← Frameworks / POPIA / Control Mappings

Protection of Personal Information Act (Act 4 of 2013)

South Africa's comprehensive data protection law, closely modelled on EU GDPR principles. Establishes 8 conditions for lawful processing: accountability, processing limitation, purpose specification, further processing limitation, information quality, openness, security safeguards, and data subject participation. Covers responsible party obligations, information officers, data subject rights, transborder data flows, enforcement by the Information Regulator, and criminal offences. Mandatory for all public and private bodies processing personal information in South Africa.

AC Access Control

Control Name POPIA References
AC-01 Policy and Procedures
s19
AC-02 Account Management
s19
AC-03 Access Enforcement
s19
AC-04 Information Flow Enforcement
s19s72
AC-05 Separation of Duties
s19
AC-06 Least Privilege
s10s19
AC-07 Unsuccessful Logon Attempts
s19
AC-08 System Use Notification
s18
AC-16 Security and Privacy Attributes
s26-27s28-33

AU Audit and Accountability

Control Name POPIA References
AU-01 Policy and Procedures
s8s17s19
AU-02 Event Logging
s8s17s19
AU-06 Audit Record Review, Analysis, and Reporting
s19s22s73-99
AU-09 Protection of Audit Information
s19
AU-11 Audit Record Retention
s14

CA Security Assessment and Authorization

Control Name POPIA References
CA-01 Policy and Procedures
s19
CA-02 Control Assessments
s19
CA-06 Authorization
s57-59
CA-07 Continuous Monitoring
s19

CM Configuration Management

Control Name POPIA References
CM-01 Policy and Procedures
s19
CM-02 Baseline Configuration
s19
CM-03 Configuration Change Control
s19
CM-06 Configuration Settings
s19
CM-07 Least Functionality
s19
CM-08 System Component Inventory
s17
CM-12 Information Location
s10s14s17
CM-13 Data Action Mapping
s8s13s15s17

CP Contingency Planning

Control Name POPIA References
CP-01 Policy and Procedures
s19
CP-02 Contingency Plan
s19
CP-09 System Backup
s19
CP-10 System Recovery and Reconstitution
s19

IA Identification and Authentication

Control Name POPIA References
IA-01 Policy and Procedures
s19
IA-02 Identification and Authentication (Organizational Users)
s19
IA-04 Identifier Management
s19
IA-05 Authenticator Management
s19

IR Incident Response

Control Name POPIA References
IR-01 Policy and Procedures
s19s22
IR-02 Incident Response Training
s22
IR-04 Incident Handling
s19s22
IR-05 Incident Monitoring
s22
IR-06 Incident Reporting
s22s73-99
IR-07 Incident Response Assistance
s22
IR-08 Incident Response Plan
s22
IR-09 Information Spillage Response
s22

MA Maintenance

Control Name POPIA References
MA-01 Policy and Procedures
s19
MA-02 Controlled Maintenance
s19

MP Media Protection

Control Name POPIA References
MP-01 Policy and Procedures
s19
MP-02 Media Access
s19
MP-04 Media Storage
s19
MP-06 Media Sanitization
s14s19

PE Physical and Environmental Protection

Control Name POPIA References
PE-01 Policy and Procedures
s19
PE-02 Physical Access Authorizations
s19
PE-03 Physical Access Control
s19

PL Planning

Control Name POPIA References
PL-01 Policy and Procedures
s8s19
PL-02 System Security and Privacy Plans
s17s19

PM Program Management

Control Name POPIA References
PM-01 Information Security Program Plan
s8s19
PM-02 Information Security Program Leadership Role
s8s55
PM-03 Information Security and Privacy Resources
s8
PM-09 Risk Management Strategy
s8s19

PS Personnel Security

Control Name POPIA References
PS-01 Policy and Procedures
s19
PS-03 Personnel Screening
s19
PS-06 Access Agreements
s19
PS-07 External Personnel Security
s20
PS-09 Position Descriptions
s55s56

PT Personally Identifiable Information Processing and Transparency

Control Name POPIA References
PT-01 Policy and Procedures
s5s8s9s13s26-27
PT-02 Authority to Process Personally Identifiable Information
s9s11s57-59
PT-03 Personally Identifiable Information Processing Purposes
s13s15s26-27
PT-04 Consent
s5s11s34-35s69
PT-05 Privacy Notice
s5s12s13s18s69s70
PT-06 System of Records Notice
s5s23-24s25
PT-07 Specific Categories of Personally Identifiable Information
s10s15s26-27s28-33s34-35
PT-08 Computer Matching Requirements
s71

RA Risk Assessment

Control Name POPIA References
RA-01 Policy and Procedures
s19
RA-02 Security Categorization
s17
RA-03 Risk Assessment
s19
RA-05 Vulnerability Monitoring and Scanning
s19
RA-07 Risk Response
s19

SA System and Services Acquisition

Control Name POPIA References
SA-04 Acquisition Process
s21
SA-09 External System Services
s20s21s72

SC System and Communications Protection

Control Name POPIA References
SC-01 Policy and Procedures
s19
SC-07 Boundary Protection
s19s72
SC-08 Transmission Confidentiality and Integrity
s19
SC-12 Cryptographic Key Establishment and Management
s19
SC-13 Cryptographic Protection
s19
SC-28 Protection of Information at Rest
s19

SI System and Information Integrity

Control Name POPIA References
SI-01 Policy and Procedures
s16s19
SI-02 Flaw Remediation
s19
SI-03 Malicious Code Protection
s19
SI-04 System Monitoring
s19
SI-06 Security and Privacy Function Verification
s16
SI-07 Software, Firmware, and Information Integrity
s16s19
SI-10 Information Input Validation
s16
SI-12 Information Management and Retention
s14
SI-18 Personally Identifiable Information Quality Operations
s16s23-24

SR Supply Chain Risk Management

Control Name POPIA References
SR-01 Policy and Procedures
s20s21
SR-02 Supply Chain Risk Management Plan
s20s21
SR-03 Supply Chain Controls and Processes
s20s21
SR-05 Acquisition Strategies, Tools, and Methods
s21