NIST SP 800-53 — Security and Privacy Controls for Information Systems and Organizations
NIS2 says what you must achieve, never how you demonstrate it. NIST 800-53 is the reference published for that purpose. If you operate there, this is what your regulator reads.
Reviewed . Verify against the scheme owner before relying on this for a certification decision.
This framework is not compliance
NIST SP 800-53 is a US federal control catalogue. It is not a European compliance route and no supervisor will accept it as one: it carries no certification, and mapping to it does not evidence NIS2 compliance. Its value here is different and real — a group that already operates an 800-53 control set, typically because of US federal or defence work, can see which families already carry each article 21(2) measure instead of rebuilding from nothing.
We put that first because it is the most expensive misunderstanding about any national framework. For a European compliance route use ISO/IEC 27001 or the national framework. Use 800-53 to reuse work already done, not to demonstrate compliance.
3 tiers, cumulative
Each level contains everything below it. The counts are the controls a level adds, because that is the figure that stays stable across publications.
| Level | Adds | Cumulative | Intended for |
|---|---|---|---|
| Low | 149 | 149 | Systems whose loss would have limited adverse impact |
| Moderate | 138 | 287 | Systems whose loss would have serious adverse impact |
| High | 83 | 370 | Systems whose loss would have severe or catastrophic impact |
The smallest baseline of SP 800-53B. It is a selection from the catalogue, not the catalogue itself.
Adds 138 controls and enhancements on top of Low, and contains it entirely.
Adds 83 further controls. The remaining controls of the catalogue belong to no baseline at all and are selected by tailoring.
What it is built on
NIST 800-53 does not invent its own taxonomy. It sits on A control catalogue organised into families, with baselines selected by system impact level.
Revision 5 organises the catalogue into 20 control families, up from 18 in Rev. 4: PT (PII processing and transparency) and SR (supply chain risk management) were added. Controls are selected through baselines and tailoring rather than adopted wholesale.
How it covers the ten NIS2 measures
Article 21(2) is the article of NIS2 — Directive (EU) 2022/2555 — that lists the ten risk-management measures every entity in scope owes, lettered (a) to (j). Those ten letters are the first column of each table on this page, and the keys every mapping we publish hangs off. The ten measures, one by one.
Family-level mapping. Each article 21(2) measure is mapped to the families that carry the relevant controls. Family identifiers are stable across the revision and publicly documented.
Family level, not control. A family contains controls of very different scope, and which of them apply depends on the baseline and tailoring you operate — so a family match is a starting point for scoping, never evidence that a measure is met.
| NIS2 art. 21(2) Directive (EU) 2022/2555 | Measure | NIST 800-53 — NIST SP 800-53 Rev. 5 control family |
|---|---|---|
| (a) | Risk analysis and security policies | RA PL PM |
| (b) | Incident handling | IR AU SI |
| (c) | Business continuity | CP PE |
| (d) | Supply chain security | SR SA |
| (e) | Security in acquisition, development and maintenance | SA CM MA RA SI |
| (f) | Assessing the effectiveness of the measures | CA PM |
| (g) | Basic cyber hygiene and cybersecurity training | AT SI CM |
| (h) | Cryptography and encryption | SC |
| (i) | Human resources security, access control and asset management | PS AC IA CM MP PE |
| (j) | Multi-factor authentication and secured communications | IA AC SC |
20 NIST SP 800-53 Rev. 5 control family units, in full
- AC — Access Control
- AT — Awareness and Training
- AU — Audit and Accountability
- CA — Assessment, Authorization and Monitoring
- CM — Configuration Management
- CP — Contingency Planning
- IA — Identification and Authentication
- IR — Incident Response
- MA — Maintenance
- MP — Media Protection
- PE — Physical and Environmental Protection
- PL — Planning
- PM — Program Management
- PS — Personnel Security
- PT — PII Processing and Transparency
- RA — Risk Assessment
- SA — System and Services Acquisition
- SC — System and Communications Protection
- SI — System and Information Integrity
- SR — Supply Chain Risk Management
1196 controls, and the level each one enters at
A mapping says which of the ten measures a framework serves. A catalogue says which control, at which level. Here are all 1196, as National Institute of Standards and Technology (NIST) publishes them.
Published by National Institute of Standards and Technology (NIST), under Work of the US federal government: not subject to copyright in the United States, and published for reuse.
NIST, SP 800-53 Rev. 5 and SP 800-53B baselines — Work of the US federal government: not subject to copyright in the United States, and published for reuse.. Structure and counts here are derived from that publication; identifiers and wording are theirs.
- NIST, SP 800-53 Rev. 5 control catalogue, OSCAL edition 5.2.0
- NIST, SP 800-53B control baselines (Low, Moderate, High), OSCAL profiles
Get the official documents from https://csrc.nist.gov/pubs/sp/800/53/r5/upd1/final — the framework and everything published with it belong to its owner, and that publication is the version that binds. Work of the US federal government: public domain.
- Levels here are the SP 800-53B baselines. They are strictly nested — Low is contained in Moderate, Moderate in High — which is checked on every extraction.
- 826 controls sit in no baseline at all: they are selected by tailoring, and 182 of those are withdrawn controls kept for traceability.
- Control titles are reproduced; the full control text is not. It is public domain and one click away at NIST, and 1,196 statements would bury the page.
- NIST publishes no crosswalk to article 21(2). The letters shown on the page are our own thematic mapping, at family level, and they are not part of this file.
What each level adds
Depth here is one thing: how many more controls the next level pulls in. Each level contains everything below it, which is checked on every extraction.
| Level | Adds | Cumulative |
|---|---|---|
| Low | +149 | 149 |
| Moderate | +138 | 287 |
| High | +83 | 370 |
| In no levelselected by tailoring | +826 | 1196 |
The catalogue, control by control
20 families, 20 families, 1196 controls. Each row carries the level at which it becomes due.
Access Control · 147 controls
Our thematic mapping puts this group against (i) (j)
| Control | Level | Title |
|---|---|---|
| AC-01 | Low | Policy and Procedures |
| AC-02 | Low | Account Management |
| AC-02(01) | Moderate | Automated System Account Management |
| AC-02(02) | Moderate | Automated Temporary and Emergency Account Management |
| AC-02(03) | Moderate | Disable Accounts |
| AC-02(04) | Moderate | Automated Audit Actions |
| AC-02(05) | Moderate | Inactivity Logout |
| AC-02(06) | Tailoring only | Dynamic Privilege Management |
| AC-02(07) | Tailoring only | Privileged User Accounts |
| AC-02(08) | Tailoring only | Dynamic Account Management |
| AC-02(09) | Tailoring only | Restrictions on Use of Shared and Group Accounts |
| AC-02(10) withdrawn → AC-2_SMT.K | Tailoring only | Shared and Group Account Credential Change |
| AC-02(11) | High | Usage Conditions |
| AC-02(12) | High | Account Monitoring for Atypical Usage |
| AC-02(13) | Moderate | Disable Accounts for High-risk Individuals |
| AC-03 | Low | Access Enforcement |
| AC-03(01) withdrawn → AC-06 | Tailoring only | Restricted Access to Privileged Functions |
| AC-03(02) | Tailoring only | Dual Authorization |
| AC-03(03) | Tailoring only | Mandatory Access Control |
| AC-03(04) | Tailoring only | Discretionary Access Control |
| AC-03(05) | Tailoring only | Security-relevant Information |
| AC-03(06) withdrawn → MP-04, SC-28 | Tailoring only | Protection of User and System Information |
| AC-03(07) | Tailoring only | Role-based Access Control |
| AC-03(08) | Tailoring only | Revocation of Access Authorizations |
| AC-03(09) | Tailoring only | Controlled Release |
| AC-03(10) | Tailoring only | Audited Override of Access Control Mechanisms |
| AC-03(11) | Tailoring only | Restrict Access to Specific Information Types |
| AC-03(12) | Tailoring only | Assert and Enforce Application Access |
| AC-03(13) | Tailoring only | Attribute-based Access Control |
| AC-03(14) | Tailoring only | Individual Access |
| AC-03(15) | Tailoring only | Discretionary and Mandatory Access Control |
| AC-04 | Moderate | Information Flow Enforcement |
| AC-04(01) | Tailoring only | Object Security and Privacy Attributes |
| AC-04(02) | Tailoring only | Processing Domains |
| AC-04(03) | Tailoring only | Dynamic Information Flow Control |
| AC-04(04) | High | Flow Control of Encrypted Information |
| AC-04(05) | Tailoring only | Embedded Data Types |
| AC-04(06) | Tailoring only | Metadata |
| AC-04(07) | Tailoring only | One-way Flow Mechanisms |
| AC-04(08) | Tailoring only | Security and Privacy Policy Filters |
| AC-04(09) | Tailoring only | Human Reviews |
| AC-04(10) | Tailoring only | Enable and Disable Security or Privacy Policy Filters |
| AC-04(11) | Tailoring only | Configuration of Security or Privacy Policy Filters |
| AC-04(12) | Tailoring only | Data Type Identifiers |
| AC-04(13) | Tailoring only | Decomposition into Policy-relevant Subcomponents |
| AC-04(14) | Tailoring only | Security or Privacy Policy Filter Constraints |
| AC-04(15) | Tailoring only | Detection of Unsanctioned Information |
| AC-04(16) withdrawn → AC-04 | Tailoring only | Information Transfers on Interconnected Systems |
| AC-04(17) | Tailoring only | Domain Authentication |
| AC-04(18) withdrawn → AC-16 | Tailoring only | Security Attribute Binding |
| AC-04(19) | Tailoring only | Validation of Metadata |
| AC-04(20) | Tailoring only | Approved Solutions |
| AC-04(21) | Tailoring only | Physical or Logical Separation of Information Flows |
| AC-04(22) | Tailoring only | Access Only |
| AC-04(23) | Tailoring only | Modify Non-releasable Information |
| AC-04(24) | Tailoring only | Internal Normalized Format |
| AC-04(25) | Tailoring only | Data Sanitization |
| AC-04(26) | Tailoring only | Audit Filtering Actions |
| AC-04(27) | Tailoring only | Redundant/Independent Filtering Mechanisms |
| AC-04(28) | Tailoring only | Linear Filter Pipelines |
| AC-04(29) | Tailoring only | Filter Orchestration Engines |
| AC-04(30) | Tailoring only | Filter Mechanisms Using Multiple Processes |
| AC-04(31) | Tailoring only | Failed Content Transfer Prevention |
| AC-04(32) | Tailoring only | Process Requirements for Information Transfer |
| AC-05 | Moderate | Separation of Duties |
| AC-06 | Moderate | Least Privilege |
| AC-06(01) | Moderate | Authorize Access to Security Functions |
| AC-06(02) | Moderate | Non-privileged Access for Nonsecurity Functions |
| AC-06(03) | High | Network Access to Privileged Commands |
| AC-06(04) | Tailoring only | Separate Processing Domains |
| AC-06(05) | Moderate | Privileged Accounts |
| AC-06(06) | Tailoring only | Privileged Access by Non-organizational Users |
| AC-06(07) | Moderate | Review of User Privileges |
| AC-06(08) | Tailoring only | Privilege Levels for Code Execution |
| AC-06(09) | Moderate | Log Use of Privileged Functions |
| AC-06(10) | Moderate | Prohibit Non-privileged Users from Executing Privileged Functions |
| AC-07 | Low | Unsuccessful Logon Attempts |
| AC-07(01) withdrawn → AC-07 | Tailoring only | Automatic Account Lock |
| AC-07(02) | Tailoring only | Purge or Wipe Mobile Device |
| AC-07(03) | Tailoring only | Biometric Attempt Limiting |
| AC-07(04) | Tailoring only | Use of Alternate Authentication Factor |
| AC-08 | Low | System Use Notification |
| AC-09 | Tailoring only | Previous Logon Notification |
| AC-09(01) | Tailoring only | Unsuccessful Logons |
| AC-09(02) | Tailoring only | Successful and Unsuccessful Logons |
| AC-09(03) | Tailoring only | Notification of Account Changes |
| AC-09(04) | Tailoring only | Additional Logon Information |
| AC-10 | High | Concurrent Session Control |
| AC-11 | Moderate | Device Lock |
| AC-11(01) | Moderate | Pattern-hiding Displays |
| AC-12 | Moderate | Session Termination |
| AC-12(01) | Tailoring only | User-initiated Logouts |
| AC-12(02) | Tailoring only | Termination Message |
| AC-12(03) | Tailoring only | Timeout Warning Message |
| AC-13 withdrawn → AC-02, AU-06 | Tailoring only | Supervision and Review — Access Control |
| AC-14 | Low | Permitted Actions Without Identification or Authentication |
| AC-14(01) withdrawn → AC-14 | Tailoring only | Necessary Uses |
| AC-15 withdrawn → MP-03 | Tailoring only | Automated Marking |
| AC-16 | Tailoring only | Security and Privacy Attributes |
| AC-16(01) | Tailoring only | Dynamic Attribute Association |
| AC-16(02) | Tailoring only | Attribute Value Changes by Authorized Individuals |
| AC-16(03) | Tailoring only | Maintenance of Attribute Associations by System |
| AC-16(04) | Tailoring only | Association of Attributes by Authorized Individuals |
| AC-16(05) | Tailoring only | Attribute Displays on Objects to Be Output |
| AC-16(06) | Tailoring only | Maintenance of Attribute Association |
| AC-16(07) | Tailoring only | Consistent Attribute Interpretation |
| AC-16(08) | Tailoring only | Association Techniques and Technologies |
| AC-16(09) | Tailoring only | Attribute Reassignment — Regrading Mechanisms |
| AC-16(10) | Tailoring only | Attribute Configuration by Authorized Individuals |
| AC-17 | Low | Remote Access |
| AC-17(01) | Moderate | Monitoring and Control |
| AC-17(02) | Moderate | Protection of Confidentiality and Integrity Using Encryption |
| AC-17(03) | Moderate | Managed Access Control Points |
| AC-17(04) | Moderate | Privileged Commands and Access |
| AC-17(05) withdrawn → SI-04 | Tailoring only | Monitoring for Unauthorized Connections |
| AC-17(06) | Tailoring only | Protection of Mechanism Information |
| AC-17(07) withdrawn → AC-03(10) | Tailoring only | Additional Protection for Security Function Access |
| AC-17(08) withdrawn → CM-07 | Tailoring only | Disable Nonsecure Network Protocols |
| AC-17(09) | Tailoring only | Disconnect or Disable Access |
| AC-17(10) | Tailoring only | Authenticate Remote Commands |
| AC-18 | Low | Wireless Access |
| AC-18(01) | Moderate | Authentication and Encryption |
| AC-18(02) withdrawn → SI-04 | Tailoring only | Monitoring Unauthorized Connections |
| AC-18(03) | Moderate | Disable Wireless Networking |
| AC-18(04) | High | Restrict Configurations by Users |
| AC-18(05) | High | Antennas and Transmission Power Levels |
| AC-19 | Low | Access Control for Mobile Devices |
| AC-19(01) withdrawn → MP-07 | Tailoring only | Use of Writable and Portable Storage Devices |
| AC-19(02) withdrawn → MP-07 | Tailoring only | Use of Personally Owned Portable Storage Devices |
| AC-19(03) withdrawn → MP-07 | Tailoring only | Use of Portable Storage Devices with No Identifiable Owner |
| AC-19(04) | Tailoring only | Restrictions for Classified Information |
| AC-19(05) | Moderate | Full Device or Container-based Encryption |
| AC-20 | Low | Use of External Systems |
| AC-20(01) | Moderate | Limits on Authorized Use |
| AC-20(02) | Moderate | Portable Storage Devices — Restricted Use |
| AC-20(03) | Tailoring only | Non-organizationally Owned Systems — Restricted Use |
| AC-20(04) | Tailoring only | Network Accessible Storage Devices — Prohibited Use |
| AC-20(05) | Tailoring only | Portable Storage Devices — Prohibited Use |
| AC-21 | Moderate | Information Sharing |
| AC-21(01) | Tailoring only | Automated Decision Support |
| AC-21(02) | Tailoring only | Information Search and Retrieval |
| AC-22 | Low | Publicly Accessible Content |
| AC-23 | Tailoring only | Data Mining Protection |
| AC-24 | Tailoring only | Access Control Decisions |
| AC-24(01) | Tailoring only | Transmit Access Authorization Information |
| AC-24(02) | Tailoring only | No User or Process Identity |
| AC-25 | Tailoring only | Reference Monitor |
Awareness and Training · 17 controls
Our thematic mapping puts this group against (g)
| Control | Level | Title |
|---|---|---|
| AT-01 | Low | Policy and Procedures |
| AT-02 | Low | Literacy Training and Awareness |
| AT-02(01) | Tailoring only | Practical Exercises |
| AT-02(02) | Low | Insider Threat |
| AT-02(03) | Moderate | Social Engineering and Mining |
| AT-02(04) | Tailoring only | Suspicious Communications and Anomalous System Behavior |
| AT-02(05) | Tailoring only | Advanced Persistent Threat |
| AT-02(06) | Tailoring only | Cyber Threat Environment |
| AT-03 | Low | Role-based Training |
| AT-03(01) | Tailoring only | Environmental Controls |
| AT-03(02) | Tailoring only | Physical Security Controls |
| AT-03(03) | Tailoring only | Practical Exercises |
| AT-03(04) withdrawn → AT-02(04) | Tailoring only | Suspicious Communications and Anomalous System Behavior |
| AT-03(05) | Tailoring only | Processing Personally Identifiable Information |
| AT-04 | Low | Training Records |
| AT-05 withdrawn → PM-15 | Tailoring only | Contacts with Security Groups and Associations |
| AT-06 | Tailoring only | Training Feedback |
Audit and Accountability · 69 controls
Our thematic mapping puts this group against (b)
| Control | Level | Title |
|---|---|---|
| AU-01 | Low | Policy and Procedures |
| AU-02 | Low | Event Logging |
| AU-02(01) withdrawn → AU-12 | Tailoring only | Compilation of Audit Records from Multiple Sources |
| AU-02(02) withdrawn → AU-12 | Tailoring only | Selection of Audit Events by Component |
| AU-02(03) withdrawn → AU-02 | Tailoring only | Reviews and Updates |
| AU-02(04) withdrawn → AC-06(09) | Tailoring only | Privileged Functions |
| AU-03 | Low | Content of Audit Records |
| AU-03(01) | Moderate | Additional Audit Information |
| AU-03(02) withdrawn → PL-09 | Tailoring only | Centralized Management of Planned Audit Record Content |
| AU-03(03) | Tailoring only | Limit Personally Identifiable Information Elements |
| AU-04 | Low | Audit Log Storage Capacity |
| AU-04(01) | Tailoring only | Transfer to Alternate Storage |
| AU-05 | Low | Response to Audit Logging Process Failures |
| AU-05(01) | High | Storage Capacity Warning |
| AU-05(02) | High | Real-time Alerts |
| AU-05(03) | Tailoring only | Configurable Traffic Volume Thresholds |
| AU-05(04) | Tailoring only | Shutdown on Failure |
| AU-05(05) | Tailoring only | Alternate Audit Logging Capability |
| AU-06 | Low | Audit Record Review, Analysis, and Reporting |
| AU-06(01) | Moderate | Automated Process Integration |
| AU-06(02) withdrawn → SI-04 | Tailoring only | Automated Security Alerts |
| AU-06(03) | Moderate | Correlate Audit Record Repositories |
| AU-06(04) | Tailoring only | Central Review and Analysis |
| AU-06(05) | High | Integrated Analysis of Audit Records |
| AU-06(06) | High | Correlation with Physical Monitoring |
| AU-06(07) | Tailoring only | Permitted Actions |
| AU-06(08) | Tailoring only | Full Text Analysis of Privileged Commands |
| AU-06(09) | Tailoring only | Correlation with Information from Nontechnical Sources |
| AU-06(10) withdrawn → AU-06 | Tailoring only | Audit Level Adjustment |
| AU-07 | Moderate | Audit Record Reduction and Report Generation |
| AU-07(01) | Moderate | Automatic Processing |
| AU-07(02) withdrawn → AU-07(01) | Tailoring only | Automatic Sort and Search |
| AU-08 | Low | Time Stamps |
| AU-08(01) withdrawn → SC-45(01) | Tailoring only | Synchronization with Authoritative Time Source |
| AU-08(02) withdrawn → SC-45(02) | Tailoring only | Secondary Authoritative Time Source |
| AU-09 | Low | Protection of Audit Information |
| AU-09(01) | Tailoring only | Hardware Write-once Media |
| AU-09(02) | High | Store on Separate Physical Systems or Components |
| AU-09(03) | High | Cryptographic Protection |
| AU-09(04) | Moderate | Access by Subset of Privileged Users |
| AU-09(05) | Tailoring only | Dual Authorization |
| AU-09(06) | Tailoring only | Read-only Access |
| AU-09(07) | Tailoring only | Store on Component with Different Operating System |
| AU-10 | High | Non-repudiation |
| AU-10(01) | Tailoring only | Association of Identities |
| AU-10(02) | Tailoring only | Validate Binding of Information Producer Identity |
| AU-10(03) | Tailoring only | Chain of Custody |
| AU-10(04) | Tailoring only | Validate Binding of Information Reviewer Identity |
| AU-10(05) withdrawn → SI-07 | Tailoring only | Digital Signatures |
| AU-11 | Low | Audit Record Retention |
| AU-11(01) | Tailoring only | Long-term Retrieval Capability |
| AU-12 | Low | Audit Record Generation |
| AU-12(01) | High | System-wide and Time-correlated Audit Trail |
| AU-12(02) | Tailoring only | Standardized Formats |
| AU-12(03) | High | Changes by Authorized Individuals |
| AU-12(04) | Tailoring only | Query Parameter Audits of Personally Identifiable Information |
| AU-13 | Tailoring only | Monitoring for Information Disclosure |
| AU-13(01) | Tailoring only | Use of Automated Tools |
| AU-13(02) | Tailoring only | Review of Monitored Sites |
| AU-13(03) | Tailoring only | Unauthorized Replication of Information |
| AU-14 | Tailoring only | Session Audit |
| AU-14(01) | Tailoring only | System Start-up |
| AU-14(02) withdrawn → AU-14 | Tailoring only | Capture and Record Content |
| AU-14(03) | Tailoring only | Remote Viewing and Listening |
| AU-15 withdrawn → AU-05(05) | Tailoring only | Alternate Audit Logging Capability |
| AU-16 | Tailoring only | Cross-organizational Audit Logging |
| AU-16(01) | Tailoring only | Identity Preservation |
| AU-16(02) | Tailoring only | Sharing of Audit Information |
| AU-16(03) | Tailoring only | Disassociability |
Assessment, Authorization, and Monitoring · 32 controls
Assessment, Authorization, and Monitoring (CA)
Our thematic mapping puts this group against (f)
| Control | Level | Title |
|---|---|---|
| CA-01 | Low | Policy and Procedures |
| CA-02 | Low | Control Assessments |
| CA-02(01) | Moderate | Independent Assessors |
| CA-02(02) | High | Specialized Assessments |
| CA-02(03) | Tailoring only | Leveraging Results from External Organizations |
| CA-03 | Low | Information Exchange |
| CA-03(01) withdrawn → SC-07(25) | Tailoring only | Unclassified National Security System Connections |
| CA-03(02) withdrawn → SC-07(26) | Tailoring only | Classified National Security System Connections |
| CA-03(03) withdrawn → SC-07(27) | Tailoring only | Unclassified Non-national Security System Connections |
| CA-03(04) withdrawn → SC-07(28) | Tailoring only | Connections to Public Networks |
| CA-03(05) withdrawn → SC-07(05) | Tailoring only | Restrictions on External System Connections |
| CA-03(06) | High | Transfer Authorizations |
| CA-03(07) | Tailoring only | Transitive Information Exchanges |
| CA-04 withdrawn → CA-02 | Tailoring only | Security Certification |
| CA-05 | Low | Plan of Action and Milestones |
| CA-05(01) | Tailoring only | Automation Support for Accuracy and Currency |
| CA-06 | Low | Authorization |
| CA-06(01) | Tailoring only | Joint Authorization — Intra-organization |
| CA-06(02) | Tailoring only | Joint Authorization — Inter-organization |
| CA-07 | Low | Continuous Monitoring |
| CA-07(01) | Moderate | Independent Assessment |
| CA-07(02) withdrawn → CA-02 | Tailoring only | Types of Assessments |
| CA-07(03) | Tailoring only | Trend Analyses |
| CA-07(04) | Low | Risk Monitoring |
| CA-07(05) | Tailoring only | Consistency Analysis |
| CA-07(06) | Tailoring only | Automation Support for Monitoring |
| CA-08 | High | Penetration Testing |
| CA-08(01) | High | Independent Penetration Testing Agent or Team |
| CA-08(02) | Tailoring only | Red Team Exercises |
| CA-08(03) | Tailoring only | Facility Penetration Testing |
| CA-09 | Low | Internal System Connections |
| CA-09(01) | Tailoring only | Compliance Checks |
Configuration Management · 66 controls
Our thematic mapping puts this group against (e) (g) (i)
| Control | Level | Title |
|---|---|---|
| CM-01 | Low | Policy and Procedures |
| CM-02 | Low | Baseline Configuration |
| CM-02(01) withdrawn → CM-02 | Tailoring only | Reviews and Updates |
| CM-02(02) | Moderate | Automation Support for Accuracy and Currency |
| CM-02(03) | Moderate | Retention of Previous Configurations |
| CM-02(04) withdrawn → CM-07(04) | Tailoring only | Unauthorized Software |
| CM-02(05) withdrawn → CM-07(05) | Tailoring only | Authorized Software |
| CM-02(06) | Tailoring only | Development and Test Environments |
| CM-02(07) | Moderate | Configure Systems and Components for High-risk Areas |
| CM-03 | Moderate | Configuration Change Control |
| CM-03(01) | High | Automated Documentation, Notification, and Prohibition of Changes |
| CM-03(02) | Moderate | Testing, Validation, and Documentation of Changes |
| CM-03(03) | Tailoring only | Automated Change Implementation |
| CM-03(04) | Moderate | Security and Privacy Representatives |
| CM-03(05) | Tailoring only | Automated Security Response |
| CM-03(06) | High | Cryptography Management |
| CM-03(07) | Tailoring only | Review System Changes |
| CM-03(08) | Tailoring only | Prevent or Restrict Configuration Changes |
| CM-04 | Low | Impact Analyses |
| CM-04(01) | High | Separate Test Environments |
| CM-04(02) | Moderate | Verification of Controls |
| CM-05 | Low | Access Restrictions for Change |
| CM-05(01) | High | Automated Access Enforcement and Audit Records |
| CM-05(02) withdrawn → CM-03(07) | Tailoring only | Review System Changes |
| CM-05(03) withdrawn → CM-14 | Tailoring only | Signed Components |
| CM-05(04) | Tailoring only | Dual Authorization |
| CM-05(05) | Tailoring only | Privilege Limitation for Production and Operation |
| CM-05(06) | Tailoring only | Limit Library Privileges |
| CM-05(07) withdrawn → SI-07 | Tailoring only | Automatic Implementation of Security Safeguards |
| CM-06 | Low | Configuration Settings |
| CM-06(01) | High | Automated Management, Application, and Verification |
| CM-06(02) | High | Respond to Unauthorized Changes |
| CM-06(03) withdrawn → SI-07 | Tailoring only | Unauthorized Change Detection |
| CM-06(04) withdrawn → CM-04 | Tailoring only | Conformance Demonstration |
| CM-07 | Low | Least Functionality |
| CM-07(01) | Moderate | Periodic Review |
| CM-07(02) | Moderate | Prevent Program Execution |
| CM-07(03) | Tailoring only | Registration Compliance |
| CM-07(04) | Tailoring only | Unauthorized Software — Deny-by-exception |
| CM-07(05) | Moderate | Authorized Software — Allow-by-exception |
| CM-07(06) | Tailoring only | Confined Environments with Limited Privileges |
| CM-07(07) | Tailoring only | Code Execution in Protected Environments |
| CM-07(08) | Tailoring only | Binary or Machine Executable Code |
| CM-07(09) | Tailoring only | Prohibiting The Use of Unauthorized Hardware |
| CM-08 | Low | System Component Inventory |
| CM-08(01) | Moderate | Updates During Installation and Removal |
| CM-08(02) | High | Automated Maintenance |
| CM-08(03) | Moderate | Automated Unauthorized Component Detection |
| CM-08(04) | High | Accountability Information |
| CM-08(05) withdrawn → CM-08 | Tailoring only | No Duplicate Accounting of Components |
| CM-08(06) | Tailoring only | Assessed Configurations and Approved Deviations |
| CM-08(07) | Tailoring only | Centralized Repository |
| CM-08(08) | Tailoring only | Automated Location Tracking |
| CM-08(09) | Tailoring only | Assignment of Components to Systems |
| CM-09 | Moderate | Configuration Management Plan |
| CM-09(01) | Tailoring only | Assignment of Responsibility |
| CM-10 | Low | Software Usage Restrictions |
| CM-10(01) | Tailoring only | Open-source Software |
| CM-11 | Low | User-installed Software |
| CM-11(01) withdrawn → CM-08(03) | Tailoring only | Alerts for Unauthorized Installations |
| CM-11(02) | Tailoring only | Software Installation with Privileged Status |
| CM-11(03) | Tailoring only | Automated Enforcement and Monitoring |
| CM-12 | Moderate | Information Location |
| CM-12(01) | Moderate | Automated Tools to Support Information Location |
| CM-13 | Tailoring only | Data Action Mapping |
| CM-14 | Tailoring only | Signed Components |
Contingency Planning · 56 controls
Our thematic mapping puts this group against (c)
| Control | Level | Title |
|---|---|---|
| CP-01 | Low | Policy and Procedures |
| CP-02 | Low | Contingency Plan |
| CP-02(01) | Moderate | Coordinate with Related Plans |
| CP-02(02) | High | Capacity Planning |
| CP-02(03) | Moderate | Resume Mission and Business Functions |
| CP-02(04) withdrawn → CP-02(03) | Tailoring only | Resume All Mission and Business Functions |
| CP-02(05) | High | Continue Mission and Business Functions |
| CP-02(06) | Tailoring only | Alternate Processing and Storage Sites |
| CP-02(07) | Tailoring only | Coordinate with External Service Providers |
| CP-02(08) | Moderate | Identify Critical Assets |
| CP-03 | Low | Contingency Training |
| CP-03(01) | High | Simulated Events |
| CP-03(02) | Tailoring only | Mechanisms Used in Training Environments |
| CP-04 | Low | Contingency Plan Testing |
| CP-04(01) | Moderate | Coordinate with Related Plans |
| CP-04(02) | High | Alternate Processing Site |
| CP-04(03) | Tailoring only | Automated Testing |
| CP-04(04) | Tailoring only | Full Recovery and Reconstitution |
| CP-04(05) | Tailoring only | Self-challenge |
| CP-05 withdrawn → CP-02 | Tailoring only | Contingency Plan Update |
| CP-06 | Moderate | Alternate Storage Site |
| CP-06(01) | Moderate | Separation from Primary Site |
| CP-06(02) | High | Recovery Time and Recovery Point Objectives |
| CP-06(03) | Moderate | Accessibility |
| CP-07 | Moderate | Alternate Processing Site |
| CP-07(01) | Moderate | Separation from Primary Site |
| CP-07(02) | Moderate | Accessibility |
| CP-07(03) | Moderate | Priority of Service |
| CP-07(04) | High | Preparation for Use |
| CP-07(05) withdrawn → CP-07 | Tailoring only | Equivalent Information Security Safeguards |
| CP-07(06) | Tailoring only | Inability to Return to Primary Site |
| CP-08 | Moderate | Telecommunications Services |
| CP-08(01) | Moderate | Priority of Service Provisions |
| CP-08(02) | Moderate | Single Points of Failure |
| CP-08(03) | High | Separation of Primary and Alternate Providers |
| CP-08(04) | High | Provider Contingency Plan |
| CP-08(05) | Tailoring only | Alternate Telecommunication Service Testing |
| CP-09 | Low | System Backup |
| CP-09(01) | Moderate | Testing for Reliability and Integrity |
| CP-09(02) | High | Test Restoration Using Sampling |
| CP-09(03) | High | Separate Storage for Critical Information |
| CP-09(04) withdrawn → CP-09 | Tailoring only | Protection from Unauthorized Modification |
| CP-09(05) | High | Transfer to Alternate Storage Site |
| CP-09(06) | Tailoring only | Redundant Secondary System |
| CP-09(07) | Tailoring only | Dual Authorization for Deletion or Destruction |
| CP-09(08) | Moderate | Cryptographic Protection |
| CP-10 | Low | System Recovery and Reconstitution |
| CP-10(01) withdrawn → CP-04 | Tailoring only | Contingency Plan Testing |
| CP-10(02) | Moderate | Transaction Recovery |
| CP-10(03) withdrawn | Tailoring only | Compensating Security Controls |
| CP-10(04) | High | Restore Within Time Period |
| CP-10(05) withdrawn → SI-13 | Tailoring only | Failover Capability |
| CP-10(06) | Tailoring only | Component Protection |
| CP-11 | Tailoring only | Alternate Communications Protocols |
| CP-12 | Tailoring only | Safe Mode |
| CP-13 | Tailoring only | Alternative Security Mechanisms |
Identification and Authentication · 74 controls
Identification and Authentication (IA)
Our thematic mapping puts this group against (i) (j)
| Control | Level | Title |
|---|---|---|
| IA-01 | Low | Policy and Procedures |
| IA-02 | Low | Identification and Authentication (Organizational Users) |
| IA-02(01) | Low | Multi-factor Authentication to Privileged Accounts |
| IA-02(02) | Low | Multi-factor Authentication to Non-privileged Accounts |
| IA-02(03) withdrawn → IA-02(01) | Tailoring only | Local Access to Privileged Accounts |
| IA-02(04) withdrawn → IA-02(02) | Tailoring only | Local Access to Non-privileged Accounts |
| IA-02(05) | High | Individual Authentication with Group Authentication |
| IA-02(06) | Tailoring only | Access to Accounts —separate Device |
| IA-02(07) withdrawn → IA-02(06) | Tailoring only | Network Access to Non-privileged Accounts — Separate Device |
| IA-02(08) | Low | Access to Accounts — Replay Resistant |
| IA-02(09) withdrawn → IA-02(08) | Tailoring only | Network Access to Non-privileged Accounts — Replay Resistant |
| IA-02(10) | Tailoring only | Single Sign-on |
| IA-02(11) withdrawn → IA-02(06) | Tailoring only | Remote Access — Separate Device |
| IA-02(12) | Low | Acceptance of PIV Credentials |
| IA-02(13) | Tailoring only | Out-of-band Authentication |
| IA-03 | Moderate | Device Identification and Authentication |
| IA-03(01) | Tailoring only | Cryptographic Bidirectional Authentication |
| IA-03(02) withdrawn → IA-03(01) | Tailoring only | Cryptographic Bidirectional Network Authentication |
| IA-03(03) | Tailoring only | Dynamic Address Allocation |
| IA-03(04) | Tailoring only | Device Attestation |
| IA-04 | Low | Identifier Management |
| IA-04(01) | Tailoring only | Prohibit Account Identifiers as Public Identifiers |
| IA-04(02) withdrawn → IA-12(01) | Tailoring only | Supervisor Authorization |
| IA-04(03) withdrawn → IA-12(02) | Tailoring only | Multiple Forms of Certification |
| IA-04(04) | Moderate | Identify User Status |
| IA-04(05) | Tailoring only | Dynamic Management |
| IA-04(06) | Tailoring only | Cross-organization Management |
| IA-04(07) withdrawn → IA-12(04) | Tailoring only | In-person Registration |
| IA-04(08) | Tailoring only | Pairwise Pseudonymous Identifiers |
| IA-04(09) | Tailoring only | Attribute Maintenance and Protection |
| IA-05 | Low | Authenticator Management |
| IA-05(01) | Low | Password-based Authentication |
| IA-05(02) | Moderate | Public Key-based Authentication |
| IA-05(03) withdrawn → IA-12(04) | Tailoring only | In-person or Trusted External Party Registration |
| IA-05(04) withdrawn → IA-05(01) | Tailoring only | Automated Support for Password Strength Determination |
| IA-05(05) | Tailoring only | Change Authenticators Prior to Delivery |
| IA-05(06) | Moderate | Protection of Authenticators |
| IA-05(07) | Tailoring only | No Embedded Unencrypted Static Authenticators |
| IA-05(08) | Tailoring only | Multiple System Accounts |
| IA-05(09) | Tailoring only | Federated Credential Management |
| IA-05(10) | Tailoring only | Dynamic Credential Binding |
| IA-05(11) withdrawn → IA-02(01), IA-02(02) | Tailoring only | Hardware Token-based Authentication |
| IA-05(12) | Tailoring only | Biometric Authentication Performance |
| IA-05(13) | Tailoring only | Expiration of Cached Authenticators |
| IA-05(14) | Tailoring only | Managing Content of PKI Trust Stores |
| IA-05(15) | Tailoring only | GSA-approved Products and Services |
| IA-05(16) | Tailoring only | In-person or Trusted External Party Authenticator Issuance |
| IA-05(17) | Tailoring only | Presentation Attack Detection for Biometric Authenticators |
| IA-05(18) | Tailoring only | Password Managers |
| IA-06 | Low | Authentication Feedback |
| IA-07 | Low | Cryptographic Module Authentication |
| IA-08 | Low | Identification and Authentication (Non-organizational Users) |
| IA-08(01) | Low | Acceptance of PIV Credentials from Other Agencies |
| IA-08(02) | Low | Acceptance of External Authenticators |
| IA-08(03) withdrawn → IA-08(02) | Tailoring only | Use of FICAM-approved Products |
| IA-08(04) | Low | Use of Defined Profiles |
| IA-08(05) | Tailoring only | Acceptance of PIV-I Credentials |
| IA-08(06) | Tailoring only | Disassociability |
| IA-09 | Tailoring only | Service Identification and Authentication |
| IA-09(01) withdrawn → IA-09 | Tailoring only | Information Exchange |
| IA-09(02) withdrawn → IA-09 | Tailoring only | Transmission of Decisions |
| IA-10 | Tailoring only | Adaptive Authentication |
| IA-11 | Low | Re-authentication |
| IA-12 | Moderate | Identity Proofing |
| IA-12(01) | Tailoring only | Supervisor Authorization |
| IA-12(02) | Moderate | Identity Evidence |
| IA-12(03) | Moderate | Identity Evidence Validation and Verification |
| IA-12(04) | High | In-person Validation and Verification |
| IA-12(05) | Moderate | Address Confirmation |
| IA-12(06) | Tailoring only | Accept Externally-proofed Identities |
| IA-13 | Tailoring only | Identity Providers and Authorization Servers |
| IA-13(01) | Tailoring only | Protection of Cryptographic Keys |
| IA-13(02) | Tailoring only | Verification of Identity Assertions and Access Tokens |
| IA-13(03) | Tailoring only | Token Management |
Incident Response · 42 controls
Our thematic mapping puts this group against (b)
| Control | Level | Title |
|---|---|---|
| IR-01 | Low | Policy and Procedures |
| IR-02 | Low | Incident Response Training |
| IR-02(01) | High | Simulated Events |
| IR-02(02) | High | Automated Training Environments |
| IR-02(03) | Tailoring only | Breach |
| IR-03 | Moderate | Incident Response Testing |
| IR-03(01) | Tailoring only | Automated Testing |
| IR-03(02) | Moderate | Coordination with Related Plans |
| IR-03(03) | Tailoring only | Continuous Improvement |
| IR-04 | Low | Incident Handling |
| IR-04(01) | Moderate | Automated Incident Handling Processes |
| IR-04(02) | Tailoring only | Dynamic Reconfiguration |
| IR-04(03) | Tailoring only | Continuity of Operations |
| IR-04(04) | High | Information Correlation |
| IR-04(05) | Tailoring only | Automatic Disabling of System |
| IR-04(06) | Tailoring only | Insider Threats |
| IR-04(07) | Tailoring only | Insider Threats — Intra-organization Coordination |
| IR-04(08) | Tailoring only | Correlation with External Organizations |
| IR-04(09) | Tailoring only | Dynamic Response Capability |
| IR-04(10) | Tailoring only | Supply Chain Coordination |
| IR-04(11) | High | Integrated Incident Response Team |
| IR-04(12) | Tailoring only | Malicious Code and Forensic Analysis |
| IR-04(13) | Tailoring only | Behavior Analysis |
| IR-04(14) | Tailoring only | Security Operations Center |
| IR-04(15) | Tailoring only | Public Relations and Reputation Repair |
| IR-05 | Low | Incident Monitoring |
| IR-05(01) | High | Automated Tracking, Data Collection, and Analysis |
| IR-06 | Low | Incident Reporting |
| IR-06(01) | Moderate | Automated Reporting |
| IR-06(02) | Tailoring only | Vulnerabilities Related to Incidents |
| IR-06(03) | Moderate | Supply Chain Coordination |
| IR-07 | Low | Incident Response Assistance |
| IR-07(01) | Moderate | Automation Support for Availability of Information and Support |
| IR-07(02) | Tailoring only | Coordination with External Providers |
| IR-08 | Low | Incident Response Plan |
| IR-08(01) | Tailoring only | Breaches |
| IR-09 | Tailoring only | Information Spillage Response |
| IR-09(01) withdrawn → IR-09 | Tailoring only | Responsible Personnel |
| IR-09(02) | Tailoring only | Training |
| IR-09(03) | Tailoring only | Post-spill Operations |
| IR-09(04) | Tailoring only | Exposure to Unauthorized Personnel |
| IR-10 withdrawn → IR-04(11) | Tailoring only | Integrated Information Security Analysis Team |
Maintenance · 30 controls
Our thematic mapping puts this group against (e)
| Control | Level | Title |
|---|---|---|
| MA-01 | Low | Policy and Procedures |
| MA-02 | Low | Controlled Maintenance |
| MA-02(01) withdrawn → MA-02 | Tailoring only | Record Content |
| MA-02(02) | High | Automated Maintenance Activities |
| MA-03 | Moderate | Maintenance Tools |
| MA-03(01) | Moderate | Inspect Tools |
| MA-03(02) | Moderate | Inspect Media |
| MA-03(03) | Moderate | Prevent Unauthorized Removal |
| MA-03(04) | Tailoring only | Restricted Tool Use |
| MA-03(05) | Tailoring only | Execution with Privilege |
| MA-03(06) | Tailoring only | Software Updates and Patches |
| MA-04 | Low | Nonlocal Maintenance |
| MA-04(01) | Tailoring only | Logging and Review |
| MA-04(02) withdrawn → MA-01, MA-04 | Tailoring only | Document Nonlocal Maintenance |
| MA-04(03) | High | Comparable Security and Sanitization |
| MA-04(04) | Tailoring only | Authentication and Separation of Maintenance Sessions |
| MA-04(05) | Tailoring only | Approvals and Notifications |
| MA-04(06) | Tailoring only | Cryptographic Protection |
| MA-04(07) | Tailoring only | Disconnect Verification |
| MA-05 | Low | Maintenance Personnel |
| MA-05(01) | High | Individuals Without Appropriate Access |
| MA-05(02) | Tailoring only | Security Clearances for Classified Systems |
| MA-05(03) | Tailoring only | Citizenship Requirements for Classified Systems |
| MA-05(04) | Tailoring only | Foreign Nationals |
| MA-05(05) | Tailoring only | Non-system Maintenance |
| MA-06 | Moderate | Timely Maintenance |
| MA-06(01) | Tailoring only | Preventive Maintenance |
| MA-06(02) | Tailoring only | Predictive Maintenance |
| MA-06(03) | Tailoring only | Automated Support for Predictive Maintenance |
| MA-07 | Tailoring only | Field Maintenance |
Media Protection · 30 controls
Our thematic mapping puts this group against (i)
| Control | Level | Title |
|---|---|---|
| MP-01 | Low | Policy and Procedures |
| MP-02 | Low | Media Access |
| MP-02(01) withdrawn → MP-04(02) | Tailoring only | Automated Restricted Access |
| MP-02(02) withdrawn → SC-28(01) | Tailoring only | Cryptographic Protection |
| MP-03 | Moderate | Media Marking |
| MP-04 | Moderate | Media Storage |
| MP-04(01) withdrawn → SC-28(01) | Tailoring only | Cryptographic Protection |
| MP-04(02) | Tailoring only | Automated Restricted Access |
| MP-05 | Moderate | Media Transport |
| MP-05(01) withdrawn → MP-05 | Tailoring only | Protection Outside of Controlled Areas |
| MP-05(02) withdrawn → MP-05 | Tailoring only | Documentation of Activities |
| MP-05(03) | Tailoring only | Custodians |
| MP-05(04) withdrawn → SC-28(01) | Tailoring only | Cryptographic Protection |
| MP-06 | Low | Media Sanitization |
| MP-06(01) | High | Review, Approve, Track, Document, and Verify |
| MP-06(02) | High | Equipment Testing |
| MP-06(03) | High | Nondestructive Techniques |
| MP-06(04) withdrawn → MP-06 | Tailoring only | Controlled Unclassified Information |
| MP-06(05) withdrawn → MP-06 | Tailoring only | Classified Information |
| MP-06(06) withdrawn → MP-06 | Tailoring only | Media Destruction |
| MP-06(07) | Tailoring only | Dual Authorization |
| MP-06(08) | Tailoring only | Remote Purging or Wiping of Information |
| MP-07 | Low | Media Use |
| MP-07(01) withdrawn → MP-07 | Tailoring only | Prohibit Use Without Owner |
| MP-07(02) | Tailoring only | Prohibit Use of Sanitization-resistant Media |
| MP-08 | Tailoring only | Media Downgrading |
| MP-08(01) | Tailoring only | Documentation of Process |
| MP-08(02) | Tailoring only | Equipment Testing |
| MP-08(03) | Tailoring only | Controlled Unclassified Information |
| MP-08(04) | Tailoring only | Classified Information |
Physical and Environmental Protection · 59 controls
Physical and Environmental Protection (PE)
Our thematic mapping puts this group against (c) (i)
| Control | Level | Title |
|---|---|---|
| PE-01 | Low | Policy and Procedures |
| PE-02 | Low | Physical Access Authorizations |
| PE-02(01) | Tailoring only | Access by Position or Role |
| PE-02(02) | Tailoring only | Two Forms of Identification |
| PE-02(03) | Tailoring only | Restrict Unescorted Access |
| PE-03 | Low | Physical Access Control |
| PE-03(01) | High | System Access |
| PE-03(02) | Tailoring only | Facility and Systems |
| PE-03(03) | Tailoring only | Continuous Guards |
| PE-03(04) | Tailoring only | Lockable Casings |
| PE-03(05) | Tailoring only | Tamper Protection |
| PE-03(06) withdrawn → CA-08 | Tailoring only | Facility Penetration Testing |
| PE-03(07) | Tailoring only | Physical Barriers |
| PE-03(08) | Tailoring only | Access Control Vestibules |
| PE-04 | Moderate | Access Control for Transmission |
| PE-05 | Moderate | Access Control for Output Devices |
| PE-05(01) withdrawn → PE-05 | Tailoring only | Access to Output by Authorized Individuals |
| PE-05(02) | Tailoring only | Link to Individual Identity |
| PE-05(03) withdrawn → PE-22 | Tailoring only | Marking Output Devices |
| PE-06 | Low | Monitoring Physical Access |
| PE-06(01) | Moderate | Intrusion Alarms and Surveillance Equipment |
| PE-06(02) | Tailoring only | Automated Intrusion Recognition and Responses |
| PE-06(03) | Tailoring only | Video Surveillance |
| PE-06(04) | High | Monitoring Physical Access to Systems |
| PE-07 withdrawn → PE-02, PE-03 | Tailoring only | Visitor Control |
| PE-08 | Low | Visitor Access Records |
| PE-08(01) | High | Automated Records Maintenance and Review |
| PE-08(02) withdrawn → PE-02 | Tailoring only | Physical Access Records |
| PE-08(03) | Tailoring only | Limit Personally Identifiable Information Elements |
| PE-09 | Moderate | Power Equipment and Cabling |
| PE-09(01) | Tailoring only | Redundant Cabling |
| PE-09(02) | Tailoring only | Automatic Voltage Controls |
| PE-10 | Moderate | Emergency Shutoff |
| PE-10(01) withdrawn → PE-10 | Tailoring only | Accidental and Unauthorized Activation |
| PE-11 | Moderate | Emergency Power |
| PE-11(01) | High | Alternate Power Supply — Minimal Operational Capability |
| PE-11(02) | Tailoring only | Alternate Power Supply — Self-contained |
| PE-12 | Low | Emergency Lighting |
| PE-12(01) | Tailoring only | Essential Mission and Business Functions |
| PE-13 | Low | Fire Protection |
| PE-13(01) | Moderate | Detection Systems — Automatic Activation and Notification |
| PE-13(02) | High | Suppression Systems — Automatic Activation and Notification |
| PE-13(03) withdrawn → PE-13(02) | Tailoring only | Automatic Fire Suppression |
| PE-13(04) | Tailoring only | Inspections |
| PE-14 | Low | Environmental Controls |
| PE-14(01) | Tailoring only | Automatic Controls |
| PE-14(02) | Tailoring only | Monitoring with Alarms and Notifications |
| PE-15 | Low | Water Damage Protection |
| PE-15(01) | High | Automation Support |
| PE-16 | Low | Delivery and Removal |
| PE-17 | Moderate | Alternate Work Site |
| PE-18 | High | Location of System Components |
| PE-18(01) withdrawn → PE-23 | Tailoring only | Facility Site |
| PE-19 | Tailoring only | Information Leakage |
| PE-19(01) | Tailoring only | National Emissions Policies and Procedures |
| PE-20 | Tailoring only | Asset Monitoring and Tracking |
| PE-21 | Tailoring only | Electromagnetic Pulse Protection |
| PE-22 | Tailoring only | Component Marking |
| PE-23 | Tailoring only | Facility Location |
Planning · 17 controls
Our thematic mapping puts this group against (a)
| Control | Level | Title |
|---|---|---|
| PL-01 | Low | Policy and Procedures |
| PL-02 | Low | System Security and Privacy Plans |
| PL-02(01) withdrawn → PL-07 | Tailoring only | Concept of Operations |
| PL-02(02) withdrawn → PL-08 | Tailoring only | Functional Architecture |
| PL-02(03) withdrawn → PL-02 | Tailoring only | Plan and Coordinate with Other Organizational Entities |
| PL-03 withdrawn → PL-02 | Tailoring only | System Security Plan Update |
| PL-04 | Low | Rules of Behavior |
| PL-04(01) | Low | Social Media and External Site/Application Usage Restrictions |
| PL-05 withdrawn → RA-08 | Tailoring only | Privacy Impact Assessment |
| PL-06 withdrawn → PL-02 | Tailoring only | Security-related Activity Planning |
| PL-07 | Tailoring only | Concept of Operations |
| PL-08 | Moderate | Security and Privacy Architectures |
| PL-08(01) | Tailoring only | Defense in Depth |
| PL-08(02) | Tailoring only | Supplier Diversity |
| PL-09 | Tailoring only | Central Management |
| PL-10 | Low | Baseline Selection |
| PL-11 | Low | Baseline Tailoring |
Program Management · 37 controls
Our thematic mapping puts this group against (a) (f)
| Control | Level | Title |
|---|---|---|
| PM-01 | Tailoring only | Information Security Program Plan |
| PM-02 | Tailoring only | Information Security Program Leadership Role |
| PM-03 | Tailoring only | Information Security and Privacy Resources |
| PM-04 | Tailoring only | Plan of Action and Milestones Process |
| PM-05 | Tailoring only | System Inventory |
| PM-05(01) | Tailoring only | Inventory of Personally Identifiable Information |
| PM-06 | Tailoring only | Measures of Performance |
| PM-07 | Tailoring only | Enterprise Architecture |
| PM-07(01) | Tailoring only | Offloading |
| PM-08 | Tailoring only | Critical Infrastructure Plan |
| PM-09 | Tailoring only | Risk Management Strategy |
| PM-10 | Tailoring only | Authorization Process |
| PM-11 | Tailoring only | Mission and Business Process Definition |
| PM-12 | Tailoring only | Insider Threat Program |
| PM-13 | Tailoring only | Security and Privacy Workforce |
| PM-14 | Tailoring only | Testing, Training, and Monitoring |
| PM-15 | Tailoring only | Security and Privacy Groups and Associations |
| PM-16 | Tailoring only | Threat Awareness Program |
| PM-16(01) | Tailoring only | Automated Means for Sharing Threat Intelligence |
| PM-17 | Tailoring only | Protecting Controlled Unclassified Information on External Systems |
| PM-18 | Tailoring only | Privacy Program Plan |
| PM-19 | Tailoring only | Privacy Program Leadership Role |
| PM-20 | Tailoring only | Dissemination of Privacy Program Information |
| PM-20(01) | Tailoring only | Privacy Policies on Websites, Applications, and Digital Services |
| PM-21 | Tailoring only | Accounting of Disclosures |
| PM-22 | Tailoring only | Personally Identifiable Information Quality Management |
| PM-23 | Tailoring only | Data Governance Body |
| PM-24 | Tailoring only | Data Integrity Board |
| PM-25 | Tailoring only | Minimization of Personally Identifiable Information Used in Testing, Training, and Research |
| PM-26 | Tailoring only | Complaint Management |
| PM-27 | Tailoring only | Privacy Reporting |
| PM-28 | Tailoring only | Risk Framing |
| PM-29 | Tailoring only | Risk Management Program Leadership Roles |
| PM-30 | Tailoring only | Supply Chain Risk Management Strategy |
| PM-30(01) | Tailoring only | Suppliers of Critical or Mission-essential Items |
| PM-31 | Tailoring only | Continuous Monitoring Strategy |
| PM-32 | Tailoring only | Purposing |
Personnel Security · 18 controls
Our thematic mapping puts this group against (i)
| Control | Level | Title |
|---|---|---|
| PS-01 | Low | Policy and Procedures |
| PS-02 | Low | Position Risk Designation |
| PS-03 | Low | Personnel Screening |
| PS-03(01) | Tailoring only | Classified Information |
| PS-03(02) | Tailoring only | Formal Indoctrination |
| PS-03(03) | Tailoring only | Information Requiring Special Protective Measures |
| PS-03(04) | Tailoring only | Citizenship Requirements |
| PS-04 | Low | Personnel Termination |
| PS-04(01) | Tailoring only | Post-employment Requirements |
| PS-04(02) | High | Automated Actions |
| PS-05 | Low | Personnel Transfer |
| PS-06 | Low | Access Agreements |
| PS-06(01) withdrawn → PS-03 | Tailoring only | Information Requiring Special Protection |
| PS-06(02) | Tailoring only | Classified Information Requiring Special Protection |
| PS-06(03) | Tailoring only | Post-employment Requirements |
| PS-07 | Low | External Personnel Security |
| PS-08 | Low | Personnel Sanctions |
| PS-09 | Low | Position Descriptions |
Personally Identifiable Information Processing and Transparency · 21 controls
Personally Identifiable Information Processing and Transparency (PT)
| Control | Level | Title |
|---|---|---|
| PT-01 | Tailoring only | Policy and Procedures |
| PT-02 | Tailoring only | Authority to Process Personally Identifiable Information |
| PT-02(01) | Tailoring only | Data Tagging |
| PT-02(02) | Tailoring only | Automation |
| PT-03 | Tailoring only | Personally Identifiable Information Processing Purposes |
| PT-03(01) | Tailoring only | Data Tagging |
| PT-03(02) | Tailoring only | Automation |
| PT-04 | Tailoring only | Consent |
| PT-04(01) | Tailoring only | Tailored Consent |
| PT-04(02) | Tailoring only | Just-in-time Consent |
| PT-04(03) | Tailoring only | Revocation |
| PT-05 | Tailoring only | Privacy Notice |
| PT-05(01) | Tailoring only | Just-in-time Notice |
| PT-05(02) | Tailoring only | Privacy Act Statements |
| PT-06 | Tailoring only | System of Records Notice |
| PT-06(01) | Tailoring only | Routine Uses |
| PT-06(02) | Tailoring only | Exemption Rules |
| PT-07 | Tailoring only | Specific Categories of Personally Identifiable Information |
| PT-07(01) | Tailoring only | Social Security Numbers |
| PT-07(02) | Tailoring only | First Amendment Information |
| PT-08 | Tailoring only | Computer Matching Requirements |
Risk Assessment · 26 controls
Our thematic mapping puts this group against (a) (e)
| Control | Level | Title |
|---|---|---|
| RA-01 | Low | Policy and Procedures |
| RA-02 | Low | Security Categorization |
| RA-02(01) | Tailoring only | Impact-level Prioritization |
| RA-03 | Low | Risk Assessment |
| RA-03(01) | Low | Supply Chain Risk Assessment |
| RA-03(02) | Tailoring only | Use of All-source Intelligence |
| RA-03(03) | Tailoring only | Dynamic Threat Awareness |
| RA-03(04) | Tailoring only | Predictive Cyber Analytics |
| RA-04 withdrawn → RA-03 | Tailoring only | Risk Assessment Update |
| RA-05 | Low | Vulnerability Monitoring and Scanning |
| RA-05(01) withdrawn → RA-05 | Tailoring only | Update Tool Capability |
| RA-05(02) | Low | Update Vulnerabilities to Be Scanned |
| RA-05(03) | Tailoring only | Breadth and Depth of Coverage |
| RA-05(04) | High | Discoverable Information |
| RA-05(05) | Moderate | Privileged Access |
| RA-05(06) | Tailoring only | Automated Trend Analyses |
| RA-05(07) withdrawn → CM-08 | Tailoring only | Automated Detection and Notification of Unauthorized Components |
| RA-05(08) | Tailoring only | Review Historic Audit Logs |
| RA-05(09) withdrawn → CA-08 | Tailoring only | Penetration Testing and Analyses |
| RA-05(10) | Tailoring only | Correlate Scanning Information |
| RA-05(11) | Low | Public Disclosure Program |
| RA-06 | Tailoring only | Technical Surveillance Countermeasures Survey |
| RA-07 | Low | Risk Response |
| RA-08 | Tailoring only | Privacy Impact Assessments |
| RA-09 | Moderate | Criticality Analysis |
| RA-10 | Tailoring only | Threat Hunting |
System and Services Acquisition · 147 controls
System and Services Acquisition (SA)
Our thematic mapping puts this group against (d) (e)
| Control | Level | Title |
|---|---|---|
| SA-01 | Low | Policy and Procedures |
| SA-02 | Low | Allocation of Resources |
| SA-03 | Low | System Development Life Cycle |
| SA-03(01) | Tailoring only | Manage Preproduction Environment |
| SA-03(02) | Tailoring only | Use of Live or Operational Data |
| SA-03(03) | Tailoring only | Technology Refresh |
| SA-04 | Low | Acquisition Process |
| SA-04(01) | Moderate | Functional Properties of Controls |
| SA-04(02) | Moderate | Design and Implementation Information for Controls |
| SA-04(03) | Tailoring only | Development Methods, Techniques, and Practices |
| SA-04(04) withdrawn → CM-08(09) | Tailoring only | Assignment of Components to Systems |
| SA-04(05) | High | System, Component, and Service Configurations |
| SA-04(06) | Tailoring only | Use of Information Assurance Products |
| SA-04(07) | Tailoring only | NIAP-approved Protection Profiles |
| SA-04(08) | Tailoring only | Continuous Monitoring Plan for Controls |
| SA-04(09) | Moderate | Functions, Ports, Protocols, and Services in Use |
| SA-04(10) | Low | Use of Approved PIV Products |
| SA-04(11) | Tailoring only | System of Records |
| SA-04(12) | Tailoring only | Data Ownership |
| SA-05 | Low | System Documentation |
| SA-05(01) withdrawn → SA-04(01) | Tailoring only | Functional Properties of Security Controls |
| SA-05(02) withdrawn → SA-04(02) | Tailoring only | Security-relevant External System Interfaces |
| SA-05(03) withdrawn → SA-04(02) | Tailoring only | High-level Design |
| SA-05(04) withdrawn → SA-04(02) | Tailoring only | Low-level Design |
| SA-05(05) withdrawn → SA-04(02) | Tailoring only | Source Code |
| SA-06 withdrawn → CM-10, SI-07 | Tailoring only | Software Usage Restrictions |
| SA-07 withdrawn → CM-11, SI-07 | Tailoring only | User-installed Software |
| SA-08 | Low | Security and Privacy Engineering Principles |
| SA-08(01) | Tailoring only | Clear Abstractions |
| SA-08(02) | Tailoring only | Least Common Mechanism |
| SA-08(03) | Tailoring only | Modularity and Layering |
| SA-08(04) | Tailoring only | Partially Ordered Dependencies |
| SA-08(05) | Tailoring only | Efficiently Mediated Access |
| SA-08(06) | Tailoring only | Minimized Sharing |
| SA-08(07) | Tailoring only | Reduced Complexity |
| SA-08(08) | Tailoring only | Secure Evolvability |
| SA-08(09) | Tailoring only | Trusted Components |
| SA-08(10) | Tailoring only | Hierarchical Trust |
| SA-08(11) | Tailoring only | Inverse Modification Threshold |
| SA-08(12) | Tailoring only | Hierarchical Protection |
| SA-08(13) | Tailoring only | Minimized Security Elements |
| SA-08(14) | Tailoring only | Least Privilege |
| SA-08(15) | Tailoring only | Predicate Permission |
| SA-08(16) | Tailoring only | Self-reliant Trustworthiness |
| SA-08(17) | Tailoring only | Secure Distributed Composition |
| SA-08(18) | Tailoring only | Trusted Communications Channels |
| SA-08(19) | Tailoring only | Continuous Protection |
| SA-08(20) | Tailoring only | Secure Metadata Management |
| SA-08(21) | Tailoring only | Self-analysis |
| SA-08(22) | Tailoring only | Accountability and Traceability |
| SA-08(23) | Tailoring only | Secure Defaults |
| SA-08(24) | Tailoring only | Secure Failure and Recovery |
| SA-08(25) | Tailoring only | Economic Security |
| SA-08(26) | Tailoring only | Performance Security |
| SA-08(27) | Tailoring only | Human Factored Security |
| SA-08(28) | Tailoring only | Acceptable Security |
| SA-08(29) | Tailoring only | Repeatable and Documented Procedures |
| SA-08(30) | Tailoring only | Procedural Rigor |
| SA-08(31) | Tailoring only | Secure System Modification |
| SA-08(32) | Tailoring only | Sufficient Documentation |
| SA-08(33) | Tailoring only | Minimization |
| SA-09 | Low | External System Services |
| SA-09(01) | Tailoring only | Risk Assessments and Organizational Approvals |
| SA-09(02) | Moderate | Identification of Functions, Ports, Protocols, and Services |
| SA-09(03) | Tailoring only | Establish and Maintain Trust Relationship with Providers |
| SA-09(04) | Tailoring only | Consistent Interests of Consumers and Providers |
| SA-09(05) | Tailoring only | Processing, Storage, and Service Location |
| SA-09(06) | Tailoring only | Organization-controlled Cryptographic Keys |
| SA-09(07) | Tailoring only | Organization-controlled Integrity Checking |
| SA-09(08) | Tailoring only | Processing and Storage Location — U.S. Jurisdiction |
| SA-10 | Moderate | Developer Configuration Management |
| SA-10(01) | Tailoring only | Software and Firmware Integrity Verification |
| SA-10(02) | Tailoring only | Alternative Configuration Management Processes |
| SA-10(03) | Tailoring only | Hardware Integrity Verification |
| SA-10(04) | Tailoring only | Trusted Generation |
| SA-10(05) | Tailoring only | Mapping Integrity for Version Control |
| SA-10(06) | Tailoring only | Trusted Distribution |
| SA-10(07) | Tailoring only | Security and Privacy Representatives |
| SA-11 | Moderate | Developer Testing and Evaluation |
| SA-11(01) | Tailoring only | Static Code Analysis |
| SA-11(02) | Tailoring only | Threat Modeling and Vulnerability Analyses |
| SA-11(03) | Tailoring only | Independent Verification of Assessment Plans and Evidence |
| SA-11(04) | Tailoring only | Manual Code Reviews |
| SA-11(05) | Tailoring only | Penetration Testing |
| SA-11(06) | Tailoring only | Attack Surface Reviews |
| SA-11(07) | Tailoring only | Verify Scope of Testing and Evaluation |
| SA-11(08) | Tailoring only | Dynamic Code Analysis |
| SA-11(09) | Tailoring only | Interactive Application Security Testing |
| SA-12 withdrawn → SR | Tailoring only | Supply Chain Protection |
| SA-12(01) withdrawn → SR-05 | Tailoring only | Acquisition Strategies / Tools / Methods |
| SA-12(02) withdrawn → SR-06 | Tailoring only | Supplier Reviews |
| SA-12(03) withdrawn → SR-03 | Tailoring only | Trusted Shipping and Warehousing |
| SA-12(04) withdrawn → SR-03(01) | Tailoring only | Diversity of Suppliers |
| SA-12(05) withdrawn → SR-03(02) | Tailoring only | Limitation of Harm |
| SA-12(06) withdrawn → SR-05(01) | Tailoring only | Minimizing Procurement Time |
| SA-12(07) withdrawn → SR-05(02) | Tailoring only | Assessments Prior to Selection / Acceptance / Update |
| SA-12(08) withdrawn → RA-03(02) | Tailoring only | Use of All-source Intelligence |
| SA-12(09) withdrawn → SR-07 | Tailoring only | Operations Security |
| SA-12(10) withdrawn → SR-04(03) | Tailoring only | Validate as Genuine and Not Altered |
| SA-12(11) withdrawn → SR-06(01) | Tailoring only | Penetration Testing / Analysis of Elements, Processes, and Actors |
| SA-12(12) withdrawn → SR-08 | Tailoring only | Inter-organizational Agreements |
| SA-12(13) withdrawn → MA-06, RA-09 | Tailoring only | Critical Information System Components |
| SA-12(14) withdrawn → SR-04(01), SR-04(02) | Tailoring only | Identity and Traceability |
| SA-12(15) withdrawn → SR-03 | Tailoring only | Processes to Address Weaknesses or Deficiencies |
| SA-13 withdrawn → SA-08 | Tailoring only | Trustworthiness |
| SA-14 withdrawn → RA-09 | Tailoring only | Criticality Analysis |
| SA-14(01) withdrawn → SA-20 | Tailoring only | Critical Components with No Viable Alternative Sourcing |
| SA-15 | Moderate | Development Process, Standards, and Tools |
| SA-15(01) | Tailoring only | Quality Metrics |
| SA-15(02) | Tailoring only | Security and Privacy Tracking Tools |
| SA-15(03) | Moderate | Criticality Analysis |
| SA-15(04) withdrawn → SA-11(02) | Tailoring only | Threat Modeling and Vulnerability Analysis |
| SA-15(05) | Tailoring only | Attack Surface Reduction |
| SA-15(06) | Tailoring only | Continuous Improvement |
| SA-15(07) | Tailoring only | Automated Vulnerability Analysis |
| SA-15(08) | Tailoring only | Reuse of Threat and Vulnerability Information |
| SA-15(09) withdrawn → SA-03(02) | Tailoring only | Use of Live Data |
| SA-15(10) | Tailoring only | Incident Response Plan |
| SA-15(11) | Tailoring only | Archive System or Component |
| SA-15(12) | Tailoring only | Minimize Personally Identifiable Information |
| SA-15(13) | Tailoring only | Logging Syntax |
| SA-16 | High | Developer-provided Training |
| SA-17 | High | Developer Security and Privacy Architecture and Design |
| SA-17(01) | Tailoring only | Formal Policy Model |
| SA-17(02) | Tailoring only | Security-relevant Components |
| SA-17(03) | Tailoring only | Formal Correspondence |
| SA-17(04) | Tailoring only | Informal Correspondence |
| SA-17(05) | Tailoring only | Conceptually Simple Design |
| SA-17(06) | Tailoring only | Structure for Testing |
| SA-17(07) | Tailoring only | Structure for Least Privilege |
| SA-17(08) | Tailoring only | Orchestration |
| SA-17(09) | Tailoring only | Design Diversity |
| SA-18 withdrawn → SR-09 | Tailoring only | Tamper Resistance and Detection |
| SA-18(01) withdrawn → SR-09(01) | Tailoring only | Multiple Phases of System Development Life Cycle |
| SA-18(02) withdrawn → SR-10 | Tailoring only | Inspection of Systems or Components |
| SA-19 withdrawn → SR-11 | Tailoring only | Component Authenticity |
| SA-19(01) withdrawn → SR-11(01) | Tailoring only | Anti-counterfeit Training |
| SA-19(02) withdrawn → SR-11(02) | Tailoring only | Configuration Control for Component Service and Repair |
| SA-19(03) withdrawn → SR-12 | Tailoring only | Component Disposal |
| SA-19(04) withdrawn → SR-11(03) | Tailoring only | Anti-counterfeit Scanning |
| SA-20 | Tailoring only | Customized Development of Critical Components |
| SA-21 | High | Developer Screening |
| SA-21(01) withdrawn → SA-21 | Tailoring only | Validation of Screening |
| SA-22 | Low | Unsupported System Components |
| SA-22(01) withdrawn → SA-22 | Tailoring only | Alternative Sources for Continued Support |
| SA-23 | Tailoring only | Specialization |
| SA-24 | Tailoring only | Design For Cyber Resiliency |
System and Communications Protection · 162 controls
System and Communications Protection (SC)
Our thematic mapping puts this group against (h) (j)
| Control | Level | Title |
|---|---|---|
| SC-01 | Low | Policy and Procedures |
| SC-02 | Moderate | Separation of System and User Functionality |
| SC-02(01) | Tailoring only | Interfaces for Non-privileged Users |
| SC-02(02) | Tailoring only | Disassociability |
| SC-03 | High | Security Function Isolation |
| SC-03(01) | Tailoring only | Hardware Separation |
| SC-03(02) | Tailoring only | Access and Flow Control Functions |
| SC-03(03) | Tailoring only | Minimize Nonsecurity Functionality |
| SC-03(04) | Tailoring only | Module Coupling and Cohesiveness |
| SC-03(05) | Tailoring only | Layered Structures |
| SC-04 | Moderate | Information in Shared System Resources |
| SC-04(01) withdrawn → SC-04 | Tailoring only | Security Levels |
| SC-04(02) | Tailoring only | Multilevel or Periods Processing |
| SC-05 | Low | Denial-of-service Protection |
| SC-05(01) | Tailoring only | Restrict Ability to Attack Other Systems |
| SC-05(02) | Tailoring only | Capacity, Bandwidth, and Redundancy |
| SC-05(03) | Tailoring only | Detection and Monitoring |
| SC-06 | Tailoring only | Resource Availability |
| SC-07 | Low | Boundary Protection |
| SC-07(01) withdrawn → SC-07 | Tailoring only | Physically Separated Subnetworks |
| SC-07(02) withdrawn → SC-07 | Tailoring only | Public Access |
| SC-07(03) | Moderate | Access Points |
| SC-07(04) | Moderate | External Telecommunications Services |
| SC-07(05) | Moderate | Deny by Default — Allow by Exception |
| SC-07(06) withdrawn → SC-07(18) | Tailoring only | Response to Recognized Failures |
| SC-07(07) | Moderate | Split Tunneling for Remote Devices |
| SC-07(08) | Moderate | Route Traffic to Authenticated Proxy Servers |
| SC-07(09) | Tailoring only | Restrict Threatening Outgoing Communications Traffic |
| SC-07(10) | Tailoring only | Prevent Exfiltration |
| SC-07(11) | Tailoring only | Restrict Incoming Communications Traffic |
| SC-07(12) | Tailoring only | Host-based Protection |
| SC-07(13) | Tailoring only | Isolation of Security Tools, Mechanisms, and Support Components |
| SC-07(14) | Tailoring only | Protect Against Unauthorized Physical Connections |
| SC-07(15) | Tailoring only | Networked Privileged Accesses |
| SC-07(16) | Tailoring only | Prevent Discovery of System Components |
| SC-07(17) | Tailoring only | Automated Enforcement of Protocol Formats |
| SC-07(18) | High | Fail Secure |
| SC-07(19) | Tailoring only | Block Communication from Non-organizationally Configured Hosts |
| SC-07(20) | Tailoring only | Dynamic Isolation and Segregation |
| SC-07(21) | High | Isolation of System Components |
| SC-07(22) | Tailoring only | Separate Subnets for Connecting to Different Security Domains |
| SC-07(23) | Tailoring only | Disable Sender Feedback on Protocol Validation Failure |
| SC-07(24) | Tailoring only | Personally Identifiable Information |
| SC-07(25) | Tailoring only | Unclassified National Security System Connections |
| SC-07(26) | Tailoring only | Classified National Security System Connections |
| SC-07(27) | Tailoring only | Unclassified Non-national Security System Connections |
| SC-07(28) | Tailoring only | Connections to Public Networks |
| SC-07(29) | Tailoring only | Separate Subnets to Isolate Functions |
| SC-08 | Moderate | Transmission Confidentiality and Integrity |
| SC-08(01) | Moderate | Cryptographic Protection |
| SC-08(02) | Tailoring only | Pre- and Post-transmission Handling |
| SC-08(03) | Tailoring only | Cryptographic Protection for Message Externals |
| SC-08(04) | Tailoring only | Conceal or Randomize Communications |
| SC-08(05) | Tailoring only | Protected Distribution System |
| SC-09 withdrawn → SC-08 | Tailoring only | Transmission Confidentiality |
| SC-10 | Moderate | Network Disconnect |
| SC-11 | Tailoring only | Trusted Path |
| SC-11(01) | Tailoring only | Irrefutable Communications Path |
| SC-12 | Low | Cryptographic Key Establishment and Management |
| SC-12(01) | High | Availability |
| SC-12(02) | Tailoring only | Symmetric Keys |
| SC-12(03) | Tailoring only | Asymmetric Keys |
| SC-12(04) withdrawn → SC-12(03) | Tailoring only | PKI Certificates |
| SC-12(05) withdrawn → SC-12(03) | Tailoring only | PKI Certificates / Hardware Tokens |
| SC-12(06) | Tailoring only | Physical Control of Keys |
| SC-13 | Low | Cryptographic Protection |
| SC-13(01) withdrawn → SC-13 | Tailoring only | FIPS-validated Cryptography |
| SC-13(02) withdrawn → SC-13 | Tailoring only | NSA-approved Cryptography |
| SC-13(03) withdrawn → SC-13 | Tailoring only | Individuals Without Formal Access Approvals |
| SC-13(04) withdrawn → SC-13 | Tailoring only | Digital Signatures |
| SC-14 withdrawn → AC-02, AC-03, AC-05, AC-06, SI-03, SI-04, SI-05, SI-07, SI-10 | Tailoring only | Public Access Protections |
| SC-15 | Low | Collaborative Computing Devices and Applications |
| SC-15(01) | Tailoring only | Physical or Logical Disconnect |
| SC-15(02) withdrawn → SC-07 | Tailoring only | Blocking Inbound and Outbound Communications Traffic |
| SC-15(03) | Tailoring only | Disabling and Removal in Secure Work Areas |
| SC-15(04) | Tailoring only | Explicitly Indicate Current Participants |
| SC-16 | Tailoring only | Transmission of Security and Privacy Attributes |
| SC-16(01) | Tailoring only | Integrity Verification |
| SC-16(02) | Tailoring only | Anti-spoofing Mechanisms |
| SC-16(03) | Tailoring only | Cryptographic Binding |
| SC-17 | Moderate | Public Key Infrastructure Certificates |
| SC-18 | Moderate | Mobile Code |
| SC-18(01) | Tailoring only | Identify Unacceptable Code and Take Corrective Actions |
| SC-18(02) | Tailoring only | Acquisition, Development, and Use |
| SC-18(03) | Tailoring only | Prevent Downloading and Execution |
| SC-18(04) | Tailoring only | Prevent Automatic Execution |
| SC-18(05) | Tailoring only | Allow Execution Only in Confined Environments |
| SC-19 withdrawn | Tailoring only | Voice Over Internet Protocol |
| SC-20 | Low | Secure Name/Address Resolution Service (Authoritative Source) |
| SC-20(01) withdrawn → SC-20 | Tailoring only | Child Subspaces |
| SC-20(02) | Tailoring only | Data Origin and Integrity |
| SC-21 | Low | Secure Name/Address Resolution Service (Recursive or Caching Resolver) |
| SC-21(01) withdrawn → SC-21 | Tailoring only | Data Origin and Integrity |
| SC-22 | Low | Architecture and Provisioning for Name/Address Resolution Service |
| SC-23 | Moderate | Session Authenticity |
| SC-23(01) | Tailoring only | Invalidate Session Identifiers at Logout |
| SC-23(02) withdrawn → AC-12(01) | Tailoring only | User-initiated Logouts and Message Displays |
| SC-23(03) | Tailoring only | Unique System-generated Session Identifiers |
| SC-23(04) withdrawn → SC-23(03) | Tailoring only | Unique Session Identifiers with Randomization |
| SC-23(05) | Tailoring only | Allowed Certificate Authorities |
| SC-24 | High | Fail in Known State |
| SC-25 | Tailoring only | Thin Nodes |
| SC-26 | Tailoring only | Decoys |
| SC-26(01) withdrawn → SC-35 | Tailoring only | Detection of Malicious Code |
| SC-27 | Tailoring only | Platform-independent Applications |
| SC-28 | Moderate | Protection of Information at Rest |
| SC-28(01) | Moderate | Cryptographic Protection |
| SC-28(02) | Tailoring only | Offline Storage |
| SC-28(03) | Tailoring only | Cryptographic Keys |
| SC-29 | Tailoring only | Heterogeneity |
| SC-29(01) | Tailoring only | Virtualization Techniques |
| SC-30 | Tailoring only | Concealment and Misdirection |
| SC-30(01) withdrawn → SC-29(01) | Tailoring only | Virtualization Techniques |
| SC-30(02) | Tailoring only | Randomness |
| SC-30(03) | Tailoring only | Change Processing and Storage Locations |
| SC-30(04) | Tailoring only | Misleading Information |
| SC-30(05) | Tailoring only | Concealment of System Components |
| SC-31 | Tailoring only | Covert Channel Analysis |
| SC-31(01) | Tailoring only | Test Covert Channels for Exploitability |
| SC-31(02) | Tailoring only | Maximum Bandwidth |
| SC-31(03) | Tailoring only | Measure Bandwidth in Operational Environments |
| SC-32 | Tailoring only | System Partitioning |
| SC-32(01) | Tailoring only | Separate Physical Domains for Privileged Functions |
| SC-33 withdrawn → SC-08 | Tailoring only | Transmission Preparation Integrity |
| SC-34 | Tailoring only | Non-modifiable Executable Programs |
| SC-34(01) | Tailoring only | No Writable Storage |
| SC-34(02) | Tailoring only | Integrity Protection on Read-only Media |
| SC-34(03) withdrawn → SC-51 | Tailoring only | Hardware-based Protection |
| SC-35 | Tailoring only | External Malicious Code Identification |
| SC-36 | Tailoring only | Distributed Processing and Storage |
| SC-36(01) | Tailoring only | Polling Techniques |
| SC-36(02) | Tailoring only | Synchronization |
| SC-37 | Tailoring only | Out-of-band Channels |
| SC-37(01) | Tailoring only | Ensure Delivery and Transmission |
| SC-38 | Tailoring only | Operations Security |
| SC-39 | Low | Process Isolation |
| SC-39(01) | Tailoring only | Hardware Separation |
| SC-39(02) | Tailoring only | Separate Execution Domain Per Thread |
| SC-40 | Tailoring only | Wireless Link Protection |
| SC-40(01) | Tailoring only | Electromagnetic Interference |
| SC-40(02) | Tailoring only | Reduce Detection Potential |
| SC-40(03) | Tailoring only | Imitative or Manipulative Communications Deception |
| SC-40(04) | Tailoring only | Signal Parameter Identification |
| SC-41 | Tailoring only | Port and I/O Device Access |
| SC-42 | Tailoring only | Sensor Capability and Data |
| SC-42(01) | Tailoring only | Reporting to Authorized Individuals or Roles |
| SC-42(02) | Tailoring only | Authorized Use |
| SC-42(03) withdrawn → SC-42 | Tailoring only | Prohibit Use of Devices |
| SC-42(04) | Tailoring only | Notice of Collection |
| SC-42(05) | Tailoring only | Collection Minimization |
| SC-43 | Tailoring only | Usage Restrictions |
| SC-44 | Tailoring only | Detonation Chambers |
| SC-45 | Tailoring only | System Time Synchronization |
| SC-45(01) | Tailoring only | Synchronization with Authoritative Time Source |
| SC-45(02) | Tailoring only | Secondary Authoritative Time Source |
| SC-46 | Tailoring only | Cross Domain Policy Enforcement |
| SC-47 | Tailoring only | Alternate Communications Paths |
| SC-48 | Tailoring only | Sensor Relocation |
| SC-48(01) | Tailoring only | Dynamic Relocation of Sensors or Monitoring Capabilities |
| SC-49 | Tailoring only | Hardware-enforced Separation and Policy Enforcement |
| SC-50 | Tailoring only | Software-enforced Separation and Policy Enforcement |
| SC-51 | Tailoring only | Hardware-based Protection |
System and Information Integrity · 119 controls
System and Information Integrity (SI)
Our thematic mapping puts this group against (b) (e) (g)
| Control | Level | Title |
|---|---|---|
| SI-01 | Low | Policy and Procedures |
| SI-02 | Low | Flaw Remediation |
| SI-02(01) withdrawn → PL-09 | Tailoring only | Central Management |
| SI-02(02) | Moderate | Automated Flaw Remediation Status |
| SI-02(03) | Tailoring only | Time to Remediate Flaws and Benchmarks for Corrective Actions |
| SI-02(04) | Tailoring only | Automated Patch Management Tools |
| SI-02(05) | Tailoring only | Automatic Software and Firmware Updates |
| SI-02(06) | Tailoring only | Removal of Previous Versions of Software and Firmware |
| SI-02(07) | Tailoring only | Root Cause Analysis |
| SI-03 | Low | Malicious Code Protection |
| SI-03(01) withdrawn → PL-09 | Tailoring only | Central Management |
| SI-03(02) withdrawn → SI-03 | Tailoring only | Automatic Updates |
| SI-03(03) withdrawn → AC-06(10) | Tailoring only | Non-privileged Users |
| SI-03(04) | Tailoring only | Updates Only by Privileged Users |
| SI-03(05) withdrawn → MP-07 | Tailoring only | Portable Storage Devices |
| SI-03(06) | Tailoring only | Testing and Verification |
| SI-03(07) withdrawn → SI-03 | Tailoring only | Nonsignature-based Detection |
| SI-03(08) | Tailoring only | Detect Unauthorized Commands |
| SI-03(09) withdrawn → AC-17(10) | Tailoring only | Authenticate Remote Commands |
| SI-03(10) | Tailoring only | Malicious Code Analysis |
| SI-04 | Low | System Monitoring |
| SI-04(01) | Tailoring only | System-wide Intrusion Detection System |
| SI-04(02) | Moderate | Automated Tools and Mechanisms for Real-time Analysis |
| SI-04(03) | Tailoring only | Automated Tool and Mechanism Integration |
| SI-04(04) | Moderate | Inbound and Outbound Communications Traffic |
| SI-04(05) | Moderate | System-generated Alerts |
| SI-04(06) withdrawn → AC-06(10) | Tailoring only | Restrict Non-privileged Users |
| SI-04(07) | Tailoring only | Automated Response to Suspicious Events |
| SI-04(08) withdrawn → SI-04 | Tailoring only | Protection of Monitoring Information |
| SI-04(09) | Tailoring only | Testing of Monitoring Tools and Mechanisms |
| SI-04(10) | High | Visibility of Encrypted Communications |
| SI-04(11) | Tailoring only | Analyze Communications Traffic Anomalies |
| SI-04(12) | High | Automated Organization-generated Alerts |
| SI-04(13) | Tailoring only | Analyze Traffic and Event Patterns |
| SI-04(14) | High | Wireless Intrusion Detection |
| SI-04(15) | Tailoring only | Wireless to Wireline Communications |
| SI-04(16) | Tailoring only | Correlate Monitoring Information |
| SI-04(17) | Tailoring only | Integrated Situational Awareness |
| SI-04(18) | Tailoring only | Analyze Traffic and Covert Exfiltration |
| SI-04(19) | Tailoring only | Risk for Individuals |
| SI-04(20) | High | Privileged Users |
| SI-04(21) | Tailoring only | Probationary Periods |
| SI-04(22) | High | Unauthorized Network Services |
| SI-04(23) | Tailoring only | Host-based Devices |
| SI-04(24) | Tailoring only | Indicators of Compromise |
| SI-04(25) | Tailoring only | Optimize Network Traffic Analysis |
| SI-05 | Low | Security Alerts, Advisories, and Directives |
| SI-05(01) | High | Automated Alerts and Advisories |
| SI-06 | High | Security and Privacy Function Verification |
| SI-06(01) withdrawn → SI-06 | Tailoring only | Notification of Failed Security Tests |
| SI-06(02) | Tailoring only | Automation Support for Distributed Testing |
| SI-06(03) | Tailoring only | Report Verification Results |
| SI-07 | Moderate | Software, Firmware, and Information Integrity |
| SI-07(01) | Moderate | Integrity Checks |
| SI-07(02) | High | Automated Notifications of Integrity Violations |
| SI-07(03) | Tailoring only | Centrally Managed Integrity Tools |
| SI-07(04) withdrawn → SR-09 | Tailoring only | Tamper-evident Packaging |
| SI-07(05) | High | Automated Response to Integrity Violations |
| SI-07(06) | Tailoring only | Cryptographic Protection |
| SI-07(07) | Moderate | Integration of Detection and Response |
| SI-07(08) | Tailoring only | Auditing Capability for Significant Events |
| SI-07(09) | Tailoring only | Verify Boot Process |
| SI-07(10) | Tailoring only | Protection of Boot Firmware |
| SI-07(11) withdrawn → CM-07(06) | Tailoring only | Confined Environments with Limited Privileges |
| SI-07(12) | Tailoring only | Integrity Verification |
| SI-07(13) withdrawn → CM-07(07) | Tailoring only | Code Execution in Protected Environments |
| SI-07(14) withdrawn → CM-07(08) | Tailoring only | Binary or Machine Executable Code |
| SI-07(15) | High | Code Authentication |
| SI-07(16) | Tailoring only | Time Limit on Process Execution Without Supervision |
| SI-07(17) | Tailoring only | Runtime Application Self-protection |
| SI-08 | Moderate | Spam Protection |
| SI-08(01) withdrawn → PL-09 | Tailoring only | Central Management |
| SI-08(02) | Moderate | Automatic Updates |
| SI-08(03) | Tailoring only | Continuous Learning Capability |
| SI-09 withdrawn → AC-02, AC-03, AC-05, AC-06 | Tailoring only | Information Input Restrictions |
| SI-10 | Moderate | Information Input Validation |
| SI-10(01) | Tailoring only | Manual Override Capability |
| SI-10(02) | Tailoring only | Review and Resolve Errors |
| SI-10(03) | Tailoring only | Predictable Behavior |
| SI-10(04) | Tailoring only | Timing Interactions |
| SI-10(05) | Tailoring only | Restrict Inputs to Trusted Sources and Approved Formats |
| SI-10(06) | Tailoring only | Injection Prevention |
| SI-11 | Moderate | Error Handling |
| SI-12 | Low | Information Management and Retention |
| SI-12(01) | Tailoring only | Limit Personally Identifiable Information Elements |
| SI-12(02) | Tailoring only | Minimize Personally Identifiable Information in Testing, Training, and Research |
| SI-12(03) | Tailoring only | Information Disposal |
| SI-13 | Tailoring only | Predictable Failure Prevention |
| SI-13(01) | Tailoring only | Transferring Component Responsibilities |
| SI-13(02) withdrawn → SI-07(16) | Tailoring only | Time Limit on Process Execution Without Supervision |
| SI-13(03) | Tailoring only | Manual Transfer Between Components |
| SI-13(04) | Tailoring only | Standby Component Installation and Notification |
| SI-13(05) | Tailoring only | Failover Capability |
| SI-14 | Tailoring only | Non-persistence |
| SI-14(01) | Tailoring only | Refresh from Trusted Sources |
| SI-14(02) | Tailoring only | Non-persistent Information |
| SI-14(03) | Tailoring only | Non-persistent Connectivity |
| SI-15 | Tailoring only | Information Output Filtering |
| SI-16 | Moderate | Memory Protection |
| SI-17 | Tailoring only | Fail-safe Procedures |
| SI-18 | Tailoring only | Personally Identifiable Information Quality Operations |
| SI-18(01) | Tailoring only | Automation Support |
| SI-18(02) | Tailoring only | Data Tags |
| SI-18(03) | Tailoring only | Collection |
| SI-18(04) | Tailoring only | Individual Requests |
| SI-18(05) | Tailoring only | Notice of Correction or Deletion |
| SI-19 | Tailoring only | De-identification |
| SI-19(01) | Tailoring only | Collection |
| SI-19(02) | Tailoring only | Archiving |
| SI-19(03) | Tailoring only | Release |
| SI-19(04) | Tailoring only | Removal, Masking, Encryption, Hashing, or Replacement of Direct Identifiers |
| SI-19(05) | Tailoring only | Statistical Disclosure Control |
| SI-19(06) | Tailoring only | Differential Privacy |
| SI-19(07) | Tailoring only | Validated Algorithms and Software |
| SI-19(08) | Tailoring only | Motivated Intruder |
| SI-20 | Tailoring only | Tainting |
| SI-21 | Tailoring only | Information Refresh |
| SI-22 | Tailoring only | Information Diversity |
| SI-23 | Tailoring only | Information Fragmentation |
Supply Chain Risk Management · 27 controls
Supply Chain Risk Management (SR)
Our thematic mapping puts this group against (d)
| Control | Level | Title |
|---|---|---|
| SR-01 | Low | Policy and Procedures |
| SR-02 | Low | Supply Chain Risk Management Plan |
| SR-02(01) | Low | Establish SCRM Team |
| SR-03 | Low | Supply Chain Controls and Processes |
| SR-03(01) | Tailoring only | Diverse Supply Base |
| SR-03(02) | Tailoring only | Limitation of Harm |
| SR-03(03) | Tailoring only | Sub-tier Flow Down |
| SR-04 | Tailoring only | Provenance |
| SR-04(01) | Tailoring only | Identity |
| SR-04(02) | Tailoring only | Track and Trace |
| SR-04(03) | Tailoring only | Validate as Genuine and Not Altered |
| SR-04(04) | Tailoring only | Supply Chain Integrity — Pedigree |
| SR-05 | Low | Acquisition Strategies, Tools, and Methods |
| SR-05(01) | Tailoring only | Adequate Supply |
| SR-05(02) | Tailoring only | Assessments Prior to Selection, Acceptance, Modification, or Update |
| SR-06 | Moderate | Supplier Assessments and Reviews |
| SR-06(01) | Tailoring only | Testing and Analysis |
| SR-07 | Tailoring only | Supply Chain Operations Security |
| SR-08 | Low | Notification Agreements |
| SR-09 | High | Tamper Resistance and Detection |
| SR-09(01) | High | Multiple Stages of System Development Life Cycle |
| SR-10 | Low | Inspection of Systems or Components |
| SR-11 | Low | Component Authenticity |
| SR-11(01) | Low | Anti-counterfeit Training |
| SR-11(02) | Low | Configuration Control for Component Service and Repair |
| SR-11(03) | Tailoring only | Anti-counterfeit Scanning |
| SR-12 | Low | Component Disposal |
Where each reference takes you
Every identifier on this page is a link. Inside the site: a control identifier links to itself, so you can cite a single row in an audit note; a group heading links to itself; and every article 21(2) letter opens that measure in full — its wording, what it means and what an auditor asks for.
Catalogue reviewed , against NIST SP 800-53 Rev. 5 requirements of 5.2.0. NIST 800-53 and the documents it comes from belong to National Institute of Standards and Technology (NIST).
We are not affiliated with National Institute of Standards and Technology (NIST). NIST 800-53 and related marks belong to their owners.