|
is related to
|
Security, Compliance & Resilience Program (SCRP) |
|
is related to
|
Publishing Security, Compliance & Resilience Documentation |
|
is related to
|
Exception Management |
|
is related to
|
Periodic Review & Update of Security, Compliance & Resilience Program |
|
is related to
|
Assigned Security, Compliance & Resilience Responsibilities |
|
is related to
|
Stakeholder Accountability Structure |
|
is related to
|
Authoritative Chain of Command |
|
is related to
|
Purpose Validation |
|
is related to
|
Business As Usual (BAU) Security, Compliance & Resilience Practices |
|
is related to
|
Select Controls |
|
is related to
|
Implement Controls |
|
is related to
|
Assess Controls |
|
is related to
|
Authorize Technology Assets, Applications and/or Services (TAAS) |
|
is related to
|
Monitor Controls |
|
is related to
|
AI Model & Agent Inventory & Lifecycle Management |
|
is related to
|
Situational Awareness of AI & Autonomous Technologies |
|
is related to
|
AI & Autonomous Technologies Risk Mapping |
|
is related to
|
AI & Autonomous Technologies Internal Controls |
|
is related to
|
AI Threat Modeling & Risk Assessment |
|
is related to
|
AI & Autonomous Technologies Mission and Goals Definition |
|
is related to
|
Model & AI Agent Documentation |
|
is related to
|
AI & Autonomous Technologies Business Case |
|
is related to
|
AI & Autonomous Technologies Targeted Application Scope |
|
is related to
|
AI & Autonomous Technologies Training |
|
is related to
|
AI & Autonomous Technologies Risk Management Decisions |
|
is related to
|
AI & Autonomous Technologies Likelihood & Impact Risk Analysis |
|
is related to
|
AI & Autonomous Technologies Continuous Improvements |
|
is related to
|
Assigned Responsibilities for AI & Autonomous Technologies |
|
is related to
|
AI & Autonomous Technologies High Risk Designations |
|
is related to
|
Artificial Intelligence Test, Evaluation, Validation & Verification (AI TEVV) |
|
is related to
|
AI TEVV Tools |
|
is related to
|
AI & Autonomous Technologies Model Validation |
|
is related to
|
AI TEVV Comparable Deployment Settings |
|
is related to
|
AI TEVV Post-Deployment Monitoring |
|
is related to
|
Updating AI & Autonomous Technologies |
|
is related to
|
AI TEVV Third-Party Risk Management |
|
is related to
|
Robust Stakeholder Engagement for AI & Autonomous Technologies |
|
is related to
|
AI & Autonomous Technologies Stakeholder Feedback Integration |
|
is related to
|
AI & Autonomous Technologies End User Feedback |
|
is related to
|
AI & Autonomous Technologies Incident & Error Reporting |
|
is related to
|
Data Source Identification |
|
is related to
|
Data Source Integrity |
|
is related to
|
AI & Autonomous Technologies Requirements Definitions |
|
is related to
|
AI & Autonomous Technologies Implementation Tasks Definition |
|
is related to
|
AI & Autonomous Technologies Knowledge Limits |
|
is related to
|
AI & Autonomous Technologies Viability Decisions |
|
is related to
|
Responsibility To Supersede, Deactivate and/or Disengage AI & Autonomous Technologies |
|
is related to
|
AI & Autonomous Technologies Production Monitoring |
|
is related to
|
AI & Autonomous Technologies Performance Changes |
|
is related to
|
Anomaly Detection & Human Oversight |
|
is related to
|
Human-in-the-Loop & Escalation |
|
is related to
|
Emergent Behavior & Collusion Protections |
|
is related to
|
Multi-Agent Trust & Communication Validation |
|
is related to
|
AI & Autonomous Technologies Harm Prevention |
|
is related to
|
AI & Autonomous Technologies Human Subject Protections |
|
is related to
|
Previously Unknown AI & Autonomous Technologies Threats & Risks |
|
is related to
|
AI & Autonomous Technologies Risk Tracking Approaches |
|
is related to
|
AI & Autonomous Technologies Risk Response |
|
is related to
|
AI & Autonomous Technologies Transparency |
|
is related to
|
AI & Autonomous Technologies Implementation Documentation |
|
is related to
|
AI & Autonomous Technologies Human Domain Knowledge Reliance |
|
is related to
|
AI & Autonomous Technologies Registration |
|
is related to
|
AI & Autonomous Technologies Deployment |
|
is related to
|
AI & Autonomous Technologies Human Oversight |
|
is related to
|
AI & Autonomous Technologies Oversight Measures |
|
is related to
|
AI & Autonomous Technologies Separate Verification |
|
is related to
|
AI & Autonomous Technologies Oversight Functions Competency |
|
is related to
|
AI & Autonomous Technologies Data Relevance |
|
is related to
|
AI & Autonomous Technologies Irregularity Reporting |
|
is related to
|
AI & Autonomous Technologies Use Notification To Employees |
|
is related to
|
AI & Autonomous Technologies Use Notification To Users |
|
is related to
|
AI & Autonomous Technologies Output Marking |
|
is related to
|
Real World Testing of AI & Autonomous Technologies |
|
is related to
|
AI & Autonomous Technologies System Value Chain |
|
is related to
|
AI & Autonomous Technologies System Value Chain Fallbacks |
|
is related to
|
AI & Autonomous Technologies Testing Techniques |
|
is related to
|
Generative Artificial Intelligence (GAI) Identification |
|
is related to
|
AI & Autonomous Technologies Capabilities Testing |
|
is related to
|
Real-World Testing |
|
is related to
|
Documenting Testing Guidance |
|
is related to
|
AI & Autonomous Technologies Output Filtering |
|
is related to
|
Human Moderation |
|
is related to
|
AI Model Resilience |
|
is related to
|
Model Pollution |
|
is related to
|
Cascading Hallucination Defense |
|
is related to
|
Resource Exhaustion & DoS Resilience |
|
is related to
|
AI Agent Governance |
|
is related to
|
Infrastructure Hardening & Isolation |
|
is related to
|
AI Agent Limitations |
|
is related to
|
Tool & API Invocation Controls |
|
is related to
|
Orchestration Protocol Safeguards |
|
is related to
|
Data Pipeline & Input Integrity |
|
is related to
|
Privileged Role & Delegation Boundaries |
|
is related to
|
AI Agent Data Access Restrictions |
|
is related to
|
Data Extraction |
|
is related to
|
AI Agent Identity & Impersonation Defense |
|
is related to
|
AI Agent Logic Integrity |
|
is related to
|
Sandboxing AI Agents |
|
is related to
|
Prompt Injection Defense |
|
is related to
|
Agent Kill Switch / User Control |
|
is related to
|
Adversarial & Red Team Testing |
|
is related to
|
Self-Modification Controls |
|
is related to
|
Purging AI Agent Data |
|
is related to
|
Delegation and Chaining Control |
|
is related to
|
Behavioral Drift Detection |
|
is related to
|
AI Agent Action Authentication & Authorization |
|
is related to
|
Transparency & Audit |
|
is related to
|
Explainability |
|
is related to
|
Ethics, Fairness & Bias Detection |
|
is related to
|
Agent Output Integrity & Verification |
|
is related to
|
Agentic Output Traceability & Repudiation |
|
is related to
|
AI Agent Logging |
|
is related to
|
Session Management |
|
is related to
|
Human-in-the-Loop Workload & Manipulation |
|
is related to
|
Robotic Process Automation (RPA) |
|
is related to
|
Business Process Task Enumeration |
|
is related to
|
Asset Governance |
|
is related to
|
Asset-Service Dependencies |
|
is related to
|
Standardized Naming Convention |
|
is related to
|
Authorized To Connect |
|
is related to
|
Asset Inventories |
|
is related to
|
Updates During Installations / Removals |
|
is related to
|
Automated Unauthorized Component Detection |
|
is related to
|
Component Duplication Avoidance |
|
is related to
|
Approved Baseline Deviations |
|
is related to
|
Network Access Control (NAC) |
|
is related to
|
Dynamic Host Configuration Protocol (DHCP) Server Logging |
|
is related to
|
Software Licensing Restrictions |
|
is related to
|
Data Action Mapping |
|
is related to
|
Configuration Management Database (CMDB) |
|
is related to
|
Automated Location
Tracking |
|
is related to
|
Component Assignment |
|
is related to
|
Accountability Information |
|
is related to
|
Provenance |
|
is related to
|
Network Diagrams & Data Flow Diagrams (DFDs) |
|
is related to
|
Asset Scope Classification |
|
is related to
|
Control Applicability Boundary Graphical Representation |
|
is related to
|
Compliance-Specific Asset Identification |
|
is related to
|
Management Approval For External Media Transfer |
|
is related to
|
Kiosks & Point of Interaction (PoI) Devices |
|
is related to
|
Secure Disposal, Destruction or Re-Use of Equipment |
|
is related to
|
Bluetooth & Wireless Devices |
|
is related to
|
Infrared Communications |
|
is related to
|
Logical Tampering Protection |
|
is related to
|
Technology Asset Inspections |
|
is related to
|
Bring Your Own Device (BYOD) Usage |
|
is related to
|
Prohibited Equipment & Services |
|
is related to
|
Roots of Trust Protection |
|
is related to
|
Telecommunications Equipment |
|
is related to
|
Video Teleconference (VTC) Security |
|
is related to
|
Voice Over Internet Protocol (VoIP) Security |
|
is related to
|
Microphones & Web Cameras |
|
is related to
|
Multi-Function Devices (MFD) |
|
is related to
|
Travel-Only Devices |
|
is related to
|
Re-Imaging Devices After Travel |
|
is related to
|
Jump Server |
|
is related to
|
Database Management System (DBMS) |
|
is related to
|
Radio Frequency Identification (RFID) Security |
|
is related to
|
Contactless Access Control Systems |
|
is related to
|
Decommissioning |
|
is related to
|
Asset Categorization |
|
is related to
|
Categorize Artificial Intelligence (AI)-Related Technologies |
|
is related to
|
High-Risk Asset Categorization |
|
is related to
|
Asset Attributes |
|
is related to
|
Automated Network Asset Discovery |
|
is related to
|
Business Continuity Management System (BCMS) |
|
is related to
|
Coordinate with Related Plans |
|
is related to
|
Coordinate With External Service Providers |
|
is related to
|
Business Continuity & Disaster Recovery (BC/DR) Plans |
|
is related to
|
Identify Critical Assets |
|
is related to
|
Contingency Training |
|
is related to
|
Simulated Events |
|
is related to
|
Automated Training Environments |
|
is related to
|
Contingency Plan Testing & Exercises |
|
is related to
|
Contingency Plan Root Cause Analysis (RCA) & Lessons Learned |
|
is related to
|
Ongoing Contingency Planning |
|
is related to
|
Alternative Security Measures |
|
is related to
|
Alternate Storage Site |
|
is related to
|
Separation from Primary Storage Site |
|
is related to
|
Alternate Processing Site |
|
is related to
|
Telecommunications Services Availability |
|
is related to
|
Separation of Primary / Alternate Providers |
|
is related to
|
Provider Contingency Plan |
|
is related to
|
Alternate Communications Channels |
|
is related to
|
Data Backups |
|
is related to
|
Testing for Reliability & Integrity |
|
is related to
|
Separate Storage for Critical Information |
|
is related to
|
Recovery Images |
|
is related to
|
Cryptographic Protection |
|
is related to
|
Transfer to Alternate Storage Site |
|
is related to
|
Redundant Secondary System |
|
is related to
|
Backup Access |
|
is related to
|
Backup Modification and/or Destruction |
|
is related to
|
Technology Assets, Applications and/or Services (TAAS) Recovery & Reconstitution |
|
is related to
|
Transaction Recovery |
|
is related to
|
Failover Capability |
|
is related to
|
Electronic Discovery (eDiscovery) |
|
is related to
|
Restore Within Time Period |
|
is related to
|
Backup & Restoration Hardware Protection |
|
is related to
|
Isolated Recovery Environment |
|
is related to
|
AI & Autonomous Technologies Incidents |
|
is related to
|
Capacity Planning |
|
is related to
|
Performance Monitoring |
|
is related to
|
Elastic Expansion |
|
is related to
|
Regional Delivery |
|
is related to
|
Change Management Program |
|
is related to
|
Configuration Change Control |
|
is related to
|
Prohibition Of Changes |
|
is related to
|
Test, Validate & Document Changes |
|
is related to
|
Security, Compliance & Resilience Representative for Asset Lifecycle Changes |
|
is related to
|
Automated Security Response |
|
is related to
|
Cryptographic Management |
|
is related to
|
Security Impact Analysis for Changes |
|
is related to
|
Access Restriction For Change |
|
is related to
|
Automated Access Enforcement / Auditing |
|
is related to
|
Signed Components |
|
is related to
|
Dual Authorization for Change |
|
is related to
|
Library Privileges |
|
is related to
|
Stakeholder Notification of Changes |
|
is related to
|
Emergency Changes |
|
is related to
|
Documenting Emergency Changes |
|
is related to
|
Dual Approval For High-Impact Environments |
|
is related to
|
Cloud Services |
|
is related to
|
Cloud Infrastructure Security Subnet |
|
is related to
|
Application Programming Interface (API) Security |
|
is related to
|
API Gateway |
|
is related to
|
Virtual Machine Images |
|
is related to
|
Multi-Tenant Environments |
|
is related to
|
Customer Responsibility Matrix (CRM) |
|
is related to
|
Multi-Tenant Event Logging Capabilities |
|
is related to
|
Multi-Tenant Forensics Capabilities |
|
is related to
|
Multi-Tenant Incident Response Capabilities |
|
is related to
|
Standardized Virtualization Formats |
|
is related to
|
Geolocation Requirements for Processing, Storage and Service Locations |
|
is related to
|
Side Channel Attack Prevention |
|
is related to
|
Software Defined Storage (SDS) |
|
is related to
|
Compliance Scope |
|
is related to
|
Ability To Demonstrate Conformity |
|
is related to
|
Conformity Assessment |
|
is related to
|
Declaration of Conformity |
|
is related to
|
Assessment Team Subject Matter Expertise |
|
is related to
|
Security, Compliance & Resilience Controls Oversight |
|
is related to
|
Corrective Action |
|
is related to
|
Security, Compliance & Resilience Assessments |
|
is related to
|
Functional Review Of Security, Compliance & Resilience Controls |
|
is related to
|
Assessor Access |
|
is related to
|
Government Surveillance |
|
is related to
|
Localized Representation |
|
is related to
|
Representative Powers |
|
is related to
|
Statement of Applicability (SOA) |
|
is related to
|
Work Products |
|
is related to
|
Defensible Evidence of Due Diligence |
|
is related to
|
Defensible Evidence of Due Care |
|
is related to
|
Configuration Management Program |
|
is related to
|
Assignment of Responsibility |
|
is related to
|
Secure Baseline Configurations |
|
is related to
|
Reviews & Updates |
|
is related to
|
Automated Central Management & Verification |
|
is related to
|
Retention Of Previous Configurations |
|
is related to
|
Development & Test Environment Configurations |
|
is related to
|
Configure Technology Assets, Applications and/or Services (TAAS) for High-Risk Areas |
|
is related to
|
Network Device Configuration File Synchronization |
|
is related to
|
Approved Configuration Deviations |
|
is related to
|
Respond To Unauthorized Changes |
|
is related to
|
Baseline Tailoring |
|
is related to
|
Least Functionality |
|
is related to
|
Periodic Review |
|
is related to
|
Prevent Unauthorized Software Execution |
|
is related to
|
Explicitly Allow / Deny Applications |
|
is related to
|
Split Tunneling |
|
is related to
|
Software Usage Restrictions |
|
is related to
|
Open Source Software |
|
is related to
|
Unsupported Internet Browsers & Email Clients |
|
is related to
|
User-Installed Software |
|
is related to
|
Unauthorized Installation Alerts |
|
is related to
|
Restrict Roles Permitted To Install Software |
|
is related to
|
Configuration Enforcement |
|
is related to
|
Integrity Assurance & Enforcement (IAE) |
|
is related to
|
Zero-Touch Provisioning (ZTP) |
|
is related to
|
Sensitive / Regulated Data Access Enforcement |
|
is related to
|
Sensitive / Regulated Data Actions |
|
is related to
|
Continuous Monitoring |
|
is related to
|
Intrusion Detection & Prevention Systems (IDS & IPS) |
|
is related to
|
Automated Tools for Real-Time Analysis |
|
is related to
|
Inbound & Outbound Communications Traffic |
|
is related to
|
System Generated Alerts |
|
is related to
|
Wireless Network Monitoring |
|
is related to
|
Host-Based Devices |
|
is related to
|
File Integrity Monitoring (FIM) |
|
is related to
|
Security Event Monitoring |
|
is related to
|
Proxy Logging |
|
is related to
|
Deactivated Account Activity |
|
is related to
|
Automated Response to Suspicious Events |
|
is related to
|
Automated Alerts |
|
is related to
|
Alert Threshold Tuning |
|
is related to
|
Individuals Posing Greater Risk |
|
is related to
|
Real-Time Session Monitoring |
|
is related to
|
Centralized Collection of Security Event Logs |
|
is related to
|
Correlate Monitoring Information |
|
is related to
|
Central Review & Analysis |
|
is related to
|
Integration of Scanning & Other Monitoring Information |
|
is related to
|
Correlation with Physical Monitoring |
|
is related to
|
Permitted Actions |
|
is related to
|
Audit Level Adjustments |
|
is related to
|
System-Wide / Time-Correlated Audit Trail |
|
is related to
|
Changes by Authorized Individuals |
|
is related to
|
Inventory of Technology Asset Event Logging |
|
is related to
|
Content of Event Logs |
|
is related to
|
Sensitive Event Log Information |
|
is related to
|
Audit Trails |
|
is related to
|
Privileged Functions Logging |
|
is related to
|
Verbosity Logging for Boundary Devices |
|
is related to
|
Limit Personal Data (PD) In Audit Records |
|
is related to
|
Centralized Management of Event Log Content |
|
is related to
|
Database Logging |
|
is related to
|
Event Log Storage Capacity |
|
is related to
|
Response To Event Log Processing Failures |
|
is related to
|
Real-Time Alerts of Event Logging Failure |
|
is related to
|
Event Log Storage Capacity Alerting |
|
is related to
|
Monitoring Reporting |
|
is related to
|
Query Parameter Audits of Personal Data (PD) |
|
is related to
|
Trend Analysis Reporting |
|
is related to
|
Time Stamps |
|
is related to
|
Synchronization With Authoritative Time Source |
|
is related to
|
Protection of Event Logs |
|
is related to
|
Event Log Backup on Separate Physical Systems / Components |
|
is related to
|
Access by Subset of Privileged Users |
|
is related to
|
Cryptographic Protection of Event Log Information |
|
is related to
|
Dual Authorization for Event Log Movement |
|
is related to
|
Non-Repudiation |
|
is related to
|
Identity Binding |
|
is related to
|
Event Log Retention |
|
is related to
|
Monitoring For Information Disclosure |
|
is related to
|
Analyze Traffic for Covert Exfiltration |
|
is related to
|
Unauthorized Network Services |
|
is related to
|
Monitoring for Indicators of Compromise (IOC) |
|
is related to
|
Session Audit |
|
is related to
|
Alternate Event Logging Capability |
|
is related to
|
Cross-Organizational Monitoring |
|
is related to
|
Sharing of Event Logs |
|
is related to
|
Covert Channel Analysis |
|
is related to
|
Anomalous Behavior |
|
is related to
|
Insider Threats |
|
is related to
|
Third-Party Threats |
|
is related to
|
Unauthorized Activities |
|
is related to
|
Account Creation and Modification Logging |
|
is related to
|
Event Log Analysis & Triage |
|
is related to
|
Event Log Review Escalation Matrix |
|
is related to
|
File Activity Monitoring (FAM) |
|
is related to
|
Write Once Read Many (WORM) Event Log Generation |
|
is related to
|
Use of Cryptographic Controls |
|
is related to
|
Pre/Post Transmission Handling |
|
is related to
|
Conceal / Randomize Communications |
|
is related to
|
Cryptographic Cipher Suites and Protocols Inventory |
|
is related to
|
Automated Authentication Through Cryptographic Modules |
|
is related to
|
Transmission Confidentiality |
|
is related to
|
Transmission Integrity |
|
is related to
|
Encrypting Data At Rest |
|
is related to
|
Storage Media |
|
is related to
|
Offline Storage |
|
is related to
|
Database Encryption |
|
is related to
|
Non-Console Administrative Access |
|
is related to
|
Wireless Access Authentication & Encryption |
|
is related to
|
Public Key Infrastructure (PKI) |
|
is related to
|
Availability |
|
is related to
|
Cryptographic Key Management |
|
is related to
|
Symmetric Keys |
|
is related to
|
Asymmetric Keys |
|
is related to
|
Cryptographic Key Loss or Change |
|
is related to
|
Control & Distribution of Cryptographic Keys |
|
is related to
|
Assigned Owners |
|
is related to
|
Third-Party Cryptographic Keys |
|
is related to
|
External System Cryptographic Key Control |
|
is related to
|
Transmission of Cybersecurity & Data Protection Attributes |
|
is related to
|
Cryptographic Hash |
|
is related to
|
Data Stewardship |
|
is related to
|
Sensitive / Regulated Data Protection |
|
is related to
|
Defining Access Authorizations for Sensitive / Regulated Data |
|
is related to
|
Data & Asset Classification |
|
is related to
|
Highest Classification Level |
|
is related to
|
Media Access |
|
is related to
|
Disclosure of Information |
|
is related to
|
Masking Displayed Data |
|
is related to
|
Controlled Release |
|
is related to
|
Media Marking |
|
is related to
|
Automated Marking |
|
is related to
|
Cybersecurity & Data Protection Attributes |
|
is related to
|
Dynamic Attribute Association |
|
is related to
|
Attribute Value Changes By Authorized Individuals |
|
is related to
|
Maintenance of Attribute Associations By System |
|
is related to
|
Association of Attributes By Authorized Individuals |
|
is related to
|
Attribute Displays for Output Devices |
|
is related to
|
Data Subject Attribute Associations |
|
is related to
|
Consistent Attribute Interpretation |
|
is related to
|
Identity Association Techniques & Technologies |
|
is related to
|
Attribute Reassignment |
|
is related to
|
Attribute Configuration By Authorized Individuals |
|
is related to
|
Audit Changes |
|
is related to
|
Media Storage |
|
is related to
|
Periodic Scans for Sensitive / Regulated Data |
|
is related to
|
Making Sensitive Data Unreadable In Storage |
|
is related to
|
Storing Authentication Data |
|
is related to
|
Encrypting Data In Storage Media |
|
is related to
|
Physical Media Disposal |
|
is related to
|
System Media Sanitization |
|
is related to
|
Equipment Testing |
|
is related to
|
Sanitization of Personal Data (PD) |
|
is related to
|
First Time Use Sanitization |
|
is related to
|
Dual Authorization for Sensitive Data Destruction |
|
is related to
|
Prohibit Use Without Owner |
|
is related to
|
Data Reclassification |
|
is related to
|
Removable Media Security |
|
is related to
|
Use of External Technology Assets, Applications and/or Services (TAAS) |
|
is related to
|
Limits of Authorized Use |
|
is related to
|
Portable Storage Devices |
|
is related to
|
Protecting Sensitive / Regulated Data on External Technology Assets, Applications and/or Services (TAAS) |
|
is related to
|
Non-Organizationally Owned Technology Assets, Applications and/or Services (TAAS) |
|
is related to
|
Information Search & Retrieval |
|
is related to
|
Publicly Accessible Content |
|
is related to
|
Data Mining Protection |
|
is related to
|
Ad-Hoc Transfers |
|
is related to
|
Media & Data Retention |
|
is related to
|
Limit Sensitive / Regulated Data In Testing, Training & Research |
|
is related to
|
Temporary Files Containing Personal Data (PD) |
|
is related to
|
Geographic Location of Data |
|
is related to
|
Information Disposal |
|
is related to
|
Data Tags |
|
is related to
|
De-Identification (Anonymization) |
|
is related to
|
Removal, Masking, Encryption, Hashing or Replacement of Direct Identifiers |
|
is related to
|
Automated De-Identification of Sensitive Data |
|
is related to
|
Information Location |
|
is related to
|
Automated Tools to Support Information Location |
|
is related to
|
Data Localization |
|
is related to
|
Data Rights Management (DRM) |
|
is related to
|
Embedded Technology Security Program |
|
is related to
|
Interface Security |
|
is related to
|
Embedded Technology Configuration Monitoring |
|
is related to
|
Prevent Alterations |
|
is related to
|
Embedded Technology Maintenance |
|
is related to
|
Resilience To Outages |
|
is related to
|
Power Level Monitoring |
|
is related to
|
Embedded Technology Reviews |
|
is related to
|
Message Queuing Telemetry Transport (MQTT) Security |
|
is related to
|
Restrict Communications |
|
is related to
|
Authorized Communications |
|
is related to
|
Operating Environment Certification |
|
is related to
|
Safety Assessment |
|
is related to
|
Certificate-Based Authentication |
|
is related to
|
Chip-To-Cloud Security |
|
is related to
|
Real-Time Operating System (RTOS) Security |
|
is related to
|
Safe Operations |
|
is related to
|
Endpoint Device Management (EDM) |
|
is related to
|
Unified Endpoint Device Management (UEDM) |
|
is related to
|
Endpoint Protection Measures |
|
is related to
|
Prohibit Installation Without Privileged Status |
|
is related to
|
Software Installation Alerts |
|
is related to
|
Governing Access Restriction for Change |
|
is related to
|
Malicious Code Protection (Anti-Malware) |
|
is related to
|
Automatic Antimalware Signature Updates |
|
is related to
|
Centralized Management of Antimalware Technologies |
|
is related to
|
Heuristic / Nonsignature-Based Detection |
|
is related to
|
Malware Protection Mechanism Testing |
|
is related to
|
Always On Protection |
|
is related to
|
Software Firewall |
|
is related to
|
Endpoint File Integrity Monitoring (FIM) |
|
is related to
|
Integrity Checks |
|
is related to
|
Automated Notifications of Integrity Violations |
|
is related to
|
Automated Response to Integrity Violations |
|
is related to
|
Boot Process Integrity |
|
is related to
|
Protection of Boot Firmware |
|
is related to
|
Binary or Machine-Executable Code |
|
is related to
|
Extended Detection & Response (XDR) |
|
is related to
|
Host Intrusion Detection and Prevention Systems (HIDS / HIPS) |
|
is related to
|
Phishing & Spam Protection |
|
is related to
|
Central Management |
|
is related to
|
Automatic Spam and Phishing Protection Updates |
|
is related to
|
Trusted Path |
|
is related to
|
Mobile Code |
|
is related to
|
Thin Nodes |
|
is related to
|
Port & Input / Output (I/O) Device Access |
|
is related to
|
Sensor Capability |
|
is related to
|
Notice of Collection |
|
is related to
|
Collaborative Computing Devices |
|
is related to
|
Disabling / Removal In Secure Work Areas |
|
is related to
|
Explicitly Indicate Current Participants |
|
is related to
|
Participant Identity Verification |
|
is related to
|
Participant Connection Management |
|
is related to
|
Malicious Link & File Protections |
|
is related to
|
Explicit Indication Of Use |
|
is related to
|
Hypervisor Access |
|
is related to
|
Restrict Access To Security Functions |
|
is related to
|
Host-Based Security Function Isolation |
|
is related to
|
Human Resources Security Management |
|
is related to
|
Onboarding, Transferring & Offboarding Personnel |
|
is related to
|
Personnel Screening |
|
is related to
|
Citizenship Identification |
|
is related to
|
Rules of Behavior |
|
is related to
|
Technology Use Restrictions |
|
is related to
|
Use of Critical Technologies |
|
is related to
|
Use of Mobile Devices |
|
is related to
|
Access Agreements |
|
is related to
|
Confidentiality Agreements |
|
is related to
|
Updating Disciplinary Processes |
|
is related to
|
Preventative Access Restriction |
|
is related to
|
Automated Employment Status Notifications |
|
is related to
|
Separation of Duties (SoD) |
|
is related to
|
Identity & Access Management (IAM) |
|
is related to
|
Authenticate, Authorize and Audit (AAA) |
|
is related to
|
User & Service Account Inventories |
|
is related to
|
Identification & Authentication for Organizational Users |
|
is related to
|
Group Authentication |
|
is related to
|
Replay-Resistant Authentication |
|
is related to
|
Acceptance of PIV Credentials |
|
is related to
|
Out-of-Band Authentication (OOBA) |
|
is related to
|
Identification & Authentication for Non-Organizational Users |
|
is related to
|
Acceptance of PIV Credentials from Other Organizations |
|
is related to
|
Acceptance of Third-Party Credentials |
|
is related to
|
Use of FICAM-Issued Profiles |
|
is related to
|
Disassociability |
|
is related to
|
Acceptance of External Authenticators |
|
is related to
|
Identification & Authentication for Devices |
|
is related to
|
Device Attestation |
|
is related to
|
Device Authorization Enforcement |
|
is related to
|
Identification & Authentication for Third-Party Technology Assets, Applications and/or Services (TAAS) |
|
is related to
|
Sharing Identification & Authentication Information |
|
is related to
|
Privileged Access by Non-Organizational Users |
|
is related to
|
Multi-Factor Authentication (MFA) |
|
is related to
|
Network Access to Privileged Accounts |
|
is related to
|
Network Access to Non-Privileged Accounts |
|
is related to
|
Local Access to Privileged Accounts |
|
is related to
|
Out-of-Band Multi-Factor Authentication |
|
is related to
|
Alternative Multi-Factor Authentication |
|
is related to
|
User Provisioning & De-Provisioning |
|
is related to
|
Termination of Employment |
|
is related to
|
Role-Based Access Control (RBAC) |
|
is related to
|
Identifier Management (User Names) |
|
is related to
|
User Identity (ID) Management |
|
is related to
|
Identity User Status |
|
is related to
|
Dynamic Management |
|
is related to
|
Cross-Organization Management |
|
is related to
|
Privileged Account Identifiers |
|
is related to
|
Pairwise Pseudonymous Identifiers (PPID) |
|
is related to
|
Authenticator Management |
|
is related to
|
Password-Based Authentication |
|
is related to
|
PKI-Based Authentication |
|
is related to
|
Automated Support For Password Strength |
|
is related to
|
Protection of Authenticators |
|
is related to
|
No Embedded Unencrypted Static Authenticators |
|
is related to
|
Hardware Token-Based Authentication |
|
is related to
|
Default Authenticators |
|
is related to
|
Multiple System Accounts |
|
is related to
|
Expiration of Cached Authenticators |
|
is related to
|
Password Managers |
|
is related to
|
Biometric Authentication |
|
is related to
|
Events Requiring Authenticator Change |
|
is related to
|
Passkeys |
|
is related to
|
Authenticator Feedback |
|
is related to
|
Cryptographic Module Authentication |
|
is related to
|
Hardware Security Modules (HSM) |
|
is related to
|
Adaptive Identification & Authentication |
|
is related to
|
Single Sign-On (SSO) Transparent Authentication |
|
is related to
|
Federated Credential Management |
|
is related to
|
Continuous Authentication |
|
is related to
|
Re-Authentication |
|
is related to
|
Account Management |
|
is related to
|
Automated System Account Management (Directory Services) |
|
is related to
|
Removal of Temporary / Emergency Accounts |
|
is related to
|
Disable Inactive Accounts |
|
is related to
|
Automated Audit Actions |
|
is related to
|
Restrictions on Shared Groups / Accounts |
|
is related to
|
Account Disabling for High Risk Individuals |
|
is related to
|
System Account Reviews |
|
is related to
|
Usage Conditions |
|
is related to
|
Emergency Accounts |
|
is related to
|
Privileged Account Management (PAM) |
|
is related to
|
Privileged Account Inventories |
|
is related to
|
Privileged Account Separation |
|
is related to
|
Privileged Command Execution |
|
is related to
|
Dedicated Privileged Account |
|
is related to
|
Manual Override |
|
is related to
|
Periodic Review of Account Privileges |
|
is related to
|
Access Enforcement |
|
is related to
|
Access To Sensitive / Regulated Data |
|
is related to
|
Database Access |
|
is related to
|
Use of Privileged Utility Programs |
|
is related to
|
Dedicated Administrative Machines |
|
is related to
|
Dual Authorization for Privileged Commands |
|
is related to
|
Revocation of Access Authorizations |
|
is related to
|
Authorized System Accounts |
|
is related to
|
Least Privilege |
|
is related to
|
Authorize Access to Security Functions |
|
is related to
|
Non-Privileged Access for Non-Security Functions |
|
is related to
|
Management Approval For Privileged Accounts |
|
is related to
|
Auditing Use of Privileged Functions |
|
is related to
|
Prohibit Non-Privileged Users from Executing Privileged Functions |
|
is related to
|
Network Access to Privileged Commands |
|
is related to
|
Privilege Levels for Code Execution |
|
is related to
|
Account Lockout |
|
is related to
|
Concurrent Session Control |
|
is related to
|
Session Lock |
|
is related to
|
Pattern-Hiding Displays |
|
is related to
|
Session Termination |
|
is related to
|
User-Initiated Logouts / Message Displays |
|
is related to
|
Permitted Actions Without Identification or Authorization |
|
is related to
|
Reference Monitor |
|
is related to
|
Identity Proofing (Identity Verification) |
|
is related to
|
Management Approval For New or Changed Accounts |
|
is related to
|
Attribute-Based Access Control (ABAC) |
|
is related to
|
Real-Time Access Decisions |
|
is related to
|
Access Profile Rules |
|
is related to
|
Mutual Authentication (MA) |
|
is related to
|
Incident Response Operations |
|
is related to
|
Automated Incident Handling Processes |
|
is related to
|
Insider Threat Response Capability |
|
is related to
|
Dynamic Reconfiguration |
|
is related to
|
Automatic Disabling of Technology Assets, Applications and/or Services (TAAS) |
|
is related to
|
Indicators of Compromise (IOC) |
|
is related to
|
Incident Response Plan (IRP) |
|
is related to
|
Data Breach |
|
is related to
|
IRP Update |
|
is related to
|
Incident Response Training |
|
is related to
|
Automated Incident Response Training Environments |
|
is related to
|
Incident Response Testing |
|
is related to
|
Integrated Security Incident Response Team (ISIRT) |
|
is related to
|
Chain of Custody & Forensics |
|
is related to
|
Licensed Forensic Investigators |
|
is related to
|
Situational Awareness For Incidents |
|
is related to
|
Automated Tracking, Data Collection & Analysis |
|
is related to
|
Recurring Incident Analysis |
|
is related to
|
Incident Tracking Repository |
|
is related to
|
Automated Reporting |
|
is related to
|
Supply Chain Coordination |
|
is related to
|
Serious Incident Reporting |
|
is related to
|
Automation Support of Availability of Information / Support |
|
is related to
|
Coordination With External Providers |
|
is related to
|
Sensitive / Regulated Data Spill Response |
|
is related to
|
Sensitive / Regulated Data Spill Responsible Personnel |
|
is related to
|
Post-Sensitive / Regulated Data Spill Operations |
|
is related to
|
Root Cause Analysis (RCA) & Lessons Learned |
|
is related to
|
Detonation Chambers (Sandboxes) |
|
is related to
|
Information Assurance (IA) Operations |
|
is related to
|
Assessments |
|
is related to
|
Specialized Assessments |
|
is related to
|
Third-Party Assessment Reciprocity |
|
is related to
|
Applied Security, Compliance and Resilience Controls Documentation |
|
is related to
|
Plan / Coordinate with Other Organizational Entities |
|
is related to
|
Adequate Security for Sensitive / Regulated Data In Support of Contracts |
|
is related to
|
Threat Analysis & Flaw Remediation During Development |
|
is related to
|
Capabilities Deficiency Tracking |
|
is related to
|
Deficiency Tracking Automation |
|
is related to
|
Technical Verification |
|
is related to
|
Security Authorization |
|
is related to
|
Maintenance Operations |
|
is related to
|
Controlled Maintenance |
|
is related to
|
Automated Maintenance Activities |
|
is related to
|
Timely Maintenance |
|
is related to
|
Preventative Maintenance |
|
is related to
|
Predictive Maintenance |
|
is related to
|
Automated Support For Predictive Maintenance |
|
is related to
|
Maintenance Tools |
|
is related to
|
Inspect Tools |
|
is related to
|
Inspect Media |
|
is related to
|
Prevent Unauthorized Removal |
|
is related to
|
Restrict Tool Usage |
|
is related to
|
Remote Maintenance |
|
is related to
|
Auditing Remote Maintenance |
|
is related to
|
Remote Maintenance Notifications |
|
is related to
|
Remote Maintenance Cryptographic Protection |
|
is related to
|
Remote Maintenance Disconnect Verification |
|
is related to
|
Remote Maintenance Pre-Approval |
|
is related to
|
Remote Maintenance Comparable Security & Sanitization |
|
is related to
|
Separation of Maintenance Sessions |
|
is related to
|
Authorized Maintenance Personnel |
|
is related to
|
Maintenance Personnel Without Appropriate Access |
|
is related to
|
Maintain Configuration Control During Maintenance |
|
is related to
|
Field Maintenance |
|
is related to
|
Off-Site Maintenance |
|
is related to
|
Maintenance Validation |
|
is related to
|
Maintenance Monitoring |
|
is related to
|
Centralized Management Of Mobile Devices |
|
is related to
|
Access Control For Mobile Devices |
|
is related to
|
Full Device & Container-Based Encryption |
|
is related to
|
Mobile Device Tampering |
|
is related to
|
Remote Purging |
|
is related to
|
Personally-Owned Mobile Devices |
|
is related to
|
Organization-Owned Mobile Devices |
|
is related to
|
Mobile Device Data Retention Limitations |
|
is related to
|
Mobile Device Geofencing |
|
is related to
|
Separate Mobile Device Profiles |
|
is related to
|
Restricting Access To Authorized Technology Assets, Applications and/or Services (TAAS) |
|
is related to
|
Network Security Controls (NSC) |
|
is related to
|
Zero Trust Architecture (ZTA) |
|
is related to
|
Layered Network Defenses |
|
is related to
|
Denial of Service (DoS) Protection |
|
is related to
|
Guest Networks |
|
is related to
|
Cross Domain Solution (CDS) |
|
is related to
|
Limit Network Connections |
|
is related to
|
External Telecommunications Services |
|
is related to
|
Prevent Discovery of Internal Information |
|
is related to
|
Personal Data (PD) |
|
is related to
|
Prevent Unauthorized Exfiltration |
|
is related to
|
Dynamic Isolation & Segregation (Sandboxing) |
|
is related to
|
Isolation of System Components |
|
is related to
|
Separate Subnet for Connecting to Different Security Domains |
|
is related to
|
Data Flow Enforcement – Access Control Lists (ACLs) |
|
is related to
|
Deny Traffic by Default & Allow Traffic by Exception |
|
is related to
|
Object Security Attributes |
|
is related to
|
Content Check for Encrypted Data |
|
is related to
|
Embedded Data Types |
|
is related to
|
Metadata |
|
is related to
|
Policy Decision Point (PDP) |
|
is related to
|
Data Type Identifiers |
|
is related to
|
Decomposition Into Policy-Related Subcomponents |
|
is related to
|
Detection of Unsanctioned Information |
|
is related to
|
Cross Domain Authentication |
|
is related to
|
Metadata Validation |
|
is related to
|
Application Proxy |
|
is related to
|
Interconnection Security Agreements (ISAs) |
|
is related to
|
External System Connections |
|
is related to
|
Internal System Connections |
|
is related to
|
Network Segmentation (macrosegementation) |
|
is related to
|
Security Management Subnets |
|
is related to
|
Virtual Local Area Network (VLAN) Separation |
|
is related to
|
Sensitive / Regulated Data Enclave (Secure Zone) |
|
is related to
|
Segregation From Enterprise Services |
|
is related to
|
Direct Internet Access Restrictions |
|
is related to
|
Microsegmentation |
|
is related to
|
Network Connection Termination |
|
is related to
|
Network Intrusion Detection / Prevention Systems (NIDS / NIPS) |
|
is related to
|
DMZ Networks |
|
is related to
|
Wireless Intrusion Detection / Prevention Systems (WIDS / WIPS) Deployment |
|
is related to
|
Host Containment |
|
is related to
|
Resource Containment |
|
is related to
|
Session Integrity |
|
is related to
|
Invalidate Session Identifiers at Logout |
|
is related to
|
Unique System-Generated Session Identifiers |
|
is related to
|
Domain Name Service (DNS) Resolution |
|
is related to
|
Architecture & Provisioning for Name / Address Resolution Service |
|
is related to
|
Secure Name / Address Resolution Service (Recursive or Caching Resolver) |
|
is related to
|
Sender Policy Framework (SPF) |
|
is related to
|
Domain Registrar Security |
|
is related to
|
Out-of-Band Channels |
|
is related to
|
Safeguarding Data Over Open Networks |
|
is related to
|
Wireless Link Protection |
|
is related to
|
End-User Messaging Technologies |
|
is related to
|
Electronic Messaging |
|
is related to
|
Remote Access |
|
is related to
|
Automated Monitoring & Control |
|
is related to
|
Protection of Confidentiality / Integrity Using Encryption |
|
is related to
|
Managed Access Control Points |
|
is related to
|
Remote Privileged Commands & Sensitive Data Access |
|
is related to
|
Work From Anywhere (WFA) - Telecommuting Security |
|
is related to
|
Third-Party Remote Access Governance |
|
is related to
|
Endpoint Security Validation |
|
is related to
|
Expeditious Disconnect / Disable Capability |
|
is related to
|
Wireless Networking |
|
is related to
|
Authentication & Encryption |
|
is related to
|
Disable Wireless Networking |
|
is related to
|
Restrict Configuration By Users |
|
is related to
|
Wireless Boundaries |
|
is related to
|
Rogue Wireless Detection |
|
is related to
|
Intranets |
|
is related to
|
Data Loss Prevention (DLP) |
|
is related to
|
DNS & Content Filtering |
|
is related to
|
Route Internal Traffic to Proxy Servers |
|
is related to
|
Visibility of Encrypted Communications |
|
is related to
|
Route Privileged Network Access |
|
is related to
|
Protocol Compliance Enforcement |
|
is related to
|
Domain Name Verification |
|
is related to
|
Internet Address Denylisting |
|
is related to
|
Bandwidth Control |
|
is related to
|
Authenticated Proxy |
|
is related to
|
Certificate Denylisting |
|
is related to
|
Content Disarm and Reconstruction (CDR) |
|
is related to
|
Email Content Protections |
|
is related to
|
Email Domain Reputation Protections |
|
is related to
|
Sender Denylisting |
|
is related to
|
User Digital Signatures for Outgoing Email |
|
is related to
|
Encryption for Outgoing Email |
|
is related to
|
Adaptive Email Protections |
|
is related to
|
Email Labeling |
|
is related to
|
User Threat Reporting |
|
is related to
|
Physical & Environmental Protections |
|
is related to
|
Physical Access Authorizations |
|
is related to
|
Role-Based Physical Access |
|
is related to
|
Physical Access Control |
|
is related to
|
Lockable Physical Casings |
|
is related to
|
Physical Access Logs |
|
is related to
|
Access To Critical Systems |
|
is related to
|
Monitoring Physical Access |
|
is related to
|
Intrusion Alarms / Surveillance Equipment |
|
is related to
|
Monitoring Physical Access To Critical Systems |
|
is related to
|
Automated Records Management & Review |
|
is related to
|
Minimize Visitor Personal Data (PD) |
|
is related to
|
Visitor Access Revocation |
|
is related to
|
Redundant Cabling |
|
is related to
|
Automatic Fire Suppression |
|
is related to
|
Temperature & Humidity Controls |
|
is related to
|
Monitoring with Alarms / Notifications |
|
is related to
|
Delivery & Removal |
|
is related to
|
Alternate Work Site |
|
is related to
|
Equipment Siting & Protection |
|
is related to
|
Transmission Medium Security |
|
is related to
|
Access Control for Output Devices |
|
is related to
|
Information Leakage Due To Electromagnetic Signals Emanations |
|
is related to
|
Asset Monitoring and Tracking |
|
is related to
|
Electromagnetic Pulse (EMP) Protection |
|
is related to
|
Proximity Sensor |
|
is related to
|
Data Privacy Program |
|
is related to
|
Reasonable Data Privacy Practices |
|
is related to
|
Automated Data Management Processes |
|
is related to
|
Computer Matching Agreements (CMA) |
|
is related to
|
System of Records Notice (SORN) |
|
is related to
|
Real-Time or Layered Notice |
|
is related to
|
Product or Service Delivery Restrictions |
|
is related to
|
Authorized Agent |
|
is related to
|
Active Participation By Data Subjects |
|
is related to
|
Global Privacy Control (GPC) |
|
is related to
|
Continued Use of Personal Data (PD) |
|
is related to
|
Cease Processing, Storing and/or Sharing Personal Data (PD) |
|
is related to
|
Communicating Processing Changes |
|
is related to
|
Identifiable Image Collection |
|
is related to
|
Acquired Personal Data (PD) |
|
is related to
|
Validate Collected Personal Data (PD) |
|
is related to
|
Re-Validate Collected Personal Data (PD) |
|
is related to
|
Personal Data (PD) Collection Methods |
|
is related to
|
Personal Data (PD) Retention & Disposal |
|
is related to
|
Data Masking |
|
is related to
|
Usage Restrictions of Personal Data (PD) |
|
is related to
|
Personal Data (PD) Inventory Automation Support |
|
is related to
|
Personal Data (PD) Formats |
|
is related to
|
Appeal Adverse Decision |
|
is related to
|
User Feedback Management |
|
is related to
|
Data Portability |
|
is related to
|
Data Privacy Requirements for Contractors & Service Providers |
|
is related to
|
Data Quality Automation |
|
is related to
|
Data Tagging |
|
is related to
|
Updating Personal Data (PD) Process |
|
is related to
|
Enabling Data Subjects To Update Personal Data (PD) |
|
is related to
|
Documenting Data Processing Activities |
|
is related to
|
Data Subject Communications |
|
is related to
|
Conspicuous Link To Data Privacy Notice |
|
is related to
|
Notice of Financial Incentive |
|
is related to
|
Data Controller Communications |
|
is related to
|
Security, Compliance & Resilience Resource Management |
|
is related to
|
Security, Compliance & Resilience In Project Management |
|
is related to
|
Security, Compliance & Resilience Requirements Definition |
|
is related to
|
Business Process Definition |
|
is related to
|
Secure Development Life Cycle (SDLC) Management |
|
is related to
|
Risk Management Program |
|
is related to
|
Risk Tolerance |
|
is related to
|
Risk Threshold |
|
is related to
|
Risk Appetite |
|
is related to
|
Risk-Based Security Categorization |
|
is related to
|
Risk Catalog |
|
is related to
|
Risk Assessment |
|
is related to
|
Risk Assessment Stakeholder Involvement |
|
is related to
|
Risk Remediation |
|
is related to
|
Risk Response |
|
is related to
|
Risk Treatment Options |
|
is related to
|
Risk Treatment Plan (RTP) |
|
is related to
|
Business Impact Analysis (BIA) |
|
is related to
|
Supply Chain Risk Management (SCRM) Plan |
|
is related to
|
Data Protection Impact Assessment (DPIA) |
|
is related to
|
Secure Engineering Principles |
|
is related to
|
Alignment With Enterprise Architecture |
|
is related to
|
Technical Debt Reviews |
|
is related to
|
System Partitioning |
|
is related to
|
Application Partitioning |
|
is related to
|
Process Isolation |
|
is related to
|
Security Function Isolation |
|
is related to
|
Hardware Separation |
|
is related to
|
Thread Separation |
|
is related to
|
System Privileges Isolation |
|
is related to
|
Information In Shared Resources |
|
is related to
|
Prevent Program Execution |
|
is related to
|
Predictable Failure Analysis |
|
is related to
|
Technology Lifecycle Management |
|
is related to
|
Fail Secure |
|
is related to
|
Fail Safe |
|
is related to
|
Non-Persistence |
|
is related to
|
Refresh from Trusted Sources |
|
is related to
|
Information Output Filtering |
|
is related to
|
Limit Personal Data (PD) Dissemination |
|
is related to
|
Memory Protection |
|
is related to
|
Honeypots |
|
is related to
|
Honeyclients |
|
is related to
|
Heterogeneity |
|
is related to
|
Virtualization Techniques |
|
is related to
|
Concealment & Misdirection |
|
is related to
|
Randomness |
|
is related to
|
Change Processing & Storage Locations |
|
is related to
|
Distributed Processing & Storage |
|
is related to
|
Non-Modifiable Executable Programs |
|
is related to
|
Secure Log-On Procedures |
|
is related to
|
System Use Notification (Logon Banner) |
|
is related to
|
Standardized Microsoft Windows Banner |
|
is related to
|
Truncated Banner |
|
is related to
|
Previous Logon Notification |
|
is related to
|
Clock Synchronization |
|
is related to
|
Application Container |
|
is related to
|
Privileged Environments |
|
is related to
|
Operations Security |
|
is related to
|
Security Concept Of Operations (CONOPS) |
|
is related to
|
Security Operations Center (SOC) |
|
is related to
|
Security Orchestration, Automation, and Response (SOAR) |
|
is related to
|
Shadow Information Technology Detection |
|
is related to
|
Security, Compliance & Resilience Knowledge Sharing |
|
is related to
|
Technology Development & Acquisition |
|
is related to
|
Integrity Mechanisms for Software / Firmware Updates |
|
is related to
|
Malware Testing Prior to Release |
|
is related to
|
Minimum Viable Product (MVP) Security Requirements |
|
is related to
|
Ports, Protocols & Services In Use |
|
is related to
|
Information Assurance Enabled Products |
|
is related to
|
Development Methods, Techniques & Processes |
|
is related to
|
Pre-Established Secure Configurations |
|
is related to
|
Identification & Justification of Ports, Protocols & Services |
|
is related to
|
Insecure Ports, Protocols & Services |
|
is related to
|
Minimizing Attack Surfaces |
|
is related to
|
Ongoing Product Security Support |
|
is related to
|
Product Testing & Reviews |
|
is related to
|
Disclosure of Vulnerabilities |
|
is related to
|
Products With Digital Elements |
|
is related to
|
Reporting Exploitable Vulnerabilities |
|
is related to
|
Logging Syntax |
|
is related to
|
Commercial Off-The-Shelf (COTS) Security Solutions |
|
is related to
|
Supplier Diversity |
|
is related to
|
Documentation Requirements |
|
is related to
|
Functional Properties |
|
is related to
|
Software Bill of Materials (SBOM) |
|
is related to
|
Developer Architecture & Design |
|
is related to
|
Physical Diagnostic & Test Interfaces |
|
is related to
|
Diagnostic & Test Interface Monitoring |
|
is related to
|
Secure Software Development Practices (SSDP) |
|
is related to
|
Criticality Analysis During Development |
|
is related to
|
Threat Modeling |
|
is related to
|
Supporting Toolchain |
|
is related to
|
Software Design Review |
|
is related to
|
Software Design Root Cause Analysis |
|
is related to
|
Secure Development Environments |
|
is related to
|
Separation of Development, Testing and Operational Environments |
|
is related to
|
Secure Migration Practices |
|
is related to
|
Security, Compliance & Resilience Testing Throughout Development |
|
is related to
|
Continuous Monitoring Plan |
|
is related to
|
Secure Settings By Default |
|
is related to
|
Manual Code Review |
|
is related to
|
Use of Live Data |
|
is related to
|
Test Data Integrity |
|
is related to
|
Product Tampering and Counterfeiting (PTC) |
|
is related to
|
Anti-Counterfeit Training |
|
is related to
|
Customized Development of Critical Components |
|
is related to
|
Developer Screening |
|
is related to
|
Developer Configuration Management |
|
is related to
|
Software / Firmware Integrity Verification |
|
is related to
|
Hardware Integrity Verification |
|
is related to
|
Developer Threat Analysis & Flaw Remediation |
|
is related to
|
Developer-Provided Training |
|
is related to
|
Unsupported Technology Assets, Applications and/or Services (TAAS) |
|
is related to
|
Alternate Sources for Continued Support |
|
is related to
|
Input Data Validation |
|
is related to
|
Error Handling |
|
is related to
|
Access to Program Source Code |
|
is related to
|
Software Release Integrity Verification |
|
is related to
|
Archiving Software Releases |
|
is related to
|
Software Escrow |
|
is related to
|
Approved Code |
|
is related to
|
Product Conformity Governance |
|
is related to
|
Technical Documentation Artifacts |
|
is related to
|
Product-Specific Risk Assessment Artifacts |
|
is related to
|
Third-Party Management |
|
is related to
|
Third-Party Inventories |
|
is related to
|
Third-Party Criticality Assessments |
|
is related to
|
Supply Chain Risk Management (SCRM) |
|
is related to
|
Acquisition Strategies, Tools & Methods |
|
is related to
|
Limit Potential Harm |
|
is related to
|
Processes To Address Weaknesses or Deficiencies |
|
is related to
|
Third-Party Risk Assessments & Approvals |
|
is related to
|
External Connectivity Requirements - Identification of Ports, Protocols & Services |
|
is related to
|
Conflict of Interests |
|
is related to
|
Third-Party Processing, Storage and Service Locations |
|
is related to
|
Third-Party Contract Requirements |
|
is related to
|
Security Compromise Notification Agreements |
|
is related to
|
Contract Flow-Down Requirements |
|
is related to
|
Third-Party Authentication Practices |
|
is related to
|
Responsible, Accountable, Supportive, Consulted & Informed (RASCI) Matrix |
|
is related to
|
Third-Party Scope Review |
|
is related to
|
Review of Third-Party Services |
|
is related to
|
Third-Party Deficiency Remediation |
|
is related to
|
Managing Changes To Third-Party Services |
|
is related to
|
Ownership Change Provisions |
|
is related to
|
Threat Intelligence Program |
|
is related to
|
Indicators of Exposure (IOE) |
|
is related to
|
Threat Intelligence Feeds |
|
is related to
|
Threat Intelligence Reporting |
|
is related to
|
Insider Threat Program |
|
is related to
|
Vulnerability Disclosure Program (VDP) |
|
is related to
|
Security Disclosure Contact Information |
|
is related to
|
Threat Hunting |
|
is related to
|
Tainting |
|
is related to
|
Threat Catalog |
|
is related to
|
Threat Analysis |
|
is related to
|
Behavioral Baselining |
|
is related to
|
Vulnerability & Patch Management Program (VPMP) |
|
is related to
|
Vulnerability Remediation Process |
|
is related to
|
Vulnerability Exploitation Analysis |
|
is related to
|
Stable Versions |
|
is related to
|
Deferred Patching Decisions |
|
is related to
|
Software & Firmware Patching |
|
is related to
|
Centralized Management of Flaw Remediation Processes |
|
is related to
|
Automated Remediation Status |
|
is related to
|
Time To Remediate / Benchmarks For Corrective Action |
|
is related to
|
Removal of Previous Versions |
|
is related to
|
Pre-Deployment Patch Testing |
|
is related to
|
Out-of-Cycle Patching |
|
is related to
|
Software Patch Integrity |
|
is related to
|
Vulnerability Scanning |
|
is related to
|
Update Tool Capability |
|
is related to
|
Breadth / Depth of Coverage |
|
is related to
|
Privileged Access |
|
is related to
|
Trend Analysis |
|
is related to
|
Review Historical Event logs |
|
is related to
|
External Vulnerability Assessment Scans |
|
is related to
|
Internal Vulnerability Assessment Scans |
|
is related to
|
Correlate Scanning Information |
|
is related to
|
Reviewing Vulnerability Scanner Usage |
|
is related to
|
Web Security |
|
is related to
|
Unauthorized Code |
|
is related to
|
Use of Demilitarized Zones (DMZ) |
|
is related to
|
Web Application Firewall (WAF) |
|
is related to
|
Client-Facing Web Services |
|
is related to
|
Cookie Management |
|
is related to
|
Strong Customer Authentication (SCA) |
|
is related to
|
Web Security Standard |
|
is related to
|
Web Application Framework |
|
is related to
|
Validation & Sanitization |
|
is related to
|
Secure Web Traffic |
|
is related to
|
Output Encoding |
|
is related to
|
Web Browser Security |
|
is related to
|
Website Change Detection |