Attachment 11 - C-SCRM Plan (Template).xlsx

XLSX spreadsheet 102 KB Posted

Attached to
GSA Global Supply OCONUS Logistics Operations Support Solution - EUCOM Federal contract opportunity
Solicitation number
47QSCC23R0008
Issued by
GSA Federal Acquisition Service

View the file

Other files for this federal contract opportunity

Other files attached to GSA Global Supply OCONUS Logistics Operations Support Solution - EUCOM, newest first.
File Type Posted
Updated Headers Attachment 7 Pricing Template Amendment 0003.xlsx XLSX spreadsheet
Updated Attachment 7 Pricing Template Amendment 0003.xlsx XLSX spreadsheet
47QSCC23R0008 Amendment 0003.pdf PDF
Updated Attachment 7 Pricing Template Amendment 2.xlsx XLSX spreadsheet
47QSCC23R0008 Amendment 0002.pdf PDF
Updated Attachment 6 - NSN Descriptions - Amendment 1.docx DOCX document
Updated Attachment 3 - List of NSNs - Amendment 1.xlsx XLSX spreadsheet
Questions and Answers for EUCOM.xlsx XLSX spreadsheet
Amendment 0001 SF30 and Continuation Pages.pdf PDF
Updated Attachment 7 - Pricing Template - Amendment 1.xlsx XLSX spreadsheet
Attachment 1 - Terms and Conditions.pdf PDF
Attachment 6 - IDPs.pdf PDF
Attachment 12 - C-SCRM Questionnaire (Template).xlsx XLSX spreadsheet
Attachment 3 - NSNs.xlsx XLSX spreadsheet
Attachment 4 - GSA Delivery Order.pdf PDF
Attachment 7 - Pricing Template.xlsx XLSX spreadsheet
Attachment 5 - QASP.pdf PDF
RFP 47QSCC23R0008 EUCOM_.pdf PDF
Attachment 8 - Security Controls.xlsx XLSX spreadsheet
Attachment 2 - Performance Work Statement for EUCOM.pdf PDF
Attachment 9 - Packing List and Documentation Supplemental Information.pdf PDF
Attachment 10 - Manage Your GHG Emissions - Slip Sheet.pdf PDF
Show all 22

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Old Instructions

SUPPLY CHAIN RISK MANAGEMENT PLAN TEMPLATE

INSTRUCTIONS
INTRODUCTION:
US adversaries have attacked our nation's supply chains and compromised Federal Government systems, capitalizing on security weaknesses in US companies and third party affiliates. It is incumbent on GSA's industrial base to implement vigilant Supply Chain Risk Management procedures.
TEMPLATE COMPLETION INSTRUCTIONS:
● Provide a contact (name, email, and phone number) for questions, support, or additional information related to the questionnaire to the respondents.
● Please provide your responses in the gray shaded lines of the template under Column C, Vendor Response.
● Please provide a response to each ‘Yes’, ‘No’ question as relevant to the offering.
● If the question does not apply to your organization, please answer ‘N/A’ and provide a supporting statement of applicability if not relevant to the offering in consideration.
● A response of ‘Alternate’ may be used if a particular supply chain risk can be addressed in alternative ways and not directly through compliance with a standard or framework.
● Please attach supporting documents to the completed SCRM Plan Template. You may provide links when submitting if documentation is available online and accessible.
● We recommend designating one primary POC from your organization who will collaborate with the appropriate POCs/teams/vendor/supplier to coordinate and collect and compile responses for each section. The appropriate POCs within each organization will vary and may consist of individuals in information technology, acquisition, procurement, supply chain, or security offices. While related, each section is design to be relevant to a different aspect of your organization. This template is intended to gather an initial and consistent baseline and additional follow-up questions from the organization, or other documentation, may be warranted.

Old Template

SUPPLY CHAIN RISK MANAGEMENT PLAN TEMPLATE

CONTACT INFORMATION
Name of Respondent:
Title:
Name of Organization:
Phone number:
Email:
SECT. 1GENERAL QUESTIONSVENDOR RESPONSE
Identity - including that of each parent and/or subsidiary corporate entities.
1.1Have you identified your key suppliers?

1.2 Do you verify the company ownership?

1.3 If so, do you confirm that the company is under U.S. ownership?

1.4 If you use distributors, do you investigate them for potential threats?

1.5 Are any subcontractors and/or suppliers located outside the United States or its territories? If 'Yes', then please list company name and foreign country location.

1.6 Do you have controls fully aligned to NIST SP 800-161, Supply Chain Risk Management Practices for Federal Information Systems and Organization? If yes, please explain in Section 1.6. If no, please proceed to Section 2.1.

1.7 Please provide evidence of alignment with NIST SP-800-161.

SECT. 2SUPPLY CHAIN MANAGEMENT AND SUPPLIER GOVERANCE
General
2.1Do you have policies to ensure timely notification of updated risk management information previously provided to us? [Yes or No]. If "yes" please explain the process.
Information Communications Technology (ICT) Supply Chain Management
2.2Do you have a documented Quality Management System (QMS) for your ICT supply chain operation based on an industry standard or framework? [Yes or No]. If "yes" please provide QMS documentation.
Supplier Governance
2.3Do you have written Supply Chain Risk Management (SCRM) requirements in your contracts with your suppliers? [Yes or No] If "yes" please provide SCRM requirements.

2.4 Describe how you verify that your suppliers are meeting SCRM contractual terms and conditions, including, where applicable, requirements to be passed down to sub-suppliers.

SECT. 3INFORMATION SECURITY
Identify
3.1Describe your process to verify that information is classified according to legal, regulatory, or internal sensitivity requirements?

3.2 How often do you review and update to those policies and procedures? When is the most recent review?

Detect
3.4Do you have defined and documented incident detection practices that outline which actions should be taken in the case of an information security or cybersecurity event? [Yes or No]. If "yes" please describe.

3.5 Are cybersecurity events centrally logged, tracked, and continuously monitored? Please explain how events are monitored.

3.6 Do you deploy anti-malware software throughout your environment? [Yes or No] If "no" please explain.

3.7 Do you have a documented incident response process and a dedicated incident response team (CSIRT - Computer Security Incident Response Team)? [Yes or No] If "no" please explain.

SECT. 4PHYSICAL SECURITY
General
4.1Is the entity (organization, operational unit, facility, etc.) currently covered by an unrestricted/unlimited National Industrial Security Program (NISP) Facility Clearance (FCL) or a related U.S. government program such as C- TPAT that certifies the entity as meeting appropriate physical security standards? [Yes or No] If "yes" please state the program that certified you and date of last certification.

4.2 Do you have documented security policies and procedures that address the control of physical access to cyber assets (network devices, data facilities, patch panels, industrial control systems, programmable logic, etc.)? [Yes or No] If "yes" please describe.

4.3 To what industry standards/controls do you adhere? (e.g., NIST publication, ISO, UL, etc.)

4.4 How often do you review and update those policies and procedures and when was the most recent review?

4.5 Do you have a documented Security Incident Response process covering physical security incidents? (e.g., potential intruder access, missing equipment, etc.) [Yes or No] If "yes" please describe.

Physical Security In-transit
4.6What requirements, if any, are in place to ensure the use of Original Equipment Manufacturer (OEM) or Authorized Distributors for all key components?

4.7 How do you pass on counterfeit prevention requirements to your third party suppliers?

SECT. 5PERSONNEL SECURITY
General
5.1Do you employ a physical security guard presence at your facilities? [Yes or No] If "yes" please describe.

5.2 Describe if physical security practices are formally governed, documented, maintained, and enforced?

Onboarding
5.3Do you have policies for conducting background checks of your employees as permitted by the country in which you operate? [Yes or No] If "yes" please describe.
SECT. 6SUPPLY CHAIN INTEGRITY
General
6.1What are your processes for managing third-party products and component defects throughout their lifecycle?

6.2 What provisions for auditing are included within supplier contracts?

6.3 How do you pass down HW/SW products or services integrity requirements to third party suppliers?

6.4 Do you have processes in place for addressing reuse and/or recycle of HW products? [Yes or No] If "yes" please describe.

SECT. 7SUPPLY CHAIN RESILIENCE
General
7.1Does your organization have a formal process for ensuring supply chain resilience as part of your product offering SCRM practices? [Yes or No] . If "yes" please describe.
Supply Chain Disruption Risk Management (Business Continuity)
7.2Can personnel work remotely? [Yes or No] If yes, do you require a licensed VPN or MFA solution to connect?

7.3 Do you currently have a data backup policy in place?

7.4 Has your organization conducted vulnerability assessments, risk assessment, or other calculations to identify what impact physical risks associated with climate change (e.g., increases in precipitation-driven flooding, extreme heat events, and inundation due to sea level rise and storm surge) might have on your assets, products, and/or services?

7.5 If yes, describe the assessment process. If assessment results are reported (CDP, GRI, Sustainability or Corporate Responsibility reports), provide the reporting platform and/or report.

7.6 Does your organization have a disaster response plan that includes contingency plans and response protocols for potential short-term acute events (e.g., hurricane, earthquake, flooding, and etc.) and long-term climate change impact (e.g.; changes in precipitation, increased average temperature, and sea level rise)?

7.7 If yes or no, how do or will you deal with potential increases in frequency, severity, or duration of weather events?

7.8 If yes, describe which assets, products, services would most significantly disrupt operations if they experienced short term acute damage (immediate failure, either temporary or catastrophic).

7.9 If yes, describe which assets, products, services, would most significantly disrupt operations if they experienced gradual long-term cumulative damage (slower degradation; greater wear and tear).

https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-161.pdf Copy of SP 800-53B

SORT-ASControl IdentifierControl (or Control Enhancement) NameWithdrawnPrivacy BaselineSecurity Control Baseline - LowSecurity Control Baseline - ModerateSecurity Control Baseline - High
AC-01-00AC-1Policy and Proceduresxxxx
AC-02-00AC-2Account Managementxxx
AC-02-01AC-2(1)Account Management | Automated System Account Managementxx
AC-02-02AC-2(2)Account Management | Automated Temporary and Emergency Account Managementxx
AC-02-03AC-2(3)Account Management | Disable Accountsxx
AC-02-04AC-2(4)Account Management | Automated Audit Actionsxx
AC-02-05AC-2(5)Account Management | Inactivity Logoutxx
AC-02-06AC-2(6)Account Management | Dynamic Privilege Management
AC-02-07AC-2(7)Account Management | Privileged User Accounts
AC-02-08AC-2(8)Account Management | Dynamic Account Management
AC-02-09AC-2(9)Account Management | Restrictions on Use of Shared and Group Accounts
AC-02-10AC-2(10)Account Management | Shared and Group Account Credential ChangeW: Incorporated into AC-2k.
AC-02-11AC-2(11)Account Management | Usage Conditionsx
AC-02-12AC-2(12)Account Management | Account Monitoring for Atypical Usagex
AC-02-13AC-2(13)Account Management | Disable Accounts for High-risk Individualsxx
AC-03-00AC-3Access Enforcementxxx
AC-03-01AC-3(1)Access Enforcement | Restricted Access to Privileged FunctionsW: Incorporated into AC-6.
AC-03-02AC-3(2)Access Enforcement | Dual Authorization
AC-03-03AC-3(3)Access Enforcement | Mandatory Access Control
AC-03-04AC-3(4)Access Enforcement | Discretionary Access Control
AC-03-05AC-3(5)Access Enforcement | Security-relevant Information
AC-03-06AC-3(6)Access Enforcement | Protection of User and System InformationW: Incorporated into MP-4 and SC-28.
AC-03-07AC-3(7)Access Enforcement | Role-based Access Control
AC-03-08AC-3(8)Access Enforcement | Revocation of Access Authorizations
AC-03-09AC-3(9)Access Enforcement | Controlled Release
AC-03-10AC-3(10)Access Enforcement | Audited Override of Access Control Mechanisms
AC-03-11AC-3(11)Access Enforcement | Restrict Access to Specific Information Types
AC-03-12AC-3(12)Access Enforcement | Assert and Enforce Application Access
AC-03-13AC-3(13)Access Enforcement | Attribute-based Access Control
AC-03-14AC-3(14)Access Enforcement | Individual Accessx
AC-03-15AC-3(15)Access Enforcement | Discretionary and Mandatory Access Control
AC-04-00AC-4Information Flow Enforcementxx
AC-04-01AC-4(1)Information Flow Enforcement | Object Security and Privacy Attributes
AC-04-02AC-4(2)Information Flow Enforcement | Processing Domains
AC-04-03AC-4(3)Information Flow Enforcement | Dynamic Information Flow Control
AC-04-04AC-4(4)Information Flow Enforcement | Flow Control of Encrypted Informationx
AC-04-05AC-4(5)Information Flow Enforcement | Embedded Data Types
AC-04-06AC-4(6)Information Flow Enforcement | Metadata
AC-04-07AC-4(7)Information Flow Enforcement | One-way Flow Mechanisms
AC-04-08AC-4(8)Information Flow Enforcement | Security and Privacy Policy Filters
AC-04-09AC-4(9)Information Flow Enforcement | Human Reviews
AC-04-10AC-4(10)Information Flow Enforcement | Enable and Disable Security or Privacy Policy Filters
AC-04-11AC-4(11)Information Flow Enforcement | Configuration of Security or Privacy Policy Filters
AC-04-12AC-4(12)Information Flow Enforcement | Data Type Identifiers
AC-04-13AC-4(13)Information Flow Enforcement | Decomposition into Policy-relevant Subcomponents
AC-04-14AC-4(14)Information Flow Enforcement | Security or Privacy Policy Filter Constraints
AC-04-15AC-4(15)Information Flow Enforcement | Detection of Unsanctioned Information
AC-04-16AC-4(16)Information Flow Enforcement | Information Transfers on Interconnected SystemsW: Incorporated into AC-4.
AC-04-17AC-4(17)Information Flow Enforcement | Domain Authentication
AC-04-18AC-4(18)Information Flow Enforcement | Security Attribute BindingW: Incorporated into AC-16.
AC-04-19AC-4(19)Information Flow Enforcement | Validation of Metadata
AC-04-20AC-4(20)Information Flow Enforcement | Approved Solutions
AC-04-21AC-4(21)Information Flow Enforcement | Physical or Logical Separation of Information Flows
AC-04-22AC-4(22)Information Flow Enforcement | Access Only
AC-04-23AC-4(23)Information Flow Enforcement | Modify Non-releasable Information
AC-04-24AC-4(24)Information Flow Enforcement | Internal Normalized Format
AC-04-25AC-4(25)Information Flow Enforcement | Data Sanitization
AC-04-26AC-4(26)Information Flow Enforcement | Audit Filtering Actions
AC-04-27AC-4(27)Information Flow Enforcement | Redundant/independent Filtering Mechanisms
AC-04-28AC-4(28)Information Flow Enforcement | Linear Filter Pipelines
AC-04-29AC-4(29)Information Flow Enforcement | Filter Orchestration Engines
AC-04-30AC-4(30)Information Flow Enforcement | Filter Mechanisms Using Multiple Processes
AC-04-31AC-4(31)Information Flow Enforcement | Failed Content Transfer Prevention
AC-04-32AC-4(32)Information Flow Enforcement | Process Requirements for Information Transfer
AC-05-00AC-5Separation of Dutiesxx
AC-06-00AC-6Least Privilegexx
AC-06-01AC-6(1)Least Privilege | Authorize Access to Security Functionsxx
AC-06-02AC-6(2)Least Privilege | Non-privileged Access for Nonsecurity Functionsxx
AC-06-03AC-6(3)Least Privilege | Network Access to Privileged Commandsx
AC-06-04AC-6(4)Least Privilege | Separate Processing Domains
AC-06-05AC-6(5)Least Privilege | Privileged Accountsxx
AC-06-06AC-6(6)Least Privilege | Privileged Access by Non-organizational Users
AC-06-07AC-6(7)Least Privilege | Review of User Privilegesxx
AC-06-08AC-6(8)Least Privilege | Privilege Levels for Code Execution
AC-06-09AC-6(9)Least Privilege | Log Use of Privileged Functionsxx
AC-06-10AC-6(10)Least Privilege | Prohibit Non-privileged Users from Executing Privileged Functionsxx
AC-07-00AC-7Unsuccessful Logon Attemptsxxx
AC-07-01AC-7(1)Unsuccessful Logon Attempts | Automatic Account LockW: Incorporated into AC-7.
AC-07-02AC-7(2)Unsuccessful Logon Attempts | Purge or Wipe Mobile Device
AC-07-03AC-7(3)Unsuccessful Logon Attempts | Biometric Attempt Limiting
AC-07-04AC-7(4)Unsuccessful Logon Attempts | Use of Alternate Authentication Factor
AC-08-00AC-8System Use Notificationxxx
AC-09-00AC-9Previous Logon Notification
AC-09-01AC-9(1)Previous Logon Notification | Unsuccessful Logons
AC-09-02AC-9(2)Previous Logon Notification | Successful and Unsuccessful Logons
AC-09-03AC-9(3)Previous Logon Notification | Notification of Account Changes
AC-09-04AC-9(4)Previous Logon Notification | Additional Logon Information
AC-10-00AC-10Concurrent Session Controlx
AC-11-00AC-11Device Lockxx
AC-11-01AC-11(1)Device Lock | Pattern-hiding Displaysxx
AC-12-00AC-12Session Terminationxx
AC-12-01AC-12(1)Session Termination | User-initiated Logouts
AC-12-02AC-12(2)Session Termination | Termination Message
AC-12-03AC-12(3)Session Termination | Timeout Warning Message
AC-13-00AC-13Supervision and Review — Access ControlW: Incorporated into AC-2 and AU-6.
AC-14-00AC-14Permitted Actions Without Identification or Authenticationxxx
AC-14-01AC-14(1)Permitted Actions Without Identification or Authentication | Necessary UsesW: Incorporated into AC-14.
AC-15-00AC-15Automated MarkingW: Incorporated into MP-3.
AC-16-00AC-16Security and Privacy Attributes
AC-16-01AC-16(1)Security and Privacy Attributes | Dynamic Attribute Association
AC-16-02AC-16(2)Security and Privacy Attributes | Attribute Value Changes by Authorized Individuals
AC-16-03AC-16(3)Security and Privacy Attributes | Maintenance of Attribute Associations by System
AC-16-04AC-16(4)Security and Privacy Attributes | Association of Attributes by Authorized Individuals
AC-16-05AC-16(5)Security and Privacy Attributes | Attribute Displays on Objects to Be Output
AC-16-06AC-16(6)Security and Privacy Attributes | Maintenance of Attribute Association
AC-16-07AC-16(7)Security and Privacy Attributes | Consistent Attribute Interpretation
AC-16-08AC-16(8)Security and Privacy Attributes | Association Techniques and Technologies
AC-16-09AC-16(9)Security and Privacy Attributes | Attribute Reassignment — Regrading Mechanisms
AC-16-10AC-16(10)Security and Privacy Attributes | Attribute Configuration by Authorized Individuals
AC-17-00AC-17Remote Accessxxx
AC-17-01AC-17(1)Remote Access | Monitoring and Controlxx
AC-17-02AC-17(2)Remote Access | Protection of Confidentiality and Integrity Using Encryptionxx
AC-17-03AC-17(3)Remote Access | Managed Access Control Pointsxx
AC-17-04AC-17(4)Remote Access | Privileged Commands and Accessxx
AC-17-05AC-17(5)Remote Access | Monitoring for Unauthorized ConnectionsW: Incorporated into SI-4.
AC-17-06AC-17(6)Remote Access | Protection of Mechanism Information
AC-17-07AC-17(7)Remote Access | Additional Protection for Security Function AccessW: Incorporated into AC-3(10).
AC-17-08AC-17(8)Remote Access | Disable Nonsecure Network ProtocolsW: Incorporated into CM-7.
AC-17-09AC-17(9)Remote Access | Disconnect or Disable Access
AC-17-10AC-17(10)Remote Access | Authenticate Remote Commands
AC-18-00AC-18Wireless Accessxxx
AC-18-01AC-18(1)Wireless Access | Authentication and Encryptionxx
AC-18-02AC-18(2)Wireless Access | Monitoring Unauthorized ConnectionsW: Incorporated into SI-4.
AC-18-03AC-18(3)Wireless Access | Disable Wireless Networkingxx
AC-18-04AC-18(4)Wireless Access | Restrict Configurations by Usersx
AC-18-05AC-18(5)Wireless Access | Antennas and Transmission Power Levelsx
AC-19-00AC-19Access Control for Mobile Devicesxxx
AC-19-01AC-19(1)Access Control for Mobile Devices | Use of Writable and Portable Storage DevicesW: Incorporated into MP-7.
AC-19-02AC-19(2)Access Control for Mobile Devices | Use of Personally Owned Portable Storage DevicesW: Incorporated into MP-7.
AC-19-03AC-19(3)Access Control for Mobile Devices | Use of Portable Storage Devices with No Identifiable OwnerW: Incorporated into MP-7.
AC-19-04AC-19(4)Access Control for Mobile Devices | Restrictions for Classified Information
AC-19-05AC-19(5)Access Control for Mobile Devices | Full Device or Container-based Encryptionxx
AC-20-00AC-20Use of External Systemsxxx
AC-20-01AC-20(1)Use of External Systems | Limits on Authorized Usexx
AC-20-02AC-20(2)Use of External Systems | Portable Storage Devices — Restricted Usexx
AC-20-03AC-20(3)Use of External Systems | Non-organizationally Owned Systems — Restricted Use
AC-20-04AC-20(4)Use of External Systems | Network Accessible Storage Devices — Prohibited Use
AC-20-05AC-20(5)Use of External Systems | Portable Storage Devices — Prohibited Use
AC-21-00AC-21Information Sharingxx
AC-21-01AC-21(1)Information Sharing | Automated Decision Support
AC-21-02AC-21(2)Information Sharing | Information Search and Retrieval
AC-22-00AC-22Publicly Accessible Contentxxx
AC-23-00AC-23Data Mining Protection
AC-24-00AC-24Access Control Decisions
AC-24-01AC-24(1)Access Control Decisions | Transmit Access Authorization Information
AC-24-02AC-24(2)Access Control Decisions | No User or Process Identity
AC-25-00AC-25Reference Monitor
AT-01-00AT-1Policy and Proceduresxxxx
AT-02-00AT-2Literacy Training and Awarenessxxxx
AT-02-01AT-2(1)Literacy Training and Awareness | Practical Exercises
AT-02-02AT-2(2)Literacy Training and Awareness | Insider Threatxxx
AT-02-03AT-2(3)Literacy Training and Awareness | Social Engineering and Miningxx
AT-02-04AT-2(4)Literacy Training and Awareness | Suspicious Communications and Anomalous System Behavior
AT-02-05AT-2(5)Literacy Training and Awareness | Advanced Persistent Threat
AT-02-06AT-2(6)Literacy Training and Awareness | Cyber Threat Environment
AT-03-00AT-3Role-based Trainingxxxx
AT-03-01AT-3(1)Role-based Training | Environmental Controls
AT-03-02AT-3(2)Role-based Training | Physical Security Controls
AT-03-03AT-3(3)Role-based Training | Practical Exercises
AT-03-04AT-3(4)Role-based Training | Suspicious Communications and Anomalous System BehaviorW: Incorporated into AT-2(4).
AT-03-05AT-3(5)Role-based Training | Processing Personally Identifiable Informationx
AT-04-00AT-4Training Recordsxxxx
AT-05-00AT-5Contacts with Security Groups and AssociationsW: Incorporated into PM-15.
AT-06-00AT-6Training Feedback
AU-01-00AU-1Policy and Proceduresxxxx
AU-02-00AU-2Event Loggingxxxx
AU-02-01AU-2(1)Event Logging | Compilation of Audit Records from Multiple SourcesW: Incorporated into AU-12.
AU-02-02AU-2(2)Event Logging | Selection of Audit Events by ComponentW: Incorporated into AU-12.
AU-02-03AU-2(3)Event Logging | Reviews and UpdatesW: Incorporated into AU-2.
AU-02-04AU-2(4)Event Logging | Privileged FunctionsW: Incorporated into AC-6(9).
AU-03-00AU-3Content of Audit Recordsxxx
AU-03-01AU-3(1)Content of Audit Records | Additional Audit Informationxx
AU-03-02AU-3(2)Content of Audit Records | Centralized Management of Planned Audit Record ContentW: Incorporated into PL-9.
AU-03-03AU-3(3)Content of Audit Records | Limit Personally Identifiable Information Elementsx
AU-04-00AU-4Audit Log Storage Capacityxxx
AU-04-01AU-4(1)Audit Log Storage Capacity | Transfer to Alternate Storage
AU-05-00AU-5Response to Audit Logging Process Failuresxxx
AU-05-01AU-5(1)Response to Audit Logging Process Failures | Storage Capacity Warningx
AU-05-02AU-5(2)Response to Audit Logging Process Failures | Real-time Alertsx
AU-05-03AU-5(3)Response to Audit Logging Process Failures | Configurable Traffic Volume Thresholds
AU-05-04AU-5(4)Response to Audit Logging Process Failures | Shutdown on Failure
AU-05-05AU-5(5)Response to Audit Logging Process Failures | Alternate Audit Logging Capability
AU-06-00AU-6Audit Record Review, Analysis, and Reportingxxx
AU-06-01AU-6(1)Audit Record Review, Analysis, and Reporting | Automated Process Integrationxx
AU-06-02AU-6(2)Audit Record Review, Analysis, and Reporting | Automated Security AlertsW: Incorporated into SI-4
AU-06-03AU-6(3)Audit Record Review, Analysis, and Reporting | Correlate Audit Record Repositoriesxx
AU-06-04AU-6(4)Audit Record Review, Analysis, and Reporting | Central Review and Analysis
AU-06-05AU-6(5)Audit Record Review, Analysis, and Reporting | Integrated Analysis of Audit Recordsx
AU-06-06AU-6(6)Audit Record Review, Analysis, and Reporting | Correlation with Physical Monitoringx
AU-06-07AU-6(7)Audit Record Review, Analysis, and Reporting | Permitted Actions
AU-06-08AU-6(8)Audit Record Review, Analysis, and Reporting | Full Text Analysis of Privileged Commands
AU-06-09AU-6(9)Audit Record Review, Analysis, and Reporting | Correlation with Information from Nontechnical Sources
AU-06-10AU-6(10)Audit Record Review, Analysis, and Reporting | Audit Level AdjustmentW: Incorporated into AU-6.
AU-07-00AU-7Audit Record Reduction and Report Generationxx
AU-07-01AU-7(1)Audit Record Reduction and Report Generation | Automatic Processingxx
AU-07-02AU-7(2)Audit Record Reduction and Report Generation | Automatic Sort and SearchW: Incorporated into AU-7(1).
AU-08-00AU-8Time Stampsxxx
AU-08-01AU-8(1)Time Stamps | Synchronization with Authoritative Time SourceW: Moved to SC-45(1).
AU-08-02AU-8(2)Time Stamps | Secondary Authoritative Time SourceW: Moved to SC-45(2).
AU-09-00AU-9Protection of Audit Informationxxx
AU-09-01AU-9(1)Protection of Audit Information | Hardware Write-once Media
AU-09-02AU-9(2)Protection of Audit Information | Store on Separate Physical Systems or Componentsx
AU-09-03AU-9(3)Protection of Audit Information | Cryptographic Protectionx
AU-09-04AU-9(4)Protection of Audit Information | Access by Subset of Privileged Usersxx
AU-09-05AU-9(5)Protection of Audit Information | Dual Authorization
AU-09-06AU-9(6)Protection of Audit Information | Read-only Access
AU-09-07AU-9(7)Protection of Audit Information | Store on Component with Different Operating System
AU-10-00AU-10Non-repudiationx
AU-10-01AU-10(1)Non-repudiation | Association of Identities
AU-10-02AU-10(2)Non-repudiation | Validate Binding of Information Producer Identity
AU-10-03AU-10(3)Non-repudiation | Chain of Custody
AU-10-04AU-10(4)Non-repudiation | Validate Binding of Information Reviewer Identity
AU-10-05AU-10(5)Non-repudiation | Digital SignaturesW: Incorporated into SI-7
AU-11-00AU-11Audit Record Retentionxxxx
AU-11-01AU-11(1)Audit Record Retention | Long-term Retrieval Capability
AU-12-00AU-12Audit Record Generationxxx
AU-12-01AU-12(1)Audit Record Generation | System-wide and Time-correlated Audit Trailx
AU-12-02AU-12(2)Audit Record Generation | Standardized Formats
AU-12-03AU-12(3)Audit Record Generation | Changes by Authorized Individualsx
AU-12-04AU-12(4)Audit Record Generation | Query Parameter Audits of Personally Identifiable Information
AU-13-00AU-13Monitoring for Information Disclosure
AU-13-01AU-13(1)Monitoring for Information Disclosure | Use of Automated Tools
AU-13-02AU-13(2)Monitoring for Information Disclosure | Review of Monitored Sites
AU-13-03AU-13(3)Monitoring for Information Disclosure | Unauthorized Replication of Information
AU-14-00AU-14Session Audit
AU-14-01AU-14(1)Session Audit | System Start-up
AU-14-02AU-14(2)Session Audit | Capture and Record ContentW: Incorporated into AU-14.
AU-14-03AU-14(3)Session Audit | Remote Viewing and Listening
AU-15-00AU-15Alternate Audit Logging CapabilityW: Moved to AU-5(5).
AU-16-00AU-16Cross-organizational Audit Logging
AU-16-01AU-16(1)Cross-organizational Audit Logging | Identity Preservation
AU-16-02AU-16(2)Cross-organizational Audit Logging | Sharing of Audit Information
AU-16-03AU-16(3)Cross-organizational Audit Logging | Disassociability
CA-01-00CA-1Policy and Proceduresxxxx
CA-02-00CA-2Control Assessmentsxxxx
CA-02-01CA-2(1)Control Assessments | Independent Assessorsxx
CA-02-02CA-2(2)Control Assessments | Specialized Assessmentsx
CA-02-03CA-2(3)Control Assessments | Leveraging Results from External Organizations
CA-03-00CA-3Information Exchangexxx
CA-03-01CA-3(1)Information Exchange | Unclassified National Security System ConnectionsW: Moved to SC-7(25).
CA-03-02CA-3(2)Information Exchange | Classified National Security System ConnectionsW: Moved to SC-7(26).
CA-03-03CA-3(3)Information Exchange | Unclassified Non-national Security System ConnectionsW: Moved to SC-7(27).
CA-03-04CA-3(4)Information Exchange | Connections to Public NetworksW: Moved to SC-7(28).
CA-03-05CA-3(5)Information Exchange | Restrictions on External System ConnectionsW: Incorporated into SC-7(5).
CA-03-06CA-3(6)Information Exchange | Transfer Authorizationsx
CA-03-07CA-3(7)Information Exchange | Transitive Information Exchanges
CA-04-00CA-4Security CertificationW: Incorporated into CA-2.
CA-05-00CA-5Plan of Action and Milestonesxxxx
CA-05-01CA-5(1)Plan of Action and Milestones | Automation Support for Accuracy and Currency
CA-06-00CA-6Authorizationxxxx
CA-06-01CA-6(1)Authorization | Joint Authorization — Intra-organization
CA-06-02CA-6(2)Authorization | Joint Authorization — Inter-organization
CA-07-00CA-7Continuous Monitoringxxxx
CA-07-01CA-7(1)Continuous Monitoring | Independent Assessmentxx
CA-07-02CA-7(2)Continuous Monitoring | Types of AssessmentsW: Incorporated into CA-2.
CA-07-03CA-7(3)Continuous Monitoring | Trend Analyses
CA-07-04CA-7(4)Continuous Monitoring | Risk Monitoringxxxx
CA-07-05CA-7(5)Continuous Monitoring | Consistency Analysis
CA-07-06CA-7(6)Continuous Monitoring | Automation Support for Monitoring
CA-08-00CA-8Penetration Testingx
CA-08-01CA-8(1)Penetration Testing | Independent Penetration Testing Agent or Teamx
CA-08-02CA-8(2)Penetration Testing | Red Team Exercises
CA-08-03CA-8(3)Penetration Testing | Facility Penetration Testing
CA-09-00CA-9Internal System Connectionsxxx
CA-09-01CA-9(1)Internal System Connections | Compliance Checks
CM-01-00CM-1Policy and Proceduresxxxx
CM-02-00CM-2Baseline Configurationxxx
CM-02-01CM-2(1)Baseline Configuration | Reviews and UpdatesW: Incorporated into CM-2.
CM-02-02CM-2(2)Baseline Configuration | Automation Support for Accuracy and Currencyxx
CM-02-03CM-2(3)Baseline Configuration | Retention of Previous Configurationsxx
CM-02-04CM-2(4)Baseline Configuration | Unauthorized SoftwareW: Incorporated into CM-7.
CM-02-05CM-2(5)Baseline Configuration | Authorized SoftwareW: Incorporated into CM-7.
CM-02-06CM-2(6)Baseline Configuration | Development and Test Environments
CM-02-07CM-2(7)Baseline Configuration | Configure Systems and Components for High-risk Areasxx
CM-03-00CM-3Configuration Change Controlxx
CM-03-01CM-3(1)Configuration Change Control | Automated Documentation, Notification, and Prohibition of Changesx
CM-03-02CM-3(2)Configuration Change Control | Testing, Validation, and Documentation of Changesxx
CM-03-03CM-3(3)Configuration Change Control | Automated Change Implementation
CM-03-04CM-3(4)Configuration Change Control | Security and Privacy Representativesxx
CM-03-05CM-3(5)Configuration Change Control | Automated Security Response
CM-03-06CM-3(6)Configuration Change Control | Cryptography Managementx
CM-03-07CM-3(7)Configuration Change Control | Review System Changes
CM-03-08CM-3(8)Configuration Change Control | Prevent or Restrict Configuration Changes
CM-04-00CM-4Impact Analysesxxxx
CM-04-01CM-4(1)Impact Analyses | Separate Test Environmentsx
CM-04-02CM-4(2)Impact Analyses | Verification of Controlsxx
CM-05-00CM-5Access Restrictions for Changexxx
CM-05-01CM-5(1)Access Restrictions for Change | Automated Access Enforcement and Audit Recordsx
CM-05-02CM-5(2)Access Restrictions for Change | Review System ChangesW: Incorporated into CM-3(7).
CM-05-03CM-5(3)Access Restrictions for Change | Signed ComponentsW: Moved to CM-14.
CM-05-04CM-5(4)Access Restrictions for Change | Dual Authorization
CM-05-05CM-5(5)Access Restrictions for Change | Privilege Limitation for Production and Operation
CM-05-06CM-5(6)Access Restrictions for Change | Limit Library Privileges
CM-05-07CM-5(7)Access Restrictions for Change | Automatic Implementation of Security SafeguardsW: Incorporated into SI-7.
CM-06-00CM-6Configuration Settingsxxx
CM-06-01CM-6(1)Configuration Settings | Automated Management, Application, and Verificationx
CM-06-02CM-6(2)Configuration Settings | Respond to Unauthorized Changesx
CM-06-03CM-6(3)Configuration Settings | Unauthorized Change DetectionW: Incorporated into SI-7.
CM-06-04CM-6(4)Configuration Settings | Conformance DemonstrationW: Incorporated into CM-4.
CM-07-00CM-7Least Functionalityxxx
CM-07-01CM-7(1)Least Functionality | Periodic Reviewxx
CM-07-02CM-7(2)Least Functionality | Prevent Program Executionxx
CM-07-03CM-7(3)Least Functionality | Registration Compliance
CM-07-04CM-7(4)Least Functionality | Unauthorized Software
CM-07-05CM-7(5)Least Functionality | Authorized Softwarexx
CM-07-06CM-7(6)Least Functionality | Confined Environments with Limited Privileges
CM-07-07CM-7(7)Least Functionality | Code Execution in Protected Environments
CM-07-08CM-7(8)Least Functionality | Binary or Machine Executable Code
CM-07-09CM-7(9)Least Functionality | Prohibiting The Use of Unauthorized Hardware
CM-08-00CM-8System Component Inventoryxxx
CM-08-01CM-8(1)System Component Inventory | Updates During Installation and Removalxx
CM-08-02CM-8(2)System Component Inventory | Automated Maintenancex
CM-08-03CM-8(3)System Component Inventory | Automated Unauthorized Component Detectionxx
CM-08-04CM-8(4)System Component Inventory | Accountability Informationx
CM-08-05CM-8(5)System Component Inventory | No Duplicate Accounting of ComponentsW: Incorporated into CM-8.
CM-08-06CM-8(6)System Component Inventory | Assessed Configurations and Approved Deviations
CM-08-07CM-8(7)System Component Inventory | Centralized Repository
CM-08-08CM-8(8)System Component Inventory | Automated Location Tracking
CM-08-09CM-8(9)System Component Inventory | Assignment of Components to Systems
CM-09-00CM-9Configuration Management Planxx
CM-09-01CM-9(1)Configuration Management Plan | Assignment of Responsibility
CM-10-00CM-10Software Usage Restrictionsxxx
CM-10-01CM-10(1)Software Usage Restrictions | Open-source Software
CM-11-00CM-11User-installed Softwarexxx
CM-11-01CM-11(1)User-installed Software | Alerts for Unauthorized InstallationsW: Incorporated into CM-8(3).
CM-11-02CM-11(2)User-installed Software | Software Installation with Privileged Status
CM-11-03CM-11(3)User-installed Software | Automated Enforcement and Monitoring
CM-12-00CM-12Information Locationxx
CM-12-01CM-12(1)Information Location | Automated Tools to Support Information Locationxx
CM-13-00CM-13Data Action Mapping
CM-14-00CM-14Signed Components
CP-01-00CP-1Policy and Proceduresxxx
CP-02-00CP-2Contingency Planxxx
CP-02-01CP-2(1)Contingency Plan | Coordinate with Related Plansxx
CP-02-02CP-2(2)Contingency Plan | Capacity Planningx
CP-02-03CP-2(3)Contingency Plan | Resume Mission and Business Functionsxx
CP-02-04CP-2(4)Contingency Plan | Resume All Mission and Business FunctionsW: Incorporated into CP-2(3).
CP-02-05CP-2(5)Contingency Plan | Continue Mission and Business Functionsx
CP-02-06CP-2(6)Contingency Plan | Alternate Processing and Storage Sites
CP-02-07CP-2(7)Contingency Plan | Coordinate with External Service Providers
CP-02-08CP-2(8)Contingency Plan | Identify Critical Assetsxx
CP-03-00CP-3Contingency Trainingxxx
CP-03-01CP-3(1)Contingency Training | Simulated Eventsx
CP-03-02CP-3(2)Contingency Training | Mechanisms Used in Training Environments
CP-04-00CP-4Contingency Plan Testingxxx
CP-04-01CP-4(1)Contingency Plan Testing | Coordinate with Related Plansxx
CP-04-02CP-4(2)Contingency Plan Testing | Alternate Processing Sitex
CP-04-03CP-4(3)Contingency Plan Testing | Automated Testing
CP-04-04CP-4(4)Contingency Plan Testing | Full Recovery and Reconstitution
CP-04-05CP-4(5)Contingency Plan Testing | Self-challenge
CP-05-00CP-5Contingency Plan UpdateW: Incorporated into CP-2.
CP-06-00CP-6Alternate Storage Sitexx
CP-06-01CP-6(1)Alternate Storage Site | Separation from Primary Sitexx
CP-06-02CP-6(2)Alternate Storage Site | Recovery Time and Recovery Point Objectivesx
CP-06-03CP-6(3)Alternate Storage Site | Accessibilityxx
CP-07-00CP-7Alternate Processing Sitexx
CP-07-01CP-7(1)Alternate Processing Site | Separation from Primary Sitexx
CP-07-02CP-7(2)Alternate Processing Site | Accessibilityxx
CP-07-03CP-7(3)Alternate Processing Site | Priority of Servicexx
CP-07-04CP-7(4)Alternate Processing Site | Preparation for Usex
CP-07-05CP-7(5)Alternate Processing Site | Equivalent Information Security SafeguardsW: Incorporated into CP-7.
CP-07-06CP-7(6)Alternate Processing Site | Inability to Return to Primary Site
CP-08-00CP-8Telecommunications Servicesxx
CP-08-01CP-8(1)Telecommunications Services | Priority of Service Provisionsxx
CP-08-02CP-8(2)Telecommunications Services | Single Points of Failurexx
CP-08-03CP-8(3)Telecommunications Services | Separation of Primary and Alternate Providersx
CP-08-04CP-8(4)Telecommunications Services | Provider Contingency Planx
CP-08-05CP-8(5)Telecommunications Services | Alternate Telecommunication Service Testing
CP-09-00CP-9System Backupxxx
CP-09-01CP-9(1)System Backup | Testing for Reliability and Integrityxx
CP-09-02CP-9(2)System Backup | Test Restoration Using Samplingx
CP-09-03CP-9(3)System Backup | Separate Storage for Critical Informationx
CP-09-04CP-9(4)System Backup | Protection from Unauthorized ModificationW: Incorporated into CP-9.
CP-09-05CP-9(5)System Backup | Transfer to Alternate Storage Sitex
CP-09-06CP-9(6)System Backup | Redundant Secondary System
CP-09-07CP-9(7)System Backup | Dual Authorization
CP-09-08CP-9(8)System Backup | Cryptographic Protectionxx
CP-10-00CP-10System Recovery and Reconstitutionxxx
CP-10-01CP-10(1)System Recovery and Reconstitution | Contingency Plan TestingW: Incorporated into CP-4.
CP-10-02CP-10(2)System Recovery and Reconstitution | Transaction Recoveryxx
CP-10-03CP-10(3)System Recovery and Reconstitution | Compensating Security ControlsW: Addressed through tailoring.
CP-10-04CP-10(4)System Recovery and Reconstitution | Restore Within Time Periodx
CP-10-05CP-10(5)System Recovery and Reconstitution | Failover CapabilityW: Incorporated into SI-13.
CP-10-06CP-10(6)System Recovery and Reconstitution | Component Protection
CP-11-00CP-11Alternate Communications Protocols
CP-12-00CP-12Safe Mode
CP-13-00CP-13Alternative Security Mechanisms
IA-01-00IA-1Policy and Proceduresxxx
IA-02-00IA-2Identification and Authentication (organizational Users)xxx
IA-02-01IA-2(1)Identification and Authentication (organizational Users) | Multi-factor Authentication to Privileged Accountsxxx
IA-02-02IA-2(2)Identification and Authentication (organizational Users) | Multi-factor Authentication to Non-privileged Accountsxxx
IA-02-03IA-2(3)Identification and Authentication (organizational Users) | Local Access to Privileged AccountsW: Incorporated into IA-2(1)(2).
IA-02-04IA-2(4)Identification and Authentication (organizational Users) | Local Access to Non-privileged AccountsW: Incorporated into IA-2(1)(2).
IA-02-05IA-2(5)Identification and Authentication (organizational Users) | Individual Authentication with Group Authenticationx
IA-02-06IA-2(6)Identification and Authentication (organizational Users) | Access to Accounts — Separate Device
IA-02-07IA-2(7)Identification and Authentication (organizational Users) | Access to Non-privileged Accounts — Separate DeviceW: Incorporated into IA-2(6).
IA-02-08IA-2(8)Identification and Authentication (organizational Users) | Access to Accounts — Replay Resistantxxx
IA-02-09IA-2(9)Identification and Authentication (organizational Users) | Network Access to Non-privileged Accounts — Replay ResistantW: Incorporated into IA-2(8).
IA-02-10IA-2(10)Identification and Authentication (organizational Users) | Single Sign-on
IA-02-11IA-2(11)Identification and Authentication (organizational Users) | Remote Access — Separate DeviceW: Incorporated into IA-2(6).
IA-02-12IA-2(12)Identification and Authentication (organizational Users) | Acceptance of PIV Credentialsxxx
IA-02-13IA-2(13)Identification and Authentication (organizational Users) | Out-of-band Authentication
IA-03-00IA-3Device Identification and Authenticationxx
IA-03-01IA-3(1)Device Identification and Authentication | Cryptographic Bidirectional Authentication
IA-03-02IA-3(2)Device Identification and Authentication | Cryptographic Bidirectional Network AuthenticationW: Incorporated into IA-3(1).
IA-03-03IA-3(3)Device Identification and Authentication | Dynamic Address Allocation
IA-03-04IA-3(4)Device Identification and Authentication | Device Attestation
IA-04-00IA-4Identifier Managementxxx
IA-04-01IA-4(1)Identifier Management | Prohibit Account Identifiers as Public Identifiers
IA-04-02IA-4(2)Identifier Management | Supervisor AuthorizationW: Incorporated into IA-12(1).
IA-04-03IA-4(3)Identifier Management | Multiple Forms of CertificationW: Incorporated into IA-12(2)
IA-04-04IA-4(4)Identifier Management | Identify User Statusxx
IA-04-05IA-4(5)Identifier Management | Dynamic Management
IA-04-06IA-4(6)Identifier Management | Cross-organization Management
IA-04-07IA-4(7)Identifier Management | In-person RegistrationW: Incorporated into IA-12(4)
IA-04-08IA-4(8)Identifier Management | Pairwise Pseudonymous Identifiers
IA-04-09IA-4(9)Identifier Management | Attribute Maintenance and Protection
IA-05-00IA-5Authenticator Managementxxx
IA-05-01IA-5(1)Authenticator Management | Password-based Authenticationxxx
IA-05-02IA-5(2)Authenticator Management | Public Key-based Authenticationxx
IA-05-03IA-5(3)Authenticator Management | In-person or Trusted External Party RegistrationW: Incorporated into IA-12(4)
IA-05-04IA-5(4)Authenticator Management | Automated Support for Password Strength DeterminationW: Incorporated into IA-5(1).
IA-05-05IA-5(5)Authenticator Management | Change Authenticators Prior to Delivery
IA-05-06IA-5(6)Authenticator Management | Protection of Authenticatorsxx
IA-05-07IA-5(7)Authenticator Management | No Embedded Unencrypted Static Authenticators
IA-05-08IA-5(8)Authenticator Management | Multiple System Accounts
IA-05-09IA-5(9)Authenticator Management | Federated Credential Management
IA-05-10IA-5(10)Authenticator Management | Dynamic Credential Binding
IA-05-11IA-5(11)Authenticator Management | Hardware Token-based AuthenticationW: Incorporated into IA-2(1) and IA-2(2).
IA-05-12IA-5(12)Authenticator Management | Biometric Authentication Performance
IA-05-13IA-5(13)Authenticator Management | Expiration of Cached Authenticators
IA-05-14IA-5(14)Authenticator Management | Managing Content of PKI Trust Stores
IA-05-15IA-5(15)Authenticator Management | GSA-approved Products and Services
IA-05-16IA-5(16)Authenticator Management | In-person or Trusted External Party Authenticator Issuance
IA-05-17IA-5(17)Authenticator Management | Presentation Attack Detection for Biometric Authenticators
IA-05-18IA-5(18)Authenticator Management | Password Managers
IA-06-00IA-6Authentication Feedbackxxx
IA-07-00IA-7Cryptographic Module Authenticationxxx
IA-08-00IA-8Identification and Authentication (non-organizational Users)xxx
IA-08-01IA-8(1)Identification and Authentication (non-organizational Users) | Acceptance of PIV Credentials from Other Agenciesxxx
IA-08-02IA-8(2)Identification and Authentication (non-organizational Users) | Acceptance of External Authenticatorsxxx
IA-08-03IA-8(3)Identification and Authentication (non-organizational Users) | Use of FICAM-approved ProductsW: Incorporated into IA-8(2).
IA-08-04IA-8(4)Identification and Authentication (non-organizational Users) | Use of Defined Profilesxxx
IA-08-05IA-8(5)Identification and Authentication (non-organizational Users) | Acceptance of PIV-I Credentials
IA-08-06IA-8(6)Identification and Authentication (non-organizational Users) | Disassociability
IA-09-00IA-9Service Identification and Authentication
IA-09-01IA-9(1)Service Identification and Authentication | Information ExchangeW: Incorporated into IA-9.
IA-09-02IA-9(2)Service Identification and Authentication | Transmission of DecisionsW: Incorporated into IA-9.
IA-10-00IA-10Adaptive Authentication
IA-11-00IA-11Re-authenticationxxx
IA-12-00IA-12Identity Proofingxx
IA-12-01IA-12(1)Identity Proofing | Supervisor Authorization
IA-12-02IA-12(2)Identity Proofing | Identity Evidencexx
IA-12-03IA-12(3)Identity Proofing | Identity Evidence Validation and Verificationxx
IA-12-04IA-12(4)Identity Proofing | In-person Validation and Verificationx
IA-12-05IA-12(5)Identity Proofing | Address Confirmationxx
IA-12-06IA-12(6)Identity Proofing | Accept Externally-proofed Identities
IR-01-00IR-1Policy and Proceduresxxxx
IR-02-00IR-2Incident Response Trainingxxxx
IR-02-01IR-2(1)Incident Response Training | Simulated Eventsx
IR-02-02IR-2(2)Incident Response Training | Automated Training Environmentsx
IR-02-03IR-2(3)Incident Response Training | Breachx
IR-03-00IR-3Incident Response Testingxxx
IR-03-01IR-3(1)Incident Response Testing | Automated Testing
IR-03-02IR-3(2)Incident Response Testing | Coordination with Related Plansxx
IR-03-03IR-3(3)Incident Response Testing | Continuous Improvement
IR-04-00IR-4Incident Handlingxxxx
IR-04-01IR-4(1)Incident Handling | Automated Incident Handling Processesxx
IR-04-02IR-4(2)Incident Handling | Dynamic Reconfiguration
IR-04-03IR-4(3)Incident Handling | Continuity of Operations
IR-04-04IR-4(4)Incident Handling | Information Correlationx
IR-04-05IR-4(5)Incident Handling | Automatic Disabling of System
IR-04-06IR-4(6)Incident Handling | Insider Threats
IR-04-07IR-4(7)Incident Handling | Insider Threats — Intra-organization Coordination
IR-04-08IR-4(8)Incident Handling | Correlation with External Organizations
IR-04-09IR-4(9)Incident Handling | Dynamic Response Capability
IR-04-10IR-4(10)Incident Handling | Supply Chain Coordination
IR-04-11IR-4(11)Incident Handling | Integrated Incident Response Teamx
IR-04-12IR-4(12)Incident Handling | Malicious Code and Forensic Analysis
IR-04-13IR-4(13)Incident Handling | Behavior Analysis
IR-04-14IR-4(14)Incident Handling | Security Operations Center
IR-04-15IR-4(15)Incident Handling | Public Relations and Reputation Repair
IR-05-00IR-5Incident Monitoringxxxx
IR-05-01IR-5(1)Incident Monitoring | Automated Tracking, Data Collection, and Analysisx
IR-06-00IR-6Incident Reportingxxxx
IR-06-01IR-6(1)Incident Reporting | Automated Reportingxx
IR-06-02IR-6(2)Incident Reporting | Vulnerabilities Related to Incidents
IR-06-03IR-6(3)Incident Reporting | Supply Chain Coordinationxx
IR-07-00IR-7Incident Response Assistancexxxx
IR-07-01IR-7(1)Incident Response Assistance | Automation Support for Availability of Information and Supportxx
IR-07-02IR-7(2)Incident Response Assistance | Coordination with External Providers
IR-08-00IR-8Incident Response Planxxxx
IR-08-01IR-8(1)Incident Response Plan | Breachesx
IR-09-00IR-9Information Spillage Response
IR-09-01IR-9(1)Information Spillage Response | Responsible PersonnelW: Incorporated into IR-9
IR-09-02IR-9(2)Information Spillage Response | Training
IR-09-03IR-9(3)Information Spillage Response | Post-spill Operations
IR-09-04IR-9(4)Information Spillage Response | Exposure to Unauthorized Personnel
IR-10-00IR-10Incident AnalysisW: Moved to IR-4(11).
MA-01-00MA-1Policy and Proceduresxxx
MA-02-00MA-2Controlled Maintenancexxx
MA-02-01MA-2(1)Controlled Maintenance | Record ContentW: Incorporated into MA-2.
MA-02-02MA-2(2)Controlled Maintenance | Automated Maintenance Activitiesx
MA-03-00MA-3Maintenance Toolsxx
MA-03-01MA-3(1)Maintenance Tools | Inspect Toolsxx
MA-03-02MA-3(2)Maintenance Tools | Inspect Mediaxx
MA-03-03MA-3(3)Maintenance Tools | Prevent Unauthorized Removalxx
MA-03-04MA-3(4)Maintenance Tools | Restricted Tool Use
MA-03-05MA-3(5)Maintenance Tools | Execution with Privilege
MA-03-06MA-3(6)Maintenance Tools | Software Updates and Patches
MA-04-00MA-4Nonlocal Maintenancexxx
MA-04-01MA-4(1)Nonlocal Maintenance | Logging and Review
MA-04-02MA-4(2)Nonlocal Maintenance | Logically separated communications paths.W: Incorporated into MA-1 and MA-4.
MA-04-03MA-4(3)Nonlocal Maintenance | Comparable Security and Sanitizationx
MA-04-04MA-4(4)Nonlocal Maintenance | Authentication and Separation of Maintenance Sessions
MA-04-05MA-4(5)Nonlocal Maintenance | Approvals and Notifications
MA-04-06MA-4(6)Nonlocal Maintenance | Cryptographic Protection
MA-04-07MA-4(7)Nonlocal Maintenance | Disconnect Verification
MA-05-00MA-5Maintenance Personnelxxx
MA-05-01MA-5(1)Maintenance Personnel | Individuals Without Appropriate Accessx

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .