DroneUp Compliance Docs

Framework

Full published catalogs. The control lookup lists active canonical requirements only; this view shows every framework as published, including withdrawn controls.

NIST SP 800-171 Rev 3 · version 1.1.0 · OSCAL v1.2.2 · 17 families · 97 active · 33 withdrawn

Access Control 03.01

IDTitleStatus
03.01.01 Account Management active
03.01.02 Access Enforcement active
03.01.03 Information Flow Enforcement active
03.01.04 Separation of Duties active
03.01.05 Least Privilege active
03.01.06 Least Privilege – Privileged Accounts active
03.01.07 Least Privilege – Privileged Functions active
03.01.08 Unsuccessful Logon Attempts active
03.01.09 System Use Notification active
03.01.10 Device Lock active
03.01.11 Session Termination active
03.01.12 Remote Access active
03.01.13 Withdrawn withdrawn → 03.13.08
03.01.14 Withdrawn withdrawn → 03.01.12
03.01.15 Withdrawn withdrawn → 03.01.12
03.01.16 Wireless Access active
03.01.17 Withdrawn withdrawn → 03.01.16
03.01.18 Access Control for Mobile Devices active
03.01.19 Withdrawn withdrawn → 03.01.18
03.01.20 Use of External Systems active
03.01.21 Withdrawn withdrawn → 03.01.20
03.01.22 Publicly Accessible Content active

Awareness and Training 03.02

IDTitleStatus
03.02.01 Literacy Training and Awareness active
03.02.02 Role-Based Training active
03.02.03 Withdrawn withdrawn → 03.02.01

Audit and Accountability 03.03

IDTitleStatus
03.03.01 Event Logging active
03.03.02 Audit Record Content active
03.03.03 Audit Record Generation active
03.03.04 Response to Audit Logging Process Failures active
03.03.05 Audit Record Review, Analysis, and Reporting active
03.03.06 Audit Record Reduction and Report Generation active
03.03.07 Time Stamps active
03.03.08 Protection of Audit Information active
03.03.09 Withdrawn withdrawn → 03.03.08

Configuration Management 03.04

IDTitleStatus
03.04.01 Baseline Configuration active
03.04.02 Configuration Settings active
03.04.03 Configuration Change Control active
03.04.04 Impact Analyses active
03.04.05 Access Restrictions for Change active
03.04.06 Least Functionality active
03.04.07 Withdrawn withdrawn → 03.04.08
03.04.08 Authorized Software – Allow by Exception active
03.04.09 Withdrawn withdrawn → 03.12.03
03.04.10 System Component Inventory active
03.04.11 Information Location active
03.04.12 System and Component Configuration for High-Risk Areas active

Identification and Authentication 03.05

IDTitleStatus
03.05.01 User Identification and Authentication active
03.05.02 Device Identification and Authentication active
03.05.03 Multi-Factor Authentication active
03.05.04 Replay-Resistant Authentication active
03.05.05 Identifier Management active
03.05.06 Withdrawn withdrawn
03.05.07 Password Management active
03.05.08 Withdrawn withdrawn
03.05.09 Withdrawn withdrawn
03.05.10 Withdrawn withdrawn → 03.05.07
03.05.11 Authentication Feedback active
03.05.12 Authenticator Management active

Incident Response 03.06

IDTitleStatus
03.06.01 Incident Handling active
03.06.02 Incident Monitoring, Reporting, and Response Assistance active
03.06.03 Incident Response Testing active
03.06.04 Incident Response Training active
03.06.05 Incident Response Plan active

Maintenance 03.07

IDTitleStatus
03.07.01 Withdrawn withdrawn
03.07.02 Withdrawn withdrawn → 03.07.06
03.07.03 Withdrawn withdrawn → 03.08.03
03.07.04 Maintenance Tools active
03.07.05 Nonlocal Maintenance active
03.07.06 Maintenance Personnel active

Media Protection 03.08

IDTitleStatus
03.08.01 Media Storage active
03.08.02 Media Access active
03.08.03 Media Sanitization active
03.08.04 Media Marking active
03.08.05 Media Transport active
03.08.06 Withdrawn withdrawn → 03.13.08
03.08.07 Media Use active
03.08.08 Withdrawn withdrawn → 03.08.07
03.08.09 System Backup – Cryptographic Protection active

Personnel Security 03.09

IDTitleStatus
03.09.01 Personnel Screening active
03.09.02 Personnel Termination and Transfer active

Physical Protection 03.10

IDTitleStatus
03.10.01 Physical Access Authorizations active
03.10.02 Monitoring Physical Access active
03.10.03 Withdrawn withdrawn → 03.10.07
03.10.04 Withdrawn withdrawn → 03.10.07
03.10.05 Withdrawn withdrawn → 03.10.07
03.10.06 Alternate Work Site active
03.10.07 Physical Access Control active
03.10.08 Access Control for Transmission active

Risk Assessment 03.11

IDTitleStatus
03.11.01 Risk Assessment active
03.11.02 Vulnerability Monitoring and Scanning active
03.11.03 Withdrawn withdrawn → 03.11.02
03.11.04 Risk Response active

Security Assessment and Monitoring 03.12

IDTitleStatus
03.12.01 Security Assessment active
03.12.02 Plan of Action and Milestones active
03.12.03 Continuous Monitoring active
03.12.04 Withdrawn withdrawn → 03.15.02
03.12.05 Information Exchange active

System and Communications Protection 03.13

IDTitleStatus
03.13.01 Boundary Protection active
03.13.02 Withdrawn withdrawn
03.13.03 Withdrawn withdrawn → 03.01.07
03.13.04 Information in Shared System Resources active
03.13.05 Withdrawn withdrawn → 03.13.01
03.13.06 Network Communications – Deny by Default – Allow by Exception active
03.13.07 Withdrawn withdrawn → 03.04.06
03.13.08 Transmission and Storage Confidentiality active
03.13.09 Network Disconnect active
03.13.10 Cryptographic Key Establishment and Management active
03.13.11 Cryptographic Protection active
03.13.12 Collaborative Computing Devices and Applications active
03.13.13 Mobile Code active
03.13.14 Withdrawn withdrawn
03.13.15 Session Authenticity active
03.13.16 Withdrawn withdrawn → 03.13.08

System and Information Integrity 03.14

IDTitleStatus
03.14.01 Flaw Remediation active
03.14.02 Malicious Code Protection active
03.14.03 Security Alerts, Advisories, and Directives active
03.14.04 Withdrawn withdrawn → 03.14.02
03.14.05 Withdrawn withdrawn → 03.14.02
03.14.06 System Monitoring active
03.14.07 Withdrawn withdrawn → 03.14.06
03.14.08 Information Management and Retention active

Planning 03.15

IDTitleStatus
03.15.01 Policy and Procedures active
03.15.02 System Security Plan active
03.15.03 Rules of Behavior active

System and Services Acquisition 03.16

IDTitleStatus
03.16.01 Security Engineering Principles active
03.16.02 Unsupported System Components active
03.16.03 External System Services active

Supply Chain Risk Management 03.17

IDTitleStatus
03.17.01 Supply Chain Risk Management Plan active
03.17.02 Acquisition Strategies, Tools, and Methods active
03.17.03 Supply Chain Requirements and Processes active