Skip to content

    HIPAA (Security, Privacy and Breach Notification Rules) to NIST SP 800-53 Rev 5 control mapping

    HIPAA (Security, Privacy and Breach Notification Rules) maps to 165 NIST SP 800-53 controls in the source dataset. Every one is listed below, with the HIPAA (Security, Privacy and Breach Notification Rules) controls that map to it.

    Shared NIST 800-53 controls
    165
    HIPAA (Security, Privacy and Breach Notification Rules) controls involved
    423
    NIST 800-53 families touched
    20

    How this pairing is derived

    NIST SP 800-53 Rev 5 is the pivot this whole dataset is built on: every framework in it is mapped to NIST SP 800-53, which is what makes the other pairings on this site derivable at all. This page is the one case where nothing is derived. It lists the authored HIPAA (Security, Privacy and Breach Notification Rules) to NIST SP 800-53 mapping itself, one row per NIST control, so the relationship on each row is the mapping the source states rather than an intersection inferred from two of them.

    Shared controls in full

    NIST SP 800-53 Rev 5 controls that HIPAA (Security, Privacy and Breach Notification Rules) maps to, with the HIPAA (Security, Privacy and Breach Notification Rules) controls that map to each one.
    NIST 800-53 controlFamilyHIPAA (Security, Privacy and Breach Notification Rules) controls
    AC-1Policy and ProceduresACAccess Control164.308(a)(1)(i), 164.308(a)(3)(i), 164.308(a)(4)(i), 164.308(a)(4)(ii)(A), 164.308(a)(4)(ii)(B), 164.308(a)(6)(i), 164.308(a)(7)(i), 164.310(a)(1), 164.310(a)(2)(ii), 164.310(a)(2)(iii), 164.310(a)(2)(iv), 164.310(b), 164.310(d)(1), 164.310(d)(2)(i), 164.312(a)(1), 164.312(c)(1), 164.316(a), 164.316(b)(1), 164.316(b)(2)(iii), 164.530(c)(2)(ii), 164.530(i)(2)(i), 164.530(i)(2)(ii), 164.530(i)(2)(iii), 164.530(i)(3), 164.530(j)(1)(i)
    AC-2Account ManagementACAccess Control164.308(a)(3)(ii)(C), 164.312(a)(2)(ii)
    AC-2(2)Automated Temporary and Emergency Account ManagementACAccess Control164.312(a)(2)(ii)
    AC-2(7)Privileged User AccountsACAccess Control164.308(a)(3)(i), 164.308(a)(3)(ii)(A), 164.308(a)(4)(ii)(C), 164.312(a)(1), 164.514(d)(2)(i)(A), 164.514(d)(2)(i)(B), 164.514(d)(2)(ii), 164.530(c)(2)(ii)
    AC-2(12)Account Monitoring for Atypical UsageACAccess Control164.312(b), 164.312(c)(2)
    AC-3(11)Restrict Access to Specific Information TypesACAccess Control164.308(a)(3)(i), 164.312(c)(2)
    AC-3(14)Individual AccessACAccess Control164.502(a)(2)(i), 164.502(a)(2)(ii), 164.514(h)(1)(i), 164.514(h)(1)(ii), 164.524(a)(1), 164.524(a)(1)(i), 164.524(a)(1)(ii), 164.524(a)(1)(iii), 164.524(a)(1)(iii)(A), 164.524(a)(1)(iii)(B), 164.524(a)(2), 164.524(a)(2)(i), 164.524(a)(2)(ii), 164.524(a)(2)(iii), 164.524(a)(2)(iv), 164.524(a)(2)(v), 164.524(a)(3), 164.524(a)(3)(i), 164.524(a)(3)(ii), 164.524(a)(3)(iii), 164.524(a)(4), 164.524(b)(1), 164.524(b)(2)(i), 164.524(b)(2)(i)(A), 164.524(b)(2)(i)(B), 164.524(b)(2)(ii), 164.524(b)(2)(ii)(A), 164.524(b)(2)(ii)(B), 164.524(c), 164.524(c)(1), 164.524(c)(3)(i), 164.524(c)(3)(ii), 164.524(c)(4), 164.524(c)(4)(i), 164.524(c)(4)(ii), 164.524(c)(4)(iii), 164.524(c)(4)(iv), 164.524(d), 164.524(d)(1), 164.524(d)(2)
    AC-6Least PrivilegeACAccess Control164.308(a)(3)(i), 164.312(a)(1)
    AC-6(7)Review of User PrivilegesACAccess Control164.308(a)(3)(ii)(B)
    AC-12Session TerminationACAccess Control164.312(a)(2)(iii)
    AC-20(2)Portable Storage Devices — Restricted UseACAccess Control164.310(d)(1)
    AC-20(5)Portable Storage Devices — Prohibited UseACAccess Control164.310(d)(1)
    AC-21Information SharingACAccess Control164.506(c)(1), 164.506(c)(2), 164.506(c)(3), 164.506(c)(4), 164.508(a)(1), 164.508(a)(4)(i)
    AC-23Data Mining ProtectionACAccess Control164.502(c), 164.502(d)(1), 164.504(g)(2), 164.506(a), 164.506(c)(1), 164.506(c)(5), 164.508(a)(1), 164.508(a)(2)(i)(C), 164.510(a)(1)(i)(A), 164.510(a)(1)(i)(B), 164.510(a)(1)(i)(C), 164.510(a)(1)(i)(D), 164.510(a)(1)(ii)(A), 164.510(a)(1)(ii)(B), 164.510(b)(4), 164.512, 164.512(i)(1), 164.512(j)(1), 164.512(j)(1)(i)(A), 164.512(j)(1)(i)(B), 164.512(j)(1)(ii), 164.512(j)(1)(ii)(A), 164.512(j)(1)(ii)(B), 164.512(j)(2)(i), 164.512(j)(2)(ii), 164.512(j)(3), 164.512(j)(4), 164.512(k)(1)(i), 164.512(k)(1)(i)(A), 164.512(k)(1)(i)(B), 164.512(k)(1)(ii), 164.512(k)(1)(iii), 164.512(k)(1)(iv), 164.512(k)(2), 164.512(k)(3), 164.512(k)(4), 164.512(k)(4)(i), 164.512(k)(4)(ii), 164.512(k)(4)(iii), 164.512(k)(5)(i), 164.512(k)(5)(i)(A), 164.512(k)(5)(i)(B), 164.512(k)(5)(i)(C), 164.512(k)(5)(i)(D), 164.512(k)(5)(i)(E), 164.512(k)(5)(i)(F), 164.512(k)(5)(ii), 164.512(k)(5)(iii), 164.512(k)(6)(i), 164.512(k)(6)(ii), 164.512(k)(6)(ii)(1), 164.514(f)(2)(i), 164.514(g), 164.530(i)(4)(ii), 164.530(i)(4)(ii)(B), 164.532(a), 164.532(b), 164.532(c)
    AC-24Access Control DecisionsACAccess Control164.308(a)(3)(ii)(A)
    AT-1Policy and ProceduresATAwareness and Training164.308(a)(1)(i), 164.308(a)(3)(i), 164.308(a)(4)(i), 164.308(a)(4)(ii)(A), 164.308(a)(5)(i), 164.308(a)(6)(i), 164.308(a)(7)(i), 164.310(a)(1), 164.310(a)(2)(ii), 164.310(a)(2)(iv), 164.310(b), 164.310(d)(1), 164.310(d)(2)(i), 164.312(a)(1), 164.312(c)(1), 164.316(a), 164.316(b)(1), 164.316(b)(2)(iii), 164.530(i)(2)(i), 164.530(i)(2)(ii), 164.530(i)(2)(iii), 164.530(i)(3), 164.530(j)(1)(i)
    AT-2Literacy Training and AwarenessATAwareness and Training164.308(a)(5)(i), 164.530(b)(2)(i), 164.530(b)(2)(i)(A), 164.530(b)(2)(i)(B), 164.530(b)(2)(i)(C), 164.530(b)(2)(ii)
    AT-2(4)Suspicious Communications and Anomalous System BehaviorATAwareness and Training164.308(a)(5)(ii)(B)
    AT-2(5)Advanced Persistent ThreatATAwareness and Training164.308(a)(5)(ii)(B)
    AT-2(6)Cyber Threat EnvironmentATAwareness and Training164.308(a)(5)(ii)(A)
    AT-3Role-based TrainingATAwareness and Training164.308(a)(5)(ii)(C), 164.308(a)(5)(ii)(D), 164.530(b)(1)
    AT-3(2)Physical Security ControlsATAwareness and Training164.308(a)(5)(ii)(C), 164.308(a)(5)(ii)(D), 164.530(b)(1)
    AU-1Policy and ProceduresAUAudit and Accountability164.308(a)(1)(i), 164.308(a)(1)(ii)(D), 164.308(a)(3)(i), 164.308(a)(4)(i), 164.308(a)(4)(ii)(A), 164.308(a)(6)(i), 164.308(a)(7)(i), 164.310(a)(1), 164.310(a)(2)(ii), 164.310(a)(2)(iv), 164.310(b), 164.310(d)(1), 164.310(d)(2)(i), 164.312(a)(1), 164.312(b), 164.312(c)(1), 164.316(a), 164.316(b)(1), 164.316(b)(2)(iii), 164.530(i)(2)(i), 164.530(i)(2)(ii), 164.530(i)(2)(iii), 164.530(i)(3), 164.530(j)(1)(i)
    AU-2Event LoggingAUAudit and Accountability164.308(a)(1)(ii)(D), 164.312(b)
    AU-3Content of Audit RecordsAUAudit and Accountability164.312(b)
    CA-1Policy and ProceduresCAAssessment, Authorization, and Monitoring164.308(a)(1)(i), 164.308(a)(3)(i), 164.308(a)(4)(i), 164.308(a)(4)(ii)(A), 164.308(a)(6)(i), 164.308(a)(7)(i), 164.310(a)(1), 164.310(a)(2)(ii), 164.310(a)(2)(iv), 164.310(b), 164.310(d)(1), 164.310(d)(2)(i), 164.312(a)(1), 164.312(c)(1), 164.316(a), 164.316(b)(1), 164.316(b)(2)(iii), 164.530(i)(2)(i), 164.530(i)(2)(ii), 164.530(i)(2)(iii), 164.530(i)(3), 164.530(j)(1)(i)
    CA-2Control AssessmentsCAAssessment, Authorization, and Monitoring164.306(d)(3)(i), 164.306(e), 164.308(a)(8), 164.316(b)(1)
    CA-7Continuous MonitoringCAAssessment, Authorization, and Monitoring164.306(d)(3)(i), 164.316(b)(2)(iii)
    CA-7(1)Independent AssessmentCAAssessment, Authorization, and Monitoring164.306(d)(3)(i), 164.316(b)(2)(iii)
    CM-1Policy and ProceduresCMConfiguration Management164.308(a)(1)(i), 164.308(a)(3)(i), 164.308(a)(4)(i), 164.308(a)(4)(ii)(A), 164.308(a)(6)(i), 164.308(a)(7)(i), 164.310(a)(1), 164.310(a)(2)(ii), 164.310(a)(2)(iv), 164.310(b), 164.310(d)(1), 164.310(d)(2)(i), 164.312(a)(1), 164.312(c)(1), 164.316(a), 164.316(b)(1), 164.316(b)(2)(iii), 164.530(i)(2)(i), 164.530(i)(2)(ii), 164.530(i)(2)(iii), 164.530(i)(3), 164.530(j)(1)(i)
    CM-2Baseline ConfigurationCMConfiguration Management164.312(a)(2)(iii), 164.312(e)(1), 164.312(e)(2)(i), 164.312(e)(2)(ii)
    CM-3Configuration Change ControlCMConfiguration Management164.308(a)(1)(i)
    CM-6Configuration SettingsCMConfiguration Management164.312(a)(2)(iii), 164.312(e)(1), 164.312(e)(2)(i), 164.312(e)(2)(ii)
    CM-8System Component InventoryCMConfiguration Management164.310(d)(2)(iii)
    CM-8(1)Updates During Installation and RemovalCMConfiguration Management164.310(d)(2)(iii)
    CM-8(2)Automated MaintenanceCMConfiguration Management164.310(d)(2)(iii)
    CM-8(4)Accountability InformationCMConfiguration Management164.310(d)(2)(iii)
    CM-8(7)Centralized RepositoryCMConfiguration Management164.310(d)(2)(iii)
    CM-9Configuration Management PlanCMConfiguration Management164.308(a)(1)(i)
    CP-1Policy and ProceduresCPContingency Planning164.308(a)(1)(i), 164.308(a)(3)(i), 164.308(a)(4)(i), 164.308(a)(4)(ii)(A), 164.308(a)(6)(i), 164.308(a)(7)(i), 164.308(a)(7)(ii)(C), 164.310(a)(1), 164.310(a)(2)(ii), 164.310(a)(2)(iv), 164.310(b), 164.310(d)(1), 164.310(d)(2)(i), 164.312(a)(1), 164.312(c)(1), 164.316(a), 164.316(b)(1), 164.316(b)(2)(iii), 164.530(i)(2)(i), 164.530(i)(2)(ii), 164.530(i)(2)(iii), 164.530(i)(3), 164.530(j)(1)(i)
    CP-2Contingency PlanCPContingency Planning164.308(a)(7)(i), 164.308(a)(7)(ii)(C)
    CP-2(5)Continue Mission and Business FunctionsCPContingency Planning164.308(a)(7)(ii)(C)
    CP-2(8)Identify Critical AssetsCPContingency Planning164.308(a)(7)(ii)(E)
    CP-4Contingency Plan TestingCPContingency Planning164.308(a)(7)(ii)(D)
    CP-7(2)AccessibilityCPContingency Planning164.310(a)(2)(i)
    CP-9System BackupCPContingency Planning164.308(a)(7)(ii)(A), 164.310(d)(2)(iv)
    CP-10System Recovery and ReconstitutionCPContingency Planning164.308(a)(7)(i), 164.308(a)(7)(ii)(B), 164.308(a)(7)(ii)(C)
    IA-1Policy and ProceduresIAIdentification and Authentication164.308(a)(1)(i), 164.308(a)(3)(i), 164.308(a)(4)(i), 164.308(a)(4)(ii)(A), 164.308(a)(4)(ii)(B), 164.308(a)(6)(i), 164.308(a)(7)(i), 164.310(a)(1), 164.310(a)(2)(ii), 164.310(a)(2)(iii), 164.310(a)(2)(iv), 164.310(b), 164.310(d)(1), 164.310(d)(2)(i), 164.312(a)(1), 164.312(c)(1), 164.316(a), 164.316(b)(1), 164.316(b)(2)(iii), 164.530(c)(2)(ii), 164.530(i)(2)(i), 164.530(i)(2)(ii), 164.530(i)(2)(iii), 164.530(i)(3), 164.530(j)(1)(i)
    IA-2Identification and Authentication (Organizational Users)IAIdentification and Authentication164.312(a)(2)(i)
    IA-4Identifier ManagementIAIdentification and Authentication164.312(a)(2)(i)
    IA-12Identity ProofingIAIdentification and Authentication164.312(d)
    IA-12(1)Supervisor AuthorizationIAIdentification and Authentication164.308(a)(3)(ii)(A)
    IA-12(2)Identity EvidenceIAIdentification and Authentication164.312(d)
    IA-12(3)Identity Evidence Validation and VerificationIAIdentification and Authentication164.312(d)
    IA-12(4)In-person Validation and VerificationIAIdentification and Authentication164.308(a)(3)(ii)(C)
    IR-1Policy and ProceduresIRIncident Response164.308(a)(1)(i), 164.308(a)(3)(i), 164.308(a)(4)(i), 164.308(a)(4)(ii)(A), 164.308(a)(6)(i), 164.308(a)(7)(i), 164.310(a)(1), 164.310(a)(2)(ii), 164.310(a)(2)(iv), 164.310(b), 164.310(d)(1), 164.310(d)(2)(i), 164.312(a)(1), 164.312(c)(1), 164.316(a), 164.316(b)(1), 164.316(b)(2)(iii), 164.530(i)(2)(i), 164.530(i)(2)(ii), 164.530(i)(2)(iii), 164.530(i)(3), 164.530(j)(1)(i)
    IR-4Incident HandlingIRIncident Response164.308(a)(6)(ii), 164.412, 164.412(a), 164.412(b), 164.530(f)
    IR-4(3)Continuity of OperationsIRIncident Response164.308(a)(7)(i), 164.308(a)(7)(ii)(C)
    IR-4(13)Behavior AnalysisIRIncident Response164.312(b), 164.312(c)(2)
    IR-5Incident MonitoringIRIncident Response164.308(a)(1)(ii)(D)
    IR-6Incident ReportingIRIncident Response164.404(b), 164.408(a), 164.408(b), 164.408(c)
    IR-8(1)BreachesIRIncident Response164.404(a)(1), 164.404(a)(2), 164.404(c)(1)(A), 164.404(c)(1)(B), 164.404(c)(1)(C), 164.404(c)(1)(D), 164.404(c)(1)(E), 164.404(c)(2), 164.404(d)(1)(i), 164.404(d)(1)(ii), 164.404(d)(2), 164.404(d)(2)(i), 164.404(d)(2)(ii)(A), 164.404(d)(2)(ii)(B), 164.404(d)(3), 164.406(a), 164.406(b), 164.406(c), 164.410(c)(1)
    MA-1Policy and ProceduresMAMaintenance164.308(a)(1)(i), 164.308(a)(3)(i), 164.308(a)(4)(i), 164.308(a)(4)(ii)(A), 164.308(a)(6)(i), 164.308(a)(7)(i), 164.310(a)(1), 164.310(a)(2)(ii), 164.310(a)(2)(iv), 164.310(b), 164.310(d)(1), 164.310(d)(2)(i), 164.312(a)(1), 164.312(c)(1), 164.316(a), 164.316(b)(1), 164.316(b)(2)(iii), 164.530(i)(2)(i), 164.530(i)(2)(ii), 164.530(i)(2)(iii), 164.530(i)(3), 164.530(j)(1)(i)
    MA-2Controlled MaintenanceMAMaintenance164.310(a)(2)(iv)
    MA-3(3)Prevent Unauthorized RemovalMAMaintenance164.310(d)(1)
    PE-1Policy and ProceduresPEPhysical and Environmental Protection164.308(a)(1)(i), 164.308(a)(3)(i), 164.308(a)(4)(i), 164.308(a)(4)(ii)(A), 164.308(a)(6)(i), 164.308(a)(7)(i), 164.310(a)(1), 164.310(a)(2)(ii), 164.310(a)(2)(iv), 164.310(b), 164.310(d)(1), 164.310(d)(2)(i), 164.312(a)(1), 164.312(c)(1), 164.316(a), 164.316(b)(1), 164.316(b)(2)(iii), 164.530(i)(2)(i), 164.530(i)(2)(ii), 164.530(i)(2)(iii), 164.530(i)(3), 164.530(j)(1)(i)
    PE-2Physical Access AuthorizationsPEPhysical and Environmental Protection164.310(a)(2)(i), 164.310(a)(2)(iii)
    PE-2(1)Access by Position or RolePEPhysical and Environmental Protection164.310(a)(2)(i)
    PE-3Physical Access ControlPEPhysical and Environmental Protection164.310(a)(2)(ii), 164.310(a)(2)(iii), 164.310(c)
    PE-3(1)System AccessPEPhysical and Environmental Protection164.310(b), 164.310(c)
    PE-3(2)Facility and SystemsPEPhysical and Environmental Protection164.310(a)(2)(ii), 164.310(a)(2)(iii), 164.310(c)
    PE-3(3)Continuous GuardsPEPhysical and Environmental Protection164.310(a)(2)(ii), 164.310(a)(2)(iii), 164.310(c)
    PE-23Facility LocationPEPhysical and Environmental Protection164.310(a)(1), 164.310(a)(2)(ii), 164.310(a)(2)(iv)
    PL-1Policy and ProceduresPLPlanning164.306(c), 164.306(d)(1), 164.306(d)(2), 164.308(a)(1)(i), 164.308(a)(3)(i), 164.308(a)(4)(i), 164.308(a)(4)(ii)(A), 164.308(a)(6)(i), 164.308(a)(7)(i), 164.310(a)(1), 164.310(a)(2)(ii), 164.310(a)(2)(iv), 164.310(b), 164.310(d)(1), 164.310(d)(2)(i), 164.312(a)(1), 164.312(c)(1), 164.314(a)(1), 164.314(a)(2)(ii), 164.316(a), 164.316(b)(1), 164.316(b)(2)(iii), 164.504(g)(1), 164.530(i)(1), 164.530(i)(2)(i), 164.530(i)(2)(ii), 164.530(i)(2)(iii), 164.530(i)(3), 164.530(j)(1)(i)
    PL-4Rules of BehaviorPLPlanning164.310(b)
    PL-8Security and Privacy ArchitecturesPLPlanning164.306(b)(1), 164.306(b)(2)(ii)
    PL-8(1)Defense in DepthPLPlanning164.306(b)(1)
    PL-9Central ManagementPLPlanning164.308(a)(2)
    PL-10Baseline SelectionPLPlanning164.312(a)(2)(iii), 164.312(e)(1), 164.312(e)(2)(i), 164.312(e)(2)(ii)
    RA-1Policy and ProceduresRARisk Assessment164.306(a)(3), 164.306(b)(2)(iv), 164.308(a)(1)(i), 164.308(a)(3)(i), 164.308(a)(4)(i), 164.308(a)(4)(ii)(A), 164.308(a)(6)(i), 164.308(a)(7)(i), 164.310(a)(1), 164.310(a)(2)(ii), 164.310(a)(2)(iv), 164.310(b), 164.310(d)(1), 164.310(d)(2)(i), 164.312(a)(1), 164.312(c)(1), 164.316(a), 164.316(b)(1), 164.316(b)(2)(iii), 164.530(i)(2)(i), 164.530(i)(2)(ii), 164.530(i)(2)(iii), 164.530(i)(3), 164.530(j)(1)(i)
    RA-2Security CategorizationRARisk Assessment164.306(b)(2)(iv)
    RA-3Risk AssessmentRARisk Assessment164.306(b)(2)(iv), 164.306(d)(3)(i), 164.306(e), 164.308(a)(1)(ii)(A), 164.308(a)(8)
    RA-9Criticality AnalysisRARisk Assessment164.306(b)(2)(ii), 164.308(a)(7)(ii)(E)
    SA-1Policy and ProceduresSASystem and Services Acquisition164.308(a)(1)(i), 164.308(a)(3)(i), 164.308(a)(4)(i), 164.308(a)(4)(ii)(A), 164.308(a)(6)(i), 164.308(a)(7)(i), 164.310(a)(1), 164.310(a)(2)(ii), 164.310(a)(2)(iv), 164.310(b), 164.310(d)(1), 164.310(d)(2)(i), 164.312(a)(1), 164.312(c)(1), 164.316(a), 164.316(b)(1), 164.316(b)(2)(iii), 164.530(i)(2)(i), 164.530(i)(2)(ii), 164.530(i)(2)(iii), 164.530(i)(3), 164.530(j)(1)(i)
    SA-2Allocation of ResourcesSASystem and Services Acquisition164.306(b)(2)(iii)
    SA-4Acquisition ProcessSASystem and Services Acquisition164.308(b)(1), 164.312(d)
    SA-4(12)Data OwnershipSASystem and Services Acquisition164.310(d)(2)(iii)
    SA-8Security and Privacy Engineering PrinciplesSASystem and Services Acquisition164.306(b)(1), 164.312(a)(2)(iii), 164.312(e)(1), 164.312(e)(2)(i), 164.312(e)(2)(ii)
    SA-8(14)Least PrivilegeSASystem and Services Acquisition164.308(a)(3)(i), 164.312(a)(1)
    SA-8(32)Sufficient DocumentationSASystem and Services Acquisition164.310(b), 164.316(b)(2)(ii)
    SA-9External System ServicesSASystem and Services Acquisition164.308(b)(1)
    SA-9(3)Establish and Maintain Trust Relationship with ProvidersSASystem and Services Acquisition164.308(a)(7)(ii)(E), 164.308(b)(1), 164.504(e)(2)(iii)
    SA-15(5)Attack Surface ReductionSASystem and Services Acquisition164.306(b)(1), 164.312(a)(2)(iii), 164.312(e)(1), 164.312(e)(2)(i), 164.312(e)(2)(ii)
    SC-1Policy and ProceduresSCSystem and Communications Protection164.306(b)(1), 164.308(a)(1)(i), 164.308(a)(3)(i), 164.308(a)(4)(i), 164.308(a)(4)(ii)(A), 164.308(a)(6)(i), 164.308(a)(7)(i), 164.310(a)(1), 164.310(a)(2)(ii), 164.310(a)(2)(iv), 164.310(b), 164.310(d)(1), 164.310(d)(2)(i), 164.312(a)(1), 164.312(c)(1), 164.312(e)(1), 164.312(e)(2)(i), 164.316(a), 164.316(b)(1), 164.316(b)(2)(iii), 164.530(i)(2)(i), 164.530(i)(2)(ii), 164.530(i)(2)(iii), 164.530(i)(3), 164.530(j)(1)(i)
    SC-3(5)Layered StructuresSCSystem and Communications Protection164.306(b)(1)
    SC-7(18)Fail SecureSCSystem and Communications Protection164.306(b)(1)
    SC-8Transmission Confidentiality and IntegritySCSystem and Communications Protection164.312(e)(1), 164.312(e)(2)(i)
    SC-8(1)Cryptographic ProtectionSCSystem and Communications Protection164.312(a)(2)(iv), 164.312(e)(1), 164.312(e)(2)(ii)
    SC-8(2)Pre- and Post-transmission HandlingSCSystem and Communications Protection164.312(a)(2)(iv), 164.312(e)(2)(ii)
    SC-13Cryptographic ProtectionSCSystem and Communications Protection164.312(a)(2)(iv), 164.312(e)(2)(ii)
    SC-16(1)Integrity VerificationSCSystem and Communications Protection164.312(e)(2)(i)
    SC-28Protection of Information at RestSCSystem and Communications Protection164.310(c)
    SC-28(1)Cryptographic ProtectionSCSystem and Communications Protection164.312(e)(2)(i)
    SC-28(2)Offline StorageSCSystem and Communications Protection164.308(a)(7)(ii)(A), 164.310(d)(2)(iv)
    SI-1Policy and ProceduresSISystem and Information Integrity164.306(b)(1), 164.308(a)(1)(i), 164.308(a)(3)(i), 164.308(a)(4)(i), 164.308(a)(4)(ii)(A), 164.308(a)(6)(i), 164.308(a)(7)(i), 164.310(a)(1), 164.310(a)(2)(ii), 164.310(a)(2)(iv), 164.310(b), 164.310(d)(1), 164.310(d)(2)(i), 164.312(a)(1), 164.312(c)(1), 164.316(a), 164.316(b)(1), 164.316(b)(2)(iii), 164.530(i)(2)(i), 164.530(i)(2)(ii), 164.530(i)(2)(iii), 164.530(i)(3), 164.530(j)(1)(i)
    SI-4System MonitoringSISystem and Information Integrity164.308(a)(1)(i), 164.308(a)(1)(ii)(D), 164.312(b)
    SI-4(5)System-generated AlertsSISystem and Information Integrity164.312(b)
    SI-4(11)Analyze Communications Traffic AnomaliesSISystem and Information Integrity164.312(b), 164.312(c)(2)
    SI-4(20)Privileged UsersSISystem and Information Integrity164.312(c)(2)
    SI-4(24)Indicators of CompromiseSISystem and Information Integrity164.312(c)(2)
    SI-7(6)Cryptographic ProtectionSISystem and Information Integrity164.312(a)(2)(iv), 164.312(e)(2)(ii)
    SI-12Information Management and RetentionSISystem and Information Integrity164.316(b)(2)(i), 164.530(j)(2)
    SI-12(1)Limit Personally Identifiable Information ElementsSISystem and Information Integrity164.502(b)(1), 164.508(a)(2)(i)(B)
    SI-12(2)Minimize Personally Identifiable Information in Testing, Training, and ResearchSISystem and Information Integrity164.508(a)(2)(i)(B)
    SI-18(4)Individual RequestsSISystem and Information Integrity164.502(a)(2)(i), 164.502(a)(2)(ii), 164.514(h)(1)(i), 164.514(h)(1)(ii), 164.524(a)(1), 164.524(a)(1)(i), 164.524(a)(1)(ii), 164.524(a)(1)(iii), 164.524(a)(1)(iii)(A), 164.524(a)(1)(iii)(B), 164.524(a)(2), 164.524(a)(2)(i), 164.524(a)(2)(ii), 164.524(a)(2)(iii), 164.524(a)(2)(iv), 164.524(a)(2)(v), 164.524(a)(3), 164.524(a)(3)(i), 164.524(a)(3)(ii), 164.524(a)(3)(iii), 164.524(a)(4), 164.524(b)(1), 164.524(b)(2)(i), 164.524(b)(2)(i)(A), 164.524(b)(2)(i)(B), 164.524(b)(2)(ii), 164.524(b)(2)(ii)(A), 164.524(b)(2)(ii)(B), 164.524(c), 164.524(c)(1), 164.524(c)(3)(i), 164.524(c)(3)(ii), 164.524(c)(4), 164.524(c)(4)(i), 164.524(c)(4)(ii), 164.524(c)(4)(iii), 164.524(c)(4)(iv), 164.524(d), 164.524(d)(1), 164.524(d)(2), 164.526(a)(1), 164.526(a)(2), 164.526(a)(2)(i), 164.526(a)(2)(ii), 164.526(a)(2)(iii), 164.526(a)(2)(iv), 164.526(b)(1)
    SI-18(5)Notice of Correction or DeletionSISystem and Information Integrity164.526(a)(1), 164.526(a)(2), 164.526(a)(2)(i), 164.526(a)(2)(ii), 164.526(a)(2)(iii), 164.526(a)(2)(iv), 164.526(b)(1), 164.526(c), 164.526(c)(1), 164.526(c)(2), 164.526(c)(3), 164.526(c)(3)(i), 164.526(c)(3)(ii)
    MP-1Policy and ProceduresMPMedia Protection164.306(a)(3), 164.308(a)(1)(i), 164.308(a)(3)(i), 164.308(a)(4)(i), 164.308(a)(4)(ii)(A), 164.308(a)(6)(i), 164.308(a)(7)(i), 164.310(a)(1), 164.310(a)(2)(ii), 164.310(a)(2)(iv), 164.310(b), 164.310(d)(1), 164.310(d)(2)(i), 164.312(a)(1), 164.312(c)(1), 164.316(a), 164.316(b)(1), 164.316(b)(2)(iii), 164.514(d)(3)(i), 164.530(c)(2)(i), 164.530(i)(2)(i), 164.530(i)(2)(ii), 164.530(i)(2)(iii), 164.530(i)(3), 164.530(j)(1)(i)
    MP-2Media AccessMPMedia Protection164.310(b), 164.310(d)(1)
    MP-5Media TransportMPMedia Protection164.310(d)(1)
    MP-5(3)CustodiansMPMedia Protection164.310(d)(1)
    MP-6Media SanitizationMPMedia Protection164.310(d)(2)(ii)
    MP-6(3)Nondestructive TechniquesMPMedia Protection164.310(d)(2)(ii)
    MP-7Media UseMPMedia Protection164.316(b)(2)(i), 164.530(j)(2)
    PS-1Policy and ProceduresPSPersonnel Security164.308(a)(1)(i), 164.308(a)(3)(i), 164.308(a)(3)(ii)(A), 164.308(a)(4)(i), 164.308(a)(4)(ii)(A), 164.308(a)(6)(i), 164.308(a)(7)(i), 164.310(a)(1), 164.310(a)(2)(ii), 164.310(a)(2)(iv), 164.310(b), 164.310(d)(1), 164.310(d)(2)(i), 164.312(a)(1), 164.312(c)(1), 164.312(d), 164.316(a), 164.316(b)(1), 164.316(b)(2)(iii), 164.530(e)(2), 164.530(i)(2)(i), 164.530(i)(2)(ii), 164.530(i)(2)(iii), 164.530(i)(3), 164.530(j)(1)(i)
    PS-2Position Risk DesignationPSPersonnel Security164.308(a)(3)(ii)(B), 164.312(a)(1), 164.530(a)(2)
    PS-3Personnel ScreeningPSPersonnel Security164.312(d)
    PS-4Personnel TerminationPSPersonnel Security164.308(a)(3)(ii)(C)
    PS-5Personnel TransferPSPersonnel Security164.308(a)(3)(ii)(C)
    PS-6Access AgreementsPSPersonnel Security164.502(a)
    PS-6(2)Classified Information Requiring Special ProtectionPSPersonnel Security164.502(a)
    PS-8Personnel SanctionsPSPersonnel Security164.308(a)(1)(ii)(C), 164.530(e)(1)
    PS-9Position DescriptionsPSPersonnel Security164.308(a)(3)(ii)(B), 164.310(a)(2)(i), 164.312(a)(1), 164.530(a)(2)
    PM-1Information Security Program PlanPMProgram Management164.306(a)(1), 164.306(a)(2), 164.306(a)(3), 164.308(a)(1)(i), 164.308(a)(3)(i), 164.308(a)(4)(i), 164.308(a)(4)(ii)(A), 164.308(a)(6)(i), 164.308(a)(7)(i), 164.310(a)(1), 164.310(a)(2)(ii), 164.310(a)(2)(iv), 164.310(b), 164.310(d)(1), 164.310(d)(2)(i), 164.312(a)(1), 164.312(c)(1), 164.316(a), 164.316(b)(1), 164.316(b)(2)(iii), 164.530(c)(1), 164.530(i)(1), 164.530(i)(2)(i), 164.530(i)(2)(ii), 164.530(i)(2)(iii), 164.530(i)(3), 164.530(j)(1)(i)
    PM-2Information Security Program Leadership RolePMProgram Management164.308(a)(2)
    PM-5System InventoryPMProgram Management164.308(a)(7)(ii)(E), 164.310(d)(1), 164.310(d)(2)(i), 164.310(d)(2)(iii)
    PM-6Measures of PerformancePMProgram Management164.308(a)(2)
    PM-7Enterprise ArchitecturePMProgram Management164.306(b)(1), 164.306(b)(2)(ii)
    PM-8Critical Infrastructure PlanPMProgram Management164.306(c), 164.306(d)(1), 164.306(d)(2), 164.308(a)(7)(i), 164.308(a)(7)(ii)(C), 164.314(a)(1), 164.314(a)(2)(ii), 164.504(g)(1), 164.530(i)(1)
    PM-9Risk Management StrategyPMProgram Management164.306(a)(3), 164.306(b)(2)(iv)
    PM-11Mission and Business Process DefinitionPMProgram Management164.306(b)(2)(i)
    PM-13Security and Privacy WorkforcePMProgram Management164.308(a)(3)(ii)(B), 164.308(a)(5)(i), 164.310(a)(2)(i), 164.312(a)(1), 164.530(a)(2)
    PM-14Testing, Training, and MonitoringPMProgram Management164.306(d)(3)(i), 164.316(b)(2)(iii)
    PM-18Privacy Program PlanPMProgram Management164.502(a), 164.530(a)(1)(i), 164.530(i)(1), 164.530(i)(4)(i)(A), 164.530(i)(4)(i)(B), 164.530(i)(5), 164.530(i)(5)(i), 164.530(i)(5)(ii)
    PM-19Privacy Program Leadership RolePMProgram Management164.530(a)(1)(i)
    PM-20(1)Privacy Policies on Websites, Applications, and Digital ServicesPMProgram Management164.520(a)(1), 164.520(a)(2)(i), 164.520(a)(2)(i)(A), 164.520(a)(2)(i)(B), 164.520(a)(2)(ii), 164.520(a)(2)(ii)(A), 164.520(a)(2)(ii)(B), 164.520(a)(2)(iii), 164.520(b)(1), 164.520(b)(1)(i), 164.520(b)(1)(ii), 164.520(b)(1)(ii)(A), 164.520(b)(1)(ii)(B), 164.520(b)(1)(ii)(C), 164.520(b)(1)(ii)(D), 164.520(b)(1)(ii)(E), 164.520(b)(1)(iv), 164.520(b)(1)(iv)(A), 164.520(b)(1)(iv)(B), 164.520(b)(1)(iv)(C), 164.520(b)(1)(iv)(D), 164.520(b)(1)(iv)(E), 164.520(b)(1)(iv)(F), 164.520(b)(1)(v), 164.520(b)(1)(v)(A), 164.520(b)(1)(v)(B), 164.520(b)(1)(v)(C), 164.520(b)(1)(vi), 164.520(b)(1)(vii), 164.520(b)(1)(viii), 164.520(b)(2)(i), 164.520(b)(2)(ii), 164.520(b)(3), 164.520(c), 164.520(c)(1)(i), 164.520(c)(1)(i)(A), 164.520(c)(1)(i)(B), 164.520(c)(1)(ii), 164.520(c)(1)(iii), 164.520(c)(1)(iv), 164.520(c)(1)(v), 164.520(c)(1)(v)(A), 164.520(c)(1)(v)(B), 164.530(i)(4)(i)(C)
    PM-21Accounting of DisclosuresPMProgram Management164.528(a)(1), 164.528(a)(1)(i), 164.528(a)(1)(ii), 164.528(a)(1)(iii), 164.528(a)(1)(iv), 164.528(a)(1)(ix), 164.528(a)(1)(v), 164.528(a)(1)(vi), 164.528(a)(1)(vii), 164.528(a)(1)(viii), 164.528(b), 164.528(b)(1), 164.528(b)(2), 164.528(b)(2)(i), 164.528(b)(2)(ii), 164.528(b)(2)(iii), 164.528(b)(2)(iv), 164.528(b)(3), 164.528(b)(3)(i), 164.528(b)(3)(ii), 164.528(b)(3)(iii), 164.528(b)(4)(i), 164.528(b)(4)(i)(A), 164.528(b)(4)(i)(B), 164.528(b)(4)(i)(C), 164.528(b)(4)(i)(D), 164.528(b)(4)(i)(E), 164.528(b)(4)(i)(F), 164.528(b)(4)(ii), 164.528(c)(1), 164.528(c)(1)(i), 164.528(c)(1)(ii), 164.528(c)(1)(ii)(A), 164.528(c)(1)(ii)(B), 164.528(c)(2), 164.528(d), 164.528(d)(1), 164.528(d)(2), 164.528(d)(3)
    PM-22Personally Identifiable Information Quality ManagementPMProgram Management164.512(i)(1)(i)(B), 164.512(i)(1)(i)(B)(1), 164.512(i)(1)(i)(B)(2), 164.512(i)(1)(i)(B)(3)
    PM-23Data Governance BodyPMProgram Management164.512(i)(1)(i)(B), 164.512(i)(1)(i)(B)(1), 164.512(i)(1)(i)(B)(2), 164.512(i)(1)(i)(B)(3)
    PM-24Data Integrity BoardPMProgram Management164.512(i)(1)(i)(B), 164.512(i)(1)(i)(B)(1), 164.512(i)(1)(i)(B)(2), 164.512(i)(1)(i)(B)(3)
    PM-25Minimization of Personally Identifiable Information Used in Testing, Training, and ResearchPMProgram Management164.502(c), 164.502(d)(1), 164.504(g)(2), 164.506(a), 164.506(c)(1), 164.506(c)(5), 164.508(a)(1), 164.508(a)(2)(i)(B), 164.508(a)(2)(i)(C), 164.510(a)(1)(i)(A), 164.510(a)(1)(i)(B), 164.510(a)(1)(i)(C), 164.510(a)(1)(i)(D), 164.510(a)(1)(ii)(A), 164.510(a)(1)(ii)(B), 164.510(b)(4), 164.512, 164.512(i)(1), 164.512(j)(1), 164.512(j)(1)(i)(A), 164.512(j)(1)(i)(B), 164.512(j)(1)(ii), 164.512(j)(1)(ii)(A), 164.512(j)(1)(ii)(B), 164.512(j)(2)(i), 164.512(j)(2)(ii), 164.512(j)(3), 164.512(j)(4), 164.512(k)(1)(i), 164.512(k)(1)(i)(A), 164.512(k)(1)(i)(B), 164.512(k)(1)(ii), 164.512(k)(1)(iii), 164.512(k)(1)(iv), 164.512(k)(2), 164.512(k)(3), 164.512(k)(4), 164.512(k)(4)(i), 164.512(k)(4)(ii), 164.512(k)(4)(iii), 164.512(k)(5)(i), 164.512(k)(5)(i)(A), 164.512(k)(5)(i)(B), 164.512(k)(5)(i)(C), 164.512(k)(5)(i)(D), 164.512(k)(5)(i)(E), 164.512(k)(5)(i)(F), 164.512(k)(5)(ii), 164.512(k)(5)(iii), 164.512(k)(6)(i), 164.512(k)(6)(ii), 164.512(k)(6)(ii)(1), 164.514(f)(2)(i), 164.514(g), 164.530(i)(4)(ii), 164.530(i)(4)(ii)(B), 164.532(a), 164.532(b), 164.532(c)
    PM-26Complaint ManagementPMProgram Management164.524(d)(4), 164.526(b)(2)(i), 164.526(b)(2)(i)(A), 164.526(b)(2)(i)(B), 164.526(b)(2)(ii), 164.526(b)(2)(ii)(A), 164.526(b)(2)(ii)(B), 164.526(d), 164.526(d)(1), 164.526(d)(1)(i), 164.526(d)(1)(ii), 164.526(d)(1)(iii), 164.526(d)(1)(iv), 164.526(d)(2), 164.526(d)(3), 164.526(d)(4), 164.526(d)(5)(i), 164.526(d)(5)(ii), 164.526(d)(5)(iii), 164.526(e), 164.526(f), 164.530(d)(1), 164.530(d)(2)
    PM-28Risk FramingPMProgram Management164.306(b)(2)(iv)
    PM-29Risk Management Program Leadership RolesPMProgram Management164.306(a)(3), 164.306(b)(2)(iv), 164.308(a)(2)
    PM-30(1)Suppliers of Critical or Mission-essential ItemsPMProgram Management164.308(a)(7)(ii)(E)
    PM-31Continuous Monitoring StrategyPMProgram Management164.308(a)(1)(i), 164.308(a)(1)(ii)(D), 164.312(b)
    PT-1Policy and ProceduresPTPII Processing and Transparency164.306(b)(1), 164.308(a)(1)(i), 164.308(a)(3)(i), 164.308(a)(4)(i), 164.308(a)(4)(ii)(A), 164.308(a)(6)(i), 164.308(a)(7)(i), 164.310(a)(1), 164.310(a)(2)(ii), 164.310(a)(2)(iv), 164.310(b), 164.310(d)(1), 164.310(d)(2)(i), 164.312(a)(1), 164.312(c)(1), 164.316(a), 164.316(b)(1), 164.316(b)(2)(iii), 164.502(a), 164.530(a)(1)(i), 164.530(i)(1), 164.530(i)(2)(i), 164.530(i)(2)(ii), 164.530(i)(2)(iii), 164.530(i)(3), 164.530(i)(4)(i)(A), 164.530(i)(4)(i)(B), 164.530(i)(5), 164.530(i)(5)(i), 164.530(i)(5)(ii), 164.530(j)(1)(i)
    PT-2Authority to Process Personally Identifiable InformationPTPII Processing and Transparency164.502(a)(1)(i), 164.502(a)(1)(ii), 164.502(a)(1)(iii), 164.502(a)(5)(i), 164.502(c), 164.502(d)(1), 164.502(i), 164.504(g)(2), 164.506(a), 164.506(c)(1), 164.506(c)(5), 164.508(a)(1), 164.508(a)(2)(i)(B), 164.508(a)(2)(i)(C), 164.510(a)(1)(i)(A), 164.510(a)(1)(i)(B), 164.510(a)(1)(i)(C), 164.510(a)(1)(i)(D), 164.510(a)(1)(ii)(A), 164.510(a)(1)(ii)(B), 164.510(b)(4), 164.512, 164.512(i)(1), 164.512(j)(1), 164.512(j)(1)(i)(A), 164.512(j)(1)(i)(B), 164.512(j)(1)(ii), 164.512(j)(1)(ii)(A), 164.512(j)(1)(ii)(B), 164.512(j)(2)(i), 164.512(j)(2)(ii), 164.512(j)(3), 164.512(j)(4), 164.512(k)(1)(i), 164.512(k)(1)(i)(A), 164.512(k)(1)(i)(B), 164.512(k)(1)(ii), 164.512(k)(1)(iii), 164.512(k)(1)(iv), 164.512(k)(2), 164.512(k)(3), 164.512(k)(4), 164.512(k)(4)(i), 164.512(k)(4)(ii), 164.512(k)(4)(iii), 164.512(k)(5)(i), 164.512(k)(5)(i)(A), 164.512(k)(5)(i)(B), 164.512(k)(5)(i)(C), 164.512(k)(5)(i)(D), 164.512(k)(5)(i)(E), 164.512(k)(5)(i)(F), 164.512(k)(5)(ii), 164.512(k)(5)(iii), 164.512(k)(6)(i), 164.512(k)(6)(ii), 164.512(k)(6)(ii)(1), 164.514(f)(2)(i), 164.514(g), 164.530(i)(4)(ii), 164.530(i)(4)(ii)(B), 164.532(a), 164.532(b), 164.532(c)
    PT-3Personally Identifiable Information Processing PurposesPTPII Processing and Transparency164.502(a)(3), 164.508(a)(2)(i)(B), 164.508(c)(1)(i), 164.508(c)(1)(ii), 164.508(c)(1)(iii), 164.508(c)(1)(iv), 164.508(c)(2)(i)(A), 164.508(c)(2)(i)(B)
    PT-4ConsentPTPII Processing and Transparency164.506(b)(1), 164.508(a)(2), 164.508(c)(1)(v), 164.508(c)(3), 164.510(b)(2)(i), 164.510(b)(2)(ii), 164.510(b)(2)(iii), 164.510(b)(3), 164.514(f)(2)(ii), 164.514(f)(2)(iv), 164.514(f)(2)(v)
    PT-5Privacy NoticePTPII Processing and Transparency164.520(a)(1), 164.520(a)(2)(i), 164.520(a)(2)(i)(A), 164.520(a)(2)(i)(B), 164.520(a)(2)(ii), 164.520(a)(2)(ii)(A), 164.520(a)(2)(ii)(B), 164.520(a)(2)(iii), 164.520(b)(1), 164.520(b)(1)(i), 164.520(b)(1)(ii), 164.520(b)(1)(ii)(A), 164.520(b)(1)(ii)(B), 164.520(b)(1)(ii)(C), 164.520(b)(1)(ii)(D), 164.520(b)(1)(ii)(E), 164.520(b)(1)(iv), 164.520(b)(1)(iv)(A), 164.520(b)(1)(iv)(B), 164.520(b)(1)(iv)(C), 164.520(b)(1)(iv)(D), 164.520(b)(1)(iv)(E), 164.520(b)(1)(iv)(F), 164.520(b)(1)(v), 164.520(b)(1)(v)(A), 164.520(b)(1)(v)(B), 164.520(b)(1)(v)(C), 164.520(b)(1)(vi), 164.520(b)(1)(vii), 164.520(b)(1)(viii), 164.520(b)(2)(i), 164.520(b)(2)(ii), 164.520(b)(3), 164.520(c), 164.520(c)(1)(i), 164.520(c)(1)(i)(A), 164.520(c)(1)(i)(B), 164.520(c)(1)(ii), 164.520(c)(1)(iii), 164.520(c)(1)(iv), 164.520(c)(1)(v), 164.520(c)(1)(v)(A), 164.520(c)(1)(v)(B), 164.530(i)(4)(i)(C)
    PT-7Specific Categories of Personally Identifiable InformationPTPII Processing and Transparency164.502(c), 164.502(d)(1), 164.504(g)(2), 164.506(a), 164.506(c)(1), 164.506(c)(5), 164.508(a)(1), 164.508(a)(2)(i)(C), 164.510(a)(1)(i)(A), 164.510(a)(1)(i)(B), 164.510(a)(1)(i)(C), 164.510(a)(1)(i)(D), 164.510(a)(1)(ii)(A), 164.510(a)(1)(ii)(B), 164.510(b)(4), 164.512, 164.512(i)(1), 164.512(j)(1), 164.512(j)(1)(i)(A), 164.512(j)(1)(i)(B), 164.512(j)(1)(ii), 164.512(j)(1)(ii)(A), 164.512(j)(1)(ii)(B), 164.512(j)(2)(i), 164.512(j)(2)(ii), 164.512(j)(3), 164.512(j)(4), 164.512(k)(1)(i), 164.512(k)(1)(i)(A), 164.512(k)(1)(i)(B), 164.512(k)(1)(ii), 164.512(k)(1)(iii), 164.512(k)(1)(iv), 164.512(k)(2), 164.512(k)(3), 164.512(k)(4), 164.512(k)(4)(i), 164.512(k)(4)(ii), 164.512(k)(4)(iii), 164.512(k)(5)(i), 164.512(k)(5)(i)(A), 164.512(k)(5)(i)(B), 164.512(k)(5)(i)(C), 164.512(k)(5)(i)(D), 164.512(k)(5)(i)(E), 164.512(k)(5)(i)(F), 164.512(k)(5)(ii), 164.512(k)(5)(iii), 164.512(k)(6)(i), 164.512(k)(6)(ii), 164.512(k)(6)(ii)(1), 164.514(f)(2)(i), 164.514(g), 164.530(i)(4)(ii), 164.530(i)(4)(ii)(B), 164.532(a), 164.532(b), 164.532(c)
    SR-1Policy and ProceduresSRSupply Chain Risk Management164.308(a)(1)(i), 164.308(a)(3)(i), 164.308(a)(4)(i), 164.308(a)(4)(ii)(A), 164.308(a)(6)(i), 164.308(a)(7)(i), 164.308(b)(1), 164.310(a)(1), 164.310(a)(2)(ii), 164.310(a)(2)(iv), 164.310(b), 164.310(d)(1), 164.310(d)(2)(i), 164.312(a)(1), 164.312(c)(1), 164.312(d), 164.316(a), 164.316(b)(1), 164.316(b)(2)(iii), 164.530(i)(2)(i), 164.530(i)(2)(ii), 164.530(i)(2)(iii), 164.530(i)(3), 164.530(j)(1)(i)
    SR-3(3)Sub-tier Flow DownSRSupply Chain Risk Management164.308(b)(1), 164.308(b)(2), 164.308(b)(3), 164.314(a)(2)(i), 164.314(a)(2)(iii), 164.314(b)(1), 164.314(b)(2), 164.502(a)(4)(i), 164.502(a)(4)(ii), 164.502(e)(1)(i), 164.502(e)(1)(ii), 164.502(e)(2), 164.504(e)(2)(i), 164.504(e)(2)(i)(A), 164.504(e)(2)(i)(B), 164.504(e)(2)(ii)(D), 164.504(e)(2)(ii)(J), 164.504(e)(4)(i)(B)(ii)(B)(1), 164.504(e)(4)(i)(B)(ii)(B)(2), 164.504(f)(1)(i), 164.504(f)(2)(i), 164.504(f)(2)(ii), 164.504(f)(2)(ii)(A), 164.504(f)(2)(ii)(B), 164.504(f)(2)(ii)(C), 164.504(f)(2)(ii)(D), 164.504(f)(2)(ii)(E), 164.504(f)(2)(ii)(F), 164.504(f)(2)(ii)(G), 164.504(f)(2)(ii)(H), 164.504(f)(2)(ii)(I), 164.504(f)(2)(ii)(J), 164.504(f)(2)(iii)(A), 164.504(f)(2)(iii)(B), 164.504(f)(2)(iii)(C), 164.504(f)(3)(i), 164.504(f)(3)(ii), 164.504(f)(3)(iii), 164.504(f)(3)(iv)
    SR-8Notification AgreementsSRSupply Chain Risk Management164.314(a)(2)(i), 164.314(b)(2), 164.410(a)(1), 164.410(a)(2), 164.410(b), 164.410(c)(2)
    SR-12Component DisposalSRSupply Chain Risk Management164.310(d)(2)(i), 164.310(d)(2)(ii)

    Source and method

    Derived from the Top Floor framework mapping dataset: 4,123 cross-framework control mappings across 19 frameworks, every one pivoted through NIST SP 800-53 Rev 5.

    Cross-framework mappings on this page are derived from the 2026.2 release of the Secure Controls Framework, used under CC BY-ND 4.0.

    Mappings are illustrative aids for planning and are not a substitute for the official text of any framework or for an assessor’s judgment. Always verify control requirements against the authoritative publication. Where no official crosswalk exists, the mapping judgment is our own analysis.