|
is blocked by
|
Security, Compliance & Resilience Program (SCRP) |
|
is blocked by
|
Steering Committee & Program Oversight |
|
is blocked by
|
Publishing Security, Compliance & Resilience Documentation |
|
is blocked by
|
Exception Management |
|
is blocked by
|
Periodic Review & Update of Security, Compliance & Resilience Program |
|
is blocked by
|
Assigned Security, Compliance & Resilience Responsibilities |
|
is blocked by
|
Stakeholder Accountability Structure |
|
is blocked by
|
Authoritative Chain of Command |
|
is blocked by
|
Contacts With Authorities |
|
is blocked by
|
Contacts With Groups & Associations |
|
is blocked by
|
Defining Business Context & Mission |
|
is blocked by
|
Define Control Objectives |
|
is blocked by
|
Data Governance |
|
is blocked by
|
Purpose Validation |
|
is blocked by
|
Forced Technology Transfer (FTT) |
|
is blocked by
|
State-Sponsored Espionage |
|
is blocked by
|
Operationalizing Security, Compliance & Resilience Capabilities |
|
is blocked by
|
Select Controls |
|
is blocked by
|
Implement Controls |
|
is blocked by
|
Assess Controls |
|
is blocked by
|
Authorize Technology Assets, Applications and/or Services (TAAS) |
|
is blocked by
|
Monitor Controls |
|
is blocked by
|
Quality Management System (QMS) |
|
is blocked by
|
Artificial Intelligence (AI) & Autonomous Technologies Governance |
|
is blocked by
|
Trustworthy AI & Autonomous Technologies |
|
is blocked by
|
AI & Autonomous Technologies Value Sustainment |
|
is blocked by
|
AI Model & Agent Inventory & Lifecycle Management |
|
is blocked by
|
Situational Awareness of AI & Autonomous Technologies |
|
is blocked by
|
AI & Autonomous Technologies Risk Mapping |
|
is blocked by
|
AI & Autonomous Technologies Internal Controls |
|
is blocked by
|
Adequate Protections For AI & Autonomous Technologies |
|
is blocked by
|
AI Threat Modeling & Risk Assessment |
|
is blocked by
|
AI & Autonomous Technologies Context Definition |
|
is blocked by
|
AI & Autonomous Technologies Mission and Goals Definition |
|
is blocked by
|
Model & AI Agent Documentation |
|
is blocked by
|
AI & Autonomous Technologies Potential Benefits Analysis |
|
is blocked by
|
AI & Autonomous Technologies Potential Costs Analysis |
|
is blocked by
|
AI & Autonomous Technologies Targeted Application Scope |
|
is blocked by
|
AI & Autonomous Technologies Training |
|
is blocked by
|
AI & Autonomous Technologies Fairness & Bias |
|
is blocked by
|
AI & Autonomous Technologies Risk Management Decisions |
|
is blocked by
|
AI & Autonomous Technologies Impact Assessment |
|
is blocked by
|
AI & Autonomous Technologies Likelihood & Impact Risk Analysis |
|
is blocked by
|
AI & Autonomous Technologies Continuous Improvements |
|
is blocked by
|
Assigned Responsibilities for AI & Autonomous Technologies |
|
is blocked by
|
AI & Autonomous Technologies Risk Profiling |
|
is blocked by
|
AI & Autonomous Technologies High Risk Designations |
|
is blocked by
|
Artificial Intelligence Test, Evaluation, Validation & Verification (AI TEVV) |
|
is blocked by
|
AI TEVV Trustworthiness Assessment |
|
is blocked by
|
AI TEVV Tools |
|
is blocked by
|
AI TEVV Trustworthiness Demonstration |
|
is blocked by
|
AI TEVV Safety Demonstration |
|
is blocked by
|
AI TEVV Security & Resiliency Assessment |
|
is blocked by
|
AI & Autonomous Technologies Model Validation |
|
is blocked by
|
AI TEVV Effectiveness |
|
is blocked by
|
AI TEVV Comparable Deployment Settings |
|
is blocked by
|
AI TEVV Post-Deployment Monitoring |
|
is blocked by
|
AI TEVV Reporting |
|
is blocked by
|
AI TEVV Empirically Validated Methods |
|
is blocked by
|
AI TEVV Benchmarking Content Provenance |
|
is blocked by
|
AI TEVV Model Collapse Mitigations |
|
is blocked by
|
AI TEVV Third-Party Risk Management |
|
is blocked by
|
Robust Stakeholder Engagement for AI & Autonomous Technologies |
|
is blocked by
|
AI & Autonomous Technologies Stakeholder Feedback Integration |
|
is blocked by
|
AI & Autonomous Technologies Ongoing Assessments |
|
is blocked by
|
AI & Autonomous Technologies End User Feedback |
|
is blocked by
|
AI & Autonomous Technologies Incident & Error Reporting |
|
is blocked by
|
Data Source Identification |
|
is blocked by
|
Data Source Integrity |
|
is blocked by
|
Data Source Lineage & Origin Disclosure |
|
is blocked by
|
Digital Content Modification Logging |
|
is blocked by
|
AI & Autonomous Technologies Stakeholder Diversity |
|
is blocked by
|
AI & Autonomous Technologies Stakeholder Competencies |
|
is blocked by
|
AI & Autonomous Technologies Requirements Definitions |
|
is blocked by
|
AI & Autonomous Technologies Implementation Tasks Definition |
|
is blocked by
|
AI & Autonomous Technologies Knowledge Limits |
|
is blocked by
|
AI & Autonomous Technologies Viability Decisions |
|
is blocked by
|
AI & Autonomous Technologies Negative Residual Risks |
|
is blocked by
|
Responsibility To Supersede, Deactivate and/or Disengage AI & Autonomous Technologies |
|
is blocked by
|
AI & Autonomous Technologies Production Monitoring |
|
is blocked by
|
AI & Autonomous Technologies Measurement Approaches |
|
is blocked by
|
Measuring AI & Autonomous Technologies Effectiveness |
|
is blocked by
|
Unmeasurable AI & Autonomous Technologies Risks |
|
is blocked by
|
Efficacy of AI & Autonomous Technologies Measurement |
|
is blocked by
|
AI & Autonomous Technologies Domain Expert Reviews |
|
is blocked by
|
AI & Autonomous Technologies Performance Changes |
|
is blocked by
|
Pre-Trained AI & Autonomous Technologies Models |
|
is blocked by
|
AI & Autonomous Technologies Event Logging |
|
is blocked by
|
Serious Incident Reporting For AI & Autonomous Technologies |
|
is blocked by
|
Serious Incident Root Cause Analysis (RCA) For AI & Autonomous Technologies |
|
is blocked by
|
Anomaly Detection & Human Oversight |
|
is blocked by
|
Human-in-the-Loop & Escalation |
|
is blocked by
|
Emergent Behavior & Collusion Protections |
|
is blocked by
|
Multi-Agent Trust & Communication Validation |
|
is blocked by
|
AI & Autonomous Technologies Harm Prevention |
|
is blocked by
|
AI & Autonomous Technologies Human Subject Protections |
|
is blocked by
|
AI & Autonomous Technologies Environmental Impact & Sustainability |
|
is blocked by
|
Previously Unknown AI & Autonomous Technologies Threats & Risks |
|
is blocked by
|
Novel Risk Assessment Methods & Technologies |
|
is blocked by
|
Fine Tuning Risk Mitigation |
|
is blocked by
|
AI & Autonomous Technologies Risk Tracking Approaches |
|
is blocked by
|
AI & Autonomous Technologies Risk Response |
|
is blocked by
|
AI & Autonomous Technologies Conformity |
|
is blocked by
|
Manipulative or Deceptive Techniques |
|
is blocked by
|
Materially Distorting Behaviors |
|
is blocked by
|
Social Scoring |
|
is blocked by
|
Detrimental or Unfavorable Treatment |
|
is blocked by
|
Risk and Criminal Profiling |
|
is blocked by
|
Populating Facial Recognition Databases |
|
is blocked by
|
Emotion Inference |
|
is blocked by
|
Biometric Categorization |
|
is blocked by
|
AI & Autonomous Technologies Development Practices |
|
is blocked by
|
AI & Autonomous Technologies Transparency |
|
is blocked by
|
AI & Autonomous Technologies Implementation Documentation |
|
is blocked by
|
AI & Autonomous Technologies Human Domain Knowledge Reliance |
|
is blocked by
|
AI & Autonomous Technologies Registration |
|
is blocked by
|
AI & Autonomous Technologies Deployment |
|
is blocked by
|
AI & Autonomous Technologies Human Oversight |
|
is blocked by
|
AI & Autonomous Technologies Oversight Measures |
|
is blocked by
|
AI & Autonomous Technologies Separate Verification |
|
is blocked by
|
AI & Autonomous Technologies Oversight Functions Competency |
|
is blocked by
|
AI & Autonomous Technologies Data Relevance |
|
is blocked by
|
AI & Autonomous Technologies Irregularity Reporting |
|
is blocked by
|
AI & Autonomous Technologies Use Notification To Employees |
|
is blocked by
|
AI & Autonomous Technologies Use Notification To Users |
|
is blocked by
|
AI & Autonomous Technologies Output Marking |
|
is blocked by
|
Real World Testing of AI & Autonomous Technologies |
|
is blocked by
|
AI & Autonomous Technologies System Value Chain |
|
is blocked by
|
AI & Autonomous Technologies System Value Chain Fallbacks |
|
is blocked by
|
AI & Autonomous Technologies Testing Techniques |
|
is blocked by
|
Generative Artificial Intelligence (GAI) Identification |
|
is blocked by
|
AI & Autonomous Technologies Capabilities Testing |
|
is blocked by
|
Real-World Testing |
|
is blocked by
|
Documenting Testing Guidance |
|
is blocked by
|
AI & Autonomous Technologies Output Filtering |
|
is blocked by
|
Human Moderation |
|
is blocked by
|
AI Model Resilience |
|
is blocked by
|
Model Pollution |
|
is blocked by
|
Cascading Hallucination Defense |
|
is blocked by
|
Resource Exhaustion & DoS Resilience |
|
is blocked by
|
AI Agent Governance |
|
is blocked by
|
Infrastructure Hardening & Isolation |
|
is blocked by
|
AI Agent Limitations |
|
is blocked by
|
Tool & API Invocation Controls |
|
is blocked by
|
Orchestration Protocol Safeguards |
|
is blocked by
|
Data Pipeline & Input Integrity |
|
is blocked by
|
Privileged Role & Delegation Boundaries |
|
is blocked by
|
AI Agent Data Access Restrictions |
|
is blocked by
|
Data Extraction |
|
is blocked by
|
AI Agent Identity & Impersonation Defense |
|
is blocked by
|
AI Agent Logic Integrity |
|
is blocked by
|
Sandboxing AI Agents |
|
is blocked by
|
Prompt Injection Defense |
|
is blocked by
|
Agent Kill Switch / User Control |
|
is blocked by
|
Adversarial & Red Team Testing |
|
is blocked by
|
Self-Modification Controls |
|
is blocked by
|
Purging AI Agent Data |
|
is blocked by
|
Delegation and Chaining Control |
|
is blocked by
|
Behavioral Drift Detection |
|
is blocked by
|
AI Agent Action Authentication & Authorization |
|
is blocked by
|
Transparency & Audit |
|
is blocked by
|
Explainability |
|
is blocked by
|
Ethics, Fairness & Bias Detection |
|
is blocked by
|
Agent Output Integrity & Verification |
|
is blocked by
|
Agentic Output Traceability & Repudiation |
|
is blocked by
|
AI Agent Logging |
|
is blocked by
|
Session Management |
|
is blocked by
|
Human-in-the-Loop Workload & Manipulation |
|
is blocked by
|
Robotic Process Automation (RPA) |
|
is blocked by
|
Business Process Task Enumeration |
|
is blocked by
|
Stakeholder Identification & Involvement |
|
is blocked by
|
Standardized Naming Convention |
|
is blocked by
|
Configuration Management Database (CMDB) |
|
is blocked by
|
Asset Ownership Assignment |
|
is blocked by
|
Accountability Information |
|
is blocked by
|
Provenance |
|
is blocked by
|
Network Diagrams & Data Flow Diagrams (DFDs) |
|
is blocked by
|
Asset Scope Classification |
|
is blocked by
|
Security of Assets & Media |
|
is blocked by
|
Asset Storage In Automobiles |
|
is blocked by
|
Secure Disposal, Destruction or Re-Use of Equipment |
|
is blocked by
|
Return of Assets |
|
is blocked by
|
Removal of Assets |
|
is blocked by
|
Use of Personal Devices |
|
is blocked by
|
Use of Third-Party Devices |
|
is blocked by
|
Bluetooth & Wireless Devices |
|
is blocked by
|
Infrared Communications |
|
is blocked by
|
Logical Tampering Protection |
|
is blocked by
|
Technology Asset Inspections |
|
is blocked by
|
Bring Your Own Device (BYOD) Usage |
|
is blocked by
|
Prohibited Equipment & Services |
|
is blocked by
|
Roots of Trust Protection |
|
is blocked by
|
Telecommunications Equipment |
|
is blocked by
|
Video Teleconference (VTC) Security |
|
is blocked by
|
Voice Over Internet Protocol (VoIP) Security |
|
is blocked by
|
Microphones & Web Cameras |
|
is blocked by
|
Multi-Function Devices (MFD) |
|
is blocked by
|
Travel-Only Devices |
|
is blocked by
|
Re-Imaging Devices After Travel |
|
is blocked by
|
System Administrative Processes |
|
is blocked by
|
Jump Server |
|
is blocked by
|
Database Administrative Processes |
|
is blocked by
|
Database Management System (DBMS) |
|
is blocked by
|
Radio Frequency Identification (RFID) Security |
|
is blocked by
|
Contactless Access Control Systems |
|
is blocked by
|
Decommissioning |
|
is blocked by
|
Asset Categorization |
|
is blocked by
|
Categorize Artificial Intelligence (AI)-Related Technologies |
|
is blocked by
|
Asset Attributes |
|
is blocked by
|
Automated Network Asset Discovery |
|
is blocked by
|
Business Continuity Management System (BCMS) |
|
is blocked by
|
Coordinate with Related Plans |
|
is blocked by
|
Coordinate With External Service Providers |
|
is blocked by
|
Transfer to Alternate Processing / Storage Site |
|
is blocked by
|
Recovery Time / Point Objectives (RTO / RPO) |
|
is blocked by
|
Recovery Operations Criteria |
|
is blocked by
|
Business Continuity & Disaster Recovery (BC/DR) Plans |
|
is blocked by
|
Identify Critical Assets |
|
is blocked by
|
Resume All Missions & Business Functions |
|
is blocked by
|
Continue Essential Mission & Business Functions |
|
is blocked by
|
Resume Essential Missions & Business Functions |
|
is blocked by
|
Data Storage Location Reviews |
|
is blocked by
|
Coordinated Testing with Related Plans |
|
is blocked by
|
Alternate Storage & Processing Sites |
|
is blocked by
|
Alternative Security Measures |
|
is blocked by
|
Alternate Storage Site |
|
is blocked by
|
Separation from Primary Storage Site |
|
is blocked by
|
Primary Storage Site Accessibility |
|
is blocked by
|
Alternate Processing Site |
|
is blocked by
|
Separation from Primary Processing Site |
|
is blocked by
|
Alternate Processing Site Accessibility |
|
is blocked by
|
Data Backups |
|
is blocked by
|
Testing for Reliability & Integrity |
|
is blocked by
|
Separate Storage for Critical Information |
|
is blocked by
|
Recovery Images |
|
is blocked by
|
Cryptographic Protection |
|
is blocked by
|
Test Restoration Using Sampling |
|
is blocked by
|
Transfer to Alternate Storage Site |
|
is blocked by
|
Redundant Secondary System |
|
is blocked by
|
Dual Authorization For Backup Media Destruction |
|
is blocked by
|
Backup Access |
|
is blocked by
|
Backup Modification and/or Destruction |
|
is blocked by
|
Technology Assets, Applications and/or Services (TAAS) Recovery & Reconstitution |
|
is blocked by
|
Transaction Recovery |
|
is blocked by
|
Failover Capability |
|
is blocked by
|
Backup & Restoration Hardware Protection |
|
is blocked by
|
Restoration Integrity Verification |
|
is blocked by
|
Isolated Recovery Environment |
|
is blocked by
|
Reserve Hardware |
|
is blocked by
|
AI & Autonomous Technologies Incidents |
|
is blocked by
|
Capacity & Performance Management |
|
is blocked by
|
Resource Priority |
|
is blocked by
|
Capacity Planning |
|
is blocked by
|
Change Management Program |
|
is blocked by
|
Configuration Change Control |
|
is blocked by
|
Prohibition Of Changes |
|
is blocked by
|
Test, Validate & Document Changes |
|
is blocked by
|
Security, Compliance & Resilience Representative for Asset Lifecycle Changes |
|
is blocked by
|
Dual Authorization for Change |
|
is blocked by
|
Permissions To Implement Changes |
|
is blocked by
|
Library Privileges |
|
is blocked by
|
Stakeholder Notification of Changes |
|
is blocked by
|
Control Functionality Verification |
|
is blocked by
|
Emergency Changes |
|
is blocked by
|
Documenting Emergency Changes |
|
is blocked by
|
Cloud Services |
|
is blocked by
|
Cloud Infrastructure Onboarding |
|
is blocked by
|
Cloud Infrastructure Offboarding |
|
is blocked by
|
Cloud Security Architecture |
|
is blocked by
|
API Gateway |
|
is blocked by
|
Virtual Machine Images |
|
is blocked by
|
Multi-Tenant Environments |
|
is blocked by
|
Geolocation Requirements for Processing, Storage and Service Locations |
|
is blocked by
|
Sensitive Data In Public Cloud Providers |
|
is blocked by
|
Side Channel Attack Prevention |
|
is blocked by
|
Hosted Assets, Applications & Services |
|
is blocked by
|
Authorized Individuals For Hosted Assets, Applications & Services |
|
is blocked by
|
Sensitive / Regulated Data On Hosted Assets, Applications & Services |
|
is blocked by
|
Prohibition On Unverified Hosted Assets, Applications & Services |
|
is blocked by
|
Software Defined Storage (SDS) |
|
is blocked by
|
Statutory, Regulatory & Contractual Compliance |
|
is blocked by
|
Non-Compliance Oversight |
|
is blocked by
|
Ability To Demonstrate Conformity |
|
is blocked by
|
Conformity Assessment |
|
is blocked by
|
Declaration of Conformity |
|
is blocked by
|
Assessment Team Subject Matter Expertise |
|
is blocked by
|
Security, Compliance & Resilience Controls Oversight |
|
is blocked by
|
Internal Audit Function |
|
is blocked by
|
Periodic Audits |
|
is blocked by
|
Corrective Action |
|
is blocked by
|
Security, Compliance & Resilience Assessments |
|
is blocked by
|
Independent Assessors |
|
is blocked by
|
Functional Review Of Security, Compliance & Resilience Controls |
|
is blocked by
|
Assessor Access |
|
is blocked by
|
Assessment Methods |
|
is blocked by
|
Assessment Rigor |
|
is blocked by
|
Evidence Request List (ERL) |
|
is blocked by
|
Evidence Sampling |
|
is blocked by
|
Legal Assessment of Investigative Inquires |
|
is blocked by
|
Investigation Request Notifications |
|
is blocked by
|
Investigation Access Restrictions |
|
is blocked by
|
Government Surveillance |
|
is blocked by
|
Grievances |
|
is blocked by
|
Grievance Response |
|
is blocked by
|
Localized Representation |
|
is blocked by
|
Representative Powers |
|
is blocked by
|
Dual Use Technology |
|
is blocked by
|
USML or CCL Identification |
|
is blocked by
|
Export-Controlled Access Restrictions |
|
is blocked by
|
Export Activities Documentation |
|
is blocked by
|
Configuration Management Program |
|
is blocked by
|
Assignment of Responsibility |
|
is blocked by
|
Secure Baseline Configurations |
|
is blocked by
|
Reviews & Updates |
|
is blocked by
|
Development & Test Environment Configurations |
|
is blocked by
|
Configure Technology Assets, Applications and/or Services (TAAS) for High-Risk Areas |
|
is blocked by
|
Approved Configuration Deviations |
|
is blocked by
|
Baseline Tailoring |
|
is blocked by
|
Least Functionality |
|
is blocked by
|
Periodic Review |
|
is blocked by
|
Prevent Unauthorized Software Execution |
|
is blocked by
|
Explicitly Allow / Deny Applications |
|
is blocked by
|
Software Usage Restrictions |
|
is blocked by
|
Open Source Software |
|
is blocked by
|
Unsupported Internet Browsers & Email Clients |
|
is blocked by
|
User-Installed Software |
|
is blocked by
|
Restrict Roles Permitted To Install Software |
|
is blocked by
|
Configuration Enforcement |
|
is blocked by
|
Integrity Assurance & Enforcement (IAE) |
|
is blocked by
|
Zero-Touch Provisioning (ZTP) |
|
is blocked by
|
Sensitive / Regulated Data Access Enforcement |
|
is blocked by
|
Sensitive / Regulated Data Actions |
|
is blocked by
|
Continuous Monitoring |
|
is blocked by
|
Intrusion Detection & Prevention Systems (IDS & IPS) |
|
is blocked by
|
Automated Tools for Real-Time Analysis |
|
is blocked by
|
Inbound & Outbound Communications Traffic |
|
is blocked by
|
System Generated Alerts |
|
is blocked by
|
Wireless Network Monitoring |
|
is blocked by
|
Host-Based Devices |
|
is blocked by
|
File Integrity Monitoring (FIM) |
|
is blocked by
|
Security Event Monitoring |
|
is blocked by
|
Proxy Logging |
|
is blocked by
|
Deactivated Account Activity |
|
is blocked by
|
Automated Response to Suspicious Events |
|
is blocked by
|
Automated Alerts |
|
is blocked by
|
Alert Threshold Tuning |
|
is blocked by
|
Individuals Posing Greater Risk |
|
is blocked by
|
Privileged User Oversight |
|
is blocked by
|
Analyze and Prioritize Monitoring Requirements |
|
is blocked by
|
Real-Time Session Monitoring |
|
is blocked by
|
Centralized Collection of Security Event Logs |
|
is blocked by
|
Correlate Monitoring Information |
|
is blocked by
|
Central Review & Analysis |
|
is blocked by
|
Integration of Scanning & Other Monitoring Information |
|
is blocked by
|
Correlation with Physical Monitoring |
|
is blocked by
|
Permitted Actions |
|
is blocked by
|
Audit Level Adjustments |
|
is blocked by
|
System-Wide / Time-Correlated Audit Trail |
|
is blocked by
|
Changes by Authorized Individuals |
|
is blocked by
|
Inventory of Technology Asset Event Logging |
|
is blocked by
|
Content of Event Logs |
|
is blocked by
|
Sensitive Event Log Information |
|
is blocked by
|
Audit Trails |
|
is blocked by
|
Privileged Functions Logging |
|
is blocked by
|
Limit Personal Data (PD) In Audit Records |
|
is blocked by
|
Database Logging |
|
is blocked by
|
Monitoring Reporting |
|
is blocked by
|
Time Stamps |
|
is blocked by
|
Synchronization With Authoritative Time Source |
|
is blocked by
|
Protection of Event Logs |
|
is blocked by
|
Event Log Backup on Separate Physical Systems / Components |
|
is blocked by
|
Access by Subset of Privileged Users |
|
is blocked by
|
Cryptographic Protection of Event Log Information |
|
is blocked by
|
Dual Authorization for Event Log Movement |
|
is blocked by
|
Monitoring For Information Disclosure |
|
is blocked by
|
Monitoring for Indicators of Compromise (IOC) |
|
is blocked by
|
Session Audit |
|
is blocked by
|
Alternate Event Logging Capability |
|
is blocked by
|
Covert Channel Analysis |
|
is blocked by
|
Anomalous Behavior |
|
is blocked by
|
Insider Threats |
|
is blocked by
|
Third-Party Threats |
|
is blocked by
|
Unauthorized Activities |
|
is blocked by
|
Account Creation and Modification Logging |
|
is blocked by
|
Event Log Analysis & Triage |
|
is blocked by
|
Event Log Review Escalation Matrix |
|
is blocked by
|
File Activity Monitoring (FAM) |
|
is blocked by
|
Use of Cryptographic Controls |
|
is blocked by
|
Alternate Physical Protection |
|
is blocked by
|
Cryptographic Cipher Suites and Protocols Inventory |
|
is blocked by
|
Automated Authentication Through Cryptographic Modules |
|
is blocked by
|
Transmission Confidentiality |
|
is blocked by
|
Transmission Integrity |
|
is blocked by
|
Encrypting Data At Rest |
|
is blocked by
|
Storage Media |
|
is blocked by
|
Offline Storage |
|
is blocked by
|
Database Encryption |
|
is blocked by
|
Non-Console Administrative Access |
|
is blocked by
|
Wireless Access Authentication & Encryption |
|
is blocked by
|
Public Key Infrastructure (PKI) |
|
is blocked by
|
Availability |
|
is blocked by
|
Cryptographic Key Management |
|
is blocked by
|
Symmetric Keys |
|
is blocked by
|
Asymmetric Keys |
|
is blocked by
|
Cryptographic Key Loss or Change |
|
is blocked by
|
Control & Distribution of Cryptographic Keys |
|
is blocked by
|
Assigned Owners |
|
is blocked by
|
Third-Party Cryptographic Keys |
|
is blocked by
|
External System Cryptographic Key Control |
|
is blocked by
|
Transmission of Cybersecurity & Data Protection Attributes |
|
is blocked by
|
Certificate Authorities |
|
is blocked by
|
Certificate Monitoring |
|
is blocked by
|
Cryptographic Hash |
|
is blocked by
|
Data Protection |
|
is blocked by
|
Data Stewardship |
|
is blocked by
|
Sensitive / Regulated Data Protection |
|
is blocked by
|
Sensitive / Regulated Media Records |
|
is blocked by
|
Defining Access Authorizations for Sensitive / Regulated Data |
|
is blocked by
|
Data & Asset Classification |
|
is blocked by
|
Highest Classification Level |
|
is blocked by
|
Media Access |
|
is blocked by
|
Disclosure of Information |
|
is blocked by
|
Masking Displayed Data |
|
is blocked by
|
Controlled Release |
|
is blocked by
|
Media Marking |
|
is blocked by
|
Automated Marking |
|
is blocked by
|
Cybersecurity & Data Protection Attributes |
|
is blocked by
|
Dynamic Attribute Association |
|
is blocked by
|
Attribute Value Changes By Authorized Individuals |
|
is blocked by
|
Maintenance of Attribute Associations By System |
|
is blocked by
|
Association of Attributes By Authorized Individuals |
|
is blocked by
|
Attribute Displays for Output Devices |
|
is blocked by
|
Data Subject Attribute Associations |
|
is blocked by
|
Consistent Attribute Interpretation |
|
is blocked by
|
Identity Association Techniques & Technologies |
|
is blocked by
|
Attribute Reassignment |
|
is blocked by
|
Attribute Configuration By Authorized Individuals |
|
is blocked by
|
Audit Changes |
|
is blocked by
|
Media Storage |
|
is blocked by
|
Physically Secure All Media |
|
is blocked by
|
Sensitive Data Inventories |
|
is blocked by
|
Periodic Scans for Sensitive / Regulated Data |
|
is blocked by
|
Making Sensitive Data Unreadable In Storage |
|
is blocked by
|
Storing Authentication Data |
|
is blocked by
|
Media Transportation |
|
is blocked by
|
Custodians |
|
is blocked by
|
Encrypting Data In Storage Media |
|
is blocked by
|
Physical Media Disposal |
|
is blocked by
|
System Media Sanitization |
|
is blocked by
|
System Media Sanitization Documentation |
|
is blocked by
|
Equipment Testing |
|
is blocked by
|
Sanitization of Personal Data (PD) |
|
is blocked by
|
First Time Use Sanitization |
|
is blocked by
|
Dual Authorization for Sensitive Data Destruction |
|
is blocked by
|
Media Use |
|
is blocked by
|
Limitations on Use |
|
is blocked by
|
Prohibit Use Without Owner |
|
is blocked by
|
Data Reclassification |
|
is blocked by
|
Removable Media Security |
|
is blocked by
|
Use of External Technology Assets, Applications and/or Services (TAAS) |
|
is blocked by
|
Limits of Authorized Use |
|
is blocked by
|
Portable Storage Devices |
|
is blocked by
|
Protecting Sensitive / Regulated Data on External Technology Assets, Applications and/or Services (TAAS) |
|
is blocked by
|
Non-Organizationally Owned Technology Assets, Applications and/or Services (TAAS) |
|
is blocked by
|
Information Sharing |
|
is blocked by
|
Information Search & Retrieval |
|
is blocked by
|
Transfer Authorizations |
|
is blocked by
|
Data Access Mapping |
|
is blocked by
|
Publicly Accessible Content |
|
is blocked by
|
Data Mining Protection |
|
is blocked by
|
Ad-Hoc Transfers |
|
is blocked by
|
Media & Data Retention |
|
is blocked by
|
Minimize Sensitive / Regulated Data |
|
is blocked by
|
Limit Sensitive / Regulated Data In Testing, Training & Research |
|
is blocked by
|
Temporary Files Containing Personal Data (PD) |
|
is blocked by
|
Geographic Location of Data |
|
is blocked by
|
Archived Data Sets |
|
is blocked by
|
Information Disposal |
|
is blocked by
|
Data Quality Operations |
|
is blocked by
|
Data Tags |
|
is blocked by
|
Information Location |
|
is blocked by
|
Automated Tools to Support Information Location |
|
is blocked by
|
Transfer of Sensitive and/or Regulated Data |
|
is blocked by
|
Data Localization |
|
is blocked by
|
Data Rights Management (DRM) |
|
is blocked by
|
Embedded Technology Security Program |
|
is blocked by
|
Internet of Things (IOT) |
|
is blocked by
|
Operational Technology (OT) |
|
is blocked by
|
Interface Security |
|
is blocked by
|
Embedded Technology Configuration Monitoring |
|
is blocked by
|
Prevent Alterations |
|
is blocked by
|
Embedded Technology Maintenance |
|
is blocked by
|
Resilience To Outages |
|
is blocked by
|
Message Queuing Telemetry Transport (MQTT) Security |
|
is blocked by
|
Restrict Communications |
|
is blocked by
|
Authorized Communications |
|
is blocked by
|
Operating Environment Certification |
|
is blocked by
|
Safety Assessment |
|
is blocked by
|
Certificate-Based Authentication |
|
is blocked by
|
Chip-To-Cloud Security |
|
is blocked by
|
Real-Time Operating System (RTOS) Security |
|
is blocked by
|
Safe Operations |
|
is blocked by
|
Endpoint Device Management (EDM) |
|
is blocked by
|
Unified Endpoint Device Management (UEDM) |
|
is blocked by
|
Endpoint Protection Measures |
|
is blocked by
|
Prohibit Installation Without Privileged Status |
|
is blocked by
|
Software Installation Alerts |
|
is blocked by
|
Governing Access Restriction for Change |
|
is blocked by
|
Malicious Code Protection (Anti-Malware) |
|
is blocked by
|
Automatic Antimalware Signature Updates |
|
is blocked by
|
Centralized Management of Antimalware Technologies |
|
is blocked by
|
Heuristic / Nonsignature-Based Detection |
|
is blocked by
|
Malware Protection Mechanism Testing |
|
is blocked by
|
Evolving Malware Threats |
|
is blocked by
|
Always On Protection |
|
is blocked by
|
Software Firewall |
|
is blocked by
|
Endpoint File Integrity Monitoring (FIM) |
|
is blocked by
|
Integrity Checks |
|
is blocked by
|
Endpoint Detection & Response (EDR) |
|
is blocked by
|
Automated Notifications of Integrity Violations |
|
is blocked by
|
Automated Response to Integrity Violations |
|
is blocked by
|
Boot Process Integrity |
|
is blocked by
|
Protection of Boot Firmware |
|
is blocked by
|
Binary or Machine-Executable Code |
|
is blocked by
|
Extended Detection & Response (XDR) |
|
is blocked by
|
Host Intrusion Detection and Prevention Systems (HIDS / HIPS) |
|
is blocked by
|
Phishing & Spam Protection |
|
is blocked by
|
Central Management |
|
is blocked by
|
Automatic Spam and Phishing Protection Updates |
|
is blocked by
|
Trusted Path |
|
is blocked by
|
Mobile Code |
|
is blocked by
|
Thin Nodes |
|
is blocked by
|
Port & Input / Output (I/O) Device Access |
|
is blocked by
|
Sensor Capability |
|
is blocked by
|
Authorized Use |
|
is blocked by
|
Sensor Delivery Verification |
|
is blocked by
|
Collaborative Computing Devices |
|
is blocked by
|
Disabling / Removal In Secure Work Areas |
|
is blocked by
|
Explicitly Indicate Current Participants |
|
is blocked by
|
Participant Identity Verification |
|
is blocked by
|
Participant Connection Management |
|
is blocked by
|
Explicit Indication Of Use |
|
is blocked by
|
Hypervisor Access |
|
is blocked by
|
Restrict Access To Security Functions |
|
is blocked by
|
Host-Based Security Function Isolation |
|
is blocked by
|
Human Resources Security Management |
|
is blocked by
|
Onboarding, Transferring & Offboarding Personnel |
|
is blocked by
|
Position Categorization |
|
is blocked by
|
Users With Elevated Privileges |
|
is blocked by
|
Probationary Periods |
|
is blocked by
|
Defined Roles & Responsibilities |
|
is blocked by
|
User Awareness |
|
is blocked by
|
Competency Requirements for Security-Related Positions |
|
is blocked by
|
Personnel Screening |
|
is blocked by
|
Roles With Special Protection Measures |
|
is blocked by
|
Formal Indoctrination |
|
is blocked by
|
Citizenship Requirements |
|
is blocked by
|
Citizenship Identification |
|
is blocked by
|
Terms of Employment |
|
is blocked by
|
Rules of Behavior |
|
is blocked by
|
Social Media & Social Networking Restrictions |
|
is blocked by
|
Technology Use Restrictions |
|
is blocked by
|
Use of Critical Technologies |
|
is blocked by
|
Use of Mobile Devices |
|
is blocked by
|
Policy Familiarization & Acknowledgement |
|
is blocked by
|
Access Agreements |
|
is blocked by
|
Confidentiality Agreements |
|
is blocked by
|
Post-Employment Requirements Awareness |
|
is blocked by
|
Personnel Sanctions |
|
is blocked by
|
Workplace Investigations |
|
is blocked by
|
Updating Disciplinary Processes |
|
is blocked by
|
Preventative Access Restriction |
|
is blocked by
|
Personnel Transfer |
|
is blocked by
|
Personnel Termination |
|
is blocked by
|
Asset Collection |
|
is blocked by
|
High-Risk Terminations |
|
is blocked by
|
Post-Employment Requirements Notification |
|
is blocked by
|
Automated Employment Status Notifications |
|
is blocked by
|
Third-Party Personnel |
|
is blocked by
|
Separation of Duties (SoD) |
|
is blocked by
|
Incompatible Roles |
|
is blocked by
|
Two-Person Rule |
|
is blocked by
|
Identify Critical Skills & Gaps |
|
is blocked by
|
Remediate Identified Skills Deficiencies |
|
is blocked by
|
Identify Vital Security, Compliance & Resilience Staff |
|
is blocked by
|
Establish Redundancy for Vital Security, Compliance & Resilience Staff |
|
is blocked by
|
Perform Succession Planning |
|
is blocked by
|
Identifying Authorized Work Locations |
|
is blocked by
|
Communicating Authorized Work Locations |
|
is blocked by
|
Reporting Suspicious Activities |
|
is blocked by
|
Retain Access Records |
|
is blocked by
|
Authenticate, Authorize and Audit (AAA) |
|
is blocked by
|
Privileged Access by Non-Organizational Users |
|
is blocked by
|
Revocation of Access Authorizations |
|
is blocked by
|
Authorized System Accounts |
|
is blocked by
|
Identity Proofing (Identity Verification) |
|
is blocked by
|
Management Approval For New or Changed Accounts |
|
is blocked by
|
Identity Evidence |
|
is blocked by
|
Identity Evidence Validation & Verification |
|
is blocked by
|
In-Person Validation & Verification |
|
is blocked by
|
Address Confirmation |
|
is blocked by
|
Attribute-Based Access Control (ABAC) |
|
is blocked by
|
Real-Time Access Decisions |
|
is blocked by
|
Access Profile Rules |
|
is blocked by
|
Incident Response Operations |
|
is blocked by
|
Incident Handling |
|
is blocked by
|
Automated Incident Handling Processes |
|
is blocked by
|
Insider Threat Response Capability |
|
is blocked by
|
Incident Classification & Prioritization |
|
is blocked by
|
Correlation with External Organizations |
|
is blocked by
|
Indicators of Compromise (IOC) |
|
is blocked by
|
Incident Response Plan (IRP) |
|
is blocked by
|
Data Breach |
|
is blocked by
|
IRP Update |
|
is blocked by
|
Continuous Incident Response Improvements |
|
is blocked by
|
Incident Response Training |
|
is blocked by
|
Simulated Incidents |
|
is blocked by
|
Automated Incident Response Training Environments |
|
is blocked by
|
Incident Response Testing |
|
is blocked by
|
Coordination with Related Plans |
|
is blocked by
|
Integrated Security Incident Response Team (ISIRT) |
|
is blocked by
|
Chain of Custody & Forensics |
|
is blocked by
|
Situational Awareness For Incidents |
|
is blocked by
|
Automated Tracking, Data Collection & Analysis |
|
is blocked by
|
Recurring Incident Analysis |
|
is blocked by
|
Vulnerabilities Related To Incidents |
|
is blocked by
|
Supply Chain Coordination |
|
is blocked by
|
Serious Incident Reporting |
|
is blocked by
|
Incident Reporting Assistance |
|
is blocked by
|
Automation Support of Availability of Information / Support |
|
is blocked by
|
Coordination With External Providers |
|
is blocked by
|
Sensitive / Regulated Data Spill Response |
|
is blocked by
|
Sensitive / Regulated Data Spill Responsible Personnel |
|
is blocked by
|
Sensitive / Regulated Data Spill Training |
|
is blocked by
|
Post-Sensitive / Regulated Data Spill Operations |
|
is blocked by
|
Sensitive / Regulated Data Exposure to Unauthorized Personnel |
|
is blocked by
|
Root Cause Analysis (RCA) & Lessons Learned |
|
is blocked by
|
Regulatory & Law Enforcement Contacts |
|
is blocked by
|
Detonation Chambers (Sandboxes) |
|
is blocked by
|
Public Relations & Reputation Repair |
|
is blocked by
|
Information Assurance (IA) Operations |
|
is blocked by
|
Assessment Boundaries |
|
is blocked by
|
Assessments |
|
is blocked by
|
Assessor Independence |
|
is blocked by
|
Specialized Assessments |
|
is blocked by
|
Third-Party Assessment Reciprocity |
|
is blocked by
|
Security Assessment Report (SAR) |
|
is blocked by
|
Applied Security, Compliance and Resilience Controls Documentation |
|
is blocked by
|
Plan / Coordinate with Other Organizational Entities |
|
is blocked by
|
Adequate Security for Sensitive / Regulated Data In Support of Contracts |
|
is blocked by
|
Threat Analysis & Flaw Remediation During Development |
|
is blocked by
|
Capabilities Deficiency Tracking |
|
is blocked by
|
Technical Verification |
|
is blocked by
|
Security Authorization |
|
is blocked by
|
Maintenance Operations |
|
is blocked by
|
Controlled Maintenance |
|
is blocked by
|
Automated Maintenance Activities |
|
is blocked by
|
Timely Maintenance |
|
is blocked by
|
Preventative Maintenance |
|
is blocked by
|
Predictive Maintenance |
|
is blocked by
|
Automated Support For Predictive Maintenance |
|
is blocked by
|
Prevent Unauthorized Removal |
|
is blocked by
|
Auditing Remote Maintenance |
|
is blocked by
|
Remote Maintenance Disconnect Verification |
|
is blocked by
|
Remote Maintenance Pre-Approval |
|
is blocked by
|
Remote Maintenance Comparable Security & Sanitization |
|
is blocked by
|
Authorized Maintenance Personnel |
|
is blocked by
|
Maintenance Personnel Without Appropriate Access |
|
is blocked by
|
Non-System Related Maintenance |
|
is blocked by
|
Maintain Configuration Control During Maintenance |
|
is blocked by
|
Field Maintenance |
|
is blocked by
|
Off-Site Maintenance |
|
is blocked by
|
Maintenance Validation |
|
is blocked by
|
Maintenance Monitoring |
|
is blocked by
|
Centralized Management Of Mobile Devices |
|
is blocked by
|
Access Control For Mobile Devices |
|
is blocked by
|
Full Device & Container-Based Encryption |
|
is blocked by
|
Mobile Device Tampering |
|
is blocked by
|
Remote Purging |
|
is blocked by
|
Personally-Owned Mobile Devices |
|
is blocked by
|
Organization-Owned Mobile Devices |
|
is blocked by
|
Mobile Device Geofencing |
|
is blocked by
|
Separate Mobile Device Profiles |
|
is blocked by
|
Restricting Access To Authorized Technology Assets, Applications and/or Services (TAAS) |
|
is blocked by
|
Network Security Controls (NSC) |
|
is blocked by
|
Zero Trust Architecture (ZTA) |
|
is blocked by
|
Layered Network Defenses |
|
is blocked by
|
Cross Domain Solution (CDS) |
|
is blocked by
|
Boundary Protection |
|
is blocked by
|
Limit Network Connections |
|
is blocked by
|
External Telecommunications Services |
|
is blocked by
|
Personal Data (PD) |
|
is blocked by
|
Prevent Unauthorized Exfiltration |
|
is blocked by
|
Isolation of System Components |
|
is blocked by
|
Separate Subnet for Connecting to Different Security Domains |
|
is blocked by
|
Data Flow Enforcement – Access Control Lists (ACLs) |
|
is blocked by
|
Deny Traffic by Default & Allow Traffic by Exception |
|
is blocked by
|
Object Security Attributes |
|
is blocked by
|
Content Check for Encrypted Data |
|
is blocked by
|
Embedded Data Types |
|
is blocked by
|
Metadata |
|
is blocked by
|
Human Reviews |
|
is blocked by
|
Data Type Identifiers |
|
is blocked by
|
Decomposition Into Policy-Related Subcomponents |
|
is blocked by
|
Cross Domain Authentication |
|
is blocked by
|
Metadata Validation |
|
is blocked by
|
Interconnection Security Agreements (ISAs) |
|
is blocked by
|
External System Connections |
|
is blocked by
|
Internal System Connections |
|
is blocked by
|
Network Segmentation (macrosegementation) |
|
is blocked by
|
Security Management Subnets |
|
is blocked by
|
Virtual Local Area Network (VLAN) Separation |
|
is blocked by
|
Sensitive / Regulated Data Enclave (Secure Zone) |
|
is blocked by
|
Segregation From Enterprise Services |
|
is blocked by
|
Direct Internet Access Restrictions |
|
is blocked by
|
Microsegmentation |
|
is blocked by
|
Software Defined Networking (SDN) |
|
is blocked by
|
Network Connection Termination |
|
is blocked by
|
DMZ Networks |
|
is blocked by
|
Host Containment |
|
is blocked by
|
Resource Containment |
|
is blocked by
|
Session Integrity |
|
is blocked by
|
Invalidate Session Identifiers at Logout |
|
is blocked by
|
Out-of-Band Channels |
|
is blocked by
|
Safeguarding Data Over Open Networks |
|
is blocked by
|
Wireless Link Protection |
|
is blocked by
|
End-User Messaging Technologies |
|
is blocked by
|
Electronic Messaging |
|
is blocked by
|
Remote Access |
|
is blocked by
|
Automated Monitoring & Control |
|
is blocked by
|
Protection of Confidentiality / Integrity Using Encryption |
|
is blocked by
|
Managed Access Control Points |
|
is blocked by
|
Remote Privileged Commands & Sensitive Data Access |
|
is blocked by
|
Work From Anywhere (WFA) - Telecommuting Security |
|
is blocked by
|
Third-Party Remote Access Governance |
|
is blocked by
|
Endpoint Security Validation |
|
is blocked by
|
Expeditious Disconnect / Disable Capability |
|
is blocked by
|
Intranets |
|
is blocked by
|
Data Loss Prevention (DLP) |
|
is blocked by
|
DNS & Content Filtering |
|
is blocked by
|
Route Internal Traffic to Proxy Servers |
|
is blocked by
|
Visibility of Encrypted Communications |
|
is blocked by
|
Protocol Compliance Enforcement |
|
is blocked by
|
Bandwidth Control |
|
is blocked by
|
Authenticated Proxy |
|
is blocked by
|
Physical & Environmental Protections |
|
is blocked by
|
Physical Security Plan (PSP) |
|
is blocked by
|
Zone-Based Physical Security |
|
is blocked by
|
Physical Access Authorizations |
|
is blocked by
|
Role-Based Physical Access |
|
is blocked by
|
Dual Authorization for Physical Access |
|
is blocked by
|
Physical Access Control |
|
is blocked by
|
Controlled Ingress & Egress Points |
|
is blocked by
|
Lockable Physical Casings |
|
is blocked by
|
Physical Access Logs |
|
is blocked by
|
Access To Critical Systems |
|
is blocked by
|
Physical Security of Offices, Rooms & Facilities |
|
is blocked by
|
Working in Secure Areas |
|
is blocked by
|
Searches |
|
is blocked by
|
Temporary Storage |
|
is blocked by
|
Monitoring Physical Access |
|
is blocked by
|
Intrusion Alarms / Surveillance Equipment |
|
is blocked by
|
Monitoring Physical Access To Critical Systems |
|
is blocked by
|
Visitor Control |
|
is blocked by
|
Distinguish Visitors from On-Site Personnel |
|
is blocked by
|
Identification Requirement |
|
is blocked by
|
Restrict Unescorted Access |
|
is blocked by
|
Automated Records Management & Review |
|
is blocked by
|
Minimize Visitor Personal Data (PD) |
|
is blocked by
|
Visitor Access Revocation |
|
is blocked by
|
Supporting Utilities |
|
is blocked by
|
Automatic Voltage Controls |
|
is blocked by
|
Emergency Shutoff |
|
is blocked by
|
Emergency Power |
|
is blocked by
|
Emergency Lighting |
|
is blocked by
|
Water Damage Protection |
|
is blocked by
|
Automation Support for Water Damage Protection |
|
is blocked by
|
Redundant Cabling |
|
is blocked by
|
Fire Protection |
|
is blocked by
|
Fire Detection Devices |
|
is blocked by
|
Fire Suppression Devices |
|
is blocked by
|
Automatic Fire Suppression |
|
is blocked by
|
Temperature & Humidity Controls |
|
is blocked by
|
Monitoring with Alarms / Notifications |
|
is blocked by
|
Delivery & Removal |
|
is blocked by
|
Alternate Work Site |
|
is blocked by
|
Equipment Siting & Protection |
|
is blocked by
|
Transmission Medium Security |
|
is blocked by
|
Access Control for Output Devices |
|
is blocked by
|
Information Leakage Due To Electromagnetic Signals Emanations |
|
is blocked by
|
Asset Monitoring and Tracking |
|
is blocked by
|
Component Marking |
|
is blocked by
|
On-Site Client Segregation |
|
is blocked by
|
Physical Access Device Inventories |
|
is blocked by
|
Data Privacy Program |
|
is blocked by
|
Personal Data (PD) Retention & Disposal |
|
is blocked by
|
Internal Use of Personal Data (PD) For Testing, Training and Research |
|
is blocked by
|
Inventory of Personal Data (PD) |
|
is blocked by
|
Personal Data (PD) Inventory Automation Support |
|
is blocked by
|
Data Privacy Requirements for Contractors & Service Providers |
|
is blocked by
|
Joint Processing of Personal Data (PD) |
|
is blocked by
|
Personal Data (PD) Control Testing, Training & Monitoring |
|
is blocked by
|
Documenting Data Processing Activities |
|
is blocked by
|
Security, Compliance & Resilience Protection Portfolio Management |
|
is blocked by
|
Strategic Plan & Objectives |
|
is blocked by
|
Targeted Capability Maturity Levels |
|
is blocked by
|
Security, Compliance & Resilience Resource Management |
|
is blocked by
|
Prioritization To Address Evolving Risks & Threats |
|
is blocked by
|
Allocation of Resources |
|
is blocked by
|
Security, Compliance & Resilience In Project Management |
|
is blocked by
|
Security, Compliance & Resilience Requirements Definition |
|
is blocked by
|
Business Process Definition |
|
is blocked by
|
Secure Development Life Cycle (SDLC) Management |
|
is blocked by
|
Manage Organizational Knowledge |
|
is blocked by
|
Risk Management Program |
|
is blocked by
|
Risk Framing |
|
is blocked by
|
Risk Management Resourcing |
|
is blocked by
|
Risk Tolerance |
|
is blocked by
|
Risk Threshold |
|
is blocked by
|
Risk Appetite |
|
is blocked by
|
Risk-Based Security Categorization |
|
is blocked by
|
Impact-Level Prioritization |
|
is blocked by
|
Risk Identification |
|
is blocked by
|
Risk Assessment |
|
is blocked by
|
Risk Register |
|
is blocked by
|
Risk Assessment Methodology |
|
is blocked by
|
Instances Requiring A Risk Assessment |
|
is blocked by
|
Risk Assessment Stakeholder Involvement |
|
is blocked by
|
Risk Ranking |
|
is blocked by
|
Risk Remediation |
|
is blocked by
|
Risk Response |
|
is blocked by
|
Compensating Countermeasures |
|
is blocked by
|
Risk Treatment Options |
|
is blocked by
|
Risk Treatment Plan (RTP) |
|
is blocked by
|
Risk Assessment Update |
|
is blocked by
|
Business Impact Analysis (BIA) |
|
is blocked by
|
Supply Chain Risk Management (SCRM) Plan |
|
is blocked by
|
Supply Chain Risk Assessment |
|
is blocked by
|
AI & Autonomous Technologies Supply Chain Impacts |
|
is blocked by
|
Risk Monitoring |
|
is blocked by
|
Risk Culture |
|
is blocked by
|
Secure Engineering Principles |
|
is blocked by
|
Centralized Management of Security, Compliance & Resilience Controls |
|
is blocked by
|
Achieving Resilience Requirements |
|
is blocked by
|
Resilience Capabilities |
|
is blocked by
|
Alignment With Enterprise Architecture |
|
is blocked by
|
Outsourcing Non-Essential Functions or Services |
|
is blocked by
|
Technical Debt Reviews |
|
is blocked by
|
Defense-In-Depth (DiD) Architecture |
|
is blocked by
|
System Partitioning |
|
is blocked by
|
Application Partitioning |
|
is blocked by
|
Process Isolation |
|
is blocked by
|
Security Function Isolation |
|
is blocked by
|
Hardware Separation |
|
is blocked by
|
Thread Separation |
|
is blocked by
|
Information In Shared Resources |
|
is blocked by
|
Predictable Failure Analysis |
|
is blocked by
|
Technology Lifecycle Management |
|
is blocked by
|
Fail Secure |
|
is blocked by
|
Fail Safe |
|
is blocked by
|
Non-Persistence |
|
is blocked by
|
Refresh from Trusted Sources |
|
is blocked by
|
Information Output Filtering |
|
is blocked by
|
Limit Personal Data (PD) Dissemination |
|
is blocked by
|
Memory Protection |
|
is blocked by
|
Heterogeneity |
|
is blocked by
|
Virtualization Techniques |
|
is blocked by
|
Distributed Processing & Storage |
|
is blocked by
|
Secure Log-On Procedures |
|
is blocked by
|
Clock Synchronization |
|
is blocked by
|
Privileged Environments |
|
is blocked by
|
Operations Security |
|
is blocked by
|
Standardized Operating Procedures (SOP) |
|
is blocked by
|
Security Operations Center (SOC) |
|
is blocked by
|
Secure Practices Guidelines |
|
is blocked by
|
Shadow Information Technology Detection |
|
is blocked by
|
Security, Compliance & Resilience-Minded Workforce |
|
is blocked by
|
Maintaining Workforce Development Relevancy |
|
is blocked by
|
Security, Compliance & Resilience Awareness Training |
|
is blocked by
|
Simulated Cyber Attack Scenario Training |
|
is blocked by
|
Social Engineering & Mining |
|
is blocked by
|
Role-Based Security, Compliance & Resilience Training |
|
is blocked by
|
Practical Exercises |
|
is blocked by
|
Suspicious Communications & Anomalous System Behavior |
|
is blocked by
|
Sensitive / Regulated Data Storage, Handling & Processing |
|
is blocked by
|
Vendor Security, Compliance & Resilience Training |
|
is blocked by
|
Privileged Users |
|
is blocked by
|
Cyber Threat Environment |
|
is blocked by
|
Counterintelligence Training |
|
is blocked by
|
Security, Compliance & Resilience Knowledge Sharing |
|
is blocked by
|
Technology Development & Acquisition |
|
is blocked by
|
Product Management |
|
is blocked by
|
DevSecOps |
|
is blocked by
|
Minimum Viable Product (MVP) Security Requirements |
|
is blocked by
|
Ports, Protocols & Services In Use |
|
is blocked by
|
Development Methods, Techniques & Processes |
|
is blocked by
|
Pre-Established Secure Configurations |
|
is blocked by
|
Identification & Justification of Ports, Protocols & Services |
|
is blocked by
|
Insecure Ports, Protocols & Services |
|
is blocked by
|
Security, Compliance & Resilience Representatives For Product Changes |
|
is blocked by
|
Minimizing Attack Surfaces |
|
is blocked by
|
Ongoing Product Security Support |
|
is blocked by
|
Product Testing & Reviews |
|
is blocked by
|
Disclosure of Vulnerabilities |
|
is blocked by
|
Products With Digital Elements |
|
is blocked by
|
Reporting Exploitable Vulnerabilities |
|
is blocked by
|
Logging Syntax |
|
is blocked by
|
Functional Properties |
|
is blocked by
|
Developer Architecture & Design |
|
is blocked by
|
Physical Diagnostic & Test Interfaces |
|
is blocked by
|
Diagnostic & Test Interface Monitoring |
|
is blocked by
|
Secure Software Development Practices (SSDP) |
|
is blocked by
|
Secure Development Environments |
|
is blocked by
|
Separation of Development, Testing and Operational Environments |
|
is blocked by
|
Secure Migration Practices |
|
is blocked by
|
Security, Compliance & Resilience Testing Throughout Development |
|
is blocked by
|
Continuous Monitoring Plan |
|
is blocked by
|
Secure Settings By Default |
|
is blocked by
|
Product Tampering and Counterfeiting (PTC) |
|
is blocked by
|
Anti-Counterfeit Training |
|
is blocked by
|
Customized Development of Critical Components |
|
is blocked by
|
Developer Screening |
|
is blocked by
|
Developer Configuration Management |
|
is blocked by
|
Software / Firmware Integrity Verification |
|
is blocked by
|
Hardware Integrity Verification |
|
is blocked by
|
Developer Threat Analysis & Flaw Remediation |
|
is blocked by
|
Developer-Provided Training |
|
is blocked by
|
Unsupported Technology Assets, Applications and/or Services (TAAS) |
|
is blocked by
|
Alternate Sources for Continued Support |
|
is blocked by
|
Access to Program Source Code |
|
is blocked by
|
Software Escrow |
|
is blocked by
|
Approved Code |
|
is blocked by
|
Product Conformity Governance |
|
is blocked by
|
Technical Documentation Artifacts |
|
is blocked by
|
Product-Specific Risk Assessment Artifacts |
|
is blocked by
|
Third-Party Management |
|
is blocked by
|
Third-Party Inventories |
|
is blocked by
|
Third-Party Criticality Assessments |
|
is blocked by
|
Supply Chain Risk Management (SCRM) |
|
is blocked by
|
Limit Potential Harm |
|
is blocked by
|
Processes To Address Weaknesses or Deficiencies |
|
is blocked by
|
Adequate Supply |
|
is blocked by
|
Third-Party Services |
|
is blocked by
|
Third-Party Risk Assessments & Approvals |
|
is blocked by
|
External Connectivity Requirements - Identification of Ports, Protocols & Services |
|
is blocked by
|
Conflict of Interests |
|
is blocked by
|
Third-Party Processing, Storage and Service Locations |
|
is blocked by
|
Third-Party Contract Requirements |
|
is blocked by
|
Security Compromise Notification Agreements |
|
is blocked by
|
Contract Flow-Down Requirements |
|
is blocked by
|
Third-Party Authentication Practices |
|
is blocked by
|
Responsible, Accountable, Supportive, Consulted & Informed (RASCI) Matrix |
|
is blocked by
|
Third-Party Scope Review |
|
is blocked by
|
First-Party Declaration (1PD) |
|
is blocked by
|
Break Clauses |
|
is blocked by
|
Third-Party Attestation (3PA) |
|
is blocked by
|
Third-Party Personnel Security |
|
is blocked by
|
Monitoring for Third-Party Information Disclosure |
|
is blocked by
|
Review of Third-Party Services |
|
is blocked by
|
Third-Party Deficiency Remediation |
|
is blocked by
|
Managing Changes To Third-Party Services |
|
is blocked by
|
Third-Party Incident Response & Recovery Capabilities |
|
is blocked by
|
Threat Intelligence Program |
|
is blocked by
|
Indicators of Exposure (IOE) |
|
is blocked by
|
Threat Intelligence Feeds |
|
is blocked by
|
Threat Intelligence Reporting |
|
is blocked by
|
Insider Threat Program |
|
is blocked by
|
Insider Threat Awareness |
|
is blocked by
|
Threat Hunting |
|
is blocked by
|
Tainting |
|
is blocked by
|
Behavioral Baselining |
|
is blocked by
|
Vulnerability & Patch Management Program (VPMP) |
|
is blocked by
|
Attack Surface Scope |
|
is blocked by
|
Vulnerability Remediation Process |
|
is blocked by
|
Vulnerability Ranking |
|
is blocked by
|
Continuous Vulnerability Remediation Activities |
|
is blocked by
|
Stable Versions |
|
is blocked by
|
Flaw Remediation with Personal Data (PD) |
|
is blocked by
|
Deferred Patching Decisions |
|
is blocked by
|
Software & Firmware Patching |
|
is blocked by
|
Centralized Management of Flaw Remediation Processes |
|
is blocked by
|
Automated Software & Firmware Updates |
|
is blocked by
|
Pre-Deployment Patch Testing |
|
is blocked by
|
Out-of-Cycle Patching |
|
is blocked by
|
Software Patch Integrity |
|
is blocked by
|
Red Team Exercises |
|
is blocked by
|
Web Security |
|
is blocked by
|
Unauthorized Code |
|
is blocked by
|
Client-Facing Web Services |
|
is blocked by
|
Strong Customer Authentication (SCA) |
|
is blocked by
|
Web Security Standard |
|
is blocked by
|
Web Application Framework |
|
is blocked by
|
Validation & Sanitization |
|
is blocked by
|
Secure Web Traffic |
|
is blocked by
|
Output Encoding |
|
is blocked by
|
Web Browser Security |
|
is blocked by
|
Website Change Detection |