Back to Frameworks

ASEAN Data Management Framework

ASEAN
v2021
6 domains
27 controls

The ASEAN Data Management Framework provides a common framework for ASEAN member states to harmonize data governance across the region. It covers data lifecycle management, cross-border data flows, data protection measures, and organizational accountability. Designed to facilitate trusted data flows within ASEAN while maintaining appropriate safeguards.

Verified

Get the official standard — this page is an AI-assisted companion tool, not a replacement for the authoritative text.

Visit asean.org

Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.

Framework Domains (6)

Controls

6 controls

Risk-based protection controls applied across the data lifecycle (Component 5).

Controls in the Controls domain of ASEAN Data Management Framework6 controls
CodeTitle
ADMF-5.1Implement risk-based protection controls
ADMF-5.2Apply technical, procedural and physical safeguards
ADMF-5.3Protect data across the data lifecycle
ADMF-5.4Build a data protection control matrix
ADMF-5.5Manage and accept residual risk
ADMF-5.6Reference recognised security and privacy standards

Data Inventory

3 controls

Identification, understanding and inventory of the data the organisation holds (Component 3).

Controls in the Data Inventory domain of ASEAN Data Management Framework3 controls
CodeTitle
ADMF-3.1Identify and understand organisational data
ADMF-3.2Maintain a data inventory
ADMF-3.3Apply overarching categorisation considerations

Governance and Oversight

5 controls

Corporate governance structure, roles and responsibilities to define, manage and oversee data management (Component 1).

Controls in the Governance and Oversight domain of ASEAN Data Management Framework5 controls
CodeTitle
ADMF-1.1Establish data management governance functions
ADMF-1.2Data management function responsibilities
ADMF-1.3Business process function responsibilities
ADMF-1.4Risk management function responsibilities
ADMF-1.5Executive direction and risk appetite

Impact / Risk Assessment

4 controls

Categorisation of datasets by impact to the organisation if compromised (Component 4).

Controls in the Impact / Risk Assessment domain of ASEAN Data Management Framework4 controls
CodeTitle
ADMF-4.1Establish a data categorisation matrix
ADMF-4.2Assess confidentiality, integrity and availability impact
ADMF-4.3Assess business impact categories
ADMF-4.4Assign datasets to risk tiers

Monitoring and Continuous Improvement

5 controls

Monitoring, measurement, analysis and evaluation to keep components current and optimised (Component 6).

Controls in the Monitoring and Continuous Improvement domain of ASEAN Data Management Framework5 controls
CodeTitle
ADMF-6.1Define monitoring and measurement scope
ADMF-6.2Review controls associated with each category
ADMF-6.3Review categories assigned to datasets
ADMF-6.4Test data protection control effectiveness
ADMF-6.5Update policies, procedures and processes

Policies and Procedures

4 controls

Documented data management policies and procedures spanning the data lifecycle (Component 2).

Controls in the Policies and Procedures domain of ASEAN Data Management Framework4 controls
CodeTitle
ADMF-2.1Leadership commitment in policy (who)
ADMF-2.2Define objectives, scope and considerations (what and why)
ADMF-2.3Establish the data management approach (how)
ADMF-2.4Embed data management in corporate governance and policy

Maps to 2 other frameworks

27 total controls
NIST Cybersecurity Framework 2.0
26 source controls mapped|25 target controls covered
96%
NIST SP 800-53 Rev 5
23 source controls mapped|9 target controls covered
85%

Frequently Asked Questions

What is ASEAN Data Management Framework?

ASEAN Data Management Framework is a compliance framework from ASEAN with 6 domains and 27 controls. The ASEAN Data Management Framework provides a common framework for ASEAN member states to harmonize data governance across the region. It covers data lifecycle management, cross-border data flows, data protection measures, and organizational accountability. Designed to facilitate trusted data flows within ASEAN while maintaining appropriate safeguards. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.

How many controls does ASEAN Data Management Framework have?

ASEAN Data Management Framework has 27 controls organised across 6 domains. The largest domains are Controls (6 controls), Governance and Oversight (5 controls), Monitoring and Continuous Improvement (5 controls). Each control defines specific requirements that organisations must implement to achieve compliance.

What frameworks does ASEAN Data Management Framework map to?

ASEAN Data Management Framework maps to 2 other compliance frameworks. The top mapping partners are NIST Cybersecurity Framework 2.0 (96% coverage), NIST SP 800-53 Rev 5 (85% coverage). Use our comparison tool to explore control-level mappings between frameworks.

How do I get started with ASEAN Data Management Framework compliance?

Start your ASEAN Data Management Framework compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about ASEAN Data Management Framework requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 27 controls and track your progress.

Start Your Compliance Journey

Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 700 frameworks.

Get Started Free →

Free forever — no credit card required