|
is blocked by
|
Security, Compliance & Resilience Program (SCRP) |
|
is blocked by
|
Steering Committee & Program Oversight |
|
is blocked by
|
Status Reporting To Governing Body |
|
is blocked by
|
Commitment To Continual Improvements |
|
is blocked by
|
Publishing Security, Compliance & Resilience Documentation |
|
is blocked by
|
Exception Management |
|
is blocked by
|
Periodic Review & Update of Security, Compliance & Resilience Program |
|
is blocked by
|
Assigned Security, Compliance & Resilience Responsibilities |
|
is blocked by
|
Stakeholder Accountability Structure |
|
is blocked by
|
Authoritative Chain of Command |
|
is blocked by
|
Measures of Performance |
|
is blocked by
|
Key Performance Indicators (KPIs) |
|
is blocked by
|
Key Risk Indicators (KRIs) |
|
is blocked by
|
Contacts With Groups & Associations |
|
is blocked by
|
Defining Business Context & Mission |
|
is blocked by
|
Define Control Objectives |
|
is blocked by
|
Data Governance |
|
is blocked by
|
Purpose Validation |
|
is blocked by
|
Forced Technology Transfer (FTT) |
|
is blocked by
|
State-Sponsored Espionage |
|
is blocked by
|
Business As Usual (BAU) Security, Compliance & Resilience Practices |
|
is blocked by
|
Operationalizing Security, Compliance & Resilience Capabilities |
|
is blocked by
|
Select Controls |
|
is blocked by
|
Implement Controls |
|
is blocked by
|
Assess Controls |
|
is blocked by
|
Authorize Technology Assets, Applications and/or Services (TAAS) |
|
is blocked by
|
Monitor Controls |
|
is blocked by
|
Materiality Determination |
|
is blocked by
|
Material Risks |
|
is blocked by
|
Material Threats |
|
is blocked by
|
Quality Management System (QMS) |
|
is blocked by
|
Assurance |
|
is blocked by
|
Assurance Levels (AL) |
|
is blocked by
|
Assessment Objectives (AO) |
|
is blocked by
|
Artificial Intelligence (AI) & Autonomous Technologies Governance |
|
is blocked by
|
AI & Autonomous Technologies-Related Legal Requirements Definition |
|
is blocked by
|
Trustworthy AI & Autonomous Technologies |
|
is blocked by
|
AI & Autonomous Technologies Value Sustainment |
|
is blocked by
|
AI Model & Agent Inventory & Lifecycle Management |
|
is blocked by
|
Situational Awareness of AI & Autonomous Technologies |
|
is blocked by
|
AI & Autonomous Technologies Risk Mapping |
|
is blocked by
|
AI & Autonomous Technologies Internal Controls |
|
is blocked by
|
Adequate Protections For AI & Autonomous Technologies |
|
is blocked by
|
AI Threat Modeling & Risk Assessment |
|
is blocked by
|
AI & Autonomous Technologies Context Definition |
|
is blocked by
|
AI & Autonomous Technologies Mission and Goals Definition |
|
is blocked by
|
Model & AI Agent Documentation |
|
is blocked by
|
AI & Autonomous Technologies Business Case |
|
is blocked by
|
AI & Autonomous Technologies Potential Benefits Analysis |
|
is blocked by
|
AI & Autonomous Technologies Potential Costs Analysis |
|
is blocked by
|
AI & Autonomous Technologies Targeted Application Scope |
|
is blocked by
|
AI & Autonomous Technologies Cost / Benefit Mapping |
|
is blocked by
|
AI & Autonomous Technologies Training |
|
is blocked by
|
AI & Autonomous Technologies Fairness & Bias |
|
is blocked by
|
AI & Autonomous Technologies Risk Management Decisions |
|
is blocked by
|
AI & Autonomous Technologies Impact Assessment |
|
is blocked by
|
AI & Autonomous Technologies Likelihood & Impact Risk Analysis |
|
is blocked by
|
AI & Autonomous Technologies Continuous Improvements |
|
is blocked by
|
Assigned Responsibilities for AI & Autonomous Technologies |
|
is blocked by
|
AI & Autonomous Technologies Risk Profiling |
|
is blocked by
|
AI & Autonomous Technologies High Risk Designations |
|
is blocked by
|
Artificial Intelligence Test, Evaluation, Validation & Verification (AI TEVV) |
|
is blocked by
|
AI TEVV Trustworthiness Assessment |
|
is blocked by
|
AI TEVV Tools |
|
is blocked by
|
AI TEVV Trustworthiness Demonstration |
|
is blocked by
|
AI TEVV Safety Demonstration |
|
is blocked by
|
AI TEVV Security & Resiliency Assessment |
|
is blocked by
|
AI TEVV Transparency & Accountability Assessment |
|
is blocked by
|
AI TEVV Privacy Assessment |
|
is blocked by
|
AI TEVV Fairness & Bias Assessment |
|
is blocked by
|
AI & Autonomous Technologies Model Validation |
|
is blocked by
|
AI TEVV Results Evaluation |
|
is blocked by
|
AI TEVV Effectiveness |
|
is blocked by
|
AI TEVV Comparable Deployment Settings |
|
is blocked by
|
AI TEVV Post-Deployment Monitoring |
|
is blocked by
|
Updating AI & Autonomous Technologies |
|
is blocked by
|
AI TEVV Reporting |
|
is blocked by
|
AI TEVV Empirically Validated Methods |
|
is blocked by
|
AI TEVV Benchmarking Content Provenance |
|
is blocked by
|
AI TEVV Model Collapse Mitigations |
|
is blocked by
|
AI TEVV Third-Party Risk Management |
|
is blocked by
|
Robust Stakeholder Engagement for AI & Autonomous Technologies |
|
is blocked by
|
AI & Autonomous Technologies Stakeholder Feedback Integration |
|
is blocked by
|
AI & Autonomous Technologies Ongoing Assessments |
|
is blocked by
|
AI & Autonomous Technologies End User Feedback |
|
is blocked by
|
AI & Autonomous Technologies Incident & Error Reporting |
|
is blocked by
|
AI & Autonomous Technologies Intellectual Property Infringement Protections |
|
is blocked by
|
Data Source Identification |
|
is blocked by
|
Data Source Integrity |
|
is blocked by
|
Data Source Lineage & Origin Disclosure |
|
is blocked by
|
Digital Content Modification Logging |
|
is blocked by
|
AI & Autonomous Technologies Stakeholder Diversity |
|
is blocked by
|
AI & Autonomous Technologies Stakeholder Competencies |
|
is blocked by
|
AI & Autonomous Technologies Requirements Definitions |
|
is blocked by
|
AI & Autonomous Technologies Implementation Tasks Definition |
|
is blocked by
|
AI & Autonomous Technologies Knowledge Limits |
|
is blocked by
|
AI & Autonomous Technologies Viability Decisions |
|
is blocked by
|
AI & Autonomous Technologies Negative Residual Risks |
|
is blocked by
|
Responsibility To Supersede, Deactivate and/or Disengage AI & Autonomous Technologies |
|
is blocked by
|
AI & Autonomous Technologies Production Monitoring |
|
is blocked by
|
AI & Autonomous Technologies Measurement Approaches |
|
is blocked by
|
Measuring AI & Autonomous Technologies Effectiveness |
|
is blocked by
|
Unmeasurable AI & Autonomous Technologies Risks |
|
is blocked by
|
Efficacy of AI & Autonomous Technologies Measurement |
|
is blocked by
|
AI & Autonomous Technologies Domain Expert Reviews |
|
is blocked by
|
AI & Autonomous Technologies Performance Changes |
|
is blocked by
|
Pre-Trained AI & Autonomous Technologies Models |
|
is blocked by
|
AI & Autonomous Technologies Event Logging |
|
is blocked by
|
Serious Incident Reporting For AI & Autonomous Technologies |
|
is blocked by
|
Serious Incident Root Cause Analysis (RCA) For AI & Autonomous Technologies |
|
is blocked by
|
Anomaly Detection & Human Oversight |
|
is blocked by
|
Human-in-the-Loop & Escalation |
|
is blocked by
|
Emergent Behavior & Collusion Protections |
|
is blocked by
|
Multi-Agent Trust & Communication Validation |
|
is blocked by
|
AI & Autonomous Technologies Harm Prevention |
|
is blocked by
|
AI & Autonomous Technologies Human Subject Protections |
|
is blocked by
|
AI & Autonomous Technologies Environmental Impact & Sustainability |
|
is blocked by
|
Previously Unknown AI & Autonomous Technologies Threats & Risks |
|
is blocked by
|
Novel Risk Assessment Methods & Technologies |
|
is blocked by
|
Fine Tuning Risk Mitigation |
|
is blocked by
|
AI & Autonomous Technologies Risk Tracking Approaches |
|
is blocked by
|
AI & Autonomous Technologies Risk Response |
|
is blocked by
|
AI & Autonomous Technologies Conformity |
|
is blocked by
|
Manipulative or Deceptive Techniques |
|
is blocked by
|
Materially Distorting Behaviors |
|
is blocked by
|
Social Scoring |
|
is blocked by
|
Detrimental or Unfavorable Treatment |
|
is blocked by
|
Risk and Criminal Profiling |
|
is blocked by
|
Populating Facial Recognition Databases |
|
is blocked by
|
Emotion Inference |
|
is blocked by
|
Biometric Categorization |
|
is blocked by
|
AI & Autonomous Technologies Development Practices |
|
is blocked by
|
AI & Autonomous Technologies Transparency |
|
is blocked by
|
AI & Autonomous Technologies Implementation Documentation |
|
is blocked by
|
AI & Autonomous Technologies Human Domain Knowledge Reliance |
|
is blocked by
|
AI & Autonomous Technologies Registration |
|
is blocked by
|
AI & Autonomous Technologies Deployment |
|
is blocked by
|
AI & Autonomous Technologies Human Oversight |
|
is blocked by
|
AI & Autonomous Technologies Oversight Measures |
|
is blocked by
|
AI & Autonomous Technologies Separate Verification |
|
is blocked by
|
AI & Autonomous Technologies Oversight Functions Competency |
|
is blocked by
|
AI & Autonomous Technologies Data Relevance |
|
is blocked by
|
AI & Autonomous Technologies Irregularity Reporting |
|
is blocked by
|
AI & Autonomous Technologies Use Notification To Employees |
|
is blocked by
|
AI & Autonomous Technologies Use Notification To Users |
|
is blocked by
|
AI & Autonomous Technologies Output Marking |
|
is blocked by
|
Real World Testing of AI & Autonomous Technologies |
|
is blocked by
|
AI & Autonomous Technologies System Value Chain |
|
is blocked by
|
AI & Autonomous Technologies System Value Chain Fallbacks |
|
is blocked by
|
AI & Autonomous Technologies Testing Techniques |
|
is blocked by
|
Generative Artificial Intelligence (GAI) Identification |
|
is blocked by
|
AI & Autonomous Technologies Capabilities Testing |
|
is blocked by
|
Real-World Testing |
|
is blocked by
|
Documenting Testing Guidance |
|
is blocked by
|
AI & Autonomous Technologies Output Filtering |
|
is blocked by
|
Human Moderation |
|
is blocked by
|
AI Model Resilience |
|
is blocked by
|
Model Pollution |
|
is blocked by
|
Cascading Hallucination Defense |
|
is blocked by
|
Resource Exhaustion & DoS Resilience |
|
is blocked by
|
AI Agent Governance |
|
is blocked by
|
Infrastructure Hardening & Isolation |
|
is blocked by
|
AI Agent Limitations |
|
is blocked by
|
Tool & API Invocation Controls |
|
is blocked by
|
Orchestration Protocol Safeguards |
|
is blocked by
|
Data Pipeline & Input Integrity |
|
is blocked by
|
Privileged Role & Delegation Boundaries |
|
is blocked by
|
AI Agent Data Access Restrictions |
|
is blocked by
|
Data Extraction |
|
is blocked by
|
AI Agent Identity & Impersonation Defense |
|
is blocked by
|
AI Agent Logic Integrity |
|
is blocked by
|
Sandboxing AI Agents |
|
is blocked by
|
Prompt Injection Defense |
|
is blocked by
|
Agent Kill Switch / User Control |
|
is blocked by
|
Adversarial & Red Team Testing |
|
is blocked by
|
Self-Modification Controls |
|
is blocked by
|
Purging AI Agent Data |
|
is blocked by
|
Delegation and Chaining Control |
|
is blocked by
|
Behavioral Drift Detection |
|
is blocked by
|
AI Agent Action Authentication & Authorization |
|
is blocked by
|
Transparency & Audit |
|
is blocked by
|
Explainability |
|
is blocked by
|
Ethics, Fairness & Bias Detection |
|
is blocked by
|
Agent Output Integrity & Verification |
|
is blocked by
|
Agentic Output Traceability & Repudiation |
|
is blocked by
|
AI Agent Logging |
|
is blocked by
|
Session Management |
|
is blocked by
|
Human-in-the-Loop Workload & Manipulation |
|
is blocked by
|
Robotic Process Automation (RPA) |
|
is blocked by
|
Business Process Task Enumeration |
|
is blocked by
|
Standardized Naming Convention |
|
is blocked by
|
Approved Technologies |
|
is blocked by
|
Authorized To Connect |
|
is blocked by
|
Asset Inventories |
|
is blocked by
|
Component Duplication Avoidance |
|
is blocked by
|
Approved Baseline Deviations |
|
is blocked by
|
Network Access Control (NAC) |
|
is blocked by
|
Dynamic Host Configuration Protocol (DHCP) Server Logging |
|
is blocked by
|
Software Licensing Restrictions |
|
is blocked by
|
Configuration Management Database (CMDB) |
|
is blocked by
|
Asset Ownership Assignment |
|
is blocked by
|
Accountability Information |
|
is blocked by
|
Provenance |
|
is blocked by
|
Network Diagrams & Data Flow Diagrams (DFDs) |
|
is blocked by
|
Asset Scope Classification |
|
is blocked by
|
Security of Assets & Media |
|
is blocked by
|
Management Approval For External Media Transfer |
|
is blocked by
|
Unattended End-User Equipment |
|
is blocked by
|
Kiosks & Point of Interaction (PoI) Devices |
|
is blocked by
|
Physical Tampering Detection |
|
is blocked by
|
Secure Disposal, Destruction or Re-Use of Equipment |
|
is blocked by
|
Use of Personal Devices |
|
is blocked by
|
Use of Third-Party Devices |
|
is blocked by
|
Bluetooth & Wireless Devices |
|
is blocked by
|
Infrared Communications |
|
is blocked by
|
Bring Your Own Device (BYOD) Usage |
|
is blocked by
|
Prohibited Equipment & Services |
|
is blocked by
|
Roots of Trust Protection |
|
is blocked by
|
Telecommunications Equipment |
|
is blocked by
|
Video Teleconference (VTC) Security |
|
is blocked by
|
Voice Over Internet Protocol (VoIP) Security |
|
is blocked by
|
Microphones & Web Cameras |
|
is blocked by
|
Multi-Function Devices (MFD) |
|
is blocked by
|
Travel-Only Devices |
|
is blocked by
|
Re-Imaging Devices After Travel |
|
is blocked by
|
System Administrative Processes |
|
is blocked by
|
Jump Server |
|
is blocked by
|
Database Administrative Processes |
|
is blocked by
|
Database Management System (DBMS) |
|
is blocked by
|
Radio Frequency Identification (RFID) Security |
|
is blocked by
|
Contactless Access Control Systems |
|
is blocked by
|
Decommissioning |
|
is blocked by
|
Asset Categorization |
|
is blocked by
|
Categorize Artificial Intelligence (AI)-Related Technologies |
|
is blocked by
|
High-Risk Asset Categorization |
|
is blocked by
|
Data Storage Location Reviews |
|
is blocked by
|
Contingency Training |
|
is blocked by
|
Simulated Events |
|
is blocked by
|
Automated Training Environments |
|
is blocked by
|
Contingency Plan Testing & Exercises |
|
is blocked by
|
Dual Authorization For Backup Media Destruction |
|
is blocked by
|
Backup Access |
|
is blocked by
|
Backup Modification and/or Destruction |
|
is blocked by
|
Isolated Recovery Environment |
|
is blocked by
|
Reserve Hardware |
|
is blocked by
|
AI & Autonomous Technologies Incidents |
|
is blocked by
|
Performance Monitoring |
|
is blocked by
|
Change Management Program |
|
is blocked by
|
Configuration Change Control |
|
is blocked by
|
Prohibition Of Changes |
|
is blocked by
|
Test, Validate & Document Changes |
|
is blocked by
|
Security, Compliance & Resilience Representative for Asset Lifecycle Changes |
|
is blocked by
|
Automated Security Response |
|
is blocked by
|
Security Impact Analysis for Changes |
|
is blocked by
|
Automated Access Enforcement / Auditing |
|
is blocked by
|
Dual Authorization for Change |
|
is blocked by
|
Permissions To Implement Changes |
|
is blocked by
|
Library Privileges |
|
is blocked by
|
Stakeholder Notification of Changes |
|
is blocked by
|
Control Functionality Verification |
|
is blocked by
|
Report Verification Results |
|
is blocked by
|
Emergency Changes |
|
is blocked by
|
Documenting Emergency Changes |
|
is blocked by
|
Dual Approval For High-Impact Environments |
|
is blocked by
|
Cloud Services |
|
is blocked by
|
Cloud Infrastructure Onboarding |
|
is blocked by
|
Cloud Infrastructure Offboarding |
|
is blocked by
|
Cloud Security Architecture |
|
is blocked by
|
API Gateway |
|
is blocked by
|
Multi-Tenant Environments |
|
is blocked by
|
Customer Responsibility Matrix (CRM) |
|
is blocked by
|
Multi-Tenant Event Logging Capabilities |
|
is blocked by
|
Multi-Tenant Forensics Capabilities |
|
is blocked by
|
Multi-Tenant Incident Response Capabilities |
|
is blocked by
|
Hosted Assets, Applications & Services |
|
is blocked by
|
Authorized Individuals For Hosted Assets, Applications & Services |
|
is blocked by
|
Sensitive / Regulated Data On Hosted Assets, Applications & Services |
|
is blocked by
|
Prohibition On Unverified Hosted Assets, Applications & Services |
|
is blocked by
|
Software Defined Storage (SDS) |
|
is blocked by
|
Statutory, Regulatory & Contractual Compliance |
|
is blocked by
|
Non-Compliance Oversight |
|
is blocked by
|
Compliance Scope |
|
is blocked by
|
Ability To Demonstrate Conformity |
|
is blocked by
|
Conformity Assessment |
|
is blocked by
|
Declaration of Conformity |
|
is blocked by
|
Assessment Team Subject Matter Expertise |
|
is blocked by
|
Designated Certifying Official |
|
is blocked by
|
Conformity Attestations |
|
is blocked by
|
Security, Compliance & Resilience Controls Oversight |
|
is blocked by
|
Internal Audit Function |
|
is blocked by
|
Periodic Audits |
|
is blocked by
|
Corrective Action |
|
is blocked by
|
Security, Compliance & Resilience Assessments |
|
is blocked by
|
Independent Assessors |
|
is blocked by
|
Functional Review Of Security, Compliance & Resilience Controls |
|
is blocked by
|
Assessor Access |
|
is blocked by
|
Assessment Methods |
|
is blocked by
|
Assessment Rigor |
|
is blocked by
|
Evidence Request List (ERL) |
|
is blocked by
|
Evidence Sampling |
|
is blocked by
|
Audit Activities |
|
is blocked by
|
Legal Assessment of Investigative Inquires |
|
is blocked by
|
Investigation Request Notifications |
|
is blocked by
|
Investigation Access Restrictions |
|
is blocked by
|
Government Surveillance |
|
is blocked by
|
Grievances |
|
is blocked by
|
Grievance Response |
|
is blocked by
|
Localized Representation |
|
is blocked by
|
Representative Powers |
|
is blocked by
|
Control Reciprocity |
|
is blocked by
|
Control Inheritance |
|
is blocked by
|
Dual Use Technology |
|
is blocked by
|
USML or CCL Identification |
|
is blocked by
|
Export-Controlled Access Restrictions |
|
is blocked by
|
Export Activities Documentation |
|
is blocked by
|
Work Products |
|
is blocked by
|
Defensible Evidence of Due Diligence |
|
is blocked by
|
Defensible Evidence of Due Care |
|
is blocked by
|
Configuration Management Program |
|
is blocked by
|
Assignment of Responsibility |
|
is blocked by
|
Secure Baseline Configurations |
|
is blocked by
|
Reviews & Updates |
|
is blocked by
|
Automated Central Management & Verification |
|
is blocked by
|
Retention Of Previous Configurations |
|
is blocked by
|
Development & Test Environment Configurations |
|
is blocked by
|
Configure Technology Assets, Applications and/or Services (TAAS) for High-Risk Areas |
|
is blocked by
|
Network Device Configuration File Synchronization |
|
is blocked by
|
Approved Configuration Deviations |
|
is blocked by
|
Respond To Unauthorized Changes |
|
is blocked by
|
Baseline Tailoring |
|
is blocked by
|
Least Functionality |
|
is blocked by
|
Periodic Review |
|
is blocked by
|
Prevent Unauthorized Software Execution |
|
is blocked by
|
Explicitly Allow / Deny Applications |
|
is blocked by
|
Split Tunneling |
|
is blocked by
|
Software Usage Restrictions |
|
is blocked by
|
Open Source Software |
|
is blocked by
|
Unsupported Internet Browsers & Email Clients |
|
is blocked by
|
User-Installed Software |
|
is blocked by
|
Unauthorized Installation Alerts |
|
is blocked by
|
Restrict Roles Permitted To Install Software |
|
is blocked by
|
Configuration Enforcement |
|
is blocked by
|
Integrity Assurance & Enforcement (IAE) |
|
is blocked by
|
Sensitive / Regulated Data Access Enforcement |
|
is blocked by
|
Sensitive / Regulated Data Actions |
|
is blocked by
|
Continuous Monitoring |
|
is blocked by
|
Intrusion Detection & Prevention Systems (IDS & IPS) |
|
is blocked by
|
Automated Tools for Real-Time Analysis |
|
is blocked by
|
Inbound & Outbound Communications Traffic |
|
is blocked by
|
System Generated Alerts |
|
is blocked by
|
Wireless Network Monitoring |
|
is blocked by
|
Host-Based Devices |
|
is blocked by
|
File Integrity Monitoring (FIM) |
|
is blocked by
|
Security Event Monitoring |
|
is blocked by
|
Proxy Logging |
|
is blocked by
|
Deactivated Account Activity |
|
is blocked by
|
Automated Response to Suspicious Events |
|
is blocked by
|
Automated Alerts |
|
is blocked by
|
Alert Threshold Tuning |
|
is blocked by
|
Individuals Posing Greater Risk |
|
is blocked by
|
Privileged User Oversight |
|
is blocked by
|
Analyze and Prioritize Monitoring Requirements |
|
is blocked by
|
Real-Time Session Monitoring |
|
is blocked by
|
Centralized Collection of Security Event Logs |
|
is blocked by
|
Correlate Monitoring Information |
|
is blocked by
|
Central Review & Analysis |
|
is blocked by
|
Integration of Scanning & Other Monitoring Information |
|
is blocked by
|
Correlation with Physical Monitoring |
|
is blocked by
|
Permitted Actions |
|
is blocked by
|
Audit Level Adjustments |
|
is blocked by
|
System-Wide / Time-Correlated Audit Trail |
|
is blocked by
|
Changes by Authorized Individuals |
|
is blocked by
|
Inventory of Technology Asset Event Logging |
|
is blocked by
|
Content of Event Logs |
|
is blocked by
|
Audit Trails |
|
is blocked by
|
Privileged Functions Logging |
|
is blocked by
|
Centralized Management of Event Log Content |
|
is blocked by
|
Database Logging |
|
is blocked by
|
Event Log Storage Capacity |
|
is blocked by
|
Response To Event Log Processing Failures |
|
is blocked by
|
Real-Time Alerts of Event Logging Failure |
|
is blocked by
|
Event Log Storage Capacity Alerting |
|
is blocked by
|
Monitoring Reporting |
|
is blocked by
|
Query Parameter Audits of Personal Data (PD) |
|
is blocked by
|
Trend Analysis Reporting |
|
is blocked by
|
Protection of Event Logs |
|
is blocked by
|
Monitoring For Information Disclosure |
|
is blocked by
|
Monitoring for Indicators of Compromise (IOC) |
|
is blocked by
|
Session Audit |
|
is blocked by
|
Anomalous Behavior |
|
is blocked by
|
Insider Threats |
|
is blocked by
|
Third-Party Threats |
|
is blocked by
|
Unauthorized Activities |
|
is blocked by
|
Account Creation and Modification Logging |
|
is blocked by
|
Event Log Analysis & Triage |
|
is blocked by
|
Event Log Review Escalation Matrix |
|
is blocked by
|
File Activity Monitoring (FAM) |
|
is blocked by
|
Write Once Read Many (WORM) Event Log Generation |
|
is blocked by
|
Cryptographic Key Management |
|
is blocked by
|
Symmetric Keys |
|
is blocked by
|
Asymmetric Keys |
|
is blocked by
|
Cryptographic Key Loss or Change |
|
is blocked by
|
Control & Distribution of Cryptographic Keys |
|
is blocked by
|
Assigned Owners |
|
is blocked by
|
External System Cryptographic Key Control |
|
is blocked by
|
Certificate Authorities |
|
is blocked by
|
Certificate Monitoring |
|
is blocked by
|
Cryptographic Hash |
|
is blocked by
|
Data Protection |
|
is blocked by
|
Data Stewardship |
|
is blocked by
|
Sensitive / Regulated Media Records |
|
is blocked by
|
Defining Access Authorizations for Sensitive / Regulated Data |
|
is blocked by
|
Data & Asset Classification |
|
is blocked by
|
Highest Classification Level |
|
is blocked by
|
Media Access |
|
is blocked by
|
Disclosure of Information |
|
is blocked by
|
Media Transportation |
|
is blocked by
|
Custodians |
|
is blocked by
|
Dual Authorization for Sensitive Data Destruction |
|
is blocked by
|
Data Reclassification |
|
is blocked by
|
Removable Media Security |
|
is blocked by
|
Use of External Technology Assets, Applications and/or Services (TAAS) |
|
is blocked by
|
Limits of Authorized Use |
|
is blocked by
|
Portable Storage Devices |
|
is blocked by
|
Protecting Sensitive / Regulated Data on External Technology Assets, Applications and/or Services (TAAS) |
|
is blocked by
|
Non-Organizationally Owned Technology Assets, Applications and/or Services (TAAS) |
|
is blocked by
|
Information Sharing |
|
is blocked by
|
Transfer Authorizations |
|
is blocked by
|
Data Access Mapping |
|
is blocked by
|
Publicly Accessible Content |
|
is blocked by
|
Ad-Hoc Transfers |
|
is blocked by
|
Media & Data Retention |
|
is blocked by
|
Minimize Sensitive / Regulated Data |
|
is blocked by
|
Limit Sensitive / Regulated Data In Testing, Training & Research |
|
is blocked by
|
Temporary Files Containing Personal Data (PD) |
|
is blocked by
|
Geographic Location of Data |
|
is blocked by
|
Information Disposal |
|
is blocked by
|
Updating & Correcting Personal Data (PD) |
|
is blocked by
|
Primary Source Personal Data (PD) Collection |
|
is blocked by
|
De-Identification (Anonymization) |
|
is blocked by
|
De-Identify Dataset Upon Collection |
|
is blocked by
|
Archiving |
|
is blocked by
|
Release |
|
is blocked by
|
Removal, Masking, Encryption, Hashing or Replacement of Direct Identifiers |
|
is blocked by
|
Information Location |
|
is blocked by
|
Automated Tools to Support Information Location |
|
is blocked by
|
Transfer of Sensitive and/or Regulated Data |
|
is blocked by
|
Transfer Activity Limits |
|
is blocked by
|
Data Localization |
|
is blocked by
|
Data Rights Management (DRM) |
|
is blocked by
|
Embedded Technology Security Program |
|
is blocked by
|
Internet of Things (IOT) |
|
is blocked by
|
Operational Technology (OT) |
|
is blocked by
|
Interface Security |
|
is blocked by
|
Embedded Technology Configuration Monitoring |
|
is blocked by
|
Prevent Alterations |
|
is blocked by
|
Embedded Technology Maintenance |
|
is blocked by
|
Resilience To Outages |
|
is blocked by
|
Power Level Monitoring |
|
is blocked by
|
Embedded Technology Reviews |
|
is blocked by
|
Safety Assessment |
|
is blocked by
|
Endpoint Device Management (EDM) |
|
is blocked by
|
Unified Endpoint Device Management (UEDM) |
|
is blocked by
|
Endpoint Protection Measures |
|
is blocked by
|
Prohibit Installation Without Privileged Status |
|
is blocked by
|
Software Installation Alerts |
|
is blocked by
|
Governing Access Restriction for Change |
|
is blocked by
|
Malicious Code Protection (Anti-Malware) |
|
is blocked by
|
Automatic Antimalware Signature Updates |
|
is blocked by
|
Documented Protection Measures |
|
is blocked by
|
Centralized Management of Antimalware Technologies |
|
is blocked by
|
Heuristic / Nonsignature-Based Detection |
|
is blocked by
|
Malware Protection Mechanism Testing |
|
is blocked by
|
Evolving Malware Threats |
|
is blocked by
|
Always On Protection |
|
is blocked by
|
Software Firewall |
|
is blocked by
|
Endpoint File Integrity Monitoring (FIM) |
|
is blocked by
|
Integrity Checks |
|
is blocked by
|
Endpoint Detection & Response (EDR) |
|
is blocked by
|
Automated Notifications of Integrity Violations |
|
is blocked by
|
Automated Response to Integrity Violations |
|
is blocked by
|
Boot Process Integrity |
|
is blocked by
|
Protection of Boot Firmware |
|
is blocked by
|
Binary or Machine-Executable Code |
|
is blocked by
|
Extended Detection & Response (XDR) |
|
is blocked by
|
Host Intrusion Detection and Prevention Systems (HIDS / HIPS) |
|
is blocked by
|
Phishing & Spam Protection |
|
is blocked by
|
Central Management |
|
is blocked by
|
Automatic Spam and Phishing Protection Updates |
|
is blocked by
|
Trusted Path |
|
is blocked by
|
Mobile Code |
|
is blocked by
|
Thin Nodes |
|
is blocked by
|
Port & Input / Output (I/O) Device Access |
|
is blocked by
|
Sensor Capability |
|
is blocked by
|
Authorized Use |
|
is blocked by
|
Notice of Collection |
|
is blocked by
|
Collection Minimization |
|
is blocked by
|
Sensor Delivery Verification |
|
is blocked by
|
Collaborative Computing Devices |
|
is blocked by
|
Disabling / Removal In Secure Work Areas |
|
is blocked by
|
Explicitly Indicate Current Participants |
|
is blocked by
|
Participant Identity Verification |
|
is blocked by
|
Participant Connection Management |
|
is blocked by
|
Explicit Indication Of Use |
|
is blocked by
|
Hypervisor Access |
|
is blocked by
|
Restrict Access To Security Functions |
|
is blocked by
|
Host-Based Security Function Isolation |
|
is blocked by
|
Human Resources Security Management |
|
is blocked by
|
Onboarding, Transferring & Offboarding Personnel |
|
is blocked by
|
Position Categorization |
|
is blocked by
|
Users With Elevated Privileges |
|
is blocked by
|
Probationary Periods |
|
is blocked by
|
Defined Roles & Responsibilities |
|
is blocked by
|
User Awareness |
|
is blocked by
|
Competency Requirements for Security-Related Positions |
|
is blocked by
|
Personnel Screening |
|
is blocked by
|
Roles With Special Protection Measures |
|
is blocked by
|
Formal Indoctrination |
|
is blocked by
|
Citizenship Requirements |
|
is blocked by
|
Citizenship Identification |
|
is blocked by
|
Terms of Employment |
|
is blocked by
|
Rules of Behavior |
|
is blocked by
|
Social Media & Social Networking Restrictions |
|
is blocked by
|
Technology Use Restrictions |
|
is blocked by
|
Use of Critical Technologies |
|
is blocked by
|
Use of Mobile Devices |
|
is blocked by
|
Policy Familiarization & Acknowledgement |
|
is blocked by
|
Access Agreements |
|
is blocked by
|
Confidentiality Agreements |
|
is blocked by
|
Post-Employment Requirements Awareness |
|
is blocked by
|
Personnel Sanctions |
|
is blocked by
|
Workplace Investigations |
|
is blocked by
|
Updating Disciplinary Processes |
|
is blocked by
|
Preventative Access Restriction |
|
is blocked by
|
Personnel Transfer |
|
is blocked by
|
Personnel Termination |
|
is blocked by
|
Asset Collection |
|
is blocked by
|
High-Risk Terminations |
|
is blocked by
|
Post-Employment Requirements Notification |
|
is blocked by
|
Automated Employment Status Notifications |
|
is blocked by
|
Third-Party Personnel |
|
is blocked by
|
Separation of Duties (SoD) |
|
is blocked by
|
Incompatible Roles |
|
is blocked by
|
Two-Person Rule |
|
is blocked by
|
Identify Critical Skills & Gaps |
|
is blocked by
|
Remediate Identified Skills Deficiencies |
|
is blocked by
|
Identify Vital Security, Compliance & Resilience Staff |
|
is blocked by
|
Establish Redundancy for Vital Security, Compliance & Resilience Staff |
|
is blocked by
|
Perform Succession Planning |
|
is blocked by
|
Identifying Authorized Work Locations |
|
is blocked by
|
Communicating Authorized Work Locations |
|
is blocked by
|
Reporting Suspicious Activities |
|
is blocked by
|
Identity & Access Management (IAM) |
|
is blocked by
|
Retain Access Records |
|
is blocked by
|
Authenticate, Authorize and Audit (AAA) |
|
is blocked by
|
User & Service Account Inventories |
|
is blocked by
|
Identification & Authentication for Organizational Users |
|
is blocked by
|
Group Authentication |
|
is blocked by
|
Replay-Resistant Authentication |
|
is blocked by
|
Acceptance of PIV Credentials |
|
is blocked by
|
Out-of-Band Authentication (OOBA) |
|
is blocked by
|
Identification & Authentication for Non-Organizational Users |
|
is blocked by
|
Acceptance of PIV Credentials from Other Organizations |
|
is blocked by
|
Acceptance of Third-Party Credentials |
|
is blocked by
|
Use of FICAM-Issued Profiles |
|
is blocked by
|
Identification & Authentication for Devices |
|
is blocked by
|
Device Attestation |
|
is blocked by
|
Device Authorization Enforcement |
|
is blocked by
|
Identification & Authentication for Third-Party Technology Assets, Applications and/or Services (TAAS) |
|
is blocked by
|
Sharing Identification & Authentication Information |
|
is blocked by
|
Privileged Access by Non-Organizational Users |
|
is blocked by
|
Multi-Factor Authentication (MFA) |
|
is blocked by
|
Network Access to Privileged Accounts |
|
is blocked by
|
Network Access to Non-Privileged Accounts |
|
is blocked by
|
Local Access to Privileged Accounts |
|
is blocked by
|
Out-of-Band Multi-Factor Authentication |
|
is blocked by
|
Alternative Multi-Factor Authentication |
|
is blocked by
|
User Provisioning & De-Provisioning |
|
is blocked by
|
Change of Roles & Duties |
|
is blocked by
|
Termination of Employment |
|
is blocked by
|
Role-Based Access Control (RBAC) |
|
is blocked by
|
Identifier Management (User Names) |
|
is blocked by
|
User Identity (ID) Management |
|
is blocked by
|
Identity User Status |
|
is blocked by
|
Dynamic Management |
|
is blocked by
|
Cross-Organization Management |
|
is blocked by
|
Privileged Account Identifiers |
|
is blocked by
|
Authenticator Management |
|
is blocked by
|
Password-Based Authentication |
|
is blocked by
|
PKI-Based Authentication |
|
is blocked by
|
In-Person or Trusted Third-Party Registration |
|
is blocked by
|
Automated Support For Password Strength |
|
is blocked by
|
Protection of Authenticators |
|
is blocked by
|
No Embedded Unencrypted Static Authenticators |
|
is blocked by
|
Hardware Token-Based Authentication |
|
is blocked by
|
Default Authenticators |
|
is blocked by
|
Multiple System Accounts |
|
is blocked by
|
Expiration of Cached Authenticators |
|
is blocked by
|
Password Managers |
|
is blocked by
|
Biometric Authentication |
|
is blocked by
|
Events Requiring Authenticator Change |
|
is blocked by
|
Passkeys |
|
is blocked by
|
Authenticator Feedback |
|
is blocked by
|
Cryptographic Module Authentication |
|
is blocked by
|
Hardware Security Modules (HSM) |
|
is blocked by
|
Adaptive Identification & Authentication |
|
is blocked by
|
Single Sign-On (SSO) Transparent Authentication |
|
is blocked by
|
Federated Credential Management |
|
is blocked by
|
Continuous Authentication |
|
is blocked by
|
Re-Authentication |
|
is blocked by
|
Account Management |
|
is blocked by
|
Automated System Account Management (Directory Services) |
|
is blocked by
|
Removal of Temporary / Emergency Accounts |
|
is blocked by
|
Disable Inactive Accounts |
|
is blocked by
|
Automated Audit Actions |
|
is blocked by
|
Restrictions on Shared Groups / Accounts |
|
is blocked by
|
Account Disabling for High Risk Individuals |
|
is blocked by
|
System Account Reviews |
|
is blocked by
|
Usage Conditions |
|
is blocked by
|
Emergency Accounts |
|
is blocked by
|
Privileged Account Management (PAM) |
|
is blocked by
|
Privileged Account Inventories |
|
is blocked by
|
Privileged Account Separation |
|
is blocked by
|
Privileged Command Execution |
|
is blocked by
|
Dedicated Privileged Account |
|
is blocked by
|
Periodic Review of Account Privileges |
|
is blocked by
|
User Responsibilities for Account Management |
|
is blocked by
|
Credential Sharing |
|
is blocked by
|
Access Enforcement |
|
is blocked by
|
Access To Sensitive / Regulated Data |
|
is blocked by
|
Database Access |
|
is blocked by
|
Use of Privileged Utility Programs |
|
is blocked by
|
Dedicated Administrative Machines |
|
is blocked by
|
Dual Authorization for Privileged Commands |
|
is blocked by
|
Revocation of Access Authorizations |
|
is blocked by
|
Authorized System Accounts |
|
is blocked by
|
Least Privilege |
|
is blocked by
|
Authorize Access to Security Functions |
|
is blocked by
|
Non-Privileged Access for Non-Security Functions |
|
is blocked by
|
Management Approval For Privileged Accounts |
|
is blocked by
|
Auditing Use of Privileged Functions |
|
is blocked by
|
Prohibit Non-Privileged Users from Executing Privileged Functions |
|
is blocked by
|
Network Access to Privileged Commands |
|
is blocked by
|
Privilege Levels for Code Execution |
|
is blocked by
|
Account Lockout |
|
is blocked by
|
Concurrent Session Control |
|
is blocked by
|
Session Lock |
|
is blocked by
|
Pattern-Hiding Displays |
|
is blocked by
|
Session Termination |
|
is blocked by
|
User-Initiated Logouts / Message Displays |
|
is blocked by
|
Permitted Actions Without Identification or Authorization |
|
is blocked by
|
Reference Monitor |
|
is blocked by
|
Identity Proofing (Identity Verification) |
|
is blocked by
|
Management Approval For New or Changed Accounts |
|
is blocked by
|
Identity Evidence |
|
is blocked by
|
Identity Evidence Validation & Verification |
|
is blocked by
|
In-Person Validation & Verification |
|
is blocked by
|
Address Confirmation |
|
is blocked by
|
Incident Response Operations |
|
is blocked by
|
Incident Handling |
|
is blocked by
|
Automated Incident Handling Processes |
|
is blocked by
|
Insider Threat Response Capability |
|
is blocked by
|
Incident Classification & Prioritization |
|
is blocked by
|
Correlation with External Organizations |
|
is blocked by
|
Indicators of Compromise (IOC) |
|
is blocked by
|
Incident Response Plan (IRP) |
|
is blocked by
|
Data Breach |
|
is blocked by
|
IRP Update |
|
is blocked by
|
Continuous Incident Response Improvements |
|
is blocked by
|
Incident Response Training |
|
is blocked by
|
Simulated Incidents |
|
is blocked by
|
Automated Incident Response Training Environments |
|
is blocked by
|
Incident Response Testing |
|
is blocked by
|
Coordination with Related Plans |
|
is blocked by
|
Integrated Security Incident Response Team (ISIRT) |
|
is blocked by
|
Chain of Custody & Forensics |
|
is blocked by
|
Licensed Forensic Investigators |
|
is blocked by
|
Situational Awareness For Incidents |
|
is blocked by
|
Automated Tracking, Data Collection & Analysis |
|
is blocked by
|
Recurring Incident Analysis |
|
is blocked by
|
Incident Tracking Repository |
|
is blocked by
|
Incident Stakeholder Reporting |
|
is blocked by
|
Automated Reporting |
|
is blocked by
|
Cyber Incident Reporting for Sensitive / Regulated Data |
|
is blocked by
|
Vulnerabilities Related To Incidents |
|
is blocked by
|
Supply Chain Coordination |
|
is blocked by
|
Serious Incident Reporting |
|
is blocked by
|
Incident Reporting Assistance |
|
is blocked by
|
Automation Support of Availability of Information / Support |
|
is blocked by
|
Coordination With External Providers |
|
is blocked by
|
Sensitive / Regulated Data Spill Response |
|
is blocked by
|
Sensitive / Regulated Data Spill Responsible Personnel |
|
is blocked by
|
Sensitive / Regulated Data Spill Training |
|
is blocked by
|
Post-Sensitive / Regulated Data Spill Operations |
|
is blocked by
|
Sensitive / Regulated Data Exposure to Unauthorized Personnel |
|
is blocked by
|
Root Cause Analysis (RCA) & Lessons Learned |
|
is blocked by
|
Regulatory & Law Enforcement Contacts |
|
is blocked by
|
Detonation Chambers (Sandboxes) |
|
is blocked by
|
Public Relations & Reputation Repair |
|
is blocked by
|
Information Assurance (IA) Operations |
|
is blocked by
|
Assessment Boundaries |
|
is blocked by
|
Assessments |
|
is blocked by
|
Assessor Independence |
|
is blocked by
|
Specialized Assessments |
|
is blocked by
|
Third-Party Assessment Reciprocity |
|
is blocked by
|
Security Assessment Report (SAR) |
|
is blocked by
|
Applied Security, Compliance and Resilience Controls Documentation |
|
is blocked by
|
Plan / Coordinate with Other Organizational Entities |
|
is blocked by
|
Adequate Security for Sensitive / Regulated Data In Support of Contracts |
|
is blocked by
|
Threat Analysis & Flaw Remediation During Development |
|
is blocked by
|
Capabilities Deficiency Tracking |
|
is blocked by
|
Technical Verification |
|
is blocked by
|
Security Authorization |
|
is blocked by
|
Maintenance Operations |
|
is blocked by
|
Controlled Maintenance |
|
is blocked by
|
Automated Maintenance Activities |
|
is blocked by
|
Timely Maintenance |
|
is blocked by
|
Preventative Maintenance |
|
is blocked by
|
Predictive Maintenance |
|
is blocked by
|
Automated Support For Predictive Maintenance |
|
is blocked by
|
Maintenance Tools |
|
is blocked by
|
Inspect Tools |
|
is blocked by
|
Inspect Media |
|
is blocked by
|
Prevent Unauthorized Removal |
|
is blocked by
|
Restrict Tool Usage |
|
is blocked by
|
Remote Maintenance |
|
is blocked by
|
Auditing Remote Maintenance |
|
is blocked by
|
Remote Maintenance Notifications |
|
is blocked by
|
Remote Maintenance Disconnect Verification |
|
is blocked by
|
Remote Maintenance Pre-Approval |
|
is blocked by
|
Remote Maintenance Comparable Security & Sanitization |
|
is blocked by
|
Separation of Maintenance Sessions |
|
is blocked by
|
Authorized Maintenance Personnel |
|
is blocked by
|
Maintenance Personnel Without Appropriate Access |
|
is blocked by
|
Maintain Configuration Control During Maintenance |
|
is blocked by
|
Field Maintenance |
|
is blocked by
|
Off-Site Maintenance |
|
is blocked by
|
Maintenance Validation |
|
is blocked by
|
Maintenance Monitoring |
|
is blocked by
|
Centralized Management Of Mobile Devices |
|
is blocked by
|
Access Control For Mobile Devices |
|
is blocked by
|
Personally-Owned Mobile Devices |
|
is blocked by
|
Organization-Owned Mobile Devices |
|
is blocked by
|
Separate Mobile Device Profiles |
|
is blocked by
|
Restricting Access To Authorized Technology Assets, Applications and/or Services (TAAS) |
|
is blocked by
|
Network Security Controls (NSC) |
|
is blocked by
|
Zero Trust Architecture (ZTA) |
|
is blocked by
|
Layered Network Defenses |
|
is blocked by
|
Guest Networks |
|
is blocked by
|
Cross Domain Solution (CDS) |
|
is blocked by
|
Boundary Protection |
|
is blocked by
|
Limit Network Connections |
|
is blocked by
|
Isolation of System Components |
|
is blocked by
|
Separate Subnet for Connecting to Different Security Domains |
|
is blocked by
|
Data Flow Enforcement – Access Control Lists (ACLs) |
|
is blocked by
|
Deny Traffic by Default & Allow Traffic by Exception |
|
is blocked by
|
Human Reviews |
|
is blocked by
|
Policy Decision Point (PDP) |
|
is blocked by
|
Detection of Unsanctioned Information |
|
is blocked by
|
Approved Solutions |
|
is blocked by
|
Application Proxy |
|
is blocked by
|
Interconnection Security Agreements (ISAs) |
|
is blocked by
|
External System Connections |
|
is blocked by
|
Internal System Connections |
|
is blocked by
|
Network Segmentation (macrosegementation) |
|
is blocked by
|
Security Management Subnets |
|
is blocked by
|
Virtual Local Area Network (VLAN) Separation |
|
is blocked by
|
Sensitive / Regulated Data Enclave (Secure Zone) |
|
is blocked by
|
Segregation From Enterprise Services |
|
is blocked by
|
Direct Internet Access Restrictions |
|
is blocked by
|
Microsegmentation |
|
is blocked by
|
Software Defined Networking (SDN) |
|
is blocked by
|
DMZ Networks |
|
is blocked by
|
Host Containment |
|
is blocked by
|
Resource Containment |
|
is blocked by
|
Domain Name Service (DNS) Resolution |
|
is blocked by
|
Architecture & Provisioning for Name / Address Resolution Service |
|
is blocked by
|
Secure Name / Address Resolution Service (Recursive or Caching Resolver) |
|
is blocked by
|
Sender Policy Framework (SPF) |
|
is blocked by
|
Domain Registrar Security |
|
is blocked by
|
End-User Messaging Technologies |
|
is blocked by
|
Electronic Messaging |
|
is blocked by
|
Work From Anywhere (WFA) - Telecommuting Security |
|
is blocked by
|
Third-Party Remote Access Governance |
|
is blocked by
|
Endpoint Security Validation |
|
is blocked by
|
Expeditious Disconnect / Disable Capability |
|
is blocked by
|
Wireless Networking |
|
is blocked by
|
Restrict Configuration By Users |
|
is blocked by
|
Wireless Boundaries |
|
is blocked by
|
Rogue Wireless Detection |
|
is blocked by
|
Intranets |
|
is blocked by
|
DNS & Content Filtering |
|
is blocked by
|
Route Internal Traffic to Proxy Servers |
|
is blocked by
|
Visibility of Encrypted Communications |
|
is blocked by
|
Protocol Compliance Enforcement |
|
is blocked by
|
Domain Name Verification |
|
is blocked by
|
Internet Address Denylisting |
|
is blocked by
|
Bandwidth Control |
|
is blocked by
|
Authenticated Proxy |
|
is blocked by
|
Certificate Denylisting |
|
is blocked by
|
Content Disarm and Reconstruction (CDR) |
|
is blocked by
|
Email Content Protections |
|
is blocked by
|
Email Domain Reputation Protections |
|
is blocked by
|
Sender Denylisting |
|
is blocked by
|
Authenticated Received Chain (ARC) |
|
is blocked by
|
Domain-Based Message Authentication Reporting and Conformance (DMARC) |
|
is blocked by
|
User Digital Signatures for Outgoing Email |
|
is blocked by
|
Encryption for Outgoing Email |
|
is blocked by
|
Adaptive Email Protections |
|
is blocked by
|
Email Labeling |
|
is blocked by
|
User Threat Reporting |
|
is blocked by
|
Physical & Environmental Protections |
|
is blocked by
|
Physical Security Plan (PSP) |
|
is blocked by
|
Zone-Based Physical Security |
|
is blocked by
|
Physical Access Authorizations |
|
is blocked by
|
Role-Based Physical Access |
|
is blocked by
|
Dual Authorization for Physical Access |
|
is blocked by
|
Physical Access Control |
|
is blocked by
|
Controlled Ingress & Egress Points |
|
is blocked by
|
Lockable Physical Casings |
|
is blocked by
|
Physical Access Logs |
|
is blocked by
|
Access To Critical Systems |
|
is blocked by
|
Physical Security of Offices, Rooms & Facilities |
|
is blocked by
|
Working in Secure Areas |
|
is blocked by
|
Searches |
|
is blocked by
|
Temporary Storage |
|
is blocked by
|
Monitoring Physical Access |
|
is blocked by
|
Visitor Control |
|
is blocked by
|
Distinguish Visitors from On-Site Personnel |
|
is blocked by
|
Identification Requirement |
|
is blocked by
|
Restrict Unescorted Access |
|
is blocked by
|
Minimize Visitor Personal Data (PD) |
|
is blocked by
|
Visitor Access Revocation |
|
is blocked by
|
Delivery & Removal |
|
is blocked by
|
Alternate Work Site |
|
is blocked by
|
Equipment Siting & Protection |
|
is blocked by
|
Transmission Medium Security |
|
is blocked by
|
Access Control for Output Devices |
|
is blocked by
|
Asset Monitoring and Tracking |
|
is blocked by
|
Component Marking |
|
is blocked by
|
Proximity Sensor |
|
is blocked by
|
On-Site Client Segregation |
|
is blocked by
|
Physical Access Device Inventories |
|
is blocked by
|
Data Privacy Program |
|
is blocked by
|
Privacy Act Statements |
|
is blocked by
|
Dissemination of Data Privacy Program Information |
|
is blocked by
|
Data Protection Officer (DPO) |
|
is blocked by
|
Binding Corporate Rules (BCR) |
|
is blocked by
|
Security of Personal Data (PD) |
|
is blocked by
|
Limiting Personal Data (PD) Disclosures |
|
is blocked by
|
Data Fiduciary |
|
is blocked by
|
Personal Data (PD) Process Manager |
|
is blocked by
|
Reasonable Data Privacy Practices |
|
is blocked by
|
Data Privacy Notice |
|
is blocked by
|
Purpose Specification |
|
is blocked by
|
Automated Data Management Processes |
|
is blocked by
|
Computer Matching Agreements (CMA) |
|
is blocked by
|
System of Records Notice (SORN) |
|
is blocked by
|
System of Records Notice (SORN) Review Process |
|
is blocked by
|
Privacy Act Exemptions |
|
is blocked by
|
Real-Time or Layered Notice |
|
is blocked by
|
Purpose Compatibility |
|
is blocked by
|
Privacy Notice Formatting |
|
is blocked by
|
Symmetry In Choice |
|
is blocked by
|
Choice Architecture |
|
is blocked by
|
Choice Architecture Testing |
|
is blocked by
|
Notice of Right To Limit |
|
is blocked by
|
Alternative Means To Deliver Privacy Notice |
|
is blocked by
|
Choice & Consent |
|
is blocked by
|
Tailored Consent |
|
is blocked by
|
Just-In-Time Notice & Updated Consent |
|
is blocked by
|
Prohibition of Selling, Processing and/or Sharing Personal Data (PD) |
|
is blocked by
|
Revoke Consent |
|
is blocked by
|
Product or Service Delivery Restrictions |
|
is blocked by
|
Active Participation By Data Subjects |
|
is blocked by
|
Global Privacy Control (GPC) |
|
is blocked by
|
Restrict Collection To Identified Purpose |
|
is blocked by
|
Authority To Collect, Process, Store & Share Personal Data (PD) |
|
is blocked by
|
Primary Sources |
|
is blocked by
|
Identifiable Image Collection |
|
is blocked by
|
Validate Collected Personal Data (PD) |
|
is blocked by
|
Re-Validate Collected Personal Data (PD) |
|
is blocked by
|
Personal Data (PD) Retention & Disposal |
|
is blocked by
|
Internal Use of Personal Data (PD) For Testing, Training and Research |
|
is blocked by
|
Usage Restrictions of Personal Data (PD) |
|
is blocked by
|
Inventory of Personal Data (PD) |
|
is blocked by
|
Correcting Inaccurate Personal Data (PD) |
|
is blocked by
|
Data Privacy Requirements for Contractors & Service Providers |
|
is blocked by
|
Joint Processing of Personal Data (PD) |
|
is blocked by
|
Personal Data (PD) Control Testing, Training & Monitoring |
|
is blocked by
|
Documenting Data Processing Activities |
|
is blocked by
|
Potential Human Rights Abuses |
|
is blocked by
|
Data Subject Communications Disclosure |
|
is blocked by
|
Data Controller Communications |
|
is blocked by
|
Automated Decision-Making Technology (ADMT) For Data Subject Actions |
|
is blocked by
|
Automated Decision-Making Technology (ADMT) Use Notification |
|
is blocked by
|
Automated Decision-Making Technology (ADMT) Opt-Out Consent |
|
is blocked by
|
Automated Decision-Making Technology (ADMT) Transparency |
|
is blocked by
|
Data Brokers |
|
is blocked by
|
Notice of Right To Opt-Out |
|
is blocked by
|
Opt-Out Links |
|
is blocked by
|
Alternative Out-Out Link |
|
is blocked by
|
Security, Compliance & Resilience Protection Portfolio Management |
|
is blocked by
|
Strategic Plan & Objectives |
|
is blocked by
|
Targeted Capability Maturity Levels |
|
is blocked by
|
Security, Compliance & Resilience Resource Management |
|
is blocked by
|
Prioritization To Address Evolving Risks & Threats |
|
is blocked by
|
Allocation of Resources |
|
is blocked by
|
Security, Compliance & Resilience In Project Management |
|
is blocked by
|
Security, Compliance & Resilience Requirements Definition |
|
is blocked by
|
Business Process Definition |
|
is blocked by
|
Secure Development Life Cycle (SDLC) Management |
|
is blocked by
|
Manage Organizational Knowledge |
|
is blocked by
|
Risk Management Program |
|
is blocked by
|
Risk Framing |
|
is blocked by
|
Risk Management Resourcing |
|
is blocked by
|
Risk Tolerance |
|
is blocked by
|
Risk Threshold |
|
is blocked by
|
Risk Appetite |
|
is blocked by
|
Risk-Based Security Categorization |
|
is blocked by
|
Impact-Level Prioritization |
|
is blocked by
|
Risk Identification |
|
is blocked by
|
Risk Catalog |
|
is blocked by
|
Risk Assessment |
|
is blocked by
|
Risk Register |
|
is blocked by
|
Risk Assessment Methodology |
|
is blocked by
|
Instances Requiring A Risk Assessment |
|
is blocked by
|
Risk Assessment Stakeholder Involvement |
|
is blocked by
|
Risk Ranking |
|
is blocked by
|
Risk Remediation |
|
is blocked by
|
Risk Response |
|
is blocked by
|
Compensating Countermeasures |
|
is blocked by
|
Risk Treatment Options |
|
is blocked by
|
Risk Treatment Plan (RTP) |
|
is blocked by
|
Risk Assessment Update |
|
is blocked by
|
Business Impact Analysis (BIA) |
|
is blocked by
|
Supply Chain Risk Management (SCRM) Plan |
|
is blocked by
|
Supply Chain Risk Assessment |
|
is blocked by
|
AI & Autonomous Technologies Supply Chain Impacts |
|
is blocked by
|
Data Protection Impact Assessment (DPIA) |
|
is blocked by
|
Risk Monitoring |
|
is blocked by
|
Risk Culture |
|
is blocked by
|
Secure Engineering Principles |
|
is blocked by
|
Centralized Management of Security, Compliance & Resilience Controls |
|
is blocked by
|
Alignment With Enterprise Architecture |
|
is blocked by
|
Outsourcing Non-Essential Functions or Services |
|
is blocked by
|
Technical Debt Reviews |
|
is blocked by
|
Defense-In-Depth (DiD) Architecture |
|
is blocked by
|
Security Function Isolation |
|
is blocked by
|
System Privileges Isolation |
|
is blocked by
|
Information In Shared Resources |
|
is blocked by
|
Technology Lifecycle Management |
|
is blocked by
|
Limit Personal Data (PD) Dissemination |
|
is blocked by
|
System Use Notification (Logon Banner) |
|
is blocked by
|
Standardized Microsoft Windows Banner |
|
is blocked by
|
Truncated Banner |
|
is blocked by
|
Privileged Environments |
|
is blocked by
|
Operations Security |
|
is blocked by
|
Security Concept Of Operations (CONOPS) |
|
is blocked by
|
Service Delivery
(Business Process Support) |
|
is blocked by
|
Security Operations Center (SOC) |
|
is blocked by
|
Secure Practices Guidelines |
|
is blocked by
|
Shadow Information Technology Detection |
|
is blocked by
|
Security, Compliance & Resilience-Minded Workforce |
|
is blocked by
|
Maintaining Workforce Development Relevancy |
|
is blocked by
|
Security, Compliance & Resilience Awareness Training |
|
is blocked by
|
Simulated Cyber Attack Scenario Training |
|
is blocked by
|
Social Engineering & Mining |
|
is blocked by
|
Role-Based Security, Compliance & Resilience Training |
|
is blocked by
|
Practical Exercises |
|
is blocked by
|
Suspicious Communications & Anomalous System Behavior |
|
is blocked by
|
Sensitive / Regulated Data Storage, Handling & Processing |
|
is blocked by
|
Vendor Security, Compliance & Resilience Training |
|
is blocked by
|
Privileged Users |
|
is blocked by
|
Cyber Threat Environment |
|
is blocked by
|
Counterintelligence Training |
|
is blocked by
|
Security, Compliance & Resilience Training Records |
|
is blocked by
|
Security, Compliance & Resilience Knowledge Sharing |
|
is blocked by
|
Technology Development & Acquisition |
|
is blocked by
|
Product Management |
|
is blocked by
|
Integrity Mechanisms for Software / Firmware Updates |
|
is blocked by
|
Malware Testing Prior to Release |
|
is blocked by
|
DevSecOps |
|
is blocked by
|
Minimum Viable Product (MVP) Security Requirements |
|
is blocked by
|
Ports, Protocols & Services In Use |
|
is blocked by
|
Development Methods, Techniques & Processes |
|
is blocked by
|
Pre-Established Secure Configurations |
|
is blocked by
|
Identification & Justification of Ports, Protocols & Services |
|
is blocked by
|
Insecure Ports, Protocols & Services |
|
is blocked by
|
Security, Compliance & Resilience Representatives For Product Changes |
|
is blocked by
|
Minimizing Attack Surfaces |
|
is blocked by
|
Ongoing Product Security Support |
|
is blocked by
|
Product Testing & Reviews |
|
is blocked by
|
Disclosure of Vulnerabilities |
|
is blocked by
|
Products With Digital Elements |
|
is blocked by
|
Reporting Exploitable Vulnerabilities |
|
is blocked by
|
Logging Syntax |
|
is blocked by
|
Software Bill of Materials (SBOM) |
|
is blocked by
|
Developer Architecture & Design |
|
is blocked by
|
Secure Software Development Practices (SSDP) |
|
is blocked by
|
Software Assurance Maturity Model (SAMM) |
|
is blocked by
|
Supporting Toolchain |
|
is blocked by
|
Software Design Review |
|
is blocked by
|
Software Design Root Cause Analysis |
|
is blocked by
|
Secure Development Environments |
|
is blocked by
|
Separation of Development, Testing and Operational Environments |
|
is blocked by
|
Secure Migration Practices |
|
is blocked by
|
Security, Compliance & Resilience Testing Throughout Development |
|
is blocked by
|
Continuous Monitoring Plan |
|
is blocked by
|
Static Code Analysis |
|
is blocked by
|
Dynamic Code Analysis |
|
is blocked by
|
Malformed Input Testing |
|
is blocked by
|
Application Penetration Testing |
|
is blocked by
|
Secure Settings By Default |
|
is blocked by
|
Manual Code Review |
|
is blocked by
|
Use of Live Data |
|
is blocked by
|
Test Data Integrity |
|
is blocked by
|
Product Tampering and Counterfeiting (PTC) |
|
is blocked by
|
Anti-Counterfeit Training |
|
is blocked by
|
Customized Development of Critical Components |
|
is blocked by
|
Developer Screening |
|
is blocked by
|
Developer Configuration Management |
|
is blocked by
|
Software / Firmware Integrity Verification |
|
is blocked by
|
Hardware Integrity Verification |
|
is blocked by
|
Developer Threat Analysis & Flaw Remediation |
|
is blocked by
|
Developer-Provided Training |
|
is blocked by
|
Unsupported Technology Assets, Applications and/or Services (TAAS) |
|
is blocked by
|
Alternate Sources for Continued Support |
|
is blocked by
|
Input Data Validation |
|
is blocked by
|
Error Handling |
|
is blocked by
|
Access to Program Source Code |
|
is blocked by
|
Software Release Integrity Verification |
|
is blocked by
|
Archiving Software Releases |
|
is blocked by
|
Approved Code |
|
is blocked by
|
Product Conformity Governance |
|
is blocked by
|
Technical Documentation Artifacts |
|
is blocked by
|
Product-Specific Risk Assessment Artifacts |
|
is blocked by
|
Third-Party Management |
|
is blocked by
|
Third-Party Inventories |
|
is blocked by
|
Third-Party Criticality Assessments |
|
is blocked by
|
Supply Chain Risk Management (SCRM) |
|
is blocked by
|
Limit Potential Harm |
|
is blocked by
|
Processes To Address Weaknesses or Deficiencies |
|
is blocked by
|
Adequate Supply |
|
is blocked by
|
Third-Party Services |
|
is blocked by
|
Third-Party Risk Assessments & Approvals |
|
is blocked by
|
External Connectivity Requirements - Identification of Ports, Protocols & Services |
|
is blocked by
|
Conflict of Interests |
|
is blocked by
|
Third-Party Processing, Storage and Service Locations |
|
is blocked by
|
Third-Party Contract Requirements |
|
is blocked by
|
Security Compromise Notification Agreements |
|
is blocked by
|
Contract Flow-Down Requirements |
|
is blocked by
|
Third-Party Authentication Practices |
|
is blocked by
|
Responsible, Accountable, Supportive, Consulted & Informed (RASCI) Matrix |
|
is blocked by
|
Third-Party Scope Review |
|
is blocked by
|
First-Party Declaration (1PD) |
|
is blocked by
|
Third-Party Attestation (3PA) |
|
is blocked by
|
Third-Party Personnel Security |
|
is blocked by
|
Monitoring for Third-Party Information Disclosure |
|
is blocked by
|
Review of Third-Party Services |
|
is blocked by
|
Third-Party Deficiency Remediation |
|
is blocked by
|
Managing Changes To Third-Party Services |
|
is blocked by
|
Third-Party Incident Response & Recovery Capabilities |
|
is blocked by
|
Ownership Change Provisions |
|
is blocked by
|
Threat Intelligence Program |
|
is blocked by
|
Indicators of Exposure (IOE) |
|
is blocked by
|
Threat Intelligence Feeds |
|
is blocked by
|
Threat Intelligence Reporting |
|
is blocked by
|
Insider Threat Program |
|
is blocked by
|
Insider Threat Awareness |
|
is blocked by
|
Threat Hunting |
|
is blocked by
|
Threat Catalog |
|
is blocked by
|
Threat Analysis |
|
is blocked by
|
Behavioral Baselining |
|
is blocked by
|
Vulnerability & Patch Management Program (VPMP) |
|
is blocked by
|
Attack Surface Scope |
|
is blocked by
|
Vulnerability Remediation Process |
|
is blocked by
|
Vulnerability Ranking |
|
is blocked by
|
Vulnerability Exploitation Analysis |
|
is blocked by
|
Continuous Vulnerability Remediation Activities |
|
is blocked by
|
Stable Versions |
|
is blocked by
|
Flaw Remediation with Personal Data (PD) |
|
is blocked by
|
Deferred Patching Decisions |
|
is blocked by
|
Software & Firmware Patching |
|
is blocked by
|
Centralized Management of Flaw Remediation Processes |
|
is blocked by
|
Automated Remediation Status |
|
is blocked by
|
Time To Remediate / Benchmarks For Corrective Action |
|
is blocked by
|
Automated Software & Firmware Updates |
|
is blocked by
|
Removal of Previous Versions |
|
is blocked by
|
Pre-Deployment Patch Testing |
|
is blocked by
|
Out-of-Cycle Patching |
|
is blocked by
|
Software Patch Integrity |
|
is blocked by
|
Vulnerability Scanning |
|
is blocked by
|
Update Tool Capability |
|
is blocked by
|
Breadth / Depth of Coverage |
|
is blocked by
|
Privileged Access |
|
is blocked by
|
Trend Analysis |
|
is blocked by
|
Review Historical Event logs |
|
is blocked by
|
External Vulnerability Assessment Scans |
|
is blocked by
|
Internal Vulnerability Assessment Scans |
|
is blocked by
|
Penetration Testing |
|
is blocked by
|
Independent Penetration Agent or Team |
|
is blocked by
|
Reviewing Vulnerability Scanner Usage |
|
is blocked by
|
Red Team Exercises |
|
is blocked by
|
Web Security |
|
is blocked by
|
Unauthorized Code |
|
is blocked by
|
Use of Demilitarized Zones (DMZ) |
|
is blocked by
|
Client-Facing Web Services |
|
is blocked by
|
Cookie Management |
|
is blocked by
|
Strong Customer Authentication (SCA) |
|
is blocked by
|
Web Security Standard |
|
is blocked by
|
Web Application Framework |
|
is blocked by
|
Validation & Sanitization |
|
is blocked by
|
Secure Web Traffic |
|
is blocked by
|
Output Encoding |
|
is blocked by
|
Web Browser Security |
|
is blocked by
|
Website Change Detection |
|
is blocked by
|
Publicly Accessible Content Reviews |