AC-1 | Policy and Procedures | 20 |
AC-14 | Permitted Actions Without Identification or Authentication | 3 |
AC-17 | Remote Access | 20 |
AC-18 | Wireless Access | 9 |
AC-19 | Access Control for Mobile Devices | 16 |
AC-2 | Account Management | 95 |
AC-20 | Use of External Systems | 17 |
AC-22 | Publicly Accessible Content | 11 |
AC-3 | Access Enforcement | 36 |
AC-7 | Unsuccessful Logon Attempts | 14 |
AC-8 | System Use Notification | 5 |
AT-1 | Policy and Procedures | 17 |
AT-2 | Literacy Training and Awareness | 31 |
AT-2(2) | Insider Threat | 13 |
AT-3 | Role-Based Training | 29 |
AT-4 | Training Records | 19 |
AU-1 | Policy and Procedures | 15 |
AU-11 | Audit Record Retention | 16 |
AU-12 | Audit Record Generation | 23 |
AU-2 | Event Logging | 23 |
AU-3 | Content of Audit Records | 19 |
AU-4 | Audit Log Storage Capacity | 12 |
AU-5 | Response to Audit Logging Process Failures | 11 |
AU-6 | Audit Record Review, Analysis, and Reporting | 27 |
AU-8 | Time Stamps | 12 |
AU-9 | Protection of Audit Information | 18 |
CA-1 | Policy and Procedures | 18 |
CA-2 | Control Assessments | 33 |
CA-3 | Information Exchange | 18 |
CA-5 | Plan of Action and Milestones | 30 |
CA-6 | Authorization | 19 |
CA-7 | Continuous Monitoring | 33 |
CA-7(4) | Continuous Monitoring | Risk Monitoring. Ensure risk monitoring is an integral part of the continuous monitoring strategy that includes the following: (a) Effectiveness monitoring; | 17 |
CA-9 | Internal System Connections | 163 |
CM-1 | Policy and Procedures | 13 |
CM-10 | Software Usage Restrictions | 17 |
CM-11 | User-Installed Software | 22 |
CM-2 | Baseline Configuration | 19 |
CM-4 | Impact Analyses | 17 |
CM-5 | Access Restrictions for Change | 19 |
CM-6 | Configuration Settings | 23 |
CM-7 | Least Functionality | 20 |
CM-8 | System Component Inventory | 26 |
CP-1 | Policy and Procedures | 17 |
CP-10 | System Recovery and Reconstitution | 21 |
CP-2 | Contingency Plan | 24 |
CP-3 | Contingency Training | 15 |
CP-4 | Contingency Plan Testing | 24 |
CP-9 | System Backup | 23 |
IA-1 | Policy and Procedures | 13 |
IA-11 | Re-Authentication | 11 |
IA-2 | Identification and Authentication (Organizational Users) | 24 |
IA-4 | Identifier Management | 22 |
IA-5 | Authenticator Management | 23 |
IA-6 | Authentication Feedback | 8 |
IA-7 | Cryptographic Module Authentication | 10 |
IA-8 | Identification and Authentication (Non-Organizational Users) | 19 |
IR-1 | Policy and Procedures | 19 |
IR-2 | Incident Response Training | 39 |
IR-4 | Incident Handling | 69 |
IR-5 | Incident Monitoring | 27 |
IR-6 | Incident Reporting | 31 |
IR-7 | Incident Response Assistance | 16 |
IR-8 | Incident Response Plan | 29 |
MA-1 | Policy and Procedures | 8 |
MA-2 | Controlled Maintenance | 14 |
MA-4 | Nonlocal Maintenance | 15 |
MA-5 | Maintenance Personnel | 12 |
MP-1 | Policy and Procedures | 14 |
MP-2 | Media Access | 13 |
MP-6 | Media Sanitization | 25 |
MP-7 | Media Use | 13 |
PE-1 | Policy and Procedures | 14 |
PE-12 | Emergency Lighting | 5 |
PE-13 | Fire Protection | 10 |
PE-14 | Environmental Controls | 8 |
PE-15 | Water Damage Protection. Protect the system from damage resulting from water leakage by providing master shutoff or isolation valves that are accessible, working properly, and know | 7 |
PE-16 | Delivery and Removal | 13 |
PE-2 | Physical Access Authorizations | 15 |
PE-3 | Physical Access Control | 19 |
PE-6 | Monitoring Physical Access | 16 |
PE-8 | Visitor Access Records | 12 |
PL-1 | Policy and Procedures | 18 |
PL-10 | Baseline Selection. Select a control baseline for the system | 13 |
PL-11 | Baseline Tailoring. Tailor the selected control baseline by applying specified tailoring actions | 9 |
PL-2 | System Security and Privacy Plans | 28 |
PL-4 | Rules of Behavior | 19 |
PM-1 | Information Security Program Plan | 0 |
PM-10 | Authorization Process | 0 |
PM-11 | Mission and Business Process Definition | 0 |
PM-12 | Insider Threat Program | 0 |
PM-13 | Security and Privacy Workforce | 0 |
PM-14 | Testing, Training, and Monitoring | 0 |
PM-15 | Security and Privacy Groups and Associations | 0 |
PM-16 | Threat Awareness Program | 0 |
PM-17 | Protecting CUI on External Systems | 0 |
PM-18 | Privacy Program Plan | 0 |
PM-19 | Privacy Program Leadership Role | 0 |
PM-2 | Information Security Program Leadership Role | 0 |
PM-20 | Dissemination of Privacy Program Information | 0 |
PM-21 | Accounting of Disclosures | 0 |
PM-22 | Personally Identifiable Information Quality Management | 0 |
PM-23 | Data Governance Body | 0 |
PM-24 | Data Integrity Board | 0 |
PM-25 | Minimization of PII Used in Testing, Training, and Research | 0 |
PM-26 | Complaint Management | 0 |
PM-27 | Privacy Reporting | 0 |
PM-28 | Risk Framing | 0 |
PM-29 | Risk Management Program Leadership Roles | 0 |
PM-3 | Information Security and Privacy Resources | 0 |
PM-30 | Supply Chain Risk Management Strategy | 0 |
PM-31 | Continuous Monitoring Strategy | 0 |
PM-32 | Purposing | 0 |
PM-4 | Plan of Action and Milestones Process | 0 |
PM-5 | System Inventory | 0 |
PM-6 | Measures of Performance | 0 |
PM-7 | Enterprise Architecture | 0 |
PM-8 | Critical Infrastructure Plan | 0 |
PM-9 | Risk Management Strategy | 0 |
PS-1 | Policy and Procedures | 14 |
PS-2 | Position Risk Designation | 10 |
PS-3 | Personnel Screening | 20 |
PS-4 | Personnel Termination | 20 |
PS-5 | Personnel Transfer | 18 |
PS-6 | Access Agreements | 15 |
PS-7 | External Personnel Security | 19 |
PS-8 | Personnel Sanctions | 12 |
PS-9 | Position Descriptions. Incorporate security and privacy roles and responsibilities into organizational position descriptions | 22 |
PT-1 | Policy and Procedures | 0 |
PT-2 | Authority to Process PII | 0 |
PT-3 | PII Processing Purposes | 0 |
PT-4 | Consent | 0 |
PT-5 | Privacy Notice | 0 |
PT-6 | System of Records Notice | 0 |
PT-7 | Specific Categories of PII | 0 |
PT-8 | Computer Matching Requirements | 0 |
RA-1 | Policy and Procedures | 86 |
RA-2 | Security Categorization | 28 |
RA-3 | Risk Assessment | 33 |
RA-5 | Vulnerability Monitoring and Scanning | 28 |
RA-7 | Risk Response | 11 |
SA-1 | Policy and Procedures | 18 |
SA-2 | Allocation of Resources | 11 |
SA-22 | Unsupported System Components. a. Replace system components when support for the components is no longer available from the developer, vendor, or manufacturer; or b. Provide the fo | 18 |
SA-3 | System Development Life Cycle | 21 |
SA-4 | Acquisition Process | 22 |
SA-5 | System Documentation | 13 |
SA-8 | Security and Privacy Engineering Principles | 19 |
SA-9 | External System Services | 30 |
SC-1 | Policy and Procedures | 13 |
SC-12 | Cryptographic Key Establishment and Management | 15 |
SC-13 | Cryptographic Protection | 22 |
SC-15 | Collaborative Computing Devices and Applications | 5 |
SC-20 | Secure Name/Address Resolution Service (Authoritative) | 5 |
SC-21 | Secure Name/Address Resolution Service (Recursive or Caching Resolver) | 6 |
SC-22 | Architecture and Provisioning for Name/Address Resolution Service | 5 |
SC-39 | Process Isolation | 9 |
SC-5 | Denial-of-Service Protection | 15 |
SC-7 | Boundary Protection | 25 |
SI-1 | Policy and Procedures | 14 |
SI-12 | Information Management and Retention | 26 |
SI-2 | Flaw Remediation | 26 |
SI-3 | Malicious Code Protection | 25 |
SI-4 | System Monitoring | 24 |
SI-5 | Security Alerts, Advisories, and Directives | 23 |
SR-1 | Policy and Procedures (SR-1) | 17 |
SR-10 | Inspection of Systems or Components (SR-10) | 8 |
SR-11 | Component Authenticity (SR-11) | 12 |
SR-12 | Component Disposal (SR-12) | 16 |
SR-2 | Supply Chain Risk Management Plan (SR-2) | 18 |
SR-3 | Supply Chain Controls and Processes (SR-3) | 27 |
SR-5 | Acquisition Strategies, Tools, and Methods (SR-5) | 20 |
SR-8 | Notification Agreements (SR-8) | 15 |