AC – Access Control
1. Authorized users are identified
3.1.1[a] – under 3.1.1: Limit system access to authorized users, processes acting on behalf of authorized users, and devices (including other systems).
2. Processes acting on behalf of authorized users are identified
3.1.1[b] – under 3.1.1: Limit system access to authorized users, processes acting on behalf of authorized users, and devices (including other systems).
3. Devices (and other systems) authorized to connect to the system are identified
3.1.1[c] – under 3.1.1: Limit system access to authorized users, processes acting on behalf of authorized users, and devices (including other systems).
4. System access is limited to authorized users
3.1.1[d] – under 3.1.1: Limit system access to authorized users, processes acting on behalf of authorized users, and devices (including other systems).
5. System access is limited to processes acting on behalf of authorized users
3.1.1[e] – under 3.1.1: Limit system access to authorized users, processes acting on behalf of authorized users, and devices (including other systems).
6. System access is limited to authorized devices (including other systems)
3.1.1[f] – under 3.1.1: Limit system access to authorized users, processes acting on behalf of authorized users, and devices (including other systems).
7. The types of transactions and functions that authorized users are permitted to execute are defined
3.1.2[a] – under 3.1.2: Limit system access to the types of transactions and functions that authorized users are permitted to execute.
8. System access is limited to the defined types of transactions and functions for authorized users
3.1.2[b] – under 3.1.2: Limit system access to the types of transactions and functions that authorized users are permitted to execute.
9. Information flow control policies are defined
3.1.3[a] – under 3.1.3: Control the flow of CUI in accordance with approved authorizations.
10. Methods and enforcement mechanisms for controlling the flow of CUI are defined
3.1.3[b] – under 3.1.3: Control the flow of CUI in accordance with approved authorizations.
11. Designated sources and destinations (e.g., networks, individuals, and devices) for CUI within the system and between interconnected systems are identified
3.1.3[c] – under 3.1.3: Control the flow of CUI in accordance with approved authorizations.
12. Authorizations for controlling the flow of CUI are defined
3.1.3[d] – under 3.1.3: Control the flow of CUI in accordance with approved authorizations.
13. Approved authorizations for controlling the flow of CUI are enforced
3.1.3[e] – under 3.1.3: Control the flow of CUI in accordance with approved authorizations.
14. The duties of individuals requiring separation are defined
3.1.4[a] – under 3.1.4: Separate the duties of individuals to reduce the risk of malevolent activity without collusion.
15. Responsibilities for duties that require separation are assigned to separate individuals
3.1.4[b] – under 3.1.4: Separate the duties of individuals to reduce the risk of malevolent activity without collusion.
16. Access privileges that enable individuals to exercise the duties that require separation are granted to separate individuals
3.1.4[c] – under 3.1.4: Separate the duties of individuals to reduce the risk of malevolent activity without collusion.
17. Privileged accounts are identified
3.1.5[a] – under 3.1.5: Employ the principle of least privilege, including for specific security functions and privileged accounts.
18. Access to privileged accounts is authorized in accordance with the principle of least privilege
3.1.5[b] – under 3.1.5: Employ the principle of least privilege, including for specific security functions and privileged accounts.
19. Security functions are identified
3.1.5[c] – under 3.1.5: Employ the principle of least privilege, including for specific security functions and privileged accounts.
20. Access to security functions is authorized in accordance with the principle of least privilege
3.1.5[d] – under 3.1.5: Employ the principle of least privilege, including for specific security functions and privileged accounts.
21. Nonsecurity functions are identified
3.1.6[a] – under 3.1.6: Use non-privileged accounts or roles when accessing nonsecurity functions.
22. Users are required to use non-privileged accounts or roles when accessing nonsecurity functions
3.1.6[b] – under 3.1.6: Use non-privileged accounts or roles when accessing nonsecurity functions.
23. Privileged functions are defined
3.1.7[a] – under 3.1.7: Prevent non-privileged users from executing privileged functions and capture the execution of such functions in audit logs.
24. Non-privileged users are defined
3.1.7[b] – under 3.1.7: Prevent non-privileged users from executing privileged functions and capture the execution of such functions in audit logs.
25. Non-privileged users are prevented from executing privileged functions
3.1.7[c] – under 3.1.7: Prevent non-privileged users from executing privileged functions and capture the execution of such functions in audit logs.
26. The execution of privileged functions is captured in audit logs
3.1.7[d] – under 3.1.7: Prevent non-privileged users from executing privileged functions and capture the execution of such functions in audit logs.
27. The means of limiting unsuccessful logon attempts is defined
3.1.8[a] – under 3.1.8: Limit unsuccessful logon attempts.
28. The defined means of limiting unsuccessful logon attempts is implemented
3.1.8[b] – under 3.1.8: Limit unsuccessful logon attempts.
29. Privacy and security notices required by CUI-specified rules are identified, consistent, and associated with the specific CUI category
3.1.9[a] – under 3.1.9: Provide privacy and security notices consistent with applicable CUI rules.
30. Privacy and security notices are displayed
3.1.9[b] – under 3.1.9: Provide privacy and security notices consistent with applicable CUI rules.
31. The period of inactivity after which the system initiates a session lock is defined
3.1.10[a] – under 3.1.10: Use session lock with pattern-hiding displays to prevent access and viewing of data after a period of inactivity.
32. Access to the system and viewing of data is prevented by initiating a session lock after the defined period of inactivity
3.1.10[b] – under 3.1.10: Use session lock with pattern-hiding displays to prevent access and viewing of data after a period of inactivity.
33. Previously visible information is concealed via a pattern-hiding display after the defined period of inactivity
3.1.10[c] – under 3.1.10: Use session lock with pattern-hiding displays to prevent access and viewing of data after a period of inactivity.
34. Conditions requiring a user session to terminate are defined
3.1.11[a] – under 3.1.11: Terminate (automatically) a user session after a defined condition.
35. A user session is automatically terminated after any of the defin ed conditions occur
3.1.11[b] – under 3.1.11: Terminate (automatically) a user session after a defined condition.
36. Remote access sessions are permitted
3.1.12[a] – under 3.1.12: Monitor and control remote access sessions.
37. The types of permitted remote access are identified
3.1.12[b] – under 3.1.12: Monitor and control remote access sessions.
38. Remote access sessions are controlled
3.1.12[c] – under 3.1.12: Monitor and control remote access sessions.
39. Remote access sessions are monitored
3.1.12[d] – under 3.1.12: Monitor and control remote access sessions.
40. Cryptographic mechanisms to protect the confidentiality of remote access sessions are identified
3.1.13[a] – under 3.1.13: Employ cryptographic mechanisms to protect the confidentiality of remote access sessions.
41. Cryptographic mechanisms to protect the confidentiality of remote access sessions are implemented
3.1.13[b] – under 3.1.13: Employ cryptographic mechanisms to protect the confidentiality of remote access sessions.
42. Managed access control points are identified and implemented
3.1.14[a] – under 3.1.14: Route remote access via managed access control points.
43. Remote access is routed through managed network access control points
3.1.14[b] – under 3.1.14: Route remote access via managed access control points.
44. Privileged commands authorized for remote execution are identified
3.1.15[a] – under 3.1.15: Authorize remote execution of privileged commands and remote access to security – relevant information.
45. Security-relevant information authorized to be accessed remotely is identified
3.1.15[b] – under 3.1.15: Authorize remote execution of privileged commands and remote access to security – relevant information.
46. The execution of the identified privileged commands via remote access is authorized
3.1.15[c] – under 3.1.15: Authorize remote execution of privileged commands and remote access to security – relevant information.
47. Access to the identified security-relevant information via remote access is authorized
3.1.15[d] – under 3.1.15: Authorize remote execution of privileged commands and remote access to security – relevant information.
48. Wireless access points are identified
3.1.16[a] – under 3.1.16: Authorize wireless access prior to allowing such connections.
49. Wireless access is authorized prior to allowing such connections
3.1.16[b] – under 3.1.16: Authorize wireless access prior to allowing such connections.
50. Wireless access to the system is protected using authentication
3.1.17[a] – under 3.1.17: Protect wireless access using authentication and encryption.
51. Wireless access to the system is protected using encryption
3.1.17[b] – under 3.1.17: Protect wireless access using authentication and encryption.
52. Mobile devices that process, store, or transmit CUI are identified
3.1.18[a] – under 3.1.18: Control connection of mobile devices.
53. Mobile device connections are authorized
3.1.18[b] – under 3.1.18: Control connection of mobile devices.
54. Mobile device connections are monitored and logged
3.1.18[c] – under 3.1.18: Control connection of mobile devices.
55. Mobile devices and mobile computing platforms that process, store, or transmit CUI are identified
3.1.19[a] – under 3.1.19: Encrypt CUI on mobile devices and mobile computing platforms.
56. Encryption is employed to protect CUI on identified mobile devices and mobile computing platforms
3.1.19[b] – under 3.1.19: Encrypt CUI on mobile devices and mobile computing platforms.
57. Connections to external systems are identified
3.1.20[a] – under 3.1.20: Verify and control/limit connections to and use of external systems.
58. The use of external systems is identified
3.1.20[b] – under 3.1.20: Verify and control/limit connections to and use of external systems.
59. Connections to external systems are verified
3.1.20[c] – under 3.1.20: Verify and control/limit connections to and use of external systems.
60. The use of external systems is verified
3.1.20[d] – under 3.1.20: Verify and control/limit connections to and use of external systems.
61. Connections to external systems are controlled/limited
3.1.20[e] – under 3.1.20: Verify and control/limit connections to and use of external systems.
62. The use of external systems is controlled/limited
3.1.20[f] – under 3.1.20: Verify and control/limit connections to and use of external systems.
63. The use of portable storage devices containing CUI on external systems is identified and documented
3.1.21[a] – under 3.1.21: Limit use of portable storage devices on external systems.
64. Limits on the use of portable storage devices containing CUI on external systems are defined
3.1.21[b] – under 3.1.21: Limit use of portable storage devices on external systems.
65. The use of portable storage devices containing CUI on external systems is limited as defined
3.1.21[c] – under 3.1.21: Limit use of portable storage devices on external systems.
66. Individuals authorized to post or process information on publicly accessible systems are identified
3.1.22[a] – under 3.1.22: Control CUI posted or processed on publicly accessible systems.
67. Procedures to ensure CUI is not posted or processed on publicly accessible systems are identified
3.1.22[b] – under 3.1.22: Control CUI posted or processed on publicly accessible systems.
68. A review process is in place prior to posting of any content to publicly accessible systems
3.1.22[c] – under 3.1.22: Control CUI posted or processed on publicly accessible systems.
69. Content on publicly accessible systems is reviewed to ensure that it does not include CUI
3.1.22[d] – under 3.1.22: Control CUI posted or processed on publicly accessible systems.
70. Mechanisms are in place to remove and address improper posting of CUI
3.1.22[e] – under 3.1.22: Control CUI posted or processed on publicly accessible systems.
AU – Audit and Accountability
80. Audit logs needed (i.e., event types to be logged) to enable the monitoring, analysis, investigation, and reporting of unlawful or unauthorized system activity are specified
3.3.1[a] – under 3.3.1: Create and retain system audit logs and records to the extent needed to enable the monitoring, analysis, investigation, and reporting of unlawful or unauthorized system activity.
81. The content of audit records needed to support monitoring, analysis, investigation, and reporting of unlawful or unauthorized system activity is defined
3.3.1[b] – under 3.3.1: Create and retain system audit logs and records to the extent needed to enable the monitoring, analysis, investigation, and reporting of unlawful or unauthorized system activity.
82. Audit records are created (generated)
3.3.1[c] – under 3.3.1: Create and retain system audit logs and records to the extent needed to enable the monitoring, analysis, investigation, and reporting of unlawful or unauthorized system activity.
83. Audit records, once created, contain the defined content
3.3.1[d] – under 3.3.1: Create and retain system audit logs and records to the extent needed to enable the monitoring, analysis, investigation, and reporting of unlawful or unauthorized system activity.
84. Retention requirements for audit records are defined
3.3.1[e] – under 3.3.1: Create and retain system audit logs and records to the extent needed to enable the monitoring, analysis, investigation, and reporting of unlawful or unauthorized system activity.
85. Audit records are retained as defined
3.3.1[f] – under 3.3.1: Create and retain system audit logs and records to the extent needed to enable the monitoring, analysis, investigation, and reporting of unlawful or unauthorized system activity.
86. The content of the audit records needed to support the ability to uniquely trace users to their actions is defined
3.3.2[a] – under 3.3.2: Ensure that the actions of individual system users can be uniquely traced to those users so they can be held accountable for their actions.
87. Audit records, once created, contain the defined content
3.3.2[b] – under 3.3.2: Ensure that the actions of individual system users can be uniquely traced to those users so they can be held accountable for their actions.
88. A process for determining when to review logged events is defined
3.3.3[a] – under 3.3.3: Review and update logged events.
89. Event types being logged are reviewed in accordance with the defined review process
3.3.3[b] – under 3.3.3: Review and update logged events.
90. Event types being logged are updated based on the review
3.3.3[c] – under 3.3.3: Review and update logged events.
91. Personnel or roles to be alerted in the event of an audit logging process failure are identified
3.3.4[a] – under 3.3.4: Alert in the event of an audit logging process failure.
92. Types of audit logging process failures for which alert will be generated are defined
3.3.4[b] – under 3.3.4: Alert in the event of an audit logging process failure.
93. Identified personnel or roles are alerted in the event of an audit logging process failure
3.3.4[c] – under 3.3.4: Alert in the event of an audit logging process failure.
94. Audit record review, analysis, and reporting processes for investigation and response to indications of unlawful, unauthorized, suspicious, or unusual activity are defined
3.3.5[a] – under 3.3.5: Correlate audit record review, analysis, and reporting processes for investigation and response to indications of unlawful, unauthorized, suspicious, or unusual activity.
95. Defined audit record review, analysis, and reporting processes are correlated
3.3.5[b] – under 3.3.5: Correlate audit record review, analysis, and reporting processes for investigation and response to indications of unlawful, unauthorized, suspicious, or unusual activity.
96. An audit record reduction capability that supports on-demand analysis is provided
3.3.6[a] – under 3.3.6: Provide audit record reduction and report generation to support on-demand analysis and reporting.
97. A report generation capability that supports on-demand reporting is provided
3.3.6[b] – under 3.3.6: Provide audit record reduction and report generation to support on-demand analysis and reporting.
98. Internal system clocks are used to generate time stamps for audit records
3.3.7[a] – under 3.3.7: Provide a system capability that compares and synchronizes internal system clocks with an authoritative source to generate time stamps for audit records.
99. An authoritative source with which to compare and synchronize internal system clocks is specified
3.3.7[b] – under 3.3.7: Provide a system capability that compares and synchronizes internal system clocks with an authoritative source to generate time stamps for audit records.
100. Internal system clocks used to generate time stamps for audit records are compared to and synchronized with the specified authoritative time source
3.3.7[c] – under 3.3.7: Provide a system capability that compares and synchronizes internal system clocks with an authoritative source to generate time stamps for audit records.
101. Audit information is protected from unauthorized access
3.3.8[a] – under 3.3.8: Protect audit information and audit logging tools from unauthorized access, modification, and deletion.
102. Audit information is protected from unauthorized modification
3.3.8[b] – under 3.3.8: Protect audit information and audit logging tools from unauthorized access, modification, and deletion.
103. Audit information is protected from unauthorized deletion
3.3.8[c] – under 3.3.8: Protect audit information and audit logging tools from unauthorized access, modification, and deletion.
104. Audit logging tools are protected from unauthorized access
3.3.8[d] – under 3.3.8: Protect audit information and audit logging tools from unauthorized access, modification, and deletion.
105. Audit logging tools are protected from unauthorized modification
3.3.8[e] – under 3.3.8: Protect audit information and audit logging tools from unauthorized access, modification, and deletion.
106. Audit logging tools are protected from unauthorized deletion
3.3.8[f] – under 3.3.8: Protect audit information and audit logging tools from unauthorized access, modification, and deletion.
107. A subset of privileged users granted access to manage audit logging functionality is defined
3.3.9[a] – under 3.3.9: Limit management of audit logging functionality to a subset of privileged users.
108. Management of audit logging functionality is limited to the defined subset of privileged users
3.3.9[b] – under 3.3.9: Limit management of audit logging functionality to a subset of privileged users.
CM – Configuration Management
109. A baseline configuration is established
3.4.1[a] – under 3.4.1: Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles.
110. The baseline configuration includes hardware, software, firmware, and documentation
3.4.1[b] – under 3.4.1: Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles.
111. The baseline configuration is maintained (reviewed and updated) throughout the system development life cycle
3.4.1[c] – under 3.4.1: Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles.
112. A system inventory is established
3.4.1[d] – under 3.4.1: Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles.
113. The system inventory includes hardware, software, firmware, and documentation
3.4.1[e] – under 3.4.1: Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles.
114. The inventory is maintained (reviewed and updated) throughout the system development life cycle
3.4.1[f] – under 3.4.1: Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles.
115. Security configuration settings for information technology products employed in the system are established and included in the baseline configuration
3.4.2[a] – under 3.4.2: Establish and enforce security configuration settings for information technology products employed in organizational systems.
116. Security configuration settings for information technology products employed in the system are enforced
3.4.2[b] – under 3.4.2: Establish and enforce security configuration settings for information technology products employed in organizational systems.
117. Changes to the system are tracked
3.4.3[a] – under 3.4.3: Track, review, approve or disapprove, and log changes to organizational systems.
118. Changes to the system are reviewed
3.4.3[b] – under 3.4.3: Track, review, approve or disapprove, and log changes to organizational systems.
119. Changes to the system are approved or disapproved
3.4.3[c] – under 3.4.3: Track, review, approve or disapprove, and log changes to organizational systems.
120. Changes to the system are logged
3.4.3[d] – under 3.4.3: Track, review, approve or disapprove, and log changes to organizational systems.
121. The security impact of changes to the system is analyzed prior to implementation
3.4.4 – under 3.4.4: Analyze the security impact of changes prior to implementation.
122. Physical access restrictions associated with changes to the system are defined
3.4.5[a] – under 3.4.5: Define, document, approve, and enforce physical and logical access restrictions associated with changes to organizational systems.
123. Physical access restrictions associated with changes to the system are documented
3.4.5[b] – under 3.4.5: Define, document, approve, and enforce physical and logical access restrictions associated with changes to organizational systems.
124. Physical access restrictions associated with changes to the system are approved
3.4.5[c] – under 3.4.5: Define, document, approve, and enforce physical and logical access restrictions associated with changes to organizational systems.
125. Physical access restrictions associated with changes to the system are enforced
3.4.5[d] – under 3.4.5: Define, document, approve, and enforce physical and logical access restrictions associated with changes to organizational systems.
126. Logical access restrictions associated with changes to the system are defined
3.4.5[e] – under 3.4.5: Define, document, approve, and enforce physical and logical access restrictions associated with changes to organizational systems.
127. Logical access restrictions associated with changes to the system are documented
3.4.5[f] – under 3.4.5: Define, document, approve, and enforce physical and logical access restrictions associated with changes to organizational systems.
128. Logical access restrictions associated with changes to the system are approved
3.4.5[g] – under 3.4.5: Define, document, approve, and enforce physical and logical access restrictions associated with changes to organizational systems.
129. Logical access restrictions associated with changes to the system are enforced
3.4.5[h] – under 3.4.5: Define, document, approve, and enforce physical and logical access restrictions associated with changes to organizational systems.
130. Essential system capabilities are defined based on the principle of least functionality
3.4.6[a] – under 3.4.6: Employ the principle of least functionality by configuring organizational systems to provide only essential capabilities.
131. The system is configured to provide only the defined essential capabilities
3.4.6[b] – under 3.4.6: Employ the principle of least functionality by configuring organizational systems to provide only essential capabilities.
132. Essential programs are defined
3.4.7[a] – under 3.4.7: Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services.
133. The use of nonessential programs is defined
3.4.7[b] – under 3.4.7: Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services.
134. The use of nonessential programs is restricted, disabled, or prevented as defined
3.4.7[c] – under 3.4.7: Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services.
135. Essential functions are defined
3.4.7[d] – under 3.4.7: Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services.
136. The use of nonessential functions is defined
3.4.7[e] – under 3.4.7: Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services.
137. The use of nonessential functions is restricted, disabled, or prevented as defined
3.4.7[f] – under 3.4.7: Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services.
138. Essential ports are defined
3.4.7[g] – under 3.4.7: Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services.
139. The use of nonessential ports is defined
3.4.7[h] – under 3.4.7: Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services.
140. The use of nonessential ports is restricted, disabled, or prevented as defined
3.4.7[i] – under 3.4.7: Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services.
141. Essential protocols are defined
3.4.7[j] – under 3.4.7: Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services.
142. The use of nonessential protocols is defined
3.4.7[k] – under 3.4.7: Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services.
143. The use of nonessential protocols is restricted, disabled, or prevented as defined
3.4.7[l] – under 3.4.7: Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services.
144. Essential services are defined
3.4.7[m] – under 3.4.7: Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services.
145. The use of nonessential services is defined
3.4.7[n] – under 3.4.7: Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services.
146. The use of nonessential services is restricted, disabled, or prevented as defined
3.4.7[o] – under 3.4.7: Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services.
147. A policy specifying whether whitelisting or blacklisting is to be implemented is specified
3.4.8[a] – under 3.4.8: Apply deny-by-exception (blacklisting) policy to prevent the use of unauthorized software or deny-all, permit-by-exception (whitelisting) policy to allow the execution of authorized software.
148. The software allowed to execute under whitelisting or denied use under blacklisting is specified
3.4.8[b] – under 3.4.8: Apply deny-by-exception (blacklisting) policy to prevent the use of unauthorized software or deny-all, permit-by-exception (whitelisting) policy to allow the execution of authorized software.
149. Whitelisting to allow the execution of authorized software or blacklisting to prevent the use of unauthorized software is implemented as specified
3.4.8[c] – under 3.4.8: Apply deny-by-exception (blacklisting) policy to prevent the use of unauthorized software or deny-all, permit-by-exception (whitelisting) policy to allow the execution of authorized software.
150. A policy for controlling the installation of software by users is established
3.4.9[a] – under 3.4.9: Control and monitor user-installed software.
151. Installation of software by users is controlled based on the established policy
3.4.9[b] – under 3.4.9: Control and monitor user-installed software.
152. Installation of software by users is monitored
3.4.9[c] – under 3.4.9: Control and monitor user-installed software.
IA – Identification and Authentication
153. System users are identified
3.5.1[a] – under 3.5.1: Identify system users, processes acting on behalf of users, and devices.
154. Processes acting on behalf of users are identified
3.5.1[b] – under 3.5.1: Identify system users, processes acting on behalf of users, and devices.
155. Devices accessing the system are identified
3.5.1[c] – under 3.5.1: Identify system users, processes acting on behalf of users, and devices.
156. The identity of each user is authenticated or verified as a prerequisite to system access
3.5.2[a] – under 3.5.2: Authenticate (or verify) the identities of users, processes, or devices, as a prerequisite to allowing access to organizational systems.
157. The identity of each process acting on behalf of a user is authenticated or verified as a prerequisite to system access
3.5.2[b] – under 3.5.2: Authenticate (or verify) the identities of users, processes, or devices, as a prerequisite to allowing access to organizational systems.
158. The identity of each device accessing or connecting to the system is authenticated or verified as a prerequisite to system access
3.5.2[c] – under 3.5.2: Authenticate (or verify) the identities of users, processes, or devices, as a prerequisite to allowing access to organizational systems.
159. Privileged accounts are identified
3.5.3[a] – under 3.5.3: Use multifactor authentication for local and network access to privileged accounts and for network access to non-privileged accounts.
160. Multifactor authentication is implemented for local access to privileged accounts
3.5.3[b] – under 3.5.3: Use multifactor authentication for local and network access to privileged accounts and for network access to non-privileged accounts.
161. Multifactor authentication is implemented for network access to privileged accounts
3.5.3[c] – under 3.5.3: Use multifactor authentication for local and network access to privileged accounts and for network access to non-privileged accounts.
162. Multifactor authentication is implemented for network access to non-privileged accounts
3.5.3[d] – under 3.5.3: Use multifactor authentication for local and network access to privileged accounts and for network access to non-privileged accounts.
163. Replay-resistant authentication mechanisms are implemented for network account access to privileged and non-privileged accounts
3.5.4 – under 3.5.4: Employ replay-resistant authentication mechanisms for network access to privileged and non-privileged accounts.
164. A period within which identifiers cannot be reused is defined
3.5.5[a] – under 3.5.5: Prevent reuse of identifiers for a defined period.
165. Reuse of identifiers is prevented within the defined period
3.5.5[b] – under 3.5.5: Prevent reuse of identifiers for a defined period.
166. A period of inactivity after which an identifier is disabled is defined
3.5.6[a] – under 3.5.6: Disable identifiers after a defined period of inactivity.
167. Identifiers are disabled after the defined period of inactivity
3.5.6[b] – under 3.5.6: Disable identifiers after a defined period of inactivity.
168. Password complexity requirements are defined
3.5.7[a] – under 3.5.7: Enforce a minimum password complexity and change of characters when new passwords are created.
169. Password change of character requirements are defined
3.5.7[b] – under 3.5.7: Enforce a minimum password complexity and change of characters when new passwords are created.
170. Minimum password complexity requirements as defined are enforced when new passwords are created
3.5.7[c] – under 3.5.7: Enforce a minimum password complexity and change of characters when new passwords are created.
171. Minimum password change of character requirements as defined are enforced when new passwords are created
3.5.7[d] – under 3.5.7: Enforce a minimum password complexity and change of characters when new passwords are created.
172. The number of generations during which a password cannot be reused is specified
3.5.8[a] – under 3.5.8: Prohibit password reuse for a specified number of generations.
173. Reuse of passwords is prohibited during the specified number of generations
3.5.8[b] – under 3.5.8: Prohibit password reuse for a specified number of generations.
174. An immediate change to a permanent password is required when a temporary password is used for system logon
3.5.9 – under 3.5.9: Allow temporary password use for system logons with an immediate change to a permanent password.
175. Passwords are cryptographically protected in storage
3.5.10[a] – under 3.5.10: Store and transmit only cryptographically-protected passwords.
176. Passwords are cryptographically protected in transit
3.5.10[b] – under 3.5.10: Store and transmit only cryptographically-protected passwords.
177. Authentication information is obscured during the authentication process
3.5.11 – under 3.5.11: Obscure feedback of authentication information.
IR – Incident Response
178. An operational incident-handling capability is established
3.6.1[a] – under 3.6.1: Establish an operational incident-handling capability for organizational systems that includes preparation, detection, analysis, containment, recovery, and user response activities.
179. The operational incident-handling capability includes preparation
3.6.1[b] – under 3.6.1: Establish an operational incident-handling capability for organizational systems that includes preparation, detection, analysis, containment, recovery, and user response activities.
180. The operational incident-handling capability includes detection
3.6.1[c] – under 3.6.1: Establish an operational incident-handling capability for organizational systems that includes preparation, detection, analysis, containment, recovery, and user response activities.
181. The operational incident-handling capability includes analysis
3.6.1[d] – under 3.6.1: Establish an operational incident-handling capability for organizational systems that includes preparation, detection, analysis, containment, recovery, and user response activities.
182. The operational incident-handling capability includes containment
3.6.1[e] – under 3.6.1: Establish an operational incident-handling capability for organizational systems that includes preparation, detection, analysis, containment, recovery, and user response activities.
183. The operational incident-handling capability includes recovery
3.6.1[f] – under 3.6.1: Establish an operational incident-handling capability for organizational systems that includes preparation, detection, analysis, containment, recovery, and user response activities.
184. The operational incident-handling capability includes user response activities
3.6.1[g] – under 3.6.1: Establish an operational incident-handling capability for organizational systems that includes preparation, detection, analysis, containment, recovery, and user response activities.
185. Incidents are tracked
3.6.2[a] – under 3.6.2: Track, document, and report incidents to designated officials and/or authorities both internal and external to the organization.
186. Incidents are documented
3.6.2[b] – under 3.6.2: Track, document, and report incidents to designated officials and/or authorities both internal and external to the organization.
187. Authorities to whom incidents are to be reported are identified
3.6.2[c] – under 3.6.2: Track, document, and report incidents to designated officials and/or authorities both internal and external to the organization.
188. Organizational officials to whom incidents are to be reported are identified
3.6.2[d] – under 3.6.2: Track, document, and report incidents to designated officials and/or authorities both internal and external to the organization.
189. Identified authorities are notified of incidents
3.6.2[e] – under 3.6.2: Track, document, and report incidents to designated officials and/or authorities both internal and external to the organization.
190. Identified organizational officials are notified of incidents
3.6.2[f] – under 3.6.2: Track, document, and report incidents to designated officials and/or authorities both internal and external to the organization.
191. The incident response capability is tested
3.6.3 – under 3.6.3: Test the organizational incident response capability.
CA – Security Assessment
246. The frequency of security control assessments is defined
3.12.1[a] – under 3.12.1: Periodically assess the security controls in organizational systems to determine if the controls are effective in their application.
247. Security controls are assessed with the defined frequency to determine if the controls are effective in their application
3.12.1[b] – under 3.12.1: Periodically assess the security controls in organizational systems to determine if the controls are effective in their application.
248. Deficiencies and vulnerabilities to be addressed by the plan of action are identified
3.12.2[a] – under 3.12.2: Develop and implement plans of action designed to correct deficiencies and reduce or eliminate vulnerabilities in organizational systems.
249. A plan of action is developed to correct identified deficiencies and reduce or eliminate identified vulnerabilities
3.12.2[b] – under 3.12.2: Develop and implement plans of action designed to correct deficiencies and reduce or eliminate vulnerabilities in organizational systems.
250. The plan of action is implemented to correct identified deficiencies and reduce or eliminate identified vulnerabilities
3.12.2[c] – under 3.12.2: Develop and implement plans of action designed to correct deficiencies and reduce or eliminate vulnerabilities in organizational systems.
251. Security controls are monitored on an ongoing basis to ensure the continued effectiveness of those controls
3.12.3 – under 3.12.3: Monitor security controls on an ongoing basis to ensure the continued effectiveness of the controls.
252. A system security plan is developed
3.12.4[a] – under 3.12.4: Develop, document, and periodically update system security plans that describe system boundaries, system environments of operation, how security requirements are implemented, and the relationships with or connections to other systems.
253. The system boundary is described and documented in the system security plan
3.12.4[b] – under 3.12.4: Develop, document, and periodically update system security plans that describe system boundaries, system environments of operation, how security requirements are implemented, and the relationships with or connections to other systems.
254. The system environment of operation is described and documented in the system security plan
3.12.4[c] – under 3.12.4: Develop, document, and periodically update system security plans that describe system boundaries, system environments of operation, how security requirements are implemented, and the relationships with or connections to other systems.
255. The security requirements identified and approved by the designated authority as non-applicable are identified
3.12.4[d] – under 3.12.4: Develop, document, and periodically update system security plans that describe system boundaries, system environments of operation, how security requirements are implemented, and the relationships with or connections to other systems.
256. The method of security requirement implementation is described and documented in the system security plan
3.12.4[e] – under 3.12.4: Develop, document, and periodically update system security plans that describe system boundaries, system environments of operation, how security requirements are implemented, and the relationships with or connections to other systems.
257. The relationship with or connection to other systems is described and documented in the system security plan
3.12.4[f] – under 3.12.4: Develop, document, and periodically update system security plans that describe system boundaries, system environments of operation, how security requirements are implemented, and the relationships with or connections to other systems.
258. The frequency to update the system security plan is defined
3.12.4[g] – under 3.12.4: Develop, document, and periodically update system security plans that describe system boundaries, system environments of operation, how security requirements are implemented, and the relationships with or connections to other systems.
259. System security plan is updated with the defined frequency
3.12.4[h] – under 3.12.4: Develop, document, and periodically update system security plans that describe system boundaries, system environments of operation, how security requirements are implemented, and the relationships with or connections to other systems.
SC – System and Communications Protection
260. The external system boundary is defined
3.13.1[a] – under 3.13.1: Monitor, control, and protect communications (i.e., information transmitted or received by organizational systems) at the external boundaries and key internal boundaries of organizational systems.
261. Key internal system boundaries are defined
3.13.1[b] – under 3.13.1: Monitor, control, and protect communications (i.e., information transmitted or received by organizational systems) at the external boundaries and key internal boundaries of organizational systems.
262. Communications are monitored at the external system boundary
3.13.1[c] – under 3.13.1: Monitor, control, and protect communications (i.e., information transmitted or received by organizational systems) at the external boundaries and key internal boundaries of organizational systems.
263. Communications are monitored at key internal boundaries
3.13.1[d] – under 3.13.1: Monitor, control, and protect communications (i.e., information transmitted or received by organizational systems) at the external boundaries and key internal boundaries of organizational systems.
264. Communications are controlled at the external system boundary
3.13.1[e] – under 3.13.1: Monitor, control, and protect communications (i.e., information transmitted or received by organizational systems) at the external boundaries and key internal boundaries of organizational systems.
265. Communications are controlled at key internal boundaries
3.13.1[f] – under 3.13.1: Monitor, control, and protect communications (i.e., information transmitted or received by organizational systems) at the external boundaries and key internal boundaries of organizational systems.
266. Communications are protected at the external system boundary
3.13.1[g] – under 3.13.1: Monitor, control, and protect communications (i.e., information transmitted or received by organizational systems) at the external boundaries and key internal boundaries of organizational systems.
267. Communications are protected at key internal boundaries
3.13.1[h] – under 3.13.1: Monitor, control, and protect communications (i.e., information transmitted or received by organizational systems) at the external boundaries and key internal boundaries of organizational systems.
268. Architectural designs that promote effective information security are identified
3.13.2[a] – under 3.13.2: Employ architectural designs, software development techniques, and systems engineering principles that promote effective information security within organizational systems.
269. Software development techniques that promote effective information security are identified
3.13.2[b] – under 3.13.2: Employ architectural designs, software development techniques, and systems engineering principles that promote effective information security within organizational systems.
270. Systems engineering principles that promote effective information security are identified
3.13.2[c] – under 3.13.2: Employ architectural designs, software development techniques, and systems engineering principles that promote effective information security within organizational systems.
271. Identified architectural designs that promote effective information security are employed
3.13.2[d] – under 3.13.2: Employ architectural designs, software development techniques, and systems engineering principles that promote effective information security within organizational systems.
272. Identified software development techniques that promote effective information security are employed
3.13.2[e] – under 3.13.2: Employ architectural designs, software development techniques, and systems engineering principles that promote effective information security within organizational systems.
273. Identified systems engineering principles that promote effective information security are employed
3.13.2[f] – under 3.13.2: Employ architectural designs, software development techniques, and systems engineering principles that promote effective information security within organizational systems.
274. User functionality is identified
3.13.3[a] – under 3.13.3: Separate user functionality from system management functionality.
275. System management functionality is identified
3.13.3[b] – under 3.13.3: Separate user functionality from system management functionality.
276. User functionality is separated from system management functionality
3.13.3[c] – under 3.13.3: Separate user functionality from system management functionality.
277. Unauthorized and unintended information transfer via shared system resources is prevented
3.13.4 – under 3.13.4: Prevent unauthorized and unintended information transfer via shared system resources.
278. Publicly accessible system components are identified
3.13.5[a] – under 3.13.5: Implement subnetworks for publicly accessible system components that are physically or logically separated from internal networks.
279. Subnetworks for publicly accessible system components are physically or logically separated from internal networks
3.13.5[b] – under 3.13.5: Implement subnetworks for publicly accessible system components that are physically or logically separated from internal networks.
280. Network communications traffic is denied by default
3.13.6[a] – under 3.13.6: Deny network communications traffic by default and allow network communications traffic by exception (i.e., deny all, permit by exception).
281. Network communications traffic is allowed by exception
3.13.6[b] – under 3.13.6: Deny network communications traffic by default and allow network communications traffic by exception (i.e., deny all, permit by exception).
282. Remote devices are prevented from simultaneously establishing non-remote connections with the system and communicating via some other connection to resources in external networks (i.e., split tunneling)
3.13.7 – under 3.13.7: Prevent remote devices from simultaneously establishing non-remote connections with organizational systems and communicating via some other connection to resources in external networks (i.e., split tunneling).
283. Cryptographic mechanisms intended to prevent unauthorized disclosure of CUI are identified
3.13.8[a] – under 3.13.8: Implement cryptographic mechanisms to prevent unauthorized disclosure of CUI during transmission unless otherwise protected by alternative physical safeguards .
284. Alternative physical safeguards intended to prevent unauthorized disclosure of CUI are identified
3.13.8[b] – under 3.13.8: Implement cryptographic mechanisms to prevent unauthorized disclosure of CUI during transmission unless otherwise protected by alternative physical safeguards .
285. Either cryptographic mechanisms or alternative physical safeguards are implemented to prevent unauthorized disclosure of CUI during transmission
3.13.8[c] – under 3.13.8: Implement cryptographic mechanisms to prevent unauthorized disclosure of CUI during transmission unless otherwise protected by alternative physical safeguards .
286. A period of inactivity to terminate network connections associated with communications sessions is defined
3.13.9[a] – under 3.13.9: Terminate network connections associated with communications sessions at the end of the sessions or after a defined period of inactivity.
287. Network connections associated with communications sessions are terminated at the end of the sessions
3.13.9[b] – under 3.13.9: Terminate network connections associated with communications sessions at the end of the sessions or after a defined period of inactivity.
288. Network connections associated with communications sessions are terminated after the defined period of inactivity
3.13.9[c] – under 3.13.9: Terminate network connections associated with communications sessions at the end of the sessions or after a defined period of inactivity.
289. Cryptographic keys are established whenever cryptography is employed
3.13.10[a] – under 3.13.10: Establish and manage cryptographic keys for cryptography employed in organizational systems.
290. Cryptographic keys are managed whenever cryptography is employed
3.13.10[b] – under 3.13.10: Establish and manage cryptographic keys for cryptography employed in organizational systems.
291. FIPS-validated cryptography is employed to protect the confidentiality of CUI
3.13.11 – under 3.13.11: Employ FIPS-validated cryptography when used to protect the confidentiality of CUI.
292. Collaborative computing devices are identified
3.13.12[a] – under 3.13.12: Prohibit remote activation of collaborative computing devices and provide indication of devices in use to users present at the device.
293. Collaborative computing devices provide indication to users of devices in use
3.13.12[b] – under 3.13.12: Prohibit remote activation of collaborative computing devices and provide indication of devices in use to users present at the device.
294. Remote activation of collaborative computing devices is prohibited
3.13.12[c] – under 3.13.12: Prohibit remote activation of collaborative computing devices and provide indication of devices in use to users present at the device.
295. Use of mobile code is controlled
3.13.13[a] – under 3.13.13: Control and monitor the use of mobile code.
296. Use of mobile code is monitored
3.13.13[b] – under 3.13.13: Control and monitor the use of mobile code.
297. Use of Voice over Internet Protocol (VoIP) technologies is controlled
3.13.14[a] – under 3.13.14: Control and monitor the use of Voice over Internet Protocol (VoIP) technologies.
298. Use of Voice over Internet Protocol (VoIP) technologies is monitored
3.13.14[b] – under 3.13.14: Control and monitor the use of Voice over Internet Protocol (VoIP) technologies.
299. The authenticity of communications sessions is protected
3.13.15 – under 3.13.15: Protect the authenticity of communications sessions.
300. The confidentiality of CUI at rest is protected
3.13.16 – under 3.13.16: Protect the confidentiality of CUI at rest.
SI – System and Information Integrity
301. The time within which to identify system flaws is specified
3.14.1[a] – under 3.14.1: Identify, report, and correct system flaws in a timely manner.
302. System flaws are identified within the specified time frame
3.14.1[b] – under 3.14.1: Identify, report, and correct system flaws in a timely manner.
303. The time within which to report system flaws is specified
3.14.1[c] – under 3.14.1: Identify, report, and correct system flaws in a timely manner.
304. System flaws are reported within the specified time frame
3.14.1[d] – under 3.14.1: Identify, report, and correct system flaws in a timely manner.
305. The time within which to correct system flaws is specified
3.14.1[e] – under 3.14.1: Identify, report, and correct system flaws in a timely manner.
306. System flaws are corrected within the specified time frame
3.14.1[f] – under 3.14.1: Identify, report, and correct system flaws in a timely manner.
307. Designated locations for malicious code protection are identified
3.14.2[a] – under 3.14.2: Provide protection from malicious code at designated locations within organizational systems.
308. Protection from malicious code at designated locations is provided
3.14.2[b] – under 3.14.2: Provide protection from malicious code at designated locations within organizational systems.
309. Response actions to system security alerts and advisories are identified
3.14.3[a] – under 3.14.3: Monitor system security alerts and advisories and take action in response.
310. System security alerts and advisories are monitored
3.14.3[b] – under 3.14.3: Monitor system security alerts and advisories and take action in response.
311. Actions in response to system security alerts and advisories are taken
3.14.3[c] – under 3.14.3: Monitor system security alerts and advisories and take action in response.
312. Malicious code protection mechanisms are updated when new releases are available
3.14.4 – under 3.14.4: Update malicious code protection mechanisms when new releases are available.
313. The frequency for malicious code scans is defined
3.14.5[a] – under 3.14.5: Perform periodic scans of organizational systems and real-time scans of files from external sources as files are downloaded, opened, or executed.
314. Malicious code scans are performed with the defined frequency
3.14.5[b] – under 3.14.5: Perform periodic scans of organizational systems and real-time scans of files from external sources as files are downloaded, opened, or executed.
315. Real-time malicious code scans of files from external sources as files are downloaded, opened, or executed are performed
3.14.5[c] – under 3.14.5: Perform periodic scans of organizational systems and real-time scans of files from external sources as files are downloaded, opened, or executed.
316. The system is monitored to detect attacks and indicators of potential attacks
3.14.6[a] – under 3.14.6: Monitor organizational systems, including inbound and outbound communications traffic, to detect attacks and indicators of potential attacks.
317. Inbound communications traffic is monitored to detect attacks and indicators of potential attacks
3.14.6[b] – under 3.14.6: Monitor organizational systems, including inbound and outbound communications traffic, to detect attacks and indicators of potential attacks.
318. Outbound communications traffic is monitored to detect attacks and indicators of potential attacks
3.14.6[c] – under 3.14.6: Monitor organizational systems, including inbound and outbound communications traffic, to detect attacks and indicators of potential attacks.
319. Authorized use of the system is defined
3.14.7[a] – under 3.14.7: Identify unauthorized use of organizational systems.
320. Unauthorized use of the system is identified
3.14.7[b] – under 3.14.7: Identify unauthorized use of organizational systems.