Attachment 11 - C-SCRM Plan (Template).xlsx
XLSX spreadsheet 119 KB Posted
- Attached to
- GSA Global Supply OCONUS Logistics Support Solutions CENTCOM Federal contract opportunity
- Solicitation number
- 47QSCC23R0040
- Issued by
- GSA Federal Acquisition Service
About this file
This document provides a Supply Chain Risk Management Plan template for assessing risks in an organization's supply chain. The template includes questions on general supply chain information, supply chain management and supplier governance, information security, physical security, personnel security, supply chain integrity, supply chain resilience, and supply chain risk management. Respondents are instructed to provide answers in the gray lines under each question. If a question does not apply, the respondent should state N/A and provide context. Supporting documents can be attached and referenced. The template is intended to gather initial baseline information and additional follow-up may be required.
View the file
Other files for this federal contract opportunity
Show all 22
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Old Instructions
SUPPLY CHAIN RISK MANAGEMENT PLAN TEMPLATE
| INSTRUCTIONS |
| INTRODUCTION: |
| US adversaries have attacked our nation's supply chains and compromised Federal Government systems, capitalizing on security weaknesses in US companies and third party affiliates. It is incumbent on GSA's industrial base to implement vigilant Supply Chain Risk Management procedures. |
| TEMPLATE COMPLETION INSTRUCTIONS: |
| ● Provide a contact (name, email, and phone number) for questions, support, or additional information related to the questionnaire to the respondents. |
| ● Please provide your responses in the gray shaded lines of the template under Column C, Vendor Response. |
| ● Please provide a response to each ‘Yes’, ‘No’ question as relevant to the offering. |
| ● If the question does not apply to your organization, please answer ‘N/A’ and provide a supporting statement of applicability if not relevant to the offering in consideration. |
| ● A response of ‘Alternate’ may be used if a particular supply chain risk can be addressed in alternative ways and not directly through compliance with a standard or framework. |
| ● Please attach supporting documents to the completed SCRM Plan Template. You may provide links when submitting if documentation is available online and accessible. |
| ● We recommend designating one primary POC from your organization who will collaborate with the appropriate POCs/teams/vendor/supplier to coordinate and collect and compile responses for each section. The appropriate POCs within each organization will vary and may consist of individuals in information technology, acquisition, procurement, supply chain, or security offices. While related, each section is design to be relevant to a different aspect of your organization. This template is intended to gather an initial and consistent baseline and additional follow-up questions from the organization, or other documentation, may be warranted. |
Old Template
SUPPLY CHAIN RISK MANAGEMENT PLAN TEMPLATE
| CONTACT INFORMATION |
| Name of Respondent: |
| Title: |
| Name of Organization: |
| Phone number: |
| Email: |
| SECT. 1 | GENERAL QUESTIONS | VENDOR RESPONSE |
| Identity - including that of each parent and/or subsidiary corporate entities. | ||
| 1.1 | Have you identified your key suppliers? |
1.2 Do you verify the company ownership?
1.3 If so, do you confirm that the company is under U.S. ownership?
1.4 If you use distributors, do you investigate them for potential threats?
1.5 Are any subcontractors and/or suppliers located outside the United States or its territories? If 'Yes', then please list company name and foreign country location.
1.6 Do you have controls fully aligned to NIST SP 800-161, Supply Chain Risk Management Practices for Federal Information Systems and Organization? If yes, please explain in Section 1.6. If no, please proceed to Section 2.1.
1.7 Please provide evidence of alignment with NIST SP-800-161.
| SECT. 2 | SUPPLY CHAIN MANAGEMENT AND SUPPLIER GOVERANCE |
| General | |
| 2.1 | Do you have policies to ensure timely notification of updated risk management information previously provided to us? [Yes or No]. If "yes" please explain the process. |
| Information Communications Technology (ICT) Supply Chain Management | |
| 2.2 | Do you have a documented Quality Management System (QMS) for your ICT supply chain operation based on an industry standard or framework? [Yes or No]. If "yes" please provide QMS documentation. |
| Supplier Governance | |
| 2.3 | Do you have written Supply Chain Risk Management (SCRM) requirements in your contracts with your suppliers? [Yes or No] If "yes" please provide SCRM requirements. |
2.4 Describe how you verify that your suppliers are meeting SCRM contractual terms and conditions, including, where applicable, requirements to be passed down to sub-suppliers.
| SECT. 3 | INFORMATION SECURITY |
| Identify | |
| 3.1 | Describe your process to verify that information is classified according to legal, regulatory, or internal sensitivity requirements? |
3.2 How often do you review and update to those policies and procedures? When is the most recent review?
| Detect | |
| 3.4 | Do you have defined and documented incident detection practices that outline which actions should be taken in the case of an information security or cybersecurity event? [Yes or No]. If "yes" please describe. |
3.5 Are cybersecurity events centrally logged, tracked, and continuously monitored? Please explain how events are monitored.
3.6 Do you deploy anti-malware software throughout your environment? [Yes or No] If "no" please explain.
3.7 Do you have a documented incident response process and a dedicated incident response team (CSIRT - Computer Security Incident Response Team)? [Yes or No] If "no" please explain.
| SECT. 4 | PHYSICAL SECURITY |
| General | |
| 4.1 | Is the entity (organization, operational unit, facility, etc.) currently covered by an unrestricted/unlimited National Industrial Security Program (NISP) Facility Clearance (FCL) or a related U.S. government program such as C- TPAT that certifies the entity as meeting appropriate physical security standards? [Yes or No] If "yes" please state the program that certified you and date of last certification. |
4.2 Do you have documented security policies and procedures that address the control of physical access to cyber assets (network devices, data facilities, patch panels, industrial control systems, programmable logic, etc.)? [Yes or No] If "yes" please describe.
4.3 To what industry standards/controls do you adhere? (e.g., NIST publication, ISO, UL, etc.)
4.4 How often do you review and update those policies and procedures and when was the most recent review?
4.5 Do you have a documented Security Incident Response process covering physical security incidents? (e.g., potential intruder access, missing equipment, etc.) [Yes or No] If "yes" please describe.
| Physical Security In-transit | |
| 4.6 | What requirements, if any, are in place to ensure the use of Original Equipment Manufacturer (OEM) or Authorized Distributors for all key components? |
4.7 How do you pass on counterfeit prevention requirements to your third party suppliers?
| SECT. 5 | PERSONNEL SECURITY |
| General | |
| 5.1 | Do you employ a physical security guard presence at your facilities? [Yes or No] If "yes" please describe. |
5.2 Describe if physical security practices are formally governed, documented, maintained, and enforced?
| Onboarding | |
| 5.3 | Do you have policies for conducting background checks of your employees as permitted by the country in which you operate? [Yes or No] If "yes" please describe. |
| SECT. 6 | SUPPLY CHAIN INTEGRITY |
| General | |
| 6.1 | What are your processes for managing third-party products and component defects throughout their lifecycle? |
6.2 What provisions for auditing are included within supplier contracts?
6.3 How do you pass down HW/SW products or services integrity requirements to third party suppliers?
6.4 Do you have processes in place for addressing reuse and/or recycle of HW products? [Yes or No] If "yes" please describe.
| SECT. 7 | SUPPLY CHAIN RESILIENCE |
| General | |
| 7.1 | Does your organization have a formal process for ensuring supply chain resilience as part of your product offering SCRM practices? [Yes or No] . If "yes" please describe. |
| Supply Chain Disruption Risk Management (Business Continuity) | |
| 7.2 | Can personnel work remotely? [Yes or No] If yes, do you require a licensed VPN or MFA solution to connect? |
7.3 Do you currently have a data backup policy in place?
7.4 Has your organization conducted vulnerability assessments, risk assessment, or other calculations to identify what impact physical risks associated with climate change (e.g., increases in precipitation-driven flooding, extreme heat events, and inundation due to sea level rise and storm surge) might have on your assets, products, and/or services?
7.5 If yes, describe the assessment process. If assessment results are reported (CDP, GRI, Sustainability or Corporate Responsibility reports), provide the reporting platform and/or report.
7.6 Does your organization have a disaster response plan that includes contingency plans and response protocols for potential short-term acute events (e.g., hurricane, earthquake, flooding, and etc.) and long-term climate change impact (e.g.; changes in precipitation, increased average temperature, and sea level rise)?
7.7 If yes or no, how do or will you deal with potential increases in frequency, severity, or duration of weather events?
7.8 If yes, describe which assets, products, services would most significantly disrupt operations if they experienced short term acute damage (immediate failure, either temporary or catastrophic).
7.9 If yes, describe which assets, products, services, would most significantly disrupt operations if they experienced gradual long-term cumulative damage (slower degradation; greater wear and tear).
https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-161.pdf Copy of SP 800-53B
| SORT-AS | Control Identifier | Control (or Control Enhancement) Name | Withdrawn | Privacy Baseline | Security Control Baseline - Low | Security Control Baseline - Moderate | Security Control Baseline - High |
| AC-01-00 | AC-1 | Policy and Procedures | x | x | x | x | |
| AC-02-00 | AC-2 | Account Management | x | x | x | ||
| AC-02-01 | AC-2(1) | Account Management | Automated System Account Management | x | x | |||
| AC-02-02 | AC-2(2) | Account Management | Automated Temporary and Emergency Account Management | x | x | |||
| AC-02-03 | AC-2(3) | Account Management | Disable Accounts | x | x | |||
| AC-02-04 | AC-2(4) | Account Management | Automated Audit Actions | x | x | |||
| AC-02-05 | AC-2(5) | Account Management | Inactivity Logout | x | x | |||
| AC-02-06 | AC-2(6) | Account Management | Dynamic Privilege Management | |||||
| AC-02-07 | AC-2(7) | Account Management | Privileged User Accounts | |||||
| AC-02-08 | AC-2(8) | Account Management | Dynamic Account Management | |||||
| AC-02-09 | AC-2(9) | Account Management | Restrictions on Use of Shared and Group Accounts | |||||
| AC-02-10 | AC-2(10) | Account Management | Shared and Group Account Credential Change | W: Incorporated into AC-2k. | ||||
| AC-02-11 | AC-2(11) | Account Management | Usage Conditions | x | ||||
| AC-02-12 | AC-2(12) | Account Management | Account Monitoring for Atypical Usage | x | ||||
| AC-02-13 | AC-2(13) | Account Management | Disable Accounts for High-risk Individuals | x | x | |||
| AC-03-00 | AC-3 | Access Enforcement | x | x | x | ||
| AC-03-01 | AC-3(1) | Access Enforcement | Restricted Access to Privileged Functions | W: Incorporated into AC-6. | ||||
| AC-03-02 | AC-3(2) | Access Enforcement | Dual Authorization | |||||
| AC-03-03 | AC-3(3) | Access Enforcement | Mandatory Access Control | |||||
| AC-03-04 | AC-3(4) | Access Enforcement | Discretionary Access Control | |||||
| AC-03-05 | AC-3(5) | Access Enforcement | Security-relevant Information | |||||
| AC-03-06 | AC-3(6) | Access Enforcement | Protection of User and System Information | W: Incorporated into MP-4 and SC-28. | ||||
| AC-03-07 | AC-3(7) | Access Enforcement | Role-based Access Control | |||||
| AC-03-08 | AC-3(8) | Access Enforcement | Revocation of Access Authorizations | |||||
| AC-03-09 | AC-3(9) | Access Enforcement | Controlled Release | |||||
| AC-03-10 | AC-3(10) | Access Enforcement | Audited Override of Access Control Mechanisms | |||||
| AC-03-11 | AC-3(11) | Access Enforcement | Restrict Access to Specific Information Types | |||||
| AC-03-12 | AC-3(12) | Access Enforcement | Assert and Enforce Application Access | |||||
| AC-03-13 | AC-3(13) | Access Enforcement | Attribute-based Access Control | |||||
| AC-03-14 | AC-3(14) | Access Enforcement | Individual Access | x | ||||
| AC-03-15 | AC-3(15) | Access Enforcement | Discretionary and Mandatory Access Control | |||||
| AC-04-00 | AC-4 | Information Flow Enforcement | x | x | |||
| AC-04-01 | AC-4(1) | Information Flow Enforcement | Object Security and Privacy Attributes | |||||
| AC-04-02 | AC-4(2) | Information Flow Enforcement | Processing Domains | |||||
| AC-04-03 | AC-4(3) | Information Flow Enforcement | Dynamic Information Flow Control | |||||
| AC-04-04 | AC-4(4) | Information Flow Enforcement | Flow Control of Encrypted Information | x | ||||
| AC-04-05 | AC-4(5) | Information Flow Enforcement | Embedded Data Types | |||||
| AC-04-06 | AC-4(6) | Information Flow Enforcement | Metadata | |||||
| AC-04-07 | AC-4(7) | Information Flow Enforcement | One-way Flow Mechanisms | |||||
| AC-04-08 | AC-4(8) | Information Flow Enforcement | Security and Privacy Policy Filters | |||||
| AC-04-09 | AC-4(9) | Information Flow Enforcement | Human Reviews | |||||
| AC-04-10 | AC-4(10) | Information Flow Enforcement | Enable and Disable Security or Privacy Policy Filters | |||||
| AC-04-11 | AC-4(11) | Information Flow Enforcement | Configuration of Security or Privacy Policy Filters | |||||
| AC-04-12 | AC-4(12) | Information Flow Enforcement | Data Type Identifiers | |||||
| AC-04-13 | AC-4(13) | Information Flow Enforcement | Decomposition into Policy-relevant Subcomponents | |||||
| AC-04-14 | AC-4(14) | Information Flow Enforcement | Security or Privacy Policy Filter Constraints | |||||
| AC-04-15 | AC-4(15) | Information Flow Enforcement | Detection of Unsanctioned Information | |||||
| AC-04-16 | AC-4(16) | Information Flow Enforcement | Information Transfers on Interconnected Systems | W: Incorporated into AC-4. | ||||
| AC-04-17 | AC-4(17) | Information Flow Enforcement | Domain Authentication | |||||
| AC-04-18 | AC-4(18) | Information Flow Enforcement | Security Attribute Binding | W: Incorporated into AC-16. | ||||
| AC-04-19 | AC-4(19) | Information Flow Enforcement | Validation of Metadata | |||||
| AC-04-20 | AC-4(20) | Information Flow Enforcement | Approved Solutions | |||||
| AC-04-21 | AC-4(21) | Information Flow Enforcement | Physical or Logical Separation of Information Flows | |||||
| AC-04-22 | AC-4(22) | Information Flow Enforcement | Access Only | |||||
| AC-04-23 | AC-4(23) | Information Flow Enforcement | Modify Non-releasable Information | |||||
| AC-04-24 | AC-4(24) | Information Flow Enforcement | Internal Normalized Format | |||||
| AC-04-25 | AC-4(25) | Information Flow Enforcement | Data Sanitization | |||||
| AC-04-26 | AC-4(26) | Information Flow Enforcement | Audit Filtering Actions | |||||
| AC-04-27 | AC-4(27) | Information Flow Enforcement | Redundant/independent Filtering Mechanisms | |||||
| AC-04-28 | AC-4(28) | Information Flow Enforcement | Linear Filter Pipelines | |||||
| AC-04-29 | AC-4(29) | Information Flow Enforcement | Filter Orchestration Engines | |||||
| AC-04-30 | AC-4(30) | Information Flow Enforcement | Filter Mechanisms Using Multiple Processes | |||||
| AC-04-31 | AC-4(31) | Information Flow Enforcement | Failed Content Transfer Prevention | |||||
| AC-04-32 | AC-4(32) | Information Flow Enforcement | Process Requirements for Information Transfer | |||||
| AC-05-00 | AC-5 | Separation of Duties | x | x | |||
| AC-06-00 | AC-6 | Least Privilege | x | x | |||
| AC-06-01 | AC-6(1) | Least Privilege | Authorize Access to Security Functions | x | x | |||
| AC-06-02 | AC-6(2) | Least Privilege | Non-privileged Access for Nonsecurity Functions | x | x | |||
| AC-06-03 | AC-6(3) | Least Privilege | Network Access to Privileged Commands | x | ||||
| AC-06-04 | AC-6(4) | Least Privilege | Separate Processing Domains | |||||
| AC-06-05 | AC-6(5) | Least Privilege | Privileged Accounts | x | x | |||
| AC-06-06 | AC-6(6) | Least Privilege | Privileged Access by Non-organizational Users | |||||
| AC-06-07 | AC-6(7) | Least Privilege | Review of User Privileges | x | x | |||
| AC-06-08 | AC-6(8) | Least Privilege | Privilege Levels for Code Execution | |||||
| AC-06-09 | AC-6(9) | Least Privilege | Log Use of Privileged Functions | x | x | |||
| AC-06-10 | AC-6(10) | Least Privilege | Prohibit Non-privileged Users from Executing Privileged Functions | x | x | |||
| AC-07-00 | AC-7 | Unsuccessful Logon Attempts | x | x | x | ||
| AC-07-01 | AC-7(1) | Unsuccessful Logon Attempts | Automatic Account Lock | W: Incorporated into AC-7. | ||||
| AC-07-02 | AC-7(2) | Unsuccessful Logon Attempts | Purge or Wipe Mobile Device | |||||
| AC-07-03 | AC-7(3) | Unsuccessful Logon Attempts | Biometric Attempt Limiting | |||||
| AC-07-04 | AC-7(4) | Unsuccessful Logon Attempts | Use of Alternate Authentication Factor | |||||
| AC-08-00 | AC-8 | System Use Notification | x | x | x | ||
| AC-09-00 | AC-9 | Previous Logon Notification | |||||
| AC-09-01 | AC-9(1) | Previous Logon Notification | Unsuccessful Logons | |||||
| AC-09-02 | AC-9(2) | Previous Logon Notification | Successful and Unsuccessful Logons | |||||
| AC-09-03 | AC-9(3) | Previous Logon Notification | Notification of Account Changes | |||||
| AC-09-04 | AC-9(4) | Previous Logon Notification | Additional Logon Information | |||||
| AC-10-00 | AC-10 | Concurrent Session Control | x | ||||
| AC-11-00 | AC-11 | Device Lock | x | x | |||
| AC-11-01 | AC-11(1) | Device Lock | Pattern-hiding Displays | x | x | |||
| AC-12-00 | AC-12 | Session Termination | x | x | |||
| AC-12-01 | AC-12(1) | Session Termination | User-initiated Logouts | |||||
| AC-12-02 | AC-12(2) | Session Termination | Termination Message | |||||
| AC-12-03 | AC-12(3) | Session Termination | Timeout Warning Message | |||||
| AC-13-00 | AC-13 | Supervision and Review — Access Control | W: Incorporated into AC-2 and AU-6. | ||||
| AC-14-00 | AC-14 | Permitted Actions Without Identification or Authentication | x | x | x | ||
| AC-14-01 | AC-14(1) | Permitted Actions Without Identification or Authentication | Necessary Uses | W: Incorporated into AC-14. | ||||
| AC-15-00 | AC-15 | Automated Marking | W: Incorporated into MP-3. | ||||
| AC-16-00 | AC-16 | Security and Privacy Attributes | |||||
| AC-16-01 | AC-16(1) | Security and Privacy Attributes | Dynamic Attribute Association | |||||
| AC-16-02 | AC-16(2) | Security and Privacy Attributes | Attribute Value Changes by Authorized Individuals | |||||
| AC-16-03 | AC-16(3) | Security and Privacy Attributes | Maintenance of Attribute Associations by System | |||||
| AC-16-04 | AC-16(4) | Security and Privacy Attributes | Association of Attributes by Authorized Individuals | |||||
| AC-16-05 | AC-16(5) | Security and Privacy Attributes | Attribute Displays on Objects to Be Output | |||||
| AC-16-06 | AC-16(6) | Security and Privacy Attributes | Maintenance of Attribute Association | |||||
| AC-16-07 | AC-16(7) | Security and Privacy Attributes | Consistent Attribute Interpretation | |||||
| AC-16-08 | AC-16(8) | Security and Privacy Attributes | Association Techniques and Technologies | |||||
| AC-16-09 | AC-16(9) | Security and Privacy Attributes | Attribute Reassignment — Regrading Mechanisms | |||||
| AC-16-10 | AC-16(10) | Security and Privacy Attributes | Attribute Configuration by Authorized Individuals | |||||
| AC-17-00 | AC-17 | Remote Access | x | x | x | ||
| AC-17-01 | AC-17(1) | Remote Access | Monitoring and Control | x | x | |||
| AC-17-02 | AC-17(2) | Remote Access | Protection of Confidentiality and Integrity Using Encryption | x | x | |||
| AC-17-03 | AC-17(3) | Remote Access | Managed Access Control Points | x | x | |||
| AC-17-04 | AC-17(4) | Remote Access | Privileged Commands and Access | x | x | |||
| AC-17-05 | AC-17(5) | Remote Access | Monitoring for Unauthorized Connections | W: Incorporated into SI-4. | ||||
| AC-17-06 | AC-17(6) | Remote Access | Protection of Mechanism Information | |||||
| AC-17-07 | AC-17(7) | Remote Access | Additional Protection for Security Function Access | W: Incorporated into AC-3(10). | ||||
| AC-17-08 | AC-17(8) | Remote Access | Disable Nonsecure Network Protocols | W: Incorporated into CM-7. | ||||
| AC-17-09 | AC-17(9) | Remote Access | Disconnect or Disable Access | |||||
| AC-17-10 | AC-17(10) | Remote Access | Authenticate Remote Commands | |||||
| AC-18-00 | AC-18 | Wireless Access | x | x | x | ||
| AC-18-01 | AC-18(1) | Wireless Access | Authentication and Encryption | x | x | |||
| AC-18-02 | AC-18(2) | Wireless Access | Monitoring Unauthorized Connections | W: Incorporated into SI-4. | ||||
| AC-18-03 | AC-18(3) | Wireless Access | Disable Wireless Networking | x | x | |||
| AC-18-04 | AC-18(4) | Wireless Access | Restrict Configurations by Users | x | ||||
| AC-18-05 | AC-18(5) | Wireless Access | Antennas and Transmission Power Levels | x | ||||
| AC-19-00 | AC-19 | Access Control for Mobile Devices | x | x | x | ||
| AC-19-01 | AC-19(1) | Access Control for Mobile Devices | Use of Writable and Portable Storage Devices | W: Incorporated into MP-7. | ||||
| AC-19-02 | AC-19(2) | Access Control for Mobile Devices | Use of Personally Owned Portable Storage Devices | W: Incorporated into MP-7. | ||||
| AC-19-03 | AC-19(3) | Access Control for Mobile Devices | Use of Portable Storage Devices with No Identifiable Owner | W: Incorporated into MP-7. | ||||
| AC-19-04 | AC-19(4) | Access Control for Mobile Devices | Restrictions for Classified Information | |||||
| AC-19-05 | AC-19(5) | Access Control for Mobile Devices | Full Device or Container-based Encryption | x | x | |||
| AC-20-00 | AC-20 | Use of External Systems | x | x | x | ||
| AC-20-01 | AC-20(1) | Use of External Systems | Limits on Authorized Use | x | x | |||
| AC-20-02 | AC-20(2) | Use of External Systems | Portable Storage Devices — Restricted Use | x | x | |||
| AC-20-03 | AC-20(3) | Use of External Systems | Non-organizationally Owned Systems — Restricted Use | |||||
| AC-20-04 | AC-20(4) | Use of External Systems | Network Accessible Storage Devices — Prohibited Use | |||||
| AC-20-05 | AC-20(5) | Use of External Systems | Portable Storage Devices — Prohibited Use | |||||
| AC-21-00 | AC-21 | Information Sharing | x | x | |||
| AC-21-01 | AC-21(1) | Information Sharing | Automated Decision Support | |||||
| AC-21-02 | AC-21(2) | Information Sharing | Information Search and Retrieval | |||||
| AC-22-00 | AC-22 | Publicly Accessible Content | x | x | x | ||
| AC-23-00 | AC-23 | Data Mining Protection | |||||
| AC-24-00 | AC-24 | Access Control Decisions | |||||
| AC-24-01 | AC-24(1) | Access Control Decisions | Transmit Access Authorization Information | |||||
| AC-24-02 | AC-24(2) | Access Control Decisions | No User or Process Identity | |||||
| AC-25-00 | AC-25 | Reference Monitor | |||||
| AT-01-00 | AT-1 | Policy and Procedures | x | x | x | x | |
| AT-02-00 | AT-2 | Literacy Training and Awareness | x | x | x | x | |
| AT-02-01 | AT-2(1) | Literacy Training and Awareness | Practical Exercises | |||||
| AT-02-02 | AT-2(2) | Literacy Training and Awareness | Insider Threat | x | x | x | ||
| AT-02-03 | AT-2(3) | Literacy Training and Awareness | Social Engineering and Mining | x | x | |||
| AT-02-04 | AT-2(4) | Literacy Training and Awareness | Suspicious Communications and Anomalous System Behavior | |||||
| AT-02-05 | AT-2(5) | Literacy Training and Awareness | Advanced Persistent Threat | |||||
| AT-02-06 | AT-2(6) | Literacy Training and Awareness | Cyber Threat Environment | |||||
| AT-03-00 | AT-3 | Role-based Training | x | x | x | x | |
| AT-03-01 | AT-3(1) | Role-based Training | Environmental Controls | |||||
| AT-03-02 | AT-3(2) | Role-based Training | Physical Security Controls | |||||
| AT-03-03 | AT-3(3) | Role-based Training | Practical Exercises | |||||
| AT-03-04 | AT-3(4) | Role-based Training | Suspicious Communications and Anomalous System Behavior | W: Incorporated into AT-2(4). | ||||
| AT-03-05 | AT-3(5) | Role-based Training | Processing Personally Identifiable Information | x | ||||
| AT-04-00 | AT-4 | Training Records | x | x | x | x | |
| AT-05-00 | AT-5 | Contacts with Security Groups and Associations | W: Incorporated into PM-15. | ||||
| AT-06-00 | AT-6 | Training Feedback | |||||
| AU-01-00 | AU-1 | Policy and Procedures | x | x | x | x | |
| AU-02-00 | AU-2 | Event Logging | x | x | x | x | |
| AU-02-01 | AU-2(1) | Event Logging | Compilation of Audit Records from Multiple Sources | W: Incorporated into AU-12. | ||||
| AU-02-02 | AU-2(2) | Event Logging | Selection of Audit Events by Component | W: Incorporated into AU-12. | ||||
| AU-02-03 | AU-2(3) | Event Logging | Reviews and Updates | W: Incorporated into AU-2. | ||||
| AU-02-04 | AU-2(4) | Event Logging | Privileged Functions | W: Incorporated into AC-6(9). | ||||
| AU-03-00 | AU-3 | Content of Audit Records | x | x | x | ||
| AU-03-01 | AU-3(1) | Content of Audit Records | Additional Audit Information | x | x | |||
| AU-03-02 | AU-3(2) | Content of Audit Records | Centralized Management of Planned Audit Record Content | W: Incorporated into PL-9. | ||||
| AU-03-03 | AU-3(3) | Content of Audit Records | Limit Personally Identifiable Information Elements | x | ||||
| AU-04-00 | AU-4 | Audit Log Storage Capacity | x | x | x | ||
| AU-04-01 | AU-4(1) | Audit Log Storage Capacity | Transfer to Alternate Storage | |||||
| AU-05-00 | AU-5 | Response to Audit Logging Process Failures | x | x | x | ||
| AU-05-01 | AU-5(1) | Response to Audit Logging Process Failures | Storage Capacity Warning | x | ||||
| AU-05-02 | AU-5(2) | Response to Audit Logging Process Failures | Real-time Alerts | x | ||||
| AU-05-03 | AU-5(3) | Response to Audit Logging Process Failures | Configurable Traffic Volume Thresholds | |||||
| AU-05-04 | AU-5(4) | Response to Audit Logging Process Failures | Shutdown on Failure | |||||
| AU-05-05 | AU-5(5) | Response to Audit Logging Process Failures | Alternate Audit Logging Capability | |||||
| AU-06-00 | AU-6 | Audit Record Review, Analysis, and Reporting | x | x | x | ||
| AU-06-01 | AU-6(1) | Audit Record Review, Analysis, and Reporting | Automated Process Integration | x | x | |||
| AU-06-02 | AU-6(2) | Audit Record Review, Analysis, and Reporting | Automated Security Alerts | W: Incorporated into SI-4 | ||||
| AU-06-03 | AU-6(3) | Audit Record Review, Analysis, and Reporting | Correlate Audit Record Repositories | x | x | |||
| AU-06-04 | AU-6(4) | Audit Record Review, Analysis, and Reporting | Central Review and Analysis | |||||
| AU-06-05 | AU-6(5) | Audit Record Review, Analysis, and Reporting | Integrated Analysis of Audit Records | x | ||||
| AU-06-06 | AU-6(6) | Audit Record Review, Analysis, and Reporting | Correlation with Physical Monitoring | x | ||||
| AU-06-07 | AU-6(7) | Audit Record Review, Analysis, and Reporting | Permitted Actions | |||||
| AU-06-08 | AU-6(8) | Audit Record Review, Analysis, and Reporting | Full Text Analysis of Privileged Commands | |||||
| AU-06-09 | AU-6(9) | Audit Record Review, Analysis, and Reporting | Correlation with Information from Nontechnical Sources | |||||
| AU-06-10 | AU-6(10) | Audit Record Review, Analysis, and Reporting | Audit Level Adjustment | W: Incorporated into AU-6. | ||||
| AU-07-00 | AU-7 | Audit Record Reduction and Report Generation | x | x | |||
| AU-07-01 | AU-7(1) | Audit Record Reduction and Report Generation | Automatic Processing | x | x | |||
| AU-07-02 | AU-7(2) | Audit Record Reduction and Report Generation | Automatic Sort and Search | W: Incorporated into AU-7(1). | ||||
| AU-08-00 | AU-8 | Time Stamps | x | x | x | ||
| AU-08-01 | AU-8(1) | Time Stamps | Synchronization with Authoritative Time Source | W: Moved to SC-45(1). | ||||
| AU-08-02 | AU-8(2) | Time Stamps | Secondary Authoritative Time Source | W: Moved to SC-45(2). | ||||
| AU-09-00 | AU-9 | Protection of Audit Information | x | x | x | ||
| AU-09-01 | AU-9(1) | Protection of Audit Information | Hardware Write-once Media | |||||
| AU-09-02 | AU-9(2) | Protection of Audit Information | Store on Separate Physical Systems or Components | x | ||||
| AU-09-03 | AU-9(3) | Protection of Audit Information | Cryptographic Protection | x | ||||
| AU-09-04 | AU-9(4) | Protection of Audit Information | Access by Subset of Privileged Users | x | x | |||
| AU-09-05 | AU-9(5) | Protection of Audit Information | Dual Authorization | |||||
| AU-09-06 | AU-9(6) | Protection of Audit Information | Read-only Access | |||||
| AU-09-07 | AU-9(7) | Protection of Audit Information | Store on Component with Different Operating System | |||||
| AU-10-00 | AU-10 | Non-repudiation | x | ||||
| AU-10-01 | AU-10(1) | Non-repudiation | Association of Identities | |||||
| AU-10-02 | AU-10(2) | Non-repudiation | Validate Binding of Information Producer Identity | |||||
| AU-10-03 | AU-10(3) | Non-repudiation | Chain of Custody | |||||
| AU-10-04 | AU-10(4) | Non-repudiation | Validate Binding of Information Reviewer Identity | |||||
| AU-10-05 | AU-10(5) | Non-repudiation | Digital Signatures | W: Incorporated into SI-7 | ||||
| AU-11-00 | AU-11 | Audit Record Retention | x | x | x | x | |
| AU-11-01 | AU-11(1) | Audit Record Retention | Long-term Retrieval Capability | |||||
| AU-12-00 | AU-12 | Audit Record Generation | x | x | x | ||
| AU-12-01 | AU-12(1) | Audit Record Generation | System-wide and Time-correlated Audit Trail | x | ||||
| AU-12-02 | AU-12(2) | Audit Record Generation | Standardized Formats | |||||
| AU-12-03 | AU-12(3) | Audit Record Generation | Changes by Authorized Individuals | x | ||||
| AU-12-04 | AU-12(4) | Audit Record Generation | Query Parameter Audits of Personally Identifiable Information | |||||
| AU-13-00 | AU-13 | Monitoring for Information Disclosure | |||||
| AU-13-01 | AU-13(1) | Monitoring for Information Disclosure | Use of Automated Tools | |||||
| AU-13-02 | AU-13(2) | Monitoring for Information Disclosure | Review of Monitored Sites | |||||
| AU-13-03 | AU-13(3) | Monitoring for Information Disclosure | Unauthorized Replication of Information | |||||
| AU-14-00 | AU-14 | Session Audit | |||||
| AU-14-01 | AU-14(1) | Session Audit | System Start-up | |||||
| AU-14-02 | AU-14(2) | Session Audit | Capture and Record Content | W: Incorporated into AU-14. | ||||
| AU-14-03 | AU-14(3) | Session Audit | Remote Viewing and Listening | |||||
| AU-15-00 | AU-15 | Alternate Audit Logging Capability | W: Moved to AU-5(5). | ||||
| AU-16-00 | AU-16 | Cross-organizational Audit Logging | |||||
| AU-16-01 | AU-16(1) | Cross-organizational Audit Logging | Identity Preservation | |||||
| AU-16-02 | AU-16(2) | Cross-organizational Audit Logging | Sharing of Audit Information | |||||
| AU-16-03 | AU-16(3) | Cross-organizational Audit Logging | Disassociability | |||||
| CA-01-00 | CA-1 | Policy and Procedures | x | x | x | x | |
| CA-02-00 | CA-2 | Control Assessments | x | x | x | x | |
| CA-02-01 | CA-2(1) | Control Assessments | Independent Assessors | x | x | |||
| CA-02-02 | CA-2(2) | Control Assessments | Specialized Assessments | x | ||||
| CA-02-03 | CA-2(3) | Control Assessments | Leveraging Results from External Organizations | |||||
| CA-03-00 | CA-3 | Information Exchange | x | x | x | ||
| CA-03-01 | CA-3(1) | Information Exchange | Unclassified National Security System Connections | W: Moved to SC-7(25). | ||||
| CA-03-02 | CA-3(2) | Information Exchange | Classified National Security System Connections | W: Moved to SC-7(26). | ||||
| CA-03-03 | CA-3(3) | Information Exchange | Unclassified Non-national Security System Connections | W: Moved to SC-7(27). | ||||
| CA-03-04 | CA-3(4) | Information Exchange | Connections to Public Networks | W: Moved to SC-7(28). | ||||
| CA-03-05 | CA-3(5) | Information Exchange | Restrictions on External System Connections | W: Incorporated into SC-7(5). | ||||
| CA-03-06 | CA-3(6) | Information Exchange | Transfer Authorizations | x | ||||
| CA-03-07 | CA-3(7) | Information Exchange | Transitive Information Exchanges | |||||
| CA-04-00 | CA-4 | Security Certification | W: Incorporated into CA-2. | ||||
| CA-05-00 | CA-5 | Plan of Action and Milestones | x | x | x | x | |
| CA-05-01 | CA-5(1) | Plan of Action and Milestones | Automation Support for Accuracy and Currency | |||||
| CA-06-00 | CA-6 | Authorization | x | x | x | x | |
| CA-06-01 | CA-6(1) | Authorization | Joint Authorization — Intra-organization | |||||
| CA-06-02 | CA-6(2) | Authorization | Joint Authorization — Inter-organization | |||||
| CA-07-00 | CA-7 | Continuous Monitoring | x | x | x | x | |
| CA-07-01 | CA-7(1) | Continuous Monitoring | Independent Assessment | x | x | |||
| CA-07-02 | CA-7(2) | Continuous Monitoring | Types of Assessments | W: Incorporated into CA-2. | ||||
| CA-07-03 | CA-7(3) | Continuous Monitoring | Trend Analyses | |||||
| CA-07-04 | CA-7(4) | Continuous Monitoring | Risk Monitoring | x | x | x | x | |
| CA-07-05 | CA-7(5) | Continuous Monitoring | Consistency Analysis | |||||
| CA-07-06 | CA-7(6) | Continuous Monitoring | Automation Support for Monitoring | |||||
| CA-08-00 | CA-8 | Penetration Testing | x | ||||
| CA-08-01 | CA-8(1) | Penetration Testing | Independent Penetration Testing Agent or Team | x | ||||
| CA-08-02 | CA-8(2) | Penetration Testing | Red Team Exercises | |||||
| CA-08-03 | CA-8(3) | Penetration Testing | Facility Penetration Testing | |||||
| CA-09-00 | CA-9 | Internal System Connections | x | x | x | ||
| CA-09-01 | CA-9(1) | Internal System Connections | Compliance Checks | |||||
| CM-01-00 | CM-1 | Policy and Procedures | x | x | x | x | |
| CM-02-00 | CM-2 | Baseline Configuration | x | x | x | ||
| CM-02-01 | CM-2(1) | Baseline Configuration | Reviews and Updates | W: Incorporated into CM-2. | ||||
| CM-02-02 | CM-2(2) | Baseline Configuration | Automation Support for Accuracy and Currency | x | x | |||
| CM-02-03 | CM-2(3) | Baseline Configuration | Retention of Previous Configurations | x | x | |||
| CM-02-04 | CM-2(4) | Baseline Configuration | Unauthorized Software | W: Incorporated into CM-7. | ||||
| CM-02-05 | CM-2(5) | Baseline Configuration | Authorized Software | W: Incorporated into CM-7. | ||||
| CM-02-06 | CM-2(6) | Baseline Configuration | Development and Test Environments | |||||
| CM-02-07 | CM-2(7) | Baseline Configuration | Configure Systems and Components for High-risk Areas | x | x | |||
| CM-03-00 | CM-3 | Configuration Change Control | x | x | |||
| CM-03-01 | CM-3(1) | Configuration Change Control | Automated Documentation, Notification, and Prohibition of Changes | x | ||||
| CM-03-02 | CM-3(2) | Configuration Change Control | Testing, Validation, and Documentation of Changes | x | x | |||
| CM-03-03 | CM-3(3) | Configuration Change Control | Automated Change Implementation | |||||
| CM-03-04 | CM-3(4) | Configuration Change Control | Security and Privacy Representatives | x | x | |||
| CM-03-05 | CM-3(5) | Configuration Change Control | Automated Security Response | |||||
| CM-03-06 | CM-3(6) | Configuration Change Control | Cryptography Management | x | ||||
| CM-03-07 | CM-3(7) | Configuration Change Control | Review System Changes | |||||
| CM-03-08 | CM-3(8) | Configuration Change Control | Prevent or Restrict Configuration Changes | |||||
| CM-04-00 | CM-4 | Impact Analyses | x | x | x | x | |
| CM-04-01 | CM-4(1) | Impact Analyses | Separate Test Environments | x | ||||
| CM-04-02 | CM-4(2) | Impact Analyses | Verification of Controls | x | x | |||
| CM-05-00 | CM-5 | Access Restrictions for Change | x | x | x | ||
| CM-05-01 | CM-5(1) | Access Restrictions for Change | Automated Access Enforcement and Audit Records | x | ||||
| CM-05-02 | CM-5(2) | Access Restrictions for Change | Review System Changes | W: Incorporated into CM-3(7). | ||||
| CM-05-03 | CM-5(3) | Access Restrictions for Change | Signed Components | W: Moved to CM-14. | ||||
| CM-05-04 | CM-5(4) | Access Restrictions for Change | Dual Authorization | |||||
| CM-05-05 | CM-5(5) | Access Restrictions for Change | Privilege Limitation for Production and Operation | |||||
| CM-05-06 | CM-5(6) | Access Restrictions for Change | Limit Library Privileges | |||||
| CM-05-07 | CM-5(7) | Access Restrictions for Change | Automatic Implementation of Security Safeguards | W: Incorporated into SI-7. | ||||
| CM-06-00 | CM-6 | Configuration Settings | x | x | x | ||
| CM-06-01 | CM-6(1) | Configuration Settings | Automated Management, Application, and Verification | x | ||||
| CM-06-02 | CM-6(2) | Configuration Settings | Respond to Unauthorized Changes | x | ||||
| CM-06-03 | CM-6(3) | Configuration Settings | Unauthorized Change Detection | W: Incorporated into SI-7. | ||||
| CM-06-04 | CM-6(4) | Configuration Settings | Conformance Demonstration | W: Incorporated into CM-4. | ||||
| CM-07-00 | CM-7 | Least Functionality | x | x | x | ||
| CM-07-01 | CM-7(1) | Least Functionality | Periodic Review | x | x | |||
| CM-07-02 | CM-7(2) | Least Functionality | Prevent Program Execution | x | x | |||
| CM-07-03 | CM-7(3) | Least Functionality | Registration Compliance | |||||
| CM-07-04 | CM-7(4) | Least Functionality | Unauthorized Software | |||||
| CM-07-05 | CM-7(5) | Least Functionality | Authorized Software | x | x | |||
| CM-07-06 | CM-7(6) | Least Functionality | Confined Environments with Limited Privileges | |||||
| CM-07-07 | CM-7(7) | Least Functionality | Code Execution in Protected Environments | |||||
| CM-07-08 | CM-7(8) | Least Functionality | Binary or Machine Executable Code | |||||
| CM-07-09 | CM-7(9) | Least Functionality | Prohibiting The Use of Unauthorized Hardware | |||||
| CM-08-00 | CM-8 | System Component Inventory | x | x | x | ||
| CM-08-01 | CM-8(1) | System Component Inventory | Updates During Installation and Removal | x | x | |||
| CM-08-02 | CM-8(2) | System Component Inventory | Automated Maintenance | x | ||||
| CM-08-03 | CM-8(3) | System Component Inventory | Automated Unauthorized Component Detection | x | x | |||
| CM-08-04 | CM-8(4) | System Component Inventory | Accountability Information | x | ||||
| CM-08-05 | CM-8(5) | System Component Inventory | No Duplicate Accounting of Components | W: Incorporated into CM-8. | ||||
| CM-08-06 | CM-8(6) | System Component Inventory | Assessed Configurations and Approved Deviations | |||||
| CM-08-07 | CM-8(7) | System Component Inventory | Centralized Repository | |||||
| CM-08-08 | CM-8(8) | System Component Inventory | Automated Location Tracking | |||||
| CM-08-09 | CM-8(9) | System Component Inventory | Assignment of Components to Systems | |||||
| CM-09-00 | CM-9 | Configuration Management Plan | x | x | |||
| CM-09-01 | CM-9(1) | Configuration Management Plan | Assignment of Responsibility | |||||
| CM-10-00 | CM-10 | Software Usage Restrictions | x | x | x | ||
| CM-10-01 | CM-10(1) | Software Usage Restrictions | Open-source Software | |||||
| CM-11-00 | CM-11 | User-installed Software | x | x | x | ||
| CM-11-01 | CM-11(1) | User-installed Software | Alerts for Unauthorized Installations | W: Incorporated into CM-8(3). | ||||
| CM-11-02 | CM-11(2) | User-installed Software | Software Installation with Privileged Status | |||||
| CM-11-03 | CM-11(3) | User-installed Software | Automated Enforcement and Monitoring | |||||
| CM-12-00 | CM-12 | Information Location | x | x | |||
| CM-12-01 | CM-12(1) | Information Location | Automated Tools to Support Information Location | x | x | |||
| CM-13-00 | CM-13 | Data Action Mapping | |||||
| CM-14-00 | CM-14 | Signed Components | |||||
| CP-01-00 | CP-1 | Policy and Procedures | x | x | x | ||
| CP-02-00 | CP-2 | Contingency Plan | x | x | x | ||
| CP-02-01 | CP-2(1) | Contingency Plan | Coordinate with Related Plans | x | x | |||
| CP-02-02 | CP-2(2) | Contingency Plan | Capacity Planning | x | ||||
| CP-02-03 | CP-2(3) | Contingency Plan | Resume Mission and Business Functions | x | x | |||
| CP-02-04 | CP-2(4) | Contingency Plan | Resume All Mission and Business Functions | W: Incorporated into CP-2(3). | ||||
| CP-02-05 | CP-2(5) | Contingency Plan | Continue Mission and Business Functions | x | ||||
| CP-02-06 | CP-2(6) | Contingency Plan | Alternate Processing and Storage Sites | |||||
| CP-02-07 | CP-2(7) | Contingency Plan | Coordinate with External Service Providers | |||||
| CP-02-08 | CP-2(8) | Contingency Plan | Identify Critical Assets | x | x | |||
| CP-03-00 | CP-3 | Contingency Training | x | x | x | ||
| CP-03-01 | CP-3(1) | Contingency Training | Simulated Events | x | ||||
| CP-03-02 | CP-3(2) | Contingency Training | Mechanisms Used in Training Environments | |||||
| CP-04-00 | CP-4 | Contingency Plan Testing | x | x | x | ||
| CP-04-01 | CP-4(1) | Contingency Plan Testing | Coordinate with Related Plans | x | x | |||
| CP-04-02 | CP-4(2) | Contingency Plan Testing | Alternate Processing Site | x | ||||
| CP-04-03 | CP-4(3) | Contingency Plan Testing | Automated Testing | |||||
| CP-04-04 | CP-4(4) | Contingency Plan Testing | Full Recovery and Reconstitution | |||||
| CP-04-05 | CP-4(5) | Contingency Plan Testing | Self-challenge | |||||
| CP-05-00 | CP-5 | Contingency Plan Update | W: Incorporated into CP-2. | ||||
| CP-06-00 | CP-6 | Alternate Storage Site | x | x | |||
| CP-06-01 | CP-6(1) | Alternate Storage Site | Separation from Primary Site | x | x | |||
| CP-06-02 | CP-6(2) | Alternate Storage Site | Recovery Time and Recovery Point Objectives | x | ||||
| CP-06-03 | CP-6(3) | Alternate Storage Site | Accessibility | x | x | |||
| CP-07-00 | CP-7 | Alternate Processing Site | x | x | |||
| CP-07-01 | CP-7(1) | Alternate Processing Site | Separation from Primary Site | x | x | |||
| CP-07-02 | CP-7(2) | Alternate Processing Site | Accessibility | x | x | |||
| CP-07-03 | CP-7(3) | Alternate Processing Site | Priority of Service | x | x | |||
| CP-07-04 | CP-7(4) | Alternate Processing Site | Preparation for Use | x | ||||
| CP-07-05 | CP-7(5) | Alternate Processing Site | Equivalent Information Security Safeguards | W: Incorporated into CP-7. | ||||
| CP-07-06 | CP-7(6) | Alternate Processing Site | Inability to Return to Primary Site | |||||
| CP-08-00 | CP-8 | Telecommunications Services | x | x | |||
| CP-08-01 | CP-8(1) | Telecommunications Services | Priority of Service Provisions | x | x | |||
| CP-08-02 | CP-8(2) | Telecommunications Services | Single Points of Failure | x | x | |||
| CP-08-03 | CP-8(3) | Telecommunications Services | Separation of Primary and Alternate Providers | x | ||||
| CP-08-04 | CP-8(4) | Telecommunications Services | Provider Contingency Plan | x | ||||
| CP-08-05 | CP-8(5) | Telecommunications Services | Alternate Telecommunication Service Testing | |||||
| CP-09-00 | CP-9 | System Backup | x | x | x | ||
| CP-09-01 | CP-9(1) | System Backup | Testing for Reliability and Integrity | x | x | |||
| CP-09-02 | CP-9(2) | System Backup | Test Restoration Using Sampling | x | ||||
| CP-09-03 | CP-9(3) | System Backup | Separate Storage for Critical Information | x | ||||
| CP-09-04 | CP-9(4) | System Backup | Protection from Unauthorized Modification | W: Incorporated into CP-9. | ||||
| CP-09-05 | CP-9(5) | System Backup | Transfer to Alternate Storage Site | x | ||||
| CP-09-06 | CP-9(6) | System Backup | Redundant Secondary System | |||||
| CP-09-07 | CP-9(7) | System Backup | Dual Authorization | |||||
| CP-09-08 | CP-9(8) | System Backup | Cryptographic Protection | x | x | |||
| CP-10-00 | CP-10 | System Recovery and Reconstitution | x | x | x | ||
| CP-10-01 | CP-10(1) | System Recovery and Reconstitution | Contingency Plan Testing | W: Incorporated into CP-4. | ||||
| CP-10-02 | CP-10(2) | System Recovery and Reconstitution | Transaction Recovery | x | x | |||
| CP-10-03 | CP-10(3) | System Recovery and Reconstitution | Compensating Security Controls | W: Addressed through tailoring. | ||||
| CP-10-04 | CP-10(4) | System Recovery and Reconstitution | Restore Within Time Period | x | ||||
| CP-10-05 | CP-10(5) | System Recovery and Reconstitution | Failover Capability | W: Incorporated into SI-13. | ||||
| CP-10-06 | CP-10(6) | System Recovery and Reconstitution | Component Protection | |||||
| CP-11-00 | CP-11 | Alternate Communications Protocols | |||||
| CP-12-00 | CP-12 | Safe Mode | |||||
| CP-13-00 | CP-13 | Alternative Security Mechanisms | |||||
| IA-01-00 | IA-1 | Policy and Procedures | x | x | x | ||
| IA-02-00 | IA-2 | Identification and Authentication (organizational Users) | x | x | x | ||
| IA-02-01 | IA-2(1) | Identification and Authentication (organizational Users) | Multi-factor Authentication to Privileged Accounts | x | x | x | ||
| IA-02-02 | IA-2(2) | Identification and Authentication (organizational Users) | Multi-factor Authentication to Non-privileged Accounts | x | x | x | ||
| IA-02-03 | IA-2(3) | Identification and Authentication (organizational Users) | Local Access to Privileged Accounts | W: Incorporated into IA-2(1)(2). | ||||
| IA-02-04 | IA-2(4) | Identification and Authentication (organizational Users) | Local Access to Non-privileged Accounts | W: Incorporated into IA-2(1)(2). | ||||
| IA-02-05 | IA-2(5) | Identification and Authentication (organizational Users) | Individual Authentication with Group Authentication | x | ||||
| IA-02-06 | IA-2(6) | Identification and Authentication (organizational Users) | Access to Accounts — Separate Device | |||||
| IA-02-07 | IA-2(7) | Identification and Authentication (organizational Users) | Access to Non-privileged Accounts — Separate Device | W: Incorporated into IA-2(6). | ||||
| IA-02-08 | IA-2(8) | Identification and Authentication (organizational Users) | Access to Accounts — Replay Resistant | x | x | x | ||
| IA-02-09 | IA-2(9) | Identification and Authentication (organizational Users) | Network Access to Non-privileged Accounts — Replay Resistant | W: Incorporated into IA-2(8). | ||||
| IA-02-10 | IA-2(10) | Identification and Authentication (organizational Users) | Single Sign-on | |||||
| IA-02-11 | IA-2(11) | Identification and Authentication (organizational Users) | Remote Access — Separate Device | W: Incorporated into IA-2(6). | ||||
| IA-02-12 | IA-2(12) | Identification and Authentication (organizational Users) | Acceptance of PIV Credentials | x | x | x | ||
| IA-02-13 | IA-2(13) | Identification and Authentication (organizational Users) | Out-of-band Authentication | |||||
| IA-03-00 | IA-3 | Device Identification and Authentication | x | x | |||
| IA-03-01 | IA-3(1) | Device Identification and Authentication | Cryptographic Bidirectional Authentication | |||||
| IA-03-02 | IA-3(2) | Device Identification and Authentication | Cryptographic Bidirectional Network Authentication | W: Incorporated into IA-3(1). | ||||
| IA-03-03 | IA-3(3) | Device Identification and Authentication | Dynamic Address Allocation | |||||
| IA-03-04 | IA-3(4) | Device Identification and Authentication | Device Attestation | |||||
| IA-04-00 | IA-4 | Identifier Management | x | x | x | ||
| IA-04-01 | IA-4(1) | Identifier Management | Prohibit Account Identifiers as Public Identifiers | |||||
| IA-04-02 | IA-4(2) | Identifier Management | Supervisor Authorization | W: Incorporated into IA-12(1). | ||||
| IA-04-03 | IA-4(3) | Identifier Management | Multiple Forms of Certification | W: Incorporated into IA-12(2) | ||||
| IA-04-04 | IA-4(4) | Identifier Management | Identify User Status | x | x | |||
| IA-04-05 | IA-4(5) | Identifier Management | Dynamic Management | |||||
| IA-04-06 | IA-4(6) | Identifier Management | Cross-organization Management | |||||
| IA-04-07 | IA-4(7) | Identifier Management | In-person Registration | W: Incorporated into IA-12(4) | ||||
| IA-04-08 | IA-4(8) | Identifier Management | Pairwise Pseudonymous Identifiers | |||||
| IA-04-09 | IA-4(9) | Identifier Management | Attribute Maintenance and Protection | |||||
| IA-05-00 | IA-5 | Authenticator Management | x | x | x | ||
| IA-05-01 | IA-5(1) | Authenticator Management | Password-based Authentication | x | x | x | ||
| IA-05-02 | IA-5(2) | Authenticator Management | Public Key-based Authentication | x | x | |||
| IA-05-03 | IA-5(3) | Authenticator Management | In-person or Trusted External Party Registration | W: Incorporated into IA-12(4) | ||||
| IA-05-04 | IA-5(4) | Authenticator Management | Automated Support for Password Strength Determination | W: Incorporated into IA-5(1). | ||||
| IA-05-05 | IA-5(5) | Authenticator Management | Change Authenticators Prior to Delivery | |||||
| IA-05-06 | IA-5(6) | Authenticator Management | Protection of Authenticators | x | x | |||
| IA-05-07 | IA-5(7) | Authenticator Management | No Embedded Unencrypted Static Authenticators | |||||
| IA-05-08 | IA-5(8) | Authenticator Management | Multiple System Accounts | |||||
| IA-05-09 | IA-5(9) | Authenticator Management | Federated Credential Management | |||||
| IA-05-10 | IA-5(10) | Authenticator Management | Dynamic Credential Binding | |||||
| IA-05-11 | IA-5(11) | Authenticator Management | Hardware Token-based Authentication | W: Incorporated into IA-2(1) and IA-2(2). | ||||
| IA-05-12 | IA-5(12) | Authenticator Management | Biometric Authentication Performance | |||||
| IA-05-13 | IA-5(13) | Authenticator Management | Expiration of Cached Authenticators | |||||
| IA-05-14 | IA-5(14) | Authenticator Management | Managing Content of PKI Trust Stores | |||||
| IA-05-15 | IA-5(15) | Authenticator Management | GSA-approved Products and Services | |||||
| IA-05-16 | IA-5(16) | Authenticator Management | In-person or Trusted External Party Authenticator Issuance | |||||
| IA-05-17 | IA-5(17) | Authenticator Management | Presentation Attack Detection for Biometric Authenticators | |||||
| IA-05-18 | IA-5(18) | Authenticator Management | Password Managers | |||||
| IA-06-00 | IA-6 | Authentication Feedback | x | x | x | ||
| IA-07-00 | IA-7 | Cryptographic Module Authentication | x | x | x | ||
| IA-08-00 | IA-8 | Identification and Authentication (non-organizational Users) | x | x | x | ||
| IA-08-01 | IA-8(1) | Identification and Authentication (non-organizational Users) | Acceptance of PIV Credentials from Other Agencies | x | x | x | ||
| IA-08-02 | IA-8(2) | Identification and Authentication (non-organizational Users) | Acceptance of External Authenticators | x | x | x | ||
| IA-08-03 | IA-8(3) | Identification and Authentication (non-organizational Users) | Use of FICAM-approved Products | W: Incorporated into IA-8(2). | ||||
| IA-08-04 | IA-8(4) | Identification and Authentication (non-organizational Users) | Use of Defined Profiles | x | x | x | ||
| IA-08-05 | IA-8(5) | Identification and Authentication (non-organizational Users) | Acceptance of PIV-I Credentials | |||||
| IA-08-06 | IA-8(6) | Identification and Authentication (non-organizational Users) | Disassociability | |||||
| IA-09-00 | IA-9 | Service Identification and Authentication | |||||
| IA-09-01 | IA-9(1) | Service Identification and Authentication | Information Exchange | W: Incorporated into IA-9. | ||||
| IA-09-02 | IA-9(2) | Service Identification and Authentication | Transmission of Decisions | W: Incorporated into IA-9. | ||||
| IA-10-00 | IA-10 | Adaptive Authentication | |||||
| IA-11-00 | IA-11 | Re-authentication | x | x | x | ||
| IA-12-00 | IA-12 | Identity Proofing | x | x | |||
| IA-12-01 | IA-12(1) | Identity Proofing | Supervisor Authorization | |||||
| IA-12-02 | IA-12(2) | Identity Proofing | Identity Evidence | x | x | |||
| IA-12-03 | IA-12(3) | Identity Proofing | Identity Evidence Validation and Verification | x | x | |||
| IA-12-04 | IA-12(4) | Identity Proofing | In-person Validation and Verification | x | ||||
| IA-12-05 | IA-12(5) | Identity Proofing | Address Confirmation | x | x | |||
| IA-12-06 | IA-12(6) | Identity Proofing | Accept Externally-proofed Identities | |||||
| IR-01-00 | IR-1 | Policy and Procedures | x | x | x | x | |
| IR-02-00 | IR-2 | Incident Response Training | x | x | x | x | |
| IR-02-01 | IR-2(1) | Incident Response Training | Simulated Events | x | ||||
| IR-02-02 | IR-2(2) | Incident Response Training | Automated Training Environments | x | ||||
| IR-02-03 | IR-2(3) | Incident Response Training | Breach | x | ||||
| IR-03-00 | IR-3 | Incident Response Testing | x | x | x | ||
| IR-03-01 | IR-3(1) | Incident Response Testing | Automated Testing | |||||
| IR-03-02 | IR-3(2) | Incident Response Testing | Coordination with Related Plans | x | x | |||
| IR-03-03 | IR-3(3) | Incident Response Testing | Continuous Improvement | |||||
| IR-04-00 | IR-4 | Incident Handling | x | x | x | x | |
| IR-04-01 | IR-4(1) | Incident Handling | Automated Incident Handling Processes | x | x | |||
| IR-04-02 | IR-4(2) | Incident Handling | Dynamic Reconfiguration | |||||
| IR-04-03 | IR-4(3) | Incident Handling | Continuity of Operations | |||||
| IR-04-04 | IR-4(4) | Incident Handling | Information Correlation | x | ||||
| IR-04-05 | IR-4(5) | Incident Handling | Automatic Disabling of System | |||||
| IR-04-06 | IR-4(6) | Incident Handling | Insider Threats | |||||
| IR-04-07 | IR-4(7) | Incident Handling | Insider Threats — Intra-organization Coordination | |||||
| IR-04-08 | IR-4(8) | Incident Handling | Correlation with External Organizations | |||||
| IR-04-09 | IR-4(9) | Incident Handling | Dynamic Response Capability | |||||
| IR-04-10 | IR-4(10) | Incident Handling | Supply Chain Coordination | |||||
| IR-04-11 | IR-4(11) | Incident Handling | Integrated Incident Response Team | x | ||||
| IR-04-12 | IR-4(12) | Incident Handling | Malicious Code and Forensic Analysis | |||||
| IR-04-13 | IR-4(13) | Incident Handling | Behavior Analysis | |||||
| IR-04-14 | IR-4(14) | Incident Handling | Security Operations Center | |||||
| IR-04-15 | IR-4(15) | Incident Handling | Public Relations and Reputation Repair | |||||
| IR-05-00 | IR-5 | Incident Monitoring | x | x | x | x | |
| IR-05-01 | IR-5(1) | Incident Monitoring | Automated Tracking, Data Collection, and Analysis | x | ||||
| IR-06-00 | IR-6 | Incident Reporting | x | x | x | x | |
| IR-06-01 | IR-6(1) | Incident Reporting | Automated Reporting | x | x | |||
| IR-06-02 | IR-6(2) | Incident Reporting | Vulnerabilities Related to Incidents | |||||
| IR-06-03 | IR-6(3) | Incident Reporting | Supply Chain Coordination | x | x | |||
| IR-07-00 | IR-7 | Incident Response Assistance | x | x | x | x | |
| IR-07-01 | IR-7(1) | Incident Response Assistance | Automation Support for Availability of Information and Support | x | x | |||
| IR-07-02 | IR-7(2) | Incident Response Assistance | Coordination with External Providers | |||||
| IR-08-00 | IR-8 | Incident Response Plan | x | x | x | x | |
| IR-08-01 | IR-8(1) | Incident Response Plan | Breaches | x | ||||
| IR-09-00 | IR-9 | Information Spillage Response | |||||
| IR-09-01 | IR-9(1) | Information Spillage Response | Responsible Personnel | W: Incorporated into IR-9 | ||||
| IR-09-02 | IR-9(2) | Information Spillage Response | Training | |||||
| IR-09-03 | IR-9(3) | Information Spillage Response | Post-spill Operations | |||||
| IR-09-04 | IR-9(4) | Information Spillage Response | Exposure to Unauthorized Personnel | |||||
| IR-10-00 | IR-10 | Incident Analysis | W: Moved to IR-4(11). | ||||
| MA-01-00 | MA-1 | Policy and Procedures | x | x | x | ||
| MA-02-00 | MA-2 | Controlled Maintenance | x | x | x | ||
| MA-02-01 | MA-2(1) | Controlled Maintenance | Record Content | W: Incorporated into MA-2. | ||||
| MA-02-02 | MA-2(2) | Controlled Maintenance | Automated Maintenance Activities | x | ||||
| MA-03-00 | MA-3 | Maintenance Tools | x | x | |||
| MA-03-01 | MA-3(1) | Maintenance Tools | Inspect Tools | x | x | |||
| MA-03-02 | MA-3(2) | Maintenance Tools | Inspect Media | x | x | |||
| MA-03-03 | MA-3(3) | Maintenance Tools | Prevent Unauthorized Removal | x | x | |||
| MA-03-04 | MA-3(4) | Maintenance Tools | Restricted Tool Use | |||||
| MA-03-05 | MA-3(5) | Maintenance Tools | Execution with Privilege | |||||
| MA-03-06 | MA-3(6) | Maintenance Tools | Software Updates and Patches | |||||
| MA-04-00 | MA-4 | Nonlocal Maintenance | x | x | x | ||
| MA-04-01 | MA-4(1) | Nonlocal Maintenance | Logging and Review | |||||
| MA-04-02 | MA-4(2) | Nonlocal Maintenance | Logically separated communications paths. | W: Incorporated into MA-1 and MA-4. | ||||
| MA-04-03 | MA-4(3) | Nonlocal Maintenance | Comparable Security and Sanitization | x | ||||
| MA-04-04 | MA-4(4) | Nonlocal Maintenance | Authentication and Separation of Maintenance Sessions | |||||
| MA-04-05 | MA-4(5) | Nonlocal Maintenance | Approvals and Notifications | |||||
| MA-04-06 | MA-4(6) | Nonlocal Maintenance | Cryptographic Protection | |||||
| MA-04-07 | MA-4(7) | Nonlocal Maintenance | Disconnect Verification | |||||
| MA-05-00 | MA-5 | Maintenance Personnel | x | x | x | ||
| MA-05-01 | MA-5(1) | Maintenance Personnel | Individuals Without Appropriate Access | x |
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .