OWASP Top 10:2025
Access Control

OWASP Top 10:2025 OWASPTOP10-1: A01:2025 Broken Access Control

Address OWASP Top 10 A01 Broken Access Control per OWASP Top 10:2025. Broken Access Control occurs when authorisation enforcement is missing + bypassable + inconsistent across web applications including bypass via URL tampering + forced browsing + tampering with metadata + role manipulation + insecure direct object reference (IDOR) + missing function-level access checks + CORS misconfiguration. Mitigations include (a) implement access control as server-side enforcement consistently across all routes + (b) implement deny-by-default policy with explicit allow + (c) implement object-level + function-level + property-level access checks + (d) implement RBAC + ABAC where appropriate + (e) protect against IDOR via unpredictable identifiers + ownership checks + (f) implement rate limiting + lockout against access control brute force + (g) test access control thoroughly across user roles + tenancy boundaries + with negative testing.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 296 controls across 153 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
  • CWE-22 Improper Limitation of a Pathname to a Restricted Directory (Path Traversal)
  • CWE-269 Improper Privilege Management
  • CWE-352 Cross-Site Request Forgery (CSRF)
  • CWE-862 Missing Authorization
  • CWE-863 Incorrect Authorization
  • AWWA-1.1 Security Policy and Governance
  • AWWA-1.3 Security Awareness and Training
  • AWWA-2.1 User Access Management
  • AWWA-2.4 Physical Access Controls

BSI IT-Grundschutz · 4 controls

  • BSI-02 Access enforcement and least privilege
  • BSI-03 Multi-factor authentication requirements
  • BSI-04 Remote access controls
  • BSI-05 Wireless access restrictions
  • DA-1 Enterprise Data Architecture
  • DIQ-2 Data Quality Management
  • DSO-2 Data Security
  • DSO-3 Data Access Management
  • ICAO-ANX17-Chap2-ThreatAssessment-RiskManagement-Cyber-GASeP ICAO Annex 17 Chapter 2 - Threat Assessment + Risk Management + Cyber Threats to Critical Aviation Systems (Amendment 17/18)
  • ICAO-ANX17-Chap4-AccessControl-AirsideRestricted-Personnel-Background ICAO Annex 17 Chapter 4 - Access Control + Airside + Security Restricted Area + Personnel Background Checks + Vetting
  • ICAO-ANX17-Chap4-Cargo-Mail-Catering-Stores-Supplies-RegulatedAgent-KnownConsignor ICAO Annex 17 Chapter 4 - Cargo + Mail + Catering + Stores + Supplies Security + Regulated Agent + Known Consignor + Supply Chain
  • ICAO-ANX17-Chap4-SpecialCategories-Weapons-InFlightSecurity-CockpitDoor ICAO Annex 17 Chapter 4 - Special Categories of Passengers + Weapons + In-Flight Security Officers + Flight Crew Compartment Door

ISO/IEC 27011:2024 · 4 controls

  • 27011-1 Scope
  • 27011-3 Terms and definitions
  • 27011-5.3 Segregation of duties
  • 27011-8.1 User Endpoint Devices

MARS-E · 4 controls

API 1164 · 3 controls

  • API1164-06 Access Control
  • API1164-07 Remote Access
  • API1164-09 Patch and Vulnerability Management
  • CAT-D3-1 Preventative controls
  • CAT-D4-3 Third-party access controls
  • CAT-IRP-4 Organizational characteristics

FedRAMP Rev 5 · 3 controls

  • FEDRAMP-CM-6 Configuration Settings
  • FEDRAMP-CP-9 System Backup
  • FedRAMP-Boundary Authorization Boundary, SSP, SAR, POA&M documentation
  • GhCSA-CII-Designation-Plan-Audit-Risk CII Designation, Registration, Cybersecurity Plan, Audit and Risk Assessment
  • GhCSA-Incident-Reporting-CERT-GH Cybersecurity Incident Reporting (24-Hour to CSA) and National CERT-GH Engagement
  • GhCSA-Scope-CSAGhana-Defs Scope, Cyber Security Authority (CSA Ghana) and Key Definitions

ISO/IEC 27004:2016 · 3 controls

  • 27004-3 Terms and definitions
  • 27004-A.2 Patching and Vulnerability Measures
  • 27004-B.1 Example measurement definitions
  • 27557-1 Scope
  • 27557-3 Terms and definitions
  • 27557-6.2 Scope, context, and criteria for privacy

ISO/IEC 29100:2024 · 3 controls

  • 29100-1 Scope
  • 29100-3 Terms and definitions
  • 29100-4.1 Actors and roles
  • ITAR-Part123-125-ExportLicensing-DSP-5-DSP-73-DSP-61-MLA-TAA-Classified-Information-Routed ITAR Parts 123-125 Export Licensing - DSP-5 Permanent Export + DSP-73 Temporary Export + DSP-61 Temporary Import + DSP-83 + Manufacturing License Agreements (MLA) + Technical Assistance Agreements (TAA) + Classified Information + Routed Export Transactions
  • ITAR-Scope-AECA-22USC2778-22CFR120-130-DDTC-USML-21Categories-DefenseArticle-Service-TechnicalData ITAR Scope + Arms Export Control Act (22 USC 2778) + 22 CFR Parts 120-130 + Directorate of Defense Trade Controls (DDTC) + United States Munitions List (USML) 21 Categories + Defense Article/Service/Technical Data Definitions
  • ITAR-TechnicalData-DefenseServices-DeemedExport-ForeignPerson-Access-USPersons-FOC-AUKUS-Exemptions ITAR Technical Data + Defense Services + Deemed Export Rule + Foreign Person Access + US Persons Only + FOCI Foreign Ownership Control Influence + AUKUS Pillar 2 Exemptions + DD-2345 MCTL

MDS2 (Medical Device) · 3 controls

  • MDS2-PHI-Data-Handling-DATA-Storage-STCF-Transmission-TXCF-TXIG-Encryption-FIPS MDS2 PHI Handling + DATA + STCF Storage + TXCF Transmission + TXIG Integrity + Encryption + FIPS
  • MDS2-Person-Node-Authentication-Authorization-Auto-Logoff-AUTH-PAUT-NAUT MDS2 Authentication + Authorization + Auto Logoff + PAUT + NAUT + AUTH + Identity Management
  • MDS2-Physical-Security-PLOK-Workstation-Disposal-Backup-DTBK-Disaster-Recovery MDS2 Physical Security + PLOK + Workstation + Disposal + Backup + DTBK + Disaster Recovery

MITRE ATT&CK · 3 controls

MTCS (Singapore) · 3 controls

  • MTCS-Asset-IAM-Cryptography-Multi-Tier-Asset-Inventory-RBAC-MFA-PAM-FIPS-HSM-Quantum-Safe MTCS Asset Mgmt + IAM + Cryptography + Asset Inventory + RBAC + MFA + PAM + FIPS + HSM + Quantum-Safe
  • MTCS-Governance-ISMS-Risk-HR-Lifecycle-Compliance-Cloud-Strategy-Roles-Responsibilities MTCS Governance + ISMS + Risk Management + HR Security + Cloud Service Lifecycle + Compliance + Roles
  • MTCS-Logging-Monitoring-Compliance-Audit-SLA-Configuration-SIEM-SOAR-Cloud-Monitoring-CSPM MTCS Logging + Monitoring + Compliance + Audit + SLA + Configuration + SIEM + SOAR + CSPM
  • NISTPF-3 Control-P - Privacy Controls, Data Management, and Disassociated Processing
  • NISTPF-5 Protect-P Access Control (PR.AC-P)
  • NISTPF-8 Protect-P Information Protection Processes (PR.PO-P)

NIST SP 800-66 · 3 controls

  • NISTSP66-2 Workforce Security, Information Access Management, and Awareness Training
  • NISTSP66-5 Physical Safeguards: Facility Access, Workstation Use and Security, Device and Media Controls
  • NISTSP66-6 Technical Safeguards: Access Control, Audit Controls, Integrity, Person Authentication
  • NISTSP82-1 OT Security Program Governance, Policy, Roles, and Safety-Security Integration
  • NISTSP82-4 OT Access Control, Identity, Authentication, and Remote Access
  • NISTSP82-7 OT Incident Response, Forensics, Recovery, and Continuity
  • NG-NDPA-1 Scope, Applicability, and Establishment of Nigeria Data Protection Commission
  • NG-NDPA-2 Lawful Basis, Consent, and Data Protection Principles
  • NG-NDPA-5 Security of Processing, Breach Notification, and DPIA
  • ORANWG11-2 O-RAN Interface Security: E2, A1, O1, O2, Open Fronthaul
  • ORANWG11-3 Cryptography, TLS, SSH, IPsec, and PKI Lifecycle Management
  • ORANWG11-6 Security Test Specifications, Certification, and Conformance
  • DSOMM-1 Culture, Organization, Education, and Governance
  • DSOMM-3 Build, Deployment, Infrastructure Hardening, and Secrets Management
  • DSOMM-4 Test and Verification - SAST, DAST, IAST, SCA, Penetration Testing
  • OWASPLLM-1 Prompt Injection and System Prompt Leakage (LLM01 + LLM07)
  • OWASPLLM-2 Improper Output Handling and Misinformation (LLM05 + LLM09)
  • OWASPLLM-6 Excessive Agency and Unbounded Consumption (LLM06 + LLM10)
  • PSPF24-1 Security Culture, Governance, Risk Management
  • PSPF24-2 Information Security, Cybersecurity Maturity, Essential Eight
  • PSPF24-4 Physical Security
  • 58.1 Scope
  • 58.3 Definitions
  • ASD37-18 Restrict administrative privileges (Essential)
  • ASD37-20 Multi-factor authentication (Essential)
  • AL-DPA-1 Scope and Definitions
  • AL-DPA-3 Lawful Basis for Processing
  • AT-DSG-2 Section 2 - Scope and application
  • AT-DSG-8 Section 22 - Functions and powers of the DPA
  • FTC-Safeguards-9-Elements 9 Safeguard Elements - Access, Inventory, Encryption, Secure-Dev, MFA, Disposal, Change-Mgmt, Monitoring, Pen-Test (16 CFR 314.4(c))
  • FTC-Safeguards-Scope-Defs Scope, Definitions and Financial Institution Applicability (16 CFR 314.1, 314.2)
  • FDBR-702 Definitions (§501.702)
  • FDBR-Scope-Defs Scope, Applicability Thresholds and Definitions (Fla. Stat. 501.701, 501.702, 501.703, 501.704)
  • GAMP5-Lifecycle-VModel-URS-FS-DS-IQOQPQ V-Model Lifecycle - URS + FS + DS + IQ + OQ + PQ + Traceability
  • GAMP5-Risk-CriticalThinking Risk-Based Approach, Critical Thinking and 5 Key Concepts

HITECH Act · 2 controls

  • HITECH-Coord-HIPAA-Privacy-Security-Cures-ONC HITECH Coordination with HIPAA Privacy Rule + HIPAA Security Rule (Verified Separately) + 21st Century Cures Act + ONC
  • HITECH-SubtitleD-StrengthIndividualRights HITECH Subtitle D - Strengthened Individual Rights (Electronic Access, Accounting of Disclosures, Restrictions, Sale Prohibition)
  • IATA-IOSA-Section1-ORG-Organization-ManagementSystem-SMS IATA IOSA Section 1 - ORG Organization and Management System + Safety Management System (SMS) + Safety Policy + Hazard ID + Quality
  • IATA-IOSA-Section8-SEC-SecurityManagement-AVSEC IATA IOSA Section 8 - SEC Security Management + Aviation Security Programme (AVSEC) + ICAO Annex 17 Alignment
  • IATF16949-Clause10-Improvement-Nonconformity-CorrectiveAction-Problem-ErrorProof IATF 16949 Clause 10 - Improvement + Nonconformity + Corrective Action + Problem Solving + Error Proofing + Continual Improvement
  • IATF16949-Clause9-Performance-Monitoring-InternalAudit-ManagementReview IATF 16949 Clause 9 - Performance Evaluation + Monitoring + Internal Audit + Manufacturing Process Audit + Management Review
  • 60601-1.3 Terminology and definitions
  • 60601-1.4.1 General requirements
  • 62351-2 Glossary of terms
  • 62351-8 Role-based access control (RBAC)
  • IMO-MSC-FAL-Identify-AssetInventory-ThreatsVulnerabilities-CyberRiskAssessment-RolesResponsibilities IMO MSC-FAL Identify Function - OT/IT Asset Inventory + Threats + Vulnerabilities + Cyber Risk Assessment + Roles and Responsibilities + Crew + CSO + DPA
  • IMO-MSC-FAL-Protect-AccessControl-NetworkSegmentation-MalwareDefence-Patch-Awareness-DataSecurity IMO MSC-FAL Protect Function - Access Control + Network Segmentation + Malware Defence + Patch Management + Awareness Training + Data Security + Crew BYOD + Removable Media

ISMAP (Japan) · 2 controls

ISO/IEC 27010:2015 · 2 controls

  • 27010-9.1 Access Control to Shared Information
  • 27010-9.2 Authentication of Sources

ISO/IEC 27014:2020 · 2 controls

  • 27014-1 Scope
  • 27014-3 Terms and definitions

ISO/IEC 27400:2022 · 2 controls

  • 27400-3 Terms and definitions
  • 27400-6.1 Secure Device Design

ISO/IEC 29147:2018 · 2 controls

  • 29147-3 Terms and definitions
  • 29147-9.2 Contact mechanisms and scope

ISO/IEC 30111:2019 · 2 controls

  • 30111-3 Terms and definitions
  • 30111-5.1 Organizational policy
  • IsraelPPL-Database-Registration-Definition-Document-Security-Level-Classification-Sec7-8-PPA-Registry Israel POPL Database Registration + Section 7 Database Definitions + Section 8 Registration Requirement + Database Definition Document + Security Level Classification + PPA Public Registry + Amendment 13 Threshold Changes
  • IsraelPPL-Scope-5741-1981-Knesset-Amendment13-March2024-BasicLaw-Dignity-Sec1-Right-Privacy Israel Protection of Privacy Law 5741-1981 Scope + Knesset + Amendment No. 13 March 2024 + Basic Law Human Dignity and Liberty + Section 1 Right to Privacy + Constitutional Status + Chapter 1 Infringement of Privacy
  • NAIC-2 Information Security Program (ISP) - Section 4
  • NAIC-6 Cybersecurity Event Investigation and Notification - Sections 6 and 7
  • STANAG-1 STANAG 4774 Confidentiality Label Schema and XML Structure
  • STANAG-2 STANAG 4778 Metadata Binding Mechanism and Cryptographic Binding
  • NISTSP115-1 Scope, Methodology, and Assessment Planning
  • NISTSP115-8 Operational Considerations - Tools, Reporting Templates, ISMS Integration, Annex Material

NIST SP 800-123 · 2 controls

  • NISTSP123-3 Authentication, Access Control, and Account Management
  • NISTSP123-8 Governance, Policies, and ISMS Integration

NIST SP 800-137 · 2 controls

  • NISTSP137-1 ISCM Strategy, Governance, and Volatility Assessment
  • NISTSP137-6 Malware, Identity Access, and Network Boundary Monitoring

NIST SP 800-145 · 2 controls

  • NISTSP145-7 Cloud Procurement Standards Aligned to NIST SP 800-145 Definition
  • NISTSP145-8 Governance, Reporting, and Stakeholder Education on Cloud Definition

NIST SP 800-146 · 2 controls

  • NISTSP146-1 Cloud Adoption Strategy, Workload Suitability, and Decision Framework
  • NISTSP146-6 Cloud Security and Privacy Recommendations

NIST SP 800-61 Rev. 3 · 2 controls

  • NISTSP61-2 Computer Security Incident Response Team (CSIRT) Structure and Staffing
  • NISTSP61-5 Containment, Eradication, and Recovery

NIST SP 800-63-4 · 2 controls

  • NISTSP63R4-1 Digital Identity Risk Management and IAL/AAL/FAL Assurance Level Selection
  • NISTSP63R4-3 Authentication: Authenticator Types, MFA, Phishing-Resistance, and Syncable Authenticators

NIST SP 800-92 · 2 controls

  • NISTSP92-1 Log Management Programme, Policy, Roles, and Operational Runbooks
  • NISTSP92-4 Log Management: Time Synchronisation, Parsing, Storage, Integrity, Access Control
  • NRC7354-2 Critical Digital Asset (CDA) Identification, Scope, and Boundary
  • NRC7354-4 Security Controls Implementation per NRC RG 5.71 Appendix B/C
  • NDPA-1 Applicability, Scope, and Carve-Outs
  • NDPA-2 Consumer Rights - Access, Correct, Delete, Portability, Appeal
  • OWASPAPI-1 Broken Object Level Authorization (BOLA) and BFLA
  • OWASPAPI-3 Broken Object Property Level Authorization (BOPLA)

OWASP ASVS · 2 controls

OWASP MASVS · 2 controls

OWASP SAMM · 2 controls

  • OWASPSAMM-1 Governance: Strategy, Policy, Compliance, Education, Champions
  • OWASPSAMM-2 Design: Threat Assessment, Security Requirements, Security Architecture

OpenSSF Scorecard · 2 controls

  • OSSFSC-1 Branch Protection, Code Review, and Repository Governance
  • OSSFSC-3 Build, CI/CD Security, Workflow Permissions, Dangerous Patterns
  • ASTWO-7 Deficiency Evaluation, Material Weakness, and Communication
  • ASTWO-8 ICFR Opinion, Basis, Definition, Limitations, Combined vs Separate Reports
  • PAKPDPB-7 NCPDP, Registration, Records, Processor Contracts, DPO
  • PAKPDPB-8 Enforcement, Penalties, Complaints, Retention, Training
  • C1 Organizational Boundary
  • C3 Scope 1 and 2 Coverage

South Korea PIPA · 2 controls

  • PIPA-Cross-Border-Transfer-Articles-28-8-28-9-Adequacy-Standard-Contract-Certification-EU Korea PIPA Cross-Border Transfer + Articles 28-8 + 28-9 + Adequacy + EU 2021
  • PIPA-Data-Subject-Rights-Access-Correction-Erasure-Portability-Automated-Decisions-Articles-35-37-2 Korea PIPA Data Subject Rights + Access + Correction + Erasure + Portability + Article 35-37
  • CFR211-A-3 Section 211.3 - Definitions

APPI · 1 control

  • APPI-A26 Report of Leakage to the Commission and Notification to the Person
  • 4.4.1 Resources, Roles, Responsibility, and Authority
  • AZ-DPA-2 Article 2 - Basic Concepts

Bahrain PDPL · 1 control

COBIT 2019 · 1 control

  • COBIT-BAI02 Managed requirements definition
  • CA-ITSG33-SC-01 Security Control Catalogue
  • CTDPA-1 Definitions
  • LOPDP-EC-Security-Processor-Breach-Notification-Articles-37-45-Encryption-72-Hour-SPDP-Notification-CSIRT Ecuador LOPDP Security + Processor + Breach Notification + Articles 37-45 + 72-Hour

FDA 21 CFR Part 11 · 1 control

  • Part11.AccessAndAuth Access control + authority + device checks (21 CFR §11.10(d) + (f) + (g) + (h))
  • QMSR-ISO13485-Sec5 Management responsibility (ISO 13485:2016 Section 5 - incorporated via §820.10)
  • FFIEC-05 Roles and responsibilities definition

FISMA · 1 control

  • FISMA-CIRCIA-ZTA-EO14028 CIRCIA, Zero Trust Architecture, EO 14028 + 14110 + OMB Memoranda
  • FERPA-Safeguards-PTAC Data Security Safeguards for PII in Education Records (PTAC Best Practices, SPPO Guidance)

FedRAMP High · 1 control

  • CA-9 Internal System Connections

FedRAMP Moderate · 1 control

  • CA-9 Internal System Connections
  • UAE-PDPL-Art.6_7 Sensitive personal data and children's data (UAE PDPL Articles 6-7)
  • Sapin2-Pillar1-Code-of-Conduct Pillar 1 - Anti-Corruption Code of Conduct

GLBA · 1 control

  • GLBA-Sec6801-PolicyDuty-SafeguardingStandard GLBA Section 6801 - Privacy Obligation Policy and Safeguarding Standard
  • GLI33-EventWagering-System-Architecture GLI-33 Event Wagering System Architecture, Wager Engine, Odds Engine and Risk Management
  • HKMA-CRAF-Domain3-4-Protection-Detection HKMA C-RAF Domain 3 (Protection) + Domain 4 (Detection) - Access, Data, Infrastructure, Application, Monitoring, Testing, Threat Intel

HKMA SPM · 1 control

  • HKMA-SPM-CG-IC-AC-Governance-Control-Audit HKMA SPM Corporate Governance (CG-1/2/3/5/6), Internal Control (IC-1/5), Auditing (AC-G)
  • IACS-UR-E26-Protect-AccessControl-Authentication-IAM-Roles IACS UR E26 Protect Goal - Access Control + Identity + Authentication + Authorization + User Management

IEEE 1686 · 1 control

  • IEEE1686-Section5.1-AccessControl-Accounts-Roles-Password-Session-Remote IEEE 1686 Section 5.1 - Electronic Access Account Management + Roles + Password + Failed Login + Session + Remote Access + Personnel

ISO/IEC 23837:2023 · 1 control

  • 23837-1.1 Scope

ISO/IEC 27007:2020 · 1 control

  • 27007-5.2 Audit Programme Objectives

ISO/IEC 27031:2011 · 1 control

  • 27031-5.1 IRBC Policy
  • 27050-1.4 Terms and definitions
  • 29115-3 Terms and definitions

ISO/IEC 29134:2023 · 1 control

  • 29134-3 Terms and definitions
  • ITU-Scope-Constitution-Convention-Radio-Regulations-WRC-Quadrennial-Treaty-Art1-Definitions ITU Constitution + Convention + Radio Regulations Scope + Article 1 Definitions + Article 2 Nomenclature + WRC World Radiocommunication Conference Quadrennial Treaty Process + Member States + Sector Members
  • BIPA-SEC5-1 Biometric Identifier Definition

India DPDP Act · 1 control

  • INCDPA-Security-ReasonablePractices-Breach-Notification-Records-Encryption-Pseudonymisation Indiana CDPA Security + Reasonable Practices + Breach Notification + Indiana Breach Notification Law (IC 24-4.9) + Records + Encryption + Pseudonymisation + De-Identification

Indonesia PDP Law · 1 control

LGPD · 1 control

  • LGPD-BR-Security-Article-46-48-Breach-Notification-ANPD-Reasonable-Time-Incident-Response-CSIRT Brazil LGPD Security + Article 46-48 + Breach Notification + ANPD + Incident Response
  • DOM172-Security-Measures-Article-25-Encryption-Pseudonymization-Access-Control-Incident-Handling-Breach-Notification-Article-22 Dominican Republic Law 172-13 Security Measures + Article 25 + Encryption + Breach Notification

Liechtenstein DPA · 1 control

MITRE D3FEND · 1 control

Malaysia PDPA 2010 · 1 control

  • MY-PDPA-Cross-Border-Transfer-Section-129-Whitelist-Abolition-2024-Adequacy-SCC-BCR-Processor-Direct-Marketing Malaysia PDPA Cross-Border + Section 129 + Whitelist Abolition 2024 + Adequacy + SCC + BCR + Processor + Marketing

Mauritius DPA · 1 control

  • MU-DPA-Governance-DPO-Designation-Section-25-DPO-ROPA-DPIA-Codes-Section-38-Commissioner-Registration Mauritius DPA Governance + DPO + ROPA + DPIA + Codes Section 38 + Commissioner Registration

Mexico LFPDPPP · 1 control

  • MX-LFPDPPP-Governance-Officer-Reglamento-47-50-Security-Manual-57-Risk-Assessment-61-Self-Regulation-Parameters-2014 Mexico LFPDPPP Governance + Officer + Reglamento 47 + Security Manual 50 + Risk Assessment 57 + Self-Regulation Parameters 2014

MiFID II / MiFIR · 1 control

  • MN-CDPA-Chief-Privacy-Officer-Section-325O-06-MN-UNIQUE-Designation-Privacy-Programme-Training Minnesota CDPA Chief Privacy Officer + Section 325O.06 + MINNESOTA-UNIQUE Designation + Privacy Programme + Training
  • MAS-TRM-Governance-Chapters-2-3-Board-Senior-Management-Risk-Framework-Information-Asset-Management MAS TRM Governance + Chapters 2-3 + Board + Senior Management + Risk Framework + Information Asset Management
  • MT-CDPA-Sensitive-Data-MCA-30-14-2802-Opt-In-Children-13-Parental-Consent-Minors-13-16-Opt-In Montana CDPA Sensitive Data + MCA 30-14-2802 + Affirmative Opt-In + Children Under 13 Parental + Minors 13-16 Opt-In
  • PQC-4 FIPS 205 SLH-DSA Implementation - Stateless Hash-Based Digital Signature

NIST SP 800-122 · 1 control

  • NISTSP122-5 PII Security Controls - Encryption, Access Control, Storage, Audit

NIST SP 800-144 · 1 control

  • NISTSP144-1 Cloud Governance, Risk Assessment, and Provider Trust Evaluation

NIST SP 800-88 · 1 control

  • NISTSP88-1 Media Sanitization Policy, Roles, and Decision Framework
  • NHPA-7 Data Protection Assessments and Processor Contracts
  • NJDPA-2 Consumer Rights - Access, Correct, Delete, Portability, Appeal
  • NGNDPR-5 Security of Personal Data, Breach Notification, and DPIA under NDPR Section 2.6-Security
  • AUNDB-A3 Eligible Data Breach Determination and Serious Harm Threshold
  • OCCHS-1 Scope, Applicability, and Definitions of Heightened Standards

OSFI B-13 · 1 control

  • OSFIB13-1 Governance, Risk Management, and Three Lines of Defense
  • OMANCS-3 Identity and Access Management, Authentication, Privileged Access
  • OPENBANK-2 Strong Customer Authentication (SCA), Consent Lifecycle, and Customer UX
  • OREGONCPA-5 Data Protection Assessments, Privacy by Design, Security Practices

PCI DSS 4.0 · 1 control

  • 2.2.2 2.2.2 Vendor default accounts managed
  • AUPRV-4 APP 10-11 Quality, Security of Personal Information
  • EHDSREG-1 Mandatory Requirements for EHR Systems (Articles 14-29)

SWIFT CSCF · 1 control

  • SWIFTCSCF-1 Restrict Internet Access and Protect Critical Systems (Objective 1)
  • TEFCAREC-1 Common Agreement Conformance and Onboarding
  • ACE-CR-4 Cargo Release Authorization
  • CPSC-CS.2 Authentication and Access Controls
  • USSDWA-2 Cybersecurity Practices (Assessment, Access, Network, IR)
  • 15 U.S.C. § 78dd-2(h) Definition of Domestic Concern
  • USMCADIGITAL-1 Cross-Border Data Flows and Localisation
  • VIETNAMCYBER-2 Prohibited Acts (Access, Interception, Forgery, Content)
  • W3CVCDM-1 Three-Party Ecosystem (Issuer, Holder, Verifier)

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 296 it maps to, and the evidence behind each claim, over MCP and REST.