NRF Cybersecurity and Data Privacy Framework (National Retail Federation)
Risk Assessment and Data Inventory

NRF Cybersecurity and Data Privacy Framework (National Retail Federation) NRFCS-2: Risk Assessment, Customer Data Inventory, Classification, and Retail Threat Model

Conduct retail-tailored risk assessment + customer data inventory + classification per the NRF framework + NIST SP 800-30 Rev 1 + adaptation to retail threat model. Customer data inventory must enumerate (a) data types collected (loyalty + transaction + browsing + clickstream + mobile location + in-store sensor + camera + payment + employee + supplier + business operations data), (b) sources (POS + e-commerce site + mobile app + email signup + in-store kiosk + loyalty programme + customer service interaction + supplier portal + third-party data brokers + warranty / registration data + market research), (c) processing locations (data centres + cloud + retail stores + warehouses + distribution centres + supplier facilities + third-party processors + cross-border transfers), (d) retention periods + deletion procedures + data subject rights compliance per applicable jurisdiction. Classification must apply data-type + sensitivity + regulatory triggers (cardholder data per PCI DSS + personal information per state privacy laws + sensitive personal information including health from over-the-counter pharmacy + biometric from in-store technology + children data from children product lines + financial information). Retail threat model must address (a) point-of-sale malware + skimmers + e-commerce site skimmers (Magecart + form-jacking), (b) account takeover via credential stuffing + phishing + SIM swap, (c) supply chain compromise via vendor breach + counterfeit goods + return fraud, (d) insider threat including loss prevention + temporary peak-season workforce + contractors, (e) ransomware targeting retail during peak shopping periods.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 192 controls across 82 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

NIST SP 800-53 Rev 5 · 8 controls

  • 27557-1 Scope
  • 27557-3 Terms and definitions
  • 27557-4.3 Individual impact consideration
  • 27557-6.3 Privacy risk assessment
  • 27557-6.4 Privacy risk treatment
  • 27557-6.6 Recording and reporting
  • 27557-7.3 Risk-based privacy program implementation

ISO/IEC 23894:2023 · 6 controls

  • ISO23894-5.1 Leadership and Commitment
  • ISO23894-5.2 AI Risk Management Integration
  • ISO23894-5.5 Framework Evaluation
  • ISO23894-6.3 AI Risk Assessment
  • ISO23894-6.3.1 AI Risk Identification
  • ISO23894-6.3.3 AI Risk Evaluation
  • IS.D.OR.205 Information Security Risk Assessment
  • IS.D.OR.210 Information Security Risk Treatment
  • IS.I.OR.205 Information Security Risk Assessment
  • IS.I.OR.210 Information Security Risk Treatment
  • IS.I.OR.220 Information Security Risk Management
  • NIST-CSF-GV.RM-03 Cybersecurity risk management activities and outcomes are included in enterprise risk management processes
  • NIST-CSF-GV.RM-04 Strategic direction that describes appropriate risk response options is established and communicated
  • NIST-CSF-GV.RM-07 Strategic opportunities (i.e., positive risks) are characterized and are included in organizational cybersecurity risk discussions
  • NIST-CSF-GV.SC-01 A cybersecurity supply chain risk management program, strategy, objectives, policies, and processes are established and agreed to by organizational stakeholders
  • NIST-CSF-ID.RA-09 The authenticity and integrity of hardware and software are assessed prior to acquisition and use
  • CPS230-11 Identification, Assessment and Management of Operational Risk
  • CPS230-16 Internal Audit Review of the Business Continuity Plan
  • CPS230-37 Service Provider Management Policy
  • CPS230-46 Ongoing Risk Management of Each Material Arrangement

BSI IT-Grundschutz · 4 controls

  • BSI-13 Risk assessment procedures
  • BSI-14 Vulnerability scanning and management
  • BSI-15 Security categorization
  • BSI-17 Continuous monitoring strategy

ISO/IEC 29134:2023 · 4 controls

  • 29134-1 Scope
  • 29134-3 Terms and definitions
  • 29134-9.1 PIA report structure
  • 29134-9.2 Report findings and recommendations

API 1164 · 3 controls

  • API1164-07 Remote Access
  • API1164-21 TSA Pipeline Security Directive Alignment
  • API1164-24 Vulnerability assessment for critical systems
  • CAT-D1-2 Risk management
  • CAT-D3-3 Corrective controls
  • CAT-ML-2 Evolving
  • FFIEC-03 Risk appetite and tolerance for IT risk
  • FFIEC-18 Ongoing monitoring and assessment
  • FFIEC-20 Exit strategy and transition planning
  • 60601-1.4.1 General requirements
  • 60601-1.4.2 Risk management process
  • 60601-1.5.1 General requirements for testing
  • IEC62304-4.1 Quality Management System
  • IEC62304-5.1 Software Development Planning
  • IEC62304-7.4 Risk Management of Software Changes

IEC 62443 · 3 controls

  • IEC62443-07 Personnel risk assessment
  • IEC62443-21 Supply chain risk management for critical components
  • IEC62443-24 Vulnerability assessment for critical systems

ISO/IEC 27003:2017 · 3 controls

  • ISO27003-6.1 Actions to address risks and opportunities
  • ISO27003-8.2 Information security risk assessment
  • ISO27003-8.3 Information security risk treatment

ISO/IEC 27019:2024 · 3 controls

  • ISO27019-07 Personnel risk assessment
  • ISO27019-21 Supply chain risk management for critical components
  • ISO27019-24 Vulnerability assessment for critical systems

ISO/IEC 29147:2018 · 3 controls

  • 29147-5.11 Researcher Safe Harbour and Legal Posture
  • 29147-5.6 Advisory Content and Quality
  • 29147-7.8 Remediation information

ISO/IEC 30111:2019 · 3 controls

  • 30111-1 Scope
  • 30111-3 Terms and definitions
  • 30111-8.1 Post-release monitoring

NIST SP 1800-32 · 3 controls

  • CRM-1 AML/CFT Compliance
  • CRM-3 Risk Management Framework
  • CRM-4 Business Risk Assessment
  • AMLCTF-82 Part A Compliance
  • AMLCTF-PartA-RiskAssess ML/TF Risk Assessment

APRA CPS 234 · 2 controls

  • CPS234-16 Assessment of Related Party and Third Party Capability
  • CPS234-20 Information Asset Classification
  • BS65000-RM-01 Resilience Journey
  • BS65000-RM-02 Integrated Approach
  • CJIS-17 Risk Assessment
  • CJIS-19 Supply Chain Risk Management
  • Sapin2-Pillar3-Risk-Mapping Pillar 3 - Corruption Risk Mapping (Cartographie des Risques)
  • Sapin2-Pillar4-ThirdParty-DueDiligence Pillar 4 - Third-Party Due Diligence (Clients, Suppliers, Intermediaries, M&A)
  • ICP-16 Enterprise Risk Management for Solvency Purposes
  • ICP-8 Risk Management and Internal Controls
  • ICAO-ANX17-Chap2-ThreatAssessment-RiskManagement-Cyber-GASeP ICAO Annex 17 Chapter 2 - Threat Assessment + Risk Management + Cyber Threats to Critical Aviation Systems (Amendment 17/18)
  • ICAO-ANX17-Chap4-Cargo-Mail-Catering-Stores-Supplies-RegulatedAgent-KnownConsignor ICAO Annex 17 Chapter 4 - Cargo + Mail + Catering + Stores + Supplies Security + Regulated Agent + Known Consignor + Supply Chain
  • NISTPF-2 Govern-P - Governance Policies, Risk Management Strategy, Awareness Training, and Monitoring
  • NISTPF-8 Protect-P Information Protection Processes (PR.PO-P)

NIST SP 800-190 · 2 controls

  • NZISM-1 NZISM Governance, Documentation, and Classification System
  • NZISM-3 Personnel Security, Physical Security, and Cryptography
  • OCCHS-3 Risk Appetite Statement, Risk Limits, Concentration Risk, and Limit Breach Protocols
  • OCCHS-7 Risk Data Aggregation, Reporting, Talent, Compensation, and Strategic Planning

OECD AI Principles · 2 controls

  • OECDAI-3 Robustness, Security, Safety, and Adversarial Attack Protection
  • OECDAI-5 Data Governance, Training Data Quality, Privacy, and Bias Mitigation
  • ASTWO-1 Audit Planning, Scaling, Risk Assessment, and Integration
  • ASTWO-3 Entity-Level Controls and Period-End Financial Reporting Process
  • 2.4.4 Hazard Analysis and Risk Assessment
  • 2.7.2 Food Fraud Plan
  • IM8-SEC.4 Vulnerability Management
  • IM8-TPM.4 Supply Chain Risk Management

South Korea ISMS-P · 2 controls

  • ISMSP-MS-02 Risk Management
  • ISMSP-SYS-04 Vulnerability Management
  • CH-FADP-21 Data protection impact assessments
  • FADP-7 Data Protection Impact Assessment (Articles 9-10)
  • AS9100D-8.1 Operational Planning and Control
  • 4.3.1 Risk Assessment and Impact Analysis
  • ACQS-8-4 Risk Management

Bahrain PDPL · 1 control

  • BB-DPA-20 Sections 50-60 - Registration and Responsibilities
  • CPG-5.A Vulnerability Disclosure Program
  • FTC-Safeguards-ServiceProvider-Evaluation Service Provider Oversight + Program Evaluation + Personnel Training (16 CFR 314.4(d-g))
  • UAE-PDPL-Art.18_19_20_21 Security measures, controller/processor relationship, DPIA (UAE PDPL Articles 18-21)

GDPR · 1 control

  • ISO-20400-4.5 Key considerations for sustainable procurement
  • ISO-22313-8.2 Business impact analysis and risk assessment

ISO 22320:2018 · 1 control

  • ISO-22320-4.3 Risk-based approach
  • ISO-26262-3-7 Hazard analysis and risk assessment (HARA)

ISO 27799:2025 · 1 control

  • ISO27799-06 Security management process and risk analysis
  • ISO28001-SA-04 Security Risk Treatment Planning

ISO/IEC 27011:2024 · 1 control

  • 27011-8.5 Vulnerability and malware management

ISO/IEC 27031:2011 · 1 control

  • 27031-7.2 Resource Requirements

ISO/IEC 27043:2015 · 1 control

  • ISO27043-25 Technical vulnerability management

ISO/SAE 21434 · 1 control

  • ISO21434-25 Technical vulnerability management
  • OECDAI24-3 Frontier Model Risk Management, Capability Disclosure, and Independent Evaluation

OWASP ASVS · 1 control

  • DSOMM-1 Culture, Organization, Education, and Governance

OWASP MASVS · 1 control

  • OWASPMASVS-6 MASVS-CODE: Code Quality, Build Settings, and Updates
  • OPENBANK-4 Third Party Provider (TPP) Onboarding, Directory Integration, Due Diligence
  • NORWAY-4 DPIA, Privacy by Design, Records of Processing
  • AUPRV-6 Sensitive Information, PIA, Privacy by Design, Children

Privacy Act 2020 · 1 control

  • NZPRV-6 IPP 13 Unique Identifiers, Privacy Impact Assessment, Privacy by Design
  • PSPF24-1 Security Culture, Governance, Risk Management
  • AIGF-1.1 Risk Management and Internal Controls

South Korea PIPA · 1 control

  • PIPA-CPO-DPO-Privacy-Officer-PIA-Personal-Information-Impact-Assessment-Articles-31-33 Korea PIPA CPO + DPO + Privacy Officer + PIA + Personal Information Impact Assessment + Articles 31-33

Turkey KVKK · 1 control

  • TURKEYKVKK-3 Special Categories and Sensitive Data
  • UNGPBHR-2 Pillar II: Corporate Responsibility to Respect Human Rights
  • CPSC-RA.3 Lifecycle Risk Assessment
  • VERMONTAICDA-4 Vermont AG Enforcement and Cure
  • VIETNAMCYBER-4 Incident Reporting and Cooperation

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 192 it maps to, and the evidence behind each claim, over MCP and REST.