NRF Cybersecurity and Data Privacy Framework (National Retail Federation)
E-Commerce, Mobile, Store, IoT

NRF Cybersecurity and Data Privacy Framework (National Retail Federation) NRFCS-5: E-Commerce, Mobile, Store Technology, and IoT Security

Secure e-commerce + mobile + in-store technology + IoT per NRF framework and OWASP + vendor-specific guidance. E-commerce security must (a) protect against OWASP Top 10 + API Top 10 vulnerabilities + skimming + form-jacking via subresource integrity + Content Security Policy + script monitoring + behavioural analytics, (b) implement bot management against credential stuffing + scraping + scalping + inventory hoarding + fake review generation, (c) protect checkout via PCI-compliant payment integration + 3D Secure / 3DS2 + tokenisation + risk-based authentication, (d) maintain WAF + DDoS protection + traffic anomaly detection. Mobile and in-store app security must (a) protect against mobile-specific threats per OWASP Mobile Top 10 + MASVS + MASTG verification, (b) implement secure mobile payment per PCI Mobile Payment Acceptance + Apple Pay + Google Pay + secure element + tokenisation, (c) protect in-store kiosk + price-checker + employee tablet + handheld scanner + self-checkout + similar devices via application allowlisting + device management + tamper detection. Store technology and IoT must (a) inventory and segment store networks + POS + back-office + guest WiFi + IoT (cameras + sensors + RFID + digital signage + smart shelves + queue management + customer counting + lighting + HVAC) with appropriate segregation per PCI DSS + general cybersecurity hygiene, (b) maintain firmware + patching + change control for store IoT, (c) protect against in-store-network compromise via segmentation + traffic monitoring + access control + visitor isolation.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.