All records
Page 5 of 17. 1677 records.
Browse the catalog · First JSON page
control
A.4.3 — Data resources
control
A.4.4 — Tooling resources
control
A.4.5 — System and computing resources
control
A.4.6 — Human resources
control
A.5.2 — AI system impact assessment process
control
A.5.3 — Documentation of AI system impact assessments
control
A.5.4 — Assessing AI system impact on individuals or groups of individuals
control
A.5.5 — Assessing societal impacts of AI systems
control
A.6.1.2 — Objectives for responsible development of AI systems
control
A.6.1.3 — Processes for responsible AI system design and development
control
A.6.2.2 — AI system requirements and specification
control
A.6.2.3 — Documentation of AI system design and development
control
A.6.2.4 — AI system verification and validation
control
A.6.2.5 — AI system deployment
control
A.6.2.6 — AI system operation and monitoring
control
A.6.2.7 — AI system technical documentation
control
A.6.2.8 — AI system recording of event logs
control
A.7.2 — Data for development and enhancement of AI systems
control
A.7.3 — Acquisition of data
control
A.7.4 — Data quality for AI systems
control
A.7.5 — Data provenance
control
A.7.6 — Data preparation
control
A.8.2 — System documentation and information for users
control
A.8.3 — External reporting
control
A.8.4 — Communication of incidents
control
A.8.5 — Information for interested parties
control
A.9.2 — Processes for responsible use of AI systems
control
A.9.3 — Objectives for responsible use of AI systems
control
A.9.4 — Intended use of the AI system
control
NIS2-Art20 — Governance and management body accountability / training
control
NIS2-Art21a — Policies on risk analysis and information system security
control
NIS2-Art21b — Incident handling
control
NIS2-Art21c — Business continuity, backup management and disaster recovery, crisis management
control
NIS2-Art21d — Supply chain security
control
NIS2-Art21e — Security in acquisition, development and maintenance of network and information systems (incl. vulnerability handling and disclosure)
control
NIS2-Art21f — Policies and procedures to assess the effectiveness of cybersecurity risk-management measures
control
NIS2-Art21g — Basic cyber hygiene practices and cybersecurity training
control
NIS2-Art21h — Policies on the use of cryptography and encryption
control
NIS2-Art21i — Human resources security, access control policies and asset management
control
NIS2-Art21j — Use of multi-factor authentication, secured communications and emergency communication systems
control
NIS2-Art23 — Reporting obligations (early warning 24h, incident notification 72h, final report 1 month)
control
AC-1 — Policy and Procedures
control
AC-10 — Concurrent Session Control
control
AC-11 — Device Lock
control
AC-12 — Session Termination
control
AC-14 — Permitted Actions Without Identification or Authentication
control
AC-16 — Security and Privacy Attributes
control
AC-17 — Remote Access
control
AC-18 — Wireless Access
control
AC-19 — Access Control for Mobile Devices
control
AC-2 — Account Management
control
AC-20 — Use of External Systems
control
AC-21 — Information Sharing
control
AC-22 — Publicly Accessible Content
control
AC-24 — Access Control Decisions
control
AC-25 — Reference Monitor
control
AC-3 — Access Enforcement
control
AC-4 — Information Flow Enforcement
control
AC-5 — Separation of Duties
control
AC-6 — Least Privilege
control
AC-7 — Unsuccessful Logon Attempts
control
AC-8 — System Use Notification
control
AC-9 — Previous Logon Notification
control
AT-1 — Policy and Procedures
control
AT-2 — Literacy Training and Awareness
control
AT-3 — Role-based Training
control
AT-4 — Training Records
control
AT-6 — Training Feedback
control
AU-1 — Policy and Procedures
control
AU-10 — Non-repudiation
control
AU-11 — Audit Record Retention
control
AU-12 — Audit Record Generation
control
AU-13 — Monitoring for Information Disclosure
control
AU-14 — Session Audit
control
AU-16 — Cross-organizational Audit Logging
control
AU-2 — Event Logging
control
AU-3 — Content of Audit Records
control
AU-4 — Audit Log Storage Capacity
control
AU-5 — Response to Audit Logging Process Failures
control
AU-6 — Audit Record Review, Analysis, and Reporting
control
AU-7 — Audit Record Reduction and Report Generation
control
AU-8 — Time Stamps
control
AU-9 — Protection of Audit Information
control
CA-1 — Policy and Procedures
control
CA-2 — Control Assessments
control
CA-3 — Information Exchange
control
CA-5 — Plan of Action and Milestones
control
CA-6 — Authorization
control
CA-7 — Continuous Monitoring
control
CA-8 — Penetration Testing
control
CA-9 — Internal System Connections
control
CM-1 — Policy and Procedures
control
CM-10 — Software Usage Restrictions
control
CM-11 — User-installed Software
control
CM-12 — Information Location
control
CM-13 — Data Action Mapping
control
CM-14 — Signed Components
control
CM-2 — Baseline Configuration
control
CM-3 — Configuration Change Control
control
CM-4 — Impact Analyses