ESM_Attachment 5 System Security Control Baselines Final.docx

DOCX document 130 KB Posted

Attached to
Enterprise Sales and Marketing Solution Federal contract opportunity
Solicitation number
2031JG22R00025
Issued by
Department of the Treasury Departmental Offices

About this file

This statement of objectives describes an enterprise sales and marketing solution for the United States Mint's numismatic program. The scope includes direct-to-consumer and business-to-business sales operations across all channels fully integrated with an order management system, eCommerce platform, point-of-sale system, and customer relationship management and business analytics solutions. The contractor shall provide a turnkey retail service solution encompassing hardware, software, hosting, operations and maintenance for contact center, fulfillment warehouse, and receipt and shipping functions, along with system and physical security and integration with internal and external systems.

View the file

Other files for this federal contract opportunity

Other files attached to Enterprise Sales and Marketing Solution, newest first.
File Type Posted
Amendment 002 Solicitation 2031JG22R00025.xlsx XLSX spreadsheet
ESM_Attachment C-1_VPAT Template.doc.docx DOCX document
REVISED United States Mint Request for Prosposal Solicitation 2031JG22R00025 Enterprise Sales and Marketing Solution.pdf PDF
ESM_Attachment 10_Contractor Performance Questionnaire_Final.docx DOCX document
Amendment 001 Solicitation 2031JG22R00025.xlsx XLSX spreadsheet
United States Mint Request for Prosposal Solicitation 2031JG22R00025 Enterprise Sales and Marketing Solution.pdf PDF
United States Mint Request for Proposal ESM Solicitation 2031JG22R00025.doc DOC document
ESM_Appendix D USM Internal and External Systems Interface Descriptions Final.xlsx XLSX spreadsheet
ESM_Attachment 7 Operational Cost Scenario Template Final.xlsx XLSX spreadsheet
ESM_Attachment 11 Contract Release-Form 7510 Final.docx DOCX document
ESM_Attachment 12 Sample Labor Categories and Descriptions Final.docx DOCX document
ESM_Appendix A 2 Functional and Business Requirements Workbook Final.xlsx XLSX spreadsheet
ESM_Appendix B Deliverables and Content Requirements Final.docx DOCX document
ESM_Attachment 9 Management and Technical Section L and M Final.pptx PPTX presentation
ESM_Appendix A 1 Functional and Business Requirements Final.docx DOCX document
ESM_Attachment 8 Overall Factor and Sub Factor Weighting Final.pptx PPTX presentation
ESM_Appendix C Go-Live and Full Operational Capability Definitions Final.docx DOCX document
ESM_Attachment 1 Statement of Objectives Final.docx DOCX document
ESM_Attachment 2 Historical Data Final.pptx PPTX presentation
ESM_Attachment 3 Key Performance Indicators Final.docx DOCX document
ESM_Attachment 4 Pay.Gov Technical Overview Final.pdf PDF
ESM_Attachment 6 Pricing Template Final.xlsx XLSX spreadsheet
ESM_Attachment 10 Contractor Performance Questionnaire Final.docx DOCX document
Show all 23

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

ATTACHMENT 5: System Security Control BaselinesAs of: 12/2/21
CONTROL NO.
CONTROL NAME
CONTROL BASELINES
MEETS / PARTIALLY MEETS / DOES NOT MEET
EXPLANATION
PRIVACY
LOW
MOD
HIGH

ACCESS CONTROL

AC-1
Policy and Procedures
X
X
X
X
AC-2
Account Management
N/A - Not Selected
X
X
X
AC-2(1)
Account Management | Automated System Account Management
N/A - Not Selected
N/A - Not Selected
X
X
AC-2(2)
Account Management | Automated Temporary and Emergency Account Management
N/A - Not Selected
N/A - Not Selected
X
X
AC-2(3)
Account Management | Disable Accounts
N/A - Not Selected
N/A - Not Selected
X
X
AC-2(4)
Account Management | Automated Audit Actions
N/A - Not Selected
N/A - Not Selected
X
X
AC-2(5)
Account Management | Inactivity Logout
N/A - Not Selected
N/A - Not Selected
X
X
AC-2(6)
Account Management | Dynamic Privilege Management
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
AC-2(7)
Account Management | Privileged User Accounts
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
AC-2(8)
Account Management | Dynamic Account Management
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
AC-2(9)
Account Management | Restrictions on Use of Shared and Group Accounts
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
AC-2(11)
Account Management | Usage Conditions
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
X
AC-2(12)
Account Management | Account Monitoring for Atypical Usage
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
X
AC-2(13)
Account Management | Disable Accounts for High-risk Individuals
N/A - Not Selected
N/A - Not Selected
X
X
AC-3
Access Enforcement
N/A - Not Selected
X
X
X
AC-3(1)
Access Enforcement | Restricted Access to Privileged Functions
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
AC-3(3)
Access Enforcement | Mandatory Access Control
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
AC-3(4)
Access Enforcement | Discretionary Access Control
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
AC-3(5)
Access Enforcement | Security-relevant Information
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
AC-3(7)
Access Enforcement | Role-based Access Control
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
AC-3(8)
Access Enforcement | Revocation of Access Authorizations
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
AC-3(9)
Access Enforcement | Controlled Release
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
AC-3(10)
Access Enforcement | Audited Override of Access Control Mechanisms
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
AC-3(11)
Access Enforcement | Restrict Access to Specific Information Types
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
AC-3(12)
Access Enforcement | Assert and Enforce Application Access
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
AC-3(13)
Access Enforcement | Attribute-based Access Control
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
AC-3(14)
Access Enforcement | Individual Access
X
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
AC-3(15)
Access Enforcement | Discretionary and Mandatory Access Control
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
AC-4
Information Flow Enforcement
N/A - Not Selected
N/A - Not Selected
X
X
AC-4(1)
Information Flow Enforcement | Object Security and Privacy Attributes
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
AC-4(2)
Information Flow Enforcement | Processing Domains
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
AC-4(3)
Information Flow Enforcement | Dynamic Information Flow Control
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
AC-4(4)
Information Flow Enforcement | Flow Control of Encrypted Information
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
X
AC-4(5)
Information Flow Enforcement | Embedded Data Types
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
AC-4(6)
Information Flow Enforcement | Metadata
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
AC-4(7)
Information Flow Enforcement | One-way Flow Mechanisms
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
AC-4(8)
Information Flow Enforcement | Security and Privacy Policy Filters
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
AC-4(9)
Information Flow Enforcement | Human Reviews
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
AC-4(10)
Information Flow Enforcement | Enable and Disable Security or Privacy Policy Filters
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
AC-4(11)
Information Flow Enforcement | Configuration of Security or Privacy Policy Filters
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
AC-4(12)
Information Flow Enforcement | Data Type Identifiers
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
AC-4(13)
Information Flow Enforcement | Decomposition into Policy-relevant Subcomponents
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
AC-4(14)
Information Flow Enforcement | Security or Privacy Policy Filter Constraints
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
AC-4(15)
Information Flow Enforcement | Detection of Unsanctioned Information
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
AC-4(17)
Information Flow Enforcement | Domain Authentication
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
AC-4(19)
Information Flow Enforcement | Validation of Metadata
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
AC-4(20)
Information Flow Enforcement | Approved Solutions
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
AC-4(21)
Information Flow Enforcement | Physical or Logical Separation of Information Flows
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
AC-4(22)
Information Flow Enforcement | Access Only
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
AC-4(23)
Information Flow Enforcement | Modify Non-releasable Information
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
AC-4(24)
Information Flow Enforcement | Internal Normalized Format
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
AC-4(25)
Information Flow Enforcement | Data Sanitization
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
AC-4(26)
Information Flow Enforcement | Audit Filtering Actions
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
AC-4(27)
Information Flow Enforcement | Redundant/independent Filtering Mechanisms
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
AC-4(28)
Information Flow Enforcement | Linear Filter Pipelines
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
AC-4(29)
Information Flow Enforcement | Filter Orchestration Engines
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
AC-4(30)
Information Flow Enforcement | Filter Mechanisms Using Multiple Processes
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
AC-4(31)
Information Flow Enforcement | Failed Content Transfer Prevention
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
AC-4(32)
Information Flow Enforcement | Process Requirements for Information Transfer
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
AC-5
Separation of Duties
N/A - Not Selected
N/A - Not Selected
X
X
AC-6
Least Privilege
N/A - Not Selected
N/A - Not Selected
X
X
AC-6(1)
Least Privilege | Authorize Access to Security Functions
N/A - Not Selected
N/A - Not Selected
X
X
AC-6(2)
Least Privilege | Non-privileged Access for Nonsecurity Functions
N/A - Not Selected
N/A - Not Selected
X
X
AC-6(3)
Least Privilege | Network Access to Privileged Commands
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
X
AC-6(4)
Least Privilege | Separate Processing Domains
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
AC-6(5)
Least Privilege | Privileged Accounts
N/A - Not Selected
N/A - Not Selected
X
X
AC-6(6)
Least Privilege | Privileged Access by Non-organizational Users
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
AC-6(7)
Least Privilege | Review of User Privileges
N/A - Not Selected
N/A - Not Selected
X
X
AC-6(8)
Least Privilege | Privilege Levels for Code Execution
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
AC-6(9)
Least Privilege | Log Use of Privileged Functions
N/A - Not Selected
N/A - Not Selected
X
X
AC-6(10)
Least Privilege | Prohibit Non-privileged Users from Executing Privileged Functions
N/A - Not Selected
N/A - Not Selected
X
X
AC-7
Unsuccessful Logon Attempts
N/A - Not Selected
X
X
X
AC-7(2)
Unsuccessful Logon Attempts | Purge or Wipe Mobile Device
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
AC-7(3)
Unsuccessful Logon Attempts | Biometric Attempt Limiting
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
AC-7(4)
Unsuccessful Logon Attempts | Use of Alternate Authentication Factor
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
AC-8
System Use Notification
N/A - Not Selected
X
X
X
AC-9
Previous Logon Notification
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
AC-9(1)
Previous Logon Notification | Unsuccessful Logons
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
AC-9(2)
Previous Logon Notification | Successful and Unsuccessful Logons
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
AC-9(3)
Previous Logon Notification | Notification of Account Changes
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
AC-9(4)
Previous Logon Notification | Additional Logon Information
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
AC-10
Concurrent Session Control
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
X
AC-11
Device Lock
N/A - Not Selected
N/A - Not Selected
X
X
AC-11(1)
Device Lock | Pattern-hiding Displays
N/A - Not Selected
N/A - Not Selected
X
X
AC-12
Session Termination
N/A - Not Selected
N/A - Not Selected
X
X
AC-12(1)
Session Termination | User-initiated Logouts
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
AC-12(2)
Session Termination | Termination Message
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
AC-12(3)
Session Termination | Timeout Warning Message
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
AC-14
Permitted Actions Without Identification or Authentication
N/A - Not Selected
X
X
X
AC-16
Security and Privacy Attributes
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
AC-16(1)
Security and Privacy Attributes | Dynamic Attribute Association
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
AC-16(2)
Security and Privacy Attributes | Attribute Value Changes by Authorized Individuals
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
AC-16(3)
Security and Privacy Attributes | Maintenance of Attribute Associations by System
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
AC-16(4)
Security and Privacy Attributes | Association of Attributes by Authorized Individuals
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
AC-16(5)
Security and Privacy Attributes | Attribute Displays on Objects to Be Output
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
AC-16(6)
Security and Privacy Attributes | Maintenance of Attribute Association
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
AC-16(7)
Security and Privacy Attributes | Consistent Attribute Interpretation
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
AC-16(8)
Security and Privacy Attributes | Association Techniques and Technologies
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
AC-16(9)
Security and Privacy Attributes | Attribute Reassignment — Regrading Mechanisms
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
AC-16(10)
Security and Privacy Attributes | Attribute Configuration by Authorized Individuals
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
AC-17
Remote Access
N/A - Not Selected
X
X
X
AC-17(1)
Remote Access | Monitoring and Control
N/A - Not Selected
N/A - Not Selected
X
X
AC-17(2)
Remote Access | Protection of Confidentiality and Integrity Using Encryption
N/A - Not Selected
N/A - Not Selected
X
X
AC-17(3)
Remote Access | Managed Access Control Points
N/A - Not Selected
N/A - Not Selected
X
X
AC-17(4)
Remote Access | Privileged Commands and Access
N/A - Not Selected
N/A - Not Selected
X
X
AC-17(6)
Remote Access | Protection of Mechanism Information
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
AC-17(9)
Remote Access | Disconnect or Disable Access
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
AC-17(10)
Remote Access | Authenticate Remote Commands
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
AC-18
Wireless Access
N/A - Not Selected
X
X
X
AC-18(1)
Wireless Access | Authentication and Encryption
N/A - Not Selected
N/A - Not Selected
X
X
AC-18(3)
Wireless Access | Disable Wireless Networking
N/A - Not Selected
N/A - Not Selected
X
X
AC-18(4)
Wireless Access | Restrict Configurations by Users
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
X
AC-18(5)
Wireless Access | Antennas and Transmission Power Levels
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
X
AC-19
Access Control for Mobile Devices
N/A - Not Selected
X
X
X
AC-19(4)
Access Control for Mobile Devices | Restrictions for Classified Information
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
AC-19(5)
Access Control for Mobile Devices | Full Device or Container-based Encryption
N/A - Not Selected
N/A - Not Selected
X
X
AC-20
Use of External Systems
N/A - Not Selected
X
X
X
AC-20(1)
Use of External Systems | Limits on Authorized Use
N/A - Not Selected
N/A - Not Selected
X
X
AC-20(2)
Use of External Systems | Portable Storage Devices — Restricted Use
N/A - Not Selected
N/A - Not Selected
X
X
AC-20(3)
Use of External Systems | Non-organizationally Owned Systems — Restricted Use
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
AC-20(4)
Use of External Systems | Network Accessible Storage Devices — Prohibited Use
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
AC-20(5)
Use of External Systems | Portable Storage Devices — Prohibited Use
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
AC-21
Information Sharing
N/A - Not Selected
N/A - Not Selected
X
X
AC-21(1)
Information Sharing | Automated Decision Support
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
AC-21(2)
Information Sharing | Information Search and Retrieval
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
AC-22
Publicly Accessible Content
N/A - Not Selected
X
X
X
AC-23
Data Mining Protection
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
AC-24
Access Control Decisions
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
AC-24(1)
Access Control Decisions | Transmit Access Authorization Information
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
AC-24(2)
Access Control Decisions | No User or Process Identity
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
AC-25
Reference Monitor
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected

AWARENESS AND TRAINING

AT-1
Policy and Procedures
X
X
X
X
AT-2
Literacy Training and Awareness
X
X
X
X
AT-2(1)
Literacy Training and Awareness | Practical Exercises
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
AT-2(2)
Literacy Training and Awareness | Insider Threat
N/A - Not Selected
X
X
X
AT-2(3)
Literacy Training and Awareness | Social Engineering and Mining
N/A - Not Selected
N/A - Not Selected
X
X
AT-2(4)
Literacy Training and Awareness | Suspicious Communications and Anomalous System Behavior
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
AT-2(5)
Literacy Training and Awareness | Advanced Persistent Threat
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
AT-2(6)
Literacy Training and Awareness | Cyber Threat Environment
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
AT-3
Role-based Training
X
X
X
X
AT-3(1)
Role-based Training | Environmental Controls
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
AT-3(2)
Role-based Training | Physical Security Controls
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
AT-3(3)
Role-based Training | Practical Exercises
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
AT-3(5)
Role-based Training | Processing Personally Identifiable Information
X
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
AT-4
Training Records
X
X
X
X
AT-6
Training Feedback
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected

AUDIT AND ACCOUNTABILITY

AU-1
Policy and Procedures
X
X
X
X
AU-2
Event Logging
X
X
X
X
AU-3
Content of Audit Records
N/A - Not Selected
X
X
X
AU-3(1)
Content of Audit Records | Additional Audit Information
N/A - Not Selected
N/A - Not Selected
X
X
AU-3(3)
Content of Audit Records | Limit Personally Identifiable Information Elements
X
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
AU-4
Audit Log Storage Capacity
N/A - Not Selected
X
X
X
AU-4(1)
Audit Log Storage Capacity | Transfer to Alternate Storage
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
AU-5
Response to Audit Logging Process Failures
N/A - Not Selected
X
X
X
AU-5(1)
Response to Audit Logging Process Failures | Storage Capacity Warning
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
X
AU-5(2)
Response to Audit Logging Process Failures | Real-time Alerts
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
X
AU-5(3)
Response to Audit Logging Process Failures | Configurable Traffic Volume Thresholds
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
AU-5(4)
Response to Audit Logging Process Failures | Shutdown on Failure
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
AU-5(5)
Response to Audit Logging Process Failures | Alternate Audit Logging Capability
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
AU-6
Audit Record Review, Analysis, and Reporting
N/A - Not Selected
X
X
X
AU-6(1)
Audit Record Review, Analysis, and Reporting | Automated Process Integration
N/A - Not Selected
N/A - Not Selected
X
X
AU-6(3)
Audit Record Review, Analysis, and Reporting | Correlate Audit Record Repositories
N/A - Not Selected
N/A - Not Selected
X
X
AU-6(4)
Audit Record Review, Analysis, and Reporting | Central Review and Analysis
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
AU-6(5)
Audit Record Review, Analysis, and Reporting | Integrated Analysis of Audit Records
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
X
AU-6(6)
Audit Record Review, Analysis, and Reporting | Correlation with Physical Monitoring
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
X
AU-6(7)
Audit Record Review, Analysis, and Reporting | Permitted Actions
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
AU-6(8)
Audit Record Review, Analysis, and Reporting | Full Text Analysis of Privileged Commands
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
AU-6(9)
Audit Record Review, Analysis, and Reporting | Correlation with Information from Nontechnical Sources
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
AU-7
Audit Record Reduction and Report Generation
N/A - Not Selected
N/A - Not Selected
X
X
AU-7(1)
Audit Record Reduction and Report Generation | Automatic Processing
N/A - Not Selected
N/A - Not Selected
X
X
AU-8
Time Stamps
N/A - Not Selected
X
X
X
AU-9
Protection of Audit Information
N/A - Not Selected
X
X
X
AU-9(1)
Protection of Audit Information | Hardware Write-once Media
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
AU-9(2)
Protection of Audit Information | Store on Separate Physical Systems or Components
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
X
AU-9(3)
Protection of Audit Information | Cryptographic Protection
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
X
AU-9(4)
Protection of Audit Information | Access by Subset of Privileged Users
N/A - Not Selected
N/A - Not Selected
X
X
AU-9(5)
Protection of Audit Information | Dual Authorization
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
AU-9(6)
Protection of Audit Information | Read-only Access
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
AU-9(7)
Protection of Audit Information | Store on Component with Different Operating System
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
AU-10
Non-repudiation
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
X
AU-10(1)
Non-repudiation | Association of Identities
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
AU-10(2)
Non-repudiation | Validate Binding of Information Producer Identity
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
AU-10(3)
Non-repudiation | Chain of Custody
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
AU-10(4)
Non-repudiation | Validate Binding of Information Reviewer Identity
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
AU-11
Audit Record Retention
X
X
X
X
AU-11(1)
Audit Record Retention | Long-term Retrieval Capability
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
AU-12
Audit Record Generation
N/A - Not Selected
X
X
X
AU-12(1)
Audit Record Generation | System-wide and Time-correlated Audit Trail
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
X
AU-12(2)
Audit Record Generation | Standardized Formats
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
AU-12(3)
Audit Record Generation | Changes by Authorized Individuals
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
X
AU-12(4)
Audit Record Generation | Query Parameter Audits of Personally Identifiable Information
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
AU-13
Monitoring for Information Disclosure
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
AU-13(1)
Monitoring for Information Disclosure | Use of Automated Tools
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
AU-13(2)
Monitoring for Information Disclosure | Review of Monitored Sites
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
AU-13(3)
Monitoring for Information Disclosure | Unauthorized Replication of Information
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
AU-14
Session Audit
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
AU-14(1)
Session Audit | System Start-up
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
AU-14(3)
Session Audit | Remote Viewing and Listening
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
AU-16
Cross-organizational Audit Logging
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
AU-16(1)
Cross-organizational Audit Logging | Identity Preservation
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
AU-16(2)
Cross-organizational Audit Logging | Sharing of Audit Information
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
AU-16(3)
Cross-organizational Audit Logging | Disassociability
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected

ASSESSMENT, AUTHORIZATION, AND MONITORING

CA-1
Policy and Procedures
X
X
X
X
CA-2
Control Assessments
X
X
X
X
CA-2(1)
Control Assessments | Independent Assessors
N/A - Not Selected
N/A - Not Selected
X
X
CA-2(2)
Control Assessments | Specialized Assessments
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
X
CA-2(3)
Control Assessments | Leveraging Results from External Organizations
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
CA-3
Information Exchange
N/A - Not Selected
X
X
X
CA-3(6)
Information Exchange | Transfer Authorizations
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
X
CA-3(7)
Information Exchange | Transitive Information Exchanges
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
CA-5
Plan of Action and Milestones
X
X
X
X
CA-5(1)
Plan of Action and Milestones | Automation Support for Accuracy and Currency
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
CA-6
Authorization
X
X
X
X
CA-6(1)
Authorization | Joint Authorization — Intra-organization
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
CA-6(2)
Authorization | Joint Authorization — Inter-organization
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
CA-7
Continuous Monitoring
X
X
X
X
CA-7(1)
Continuous Monitoring | Independent Assessment
N/A - Not Selected
N/A - Not Selected
X
X
CA-7(3)
Continuous Monitoring | Trend Analyses
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
CA-7(4)
Continuous Monitoring | Risk Monitoring
X
X
X
X
CA-7(5)
Continuous Monitoring | Consistency Analysis
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
CA-7(6)
Continuous Monitoring | Automation Support for Monitoring
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
CA-8
Penetration Testing
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
X
CA-8(1)
Penetration Testing | Independent Penetration Testing Agent or Team
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
X
CA-8(2)
Penetration Testing | Red Team Exercises
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
CA-8(3)
Penetration Testing | Facility Penetration Testing
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
CA-9
Internal System Connections
N/A - Not Selected
X
X
X
CA-9(1)
Internal System Connections | Compliance Checks
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected

CONFIGURATION MANAGEMENT

CM-1
Policy and Procedures
X
X
X
X
CM-2
Baseline Configuration
N/A - Not Selected
X
X
X
CM-2(2)
Baseline Configuration | Automation Support for Accuracy and Currency
N/A - Not Selected
N/A - Not Selected
X
X
CM-2(3)
Baseline Configuration | Retention of Previous Configurations
N/A - Not Selected
N/A - Not Selected
X
X
CM-2(6)
Baseline Configuration | Development and Test Environments
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
CM-2(7)
Baseline Configuration | Configure Systems and Components for High-risk Areas
N/A - Not Selected
N/A - Not Selected
X
X
CM-3
Configuration Change Control
N/A - Not Selected
N/A - Not Selected
X
X
CM-3(1)
Configuration Change Control | Automated Documentation, Notification, and Prohibition of Changes
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
X
CM-3(2)
Configuration Change Control | Testing, Validation, and Documentation of Changes
N/A - Not Selected
N/A - Not Selected
X
X
CM-3(3)
Configuration Change Control | Automated Change Implementation
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
CM-3(4)
Configuration Change Control | Security and Privacy Representatives
N/A - Not Selected
N/A - Not Selected
X
X
CM-3(5)
Configuration Change Control | Automated Security Response
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
CM-3(6)
Configuration Change Control | Cryptography Management
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
X
CM-3(7)
Configuration Change Control | Review System Changes
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
CM-3(8)
Configuration Change Control | Prevent or Restrict Configuration Changes
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
CM-4
Impact Analyses
X
X
X
X
CM-4(1)
Impact Analyses | Separate Test Environments
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
X
CM-4(2)
Impact Analyses | Verification of Controls
N/A - Not Selected
N/A - Not Selected
X
X
CM-5
Access Restrictions for Change
N/A - Not Selected
X
X
X
CM-5(1)
Access Restrictions for Change | Automated Access Enforcement and Audit Records
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
X
CM-5(4)
Access Restrictions for Change | Dual Authorization
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
CM-5(5)
Access Restrictions for Change | Privilege Limitation for Production and Operation
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
CM-5(6)
Access Restrictions for Change | Limit Library Privileges
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
CM-6
Configuration Settings
N/A - Not Selected
X
X
X
CM-6(1)
Configuration Settings | Automated Management, Application, and Verification
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
X
CM-6(2)
Configuration Settings | Respond to Unauthorized Changes
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
X
CM-7
Least Functionality
N/A - Not Selected
X
X
X
CM-7(1)
Least Functionality | Periodic Review
N/A - Not Selected
N/A - Not Selected
X
X
CM-7(2)
Least Functionality | Prevent Program Execution
N/A - Not Selected
N/A - Not Selected
X
X
CM-7(3)
Least Functionality | Registration Compliance
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
CM-7(4)
Least Functionality | Unauthorized Software
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
CM-7(5)
Least Functionality | Authorized Software
N/A - Not Selected
N/A - Not Selected
X
X
CM-7(6)
Least Functionality | Confined Environments with Limited Privileges
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
CM-7(7)
Least Functionality | Code Execution in Protected Environments
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
CM-7(8)
Least Functionality | Binary or Machine Executable Code
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
CM-7(9)
Least Functionality | Prohibiting The Use of Unauthorized Hardware
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
CM-8
System Component Inventory
N/A - Not Selected
X
X
X
CM-8(1)
System Component Inventory | Updates During Installation and Removal
N/A - Not Selected
N/A - Not Selected
X
X
CM-8(2)
System Component Inventory | Automated Maintenance
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
X
CM-8(3)
System Component Inventory | Automated Unauthorized Component Detection
N/A - Not Selected
N/A - Not Selected
X
X
CM-8(4)
System Component Inventory | Accountability Information
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
X
CM-8(6)
System Component Inventory | Assessed Configurations and Approved Deviations
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
CM-8(7)
System Component Inventory | Centralized Repository
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
CM-8(8)
System Component Inventory | Automated Location Tracking
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
CM-8(9)
System Component Inventory | Assignment of Components to Systems
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
CM-9
Configuration Management Plan
N/A - Not Selected
N/A - Not Selected
X
X
CM-9(1)
Configuration Management Plan | Assignment of Responsibility
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
CM-10
Software Usage Restrictions
N/A - Not Selected
X
X
X
CM-10(1)
Software Usage Restrictions | Open-source Software
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
CM-11
User-installed Software
N/A - Not Selected
X
X
X
CM-11(2)
User-installed Software | Software Installation with Privileged Status
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
CM-11(3)
User-installed Software | Automated Enforcement and Monitoring
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
CM-12
Information Location
N/A - Not Selected
N/A - Not Selected
X
X
CM-12(1)
Information Location | Automated Tools to Support Information Location
N/A - Not Selected
N/A - Not Selected
X
X
CM-13
Data Action Mapping
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
CM-14
Signed Components
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected

CONTINGENCY PLANNING

CP-1
Policy and Procedures
N/A - Not Selected
X
X
X
CP-2
Contingency Plan
N/A - Not Selected
X
X
X
CP-2(1)
Contingency Plan | Coordinate with Related Plans
N/A - Not Selected
N/A - Not Selected
X
X
CP-2(2)
Contingency Plan | Capacity Planning
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
X
CP-2(3)
Contingency Plan | Resume Mission and Business Functions
N/A - Not Selected
N/A - Not Selected
X
X
CP-2(5)
Contingency Plan | Continue Mission and Business Functions
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
X
CP-2(6)
Contingency Plan | Alternate Processing and Storage Sites
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
CP-2(7)
Contingency Plan | Coordinate with External Service Providers
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
CP-2(8)
Contingency Plan | Identify Critical Assets
N/A - Not Selected
N/A - Not Selected
X
X
CP-3
Contingency Training
N/A - Not Selected
X
X
X
CP-3(1)
Contingency Training | Simulated Events
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
X
CP-3(2)
Contingency Training | Mechanisms Used in Training Environments
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
CP-4
Contingency Plan Testing
N/A - Not Selected
X
X
X
CP-4(1)
Contingency Plan Testing | Coordinate with Related Plans
N/A - Not Selected
N/A - Not Selected
X
X
CP-4(2)
Contingency Plan Testing | Alternate Processing Site
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
X
CP-4(3)
Contingency Plan Testing | Automated Testing
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
CP-4(4)
Contingency Plan Testing | Full Recovery and Reconstitution
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
CP-4(5)
Contingency Plan Testing | Self-challenge
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
CP-6
Alternate Storage Site
N/A - Not Selected
N/A - Not Selected
X
X
CP-6(1)
Alternate Storage Site | Separation from Primary Site
N/A - Not Selected
N/A - Not Selected
X
X
CP-6(2)
Alternate Storage Site | Recovery Time and Recovery Point Objectives
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
X
CP-6(3)
Alternate Storage Site | Accessibility
N/A - Not Selected
N/A - Not Selected
X
X
CP-7
Alternate Processing Site
N/A - Not Selected
N/A - Not Selected
X
X
CP-7(1)
Alternate Processing Site | Separation from Primary Site
N/A - Not Selected
N/A - Not Selected
X
X
CP-7(2)
Alternate Processing Site | Accessibility
N/A - Not Selected
N/A - Not Selected
X
X
CP-7(3)
Alternate Processing Site | Priority of Service
N/A - Not Selected
N/A - Not Selected
X
X
CP-7(4)
Alternate Processing Site | Preparation for Use
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
X
CP-7(6)
Alternate Processing Site | Inability to Return to Primary Site
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
CP-8
Telecommunications Services
N/A - Not Selected
N/A - Not Selected
X
X
CP-8(1)
Telecommunications Services | Priority of Service Provisions
N/A - Not Selected
N/A - Not Selected
X
X
CP-8(2)
Telecommunications Services | Single Points of Failure
N/A - Not Selected
N/A - Not Selected
X
X
CP-8(3)
Telecommunications Services | Separation of Primary and Alternate Providers
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
X
CP-8(4)
Telecommunications Services | Provider Contingency Plan
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
X
CP-8(5)
Telecommunications Services | Alternate Telecommunication Service Testing
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
CP-9
System Backup
N/A - Not Selected
X
X
X
CP-9(1)
System Backup | Testing for Reliability and Integrity
N/A - Not Selected
N/A - Not Selected
X
X
CP-9(2)
System Backup | Test Restoration Using Sampling
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
X
CP-9(3)
System Backup | Separate Storage for Critical Information
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
X
CP-9(5)
System Backup | Transfer to Alternate Storage Site
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
X
CP-9(6)
System Backup | Redundant Secondary System
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
CP-9(7)
System Backup | Dual Authorization
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
CP-9(8)
System Backup | Cryptographic Protection
N/A - Not Selected
N/A - Not Selected
X
X
CP-10
System Recovery and Reconstitution
N/A - Not Selected
X
X
X
CP-10(2)
System Recovery and Reconstitution | Transaction Recovery
N/A - Not Selected
N/A - Not Selected
X
X
CP-10(4)
System Recovery and Reconstitution | Restore Within Time Period
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
X
CP-10(6)
System Recovery and Reconstitution | Component Protection
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
CP-11
Alternate Communications Protocols
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
CP-12
Safe Mode
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
CP-13
Alternative Security Mechanisms
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected

IDENTIFICATION AND AUTHENTICATION

IA-1
Policy and Procedures
N/A - Not Selected
X
X
X
IA-2
Identification and Authentication (organizational Users)
N/A - Not Selected
X
X
X
IA-2(1)
Identification and Authentication (organizational Users) | Multi-factor Authentication to Privileged Accounts
N/A - Not Selected
X
X
X
IA-2(2)
Identification and Authentication (organizational Users) | Multi-factor Authentication to Non-privileged Accounts
N/A - Not Selected
X
X
X
IA-2(5)
Identification and Authentication (organizational Users) | Individual Authentication with Group Authentication
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
X
IA-2(6)
Identification and Authentication (organizational Users) | Access to Accounts — Separate Device
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
IA-2(8)
Identification and Authentication (organizational Users) | Access to Accounts — Replay Resistant
N/A - Not Selected
X
X
X
IA-2(10)
Identification and Authentication (organizational Users) | Single Sign-on
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
IA-2(12)
Identification and Authentication (organizational Users) | Acceptance of PIV Credentials
N/A - Not Selected
X
X
X
IA-2(13)
Identification and Authentication (organizational Users) | Out-of-band Authentication
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
IA-3
Device Identification and Authentication
N/A - Not Selected
N/A - Not Selected
X
X
IA-3(1)
Device Identification and Authentication | Cryptographic Bidirectional Authentication
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
IA-3(3)
Device Identification and Authentication | Dynamic Address Allocation
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
IA-3(4)
Device Identification and Authentication | Device Attestation
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
IA-4
Identifier Management
N/A - Not Selected
X
X
X
IA-4(1)
Identifier Management | Prohibit Account Identifiers as Public Identifiers
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
IA-4(4)
Identifier Management | Identify User Status
N/A - Not Selected
N/A - Not Selected
X
X
IA-4(5)
Identifier Management | Dynamic Management
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
IA-4(6)
Identifier Management | Cross-organization Management
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
IA-4(8)
Identifier Management | Pairwise Pseudonymous Identifiers
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
IA-4(9)
Identifier Management | Attribute Maintenance and Protection
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
IA-5
Authenticator Management
N/A - Not Selected
X
X
X
IA-5(1)
Authenticator Management | Password-based Authentication
N/A - Not Selected
X
X
X
IA-5(2)
Authenticator Management | Public Key-based Authentication
N/A - Not Selected
N/A - Not Selected
X
X
IA-5(5)
Authenticator Management | Change Authenticators Prior to Delivery
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
IA-5(6)
Authenticator Management | Protection of Authenticators
N/A - Not Selected
N/A - Not Selected
X
X
IA-5(7)
Authenticator Management | No Embedded Unencrypted Static Authenticators
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
IA-5(8)
Authenticator Management | Multiple System Accounts
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
IA-5(9)
Authenticator Management | Federated Credential Management
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
IA-5(10)
Authenticator Management | Dynamic Credential Binding
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
IA-5(12)
Authenticator Management | Biometric Authentication Performance
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
IA-5(13)
Authenticator Management | Expiration of Cached Authenticators
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
IA-5(14)
Authenticator Management | Managing Content of PKI Trust Stores
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
IA-5(15)
Authenticator Management | GSA-approved Products and Services
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
IA-5(16)
Authenticator Management | In-person or Trusted External Party Authenticator Issuance
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
IA-5(17)
Authenticator Management | Presentation Attack Detection for Biometric Authenticators
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
IA-5(18)
Authenticator Management | Password Managers
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
IA-6
Authentication Feedback
N/A - Not Selected
X
X
X
IA-7
Cryptographic Module Authentication
N/A - Not Selected
X
X
X
IA-8
Identification and Authentication (non-organizational Users)
N/A - Not Selected
X
X
X
IA-8(1)
Identification and Authentication (non-organizational Users) | Acceptance of PIV Credentials from Other Agencies
N/A - Not Selected
X
X
X
IA-8(2)
Identification and Authentication (non-organizational Users) | Acceptance of External Authenticators
N/A - Not Selected
X
X
X
IA-8(4)
Identification and Authentication (non-organizational Users) | Use of Defined Profiles
N/A - Not Selected
X
X
X
IA-8(5)
Identification and Authentication (non-organizational Users) | Acceptance of PIV-I Credentials
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
IA-8(6)
Identification and Authentication (non-organizational Users) | Disassociability
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
IA-9
Service Identification and Authentication
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
IA-10
Adaptive Authentication
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
IA-11
Re-authentication
N/A - Not Selected
X
X
X
IA-12
Identity Proofing
N/A - Not Selected
N/A - Not Selected
X
X
IA-12(1)
Identity Proofing | Supervisor Authorization
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
IA-12(2)
Identity Proofing | Identity Evidence
N/A - Not Selected
N/A - Not Selected
X
X
IA-12(3)
Identity Proofing | Identity Evidence Validation and Verification
N/A - Not Selected
N/A - Not Selected
X
X
IA-12(4)
Identity Proofing | In-person Validation and Verification
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
X
IA-12(5)
Identity Proofing | Address Confirmation
N/A - Not Selected
N/A - Not Selected
X
X
IA-12(6)
Identity Proofing | Accept Externally-proofed Identities
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected

INCIDENT RESPONSE

IR-1
Policy and Procedures
X
X
X
X
IR-2
Incident Response Training
X
X
X
X
IR-2(1)
Incident Response Training | Simulated Events
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
X
IR-2(2)
Incident Response Training | Automated Training Environments
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
X
IR-2(3)
Incident Response Training | Breach
X
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
IR-3
Incident Response Testing
X
N/A - Not Selected
X
X
IR-3(1)
Incident Response Testing | Automated Testing
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
IR-3(2)
Incident Response Testing | Coordination with Related Plans
N/A - Not Selected
N/A - Not Selected
X
X
IR-3(3)
Incident Response Testing | Continuous Improvement
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
IR-4
Incident Handling
X
X
X
X
IR-4(1)
Incident Handling | Automated Incident Handling Processes
N/A - Not Selected
N/A - Not Selected
X
X
IR-4(2)
Incident Handling | Dynamic Reconfiguration
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
IR-4(3)
Incident Handling | Continuity of Operations
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
IR-4(4)
Incident Handling | Information Correlation
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
X
IR-4(5)
Incident Handling | Automatic Disabling of System
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
IR-4(6)
Incident Handling | Insider Threats
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
IR-4(7)
Incident Handling | Insider Threats — Intra-organization Coordination
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
IR-4(8)
Incident Handling | Correlation with External Organizations
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
IR-4(9)
Incident Handling | Dynamic Response Capability
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
IR-4(10)
Incident Handling | Supply Chain Coordination
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
IR-4(11)
Incident Handling | Integrated Incident Response Team
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
X
IR-4(12)
Incident Handling | Malicious Code and Forensic Analysis
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
IR-4(13)
Incident Handling | Behavior Analysis
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
IR-4(14)
Incident Handling | Security Operations Center
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
IR-4(15)
Incident Handling | Public Relations and Reputation Repair
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
IR-5
Incident Monitoring
X
X
X
X
IR-5(1)
Incident Monitoring | Automated Tracking, Data Collection, and Analysis
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
X
IR-6
Incident Reporting
X
X
X
X
IR-6(1)
Incident Reporting | Automated Reporting
N/A - Not Selected
N/A - Not Selected
X
X
IR-6(2)
Incident Reporting | Vulnerabilities Related to Incidents
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
IR-6(3)
Incident Reporting | Supply Chain Coordination
N/A - Not Selected
N/A - Not Selected
X
X
IR-7
Incident Response Assistance
X
X
X
X
IR-7(1)
Incident Response Assistance | Automation Support for Availability of Information and Support
N/A - Not Selected
N/A - Not Selected
X
X
IR-7(2)
Incident Response Assistance | Coordination with External Providers
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
IR-8
Incident Response Plan
X
X
X
X
IR-8(1)
Incident Response Plan | Breaches
X
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
IR-9
Information Spillage Response
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
IR-9(2)
Information Spillage Response | Training
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
IR-9(3)
Information Spillage Response | Post-spill Operations
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
IR-9(4)
Information Spillage Response | Exposure to Unauthorized Personnel
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected

MAINTENANCE

MA-1
Policy and Procedures
N/A - Not Selected
X
X
X
MA-2
Controlled Maintenance
N/A - Not Selected
X
X
X
MA-2(2)
Controlled Maintenance | Automated Maintenance Activities
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
X
MA-3
Maintenance Tools
N/A - Not Selected
N/A - Not Selected
X
X
MA-3(1)
Maintenance Tools | Inspect Tools
N/A - Not Selected
N/A - Not Selected
X
X
MA-3(2)
Maintenance Tools | Inspect Media
N/A - Not Selected
N/A - Not Selected
X
X
MA-3(3)
Maintenance Tools | Prevent Unauthorized Removal
N/A - Not Selected
N/A - Not Selected
X
X
MA-3(4)
Maintenance Tools | Restricted Tool Use
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
MA-3(5)
Maintenance Tools | Execution with Privilege
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
MA-3(6)
Maintenance Tools | Software Updates and Patches
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
MA-4
Nonlocal Maintenance
N/A - Not Selected
X
X
X
MA-4(1)
Nonlocal Maintenance | Logging and Review
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
MA-4(3)
Nonlocal Maintenance | Comparable Security and Sanitization
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
X
MA-4(4)
Nonlocal Maintenance | Authentication and Separation of Maintenance Sessions
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
MA-4(5)
Nonlocal Maintenance | Approvals and Notifications
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
MA-4(6)
Nonlocal Maintenance | Cryptographic Protection
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
MA-4(7)
Nonlocal Maintenance | Disconnect Verification
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
N/A - Not Selected
MA-5
Maintenance Personnel
N/A - Not Selected
X
X
X
MA-5(1)
Maintenance Personnel | Individuals Without Appropriate Access
N/A - Not Selected
N/A - Not Selected

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .