Security Controls Quick Reference
A comprehensive, searchable reference of all NIST SP 800-53 Revision 5 security and privacy controls. Browse by control family, search for specific controls, and link directly to official NIST documentation.
AC Access Control 23 controls
Controls for managing who can access what within an information system, including account management, access enforcement, separation of duties, least privilege, remote access, and wireless access.
Policy and Procedures
Develop, document, and disseminate access control policy and procedures.
Description
Develop, document, and disseminate access control policy and procedures consistent with applicable laws, executive orders, directives, regulations, policies, standards, and guidelines. These policies address purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance. Procedures facilitate the implementation of the access control policy and associated controls. Policies and procedures are reviewed and updated on an organization-defined frequency and following organization-defined events.
Account Management
Define and manage system account types, establish conditions for group and role membership, and manage the complete account lifecycle.
Description
Define and manage system account types, establish conditions for group and role membership, specify authorized users of the system, and manage the complete account lifecycle including creation, activation, modification, review, disabling, and removal. Require approvals for requests to create accounts, review accounts on an organization-defined frequency, and establish and implement a process for changing shared or group account authenticators when members leave the group.
Access Enforcement
Enforce approved authorizations for logical access to information and system resources.
Description
Enforce approved authorizations for logical access to information and system resources in accordance with applicable access control policies. Access control policies control access between active entities or subjects and passive entities or objects in organizational systems. Access enforcement mechanisms can be employed at the application and service level to provide increased information security and privacy.
Information Flow Enforcement
Enforce approved authorizations for controlling the flow of information within the system and between connected systems.
Description
Enforce approved authorizations for controlling the flow of information within the system and between connected systems based on organization-defined information flow control policies. Information flow control regulates where information can travel within a system and between systems as opposed to who can access the information. Flow control restrictions include blocking external traffic that claims to be from within the organization, keeping export-controlled information from being transmitted in the clear to the internet, and restricting web requests that are not from the internal web proxy server.
Separation of Duties
Identify and document duties of individuals requiring separation and define system access authorizations to support separation of duties.
Description
Identify and document duties of individuals requiring separation, and define system access authorizations to support separation of duties. Separation of duties addresses the potential for abuse of authorized privileges and helps to reduce the risk of malevolent activity without collusion. Separation of duties includes dividing mission or business functions and support functions among different individuals or roles, conducting system support functions with different individuals, and ensuring that security personnel administering access control functions do not also administer audit functions.
Least Privilege
Employ the principle of least privilege, allowing only authorized accesses for users and processes necessary to accomplish assigned tasks.
Description
Employ the principle of least privilege, allowing only authorized accesses for users and processes which are necessary to accomplish assigned organizational tasks. Organizations employ least privilege for specific duties and systems, including for specific system processes, restricting privileges to only those that are necessary. The principle of least privilege is also applied to system processes, ensuring that the processes have only the minimum level of access needed to perform their functions.
Unsuccessful Logon Attempts
Enforce a limit of consecutive invalid logon attempts and automatically lock or delay subsequent logon attempts.
Description
Enforce a limit of consecutive invalid logon attempts by a user during an organization-defined time period and automatically lock the account or node for an organization-defined time period, lock the account or node until released by an administrator, delay the next logon prompt for an organization-defined delay period, notify the system administrator, or take other organization-defined action when the maximum number of unsuccessful attempts is exceeded.
System Use Notification
Display an approved system use notification message before granting access providing privacy and security notices.
Description
Display an approved system use notification message or banner to users before granting access to the system that provides privacy and security notices consistent with applicable laws, executive orders, directives, regulations, policies, standards, and guidelines. The system use notification message states that users are accessing a government or organizational information system, system usage may be monitored, recorded, and subject to audit, unauthorized use of the system is prohibited and subject to criminal and civil penalties, and use of the system indicates consent to monitoring and recording.
Previous Logon Notification
Notify the user upon successful logon of the date and time of the last logon and unsuccessful attempts since then.
Description
Notify the user, upon successful logon to the system, of the date and time of the last logon, the number of unsuccessful logon attempts since the last successful logon, and any changes to account information or the security posture of the system during the defined time period. This control provides users with information about recent account activity so they can determine if any unauthorized activity has occurred.
Concurrent Session Control
Limit the number of concurrent sessions for each system account to an organization-defined number.
Description
Limit the number of concurrent sessions for each system account to an organization-defined number of sessions. Organizations may define the maximum number of concurrent sessions for system accounts globally, by account type, by account, or by a combination thereof. This control addresses concurrent sessions for system accounts and does not address concurrent sessions by single users via multiple system accounts.
Device Lock
Prevent further access to the system by initiating a device lock after an organization-defined time period of inactivity.
Description
Prevent further access to the system by initiating a device lock after an organization-defined time period of inactivity. Device locks are temporary actions taken to prevent logical access to the system when the user stops work and moves away from the immediate physical vicinity of the system but does not want to log out. Device locks can be implemented at the operating system level or at the application level, and may conceal previously visible information with a publicly viewable image.
Session Termination
Automatically terminate a user session after organization-defined conditions or trigger events.
Description
Automatically terminate a user session after organization-defined conditions or trigger events requiring session disconnect. Session termination addresses the termination of user-initiated logical sessions in contrast to the termination of network connections associated with communications sessions. Conditions or trigger events requiring automatic session termination include organization-defined periods of user inactivity, targeted responses to certain types of incidents, and time-of-day restrictions on system use.
Permitted Actions Without Identification or Authentication
Identify user actions that can be performed on the system without identification or authentication.
Description
Identify user actions that can be performed on the system without identification or authentication consistent with organizational mission and business functions. Organizations may allow a limited number of user actions without identification or authentication, including accessing public websites or other publicly accessible federal systems, viewing information in public areas, and accessing certain organizational systems to obtain information that is not sensitive or classified.
Security and Privacy Attributes
Provide the means to associate security and privacy attributes with information in storage, in process, and in transmission.
Description
Provide the means to associate organization-defined types of security and privacy attributes with organization-defined security and privacy attribute values for information in storage, in process, and in transmission. Information is represented internally within systems using abstractions known as data structures. Security and privacy attributes are associated with these internal data structures so that the attributes are available when the information is processed. Security and privacy attributes can also be associated with the information being exchanged between systems.
Remote Access
Establish and document usage restrictions, configuration requirements, and connection requirements for each type of remote access allowed.
Description
Establish and document usage restrictions, configuration and connection requirements, and implementation guidance for each type of remote access allowed. Authorize each type of remote access to the system prior to allowing such connections. Remote access is access to organizational systems or processes that communicate through external networks such as the internet. Types of remote access include dial-up, broadband, and wireless. Organizations limit remote access to reduce exposure to vulnerabilities from external networks.
Wireless Access
Establish configuration and connection requirements and implementation guidance for each type of wireless access.
Description
Establish configuration and connection requirements and implementation guidance for each type of wireless access. Authorize each type of wireless access to the system prior to allowing such connections. Wireless technologies include microwave, packet radio, satellite, and spread spectrum. Wireless networks use authentication protocols that provide credential protection and mutual authentication. Organizations protect wireless access using authentication, encryption, and monitoring of wireless activities.
Access Control for Mobile Devices
Establish configuration and connection requirements for organization-controlled mobile devices.
Description
Establish configuration and connection requirements and implementation guidance for organization-controlled mobile devices, and authorize the connection of mobile devices to organizational systems. A mobile device is a computing device that has a small form factor such that it can easily be carried by a single individual, is designed to operate without a physical connection, possesses local and non-removable or removable data storage, and includes a self-contained power source. Usage restrictions and specific implementation guidance for mobile devices include configuration management, device identification and authentication, implementation of mandatory protective software, and scanning devices for malicious code.
Use of External Systems
Establish terms and conditions for authorized use of external systems to access or process organizational information.
Description
Establish terms and conditions, consistent with any trust relationships established with other organizations owning, operating, or maintaining external systems, allowing authorized individuals to access the system from external systems and to process, store, or transmit organization-controlled information using external systems. External systems are systems that are used by but are not part of organizational systems and for which the organization has no direct control over the implementation of required security and privacy controls.
Information Sharing
Enable authorized users to determine whether access authorizations assigned to a sharing partner match the information access restrictions.
Description
Enable authorized users to determine whether access authorizations assigned to a sharing partner match the access restrictions on the information for organization-defined information sharing circumstances where user discretion is required. Employ organization-defined automated mechanisms or manual processes to assist users in making information sharing and collaboration decisions. Access authorization information includes access rules, permissions, and attributes.
Publicly Accessible Content
Designate authorized individuals to post information onto publicly accessible systems and review content for nonpublic information.
Description
Designate individuals authorized to post information onto a publicly accessible system. Train authorized individuals to ensure that publicly accessible information does not contain nonpublic information. Review the proposed content of information prior to posting onto the publicly accessible system to ensure that nonpublic information is not included. Review the content on the publicly accessible system for nonpublic information on an organization-defined frequency and remove such information if discovered.
Data Mining Protection
Employ data mining prevention and detection techniques for data storage objects to detect and protect against unauthorized data mining.
Description
Employ organization-defined data mining prevention and detection techniques for organization-defined data storage objects to detect and protect against unauthorized data mining. Data mining is an analytical process that attempts to find correlations or patterns in large data sets for the purpose of data or knowledge discovery. Data storage objects include database records and database fields. Organizations determine if there are adequate protections in place to protect sensitive information prior to publishing data or connecting systems to shared data environments.
Access Control Decisions
Establish procedures to ensure access control decisions are applied to each access request prior to access enforcement.
Description
Establish procedures to ensure that organization-defined access control decisions are applied to each access request prior to access enforcement. Access control decisions are based on the content of access rules or databases specified by organizational access control policies. Organizations ensure that access control decisions are properly applied by systems prior to enforcing access, and verification of correct application of access controls can be done through system testing and code reviews.
Reference Monitor
Implement a reference monitor for access control that is tamperproof, always invoked, and small enough to be subject to analysis and testing.
Description
Implement a reference monitor for organization-defined access control policies that is tamperproof, always invoked, and small enough to be subject to analysis and testing, the completeness of which can be assured. A reference monitor is a set of design requirements on a reference validation mechanism that enforces an access control policy over all subjects and objects in a system. The reference validation mechanism is always invoked, tamper proof, and small enough to be subject to complete analysis and testing.
AT Awareness and Training 5 controls
Controls ensuring that personnel are adequately trained and aware of security and privacy risks, policies, and procedures relevant to their roles.
Policy and Procedures
Develop, document, and disseminate awareness and training policy and procedures.
Description
Develop, document, and disseminate awareness and training policy and procedures that address purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance. Review and update the current awareness and training policy and procedures on an organization-defined frequency and following organization-defined events.
Literacy Training and Awareness
Provide security and privacy literacy training to system users including recognizing and reporting potential indicators of insider threat.
Description
Provide security and privacy literacy training to system users, including initial training when the user is provided access and subsequent updates on an organization-defined frequency. Training content includes recognizing and reporting potential indicators of insider threat, recognizing social engineering attempts, understanding security responsibilities, and reporting suspicious activities. Literacy training is a prerequisite to role-based training and ensures all users have a foundational understanding of security and privacy principles.
Role-Based Training
Provide role-based security and privacy training to personnel with assigned security roles and responsibilities before authorizing access.
Description
Provide role-based security and privacy training to personnel with assigned security and privacy roles and responsibilities before authorizing access to the system or performing assigned duties and on an organization-defined frequency thereafter. Role-based training addresses management, operational, and technical roles and responsibilities covering physical, personnel, and technical controls. Organizations provide role-based training to system developers, enterprise architects, security and privacy architects, system and network administrators, and personnel performing configuration management activities.
Training Records
Document and monitor individual information security and privacy training activities including basic awareness and role-based training.
Description
Document and monitor individual information security and privacy training activities, including basic security and privacy awareness training and specific role-based training. Retain individual training records for an organization-defined time period. Training records can be automated and can be maintained by the security and privacy training program, the human resources department, or individual supervisors.
Training Feedback
Provide feedback on organizational training results to training developers and instructors on an ongoing basis.
Description
Provide feedback on organizational training results on an organization-defined frequency to the following personnel: training developers, training instructors, and organization-defined personnel. Training feedback ensures that training remains relevant and effective. Feedback mechanisms include post-training evaluations, assessment results, lessons learned from incidents, and changes in threat landscape that may necessitate updates to training content and delivery methods.
AU Audit and Accountability 15 controls
Controls for creating, protecting, and retaining system audit records to enable monitoring, analysis, investigation, and reporting of unlawful or unauthorized activities.
Policy and Procedures
Develop, document, and disseminate audit and accountability policy and procedures.
Description
Develop, document, and disseminate audit and accountability policy and procedures that address purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance. Review and update the current audit and accountability policy and procedures on an organization-defined frequency and following organization-defined events.
Event Logging
Identify the types of events that the system is capable of logging in support of the audit function.
Description
Identify the types of events that the system is capable of logging in support of the audit function, including successful and unsuccessful account logon events, account management events, object access, policy change, privilege functions, process tracking, and system events. Coordinate the event logging function with other organizational entities requiring audit-related information to guide and inform the selection criteria for events to be logged. Review and update the list of auditable events on an organization-defined frequency.
Content of Audit Records
Ensure that audit records contain information that establishes the type of event, when and where it occurred, the source, and outcome.
Description
Ensure that audit records contain information that establishes the following: what type of event occurred, when the event occurred, where the event occurred, the source of the event, the outcome of the event, and the identity of any individuals, subjects, or objects associated with the event. Audit record content that may be necessary to support the auditing function includes event descriptions, time stamps, source and destination addresses, user or process identifiers, success or failure indications, and filenames involved.
Audit Log Storage Capacity
Allocate audit log storage capacity to accommodate anticipated audit log volume and retention requirements.
Description
Allocate audit log storage capacity to accommodate the anticipated volume of audit log data based on the types and frequency of auditable events, the storage requirements of individual audit records, and organizational retention requirements. Organizations consider the types of audit logging to be performed and the audit log processing requirements when allocating storage capacity. Allocating sufficient audit log storage reduces the likelihood of such capacity being exceeded and resulting in the potential loss or reduction of audit logging capability.
Response to Audit Logging Process Failures
Alert designated organizational personnel in the event of an audit logging process failure and take defined additional actions.
Description
Alert organization-defined personnel or roles within an organization-defined time period in the event of an audit logging process failure, and take organization-defined additional actions. Audit logging process failures include software and hardware errors, failures in audit log capturing mechanisms, and reaching or exceeding audit log storage capacity. Organizations may choose to define additional actions for audit logging process failures based on the type of failure, the location of the failure, or the severity of the failure.
Audit Record Review, Analysis, and Reporting
Review and analyze system audit records for indications of inappropriate or unusual activity and report findings.
Description
Review and analyze system audit records on an organization-defined frequency for indications of organization-defined inappropriate or unusual activity, and report findings to organization-defined personnel or roles. Audit record review, analysis, and reporting covers information security and privacy related logging performed by organizations including logging that results from monitoring of account usage, remote access, wireless connectivity, mobile device connection, configuration settings, system component inventory, and use of maintenance tools and non-local maintenance sessions.
Audit Record Reduction and Report Generation
Provide and implement an audit record reduction and report generation capability that supports on-demand review, analysis, and reporting.
Description
Provide and implement an audit record reduction and report generation capability that supports on-demand audit review, analysis, and reporting requirements and after-the-fact investigations of incidents. Audit record reduction is a process that manipulates collected audit log information and organizes it into a summary format that is more meaningful to analysts. Audit record reduction and report generation capabilities do not alter the original audit records. This control supports the process of reviewing and analyzing system audit data while preserving the integrity of original audit records.
Time Stamps
Use internal system clocks to generate time stamps for audit records with a defined granularity of time measurement.
Description
Use internal system clocks to generate time stamps for audit records and record time stamps for audit records that meet an organization-defined granularity of time measurement that can be mapped to Coordinated Universal Time or Greenwich Mean Time. Time stamps generated by the system include date and time, and are used to determine when events occurred. The granularity of time measurements refers to the degree of synchronization between system clocks and reference clocks.
Protection of Audit Information
Protect audit information and audit logging tools from unauthorized access, modification, and deletion.
Description
Protect audit information and audit logging tools from unauthorized access, modification, and deletion. Organizations may need to take actions to protect audit information, including audit logs and audit records, audit settings, and audit reports. This includes ensuring that audit information is not modified, deleted, or overwritten by unauthorized individuals or processes, and is maintained in a secure location with restricted access. Audit information may also be protected by encrypting audit records or using digital signatures to verify integrity.
Non-Repudiation
Provide irrefutable evidence that an individual or process performed a specific action to protect against false claims.
Description
Provide irrefutable evidence that an individual or process performed a specific action to protect against false claims of not having performed the action. Non-repudiation services can be used to determine if information originated from a particular individual or if an individual took specific actions, such as sending an email, signing a contract, approving a procurement request, or receiving specific information. Types of non-repudiation services include digital signatures and digital message receipts.
Audit Record Retention
Retain audit records for an organization-defined time period consistent with records retention policies.
Description
Retain audit records for an organization-defined time period consistent with records retention policies to provide support for after-the-fact investigations of incidents and to meet regulatory and organizational information retention requirements. Organizations retain audit records until it is determined that the records are no longer needed for administrative, legal, audit, or other operational purposes, including the investigation of or response to incidents and the correlation of audit record information with other information.
Audit Record Generation
Provide audit record generation capability for the event types defined in AU-2 and allow designated personnel to select events to audit.
Description
Provide audit record generation capability for the event types the system is capable of auditing as defined in AU-2 on all information system and network components. Allow organization-defined personnel or roles to select the event types that are to be logged by specific components of the system. Generate audit records for the selected event types with the content defined in AU-3. The selection of event types for auditing is a dynamic process that can change over time based on evolving threat information and changing system configurations.
Monitoring for Information Disclosure
Monitor designated open-source information channels for evidence of unauthorized disclosure of organizational information.
Description
Monitor organization-defined open-source information and information channels on an organization-defined frequency for evidence of unauthorized disclosure of organizational information. Open-source information includes social media sites, blogs, discussion forums, and websites. Monitoring these channels allows organizations to detect and respond to unauthorized disclosures of sensitive information in a timely manner, potentially limiting the damage caused by such disclosures.
Session Audit
Provide and implement the capability for authorized users to select a user session to capture, record, and review audit records.
Description
Provide and implement the capability for organization-defined users or roles to select a user session to capture and record, and to remotely view and hear all content related to an established user session in real time. Session auditing activities are developed, integrated, and used in consultation with legal counsel in accordance with applicable laws, executive orders, directives, regulations, policies, standards, and guidelines. Session audits can include monitoring keystrokes, tracking websites visited, and recording information or file transfers.
Cross-Organizational Audit Logging
Employ methods for coordinating audit information among external organizations when audit information is transmitted across boundaries.
Description
Employ organization-defined methods for coordinating organization-defined audit information among external organizations when audit information is transmitted across organizational boundaries. When organizations use systems or services of external organizations, the auditing capability necessitates a coordinated, cross-organization approach. Organizations may employ methods such as memoranda of understanding to manage the coordination of audit information between organizations, including shared audit log formats, standardized time synchronization, and agreed-upon retention periods.
CA Assessment, Authorization, and Monitoring 8 controls
Controls for assessing security controls, authorizing system operations, and continuously monitoring information systems.
Policy and Procedures
Develop, document, and disseminate assessment, authorization, and monitoring policy and procedures.
Description
Develop, document, and disseminate assessment, authorization, and monitoring policy and procedures that address purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance. Review and update the current assessment, authorization, and monitoring policy and procedures on an organization-defined frequency and following organization-defined events.
Control Assessments
Select assessors, develop an assessment plan, assess controls for correctness and effectiveness, and produce a report.
Description
Select the appropriate assessor or assessment team for the type of assessment to be conducted. Develop a control assessment plan that describes the scope of the assessment including controls and control enhancements under assessment, assessment procedures to be used, and the assessment environment. Assess the controls in the system and its environment of operation on an organization-defined frequency to determine the extent to which the controls are implemented correctly, operating as intended, and producing the desired outcome. Produce a control assessment report that documents the results of the assessment.
Information Exchange
Approve and manage the exchange of information between the system and other systems using interconnection security agreements.
Description
Approve and manage the exchange of information between the system and other systems using interconnection security agreements, information exchange security agreements, memoranda of understanding or agreement, service level agreements, user agreements, nondisclosure agreements, or other forms of agreement. Document the interface characteristics, security and privacy requirements, controls, and responsibilities for each connection. Review and update the agreements on an organization-defined frequency.
Plan of Action and Milestones
Develop a plan of action and milestones to document planned remedial actions for weaknesses or deficiencies.
Description
Develop a plan of action and milestones for the system to document the planned remedial actions of the organization to correct weaknesses or deficiencies noted during the assessment of the controls and to reduce or eliminate known vulnerabilities in the system. Update the existing plan of action and milestones on an organization-defined frequency based on the findings from control assessments, independent audits or reviews, and continuous monitoring activities.
Authorization
Assign a senior official as the authorizing official and ensure the system is authorized before operation.
Description
Assign a senior official as the authorizing official for the system. Ensure that the authorizing official authorizes the system for processing before commencing operations and updates the authorization on an organization-defined frequency. Authorization is the official management decision to authorize the operation of an information system and to explicitly accept the risk to organizational operations, organizational assets, individuals, other organizations, and the nation based on the implementation of an agreed-upon set of controls.
Continuous Monitoring
Develop a system-level continuous monitoring strategy and implement a program with established metrics and frequencies.
Description
Develop a system-level continuous monitoring strategy and implement a continuous monitoring program that includes establishing organization-defined metrics to be monitored, establishing organization-defined frequencies for monitoring and assessment of control effectiveness, ongoing control assessments in accordance with the continuous monitoring strategy, ongoing monitoring of system and organization-defined metrics, correlation and analysis of information generated by control assessments and monitoring, and response actions to address results of analysis.
Penetration Testing
Conduct penetration testing on defined systems or system components using defined methodologies.
Description
Conduct penetration testing on an organization-defined frequency on organization-defined systems or system components. Penetration testing is a specialized type of assessment conducted as part of security and privacy assessments that leverages adversary tools, techniques, and procedures to evaluate the effectiveness of implemented controls. Penetration testing can be used to validate vulnerabilities or determine the degree of penetration resistance of systems to sophisticated adversaries. Results from penetration testing are used to prioritize corrective actions.
Internal System Connections
Authorize and document internal connections of system components and monitor for compliance.
Description
Authorize internal connections of organization-defined system components or classes of components to the system. Document for each internal connection the interface characteristics, security and privacy requirements, and the nature of the information communicated. Internal system connections include connections between separate physical or virtual systems within the authorization boundary, and connections between different operating systems, applications, or databases within the same physical or virtual system.
CM Configuration Management 14 controls
Controls for establishing and maintaining baseline configurations, tracking and controlling changes, restricting unnecessary functionality, and maintaining component inventories.
Policy and Procedures
Develop, document, and disseminate configuration management policy and procedures.
Description
Develop, document, and disseminate configuration management policy and procedures that address purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance. Review and update the current configuration management policy and procedures on an organization-defined frequency and following organization-defined events.
Baseline Configuration
Develop, document, and maintain a current baseline configuration of the system under configuration control.
Description
Develop, document, and maintain under configuration control a current baseline configuration of the system. Baseline configurations are documented, formally reviewed, and agreed-upon specifications for systems or configuration items within those systems. Baseline configurations serve as a basis for future builds, releases, or changes to systems and include information about system components, network topology, and the logical placement of functions or components within the system architecture.
Configuration Change Control
Determine and document types of changes that are configuration-controlled, review proposed changes, and document decisions.
Description
Determine and document the types of changes to the system that are configuration-controlled. Review proposed configuration-controlled changes to the system and approve or disapprove such changes with explicit consideration for security and privacy impact analyses. Document configuration change decisions associated with the system. Implement approved configuration-controlled changes to the system. Retain records of configuration-controlled changes to the system and review changes on an organization-defined frequency.
Impact Analyses
Analyze changes to the system to determine potential security and privacy impacts prior to change implementation.
Description
Analyze changes to the system to determine potential security and privacy impacts prior to change implementation. Security and privacy impact analyses may include assessments of risk to understand the impact of the changes and to determine if additional controls are required. Organizations conduct impact analyses on proposed changes to system configurations, software, hardware, firmware, and associated documentation to assess the potential effects on security and privacy.
Access Restrictions for Change
Define, document, approve, and enforce physical and logical access restrictions associated with changes to the system.
Description
Define, document, approve, and enforce physical and logical access restrictions associated with changes to the system. Changes to the hardware, software, or firmware components of systems or the operational procedures related to the system can potentially have significant effects on the security of the systems. Therefore, organizations permit only qualified and authorized individuals to access systems for purposes of initiating changes. Access restrictions include physical and logical access control requirements, workflow automation, media libraries, abstract layers, and change windows.
Configuration Settings
Establish and document configuration settings for components using the most restrictive mode consistent with requirements.
Description
Establish and document mandatory configuration settings for information technology products employed within the system using organization-defined common secure configurations that reflect the most restrictive mode consistent with operational requirements. Implement the configuration settings. Identify, document, and approve any deviations from established configuration settings. Monitor and control changes to the configuration settings in accordance with organizational policies and procedures.
Least Functionality
Configure the system to provide only mission-essential capabilities and restrict the use of specific functions, ports, and services.
Description
Configure the system to provide only organization-defined mission-essential capabilities and prohibit or restrict the use of organization-defined functions, ports, protocols, software, and services. Systems provide a wide variety of functions and services. Some of the functions and services routinely provided by default may not be necessary to support essential organizational missions, functions, or operations. Additionally, it is sometimes convenient to provide multiple services from a single system component, but doing so increases risk.
System Component Inventory
Develop and document an inventory of system components that accurately reflects the system and its authorization boundary.
Description
Develop and document an inventory of system components that accurately reflects the system, is consistent with the authorization boundary of the system, is at the level of granularity deemed necessary for tracking and reporting, and includes information deemed necessary to achieve effective system component accountability. Review and update the system component inventory on an organization-defined frequency. System components include hardware, software, firmware, documentation, and organizational policies.
Configuration Management Plan
Develop, document, and implement a configuration management plan that addresses roles, responsibilities, and procedures.
Description
Develop, document, and implement a configuration management plan for the system that addresses roles, responsibilities, and configuration management processes and procedures. Establish a process for identifying configuration items throughout the system development life cycle and for managing the configuration of the configuration items. Define the configuration items for the system and place them under configuration management. The plan describes how to move changes through the change management process and how to update configuration settings and baselines.
Software Usage Restrictions
Use software in accordance with contract agreements and copyright laws, and track, control, and document usage.
Description
Use software and associated documentation in accordance with contract agreements and copyright laws. Track the use of software and associated documentation protected by quantity licenses to control copying and distribution. Control and document the use of peer-to-peer file sharing technology to ensure that this capability is not used for the unauthorized distribution, display, performance, or reproduction of copyrighted work. Organizations employ tracking systems for software licenses to ensure compliance.
User-Installed Software
Establish and enforce policies governing the installation of software by users, monitor policy compliance, and enforce restrictions.
Description
Establish organization-defined policies governing the installation of software by users. Enforce software installation policies through organization-defined methods. Monitor policy compliance on an organization-defined frequency. User-installed software can introduce vulnerabilities and may require additional security controls. Organizations enforce policies through technical controls, such as software whitelisting or application control solutions, and through administrative controls, such as periodic audits of installed software.
Information Location
Identify and document the location of information processed and maintained and the specific system components on which it resides.
Description
Identify and document the location of organization-defined information and the specific system components on which the information is processed and stored. Information location addresses the need to understand where information is being processed and stored so that appropriate controls can be applied to protect the information. Organizations may define different types of information that require location tracking, including personally identifiable information, classified information, and controlled unclassified information.
Data Action Mapping
Develop and document a map of system data actions identifying where personally identifiable information is processed, stored, and transmitted.
Description
Develop and document a map of system data actions that identifies where in the system personally identifiable information is processed, stored, or transmitted. Data action mapping supports the identification of where personally identifiable information resides on a system. It helps organizations comply with privacy requirements, ensure appropriate privacy protections are in place, and support incident response activities by enabling rapid identification of affected data and data subjects when breaches or unauthorized disclosures occur.
Signed Components
Prevent the installation of software and firmware components without verification that the component has been digitally signed.
Description
Prevent the installation of organization-defined software and firmware components without verification that the component has been digitally signed using a certificate that is recognized and approved by the organization. Digital signatures and the verification of those signatures is a method of code authentication. Organizations can employ digital signature verification to validate that certain software or firmware components have not been tampered with and that the components come from a verified, trusted source.
CP Contingency Planning 12 controls
Controls for ensuring continued operations in the event of disruption, including contingency planning, testing, alternate processing sites, and system backup and recovery.
Policy and Procedures
Develop, document, and disseminate contingency planning policy and procedures.
Description
Develop, document, and disseminate contingency planning policy and procedures that address purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance. Review and update the current contingency planning policy and procedures on an organization-defined frequency and following organization-defined events.
Contingency Plan
Develop a contingency plan that identifies essential missions and business functions, provides recovery objectives and priorities.
Description
Develop a contingency plan for the system that identifies essential mission and business functions and associated contingency requirements, provides recovery objectives and restoration priorities and metrics, addresses contingency roles and responsibilities and assigned individuals with contact information, addresses maintaining essential mission and business functions despite a system disruption, compromise, or failure, and is reviewed and updated on an organization-defined frequency. Distribute copies of the contingency plan to organization-defined key contingency personnel and organizational elements.
Contingency Training
Provide contingency training to system users consistent with assigned roles and responsibilities.
Description
Provide contingency training to system users consistent with assigned roles and responsibilities within an organization-defined time period of assuming a contingency role or responsibility. Provide contingency training on an organization-defined frequency thereafter. Review and update contingency training content on an organization-defined frequency and following organization-defined events. Contingency training includes training for initial and refresher activities, providing users with the knowledge and skills needed to execute contingency plans effectively.
Contingency Plan Testing
Test the contingency plan on a defined frequency to determine effectiveness and organizational readiness.
Description
Test the contingency plan for the system on an organization-defined frequency using organization-defined tests to determine the effectiveness of the plan and the readiness of the organization to execute the plan. Review the contingency plan test results and initiate corrective actions if needed. Methods for testing contingency plans include tabletop exercises, simulations, parallel processing, full interrupt testing, and checklist testing. Organizations coordinate contingency plan testing with organizational elements responsible for related plans.
Alternate Storage Site
Establish an alternate storage site with agreements to permit storage and retrieval of system backup information.
Description
Establish an alternate storage site, including necessary agreements, either commercial or governmental, to permit the storage and retrieval of system backup information. Ensure that the alternate storage site provides security controls equivalent to that of the primary site. Alternate storage sites are geographically distinct from primary storage sites and are resistant to the same hazards. Organizations may establish multiple alternate storage sites to account for different types of disruptions.
Alternate Processing Site
Establish an alternate processing site with agreements to permit the transfer and resumption of system operations.
Description
Establish an alternate processing site, including necessary agreements to permit the transfer and resumption of organization-defined system operations for essential mission and business functions within an organization-defined time period consistent with recovery time and recovery point objectives when the primary processing capabilities are unavailable. Ensure that equipment and supplies required to transfer and resume operations are available at the alternate processing site or contracts are in place to support delivery to the site within the organization-defined time period for transfer and resumption.
Telecommunications Services
Establish alternate telecommunications services with agreements to permit the resumption of system operations.
Description
Establish alternate telecommunications services, including necessary agreements, to permit the resumption of organization-defined system operations for essential mission and business functions within an organization-defined time period when the primary telecommunications capabilities are unavailable at either the primary or alternate processing or storage sites. Organizations may specify different telecommunications services at different levels of capability, such as primary, alternate, and emergency services with corresponding priorities for restoration.
System Backup
Conduct backups of user-level, system-level, and system documentation consistent with recovery objectives.
Description
Conduct backups of user-level information, system-level information, and system documentation including security and privacy-related documentation contained in the system on an organization-defined frequency consistent with recovery time and recovery point objectives. Protect the confidentiality, integrity, and availability of backup information. System backups include system state information, operating system software, middleware, application software, and licenses. Differential, incremental, and full backup strategies may be employed depending on organizational requirements.
System Recovery and Reconstitution
Provide for the recovery and reconstitution of the system to a known state within defined time periods after a disruption.
Description
Provide for the recovery and reconstitution of the system to a known state within organization-defined time periods consistent with recovery time and recovery point objectives after a disruption, compromise, or failure. Recovery is the process of restoring system capabilities to operational status. Reconstitution takes place after recovery and includes activities for returning systems to fully operational status. Organizations determine the desired system state for recovery and reconstitution activities.
Alternate Communications Protocols
Provide the capability to employ alternative communications protocols in support of maintaining continuity of operations.
Description
Provide the capability to employ organization-defined alternative communications protocols in support of maintaining continuity of operations. Contingency plans and the contingency training or testing associated with those plans incorporate an appropriate set of alternative communications protocols as part of establishing resilience in organizational systems. Alternative communications protocols support a comprehensive approach to resilience, including the ability to switch between different protocols if primary protocols are unavailable or compromised.
Safe Mode
When defined conditions are detected, enter a safe mode of operation with defined restrictions of safe mode.
Description
When organization-defined conditions are detected, enter a safe mode of operation with organization-defined restrictions of safe mode of operation. For systems that support safe mode of operation, the safe mode limits the types of activities or functions that can be performed when those conditions are encountered. Safe mode of operation provides a limited subset of the functionality available on the system in a degraded but operational state, enabling continued mission-critical activities while managing risk from identified conditions.
Alternative Security Mechanisms
Employ alternative or supplemental security mechanisms when primary means are unavailable or compromised.
Description
Employ organization-defined alternative or supplemental security mechanisms for satisfying organization-defined security requirements when the primary means of implementing the security requirements are unavailable or compromised. Use of alternative security mechanisms supports system resilience, contingency planning, and continuity of operations. Organizations can deploy alternative or supplemental security mechanisms to address any of the security requirements in the security plan, including authentication, encryption, access control, and auditing.
IA Identification and Authentication 12 controls
Controls for uniquely identifying and authenticating users, devices, and services before granting access to system resources.
Policy and Procedures
Develop, document, and disseminate identification and authentication policy and procedures.
Description
Develop, document, and disseminate identification and authentication policy and procedures that address purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance. Review and update the current policy and procedures on a defined frequency and following defined events.
Identification and Authentication (Organizational Users)
Uniquely identify and authenticate organizational users and associate that identification with processes acting on behalf of those users.
Description
Uniquely identify and authenticate organizational users and associate that unique identification with processes acting on behalf of those users. Implement multi-factor authentication for access to privileged and non-privileged accounts as required by organizational policy.
Device Identification and Authentication
Uniquely identify and authenticate devices before establishing a connection.
Description
Uniquely identify and authenticate devices before establishing a local, remote, or network connection using bidirectional authentication that is cryptographically based or uses other defined methods of device identification and authentication.
Identifier Management
Manage system identifiers by receiving authorization, selecting and assigning identifiers, preventing reuse, and disabling after inactivity.
Description
Manage system identifiers by receiving authorization from organizational personnel to assign an individual, group, role, service, or device identifier. Select an identifier that identifies an individual, group, role, service, or device. Assign the identifier to the intended individual, group, role, service, or device. Prevent reuse of identifiers for a defined time period and disable the identifier after a defined period of inactivity.
Authenticator Management
Manage system authenticators by verifying identity, establishing initial content, and ensuring sufficient strength.
Description
Manage system authenticators by verifying the identity of the individual, group, role, service, or device receiving the authenticator as part of the initial authenticator distribution. Establish initial authenticator content for any authenticators issued by the organization. Ensure that authenticators have sufficient strength of mechanism for their intended use. Establish and implement administrative procedures for initial authenticator distribution, for lost, compromised, or damaged authenticators, and for revoking authenticators. Change default authenticators prior to first use. Change or refresh authenticators on a defined frequency or when defined events occur.
Authentication Feedback
Obscure feedback of authentication information during the authentication process.
Description
Obscure feedback of authentication information during the authentication process to protect the information from possible exploitation and use by unauthorized individuals.
Cryptographic Module Authentication
Implement mechanisms for authentication to a cryptographic module meeting applicable requirements.
Description
Implement mechanisms for authentication to a cryptographic module that meet the requirements of applicable federal laws, executive orders, directives, policies, regulations, standards, and guidelines for such authentication.
Identification and Authentication (Non-Organizational Users)
Uniquely identify and authenticate non-organizational users or processes acting on their behalf.
Description
Uniquely identify and authenticate non-organizational users or processes acting on behalf of non-organizational users. Implement multi-factor authentication and replay-resistant authentication mechanisms for network access to non-privileged and privileged accounts as required.
Service Identification and Authentication
Uniquely identify and authenticate services and service providers before establishing communications.
Description
Uniquely identify and authenticate defined services and service providers before establishing communications with requesting services or service providers.
Adaptive Authentication
Require users to provide additional authentication factors when defined conditions are met.
Description
Require users to provide additional authentication factors when defined conditions or situations requiring re-authentication are met, such as changes in risk levels, access to sensitive resources, or when anomalous behavior is detected.
Re-authentication
Require users to re-authenticate when defined circumstances or situations require it.
Description
Require users to re-authenticate when defined circumstances or situations require re-authentication, such as after a defined time period of inactivity, when changes in roles or privileges occur, or when security-relevant events are detected.
Identity Proofing
Identity proof users that require accounts by resolving identification to a records database.
Description
Identity proof users that require accounts for logical access to systems by resolving a government-issued form of identification to a maintained records database, verifying the identity of the individual, and issuing credentials bound to the verified identity.
IR Incident Response 10 controls
Controls for establishing operational incident handling capabilities including preparation, detection, analysis, containment, recovery, and user response activities.
Policy and Procedures
Develop, document, and disseminate incident response policy and procedures.
Description
Develop, document, and disseminate incident response policy and procedures that address purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance. Review and update the current policy and procedures on a defined frequency and following defined events.
Incident Response Training
Provide incident response training to system users consistent with assigned roles and responsibilities.
Description
Provide incident response training to system users consistent with assigned roles and responsibilities within a defined time period of assuming an incident response role or responsibility, and at a defined frequency thereafter. Review and update incident response training content on a defined frequency and following defined events. Incorporate lessons learned from ongoing incident handling activities into incident response training.
Incident Response Testing
Test the incident response capability at a defined frequency using defined tests.
Description
Test the effectiveness of the incident response capability for the system at a defined frequency using defined tests to determine the incident response effectiveness and document the results.
Incident Handling
Implement an incident handling capability including preparation, detection, analysis, containment, eradication, and recovery.
Description
Implement an incident handling capability for incidents that is consistent with the incident response plan and includes preparation, detection and analysis, containment, eradication, and recovery. Coordinate incident handling activities with contingency planning activities and incorporate lessons learned from ongoing incident handling activities into incident response procedures, training, and testing.
Incident Monitoring
Track and document incidents on an ongoing basis.
Description
Track and document incidents on an ongoing basis to identify trends, recurring events, and systemic weaknesses in the organizational security posture.
Incident Reporting
Require personnel to report suspected incidents to the organizational incident response capability.
Description
Require personnel to report suspected incidents to the organizational incident response capability within a defined time period. Report incident information to defined authorities. Correlate incident information and individual incident reports to achieve organization-wide situational awareness.
Incident Response Assistance
Provide an incident response support resource that offers advice and assistance for handling and reporting incidents.
Description
Provide an incident response support resource, integral to the organizational incident response capability, that offers advice and assistance to users of the system for the handling and reporting of incidents.
Incident Response Plan
Develop an incident response plan that provides a roadmap for implementing the incident response capability.
Description
Develop an incident response plan that provides the organization with a roadmap for implementing its incident response capability. Describe the structure and organization of the incident response capability, provide a high-level approach for how the incident response capability fits into the overall organization, and meet the unique requirements of the organization including mission, size, structure, and functions.
Information Spillage Response
Respond to information spills by identifying, alerting, isolating, and eradicating the information.
Description
Respond to information spills by identifying the specific information involved in the system contamination, alerting defined personnel or roles using a method of communication not associated with the spill, isolating the contaminated system or system component, eradicating the information from the contaminated system or component, and identifying other systems that may have been subsequently contaminated.
Integrated Information Security Analysis Team
Establish an integrated team of forensic, malware, and other analysts to address suspected incidents.
Description
Establish an integrated team of forensic and malware analysts, tool developers, and real-time operations personnel to address suspected incidents and assist in the rapid detection, analysis, and recovery from incidents.
MA Maintenance 7 controls
Controls for performing timely and effective system maintenance, controlling maintenance tools, and managing maintenance personnel.
Policy and Procedures
Develop, document, and disseminate maintenance policy and procedures.
Description
Develop, document, and disseminate maintenance policy and procedures that address purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance. Review and update the current policy and procedures on a defined frequency and following defined events.
Controlled Maintenance
Schedule, document, and review records of maintenance, repair, and replacement on system components.
Description
Schedule, document, and review records of maintenance, repair, and replacement on system components in accordance with manufacturer or vendor specifications and organizational requirements. Approve and monitor all maintenance activities whether performed on site or remotely and whether the system or component is serviced on site or removed to another location.
Maintenance Tools
Approve, control, and monitor the use of system maintenance tools.
Description
Approve, control, and monitor the use of system maintenance tools. Review previously approved system maintenance tools on a defined frequency. Prevent the unauthorized removal of maintenance equipment containing organizational information by verifying that there is no organizational information contained on the equipment, sanitizing or destroying the equipment, retaining the equipment within the facility, or obtaining an exemption from authorized personnel.
Nonlocal Maintenance
Approve and monitor nonlocal maintenance and diagnostic activities.
Description
Approve and monitor nonlocal maintenance and diagnostic activities. Allow the use of nonlocal maintenance and diagnostic tools only as consistent with organizational policy and documented in the security plan for the system. Employ strong identification and authentication techniques in the establishment of nonlocal maintenance and diagnostic sessions. Maintain records for nonlocal maintenance and diagnostic activities. Terminate session and network connections when nonlocal maintenance is completed.
Maintenance Personnel
Establish a process for maintenance personnel authorization and maintain a list of authorized personnel.
Description
Establish a process for maintenance personnel authorization and maintain a list of authorized maintenance organizations or personnel. Verify that non-escorted personnel performing maintenance on the system possess the required access authorizations. Designate organizational personnel with required access authorizations and technical competence to supervise the maintenance activities of personnel who do not possess the required access authorizations.
Timely Maintenance
Obtain maintenance support and spare parts for defined system components within a defined time period.
Description
Obtain maintenance support and spare parts for defined system components within a defined time period of failure to ensure continuity of operations and system availability.
Field Maintenance
Restrict or prohibit field maintenance on defined systems or system components.
Description
Restrict or prohibit field maintenance on defined systems or system components to defined trusted maintenance facilities to ensure proper controls and oversight of maintenance activities.
MP Media Protection 8 controls
Controls for protecting system media, both physical and digital, including restricting access, marking, storage, transport, sanitization, and use.
Policy and Procedures
Develop, document, and disseminate media protection policy and procedures.
Description
Develop, document, and disseminate media protection policy and procedures that address purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance. Review and update the current policy and procedures on a defined frequency and following defined events.
Media Access
Restrict access to defined types of digital and non-digital media to defined personnel or roles.
Description
Restrict access to defined types of digital and non-digital media to defined personnel or roles using defined controls to protect sensitive information from unauthorized access and disclosure.
Media Marking
Mark system media indicating distribution limitations, handling caveats, and applicable security markings.
Description
Mark system media indicating the distribution limitations, handling caveats, and applicable security markings of the information. Exempt defined types of media from marking if the media remain within defined controlled areas.
Media Storage
Physically control and securely store defined types of digital and non-digital media.
Description
Physically control and securely store defined types of digital and non-digital media within defined controlled areas using defined security controls to prevent unauthorized access, theft, or damage to the media.
Media Transport
Protect and control defined types of system media during transport outside of controlled areas.
Description
Protect and control defined types of system media during transport outside of controlled areas using defined controls. Maintain accountability for system media during transport and restrict the activities associated with the transport of media to authorized personnel.
Media Sanitization
Sanitize system media prior to disposal, release out of organizational control, or release for reuse.
Description
Sanitize system media prior to disposal, release out of organizational control, or release for reuse using defined sanitization techniques and procedures in accordance with applicable federal and organizational standards and policies.
Media Use
Restrict the use of defined types of system media on defined systems or system components.
Description
Restrict or prohibit the use of defined types of system media on defined systems or system components using defined controls to prevent unauthorized use and potential introduction of malicious code or unauthorized data exfiltration.
Media Downgrading
Establish and apply a process to downgrade system media with defined strength and integrity.
Description
Establish and apply a media downgrading process that includes employing downgrading mechanisms with defined strength and integrity, testing downgrading equipment and procedures on a defined frequency, and properly documenting all downgrading actions to maintain an audit trail.
PE Physical and Environmental Protection 22 controls
Controls for protecting the physical environment and infrastructure of information systems, including facility access, monitoring, power, and environmental protections.
Policy and Procedures
Develop, document, and disseminate physical and environmental protection policy and procedures.
Description
Develop, document, and disseminate physical and environmental protection policy and procedures that address purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance. Review and update the current policy and procedures on a defined frequency and following defined events.
Physical Access Authorizations
Develop, approve, and maintain a list of individuals with authorized access to the facility.
Description
Develop, approve, and maintain a list of individuals with authorized access to the facility where the system resides. Issue authorization credentials for facility access. Review the access list detailing authorized facility access by individuals on a defined frequency. Remove individuals from the facility access list when access is no longer required.
Physical Access Control
Enforce physical access authorizations at defined entry and exit points to the facility.
Description
Enforce physical access authorizations at defined entry and exit points to the facility where the system resides by verifying individual access authorizations before granting access to the facility, controlling ingress and egress with defined physical access control systems and guards, controlling access to areas within the facility designated as publicly accessible by implementing appropriate controls, and securing keys, combinations, and other physical access devices.
Access Control for Transmission
Control physical access to system distribution and transmission lines within organizational facilities.
Description
Control physical access to defined system distribution and transmission lines within organizational facilities using defined security controls to prevent unauthorized access, tampering, or eavesdropping on communications.
Access Control for Output Devices
Control physical access to output from defined output devices to prevent unauthorized access.
Description
Control physical access to output from defined output devices to prevent unauthorized individuals from obtaining the output, including printers, scanners, copiers, and other devices that produce tangible output.
Monitoring Physical Access
Monitor physical access to the facility where the system resides to detect and respond to incidents.
Description
Monitor physical access to the facility where the system resides to detect and respond to physical security incidents. Review physical access logs on a defined frequency and upon occurrence of defined events. Coordinate results of reviews and investigations with the organizational incident response capability.
Visitor Access Records
Maintain visitor access records to the facility including name, organization, and purpose of visit.
Description
Maintain visitor access records to the facility where the system resides that include the name and organization of the person visiting, the signature of the visitor, the form of identification, the date of access, the time of entry and departure, the purpose of the visit, and the name and organization of the person visited. Review visitor access records on a defined frequency and retain records for a defined period.
Power Equipment and Cabling
Protect power equipment and power cabling for the system from damage and destruction.
Description
Protect power equipment and power cabling for the system from damage and destruction through physical security measures and environmental controls.
Emergency Shutoff
Provide the capability of shutting off power to system components in emergency situations.
Description
Provide the capability of shutting off power to defined system components or the system in emergency situations. Place emergency shutoff switches or devices in defined locations by system or system component to facilitate access for authorized personnel and protect personnel from electromagnetic or electrical hazards.
Emergency Power
Provide an uninterruptible power supply to facilitate orderly shutdown or transition to alternate power.
Description
Provide an uninterruptible power supply to facilitate an orderly shutdown of the system in the event of a primary power source loss and to enable transition of the system to long-term alternate power.
Emergency Lighting
Employ and maintain automatic emergency lighting that activates in the event of a power outage.
Description
Employ and maintain automatic emergency lighting for the system that activates in the event of a power outage or disruption and that covers emergency exits and evacuation routes within the facility.
Fire Protection
Employ and maintain fire detection and suppression systems supported by an independent energy source.
Description
Employ and maintain fire detection and suppression systems for the system that are supported by an independent energy source to ensure continuous protection in the event of primary power loss.
Environmental Controls
Maintain temperature and humidity levels within the facility and monitor environmental conditions.
Description
Maintain temperature and humidity levels within the facility where the system resides at acceptable levels as defined by organizational requirements and equipment specifications. Monitor environmental conditions at a defined frequency to detect conditions that could adversely affect system operations.
Water Damage Protection
Protect the system from damage resulting from water leakage by providing master shutoff or isolation valves.
Description
Protect the system from damage resulting from water leakage by providing master shutoff or isolation valves that are accessible, working properly, and known to key personnel.
Delivery and Removal
Authorize and control system components entering and exiting the facility and maintain records.
Description
Authorize and control defined types of system components entering and exiting the facility. Maintain records of the system components entering and exiting the facility to support accountability and asset management.
Alternate Work Site
Establish and implement controls at alternate work sites and assess effectiveness.
Description
Establish and implement security and privacy controls at alternate work sites equivalent to those at the primary work site. Assess the effectiveness of controls at alternate work sites on a defined frequency and provide a means for employees to communicate with information security and privacy personnel in case of incidents or problems.
Location of System Components
Position system components within the facility to minimize potential damage and unauthorized access.
Description
Position system components within the facility to minimize potential damage from defined physical and environmental hazards and to minimize the opportunity for unauthorized access.
Information Leakage
Protect the system from information leakage due to electromagnetic signals emanations.
Description
Protect the system from information leakage due to electromagnetic signals emanations by implementing defined protective measures to contain and prevent the interception of unintended signals.
Asset Monitoring and Tracking
Employ asset location technologies to track and monitor the location and movement of assets.
Description
Employ defined asset location technologies to track and monitor the location and movement of defined assets within defined controlled areas to support asset management and physical security operations.
Electromagnetic Pulse Protection
Employ protective measures against electromagnetic pulse damage for defined systems and components.
Description
Employ defined protective measures against electromagnetic pulse damage for defined systems and system components to ensure continued operation and protection of critical infrastructure.
Component Marking
Mark system hardware components indicating the impact level or classification of information permitted.
Description
Mark system hardware components indicating the impact level or classification of the information permitted to be processed, stored, or transmitted by the component to ensure proper handling and access control.
Facility Location
Plan the location of the facility considering physical and environmental hazards.
Description
Plan the location or site of the facility where the system resides considering physical and environmental hazards. For existing facilities, consider the physical and environmental hazards in the organizational risk management strategy.
PL Planning 8 controls
Controls for developing, documenting, and maintaining security and privacy plans, rules of behavior, and security architecture information.
Policy and Procedures
Develop, document, and disseminate planning policy and procedures.
Description
Develop, document, and disseminate planning policy and procedures that address purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance. Review and update the current policy and procedures on a defined frequency and following defined events.
System Security and Privacy Plans
Develop, review, update, and protect security and privacy plans for the system.
Description
Develop security and privacy plans for the system that describe the system architecture, operational environment, security and privacy requirements, and planned controls. Review and update the plans on a defined frequency and protect the plans from unauthorized disclosure and modification.
Rules of Behavior
Establish and provide rules describing responsibilities and expected behavior for system usage.
Description
Establish and provide to individuals requiring access to the system the rules that describe their responsibilities and expected behavior with regard to information and system usage. Receive a documented acknowledgment from such individuals indicating that they have read, understand, and agree to abide by the rules of behavior before authorizing access.
Concept of Operations
Develop a security and privacy concept of operations for the system.
Description
Develop a security and privacy concept of operations for the system that describes how the organization intends to operate the system from the perspective of information security and privacy.
Security and Privacy Architectures
Develop and maintain security and privacy architectures for the system.
Description
Develop and maintain security and privacy architectures for the system that describe the requirements and approach to protecting the confidentiality, integrity, and availability of system information. Review and update the architectures on a defined frequency to reflect changes in the enterprise architecture.
Central Management
Centrally manage defined controls and related processes for consistent organization-wide implementation.
Description
Centrally manage defined controls and related processes to enable consistent organization-wide implementation and oversight of security and privacy requirements.
Baseline Selection
Select a control baseline for the system based on security categorization.
Description
Select a control baseline for the system based on the security categorization of the system to establish a foundation for the security and privacy controls needed to protect the system and the information it processes.
Baseline Tailoring
Tailor the selected control baseline to ensure it is appropriate for the system.
Description
Tailor the selected control baseline by applying specified tailoring actions to adjust the controls to more closely align with the conditions specific to the system and its operating environment.
PM Program Management 29 controls
Controls at the organization level for managing the information security and privacy programs, including program plans, roles, risk management, and workforce management.
Information Security Program Plan
Develop and disseminate an organization-wide information security program plan.
Description
Develop and disseminate an organization-wide information security program plan that provides an overview of the requirements for the security program and a description of the security program management controls and common controls. Review and update the plan on a defined frequency and following defined events.
Information Security Program Leadership Role
Appoint a senior information security officer to coordinate the organization-wide security program.
Description
Appoint a senior information security officer with the mission and resources to coordinate, develop, implement, and maintain an organization-wide information security program.
Information Security and Privacy Resources
Include resources needed to implement security and privacy programs in capital planning.
Description
Include the resources needed to implement the information security and privacy programs in capital planning and investment requests. Establish a discrete line item for information security and privacy in organizational programming and budgeting documentation.
Plan of Action and Milestones Process
Implement a process to ensure plans of action and milestones document remedial actions to mitigate risk.
Description
Implement a process to ensure that plans of action and milestones for the information security, privacy, and supply chain risk management programs and associated organizational systems are developed and maintained, and document the remedial information security, privacy, and supply chain risk management actions to adequately respond to risk.
System Inventory
Develop and maintain an inventory of organizational systems.
Description
Develop and maintain an inventory of organizational systems that identifies each system, the interfaces between systems, and which systems support organizational missions and business processes.
Measures of Performance
Develop, monitor, and report on the results of information security and privacy measures of performance.
Description
Develop, monitor, and report on the results of information security and privacy measures of performance to assess the effectiveness of security and privacy programs and controls.
Enterprise Architecture
Develop and maintain an enterprise architecture with consideration for information security and privacy.
Description
Develop and maintain an enterprise architecture with consideration for information security, privacy, and the resulting risk to organizational operations and assets, individuals, other organizations, and the Nation.
Critical Infrastructure Plan
Address information security and privacy issues in the critical infrastructure protection plan.
Description
Address information security and privacy issues in the development, documentation, and updating of a critical infrastructure and key resources protection plan.
Risk Management Strategy
Develop a comprehensive organization-wide risk management strategy.
Description
Develop, document, and communicate a comprehensive organization-wide risk management strategy that consistently addresses security and privacy risk, includes a determination of risk tolerance, and is reviewed and updated on a defined frequency.
Authorization Process
Manage the authorization of systems through a defined process with security and privacy considerations.
Description
Manage the security and privacy state of organizational systems and the environments in which those systems operate through authorization processes. Designate individuals to fulfill specific roles and responsibilities within the organizational risk management process.
Mission and Business Process Definition
Define organizational mission and business processes with consideration for information security and privacy.
Description
Define organizational mission and business processes with consideration for information security and privacy, and the resulting risk to organizational operations, organizational assets, individuals, other organizations, and the Nation. Determine information protection and personally identifiable information processing needs arising from the defined mission and business processes.
Insider Threat Program
Implement an insider threat program that includes a cross-discipline incident handling team.
Description
Implement an insider threat program that includes a cross-discipline insider threat incident handling team to detect, deter, and mitigate insider threats to organizational operations, assets, and individuals.
Security and Privacy Workforce
Establish a security and privacy workforce development and improvement program.
Description
Establish a security and privacy workforce development and improvement program to ensure adequate staffing and skills for roles requiring security and privacy expertise.
Testing, Training, and Monitoring
Implement a process for ensuring security and privacy testing, training, and monitoring activities.
Description
Implement a process for ensuring that organizational plans for conducting security and privacy testing, training, and monitoring activities associated with organizational systems are developed and maintained on a defined frequency.
Security and Privacy Groups and Associations
Establish and institutionalize contact with selected security and privacy groups and associations.
Description
Establish and institutionalize contact with selected groups and associations within the security and privacy communities to stay current with security and privacy practices, share lessons learned, and facilitate knowledge exchange.
Threat Awareness Program
Implement a threat awareness program that includes cross-organization information sharing.
Description
Implement a threat awareness program that includes a cross-organization information-sharing capability for threat and vulnerability intelligence.
Protecting Controlled Unclassified Information on External Systems
Establish policy and procedures for the protection of CUI on external systems.
Description
Establish policy and procedures to ensure compliance with requirements for the protection of controlled unclassified information that is processed, stored, or transmitted on external systems.
Dissemination of Privacy Program Information
Maintain a central resource webpage for public access to organizational privacy activities.
Description
Maintain a central resource webpage accessible to the public to ensure that the public has access to information about organizational privacy activities and can communicate with the organization on privacy-related issues.
Accounting of Disclosures
Develop and maintain an accurate accounting of disclosures of personally identifiable information.
Description
Develop and maintain an accurate accounting of disclosures of personally identifiable information and make the accounting available to the individual to whom the PII relates upon request.
Personally Identifiable Information Quality Management
Develop organization-wide policies and procedures for ensuring PII quality.
Description
Develop and document organization-wide policies and procedures for ensuring that personally identifiable information quality is commensurate with the impact of decisions based on that information.
Data Governance Body
Establish a data governance body for organization-wide governance of PII management.
Description
Establish a data governance body consisting of appropriate stakeholders to provide organization-wide governance for the management and protection of personally identifiable information.
Data Integrity Board
Establish a data integrity board to review proposals for computer-matching activities.
Description
Establish a data integrity board to review proposals to conduct or participate in computer-matching programs and to maintain ongoing oversight of such programs.
Minimization of PII Used in Testing, Training, and Research
Develop policies to address the use of PII for internal testing, training, and research.
Description
Develop policies and procedures that address the use of personally identifiable information for internal testing, training, and research, and implement controls to minimize the use of PII for such purposes.
Complaint Management
Implement a process for receiving and responding to complaints about organizational privacy practices.
Description
Implement a process for receiving and responding to complaints, concerns, or questions from individuals about organizational privacy practices, and communicate the process to the public.
Privacy Reporting
Develop and disseminate privacy reports to oversight bodies and organizational officials.
Description
Develop and disseminate privacy reports to oversight bodies, organizational officials, and other personnel responsible for monitoring privacy program compliance.
Risk Framing
Establish the context for risk-based decisions by identifying assumptions, constraints, and priorities.
Description
Establish the context for risk-based decisions by identifying assumptions, constraints, risk tolerance, and priorities for managing security and privacy risk to organizational operations and assets.
Supply Chain Risk Management Strategy
Develop an organization-wide strategy for managing supply chain risks.
Description
Develop and implement an organization-wide strategy for managing supply chain risks associated with the development, acquisition, maintenance, and disposal of systems, system components, and system services.
Continuous Monitoring Strategy
Develop an organization-wide continuous monitoring strategy and program.
Description
Develop and implement an organization-wide continuous monitoring strategy and program that covers the monitoring of security and privacy controls, assessing control effectiveness, and collecting, correlating, and analyzing security and privacy-related information.
Purposing
Analyze systems, components, or services to identify their intended purpose and design constraints.
Description
Analyze systems, system components, or system services to identify their intended purpose and design them to fulfill only their stated purpose, reducing the attack surface and limiting unintended functionality.
PS Personnel Security 9 controls
Controls for screening individuals prior to access, managing personnel transfers and terminations, and establishing access agreements.
Policy and Procedures
Develop, document, and disseminate personnel security policy and procedures.
Description
Develop, document, and disseminate personnel security policy and procedures that address purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance. Review and update the current policy and procedures on a defined frequency and following defined events.
Position Risk Designation
Assign a risk designation to all organizational positions and establish screening criteria.
Description
Assign a risk designation to all organizational positions. Establish screening criteria for individuals filling those positions. Review and update position risk designations on a defined frequency.
Personnel Screening
Screen individuals prior to authorizing access to the system and rescreen on a defined frequency.
Description
Screen individuals prior to authorizing access to the system. Rescreen individuals in accordance with defined conditions requiring rescreening and on a defined frequency of such rescreening.
Personnel Termination
Upon termination, disable system access, terminate authenticators, and retrieve security-related property.
Description
Upon termination of individual employment, disable information system access within a defined time period, terminate or revoke any authenticators and credentials associated with the individual, conduct exit interviews that include a discussion of information security topics, retrieve all security-related organizational information system-related property, and retain access to organizational information and systems formerly controlled by the terminated individual.
Personnel Transfer
Review and confirm ongoing operational need for access when individuals are reassigned or transferred.
Description
Review and confirm ongoing operational need for current logical and physical access authorizations to systems and facilities when individuals are reassigned or transferred to other positions within the organization. Initiate defined transfer or reassignment actions within a defined time period following the formal transfer action.
Access Agreements
Develop and document access agreements for organizational systems and ensure individuals sign before access.
Description
Develop and document access agreements for organizational systems. Review and update the access agreements on a defined frequency. Verify that individuals requiring access to organizational information and systems sign appropriate access agreements prior to being granted access and re-sign access agreements to maintain access when access agreements have been updated or on a defined frequency.
External Personnel Security
Establish personnel security requirements for external providers and monitor compliance.
Description
Establish personnel security requirements including security roles and responsibilities for external providers. Require external providers to comply with personnel security policies and procedures established by the organization. Document personnel security requirements. Monitor provider compliance with personnel security requirements.
Personnel Sanctions
Employ a formal sanctions process for individuals failing to comply with security policies.
Description
Employ a formal sanctions process for individuals failing to comply with established information security and privacy policies and procedures. Notify defined personnel or roles within a defined time period when a formal employee sanctions process is initiated.
Position Descriptions
Incorporate security and privacy roles and responsibilities into organizational position descriptions.
Description
Incorporate security and privacy roles and responsibilities into organizational position descriptions to ensure that security and privacy requirements are clearly defined and understood for all personnel.
PT PII Processing and Transparency 8 controls
Controls for managing the processing of personally identifiable information, ensuring transparency, obtaining consent, and providing privacy notices.
Policy and Procedures
Develop, document, and disseminate PII processing and transparency policy and procedures.
Description
Develop, document, and disseminate personally identifiable information processing and transparency policy and procedures that address purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance. Review and update the current policy and procedures on a defined frequency and following defined events.
Authority to Process Personally Identifiable Information
Determine and document the legal authority for the collection, use, and sharing of PII.
Description
Determine and document the legal authority that permits the collection, use, maintenance, and sharing of personally identifiable information, either generally or in support of a specific program or system need.
Personally Identifiable Information Processing Purposes
Identify and document the purpose for processing PII and restrict processing to identified purposes.
Description
Identify and document the specific purpose for processing personally identifiable information. Describe the purpose in the public privacy notices and other applicable documents. Restrict PII processing to only those purposes that are compatible with the identified and documented purposes.
Consent
Implement mechanisms to obtain consent from individuals for the processing of their PII.
Description
Implement defined mechanisms for individuals to consent to the processing of their personally identifiable information prior to its collection that facilitate individual understanding of the consequences of providing consent and provide a means for individuals to revoke consent.
Privacy Notice
Provide notice to individuals about the processing of PII including authority, purpose, and use.
Description
Provide effective notice to individuals about the processing of personally identifiable information that includes the authority for the collection, the purposes of processing, the types of PII collected, intended use and sharing, retention, and the consequences of not providing PII.
System of Records Notice
Publish system of records notices in the Federal Register for systems maintaining PII.
Description
Publish system of records notices in the Federal Register, subject to required oversight processes, for systems containing personally identifiable information that identify the system of records and the purposes for which PII is collected, maintained, used, and shared.
Specific Categories of Personally Identifiable Information
Apply defined processing conditions for specific categories of PII requiring additional protection.
Description
Apply defined processing conditions for specific categories of personally identifiable information that may include social security numbers, biometric data, financial information, and other sensitive categories that warrant additional protection beyond standard PII handling requirements.
Computer Matching Requirements
Ensure compliance with the Computer Matching and Privacy Protection Act for matching programs.
Description
When a system or organization processes information for the purpose of conducting a matching program, verify that the requirements of the Computer Matching and Privacy Protection Act are met, including establishing matching agreements, notifying individuals, and conducting cost-benefit analyses.
RA Risk Assessment 9 controls
Controls for assessing risks to organizational operations, assets, and individuals from the operation and use of information systems.
Policy and Procedures
Develop, document, and disseminate risk assessment policy and procedures.
Description
Develop, document, and disseminate risk assessment policy and procedures that address purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance. Review and update the current risk assessment policy and procedures on a defined frequency and following defined events.
Security Categorization
Categorize the system and information processed, stored, and transmitted.
Description
Categorize the system and information processed, stored, and transmitted, document results in the security plan, and ensure categorization is consistent with FIPS 199. Review and update the security categorization on a defined frequency and when significant changes occur.
Risk Assessment
Conduct a risk assessment to identify threats, vulnerabilities, impact, and likelihood.
Description
Conduct a risk assessment to identify threats, vulnerabilities, impact, likelihood, and risk to organizational operations and assets. Document results in the risk assessment report and update on a defined frequency or when significant changes occur to the system or environment of operation.
Vulnerability Monitoring and Scanning
Monitor and scan for vulnerabilities in the system on a defined frequency.
Description
Monitor and scan for vulnerabilities in the system on a defined frequency, employ vulnerability monitoring tools, analyze vulnerability scan reports, remediate legitimate vulnerabilities within a defined time period, and share vulnerability information with designated personnel.
Technical Surveillance Countermeasures Survey
Employ a technical surveillance countermeasures survey at defined locations.
Description
Employ a technical surveillance countermeasures survey at defined locations at a defined frequency or when certain events or indicators occur to detect the presence of eavesdropping devices and technical surveillance hazards.
Risk Response
Respond to findings from security and privacy assessments, monitoring, and audits.
Description
Respond to findings from security and privacy assessments, monitoring, and audits in accordance with organizational risk tolerance. Determine the appropriate risk response strategy including acceptance, avoidance, mitigation, sharing, or transfer.
Privacy Impact Assessments
Conduct privacy impact assessments for systems processing PII.
Description
Conduct privacy impact assessments for systems processing personally identifiable information to determine the impact of the collection, use, maintenance, and sharing of PII on individuals and ensure appropriate safeguards are in place.
Criticality Analysis
Identify critical system components and functions by performing a criticality analysis.
Description
Identify critical system components and functions by performing a criticality analysis at defined decision points in the system development life cycle. Use the results to inform risk-based decisions regarding security and privacy requirements.
Threat Hunting
Establish and maintain a cyber threat hunting capability.
Description
Establish and maintain a cyber threat hunting capability to detect, track, and disrupt threats that evade existing security controls. Employ threat intelligence and advanced analytics to proactively search for indicators of compromise across organizational systems.
SA System and Services Acquisition 16 controls
Controls for managing the system development life cycle, acquisition processes, developer security testing, and supply chain considerations.
Policy and Procedures
Develop, document, and disseminate system and services acquisition policy and procedures.
Description
Develop, document, and disseminate system and services acquisition policy and procedures that address purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance. Review and update the current policy and procedures on a defined frequency and following defined events.
Allocation of Resources
Determine, document, and allocate the resources required to protect the system.
Description
Determine, document, and allocate the resources required to protect the system as part of the organizational capital planning and investment control process. Establish a discrete line item for information security and privacy in organizational programming and budgeting documentation.
System Development Life Cycle
Acquire, develop, and manage the system using a system development life cycle methodology.
Description
Acquire, develop, and manage the system using a system development life cycle methodology that incorporates information security and privacy considerations. Define and document information security and privacy roles and responsibilities throughout the system development life cycle.
Acquisition Process
Include security and privacy requirements in the acquisition contract for the system.
Description
Include security and privacy functional requirements, design and development requirements, and testing requirements in the acquisition contract for the system or component. Require the developer to provide design and implementation information for the controls employed.
System Documentation
Obtain or develop administrator and user documentation for the system.
Description
Obtain or develop administrator and user documentation for the system that describes secure configuration, installation, operation, and effective use of security and privacy features. Document attempts to obtain documentation when it is unavailable or nonexistent and take defined actions in response.
Security and Privacy Engineering Principles
Apply systems security and privacy engineering principles in specification, design, and development.
Description
Apply systems security and privacy engineering principles in the specification, design, development, implementation, and modification of the system and system components. Ensure that engineering principles are applied consistently across all phases of the system development life cycle.
External System Services
Require providers of external system services to comply with organizational security requirements.
Description
Require providers of external system services to comply with organizational security and privacy requirements and employ defined controls. Document government oversight, user roles and responsibilities, and monitoring processes for external system services.
Developer Configuration Management
Require the developer to perform configuration management during design, development, and operation.
Description
Require the developer of the system to perform configuration management during design, development, implementation, and operation. Track and control changes to the system, manage flaws, and document the implementation of the configuration management process.
Developer Testing and Evaluation
Require the developer to create and implement a security and privacy assessment plan.
Description
Require the developer of the system to create and implement a security and privacy assessment plan, perform testing and evaluation at defined depth and coverage, and produce evidence of execution of the plan and results of the testing and evaluation.
Development Process, Standards, and Tools
Require the developer to follow a documented development process and use defined tools.
Description
Require the developer to follow a documented development process, use defined tools and methods, document their use, and review the development process periodically to ensure alignment with organizational security and privacy requirements.
Developer-Provided Training
Require the developer to provide training on the correct use and operation of security functions.
Description
Require the developer to provide training on the correct use and operation of implemented security and privacy functions, controls, and mechanisms to authorized personnel with defined roles and responsibilities.
Developer Security and Privacy Architecture and Design
Require the developer to produce a design specification and security architecture.
Description
Require the developer to produce a design specification and security and privacy architecture that is consistent with the organizational security and privacy architecture established as part of the enterprise architecture.
Customized Development of Critical Components
Re-implement or custom develop critical system components to minimize vulnerabilities.
Description
Re-implement or custom develop defined critical system components to minimize potential vulnerabilities that could be exploited through supply chain compromise or insertion of counterfeit components.
Developer Screening
Require that the developer of defined system components be screened according to defined criteria.
Description
Require that the developer of defined system components be screened according to defined criteria to ensure trustworthiness and reduce the risk of malicious or compromised development activities.
Unsupported System Components
Replace system components when support is no longer available from the developer or vendor.
Description
Replace system components when support is no longer available from the developer or vendor. Provide documented justification and approval for the continued use of unsupported system components required to satisfy mission or business needs.
Specialization
Employ specialization techniques in design and development to minimize potential vulnerabilities.
Description
Employ defined specialization techniques in the design and development of defined system components to minimize potential vulnerabilities and reduce the attack surface of the system.
SC System and Communications Protection 47 controls
Controls for protecting information during transmission and at rest, establishing boundary defenses, implementing cryptographic protections, and ensuring system isolation.
Policy and Procedures
Develop, document, and disseminate system and communications protection policy and procedures.
Description
Develop, document, and disseminate system and communications protection policy and procedures that address purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance. Review and update the current policy and procedures on a defined frequency and following defined events.
Separation of System and User Functionality
Separate user functionality from system management functionality.
Description
Separate user functionality including user interface services from system management functionality to reduce the attack surface and prevent unauthorized access to administrative functions.
Security Function Isolation
Isolate security functions from nonsecurity functions.
Description
Isolate security functions from nonsecurity functions to minimize the attack surface and prevent unauthorized interference with security mechanisms.
Information in Shared System Resources
Prevent unauthorized and unintended information transfer via shared system resources.
Description
Prevent unauthorized and unintended information transfer via shared system resources by controlling access to shared memory, storage, and other resources that could be exploited for covert data exchange.
Denial-of-Service Protection
Protect against or limit the effects of denial-of-service attacks.
Description
Protect against or limit the effects of denial-of-service attacks by employing defined controls including monitoring, capacity planning, and redundancy measures.
Resource Availability
Protect the availability of resources by allocating resources by priority or quota.
Description
Protect the availability of resources by allocating defined resources by priority, quota, or other means to ensure critical system functions continue to operate under adverse conditions.
Boundary Protection
Monitor and control communications at external managed interfaces and key internal boundaries.
Description
Monitor and control communications at the external managed interfaces and at key internal boundaries, implement subnetworks for publicly accessible components, and connect to external networks only through managed interfaces consisting of boundary protection devices.
Transmission Confidentiality and Integrity
Protect the confidentiality and integrity of transmitted information.
Description
Protect the confidentiality and integrity of transmitted information using defined mechanisms such as encryption, digital signatures, and secure communication protocols.
Network Disconnect
Terminate network connections at session end or after a defined period of inactivity.
Description
Terminate the network connection associated with a communications session at the end of the session or after a defined time period of inactivity to reduce the window of opportunity for unauthorized access.
Trusted Path
Provide a trusted communications path between the user and security functions.
Description
Provide a trusted communications path between the user and defined security functions of the system that cannot be intercepted or compromised by untrusted processes.
Cryptographic Key Establishment and Management
Establish and manage cryptographic keys using defined key management methods.
Description
Establish and manage cryptographic keys using defined key management methods and requirements including generation, distribution, storage, access, rotation, revocation, and destruction of keys.
Cryptographic Protection
Determine cryptographic uses and implement defined types of cryptography for each use.
Description
Determine the cryptographic uses required and implement defined types of cryptography for each specified use in accordance with applicable laws, executive orders, directives, regulations, policies, standards, and guidelines.
Collaborative Computing Devices and Applications
Prohibit remote activation of collaborative computing devices and provide indication of use.
Description
Prohibit remote activation of collaborative computing devices and applications and provide an explicit indication of use to users physically present at the device to prevent unauthorized surveillance.
Transmission of Security and Privacy Attributes
Associate security and privacy attributes with information exchanged between systems.
Description
Associate defined security and privacy attributes with information exchanged between systems and between system components to enforce access control and data protection policies across organizational boundaries.
Public Key Infrastructure Certificates
Issue public key certificates under an organization-defined certificate policy.
Description
Issue public key certificates under an organization-defined certificate policy or obtain public key certificates from an approved service provider. Manage the certificate lifecycle including issuance, renewal, revocation, and validation.
Mobile Code
Define acceptable and unacceptable mobile code and establish usage restrictions.
Description
Define acceptable and unacceptable mobile code and mobile code technologies, establish usage restrictions and implementation guidance, and authorize and monitor the use of mobile code within the system.
Secure Name/Address Resolution Service (Authoritative Source)
Provide data origin and integrity artifacts with authoritative name resolution data.
Description
Provide additional data origin and data integrity artifacts along with authoritative name resolution data to enable receiving systems to verify the authenticity and integrity of resolution responses.
Secure Name/Address Resolution Service (Recursive or Caching Resolver)
Request and perform data origin authentication and integrity verification on resolution responses.
Description
Request and perform data origin authentication and data integrity verification on the name/address resolution responses the system receives from authoritative sources to protect against DNS spoofing and cache poisoning attacks.
Architecture and Provisioning for Name/Address Resolution Service
Ensure name/address resolution systems are fault-tolerant with internal/external role separation.
Description
Ensure the systems that collectively provide name/address resolution service are fault-tolerant and implement internal/external role separation to support resilient and secure DNS operations.
Session Authenticity
Protect the authenticity of communications sessions.
Description
Protect the authenticity of communications sessions to prevent man-in-the-middle and session hijacking attacks using mechanisms such as session tokens, mutual authentication, and encrypted channels.
Fail in Known State
Fail to a defined known system state in defined failure scenarios.
Description
Fail to a defined known system state in defined failure scenarios, preserving defined system state information in failure to support forensic analysis and recovery operations.
Thin Nodes
Employ minimal functionality and information storage on defined system components.
Description
Employ minimal functionality and information storage on defined system components to reduce the attack surface and limit the potential impact of a compromise.
Decoys
Employ decoys to detect and deflect potential cyber attacks against the system.
Description
Employ defined decoys such as honeypots, honeynets, and deception technologies to detect and deflect potential cyber attacks against the system and gather threat intelligence.
Platform-Independent Applications
Include platform-independent applications to enhance portability and reduce vendor dependence.
Description
Include within organizational systems defined platform-independent applications to enhance portability, reduce vendor dependence, and support interoperability across diverse computing environments.
Protection of Information at Rest
Protect the confidentiality and integrity of defined information at rest.
Description
Protect the confidentiality and integrity of defined information at rest using defined mechanisms such as encryption, access controls, and physical safeguards for storage media.
Heterogeneity
Employ a diverse set of information technologies to reduce vulnerability to common-mode threats.
Description
Employ a diverse set of information technologies for defined system components in the implementation of the system to reduce vulnerability to common-mode threats that exploit a single technology.
Concealment and Misdirection
Employ concealment and misdirection techniques to confuse and mislead adversaries.
Description
Employ defined concealment and misdirection techniques to confuse and mislead adversaries, making it more difficult for them to identify and target critical system components and data.
Covert Channel Analysis
Perform covert channel analysis to identify potential avenues for covert channels.
Description
Perform a covert channel analysis to identify those aspects of system communications that are potential avenues for covert storage and timing channels, and implement measures to limit their bandwidth and detectability.
System Partitioning
Partition the system into components residing in separate physical or logical domains.
Description
Partition the system into defined system components residing in separate physical or logical domains or environments based on defined circumstances to limit the impact of security incidents and contain adversary lateral movement.
Non-Modifiable Executable Programs
Require system components to load and execute from hardware-enforced, read-only media.
Description
Require that defined system components load and execute the operating environment from hardware-enforced, read-only media to prevent unauthorized modification of executable programs.
External Malicious Code Identification
Include components that proactively seek to identify malicious websites and network-based attacks.
Description
Include system components that proactively seek to identify malicious websites, malicious code, and network-based attacks against organizational systems using threat intelligence and automated scanning.
Distributed Processing and Storage
Distribute processing and storage across multiple physical locations.
Description
Distribute defined processing and storage across multiple physical locations to reduce the impact of a single point of failure and improve resilience against targeted attacks.
Out-of-Band Channels
Employ out-of-band channels for physical delivery or electronic transmission of defined information.
Description
Employ defined out-of-band channels for the physical delivery or electronic transmission of defined information, system components, or devices to reduce the risk of interception or compromise through primary communication channels.
Operations Security
Employ operations security controls to protect key organizational information.
Description
Employ defined operations security controls to protect key organizational information throughout the system development life cycle and prevent adversaries from exploiting sensitive operational details.
Process Isolation
Maintain a separate execution domain for each executing system process.
Description
Maintain a separate execution domain for each executing system process to prevent unauthorized access and interference between processes and protect against privilege escalation attacks.
Wireless Link Protection
Protect external and internal wireless links from signal parameter attacks.
Description
Protect external and internal wireless links from defined types of signal parameter attacks using defined methods such as encryption, frequency hopping, and spread spectrum technologies.
Port and I/O Device Access
Physically or logically disable or remove defined external ports or I/O devices.
Description
Physically or logically disable or remove defined external ports or input/output devices on defined systems or system components to prevent unauthorized data transfer and reduce the attack surface.
Sensor Capability and Data
Prohibit or restrict the use of devices possessing environmental sensing capabilities.
Description
Prohibit the use of devices possessing defined environmental sensing capabilities in defined facilities, areas, or systems, or restrict their use under specified conditions to prevent unauthorized surveillance and data collection.
Usage Restrictions
Establish usage restrictions and implementation guidelines for defined system components.
Description
Establish usage restrictions and implementation guidelines for defined system components based on the potential to cause damage to the system if used maliciously, and enforce compliance through technical and procedural controls.
Detonation Chambers
Employ a detonation chamber capability to automatically identify malicious code.
Description
Employ a detonation chamber capability within defined systems to automatically identify malicious code by executing code in a controlled environment and analyzing its behavior before allowing execution in production.
System Time Synchronization
Synchronize system clocks within and between systems and system components.
Description
Synchronize system clocks within and between systems and system components using defined time sources and mechanisms to support accurate audit logging, event correlation, and forensic analysis.
Cross Domain Policy Enforcement
Implement a policy enforcement mechanism between defined security domains.
Description
Implement a policy enforcement mechanism between defined security domains for the transfer of data between domains, ensuring that data flows comply with organizational security policies and classification requirements.
Alternate Communications Paths
Establish alternate communications paths for system operations and organizational command and control.
Description
Establish defined alternate communications paths for system operations organizational command and control to support resilience and ensure continuity of operations during disruptions to primary communication channels.
Sensor Relocation
Relocate sensors and monitoring capabilities to reduce adversary targeting.
Description
Relocate defined sensors and monitoring capabilities to a defined frequency to reduce adversary targeting and make it more difficult for adversaries to identify and evade detection mechanisms.
Hardware-Enforced Separation and Policy Enforcement
Implement hardware-based mechanisms for process separation and policy enforcement.
Description
Implement hardware-based mechanisms to provide process separation and policy enforcement that cannot be bypassed by software-only attacks, ensuring strong isolation between security domains.
Software-Enforced Separation and Policy Enforcement
Implement software-based mechanisms for process separation and policy enforcement.
Description
Implement software-based mechanisms to provide process separation and policy enforcement using virtualization, containerization, and other software isolation techniques to maintain security boundaries.
Hardware-Based Protection
Implement hardware-based mechanisms to protect from firmware corruption and support tamper resistance.
Description
Implement hardware-based mechanisms to protect the system from firmware corruption and support tamper resistance and detection, ensuring the integrity of low-level system components that underpin all higher-level security functions.
SI System and Information Integrity 22 controls
Controls for identifying, reporting, and correcting system flaws, protecting against malicious code, monitoring system events, and maintaining software and information integrity.
Policy and Procedures
Develop, document, and disseminate system and information integrity policy and procedures.
Description
Develop, document, and disseminate system and information integrity policy and procedures that address purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance. Review and update the current policy and procedures on a defined frequency and following defined events.
Flaw Remediation
Identify, report, and correct system flaws; test and install security-relevant updates.
Description
Identify, report, and correct system flaws, test updates and patches before installing, and install security-relevant software and firmware updates within a defined time period of release to maintain system integrity.
Malicious Code Protection
Implement malicious code protection mechanisms at system entry and exit points.
Description
Implement signature and non-signature-based malicious code protection mechanisms at system entry and exit points, update mechanisms as new releases become available, and address false positives to maintain system availability.
System Monitoring
Monitor the system to detect attacks, indicators of potential attacks, and unauthorized use.
Description
Monitor the system to detect attacks and indicators of potential attacks, identify unauthorized use, and deploy monitoring devices strategically within the system to collect essential information and at ad hoc locations to track specific types of transactions.
Security Alerts, Advisories, and Directives
Receive and disseminate system security alerts, advisories, and directives.
Description
Receive system security alerts, advisories, and directives from defined external organizations on an ongoing basis, generate internal alerts and advisories, and disseminate to defined personnel or roles to maintain security awareness.
Security and Privacy Function Verification
Verify the correct operation of defined security and privacy functions.
Description
Verify the correct operation of defined security and privacy functions, perform verification at defined states, notify defined personnel of failed tests, and take defined actions when anomalies are discovered to ensure continuous protection.
Software, Firmware, and Information Integrity
Employ integrity verification tools to detect unauthorized changes.
Description
Employ integrity verification tools to detect unauthorized changes to defined software, firmware, and information, and take appropriate actions when discrepancies are identified to restore system integrity.
Spam Protection
Employ spam protection mechanisms at system entry and exit points.
Description
Employ spam protection mechanisms at system entry and exit points to detect and act on unsolicited messages transported by electronic mail, web browsers, or other common means.
Information Input Validation
Check the validity of defined information inputs to the system.
Description
Check the validity of defined information inputs to the system to verify that inputs match specified formats and content, preventing injection attacks and malformed data from compromising system integrity.
Error Handling
Generate error messages that provide corrective information without revealing exploitable details.
Description
Generate error messages that provide information necessary for corrective actions without revealing information that could be exploited by adversaries, such as stack traces, system paths, or internal configuration details.
Information Management and Retention
Manage and retain information in accordance with applicable laws and policies.
Description
Manage and retain information within the system and information output from the system in accordance with applicable laws, executive orders, directives, regulations, policies, standards, guidelines, and operational requirements.
Predictable Failure Prevention
Determine mean time to failure for defined system components and provide substitutes.
Description
Determine mean time to failure for defined system components in specific environments and provide substitute components and transfer responsibilities to ensure system continuity when failure thresholds are reached.
Non-Persistence
Implement non-persistent system components initiated in a known state and terminated periodically.
Description
Implement non-persistent defined system components and services that are initiated in a known state and terminated on a defined frequency or at the end of a user session to limit the persistence of adversary footholds.
Information Output Filtering
Validate information output from defined software programs for consistency.
Description
Validate information output from defined software programs to ensure that the information is consistent with expected content and format, preventing data leakage and corruption of downstream processes.
Memory Protection
Implement controls to protect system memory from unauthorized code execution.
Description
Implement defined controls such as data execution prevention, address space layout randomization, and stack protection to protect the system memory from unauthorized code execution and buffer overflow attacks.
Fail-Safe Procedures
Implement fail-safe procedures when defined failure conditions occur.
Description
Implement defined fail-safe procedures when defined failure conditions occur to ensure the system fails in a safe and secure state that does not compromise security or expose sensitive information.
Personally Identifiable Information Quality Operations
Check the accuracy, relevance, timeliness, and completeness of PII.
Description
Check the accuracy, relevance, timeliness, and completeness of personally identifiable information across the information life cycle and take defined actions to correct or minimize the use of inaccurate or outdated PII.
De-Identification
Remove PII elements from datasets prior to release using de-identification techniques.
Description
Remove personally identifiable information elements from datasets prior to release by applying defined de-identification techniques and methods to prevent the re-identification of individuals from released data.
Tainting
Embed data or capabilities in systems to identify malicious use or exfiltration.
Description
Embed data or capabilities in defined systems or system components as a means for identifying malicious use, exfiltration, or unauthorized access through digital watermarks, canary tokens, or other tainting mechanisms.
Information Refresh
Refresh defined information at defined frequencies or generate on demand.
Description
Refresh defined information at defined frequencies or generate the information on demand to ensure freshness and reduce the risk of decisions based on stale or corrupted data.
Information Diversity
Employ alternative information sources to reduce single-source dependencies.
Description
Employ defined alternative information sources for defined essential information to reduce the risk of information corruption or single-source dependencies that could compromise decision-making.
Information Fragmentation
Fragment information so only authorized parties can reconstruct it.
Description
Based on defined circumstances, fragment information in a manner that only authorized parties can reconstruct the information, providing an additional layer of protection against unauthorized access and data breaches.
SR Supply Chain Risk Management 12 controls
Controls for managing supply chain risks throughout the system development life cycle, including acquisition strategies, supplier assessments, and component authenticity.
Policy and Procedures
Develop, document, and disseminate supply chain risk management policy and procedures.
Description
Develop, document, and disseminate supply chain risk management policy and procedures that address purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance. Review and update the current policy and procedures on a defined frequency and following defined events.
Supply Chain Risk Management Plan
Develop a plan for managing supply chain risks associated with system development and acquisition.
Description
Develop a plan for managing supply chain risks associated with the development, acquisition, maintenance, and disposal of systems, components, and services. Review and update the plan on a defined frequency.
Supply Chain Controls and Processes
Establish a process for identifying and addressing weaknesses in supply chain elements.
Description
Establish and apply a process for identifying and addressing weaknesses or deficiencies in the supply chain elements and processes used in the development, acquisition, and maintenance of the system.
Provenance
Document, monitor, and maintain valid provenance of systems and components.
Description
Document, monitor, and maintain valid provenance of defined systems, system components, and associated data to prevent counterfeiting and unauthorized modification throughout the supply chain.
Acquisition Strategies, Tools, and Methods
Employ acquisition strategies and procurement methods to protect against supply chain risks.
Description
Employ defined acquisition strategies, contract tools, and procurement methods to protect against, identify, and mitigate supply chain risks associated with the acquisition of systems, components, and services.
Supplier Assessments and Reviews
Assess and review supply chain practices of suppliers and developers.
Description
Assess and review the supply chain practices and components of suppliers and developers associated with the system on a defined frequency to identify and mitigate supply chain risks before they impact the organization.
Supply Chain Operations Security
Employ operations security controls to protect supply chain information.
Description
Employ defined operations security controls to protect supply chain information and reduce the vulnerability of the supply chain to adversary exploitation and intelligence gathering.
Notification Agreements
Establish agreements for notification of supply chain compromises.
Description
Establish agreements and procedures with entities involved in the supply chain for notification of supply chain compromises and results of assessments or audits to enable timely response to supply chain incidents.
Tamper Resistance and Detection
Implement a tamper protection program for the system and associated environments.
Description
Implement a tamper protection program for the system, system components, and associated development or manufacturing environments to detect and prevent unauthorized physical and logical modifications.
Inspection of Systems or Components
Inspect defined systems or components on a defined frequency to detect tampering.
Description
Inspect defined systems or system components on a defined frequency to detect tampering, unauthorized modifications, or counterfeit components that may have been introduced through the supply chain.
Component Authenticity
Develop and implement anti-counterfeit policies and procedures.
Description
Develop and implement anti-counterfeit policies and procedures that include provisions for the detection and prevention of counterfeit components through verification of authenticity and provenance.
Component Disposal
Dispose of data, documentation, tools, and system components using defined techniques.
Description
Dispose of defined data, documentation, tools, and system components using defined techniques and methods to prevent unauthorized recovery and ensure that sensitive information cannot be reconstructed from discarded materials.
No controls match your search. Try a different keyword or clear the filter.
Need Help Implementing These Controls?
TeamThru provides hands-on support for NIST 800-53 control implementation, documentation, continuous monitoring, and ATO acceleration across federal and enterprise environments.
AI answers from TeamThru’s site. Check important details with us.