Framework
Full published catalogs. The control lookup lists active canonical requirements only; this view shows every framework as published, including withdrawn controls.
NIST SP 800-171 Rev 3 · version 1.1.0 · OSCAL v1.2.2 · 17 families · 97 active · 33 withdrawn
Access Control 03.01
| ID | Title | Status |
|---|---|---|
| 03.01.01 | Account Management | active |
| 03.01.02 | Access Enforcement | active |
| 03.01.03 | Information Flow Enforcement | active |
| 03.01.04 | Separation of Duties | active |
| 03.01.05 | Least Privilege | active |
| 03.01.06 | Least Privilege – Privileged Accounts | active |
| 03.01.07 | Least Privilege – Privileged Functions | active |
| 03.01.08 | Unsuccessful Logon Attempts | active |
| 03.01.09 | System Use Notification | active |
| 03.01.10 | Device Lock | active |
| 03.01.11 | Session Termination | active |
| 03.01.12 | Remote Access | active |
| 03.01.13 | Withdrawn | withdrawn → 03.13.08 |
| 03.01.14 | Withdrawn | withdrawn → 03.01.12 |
| 03.01.15 | Withdrawn | withdrawn → 03.01.12 |
| 03.01.16 | Wireless Access | active |
| 03.01.17 | Withdrawn | withdrawn → 03.01.16 |
| 03.01.18 | Access Control for Mobile Devices | active |
| 03.01.19 | Withdrawn | withdrawn → 03.01.18 |
| 03.01.20 | Use of External Systems | active |
| 03.01.21 | Withdrawn | withdrawn → 03.01.20 |
| 03.01.22 | Publicly Accessible Content | active |
Awareness and Training 03.02
| ID | Title | Status |
|---|---|---|
| 03.02.01 | Literacy Training and Awareness | active |
| 03.02.02 | Role-Based Training | active |
| 03.02.03 | Withdrawn | withdrawn → 03.02.01 |
Audit and Accountability 03.03
| ID | Title | Status |
|---|---|---|
| 03.03.01 | Event Logging | active |
| 03.03.02 | Audit Record Content | active |
| 03.03.03 | Audit Record Generation | active |
| 03.03.04 | Response to Audit Logging Process Failures | active |
| 03.03.05 | Audit Record Review, Analysis, and Reporting | active |
| 03.03.06 | Audit Record Reduction and Report Generation | active |
| 03.03.07 | Time Stamps | active |
| 03.03.08 | Protection of Audit Information | active |
| 03.03.09 | Withdrawn | withdrawn → 03.03.08 |
Configuration Management 03.04
| ID | Title | Status |
|---|---|---|
| 03.04.01 | Baseline Configuration | active |
| 03.04.02 | Configuration Settings | active |
| 03.04.03 | Configuration Change Control | active |
| 03.04.04 | Impact Analyses | active |
| 03.04.05 | Access Restrictions for Change | active |
| 03.04.06 | Least Functionality | active |
| 03.04.07 | Withdrawn | withdrawn → 03.04.08 |
| 03.04.08 | Authorized Software – Allow by Exception | active |
| 03.04.09 | Withdrawn | withdrawn → 03.12.03 |
| 03.04.10 | System Component Inventory | active |
| 03.04.11 | Information Location | active |
| 03.04.12 | System and Component Configuration for High-Risk Areas | active |
Identification and Authentication 03.05
| ID | Title | Status |
|---|---|---|
| 03.05.01 | User Identification and Authentication | active |
| 03.05.02 | Device Identification and Authentication | active |
| 03.05.03 | Multi-Factor Authentication | active |
| 03.05.04 | Replay-Resistant Authentication | active |
| 03.05.05 | Identifier Management | active |
| 03.05.06 | Withdrawn | withdrawn |
| 03.05.07 | Password Management | active |
| 03.05.08 | Withdrawn | withdrawn |
| 03.05.09 | Withdrawn | withdrawn |
| 03.05.10 | Withdrawn | withdrawn → 03.05.07 |
| 03.05.11 | Authentication Feedback | active |
| 03.05.12 | Authenticator Management | active |
Incident Response 03.06
| ID | Title | Status |
|---|---|---|
| 03.06.01 | Incident Handling | active |
| 03.06.02 | Incident Monitoring, Reporting, and Response Assistance | active |
| 03.06.03 | Incident Response Testing | active |
| 03.06.04 | Incident Response Training | active |
| 03.06.05 | Incident Response Plan | active |
Maintenance 03.07
| ID | Title | Status |
|---|---|---|
| 03.07.01 | Withdrawn | withdrawn |
| 03.07.02 | Withdrawn | withdrawn → 03.07.06 |
| 03.07.03 | Withdrawn | withdrawn → 03.08.03 |
| 03.07.04 | Maintenance Tools | active |
| 03.07.05 | Nonlocal Maintenance | active |
| 03.07.06 | Maintenance Personnel | active |
Media Protection 03.08
| ID | Title | Status |
|---|---|---|
| 03.08.01 | Media Storage | active |
| 03.08.02 | Media Access | active |
| 03.08.03 | Media Sanitization | active |
| 03.08.04 | Media Marking | active |
| 03.08.05 | Media Transport | active |
| 03.08.06 | Withdrawn | withdrawn → 03.13.08 |
| 03.08.07 | Media Use | active |
| 03.08.08 | Withdrawn | withdrawn → 03.08.07 |
| 03.08.09 | System Backup – Cryptographic Protection | active |
Personnel Security 03.09
| ID | Title | Status |
|---|---|---|
| 03.09.01 | Personnel Screening | active |
| 03.09.02 | Personnel Termination and Transfer | active |
Physical Protection 03.10
| ID | Title | Status |
|---|---|---|
| 03.10.01 | Physical Access Authorizations | active |
| 03.10.02 | Monitoring Physical Access | active |
| 03.10.03 | Withdrawn | withdrawn → 03.10.07 |
| 03.10.04 | Withdrawn | withdrawn → 03.10.07 |
| 03.10.05 | Withdrawn | withdrawn → 03.10.07 |
| 03.10.06 | Alternate Work Site | active |
| 03.10.07 | Physical Access Control | active |
| 03.10.08 | Access Control for Transmission | active |
Risk Assessment 03.11
| ID | Title | Status |
|---|---|---|
| 03.11.01 | Risk Assessment | active |
| 03.11.02 | Vulnerability Monitoring and Scanning | active |
| 03.11.03 | Withdrawn | withdrawn → 03.11.02 |
| 03.11.04 | Risk Response | active |
Security Assessment and Monitoring 03.12
| ID | Title | Status |
|---|---|---|
| 03.12.01 | Security Assessment | active |
| 03.12.02 | Plan of Action and Milestones | active |
| 03.12.03 | Continuous Monitoring | active |
| 03.12.04 | Withdrawn | withdrawn → 03.15.02 |
| 03.12.05 | Information Exchange | active |
System and Communications Protection 03.13
| ID | Title | Status |
|---|---|---|
| 03.13.01 | Boundary Protection | active |
| 03.13.02 | Withdrawn | withdrawn |
| 03.13.03 | Withdrawn | withdrawn → 03.01.07 |
| 03.13.04 | Information in Shared System Resources | active |
| 03.13.05 | Withdrawn | withdrawn → 03.13.01 |
| 03.13.06 | Network Communications – Deny by Default – Allow by Exception | active |
| 03.13.07 | Withdrawn | withdrawn → 03.04.06 |
| 03.13.08 | Transmission and Storage Confidentiality | active |
| 03.13.09 | Network Disconnect | active |
| 03.13.10 | Cryptographic Key Establishment and Management | active |
| 03.13.11 | Cryptographic Protection | active |
| 03.13.12 | Collaborative Computing Devices and Applications | active |
| 03.13.13 | Mobile Code | active |
| 03.13.14 | Withdrawn | withdrawn |
| 03.13.15 | Session Authenticity | active |
| 03.13.16 | Withdrawn | withdrawn → 03.13.08 |
System and Information Integrity 03.14
| ID | Title | Status |
|---|---|---|
| 03.14.01 | Flaw Remediation | active |
| 03.14.02 | Malicious Code Protection | active |
| 03.14.03 | Security Alerts, Advisories, and Directives | active |
| 03.14.04 | Withdrawn | withdrawn → 03.14.02 |
| 03.14.05 | Withdrawn | withdrawn → 03.14.02 |
| 03.14.06 | System Monitoring | active |
| 03.14.07 | Withdrawn | withdrawn → 03.14.06 |
| 03.14.08 | Information Management and Retention | active |
Planning 03.15
| ID | Title | Status |
|---|---|---|
| 03.15.01 | Policy and Procedures | active |
| 03.15.02 | System Security Plan | active |
| 03.15.03 | Rules of Behavior | active |
System and Services Acquisition 03.16
| ID | Title | Status |
|---|---|---|
| 03.16.01 | Security Engineering Principles | active |
| 03.16.02 | Unsupported System Components | active |
| 03.16.03 | External System Services | active |
Supply Chain Risk Management 03.17
| ID | Title | Status |
|---|---|---|
| 03.17.01 | Supply Chain Risk Management Plan | active |
| 03.17.02 | Acquisition Strategies, Tools, and Methods | active |
| 03.17.03 | Supply Chain Requirements and Processes | active |
NIST SP 800-53 Rev 5 · version 5.2.0 · OSCAL 1.2.2 · 20 families · 1014 active · 182 withdrawn
Access Control ac
| ID | Title | Status |
|---|---|---|
| ac-1 | Policy and Procedures | active |
| ac-2 | Account Management | active |
| ac-2.1 | Automated System Account Management | enhancement |
| ac-2.2 | Automated Temporary and Emergency Account Management | enhancement |
| ac-2.3 | Disable Accounts | enhancement |
| ac-2.4 | Automated Audit Actions | enhancement |
| ac-2.5 | Inactivity Logout | enhancement |
| ac-2.6 | Dynamic Privilege Management | enhancement |
| ac-2.7 | Privileged User Accounts | enhancement |
| ac-2.8 | Dynamic Account Management | enhancement |
| ac-2.9 | Restrictions on Use of Shared and Group Accounts | enhancement |
| ac-2.10 | Withdrawn | withdrawn → ac-2_smt.k |
| ac-2.11 | Usage Conditions | enhancement |
| ac-2.12 | Account Monitoring for Atypical Usage | enhancement |
| ac-2.13 | Disable Accounts for High-risk Individuals | enhancement |
| ac-3 | Access Enforcement | active |
| ac-3.1 | Withdrawn | withdrawn → ac-6 |
| ac-3.2 | Dual Authorization | enhancement |
| ac-3.3 | Mandatory Access Control | enhancement |
| ac-3.4 | Discretionary Access Control | enhancement |
| ac-3.5 | Security-relevant Information | enhancement |
| ac-3.6 | Withdrawn | withdrawn → sc-28 |
| ac-3.7 | Role-based Access Control | enhancement |
| ac-3.8 | Revocation of Access Authorizations | enhancement |
| ac-3.9 | Controlled Release | enhancement |
| ac-3.10 | Audited Override of Access Control Mechanisms | enhancement |
| ac-3.11 | Restrict Access to Specific Information Types | enhancement |
| ac-3.12 | Assert and Enforce Application Access | enhancement |
| ac-3.13 | Attribute-based Access Control | enhancement |
| ac-3.14 | Individual Access | enhancement |
| ac-3.15 | Discretionary and Mandatory Access Control | enhancement |
| ac-4 | Information Flow Enforcement | active |
| ac-4.1 | Object Security and Privacy Attributes | enhancement |
| ac-4.2 | Processing Domains | enhancement |
| ac-4.3 | Dynamic Information Flow Control | enhancement |
| ac-4.4 | Flow Control of Encrypted Information | enhancement |
| ac-4.5 | Embedded Data Types | enhancement |
| ac-4.6 | Metadata | enhancement |
| ac-4.7 | One-way Flow Mechanisms | enhancement |
| ac-4.8 | Security and Privacy Policy Filters | enhancement |
| ac-4.9 | Human Reviews | enhancement |
| ac-4.10 | Enable and Disable Security or Privacy Policy Filters | enhancement |
| ac-4.11 | Configuration of Security or Privacy Policy Filters | enhancement |
| ac-4.12 | Data Type Identifiers | enhancement |
| ac-4.13 | Decomposition into Policy-relevant Subcomponents | enhancement |
| ac-4.14 | Security or Privacy Policy Filter Constraints | enhancement |
| ac-4.15 | Detection of Unsanctioned Information | enhancement |
| ac-4.16 | Withdrawn | withdrawn → ac-4 |
| ac-4.17 | Domain Authentication | enhancement |
| ac-4.18 | Withdrawn | withdrawn → ac-16 |
| ac-4.19 | Validation of Metadata | enhancement |
| ac-4.20 | Approved Solutions | enhancement |
| ac-4.21 | Physical or Logical Separation of Information Flows | enhancement |
| ac-4.22 | Access Only | enhancement |
| ac-4.23 | Modify Non-releasable Information | enhancement |
| ac-4.24 | Internal Normalized Format | enhancement |
| ac-4.25 | Data Sanitization | enhancement |
| ac-4.26 | Audit Filtering Actions | enhancement |
| ac-4.27 | Redundant/Independent Filtering Mechanisms | enhancement |
| ac-4.28 | Linear Filter Pipelines | enhancement |
| ac-4.29 | Filter Orchestration Engines | enhancement |
| ac-4.30 | Filter Mechanisms Using Multiple Processes | enhancement |
| ac-4.31 | Failed Content Transfer Prevention | enhancement |
| ac-4.32 | Process Requirements for Information Transfer | enhancement |
| ac-5 | Separation of Duties | active |
| ac-6 | Least Privilege | active |
| ac-6.1 | Authorize Access to Security Functions | enhancement |
| ac-6.2 | Non-privileged Access for Nonsecurity Functions | enhancement |
| ac-6.3 | Network Access to Privileged Commands | enhancement |
| ac-6.4 | Separate Processing Domains | enhancement |
| ac-6.5 | Privileged Accounts | enhancement |
| ac-6.6 | Privileged Access by Non-organizational Users | enhancement |
| ac-6.7 | Review of User Privileges | enhancement |
| ac-6.8 | Privilege Levels for Code Execution | enhancement |
| ac-6.9 | Log Use of Privileged Functions | enhancement |
| ac-6.10 | Prohibit Non-privileged Users from Executing Privileged Functions | enhancement |
| ac-7 | Unsuccessful Logon Attempts | active |
| ac-7.1 | Withdrawn | withdrawn → ac-7 |
| ac-7.2 | Purge or Wipe Mobile Device | enhancement |
| ac-7.3 | Biometric Attempt Limiting | enhancement |
| ac-7.4 | Use of Alternate Authentication Factor | enhancement |
| ac-8 | System Use Notification | active |
| ac-9 | Previous Logon Notification | active |
| ac-9.1 | Unsuccessful Logons | enhancement |
| ac-9.2 | Successful and Unsuccessful Logons | enhancement |
| ac-9.3 | Notification of Account Changes | enhancement |
| ac-9.4 | Additional Logon Information | enhancement |
| ac-10 | Concurrent Session Control | active |
| ac-11 | Device Lock | active |
| ac-11.1 | Pattern-hiding Displays | enhancement |
| ac-12 | Session Termination | active |
| ac-12.1 | User-initiated Logouts | enhancement |
| ac-12.2 | Termination Message | enhancement |
| ac-12.3 | Timeout Warning Message | enhancement |
| ac-13 | Withdrawn | withdrawn → au-6 |
| ac-14 | Permitted Actions Without Identification or Authentication | active |
| ac-14.1 | Withdrawn | withdrawn → ac-14 |
| ac-15 | Withdrawn | withdrawn → mp-3 |
| ac-16 | Security and Privacy Attributes | active |
| ac-16.1 | Dynamic Attribute Association | enhancement |
| ac-16.2 | Attribute Value Changes by Authorized Individuals | enhancement |
| ac-16.3 | Maintenance of Attribute Associations by System | enhancement |
| ac-16.4 | Association of Attributes by Authorized Individuals | enhancement |
| ac-16.5 | Attribute Displays on Objects to Be Output | enhancement |
| ac-16.6 | Maintenance of Attribute Association | enhancement |
| ac-16.7 | Consistent Attribute Interpretation | enhancement |
| ac-16.8 | Association Techniques and Technologies | enhancement |
| ac-16.9 | Attribute Reassignment — Regrading Mechanisms | enhancement |
| ac-16.10 | Attribute Configuration by Authorized Individuals | enhancement |
| ac-17 | Remote Access | active |
| ac-17.1 | Monitoring and Control | enhancement |
| ac-17.2 | Protection of Confidentiality and Integrity Using Encryption | enhancement |
| ac-17.3 | Managed Access Control Points | enhancement |
| ac-17.4 | Privileged Commands and Access | enhancement |
| ac-17.5 | Withdrawn | withdrawn → si-4 |
| ac-17.6 | Protection of Mechanism Information | enhancement |
| ac-17.7 | Withdrawn | withdrawn → ac-3.10 |
| ac-17.8 | Withdrawn | withdrawn → cm-7 |
| ac-17.9 | Disconnect or Disable Access | enhancement |
| ac-17.10 | Authenticate Remote Commands | enhancement |
| ac-18 | Wireless Access | active |
| ac-18.1 | Authentication and Encryption | enhancement |
| ac-18.2 | Withdrawn | withdrawn → si-4 |
| ac-18.3 | Disable Wireless Networking | enhancement |
| ac-18.4 | Restrict Configurations by Users | enhancement |
| ac-18.5 | Antennas and Transmission Power Levels | enhancement |
| ac-19 | Access Control for Mobile Devices | active |
| ac-19.1 | Withdrawn | withdrawn → mp-7 |
| ac-19.2 | Withdrawn | withdrawn → mp-7 |
| ac-19.3 | Withdrawn | withdrawn → mp-7 |
| ac-19.4 | Restrictions for Classified Information | enhancement |
| ac-19.5 | Full Device or Container-based Encryption | enhancement |
| ac-20 | Use of External Systems | active |
| ac-20.1 | Limits on Authorized Use | enhancement |
| ac-20.2 | Portable Storage Devices — Restricted Use | enhancement |
| ac-20.3 | Non-organizationally Owned Systems — Restricted Use | enhancement |
| ac-20.4 | Network Accessible Storage Devices — Prohibited Use | enhancement |
| ac-20.5 | Portable Storage Devices — Prohibited Use | enhancement |
| ac-21 | Information Sharing | active |
| ac-21.1 | Automated Decision Support | enhancement |
| ac-21.2 | Information Search and Retrieval | enhancement |
| ac-22 | Publicly Accessible Content | active |
| ac-23 | Data Mining Protection | active |
| ac-24 | Access Control Decisions | active |
| ac-24.1 | Transmit Access Authorization Information | enhancement |
| ac-24.2 | No User or Process Identity | enhancement |
| ac-25 | Reference Monitor | active |
Awareness and Training at
| ID | Title | Status |
|---|---|---|
| at-1 | Policy and Procedures | active |
| at-2 | Literacy Training and Awareness | active |
| at-2.1 | Practical Exercises | enhancement |
| at-2.2 | Insider Threat | enhancement |
| at-2.3 | Social Engineering and Mining | enhancement |
| at-2.4 | Suspicious Communications and Anomalous System Behavior | enhancement |
| at-2.5 | Advanced Persistent Threat | enhancement |
| at-2.6 | Cyber Threat Environment | enhancement |
| at-3 | Role-based Training | active |
| at-3.1 | Environmental Controls | enhancement |
| at-3.2 | Physical Security Controls | enhancement |
| at-3.3 | Practical Exercises | enhancement |
| at-3.4 | Withdrawn | withdrawn → at-2.4 |
| at-3.5 | Processing Personally Identifiable Information | enhancement |
| at-4 | Training Records | active |
| at-5 | Withdrawn | withdrawn → pm-15 |
| at-6 | Training Feedback | active |
Audit and Accountability au
| ID | Title | Status |
|---|---|---|
| au-1 | Policy and Procedures | active |
| au-2 | Event Logging | active |
| au-2.1 | Withdrawn | withdrawn → au-12 |
| au-2.2 | Withdrawn | withdrawn → au-12 |
| au-2.3 | Withdrawn | withdrawn → au-2 |
| au-2.4 | Withdrawn | withdrawn → ac-6.9 |
| au-3 | Content of Audit Records | active |
| au-3.1 | Additional Audit Information | enhancement |
| au-3.2 | Withdrawn | withdrawn → pl-9 |
| au-3.3 | Limit Personally Identifiable Information Elements | enhancement |
| au-4 | Audit Log Storage Capacity | active |
| au-4.1 | Transfer to Alternate Storage | enhancement |
| au-5 | Response to Audit Logging Process Failures | active |
| au-5.1 | Storage Capacity Warning | enhancement |
| au-5.2 | Real-time Alerts | enhancement |
| au-5.3 | Configurable Traffic Volume Thresholds | enhancement |
| au-5.4 | Shutdown on Failure | enhancement |
| au-5.5 | Alternate Audit Logging Capability | enhancement |
| au-6 | Audit Record Review, Analysis, and Reporting | active |
| au-6.1 | Automated Process Integration | enhancement |
| au-6.2 | Withdrawn | withdrawn → si-4 |
| au-6.3 | Correlate Audit Record Repositories | enhancement |
| au-6.4 | Central Review and Analysis | enhancement |
| au-6.5 | Integrated Analysis of Audit Records | enhancement |
| au-6.6 | Correlation with Physical Monitoring | enhancement |
| au-6.7 | Permitted Actions | enhancement |
| au-6.8 | Full Text Analysis of Privileged Commands | enhancement |
| au-6.9 | Correlation with Information from Nontechnical Sources | enhancement |
| au-6.10 | Withdrawn | withdrawn → au-6 |
| au-7 | Audit Record Reduction and Report Generation | active |
| au-7.1 | Automatic Processing | enhancement |
| au-7.2 | Withdrawn | withdrawn → au-7.1 |
| au-8 | Time Stamps | active |
| au-8.1 | Withdrawn | withdrawn → sc-45.1 |
| au-8.2 | Withdrawn | withdrawn → sc-45.2 |
| au-9 | Protection of Audit Information | active |
| au-9.1 | Hardware Write-once Media | enhancement |
| au-9.2 | Store on Separate Physical Systems or Components | enhancement |
| au-9.3 | Cryptographic Protection | enhancement |
| au-9.4 | Access by Subset of Privileged Users | enhancement |
| au-9.5 | Dual Authorization | enhancement |
| au-9.6 | Read-only Access | enhancement |
| au-9.7 | Store on Component with Different Operating System | enhancement |
| au-10 | Non-repudiation | active |
| au-10.1 | Association of Identities | enhancement |
| au-10.2 | Validate Binding of Information Producer Identity | enhancement |
| au-10.3 | Chain of Custody | enhancement |
| au-10.4 | Validate Binding of Information Reviewer Identity | enhancement |
| au-10.5 | Withdrawn | withdrawn → si-7 |
| au-11 | Audit Record Retention | active |
| au-11.1 | Long-term Retrieval Capability | enhancement |
| au-12 | Audit Record Generation | active |
| au-12.1 | System-wide and Time-correlated Audit Trail | enhancement |
| au-12.2 | Standardized Formats | enhancement |
| au-12.3 | Changes by Authorized Individuals | enhancement |
| au-12.4 | Query Parameter Audits of Personally Identifiable Information | enhancement |
| au-13 | Monitoring for Information Disclosure | active |
| au-13.1 | Use of Automated Tools | enhancement |
| au-13.2 | Review of Monitored Sites | enhancement |
| au-13.3 | Unauthorized Replication of Information | enhancement |
| au-14 | Session Audit | active |
| au-14.1 | System Start-up | enhancement |
| au-14.2 | Withdrawn | withdrawn → au-14 |
| au-14.3 | Remote Viewing and Listening | enhancement |
| au-15 | Withdrawn | withdrawn → au-5.5 |
| au-16 | Cross-organizational Audit Logging | active |
| au-16.1 | Identity Preservation | enhancement |
| au-16.2 | Sharing of Audit Information | enhancement |
| au-16.3 | Disassociability | enhancement |
Assessment, Authorization, and Monitoring ca
| ID | Title | Status |
|---|---|---|
| ca-1 | Policy and Procedures | active |
| ca-2 | Control Assessments | active |
| ca-2.1 | Independent Assessors | enhancement |
| ca-2.2 | Specialized Assessments | enhancement |
| ca-2.3 | Leveraging Results from External Organizations | enhancement |
| ca-3 | Information Exchange | active |
| ca-3.1 | Withdrawn | withdrawn → sc-7.25 |
| ca-3.2 | Withdrawn | withdrawn → sc-7.26 |
| ca-3.3 | Withdrawn | withdrawn → sc-7.27 |
| ca-3.4 | Withdrawn | withdrawn → sc-7.28 |
| ca-3.5 | Withdrawn | withdrawn → sc-7.5 |
| ca-3.6 | Transfer Authorizations | enhancement |
| ca-3.7 | Transitive Information Exchanges | enhancement |
| ca-4 | Withdrawn | withdrawn → ca-2 |
| ca-5 | Plan of Action and Milestones | active |
| ca-5.1 | Automation Support for Accuracy and Currency | enhancement |
| ca-6 | Authorization | active |
| ca-6.1 | Joint Authorization — Intra-organization | enhancement |
| ca-6.2 | Joint Authorization — Inter-organization | enhancement |
| ca-7 | Continuous Monitoring | active |
| ca-7.1 | Independent Assessment | enhancement |
| ca-7.2 | Withdrawn | withdrawn → ca-2 |
| ca-7.3 | Trend Analyses | enhancement |
| ca-7.4 | Risk Monitoring | enhancement |
| ca-7.5 | Consistency Analysis | enhancement |
| ca-7.6 | Automation Support for Monitoring | enhancement |
| ca-8 | Penetration Testing | active |
| ca-8.1 | Independent Penetration Testing Agent or Team | enhancement |
| ca-8.2 | Red Team Exercises | enhancement |
| ca-8.3 | Facility Penetration Testing | enhancement |
| ca-9 | Internal System Connections | active |
| ca-9.1 | Compliance Checks | enhancement |
Configuration Management cm
| ID | Title | Status |
|---|---|---|
| cm-1 | Policy and Procedures | active |
| cm-2 | Baseline Configuration | active |
| cm-2.1 | Withdrawn | withdrawn → cm-2 |
| cm-2.2 | Automation Support for Accuracy and Currency | enhancement |
| cm-2.3 | Retention of Previous Configurations | enhancement |
| cm-2.4 | Withdrawn | withdrawn → cm-7.4 |
| cm-2.5 | Withdrawn | withdrawn → cm-7.5 |
| cm-2.6 | Development and Test Environments | enhancement |
| cm-2.7 | Configure Systems and Components for High-risk Areas | enhancement |
| cm-3 | Configuration Change Control | active |
| cm-3.1 | Automated Documentation, Notification, and Prohibition of Changes | enhancement |
| cm-3.2 | Testing, Validation, and Documentation of Changes | enhancement |
| cm-3.3 | Automated Change Implementation | enhancement |
| cm-3.4 | Security and Privacy Representatives | enhancement |
| cm-3.5 | Automated Security Response | enhancement |
| cm-3.6 | Cryptography Management | enhancement |
| cm-3.7 | Review System Changes | enhancement |
| cm-3.8 | Prevent or Restrict Configuration Changes | enhancement |
| cm-4 | Impact Analyses | active |
| cm-4.1 | Separate Test Environments | enhancement |
| cm-4.2 | Verification of Controls | enhancement |
| cm-5 | Access Restrictions for Change | active |
| cm-5.1 | Automated Access Enforcement and Audit Records | enhancement |
| cm-5.2 | Withdrawn | withdrawn → cm-3.7 |
| cm-5.3 | Withdrawn | withdrawn → cm-14 |
| cm-5.4 | Dual Authorization | enhancement |
| cm-5.5 | Privilege Limitation for Production and Operation | enhancement |
| cm-5.6 | Limit Library Privileges | enhancement |
| cm-5.7 | Withdrawn | withdrawn → si-7 |
| cm-6 | Configuration Settings | active |
| cm-6.1 | Automated Management, Application, and Verification | enhancement |
| cm-6.2 | Respond to Unauthorized Changes | enhancement |
| cm-6.3 | Withdrawn | withdrawn → si-7 |
| cm-6.4 | Withdrawn | withdrawn → cm-4 |
| cm-7 | Least Functionality | active |
| cm-7.1 | Periodic Review | enhancement |
| cm-7.2 | Prevent Program Execution | enhancement |
| cm-7.3 | Registration Compliance | enhancement |
| cm-7.4 | Unauthorized Software — Deny-by-exception | enhancement |
| cm-7.5 | Authorized Software — Allow-by-exception | enhancement |
| cm-7.6 | Confined Environments with Limited Privileges | enhancement |
| cm-7.7 | Code Execution in Protected Environments | enhancement |
| cm-7.8 | Binary or Machine Executable Code | enhancement |
| cm-7.9 | Prohibiting The Use of Unauthorized Hardware | enhancement |
| cm-8 | System Component Inventory | active |
| cm-8.1 | Updates During Installation and Removal | enhancement |
| cm-8.2 | Automated Maintenance | enhancement |
| cm-8.3 | Automated Unauthorized Component Detection | enhancement |
| cm-8.4 | Accountability Information | enhancement |
| cm-8.5 | Withdrawn | withdrawn → cm-8 |
| cm-8.6 | Assessed Configurations and Approved Deviations | enhancement |
| cm-8.7 | Centralized Repository | enhancement |
| cm-8.8 | Automated Location Tracking | enhancement |
| cm-8.9 | Assignment of Components to Systems | enhancement |
| cm-9 | Configuration Management Plan | active |
| cm-9.1 | Assignment of Responsibility | enhancement |
| cm-10 | Software Usage Restrictions | active |
| cm-10.1 | Open-source Software | enhancement |
| cm-11 | User-installed Software | active |
| cm-11.1 | Withdrawn | withdrawn → cm-8.3 |
| cm-11.2 | Software Installation with Privileged Status | enhancement |
| cm-11.3 | Automated Enforcement and Monitoring | enhancement |
| cm-12 | Information Location | active |
| cm-12.1 | Automated Tools to Support Information Location | enhancement |
| cm-13 | Data Action Mapping | active |
| cm-14 | Signed Components | active |
Contingency Planning cp
| ID | Title | Status |
|---|---|---|
| cp-1 | Policy and Procedures | active |
| cp-2 | Contingency Plan | active |
| cp-2.1 | Coordinate with Related Plans | enhancement |
| cp-2.2 | Capacity Planning | enhancement |
| cp-2.3 | Resume Mission and Business Functions | enhancement |
| cp-2.4 | Withdrawn | withdrawn → cp-2.3 |
| cp-2.5 | Continue Mission and Business Functions | enhancement |
| cp-2.6 | Alternate Processing and Storage Sites | enhancement |
| cp-2.7 | Coordinate with External Service Providers | enhancement |
| cp-2.8 | Identify Critical Assets | enhancement |
| cp-3 | Contingency Training | active |
| cp-3.1 | Simulated Events | enhancement |
| cp-3.2 | Mechanisms Used in Training Environments | enhancement |
| cp-4 | Contingency Plan Testing | active |
| cp-4.1 | Coordinate with Related Plans | enhancement |
| cp-4.2 | Alternate Processing Site | enhancement |
| cp-4.3 | Automated Testing | enhancement |
| cp-4.4 | Full Recovery and Reconstitution | enhancement |
| cp-4.5 | Self-challenge | enhancement |
| cp-5 | Withdrawn | withdrawn → cp-2 |
| cp-6 | Alternate Storage Site | active |
| cp-6.1 | Separation from Primary Site | enhancement |
| cp-6.2 | Recovery Time and Recovery Point Objectives | enhancement |
| cp-6.3 | Accessibility | enhancement |
| cp-7 | Alternate Processing Site | active |
| cp-7.1 | Separation from Primary Site | enhancement |
| cp-7.2 | Accessibility | enhancement |
| cp-7.3 | Priority of Service | enhancement |
| cp-7.4 | Preparation for Use | enhancement |
| cp-7.5 | Withdrawn | withdrawn → cp-7 |
| cp-7.6 | Inability to Return to Primary Site | enhancement |
| cp-8 | Telecommunications Services | active |
| cp-8.1 | Priority of Service Provisions | enhancement |
| cp-8.2 | Single Points of Failure | enhancement |
| cp-8.3 | Separation of Primary and Alternate Providers | enhancement |
| cp-8.4 | Provider Contingency Plan | enhancement |
| cp-8.5 | Alternate Telecommunication Service Testing | enhancement |
| cp-9 | System Backup | active |
| cp-9.1 | Testing for Reliability and Integrity | enhancement |
| cp-9.2 | Test Restoration Using Sampling | enhancement |
| cp-9.3 | Separate Storage for Critical Information | enhancement |
| cp-9.4 | Withdrawn | withdrawn → cp-9 |
| cp-9.5 | Transfer to Alternate Storage Site | enhancement |
| cp-9.6 | Redundant Secondary System | enhancement |
| cp-9.7 | Dual Authorization for Deletion or Destruction | enhancement |
| cp-9.8 | Cryptographic Protection | enhancement |
| cp-10 | System Recovery and Reconstitution | active |
| cp-10.1 | Withdrawn | withdrawn → cp-4 |
| cp-10.2 | Transaction Recovery | enhancement |
| cp-10.3 | Withdrawn | withdrawn |
| cp-10.4 | Restore Within Time Period | enhancement |
| cp-10.5 | Withdrawn | withdrawn → si-13 |
| cp-10.6 | Component Protection | enhancement |
| cp-11 | Alternate Communications Protocols | active |
| cp-12 | Safe Mode | active |
| cp-13 | Alternative Security Mechanisms | active |
Identification and Authentication ia
| ID | Title | Status |
|---|---|---|
| ia-1 | Policy and Procedures | active |
| ia-2 | Identification and Authentication (Organizational Users) | active |
| ia-2.1 | Multi-factor Authentication to Privileged Accounts | enhancement |
| ia-2.2 | Multi-factor Authentication to Non-privileged Accounts | enhancement |
| ia-2.3 | Withdrawn | withdrawn → ia-2.1 |
| ia-2.4 | Withdrawn | withdrawn → ia-2.2 |
| ia-2.5 | Individual Authentication with Group Authentication | enhancement |
| ia-2.6 | Access to Accounts —separate Device | enhancement |
| ia-2.7 | Withdrawn | withdrawn → ia-2.6 |
| ia-2.8 | Access to Accounts — Replay Resistant | enhancement |
| ia-2.9 | Withdrawn | withdrawn → ia-2.8 |
| ia-2.10 | Single Sign-on | enhancement |
| ia-2.11 | Withdrawn | withdrawn → ia-2.6 |
| ia-2.12 | Acceptance of PIV Credentials | enhancement |
| ia-2.13 | Out-of-band Authentication | enhancement |
| ia-3 | Device Identification and Authentication | active |
| ia-3.1 | Cryptographic Bidirectional Authentication | enhancement |
| ia-3.2 | Withdrawn | withdrawn → ia-3.1 |
| ia-3.3 | Dynamic Address Allocation | enhancement |
| ia-3.4 | Device Attestation | enhancement |
| ia-4 | Identifier Management | active |
| ia-4.1 | Prohibit Account Identifiers as Public Identifiers | enhancement |
| ia-4.2 | Withdrawn | withdrawn → ia-12.1 |
| ia-4.3 | Withdrawn | withdrawn → ia-12.2 |
| ia-4.4 | Identify User Status | enhancement |
| ia-4.5 | Dynamic Management | enhancement |
| ia-4.6 | Cross-organization Management | enhancement |
| ia-4.7 | Withdrawn | withdrawn → ia-12.4 |
| ia-4.8 | Pairwise Pseudonymous Identifiers | enhancement |
| ia-4.9 | Attribute Maintenance and Protection | enhancement |
| ia-5 | Authenticator Management | active |
| ia-5.1 | Password-based Authentication | enhancement |
| ia-5.2 | Public Key-based Authentication | enhancement |
| ia-5.3 | Withdrawn | withdrawn → ia-12.4 |
| ia-5.4 | Withdrawn | withdrawn → ia-5.1 |
| ia-5.5 | Change Authenticators Prior to Delivery | enhancement |
| ia-5.6 | Protection of Authenticators | enhancement |
| ia-5.7 | No Embedded Unencrypted Static Authenticators | enhancement |
| ia-5.8 | Multiple System Accounts | enhancement |
| ia-5.9 | Federated Credential Management | enhancement |
| ia-5.10 | Dynamic Credential Binding | enhancement |
| ia-5.11 | Withdrawn | withdrawn → ia-2.2 |
| ia-5.12 | Biometric Authentication Performance | enhancement |
| ia-5.13 | Expiration of Cached Authenticators | enhancement |
| ia-5.14 | Managing Content of PKI Trust Stores | enhancement |
| ia-5.15 | GSA-approved Products and Services | enhancement |
| ia-5.16 | In-person or Trusted External Party Authenticator Issuance | enhancement |
| ia-5.17 | Presentation Attack Detection for Biometric Authenticators | enhancement |
| ia-5.18 | Password Managers | enhancement |
| ia-6 | Authentication Feedback | active |
| ia-7 | Cryptographic Module Authentication | active |
| ia-8 | Identification and Authentication (Non-organizational Users) | active |
| ia-8.1 | Acceptance of PIV Credentials from Other Agencies | enhancement |
| ia-8.2 | Acceptance of External Authenticators | enhancement |
| ia-8.3 | Withdrawn | withdrawn → ia-8.2 |
| ia-8.4 | Use of Defined Profiles | enhancement |
| ia-8.5 | Acceptance of PIV-I Credentials | enhancement |
| ia-8.6 | Disassociability | enhancement |
| ia-9 | Service Identification and Authentication | active |
| ia-9.1 | Withdrawn | withdrawn → ia-9 |
| ia-9.2 | Withdrawn | withdrawn → ia-9 |
| ia-10 | Adaptive Authentication | active |
| ia-11 | Re-authentication | active |
| ia-12 | Identity Proofing | active |
| ia-12.1 | Supervisor Authorization | enhancement |
| ia-12.2 | Identity Evidence | enhancement |
| ia-12.3 | Identity Evidence Validation and Verification | enhancement |
| ia-12.4 | In-person Validation and Verification | enhancement |
| ia-12.5 | Address Confirmation | enhancement |
| ia-12.6 | Accept Externally-proofed Identities | enhancement |
| ia-13 | Identity Providers and Authorization Servers | active |
| ia-13.1 | Protection of Cryptographic Keys | enhancement |
| ia-13.2 | Verification of Identity Assertions and Access Tokens | enhancement |
| ia-13.3 | Token Management | enhancement |
Incident Response ir
| ID | Title | Status |
|---|---|---|
| ir-1 | Policy and Procedures | active |
| ir-2 | Incident Response Training | active |
| ir-2.1 | Simulated Events | enhancement |
| ir-2.2 | Automated Training Environments | enhancement |
| ir-2.3 | Breach | enhancement |
| ir-3 | Incident Response Testing | active |
| ir-3.1 | Automated Testing | enhancement |
| ir-3.2 | Coordination with Related Plans | enhancement |
| ir-3.3 | Continuous Improvement | enhancement |
| ir-4 | Incident Handling | active |
| ir-4.1 | Automated Incident Handling Processes | enhancement |
| ir-4.2 | Dynamic Reconfiguration | enhancement |
| ir-4.3 | Continuity of Operations | enhancement |
| ir-4.4 | Information Correlation | enhancement |
| ir-4.5 | Automatic Disabling of System | enhancement |
| ir-4.6 | Insider Threats | enhancement |
| ir-4.7 | Insider Threats — Intra-organization Coordination | enhancement |
| ir-4.8 | Correlation with External Organizations | enhancement |
| ir-4.9 | Dynamic Response Capability | enhancement |
| ir-4.10 | Supply Chain Coordination | enhancement |
| ir-4.11 | Integrated Incident Response Team | enhancement |
| ir-4.12 | Malicious Code and Forensic Analysis | enhancement |
| ir-4.13 | Behavior Analysis | enhancement |
| ir-4.14 | Security Operations Center | enhancement |
| ir-4.15 | Public Relations and Reputation Repair | enhancement |
| ir-5 | Incident Monitoring | active |
| ir-5.1 | Automated Tracking, Data Collection, and Analysis | enhancement |
| ir-6 | Incident Reporting | active |
| ir-6.1 | Automated Reporting | enhancement |
| ir-6.2 | Vulnerabilities Related to Incidents | enhancement |
| ir-6.3 | Supply Chain Coordination | enhancement |
| ir-7 | Incident Response Assistance | active |
| ir-7.1 | Automation Support for Availability of Information and Support | enhancement |
| ir-7.2 | Coordination with External Providers | enhancement |
| ir-8 | Incident Response Plan | active |
| ir-8.1 | Breaches | enhancement |
| ir-9 | Information Spillage Response | active |
| ir-9.1 | Withdrawn | withdrawn → ir-9 |
| ir-9.2 | Training | enhancement |
| ir-9.3 | Post-spill Operations | enhancement |
| ir-9.4 | Exposure to Unauthorized Personnel | enhancement |
| ir-10 | Withdrawn | withdrawn → ir-4.11 |
Maintenance ma
| ID | Title | Status |
|---|---|---|
| ma-1 | Policy and Procedures | active |
| ma-2 | Controlled Maintenance | active |
| ma-2.1 | Withdrawn | withdrawn → ma-2 |
| ma-2.2 | Automated Maintenance Activities | enhancement |
| ma-3 | Maintenance Tools | active |
| ma-3.1 | Inspect Tools | enhancement |
| ma-3.2 | Inspect Media | enhancement |
| ma-3.3 | Prevent Unauthorized Removal | enhancement |
| ma-3.4 | Restricted Tool Use | enhancement |
| ma-3.5 | Execution with Privilege | enhancement |
| ma-3.6 | Software Updates and Patches | enhancement |
| ma-4 | Nonlocal Maintenance | active |
| ma-4.1 | Logging and Review | enhancement |
| ma-4.2 | Withdrawn | withdrawn → ma-4 |
| ma-4.3 | Comparable Security and Sanitization | enhancement |
| ma-4.4 | Authentication and Separation of Maintenance Sessions | enhancement |
| ma-4.5 | Approvals and Notifications | enhancement |
| ma-4.6 | Cryptographic Protection | enhancement |
| ma-4.7 | Disconnect Verification | enhancement |
| ma-5 | Maintenance Personnel | active |
| ma-5.1 | Individuals Without Appropriate Access | enhancement |
| ma-5.2 | Security Clearances for Classified Systems | enhancement |
| ma-5.3 | Citizenship Requirements for Classified Systems | enhancement |
| ma-5.4 | Foreign Nationals | enhancement |
| ma-5.5 | Non-system Maintenance | enhancement |
| ma-6 | Timely Maintenance | active |
| ma-6.1 | Preventive Maintenance | enhancement |
| ma-6.2 | Predictive Maintenance | enhancement |
| ma-6.3 | Automated Support for Predictive Maintenance | enhancement |
| ma-7 | Field Maintenance | active |
Media Protection mp
| ID | Title | Status |
|---|---|---|
| mp-1 | Policy and Procedures | active |
| mp-2 | Media Access | active |
| mp-2.1 | Withdrawn | withdrawn → mp-4.2 |
| mp-2.2 | Withdrawn | withdrawn → sc-28.1 |
| mp-3 | Media Marking | active |
| mp-4 | Media Storage | active |
| mp-4.1 | Withdrawn | withdrawn → sc-28.1 |
| mp-4.2 | Automated Restricted Access | enhancement |
| mp-5 | Media Transport | active |
| mp-5.1 | Withdrawn | withdrawn → mp-5 |
| mp-5.2 | Withdrawn | withdrawn → mp-5 |
| mp-5.3 | Custodians | enhancement |
| mp-5.4 | Withdrawn | withdrawn → sc-28.1 |
| mp-6 | Media Sanitization | active |
| mp-6.1 | Review, Approve, Track, Document, and Verify | enhancement |
| mp-6.2 | Equipment Testing | enhancement |
| mp-6.3 | Nondestructive Techniques | enhancement |
| mp-6.4 | Withdrawn | withdrawn → mp-6 |
| mp-6.5 | Withdrawn | withdrawn → mp-6 |
| mp-6.6 | Withdrawn | withdrawn → mp-6 |
| mp-6.7 | Dual Authorization | enhancement |
| mp-6.8 | Remote Purging or Wiping of Information | enhancement |
| mp-7 | Media Use | active |
| mp-7.1 | Withdrawn | withdrawn → mp-7 |
| mp-7.2 | Prohibit Use of Sanitization-resistant Media | enhancement |
| mp-8 | Media Downgrading | active |
| mp-8.1 | Documentation of Process | enhancement |
| mp-8.2 | Equipment Testing | enhancement |
| mp-8.3 | Controlled Unclassified Information | enhancement |
| mp-8.4 | Classified Information | enhancement |
Physical and Environmental Protection pe
| ID | Title | Status |
|---|---|---|
| pe-1 | Policy and Procedures | active |
| pe-2 | Physical Access Authorizations | active |
| pe-2.1 | Access by Position or Role | enhancement |
| pe-2.2 | Two Forms of Identification | enhancement |
| pe-2.3 | Restrict Unescorted Access | enhancement |
| pe-3 | Physical Access Control | active |
| pe-3.1 | System Access | enhancement |
| pe-3.2 | Facility and Systems | enhancement |
| pe-3.3 | Continuous Guards | enhancement |
| pe-3.4 | Lockable Casings | enhancement |
| pe-3.5 | Tamper Protection | enhancement |
| pe-3.6 | Withdrawn | withdrawn → ca-8 |
| pe-3.7 | Physical Barriers | enhancement |
| pe-3.8 | Access Control Vestibules | enhancement |
| pe-4 | Access Control for Transmission | active |
| pe-5 | Access Control for Output Devices | active |
| pe-5.1 | Withdrawn | withdrawn → pe-5 |
| pe-5.2 | Link to Individual Identity | enhancement |
| pe-5.3 | Withdrawn | withdrawn → pe-22 |
| pe-6 | Monitoring Physical Access | active |
| pe-6.1 | Intrusion Alarms and Surveillance Equipment | enhancement |
| pe-6.2 | Automated Intrusion Recognition and Responses | enhancement |
| pe-6.3 | Video Surveillance | enhancement |
| pe-6.4 | Monitoring Physical Access to Systems | enhancement |
| pe-7 | Withdrawn | withdrawn → pe-3 |
| pe-8 | Visitor Access Records | active |
| pe-8.1 | Automated Records Maintenance and Review | enhancement |
| pe-8.2 | Withdrawn | withdrawn → pe-2 |
| pe-8.3 | Limit Personally Identifiable Information Elements | enhancement |
| pe-9 | Power Equipment and Cabling | active |
| pe-9.1 | Redundant Cabling | enhancement |
| pe-9.2 | Automatic Voltage Controls | enhancement |
| pe-10 | Emergency Shutoff | active |
| pe-10.1 | Withdrawn | withdrawn → pe-10 |
| pe-11 | Emergency Power | active |
| pe-11.1 | Alternate Power Supply — Minimal Operational Capability | enhancement |
| pe-11.2 | Alternate Power Supply — Self-contained | enhancement |
| pe-12 | Emergency Lighting | active |
| pe-12.1 | Essential Mission and Business Functions | enhancement |
| pe-13 | Fire Protection | active |
| pe-13.1 | Detection Systems — Automatic Activation and Notification | enhancement |
| pe-13.2 | Suppression Systems — Automatic Activation and Notification | enhancement |
| pe-13.3 | Withdrawn | withdrawn → pe-13.2 |
| pe-13.4 | Inspections | enhancement |
| pe-14 | Environmental Controls | active |
| pe-14.1 | Automatic Controls | enhancement |
| pe-14.2 | Monitoring with Alarms and Notifications | enhancement |
| pe-15 | Water Damage Protection | active |
| pe-15.1 | Automation Support | enhancement |
| pe-16 | Delivery and Removal | active |
| pe-17 | Alternate Work Site | active |
| pe-18 | Location of System Components | active |
| pe-18.1 | Withdrawn | withdrawn → pe-23 |
| pe-19 | Information Leakage | active |
| pe-19.1 | National Emissions Policies and Procedures | enhancement |
| pe-20 | Asset Monitoring and Tracking | active |
| pe-21 | Electromagnetic Pulse Protection | active |
| pe-22 | Component Marking | active |
| pe-23 | Facility Location | active |
Planning pl
| ID | Title | Status |
|---|---|---|
| pl-1 | Policy and Procedures | active |
| pl-2 | System Security and Privacy Plans | active |
| pl-2.1 | Withdrawn | withdrawn → pl-7 |
| pl-2.2 | Withdrawn | withdrawn → pl-8 |
| pl-2.3 | Withdrawn | withdrawn → pl-2 |
| pl-3 | Withdrawn | withdrawn → pl-2 |
| pl-4 | Rules of Behavior | active |
| pl-4.1 | Social Media and External Site/Application Usage Restrictions | enhancement |
| pl-5 | Withdrawn | withdrawn → ra-8 |
| pl-6 | Withdrawn | withdrawn → pl-2 |
| pl-7 | Concept of Operations | active |
| pl-8 | Security and Privacy Architectures | active |
| pl-8.1 | Defense in Depth | enhancement |
| pl-8.2 | Supplier Diversity | enhancement |
| pl-9 | Central Management | active |
| pl-10 | Baseline Selection | active |
| pl-11 | Baseline Tailoring | active |
Program Management pm
| ID | Title | Status |
|---|---|---|
| pm-1 | Information Security Program Plan | active |
| pm-2 | Information Security Program Leadership Role | active |
| pm-3 | Information Security and Privacy Resources | active |
| pm-4 | Plan of Action and Milestones Process | active |
| pm-5 | System Inventory | active |
| pm-5.1 | Inventory of Personally Identifiable Information | enhancement |
| pm-6 | Measures of Performance | active |
| pm-7 | Enterprise Architecture | active |
| pm-7.1 | Offloading | enhancement |
| pm-8 | Critical Infrastructure Plan | active |
| pm-9 | Risk Management Strategy | active |
| pm-10 | Authorization Process | active |
| pm-11 | Mission and Business Process Definition | active |
| pm-12 | Insider Threat Program | active |
| pm-13 | Security and Privacy Workforce | active |
| pm-14 | Testing, Training, and Monitoring | active |
| pm-15 | Security and Privacy Groups and Associations | active |
| pm-16 | Threat Awareness Program | active |
| pm-16.1 | Automated Means for Sharing Threat Intelligence | enhancement |
| pm-17 | Protecting Controlled Unclassified Information on External Systems | active |
| pm-18 | Privacy Program Plan | active |
| pm-19 | Privacy Program Leadership Role | active |
| pm-20 | Dissemination of Privacy Program Information | active |
| pm-20.1 | Privacy Policies on Websites, Applications, and Digital Services | enhancement |
| pm-21 | Accounting of Disclosures | active |
| pm-22 | Personally Identifiable Information Quality Management | active |
| pm-23 | Data Governance Body | active |
| pm-24 | Data Integrity Board | active |
| pm-25 | Minimization of Personally Identifiable Information Used in Testing, Training, and Research | active |
| pm-26 | Complaint Management | active |
| pm-27 | Privacy Reporting | active |
| pm-28 | Risk Framing | active |
| pm-29 | Risk Management Program Leadership Roles | active |
| pm-30 | Supply Chain Risk Management Strategy | active |
| pm-30.1 | Suppliers of Critical or Mission-essential Items | enhancement |
| pm-31 | Continuous Monitoring Strategy | active |
| pm-32 | Purposing | active |
Personnel Security ps
| ID | Title | Status |
|---|---|---|
| ps-1 | Policy and Procedures | active |
| ps-2 | Position Risk Designation | active |
| ps-3 | Personnel Screening | active |
| ps-3.1 | Classified Information | enhancement |
| ps-3.2 | Formal Indoctrination | enhancement |
| ps-3.3 | Information Requiring Special Protective Measures | enhancement |
| ps-3.4 | Citizenship Requirements | enhancement |
| ps-4 | Personnel Termination | active |
| ps-4.1 | Post-employment Requirements | enhancement |
| ps-4.2 | Automated Actions | enhancement |
| ps-5 | Personnel Transfer | active |
| ps-6 | Access Agreements | active |
| ps-6.1 | Withdrawn | withdrawn → ps-3 |
| ps-6.2 | Classified Information Requiring Special Protection | enhancement |
| ps-6.3 | Post-employment Requirements | enhancement |
| ps-7 | External Personnel Security | active |
| ps-8 | Personnel Sanctions | active |
| ps-9 | Position Descriptions | active |
Personally Identifiable Information Processing and Transparency pt
| ID | Title | Status |
|---|---|---|
| pt-1 | Policy and Procedures | active |
| pt-2 | Authority to Process Personally Identifiable Information | active |
| pt-2.1 | Data Tagging | enhancement |
| pt-2.2 | Automation | enhancement |
| pt-3 | Personally Identifiable Information Processing Purposes | active |
| pt-3.1 | Data Tagging | enhancement |
| pt-3.2 | Automation | enhancement |
| pt-4 | Consent | active |
| pt-4.1 | Tailored Consent | enhancement |
| pt-4.2 | Just-in-time Consent | enhancement |
| pt-4.3 | Revocation | enhancement |
| pt-5 | Privacy Notice | active |
| pt-5.1 | Just-in-time Notice | enhancement |
| pt-5.2 | Privacy Act Statements | enhancement |
| pt-6 | System of Records Notice | active |
| pt-6.1 | Routine Uses | enhancement |
| pt-6.2 | Exemption Rules | enhancement |
| pt-7 | Specific Categories of Personally Identifiable Information | active |
| pt-7.1 | Social Security Numbers | enhancement |
| pt-7.2 | First Amendment Information | enhancement |
| pt-8 | Computer Matching Requirements | active |
Risk Assessment ra
| ID | Title | Status |
|---|---|---|
| ra-1 | Policy and Procedures | active |
| ra-2 | Security Categorization | active |
| ra-2.1 | Impact-level Prioritization | enhancement |
| ra-3 | Risk Assessment | active |
| ra-3.1 | Supply Chain Risk Assessment | enhancement |
| ra-3.2 | Use of All-source Intelligence | enhancement |
| ra-3.3 | Dynamic Threat Awareness | enhancement |
| ra-3.4 | Predictive Cyber Analytics | enhancement |
| ra-4 | Withdrawn | withdrawn → ra-3 |
| ra-5 | Vulnerability Monitoring and Scanning | active |
| ra-5.1 | Withdrawn | withdrawn → ra-5 |
| ra-5.2 | Update Vulnerabilities to Be Scanned | enhancement |
| ra-5.3 | Breadth and Depth of Coverage | enhancement |
| ra-5.4 | Discoverable Information | enhancement |
| ra-5.5 | Privileged Access | enhancement |
| ra-5.6 | Automated Trend Analyses | enhancement |
| ra-5.7 | Withdrawn | withdrawn → cm-8 |
| ra-5.8 | Review Historic Audit Logs | enhancement |
| ra-5.9 | Withdrawn | withdrawn → ca-8 |
| ra-5.10 | Correlate Scanning Information | enhancement |
| ra-5.11 | Public Disclosure Program | enhancement |
| ra-6 | Technical Surveillance Countermeasures Survey | active |
| ra-7 | Risk Response | active |
| ra-8 | Privacy Impact Assessments | active |
| ra-9 | Criticality Analysis | active |
| ra-10 | Threat Hunting | active |
System and Services Acquisition sa
| ID | Title | Status |
|---|---|---|
| sa-1 | Policy and Procedures | active |
| sa-2 | Allocation of Resources | active |
| sa-3 | System Development Life Cycle | active |
| sa-3.1 | Manage Preproduction Environment | enhancement |
| sa-3.2 | Use of Live or Operational Data | enhancement |
| sa-3.3 | Technology Refresh | enhancement |
| sa-4 | Acquisition Process | active |
| sa-4.1 | Functional Properties of Controls | enhancement |
| sa-4.2 | Design and Implementation Information for Controls | enhancement |
| sa-4.3 | Development Methods, Techniques, and Practices | enhancement |
| sa-4.4 | Withdrawn | withdrawn → cm-8.9 |
| sa-4.5 | System, Component, and Service Configurations | enhancement |
| sa-4.6 | Use of Information Assurance Products | enhancement |
| sa-4.7 | NIAP-approved Protection Profiles | enhancement |
| sa-4.8 | Continuous Monitoring Plan for Controls | enhancement |
| sa-4.9 | Functions, Ports, Protocols, and Services in Use | enhancement |
| sa-4.10 | Use of Approved PIV Products | enhancement |
| sa-4.11 | System of Records | enhancement |
| sa-4.12 | Data Ownership | enhancement |
| sa-5 | System Documentation | active |
| sa-5.1 | Withdrawn | withdrawn → sa-4.1 |
| sa-5.2 | Withdrawn | withdrawn → sa-4.2 |
| sa-5.3 | Withdrawn | withdrawn → sa-4.2 |
| sa-5.4 | Withdrawn | withdrawn → sa-4.2 |
| sa-5.5 | Withdrawn | withdrawn → sa-4.2 |
| sa-6 | Withdrawn | withdrawn → si-7 |
| sa-7 | Withdrawn | withdrawn → si-7 |
| sa-8 | Security and Privacy Engineering Principles | active |
| sa-8.1 | Clear Abstractions | enhancement |
| sa-8.2 | Least Common Mechanism | enhancement |
| sa-8.3 | Modularity and Layering | enhancement |
| sa-8.4 | Partially Ordered Dependencies | enhancement |
| sa-8.5 | Efficiently Mediated Access | enhancement |
| sa-8.6 | Minimized Sharing | enhancement |
| sa-8.7 | Reduced Complexity | enhancement |
| sa-8.8 | Secure Evolvability | enhancement |
| sa-8.9 | Trusted Components | enhancement |
| sa-8.10 | Hierarchical Trust | enhancement |
| sa-8.11 | Inverse Modification Threshold | enhancement |
| sa-8.12 | Hierarchical Protection | enhancement |
| sa-8.13 | Minimized Security Elements | enhancement |
| sa-8.14 | Least Privilege | enhancement |
| sa-8.15 | Predicate Permission | enhancement |
| sa-8.16 | Self-reliant Trustworthiness | enhancement |
| sa-8.17 | Secure Distributed Composition | enhancement |
| sa-8.18 | Trusted Communications Channels | enhancement |
| sa-8.19 | Continuous Protection | enhancement |
| sa-8.20 | Secure Metadata Management | enhancement |
| sa-8.21 | Self-analysis | enhancement |
| sa-8.22 | Accountability and Traceability | enhancement |
| sa-8.23 | Secure Defaults | enhancement |
| sa-8.24 | Secure Failure and Recovery | enhancement |
| sa-8.25 | Economic Security | enhancement |
| sa-8.26 | Performance Security | enhancement |
| sa-8.27 | Human Factored Security | enhancement |
| sa-8.28 | Acceptable Security | enhancement |
| sa-8.29 | Repeatable and Documented Procedures | enhancement |
| sa-8.30 | Procedural Rigor | enhancement |
| sa-8.31 | Secure System Modification | enhancement |
| sa-8.32 | Sufficient Documentation | enhancement |
| sa-8.33 | Minimization | enhancement |
| sa-9 | External System Services | active |
| sa-9.1 | Risk Assessments and Organizational Approvals | enhancement |
| sa-9.2 | Identification of Functions, Ports, Protocols, and Services | enhancement |
| sa-9.3 | Establish and Maintain Trust Relationship with Providers | enhancement |
| sa-9.4 | Consistent Interests of Consumers and Providers | enhancement |
| sa-9.5 | Processing, Storage, and Service Location | enhancement |
| sa-9.6 | Organization-controlled Cryptographic Keys | enhancement |
| sa-9.7 | Organization-controlled Integrity Checking | enhancement |
| sa-9.8 | Processing and Storage Location — U.S. Jurisdiction | enhancement |
| sa-10 | Developer Configuration Management | active |
| sa-10.1 | Software and Firmware Integrity Verification | enhancement |
| sa-10.2 | Alternative Configuration Management Processes | enhancement |
| sa-10.3 | Hardware Integrity Verification | enhancement |
| sa-10.4 | Trusted Generation | enhancement |
| sa-10.5 | Mapping Integrity for Version Control | enhancement |
| sa-10.6 | Trusted Distribution | enhancement |
| sa-10.7 | Security and Privacy Representatives | enhancement |
| sa-11 | Developer Testing and Evaluation | active |
| sa-11.1 | Static Code Analysis | enhancement |
| sa-11.2 | Threat Modeling and Vulnerability Analyses | enhancement |
| sa-11.3 | Independent Verification of Assessment Plans and Evidence | enhancement |
| sa-11.4 | Manual Code Reviews | enhancement |
| sa-11.5 | Penetration Testing | enhancement |
| sa-11.6 | Attack Surface Reviews | enhancement |
| sa-11.7 | Verify Scope of Testing and Evaluation | enhancement |
| sa-11.8 | Dynamic Code Analysis | enhancement |
| sa-11.9 | Interactive Application Security Testing | enhancement |
| sa-12 | Withdrawn | withdrawn → sr |
| sa-12.1 | Withdrawn | withdrawn → sr-5 |
| sa-12.2 | Withdrawn | withdrawn → sr-6 |
| sa-12.3 | Withdrawn | withdrawn → sr-3 |
| sa-12.4 | Withdrawn | withdrawn → sr-3.1 |
| sa-12.5 | Withdrawn | withdrawn → sr-3.2 |
| sa-12.6 | Withdrawn | withdrawn → sr-5.1 |
| sa-12.7 | Withdrawn | withdrawn → sr-5.2 |
| sa-12.8 | Withdrawn | withdrawn → ra-3.2 |
| sa-12.9 | Withdrawn | withdrawn → sr-7 |
| sa-12.10 | Withdrawn | withdrawn → sr-4.3 |
| sa-12.11 | Withdrawn | withdrawn → sr-6.1 |
| sa-12.12 | Withdrawn | withdrawn → sr-8 |
| sa-12.13 | Withdrawn | withdrawn → ra-9 |
| sa-12.14 | Withdrawn | withdrawn → sr-4.2 |
| sa-12.15 | Withdrawn | withdrawn → sr-3 |
| sa-13 | Withdrawn | withdrawn → sa-8 |
| sa-14 | Withdrawn | withdrawn → ra-9 |
| sa-14.1 | Withdrawn | withdrawn → sa-20 |
| sa-15 | Development Process, Standards, and Tools | active |
| sa-15.1 | Quality Metrics | enhancement |
| sa-15.2 | Security and Privacy Tracking Tools | enhancement |
| sa-15.3 | Criticality Analysis | enhancement |
| sa-15.4 | Withdrawn | withdrawn → sa-11.2 |
| sa-15.5 | Attack Surface Reduction | enhancement |
| sa-15.6 | Continuous Improvement | enhancement |
| sa-15.7 | Automated Vulnerability Analysis | enhancement |
| sa-15.8 | Reuse of Threat and Vulnerability Information | enhancement |
| sa-15.9 | Withdrawn | withdrawn → sa-3.2 |
| sa-15.10 | Incident Response Plan | enhancement |
| sa-15.11 | Archive System or Component | enhancement |
| sa-15.12 | Minimize Personally Identifiable Information | enhancement |
| sa-15.13 | Logging Syntax | enhancement |
| sa-16 | Developer-provided Training | active |
| sa-17 | Developer Security and Privacy Architecture and Design | active |
| sa-17.1 | Formal Policy Model | enhancement |
| sa-17.2 | Security-relevant Components | enhancement |
| sa-17.3 | Formal Correspondence | enhancement |
| sa-17.4 | Informal Correspondence | enhancement |
| sa-17.5 | Conceptually Simple Design | enhancement |
| sa-17.6 | Structure for Testing | enhancement |
| sa-17.7 | Structure for Least Privilege | enhancement |
| sa-17.8 | Orchestration | enhancement |
| sa-17.9 | Design Diversity | enhancement |
| sa-18 | Withdrawn | withdrawn → sr-9 |
| sa-18.1 | Withdrawn | withdrawn → sr-9.1 |
| sa-18.2 | Withdrawn | withdrawn → sr-10 |
| sa-19 | Withdrawn | withdrawn → sr-11 |
| sa-19.1 | Withdrawn | withdrawn → sr-11.1 |
| sa-19.2 | Withdrawn | withdrawn → sr-11.2 |
| sa-19.3 | Withdrawn | withdrawn → sr-12 |
| sa-19.4 | Withdrawn | withdrawn → sr-11.3 |
| sa-20 | Customized Development of Critical Components | active |
| sa-21 | Developer Screening | active |
| sa-21.1 | Withdrawn | withdrawn → sa-21 |
| sa-22 | Unsupported System Components | active |
| sa-22.1 | Withdrawn | withdrawn → sa-22 |
| sa-23 | Specialization | active |
| sa-24 | Design For Cyber Resiliency | active |
System and Communications Protection sc
| ID | Title | Status |
|---|---|---|
| sc-1 | Policy and Procedures | active |
| sc-2 | Separation of System and User Functionality | active |
| sc-2.1 | Interfaces for Non-privileged Users | enhancement |
| sc-2.2 | Disassociability | enhancement |
| sc-3 | Security Function Isolation | active |
| sc-3.1 | Hardware Separation | enhancement |
| sc-3.2 | Access and Flow Control Functions | enhancement |
| sc-3.3 | Minimize Nonsecurity Functionality | enhancement |
| sc-3.4 | Module Coupling and Cohesiveness | enhancement |
| sc-3.5 | Layered Structures | enhancement |
| sc-4 | Information in Shared System Resources | active |
| sc-4.1 | Withdrawn | withdrawn → sc-4 |
| sc-4.2 | Multilevel or Periods Processing | enhancement |
| sc-5 | Denial-of-service Protection | active |
| sc-5.1 | Restrict Ability to Attack Other Systems | enhancement |
| sc-5.2 | Capacity, Bandwidth, and Redundancy | enhancement |
| sc-5.3 | Detection and Monitoring | enhancement |
| sc-6 | Resource Availability | active |
| sc-7 | Boundary Protection | active |
| sc-7.1 | Withdrawn | withdrawn → sc-7 |
| sc-7.2 | Withdrawn | withdrawn → sc-7 |
| sc-7.3 | Access Points | enhancement |
| sc-7.4 | External Telecommunications Services | enhancement |
| sc-7.5 | Deny by Default — Allow by Exception | enhancement |
| sc-7.6 | Withdrawn | withdrawn → sc-7.18 |
| sc-7.7 | Split Tunneling for Remote Devices | enhancement |
| sc-7.8 | Route Traffic to Authenticated Proxy Servers | enhancement |
| sc-7.9 | Restrict Threatening Outgoing Communications Traffic | enhancement |
| sc-7.10 | Prevent Exfiltration | enhancement |
| sc-7.11 | Restrict Incoming Communications Traffic | enhancement |
| sc-7.12 | Host-based Protection | enhancement |
| sc-7.13 | Isolation of Security Tools, Mechanisms, and Support Components | enhancement |
| sc-7.14 | Protect Against Unauthorized Physical Connections | enhancement |
| sc-7.15 | Networked Privileged Accesses | enhancement |
| sc-7.16 | Prevent Discovery of System Components | enhancement |
| sc-7.17 | Automated Enforcement of Protocol Formats | enhancement |
| sc-7.18 | Fail Secure | enhancement |
| sc-7.19 | Block Communication from Non-organizationally Configured Hosts | enhancement |
| sc-7.20 | Dynamic Isolation and Segregation | enhancement |
| sc-7.21 | Isolation of System Components | enhancement |
| sc-7.22 | Separate Subnets for Connecting to Different Security Domains | enhancement |
| sc-7.23 | Disable Sender Feedback on Protocol Validation Failure | enhancement |
| sc-7.24 | Personally Identifiable Information | enhancement |
| sc-7.25 | Unclassified National Security System Connections | enhancement |
| sc-7.26 | Classified National Security System Connections | enhancement |
| sc-7.27 | Unclassified Non-national Security System Connections | enhancement |
| sc-7.28 | Connections to Public Networks | enhancement |
| sc-7.29 | Separate Subnets to Isolate Functions | enhancement |
| sc-8 | Transmission Confidentiality and Integrity | active |
| sc-8.1 | Cryptographic Protection | enhancement |
| sc-8.2 | Pre- and Post-transmission Handling | enhancement |
| sc-8.3 | Cryptographic Protection for Message Externals | enhancement |
| sc-8.4 | Conceal or Randomize Communications | enhancement |
| sc-8.5 | Protected Distribution System | enhancement |
| sc-9 | Withdrawn | withdrawn → sc-8 |
| sc-10 | Network Disconnect | active |
| sc-11 | Trusted Path | active |
| sc-11.1 | Irrefutable Communications Path | enhancement |
| sc-12 | Cryptographic Key Establishment and Management | active |
| sc-12.1 | Availability | enhancement |
| sc-12.2 | Symmetric Keys | enhancement |
| sc-12.3 | Asymmetric Keys | enhancement |
| sc-12.4 | Withdrawn | withdrawn → sc-12.3 |
| sc-12.5 | Withdrawn | withdrawn → sc-12.3 |
| sc-12.6 | Physical Control of Keys | enhancement |
| sc-13 | Cryptographic Protection | active |
| sc-13.1 | Withdrawn | withdrawn → sc-13 |
| sc-13.2 | Withdrawn | withdrawn → sc-13 |
| sc-13.3 | Withdrawn | withdrawn → sc-13 |
| sc-13.4 | Withdrawn | withdrawn → sc-13 |
| sc-14 | Withdrawn | withdrawn → si-10 |
| sc-15 | Collaborative Computing Devices and Applications | active |
| sc-15.1 | Physical or Logical Disconnect | enhancement |
| sc-15.2 | Withdrawn | withdrawn → sc-7 |
| sc-15.3 | Disabling and Removal in Secure Work Areas | enhancement |
| sc-15.4 | Explicitly Indicate Current Participants | enhancement |
| sc-16 | Transmission of Security and Privacy Attributes | active |
| sc-16.1 | Integrity Verification | enhancement |
| sc-16.2 | Anti-spoofing Mechanisms | enhancement |
| sc-16.3 | Cryptographic Binding | enhancement |
| sc-17 | Public Key Infrastructure Certificates | active |
| sc-18 | Mobile Code | active |
| sc-18.1 | Identify Unacceptable Code and Take Corrective Actions | enhancement |
| sc-18.2 | Acquisition, Development, and Use | enhancement |
| sc-18.3 | Prevent Downloading and Execution | enhancement |
| sc-18.4 | Prevent Automatic Execution | enhancement |
| sc-18.5 | Allow Execution Only in Confined Environments | enhancement |
| sc-19 | Withdrawn | withdrawn |
| sc-20 | Secure Name/Address Resolution Service (Authoritative Source) | active |
| sc-20.1 | Withdrawn | withdrawn → sc-20 |
| sc-20.2 | Data Origin and Integrity | enhancement |
| sc-21 | Secure Name/Address Resolution Service (Recursive or Caching Resolver) | active |
| sc-21.1 | Withdrawn | withdrawn → sc-21 |
| sc-22 | Architecture and Provisioning for Name/Address Resolution Service | active |
| sc-23 | Session Authenticity | active |
| sc-23.1 | Invalidate Session Identifiers at Logout | enhancement |
| sc-23.2 | Withdrawn | withdrawn → ac-12.1 |
| sc-23.3 | Unique System-generated Session Identifiers | enhancement |
| sc-23.4 | Withdrawn | withdrawn → sc-23.3 |
| sc-23.5 | Allowed Certificate Authorities | enhancement |
| sc-24 | Fail in Known State | active |
| sc-25 | Thin Nodes | active |
| sc-26 | Decoys | active |
| sc-26.1 | Withdrawn | withdrawn → sc-35 |
| sc-27 | Platform-independent Applications | active |
| sc-28 | Protection of Information at Rest | active |
| sc-28.1 | Cryptographic Protection | enhancement |
| sc-28.2 | Offline Storage | enhancement |
| sc-28.3 | Cryptographic Keys | enhancement |
| sc-29 | Heterogeneity | active |
| sc-29.1 | Virtualization Techniques | enhancement |
| sc-30 | Concealment and Misdirection | active |
| sc-30.1 | Withdrawn | withdrawn → sc-29.1 |
| sc-30.2 | Randomness | enhancement |
| sc-30.3 | Change Processing and Storage Locations | enhancement |
| sc-30.4 | Misleading Information | enhancement |
| sc-30.5 | Concealment of System Components | enhancement |
| sc-31 | Covert Channel Analysis | active |
| sc-31.1 | Test Covert Channels for Exploitability | enhancement |
| sc-31.2 | Maximum Bandwidth | enhancement |
| sc-31.3 | Measure Bandwidth in Operational Environments | enhancement |
| sc-32 | System Partitioning | active |
| sc-32.1 | Separate Physical Domains for Privileged Functions | enhancement |
| sc-33 | Withdrawn | withdrawn → sc-8 |
| sc-34 | Non-modifiable Executable Programs | active |
| sc-34.1 | No Writable Storage | enhancement |
| sc-34.2 | Integrity Protection on Read-only Media | enhancement |
| sc-34.3 | Withdrawn | withdrawn → sc-51 |
| sc-35 | External Malicious Code Identification | active |
| sc-36 | Distributed Processing and Storage | active |
| sc-36.1 | Polling Techniques | enhancement |
| sc-36.2 | Synchronization | enhancement |
| sc-37 | Out-of-band Channels | active |
| sc-37.1 | Ensure Delivery and Transmission | enhancement |
| sc-38 | Operations Security | active |
| sc-39 | Process Isolation | active |
| sc-39.1 | Hardware Separation | enhancement |
| sc-39.2 | Separate Execution Domain Per Thread | enhancement |
| sc-40 | Wireless Link Protection | active |
| sc-40.1 | Electromagnetic Interference | enhancement |
| sc-40.2 | Reduce Detection Potential | enhancement |
| sc-40.3 | Imitative or Manipulative Communications Deception | enhancement |
| sc-40.4 | Signal Parameter Identification | enhancement |
| sc-41 | Port and I/O Device Access | active |
| sc-42 | Sensor Capability and Data | active |
| sc-42.1 | Reporting to Authorized Individuals or Roles | enhancement |
| sc-42.2 | Authorized Use | enhancement |
| sc-42.3 | Withdrawn | withdrawn → sc-42 |
| sc-42.4 | Notice of Collection | enhancement |
| sc-42.5 | Collection Minimization | enhancement |
| sc-43 | Usage Restrictions | active |
| sc-44 | Detonation Chambers | active |
| sc-45 | System Time Synchronization | active |
| sc-45.1 | Synchronization with Authoritative Time Source | enhancement |
| sc-45.2 | Secondary Authoritative Time Source | enhancement |
| sc-46 | Cross Domain Policy Enforcement | active |
| sc-47 | Alternate Communications Paths | active |
| sc-48 | Sensor Relocation | active |
| sc-48.1 | Dynamic Relocation of Sensors or Monitoring Capabilities | enhancement |
| sc-49 | Hardware-enforced Separation and Policy Enforcement | active |
| sc-50 | Software-enforced Separation and Policy Enforcement | active |
| sc-51 | Hardware-based Protection | active |
System and Information Integrity si
| ID | Title | Status |
|---|---|---|
| si-1 | Policy and Procedures | active |
| si-2 | Flaw Remediation | active |
| si-2.1 | Withdrawn | withdrawn → pl-9 |
| si-2.2 | Automated Flaw Remediation Status | enhancement |
| si-2.3 | Time to Remediate Flaws and Benchmarks for Corrective Actions | enhancement |
| si-2.4 | Automated Patch Management Tools | enhancement |
| si-2.5 | Automatic Software and Firmware Updates | enhancement |
| si-2.6 | Removal of Previous Versions of Software and Firmware | enhancement |
| si-2.7 | Root Cause Analysis | enhancement |
| si-3 | Malicious Code Protection | active |
| si-3.1 | Withdrawn | withdrawn → pl-9 |
| si-3.2 | Withdrawn | withdrawn → si-3 |
| si-3.3 | Withdrawn | withdrawn → ac-6.10 |
| si-3.4 | Updates Only by Privileged Users | enhancement |
| si-3.5 | Withdrawn | withdrawn → mp-7 |
| si-3.6 | Testing and Verification | enhancement |
| si-3.7 | Withdrawn | withdrawn → si-3 |
| si-3.8 | Detect Unauthorized Commands | enhancement |
| si-3.9 | Withdrawn | withdrawn → ac-17.10 |
| si-3.10 | Malicious Code Analysis | enhancement |
| si-4 | System Monitoring | active |
| si-4.1 | System-wide Intrusion Detection System | enhancement |
| si-4.2 | Automated Tools and Mechanisms for Real-time Analysis | enhancement |
| si-4.3 | Automated Tool and Mechanism Integration | enhancement |
| si-4.4 | Inbound and Outbound Communications Traffic | enhancement |
| si-4.5 | System-generated Alerts | enhancement |
| si-4.6 | Withdrawn | withdrawn → ac-6.10 |
| si-4.7 | Automated Response to Suspicious Events | enhancement |
| si-4.8 | Withdrawn | withdrawn → si-4 |
| si-4.9 | Testing of Monitoring Tools and Mechanisms | enhancement |
| si-4.10 | Visibility of Encrypted Communications | enhancement |
| si-4.11 | Analyze Communications Traffic Anomalies | enhancement |
| si-4.12 | Automated Organization-generated Alerts | enhancement |
| si-4.13 | Analyze Traffic and Event Patterns | enhancement |
| si-4.14 | Wireless Intrusion Detection | enhancement |
| si-4.15 | Wireless to Wireline Communications | enhancement |
| si-4.16 | Correlate Monitoring Information | enhancement |
| si-4.17 | Integrated Situational Awareness | enhancement |
| si-4.18 | Analyze Traffic and Covert Exfiltration | enhancement |
| si-4.19 | Risk for Individuals | enhancement |
| si-4.20 | Privileged Users | enhancement |
| si-4.21 | Probationary Periods | enhancement |
| si-4.22 | Unauthorized Network Services | enhancement |
| si-4.23 | Host-based Devices | enhancement |
| si-4.24 | Indicators of Compromise | enhancement |
| si-4.25 | Optimize Network Traffic Analysis | enhancement |
| si-5 | Security Alerts, Advisories, and Directives | active |
| si-5.1 | Automated Alerts and Advisories | enhancement |
| si-6 | Security and Privacy Function Verification | active |
| si-6.1 | Withdrawn | withdrawn → si-6 |
| si-6.2 | Automation Support for Distributed Testing | enhancement |
| si-6.3 | Report Verification Results | enhancement |
| si-7 | Software, Firmware, and Information Integrity | active |
| si-7.1 | Integrity Checks | enhancement |
| si-7.2 | Automated Notifications of Integrity Violations | enhancement |
| si-7.3 | Centrally Managed Integrity Tools | enhancement |
| si-7.4 | Withdrawn | withdrawn → sr-9 |
| si-7.5 | Automated Response to Integrity Violations | enhancement |
| si-7.6 | Cryptographic Protection | enhancement |
| si-7.7 | Integration of Detection and Response | enhancement |
| si-7.8 | Auditing Capability for Significant Events | enhancement |
| si-7.9 | Verify Boot Process | enhancement |
| si-7.10 | Protection of Boot Firmware | enhancement |
| si-7.11 | Withdrawn | withdrawn → cm-7.6 |
| si-7.12 | Integrity Verification | enhancement |
| si-7.13 | Withdrawn | withdrawn → cm-7.7 |
| si-7.14 | Withdrawn | withdrawn → cm-7.8 |
| si-7.15 | Code Authentication | enhancement |
| si-7.16 | Time Limit on Process Execution Without Supervision | enhancement |
| si-7.17 | Runtime Application Self-protection | enhancement |
| si-8 | Spam Protection | active |
| si-8.1 | Withdrawn | withdrawn → pl-9 |
| si-8.2 | Automatic Updates | enhancement |
| si-8.3 | Continuous Learning Capability | enhancement |
| si-9 | Withdrawn | withdrawn → ac-6 |
| si-10 | Information Input Validation | active |
| si-10.1 | Manual Override Capability | enhancement |
| si-10.2 | Review and Resolve Errors | enhancement |
| si-10.3 | Predictable Behavior | enhancement |
| si-10.4 | Timing Interactions | enhancement |
| si-10.5 | Restrict Inputs to Trusted Sources and Approved Formats | enhancement |
| si-10.6 | Injection Prevention | enhancement |
| si-11 | Error Handling | active |
| si-12 | Information Management and Retention | active |
| si-12.1 | Limit Personally Identifiable Information Elements | enhancement |
| si-12.2 | Minimize Personally Identifiable Information in Testing, Training, and Research | enhancement |
| si-12.3 | Information Disposal | enhancement |
| si-13 | Predictable Failure Prevention | active |
| si-13.1 | Transferring Component Responsibilities | enhancement |
| si-13.2 | Withdrawn | withdrawn → si-7.16 |
| si-13.3 | Manual Transfer Between Components | enhancement |
| si-13.4 | Standby Component Installation and Notification | enhancement |
| si-13.5 | Failover Capability | enhancement |
| si-14 | Non-persistence | active |
| si-14.1 | Refresh from Trusted Sources | enhancement |
| si-14.2 | Non-persistent Information | enhancement |
| si-14.3 | Non-persistent Connectivity | enhancement |
| si-15 | Information Output Filtering | active |
| si-16 | Memory Protection | active |
| si-17 | Fail-safe Procedures | active |
| si-18 | Personally Identifiable Information Quality Operations | active |
| si-18.1 | Automation Support | enhancement |
| si-18.2 | Data Tags | enhancement |
| si-18.3 | Collection | enhancement |
| si-18.4 | Individual Requests | enhancement |
| si-18.5 | Notice of Correction or Deletion | enhancement |
| si-19 | De-identification | active |
| si-19.1 | Collection | enhancement |
| si-19.2 | Archiving | enhancement |
| si-19.3 | Release | enhancement |
| si-19.4 | Removal, Masking, Encryption, Hashing, or Replacement of Direct Identifiers | enhancement |
| si-19.5 | Statistical Disclosure Control | enhancement |
| si-19.6 | Differential Privacy | enhancement |
| si-19.7 | Validated Algorithms and Software | enhancement |
| si-19.8 | Motivated Intruder | enhancement |
| si-20 | Tainting | active |
| si-21 | Information Refresh | active |
| si-22 | Information Diversity | active |
| si-23 | Information Fragmentation | active |
Supply Chain Risk Management sr
| ID | Title | Status |
|---|---|---|
| sr-1 | Policy and Procedures | active |
| sr-2 | Supply Chain Risk Management Plan | active |
| sr-2.1 | Establish SCRM Team | enhancement |
| sr-3 | Supply Chain Controls and Processes | active |
| sr-3.1 | Diverse Supply Base | enhancement |
| sr-3.2 | Limitation of Harm | enhancement |
| sr-3.3 | Sub-tier Flow Down | enhancement |
| sr-4 | Provenance | active |
| sr-4.1 | Identity | enhancement |
| sr-4.2 | Track and Trace | enhancement |
| sr-4.3 | Validate as Genuine and Not Altered | enhancement |
| sr-4.4 | Supply Chain Integrity — Pedigree | enhancement |
| sr-5 | Acquisition Strategies, Tools, and Methods | active |
| sr-5.1 | Adequate Supply | enhancement |
| sr-5.2 | Assessments Prior to Selection, Acceptance, Modification, or Update | enhancement |
| sr-6 | Supplier Assessments and Reviews | active |
| sr-6.1 | Testing and Analysis | enhancement |
| sr-7 | Supply Chain Operations Security | active |
| sr-8 | Notification Agreements | active |
| sr-9 | Tamper Resistance and Detection | active |
| sr-9.1 | Multiple Stages of System Development Life Cycle | enhancement |
| sr-10 | Inspection of Systems or Components | active |
| sr-11 | Component Authenticity | active |
| sr-11.1 | Anti-counterfeit Training | enhancement |
| sr-11.2 | Configuration Control for Component Service and Repair | enhancement |
| sr-11.3 | Anti-counterfeit Scanning | enhancement |
| sr-12 | Component Disposal | active |