Skip to content

    SOC 2 Type II to HIPAA (Security, Privacy and Breach Notification Rules) control mapping

    SOC 2 Type II and HIPAA (Security, Privacy and Breach Notification Rules) both map to 132 NIST SP 800-53 controls. Every one is listed below, with the controls on each side that map to it.

    Shared NIST 800-53 controls
    132
    SOC 2 Type II controls involved
    58
    HIPAA (Security, Privacy and Breach Notification Rules) controls involved
    409
    NIST 800-53 families touched
    20

    How this pairing is derived

    Both frameworks are mapped to NIST SP 800-53 Rev 5 in the source dataset, so the ground they share is the set of NIST controls they both reference. That set is what the table shows. It is not an authored SOC 2 Type II to HIPAA (Security, Privacy and Breach Notification Rules) crosswalk: two controls on the same row are related through the NIST control between them, not asserted to be equivalent to each other.

    Shared controls in full

    NIST SP 800-53 Rev 5 controls mapped by both SOC 2 Type II and HIPAA (Security, Privacy and Breach Notification Rules), with the controls on each side that map to them.
    NIST 800-53 controlFamilySOC 2 Type II controlsHIPAA (Security, Privacy and Breach Notification Rules) controls
    AC-1Policy and ProceduresACAccess ControlCC5.3, CC6.1, CC6.6164.308(a)(1)(i), 164.308(a)(3)(i), 164.308(a)(4)(i), 164.308(a)(4)(ii)(A), 164.308(a)(4)(ii)(B), 164.308(a)(6)(i), 164.308(a)(7)(i), 164.310(a)(1), 164.310(a)(2)(ii), 164.310(a)(2)(iii), 164.310(a)(2)(iv), 164.310(b), 164.310(d)(1), 164.310(d)(2)(i), 164.312(a)(1), 164.312(c)(1), 164.316(a), 164.316(b)(1), 164.316(b)(2)(iii), 164.530(c)(2)(ii), 164.530(i)(2)(i), 164.530(i)(2)(ii), 164.530(i)(2)(iii), 164.530(i)(3), 164.530(j)(1)(i)
    AC-2Account ManagementACAccess ControlCC6.1, CC6.6164.308(a)(3)(ii)(C), 164.312(a)(2)(ii)
    AC-2(7)Privileged User AccountsACAccess ControlCC6.1, CC6.3164.308(a)(3)(i), 164.308(a)(3)(ii)(A), 164.308(a)(4)(ii)(C), 164.312(a)(1), 164.514(d)(2)(i)(A), 164.514(d)(2)(i)(B), 164.514(d)(2)(ii), 164.530(c)(2)(ii)
    AC-2(12)Account Monitoring for Atypical UsageACAccess ControlCC7.2164.312(b), 164.312(c)(2)
    AC-3(14)Individual AccessACAccess ControlP5.1164.502(a)(2)(i), 164.502(a)(2)(ii), 164.514(h)(1)(i), 164.514(h)(1)(ii), 164.524(a)(1), 164.524(a)(1)(i), 164.524(a)(1)(ii), 164.524(a)(1)(iii), 164.524(a)(1)(iii)(A), 164.524(a)(1)(iii)(B), 164.524(a)(2), 164.524(a)(2)(i), 164.524(a)(2)(ii), 164.524(a)(2)(iii), 164.524(a)(2)(iv), 164.524(a)(2)(v), 164.524(a)(3), 164.524(a)(3)(i), 164.524(a)(3)(ii), 164.524(a)(3)(iii), 164.524(a)(4), 164.524(b)(1), 164.524(b)(2)(i), 164.524(b)(2)(i)(A), 164.524(b)(2)(i)(B), 164.524(b)(2)(ii), 164.524(b)(2)(ii)(A), 164.524(b)(2)(ii)(B), 164.524(c), 164.524(c)(1), 164.524(c)(3)(i), 164.524(c)(3)(ii), 164.524(c)(4), 164.524(c)(4)(i), 164.524(c)(4)(ii), 164.524(c)(4)(iii), 164.524(c)(4)(iv), 164.524(d), 164.524(d)(1), 164.524(d)(2)
    AC-6Least PrivilegeACAccess ControlCC6.1164.308(a)(3)(i), 164.312(a)(1)
    AC-6(7)Review of User PrivilegesACAccess ControlCC6.2164.308(a)(3)(ii)(B)
    AC-20(2)Portable Storage Devices — Restricted UseACAccess ControlCC6.7164.310(d)(1)
    AC-20(5)Portable Storage Devices — Prohibited UseACAccess ControlCC6.7164.310(d)(1)
    AC-21Information SharingACAccess ControlCC6.7, P6.1164.506(c)(1), 164.506(c)(2), 164.506(c)(3), 164.506(c)(4), 164.508(a)(1), 164.508(a)(4)(i)
    AC-23Data Mining ProtectionACAccess ControlP4.1164.502(c), 164.502(d)(1), 164.504(g)(2), 164.506(a), 164.506(c)(1), 164.506(c)(5), 164.508(a)(1), 164.508(a)(2)(i)(C), 164.510(a)(1)(i)(A), 164.510(a)(1)(i)(B), 164.510(a)(1)(i)(C), 164.510(a)(1)(i)(D), 164.510(a)(1)(ii)(A), 164.510(a)(1)(ii)(B), 164.510(b)(4), 164.512, 164.512(i)(1), 164.512(j)(1), 164.512(j)(1)(i)(A), 164.512(j)(1)(i)(B), 164.512(j)(1)(ii), 164.512(j)(1)(ii)(A), 164.512(j)(1)(ii)(B), 164.512(j)(2)(i), 164.512(j)(2)(ii), 164.512(j)(3), 164.512(j)(4), 164.512(k)(1)(i), 164.512(k)(1)(i)(A), 164.512(k)(1)(i)(B), 164.512(k)(1)(ii), 164.512(k)(1)(iii), 164.512(k)(1)(iv), 164.512(k)(2), 164.512(k)(3), 164.512(k)(4), 164.512(k)(4)(i), 164.512(k)(4)(ii), 164.512(k)(4)(iii), 164.512(k)(5)(i), 164.512(k)(5)(i)(A), 164.512(k)(5)(i)(B), 164.512(k)(5)(i)(C), 164.512(k)(5)(i)(D), 164.512(k)(5)(i)(E), 164.512(k)(5)(i)(F), 164.512(k)(5)(ii), 164.512(k)(5)(iii), 164.512(k)(6)(i), 164.512(k)(6)(ii), 164.512(k)(6)(ii)(1), 164.514(f)(2)(i), 164.514(g), 164.530(i)(4)(ii), 164.530(i)(4)(ii)(B), 164.532(a), 164.532(b), 164.532(c)
    AT-1Policy and ProceduresATAwareness and TrainingCC1.4, CC5.3164.308(a)(1)(i), 164.308(a)(3)(i), 164.308(a)(4)(i), 164.308(a)(4)(ii)(A), 164.308(a)(5)(i), 164.308(a)(6)(i), 164.308(a)(7)(i), 164.310(a)(1), 164.310(a)(2)(ii), 164.310(a)(2)(iv), 164.310(b), 164.310(d)(1), 164.310(d)(2)(i), 164.312(a)(1), 164.312(c)(1), 164.316(a), 164.316(b)(1), 164.316(b)(2)(iii), 164.530(i)(2)(i), 164.530(i)(2)(ii), 164.530(i)(2)(iii), 164.530(i)(3), 164.530(j)(1)(i)
    AU-1Policy and ProceduresAUAudit and AccountabilityCC5.3, CC7.2164.308(a)(1)(i), 164.308(a)(1)(ii)(D), 164.308(a)(3)(i), 164.308(a)(4)(i), 164.308(a)(4)(ii)(A), 164.308(a)(6)(i), 164.308(a)(7)(i), 164.310(a)(1), 164.310(a)(2)(ii), 164.310(a)(2)(iv), 164.310(b), 164.310(d)(1), 164.310(d)(2)(i), 164.312(a)(1), 164.312(b), 164.312(c)(1), 164.316(a), 164.316(b)(1), 164.316(b)(2)(iii), 164.530(i)(2)(i), 164.530(i)(2)(ii), 164.530(i)(2)(iii), 164.530(i)(3), 164.530(j)(1)(i)
    AU-2Event LoggingAUAudit and AccountabilityCC7.2, CC7.3164.308(a)(1)(ii)(D), 164.312(b)
    AU-3Content of Audit RecordsAUAudit and AccountabilityPI1.4164.312(b)
    CA-1Policy and ProceduresCAAssessment, Authorization, and MonitoringCC4.1, CC5.3164.308(a)(1)(i), 164.308(a)(3)(i), 164.308(a)(4)(i), 164.308(a)(4)(ii)(A), 164.308(a)(6)(i), 164.308(a)(7)(i), 164.310(a)(1), 164.310(a)(2)(ii), 164.310(a)(2)(iv), 164.310(b), 164.310(d)(1), 164.310(d)(2)(i), 164.312(a)(1), 164.312(c)(1), 164.316(a), 164.316(b)(1), 164.316(b)(2)(iii), 164.530(i)(2)(i), 164.530(i)(2)(ii), 164.530(i)(2)(iii), 164.530(i)(3), 164.530(j)(1)(i)
    CA-2Control AssessmentsCAAssessment, Authorization, and MonitoringCC3.1, CC4.1, CC5.2164.306(d)(3)(i), 164.306(e), 164.308(a)(8), 164.316(b)(1)
    CA-7Continuous MonitoringCAAssessment, Authorization, and MonitoringCC1.1, CC2.2, CC2.3164.306(d)(3)(i), 164.316(b)(2)(iii)
    CA-7(1)Independent AssessmentCAAssessment, Authorization, and MonitoringCC1.1, CC2.2, CC2.3164.306(d)(3)(i), 164.316(b)(2)(iii)
    CM-1Policy and ProceduresCMConfiguration ManagementCC5.3, CC7.1164.308(a)(1)(i), 164.308(a)(3)(i), 164.308(a)(4)(i), 164.308(a)(4)(ii)(A), 164.308(a)(6)(i), 164.308(a)(7)(i), 164.310(a)(1), 164.310(a)(2)(ii), 164.310(a)(2)(iv), 164.310(b), 164.310(d)(1), 164.310(d)(2)(i), 164.312(a)(1), 164.312(c)(1), 164.316(a), 164.316(b)(1), 164.316(b)(2)(iii), 164.530(i)(2)(i), 164.530(i)(2)(ii), 164.530(i)(2)(iii), 164.530(i)(3), 164.530(j)(1)(i)
    CM-2Baseline ConfigurationCMConfiguration ManagementCC7.1, CC8.1164.312(a)(2)(iii), 164.312(e)(1), 164.312(e)(2)(i), 164.312(e)(2)(ii)
    CM-3Configuration Change ControlCMConfiguration ManagementCC3.4, CC8.1164.308(a)(1)(i)
    CM-6Configuration SettingsCMConfiguration ManagementCC7.1, CC8.1164.312(a)(2)(iii), 164.312(e)(1), 164.312(e)(2)(i), 164.312(e)(2)(ii)
    CM-9Configuration Management PlanCMConfiguration ManagementCC7.1, CC8.1164.308(a)(1)(i)
    CP-1Policy and ProceduresCPContingency PlanningA1.2, CC5.3, CC7.5, CC9.1164.308(a)(1)(i), 164.308(a)(3)(i), 164.308(a)(4)(i), 164.308(a)(4)(ii)(A), 164.308(a)(6)(i), 164.308(a)(7)(i), 164.308(a)(7)(ii)(C), 164.310(a)(1), 164.310(a)(2)(ii), 164.310(a)(2)(iv), 164.310(b), 164.310(d)(1), 164.310(d)(2)(i), 164.312(a)(1), 164.312(c)(1), 164.316(a), 164.316(b)(1), 164.316(b)(2)(iii), 164.530(i)(2)(i), 164.530(i)(2)(ii), 164.530(i)(2)(iii), 164.530(i)(3), 164.530(j)(1)(i)
    CP-2Contingency PlanCPContingency PlanningA1.2, CC7.5, CC9.1164.308(a)(7)(i), 164.308(a)(7)(ii)(C)
    CP-2(5)Continue Mission and Business FunctionsCPContingency PlanningCC7.5164.308(a)(7)(ii)(C)
    CP-2(8)Identify Critical AssetsCPContingency PlanningCC7.5164.308(a)(7)(ii)(E)
    CP-4Contingency Plan TestingCPContingency PlanningA1.3, CC7.5164.308(a)(7)(ii)(D)
    CP-7(2)AccessibilityCPContingency PlanningA1.2164.310(a)(2)(i)
    CP-9System BackupCPContingency PlanningA1.2, CC7.5164.308(a)(7)(ii)(A), 164.310(d)(2)(iv)
    CP-10System Recovery and ReconstitutionCPContingency PlanningA1.2, CC7.5, CC9.1164.308(a)(7)(i), 164.308(a)(7)(ii)(B), 164.308(a)(7)(ii)(C)
    IA-1Policy and ProceduresIAIdentification and AuthenticationCC5.3, CC6.1, CC6.6164.308(a)(1)(i), 164.308(a)(3)(i), 164.308(a)(4)(i), 164.308(a)(4)(ii)(A), 164.308(a)(4)(ii)(B), 164.308(a)(6)(i), 164.308(a)(7)(i), 164.310(a)(1), 164.310(a)(2)(ii), 164.310(a)(2)(iii), 164.310(a)(2)(iv), 164.310(b), 164.310(d)(1), 164.310(d)(2)(i), 164.312(a)(1), 164.312(c)(1), 164.316(a), 164.316(b)(1), 164.316(b)(2)(iii), 164.530(c)(2)(ii), 164.530(i)(2)(i), 164.530(i)(2)(ii), 164.530(i)(2)(iii), 164.530(i)(3), 164.530(j)(1)(i)
    IA-2Identification and Authentication (Organizational Users)IAIdentification and AuthenticationCC6.1164.312(a)(2)(i)
    IA-4Identifier ManagementIAIdentification and AuthenticationCC6.1, CC6.6164.312(a)(2)(i)
    IA-12(4)In-person Validation and VerificationIAIdentification and AuthenticationCC6.2164.308(a)(3)(ii)(C)
    IR-1Policy and ProceduresIRIncident ResponseCC5.3, CC7.3, CC7.4164.308(a)(1)(i), 164.308(a)(3)(i), 164.308(a)(4)(i), 164.308(a)(4)(ii)(A), 164.308(a)(6)(i), 164.308(a)(7)(i), 164.310(a)(1), 164.310(a)(2)(ii), 164.310(a)(2)(iv), 164.310(b), 164.310(d)(1), 164.310(d)(2)(i), 164.312(a)(1), 164.312(c)(1), 164.316(a), 164.316(b)(1), 164.316(b)(2)(iii), 164.530(i)(2)(i), 164.530(i)(2)(ii), 164.530(i)(2)(iii), 164.530(i)(3), 164.530(j)(1)(i)
    IR-4Incident HandlingIRIncident ResponseCC7.3, CC7.4164.308(a)(6)(ii), 164.412, 164.412(a), 164.412(b), 164.530(f)
    IR-4(3)Continuity of OperationsIRIncident ResponseA1.2, CC7.5, CC9.1164.308(a)(7)(i), 164.308(a)(7)(ii)(C)
    IR-4(13)Behavior AnalysisIRIncident ResponseCC7.2164.312(b), 164.312(c)(2)
    IR-5Incident MonitoringIRIncident ResponseCC7.4164.308(a)(1)(ii)(D)
    IR-6Incident ReportingIRIncident ResponseCC2.3, CC7.4, P6.3, P6.7164.404(b), 164.408(a), 164.408(b), 164.408(c)
    IR-8(1)BreachesIRIncident ResponseCC7.3, P6.3, P6.6, P6.7164.404(a)(1), 164.404(a)(2), 164.404(c)(1)(A), 164.404(c)(1)(B), 164.404(c)(1)(C), 164.404(c)(1)(D), 164.404(c)(1)(E), 164.404(c)(2), 164.404(d)(1)(i), 164.404(d)(1)(ii), 164.404(d)(2), 164.404(d)(2)(i), 164.404(d)(2)(ii)(A), 164.404(d)(2)(ii)(B), 164.404(d)(3), 164.406(a), 164.406(b), 164.406(c), 164.410(c)(1)
    MA-1Policy and ProceduresMAMaintenanceCC5.3164.308(a)(1)(i), 164.308(a)(3)(i), 164.308(a)(4)(i), 164.308(a)(4)(ii)(A), 164.308(a)(6)(i), 164.308(a)(7)(i), 164.310(a)(1), 164.310(a)(2)(ii), 164.310(a)(2)(iv), 164.310(b), 164.310(d)(1), 164.310(d)(2)(i), 164.312(a)(1), 164.312(c)(1), 164.316(a), 164.316(b)(1), 164.316(b)(2)(iii), 164.530(i)(2)(i), 164.530(i)(2)(ii), 164.530(i)(2)(iii), 164.530(i)(3), 164.530(j)(1)(i)
    PE-1Policy and ProceduresPEPhysical and Environmental ProtectionA1.2, CC5.3, CC6.4164.308(a)(1)(i), 164.308(a)(3)(i), 164.308(a)(4)(i), 164.308(a)(4)(ii)(A), 164.308(a)(6)(i), 164.308(a)(7)(i), 164.310(a)(1), 164.310(a)(2)(ii), 164.310(a)(2)(iv), 164.310(b), 164.310(d)(1), 164.310(d)(2)(i), 164.312(a)(1), 164.312(c)(1), 164.316(a), 164.316(b)(1), 164.316(b)(2)(iii), 164.530(i)(2)(i), 164.530(i)(2)(ii), 164.530(i)(2)(iii), 164.530(i)(3), 164.530(j)(1)(i)
    PE-2Physical Access AuthorizationsPEPhysical and Environmental ProtectionCC6.4164.310(a)(2)(i), 164.310(a)(2)(iii)
    PE-2(1)Access by Position or RolePEPhysical and Environmental ProtectionCC6.4164.310(a)(2)(i)
    PE-3Physical Access ControlPEPhysical and Environmental ProtectionCC6.4164.310(a)(2)(ii), 164.310(a)(2)(iii), 164.310(c)
    PE-3(2)Facility and SystemsPEPhysical and Environmental ProtectionCC6.4164.310(a)(2)(ii), 164.310(a)(2)(iii), 164.310(c)
    PE-3(3)Continuous GuardsPEPhysical and Environmental ProtectionCC6.4164.310(a)(2)(ii), 164.310(a)(2)(iii), 164.310(c)
    PE-23Facility LocationPEPhysical and Environmental ProtectionA1.2, CC6.4, CC9.1164.310(a)(1), 164.310(a)(2)(ii), 164.310(a)(2)(iv)
    PL-1Policy and ProceduresPLPlanningCC1.5, CC2.2, CC2.3, CC3.1, CC3.4, CC5.2, CC5.3, PI1.2, PI1.3164.306(c), 164.306(d)(1), 164.306(d)(2), 164.308(a)(1)(i), 164.308(a)(3)(i), 164.308(a)(4)(i), 164.308(a)(4)(ii)(A), 164.308(a)(6)(i), 164.308(a)(7)(i), 164.310(a)(1), 164.310(a)(2)(ii), 164.310(a)(2)(iv), 164.310(b), 164.310(d)(1), 164.310(d)(2)(i), 164.312(a)(1), 164.312(c)(1), 164.314(a)(1), 164.314(a)(2)(ii), 164.316(a), 164.316(b)(1), 164.316(b)(2)(iii), 164.504(g)(1), 164.530(i)(1), 164.530(i)(2)(i), 164.530(i)(2)(ii), 164.530(i)(2)(iii), 164.530(i)(3), 164.530(j)(1)(i)
    PL-4Rules of BehaviorPLPlanningCC1.1164.310(b)
    PL-8Security and Privacy ArchitecturesPLPlanningCC3.1, CC4.1, CC5.1164.306(b)(1), 164.306(b)(2)(ii)
    PL-9Central ManagementPLPlanningCC1.1, CC1.3, CC5.1164.308(a)(2)
    PL-10Baseline SelectionPLPlanningCC7.1, CC8.1164.312(a)(2)(iii), 164.312(e)(1), 164.312(e)(2)(i), 164.312(e)(2)(ii)
    RA-1Policy and ProceduresRARisk AssessmentCC3.1, CC4.1, CC5.1, CC5.3, CC9.1164.306(a)(3), 164.306(b)(2)(iv), 164.308(a)(1)(i), 164.308(a)(3)(i), 164.308(a)(4)(i), 164.308(a)(4)(ii)(A), 164.308(a)(6)(i), 164.308(a)(7)(i), 164.310(a)(1), 164.310(a)(2)(ii), 164.310(a)(2)(iv), 164.310(b), 164.310(d)(1), 164.310(d)(2)(i), 164.312(a)(1), 164.312(c)(1), 164.316(a), 164.316(b)(1), 164.316(b)(2)(iii), 164.530(i)(2)(i), 164.530(i)(2)(ii), 164.530(i)(2)(iii), 164.530(i)(3), 164.530(j)(1)(i)
    RA-2Security CategorizationRARisk AssessmentCC3.2164.306(b)(2)(iv)
    RA-3Risk AssessmentRARisk AssessmentA1.2, CC4.1, CC7.3164.306(b)(2)(iv), 164.306(d)(3)(i), 164.306(e), 164.308(a)(1)(ii)(A), 164.308(a)(8)
    RA-9Criticality AnalysisRARisk AssessmentCC2.2, CC4.1, CC5.2, CC9.1, PI1.1164.306(b)(2)(ii), 164.308(a)(7)(ii)(E)
    SA-1Policy and ProceduresSASystem and Services AcquisitionCC5.2, CC5.3, P6.4, PI1.1, PI1.2, PI1.3, PI1.4, PI1.5164.308(a)(1)(i), 164.308(a)(3)(i), 164.308(a)(4)(i), 164.308(a)(4)(ii)(A), 164.308(a)(6)(i), 164.308(a)(7)(i), 164.310(a)(1), 164.310(a)(2)(ii), 164.310(a)(2)(iv), 164.310(b), 164.310(d)(1), 164.310(d)(2)(i), 164.312(a)(1), 164.312(c)(1), 164.316(a), 164.316(b)(1), 164.316(b)(2)(iii), 164.530(i)(2)(i), 164.530(i)(2)(ii), 164.530(i)(2)(iii), 164.530(i)(3), 164.530(j)(1)(i)
    SA-2Allocation of ResourcesSASystem and Services AcquisitionCC1.4, CC4.1164.306(b)(2)(iii)
    SA-4Acquisition ProcessSASystem and Services AcquisitionCC3.3, CC3.4, CC5.2, CC9.1, CC9.2, P6.4, PI1.2, PI1.3164.308(b)(1), 164.312(d)
    SA-4(12)Data OwnershipSASystem and Services AcquisitionCC2.1164.310(d)(2)(iii)
    SA-8Security and Privacy Engineering PrinciplesSASystem and Services AcquisitionCC2.2, CC3.2, CC5.1, CC5.2, CC7.1, CC8.1164.306(b)(1), 164.312(a)(2)(iii), 164.312(e)(1), 164.312(e)(2)(i), 164.312(e)(2)(ii)
    SA-8(14)Least PrivilegeSASystem and Services AcquisitionCC6.1164.308(a)(3)(i), 164.312(a)(1)
    SA-8(32)Sufficient DocumentationSASystem and Services AcquisitionCC2.2, CC5.1, CC5.3164.310(b), 164.316(b)(2)(ii)
    SA-9External System ServicesSASystem and Services AcquisitionCC3.3, P6.4164.308(b)(1)
    SA-9(3)Establish and Maintain Trust Relationship with ProvidersSASystem and Services AcquisitionCC3.1, CC3.2, CC3.3, CC4.1, CC9.1, CC9.2164.308(a)(7)(ii)(E), 164.308(b)(1), 164.504(e)(2)(iii)
    SA-15(5)Attack Surface ReductionSASystem and Services AcquisitionCC2.2, CC3.2, CC5.1, CC5.2, CC7.1, CC8.1164.306(b)(1), 164.312(a)(2)(iii), 164.312(e)(1), 164.312(e)(2)(i), 164.312(e)(2)(ii)
    SC-1Policy and ProceduresSCSystem and Communications ProtectionCC2.2, CC3.2, CC5.1, CC5.2, CC5.3, CC6.1, CC6.6164.306(b)(1), 164.308(a)(1)(i), 164.308(a)(3)(i), 164.308(a)(4)(i), 164.308(a)(4)(ii)(A), 164.308(a)(6)(i), 164.308(a)(7)(i), 164.310(a)(1), 164.310(a)(2)(ii), 164.310(a)(2)(iv), 164.310(b), 164.310(d)(1), 164.310(d)(2)(i), 164.312(a)(1), 164.312(c)(1), 164.312(e)(1), 164.312(e)(2)(i), 164.316(a), 164.316(b)(1), 164.316(b)(2)(iii), 164.530(i)(2)(i), 164.530(i)(2)(ii), 164.530(i)(2)(iii), 164.530(i)(3), 164.530(j)(1)(i)
    SC-7(18)Fail SecureSCSystem and Communications ProtectionCC2.2, CC3.2, CC5.1, CC5.2164.306(b)(1)
    SC-8Transmission Confidentiality and IntegritySCSystem and Communications ProtectionCC6.1, CC6.7164.312(e)(1), 164.312(e)(2)(i)
    SC-8(1)Cryptographic ProtectionSCSystem and Communications ProtectionCC6.1, CC6.7164.312(a)(2)(iv), 164.312(e)(1), 164.312(e)(2)(ii)
    SC-8(2)Pre- and Post-transmission HandlingSCSystem and Communications ProtectionCC6.1, CC6.7164.312(a)(2)(iv), 164.312(e)(2)(ii)
    SC-13Cryptographic ProtectionSCSystem and Communications ProtectionCC6.1, CC6.7164.312(a)(2)(iv), 164.312(e)(2)(ii)
    SC-28Protection of Information at RestSCSystem and Communications ProtectionCC6.1, CC6.7164.310(c)
    SC-28(1)Cryptographic ProtectionSCSystem and Communications ProtectionA1.2, CC6.1, CC6.7164.312(e)(2)(i)
    SC-28(2)Offline StorageSCSystem and Communications ProtectionA1.2, CC7.5164.308(a)(7)(ii)(A), 164.310(d)(2)(iv)
    SI-1Policy and ProceduresSISystem and Information IntegrityCC2.2, CC3.2, CC5.1, CC5.2, CC5.3164.306(b)(1), 164.308(a)(1)(i), 164.308(a)(3)(i), 164.308(a)(4)(i), 164.308(a)(4)(ii)(A), 164.308(a)(6)(i), 164.308(a)(7)(i), 164.310(a)(1), 164.310(a)(2)(ii), 164.310(a)(2)(iv), 164.310(b), 164.310(d)(1), 164.310(d)(2)(i), 164.312(a)(1), 164.312(c)(1), 164.316(a), 164.316(b)(1), 164.316(b)(2)(iii), 164.530(i)(2)(i), 164.530(i)(2)(ii), 164.530(i)(2)(iii), 164.530(i)(3), 164.530(j)(1)(i)
    SI-4System MonitoringSISystem and Information IntegrityCC6.6, CC7.2, CC7.3164.308(a)(1)(i), 164.308(a)(1)(ii)(D), 164.312(b)
    SI-4(5)System-generated AlertsSISystem and Information IntegrityCC7.2164.312(b)
    SI-4(11)Analyze Communications Traffic AnomaliesSISystem and Information IntegrityCC7.2164.312(b), 164.312(c)(2)
    SI-4(24)Indicators of CompromiseSISystem and Information IntegrityCC6.8, CC7.1164.312(c)(2)
    SI-7(6)Cryptographic ProtectionSISystem and Information IntegrityCC6.1164.312(a)(2)(iv), 164.312(e)(2)(ii)
    SI-12Information Management and RetentionSISystem and Information IntegrityC1.2, CC6.5, P4.2, P4.3, PI1.5164.316(b)(2)(i), 164.530(j)(2)
    SI-12(1)Limit Personally Identifiable Information ElementsSISystem and Information IntegrityP4.1164.502(b)(1), 164.508(a)(2)(i)(B)
    SI-12(2)Minimize Personally Identifiable Information in Testing, Training, and ResearchSISystem and Information IntegrityP4.1164.508(a)(2)(i)(B)
    SI-18(4)Individual RequestsSISystem and Information IntegrityP5.1, P5.2164.502(a)(2)(i), 164.502(a)(2)(ii), 164.514(h)(1)(i), 164.514(h)(1)(ii), 164.524(a)(1), 164.524(a)(1)(i), 164.524(a)(1)(ii), 164.524(a)(1)(iii), 164.524(a)(1)(iii)(A), 164.524(a)(1)(iii)(B), 164.524(a)(2), 164.524(a)(2)(i), 164.524(a)(2)(ii), 164.524(a)(2)(iii), 164.524(a)(2)(iv), 164.524(a)(2)(v), 164.524(a)(3), 164.524(a)(3)(i), 164.524(a)(3)(ii), 164.524(a)(3)(iii), 164.524(a)(4), 164.524(b)(1), 164.524(b)(2)(i), 164.524(b)(2)(i)(A), 164.524(b)(2)(i)(B), 164.524(b)(2)(ii), 164.524(b)(2)(ii)(A), 164.524(b)(2)(ii)(B), 164.524(c), 164.524(c)(1), 164.524(c)(3)(i), 164.524(c)(3)(ii), 164.524(c)(4), 164.524(c)(4)(i), 164.524(c)(4)(ii), 164.524(c)(4)(iii), 164.524(c)(4)(iv), 164.524(d), 164.524(d)(1), 164.524(d)(2), 164.526(a)(1), 164.526(a)(2), 164.526(a)(2)(i), 164.526(a)(2)(ii), 164.526(a)(2)(iii), 164.526(a)(2)(iv), 164.526(b)(1)
    SI-18(5)Notice of Correction or DeletionSISystem and Information IntegrityP5.1, P5.2164.526(a)(1), 164.526(a)(2), 164.526(a)(2)(i), 164.526(a)(2)(ii), 164.526(a)(2)(iii), 164.526(a)(2)(iv), 164.526(b)(1), 164.526(c), 164.526(c)(1), 164.526(c)(2), 164.526(c)(3), 164.526(c)(3)(i), 164.526(c)(3)(ii)
    MP-1Policy and ProceduresMPMedia ProtectionC1.1, CC2.1, CC5.3, CC6.5, CC6.7, PI1.5164.306(a)(3), 164.308(a)(1)(i), 164.308(a)(3)(i), 164.308(a)(4)(i), 164.308(a)(4)(ii)(A), 164.308(a)(6)(i), 164.308(a)(7)(i), 164.310(a)(1), 164.310(a)(2)(ii), 164.310(a)(2)(iv), 164.310(b), 164.310(d)(1), 164.310(d)(2)(i), 164.312(a)(1), 164.312(c)(1), 164.316(a), 164.316(b)(1), 164.316(b)(2)(iii), 164.514(d)(3)(i), 164.530(c)(2)(i), 164.530(i)(2)(i), 164.530(i)(2)(ii), 164.530(i)(2)(iii), 164.530(i)(3), 164.530(j)(1)(i)
    MP-2Media AccessMPMedia ProtectionC1.1164.310(b), 164.310(d)(1)
    MP-6Media SanitizationMPMedia ProtectionCC6.5, P4.3164.310(d)(2)(ii)
    MP-6(3)Nondestructive TechniquesMPMedia ProtectionCC6.5, P4.3164.310(d)(2)(ii)
    MP-7Media UseMPMedia ProtectionCC6.7, PI1.5164.316(b)(2)(i), 164.530(j)(2)
    PS-1Policy and ProceduresPSPersonnel SecurityCC1.1, CC1.4, CC5.3164.308(a)(1)(i), 164.308(a)(3)(i), 164.308(a)(3)(ii)(A), 164.308(a)(4)(i), 164.308(a)(4)(ii)(A), 164.308(a)(6)(i), 164.308(a)(7)(i), 164.310(a)(1), 164.310(a)(2)(ii), 164.310(a)(2)(iv), 164.310(b), 164.310(d)(1), 164.310(d)(2)(i), 164.312(a)(1), 164.312(c)(1), 164.312(d), 164.316(a), 164.316(b)(1), 164.316(b)(2)(iii), 164.530(e)(2), 164.530(i)(2)(i), 164.530(i)(2)(ii), 164.530(i)(2)(iii), 164.530(i)(3), 164.530(j)(1)(i)
    PS-2Position Risk DesignationPSPersonnel SecurityCC1.2, CC1.3, CC1.5, CC5.3164.308(a)(3)(ii)(B), 164.312(a)(1), 164.530(a)(2)
    PS-4Personnel TerminationPSPersonnel SecurityCC1.5164.308(a)(3)(ii)(C)
    PS-5Personnel TransferPSPersonnel SecurityCC1.5164.308(a)(3)(ii)(C)
    PS-6Access AgreementsPSPersonnel SecurityCC1.5164.502(a)
    PS-6(2)Classified Information Requiring Special ProtectionPSPersonnel SecurityCC1.5164.502(a)
    PS-8Personnel SanctionsPSPersonnel SecurityCC1.5164.308(a)(1)(ii)(C), 164.530(e)(1)
    PS-9Position DescriptionsPSPersonnel SecurityCC1.2, CC1.3, CC2.2164.308(a)(3)(ii)(B), 164.310(a)(2)(i), 164.312(a)(1), 164.530(a)(2)
    PM-1Information Security Program PlanPMProgram ManagementCC1.1, CC1.2, CC5.3164.306(a)(1), 164.306(a)(2), 164.306(a)(3), 164.308(a)(1)(i), 164.308(a)(3)(i), 164.308(a)(4)(i), 164.308(a)(4)(ii)(A), 164.308(a)(6)(i), 164.308(a)(7)(i), 164.310(a)(1), 164.310(a)(2)(ii), 164.310(a)(2)(iv), 164.310(b), 164.310(d)(1), 164.310(d)(2)(i), 164.312(a)(1), 164.312(c)(1), 164.316(a), 164.316(b)(1), 164.316(b)(2)(iii), 164.530(c)(1), 164.530(i)(1), 164.530(i)(2)(i), 164.530(i)(2)(ii), 164.530(i)(2)(iii), 164.530(i)(3), 164.530(j)(1)(i)
    PM-2Information Security Program Leadership RolePMProgram ManagementCC1.1, CC1.3164.308(a)(2)
    PM-6Measures of PerformancePMProgram ManagementCC1.1, CC1.2, CC1.3, CC1.5, CC2.2, CC4.1164.308(a)(2)
    PM-7Enterprise ArchitecturePMProgram ManagementCC3.1, CC4.1, CC5.1164.306(b)(1), 164.306(b)(2)(ii)
    PM-8Critical Infrastructure PlanPMProgram ManagementA1.2, CC1.5, CC2.2, CC2.3, CC7.5, CC9.1164.306(c), 164.306(d)(1), 164.306(d)(2), 164.308(a)(7)(i), 164.308(a)(7)(ii)(C), 164.314(a)(1), 164.314(a)(2)(ii), 164.504(g)(1), 164.530(i)(1)
    PM-9Risk Management StrategyPMProgram ManagementCC3.1, CC4.1, CC5.1, CC9.1164.306(a)(3), 164.306(b)(2)(iv)
    PM-11Mission and Business Process DefinitionPMProgram ManagementCC1.3, CC3.1, CC3.4, CC4.1, CC5.1, CC5.2, PI1.1164.306(b)(2)(i)
    PM-13Security and Privacy WorkforcePMProgram ManagementCC1.2, CC1.3, CC1.4, CC2.2164.308(a)(3)(ii)(B), 164.308(a)(5)(i), 164.310(a)(2)(i), 164.312(a)(1), 164.530(a)(2)
    PM-14Testing, Training, and MonitoringPMProgram ManagementCC1.1, CC2.2, CC2.3164.306(d)(3)(i), 164.316(b)(2)(iii)
    PM-20(1)Privacy Policies on Websites, Applications, and Digital ServicesPMProgram ManagementP1.1164.520(a)(1), 164.520(a)(2)(i), 164.520(a)(2)(i)(A), 164.520(a)(2)(i)(B), 164.520(a)(2)(ii), 164.520(a)(2)(ii)(A), 164.520(a)(2)(ii)(B), 164.520(a)(2)(iii), 164.520(b)(1), 164.520(b)(1)(i), 164.520(b)(1)(ii), 164.520(b)(1)(ii)(A), 164.520(b)(1)(ii)(B), 164.520(b)(1)(ii)(C), 164.520(b)(1)(ii)(D), 164.520(b)(1)(ii)(E), 164.520(b)(1)(iv), 164.520(b)(1)(iv)(A), 164.520(b)(1)(iv)(B), 164.520(b)(1)(iv)(C), 164.520(b)(1)(iv)(D), 164.520(b)(1)(iv)(E), 164.520(b)(1)(iv)(F), 164.520(b)(1)(v), 164.520(b)(1)(v)(A), 164.520(b)(1)(v)(B), 164.520(b)(1)(v)(C), 164.520(b)(1)(vi), 164.520(b)(1)(vii), 164.520(b)(1)(viii), 164.520(b)(2)(i), 164.520(b)(2)(ii), 164.520(b)(3), 164.520(c), 164.520(c)(1)(i), 164.520(c)(1)(i)(A), 164.520(c)(1)(i)(B), 164.520(c)(1)(ii), 164.520(c)(1)(iii), 164.520(c)(1)(iv), 164.520(c)(1)(v), 164.520(c)(1)(v)(A), 164.520(c)(1)(v)(B), 164.530(i)(4)(i)(C)
    PM-21Accounting of DisclosuresPMProgram ManagementP6.2, P6.3164.528(a)(1), 164.528(a)(1)(i), 164.528(a)(1)(ii), 164.528(a)(1)(iii), 164.528(a)(1)(iv), 164.528(a)(1)(ix), 164.528(a)(1)(v), 164.528(a)(1)(vi), 164.528(a)(1)(vii), 164.528(a)(1)(viii), 164.528(b), 164.528(b)(1), 164.528(b)(2), 164.528(b)(2)(i), 164.528(b)(2)(ii), 164.528(b)(2)(iii), 164.528(b)(2)(iv), 164.528(b)(3), 164.528(b)(3)(i), 164.528(b)(3)(ii), 164.528(b)(3)(iii), 164.528(b)(4)(i), 164.528(b)(4)(i)(A), 164.528(b)(4)(i)(B), 164.528(b)(4)(i)(C), 164.528(b)(4)(i)(D), 164.528(b)(4)(i)(E), 164.528(b)(4)(i)(F), 164.528(b)(4)(ii), 164.528(c)(1), 164.528(c)(1)(i), 164.528(c)(1)(ii), 164.528(c)(1)(ii)(A), 164.528(c)(1)(ii)(B), 164.528(c)(2), 164.528(d), 164.528(d)(1), 164.528(d)(2), 164.528(d)(3)
    PM-22Personally Identifiable Information Quality ManagementPMProgram ManagementCC2.1, P7.1164.512(i)(1)(i)(B), 164.512(i)(1)(i)(B)(1), 164.512(i)(1)(i)(B)(2), 164.512(i)(1)(i)(B)(3)
    PM-23Data Governance BodyPMProgram ManagementP7.1164.512(i)(1)(i)(B), 164.512(i)(1)(i)(B)(1), 164.512(i)(1)(i)(B)(2), 164.512(i)(1)(i)(B)(3)
    PM-24Data Integrity BoardPMProgram ManagementP7.1164.512(i)(1)(i)(B), 164.512(i)(1)(i)(B)(1), 164.512(i)(1)(i)(B)(2), 164.512(i)(1)(i)(B)(3)
    PM-25Minimization of Personally Identifiable Information Used in Testing, Training, and ResearchPMProgram ManagementP4.1164.502(c), 164.502(d)(1), 164.504(g)(2), 164.506(a), 164.506(c)(1), 164.506(c)(5), 164.508(a)(1), 164.508(a)(2)(i)(B), 164.508(a)(2)(i)(C), 164.510(a)(1)(i)(A), 164.510(a)(1)(i)(B), 164.510(a)(1)(i)(C), 164.510(a)(1)(i)(D), 164.510(a)(1)(ii)(A), 164.510(a)(1)(ii)(B), 164.510(b)(4), 164.512, 164.512(i)(1), 164.512(j)(1), 164.512(j)(1)(i)(A), 164.512(j)(1)(i)(B), 164.512(j)(1)(ii), 164.512(j)(1)(ii)(A), 164.512(j)(1)(ii)(B), 164.512(j)(2)(i), 164.512(j)(2)(ii), 164.512(j)(3), 164.512(j)(4), 164.512(k)(1)(i), 164.512(k)(1)(i)(A), 164.512(k)(1)(i)(B), 164.512(k)(1)(ii), 164.512(k)(1)(iii), 164.512(k)(1)(iv), 164.512(k)(2), 164.512(k)(3), 164.512(k)(4), 164.512(k)(4)(i), 164.512(k)(4)(ii), 164.512(k)(4)(iii), 164.512(k)(5)(i), 164.512(k)(5)(i)(A), 164.512(k)(5)(i)(B), 164.512(k)(5)(i)(C), 164.512(k)(5)(i)(D), 164.512(k)(5)(i)(E), 164.512(k)(5)(i)(F), 164.512(k)(5)(ii), 164.512(k)(5)(iii), 164.512(k)(6)(i), 164.512(k)(6)(ii), 164.512(k)(6)(ii)(1), 164.514(f)(2)(i), 164.514(g), 164.530(i)(4)(ii), 164.530(i)(4)(ii)(B), 164.532(a), 164.532(b), 164.532(c)
    PM-26Complaint ManagementPMProgram ManagementP5.1, P5.2, P8.1164.524(d)(4), 164.526(b)(2)(i), 164.526(b)(2)(i)(A), 164.526(b)(2)(i)(B), 164.526(b)(2)(ii), 164.526(b)(2)(ii)(A), 164.526(b)(2)(ii)(B), 164.526(d), 164.526(d)(1), 164.526(d)(1)(i), 164.526(d)(1)(ii), 164.526(d)(1)(iii), 164.526(d)(1)(iv), 164.526(d)(2), 164.526(d)(3), 164.526(d)(4), 164.526(d)(5)(i), 164.526(d)(5)(ii), 164.526(d)(5)(iii), 164.526(e), 164.526(f), 164.530(d)(1), 164.530(d)(2)
    PM-28Risk FramingPMProgram ManagementCC3.2164.306(b)(2)(iv)
    PM-29Risk Management Program Leadership RolesPMProgram ManagementCC1.1, CC1.3, CC3.1, CC3.2, CC4.1, CC5.1, CC9.1, CC9.2164.306(a)(3), 164.306(b)(2)(iv), 164.308(a)(2)
    PM-30(1)Suppliers of Critical or Mission-essential ItemsPMProgram ManagementCC9.1, PI1.1164.308(a)(7)(ii)(E)
    PM-31Continuous Monitoring StrategyPMProgram ManagementCC7.2164.308(a)(1)(i), 164.308(a)(1)(ii)(D), 164.312(b)
    PT-1Policy and ProceduresPTPII Processing and TransparencyCC2.2, CC3.2, CC5.1, CC5.2, CC5.3164.306(b)(1), 164.308(a)(1)(i), 164.308(a)(3)(i), 164.308(a)(4)(i), 164.308(a)(4)(ii)(A), 164.308(a)(6)(i), 164.308(a)(7)(i), 164.310(a)(1), 164.310(a)(2)(ii), 164.310(a)(2)(iv), 164.310(b), 164.310(d)(1), 164.310(d)(2)(i), 164.312(a)(1), 164.312(c)(1), 164.316(a), 164.316(b)(1), 164.316(b)(2)(iii), 164.502(a), 164.530(a)(1)(i), 164.530(i)(1), 164.530(i)(2)(i), 164.530(i)(2)(ii), 164.530(i)(2)(iii), 164.530(i)(3), 164.530(i)(4)(i)(A), 164.530(i)(4)(i)(B), 164.530(i)(5), 164.530(i)(5)(i), 164.530(i)(5)(ii), 164.530(j)(1)(i)
    PT-2Authority to Process Personally Identifiable InformationPTPII Processing and TransparencyP3.1, P4.1164.502(a)(1)(i), 164.502(a)(1)(ii), 164.502(a)(1)(iii), 164.502(a)(5)(i), 164.502(c), 164.502(d)(1), 164.502(i), 164.504(g)(2), 164.506(a), 164.506(c)(1), 164.506(c)(5), 164.508(a)(1), 164.508(a)(2)(i)(B), 164.508(a)(2)(i)(C), 164.510(a)(1)(i)(A), 164.510(a)(1)(i)(B), 164.510(a)(1)(i)(C), 164.510(a)(1)(i)(D), 164.510(a)(1)(ii)(A), 164.510(a)(1)(ii)(B), 164.510(b)(4), 164.512, 164.512(i)(1), 164.512(j)(1), 164.512(j)(1)(i)(A), 164.512(j)(1)(i)(B), 164.512(j)(1)(ii), 164.512(j)(1)(ii)(A), 164.512(j)(1)(ii)(B), 164.512(j)(2)(i), 164.512(j)(2)(ii), 164.512(j)(3), 164.512(j)(4), 164.512(k)(1)(i), 164.512(k)(1)(i)(A), 164.512(k)(1)(i)(B), 164.512(k)(1)(ii), 164.512(k)(1)(iii), 164.512(k)(1)(iv), 164.512(k)(2), 164.512(k)(3), 164.512(k)(4), 164.512(k)(4)(i), 164.512(k)(4)(ii), 164.512(k)(4)(iii), 164.512(k)(5)(i), 164.512(k)(5)(i)(A), 164.512(k)(5)(i)(B), 164.512(k)(5)(i)(C), 164.512(k)(5)(i)(D), 164.512(k)(5)(i)(E), 164.512(k)(5)(i)(F), 164.512(k)(5)(ii), 164.512(k)(5)(iii), 164.512(k)(6)(i), 164.512(k)(6)(ii), 164.512(k)(6)(ii)(1), 164.514(f)(2)(i), 164.514(g), 164.530(i)(4)(ii), 164.530(i)(4)(ii)(B), 164.532(a), 164.532(b), 164.532(c)
    PT-3Personally Identifiable Information Processing PurposesPTPII Processing and TransparencyP4.1164.502(a)(3), 164.508(a)(2)(i)(B), 164.508(c)(1)(i), 164.508(c)(1)(ii), 164.508(c)(1)(iii), 164.508(c)(1)(iv), 164.508(c)(2)(i)(A), 164.508(c)(2)(i)(B)
    PT-4ConsentPTPII Processing and TransparencyP2.1, P3.2164.506(b)(1), 164.508(a)(2), 164.508(c)(1)(v), 164.508(c)(3), 164.510(b)(2)(i), 164.510(b)(2)(ii), 164.510(b)(2)(iii), 164.510(b)(3), 164.514(f)(2)(ii), 164.514(f)(2)(iv), 164.514(f)(2)(v)
    PT-5Privacy NoticePTPII Processing and TransparencyP1.1164.520(a)(1), 164.520(a)(2)(i), 164.520(a)(2)(i)(A), 164.520(a)(2)(i)(B), 164.520(a)(2)(ii), 164.520(a)(2)(ii)(A), 164.520(a)(2)(ii)(B), 164.520(a)(2)(iii), 164.520(b)(1), 164.520(b)(1)(i), 164.520(b)(1)(ii), 164.520(b)(1)(ii)(A), 164.520(b)(1)(ii)(B), 164.520(b)(1)(ii)(C), 164.520(b)(1)(ii)(D), 164.520(b)(1)(ii)(E), 164.520(b)(1)(iv), 164.520(b)(1)(iv)(A), 164.520(b)(1)(iv)(B), 164.520(b)(1)(iv)(C), 164.520(b)(1)(iv)(D), 164.520(b)(1)(iv)(E), 164.520(b)(1)(iv)(F), 164.520(b)(1)(v), 164.520(b)(1)(v)(A), 164.520(b)(1)(v)(B), 164.520(b)(1)(v)(C), 164.520(b)(1)(vi), 164.520(b)(1)(vii), 164.520(b)(1)(viii), 164.520(b)(2)(i), 164.520(b)(2)(ii), 164.520(b)(3), 164.520(c), 164.520(c)(1)(i), 164.520(c)(1)(i)(A), 164.520(c)(1)(i)(B), 164.520(c)(1)(ii), 164.520(c)(1)(iii), 164.520(c)(1)(iv), 164.520(c)(1)(v), 164.520(c)(1)(v)(A), 164.520(c)(1)(v)(B), 164.530(i)(4)(i)(C)
    PT-7Specific Categories of Personally Identifiable InformationPTPII Processing and TransparencyP4.1164.502(c), 164.502(d)(1), 164.504(g)(2), 164.506(a), 164.506(c)(1), 164.506(c)(5), 164.508(a)(1), 164.508(a)(2)(i)(C), 164.510(a)(1)(i)(A), 164.510(a)(1)(i)(B), 164.510(a)(1)(i)(C), 164.510(a)(1)(i)(D), 164.510(a)(1)(ii)(A), 164.510(a)(1)(ii)(B), 164.510(b)(4), 164.512, 164.512(i)(1), 164.512(j)(1), 164.512(j)(1)(i)(A), 164.512(j)(1)(i)(B), 164.512(j)(1)(ii), 164.512(j)(1)(ii)(A), 164.512(j)(1)(ii)(B), 164.512(j)(2)(i), 164.512(j)(2)(ii), 164.512(j)(3), 164.512(j)(4), 164.512(k)(1)(i), 164.512(k)(1)(i)(A), 164.512(k)(1)(i)(B), 164.512(k)(1)(ii), 164.512(k)(1)(iii), 164.512(k)(1)(iv), 164.512(k)(2), 164.512(k)(3), 164.512(k)(4), 164.512(k)(4)(i), 164.512(k)(4)(ii), 164.512(k)(4)(iii), 164.512(k)(5)(i), 164.512(k)(5)(i)(A), 164.512(k)(5)(i)(B), 164.512(k)(5)(i)(C), 164.512(k)(5)(i)(D), 164.512(k)(5)(i)(E), 164.512(k)(5)(i)(F), 164.512(k)(5)(ii), 164.512(k)(5)(iii), 164.512(k)(6)(i), 164.512(k)(6)(ii), 164.512(k)(6)(ii)(1), 164.514(f)(2)(i), 164.514(g), 164.530(i)(4)(ii), 164.530(i)(4)(ii)(B), 164.532(a), 164.532(b), 164.532(c)
    SR-1Policy and ProceduresSRSupply Chain Risk ManagementCC3.3, CC5.3, CC9.1, CC9.2164.308(a)(1)(i), 164.308(a)(3)(i), 164.308(a)(4)(i), 164.308(a)(4)(ii)(A), 164.308(a)(6)(i), 164.308(a)(7)(i), 164.308(b)(1), 164.310(a)(1), 164.310(a)(2)(ii), 164.310(a)(2)(iv), 164.310(b), 164.310(d)(1), 164.310(d)(2)(i), 164.312(a)(1), 164.312(c)(1), 164.312(d), 164.316(a), 164.316(b)(1), 164.316(b)(2)(iii), 164.530(i)(2)(i), 164.530(i)(2)(ii), 164.530(i)(2)(iii), 164.530(i)(3), 164.530(j)(1)(i)
    SR-3(3)Sub-tier Flow DownSRSupply Chain Risk ManagementCC9.1164.308(b)(1), 164.308(b)(2), 164.308(b)(3), 164.314(a)(2)(i), 164.314(a)(2)(iii), 164.314(b)(1), 164.314(b)(2), 164.502(a)(4)(i), 164.502(a)(4)(ii), 164.502(e)(1)(i), 164.502(e)(1)(ii), 164.502(e)(2), 164.504(e)(2)(i), 164.504(e)(2)(i)(A), 164.504(e)(2)(i)(B), 164.504(e)(2)(ii)(D), 164.504(e)(2)(ii)(J), 164.504(e)(4)(i)(B)(ii)(B)(1), 164.504(e)(4)(i)(B)(ii)(B)(2), 164.504(f)(1)(i), 164.504(f)(2)(i), 164.504(f)(2)(ii), 164.504(f)(2)(ii)(A), 164.504(f)(2)(ii)(B), 164.504(f)(2)(ii)(C), 164.504(f)(2)(ii)(D), 164.504(f)(2)(ii)(E), 164.504(f)(2)(ii)(F), 164.504(f)(2)(ii)(G), 164.504(f)(2)(ii)(H), 164.504(f)(2)(ii)(I), 164.504(f)(2)(ii)(J), 164.504(f)(2)(iii)(A), 164.504(f)(2)(iii)(B), 164.504(f)(2)(iii)(C), 164.504(f)(3)(i), 164.504(f)(3)(ii), 164.504(f)(3)(iii), 164.504(f)(3)(iv)
    SR-12Component DisposalSRSupply Chain Risk ManagementCC6.5164.310(d)(2)(i), 164.310(d)(2)(ii)

    Source and method

    Derived from the Top Floor framework mapping dataset: 4,123 cross-framework control mappings across 19 frameworks, every one pivoted through NIST SP 800-53 Rev 5.

    Cross-framework mappings on this page are derived from the 2026.2 release of the Secure Controls Framework, used under CC BY-ND 4.0.

    Mappings are illustrative aids for planning and are not a substitute for the official text of any framework or for an assessor’s judgment. Always verify control requirements against the authoritative publication. Where no official crosswalk exists, the mapping judgment is our own analysis.