πΌ Access Control | 18 | | | |
πΌ AC-1 Policy and Procedures (L)(M)(H) | | | | |
πΌ AC-2 Account Management (L)(M)(H) | 9 | | 3 | |
πΌ AC-2(1) Automated System Account Management (M)(H) | | | 16 | |
πΌ AC-2(2) Automated Temporary and Emergency Account Management (M)(H) | | | | |
πΌ AC-2(3) Disable Accounts (M)(H) | | | 4 | |
πΌ AC-2(4) Automated Audit Actions (M)(H) | | | 13 | |
πΌ AC-2(5) Inactivity Logout (M)(H) | | | | |
πΌ AC-2(7) Privileged User Accounts (M)(H) | | | 7 | |
πΌ AC-2(9) Restrictions on Use of Shared and Group Accounts (M)(H) | | | 2 | |
πΌ AC-2(12) Account Monitoring for Atypical Usage (M)(H) | | | 2 | |
πΌ AC-2(13) Disable Accounts for High-risk Individuals (M)(H) | | | | |
πΌ AC-3 Access Enforcement (L)(M)(H) | | | 46 | |
πΌ AC-4 Information Flow Enforcement (M)(H) | 1 | | 27 | |
πΌ AC-4(21) Physical or Logical Separation of Information Flows (M)(H) | | | 38 | |
πΌ AC-5 Separation of Duties (M)(H) | | | 1 | |
πΌ AC-6 Least Privilege (M)(H) | 6 | | 7 | |
πΌ AC-6(1) Authorize Access to Security Functions (M)(H) | | | 4 | |
πΌ AC-6(2) Non-privileged Access for Nonsecurity Functions (M)(H) | | | 4 | |
πΌ AC-6(5) Privileged Accounts (M)(H) | | | 5 | |
πΌ AC-6(7) Review of User Privileges (M)(H) | | | 2 | |
πΌ AC-6(9) Log Use of Privileged Functions (M)(H) | | | 23 | |
πΌ AC-6(10) Prohibit Non-privileged Users from Executing Privileged Functions (M)(H) | | | 3 | |
πΌ AC-7 Unsuccessful Logon Attempts (L)(M)(H) | | | 1 | |
πΌ AC-8 System Use Notification (L)(M)(H) | | | | |
πΌ AC-10 Concurrent Session Control (H) | | | | |
πΌ AC-11 Device Lock (M)(H) | 1 | | | |
πΌ AC-11(1) Pattern-hiding Displays (M)(H) | | | | |
πΌ AC-12 Session Termination (M)(H) | | | | |
πΌ AC-14 Permitted Actions Without Identification or Authentication (L)(M)(H) | | | | |
πΌ AC-17 Remote Access (L)(M)(H) | 4 | | | |
πΌ AC-17(1) Monitoring and Control (M)(H) | | | 1 | |
πΌ AC-17(2) Protection of Confidentiality and Integrity Using Encryption (M)(H) | | | 13 | |
πΌ AC-17(3) Managed Access Control Points (M)(H) | | | | |
πΌ AC-17(4) Privileged Commands and Access (M)(H) | | | | |
πΌ AC-18 Wireless Access (L)(M)(H) | 2 | | | |
πΌ AC-18(1) Authentication and Encryption (M)(H) | | | | |
πΌ AC-18(3) Disable Wireless Networking (M)(H) | | | | |
πΌ AC-19 Access Control for Mobile Devices (L)(M)(H) | 1 | | | |
πΌ AC-19(5) Full Device or Container-based Encryption (M)(H) | | | | |
πΌ AC-20 Use of External Systems (L)(M)(H) | 2 | | | |
πΌ AC-20(1) Limits on Authorized Use (M)(H) | | | | |
πΌ AC-20(2) Portable Storage Devices β Restricted Use (M)(H) | | | | |
πΌ AC-21 Information Sharing (M)(H) | | | 2 | |
πΌ AC-22 Publicly Accessible Content (L)(M)(H) | | | | |
πΌ Assessment, Authorization, and Monitoring | 8 | | | |
πΌ CA-1 Policy and Procedures (L)(M)(H) | | | | |
πΌ CA-2 Control Assessments (L)(M)(H) | 2 | | | |
πΌ CA-2(1) Independent Assessors (L)(M)(H) | | | | |
πΌ CA-2(3) Leveraging Results from External Organizations (M)(H) | | | | |
πΌ CA-3 Information Exchange (L)(M)(H) | | | | |
πΌ CA-5 Plan of Action and Milestones (L)(M)(H) | | | | |
πΌ CA-6 Authorization (L)(M)(H) | | | | |
πΌ CA-7 Continuous Monitoring (L)(M)(H) | 2 | | 8 | |
πΌ CA-7(1) Independent Assessment (M)(H) | | | | |
πΌ CA-7(4) Risk Monitoring (L)(M)(H) | | | | |
πΌ CA-8 Penetration Testing (L)(M)(H) | 2 | | | |
πΌ CA-8(1) Independent Penetration Testing Agent or Team (M)(H) | | | | |
πΌ CA-8(2) Red Team Exercises (M)(H) | | | | |
πΌ CA-9 Internal System Connections (L)(M)(H) | | | | |
πΌ Audit and Accountability | 11 | | | |
πΌ AU-1 Policy and Procedures (L)(M)(H) | | | | |
πΌ AU-2 Event Logging (L)(M)(H) | | | 6 | |
πΌ AU-3 Content of Audit Records (L)(M)(H) | 1 | | 6 | |
πΌ AU-3(1) Additional Audit Information (M)(H) | | | 14 | |
πΌ AU-4 Audit Log Storage Capacity (L)(M)(H) | | | | |
πΌ AU-5 Response to Audit Logging Process Failures (L)(M)(H) | | | | |
πΌ AU-6 Audit Record Review, Analysis, and Reporting (L)(M)(H) | 2 | | 23 | |
πΌ AU-6(1) Automated Process Integration (M)(H) | | | 1 | |
πΌ AU-6(3) Correlate Audit Record Repositories (M)(H) | | | 6 | |
πΌ AU-7 Audit Record Reduction and Report Generation (M)(H) | 1 | | | |
πΌ AU-7(1) Automatic Processing (M)(H) | | | 1 | |
πΌ AU-8 Time Stamps (L)(M)(H) | | | | |
πΌ AU-9 Protection of Audit Information (L)(M)(H) | 1 | | 11 | |
πΌ AU-9(4) Access by Subset of Privileged Users (M)(H) | | | | |
πΌ AU-11 Audit Record Retention (L)(M)(H) | | | 19 | |
πΌ AU-12 Audit Record Generation (L)(M)(H) | | | 47 | |
πΌ Awareness and Training | 4 | | | |
πΌ AT-1 Policy and Procedures (L)(M)(H) | | | | |
πΌ AT-2 Literacy Training and Awareness (L)(M)(H) | 2 | | | |
πΌ AT-2(2) Insider Threat (L)(M)(H) | | | | |
πΌ AT-2(3) Social Engineering and Mining (M)(H) | | | | |
πΌ AT-3 Role-based Training (L)(M)(H) | | | | |
πΌ AT-4 Training Records (L)(M)(H) | | | | |
πΌ Configuration Management | 12 | | | |
πΌ CM-1 Policy and Procedures (L)(M)(H) | | | | |
πΌ CM-2 Baseline Configuration (L)(M)(H) | 3 | | 13 | |
πΌ CM-2(2) Automation Support for Accuracy and Currency (M)(H) | | | 13 | |
πΌ CM-2(3) Retention of Previous Configurations (M)(H) | | | 1 | |
πΌ CM-2(7) Configure Systems and Components for High-risk Areas (M)(H) | | | | |
πΌ CM-3 Configuration Change Control (M)(H) | 2 | | 17 | |
πΌ CM-3(2) Testing, Validation, and Documentation of Changes (M)(H) | | | | |
πΌ CM-3(4) Security and Privacy Representatives (M)(H) | | | | |
πΌ CM-4 Impact Analyses (L)(M)(H) | 1 | | | |
πΌ CM-4(2) Verification of Controls (M)(H) | | | | |
πΌ CM-5 Access Restrictions for Change (L)(M)(H) | 2 | | 8 | |
πΌ CM-5(1) Automated Access Enforcement and Audit Records (M)(H) | | | 9 | |
πΌ CM-5(5) Privilege Limitation for Production and Operation (M)(H) | | | 1 | |
πΌ CM-6 Configuration Settings (L)(M)(H) | 1 | | | |
πΌ CM-6(1) Automated Management, Application, and Verification (M)(H) | | | 1 | |
πΌ CM-7 Least Functionality (L)(M)(H) | 3 | | 17 | |
πΌ CM-7(1) Periodic Review (M)(H) | | | 11 | |
πΌ CM-7(2) Prevent Program Execution (M)(H) | | | | |
πΌ CM-7(5) Authorized Software β Allow-by-exception (M)(H) | | | | |
πΌ CM-8 System Component Inventory (L)(M)(H) | 2 | | 1 | |
πΌ CM-8(1) Updates During Installation and Removal (M)(H) | | | | |
πΌ CM-8(3) Automated Unauthorized Component Detection (M)(H) | | | | |
πΌ CM-9 Configuration Management Plan (M)(H) | | | | |
πΌ CM-10 Software Usage Restrictions (L)(M)(H) | | | | |
πΌ CM-11 User-installed Software (L)(M)(H) | | | 4 | |
πΌ CM-12 Information Location (M)(H) | 1 | | | |
πΌ CM-12(1) Automated Tools to Support Information Location (M)(H) | | | | |
πΌ Contingency Planning | 9 | | | |
πΌ CP-1 Policy and Procedures (L)(M)(H) | | | | |
πΌ CP-2 Contingency Plan (L)(M)(H) | 3 | | | |
πΌ CP-2(1) Coordinate with Related Plans (M)(H) | | | | |
πΌ CP-2(3) Resume Mission and Business Functions (M)(H) | | | | |
πΌ CP-2(8) Identify Critical Assets (M)(H) | | | | |
πΌ CP-3 Contingency Training (L)(M)(H) | | | | |
πΌ CP-4 Contingency Plan Testing (L)(M)(H) | 1 | | | |
πΌ CP-4(1) Coordinate with Related Plans (M)(H) | | | | |
πΌ CP-6 Alternate Storage Site (M)(H) | 2 | | | |
πΌ CP-6(1) Separation from Primary Site (M)(H) | | | | |
πΌ CP-6(3) Accessibility (M)(H) | | | | |
πΌ CP-7 Alternate Processing Site (M)(H) | 3 | | | |
πΌ CP-7(1) Separation from Primary Site (M)(H) | | | | |
πΌ CP-7(2) Accessibility (M)(H) | | | | |
πΌ CP-7(3) Priority of Service (M)(H) | | | | |
πΌ CP-8 Telecommunications Services (M)(H) | 2 | | | |
πΌ CP-8(1) Priority of Service Provisions (M)(H) | | | | |
πΌ CP-8(2) Single Points of Failure (M)(H) | | | | |
πΌ CP-9 System Backup (L)(M)(H) | 2 | | 6 | |
πΌ CP-9(1) Testing for Reliability and Integrity (M)(H) | | | | |
πΌ CP-9(8) Cryptographic Protection (M)(H) | | | | |
πΌ CP-10 System Recovery and Reconstitution (L)(M)(H) | 1 | | 2 | |
πΌ CP-10(2) Transaction Recovery (M)(H) | | | | |
πΌ Identification and Authentication | 10 | | | |
πΌ IA-1 Policy and Procedures (L)(M)(H) | | | | |
πΌ IA-2 Identification and Authentication (Organizational Users) (L)(M)(H) | 6 | | 1 | |
πΌ IA-2(1) Multi-factor Authentication to Privileged Accounts (L)(M)(H) | | | 2 | |
πΌ IA-2(2) Multi-factor Authentication to Non-privileged Accounts (L)(M)(H) | | | 2 | |
πΌ IA-2(5) Individual Authentication with Group Authentication (M)(H) | | | | |
πΌ IA-2(6) Access to Accounts βseparate Device (M)(H) | | | 2 | |
πΌ IA-2(8) Access to Accounts β Replay Resistant (L)(M)(H) | | | 2 | |
πΌ IA-2(12) Acceptance of PIV Credentials (L)(M)(H) | | | | |
πΌ IA-3 Device Identification and Authentication (M)(H) | | | | |
πΌ IA-4 Identifier Management (L)(M)(H) | 1 | | 1 | |
πΌ IA-4(4) Identify User Status (M)(H) | | | | |
πΌ IA-5 Authenticator Management (L)(M)(H) | 4 | | 17 | |
πΌ IA-5(1) Password-based Authentication (L)(M)(H) | | | 4 | |
πΌ IA-5(2) Public Key-based Authentication (M)(H) | | | 1 | |
πΌ IA-5(6) Protection of Authenticators (M)(H) | | | | |
πΌ IA-5(7) No Embedded Unencrypted Static Authenticators (M)(H) | | | | |
πΌ IA-6 Authentication Feedback (L)(M)(H) | | | 1 | |
πΌ IA-7 Cryptographic Module Authentication (L)(M)(H) | | | | |
πΌ IA-8 Identification and Authentication (Non-organizational Users) (L)(M)(H) | 3 | | | |
πΌ IA-8(1) Acceptance of PIV Credentials from Other Agencies (L)(M)(H) | | | | |
πΌ IA-8(2) Acceptance of External Authenticators (L)(M)(H) | | | | |
πΌ IA-8(4) Use of Defined Profiles (L)(M)(H) | | | | |
πΌ IA-11 Re-authentication (L)(M)(H) | | | | |
πΌ IA-12 Identity Proofing (M)(H) | 3 | | | |
πΌ IA-12(2) Identity Evidence (M)(H) | | | | |
πΌ IA-12(3) Identity Evidence Validation and Verification (M)(H) | | | | |
πΌ IA-12(5) Address Confirmation (M)(H) | | | | |
πΌ Incident Response | 9 | | | |
πΌ IR-1 Policy and Procedures (L)(M)(H) | | | | |
πΌ IR-2 Incident Response Training (L)(M)(H) | | | | |
πΌ IR-3 Incident Response Testing (M)(H) | 1 | | | |
πΌ IR-3(2) Coordination with Related Plans (M)(H) | | | | |
πΌ IR-4 Incident Handling (L)(M)(H) | 1 | | | |
πΌ IR-4(1) Automated Incident Handling Processes (M)(H) | | | | |
πΌ IR-5 Incident Monitoring (L)(M)(H) | | | | |
πΌ IR-6 Incident Reporting (L)(M)(H) | 2 | | | |
πΌ IR-6(1) Automated Reporting (M)(H) | | | 10 | |
πΌ IR-6(3) Supply Chain Coordination (M)(H) | | | 2 | |
πΌ IR-7 Incident Response Assistance (L)(M)(H) | 1 | | | |
πΌ IR-7(1) Automation Support for Availability of Information and Support (M)(H) | | | | |
πΌ IR-8 Incident Response Plan (L)(M)(H) | | | | |
πΌ IR-9 Information Spillage Response (M)(H) | 3 | | | |
πΌ IR-9(2) Training (M)(H) | | | | |
πΌ IR-9(3) Post-spill Operations (M)(H) | | | | |
πΌ IR-9(4) Exposure to Unauthorized Personnel (M)(H) | | | | |
πΌ Maintenance | 6 | | | |
πΌ MA-1 Policy and Procedures (L)(M)(H) | | | | |
πΌ MA-2 Controlled Maintenance (L)(M)(H) | | | | |
πΌ MA-3 Maintenance Tools (M)(H) | 3 | | | |
πΌ MA-3(1) Inspect Tools (M)(H) | | | | |
πΌ MA-3(2) Inspect Media (M)(H) | | | | |
πΌ MA-3(3) Prevent Unauthorized Removal (M)(H) | | | | |
πΌ MA-4 Nonlocal Maintenance (L)(M)(H) | | | | |
πΌ MA-5 Maintenance Personnel (L)(M)(H) | 1 | | | |
πΌ MA-5(1) Individuals Without Appropriate Access (M)(H) | | | | |
πΌ MA-6 Timely Maintenance (M)(H) | | | | |
πΌ Media Protection | 7 | | | |
πΌ MP-1 Policy and Procedures (L)(M)(H) | | | | |
πΌ MP-2 Media Access (L)(M)(H) | | | | |
πΌ MP-3 Media Marking (M)(H) | | | | |
πΌ MP-4 Media Storage (M)(H) | | | | |
πΌ MP-5 Media Transport (M)(H) | | | | |
πΌ MP-6 Media Sanitization (L)(M)(H) | | | | |
πΌ MP-7 Media Use (L)(M)(H) | | | | |
πΌ Personnel Security | 9 | | | |
πΌ PS-1 Policy and Procedures (L)(M)(H) | | | | |
πΌ PS-2 Position Risk Designation (L)(M)(H) | | | | |
πΌ PS-3 Personnel Screening (L)(M)(H) | 1 | | | |
πΌ PS-3(3) Information Requiring Special Protective Measures (M)(H) | | | | |
πΌ PS-4 Personnel Termination (L)(M)(H) | | | | |
πΌ PS-5 Personnel Transfer (L)(M)(H) | | | | |
πΌ PS-6 Access Agreements (L)(M)(H) | | | | |
πΌ PS-7 External Personnel Security (L)(M)(H) | | | | |
πΌ PS-8 Personnel Sanctions (L)(M)(H) | | | | |
πΌ PS-9 Position Descriptions (L)(M)(H) | | | | |
πΌ Physical and Environmental Protection | 16 | | | |
πΌ PE-1 Policy and Procedures (L)(M)(H) | | | | |
πΌ PE-2 Physical Access Authorizations (L)(M)(H) | | | | |
πΌ PE-3 Physical Access Control (L)(M)(H) | | | | |
πΌ PE-4 Access Control for Transmission (M)(H) | | | | |
πΌ PE-5 Access Control for Output Devices (M)(H) | | | | |
πΌ PE-6 Monitoring Physical Access (L)(M)(H) | 1 | | | |
πΌ PE-6(1) Intrusion Alarms and Surveillance Equipment (M)(H) | | | | |
πΌ PE-8 Visitor Access Records (L)(M)(H) | | | | |
πΌ PE-9 Power Equipment and Cabling (M)(H) | | | | |
πΌ PE-10 Emergency Shutoff (M)(H) | | | | |
πΌ PE-11 Emergency Power (M)(H) | | | | |
πΌ PE-12 Emergency Lighting (L)(M)(H) | | | | |
πΌ PE-13 Fire Protection (L)(M)(H) | 2 | | | |
πΌ PE-13(1) Detection Systems β Automatic Activation and Notification (M)(H) | | | | |
πΌ PE-13(2) Suppression Systems β Automatic Activation and Notification (M)(H) | | | | |
πΌ PE-14 Environmental Controls (L)(M)(H) | | | | |
πΌ PE-15 Water Damage Protection (L)(M)(H) | | | | |
πΌ PE-16 Delivery and Removal (L)(M)(H) | | | | |
πΌ PE-17 Alternate Work Site (M)(H) | | | | |
πΌ Planning | 6 | | | |
πΌ PL-1 Policy and Procedures (L)(M)(H) | | | | |
πΌ PL-2 System Security and Privacy Plans (L)(M)(H) | | | | |
πΌ PL-4 Rules of Behavior (L)(M)(H) | 1 | | | |
πΌ PL-4(1) Social Media and External Site/Application Usage Restrictions (L)(M)(H) | | | | |
πΌ PL-8 Security and Privacy Architectures (L)(M)(H) | | | | |
πΌ PL-10 Baseline Selection (L)(M)(H) | | | | |
πΌ PL-11 Baseline Tailoring (L)(M)(H) | | | | |
πΌ Risk Assessment | 6 | | | |
πΌ RA-1 Policy and Procedures (L)(M)(H) | | | | |
πΌ RA-2 Security Categorization (L)(M)(H) | | | | |
πΌ RA-3 Risk Assessment (L)(M)(H) | 1 | | 7 | |
πΌ RA-3(1) Supply Chain Risk Assessment (L)(M)(H) | | | | |
πΌ RA-5 Vulnerability Monitoring and Scanning (L)(M)(H) | 4 | | 7 | |
πΌ RA-5(2) Update Vulnerabilities to Be Scanned (L)(M)(H) | | | | |
πΌ RA-5(3) Breadth and Depth of Coverage (M)(H) | | | | |
πΌ RA-5(5) Privileged Access (M)(H) | | | | |
πΌ RA-5(11) Public Disclosure Program (L)(M)(H) | | | | |
πΌ RA-7 Risk Response (L)(M)(H) | | | | |
πΌ RA-9 Criticality Analysis (M)(H) | | | | |
πΌ Supply Chain Risk Management | 9 | | | |
πΌ SR-1 Policy and Procedures (L)(M)(H) | | | | |
πΌ SR-2 Supply Chain Risk Management Plan (L)(M)(H) | 1 | | | |
πΌ SR-2(1) Establish SCRM Team (L)(M)(H) | | | | |
πΌ SR-3 Supply Chain Controls and Processes (L)(M)(H) | | | | |
πΌ SR-5 Acquisition Strategies, Tools, and Methods (L)(M)(H) | | | | |
πΌ SR-6 Supplier Assessments and Reviews (M)(H) | | | | |
πΌ SR-8 Notification Agreements (L)(M)(H) | | | | |
πΌ SR-10 Inspection of Systems or Components (L)(M)(H) | | | | |
πΌ SR-11 Component Authenticity (L)(M)(H) | 2 | | | |
πΌ SR-11(1) Anti-counterfeit Training (L)(M)(H) | | | | |
πΌ SR-11(2) Configuration Control for Component Service and Repair (L)(M)(H) | | | | |
πΌ SR-12 Component Disposal (L)(M)(H) | | | | |
πΌ System and Communications Protection | 19 | | | |
πΌ SC-1 Policy and Procedures (L)(M)(H) | | | | |
πΌ SC-2 Separation of System and User Functionality (M)(H) | | | | |
πΌ SC-4 Information in Shared System Resources (M)(H) | | | | |
πΌ SC-5 Denial-of-service Protection (L)(M)(H) | | | | |
πΌ SC-7 Boundary Protection (L)(M)(H) | 7 | | 23 | |
πΌ SC-7(3) Access Points (M)(H) | | | 2 | |
πΌ SC-7(4) External Telecommunications Services (M)(H) | | | 17 | |
πΌ SC-7(5) Deny by Default β Allow by Exception (M)(H) | | | 18 | |
πΌ SC-7(7) Split Tunneling for Remote Devices (M)(H) | | | | |
πΌ SC-7(8) Route Traffic to Authenticated Proxy Servers (M)(H) | | | | |
πΌ SC-7(12) Host-based Protection (M)(H) | | | | |
πΌ SC-7(18) Fail Secure (M)(H) | | | | |
πΌ SC-8 Transmission Confidentiality and Integrity (L)(M)(H) | 1 | | 8 | |
πΌ SC-8(1) Cryptographic Protection (L)(M)(H) | | | 10 | |
πΌ SC-10 Network Disconnect (M)(H) | | | | |
πΌ SC-12 Cryptographic Key Establishment and Management (L)(M)(H) | | | 11 | |
πΌ SC-13 Cryptographic Protection (L)(M)(H) | | | 16 | |
πΌ SC-15 Collaborative Computing Devices and Applications (L)(M)(H) | | | | |
πΌ SC-17 Public Key Infrastructure Certificates (M)(H) | | | 1 | |
πΌ SC-18 Mobile Code (M)(H) | | | | |
πΌ SC-20 Secure Name/Address Resolution Service (Authoritative Source) (L)(M)(H) | | | | |
πΌ SC-21 Secure Name/Address Resolution Service (Recursive or Caching Resolver) (L)(M)(H) | | | | |
πΌ SC-22 Architecture and Provisioning for Name/Address Resolution Service (L)(M)(H) | | | | |
πΌ SC-23 Session Authenticity (M)(H) | | | 7 | |
πΌ SC-28 Protection of Information at Rest (L)(M)(H) | 1 | | 15 | |
πΌ SC-28(1) Cryptographic Protection (L)(M)(H) | | | 12 | |
πΌ SC-39 Process Isolation (L)(M)(H) | | | | |
πΌ SC-45 System Time Synchronization (M)(H) | 1 | | | |
πΌ SC-45(1) Synchronization with Authoritative Time Source (M)(H) | | | | |
πΌ System and Information Integrity | 12 | | | |
πΌ SI-1 Policy and Procedures (L)(M)(H) | | | | |
πΌ SI-2 Flaw Remediation (L)(M)(H) | 2 | | 9 | |
πΌ SI-2(2) Automated Flaw Remediation Status (M)(H) | | | 1 | |
πΌ SI-2(3) Time to Remediate Flaws and Benchmarks for Corrective Actions (M)(H) | | | | |
πΌ SI-3 Malicious Code Protection (L)(M)(H) | | | 7 | |
πΌ SI-4 System Monitoring (L)(M)(H) | 7 | | 7 | |
πΌ SI-4(1) System-wide Intrusion Detection System (M)(H) | | | 1 | |
πΌ SI-4(2) Automated Tools and Mechanisms for Real-time Analysis (M)(H) | | | | |
πΌ SI-4(4) Inbound and Outbound Communications Traffic (M)(H) | | | 8 | |
πΌ SI-4(5) System-generated Alerts (M)(H) | | | | |
πΌ SI-4(16) Correlate Monitoring Information (M)(H) | | | | |
πΌ SI-4(18) Analyze Traffic and Covert Exfiltration (M)(H) | | | | |
πΌ SI-4(23) Host-based Devices (M)(H) | | | | |
πΌ SI-5 Security Alerts, Advisories, and Directives (L)(M)(H) | | | | |
πΌ SI-6 Security and Privacy Function Verification (M)(H) | | | | |
πΌ SI-7 Software, Firmware, and Information Integrity (M)(H) | 2 | | | |
πΌ SI-7(1) Integrity Checks (M)(H) | | | 1 | |
πΌ SI-7(7) Integration of Detection and Response (M)(H) | | | 1 | |
πΌ SI-8 Spam Protection (M)(H) | 1 | | | |
πΌ SI-8(2) Automatic Updates (M)(H) | | | | |
πΌ SI-10 Information Input Validation (M)(H) | | | | |
πΌ SI-11 Error Handling (M)(H) | | | | |
πΌ SI-12 Information Management and Retention (L)(M)(H) | | | | |
πΌ SI-16 Memory Protection (M)(H) | | | | |
πΌ System and Services Acquisition | 11 | | | |
πΌ SA-1 Policy and Procedures (L)(M)(H) | | | | |
πΌ SA-2 Allocation of Resources (L)(M)(H) | | | | |
πΌ SA-3 System Development Life Cycle (L)(M)(H) | | | | |
πΌ SA-4 Acquisition Process (L)(M)(H) | 4 | | | |
πΌ SA-4(1) Functional Properties of Controls (M)(H) | | | | |
πΌ SA-4(2) Design and Implementation Information for Controls (M)(H) | | | | |
πΌ SA-4(9) Functions, Ports, Protocols, and Services in Use (M)(H) | | | | |
πΌ SA-4(10) Use of Approved PIV Products (L)(M)(H) | | | | |
πΌ SA-5 System Documentation (L)(M)(H) | | | | |
πΌ SA-8 Security and Privacy Engineering Principles (L)(M)(H) | | | | |
πΌ SA-9 External System Services (L)(M)(H) | 3 | | | |
πΌ SA-9(1) Risk Assessments and Organizational Approvals (M)(H) | | | | |
πΌ SA-9(2) Identification of Functions, Ports, Protocols, and Services (M)(H) | | | | |
πΌ SA-9(5) Processing, Storage, and Service Location (M)(H) | | | 1 | |
πΌ SA-10 Developer Configuration Management (M)(H) | | | | |
πΌ SA-11 Developer Testing and Evaluation (M)(H) | 2 | | | |
πΌ SA-11(1) Static Code Analysis (M)(H) | | | | |
πΌ SA-11(2) Threat Modeling and Vulnerability Analyses (M)(H) | | | | |
πΌ SA-15 Development Process, Standards, and Tools (M)(H) | 1 | | | |
πΌ SA-15(3) Criticality Analysis (M)(H) | | | | |
πΌ SA-22 Unsupported System Components (L)(M)(H) | | | | |