United States

NIST SP 800-161 Rev 1

191 controls. 37 other frameworks in our corpus share controls with it. Here is all of it, and how much of it you are already doing.

Page built . This page is derived from the framework corpus, which changes when the corpus is extended rather than daily.

191 controls 37 frameworks share controls with it United States verified against its source document

Every control below is one this framework asks for. The right hand column counts how many other frameworks in our corpus carry the same control, which is the difference between doing this work once and doing it again for the next standard.

NIST SP 800-161 Cybersecurity Supply Chain Risk Management Evidence & Implementation Kit

191 controls is the documentation set somebody has to write. This is that set, already written: an adopt-ready artifact for every control in policy and procedure text you edit rather than draft, and the evidence checklist an auditor asks for against each.

See what is in it, $249

The same set every buyer of this kit receives. Nothing here is produced on request.

What you already have

Frameworks whose controls overlap this one, most first. If you run any of them, the count is roughly what you have already evidenced.

Every control

CodeControlAlso in
161R1-AC-1Policy and Procedures12
161R1-AC-17Remote Access22
161R1-AC-18Wireless Access12
161R1-AC-19Access Control for Mobile Devices19
161R1-AC-2Account Management25
161R1-AC-20Use of External Systems23
161R1-AC-21Information Sharing14
161R1-AC-22Publicly Accessible Content10
161R1-AC-23Data Mining Protection2
161R1-AC-24Access Control Decisions10
161R1-AC-3Access Enforcement25
161R1-AC-4Information Flow Enforcement16
161R1-AC-5Separation of Duties19
161R1-AC-6Least Privilege28
161R1-AT-1Policy and Procedures10
161R1-AT-2Literacy Training and Awareness28
161R1-AT-3Role-Based Training26
161R1-AT-4Training Records16
161R1-AU-1Policy and Procedures11
161R1-AU-10Non-repudiation11
161R1-AU-12Audit Record Generation18
161R1-AU-13Monitoring for Information Disclosure7
161R1-AU-14Session Audit6
161R1-AU-16Cross-Organizational Audit Logging8
161R1-AU-2Event Logging22
161R1-AU-3Content of Audit Records18
161R1-AU-6Audit Review, Analysis, and Reporting24
161R1-CA-1Policy and Procedures8
161R1-CA-2Control Assessments33
161R1-CA-3Information Exchange17
161R1-CA-5Plan of Action and Milestones24
161R1-CA-6Authorization9
161R1-CA-7Continuous Monitoring31
161R1-CM-1Policy and Procedures8
161R1-CM-10Software Usage Restrictions22
161R1-CM-11User-Installed Software23
161R1-CM-12Information Location20
161R1-CM-13Data Action Mapping6
161R1-CM-14Signed Components21
161R1-CM-2Baseline Configuration21
161R1-CM-3Configuration Change Control19
161R1-CM-4Impact Analysis18
161R1-CM-5Access Restrictions for Change18
161R1-CM-6Configuration Settings21
161R1-CM-7Least Functionality21
161R1-CM-8System Component Inventory26
161R1-CM-9Configuration Management Plan15
161R1-CP-1Policy and Procedures13
161R1-CP-11Alternative Communications Protocols3
161R1-CP-2Contingency Plan25
161R1-CP-3Contingency Training11
161R1-CP-4Contingency Plan Testing24
161R1-CP-6Alternative Storage Site13
161R1-CP-7Alternative Processing Site15
161R1-CP-8Telecommunications Services10
161R1-IA-1Policy and Procedures10
161R1-IA-2Identification and Authentication (Organizational Users)23
161R1-IA-3Device Identification and Authentication15
161R1-IA-4Identifier Management22
161R1-IA-5Authenticator Management24
161R1-IA-8Identification and Authentication (Non-Organizational Users)18
161R1-IA-9Service Identification and Authentication8
161R1-IR-1Policy and Procedures19
161R1-IR-2Incident Response Training13
161R1-IR-3Incident Response Testing20
161R1-IR-4Incident Handling29
161R1-IR-5Incident Monitoring23
161R1-IR-6Incident Reporting30
161R1-IR-7Incident Response Assistance13
161R1-IR-8Incident Response Plan29
161R1-IR-9Information Spillage Response7
161R1-MA-1Policy and Procedures8
161R1-MA-2Controlled Maintenance16
161R1-MA-3Maintenance Tools12
161R1-MA-4Nonlocal Maintenance14
161R1-MA-5Maintenance Personnel15
161R1-MA-6Timely Maintenance13
161R1-MA-7Field Maintenance7
161R1-MA-8Maintenance Monitoring and Information Sharing1
161R1-MP-1Policy and Procedures10
161R1-MP-4Media Storage16
161R1-MP-5Media Transport18
161R1-MP-6Media Sanitization22
161R1-PE-1Policy and Procedures10
161R1-PE-16Delivery and Removal12
161R1-PE-17Alternative Work Site13
161R1-PE-18Location of System Components2
161R1-PE-2Physical Access Authorizations16
161R1-PE-20Asset Monitoring and Tracking13
161R1-PE-23Facility Location5
161R1-PE-3Physical Access Control20
161R1-PE-6Monitoring Physical Access17
161R1-PL-1Policy and Procedures9
161R1-PL-10Baseline Selection13
161R1-PL-2System Security and Privacy Plans20
161R1-PL-4Rules of Behavior19
161R1-PL-7Concept of Operations4
161R1-PL-8Security and Privacy Architectures14
161R1-PL-9Central Management7
161R1-PM-10Authorization Process3
161R1-PM-11Mission and Business Process Definition7
161R1-PM-12Insider Threat Program15
161R1-PM-13Security and Privacy Workforce9
161R1-PM-14Testing, Training, and Monitoring7
161R1-PM-15Security and Privacy Groups and Associations11
161R1-PM-16Threat Awareness Program13
161R1-PM-17Protecting Controlled Unclassified Information on External Systems8
161R1-PM-18Privacy Program Plan5
161R1-PM-19Privacy Program Leadership Role4
161R1-PM-2Information Security Program Leadership Role20
161R1-PM-20Dissemination of Privacy Program Information7
161R1-PM-21Accounting of Disclosures8
161R1-PM-22Personally Identifiable Information Quality Management7
161R1-PM-23Data Governance Body2
161R1-PM-25Minimization of Personally Identifiable Information Used in Testing, Training, and Research10
161R1-PM-26Complaint Management6
161R1-PM-27Privacy Reporting2
161R1-PM-28Risk Framing10
161R1-PM-29Risk Management Program Leadership Roles16
161R1-PM-3Information Security and Privacy Resources10
161R1-PM-30Supply Chain Risk Management Strategy10
161R1-PM-31Continuous Monitoring Strategy15
161R1-PM-32Purposing3
161R1-PM-4Plan of Action and Milestones Process10
161R1-PM-5System Inventory14
161R1-PM-6Measures of Performance15
161R1-PM-7Enterprise Architecture3
161R1-PM-8Critical Infrastructure Plan4
161R1-PM-9Risk Management Strategy15
161R1-PS-1Policy and Procedures11
161R1-PS-3Personnel Screening22
161R1-PS-6Access Agreements19
161R1-PS-7External Personnel Security28
161R1-PT-1Policy and Procedures8
161R1-RA-1Policy and Procedures11
161R1-RA-10Threat Hunting8
161R1-RA-2Security Categorization19
161R1-RA-3Risk Assessment30
161R1-RA-5Vulnerability Monitoring and Scanning29
161R1-RA-7Risk Response20
161R1-RA-9Criticality Analysis24
161R1-SA-1Policy and Procedures10
161R1-SA-10Developer Configuration Management11
161R1-SA-11Developer Testing and Evaluation17
161R1-SA-15Development Process, Standards, and Tools17
161R1-SA-16Developer-Provided Training6
161R1-SA-17Developer Security and Privacy Architecture and Design12
161R1-SA-2Allocation of Resources7
161R1-SA-20Customized Development of Critical Components3
161R1-SA-21Developer Screening5
161R1-SA-22Unsupported System Components21
161R1-SA-3System Development Life Cycle17
161R1-SA-4Acquisition Process24
161R1-SA-5System Documentation15
161R1-SA-8Security and Privacy Engineering Principles18
161R1-SA-9External System Services32
161R1-SC-1Policy and Procedures9
161R1-SC-18Mobile Code9
161R1-SC-27Platform-Independent Applications5
161R1-SC-28Protection of Information at Rest23
161R1-SC-29Heterogeneity7
161R1-SC-30Concealment and Misdirection3
161R1-SC-36Distributed Processing and Storage11
161R1-SC-37Out-of-Band Channels7
161R1-SC-38Operations Security3
161R1-SC-4Information in Shared Resources14
161R1-SC-47Alternative Communications Paths8
161R1-SC-5Denial-of-Service Protection11
161R1-SC-7Boundary Protection26
161R1-SC-8Transmission Confidentiality and Integrity25
161R1-SI-1Policy and Procedures8
161R1-SI-12Information Management and Retention26
161R1-SI-2Flaw Remediation27
161R1-SI-20Tainting11
161R1-SI-3Malicious Code Protection26
161R1-SI-4System Monitoring25
161R1-SI-5Security Alerts, Advisories, and Directives26
161R1-SI-7Software, Firmware, and Information Integrity20
161R1-SR-1Policy and Procedures23
161R1-SR-10Inspection of Systems or Components12
161R1-SR-11Component Authenticity16
161R1-SR-12Component Disposal22
161R1-SR-13Supplier Inventory16
161R1-SR-2Supply Chain Risk Management Plan18
161R1-SR-3Supply Chain Controls and Processes26
161R1-SR-4Provenance19
161R1-SR-5Acquisition Strategies, Tools, and Methods23
161R1-SR-6Supplier Assessments and Reviews30
161R1-SR-7Supply Chain Operations Security8
161R1-SR-8Notification Agreements24
161R1-SR-9Tamper Resistance and Detection13

Tell me when NIST SP 800-161 Rev 1 files something new

One email when a public company newly discloses something this framework governs, naming the company and what our corpus says it puts in scope. Nothing else, and one click to stop.

What an auditor will ask you to produce

The artefacts named on the failure modes this framework speaks to.

  • cloud security policy
  • strategy document
  • governance charter
  • review log
  • ISCM strategy document
  • Volatility assessment

How programmes fail on this

Failure modes named by this framework and others. Each opens the full record.

What this page is

A control-level reference for NIST SP 800-161 Rev 1, drawn from our framework corpus. Control codes and titles are references to the standard, not reproductions of it. The overlap counts and the auditor artefacts are our own work and are the part you will not find elsewhere.

Measure this against what you already run · All frameworks · Today's edition