Skip to content

GDPRNIST CSF 2.0 crosswalk

A control-by-control mapping between General Data Protection Regulation (EU 2016/679) and NIST Cybersecurity Framework 2.0. 5 mappings.

GDPRNIST CSF 2.0RelationshipNotes
Art. 25
Data protection by design and by default
GV.OC-01
Organizational mission and security role understood
RelatedCurated
Gouvernance et politique de sécurité
Art. 30
Records of processing activities
ID.AM-01
Inventories of hardware managed
RelatedCurated
Inventaire des actifs et des données
Art. 32
Security of processing
PR.DS-01
Confidentiality of data-at-rest protected
PartialCurated
Cryptographie et protection des données
Art. 32
Security of processing
PR.DS-02
Confidentiality of data-in-transit protected
PartialCurated
Cryptographie et protection des données
Art. 32
Security of processing
PR.DS-11
Backups of data created and tested
RelatedCurated
Sauvegarde et restauration

Mappings marked “Official” derive from standards-body informative references; “Curated” mappings are authored by Cyber Compliance and provided for guidance only.