Secure Controls Framework

The Secure Controls Framework® (SCF)

"The SCF is the Common Controls Framework™ (CCF), the world's most comprehensive cybersecurity and data privacy metaframework - it is also free to use. The entire concept is building secure, compliant and resilient capabilities in the most efficient and cost-effective manner possible.

The SCF is more than just a unified control catalog, since its included content creates a playbook for Governance, Risk & Compliance (GRC) capabilities. Used globally by organizations of every size, the SCF is a robust and scalable solution for security, compliance and resilience controls. As a comprehensive security framework, the SCF maps 1,400+ controls across 200+ laws, regulations, and industry frameworks so you can implement once and comply everywhere.

Like it or not, cybersecurity is a protracted war on an asymmetric battlefield, where the threats are everywhere and as defenders we have to make the effort to work together to help improve cybersecurity and data privacy practices, since we all suffer when massive data breaches occur or when cyber attacks have physical impacts. Hackers share information on attack methods with other hackers, so why shouldn’t the good guys share information on how to best protect an organization? We decided to take action and make a difference, since we feel it is too important to wait for someone else to fix the problems that exist.

The SCF is made up of volunteers, mainly specialists within the cybersecurity profession, who focus on GRC and the cybersecurity side of data privacy. These are auditors, engineers, architects, incident responders, consultants and other specialists who live and breathe these topics on a daily basis. The end product is "expert-derived content" that makes up the SCF." https://securecontrolsframework.com/ 

Terms & Conditions

The SCF End User License Agreement (EULA) governs the use of the Secure Controls Framework® (SCF) under the Creative Commons Attribution-No Derivatives 4.0 International Public License.

Issues
Issuetype Summary Source
Standard Secure Controls Framework

Secure Controls Framework

Issues
Summary Source
+ Secure Controls Framework
---+ Cybersecurity & Data Protection Governance
------+ Security, Compliance & Resilience Program (SCRP)
---------+ Steering Committee & Program Oversight
---------+ Status Reporting To Governing Body
---------+ Commitment To Continual Improvements
------+ Publishing Security, Compliance & Resilience Documentation
---------+ Exception Management
------+ Periodic Review & Update of Security, Compliance & Resilience Program
------+ Assigned Security, Compliance & Resilience Responsibilities
---------+ Stakeholder Accountability Structure
---------+ Authoritative Chain of Command
------+ Measures of Performance
---------+ Key Performance Indicators (KPIs)
---------+ Key Risk Indicators (KRIs)
------+ Contacts With Authorities
------+ Contacts With Groups & Associations
------+ Defining Business Context & Mission
------+ Define Control Objectives
------+ Data Governance
------+ Purpose Validation
------+ Forced Technology Transfer (FTT)
------+ State-Sponsored Espionage
------+ Business As Usual (BAU) Security, Compliance & Resilience Practices
------+ Operationalizing Security, Compliance & Resilience Capabilities
---------+ Select Controls
---------+ Implement Controls
---------+ Assess Controls
---------+ Authorize Technology Assets, Applications and/or Services (TAAS)
---------+ Monitor Controls
------+ Materiality Determination
---------+ Material Risks
---------+ Material Threats
------+ Security, Compliance & Resilience Status Reporting
------+ Quality Management System (QMS)
------+ Assurance
---------+ Assurance Levels (AL)
---------+ Assessment Objectives (AO)
------+ Mergers, Acquisitions & Divestitures (MA&D)
---------+ Virtual Data Room (VDR)
---+ Artificial Intelligence & Autonomous Technologies
------+ Artificial Intelligence (AI) & Autonomous Technologies Governance
---------+ AI & Autonomous Technologies-Related Legal Requirements Definition
---------+ Trustworthy AI & Autonomous Technologies
---------+ AI & Autonomous Technologies Value Sustainment
---------+ AI Model & Agent Inventory & Lifecycle Management
------+ Situational Awareness of AI & Autonomous Technologies
---------+ AI & Autonomous Technologies Risk Mapping
---------+ AI & Autonomous Technologies Internal Controls
---------+ Adequate Protections For AI & Autonomous Technologies
---------+ AI Threat Modeling & Risk Assessment
------+ AI & Autonomous Technologies Context Definition
---------+ AI & Autonomous Technologies Mission and Goals Definition
---------+ Model & AI Agent Documentation
------+ AI & Autonomous Technologies Business Case
---------+ AI & Autonomous Technologies Potential Benefits Analysis
---------+ AI & Autonomous Technologies Potential Costs Analysis
---------+ AI & Autonomous Technologies Targeted Application Scope
---------+ AI & Autonomous Technologies Cost / Benefit Mapping
------+ AI & Autonomous Technologies Training
------+ AI & Autonomous Technologies Fairness & Bias
------+ AI & Autonomous Technologies Risk Management Decisions
---------+ AI & Autonomous Technologies Impact Assessment
---------+ AI & Autonomous Technologies Likelihood & Impact Risk Analysis
---------+ AI & Autonomous Technologies Continuous Improvements
------+ Assigned Responsibilities for AI & Autonomous Technologies
------+ AI & Autonomous Technologies Risk Profiling
---------+ AI & Autonomous Technologies High Risk Designations
------+ Artificial Intelligence Test, Evaluation, Validation & Verification (AI TEVV)
---------+ AI TEVV Trustworthiness Assessment
---------+ AI TEVV Tools
---------+ AI TEVV Trustworthiness Demonstration
---------+ AI TEVV Safety Demonstration
---------+ AI TEVV Security & Resiliency Assessment
---------+ AI TEVV Transparency & Accountability Assessment
---------+ AI TEVV Privacy Assessment
---------+ AI TEVV Fairness & Bias Assessment
---------+ AI & Autonomous Technologies Model Validation
---------+ AI TEVV Results Evaluation
---------+ AI TEVV Effectiveness
---------+ AI TEVV Comparable Deployment Settings
---------+ AI TEVV Post-Deployment Monitoring
---------+ Updating AI & Autonomous Technologies
---------+ AI TEVV Reporting
---------+ AI TEVV Empirically Validated Methods
---------+ AI TEVV Benchmarking Content Provenance
---------+ AI TEVV Model Collapse Mitigations
---------+ AI TEVV Third-Party Risk Management
------+ Robust Stakeholder Engagement for AI & Autonomous Technologies
---------+ AI & Autonomous Technologies Stakeholder Feedback Integration
---------+ AI & Autonomous Technologies Ongoing Assessments
---------+ AI & Autonomous Technologies End User Feedback
---------+ AI & Autonomous Technologies Incident & Error Reporting
------+ AI & Autonomous Technologies Intellectual Property Infringement Protections
---------+ Data Source Identification
---------+ Data Source Integrity
---------+ Data Source Lineage & Origin Disclosure
---------+ Digital Content Modification Logging
------+ AI & Autonomous Technologies Stakeholder Diversity
---------+ AI & Autonomous Technologies Stakeholder Competencies
------+ AI & Autonomous Technologies Requirements Definitions
---------+ AI & Autonomous Technologies Implementation Tasks Definition
---------+ AI & Autonomous Technologies Knowledge Limits
------+ AI & Autonomous Technologies Viability Decisions
---------+ AI & Autonomous Technologies Negative Residual Risks
---------+ Responsibility To Supersede, Deactivate and/or Disengage AI & Autonomous Technologies
------+ AI & Autonomous Technologies Production Monitoring
---------+ AI & Autonomous Technologies Measurement Approaches
---------+ Measuring AI & Autonomous Technologies Effectiveness
---------+ Unmeasurable AI & Autonomous Technologies Risks
---------+ Efficacy of AI & Autonomous Technologies Measurement
---------+ AI & Autonomous Technologies Domain Expert Reviews
---------+ AI & Autonomous Technologies Performance Changes
---------+ Pre-Trained AI & Autonomous Technologies Models
---------+ AI & Autonomous Technologies Event Logging
---------+ Serious Incident Reporting For AI & Autonomous Technologies
---------+ Serious Incident Root Cause Analysis (RCA) For AI & Autonomous Technologies
---------+ Anomaly Detection & Human Oversight
---------+ Human-in-the-Loop & Escalation
---------+ Emergent Behavior & Collusion Protections
---------+ Multi-Agent Trust & Communication Validation
------+ AI & Autonomous Technologies Harm Prevention
---------+ AI & Autonomous Technologies Human Subject Protections
---------+ AI & Autonomous Technologies Environmental Impact & Sustainability
---------+ Previously Unknown AI & Autonomous Technologies Threats & Risks
---------+ Novel Risk Assessment Methods & Technologies
---------+ Fine Tuning Risk Mitigation
------+ AI & Autonomous Technologies Risk Tracking Approaches
---------+ AI & Autonomous Technologies Risk Response
------+ AI & Autonomous Technologies Conformity
---------+ Manipulative or Deceptive Techniques
---------+ Materially Distorting Behaviors
---------+ Social Scoring
---------+ Detrimental or Unfavorable Treatment
---------+ Risk and Criminal Profiling
---------+ Populating Facial Recognition Databases
---------+ Emotion Inference
---------+ Biometric Categorization
------+ AI & Autonomous Technologies Development Practices
---------+ AI & Autonomous Technologies Transparency
---------+ AI & Autonomous Technologies Implementation Documentation
---------+ AI & Autonomous Technologies Human Domain Knowledge Reliance
------+ AI & Autonomous Technologies Registration
------+ AI & Autonomous Technologies Deployment
---------+ AI & Autonomous Technologies Human Oversight
---------+ AI & Autonomous Technologies Oversight Measures
---------+ AI & Autonomous Technologies Separate Verification
---------+ AI & Autonomous Technologies Oversight Functions Competency
---------+ AI & Autonomous Technologies Data Relevance
---------+ AI & Autonomous Technologies Irregularity Reporting
---------+ AI & Autonomous Technologies Use Notification To Employees
---------+ AI & Autonomous Technologies Use Notification To Users
------+ AI & Autonomous Technologies Output Marking
------+ Real World Testing of AI & Autonomous Technologies
------+ AI & Autonomous Technologies System Value Chain
---------+ AI & Autonomous Technologies System Value Chain Fallbacks
------+ AI & Autonomous Technologies Testing Techniques
---------+ Generative Artificial Intelligence (GAI) Identification
---------+ AI & Autonomous Technologies Capabilities Testing
---------+ Real-World Testing
---------+ Documenting Testing Guidance
------+ AI & Autonomous Technologies Output Filtering
---------+ Human Moderation
------+ AI Model Resilience
---------+ Model Pollution
---------+ Cascading Hallucination Defense
---------+ Resource Exhaustion & DoS Resilience
------+ AI Agent Governance
---------+ Infrastructure Hardening & Isolation
---------+ AI Agent Limitations
---------+ Tool & API Invocation Controls
---------+ Orchestration Protocol Safeguards
---------+ Data Pipeline & Input Integrity
---------+ Privileged Role & Delegation Boundaries
---------+ AI Agent Data Access Restrictions
---------+ Data Extraction
---------+ AI Agent Identity & Impersonation Defense
---------+ AI Agent Logic Integrity
---------+ Sandboxing AI Agents
---------+ Prompt Injection Defense
---------+ Agent Kill Switch / User Control
---------+ Adversarial & Red Team Testing
---------+ Self-Modification Controls
---------+ Purging AI Agent Data
---------+ Delegation and Chaining Control
---------+ Behavioral Drift Detection
---------+ AI Agent Action Authentication & Authorization
---------+ Transparency & Audit
---------+ Explainability
---------+ Ethics, Fairness & Bias Detection
---------+ Agent Output Integrity & Verification
------+ Agentic Output Traceability & Repudiation
---------+ AI Agent Logging
---------+ Session Management
------+ Human-in-the-Loop Workload & Manipulation
------+ Robotic Process Automation (RPA)
---------+ Business Process Task Enumeration
---+ Asset Management
------+ Asset Governance
---------+ Asset-Service Dependencies
---------+ Stakeholder Identification & Involvement
---------+ Standardized Naming Convention
---------+ Approved Technologies
---------+ Authorized To Connect
------+ Asset Inventories
---------+ Updates During Installations / Removals
---------+ Automated Unauthorized Component Detection
---------+ Component Duplication Avoidance
---------+ Approved Baseline Deviations
---------+ Network Access Control (NAC)
---------+ Dynamic Host Configuration Protocol (DHCP) Server Logging
---------+ Software Licensing Restrictions
---------+ Data Action Mapping
---------+ Configuration Management Database (CMDB)
---------+ Automated Location Tracking
---------+ Component Assignment
------+ Asset Ownership Assignment
---------+ Accountability Information
---------+ Provenance
------+ Network Diagrams & Data Flow Diagrams (DFDs)
---------+ Asset Scope Classification
---------+ Control Applicability Boundary Graphical Representation
---------+ Compliance-Specific Asset Identification
------+ Security of Assets & Media
---------+ Management Approval For External Media Transfer
------+ Unattended End-User Equipment
---------+ Asset Storage In Automobiles
------+ Kiosks & Point of Interaction (PoI) Devices
------+ Physical Tampering Detection
------+ Secure Disposal, Destruction or Re-Use of Equipment
------+ Return of Assets
------+ Removal of Assets
------+ Use of Personal Devices
------+ Use of Third-Party Devices
------+ Usage Parameters
---------+ Bluetooth & Wireless Devices
---------+ Infrared Communications
------+ Logical Tampering Protection
---------+ Technology Asset Inspections
------+ Bring Your Own Device (BYOD) Usage
------+ Prohibited Equipment & Services
------+ Roots of Trust Protection
------+ Telecommunications Equipment
------+ Video Teleconference (VTC) Security
------+ Voice Over Internet Protocol (VoIP) Security
------+ Microphones & Web Cameras
------+ Multi-Function Devices (MFD)
------+ Travel-Only Devices
------+ Re-Imaging Devices After Travel
------+ System Administrative Processes
------+ Jump Server
------+ Database Administrative Processes
---------+ Database Management System (DBMS)
------+ Radio Frequency Identification (RFID) Security
---------+ Contactless Access Control Systems
------+ Decommissioning
------+ Asset Categorization
---------+ Categorize Artificial Intelligence (AI)-Related Technologies
---------+ High-Risk Asset Categorization
---------+ Asset Attributes
------+ Automated Network Asset Discovery
---+ Business Continuity & Disaster Recovery
------+ Business Continuity Management System (BCMS)
---------+ Coordinate with Related Plans
---------+ Coordinate With External Service Providers
---------+ Transfer to Alternate Processing / Storage Site
---------+ Recovery Time / Point Objectives (RTO / RPO)
---------+ Recovery Operations Criteria
---------+ Recovery Operations Communications
---------+ Business Continuity & Disaster Recovery (BC/DR) Plans
------+ Identify Critical Assets
---------+ Resume All Missions & Business Functions
---------+ Continue Essential Mission & Business Functions
---------+ Resume Essential Missions & Business Functions
---------+ Data Storage Location Reviews
------+ Contingency Training
---------+ Simulated Events
---------+ Automated Training Environments
------+ Contingency Plan Testing & Exercises
---------+ Coordinated Testing with Related Plans
---------+ Alternate Storage & Processing Sites
------+ Contingency Plan Root Cause Analysis (RCA) & Lessons Learned
------+ Ongoing Contingency Planning
---------+ Contingency Planning Components
---------+ Contingency Plan Update Notifications
------+ Alternative Security Measures
------+ Alternate Storage Site
---------+ Separation from Primary Storage Site
---------+ Primary Storage Site Accessibility
------+ Alternate Processing Site
---------+ Separation from Primary Processing Site
---------+ Alternate Processing Site Accessibility
---------+ Alternate Site Priority of Service
---------+ Preparation for Use
---------+ Inability to Return to Primary Site
------+ Telecommunications Services Availability
---------+ Telecommunications Priority of Service Provisions
---------+ Separation of Primary / Alternate Providers
---------+ Provider Contingency Plan
---------+ Alternate Communications Channels
------+ Data Backups
---------+ Testing for Reliability & Integrity
---------+ Separate Storage for Critical Information
---------+ Recovery Images
---------+ Cryptographic Protection
---------+ Test Restoration Using Sampling
---------+ Transfer to Alternate Storage Site
---------+ Redundant Secondary System
---------+ Dual Authorization For Backup Media Destruction
---------+ Backup Access
---------+ Backup Modification and/or Destruction
------+ Technology Assets, Applications and/or Services (TAAS) Recovery & Reconstitution
---------+ Transaction Recovery
---------+ Failover Capability
---------+ Electronic Discovery (eDiscovery)
---------+ Restore Within Time Period
------+ Backup & Restoration Hardware Protection
---------+ Restoration Integrity Verification
------+ Isolated Recovery Environment
------+ Reserve Hardware
------+ AI & Autonomous Technologies Incidents
---+ Capacity & Performance Planning
------+ Capacity & Performance Management
------+ Resource Priority
------+ Capacity Planning
------+ Performance Monitoring
------+ Elastic Expansion
------+ Regional Delivery
---+ Change Management
------+ Change Management Program
------+ Configuration Change Control
---------+ Prohibition Of Changes
---------+ Test, Validate & Document Changes
---------+ Security, Compliance & Resilience Representative for Asset Lifecycle Changes
---------+ Automated Security Response
---------+ Cryptographic Management
------+ Security Impact Analysis for Changes
------+ Access Restriction For Change
---------+ Automated Access Enforcement / Auditing
---------+ Signed Components
---------+ Dual Authorization for Change
---------+ Permissions To Implement Changes
---------+ Library Privileges
------+ Stakeholder Notification of Changes
------+ Control Functionality Verification
---------+ Report Verification Results
------+ Emergency Changes
---------+ Documenting Emergency Changes
------+ Dual Approval For High-Impact Environments
---+ Cloud Security
------+ Cloud Services
---------+ Cloud Infrastructure Onboarding
---------+ Cloud Infrastructure Offboarding
------+ Cloud Security Architecture
------+ Cloud Infrastructure Security Subnet
------+ Application Programming Interface (API) Security
---------+ API Gateway
------+ Virtual Machine Images
------+ Multi-Tenant Environments
---------+ Customer Responsibility Matrix (CRM)
---------+ Multi-Tenant Event Logging Capabilities
---------+ Multi-Tenant Forensics Capabilities
---------+ Multi-Tenant Incident Response Capabilities
------+ Data Handling & Portability
------+ Standardized Virtualization Formats
------+ Geolocation Requirements for Processing, Storage and Service Locations
------+ Sensitive Data In Public Cloud Providers
------+ Cloud Access Security Broker (CASB)
------+ Side Channel Attack Prevention
------+ Hosted Assets, Applications & Services
---------+ Authorized Individuals For Hosted Assets, Applications & Services
---------+ Sensitive / Regulated Data On Hosted Assets, Applications & Services
------+ Prohibition On Unverified Hosted Assets, Applications & Services
------+ Software Defined Storage (SDS)
---+ Compliance
------+ Statutory, Regulatory & Contractual Compliance
---------+ Non-Compliance Oversight
---------+ Compliance Scope
---------+ Ability To Demonstrate Conformity
---------+ Conformity Assessment
---------+ Declaration of Conformity
---------+ Assessment Team Subject Matter Expertise
---------+ Designated Certifying Official
---------+ Conformity Attestations
------+ Security, Compliance & Resilience Controls Oversight
---------+ Internal Audit Function
---------+ Periodic Audits
---------+ Corrective Action
------+ Security, Compliance & Resilience Assessments
---------+ Independent Assessors
---------+ Functional Review Of Security, Compliance & Resilience Controls
---------+ Assessor Access
---------+ Assessment Methods
---------+ Assessment Rigor
---------+ Evidence Request List (ERL)
---------+ Evidence Sampling
------+ Audit Activities
------+ Legal Assessment of Investigative Inquires
---------+ Investigation Request Notifications
---------+ Investigation Access Restrictions
------+ Government Surveillance
------+ Grievances
---------+ Grievance Response
------+ Localized Representation
---------+ Representative Powers
------+ Control Reciprocity
------+ Control Inheritance
------+ Dual Use Technology
---------+ USML or CCL Identification
---------+ Export-Controlled Access Restrictions
---------+ Export Activities Documentation
------+ Statement of Applicability (SOA)
------+ Work Products
---------+ Defensible Evidence of Due Diligence
---------+ Defensible Evidence of Due Care
---+ Configuration Management
------+ Configuration Management Program
---------+ Assignment of Responsibility
------+ Secure Baseline Configurations
---------+ Reviews & Updates
---------+ Automated Central Management & Verification
---------+ Retention Of Previous Configurations
---------+ Development & Test Environment Configurations
---------+ Configure Technology Assets, Applications and/or Services (TAAS) for High-Risk Areas
---------+ Network Device Configuration File Synchronization
---------+ Approved Configuration Deviations
---------+ Respond To Unauthorized Changes
---------+ Baseline Tailoring
------+ Least Functionality
---------+ Periodic Review
---------+ Prevent Unauthorized Software Execution
---------+ Explicitly Allow / Deny Applications
---------+ Split Tunneling
------+ Software Usage Restrictions
---------+ Open Source Software
---------+ Unsupported Internet Browsers & Email Clients
------+ User-Installed Software
---------+ Unauthorized Installation Alerts
---------+ Restrict Roles Permitted To Install Software
------+ Configuration Enforcement
---------+ Integrity Assurance & Enforcement (IAE)
------+ Zero-Touch Provisioning (ZTP)
------+ Sensitive / Regulated Data Access Enforcement
---------+ Sensitive / Regulated Data Actions
---+ Continuous Monitoring
------+ Continuous Monitoring
---------+ Intrusion Detection & Prevention Systems (IDS & IPS)
---------+ Automated Tools for Real-Time Analysis
---------+ Inbound & Outbound Communications Traffic
---------+ System Generated Alerts
---------+ Wireless Network Monitoring
---------+ Host-Based Devices
---------+ File Integrity Monitoring (FIM)
---------+ Security Event Monitoring
---------+ Proxy Logging
---------+ Deactivated Account Activity
---------+ Automated Response to Suspicious Events
---------+ Automated Alerts
---------+ Alert Threshold Tuning
---------+ Individuals Posing Greater Risk
---------+ Privileged User Oversight
---------+ Analyze and Prioritize Monitoring Requirements
---------+ Real-Time Session Monitoring
------+ Centralized Collection of Security Event Logs
---------+ Correlate Monitoring Information
---------+ Central Review & Analysis
---------+ Integration of Scanning & Other Monitoring Information
---------+ Correlation with Physical Monitoring
---------+ Permitted Actions
---------+ Audit Level Adjustments
---------+ System-Wide / Time-Correlated Audit Trail
---------+ Changes by Authorized Individuals
---------+ Inventory of Technology Asset Event Logging
------+ Content of Event Logs
---------+ Sensitive Event Log Information
---------+ Audit Trails
---------+ Privileged Functions Logging
---------+ Verbosity Logging for Boundary Devices
---------+ Limit Personal Data (PD) In Audit Records
---------+ Centralized Management of Event Log Content
---------+ Database Logging
------+ Event Log Storage Capacity
------+ Response To Event Log Processing Failures
---------+ Real-Time Alerts of Event Logging Failure
---------+ Event Log Storage Capacity Alerting
------+ Monitoring Reporting
---------+ Query Parameter Audits of Personal Data (PD)
---------+ Trend Analysis Reporting
------+ Time Stamps
---------+ Synchronization With Authoritative Time Source
------+ Protection of Event Logs
---------+ Event Log Backup on Separate Physical Systems / Components
---------+ Access by Subset of Privileged Users
---------+ Cryptographic Protection of Event Log Information
---------+ Dual Authorization for Event Log Movement
------+ Non-Repudiation
---------+ Identity Binding
------+ Event Log Retention
------+ Monitoring For Information Disclosure
---------+ Analyze Traffic for Covert Exfiltration
---------+ Unauthorized Network Services
---------+ Monitoring for Indicators of Compromise (IOC)
------+ Session Audit
------+ Alternate Event Logging Capability
------+ Cross-Organizational Monitoring
---------+ Sharing of Event Logs
------+ Covert Channel Analysis
------+ Anomalous Behavior
---------+ Insider Threats
---------+ Third-Party Threats
---------+ Unauthorized Activities
---------+ Account Creation and Modification Logging
------+ Event Log Analysis & Triage
---------+ Event Log Review Escalation Matrix
------+ File Activity Monitoring (FAM)
------+ Write Once Read Many (WORM) Event Log Generation
---+ Cryptographic Protections
------+ Use of Cryptographic Controls
---------+ Alternate Physical Protection
---------+ Export-Controlled Cryptography
---------+ Pre/Post Transmission Handling
---------+ Conceal / Randomize Communications
---------+ Cryptographic Cipher Suites and Protocols Inventory
------+ Automated Authentication Through Cryptographic Modules
------+ Transmission Confidentiality
------+ Transmission Integrity
------+ Encrypting Data At Rest
---------+ Storage Media
---------+ Offline Storage
---------+ Database Encryption
------+ Non-Console Administrative Access
------+ Wireless Access Authentication & Encryption
------+ Public Key Infrastructure (PKI)
---------+ Availability
------+ Cryptographic Key Management
---------+ Symmetric Keys
---------+ Asymmetric Keys
---------+ Cryptographic Key Loss or Change
---------+ Control & Distribution of Cryptographic Keys
---------+ Assigned Owners
---------+ Third-Party Cryptographic Keys
---------+ External System Cryptographic Key Control
------+ Transmission of Cybersecurity & Data Protection Attributes
------+ Certificate Authorities
------+ Certificate Monitoring
------+ Cryptographic Hash
---+ Data Classification & Handling
------+ Data Protection
---------+ Data Stewardship
---------+ Sensitive / Regulated Data Protection
---------+ Sensitive / Regulated Media Records
---------+ Defining Access Authorizations for Sensitive / Regulated Data
------+ Data & Asset Classification
---------+ Highest Classification Level
------+ Media Access
---------+ Disclosure of Information
---------+ Masking Displayed Data
---------+ Controlled Release
------+ Media Marking
---------+ Automated Marking
------+ Cybersecurity & Data Protection Attributes
---------+ Dynamic Attribute Association
---------+ Attribute Value Changes By Authorized Individuals
---------+ Maintenance of Attribute Associations By System
---------+ Association of Attributes By Authorized Individuals
---------+ Attribute Displays for Output Devices
---------+ Data Subject Attribute Associations
---------+ Consistent Attribute Interpretation
---------+ Identity Association Techniques & Technologies
---------+ Attribute Reassignment
---------+ Attribute Configuration By Authorized Individuals
---------+ Audit Changes
------+ Media Storage
---------+ Physically Secure All Media
---------+ Sensitive Data Inventories
---------+ Periodic Scans for Sensitive / Regulated Data
---------+ Making Sensitive Data Unreadable In Storage
---------+ Storing Authentication Data
------+ Media Transportation
---------+ Custodians
---------+ Encrypting Data In Storage Media
------+ Physical Media Disposal
------+ System Media Sanitization
---------+ System Media Sanitization Documentation
---------+ Equipment Testing
---------+ Sanitization of Personal Data (PD)
---------+ First Time Use Sanitization
---------+ Dual Authorization for Sensitive Data Destruction
------+ Media Use
---------+ Limitations on Use
---------+ Prohibit Use Without Owner
------+ Data Reclassification
------+ Removable Media Security
------+ Use of External Technology Assets, Applications and/or Services (TAAS)
---------+ Limits of Authorized Use
---------+ Portable Storage Devices
---------+ Protecting Sensitive / Regulated Data on External Technology Assets, Applications and/or Services (TAAS)
---------+ Non-Organizationally Owned Technology Assets, Applications and/or Services (TAAS)
------+ Information Sharing
---------+ Information Search & Retrieval
---------+ Transfer Authorizations
---------+ Data Access Mapping
------+ Publicly Accessible Content
------+ Data Mining Protection
------+ Ad-Hoc Transfers
------+ Media & Data Retention
---------+ Minimize Sensitive / Regulated Data
---------+ Limit Sensitive / Regulated Data In Testing, Training & Research
---------+ Temporary Files Containing Personal Data (PD)
------+ Geographic Location of Data
------+ Archived Data Sets
------+ Information Disposal
------+ Data Quality Operations
---------+ Updating & Correcting Personal Data (PD)
---------+ Data Tags
---------+ Primary Source Personal Data (PD) Collection
------+ De-Identification (Anonymization)
---------+ De-Identify Dataset Upon Collection
---------+ Archiving
---------+ Release
---------+ Removal, Masking, Encryption, Hashing or Replacement of Direct Identifiers
---------+ Statistical Disclosure Control
---------+ Differential Data Privacy
---------+ Automated De-Identification of Sensitive Data
---------+ Motivated Intruder
---------+ Code Names
------+ Information Location
---------+ Automated Tools to Support Information Location
------+ Transfer of Sensitive and/or Regulated Data
---------+ Transfer Activity Limits
------+ Data Localization
------+ Data Rights Management (DRM)
---+ Embedded Technology
------+ Embedded Technology Security Program
------+ Internet of Things (IOT)
------+ Operational Technology (OT)
------+ Interface Security
------+ Embedded Technology Configuration Monitoring
------+ Prevent Alterations
------+ Embedded Technology Maintenance
------+ Resilience To Outages
------+ Power Level Monitoring
------+ Embedded Technology Reviews
------+ Message Queuing Telemetry Transport (MQTT) Security
------+ Restrict Communications
------+ Authorized Communications
------+ Operating Environment Certification
------+ Safety Assessment
------+ Certificate-Based Authentication
------+ Chip-To-Cloud Security
------+ Real-Time Operating System (RTOS) Security
------+ Safe Operations
---+ Endpoint Security
------+ Endpoint Device Management (EDM)
---------+ Unified Endpoint Device Management (UEDM)
------+ Endpoint Protection Measures
------+ Prohibit Installation Without Privileged Status
---------+ Software Installation Alerts
---------+ Governing Access Restriction for Change
------+ Malicious Code Protection (Anti-Malware)
---------+ Automatic Antimalware Signature Updates
---------+ Documented Protection Measures
---------+ Centralized Management of Antimalware Technologies
---------+ Heuristic / Nonsignature-Based Detection
---------+ Malware Protection Mechanism Testing
---------+ Evolving Malware Threats
---------+ Always On Protection
------+ Software Firewall
------+ Endpoint File Integrity Monitoring (FIM)
---------+ Integrity Checks
---------+ Endpoint Detection & Response (EDR)
---------+ Automated Notifications of Integrity Violations
---------+ Automated Response to Integrity Violations
---------+ Boot Process Integrity
---------+ Protection of Boot Firmware
---------+ Binary or Machine-Executable Code
---------+ Extended Detection & Response (XDR)
------+ Host Intrusion Detection and Prevention Systems (HIDS / HIPS)
------+ Phishing & Spam Protection
---------+ Central Management
---------+ Automatic Spam and Phishing Protection Updates
------+ Trusted Path
------+ Mobile Code
------+ Thin Nodes
------+ Port & Input / Output (I/O) Device Access
------+ Sensor Capability
---------+ Authorized Use
---------+ Notice of Collection
---------+ Collection Minimization
---------+ Sensor Delivery Verification
------+ Collaborative Computing Devices
---------+ Disabling / Removal In Secure Work Areas
---------+ Explicitly Indicate Current Participants
---------+ Participant Identity Verification
---------+ Participant Connection Management
---------+ Malicious Link & File Protections
---------+ Explicit Indication Of Use
------+ Hypervisor Access
------+ Restrict Access To Security Functions
---------+ Host-Based Security Function Isolation
---+ Human Resources Security
------+ Human Resources Security Management
---------+ Onboarding, Transferring & Offboarding Personnel
------+ Position Categorization
---------+ Users With Elevated Privileges
---------+ Probationary Periods
------+ Defined Roles & Responsibilities
---------+ User Awareness
---------+ Competency Requirements for Security-Related Positions
------+ Personnel Screening
---------+ Roles With Special Protection Measures
---------+ Formal Indoctrination
---------+ Citizenship Requirements
---------+ Citizenship Identification
------+ Terms of Employment
---------+ Rules of Behavior
---------+ Social Media & Social Networking Restrictions
---------+ Technology Use Restrictions
---------+ Use of Critical Technologies
---------+ Use of Mobile Devices
---------+ Security-Minded Dress Code
---------+ Policy Familiarization & Acknowledgement
------+ Access Agreements
---------+ Confidentiality Agreements
---------+ Post-Employment Requirements Awareness
------+ Personnel Sanctions
---------+ Workplace Investigations
---------+ Updating Disciplinary Processes
---------+ Preventative Access Restriction
------+ Personnel Transfer
------+ Personnel Termination
---------+ Asset Collection
---------+ High-Risk Terminations
---------+ Post-Employment Requirements Notification
---------+ Automated Employment Status Notifications
------+ Third-Party Personnel
------+ Separation of Duties (SoD)
------+ Incompatible Roles
---------+ Two-Person Rule
------+ Identify Critical Skills & Gaps
---------+ Remediate Identified Skills Deficiencies
---------+ Identify Vital Security, Compliance & Resilience Staff
---------+ Establish Redundancy for Vital Security, Compliance & Resilience Staff
---------+ Perform Succession Planning
------+ Identifying Authorized Work Locations
---------+ Communicating Authorized Work Locations
------+ Reporting Suspicious Activities
---+ Identification & Authentication
------+ Identity & Access Management (IAM)
---------+ Retain Access Records
---------+ Authenticate, Authorize and Audit (AAA)
---------+ User & Service Account Inventories
------+ Identification & Authentication for Organizational Users
---------+ Group Authentication
---------+ Replay-Resistant Authentication
---------+ Acceptance of PIV Credentials
---------+ Out-of-Band Authentication (OOBA)
------+ Identification & Authentication for Non-Organizational Users
---------+ Acceptance of PIV Credentials from Other Organizations
---------+ Acceptance of Third-Party Credentials
---------+ Use of FICAM-Issued Profiles
---------+ Disassociability
---------+ Acceptance of External Authenticators
------+ Identification & Authentication for Devices
---------+ Device Attestation
---------+ Device Authorization Enforcement
------+ Identification & Authentication for Third-Party Technology Assets, Applications and/or Services (TAAS)
---------+ Sharing Identification & Authentication Information
---------+ Privileged Access by Non-Organizational Users
------+ Multi-Factor Authentication (MFA)
---------+ Network Access to Privileged Accounts
---------+ Network Access to Non-Privileged Accounts
---------+ Local Access to Privileged Accounts
---------+ Out-of-Band Multi-Factor Authentication
---------+ Alternative Multi-Factor Authentication
------+ User Provisioning & De-Provisioning
---------+ Change of Roles & Duties
---------+ Termination of Employment
------+ Role-Based Access Control (RBAC)
------+ Identifier Management (User Names)
---------+ User Identity (ID) Management
---------+ Identity User Status
---------+ Dynamic Management
---------+ Cross-Organization Management
---------+ Privileged Account Identifiers
---------+ Pairwise Pseudonymous Identifiers (PPID)
------+ Authenticator Management
---------+ Password-Based Authentication
---------+ PKI-Based Authentication
---------+ In-Person or Trusted Third-Party Registration
---------+ Automated Support For Password Strength
---------+ Protection of Authenticators
---------+ No Embedded Unencrypted Static Authenticators
---------+ Hardware Token-Based Authentication
---------+ Default Authenticators
---------+ Multiple System Accounts
---------+ Expiration of Cached Authenticators
---------+ Password Managers
---------+ Biometric Authentication
---------+ Events Requiring Authenticator Change
---------+ Passkeys
------+ Authenticator Feedback
------+ Cryptographic Module Authentication
---------+ Hardware Security Modules (HSM)
------+ Adaptive Identification & Authentication
---------+ Single Sign-On (SSO) Transparent Authentication
---------+ Federated Credential Management
---------+ Continuous Authentication
------+ Re-Authentication
------+ Account Management
---------+ Automated System Account Management (Directory Services)
---------+ Removal of Temporary / Emergency Accounts
---------+ Disable Inactive Accounts
---------+ Automated Audit Actions
---------+ Restrictions on Shared Groups / Accounts
---------+ Account Disabling for High Risk Individuals
---------+ System Account Reviews
---------+ Usage Conditions
---------+ Emergency Accounts
------+ Privileged Account Management (PAM)
---------+ Privileged Account Inventories
---------+ Privileged Account Separation
---------+ Privileged Command Execution
---------+ Dedicated Privileged Account
---------+ Manual Override
------+ Periodic Review of Account Privileges
------+ User Responsibilities for Account Management
------+ Credential Sharing
------+ Access Enforcement
---------+ Access To Sensitive / Regulated Data
---------+ Database Access
---------+ Use of Privileged Utility Programs
---------+ Dedicated Administrative Machines
---------+ Dual Authorization for Privileged Commands
---------+ Revocation of Access Authorizations
---------+ Authorized System Accounts
------+ Least Privilege
---------+ Authorize Access to Security Functions
---------+ Non-Privileged Access for Non-Security Functions
---------+ Management Approval For Privileged Accounts
---------+ Auditing Use of Privileged Functions
---------+ Prohibit Non-Privileged Users from Executing Privileged Functions
---------+ Network Access to Privileged Commands
---------+ Privilege Levels for Code Execution
------+ Account Lockout
------+ Concurrent Session Control
------+ Session Lock
---------+ Pattern-Hiding Displays
------+ Session Termination
---------+ User-Initiated Logouts / Message Displays
------+ Permitted Actions Without Identification or Authorization
------+ Reference Monitor
------+ Identity Proofing (Identity Verification)
---------+ Management Approval For New or Changed Accounts
---------+ Identity Evidence
---------+ Identity Evidence Validation & Verification
---------+ In-Person Validation & Verification
---------+ Address Confirmation
------+ Attribute-Based Access Control (ABAC)
---------+ Real-Time Access Decisions
---------+ Access Profile Rules
------+ Mutual Authentication (MA)
---+ Incident Response
------+ Incident Response Operations
------+ Incident Handling
---------+ Automated Incident Handling Processes
---------+ Insider Threat Response Capability
---------+ Dynamic Reconfiguration
---------+ Incident Classification & Prioritization
---------+ Correlation with External Organizations
---------+ Automatic Disabling of Technology Assets, Applications and/or Services (TAAS)
------+ Indicators of Compromise (IOC)
------+ Incident Response Plan (IRP)
---------+ Data Breach
---------+ IRP Update
---------+ Continuous Incident Response Improvements
------+ Incident Response Training
---------+ Simulated Incidents
---------+ Automated Incident Response Training Environments
------+ Incident Response Testing
---------+ Coordination with Related Plans
------+ Integrated Security Incident Response Team (ISIRT)
------+ Chain of Custody & Forensics
---------+ Licensed Forensic Investigators
------+ Situational Awareness For Incidents
---------+ Automated Tracking, Data Collection & Analysis
---------+ Recurring Incident Analysis
---------+ Incident Tracking Repository
---------+ Incident Pattern Analysis
------+ Incident Stakeholder Reporting
---------+ Automated Reporting
---------+ Cyber Incident Reporting for Sensitive / Regulated Data
---------+ Vulnerabilities Related To Incidents
---------+ Supply Chain Coordination
---------+ Serious Incident Reporting
------+ Incident Reporting Assistance
---------+ Automation Support of Availability of Information / Support
---------+ Coordination With External Providers
------+ Sensitive / Regulated Data Spill Response
---------+ Sensitive / Regulated Data Spill Responsible Personnel
---------+ Sensitive / Regulated Data Spill Training
---------+ Post-Sensitive / Regulated Data Spill Operations
---------+ Sensitive / Regulated Data Exposure to Unauthorized Personnel
------+ Root Cause Analysis (RCA) & Lessons Learned
------+ Regulatory & Law Enforcement Contacts
------+ Detonation Chambers (Sandboxes)
------+ Public Relations & Reputation Repair
---+ Information Assurance
------+ Information Assurance (IA) Operations
---------+ Assessment Boundaries
------+ Assessments
---------+ Assessor Independence
---------+ Specialized Assessments
---------+ Third-Party Assessment Reciprocity
---------+ Security Assessment Report (SAR)
------+ Applied Security, Compliance and Resilience Controls Documentation
---------+ Plan / Coordinate with Other Organizational Entities
---------+ Adequate Security for Sensitive / Regulated Data In Support of Contracts
------+ Threat Analysis & Flaw Remediation During Development
------+ Capabilities Deficiency Tracking
---------+ Deficiency Tracking Automation
------+ Technical Verification
------+ Security Authorization
---+ Maintenance
------+ Maintenance Operations
------+ Controlled Maintenance
---------+ Automated Maintenance Activities
------+ Timely Maintenance
---------+ Preventative Maintenance
---------+ Predictive Maintenance
---------+ Automated Support For Predictive Maintenance
------+ Maintenance Tools
---------+ Inspect Tools
---------+ Inspect Media
---------+ Prevent Unauthorized Removal
---------+ Restrict Tool Usage
------+ Remote Maintenance
---------+ Auditing Remote Maintenance
---------+ Remote Maintenance Notifications
---------+ Remote Maintenance Cryptographic Protection
---------+ Remote Maintenance Disconnect Verification
---------+ Remote Maintenance Pre-Approval
---------+ Remote Maintenance Comparable Security & Sanitization
---------+ Separation of Maintenance Sessions
------+ Authorized Maintenance Personnel
---------+ Maintenance Personnel Without Appropriate Access
---------+ Non-System Related Maintenance
------+ Maintain Configuration Control During Maintenance
------+ Field Maintenance
------+ Off-Site Maintenance
------+ Maintenance Validation
------+ Maintenance Monitoring
---+ Mobile Device Management
------+ Centralized Management Of Mobile Devices
------+ Access Control For Mobile Devices
------+ Full Device & Container-Based Encryption
------+ Mobile Device Tampering
------+ Remote Purging
------+ Personally-Owned Mobile Devices
------+ Organization-Owned Mobile Devices
------+ Mobile Device Data Retention Limitations
------+ Mobile Device Geofencing
------+ Separate Mobile Device Profiles
------+ Restricting Access To Authorized Technology Assets, Applications and/or Services (TAAS)
---+ Network Security
------+ Network Security Controls (NSC)
---------+ Zero Trust Architecture (ZTA)
------+ Layered Network Defenses
---------+ Denial of Service (DoS) Protection
---------+ Guest Networks
---------+ Cross Domain Solution (CDS)
------+ Boundary Protection
---------+ Limit Network Connections
---------+ External Telecommunications Services
---------+ Prevent Discovery of Internal Information
---------+ Personal Data (PD)
---------+ Prevent Unauthorized Exfiltration
---------+ Dynamic Isolation & Segregation (Sandboxing)
---------+ Isolation of System Components
---------+ Separate Subnet for Connecting to Different Security Domains
------+ Data Flow Enforcement – Access Control Lists (ACLs)
---------+ Deny Traffic by Default & Allow Traffic by Exception
---------+ Object Security Attributes
---------+ Content Check for Encrypted Data
---------+ Embedded Data Types
---------+ Metadata
---------+ Human Reviews
---------+ Policy Decision Point (PDP)
---------+ Data Type Identifiers
---------+ Decomposition Into Policy-Related Subcomponents
---------+ Detection of Unsanctioned Information
---------+ Approved Solutions
---------+ Cross Domain Authentication
---------+ Metadata Validation
---------+ Application Proxy
------+ Interconnection Security Agreements (ISAs)
---------+ External System Connections
---------+ Internal System Connections
------+ Network Segmentation (macrosegementation)
---------+ Security Management Subnets
---------+ Virtual Local Area Network (VLAN) Separation
---------+ Sensitive / Regulated Data Enclave (Secure Zone)
---------+ Segregation From Enterprise Services
---------+ Direct Internet Access Restrictions
---------+ Microsegmentation
---------+ Software Defined Networking (SDN)
------+ Network Connection Termination
------+ Network Intrusion Detection / Prevention Systems (NIDS / NIPS)
---------+ DMZ Networks
---------+ Wireless Intrusion Detection / Prevention Systems (WIDS / WIPS) Deployment
---------+ Host Containment
---------+ Resource Containment
------+ Session Integrity
---------+ Invalidate Session Identifiers at Logout
---------+ Unique System-Generated Session Identifiers
------+ Domain Name Service (DNS) Resolution
---------+ Architecture & Provisioning for Name / Address Resolution Service
---------+ Secure Name / Address Resolution Service (Recursive or Caching Resolver)
---------+ Sender Policy Framework (SPF)
---------+ Domain Registrar Security
------+ Out-of-Band Channels
------+ Safeguarding Data Over Open Networks
---------+ Wireless Link Protection
---------+ End-User Messaging Technologies
------+ Electronic Messaging
------+ Remote Access
---------+ Automated Monitoring & Control
---------+ Protection of Confidentiality / Integrity Using Encryption
---------+ Managed Access Control Points
---------+ Remote Privileged Commands & Sensitive Data Access
---------+ Work From Anywhere (WFA) - Telecommuting Security
---------+ Third-Party Remote Access Governance
---------+ Endpoint Security Validation
---------+ Expeditious Disconnect / Disable Capability
------+ Wireless Networking
---------+ Authentication & Encryption
---------+ Disable Wireless Networking
---------+ Restrict Configuration By Users
---------+ Wireless Boundaries
---------+ Rogue Wireless Detection
------+ Intranets
------+ Data Loss Prevention (DLP)
------+ DNS & Content Filtering
---------+ Route Internal Traffic to Proxy Servers
---------+ Visibility of Encrypted Communications
---------+ Route Privileged Network Access
---------+ Protocol Compliance Enforcement
---------+ Domain Name Verification
---------+ Internet Address Denylisting
---------+ Bandwidth Control
---------+ Authenticated Proxy
---------+ Certificate Denylisting
------+ Content Disarm and Reconstruction (CDR)
------+ Email Content Protections
---------+ Email Domain Reputation Protections
---------+ Sender Denylisting
---------+ Authenticated Received Chain (ARC)
---------+ Domain-Based Message Authentication Reporting and Conformance (DMARC)
---------+ User Digital Signatures for Outgoing Email
---------+ Encryption for Outgoing Email
---------+ Adaptive Email Protections
---------+ Email Labeling
---------+ User Threat Reporting
---+ Physical & Environmental Security
------+ Physical & Environmental Protections
---------+ Physical Security Plan (PSP)
---------+ Zone-Based Physical Security
------+ Physical Access Authorizations
---------+ Role-Based Physical Access
---------+ Dual Authorization for Physical Access
------+ Physical Access Control
---------+ Controlled Ingress & Egress Points
---------+ Lockable Physical Casings
---------+ Physical Access Logs
---------+ Access To Critical Systems
------+ Physical Security of Offices, Rooms & Facilities
---------+ Working in Secure Areas
---------+ Searches
---------+ Temporary Storage
------+ Monitoring Physical Access
---------+ Intrusion Alarms / Surveillance Equipment
---------+ Monitoring Physical Access To Critical Systems
------+ Visitor Control
---------+ Distinguish Visitors from On-Site Personnel
---------+ Identification Requirement
---------+ Restrict Unescorted Access
---------+ Automated Records Management & Review
---------+ Minimize Visitor Personal Data (PD)
---------+ Visitor Access Revocation
------+ Supporting Utilities
---------+ Automatic Voltage Controls
---------+ Emergency Shutoff
---------+ Emergency Power
---------+ Emergency Lighting
---------+ Water Damage Protection
---------+ Automation Support for Water Damage Protection
---------+ Redundant Cabling
------+ Fire Protection
---------+ Fire Detection Devices
---------+ Fire Suppression Devices
---------+ Automatic Fire Suppression
------+ Temperature & Humidity Controls
---------+ Monitoring with Alarms / Notifications
------+ Delivery & Removal
------+ Alternate Work Site
------+ Equipment Siting & Protection
---------+ Transmission Medium Security
---------+ Access Control for Output Devices
------+ Information Leakage Due To Electromagnetic Signals Emanations
------+ Asset Monitoring and Tracking
------+ Electromagnetic Pulse (EMP) Protection
------+ Component Marking
------+ Proximity Sensor
------+ On-Site Client Segregation
------+ Physical Access Device Inventories
---+ Data Privacy
------+ Data Privacy Program
---------+ Chief Privacy Officer (CPO)
---------+ Privacy Act Statements
---------+ Dissemination of Data Privacy Program Information
---------+ Data Protection Officer (DPO)
---------+ Binding Corporate Rules (BCR)
---------+ Security of Personal Data (PD)
---------+ Limiting Personal Data (PD) Disclosures
---------+ Data Fiduciary
---------+ Personal Data (PD) Process Manager
---------+ Financial Incentives For Personal Data (PD)
---------+ Reasonable Data Privacy Practices
------+ Data Privacy Notice
---------+ Purpose Specification
---------+ Automated Data Management Processes
---------+ Computer Matching Agreements (CMA)
---------+ System of Records Notice (SORN)
---------+ System of Records Notice (SORN) Review Process
---------+ Privacy Act Exemptions
---------+ Real-Time or Layered Notice
---------+ Purpose Compatibility
---------+ Privacy Notice Formatting
---------+ Symmetry In Choice
---------+ Choice Architecture
---------+ Choice Architecture Testing
---------+ Notice of Right To Limit
---------+ Alternative Means To Deliver Privacy Notice
------+ Choice & Consent
---------+ Tailored Consent
---------+ Just-In-Time Notice & Updated Consent
---------+ Prohibition of Selling, Processing and/or Sharing Personal Data (PD)
---------+ Revoke Consent
---------+ Product or Service Delivery Restrictions
---------+ Authorized Agent
---------+ Active Participation By Data Subjects
---------+ Global Privacy Control (GPC)
---------+ Continued Use of Personal Data (PD)
---------+ Cease Processing, Storing and/or Sharing Personal Data (PD)
---------+ Communicating Processing Changes
---------+ Data Subject Opt-In Consent
---------+ Parent or Guardian Opt-In Consent For Minors
------+ Restrict Collection To Identified Purpose
---------+ Authority To Collect, Process, Store & Share Personal Data (PD)
---------+ Primary Sources
---------+ Identifiable Image Collection
---------+ Acquired Personal Data (PD)
---------+ Validate Collected Personal Data (PD)
---------+ Re-Validate Collected Personal Data (PD)
---------+ Personal Data (PD) Collection Methods
------+ Personal Data (PD) Retention & Disposal
---------+ Internal Use of Personal Data (PD) For Testing, Training and Research
---------+ Personal Data (PD) Accuracy & Integrity
---------+ Data Masking
---------+ Usage Restrictions of Personal Data (PD)
---------+ Inventory of Personal Data (PD)
---------+ Personal Data (PD) Inventory Automation Support
---------+ Personal Data (PD) Categories
---------+ Personal Data (PD) Formats
------+ Data Subject Empowerment
---------+ Correcting Inaccurate Personal Data (PD)
---------+ Notice of Correction or Processing Change
---------+ Appeal Adverse Decision
---------+ User Feedback Management
---------+ Right to Erasure
---------+ Data Portability
---------+ Personal Data (PD) Exports
---------+ Data Subject Authentication
------+ Information Sharing With Third Parties
---------+ Data Privacy Requirements for Contractors & Service Providers
---------+ Joint Processing of Personal Data (PD)
---------+ Obligation To Inform Third-Parties
---------+ Reject Unauthenticated or Untrustworthy Disclosure Requests
---------+ Justification To Reject Disclosure Requests
------+ Personal Data (PD) Control Testing, Training & Monitoring
------+ Personal Data (PD) Lineage
------+ Data Quality Management
---------+ Data Quality Automation
---------+ Data Analytics Bias
------+ Data Tagging
------+ Updating Personal Data (PD) Process
---------+ Enabling Data Subjects To Update Personal Data (PD)
------+ Data Management Board
------+ Documenting Data Processing Activities
---------+ Accounting of Disclosures
---------+ Notification of Disclosure Request To Data Subject
------+ Register As A Data Controller and/or Data Processor
------+ Potential Human Rights Abuses
------+ Data Subject Communications
---------+ Conspicuous Link To Data Privacy Notice
---------+ Notice of Financial Incentive
---------+ Data Subject Communications Documentation
---------+ Data Subject Communications Metrics
---------+ Data Subject Communications Disclosure
------+ Data Controller Communications
------+ Automated Decision-Making Technology (ADMT) For Data Subject Actions
---------+ Automated Decision-Making Technology (ADMT) Use Notification
---------+ Automated Decision-Making Technology (ADMT) Opt-Out Consent
---------+ Automated Decision-Making Technology (ADMT) Transparency
------+ Data Brokers
------+ Notice of Right To Opt-Out
---------+ Opt-Out Links
---------+ Alternative Out-Out Link
---+ Project & Resource Management
------+ Security, Compliance & Resilience Protection Portfolio Management
---------+ Strategic Plan & Objectives
---------+ Targeted Capability Maturity Levels
------+ Security, Compliance & Resilience Resource Management
---------+ Prioritization To Address Evolving Risks & Threats
------+ Allocation of Resources
------+ Security, Compliance & Resilience In Project Management
------+ Security, Compliance & Resilience Requirements Definition
------+ Business Process Definition
------+ Secure Development Life Cycle (SDLC) Management
------+ Manage Organizational Knowledge
---+ Risk Management
------+ Risk Management Program
---------+ Risk Framing
---------+ Risk Management Resourcing
---------+ Risk Tolerance
---------+ Risk Threshold
---------+ Risk Appetite
------+ Risk-Based Security Categorization
---------+ Impact-Level Prioritization
------+ Risk Identification
---------+ Risk Catalog
------+ Risk Assessment
---------+ Risk Register
---------+ Risk Assessment Methodology
---------+ Instances Requiring A Risk Assessment
---------+ Risk Assessment Stakeholder Involvement
------+ Risk Ranking
------+ Risk Remediation
---------+ Risk Response
---------+ Compensating Countermeasures
---------+ Risk Treatment Options
---------+ Risk Treatment Plan (RTP)
------+ Risk Assessment Update
------+ Business Impact Analysis (BIA)
------+ Supply Chain Risk Management (SCRM) Plan
---------+ Supply Chain Risk Assessment
---------+ AI & Autonomous Technologies Supply Chain Impacts
------+ Data Protection Impact Assessment (DPIA)
------+ Risk Monitoring
------+ Risk Culture
------+ Executive Leadership Approval For Managing Material Risk
---------+ Documented Alternatives
---------+ Documented Justification For Material Risk Management Decisions
---+ Secure Engineering & Architecture
------+ Secure Engineering Principles
---------+ Centralized Management of Security, Compliance & Resilience Controls
---------+ Achieving Resilience Requirements
---------+ Resilience Capabilities
------+ Alignment With Enterprise Architecture
---------+ Standardized Terminology
---------+ Outsourcing Non-Essential Functions or Services
---------+ Technical Debt Reviews
------+ Defense-In-Depth (DiD) Architecture
---------+ System Partitioning
---------+ Application Partitioning
------+ Process Isolation
---------+ Security Function Isolation
---------+ Hardware Separation
---------+ Thread Separation
---------+ System Privileges Isolation
------+ Information In Shared Resources
------+ Prevent Program Execution
------+ Predictable Failure Analysis
---------+ Technology Lifecycle Management
---------+ Fail Secure
---------+ Fail Safe
------+ Non-Persistence
---------+ Refresh from Trusted Sources
------+ Information Output Filtering
---------+ Limit Personal Data (PD) Dissemination
------+ Memory Protection
------+ Honeypots
------+ Honeyclients
------+ Heterogeneity
---------+ Virtualization Techniques
------+ Concealment & Misdirection
---------+ Randomness
---------+ Change Processing & Storage Locations
------+ Distributed Processing & Storage
------+ Non-Modifiable Executable Programs
------+ Secure Log-On Procedures
------+ System Use Notification (Logon Banner)
---------+ Standardized Microsoft Windows Banner
---------+ Truncated Banner
------+ Previous Logon Notification
------+ Clock Synchronization
------+ Application Container
------+ Privileged Environments
---+ Security Operations
------+ Operations Security
---------+ Standardized Operating Procedures (SOP)
------+ Security Concept Of Operations (CONOPS)
------+ Service Delivery (Business Process Support)
------+ Security Operations Center (SOC)
------+ Secure Practices Guidelines
------+ Security Orchestration, Automation, and Response (SOAR)
------+ Shadow Information Technology Detection
---+ Security Awareness & Training
------+ Security, Compliance & Resilience-Minded Workforce
---------+ Maintaining Workforce Development Relevancy
------+ Security, Compliance & Resilience Awareness Training
---------+ Simulated Cyber Attack Scenario Training
---------+ Social Engineering & Mining
------+ Role-Based Security, Compliance & Resilience Training
---------+ Practical Exercises
---------+ Suspicious Communications & Anomalous System Behavior
---------+ Sensitive / Regulated Data Storage, Handling & Processing
---------+ Vendor Security, Compliance & Resilience Training
---------+ Privileged Users
---------+ Cyber Threat Environment
---------+ Continuing Professional Education (CPE) - Security, Compliance & Resilience Personnel
---------+ Continuing Professional Education (CPE) - DevOps Personnel
---------+ Counterintelligence Training
------+ Security, Compliance & Resilience Training Records
------+ Security, Compliance & Resilience Knowledge Sharing
---+ Technology Development & Acquisition
------+ Technology Development & Acquisition
---------+ Product Management
---------+ Integrity Mechanisms for Software / Firmware Updates
---------+ Malware Testing Prior to Release
---------+ DevSecOps
------+ Minimum Viable Product (MVP) Security Requirements
---------+ Ports, Protocols & Services In Use
---------+ Information Assurance Enabled Products
---------+ Development Methods, Techniques & Processes
---------+ Pre-Established Secure Configurations
---------+ Identification & Justification of Ports, Protocols & Services
---------+ Insecure Ports, Protocols & Services
---------+ Security, Compliance & Resilience Representatives For Product Changes
---------+ Minimizing Attack Surfaces
---------+ Ongoing Product Security Support
---------+ Product Testing & Reviews
---------+ Disclosure of Vulnerabilities
---------+ Products With Digital Elements
---------+ Reporting Exploitable Vulnerabilities
---------+ Logging Syntax
------+ Commercial Off-The-Shelf (COTS) Security Solutions
---------+ Supplier Diversity
------+ Documentation Requirements
---------+ Functional Properties
---------+ Software Bill of Materials (SBOM)
------+ Developer Architecture & Design
---------+ Physical Diagnostic & Test Interfaces
---------+ Diagnostic & Test Interface Monitoring
------+ Secure Software Development Practices (SSDP)
---------+ Criticality Analysis During Development
---------+ Threat Modeling
---------+ Software Assurance Maturity Model (SAMM)
---------+ Supporting Toolchain
---------+ Software Design Review
---------+ Software Design Root Cause Analysis
------+ Secure Development Environments
------+ Separation of Development, Testing and Operational Environments
---------+ Secure Migration Practices
------+ Security, Compliance & Resilience Testing Throughout Development
---------+ Continuous Monitoring Plan
---------+ Static Code Analysis
---------+ Dynamic Code Analysis
---------+ Malformed Input Testing
---------+ Application Penetration Testing
---------+ Secure Settings By Default
---------+ Manual Code Review
------+ Use of Live Data
---------+ Test Data Integrity
------+ Product Tampering and Counterfeiting (PTC)
---------+ Anti-Counterfeit Training
---------+ Component Disposal
------+ Customized Development of Critical Components
------+ Developer Screening
------+ Developer Configuration Management
---------+ Software / Firmware Integrity Verification
---------+ Hardware Integrity Verification
------+ Developer Threat Analysis & Flaw Remediation
------+ Developer-Provided Training
------+ Unsupported Technology Assets, Applications and/or Services (TAAS)
---------+ Alternate Sources for Continued Support
------+ Input Data Validation
------+ Error Handling
------+ Access to Program Source Code
---------+ Software Release Integrity Verification
---------+ Archiving Software Releases
---------+ Software Escrow
---------+ Approved Code
------+ Product Conformity Governance
------+ Technical Documentation Artifacts
---------+ Product-Specific Risk Assessment Artifacts
---+ Third-Party Management
------+ Third-Party Management
---------+ Third-Party Inventories
------+ Third-Party Criticality Assessments
------+ Supply Chain Risk Management (SCRM)
---------+ Acquisition Strategies, Tools & Methods
---------+ Limit Potential Harm
---------+ Processes To Address Weaknesses or Deficiencies
---------+ Adequate Supply
------+ Third-Party Services
---------+ Third-Party Risk Assessments & Approvals
---------+ External Connectivity Requirements - Identification of Ports, Protocols & Services
---------+ Conflict of Interests
---------+ Third-Party Processing, Storage and Service Locations
------+ Third-Party Contract Requirements
---------+ Security Compromise Notification Agreements
---------+ Contract Flow-Down Requirements
---------+ Third-Party Authentication Practices
---------+ Responsible, Accountable, Supportive, Consulted & Informed (RASCI) Matrix
---------+ Third-Party Scope Review
---------+ First-Party Declaration (1PD)
---------+ Break Clauses
---------+ Third-Party Attestation (3PA)
------+ Third-Party Personnel Security
------+ Monitoring for Third-Party Information Disclosure
------+ Review of Third-Party Services
------+ Third-Party Deficiency Remediation
------+ Managing Changes To Third-Party Services
------+ Third-Party Incident Response & Recovery Capabilities
------+ Foreign Ownership, Control or Influence (FOCI)
---------+ Ownership Change Monitoring
---------+ Ownership Change Provisions
---+ Threat Management
------+ Threat Intelligence Program
------+ Indicators of Exposure (IOE)
------+ Threat Intelligence Feeds
---------+ Threat Intelligence Reporting
------+ Insider Threat Program
------+ Insider Threat Awareness
------+ Vulnerability Disclosure Program (VDP)
---------+ Security Disclosure Contact Information
------+ Threat Hunting
------+ Tainting
------+ Threat Catalog
------+ Threat Analysis
------+ Behavioral Baselining
---+ Vulnerability & Patch Management
------+ Vulnerability & Patch Management Program (VPMP)
---------+ Attack Surface Scope
------+ Vulnerability Remediation Process
------+ Vulnerability Ranking
---------+ Vulnerability Exploitation Analysis
------+ Continuous Vulnerability Remediation Activities
---------+ Stable Versions
---------+ Flaw Remediation with Personal Data (PD)
---------+ Deferred Patching Decisions
------+ Software & Firmware Patching
---------+ Centralized Management of Flaw Remediation Processes
---------+ Automated Remediation Status
---------+ Time To Remediate / Benchmarks For Corrective Action
---------+ Automated Software & Firmware Updates
---------+ Removal of Previous Versions
---------+ Pre-Deployment Patch Testing
---------+ Out-of-Cycle Patching
---------+ Software Patch Integrity
------+ Vulnerability Scanning
---------+ Update Tool Capability
---------+ Breadth / Depth of Coverage
---------+ Privileged Access
---------+ Trend Analysis
---------+ Review Historical Event logs
---------+ External Vulnerability Assessment Scans
---------+ Internal Vulnerability Assessment Scans
---------+ Acceptable Discoverable Information
---------+ Correlate Scanning Information
------+ Penetration Testing
---------+ Independent Penetration Agent or Team
------+ Technical Surveillance Countermeasures Security
------+ Reviewing Vulnerability Scanner Usage
------+ Red Team Exercises
---+ Web Security
------+ Web Security
---------+ Unauthorized Code
------+ Use of Demilitarized Zones (DMZ)
------+ Web Application Firewall (WAF)
------+ Client-Facing Web Services
------+ Cookie Management
------+ Strong Customer Authentication (SCA)
------+ Web Security Standard
------+ Web Application Framework
------+ Validation & Sanitization
------+ Secure Web Traffic
------+ Output Encoding
------+ Web Browser Security
------+ Website Change Detection
------+ Publicly Accessible Content Reviews
---+ Access Control
------+ Inability to maintain individual accountability
------+ Improper assignment of privileged functions
------+ Privilege escalation
------+ Unauthorized access
---+ Asset Management
------+ Lost, damaged or stolen asset(s)
------+ Loss of integrity through unauthorized changes
------+ Emergent properties and/or unintended consequences
---+ Business Continuity
------+ Business interruption
------+ Data loss / corruption
------+ Reduction in productivity
------+ Information loss / corruption or system compromise due to technical attack
------+ Information loss / corruption or system compromise due to non‐technical attack
---+ Exposure
------+ Loss of revenue
------+ Cancelled contract
------+ Diminished competitive advantage
------+ Diminished reputation
------+ Fines and judgements
------+ Unmitigated vulnerabilities
------+ System compromise
---+ Governance
------+ Inability to support business processes
------+ Incorrect controls scoping
------+ Lack of roles & responsibilities
------+ Inadequate internal practices
------+ Inadequate third-party practices
------+ Lack of oversight of internal controls
------+ Lack of oversight of third-party controls
------+ Illegal content or abusive action
---+ Incident Response
------+ Inability to investigate / prosecute incidents
------+ Improper response to incidents
------+ Ineffective remediation actions
------+ Expense associated with managing a loss event
---+ Situational Awareness
------+ Inability to maintain situational awareness
------+ Lack of a security-minded workforce
---+ Supply Chain
------+ Third-party cybersecurity exposure
------+ Third-party physical security exposure
------+ Third-party supply chain relationships, visibility and controls
------+ Third-party compliance / legal exposure
------+ Use of product / service
------+ Reliance on the third-party

Impressum German English