Framework overlap

Does NIST SP 800-171A Rev 3 cover Illinois Biometric Information Privacy Act (BIPA)?

You hold NIST SP 800-171A Rev 3 and have been told to do Illinois Biometric Information Privacy Act (BIPA). Here is how much overlaps, control by control.

13% of Illinois Biometric Information Privacy Act (BIPA) you already have

NIST SP 800-171A Rev 3 already covers about 13% of Illinois Biometric Information Privacy Act (BIPA), leaving 28 of 32 controls as genuinely new work.

Already covered 2 Likely covered 2 New work 28

What is genuinely new work

Nothing in NIST SP 800-171A Rev 3 reaches these. This is the list to scope.

7012(b)(1)
Covered Defence Information Identification
7012(b)(2)
Scope of Protected Systems
7012(b)(3)
COTS Exclusion
BIPA-AUDIT
Periodic Audit and Compliance Review
BIPA-EMPLOYEE
Employee Biometric Programs (Timekeeping, Access)
BIPA-EXEMPT
Statutory Exemptions
BIPA-INCIDENT
Incident Response for Biometric Compromise
BIPA-IRRECOV
Irreversible Harm and Special Risk Recognition
BIPA-MINORS
Minors and Authorised Representatives
BIPA-PRA
Private Right of Action and Statutory Damages
BIPA-SEC10-DEF
Biometric Identifier and Information Definitions
BIPA-SEC15A-DESTROY
Destruction When Purpose Satisfied or Three Years Inactive
BIPA-SEC15A-POLICY
Written Retention and Destruction Policy
BIPA-SEC15B-CONSENT
Written Release (Informed Consent)
BIPA-SEC15B-NOTICE
Written Notice Before Collection
BIPA-SEC15C-PROFIT
No Sale, Lease, Trade, or Profit
BIPA-SEC15D-DISCLOSE
Disclosure Restrictions
BIPA-SEC15E-STORE
Reasonable Standard of Care and Storage Protections
BIPA-SEC15a
Written Informed Consent Required
BIPA-SEC15b
Disclosure and Profit Prohibition
BIPA-SEC15c
Disclosure Restriction
BIPA-SEC15d
Retention and Destruction Policy
BIPA-SEC15e
Storage and Protection Requirements
BIPA-SEC5-3
Private Entity Definition
BIPA-TRAIN
Workforce Training
BIPA-VENDOR
Vendor and Processor Contracts
CTDPA-2
Applicability Thresholds
MSA-Threshold
Revenue Threshold
Show the 4 you already have
BIPA-SEC5-1
Biometric Identifier Definition
BIPA-SEC5-2
Biometric Information Definition
MSA-5
Definition of Modern Slavery
MSA-Commonwealth
Commonwealth Entities

How this is calculated

Already covered means a mapping runs from a control in NIST SP 800-171A Rev 3 to that control. Likely covered means no direct mapping exists but both frameworks map to the same control in a third standard. New work means neither. We keep those separate rather than adding them into one friendlier number, because blending them would present a two-hop inference as a verified fact.

Coverage is not symmetric. Run it the other way and you will get a different number; both are correct.

From 332,959 cross-framework control mappings across 723 frameworks, 531 of them verified against their source documents. It does not tell you that you are compliant: a mapped control means the two standards ask for the same thing, not that you have done it.

Try another pair ยท Today's edition