AC-1 | Policy and Procedures | 20 |
AC-10 | Concurrent Session Control | 0 |
AC-11 | Device Lock | 12 |
AC-11(1) | Device Lock | Pattern-hiding Displays. Conceal, via the device lock, information previously visible on the display with a publicly viewable image | 8 |
AC-12 | Session Termination | 10 |
AC-14 | Permitted Actions Without Identification or Authentication | 3 |
AC-17 | Remote Access | 20 |
AC-17(1) | Monitoring and Control | 13 |
AC-17(2) | Protection of Confidentiality and Integrity Using Encryption | 16 |
AC-17(3) | Managed Access Control Points | 16 |
AC-17(4) | Privileged Commands and Access | 12 |
AC-18 | Wireless Access | 9 |
AC-18(1) | Authentication and Encryption | 10 |
AC-18(3) | Wireless Access | Disable Wireless Networking. Disable, when not intended for use, wireless networking capabilities embedded within system components prior to issuance and deployme | 7 |
AC-19 | Access Control for Mobile Devices | 16 |
AC-19(5) | Full Device or Container-Based Encryption | 14 |
AC-2 | Account Management | 95 |
AC-2(1) | Automated System Account Management | 9 |
AC-2(11) | Usage Conditions | 0 |
AC-2(12) | Account Monitoring for Atypical Usage | 15 |
AC-2(13) | Disable Accounts for High-Risk Individuals | 13 |
AC-2(2) | Automated Temporary and Emergency Account Management | 10 |
AC-2(3) | Disable Accounts | 19 |
AC-2(4) | Automated Audit Actions | 12 |
AC-2(5) | Inactivity Logout | 12 |
AC-20 | Use of External Systems | 17 |
AC-20(1) | Limits on Authorized Use | 14 |
AC-20(2) | Portable Storage Devices Restricted Use | 13 |
AC-21 | Information Sharing | 14 |
AC-22 | Publicly Accessible Content | 11 |
AC-3 | Access Enforcement | 36 |
AC-4 | Information Flow Enforcement | 22 |
AC-4(4) | Flow Control of Encrypted Information | 0 |
AC-5 | Separation of Duties | 19 |
AC-6 | Least Privilege | 26 |
AC-6(1) | Authorize Access to Security Functions | 14 |
AC-6(10) | Prohibit Non-Privileged Users from Executing Privileged Functions | 15 |
AC-6(2) | Non-Privileged Access for Nonsecurity Functions | 15 |
AC-6(3) | Network Access to Privileged Commands | 0 |
AC-6(5) | Privileged Accounts | 16 |
AC-6(7) | Review of User Privileges | 20 |
AC-6(9) | Log Use of Privileged Functions | 14 |
AC-7 | Unsuccessful Logon Attempts | 14 |
AC-8 | System Use Notification | 5 |
AT-1 | Policy and Procedures | 17 |
AT-2 | Literacy Training and Awareness | 31 |
AT-2(2) | Insider Threat | 13 |
AT-2(3) | Social Engineering and Mining | 13 |
AT-3 | Role-Based Training | 29 |
AT-4 | Training Records | 19 |
AU-1 | Policy and Procedures | 15 |
AU-10 | Non-Repudiation | 0 |
AU-11 | Audit Record Retention | 16 |
AU-12 | Audit Record Generation | 23 |
AU-12(1) | System-wide and Time-correlated Audit Trail | 0 |
AU-12(3) | Changes by Authorized Individuals | 0 |
AU-2 | Event Logging | 23 |
AU-3 | Content of Audit Records | 19 |
AU-3(1) | Additional Audit Information | 12 |
AU-4 | Audit Log Storage Capacity | 12 |
AU-5 | Response to Audit Logging Process Failures | 11 |
AU-5(1) | Storage Capacity Warning | 0 |
AU-5(2) | Real-Time Alerts | 0 |
AU-6 | Audit Record Review, Analysis, and Reporting | 27 |
AU-6(1) | Automated Process Integration | 18 |
AU-6(3) | Correlate Audit Record Repositories | 18 |
AU-6(5) | Integrated Analysis of Audit Records | 0 |
AU-6(6) | Correlation with Physical Monitoring | 0 |
AU-7 | Audit Record Reduction and Report Generation | 12 |
AU-7(1) | Automatic Processing | 12 |
AU-8 | Time Stamps | 12 |
AU-9 | Protection of Audit Information | 18 |
AU-9(2) | Store on Separate Physical Systems or Components | 0 |
AU-9(3) | Cryptographic Protection | 0 |
AU-9(4) | Access by Subset of Privileged Users | 13 |
CA-1 | Policy and Procedures | 18 |
CA-2 | Control Assessments | 33 |
CA-2(1) | Independent Assessors | 23 |
CA-3 | Information Exchange | 18 |
CA-5 | Plan of Action and Milestones | 30 |
CA-6 | Authorization | 19 |
CA-7 | Continuous Monitoring | 33 |
CA-7(1) | Independent Assessment | 13 |
CA-7(4) | Continuous Monitoring | Risk Monitoring. Ensure risk monitoring is an integral part of the continuous monitoring strategy that includes the following: (a) Effectiveness monitoring; | 17 |
CA-8 | Penetration Testing | 65 |
CA-9 | Internal System Connections | 163 |
CM-1 | Policy and Procedures | 13 |
CM-10 | Software Usage Restrictions | 17 |
CM-11 | User-Installed Software | 22 |
CM-12 | Information Location. a. Identify and document the location of [Assignment: organization-defined information] and the specific system components on which the information is process | 20 |
CM-12(1) | Information Location | Automated Tools to Support Information Location. Use automated tools to identify [Assignment: organization-defined information by information type] on [Assig | 11 |
CM-2 | Baseline Configuration | 19 |
CM-2(2) | Automation Support for Accuracy and Currency | 12 |
CM-2(3) | Retention of Previous Configurations | 11 |
CM-2(7) | Configure Systems and Components for High-Risk Areas | 5 |
CM-3 | Configuration Change Control | 18 |
CM-3(1) | Automated Documentation, Notification, and Prohibition | 0 |
CM-3(2) | Testing, Validation, and Documentation of Changes | 14 |
CM-3(4) | Security and Privacy Representatives | 9 |
CM-3(6) | Cryptography Management | 1 |
CM-4 | Impact Analyses | 17 |
CM-4(2) | Impact Analyses | Verification of Controls. After system changes, verify that the impacted controls are implemented correctly, operating as intended, and producing the desired outc | 14 |
CM-5 | Access Restrictions for Change | 19 |
CM-5(1) | Access Restrictions for Change | Automated Access Enforcement and Audit Records. (a) Enforce access restrictions using [Assignment: organization-defined automated mechanisms]; and | 14 |
CM-6 | Configuration Settings | 23 |
CM-7 | Least Functionality | 20 |
CM-7(1) | Periodic Review | 17 |
CM-7(2) | Prevent Program Execution | 16 |
CM-7(5) | Authorized Software Allow-by-Exception | 18 |
CM-8 | System Component Inventory | 26 |
CM-8(1) | Updates During Installation and Removal | 13 |
CM-8(3) | Automated Unauthorized Component Detection | 14 |
CM-8(4) | Accountability Information | 1 |
CM-9 | Configuration Management Plan | 14 |
CP-1 | Policy and Procedures | 17 |
CP-10 | System Recovery and Reconstitution | 21 |
CP-10(2) | System Recovery and Reconstitution | Transaction Recovery. Implement transaction recovery for systems that are transaction-based | 7 |
CP-10(4) | Restore Within Time Period | 0 |
CP-2 | Contingency Plan | 24 |
CP-2(1) | Coordinate with Related Plans | 10 |
CP-2(2) | Capacity Planning | 0 |
CP-2(3) | Resume Mission and Business Functions | 13 |
CP-2(5) | Continue Mission and Business Functions | 0 |
CP-2(8) | Contingency Plan | Identify Critical Assets. Identify critical system assets supporting [Selection: all; essential] mission and business functions | 15 |
CP-3 | Contingency Training | 15 |
CP-3(1) | Simulated Events | 0 |
CP-4 | Contingency Plan Testing | 24 |
CP-4(1) | Coordinate with Related Plans | 12 |
CP-4(2) | Alternate Processing Site | 0 |
CP-6 | Alternate Storage Site | 18 |
CP-6(1) | Alternate Storage Site | Separation from Primary Site. Identify an alternate storage site that is sufficiently separated from the primary storage site to reduce susceptibility to t | 9 |
CP-6(2) | Recovery Time and Recovery Point Objectives | 0 |
CP-6(3) | Alternate Storage Site | Accessibility. Identify potential accessibility problems to the alternate storage site in the event of an area-wide disruption or disaster and outline expl | 5 |
CP-7 | Alternate Processing Site | 15 |
CP-7(1) | Alternate Processing Site | Separation from Primary Site. Identify an alternate processing site that is sufficiently separated from the primary processing site to reduce susceptibi | 6 |
CP-7(2) | Alternate Processing Site | Accessibility. Identify potential accessibility problems to alternate processing sites in the event of an area-wide disruption or disaster and outlines | 7 |
CP-7(3) | Alternate Processing Site | Priority of Service. Develop alternate processing site agreements that contain priority-of-service provisions in accordance with availability requiremen | 6 |
CP-7(4) | Preparation for Use | 0 |
CP-8 | Telecommunications Services | 10 |
CP-8(1) | Telecommunications Services | Priority of Service Provisions. (a) Develop primary and alternate telecommunications service agreements that contain priority-of-service provisions in | 6 |
CP-8(2) | Telecommunications Services | Single Points of Failure. Obtain alternate telecommunications services to reduce the likelihood of sharing a single point of failure with primary tele | 9 |
CP-8(3) | Separation of Primary and Alternate Providers | 0 |
CP-8(4) | Provider Contingency Plan | 0 |
CP-9 | System Backup | 23 |
CP-9(1) | Testing for Reliability and Integrity | 19 |
CP-9(2) | Test Restoration Using Sampling | 0 |
CP-9(3) | Separate Storage for Critical Information | 0 |
CP-9(5) | Transfer to Alternate Storage Site | 0 |
CP-9(8) | System Backup | Cryptographic Protection. Implement cryptographic mechanisms to prevent unauthorized disclosure and modification of [Assignment: organization-defined backup informa | 16 |
IA-1 | Policy and Procedures | 13 |
IA-10 | Adaptive Authentication | 0 |
IA-11 | Re-Authentication | 11 |
IA-12 | Identity Proofing. a. Identity proof users that require accounts for logical access to systems based on appropriate identity assurance level requirements as specified in applicable | 10 |
IA-2 | Identification and Authentication (Organizational Users) | 24 |
IA-3 | Device Identification and Authentication | 16 |
IA-4 | Identifier Management | 22 |
IA-5 | Authenticator Management | 23 |
IA-6 | Authentication Feedback | 8 |
IA-7 | Cryptographic Module Authentication | 10 |
IA-8 | Identification and Authentication (Non-Organizational Users) | 19 |
IR-1 | Policy and Procedures | 19 |
IR-2 | Incident Response Training | 39 |
IR-3 | Incident Response Testing | 23 |
IR-4 | Incident Handling | 68 |
IR-5 | Incident Monitoring | 27 |
IR-6 | Incident Reporting | 31 |
IR-7 | Incident Response Assistance | 16 |
IR-8 | Incident Response Plan | 29 |
MA-1 | Policy and Procedures | 8 |
MA-2 | Controlled Maintenance | 14 |
MA-3 | Maintenance Tools. a. Approve, control, and monitor the use of system maintenance tools; and b. Review previously approved system maintenance tools [Assignment: organization-define | 9 |
MA-4 | Nonlocal Maintenance | 15 |
MA-5 | Maintenance Personnel | 12 |
MA-6 | Timely Maintenance. Obtain maintenance support and/or spare parts for [Assignment: organization-defined system components] within [Assignment: organization-defined time period] of | 7 |
MP-1 | Policy and Procedures | 14 |
MP-2 | Media Access | 13 |
MP-3 | Media Marking | 13 |
MP-4 | Media Storage | 17 |
MP-5 | Media Transport | 16 |
MP-6 | Media Sanitization | 25 |
MP-7 | Media Use | 13 |
PE-1 | Policy and Procedures | 14 |
PE-10 | Emergency Shutoff. a. Provide the capability of shutting off power to [Assignment: organization-defined system or individual system components] in emergency situations; b. Place em | 6 |
PE-11 | Emergency Power. Provide an uninterruptible power supply to facilitate [Selection (one or more): an orderly shutdown of the system; transition of the system to long-term alternate | 8 |
PE-12 | Emergency Lighting | 5 |
PE-13 | Fire Protection | 10 |
PE-14 | Environmental Controls | 8 |
PE-15 | Water Damage Protection. Protect the system from damage resulting from water leakage by providing master shutoff or isolation valves that are accessible, working properly, and know | 7 |
PE-16 | Delivery and Removal | 13 |
PE-17 | Alternate Work Site | 15 |
PE-18 | Location of System Components | 0 |
PE-19 | Information Leakage | 0 |
PE-2 | Physical Access Authorizations | 15 |
PE-20 | Asset Monitoring and Tracking | 0 |
PE-3 | Physical Access Control | 19 |
PE-4 | Access Control for Transmission. Control physical access to [Assignment: organization-defined system distribution and transmission lines] within organizational facilities using [As | 9 |
PE-5 | Access Control for Output Devices. Control physical access to output from [Assignment: organization-defined output devices] to prevent unauthorized individuals from obtaining the o | 10 |
PE-6 | Monitoring Physical Access | 16 |
PE-8 | Visitor Access Records | 12 |
PE-9 | Power Equipment and Cabling. Protect power equipment and power cabling for the system from damage and destruction | 8 |
PL-1 | Policy and Procedures | 18 |
PL-10 | Baseline Selection. Select a control baseline for the system | 13 |
PL-11 | Baseline Tailoring. Tailor the selected control baseline by applying specified tailoring actions | 9 |
PL-2 | System Security and Privacy Plans | 28 |
PL-4 | Rules of Behavior | 19 |
PL-8 | Security and Privacy Architectures | 16 |
PM-1 | Information Security Program Plan | 0 |
PM-10 | Authorization Process | 0 |
PM-11 | Mission and Business Process Definition | 0 |
PM-12 | Insider Threat Program | 0 |
PM-13 | Security and Privacy Workforce | 0 |
PM-14 | Testing, Training, and Monitoring | 0 |
PM-15 | Security and Privacy Groups and Associations | 0 |
PM-16 | Threat Awareness Program | 0 |
PM-17 | Protecting CUI on External Systems | 0 |
PM-18 | Privacy Program Plan | 0 |
PM-19 | Privacy Program Leadership Role | 0 |
PM-2 | Information Security Program Leadership Role | 0 |
PM-20 | Dissemination of Privacy Program Information | 0 |
PM-21 | Accounting of Disclosures | 0 |
PM-22 | Personally Identifiable Information Quality Management | 0 |
PM-23 | Data Governance Body | 0 |
PM-24 | Data Integrity Board | 0 |
PM-25 | Minimization of PII Used in Testing, Training, and Research | 0 |
PM-26 | Complaint Management | 0 |
PM-27 | Privacy Reporting | 0 |
PM-28 | Risk Framing | 0 |
PM-29 | Risk Management Program Leadership Roles | 0 |
PM-3 | Information Security and Privacy Resources | 0 |
PM-30 | Supply Chain Risk Management Strategy | 0 |
PM-31 | Continuous Monitoring Strategy | 0 |
PM-32 | Purposing | 0 |
PM-4 | Plan of Action and Milestones Process | 0 |
PM-5 | System Inventory | 0 |
PM-6 | Measures of Performance | 0 |
PM-7 | Enterprise Architecture | 0 |
PM-8 | Critical Infrastructure Plan | 0 |
PM-9 | Risk Management Strategy | 0 |
PS-1 | Policy and Procedures | 14 |
PS-2 | Position Risk Designation | 10 |
PS-3 | Personnel Screening | 20 |
PS-4 | Personnel Termination | 20 |
PS-5 | Personnel Transfer | 18 |
PS-6 | Access Agreements | 15 |
PS-7 | External Personnel Security | 19 |
PS-8 | Personnel Sanctions | 12 |
PS-9 | Position Descriptions. Incorporate security and privacy roles and responsibilities into organizational position descriptions | 22 |
PT-1 | Policy and Procedures | 0 |
PT-2 | Authority to Process PII | 0 |
PT-3 | PII Processing Purposes | 0 |
PT-4 | Consent | 0 |
PT-5 | Privacy Notice | 0 |
PT-6 | System of Records Notice | 0 |
PT-7 | Specific Categories of PII | 0 |
PT-8 | Computer Matching Requirements | 0 |
RA-1 | Policy and Procedures | 86 |
RA-2 | Security Categorization | 28 |
RA-3 | Risk Assessment | 33 |
RA-5 | Vulnerability Monitoring and Scanning | 28 |
RA-7 | Risk Response | 11 |
RA-9 | Criticality Analysis. Identify critical system components and functions by performing a criticality analysis for [Assignment: organization-defined systems, system components, or sy | 18 |
SA-1 | Policy and Procedures | 18 |
SA-10 | Developer Configuration Management | 13 |
SA-11 | Developer Testing and Evaluation | 19 |
SA-15 | Development Process, Standards, and Tools. a. Require the developer of the system, system component, or system service to follow a documented development process that: 1. Explicitl | 16 |
SA-16 | Developer-Provided Training | 0 |
SA-17 | Developer Security and Privacy Architecture and Design | 0 |
SA-2 | Allocation of Resources | 11 |
SA-22 | Unsupported System Components. a. Replace system components when support for the components is no longer available from the developer, vendor, or manufacturer; or b. Provide the fo | 18 |
SA-3 | System Development Life Cycle | 21 |
SA-4 | Acquisition Process | 22 |
SA-5 | System Documentation | 13 |
SA-8 | Security and Privacy Engineering Principles | 19 |
SA-9 | External System Services | 30 |
SC-1 | Policy and Procedures | 13 |
SC-10 | Network Disconnect | 10 |
SC-12 | Cryptographic Key Establishment and Management | 15 |
SC-13 | Cryptographic Protection | 22 |
SC-15 | Collaborative Computing Devices and Applications | 5 |
SC-17 | Public Key Infrastructure Certificates | 9 |
SC-18 | Mobile Code | 12 |
SC-2 | Separation of System and User Functionality | 13 |
SC-20 | Secure Name/Address Resolution Service (Authoritative) | 5 |
SC-21 | Secure Name/Address Resolution Service (Recursive or Caching Resolver) | 6 |
SC-22 | Architecture and Provisioning for Name/Address Resolution Service | 5 |
SC-23 | Session Authenticity | 17 |
SC-24 | Fail in Known State | 0 |
SC-28 | Protection of Information at Rest | 23 |
SC-3 | Security Function Isolation | 0 |
SC-39 | Process Isolation | 9 |
SC-4 | Information in Shared System Resources | 11 |
SC-5 | Denial-of-Service Protection | 15 |
SC-7 | Boundary Protection | 25 |
SC-8 | Transmission Confidentiality and Integrity | 26 |
SI-1 | Policy and Procedures | 14 |
SI-10 | Information Input Validation | 13 |
SI-11 | Error Handling | 6 |
SI-12 | Information Management and Retention | 26 |
SI-14 | Non-persistence | 0 |
SI-16 | Memory Protection | 8 |
SI-2 | Flaw Remediation | 26 |
SI-3 | Malicious Code Protection | 25 |
SI-4 | System Monitoring | 24 |
SI-5 | Security Alerts, Advisories, and Directives | 23 |
SI-6 | Security and Privacy Function Verification. a. Verify the correct operation of [Assignment: organization-defined security and privacy functions]; b. Perform the verification of the | 10 |
SI-7 | Software, Firmware, and Information Integrity | 18 |
SI-8 | Spam Protection | 12 |
SR-1 | Policy and Procedures (SR-1) | 17 |
SR-10 | Inspection of Systems or Components (SR-10) | 8 |
SR-11 | Component Authenticity (SR-11) | 12 |
SR-12 | Component Disposal (SR-12) | 16 |
SR-2 | Supply Chain Risk Management Plan (SR-2) | 18 |
SR-3 | Supply Chain Controls and Processes (SR-3) | 27 |
SR-5 | Acquisition Strategies, Tools, and Methods (SR-5) | 20 |
SR-6 | Supplier Assessments and Reviews (SR-6) | 26 |
SR-8 | Notification Agreements (SR-8) | 15 |
SR-9 | Tamper Resistance and Detection (SR-9) | 0 |