From the control library

How compliance programmes actually fail

826 distinct failure modes, taken from the control libraries themselves. Ranked by how many independent standards warn about the same one.

Data measured , page built 22 September 2026 at 16:18 UTC.

Why rank it this way

Every control in our corpus records how implementations commonly fail, written when that control was verified against its source document. Across 20,473 controls that is a large catalogue of what goes wrong, and the useful ordering is not our opinion of severity: it is how many separate standards, written by different bodies in different jurisdictions for different industries, independently warn about the same thing. Twenty-four frameworks converging on one failure is a stronger claim than any score we could invent.

Sorted by how many independent frameworks warn about the same failure, most-converged first. That ordering is a count, not our opinion of severity, and it puts the problems the whole industry agrees on at the top.

The fourteen most-converged failures. The full catalogue follows.

Failure modeFrameworks ControlsExamples of who warns
Roles undefined
2427APRA CPS 230 Operational Risk Management, APRA CPS 234, AWS Well-Architected Security Pillar
findings not remediated
1417AS9100D, AS9100D:2016, ASIC Cyber Resilience Good Practices
no annual review
13266th Anti-Money Laundering Directive (AMLD6, Directive (EU) 2018/1673), Australian Information Security Manual, Bank Secrecy Act / Anti-Money Laundering (BSA/AML)
Bundled consent
1212Code of Conduct on Data Protection for Research (GDPR Article 40), LGPD, Law No. 09-08 on the Protection of Individuals with Regard to the Processing of Personal Data
Tooling fragmented
Event wagering systems: technical certification and operational audit, Farm assurance: food safety, workers, environment, GxP computerized systems: risk-based compliance and fitness for intended use across the system life cycle
1111GAMP 5, GHG Protocol, GLI-33
No retention schedule
Digital investigation processes, Emergency management, business continuity and crisis management programs, Organizational resilience: security, preparedness and business continuity management
1011APPI, ASIS SPC.1-2009, Bermuda Personal Information Protection Act 2016 (PIPA)
No withdrawal mechanism
1010Bosnia and Herzegovina Law on Protection of Personal Data (2006, amended 2011), Brunei Personal Data Protection Order 2022 (PDPO), Cambodia Sub-Decree on Personal Data Protection (Sub-Decree No. 134)
no ongoing monitoring
IT risk management supervision of financial institutions and technology service providers, Insurance cybersecurity, PIN and cryptographic key security for payment transactions
921C-TPAT, C2M2, FFIEC IT Examination Handbook
Objectives not measurable
IT service management, Organizational resilience: security, preparedness and business continuity management, Privacy risk management
920AS9100D:2016, ASIS SPC.1-2009, ISO 28001:2007 Supply Chain Security Management
No sanctions exposure analysis
99LGPD, Law No. 09-08 on the Protection of Individuals with Regard to the Processing of Personal Data, Law No. 172-13 on the Protection of Personal Data
Flat networks
840Azure Security Benchmark, Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1, FFIEC IT Examination Handbook
no executive sponsor
Data quality management, PIN and cryptographic key security for payment transactions, Payment account data encryption from point of interaction to decryption
817API 1164, ISO 8000, NIST SP 800-161
no trend analysis
813BRCGS Global Standard for Food Safety Issue 9, FFIEC IT Examination Handbook, IEC 62304:2015 Medical Device Software Lifecycle Processes
No inventory
89Estonia Personal Data Protection Act (Isikuandmete kaitse seadus, 2019), ISO 22739:2024, ISO 26000:2010
Pipeline not tracked
Banking supervision, Event wagering systems: technical certification and operational audit, Financial privacy
89GLBA, GLI-33, GRI Standards
No insider threats
Occupational health and safety
88AS9100D:2016, ISO 13485, ISO 14001
no withdrawal mechanism
88Bosnia and Herzegovina Law on Protection of Personal Data (2006, amended 2011), Brunei Personal Data Protection Order 2022 (PDPO), Cambodia Sub-Decree on Personal Data Protection (Sub-Decree No. 134)
Tactical only
Occupational health and safety
88AS9100D:2016, ISO 13485, ISO 14001
Catalogue not refreshed
Occupational health and safety
88AS9100D:2016, ISO 13485, ISO 14001
Coverage gaps for in scope entities or systems
727UAE Virtual Asset Regulatory Authority (VARA) Regulations, UK Age Appropriate Design Code (Children's Code), UK Bribery Act 2010
Procedure exists but execution inconsistent
727UAE Virtual Asset Regulatory Authority (VARA) Regulations, UK Age Appropriate Design Code (Children's Code), UK Bribery Act 2010
Owner accountability not codified
727UAE Virtual Asset Regulatory Authority (VARA) Regulations, UK Age Appropriate Design Code (Children's Code), UK Bribery Act 2010
Review cadence missed or undocumented
727UAE Virtual Asset Regulatory Authority (VARA) Regulations, UK Age Appropriate Design Code (Children's Code), UK Bribery Act 2010
Flat network
79AWS Well-Architected Security Pillar, AWWA Cybersecurity Guidance for the Water Sector (American Water Works Association), CISA Cross-Sector Cybersecurity Performance Goals (CPG) 2.0
Multi-framework alignment ad-hoc
Banking supervision, Financial customer information security
79FTC GLBA Safeguards Rule (16 CFR Part 314), GHG Protocol, GRI Standards
Reviews skipped
AI risk management
78COBIT 2019, EASA Part-IS, FFIEC IT Examination Handbook
Indefinite retention
Data protection and privacy, Personal information protection
78African Union Malabo Convention, Armenia Law on Protection of Personal Data (2015), Cambodia Sub-Decree on Personal Data Protection (Sub-Decree No. 134)
No review cadence
78COBIT 2019, ISO 28001:2007 Supply Chain Security Management, ISO/IEC 27003:2017
Transfer without lawful basis
77LGPD, Latvia Personal Data Processing Law (Fizisko personu datu apstrades likums, 2018), Law No. 172-13 on the Protection of Personal Data
Findings not closed
Food safety and quality management certification, Whistleblowing management
77BRCGS Global Standard for Food Safety Issue 9, FSSC 22000, ISO 37001
No appeals path
77LGPD, Law No. 09-08 on the Protection of Individuals with Regard to the Processing of Personal Data, Law No. 2013-450 of 19 June 2013 on the Protection of Personal Data
Late responses
77NIST SP 800-122, Nebraska Data Privacy Act, Netherlands GDPR Implementation Act (UAVG
Register stale
77FBI CJIS Security Policy, FFIEC Cybersecurity Assessment Tool (CAT), ISO 27019
No certification
77Latvia Personal Data Processing Law (Fizisko personu datu apstrades likums, 2018), Law on Personal Data Protection (Official Gazette No. 42/2020), Ley Orgánica de Protección de Datos Personales (LOPDP)
Missing training
77BS 65000:2014, NIS2 Directive, NIST Privacy Framework
No age verification
Biometric privacy, Data protection and privacy
77Illinois Biometric Information Privacy Act (BIPA), Latvia Personal Data Processing Law (Fizisko personu datu apstrades likums, 2018), Nebraska Data Privacy Act
No encryption
77C2M2, LGPD, Law on Personal Data Protection (Official Gazette No. 42/2020)
ROPA incomplete
77BSI IT-Grundschutz, LGPD, Law No. 2013-450 of 19 June 2013 on the Protection of Personal Data
IP register incomplete, ownership disputes likely
Business continuity management, Energy management, Facility management
619ISO 22313:2020, ISO 37002:2021, ISO 39001:2012
Time allocation for innovation crowded out by BAU
Business continuity management, Energy management, Facility management
617ISO 22313:2020, ISO 37002:2021, ISO 39001:2012
Innovation budget not ring-fenced from operating budget
Business continuity management, Energy management, Facility management
617ISO 22313:2020, ISO 37002:2021, ISO 39001:2012
Strategic intelligence siloed in one team
Business continuity management, Energy management, Facility management
617ISO 22313:2020, ISO 37002:2021, ISO 39001:2012
Competence requirements for innovation roles not defined
Business continuity management, Energy management, Facility management
616ISO 22313:2020, ISO 37002:2021, ISO 39001:2012
Trend scanning is ad hoc and undocumented
Business continuity management, Energy management, Facility management
616ISO 22313:2020, ISO 37002:2021, ISO 39001:2012
Partnership agreements lack IP and confidentiality clauses
Business continuity management, Energy management, Facility management
616ISO 22313:2020, ISO 37002:2021, ISO 39001:2012
Stakeholder map omits external innovation partners (universities, startups)
Business continuity management, Energy management, Facility management
616ISO 22313:2020, ISO 37002:2021, ISO 39001:2012
No resource plan tied to portfolio priorities
Business continuity management, Energy management, Facility management
615ISO 22313:2020, ISO 37002:2021, ISO 39001:2012
Portfolio biased toward horizon 1 incremental projects
Business continuity management, Energy management, Facility management
614ISO 22313:2020, ISO 37002:2021, ISO 39001:2012
Executive sponsorship limited to lip service, no time committed
Business continuity management, Energy management, Facility management
613ISO 22313:2020, ISO 37002:2021, ISO 39001:2012
Context analysis treated as one-off, not refreshed annually
Business continuity management, Energy management, Facility management
613ISO 22313:2020, ISO 37002:2021, ISO 39001:2012
Innovation strategy disconnected from corporate strategy
Business continuity management, Energy management, Facility management
613ISO 22313:2020, ISO 37002:2021, ISO 39001:2012
Opportunities and risks tracked separately with no link to objectives
Business continuity management, Energy management, Facility management
613ISO 22313:2020, ISO 37002:2021, ISO 39001:2012
Lagging indicators only, no leading indicators
Business continuity management, Energy management, Facility management
613ISO 22313:2020, ISO 37002:2021, ISO 39001:2012
Tools and methods inconsistent across teams
Business continuity management, Energy management, Facility management
613ISO 22313:2020, ISO 37002:2021, ISO 39001:2012
No clear accountability for innovation outcomes
Business continuity management, Energy management, Facility management
613ISO 22313:2020, ISO 37002:2021, ISO 39001:2012
Strategic intelligence not feeding into innovation decisions
Business continuity management, Energy management, Facility management
612ISO 22313:2020, ISO 37002:2021, ISO 39001:2012
Evaluation criteria differ across portfolio without rationale
Business continuity management, Energy management, Facility management
612ISO 22313:2020, ISO 37002:2021, ISO 39001:2012
Roles and responsibilities for innovation undefined
Business continuity management, Energy management, Facility management
612ISO 22313:2020, ISO 37002:2021, ISO 39001:2012
Innovation maturity baseline never established
Business continuity management, Energy management, Facility management
612ISO 22313:2020, ISO 37002:2021, ISO 39001:2012
No procedure
611Bermuda Personal Information Protection Act 2016 (PIPA), Bosnia and Herzegovina Law on Protection of Personal Data (2006, amended 2011), Botswana Data Protection Act (2024)
Inventory incomplete
Attestation and assurance standards, Criminal justice information security, Information security measurement
611FBI CJIS Security Policy, ISO/IEC 27004:2016, ISO/IEC 27011:2024
Internal audits of IMS not scheduled
Business continuity management, Energy management, Facility management
610ISO 22313:2020, ISO 37002:2021, ISO 39001:2012
Governance forum lacks decision-making authority
Business continuity management, Energy management, Facility management
610ISO 22313:2020, ISO 37002:2021, ISO 39001:2012
Risk treatment plans absent for high-uncertainty bets
Business continuity management, Energy management, Facility management
69ISO 22313:2020, ISO 37002:2021, ISO 39001:2012
KPIs measure activity (idea count) not outcomes (revenue, adoption)
Business continuity management, Energy management, Facility management
69ISO 22313:2020, ISO 37002:2021, ISO 39001:2012
Customer feedback not systematically captured
Business continuity management, Energy management, Facility management
69ISO 22313:2020, ISO 37002:2021, ISO 39001:2012
Root cause analysis stops at symptom level
Business continuity management, Energy management, Facility management
69ISO 22313:2020, ISO 37002:2021, ISO 39001:2012
Culture barriers to risk-taking not addressed by leadership
Business continuity management, Energy management, Facility management
69ISO 22313:2020, ISO 37002:2021, ISO 39001:2012
Lessons learned stored but never reused
Business continuity management, Energy management, Facility management
68ISO 22313:2020, ISO 37002:2021, ISO 39001:2012
Maturity reassessment skipped year over year
Business continuity management, Energy management, Facility management
68ISO 22313:2020, ISO 37002:2021, ISO 39001:2012
No audit trail
67Authorised Economic Operator (AEO) Programmes, ISO 27018, ISO 27043
Metrics not tracked
Financial privacy, GxP computerized systems: risk-based compliance and fitness for intended use across the system life cycle
66French Sapin II Law (Law No. 2016-1691), GAMP 5, GHG Protocol
Effectiveness not verified
Road traffic safety management, Supply chain security, Whistleblowing management
66ISO 28001:2007 Supply Chain Security Management, ISO 37002:2021, ISO 37301
No tabletop exercises
66Bermuda Monetary Authority (BMA) Cyber Risk Management Code of Conduct, Kuwait Data Privacy Protection Regulation (KDPPR, 2021, Kuwait National Cybersecurity Framework
Lessons not actioned
Business continuity management, Business continuity, supply chain, Digital investigation processes
66Argyris Double-Loop Learning, ISO 22313:2020, ISO 30401
No periodic review
Emergency and incident management, Governance and management of enterprise information and technology, Information security measurement
66COBIT 2019, ISO 22320:2018, ISO 37002:2021
Metrics gaps
66GLI-33, GLOBALG.A.P. Integrated Farm Assurance (IFA) Standard v6, GS1 Global Standards
Design-only testing
66AS9100D, AS9100D:2016, ISO 13485
Internal traffic between services unencrypted within trusted zones
569FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 LOW
Firewall rule base contains stale allow any entries
569FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 LOW
Server room doors propped open during cooling failures
565FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 LOW
CCTV coverage gaps at loading docks and equipment delivery areas
564FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 LOW
Access reviews performed but exceptions never remediated
560FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 LOW
Legacy TLS versions remain enabled on external services
555FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 LOW
Role definitions drift from documented matrix without change control
555FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 LOW
Service accounts excluded from periodic recertification
551FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 LOW
Clock drift across hosts breaks event correlation
549FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 LOW
Emergency changes bypass CAB and lack retrospective review
549FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 LOW
Privileged user activity not isolated for independent review
549FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 LOW
Unauthorised software present on endpoints not flagged by tooling
548FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 LOW
Federation trust relationships not reviewed when partnerships change
548FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 LOW
Privileged accounts shared across administrators without individual accountability
547FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 LOW
Cryptographic keys stored alongside the data they protect
545FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 LOW
Contractor screening relies on vendor attestation without sampling
545FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 LOW
Supplier incidents discovered through news rather than contractual notification
544FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 LOW
MFA exceptions granted indefinitely without compensating controls
543FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 LOW
Vendor SOC reports collected but exceptions not analysed
542FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 LOW
Environmental sensor alerts route to unmonitored mailboxes
541FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 LOW
Tailgating observed without challenge during walkthroughs
541FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 LOW
Flat networks expose sensitive workloads without segmentation
541FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 LOW
Severity criteria inconsistent across teams leading to under reporting
539FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 LOW
Flow down clauses present in master agreements but missing from statements of work
539FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 LOW
Critical patches deployed beyond the policy SLA without exception
538FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 LOW
Tabletop exercises lack participation from business owners
537FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 LOW
EDR coverage gaps on legacy operating systems
537FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 LOW
Alternate site capacity not validated against current load
537FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 LOW
Sanctions applied informally without HR documentation
535FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 LOW
Baselines exist on paper but production hosts drift without alerting
534FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 LOW
Documentation exists but lacks evidence of periodic refresh
534South Africa Promotion of Access to Information Act (PAIA), South Korea ISMS-P, South Korea Korea Internet Self-Governance Organisation (KISO) Code of Ethics
Lessons learned captured but corrective actions not tracked to closure
534FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 LOW
Stale accounts retained for terminated personnel beyond the 24 hour SLA
534FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 LOW
Critical log sources missing from the SIEM with no detection coverage
534FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 LOW
Code scan findings closed without verification of fix
533FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 LOW
Assessment scope omits inherited cloud provider controls
533FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 LOW
Open source components used without SBOM or licence review
533FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 LOW
Continuous monitoring metrics collected but not reported to leadership
533FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 LOW
Decommissioned drives stored unencrypted while awaiting destruction
532FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 LOW
USB usage permitted without DLP inspection or encryption
532FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 LOW
Reviewers acknowledge alerts but do not document investigation outcomes
530FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 LOW
Counterfeit detection procedures absent for hardware refresh cycles
530FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 LOW
Position risk designations not reviewed when responsibilities change
530FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 LOW
RTO and RPO targets undefined for tier two systems
530FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 LOW
Password complexity enforced but reuse not blocked across systems
529FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 LOW
Hardening benchmarks applied at build but not re evaluated annually
529FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 LOW
Alert backlog exceeds analyst capacity leading to triage delays
529FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 LOW
System security plan not refreshed after material system changes
529FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 LOW
Sub tier suppliers not identified for critical components
529FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 LOW
Shared accounts authenticate without traceability to individuals
529FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 LOW
Detection coverage gaps allow incidents to be discovered externally
529FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 LOW
Threat modelling performed inconsistently across product teams
528FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 LOW
Security requirements absent from procurement templates for low value buys
528FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 LOW
Visitor logs incomplete or escort sign offs missing
528FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 LOW
Plan not updated after major architecture changes
527FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 LOW
Termination access removal exceeds documented SLA
525FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 LOW
Audit log retention shorter than the policy mandated period
525FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 LOW
Background checks not re run when employees move to higher risk roles
525FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 LOW
Privacy considerations addressed separately from security planning
525FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 LOW
Asset inventory missing cloud workloads and ephemeral resources
524FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 LOW
Risk register entries lack named owner or due date
524FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 LOW
Rules of behaviour acknowledged once but not refreshed annually
524FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 LOW
Vendor engineers granted standing access rather than session based access
524FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 LOW
Authorization boundary description does not match the asset inventory
523FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 LOW
Role based training not refreshed when job duties change
520FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 LOW
Default vendor credentials remain on appliances and IoT devices
520FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 LOW
Phishing failures not followed by remedial coaching
520FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 LOW
POAM items past due without justification or risk acceptance
520FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 LOW
Remote maintenance sessions unmonitored after initial authentication
519FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 LOW
Backups taken but restore tests never performed end to end
519FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 LOW
Third party incident responder retainer expired
519FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 LOW
Maintenance vendors lack signed confidentiality and security clauses
519FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 LOW
Destruction certificates lack serial numbers tying back to inventory
518FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 LOW
Media classification labels missing on physical assets
518FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 LOW
Anti malware signatures not updated on isolated network segments
518FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 LOW
Reauthorization scheduled past the policy required interval
518FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 LOW
Vendor risk tier ratings static despite changes in service scope
515FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 LOW
Notification timelines miss jurisdictional regulatory deadlines
515FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 LOW
Contractors and third parties not enrolled in mandatory training
515FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 LOW
Knowledge from past projects not captured or reused
Business continuity management, Facility management, Innovation management
515ISO 22313:2020, ISO 37002:2021, ISO 39001:2012
Maintenance tools not sanitised before removal from secure areas
515FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 LOW
Training content not reviewed annually for current threat trends
515FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 LOW
Backup tapes shipped without tamper evident packaging
514FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 LOW
Input validation handled inconsistently across microservices
514FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 LOW
Unclear escalation thresholds
Financial institution cybersecurity self-assessment, Information security baseline protection (ISMS and technical, organisational, personnel and infrastructure requirements)
514BSI IT-Grundschutz, Bahrain PDPL, Belgium CyberFundamentals
Planning artefacts lack version history and approval signatures
514FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 LOW
Architecture diagrams missing third party and SaaS dependencies
514FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 LOW
Long-lived tokens
514AWS Well-Architected Security Pillar, ISO 27017, ISO 27018
Initiative prioritisation done by HiPPO not criteria
Business continuity management, Energy management, Facility management
512ISO 22313:2020, ISO 39001:2012, ISO 41001:2018
Innovation objectives lack measurable targets
Business continuity management, Energy management, Facility management
512ISO 22313:2020, ISO 39001:2012, ISO 41001:2018
Recovery untested
512AWS Well-Architected Security Pillar, Australian Energy Sector Cyber Security Framework (AESCSF), Authorised Economic Operator (AEO) Programmes
IMS scope undefined or inconsistent across business units
Business continuity management, Energy management, Innovation management
511ISO 22313:2020, ISO 37002:2021, ISO 39001:2012
Internal capability gaps not assessed against strategy
Business continuity management, Energy management, Facility management
511ISO 22313:2020, ISO 37002:2021, ISO 41001:2018
Management reviews skip innovation as an agenda item
Business continuity management, Facility management, Innovation management
511ISO 22313:2020, ISO 37002:2021, ISO 39001:2012
Benchmarking against peers absent
Business continuity management, Energy management, Innovation management
510ISO 22313:2020, ISO 37002:2021, ISO 39001:2012
Scope unclear
59GLI-33, HKMA Cyber Resilience Assessment Framework (C-RAF), ISO/IEC 27014:2020
Feedback loops from operations back to strategy missing
Business continuity management, Energy management, Innovation management
59ISO 22313:2020, ISO 37002:2021, ISO 39001:2012
Annual-only review
59FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 MODERATE
Scope ambiguous
59Estonia Personal Data Protection Act (Isikuandmete kaitse seadus, 2019), ISO 22000, ISO/IEC 23837
Metrics absent
59COBIT 2019, FFIEC Cybersecurity Assessment Tool (CAT), FFIEC IT Examination Handbook
Roadmap not updated when strategy changes
Business continuity management, Energy management, Innovation management
58ISO 22313:2020, ISO 37002:2021, ISO 39001:2012
Improvement register stale, items older than 12 months unactioned
Business continuity management, Facility management, Innovation management
57ISO 22313:2020, ISO 37002:2021, ISO 39001:2012
Unclear roles
57APRA CPS 234, Azure Security Benchmark, NIST SP 800-115 (Technical Guide to Information Security Testing and Assessment)
Evidence not retained
Information security management system auditing
57Bahrain PDPL, Bank Secrecy Act / Anti-Money Laundering (BSA/AML), Barbados Data Protection Act 2019
No screening
56Australian Energy Sector Cyber Security Framework (AESCSF), Authorised Economic Operator (AEO) Programmes, CMMC 2.0
Findings not remediated
56ASIC Cyber Resilience Good Practices, BSIMM, Bosnia and Herzegovina Law on Protection of Personal Data (2006, amended 2011)
no monitoring
56Azure Security Benchmark, BREEAM, DAMA-DMBOK2
No methodology
56Azure Security Benchmark, C2M2, ISO/IEC 27004:2016
Annual review skipped
Financial customer information security
56FSSC 22000, FTC GLBA Safeguards Rule (16 CFR Part 314), French Sapin II Law (Law No. 2016-1691)
Risk monitoring siloed
55FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 LOW
Audit rights never exercised
55ISO 37001, Rhode Island Data Transparency and Privacy Protection Act (RIDTPPA), Serbia Law on Personal Data Protection (2018)
Exclusions unjustified
55AS9100D, AS9100D:2016, ISO 13485
Remediation not tracked
55Australian Energy Sector Cyber Security Framework (AESCSF), Bermuda Personal Information Protection Act 2016 (PIPA), Botswana Data Protection Act (2024)
Module absent
55FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 LOW
Marketing without opt-in
55Law on Personal Data Protection (Official Gazette No. 42/2020), Ley Orgánica de Protección de Datos Personales (LOPDP), Liechtenstein DPA
Controls not traced to risks
55AS9100D, AS9100D:2016, ISO 13485
No incident response plan
Cybersecurity of networks, critical information infrastructure and network information, Personal information protection
55BIMCO Cyber Security, C2M2, China Cybersecurity Law (CSL)
Missing FedRAMP banner language
55FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 LOW
Shared admin accounts
Telecommunications information security
553GPP 5G Security Architecture (TS 33.501), Cambodia Sub-Decree on Personal Data Protection (Sub-Decree No. 134), ISO/IEC 27011:2024
no concentration analysis
Financial institution cybersecurity self-assessment, IT risk management supervision of financial institutions and technology service providers, Organizational resilience
55AASB S2 Climate-related Disclosures, BS 65000:2014, FFIEC Cybersecurity Assessment Tool (CAT)
Claims not handled
55Bermuda Personal Information Protection Act 2016 (PIPA), Bosnia and Herzegovina Law on Protection of Personal Data (2006, amended 2011), Botswana Data Protection Act (2024)
No change triggers
55FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 LOW
No phishing simulation
55Kuwait National Cybersecurity Framework, Laos Law on Prevention and Combating Cybercrime (2015), Lloyd's Minimum Standards
No documented lawful basis
Personal data protection
55African Union Malabo Convention, Danish Data Protection Act (Databeskyttelsesloven), Data Protection Act 2017
Slow response
55LGPD, Law No. 09-08 on the Protection of Individuals with Regard to the Processing of Personal Data, Law No. 2013-450 of 19 June 2013 on the Protection of Personal Data
Emergency maintenance performed without retrospective documentation
55FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 LOW
Findings closed without verification
Food safety management, Laboratory competence
55ISO 22000:2018, ISO/IEC 17025:2017, NY DFS 23 NYCRR 500
Effectiveness of corrective action never reviewed
Asset management, Environmental management, Sustainable development in communities; management system
55ISO 14001:2015, ISO 14001:2026, ISO 37101:2016
No closure tracking
Aviation, space and defense quality management system on ISO 9001:2015
55AS9100D, Argyris Double-Loop Learning, BSIMM
no tabletop exercises
55Kuwait National Cybersecurity Framework, Laos Law on Prevention and Combating Cybercrime (2015), Ley Orgánica de Protección de Datos Personales (LOPDP)
No key management
55Bermuda Monetary Authority (BMA) Cyber Risk Management Code of Conduct, C2M2, NATO STANAG 4774 (Confidentiality Metadata Labels) and STANAG 4778 (Metadata Binding)
No phishing tests
55FedRAMP High, FedRAMP Moderate, ISO 27799
No annual training
55Laos Law on Prevention and Combating Cybercrime (2015), Law on Personal Data Protection (Official Gazette No. 42/2020), Ley Orgánica de Protección de Datos Personales (LOPDP)
no board reporting
IT risk management supervision of financial institutions and technology service providers, Whistleblowing management
55FFIEC IT Examination Handbook, ISO 37002:2021, Kuwait National Cybersecurity Framework
register incomplete
Criminal justice information security, Health information security, IT risk management supervision of financial institutions and technology service providers
55FBI CJIS Security Policy, FFIEC IT Examination Handbook, ISO 27799:2025
No independent assurance
Business continuity, business impact analysis, Privacy framework
55ISO 30414:2018, ISO/IEC 29100:2024, ISO/TS 22317:2021
no annual refresh
556th Anti-Money Laundering Directive (AMLD6, Directive (EU) 2018/1673), Bank Secrecy Act / Anti-Money Laundering (BSA/AML), Illinois Biometric Information Privacy Act (BIPA)
Nonconformities not logged or trended
Energy management, Facility management, Innovation management
55ISO 37002:2021, ISO 39001:2012, ISO 41001:2018
Shared accounts in use
Information security baseline protection (ISMS and technical, organisational, personnel and infrastructure requirements), Supply chain security
55BSI IT-Grundschutz, Cyber Essentials Plus, ISO 28001:2007 Supply Chain Security Management
exclusions undocumented
Greenhouse gas accounting, reporting, verification and validation
55APRA CPS 230 Operational Risk Management, CFTC System Safeguards (17 CFR 37, 38, 39, 49), ISO 14064
Evidence is point in time rather than ongoing
Aviation, space and defense quality management system on ISO 9001:2015, Organizational resilience: security, preparedness and business continuity management
444AS9100D, ASIS SPC.1-2009, Argyris Double-Loop Learning
Policy document exists but lacks evidence of board approval or refresh cycle
439Solvency II, South Korea ISMS-P, South Korea Korea Internet Self-Governance Organisation (KISO) Code of Ethics
Accountabilities defined on paper but not reflected in performance objectives
439Solvency II, South Korea ISMS-P, South Korea Korea Internet Self-Governance Organisation (KISO) Code of Ethics
Unmanaged endpoints
429Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1, PCI P2PE, PCI PIN Security
Control owner unclear or vacant
Aviation, space and defense quality management system on ISO 9001:2015, Organizational resilience: security, preparedness and business continuity management
422AS9100D, ASIS SPC.1-2009, Argyris Double-Loop Learning
No metric tracks control effectiveness
Aviation, space and defense quality management system on ISO 9001:2015, Organizational resilience: security, preparedness and business continuity management
422AS9100D, ASIS SPC.1-2009, Argyris Double-Loop Learning
No exit plan
416BSI IT-Grundschutz, PCI P2PE, PCI PIN Security
default credentials
PIN and cryptographic key security for payment transactions, Payment account data encryption from point of interaction to decryption, Payment software security
416NIST SP 800-123, PCI P2PE, PCI PIN Security
late notifications
PIN and cryptographic key security for payment transactions, Payment account data encryption from point of interaction to decryption, Payment software security
416PCI P2PE, PCI PIN Security, PCI SSF
MFA not enforced for privileged or remote access
Information security baseline protection (ISMS and technical, organisational, personnel and infrastructure requirements)
414BSI IT-Grundschutz, Bahrain PDPL, Bank Secrecy Act / Anti-Money Laundering (BSA/AML)
Shared or generic accounts retained
Information security baseline protection (ISMS and technical, organisational, personnel and infrastructure requirements)
414BSI IT-Grundschutz, Bahrain PDPL, Bank Secrecy Act / Anti-Money Laundering (BSA/AML)
Stale or dormant accounts not deprovisioned
Information security baseline protection (ISMS and technical, organisational, personnel and infrastructure requirements)
414BSI IT-Grundschutz, Bahrain PDPL, Bank Secrecy Act / Anti-Money Laundering (BSA/AML)
Access reviews skipped or rubber-stamped
Information security baseline protection (ISMS and technical, organisational, personnel and infrastructure requirements)
414BSI IT-Grundschutz, Bahrain PDPL, Bank Secrecy Act / Anti-Money Laundering (BSA/AML)
stale policies
413DAMA-DMBOK2, PCI P2PE, PCI PIN Security
Lessons learned never closed out
Information security baseline protection (ISMS and technical, organisational, personnel and infrastructure requirements)
413BSI IT-Grundschutz, Bahrain PDPL, Belgium CyberFundamentals
Policy not communicated
Aviation information security management, Knowledge management
413AS9100D:2016, EASA Part-IS, ISO 30401
Forensic readiness lacking outside core systems
Information security baseline protection (ISMS and technical, organisational, personnel and infrastructure requirements)
413BSI IT-Grundschutz, Bahrain PDPL, Belgium CyberFundamentals
Playbooks untested for major scenarios
Information security baseline protection (ISMS and technical, organisational, personnel and infrastructure requirements)
413BSI IT-Grundschutz, Bahrain PDPL, Belgium CyberFundamentals
Lessons not shared
Information security management system auditing, Sustainable procurement
411ISO 20400:2017, ISO 45001, ISO 9001
No traceability
49BSIMM, COBIT 2019, ISO 26262:2018
No independent assessment
49CFTC System Safeguards (17 CFR 37, 38, 39, 49), Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1, NIST SP 800-128
Metrics not tied to outcomes
48ISO 30401, NIST SP 800-53 Rev 5 LOW, NIST SP 800-53 Rev 5 MODERATE
Policies past their review date
Aviation, space and defense quality management system on ISO 9001:2015, Organizational resilience: security, preparedness and business continuity management
48AS9100D, ASIS SPC.1-2009, Aged Care Quality Standards (Australia)
AI inventory missing shadow deployments by business units
47South Africa Promotion of Access to Information Act (PAIA), South Korea Korea Internet Self-Governance Organisation (KISO) Code of Ethics, Sweden Data Protection Act (Dataskyddslag, 2018:218)
Coverage gaps
47BSIMM, CISA Cross-Sector Cybersecurity Performance Goals (CPG) 2.0, NIST SP 800-171
Innovation policy not formally approved or communicated
Facility management, Innovation management, Road traffic safety management
47ISO 37002:2021, ISO 39001:2012, ISO 41001:2018
no key rotation
46FFIEC IT Examination Handbook, ISO/IEC 27010:2015, NIST SP 800-171 Rev 3
Corrective actions closed without verifying effectiveness
Business continuity management, Innovation management, Road traffic safety management
46ISO 22313:2020, ISO 37002:2021, ISO 39001:2012
Inventory stale
46Australian Energy Sector Cyber Security Framework (AESCSF), C2M2, FFIEC Cybersecurity Assessment Tool (CAT)
Bias and safety testing not performed at required cadence
46South Africa Promotion of Access to Information Act (PAIA), South Korea Korea Internet Self-Governance Organisation (KISO) Code of Ethics, Sweden Data Protection Act (Dataskyddslag, 2018:218)
Lessons not captured
Governance of organizations
45ISO 37000:2021, ISO 37001, ISO/IEC 27003:2017
Late notification
45ISO/IEC 27007:2020, NIST SP 800-122, Nigeria Data Protection Regulation (NDPR)
No exit confirmation
Enterprise risk management
45ISO 15189:2022, ISO 19011, ISO 27018
No effectiveness check
Aviation information security management
45AS9100D:2016, EASA Part-IS, ISO 19011
Actions not tracked
Whistleblowing management
45ISO 22000, ISO 37001, ISO 37002:2021
No automated-decision opt-out
45Latvia Personal Data Processing Law (Fizisko personu datu apstrades likums, 2018), Law No. 2013-450 of 19 June 2013 on the Protection of Personal Data, Law on Personal Data Protection (Official Gazette No. 42/2020)
No correction workflow
45ISO 27018, ISO/IEC 27018:2019, NIST SP 800-53 Rev 5 LOW
No verification step
45FedRAMP High, ISO 22313:2020, ISO 22320:2018
No rollback capability
44FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 MODERATE
Setuid binaries unaudited
44FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 MODERATE
Transfers not inventoried
44Bermuda Personal Information Protection Act 2016 (PIPA), Bosnia and Herzegovina Law on Protection of Personal Data (2006, amended 2011), Botswana Data Protection Act (2024)
Operating criteria not documented for SEUs
Business continuity management, Energy management, Facility management
44ISO 22313:2020, ISO 39001:2012, ISO 41001:2018
No enhanced safeguards
Social responsibility
44Bermuda Personal Information Protection Act 2016 (PIPA), Bosnia and Herzegovina Law on Protection of Personal Data (2006, amended 2011), Botswana Data Protection Act (2024)
All admins see all logs
44FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 MODERATE
Sensitive categories not identified
44Bermuda Personal Information Protection Act 2016 (PIPA), Bosnia and Herzegovina Law on Protection of Personal Data (2006, amended 2011), Botswana Data Protection Act (2024)
Correction requests not actioned
44AICPA Privacy Management Framework (PMF), Australia Consumer Data Right, Australian Privacy Principles (APPs)
Design briefs silent on energy
Business continuity management, Energy management, Facility management
44ISO 22313:2020, ISO 39001:2012, ISO 41001:2018
Timeout over 15 minutes
44FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 MODERATE
No leading indicators
Organizational resilience: security, preparedness and business continuity management
44ASIS SPC.1-2009, ISO 37001, ISO 45001
Non-accredited assessor
44FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 MODERATE
No spam protection
44FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 MODERATE
Command text not captured
44FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 MODERATE
Personal containers unencrypted
44FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 MODERATE
Lock shows live data
44FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 MODERATE
Bluetooth/Wi-Fi enabled by default
44FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 MODERATE
No travel device program
44FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 MODERATE
Children without parental consent
44LGPD, Law No. 2013-450 of 19 June 2013 on the Protection of Personal Data, Law on Personal Data Protection (Official Gazette No. 42/2020)
no remediation plan
Financial institution cybersecurity self-assessment
44Cambodia Sub-Decree on Personal Data Protection (Sub-Decree No. 134), FFIEC Cybersecurity Assessment Tool (CAT), PCI DSS 4.0
No detection rules
44FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 MODERATE
No bastion enforcement
44FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 MODERATE
Configuration drift
44FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 MODERATE
Undocumented sec-admin access
44FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 MODERATE
Split tunneling allowed
44FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 MODERATE
Admins browse with admin
44FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 MODERATE
Inactive accounts active over 35 days
44FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 MODERATE
Multi-theory integration ad-hoc
Leadership behaviour: the transformational, transactional and passive-avoidant range and its measurement, Leadership development
44Full Range Leadership Model (Bass & Avolio), Goleman Emotional Intelligence Leadership Framework, Heifetz Adaptive Leadership Framework
Commissioning does not verify energy performance
Business continuity management, Energy management, Facility management
44ISO 22313:2020, ISO 39001:2012, ISO 41001:2018
Emergency accounts persist
44FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 MODERATE
Processing wrongly scoped out
44Bermuda Personal Information Protection Act 2016 (PIPA), Bosnia and Herzegovina Law on Protection of Personal Data (2006, amended 2011), Botswana Data Protection Act (2024)
Patches exceed SLA
44NIS2 Directive Implementing Acts, NIST SP 800-123, NIST SP 800-137
Non-FIPS ciphers enabled
44FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 MODERATE
shadow IT not captured
Financial institution cybersecurity self-assessment
44FFIEC Cybersecurity Assessment Tool (CAT), NIST SP 800-172, NIST SP 800-53 Rev 5 LOW
No automated deprovisioning
44FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 MODERATE
No PbD in development
44LGPD, Law on Personal Data Protection (Official Gazette No. 42/2020), Ley Orgánica de Protección de Datos Personales (LOPDP)
No processor contracts
44Law No. 2013-450 of 19 June 2013 on the Protection of Personal Data, Law on Personal Data Protection (Official Gazette No. 42/2020), Ley Orgánica de Protección de Datos Personales (LOPDP)
no completion tracking
44C5 (Germany), Canada's Anti-Spam Legislation (CASL), ISO/IEC 27003:2017
Improvement limited to closing audit findings
Anti-bribery management, Food safety management
44ISO 22000:2018, ISO 37001:2016, ISO 37001:2025
Retention shorter than required
44ISO 13485, ISO 15189:2022, ISO 19011
Manual inventory
44FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 MODERATE
Siloed plans
44FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 MODERATE
RTO undefined
44FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 MODERATE
Competence assumed from job title
Business continuity management, Organizational resilience: security, preparedness and business continuity management, Privacy information management
44ASIS SPC.1-2009, ISO 22313:2020, ISO 27701:2019
Sensitive data unencrypted
44AICPA SOC 3, APRA CPS 234, ASIC Cyber Resilience Good Practices
USB unrestricted
44FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 MODERATE
No allowlisting
44FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 MODERATE
Maintenance focused on uptime not energy
Business continuity management, Energy management, Facility management
44ISO 22313:2020, ISO 39001:2012, ISO 41001:2018
No data inventory
44FedRAMP High, NIST SP 800-53 Rev 5 MODERATE, NIST SP 800-53 Revision 5.1 HIGH
Controls drift after change
44FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 MODERATE
Unencrypted backups
44FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 MODERATE
No verification
44FedRAMP High, NIST SP 800-53 Revision 5.1 HIGH, New Jersey Data Privacy Act
No session recording
Financial institution cybersecurity self-assessment, Information security baseline protection (ISMS and technical, organisational, personnel and infrastructure requirements), Pipeline industrial control systems cybersecurity
44API 1164, BSI IT-Grundschutz, FFIEC Cybersecurity Assessment Tool (CAT)
No remote session logging
44FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 MODERATE
Verification not documented
44FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 MODERATE
Stale notice
44NIST Privacy Framework, Nebraska Data Privacy Act, New Hampshire Data Privacy Act
No sharing review process
44FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 MODERATE
No screenshot evidence
44FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 MODERATE
Consent not demonstrable
44Bermuda Personal Information Protection Act 2016 (PIPA), Bosnia and Herzegovina Law on Protection of Personal Data (2006, amended 2011), Botswana Data Protection Act (2024)
No peer review
44Argyris Double-Loop Learning, IAIS Insurance Core Principles (ICPs), ISO 27019
No exec sponsor
44Azure Security Benchmark, ISO 22313:2020, ISO 22318
stale review
44Azure Security Benchmark, BREEAM, BS 65000:2014
No pre-prod testing
44FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 MODERATE
Requests not actioned
44Austria Data Protection Act (Datenschutzgesetz, DSG, amended 2018), Azerbaijan Law on Personal Data (2010), Bermuda Personal Information Protection Act 2016 (PIPA)
TI not actioned
44BSI IT-Grundschutz, NIST SP 800-53 Rev 5 LOW, NIST SP 800-53 Rev 5 MODERATE
No defined review cadence
44Bahrain PDPL, Barbados Data Protection Act 2019, ISO/IEC 27031:2011
No security on CAB
44FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 MODERATE
No PAM session logs
44FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 MODERATE
No post-change testing
44FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 MODERATE
Resources allocated only at start of year
Occupational health and safety
44BRCGS Global Standard for Food Safety Issue 9, ISO 15189:2022, ISO 19011
No priority clauses
44FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 MODERATE
No criticality tiers
44FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 MODERATE
No alerts on account changes
44FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 MODERATE
No application control
44FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 MODERATE
No transaction replay
44FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 MODERATE
No rogue detection
44FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 MODERATE
Independent testing only
44FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 MODERATE
Manual ticket-only provisioning
44FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 MODERATE
Definitions not applied
44Botswana Data Protection Act (2024), Brazil AI Framework, Brazil Open Finance (Resolução Conjunta No. 1/2020)
No coordination with HR/legal
44FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 MODERATE
No automated expiry
44FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 MODERATE
Storage reassigned between tenants without sanitisation
Cloud PII protection, Cloud information security, Cloud privacy
44ISO 27017:2015, ISO 27018:2019, ISO/IEC 27017:2026
No remediation tracking
44BIMCO Cyber Security, NIST SP 800-115 (Technical Guide to Information Security Testing and Assessment), Security of Critical Infrastructure Act 2018 (SOCI)
No documented risk assessment
Insurance cybersecurity
44AICPA SOC 3, C-TPAT, NAIC Insurance Data Security Model Law (MDL-668)
no maturity assessment
Organizational resilience
44BS 65000:2014, Kuwait National Cybersecurity Framework, NIST SP 800-150
No life cycle cost analysis
Business continuity management, Energy management, Facility management
44ISO 22313:2020, ISO 39001:2012, ISO 41001:2018
Internal traffic unencrypted
44AWS Well-Architected Security Pillar, ISO 27018, NIST Cybersecurity Framework 2.0
No access controls
44Bermuda Personal Information Protection Act 2016 (PIPA), Bosnia and Herzegovina Law on Protection of Personal Data (2006, amended 2011), Botswana Data Protection Act (2024)
Backups never restored
44FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 MODERATE
No risk assessment
44Australia My Health Records Act 2012, Authorised Economic Operator (AEO) Programmes, NIST Privacy Framework
Stack traces exposed
44FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 MODERATE
No continuous monitoring
44Australia IRAP, NIST SP 800-115 (Technical Guide to Information Security Testing and Assessment), NIST SP 800-122
No maturity baseline
Innovation management
44ISO 31000, ISO 37301, ISO 55001
No method statement
Occupational health and safety
44BRCGS Global Standard for Food Safety Issue 9, ISO 15189:2022, ISO 19011
No independent ConMon
44FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Rev 5 MODERATE
Inadequate logging
44Australian Energy Sector Cyber Security Framework (AESCSF), Law No. 2013-450 of 19 June 2013 on the Protection of Personal Data, NIST SP 800-123
Untested backups
370Australian Information Security Manual, Azure Security Benchmark, NERC CIP
No awareness training
Insurance cybersecurity
355Australian Information Security Manual, BSIMM, NAIC Insurance Data Security Model Law (MDL-668)
compliance nominal not operational
324Ontario Accessibility for Ontarians with Disabilities Act (AODA), Open Banking Security, OpenSSF Scorecard
Logs not centralised
321Australian Information Security Manual, BSI IT-Grundschutz, TISAX
No data classification
321BSIMM, Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1, Lloyd's Minimum Standards
Consent not granular
319NIST SP 800-53 Rev 5, SOC 2, SSAE 18
single vendor dependency
PIN and cryptographic key security for payment transactions, Payment account data encryption from point of interaction to decryption, Payment software security
315PCI P2PE, PCI PIN Security, PCI SSF
missing AOCs
315PCI P2PE, PCI PIN Security, PCI SSF
weak forensic preservation
PIN and cryptographic key security for payment transactions, Payment account data encryption from point of interaction to decryption, Payment software security
315PCI P2PE, PCI PIN Security, PCI SSF
Time drift on legacy systems
Information security baseline protection (ISMS and technical, organisational, personnel and infrastructure requirements)
315BSI IT-Grundschutz, Bahrain PDPL, Belgium CyberFundamentals
No tamper-evident protections on logs
Information security baseline protection (ISMS and technical, organisational, personnel and infrastructure requirements)
315BSI IT-Grundschutz, Bahrain PDPL, Belgium CyberFundamentals
Retention shorter than regulatory minimum
Information security baseline protection (ISMS and technical, organisational, personnel and infrastructure requirements)
315BSI IT-Grundschutz, Bahrain PDPL, Belgium CyberFundamentals
weak responsibility matrix
PIN and cryptographic key security for payment transactions, Payment account data encryption from point of interaction to decryption, Payment software security
315PCI P2PE, PCI PIN Security, PCI SSF
expired attestations
PIN and cryptographic key security for payment transactions, Payment account data encryption from point of interaction to decryption, Payment software security
315PCI P2PE, PCI PIN Security, PCI SSF
no card brand contact
PIN and cryptographic key security for payment transactions, Payment account data encryption from point of interaction to decryption, Payment software security
315PCI P2PE, PCI PIN Security, PCI SSF
missing comms tree
PIN and cryptographic key security for payment transactions, Payment account data encryption from point of interaction to decryption, Payment software security
315PCI P2PE, PCI PIN Security, PCI SSF
Critical systems not forwarding logs
Information security baseline protection (ISMS and technical, organisational, personnel and infrastructure requirements)
315BSI IT-Grundschutz, Bahrain PDPL, Belgium CyberFundamentals
weak key rotation
315PCI P2PE, PCI PIN Security, PCI SSF
unmanaged endpoints
PIN and cryptographic key security for payment transactions, Payment account data encryption from point of interaction to decryption, Payment software security
315PCI P2PE, PCI PIN Security, PCI SSF
Stakeholder needs not refreshed annually
313AS9100D, ISO/IEC 27003:2017, South Korea Korea Internet Self-Governance Organisation (KISO) Code of Ethics
No penetration testing
312BSIMM, CFTC System Safeguards (17 CFR 37, 38, 39, 49), Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1
missing risk appetite
PIN and cryptographic key security for payment transactions, Payment account data encryption from point of interaction to decryption, Payment software security
312PCI P2PE, PCI PIN Security, PCI SSF
undefined accountability
PIN and cryptographic key security for payment transactions, Payment account data encryption from point of interaction to decryption, Payment software security
312PCI P2PE, PCI PIN Security, PCI SSF
No baselines
311Australian Energy Sector Cyber Security Framework (AESCSF), CMMC 2.0, NIST Privacy Framework
No automated drift detection
Information security baseline protection (ISMS and technical, organisational, personnel and infrastructure requirements)
311BSI IT-Grundschutz, Belgium CyberFundamentals, NIST SP 1800-32
Logs not reviewed
311Australia My Health Records Act 2012, BIMCO Cyber Security, CMMC 2.0
Management review skipped
Aviation information security management
311EASA Part-IS, ISO 27005, ISO 31000
Penetration tests scope narrow and exclude key applications
311COSO Internal Control, NIST SP 800-53 Rev 5 LOW, NIST SP 800-53 Rev 5 MODERATE
Audit findings without closure dates
310ASIS SPC.1-2009, AWWA Cybersecurity Guidance for the Water Sector (American Water Works Association), ISO/IEC 27003:2017
Pseudonymous data treated as out of scope without safeguards review
Biometric privacy
310DFARS 252.204-7012, Illinois Biometric Information Privacy Act (BIPA), Modern Slavery Act 2018 (Australia)
Applicability re-run not triggered when revenue mix shifts
Biometric privacy
310DFARS 252.204-7012, Illinois Biometric Information Privacy Act (BIPA), Modern Slavery Act 2018 (Australia)
Scan coverage gaps for containerised and ephemeral workloads
310COSO Internal Control, NIST SP 800-53 Rev 5 LOW, NIST SP 800-53 Rev 5 MODERATE
Consumer health data not separated from general sensitive data
Biometric privacy
310DFARS 252.204-7012, Illinois Biometric Information Privacy Act (BIPA), Modern Slavery Act 2018 (Australia)
Policy not reviewed annually
Food safety and quality management certification
310BRCGS Global Standard for Food Safety Issue 9, ISO 15189:2022, ISO 27043
B2B contact data assumed exempt past PA 23-56 effective date
Biometric privacy
310DFARS 252.204-7012, Illinois Biometric Information Privacy Act (BIPA), Modern Slavery Act 2018 (Australia)
Continual improvement not demonstrated through EnPIs
39ISO 22313:2020, ISO 39001:2012, ISO 41001:2018
Management review skipped one or more cycles
39ASIS SPC.1-2009, AWWA Cybersecurity Guidance for the Water Sector (American Water Works Association), ISO/IEC 27003:2017
No threat modelling
38BSIMM, Canada Artificial Intelligence and Data Act (AIDA), Secure by Design: A Guide for Manufacturers (CISA)
High severity vulnerabilities exceed remediation SLA without risk acceptance
38COSO Internal Control, NIST SP 800-53 Rev 5 LOW, NIST SP 800-53 Rev 5 MODERATE
Threat intelligence consumed but not operationalised into detections
38COSO Internal Control, NIST SP 800-53 Rev 5 LOW, NIST SP 800-53 Rev 5 MODERATE
Root cause analysis is symptomatic only
38AS9100D, ASIS SPC.1-2009, ISO/IEC 27003:2017
IT and OT response teams not aligned
38AWWA Cybersecurity Guidance for the Water Sector (American Water Works Association), Argyris Double-Loop Learning, South Korea Korea Internet Self-Governance Organisation (KISO) Code of Ethics
Roles overlap without clear accountable owner
Aviation, space and defense quality management system on ISO 9001:2015, Organizational resilience: security, preparedness and business continuity management
38AS9100D, ASIS SPC.1-2009, AWWA Cybersecurity Guidance for the Water Sector (American Water Works Association)
Board reporting cadence not formalised
Aviation, space and defense quality management system on ISO 9001:2015, Organizational resilience: security, preparedness and business continuity management
38AS9100D, ASIS SPC.1-2009, AWWA Cybersecurity Guidance for the Water Sector (American Water Works Association)
Decisions undocumented
Digital investigation processes, Governance of information security, Health information security
38ISO 27799:2025, ISO/IEC 27014:2020, ISO/IEC 27043:2015
Mitigations not tracked
37ISO/IEC 27014:2020, ISO/IEC 29134:2023, Spain Organic Law 3/2018 on Data Protection and Digital Rights (LOPDGDD)
Director and officer awareness thin
37UK Bribery Act 2010, UK Data Protection Act 2018, UK Online Safety Act 2023
Detection coverage not mapped to MITRE ATT&CK
37ASIS SPC.1-2009, AWWA Cybersecurity Guidance for the Water Sector (American Water Works Association), ISO/IEC 27003:2017
Withdrawal not as easy as granting consent
37UK Bribery Act 2010, UK Data Protection Act 2018, UK Open Banking Standard
No evidence policies were communicated to staff
Aviation, space and defense quality management system on ISO 9001:2015, Organizational resilience: security, preparedness and business continuity management
37AS9100D, ASIS SPC.1-2009, Argyris Double-Loop Learning
Scope boundaries unclear for cloud services
Aviation, space and defense quality management system on ISO 9001:2015, Organizational resilience: security, preparedness and business continuity management
37AS9100D, ASIS SPC.1-2009, South Korea Korea Internet Self-Governance Organisation (KISO) Code of Ethics
Cooperation credit strategy absent
37UK Bribery Act 2010, UK Data Protection Act 2018, UK Online Safety Act 2023
Self disclosure protocols undefined
37UK Bribery Act 2010, UK Data Protection Act 2018, UK Online Safety Act 2023
Risk appetite undefined
Financial institution cybersecurity self-assessment, Governance and management of enterprise information and technology
37C2M2, COBIT 2019, FFIEC Cybersecurity Assessment Tool (CAT)
Children consent thresholds not enforced
37UK Bribery Act 2010, UK Data Protection Act 2018, UK Open Banking Standard
Tabletop exercises not run in last 12 months
37ASIS SPC.1-2009, AWWA Cybersecurity Guidance for the Water Sector (American Water Works Association), ISO/IEC 27003:2017
Records lack granularity per processing purpose
37UK Bribery Act 2010, UK Data Protection Act 2018, UK Open Banking Standard
ICS forensics tooling not in place
37AWWA Cybersecurity Guidance for the Water Sector (American Water Works Association), Argyris Double-Loop Learning, South Korea Korea Internet Self-Governance Organisation (KISO) Code of Ethics
Bundled consent across distinct purposes
37UK Bribery Act 2010, UK Data Protection Act 2018, UK Open Banking Standard
Benefits not tracked
37Authorised Economic Operator (AEO) Programmes, COBIT 2019, ISO 9001
Legal register not refreshed for new enforcement actions
37UK Bribery Act 2010, UK Data Protection Act 2018, UK Online Safety Act 2023
Change management bypasses energy review
36ISO 22313:2020, ISO 39001:2012, ISO 41001:2018
Operational controls not linked to risks
36AS9100D, ASIS SPC.1-2009, ISO/IEC 27003:2017
missing legal review
36Security of Critical Infrastructure Act 2018 (SOCI), Singapore Cybersecurity Act 2018, Singapore Protection from Online Falsehoods and Manipulation Act (POFMA, 2019)
Effectiveness checks not performed
36AS9100D, ASIS SPC.1-2009, ISO/IEC 27003:2017
Control implemented without explicit link to the EnMS
36ISO 22313:2020, ISO 39001:2012, ISO 41001:2018
no regulator engagement
36Azerbaijan Law on Personal Data (2010), Estonia Personal Data Protection Act (Isikuandmete kaitse seadus, 2019), Security of Critical Infrastructure Act 2018 (SOCI)
Data subject request workflow exceeds statutory response deadlines
36South Korea ISMS-P, Sweden Data Protection Act (Dataskyddslag, 2018:218), Switzerland New Federal Act on Data Protection (nFADP/nDSG, 2023)
Consent capture mechanisms do not record granularity required by law
36South Korea ISMS-P, Sweden Data Protection Act (Dataskyddslag, 2018:218), Switzerland New Federal Act on Data Protection (nFADP/nDSG, 2023)
Change records missing rollback evidence
36AS9100D, ASIS SPC.1-2009, ISO/IEC 27003:2017
Energy performance impact not assessed
36ISO 22313:2020, ISO 39001:2012, ISO 41001:2018
Environmental excursions not investigated
36ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024
Top management oversight not evidenced
36ISO 22313:2020, ISO 39001:2012, ISO 41001:2018
No life cycle energy assessment for purchases
36ISO 22313:2020, ISO 39001:2012, ISO 41001:2018
Use of deprecated ciphers or self-signed certificates
Information security baseline protection (ISMS and technical, organisational, personnel and infrastructure requirements)
35BSI IT-Grundschutz, Bahrain PDPL, Belgium CyberFundamentals
Inconsistent encryption coverage across data stores
Information security baseline protection (ISMS and technical, organisational, personnel and infrastructure requirements)
35BSI IT-Grundschutz, Bahrain PDPL, Belgium CyberFundamentals
No documented rotation schedule
Information security baseline protection (ISMS and technical, organisational, personnel and infrastructure requirements)
35BSI IT-Grundschutz, Bahrain PDPL, Belgium CyberFundamentals
No SLA tracking
35COBIT 2019, ISO 27018, ISO/IEC 27004:2016
No periodic monitoring
35Bahrain PDPL, Bank Secrecy Act / Anti-Money Laundering (BSA/AML), Barbados Data Protection Act 2019
Disposal undocumented
Attestation and assurance standards
35HIPAA Security Rule, SOC for Cybersecurity, SSAE 18
Boundaries unclear
Automotive functional safety
35Estonia Personal Data Protection Act (Isikuandmete kaitse seadus, 2019), ISO 26262:2018, SOC for Cybersecurity
No transfer impact assessment performed
35Bahrain PDPL, Bank Secrecy Act / Anti-Money Laundering (BSA/AML), Barbados Data Protection Act 2019
Reliance on adequacy without supplementary measures
35Bahrain PDPL, Bank Secrecy Act / Anti-Money Laundering (BSA/AML), Barbados Data Protection Act 2019
No simulations
35FedRAMP High, ISO/IEC 27011:2024, NIST SP 800-53 Revision 5.1 HIGH
Sub-processor transfers untracked
35Bahrain PDPL, Bank Secrecy Act / Anti-Money Laundering (BSA/AML), Barbados Data Protection Act 2019
Keys stored alongside encrypted data
Information security baseline protection (ISMS and technical, organisational, personnel and infrastructure requirements)
35BSI IT-Grundschutz, Bahrain PDPL, Belgium CyberFundamentals
Policy not aligned to control statement
35Bahrain PDPL, Bank Secrecy Act / Anti-Money Laundering (BSA/AML), Barbados Data Protection Act 2019
Procedure undocumented
35Bahrain PDPL, Bank Secrecy Act / Anti-Money Laundering (BSA/AML), Barbados Data Protection Act 2019
SCCs not updated to current versions
35Bahrain PDPL, Bank Secrecy Act / Anti-Money Laundering (BSA/AML), Barbados Data Protection Act 2019
Responsibilities undefined
34Botswana Data Protection Act (2024), Brazil Open Finance (Resolução Conjunta No. 1/2020), C2M2
Audit trail incomplete
34ASEAN Guide on AI Governance and Ethics, French Sapin II Law (Law No. 2016-1691), NIST Cybersecurity Framework 2.0
No attestation
34Azure Security Benchmark, ISO 27017, NIST SP 800-144
Scrap not physically destroyed
34AS9100D, AS9100D:2016, ISO/IEC 27003:2017
Records incomplete
Aviation information security management, Criminal justice information security
34EASA Part-IS, FBI CJIS Security Policy, NIST SP 800-53 Rev 5
Supervisory engagement weak
34HKMA Cyber Resilience Assessment Framework (C-RAF), HKMA SPM, HKMA TM-G-1
Internal audit coverage skews to financial controls rather than full scope
34Solvency II, South Korea ISMS-P, Switzerland New Federal Act on Data Protection (nFADP/nDSG, 2023)
Training not refreshed
34CMMC 2.0, ISO 37001, Samoa Telecommunications Act (2005)
Log retention periods inconsistent across systems
34Solvency II, South Korea ISMS-P, Switzerland New Federal Act on Data Protection (nFADP/nDSG, 2023)
weak governance
34Azure Security Benchmark, DAMA-DMBOK2, NIST SP 800-122
Methodology inconsistent
Aviation information security management
34EASA Part-IS, GHG Protocol, NIST SP 800-171
No access mechanism
34APPI, Angola Personal Data Protection Law (Law No. 22/11), Argentina Law 25.326 (Personal Data Protection Law)
Critique not engaged
Leadership development
34Goleman Emotional Intelligence Leadership Framework, Heifetz Adaptive Leadership Framework, Hersey & Blanchard Situational Leadership Model
No risk appetite statement
34APRA CPS 220 Risk Management, APRA SPS 220 Risk Management (Superannuation), COBIT 2019
Late changes uncontrolled
34AS9100D, AS9100D:2016, ISO/IEC 27003:2017
Sectoral coordination ad-hoc
Financial customer information security
34FTC GLBA Safeguards Rule (16 CFR Part 314), Georgia Law on Personal Data Protection (2012), Ghana Data Protection Act 2012 (Act 843)
No flowdown of customer reqs
34AS9100D, AS9100D:2016, ISO/IEC 27003:2017
No verification vs validation distinction
34AS9100D, AS9100D:2016, ISO/IEC 27003:2017
No MRB for use-as-is
34AS9100D, AS9100D:2016, ISO/IEC 27003:2017
no egress filtering
34AWS Well-Architected Security Pillar, Azure Security Benchmark, NIST SP 800-171 Rev 3
Supplier de-listing not executed
34AS9100D, AS9100D:2016, ISO/IEC 27003:2017
No deploy audit trail
33FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Revision 5.1 HIGH
No SCRM strategy
33NIST SP 800-53 Rev 5 LOW, NIST SP 800-53 Rev 5 MODERATE, NIST SP 800-53 Revision 5.1 HIGH
Logs collected but never reviewed
Cloud PII protection, Financial customer information security
33FTC GLBA Safeguards Rule (16 CFR Part 314), HIPAA Security Rule, ISO 27018:2019
POA&Ms stale
33NIST SP 800-53 Rev 5 LOW, NIST SP 800-53 Rev 5 MODERATE, NIST SP 800-53 Revision 5.1 HIGH
No data discovery
33FedRAMP High, NIST SP 800-53 Rev 5 MODERATE, NIST SP 800-53 Revision 5.1 HIGH
Updates not communicated
33ASEAN Data Management Framework, HIPAA Security Rule, Russia Federal Law on Personal Data (152-FZ)
No drift detection
Security configuration hardening of DOD information systems
33DISA Security Technical Implementation Guides (STIGs), ISO 27017, Lloyd's Minimum Standards
Role based training not delivered to high risk teams
Aviation, space and defense quality management system on ISO 9001:2015, Organizational resilience: security, preparedness and business continuity management
33AS9100D, ASIS SPC.1-2009, Argyris Double-Loop Learning
Contractor competence not verified
Asset management, Food safety management
33ISO 22000:2018, ISO 45001, ISO 55001:2014
No criminal-risk register
33Liechtenstein DPA, Lithuania Law on Legal Protection of Personal Data (2018), South Korea PIPA
Changes made without change control
33Annex 11 to EU GMP, Bermuda Monetary Authority (BMA) Cyber Risk Management Code of Conduct, C2M2
Lessons learned not captured
33NIST SP 800-128, Space ISAC (Information Sharing and Analysis Center), TISAX
Reasonable care defence undocumented
33Jamaica Data Protection Act 2020, Kazakhstan Law on Personal Data and Their Protection (No. 94-V), Kentucky Consumer Data Protection Act
Auditors not independent of audited area
Laboratory competence
33ISO 37301, ISO/IEC 17025:2017, ISO/IEC 17025:2017
Corrections applied without a cause analysis
Anti-bribery management
33ISO 37001:2016, ISO 37001:2025, ISO/IEC 27003:2017
corrective actions not tracked to closure
33ISO/IEC 29100:2024, South Africa Promotion of Access to Information Act (PAIA), US Maritime Transportation Security Act (MTSA) and USCG Cybersecurity Requirements
Objectives stated as aspirations with no measure
Anti-bribery management, Quality plans
33ISO 10005:2005, ISO 37001:2016, ISO 37001:2025
Effectiveness never reviewed
Environmental management, Food safety management, Information security management system auditing
33ISO 14004:2016, ISO 22000:2018, ISO/IEC 27007:2020
Competence reassessment intervals not defined
ISMS certification body requirements
33ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006-1:2024
Corrective actions overdue
Emergency management, business continuity and crisis management programs
33NFPA 1600, TISAX, US Maritime Transportation Security Act (MTSA) and USCG Cybersecurity Requirements
Indefinite retention by default
33Israel Protection of Privacy Law (5741-1981), PCI DSS 4.0, Uzbekistan Law on Personal Data (No. ZRU-547)
Subject notification skipped (high-risk underestimated)
33Jamaica Data Protection Act 2020, Jordan Draft Personal Data Protection Law (2022), Kazakhstan Law on Personal Data and Their Protection (No. 94-V)
Lawful mechanism not chosen per transfer
33Jamaica Data Protection Act 2020, Jordan Draft Personal Data Protection Law (2022), Kazakhstan Law on Personal Data and Their Protection (No. 94-V)
Thresholds not defined
Farm assurance: food safety, workers, environment
33DAMA-DMBOK2, GLOBALG.A.P. Integrated Farm Assurance (IFA) Standard v6, Science Based Targets initiative (SBTi) Corporate Standard
Training metrics not reported to leadership
Aviation, space and defense quality management system on ISO 9001:2015, Organizational resilience: security, preparedness and business continuity management
33AS9100D, ASIS SPC.1-2009, Argyris Double-Loop Learning
Cleaning frequency not based on risk
33ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024
Agreements not updated when scope changes
33ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024
Visitor logs incomplete
33HIPAA Security Rule, NIST SP 800-171, NIST SP 800-53 Rev 5
Monitoring gaps
33COBIT 2019, FBI CJIS Security Policy, ISO 22000
Disposal informal
33COBIT 2019, ISO 27043, ISO 27799
No feedback loop
33COBIT 2019, ISO 20400:2017, Kotter 8-Step Change Model
No BCR approval procedure
33LGPD, Law on Personal Data Protection (Official Gazette No. 42/2020), Ley Orgánica de Protección de Datos Personales (LOPDP)
plan untested
33AWS Well-Architected Security Pillar, FFIEC IT Examination Handbook, ISO 28001:2007 Supply Chain Security Management
No external comms
33AS9100D:2016, ISO 20000-1, ISO 27005
No benchmarking
33ISO 39001:2012, ISO 45001, ISO 55001
recovery objectives undefined
Federal information security governance, GxP computerized systems: risk-based compliance and fitness for intended use across the system life cycle
33C2M2, FISMA, GAMP 5
Access granted before screening completes
33CMMC 2.0, NIST SP 800-171, NIST SP 800-171A
No accountability
33AWS Well-Architected Security Pillar, C2M2, ISO 22000
Processors with no notification duty
Data protection and privacy
33Rwanda DPL, Uruguay DPL, Vietnam PDPD
No federation
33AWS Well-Architected Security Pillar, MARS-E, NIST SP 800-144
No segmentation
33AWS Well-Architected Security Pillar, BIMCO Cyber Security, Nevada Gaming Control Board Cybersecurity Requirements
no risk assessment
33Australia My Health Records Act 2012, NIST SP 800-144, Saudi Arabia PDPL
stale strategy
33Azure Security Benchmark, NIST SP 800-137, NIST SP 800-161 Rev 1
short retention
336th Anti-Money Laundering Directive (AMLD6, Directive (EU) 2018/1673), Azure Security Benchmark, PCI DSS 4.0
keys not rotated
33C5 (Germany), NIST SP 800-150, PCI DSS 4.0
reviews overdue
33C5 (Germany), ISO 15189:2022, ISO/IEC 17025:2017
No Whistleblower integration
33Liechtenstein DPA, Lithuania Law on Legal Protection of Personal Data (2018), Luxembourg Law of 1 August 2018 on Data Protection (GDPR Implementation)
Keys never rotated
Aviation information security management, Industrial automation and control system security
33AWS Well-Architected Security Pillar, EASA Part-IS, IEC 62443
Restore never tested
GxP computerized systems: risk-based compliance and fitness for intended use across the system life cycle, Health information security
33CISA Cross-Sector Cybersecurity Performance Goals (CPG) 2.0, GAMP 5, ISO 27799:2025
Training stale
33ISO 27043, ISO 27799, PCI DSS 4.0
No restore tests
33ISO 22317, ISO 27019, PCI DSS 4.0
Corrections not actioned
33Colorado Privacy Act, Connecticut Data Privacy Act (CTDPA), Consumer Data Right (CDR) Framework (Australia)
No board visibility
Biometric privacy, Organizational resilience
33BS 65000:2014, Illinois Biometric Information Privacy Act (BIPA), Texas Data Privacy Act
No subprocessor visibility
33Nebraska Data Privacy Act, New Hampshire Data Privacy Act, New Jersey Data Privacy Act
No measurement of effectiveness
33HIPAA Security Rule, ISO/IEC 27007:2020, NIST SP 800-66 Rev 2
No written programme
33Nebraska Data Privacy Act, New Hampshire Data Privacy Act, New Jersey Data Privacy Act
Missing notice elements
33Nebraska Data Privacy Act, New Hampshire Data Privacy Act, New Jersey Data Privacy Act
Overseas disclosure without safeguards
33Australia Consumer Data Right, Australian Privacy Principles (APPs), Consumer Data Right (CDR) Framework (Australia)
No collection notice
33Australian Privacy Principles (APPs), Bosnia and Herzegovina Law on Protection of Personal Data (2006, amended 2011), Botswana Data Protection Act (2024)
No DPA register
33Nebraska Data Privacy Act, New Hampshire Data Privacy Act, New Jersey Data Privacy Act
Selection undocumented
Information security management system auditing
33Canada ITSG-33, ISO/IEC 27007:2020, MARS-E
No Board oversight
33Lloyd's Minimum Standards, Nigeria Open Banking Regulatory Framework (CBN, 2023), Science Based Targets initiative (SBTi) Corporate Standard
Purpose creep
33Bermuda Personal Information Protection Act 2016 (PIPA), Brazil Open Finance (Resolução Conjunta No. 1/2020), New Hampshire Data Privacy Act
No stress testing
33APRA CPS 220 Risk Management, APRA SPS 220 Risk Management (Superannuation), IAIS Insurance Core Principles (ICPs)
No root cause
33ISO 28001:2007 Supply Chain Security Management, ISO/IEC 25012:2008, ISO/IEC 27003:2017
30-day SLA frequently missed
33Jamaica Data Protection Act 2020, Jordan Draft Personal Data Protection Law (2022), Kazakhstan Law on Personal Data and Their Protection (No. 94-V)
Audit log integrity not assessed
33NIST SP 800-171, NIST SP 800-171A Rev 3, PCI DSS 4.0
no remediation
33Argyris Double-Loop Learning, ISO 37002:2021, PCI DSS 4.0
No access logging
33Australia My Health Records Act 2012, Laos Law on Prevention and Combating Cybercrime (2015), PCI DSS 4.0
No outcome metrics
Governance of organizations, Social responsibility
33ISO 26000:2010, ISO 37000:2021, LEADS in a Caring Environment
No formal ConMon strategy
33NIST SP 800-53 Rev 5 LOW, NIST SP 800-53 Rev 5 MODERATE, NIST SP 800-53 Revision 5.1 HIGH
No tracked SLA
33NIST SP 800-53 Rev 5 LOW, NIST SP 800-53 Rev 5 MODERATE, NIST SP 800-53 Revision 5.1 HIGH
EA not maintained
33NIST SP 800-53 Rev 5 LOW, NIST SP 800-53 Rev 5 MODERATE, NIST SP 800-53 Revision 5.1 HIGH
No aging metric
33NIST SP 800-53 Rev 5 LOW, NIST SP 800-53 Rev 5 MODERATE, NIST SP 800-53 Revision 5.1 HIGH
SPOFs unmitigated
33FedRAMP High, NIST SP 800-53 Rev 5 MODERATE, NIST SP 800-53 Revision 5.1 HIGH
Same metro zone
33FedRAMP High, NIST SP 800-53 Rev 5 MODERATE, NIST SP 800-53 Revision 5.1 HIGH
Local-only logs
33FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Revision 5.1 HIGH
Scope misunderstood
Health information privacy and security
33Ghana Cybersecurity Act, Ghana Data Protection Act 2012 (Act 843), HITECH Act
Feedback collected but not acted on
33ISO 15189:2022, ISO/IEC 17025:2017, ITIL 4
Annual review not performed
33NIST Cybersecurity Framework 2.0, UK Building Safety Act 2022, US Foreign Corrupt Practices Act (FCPA)
No annual pen test
Information security baseline protection (ISMS and technical, organisational, personnel and infrastructure requirements)
33BSI IT-Grundschutz, Lloyd's Minimum Standards, New Zealand Information Security Manual (NZISM)
Visitor escorts not enforced
33HIPAA Security Rule, NIST Cybersecurity Framework 2.0, NIST SP 800-66 Rev 2
Emergency changes bypass review
33FBI CJIS Security Policy, NIST SP 800-171 Rev 3, NIST SP 800-53 Rev 5
Recertification not performed
33HIPAA Security Rule, NIST SP 800-66 Rev 2, UK Defence Standard 05-138
Configuration drift unmanaged
33ASIC Cyber Resilience Good Practices, AWS Well-Architected Security Pillar, Australian Energy Sector Cyber Security Framework (AESCSF)
Re-screening not performed
33HIPAA Security Rule, ISO 37001, NIST SP 800-66 Rev 2
Contractors and temporary staff excluded
33APEC Cross-Border Privacy Rules (CBPR) System, Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1, Tunisia Organic Law on Personal Data Protection (Law No. 2004-63)
Effectiveness not measured
33Bermuda Monetary Authority (BMA) Cyber Risk Management Code of Conduct, ISO/SAE 21434, NIST SP 800-53 Rev 5
Coverage incomplete
33Australian Privacy Principles (APPs), BSIMM, PCI DSS 4.0
Exceptions granted with no expiry
33Azure Security Benchmark, NIST Cybersecurity Framework 2.0, NIST SP 800-171A
No role-based training
Business continuity management, Insurance cybersecurity
33ISO 22313:2020, ISO 37001, NAIC Insurance Data Security Model Law (MDL-668)
CUI specific incidents not exercised
33NIST SP 800-171, NIST SP 800-171A Rev 3, PCI DSS 4.0
no breach response
33Australian Privacy Principles (APPs), FFIEC IT Examination Handbook, Nevada Gaming Control Board Cybersecurity Requirements
Exceptions never reviewed
Privacy framework
33ANSSI Guide d'hygiene informatique (42 mesures, v2.0), ISO/IEC 29100:2024, NIST Cybersecurity Framework 2.0
No accuracy review of long-held records
Data protection and privacy
33POPIA, Qatar DPL, Rwanda DPL
No data subject breach notification
33LGPD, Law on Personal Data Protection (Official Gazette No. 42/2020), Ley Orgánica de Protección de Datos Personales (LOPDP)
Data collected but not analysed
Environmental management, Quality management
33ISO 14004:2016, ISO 9001, ISO 9001:2015
Retention period inconsistent across systems
33NIST SP 800-171, NIST SP 800-171A Rev 3, PCI DSS 4.0
No SLA monitoring
33AWS Well-Architected Security Pillar, CCPA/CPRA, NIST SP 800-144
API authorization not tested
33NIST SP 800-171, NIST SP 800-171A Rev 3, PCI DSS 4.0
Transfers without mapping (cloud sprawl)
33Jamaica Data Protection Act 2020, Jordan Draft Personal Data Protection Law (2022), Kazakhstan Law on Personal Data and Their Protection (No. 94-V)
Plan unwritten
33AS9100D:2016, ISO 20000-1, ISO 27005
No tracking of completion
33C5 (Germany), HIPAA Security Rule, NIST SP 800-66 Rev 2
Service accounts not enumerated
33NIST SP 800-171, NIST SP 800-171A Rev 3, PCI DSS 4.0
no governance
33Azure Security Benchmark, DAMA-DMBOK2, NIST SP 800-144
Auditors auditing their own area
Environmental management, Food safety management, Organizational resilience: security, preparedness and business continuity management
33ASIS SPC.1-2009, ISO 14004:2016, ISO 22000:2018
findings reported but not tracked to closure
Environmental management
33Azure Security Benchmark, ISO 14001:2015, ISO 14001:2026
Flat OT network
33IEC 62351, ISO 27019, NIST SP 800-82 Rev 3
CAPA backlog from prior inspections
33EU Clinical Trials Regulation (CTR 536/2014), EU In Vitro Diagnostic Medical Devices Regulation (IVDR), EU Medical Devices Regulation (MDR 2017/745)
KPIs not defined
Enterprise risk management
33ISO 13485, ISO 19011, ISO 31000:2018
No appeal process
33Colorado Privacy Act, New Hampshire Data Privacy Act, New Jersey Data Privacy Act
Measurement uncertainty not estimated
33ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024
BYOD authorization unclear
33NIST SP 800-171, NIST SP 800-171A Rev 3, PCI DSS 4.0
Resource gaps not surfaced before incidents
33ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024
Evaluation criteria not documented
33ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024
Standards updates not tracked
Battery sustainability, safety, labelling, due diligence, waste management and the battery passport; circular economy
33EU Batteries Regulation (Regulation (EU) 2023/1542), FISMA, GS1 Global Standards
No periodic refresh
Aviation, space and defense quality management system on ISO 9001:2015, Information management for built assets (BIM)
33AS9100D, ISO 19650, ISO 9001
lessons not implemented
33FFIEC Cybersecurity Assessment Tool (CAT), FFIEC IT Examination Handbook, NIST SP 800-82 Rev 3
No lessons learned
Management system auditing
33ISO 19011:2018, ISO 19011:2026, NIST SP 800-115 (Technical Guide to Information Security Testing and Assessment)
Resource gaps surfaced only after incidents
33ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024
unauthenticated scans only
33Cyber Essentials Plus, NIST SP 800-190, PCI DSS 4.0
Identity verification weak (impersonation risk)
33Indonesia PDP Law, Jamaica Data Protection Act 2020, Kazakhstan Law on Personal Data and Their Protection (No. 94-V)
Missing NIST alignment
33Nebraska Data Privacy Act, New Hampshire Data Privacy Act, New Jersey Data Privacy Act
Records not retrievable on demand
33HIPAA Security Rule, NIST SP 800-66 Rev 2, Union Customs Code (UCC)
Asset register out of date
33HIPAA Security Rule, NIST SP 800-66 Rev 2, UK Defence Standard 05-138
Exceptions never expire
33NIST SP 800-128, NIST SP 800-171, NIST SP 800-218
Backups unencrypted
333GPP 5G Security Architecture (TS 33.501), CISA Zero Trust Maturity Model, Ukraine Law on Personal Data Protection (Law No. 2297-VI)
Surge capacity not planned for outbreak scenarios
33ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024
No management review
Biometric privacy
33BIMCO Cyber Security, ISO/IEC 27003:2017, Illinois Biometric Information Privacy Act (BIPA)
Reassessment overdue for long serving staff
33ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024
Locum induction not recorded
33ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024
No customer notification
33ISO 27018, Nigeria Open Banking Regulatory Framework (CBN, 2023), PCI DSS 4.0
Contractors untrained
Supply chain security
33Cambodia Sub-Decree on Personal Data Protection (Sub-Decree No. 134), ISO 22000, ISO 28001:2007 Supply Chain Security Management
Minutes record discussion but no decisions
Asset management, Food safety management, Quality management
33ISO 22000:2018, ISO 55001:2024, ISO 9001:2015
Access logs not reviewed
33NIST Cybersecurity Framework 2.0, UK Concordat on Open Research Data (UKRI), WHO Global Strategy on Digital Health 2020-2025
Documents uncontrolled
Asset management, Environmental management
33ISO 14001:2015, ISO 55001:2014, ISO 55001:2024
External notification timelines unclear
33NIST SP 800-171, NIST SP 800-171A Rev 3, PCI DSS 4.0
Contractors missing NDA
Enterprise risk management
33ISO 15189:2022, ISO 19011, ISO 31000:2018
Lot to lot verification skipped under pressure
33ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024
Critical reagents single sourced without contingency
33ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024
Supplier performance not monitored
33ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024
No process for handling unaccredited referral results
33ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024
External comms ad hoc
AI risk management, Whistleblowing management
33ISO 37002:2021, ISO/IEC 23894:2023, ISO/IEC 27003:2017
Traceability chain broken to manufacturer working calibrators
33ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024
Calibration intervals not justified by data
33ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024
Non-APL products
33FedRAMP High, FedRAMP Moderate, New Zealand Information Security Manual (NZISM)
No ongoing monitoring after onboarding
33HIPAA Security Rule, NIST SP 800-66 Rev 2, Samoa Telecommunications Act (2005)
Drift not detected
33AWS Well-Architected Security Pillar, NIST SP 800-137, NIST SP 800-171
Contractors excluded
Environmental management
33ISO 14004:2016, ISO 37301, Spain Organic Law 3/2018 on Data Protection and Digital Rights (LOPDGDD)
Trends not reviewed in management review
3321 CFR Part 211, ISO 15189:2022, ISO/IEC 17025:2017
No measurement uncertainty estimate per assay
33ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024
Alerts not triaged
33ASIC Cyber Resilience Good Practices, AWWA Cybersecurity Guidance for the Water Sector (American Water Works Association), IEC 62351
Consent records lack timestamp or version
33AS9100D, ASIS SPC.1-2009, ISO/IEC 27003:2017
Turnaround time commitments not monitored
33ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024
No documented review cadence
Criminal justice information security
33FBI CJIS Security Policy, HIPAA Security Rule, NIST SP 800-172
no root-cause analysis
Aviation information security management
33BIMCO Cyber Security, EASA Part-IS, Saudi Arabia PDPL
Sample acceptance criteria not in writing
33ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024
Inherent vs residual risk scoring not documented
33ASIS SPC.1-2009, AWWA Cybersecurity Guidance for the Water Sector (American Water Works Association), ISO/IEC 27003:2017
ERP transaction restrictions undocumented
33NIST SP 800-171, NIST SP 800-171A Rev 3, PCI DSS 4.0
Energy considered only after design freeze
33ISO 22313:2020, ISO 39001:2012, ISO 41001:2018
Records dispersed and not centrally managed
33ISO 22313:2020, ISO 39001:2012, ISO 41001:2018
no root cause analysis
33ISO/IEC 27031:2011, PDPA Thailand, Vermont Artificial Intelligence and Consumer Data Act (AICDA)
No anonymous channel
Aviation information security management
336th Anti-Money Laundering Directive (AMLD6, Directive (EU) 2018/1673), EASA Part-IS, ISO 37301
Missing risk analysis
33Nebraska Data Privacy Act, New Hampshire Data Privacy Act, New Jersey Data Privacy Act
Expired reagents found in active stock
33ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024
Annual cycle ad-hoc
Event wagering systems: technical certification and operational audit
33GLI-33, Global Cross-Border Privacy Rules (Global CBPR) Forum, Greece Law 4624/2019
delayed notification
33Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (UAE PDPL), PDPA Thailand, Singapore Cybersecurity Act 2018
Downstream propagation absent (siloed responses)
33Jamaica Data Protection Act 2020, Jordan Draft Personal Data Protection Law (2022), Kazakhstan Law on Personal Data and Their Protection (No. 94-V)
Performance verification skipped after relocation
33ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024
Maintenance done by unqualified staff
33ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024
Critical suppliers not risk assessed
33ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024
No portability format
33Law on Personal Data Protection (Official Gazette No. 42/2020), Ley Orgánica de Protección de Datos Personales (LOPDP), Liechtenstein DPA
No lessons captured
Digital investigation processes, Innovation management
33ISO 56002, ISO/IEC 27043:2015, NIST SP 800-150
Gaps in log generation for critical events
33NIST SP 800-171, NIST SP 800-171A Rev 3, PCI DSS 4.0
Forensic capability not validated
33NIST SP 800-171, NIST SP 800-171A Rev 3, PCI DSS 4.0
Cloud audit logs not retained
33NIST SP 800-171, NIST SP 800-171A Rev 3, PCI DSS 4.0
Application level controls absent
33NIST SP 800-171, NIST SP 800-171A Rev 3, PCI DSS 4.0
Sample size too small
33NIST SP 800-171, NIST SP 800-171A Rev 3, PCI DSS 4.0
No applicability memo
33Nebraska Data Privacy Act, New Hampshire Data Privacy Act, New Jersey Data Privacy Act
De-identification public commitment missing
33Maryland Online Data Privacy Act of 2024, Minnesota Consumer Data Privacy Act, Montana Consumer Data Privacy Act
Missing exemption documentation
Insurance cybersecurity
33NAIC Insurance Data Security Model Law (MDL-668), Nebraska Data Privacy Act, New Hampshire Data Privacy Act
Review held without top management
Asset management, Environmental management
33ISO 14001:2015, ISO 14004:2016, ISO 55001:2024
Contractor devices missing from inventory
33NIST SP 800-171, NIST SP 800-171A Rev 3, PCI DSS 4.0
Generic training only
Emergency management, business continuity and crisis management programs
33AWWA Cybersecurity Guidance for the Water Sector (American Water Works Association), NFPA 1600, NIST SP 800-171
Auditors auditing their own work
AI management, Asset management, Quality management
33ISO 55001:2024, ISO 9001:2015, ISO/IEC 42001:2023
Referral labs used without accreditation evidence
33ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024
Objectives not measurable, so achievement cannot be shown
Asset management, Environmental management
33ISO 14001:2015, ISO 14001:2026, ISO 55001:2024
No periodic review of authorization list
33NIST SP 800-171, NIST SP 800-171A Rev 3, PCI DSS 4.0
Briefings irregular
33AS9100D:2016, ISO 20000-1, ISO 27005
Context not refreshed
AI risk management, Knowledge management
33ISO 30401, ISO/IEC 23894:2023, ISO/IEC 27003:2017
Audit rights not exercised
33FCC Customer Proprietary Network Information (CPNI) and Data Breach Rules (47 CFR 64.2001-2011), Spain Organic Law 3/2018 on Data Protection and Digital Rights (LOPDGDD), Turkey KVKK
Reviews not performed
33ISO 22318, NIST SP 800-171, PCI DSS 4.0
Indirect collection notice missing
33Law No. 09-08 on the Protection of Individuals with Regard to the Processing of Personal Data, Law No. 2013-450 of 19 June 2013 on the Protection of Personal Data, Senegal Law on Personal Data Protection (Law No. 2008-12)
No Code of Conduct adoption
33Law No. 09-08 on the Protection of Individuals with Regard to the Processing of Personal Data, Law No. 2013-450 of 19 June 2013 on the Protection of Personal Data, Lithuania Law on Legal Protection of Personal Data (2018)
Training not delivered
33ISO 22739:2024, ISO 26000:2010, Kuwait Data Privacy Protection Regulation (KDPPR, 2021
Sensitive data uncategorised (treated as general)
33Jamaica Data Protection Act 2020, Jordan Draft Personal Data Protection Law (2022), Kazakhstan Law on Personal Data and Their Protection (No. 94-V)
No crisis communication plan
33Belgium CyberFundamentals, DORA, EIOPA Guidelines on ICT Security and Governance (EIOPA-BoS-20/600)
No configuration baselines
33ASIC Cyber Resilience Good Practices, C2M2, CFTC System Safeguards (17 CFR 37, 38, 39, 49)
Auditors not independent
Business continuity management, Knowledge management
33ISO 22313:2020, ISO 30401, ISO 9001
System documented once and never maintained
Asset management, Environmental management
33ISO 14001:2015, ISO 14001:2026, ISO 55001:2024
Breach detection passive (manual reports only)
33Jamaica Data Protection Act 2020, Jordan Draft Personal Data Protection Law (2022), Kenya Data Protection Act
Consent records weak (bundled + pre-ticked)
33Jamaica Data Protection Act 2020, Jordan Draft Personal Data Protection Law (2022), Kenya Data Protection Act
Interested parties listed without the requirement each imposes
Anti-bribery management, Privacy information management
33ISO 37001:2016, ISO 37001:2025, ISO/IEC 27701:2025
No internal audit programme
33NATO AQAP 2110, Turkey KVKK, Union Customs Code (UCC)
Software versions not tracked per analyser
33ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024
Segregation between incompatible activities unclear
33ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024
No DPIA for high-risk
33Law on Personal Data Protection (Official Gazette No. 42/2020), Ley Orgánica de Protección de Datos Personales (LOPDP), Liechtenstein DPA
Missing insurance coverage
ISMS certification body requirements
33ISO/IEC 17025:2017, ISO/IEC 27006-1:2024, South Korea PIPA
Remote access without MFA
33IEC 62443, TISAX, US Maritime Transportation Security Act (MTSA) and USCG Cybersecurity Requirements
Sectoral coordination weak
Banking supervision
33GS1 Global Standards, HKMA Cyber Resilience Assessment Framework (C-RAF), HKMA SPM
Standing privileged access
33Azure Security Benchmark, CISA Zero Trust Maturity Model, DoD Zero Trust Reference Architecture
No transition plan
33Brazil AI Framework, Brazil Open Finance (Resolução Conjunta No. 1/2020), CDP (formerly Carbon Disclosure Project)
keys never rotated
Aviation information security management
33AWS Well-Architected Security Pillar, EASA Part-IS, PCI DSS 4.0
Self-signed certificates in production
333GPP 5G Security Architecture (TS 33.501), Azure Security Benchmark, UK Defence Standard 05-138
Classification not documented
33Brazil AI Framework, Canada Artificial Intelligence and Data Act (AIDA), Russia Federal Law on Personal Data (152-FZ)
Evidence not preserved
Aviation information security management
33EASA Part-IS, NIST SP 800-161, US Foreign Corrupt Practices Act (FCPA)
Templates outdated
Business continuity management, Business continuity, business impact analysis
33ISO 22313:2020, ISO/TS 22317:2021, NIST SP 800-161
no independent audit
33Digital Services Act (DSA), Kuwait Data Privacy Protection Regulation (KDPPR, 2021, TNFD Recommendations
No regulatory mapping
33ISO 15189:2022, ISO 27005, ISO/IEC 25012:2008
Changes made without reviewing environmental consequences
Environmental management
33ISO 14001:2015, ISO 14001:2026, ISO 14004:2016
Uncontrolled documents
Environmental management, Food safety management
33DAMA-DMBOK2, ISO 14004:2016, ISO 22000:2018
no annual review evidence
33AWWA Cybersecurity Guidance for the Water Sector (American Water Works Association), NIST SP 800-61, NIST Special Publication 800-34 Revision 1, Contingency Planning Guide for Federal Information Systems
Contractors not screened
33ISO 27019, NIST SP 800-171 Rev 3, PCI DSS 4.0
Weak authentication
33Brazil Open Finance (Resolução Conjunta No. 1/2020), NIST SP 800-123, TNFD Recommendations
International cooperation absent
33French Sapin II Law (Law No. 2016-1691), Ghana Cybersecurity Act, Ghana Data Protection Act 2012 (Act 843)
No complaints process
33Australia Consumer Data Right, Australia NHMRC National Statement on Ethical Conduct in Human Research, Australian Privacy Principles (APPs)
No retention policy
33ISO 22739:2024, NIST SP 800-128, Sigstore
Dependencies not mapped
33APRA CPS 230 Operational Risk Management, ISO 22313:2020, ISO/IEC 29134:2023
No prior consultation
Data protection and privacy
33Law on Personal Data Protection (Official Gazette No. 42/2020), Ley Orgánica de Protección de Datos Personales (LOPDP), Nigeria Data Protection Act 2023 (NDPA)
Follow-ups close on promise not evidence
Enterprise risk management
33ISO 15189:2022, ISO 19011, ISO 31000:2018
Complaints not handled or escalated
33Bermuda Personal Information Protection Act 2016 (PIPA), Bosnia and Herzegovina Law on Protection of Personal Data (2006, amended 2011), Botswana Data Protection Act (2024)
No revocation mechanism
33Botswana Data Protection Act (2024), Connecticut Data Privacy Act (CTDPA), Costa Rica Personal Data Protection Law (Law No. 8968) as amended by Executive Decree No. 42089-MGP
No documented rationale
ISMS certification body requirements
33ISO/IEC 27006-1:2024, PCI DSS 4.0, Union Customs Code (UCC)
Logs collected but not parsed by SIEM
33ISO 13485, ISO 15189:2022, ISO 19011
Sampling plan not statistically justified
3321 CFR Part 211, ISO 15189:2022, ISO/IEC 17025:2017
Use cases focused on IT, missing SWIFT-specific scenarios
33ISO 13485, ISO 15189:2022, ISO 19011
Risk register not refreshed on a defined cadence
33ASIS SPC.1-2009, AWWA Cybersecurity Guidance for the Water Sector (American Water Works Association), ISO/IEC 27003:2017
Out of date records
ISMS certification body requirements
33ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006-1:2024
Sampling not representative
Enterprise risk management
3321 CFR Part 211, ISO 19011, ISO 31000:2018
Reviews not minuted
Enterprise risk management
33ISO 13485, ISO 19011, ISO 31000:2018
Competence assumed from job titles
Compliance management, Compliance management; effectiveness evaluation, Quality plans
33ISO 10005:2018, ISO 37301:2021, ISO 37302:2025
Out of service equipment used for urgent work
33ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024
Production data copied to test
33NIST SP 800-53 Rev 5 LOW, NIST SP 800-53 Rev 5 MODERATE, NIST SP 800-53 Revision 5.1 HIGH
Lessons learned not implemented
33NIST SP 800-53 Rev 5, PCI DSS 4.0, Senegal Law on Personal Data Protection (Law No. 2008-12)
Setpoints drift between shifts
Business continuity management, Energy management, Road traffic safety management
33ISO 22313:2020, ISO 39001:2012, ISO 50001:2018
Same nonconformity recurring across audits
Anti-bribery management, Privacy information management
33ISO 37001:2016, ISO 37001:2025, ISO/IEC 27701:2025
Reference material traceability not documented to SI where applicable
33ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024
Calibration providers not assessed for competence
33ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024
Outsourced providers have no energy obligations
Business continuity management, Facility management, Road traffic safety management
33ISO 22313:2020, ISO 39001:2012, ISO 41001:2018
Material changes not notified
33Ethiopia Personal Data Protection Proclamation (No. 1321/2024), Kenya Data Protection Act, South Korea Cloud Security Assurance Program (CSAP)
Lot bridging absent for critical assays
33ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024
Suppliers not assessed against energy criteria
Business continuity management, Energy management, Facility management
33ISO 22313:2020, ISO 41001:2018, ISO 50001:2018
Procurement decisions based on capex only
Business continuity management, Energy management, Facility management
33ISO 22313:2020, ISO 41001:2018, ISO 50001:2018
Certificates of destruction not retained
33HIPAA Security Rule, ISO/IEC 27701:2019, NIST SP 800-66 Rev 2
No link between scope changes and resource updates
33ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024
Surge capacity not planned
33ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024
Removable media unrestricted
33Cyber Essentials Plus, HIPAA Security Rule, NIST SP 800-66 Rev 2
No communication plan
Enterprise risk management
33ASIC Cyber Resilience Good Practices, Australian Energy Sector Cyber Security Framework (AESCSF), ISO 31000:2018
Subcontracted resources not included in plan
33ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024
Critical suppliers single sourced
33ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024
Plan never exercised
33Authorised Economic Operator (AEO) Programmes, BS 65000:2014, NIST SP 800-82 Rev 3
Specifications not updated after method changes
33ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024
Supplier performance not reviewed annually
33ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024
No verification after software upgrades
33ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024
Statutory timeframes missed
33Bermuda Personal Information Protection Act 2016 (PIPA), Bosnia and Herzegovina Law on Protection of Personal Data (2006, amended 2011), Botswana Data Protection Act (2024)
No community engagement
Building sustainability assessment and certification
33Australia NHMRC National Statement on Ethical Conduct in Human Research, BREEAM, LEADS in a Caring Environment
Over-collection beyond stated purpose
Personal information protection
33China Personal Information Protection Law (PIPL), Colorado Privacy Act, Connecticut Data Privacy Act (CTDPA)
Access controls not enforced for visitors
33ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024
Authorization granted without practical assessment
33ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024
No periodic review of agreements
33ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024
No 10-year supply-chain records
33EU Cyber Resilience Act, EU In Vitro Diagnostic Medical Devices Regulation (IVDR), EU Machinery Regulation (Regulation (EU) 2023/1230)
Reassessment intervals not defined
33ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024
Subcontracted personnel competence not verified
33ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024
No record of authorization changes when methods change
33ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024
Stale compliance review
Data protection and privacy
33Nebraska Data Privacy Act, New Hampshire Data Privacy Act, Nigeria Data Protection Act 2023 (NDPA)
No 72-hour notification capability
Personal data protection
33Egypt Personal Data Protection Law (Law No. 151 of 2020), Malta Data Protection Act (Cap. 586, 2018), Montenegro Law on Personal Data Protection (2023)
Workload not measured against capacity
33ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024
Competence on rare assays not maintained
33ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024
No minimisation justification
33Nebraska Data Privacy Act, New Hampshire Data Privacy Act, New Jersey Data Privacy Act
Vendor risk assessments not refreshed at the required cadence
33Solvency II, South Korea ISMS-P, Space ISAC (Information Sharing and Analysis Center)
Budget cycles not aligned with method changes
33ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024
identity verification overly burdensome
Privacy framework
33ISO/IEC 29100:2024, South Korea Credit Information Act, Uzbekistan Law on Personal Data (No. ZRU-547)
Documentation only for notified breaches
33Jordan Draft Personal Data Protection Law (2022), Kazakhstan Law on Personal Data and Their Protection (No. 94-V), Kenya Data Protection Act
Findings unremediated
33COBIT 2019, HIPAA Security Rule, NIST SP 800-66 Rev 2
New starter checklist incomplete
33ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024
Notifiable breaches not reported
33Australian Energy Sector Cyber Security Framework (AESCSF), Botswana Data Protection Act (2024), Brunei Personal Data Protection Order 2022 (PDPO)
No independent review
ISMS certification body requirements, Medical device software life cycle processes
33Canada Artificial Intelligence and Data Act (AIDA), IEC 62304:2015 Medical Device Software Lifecycle Processes, ISO/IEC 27006-1:2024
Inadequate security measures
33Argentina Law 25.326 (Personal Data Protection Law), Azerbaijan Law on Personal Data (2010), Netherlands GDPR Implementation Act (UAVG
Corrective actions not tracked
Compliance management; effectiveness evaluation, Conformity assessment; AI governance
33ISO 37002:2021, ISO 37302:2025, ISO/IEC 42006:2025
No certificate of destruction
Criminal justice information security
33Cambodia Sub-Decree on Personal Data Protection (Sub-Decree No. 134), FBI CJIS Security Policy, NIST SP 800-171
Storage temperature deviations not actioned
33ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024
Subcontractor flow-down clauses absent or weak in contracts
33Solvency II, South Korea ISMS-P, Space ISAC (Information Sharing and Analysis Center)
Authorization tied to job title rather than verified competence
ISMS certification body requirements
33ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006-1:2024
No privacy program plan distinct from security
33NIST SP 800-53 Rev 5 LOW, NIST SP 800-53 Rev 5 MODERATE, NIST SP 800-53 Revision 5.1 HIGH
Out of service status not flagged in LIS
33ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024
Renewable or low carbon options not evaluated
33ISO 22313:2020, ISO 39001:2012, ISO 41001:2018
No breach notification process
33Albania Law on Protection of Personal Data (Law No. 9887, 2008, amended 2014), Argentina Law 25.326 (Personal Data Protection Law), Data Protection Act 2017
No completion tracking
33Canada's Anti-Spam Legislation (CASL), ISO/IEC 27003:2017, PCI DSS 4.0
Findings not tracked to closure
Automotive system, software, hardware and machine learning engineering process capability, Biometric privacy, Governance of organizations
33Automotive SPICE (ASPICE) v4.1, ISO 37000:2021, Illinois Biometric Information Privacy Act (BIPA)
No drift monitoring
AI risk management
33Canada Artificial Intelligence and Data Act (AIDA), ISO/IEC 23894:2023, PCI DSS 4.0
Required records not identified
Asset management, Occupational health and safety, Quality management
33ISO 45001:2018, ISO 55001:2014, ISO 9001:2015
No objection mechanism
33African Union Malabo Convention, Angola Personal Data Protection Law (Law No. 22/11), Data Protection Act 2017
Maintenance carried out by users without training
33ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024
Appeals not tracked
33Botswana Data Protection Act (2024), Brunei Personal Data Protection Order 2022 (PDPO), South Korea Korea Internet Self-Governance Organisation (KISO) Code of Ethics
Reference material lot changes not bridged
33ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024
Sectoral application gaps
Health information privacy and security, Leadership development
33GS1 Global Standards, HITECH Act, Hersey & Blanchard Situational Leadership Model
No maturity assessment
33BS 65000:2014, Kuwait National Cybersecurity Framework, NIST SP 800-150
Containment level not validated for new agents
33ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024
Storage of patient samples not segregated from reagents
33ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024
Security not documented
33Bosnia and Herzegovina Law on Protection of Personal Data (2006, amended 2011), Botswana Data Protection Act (2024), Brunei Personal Data Protection Order 2022 (PDPO)
Root cause analysis superficial
Laboratory competence, Quality management
33ISO 15189:2022, ISO 9001:2015, ISO/IEC 17025:2017
Opportunities never identified
Environmental management, Food safety management, Quality management
33ISO 14001:2026, ISO 22000:2018, ISO 9001:2015
No review after a real incident
Environmental management, Food safety management
33ISO 14001:2015, ISO 14001:2026, ISO 22000:2018
split tunneling enabled
33FedRAMP High, FedRAMP Moderate, NIST SP 800-171 Rev 3
Cleaning and decontamination logs incomplete
33ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024
Modifications bypass design review
33ISO 22313:2020, ISO 39001:2012, ISO 41001:2018
Correspondence not tracked
33Bermuda Personal Information Protection Act 2016 (PIPA), Bosnia and Herzegovina Law on Protection of Personal Data (2006, amended 2011), Botswana Data Protection Act (2024)
Roadmap not tracked
GxP computerized systems: risk-based compliance and fitness for intended use across the system life cycle
33GAMP 5, Global Cross-Border Privacy Rules (Global CBPR) Forum, HKMA Cyber Resilience Assessment Framework (C-RAF)
No covert channel detection
33FedRAMP High, FedRAMP Moderate, PCI DSS 4.0
No matching agreements
33NIST SP 800-53 Rev 5 LOW, NIST SP 800-53 Rev 5 MODERATE, NIST SP 800-53 Revision 5.1 HIGH
No performance evidence
ISMS certification body requirements
33ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006-1:2024
No evidence of practical assessment for new methods
ISMS certification body requirements
33ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006-1:2024
Training records missing for locum or agency staff
ISMS certification body requirements
33ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006-1:2024
SSN used as primary key
33NIST SP 800-53 Rev 5 LOW, NIST SP 800-53 Rev 5 MODERATE, NIST SP 800-53 Revision 5.1 HIGH
No threat modeling
33CNCF Security Technical Advisory Group (TAG), FedRAMP High, FedRAMP Moderate
Health PII commingled
33NIST SP 800-53 Rev 5 LOW, NIST SP 800-53 Rev 5 MODERATE, NIST SP 800-53 Revision 5.1 HIGH
Vague lawful basis
33NIST SP 800-53 Rev 5 LOW, NIST SP 800-53 Rev 5 MODERATE, NIST SP 800-53 Revision 5.1 HIGH
No purposing analysis
33NIST SP 800-53 Rev 5 LOW, NIST SP 800-53 Rev 5 MODERATE, NIST SP 800-53 Revision 5.1 HIGH
No risk executive function
33NIST SP 800-53 Rev 5 LOW, NIST SP 800-53 Rev 5 MODERATE, NIST SP 800-53 Revision 5.1 HIGH
No external privacy reporting
33NIST SP 800-53 Rev 5 LOW, NIST SP 800-53 Rev 5 MODERATE, NIST SP 800-53 Revision 5.1 HIGH
Lessons learned not actioned
33EASA Part-IS, NIST SP 800-171 Rev 3, PCI DSS 4.0
Improvements not tracked
33COSO Enterprise Risk Management (ERM) Framework (2017), ISO 20400:2017, ISO/IEC 17025:2017
No privacy-specific policy
33NIST SP 800-53 Rev 5 LOW, NIST SP 800-53 Rev 5 MODERATE, NIST SP 800-53 Revision 5.1 HIGH
DGB exists in name only
33NIST SP 800-53 Rev 5 LOW, NIST SP 800-53 Rev 5 MODERATE, NIST SP 800-53 Revision 5.1 HIGH
No disclosure register
33NIST SP 800-53 Rev 5 LOW, NIST SP 800-53 Rev 5 MODERATE, NIST SP 800-53 Revision 5.1 HIGH
Energy specifications not communicated to suppliers
Business continuity management, Energy management, Facility management
33ISO 22313:2020, ISO 41001:2018, ISO 50001:2018
Board reporting infrequent or absent
33Jamaica Data Protection Act 2020, Jordan Draft Personal Data Protection Law (2022), Kazakhstan Law on Personal Data and Their Protection (No. 94-V)
Processor notification absent in contracts
33Jamaica Data Protection Act 2020, Jordan Draft Personal Data Protection Law (2022), Kenya Data Protection Act
Lawful basis selected after processing (consent bias)
33Jamaica Data Protection Act 2020, Jordan Draft Personal Data Protection Law (2022), Kazakhstan Law on Personal Data and Their Protection (No. 94-V)
Privacy notices out of date
33NIST SP 800-53 Rev 5 LOW, NIST SP 800-53 Rev 5 MODERATE, NIST SP 800-53 Revision 5.1 HIGH
Appetite not approved at board level
33NIST SP 800-53 Rev 5 LOW, NIST SP 800-53 Rev 5 MODERATE, NIST SP 800-53 Revision 5.1 HIGH
DSAR portal absent (email-only handling)
33Jordan Draft Personal Data Protection Law (2022), Kazakhstan Law on Personal Data and Their Protection (No. 94-V), Kenya Data Protection Act
RoPA missing or incomplete
33Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (UAE PDPL), Fiji Data Protection Bill (2020), Georgia Law on Personal Data Protection (2012)
No CI mapping for the organization
33NIST SP 800-53 Rev 5 LOW, NIST SP 800-53 Rev 5 MODERATE, NIST SP 800-53 Revision 5.1 HIGH
No behavior baseline
33FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Revision 5.1 HIGH
Training delivered but effectiveness never evaluated
Compliance management; competence management, Environmental management
33ISO 14001:2015, ISO 14001:2026, ISO 37303:2025
Unlimited concurrent sessions
33FedRAMP High, FedRAMP Moderate, NIST SP 800-53 Revision 5.1 HIGH
Backup analysers not maintained to same standard
33ISO 15189:2022, ISO/IEC 17025:2017, ISO/IEC 27006:2024
No authority assessment
33NIST SP 800-53 Rev 5 LOW, NIST SP 800-53 Rev 5 MODERATE, NIST SP 800-53 Revision 5.1 HIGH
No HR/Legal/IT working group
33NIST SP 800-53 Rev 5 LOW, NIST SP 800-53 Rev 5 MODERATE, NIST SP 800-53 Revision 5.1 HIGH
No SORN for in-scope systems
33NIST SP 800-53 Rev 5 LOW, NIST SP 800-53 Rev 5 MODERATE, NIST SP 800-53 Revision 5.1 HIGH
Notice misaligned with actual processing
33NIST SP 800-53 Rev 5 LOW, NIST SP 800-53 Rev 5 MODERATE, NIST SP 800-53 Revision 5.1 HIGH
Purposes drift after launch
33NIST SP 800-53 Rev 5 LOW, NIST SP 800-53 Rev 5 MODERATE, NIST SP 800-53 Revision 5.1 HIGH
Role split between functions
33NIST SP 800-53 Rev 5 LOW, NIST SP 800-53 Rev 5 MODERATE, NIST SP 800-53 Revision 5.1 HIGH
Framing assumptions undocumented
33NIST SP 800-53 Rev 5 LOW, NIST SP 800-53 Rev 5 MODERATE, NIST SP 800-53 Revision 5.1 HIGH
No oversight of data matching
33NIST SP 800-53 Rev 5 LOW, NIST SP 800-53 Rev 5 MODERATE, NIST SP 800-53 Revision 5.1 HIGH
No CUI clauses in contracts
33NIST SP 800-53 Rev 5 LOW, NIST SP 800-53 Rev 5 MODERATE, NIST SP 800-53 Revision 5.1 HIGH
No threat-sharing memberships
33NIST SP 800-53 Rev 5 LOW, NIST SP 800-53 Rev 5 MODERATE, NIST SP 800-53 Revision 5.1 HIGH
Testing siloed by system
33NIST SP 800-53 Rev 5 LOW, NIST SP 800-53 Rev 5 MODERATE, NIST SP 800-53 Revision 5.1 HIGH
Plan stale or generic
33NIST SP 800-53 Rev 5 LOW, NIST SP 800-53 Rev 5 MODERATE, NIST SP 800-53 Revision 5.1 HIGH
No role-based pathway
33NIST SP 800-53 Rev 5 LOW, NIST SP 800-53 Rev 5 MODERATE, NIST SP 800-53 Revision 5.1 HIGH
Budget not tracked separately
33NIST SP 800-53 Rev 5 LOW, NIST SP 800-53 Rev 5 MODERATE, NIST SP 800-53 Revision 5.1 HIGH
Privacy considered only at the end
33NIST SP 800-53 Rev 5 LOW, NIST SP 800-53 Rev 5 MODERATE, NIST SP 800-53 Revision 5.1 HIGH
Authorization stale
33NIST SP 800-53 Rev 5 LOW, NIST SP 800-53 Rev 5 MODERATE, NIST SP 800-53 Revision 5.1 HIGH

What this is, and what it is not

It is
A count. 826 failures, each named by three or more frameworks, with the artefacts that close them.
It is not
A prediction, a severity score, or a claim about how often these happen in the wild. We do not measure that and we will not pretend to.
Source
The control libraries of 723 frameworks, 531 of them verified against their source documents.
Threshold
Three frameworks. Below that a phrase is one verifier's wording rather than a general problem.
On each page
What closing that failure also buys you, traversed from 332,959 cross-framework control mappings. One piece of work, counted once, against every obligation it satisfies.

The corpus this comes from

723 frameworks, 20,473 controls, 332,959 cross-framework mappings, 531 frameworks verified against source documents.

See the corpus