Control records
Page 1 of 10. 979 records.
Browse the catalog · First JSON page
control
A001 — Establish input data policy
control
A002 — Establish output data policy
control
A003 — Limit AI agent data access
control
A004 — Protect IP & trade secrets
control
A005 — Prevent cross-customer data exposure
control
A006 — Prevent PII leakage
control
A007 — Prevent IP violations
control
A008 — Prevent leakage of credentials and secrets
control
B001 — Third-party testing of adversarial robustness
control
B002 — Detect adversarial input
control
B003 — Manage public release of technical details
control
B004 — Prevent AI endpoint scraping
control
B005 — Implement real-time input filtering
control
B006 — Prevent unauthorized AI agent actions
control
B007 — Enforce user access privileges to AI systems
control
B008 — Protect AI system deployment environment
control
B009 — Limit output over-exposure
control
B010 — Promote secure patterns in generated code
control
C001 — Define AI risk taxonomy
control
C002 — Conduct pre-deployment testing
control
C003 — Prevent harmful outputs
control
C004 — Prevent out-of-scope outputs
control
C005 — Prevent agent-specific high risk outputs
control
C006 — Prevent output vulnerabilities
control
C007 — Flag high risk outputs for human review
control
C008 — Monitor AI risk categories
control
C009 — Enable real-time feedback and intervention
control
C010 — Third-party testing for harmful outputs
control
C011 — Third-party testing for out-of-scope outputs
control
C012 — Third-party testing for customer-defined risk
control
D001 — Prevent hallucinated outputs
control
D002 — Third-party testing for hallucinations
control
D003 — Restrict unsafe tool calls
control
D004 — Third-party testing of tool calls
control
E001 — AI failure plan for security breaches
control
E002 — AI failure plan for harmful outputs
control
E003 — AI failure plan for hallucinations
control
E004 — Assign accountability
control
E005 — Document data storage security
control
E006 — Conduct vendor due diligence
control
E008 — Review internal processes
control
E009 — Monitor third-party access
control
E010 — Establish AI acceptable use policy
control
E011 — Record processing locations
control
E012 — Document regulatory compliance
control
E013 — Implement quality management system
control
E015 — Log AI system activity
control
E016 — Implement AI disclosure mechanisms
control
E017 — Document system transparency policy
control
F001 — Prevent AI cyber misuse
control
F002 — Prevent catastrophic misuse
control
CCPA-1798.100 — Notice at collection and consumer right to know
control
CCPA-1798.105 — Right to delete personal information
control
CCPA-1798.106 — Right to correct inaccurate personal information
control
CCPA-1798.110-115 — Rights to access and disclosure of personal information collected, sold, or shared
control
CCPA-1798.120-121 — Right to opt out of sale/sharing and to limit use of sensitive personal information
control
CCPA-1798.125 — Non-discrimination and financial-incentive requirements
control
CCPA-1798.130-135 — Request-handling mechanics, verification, and opt-out link requirements
control
CCPA-1798.140 — Service-provider and contractor contract requirements
control
CCPA-1798.150 — Reasonable security procedures; private right of action for breaches
control
CCPA-1798.185 — CPPA regulations: cybersecurity audits and risk assessments
control
APO01 — Managed I&T Management Framework
control
APO02 — Managed Strategy
control
APO03 — Managed Enterprise Architecture
control
APO04 — Managed Innovation
control
APO05 — Managed Portfolio
control
APO06 — Managed Budget and Costs
control
APO07 — Managed Human Resources
control
APO08 — Managed Relationships
control
APO09 — Managed Service Agreements
control
APO10 — Managed Vendors
control
APO11 — Managed Quality
control
APO12 — Managed Risk
control
APO13 — Managed Security
control
APO14 — Managed Data
control
BAI01 — Managed Programs
control
BAI02 — Managed Requirements Definition
control
BAI03 — Managed Solutions Identification and Build
control
BAI04 — Managed Availability and Capacity
control
BAI05 — Managed Organizational Change
control
BAI06 — Managed IT Changes
control
BAI07 — Managed IT Change Acceptance and Transitioning
control
BAI08 — Managed Knowledge
control
BAI09 — Managed Assets
control
BAI10 — Managed Configuration
control
BAI11 — Managed Projects
control
DSS01 — Managed Operations
control
DSS02 — Managed Service Requests and Incidents
control
DSS03 — Managed Problems
control
DSS04 — Managed Continuity
control
DSS05 — Managed Security Services
control
DSS06 — Managed Business Process Controls
control
EDM01 — Ensured Governance Framework Setting and Maintenance
control
EDM02 — Ensured Benefits Delivery
control
EDM03 — Ensured Risk Optimization
control
EDM04 — Ensured Resource Optimization
control
EDM05 — Ensured Stakeholder Engagement
control
MEA01 — Managed Performance and Conformance Monitoring
control
MEA02 — Managed System of Internal Control
control
MEA03 — Managed Compliance With External Requirements