{
  "controls": [
    {
      "coverage": {
        "documents": 1,
        "gap": false,
        "statements": 1
      },
      "family": "Access Control",
      "frameworks": {
        "800-53": [
          {
            "id": "ac-2",
            "title": "Account Management"
          },
          {
            "id": "ac-3",
            "title": "Access Enforcement"
          }
        ],
        "cmmc": [
          {
            "id": "AC.L2-3.1.1",
            "title": ""
          }
        ],
        "iso": [
          {
            "id": "A.5.15",
            "title": ""
          }
        ]
      },
      "id": "03.01.01",
      "statements": [
        {
          "anchor": "account-management",
          "doc_id": "DU-1-POL-717-001",
          "summary": "Governs how accounts are established, reviewed, and removed so access traces to an approved need.",
          "title": "Access Control Policy",
          "type": "policy",
          "url": "/documents/infosec/du-1-pol-717-001/"
        }
      ],
      "title": "Account Management"
    },
    {
      "coverage": {
        "documents": 1,
        "gap": false,
        "statements": 1
      },
      "family": "Access Control",
      "frameworks": {},
      "id": "03.01.02",
      "statements": [
        {
          "anchor": "access-enforcement",
          "doc_id": "DU-1-POL-717-001",
          "summary": "Access decisions reflect current, approved authorizations based on role and business need.",
          "title": "Access Control Policy",
          "type": "policy",
          "url": "/documents/infosec/du-1-pol-717-001/"
        }
      ],
      "title": "Access Enforcement"
    },
    {
      "coverage": {
        "documents": 1,
        "gap": false,
        "statements": 1
      },
      "family": "Access Control",
      "frameworks": {},
      "id": "03.01.03",
      "statements": [
        {
          "anchor": "information-flow-enforcement",
          "doc_id": "DU-1-POL-717-001",
          "summary": "Controls movement of CUI to approved people, systems, and destinations.",
          "title": "Access Control Policy",
          "type": "policy",
          "url": "/documents/infosec/du-1-pol-717-001/"
        }
      ],
      "title": "Information Flow Enforcement"
    },
    {
      "coverage": {
        "documents": 1,
        "gap": false,
        "statements": 1
      },
      "family": "Access Control",
      "frameworks": {},
      "id": "03.01.04",
      "statements": [
        {
          "anchor": "separation-of-duties",
          "doc_id": "DU-1-POL-717-001",
          "summary": "Divides high-risk activities so no single person completes them alone.",
          "title": "Access Control Policy",
          "type": "policy",
          "url": "/documents/infosec/du-1-pol-717-001/"
        }
      ],
      "title": "Separation of Duties"
    },
    {
      "coverage": {
        "documents": 1,
        "gap": false,
        "statements": 1
      },
      "family": "Access Control",
      "frameworks": {},
      "id": "03.01.05",
      "statements": [
        {
          "anchor": "least-privilege",
          "doc_id": "DU-1-POL-717-001",
          "summary": "Grants only the access required for assigned duties; elevation requires justification.",
          "title": "Access Control Policy",
          "type": "policy",
          "url": "/documents/infosec/du-1-pol-717-001/"
        }
      ],
      "title": "Least Privilege"
    },
    {
      "coverage": {
        "documents": 1,
        "gap": false,
        "statements": 1
      },
      "family": "Access Control",
      "frameworks": {},
      "id": "03.01.06",
      "statements": [
        {
          "anchor": "least-privilege-privileged-accounts",
          "doc_id": "DU-1-POL-717-001",
          "summary": "Confines privileged accounts to entrusted roles; routine work uses ordinary accounts.",
          "title": "Access Control Policy",
          "type": "policy",
          "url": "/documents/infosec/du-1-pol-717-001/"
        }
      ],
      "title": "Least Privilege – Privileged Accounts"
    },
    {
      "coverage": {
        "documents": 1,
        "gap": false,
        "statements": 1
      },
      "family": "Access Control",
      "frameworks": {},
      "id": "03.01.07",
      "statements": [
        {
          "anchor": "least-privilege-privileged-functions",
          "doc_id": "DU-1-POL-717-001",
          "summary": "Restricts privileged actions to authorized users and keeps them logged.",
          "title": "Access Control Policy",
          "type": "policy",
          "url": "/documents/infosec/du-1-pol-717-001/"
        }
      ],
      "title": "Least Privilege – Privileged Functions"
    },
    {
      "coverage": {
        "documents": 1,
        "gap": false,
        "statements": 1
      },
      "family": "Access Control",
      "frameworks": {},
      "id": "03.01.08",
      "statements": [
        {
          "anchor": "unsuccessful-logon-attempts",
          "doc_id": "DU-1-POL-717-001",
          "summary": "Automatically curtails repeated failed sign-in attempts.",
          "title": "Access Control Policy",
          "type": "policy",
          "url": "/documents/infosec/du-1-pol-717-001/"
        }
      ],
      "title": "Unsuccessful Logon Attempts"
    },
    {
      "coverage": {
        "documents": 1,
        "gap": false,
        "statements": 1
      },
      "family": "Access Control",
      "frameworks": {},
      "id": "03.01.09",
      "statements": [
        {
          "anchor": "system-use-notification",
          "doc_id": "DU-1-POL-717-001",
          "summary": "Presents and requires acknowledgment of a system-use notice before access.",
          "title": "Access Control Policy",
          "type": "policy",
          "url": "/documents/infosec/du-1-pol-717-001/"
        }
      ],
      "title": "System Use Notification"
    },
    {
      "coverage": {
        "documents": 1,
        "gap": false,
        "statements": 1
      },
      "family": "Access Control",
      "frameworks": {},
      "id": "03.01.10",
      "statements": [
        {
          "anchor": "device-lock",
          "doc_id": "DU-1-POL-717-001",
          "summary": "Locks sessions after inactivity and conceals content until re-authentication.",
          "title": "Access Control Policy",
          "type": "policy",
          "url": "/documents/infosec/du-1-pol-717-001/"
        }
      ],
      "title": "Device Lock"
    },
    {
      "coverage": {
        "documents": 1,
        "gap": false,
        "statements": 1
      },
      "family": "Access Control",
      "frameworks": {},
      "id": "03.01.11",
      "statements": [
        {
          "anchor": "session-termination",
          "doc_id": "DU-1-POL-717-001",
          "summary": "Closes sessions automatically under defined conditions.",
          "title": "Access Control Policy",
          "type": "policy",
          "url": "/documents/infosec/du-1-pol-717-001/"
        }
      ],
      "title": "Session Termination"
    },
    {
      "coverage": {
        "documents": 1,
        "gap": false,
        "statements": 1
      },
      "family": "Access Control",
      "frameworks": {},
      "id": "03.01.12",
      "statements": [
        {
          "anchor": "remote-access",
          "doc_id": "DU-1-POL-717-001",
          "summary": "Defines, approves, and routes remote access through managed entry points.",
          "title": "Access Control Policy",
          "type": "policy",
          "url": "/documents/infosec/du-1-pol-717-001/"
        }
      ],
      "title": "Remote Access"
    },
    {
      "coverage": {
        "documents": 1,
        "gap": false,
        "statements": 1
      },
      "family": "Access Control",
      "frameworks": {},
      "id": "03.01.16",
      "statements": [
        {
          "anchor": "wireless-access",
          "doc_id": "DU-1-POL-717-001",
          "summary": "Defines, approves, and protects wireless access; disables unused wireless.",
          "title": "Access Control Policy",
          "type": "policy",
          "url": "/documents/infosec/du-1-pol-717-001/"
        }
      ],
      "title": "Wireless Access"
    },
    {
      "coverage": {
        "documents": 1,
        "gap": false,
        "statements": 1
      },
      "family": "Access Control",
      "frameworks": {},
      "id": "03.01.18",
      "statements": [
        {
          "anchor": "mobile-devices",
          "doc_id": "DU-1-POL-717-001",
          "summary": "Authorizes, configures, and encrypts mobile device access to systems and CUI.",
          "title": "Access Control Policy",
          "type": "policy",
          "url": "/documents/infosec/du-1-pol-717-001/"
        }
      ],
      "title": "Access Control for Mobile Devices"
    },
    {
      "coverage": {
        "documents": 1,
        "gap": false,
        "statements": 1
      },
      "family": "Access Control",
      "frameworks": {},
      "id": "03.01.20",
      "statements": [
        {
          "anchor": "external-systems",
          "doc_id": "DU-1-POL-717-001",
          "summary": "Restricts use of external or personal systems and portable storage for CUI.",
          "title": "Access Control Policy",
          "type": "policy",
          "url": "/documents/infosec/du-1-pol-717-001/"
        }
      ],
      "title": "Use of External Systems"
    },
    {
      "coverage": {
        "documents": 1,
        "gap": false,
        "statements": 1
      },
      "family": "Access Control",
      "frameworks": {},
      "id": "03.01.22",
      "statements": [
        {
          "anchor": "publicly-accessible-content",
          "doc_id": "DU-1-POL-717-001",
          "summary": "Limits public posting to trained, designated publishers and reviews content for CUI.",
          "title": "Access Control Policy",
          "type": "policy",
          "url": "/documents/infosec/du-1-pol-717-001/"
        }
      ],
      "title": "Publicly Accessible Content"
    },
    {
      "coverage": {
        "documents": 0,
        "gap": true,
        "statements": 0
      },
      "family": "Awareness and Training",
      "frameworks": {},
      "id": "03.02.01",
      "statements": [],
      "title": "Literacy Training and Awareness"
    },
    {
      "coverage": {
        "documents": 0,
        "gap": true,
        "statements": 0
      },
      "family": "Awareness and Training",
      "frameworks": {},
      "id": "03.02.02",
      "statements": [],
      "title": "Role-Based Training"
    },
    {
      "coverage": {
        "documents": 1,
        "gap": false,
        "statements": 1
      },
      "family": "Audit and Accountability",
      "frameworks": {
        "800-53": [
          {
            "id": "au-2",
            "title": "Event Logging"
          },
          {
            "id": "au-3",
            "title": "Content of Audit Records"
          },
          {
            "id": "au-12",
            "title": "Audit Record Generation"
          }
        ],
        "cmmc": [
          {
            "id": "AU.L2-3.3.1",
            "title": ""
          }
        ],
        "iso": [
          {
            "id": "A.8.15",
            "title": ""
          }
        ]
      },
      "id": "03.03.01",
      "statements": [
        {
          "anchor": "event-logging",
          "doc_id": "DU-1-POL-911-001",
          "summary": "Defines and maintains the categories of security-relevant events that systems log.",
          "title": "Security Audit and Accountability Policy",
          "type": "policy",
          "url": "/documents/infosec/du-1-pol-911-001/"
        }
      ],
      "title": "Event Logging"
    },
    {
      "coverage": {
        "documents": 1,
        "gap": false,
        "statements": 1
      },
      "family": "Audit and Accountability",
      "frameworks": {},
      "id": "03.03.02",
      "statements": [
        {
          "anchor": "audit-record-content",
          "doc_id": "DU-1-POL-911-001",
          "summary": "Ensures each record captures what, when, where, source, outcome, and identity.",
          "title": "Security Audit and Accountability Policy",
          "type": "policy",
          "url": "/documents/infosec/du-1-pol-911-001/"
        }
      ],
      "title": "Audit Record Content"
    },
    {
      "coverage": {
        "documents": 1,
        "gap": false,
        "statements": 1
      },
      "family": "Audit and Accountability",
      "frameworks": {},
      "id": "03.03.03",
      "statements": [
        {
          "anchor": "audit-record-generation",
          "doc_id": "DU-1-POL-911-001",
          "summary": "Generates and retains audit records across all in-scope systems.",
          "title": "Security Audit and Accountability Policy",
          "type": "policy",
          "url": "/documents/infosec/du-1-pol-911-001/"
        }
      ],
      "title": "Audit Record Generation"
    },
    {
      "coverage": {
        "documents": 1,
        "gap": false,
        "statements": 1
      },
      "family": "Audit and Accountability",
      "frameworks": {},
      "id": "03.03.04",
      "statements": [
        {
          "anchor": "audit-logging-failures",
          "doc_id": "DU-1-POL-911-001",
          "summary": "Alerts and responds when the audit subsystem fails or nears capacity.",
          "title": "Security Audit and Accountability Policy",
          "type": "policy",
          "url": "/documents/infosec/du-1-pol-911-001/"
        }
      ],
      "title": "Response to Audit Logging Process Failures"
    },
    {
      "coverage": {
        "documents": 1,
        "gap": false,
        "statements": 1
      },
      "family": "Audit and Accountability",
      "frameworks": {},
      "id": "03.03.05",
      "statements": [
        {
          "anchor": "audit-review",
          "doc_id": "DU-1-POL-911-001",
          "summary": "Reviews, correlates, and reports on audit records; escalates suspicious activity.",
          "title": "Security Audit and Accountability Policy",
          "type": "policy",
          "url": "/documents/infosec/du-1-pol-911-001/"
        }
      ],
      "title": "Audit Record Review, Analysis, and Reporting"
    },
    {
      "coverage": {
        "documents": 1,
        "gap": false,
        "statements": 1
      },
      "family": "Audit and Accountability",
      "frameworks": {},
      "id": "03.03.06",
      "statements": [
        {
          "anchor": "audit-reduction",
          "doc_id": "DU-1-POL-911-001",
          "summary": "Consolidates records into reports without altering the originals.",
          "title": "Security Audit and Accountability Policy",
          "type": "policy",
          "url": "/documents/infosec/du-1-pol-911-001/"
        }
      ],
      "title": "Audit Record Reduction and Report Generation"
    },
    {
      "coverage": {
        "documents": 1,
        "gap": false,
        "statements": 1
      },
      "family": "Audit and Accountability",
      "frameworks": {},
      "id": "03.03.07",
      "statements": [
        {
          "anchor": "time-stamps",
          "doc_id": "DU-1-POL-911-001",
          "summary": "Time-stamps records from a synchronized source, in UTC or with offset.",
          "title": "Security Audit and Accountability Policy",
          "type": "policy",
          "url": "/documents/infosec/du-1-pol-911-001/"
        }
      ],
      "title": "Time Stamps"
    },
    {
      "coverage": {
        "documents": 1,
        "gap": false,
        "statements": 1
      },
      "family": "Audit and Accountability",
      "frameworks": {},
      "id": "03.03.08",
      "statements": [
        {
          "anchor": "protection-of-audit-information",
          "doc_id": "DU-1-POL-911-001",
          "summary": "Protects audit information from unauthorized access, modification, and deletion.",
          "title": "Security Audit and Accountability Policy",
          "type": "policy",
          "url": "/documents/infosec/du-1-pol-911-001/"
        }
      ],
      "title": "Protection of Audit Information"
    },
    {
      "coverage": {
        "documents": 0,
        "gap": true,
        "statements": 0
      },
      "family": "Configuration Management",
      "frameworks": {},
      "id": "03.04.01",
      "statements": [],
      "title": "Baseline Configuration"
    },
    {
      "coverage": {
        "documents": 0,
        "gap": true,
        "statements": 0
      },
      "family": "Configuration Management",
      "frameworks": {},
      "id": "03.04.02",
      "statements": [],
      "title": "Configuration Settings"
    },
    {
      "coverage": {
        "documents": 0,
        "gap": true,
        "statements": 0
      },
      "family": "Configuration Management",
      "frameworks": {},
      "id": "03.04.03",
      "statements": [],
      "title": "Configuration Change Control"
    },
    {
      "coverage": {
        "documents": 0,
        "gap": true,
        "statements": 0
      },
      "family": "Configuration Management",
      "frameworks": {},
      "id": "03.04.04",
      "statements": [],
      "title": "Impact Analyses"
    },
    {
      "coverage": {
        "documents": 0,
        "gap": true,
        "statements": 0
      },
      "family": "Configuration Management",
      "frameworks": {},
      "id": "03.04.05",
      "statements": [],
      "title": "Access Restrictions for Change"
    },
    {
      "coverage": {
        "documents": 0,
        "gap": true,
        "statements": 0
      },
      "family": "Configuration Management",
      "frameworks": {},
      "id": "03.04.06",
      "statements": [],
      "title": "Least Functionality"
    },
    {
      "coverage": {
        "documents": 0,
        "gap": true,
        "statements": 0
      },
      "family": "Configuration Management",
      "frameworks": {},
      "id": "03.04.08",
      "statements": [],
      "title": "Authorized Software – Allow by Exception"
    },
    {
      "coverage": {
        "documents": 0,
        "gap": true,
        "statements": 0
      },
      "family": "Configuration Management",
      "frameworks": {},
      "id": "03.04.10",
      "statements": [],
      "title": "System Component Inventory"
    },
    {
      "coverage": {
        "documents": 0,
        "gap": true,
        "statements": 0
      },
      "family": "Configuration Management",
      "frameworks": {},
      "id": "03.04.11",
      "statements": [],
      "title": "Information Location"
    },
    {
      "coverage": {
        "documents": 0,
        "gap": true,
        "statements": 0
      },
      "family": "Configuration Management",
      "frameworks": {},
      "id": "03.04.12",
      "statements": [],
      "title": "System and Component Configuration for High-Risk Areas"
    },
    {
      "coverage": {
        "documents": 2,
        "gap": false,
        "statements": 2
      },
      "family": "Identification and Authentication",
      "frameworks": {},
      "id": "03.05.01",
      "statements": [
        {
          "anchor": "user-identification-authentication",
          "doc_id": "DU-1-POL-717-002",
          "summary": "Uniquely identifies and authenticates organizational and non-organizational users and their processes.",
          "title": "Identification and Authentication Policy",
          "type": "policy",
          "url": "/documents/infosec/du-1-pol-717-002/"
        },
        {
          "anchor": "re-authentication",
          "doc_id": "DU-2-SUB-717-007",
          "summary": "Defines the conditions requiring re-authentication and step-up for privileged functions.",
          "title": "Multi-Factor Authentication (MFA) Subpolicy",
          "type": "sub-policy",
          "url": "/documents/infosec/du-2-sub-717-007/"
        }
      ],
      "title": "User Identification and Authentication"
    },
    {
      "coverage": {
        "documents": 1,
        "gap": false,
        "statements": 1
      },
      "family": "Identification and Authentication",
      "frameworks": {},
      "id": "03.05.02",
      "statements": [
        {
          "anchor": "device-identification-authentication",
          "doc_id": "DU-1-POL-717-002",
          "summary": "Uniquely identifies and authenticates devices before local, remote, or network connection.",
          "title": "Identification and Authentication Policy",
          "type": "policy",
          "url": "/documents/infosec/du-1-pol-717-002/"
        }
      ],
      "title": "Device Identification and Authentication"
    },
    {
      "coverage": {
        "documents": 3,
        "gap": false,
        "statements": 3
      },
      "family": "Identification and Authentication",
      "frameworks": {
        "800-53": [
          {
            "id": "ia-2.1",
            "title": "Multi-factor Authentication to Privileged Accounts"
          },
          {
            "id": "ia-2.2",
            "title": "Multi-factor Authentication to Non-privileged Accounts"
          }
        ],
        "cmmc": [
          {
            "id": "IA.L2-3.5.3",
            "title": ""
          }
        ],
        "iso": [
          {
            "id": "A.8.5",
            "title": ""
          }
        ]
      },
      "id": "03.05.03",
      "statements": [
        {
          "anchor": "multi-factor-authentication",
          "doc_id": "DU-1-POL-717-002",
          "summary": "Requires MFA for privileged and non-privileged accounts.",
          "title": "Identification and Authentication Policy",
          "type": "policy",
          "url": "/documents/infosec/du-1-pol-717-002/"
        },
        {
          "anchor": "procedure-definition",
          "doc_id": "DU-2-PRO-717-017",
          "summary": "Configures the identity provider MFA policy, enrolls accounts, and verifies ongoing enforcement, with go-criteria per step.",
          "title": "Multi-Factor Authentication (MFA) Procedure",
          "type": "procedure",
          "url": "/documents/infosec/du-2-pro-717-017/"
        },
        {
          "anchor": "multi-factor-authentication",
          "doc_id": "DU-2-SUB-717-007",
          "summary": "Requires MFA via the central identity provider for all accounts; defines permitted factors and prohibits SMS and voice.",
          "title": "Multi-Factor Authentication (MFA) Subpolicy",
          "type": "sub-policy",
          "url": "/documents/infosec/du-2-sub-717-007/"
        }
      ],
      "title": "Multi-Factor Authentication"
    },
    {
      "coverage": {
        "documents": 2,
        "gap": false,
        "statements": 2
      },
      "family": "Identification and Authentication",
      "frameworks": {},
      "id": "03.05.04",
      "statements": [
        {
          "anchor": "replay-resistant-authentication",
          "doc_id": "DU-1-POL-717-002",
          "summary": "Uses replay-resistant authentication via the central identity provider.",
          "title": "Identification and Authentication Policy",
          "type": "policy",
          "url": "/documents/infosec/du-1-pol-717-002/"
        },
        {
          "anchor": "replay-resistance",
          "doc_id": "DU-2-SUB-717-007",
          "summary": "Requires replay-resistant authentication with no replay-able fallback; binds admin sessions to IP and AS.",
          "title": "Multi-Factor Authentication (MFA) Subpolicy",
          "type": "sub-policy",
          "url": "/documents/infosec/du-2-sub-717-007/"
        }
      ],
      "title": "Replay-Resistant Authentication"
    },
    {
      "coverage": {
        "documents": 1,
        "gap": false,
        "statements": 1
      },
      "family": "Identification and Authentication",
      "frameworks": {},
      "id": "03.05.05",
      "statements": [
        {
          "anchor": "identifier-management",
          "doc_id": "DU-1-POL-717-002",
          "summary": "Manages identifier authorization, uniqueness, assignment, and reuse.",
          "title": "Identification and Authentication Policy",
          "type": "policy",
          "url": "/documents/infosec/du-1-pol-717-002/"
        }
      ],
      "title": "Identifier Management"
    },
    {
      "coverage": {
        "documents": 1,
        "gap": false,
        "statements": 1
      },
      "family": "Identification and Authentication",
      "frameworks": {},
      "id": "03.05.07",
      "statements": [
        {
          "anchor": "password-management",
          "doc_id": "DU-1-POL-717-002",
          "summary": "Verifies passwords against compromised lists; protects them in transit and at rest.",
          "title": "Identification and Authentication Policy",
          "type": "policy",
          "url": "/documents/infosec/du-1-pol-717-002/"
        }
      ],
      "title": "Password Management"
    },
    {
      "coverage": {
        "documents": 1,
        "gap": false,
        "statements": 1
      },
      "family": "Identification and Authentication",
      "frameworks": {},
      "id": "03.05.11",
      "statements": [
        {
          "anchor": "authentication-feedback",
          "doc_id": "DU-1-POL-717-002",
          "summary": "Obscures authentication feedback, including masking password entry.",
          "title": "Identification and Authentication Policy",
          "type": "policy",
          "url": "/documents/infosec/du-1-pol-717-002/"
        }
      ],
      "title": "Authentication Feedback"
    },
    {
      "coverage": {
        "documents": 1,
        "gap": false,
        "statements": 1
      },
      "family": "Identification and Authentication",
      "frameworks": {},
      "id": "03.05.12",
      "statements": [
        {
          "anchor": "authenticator-management",
          "doc_id": "DU-1-POL-717-002",
          "summary": "Manages authenticators across issuance, refresh, revocation, and protection.",
          "title": "Identification and Authentication Policy",
          "type": "policy",
          "url": "/documents/infosec/du-1-pol-717-002/"
        }
      ],
      "title": "Authenticator Management"
    },
    {
      "coverage": {
        "documents": 0,
        "gap": true,
        "statements": 0
      },
      "family": "Incident Response",
      "frameworks": {
        "800-53": [
          {
            "id": "ir-4",
            "title": "Incident Handling"
          }
        ],
        "cmmc": [
          {
            "id": "IR.L2-3.6.1",
            "title": ""
          }
        ],
        "iso": [
          {
            "id": "A.5.24",
            "title": ""
          }
        ]
      },
      "id": "03.06.01",
      "statements": [],
      "title": "Incident Handling"
    },
    {
      "coverage": {
        "documents": 0,
        "gap": true,
        "statements": 0
      },
      "family": "Incident Response",
      "frameworks": {},
      "id": "03.06.02",
      "statements": [],
      "title": "Incident Monitoring, Reporting, and Response Assistance"
    },
    {
      "coverage": {
        "documents": 0,
        "gap": true,
        "statements": 0
      },
      "family": "Incident Response",
      "frameworks": {},
      "id": "03.06.03",
      "statements": [],
      "title": "Incident Response Testing"
    },
    {
      "coverage": {
        "documents": 0,
        "gap": true,
        "statements": 0
      },
      "family": "Incident Response",
      "frameworks": {},
      "id": "03.06.04",
      "statements": [],
      "title": "Incident Response Training"
    },
    {
      "coverage": {
        "documents": 0,
        "gap": true,
        "statements": 0
      },
      "family": "Incident Response",
      "frameworks": {},
      "id": "03.06.05",
      "statements": [],
      "title": "Incident Response Plan"
    },
    {
      "coverage": {
        "documents": 0,
        "gap": true,
        "statements": 0
      },
      "family": "Maintenance",
      "frameworks": {},
      "id": "03.07.04",
      "statements": [],
      "title": "Maintenance Tools"
    },
    {
      "coverage": {
        "documents": 0,
        "gap": true,
        "statements": 0
      },
      "family": "Maintenance",
      "frameworks": {},
      "id": "03.07.05",
      "statements": [],
      "title": "Nonlocal Maintenance"
    },
    {
      "coverage": {
        "documents": 0,
        "gap": true,
        "statements": 0
      },
      "family": "Maintenance",
      "frameworks": {},
      "id": "03.07.06",
      "statements": [],
      "title": "Maintenance Personnel"
    },
    {
      "coverage": {
        "documents": 0,
        "gap": true,
        "statements": 0
      },
      "family": "Media Protection",
      "frameworks": {},
      "id": "03.08.01",
      "statements": [],
      "title": "Media Storage"
    },
    {
      "coverage": {
        "documents": 0,
        "gap": true,
        "statements": 0
      },
      "family": "Media Protection",
      "frameworks": {},
      "id": "03.08.02",
      "statements": [],
      "title": "Media Access"
    },
    {
      "coverage": {
        "documents": 0,
        "gap": true,
        "statements": 0
      },
      "family": "Media Protection",
      "frameworks": {},
      "id": "03.08.03",
      "statements": [],
      "title": "Media Sanitization"
    },
    {
      "coverage": {
        "documents": 0,
        "gap": true,
        "statements": 0
      },
      "family": "Media Protection",
      "frameworks": {},
      "id": "03.08.04",
      "statements": [],
      "title": "Media Marking"
    },
    {
      "coverage": {
        "documents": 0,
        "gap": true,
        "statements": 0
      },
      "family": "Media Protection",
      "frameworks": {},
      "id": "03.08.05",
      "statements": [],
      "title": "Media Transport"
    },
    {
      "coverage": {
        "documents": 0,
        "gap": true,
        "statements": 0
      },
      "family": "Media Protection",
      "frameworks": {},
      "id": "03.08.07",
      "statements": [],
      "title": "Media Use"
    },
    {
      "coverage": {
        "documents": 0,
        "gap": true,
        "statements": 0
      },
      "family": "Media Protection",
      "frameworks": {},
      "id": "03.08.09",
      "statements": [],
      "title": "System Backup – Cryptographic Protection"
    },
    {
      "coverage": {
        "documents": 0,
        "gap": true,
        "statements": 0
      },
      "family": "Personnel Security",
      "frameworks": {},
      "id": "03.09.01",
      "statements": [],
      "title": "Personnel Screening"
    },
    {
      "coverage": {
        "documents": 0,
        "gap": true,
        "statements": 0
      },
      "family": "Personnel Security",
      "frameworks": {},
      "id": "03.09.02",
      "statements": [],
      "title": "Personnel Termination and Transfer"
    },
    {
      "coverage": {
        "documents": 0,
        "gap": true,
        "statements": 0
      },
      "family": "Physical Protection",
      "frameworks": {},
      "id": "03.10.01",
      "statements": [],
      "title": "Physical Access Authorizations"
    },
    {
      "coverage": {
        "documents": 0,
        "gap": true,
        "statements": 0
      },
      "family": "Physical Protection",
      "frameworks": {},
      "id": "03.10.02",
      "statements": [],
      "title": "Monitoring Physical Access"
    },
    {
      "coverage": {
        "documents": 0,
        "gap": true,
        "statements": 0
      },
      "family": "Physical Protection",
      "frameworks": {},
      "id": "03.10.06",
      "statements": [],
      "title": "Alternate Work Site"
    },
    {
      "coverage": {
        "documents": 0,
        "gap": true,
        "statements": 0
      },
      "family": "Physical Protection",
      "frameworks": {},
      "id": "03.10.07",
      "statements": [],
      "title": "Physical Access Control"
    },
    {
      "coverage": {
        "documents": 0,
        "gap": true,
        "statements": 0
      },
      "family": "Physical Protection",
      "frameworks": {},
      "id": "03.10.08",
      "statements": [],
      "title": "Access Control for Transmission"
    },
    {
      "coverage": {
        "documents": 0,
        "gap": true,
        "statements": 0
      },
      "family": "Risk Assessment",
      "frameworks": {},
      "id": "03.11.01",
      "statements": [],
      "title": "Risk Assessment"
    },
    {
      "coverage": {
        "documents": 0,
        "gap": true,
        "statements": 0
      },
      "family": "Risk Assessment",
      "frameworks": {},
      "id": "03.11.02",
      "statements": [],
      "title": "Vulnerability Monitoring and Scanning"
    },
    {
      "coverage": {
        "documents": 0,
        "gap": true,
        "statements": 0
      },
      "family": "Risk Assessment",
      "frameworks": {},
      "id": "03.11.04",
      "statements": [],
      "title": "Risk Response"
    },
    {
      "coverage": {
        "documents": 0,
        "gap": true,
        "statements": 0
      },
      "family": "Security Assessment and Monitoring",
      "frameworks": {},
      "id": "03.12.01",
      "statements": [],
      "title": "Security Assessment"
    },
    {
      "coverage": {
        "documents": 0,
        "gap": true,
        "statements": 0
      },
      "family": "Security Assessment and Monitoring",
      "frameworks": {},
      "id": "03.12.02",
      "statements": [],
      "title": "Plan of Action and Milestones"
    },
    {
      "coverage": {
        "documents": 0,
        "gap": true,
        "statements": 0
      },
      "family": "Security Assessment and Monitoring",
      "frameworks": {},
      "id": "03.12.03",
      "statements": [],
      "title": "Continuous Monitoring"
    },
    {
      "coverage": {
        "documents": 0,
        "gap": true,
        "statements": 0
      },
      "family": "Security Assessment and Monitoring",
      "frameworks": {},
      "id": "03.12.05",
      "statements": [],
      "title": "Information Exchange"
    },
    {
      "coverage": {
        "documents": 0,
        "gap": true,
        "statements": 0
      },
      "family": "System and Communications Protection",
      "frameworks": {},
      "id": "03.13.01",
      "statements": [],
      "title": "Boundary Protection"
    },
    {
      "coverage": {
        "documents": 0,
        "gap": true,
        "statements": 0
      },
      "family": "System and Communications Protection",
      "frameworks": {},
      "id": "03.13.04",
      "statements": [],
      "title": "Information in Shared System Resources"
    },
    {
      "coverage": {
        "documents": 0,
        "gap": true,
        "statements": 0
      },
      "family": "System and Communications Protection",
      "frameworks": {},
      "id": "03.13.06",
      "statements": [],
      "title": "Network Communications – Deny by Default – Allow by Exception"
    },
    {
      "coverage": {
        "documents": 0,
        "gap": true,
        "statements": 0
      },
      "family": "System and Communications Protection",
      "frameworks": {},
      "id": "03.13.08",
      "statements": [],
      "title": "Transmission and Storage Confidentiality"
    },
    {
      "coverage": {
        "documents": 0,
        "gap": true,
        "statements": 0
      },
      "family": "System and Communications Protection",
      "frameworks": {},
      "id": "03.13.09",
      "statements": [],
      "title": "Network Disconnect"
    },
    {
      "coverage": {
        "documents": 0,
        "gap": true,
        "statements": 0
      },
      "family": "System and Communications Protection",
      "frameworks": {},
      "id": "03.13.10",
      "statements": [],
      "title": "Cryptographic Key Establishment and Management"
    },
    {
      "coverage": {
        "documents": 0,
        "gap": true,
        "statements": 0
      },
      "family": "System and Communications Protection",
      "frameworks": {},
      "id": "03.13.11",
      "statements": [],
      "title": "Cryptographic Protection"
    },
    {
      "coverage": {
        "documents": 0,
        "gap": true,
        "statements": 0
      },
      "family": "System and Communications Protection",
      "frameworks": {},
      "id": "03.13.12",
      "statements": [],
      "title": "Collaborative Computing Devices and Applications"
    },
    {
      "coverage": {
        "documents": 0,
        "gap": true,
        "statements": 0
      },
      "family": "System and Communications Protection",
      "frameworks": {},
      "id": "03.13.13",
      "statements": [],
      "title": "Mobile Code"
    },
    {
      "coverage": {
        "documents": 0,
        "gap": true,
        "statements": 0
      },
      "family": "System and Communications Protection",
      "frameworks": {},
      "id": "03.13.15",
      "statements": [],
      "title": "Session Authenticity"
    },
    {
      "coverage": {
        "documents": 0,
        "gap": true,
        "statements": 0
      },
      "family": "System and Information Integrity",
      "frameworks": {},
      "id": "03.14.01",
      "statements": [],
      "title": "Flaw Remediation"
    },
    {
      "coverage": {
        "documents": 0,
        "gap": true,
        "statements": 0
      },
      "family": "System and Information Integrity",
      "frameworks": {},
      "id": "03.14.02",
      "statements": [],
      "title": "Malicious Code Protection"
    },
    {
      "coverage": {
        "documents": 0,
        "gap": true,
        "statements": 0
      },
      "family": "System and Information Integrity",
      "frameworks": {},
      "id": "03.14.03",
      "statements": [],
      "title": "Security Alerts, Advisories, and Directives"
    },
    {
      "coverage": {
        "documents": 0,
        "gap": true,
        "statements": 0
      },
      "family": "System and Information Integrity",
      "frameworks": {},
      "id": "03.14.06",
      "statements": [],
      "title": "System Monitoring"
    },
    {
      "coverage": {
        "documents": 0,
        "gap": true,
        "statements": 0
      },
      "family": "System and Information Integrity",
      "frameworks": {},
      "id": "03.14.08",
      "statements": [],
      "title": "Information Management and Retention"
    },
    {
      "coverage": {
        "documents": 0,
        "gap": true,
        "statements": 0
      },
      "family": "Planning",
      "frameworks": {},
      "id": "03.15.01",
      "statements": [],
      "title": "Policy and Procedures"
    },
    {
      "coverage": {
        "documents": 0,
        "gap": true,
        "statements": 0
      },
      "family": "Planning",
      "frameworks": {},
      "id": "03.15.02",
      "statements": [],
      "title": "System Security Plan"
    },
    {
      "coverage": {
        "documents": 0,
        "gap": true,
        "statements": 0
      },
      "family": "Planning",
      "frameworks": {},
      "id": "03.15.03",
      "statements": [],
      "title": "Rules of Behavior"
    },
    {
      "coverage": {
        "documents": 0,
        "gap": true,
        "statements": 0
      },
      "family": "System and Services Acquisition",
      "frameworks": {},
      "id": "03.16.01",
      "statements": [],
      "title": "Security Engineering Principles"
    },
    {
      "coverage": {
        "documents": 0,
        "gap": true,
        "statements": 0
      },
      "family": "System and Services Acquisition",
      "frameworks": {},
      "id": "03.16.02",
      "statements": [],
      "title": "Unsupported System Components"
    },
    {
      "coverage": {
        "documents": 0,
        "gap": true,
        "statements": 0
      },
      "family": "System and Services Acquisition",
      "frameworks": {},
      "id": "03.16.03",
      "statements": [],
      "title": "External System Services"
    },
    {
      "coverage": {
        "documents": 0,
        "gap": true,
        "statements": 0
      },
      "family": "Supply Chain Risk Management",
      "frameworks": {},
      "id": "03.17.01",
      "statements": [],
      "title": "Supply Chain Risk Management Plan"
    },
    {
      "coverage": {
        "documents": 0,
        "gap": true,
        "statements": 0
      },
      "family": "Supply Chain Risk Management",
      "frameworks": {},
      "id": "03.17.02",
      "statements": [],
      "title": "Acquisition Strategies, Tools, and Methods"
    },
    {
      "coverage": {
        "documents": 0,
        "gap": true,
        "statements": 0
      },
      "family": "Supply Chain Risk Management",
      "frameworks": {},
      "id": "03.17.03",
      "statements": [],
      "title": "Supply Chain Requirements and Processes"
    }
  ],
  "generated": "2026-07-01",
  "profile": "NIST SP 800-171 Rev 3"
}