# Principles for Financial Market Infrastructures

Framework id: `cpmi_pfmi`. Global Financial Standard. Publisher: CPMI-IOSCO (BIS / IOSCO). Version: 2012. Region: Global. Mapping licence: CC BY-SA 4.0.
Source text: https://www.bis.org/cpmi/publ/d101a.htm

Each line is a clause, the NIST SP 800-53 controls OSA maps to it, and OSA's estimate of how far those controls cover it.
Clause titles and coverage figures are OSA's own summaries and estimates. No line-by-line check against the source text is recorded for this framework, so quote the source, not this card.

## Clauses (13, average coverage 74%)
- CG.DE Cyber Guidance — Detection: AU-02, AU-03, AU-04, AU-05, AU-06, AU-07, AU-09, AU-12, AU-13, AU-14, CA-07, IR-04, PM-14, PM-16, RA-05, RA-10, SC-05, SC-07, SC-26, SI-03, SI-04, SI-05, SI-07 (85%)
- CG.GOV Cyber Guidance — Governance: AT-01, AT-02, AT-03, AT-06, PL-01, PL-04, PL-09, PM-01, PM-02, PM-03, PM-13, PM-14, PM-29, PS-01, PS-02, PS-03, PS-06, PS-09 (73%)
- CG.ID Cyber Guidance — Identification: CM-08, CM-12, CM-13, PM-05, PM-11, RA-02, RA-03, RA-05, RA-06, RA-09, RA-10, SA-09, SA-15, SR-01, SR-02, SR-06 (80%)
- CG.LE Cyber Guidance — Learning and evolving: AT-02, AT-03, AT-06, CA-02, CA-05, CA-07, IR-04, IR-05, PM-04, PM-14, PM-31, RA-07, SI-02 (74%)
- CG.PR Cyber Guidance — Protection: AC-02, AC-03, AC-04, AC-05, AC-06, AC-07, AC-11, AC-17, AC-19, AC-20, CM-02, CM-03, CM-05, CM-06, CM-07, IA-02, IA-04, IA-05, IA-08, IA-12, MA-04, MP-02, MP-04, MP-06, PE-02, PE-03, PE-06, SC-02, SC-03, SC-04, SC-07, SC-08, SC-12, SC-13, SC-28, SC-39, SI-02, SI-03, SI-07, SI-16, SR-03, SR-05, SR-11 (87%)
- CG.RR Cyber Guidance — Response and recovery: CP-01, CP-02, CP-03, CP-04, CP-06, CP-07, CP-08, CP-09, CP-10, CP-12, CP-13, IR-01, IR-02, IR-03, IR-04, IR-05, IR-06, IR-07, IR-08, IR-09, PE-11, PE-17, PM-08, SC-24, SC-36 (78%)
- CG.SA Cyber Guidance — Situational awareness: AU-13, PM-12, PM-15, PM-16, RA-03, RA-05, RA-10, SI-05, SR-06, SR-08 (72%)
- CG.TE Cyber Guidance — Testing: CA-02, CA-04, CA-08, CP-04, IR-03, PM-14, PM-16, RA-05, RA-06, SA-11, SA-15, SC-26, SI-06 (75%)
- PFMI.P2 Principle 2 — Governance arrangements: AC-01, AT-01, CA-01, PL-01, PL-09, PM-01, PM-02, PM-03, PM-13, PM-14, PM-29, PS-01, RA-01, SA-01 (68%)
- PFMI.P3 Principle 3 — Framework for the comprehensive management of risks: CA-02, CA-05, CA-06, CA-07, PL-02, PL-09, PM-01, PM-04, PM-05, PM-08, PM-09, PM-28, RA-01, RA-02, RA-03, RA-07, RA-09, SA-08, SA-09 (72%)
- PFMI.P15 Principle 15 — General business risk: CP-02, PL-02, PM-01, PM-03, PM-09, PM-11, RA-03, SA-02 (42%)
- PFMI.P17 Principle 17 — Operational risk management: AC-01, AC-02, AC-03, AC-04, AC-06, AU-02, AU-03, AU-06, AU-12, CA-02, CA-07, CM-01, CM-02, CM-03, CM-06, CM-08, CP-01, CP-02, CP-03, CP-04, CP-06, CP-07, CP-08, CP-09, CP-10, IA-01, IA-02, IA-05, IR-01, IR-02, IR-03, IR-04, IR-05, IR-06, IR-08, MA-01, MA-02, MA-05, PE-01, PE-02, PE-09, PE-10, PE-11, PE-12, PE-13, PE-14, PE-17, PL-02, PM-08, PM-09, PM-11, RA-03, RA-05, SA-04, SA-05, SA-08, SA-09, SA-11, SC-05, SC-07, SC-08, SC-28, SI-02, SI-04, SI-07, SR-01, SR-03, SR-05 (82%)
- PFMI.P22 Principle 22 — Communication procedures and standards: AC-04, AC-17, CA-03, CM-06, IA-03, PL-08, SA-04, SA-09, SC-07, SC-08, SC-13, SC-16, SC-23 (70%)

## More
- A pattern's controls with their clauses in this framework: /api/v1/patterns/{id}/crosswalk?framework=cpmi_pfmi
- Control-to-clause mappings as JSON: /api/v1/frameworks/cpmi_pfmi?fields=mappings&per_page=100
- Rationale and gaps for each clause, as JSON: https://raw.githubusercontent.com/opensecurityarchitecture/osa-data/main/data/framework-coverage/cpmi-pfmi.json
- Page for people: /frameworks/cpmi-pfmi/
