NIST800-AC-1 | Access control policy and procedures | 29 |
NIST800-AC-10 | Concurrent Session Control. Limit the number of concurrent sessions for each [organization-defined] to [organization-defined] | 2 |
NIST800-AC-11 | Device lock | 16 |
NIST800-AC-12 | Session control | 16 |
NIST800-AC-14 | Permitted actions without identification or authentication | 9 |
NIST800-AC-16 | Security and Privacy Attributes. Provide the means to associate [organization-defined] with [organization-defined] for information in storage, in process, and/or in transmission; E | 12 |
NIST800-AC-17 | Remote access | 30 |
NIST800-AC-18 | Wireless access | 16 |
NIST800-AC-19 | Access control for mobile devices | 23 |
NIST800-AC-2 | Account management | 104 |
NIST800-AC-20 | Use of external systems | 97 |
NIST800-AC-21 | Information Sharing. Enable authorized users to determine whether access authorizations assigned to a sharing partner match the information's access and use restrictions for [organ | 19 |
NIST800-AC-22 | Publicly accessible content | 17 |
NIST800-AC-23 | Data Mining Protection. Employ [organization-defined] for [organization-defined] to detect and protect against unauthorized data mining | 7 |
NIST800-AC-24 | Access Control Decisions. [organization-defined] to ensure [organization-defined] are applied to each access request prior to access enforcement | 13 |
NIST800-AC-25 | Reference Monitor. Implement a reference monitor for [organization-defined] that is tamperproof, always invoked, and small enough to be subject to analysis and testing, the complet | 0 |
NIST800-AC-3 | Access enforcement | 44 |
NIST800-AC-4 | Information flow enforcement | 30 |
NIST800-AC-5 | Separation of duties | 24 |
NIST800-AC-6 | Least privilege | 79 |
NIST800-AC-7 | Unsuccessful logon attempts | 89 |
NIST800-AC-8 | System Use Notification. Display [organization-defined] to users before granting access to the system that provides privacy and security notices consistent with applicable laws, ex | 11 |
NIST800-AC-9 | Previous Logon Notification. Notify the user, upon successful logon to the system, of the date and time of the last logon | 3 |
NIST800-AT-1 | Policy and procedures for awareness and training | 22 |
NIST800-AT-2 | Literacy training and awareness | 37 |
NIST800-AT-3 | Role-based training | 82 |
NIST800-AT-4 | Training records | 24 |
NIST800-AT-6 | Training feedback | 6 |
NIST800-AU-1 | Policy and procedures for audit and accountability | 19 |
NIST800-AU-10 | Non-repudiation. Provide irrefutable evidence that an individual (or process acting on behalf of an individual) has performed [organization-defined] | 17 |
NIST800-AU-11 | Audit record retention | 26 |
NIST800-AU-12 | Audit record generation | 61 |
NIST800-AU-13 | Monitoring for Information Disclosure. Monitor [organization-defined] [organization-defined] for evidence of unauthorized disclosure of organizational information; and If an inform | 18 |
NIST800-AU-14 | Session Audit. Provide and implement the capability for [organization-defined] to [organization-defined] the content of a user session under [organization-defined] ; and Develop, i | 6 |
NIST800-AU-16 | Cross-organizational Audit Logging. Employ [organization-defined] for coordinating [organization-defined] among external organizations when audit information is transmitted across | 7 |
NIST800-AU-2 | Event logging | 67 |
NIST800-AU-3 | Content of audit records | 55 |
NIST800-AU-4 | Audit log storage capacity | 17 |
NIST800-AU-5 | Response to audit logging process failures | 15 |
NIST800-AU-6 | Audit record review, analysis, and reporting | 40 |
NIST800-AU-7 | Audit record reduction and report generation | 15 |
NIST800-AU-8 | Time stamps | 17 |
NIST800-AU-9 | Protection of audit information | 22 |
NIST800-CA-1 | Policy and procedures for assessment, authorization, and monitoring | 22 |
NIST800-CA-2 | Control assessments | 42 |
NIST800-CA-3 | Information exchange | 28 |
NIST800-CA-5 | Plan of action and milestones | 38 |
NIST800-CA-6 | Authorization | 22 |
NIST800-CA-7 | Continuous monitoring | 77 |
NIST800-CA-8 | Penetration testing | 61 |
NIST800-CA-9 | Internal system connections | 17 |
NIST800-CM-1 | Policy and procedures for configuration management | 23 |
NIST800-CM-10 | Software usage restrictions | 21 |
NIST800-CM-11 | User-installed software | 25 |
NIST800-CM-12 | Information Location. Identify and document the location of [organization-defined] and the specific system components on which the information is processed and stored; Identify and | 21 |
NIST800-CM-13 | Data Action Mapping. Develop and document a map of system data actions | 11 |
NIST800-CM-14 | Signed Components. Prevent the installation of [organization-defined] without verification that the component has been digitally signed using a certificate that is recognized and a | 16 |
NIST800-CM-2 | Baseline configuration | 29 |
NIST800-CM-3 | Configuration change control | 56 |
NIST800-CM-4 | Impact analyses | 60 |
NIST800-CM-5 | Access restrictions for change | 22 |
NIST800-CM-6 | Configuration settings | 37 |
NIST800-CM-7 | Least functionality | 28 |
NIST800-CM-8 | System component inventory | 41 |
NIST800-CM-9 | Configuration management plan | 58 |
NIST800-CP-1 | Policy and procedures for contingency planning | 24 |
NIST800-CP-10 | System recovery and reconstitution | 72 |
NIST800-CP-11 | Alternate Communications Protocols. Provide the capability to employ [organization-defined] in support of maintaining continuity of operations | 14 |
NIST800-CP-12 | Safe Mode. When [organization-defined] are detected, enter a safe mode of operation with [organization-defined] | 3 |
NIST800-CP-13 | Alternative Security Mechanisms. Employ [organization-defined] for satisfying [organization-defined] when the primary means of implementing the security function is unavailable or | 6 |
NIST800-CP-2 | Contingency plan | 29 |
NIST800-CP-3 | Contingency training | 19 |
NIST800-CP-4 | Contingency plan testing | 27 |
NIST800-CP-6 | Alternate storage site | 20 |
NIST800-CP-7 | Alternate processing site | 17 |
NIST800-CP-8 | Telecommunications services | 18 |
NIST800-CP-9 | System backup | 78 |
NIST800-IA-1 | Policy and procedures for identification and authentication | 19 |
NIST800-IA-10 | Adaptive Authentication. Require individuals accessing the system to employ [organization-defined] under specific [organization-defined] | 7 |
NIST800-IA-11 | Re-authentication | 16 |
NIST800-IA-12 | Identity proofing | 14 |
NIST800-IA-13 | Identity Providers and Authorization Servers. Employ identity providers and authorization servers to manage user, device, and non-person entity (NPE) identities, attributes, and ac | 12 |
NIST800-IA-2 | Identification and authentication of organizational users | 36 |
NIST800-IA-3 | Device identification and authentication | 21 |
NIST800-IA-4 | Identifier management | 78 |
NIST800-IA-5 | Authenticator management | 32 |
NIST800-IA-6 | Authentication feedback | 10 |
NIST800-IA-7 | Cryptographic module authentication | 107 |
NIST800-IA-8 | Identification and authentication of non-organizational users | 76 |
NIST800-IA-9 | Service Identification and Authentication. Uniquely identify and authenticate [organization-defined] before establishing communications with devices, users, or other services or ap | 15 |
NIST800-IR-1 | Policy and procedures for incident response | 24 |
NIST800-IR-2 | Incident response training | 103 |
NIST800-IR-3 | Incident response testing | 24 |
NIST800-IR-4 | Incident handling | 46 |
NIST800-IR-5 | Incident monitoring | 114 |
NIST800-IR-6 | Incident reporting | 40 |
NIST800-IR-7 | Incident response assistance | 104 |
NIST800-IR-8 | Incident response plan | 35 |
NIST800-IR-9 | Information Spillage Response. Respond to information spills by: Assigning [organization-defined] with responsibility for responding to information spills; Identifying the specific | 13 |
NIST800-MA-1 | Policy and procedures for maintenance | 17 |
NIST800-MA-2 | Controlled maintenance | 21 |
NIST800-MA-3 | Maintenance tools | 12 |
NIST800-MA-4 | Nonlocal maintenance | 22 |
NIST800-MA-5 | Maintenance personnel | 16 |
NIST800-MA-6 | Timely Maintenance. Obtain maintenance support and/or spare parts for [organization-defined] within [organization-defined] of failure | 13 |
NIST800-MA-7 | Field Maintenance. Restrict or prohibit field maintenance on [organization-defined] to [organization-defined] | 5 |
NIST800-MP-1 | Policy and procedures for media protection | 20 |
NIST800-MP-2 | Media access | 21 |
NIST800-MP-3 | Media marking | 17 |
NIST800-MP-4 | Media storage | 24 |
NIST800-MP-5 | Media transport | 22 |
NIST800-MP-6 | Media sanitization | 33 |
NIST800-MP-7 | Media use | 19 |
NIST800-MP-8 | Media Downgrading. Establish [organization-defined] that includes employing downgrading mechanisms with strength and integrity commensurate with the security category or classifica | 4 |
NIST800-PE-1 | Policy and procedures for physical and environmental protection | 23 |
NIST800-PE-10 | Emergency shutoff | 10 |
NIST800-PE-11 | Emergency power | 11 |
NIST800-PE-12 | Emergency lighting | 9 |
NIST800-PE-13 | Fire protection | 12 |
NIST800-PE-14 | Environmental controls | 33 |
NIST800-PE-15 | Water damage protection | 11 |
NIST800-PE-16 | Delivery and Removal. Authorize and control [organization-defined] entering and exiting the facility; and Maintain records of the system components | 18 |
NIST800-PE-17 | Alternate work site | 18 |
NIST800-PE-18 | Location of System Components. Position system components within the facility to minimize potential damage from [organization-defined] and to minimize the opportunity for unauthori | 11 |
NIST800-PE-19 | Information Leakage. Protect the system from information leakage due to electromagnetic signals emanations | 3 |
NIST800-PE-2 | Physical access authorizations | 76 |
NIST800-PE-20 | Asset Monitoring and Tracking. Employ [organization-defined] to track and monitor the location and movement of [organization-defined] within [organization-defined] | 13 |
NIST800-PE-21 | Electromagnetic Pulse Protection. Employ [organization-defined] against electromagnetic pulse damage for [organization-defined] | 0 |
NIST800-PE-22 | Component Marking. Mark [organization-defined] indicating the impact level or classification level of the information permitted to be processed, stored, or transmitted by the hardw | 7 |
NIST800-PE-23 | Facility Location. Plan the location or site of the facility where the system resides considering physical and environmental hazards; and For existing facilities, consider the phys | 11 |
NIST800-PE-3 | Physical access control | 45 |
NIST800-PE-4 | Access control for transmission | 12 |
NIST800-PE-5 | Access control for output devices | 12 |
NIST800-PE-6 | Monitoring physical access | 21 |
NIST800-PE-8 | Visitor access records | 17 |
NIST800-PE-9 | Power equipment and cabling | 12 |
NIST800-PL-1 | Policy and procedures for planning | 25 |
NIST800-PL-10 | Baseline selection | 19 |
NIST800-PL-11 | Baseline tailoring | 16 |
NIST800-PL-2 | System security and privacy plans | 34 |
NIST800-PL-4 | Rules of behavior | 25 |
NIST800-PL-7 | Concept of Operations. Develop a Concept of Operations (CONOPS) for the system describing how the organization intends to operate the system from the perspective of information sec | 7 |
NIST800-PL-8 | Security and privacy architectures | 25 |
NIST800-PL-9 | Central Management. Centrally manage [organization-defined] | 9 |
NIST800-PM-1 | Information Security Program Plan. Develop and disseminate an organization-wide information security program plan that: Provides an overview of the requirements for the security pr | 21 |
NIST800-PM-10 | Authorization Process. Manage the security and privacy state of organizational systems and the environments in which those systems operate through authorization processes; Designat | 10 |
NIST800-PM-11 | Mission and Business Process Definition. Define organizational mission and business processes with consideration for information security and privacy and the resulting risk to orga | 17 |
NIST800-PM-12 | Insider Threat Program. Implement an insider threat program that includes a cross-discipline insider threat incident handling team | 15 |
NIST800-PM-13 | Security and Privacy Workforce. Establish a security and privacy workforce development and improvement program | 17 |
NIST800-PM-14 | Testing, Training, and Monitoring. Implement a process for ensuring that organizational plans for conducting security and privacy testing, training, and monitoring activities assoc | 21 |
NIST800-PM-15 | Security and Privacy Groups and Associations. Establish and institutionalize contact with selected groups and associations within the security and privacy communities: To facilitat | 12 |
NIST800-PM-16 | Threat Awareness Program. Implement a threat awareness program that includes a cross-organization information-sharing capability for threat intelligence | 13 |
NIST800-PM-17 | Protecting Controlled Unclassified Information on External Systems. Establish policy and procedures to ensure that requirements for the protection of controlled unclassified inform | 10 |
NIST800-PM-18 | Privacy Program Plan. Develop and disseminate an organization-wide privacy program plan that provides an overview of the agency's privacy program, and: Includes a description of th | 12 |
NIST800-PM-19 | Privacy Program Leadership Role. Appoint a senior agency official for privacy with the authority, mission, accountability, and resources to coordinate, develop, and implement, appl | 13 |
NIST800-PM-2 | Information Security Program Leadership Role. Appoint a senior agency information security officer with the mission and resources to coordinate, develop, implement, and maintain an | 22 |
NIST800-PM-20 | Dissemination of Privacy Program Information. Maintain a central resource webpage on the organization's principal public website that serves as a central source of information abou | 10 |
NIST800-PM-21 | Accounting of Disclosures. Develop and maintain an accurate accounting of disclosures of personally identifiable information, including: Date, nature, and purpose of each disclosur | 15 |
NIST800-PM-22 | Personally Identifiable Information Quality Management. Develop and document organization-wide policies and procedures for: Reviewing for the accuracy, relevance, timeliness, and c | 14 |
NIST800-PM-23 | Data Governance Body. Establish a Data Governance Body consisting of [organization-defined] with [organization-defined] | 14 |
NIST800-PM-24 | Data Integrity Board. Establish a Data Integrity Board to: Review proposals to conduct or participate in a matching program; and Conduct an annual review of all matching programs i | 5 |
NIST800-PM-25 | Minimization of Personally Identifiable Information Used in Testing, Training, and Research. Develop, document, and implement policies and procedures that address the use of person | 11 |
NIST800-PM-26 | Complaint Management. Implement a process for receiving and responding to complaints, concerns, or questions from individuals about the organizational security and privacy practice | 11 |
NIST800-PM-27 | Privacy Reporting. Develop [organization-defined] and disseminate to: [organization-defined] to demonstrate accountability with statutory, regulatory, and policy privacy mandates; | 12 |
NIST800-PM-28 | Risk Framing. Identify and document: Assumptions affecting risk assessments, risk responses, and risk monitoring; Constraints affecting risk assessments, risk responses, and risk m | 23 |
NIST800-PM-29 | Risk Management Program Leadership Roles. Appoint a Senior Accountable Official for Risk Management to align organizational information security and privacy management processes wi | 14 |
NIST800-PM-3 | Information Security and Privacy Resources. Include the resources needed to implement the information security and privacy programs in capital planning and investment requests and | 11 |
NIST800-PM-30 | Supply Chain Risk Management Strategy. Develop an organization-wide strategy for managing supply chain risks associated with the development, acquisition, maintenance, and disposal | 23 |
NIST800-PM-31 | Continuous Monitoring Strategy. Develop an organization-wide continuous monitoring strategy and implement continuous monitoring programs that include: Establishing the following or | 30 |
NIST800-PM-32 | Purposing. Analyze [organization-defined] supporting mission essential services or functions to ensure that the information resources are being used consistent with their intended | 7 |
NIST800-PM-4 | Plan of Action and Milestones Process. Implement a process to ensure that plans of action and milestones for the information security, privacy, and supply chain risk management pro | 22 |
NIST800-PM-5 | System Inventory. Develop and update [organization-defined] an inventory of organizational systems | 18 |
NIST800-PM-6 | Measures of Performance. Develop, monitor, and report on the results of information security and privacy measures of performance | 17 |
NIST800-PM-7 | Enterprise Architecture. Develop and maintain an enterprise architecture with consideration for information security, privacy, and the resulting risk to organizational operations a | 6 |
NIST800-PM-8 | Critical Infrastructure Plan. Address information security and privacy issues in the development, documentation, and updating of a critical infrastructure and key resources protect | 5 |
NIST800-PM-9 | Risk Management Strategy. Develops a comprehensive strategy to manage: Security risk to organizational operations and assets, individuals, other organizations, and the Nation assoc | 21 |
NIST800-PS-1 | Policy and procedures for personnel security | 28 |
NIST800-PS-2 | Position risk designation | 13 |
NIST800-PS-3 | Personnel screening | 34 |
NIST800-PS-4 | Personnel termination | 25 |
NIST800-PS-5 | Personnel transfer | 20 |
NIST800-PS-6 | Access agreements | 22 |
NIST800-PS-7 | External personnel security | 25 |
NIST800-PS-8 | Personnel sanctions | 35 |
NIST800-PS-9 | Position descriptions | 20 |
NIST800-PT-1 | Policy and Procedures. Develop, document, and disseminate to [organization-defined]: [organization-defined] personally identifiable information processing and transparency policy t | 15 |
NIST800-PT-2 | Authority to Process Personally Identifiable Information. Determine and document the [organization-defined] that permits the [organization-defined] of personally identifiable infor | 14 |
NIST800-PT-3 | Personally Identifiable Information Processing Purposes. Identify and document the [organization-defined] for processing personally identifiable information; Describe the purpose(s | 14 |
NIST800-PT-4 | Consent. Implement [organization-defined] for individuals to consent to the processing of their personally identifiable information prior to its collection that facilitate individu | 12 |
NIST800-PT-5 | Privacy Notice. Provide notice to individuals about the processing of personally identifiable information that: Is available to individuals upon first interacting with an organizat | 16 |
NIST800-PT-6 | System of Records Notice. For systems that process information that will be maintained in a Privacy Act system of records: Draft system of records notices in accordance with OMB gu | 4 |
NIST800-PT-7 | Specific Categories of Personally Identifiable Information. Apply [organization-defined] for specific categories of personally identifiable information | 8 |
NIST800-PT-8 | Computer Matching Requirements. When a system or organization processes information for the purpose of conducting a matching program: Obtain approval from the Data Integrity Board | 4 |
NIST800-RA-1 | Policy and procedures for risk assessment | 112 |
NIST800-RA-10 | Threat hunting | 12 |
NIST800-RA-2 | Security categorization | 130 |
NIST800-RA-3 | Risk assessment | 48 |
NIST800-RA-5 | Vulnerability monitoring and scanning | 125 |
NIST800-RA-6 | Technical Surveillance Countermeasures Survey. Employ a technical surveillance countermeasures survey at [organization-defined] [organization-defined] | 1 |
NIST800-RA-7 | Risk response | 29 |
NIST800-RA-8 | Privacy Impact Assessments. Conduct privacy impact assessments for systems, programs, or other activities before: Developing or procuring information technology that processes pers | 13 |
NIST800-RA-9 | Criticality analysis | 23 |
NIST800-SA-1 | Policy and procedures for system and services acquisition | 18 |
NIST800-SA-10 | Developer configuration management | 55 |
NIST800-SA-11 | Developer testing and evaluation | 28 |
NIST800-SA-15 | Development process, standards, and tools | 21 |
NIST800-SA-16 | Developer-provided Training. Require the developer of the system, system component, or system service to provide the following training on the correct use and operation of the impl | 9 |
NIST800-SA-17 | Developer Security and Privacy Architecture and Design. Require the developer of the system, system component, or system service to produce a design specification and security and | 21 |
NIST800-SA-2 | Allocation of resources | 8 |
NIST800-SA-20 | Customized Development of Critical Components. Reimplement or custom develop the following critical system components: [organization-defined] | 4 |
NIST800-SA-21 | Developer Screening. Require that the developer of [organization-defined]: Has appropriate access authorizations as determined by assigned [organization-defined] ; and Satisfies th | 13 |
NIST800-SA-22 | Unsupported System Components | 25 |
NIST800-SA-23 | Specialization. Employ [organization-defined] on [organization-defined] supporting mission essential services or functions to increase the trustworthiness in those systems or compo | 0 |
NIST800-SA-24 | Design For Cyber Resiliency. Design organizational systems, system components, or system services to achieve cyber resiliency by: Defining the following cyber resiliency goals: [or | 9 |
NIST800-SA-3 | System development life cycle | 25 |
NIST800-SA-4 | Acquisition process | 33 |
NIST800-SA-5 | System documentation | 19 |
NIST800-SA-8 | Security and privacy engineering principles | 30 |
NIST800-SA-9 | External system services | 36 |
NIST800-SC-1 | Policy and procedures for system and communications protection | 18 |
NIST800-SC-10 | Network disconnect | 11 |
NIST800-SC-11 | Trusted Path. Provide a [organization-defined] isolated trusted communications path for communications between the user and the trusted components of the system; and Permit users t | 1 |
NIST800-SC-12 | Cryptographic key establishment and management | 101 |
NIST800-SC-13 | Cryptographic protection | 108 |
NIST800-SC-15 | Collaborative computing devices and applications | 4 |
NIST800-SC-16 | Transmission of Security and Privacy Attributes. Associate [organization-defined] with information exchanged between systems and between system components | 7 |
NIST800-SC-17 | Public key infrastructure certificates | 17 |
NIST800-SC-18 | Mobile Code. Define acceptable and unacceptable mobile code and mobile code technologies; and Authorize, monitor, and control the use of mobile code within the system | 17 |
NIST800-SC-2 | Separation of system and user functionality | 16 |
NIST800-SC-20 | Secure name/address resolution service | 8 |
NIST800-SC-21 | Secure name/address resolution service (recursive) | 3 |
NIST800-SC-22 | Architecture and provisioning for name/address resolution service | 33 |
NIST800-SC-23 | Session authenticity | 17 |
NIST800-SC-24 | Fail in Known State. Fail to a [organization-defined] for the following failures on the indicated components while preserving [organization-defined] in failure: [organization-defin | 6 |
NIST800-SC-25 | Thin Nodes. Employ minimal functionality and information storage on the following system components: [organization-defined] | 3 |
NIST800-SC-26 | Decoys. Include components within organizational systems specifically designed to be the target of malicious attacks for detecting, deflecting, and analyzing such attacks | 3 |
NIST800-SC-27 | Platform-independent Applications. Include within organizational systems the following platform independent applications: [organization-defined] | 1 |
NIST800-SC-28 | Protection of information at rest | 34 |
NIST800-SC-29 | Heterogeneity. Employ a diverse set of information technologies for the following system components in the implementation of the system: [organization-defined] | 2 |
NIST800-SC-3 | Security Function Isolation. Isolate security functions from nonsecurity functions | 15 |
NIST800-SC-30 | Concealment and Misdirection. Employ the following concealment and misdirection techniques for [organization-defined] at [organization-defined] to confuse and mislead adversaries: | 3 |
NIST800-SC-31 | Covert Channel Analysis. Perform a covert channel analysis to identify those aspects of communications within the system that are potential avenues for covert [organization-defined | 5 |
NIST800-SC-32 | System Partitioning. Partition the system into [organization-defined] residing in separate [organization-defined] domains or environments based on [organization-defined] | 17 |
NIST800-SC-34 | Non-modifiable Executable Programs. For [organization-defined] , load and execute: The operating environment from hardware-enforced, read-only media; and The following applications | 9 |
NIST800-SC-35 | External Malicious Code Identification. Include system components that proactively seek to identify network-based malicious code or malicious websites | 13 |
NIST800-SC-36 | Distributed Processing and Storage. Distribute the following processing and storage components across multiple [organization-defined]: [organization-defined] | 5 |
NIST800-SC-37 | Out-of-band Channels. Employ the following out-of-band channels for the physical delivery or electronic transmission of [organization-defined] to [organization-defined]: [organizat | 2 |
NIST800-SC-38 | Operations Security. Employ the following operations security controls to protect key organizational information throughout the system development life cycle: [organization-defined | 11 |
NIST800-SC-39 | Process isolation | 12 |
NIST800-SC-4 | Information in shared system resources | 15 |
NIST800-SC-40 | Wireless Link Protection. Protect external and internal [organization-defined] from the following signal parameter attacks: [organization-defined] | 9 |
NIST800-SC-41 | Port and I/O Device Access. [organization-defined] disable or remove [organization-defined] on the following systems or system components: [organization-defined] | 8 |
NIST800-SC-42 | Sensor Capability and Data. Prohibit [organization-defined] ; and Provide an explicit indication of sensor use to [organization-defined] | 9 |
NIST800-SC-43 | Usage Restrictions. Establish usage restrictions and implementation guidelines for the following system components: [organization-defined] ; and Authorize, monitor, and control the | 10 |
NIST800-SC-44 | Detonation Chambers. Employ a detonation chamber capability within [organization-defined] | 3 |
NIST800-SC-45 | System Time Synchronization. Synchronize system clocks within and between systems and system components | 13 |
NIST800-SC-46 | Cross Domain Policy Enforcement. Implement a policy enforcement mechanism [organization-defined] between the physical and/or network interfaces for the connecting security domains | 12 |
NIST800-SC-47 | Alternate Communications Paths. Establish [organization-defined] for system operations organizational command and control | 11 |
NIST800-SC-48 | Sensor Relocation. Relocate [organization-defined] to [organization-defined] under the following conditions or circumstances: [organization-defined] | 0 |
NIST800-SC-49 | Hardware-enforced Separation and Policy Enforcement. Implement hardware-enforced separation and policy enforcement mechanisms between [organization-defined] | 7 |
NIST800-SC-5 | Denial-of-service protection | 19 |
NIST800-SC-50 | Software-enforced Separation and Policy Enforcement. Implement software-enforced separation and policy enforcement mechanisms between [organization-defined] | 7 |
NIST800-SC-51 | Hardware-based Protection. Employ hardware-based, write-protect for [organization-defined] ; and Implement specific procedures for [organization-defined] to manually disable hardwa | 2 |
NIST800-SC-6 | Resource Availability. Protect the availability of resources by allocating [organization-defined] by [organization-defined] | 14 |
NIST800-SC-7 | Boundary protection | 39 |
NIST800-SC-8 | Transmission confidentiality and integrity | 35 |
NIST800-SI-1 | Policy and procedures for system and information integrity | 20 |
NIST800-SI-10 | Information input validation | 16 |
NIST800-SI-11 | Error Handling. Generate error messages that provide information necessary for corrective actions without revealing information that could be exploited; and Reveal error messages o | 10 |
NIST800-SI-12 | Information management and retention | 33 |
NIST800-SI-13 | Predictable Failure Prevention. Determine mean time to failure (MTTF) for the following system components in specific environments of operation: [organization-defined] ; and Provid | 4 |
NIST800-SI-14 | Non-persistence. Implement non-persistent [organization-defined] that are initiated in a known state and terminated [organization-defined] | 5 |
NIST800-SI-15 | Information Output Filtering. Validate information output from the following software programs and/or applications to ensure that the information is consistent with the expected co | 4 |
NIST800-SI-16 | Memory protection | 10 |
NIST800-SI-17 | Fail-safe Procedures. Implement the indicated fail-safe procedures when the indicated failures occur: [organization-defined] | 5 |
NIST800-SI-18 | Personally Identifiable Information Quality Operations. Check the accuracy, relevance, timeliness, and completeness of personally identifiable information across the information li | 15 |
NIST800-SI-19 | De-identification. Remove the following elements of personally identifiable information from datasets: [organization-defined] ; and Evaluate [organization-defined] for effectivenes | 14 |
NIST800-SI-2 | Flaw remediation | 74 |
NIST800-SI-20 | Tainting. Embed data or capabilities in the following systems or system components to determine if organizational data has been exfiltrated or improperly removed from the organizat | 6 |
NIST800-SI-21 | Information Refresh. Refresh [organization-defined] at [organization-defined] or generate the information on demand and delete the information when no longer needed | 6 |
NIST800-SI-22 | Information Diversity. Identify the following alternative sources of information for [organization-defined]: [organization-defined] ; and Use an alternative information source for | 3 |
NIST800-SI-23 | Information Fragmentation. Based on [organization-defined]: Fragment the following information: [organization-defined] ; and Distribute the fragmented information across the follow | 0 |
NIST800-SI-3 | Malicious code protection | 32 |
NIST800-SI-4 | System monitoring | 43 |
NIST800-SI-5 | Security alerts, advisories, and directives | 31 |
NIST800-SI-6 | Security and Privacy Function Verification. Verify the correct operation of [organization-defined]; Perform the verification of the functions specified in SI-6a [organization-defin | 15 |
NIST800-SI-7 | Software, firmware, and information integrity | 26 |
NIST800-SI-8 | Spam Protection. Employ spam protection mechanisms at system entry and exit points to detect and act on unsolicited messages; and Update spam protection mechanisms when new release | 16 |
NIST800-SR-1 | Policy and procedures for supply chain risk management | 19 |
NIST800-SR-10 | Inspection of systems or components | 16 |
NIST800-SR-11 | Component authenticity | 109 |
NIST800-SR-12 | Component disposal | 12 |
NIST800-SR-2 | Supply chain risk management plan | 25 |
NIST800-SR-3 | Supply chain controls and processes | 124 |
NIST800-SR-4 | Provenance. Document, monitor, and maintain valid provenance of the following systems, system components, and associated data: [organization-defined] | 19 |
NIST800-SR-5 | Acquisition strategies, tools, and methods | 24 |
NIST800-SR-6 | Supplier assessments and reviews | 29 |
NIST800-SR-7 | Supply Chain Operations Security. Employ the following Operations Security (OPSEC) controls to protect supply chain-related information for the system, system component, or system | 10 |
NIST800-SR-8 | Notification agreements | 112 |
NIST800-SR-9 | Tamper Resistance and Detection. Implement a tamper protection program for the system, system component, or system service | 10 |
SP800-53-AC | Access Control Family | 4 |
SP800-53-AT | Awareness and Training Family | 14 |
SP800-53-AU | Audit and Accountability Family | 8 |
SP800-53-CA | Assessment, Authorization, and Monitoring Family | 6 |
SP800-53-CM | Configuration Management Family | 8 |
SP800-53-CP | Contingency Planning Family | 8 |
SP800-53-IA | Identification and Authentication Family | 8 |
SP800-53-IR | Incident Response Family | 8 |
SP800-53-MA | Maintenance Family | 4 |
SP800-53-MP | Media Protection Family | 3 |
SP800-53-PE | Physical and Environmental Protection Family | 14 |
SP800-53-PL | Planning Family | 7 |
SP800-53-PM | Program Management Family | 8 |
SP800-53-PS | Personnel Security Family | 9 |
SP800-53-PT | PII Processing and Transparency Family | 6 |
SP800-53-RA | Risk Assessment Family | 18 |
SP800-53-SA | System and Services Acquisition Family | 10 |
SP800-53-SC | System and Communications Protection Family | 6 |
SP800-53-SI | System and Information Integrity Family | 7 |
SP800-53-SR | Supply Chain Risk Management Family | 10 |