CCPA / CPRA → NIST 800-53 crosswalk
A control-by-control mapping between California Consumer Privacy Act (as amended by CPRA) and NIST SP 800-53 Rev. 5. 3 mappings.
| CCPA / CPRA | NIST 800-53 | Relationship | Notes |
|---|---|---|---|
| §1798.100 Consumers' right to know and notice at collection | PM-1 Information security program plan | RelatedCurated | Gouvernance et politique de sécurité |
| §1798.130 Methods for handling consumer requests | CM-8 System component inventory | RelatedCurated | Inventaire des actifs et des données |
| §1798.150 Duty to implement reasonable security | RA-3 Risk assessment | RelatedCurated | Évaluation et gestion des risques |
Mappings marked “Official” derive from standards-body informative references; “Curated” mappings are authored by Cyber Compliance and provided for guidance only.