171-AC-1 | Access Control Policy and Procedures | 2 |
171-AC-2 | Least Privilege and Separation of Duties | 2 |
171-AC-3 | Remote Access and Mobile Devices | 1 |
171-AT-1 | Security Awareness and Role-Based Training | 0 |
171-AU-1 | Audit Event Capture | 0 |
171-AU-2 | Audit Review and Analysis | 0 |
171-CM-1 | Baseline Configuration and Inventory | 2 |
171-IA-1 | Identification and Authentication | 2 |
171-IA-2 | Multi-Factor Authentication | 2 |
171-IR-1 | Incident Handling Capability | 0 |
171-IR-2 | Incident Reporting | 0 |
171-MA-1 | Maintenance Authorisation and Control | 0 |
171-MP-1 | Media Protection | 0 |
171-PE-1 | Physical Access Authorisations | 0 |
171-RA-1 | Risk Assessment | 4 |
171-RA-2 | Vulnerability Scanning and Remediation | 2 |
171-SC-1 | Boundary Protection | 1 |
171-SC-2 | Encryption of Controlled Unclassified Information | 1 |
171-SI-1 | Flaw Remediation | 0 |
171-SI-2 | Malicious Code Protection | 0 |
3.1.20 | External Connections Control | 0 |
3.10.6 | Alternate Work Site Safeguards | 0 |
3.11.1 | Risk Assessments | 0 |
3.11.2 | Vulnerability Scanning | 0 |
3.12.1 | Security Control Assessment | 0 |
3.13.11 | Cryptographic Protection | 0 |
3.13.5 | Network Segmentation | 0 |
3.13.8 | Transmission Confidentiality | 0 |
3.14.1 | Flaw Remediation | 0 |
3.14.6 | Monitoring for Attacks | 0 |
3.4.6 | Least Functionality | 0 |
3.5.3 | Multi Factor Authentication | 0 |
3.8.3 | Media Sanitization | 0 |
3.9.2 | Personnel Transfer and Termination | 0 |
A.03.01.01 | Account Management Assessment | 0 |
A.03.01.05 | Least Privilege Assessment | 0 |
A.03.01.12 | Remote Access Assessment | 0 |
A.03.03.01 | Event Logging Assessment | 1 |
A.03.04.01 | Baseline Configuration Assessment | 0 |
A.03.04.02 | Configuration Settings Assessment | 0 |
A.03.05.03 | Multi Factor Authentication Assessment | 0 |
A.03.06.01 | Incident Handling Assessment | 0 |
A.03.07.04 | Maintenance Tools Assessment | 0 |
A.03.08.03 | Media Sanitization Assessment | 0 |
A.03.09.02 | Personnel Termination Assessment | 0 |
A.03.10.01 | Physical Access Authorization Assessment | 0 |
A.03.11.01 | Risk Assessment Process | 4 |
A.03.11.02 | Vulnerability Monitoring Assessment | 0 |
A.03.12.01 | Security Control Assessments | 0 |
A.03.13.11 | Cryptographic Protection of CUI at Rest | 0 |
A.03.14.01 | Flaw Remediation Assessment | 0 |
A.03.14.06 | System Monitoring Assessment | 0 |
A.03.15.01 | System Security Plan Assessment | 0 |
SP800-171-3.10.1 | Limit physical access | 1 |
SP800-171-3.10.3 | Escort and monitor visitors | 1 |
SP800-171-3.10.6 | Safeguard CUI at alternate work sites | 1 |
SP800-171-3.11.1 | Periodically assess risk | 1 |
SP800-171-3.11.2 | Scan for vulnerabilities | 1 |
SP800-171-3.11.3 | Remediate vulnerabilities | 1 |
SP800-171-3.12.1 | Periodically assess security controls | 1 |
SP800-171-3.12.2 | Plans of action for deficiencies | 1 |
SP800-171-3.12.3 | Continuously monitor controls | 1 |
SP800-171-3.13.1 | Monitor and protect communications at boundaries | 1 |
SP800-171-3.13.11 | Employ FIPS-validated cryptography | 1 |
SP800-171-3.13.16 | Protect confidentiality of CUI at rest | 1 |
SP800-171-3.13.6 | Deny network traffic by default | 1 |
SP800-171-3.13.8 | Encrypt CUI in transmission | 1 |
SP800-171-3.14.1 | Identify, report, and correct flaws | 1 |
SP800-171-3.14.2 | Malicious code protection | 1 |
SP800-171-3.14.3 | Monitor security alerts and advisories | 1 |
SP800-171-3.14.6 | Monitor systems and traffic for attacks | 1 |
SP800-171-3.5.1 | Identify system users, processes, and devices | 1 |
SP800-171-3.5.10 | Store and transmit only encrypted passwords | 1 |
SP800-171-3.5.2 | Authenticate identities before access | 1 |
SP800-171-3.5.3 | Multifactor authentication for privileged/network access | 1 |
SP800-171-3.5.4 | Replay-resistant authentication | 1 |
SP800-171-3.6.1 | Operational incident-handling capability | 1 |
SP800-171-3.6.2 | Track, document, and report incidents | 1 |
SP800-171-3.6.3 | Test incident response capability | 1 |
SP800-171-3.7.1 | Perform system maintenance | 1 |
SP800-171-3.7.2 | Control maintenance tools and personnel | 1 |
SP800-171-3.7.5 | MFA for nonlocal maintenance | 1 |
SP800-171-3.8.1 | Protect system media containing CUI | 1 |
SP800-171-3.8.3 | Sanitize or destroy media before disposal | 1 |
SP800-171-3.8.6 | Encrypt CUI on digital media during transport | 1 |
SP800-171-3.8.7 | Control removable media | 1 |
SP800-171-3.9.1 | Screen individuals before CUI access | 1 |
SP800-171-3.9.2 | Protect CUI during personnel actions | 1 |