UK Defence Standard 05-138 - Cyber Security for Defence Suppliers
DEFSTAN 05-138 Section D: Minimising the Impact of Incidents

UK Defence Standard 05-138 - Cyber Security for Defence Suppliers D.1: Incident Response Planning

The supplier must have capabilities to minimise the adverse impact of a cyber security incident on operations and data protection.

What else in your programme already covers this

This control maps to 460 controls across 169 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • CH-FADP-16 Record keeping and accountability
  • CH-FADP-17 Workplace and employment data
  • CH-FADP-19 Transparency and proactive information
  • CH-FADP-21 Data protection impact assessments
  • FADP-15 Data Breach Notification
  • FADP-16 FDPIC Independence and Functions
  • FADP-7 Data Protection Impact Assessment (Articles 9-10)
  • FADP-9 Data Protection Advisor (Articles 14-15)
  • NDPA-1 Applicability, Scope, and Carve-Outs
  • NDPA-2 Consumer Rights - Access, Correct, Delete, Portability, Appeal
  • NDPA-4 Sensitive Data Processing Consent and Childrens Protections
  • NDPA-5 Privacy Notice, Data Minimisation, and Purpose Limitation
  • NDPA-6 Reasonable Security Practices and Incident Response
  • NDPA-7 Data Protection Assessments and Processor Contracts
  • NDPA-8 Nebraska Attorney General Enforcement, Permanent 30-Day Cure, and Penalties
  • NG-NDPA-1 Scope, Applicability, and Establishment of Nigeria Data Protection Commission
  • NG-NDPA-2 Lawful Basis, Consent, and Data Protection Principles
  • NG-NDPA-4 Data Subject Rights and Automated Decision-Making
  • NG-NDPA-5 Security of Processing, Breach Notification, and DPIA
  • NG-NDPA-6 Data Protection Officer, DPCO, and Processor Agreements
  • NG-NDPA-7 Cross-Border Data Transfers and International Cooperation
  • NG-NDPA-8 Enforcement, Penalties, Data Controllers of Major Importance (DCMI), and Compliance

Bahrain PDPL · 4 controls

ISO 27017 · 4 controls

ISO 27018 · 4 controls

MTCS (Singapore) · 4 controls

NIST SP 800-190 · 4 controls

  • NJDPA-2 Consumer Rights - Access, Correct, Delete, Portability, Appeal
  • NJDPA-6 Reasonable Data Security and Incident Response
  • NJDPA-7 Data Protection Assessments and Processor Contracts
  • NJDPA-8 AG Platkin Enforcement, 18-Month Cure Sunset, and Division of Consumer Affairs

Saudi Arabia PDPL · 4 controls

API 1164 · 3 controls

  • ASD37-27 Outbound data loss prevention (Very Good)
  • ASD37-31 Hunt to discover incidents (Very Good)
  • ASD37-33 Capture network traffic (Limited)
  • AT-DSG-10 Section 29 - Liability and right to compensation / civil jurisdiction
  • AT-DSG-12 Section 62 - Administrative penalties
  • AT-DSG-7 Section 18 - Establishment of the Data Protection Authority

BSI IT-Grundschutz · 3 controls

  • BSI-18 Incident response planning and testing
  • BSI-20 Incident reporting and notification
  • BSI-21 Forensic analysis capabilities
  • BB-DPA-1 Section 1 - Short Title
  • BB-DPA-20 Sections 50-60 - Registration and Responsibilities
  • BB-DPA-4 Section 4 - Principles Relating to Processing

FDA 21 CFR Part 11 · 3 controls

  • Part11.30 Controls for open systems (21 CFR §11.30)
  • Part11.AuditTrail Audit trail requirements - secure computer-generated time-stamped (21 CFR §11.10(e))
  • Part11.RecordRetention Record protection + retention + readiness for inspection (21 CFR §11.10(b) + (c))
  • FFIEC-23 Regulatory reporting requirements
  • FFIEC-24 Customer notification procedures
  • FFIEC-25 Post-incident review and improvement

GDPR · 3 controls

IEC 62443 · 3 controls

ISO 13485 · 3 controls

ISO 22320:2018 · 3 controls

ISO 27019 · 3 controls

ISO 27799 · 3 controls

ISO/IEC 27011:2024 · 3 controls

ISO/IEC 27400:2022 · 3 controls

Indonesia PDP Law · 3 controls

Malaysia PDPA 2010 · 3 controls

Mauritius DPA · 3 controls

Mexico LFPDPPP · 3 controls

  • NIST-CSF-ID.IM-04 Incident response plans and other cybersecurity plans that affect operations are established, communicated, maintained, and improved
  • NIST-CSF-RC.RP-01 The recovery portion of the incident response plan is executed once initiated from the incident response process
  • NIST-CSF-RS.MA-01 The incident response plan is executed in coordination with relevant third parties once an incident is declared
  • NISTPF-4 Communicate-P - Privacy Notice, Transparency, and Individual Awareness
  • NISTPF-7 Protect-P Maintenance and Protective Technology (PR.MA-P, PR.PT-P)
  • NISTPF-8 Protect-P Information Protection Processes (PR.PO-P)

NIST SP 1800-32 · 3 controls

NIST SP 800-144 · 3 controls

  • NISTSP144-3 Data Classification, Handling, and Sovereignty
  • NISTSP144-5 Identity and Access in Cloud, Federation, and Privileged Access
  • NISTSP144-8 Monitoring, Incident Response, Exit Strategy, and Compliance

NIST SP 800-53 Rev 5 · 3 controls

  • NHPA-6 Reasonable Data Security and Breach Response
  • NHPA-7 Data Protection Assessments and Processor Contracts
  • NHPA-8 AG Formella Enforcement, Permanent 60-Day Cure, and Penalties

OSFI B-13 · 3 controls

  • OSFIB13-3 Cyber Security: Identification, Protection, Detection, Response, Recovery
  • OSFIB13-7 Incident Reporting to OSFI and Regulatory Coordination
  • OSFIB13-8 Metrics, Monitoring, Continuous Improvement, Maturity
  • OREGONCPA-3 Consent, Sensitive Data, Children and Teen Protections
  • OREGONCPA-5 Data Protection Assessments, Privacy by Design, Security Practices
  • OREGONCPA-8 Cure Period, Attorney General Enforcement, Training, Compliance Monitoring

PCI P2PE · 3 controls

PCI PIN Security · 3 controls

PCI SSF · 3 controls

PDPA Singapore · 3 controls

  • PDPASG-1 Accountability, Records, DPO Appointment, and Training
  • PDPASG-4 Children's Data, DPIA, and Privacy by Design
  • PDPASG-8 Data Breach Notification, Incident Response, and Enforcement

PDPA Thailand · 3 controls

  • PDPATH-4 DPIA, Privacy by Design, Children's Data
  • PDPATH-7 DPO, Records of Processing, Retention, Marketing, Training
  • PDPATH-8 Data Breach Notification, Complaints, Compliance, Enforcement

POPIA · 3 controls

  • POPIASA-4 Special Personal Information, Children, Information Quality, Documentation
  • POPIASA-5 Security Safeguards, Encryption, Access Control, Operator Obligations
  • POPIASA-7 Information Officer, Records of Processing, Notification, Training
  • NORWAY-4 DPIA, Privacy by Design, Records of Processing
  • NORWAY-7 DPO, Cooperation with Datatilsynet, Retention, Marketing, Training
  • NORWAY-8 Breach Notification, Complaints, Compliance, Enforcement

Peru DPL · 3 controls

  • PERU-3 Data Subject Rights (ARCO), Habeas Data, Automated Decisions
  • PERU-7 DPO, Records, Retention, Marketing, Training
  • PERU-8 Breach Notification, ANPD Cooperation, Sanctions, Compliance

Privacy Act 2020 · 3 controls

  • NZPRV-6 IPP 13 Unique Identifiers, Privacy Impact Assessment, Privacy by Design
  • NZPRV-7 Notifiable Privacy Breach Scheme
  • NZPRV-8 Privacy Officer, OPC Cooperation, Compliance Notices, Complaints, Training

Qatar DPL · 3 controls

  • QATAR-5 Security of Processing
  • QATAR-7 DPO, Records, Retention, Marketing, Training
  • QATAR-8 Breach Notification, Compliance, Enforcement
  • UGA-3 Accountability Principle
  • UGA-6 Personal Data Protection Office
  • UGA-7 Data Protection Officer

APPI · 2 controls

  • APPI-A41 Preparation and Handling of Pseudonymized Personal Information
  • APPI-A43 Preparation of Anonymized Personal Information

APRA CPS 234 · 2 controls

  • CPS234-21 Implementation of Information Security Controls
  • CPS234-25 Internal Audit Review of Information Security Controls
  • AZ-DPA-15 Article 17 - Dispute resolution
  • AZ-DPA-6 Article 6 - State regulation in personal data protection

FISMA · 2 controls

FedRAMP Rev 5 · 2 controls

GLBA · 2 controls

ISMAP (Japan) · 2 controls

ISO/IEC 30111:2019 · 2 controls

India DPDP Act · 2 controls

LGPD · 2 controls

Liechtenstein DPA · 2 controls

MARS-E · 2 controls

MDS2 (Medical Device) · 2 controls

  • NIS2I-3 Incident Handling Policy, Reporting Significance Criteria, and Business Continuity
  • NIS2I-5 Cyber Hygiene, Training, Cryptography, and Human Resources Security

NIST SP 800-122 · 2 controls

  • NISTSP122-6 PII Breach Response and Incident Handling
  • NISTSP122-8 Continuous Monitoring, Training, and Privacy Programme Governance

NIST SP 800-145 · 2 controls

  • NISTSP145-3 Rapid Elasticity Characteristic and Capacity Management
  • NISTSP145-8 Governance, Reporting, and Stakeholder Education on Cloud Definition

NIST SP 800-146 · 2 controls

  • NISTSP146-6 Cloud Security and Privacy Recommendations
  • NISTSP146-7 Service Level, Performance, Reliability, Interoperability, and Portability
  • 3.6 Encrypt Data on End-User Devices
  • 3.6.1 Procedures are defined and implemented to protect cryptographic keys used to protect stored account data against disclosure and misuse that include: • Access to keys is restricted to the fewest number of custodians necessary.
  • NRFCS-1 Retail Cybersecurity Governance, Policy, and Regulatory Change Management
  • NRFCS-7 Detection, Logging, Incident Response, Breach Notification, and Fraud Detection
  • NGCB-6 Incident Response, 72-Hour NGCB Notification, and Independent Investigation
  • NGCB-7 Patron and Employee Data Protection + Data Inventory + Vendor Management
  • NGNDPR-5 Security of Personal Data, Breach Notification, and DPIA under NDPR Section 2.6-Security
  • NGNDPR-6 Data Protection Officer, DPCOs, and Processor Obligations
  • OMANCS-4 Data Protection, Cryptography, and Privacy Alignment
  • OMANCS-6 Security Monitoring, Detection, Incident Response, and OmanCERT Notification

Open Banking Security · 2 controls

  • OPENBANK-7 Logging, Monitoring, Regulatory Reporting, SLA, Availability
  • OPENBANK-8 Incident Detection, Response, Customer Notification, Post-Incident Review, BCM

PSD2 SCA · 2 controls

  • PSDTWO-3 Common and Secure Communication, API Access for AISPs and PISPs
  • PSDTWO-4 Fraud Reporting and Incident Management

SOC 2 · 2 controls

  • SOC2-CC7.4 Responds to identified security incidents through defined procedures
  • SOC2-CC7.5 Identifies the root cause of security incidents

South Korea PIPA · 2 controls

Turkey KVKK · 2 controls

Uruguay DPL · 2 controls

Vietnam PDPD · 2 controls

  • PMF-M.4 Privacy Incident Management
  • CPS230-13 Board Accountability for Operational Risk Management
  • 4.4.7 Emergency and Incident Response
  • CA-12 Deploys Through Policies and Procedures
  • FIRST-CSIRTF-SA2-ISIM Service Area 2 - Information Security Incident Management (Intake, Analysis, Containment, Recovery, Coordination, Crisis)

HITECH Act · 1 control

HKMA SPM · 1 control

IEEE 1686 · 1 control

IEEE 7000 · 1 control

ISO 20000-1 · 1 control

ISO 26000:2010 · 1 control

ISO/IEC 23894:2023 · 1 control

ISO/IEC 27010:2015 · 1 control

ISO/IEC 29147:2018 · 1 control

ITIL 4 · 1 control

Japan AI Guidelines · 1 control

NERC CIP · 1 control

  • NERCCIP-6 Incident Reporting and Response Planning + Recovery Plans (CIP-008 + CIP-009)

NIST SP 800-171 · 1 control

  • 3.6.1 Procedures are defined and implemented to protect cryptographic keys used to protect stored account data against disclosure and misuse that include: • Access to keys is restricted to the fewest number of custodians necessary.

NIST SP 800-66 · 1 control

  • NISTSP66-6 Technical Safeguards: Access Control, Audit Controls, Integrity, Person Authentication
  • NISTSP82-7 OT Incident Response, Forensics, Recovery, and Continuity
  • NGOB-5 Fraud Monitoring, Incident Notification, and Reporting to CBN

OECD AI Principles · 1 control

  • OECDAI-5 Data Governance, Training Data Quality, Privacy, and Bias Mitigation
  • DSOMM-1 Culture, Organization, Education, and Governance
  • PASONE-6 Incident Management, Audit, Handover, Operational Phase, Decommissioning
  • PNGCYBER-4 Incident Response, Investigation, Evidence Preservation, Data Retention
  • PARAGUAY-5 Security of Processing, Data Integrity, Information Security
  • PSPF24-1 Security Culture, Governance, Risk Management

South Korea ISMS-P · 1 control

  • STUDPRV-2 Data Subject Rights for Students and Parents
  • TSAPIPE-2 OT/IT Network Segmentation and Access Control

Taiwan PDPA · 1 control

  • UKAI-2 Sector-Specific Regulator Engagement
  • UNESCOAI-2 Principles 4-7: Sustainability, Privacy, Human Oversight, Transparency
  • UNICEFAI-4 Transparency, Explanation, Adult Capacity

Virginia CDPA · 1 control

  • VPSHR-3 Implementation Guidance and Reporting

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in DEFSTAN 05-138 Section D: Minimising the Impact of Incidents

Query this from an agent

The graph holds this control, the 460 it maps to, and the evidence behind each claim, over MCP and REST.