03.01.01 | Account Management | 27 |
03.01.02 | Access Enforcement | 25 |
03.01.03 | Information Flow Enforcement | 23 |
03.01.04 | Separation of Duties | 21 |
03.01.05 | Least Privilege | 27 |
03.01.06 | Least Privilege - Privileged Accounts | 24 |
03.01.07 | Least Privilege - Privileged Functions | 22 |
03.01.08 | Unsuccessful Logon Attempts | 18 |
03.01.09 | System Use Notification | 9 |
03.01.10 | Device Lock | 16 |
03.01.11 | Session Termination | 13 |
03.01.12 | Remote Access | 24 |
03.01.16 | Wireless Access | 16 |
03.01.18 | Access Control for Mobile Devices | 22 |
03.01.20 | Use of External Systems | 20 |
03.01.22 | Publicly Accessible Content | 12 |
03.02.01 | Literacy Training and Awareness | 29 |
03.02.02 | Role-Based Training | 28 |
03.03.01 | Event Logging | 26 |
03.03.02 | Audit Record Content | 20 |
03.03.03 | Audit Record Generation | 24 |
03.03.04 | Response to Audit Logging Process Failures | 13 |
03.03.05 | Audit Record Review, Analysis, and Reporting | 27 |
03.03.06 | Audit Record Reduction and Report Generation | 18 |
03.03.07 | Time Stamps | 14 |
03.03.08 | Protection of Audit Information | 19 |
03.04.01 | Baseline Configuration | 27 |
03.04.02 | Configuration Settings | 26 |
03.04.03 | Configuration Change Control | 23 |
03.04.04 | Impact Analyses | 19 |
03.04.05 | Access Restrictions for Change | 18 |
03.04.06 | Least Functionality | 24 |
03.04.08 | Authorized Software - Allow by Exception | 27 |
03.04.10 | System Component Inventory | 28 |
03.04.11 | Information Location | 22 |
03.04.12 | System and Component Configuration for High-Risk Areas | 9 |
03.05.01 | User Identification and Authentication | 27 |
03.05.02 | Device Identification and Authentication | 16 |
03.05.03 | Multi-Factor Authentication | 23 |
03.05.04 | Replay-Resistant Authentication | 16 |
03.05.05 | Identifier Management | 23 |
03.05.07 | Password Management | 22 |
03.05.11 | Authentication Feedback | 14 |
03.05.12 | Authenticator Management | 25 |
03.06.01 | Incident Handling | 30 |
03.06.02 | Incident Monitoring, Reporting, and Response Assistance | 29 |
03.06.03 | Incident Response Testing | 25 |
03.06.04 | Incident Response Training | 24 |
03.06.05 | Incident Response Plan | 29 |
03.07.04 | Maintenance Tools | 14 |
03.07.05 | Nonlocal Maintenance | 20 |
03.07.06 | Maintenance Personnel | 15 |
03.08.01 | Media Storage | 18 |
03.08.02 | Media Access | 18 |
03.08.03 | Media Sanitization | 24 |
03.08.04 | Media Marking | 18 |
03.08.05 | Media Transport | 17 |
03.08.07 | Media Use | 21 |
03.08.09 | System Backup - Cryptographic Protection | 25 |
03.09.01 | Personnel Screening | 25 |
03.09.02 | Personnel Termination and Transfer | 26 |
03.10.01 | Physical Access Authorizations | 22 |
03.10.02 | Monitoring Physical Access | 20 |
03.10.06 | Alternate Work Site | 15 |
03.10.07 | Physical Access Control | 21 |
03.10.08 | Access Control for Transmission | 18 |
03.11.01 | Risk Assessment | 31 |
03.11.02 | Vulnerability Monitoring and Scanning | 31 |
03.11.04 | Risk Response | 24 |
03.12.01 | Security Assessment | 30 |
03.12.02 | Plan of Action and Milestones | 28 |
03.12.03 | Continuous Monitoring | 31 |
03.12.05 | Information Exchange | 25 |
03.13.01 | Boundary Protection | 27 |
03.13.04 | Information in Shared System Resources | 16 |
03.13.06 | Network Communications - Deny by Default - Allow by Exception | 20 |
03.13.08 | Transmission Confidentiality and Integrity | 25 |
03.13.09 | Network Disconnect | 12 |
03.13.10 | Cryptographic Key Establishment and Management | 21 |
03.13.11 | Cryptographic Protection | 23 |
03.13.12 | Collaborative Computing Devices and Applications | 9 |
03.13.13 | Mobile Code | 18 |
03.13.15 | Session Authenticity | 18 |
03.14.01 | Flaw Remediation | 28 |
03.14.02 | Malicious Code Protection | 28 |
03.14.03 | Security Alerts, Advisories, and Directives | 25 |
03.14.06 | System Monitoring | 27 |
03.14.08 | Information Management and Retention | 22 |
03.15.01 | Policy and Procedures | 27 |
03.15.02 | System Security Plan | 28 |
03.15.03 | Rules of Behavior | 21 |
03.16.01 | Security Engineering Principles | 25 |
03.16.02 | Unsupported System Components | 21 |
03.16.03 | External System Services | 29 |
03.17.01 | Supply Chain Risk Management Plan | 23 |
03.17.02 | Acquisition Strategies, Tools, and Methods | 24 |
03.17.03 | Supply Chain Requirements and Processes | 25 |