161R1-AC-1 | Policy and Procedures | 12 |
161R1-AC-17 | Remote Access | 22 |
161R1-AC-18 | Wireless Access | 12 |
161R1-AC-19 | Access Control for Mobile Devices | 19 |
161R1-AC-2 | Account Management | 25 |
161R1-AC-20 | Use of External Systems | 23 |
161R1-AC-21 | Information Sharing | 14 |
161R1-AC-22 | Publicly Accessible Content | 10 |
161R1-AC-23 | Data Mining Protection | 2 |
161R1-AC-24 | Access Control Decisions | 10 |
161R1-AC-3 | Access Enforcement | 25 |
161R1-AC-4 | Information Flow Enforcement | 16 |
161R1-AC-5 | Separation of Duties | 19 |
161R1-AC-6 | Least Privilege | 28 |
161R1-AT-1 | Policy and Procedures | 10 |
161R1-AT-2 | Literacy Training and Awareness | 28 |
161R1-AT-3 | Role-Based Training | 26 |
161R1-AT-4 | Training Records | 16 |
161R1-AU-1 | Policy and Procedures | 11 |
161R1-AU-10 | Non-repudiation | 11 |
161R1-AU-12 | Audit Record Generation | 18 |
161R1-AU-13 | Monitoring for Information Disclosure | 7 |
161R1-AU-14 | Session Audit | 6 |
161R1-AU-16 | Cross-Organizational Audit Logging | 8 |
161R1-AU-2 | Event Logging | 22 |
161R1-AU-3 | Content of Audit Records | 18 |
161R1-AU-6 | Audit Review, Analysis, and Reporting | 24 |
161R1-CA-1 | Policy and Procedures | 8 |
161R1-CA-2 | Control Assessments | 33 |
161R1-CA-3 | Information Exchange | 17 |
161R1-CA-5 | Plan of Action and Milestones | 24 |
161R1-CA-6 | Authorization | 9 |
161R1-CA-7 | Continuous Monitoring | 31 |
161R1-CM-1 | Policy and Procedures | 8 |
161R1-CM-10 | Software Usage Restrictions | 22 |
161R1-CM-11 | User-Installed Software | 23 |
161R1-CM-12 | Information Location | 20 |
161R1-CM-13 | Data Action Mapping | 6 |
161R1-CM-14 | Signed Components | 21 |
161R1-CM-2 | Baseline Configuration | 21 |
161R1-CM-3 | Configuration Change Control | 19 |
161R1-CM-4 | Impact Analysis | 18 |
161R1-CM-5 | Access Restrictions for Change | 18 |
161R1-CM-6 | Configuration Settings | 21 |
161R1-CM-7 | Least Functionality | 21 |
161R1-CM-8 | System Component Inventory | 26 |
161R1-CM-9 | Configuration Management Plan | 15 |
161R1-CP-1 | Policy and Procedures | 13 |
161R1-CP-11 | Alternative Communications Protocols | 3 |
161R1-CP-2 | Contingency Plan | 25 |
161R1-CP-3 | Contingency Training | 11 |
161R1-CP-4 | Contingency Plan Testing | 24 |
161R1-CP-6 | Alternative Storage Site | 13 |
161R1-CP-7 | Alternative Processing Site | 15 |
161R1-CP-8 | Telecommunications Services | 10 |
161R1-IA-1 | Policy and Procedures | 10 |
161R1-IA-2 | Identification and Authentication (Organizational Users) | 23 |
161R1-IA-3 | Device Identification and Authentication | 15 |
161R1-IA-4 | Identifier Management | 22 |
161R1-IA-5 | Authenticator Management | 24 |
161R1-IA-8 | Identification and Authentication (Non-Organizational Users) | 18 |
161R1-IA-9 | Service Identification and Authentication | 8 |
161R1-IR-1 | Policy and Procedures | 19 |
161R1-IR-2 | Incident Response Training | 13 |
161R1-IR-3 | Incident Response Testing | 20 |
161R1-IR-4 | Incident Handling | 29 |
161R1-IR-5 | Incident Monitoring | 23 |
161R1-IR-6 | Incident Reporting | 30 |
161R1-IR-7 | Incident Response Assistance | 13 |
161R1-IR-8 | Incident Response Plan | 29 |
161R1-IR-9 | Information Spillage Response | 7 |
161R1-MA-1 | Policy and Procedures | 8 |
161R1-MA-2 | Controlled Maintenance | 16 |
161R1-MA-3 | Maintenance Tools | 12 |
161R1-MA-4 | Nonlocal Maintenance | 14 |
161R1-MA-5 | Maintenance Personnel | 15 |
161R1-MA-6 | Timely Maintenance | 13 |
161R1-MA-7 | Field Maintenance | 7 |
161R1-MA-8 | Maintenance Monitoring and Information Sharing | 1 |
161R1-MP-1 | Policy and Procedures | 10 |
161R1-MP-4 | Media Storage | 16 |
161R1-MP-5 | Media Transport | 18 |
161R1-MP-6 | Media Sanitization | 22 |
161R1-PE-1 | Policy and Procedures | 10 |
161R1-PE-16 | Delivery and Removal | 12 |
161R1-PE-17 | Alternative Work Site | 13 |
161R1-PE-18 | Location of System Components | 2 |
161R1-PE-2 | Physical Access Authorizations | 16 |
161R1-PE-20 | Asset Monitoring and Tracking | 13 |
161R1-PE-23 | Facility Location | 5 |
161R1-PE-3 | Physical Access Control | 20 |
161R1-PE-6 | Monitoring Physical Access | 17 |
161R1-PL-1 | Policy and Procedures | 9 |
161R1-PL-10 | Baseline Selection | 13 |
161R1-PL-2 | System Security and Privacy Plans | 20 |
161R1-PL-4 | Rules of Behavior | 19 |
161R1-PL-7 | Concept of Operations | 4 |
161R1-PL-8 | Security and Privacy Architectures | 14 |
161R1-PL-9 | Central Management | 7 |
161R1-PM-10 | Authorization Process | 3 |
161R1-PM-11 | Mission and Business Process Definition | 7 |
161R1-PM-12 | Insider Threat Program | 15 |
161R1-PM-13 | Security and Privacy Workforce | 9 |
161R1-PM-14 | Testing, Training, and Monitoring | 7 |
161R1-PM-15 | Security and Privacy Groups and Associations | 11 |
161R1-PM-16 | Threat Awareness Program | 13 |
161R1-PM-17 | Protecting Controlled Unclassified Information on External Systems | 8 |
161R1-PM-18 | Privacy Program Plan | 5 |
161R1-PM-19 | Privacy Program Leadership Role | 4 |
161R1-PM-2 | Information Security Program Leadership Role | 20 |
161R1-PM-20 | Dissemination of Privacy Program Information | 7 |
161R1-PM-21 | Accounting of Disclosures | 8 |
161R1-PM-22 | Personally Identifiable Information Quality Management | 7 |
161R1-PM-23 | Data Governance Body | 2 |
161R1-PM-25 | Minimization of Personally Identifiable Information Used in Testing, Training, and Research | 10 |
161R1-PM-26 | Complaint Management | 6 |
161R1-PM-27 | Privacy Reporting | 2 |
161R1-PM-28 | Risk Framing | 10 |
161R1-PM-29 | Risk Management Program Leadership Roles | 16 |
161R1-PM-3 | Information Security and Privacy Resources | 10 |
161R1-PM-30 | Supply Chain Risk Management Strategy | 10 |
161R1-PM-31 | Continuous Monitoring Strategy | 15 |
161R1-PM-32 | Purposing | 3 |
161R1-PM-4 | Plan of Action and Milestones Process | 10 |
161R1-PM-5 | System Inventory | 14 |
161R1-PM-6 | Measures of Performance | 15 |
161R1-PM-7 | Enterprise Architecture | 3 |
161R1-PM-8 | Critical Infrastructure Plan | 4 |
161R1-PM-9 | Risk Management Strategy | 15 |
161R1-PS-1 | Policy and Procedures | 11 |
161R1-PS-3 | Personnel Screening | 22 |
161R1-PS-6 | Access Agreements | 19 |
161R1-PS-7 | External Personnel Security | 28 |
161R1-PT-1 | Policy and Procedures | 8 |
161R1-RA-1 | Policy and Procedures | 11 |
161R1-RA-10 | Threat Hunting | 8 |
161R1-RA-2 | Security Categorization | 19 |
161R1-RA-3 | Risk Assessment | 30 |
161R1-RA-5 | Vulnerability Monitoring and Scanning | 29 |
161R1-RA-7 | Risk Response | 20 |
161R1-RA-9 | Criticality Analysis | 24 |
161R1-SA-1 | Policy and Procedures | 10 |
161R1-SA-10 | Developer Configuration Management | 11 |
161R1-SA-11 | Developer Testing and Evaluation | 17 |
161R1-SA-15 | Development Process, Standards, and Tools | 17 |
161R1-SA-16 | Developer-Provided Training | 6 |
161R1-SA-17 | Developer Security and Privacy Architecture and Design | 12 |
161R1-SA-2 | Allocation of Resources | 7 |
161R1-SA-20 | Customized Development of Critical Components | 3 |
161R1-SA-21 | Developer Screening | 5 |
161R1-SA-22 | Unsupported System Components | 21 |
161R1-SA-3 | System Development Life Cycle | 17 |
161R1-SA-4 | Acquisition Process | 24 |
161R1-SA-5 | System Documentation | 15 |
161R1-SA-8 | Security and Privacy Engineering Principles | 18 |
161R1-SA-9 | External System Services | 32 |
161R1-SC-1 | Policy and Procedures | 9 |
161R1-SC-18 | Mobile Code | 9 |
161R1-SC-27 | Platform-Independent Applications | 5 |
161R1-SC-28 | Protection of Information at Rest | 23 |
161R1-SC-29 | Heterogeneity | 7 |
161R1-SC-30 | Concealment and Misdirection | 3 |
161R1-SC-36 | Distributed Processing and Storage | 11 |
161R1-SC-37 | Out-of-Band Channels | 7 |
161R1-SC-38 | Operations Security | 3 |
161R1-SC-4 | Information in Shared Resources | 14 |
161R1-SC-47 | Alternative Communications Paths | 8 |
161R1-SC-5 | Denial-of-Service Protection | 11 |
161R1-SC-7 | Boundary Protection | 26 |
161R1-SC-8 | Transmission Confidentiality and Integrity | 25 |
161R1-SI-1 | Policy and Procedures | 8 |
161R1-SI-12 | Information Management and Retention | 26 |
161R1-SI-2 | Flaw Remediation | 27 |
161R1-SI-20 | Tainting | 11 |
161R1-SI-3 | Malicious Code Protection | 26 |
161R1-SI-4 | System Monitoring | 25 |
161R1-SI-5 | Security Alerts, Advisories, and Directives | 26 |
161R1-SI-7 | Software, Firmware, and Information Integrity | 20 |
161R1-SR-1 | Policy and Procedures | 23 |
161R1-SR-10 | Inspection of Systems or Components | 12 |
161R1-SR-11 | Component Authenticity | 16 |
161R1-SR-12 | Component Disposal | 22 |
161R1-SR-13 | Supplier Inventory | 16 |
161R1-SR-2 | Supply Chain Risk Management Plan | 18 |
161R1-SR-3 | Supply Chain Controls and Processes | 26 |
161R1-SR-4 | Provenance | 19 |
161R1-SR-5 | Acquisition Strategies, Tools, and Methods | 23 |
161R1-SR-6 | Supplier Assessments and Reviews | 30 |
161R1-SR-7 | Supply Chain Operations Security | 8 |
161R1-SR-8 | Notification Agreements | 24 |
161R1-SR-9 | Tamper Resistance and Detection | 13 |