Frameworks / TEFCA - Trusted Exchange Framework and Common Agreement / TEFCAREC-1 TEFCA - Trusted Exchange Framework and Common Agreement
Conformance
TEFCA - Trusted Exchange Framework and Common Agreement TEFCAREC-1: Common Agreement Conformance and Onboarding Per TEFCA (Trusted Exchange Framework and Common Agreement) under ONC: conformance. Requirements include (a) Common Agreement adherence + (b) Qualified Health Information Network (QHIN) onboarding + (c) participant + sub-participant agreement + (d) cooperate with RCE (Recognized Coordinating Entity).
Maintained by Gerard Blokdyk · Verified against the published standard 31 May 2026 · Control text last updated 21 May 2026 What else in your programme already covers this This control maps to 497 controls across 182 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
ASD37-20 Multi-factor authentication (Essential) ASD37-23 Protect authentication credentials (Excellent) ASD37-29 Host-based IDS/IPS (Very Good) ASD37-31 Hunt to discover incidents (Very Good) ASD37-32 Network-based IDS/IPS (Limited) ASD37-33 Capture network traffic (Limited) AT-DSG-11 Sections 42-45 - Data subject rights (law enforcement) AT-DSG-13 Section 36 - Scope of law enforcement processing AT-DSG-14 Section 38 - Lawfulness of law enforcement processing AT-DSG-2 Section 2 - Scope and application AT-DSG-6 Sections 12-13 - Image processing (video surveillance/CCTV) AT-DSG-8 Section 22 - Functions and powers of the DPA 29100-1 Scope 29100-3 Terms and definitions 29100-4.1 Actors and roles 29100-6.10 Information security 29100-6.5 Use, retention and disclosure limitation 29100-6.9 Accountability NISTPF-1 Identify-P - Business Environment, Data Processing Inventory, Ecosystem, and Risk Assessment NISTPF-3 Control-P - Privacy Controls, Data Management, and Disassociated Processing NISTPF-4 Communicate-P - Privacy Notice, Transparency, and Individual Awareness NISTPF-5 Protect-P Access Control (PR.AC-P) NISTPF-7 Protect-P Maintenance and Protective Technology (PR.MA-P, PR.PT-P) NISTPF-8 Protect-P Information Protection Processes (PR.PO-P) NDPA-1 Applicability, Scope, and Carve-Outs NDPA-2 Consumer Rights - Access, Correct, Delete, Portability, Appeal NDPA-4 Sensitive Data Processing Consent and Childrens Protections NDPA-5 Privacy Notice, Data Minimisation, and Purpose Limitation NDPA-6 Reasonable Security Practices and Incident Response NDPA-7 Data Protection Assessments and Processor Contracts NG-NDPA-1 Scope, Applicability, and Establishment of Nigeria Data Protection Commission NG-NDPA-2 Lawful Basis, Consent, and Data Protection Principles NG-NDPA-4 Data Subject Rights and Automated Decision-Making NG-NDPA-5 Security of Processing, Breach Notification, and DPIA NG-NDPA-6 Data Protection Officer, DPCO, and Processor Agreements NG-NDPA-7 Cross-Border Data Transfers and International Cooperation APPI-A23 Security Control Measures APPI-A24 Supervision of Employees APPI-A33 Request for Disclosure of Retained Personal Data APPI-A41 Preparation and Handling of Pseudonymized Personal Information APPI-A43 Preparation of Anonymized Personal Information BSI-03 Multi-factor authentication requirements BSI-17 Continuous monitoring strategy BSI-18 Incident response planning and testing BSI-20 Incident reporting and notification BSI-21 Forensic analysis capabilities BB-DPA-14 Section 15 - Right to Data Portability BB-DPA-16 Section 22 - General Principle for Transfers BB-DPA-2 Section 2 - Interpretation BB-DPA-20 Sections 50-60 - Registration and Responsibilities BB-DPA-21 Sections 61-69 - Data Privacy Officer 27400-3 Terms and definitions 27400-5.4 Data and privacy risks 27400-6.1 Secure Device Design 27400-6.5 Security monitoring and incident response 27400-7.3 Data minimization and purpose limitation NISTSP82-1 OT Security Program Governance, Policy, Roles, and Safety-Security Integration NISTSP82-2 OT Risk Assessment and Threat/Vulnerability Identification NISTSP82-4 OT Access Control, Identity, Authentication, and Remote Access NISTSP82-6 OT Audit, Monitoring, Anomaly Detection, and OT-Specific SOC NISTSP82-7 OT Incident Response, Forensics, Recovery, and Continuity API1164-13 Business Continuity and Recovery API1164-17 Wireless and Field Communications API1164-18 Field Device Security API1164-19 Safety Instrumented Systems Interface AZ-DPA-12 Article 13 - Cross-border transfer AZ-DPA-14 Article 16 - Liability for violations AZ-DPA-15 Article 17 - Dispute resolution AZ-DPA-2 Article 2 - Basic Concepts FTC-Safeguards-9-Elements 9 Safeguard Elements - Access, Inventory, Encryption, Secure-Dev, MFA, Disposal, Change-Mgmt, Monitoring, Pen-Test (16 CFR 314.4(c)) FTC-Safeguards-IR-Plan-BoardReporting-FTC-Notification Written Incident Response Plan + Board Reporting + FTC Breach Notification (16 CFR 314.4(h), (i), (j)) FTC-Safeguards-Scope-Defs Scope, Definitions and Financial Institution Applicability (16 CFR 314.1, 314.2) FTC-Safeguards-ServiceProvider-Evaluation Service Provider Oversight + Program Evaluation + Personnel Training (16 CFR 314.4(d-g)) FedRAMP-Boundary Authorization Boundary, SSP, SAR, POA&M documentation FedRAMP-ConMon Continuous Monitoring (ConMon) and Significant Change Requests FedRAMP-IncidentReporting FedRAMP incident reporting to PMO and US-CERT FedRAMP-PII-Privacy FedRAMP PII processing + privacy controls (NIST 800-53 Rev 5 PT family + Privacy Act) FDBR-ControllerObligations-DPA-Notice Controller + Processor Obligations + Data Protection Assessments (Fla. Stat. 501.707, 501.708, 501.71, 501.711) FDBR-Enforcement-AG-CurePeriod Enforcement by Florida Department of Legal Affairs + Penalties + 45-Day Cure (Fla. Stat. 501.72, 501.721, 501.722) FDBR-Scope-Defs Scope, Applicability Thresholds and Definitions (Fla. Stat. 501.701, 501.702, 501.703, 501.704) FDBR-SensitiveData-Children-VoiceFacial Sensitive Data, Children's Privacy and Voice/Facial Recognition (Fla. Stat. 501.711, 501.1735) GhCSA-CII-Designation-Plan-Audit-Risk CII Designation, Registration, Cybersecurity Plan, Audit and Risk Assessment GhCSA-Cybercrime-Lawful-Access-Preservation Cybercrime Offences, Lawful Access and Electronic Evidence Preservation GhCSA-Implementation-Roadmap Implementation Roadmap - Organizational Roles, Tooling and Metrics GhCSA-Incident-Reporting-CERT-GH Cybersecurity Incident Reporting (24-Hour to CSA) and National CERT-GH Engagement 27557-1 Scope 27557-3 Terms and definitions 27557-4.3 Individual impact consideration 27557-6.2 Scope, context, and criteria for privacy 29115-11 Mapping other authentication schemes 29115-12.1 Exchanging authentication results 29115-12.2 Controls for mitigating threats 29115-3 Terms and definitions IsraelPPL-CrossBorder-Transfer-Sec36-EU-Adequacy-Israel-Adequacy-SCCs-Reciprocity-Foreign-Recipient Israel POPL Cross-Border Transfer + Section 36 + Privacy Protection (Transfer of Data to Databases Abroad) Regulations 5761-2001 + EU Adequacy Decision (2011) + SCCs + Foreign Recipient Obligations + Reciprocity IsraelPPL-DataSubjectRights-Access-Correction-Information-Delivery-Sec13-14-23A-23C-Subject-Notification Israel POPL Data Subject Rights - Section 13 Right of Access + Section 14 Right of Correction + Section 23A-C Prohibition on Information Delivery + Notice Obligation + Right to Object + Amendment 13 Enhancements IsraelPPL-Database-Registration-Definition-Document-Security-Level-Classification-Sec7-8-PPA-Registry Israel POPL Database Registration + Section 7 Database Definitions + Section 8 Registration Requirement + Database Definition Document + Security Level Classification + PPA Public Registry + Amendment 13 Threshold Changes IsraelPPL-Scope-5741-1981-Knesset-Amendment13-March2024-BasicLaw-Dignity-Sec1-Right-Privacy Israel Protection of Privacy Law 5741-1981 Scope + Knesset + Amendment No. 13 March 2024 + Basic Law Human Dignity and Liberty + Section 1 Right to Privacy + Constitutional Status + Chapter 1 Infringement of Privacy MTCS-Asset-IAM-Cryptography-Multi-Tier-Asset-Inventory-RBAC-MFA-PAM-FIPS-HSM-Quantum-Safe MTCS Asset Mgmt + IAM + Cryptography + Asset Inventory + RBAC + MFA + PAM + FIPS + HSM + Quantum-Safe MTCS-Governance-ISMS-Risk-HR-Lifecycle-Compliance-Cloud-Strategy-Roles-Responsibilities MTCS Governance + ISMS + Risk Management + HR Security + Cloud Service Lifecycle + Compliance + Roles MTCS-Incident-Business-Continuity-CSC-Data-Protection-72-Hour-Notification-BCP-DR-PDPA MTCS Incident + Business Continuity + CSC Data Protection + 72-Hour Notification + BCP + DR + PDPA MTCS-Logging-Monitoring-Compliance-Audit-SLA-Configuration-SIEM-SOAR-Cloud-Monitoring-CSPM MTCS Logging + Monitoring + Compliance + Audit + SLA + Configuration + SIEM + SOAR + CSPM MY-PDPA-Cross-Border-Transfer-Section-129-Whitelist-Abolition-2024-Adequacy-SCC-BCR-Processor-Direct-Marketing Malaysia PDPA Cross-Border + Section 129 + Whitelist Abolition 2024 + Adequacy + SCC + BCR + Processor + Marketing MY-PDPA-Data-Subject-Rights-Access-Correction-Portability-Withdraw-Consent-Prevent-Marketing-Sections-30-43 Malaysia PDPA Subject Rights + Access + Correction + Portability + Withdraw Consent + Prevent Marketing + Sections 30 to 43 MY-PDPA-Security-Principle-Retention-Data-Integrity-Breach-Notification-72-Hour-Section-12B-2024-Amendment Malaysia PDPA Security + Retention + Data Integrity + Breach Notification 72 Hour + Section 12B + 2024 Amendment MY-PDPA-Seven-Personal-Data-Protection-Principles-General-Notice-Choice-Disclosure-Security-Retention-Data-Integrity-Access Malaysia PDPA Seven Principles + General + Notice and Choice + Disclosure + Security + Retention + Data Integrity + Access OSFIB13-1 Governance, Risk Management, and Three Lines of Defense OSFIB13-3 Cyber Security: Identification, Protection, Detection, Response, Recovery OSFIB13-7 Incident Reporting to OSFI and Regulatory Coordination OSFIB13-8 Metrics, Monitoring, Continuous Improvement, Maturity DSOMM-1 Culture, Organization, Education, and Governance DSOMM-2 Implementation Practices, Secure Coding, and Threat Modelling DSOMM-4 Test and Verification - SAST, DAST, IAST, SCA, Penetration Testing DSOMM-5 Information Gathering, Logging, Monitoring, and Incident Response PICSGMP-1 Chapter 1: Pharmaceutical Quality System (PQS) and Quality Risk Management PICSGMP-2 Chapter 2: Personnel - Qualified Personnel, Key Responsibilities, Training PICSGMP-5 Chapter 5: Production Operations and Material Management PICSGMP-7 Chapter 7: Outsourced Activities and Supplier Management PERU-2 Consent, Privacy Notice, Sensitive Data PERU-5 Security of Personal Data and Processor Agreements PERU-7 DPO, Records, Retention, Marketing, Training PERU-8 Breach Notification, ANPD Cooperation, Sanctions, Compliance QATAR-3 Data Subject Rights QATAR-5 Security of Processing QATAR-7 DPO, Records, Retention, Marketing, Training QATAR-8 Breach Notification, Compliance, Enforcement EHDSREG-1 Mandatory Requirements for EHR Systems (Articles 14-29) EHDSREG-3 Secondary Use - Health Data for Research and Innovation EHDSREG-5 Cross-Border Health Data Flows EHDSREG-6 Phased Application and Enforcement TANZANIA-1 Scope, Registration, Lawful Basis TANZANIA-3 Data Subject Rights TANZANIA-4 Security and Cross-Border TANZANIA-5 DPO, Governance, Breach ACQS-3-1 Safe and Effective Care ACQS-8-2 Clinical Governance ACQS-8-4 Risk Management AL-DPA-1 Scope and Definitions AL-DPA-12 International Data Transfers AL-DPA-3 Lawful Basis for Processing APP-1 APP 1 - Open and transparent management of personal information APP-3 APP 3 - Collection of solicited personal information APP-5 APP 5 - Notification of the collection of personal information QMSR-820.10 Requirements for a Quality Management System - ISO 13485:2016 Sections 4-8 incorporation (§820.10) QMSR-ISO13485-Sec5 Management responsibility (ISO 13485:2016 Section 5 - incorporated via §820.10) QMSR-ISO13485-Sec7_DesignControls Product realization - Design and Development controls (ISO 13485:2016 Section 7.3) FISMA-3554-Agency-Responsibilities Federal Agency Responsibilities (44 USC 3554) - CIO + CISO + Program + Reporting FISMA-CIRCIA-ZTA-EO14028 CIRCIA, Zero Trust Architecture, EO 14028 + 14110 + OMB Memoranda FISMA-NIST-800-53-RMF-800-171-FIPS Operationalisation via NIST 800-53 + 800-37 RMF + 800-171 + FIPS 199 + FIPS 200 UAE-PDPL-Art.10 Data Protection Officer (DPO) (UAE PDPL Article 10) UAE-PDPL-Art.18_19_20_21 Security measures, controller/processor relationship, DPIA (UAE PDPL Articles 18-21) UAE-PDPL-Art.4_5 Lawful basis and principles for processing personal data (UAE PDPL Articles 4-5) GLBA-Implementation-Roadmap-Examination GLBA Implementation Roadmap, Examination Readiness, Roles and Tooling GLBA-Sec6801-PolicyDuty-SafeguardingStandard GLBA Section 6801 - Privacy Obligation Policy and Safeguarding Standard GLBA-Status-FTC-CFPB-SEC-NAIC-Enforcement GLBA Status, Enforcement Activity, FTC + CFPB + SEC + NAIC Recent Actions HITECH-Coord-HIPAA-Privacy-Security-Cures-ONC HITECH Coordination with HIPAA Privacy Rule + HIPAA Security Rule (Verified Separately) + 21st Century Cures Act + ONC HITECH-Enforcement-CMP-Tiers-StateAGs-OCR HITECH 4-Tier Civil Monetary Penalty Structure, State AGs Enforcement and HHS OCR Settlements HITECH-SubtitleD-Breach-Notification-BA-Direct-Liability HITECH Subtitle D - Breach Notification Rule (45 CFR Part 164 Subpart D), Business Associate Direct Liability, Subcontractors HKMA-CRAF-Domain1-2-Governance-Identification HKMA C-RAF Domain 1 (Governance) + Domain 2 (Identification) - Cyber Strategy, Risk Management, Asset Management, Threat Assessment HKMA-CRAF-Domain3-4-Protection-Detection HKMA C-RAF Domain 3 (Protection) + Domain 4 (Detection) - Access, Data, Infrastructure, Application, Monitoring, Testing, Threat Intel HKMA-CRAF-Domain5-6-Response-Recovery-SitAwareness HKMA C-RAF Domain 5 (Response and Recovery) + Domain 6 (Situational Awareness) - Incident Response, Recovery, Threat Landscape, Information Sharing IACS-UR-E26-Respond-Recover-IncidentResponse-Recovery-Backup-Lessons IACS UR E26 Respond + Recover Goals - Incident Response + Communication + Recovery + Backup + Lessons Learned IACS-UR-E27-Equipment-UserAuth-Authentication-Authorization IACS UR E27 - Equipment User Authentication + Authorization + Session Management + Privileged Access IACS-UR-E27-Logging-Forensics-EventCapture IACS UR E27 - Equipment Logging + Forensic Readiness + Event Capture + Tamper Detection 60601-1.12 Accuracy of controls and instruments 60601-1.3 Terminology and definitions 60601-1.4.1 General requirements 27004-3 Terms and definitions 27004-A.2 Patching and Vulnerability Measures 27004-B.1 Example measurement definitions 29134-1 Scope 29134-3 Terms and definitions 29134-9.1 PIA report structure 30111-3 Terms and definitions 30111-5.1 Organizational policy 30111-5.2 Vulnerability handling team MDS2-Audit-Logging-AUDT-Integrity-IGAU-Cybersecurity-Risk-CYBR-Monitoring MDS2 Audit Controls + AUDT + Integrity + IGAU + Cybersecurity Risk + CYBR + Continuous Monitoring MDS2-PHI-Data-Handling-DATA-Storage-STCF-Transmission-TXCF-TXIG-Encryption-FIPS MDS2 PHI Handling + DATA + STCF Storage + TXCF Transmission + TXIG Integrity + Encryption + FIPS MDS2-Person-Node-Authentication-Authorization-Auto-Logoff-AUTH-PAUT-NAUT MDS2 Authentication + Authorization + Auto Logoff + PAUT + NAUT + AUTH + Identity Management MU-DPA-Data-Subject-Rights-Sections-26-33-Access-Rectification-Erasure-Restriction-Portability-Objection Mauritius DPA Subject Rights + Sections 26 to 33 + Access + Rectification + Erasure + Restriction + Portability + Objection MU-DPA-Governance-DPO-Designation-Section-25-DPO-ROPA-DPIA-Codes-Section-38-Commissioner-Registration Mauritius DPA Governance + DPO + ROPA + DPIA + Codes Section 38 + Commissioner Registration MU-DPA-Seven-Principles-Section-21-Lawfulness-Purpose-Minimisation-Accuracy-Storage-Integrity-Accountability Mauritius DPA Seven Principles + Section 21 + Lawfulness + Purpose + Minimisation + Accuracy + Storage + Integrity + Accountability MN-CDPA-Chief-Privacy-Officer-Section-325O-06-MN-UNIQUE-Designation-Privacy-Programme-Training Minnesota CDPA Chief Privacy Officer + Section 325O.06 + MINNESOTA-UNIQUE Designation + Privacy Programme + Training MN-CDPA-Enforcement-AG-Ellison-Section-325O-10-USD-7500-Per-Violation-Data-Broker-Registration-325O-13-Sunset-25-Jan-2026 Minnesota CDPA Enforcement + AG Ellison + Section 325O.10 + USD 7,500 Per Violation + Data Broker Registration + Sunset 25 January 2026 MN-CDPA-Processor-Contract-Security-Section-325O-08-Pseudonymisation-Section-325O-09-De-Identification Minnesota CDPA Processor + Section 325O.08 + Security + Pseudonymisation + Section 325O.09 + De-Identification MT-CDPA-Privacy-Notice-MCA-30-14-2806-Categories-Purposes-Rights-Email-Online-Mechanism-Appeal Montana CDPA Privacy Notice + MCA 30-14-2806 + Categories + Purposes + Rights + Online Mechanism + Appeal MT-CDPA-Scope-SB-384-Gianforte-19-May-2023-Effective-1-October-2024-MCA-30-14-2801-AG-Knudsen-50K-Threshold Montana CDPA Scope + SB 384 + Gianforte 19 May 2023 + Effective 1 October 2024 + MCA 30-14-2801 + AG Knudsen + 50K Threshold MT-CDPA-Sensitive-Data-MCA-30-14-2802-Opt-In-Children-13-Parental-Consent-Minors-13-16-Opt-In Montana CDPA Sensitive Data + MCA 30-14-2802 + Affirmative Opt-In + Children Under 13 Parental + Minors 13-16 Opt-In NISTSP122-4 PII Minimisation, Purpose Limitation, and Pseudonymisation NISTSP122-5 PII Security Controls - Encryption, Access Control, Storage, Audit NISTSP122-6 PII Breach Response and Incident Handling NHPA-5 Privacy Notice, Data Minimisation, and Purpose Limitation NHPA-6 Reasonable Data Security and Breach Response NHPA-7 Data Protection Assessments and Processor Contracts NJDPA-2 Consumer Rights - Access, Correct, Delete, Portability, Appeal NJDPA-6 Reasonable Data Security and Incident Response NJDPA-8 AG Platkin Enforcement, 18-Month Cure Sunset, and Division of Consumer Affairs NGOB-1 Open Banking Registry Participation, Tiered Categorisation, and KYP NGOB-2 Customer Consent Management and Lifecycle NGOB-5 Fraud Monitoring, Incident Notification, and Reporting to CBN ORANWG11-2 O-RAN Interface Security: E2, A1, O1, O2, Open Fronthaul ORANWG11-3 Cryptography, TLS, SSH, IPsec, and PKI Lifecycle Management ORANWG11-6 Security Test Specifications, Certification, and Conformance OMANCS-3 Identity and Access Management, Authentication, Privileged Access OMANCS-4 Data Protection, Cryptography, and Privacy Alignment OMANCS-6 Security Monitoring, Detection, Incident Response, and OmanCERT Notification OPENBANK-2 Strong Customer Authentication (SCA), Consent Lifecycle, and Customer UX OPENBANK-7 Logging, Monitoring, Regulatory Reporting, SLA, Availability OPENBANK-8 Incident Detection, Response, Customer Notification, Post-Incident Review, BCM OREGONCPA-3 Consent, Sensitive Data, Children and Teen Protections OREGONCPA-5 Data Protection Assessments, Privacy by Design, Security Practices OREGONCPA-7 Processor Contracts, Cross-Border Transfers, DPAs PDPASG-2 Notification, Consent, Purpose Limitation, and Lawful Basis PDPASG-5 Protection, Accuracy, and Security of Personal Data PDPASG-8 Data Breach Notification, Incident Response, and Enforcement POPIASA-3 Data Subject Rights (Access, Correction, Objection), Automated Decisions POPIASA-4 Special Personal Information, Children, Information Quality, Documentation POPIASA-5 Security Safeguards, Encryption, Access Control, Operator Obligations PSDTWO-1 Strong Customer Authentication (SCA) Core Requirements PSDTWO-3 Common and Secure Communication, API Access for AISPs and PISPs PSDTWO-4 Fraud Reporting and Incident Management PAKPDPB-5 Security of Processing and Personal Data Breach Notification PAKPDPB-7 NCPDP, Registration, Records, Processor Contracts, DPO PAKPDPB-8 Enforcement, Penalties, Complaints, Retention, Training NZPRV-2 IPP 5 Storage and Security of Personal Information NZPRV-6 IPP 13 Unique Identifiers, Privacy Impact Assessment, Privacy by Design NZPRV-7 Notifiable Privacy Breach Scheme PIPA-CPO-DPO-Privacy-Officer-PIA-Personal-Information-Impact-Assessment-Articles-31-33 Korea PIPA CPO + DPO + Privacy Officer + PIA + Personal Information Impact Assessment + Articles 31-33 PIPA-Data-Subject-Rights-Access-Correction-Erasure-Portability-Automated-Decisions-Articles-35-37-2 Korea PIPA Data Subject Rights + Access + Correction + Erasure + Portability + Article 35-37 PIPA-Sensitive-Information-Unique-ID-Resident-Registration-Numbers-CCTV-Articles-23-24-25 Korea PIPA Sensitive Information + Unique ID + RRN + CCTV + Articles 23-25 58.1 Scope 58.3 Definitions 4.4.1 Resources, Roles, Responsibility, and Authority 4.4.7 Emergency and Incident Response AWWA-1.1 Security Policy and Governance AWWA-2.2 Authentication Mechanisms GAMP5-Lifecycle-VModel-URS-FS-DS-IQOQPQ V-Model Lifecycle - URS + FS + DS + IQ + OQ + PQ + Traceability GAMP5-Risk-CriticalThinking Risk-Based Approach, Critical Thinking and 5 Key Concepts GLI33-EventWagering-System-Architecture GLI-33 Event Wagering System Architecture, Wager Engine, Odds Engine and Risk Management GLI33-PAM-KYC-AML-Payments GLI-33 Player Account Management, KYC, AML, Payment Processing and Account Lifecycle HKMA-SPM-CG-IC-AC-Governance-Control-Audit HKMA SPM Corporate Governance (CG-1/2/3/5/6), Internal Control (IC-1/5), Auditing (AC-G) HKMA-SPM-TM-Technology-TM-G-1-CRAF-Coord HKMA SPM Technology Management Modules (TM-G-1 to TM-G-4, TM-E-1) + Coordination with C-RAF IATF16949-Clause10-Improvement-Nonconformity-CorrectiveAction-Problem-ErrorProof IATF 16949 Clause 10 - Improvement + Nonconformity + Corrective Action + Problem Solving + Error Proofing + Continual Improvement IATF16949-Clause9-Performance-Monitoring-InternalAudit-ManagementReview IATF 16949 Clause 9 - Performance Evaluation + Monitoring + Internal Audit + Manufacturing Process Audit + Management Review IEEE1686-IR-Recovery-Reporting-Exercises-Drills-RECOV IEEE 1686 - Incident Response + Recovery from Failed Update + Reporting to Authorities + Coordination with Sector-Specific Agencies + Exercises and Drills IEEE1686-Section5.2-5.3-AuditLog-Retention-Export-Monitoring IEEE 1686 Section 5.2 + 5.3 - Audit Trail Records + Retention + Export + Supervisory Monitoring and Control + Network Security Monitoring IMO-MSC-FAL-Detect-AnomalyDetection-OT-IT-Monitoring-Reporting-BridgeAlarms IMO MSC-FAL Detect Function - Anomaly Detection + OT and IT System Monitoring + Bridge Alarms + Log Aggregation + Incident Reporting Channels + Crew Observation IMO-MSC-FAL-Identify-AssetInventory-ThreatsVulnerabilities-CyberRiskAssessment-RolesResponsibilities IMO MSC-FAL Identify Function - OT/IT Asset Inventory + Threats + Vulnerabilities + Cyber Risk Assessment + Roles and Responsibilities + Crew + CSO + DPA 23837-1.1 Scope 23837-1.7.3 Authentication and classical post-processing 27011-1 Scope 27011-3 Terms and definitions 27014-1 Scope 27014-3 Terms and definitions 29147-3 Terms and definitions 29147-9.2 Contact mechanisms and scope BIPA-SEC5-1 Biometric Identifier Definition BIPA-SEC5-2 Biometric Information Definition INCDPA-Controller-PrivacyNotice-PurposeLimitation-DataMinimisation-Transparency-LawfulBasis Indiana CDPA Controller Obligations - Privacy Notice + Purpose Limitation + Data Minimisation + Transparency + Lawful Basis + Reasonable + Adequate + Relevant + Limited to What is Necessary INCDPA-Security-ReasonablePractices-Breach-Notification-Records-Encryption-Pseudonymisation Indiana CDPA Security + Reasonable Practices + Breach Notification + Indiana Breach Notification Law (IC 24-4.9) + Records + Encryption + Pseudonymisation + De-Identification JP-FSA-CYB-Incident-Response-Playbooks-Containment-Eradication-Recovery-Post-Mortem-Tabletop-CSIRT Japan FSA Cybersecurity Incident Response + Playbooks + Containment + Eradication + Recovery + Post-Mortem + Tabletop Exercises + CSIRT + FSA Notification + Customer Communication + Forensics + Lessons Learned JP-FSA-CYB-Security-Monitoring-SOC-Operations-SIEM-EDR-MDR-XDR-24x7-Detection-Alert-Triage Japan FSA Cybersecurity Security Monitoring + SOC 24x7 Operations + SIEM + EDR + MDR + XDR + Detection + Alert Triage + Threat Hunting + Incident Response Integration + Threat Intelligence Integration + UEBA DOM172-Lawful-Basis-Consent-Notice-Information-Duty-Articles-4-12-Quality-Principle-Purpose-Limitation-Minimisation Dominican Republic Law 172-13 Lawful Basis + Consent + Notice + Information Duty + Articles 4-12 DOM172-Security-Measures-Article-25-Encryption-Pseudonymization-Access-Control-Incident-Handling-Breach-Notification-Article-22 Dominican Republic Law 172-13 Security Measures + Article 25 + Encryption + Breach Notification MX-LFPDPPP-Governance-Officer-Reglamento-47-50-Security-Manual-57-Risk-Assessment-61-Self-Regulation-Parameters-2014 Mexico LFPDPPP Governance + Officer + Reglamento 47 + Security Manual 50 + Risk Assessment 57 + Self-Regulation Parameters 2014 MX-LFPDPPP-Sensitive-Article-3-VI-Genetic-Health-Sexual-Religious-Article-9-Minors-18-Parental-Consent Mexico LFPDPPP Sensitive Data + Article 3 Section VI + Genetic + Health + Sexual + Religious + Article 9 Minors + Parental Consent MAS-TRM-Cyber-Resilience-Chapter-11-Threat-Intelligence-Penetration-Testing-Incident-Response-1-Hour-Notification MAS TRM Cyber Resilience + Chapter 11 + Threat Intelligence + Penetration Testing + Incident Response + 1-Hour Notification MAS-TRM-Governance-Chapters-2-3-Board-Senior-Management-Risk-Framework-Information-Asset-Management MAS TRM Governance + Chapters 2-3 + Board + Senior Management + Risk Framework + Information Asset Management NAIC-1 NAIC Model Law Adoption, Scope, and Licensee Definitions NAIC-6 Cybersecurity Event Investigation and Notification - Sections 6 and 7 STANAG-1 STANAG 4774 Confidentiality Label Schema and XML Structure STANAG-2 STANAG 4778 Metadata Binding Mechanism and Cryptographic Binding NERCCIP-5 System Security Management + Configuration Change Management and Vulnerability Assessments (CIP-007 + CIP-010) NERCCIP-6 Incident Reporting and Response Planning + Recovery Plans (CIP-008 + CIP-009) NISTSP115-1 Scope, Methodology, and Assessment Planning NISTSP115-8 Operational Considerations - Tools, Reporting Templates, ISMS Integration, Annex Material NISTSP123-3 Authentication, Access Control, and Account Management NISTSP123-8 Governance, Policies, and ISMS Integration NISTSP137-1 ISCM Strategy, Governance, and Volatility Assessment NISTSP137-6 Malware, Identity Access, and Network Boundary Monitoring NISTSP144-1 Cloud Governance, Risk Assessment, and Provider Trust Evaluation NISTSP144-8 Monitoring, Incident Response, Exit Strategy, and Compliance NISTSP145-7 Cloud Procurement Standards Aligned to NIST SP 800-145 Definition NISTSP145-8 Governance, Reporting, and Stakeholder Education on Cloud Definition NISTSP146-1 Cloud Adoption Strategy, Workload Suitability, and Decision Framework NISTSP146-6 Cloud Security and Privacy Recommendations NISTSP61-2 Computer Security Incident Response Team (CSIRT) Structure and Staffing NISTSP61-5 Containment, Eradication, and Recovery NISTSP63R4-1 Digital Identity Risk Management and IAL/AAL/FAL Assurance Level Selection NISTSP63R4-3 Authentication: Authenticator Types, MFA, Phishing-Resistance, and Syncable Authenticators NISTSP92-1 Log Management Programme, Policy, Roles, and Operational Runbooks NISTSP92-4 Log Management: Time Synchronisation, Parsing, Storage, Integrity, Access Control NISTSP34-1 Contingency Planning Policy, Programme, and Plan Coordination NISTSP34-2 Business Impact Analysis (BIA): Critical Resources, Recovery Priorities NRC7354-2 Critical Digital Asset (CDA) Identification, Scope, and Boundary NRC7354-4 Security Controls Implementation per NRC RG 5.71 Appendix B/C NGCB-6 Incident Response, 72-Hour NGCB Notification, and Independent Investigation NGCB-7 Patron and Employee Data Protection + Data Inventory + Vendor Management NGNDPR-2 Governing Principles, Lawful Basis, and Consent under NDPR Section 2.1-2.3 NGNDPR-5 Security of Personal Data, Breach Notification, and DPIA under NDPR Section 2.6-Security OWASPSAMM-1 Governance: Strategy, Policy, Compliance, Education, Champions OWASPSAMM-2 Design: Threat Assessment, Security Requirements, Security Architecture OWASPLLM-1 Prompt Injection and System Prompt Leakage (LLM01 + LLM07) OWASPLLM-3 Sensitive Information Disclosure and Privacy (LLM02) OSSFSC-1 Branch Protection, Code Review, and Repository Governance OSSFSC-3 Build, CI/CD Security, Workflow Permissions, Dangerous Patterns PASONE-4 Technical Security: CDE Configuration, BIM Tools, Encryption, Aggregation, Mobile Working PASONE-6 Incident Management, Audit, Handover, Operational Phase, Decommissioning PDPATH-5 Security Measures and Data Protection PDPATH-8 Data Breach Notification, Complaints, Compliance, Enforcement PTESPHASE-1 Pre-Engagement Interactions and Scoping PTESPHASE-2 Intelligence Gathering (OSINT) NORWAY-5 Security of Processing, Encryption, Pseudonymization, Access Control NORWAY-8 Breach Notification, Complaints, Compliance, Enforcement SHAREASSESS-1 Information Governance and Risk SHAREASSESS-2 Access Control, Identity, Authentication C1 Organizational Boundary C3 Scope 1 and 2 Coverage TAIWAN-2 Consent, Notice, Sensitive Data TAIWAN-3 Data Subject Rights USMCADIGITAL-1 Cross-Border Data Flows and Localisation USMCADIGITAL-2 Personal Information Protection and Consumer Protection VIETNAMCYBER-2 Prohibited Acts (Access, Interception, Forgery, Content) VIETNAMCYBER-4 Incident Reporting and Cooperation AMLCTF-35 Identity Verification Standard LOPDP-EC-Security-Processor-Breach-Notification-Articles-37-45-Encryption-72-Hour-SPDP-Notification-CSIRT Ecuador LOPDP Security + Processor + Breach Notification + Articles 37-45 + 72-Hour R.16-VATR.Unhosted Unhosted (self-hosted / non-custodial) wallet transfers - 2024 Targeted Update Part11.300 Controls for identification codes and passwords (21 CFR §11.300) FIRST-CSIRTF-SA2-ISIM Service Area 2 - Information Security Incident Management (Intake, Analysis, Containment, Recovery, Coordination, Crisis) Sapin2-Pillar1-Code-of-Conduct Pillar 1 - Anti-Corruption Code of Conduct CBPR-9-APEC-Privacy-Principles Global CBPR Forum: 9 APEC Privacy Principles (Notice + Collection + Uses + Choice + Integrity + Security + Access + Accountability + Preventing Harm) IATA-IOSA-Section1-ORG-Organization-ManagementSystem-SMS IATA IOSA Section 1 - ORG Organization and Management System + Safety Management System (SMS) + Safety Policy + Hazard ID + Quality 62351-2 Glossary of terms IEEE7000-Values-Elicitation-Prioritisation-IEEE7000Family-Bias-Privacy-Transparency IEEE 7000 Clauses 6 + 6.1 - Ethical Values Elicitation + Prioritisation + IEEE 7000 Family Integration (Bias + Privacy + Transparency + Wellbeing) 27006-9.4 Surveillance and recertification 27007-5.2 Audit Programme Objectives 27010-16.1 Continuity of Sharing 27050-1.4 Terms and definitions ITAR-Scope-AECA-22USC2778-22CFR120-130-DDTC-USML-21Categories-DefenseArticle-Service-TechnicalData ITAR Scope + Arms Export Control Act (22 USC 2778) + 22 CFR Parts 120-130 + Directorate of Defense Trade Controls (DDTC) + United States Munitions List (USML) 21 Categories + Defense Article/Service/Technical Data Definitions ITU-Scope-Constitution-Convention-Radio-Regulations-WRC-Quadrennial-Treaty-Art1-Definitions ITU Constitution + Convention + Radio Regulations Scope + Article 1 Definitions + Article 2 Nomenclature + WRC World Radiocommunication Conference Quadrennial Treaty Process + Member States + Sector Members JP-AIG-Data-Governance-Training-Data-Quality-Provenance-Lineage-Copyright-APPI-Personal-Information-Protection Japan AI Guidelines Data Governance + Training Data Quality + Provenance + Lineage + Copyright Act 2018 Article 30-4 Text Data Mining Exception + APPI 2022 Amendment + Personal Information Protection + Privacy Principle LGPD-BR-Security-Article-46-48-Breach-Notification-ANPD-Reasonable-Time-Incident-Response-CSIRT Brazil LGPD Security + Article 46-48 + Breach Notification + ANPD + Incident Response LAOS-CC-LaoCERT-Incident-Response-National-Cybersecurity-Coordination-Article-22 Laos Cybercrime LaoCERT + Incident Response + National Cybersecurity Coordination + Article 22 AQAP2110-3 Design and Development Control - NATO plus ISO 13485 Cross-Walk NISTAI600-7 Confabulation, Bias, Information Integrity, Privacy, IP (Risks 2, 4, 5, 6, 7, 8, 10, 11) PQC-4 FIPS 205 SLH-DSA Implementation - Stateless Hash-Based Digital Signature NISTSP66-6 Technical Safeguards: Access Control, Audit Controls, Integrity, Person Authentication NISTSP88-1 Media Sanitization Policy, Roles, and Decision Framework NRFCS-7 Detection, Logging, Incident Response, Breach Notification, and Fraud Detection NZISM-5 Network Security, System Hardening, and Application Security AUNDB-A3 Eligible Data Breach Determination and Serious Harm Threshold OCCHS-1 Scope, Applicability, and Definitions of Heightened Standards OECDAI-5 Data Governance, Training Data Quality, Privacy, and Bias Mitigation 2.2.2 2.2.2 Vendor default accounts managed PNGCYBER-4 Incident Response, Investigation, Evidence Preservation, Data Retention PHILCC-1 Computer Crime Offences (Illegal Access, Interference, Misuse of Devices) PSPF24-1 Security Culture, Governance, Risk Management RIDTPPA-2 Consumer Rights (Access, Correction, Deletion, Portability, Opt-Out) SASB-4 Social Capital (SC) SUPCHAIN-1 Build Integrity - Source, Build, Provenance CISABD-1 Take Ownership of Customer Security Outcomes SIGSTORE-2 Transparency Log (Rekor) and Verification SGCYBER-1 Critical Information Infrastructure (CII) Designation and Registration STUDPRV-2 Data Subject Rights for Students and Parents UAEVARA-1 Activity Licensing (Advisory, Exchange, Custody, Broker-Dealer, etc.) 15 U.S.C. § 78dd-2(h) Definition of Domestic Concern VERMONTAICDA-3 Bias Testing, Discrimination Prevention, Transparency Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Query this from an agent The graph holds this control, the 497 it maps to, and the evidence behind each claim, over MCP and REST.