Process

Linked Issues

Issuelinks
Linktype Issue
is related to Security, Compliance & Resilience Program (SCRP)
is related to Steering Committee & Program Oversight
is related to Status Reporting To Governing Body
is related to Commitment To Continual Improvements
is related to Publishing Security, Compliance & Resilience Documentation
is related to Exception Management
is related to Periodic Review & Update of Security, Compliance & Resilience Program
is related to Stakeholder Accountability Structure
is related to Authoritative Chain of Command
is related to Measures of Performance
is related to Key Performance Indicators (KPIs)
is related to Key Risk Indicators (KRIs)
is related to Contacts With Authorities
is related to Contacts With Groups & Associations
is related to Defining Business Context & Mission
is related to Define Control Objectives
is related to Data Governance
is related to Purpose Validation
is related to Forced Technology Transfer (FTT)
is related to State-Sponsored Espionage
is related to Business As Usual (BAU) Security, Compliance & Resilience Practices
is related to Operationalizing Security, Compliance & Resilience Capabilities
is related to Select Controls
is related to Implement Controls
is related to Assess Controls
is related to Authorize Technology Assets, Applications and/or Services (TAAS)
is related to Monitor Controls
is related to Materiality Determination
is related to Material Risks
is related to Material Threats
is related to Security, Compliance & Resilience Status Reporting
is related to Quality Management System (QMS)
is related to Assurance
is related to Assurance Levels (AL)
is related to Assessment Objectives (AO)
is related to Mergers, Acquisitions & Divestitures (MA&D)
is related to Virtual Data Room (VDR)
is related to Artificial Intelligence (AI) & Autonomous Technologies Governance
is related to AI & Autonomous Technologies-Related Legal Requirements Definition
is related to Trustworthy AI & Autonomous Technologies
is related to AI & Autonomous Technologies Value Sustainment
is related to AI Model & Agent Inventory & Lifecycle Management
is related to Situational Awareness of AI & Autonomous Technologies
is related to AI & Autonomous Technologies Risk Mapping
is related to AI & Autonomous Technologies Internal Controls
is related to Adequate Protections For AI & Autonomous Technologies
is related to AI Threat Modeling & Risk Assessment
is related to AI & Autonomous Technologies Context Definition
is related to AI & Autonomous Technologies Mission and Goals Definition
is related to Model & AI Agent Documentation
is related to AI & Autonomous Technologies Business Case
is related to AI & Autonomous Technologies Potential Benefits Analysis
is related to AI & Autonomous Technologies Potential Costs Analysis
is related to AI & Autonomous Technologies Targeted Application Scope
is related to AI & Autonomous Technologies Cost / Benefit Mapping
is related to AI & Autonomous Technologies Fairness & Bias
is related to AI & Autonomous Technologies Risk Management Decisions
is related to AI & Autonomous Technologies Impact Assessment
is related to AI & Autonomous Technologies Likelihood & Impact Risk Analysis
is related to AI & Autonomous Technologies Continuous Improvements
is related to Assigned Responsibilities for AI & Autonomous Technologies
is related to AI & Autonomous Technologies Risk Profiling
is related to AI & Autonomous Technologies High Risk Designations
is related to Artificial Intelligence Test, Evaluation, Validation & Verification (AI TEVV)
is related to AI TEVV Trustworthiness Assessment
is related to AI TEVV Tools
is related to AI TEVV Trustworthiness Demonstration
is related to AI TEVV Safety Demonstration
is related to AI TEVV Security & Resiliency Assessment
is related to AI TEVV Transparency & Accountability Assessment
is related to AI TEVV Privacy Assessment
is related to AI TEVV Fairness & Bias Assessment
is related to AI & Autonomous Technologies Model Validation
is related to AI TEVV Results Evaluation
is related to AI TEVV Effectiveness
is related to AI TEVV Comparable Deployment Settings
is related to AI TEVV Post-Deployment Monitoring
is related to Updating AI & Autonomous Technologies
is related to AI TEVV Reporting
is related to AI TEVV Empirically Validated Methods
is related to AI TEVV Benchmarking Content Provenance
is related to AI TEVV Model Collapse Mitigations
is related to AI TEVV Third-Party Risk Management
is related to Robust Stakeholder Engagement for AI & Autonomous Technologies
is related to AI & Autonomous Technologies Stakeholder Feedback Integration
is related to AI & Autonomous Technologies Ongoing Assessments
is related to AI & Autonomous Technologies End User Feedback
is related to AI & Autonomous Technologies Incident & Error Reporting
is related to AI & Autonomous Technologies Intellectual Property Infringement Protections
is related to Data Source Identification
is related to Data Source Lineage & Origin Disclosure
is related to Digital Content Modification Logging
is related to AI & Autonomous Technologies Requirements Definitions
is related to AI & Autonomous Technologies Implementation Tasks Definition
is related to AI & Autonomous Technologies Knowledge Limits
is related to AI & Autonomous Technologies Viability Decisions
is related to AI & Autonomous Technologies Negative Residual Risks
is related to Responsibility To Supersede, Deactivate and/or Disengage AI & Autonomous Technologies
is related to AI & Autonomous Technologies Measurement Approaches
is related to Measuring AI & Autonomous Technologies Effectiveness
is related to Unmeasurable AI & Autonomous Technologies Risks
is related to Efficacy of AI & Autonomous Technologies Measurement
is related to AI & Autonomous Technologies Performance Changes
is related to Pre-Trained AI & Autonomous Technologies Models
is related to AI & Autonomous Technologies Event Logging
is related to Serious Incident Reporting For AI & Autonomous Technologies
is related to Serious Incident Root Cause Analysis (RCA) For AI & Autonomous Technologies
is related to Anomaly Detection & Human Oversight
is related to Human-in-the-Loop & Escalation
is related to Emergent Behavior & Collusion Protections
is related to Multi-Agent Trust & Communication Validation
is related to AI & Autonomous Technologies Harm Prevention
is related to AI & Autonomous Technologies Human Subject Protections
is related to AI & Autonomous Technologies Environmental Impact & Sustainability
is related to Novel Risk Assessment Methods & Technologies
is related to Fine Tuning Risk Mitigation
is related to AI & Autonomous Technologies Risk Tracking Approaches
is related to AI & Autonomous Technologies Risk Response
is related to AI & Autonomous Technologies Conformity
is related to Manipulative or Deceptive Techniques
is related to Materially Distorting Behaviors
is related to Social Scoring
is related to Detrimental or Unfavorable Treatment
is related to Risk and Criminal Profiling
is related to Populating Facial Recognition Databases
is related to Emotion Inference
is related to Biometric Categorization
is related to AI & Autonomous Technologies Development Practices
is related to AI & Autonomous Technologies Transparency
is related to AI & Autonomous Technologies Implementation Documentation
is related to AI & Autonomous Technologies Human Domain Knowledge Reliance
is related to AI & Autonomous Technologies Registration
is related to AI & Autonomous Technologies Deployment
is related to AI & Autonomous Technologies Human Oversight
is related to AI & Autonomous Technologies Oversight Measures
is related to AI & Autonomous Technologies Separate Verification
is related to AI & Autonomous Technologies Oversight Functions Competency
is related to AI & Autonomous Technologies Data Relevance
is related to AI & Autonomous Technologies Irregularity Reporting
is related to AI & Autonomous Technologies Use Notification To Employees
is related to AI & Autonomous Technologies Use Notification To Users
is related to Real World Testing of AI & Autonomous Technologies
is related to AI & Autonomous Technologies System Value Chain
is related to AI & Autonomous Technologies System Value Chain Fallbacks
is related to AI & Autonomous Technologies Testing Techniques
is related to Generative Artificial Intelligence (GAI) Identification
is related to AI & Autonomous Technologies Capabilities Testing
is related to Real-World Testing
is related to Documenting Testing Guidance
is related to AI & Autonomous Technologies Output Filtering
is related to Human Moderation
is related to AI Model Resilience
is related to Model Pollution
is related to Cascading Hallucination Defense
is related to Resource Exhaustion & DoS Resilience
is related to AI Agent Governance
is related to Adversarial & Red Team Testing
is related to Behavioral Drift Detection
is related to AI Agent Action Authentication & Authorization
is related to Explainability
is related to Ethics, Fairness & Bias Detection
is related to Human-in-the-Loop Workload & Manipulation
is related to Robotic Process Automation (RPA)
is related to Business Process Task Enumeration
is related to Asset Governance
is related to Asset-Service Dependencies
is related to Stakeholder Identification & Involvement
is related to Standardized Naming Convention
is related to Approved Technologies
is related to Authorized To Connect
is related to Asset Inventories
is related to Updates During Installations / Removals
is related to Component Duplication Avoidance
is related to Approved Baseline Deviations
is related to Data Action Mapping
is related to Asset Ownership Assignment
is related to Accountability Information
is related to Provenance
is related to Network Diagrams & Data Flow Diagrams (DFDs)
is related to Asset Scope Classification
is related to Control Applicability Boundary Graphical Representation
is related to Compliance-Specific Asset Identification
is related to Management Approval For External Media Transfer
is related to Unattended End-User Equipment
is related to Asset Storage In Automobiles
is related to Physical Tampering Detection
is related to Secure Disposal, Destruction or Re-Use of Equipment
is related to Return of Assets
is related to Removal of Assets
is related to Technology Asset Inspections
is related to Bring Your Own Device (BYOD) Usage
is related to Prohibited Equipment & Services
is related to Telecommunications Equipment
is related to System Administrative Processes
is related to Decommissioning
is related to Asset Categorization
is related to Categorize Artificial Intelligence (AI)-Related Technologies
is related to High-Risk Asset Categorization
is related to Asset Attributes
is related to Business Continuity Management System (BCMS)
is related to Coordinate with Related Plans
is related to Coordinate With External Service Providers
is related to Transfer to Alternate Processing / Storage Site
is related to Recovery Time / Point Objectives (RTO / RPO)
is related to Recovery Operations Criteria
is related to Recovery Operations Communications
is related to Business Continuity & Disaster Recovery (BC/DR) Plans
is related to Identify Critical Assets
is related to Resume All Missions & Business Functions
is related to Continue Essential Mission & Business Functions
is related to Resume Essential Missions & Business Functions
is related to Data Storage Location Reviews
is related to Simulated Events
is related to Contingency Plan Testing & Exercises
is related to Coordinated Testing with Related Plans
is related to Contingency Plan Root Cause Analysis (RCA) & Lessons Learned
is related to Ongoing Contingency Planning
is related to Contingency Planning Components
is related to Contingency Plan Update Notifications
is related to Alternative Security Measures
is related to Inability to Return to Primary Site
is related to Provider Contingency Plan
is related to Testing for Reliability & Integrity
is related to Separate Storage for Critical Information
is related to Transfer to Alternate Storage Site
is related to Dual Authorization For Backup Media Destruction
is related to Isolated Recovery Environment
is related to AI & Autonomous Technologies Incidents
is related to Capacity & Performance Management
is related to Capacity Planning
is related to Change Management Program
is related to Configuration Change Control
is related to Prohibition Of Changes
is related to Test, Validate & Document Changes
is related to Security, Compliance & Resilience Representative for Asset Lifecycle Changes
is related to Security Impact Analysis for Changes
is related to Access Restriction For Change
is related to Dual Authorization for Change
is related to Stakeholder Notification of Changes
is related to Control Functionality Verification
is related to Report Verification Results
is related to Emergency Changes
is related to Documenting Emergency Changes
is related to Dual Approval For High-Impact Environments
is related to Cloud Services
is related to Cloud Infrastructure Onboarding
is related to Cloud Infrastructure Offboarding
is related to Cloud Security Architecture
is related to API Gateway
is related to Customer Responsibility Matrix (CRM)
is related to Multi-Tenant Event Logging Capabilities
is related to Multi-Tenant Forensics Capabilities
is related to Multi-Tenant Incident Response Capabilities
is related to Geolocation Requirements for Processing, Storage and Service Locations
is related to Authorized Individuals For Hosted Assets, Applications & Services
is related to Sensitive / Regulated Data On Hosted Assets, Applications & Services
is related to Statutory, Regulatory & Contractual Compliance
is related to Non-Compliance Oversight
is related to Compliance Scope
is related to Ability To Demonstrate Conformity
is related to Conformity Assessment
is related to Declaration of Conformity
is related to Security, Compliance & Resilience Controls Oversight
is related to Internal Audit Function
is related to Periodic Audits
is related to Corrective Action
is related to Security, Compliance & Resilience Assessments
is related to Independent Assessors
is related to Functional Review Of Security, Compliance & Resilience Controls
is related to Assessor Access
is related to Assessment Methods
is related to Assessment Rigor
is related to Evidence Request List (ERL)
is related to Evidence Sampling
is related to Audit Activities
is related to Legal Assessment of Investigative Inquires
is related to Investigation Request Notifications
is related to Investigation Access Restrictions
is related to Government Surveillance
is related to Grievances
is related to Grievance Response
is related to Localized Representation
is related to Representative Powers
is related to Control Reciprocity
is related to Control Inheritance
is related to Dual Use Technology
is related to USML or CCL Identification
is related to Export-Controlled Access Restrictions
is related to Export Activities Documentation
is related to Statement of Applicability (SOA)
is related to Work Products
is related to Defensible Evidence of Due Diligence
is related to Defensible Evidence of Due Care
is related to Configuration Management Program
is related to Assignment of Responsibility
is related to Secure Baseline Configurations
is related to Reviews & Updates
is related to Retention Of Previous Configurations
is related to Development & Test Environment Configurations
is related to Approved Configuration Deviations
is related to Respond To Unauthorized Changes
is related to Periodic Review
is related to Security Event Monitoring
is related to Inventory of Technology Asset Event Logging
is related to Centralized Management of Event Log Content
is related to Response To Event Log Processing Failures
is related to Monitoring For Information Disclosure
is related to Sharing of Event Logs
is related to Export-Controlled Cryptography
is related to Cryptographic Cipher Suites and Protocols Inventory
is related to Defining Access Authorizations for Sensitive / Regulated Data
is related to Data Subject Attribute Associations
is related to Audit Changes
is related to Dual Authorization for Sensitive Data Destruction
is related to Information Sharing
is related to Transfer Authorizations
is related to Statistical Disclosure Control
is related to Transfer Activity Limits
is related to Embedded Technology Reviews
is related to Operating Environment Certification
is related to Safety Assessment
is related to Governing Access Restriction for Change
is related to Documented Protection Measures
is related to Malware Protection Mechanism Testing
is related to Evolving Malware Threats
is related to Human Resources Security Management
is related to Onboarding, Transferring & Offboarding Personnel
is related to Users With Elevated Privileges
is related to Probationary Periods
is related to Updating Disciplinary Processes
is related to Preventative Access Restriction
is related to Identify Critical Skills & Gaps
is related to Remediate Identified Skills Deficiencies
is related to Identify Vital Security, Compliance & Resilience Staff
is related to Establish Redundancy for Vital Security, Compliance & Resilience Staff
is related to Perform Succession Planning
is related to Identifying Authorized Work Locations
is related to Communicating Authorized Work Locations
is related to Reporting Suspicious Activities
is related to User & Service Account Inventories
is related to Events Requiring Authenticator Change
is related to Periodic Review of Account Privileges
is related to Credential Sharing
is related to Auditing Use of Privileged Functions
is related to Identity Proofing (Identity Verification)
is related to Management Approval For New or Changed Accounts
is related to Identity Evidence
is related to Identity Evidence Validation & Verification
is related to In-Person Validation & Verification
is related to Address Confirmation
is related to Incident Response Operations
is related to Incident Handling
is related to Insider Threat Response Capability
is related to Incident Classification & Prioritization
is related to Correlation with External Organizations
is related to Indicators of Compromise (IOC)
is related to Incident Response Plan (IRP)
is related to Data Breach
is related to IRP Update
is related to Continuous Incident Response Improvements
is related to Incident Response Training
is related to Simulated Incidents
is related to Incident Response Testing
is related to Coordination with Related Plans
is related to Integrated Security Incident Response Team (ISIRT)
is related to Situational Awareness For Incidents
is related to Recurring Incident Analysis
is related to Incident Tracking Repository
is related to Incident Pattern Analysis
is related to Incident Stakeholder Reporting
is related to Cyber Incident Reporting for Sensitive / Regulated Data
is related to Vulnerabilities Related To Incidents
is related to Supply Chain Coordination
is related to Serious Incident Reporting
is related to Incident Reporting Assistance
is related to Coordination With External Providers
is related to Sensitive / Regulated Data Spill Response
is related to Sensitive / Regulated Data Spill Responsible Personnel
is related to Sensitive / Regulated Data Spill Training
is related to Post-Sensitive / Regulated Data Spill Operations
is related to Sensitive / Regulated Data Exposure to Unauthorized Personnel
is related to Root Cause Analysis (RCA) & Lessons Learned
is related to Regulatory & Law Enforcement Contacts
is related to Public Relations & Reputation Repair
is related to Information Assurance (IA) Operations
is related to Assessment Boundaries
is related to Assessments
is related to Assessor Independence
is related to Specialized Assessments
is related to Third-Party Assessment Reciprocity
is related to Security Assessment Report (SAR)
is related to Applied Security, Compliance and Resilience Controls Documentation
is related to Plan / Coordinate with Other Organizational Entities
is related to Adequate Security for Sensitive / Regulated Data In Support of Contracts
is related to Threat Analysis & Flaw Remediation During Development
is related to Capabilities Deficiency Tracking
is related to Technical Verification
is related to Security Authorization
is related to Maintenance Operations
is related to Controlled Maintenance
is related to Timely Maintenance
is related to Preventative Maintenance
is related to Predictive Maintenance
is related to Maintenance Tools
is related to Inspect Media
is related to Prevent Unauthorized Removal
is related to Remote Maintenance
is related to Auditing Remote Maintenance
is related to Remote Maintenance Notifications
is related to Remote Maintenance Pre-Approval
is related to Remote Maintenance Comparable Security & Sanitization
is related to Authorized Maintenance Personnel
is related to Non-System Related Maintenance
is related to Maintain Configuration Control During Maintenance
is related to Field Maintenance
is related to Off-Site Maintenance
is related to Maintenance Validation
is related to Maintenance Monitoring
is related to External Telecommunications Services
is related to Human Reviews
is related to Interconnection Security Agreements (ISAs)
is related to Work From Anywhere (WFA) - Telecommuting Security
is related to Third-Party Remote Access Governance
is related to User Threat Reporting
is related to Physical & Environmental Protections
is related to Physical Security Plan (PSP)
is related to Zone-Based Physical Security
is related to Physical Access Authorizations
is related to Dual Authorization for Physical Access
is related to Monitoring Physical Access
is related to Monitoring Physical Access To Critical Systems
is related to Monitoring with Alarms / Notifications
is related to Data Privacy Program
is related to Privacy Act Statements
is related to Dissemination of Data Privacy Program Information
is related to Binding Corporate Rules (BCR)
is related to Data Fiduciary
is related to Financial Incentives For Personal Data (PD)
is related to Reasonable Data Privacy Practices
is related to Data Privacy Notice
is related to Purpose Specification
is related to Computer Matching Agreements (CMA)
is related to System of Records Notice (SORN)
is related to System of Records Notice (SORN) Review Process
is related to Privacy Act Exemptions
is related to Real-Time or Layered Notice
is related to Purpose Compatibility
is related to Privacy Notice Formatting
is related to Symmetry In Choice
is related to Choice Architecture
is related to Choice Architecture Testing
is related to Notice of Right To Limit
is related to Alternative Means To Deliver Privacy Notice
is related to Choice & Consent
is related to Tailored Consent
is related to Just-In-Time Notice & Updated Consent
is related to Product or Service Delivery Restrictions
is related to Authorized Agent
is related to Active Participation By Data Subjects
is related to Continued Use of Personal Data (PD)
is related to Cease Processing, Storing and/or Sharing Personal Data (PD)
is related to Communicating Processing Changes
is related to Data Subject Opt-In Consent
is related to Parent or Guardian Opt-In Consent For Minors
is related to Authority To Collect, Process, Store & Share Personal Data (PD)
is related to Primary Sources
is related to Identifiable Image Collection
is related to Acquired Personal Data (PD)
is related to Personal Data (PD) Collection Methods
is related to Personal Data (PD) Formats
is related to Notice of Correction or Processing Change
is related to Appeal Adverse Decision
is related to User Feedback Management
is related to Data Subject Authentication
is related to Obligation To Inform Third-Parties
is related to Reject Unauthenticated or Untrustworthy Disclosure Requests
is related to Justification To Reject Disclosure Requests
is related to Personal Data (PD) Control Testing, Training & Monitoring
is related to Personal Data (PD) Lineage
is related to Data Quality Management
is related to Data Analytics Bias
is related to Enabling Data Subjects To Update Personal Data (PD)
is related to Data Management Board
is related to Documenting Data Processing Activities
is related to Accounting of Disclosures
is related to Notification of Disclosure Request To Data Subject
is related to Register As A Data Controller and/or Data Processor
is related to Potential Human Rights Abuses
is related to Data Subject Communications
is related to Conspicuous Link To Data Privacy Notice
is related to Notice of Financial Incentive
is related to Data Subject Communications Documentation
is related to Data Subject Communications Metrics
is related to Data Subject Communications Disclosure
is related to Data Controller Communications
is related to Automated Decision-Making Technology (ADMT) For Data Subject Actions
is related to Automated Decision-Making Technology (ADMT) Use Notification
is related to Automated Decision-Making Technology (ADMT) Opt-Out Consent
is related to Automated Decision-Making Technology (ADMT) Transparency
is related to Data Brokers
is related to Notice of Right To Opt-Out
is related to Opt-Out Links
is related to Alternative Out-Out Link
is related to Security, Compliance & Resilience Protection Portfolio Management
is related to Strategic Plan & Objectives
is related to Targeted Capability Maturity Levels
is related to Security, Compliance & Resilience Resource Management
is related to Prioritization To Address Evolving Risks & Threats
is related to Allocation of Resources
is related to Security, Compliance & Resilience In Project Management
is related to Security, Compliance & Resilience Requirements Definition
is related to Business Process Definition
is related to Secure Development Life Cycle (SDLC) Management
is related to Manage Organizational Knowledge
is related to Risk Management Program
is related to Risk Framing
is related to Risk Management Resourcing
is related to Risk Tolerance
is related to Risk Threshold
is related to Risk Appetite
is related to Risk-Based Security Categorization
is related to Impact-Level Prioritization
is related to Risk Identification
is related to Risk Catalog
is related to Risk Assessment
is related to Risk Register
is related to Risk Assessment Methodology
is related to Instances Requiring A Risk Assessment
is related to Risk Assessment Stakeholder Involvement
is related to Risk Ranking
is related to Risk Remediation
is related to Risk Response
is related to Compensating Countermeasures
is related to Risk Treatment Options
is related to Risk Treatment Plan (RTP)
is related to Risk Assessment Update
is related to Business Impact Analysis (BIA)
is related to Supply Chain Risk Management (SCRM) Plan
is related to Supply Chain Risk Assessment
is related to AI & Autonomous Technologies Supply Chain Impacts
is related to Data Protection Impact Assessment (DPIA)
is related to Risk Monitoring
is related to Risk Culture
is related to Executive Leadership Approval For Managing Material Risk
is related to Documented Alternatives
is related to Documented Justification For Material Risk Management Decisions
is related to Secure Engineering Principles
is related to Centralized Management of Security, Compliance & Resilience Controls
is related to Achieving Resilience Requirements
is related to Alignment With Enterprise Architecture
is related to Standardized Terminology
is related to Outsourcing Non-Essential Functions or Services
is related to Technical Debt Reviews
is related to Predictable Failure Analysis
is related to Technology Lifecycle Management
is related to Refresh from Trusted Sources
is related to Information Output Filtering
is related to Privileged Environments
is related to Operations Security
is related to Standardized Operating Procedures (SOP)
is related to Security Concept Of Operations (CONOPS)
is related to Service Delivery (Business Process Support)
is related to Security Operations Center (SOC)
is related to Secure Practices Guidelines
is related to Security Orchestration, Automation, and Response (SOAR)
is related to Shadow Information Technology Detection
is related to Security, Compliance & Resilience-Minded Workforce
is related to Maintaining Workforce Development Relevancy
is related to Security, Compliance & Resilience Training Records
is related to Security, Compliance & Resilience Knowledge Sharing
is related to Technology Development & Acquisition
is related to Product Management
is related to Integrity Mechanisms for Software / Firmware Updates
is related to Malware Testing Prior to Release
is related to DevSecOps
is related to Minimum Viable Product (MVP) Security Requirements
is related to Ports, Protocols & Services In Use
is related to Information Assurance Enabled Products
is related to Development Methods, Techniques & Processes
is related to Identification & Justification of Ports, Protocols & Services
is related to Insecure Ports, Protocols & Services
is related to Security, Compliance & Resilience Representatives For Product Changes
is related to Minimizing Attack Surfaces
is related to Product Testing & Reviews
is related to Disclosure of Vulnerabilities
is related to Products With Digital Elements
is related to Reporting Exploitable Vulnerabilities
is related to Commercial Off-The-Shelf (COTS) Security Solutions
is related to Supplier Diversity
is related to Documentation Requirements
is related to Functional Properties
is related to Software Bill of Materials (SBOM)
is related to Developer Architecture & Design
is related to Physical Diagnostic & Test Interfaces
is related to Secure Software Development Practices (SSDP)
is related to Criticality Analysis During Development
is related to Threat Modeling
is related to Software Assurance Maturity Model (SAMM)
is related to Software Design Review
is related to Software Design Root Cause Analysis
is related to Secure Development Environments
is related to Separation of Development, Testing and Operational Environments
is related to Secure Migration Practices
is related to Security, Compliance & Resilience Testing Throughout Development
is related to Continuous Monitoring Plan
is related to Static Code Analysis
is related to Dynamic Code Analysis
is related to Malformed Input Testing
is related to Application Penetration Testing
is related to Manual Code Review
is related to Use of Live Data
is related to Test Data Integrity
is related to Product Tampering and Counterfeiting (PTC)
is related to Customized Development of Critical Components
is related to Developer Configuration Management
is related to Software / Firmware Integrity Verification
is related to Hardware Integrity Verification
is related to Developer Threat Analysis & Flaw Remediation
is related to Developer-Provided Training
is related to Unsupported Technology Assets, Applications and/or Services (TAAS)
is related to Alternate Sources for Continued Support
is related to Access to Program Source Code
is related to Software Release Integrity Verification
is related to Archiving Software Releases
is related to Software Escrow
is related to Approved Code
is related to Product Conformity Governance
is related to Technical Documentation Artifacts
is related to Product-Specific Risk Assessment Artifacts
is related to Third-Party Management
is related to Third-Party Inventories
is related to Third-Party Criticality Assessments
is related to Supply Chain Risk Management (SCRM)
is related to Acquisition Strategies, Tools & Methods
is related to Limit Potential Harm
is related to Processes To Address Weaknesses or Deficiencies
is related to Adequate Supply
is related to Third-Party Services
is related to Third-Party Risk Assessments & Approvals
is related to External Connectivity Requirements - Identification of Ports, Protocols & Services
is related to Conflict of Interests
is related to Third-Party Processing, Storage and Service Locations
is related to Third-Party Contract Requirements
is related to Security Compromise Notification Agreements
is related to Contract Flow-Down Requirements
is related to Third-Party Authentication Practices
is related to Responsible, Accountable, Supportive, Consulted & Informed (RASCI) Matrix
is related to Third-Party Scope Review
is related to First-Party Declaration (1PD)
is related to Break Clauses
is related to Third-Party Attestation (3PA)
is related to Third-Party Personnel Security
is related to Monitoring for Third-Party Information Disclosure
is related to Review of Third-Party Services
is related to Third-Party Deficiency Remediation
is related to Managing Changes To Third-Party Services
is related to Third-Party Incident Response & Recovery Capabilities
is related to Foreign Ownership, Control or Influence (FOCI)
is related to Ownership Change Monitoring
is related to Ownership Change Provisions
is related to Threat Intelligence Program
is related to Indicators of Exposure (IOE)
is related to Threat Intelligence Feeds
is related to Threat Intelligence Reporting
is related to Insider Threat Program
is related to Insider Threat Awareness
is related to Vulnerability Disclosure Program (VDP)
is related to Security Disclosure Contact Information
is related to Threat Hunting
is related to Tainting
is related to Threat Catalog
is related to Threat Analysis
is related to Vulnerability & Patch Management Program (VPMP)
is related to Attack Surface Scope
is related to Vulnerability Remediation Process
is related to Vulnerability Ranking
is related to Vulnerability Exploitation Analysis
is related to Continuous Vulnerability Remediation Activities
is related to Stable Versions
is related to Flaw Remediation with Personal Data (PD)
is related to Deferred Patching Decisions
is related to Centralized Management of Flaw Remediation Processes
is related to Time To Remediate / Benchmarks For Corrective Action
is related to Pre-Deployment Patch Testing
is related to Out-of-Cycle Patching
is related to Vulnerability Scanning
is related to Breadth / Depth of Coverage
is related to Review Historical Event logs
is related to Independent Penetration Agent or Team
is related to Technical Surveillance Countermeasures Security
is related to Reviewing Vulnerability Scanner Usage
is related to Red Team Exercises
is related to Web Security
is related to Unauthorized Code
is related to Use of Demilitarized Zones (DMZ)
is related to Web Security Standard
is related to Web Application Framework
is related to Validation & Sanitization
is related to Publicly Accessible Content Reviews
Impressum German English