| PR.AA-01Identity Management, Authentication, and Access Control: Identities and credentials for authorized users, services, and hardware are managed by the organization | |
|---|
| PR.AA-02Identity Management, Authentication, and Access Control: Identities are proofed and bound to credentials based on the context of interactions | |
|---|
| PR.AA-03Identity Management, Authentication, and Access Control: Users, services, and hardware are authenticated | |
|---|
| PR.AA-04Identity Management, Authentication, and Access Control: Identity assertions are protected, conveyed, and verified | |
|---|
| PR.AA-05Identity Management, Authentication, and Access Control: Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties | |
|---|
| PR.AA-06Identity Management, Authentication, and Access Control: Physical access to assets is managed, monitored, and enforced commensurate with risk | |
|---|
| PR.AT-01Awareness and Training: Personnel are provided with awareness and training so that they possess the knowledge and skills to perform general tasks with cybersecurity risks in mind | |
|---|
| PR.AT-02Awareness and Training: Individuals in specialized roles are provided with awareness and training so that they possess the knowledge and skills to perform relevant tasks with cybersecurity risks in mind | |
|---|
| PR.DS-01Data Security: The confidentiality, integrity, and availability of data-at-rest are protected | |
|---|
| PR.DS-02Data Security: The confidentiality, integrity, and availability of data-in-transit are protected | |
|---|
| PR.DS-10Data Security: The confidentiality, integrity, and availability of data-in-use are protected | |
|---|
| PR.DS-11Data Security: Backups of data are created, protected, maintained, and tested | |
|---|
| PR.PS-01Platform Security: Configuration management practices are established and applied | |
|---|
| PR.PS-02Platform Security: Software is maintained, replaced, and removed commensurate with risk | |
|---|
| PR.PS-03Platform Security: Hardware is maintained, replaced, and removed commensurate with risk | |
|---|
| PR.PS-04Platform Security: Log records are generated and made available for continuous monitoring | |
|---|
| PR.PS-05Platform Security: Installation and execution of unauthorized software are prevented | |
|---|
| PR.PS-06Platform Security: Secure software development practices are integrated, and their performance is monitored throughout the software development life cycle | |
|---|
| PR.IR-01Technology Infrastructure Resilience: Networks and environments are protected from unauthorized logical access and usage | |
|---|
| PR.IR-02Technology Infrastructure Resilience: The organization's technology assets are protected from environmental threats | |
|---|
| PR.IR-03Technology Infrastructure Resilience: Mechanisms are implemented to achieve resilience requirements in normal and adverse situations | |
|---|
| PR.IR-04Technology Infrastructure Resilience: Adequate resource capacity to ensure availability is maintained | |
|---|