Skip to content

LGPDNIST CSF 2.0 crosswalk

A control-by-control mapping between Lei Geral de Proteção de Dados (Brazil, Lei 13.709/2018) and NIST Cybersecurity Framework 2.0. 5 mappings.

LGPDNIST CSF 2.0RelationshipNotes
Art. 37
Records of processing operations
ID.AM-01
Inventories of hardware managed
RelatedCurated
Asset & data inventory
Art. 46
Security measures
PR.DS-01
Confidentiality of data-at-rest protected
PartialCurated
Cryptography & data protection
Art. 46
Security measures
PR.DS-02
Confidentiality of data-in-transit protected
PartialCurated
Cryptography & data protection
Art. 46
Security measures
ID.RA-01
Vulnerabilities identified and recorded
PartialCurated
Risk assessment & management
Art. 50
Good practices and governance rules
GV.OC-01
Organizational mission and security role understood
RelatedCurated
Governance & security policy

Mappings marked “Official” derive from standards-body informative references; “Curated” mappings are authored by Cyber Compliance and provided for guidance only.