Frameworks / Privacy Act 2020 / NZPRV-2 Privacy Act 2020 NZPRV-2: IPP 5 Storage and Security of Personal Information Per IPP 5 of Privacy Act 2020: storage and security. Requirements include (a) IPP 5 - Storage and Security of Personal Information - agency holding personal information must ensure it is protected by reasonable security safeguards against loss + unauthorised access + use + modification + disclosure + (b) if agency provides personal information to another person for storing + processing - ensure preventive measures + (c) implement encryption + access control + activity logging where appropriate + (d) conduct regular security testing + assessment + (e) integrate with broader information security baseline + (f) maintain documented security measures aligned to OPC guidance.
What else in your programme already covers this This control maps to 297 controls across 97 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
APPI-A23 Security Control Measures APPI-A24 Supervision of Employees APPI-A26 Report of Leakage to the Commission and Notification to the Person APPI-A31 Provision of Personally Referable Information APPI-A33 Request for Disclosure of Retained Personal Data APPI-A34 Request for Correction, Addition or Deletion GDPR-Art.10 Processing of personal data relating to criminal convictions GDPR-Art.11 Processing which does not require identification GDPR-Art.15 Right of access by the data subject GDPR-Art.19 Notification obligation regarding rectification, erasure or restriction GDPR-Art.9 Processing of special categories of personal data BSI-03 Multi-factor authentication requirements BSI-04 Remote access controls BSI-05 Wireless access restrictions BSI-08 Cryptographic protection of data NISTPF-3 Control-P - Privacy Controls, Data Management, and Disassociated Processing NISTPF-4 Communicate-P - Privacy Notice, Transparency, and Individual Awareness NISTPF-5 Protect-P Access Control (PR.AC-P) NISTPF-7 Protect-P Maintenance and Protective Technology (PR.MA-P, PR.PT-P) OREGONCPA-3 Consent, Sensitive Data, Children and Teen Protections OREGONCPA-4 Universal Opt-Out, Targeted Advertising, Profiling OREGONCPA-5 Data Protection Assessments, Privacy by Design, Security Practices OREGONCPA-7 Processor Contracts, Cross-Border Transfers, DPAs PERU-2 Consent, Privacy Notice, Sensitive Data PERU-4 Children's Data, Privacy Impact, Sensitive Categories PERU-5 Security of Personal Data and Processor Agreements PERU-7 DPO, Records, Retention, Marketing, Training APP-1 APP 1 - Open and transparent management of personal information APP-3 APP 3 - Collection of solicited personal information APP-5 APP 5 - Notification of the collection of personal information AT-DSG-11 Sections 42-45 - Data subject rights (law enforcement) AT-DSG-13 Section 36 - Scope of law enforcement processing AT-DSG-14 Section 38 - Lawfulness of law enforcement processing BB-DPA-14 Section 15 - Right to Data Portability BB-DPA-16 Section 22 - General Principle for Transfers BB-DPA-21 Sections 61-69 - Data Privacy Officer ORANWG11-2 O-RAN Interface Security: E2, A1, O1, O2, Open Fronthaul ORANWG11-3 Cryptography, TLS, SSH, IPsec, and PKI Lifecycle Management ORANWG11-8 Supply Chain, Secure Development Lifecycle, Privacy, Multi-Vendor Trust POPIASA-3 Data Subject Rights (Access, Correction, Objection), Automated Decisions POPIASA-4 Special Personal Information, Children, Information Quality, Documentation POPIASA-5 Security Safeguards, Encryption, Access Control, Operator Obligations CJIS-8 Media Protection CJIS-9 System and Communications Protection FTC-Safeguards-9-Elements 9 Safeguard Elements - Access, Inventory, Encryption, Secure-Dev, MFA, Disposal, Change-Mgmt, Monitoring, Pen-Test (16 CFR 314.4(c)) FTC-Safeguards-Scope-Defs Scope, Definitions and Financial Institution Applicability (16 CFR 314.1, 314.2) FDBR-ControllerObligations-DPA-Notice Controller + Processor Obligations + Data Protection Assessments (Fla. Stat. 501.707, 501.708, 501.71, 501.711) FDBR-Scope-Defs Scope, Applicability Thresholds and Definitions (Fla. Stat. 501.701, 501.702, 501.703, 501.704) 62351-8 Role-based access control (RBAC) 62351-9 Cyber security key management 6.6 Confidentiality or non-disclosure agreements 6.7 Conducting Audit Follow-up 6.6 Confidentiality or non-disclosure agreements 6.7 Conducting Audit Follow-up 9.1 Risk communication and consultation ISO20000-15 Access management for services 6.6 Confidentiality or non-disclosure agreements 6.7 Conducting Audit Follow-up OMANCS-3 Identity and Access Management, Authentication, Privileged Access OMANCS-4 Data Protection, Cryptography, and Privacy Alignment OSSFSC-3 Build, CI/CD Security, Workflow Permissions, Dangerous Patterns OSSFSC-6 Signed Releases, Provenance, Trusted Publishing, Binary Artifacts PDPASG-2 Notification, Consent, Purpose Limitation, and Lawful Basis PDPASG-5 Protection, Accuracy, and Security of Personal Data PDPATH-5 Security Measures and Data Protection PDPATH-8 Data Breach Notification, Complaints, Compliance, Enforcement PSPF24-2 Information Security, Cybersecurity Maturity, Essential Eight PSPF24-4 Physical Security RUSPD-1 Scope, Definitions, Principles under 152-FZ RUSPD-4 Special Categories, Biometric Data 9.1 Risk communication and consultation ASD37-17 TLS encryption between email servers (Limited) DS-2 Ensure software supply chain security CA-10 Selects and Develops Control Activities 9.1 Risk communication and consultation STANAG-2 STANAG 4778 Metadata Binding Mechanism and Cryptographic Binding NIST-CSF-PR.PS-06 Secure software development practices are integrated, and their performance is monitored throughout the software development life cycle OECDAI-5 Data Governance, Training Data Quality, Privacy, and Bias Mitigation OSFIB13-3 Cyber Security: Identification, Protection, Detection, Response, Recovery OWASPSAMM-2 Design: Threat Assessment, Security Requirements, Security Architecture OPENBANK-3 Mutual TLS, Token Binding, Request Signing (JWS), Key Management PASONE-4 Technical Security: CDE Configuration, BIM Tools, Encryption, Aggregation, Mobile Working RIDTPPA-2 Consumer Rights (Access, Correction, Deletion, Portability, Opt-Out) TEFCAREC-1 Common Agreement Conformance and Onboarding USCOPPA-3 Data Minimisation, Retention, Erasure (Eraser Button) USSDWA-2 Cybersecurity Practices (Assessment, Access, Network, IR) Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Query this from an agent The graph holds this control, the 297 it maps to, and the evidence behind each claim, over MCP and REST.