Frameworks / Personal Data Act (personopplysningsloven) / NORWAY-5 Personal Data Act (personopplysningsloven)
Security
Personal Data Act (personopplysningsloven) NORWAY-5: Security of Processing, Encryption, Pseudonymization, Access Control Per Norwegian PDPA + GDPR Article 32: security of processing. Requirements include (a) implement appropriate technical + organisational security measures appropriate to risk per GDPR Article 32 + (b) implement Encryption of personal data at rest + in transit + appropriate to classification + (c) implement Pseudonymization Techniques where appropriate + (d) implement Access Control for personal data including authentication + authorisation + audit + (e) conduct Regular Security Testing and Assessment + (f) integrate with broader information security programme + (g) align with NSM (Norwegian National Security Authority) guidance + Datatilsynet expectations.
Maintained by Gerard Blokdyk · Verified against the published standard 31 May 2026 · Control text last updated 21 May 2026 What else in your programme already covers this This control maps to 275 controls across 87 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
ISO27043-11 Access control policy and enforcement ISO27043-14 Privileged access management ISO27043-15 Access review and recertification ISO27043-17 Encryption of data at rest ISO27043-18 Encryption of data in transit ISO27043-19 Certificate management ISO27043-20 Key lifecycle management ISO21434-12 User access management and provisioning ISO21434-14 Privileged access management ISO21434-15 Access review and recertification ISO21434-16 Cryptographic policy and key management ISO21434-17 Encryption of data at rest ISO21434-18 Encryption of data in transit ISO21434-19 Certificate management APPI-A23 Security Control Measures APPI-A24 Supervision of Employees APPI-A26 Report of Leakage to the Commission and Notification to the Person APPI-A31 Provision of Personally Referable Information APPI-A33 Request for Disclosure of Retained Personal Data APPI-A34 Request for Correction, Addition or Deletion UAE-PDPL-Art.10 Data Protection Officer (DPO) (UAE PDPL Article 10) UAE-PDPL-Art.18_19_20_21 Security measures, controller/processor relationship, DPIA (UAE PDPL Articles 18-21) UAE-PDPL-Art.25_26_27_28_29 UAE Data Office establishment, powers, penalties, complaints (UAE PDPL Articles 25-29) UAE-PDPL-Art.4_5 Lawful basis and principles for processing personal data (UAE PDPL Articles 4-5) UAE-PDPL-Art.6_7 Sensitive personal data and children's data (UAE PDPL Articles 6-7) GDPR-Art.10 Processing of personal data relating to criminal convictions GDPR-Art.11 Processing which does not require identification GDPR-Art.15 Right of access by the data subject GDPR-Art.19 Notification obligation regarding rectification, erasure or restriction GDPR-Art.9 Processing of special categories of personal data ISO27799-01 ePHI access controls and authorization ISO27799-02 ePHI encryption at rest and in transit ISO27799-08 Information access management ISO27799-16 Transmission security and encryption ISO27799-17 Facility access controls ISMSP-AC-01 Access Control Policy ISMSP-AC-04 Network Access Control ISMSP-PI-01 Personal Information Collection ISMSP-PI-04 Cross-Border Transfer ISMSP-SYS-02 Encryption Implementation AWWA-2.1 User Access Management AWWA-2.4 Physical Access Controls AWWA-3.2 Remote Access Security AWWA-3.4 Encryption and Data Protection BSI-03 Multi-factor authentication requirements BSI-04 Remote access controls BSI-05 Wireless access restrictions BSI-08 Cryptographic protection of data 27400-5.4 Data and privacy risks 27400-6.2 Device Identity and Authentication 27400-6.3 Secure Update Mechanism 27400-7.3 Data minimization and purpose limitation NISTPF-3 Control-P - Privacy Controls, Data Management, and Disassociated Processing NISTPF-4 Communicate-P - Privacy Notice, Transparency, and Individual Awareness NISTPF-5 Protect-P Access Control (PR.AC-P) NISTPF-7 Protect-P Maintenance and Protective Technology (PR.MA-P, PR.PT-P) NGOB-1 Open Banking Registry Participation, Tiered Categorisation, and KYP NGOB-2 Customer Consent Management and Lifecycle NGOB-3 API Security Standards, mTLS, and Encryption NGOB-5 Fraud Monitoring, Incident Notification, and Reporting to CBN OREGONCPA-3 Consent, Sensitive Data, Children and Teen Protections OREGONCPA-4 Universal Opt-Out, Targeted Advertising, Profiling OREGONCPA-5 Data Protection Assessments, Privacy by Design, Security Practices OREGONCPA-7 Processor Contracts, Cross-Border Transfers, DPAs API1164-06 Access Control API1164-07 Remote Access API1164-09 Patch and Vulnerability Management APP-1 APP 1 - Open and transparent management of personal information APP-3 APP 3 - Collection of solicited personal information APP-5 APP 5 - Notification of the collection of personal information AT-DSG-11 Sections 42-45 - Data subject rights (law enforcement) AT-DSG-13 Section 36 - Scope of law enforcement processing AT-DSG-14 Section 38 - Lawfulness of law enforcement processing AZ-DPA-12 Article 13 - Cross-border transfer AZ-DPA-14 Article 16 - Liability for violations AZ-DPA-15 Article 17 - Dispute resolution BB-DPA-14 Section 15 - Right to Data Portability BB-DPA-16 Section 22 - General Principle for Transfers BB-DPA-21 Sections 61-69 - Data Privacy Officer FEDRAMP-SC-13 Cryptographic Protection FEDRAMP-SC-28 Protection of Information at Rest FEDRAMP-SC-8 Transmission Confidentiality and Integrity IEC62443-07 Personnel risk assessment IEC62443-08 Electronic access perimeter management IEC62443-10 Revocation of access procedures 23837-1.2 Normative references 23837-1.5.2 Cryptographic module requirements 23837-1.5.3 Network device testing requirements 27010-10.1 Cryptographic Protection 27010-9.1 Access Control to Shared Information 27010-9.2 Authentication of Sources 27011-5.3 Segregation of duties 27011-8.1 User Endpoint Devices 27011-8.3 Cryptography and key management ISO27019-07 Personnel risk assessment ISO27019-08 Electronic access perimeter management ISO27019-10 Revocation of access procedures 29100-6.10 Information security 29100-6.5 Use, retention and disclosure limitation 29100-6.9 Accountability 29134-1 Scope 29134-3 Terms and definitions 29134-9.1 PIA report structure ORANWG11-2 O-RAN Interface Security: E2, A1, O1, O2, Open Fronthaul ORANWG11-3 Cryptography, TLS, SSH, IPsec, and PKI Lifecycle Management ORANWG11-8 Supply Chain, Secure Development Lifecycle, Privacy, Multi-Vendor Trust IM8-CLD.2 Cloud Security Controls IM8-DSS.3 Secure Development Practices IM8-SEC.2 Access Control PIPA-CPO-DPO-Privacy-Officer-PIA-Personal-Information-Impact-Assessment-Articles-31-33 Korea PIPA CPO + DPO + Privacy Officer + PIA + Personal Information Impact Assessment + Articles 31-33 PIPA-Cross-Border-Transfer-Articles-28-8-28-9-Adequacy-Standard-Contract-Certification-EU Korea PIPA Cross-Border Transfer + Articles 28-8 + 28-9 + Adequacy + EU 2021 PIPA-Data-Subject-Rights-Access-Correction-Erasure-Portability-Automated-Decisions-Articles-35-37-2 Korea PIPA Data Subject Rights + Access + Correction + Erasure + Portability + Article 35-37 DSO-2 Data Security DSO-3 Data Access Management CJIS-8 Media Protection CJIS-9 System and Communications Protection CAT-D3-1 Preventative controls CAT-D4-3 Third-party access controls FFIEC-08 Application security controls FFIEC-09 Encryption and key management FTC-Safeguards-9-Elements 9 Safeguard Elements - Access, Inventory, Encryption, Secure-Dev, MFA, Disposal, Change-Mgmt, Monitoring, Pen-Test (16 CFR 314.4(c)) FTC-Safeguards-Scope-Defs Scope, Definitions and Financial Institution Applicability (16 CFR 314.1, 314.2) FDBR-ControllerObligations-DPA-Notice Controller + Processor Obligations + Data Protection Assessments (Fla. Stat. 501.707, 501.708, 501.71, 501.711) FDBR-Scope-Defs Scope, Applicability Thresholds and Definitions (Fla. Stat. 501.701, 501.702, 501.703, 501.704) 62351-8 Role-based access control (RBAC) 62351-9 Cyber security key management 27557-3 Terms and definitions 27557-4.3 Individual impact consideration OMANCS-3 Identity and Access Management, Authentication, Privileged Access OMANCS-4 Data Protection, Cryptography, and Privacy Alignment OSSFSC-3 Build, CI/CD Security, Workflow Permissions, Dangerous Patterns OSSFSC-6 Signed Releases, Provenance, Trusted Publishing, Binary Artifacts PDPASG-2 Notification, Consent, Purpose Limitation, and Lawful Basis PDPASG-5 Protection, Accuracy, and Security of Personal Data PDPATH-5 Security Measures and Data Protection PDPATH-8 Data Breach Notification, Complaints, Compliance, Enforcement AUPRV-4 APP 10-11 Quality, Security of Personal Information AUPRV-7 Notifiable Data Breaches (NDB) Scheme, Incident Response PSPF24-2 Information Security, Cybersecurity Maturity, Essential Eight PSPF24-4 Physical Security RUSPD-1 Scope, Definitions, Principles under 152-FZ RUSPD-4 Special Categories, Biometric Data USMCADIGITAL-1 Cross-Border Data Flows and Localisation USMCADIGITAL-2 Personal Information Protection and Consumer Protection VIETNAMCYBER-2 Prohibited Acts (Access, Interception, Forgery, Content) VIETNAMCYBER-4 Incident Reporting and Cooperation ASD37-17 TLS encryption between email servers (Limited) AL-DPA-12 International Data Transfers DS-2 Ensure software supply chain security CA-10 Selects and Develops Control Activities CA-ITSG33-SC-01 Security Control Catalogue IATA-IOSA-Section8-SEC-SecurityManagement-AVSEC IATA IOSA Section 8 - SEC Security Management + Aviation Security Programme (AVSEC) + ICAO Annex 17 Alignment ICAO-ANX17-Chap2-ThreatAssessment-RiskManagement-Cyber-GASeP ICAO Annex 17 Chapter 2 - Threat Assessment + Risk Management + Cyber Threats to Critical Aviation Systems (Amendment 17/18) ISO28001-PS-01 Facility Security ISO20000-15 Access management for services ISO23894-A.5 Privacy and Data Protection in AI 29115-7.4 Level of Assurance 4 (LoA4) ITIL4-15 Access management for services STANAG-2 STANAG 4778 Metadata Binding Mechanism and Cryptographic Binding NIST-CSF-PR.PS-06 Secure software development practices are integrated, and their performance is monitored throughout the software development life cycle NRFCS-7 Detection, Logging, Incident Response, Breach Notification, and Fraud Detection NZISM-3 Personnel Security, Physical Security, and Cryptography OECDAI-5 Data Governance, Training Data Quality, Privacy, and Bias Mitigation OSFIB13-3 Cyber Security: Identification, Protection, Detection, Response, Recovery OWASPSAMM-2 Design: Threat Assessment, Security Requirements, Security Architecture OPENBANK-3 Mutual TLS, Token Binding, Request Signing (JWS), Key Management PASONE-4 Technical Security: CDE Configuration, BIM Tools, Encryption, Aggregation, Mobile Working RIDTPPA-2 Consumer Rights (Access, Correction, Deletion, Portability, Opt-Out) TEFCAREC-1 Common Agreement Conformance and Onboarding TURKEYKVKK-2 Information Notice and Data Subject Rights CPSC-CS.2 Authentication and Access Controls USSDWA-2 Cybersecurity Practices (Assessment, Access, Network, IR) VERMONTAICDA-3 Bias Testing, Discrimination Prevention, Transparency Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Query this from an agent The graph holds this control, the 275 it maps to, and the evidence behind each claim, over MCP and REST.