relative Control Weighting = 05

Linked Issues

Issuelinks
Linktype Issue
is related to Status Reporting To Governing Body
is related to Contacts With Authorities
is related to Defining Business Context & Mission
is related to Define Control Objectives
is related to Purpose Validation
is related to AI Model & Agent Inventory & Lifecycle Management
is related to AI Threat Modeling & Risk Assessment
is related to Model & AI Agent Documentation
is related to AI & Autonomous Technologies Training
is related to AI & Autonomous Technologies Model Validation
is related to AI TEVV Effectiveness
is related to AI TEVV Comparable Deployment Settings
is related to AI TEVV Reporting
is related to AI TEVV Third-Party Risk Management
is related to Measuring AI & Autonomous Technologies Effectiveness
is related to Efficacy of AI & Autonomous Technologies Measurement
is related to Serious Incident Reporting For AI & Autonomous Technologies
is related to Anomaly Detection & Human Oversight
is related to Human-in-the-Loop & Escalation
is related to Emergent Behavior & Collusion Protections
is related to Multi-Agent Trust & Communication Validation
is related to Emotion Inference
is related to Biometric Categorization
is related to AI & Autonomous Technologies Human Domain Knowledge Reliance
is related to AI & Autonomous Technologies Data Relevance
is related to AI & Autonomous Technologies Use Notification To Employees
is related to AI & Autonomous Technologies Use Notification To Users
is related to AI & Autonomous Technologies Output Marking
is related to Real World Testing of AI & Autonomous Technologies
is related to AI & Autonomous Technologies System Value Chain Fallbacks
is related to Generative Artificial Intelligence (GAI) Identification
is related to Documenting Testing Guidance
is related to AI & Autonomous Technologies Output Filtering
is related to AI Model Resilience
is related to Model Pollution
is related to Cascading Hallucination Defense
is related to Resource Exhaustion & DoS Resilience
is related to AI Agent Governance
is related to Infrastructure Hardening & Isolation
is related to AI Agent Limitations
is related to Tool & API Invocation Controls
is related to Orchestration Protocol Safeguards
is related to Data Pipeline & Input Integrity
is related to Privileged Role & Delegation Boundaries
is related to AI Agent Data Access Restrictions
is related to Data Extraction
is related to AI Agent Identity & Impersonation Defense
is related to AI Agent Logic Integrity
is related to Sandboxing AI Agents
is related to Prompt Injection Defense
is related to Self-Modification Controls
is related to Purging AI Agent Data
is related to Delegation and Chaining Control
is related to Behavioral Drift Detection
is related to AI Agent Action Authentication & Authorization
is related to Transparency & Audit
is related to Explainability
is related to Ethics, Fairness & Bias Detection
is related to Agent Output Integrity & Verification
is related to Agentic Output Traceability & Repudiation
is related to AI Agent Logging
is related to Session Management
is related to Human-in-the-Loop Workload & Manipulation
is related to Robotic Process Automation (RPA)
is related to Business Process Task Enumeration
is related to Asset-Service Dependencies
is related to Stakeholder Identification & Involvement
is related to Standardized Naming Convention
is related to Configuration Management Database (CMDB)
is related to Automated Location Tracking
is related to Accountability Information
is related to Infrared Communications
is related to Asset Attributes
is related to Coordinate with Related Plans
is related to Coordinate With External Service Providers
is related to Transfer to Alternate Processing / Storage Site
is related to Recovery Time / Point Objectives (RTO / RPO)
is related to Contingency Training
is related to Alternate Storage & Processing Sites
is related to Contingency Plan Update Notifications
is related to Primary Storage Site Accessibility
is related to Alternate Processing Site Accessibility
is related to Preparation for Use
is related to Inability to Return to Primary Site
is related to Separation of Primary / Alternate Providers
is related to Provider Contingency Plan
is related to Alternate Communications Channels
is related to Test Restoration Using Sampling
is related to Transfer to Alternate Storage Site
is related to Redundant Secondary System
is related to Dual Authorization For Backup Media Destruction
is related to Restore Within Time Period
is related to Isolated Recovery Environment
is related to Elastic Expansion
is related to Automated Security Response
is related to Cryptographic Management
is related to Report Verification Results
is related to Assessment Team Subject Matter Expertise
is related to Designated Certifying Official
is related to Conformity Attestations
is related to Internal Audit Function
is related to Audit Activities
is related to Grievances
is related to Grievance Response
is related to Control Reciprocity
is related to Control Inheritance
is related to Statement of Applicability (SOA)
is related to Assignment of Responsibility
is related to Development & Test Environment Configurations
is related to Explicitly Allow / Deny Applications
is related to Wireless Network Monitoring
is related to Automated Response to Suspicious Events
is related to Automated Alerts
is related to Alert Threshold Tuning
is related to Individuals Posing Greater Risk
is related to Privileged User Oversight
is related to Analyze and Prioritize Monitoring Requirements
is related to Central Review & Analysis
is related to Integration of Scanning & Other Monitoring Information
is related to Correlation with Physical Monitoring
is related to Permitted Actions
is related to Audit Level Adjustments
is related to System-Wide / Time-Correlated Audit Trail
is related to Changes by Authorized Individuals
is related to Verbosity Logging for Boundary Devices
is related to Centralized Management of Event Log Content
is related to Event Log Storage Capacity Alerting
is related to Trend Analysis Reporting
is related to Event Log Backup on Separate Physical Systems / Components
is related to Cryptographic Protection of Event Log Information
is related to Dual Authorization for Event Log Movement
is related to Analyze Traffic for Covert Exfiltration
is related to Unauthorized Network Services
is related to Monitoring for Indicators of Compromise (IOC)
is related to Sharing of Event Logs
is related to File Activity Monitoring (FAM)
is related to Alternate Physical Protection
is related to Export-Controlled Cryptography
is related to Pre/Post Transmission Handling
is related to Conceal / Randomize Communications
is related to Offline Storage
is related to External System Cryptographic Key Control
is related to Transmission of Cybersecurity & Data Protection Attributes
is related to Certificate Monitoring
is related to Cryptographic Hash
is related to Storing Authentication Data
is related to Encrypting Data In Storage Media
is related to Equipment Testing
is related to First Time Use Sanitization
is related to Dual Authorization for Sensitive Data Destruction
is related to Prohibit Use Without Owner
is related to Non-Organizationally Owned Technology Assets, Applications and/or Services (TAAS)
is related to Information Search & Retrieval
is related to Temporary Files Containing Personal Data (PD)
is related to Data Quality Operations
is related to Certificate-Based Authentication
is related to Real-Time Operating System (RTOS) Security
is related to Malware Protection Mechanism Testing
is related to Automated Notifications of Integrity Violations
is related to Automated Response to Integrity Violations
is related to Boot Process Integrity
is related to Protection of Boot Firmware
is related to Binary or Machine-Executable Code
is related to Extended Detection & Response (XDR)
is related to Central Management
is related to Disabling / Removal In Secure Work Areas
is related to Explicitly Indicate Current Participants
is related to Participant Connection Management
is related to Citizenship Requirements
is related to Post-Employment Requirements Awareness
is related to Preventative Access Restriction
is related to Automated Employment Status Notifications
is related to Identify Critical Skills & Gaps
is related to Remediate Identified Skills Deficiencies
is related to Identify Vital Security, Compliance & Resilience Staff
is related to Establish Redundancy for Vital Security, Compliance & Resilience Staff
is related to Perform Succession Planning
is related to Out-of-Band Authentication (OOBA)
is related to Device Attestation
is related to Device Authorization Enforcement
is related to Sharing Identification & Authentication Information
is related to Local Access to Privileged Accounts
is related to Out-of-Band Multi-Factor Authentication
is related to Alternative Multi-Factor Authentication
is related to Dynamic Management
is related to Cross-Organization Management
is related to Automated Support For Password Strength
is related to Multiple System Accounts
is related to Expiration of Cached Authenticators
is related to Biometric Authentication
is related to Adaptive Identification & Authentication
is related to Single Sign-On (SSO) Transparent Authentication
is related to Automated System Account Management (Directory Services)
is related to Automated Audit Actions
is related to Usage Conditions
is related to Emergency Accounts
is related to Privileged Command Execution
is related to Dual Authorization for Privileged Commands
is related to Network Access to Privileged Commands
is related to Privilege Levels for Code Execution
is related to User-Initiated Logouts / Message Displays
is related to Identity Evidence
is related to Identity Evidence Validation & Verification
is related to In-Person Validation & Verification
is related to Attribute-Based Access Control (ABAC)
is related to Access Profile Rules
is related to Insider Threat Response Capability
is related to Dynamic Reconfiguration
is related to Incident Classification & Prioritization
is related to Correlation with External Organizations
is related to Simulated Incidents
is related to Automated Incident Response Training Environments
is related to Recurring Incident Analysis
is related to Incident Pattern Analysis
is related to Serious Incident Reporting
is related to Incident Reporting Assistance
is related to Coordination With External Providers
is related to Detonation Chambers (Sandboxes)
is related to Plan / Coordinate with Other Organizational Entities
is related to Automated Maintenance Activities
is related to Preventative Maintenance
is related to Predictive Maintenance
is related to Automated Support For Predictive Maintenance
is related to Maintenance Tools
is related to Inspect Tools
is related to Inspect Media
is related to Restrict Tool Usage
is related to Remote Maintenance Comparable Security & Sanitization
is related to Non-System Related Maintenance
is related to Prevent Unauthorized Exfiltration
is related to Dynamic Isolation & Segregation (Sandboxing)
is related to Isolation of System Components
is related to Separate Subnet for Connecting to Different Security Domains
is related to Object Security Attributes
is related to Policy Decision Point (PDP)
is related to Data Type Identifiers
is related to Decomposition Into Policy-Related Subcomponents
is related to Detection of Unsanctioned Information
is related to Approved Solutions
is related to Cross Domain Authentication
is related to Software Defined Networking (SDN)
is related to Invalidate Session Identifiers at Logout
is related to Disable Wireless Networking
is related to Wireless Boundaries
is related to Visibility of Encrypted Communications
is related to Protocol Compliance Enforcement
is related to Email Labeling
is related to Lockable Physical Casings
is related to Access To Critical Systems
is related to Monitoring Physical Access To Critical Systems
is related to Automated Records Management & Review
is related to Automation Support for Water Damage Protection
is related to Automatic Fire Suppression
is related to Information Leakage Due To Electromagnetic Signals Emanations
is related to Dissemination of Data Privacy Program Information
is related to Binding Corporate Rules (BCR)
is related to Personal Data (PD) Process Manager
is related to Prohibition of Selling, Processing and/or Sharing Personal Data (PD)
is related to Global Privacy Control (GPC)
is related to Continued Use of Personal Data (PD)
is related to Communicating Processing Changes
is related to Personal Data (PD) Accuracy & Integrity
is related to Personal Data (PD) Categories
is related to Correcting Inaccurate Personal Data (PD)
is related to User Feedback Management
is related to Right to Erasure
is related to Personal Data (PD) Exports
is related to Joint Processing of Personal Data (PD)
is related to Obligation To Inform Third-Parties
is related to Reject Unauthenticated or Untrustworthy Disclosure Requests
is related to Justification To Reject Disclosure Requests
is related to Personal Data (PD) Lineage
is related to Data Quality Management
is related to Data Analytics Bias
is related to Notification of Disclosure Request To Data Subject
is related to Data Subject Communications Documentation
is related to Strategic Plan & Objectives
is related to Targeted Capability Maturity Levels
is related to Prioritization To Address Evolving Risks & Threats
is related to Manage Organizational Knowledge
is related to Risk Catalog
is related to Resilience Capabilities
is related to System Privileges Isolation
is related to Predictable Failure Analysis
is related to Refresh from Trusted Sources
is related to Randomness
is related to Change Processing & Storage Locations
is related to Application Container
is related to Privileged Environments
is related to Security Orchestration, Automation, and Response (SOAR)
is related to Social Engineering & Mining
is related to Integrity Mechanisms for Software / Firmware Updates
is related to Development Methods, Techniques & Processes
is related to Disclosure of Vulnerabilities
is related to Commercial Off-The-Shelf (COTS) Security Solutions
is related to Physical Diagnostic & Test Interfaces
is related to Software Design Root Cause Analysis
is related to Manual Code Review
is related to Hardware Integrity Verification
is related to Third-Party Attestation (3PA)
is related to Threat Catalog
is related to Behavioral Baselining
is related to Attack Surface Scope
is related to Vulnerability Exploitation Analysis
is related to Automated Software & Firmware Updates
is related to Removal of Previous Versions
is related to Acceptable Discoverable Information
is related to Correlate Scanning Information
is related to Cookie Management
Impressum German English