Frameworks / Oman National Cybersecurity Framework / OMANCS-4 Oman National Cybersecurity Framework
Data Protection + Crypto
Oman National Cybersecurity Framework OMANCS-4: Data Protection, Cryptography, and Privacy Alignment Operate data protection + cryptography + privacy alignment per Oman framework + Oman Personal Data Protection Law (Royal Decree 6/2022 effective 13 February 2023). Implement encryption at rest + in transit + with cryptographic key management lifecycle + HSM where appropriate + FIPS 140-2 / 140-3 validated modules. Apply data minimisation + purpose limitation + retention + secure deletion per PDPL. Implement DLP + classification-based protection + cross-border transfer mechanism per PDPL Article 36 (regulator approval required for transfer + adequacy / safeguards / consent). Maintain data subject rights handling + breach notification per PDPL Article 35 (72 hour notification to MTCIT regulator + affected individuals).
Maintained by Gerard Blokdyk · Verified against the published standard 31 May 2026 · Control text last updated 21 May 2026 What else in your programme already covers this This control maps to 277 controls across 80 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
CH-FADP-02 Principles of lawful processing CH-FADP-04 Data subject access right CH-FADP-05 Data accuracy and rectification CH-FADP-13 Right to object and request blocking CH-FADP-19 Transparency and proactive information CH-FADP-21 Data protection impact assessments FADP-11 Duty to Inform (Article 19) FADP-12 Right of Access (Article 25) FADP-15 Data Breach Notification FADP-16 FDPIC Independence and Functions FADP-7 Data Protection Impact Assessment (Articles 9-10) FADP-9 Data Protection Advisor (Articles 14-15) GDPR-Art.10 Processing of personal data relating to criminal convictions GDPR-Art.11 Processing which does not require identification GDPR-Art.15 Right of access by the data subject GDPR-Art.19 Notification obligation regarding rectification, erasure or restriction GDPR-Art.25 Data protection by design and by default GDPR-Art.35 Data protection impact assessment GDPR-Art.38 Position of the data protection officer GDPR-Art.9 Processing of special categories of personal data AT-DSG-10 Section 29 - Liability and right to compensation / civil jurisdiction AT-DSG-11 Sections 42-45 - Data subject rights (law enforcement) AT-DSG-12 Section 62 - Administrative penalties AT-DSG-13 Section 36 - Scope of law enforcement processing AT-DSG-14 Section 38 - Lawfulness of law enforcement processing AT-DSG-7 Section 18 - Establishment of the Data Protection Authority BB-DPA-1 Section 1 - Short Title BB-DPA-14 Section 15 - Right to Data Portability BB-DPA-16 Section 22 - General Principle for Transfers BB-DPA-21 Sections 61-69 - Data Privacy Officer BB-DPA-4 Section 4 - Principles Relating to Processing ISO27799-02 ePHI encryption at rest and in transit ISO27799-03 Minimum necessary standard enforcement ISO27799-04 Patient data de-identification procedures ISO27799-05 Audit trail for ePHI access ISO27799-16 Transmission security and encryption ISO27043-08 Information classification and labeling ISO27043-17 Encryption of data at rest ISO27043-18 Encryption of data in transit ISO27043-19 Certificate management ISO27043-20 Key lifecycle management 27400-5.4 Data and privacy risks 27400-6.2 Device Identity and Authentication 27400-7.1 Network Security for IoT 27400-7.3 Data minimization and purpose limitation 27400-7.4 Data retention and deletion ISO21434-08 Information classification and labeling ISO21434-16 Cryptographic policy and key management ISO21434-17 Encryption of data at rest ISO21434-18 Encryption of data in transit ISO21434-19 Certificate management APPI-A23 Security Control Measures APPI-A24 Supervision of Employees APPI-A33 Request for Disclosure of Retained Personal Data APPI-A34 Request for Correction, Addition or Deletion AZ-DPA-12 Article 13 - Cross-border transfer AZ-DPA-14 Article 16 - Liability for violations AZ-DPA-15 Article 17 - Dispute resolution AZ-DPA-6 Article 6 - State regulation in personal data protection 27011-5.2 Information Security Roles in Telecoms 27011-6.3 Awareness and Training 27011-8.3 Cryptography and key management 27011-8.6 Data protection and backup NISTPF-3 Control-P - Privacy Controls, Data Management, and Disassociated Processing NISTPF-4 Communicate-P - Privacy Notice, Transparency, and Individual Awareness NISTPF-7 Protect-P Maintenance and Protective Technology (PR.MA-P, PR.PT-P) NISTPF-8 Protect-P Information Protection Processes (PR.PO-P) NORWAY-4 DPIA, Privacy by Design, Records of Processing NORWAY-5 Security of Processing, Encryption, Pseudonymization, Access Control NORWAY-7 DPO, Cooperation with Datatilsynet, Retention, Marketing, Training NORWAY-8 Breach Notification, Complaints, Compliance, Enforcement AUPRV-1 APP 1 Open and Transparent Management + Privacy Management Framework AUPRV-4 APP 10-11 Quality, Security of Personal Information AUPRV-6 Sensitive Information, PIA, Privacy by Design, Children AUPRV-7 Notifiable Data Breaches (NDB) Scheme, Incident Response IM8-CLD.2 Cloud Security Controls IM8-DAT.1 Data Classification IM8-DAT.2 Data Protection IM8-DAT.4 Data Retention and Disposal CFR211-G-122 Section 211.122 - Materials Examination and Usage Criteria CFR211-G-125 Section 211.125 - Labeling Issuance CFR211-G-130 Section 211.130 - Packaging and Labeling Operations APP-1 APP 1 - Open and transparent management of personal information APP-3 APP 3 - Collection of solicited personal information APP-5 APP 5 - Notification of the collection of personal information FEDRAMP-SC-13 Cryptographic Protection FEDRAMP-SC-28 Protection of Information at Rest FEDRAMP-SC-8 Transmission Confidentiality and Integrity UAE-PDPL-Art.10 Data Protection Officer (DPO) (UAE PDPL Article 10) UAE-PDPL-Art.18_19_20_21 Security measures, controller/processor relationship, DPIA (UAE PDPL Articles 18-21) UAE-PDPL-Art.4_5 Lawful basis and principles for processing personal data (UAE PDPL Articles 4-5) 23837-1.2 Normative references 23837-1.5.2 Cryptographic module requirements 23837-1.5.3 Network device testing requirements 29100-6.10 Information security 29100-6.5 Use, retention and disclosure limitation 29100-6.9 Accountability 29134-1 Scope 29134-3 Terms and definitions 29134-9.1 PIA report structure PAKPDPB-6 Cross-Border Transfer and Data Localization PAKPDPB-7 NCPDP, Registration, Records, Processor Contracts, DPO PAKPDPB-8 Enforcement, Penalties, Complaints, Retention, Training NZPRV-2 IPP 5 Storage and Security of Personal Information NZPRV-6 IPP 13 Unique Identifiers, Privacy Impact Assessment, Privacy by Design NZPRV-8 Privacy Officer, OPC Cooperation, Compliance Notices, Complaints, Training ISMSP-PI-01 Personal Information Collection ISMSP-PI-04 Cross-Border Transfer ISMSP-SYS-02 Encryption Implementation OB-CX.2 Granular Consent Management OB-SEC.2 Transport Layer Security OB-SEC.4 Certificate Management ASD37-17 TLS encryption between email servers (Limited) ASD37-27 Outbound data loss prevention (Very Good) AWWA-3.2 Remote Access Security AWWA-3.4 Encryption and Data Protection AL-DPA-12 International Data Transfers AL-DPA-14 Direct Marketing BSI-08 Cryptographic protection of data BSI-15 Security categorization CJIS-8 Media Protection CJIS-9 System and Communications Protection FTC-Safeguards-9-Elements 9 Safeguard Elements - Access, Inventory, Encryption, Secure-Dev, MFA, Disposal, Change-Mgmt, Monitoring, Pen-Test (16 CFR 314.4(c)) FTC-Safeguards-Scope-Defs Scope, Definitions and Financial Institution Applicability (16 CFR 314.1, 314.2) FDBR-ControllerObligations-DPA-Notice Controller + Processor Obligations + Data Protection Assessments (Fla. Stat. 501.707, 501.708, 501.71, 501.711) FDBR-Scope-Defs Scope, Applicability Thresholds and Definitions (Fla. Stat. 501.701, 501.702, 501.703, 501.704) 27010-10.1 Cryptographic Protection 27010-8.2 Membership Termination 27557-3 Terms and definitions 27557-4.3 Individual impact consideration NDPA-1 Applicability, Scope, and Carve-Outs NDPA-4 Sensitive Data Processing Consent and Childrens Protections OWASPTOP10-2 A02:2025 Cryptographic Failures and Secret Management OWASPTOP10-4 A04:2025 Insecure Design and Business Logic (incl. A11 API Abuse) RUSPD-1 Scope, Definitions, Principles under 152-FZ RUSPD-4 Special Categories, Biometric Data PIPA-CPO-DPO-Privacy-Officer-PIA-Personal-Information-Impact-Assessment-Articles-31-33 Korea PIPA CPO + DPO + Privacy Officer + PIA + Personal Information Impact Assessment + Articles 31-33 PIPA-Data-Subject-Rights-Access-Correction-Erasure-Portability-Automated-Decisions-Articles-35-37-2 Korea PIPA Data Subject Rights + Access + Correction + Erasure + Portability + Article 35-37 TURKEYKVKK-2 Information Notice and Data Subject Rights TURKEYKVKK-3 Special Categories and Sensitive Data USMCADIGITAL-1 Cross-Border Data Flows and Localisation USMCADIGITAL-2 Personal Information Protection and Consumer Protection VERMONTAICDA-3 Bias Testing, Discrimination Prevention, Transparency VERMONTAICDA-4 Vermont AG Enforcement and Cure VIETNAMCYBER-2 Prohibited Acts (Access, Interception, Forgery, Content) VIETNAMCYBER-4 Incident Reporting and Cooperation API1164-02 Risk Management Framework DS-2 Ensure software supply chain security CA-10 Selects and Develops Control Activities QMSR-820.45 Device labelling and packaging controls (§820.45) FFIEC-09 Encryption and key management 60601-1.7.1 Equipment identification and marking 62351-9 Cyber security key management IEC62443-02 System security categorization ISO-14064-1-5.4 Categorization of indirect GHG emissions ISO-26000-6.7 Consumer issues ISO23894-A.5 Privacy and Data Protection in AI ISO27019-02 System security categorization 29115-7.4 Level of Assurance 4 (LoA4) STANAG-2 STANAG 4778 Metadata Binding Mechanism and Cryptographic Binding ORANWG11-3 Cryptography, TLS, SSH, IPsec, and PKI Lifecycle Management OWASPAPI-6 Security Misconfiguration and Secure API Design OWASPLLM-3 Sensitive Information Disclosure and Privacy (LLM02) OPENBANK-3 Mutual TLS, Token Binding, Request Signing (JWS), Key Management PSPF24-2 Information Security, Cybersecurity Maturity, Essential Eight RIDTPPA-2 Consumer Rights (Access, Correction, Deletion, Portability, Opt-Out) TEFCAREC-1 Common Agreement Conformance and Onboarding D.1 Incident Response Planning CPSC-CS.3 Data Protection for Safety Systems Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Query this from an agent The graph holds this control, the 277 it maps to, and the evidence behind each claim, over MCP and REST.