UN Guiding Principles on Business and Human Rights (UNGPs)
Respect

UN Guiding Principles on Business and Human Rights (UNGPs) UNGPBHR-2: Pillar II: Corporate Responsibility to Respect Human Rights

Per UNGPs Pillar II (GP 11-24): Responsibility to Respect + Policy Commitment + Human Rights Due Diligence (HRDD) including identification + integration + tracking + reporting + Avoid Causing Harm.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 64 controls across 46 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

ISO/IEC 30111:2019 · 3 controls

  • 30111-1 Scope
  • 30111-3 Terms and definitions
  • 30111-8.1 Post-release monitoring

ISO/IEC 29147:2018 · 2 controls

  • 29147-5.6 Advisory Content and Quality
  • 29147-7.8 Remediation information
  • OECDMNE-1 Concepts and General Policies, Risk-Based Due Diligence Framework
  • OECDMNE-4 Employment and Industrial Relations: Labour Rights and Working Conditions
  • OECDAI24-1 Updated AI System Definition, Foundation Models, and Generative AI Scope
  • OECDAI24-3 Frontier Model Risk Management, Capability Disclosure, and Independent Evaluation
  • CISABD-2 Embrace Radical Transparency and Accountability
  • CISABD-3 Build Organizational Structure and Leadership for Secure Outcomes

BSI IT-Grundschutz · 1 control

  • BSI-14 Vulnerability scanning and management
  • CPG-5.A Vulnerability Disclosure Program
  • CAT-D3-3 Corrective controls
  • FTC-Safeguards-ServiceProvider-Evaluation Service Provider Oversight + Program Evaluation + Personnel Training (16 CFR 314.4(d-g))
  • ICMM-MP-P3-P4-HumanRights-RiskMgmt-UNGP-DueDiligence ICMM Mining Principles 3 + 4 - Human Rights (UNGPs Alignment) + Risk Management + Due Diligence

ISMAP (Japan) · 1 control

ISO/IEC 27011:2024 · 1 control

  • 27011-8.5 Vulnerability and malware management

ISO/IEC 29134:2023 · 1 control

  • 29134-9.2 Report findings and recommendations
  • JP-FSA-CYB-Cybersecurity-Exercises-Drills-Annual-Tabletop-Industry-Wide-Exercise-Delta-Wall-FSA-Coordinated-Sector Japan FSA Cybersecurity Exercises + Drills + Annual Tabletop + Industry-Wide Exercise + Delta Wall + FSA Coordinated Sector-Wide + FISC Drills + Cross-Sector Crisis Coordination + International Exercises + Cyber Range

MITRE ATT&CK · 1 control

MTCS (Singapore) · 1 control

  • MTCS-Acquisition-Development-Maintenance-Supplier-Vulnerability-DevSecOps-SBOM-SDLC-SCA-API-Container MTCS Acquisition + Development + Maintenance + Supplier + Vulnerability + DevSecOps + SBOM + SDLC + SCA
  • NISTPF-8 Protect-P Information Protection Processes (PR.PO-P)
  • NISTSP115-3 Target Identification and Analysis - Network Discovery, Port and Service ID, Vuln Scanning

NIST SP 800-123 · 1 control

  • NISTSP123-5 Server Operations - Patching, Malware, Logging, Backup

NIST SP 800-137 · 1 control

  • NISTSP137-5 Vulnerability + Patch + Configuration Status Monitoring

NIST SP 800-144 · 1 control

  • NISTSP144-7 Cloud Workload Protection, Containers, Serverless, and Configuration

NIST SP 800-145 · 1 control

  • NISTSP145-7 Cloud Procurement Standards Aligned to NIST SP 800-145 Definition

NIST SP 800-146 · 1 control

  • NISTSP61-5 Containment, Eradication, and Recovery

NIST SP 800-63-4 · 1 control

  • NISTSP63R4-8 Operational Audit, Session Management, Recovery, and Cross-cutting Controls

NIST SP 800-88 · 1 control

  • NISTSP88-7 Verification, Audit, Training, and Environmental/Safety Controls

NIST SP 800-92 · 1 control

  • NISTSP92-5 Log Analysis: Correlation, Baselining, Anomaly Detection, Alerting, Manual Review
  • NRFCS-2 Risk Assessment, Customer Data Inventory, Classification, and Retail Threat Model
  • NGCB-6 Incident Response, 72-Hour NGCB Notification, and Independent Investigation
  • NZISM-5 Network Security, System Hardening, and Application Security
  • ORANWG11-1 O-RAN Threat Model, Risk Management, and Security Architecture

OECD AI Principles · 1 control

  • OECDAI-1 Inclusive Growth, Human-Centred Values, Fairness, and Sustainable Development

OWASP MASVS · 1 control

  • OWASPMASVS-6 MASVS-CODE: Code Quality, Build Settings, and Updates

OWASP SAMM · 1 control

  • OWASPSAMM-4 Verification: Architecture Assessment, Requirements-Driven Testing, Security Testing

OpenSSF Scorecard · 1 control

  • OSSFSC-2 Dependency Management, Pinning, Updates, Vulnerability Tracking
  • PASONE-6 Incident Management, Audit, Handover, Operational Phase, Decommissioning

PTES · 1 control

  • PTESPHASE-4 Vulnerability Analysis
  • SAEIGHT-1 Child Labour and Young Worker Protection
  • SHAREASSESS-4 Vulnerability Management, Patching, Application Security

SLSA · 1 control

  • SUPCHAIN-2 Source Integrity - Branch Protection, Code Review, Two-Person Rule
  • TSAPIPE-1 Cybersecurity Implementation Plan and Coordinator
  • UKOPRES-4 Incident Management, Lessons Learned, Comms

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 64 it maps to, and the evidence behind each claim, over MCP and REST.