CJIS-1 | Information Exchange Agreements | 0 |
CJIS-10 | System and Information Integrity | 32 |
CJIS-14 | Physical Protection | 25 |
CJIS-15 | Mobile Devices | 2 |
CJIS-16 | Cloud Computing | 17 |
CJIS-17 | Risk Assessment | 153 |
CJIS-18 | Security Assessment and Authorization | 0 |
CJIS-19 | Supply Chain Risk Management | 122 |
CJIS-2 | Security Awareness Training | 28 |
CJIS-20 | System Acquisition | 0 |
CJIS-3 | Personnel Security | 14 |
CJIS-5.1 | Information Exchange Agreements | 0 |
CJIS-5.10 | System and Communications Protection | 0 |
CJIS-5.11 | Formal Audits | 0 |
CJIS-5.12 | Personnel Security | 0 |
CJIS-5.13 | Mobile Devices | 2 |
CJIS-5.2 | Security Awareness Training | 0 |
CJIS-5.3 | Incident Response | 0 |
CJIS-5.4 | Auditing and Accountability | 0 |
CJIS-5.5 | Access Control | 3 |
CJIS-5.6 | Identification and Authentication | 1 |
CJIS-5.7 | Configuration Management | 2 |
CJIS-5.8 | Media Protection | 0 |
CJIS-5.9 | Physical Protection | 0 |
CJIS-7 | Configuration Management | 56 |
CJIS-8 | Media Protection | 133 |
CJIS-9 | System and Communications Protection | 133 |
CJIS-AM-1 | Account Management | 0 |
CJIS-CM-1 | Cloud Service Provider Controls | 0 |
CJIS-IR-2 | Notification to CJIS Systems Officer | 0 |
CJIS-PE-2 | Physically Secure Location | 0 |
CJIS-SC-1 | Boundary Protection | 0 |
CJIS-SC-2 | Wireless Network Protections | 0 |
5.1 | 5.1 Policy Area 1: Information Exchange Agreements | 0 |
5.1.1 | 5.1.1 Information Exchange | 0 |
5.1.2 | 5.1.2 Monitoring, Review, and Delivery of Services | 0 |
5.1.2.1 | 5.1.2.1 Managing Changes to Service Providers | 0 |
5.20 | 5.20 Policy Area 20: Mobile Devices | 0 |
5.20.1 | 5.20.1 Wireless Communications Technologies | 0 |
5.20.1.1 | 5.20.1.1 802.11 Wireless Protocols | 0 |
5.20.1.2 | 5.20.1.2 Cellular Devices | 0 |
5.20.1.2.1 | 5.20.1.2.1 Cellular Service Abroad | 0 |
5.20.1.2.2 | 5.20.1.2.2 Voice Transmissions Over Cellular Devices | 0 |
5.20.1.3 | 5.20.1.3 Bluetooth | 0 |
5.20.1.4 | 5.20.1.4 Mobile Hotspots | 0 |
5.20.2 | 5.20.2 Mobile Device Management (MDM) | 0 |
5.20.3 | 5.20.3 Wireless Device Risk Mitigations | 0 |
5.20.4 | 5.20.4 System Integrity | 0 |
5.20.4.1 | 5.20.4.1 Patching/Updates | 0 |
5.20.4.2 | 5.20.4.2 Malicious Code Protection | 0 |
5.20.4.3 | 5.20.4.3 Personal Firewall | 0 |
5.20.5 | 5.20.5 Incident Response | 0 |
5.20.6 | 5.20.6 Access Control | 0 |
5.20.7 | 5.20.7 Identification and Authentication | 0 |
5.20.7.1 | 5.20.7.1 Local Device Authentication | 0 |
5.20.7.2 | 5.20.7.2 Advanced Authentication | 0 |
5.20.7.2.1 | 5.20.7.2.1 Compensating Controls | 0 |
5.20.7.3 | 5.20.7.3 Device Certificates | 0 |
AC | Access Control (AC) | 0 |
AC-1 | AC-1 Policy and Procedures | 0 |
AC-11 | AC-11 Device Lock | 0 |
AC-11(1) | AC-11(1) Device Lock | Pattern-Hiding Displays | 0 |
AC-12 | AC-12 Session Termination | 0 |
AC-14 | AC-14 Permitted Actions without Identification or Authentication | 0 |
AC-17 | AC-17 Remote Access | 0 |
AC-17(1) | AC-17(1) Remote Access | Monitoring and Control | 0 |
AC-17(2) | AC-17(2) Remote Access | Protection of Confidentiality and Integrity Using Encryption | 0 |
AC-17(3) | AC-17(3) Remote Access | Managed Access Control Points | 0 |
AC-17(4) | AC-17(4) Remote Access | Privileged Commands and Access | 0 |
AC-18 | AC-18 Wireless Access | 0 |
AC-18(1) | AC-18(1) Wireless Access | Authentication and Encryption | 0 |
AC-18(3) | AC-18(3) Wireless Access | Disable Wireless Networking | 0 |
AC-19 | AC-19 Access Control for Mobile Devices | 0 |
AC-19(5) | AC-19(5) Access Control for Mobile Devices | Full Device or Container-Based Encryption | 0 |
AC-2 | AC-2 Account Management | 0 |
AC-2(1) | AC-2(1) Account Management | Automated System Account Management | 0 |
AC-2(13) | AC-2(13) Account Management | Disable Accounts for High-Risk Individuals | 0 |
AC-2(2) | AC-2(2) Account Management | Automated Temporary and Emergency Account Management | 0 |
AC-2(3) | AC-2(3) Account Management | Disable Accounts | 0 |
AC-2(4) | AC-2(4) Account Management | Automated Audit Actions | 0 |
AC-2(5) | AC-2(5) Account Management | Inactivity Logout | 0 |
AC-20 | AC-20 Use of External Systems | 0 |
AC-20(1) | AC-20(1) Use of External Systems | Limits on Authorized Use | 0 |
AC-20(2) | AC-20(2) Use of External Systems | Portable Storage Devices - Restricted Use | 0 |
AC-21 | AC-21 Information Sharing | 0 |
AC-22 | AC-22 Publicly Accessible Content | 0 |
AC-3 | AC-3 Access Enforcement | 0 |
AC-3(14) | AC-3(14) Access Enforcement | Individual Access | 0 |
AC-4 | AC-4 Information Flow Enforcement | 0 |
AC-5 | AC-5 Separation of Duties | 0 |
AC-6 | AC-6 Least Privilege | 0 |
AC-6(1) | AC-6(1) Least Privilege | Authorize Access to Security Functions | 0 |
AC-6(10) | AC-6(10) Least Privilege | Prohibit Non-Privileged Users from Executing Privileged Functions | 0 |
AC-6(2) | AC-6(2) Least Privilege | Non-Privileged Access for Nonsecurity Functions | 0 |
AC-6(5) | AC-6(5) Least Privilege | Privileged Accounts | 0 |
AC-6(7) | AC-6(7) Least Privilege | Review of User Privileges | 0 |
AC-6(9) | AC-6(9) Least Privilege | Log Use of Privileged Functions | 0 |
AC-7 | AC-7 Unsuccessful Logon Attempts | 0 |
AC-8 | AC-8 System Use Notification | 0 |
AT | Awareness and Training (AT) | 0 |
AT-1 | AT-1 Policy and Procedures | 0 |
AT-2 | AT-2 Literacy Training and Awareness | 0 |
AT-2(2) | AT-2(2) Literacy Training and Awareness | Insider Threat | 0 |
AT-2(3) | AT-2(3) Literacy Training and Awareness | Social Engineering and Mining | 0 |
AT-3 | AT-3 Role-Based Training | 0 |
AT-3(5) | AT-3(5) Role-Based Training | Processing Personally Identifiable Information | 0 |
AT-4 | AT-4 Training Records | 0 |
AU | Audit and Accountability (AU) | 0 |
AU-1 | AU-1 Policy and Procedures | 0 |
AU-11 | AU-11 Audit Record Retention | 0 |
AU-12 | AU-12 Audit Record Generation | 0 |
AU-2 | AU-2 Event Logging | 0 |
AU-3 | AU-3 Content of Audit Records | 0 |
AU-3(1) | AU-3(1) Content of Audit Records | Additional Audit Information | 0 |
AU-3(3) | AU-3(3) Content of Audit Records | Limit Personally Identifiable Information Elements | 0 |
AU-4 | AU-4 Audit Log Storage Capacity | 0 |
AU-5 | AU-5 Response to Audit Logging Process Failures | 0 |
AU-6 | AU-6 Audit Record Review, Analysis, and Reporting | 0 |
AU-6(1) | AU-6(1) Audit Record Review, Analysis, and Reporting | Automated Process Integration | 0 |
AU-6(3) | AU-6(3) Audit Record Review, Analysis, and Reporting | Correlate Audit Record Repositories | 0 |
AU-7 | AU-7 Audit Record Reduction and Report Generation | 0 |
AU-7(1) | AU-7(1) Audit Record Reduction and Report Generation | Automatic Processing | 0 |
AU-8 | AU-8 Time Stamps | 0 |
AU-9 | AU-9 Protection of Audit Information | 0 |
AU-9(4) | AU-9(4) Protection of Audit Information | Access by Subset of Privileged Users | 0 |
CA | Assessment, Authorization, and Monitoring (CA) | 0 |
CA-1 | CA-1 Policy and Procedures | 0 |
CA-2 | CA-2 Control Assessments | 0 |
CA-2(1) | CA-2(1) Control Assessments | Independent Assessors | 0 |
CA-3 | CA-3 Information Exchange | 0 |
CA-5 | CA-5 Plan of Action and Milestones | 0 |
CA-6 | CA-6 Authorization | 0 |
CA-7 | CA-7 Continuous Monitoring | 0 |
CA-7(1) | CA-7(1) Continuous Monitoring | Independent Assessment | 0 |
CA-7(4) | CA-7(4) Continuous Monitoring | Risk Monitoring | 0 |
CA-9 | CA-9 Internal System Connections | 0 |
CJI | Section 4: criminal justice information, CHRI, NCIC files, and personally identifiable information | 0 |
CM | Configuration Management (CM) | 0 |
CM-1 | CM-1 Policy and Procedures | 0 |
CM-10 | CM-10 Software Usage Restrictions | 0 |
CM-11 | CM-11 User-Installed Software | 0 |
CM-12 | CM-12 Information Location | 0 |
CM-12(1) | CM-12(1) Information Location | Automated Tools to Support Information Location | 0 |
CM-2 | CM-2 Baseline Configuration | 0 |
CM-2(2) | CM-2(2) Baseline Configuration | Automation Support for Accuracy and Currency | 0 |
CM-2(3) | CM-2(3) Baseline Configuration | Retention of Previous Configurations | 0 |
CM-2(7) | CM-2(7) Baseline Configuration | Configure Systems and Components for High-Risk Areas | 0 |
CM-3 | CM-3 Configuration Change Control | 0 |
CM-3(2) | CM-3(2) Configuration Change Control | Testing, Validation, and Documentation of Changes | 0 |
CM-3(4) | CM-3(4) Configuration Change Control | Security and Privacy Representatives | 0 |
CM-4 | CM-4 Impact Analyses | 0 |
CM-4(2) | CM-4(2) Impact Analyses | Verification of Controls | 0 |
CM-5 | CM-5 Access Restrictions for Change | 0 |
CM-6 | CM-6 Configuration Settings | 0 |
CM-7 | CM-7 Least Functionality | 0 |
CM-7(1) | CM-7(1) Least Functionality | Periodic Review | 0 |
CM-7(2) | CM-7(2) Least Functionality | Prevent Program Execution | 0 |
CM-7(5) | CM-7(5) Least Functionality | Authorized Software - Allow-By-Exception | 0 |
CM-8 | CM-8 System Component Inventory | 0 |
CM-8(1) | CM-8(1) System Component Inventory | Updates During Installation and Removal | 0 |
CM-8(3) | CM-8(3) System Component Inventory | Automated Unauthorized Component Detection | 0 |
CM-9 | CM-9 Configuration Management Plan | 0 |
CP | Contingency Planning (CP) | 0 |
CP-1 | CP-1 Policy and Procedures | 0 |
CP-10 | CP-10 System Recovery and Reconstitution | 0 |
CP-10(2) | CP-10(2) System Recovery and Reconstitution | Transaction Recovery | 0 |
CP-2 | CP-2 Contingency Plan | 0 |
CP-2(1) | CP-2(1) Contingency Plan | Coordinate with Related Plans | 0 |
CP-2(3) | CP-2(3) Contingency Plan | Resume Mission and Business Functions | 0 |
CP-2(8) | CP-2(8) Contingency Plan | Identify Critical Assets | 0 |
CP-3 | CP-3 Contingency Training | 0 |
CP-4 | CP-4 Contingency Plan Testing | 0 |
CP-4(1) | CP-4(1) Contingency Plan Testing | Coordinate with Related Plans | 0 |
CP-6 | CP-6 Alternate Storage Site | 0 |
CP-6(1) | CP-6(1) Alternate Storage Site | Separation from Primary Site | 0 |
CP-6(3) | CP-6(3) Alternate Storage Site | Accessibility | 0 |
CP-7 | CP-7 Alternate Processing Site | 0 |
CP-7(1) | CP-7(1) Alternate Processing Site | Separation from Primary Site | 0 |
CP-7(2) | CP-7(2) Alternate Processing Site | Accessibility | 0 |
CP-7(3) | CP-7(3) Alternate Processing Site | Priority of Service | 0 |
CP-8 | CP-8 Telecommunications Services | 0 |
CP-8(1) | CP-8(1) Telecommunications Services | Priority of Service Provisions | 0 |
CP-8(2) | CP-8(2) Telecommunications Services | Single Points of Failure | 0 |
CP-9 | CP-9 System Backup | 0 |
CP-9(1) | CP-9(1) System Backup | Testing for Reliability and Integrity | 0 |
CP-9(8) | CP-9(8) System Backup | Cryptographic Protection | 0 |
IA | Identification and Authentication (IA) | 0 |
IA-0 | IA-0 Use of Originating Agency Identifiers in Transactions and Information Exchanges | 0 |
IA-1 | IA-1 Policy and Procedures | 0 |
IA-11 | IA-11 Re-Authentication | 0 |
IA-12 | IA-12 Identity Proofing | 0 |
IA-12(2) | IA-12(2) Identity Proofing | Identity Evidence | 0 |
IA-12(3) | IA-12(3) Identity Proofing | Identity Evidence Validation and Verification | 0 |
IA-12(5) | IA-12(5) Identity Proofing | Address Confirmation | 0 |
IA-2 | IA-2 Identification and Authentication (Organizational Users) | 0 |
IA-2(1) | IA-2(1) Identification and Authentication (Organizational Users) | Multi- Factor Authentication to Privileged Accounts | 0 |
IA-2(12) | IA-2(12) Identification and Authentication (Organizational Users) | Acceptance of PIV Credentials | 0 |
IA-2(2) | IA-2(2) Identification and Authentication (Organizational Users) | Multi- Factor Authentication to Non-Privileged Accounts | 0 |
IA-2(8) | IA-2(8) Identification and Authentication (Organizational Users) | Access to Accounts - Replay Resistant | 0 |
IA-3 | IA-3 Device Identification and Authentication | 0 |
IA-4 | IA-4 Identifier Management | 0 |
IA-4(4) | IA-4(4) Identifier Management | Identify User Status | 0 |
IA-5 | IA-5 Authenticator Management | 0 |
IA-5(1) | IA-5(1) Authenticator Management | Authenticator Types | 0 |
IA-5(2) | IA-5(2) Authenticator Management | Public Key Based Authentication | 0 |
IA-5(6) | IA-5(6) Authenticator Management | Protection of Authenticators | 0 |
IA-6 | IA-6 Authentication Feedback | 0 |
IA-7 | IA-7 Cryptographic Module Authentication | 0 |
IA-8 | IA-8 Identification and Authentication (Non-Organizational Users) | 0 |
IA-8(1) | IA-8(1) Identification and Authentication (Non-Organizational Users) | Acceptance of PIV Credentials from Other Agencies | 0 |
IA-8(2) | IA-8(2) Identification and Authentication (Non-Organizational Users) | Acceptance of External Authenticators | 0 |
IA-8(4) | IA-8(4) Identification and Authentication (Non-Organizational Users) | Use of Defined Profiles | 0 |
IR | Incident Response (IR) | 0 |
IR-1 | IR-1 Policy and Procedures | 0 |
IR-2 | IR-2 Incident Response Training | 0 |
IR-2(3) | IR-2(3) Incident Response Training | Breach | 0 |
IR-3 | IR-3 Incident Response Testing | 0 |
IR-3(2) | IR-3(2) Incident Response Testing | Coordination with Related Plans | 0 |
IR-4 | IR-4 Incident Handling | 0 |
IR-4(1) | IR-4(1) Incident Handling | Automated Incident Handling Processes | 0 |
IR-5 | IR-5 Incident Monitoring | 0 |
IR-6 | IR-6 Incident Reporting | 0 |
IR-6(1) | IR-6(1) Incident Reporting | Automated Reporting | 0 |
IR-6(3) | IR-6(3) Incident Reporting | Supply Chain Coordination | 0 |
IR-7 | IR-7 Incident Response Assistance | 0 |
IR-7(1) | IR-7(1) Incident Response Assistance | Automation Support for Availability of Information and Support | 0 |
IR-8 | IR-8 Incident Response Plan | 0 |
IR-8(1) | IR-8(1) Incident Response Plan | Breaches | 0 |
MA | Maintenance (MA) | 0 |
MA-1 | MA-1 Policy and Procedures | 0 |
MA-2 | MA-2 Controlled Maintenance | 0 |
MA-3 | MA-3 Maintenance Tools | 0 |
MA-3(1) | MA-3(1) Maintenance Tools | Inspect Tools | 0 |
MA-3(2) | MA-3(2) Maintenance Tools | Inspect Media | 0 |
MA-3(3) | MA-3(3) Maintenance Tools | Prevent Unauthorized Removal | 0 |
MA-4 | MA-4 Nonlocal Maintenance | 0 |
MA-5 | MA-5 Maintenance Personnel | 0 |
MA-6 | MA-6 Timely Maintenance | 0 |
MP | Media Protection (MP) | 0 |
MP-1 | MP-1 Policy and Procedures | 0 |
MP-2 | MP-2 Media Access | 0 |
MP-3 | MP-3 Media Marking | 0 |
MP-4 | MP-4 Media Storage | 0 |
MP-5 | MP-5 Media Transport | 0 |
MP-6 | MP-6 Media Sanitization | 0 |
MP-7 | MP-7 Media Use | 0 |
PA1 | Policy Area 1: Information Exchange Agreements | 0 |
PA20 | Policy Area 20: Mobile Devices | 0 |
PE | Physical and Environmental Protection (PE) | 0 |
PE-1 | PE-1 Policy and Procedures | 0 |
PE-10 | PE-10 Emergency Shutof | 0 |
PE-11 | PE-11 Emergency Power | 0 |
PE-12 | PE-12 Emergency Lighting | 0 |
PE-13 | PE-13 Fire Protection | 0 |
PE-13(1) | PE-13(1) Fire Protection | Detection Systems - Automatic Activation and Notification | 0 |
PE-14 | PE-14 Environmental Controls | 0 |
PE-15 | PE-15 Water Damage Protection | 0 |
PE-16 | PE-16 Delivery and Removal | 0 |
PE-17 | PE-17 Alternate Work Site | 0 |
PE-2 | PE-2 Physical Access Authorizations | 0 |
PE-3 | PE-3 Physical Access Control | 0 |
PE-4 | PE-4 Access Control for Transmission | 0 |
PE-5 | PE-5 Access Control for Output Devices | 0 |
PE-6 | PE-6 Monitoring Physical Access | 0 |
PE-6(1) | PE-6(1) Monitoring Physical Access | Intrusion Alarms and Surveillance Equipment | 0 |
PE-8 | PE-8 Visitor Access Records | 0 |
PE-8(3) | PE-8(3) Visitor Access Records | Limit Personally Identifiable Information Elements | 0 |
PE-9 | PE-9 Power Equipment and Cabling | 0 |
PL | Planning (PL) | 0 |
PL-1 | PL-1 Policy and Procedures | 0 |
PL-10 | PL-10 Baseline Selection | 0 |
PL-11 | PL-11 Baseline Tailoring | 0 |
PL-2 | PL-2 System Security and Privacy Plans | 0 |
PL-4 | PL-4 Rules of Behavior | 0 |
PL-4(1) | PL-4(1) Rules of Behavior | Social Media and External Site/Application Usage Restrictions | 0 |
PL-8 | PL-8 Security and Privacy Architectures | 0 |
PL-9 | PL-9 Central Management | 0 |
POLICY | The CJIS Security Policy: what it is, its versions, and what is held | 0 |
PRIORITIES | The priority and implementation markings, the sanction timeline and the appendices | 0 |
PS | Personnel Security (PS) | 0 |
PS-1 | PS-1 Policy and Procedures | 0 |
PS-2 | PS-2 Position Risk Designation | 0 |
PS-3 | PS-3 Personnel Screening | 0 |
PS-4 | PS-4 Personnel Termination | 0 |
PS-5 | PS-5 Personnel Transfer | 0 |
PS-6 | PS-6 Access Agreements | 0 |
PS-7 | PS-7 External Personnel Security | 0 |
PS-8 | PS-8 Personnel Sanctions | 0 |
PS-9 | PS-9 Position Descriptions | 0 |
RA | Risk Assessment (RA) | 0 |
RA-1 | RA-1 Policy and Procedures | 0 |
RA-2 | RA-2 Security Categorization | 0 |
RA-3 | RA-3 Risk Assessment | 0 |
RA-5 | RA-5 Vulnerability Monitoring and Scanning | 0 |
RA-5(11) | RA-5(11) Vulnerability Monitoring and Scanning | Public Disclosure Program | 0 |
RA-5(2) | RA-5(2) Vulnerability Monitoring and Scanning | Update Vulnerabilities to Be Scanned | 0 |
RA-5(5) | RA-5(5) Vulnerability Monitoring and Scanning | Privileged Access | 0 |
RA-7 | RA-7 Risk Response | 0 |
RA-9 | RA-9 Criticality Analysis | 0 |
ROLES | Sections 1 to 3: purpose, scope, approach and the roles and responsibilities | 0 |
SA | System and Services Acquisition (SA) | 0 |
SA-1 | SA-1 Policy and Procedures | 0 |
SA-10 | SA-10 Developer Configuration Management | 0 |
SA-11 | SA-11 Developer Testing and Evaluation | 0 |
SA-15 | SA-15 Development Process, Standards, and Tools | 0 |
SA-15(3) | SA-15(3) Development Process, Standards, and Tools | Criticality Analysis | 0 |
SA-2 | SA-2 Allocation of Resources | 0 |
SA-22 | SA-22 Unsupported System Components | 0 |
SA-3 | SA-3 System Development Life Cycle | 0 |
SA-4 | SA-4 Acquisition Process | 0 |
SA-4(1) | SA-4(1) Acquisition Process | Functional Properties of Controls | 0 |
SA-4(10) | SA-4(10) Acquisition Process | Use of Approved PIV Products | 0 |
SA-4(2) | SA-4(2) Acquisition Process | Design and Implementation Information for Controls | 0 |
SA-4(9) | SA-4(9) Acquisition Process | Functions, Ports, Protocols, and Services in Use | 0 |
SA-5 | SA-5 System Documentation | 0 |
SA-8 | SA-8 Security and Privacy Engineering Principles | 0 |
SA-8(33) | SA-8(33) Security and Privacy Engineering Principles | Minimization | 0 |
SA-9 | SA-9 External System Services | 0 |
SA-9(2) | SA-9(2) External System Services | Identification of Functions, Ports, Protocols, and Services | 0 |
SC | System and Communications Protection (SC) | 0 |
SC-1 | SC-1 Policy and Procedures | 0 |
SC-10 | SC-10 Network Disconnect | 0 |
SC-12 | SC-12 Cryptographic Key Establishment and Management | 0 |
SC-13 | SC-13 Cryptographic Protection | 0 |
SC-15 | SC-15 Collaborative Computing Devices and Applications | 0 |
SC-17 | SC-17 Public Key Infrastructure Certificates | 0 |
SC-18 | SC-18 Mobile Code | 0 |
SC-2 | SC-2 Separation of System and User Functionality | 0 |
SC-20 | SC-20 Secure Name/Address Resolution Service (Authoritative Source) | 0 |
SC-21 | SC-21 Secure Name/Address Resolution Service (Recursive or Caching Resolver) | 0 |
SC-22 | SC-22 Architecture and Provisioning for Name/Address Resolution Service | 0 |
SC-23 | SC-23 Session Authenticity | 0 |
SC-28 | SC-28 Protection of Information at Rest | 0 |
SC-28(1) | SC-28(1) Protection of Information at Rest | Cryptographic Protection | 0 |
SC-39 | SC-39 Process Isolation | 0 |
SC-4 | SC-4 Information in Shared System Resources | 0 |
SC-5 | SC-5 Denial-Of-Service Protection | 0 |
SC-7 | SC-7 Boundary Protection | 0 |
SC-7(24) | SC-7(24) Boundary Protection | Personally Identifiable Information | 0 |
SC-7(3) | SC-7(3) Boundary Protection | Access Points | 0 |
SC-7(4) | SC-7(4) Boundary Protection | External Telecommunications Services | 0 |
SC-7(5) | SC-7(5) Boundary Protection | Deny by Default - Allow by Exception | 0 |
SC-7(7) | SC-7(7) Boundary Protection | Split Tunneling for Remote Devices | 0 |
SC-7(8) | SC-7(8) Boundary Protection | Route Traffic to Authenticated Proxy Servers | 0 |
SC-8 | SC-8 Transmission Confidentiality and Integrity | 0 |
SC-8(1) | SC-8(1) Transmission Confidentiality and Integrity | Cryptographic Protection | 0 |
SI | System and Information Integrity (SI) | 0 |
SI-1 | SI-1 Policy and Procedures | 0 |
SI-10 | SI-10 Information Input Validation | 0 |
SI-11 | SI-11 Error Handling | 0 |
SI-12 | SI-12 Information Management and Retention | 0 |
SI-12(1) | SI-12(1) Information Management and Retention | Limit Personally Identifiable Information Elements | 0 |
SI-12(2) | SI-12(2) Information Management and Retention | Minimize Personally Identifiable Information in Testing, Training, and Research | 0 |
SI-12(3) | SI-12(3) Information Management and Retention | Information Disposal | 0 |
SI-16 | SI-16 Memory Protection | 0 |
SI-2 | SI-2 Flaw Remediation | 0 |
SI-2(2) | SI-2(2) Flaw Remediation | Automated Flaw Remediation Status | 0 |
SI-3 | SI-3 Malicious Code Protection | 0 |
SI-4 | SI-4 System Monitoring | 0 |
SI-4(2) | SI-4(2) System Monitoring | Automated Tools and Mechanisms for Real-Time Analysis | 0 |
SI-4(4) | SI-4(4) System Monitoring | Inbound and Outbound Communications Traffic | 0 |
SI-4(5) | SI-4(5) System Monitoring | System-Generated Alerts | 0 |
SI-5 | SI-5 Security Alerts, Advisories, and Directives | 0 |
SI-7 | SI-7 Software, Firmware, and Information Integrity | 0 |
SI-7(1) | SI-7(1) Software, Firmware, and Information Integrity | Integrity Checks | 0 |
SI-7(7) | SI-7(7) Software, Firmware, and Information Integrity | Integration of Detection and Response | 0 |
SI-8 | SI-8 Spam Protection | 0 |
SI-8(2) | SI-8(2) Spam Protection | Automatic Updates | 0 |
SR | Supply Chain Risk Management (SR) | 0 |
SR-1 | SR-1 Policy and Procedures | 0 |
SR-10 | SR-10 Inspection of Systems or Components | 0 |
SR-12 | SR-12 Component Disposal | 0 |
SR-2 | SR-2 Supply Chain Risk Management Plan | 0 |
SR-2(1) | SR-2(1) Supply Chain Risk Management Plan | Establish SCRM Team | 0 |
SR-5 | SR-5 Acquisition Strategies, Tools, and Methods | 0 |
SR-8 | SR-8 Notification Agreements | 0 |