relative Control Weighting = 10

Linked Issues

Issuelinks
Linktype Issue
is related to Security, Compliance & Resilience Program (SCRP)
is related to Publishing Security, Compliance & Resilience Documentation
is related to Assigned Security, Compliance & Resilience Responsibilities
is related to Forced Technology Transfer (FTT)
is related to State-Sponsored Espionage
is related to Artificial Intelligence (AI) & Autonomous Technologies Governance
is related to Trustworthy AI & Autonomous Technologies
is related to Adequate Protections For AI & Autonomous Technologies
is related to AI & Autonomous Technologies Risk Management Decisions
is related to AI & Autonomous Technologies Likelihood & Impact Risk Analysis
is related to Artificial Intelligence Test, Evaluation, Validation & Verification (AI TEVV)
is related to AI TEVV Trustworthiness Assessment
is related to AI TEVV Safety Demonstration
is related to AI TEVV Results Evaluation
is related to AI & Autonomous Technologies Intellectual Property Infringement Protections
is related to Data Source Identification
is related to Data Source Integrity
is related to AI & Autonomous Technologies Knowledge Limits
is related to AI & Autonomous Technologies Viability Decisions
is related to Responsibility To Supersede, Deactivate and/or Disengage AI & Autonomous Technologies
is related to AI & Autonomous Technologies Performance Changes
is related to AI & Autonomous Technologies Harm Prevention
is related to AI & Autonomous Technologies Human Subject Protections
is related to AI & Autonomous Technologies Risk Response
is related to AI & Autonomous Technologies Development Practices
is related to Asset Governance
is related to Asset Inventories
is related to Network Diagrams & Data Flow Diagrams (DFDs)
is related to Secure Disposal, Destruction or Re-Use of Equipment
is related to Use of Personal Devices
is related to Bring Your Own Device (BYOD) Usage
is related to Business Continuity Management System (BCMS)
is related to Data Backups
is related to AI & Autonomous Technologies Incidents
is related to Change Management Program
is related to Prohibition Of Changes
is related to Cloud Services
is related to Geolocation Requirements for Processing, Storage and Service Locations
is related to Statutory, Regulatory & Contractual Compliance
is related to Compliance Scope
is related to Security, Compliance & Resilience Controls Oversight
is related to Security, Compliance & Resilience Assessments
is related to Government Surveillance
is related to Secure Baseline Configurations
is related to Least Functionality
is related to User-Installed Software
is related to Continuous Monitoring
is related to Security Event Monitoring
is related to Centralized Collection of Security Event Logs
is related to Content of Event Logs
is related to Audit Trails
is related to Time Stamps
is related to Protection of Event Logs
is related to Event Log Retention
is related to Anomalous Behavior
is related to Use of Cryptographic Controls
is related to Transmission Confidentiality
is related to Transmission Integrity
is related to Encrypting Data At Rest
is related to Cryptographic Key Management
is related to Data Protection
is related to Data Stewardship
is related to Data & Asset Classification
is related to Disclosure of Information
is related to Physical Media Disposal
is related to System Media Sanitization
is related to Limitations on Use
is related to Removable Media Security
is related to Protecting Sensitive / Regulated Data on External Technology Assets, Applications and/or Services (TAAS)
is related to Publicly Accessible Content
is related to Information Disposal
is related to Information Location
is related to Transfer of Sensitive and/or Regulated Data
is related to Data Localization
is related to Embedded Technology Security Program
is related to Endpoint Device Management (EDM)
is related to Malicious Code Protection (Anti-Malware)
is related to Phishing & Spam Protection
is related to Human Resources Security Management
is related to Users With Elevated Privileges
is related to Defined Roles & Responsibilities
is related to Personnel Screening
is related to Terms of Employment
is related to Rules of Behavior
is related to Technology Use Restrictions
is related to Access Agreements
is related to Confidentiality Agreements
is related to Third-Party Personnel
is related to Identity & Access Management (IAM)
is related to User & Service Account Inventories
is related to User Provisioning & De-Provisioning
is related to Change of Roles & Duties
is related to Termination of Employment
is related to Authenticator Management
is related to Protection of Authenticators
is related to No Embedded Unencrypted Static Authenticators
is related to Default Authenticators
is related to Account Management
is related to Disable Inactive Accounts
is related to Restrictions on Shared Groups / Accounts
is related to Account Disabling for High Risk Individuals
is related to System Account Reviews
is related to Privileged Account Management (PAM)
is related to Privileged Account Inventories
is related to Periodic Review of Account Privileges
is related to User Responsibilities for Account Management
is related to Credential Sharing
is related to Access Enforcement
is related to Access To Sensitive / Regulated Data
is related to Database Access
is related to Least Privilege
is related to Management Approval For Privileged Accounts
is related to Identity Proofing (Identity Verification)
is related to Management Approval For New or Changed Accounts
is related to Incident Handling
is related to Information Assurance (IA) Operations
is related to Assessments
is related to Threat Analysis & Flaw Remediation During Development
is related to Security Authorization
is related to Controlled Maintenance
is related to Centralized Management Of Mobile Devices
is related to Network Security Controls (NSC)
is related to Boundary Protection
is related to Data Flow Enforcement – Access Control Lists (ACLs)
is related to Deny Traffic by Default & Allow Traffic by Exception
is related to Network Segmentation (macrosegementation)
is related to Sensitive / Regulated Data Enclave (Secure Zone)
is related to Domain Name Service (DNS) Resolution
is related to Electronic Messaging
is related to Remote Access
is related to Work From Anywhere (WFA) - Telecommuting Security
is related to Email Content Protections
is related to Physical Access Control
is related to Physical Security of Offices, Rooms & Facilities
is related to Working in Secure Areas
is related to Restrict Unescorted Access
is related to Data Privacy Program
is related to Data Privacy Requirements for Contractors & Service Providers
is related to Potential Human Rights Abuses
is related to Security, Compliance & Resilience In Project Management
is related to Secure Development Life Cycle (SDLC) Management
is related to Risk Management Program
is related to Risk Assessment
is related to Risk Register
is related to Risk Remediation
is related to Supply Chain Risk Management (SCRM) Plan
is related to Secure Engineering Principles
is related to Defense-In-Depth (DiD) Architecture
is related to Technology Development & Acquisition
is related to Product Management
is related to Security, Compliance & Resilience Representatives For Product Changes
is related to Secure Software Development Practices (SSDP)
is related to Software Design Review
is related to Separation of Development, Testing and Operational Environments
is related to Unsupported Technology Assets, Applications and/or Services (TAAS)
is related to Third-Party Management
is related to Third-Party Services
is related to Third-Party Processing, Storage and Service Locations
is related to Third-Party Contract Requirements
is related to Third-Party Scope Review
is related to Vulnerability Remediation Process
is related to Software & Firmware Patching
is related to Client-Facing Web Services
Impressum German English