Compliance, Mapped to Your Cloud

Assess your AWS, Azure, and Google Cloud environments against the industry frameworks and regulations your auditors expect.

56
Frameworks Supported
18
Standards Families
3
Cloud Providers
5 min
To First Results
ASecureCloud compliance report preview
AWS logo

NIST 800-53 Rev. 5

241 controls
133 checks mapped

NIST SP 800-53 provides a comprehensive catalog of security and privacy controls for federal information systems and the organizations that operate them.

Controls assessed

Access Control (AC) - Account Management (AC-2) - AC-2(1) Automated System Account Management15

Support the management of system accounts using \[Assignment: organization-defined automated mechanisms\].

Access Control (AC) - Account Management (AC-2) - AC-2(3) Disable Accounts3

Disable accounts within \[Assignment: organization-defined time period\] when the accounts: (a) Have expired; (b) Are no longer associated with a user or individual; (c) Are in violation of organizational policy; or (d) Have been inactive for \[Assignment: organization-defined time period\].

Access Control (AC) - Account Management (AC-2) - AC-2(4) Automated Audit Actions10

Automatically audit account creation, modification, enabling, disabling, and removal actions.

Access Control (AC) - Account Management (AC-2) - AC-2(6) Dynamic Privilege Management24

Implement \[Assignment: organization-defined dynamic privilege management capabilities\].

Access Control (AC) - Account Management (AC-2) - AC-2(12) Account Monitoring2

Monitors and reports atypical usage of information system accounts to organization-defined personnel or roles.

Access Control (AC) - Account Management (AC-2) - AC-2(d)(1)1

d. Specify: 1. Authorized users of the system;personnel termination and transfer processes.

Access Control (AC) - Account Management (AC-2) - AC-2(g)1

The organization: g. Monitors the use of information system accounts.

Access Control (AC) - Account Management (AC-2) - AC-2(i)(2)5

i. Authorize access to the system based on: 2. Intended system usage.

Access Control (AC) - Account Management (AC-2) - AC-2(j)1

The organization: j. Reviews accounts for compliance with account management requirements \[Assignment: organization-defined frequency\].

Access Control (AC) - Access Enforcement (AC-3)28

Enforce approved authorizations for logical access to information and system resources in accordance with applicable access control policies.

Access Control (AC) - Access Enforcement (AC-3) - AC-3(1) Restricted Access To Privileged Functions11

Employ an audited override of automated access control mechanisms under \[Assignment: organization-defined conditions\] by \[Assignment: organization-defined roles\].

Access Control (AC) - Access Enforcement (AC-3) - AC-3(2) Dual Authorization5

Enforce dual authorization for \[Assignment: organization-defined privileged commands and/or other organization-defined actions\].

Access Control (AC) - Access Enforcement (AC-3) - AC-3(3) Mandatory Access Control17

Enforce \[Assignment: organization-defined mandatory access control policy\] over the set of covered subjects and objects specified in the policy, and where the policy: (a) Is uniformly enforced across the covered subjects and objects within the system; (b) Specifies that a subject that has been granted access to information is constrained from doing any of the following; (1) Passing the information to unauthorized subjects or objects; (2) Granting its privileges to other subjects; (3) Changing one or more security attributes (specified by the policy) on subjects, objects, the system, or system components; (4) Choosing the security attributes and attribute values (specified by the policy) to be associated with newly created or modified objects; and (5) Changing the rules governing access control; and (c) Specifies that \[Assignment: organization-defined subjects\] may explicitly be granted \[Assignment: organization-defined privileges\] such that they are not limited by any defined subset (or all) of the above constraints.

Access Control (AC) - Access Enforcement (AC-3) - AC-3(4) Discretionary Access Control17

Enforce \[Assignment: organization-defined discretionary access control policy\] over the set of covered subjects and objects specified in the policy, and where the policy specifies that a subject that has been granted access to information can do one or more of the following: (a) Pass the information to any other subjects or objects; (b) Grant its privileges to other subjects; (c) Change security attributes on subjects, objects, the system, or the system’s components; (d) Choose the security attributes to be associated with newly created or revised objects; or (e) Change the rules governing access control.

Access Control (AC) - Access Enforcement (AC-3) - AC-3(7) Role-Based Access Control25

Enforce a role-based access control policy over defined subjects and objects and control access based upon \[Assignment: organization-defined roles and users authorized to assume such roles\].

Access Control (AC) - Access Enforcement (AC-3) - AC-3(8) Revocation Of Access Authorizations17

Enforce the revocation of access authorizations resulting from changes to the security attributes of subjects and objects based on \[Assignment: organization-defined rules governing the timing of revocations of access authorizations\].

Access Control (AC) - Access Enforcement (AC-3) - AC-3(10) Audited Override Of Access Control Mechanisms11

Employ an audited override of automated access mechanisms under \[Assignment: organization-defined conditions\] by \[Assignment: organization-defined roles\].

Access Control (AC) - Access Enforcement (AC-3) - AC-3(12) Assert And Enforce Application Access18

a. Require applications to assert, as part of the installation process, the access needed to the following system applications and functions: \[Assignment: organization-defined system applications and functions\];b. Provide an enforcement mechanism to prevent unauthorized access; and c. Approve access changes after initial installation of the application.

Access Control (AC) - Access Enforcement (AC-3) - AC-3(13) Attribute-Based Access Control17

Enforce attribute-based access control policy over defined subjects and objects and control access based upon \[Assignment: organization-defined attributes to assume access permissions\].

Access Control (AC) - Access Enforcement (AC-3) - AC-3(15) Discretionary And Mandatory Access Control17

a. Enforce \[Assignment: organization-defined mandatory access control policy\] over the set of covered subjects and objects specified in the policy; and b. Enforce \[Assignment: organization-defined discretionary access control policy\] over the set of covered subjects and objects specified in the policy.

Access Control (AC) - Information Flow Enforcement (AC-4)11

Enforce approved authorizations for controlling the flow of information within the system and between connected systems based on \[Assignment: organization-defined information flow control policies\].

Access Control (AC) - Information Flow Enforcement (AC-4) - AC-4(21) Physical Or Logical Separation Of Infomation Flows36

Separate information flows logically or physically using \[Assignment: organization-defined mechanisms and/or techniques\] to accomplish \[Assignment: organization-defined required separations by types of information\].

Access Control (AC) - Information Flow Enforcement (AC-4) - AC-4(22) Access Only11

Provide access from a single device to computing platforms, applications, or data residing in multiple different security domains, while preventing information flow between the different security domains.

Access Control (AC) - Information Flow Enforcement (AC-4) - AC-4(26) Audit Filtering Actions17

When transferring information between different security domains, record and audit content filtering actions and results for the information being filtered.

Access Control (AC) - Information Flow Enforcement (AC-4) - AC-4(28) Linear Filter Pipelines19

When transferring information between different security domains, implement a linear content filter pipeline that is enforced with discretionary and mandatory access controls.

Access Control (AC) - Separation Of Duties (AC-5) - AC-5(b)5

Define system access authorizations to support separation of duties.

Access Control (AC) - Least Privilege (AC-6)25

Employ the principle of least privilege, allowing only authorized accesses for users (or processes acting on behalf of users) that are necessary to accomplish assigned organizational tasks.

Access Control (AC) - Least Privilege (AC-6) - AC-6(2)7

Require that users of system accounts (or roles) with access to \[Assignment: organization-defined security functions or security-relevant information\] use non-privileged accounts or roles, when accessing nonsecurity functions.

Access Control (AC) - Least Privilege (AC-6) - AC-6(3)7

Authorize network access to \[Assignment: organization-defined privileged commands\] only for \[Assignment: organization-defined compelling operational needs\] and document the rationale for such access in the security plan for the system.

Access Control (AC) - Least Privilege (AC-6) - AC-6(9)11

Log the execution of privileged functions.

Access Control (AC) - Least Privilege (AC-6) - AC-6(10)7

Prevent non-privileged users from executing privileged functions.

Access Control (AC) - Unsuccessful Logon Attempts (AC-7) - AC-7(4) Use Of Alternate Authentication Factor4

a. Allow the use of \[Assignment: organization-defined authentication factors\] that are different from the primary authentication factors after the number of organization-defined consecutive invalid logon attempts have been exceeded; and b. Enforce a limit of \[Assignment: organization-defined number\] consecutive invalid logon attempts through use of the alternative factors by a user during a \[Assignment: organization-defined time period\].

Access Control (AC) - Security And Privacy Attributes (AC-16) - AC-16(b)1

Ensure that the attribute associations are made and retained with the information.

Access Control (AC) - Remote Access (AC-17) - AC-17(1) Monitoring And Control29

Employ automated mechanisms to monitor and control remote access methods.

Access Control (AC) - Remote Access (AC-17) - AC-17(2) Protection Of Confidentiality And Integrity Using Encryption7

Implement cryptographic mechanisms to protect the confidentiality and integrity of remote access sessions.

Access Control (AC) - Remote Access (AC-17) - AC-17(4) Privileged Commands And Access29

a. Authorize the execution of privileged commands and access to security-relevant information via remote access only in a format that provides assessable evidence and for the following needs: \[Assignment: organization-defined needs\]; and b. Document the rationale for remote access in the security plan for the system.

Access Control (AC) - Remote Access (AC-17) - AC-17(9) Disconnect Or Disable Access29

Provide the capability to disconnect or disable remote access to the system within \[Assignment: organization-defined time period\].

Access Control (AC) - Remote Access (AC-17) - AC-17(10) Authenticate Remote Commands29

Provide the capability to disconnect or disable remote access to the system within \[Assignment: organization-defined time period\].

Access Control (AC) - Remote Access (AC-17) - AC-17(b)29

Authorize each type of remote access to the system prior to allowing such connections.

Access Control (AC) - Access Control Decisions (AC-24)15

\[Selection: Establish procedures; Implement mechanisms\] to ensure \[Assignment: organization-defined access control decisions\] are applied to each access request prior to access enforcement.

Access Control (AC) - Access Control Decisions (AC-24) - AC-24(1)7

Transmit \[Assignment: organization-defined access authorization information\] using \[Assignment: organization-defined controls\] to \[Assignment: organization-defined systems\] that enforce access control decisions.

Audit and Accountability (AU) - Event Logging (AU-2) - AU-2(b)13

Coordinate the event logging function with other organizational entities requiring audit-related information to guide and inform the selection criteria for events to be logged.

Audit and Accountability (AU) - Content of Audit Records (AU-3) - AU-3(1) Additional Audit Information2

Generate audit records containing the following additional information: \[Assignment: organization-defined additional information\].

Audit and Accountability (AU) - Content of Audit Records (AU-3) - AU-3(a)12

Ensure that audit records contain information that establishes the following: a. What type of event occurred.

Audit and Accountability (AU) - Content of Audit Records (AU-3) - AU-3(b)12

Ensure that audit records contain information that establishes the following: b. When the event occurred.

Audit and Accountability (AU) - Content of Audit Records (AU-3) - AU-3(c)12

Ensure that audit records contain information that establishes the following: c. Where the event occurred.

Audit and Accountability (AU) - Content of Audit Records (AU-3) - AU-3(d)12

Ensure that audit records contain information that establishes the following: d. Source of the event.

Audit and Accountability (AU) - Content of Audit Records (AU-3) - AU-3(e)12

Ensure that audit records contain information that establishes the following: e. Outcome of the event.

Audit and Accountability (AU) - Content of Audit Records (AU-3) - AU-3(f)12

Ensure that audit records contain information that establishes the following: e. Outcome of the event.

Audit and Accountability (AU) - Audit Log Stprage Capacity (AU-4) - AU-4(1) Transfer To Alternate Storage1

Transfer audit logs \[Assignment: organization-defined frequency\] to a different system, system component, or media other than the system or system component conducting the logging.

Audit and Accountability (AU) - Audit Record Review, Analysis And Reporting (AU-6) - AU-6(1) Automated Process Integration4

Integrate audit record review, analysis, and reporting processes using \[Assignment: organization-defined automated mechanisms\].

Audit and Accountability (AU) - Audit Record Review, Analysis And Reporting (AU-6) - AU-6(3) Correlate Audit Record Repositories14

Analyze and correlate audit records across different repositories to gain organization-wide situational awareness.

Audit and Accountability (AU) - Audit Record Review, Analysis And Reporting (AU-6) - AU-6(4) Central Review And Analysis14

Provide and implement the capability to centrally review and analyze audit records from multiple components within the system.

Audit and Accountability (AU) - Audit Record Review, Analysis And Reporting (AU-6) - AU-6(5) Central Review And Analysis4

Integrate analysis of audit records with analysis of \[Selection (one or more): vulnerability scanning information; performance data; system monitoring information; \[Assignment: organization-defined data/information collected from other sources\]\] to further enhance the ability to identify inappropriate or unusual activity.

Audit and Accountability (AU) - Audit Record Review, Analysis And Reporting (AU-6) - AU-6(6) Correletion With Physical Monitoring14

Correlate information from audit records with information obtained from monitoring physical access to further enhance the ability to identify suspicious, inappropriate, unusual, or malevolent activity.

Audit and Accountability (AU) - Audit Record Review, Analysis And Reporting (AU-6) - AU-6(9) Correletion With From Nontechnical Sources14

Correlate information from nontechnical sources with audit record information to enhance organization-wide situational awareness.

Audit and Accountability (AU) - Audit Record Reduction And Report Generation (AU-7) - AU-7(1) Automatic Processing1

Provide and implement the capability to process, sort, and search audit records for events of interest based on the following content: \[Assignment: organization-defined fields within audit records\].

Audit and Accountability (AU) - Time Stamps (AU-8) - AU-8(b)13

Record time stamps for audit records that meet \[Assignment: organization-defined granularity of time measurement\] and that use Coordinated Universal Time, have a fixed local time offset from Coordinated Universal Time, or that include the local time offset as part of the time stamp.

Audit and Accountability (AU) - Protection of Audit Information (AU-9) - AU-9(2) Store On Separate Physical Systems Or Components2

Store audit records \[Assignment: organization-defined frequency\] in a repository that is part of a physically different system or system component than the system or component being audited.

Audit and Accountability (AU) - Protection of Audit Information (AU-9) - AU-9(3) Cryptographic Protection24

Implement cryptographic mechanisms to protect the integrity of audit information and audit tools.

Audit and Accountability (AU) - Protection of Audit Information (AU-9) - AU-9(7) Store On Component With Different Operation Systems1

Store audit information on a component running a different operating system than the system or component being audited.

Audit and Accountability (AU) - Protection of Audit Information (AU-9) - AU-9(a)1

Protect audit information and audit logging tools from unauthorized access, modification, and deletion.

Audit and Accountability (AU) - Non-Repudiation (AU-10)14

Provide irrefutable evidence that an individual (or process acting on behalf of an individual) has performed \[Assignment: organization-defined actions to be covered by non-repudiation\].

Audit and Accountability (AU) - Audit Record Retention (AU-11)1

Retain audit records for \[Assignment: organization-defined time period consistent with records retention policy\] to provide support for after-the-fact investigations of incidents and to meet regulatory and organizational information retention requirements.

Audit and Accountability (AU) - Audit Record Retention (AU-11) - AU-11(1) Long-Term Retrieval Capability1

Employ \[Assignment: organization-defined measures\] to ensure that long-term audit records generated by the system can be retrieved.

Audit and Accountability (AU) - Audit Record Generation (AU-12) - AU-12(1) System-Wide And Time-Correlated Audit Trial14

Compile audit records from \[Assignment: organization-defined system components\] into a system-wide (logical or physical) audit trail that is time-correlated to within \[Assignment: organization-defined level of tolerance for the relationship between time stamps of individual records in the audit trail\].

Audit and Accountability (AU) - Audit Record Generation (AU-12) - AU-12(2) Standardized Formats14

Produce a system-wide (logical or physical) audit trail composed of audit records in a standardized format.

Audit and Accountability (AU) - Audit Record Generation (AU-12) - AU-12(3) Changes By Authorized Individuals22

Provide and implement the capability for \[Assignment: organization-defined individuals or roles\] to change the logging to be performed on \[Assignment: organization-defined system components\] based on \[Assignment: organization-defined selectable event criteria\] within \[Assignment: organization-defined time thresholds\].

Audit and Accountability (AU) - Audit Record Generation (AU-12) - AU-12(4) Query Parameter Audits Of Personally Identifiable Information13

Provide and implement the capability for auditing the parameters of user query events for data sets containing personally identifiable information.

Audit and Accountability (AU) - Audit Record Generation (AU-12) - AU-12(a)13

Provide audit record generation capability for the event types the system is capable of auditing as defined in AU-2a on \[Assignment: organization-defined system components\].

Audit and Accountability (AU) - Audit Record Generation (AU-12) - AU-12(c)13

Generate audit records for the event types defined in AU-2c that include the audit record content defined in AU-3.

Audit and Accountability (AU) - Session Audit (AU-14) - AU-14(3) Remote Viewing And Listening13

Provide and implement the capability for authorized users to remotely view and hear content related to an established user session in real time.

Audit and Accountability (AU) - Session Audit (AU-14) - AU-14(a)22

Provide and implement the capability for \[Assignment: organization-defined users or roles\] to \[Selection (one or more): record; view; hear; log\] the content of a user session under \[Assignment: organization-defined circumstances\].

Audit and Accountability (AU) - Session Audit (AU-14) - AU-14(b)22

Develop, integrate, and use session auditing activities in consultation with legal counsel and in accordance with applicable laws, executive orders, directives, regulations, policies, standards, and guidelines.

Audit and Accountability (AU) - Cross-Organizational Audit Logging (AU-16)1

Employ \[Assignment: organization-defined methods\] for coordinating \[Assignment: organization-defined audit information\] among external organizations when audit information is transmitted across organizational boundaries.

Assessment, Authorization, And Monitoring (CA) - Control Assessments (CA-2) - CA-2(2) Specialized Assessments5

Include as part of control assessments, \[Assignment: organization-defined frequency\], \[Selection: announced; unannounced\], \[Selection (one or more): in-depth monitoring; security instrumentation; automated security test cases; vulnerability scanning; malicious user testing; insider threat assessment; performance and load testing; data leakage or data loss assessment; \[Assignment: organization-defined other forms of assessment\]\].

Assessment, Authorization, And Monitoring (CA) - Control Assessments (CA-2) - CA-2(d)2

Assess the controls in the system and its environment of operation \[Assignment: organization-defined frequency\] to determine the extent to which the controls are implemented correctly, operating as intended, and producing the desired outcome with respect to meeting established security and privacy requirements.

Assessment, Authorization, And Monitoring (CA) - Continuous Monitoring (CA-7)8

Continuously monitor configuration management processes. Determine security impact, environment and operational risks.

Assessment, Authorization, And Monitoring (CA) - Continuous Monitoring (CA-7) - CA-7(4) Risk Monitoring2

Ensure risk monitoring is an integral part of the continuous monitoring strategy that includes the following: a. Effectiveness monitoring; b. Compliance monitoring; and c. Change monitoring.

Assessment, Authorization, And Monitoring (CA) - Continuous Monitoring (CA-7) - CA-7(b)22

Develop a system-level continuous monitoring strategy and implement continuous monitoring in accordance with the organization-level continuous monitoring strategy that includes: b. Establishing \[Assignment: organization-defined frequencies\] for monitoring and \[Assignment: organization-defined frequencies\] for assessment of control effectiveness.

Assessment, Authorization, And Monitoring (CA) - Internal System Connections (CA-9) - CA-9(b)7

Document, for each internal connection, the interface characteristics, security and privacy requirements, and the nature of the information communicated.

Configuration Management (CM) - Baseline Configuration (CM-2) - CM-2(2) Automation Support For Accuracy And Currency18

Maintain the currency, completeness, accuracy, and availability of the baseline configuration of the system using \[Assignment: organization-defined automated mechanisms\].

Configuration Management (CM) - Baseline Configuration (CM-2) - CM-2(a)17

Develop, document, and maintain under configuration control, a current baseline configuration of the system.

Configuration Management (CM) - Baseline Configuration (CM-2) - CM-2(b)8

Review and update the baseline configuration of the system: 1. \[Assignment: organization-defined frequency\]; 2. When required due to \[Assignment: organization-defined circumstances\]; and 3. When system components are installed or upgraded.

Configuration Management (CM) - Configuration Change Control (CM-3) - CM-3(3) Automated Change Implementation7

Implement changes to the current system baseline and deploy the updated baseline across the installed base using \[Assignment: organization-defined automated mechanisms\].

Configuration Management (CM) - Configuration Change Control (CM-3) - CM-3(a)2

Determine and document the types of changes to the system that are configuration-controlled.

Configuration Management (CM) - Access Restrictions For Change (CM-5) - CM-5(1) Automated Access Enforcement And Audit Records31

a. Enforce access restrictions using \[Assignment: organization-defined automated mechanisms\]; and b. Automatically generate audit records of the enforcement actions.

Configuration Management (CM) - Configuration Settings (CM-6)2

The organization: (i) establishes mandatory configuration settings for information technology products employed within the information system; (ii) configures the security settings of information technology products to the most restrictive mode consistent with operational requirements; (iii) documents the configuration settings; and (iv) enforces the configuration settings in all components of the information system.

Configuration Management (CM) - Configuration Settings (CM-6) - CM-6(a)43

Establish and document configuration settings for components employed within the system that reflect the most restrictive mode consistent with operational requirements using \[Assignment: organization-defined common secure configurations\].

Configuration Management (CM) - Least Functionality (CM-7) - CM-7(b)11

Prohibit or restrict the use of the following functions, ports, protocols, software, and/or services: \[Assignment: organization-defined prohibited or restricted functions, system ports, protocols, software, and/or services\].

Configuration Management (CM) - System Component Inventory (CM-8) - CM-8(1) Updates During Installation And Removals2

Update the inventory of system components as part of component installations, removals, and system updates.

Configuration Management (CM) - System Component Inventory (CM-8) - CM-8(2) Automated Maintenance1

Maintain the currency, completeness, accuracy, and availability of the inventory of system components using \[Assignment: organization-defined automated mechanisms\].

Configuration Management (CM) - System Component Inventory (CM-8) - CM-8(3) Automated Unauthorized Component Detection4

The organization: Employs automated mechanisms \[Assignment: organization-defined frequency\] to detect the presence of unauthorized hardware, software, and firmware components within the information system; and Takes the following actions when unauthorized components are detected: \[Selection (one or more): disables network access by such components; isolates the components; notifies \[Assignment: organization-defined personnel or roles\]\].

Configuration Management (CM) - System Component Inventory (CM-8) - CM-8(6) Assessed Configurations And Approved Deviations15

Include assessed component configurations and any approved deviations to current deployed configurations in the system component inventory.

Configuration Management (CM) - System Component Inventory (CM-8) - CM-8(a)2

Develop and document an inventory of system components that: 1. Accurately reflects the system; 2. Includes all components within the system; 3. Does not include duplicate accounting of components or components assigned to any other system; 4. Is at the level of granularity deemed necessary for tracking and reporting; and 5. Includes the following information to achieve system component accountability: \[Assignment: organization-defined information deemed necessary to achieve effective system component accountability\].

Configuration Management (CM) - System Component Inventory (CM-8) - CM-8(b)2

Review and update the system component inventory \[Assignment: organization-defined frequency\].

Configuration Management (CM) - Configuration Management Plan (CM-9) - CM-9(b)41

Develop, document, and implement a configuration management plan for the system that: b. Establishes a process for identifying configuration items throughout the system development life cycle and for managing the configuration of the configuration items.

Configuration Management (CM) - Information Location (CM-12) - CM-12(b)1

Identify and document the users who have access to the system and system components where the information is processed and stored.

Contingency Planning (CP) - Policy And Procedures (CP-1) - CP-1(2)10

Implement transaction recovery for systems that are transaction-based.

Contingency Planning (CP) - Policy And Procedures (CP-1) - CP-1(a)6

a. Develop, document, and disseminate to \[Assignment: organization-defined personnel or roles\]: 1. \[Selection (one or more): Organization-level; Mission/business process-level; System-level\] contingency planning policy that: a). Addresses purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance; and b). Is consistent with applicable laws, executive orders, directives, regulations, policies, standards, and guidelines; and 2. Procedures to facilitate the implementation of the contingency planning policy and the associated contingency planning controls.

Contingency Planning (CP) - Contingency Plan (CP-2) - CP-2(a)6

a. Develop a contingency plan for the system that: 1. Identifies essential mission and business functions and associated contingency requirements; 2. Provides recovery objectives, restoration priorities, and metrics; 3. Addresses contingency roles, responsibilities, assigned individuals with contact information; 4. Addresses maintaining essential mission and business functions despite a system disruption, compromise, or failure; 5. Addresses eventual, full system restoration without deterioration of the controls originally planned and implemented; 6. Addresses the sharing of contingency information; and 7. Is reviewed and approved by \[Assignment: organization-defined personnel or roles\].

Contingency Planning (CP) - Contingency Plan (CP-2) - CP-2(d)6

Review the contingency plan for the system \[Assignment: organization-defined frequency\]

Contingency Planning (CP) - Contingency Plan (CP-2) - CP-2(e)6

Update the contingency plan to address changes to the organization, system, or environment of operation and problems encountered during contingency plan implementation, execution, or testing.

Contingency Planning (CP) - Contingency Plan (CP-2) - CP-2(5) Continue Mission And Business Functions17

Plan for the continuance of \[Selection: all; essential\] mission and business functions with minimal or no loss of operational continuity and sustains that continuity until full system restoration at primary processing and/or storage sites.

Contingency Planning (CP) - Contingency Plan (CP-2) - CP-2(6) Alternate Processing And Storage Sites4

Plan for the transfer of \[Selection: all; essential\] mission and business functions to alternate processing and/or storage sites with minimal or no loss of operational continuity and sustain that continuity through system restoration to primary processing and/or storage sites.

Contingency Planning (CP) - Alternate Storage Sites (CP-6) - CP-6(1) Separation From Primary Site9

Identify an alternate storage site that is sufficiently separated from the primary storage site to reduce susceptibility to the same threats.

Contingency Planning (CP) - Alternate Storage Sites (CP-6) - CP-6(2) Recovery Time And Recovery Point Objectives14

Configure the alternate storage site to facilitate recovery operations in accordance with recovery time and recovery point objectives.

Contingency Planning (CP) - Alternate Storage Sites (CP-6) - CP-6(a)9

Establish an alternate storage site, including necessary agreements to permit the storage and retrieval of system backup information.

Contingency Planning (CP) - System Backup (CP-9) - CP-9(8) Cryptographic Protection3

Implement cryptographic mechanisms to prevent unauthorized disclosure and modification of \[Assignment: organization-defined backup information\].

Contingency Planning (CP) - System Backup (CP-9) - CP-9(a)12

Conduct backups of user-level information contained in \[Assignment: organization-defined system components\] \[Assignment: organization-defined frequency consistent with recovery time and recovery point objectives\].

Contingency Planning (CP) - System Backup (CP-9) - CP-9(b)12

Conduct backups of system-level information contained in the system \[Assignment: organization-defined frequency consistent with recovery time and recovery point objectives\].

Contingency Planning (CP) - System Backup (CP-9) - CP-9(c)12

Conduct backups of system documentation, including security- and privacy-related documentation \[Assignment: organization-defined frequency consistent with recovery time and recovery point objectives\].

Contingency Planning (CP) - System Backup (CP-9) - CP-9(d)18

Protect the confidentiality, integrity, and availability of backup information.

Contingency Planning (CP) - System Recovery And Reconstitution (CP-10)15

Provide for the recovery and reconstitution of the system to a known state within \[Assignment: organization-defined time period consistent with recovery time and recovery point objectives\] after a disruption, compromise, or failure.

Contingency Planning (CP) - System Recovery And Reconstitution (CP-10) - CP-10(2) Transaction Recovery10

Implement transaction recovery for systems that are transaction-based.

Identification and Authentication (IA) - Identification and Authentication (Organizational users) (IA-2)1

The information system uniquely identifies and authenticates organizational users (or processes acting on behalf of organizational users).

Identification and Authentication (IA) - Identification and Authentication (Organizational users) (IA-2) - IA-2(1) Multi-Factor Authentication To Privileged Accounts3

Implement multi-factor authentication for access to privileged accounts.

Identification and Authentication (IA) - Identification and Authentication (Organizational users) (IA-2) - IA-2(2) Multi-Factor Authentication To Non-Privileged Accounts3

Implement multi-factor authentication for access to non-privileged accounts.

Identification and Authentication (IA) - Identification and Authentication (Organizational users) (IA-2) - IA-2(6) Acces To Accounts — Separate Device3

Implement multi-factor authentication for \[Selection (one or more): local; network; remote\] access to \[Selection (one or more): privileged accounts; non-privileged accounts\] such that: (a) One of the factors is provided by a device separate from the system gaining access; and (b) The device meets \[Assignment: organization-defined strength of mechanism requirements\].

Identification and Authentication (IA) - Identification and Authentication (Organizational users) (IA-2) - IA-2(8) Access To Accounts — Replay Resistant3

Implement replay-resistant authentication mechanisms for access to \[Selection (one or more): privileged accounts; non-privileged accounts\].

Identification and Authentication (IA) - Device Identification And Authentication (IA-3) - IA-3(3) Dynamic Address Allocation13

a. Where addresses are allocated dynamically, standardize dynamic address allocation lease information and the lease duration assigned to devices in accordance with \[Assignment: organization-defined lease information and lease duration\]; and b. Audit lease information when assigned to a device.

Identification and Authentication (IA) - Identifier Management (IA-4) - IA-4(8)1

Generate pairwise pseudonymous identifiers.

Identification and Authentication (IA) - Identifier Management (IA-4) - IA-4(b)1

Manage system identifiers by: b. Selecting an identifier that identifies an individual, group, role, service, or device.

Identification and Authentication (IA) - Identifier Management (IA-4) - IA-4(d)1

Manage system identifiers by: d. Preventing reuse of identifiers for \[Assignment: organization-defined time period\].

Identification and Authentication (IA) - Identifier Management (IA-4) - IA-4(4)1

Manage individual identifiers by uniquely identifying each individual as \[Assignment: organization-defined characteristic identifying individual status\].

Identification and Authentication (IA) - Authenticator Management (IA-5)1

Authenticate users and devices. Automate administrative control. Enforce restrictions. Protect against unauthorized use.

Identification and Authentication (IA) - Authenticator Management (IA-5) - IA-5(1) Password-Based Authentication6

The information system, for password-based authentication that enforces minimum password complexity, stores and transmits only cryptographically-protected passwords, enforces password minimum and maximum lifetime restrictions, prohibits password reuse, allows the use of a temporary password for system logons with an immediate change to a permanent password etc.

Identification and Authentication (IA) - Authenticator Management (IA-5) - IA-5(8) Multiple System Accounts1

Implement \[Assignment: organization-defined security controls\] to manage the risk of compromise due to individuals having accounts on multiple systems.

Identification and Authentication (IA) - Authenticator Management (IA-5) - IA-5(18) Password Managers1

a. Employ \[Assignment: organization-defined password managers\] to generate and manage passwords; and b. Protect the passwords using \[Assignment: organization-defined controls\].

Identification and Authentication (IA) - Authenticator Management (IA-5) - IA-5(b)1

Manage system authenticators by: b. Establishing initial authenticator content for any authenticators issued by the organization.

Identification and Authentication (IA) - Authenticator Management (IA-5) - IA-5(c)1

Manage system authenticators by: c. Ensuring that authenticators have sufficient strength of mechanism for their intended use.

Identification and Authentication (IA) - Authenticator Management (IA-5) - IA-5(d)1

Manage system authenticators by: d. Establishing and implementing administrative procedures for initial authenticator distribution, for lost or compromised or damaged authenticators, and for revoking authenticators.

Identification and Authentication (IA) - Authenticator Management (IA-5) - IA-5(f)1

Manage system authenticators by: f. Changing or refreshing authenticators \[Assignment: organization-defined time period by authenticator type\] or when \[Assignment: organization-defined events\] occur.

Identification and Authentication (IA) - Authenticator Management (IA-5) - IA-5(h)1

Manage system authenticators by: h. Requiring individuals to take, and having devices implement, specific controls to protect authenticators.

Identification and Authentication (IA) - IA-8(2) Acceptance Of External Authenticators - IA-8(2) Acceptance Of External Authenticators1

Uniquely identify and authenticate non-organizational users or processes acting on behalf of non-organizational users.

Incident Response (IR) - Incident Handling (IR-4) - IR-4(a)1

Implement an incident handling capability for incidents that is consistent with the incident response plan and includes preparation, detection and analysis, containment, eradication, and recovery.

Maintenance (MA) - Nonlocal Maintenance (MA-4) - MA-4(1) Logging And Review13

a. Log \[Assignment: organization-defined audit events\] for nonlocal maintenance and diagnostic sessions; and b. Review the audit records of the maintenance and diagnostic sessions to detect anomalous behavior.

Maintenance (MA) - Nonlocal Maintenance (MA-4) - MA-4(c)1

Employ strong authentication in the establishment of nonlocal maintenance and diagnostic sessions.

Media Protection (MP) - Media Access (MP-2)23

Restrict access to \[Assignment: organization-defined types of digital and/or non-digital media\] to \[Assignment: organization-defined personnel or roles\].

Physical And Environmental Protection (PE) - Monitoring Physical Access (PE-6) - PE-6(2) Monitoring Physical Access1

Recognize \[Assignment: organization-defined classes or types of intrusions\] and initiate \[Assignment: organization-defined response actions\] using \[Assignment: organization-defined automated mechanisms\].

Physical And Environmental Protection (PE) - Monitoring Physical Access (PE-6) - PE-6(4) Monitoring Physical Access1

Monitor physical access to the system in addition to the physical access monitoring of the facility at \[Assignment: organization-defined physical spaces containing one or more components of the system\].

Program Management (PM) - Mission And Business Process Defination (PM-11) - PM-11(b)4

Determine information protection and personally identifiable information processing needs arising from the defined mission and business processes.

Program Management (PM) - Testing, Training, And Monitoring (PM-14) - PM-14(a)(1)22

a. Implement a process for ensuring that organizational plans for conducting security and privacy testing, training, and monitoring activities associated with organizational systems: 1. Are developed and maintained.

Program Management (PM) - Testing, Training, And Monitoring (PM-14) - PM-14(b)22

Review testing, training, and monitoring plans for consistency with the organizational risk management strategy and organization-wide priorities for risk response actions.

Program Management (PM) - Threat Awareness Program (PM-16)1

Implement a threat awareness program that includes a cross-organization information-sharing capability for threat intelligence.

Program Management (PM) - Protecting Controlled Unclassified Information On External Systems (PM-17) - PM-17(b)9

Review and update the policy and procedures \[Assignment: organization-defined frequency\].

Program Management (PM) - Accounting Of Disclosures (PM-21) - PM-21(b)1

Retain the accounting of disclosures for the length of the time the personally identifiable information is maintained or five years after the disclosure is made, whichever is longer.

Program Management (PM) - Continuous Monitoring Strategy (PM-31)22

Develop an organization-wide continuous monitoring strategy and implement continuous monitoring programs that include: a. Establishing the following organization-wide metrics to be monitored: \[Assignment: organization-defined metrics\]; b. Establishing \[Assignment: organization-defined frequencies\] for monitoring and \[Assignment: organization-defined frequencies\] for assessment of control effectiveness; c. Ongoing monitoring of organizationally-defined metrics in accordance with the continuous monitoring strategy; d. Correlation and analysis of information generated by control assessments and monitoring; e. Response actions to address results of the analysis of control assessment and monitoring information; and f. Reporting the security and privacy status of organizational systems to \[Assignment: organization-defined personnel or roles\] \[Assignment: organization-defined frequency\].

Risk Assessment (RA) - Policy And Procedures (RA-1) - RA-1(a)1

Establish and maintain a cyber threat hunting capability to: 1. Search for indicators of compromise in organizational systems; and 2. Detect, track, and disrupt threats that evade existing controls.

Risk Assessment (RA) - Risk Assessment (RA-3) - RA-3(4) Predictive Cyber Analytics1

Employ the following advanced automation and analytics capabilities to predict and identify risks to \[Assignment: organization-defined systems or system components\]: \[Assignment: organization-defined advanced automation and analytics capabilities\].

Risk Assessment (RA) - Risk Assessment (RA-3) - RA-3(a)(1)2

a. Conduct a risk assessment, including: 1. Identifying threats to and vulnerabilities in the system.

Risk Assessment (RA) - Vulnerability Monitoring And Scanning (RA-5) - RA-5(4) Discoverable Information1

Determine information about the system that is discoverable and take \[Assignment: organization-defined corrective actions\].

Risk Assessment (RA) - Vulnerability Monitoring And Scanning (RA-5) - RA-5(a)1

Monitor and scan for vulnerabilities in the system and hosted applications \[Assignment: organization-defined frequency and/or randomly in accordance with organization-defined process\] and when new vulnerabilities potentially affecting the system are identified and reported.

Risk Assessment (RA) - Threat Hunting (RA-10) - RA-10(a)1

Establish and maintain a cyber threat hunting capability to: 1. Search for indicators of compromise in organizational systems; and 2. Detect, track, and disrupt threats that evade existings.

System and Services Acquisition (SA) - Policy And Procedures (SA-1) - SA-1(1)1

Require the developer of the system, system component, or system service to enable integrity verification of software and firmware components.

System and Services Acquisition (SA) - External System Services (SA-9) - SA-9(6) Organization-Controlled Cryptographic Keys2

Maintain exclusive control of cryptographic keys for encrypted material stored or transmitted through an external system.

System and Services Acquisition (SA) - Developer Configuration Management (SA-10) - SA-10(1) Software And Firmware Integrity Verification1

Require the developer of the system, system component, or system service to enable integrity verification of software and firmware components.

System and Services Acquisition (SA) - Development Process, Standards, And Tools (SA-15) - SA-15(a)(4)2

a. Require the developer of the system, system component, or system service to follow a documented development process that: 4. Documents, manages, and ensures the integrity of changes to the process and/or tools used in development.

System and Communications Protection (SC) - Denial Of Service Protection (SC-5) - SC-5(1) Restrict Ability TO Attack Other Systems1

Restrict the ability of individuals to launch the following denial-of-service attacks against other systems: \[Assignment: organization-defined denial-of-service attacks\].

System and Communications Protection (SC) - Denial Of Service Protection (SC-5) - SC-5(2) Capacity, Bandwidth, And Redundancy18

Manage capacity, bandwidth, or other redundancy to limit the effects of information flooding denial-of-service attacks.

System and Communications Protection (SC) - Denial Of Service Protection (SC-5) - SC-5(3) Detection And Monitoring1

a. Employ the following monitoring tools to detect indicators of denial-of-service attacks against, or launched from, the system: \[Assignment: organization-defined monitoring tools\]; and b. Monitor the following system resources to determine if sufficient resources exist to prevent effective denial-of-service attacks: \[Assignment: organization-defined system resources\].

System and Communications Protection (SC) - Denial Of Service Protection (SC-5) - SC-5(a)1

\[Selection: Protect against; Limit\] the effects of the following types of denial-of-service events: \[Assignment: organization-defined types of denial-of-service events\].

System and Communications Protection (SC) - Denial Of Service Protection (SC-5) - SC-5(b)1

Employ the following controls to achieve the denial-of-service objective: \[Assignment: organization-defined controls by type of denial-of-service event\].

System and Communications Protection (SC) - Resource Availability (SC-6)7

Protect the availability of resources by allocating \[Assignment: organization-defined resources\] by \[Selection (one or more): priority; quota; \[Assignment: organization-defined controls\]\].

System and Communications Protection (SC) - Boundary Protection (SC-7) - SC-7(2) Public Access19

Provide the capability to dynamically isolate \[Assignment: organization-defined system components\] from other system components.

System and Communications Protection (SC) - Boundary Protection (SC-7) - SC-7(3) Access Points20

Limit the number of external network connections to the system.

System and Communications Protection (SC) - Boundary Protection (SC-7) - SC-7(4) External Telecommunications Services11

a. Implement a managed interface for each external telecommunication service; b. Establish a traffic flow policy for each managed interface; c. Protect the confidentiality and integrity of the information being transmitted across each interface; d. Document each exception to the traffic flow policy with a supporting mission or business need and duration of that need; e. Review exceptions to the traffic flow policy \[Assignment: organization-defined frequency\] and remove exceptions that are no longer supported by an explicit mission or business need; f. Prevent unauthorized exchange of control plane traffic with external networks; g. Publish information to enable remote networks to detect unauthorized control plane traffic from internal networks; and h. Filter unauthorized control plane traffic from external networks.

System and Communications Protection (SC) - Boundary Protection (SC-7) - SC-7(5) Deny By Default — Allow By Exception20

Deny network communications traffic by default and allow network communications traffic by exception \[Selection (one or more): at managed interfaces; for \[Assignment: organization-defined systems\]\].

System and Communications Protection (SC) - Boundary Protection (SC-7) - SC-7(7) Split Tunneling For Remote Devices28

Prevent split tunneling for remote devices connecting to organizational systems unless the split tunnel is securely provisioned using \[Assignment: organization-defined safeguards\].

System and Communications Protection (SC) - Boundary Protection (SC-7) - SC-7(9) Restrict Threatening Outgoing Communications Traffic31

a. Detect and deny outgoing communications traffic posing a threat to external systems; and b. Audit the identity of internal users associated with denied communications.

System and Communications Protection (SC) - Boundary Protection (SC-7) - SC-7(11) Restrict Incoming communications Traffic31

Only allow incoming communications from \[Assignment: organization-defined authorized sources\] to be routed to \[Assignment: organization-defined authorized destinations\].

System and Communications Protection (SC) - Boundary Protection (SC-7) - SC-7(12) Host-Based Protection32

Implement \[Assignment: organization-defined host-based boundary protection mechanisms\] at \[Assignment: organization-defined system components\].

System and Communications Protection (SC) - Boundary Protection (SC-7) - SC-7(16) Prevent Discovery Of System Components32

Prevent the discovery of specific system components that represent a managed interface.

System and Communications Protection (SC) - Boundary Protection (SC-7) - SC-7(20) Prevent Discovery Of System Components19

Prevent the discovery of specific system components that represent a managed interface.

System and Communications Protection (SC) - Boundary Protection (SC-7) - SC-7(21) Isolation Of System Components31

Employ boundary protection mechanisms to isolate \[Assignment: organization-defined system components\] supporting \[Assignment: organization-defined missions and/or business functions\].

System and Communications Protection (SC) - Boundary Protection (SC-7) - SC-7(24) Personally Identifiable Information31

For systems that process personally identifiable information: a. Apply the following processing rules to data elements of personally identifiable information: \[Assignment: organization-defined processing rules\];b. Monitor for permitted processing at the external interfaces to the system and at key internal boundaries within the system; c. Document each processing exception; and d. Review and remove exceptions that are no longer supported.

System and Communications Protection (SC) - Boundary Protection (SC-7) - SC-7(25) Unclassified National Security System Connections27

Prohibit the direct connection of \[Assignment: organization-defined unclassified national security system\] to an external network without the use of \[Assignment: organization-defined boundary protection device\].

System and Communications Protection (SC) - Boundary Protection (SC-7) - SC-7(26) Classified National Security System Connections27

Prohibit the direct connection of a classified national security system to an external network without the use of \[Assignment: organization-defined boundary protection device\].

System and Communications Protection (SC) - Boundary Protection (SC-7) - SC-7(27) Unclassified Non-National Security System Connections27

Prohibit the direct connection of \[Assignment: organization-defined unclassified non-national security system\] to an external network without the use of \[Assignment: organization-defined boundary protection device\].

System and Communications Protection (SC) - Boundary Protection (SC-7) - SC-7(28) Connections To Public Networks27

Prohibit the direct connection of \[Assignment: organization-defined system\] to a public network.

System and Communications Protection (SC) - Boundary Protection (SC-7) - SC-7(a)31

Monitor and control communications at the external managed interfaces to the system and at key internal managed interfaces within the system.

System and Communications Protection (SC) - Boundary Protection (SC-7) - SC-7(b)20

Implement subnetworks for publicly accessible system components that are \[Selection: physically; logically\] separated from internal organizational networks.

System and Communications Protection (SC) - Boundary Protection (SC-7) - SC-7(c)31

Connect to external networks or systems only through managed interfaces consisting of boundary protection devices arranged in accordance with an organizational security and privacy architecture.

System and Communications Protection (SC) - Transmission Confidentiality And Integrity (SC-8)7

Protect the \[Selection (one or more): confidentiality; integrity\] of transmitted information.

System and Communications Protection (SC) - Transmission Confidentiality And Integrity (SC-8) - SC-8(1) Cryptographic Protection7

Implement cryptographic mechanisms to \[Selection (one or more): prevent unauthorized disclosure of information; detect changes to information\] during transmission.

System and Communications Protection (SC) - Transmission Confidentiality And Integrity (SC-8) - SC-8(2) Pre- And Post-Transmission Handling7

Maintain the \[Selection (one or more): confidentiality; integrity\] of information during preparation for transmission and during reception.

System and Communications Protection (SC) - Transmission Confidentiality And Integrity (SC-8) - SC-8(3) Cryptographic Protection For Message Externals25

Implement cryptographic mechanisms to protect message externals unless otherwise protected by \[Assignment: organization-defined alternative physical controls\].

System and Communications Protection (SC) - Transmission Confidentiality And Integrity (SC-8) - SC-8(4) Conceal Or Ramdomize Communications25

Implement cryptographic mechanisms to conceal or randomize communication patterns unless otherwise protected by \[Assignment: organization-defined alternative physical controls\].

System and Communications Protection (SC) - Transmission Confidentiality And Integrity (SC-8) - SC-8(5) Protected Distribution System7

Implement \[Assignment: organization-defined protected distribution system\] to \[Selection (one or more): prevent unauthorized disclosure of information; detect changes to information\] during transmission.

System and Communications Protection (SC) - Cryptographic Key Establishment And Management (SC-12)2

Establish and manage cryptographic keys when cryptography is employed within the system in accordance with the following key management requirements: \[Assignment: organization-defined requirements for key generation, distribution, storage, access, and destruction\].

System and Communications Protection (SC) - Cryptographic Key Establishment And Management (SC-12) - SC-12(2) Symmetric Keys2

Produce, control, and distribute symmetric cryptographic keys using \[Selection: NIST FIPS-validated; NSA-approved\] key management technology and processes.

System and Communications Protection (SC) - Cryptographic Key Establishment And Management (SC-12) - SC-12(6) Physical Control Of Keys2

Maintain physical control of cryptographic keys when stored information is encrypted by external service providers.

System and Communications Protection (SC) - Cryptographic Protection (SC-13) - SC-13(a)26

Determine the \[Assignment: organization-defined cryptographic uses\].

System and Communications Protection (SC) - Transmission Of Security And Privacy Attributes (SC-16) - SC-16(1) Integrity Verification4

Verify the integrity of transmitted security and privacy attributes.

System and Communications Protection (SC) - Architecture And Provisioning For Name/Address Resolution Service (SC-22)6

Ensure the systems that collectively provide name/address resolution service for an organization are fault-tolerant and implement internal and external role separation.

System and Communications Protection (SC) - Session Authenticity (SC-23)7

Protect the authenticity of communications sessions.

System and Communications Protection (SC) - Session Authenticity (SC-23) - SC-23(3) Unique System-Generated Session Identifiers15

Generate a unique session identifier for each session with \[Assignment: organization-defined randomness requirements\] and recognize only session identifiers that are system-generated.

System and Communications Protection (SC) - Session Authenticity (SC-23) - SC-23(5) Allowed Certificate Authorities1

Only allow the use of \[Assignment: organization-defined certificate authorities\] for verification of the establishment of protected sessions.

System and Communications Protection (SC) - Thin Nodes (SC-25)19

Employ minimal functionality and information storage on the following system components: \[Assignment: organization-defined system components\].

System and Communications Protection (SC) - Protection Of Information At Rest (SC-28) - SC-28(1) Cryptographic Protection19

Implement cryptographic mechanisms to prevent unauthorized disclosure and modification of the following information at rest on \[Assignment: organization-defined system components or media\]: \[Assignment: organization-defined information\].

System and Communications Protection (SC) - Protection Of Information At Rest (SC-28) - SC-28(2) Offline Storage2

Remove the following information from online storage and store offline in a secure location: \[Assignment: organization-defined information\].

System and Communications Protection (SC) - Distributed Processing And Storage (SC-36)4

Distribute the following processing and storage components across multiple \[Selection: physical locations; logical domains\]: \[Assignment: organization-defined processing and storage components\].

System and Communications Protection (SC) - Distributed Processing And Storage (SC-36) - SC-36(1)(a)5

Employ polling techniques to identify potential faults, errors, or compromises to the following processing and storage components: \[Assignment: organization-defined distributed processing and storage components\].

System and Communications Protection (SC) - Usage Restrictions (SC-43) - SC-43(b)1

Authorize, monitor, and control the use of such components within the system.

System and Information integrity (SI) - Policy And Procedures (SI-1) - SI-1(1)(c)9

Audit the use of the manual override capability.

System and Information integrity (SI) - Policy And Procedures (SI-1) - SI-1(a)(2)9

a. Develop, document, and disseminate to \[Assignment: organization-defined personnel or roles\]: 2. Procedures to facilitate the implementation of the system and information integrity policy and the associated system and information integrity controls;.

System and Information integrity (SI) - Policy And Procedures (SI-1) - SI-1(c)(2)9

c. Review and update the current system and information integrity: 2. Procedures \[Assignment: organization-defined frequency\] and following \[Assignment: organization-defined events\].

System and Information integrity (SI) - Flaw Remediation (SI-2) - SI-2(2) Automated Flaw RemediationN Status5

Determine if system components have applicable security-relevant software and firmware updates installed using \[Assignment: organization-defined automated mechanisms\] \[Assignment: organization-defined frequency\].

System and Information integrity (SI) - Flaw Remediation (SI-2) - SI-2(5) Automatic Software And Firmware Updated5

Install \[Assignment: organization-defined security-relevant software and firmware updates\] automatically to \[Assignment: organization-defined system components\].

System and Information integrity (SI) - Flaw Remediation (SI-2) - SI-2(a)6

Identify, report, and correct system flaws.

System and Information integrity (SI) - Flaw Remediation (SI-2) - SI-2(c)5

Install security-relevant software and firmware updates within \[Assignment: organization-defined time period\] of the release of the updates.

System and Information integrity (SI) - Flaw Remediation (SI-2) - SI-2(d)5

Incorporate flaw remediation into the organizational configuration management process.

System and Information integrity (SI) - Malicious Code Protection (SI-3) - SI-3(8) Detect Unauthorized Commands10

a. Detect the following unauthorized operating system commands through the kernel application programming interface on \[Assignment: organization-defined system hardware components\]: \[Assignment: organization-defined unauthorized operating system commands\]; and b. \[Selection (one or more): issue a warning; audit the command execution; prevent the execution of the command\].

System and Information integrity (SI) - Malicious Code Protection (SI-3) - SI-3(c)(2)3

c. Configure malicious code protection mechanisms to: 2. \[Selection (one or more): block malicious code; quarantine malicious code; take \[Assignment: organization-defined action\]\]; and send alert to \[Assignment: organization-defined personnel or roles\] in response to malicious code detection.

System and Information integrity (SI) - System Monitoring (SI-4) - SI-4(1) System-Wide Intrusion Detection System1

Connect and configure individual intrusion detection tools into a system-wide intrusion detection system.

System and Information integrity (SI) - System Monitoring (SI-4) - SI-4(2) Automated Tools For Real-Time Analysis10

Implement the following additional monitoring of privileged users: \[Assignment: organization-defined additional monitoring\]. Employ automated tools and mechanisms to support near real-time analysis of events.

System and Information integrity (SI) - System Monitoring (SI-4) - SI-4(3) Automated Tools And Mechanism Integration1

Employ automated tools and mechanisms to integrate intrusion detection tools and mechanisms into access control and flow control mechanisms.

System and Information integrity (SI) - System Monitoring (SI-4) - SI-4(4) Inbound and Outbound Communications Traffic1

The information system monitors inbound and outbound communications traffic continuously for unusual or unauthorized activities or conditions.

System and Information integrity (SI) - System Monitoring (SI-4) - SI-4(10) Visibility Of Encrypted Communications1

Make provisions so that \[Assignment: organization-defined encrypted communications traffic\] is visible to \[Assignment: organization-defined system monitoring tools and mechanisms\].

System and Information integrity (SI) - System Monitoring (SI-4) - SI-4(12) Automated Organization-Generated Alerts1

Alert \[Assignment: organization-defined personnel or roles\] using \[Assignment: organization-defined automated mechanisms\] when the following indications of inappropriate or unusual activities with security or privacy implications occur: \[Assignment: organization-defined activities that trigger alerts\].

System and Information integrity (SI) - System Monitoring (SI-4) - SI-4(13) Analyze Traffic And Event Patterns1

a. Analyze communications traffic and event patterns for the system; b. Develop profiles representing common traffic and event patterns; and c. Use the traffic and event profiles in tuning system-monitoring devices.

System and Information integrity (SI) - System Monitoring (SI-4) - SI-4(14) Wireless Intrusion Detection1

Employ a wireless intrusion detection system to identify rogue wireless devices and to detect attack attempts and potential compromises or breaches to the system.

System and Information integrity (SI) - System Monitoring (SI-4) - SI-4(17) Integrated Situational Awareness14

Correlate information from monitoring physical, cyber, and supply chain activities to achieve integrated, organization-wide situational awareness.

System and Information integrity (SI) - System Monitoring (SI-4) - SI-4(20) Privileged Users9

Implement the following additional monitoring of privileged users: \[Assignment: organization-defined additional monitoring\].

System and Information integrity (SI) - System Monitoring (SI-4) - SI-4(23) Host-Based Devices1

Implement the following host-based monitoring mechanisms at \[Assignment: organization-defined system components\]: \[Assignment: organization-defined host-based monitoring mechanisms\].

System and Information integrity (SI) - System Monitoring (SI-4) - SI-4(25) Optimize Network Traffic Analysis1

Provide visibility into network traffic at external and key internal system interfaces to optimize the effectiveness of monitoring devices.

System and Information integrity (SI) - System Monitoring (SI-4) - SI-4(a)1

Monitor the system to detect: 1. Attacks and indicators of potential attacks in accordance with the following monitoring objectives: \[Assignment: organization-defined monitoring objectives\]; and 2. Unauthorized local, network, and remote connections.

System and Information integrity (SI) - System Monitoring (SI-4) - SI-4(b)1

Identify unauthorized use of the system through the following techniques and methods: \[Assignment: organization-defined techniques and methods\].

System and Information integrity (SI) - System Monitoring (SI-4) - SI-4(c)1

c. Invoke internal monitoring capabilities or deploy monitoring devices: 1. Strategically within the system to collect organization-determined essential information; and 2. At ad hoc locations within the system to track specific types of transactions of interest to the organization.

System and Information integrity (SI) - System Monitoring (SI-4) - SI-4(d)1

Analyze detected events and anomalies.

System and Information integrity (SI) - Secuity Alerts, Advisories, And Directives (SI-5) - SI-5(1) Automated Alerts And Advisories2

Broadcast security alert and advisory information throughout the organization using \[Assignment: organization-defined automated mechanisms\].

System and Information integrity (SI) - Secuity Alerts, Advisories, And Directives (SI-5) - SI-5(b)2

Generate internal security alerts, advisories, and directives as deemed necessary.

System and Information integrity (SI) - Software, Firmware, and Information Integrity (SI-7) - SI-7(1) Integrity Checks1

Perform an integrity check of \[Assignment: organization-defined software, firmware, and information\] \[Selection (one or more): at startup; at \[Assignment: organization-defined transitional states or security-relevant events\]; \[Assignment: organization-defined frequency\]\].

System and Information integrity (SI) - Software, Firmware, and Information Integrity (SI-7) - SI-7(3) Centrally Managed Integrity Tools1

Employ centrally managed integrity verification tools.

System and Information integrity (SI) - Software, Firmware, and Information Integrity (SI-7) - SI-7(7) Integration Of Detection And Response1

Incorporate the detection of the following unauthorized changes into the organizational incident response capability: \[Assignment: organization-defined security-relevant changes to the system\].

System and Information integrity (SI) - Software, Firmware, and Information Integrity (SI-7) - SI-7(8) Auditing Capability For Significant Events13

Upon detection of a potential integrity violation, provide the capability to audit the event and initiate the following actions: \[Selection (one or more): generate an audit record; alert current user; alert \[Assignment: organization-defined personnel or roles\]; \[Assignment: organization-defined other actions\]\].

System and Information integrity (SI) - Software, Firmware, and Information Integrity (SI-7) - SI-7(a)1

Employ integrity verification tools to detect unauthorized changes to the following software, firmware, and information: \[Assignment: organization-defined software, firmware, and information\].

System and Information integrity (SI) - Information Input Validation (SI-10) - SI-10(1) Manual Override Capability9

a. Provide a manual override capability for input validation of the following information inputs: \[Assignment: organization-defined inputs defined in the base control (SI-10)\]; b. Restrict the use of the manual override capability to only \[Assignment: organization-defined authorized individuals\]; and c. Audit the use of the manual override capability.

System and Information integrity (SI) - Information Management and Retention (SI-12)1

Manage and retain information within the system and information output from the system in accordance with applicable laws, executive orders, directives, regulations, policies, standards, guidelines and operational requirements.

System and Information integrity (SI) - Predictable Failure Prevention (SI-13) - SI-13(5) Failover Capability15

Provide \[Selection: real-time; near real-time\] \[Assignment: organization-defined failover capability\] for the system.

System and Information integrity (SI) - De-Identification (SI-19) - SI-19(4) Removal, Masking, Encryption, Hashing, Or Replacement Of Direct Identifiers17

Remove, mask, encrypt, hash, or replace direct identifiers in a dataset.

See where you stand against any framework

Connect an account and get a full compliance breakdown with mapped findings and remediation guidance — free to start.