Control records
Page 8 of 10. 979 records.
Browse the catalog · First JSON page
control
SC-7 — Boundary Protection
control
SC-8 — Transmission Confidentiality and Integrity
control
SI-1 — Policy and Procedures
control
SI-10 — Information Input Validation
control
SI-11 — Error Handling
control
SI-12 — Information Management and Retention
control
SI-13 — Predictable Failure Prevention
control
SI-14 — Non-persistence
control
SI-15 — Information Output Filtering
control
SI-16 — Memory Protection
control
SI-17 — Fail-safe Procedures
control
SI-18 — Personally Identifiable Information Quality Operations
control
SI-19 — De-identification
control
SI-2 — Flaw Remediation
control
SI-20 — Tainting
control
SI-21 — Information Refresh
control
SI-22 — Information Diversity
control
SI-23 — Information Fragmentation
control
SI-3 — Malicious Code Protection
control
SI-4 — System Monitoring
control
SI-5 — Security Alerts, Advisories, and Directives
control
SI-6 — Security and Privacy Function Verification
control
SI-7 — Software, Firmware, and Information Integrity
control
SI-8 — Spam Protection
control
SR-1 — Policy and Procedures
control
SR-10 — Inspection of Systems or Components
control
SR-11 — Component Authenticity
control
SR-12 — Component Disposal
control
SR-2 — Supply Chain Risk Management Plan
control
SR-3 — Supply Chain Controls and Processes
control
SR-4 — Provenance
control
SR-5 — Acquisition Strategies, Tools, and Methods
control
SR-6 — Supplier Assessments and Reviews
control
SR-7 — Supply Chain Operations Security
control
SR-8 — Notification Agreements
control
SR-9 — Tamper Resistance and Detection
control
NIST-AGI-01 — Distinct agent identities and identity boundaries
control
NIST-AGI-02 — Agent authentication and credential lifecycle
control
NIST-AGI-03 — Context-sensitive authorization and least privilege
control
NIST-AGI-04 — Delegated authority and human accountability
control
NIST-AGI-05 — Verifiable agent action logs and authorization traceability
control
NIST-AGI-06 — Prompt-injection prevention and limits on resulting harm
control
NIST-AGI-07 — Prompt provenance and data-flow tracking
control
NIST-TEVV-01 — Define evaluation objectives, context, and measurements
control
NIST-TEVV-02 — Run evaluations and examine results and limitations
control
NIST-TEVV-03 — Evaluate AI systems in realistic operating settings
control
NIST-TEVV-04 — Test for disclosure of confidential information
control
NIST-TEVV-05 — Test direct and indirect prompt injection
control
NIST-TEVV-06 — Test agent tool misuse and unauthorized external actions
control
DE.AE-02 — Adverse Event Analysis: Potentially adverse events are analyzed to better understand associated activities
control
DE.AE-03 — Adverse Event Analysis: Information is correlated from multiple sources
control
DE.AE-04 — Adverse Event Analysis: The estimated impact and scope of adverse events are understood
control
DE.AE-06 — Adverse Event Analysis: Information on adverse events is provided to authorized staff and tools
control
DE.AE-07 — Adverse Event Analysis: Cyber threat intelligence and other contextual information are integrated into the analysis
control
DE.AE-08 — Adverse Event Analysis: Incidents are declared when adverse events meet the defined incident criteria
control
DE.CM-01 — Continuous Monitoring: Networks and network services are monitored to find potentially adverse events
control
DE.CM-02 — Continuous Monitoring: The physical environment is monitored to find potentially adverse events
control
DE.CM-03 — Continuous Monitoring: Personnel activity and technology usage are monitored to find potentially adverse events
control
DE.CM-06 — Continuous Monitoring: External service provider activities and services are monitored to find potentially adverse events
control
DE.CM-09 — Continuous Monitoring: Computing hardware and software, runtime environments, and their data are monitored to find potentially adverse events
control
GV.OC-01 — Organizational Context: The organizational mission is understood and informs cybersecurity risk management
control
GV.OC-02 — Organizational Context: Internal and external stakeholders are understood, and their needs and expectations regarding cybersecurity risk management are understood and considered
control
GV.OC-03 — Organizational Context: Legal, regulatory, and contractual requirements regarding cybersecurity — including privacy and civil liberties obligations — are understood and managed
control
GV.OC-04 — Organizational Context: Critical objectives, capabilities, and services that external stakeholders depend on or expect from the organization are understood and communicated
control
GV.OC-05 — Organizational Context: Outcomes, capabilities, and services that the organization depends on are understood and communicated
control
GV.OV-01 — Oversight: Cybersecurity risk management strategy outcomes are reviewed to inform and adjust strategy and direction
control
GV.OV-02 — Oversight: The cybersecurity risk management strategy is reviewed and adjusted to ensure coverage of organizational requirements and risks
control
GV.OV-03 — Oversight: Organizational cybersecurity risk management performance is evaluated and reviewed for adjustments needed
control
GV.PO-01 — Policy: Policy for managing cybersecurity risks is established based on organizational context, cybersecurity strategy, and priorities and is communicated and enforced
control
GV.PO-02 — Policy: Policy for managing cybersecurity risks is reviewed, updated, communicated, and enforced to reflect changes in requirements, threats, technology, and organizational mission
control
GV.RM-01 — Risk Management Strategy: Risk management objectives are established and agreed to by organizational stakeholders
control
GV.RM-02 — Risk Management Strategy: Risk appetite and risk tolerance statements are established, communicated, and maintained
control
GV.RM-03 — Risk Management Strategy: Cybersecurity risk management activities and outcomes are included in enterprise risk management processes
control
GV.RM-04 — Risk Management Strategy: Strategic direction that describes appropriate risk response options is established and communicated
control
GV.RM-05 — Risk Management Strategy: Lines of communication across the organization are established for cybersecurity risks, including risks from suppliers and other third parties
control
GV.RM-06 — Risk Management Strategy: A standardized method for calculating, documenting, categorizing, and prioritizing cybersecurity risks is established and communicated
control
GV.RM-07 — Risk Management Strategy: Strategic opportunities (i.e., positive risks) are characterized and are included in organizational cybersecurity risk discussions
control
GV.RR-01 — Roles, Responsibilities, and Authorities: Organizational leadership is responsible and accountable for cybersecurity risk and fosters a culture that is risk-aware, ethical, and continually improving
control
GV.RR-02 — Roles, Responsibilities, and Authorities: Roles, responsibilities, and authorities related to cybersecurity risk management are established, communicated, understood, and enforced
control
GV.RR-03 — Roles, Responsibilities, and Authorities: Adequate resources are allocated commensurate with the cybersecurity risk strategy, roles, responsibilities, and policies
control
GV.RR-04 — Roles, Responsibilities, and Authorities: Cybersecurity is included in human resources practices
control
GV.SC-01 — Cybersecurity Supply Chain Risk Management: A cybersecurity supply chain risk management program, strategy, objectives, policies, and processes are established and agreed to by organizational stakeholders
control
GV.SC-02 — Cybersecurity Supply Chain Risk Management: Cybersecurity roles and responsibilities for suppliers, customers, and partners are established, communicated, and coordinated internally and externally
control
GV.SC-03 — Cybersecurity Supply Chain Risk Management: Cybersecurity supply chain risk management is integrated into cybersecurity and enterprise risk management, risk assessment, and improvement processes
control
GV.SC-04 — Cybersecurity Supply Chain Risk Management: Suppliers are known and prioritized by criticality
control
GV.SC-05 — Cybersecurity Supply Chain Risk Management: Requirements to address cybersecurity risks in supply chains are established, prioritized, and integrated into contracts and other types of agreements with suppliers and other relevant third parties
control
GV.SC-06 — Cybersecurity Supply Chain Risk Management: Planning and due diligence are performed to reduce risks before entering into formal supplier or other third-party relationships
control
GV.SC-07 — Cybersecurity Supply Chain Risk Management: The risks posed by a supplier, their products and services, and other third parties are understood, recorded, prioritized, assessed, responded to, and monitored over the course of the relationship
control
GV.SC-08 — Cybersecurity Supply Chain Risk Management: Relevant suppliers and other third parties are included in incident planning, response, and recovery activities
control
GV.SC-09 — Cybersecurity Supply Chain Risk Management: Supply chain security practices are integrated into cybersecurity and enterprise risk management programs, and their performance is monitored throughout the technology product and service life cycle
control
GV.SC-10 — Cybersecurity Supply Chain Risk Management: Cybersecurity supply chain risk management plans include provisions for activities that occur after the conclusion of a partnership or service agreement
control
ID.AM-01 — Asset Management: Inventories of hardware managed by the organization are maintained
control
ID.AM-02 — Asset Management: Inventories of software, services, and systems managed by the organization are maintained
control
ID.AM-03 — Asset Management: Representations of the organization's authorized network communication and internal and external network data flows are maintained
control
ID.AM-04 — Asset Management: Inventories of services provided by suppliers are maintained
control
ID.AM-05 — Asset Management: Assets are prioritized based on classification, criticality, resources, and impact on the mission
control
ID.AM-07 — Asset Management: Inventories of data and corresponding metadata for designated data types are maintained
control
ID.AM-08 — Asset Management: Systems, hardware, software, services, and data are managed throughout their life cycles
control
ID.IM-01 — Improvement: Improvements are identified from evaluations
control
ID.IM-02 — Improvement: Improvements are identified from security tests and exercises, including those done in coordination with suppliers and relevant third parties