOMM-1 Culture, Organization, Education, and Governance

OWASP MASVS · 1 control

  • OWASPMASVS-6 MASVS-CODE: Code Quality, Build Settings, and Updates
  • OPENBANK-4 Third Party Provider (TPP) Onboarding, Directory Integration, Due Diligence
  • NORWAY-4 DPIA, Privacy by Design, Records of Processing
  • AUPRV-6 Sensitive Information, PIA, Privacy by Design, Children

Privacy Act 2020 · 1 control

  • NZPRV-6 IPP 13 Unique Identifiers, Privacy Impact Assessment, Privacy by Design
  • PSPF24-1 Security Culture, Governance, Risk Management
  • AIGF-1.1 Risk Management and Internal Controls

South Korea PIPA · 1 control

Turkey KVKK · 1 control

  • UNGPBHR-2 Pillar II: Corporate Responsibility to Respect Human Rights

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 222 it maps to, and the evidence behind each claim, over MCP and REST.