relative Control Weighting = 08

Linked Issues

Issuelinks
Linktype Issue
is related to Exception Management
is related to Stakeholder Accountability Structure
is related to Select Controls
is related to Assess Controls
is related to Authorize Technology Assets, Applications and/or Services (TAAS)
is related to Monitor Controls
is related to Security, Compliance & Resilience Status Reporting
is related to AI & Autonomous Technologies-Related Legal Requirements Definition
is related to AI & Autonomous Technologies Context Definition
is related to AI & Autonomous Technologies Mission and Goals Definition
is related to AI & Autonomous Technologies Business Case
is related to AI & Autonomous Technologies Targeted Application Scope
is related to AI & Autonomous Technologies Impact Assessment
is related to AI & Autonomous Technologies Continuous Improvements
is related to AI TEVV Model Collapse Mitigations
is related to AI & Autonomous Technologies Stakeholder Diversity
is related to AI & Autonomous Technologies Requirements Definitions
is related to AI & Autonomous Technologies Implementation Tasks Definition
is related to AI & Autonomous Technologies Measurement Approaches
is related to AI & Autonomous Technologies Domain Expert Reviews
is related to Pre-Trained AI & Autonomous Technologies Models
is related to Serious Incident Root Cause Analysis (RCA) For AI & Autonomous Technologies
is related to AI & Autonomous Technologies Deployment
is related to AI & Autonomous Technologies Irregularity Reporting
is related to AI & Autonomous Technologies Testing Techniques
is related to Approved Baseline Deviations
is related to Software Licensing Restrictions
is related to Asset Ownership Assignment
is related to Provenance
is related to Asset Scope Classification
is related to Security of Assets & Media
is related to Management Approval For External Media Transfer
is related to Kiosks & Point of Interaction (PoI) Devices
is related to Return of Assets
is related to Removal of Assets
is related to Video Teleconference (VTC) Security
is related to Voice Over Internet Protocol (VoIP) Security
is related to Microphones & Web Cameras
is related to Multi-Function Devices (MFD)
is related to Travel-Only Devices
is related to Re-Imaging Devices After Travel
is related to Resume All Missions & Business Functions
is related to Continue Essential Mission & Business Functions
is related to Resume Essential Missions & Business Functions
is related to Data Storage Location Reviews
is related to Ongoing Contingency Planning
is related to Contingency Planning Components
is related to Separate Storage for Critical Information
is related to Recovery Images
is related to Failover Capability
is related to Electronic Discovery (eDiscovery)
is related to Backup & Restoration Hardware Protection
is related to Capacity & Performance Management
is related to Resource Priority
is related to Capacity Planning
is related to Configuration Change Control
is related to Access Restriction For Change
is related to Library Privileges
is related to Cloud Security Architecture
is related to Virtual Machine Images
is related to Customer Responsibility Matrix (CRM)
is related to Multi-Tenant Event Logging Capabilities
is related to Multi-Tenant Forensics Capabilities
is related to Multi-Tenant Incident Response Capabilities
is related to Prohibition On Unverified Hosted Assets, Applications & Services
is related to Ability To Demonstrate Conformity
is related to Periodic Audits
is related to Functional Review Of Security, Compliance & Resilience Controls
is related to Dual Use Technology
is related to USML or CCL Identification
is related to Export-Controlled Access Restrictions
is related to Export Activities Documentation
is related to Work Products
is related to Defensible Evidence of Due Diligence
is related to Defensible Evidence of Due Care
is related to Reviews & Updates
is related to Configure Technology Assets, Applications and/or Services (TAAS) for High-Risk Areas
is related to Periodic Review
is related to Split Tunneling
is related to Unauthorized Installation Alerts
is related to Zero-Touch Provisioning (ZTP)
is related to Host-Based Devices
is related to Proxy Logging
is related to Sensitive Event Log Information
is related to Privileged Functions Logging
is related to Limit Personal Data (PD) In Audit Records
is related to Database Logging
is related to Event Log Storage Capacity
is related to Response To Event Log Processing Failures
is related to Synchronization With Authoritative Time Source
is related to Access by Subset of Privileged Users
is related to Non-Repudiation
is related to Monitoring For Information Disclosure
is related to Insider Threats
is related to Third-Party Threats
is related to Unauthorized Activities
is related to Automated Authentication Through Cryptographic Modules
is related to Storage Media
is related to Database Encryption
is related to Cryptographic Key Loss or Change
is related to Assigned Owners
is related to Certificate Authorities
is related to Highest Classification Level
is related to Media Access
is related to Attribute Value Changes By Authorized Individuals
is related to Attribute Displays for Output Devices
is related to Attribute Configuration By Authorized Individuals
is related to Media Storage
is related to Media Use
is related to Data Reclassification
is related to Limits of Authorized Use
is related to Transfer Authorizations
is related to Ad-Hoc Transfers
is related to Media & Data Retention
is related to Minimize Sensitive / Regulated Data
is related to Limit Sensitive / Regulated Data In Testing, Training & Research
is related to Archived Data Sets
is related to Primary Source Personal Data (PD) Collection
is related to De-Identification (Anonymization)
is related to De-Identify Dataset Upon Collection
is related to Archiving
is related to Release
is related to Removal, Masking, Encryption, Hashing or Replacement of Direct Identifiers
is related to Embedded Technology Reviews
is related to Restrict Communications
is related to Authorized Communications
is related to Software Installation Alerts
is related to Governing Access Restriction for Change
is related to Centralized Management of Antimalware Technologies
is related to Heuristic / Nonsignature-Based Detection
is related to Endpoint File Integrity Monitoring (FIM)
is related to Automatic Spam and Phishing Protection Updates
is related to Authorized Use
is related to Collection Minimization
is related to Position Categorization
is related to Policy Familiarization & Acknowledgement
is related to Workplace Investigations
is related to Post-Employment Requirements Notification
is related to Incompatible Roles
is related to Identifying Authorized Work Locations
is related to Communicating Authorized Work Locations
is related to Password Managers
is related to Passkeys
is related to Cryptographic Module Authentication
is related to Re-Authentication
is related to Dedicated Administrative Machines
is related to Permitted Actions Without Identification or Authorization
is related to Indicators of Compromise (IOC)
is related to Data Breach
is related to IRP Update
is related to Situational Awareness For Incidents
is related to Vulnerabilities Related To Incidents
is related to Sensitive / Regulated Data Spill Response
is related to Sensitive / Regulated Data Spill Responsible Personnel
is related to Sensitive / Regulated Data Spill Training
is related to Post-Sensitive / Regulated Data Spill Operations
is related to Sensitive / Regulated Data Exposure to Unauthorized Personnel
is related to Root Cause Analysis (RCA) & Lessons Learned
is related to Technical Verification
is related to Maintain Configuration Control During Maintenance
is related to Field Maintenance
is related to Off-Site Maintenance
is related to Personally-Owned Mobile Devices
is related to Organization-Owned Mobile Devices
is related to Restricting Access To Authorized Technology Assets, Applications and/or Services (TAAS)
is related to Zero Trust Architecture (ZTA)
is related to External System Connections
is related to Network Connection Termination
is related to DMZ Networks
is related to Wireless Intrusion Detection / Prevention Systems (WIDS / WIPS) Deployment
is related to Session Integrity
is related to Sender Policy Framework (SPF)
is related to Safeguarding Data Over Open Networks
is related to Wireless Link Protection
is related to Remote Privileged Commands & Sensitive Data Access
is related to Third-Party Remote Access Governance
is related to Expeditious Disconnect / Disable Capability
is related to Restrict Configuration By Users
is related to Rogue Wireless Detection
is related to Intranets
is related to Data Loss Prevention (DLP)
is related to Domain Name Verification
is related to Internet Address Denylisting
is related to Distinguish Visitors from On-Site Personnel
is related to Identification Requirement
is related to Automatic Voltage Controls
is related to Emergency Shutoff
is related to Emergency Power
is related to Water Damage Protection
is related to Monitoring with Alarms / Notifications
is related to Delivery & Removal
is related to Alternate Work Site
is related to Access Control for Output Devices
is related to Personal Data (PD) Retention & Disposal
is related to Internal Use of Personal Data (PD) For Testing, Training and Research
is related to Data Masking
is related to Usage Restrictions of Personal Data (PD)
is related to Inventory of Personal Data (PD)
is related to Personal Data (PD) Control Testing, Training & Monitoring
is related to Documenting Data Processing Activities
is related to Accounting of Disclosures
is related to Security, Compliance & Resilience Protection Portfolio Management
is related to Security, Compliance & Resilience Resource Management
is related to Allocation of Resources
is related to Risk Management Resourcing
is related to Risk Assessment Methodology
is related to Risk Assessment Stakeholder Involvement
is related to Business Impact Analysis (BIA)
is related to AI & Autonomous Technologies Supply Chain Impacts
is related to System Partitioning
is related to Application Partitioning
is related to Information In Shared Resources
is related to Prevent Program Execution
is related to Fail Secure
is related to Fail Safe
is related to Information Output Filtering
is related to Limit Personal Data (PD) Dissemination
is related to Memory Protection
is related to Secure Log-On Procedures
is related to Operations Security
is related to Security Operations Center (SOC)
is related to Shadow Information Technology Detection
is related to Security, Compliance & Resilience-Minded Workforce
is related to Security, Compliance & Resilience Awareness Training
is related to Role-Based Security, Compliance & Resilience Training
is related to Cyber Threat Environment
is related to Continuing Professional Education (CPE) - Security, Compliance & Resilience Personnel
is related to Continuing Professional Education (CPE) - DevOps Personnel
is related to Ports, Protocols & Services In Use
is related to Pre-Established Secure Configurations
is related to Identification & Justification of Ports, Protocols & Services
is related to Reporting Exploitable Vulnerabilities
is related to Logging Syntax
is related to Documentation Requirements
is related to Functional Properties
is related to Developer Architecture & Design
is related to Secure Migration Practices
is related to Test Data Integrity
is related to Customized Development of Critical Components
is related to Software / Firmware Integrity Verification
is related to Alternate Sources for Continued Support
is related to Archiving Software Releases
is related to Approved Code
is related to Third-Party Inventories
is related to Conflict of Interests
is related to Third-Party Authentication Practices
is related to Responsible, Accountable, Supportive, Consulted & Informed (RASCI) Matrix
is related to Monitoring for Third-Party Information Disclosure
is related to Managing Changes To Third-Party Services
is related to Third-Party Incident Response & Recovery Capabilities
is related to Threat Intelligence Program
is related to Indicators of Exposure (IOE)
is related to Threat Intelligence Feeds
is related to Threat Intelligence Reporting
is related to Insider Threat Program
is related to Insider Threat Awareness
is related to Vulnerability Disclosure Program (VDP)
is related to Vulnerability Ranking
is related to Continuous Vulnerability Remediation Activities
is related to Stable Versions
is related to Flaw Remediation with Personal Data (PD)
is related to Update Tool Capability
is related to Breadth / Depth of Coverage
is related to Web Security
is related to Web Application Firewall (WAF)
is related to Strong Customer Authentication (SCA)
is related to Website Change Detection
Impressum German English