Security Controls Quick Reference

A comprehensive, searchable reference of all NIST SP 800-53 Revision 5 security and privacy controls. Browse by control family, search for specific controls, and link directly to official NIST documentation.

Controls for managing who can access what within an information system, including account management, access enforcement, separation of duties, least privilege, remote access, and wireless access.

Description

Develop, document, and disseminate access control policy and procedures consistent with applicable laws, executive orders, directives, regulations, policies, standards, and guidelines. These policies address purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance. Procedures facilitate the implementation of the access control policy and associated controls. Policies and procedures are reviewed and updated on an organization-defined frequency and following organization-defined events.

Description

Define and manage system account types, establish conditions for group and role membership, specify authorized users of the system, and manage the complete account lifecycle including creation, activation, modification, review, disabling, and removal. Require approvals for requests to create accounts, review accounts on an organization-defined frequency, and establish and implement a process for changing shared or group account authenticators when members leave the group.

Description

Enforce approved authorizations for logical access to information and system resources in accordance with applicable access control policies. Access control policies control access between active entities or subjects and passive entities or objects in organizational systems. Access enforcement mechanisms can be employed at the application and service level to provide increased information security and privacy.

Description

Enforce approved authorizations for controlling the flow of information within the system and between connected systems based on organization-defined information flow control policies. Information flow control regulates where information can travel within a system and between systems as opposed to who can access the information. Flow control restrictions include blocking external traffic that claims to be from within the organization, keeping export-controlled information from being transmitted in the clear to the internet, and restricting web requests that are not from the internal web proxy server.

Description

Identify and document duties of individuals requiring separation, and define system access authorizations to support separation of duties. Separation of duties addresses the potential for abuse of authorized privileges and helps to reduce the risk of malevolent activity without collusion. Separation of duties includes dividing mission or business functions and support functions among different individuals or roles, conducting system support functions with different individuals, and ensuring that security personnel administering access control functions do not also administer audit functions.

Description

Employ the principle of least privilege, allowing only authorized accesses for users and processes which are necessary to accomplish assigned organizational tasks. Organizations employ least privilege for specific duties and systems, including for specific system processes, restricting privileges to only those that are necessary. The principle of least privilege is also applied to system processes, ensuring that the processes have only the minimum level of access needed to perform their functions.

Description

Enforce a limit of consecutive invalid logon attempts by a user during an organization-defined time period and automatically lock the account or node for an organization-defined time period, lock the account or node until released by an administrator, delay the next logon prompt for an organization-defined delay period, notify the system administrator, or take other organization-defined action when the maximum number of unsuccessful attempts is exceeded.

Description

Display an approved system use notification message or banner to users before granting access to the system that provides privacy and security notices consistent with applicable laws, executive orders, directives, regulations, policies, standards, and guidelines. The system use notification message states that users are accessing a government or organizational information system, system usage may be monitored, recorded, and subject to audit, unauthorized use of the system is prohibited and subject to criminal and civil penalties, and use of the system indicates consent to monitoring and recording.

Description

Notify the user, upon successful logon to the system, of the date and time of the last logon, the number of unsuccessful logon attempts since the last successful logon, and any changes to account information or the security posture of the system during the defined time period. This control provides users with information about recent account activity so they can determine if any unauthorized activity has occurred.

Description

Limit the number of concurrent sessions for each system account to an organization-defined number of sessions. Organizations may define the maximum number of concurrent sessions for system accounts globally, by account type, by account, or by a combination thereof. This control addresses concurrent sessions for system accounts and does not address concurrent sessions by single users via multiple system accounts.

Description

Prevent further access to the system by initiating a device lock after an organization-defined time period of inactivity. Device locks are temporary actions taken to prevent logical access to the system when the user stops work and moves away from the immediate physical vicinity of the system but does not want to log out. Device locks can be implemented at the operating system level or at the application level, and may conceal previously visible information with a publicly viewable image.

Description

Automatically terminate a user session after organization-defined conditions or trigger events requiring session disconnect. Session termination addresses the termination of user-initiated logical sessions in contrast to the termination of network connections associated with communications sessions. Conditions or trigger events requiring automatic session termination include organization-defined periods of user inactivity, targeted responses to certain types of incidents, and time-of-day restrictions on system use.

Description

Identify user actions that can be performed on the system without identification or authentication consistent with organizational mission and business functions. Organizations may allow a limited number of user actions without identification or authentication, including accessing public websites or other publicly accessible federal systems, viewing information in public areas, and accessing certain organizational systems to obtain information that is not sensitive or classified.

Description

Provide the means to associate organization-defined types of security and privacy attributes with organization-defined security and privacy attribute values for information in storage, in process, and in transmission. Information is represented internally within systems using abstractions known as data structures. Security and privacy attributes are associated with these internal data structures so that the attributes are available when the information is processed. Security and privacy attributes can also be associated with the information being exchanged between systems.

Description

Establish and document usage restrictions, configuration and connection requirements, and implementation guidance for each type of remote access allowed. Authorize each type of remote access to the system prior to allowing such connections. Remote access is access to organizational systems or processes that communicate through external networks such as the internet. Types of remote access include dial-up, broadband, and wireless. Organizations limit remote access to reduce exposure to vulnerabilities from external networks.

Description

Establish configuration and connection requirements and implementation guidance for each type of wireless access. Authorize each type of wireless access to the system prior to allowing such connections. Wireless technologies include microwave, packet radio, satellite, and spread spectrum. Wireless networks use authentication protocols that provide credential protection and mutual authentication. Organizations protect wireless access using authentication, encryption, and monitoring of wireless activities.

Description

Establish configuration and connection requirements and implementation guidance for organization-controlled mobile devices, and authorize the connection of mobile devices to organizational systems. A mobile device is a computing device that has a small form factor such that it can easily be carried by a single individual, is designed to operate without a physical connection, possesses local and non-removable or removable data storage, and includes a self-contained power source. Usage restrictions and specific implementation guidance for mobile devices include configuration management, device identification and authentication, implementation of mandatory protective software, and scanning devices for malicious code.

Description

Establish terms and conditions, consistent with any trust relationships established with other organizations owning, operating, or maintaining external systems, allowing authorized individuals to access the system from external systems and to process, store, or transmit organization-controlled information using external systems. External systems are systems that are used by but are not part of organizational systems and for which the organization has no direct control over the implementation of required security and privacy controls.

Description

Enable authorized users to determine whether access authorizations assigned to a sharing partner match the access restrictions on the information for organization-defined information sharing circumstances where user discretion is required. Employ organization-defined automated mechanisms or manual processes to assist users in making information sharing and collaboration decisions. Access authorization information includes access rules, permissions, and attributes.

Description

Designate individuals authorized to post information onto a publicly accessible system. Train authorized individuals to ensure that publicly accessible information does not contain nonpublic information. Review the proposed content of information prior to posting onto the publicly accessible system to ensure that nonpublic information is not included. Review the content on the publicly accessible system for nonpublic information on an organization-defined frequency and remove such information if discovered.

Description

Employ organization-defined data mining prevention and detection techniques for organization-defined data storage objects to detect and protect against unauthorized data mining. Data mining is an analytical process that attempts to find correlations or patterns in large data sets for the purpose of data or knowledge discovery. Data storage objects include database records and database fields. Organizations determine if there are adequate protections in place to protect sensitive information prior to publishing data or connecting systems to shared data environments.

Description

Establish procedures to ensure that organization-defined access control decisions are applied to each access request prior to access enforcement. Access control decisions are based on the content of access rules or databases specified by organizational access control policies. Organizations ensure that access control decisions are properly applied by systems prior to enforcing access, and verification of correct application of access controls can be done through system testing and code reviews.

Description

Implement a reference monitor for organization-defined access control policies that is tamperproof, always invoked, and small enough to be subject to analysis and testing, the completeness of which can be assured. A reference monitor is a set of design requirements on a reference validation mechanism that enforces an access control policy over all subjects and objects in a system. The reference validation mechanism is always invoked, tamper proof, and small enough to be subject to complete analysis and testing.

Controls ensuring that personnel are adequately trained and aware of security and privacy risks, policies, and procedures relevant to their roles.

Description

Develop, document, and disseminate awareness and training policy and procedures that address purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance. Review and update the current awareness and training policy and procedures on an organization-defined frequency and following organization-defined events.

Description

Provide security and privacy literacy training to system users, including initial training when the user is provided access and subsequent updates on an organization-defined frequency. Training content includes recognizing and reporting potential indicators of insider threat, recognizing social engineering attempts, understanding security responsibilities, and reporting suspicious activities. Literacy training is a prerequisite to role-based training and ensures all users have a foundational understanding of security and privacy principles.

Description

Provide role-based security and privacy training to personnel with assigned security and privacy roles and responsibilities before authorizing access to the system or performing assigned duties and on an organization-defined frequency thereafter. Role-based training addresses management, operational, and technical roles and responsibilities covering physical, personnel, and technical controls. Organizations provide role-based training to system developers, enterprise architects, security and privacy architects, system and network administrators, and personnel performing configuration management activities.

Description

Document and monitor individual information security and privacy training activities, including basic security and privacy awareness training and specific role-based training. Retain individual training records for an organization-defined time period. Training records can be automated and can be maintained by the security and privacy training program, the human resources department, or individual supervisors.

Description

Provide feedback on organizational training results on an organization-defined frequency to the following personnel: training developers, training instructors, and organization-defined personnel. Training feedback ensures that training remains relevant and effective. Feedback mechanisms include post-training evaluations, assessment results, lessons learned from incidents, and changes in threat landscape that may necessitate updates to training content and delivery methods.

Controls for creating, protecting, and retaining system audit records to enable monitoring, analysis, investigation, and reporting of unlawful or unauthorized activities.

Description

Develop, document, and disseminate audit and accountability policy and procedures that address purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance. Review and update the current audit and accountability policy and procedures on an organization-defined frequency and following organization-defined events.

Description

Identify the types of events that the system is capable of logging in support of the audit function, including successful and unsuccessful account logon events, account management events, object access, policy change, privilege functions, process tracking, and system events. Coordinate the event logging function with other organizational entities requiring audit-related information to guide and inform the selection criteria for events to be logged. Review and update the list of auditable events on an organization-defined frequency.

Description

Ensure that audit records contain information that establishes the following: what type of event occurred, when the event occurred, where the event occurred, the source of the event, the outcome of the event, and the identity of any individuals, subjects, or objects associated with the event. Audit record content that may be necessary to support the auditing function includes event descriptions, time stamps, source and destination addresses, user or process identifiers, success or failure indications, and filenames involved.

Description

Allocate audit log storage capacity to accommodate the anticipated volume of audit log data based on the types and frequency of auditable events, the storage requirements of individual audit records, and organizational retention requirements. Organizations consider the types of audit logging to be performed and the audit log processing requirements when allocating storage capacity. Allocating sufficient audit log storage reduces the likelihood of such capacity being exceeded and resulting in the potential loss or reduction of audit logging capability.

Description

Alert organization-defined personnel or roles within an organization-defined time period in the event of an audit logging process failure, and take organization-defined additional actions. Audit logging process failures include software and hardware errors, failures in audit log capturing mechanisms, and reaching or exceeding audit log storage capacity. Organizations may choose to define additional actions for audit logging process failures based on the type of failure, the location of the failure, or the severity of the failure.

Description

Review and analyze system audit records on an organization-defined frequency for indications of organization-defined inappropriate or unusual activity, and report findings to organization-defined personnel or roles. Audit record review, analysis, and reporting covers information security and privacy related logging performed by organizations including logging that results from monitoring of account usage, remote access, wireless connectivity, mobile device connection, configuration settings, system component inventory, and use of maintenance tools and non-local maintenance sessions.

Description

Provide and implement an audit record reduction and report generation capability that supports on-demand audit review, analysis, and reporting requirements and after-the-fact investigations of incidents. Audit record reduction is a process that manipulates collected audit log information and organizes it into a summary format that is more meaningful to analysts. Audit record reduction and report generation capabilities do not alter the original audit records. This control supports the process of reviewing and analyzing system audit data while preserving the integrity of original audit records.

Description

Use internal system clocks to generate time stamps for audit records and record time stamps for audit records that meet an organization-defined granularity of time measurement that can be mapped to Coordinated Universal Time or Greenwich Mean Time. Time stamps generated by the system include date and time, and are used to determine when events occurred. The granularity of time measurements refers to the degree of synchronization between system clocks and reference clocks.

Description

Protect audit information and audit logging tools from unauthorized access, modification, and deletion. Organizations may need to take actions to protect audit information, including audit logs and audit records, audit settings, and audit reports. This includes ensuring that audit information is not modified, deleted, or overwritten by unauthorized individuals or processes, and is maintained in a secure location with restricted access. Audit information may also be protected by encrypting audit records or using digital signatures to verify integrity.

Description

Provide irrefutable evidence that an individual or process performed a specific action to protect against false claims of not having performed the action. Non-repudiation services can be used to determine if information originated from a particular individual or if an individual took specific actions, such as sending an email, signing a contract, approving a procurement request, or receiving specific information. Types of non-repudiation services include digital signatures and digital message receipts.

Description

Retain audit records for an organization-defined time period consistent with records retention policies to provide support for after-the-fact investigations of incidents and to meet regulatory and organizational information retention requirements. Organizations retain audit records until it is determined that the records are no longer needed for administrative, legal, audit, or other operational purposes, including the investigation of or response to incidents and the correlation of audit record information with other information.

Description

Provide audit record generation capability for the event types the system is capable of auditing as defined in AU-2 on all information system and network components. Allow organization-defined personnel or roles to select the event types that are to be logged by specific components of the system. Generate audit records for the selected event types with the content defined in AU-3. The selection of event types for auditing is a dynamic process that can change over time based on evolving threat information and changing system configurations.

Description

Monitor organization-defined open-source information and information channels on an organization-defined frequency for evidence of unauthorized disclosure of organizational information. Open-source information includes social media sites, blogs, discussion forums, and websites. Monitoring these channels allows organizations to detect and respond to unauthorized disclosures of sensitive information in a timely manner, potentially limiting the damage caused by such disclosures.

Description

Provide and implement the capability for organization-defined users or roles to select a user session to capture and record, and to remotely view and hear all content related to an established user session in real time. Session auditing activities are developed, integrated, and used in consultation with legal counsel in accordance with applicable laws, executive orders, directives, regulations, policies, standards, and guidelines. Session audits can include monitoring keystrokes, tracking websites visited, and recording information or file transfers.

Description

Employ organization-defined methods for coordinating organization-defined audit information among external organizations when audit information is transmitted across organizational boundaries. When organizations use systems or services of external organizations, the auditing capability necessitates a coordinated, cross-organization approach. Organizations may employ methods such as memoranda of understanding to manage the coordination of audit information between organizations, including shared audit log formats, standardized time synchronization, and agreed-upon retention periods.

Controls for assessing security controls, authorizing system operations, and continuously monitoring information systems.

Description

Develop, document, and disseminate assessment, authorization, and monitoring policy and procedures that address purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance. Review and update the current assessment, authorization, and monitoring policy and procedures on an organization-defined frequency and following organization-defined events.

Description

Select the appropriate assessor or assessment team for the type of assessment to be conducted. Develop a control assessment plan that describes the scope of the assessment including controls and control enhancements under assessment, assessment procedures to be used, and the assessment environment. Assess the controls in the system and its environment of operation on an organization-defined frequency to determine the extent to which the controls are implemented correctly, operating as intended, and producing the desired outcome. Produce a control assessment report that documents the results of the assessment.

Description

Approve and manage the exchange of information between the system and other systems using interconnection security agreements, information exchange security agreements, memoranda of understanding or agreement, service level agreements, user agreements, nondisclosure agreements, or other forms of agreement. Document the interface characteristics, security and privacy requirements, controls, and responsibilities for each connection. Review and update the agreements on an organization-defined frequency.

Description

Develop a plan of action and milestones for the system to document the planned remedial actions of the organization to correct weaknesses or deficiencies noted during the assessment of the controls and to reduce or eliminate known vulnerabilities in the system. Update the existing plan of action and milestones on an organization-defined frequency based on the findings from control assessments, independent audits or reviews, and continuous monitoring activities.

Description

Assign a senior official as the authorizing official for the system. Ensure that the authorizing official authorizes the system for processing before commencing operations and updates the authorization on an organization-defined frequency. Authorization is the official management decision to authorize the operation of an information system and to explicitly accept the risk to organizational operations, organizational assets, individuals, other organizations, and the nation based on the implementation of an agreed-upon set of controls.

Description

Develop a system-level continuous monitoring strategy and implement a continuous monitoring program that includes establishing organization-defined metrics to be monitored, establishing organization-defined frequencies for monitoring and assessment of control effectiveness, ongoing control assessments in accordance with the continuous monitoring strategy, ongoing monitoring of system and organization-defined metrics, correlation and analysis of information generated by control assessments and monitoring, and response actions to address results of analysis.

Description

Conduct penetration testing on an organization-defined frequency on organization-defined systems or system components. Penetration testing is a specialized type of assessment conducted as part of security and privacy assessments that leverages adversary tools, techniques, and procedures to evaluate the effectiveness of implemented controls. Penetration testing can be used to validate vulnerabilities or determine the degree of penetration resistance of systems to sophisticated adversaries. Results from penetration testing are used to prioritize corrective actions.

Description

Authorize internal connections of organization-defined system components or classes of components to the system. Document for each internal connection the interface characteristics, security and privacy requirements, and the nature of the information communicated. Internal system connections include connections between separate physical or virtual systems within the authorization boundary, and connections between different operating systems, applications, or databases within the same physical or virtual system.

Controls for establishing and maintaining baseline configurations, tracking and controlling changes, restricting unnecessary functionality, and maintaining component inventories.

Description

Develop, document, and disseminate configuration management policy and procedures that address purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance. Review and update the current configuration management policy and procedures on an organization-defined frequency and following organization-defined events.

Description

Develop, document, and maintain under configuration control a current baseline configuration of the system. Baseline configurations are documented, formally reviewed, and agreed-upon specifications for systems or configuration items within those systems. Baseline configurations serve as a basis for future builds, releases, or changes to systems and include information about system components, network topology, and the logical placement of functions or components within the system architecture.

Description

Determine and document the types of changes to the system that are configuration-controlled. Review proposed configuration-controlled changes to the system and approve or disapprove such changes with explicit consideration for security and privacy impact analyses. Document configuration change decisions associated with the system. Implement approved configuration-controlled changes to the system. Retain records of configuration-controlled changes to the system and review changes on an organization-defined frequency.

Description

Analyze changes to the system to determine potential security and privacy impacts prior to change implementation. Security and privacy impact analyses may include assessments of risk to understand the impact of the changes and to determine if additional controls are required. Organizations conduct impact analyses on proposed changes to system configurations, software, hardware, firmware, and associated documentation to assess the potential effects on security and privacy.

Description

Define, document, approve, and enforce physical and logical access restrictions associated with changes to the system. Changes to the hardware, software, or firmware components of systems or the operational procedures related to the system can potentially have significant effects on the security of the systems. Therefore, organizations permit only qualified and authorized individuals to access systems for purposes of initiating changes. Access restrictions include physical and logical access control requirements, workflow automation, media libraries, abstract layers, and change windows.

Description

Establish and document mandatory configuration settings for information technology products employed within the system using organization-defined common secure configurations that reflect the most restrictive mode consistent with operational requirements. Implement the configuration settings. Identify, document, and approve any deviations from established configuration settings. Monitor and control changes to the configuration settings in accordance with organizational policies and procedures.

Description

Configure the system to provide only organization-defined mission-essential capabilities and prohibit or restrict the use of organization-defined functions, ports, protocols, software, and services. Systems provide a wide variety of functions and services. Some of the functions and services routinely provided by default may not be necessary to support essential organizational missions, functions, or operations. Additionally, it is sometimes convenient to provide multiple services from a single system component, but doing so increases risk.

Description

Develop and document an inventory of system components that accurately reflects the system, is consistent with the authorization boundary of the system, is at the level of granularity deemed necessary for tracking and reporting, and includes information deemed necessary to achieve effective system component accountability. Review and update the system component inventory on an organization-defined frequency. System components include hardware, software, firmware, documentation, and organizational policies.

Description

Develop, document, and implement a configuration management plan for the system that addresses roles, responsibilities, and configuration management processes and procedures. Establish a process for identifying configuration items throughout the system development life cycle and for managing the configuration of the configuration items. Define the configuration items for the system and place them under configuration management. The plan describes how to move changes through the change management process and how to update configuration settings and baselines.

Description

Use software and associated documentation in accordance with contract agreements and copyright laws. Track the use of software and associated documentation protected by quantity licenses to control copying and distribution. Control and document the use of peer-to-peer file sharing technology to ensure that this capability is not used for the unauthorized distribution, display, performance, or reproduction of copyrighted work. Organizations employ tracking systems for software licenses to ensure compliance.

Description

Establish organization-defined policies governing the installation of software by users. Enforce software installation policies through organization-defined methods. Monitor policy compliance on an organization-defined frequency. User-installed software can introduce vulnerabilities and may require additional security controls. Organizations enforce policies through technical controls, such as software whitelisting or application control solutions, and through administrative controls, such as periodic audits of installed software.

Description

Identify and document the location of organization-defined information and the specific system components on which the information is processed and stored. Information location addresses the need to understand where information is being processed and stored so that appropriate controls can be applied to protect the information. Organizations may define different types of information that require location tracking, including personally identifiable information, classified information, and controlled unclassified information.

Description

Develop and document a map of system data actions that identifies where in the system personally identifiable information is processed, stored, or transmitted. Data action mapping supports the identification of where personally identifiable information resides on a system. It helps organizations comply with privacy requirements, ensure appropriate privacy protections are in place, and support incident response activities by enabling rapid identification of affected data and data subjects when breaches or unauthorized disclosures occur.

Description

Prevent the installation of organization-defined software and firmware components without verification that the component has been digitally signed using a certificate that is recognized and approved by the organization. Digital signatures and the verification of those signatures is a method of code authentication. Organizations can employ digital signature verification to validate that certain software or firmware components have not been tampered with and that the components come from a verified, trusted source.

Controls for ensuring continued operations in the event of disruption, including contingency planning, testing, alternate processing sites, and system backup and recovery.

Description

Develop, document, and disseminate contingency planning policy and procedures that address purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance. Review and update the current contingency planning policy and procedures on an organization-defined frequency and following organization-defined events.

Description

Develop a contingency plan for the system that identifies essential mission and business functions and associated contingency requirements, provides recovery objectives and restoration priorities and metrics, addresses contingency roles and responsibilities and assigned individuals with contact information, addresses maintaining essential mission and business functions despite a system disruption, compromise, or failure, and is reviewed and updated on an organization-defined frequency. Distribute copies of the contingency plan to organization-defined key contingency personnel and organizational elements.

Description

Provide contingency training to system users consistent with assigned roles and responsibilities within an organization-defined time period of assuming a contingency role or responsibility. Provide contingency training on an organization-defined frequency thereafter. Review and update contingency training content on an organization-defined frequency and following organization-defined events. Contingency training includes training for initial and refresher activities, providing users with the knowledge and skills needed to execute contingency plans effectively.

Description

Test the contingency plan for the system on an organization-defined frequency using organization-defined tests to determine the effectiveness of the plan and the readiness of the organization to execute the plan. Review the contingency plan test results and initiate corrective actions if needed. Methods for testing contingency plans include tabletop exercises, simulations, parallel processing, full interrupt testing, and checklist testing. Organizations coordinate contingency plan testing with organizational elements responsible for related plans.

Description

Establish an alternate storage site, including necessary agreements, either commercial or governmental, to permit the storage and retrieval of system backup information. Ensure that the alternate storage site provides security controls equivalent to that of the primary site. Alternate storage sites are geographically distinct from primary storage sites and are resistant to the same hazards. Organizations may establish multiple alternate storage sites to account for different types of disruptions.

Description

Establish an alternate processing site, including necessary agreements to permit the transfer and resumption of organization-defined system operations for essential mission and business functions within an organization-defined time period consistent with recovery time and recovery point objectives when the primary processing capabilities are unavailable. Ensure that equipment and supplies required to transfer and resume operations are available at the alternate processing site or contracts are in place to support delivery to the site within the organization-defined time period for transfer and resumption.

Description

Establish alternate telecommunications services, including necessary agreements, to permit the resumption of organization-defined system operations for essential mission and business functions within an organization-defined time period when the primary telecommunications capabilities are unavailable at either the primary or alternate processing or storage sites. Organizations may specify different telecommunications services at different levels of capability, such as primary, alternate, and emergency services with corresponding priorities for restoration.

Description

Conduct backups of user-level information, system-level information, and system documentation including security and privacy-related documentation contained in the system on an organization-defined frequency consistent with recovery time and recovery point objectives. Protect the confidentiality, integrity, and availability of backup information. System backups include system state information, operating system software, middleware, application software, and licenses. Differential, incremental, and full backup strategies may be employed depending on organizational requirements.

Description

Provide for the recovery and reconstitution of the system to a known state within organization-defined time periods consistent with recovery time and recovery point objectives after a disruption, compromise, or failure. Recovery is the process of restoring system capabilities to operational status. Reconstitution takes place after recovery and includes activities for returning systems to fully operational status. Organizations determine the desired system state for recovery and reconstitution activities.

Description

Provide the capability to employ organization-defined alternative communications protocols in support of maintaining continuity of operations. Contingency plans and the contingency training or testing associated with those plans incorporate an appropriate set of alternative communications protocols as part of establishing resilience in organizational systems. Alternative communications protocols support a comprehensive approach to resilience, including the ability to switch between different protocols if primary protocols are unavailable or compromised.

Description

When organization-defined conditions are detected, enter a safe mode of operation with organization-defined restrictions of safe mode of operation. For systems that support safe mode of operation, the safe mode limits the types of activities or functions that can be performed when those conditions are encountered. Safe mode of operation provides a limited subset of the functionality available on the system in a degraded but operational state, enabling continued mission-critical activities while managing risk from identified conditions.

Description

Employ organization-defined alternative or supplemental security mechanisms for satisfying organization-defined security requirements when the primary means of implementing the security requirements are unavailable or compromised. Use of alternative security mechanisms supports system resilience, contingency planning, and continuity of operations. Organizations can deploy alternative or supplemental security mechanisms to address any of the security requirements in the security plan, including authentication, encryption, access control, and auditing.

Controls for uniquely identifying and authenticating users, devices, and services before granting access to system resources.

Description

Develop, document, and disseminate identification and authentication policy and procedures that address purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance. Review and update the current policy and procedures on a defined frequency and following defined events.

Description

Uniquely identify and authenticate organizational users and associate that unique identification with processes acting on behalf of those users. Implement multi-factor authentication for access to privileged and non-privileged accounts as required by organizational policy.

Description

Uniquely identify and authenticate devices before establishing a local, remote, or network connection using bidirectional authentication that is cryptographically based or uses other defined methods of device identification and authentication.

Description

Manage system identifiers by receiving authorization from organizational personnel to assign an individual, group, role, service, or device identifier. Select an identifier that identifies an individual, group, role, service, or device. Assign the identifier to the intended individual, group, role, service, or device. Prevent reuse of identifiers for a defined time period and disable the identifier after a defined period of inactivity.

Description

Manage system authenticators by verifying the identity of the individual, group, role, service, or device receiving the authenticator as part of the initial authenticator distribution. Establish initial authenticator content for any authenticators issued by the organization. Ensure that authenticators have sufficient strength of mechanism for their intended use. Establish and implement administrative procedures for initial authenticator distribution, for lost, compromised, or damaged authenticators, and for revoking authenticators. Change default authenticators prior to first use. Change or refresh authenticators on a defined frequency or when defined events occur.

Description

Obscure feedback of authentication information during the authentication process to protect the information from possible exploitation and use by unauthorized individuals.

Description

Implement mechanisms for authentication to a cryptographic module that meet the requirements of applicable federal laws, executive orders, directives, policies, regulations, standards, and guidelines for such authentication.

Description

Uniquely identify and authenticate non-organizational users or processes acting on behalf of non-organizational users. Implement multi-factor authentication and replay-resistant authentication mechanisms for network access to non-privileged and privileged accounts as required.

Description

Uniquely identify and authenticate defined services and service providers before establishing communications with requesting services or service providers.

Description

Require users to provide additional authentication factors when defined conditions or situations requiring re-authentication are met, such as changes in risk levels, access to sensitive resources, or when anomalous behavior is detected.

Description

Require users to re-authenticate when defined circumstances or situations require re-authentication, such as after a defined time period of inactivity, when changes in roles or privileges occur, or when security-relevant events are detected.

Description

Identity proof users that require accounts for logical access to systems by resolving a government-issued form of identification to a maintained records database, verifying the identity of the individual, and issuing credentials bound to the verified identity.

Controls for establishing operational incident handling capabilities including preparation, detection, analysis, containment, recovery, and user response activities.

Description

Develop, document, and disseminate incident response policy and procedures that address purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance. Review and update the current policy and procedures on a defined frequency and following defined events.

Description

Provide incident response training to system users consistent with assigned roles and responsibilities within a defined time period of assuming an incident response role or responsibility, and at a defined frequency thereafter. Review and update incident response training content on a defined frequency and following defined events. Incorporate lessons learned from ongoing incident handling activities into incident response training.

Description

Test the effectiveness of the incident response capability for the system at a defined frequency using defined tests to determine the incident response effectiveness and document the results.

Description

Implement an incident handling capability for incidents that is consistent with the incident response plan and includes preparation, detection and analysis, containment, eradication, and recovery. Coordinate incident handling activities with contingency planning activities and incorporate lessons learned from ongoing incident handling activities into incident response procedures, training, and testing.

Description

Track and document incidents on an ongoing basis to identify trends, recurring events, and systemic weaknesses in the organizational security posture.

Description

Require personnel to report suspected incidents to the organizational incident response capability within a defined time period. Report incident information to defined authorities. Correlate incident information and individual incident reports to achieve organization-wide situational awareness.

Description

Provide an incident response support resource, integral to the organizational incident response capability, that offers advice and assistance to users of the system for the handling and reporting of incidents.

Description

Develop an incident response plan that provides the organization with a roadmap for implementing its incident response capability. Describe the structure and organization of the incident response capability, provide a high-level approach for how the incident response capability fits into the overall organization, and meet the unique requirements of the organization including mission, size, structure, and functions.

Description

Respond to information spills by identifying the specific information involved in the system contamination, alerting defined personnel or roles using a method of communication not associated with the spill, isolating the contaminated system or system component, eradicating the information from the contaminated system or component, and identifying other systems that may have been subsequently contaminated.

Description

Establish an integrated team of forensic and malware analysts, tool developers, and real-time operations personnel to address suspected incidents and assist in the rapid detection, analysis, and recovery from incidents.

Controls for performing timely and effective system maintenance, controlling maintenance tools, and managing maintenance personnel.

Description

Develop, document, and disseminate maintenance policy and procedures that address purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance. Review and update the current policy and procedures on a defined frequency and following defined events.

Description

Schedule, document, and review records of maintenance, repair, and replacement on system components in accordance with manufacturer or vendor specifications and organizational requirements. Approve and monitor all maintenance activities whether performed on site or remotely and whether the system or component is serviced on site or removed to another location.

Description

Approve, control, and monitor the use of system maintenance tools. Review previously approved system maintenance tools on a defined frequency. Prevent the unauthorized removal of maintenance equipment containing organizational information by verifying that there is no organizational information contained on the equipment, sanitizing or destroying the equipment, retaining the equipment within the facility, or obtaining an exemption from authorized personnel.

Description

Approve and monitor nonlocal maintenance and diagnostic activities. Allow the use of nonlocal maintenance and diagnostic tools only as consistent with organizational policy and documented in the security plan for the system. Employ strong identification and authentication techniques in the establishment of nonlocal maintenance and diagnostic sessions. Maintain records for nonlocal maintenance and diagnostic activities. Terminate session and network connections when nonlocal maintenance is completed.

Description

Establish a process for maintenance personnel authorization and maintain a list of authorized maintenance organizations or personnel. Verify that non-escorted personnel performing maintenance on the system possess the required access authorizations. Designate organizational personnel with required access authorizations and technical competence to supervise the maintenance activities of personnel who do not possess the required access authorizations.

Description

Obtain maintenance support and spare parts for defined system components within a defined time period of failure to ensure continuity of operations and system availability.

Description

Restrict or prohibit field maintenance on defined systems or system components to defined trusted maintenance facilities to ensure proper controls and oversight of maintenance activities.

Controls for protecting system media, both physical and digital, including restricting access, marking, storage, transport, sanitization, and use.

Description

Develop, document, and disseminate media protection policy and procedures that address purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance. Review and update the current policy and procedures on a defined frequency and following defined events.

Description

Restrict access to defined types of digital and non-digital media to defined personnel or roles using defined controls to protect sensitive information from unauthorized access and disclosure.

Description

Mark system media indicating the distribution limitations, handling caveats, and applicable security markings of the information. Exempt defined types of media from marking if the media remain within defined controlled areas.

Description

Physically control and securely store defined types of digital and non-digital media within defined controlled areas using defined security controls to prevent unauthorized access, theft, or damage to the media.

Description

Protect and control defined types of system media during transport outside of controlled areas using defined controls. Maintain accountability for system media during transport and restrict the activities associated with the transport of media to authorized personnel.

Description

Sanitize system media prior to disposal, release out of organizational control, or release for reuse using defined sanitization techniques and procedures in accordance with applicable federal and organizational standards and policies.

Description

Restrict or prohibit the use of defined types of system media on defined systems or system components using defined controls to prevent unauthorized use and potential introduction of malicious code or unauthorized data exfiltration.

Description

Establish and apply a media downgrading process that includes employing downgrading mechanisms with defined strength and integrity, testing downgrading equipment and procedures on a defined frequency, and properly documenting all downgrading actions to maintain an audit trail.

Controls for protecting the physical environment and infrastructure of information systems, including facility access, monitoring, power, and environmental protections.

Description

Develop, document, and disseminate physical and environmental protection policy and procedures that address purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance. Review and update the current policy and procedures on a defined frequency and following defined events.

Description

Develop, approve, and maintain a list of individuals with authorized access to the facility where the system resides. Issue authorization credentials for facility access. Review the access list detailing authorized facility access by individuals on a defined frequency. Remove individuals from the facility access list when access is no longer required.

Description

Enforce physical access authorizations at defined entry and exit points to the facility where the system resides by verifying individual access authorizations before granting access to the facility, controlling ingress and egress with defined physical access control systems and guards, controlling access to areas within the facility designated as publicly accessible by implementing appropriate controls, and securing keys, combinations, and other physical access devices.

Description

Control physical access to defined system distribution and transmission lines within organizational facilities using defined security controls to prevent unauthorized access, tampering, or eavesdropping on communications.

Description

Control physical access to output from defined output devices to prevent unauthorized individuals from obtaining the output, including printers, scanners, copiers, and other devices that produce tangible output.

Description

Monitor physical access to the facility where the system resides to detect and respond to physical security incidents. Review physical access logs on a defined frequency and upon occurrence of defined events. Coordinate results of reviews and investigations with the organizational incident response capability.

Description

Maintain visitor access records to the facility where the system resides that include the name and organization of the person visiting, the signature of the visitor, the form of identification, the date of access, the time of entry and departure, the purpose of the visit, and the name and organization of the person visited. Review visitor access records on a defined frequency and retain records for a defined period.

Description

Protect power equipment and power cabling for the system from damage and destruction through physical security measures and environmental controls.

Description

Provide the capability of shutting off power to defined system components or the system in emergency situations. Place emergency shutoff switches or devices in defined locations by system or system component to facilitate access for authorized personnel and protect personnel from electromagnetic or electrical hazards.

Description

Provide an uninterruptible power supply to facilitate an orderly shutdown of the system in the event of a primary power source loss and to enable transition of the system to long-term alternate power.

Description

Employ and maintain automatic emergency lighting for the system that activates in the event of a power outage or disruption and that covers emergency exits and evacuation routes within the facility.

Description

Employ and maintain fire detection and suppression systems for the system that are supported by an independent energy source to ensure continuous protection in the event of primary power loss.

Description

Maintain temperature and humidity levels within the facility where the system resides at acceptable levels as defined by organizational requirements and equipment specifications. Monitor environmental conditions at a defined frequency to detect conditions that could adversely affect system operations.

Description

Protect the system from damage resulting from water leakage by providing master shutoff or isolation valves that are accessible, working properly, and known to key personnel.

Description

Authorize and control defined types of system components entering and exiting the facility. Maintain records of the system components entering and exiting the facility to support accountability and asset management.

Description

Establish and implement security and privacy controls at alternate work sites equivalent to those at the primary work site. Assess the effectiveness of controls at alternate work sites on a defined frequency and provide a means for employees to communicate with information security and privacy personnel in case of incidents or problems.

Description

Position system components within the facility to minimize potential damage from defined physical and environmental hazards and to minimize the opportunity for unauthorized access.

Description

Protect the system from information leakage due to electromagnetic signals emanations by implementing defined protective measures to contain and prevent the interception of unintended signals.

Description

Employ defined asset location technologies to track and monitor the location and movement of defined assets within defined controlled areas to support asset management and physical security operations.

Description

Employ defined protective measures against electromagnetic pulse damage for defined systems and system components to ensure continued operation and protection of critical infrastructure.

Description

Mark system hardware components indicating the impact level or classification of the information permitted to be processed, stored, or transmitted by the component to ensure proper handling and access control.

Description

Plan the location or site of the facility where the system resides considering physical and environmental hazards. For existing facilities, consider the physical and environmental hazards in the organizational risk management strategy.

Controls for developing, documenting, and maintaining security and privacy plans, rules of behavior, and security architecture information.

Description

Develop, document, and disseminate planning policy and procedures that address purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance. Review and update the current policy and procedures on a defined frequency and following defined events.

Description

Develop security and privacy plans for the system that describe the system architecture, operational environment, security and privacy requirements, and planned controls. Review and update the plans on a defined frequency and protect the plans from unauthorized disclosure and modification.

Description

Establish and provide to individuals requiring access to the system the rules that describe their responsibilities and expected behavior with regard to information and system usage. Receive a documented acknowledgment from such individuals indicating that they have read, understand, and agree to abide by the rules of behavior before authorizing access.

Description

Develop a security and privacy concept of operations for the system that describes how the organization intends to operate the system from the perspective of information security and privacy.

Description

Develop and maintain security and privacy architectures for the system that describe the requirements and approach to protecting the confidentiality, integrity, and availability of system information. Review and update the architectures on a defined frequency to reflect changes in the enterprise architecture.

Description

Centrally manage defined controls and related processes to enable consistent organization-wide implementation and oversight of security and privacy requirements.

Description

Select a control baseline for the system based on the security categorization of the system to establish a foundation for the security and privacy controls needed to protect the system and the information it processes.

Description

Tailor the selected control baseline by applying specified tailoring actions to adjust the controls to more closely align with the conditions specific to the system and its operating environment.

Controls at the organization level for managing the information security and privacy programs, including program plans, roles, risk management, and workforce management.

Description

Develop and disseminate an organization-wide information security program plan that provides an overview of the requirements for the security program and a description of the security program management controls and common controls. Review and update the plan on a defined frequency and following defined events.

Description

Appoint a senior information security officer with the mission and resources to coordinate, develop, implement, and maintain an organization-wide information security program.

Description

Include the resources needed to implement the information security and privacy programs in capital planning and investment requests. Establish a discrete line item for information security and privacy in organizational programming and budgeting documentation.

Description

Implement a process to ensure that plans of action and milestones for the information security, privacy, and supply chain risk management programs and associated organizational systems are developed and maintained, and document the remedial information security, privacy, and supply chain risk management actions to adequately respond to risk.

Description

Develop and maintain an inventory of organizational systems that identifies each system, the interfaces between systems, and which systems support organizational missions and business processes.

Description

Develop, monitor, and report on the results of information security and privacy measures of performance to assess the effectiveness of security and privacy programs and controls.

Description

Develop and maintain an enterprise architecture with consideration for information security, privacy, and the resulting risk to organizational operations and assets, individuals, other organizations, and the Nation.

Description

Address information security and privacy issues in the development, documentation, and updating of a critical infrastructure and key resources protection plan.

Description

Develop, document, and communicate a comprehensive organization-wide risk management strategy that consistently addresses security and privacy risk, includes a determination of risk tolerance, and is reviewed and updated on a defined frequency.

Description

Manage the security and privacy state of organizational systems and the environments in which those systems operate through authorization processes. Designate individuals to fulfill specific roles and responsibilities within the organizational risk management process.

Description

Define organizational mission and business processes with consideration for information security and privacy, and the resulting risk to organizational operations, organizational assets, individuals, other organizations, and the Nation. Determine information protection and personally identifiable information processing needs arising from the defined mission and business processes.

Description

Implement an insider threat program that includes a cross-discipline insider threat incident handling team to detect, deter, and mitigate insider threats to organizational operations, assets, and individuals.

Description

Establish a security and privacy workforce development and improvement program to ensure adequate staffing and skills for roles requiring security and privacy expertise.

Description

Implement a process for ensuring that organizational plans for conducting security and privacy testing, training, and monitoring activities associated with organizational systems are developed and maintained on a defined frequency.

Description

Establish and institutionalize contact with selected groups and associations within the security and privacy communities to stay current with security and privacy practices, share lessons learned, and facilitate knowledge exchange.

Description

Implement a threat awareness program that includes a cross-organization information-sharing capability for threat and vulnerability intelligence.

Description

Establish policy and procedures to ensure compliance with requirements for the protection of controlled unclassified information that is processed, stored, or transmitted on external systems.

Description

Maintain a central resource webpage accessible to the public to ensure that the public has access to information about organizational privacy activities and can communicate with the organization on privacy-related issues.

Description

Develop and maintain an accurate accounting of disclosures of personally identifiable information and make the accounting available to the individual to whom the PII relates upon request.

Description

Develop and document organization-wide policies and procedures for ensuring that personally identifiable information quality is commensurate with the impact of decisions based on that information.

Description

Establish a data governance body consisting of appropriate stakeholders to provide organization-wide governance for the management and protection of personally identifiable information.

Description

Establish a data integrity board to review proposals to conduct or participate in computer-matching programs and to maintain ongoing oversight of such programs.

Description

Develop policies and procedures that address the use of personally identifiable information for internal testing, training, and research, and implement controls to minimize the use of PII for such purposes.

Description

Implement a process for receiving and responding to complaints, concerns, or questions from individuals about organizational privacy practices, and communicate the process to the public.

Description

Develop and disseminate privacy reports to oversight bodies, organizational officials, and other personnel responsible for monitoring privacy program compliance.

Description

Establish the context for risk-based decisions by identifying assumptions, constraints, risk tolerance, and priorities for managing security and privacy risk to organizational operations and assets.

Description

Develop and implement an organization-wide strategy for managing supply chain risks associated with the development, acquisition, maintenance, and disposal of systems, system components, and system services.

Description

Develop and implement an organization-wide continuous monitoring strategy and program that covers the monitoring of security and privacy controls, assessing control effectiveness, and collecting, correlating, and analyzing security and privacy-related information.

Description

Analyze systems, system components, or system services to identify their intended purpose and design them to fulfill only their stated purpose, reducing the attack surface and limiting unintended functionality.

Controls for screening individuals prior to access, managing personnel transfers and terminations, and establishing access agreements.

Description

Develop, document, and disseminate personnel security policy and procedures that address purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance. Review and update the current policy and procedures on a defined frequency and following defined events.

Description

Assign a risk designation to all organizational positions. Establish screening criteria for individuals filling those positions. Review and update position risk designations on a defined frequency.

Description

Screen individuals prior to authorizing access to the system. Rescreen individuals in accordance with defined conditions requiring rescreening and on a defined frequency of such rescreening.

Description

Upon termination of individual employment, disable information system access within a defined time period, terminate or revoke any authenticators and credentials associated with the individual, conduct exit interviews that include a discussion of information security topics, retrieve all security-related organizational information system-related property, and retain access to organizational information and systems formerly controlled by the terminated individual.

Description

Review and confirm ongoing operational need for current logical and physical access authorizations to systems and facilities when individuals are reassigned or transferred to other positions within the organization. Initiate defined transfer or reassignment actions within a defined time period following the formal transfer action.

Description

Develop and document access agreements for organizational systems. Review and update the access agreements on a defined frequency. Verify that individuals requiring access to organizational information and systems sign appropriate access agreements prior to being granted access and re-sign access agreements to maintain access when access agreements have been updated or on a defined frequency.

Description

Establish personnel security requirements including security roles and responsibilities for external providers. Require external providers to comply with personnel security policies and procedures established by the organization. Document personnel security requirements. Monitor provider compliance with personnel security requirements.

Description

Employ a formal sanctions process for individuals failing to comply with established information security and privacy policies and procedures. Notify defined personnel or roles within a defined time period when a formal employee sanctions process is initiated.

Description

Incorporate security and privacy roles and responsibilities into organizational position descriptions to ensure that security and privacy requirements are clearly defined and understood for all personnel.

Controls for managing the processing of personally identifiable information, ensuring transparency, obtaining consent, and providing privacy notices.

Description

Develop, document, and disseminate personally identifiable information processing and transparency policy and procedures that address purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance. Review and update the current policy and procedures on a defined frequency and following defined events.

Description

Determine and document the legal authority that permits the collection, use, maintenance, and sharing of personally identifiable information, either generally or in support of a specific program or system need.

Description

Identify and document the specific purpose for processing personally identifiable information. Describe the purpose in the public privacy notices and other applicable documents. Restrict PII processing to only those purposes that are compatible with the identified and documented purposes.

Description

Implement defined mechanisms for individuals to consent to the processing of their personally identifiable information prior to its collection that facilitate individual understanding of the consequences of providing consent and provide a means for individuals to revoke consent.

Description

Provide effective notice to individuals about the processing of personally identifiable information that includes the authority for the collection, the purposes of processing, the types of PII collected, intended use and sharing, retention, and the consequences of not providing PII.

Description

Publish system of records notices in the Federal Register, subject to required oversight processes, for systems containing personally identifiable information that identify the system of records and the purposes for which PII is collected, maintained, used, and shared.

Description

Apply defined processing conditions for specific categories of personally identifiable information that may include social security numbers, biometric data, financial information, and other sensitive categories that warrant additional protection beyond standard PII handling requirements.

Description

When a system or organization processes information for the purpose of conducting a matching program, verify that the requirements of the Computer Matching and Privacy Protection Act are met, including establishing matching agreements, notifying individuals, and conducting cost-benefit analyses.

Controls for assessing risks to organizational operations, assets, and individuals from the operation and use of information systems.

Description

Develop, document, and disseminate risk assessment policy and procedures that address purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance. Review and update the current risk assessment policy and procedures on a defined frequency and following defined events.

Description

Categorize the system and information processed, stored, and transmitted, document results in the security plan, and ensure categorization is consistent with FIPS 199. Review and update the security categorization on a defined frequency and when significant changes occur.

Description

Conduct a risk assessment to identify threats, vulnerabilities, impact, likelihood, and risk to organizational operations and assets. Document results in the risk assessment report and update on a defined frequency or when significant changes occur to the system or environment of operation.

Description

Monitor and scan for vulnerabilities in the system on a defined frequency, employ vulnerability monitoring tools, analyze vulnerability scan reports, remediate legitimate vulnerabilities within a defined time period, and share vulnerability information with designated personnel.

Description

Employ a technical surveillance countermeasures survey at defined locations at a defined frequency or when certain events or indicators occur to detect the presence of eavesdropping devices and technical surveillance hazards.

Description

Respond to findings from security and privacy assessments, monitoring, and audits in accordance with organizational risk tolerance. Determine the appropriate risk response strategy including acceptance, avoidance, mitigation, sharing, or transfer.

Description

Conduct privacy impact assessments for systems processing personally identifiable information to determine the impact of the collection, use, maintenance, and sharing of PII on individuals and ensure appropriate safeguards are in place.

Description

Identify critical system components and functions by performing a criticality analysis at defined decision points in the system development life cycle. Use the results to inform risk-based decisions regarding security and privacy requirements.

Description

Establish and maintain a cyber threat hunting capability to detect, track, and disrupt threats that evade existing security controls. Employ threat intelligence and advanced analytics to proactively search for indicators of compromise across organizational systems.

Controls for managing the system development life cycle, acquisition processes, developer security testing, and supply chain considerations.

Description

Develop, document, and disseminate system and services acquisition policy and procedures that address purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance. Review and update the current policy and procedures on a defined frequency and following defined events.

Description

Determine, document, and allocate the resources required to protect the system as part of the organizational capital planning and investment control process. Establish a discrete line item for information security and privacy in organizational programming and budgeting documentation.

Description

Acquire, develop, and manage the system using a system development life cycle methodology that incorporates information security and privacy considerations. Define and document information security and privacy roles and responsibilities throughout the system development life cycle.

Description

Include security and privacy functional requirements, design and development requirements, and testing requirements in the acquisition contract for the system or component. Require the developer to provide design and implementation information for the controls employed.

Description

Obtain or develop administrator and user documentation for the system that describes secure configuration, installation, operation, and effective use of security and privacy features. Document attempts to obtain documentation when it is unavailable or nonexistent and take defined actions in response.

Description

Apply systems security and privacy engineering principles in the specification, design, development, implementation, and modification of the system and system components. Ensure that engineering principles are applied consistently across all phases of the system development life cycle.

Description

Require providers of external system services to comply with organizational security and privacy requirements and employ defined controls. Document government oversight, user roles and responsibilities, and monitoring processes for external system services.

Description

Require the developer of the system to perform configuration management during design, development, implementation, and operation. Track and control changes to the system, manage flaws, and document the implementation of the configuration management process.

Description

Require the developer of the system to create and implement a security and privacy assessment plan, perform testing and evaluation at defined depth and coverage, and produce evidence of execution of the plan and results of the testing and evaluation.

Description

Require the developer to follow a documented development process, use defined tools and methods, document their use, and review the development process periodically to ensure alignment with organizational security and privacy requirements.

Description

Require the developer to provide training on the correct use and operation of implemented security and privacy functions, controls, and mechanisms to authorized personnel with defined roles and responsibilities.

Description

Require the developer to produce a design specification and security and privacy architecture that is consistent with the organizational security and privacy architecture established as part of the enterprise architecture.

Description

Re-implement or custom develop defined critical system components to minimize potential vulnerabilities that could be exploited through supply chain compromise or insertion of counterfeit components.

Description

Require that the developer of defined system components be screened according to defined criteria to ensure trustworthiness and reduce the risk of malicious or compromised development activities.

Description

Replace system components when support is no longer available from the developer or vendor. Provide documented justification and approval for the continued use of unsupported system components required to satisfy mission or business needs.

Description

Employ defined specialization techniques in the design and development of defined system components to minimize potential vulnerabilities and reduce the attack surface of the system.

Controls for protecting information during transmission and at rest, establishing boundary defenses, implementing cryptographic protections, and ensuring system isolation.

Description

Develop, document, and disseminate system and communications protection policy and procedures that address purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance. Review and update the current policy and procedures on a defined frequency and following defined events.

Description

Separate user functionality including user interface services from system management functionality to reduce the attack surface and prevent unauthorized access to administrative functions.

Description

Isolate security functions from nonsecurity functions to minimize the attack surface and prevent unauthorized interference with security mechanisms.

Description

Prevent unauthorized and unintended information transfer via shared system resources by controlling access to shared memory, storage, and other resources that could be exploited for covert data exchange.

Description

Protect against or limit the effects of denial-of-service attacks by employing defined controls including monitoring, capacity planning, and redundancy measures.

Description

Protect the availability of resources by allocating defined resources by priority, quota, or other means to ensure critical system functions continue to operate under adverse conditions.

Description

Monitor and control communications at the external managed interfaces and at key internal boundaries, implement subnetworks for publicly accessible components, and connect to external networks only through managed interfaces consisting of boundary protection devices.

Description

Protect the confidentiality and integrity of transmitted information using defined mechanisms such as encryption, digital signatures, and secure communication protocols.

Description

Terminate the network connection associated with a communications session at the end of the session or after a defined time period of inactivity to reduce the window of opportunity for unauthorized access.

Description

Provide a trusted communications path between the user and defined security functions of the system that cannot be intercepted or compromised by untrusted processes.

Description

Establish and manage cryptographic keys using defined key management methods and requirements including generation, distribution, storage, access, rotation, revocation, and destruction of keys.

Description

Determine the cryptographic uses required and implement defined types of cryptography for each specified use in accordance with applicable laws, executive orders, directives, regulations, policies, standards, and guidelines.

Description

Prohibit remote activation of collaborative computing devices and applications and provide an explicit indication of use to users physically present at the device to prevent unauthorized surveillance.

Description

Associate defined security and privacy attributes with information exchanged between systems and between system components to enforce access control and data protection policies across organizational boundaries.

Description

Issue public key certificates under an organization-defined certificate policy or obtain public key certificates from an approved service provider. Manage the certificate lifecycle including issuance, renewal, revocation, and validation.

Description

Define acceptable and unacceptable mobile code and mobile code technologies, establish usage restrictions and implementation guidance, and authorize and monitor the use of mobile code within the system.

Description

Provide additional data origin and data integrity artifacts along with authoritative name resolution data to enable receiving systems to verify the authenticity and integrity of resolution responses.

Description

Request and perform data origin authentication and data integrity verification on the name/address resolution responses the system receives from authoritative sources to protect against DNS spoofing and cache poisoning attacks.

Description

Ensure the systems that collectively provide name/address resolution service are fault-tolerant and implement internal/external role separation to support resilient and secure DNS operations.

Description

Protect the authenticity of communications sessions to prevent man-in-the-middle and session hijacking attacks using mechanisms such as session tokens, mutual authentication, and encrypted channels.

Description

Fail to a defined known system state in defined failure scenarios, preserving defined system state information in failure to support forensic analysis and recovery operations.

Description

Employ minimal functionality and information storage on defined system components to reduce the attack surface and limit the potential impact of a compromise.

Description

Employ defined decoys such as honeypots, honeynets, and deception technologies to detect and deflect potential cyber attacks against the system and gather threat intelligence.

Description

Include within organizational systems defined platform-independent applications to enhance portability, reduce vendor dependence, and support interoperability across diverse computing environments.

Description

Protect the confidentiality and integrity of defined information at rest using defined mechanisms such as encryption, access controls, and physical safeguards for storage media.

Description

Employ a diverse set of information technologies for defined system components in the implementation of the system to reduce vulnerability to common-mode threats that exploit a single technology.

Description

Employ defined concealment and misdirection techniques to confuse and mislead adversaries, making it more difficult for them to identify and target critical system components and data.

Description

Perform a covert channel analysis to identify those aspects of system communications that are potential avenues for covert storage and timing channels, and implement measures to limit their bandwidth and detectability.

Description

Partition the system into defined system components residing in separate physical or logical domains or environments based on defined circumstances to limit the impact of security incidents and contain adversary lateral movement.

Description

Require that defined system components load and execute the operating environment from hardware-enforced, read-only media to prevent unauthorized modification of executable programs.

Description

Include system components that proactively seek to identify malicious websites, malicious code, and network-based attacks against organizational systems using threat intelligence and automated scanning.

Description

Distribute defined processing and storage across multiple physical locations to reduce the impact of a single point of failure and improve resilience against targeted attacks.

Description

Employ defined out-of-band channels for the physical delivery or electronic transmission of defined information, system components, or devices to reduce the risk of interception or compromise through primary communication channels.

Description

Employ defined operations security controls to protect key organizational information throughout the system development life cycle and prevent adversaries from exploiting sensitive operational details.

Description

Maintain a separate execution domain for each executing system process to prevent unauthorized access and interference between processes and protect against privilege escalation attacks.

Description

Protect external and internal wireless links from defined types of signal parameter attacks using defined methods such as encryption, frequency hopping, and spread spectrum technologies.

Description

Physically or logically disable or remove defined external ports or input/output devices on defined systems or system components to prevent unauthorized data transfer and reduce the attack surface.

Description

Prohibit the use of devices possessing defined environmental sensing capabilities in defined facilities, areas, or systems, or restrict their use under specified conditions to prevent unauthorized surveillance and data collection.

Description

Establish usage restrictions and implementation guidelines for defined system components based on the potential to cause damage to the system if used maliciously, and enforce compliance through technical and procedural controls.

Description

Employ a detonation chamber capability within defined systems to automatically identify malicious code by executing code in a controlled environment and analyzing its behavior before allowing execution in production.

Description

Synchronize system clocks within and between systems and system components using defined time sources and mechanisms to support accurate audit logging, event correlation, and forensic analysis.

Description

Implement a policy enforcement mechanism between defined security domains for the transfer of data between domains, ensuring that data flows comply with organizational security policies and classification requirements.

Description

Establish defined alternate communications paths for system operations organizational command and control to support resilience and ensure continuity of operations during disruptions to primary communication channels.

Description

Relocate defined sensors and monitoring capabilities to a defined frequency to reduce adversary targeting and make it more difficult for adversaries to identify and evade detection mechanisms.

Description

Implement hardware-based mechanisms to provide process separation and policy enforcement that cannot be bypassed by software-only attacks, ensuring strong isolation between security domains.

Description

Implement software-based mechanisms to provide process separation and policy enforcement using virtualization, containerization, and other software isolation techniques to maintain security boundaries.

Description

Implement hardware-based mechanisms to protect the system from firmware corruption and support tamper resistance and detection, ensuring the integrity of low-level system components that underpin all higher-level security functions.

Controls for identifying, reporting, and correcting system flaws, protecting against malicious code, monitoring system events, and maintaining software and information integrity.

Description

Develop, document, and disseminate system and information integrity policy and procedures that address purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance. Review and update the current policy and procedures on a defined frequency and following defined events.

Description

Identify, report, and correct system flaws, test updates and patches before installing, and install security-relevant software and firmware updates within a defined time period of release to maintain system integrity.

Description

Implement signature and non-signature-based malicious code protection mechanisms at system entry and exit points, update mechanisms as new releases become available, and address false positives to maintain system availability.

Description

Monitor the system to detect attacks and indicators of potential attacks, identify unauthorized use, and deploy monitoring devices strategically within the system to collect essential information and at ad hoc locations to track specific types of transactions.

Description

Receive system security alerts, advisories, and directives from defined external organizations on an ongoing basis, generate internal alerts and advisories, and disseminate to defined personnel or roles to maintain security awareness.

Description

Verify the correct operation of defined security and privacy functions, perform verification at defined states, notify defined personnel of failed tests, and take defined actions when anomalies are discovered to ensure continuous protection.

Description

Employ integrity verification tools to detect unauthorized changes to defined software, firmware, and information, and take appropriate actions when discrepancies are identified to restore system integrity.

Description

Employ spam protection mechanisms at system entry and exit points to detect and act on unsolicited messages transported by electronic mail, web browsers, or other common means.

Description

Check the validity of defined information inputs to the system to verify that inputs match specified formats and content, preventing injection attacks and malformed data from compromising system integrity.

Description

Generate error messages that provide information necessary for corrective actions without revealing information that could be exploited by adversaries, such as stack traces, system paths, or internal configuration details.

Description

Manage and retain information within the system and information output from the system in accordance with applicable laws, executive orders, directives, regulations, policies, standards, guidelines, and operational requirements.

Description

Determine mean time to failure for defined system components in specific environments and provide substitute components and transfer responsibilities to ensure system continuity when failure thresholds are reached.

Description

Implement non-persistent defined system components and services that are initiated in a known state and terminated on a defined frequency or at the end of a user session to limit the persistence of adversary footholds.

Description

Validate information output from defined software programs to ensure that the information is consistent with expected content and format, preventing data leakage and corruption of downstream processes.

Description

Implement defined controls such as data execution prevention, address space layout randomization, and stack protection to protect the system memory from unauthorized code execution and buffer overflow attacks.

Description

Implement defined fail-safe procedures when defined failure conditions occur to ensure the system fails in a safe and secure state that does not compromise security or expose sensitive information.

Description

Check the accuracy, relevance, timeliness, and completeness of personally identifiable information across the information life cycle and take defined actions to correct or minimize the use of inaccurate or outdated PII.

Description

Remove personally identifiable information elements from datasets prior to release by applying defined de-identification techniques and methods to prevent the re-identification of individuals from released data.

Description

Embed data or capabilities in defined systems or system components as a means for identifying malicious use, exfiltration, or unauthorized access through digital watermarks, canary tokens, or other tainting mechanisms.

Description

Refresh defined information at defined frequencies or generate the information on demand to ensure freshness and reduce the risk of decisions based on stale or corrupted data.

Description

Employ defined alternative information sources for defined essential information to reduce the risk of information corruption or single-source dependencies that could compromise decision-making.

Description

Based on defined circumstances, fragment information in a manner that only authorized parties can reconstruct the information, providing an additional layer of protection against unauthorized access and data breaches.

Controls for managing supply chain risks throughout the system development life cycle, including acquisition strategies, supplier assessments, and component authenticity.

Description

Develop, document, and disseminate supply chain risk management policy and procedures that address purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance. Review and update the current policy and procedures on a defined frequency and following defined events.

Description

Develop a plan for managing supply chain risks associated with the development, acquisition, maintenance, and disposal of systems, components, and services. Review and update the plan on a defined frequency.

Description

Establish and apply a process for identifying and addressing weaknesses or deficiencies in the supply chain elements and processes used in the development, acquisition, and maintenance of the system.

Description

Document, monitor, and maintain valid provenance of defined systems, system components, and associated data to prevent counterfeiting and unauthorized modification throughout the supply chain.

Description

Employ defined acquisition strategies, contract tools, and procurement methods to protect against, identify, and mitigate supply chain risks associated with the acquisition of systems, components, and services.

Description

Assess and review the supply chain practices and components of suppliers and developers associated with the system on a defined frequency to identify and mitigate supply chain risks before they impact the organization.

Description

Employ defined operations security controls to protect supply chain information and reduce the vulnerability of the supply chain to adversary exploitation and intelligence gathering.

Description

Establish agreements and procedures with entities involved in the supply chain for notification of supply chain compromises and results of assessments or audits to enable timely response to supply chain incidents.

Description

Implement a tamper protection program for the system, system components, and associated development or manufacturing environments to detect and prevent unauthorized physical and logical modifications.

Description

Inspect defined systems or system components on a defined frequency to detect tampering, unauthorized modifications, or counterfeit components that may have been introduced through the supply chain.

Description

Develop and implement anti-counterfeit policies and procedures that include provisions for the detection and prevention of counterfeit components through verification of authenticity and provenance.

Description

Dispose of defined data, documentation, tools, and system components using defined techniques and methods to prevent unauthorized recovery and ensure that sensitive information cannot be reconstructed from discarded materials.

No controls match your search. Try a different keyword or clear the filter.

Need Help Implementing These Controls?

TeamThru provides hands-on support for NIST 800-53 control implementation, documentation, continuous monitoring, and ATO acceleration across federal and enterprise environments.