Frameworks / UK Open Banking Standard / OB-SEC.4 What else in your programme already covers this This control maps to 207 controls across 86 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
ASD37-17 TLS encryption between email servers (Limited) ASD37-20 Multi-factor authentication (Essential) ASD37-23 Protect authentication credentials (Excellent) BSI-03 Multi-factor authentication requirements BSI-08 Cryptographic protection of data CJIS-8 Media Protection CJIS-9 System and Communications Protection 6.5 Preparing and Distributing Audit Report 6.7 Conducting Audit Follow-up NIST-CSF-PR.AA-01 Identities and credentials for authorized users, services, and hardware are managed by the organization NIST-CSF-PR.AA-02 Identities are proofed and bound to credentials based on the context of interactions ORANWG11-2 O-RAN Interface Security: E2, A1, O1, O2, Open Fronthaul ORANWG11-3 Cryptography, TLS, SSH, IPsec, and PKI Lifecycle Management OMANCS-3 Identity and Access Management, Authentication, Privileged Access OMANCS-4 Data Protection, Cryptography, and Privacy Alignment OSSFSC-3 Build, CI/CD Security, Workflow Permissions, Dangerous Patterns OSSFSC-6 Signed Releases, Provenance, Trusted Publishing, Binary Artifacts SUPCHAIN-1 Build Integrity - Source, Build, Provenance SUPCHAIN-2 Source Integrity - Branch Protection, Code Review, Two-Person Rule CISABD-1 Take Ownership of Customer Security Outcomes SBD-DEV-04 Phishing-Resistant Authentication SIGSTORE-2 Transparency Log (Rekor) and Verification SIGSTORE-3 Sigstore for Containers and Artifacts (Cosign) VP-2 Holder Binding W3CVCDM-4 Accessibility, Internationalization, Security APPI-A34 Request for Correction, Addition or Deletion DSO-3 Data Access Management FTC-Safeguards-9-Elements 9 Safeguard Elements - Access, Inventory, Encryption, Secure-Dev, MFA, Disposal, Change-Mgmt, Monitoring, Pen-Test (16 CFR 314.4(c)) UAE-PDPL-Art.4_5 Lawful basis and principles for processing personal data (UAE PDPL Articles 4-5) 62351-9 Cyber security key management 9.1 Risk communication and consultation STANAG-2 STANAG 4778 Metadata Binding Mechanism and Cryptographic Binding NISTPF-5 Protect-P Access Control (PR.AC-P) OSFIB13-3 Cyber Security: Identification, Protection, Detection, Response, Recovery OWASPSAMM-2 Design: Threat Assessment, Security Requirements, Security Architecture OPENBANK-3 Mutual TLS, Token Binding, Request Signing (JWS), Key Management OREGONCPA-7 Processor Contracts, Cross-Border Transfers, DPAs PASONE-4 Technical Security: CDE Configuration, BIM Tools, Encryption, Aggregation, Mobile Working PDPASG-5 Protection, Accuracy, and Security of Personal Data PDPATH-5 Security Measures and Data Protection POPIASA-5 Security Safeguards, Encryption, Access Control, Operator Obligations PSDTWO-2 SCA Exemptions and Risk-Based Authentication PERU-7 DPO, Records, Retention, Marketing, Training RCEPEC-1 Online Personal Information Protection (12.13) SSAE18-CC6.2 CC6.2 - New User Registration and Authorization TSAPIPE-2 OT/IT Network Segmentation and Access Control TAIWAN-2 Consent, Notice, Sensitive Data CYB-2 Account Security Measures URUGUAY-3 Sensitive Data, Health Data, Children Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Other controls in Security Profile Query this from an agent The graph holds this control, the 207 it maps to, and the evidence behind each claim, over MCP and REST.