AC.L2-3.1.1 | Authorized Access Control | 32 |
AC.L2-3.1.10 | Session Lock | 16 |
AC.L2-3.1.11 | Session Termination | 16 |
AC.L2-3.1.12 | Control Remote Access | 25 |
AC.L2-3.1.13 | Remote Access Confidentiality | 20 |
AC.L2-3.1.14 | Remote Access Routing | 19 |
AC.L2-3.1.15 | Privileged Remote Access | 21 |
AC.L2-3.1.16 | Wireless Access Authorization | 15 |
AC.L2-3.1.17 | Wireless Access Protection | 13 |
AC.L2-3.1.18 | Mobile Device Connection | 19 |
AC.L2-3.1.19 | Encrypt CUI on Mobile | 17 |
AC.L2-3.1.2 | Transaction & Function Control | 25 |
AC.L2-3.1.20 | External Connections | 25 |
AC.L2-3.1.21 | Portable Storage Use | 19 |
AC.L2-3.1.22 | Control Public Information | 20 |
AC.L2-3.1.3 | Control CUI Flow | 24 |
AC.L2-3.1.4 | Separation of Duties | 24 |
AC.L2-3.1.5 | Least Privilege | 28 |
AC.L2-3.1.6 | Non-Privileged Account Use | 23 |
AC.L2-3.1.7 | Privileged Functions | 23 |
AC.L2-3.1.8 | Unsuccessful Logon Attempts | 18 |
AC.L2-3.1.9 | Privacy & Security Notices | 12 |
AT.L2-3.2.1 | Role-Based Risk Awareness | 34 |
AT.L2-3.2.2 | Role-Based Training | 32 |
AT.L2-3.2.3 | Insider Threat Awareness | 21 |
AU.L2-3.3.1 | System Auditing | 28 |
AU.L2-3.3.2 | User Accountability | 25 |
AU.L2-3.3.3 | Event Review | 24 |
AU.L2-3.3.4 | Audit Failure Alerting | 17 |
AU.L2-3.3.5 | Audit Correlation | 25 |
AU.L2-3.3.6 | Reduction & Reporting | 19 |
AU.L2-3.3.7 | Time Stamps & Synchronization | 16 |
AU.L2-3.3.8 | Audit Protection | 21 |
AU.L2-3.3.9 | Audit Management | 21 |
CA.L2-3.12.1 | Security Control Assessment | 35 |
CA.L2-3.12.2 | Plan of Action | 31 |
CA.L2-3.12.3 | Security Control Monitoring | 38 |
CA.L2-3.12.4 | System Security Plan | 32 |
CM.L2-3.4.1 | System Baselining | 31 |
CM.L2-3.4.2 | Security Configuration Enforcement | 27 |
CM.L2-3.4.3 | System Change Management | 24 |
CM.L2-3.4.4 | Security Impact Analysis | 25 |
CM.L2-3.4.5 | Access Restrictions for Change | 22 |
CM.L2-3.4.6 | Least Functionality | 24 |
CM.L2-3.4.7 | Nonessential Functionality | 22 |
CM.L2-3.4.8 | Application Execution Policy | 23 |
CM.L2-3.4.9 | User-Installed Software | 28 |
IA.L2-3.5.1 | Identification | 32 |
IA.L2-3.5.10 | Cryptographically-Protected Passwords | 20 |
IA.L2-3.5.11 | Obscure Feedback | 13 |
IA.L2-3.5.2 | Authentication | 29 |
IA.L2-3.5.3 | Multifactor Authentication | 24 |
IA.L2-3.5.4 | Replay-Resistant Authentication | 18 |
IA.L2-3.5.5 | Identifier Reuse | 18 |
IA.L2-3.5.6 | Identifier Handling | 23 |
IA.L2-3.5.7 | Password Complexity | 21 |
IA.L2-3.5.8 | Password Reuse | 16 |
IA.L2-3.5.9 | Temporary Passwords | 15 |
IR.L2-3.6.1 | Incident Handling | 32 |
IR.L2-3.6.2 | Incident Reporting | 35 |
IR.L2-3.6.3 | Incident Response Testing | 29 |
MA.L2-3.7.1 | Perform Maintenance | 18 |
MA.L2-3.7.2 | System Maintenance Control | 18 |
MA.L2-3.7.3 | Equipment Sanitization | 21 |
MA.L2-3.7.4 | Media Inspection | 16 |
MA.L2-3.7.5 | Nonlocal Maintenance | 21 |
MA.L2-3.7.6 | Maintenance Personnel | 17 |
MP.L2-3.8.1 | Media Protection | 25 |
MP.L2-3.8.2 | Media Access | 20 |
MP.L2-3.8.3 | Media Disposal | 27 |
MP.L2-3.8.4 | Media Markings | 18 |
MP.L2-3.8.5 | Media Accountability | 19 |
MP.L2-3.8.6 | Portable Storage Encryption | 18 |
MP.L2-3.8.7 | Removable Media | 19 |
MP.L2-3.8.8 | Shared Media | 15 |
MP.L2-3.8.9 | Protect Backups | 26 |
PE.L2-3.10.1 | Limit Physical Access | 23 |
PE.L2-3.10.2 | Monitor Facility | 22 |
PE.L2-3.10.3 | Escort Visitors | 21 |
PE.L2-3.10.4 | Physical Access Logs | 20 |
PE.L2-3.10.5 | Manage Physical Access | 22 |
PE.L2-3.10.6 | Alternative Work Sites | 19 |
PS.L2-3.9.1 | Screen Individuals | 26 |
PS.L2-3.9.2 | Personnel Actions | 27 |
RA.L2-3.11.1 | Risk Assessments | 33 |
RA.L2-3.11.2 | Vulnerability Scan | 30 |
RA.L2-3.11.3 | Vulnerability Remediation | 34 |
SC.L2-3.13.1 | Boundary Protection | 26 |
SC.L2-3.13.10 | Key Management | 21 |
SC.L2-3.13.11 | CUI Encryption | 23 |
SC.L2-3.13.12 | Collaborative Device Control | 12 |
SC.L2-3.13.13 | Mobile Code | 18 |
SC.L2-3.13.14 | Voice over Internet Protocol | 3 |
SC.L2-3.13.15 | Communications Authenticity | 23 |
SC.L2-3.13.16 | Data at Rest | 24 |
SC.L2-3.13.2 | Security Engineering | 24 |
SC.L2-3.13.3 | Role Separation | 21 |
SC.L2-3.13.4 | Shared Resource Control | 16 |
SC.L2-3.13.5 | Public-Access System Separation | 25 |
SC.L2-3.13.6 | Network Communication by Exception | 20 |
SC.L2-3.13.7 | Split Tunneling | 9 |
SC.L2-3.13.8 | Data in Transit | 26 |
SC.L2-3.13.9 | Connections Termination | 14 |
SI.L2-3.14.1 | Flaw Remediation | 33 |
SI.L2-3.14.2 | Malicious Code Protection | 30 |
SI.L2-3.14.3 | Security Alerts & Advisories | 27 |
SI.L2-3.14.4 | Update Malicious Code Protection | 26 |
SI.L2-3.14.5 | System & File Scanning | 24 |
SI.L2-3.14.6 | Monitor Communications for Attacks | 26 |
SI.L2-3.14.7 | Identify Unauthorized Use | 24 |