← Frameworks / EU GDPR / Control Mappings

EU General Data Protection Regulation (2016/679)

The EU's comprehensive data protection and privacy regulation. Establishes principles for lawful processing, data subject rights, controller and processor obligations, breach notification (72 hours), data protection by design and by default, and cross-border transfer safeguards. Applies to any organisation processing personal data of EU residents.

Controls: 194
Total Mappings: 439
Publisher: European Union Version: 2016/679

AC Access Control

Control Name EU GDPR References
AC-01 Policy and Procedures
Art.5(1)(f)Art.24(1)Art.24(2)Art.25(1)Art.32(1)(b)Art.32(2)
AC-02 Account Management
Art.5(1)(f)Art.25(2)Art.32(1)(b)Art.32(4)
AC-03 Access Enforcement
Art.5(1)(f)Art.25(2)Art.32(1)(b)
AC-04 Information Flow Enforcement
Art.5(1)(f)Art.32(1)(a)Art.44Art.46(1)
AC-05 Separation of Duties
Art.5(1)(f)Art.24(1)Art.32(1)(b)
AC-06 Least Privilege
Art.5(1)(c)Art.5(1)(f)Art.25(2)Art.32(1)(b)
AC-07 Unsuccessful Logon Attempts
Art.32(1)(b)Art.32(1)(d)
AC-08 System Use Notification
Art.12(1)Art.13(1)
AC-09 Previous Logon Notification
Art.5(1)(f)Art.32(1)(d)
AC-10 Concurrent Session Control
Art.32(1)(b)
AC-11 Device Lock
Art.32(1)(b)
AC-12 Session Termination
Art.32(1)(b)
AC-13 Supervision and Review — Access Control
Art.5(1)(f)Art.5(2)Art.32(1)(d)
AC-14 Permitted Actions Without Identification or Authentication
Art.25(2)
AC-15 Automated Marking
Art.5(1)(f)
AC-16 Security and Privacy Attributes
Art.5(1)(e)Art.9(1)
AC-17 Remote Access
Art.32(1)(a)Art.32(1)(b)Art.44
AC-18 Wireless Access
Art.32(1)(a)Art.32(1)(b)
AC-19 Access Control for Mobile Devices
Art.32(1)(a)Art.32(1)(b)
AC-20 Use of External Systems
Art.28(1)Art.28(3)(a)Art.32(1)(b)

AT Awareness and Training

Control Name EU GDPR References
AT-01 Policy and Procedures
Art.39(1)(b)Art.47(2)(n)Rec.78
AT-02 Literacy Training and Awareness
Art.39(1)(b)Art.47(2)(n)
AT-03 Role-based Training
Art.29Art.32(4)Art.47(2)(n)
AT-04 Training Records
Art.5(2)Art.24(1)
AT-05 Contacts with Security Groups and Associations
Art.39(1)(b)
AT-06 Training Feedback
Art.39(1)(b)Art.47(2)(n)

AU Audit and Accountability

Control Name EU GDPR References
AU-01 Policy and Procedures
Art.5(2)Art.24(1)Art.30(1)Art.30(2)
AU-02 Event Logging
Art.5(2)Art.7(1)Art.30(1)(g)Art.33(3)
AU-03 Content of Audit Records
Art.7(1)Art.30(1)(g)Art.33(3)(a)Art.33(3)(b)
AU-04 Audit Log Storage Capacity
Art.5(1)(e)Art.30(1)
AU-05 Response to Audit Logging Process Failures
Art.32(1)(b)Art.32(1)(d)
AU-06 Audit Record Review, Analysis, and Reporting
Art.32(1)(d)Art.33(3)(d)
AU-07 Audit Record Reduction and Report Generation
Art.5(2)Art.30(1)
AU-08 Time Stamps
Art.33(1)
AU-09 Protection of Audit Information
Art.5(1)(f)Art.32(1)(b)
AU-10 Non-repudiation
Art.5(2)
AU-11 Audit Record Retention
Art.5(1)(e)Art.17(1)

CA Security Assessment and Authorization

Control Name EU GDPR References
CA-01 Policy and Procedures
Art.24(1)Art.32(1)(d)Art.32(2)
CA-02 Control Assessments
Art.32(1)(d)Art.35(1)Art.35(7)
CA-03 Information Exchange
Art.28(3)(a)Art.32(1)(a)
CA-04 Security Certification
Art.32(1)(d)
CA-05 Plan of Action and Milestones
Art.24(1)Art.32(1)(d)
CA-06 Authorization
Art.24(1)Art.36(1)
CA-07 Continuous Monitoring
Art.32(1)(d)Art.35(11)
CA-09 Internal System Connections
Art.32(1)(d)

CM Configuration Management

Control Name EU GDPR References
CM-01 Policy and Procedures
Art.25(1)Art.32(1)(b)Rec.78
CM-02 Baseline Configuration
Art.25(1)Art.32(1)(b)
CM-03 Configuration Change Control
Art.32(1)(b)Art.32(1)(d)
CM-04 Impact Analyses
Art.32(1)(d)Art.35(1)
CM-05 Access Restrictions for Change
Art.32(1)(b)
CM-06 Configuration Settings
Art.25(1)Art.25(2)Art.32(1)(b)
CM-07 Least Functionality
Art.25(1)Art.25(2)Art.32(1)(b)
CM-08 System Component Inventory
Art.30(1)Art.35(7)(a)
CM-12 Information Location
Art.5(1)(c)Art.5(1)(e)Art.25(1)Art.30(1)Art.35(7)(a)Rec.78
CM-13 Data Action Mapping
Art.5(1)(b)Art.5(2)Art.6(4)Art.25(1)Art.30(1)Art.30(2)Art.35(7)(a)Rec.78

CP Contingency Planning

Control Name EU GDPR References
CP-01 Policy and Procedures
Art.32(1)(b)Art.32(1)(c)
CP-02 Contingency Plan
Art.32(1)(b)Art.32(1)(c)Art.32(1)(d)
CP-03 Contingency Training
Art.32(1)(d)
CP-04 Contingency Plan Testing
Art.32(1)(d)
CP-05 Contingency Plan Update
Art.32(1)(c)Art.32(1)(d)
CP-06 Alternate Storage Site
Art.32(1)(c)
CP-07 Alternate Processing Site
Art.32(1)(c)
CP-08 Telecommunications Services
Art.32(1)(b)Art.32(1)(c)
CP-09 System Backup
Art.32(1)(c)
CP-10 System Recovery and Reconstitution
Art.32(1)(c)Art.32(1)(d)

IA Identification and Authentication

Control Name EU GDPR References
IA-01 Policy and Procedures
Art.5(1)(f)Art.32(1)(b)Art.32(1)(d)
IA-02 Identification and Authentication (Organizational Users)
Art.32(1)(b)Art.32(1)(d)
IA-03 Device Identification and Authentication
Art.32(1)(b)
IA-04 Identifier Management
Art.5(1)(f)Art.32(1)(b)
IA-05 Authenticator Management
Art.32(1)(a)Art.32(1)(b)
IA-06 Authentication Feedback
Art.32(1)(b)
IA-07 Cryptographic Module Authentication
Art.32(1)(a)Rec.83

IR Incident Response

Control Name EU GDPR References
IR-01 Policy and Procedures
Art.33(1)Art.33(2)Art.34(1)Art.34(2)
IR-02 Incident Response Training
Art.33(2)Art.39(1)(b)
IR-03 Incident Response Testing
Art.32(1)(d)Art.33(5)
IR-04 Incident Handling
Art.33(1)Art.33(3)Art.33(4)Art.34(1)
IR-05 Incident Monitoring
Art.33(3)(d)Art.33(5)
IR-06 Incident Reporting
Art.33(1)Art.33(2)Art.34(1)Art.34(3)
IR-07 Incident Response Assistance
Art.33(1)Art.34(1)Art.34(2)
IR-09 Information Spillage Response
Art.33(2)Art.33(5)

MA Maintenance

Control Name EU GDPR References
MA-01 Policy and Procedures
Art.32(1)(b)Rec.78
MA-02 Controlled Maintenance
Art.32(1)(b)Art.32(1)(d)
MA-03 Maintenance Tools
Art.32(1)(b)
MA-04 Nonlocal Maintenance
Art.32(1)(a)Art.32(1)(b)
MA-05 Maintenance Personnel
Art.28(3)(b)Art.32(4)
MA-06 Timely Maintenance
Art.32(1)(d)

MP Media Protection

Control Name EU GDPR References
MP-01 Policy and Procedures
Art.5(1)(f)Art.32(1)(a)Rec.78
MP-02 Media Access
Art.5(1)(f)Art.32(1)(b)
MP-03 Media Marking
Art.5(1)(f)Art.9(1)
MP-04 Media Storage
Art.5(1)(f)Art.32(1)(a)
MP-05 Media Transport
Art.5(1)(f)Art.32(1)(a)Art.44
MP-06 Media Sanitization
Art.5(1)(f)Art.17(1)Art.32(1)(a)

PE Physical and Environmental Protection

Control Name EU GDPR References
PE-01 Policy and Procedures
Art.32(1)(b)Rec.78
PE-02 Physical Access Authorizations
Art.32(1)(b)
PE-03 Physical Access Control
Art.32(1)(b)
PE-04 Access Control for Transmission
Art.32(1)(b)
PE-05 Access Control for Output Devices
Art.32(1)(b)
PE-06 Monitoring Physical Access
Art.32(1)(b)Art.32(1)(d)
PE-08 Visitor Access Records
Art.32(1)(b)
PE-16 Delivery and Removal
Art.32(1)(b)
PE-17 Alternate Work Site
Art.32(1)(b)

PL Planning

Control Name EU GDPR References
PL-01 Policy and Procedures
Art.24(1)Art.25(1)
PL-02 System Security and Privacy Plans
Art.25(1)Art.35(1)Art.35(7)
PL-03 System Security Plan Update
Art.25(1)
PL-04 Rules of Behavior
Art.29Art.39(1)(b)
PL-05 Privacy Impact Assessment
Art.35(1)Art.35(7)Art.36(1)
PL-06 Security-related Activity Planning
Art.25(1)Art.35(1)
PL-09 Central Management
Art.24(1)Art.24(2)
PL-10 Baseline Selection
Art.24(1)

PS Personnel Security

Control Name EU GDPR References
PS-01 Policy and Procedures
Art.32(4)Art.39(1)(b)Rec.78
PS-02 Position Risk Designation
Art.32(4)
PS-03 Personnel Screening
Art.28(3)(b)Art.32(4)
PS-04 Personnel Termination
Art.29Art.32(1)(b)
PS-05 Personnel Transfer
Art.29Art.32(1)(b)
PS-06 Access Agreements
Art.29Art.32(4)
PS-07 External Personnel Security
Art.28(1)Art.28(3)(b)Art.32(4)
PS-08 Personnel Sanctions
Art.32(4)
PS-09 Position Descriptions
Art.29Art.32(4)Art.37(1)Art.39(1)

PT Personally Identifiable Information Processing and Transparency

Control Name EU GDPR References
PT-01 Policy and Procedures
Art.5(1)(a)Art.5(1)(b)Art.5(2)Art.6(1)Art.9(1)Art.12(1)Art.13(1)Art.14(1)
PT-02 Authority to Process Personally Identifiable Information
Art.5(1)(a)Art.6(1)Art.12(1)Art.12(7)Art.13(1)Art.13(2)Art.14(1)Art.14(2)
PT-03 Personally Identifiable Information Processing Purposes
Art.5(1)(b)Art.6(4)Art.9(1)Art.9(2)
PT-04 Consent
Art.5(1)(a)Art.6(1)(a)Art.7(1)Art.7(2)Art.7(3)Art.8(1)
PT-05 Privacy Notice
Art.5(1)(a)Art.5(1)(b)Art.12(1)Art.13(1)Art.14(1)
PT-06 System of Records Notice
Art.25(1)Art.25(2)Art.35(1)Art.35(7)
PT-07 Specific Categories of Personally Identifiable Information
Art.5(1)(b)Art.5(1)(c)Art.5(1)(e)Art.6(4)Art.9(1)
PT-08 Computer Matching Requirements
Art.22(1)Art.22(2)Art.22(3)Art.22(4)

RA Risk Assessment

Control Name EU GDPR References
RA-01 Policy and Procedures
Art.24(1)Art.32(1)Art.35(1)
RA-02 Security Categorization
Art.30(1)Art.35(7)(a)
RA-03 Risk Assessment
Art.32(1)Art.35(1)Art.35(7)(c)
RA-04 Risk Assessment Update
Art.32(1)(d)Art.35(11)
RA-05 Vulnerability Monitoring and Scanning
Art.32(1)(d)
RA-07 Risk Response
Art.32(1)Art.32(2)
RA-08 Privacy Impact Assessments
Art.35(1)Art.35(3)Art.35(7)Art.35(7)(c)

SA System and Services Acquisition

Control Name EU GDPR References
SA-01 Policy and Procedures
Art.25(1)Rec.78
SA-02 Allocation of Resources
Art.25(1)Art.32(1)
SA-03 System Development Life Cycle
Art.25(1)Art.28(1)
SA-04 Acquisition Process
Art.28(1)Art.28(3)Art.28(3)(a)
SA-05 System Documentation
Art.30(1)
SA-06 Software Usage Restrictions
Art.25(1)
SA-07 User-installed Software
Art.25(1)
SA-08 Security and Privacy Engineering Principles
Art.25(1)Art.25(2)Rec.78
SA-09 External System Services
Art.28(1)Art.28(3)Art.44Art.46(1)Art.46(2)
SA-10 Developer Configuration Management
Art.25(1)Art.32(1)(d)
SA-11 Developer Testing and Evaluation
Art.25(1)Art.32(1)(d)

SC System and Communications Protection

Control Name EU GDPR References
SC-01 Policy and Procedures
Art.5(1)(f)Art.32(1)(a)Art.32(1)(b)
SC-02 Separation of System and User Functionality
Art.5(1)(f)Art.32(1)(b)
SC-03 Security Function Isolation
Art.32(1)(a)Art.32(1)(b)
SC-04 Information in Shared System Resources
Art.5(1)(f)Art.32(1)(a)
SC-05 Denial-of-service Protection
Art.32(1)(b)
SC-06 Resource Availability
Art.32(1)(b)
SC-07 Boundary Protection
Art.5(1)(f)Art.32(1)(a)Art.32(1)(b)
SC-08 Transmission Confidentiality and Integrity
Art.5(1)(f)Art.32(1)(a)Rec.83
SC-09 Transmission Confidentiality
Art.32(1)(a)Rec.83
SC-10 Network Disconnect
Art.32(1)(b)
SC-11 Trusted Path
Art.32(1)(a)
SC-12 Cryptographic Key Establishment and Management
Art.32(1)(a)Rec.83
SC-13 Cryptographic Protection
Art.5(1)(f)Art.32(1)(a)Rec.83
SC-14 Public Access Protections
Art.32(1)(a)
SC-15 Collaborative Computing Devices and Applications
Art.32(1)(b)
SC-16 Transmission of Security and Privacy Attributes
Art.32(1)(a)
SC-17 Public Key Infrastructure Certificates
Art.32(1)(a)Rec.83
SC-18 Mobile Code
Art.32(1)(b)
SC-19 Voice Over Internet Protocol
Art.32(1)(a)
SC-20 Secure Name/Address Resolution Service (Authoritative Source)
Art.32(1)(a)
SC-21 Secure Name/Address Resolution Service (Recursive or Caching Resolver)
Art.32(1)(a)
SC-22 Architecture and Provisioning for Name/Address Resolution Service
Art.32(1)(a)
SC-23 Session Authenticity
Art.32(1)(a)Art.32(1)(b)
SC-24 Fail in Known State
Art.32(1)(b)
SC-28 Protection of Information at Rest
Art.5(1)(f)Art.32(1)(a)Rec.83

SI System and Information Integrity

Control Name EU GDPR References
SI-01 Policy and Procedures
Art.5(1)(d)Art.5(1)(f)Art.32(1)(b)
SI-02 Flaw Remediation
Art.32(1)(b)Art.32(1)(d)
SI-03 Malicious Code Protection
Art.32(1)(b)
SI-04 System Monitoring
Art.32(1)(b)Art.32(1)(d)
SI-05 Security Alerts, Advisories, and Directives
Art.32(1)(d)
SI-06 Security and Privacy Function Verification
Art.5(1)(d)Art.32(1)(d)
SI-07 Software, Firmware, and Information Integrity
Art.5(1)(d)Art.5(1)(f)Art.32(1)(b)
SI-08 Spam Protection
Art.32(1)(b)
SI-09 Information Input Restrictions
Art.5(1)(f)Art.25(2)
SI-10 Information Input Validation
Art.5(1)(d)
SI-11 Error Handling
Art.32(1)(b)
SI-12 Information Management and Retention
Art.5(1)(e)Art.5(1)(f)Art.17(1)Art.32(1)(a)
SI-18 Personally Identifiable Information Quality Operations
Art.5(1)(d)Art.16

SR Supply Chain Risk Management

Control Name EU GDPR References
SR-01 Policy and Procedures
Art.28(1)Art.28(3)Art.28(4)
SR-02 Supply Chain Risk Management Plan
Art.28(1)Art.28(3)(c)Art.28(3)(h)
SR-03 Supply Chain Controls and Processes
Art.28(1)Art.28(2)Art.28(4)
SR-04 Provenance
Art.28(3)(a)Art.28(3)(h)
SR-05 Acquisition Strategies, Tools, and Methods
Art.28(3)(a)Art.28(3)(h)
SR-06 Supplier Assessments and Reviews
Art.28(3)(h)
SR-07 Supply Chain Operations Security
Art.28(3)(a)Art.28(3)(h)
SR-08 Notification Agreements
Art.28(3)(f)Art.33(2)
SR-09 Tamper Resistance and Detection
Art.28(1)Art.28(4)
SR-10 Inspection of Systems or Components
Art.28(3)(h)
SR-11 Component Authenticity
Art.28(3)(h)Art.30(2)(d)
SR-12 Component Disposal
Art.17(1)Art.28(1)Art.28(3)(g)