A.5.34 Organizational
Privacy and protection of PII
Structured attributes from ISO/IEC 27002:2022 — control type · CIA properties · cybersecurity concept · operational capability · security domain. What do these mean?
Mapped NIST 800-53 r5 controls (11)
Our AI-authored reading (authority llm_unverified, under review) of how this ISO control and each NIST 800-53 control relate. Not an ISO or NIST product.
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- PT-1mostlycovers — Both controls establish and communicate organization-wide policy and procedures for the lawful processing and protection of PII.
- PT-2mostlyaligns with — Both require documented authority and defined responsibilities for processing PII in accordance with applicable laws.
- PT-3mostlyaligns with — Both mandate that the specific purposes for which PII is processed are identified, documented, and communicated to relevant parties.
- PM-18partialaligns with — Both emphasize the need for an overarching privacy program plan and the assignment of privacy leadership roles such as a privacy officer.
- PS-6partialaligns with — Both require personnel to acknowledge and accept responsibilities for handling PII through agreements or role assignments.
- SC-8partialaligns with — Both address the need for technical measures to protect PII during transmission and storage.
Aligned NIST CSF 2.0 outcomes (9)
NIST CSF 2.0 outcomes this ISO control aligns with — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- GV.OC-03mostlyaligns with — The ISO control's explicit focus on compliance with legislation and regulations concerning PII protection maps to the CSF outcome of understanding legal, regulatory, and contractual cybersecurity requirements including privacy obligations.
- GV.PO-01mostlyaligns with — The ISO control's requirement to establish and communicate a topic-specific privacy policy directly supports the CSF outcome of creating policy for managing cybersecurity risks based on organizational context and priorities.
- GV.RR-02mostlyaligns with — Assigning privacy responsibilities and designating a privacy officer to guide personnel and service providers fulfills the CSF outcome of establishing, communicating, and understanding roles and authorities for cybersecurity risk management.
- GV.SC-05partialaligns with — Communicating privacy procedures to service providers and other interested parties involved in PII processing supports the CSF outcome of establishing and integrating supply-chain cybersecurity requirements into contracts.
- PR.AA-05partialaligns with — Implementing technical and organizational measures to protect PII contributes to the CSF outcome of defining, managing, and enforcing access permissions and authorizations in accordance with policy.
Related OWASP ASVS 5.0 requirements (10)
Application-security verification requirements (OWASP ASVS 5.0) this ISO control aligns with; links open the ASVS chapter. Our AI-authored analysis (authority llm_unverified, under review) — many ISO controls have no ASVS counterpart.
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- V14.1.1mostlyaligns with — The ISO requirement to identify and classify PII and establish protection procedures directly supports the ASVS mandate to identify and classify all sensitive data processed by the application.
- V14.1.2mostlyaligns with — Defining documented protection requirements for PII under the ISO control aligns with the ASVS requirement that each sensitivity level must have explicit, documented protection controls.
- V14.2.4partialaligns with — The ISO directive to implement technical and organizational measures for PII protection corresponds to the ASVS requirement that sensitive-data handling must include encryption, integrity, logging, access control and retention rules.
- V14.2.7partialaligns with — The ISO emphasis on procedures that respect relevant legislation for PII retention and deletion aligns with the ASVS requirement to enforce data-retention classification and automatic removal of unnecessary sensitive data.
Related weaknesses / CWE (14)
Weakness classes this ISO control helps prevent or mitigate — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- CWE-200mostlyprevents — Requiring defined procedures, assigned roles, and technical/organizational measures for handling PII reduces the chance that sensitive personal data will be exposed to unauthorized actors through inadequate handling or missing safeguards.
- CWE-213mostlyprevents — PII protection explicitly reconciles developer exposure with data-subject or regulator expectations.
- CWE-201partialmitigates — PII-protection requirements reduce the chance of sending personal data to unauthorized recipients.
- CWE-212partialprevents — PII-protection requirements include removing identifiers before storage or disclosure.
- CWE-284partialprevents — Establishing explicit responsibilities and controls for PII processing limits situations where access control mechanisms fail to restrict who can view or manipulate personal data.
- CWE-315partialprevents — Addresses privacy and PII protection, which would necessitate securing sensitive data in cookies.
- CWE-359partialprevents — Mandating privacy procedures and a designated privacy officer helps ensure that private personal information is not disclosed without proper authorization or necessity.
- CWE-539partialmitigates — Privacy and PII protection policies require safeguards against exposing sensitive data via cookies.
- CWE-522nonenone — Specifying procedures and controls for PII handling encourages the use of adequate credential protection mechanisms when personal data or related accounts are accessed or stored.
- CWE-732nonenone — Requiring appropriate technical and organizational measures for PII protection decreases the likelihood that critical resources containing personal information will be assigned overly permissive permissions.
Control IDs, short titles and the structured attribute table (control type, CIA properties, cybersecurity-concept, operational capability, security domain) are facts from ISO/IEC 27001:2022 Annex A / ISO/IEC 27002:2022. The full implementation guidance prose lives in ISO/IEC 27002:2022 — not reproduced here. Cross-walks to NIST 800-53, NIST CSF 2.0, OWASP ASVS, CWE, MITRE ATT&CK and OWASP Web Top 10 are our own AI-authored analysis (authority llm_unverified, under review), not an ISO, NIST, MITRE or OWASP product — how ours compare.