Annual

Linked Issues

Issuelinks
Linktype Issue
is related to Security, Compliance & Resilience Program (SCRP)
is related to Steering Committee & Program Oversight
is related to Status Reporting To Governing Body
is related to Commitment To Continual Improvements
is related to Publishing Security, Compliance & Resilience Documentation
is related to Exception Management
is related to Periodic Review & Update of Security, Compliance & Resilience Program
is related to Assigned Security, Compliance & Resilience Responsibilities
is related to Stakeholder Accountability Structure
is related to Authoritative Chain of Command
is related to Measures of Performance
is related to Key Performance Indicators (KPIs)
is related to Key Risk Indicators (KRIs)
is related to Contacts With Authorities
is related to Contacts With Groups & Associations
is related to Defining Business Context & Mission
is related to Define Control Objectives
is related to Data Governance
is related to Purpose Validation
is related to Forced Technology Transfer (FTT)
is related to State-Sponsored Espionage
is related to Business As Usual (BAU) Security, Compliance & Resilience Practices
is related to Operationalizing Security, Compliance & Resilience Capabilities
is related to Select Controls
is related to Implement Controls
is related to Assess Controls
is related to Authorize Technology Assets, Applications and/or Services (TAAS)
is related to Monitor Controls
is related to Materiality Determination
is related to Material Risks
is related to Material Threats
is related to Quality Management System (QMS)
is related to Assurance
is related to Assurance Levels (AL)
is related to Assessment Objectives (AO)
is related to Mergers, Acquisitions & Divestitures (MA&D)
is related to Virtual Data Room (VDR)
is related to Artificial Intelligence (AI) & Autonomous Technologies Governance
is related to Trustworthy AI & Autonomous Technologies
is related to AI & Autonomous Technologies Value Sustainment
is related to AI Model & Agent Inventory & Lifecycle Management
is related to Situational Awareness of AI & Autonomous Technologies
is related to AI & Autonomous Technologies Internal Controls
is related to AI & Autonomous Technologies Context Definition
is related to AI & Autonomous Technologies Mission and Goals Definition
is related to AI & Autonomous Technologies Training
is related to AI & Autonomous Technologies Fairness & Bias
is related to AI & Autonomous Technologies Risk Management Decisions
is related to Artificial Intelligence Test, Evaluation, Validation & Verification (AI TEVV)
is related to AI TEVV Trustworthiness Assessment
is related to AI TEVV Tools
is related to AI TEVV Trustworthiness Demonstration
is related to AI TEVV Safety Demonstration
is related to AI TEVV Security & Resiliency Assessment
is related to AI TEVV Transparency & Accountability Assessment
is related to AI TEVV Privacy Assessment
is related to AI TEVV Fairness & Bias Assessment
is related to AI & Autonomous Technologies Model Validation
is related to AI TEVV Results Evaluation
is related to AI TEVV Effectiveness
is related to AI TEVV Comparable Deployment Settings
is related to AI TEVV Reporting
is related to AI TEVV Empirically Validated Methods
is related to AI TEVV Benchmarking Content Provenance
is related to Robust Stakeholder Engagement for AI & Autonomous Technologies
is related to AI & Autonomous Technologies Ongoing Assessments
is related to AI & Autonomous Technologies End User Feedback
is related to AI & Autonomous Technologies Incident & Error Reporting
is related to AI & Autonomous Technologies Intellectual Property Infringement Protections
is related to Data Source Identification
is related to Data Source Lineage & Origin Disclosure
is related to Digital Content Modification Logging
is related to AI & Autonomous Technologies Stakeholder Diversity
is related to AI & Autonomous Technologies Stakeholder Competencies
is related to AI & Autonomous Technologies Requirements Definitions
is related to AI & Autonomous Technologies Implementation Tasks Definition
is related to AI & Autonomous Technologies Knowledge Limits
is related to AI & Autonomous Technologies Viability Decisions
is related to AI & Autonomous Technologies Negative Residual Risks
is related to Responsibility To Supersede, Deactivate and/or Disengage AI & Autonomous Technologies
is related to AI & Autonomous Technologies Measurement Approaches
is related to Unmeasurable AI & Autonomous Technologies Risks
is related to Efficacy of AI & Autonomous Technologies Measurement
is related to AI & Autonomous Technologies Domain Expert Reviews
is related to AI & Autonomous Technologies Performance Changes
is related to Pre-Trained AI & Autonomous Technologies Models
is related to AI & Autonomous Technologies Event Logging
is related to Serious Incident Reporting For AI & Autonomous Technologies
is related to Serious Incident Root Cause Analysis (RCA) For AI & Autonomous Technologies
is related to Anomaly Detection & Human Oversight
is related to Human-in-the-Loop & Escalation
is related to Multi-Agent Trust & Communication Validation
is related to AI & Autonomous Technologies Human Subject Protections
is related to AI & Autonomous Technologies Environmental Impact & Sustainability
is related to Novel Risk Assessment Methods & Technologies
is related to Fine Tuning Risk Mitigation
is related to AI & Autonomous Technologies Risk Tracking Approaches
is related to Manipulative or Deceptive Techniques
is related to Materially Distorting Behaviors
is related to Social Scoring
is related to Detrimental or Unfavorable Treatment
is related to Risk and Criminal Profiling
is related to Populating Facial Recognition Databases
is related to Emotion Inference
is related to Biometric Categorization
is related to AI & Autonomous Technologies Development Practices
is related to AI & Autonomous Technologies Transparency
is related to AI & Autonomous Technologies Implementation Documentation
is related to AI & Autonomous Technologies Human Domain Knowledge Reliance
is related to AI & Autonomous Technologies Deployment
is related to AI & Autonomous Technologies Human Oversight
is related to AI & Autonomous Technologies Oversight Measures
is related to AI & Autonomous Technologies Separate Verification
is related to AI & Autonomous Technologies Oversight Functions Competency
is related to AI & Autonomous Technologies Data Relevance
is related to AI & Autonomous Technologies Irregularity Reporting
is related to AI & Autonomous Technologies Use Notification To Employees
is related to AI & Autonomous Technologies Use Notification To Users
is related to AI & Autonomous Technologies Output Marking
is related to Real World Testing of AI & Autonomous Technologies
is related to AI & Autonomous Technologies System Value Chain
is related to AI & Autonomous Technologies System Value Chain Fallbacks
is related to AI & Autonomous Technologies Testing Techniques
is related to Generative Artificial Intelligence (GAI) Identification
is related to AI & Autonomous Technologies Capabilities Testing
is related to Real-World Testing
is related to Documenting Testing Guidance
is related to AI & Autonomous Technologies Output Filtering
is related to Human Moderation
is related to AI Model Resilience
is related to Cascading Hallucination Defense
is related to Resource Exhaustion & DoS Resilience
is related to AI Agent Governance
is related to Infrastructure Hardening & Isolation
is related to Tool & API Invocation Controls
is related to Orchestration Protocol Safeguards
is related to Data Pipeline & Input Integrity
is related to Privileged Role & Delegation Boundaries
is related to AI Agent Data Access Restrictions
is related to Data Extraction
is related to AI Agent Identity & Impersonation Defense
is related to AI Agent Logic Integrity
is related to Sandboxing AI Agents
is related to Prompt Injection Defense
is related to Agent Kill Switch / User Control
is related to Self-Modification Controls
is related to Purging AI Agent Data
is related to Delegation and Chaining Control
is related to AI Agent Action Authentication & Authorization
is related to Transparency & Audit
is related to Explainability
is related to Ethics, Fairness & Bias Detection
is related to Agent Output Integrity & Verification
is related to Agentic Output Traceability & Repudiation
is related to AI Agent Logging
is related to Session Management
is related to Human-in-the-Loop Workload & Manipulation
is related to Robotic Process Automation (RPA)
is related to Business Process Task Enumeration
is related to Asset Governance
is related to Asset-Service Dependencies
is related to Stakeholder Identification & Involvement
is related to Standardized Naming Convention
is related to Approved Technologies
is related to Asset Inventories
is related to Updates During Installations / Removals
is related to Component Duplication Avoidance
is related to Approved Baseline Deviations
is related to Dynamic Host Configuration Protocol (DHCP) Server Logging
is related to Software Licensing Restrictions
is related to Component Assignment
is related to Asset Ownership Assignment
is related to Accountability Information
is related to Provenance
is related to Network Diagrams & Data Flow Diagrams (DFDs)
is related to Asset Scope Classification
is related to Control Applicability Boundary Graphical Representation
is related to Security of Assets & Media
is related to Management Approval For External Media Transfer
is related to Unattended End-User Equipment
is related to Asset Storage In Automobiles
is related to Kiosks & Point of Interaction (PoI) Devices
is related to Secure Disposal, Destruction or Re-Use of Equipment
is related to Return of Assets
is related to Removal of Assets
is related to Use of Personal Devices
is related to Use of Third-Party Devices
is related to Usage Parameters
is related to Bluetooth & Wireless Devices
is related to Infrared Communications
is related to Logical Tampering Protection
is related to Technology Asset Inspections
is related to Bring Your Own Device (BYOD) Usage
is related to Roots of Trust Protection
is related to Telecommunications Equipment
is related to Video Teleconference (VTC) Security
is related to Voice Over Internet Protocol (VoIP) Security
is related to Microphones & Web Cameras
is related to Multi-Function Devices (MFD)
is related to Travel-Only Devices
is related to Re-Imaging Devices After Travel
is related to System Administrative Processes
is related to Jump Server
is related to Database Administrative Processes
is related to Database Management System (DBMS)
is related to Radio Frequency Identification (RFID) Security
is related to Contactless Access Control Systems
is related to Asset Categorization
is related to Categorize Artificial Intelligence (AI)-Related Technologies
is related to High-Risk Asset Categorization
is related to Asset Attributes
is related to Automated Network Asset Discovery
is related to Business Continuity Management System (BCMS)
is related to Coordinate with Related Plans
is related to Coordinate With External Service Providers
is related to Transfer to Alternate Processing / Storage Site
is related to Recovery Time / Point Objectives (RTO / RPO)
is related to Recovery Operations Criteria
is related to Recovery Operations Communications
is related to Identify Critical Assets
is related to Resume All Missions & Business Functions
is related to Continue Essential Mission & Business Functions
is related to Resume Essential Missions & Business Functions
is related to Data Storage Location Reviews
is related to Contingency Training
is related to Simulated Events
is related to Contingency Plan Testing & Exercises
is related to Coordinated Testing with Related Plans
is related to Alternate Storage & Processing Sites
is related to Contingency Plan Root Cause Analysis (RCA) & Lessons Learned
is related to Ongoing Contingency Planning
is related to Contingency Planning Components
is related to Contingency Plan Update Notifications
is related to Alternative Security Measures
is related to Alternate Storage Site
is related to Separation from Primary Storage Site
is related to Primary Storage Site Accessibility
is related to Alternate Processing Site
is related to Separation from Primary Processing Site
is related to Alternate Processing Site Accessibility
is related to Alternate Site Priority of Service
is related to Preparation for Use
is related to Inability to Return to Primary Site
is related to Telecommunications Services Availability
is related to Telecommunications Priority of Service Provisions
is related to Separation of Primary / Alternate Providers
is related to Provider Contingency Plan
is related to Alternate Communications Channels
is related to Testing for Reliability & Integrity
is related to Separate Storage for Critical Information
is related to Recovery Images
is related to Cryptographic Protection
is related to Test Restoration Using Sampling
is related to Transfer to Alternate Storage Site
is related to Dual Authorization For Backup Media Destruction
is related to Backup Access
is related to Backup Modification and/or Destruction
is related to Technology Assets, Applications and/or Services (TAAS) Recovery & Reconstitution
is related to Failover Capability
is related to Electronic Discovery (eDiscovery)
is related to Restore Within Time Period
is related to Backup & Restoration Hardware Protection
is related to Restoration Integrity Verification
is related to Isolated Recovery Environment
is related to Reserve Hardware
is related to AI & Autonomous Technologies Incidents
is related to Capacity & Performance Management
is related to Resource Priority
is related to Capacity Planning
is related to Elastic Expansion
is related to Regional Delivery
is related to Change Management Program
is related to Configuration Change Control
is related to Prohibition Of Changes
is related to Test, Validate & Document Changes
is related to Security, Compliance & Resilience Representative for Asset Lifecycle Changes
is related to Cryptographic Management
is related to Security Impact Analysis for Changes
is related to Access Restriction For Change
is related to Automated Access Enforcement / Auditing
is related to Signed Components
is related to Dual Authorization for Change
is related to Permissions To Implement Changes
is related to Library Privileges
is related to Stakeholder Notification of Changes
is related to Control Functionality Verification
is related to Report Verification Results
is related to Emergency Changes
is related to Documenting Emergency Changes
is related to Dual Approval For High-Impact Environments
is related to Cloud Services
is related to Cloud Infrastructure Onboarding
is related to Cloud Security Architecture
is related to Cloud Infrastructure Security Subnet
is related to Application Programming Interface (API) Security
is related to API Gateway
is related to Virtual Machine Images
is related to Multi-Tenant Environments
is related to Customer Responsibility Matrix (CRM)
is related to Multi-Tenant Forensics Capabilities
is related to Multi-Tenant Incident Response Capabilities
is related to Data Handling & Portability
is related to Standardized Virtualization Formats
is related to Sensitive Data In Public Cloud Providers
is related to Cloud Access Security Broker (CASB)
is related to Side Channel Attack Prevention
is related to Hosted Assets, Applications & Services
is related to Authorized Individuals For Hosted Assets, Applications & Services
is related to Prohibition On Unverified Hosted Assets, Applications & Services
is related to Ability To Demonstrate Conformity
is related to Conformity Assessment
is related to Declaration of Conformity
is related to Assessment Team Subject Matter Expertise
is related to Designated Certifying Official
is related to Conformity Attestations
is related to Security, Compliance & Resilience Controls Oversight
is related to Internal Audit Function
is related to Periodic Audits
is related to Independent Assessors
is related to Assessor Access
is related to Assessment Methods
is related to Assessment Rigor
is related to Evidence Request List (ERL)
is related to Evidence Sampling
is related to Audit Activities
is related to Legal Assessment of Investigative Inquires
is related to Investigation Request Notifications
is related to Investigation Access Restrictions
is related to Government Surveillance
is related to Grievances
is related to Control Reciprocity
is related to Control Inheritance
is related to Dual Use Technology
is related to USML or CCL Identification
is related to Export Activities Documentation
is related to Statement of Applicability (SOA)
is related to Configuration Management Program
is related to Assignment of Responsibility
is related to Secure Baseline Configurations
is related to Reviews & Updates
is related to Retention Of Previous Configurations
is related to Development & Test Environment Configurations
is related to Configure Technology Assets, Applications and/or Services (TAAS) for High-Risk Areas
is related to Network Device Configuration File Synchronization
is related to Approved Configuration Deviations
is related to Baseline Tailoring
is related to Least Functionality
is related to Periodic Review
is related to Prevent Unauthorized Software Execution
is related to Explicitly Allow / Deny Applications
is related to Split Tunneling
is related to Software Usage Restrictions
is related to Open Source Software
is related to Unsupported Internet Browsers & Email Clients
is related to User-Installed Software
is related to Unauthorized Installation Alerts
is related to Restrict Roles Permitted To Install Software
is related to Zero-Touch Provisioning (ZTP)
is related to Sensitive / Regulated Data Access Enforcement
is related to Continuous Monitoring
is related to Intrusion Detection & Prevention Systems (IDS & IPS)
is related to Automated Tools for Real-Time Analysis
is related to Wireless Network Monitoring
is related to Host-Based Devices
is related to File Integrity Monitoring (FIM)
is related to Security Event Monitoring
is related to Proxy Logging
is related to Deactivated Account Activity
is related to Automated Alerts
is related to Alert Threshold Tuning
is related to Individuals Posing Greater Risk
is related to Privileged User Oversight
is related to Analyze and Prioritize Monitoring Requirements
is related to Real-Time Session Monitoring
is related to Centralized Collection of Security Event Logs
is related to Permitted Actions
is related to Audit Level Adjustments
is related to Changes by Authorized Individuals
is related to Inventory of Technology Asset Event Logging
is related to Content of Event Logs
is related to Sensitive Event Log Information
is related to Audit Trails
is related to Privileged Functions Logging
is related to Verbosity Logging for Boundary Devices
is related to Limit Personal Data (PD) In Audit Records
is related to Centralized Management of Event Log Content
is related to Database Logging
is related to Response To Event Log Processing Failures
is related to Real-Time Alerts of Event Logging Failure
is related to Monitoring Reporting
is related to Query Parameter Audits of Personal Data (PD)
is related to Trend Analysis Reporting
is related to Time Stamps
is related to Synchronization With Authoritative Time Source
is related to Protection of Event Logs
is related to Event Log Backup on Separate Physical Systems / Components
is related to Access by Subset of Privileged Users
is related to Cryptographic Protection of Event Log Information
is related to Non-Repudiation
is related to Identity Binding
is related to Monitoring For Information Disclosure
is related to Session Audit
is related to Alternate Event Logging Capability
is related to Cross-Organizational Monitoring
is related to Sharing of Event Logs
is related to Covert Channel Analysis
is related to Insider Threats
is related to Third-Party Threats
is related to Unauthorized Activities
is related to Event Log Analysis & Triage
is related to Event Log Review Escalation Matrix
is related to Write Once Read Many (WORM) Event Log Generation
is related to Use of Cryptographic Controls
is related to Alternate Physical Protection
is related to Pre/Post Transmission Handling
is related to Conceal / Randomize Communications
is related to Transmission Confidentiality
is related to Transmission Integrity
is related to Encrypting Data At Rest
is related to Storage Media
is related to Offline Storage
is related to Database Encryption
is related to Non-Console Administrative Access
is related to Wireless Access Authentication & Encryption
is related to Public Key Infrastructure (PKI)
is related to Availability
is related to Cryptographic Key Management
is related to Symmetric Keys
is related to Asymmetric Keys
is related to Cryptographic Key Loss or Change
is related to Control & Distribution of Cryptographic Keys
is related to Assigned Owners
is related to Third-Party Cryptographic Keys
is related to External System Cryptographic Key Control
is related to Transmission of Cybersecurity & Data Protection Attributes
is related to Cryptographic Hash
is related to Data Protection
is related to Data Stewardship
is related to Sensitive / Regulated Data Protection
is related to Sensitive / Regulated Media Records
is related to Defining Access Authorizations for Sensitive / Regulated Data
is related to Highest Classification Level
is related to Media Access
is related to Disclosure of Information
is related to Masking Displayed Data
is related to Media Marking
is related to Cybersecurity & Data Protection Attributes
is related to Dynamic Attribute Association
is related to Attribute Value Changes By Authorized Individuals
is related to Maintenance of Attribute Associations By System
is related to Association of Attributes By Authorized Individuals
is related to Attribute Displays for Output Devices
is related to Data Subject Attribute Associations
is related to Consistent Attribute Interpretation
is related to Identity Association Techniques & Technologies
is related to Attribute Reassignment
is related to Attribute Configuration By Authorized Individuals
is related to Media Storage
is related to Physically Secure All Media
is related to Sensitive Data Inventories
is related to Making Sensitive Data Unreadable In Storage
is related to Storing Authentication Data
is related to Media Transportation
is related to Custodians
is related to Encrypting Data In Storage Media
is related to Physical Media Disposal
is related to System Media Sanitization
is related to System Media Sanitization Documentation
is related to Equipment Testing
is related to Sanitization of Personal Data (PD)
is related to First Time Use Sanitization
is related to Dual Authorization for Sensitive Data Destruction
is related to Media Use
is related to Limitations on Use
is related to Prohibit Use Without Owner
is related to Data Reclassification
is related to Removable Media Security
is related to Use of External Technology Assets, Applications and/or Services (TAAS)
is related to Limits of Authorized Use
is related to Portable Storage Devices
is related to Non-Organizationally Owned Technology Assets, Applications and/or Services (TAAS)
is related to Information Sharing
is related to Information Search & Retrieval
is related to Transfer Authorizations
is related to Publicly Accessible Content
is related to Data Mining Protection
is related to Ad-Hoc Transfers
is related to Minimize Sensitive / Regulated Data
is related to Limit Sensitive / Regulated Data In Testing, Training & Research
is related to Temporary Files Containing Personal Data (PD)
is related to Geographic Location of Data
is related to Information Disposal
is related to Data Quality Operations
is related to Updating & Correcting Personal Data (PD)
is related to Data Tags
is related to Primary Source Personal Data (PD) Collection
is related to De-Identification (Anonymization)
is related to De-Identify Dataset Upon Collection
is related to Archiving
is related to Release
is related to Removal, Masking, Encryption, Hashing or Replacement of Direct Identifiers
is related to Statistical Disclosure Control
is related to Differential Data Privacy
is related to Automated De-Identification of Sensitive Data
is related to Motivated Intruder
is related to Code Names
is related to Information Location
is related to Transfer of Sensitive and/or Regulated Data
is related to Data Rights Management (DRM)
is related to Embedded Technology Security Program
is related to Interface Security
is related to Embedded Technology Configuration Monitoring
is related to Prevent Alterations
is related to Embedded Technology Maintenance
is related to Resilience To Outages
is related to Embedded Technology Reviews
is related to Message Queuing Telemetry Transport (MQTT) Security
is related to Restrict Communications
is related to Authorized Communications
is related to Operating Environment Certification
is related to Safety Assessment
is related to Certificate-Based Authentication
is related to Chip-To-Cloud Security
is related to Real-Time Operating System (RTOS) Security
is related to Endpoint Device Management (EDM)
is related to Unified Endpoint Device Management (UEDM)
is related to Endpoint Protection Measures
is related to Software Installation Alerts
is related to Governing Access Restriction for Change
is related to Malicious Code Protection (Anti-Malware)
is related to Documented Protection Measures
is related to Heuristic / Nonsignature-Based Detection
is related to Malware Protection Mechanism Testing
is related to Evolving Malware Threats
is related to Software Firewall
is related to Endpoint File Integrity Monitoring (FIM)
is related to Integrity Checks
is related to Binary or Machine-Executable Code
is related to Host Intrusion Detection and Prevention Systems (HIDS / HIPS)
is related to Phishing & Spam Protection
is related to Central Management
is related to Automatic Spam and Phishing Protection Updates
is related to Trusted Path
is related to Mobile Code
is related to Thin Nodes
is related to Port & Input / Output (I/O) Device Access
is related to Sensor Capability
is related to Authorized Use
is related to Notice of Collection
is related to Collection Minimization
is related to Sensor Delivery Verification
is related to Collaborative Computing Devices
is related to Disabling / Removal In Secure Work Areas
is related to Participant Identity Verification
is related to Participant Connection Management
is related to Explicit Indication Of Use
is related to Hypervisor Access
is related to Restrict Access To Security Functions
is related to Host-Based Security Function Isolation
is related to Human Resources Security Management
is related to Position Categorization
is related to Probationary Periods
is related to Defined Roles & Responsibilities
is related to User Awareness
is related to Competency Requirements for Security-Related Positions
is related to Personnel Screening
is related to Roles With Special Protection Measures
is related to Formal Indoctrination
is related to Citizenship Identification
is related to Terms of Employment
is related to Rules of Behavior
is related to Social Media & Social Networking Restrictions
is related to Technology Use Restrictions
is related to Use of Critical Technologies
is related to Use of Mobile Devices
is related to Security-Minded Dress Code
is related to Policy Familiarization & Acknowledgement
is related to Access Agreements
is related to Confidentiality Agreements
is related to Post-Employment Requirements Awareness
is related to Personnel Sanctions
is related to Workplace Investigations
is related to Updating Disciplinary Processes
is related to Personnel Transfer
is related to Personnel Termination
is related to Asset Collection
is related to High-Risk Terminations
is related to Post-Employment Requirements Notification
is related to Third-Party Personnel
is related to Separation of Duties (SoD)
is related to Incompatible Roles
is related to Two-Person Rule
is related to Identify Critical Skills & Gaps
is related to Remediate Identified Skills Deficiencies
is related to Identify Vital Security, Compliance & Resilience Staff
is related to Establish Redundancy for Vital Security, Compliance & Resilience Staff
is related to Perform Succession Planning
is related to Identifying Authorized Work Locations
is related to Communicating Authorized Work Locations
is related to Reporting Suspicious Activities
is related to Identity & Access Management (IAM)
is related to Retain Access Records
is related to Authenticate, Authorize and Audit (AAA)
is related to User & Service Account Inventories
is related to Identification & Authentication for Organizational Users
is related to Group Authentication
is related to Acceptance of PIV Credentials
is related to Out-of-Band Authentication (OOBA)
is related to Identification & Authentication for Non-Organizational Users
is related to Acceptance of PIV Credentials from Other Organizations
is related to Use of FICAM-Issued Profiles
is related to Disassociability
is related to Acceptance of External Authenticators
is related to Identification & Authentication for Devices
is related to Device Attestation
is related to Device Authorization Enforcement
is related to Identification & Authentication for Third-Party Technology Assets, Applications and/or Services (TAAS)
is related to Sharing Identification & Authentication Information
is related to Privileged Access by Non-Organizational Users
is related to Network Access to Privileged Accounts
is related to Network Access to Non-Privileged Accounts
is related to Local Access to Privileged Accounts
is related to Out-of-Band Multi-Factor Authentication
is related to Alternative Multi-Factor Authentication
is related to User Provisioning & De-Provisioning
is related to Change of Roles & Duties
is related to Termination of Employment
is related to Role-Based Access Control (RBAC)
is related to Identifier Management (User Names)
is related to User Identity (ID) Management
is related to Identity User Status
is related to Dynamic Management
is related to Cross-Organization Management
is related to Privileged Account Identifiers
is related to Pairwise Pseudonymous Identifiers (PPID)
is related to Authenticator Management
is related to Password-Based Authentication
is related to In-Person or Trusted Third-Party Registration
is related to Protection of Authenticators
is related to No Embedded Unencrypted Static Authenticators
is related to Default Authenticators
is related to Multiple System Accounts
is related to Biometric Authentication
is related to Events Requiring Authenticator Change
is related to Passkeys
is related to Authenticator Feedback
is related to Adaptive Identification & Authentication
is related to Single Sign-On (SSO) Transparent Authentication
is related to Federated Credential Management
is related to Re-Authentication
is related to Restrictions on Shared Groups / Accounts
is related to Account Disabling for High Risk Individuals
is related to System Account Reviews
is related to Emergency Accounts
is related to Privileged Account Inventories
is related to Privileged Account Separation
is related to Privileged Command Execution
is related to Dedicated Privileged Account
is related to Manual Override
is related to Periodic Review of Account Privileges
is related to User Responsibilities for Account Management
is related to Credential Sharing
is related to Access Enforcement
is related to Access To Sensitive / Regulated Data
is related to Database Access
is related to Use of Privileged Utility Programs
is related to Dedicated Administrative Machines
is related to Revocation of Access Authorizations
is related to Authorized System Accounts
is related to Least Privilege
is related to Authorize Access to Security Functions
is related to Non-Privileged Access for Non-Security Functions
is related to Management Approval For Privileged Accounts
is related to Auditing Use of Privileged Functions
is related to Prohibit Non-Privileged Users from Executing Privileged Functions
is related to Network Access to Privileged Commands
is related to Account Lockout
is related to Concurrent Session Control
is related to Session Lock
is related to Pattern-Hiding Displays
is related to User-Initiated Logouts / Message Displays
is related to Permitted Actions Without Identification or Authorization
is related to Reference Monitor
is related to Identity Proofing (Identity Verification)
is related to Management Approval For New or Changed Accounts
is related to Identity Evidence
is related to Identity Evidence Validation & Verification
is related to In-Person Validation & Verification
is related to Address Confirmation
is related to Attribute-Based Access Control (ABAC)
is related to Access Profile Rules
is related to Mutual Authentication (MA)
is related to Incident Response Operations
is related to Incident Handling
is related to Insider Threat Response Capability
is related to Incident Classification & Prioritization
is related to Correlation with External Organizations
is related to Automatic Disabling of Technology Assets, Applications and/or Services (TAAS)
is related to Incident Response Plan (IRP)
is related to Data Breach
is related to Continuous Incident Response Improvements
is related to Incident Response Training
is related to Simulated Incidents
is related to Incident Response Testing
is related to Coordination with Related Plans
is related to Integrated Security Incident Response Team (ISIRT)
is related to Chain of Custody & Forensics
is related to Licensed Forensic Investigators
is related to Situational Awareness For Incidents
is related to Recurring Incident Analysis
is related to Incident Pattern Analysis
is related to Incident Stakeholder Reporting
is related to Cyber Incident Reporting for Sensitive / Regulated Data
is related to Vulnerabilities Related To Incidents
is related to Supply Chain Coordination
is related to Serious Incident Reporting
is related to Incident Reporting Assistance
is related to Coordination With External Providers
is related to Sensitive / Regulated Data Spill Training
is related to Post-Sensitive / Regulated Data Spill Operations
is related to Sensitive / Regulated Data Exposure to Unauthorized Personnel
is related to Root Cause Analysis (RCA) & Lessons Learned
is related to Regulatory & Law Enforcement Contacts
is related to Detonation Chambers (Sandboxes)
is related to Information Assurance (IA) Operations
is related to Assessment Boundaries
is related to Assessor Independence
is related to Security Assessment Report (SAR)
is related to Applied Security, Compliance and Resilience Controls Documentation
is related to Plan / Coordinate with Other Organizational Entities
is related to Adequate Security for Sensitive / Regulated Data In Support of Contracts
is related to Threat Analysis & Flaw Remediation During Development
is related to Capabilities Deficiency Tracking
is related to Technical Verification
is related to Security Authorization
is related to Maintenance Operations
is related to Controlled Maintenance
is related to Timely Maintenance
is related to Preventative Maintenance
is related to Predictive Maintenance
is related to Maintenance Tools
is related to Inspect Tools
is related to Inspect Media
is related to Prevent Unauthorized Removal
is related to Remote Maintenance
is related to Auditing Remote Maintenance
is related to Remote Maintenance Notifications
is related to Remote Maintenance Cryptographic Protection
is related to Remote Maintenance Disconnect Verification
is related to Remote Maintenance Pre-Approval
is related to Remote Maintenance Comparable Security & Sanitization
is related to Separation of Maintenance Sessions
is related to Authorized Maintenance Personnel
is related to Maintenance Personnel Without Appropriate Access
is related to Non-System Related Maintenance
is related to Maintain Configuration Control During Maintenance
is related to Field Maintenance
is related to Off-Site Maintenance
is related to Maintenance Validation
is related to Maintenance Monitoring
is related to Centralized Management Of Mobile Devices
is related to Access Control For Mobile Devices
is related to Full Device & Container-Based Encryption
is related to Mobile Device Tampering
is related to Remote Purging
is related to Personally-Owned Mobile Devices
is related to Organization-Owned Mobile Devices
is related to Mobile Device Data Retention Limitations
is related to Mobile Device Geofencing
is related to Separate Mobile Device Profiles
is related to Restricting Access To Authorized Technology Assets, Applications and/or Services (TAAS)
is related to Network Security Controls (NSC)
is related to Zero Trust Architecture (ZTA)
is related to Layered Network Defenses
is related to Guest Networks
is related to Cross Domain Solution (CDS)
is related to Boundary Protection
is related to Limit Network Connections
is related to External Telecommunications Services
is related to Prevent Discovery of Internal Information
is related to Personal Data (PD)
is related to Isolation of System Components
is related to Separate Subnet for Connecting to Different Security Domains
is related to Data Flow Enforcement – Access Control Lists (ACLs)
is related to Deny Traffic by Default & Allow Traffic by Exception
is related to Object Security Attributes
is related to Content Check for Encrypted Data
is related to Embedded Data Types
is related to Metadata
is related to Human Reviews
is related to Application Proxy
is related to Interconnection Security Agreements (ISAs)
is related to External System Connections
is related to Internal System Connections
is related to Network Segmentation (macrosegementation)
is related to Security Management Subnets
is related to Virtual Local Area Network (VLAN) Separation
is related to Sensitive / Regulated Data Enclave (Secure Zone)
is related to Segregation From Enterprise Services
is related to Direct Internet Access Restrictions
is related to Network Connection Termination
is related to Network Intrusion Detection / Prevention Systems (NIDS / NIPS)
is related to DMZ Networks
is related to Wireless Intrusion Detection / Prevention Systems (WIDS / WIPS) Deployment
is related to Session Integrity
is related to Domain Name Service (DNS) Resolution
is related to Architecture & Provisioning for Name / Address Resolution Service
is related to Secure Name / Address Resolution Service (Recursive or Caching Resolver)
is related to Sender Policy Framework (SPF)
is related to Domain Registrar Security
is related to Out-of-Band Channels
is related to Safeguarding Data Over Open Networks
is related to Wireless Link Protection
is related to End-User Messaging Technologies
is related to Electronic Messaging
is related to Remote Access
is related to Protection of Confidentiality / Integrity Using Encryption
is related to Managed Access Control Points
is related to Remote Privileged Commands & Sensitive Data Access
is related to Work From Anywhere (WFA) - Telecommuting Security
is related to Expeditious Disconnect / Disable Capability
is related to Wireless Networking
is related to Authentication & Encryption
is related to Disable Wireless Networking
is related to Restrict Configuration By Users
is related to Wireless Boundaries
is related to Rogue Wireless Detection
is related to Intranets
is related to DNS & Content Filtering
is related to Route Internal Traffic to Proxy Servers
is related to Visibility of Encrypted Communications
is related to Domain Name Verification
is related to Internet Address Denylisting
is related to Bandwidth Control
is related to Authenticated Proxy
is related to Certificate Denylisting
is related to Content Disarm and Reconstruction (CDR)
is related to Email Content Protections
is related to Email Domain Reputation Protections
is related to Sender Denylisting
is related to Authenticated Received Chain (ARC)
is related to Domain-Based Message Authentication Reporting and Conformance (DMARC)
is related to User Digital Signatures for Outgoing Email
is related to Encryption for Outgoing Email
is related to Adaptive Email Protections
is related to User Threat Reporting
is related to Physical & Environmental Protections
is related to Physical Security Plan (PSP)
is related to Zone-Based Physical Security
is related to Physical Access Authorizations
is related to Role-Based Physical Access
is related to Dual Authorization for Physical Access
is related to Physical Access Control
is related to Controlled Ingress & Egress Points
is related to Lockable Physical Casings
is related to Physical Access Logs
is related to Access To Critical Systems
is related to Physical Security of Offices, Rooms & Facilities
is related to Working in Secure Areas
is related to Searches
is related to Temporary Storage
is related to Intrusion Alarms / Surveillance Equipment
is related to Monitoring Physical Access To Critical Systems
is related to Visitor Control
is related to Distinguish Visitors from On-Site Personnel
is related to Identification Requirement
is related to Restrict Unescorted Access
is related to Minimize Visitor Personal Data (PD)
is related to Visitor Access Revocation
is related to Supporting Utilities
is related to Automatic Voltage Controls
is related to Emergency Shutoff
is related to Emergency Power
is related to Emergency Lighting
is related to Water Damage Protection
is related to Automation Support for Water Damage Protection
is related to Redundant Cabling
is related to Fire Protection
is related to Automatic Fire Suppression
is related to Temperature & Humidity Controls
is related to Delivery & Removal
is related to Alternate Work Site
is related to Equipment Siting & Protection
is related to Transmission Medium Security
is related to Access Control for Output Devices
is related to Information Leakage Due To Electromagnetic Signals Emanations
is related to Asset Monitoring and Tracking
is related to Electromagnetic Pulse (EMP) Protection
is related to Component Marking
is related to On-Site Client Segregation
is related to Physical Access Device Inventories
is related to Data Privacy Program
is related to Chief Privacy Officer (CPO)
is related to Privacy Act Statements
is related to Dissemination of Data Privacy Program Information
is related to Data Protection Officer (DPO)
is related to Binding Corporate Rules (BCR)
is related to Security of Personal Data (PD)
is related to Limiting Personal Data (PD) Disclosures
is related to Data Fiduciary
is related to Personal Data (PD) Process Manager
is related to Financial Incentives For Personal Data (PD)
is related to Reasonable Data Privacy Practices
is related to Data Privacy Notice
is related to Purpose Specification
is related to Computer Matching Agreements (CMA)
is related to System of Records Notice (SORN)
is related to System of Records Notice (SORN) Review Process
is related to Privacy Act Exemptions
is related to Real-Time or Layered Notice
is related to Purpose Compatibility
is related to Privacy Notice Formatting
is related to Symmetry In Choice
is related to Choice Architecture
is related to Choice Architecture Testing
is related to Notice of Right To Limit
is related to Alternative Means To Deliver Privacy Notice
is related to Tailored Consent
is related to Just-In-Time Notice & Updated Consent
is related to Prohibition of Selling, Processing and/or Sharing Personal Data (PD)
is related to Revoke Consent
is related to Product or Service Delivery Restrictions
is related to Authorized Agent
is related to Active Participation By Data Subjects
is related to Continued Use of Personal Data (PD)
is related to Cease Processing, Storing and/or Sharing Personal Data (PD)
is related to Communicating Processing Changes
is related to Data Subject Opt-In Consent
is related to Parent or Guardian Opt-In Consent For Minors
is related to Restrict Collection To Identified Purpose
is related to Authority To Collect, Process, Store & Share Personal Data (PD)
is related to Primary Sources
is related to Identifiable Image Collection
is related to Acquired Personal Data (PD)
is related to Validate Collected Personal Data (PD)
is related to Re-Validate Collected Personal Data (PD)
is related to Personal Data (PD) Retention & Disposal
is related to Internal Use of Personal Data (PD) For Testing, Training and Research
is related to Personal Data (PD) Accuracy & Integrity
is related to Data Masking
is related to Usage Restrictions of Personal Data (PD)
is related to Inventory of Personal Data (PD)
is related to Personal Data (PD) Categories
is related to Personal Data (PD) Formats
is related to Data Subject Empowerment
is related to Correcting Inaccurate Personal Data (PD)
is related to Notice of Correction or Processing Change
is related to Appeal Adverse Decision
is related to Right to Erasure
is related to Data Portability
is related to Personal Data (PD) Exports
is related to Data Subject Authentication
is related to Information Sharing With Third Parties
is related to Data Privacy Requirements for Contractors & Service Providers
is related to Joint Processing of Personal Data (PD)
is related to Obligation To Inform Third-Parties
is related to Reject Unauthenticated or Untrustworthy Disclosure Requests
is related to Justification To Reject Disclosure Requests
is related to Personal Data (PD) Control Testing, Training & Monitoring
is related to Personal Data (PD) Lineage
is related to Data Quality Management
is related to Data Analytics Bias
is related to Data Tagging
is related to Updating Personal Data (PD) Process
is related to Enabling Data Subjects To Update Personal Data (PD)
is related to Data Management Board
is related to Accounting of Disclosures
is related to Notification of Disclosure Request To Data Subject
is related to Register As A Data Controller and/or Data Processor
is related to Potential Human Rights Abuses
is related to Data Subject Communications
is related to Conspicuous Link To Data Privacy Notice
is related to Notice of Financial Incentive
is related to Data Subject Communications Documentation
is related to Data Subject Communications Metrics
is related to Data Subject Communications Disclosure
is related to Automated Decision-Making Technology (ADMT) For Data Subject Actions
is related to Automated Decision-Making Technology (ADMT) Use Notification
is related to Automated Decision-Making Technology (ADMT) Opt-Out Consent
is related to Automated Decision-Making Technology (ADMT) Transparency
is related to Data Brokers
is related to Notice of Right To Opt-Out
is related to Opt-Out Links
is related to Alternative Out-Out Link
is related to Security, Compliance & Resilience Protection Portfolio Management
is related to Strategic Plan & Objectives
is related to Targeted Capability Maturity Levels
is related to Security, Compliance & Resilience Resource Management
is related to Prioritization To Address Evolving Risks & Threats
is related to Allocation of Resources
is related to Security, Compliance & Resilience In Project Management
is related to Security, Compliance & Resilience Requirements Definition
is related to Business Process Definition
is related to Secure Development Life Cycle (SDLC) Management
is related to Manage Organizational Knowledge
is related to Risk Management Program
is related to Risk Framing
is related to Risk Management Resourcing
is related to Risk Tolerance
is related to Risk Threshold
is related to Risk Appetite
is related to Risk-Based Security Categorization
is related to Impact-Level Prioritization
is related to Risk Identification
is related to Risk Catalog
is related to Risk Assessment
is related to Risk Assessment Methodology
is related to Instances Requiring A Risk Assessment
is related to Risk Assessment Stakeholder Involvement
is related to Risk Ranking
is related to Compensating Countermeasures
is related to Risk Treatment Options
is related to Risk Assessment Update
is related to Business Impact Analysis (BIA)
is related to Supply Chain Risk Management (SCRM) Plan
is related to Supply Chain Risk Assessment
is related to AI & Autonomous Technologies Supply Chain Impacts
is related to Data Protection Impact Assessment (DPIA)
is related to Risk Monitoring
is related to Risk Culture
is related to Executive Leadership Approval For Managing Material Risk
is related to Documented Alternatives
is related to Documented Justification For Material Risk Management Decisions
is related to Secure Engineering Principles
is related to Centralized Management of Security, Compliance & Resilience Controls
is related to Achieving Resilience Requirements
is related to Resilience Capabilities
is related to Alignment With Enterprise Architecture
is related to Standardized Terminology
is related to Outsourcing Non-Essential Functions or Services
is related to Technical Debt Reviews
is related to Defense-In-Depth (DiD) Architecture
is related to System Partitioning
is related to Application Partitioning
is related to Process Isolation
is related to Security Function Isolation
is related to Hardware Separation
is related to Thread Separation
is related to System Privileges Isolation
is related to Information In Shared Resources
is related to Predictable Failure Analysis
is related to Technology Lifecycle Management
is related to Fail Secure
is related to Fail Safe
is related to Non-Persistence
is related to Refresh from Trusted Sources
is related to Information Output Filtering
is related to Limit Personal Data (PD) Dissemination
is related to Memory Protection
is related to Honeypots
is related to Heterogeneity
is related to Virtualization Techniques
is related to Concealment & Misdirection
is related to Distributed Processing & Storage
is related to Non-Modifiable Executable Programs
is related to Secure Log-On Procedures
is related to System Use Notification (Logon Banner)
is related to Standardized Microsoft Windows Banner
is related to Truncated Banner
is related to Previous Logon Notification
is related to Clock Synchronization
is related to Application Container
is related to Privileged Environments
is related to Operations Security
is related to Standardized Operating Procedures (SOP)
is related to Security Concept Of Operations (CONOPS)
is related to Service Delivery (Business Process Support)
is related to Security Operations Center (SOC)
is related to Secure Practices Guidelines
is related to Security Orchestration, Automation, and Response (SOAR)
is related to Shadow Information Technology Detection
is related to Security, Compliance & Resilience-Minded Workforce
is related to Maintaining Workforce Development Relevancy
is related to Security, Compliance & Resilience Awareness Training
is related to Simulated Cyber Attack Scenario Training
is related to Social Engineering & Mining
is related to Role-Based Security, Compliance & Resilience Training
is related to Practical Exercises
is related to Suspicious Communications & Anomalous System Behavior
is related to Sensitive / Regulated Data Storage, Handling & Processing
is related to Vendor Security, Compliance & Resilience Training
is related to Privileged Users
is related to Cyber Threat Environment
is related to Continuing Professional Education (CPE) - Security, Compliance & Resilience Personnel
is related to Continuing Professional Education (CPE) - DevOps Personnel
is related to Counterintelligence Training
is related to Security, Compliance & Resilience Training Records
is related to Security, Compliance & Resilience Knowledge Sharing
is related to Technology Development & Acquisition
is related to Product Management
is related to Malware Testing Prior to Release
is related to DevSecOps
is related to Minimum Viable Product (MVP) Security Requirements
is related to Ports, Protocols & Services In Use
is related to Information Assurance Enabled Products
is related to Development Methods, Techniques & Processes
is related to Pre-Established Secure Configurations
is related to Identification & Justification of Ports, Protocols & Services
is related to Insecure Ports, Protocols & Services
is related to Security, Compliance & Resilience Representatives For Product Changes
is related to Minimizing Attack Surfaces
is related to Ongoing Product Security Support
is related to Disclosure of Vulnerabilities
is related to Products With Digital Elements
is related to Logging Syntax
is related to Commercial Off-The-Shelf (COTS) Security Solutions
is related to Supplier Diversity
is related to Documentation Requirements
is related to Functional Properties
is related to Software Bill of Materials (SBOM)
is related to Developer Architecture & Design
is related to Physical Diagnostic & Test Interfaces
is related to Diagnostic & Test Interface Monitoring
is related to Secure Software Development Practices (SSDP)
is related to Criticality Analysis During Development
is related to Threat Modeling
is related to Software Assurance Maturity Model (SAMM)
is related to Software Design Review
is related to Software Design Root Cause Analysis
is related to Secure Development Environments
is related to Separation of Development, Testing and Operational Environments
is related to Secure Migration Practices
is related to Security, Compliance & Resilience Testing Throughout Development
is related to Continuous Monitoring Plan
is related to Static Code Analysis
is related to Dynamic Code Analysis
is related to Malformed Input Testing
is related to Application Penetration Testing
is related to Secure Settings By Default
is related to Manual Code Review
is related to Use of Live Data
is related to Test Data Integrity
is related to Product Tampering and Counterfeiting (PTC)
is related to Anti-Counterfeit Training
is related to Component Disposal
is related to Customized Development of Critical Components
is related to Developer Screening
is related to Developer Configuration Management
is related to Software / Firmware Integrity Verification
is related to Hardware Integrity Verification
is related to Developer Threat Analysis & Flaw Remediation
is related to Developer-Provided Training
is related to Unsupported Technology Assets, Applications and/or Services (TAAS)
is related to Alternate Sources for Continued Support
is related to Input Data Validation
is related to Error Handling
is related to Access to Program Source Code
is related to Software Release Integrity Verification
is related to Archiving Software Releases
is related to Software Escrow
is related to Approved Code
is related to Product-Specific Risk Assessment Artifacts
is related to Third-Party Management
is related to Third-Party Inventories
is related to Third-Party Criticality Assessments
is related to Supply Chain Risk Management (SCRM)
is related to Acquisition Strategies, Tools & Methods
is related to Limit Potential Harm
is related to Processes To Address Weaknesses or Deficiencies
is related to Adequate Supply
is related to Third-Party Services
is related to Third-Party Risk Assessments & Approvals
is related to External Connectivity Requirements - Identification of Ports, Protocols & Services
is related to Conflict of Interests
is related to Third-Party Processing, Storage and Service Locations
is related to Third-Party Contract Requirements
is related to Security Compromise Notification Agreements
is related to Contract Flow-Down Requirements
is related to Third-Party Authentication Practices
is related to Responsible, Accountable, Supportive, Consulted & Informed (RASCI) Matrix
is related to Third-Party Scope Review
is related to Break Clauses
is related to Third-Party Personnel Security
is related to Monitoring for Third-Party Information Disclosure
is related to Third-Party Deficiency Remediation
is related to Managing Changes To Third-Party Services
is related to Third-Party Incident Response & Recovery Capabilities
is related to Foreign Ownership, Control or Influence (FOCI)
is related to Ownership Change Monitoring
is related to Ownership Change Provisions
is related to Threat Intelligence Program
is related to Indicators of Exposure (IOE)
is related to Threat Intelligence Feeds
is related to Threat Intelligence Reporting
is related to Insider Threat Program
is related to Insider Threat Awareness
is related to Vulnerability Disclosure Program (VDP)
is related to Security Disclosure Contact Information
is related to Threat Hunting
is related to Tainting
is related to Threat Catalog
is related to Threat Analysis
is related to Vulnerability & Patch Management Program (VPMP)
is related to Attack Surface Scope
is related to Vulnerability Remediation Process
is related to Vulnerability Ranking
is related to Vulnerability Exploitation Analysis
is related to Continuous Vulnerability Remediation Activities
is related to Stable Versions
is related to Flaw Remediation with Personal Data (PD)
is related to Deferred Patching Decisions
is related to Centralized Management of Flaw Remediation Processes
is related to Removal of Previous Versions
is related to Pre-Deployment Patch Testing
is related to Out-of-Cycle Patching
is related to Software Patch Integrity
is related to Update Tool Capability
is related to Breadth / Depth of Coverage
is related to Review Historical Event logs
is related to Acceptable Discoverable Information
is related to Penetration Testing
is related to Independent Penetration Agent or Team
is related to Technical Surveillance Countermeasures Security
is related to Reviewing Vulnerability Scanner Usage
is related to Red Team Exercises
is related to Web Security
is related to Unauthorized Code
is related to Use of Demilitarized Zones (DMZ)
is related to Web Application Firewall (WAF)
is related to Client-Facing Web Services
is related to Cookie Management
is related to Strong Customer Authentication (SCA)
is related to Web Security Standard
is related to Web Application Framework
is related to Validation & Sanitization
is related to Secure Web Traffic
is related to Output Encoding
is related to Web Browser Security
is related to Publicly Accessible Content Reviews
Impressum German English