Frameworks / Vietnam Law on Cybersecurity (No. 24/2018/QH14) / VIETNAMCYBER-2 What else in your programme already covers this This control maps to 419 controls across 182 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
NDPA-1 Applicability, Scope, and Carve-Outs NDPA-2 Consumer Rights - Access, Correct, Delete, Portability, Appeal NDPA-4 Sensitive Data Processing Consent and Childrens Protections NDPA-5 Privacy Notice, Data Minimisation, and Purpose Limitation NDPA-6 Reasonable Security Practices and Incident Response NDPA-7 Data Protection Assessments and Processor Contracts NG-NDPA-1 Scope, Applicability, and Establishment of Nigeria Data Protection Commission NG-NDPA-2 Lawful Basis, Consent, and Data Protection Principles NG-NDPA-4 Data Subject Rights and Automated Decision-Making NG-NDPA-5 Security of Processing, Breach Notification, and DPIA NG-NDPA-6 Data Protection Officer, DPCO, and Processor Agreements NG-NDPA-7 Cross-Border Data Transfers and International Cooperation APPI-A23 Security Control Measures APPI-A24 Supervision of Employees APPI-A33 Request for Disclosure of Retained Personal Data APPI-A41 Preparation and Handling of Pseudonymized Personal Information APPI-A43 Preparation of Anonymized Personal Information AT-DSG-11 Sections 42-45 - Data subject rights (law enforcement) AT-DSG-13 Section 36 - Scope of law enforcement processing AT-DSG-14 Section 38 - Lawfulness of law enforcement processing AT-DSG-2 Section 2 - Scope and application AT-DSG-8 Section 22 - Functions and powers of the DPA NISTPF-1 Identify-P - Business Environment, Data Processing Inventory, Ecosystem, and Risk Assessment NISTPF-3 Control-P - Privacy Controls, Data Management, and Disassociated Processing NISTPF-4 Communicate-P - Privacy Notice, Transparency, and Individual Awareness NISTPF-7 Protect-P Maintenance and Protective Technology (PR.MA-P, PR.PT-P) NISTPF-8 Protect-P Information Protection Processes (PR.PO-P) OSFIB13-1 Governance, Risk Management, and Three Lines of Defense OSFIB13-3 Cyber Security: Identification, Protection, Detection, Response, Recovery OSFIB13-7 Incident Reporting to OSFI and Regulatory Coordination OSFIB13-8 Metrics, Monitoring, Continuous Improvement, Maturity PERU-2 Consent, Privacy Notice, Sensitive Data PERU-5 Security of Personal Data and Processor Agreements PERU-7 DPO, Records, Retention, Marketing, Training PERU-8 Breach Notification, ANPD Cooperation, Sanctions, Compliance QATAR-3 Data Subject Rights QATAR-5 Security of Processing QATAR-7 DPO, Records, Retention, Marketing, Training QATAR-8 Breach Notification, Compliance, Enforcement APP-1 APP 1 - Open and transparent management of personal information APP-3 APP 3 - Collection of solicited personal information APP-5 APP 5 - Notification of the collection of personal information 1.2 Operating System Privileged Account Control 1.3 Virtualisation Platform Protection 3.3 Configure Data Access Control Lists NISTSP122-4 PII Minimisation, Purpose Limitation, and Pseudonymisation NISTSP122-5 PII Security Controls - Encryption, Access Control, Storage, Audit NISTSP122-6 PII Breach Response and Incident Handling 3.3 Configure Data Access Control Lists 3.6 Encrypt Data on End-User Devices 3.6.1 Procedures are defined and implemented to protect cryptographic keys used to protect stored account data against disclosure and misuse that include: • Access to keys is restricted to the fewest number of custodians necessary. NHPA-5 Privacy Notice, Data Minimisation, and Purpose Limitation NHPA-6 Reasonable Data Security and Breach Response NHPA-7 Data Protection Assessments and Processor Contracts NJDPA-2 Consumer Rights - Access, Correct, Delete, Portability, Appeal NJDPA-6 Reasonable Data Security and Incident Response NJDPA-8 AG Platkin Enforcement, 18-Month Cure Sunset, and Division of Consumer Affairs NGOB-1 Open Banking Registry Participation, Tiered Categorisation, and KYP NGOB-2 Customer Consent Management and Lifecycle NGOB-5 Fraud Monitoring, Incident Notification, and Reporting to CBN ORANWG11-2 O-RAN Interface Security: E2, A1, O1, O2, Open Fronthaul ORANWG11-3 Cryptography, TLS, SSH, IPsec, and PKI Lifecycle Management ORANWG11-6 Security Test Specifications, Certification, and Conformance OPENBANK-2 Strong Customer Authentication (SCA), Consent Lifecycle, and Customer UX OPENBANK-7 Logging, Monitoring, Regulatory Reporting, SLA, Availability OPENBANK-8 Incident Detection, Response, Customer Notification, Post-Incident Review, BCM OREGONCPA-3 Consent, Sensitive Data, Children and Teen Protections OREGONCPA-5 Data Protection Assessments, Privacy by Design, Security Practices OREGONCPA-7 Processor Contracts, Cross-Border Transfers, DPAs PDPASG-2 Notification, Consent, Purpose Limitation, and Lawful Basis PDPASG-5 Protection, Accuracy, and Security of Personal Data PDPASG-8 Data Breach Notification, Incident Response, and Enforcement PICSGMP-2 Chapter 2: Personnel - Qualified Personnel, Key Responsibilities, Training PICSGMP-5 Chapter 5: Production Operations and Material Management PICSGMP-7 Chapter 7: Outsourced Activities and Supplier Management POPIASA-3 Data Subject Rights (Access, Correction, Objection), Automated Decisions POPIASA-4 Special Personal Information, Children, Information Quality, Documentation POPIASA-5 Security Safeguards, Encryption, Access Control, Operator Obligations PSDTWO-1 Strong Customer Authentication (SCA) Core Requirements PSDTWO-3 Common and Secure Communication, API Access for AISPs and PISPs PSDTWO-4 Fraud Reporting and Incident Management PAKPDPB-5 Security of Processing and Personal Data Breach Notification PAKPDPB-7 NCPDP, Registration, Records, Processor Contracts, DPO PAKPDPB-8 Enforcement, Penalties, Complaints, Retention, Training NZPRV-2 IPP 5 Storage and Security of Personal Information NZPRV-6 IPP 13 Unique Identifiers, Privacy Impact Assessment, Privacy by Design NZPRV-7 Notifiable Privacy Breach Scheme ASD37-31 Hunt to discover incidents (Very Good) ASD37-33 Capture network traffic (Limited) 4.4.1 Resources, Roles, Responsibility, and Authority 4.4.7 Emergency and Incident Response 6.5 Preparing and Distributing Audit Report 6.7 Conducting Audit Follow-up 6.5 Preparing and Distributing Audit Report 6.7 Conducting Audit Follow-up STANAG-1 STANAG 4774 Confidentiality Label Schema and XML Structure STANAG-2 STANAG 4778 Metadata Binding Mechanism and Cryptographic Binding NISTSP144-1 Cloud Governance, Risk Assessment, and Provider Trust Evaluation NISTSP144-8 Monitoring, Incident Response, Exit Strategy, and Compliance NISTSP145-7 Cloud Procurement Standards Aligned to NIST SP 800-145 Definition NISTSP145-8 Governance, Reporting, and Stakeholder Education on Cloud Definition NISTSP146-1 Cloud Adoption Strategy, Workload Suitability, and Decision Framework NISTSP146-6 Cloud Security and Privacy Recommendations NISTSP82-1 OT Security Program Governance, Policy, Roles, and Safety-Security Integration NISTSP82-7 OT Incident Response, Forensics, Recovery, and Continuity NISTSP34-1 Contingency Planning Policy, Programme, and Plan Coordination NISTSP34-2 Business Impact Analysis (BIA): Critical Resources, Recovery Priorities NRC7354-2 Critical Digital Asset (CDA) Identification, Scope, and Boundary NRC7354-4 Security Controls Implementation per NRC RG 5.71 Appendix B/C NGCB-6 Incident Response, 72-Hour NGCB Notification, and Independent Investigation NGCB-7 Patron and Employee Data Protection + Data Inventory + Vendor Management NGNDPR-2 Governing Principles, Lawful Basis, and Consent under NDPR Section 2.1-2.3 NGNDPR-5 Security of Personal Data, Breach Notification, and DPIA under NDPR Section 2.6-Security DSOMM-1 Culture, Organization, Education, and Governance DSOMM-2 Implementation Practices, Secure Coding, and Threat Modelling OMANCS-4 Data Protection, Cryptography, and Privacy Alignment OMANCS-6 Security Monitoring, Detection, Incident Response, and OmanCERT Notification PDPATH-5 Security Measures and Data Protection PDPATH-8 Data Breach Notification, Complaints, Compliance, Enforcement NORWAY-5 Security of Processing, Encryption, Pseudonymization, Access Control NORWAY-8 Breach Notification, Complaints, Compliance, Enforcement R.16-VATR.Unhosted Unhosted (self-hosted / non-custodial) wallet transfers - 2024 Targeted Update QMSR-ISO13485-Sec5 Management responsibility (ISO 13485:2016 Section 5 - incorporated via §820.10) FIRST-CSIRTF-SA2-ISIM Service Area 2 - Information Security Incident Management (Intake, Analysis, Containment, Recovery, Coordination, Crisis) CBPR-9-APEC-Privacy-Principles Global CBPR Forum: 9 APEC Privacy Principles (Notice + Collection + Uses + Choice + Integrity + Security + Access + Accountability + Preventing Harm) 6.7 Conducting Audit Follow-up NAIC-6 Cybersecurity Event Investigation and Notification - Sections 6 and 7 NERCCIP-6 Incident Reporting and Response Planning + Recovery Plans (CIP-008 + CIP-009) NIS2I-3 Incident Handling Policy, Reporting Significance Criteria, and Business Continuity NISTAI600-7 Confabulation, Bias, Information Integrity, Privacy, IP (Risks 2, 4, 5, 6, 7, 8, 10, 11) PQC-4 FIPS 205 SLH-DSA Implementation - Stateless Hash-Based Digital Signature NISTSP115-1 Scope, Methodology, and Assessment Planning NISTSP137-1 ISCM Strategy, Governance, and Volatility Assessment 3.6.1 Procedures are defined and implemented to protect cryptographic keys used to protect stored account data against disclosure and misuse that include: • Access to keys is restricted to the fewest number of custodians necessary. NISTSP61-2 Computer Security Incident Response Team (CSIRT) Structure and Staffing NISTSP63R4-1 Digital Identity Risk Management and IAL/AAL/FAL Assurance Level Selection NISTSP88-1 Media Sanitization Policy, Roles, and Decision Framework NISTSP92-1 Log Management Programme, Policy, Roles, and Operational Runbooks NRFCS-7 Detection, Logging, Incident Response, Breach Notification, and Fraud Detection AUNDB-A3 Eligible Data Breach Determination and Serious Harm Threshold OCCHS-1 Scope, Applicability, and Definitions of Heightened Standards OECDAI-5 Data Governance, Training Data Quality, Privacy, and Bias Mitigation OWASPSAMM-1 Governance: Strategy, Policy, Compliance, Education, Champions OWASPLLM-3 Sensitive Information Disclosure and Privacy (LLM02) OSSFSC-1 Branch Protection, Code Review, and Repository Governance PASONE-6 Incident Management, Audit, Handover, Operational Phase, Decommissioning 2.2.2 Vendor default accounts are managed as follows: • If the vendor default account(s) will be used, the default password is changed per Requirement 8.3.6. • If the vendor default account(s) will not be used, PNGCYBER-4 Incident Response, Investigation, Evidence Preservation, Data Retention PHILCC-1 Computer Crime Offences (Illegal Access, Interference, Misuse of Devices) PSPF24-1 Security Culture, Governance, Risk Management RCEPEC-1 Online Personal Information Protection (12.13) EHDSREG-1 Mandatory Requirements for EHR Systems (Articles 14-29) RIDTPPA-2 Consumer Rights (Access, Correction, Deletion, Portability, Opt-Out) SUPCHAIN-1 Build Integrity - Source, Build, Provenance SGCYBER-1 Critical Information Infrastructure (CII) Designation and Registration SAPAIA-4 Information Regulator Cooperation and Appeals STUDPRV-2 Data Subject Rights for Students and Parents TEFCAREC-1 Common Agreement Conformance and Onboarding TISAXASS-3 Prototype Protection and Confidentiality TSAPIPE-2 OT/IT Network Segmentation and Access Control UKAI-2 Sector-Specific Regulator Engagement UNICEFAI-4 Transparency, Explanation, Adult Capacity USCOPPA-3 Data Minimisation, Retention, Erasure (Eraser Button) USSDWA-2 Cybersecurity Practices (Assessment, Access, Network, IR) USMTSA-2 Cybersecurity Assessment and CSO Designation Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Query this from an agent The graph holds this control, the 419 it maps to, and the evidence behind each claim, over MCP and REST.