|
is related to
|
Security, Compliance & Resilience Program (SCRP) |
|
is related to
|
Steering Committee & Program Oversight |
|
is related to
|
Status Reporting To Governing Body |
|
is related to
|
Commitment To Continual Improvements |
|
is related to
|
Publishing Security, Compliance & Resilience Documentation |
|
is related to
|
Exception Management |
|
is related to
|
Periodic Review & Update of Security, Compliance & Resilience Program |
|
is related to
|
Stakeholder Accountability Structure |
|
is related to
|
Authoritative Chain of Command |
|
is related to
|
Measures of Performance |
|
is related to
|
Key Performance Indicators (KPIs) |
|
is related to
|
Key Risk Indicators (KRIs) |
|
is related to
|
Contacts With Authorities |
|
is related to
|
Contacts With Groups & Associations |
|
is related to
|
Defining Business Context & Mission |
|
is related to
|
Define Control Objectives |
|
is related to
|
Data Governance |
|
is related to
|
Purpose Validation |
|
is related to
|
Forced Technology Transfer (FTT) |
|
is related to
|
State-Sponsored Espionage |
|
is related to
|
Business As Usual (BAU) Security, Compliance & Resilience Practices |
|
is related to
|
Operationalizing Security, Compliance & Resilience Capabilities |
|
is related to
|
Select Controls |
|
is related to
|
Implement Controls |
|
is related to
|
Assess Controls |
|
is related to
|
Authorize Technology Assets, Applications and/or Services (TAAS) |
|
is related to
|
Monitor Controls |
|
is related to
|
Materiality Determination |
|
is related to
|
Material Risks |
|
is related to
|
Material Threats |
|
is related to
|
Security, Compliance & Resilience Status Reporting |
|
is related to
|
Quality Management System (QMS) |
|
is related to
|
Assurance |
|
is related to
|
Assurance Levels (AL) |
|
is related to
|
Assessment Objectives (AO) |
|
is related to
|
Mergers, Acquisitions & Divestitures (MA&D) |
|
is related to
|
Virtual Data Room (VDR) |
|
is related to
|
Artificial Intelligence (AI) & Autonomous Technologies Governance |
|
is related to
|
AI & Autonomous Technologies-Related Legal Requirements Definition |
|
is related to
|
Trustworthy AI & Autonomous Technologies |
|
is related to
|
AI & Autonomous Technologies Value Sustainment |
|
is related to
|
AI Model & Agent Inventory & Lifecycle Management |
|
is related to
|
Situational Awareness of AI & Autonomous Technologies |
|
is related to
|
AI & Autonomous Technologies Risk Mapping |
|
is related to
|
AI & Autonomous Technologies Internal Controls |
|
is related to
|
Adequate Protections For AI & Autonomous Technologies |
|
is related to
|
AI Threat Modeling & Risk Assessment |
|
is related to
|
AI & Autonomous Technologies Context Definition |
|
is related to
|
AI & Autonomous Technologies Mission and Goals Definition |
|
is related to
|
Model & AI Agent Documentation |
|
is related to
|
AI & Autonomous Technologies Business Case |
|
is related to
|
AI & Autonomous Technologies Potential Benefits Analysis |
|
is related to
|
AI & Autonomous Technologies Potential Costs Analysis |
|
is related to
|
AI & Autonomous Technologies Targeted Application Scope |
|
is related to
|
AI & Autonomous Technologies Cost / Benefit Mapping |
|
is related to
|
AI & Autonomous Technologies Fairness & Bias |
|
is related to
|
AI & Autonomous Technologies Risk Management Decisions |
|
is related to
|
AI & Autonomous Technologies Impact Assessment |
|
is related to
|
AI & Autonomous Technologies Likelihood & Impact Risk Analysis |
|
is related to
|
AI & Autonomous Technologies Continuous Improvements |
|
is related to
|
Assigned Responsibilities for AI & Autonomous Technologies |
|
is related to
|
AI & Autonomous Technologies Risk Profiling |
|
is related to
|
AI & Autonomous Technologies High Risk Designations |
|
is related to
|
Artificial Intelligence Test, Evaluation, Validation & Verification (AI TEVV) |
|
is related to
|
AI TEVV Trustworthiness Assessment |
|
is related to
|
AI TEVV Tools |
|
is related to
|
AI TEVV Trustworthiness Demonstration |
|
is related to
|
AI TEVV Safety Demonstration |
|
is related to
|
AI TEVV Security & Resiliency Assessment |
|
is related to
|
AI TEVV Transparency & Accountability Assessment |
|
is related to
|
AI TEVV Privacy Assessment |
|
is related to
|
AI TEVV Fairness & Bias Assessment |
|
is related to
|
AI & Autonomous Technologies Model Validation |
|
is related to
|
AI TEVV Results Evaluation |
|
is related to
|
AI TEVV Effectiveness |
|
is related to
|
AI TEVV Comparable Deployment Settings |
|
is related to
|
AI TEVV Post-Deployment Monitoring |
|
is related to
|
Updating AI & Autonomous Technologies |
|
is related to
|
AI TEVV Reporting |
|
is related to
|
AI TEVV Empirically Validated Methods |
|
is related to
|
AI TEVV Benchmarking Content Provenance |
|
is related to
|
AI TEVV Model Collapse Mitigations |
|
is related to
|
AI TEVV Third-Party Risk Management |
|
is related to
|
Robust Stakeholder Engagement for AI & Autonomous Technologies |
|
is related to
|
AI & Autonomous Technologies Stakeholder Feedback Integration |
|
is related to
|
AI & Autonomous Technologies Ongoing Assessments |
|
is related to
|
AI & Autonomous Technologies End User Feedback |
|
is related to
|
AI & Autonomous Technologies Incident & Error Reporting |
|
is related to
|
AI & Autonomous Technologies Intellectual Property Infringement Protections |
|
is related to
|
Data Source Identification |
|
is related to
|
Data Source Lineage & Origin Disclosure |
|
is related to
|
Digital Content Modification Logging |
|
is related to
|
AI & Autonomous Technologies Requirements Definitions |
|
is related to
|
AI & Autonomous Technologies Implementation Tasks Definition |
|
is related to
|
AI & Autonomous Technologies Knowledge Limits |
|
is related to
|
AI & Autonomous Technologies Viability Decisions |
|
is related to
|
AI & Autonomous Technologies Negative Residual Risks |
|
is related to
|
Responsibility To Supersede, Deactivate and/or Disengage AI & Autonomous Technologies |
|
is related to
|
AI & Autonomous Technologies Measurement Approaches |
|
is related to
|
Measuring AI & Autonomous Technologies Effectiveness |
|
is related to
|
Unmeasurable AI & Autonomous Technologies Risks |
|
is related to
|
Efficacy of AI & Autonomous Technologies Measurement |
|
is related to
|
AI & Autonomous Technologies Performance Changes |
|
is related to
|
Pre-Trained AI & Autonomous Technologies Models |
|
is related to
|
AI & Autonomous Technologies Event Logging |
|
is related to
|
Serious Incident Reporting For AI & Autonomous Technologies |
|
is related to
|
Serious Incident Root Cause Analysis (RCA) For AI & Autonomous Technologies |
|
is related to
|
Anomaly Detection & Human Oversight |
|
is related to
|
Human-in-the-Loop & Escalation |
|
is related to
|
Emergent Behavior & Collusion Protections |
|
is related to
|
Multi-Agent Trust & Communication Validation |
|
is related to
|
AI & Autonomous Technologies Harm Prevention |
|
is related to
|
AI & Autonomous Technologies Human Subject Protections |
|
is related to
|
AI & Autonomous Technologies Environmental Impact & Sustainability |
|
is related to
|
Novel Risk Assessment Methods & Technologies |
|
is related to
|
Fine Tuning Risk Mitigation |
|
is related to
|
AI & Autonomous Technologies Risk Tracking Approaches |
|
is related to
|
AI & Autonomous Technologies Risk Response |
|
is related to
|
AI & Autonomous Technologies Conformity |
|
is related to
|
Manipulative or Deceptive Techniques |
|
is related to
|
Materially Distorting Behaviors |
|
is related to
|
Social Scoring |
|
is related to
|
Detrimental or Unfavorable Treatment |
|
is related to
|
Risk and Criminal Profiling |
|
is related to
|
Populating Facial Recognition Databases |
|
is related to
|
Emotion Inference |
|
is related to
|
Biometric Categorization |
|
is related to
|
AI & Autonomous Technologies Development Practices |
|
is related to
|
AI & Autonomous Technologies Transparency |
|
is related to
|
AI & Autonomous Technologies Implementation Documentation |
|
is related to
|
AI & Autonomous Technologies Human Domain Knowledge Reliance |
|
is related to
|
AI & Autonomous Technologies Registration |
|
is related to
|
AI & Autonomous Technologies Deployment |
|
is related to
|
AI & Autonomous Technologies Human Oversight |
|
is related to
|
AI & Autonomous Technologies Oversight Measures |
|
is related to
|
AI & Autonomous Technologies Separate Verification |
|
is related to
|
AI & Autonomous Technologies Oversight Functions Competency |
|
is related to
|
AI & Autonomous Technologies Data Relevance |
|
is related to
|
AI & Autonomous Technologies Irregularity Reporting |
|
is related to
|
AI & Autonomous Technologies Use Notification To Employees |
|
is related to
|
AI & Autonomous Technologies Use Notification To Users |
|
is related to
|
Real World Testing of AI & Autonomous Technologies |
|
is related to
|
AI & Autonomous Technologies System Value Chain |
|
is related to
|
AI & Autonomous Technologies System Value Chain Fallbacks |
|
is related to
|
AI & Autonomous Technologies Testing Techniques |
|
is related to
|
Generative Artificial Intelligence (GAI) Identification |
|
is related to
|
AI & Autonomous Technologies Capabilities Testing |
|
is related to
|
Real-World Testing |
|
is related to
|
Documenting Testing Guidance |
|
is related to
|
AI & Autonomous Technologies Output Filtering |
|
is related to
|
Human Moderation |
|
is related to
|
AI Model Resilience |
|
is related to
|
Model Pollution |
|
is related to
|
Cascading Hallucination Defense |
|
is related to
|
Resource Exhaustion & DoS Resilience |
|
is related to
|
AI Agent Governance |
|
is related to
|
Adversarial & Red Team Testing |
|
is related to
|
Behavioral Drift Detection |
|
is related to
|
AI Agent Action Authentication & Authorization |
|
is related to
|
Explainability |
|
is related to
|
Ethics, Fairness & Bias Detection |
|
is related to
|
Human-in-the-Loop Workload & Manipulation |
|
is related to
|
Robotic Process Automation (RPA) |
|
is related to
|
Business Process Task Enumeration |
|
is related to
|
Asset Governance |
|
is related to
|
Asset-Service Dependencies |
|
is related to
|
Stakeholder Identification & Involvement |
|
is related to
|
Standardized Naming Convention |
|
is related to
|
Approved Technologies |
|
is related to
|
Authorized To Connect |
|
is related to
|
Asset Inventories |
|
is related to
|
Updates During Installations / Removals |
|
is related to
|
Component Duplication Avoidance |
|
is related to
|
Approved Baseline Deviations |
|
is related to
|
Data Action Mapping |
|
is related to
|
Asset Ownership Assignment |
|
is related to
|
Accountability Information |
|
is related to
|
Provenance |
|
is related to
|
Network Diagrams & Data Flow Diagrams (DFDs) |
|
is related to
|
Asset Scope Classification |
|
is related to
|
Control Applicability Boundary Graphical Representation |
|
is related to
|
Compliance-Specific Asset Identification |
|
is related to
|
Management Approval For External Media Transfer |
|
is related to
|
Unattended End-User Equipment |
|
is related to
|
Asset Storage In Automobiles |
|
is related to
|
Physical Tampering Detection |
|
is related to
|
Secure Disposal, Destruction or Re-Use of Equipment |
|
is related to
|
Return of Assets |
|
is related to
|
Removal of Assets |
|
is related to
|
Technology Asset Inspections |
|
is related to
|
Bring Your Own Device (BYOD) Usage |
|
is related to
|
Prohibited Equipment & Services |
|
is related to
|
Telecommunications Equipment |
|
is related to
|
System Administrative Processes |
|
is related to
|
Decommissioning |
|
is related to
|
Asset Categorization |
|
is related to
|
Categorize Artificial Intelligence (AI)-Related Technologies |
|
is related to
|
High-Risk Asset Categorization |
|
is related to
|
Asset Attributes |
|
is related to
|
Business Continuity Management System (BCMS) |
|
is related to
|
Coordinate with Related Plans |
|
is related to
|
Coordinate With External Service Providers |
|
is related to
|
Transfer to Alternate Processing / Storage Site |
|
is related to
|
Recovery Time / Point Objectives (RTO / RPO) |
|
is related to
|
Recovery Operations Criteria |
|
is related to
|
Recovery Operations Communications |
|
is related to
|
Business Continuity & Disaster Recovery (BC/DR) Plans |
|
is related to
|
Identify Critical Assets |
|
is related to
|
Resume All Missions & Business Functions |
|
is related to
|
Continue Essential Mission & Business Functions |
|
is related to
|
Resume Essential Missions & Business Functions |
|
is related to
|
Data Storage Location Reviews |
|
is related to
|
Simulated Events |
|
is related to
|
Contingency Plan Testing & Exercises |
|
is related to
|
Coordinated Testing with Related Plans |
|
is related to
|
Contingency Plan Root Cause Analysis (RCA) & Lessons Learned |
|
is related to
|
Ongoing Contingency Planning |
|
is related to
|
Contingency Planning Components |
|
is related to
|
Contingency Plan Update Notifications |
|
is related to
|
Alternative Security Measures |
|
is related to
|
Inability to Return to Primary Site |
|
is related to
|
Provider Contingency Plan |
|
is related to
|
Testing for Reliability & Integrity |
|
is related to
|
Separate Storage for Critical Information |
|
is related to
|
Transfer to Alternate Storage Site |
|
is related to
|
Dual Authorization For Backup Media Destruction |
|
is related to
|
Isolated Recovery Environment |
|
is related to
|
AI & Autonomous Technologies Incidents |
|
is related to
|
Capacity & Performance Management |
|
is related to
|
Capacity Planning |
|
is related to
|
Change Management Program |
|
is related to
|
Configuration Change Control |
|
is related to
|
Prohibition Of Changes |
|
is related to
|
Test, Validate & Document Changes |
|
is related to
|
Security, Compliance & Resilience Representative for Asset Lifecycle Changes |
|
is related to
|
Security Impact Analysis for Changes |
|
is related to
|
Access Restriction For Change |
|
is related to
|
Dual Authorization for Change |
|
is related to
|
Stakeholder Notification of Changes |
|
is related to
|
Control Functionality Verification |
|
is related to
|
Report Verification Results |
|
is related to
|
Emergency Changes |
|
is related to
|
Documenting Emergency Changes |
|
is related to
|
Dual Approval For High-Impact Environments |
|
is related to
|
Cloud Services |
|
is related to
|
Cloud Infrastructure Onboarding |
|
is related to
|
Cloud Infrastructure Offboarding |
|
is related to
|
Cloud Security Architecture |
|
is related to
|
API Gateway |
|
is related to
|
Customer Responsibility Matrix (CRM) |
|
is related to
|
Multi-Tenant Event Logging Capabilities |
|
is related to
|
Multi-Tenant Forensics Capabilities |
|
is related to
|
Multi-Tenant Incident Response Capabilities |
|
is related to
|
Geolocation Requirements for Processing, Storage and Service Locations |
|
is related to
|
Authorized Individuals For Hosted Assets, Applications & Services |
|
is related to
|
Sensitive / Regulated Data On Hosted Assets, Applications & Services |
|
is related to
|
Statutory, Regulatory & Contractual Compliance |
|
is related to
|
Non-Compliance Oversight |
|
is related to
|
Compliance Scope |
|
is related to
|
Ability To Demonstrate Conformity |
|
is related to
|
Conformity Assessment |
|
is related to
|
Declaration of Conformity |
|
is related to
|
Security, Compliance & Resilience Controls Oversight |
|
is related to
|
Internal Audit Function |
|
is related to
|
Periodic Audits |
|
is related to
|
Corrective Action |
|
is related to
|
Security, Compliance & Resilience Assessments |
|
is related to
|
Independent Assessors |
|
is related to
|
Functional Review Of Security, Compliance & Resilience Controls |
|
is related to
|
Assessor Access |
|
is related to
|
Assessment Methods |
|
is related to
|
Assessment Rigor |
|
is related to
|
Evidence Request List (ERL) |
|
is related to
|
Evidence Sampling |
|
is related to
|
Audit Activities |
|
is related to
|
Legal Assessment of Investigative Inquires |
|
is related to
|
Investigation Request Notifications |
|
is related to
|
Investigation Access Restrictions |
|
is related to
|
Government Surveillance |
|
is related to
|
Grievances |
|
is related to
|
Grievance Response |
|
is related to
|
Localized Representation |
|
is related to
|
Representative Powers |
|
is related to
|
Control Reciprocity |
|
is related to
|
Control Inheritance |
|
is related to
|
Dual Use Technology |
|
is related to
|
USML or CCL Identification |
|
is related to
|
Export-Controlled Access Restrictions |
|
is related to
|
Export Activities Documentation |
|
is related to
|
Statement of Applicability (SOA) |
|
is related to
|
Work Products |
|
is related to
|
Defensible Evidence of Due Diligence |
|
is related to
|
Defensible Evidence of Due Care |
|
is related to
|
Configuration Management Program |
|
is related to
|
Assignment of Responsibility |
|
is related to
|
Secure Baseline Configurations |
|
is related to
|
Reviews & Updates |
|
is related to
|
Retention Of Previous Configurations |
|
is related to
|
Development & Test Environment Configurations |
|
is related to
|
Approved Configuration Deviations |
|
is related to
|
Respond To Unauthorized Changes |
|
is related to
|
Periodic Review |
|
is related to
|
Security Event Monitoring |
|
is related to
|
Inventory of Technology Asset Event Logging |
|
is related to
|
Centralized Management of Event Log Content |
|
is related to
|
Response To Event Log Processing Failures |
|
is related to
|
Monitoring For Information Disclosure |
|
is related to
|
Sharing of Event Logs |
|
is related to
|
Export-Controlled Cryptography |
|
is related to
|
Cryptographic Cipher Suites and Protocols Inventory |
|
is related to
|
Defining Access Authorizations for Sensitive / Regulated Data |
|
is related to
|
Data Subject Attribute Associations |
|
is related to
|
Audit Changes |
|
is related to
|
Dual Authorization for Sensitive Data Destruction |
|
is related to
|
Information Sharing |
|
is related to
|
Transfer Authorizations |
|
is related to
|
Statistical Disclosure Control |
|
is related to
|
Transfer Activity Limits |
|
is related to
|
Embedded Technology Reviews |
|
is related to
|
Operating Environment Certification |
|
is related to
|
Safety Assessment |
|
is related to
|
Governing Access Restriction for Change |
|
is related to
|
Documented Protection Measures |
|
is related to
|
Malware Protection Mechanism Testing |
|
is related to
|
Evolving Malware Threats |
|
is related to
|
Human Resources Security Management |
|
is related to
|
Onboarding, Transferring & Offboarding Personnel |
|
is related to
|
Users With Elevated Privileges |
|
is related to
|
Probationary Periods |
|
is related to
|
Updating Disciplinary Processes |
|
is related to
|
Preventative Access Restriction |
|
is related to
|
Identify Critical Skills & Gaps |
|
is related to
|
Remediate Identified Skills Deficiencies |
|
is related to
|
Identify Vital Security, Compliance & Resilience Staff |
|
is related to
|
Establish Redundancy for Vital Security, Compliance & Resilience Staff |
|
is related to
|
Perform Succession Planning |
|
is related to
|
Identifying Authorized Work Locations |
|
is related to
|
Communicating Authorized Work Locations |
|
is related to
|
Reporting Suspicious Activities |
|
is related to
|
User & Service Account Inventories |
|
is related to
|
Events Requiring Authenticator Change |
|
is related to
|
Periodic Review of Account Privileges |
|
is related to
|
Credential Sharing |
|
is related to
|
Auditing Use of Privileged Functions |
|
is related to
|
Identity Proofing (Identity Verification) |
|
is related to
|
Management Approval For New or Changed Accounts |
|
is related to
|
Identity Evidence |
|
is related to
|
Identity Evidence Validation & Verification |
|
is related to
|
In-Person Validation & Verification |
|
is related to
|
Address Confirmation |
|
is related to
|
Incident Response Operations |
|
is related to
|
Incident Handling |
|
is related to
|
Insider Threat Response Capability |
|
is related to
|
Incident Classification & Prioritization |
|
is related to
|
Correlation with External Organizations |
|
is related to
|
Indicators of Compromise (IOC) |
|
is related to
|
Incident Response Plan (IRP) |
|
is related to
|
Data Breach |
|
is related to
|
IRP Update |
|
is related to
|
Continuous Incident Response Improvements |
|
is related to
|
Incident Response Training |
|
is related to
|
Simulated Incidents |
|
is related to
|
Incident Response Testing |
|
is related to
|
Coordination with Related Plans |
|
is related to
|
Integrated Security Incident Response Team (ISIRT) |
|
is related to
|
Situational Awareness For Incidents |
|
is related to
|
Recurring Incident Analysis |
|
is related to
|
Incident Tracking Repository |
|
is related to
|
Incident Pattern Analysis |
|
is related to
|
Incident Stakeholder Reporting |
|
is related to
|
Cyber Incident Reporting for Sensitive / Regulated Data |
|
is related to
|
Vulnerabilities Related To Incidents |
|
is related to
|
Supply Chain Coordination |
|
is related to
|
Serious Incident Reporting |
|
is related to
|
Incident Reporting Assistance |
|
is related to
|
Coordination With External Providers |
|
is related to
|
Sensitive / Regulated Data Spill Response |
|
is related to
|
Sensitive / Regulated Data Spill Responsible Personnel |
|
is related to
|
Sensitive / Regulated Data Spill Training |
|
is related to
|
Post-Sensitive / Regulated Data Spill Operations |
|
is related to
|
Sensitive / Regulated Data Exposure to Unauthorized Personnel |
|
is related to
|
Root Cause Analysis (RCA) & Lessons Learned |
|
is related to
|
Regulatory & Law Enforcement Contacts |
|
is related to
|
Public Relations & Reputation Repair |
|
is related to
|
Information Assurance (IA) Operations |
|
is related to
|
Assessment Boundaries |
|
is related to
|
Assessments |
|
is related to
|
Assessor Independence |
|
is related to
|
Specialized Assessments |
|
is related to
|
Third-Party Assessment Reciprocity |
|
is related to
|
Security Assessment Report (SAR) |
|
is related to
|
Applied Security, Compliance and Resilience Controls Documentation |
|
is related to
|
Plan / Coordinate with Other Organizational Entities |
|
is related to
|
Adequate Security for Sensitive / Regulated Data In Support of Contracts |
|
is related to
|
Threat Analysis & Flaw Remediation During Development |
|
is related to
|
Capabilities Deficiency Tracking |
|
is related to
|
Technical Verification |
|
is related to
|
Security Authorization |
|
is related to
|
Maintenance Operations |
|
is related to
|
Controlled Maintenance |
|
is related to
|
Timely Maintenance |
|
is related to
|
Preventative Maintenance |
|
is related to
|
Predictive Maintenance |
|
is related to
|
Maintenance Tools |
|
is related to
|
Inspect Media |
|
is related to
|
Prevent Unauthorized Removal |
|
is related to
|
Remote Maintenance |
|
is related to
|
Auditing Remote Maintenance |
|
is related to
|
Remote Maintenance Notifications |
|
is related to
|
Remote Maintenance Pre-Approval |
|
is related to
|
Remote Maintenance Comparable Security & Sanitization |
|
is related to
|
Authorized Maintenance Personnel |
|
is related to
|
Non-System Related Maintenance |
|
is related to
|
Maintain Configuration Control During Maintenance |
|
is related to
|
Field Maintenance |
|
is related to
|
Off-Site Maintenance |
|
is related to
|
Maintenance Validation |
|
is related to
|
Maintenance Monitoring |
|
is related to
|
External Telecommunications Services |
|
is related to
|
Human Reviews |
|
is related to
|
Interconnection Security Agreements (ISAs) |
|
is related to
|
Work From Anywhere (WFA) - Telecommuting Security |
|
is related to
|
Third-Party Remote Access Governance |
|
is related to
|
User Threat Reporting |
|
is related to
|
Physical & Environmental Protections |
|
is related to
|
Physical Security Plan (PSP) |
|
is related to
|
Zone-Based Physical Security |
|
is related to
|
Physical Access Authorizations |
|
is related to
|
Dual Authorization for Physical Access |
|
is related to
|
Monitoring Physical Access |
|
is related to
|
Monitoring Physical Access To Critical Systems |
|
is related to
|
Monitoring with Alarms / Notifications |
|
is related to
|
Data Privacy Program |
|
is related to
|
Privacy Act Statements |
|
is related to
|
Dissemination of Data Privacy Program Information |
|
is related to
|
Binding Corporate Rules (BCR) |
|
is related to
|
Data Fiduciary |
|
is related to
|
Financial Incentives For Personal Data (PD) |
|
is related to
|
Reasonable Data Privacy Practices |
|
is related to
|
Data Privacy Notice |
|
is related to
|
Purpose Specification |
|
is related to
|
Computer Matching Agreements (CMA) |
|
is related to
|
System of Records Notice (SORN) |
|
is related to
|
System of Records Notice (SORN) Review Process |
|
is related to
|
Privacy Act Exemptions |
|
is related to
|
Real-Time or Layered Notice |
|
is related to
|
Purpose Compatibility |
|
is related to
|
Privacy Notice Formatting |
|
is related to
|
Symmetry In Choice |
|
is related to
|
Choice Architecture |
|
is related to
|
Choice Architecture Testing |
|
is related to
|
Notice of Right To Limit |
|
is related to
|
Alternative Means To Deliver Privacy Notice |
|
is related to
|
Choice & Consent |
|
is related to
|
Tailored Consent |
|
is related to
|
Just-In-Time Notice & Updated Consent |
|
is related to
|
Product or Service Delivery Restrictions |
|
is related to
|
Authorized Agent |
|
is related to
|
Active Participation By Data Subjects |
|
is related to
|
Continued Use of Personal Data (PD) |
|
is related to
|
Cease Processing, Storing and/or Sharing Personal Data (PD) |
|
is related to
|
Communicating Processing Changes |
|
is related to
|
Data Subject Opt-In Consent |
|
is related to
|
Parent or Guardian Opt-In Consent For Minors |
|
is related to
|
Authority To Collect, Process, Store & Share Personal Data (PD) |
|
is related to
|
Primary Sources |
|
is related to
|
Identifiable Image Collection |
|
is related to
|
Acquired Personal Data (PD) |
|
is related to
|
Personal Data (PD) Collection Methods |
|
is related to
|
Personal Data (PD) Formats |
|
is related to
|
Notice of Correction or Processing Change |
|
is related to
|
Appeal Adverse Decision |
|
is related to
|
User Feedback Management |
|
is related to
|
Data Subject Authentication |
|
is related to
|
Obligation To Inform Third-Parties |
|
is related to
|
Reject Unauthenticated or Untrustworthy Disclosure Requests |
|
is related to
|
Justification To Reject Disclosure Requests |
|
is related to
|
Personal Data (PD) Control Testing, Training & Monitoring |
|
is related to
|
Personal Data (PD) Lineage |
|
is related to
|
Data Quality Management |
|
is related to
|
Data Analytics Bias |
|
is related to
|
Enabling Data Subjects To Update Personal Data (PD) |
|
is related to
|
Data Management Board |
|
is related to
|
Documenting Data Processing Activities |
|
is related to
|
Accounting of Disclosures |
|
is related to
|
Notification of Disclosure Request To Data Subject |
|
is related to
|
Register As A Data Controller and/or Data Processor |
|
is related to
|
Potential Human Rights Abuses |
|
is related to
|
Data Subject Communications |
|
is related to
|
Conspicuous Link To Data Privacy Notice |
|
is related to
|
Notice of Financial Incentive |
|
is related to
|
Data Subject Communications Documentation |
|
is related to
|
Data Subject Communications Metrics |
|
is related to
|
Data Subject Communications Disclosure |
|
is related to
|
Data Controller Communications |
|
is related to
|
Automated Decision-Making Technology (ADMT) For Data Subject Actions |
|
is related to
|
Automated Decision-Making Technology (ADMT) Use Notification |
|
is related to
|
Automated Decision-Making Technology (ADMT) Opt-Out Consent |
|
is related to
|
Automated Decision-Making Technology (ADMT) Transparency |
|
is related to
|
Data Brokers |
|
is related to
|
Notice of Right To Opt-Out |
|
is related to
|
Opt-Out Links |
|
is related to
|
Alternative Out-Out Link |
|
is related to
|
Security, Compliance & Resilience Protection Portfolio Management |
|
is related to
|
Strategic Plan & Objectives |
|
is related to
|
Targeted Capability Maturity Levels |
|
is related to
|
Security, Compliance & Resilience Resource Management |
|
is related to
|
Prioritization To Address Evolving Risks & Threats |
|
is related to
|
Allocation of Resources |
|
is related to
|
Security, Compliance & Resilience In Project Management |
|
is related to
|
Security, Compliance & Resilience Requirements Definition |
|
is related to
|
Business Process Definition |
|
is related to
|
Secure Development Life Cycle (SDLC) Management |
|
is related to
|
Manage Organizational Knowledge |
|
is related to
|
Risk Management Program |
|
is related to
|
Risk Framing |
|
is related to
|
Risk Management Resourcing |
|
is related to
|
Risk Tolerance |
|
is related to
|
Risk Threshold |
|
is related to
|
Risk Appetite |
|
is related to
|
Risk-Based Security Categorization |
|
is related to
|
Impact-Level Prioritization |
|
is related to
|
Risk Identification |
|
is related to
|
Risk Catalog |
|
is related to
|
Risk Assessment |
|
is related to
|
Risk Register |
|
is related to
|
Risk Assessment Methodology |
|
is related to
|
Instances Requiring A Risk Assessment |
|
is related to
|
Risk Assessment Stakeholder Involvement |
|
is related to
|
Risk Ranking |
|
is related to
|
Risk Remediation |
|
is related to
|
Risk Response |
|
is related to
|
Compensating Countermeasures |
|
is related to
|
Risk Treatment Options |
|
is related to
|
Risk Treatment Plan (RTP) |
|
is related to
|
Risk Assessment Update |
|
is related to
|
Business Impact Analysis (BIA) |
|
is related to
|
Supply Chain Risk Management (SCRM) Plan |
|
is related to
|
Supply Chain Risk Assessment |
|
is related to
|
AI & Autonomous Technologies Supply Chain Impacts |
|
is related to
|
Data Protection Impact Assessment (DPIA) |
|
is related to
|
Risk Monitoring |
|
is related to
|
Risk Culture |
|
is related to
|
Executive Leadership Approval For Managing Material Risk |
|
is related to
|
Documented Alternatives |
|
is related to
|
Documented Justification For Material Risk Management Decisions |
|
is related to
|
Secure Engineering Principles |
|
is related to
|
Centralized Management of Security, Compliance & Resilience Controls |
|
is related to
|
Achieving Resilience Requirements |
|
is related to
|
Alignment With Enterprise Architecture |
|
is related to
|
Standardized Terminology |
|
is related to
|
Outsourcing Non-Essential Functions or Services |
|
is related to
|
Technical Debt Reviews |
|
is related to
|
Predictable Failure Analysis |
|
is related to
|
Technology Lifecycle Management |
|
is related to
|
Refresh from Trusted Sources |
|
is related to
|
Information Output Filtering |
|
is related to
|
Privileged Environments |
|
is related to
|
Operations Security |
|
is related to
|
Standardized Operating Procedures (SOP) |
|
is related to
|
Security Concept Of Operations (CONOPS) |
|
is related to
|
Service Delivery
(Business Process Support) |
|
is related to
|
Security Operations Center (SOC) |
|
is related to
|
Secure Practices Guidelines |
|
is related to
|
Security Orchestration, Automation, and Response (SOAR) |
|
is related to
|
Shadow Information Technology Detection |
|
is related to
|
Security, Compliance & Resilience-Minded Workforce |
|
is related to
|
Maintaining Workforce Development Relevancy |
|
is related to
|
Security, Compliance & Resilience Training Records |
|
is related to
|
Security, Compliance & Resilience Knowledge Sharing |
|
is related to
|
Technology Development & Acquisition |
|
is related to
|
Product Management |
|
is related to
|
Integrity Mechanisms for Software / Firmware Updates |
|
is related to
|
Malware Testing Prior to Release |
|
is related to
|
DevSecOps |
|
is related to
|
Minimum Viable Product (MVP) Security Requirements |
|
is related to
|
Ports, Protocols & Services In Use |
|
is related to
|
Information Assurance Enabled Products |
|
is related to
|
Development Methods, Techniques & Processes |
|
is related to
|
Identification & Justification of Ports, Protocols & Services |
|
is related to
|
Insecure Ports, Protocols & Services |
|
is related to
|
Security, Compliance & Resilience Representatives For Product Changes |
|
is related to
|
Minimizing Attack Surfaces |
|
is related to
|
Product Testing & Reviews |
|
is related to
|
Disclosure of Vulnerabilities |
|
is related to
|
Products With Digital Elements |
|
is related to
|
Reporting Exploitable Vulnerabilities |
|
is related to
|
Commercial Off-The-Shelf (COTS) Security Solutions |
|
is related to
|
Supplier Diversity |
|
is related to
|
Documentation Requirements |
|
is related to
|
Functional Properties |
|
is related to
|
Software Bill of Materials (SBOM) |
|
is related to
|
Developer Architecture & Design |
|
is related to
|
Physical Diagnostic & Test Interfaces |
|
is related to
|
Secure Software Development Practices (SSDP) |
|
is related to
|
Criticality Analysis During Development |
|
is related to
|
Threat Modeling |
|
is related to
|
Software Assurance Maturity Model (SAMM) |
|
is related to
|
Software Design Review |
|
is related to
|
Software Design Root Cause Analysis |
|
is related to
|
Secure Development Environments |
|
is related to
|
Separation of Development, Testing and Operational Environments |
|
is related to
|
Secure Migration Practices |
|
is related to
|
Security, Compliance & Resilience Testing Throughout Development |
|
is related to
|
Continuous Monitoring Plan |
|
is related to
|
Static Code Analysis |
|
is related to
|
Dynamic Code Analysis |
|
is related to
|
Malformed Input Testing |
|
is related to
|
Application Penetration Testing |
|
is related to
|
Manual Code Review |
|
is related to
|
Use of Live Data |
|
is related to
|
Test Data Integrity |
|
is related to
|
Product Tampering and Counterfeiting (PTC) |
|
is related to
|
Customized Development of Critical Components |
|
is related to
|
Developer Configuration Management |
|
is related to
|
Software / Firmware Integrity Verification |
|
is related to
|
Hardware Integrity Verification |
|
is related to
|
Developer Threat Analysis & Flaw Remediation |
|
is related to
|
Developer-Provided Training |
|
is related to
|
Unsupported Technology Assets, Applications and/or Services (TAAS) |
|
is related to
|
Alternate Sources for Continued Support |
|
is related to
|
Access to Program Source Code |
|
is related to
|
Software Release Integrity Verification |
|
is related to
|
Archiving Software Releases |
|
is related to
|
Software Escrow |
|
is related to
|
Approved Code |
|
is related to
|
Product Conformity Governance |
|
is related to
|
Technical Documentation Artifacts |
|
is related to
|
Product-Specific Risk Assessment Artifacts |
|
is related to
|
Third-Party Management |
|
is related to
|
Third-Party Inventories |
|
is related to
|
Third-Party Criticality Assessments |
|
is related to
|
Supply Chain Risk Management (SCRM) |
|
is related to
|
Acquisition Strategies, Tools & Methods |
|
is related to
|
Limit Potential Harm |
|
is related to
|
Processes To Address Weaknesses or Deficiencies |
|
is related to
|
Adequate Supply |
|
is related to
|
Third-Party Services |
|
is related to
|
Third-Party Risk Assessments & Approvals |
|
is related to
|
External Connectivity Requirements - Identification of Ports, Protocols & Services |
|
is related to
|
Conflict of Interests |
|
is related to
|
Third-Party Processing, Storage and Service Locations |
|
is related to
|
Third-Party Contract Requirements |
|
is related to
|
Security Compromise Notification Agreements |
|
is related to
|
Contract Flow-Down Requirements |
|
is related to
|
Third-Party Authentication Practices |
|
is related to
|
Responsible, Accountable, Supportive, Consulted & Informed (RASCI) Matrix |
|
is related to
|
Third-Party Scope Review |
|
is related to
|
First-Party Declaration (1PD) |
|
is related to
|
Break Clauses |
|
is related to
|
Third-Party Attestation (3PA) |
|
is related to
|
Third-Party Personnel Security |
|
is related to
|
Monitoring for Third-Party Information Disclosure |
|
is related to
|
Review of Third-Party Services |
|
is related to
|
Third-Party Deficiency Remediation |
|
is related to
|
Managing Changes To Third-Party Services |
|
is related to
|
Third-Party Incident Response & Recovery Capabilities |
|
is related to
|
Foreign Ownership, Control or Influence (FOCI) |
|
is related to
|
Ownership Change Monitoring |
|
is related to
|
Ownership Change Provisions |
|
is related to
|
Threat Intelligence Program |
|
is related to
|
Indicators of Exposure (IOE) |
|
is related to
|
Threat Intelligence Feeds |
|
is related to
|
Threat Intelligence Reporting |
|
is related to
|
Insider Threat Program |
|
is related to
|
Insider Threat Awareness |
|
is related to
|
Vulnerability Disclosure Program (VDP) |
|
is related to
|
Security Disclosure Contact Information |
|
is related to
|
Threat Hunting |
|
is related to
|
Tainting |
|
is related to
|
Threat Catalog |
|
is related to
|
Threat Analysis |
|
is related to
|
Vulnerability & Patch Management Program (VPMP) |
|
is related to
|
Attack Surface Scope |
|
is related to
|
Vulnerability Remediation Process |
|
is related to
|
Vulnerability Ranking |
|
is related to
|
Vulnerability Exploitation Analysis |
|
is related to
|
Continuous Vulnerability Remediation Activities |
|
is related to
|
Stable Versions |
|
is related to
|
Flaw Remediation with Personal Data (PD) |
|
is related to
|
Deferred Patching Decisions |
|
is related to
|
Centralized Management of Flaw Remediation Processes |
|
is related to
|
Time To Remediate / Benchmarks For Corrective Action |
|
is related to
|
Pre-Deployment Patch Testing |
|
is related to
|
Out-of-Cycle Patching |
|
is related to
|
Vulnerability Scanning |
|
is related to
|
Breadth / Depth of Coverage |
|
is related to
|
Review Historical Event logs |
|
is related to
|
Independent Penetration Agent or Team |
|
is related to
|
Technical Surveillance Countermeasures Security |
|
is related to
|
Reviewing Vulnerability Scanner Usage |
|
is related to
|
Red Team Exercises |
|
is related to
|
Web Security |
|
is related to
|
Unauthorized Code |
|
is related to
|
Use of Demilitarized Zones (DMZ) |
|
is related to
|
Web Security Standard |
|
is related to
|
Web Application Framework |
|
is related to
|
Validation & Sanitization |
|
is related to
|
Publicly Accessible Content Reviews |