OWASP ASVS
V8 Data Protection

OWASP ASVS OWASPASVS-8: Data Protection (V8 + V8.3)

Per OWASP ASVS V8 + V8.3: implement data protection. Requirements include (a) classify sensitive data + apply appropriate protection per classification + (b) implement encryption at rest + in transit + appropriate to classification + (c) implement data minimisation + retention limits + secure deletion + (d) protect data in memory + during processing + (e) protect against caching + browser history exposure of sensitive data + (f) protect against device storage exposure + (g) implement privacy controls aligned to applicable regulation (GDPR + CCPA + APPI + similar) including data subject rights.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 91 controls across 51 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

API 1164 · 4 controls

  • API1164-02 Risk Management Framework
  • API1164-17 Wireless and Field Communications
  • API1164-18 Field Device Security
  • API1164-19 Safety Instrumented Systems Interface

NIST SP 800-61 Rev. 3 · 4 controls

  • NISTSP61-1 Incident Response Policy, Plan, and Procedures
  • NISTSP61-3 Preparation: Communications, Toolkits, Training, Exercises, Threat Intelligence
  • NISTSP61-4 Detection and Analysis: Sources, Triage, Categorisation, Prioritisation
  • NISTSP61-5 Containment, Eradication, and Recovery
  • ASD37-34 Regular backups (Essential)
  • ASD37-35 Business continuity and disaster recovery plans (Very Good)
  • ASD37-36 System recovery capabilities (Very Good)

ISO/IEC 27031:2011 · 3 controls

  • 27031-8.1 Exercising and Testing
  • 27031-8.2 Maintaining IRBC
  • 27031-9.3 Management Review

MITRE ATT&CK · 3 controls

MITRE D3FEND · 3 controls

NIST SP 800-92 · 3 controls

  • NISTSP92-2 Log Generation: OS, Application, Security Tools, Network, Cloud, Required Event Content
  • NISTSP92-6 Log Retention: Policy, Tiered Storage, Backup, Secure Disposal, Legal Hold
  • NISTSP92-7 Privacy in Logs, Sensitive Content Handling, Cloud and SaaS Log Considerations

FedRAMP Rev 5 · 2 controls

  • FedRAMP-Boundary Authorization Boundary, SSP, SAR, POA&M documentation
  • FedRAMP-IncidentReporting FedRAMP incident reporting to PMO and US-CERT
  • IACS-UR-E26-Identify-AssetInventory-CBS-NetworkArchitecture-Risk IACS UR E26 Identify Goal - Asset Inventory of Computer Based Systems + Network Architecture Documentation + Risk-Assessable Scope
  • IACS-UR-E26-Respond-Recover-IncidentResponse-Recovery-Backup-Lessons IACS UR E26 Respond + Recover Goals - Incident Response + Communication + Recovery + Backup + Lessons Learned

IEEE 1686 · 2 controls

  • IEEE1686-IR-Recovery-Reporting-Exercises-Drills-RECOV IEEE 1686 - Incident Response + Recovery from Failed Update + Reporting to Authorities + Coordination with Sector-Specific Agencies + Exercises and Drills
  • IEEE1686-Scope-IED-Substation-Automation-2022-IEC-NERC-NIST-Coord IEEE 1686 - Scope + Intelligent Electronic Devices (IEDs) + Substation Automation + 2022 Edition + Coordination with IEC 62351 + IEC 62443 + NERC CIP + NIST SP 800-82
  • IMO-MSC-FAL-Recover-BackupRestore-ContinuityOfNavigation-LessonsLearned-Drills IMO MSC-FAL Recover Function - Backup and Restore + Continuity of Navigation + Continuity of Cargo Operations + Continuity of Propulsion + Lessons Learned + Drills + Resilience
  • IMO-MSC-FAL-Respond-IncidentResponse-Communication-FlagState-PortAuthority-CIRT-USCGNVIC IMO MSC-FAL Respond Function - Incident Response Plan + Containment + Communication + Flag State + Port Authority + USCG NVIC + Class Society Notification + CIRT

ISO/IEC 27010:2015 · 2 controls

  • 27010-8.1 Membership Onboarding
  • 27010-8.2 Membership Termination
  • NAIC-2 Information Security Program (ISP) - Section 4
  • NAIC-5 Third Party Service Provider Oversight - Section 4(F)(3) and Section 5

NIST SP 800-123 · 2 controls

  • NISTSP123-5 Server Operations - Patching, Malware, Logging, Backup
  • NISTSP123-8 Governance, Policies, and ISMS Integration

NIST SP 800-137 · 2 controls

  • NISTSP137-1 ISCM Strategy, Governance, and Volatility Assessment
  • NISTSP137-7 Incident Response Integration and Ongoing Authorization

NIST SP 800-144 · 2 controls

  • NISTSP144-5 Identity and Access in Cloud, Federation, and Privileged Access
  • NISTSP144-6 Availability, Resilience, BCP/DR, and SLA Management

NIST SP 800-145 · 2 controls

  • NISTSP145-3 Rapid Elasticity Characteristic and Capacity Management
  • NISTSP145-8 Governance, Reporting, and Stakeholder Education on Cloud Definition

NIST SP 800-146 · 2 controls

  • NISTSP146-6 Cloud Security and Privacy Recommendations
  • NISTSP146-7 Service Level, Performance, Reliability, Interoperability, and Portability

NIST SP 800-63-4 · 2 controls

  • NISTSP63R4-4 Authenticator Lifecycle: Binding, Recovery, Replacement, Suspension, Revocation
  • NISTSP63R4-7 Privacy, Records Retention, and User-Controlled Wallets

NIST SP 800-88 · 2 controls

  • NISTSP88-1 Media Sanitization Policy, Roles, and Decision Framework
  • NISTSP88-5 Media Inventory, Tracking, Chain of Custody, and Sanitization Records
  • NISTSP34-2 Business Impact Analysis (BIA): Critical Resources, Recovery Priorities
  • NISTSP34-4 Information System Contingency Plan (ISCP) Development
  • OMANCS-4 Data Protection, Cryptography, and Privacy Alignment
  • OMANCS-7 Business Continuity, Disaster Recovery, and Resilience

OpenSSF Scorecard · 2 controls

  • OSSFSC-2 Dependency Management, Pinning, Updates, Vulnerability Tracking
  • OSSFSC-8 Project Maintenance, Sustainability, Integration with Supply Chain Security
  • 4.4.8 Business Continuity and Recovery
  • QMSR-820.45 Device labelling and packaging controls (§820.45)
  • FIRST-CSIRTF-SA2-ISIM Service Area 2 - Information Security Incident Management (Intake, Analysis, Containment, Recovery, Coordination, Crisis)

FISMA · 1 control

  • FISMA-NIST-800-53-RMF-800-171-FIPS Operationalisation via NIST 800-53 + 800-37 RMF + 800-171 + FIPS 199 + FIPS 200
  • GAMP5-Supplier-Operations-Change-Periodic Supplier Assessment, Operational Phase, Change Control and Periodic Review

GLBA · 1 control

  • GLBA-Subordinate-Rules-Operationalisation GLBA Operationalisation through FTC Safeguards Rule, Privacy Rule, SEC Reg S-P and Banking-Agency Guidelines
  • GhCSA-Implementation-Roadmap Implementation Roadmap - Organizational Roles, Tooling and Metrics
  • HKMA-CRAF-Domain5-6-Response-Recovery-SitAwareness HKMA C-RAF Domain 5 (Response and Recovery) + Domain 6 (Situational Awareness) - Incident Response, Recovery, Threat Landscape, Information Sharing

HKMA SPM · 1 control

  • HKMA-SPM-OR-RR-SA-OperationalResilience HKMA SPM Operational Risk (OR-1), Operational Resilience (OR-2), Recovery Planning (RR-1), Outsourcing (SA-2)
  • 60601-1.7.1 Equipment identification and marking

IEEE 7000 · 1 control

  • IEEE7000-EthicalRisk-Identification-Analysis-Treatment-ValidationOutcomes IEEE 7000 Clauses 8 + 8.1 + 8.2 - Ethical Risk Identification + Analysis + Treatment + Validation of Ethical Outcomes + AI Safety + Robustness + Adversarial Protection

ISMAP (Japan) · 1 control

ISO/IEC 27011:2024 · 1 control

  • 27011-8.6 Data protection and backup

Japan AI Guidelines · 1 control

  • JP-AIG-Risk-Based-AI-System-Categorisation-Tiered-Approach-EU-AI-Act-Aligned-Generative-Foundation-Models Japan AI Guidelines Risk-Based AI System Categorisation + Tiered Approach + EU AI Act Aligned + Generative AI + Foundation Models + High-Risk + Limited-Risk + Minimal-Risk + AISI Capability-Based Thresholds
  • JP-FSA-CYB-Incident-Response-Playbooks-Containment-Eradication-Recovery-Post-Mortem-Tabletop-CSIRT Japan FSA Cybersecurity Incident Response + Playbooks + Containment + Eradication + Recovery + Post-Mortem + Tabletop Exercises + CSIRT + FSA Notification + Customer Communication + Forensics + Lessons Learned

MTCS (Singapore) · 1 control

  • MTCS-Acquisition-Development-Maintenance-Supplier-Vulnerability-DevSecOps-SBOM-SDLC-SCA-API-Container MTCS Acquisition + Development + Maintenance + Supplier + Vulnerability + DevSecOps + SBOM + SDLC + SCA
  • MAS-TRM-Reliability-Data-Centre-Chapters-7-8-RTO-RPO-BCP-DR-System-Availability-4-Hours-12-Months MAS TRM Reliability + Data Centre + Chapters 7-8 + RTO + RPO + BCP + DR + System Availability 4 Hours 12 Months
  • NABERS-3 NABERS Water Performance Rating

NERC CIP · 1 control

  • NERCCIP-6 Incident Reporting and Response Planning + Recovery Plans (CIP-008 + CIP-009)
  • NISTPF-8 Protect-P Information Protection Processes (PR.PO-P)
  • NISTSP115-8 Operational Considerations - Tools, Reporting Templates, ISMS Integration, Annex Material
  • NISTSP82-7 OT Incident Response, Forensics, Recovery, and Continuity
  • NGCB-6 Incident Response, 72-Hour NGCB Notification, and Independent Investigation

OECD AI Principles · 1 control

  • OECDAI-3 Robustness, Security, Safety, and Adversarial Attack Protection

OSFI B-13 · 1 control

  • OSFIB13-3 Cyber Security: Identification, Protection, Detection, Response, Recovery
  • OPENBANK-8 Incident Detection, Response, Customer Notification, Post-Incident Review, BCM

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 91 it maps to, and the evidence behind each claim, over MCP and REST.