AC-1 | Policy and Procedures | 20 |
AC-10 | Concurrent Session Control | 0 |
AC-11 | Device Lock | 12 |
AC-11(1) | Device Lock | Pattern-hiding Displays. Conceal, via the device lock, information previously visible on the display with a publicly viewable image | 8 |
AC-12 | Session Termination | 10 |
AC-14 | Permitted Actions Without Identification or Authentication | 3 |
AC-17 | Remote Access | 20 |
AC-17(1) | Monitoring and Control | 13 |
AC-17(2) | Protection of Confidentiality and Integrity Using Encryption | 16 |
AC-17(3) | Managed Access Control Points | 16 |
AC-17(4) | Privileged Commands and Access | 12 |
AC-18 | Wireless Access | 9 |
AC-18(1) | Authentication and Encryption | 10 |
AC-18(3) | Wireless Access | Disable Wireless Networking. Disable, when not intended for use, wireless networking capabilities embedded within system components prior to issuance and deployme | 7 |
AC-18(4) | Restrict Configurations by Users | 0 |
AC-18(5) | Antennas and Transmission Power Levels | 0 |
AC-19 | Access Control for Mobile Devices | 16 |
AC-19(5) | Full Device or Container-Based Encryption | 14 |
AC-2 | Account Management | 95 |
AC-2(1) | Automated System Account Management | 9 |
AC-2(11) | Usage Conditions | 0 |
AC-2(12) | Account Monitoring for Atypical Usage | 15 |
AC-2(13) | Disable Accounts for High-Risk Individuals | 13 |
AC-2(2) | Automated Temporary and Emergency Account Management | 10 |
AC-2(3) | Disable Accounts | 19 |
AC-2(4) | Automated Audit Actions | 12 |
AC-2(5) | Inactivity Logout | 12 |
AC-2(7) | Privileged User Accounts | 16 |
AC-2(9) | Restrictions on Use of Shared and Group Accounts | 15 |
AC-20 | Use of External Systems | 17 |
AC-20(1) | Limits on Authorized Use | 14 |
AC-20(2) | Portable Storage Devices Restricted Use | 13 |
AC-21 | Information Sharing | 14 |
AC-22 | Publicly Accessible Content | 11 |
AC-3 | Access Enforcement | 36 |
AC-4 | Information Flow Enforcement | 22 |
AC-4(21) | Physical or Logical Separation of Information Flows | 15 |
AC-4(4) | Flow Control of Encrypted Information | 0 |
AC-5 | Separation of Duties | 19 |
AC-6 | Least Privilege | 26 |
AC-6(1) | Authorize Access to Security Functions | 14 |
AC-6(10) | Prohibit Non-Privileged Users from Executing Privileged Functions | 15 |
AC-6(2) | Non-Privileged Access for Nonsecurity Functions | 15 |
AC-6(3) | Network Access to Privileged Commands | 0 |
AC-6(5) | Privileged Accounts | 16 |
AC-6(7) | Review of User Privileges | 20 |
AC-6(8) | Privilege Levels for Code Execution | 0 |
AC-6(9) | Log Use of Privileged Functions | 14 |
AC-7 | Unsuccessful Logon Attempts | 14 |
AC-8 | System Use Notification | 5 |
AT-1 | Policy and Procedures | 17 |
AT-2 | Literacy Training and Awareness | 31 |
AT-2(2) | Insider Threat | 13 |
AT-2(3) | Social Engineering and Mining | 13 |
AT-3 | Role-Based Training | 29 |
AT-4 | Training Records | 19 |
AU-1 | Policy and Procedures | 15 |
AU-10 | Non-Repudiation | 0 |
AU-11 | Audit Record Retention | 16 |
AU-12 | Audit Record Generation | 23 |
AU-12(1) | System-wide and Time-correlated Audit Trail | 0 |
AU-12(3) | Changes by Authorized Individuals | 0 |
AU-2 | Event Logging | 23 |
AU-3 | Content of Audit Records | 19 |
AU-3(1) | Additional Audit Information | 12 |
AU-4 | Audit Log Storage Capacity | 12 |
AU-5 | Response to Audit Logging Process Failures | 11 |
AU-5(1) | Storage Capacity Warning | 0 |
AU-5(2) | Real-Time Alerts | 0 |
AU-6 | Audit Record Review, Analysis, and Reporting | 27 |
AU-6(1) | Automated Process Integration | 18 |
AU-6(3) | Correlate Audit Record Repositories | 18 |
AU-6(4) | Central Review and Analysis | 0 |
AU-6(5) | Integrated Analysis of Audit Records | 0 |
AU-6(6) | Correlation with Physical Monitoring | 0 |
AU-6(7) | Permitted Actions | 0 |
AU-7 | Audit Record Reduction and Report Generation | 12 |
AU-7(1) | Automatic Processing | 12 |
AU-8 | Time Stamps | 12 |
AU-9 | Protection of Audit Information | 18 |
AU-9(2) | Store on Separate Physical Systems or Components | 0 |
AU-9(3) | Cryptographic Protection | 0 |
AU-9(4) | Access by Subset of Privileged Users | 13 |
CA-1 | Policy and Procedures | 18 |
CA-2 | Control Assessments | 33 |
CA-2(1) | Independent Assessors | 23 |
CA-2(2) | Specialized Assessments | 0 |
CA-2(3) | Control Assessments | Leveraging Results from External Organizations. Leverage the results of control assessments performed by [Assignment: organization-defined external organizati | 11 |
CA-3 | Information Exchange | 18 |
CA-3(6) | Information Exchange | Transfer Authorizations | 0 |
CA-5 | Plan of Action and Milestones | 30 |
CA-6 | Authorization | 19 |
CA-7 | Continuous Monitoring | 33 |
CA-7(1) | Independent Assessment | 13 |
CA-7(4) | Continuous Monitoring | Risk Monitoring. Ensure risk monitoring is an integral part of the continuous monitoring strategy that includes the following: (a) Effectiveness monitoring; | 17 |
CA-8 | Penetration Testing | 65 |
CA-8(1) | Penetration Testing | Independent Penetration Testing Agent or Team. Employ an independent penetration testing agent or team to perform penetration testing on the system or system | 14 |
CA-8(2) | Penetration Testing | Red Team Exercises. Employ the following red-team exercises to simulate attempts by adversaries to compromise organizational systems in accordance with applic | 12 |
CA-9 | Internal System Connections | 163 |
CM-1 | Policy and Procedures | 13 |
CM-10 | Software Usage Restrictions | 17 |
CM-11 | User-Installed Software | 22 |
CM-12 | Information Location. a. Identify and document the location of [Assignment: organization-defined information] and the specific system components on which the information is process | 20 |
CM-12(1) | Information Location | Automated Tools to Support Information Location. Use automated tools to identify [Assignment: organization-defined information by information type] on [Assig | 11 |
CM-14 | Signed Components | 0 |
CM-2 | Baseline Configuration | 19 |
CM-2(2) | Automation Support for Accuracy and Currency | 12 |
CM-2(3) | Retention of Previous Configurations | 11 |
CM-2(7) | Configure Systems and Components for High-Risk Areas | 5 |
CM-3 | Configuration Change Control | 18 |
CM-3(1) | Automated Documentation, Notification, and Prohibition | 0 |
CM-3(2) | Testing, Validation, and Documentation of Changes | 14 |
CM-3(4) | Security and Privacy Representatives | 9 |
CM-3(6) | Cryptography Management | 1 |
CM-4 | Impact Analyses | 17 |
CM-4(1) | Separate Test Environments | 0 |
CM-4(2) | Impact Analyses | Verification of Controls. After system changes, verify that the impacted controls are implemented correctly, operating as intended, and producing the desired outc | 14 |
CM-5 | Access Restrictions for Change | 19 |
CM-5(1) | Access Restrictions for Change | Automated Access Enforcement and Audit Records. (a) Enforce access restrictions using [Assignment: organization-defined automated mechanisms]; and | 14 |
CM-5(5) | Access Restrictions for Change | Privilege Limitation for Production and Operation. (a) Limit privileges to change system components and system-related information within a product | 15 |
CM-6 | Configuration Settings | 23 |
CM-6(1) | Automated Management, Application, and Verification | 16 |
CM-6(2) | Respond to Unauthorized Changes | 0 |
CM-7 | Least Functionality | 20 |
CM-7(1) | Periodic Review | 17 |
CM-7(2) | Prevent Program Execution | 16 |
CM-7(5) | Authorized Software Allow-by-Exception | 18 |
CM-8 | System Component Inventory | 26 |
CM-8(1) | Updates During Installation and Removal | 13 |
CM-8(2) | Automated Maintenance | 0 |
CM-8(3) | Automated Unauthorized Component Detection | 14 |
CM-8(4) | Accountability Information | 1 |
CM-9 | Configuration Management Plan | 14 |
CP-1 | Policy and Procedures | 17 |
CP-10 | System Recovery and Reconstitution | 21 |
CP-10(2) | System Recovery and Reconstitution | Transaction Recovery. Implement transaction recovery for systems that are transaction-based | 7 |
CP-10(4) | Restore Within Time Period | 0 |
CP-2 | Contingency Plan | 24 |
CP-2(1) | Coordinate with Related Plans | 10 |
CP-2(2) | Capacity Planning | 0 |
CP-2(3) | Resume Mission and Business Functions | 13 |
CP-2(5) | Continue Mission and Business Functions | 0 |
CP-2(8) | Contingency Plan | Identify Critical Assets. Identify critical system assets supporting [Selection: all; essential] mission and business functions | 15 |
CP-3 | Contingency Training | 15 |
CP-3(1) | Simulated Events | 0 |
CP-4 | Contingency Plan Testing | 24 |
CP-4(1) | Coordinate with Related Plans | 12 |
CP-4(2) | Alternate Processing Site | 0 |
CP-6 | Alternate Storage Site | 18 |
CP-6(1) | Alternate Storage Site | Separation from Primary Site. Identify an alternate storage site that is sufficiently separated from the primary storage site to reduce susceptibility to t | 9 |
CP-6(2) | Recovery Time and Recovery Point Objectives | 0 |
CP-6(3) | Alternate Storage Site | Accessibility. Identify potential accessibility problems to the alternate storage site in the event of an area-wide disruption or disaster and outline expl | 5 |
CP-7 | Alternate Processing Site | 15 |
CP-7(1) | Alternate Processing Site | Separation from Primary Site. Identify an alternate processing site that is sufficiently separated from the primary processing site to reduce susceptibi | 6 |
CP-7(2) | Alternate Processing Site | Accessibility. Identify potential accessibility problems to alternate processing sites in the event of an area-wide disruption or disaster and outlines | 7 |
CP-7(3) | Alternate Processing Site | Priority of Service. Develop alternate processing site agreements that contain priority-of-service provisions in accordance with availability requiremen | 6 |
CP-7(4) | Preparation for Use | 0 |
CP-8 | Telecommunications Services | 10 |
CP-8(1) | Telecommunications Services | Priority of Service Provisions. (a) Develop primary and alternate telecommunications service agreements that contain priority-of-service provisions in | 6 |
CP-8(2) | Telecommunications Services | Single Points of Failure. Obtain alternate telecommunications services to reduce the likelihood of sharing a single point of failure with primary tele | 9 |
CP-8(3) | Separation of Primary and Alternate Providers | 0 |
CP-8(4) | Provider Contingency Plan | 0 |
CP-9 | System Backup | 23 |
CP-9(1) | Testing for Reliability and Integrity | 19 |
CP-9(2) | Test Restoration Using Sampling | 0 |
CP-9(3) | Separate Storage for Critical Information | 0 |
CP-9(5) | Transfer to Alternate Storage Site | 0 |
CP-9(8) | System Backup | Cryptographic Protection. Implement cryptographic mechanisms to prevent unauthorized disclosure and modification of [Assignment: organization-defined backup informa | 16 |
IA-1 | Policy and Procedures | 13 |
IA-11 | Re-Authentication | 11 |
IA-12 | Identity Proofing. a. Identity proof users that require accounts for logical access to systems based on appropriate identity assurance level requirements as specified in applicable | 10 |
IA-12(2) | Identity Proofing | Identity Evidence. Require evidence of individual identification be presented to the registration authority | 6 |
IA-12(3) | Identity Proofing | Identity Evidence Validation and Verification. Require that the presented identity evidence be validated and verified through [Assignment: organizational define | 6 |
IA-12(4) | In-Person Validation and Verification | 0 |
IA-12(5) | Identity Proofing | Address Confirmation. Require that a [Selection: registration code; notice of proofing] be delivered through an out-of-band channel to verify the users address | 3 |
IA-2 | Identification and Authentication (Organizational Users) | 24 |
IA-2(1) | MFA to Privileged Accounts | 21 |
IA-2(12) | Acceptance of PIV Credentials | 5 |
IA-2(2) | MFA to Non-Privileged Accounts | 19 |
IA-2(5) | Identification and Authentication (organizational Users) | Individual Authentication with Group Authentication. When shared accounts or authenticators are employed, require users t | 10 |
IA-2(6) | Identification and Authentication (organizational Users) | Access to Accounts , separate Device. Implement multi-factor authentication for [Selection (one or more): local; network; | 11 |
IA-2(8) | Access to Accounts Replay Resistant | 12 |
IA-3 | Device Identification and Authentication | 16 |
IA-4 | Identifier Management | 22 |
IA-4(4) | Identifier Management | Identify User Status. Manage individual identifiers by uniquely identifying each individual as [Assignment: organization-defined characteristic identifying | 9 |
IA-5 | Authenticator Management | 23 |
IA-5(1) | Password-Based Authentication | 19 |
IA-5(13) | Authenticator Management | Expiration of Cached Authenticators | 0 |
IA-5(2) | Public Key-Based Authentication | 11 |
IA-5(6) | Protection of Authenticators | 19 |
IA-5(7) | Authenticator Management | No Embedded Unencrypted Static Authenticators. Ensure that unencrypted static authenticators are not embedded in applications or other forms of static st | 13 |
IA-5(8) | Multiple System Accounts | 0 |
IA-6 | Authentication Feedback | 8 |
IA-7 | Cryptographic Module Authentication | 10 |
IA-8 | Identification and Authentication (Non-Organizational Users) | 19 |
IA-8(1) | Identification and Authentication (non-organizational Users) | Acceptance of PIV Credentials from Other Agencies. Accept and electronically verify Personal Identity Verification-co | 5 |
IA-8(2) | Identification and Authentication (non-organizational Users) | Acceptance of External Authenticators. (a) Accept only external authenticators that are NIST-compliant; and (b) Docum | 5 |
IA-8(4) | Identification and Authentication (non-organizational Users) | Use of Defined Profiles. Conform to the following profiles for identity management [Assignment: organization-defined | 4 |
IR-1 | Policy and Procedures | 19 |
IR-2 | Incident Response Training | 39 |
IR-2(1) | Simulated Events | 0 |
IR-2(2) | Automated Training Environments | 0 |
IR-3 | Incident Response Testing | 23 |
IR-3(2) | Incident Response Testing | Coordination with Related Plans. Coordinate incident response testing with organizational elements responsible for related plans | 12 |
IR-4 | Incident Handling | 68 |
IR-4(1) | Automated Incident Handling Processes | 14 |
IR-4(11) | Incident Handling | Integrated Incident Response Team | 0 |
IR-4(2) | Incident Handling | Dynamic Reconfiguration | 0 |
IR-4(4) | Information Correlation | 0 |
IR-4(6) | Insider Threats | 0 |
IR-5 | Incident Monitoring | 27 |
IR-5(1) | Automated Tracking, Data Collection, and Analysis | 0 |
IR-6 | Incident Reporting | 31 |
IR-6(1) | Automated Reporting | 13 |
IR-6(3) | Incident Reporting | Supply Chain Coordination. Provide incident information to the provider of the product or service and other organizations involved in the supply chain or suppl | 11 |
IR-7 | Incident Response Assistance | 16 |
IR-7(1) | Incident Response Assistance | Automation Support for Availability of Information and Support. Increase the availability of incident response information and support using [Assignm | 10 |
IR-8 | Incident Response Plan | 29 |
IR-9 | Information Spillage Response. Respond to information spills by: a. Assigning [Assignment: organization-defined personnel or roles] with responsibility for responding to informatio | 11 |
IR-9(2) | Information Spillage Response | Training. Provide information spillage response training [Assignment: organization-defined frequency] | 6 |
IR-9(3) | Information Spillage Response | Post-spill Operations. Implement the following procedures to ensure that organizational personnel impacted by information spills can continue to car | 4 |
IR-9(4) | Information Spillage Response | Exposure to Unauthorized Personnel. Employ the following controls for personnel exposed to information not within assigned access authorizations: [A | 5 |
MA-1 | Policy and Procedures | 8 |
MA-2 | Controlled Maintenance | 14 |
MA-2(2) | Automated Maintenance Activities | 0 |
MA-3 | Maintenance Tools. a. Approve, control, and monitor the use of system maintenance tools; and b. Review previously approved system maintenance tools [Assignment: organization-define | 9 |
MA-3(1) | Maintenance Tools | Inspect Tools. Inspect the maintenance tools used by maintenance personnel for improper or unauthorized modifications | 8 |
MA-3(2) | Maintenance Tools | Inspect Media. Check media containing diagnostic and test programs for malicious code before the media are used in the system | 10 |
MA-3(3) | Maintenance Tools | Prevent Unauthorized Removal. Prevent the removal of maintenance equipment containing organizational information by: (a) Verifying that there is no organization | 12 |
MA-4 | Nonlocal Maintenance | 15 |
MA-4(3) | Comparable Security and Sanitization | 0 |
MA-5 | Maintenance Personnel | 12 |
MA-5(1) | Maintenance Personnel | Individuals Without Appropriate Access. The organization: (a) Implements procedures for the use of maintenance personnel that lack appropriate security clea | 6 |
MA-6 | Timely Maintenance. Obtain maintenance support and/or spare parts for [Assignment: organization-defined system components] within [Assignment: organization-defined time period] of | 7 |
MP-1 | Policy and Procedures | 14 |
MP-2 | Media Access | 13 |
MP-3 | Media Marking | 13 |
MP-4 | Media Storage | 17 |
MP-5 | Media Transport | 16 |
MP-6 | Media Sanitization | 25 |
MP-6(1) | Review, Approve, Track, Document, Verify | 0 |
MP-6(2) | Equipment Testing | 0 |
MP-6(3) | Nondestructive Techniques | 0 |
MP-7 | Media Use | 13 |
PE-1 | Policy and Procedures | 14 |
PE-10 | Emergency Shutoff. a. Provide the capability of shutting off power to [Assignment: organization-defined system or individual system components] in emergency situations; b. Place em | 6 |
PE-11 | Emergency Power. Provide an uninterruptible power supply to facilitate [Selection (one or more): an orderly shutdown of the system; transition of the system to long-term alternate | 8 |
PE-11(1) | Alternate Power Supply Minimal Operational Capability | 0 |
PE-12 | Emergency Lighting | 5 |
PE-13 | Fire Protection | 10 |
PE-13(1) | Fire Protection | Detection Systems, Automatic Activation and Notification. Employ fire detection systems that activate automatically and notify [Assignment: organization-defined p | 7 |
PE-13(2) | Fire Protection | Suppression Systems, Automatic Activation and Notification. (a) Employ fire suppression systems that activate automatically and notify [Assignment: organization-d | 6 |
PE-14 | Environmental Controls | 8 |
PE-14(2) | Environmental Controls | Monitoring with Alarms and Notifications | 0 |
PE-15 | Water Damage Protection. Protect the system from damage resulting from water leakage by providing master shutoff or isolation valves that are accessible, working properly, and know | 7 |
PE-15(1) | Automation Support | 0 |
PE-16 | Delivery and Removal | 13 |
PE-17 | Alternate Work Site | 15 |
PE-18 | Location of System Components | 0 |
PE-2 | Physical Access Authorizations | 15 |
PE-3 | Physical Access Control | 19 |
PE-3(1) | System Access | 0 |
PE-4 | Access Control for Transmission. Control physical access to [Assignment: organization-defined system distribution and transmission lines] within organizational facilities using [As | 9 |
PE-5 | Access Control for Output Devices. Control physical access to output from [Assignment: organization-defined output devices] to prevent unauthorized individuals from obtaining the o | 10 |
PE-6 | Monitoring Physical Access | 16 |
PE-6(1) | Monitoring Physical Access | Intrusion Alarms and Surveillance Equipment. Monitor physical access to the facility where the system resides using physical intrusion alarms and surve | 10 |
PE-6(4) | Monitoring Physical Access to Systems | 0 |
PE-8 | Visitor Access Records | 12 |
PE-8(1) | Automated Records Maintenance and Review | 0 |
PE-9 | Power Equipment and Cabling. Protect power equipment and power cabling for the system from damage and destruction | 8 |
PL-1 | Policy and Procedures | 18 |
PL-10 | Baseline Selection. Select a control baseline for the system | 13 |
PL-11 | Baseline Tailoring. Tailor the selected control baseline by applying specified tailoring actions | 9 |
PL-2 | System Security and Privacy Plans | 28 |
PL-4 | Rules of Behavior | 19 |
PL-4(1) | Rules of Behavior | Social Media and External Site/application Usage Restrictions. Include in the rules of behavior, restrictions on: (a) Use of social media, social networking sit | 8 |
PL-8 | Security and Privacy Architectures | 16 |
PS-1 | Policy and Procedures | 14 |
PS-2 | Position Risk Designation | 10 |
PS-3 | Personnel Screening | 20 |
PS-3(3) | Personnel Screening | Information Requiring Special Protective Measures. Verify that individuals accessing a system processing, storing, or transmitting information requiring speci | 9 |
PS-4 | Personnel Termination | 20 |
PS-4(2) | Automated Actions | 0 |
PS-5 | Personnel Transfer | 18 |
PS-6 | Access Agreements | 15 |
PS-7 | External Personnel Security | 19 |
PS-8 | Personnel Sanctions | 12 |
PS-9 | Position Descriptions. Incorporate security and privacy roles and responsibilities into organizational position descriptions | 22 |
RA-1 | Policy and Procedures | 86 |
RA-2 | Security Categorization | 28 |
RA-3 | Risk Assessment | 33 |
RA-3(1) | Risk Assessment | Supply Chain Risk Assessment. (a) Assess supply chain risks associated with [Assignment: organization-defined systems, system components, and system services]; an | 17 |
RA-5 | Vulnerability Monitoring and Scanning | 28 |
RA-5(11) | Vulnerability Monitoring and Scanning | Public Disclosure Program. Establish a public reporting channel for receiving reports of vulnerabilities in organizational systems and syste | 8 |
RA-5(2) | Update Vulnerabilities to be Scanned | 15 |
RA-5(3) | Vulnerability Monitoring and Scanning | Breadth and Depth of Coverage. Define the breadth and depth of vulnerability scanning coverage | 14 |
RA-5(4) | Discoverable Information | 0 |
RA-5(5) | Privileged Access | 10 |
RA-5(8) | Vulnerability Monitoring and Scanning | Review Historic Audit Logs | 0 |
RA-7 | Risk Response | 11 |
RA-9 | Criticality Analysis. Identify critical system components and functions by performing a criticality analysis for [Assignment: organization-defined systems, system components, or sy | 18 |
SA-1 | Policy and Procedures | 18 |
SA-10 | Developer Configuration Management | 13 |
SA-11 | Developer Testing and Evaluation | 19 |
SA-11(1) | Developer Testing and Evaluation | Static Code Analysis. Require the developer of the system, system component, or system service to employ static code analysis tools to identify c | 13 |
SA-11(2) | Developer Testing and Evaluation | Threat Modeling and Vulnerability Analyses. Require the developer of the system, system component, or system service to perform threat modeling a | 12 |
SA-15 | Development Process, Standards, and Tools. a. Require the developer of the system, system component, or system service to follow a documented development process that: 1. Explicitl | 16 |
SA-15(3) | Development Process, Standards, and Tools | Criticality Analysis. Require the developer of the system, system component, or system service to perform a criticality analysis: (a) At | 6 |
SA-16 | Developer-Provided Training | 0 |
SA-17 | Developer Security and Privacy Architecture and Design | 0 |
SA-2 | Allocation of Resources | 11 |
SA-21 | Developer Screening | 0 |
SA-22 | Unsupported System Components. a. Replace system components when support for the components is no longer available from the developer, vendor, or manufacturer; or b. Provide the fo | 18 |
SA-3 | System Development Life Cycle | 21 |
SA-4 | Acquisition Process | 22 |
SA-4(1) | Acquisition Process | Functional Properties of Controls. Require the developer of the system, system component, or system service to provide a description of the functional propert | 5 |
SA-4(10) | Use of Approved PIV Products | 3 |
SA-4(2) | Acquisition Process | Design and Implementation Information for Controls. Require the developer of the system, system component, or system service to provide design and implementat | 5 |
SA-4(5) | System, Component, and Service Configurations | 0 |
SA-4(9) | Acquisition Process | Functions, Ports, Protocols, and Services in Use. Require the developer of the system, system component, or system service to identify the functions, ports, p | 7 |
SA-5 | System Documentation | 13 |
SA-8 | Security and Privacy Engineering Principles | 19 |
SA-9 | External System Services | 30 |
SA-9(1) | External System Services | Risk Assessments and Organizational Approvals. (a) Conduct an organizational assessment of risk prior to the acquisition or outsourcing of information se | 17 |
SA-9(2) | Identification of Functions, Ports, Protocols, and Services | 9 |
SA-9(5) | External System Services | Processing, Storage, and Service Location. Restrict the location of [Selection (one or more): information processing; information or data; system service | 16 |
SC-1 | Policy and Procedures | 13 |
SC-10 | Network Disconnect | 10 |
SC-12 | Cryptographic Key Establishment and Management | 15 |
SC-12(1) | Availability | 0 |
SC-13 | Cryptographic Protection | 22 |
SC-15 | Collaborative Computing Devices and Applications | 5 |
SC-17 | Public Key Infrastructure Certificates | 9 |
SC-18 | Mobile Code | 12 |
SC-2 | Separation of System and User Functionality | 13 |
SC-20 | Secure Name/Address Resolution Service (Authoritative) | 5 |
SC-21 | Secure Name/Address Resolution Service (Recursive or Caching Resolver) | 6 |
SC-22 | Architecture and Provisioning for Name/Address Resolution Service | 5 |
SC-23 | Session Authenticity | 17 |
SC-24 | Fail in Known State | 0 |
SC-28 | Protection of Information at Rest | 23 |
SC-28(1) | Cryptographic Protection | 16 |
SC-3 | Security Function Isolation | 0 |
SC-39 | Process Isolation | 9 |
SC-4 | Information in Shared System Resources | 11 |
SC-45 | System Time Synchronization. Synchronize system clocks within and between systems and system components | 13 |
SC-45(1) | System Time Synchronization | Synchronization with Authoritative Time Source. (a) Compare the internal system clocks [Assignment: organization-defined frequency] with [Assignment: | 9 |
SC-5 | Denial-of-Service Protection | 15 |
SC-7 | Boundary Protection | 25 |
SC-7(10) | Prevent Exfiltration | 0 |
SC-7(12) | Boundary Protection | Host-based Protection. Implement [Assignment: organization-defined host-based boundary protection mechanisms] at [Assignment: organization-defined system comp | 13 |
SC-7(18) | Boundary Protection | Fail Secure. Prevent systems from entering unsecure states in the event of an operational failure of a boundary protection device | 4 |
SC-7(20) | Dynamic Isolation and Segregation | 0 |
SC-7(21) | Isolation of System Components | 0 |
SC-7(3) | Access Points | 17 |
SC-7(4) | External Telecommunications Services | 13 |
SC-7(5) | Deny by Default Allow by Exception | 17 |
SC-7(7) | Split Tunneling for Remote Devices | 8 |
SC-7(8) | Route Traffic to Authenticated Proxy Servers | 17 |
SC-8 | Transmission Confidentiality and Integrity | 26 |
SC-8(1) | Cryptographic Protection | 20 |
SI-1 | Policy and Procedures | 14 |
SI-10 | Information Input Validation | 13 |
SI-11 | Error Handling | 6 |
SI-12 | Information Management and Retention | 26 |
SI-16 | Memory Protection | 8 |
SI-2 | Flaw Remediation | 26 |
SI-2(2) | Automated Flaw Remediation Status | 14 |
SI-2(3) | Flaw Remediation | Time to Remediate Flaws and Benchmarks for Corrective Actions. (a) Measure the time between flaw identification and flaw remediation; and (b) Establish the follo | 15 |
SI-3 | Malicious Code Protection | 25 |
SI-4 | System Monitoring | 24 |
SI-4(1) | System Monitoring | System-wide Intrusion Detection System. Connect and configure individual intrusion detection tools into a system-wide intrusion detection system | 13 |
SI-4(10) | Visibility of Encrypted Communications | 0 |
SI-4(11) | Analyze Communications Traffic Anomalies | 0 |
SI-4(12) | Automated Organization-Generated Alerts | 0 |
SI-4(14) | Wireless Intrusion Detection | 0 |
SI-4(16) | System Monitoring | Correlate Monitoring Information. Correlate information from monitoring tools and mechanisms employed throughout the system | 12 |
SI-4(18) | System Monitoring | Analyze Traffic and Covert Exfiltration. Analyze outbound communications traffic at external interfaces to the system and at the following interior points to de | 16 |
SI-4(19) | Risk for Individuals | 0 |
SI-4(2) | Automated Tools and Mechanisms for Real-Time Analysis | 14 |
SI-4(20) | Privileged Users | 0 |
SI-4(22) | Unauthorized Network Services | 0 |
SI-4(23) | System Monitoring | Host-based Devices. Implement the following host-based monitoring mechanisms at [Assignment: organization-defined system components]: [Assignment: organization- | 13 |
SI-4(4) | Inbound and Outbound Communications Traffic | 14 |
SI-4(5) | System-Generated Alerts | 14 |
SI-5 | Security Alerts, Advisories, and Directives | 23 |
SI-5(1) | Automated Alerts and Advisories | 0 |
SI-6 | Security and Privacy Function Verification. a. Verify the correct operation of [Assignment: organization-defined security and privacy functions]; b. Perform the verification of the | 10 |
SI-7 | Software, Firmware, and Information Integrity | 18 |
SI-7(1) | Integrity Checks | 15 |
SI-7(15) | Software, Firmware, and Information Integrity | Code Authentication | 0 |
SI-7(2) | Automated Notifications of Integrity Violations | 0 |
SI-7(5) | Automated Response to Integrity Violations | 0 |
SI-7(7) | Integration of Detection and Response | 11 |
SI-8 | Spam Protection | 12 |
SI-8(2) | Spam Protection | Automatic Updates. Automatically update spam protection mechanisms [Assignment: organization-defined frequency] | 7 |
SR-1 | Policy and Procedures (SR-1) | 17 |
SR-10 | Inspection of Systems or Components (SR-10) | 8 |
SR-11 | Component Authenticity (SR-11) | 12 |
SR-11(1) | Component Authenticity | Anti-counterfeit Training. Train [Assignment: organization-defined personnel or roles] to detect counterfeit system components (including hardware, softwar | 6 |