NIST SP 800-53 Rev 5 controls
1014 controls held for NIST SP 800-53 Rev 5 (NIST). Edition: NIST SP 800-53 Rev 5, Release 5.2.0. Place a control statement and the reader picks the closest text here and the closest matches in the other frameworks. Open NIST SP 800-53 Rev 5 on the standards site.
| Code | Control | Domain | |
|---|---|---|---|
| NIST800-AC-1 | AC-1 Policy and Procedures | AC - Access Control | open |
| NIST800-AC-2 | AC-2 Account Management | AC - Access Control | open |
| NIST800-AC-2(1) | AC-2(1) Account Management | Automated System Account Management | AC - Access Control | open |
| NIST800-AC-2(2) | AC-2(2) Account Management | Automated Temporary and Emergency Account Management | AC - Access Control | open |
| NIST800-AC-2(3) | AC-2(3) Account Management | Disable Accounts | AC - Access Control | open |
| NIST800-AC-2(4) | AC-2(4) Account Management | Automated Audit Actions | AC - Access Control | open |
| NIST800-AC-2(5) | AC-2(5) Account Management | Inactivity Logout | AC - Access Control | open |
| NIST800-AC-2(6) | AC-2(6) Account Management | Dynamic Privilege Management | AC - Access Control | open |
| NIST800-AC-2(7) | AC-2(7) Account Management | Privileged User Accounts | AC - Access Control | open |
| NIST800-AC-2(8) | AC-2(8) Account Management | Dynamic Account Management | AC - Access Control | open |
| NIST800-AC-2(9) | AC-2(9) Account Management | Restrictions on Use of Shared and Group Accounts | AC - Access Control | open |
| NIST800-AC-2(11) | AC-2(11) Account Management | Usage Conditions | AC - Access Control | open |
| NIST800-AC-2(12) | AC-2(12) Account Management | Account Monitoring for Atypical Usage | AC - Access Control | open |
| NIST800-AC-2(13) | AC-2(13) Account Management | Disable Accounts for High-risk Individuals | AC - Access Control | open |
| NIST800-AC-3 | AC-3 Access Enforcement | AC - Access Control | open |
| NIST800-AC-3(2) | AC-3(2) Access Enforcement | Dual Authorization | AC - Access Control | open |
| NIST800-AC-3(3) | AC-3(3) Access Enforcement | Mandatory Access Control | AC - Access Control | open |
| NIST800-AC-3(4) | AC-3(4) Access Enforcement | Discretionary Access Control | AC - Access Control | open |
| NIST800-AC-3(5) | AC-3(5) Access Enforcement | Security-relevant Information | AC - Access Control | open |
| NIST800-AC-3(7) | AC-3(7) Access Enforcement | Role-based Access Control | AC - Access Control | open |
| NIST800-AC-3(8) | AC-3(8) Access Enforcement | Revocation of Access Authorizations | AC - Access Control | open |
| NIST800-AC-3(9) | AC-3(9) Access Enforcement | Controlled Release | AC - Access Control | open |
| NIST800-AC-3(10) | AC-3(10) Access Enforcement | Audited Override of Access Control Mechanisms | AC - Access Control | open |
| NIST800-AC-3(11) | AC-3(11) Access Enforcement | Restrict Access to Specific Information Types | AC - Access Control | open |
| NIST800-AC-3(12) | AC-3(12) Access Enforcement | Assert and Enforce Application Access | AC - Access Control | open |
| NIST800-AC-3(13) | AC-3(13) Access Enforcement | Attribute-based Access Control | AC - Access Control | open |
| NIST800-AC-3(14) | AC-3(14) Access Enforcement | Individual Access | AC - Access Control | open |
| NIST800-AC-3(15) | AC-3(15) Access Enforcement | Discretionary and Mandatory Access Control | AC - Access Control | open |
| NIST800-AC-4 | AC-4 Information Flow Enforcement | AC - Access Control | open |
| NIST800-AC-4(1) | AC-4(1) Information Flow Enforcement | Object Security and Privacy Attributes | AC - Access Control | open |
| NIST800-AC-4(2) | AC-4(2) Information Flow Enforcement | Processing Domains | AC - Access Control | open |
| NIST800-AC-4(3) | AC-4(3) Information Flow Enforcement | Dynamic Information Flow Control | AC - Access Control | open |
| NIST800-AC-4(4) | AC-4(4) Information Flow Enforcement | Flow Control of Encrypted Information | AC - Access Control | open |
| NIST800-AC-4(5) | AC-4(5) Information Flow Enforcement | Embedded Data Types | AC - Access Control | open |
| NIST800-AC-4(6) | AC-4(6) Information Flow Enforcement | Metadata | AC - Access Control | open |
| NIST800-AC-4(7) | AC-4(7) Information Flow Enforcement | One-way Flow Mechanisms | AC - Access Control | open |
| NIST800-AC-4(8) | AC-4(8) Information Flow Enforcement | Security and Privacy Policy Filters | AC - Access Control | open |
| NIST800-AC-4(9) | AC-4(9) Information Flow Enforcement | Human Reviews | AC - Access Control | open |
| NIST800-AC-4(10) | AC-4(10) Information Flow Enforcement | Enable and Disable Security or Privacy Policy Filters | AC - Access Control | open |
| NIST800-AC-4(11) | AC-4(11) Information Flow Enforcement | Configuration of Security or Privacy Policy Filters | AC - Access Control | open |
| NIST800-AC-4(12) | AC-4(12) Information Flow Enforcement | Data Type Identifiers | AC - Access Control | open |
| NIST800-AC-4(13) | AC-4(13) Information Flow Enforcement | Decomposition into Policy-relevant Subcomponents | AC - Access Control | open |
| NIST800-AC-4(14) | AC-4(14) Information Flow Enforcement | Security or Privacy Policy Filter Constraints | AC - Access Control | open |
| NIST800-AC-4(15) | AC-4(15) Information Flow Enforcement | Detection of Unsanctioned Information | AC - Access Control | open |
| NIST800-AC-4(17) | AC-4(17) Information Flow Enforcement | Domain Authentication | AC - Access Control | open |
| NIST800-AC-4(19) | AC-4(19) Information Flow Enforcement | Validation of Metadata | AC - Access Control | open |
| NIST800-AC-4(20) | AC-4(20) Information Flow Enforcement | Approved Solutions | AC - Access Control | open |
| NIST800-AC-4(21) | AC-4(21) Information Flow Enforcement | Physical or Logical Separation of Information Flows | AC - Access Control | open |
| NIST800-AC-4(22) | AC-4(22) Information Flow Enforcement | Access Only | AC - Access Control | open |
| NIST800-AC-4(23) | AC-4(23) Information Flow Enforcement | Modify Non-releasable Information | AC - Access Control | open |
| NIST800-AC-4(24) | AC-4(24) Information Flow Enforcement | Internal Normalized Format | AC - Access Control | open |
| NIST800-AC-4(25) | AC-4(25) Information Flow Enforcement | Data Sanitization | AC - Access Control | open |
| NIST800-AC-4(26) | AC-4(26) Information Flow Enforcement | Audit Filtering Actions | AC - Access Control | open |
| NIST800-AC-4(27) | AC-4(27) Information Flow Enforcement | Redundant/Independent Filtering Mechanisms | AC - Access Control | open |
| NIST800-AC-4(28) | AC-4(28) Information Flow Enforcement | Linear Filter Pipelines | AC - Access Control | open |
| NIST800-AC-4(29) | AC-4(29) Information Flow Enforcement | Filter Orchestration Engines | AC - Access Control | open |
| NIST800-AC-4(30) | AC-4(30) Information Flow Enforcement | Filter Mechanisms Using Multiple Processes | AC - Access Control | open |
| NIST800-AC-4(31) | AC-4(31) Information Flow Enforcement | Failed Content Transfer Prevention | AC - Access Control | open |
| NIST800-AC-4(32) | AC-4(32) Information Flow Enforcement | Process Requirements for Information Transfer | AC - Access Control | open |
| NIST800-AC-5 | AC-5 Separation of Duties | AC - Access Control | open |
| NIST800-AC-6 | AC-6 Least Privilege | AC - Access Control | open |
| NIST800-AC-6(1) | AC-6(1) Least Privilege | Authorize Access to Security Functions | AC - Access Control | open |
| NIST800-AC-6(2) | AC-6(2) Least Privilege | Non-privileged Access for Nonsecurity Functions | AC - Access Control | open |
| NIST800-AC-6(3) | AC-6(3) Least Privilege | Network Access to Privileged Commands | AC - Access Control | open |
| NIST800-AC-6(4) | AC-6(4) Least Privilege | Separate Processing Domains | AC - Access Control | open |
| NIST800-AC-6(5) | AC-6(5) Least Privilege | Privileged Accounts | AC - Access Control | open |
| NIST800-AC-6(6) | AC-6(6) Least Privilege | Privileged Access by Non-organizational Users | AC - Access Control | open |
| NIST800-AC-6(7) | AC-6(7) Least Privilege | Review of User Privileges | AC - Access Control | open |
| NIST800-AC-6(8) | AC-6(8) Least Privilege | Privilege Levels for Code Execution | AC - Access Control | open |
| NIST800-AC-6(9) | AC-6(9) Least Privilege | Log Use of Privileged Functions | AC - Access Control | open |
| NIST800-AC-6(10) | AC-6(10) Least Privilege | Prohibit Non-privileged Users from Executing Privileged Functions | AC - Access Control | open |
| NIST800-AC-7 | AC-7 Unsuccessful Logon Attempts | AC - Access Control | open |
| NIST800-AC-7(2) | AC-7(2) Unsuccessful Logon Attempts | Purge or Wipe Mobile Device | AC - Access Control | open |
| NIST800-AC-7(3) | AC-7(3) Unsuccessful Logon Attempts | Biometric Attempt Limiting | AC - Access Control | open |
| NIST800-AC-7(4) | AC-7(4) Unsuccessful Logon Attempts | Use of Alternate Authentication Factor | AC - Access Control | open |
| NIST800-AC-8 | AC-8 System Use Notification | AC - Access Control | open |
| NIST800-AC-9 | AC-9 Previous Logon Notification | AC - Access Control | open |
| NIST800-AC-9(1) | AC-9(1) Previous Logon Notification | Unsuccessful Logons | AC - Access Control | open |
| NIST800-AC-9(2) | AC-9(2) Previous Logon Notification | Successful and Unsuccessful Logons | AC - Access Control | open |
| NIST800-AC-9(3) | AC-9(3) Previous Logon Notification | Notification of Account Changes | AC - Access Control | open |
| NIST800-AC-9(4) | AC-9(4) Previous Logon Notification | Additional Logon Information | AC - Access Control | open |
| NIST800-AC-10 | AC-10 Concurrent Session Control | AC - Access Control | open |
| NIST800-AC-11 | AC-11 Device Lock | AC - Access Control | open |
| NIST800-AC-11(1) | AC-11(1) Device Lock | Pattern-hiding Displays | AC - Access Control | open |
| NIST800-AC-12 | AC-12 Session Termination | AC - Access Control | open |
| NIST800-AC-12(1) | AC-12(1) Session Termination | User-initiated Logouts | AC - Access Control | open |
| NIST800-AC-12(2) | AC-12(2) Session Termination | Termination Message | AC - Access Control | open |
| NIST800-AC-12(3) | AC-12(3) Session Termination | Timeout Warning Message | AC - Access Control | open |
| NIST800-AC-14 | AC-14 Permitted Actions Without Identification or Authentication | AC - Access Control | open |
| NIST800-AC-16 | AC-16 Security and Privacy Attributes | AC - Access Control | open |
| NIST800-AC-16(1) | AC-16(1) Security and Privacy Attributes | Dynamic Attribute Association | AC - Access Control | open |
| NIST800-AC-16(2) | AC-16(2) Security and Privacy Attributes | Attribute Value Changes by Authorized Individuals | AC - Access Control | open |
| NIST800-AC-16(3) | AC-16(3) Security and Privacy Attributes | Maintenance of Attribute Associations by System | AC - Access Control | open |
| NIST800-AC-16(4) | AC-16(4) Security and Privacy Attributes | Association of Attributes by Authorized Individuals | AC - Access Control | open |
| NIST800-AC-16(5) | AC-16(5) Security and Privacy Attributes | Attribute Displays on Objects to Be Output | AC - Access Control | open |
| NIST800-AC-16(6) | AC-16(6) Security and Privacy Attributes | Maintenance of Attribute Association | AC - Access Control | open |
| NIST800-AC-16(7) | AC-16(7) Security and Privacy Attributes | Consistent Attribute Interpretation | AC - Access Control | open |
| NIST800-AC-16(8) | AC-16(8) Security and Privacy Attributes | Association Techniques and Technologies | AC - Access Control | open |
| NIST800-AC-16(9) | AC-16(9) Security and Privacy Attributes | Attribute Reassignment: Regrading Mechanisms | AC - Access Control | open |
| NIST800-AC-16(10) | AC-16(10) Security and Privacy Attributes | Attribute Configuration by Authorized Individuals | AC - Access Control | open |
| NIST800-AC-17 | AC-17 Remote Access | AC - Access Control | open |
| NIST800-AC-17(1) | AC-17(1) Remote Access | Monitoring and Control | AC - Access Control | open |
| NIST800-AC-17(2) | AC-17(2) Remote Access | Protection of Confidentiality and Integrity Using Encryption | AC - Access Control | open |
| NIST800-AC-17(3) | AC-17(3) Remote Access | Managed Access Control Points | AC - Access Control | open |
| NIST800-AC-17(4) | AC-17(4) Remote Access | Privileged Commands and Access | AC - Access Control | open |
| NIST800-AC-17(6) | AC-17(6) Remote Access | Protection of Mechanism Information | AC - Access Control | open |
| NIST800-AC-17(9) | AC-17(9) Remote Access | Disconnect or Disable Access | AC - Access Control | open |
| NIST800-AC-17(10) | AC-17(10) Remote Access | Authenticate Remote Commands | AC - Access Control | open |
| NIST800-AC-18 | AC-18 Wireless Access | AC - Access Control | open |
| NIST800-AC-18(1) | AC-18(1) Wireless Access | Authentication and Encryption | AC - Access Control | open |
| NIST800-AC-18(3) | AC-18(3) Wireless Access | Disable Wireless Networking | AC - Access Control | open |
| NIST800-AC-18(4) | AC-18(4) Wireless Access | Restrict Configurations by Users | AC - Access Control | open |
| NIST800-AC-18(5) | AC-18(5) Wireless Access | Antennas and Transmission Power Levels | AC - Access Control | open |
| NIST800-AC-19 | AC-19 Access Control for Mobile Devices | AC - Access Control | open |
| NIST800-AC-19(4) | AC-19(4) Access Control for Mobile Devices | Restrictions for Classified Information | AC - Access Control | open |
| NIST800-AC-19(5) | AC-19(5) Access Control for Mobile Devices | Full Device or Container-based Encryption | AC - Access Control | open |
| NIST800-AC-20 | AC-20 Use of External Systems | AC - Access Control | open |
| NIST800-AC-20(1) | AC-20(1) Use of External Systems | Limits on Authorized Use | AC - Access Control | open |
| NIST800-AC-20(2) | AC-20(2) Use of External Systems | Portable Storage Devices: Restricted Use | AC - Access Control | open |
| NIST800-AC-20(3) | AC-20(3) Use of External Systems | Non-organizationally Owned Systems: Restricted Use | AC - Access Control | open |
| NIST800-AC-20(4) | AC-20(4) Use of External Systems | Network Accessible Storage Devices: Prohibited Use | AC - Access Control | open |
| NIST800-AC-20(5) | AC-20(5) Use of External Systems | Portable Storage Devices: Prohibited Use | AC - Access Control | open |
| NIST800-AC-21 | AC-21 Information Sharing | AC - Access Control | open |
| NIST800-AC-21(1) | AC-21(1) Information Sharing | Automated Decision Support | AC - Access Control | open |
| NIST800-AC-21(2) | AC-21(2) Information Sharing | Information Search and Retrieval | AC - Access Control | open |
| NIST800-AC-22 | AC-22 Publicly Accessible Content | AC - Access Control | open |
| NIST800-AC-23 | AC-23 Data Mining Protection | AC - Access Control | open |
| NIST800-AC-24 | AC-24 Access Control Decisions | AC - Access Control | open |
| NIST800-AC-24(1) | AC-24(1) Access Control Decisions | Transmit Access Authorization Information | AC - Access Control | open |
| NIST800-AC-24(2) | AC-24(2) Access Control Decisions | No User or Process Identity | AC - Access Control | open |
| NIST800-AC-25 | AC-25 Reference Monitor | AC - Access Control | open |
| NIST800-AT-1 | AT-1 Policy and Procedures | AT - Awareness and Training | open |
| NIST800-AT-2 | AT-2 Literacy Training and Awareness | AT - Awareness and Training | open |
| NIST800-AT-2(1) | AT-2(1) Literacy Training and Awareness | Practical Exercises | AT - Awareness and Training | open |
| NIST800-AT-2(2) | AT-2(2) Literacy Training and Awareness | Insider Threat | AT - Awareness and Training | open |
| NIST800-AT-2(3) | AT-2(3) Literacy Training and Awareness | Social Engineering and Mining | AT - Awareness and Training | open |
| NIST800-AT-2(4) | AT-2(4) Literacy Training and Awareness | Suspicious Communications and Anomalous System Behavior | AT - Awareness and Training | open |
| NIST800-AT-2(5) | AT-2(5) Literacy Training and Awareness | Advanced Persistent Threat | AT - Awareness and Training | open |
| NIST800-AT-2(6) | AT-2(6) Literacy Training and Awareness | Cyber Threat Environment | AT - Awareness and Training | open |
| NIST800-AT-3 | AT-3 Role-based Training | AT - Awareness and Training | open |
| NIST800-AT-3(1) | AT-3(1) Role-based Training | Environmental Controls | AT - Awareness and Training | open |
| NIST800-AT-3(2) | AT-3(2) Role-based Training | Physical Security Controls | AT - Awareness and Training | open |
| NIST800-AT-3(3) | AT-3(3) Role-based Training | Practical Exercises | AT - Awareness and Training | open |
| NIST800-AT-3(5) | AT-3(5) Role-based Training | Processing Personally Identifiable Information | AT - Awareness and Training | open |
| NIST800-AT-4 | AT-4 Training Records | AT - Awareness and Training | open |
| NIST800-AT-6 | AT-6 Training Feedback | AT - Awareness and Training | open |
| NIST800-AU-1 | AU-1 Policy and Procedures | AU - Audit and Accountability | open |
| NIST800-AU-2 | AU-2 Event Logging | AU - Audit and Accountability | open |
| NIST800-AU-3 | AU-3 Content of Audit Records | AU - Audit and Accountability | open |
| NIST800-AU-3(1) | AU-3(1) Content of Audit Records | Additional Audit Information | AU - Audit and Accountability | open |
| NIST800-AU-3(3) | AU-3(3) Content of Audit Records | Limit Personally Identifiable Information Elements | AU - Audit and Accountability | open |
| NIST800-AU-4 | AU-4 Audit Log Storage Capacity | AU - Audit and Accountability | open |
| NIST800-AU-4(1) | AU-4(1) Audit Log Storage Capacity | Transfer to Alternate Storage | AU - Audit and Accountability | open |
| NIST800-AU-5 | AU-5 Response to Audit Logging Process Failures | AU - Audit and Accountability | open |
| NIST800-AU-5(1) | AU-5(1) Response to Audit Logging Process Failures | Storage Capacity Warning | AU - Audit and Accountability | open |
| NIST800-AU-5(2) | AU-5(2) Response to Audit Logging Process Failures | Real-time Alerts | AU - Audit and Accountability | open |
| NIST800-AU-5(3) | AU-5(3) Response to Audit Logging Process Failures | Configurable Traffic Volume Thresholds | AU - Audit and Accountability | open |
| NIST800-AU-5(4) | AU-5(4) Response to Audit Logging Process Failures | Shutdown on Failure | AU - Audit and Accountability | open |
| NIST800-AU-5(5) | AU-5(5) Response to Audit Logging Process Failures | Alternate Audit Logging Capability | AU - Audit and Accountability | open |
| NIST800-AU-6 | AU-6 Audit Record Review, Analysis, and Reporting | AU - Audit and Accountability | open |
| NIST800-AU-6(1) | AU-6(1) Audit Record Review, Analysis, and Reporting | Automated Process Integration | AU - Audit and Accountability | open |
| NIST800-AU-6(3) | AU-6(3) Audit Record Review, Analysis, and Reporting | Correlate Audit Record Repositories | AU - Audit and Accountability | open |
| NIST800-AU-6(4) | AU-6(4) Audit Record Review, Analysis, and Reporting | Central Review and Analysis | AU - Audit and Accountability | open |
| NIST800-AU-6(5) | AU-6(5) Audit Record Review, Analysis, and Reporting | Integrated Analysis of Audit Records | AU - Audit and Accountability | open |
| NIST800-AU-6(6) | AU-6(6) Audit Record Review, Analysis, and Reporting | Correlation with Physical Monitoring | AU - Audit and Accountability | open |
| NIST800-AU-6(7) | AU-6(7) Audit Record Review, Analysis, and Reporting | Permitted Actions | AU - Audit and Accountability | open |
| NIST800-AU-6(8) | AU-6(8) Audit Record Review, Analysis, and Reporting | Full Text Analysis of Privileged Commands | AU - Audit and Accountability | open |
| NIST800-AU-6(9) | AU-6(9) Audit Record Review, Analysis, and Reporting | Correlation with Information from Nontechnical Sources | AU - Audit and Accountability | open |
| NIST800-AU-7 | AU-7 Audit Record Reduction and Report Generation | AU - Audit and Accountability | open |
| NIST800-AU-7(1) | AU-7(1) Audit Record Reduction and Report Generation | Automatic Processing | AU - Audit and Accountability | open |
| NIST800-AU-8 | AU-8 Time Stamps | AU - Audit and Accountability | open |
| NIST800-AU-9 | AU-9 Protection of Audit Information | AU - Audit and Accountability | open |
| NIST800-AU-9(1) | AU-9(1) Protection of Audit Information | Hardware Write-once Media | AU - Audit and Accountability | open |
| NIST800-AU-9(2) | AU-9(2) Protection of Audit Information | Store on Separate Physical Systems or Components | AU - Audit and Accountability | open |
| NIST800-AU-9(3) | AU-9(3) Protection of Audit Information | Cryptographic Protection | AU - Audit and Accountability | open |
| NIST800-AU-9(4) | AU-9(4) Protection of Audit Information | Access by Subset of Privileged Users | AU - Audit and Accountability | open |
| NIST800-AU-9(5) | AU-9(5) Protection of Audit Information | Dual Authorization | AU - Audit and Accountability | open |
| NIST800-AU-9(6) | AU-9(6) Protection of Audit Information | Read-only Access | AU - Audit and Accountability | open |
| NIST800-AU-9(7) | AU-9(7) Protection of Audit Information | Store on Component with Different Operating System | AU - Audit and Accountability | open |
| NIST800-AU-10 | AU-10 Non-repudiation | AU - Audit and Accountability | open |
| NIST800-AU-10(1) | AU-10(1) Non-repudiation | Association of Identities | AU - Audit and Accountability | open |
| NIST800-AU-10(2) | AU-10(2) Non-repudiation | Validate Binding of Information Producer Identity | AU - Audit and Accountability | open |
| NIST800-AU-10(3) | AU-10(3) Non-repudiation | Chain of Custody | AU - Audit and Accountability | open |
| NIST800-AU-10(4) | AU-10(4) Non-repudiation | Validate Binding of Information Reviewer Identity | AU - Audit and Accountability | open |
| NIST800-AU-11 | AU-11 Audit Record Retention | AU - Audit and Accountability | open |
| NIST800-AU-11(1) | AU-11(1) Audit Record Retention | Long-term Retrieval Capability | AU - Audit and Accountability | open |
| NIST800-AU-12 | AU-12 Audit Record Generation | AU - Audit and Accountability | open |
| NIST800-AU-12(1) | AU-12(1) Audit Record Generation | System-wide and Time-correlated Audit Trail | AU - Audit and Accountability | open |
| NIST800-AU-12(2) | AU-12(2) Audit Record Generation | Standardized Formats | AU - Audit and Accountability | open |
| NIST800-AU-12(3) | AU-12(3) Audit Record Generation | Changes by Authorized Individuals | AU - Audit and Accountability | open |
| NIST800-AU-12(4) | AU-12(4) Audit Record Generation | Query Parameter Audits of Personally Identifiable Information | AU - Audit and Accountability | open |
| NIST800-AU-13 | AU-13 Monitoring for Information Disclosure | AU - Audit and Accountability | open |
| NIST800-AU-13(1) | AU-13(1) Monitoring for Information Disclosure | Use of Automated Tools | AU - Audit and Accountability | open |
| NIST800-AU-13(2) | AU-13(2) Monitoring for Information Disclosure | Review of Monitored Sites | AU - Audit and Accountability | open |
| NIST800-AU-13(3) | AU-13(3) Monitoring for Information Disclosure | Unauthorized Replication of Information | AU - Audit and Accountability | open |
| NIST800-AU-14 | AU-14 Session Audit | AU - Audit and Accountability | open |
| NIST800-AU-14(1) | AU-14(1) Session Audit | System Start-up | AU - Audit and Accountability | open |
| NIST800-AU-14(3) | AU-14(3) Session Audit | Remote Viewing and Listening | AU - Audit and Accountability | open |
| NIST800-AU-16 | AU-16 Cross-organizational Audit Logging | AU - Audit and Accountability | open |
| NIST800-AU-16(1) | AU-16(1) Cross-organizational Audit Logging | Identity Preservation | AU - Audit and Accountability | open |
| NIST800-AU-16(2) | AU-16(2) Cross-organizational Audit Logging | Sharing of Audit Information | AU - Audit and Accountability | open |
| NIST800-AU-16(3) | AU-16(3) Cross-organizational Audit Logging | Disassociability | AU - Audit and Accountability | open |
| NIST800-CA-1 | CA-1 Policy and Procedures | CA - Assessment, Authorization, and Monitoring | open |
| NIST800-CA-2 | CA-2 Control Assessments | CA - Assessment, Authorization, and Monitoring | open |
| NIST800-CA-2(1) | CA-2(1) Control Assessments | Independent Assessors | CA - Assessment, Authorization, and Monitoring | open |
| NIST800-CA-2(2) | CA-2(2) Control Assessments | Specialized Assessments | CA - Assessment, Authorization, and Monitoring | open |
| NIST800-CA-2(3) | CA-2(3) Control Assessments | Leveraging Results from External Organizations | CA - Assessment, Authorization, and Monitoring | open |
| NIST800-CA-3 | CA-3 Information Exchange | CA - Assessment, Authorization, and Monitoring | open |
| NIST800-CA-3(6) | CA-3(6) Information Exchange | Transfer Authorizations | CA - Assessment, Authorization, and Monitoring | open |
| NIST800-CA-3(7) | CA-3(7) Information Exchange | Transitive Information Exchanges | CA - Assessment, Authorization, and Monitoring | open |
| NIST800-CA-5 | CA-5 Plan of Action and Milestones | CA - Assessment, Authorization, and Monitoring | open |
| NIST800-CA-5(1) | CA-5(1) Plan of Action and Milestones | Automation Support for Accuracy and Currency | CA - Assessment, Authorization, and Monitoring | open |
| NIST800-CA-6 | CA-6 Authorization | CA - Assessment, Authorization, and Monitoring | open |
| NIST800-CA-6(1) | CA-6(1) Authorization | Joint Authorization: Intra-organization | CA - Assessment, Authorization, and Monitoring | open |
| NIST800-CA-6(2) | CA-6(2) Authorization | Joint Authorization: Inter-organization | CA - Assessment, Authorization, and Monitoring | open |
| NIST800-CA-7 | CA-7 Continuous Monitoring | CA - Assessment, Authorization, and Monitoring | open |
| NIST800-CA-7(1) | CA-7(1) Continuous Monitoring | Independent Assessment | CA - Assessment, Authorization, and Monitoring | open |
| NIST800-CA-7(3) | CA-7(3) Continuous Monitoring | Trend Analyses | CA - Assessment, Authorization, and Monitoring | open |
| NIST800-CA-7(4) | CA-7(4) Continuous Monitoring | Risk Monitoring | CA - Assessment, Authorization, and Monitoring | open |
| NIST800-CA-7(5) | CA-7(5) Continuous Monitoring | Consistency Analysis | CA - Assessment, Authorization, and Monitoring | open |
| NIST800-CA-7(6) | CA-7(6) Continuous Monitoring | Automation Support for Monitoring | CA - Assessment, Authorization, and Monitoring | open |
| NIST800-CA-8 | CA-8 Penetration Testing | CA - Assessment, Authorization, and Monitoring | open |
| NIST800-CA-8(1) | CA-8(1) Penetration Testing | Independent Penetration Testing Agent or Team | CA - Assessment, Authorization, and Monitoring | open |
| NIST800-CA-8(2) | CA-8(2) Penetration Testing | Red Team Exercises | CA - Assessment, Authorization, and Monitoring | open |
| NIST800-CA-8(3) | CA-8(3) Penetration Testing | Facility Penetration Testing | CA - Assessment, Authorization, and Monitoring | open |
| NIST800-CA-9 | CA-9 Internal System Connections | CA - Assessment, Authorization, and Monitoring | open |
| NIST800-CA-9(1) | CA-9(1) Internal System Connections | Compliance Checks | CA - Assessment, Authorization, and Monitoring | open |
| NIST800-CM-1 | CM-1 Policy and Procedures | CM - Configuration Management | open |
| NIST800-CM-2 | CM-2 Baseline Configuration | CM - Configuration Management | open |
| NIST800-CM-2(2) | CM-2(2) Baseline Configuration | Automation Support for Accuracy and Currency | CM - Configuration Management | open |
| NIST800-CM-2(3) | CM-2(3) Baseline Configuration | Retention of Previous Configurations | CM - Configuration Management | open |
| NIST800-CM-2(6) | CM-2(6) Baseline Configuration | Development and Test Environments | CM - Configuration Management | open |
| NIST800-CM-2(7) | CM-2(7) Baseline Configuration | Configure Systems and Components for High-risk Areas | CM - Configuration Management | open |
| NIST800-CM-3 | CM-3 Configuration Change Control | CM - Configuration Management | open |
| NIST800-CM-3(1) | CM-3(1) Configuration Change Control | Automated Documentation, Notification, and Prohibition of Changes | CM - Configuration Management | open |
| NIST800-CM-3(2) | CM-3(2) Configuration Change Control | Testing, Validation, and Documentation of Changes | CM - Configuration Management | open |
| NIST800-CM-3(3) | CM-3(3) Configuration Change Control | Automated Change Implementation | CM - Configuration Management | open |
| NIST800-CM-3(4) | CM-3(4) Configuration Change Control | Security and Privacy Representatives | CM - Configuration Management | open |
| NIST800-CM-3(5) | CM-3(5) Configuration Change Control | Automated Security Response | CM - Configuration Management | open |
| NIST800-CM-3(6) | CM-3(6) Configuration Change Control | Cryptography Management | CM - Configuration Management | open |
| NIST800-CM-3(7) | CM-3(7) Configuration Change Control | Review System Changes | CM - Configuration Management | open |
| NIST800-CM-3(8) | CM-3(8) Configuration Change Control | Prevent or Restrict Configuration Changes | CM - Configuration Management | open |
| NIST800-CM-4 | CM-4 Impact Analyses | CM - Configuration Management | open |
| NIST800-CM-4(1) | CM-4(1) Impact Analyses | Separate Test Environments | CM - Configuration Management | open |
| NIST800-CM-4(2) | CM-4(2) Impact Analyses | Verification of Controls | CM - Configuration Management | open |
| NIST800-CM-5 | CM-5 Access Restrictions for Change | CM - Configuration Management | open |
| NIST800-CM-5(1) | CM-5(1) Access Restrictions for Change | Automated Access Enforcement and Audit Records | CM - Configuration Management | open |
| NIST800-CM-5(4) | CM-5(4) Access Restrictions for Change | Dual Authorization | CM - Configuration Management | open |
| NIST800-CM-5(5) | CM-5(5) Access Restrictions for Change | Privilege Limitation for Production and Operation | CM - Configuration Management | open |
| NIST800-CM-5(6) | CM-5(6) Access Restrictions for Change | Limit Library Privileges | CM - Configuration Management | open |
| NIST800-CM-6 | CM-6 Configuration Settings | CM - Configuration Management | open |
| NIST800-CM-6(1) | CM-6(1) Configuration Settings | Automated Management, Application, and Verification | CM - Configuration Management | open |
| NIST800-CM-6(2) | CM-6(2) Configuration Settings | Respond to Unauthorized Changes | CM - Configuration Management | open |
| NIST800-CM-7 | CM-7 Least Functionality | CM - Configuration Management | open |
| NIST800-CM-7(1) | CM-7(1) Least Functionality | Periodic Review | CM - Configuration Management | open |
| NIST800-CM-7(2) | CM-7(2) Least Functionality | Prevent Program Execution | CM - Configuration Management | open |
| NIST800-CM-7(3) | CM-7(3) Least Functionality | Registration Compliance | CM - Configuration Management | open |
| NIST800-CM-7(4) | CM-7(4) Least Functionality | Unauthorized Software: Deny-by-exception | CM - Configuration Management | open |
| NIST800-CM-7(5) | CM-7(5) Least Functionality | Authorized Software: Allow-by-exception | CM - Configuration Management | open |
| NIST800-CM-7(6) | CM-7(6) Least Functionality | Confined Environments with Limited Privileges | CM - Configuration Management | open |
| NIST800-CM-7(7) | CM-7(7) Least Functionality | Code Execution in Protected Environments | CM - Configuration Management | open |
| NIST800-CM-7(8) | CM-7(8) Least Functionality | Binary or Machine Executable Code | CM - Configuration Management | open |
| NIST800-CM-7(9) | CM-7(9) Least Functionality | Prohibiting The Use of Unauthorized Hardware | CM - Configuration Management | open |
| NIST800-CM-8 | CM-8 System Component Inventory | CM - Configuration Management | open |
| NIST800-CM-8(1) | CM-8(1) System Component Inventory | Updates During Installation and Removal | CM - Configuration Management | open |
| NIST800-CM-8(2) | CM-8(2) System Component Inventory | Automated Maintenance | CM - Configuration Management | open |
| NIST800-CM-8(3) | CM-8(3) System Component Inventory | Automated Unauthorized Component Detection | CM - Configuration Management | open |
| NIST800-CM-8(4) | CM-8(4) System Component Inventory | Accountability Information | CM - Configuration Management | open |
| NIST800-CM-8(6) | CM-8(6) System Component Inventory | Assessed Configurations and Approved Deviations | CM - Configuration Management | open |
| NIST800-CM-8(7) | CM-8(7) System Component Inventory | Centralized Repository | CM - Configuration Management | open |
| NIST800-CM-8(8) | CM-8(8) System Component Inventory | Automated Location Tracking | CM - Configuration Management | open |
| NIST800-CM-8(9) | CM-8(9) System Component Inventory | Assignment of Components to Systems | CM - Configuration Management | open |
| NIST800-CM-9 | CM-9 Configuration Management Plan | CM - Configuration Management | open |
| NIST800-CM-9(1) | CM-9(1) Configuration Management Plan | Assignment of Responsibility | CM - Configuration Management | open |
| NIST800-CM-10 | CM-10 Software Usage Restrictions | CM - Configuration Management | open |
| NIST800-CM-10(1) | CM-10(1) Software Usage Restrictions | Open-source Software | CM - Configuration Management | open |
| NIST800-CM-11 | CM-11 User-installed Software | CM - Configuration Management | open |
| NIST800-CM-11(2) | CM-11(2) User-installed Software | Software Installation with Privileged Status | CM - Configuration Management | open |
| NIST800-CM-11(3) | CM-11(3) User-installed Software | Automated Enforcement and Monitoring | CM - Configuration Management | open |
| NIST800-CM-12 | CM-12 Information Location | CM - Configuration Management | open |
| NIST800-CM-12(1) | CM-12(1) Information Location | Automated Tools to Support Information Location | CM - Configuration Management | open |
| NIST800-CM-13 | CM-13 Data Action Mapping | CM - Configuration Management | open |
| NIST800-CM-14 | CM-14 Signed Components | CM - Configuration Management | open |
| NIST800-CP-1 | CP-1 Policy and Procedures | CP - Contingency Planning | open |
| NIST800-CP-2 | CP-2 Contingency Plan | CP - Contingency Planning | open |
| NIST800-CP-2(1) | CP-2(1) Contingency Plan | Coordinate with Related Plans | CP - Contingency Planning | open |
| NIST800-CP-2(2) | CP-2(2) Contingency Plan | Capacity Planning | CP - Contingency Planning | open |
| NIST800-CP-2(3) | CP-2(3) Contingency Plan | Resume Mission and Business Functions | CP - Contingency Planning | open |
| NIST800-CP-2(5) | CP-2(5) Contingency Plan | Continue Mission and Business Functions | CP - Contingency Planning | open |
| NIST800-CP-2(6) | CP-2(6) Contingency Plan | Alternate Processing and Storage Sites | CP - Contingency Planning | open |
| NIST800-CP-2(7) | CP-2(7) Contingency Plan | Coordinate with External Service Providers | CP - Contingency Planning | open |
| NIST800-CP-2(8) | CP-2(8) Contingency Plan | Identify Critical Assets | CP - Contingency Planning | open |
| NIST800-CP-3 | CP-3 Contingency Training | CP - Contingency Planning | open |
| NIST800-CP-3(1) | CP-3(1) Contingency Training | Simulated Events | CP - Contingency Planning | open |
| NIST800-CP-3(2) | CP-3(2) Contingency Training | Mechanisms Used in Training Environments | CP - Contingency Planning | open |
| NIST800-CP-4 | CP-4 Contingency Plan Testing | CP - Contingency Planning | open |
| NIST800-CP-4(1) | CP-4(1) Contingency Plan Testing | Coordinate with Related Plans | CP - Contingency Planning | open |
| NIST800-CP-4(2) | CP-4(2) Contingency Plan Testing | Alternate Processing Site | CP - Contingency Planning | open |
| NIST800-CP-4(3) | CP-4(3) Contingency Plan Testing | Automated Testing | CP - Contingency Planning | open |
| NIST800-CP-4(4) | CP-4(4) Contingency Plan Testing | Full Recovery and Reconstitution | CP - Contingency Planning | open |
| NIST800-CP-4(5) | CP-4(5) Contingency Plan Testing | Self-challenge | CP - Contingency Planning | open |
| NIST800-CP-6 | CP-6 Alternate Storage Site | CP - Contingency Planning | open |
| NIST800-CP-6(1) | CP-6(1) Alternate Storage Site | Separation from Primary Site | CP - Contingency Planning | open |
| NIST800-CP-6(2) | CP-6(2) Alternate Storage Site | Recovery Time and Recovery Point Objectives | CP - Contingency Planning | open |
| NIST800-CP-6(3) | CP-6(3) Alternate Storage Site | Accessibility | CP - Contingency Planning | open |
| NIST800-CP-7 | CP-7 Alternate Processing Site | CP - Contingency Planning | open |
| NIST800-CP-7(1) | CP-7(1) Alternate Processing Site | Separation from Primary Site | CP - Contingency Planning | open |
| NIST800-CP-7(2) | CP-7(2) Alternate Processing Site | Accessibility | CP - Contingency Planning | open |
| NIST800-CP-7(3) | CP-7(3) Alternate Processing Site | Priority of Service | CP - Contingency Planning | open |
| NIST800-CP-7(4) | CP-7(4) Alternate Processing Site | Preparation for Use | CP - Contingency Planning | open |
| NIST800-CP-7(6) | CP-7(6) Alternate Processing Site | Inability to Return to Primary Site | CP - Contingency Planning | open |
| NIST800-CP-8 | CP-8 Telecommunications Services | CP - Contingency Planning | open |
| NIST800-CP-8(1) | CP-8(1) Telecommunications Services | Priority of Service Provisions | CP - Contingency Planning | open |
| NIST800-CP-8(2) | CP-8(2) Telecommunications Services | Single Points of Failure | CP - Contingency Planning | open |
| NIST800-CP-8(3) | CP-8(3) Telecommunications Services | Separation of Primary and Alternate Providers | CP - Contingency Planning | open |
| NIST800-CP-8(4) | CP-8(4) Telecommunications Services | Provider Contingency Plan | CP - Contingency Planning | open |
| NIST800-CP-8(5) | CP-8(5) Telecommunications Services | Alternate Telecommunication Service Testing | CP - Contingency Planning | open |
| NIST800-CP-9 | CP-9 System Backup | CP - Contingency Planning | open |
| NIST800-CP-9(1) | CP-9(1) System Backup | Testing for Reliability and Integrity | CP - Contingency Planning | open |
| NIST800-CP-9(2) | CP-9(2) System Backup | Test Restoration Using Sampling | CP - Contingency Planning | open |
| NIST800-CP-9(3) | CP-9(3) System Backup | Separate Storage for Critical Information | CP - Contingency Planning | open |
| NIST800-CP-9(5) | CP-9(5) System Backup | Transfer to Alternate Storage Site | CP - Contingency Planning | open |
| NIST800-CP-9(6) | CP-9(6) System Backup | Redundant Secondary System | CP - Contingency Planning | open |
| NIST800-CP-9(7) | CP-9(7) System Backup | Dual Authorization for Deletion or Destruction | CP - Contingency Planning | open |
| NIST800-CP-9(8) | CP-9(8) System Backup | Cryptographic Protection | CP - Contingency Planning | open |
| NIST800-CP-10 | CP-10 System Recovery and Reconstitution | CP - Contingency Planning | open |
| NIST800-CP-10(2) | CP-10(2) System Recovery and Reconstitution | Transaction Recovery | CP - Contingency Planning | open |
| NIST800-CP-10(4) | CP-10(4) System Recovery and Reconstitution | Restore Within Time Period | CP - Contingency Planning | open |
| NIST800-CP-10(6) | CP-10(6) System Recovery and Reconstitution | Component Protection | CP - Contingency Planning | open |
| NIST800-CP-11 | CP-11 Alternate Communications Protocols | CP - Contingency Planning | open |
| NIST800-CP-12 | CP-12 Safe Mode | CP - Contingency Planning | open |
| NIST800-CP-13 | CP-13 Alternative Security Mechanisms | CP - Contingency Planning | open |
| NIST800-IA-1 | IA-1 Policy and Procedures | IA - Identification and Authentication | open |
| NIST800-IA-2 | IA-2 Identification and Authentication (Organizational Users) | IA - Identification and Authentication | open |
| NIST800-IA-2(1) | IA-2(1) Identification and Authentication (Organizational Users) | Multi-factor Authentication to Privileged Accounts | IA - Identification and Authentication | open |
| NIST800-IA-2(2) | IA-2(2) Identification and Authentication (Organizational Users) | Multi-factor Authentication to Non-privileged Accounts | IA - Identification and Authentication | open |
| NIST800-IA-2(5) | IA-2(5) Identification and Authentication (Organizational Users) | Individual Authentication with Group Authentication | IA - Identification and Authentication | open |
| NIST800-IA-2(6) | IA-2(6) Identification and Authentication (Organizational Users) | Access to Accounts: separate Device | IA - Identification and Authentication | open |
| NIST800-IA-2(8) | IA-2(8) Identification and Authentication (Organizational Users) | Access to Accounts: Replay Resistant | IA - Identification and Authentication | open |
| NIST800-IA-2(10) | IA-2(10) Identification and Authentication (Organizational Users) | Single Sign-on | IA - Identification and Authentication | open |
| NIST800-IA-2(12) | IA-2(12) Identification and Authentication (Organizational Users) | Acceptance of PIV Credentials | IA - Identification and Authentication | open |
| NIST800-IA-2(13) | IA-2(13) Identification and Authentication (Organizational Users) | Out-of-band Authentication | IA - Identification and Authentication | open |
| NIST800-IA-3 | IA-3 Device Identification and Authentication | IA - Identification and Authentication | open |
| NIST800-IA-3(1) | IA-3(1) Device Identification and Authentication | Cryptographic Bidirectional Authentication | IA - Identification and Authentication | open |
| NIST800-IA-3(3) | IA-3(3) Device Identification and Authentication | Dynamic Address Allocation | IA - Identification and Authentication | open |
| NIST800-IA-3(4) | IA-3(4) Device Identification and Authentication | Device Attestation | IA - Identification and Authentication | open |
| NIST800-IA-4 | IA-4 Identifier Management | IA - Identification and Authentication | open |
| NIST800-IA-4(1) | IA-4(1) Identifier Management | Prohibit Account Identifiers as Public Identifiers | IA - Identification and Authentication | open |
| NIST800-IA-4(4) | IA-4(4) Identifier Management | Identify User Status | IA - Identification and Authentication | open |
| NIST800-IA-4(5) | IA-4(5) Identifier Management | Dynamic Management | IA - Identification and Authentication | open |
| NIST800-IA-4(6) | IA-4(6) Identifier Management | Cross-organization Management | IA - Identification and Authentication | open |
| NIST800-IA-4(8) | IA-4(8) Identifier Management | Pairwise Pseudonymous Identifiers | IA - Identification and Authentication | open |
| NIST800-IA-4(9) | IA-4(9) Identifier Management | Attribute Maintenance and Protection | IA - Identification and Authentication | open |
| NIST800-IA-5 | IA-5 Authenticator Management | IA - Identification and Authentication | open |
| NIST800-IA-5(1) | IA-5(1) Authenticator Management | Password-based Authentication | IA - Identification and Authentication | open |
| NIST800-IA-5(2) | IA-5(2) Authenticator Management | Public Key-based Authentication | IA - Identification and Authentication | open |
| NIST800-IA-5(5) | IA-5(5) Authenticator Management | Change Authenticators Prior to Delivery | IA - Identification and Authentication | open |
| NIST800-IA-5(6) | IA-5(6) Authenticator Management | Protection of Authenticators | IA - Identification and Authentication | open |
| NIST800-IA-5(7) | IA-5(7) Authenticator Management | No Embedded Unencrypted Static Authenticators | IA - Identification and Authentication | open |
| NIST800-IA-5(8) | IA-5(8) Authenticator Management | Multiple System Accounts | IA - Identification and Authentication | open |
| NIST800-IA-5(9) | IA-5(9) Authenticator Management | Federated Credential Management | IA - Identification and Authentication | open |
| NIST800-IA-5(10) | IA-5(10) Authenticator Management | Dynamic Credential Binding | IA - Identification and Authentication | open |
| NIST800-IA-5(12) | IA-5(12) Authenticator Management | Biometric Authentication Performance | IA - Identification and Authentication | open |
| NIST800-IA-5(13) | IA-5(13) Authenticator Management | Expiration of Cached Authenticators | IA - Identification and Authentication | open |
| NIST800-IA-5(14) | IA-5(14) Authenticator Management | Managing Content of PKI Trust Stores | IA - Identification and Authentication | open |
| NIST800-IA-5(15) | IA-5(15) Authenticator Management | GSA-approved Products and Services | IA - Identification and Authentication | open |
| NIST800-IA-5(16) | IA-5(16) Authenticator Management | In-person or Trusted External Party Authenticator Issuance | IA - Identification and Authentication | open |
| NIST800-IA-5(17) | IA-5(17) Authenticator Management | Presentation Attack Detection for Biometric Authenticators | IA - Identification and Authentication | open |
| NIST800-IA-5(18) | IA-5(18) Authenticator Management | Password Managers | IA - Identification and Authentication | open |
| NIST800-IA-6 | IA-6 Authentication Feedback | IA - Identification and Authentication | open |
| NIST800-IA-7 | IA-7 Cryptographic Module Authentication | IA - Identification and Authentication | open |
| NIST800-IA-8 | IA-8 Identification and Authentication (Non-organizational Users) | IA - Identification and Authentication | open |
| NIST800-IA-8(1) | IA-8(1) Identification and Authentication (Non-organizational Users) | Acceptance of PIV Credentials from Other Agencies | IA - Identification and Authentication | open |
| NIST800-IA-8(2) | IA-8(2) Identification and Authentication (Non-organizational Users) | Acceptance of External Authenticators | IA - Identification and Authentication | open |
| NIST800-IA-8(4) | IA-8(4) Identification and Authentication (Non-organizational Users) | Use of Defined Profiles | IA - Identification and Authentication | open |
| NIST800-IA-8(5) | IA-8(5) Identification and Authentication (Non-organizational Users) | Acceptance of PIV-I Credentials | IA - Identification and Authentication | open |
| NIST800-IA-8(6) | IA-8(6) Identification and Authentication (Non-organizational Users) | Disassociability | IA - Identification and Authentication | open |
| NIST800-IA-9 | IA-9 Service Identification and Authentication | IA - Identification and Authentication | open |
| NIST800-IA-10 | IA-10 Adaptive Authentication | IA - Identification and Authentication | open |
| NIST800-IA-11 | IA-11 Re-authentication | IA - Identification and Authentication | open |
| NIST800-IA-12 | IA-12 Identity Proofing | IA - Identification and Authentication | open |
| NIST800-IA-12(1) | IA-12(1) Identity Proofing | Supervisor Authorization | IA - Identification and Authentication | open |
| NIST800-IA-12(2) | IA-12(2) Identity Proofing | Identity Evidence | IA - Identification and Authentication | open |
| NIST800-IA-12(3) | IA-12(3) Identity Proofing | Identity Evidence Validation and Verification | IA - Identification and Authentication | open |
| NIST800-IA-12(4) | IA-12(4) Identity Proofing | In-person Validation and Verification | IA - Identification and Authentication | open |
| NIST800-IA-12(5) | IA-12(5) Identity Proofing | Address Confirmation | IA - Identification and Authentication | open |
| NIST800-IA-12(6) | IA-12(6) Identity Proofing | Accept Externally-proofed Identities | IA - Identification and Authentication | open |
| NIST800-IA-13 | IA-13 Identity Providers and Authorization Servers | IA - Identification and Authentication | open |
| NIST800-IA-13(1) | IA-13(1) Identity Providers and Authorization Servers | Protection of Cryptographic Keys | IA - Identification and Authentication | open |
| NIST800-IA-13(2) | IA-13(2) Identity Providers and Authorization Servers | Verification of Identity Assertions and Access Tokens | IA - Identification and Authentication | open |
| NIST800-IA-13(3) | IA-13(3) Identity Providers and Authorization Servers | Token Management | IA - Identification and Authentication | open |
| NIST800-IR-1 | IR-1 Policy and Procedures | IR - Incident Response | open |
| NIST800-IR-2 | IR-2 Incident Response Training | IR - Incident Response | open |
| NIST800-IR-2(1) | IR-2(1) Incident Response Training | Simulated Events | IR - Incident Response | open |
| NIST800-IR-2(2) | IR-2(2) Incident Response Training | Automated Training Environments | IR - Incident Response | open |
| NIST800-IR-2(3) | IR-2(3) Incident Response Training | Breach | IR - Incident Response | open |
| NIST800-IR-3 | IR-3 Incident Response Testing | IR - Incident Response | open |
| NIST800-IR-3(1) | IR-3(1) Incident Response Testing | Automated Testing | IR - Incident Response | open |
| NIST800-IR-3(2) | IR-3(2) Incident Response Testing | Coordination with Related Plans | IR - Incident Response | open |
| NIST800-IR-3(3) | IR-3(3) Incident Response Testing | Continuous Improvement | IR - Incident Response | open |
| NIST800-IR-4 | IR-4 Incident Handling | IR - Incident Response | open |
| NIST800-IR-4(1) | IR-4(1) Incident Handling | Automated Incident Handling Processes | IR - Incident Response | open |
| NIST800-IR-4(2) | IR-4(2) Incident Handling | Dynamic Reconfiguration | IR - Incident Response | open |
| NIST800-IR-4(3) | IR-4(3) Incident Handling | Continuity of Operations | IR - Incident Response | open |
| NIST800-IR-4(4) | IR-4(4) Incident Handling | Information Correlation | IR - Incident Response | open |
| NIST800-IR-4(5) | IR-4(5) Incident Handling | Automatic Disabling of System | IR - Incident Response | open |
| NIST800-IR-4(6) | IR-4(6) Incident Handling | Insider Threats | IR - Incident Response | open |
| NIST800-IR-4(7) | IR-4(7) Incident Handling | Insider Threats: Intra-organization Coordination | IR - Incident Response | open |
| NIST800-IR-4(8) | IR-4(8) Incident Handling | Correlation with External Organizations | IR - Incident Response | open |
| NIST800-IR-4(9) | IR-4(9) Incident Handling | Dynamic Response Capability | IR - Incident Response | open |
| NIST800-IR-4(10) | IR-4(10) Incident Handling | Supply Chain Coordination | IR - Incident Response | open |
| NIST800-IR-4(11) | IR-4(11) Incident Handling | Integrated Incident Response Team | IR - Incident Response | open |
| NIST800-IR-4(12) | IR-4(12) Incident Handling | Malicious Code and Forensic Analysis | IR - Incident Response | open |
| NIST800-IR-4(13) | IR-4(13) Incident Handling | Behavior Analysis | IR - Incident Response | open |
| NIST800-IR-4(14) | IR-4(14) Incident Handling | Security Operations Center | IR - Incident Response | open |
| NIST800-IR-4(15) | IR-4(15) Incident Handling | Public Relations and Reputation Repair | IR - Incident Response | open |
| NIST800-IR-5 | IR-5 Incident Monitoring | IR - Incident Response | open |
| NIST800-IR-5(1) | IR-5(1) Incident Monitoring | Automated Tracking, Data Collection, and Analysis | IR - Incident Response | open |
| NIST800-IR-6 | IR-6 Incident Reporting | IR - Incident Response | open |
| NIST800-IR-6(1) | IR-6(1) Incident Reporting | Automated Reporting | IR - Incident Response | open |
| NIST800-IR-6(2) | IR-6(2) Incident Reporting | Vulnerabilities Related to Incidents | IR - Incident Response | open |
| NIST800-IR-6(3) | IR-6(3) Incident Reporting | Supply Chain Coordination | IR - Incident Response | open |
| NIST800-IR-7 | IR-7 Incident Response Assistance | IR - Incident Response | open |
| NIST800-IR-7(1) | IR-7(1) Incident Response Assistance | Automation Support for Availability of Information and Support | IR - Incident Response | open |
| NIST800-IR-7(2) | IR-7(2) Incident Response Assistance | Coordination with External Providers | IR - Incident Response | open |
| NIST800-IR-8 | IR-8 Incident Response Plan | IR - Incident Response | open |
| NIST800-IR-8(1) | IR-8(1) Incident Response Plan | Breaches | IR - Incident Response | open |
| NIST800-IR-9 | IR-9 Information Spillage Response | IR - Incident Response | open |
| NIST800-IR-9(2) | IR-9(2) Information Spillage Response | Training | IR - Incident Response | open |
| NIST800-IR-9(3) | IR-9(3) Information Spillage Response | Post-spill Operations | IR - Incident Response | open |
| NIST800-IR-9(4) | IR-9(4) Information Spillage Response | Exposure to Unauthorized Personnel | IR - Incident Response | open |
| NIST800-MA-1 | MA-1 Policy and Procedures | MA - Maintenance | open |
| NIST800-MA-2 | MA-2 Controlled Maintenance | MA - Maintenance | open |
| NIST800-MA-2(2) | MA-2(2) Controlled Maintenance | Automated Maintenance Activities | MA - Maintenance | open |
| NIST800-MA-3 | MA-3 Maintenance Tools | MA - Maintenance | open |
| NIST800-MA-3(1) | MA-3(1) Maintenance Tools | Inspect Tools | MA - Maintenance | open |
| NIST800-MA-3(2) | MA-3(2) Maintenance Tools | Inspect Media | MA - Maintenance | open |
| NIST800-MA-3(3) | MA-3(3) Maintenance Tools | Prevent Unauthorized Removal | MA - Maintenance | open |
| NIST800-MA-3(4) | MA-3(4) Maintenance Tools | Restricted Tool Use | MA - Maintenance | open |
| NIST800-MA-3(5) | MA-3(5) Maintenance Tools | Execution with Privilege | MA - Maintenance | open |
| NIST800-MA-3(6) | MA-3(6) Maintenance Tools | Software Updates and Patches | MA - Maintenance | open |
| NIST800-MA-4 | MA-4 Nonlocal Maintenance | MA - Maintenance | open |
| NIST800-MA-4(1) | MA-4(1) Nonlocal Maintenance | Logging and Review | MA - Maintenance | open |
| NIST800-MA-4(3) | MA-4(3) Nonlocal Maintenance | Comparable Security and Sanitization | MA - Maintenance | open |
| NIST800-MA-4(4) | MA-4(4) Nonlocal Maintenance | Authentication and Separation of Maintenance Sessions | MA - Maintenance | open |
| NIST800-MA-4(5) | MA-4(5) Nonlocal Maintenance | Approvals and Notifications | MA - Maintenance | open |
| NIST800-MA-4(6) | MA-4(6) Nonlocal Maintenance | Cryptographic Protection | MA - Maintenance | open |
| NIST800-MA-4(7) | MA-4(7) Nonlocal Maintenance | Disconnect Verification | MA - Maintenance | open |
| NIST800-MA-5 | MA-5 Maintenance Personnel | MA - Maintenance | open |
| NIST800-MA-5(1) | MA-5(1) Maintenance Personnel | Individuals Without Appropriate Access | MA - Maintenance | open |
| NIST800-MA-5(2) | MA-5(2) Maintenance Personnel | Security Clearances for Classified Systems | MA - Maintenance | open |
| NIST800-MA-5(3) | MA-5(3) Maintenance Personnel | Citizenship Requirements for Classified Systems | MA - Maintenance | open |
| NIST800-MA-5(4) | MA-5(4) Maintenance Personnel | Foreign Nationals | MA - Maintenance | open |
| NIST800-MA-5(5) | MA-5(5) Maintenance Personnel | Non-system Maintenance | MA - Maintenance | open |
| NIST800-MA-6 | MA-6 Timely Maintenance | MA - Maintenance | open |
| NIST800-MA-6(1) | MA-6(1) Timely Maintenance | Preventive Maintenance | MA - Maintenance | open |
| NIST800-MA-6(2) | MA-6(2) Timely Maintenance | Predictive Maintenance | MA - Maintenance | open |
| NIST800-MA-6(3) | MA-6(3) Timely Maintenance | Automated Support for Predictive Maintenance | MA - Maintenance | open |
| NIST800-MA-7 | MA-7 Field Maintenance | MA - Maintenance | open |
| NIST800-MP-1 | MP-1 Policy and Procedures | MP - Media Protection | open |
| NIST800-MP-2 | MP-2 Media Access | MP - Media Protection | open |
| NIST800-MP-3 | MP-3 Media Marking | MP - Media Protection | open |
| NIST800-MP-4 | MP-4 Media Storage | MP - Media Protection | open |
| NIST800-MP-4(2) | MP-4(2) Media Storage | Automated Restricted Access | MP - Media Protection | open |
| NIST800-MP-5 | MP-5 Media Transport | MP - Media Protection | open |
| NIST800-MP-5(3) | MP-5(3) Media Transport | Custodians | MP - Media Protection | open |
| NIST800-MP-6 | MP-6 Media Sanitization | MP - Media Protection | open |
| NIST800-MP-6(1) | MP-6(1) Media Sanitization | Review, Approve, Track, Document, and Verify | MP - Media Protection | open |
| NIST800-MP-6(2) | MP-6(2) Media Sanitization | Equipment Testing | MP - Media Protection | open |
| NIST800-MP-6(3) | MP-6(3) Media Sanitization | Nondestructive Techniques | MP - Media Protection | open |
| NIST800-MP-6(7) | MP-6(7) Media Sanitization | Dual Authorization | MP - Media Protection | open |
| NIST800-MP-6(8) | MP-6(8) Media Sanitization | Remote Purging or Wiping of Information | MP - Media Protection | open |
| NIST800-MP-7 | MP-7 Media Use | MP - Media Protection | open |
| NIST800-MP-7(2) | MP-7(2) Media Use | Prohibit Use of Sanitization-resistant Media | MP - Media Protection | open |
| NIST800-MP-8 | MP-8 Media Downgrading | MP - Media Protection | open |
| NIST800-MP-8(1) | MP-8(1) Media Downgrading | Documentation of Process | MP - Media Protection | open |
| NIST800-MP-8(2) | MP-8(2) Media Downgrading | Equipment Testing | MP - Media Protection | open |
| NIST800-MP-8(3) | MP-8(3) Media Downgrading | Controlled Unclassified Information | MP - Media Protection | open |
| NIST800-MP-8(4) | MP-8(4) Media Downgrading | Classified Information | MP - Media Protection | open |
| NIST800-PE-1 | PE-1 Policy and Procedures | PE - Physical and Environmental Protection | open |
| NIST800-PE-2 | PE-2 Physical Access Authorizations | PE - Physical and Environmental Protection | open |
| NIST800-PE-2(1) | PE-2(1) Physical Access Authorizations | Access by Position or Role | PE - Physical and Environmental Protection | open |
| NIST800-PE-2(2) | PE-2(2) Physical Access Authorizations | Two Forms of Identification | PE - Physical and Environmental Protection | open |
| NIST800-PE-2(3) | PE-2(3) Physical Access Authorizations | Restrict Unescorted Access | PE - Physical and Environmental Protection | open |
| NIST800-PE-3 | PE-3 Physical Access Control | PE - Physical and Environmental Protection | open |
| NIST800-PE-3(1) | PE-3(1) Physical Access Control | System Access | PE - Physical and Environmental Protection | open |
| NIST800-PE-3(2) | PE-3(2) Physical Access Control | Facility and Systems | PE - Physical and Environmental Protection | open |
| NIST800-PE-3(3) | PE-3(3) Physical Access Control | Continuous Guards | PE - Physical and Environmental Protection | open |
| NIST800-PE-3(4) | PE-3(4) Physical Access Control | Lockable Casings | PE - Physical and Environmental Protection | open |
| NIST800-PE-3(5) | PE-3(5) Physical Access Control | Tamper Protection | PE - Physical and Environmental Protection | open |
| NIST800-PE-3(7) | PE-3(7) Physical Access Control | Physical Barriers | PE - Physical and Environmental Protection | open |
| NIST800-PE-3(8) | PE-3(8) Physical Access Control | Access Control Vestibules | PE - Physical and Environmental Protection | open |
| NIST800-PE-4 | PE-4 Access Control for Transmission | PE - Physical and Environmental Protection | open |
| NIST800-PE-5 | PE-5 Access Control for Output Devices | PE - Physical and Environmental Protection | open |
| NIST800-PE-5(2) | PE-5(2) Access Control for Output Devices | Link to Individual Identity | PE - Physical and Environmental Protection | open |
| NIST800-PE-6 | PE-6 Monitoring Physical Access | PE - Physical and Environmental Protection | open |
| NIST800-PE-6(1) | PE-6(1) Monitoring Physical Access | Intrusion Alarms and Surveillance Equipment | PE - Physical and Environmental Protection | open |
| NIST800-PE-6(2) | PE-6(2) Monitoring Physical Access | Automated Intrusion Recognition and Responses | PE - Physical and Environmental Protection | open |
| NIST800-PE-6(3) | PE-6(3) Monitoring Physical Access | Video Surveillance | PE - Physical and Environmental Protection | open |
| NIST800-PE-6(4) | PE-6(4) Monitoring Physical Access | Monitoring Physical Access to Systems | PE - Physical and Environmental Protection | open |
| NIST800-PE-8 | PE-8 Visitor Access Records | PE - Physical and Environmental Protection | open |
| NIST800-PE-8(1) | PE-8(1) Visitor Access Records | Automated Records Maintenance and Review | PE - Physical and Environmental Protection | open |
| NIST800-PE-8(3) | PE-8(3) Visitor Access Records | Limit Personally Identifiable Information Elements | PE - Physical and Environmental Protection | open |
| NIST800-PE-9 | PE-9 Power Equipment and Cabling | PE - Physical and Environmental Protection | open |
| NIST800-PE-9(1) | PE-9(1) Power Equipment and Cabling | Redundant Cabling | PE - Physical and Environmental Protection | open |
| NIST800-PE-9(2) | PE-9(2) Power Equipment and Cabling | Automatic Voltage Controls | PE - Physical and Environmental Protection | open |
| NIST800-PE-10 | PE-10 Emergency Shutoff | PE - Physical and Environmental Protection | open |
| NIST800-PE-11 | PE-11 Emergency Power | PE - Physical and Environmental Protection | open |
| NIST800-PE-11(1) | PE-11(1) Emergency Power | Alternate Power Supply: Minimal Operational Capability | PE - Physical and Environmental Protection | open |
| NIST800-PE-11(2) | PE-11(2) Emergency Power | Alternate Power Supply: Self-contained | PE - Physical and Environmental Protection | open |
| NIST800-PE-12 | PE-12 Emergency Lighting | PE - Physical and Environmental Protection | open |
| NIST800-PE-12(1) | PE-12(1) Emergency Lighting | Essential Mission and Business Functions | PE - Physical and Environmental Protection | open |
| NIST800-PE-13 | PE-13 Fire Protection | PE - Physical and Environmental Protection | open |
| NIST800-PE-13(1) | PE-13(1) Fire Protection | Detection Systems: Automatic Activation and Notification | PE - Physical and Environmental Protection | open |
| NIST800-PE-13(2) | PE-13(2) Fire Protection | Suppression Systems: Automatic Activation and Notification | PE - Physical and Environmental Protection | open |
| NIST800-PE-13(4) | PE-13(4) Fire Protection | Inspections | PE - Physical and Environmental Protection | open |
| NIST800-PE-14 | PE-14 Environmental Controls | PE - Physical and Environmental Protection | open |
| NIST800-PE-14(1) | PE-14(1) Environmental Controls | Automatic Controls | PE - Physical and Environmental Protection | open |
| NIST800-PE-14(2) | PE-14(2) Environmental Controls | Monitoring with Alarms and Notifications | PE - Physical and Environmental Protection | open |
| NIST800-PE-15 | PE-15 Water Damage Protection | PE - Physical and Environmental Protection | open |
| NIST800-PE-15(1) | PE-15(1) Water Damage Protection | Automation Support | PE - Physical and Environmental Protection | open |
| NIST800-PE-16 | PE-16 Delivery and Removal | PE - Physical and Environmental Protection | open |
| NIST800-PE-17 | PE-17 Alternate Work Site | PE - Physical and Environmental Protection | open |
| NIST800-PE-18 | PE-18 Location of System Components | PE - Physical and Environmental Protection | open |
| NIST800-PE-19 | PE-19 Information Leakage | PE - Physical and Environmental Protection | open |
| NIST800-PE-19(1) | PE-19(1) Information Leakage | National Emissions Policies and Procedures | PE - Physical and Environmental Protection | open |
| NIST800-PE-20 | PE-20 Asset Monitoring and Tracking | PE - Physical and Environmental Protection | open |
| NIST800-PE-21 | PE-21 Electromagnetic Pulse Protection | PE - Physical and Environmental Protection | open |
| NIST800-PE-22 | PE-22 Component Marking | PE - Physical and Environmental Protection | open |
| NIST800-PE-23 | PE-23 Facility Location | PE - Physical and Environmental Protection | open |
| NIST800-PL-1 | PL-1 Policy and Procedures | PL - Planning | open |
| NIST800-PL-2 | PL-2 System Security and Privacy Plans | PL - Planning | open |
| NIST800-PL-4 | PL-4 Rules of Behavior | PL - Planning | open |
| NIST800-PL-4(1) | PL-4(1) Rules of Behavior | Social Media and External Site/Application Usage Restrictions | PL - Planning | open |
| NIST800-PL-7 | PL-7 Concept of Operations | PL - Planning | open |
| NIST800-PL-8 | PL-8 Security and Privacy Architectures | PL - Planning | open |
| NIST800-PL-8(1) | PL-8(1) Security and Privacy Architectures | Defense in Depth | PL - Planning | open |
| NIST800-PL-8(2) | PL-8(2) Security and Privacy Architectures | Supplier Diversity | PL - Planning | open |
| NIST800-PL-9 | PL-9 Central Management | PL - Planning | open |
| NIST800-PL-10 | PL-10 Baseline Selection | PL - Planning | open |
| NIST800-PL-11 | PL-11 Baseline Tailoring | PL - Planning | open |
| NIST800-PM-1 | PM-1 Information Security Program Plan | PM - Program Management | open |
| NIST800-PM-2 | PM-2 Information Security Program Leadership Role | PM - Program Management | open |
| NIST800-PM-3 | PM-3 Information Security and Privacy Resources | PM - Program Management | open |
| NIST800-PM-4 | PM-4 Plan of Action and Milestones Process | PM - Program Management | open |
| NIST800-PM-5 | PM-5 System Inventory | PM - Program Management | open |
| NIST800-PM-5(1) | PM-5(1) System Inventory | Inventory of Personally Identifiable Information | PM - Program Management | open |
| NIST800-PM-6 | PM-6 Measures of Performance | PM - Program Management | open |
| NIST800-PM-7 | PM-7 Enterprise Architecture | PM - Program Management | open |
| NIST800-PM-7(1) | PM-7(1) Enterprise Architecture | Offloading | PM - Program Management | open |
| NIST800-PM-8 | PM-8 Critical Infrastructure Plan | PM - Program Management | open |
| NIST800-PM-9 | PM-9 Risk Management Strategy | PM - Program Management | open |
| NIST800-PM-10 | PM-10 Authorization Process | PM - Program Management | open |
| NIST800-PM-11 | PM-11 Mission and Business Process Definition | PM - Program Management | open |
| NIST800-PM-12 | PM-12 Insider Threat Program | PM - Program Management | open |
| NIST800-PM-13 | PM-13 Security and Privacy Workforce | PM - Program Management | open |
| NIST800-PM-14 | PM-14 Testing, Training, and Monitoring | PM - Program Management | open |
| NIST800-PM-15 | PM-15 Security and Privacy Groups and Associations | PM - Program Management | open |
| NIST800-PM-16 | PM-16 Threat Awareness Program | PM - Program Management | open |
| NIST800-PM-16(1) | PM-16(1) Threat Awareness Program | Automated Means for Sharing Threat Intelligence | PM - Program Management | open |
| NIST800-PM-17 | PM-17 Protecting Controlled Unclassified Information on External Systems | PM - Program Management | open |
| NIST800-PM-18 | PM-18 Privacy Program Plan | PM - Program Management | open |
| NIST800-PM-19 | PM-19 Privacy Program Leadership Role | PM - Program Management | open |
| NIST800-PM-20 | PM-20 Dissemination of Privacy Program Information | PM - Program Management | open |
| NIST800-PM-20(1) | PM-20(1) Dissemination of Privacy Program Information | Privacy Policies on Websites, Applications, and Digital Services | PM - Program Management | open |
| NIST800-PM-21 | PM-21 Accounting of Disclosures | PM - Program Management | open |
| NIST800-PM-22 | PM-22 Personally Identifiable Information Quality Management | PM - Program Management | open |
| NIST800-PM-23 | PM-23 Data Governance Body | PM - Program Management | open |
| NIST800-PM-24 | PM-24 Data Integrity Board | PM - Program Management | open |
| NIST800-PM-25 | PM-25 Minimization of Personally Identifiable Information Used in Testing, Training, and Research | PM - Program Management | open |
| NIST800-PM-26 | PM-26 Complaint Management | PM - Program Management | open |
| NIST800-PM-27 | PM-27 Privacy Reporting | PM - Program Management | open |
| NIST800-PM-28 | PM-28 Risk Framing | PM - Program Management | open |
| NIST800-PM-29 | PM-29 Risk Management Program Leadership Roles | PM - Program Management | open |
| NIST800-PM-30 | PM-30 Supply Chain Risk Management Strategy | PM - Program Management | open |
| NIST800-PM-30(1) | PM-30(1) Supply Chain Risk Management Strategy | Suppliers of Critical or Mission-essential Items | PM - Program Management | open |
| NIST800-PM-31 | PM-31 Continuous Monitoring Strategy | PM - Program Management | open |
| NIST800-PM-32 | PM-32 Purposing | PM - Program Management | open |
| NIST800-PS-1 | PS-1 Policy and Procedures | PS - Personnel Security | open |
| NIST800-PS-2 | PS-2 Position Risk Designation | PS - Personnel Security | open |
| NIST800-PS-3 | PS-3 Personnel Screening | PS - Personnel Security | open |
| NIST800-PS-3(1) | PS-3(1) Personnel Screening | Classified Information | PS - Personnel Security | open |
| NIST800-PS-3(2) | PS-3(2) Personnel Screening | Formal Indoctrination | PS - Personnel Security | open |
| NIST800-PS-3(3) | PS-3(3) Personnel Screening | Information Requiring Special Protective Measures | PS - Personnel Security | open |
| NIST800-PS-3(4) | PS-3(4) Personnel Screening | Citizenship Requirements | PS - Personnel Security | open |
| NIST800-PS-4 | PS-4 Personnel Termination | PS - Personnel Security | open |
| NIST800-PS-4(1) | PS-4(1) Personnel Termination | Post-employment Requirements | PS - Personnel Security | open |
| NIST800-PS-4(2) | PS-4(2) Personnel Termination | Automated Actions | PS - Personnel Security | open |
| NIST800-PS-5 | PS-5 Personnel Transfer | PS - Personnel Security | open |
| NIST800-PS-6 | PS-6 Access Agreements | PS - Personnel Security | open |
| NIST800-PS-6(2) | PS-6(2) Access Agreements | Classified Information Requiring Special Protection | PS - Personnel Security | open |
| NIST800-PS-6(3) | PS-6(3) Access Agreements | Post-employment Requirements | PS - Personnel Security | open |
| NIST800-PS-7 | PS-7 External Personnel Security | PS - Personnel Security | open |
| NIST800-PS-8 | PS-8 Personnel Sanctions | PS - Personnel Security | open |
| NIST800-PS-9 | PS-9 Position Descriptions | PS - Personnel Security | open |
| NIST800-PT-1 | PT-1 Policy and Procedures | PT - PII Processing and Transparency | open |
| NIST800-PT-2 | PT-2 Authority to Process Personally Identifiable Information | PT - PII Processing and Transparency | open |
| NIST800-PT-2(1) | PT-2(1) Authority to Process Personally Identifiable Information | Data Tagging | PT - PII Processing and Transparency | open |
| NIST800-PT-2(2) | PT-2(2) Authority to Process Personally Identifiable Information | Automation | PT - PII Processing and Transparency | open |
| NIST800-PT-3 | PT-3 Personally Identifiable Information Processing Purposes | PT - PII Processing and Transparency | open |
| NIST800-PT-3(1) | PT-3(1) Personally Identifiable Information Processing Purposes | Data Tagging | PT - PII Processing and Transparency | open |
| NIST800-PT-3(2) | PT-3(2) Personally Identifiable Information Processing Purposes | Automation | PT - PII Processing and Transparency | open |
| NIST800-PT-4 | PT-4 Consent | PT - PII Processing and Transparency | open |
| NIST800-PT-4(1) | PT-4(1) Consent | Tailored Consent | PT - PII Processing and Transparency | open |
| NIST800-PT-4(2) | PT-4(2) Consent | Just-in-time Consent | PT - PII Processing and Transparency | open |
| NIST800-PT-4(3) | PT-4(3) Consent | Revocation | PT - PII Processing and Transparency | open |
| NIST800-PT-5 | PT-5 Privacy Notice | PT - PII Processing and Transparency | open |
| NIST800-PT-5(1) | PT-5(1) Privacy Notice | Just-in-time Notice | PT - PII Processing and Transparency | open |
| NIST800-PT-5(2) | PT-5(2) Privacy Notice | Privacy Act Statements | PT - PII Processing and Transparency | open |
| NIST800-PT-6 | PT-6 System of Records Notice | PT - PII Processing and Transparency | open |
| NIST800-PT-6(1) | PT-6(1) System of Records Notice | Routine Uses | PT - PII Processing and Transparency | open |
| NIST800-PT-6(2) | PT-6(2) System of Records Notice | Exemption Rules | PT - PII Processing and Transparency | open |
| NIST800-PT-7 | PT-7 Specific Categories of Personally Identifiable Information | PT - PII Processing and Transparency | open |
| NIST800-PT-7(1) | PT-7(1) Specific Categories of Personally Identifiable Information | Social Security Numbers | PT - PII Processing and Transparency | open |
| NIST800-PT-7(2) | PT-7(2) Specific Categories of Personally Identifiable Information | First Amendment Information | PT - PII Processing and Transparency | open |
| NIST800-PT-8 | PT-8 Computer Matching Requirements | PT - PII Processing and Transparency | open |
| NIST800-RA-1 | RA-1 Policy and Procedures | RA - Risk Assessment | open |
| NIST800-RA-2 | RA-2 Security Categorization | RA - Risk Assessment | open |
| NIST800-RA-2(1) | RA-2(1) Security Categorization | Impact-level Prioritization | RA - Risk Assessment | open |
| NIST800-RA-3 | RA-3 Risk Assessment | RA - Risk Assessment | open |
| NIST800-RA-3(1) | RA-3(1) Risk Assessment | Supply Chain Risk Assessment | RA - Risk Assessment | open |
| NIST800-RA-3(2) | RA-3(2) Risk Assessment | Use of All-source Intelligence | RA - Risk Assessment | open |
| NIST800-RA-3(3) | RA-3(3) Risk Assessment | Dynamic Threat Awareness | RA - Risk Assessment | open |
| NIST800-RA-3(4) | RA-3(4) Risk Assessment | Predictive Cyber Analytics | RA - Risk Assessment | open |
| NIST800-RA-5 | RA-5 Vulnerability Monitoring and Scanning | RA - Risk Assessment | open |
| NIST800-RA-5(2) | RA-5(2) Vulnerability Monitoring and Scanning | Update Vulnerabilities to Be Scanned | RA - Risk Assessment | open |
| NIST800-RA-5(3) | RA-5(3) Vulnerability Monitoring and Scanning | Breadth and Depth of Coverage | RA - Risk Assessment | open |
| NIST800-RA-5(4) | RA-5(4) Vulnerability Monitoring and Scanning | Discoverable Information | RA - Risk Assessment | open |
| NIST800-RA-5(5) | RA-5(5) Vulnerability Monitoring and Scanning | Privileged Access | RA - Risk Assessment | open |
| NIST800-RA-5(6) | RA-5(6) Vulnerability Monitoring and Scanning | Automated Trend Analyses | RA - Risk Assessment | open |
| NIST800-RA-5(8) | RA-5(8) Vulnerability Monitoring and Scanning | Review Historic Audit Logs | RA - Risk Assessment | open |
| NIST800-RA-5(10) | RA-5(10) Vulnerability Monitoring and Scanning | Correlate Scanning Information | RA - Risk Assessment | open |
| NIST800-RA-5(11) | RA-5(11) Vulnerability Monitoring and Scanning | Public Disclosure Program | RA - Risk Assessment | open |
| NIST800-RA-6 | RA-6 Technical Surveillance Countermeasures Survey | RA - Risk Assessment | open |
| NIST800-RA-7 | RA-7 Risk Response | RA - Risk Assessment | open |
| NIST800-RA-8 | RA-8 Privacy Impact Assessments | RA - Risk Assessment | open |
| NIST800-RA-9 | RA-9 Criticality Analysis | RA - Risk Assessment | open |
| NIST800-RA-10 | RA-10 Threat Hunting | RA - Risk Assessment | open |
| NIST800-SA-1 | SA-1 Policy and Procedures | SA - System and Services Acquisition | open |
| NIST800-SA-2 | SA-2 Allocation of Resources | SA - System and Services Acquisition | open |
| NIST800-SA-3 | SA-3 System Development Life Cycle | SA - System and Services Acquisition | open |
| NIST800-SA-3(1) | SA-3(1) System Development Life Cycle | Manage Preproduction Environment | SA - System and Services Acquisition | open |
| NIST800-SA-3(2) | SA-3(2) System Development Life Cycle | Use of Live or Operational Data | SA - System and Services Acquisition | open |
| NIST800-SA-3(3) | SA-3(3) System Development Life Cycle | Technology Refresh | SA - System and Services Acquisition | open |
| NIST800-SA-4 | SA-4 Acquisition Process | SA - System and Services Acquisition | open |
| NIST800-SA-4(1) | SA-4(1) Acquisition Process | Functional Properties of Controls | SA - System and Services Acquisition | open |
| NIST800-SA-4(2) | SA-4(2) Acquisition Process | Design and Implementation Information for Controls | SA - System and Services Acquisition | open |
| NIST800-SA-4(3) | SA-4(3) Acquisition Process | Development Methods, Techniques, and Practices | SA - System and Services Acquisition | open |
| NIST800-SA-4(5) | SA-4(5) Acquisition Process | System, Component, and Service Configurations | SA - System and Services Acquisition | open |
| NIST800-SA-4(6) | SA-4(6) Acquisition Process | Use of Information Assurance Products | SA - System and Services Acquisition | open |
| NIST800-SA-4(7) | SA-4(7) Acquisition Process | NIAP-approved Protection Profiles | SA - System and Services Acquisition | open |
| NIST800-SA-4(8) | SA-4(8) Acquisition Process | Continuous Monitoring Plan for Controls | SA - System and Services Acquisition | open |
| NIST800-SA-4(9) | SA-4(9) Acquisition Process | Functions, Ports, Protocols, and Services in Use | SA - System and Services Acquisition | open |
| NIST800-SA-4(10) | SA-4(10) Acquisition Process | Use of Approved PIV Products | SA - System and Services Acquisition | open |
| NIST800-SA-4(11) | SA-4(11) Acquisition Process | System of Records | SA - System and Services Acquisition | open |
| NIST800-SA-4(12) | SA-4(12) Acquisition Process | Data Ownership | SA - System and Services Acquisition | open |
| NIST800-SA-5 | SA-5 System Documentation | SA - System and Services Acquisition | open |
| NIST800-SA-8 | SA-8 Security and Privacy Engineering Principles | SA - System and Services Acquisition | open |
| NIST800-SA-8(1) | SA-8(1) Security and Privacy Engineering Principles | Clear Abstractions | SA - System and Services Acquisition | open |
| NIST800-SA-8(2) | SA-8(2) Security and Privacy Engineering Principles | Least Common Mechanism | SA - System and Services Acquisition | open |
| NIST800-SA-8(3) | SA-8(3) Security and Privacy Engineering Principles | Modularity and Layering | SA - System and Services Acquisition | open |
| NIST800-SA-8(4) | SA-8(4) Security and Privacy Engineering Principles | Partially Ordered Dependencies | SA - System and Services Acquisition | open |
| NIST800-SA-8(5) | SA-8(5) Security and Privacy Engineering Principles | Efficiently Mediated Access | SA - System and Services Acquisition | open |
| NIST800-SA-8(6) | SA-8(6) Security and Privacy Engineering Principles | Minimized Sharing | SA - System and Services Acquisition | open |
| NIST800-SA-8(7) | SA-8(7) Security and Privacy Engineering Principles | Reduced Complexity | SA - System and Services Acquisition | open |
| NIST800-SA-8(8) | SA-8(8) Security and Privacy Engineering Principles | Secure Evolvability | SA - System and Services Acquisition | open |
| NIST800-SA-8(9) | SA-8(9) Security and Privacy Engineering Principles | Trusted Components | SA - System and Services Acquisition | open |
| NIST800-SA-8(10) | SA-8(10) Security and Privacy Engineering Principles | Hierarchical Trust | SA - System and Services Acquisition | open |
| NIST800-SA-8(11) | SA-8(11) Security and Privacy Engineering Principles | Inverse Modification Threshold | SA - System and Services Acquisition | open |
| NIST800-SA-8(12) | SA-8(12) Security and Privacy Engineering Principles | Hierarchical Protection | SA - System and Services Acquisition | open |
| NIST800-SA-8(13) | SA-8(13) Security and Privacy Engineering Principles | Minimized Security Elements | SA - System and Services Acquisition | open |
| NIST800-SA-8(14) | SA-8(14) Security and Privacy Engineering Principles | Least Privilege | SA - System and Services Acquisition | open |
| NIST800-SA-8(15) | SA-8(15) Security and Privacy Engineering Principles | Predicate Permission | SA - System and Services Acquisition | open |
| NIST800-SA-8(16) | SA-8(16) Security and Privacy Engineering Principles | Self-reliant Trustworthiness | SA - System and Services Acquisition | open |
| NIST800-SA-8(17) | SA-8(17) Security and Privacy Engineering Principles | Secure Distributed Composition | SA - System and Services Acquisition | open |
| NIST800-SA-8(18) | SA-8(18) Security and Privacy Engineering Principles | Trusted Communications Channels | SA - System and Services Acquisition | open |
| NIST800-SA-8(19) | SA-8(19) Security and Privacy Engineering Principles | Continuous Protection | SA - System and Services Acquisition | open |
| NIST800-SA-8(20) | SA-8(20) Security and Privacy Engineering Principles | Secure Metadata Management | SA - System and Services Acquisition | open |
| NIST800-SA-8(21) | SA-8(21) Security and Privacy Engineering Principles | Self-analysis | SA - System and Services Acquisition | open |
| NIST800-SA-8(22) | SA-8(22) Security and Privacy Engineering Principles | Accountability and Traceability | SA - System and Services Acquisition | open |
| NIST800-SA-8(23) | SA-8(23) Security and Privacy Engineering Principles | Secure Defaults | SA - System and Services Acquisition | open |
| NIST800-SA-8(24) | SA-8(24) Security and Privacy Engineering Principles | Secure Failure and Recovery | SA - System and Services Acquisition | open |
| NIST800-SA-8(25) | SA-8(25) Security and Privacy Engineering Principles | Economic Security | SA - System and Services Acquisition | open |
| NIST800-SA-8(26) | SA-8(26) Security and Privacy Engineering Principles | Performance Security | SA - System and Services Acquisition | open |
| NIST800-SA-8(27) | SA-8(27) Security and Privacy Engineering Principles | Human Factored Security | SA - System and Services Acquisition | open |
| NIST800-SA-8(28) | SA-8(28) Security and Privacy Engineering Principles | Acceptable Security | SA - System and Services Acquisition | open |
| NIST800-SA-8(29) | SA-8(29) Security and Privacy Engineering Principles | Repeatable and Documented Procedures | SA - System and Services Acquisition | open |
| NIST800-SA-8(30) | SA-8(30) Security and Privacy Engineering Principles | Procedural Rigor | SA - System and Services Acquisition | open |
| NIST800-SA-8(31) | SA-8(31) Security and Privacy Engineering Principles | Secure System Modification | SA - System and Services Acquisition | open |
| NIST800-SA-8(32) | SA-8(32) Security and Privacy Engineering Principles | Sufficient Documentation | SA - System and Services Acquisition | open |
| NIST800-SA-8(33) | SA-8(33) Security and Privacy Engineering Principles | Minimization | SA - System and Services Acquisition | open |
| NIST800-SA-9 | SA-9 External System Services | SA - System and Services Acquisition | open |
| NIST800-SA-9(1) | SA-9(1) External System Services | Risk Assessments and Organizational Approvals | SA - System and Services Acquisition | open |
| NIST800-SA-9(2) | SA-9(2) External System Services | Identification of Functions, Ports, Protocols, and Services | SA - System and Services Acquisition | open |
| NIST800-SA-9(3) | SA-9(3) External System Services | Establish and Maintain Trust Relationship with Providers | SA - System and Services Acquisition | open |
| NIST800-SA-9(4) | SA-9(4) External System Services | Consistent Interests of Consumers and Providers | SA - System and Services Acquisition | open |
| NIST800-SA-9(5) | SA-9(5) External System Services | Processing, Storage, and Service Location | SA - System and Services Acquisition | open |
| NIST800-SA-9(6) | SA-9(6) External System Services | Organization-controlled Cryptographic Keys | SA - System and Services Acquisition | open |
| NIST800-SA-9(7) | SA-9(7) External System Services | Organization-controlled Integrity Checking | SA - System and Services Acquisition | open |
| NIST800-SA-9(8) | SA-9(8) External System Services | Processing and Storage Location: U.S. Jurisdiction | SA - System and Services Acquisition | open |
| NIST800-SA-10 | SA-10 Developer Configuration Management | SA - System and Services Acquisition | open |
| NIST800-SA-10(1) | SA-10(1) Developer Configuration Management | Software and Firmware Integrity Verification | SA - System and Services Acquisition | open |
| NIST800-SA-10(2) | SA-10(2) Developer Configuration Management | Alternative Configuration Management Processes | SA - System and Services Acquisition | open |
| NIST800-SA-10(3) | SA-10(3) Developer Configuration Management | Hardware Integrity Verification | SA - System and Services Acquisition | open |
| NIST800-SA-10(4) | SA-10(4) Developer Configuration Management | Trusted Generation | SA - System and Services Acquisition | open |
| NIST800-SA-10(5) | SA-10(5) Developer Configuration Management | Mapping Integrity for Version Control | SA - System and Services Acquisition | open |
| NIST800-SA-10(6) | SA-10(6) Developer Configuration Management | Trusted Distribution | SA - System and Services Acquisition | open |
| NIST800-SA-10(7) | SA-10(7) Developer Configuration Management | Security and Privacy Representatives | SA - System and Services Acquisition | open |
| NIST800-SA-11 | SA-11 Developer Testing and Evaluation | SA - System and Services Acquisition | open |
| NIST800-SA-11(1) | SA-11(1) Developer Testing and Evaluation | Static Code Analysis | SA - System and Services Acquisition | open |
| NIST800-SA-11(2) | SA-11(2) Developer Testing and Evaluation | Threat Modeling and Vulnerability Analyses | SA - System and Services Acquisition | open |
| NIST800-SA-11(3) | SA-11(3) Developer Testing and Evaluation | Independent Verification of Assessment Plans and Evidence | SA - System and Services Acquisition | open |
| NIST800-SA-11(4) | SA-11(4) Developer Testing and Evaluation | Manual Code Reviews | SA - System and Services Acquisition | open |
| NIST800-SA-11(5) | SA-11(5) Developer Testing and Evaluation | Penetration Testing | SA - System and Services Acquisition | open |
| NIST800-SA-11(6) | SA-11(6) Developer Testing and Evaluation | Attack Surface Reviews | SA - System and Services Acquisition | open |
| NIST800-SA-11(7) | SA-11(7) Developer Testing and Evaluation | Verify Scope of Testing and Evaluation | SA - System and Services Acquisition | open |
| NIST800-SA-11(8) | SA-11(8) Developer Testing and Evaluation | Dynamic Code Analysis | SA - System and Services Acquisition | open |
| NIST800-SA-11(9) | SA-11(9) Developer Testing and Evaluation | Interactive Application Security Testing | SA - System and Services Acquisition | open |
| NIST800-SA-15 | SA-15 Development Process, Standards, and Tools | SA - System and Services Acquisition | open |
| NIST800-SA-15(1) | SA-15(1) Development Process, Standards, and Tools | Quality Metrics | SA - System and Services Acquisition | open |
| NIST800-SA-15(2) | SA-15(2) Development Process, Standards, and Tools | Security and Privacy Tracking Tools | SA - System and Services Acquisition | open |
| NIST800-SA-15(3) | SA-15(3) Development Process, Standards, and Tools | Criticality Analysis | SA - System and Services Acquisition | open |
| NIST800-SA-15(5) | SA-15(5) Development Process, Standards, and Tools | Attack Surface Reduction | SA - System and Services Acquisition | open |
| NIST800-SA-15(6) | SA-15(6) Development Process, Standards, and Tools | Continuous Improvement | SA - System and Services Acquisition | open |
| NIST800-SA-15(7) | SA-15(7) Development Process, Standards, and Tools | Automated Vulnerability Analysis | SA - System and Services Acquisition | open |
| NIST800-SA-15(8) | SA-15(8) Development Process, Standards, and Tools | Reuse of Threat and Vulnerability Information | SA - System and Services Acquisition | open |
| NIST800-SA-15(10) | SA-15(10) Development Process, Standards, and Tools | Incident Response Plan | SA - System and Services Acquisition | open |
| NIST800-SA-15(11) | SA-15(11) Development Process, Standards, and Tools | Archive System or Component | SA - System and Services Acquisition | open |
| NIST800-SA-15(12) | SA-15(12) Development Process, Standards, and Tools | Minimize Personally Identifiable Information | SA - System and Services Acquisition | open |
| NIST800-SA-15(13) | SA-15(13) Development Process, Standards, and Tools | Logging Syntax | SA - System and Services Acquisition | open |
| NIST800-SA-16 | SA-16 Developer-provided Training | SA - System and Services Acquisition | open |
| NIST800-SA-17 | SA-17 Developer Security and Privacy Architecture and Design | SA - System and Services Acquisition | open |
| NIST800-SA-17(1) | SA-17(1) Developer Security and Privacy Architecture and Design | Formal Policy Model | SA - System and Services Acquisition | open |
| NIST800-SA-17(2) | SA-17(2) Developer Security and Privacy Architecture and Design | Security-relevant Components | SA - System and Services Acquisition | open |
| NIST800-SA-17(3) | SA-17(3) Developer Security and Privacy Architecture and Design | Formal Correspondence | SA - System and Services Acquisition | open |
| NIST800-SA-17(4) | SA-17(4) Developer Security and Privacy Architecture and Design | Informal Correspondence | SA - System and Services Acquisition | open |
| NIST800-SA-17(5) | SA-17(5) Developer Security and Privacy Architecture and Design | Conceptually Simple Design | SA - System and Services Acquisition | open |
| NIST800-SA-17(6) | SA-17(6) Developer Security and Privacy Architecture and Design | Structure for Testing | SA - System and Services Acquisition | open |
| NIST800-SA-17(7) | SA-17(7) Developer Security and Privacy Architecture and Design | Structure for Least Privilege | SA - System and Services Acquisition | open |
| NIST800-SA-17(8) | SA-17(8) Developer Security and Privacy Architecture and Design | Orchestration | SA - System and Services Acquisition | open |
| NIST800-SA-17(9) | SA-17(9) Developer Security and Privacy Architecture and Design | Design Diversity | SA - System and Services Acquisition | open |
| NIST800-SA-20 | SA-20 Customized Development of Critical Components | SA - System and Services Acquisition | open |
| NIST800-SA-21 | SA-21 Developer Screening | SA - System and Services Acquisition | open |
| NIST800-SA-22 | SA-22 Unsupported System Components | SA - System and Services Acquisition | open |
| NIST800-SA-23 | SA-23 Specialization | SA - System and Services Acquisition | open |
| NIST800-SA-24 | SA-24 Design For Cyber Resiliency | SA - System and Services Acquisition | open |
| NIST800-SC-1 | SC-1 Policy and Procedures | SC - System and Communications Protection | open |
| NIST800-SC-2 | SC-2 Separation of System and User Functionality | SC - System and Communications Protection | open |
| NIST800-SC-2(1) | SC-2(1) Separation of System and User Functionality | Interfaces for Non-privileged Users | SC - System and Communications Protection | open |
| NIST800-SC-2(2) | SC-2(2) Separation of System and User Functionality | Disassociability | SC - System and Communications Protection | open |
| NIST800-SC-3 | SC-3 Security Function Isolation | SC - System and Communications Protection | open |
| NIST800-SC-3(1) | SC-3(1) Security Function Isolation | Hardware Separation | SC - System and Communications Protection | open |
| NIST800-SC-3(2) | SC-3(2) Security Function Isolation | Access and Flow Control Functions | SC - System and Communications Protection | open |
| NIST800-SC-3(3) | SC-3(3) Security Function Isolation | Minimize Nonsecurity Functionality | SC - System and Communications Protection | open |
| NIST800-SC-3(4) | SC-3(4) Security Function Isolation | Module Coupling and Cohesiveness | SC - System and Communications Protection | open |
| NIST800-SC-3(5) | SC-3(5) Security Function Isolation | Layered Structures | SC - System and Communications Protection | open |
| NIST800-SC-4 | SC-4 Information in Shared System Resources | SC - System and Communications Protection | open |
| NIST800-SC-4(2) | SC-4(2) Information in Shared System Resources | Multilevel or Periods Processing | SC - System and Communications Protection | open |
| NIST800-SC-5 | SC-5 Denial-of-service Protection | SC - System and Communications Protection | open |
| NIST800-SC-5(1) | SC-5(1) Denial-of-service Protection | Restrict Ability to Attack Other Systems | SC - System and Communications Protection | open |
| NIST800-SC-5(2) | SC-5(2) Denial-of-service Protection | Capacity, Bandwidth, and Redundancy | SC - System and Communications Protection | open |
| NIST800-SC-5(3) | SC-5(3) Denial-of-service Protection | Detection and Monitoring | SC - System and Communications Protection | open |
| NIST800-SC-6 | SC-6 Resource Availability | SC - System and Communications Protection | open |
| NIST800-SC-7 | SC-7 Boundary Protection | SC - System and Communications Protection | open |
| NIST800-SC-7(3) | SC-7(3) Boundary Protection | Access Points | SC - System and Communications Protection | open |
| NIST800-SC-7(4) | SC-7(4) Boundary Protection | External Telecommunications Services | SC - System and Communications Protection | open |
| NIST800-SC-7(5) | SC-7(5) Boundary Protection | Deny by Default: Allow by Exception | SC - System and Communications Protection | open |
| NIST800-SC-7(7) | SC-7(7) Boundary Protection | Split Tunneling for Remote Devices | SC - System and Communications Protection | open |
| NIST800-SC-7(8) | SC-7(8) Boundary Protection | Route Traffic to Authenticated Proxy Servers | SC - System and Communications Protection | open |
| NIST800-SC-7(9) | SC-7(9) Boundary Protection | Restrict Threatening Outgoing Communications Traffic | SC - System and Communications Protection | open |
| NIST800-SC-7(10) | SC-7(10) Boundary Protection | Prevent Exfiltration | SC - System and Communications Protection | open |
| NIST800-SC-7(11) | SC-7(11) Boundary Protection | Restrict Incoming Communications Traffic | SC - System and Communications Protection | open |
| NIST800-SC-7(12) | SC-7(12) Boundary Protection | Host-based Protection | SC - System and Communications Protection | open |
| NIST800-SC-7(13) | SC-7(13) Boundary Protection | Isolation of Security Tools, Mechanisms, and Support Components | SC - System and Communications Protection | open |
| NIST800-SC-7(14) | SC-7(14) Boundary Protection | Protect Against Unauthorized Physical Connections | SC - System and Communications Protection | open |
| NIST800-SC-7(15) | SC-7(15) Boundary Protection | Networked Privileged Accesses | SC - System and Communications Protection | open |
| NIST800-SC-7(16) | SC-7(16) Boundary Protection | Prevent Discovery of System Components | SC - System and Communications Protection | open |
| NIST800-SC-7(17) | SC-7(17) Boundary Protection | Automated Enforcement of Protocol Formats | SC - System and Communications Protection | open |
| NIST800-SC-7(18) | SC-7(18) Boundary Protection | Fail Secure | SC - System and Communications Protection | open |
| NIST800-SC-7(19) | SC-7(19) Boundary Protection | Block Communication from Non-organizationally Configured Hosts | SC - System and Communications Protection | open |
| NIST800-SC-7(20) | SC-7(20) Boundary Protection | Dynamic Isolation and Segregation | SC - System and Communications Protection | open |
| NIST800-SC-7(21) | SC-7(21) Boundary Protection | Isolation of System Components | SC - System and Communications Protection | open |
| NIST800-SC-7(22) | SC-7(22) Boundary Protection | Separate Subnets for Connecting to Different Security Domains | SC - System and Communications Protection | open |
| NIST800-SC-7(23) | SC-7(23) Boundary Protection | Disable Sender Feedback on Protocol Validation Failure | SC - System and Communications Protection | open |
| NIST800-SC-7(24) | SC-7(24) Boundary Protection | Personally Identifiable Information | SC - System and Communications Protection | open |
| NIST800-SC-7(25) | SC-7(25) Boundary Protection | Unclassified National Security System Connections | SC - System and Communications Protection | open |
| NIST800-SC-7(26) | SC-7(26) Boundary Protection | Classified National Security System Connections | SC - System and Communications Protection | open |
| NIST800-SC-7(27) | SC-7(27) Boundary Protection | Unclassified Non-national Security System Connections | SC - System and Communications Protection | open |
| NIST800-SC-7(28) | SC-7(28) Boundary Protection | Connections to Public Networks | SC - System and Communications Protection | open |
| NIST800-SC-7(29) | SC-7(29) Boundary Protection | Separate Subnets to Isolate Functions | SC - System and Communications Protection | open |
| NIST800-SC-8 | SC-8 Transmission Confidentiality and Integrity | SC - System and Communications Protection | open |
| NIST800-SC-8(1) | SC-8(1) Transmission Confidentiality and Integrity | Cryptographic Protection | SC - System and Communications Protection | open |
| NIST800-SC-8(2) | SC-8(2) Transmission Confidentiality and Integrity | Pre- and Post-transmission Handling | SC - System and Communications Protection | open |
| NIST800-SC-8(3) | SC-8(3) Transmission Confidentiality and Integrity | Cryptographic Protection for Message Externals | SC - System and Communications Protection | open |
| NIST800-SC-8(4) | SC-8(4) Transmission Confidentiality and Integrity | Conceal or Randomize Communications | SC - System and Communications Protection | open |
| NIST800-SC-8(5) | SC-8(5) Transmission Confidentiality and Integrity | Protected Distribution System | SC - System and Communications Protection | open |
| NIST800-SC-10 | SC-10 Network Disconnect | SC - System and Communications Protection | open |
| NIST800-SC-11 | SC-11 Trusted Path | SC - System and Communications Protection | open |
| NIST800-SC-11(1) | SC-11(1) Trusted Path | Irrefutable Communications Path | SC - System and Communications Protection | open |
| NIST800-SC-12 | SC-12 Cryptographic Key Establishment and Management | SC - System and Communications Protection | open |
| NIST800-SC-12(1) | SC-12(1) Cryptographic Key Establishment and Management | Availability | SC - System and Communications Protection | open |
| NIST800-SC-12(2) | SC-12(2) Cryptographic Key Establishment and Management | Symmetric Keys | SC - System and Communications Protection | open |
| NIST800-SC-12(3) | SC-12(3) Cryptographic Key Establishment and Management | Asymmetric Keys | SC - System and Communications Protection | open |
| NIST800-SC-12(6) | SC-12(6) Cryptographic Key Establishment and Management | Physical Control of Keys | SC - System and Communications Protection | open |
| NIST800-SC-13 | SC-13 Cryptographic Protection | SC - System and Communications Protection | open |
| NIST800-SC-15 | SC-15 Collaborative Computing Devices and Applications | SC - System and Communications Protection | open |
| NIST800-SC-15(1) | SC-15(1) Collaborative Computing Devices and Applications | Physical or Logical Disconnect | SC - System and Communications Protection | open |
| NIST800-SC-15(3) | SC-15(3) Collaborative Computing Devices and Applications | Disabling and Removal in Secure Work Areas | SC - System and Communications Protection | open |
| NIST800-SC-15(4) | SC-15(4) Collaborative Computing Devices and Applications | Explicitly Indicate Current Participants | SC - System and Communications Protection | open |
| NIST800-SC-16 | SC-16 Transmission of Security and Privacy Attributes | SC - System and Communications Protection | open |
| NIST800-SC-16(1) | SC-16(1) Transmission of Security and Privacy Attributes | Integrity Verification | SC - System and Communications Protection | open |
| NIST800-SC-16(2) | SC-16(2) Transmission of Security and Privacy Attributes | Anti-spoofing Mechanisms | SC - System and Communications Protection | open |
| NIST800-SC-16(3) | SC-16(3) Transmission of Security and Privacy Attributes | Cryptographic Binding | SC - System and Communications Protection | open |
| NIST800-SC-17 | SC-17 Public Key Infrastructure Certificates | SC - System and Communications Protection | open |
| NIST800-SC-18 | SC-18 Mobile Code | SC - System and Communications Protection | open |
| NIST800-SC-18(1) | SC-18(1) Mobile Code | Identify Unacceptable Code and Take Corrective Actions | SC - System and Communications Protection | open |
| NIST800-SC-18(2) | SC-18(2) Mobile Code | Acquisition, Development, and Use | SC - System and Communications Protection | open |
| NIST800-SC-18(3) | SC-18(3) Mobile Code | Prevent Downloading and Execution | SC - System and Communications Protection | open |
| NIST800-SC-18(4) | SC-18(4) Mobile Code | Prevent Automatic Execution | SC - System and Communications Protection | open |
| NIST800-SC-18(5) | SC-18(5) Mobile Code | Allow Execution Only in Confined Environments | SC - System and Communications Protection | open |
| NIST800-SC-20 | SC-20 Secure Name/Address Resolution Service (Authoritative Source) | SC - System and Communications Protection | open |
| NIST800-SC-20(2) | SC-20(2) Secure Name/Address Resolution Service (Authoritative Source) | Data Origin and Integrity | SC - System and Communications Protection | open |
| NIST800-SC-21 | SC-21 Secure Name/Address Resolution Service (Recursive or Caching Resolver) | SC - System and Communications Protection | open |
| NIST800-SC-22 | SC-22 Architecture and Provisioning for Name/Address Resolution Service | SC - System and Communications Protection | open |
| NIST800-SC-23 | SC-23 Session Authenticity | SC - System and Communications Protection | open |
| NIST800-SC-23(1) | SC-23(1) Session Authenticity | Invalidate Session Identifiers at Logout | SC - System and Communications Protection | open |
| NIST800-SC-23(3) | SC-23(3) Session Authenticity | Unique System-generated Session Identifiers | SC - System and Communications Protection | open |
| NIST800-SC-23(5) | SC-23(5) Session Authenticity | Allowed Certificate Authorities | SC - System and Communications Protection | open |
| NIST800-SC-24 | SC-24 Fail in Known State | SC - System and Communications Protection | open |
| NIST800-SC-25 | SC-25 Thin Nodes | SC - System and Communications Protection | open |
| NIST800-SC-26 | SC-26 Decoys | SC - System and Communications Protection | open |
| NIST800-SC-27 | SC-27 Platform-independent Applications | SC - System and Communications Protection | open |
| NIST800-SC-28 | SC-28 Protection of Information at Rest | SC - System and Communications Protection | open |
| NIST800-SC-28(1) | SC-28(1) Protection of Information at Rest | Cryptographic Protection | SC - System and Communications Protection | open |
| NIST800-SC-28(2) | SC-28(2) Protection of Information at Rest | Offline Storage | SC - System and Communications Protection | open |
| NIST800-SC-28(3) | SC-28(3) Protection of Information at Rest | Cryptographic Keys | SC - System and Communications Protection | open |
| NIST800-SC-29 | SC-29 Heterogeneity | SC - System and Communications Protection | open |
| NIST800-SC-29(1) | SC-29(1) Heterogeneity | Virtualization Techniques | SC - System and Communications Protection | open |
| NIST800-SC-30 | SC-30 Concealment and Misdirection | SC - System and Communications Protection | open |
| NIST800-SC-30(2) | SC-30(2) Concealment and Misdirection | Randomness | SC - System and Communications Protection | open |
| NIST800-SC-30(3) | SC-30(3) Concealment and Misdirection | Change Processing and Storage Locations | SC - System and Communications Protection | open |
| NIST800-SC-30(4) | SC-30(4) Concealment and Misdirection | Misleading Information | SC - System and Communications Protection | open |
| NIST800-SC-30(5) | SC-30(5) Concealment and Misdirection | Concealment of System Components | SC - System and Communications Protection | open |
| NIST800-SC-31 | SC-31 Covert Channel Analysis | SC - System and Communications Protection | open |
| NIST800-SC-31(1) | SC-31(1) Covert Channel Analysis | Test Covert Channels for Exploitability | SC - System and Communications Protection | open |
| NIST800-SC-31(2) | SC-31(2) Covert Channel Analysis | Maximum Bandwidth | SC - System and Communications Protection | open |
| NIST800-SC-31(3) | SC-31(3) Covert Channel Analysis | Measure Bandwidth in Operational Environments | SC - System and Communications Protection | open |
| NIST800-SC-32 | SC-32 System Partitioning | SC - System and Communications Protection | open |
| NIST800-SC-32(1) | SC-32(1) System Partitioning | Separate Physical Domains for Privileged Functions | SC - System and Communications Protection | open |
| NIST800-SC-34 | SC-34 Non-modifiable Executable Programs | SC - System and Communications Protection | open |
| NIST800-SC-34(1) | SC-34(1) Non-modifiable Executable Programs | No Writable Storage | SC - System and Communications Protection | open |
| NIST800-SC-34(2) | SC-34(2) Non-modifiable Executable Programs | Integrity Protection on Read-only Media | SC - System and Communications Protection | open |
| NIST800-SC-35 | SC-35 External Malicious Code Identification | SC - System and Communications Protection | open |
| NIST800-SC-36 | SC-36 Distributed Processing and Storage | SC - System and Communications Protection | open |
| NIST800-SC-36(1) | SC-36(1) Distributed Processing and Storage | Polling Techniques | SC - System and Communications Protection | open |
| NIST800-SC-36(2) | SC-36(2) Distributed Processing and Storage | Synchronization | SC - System and Communications Protection | open |
| NIST800-SC-37 | SC-37 Out-of-band Channels | SC - System and Communications Protection | open |
| NIST800-SC-37(1) | SC-37(1) Out-of-band Channels | Ensure Delivery and Transmission | SC - System and Communications Protection | open |
| NIST800-SC-38 | SC-38 Operations Security | SC - System and Communications Protection | open |
| NIST800-SC-39 | SC-39 Process Isolation | SC - System and Communications Protection | open |
| NIST800-SC-39(1) | SC-39(1) Process Isolation | Hardware Separation | SC - System and Communications Protection | open |
| NIST800-SC-39(2) | SC-39(2) Process Isolation | Separate Execution Domain Per Thread | SC - System and Communications Protection | open |
| NIST800-SC-40 | SC-40 Wireless Link Protection | SC - System and Communications Protection | open |
| NIST800-SC-40(1) | SC-40(1) Wireless Link Protection | Electromagnetic Interference | SC - System and Communications Protection | open |
| NIST800-SC-40(2) | SC-40(2) Wireless Link Protection | Reduce Detection Potential | SC - System and Communications Protection | open |
| NIST800-SC-40(3) | SC-40(3) Wireless Link Protection | Imitative or Manipulative Communications Deception | SC - System and Communications Protection | open |
| NIST800-SC-40(4) | SC-40(4) Wireless Link Protection | Signal Parameter Identification | SC - System and Communications Protection | open |
| NIST800-SC-41 | SC-41 Port and I/O Device Access | SC - System and Communications Protection | open |
| NIST800-SC-42 | SC-42 Sensor Capability and Data | SC - System and Communications Protection | open |
| NIST800-SC-42(1) | SC-42(1) Sensor Capability and Data | Reporting to Authorized Individuals or Roles | SC - System and Communications Protection | open |
| NIST800-SC-42(2) | SC-42(2) Sensor Capability and Data | Authorized Use | SC - System and Communications Protection | open |
| NIST800-SC-42(4) | SC-42(4) Sensor Capability and Data | Notice of Collection | SC - System and Communications Protection | open |
| NIST800-SC-42(5) | SC-42(5) Sensor Capability and Data | Collection Minimization | SC - System and Communications Protection | open |
| NIST800-SC-43 | SC-43 Usage Restrictions | SC - System and Communications Protection | open |
| NIST800-SC-44 | SC-44 Detonation Chambers | SC - System and Communications Protection | open |
| NIST800-SC-45 | SC-45 System Time Synchronization | SC - System and Communications Protection | open |
| NIST800-SC-45(1) | SC-45(1) System Time Synchronization | Synchronization with Authoritative Time Source | SC - System and Communications Protection | open |
| NIST800-SC-45(2) | SC-45(2) System Time Synchronization | Secondary Authoritative Time Source | SC - System and Communications Protection | open |
| NIST800-SC-46 | SC-46 Cross Domain Policy Enforcement | SC - System and Communications Protection | open |
| NIST800-SC-47 | SC-47 Alternate Communications Paths | SC - System and Communications Protection | open |
| NIST800-SC-48 | SC-48 Sensor Relocation | SC - System and Communications Protection | open |
| NIST800-SC-48(1) | SC-48(1) Sensor Relocation | Dynamic Relocation of Sensors or Monitoring Capabilities | SC - System and Communications Protection | open |
| NIST800-SC-49 | SC-49 Hardware-enforced Separation and Policy Enforcement | SC - System and Communications Protection | open |
| NIST800-SC-50 | SC-50 Software-enforced Separation and Policy Enforcement | SC - System and Communications Protection | open |
| NIST800-SC-51 | SC-51 Hardware-based Protection | SC - System and Communications Protection | open |
| NIST800-SI-1 | SI-1 Policy and Procedures | SI - System and Information Integrity | open |
| NIST800-SI-2 | SI-2 Flaw Remediation | SI - System and Information Integrity | open |
| NIST800-SI-2(2) | SI-2(2) Flaw Remediation | Automated Flaw Remediation Status | SI - System and Information Integrity | open |
| NIST800-SI-2(3) | SI-2(3) Flaw Remediation | Time to Remediate Flaws and Benchmarks for Corrective Actions | SI - System and Information Integrity | open |
| NIST800-SI-2(4) | SI-2(4) Flaw Remediation | Automated Patch Management Tools | SI - System and Information Integrity | open |
| NIST800-SI-2(5) | SI-2(5) Flaw Remediation | Automatic Software and Firmware Updates | SI - System and Information Integrity | open |
| NIST800-SI-2(6) | SI-2(6) Flaw Remediation | Removal of Previous Versions of Software and Firmware | SI - System and Information Integrity | open |
| NIST800-SI-2(7) | SI-2(7) Flaw Remediation | Root Cause Analysis | SI - System and Information Integrity | open |
| NIST800-SI-3 | SI-3 Malicious Code Protection | SI - System and Information Integrity | open |
| NIST800-SI-3(4) | SI-3(4) Malicious Code Protection | Updates Only by Privileged Users | SI - System and Information Integrity | open |
| NIST800-SI-3(6) | SI-3(6) Malicious Code Protection | Testing and Verification | SI - System and Information Integrity | open |
| NIST800-SI-3(8) | SI-3(8) Malicious Code Protection | Detect Unauthorized Commands | SI - System and Information Integrity | open |
| NIST800-SI-3(10) | SI-3(10) Malicious Code Protection | Malicious Code Analysis | SI - System and Information Integrity | open |
| NIST800-SI-4 | SI-4 System Monitoring | SI - System and Information Integrity | open |
| NIST800-SI-4(1) | SI-4(1) System Monitoring | System-wide Intrusion Detection System | SI - System and Information Integrity | open |
| NIST800-SI-4(2) | SI-4(2) System Monitoring | Automated Tools and Mechanisms for Real-time Analysis | SI - System and Information Integrity | open |
| NIST800-SI-4(3) | SI-4(3) System Monitoring | Automated Tool and Mechanism Integration | SI - System and Information Integrity | open |
| NIST800-SI-4(4) | SI-4(4) System Monitoring | Inbound and Outbound Communications Traffic | SI - System and Information Integrity | open |
| NIST800-SI-4(5) | SI-4(5) System Monitoring | System-generated Alerts | SI - System and Information Integrity | open |
| NIST800-SI-4(7) | SI-4(7) System Monitoring | Automated Response to Suspicious Events | SI - System and Information Integrity | open |
| NIST800-SI-4(9) | SI-4(9) System Monitoring | Testing of Monitoring Tools and Mechanisms | SI - System and Information Integrity | open |
| NIST800-SI-4(10) | SI-4(10) System Monitoring | Visibility of Encrypted Communications | SI - System and Information Integrity | open |
| NIST800-SI-4(11) | SI-4(11) System Monitoring | Analyze Communications Traffic Anomalies | SI - System and Information Integrity | open |
| NIST800-SI-4(12) | SI-4(12) System Monitoring | Automated Organization-generated Alerts | SI - System and Information Integrity | open |
| NIST800-SI-4(13) | SI-4(13) System Monitoring | Analyze Traffic and Event Patterns | SI - System and Information Integrity | open |
| NIST800-SI-4(14) | SI-4(14) System Monitoring | Wireless Intrusion Detection | SI - System and Information Integrity | open |
| NIST800-SI-4(15) | SI-4(15) System Monitoring | Wireless to Wireline Communications | SI - System and Information Integrity | open |
| NIST800-SI-4(16) | SI-4(16) System Monitoring | Correlate Monitoring Information | SI - System and Information Integrity | open |
| NIST800-SI-4(17) | SI-4(17) System Monitoring | Integrated Situational Awareness | SI - System and Information Integrity | open |
| NIST800-SI-4(18) | SI-4(18) System Monitoring | Analyze Traffic and Covert Exfiltration | SI - System and Information Integrity | open |
| NIST800-SI-4(19) | SI-4(19) System Monitoring | Risk for Individuals | SI - System and Information Integrity | open |
| NIST800-SI-4(20) | SI-4(20) System Monitoring | Privileged Users | SI - System and Information Integrity | open |
| NIST800-SI-4(21) | SI-4(21) System Monitoring | Probationary Periods | SI - System and Information Integrity | open |
| NIST800-SI-4(22) | SI-4(22) System Monitoring | Unauthorized Network Services | SI - System and Information Integrity | open |
| NIST800-SI-4(23) | SI-4(23) System Monitoring | Host-based Devices | SI - System and Information Integrity | open |
| NIST800-SI-4(24) | SI-4(24) System Monitoring | Indicators of Compromise | SI - System and Information Integrity | open |
| NIST800-SI-4(25) | SI-4(25) System Monitoring | Optimize Network Traffic Analysis | SI - System and Information Integrity | open |
| NIST800-SI-5 | SI-5 Security Alerts, Advisories, and Directives | SI - System and Information Integrity | open |
| NIST800-SI-5(1) | SI-5(1) Security Alerts, Advisories, and Directives | Automated Alerts and Advisories | SI - System and Information Integrity | open |
| NIST800-SI-6 | SI-6 Security and Privacy Function Verification | SI - System and Information Integrity | open |
| NIST800-SI-6(2) | SI-6(2) Security and Privacy Function Verification | Automation Support for Distributed Testing | SI - System and Information Integrity | open |
| NIST800-SI-6(3) | SI-6(3) Security and Privacy Function Verification | Report Verification Results | SI - System and Information Integrity | open |
| NIST800-SI-7 | SI-7 Software, Firmware, and Information Integrity | SI - System and Information Integrity | open |
| NIST800-SI-7(1) | SI-7(1) Software, Firmware, and Information Integrity | Integrity Checks | SI - System and Information Integrity | open |
| NIST800-SI-7(2) | SI-7(2) Software, Firmware, and Information Integrity | Automated Notifications of Integrity Violations | SI - System and Information Integrity | open |
| NIST800-SI-7(3) | SI-7(3) Software, Firmware, and Information Integrity | Centrally Managed Integrity Tools | SI - System and Information Integrity | open |
| NIST800-SI-7(5) | SI-7(5) Software, Firmware, and Information Integrity | Automated Response to Integrity Violations | SI - System and Information Integrity | open |
| NIST800-SI-7(6) | SI-7(6) Software, Firmware, and Information Integrity | Cryptographic Protection | SI - System and Information Integrity | open |
| NIST800-SI-7(7) | SI-7(7) Software, Firmware, and Information Integrity | Integration of Detection and Response | SI - System and Information Integrity | open |
| NIST800-SI-7(8) | SI-7(8) Software, Firmware, and Information Integrity | Auditing Capability for Significant Events | SI - System and Information Integrity | open |
| NIST800-SI-7(9) | SI-7(9) Software, Firmware, and Information Integrity | Verify Boot Process | SI - System and Information Integrity | open |
| NIST800-SI-7(10) | SI-7(10) Software, Firmware, and Information Integrity | Protection of Boot Firmware | SI - System and Information Integrity | open |
| NIST800-SI-7(12) | SI-7(12) Software, Firmware, and Information Integrity | Integrity Verification | SI - System and Information Integrity | open |
| NIST800-SI-7(15) | SI-7(15) Software, Firmware, and Information Integrity | Code Authentication | SI - System and Information Integrity | open |
| NIST800-SI-7(16) | SI-7(16) Software, Firmware, and Information Integrity | Time Limit on Process Execution Without Supervision | SI - System and Information Integrity | open |
| NIST800-SI-7(17) | SI-7(17) Software, Firmware, and Information Integrity | Runtime Application Self-protection | SI - System and Information Integrity | open |
| NIST800-SI-8 | SI-8 Spam Protection | SI - System and Information Integrity | open |
| NIST800-SI-8(2) | SI-8(2) Spam Protection | Automatic Updates | SI - System and Information Integrity | open |
| NIST800-SI-8(3) | SI-8(3) Spam Protection | Continuous Learning Capability | SI - System and Information Integrity | open |
| NIST800-SI-10 | SI-10 Information Input Validation | SI - System and Information Integrity | open |
| NIST800-SI-10(1) | SI-10(1) Information Input Validation | Manual Override Capability | SI - System and Information Integrity | open |
| NIST800-SI-10(2) | SI-10(2) Information Input Validation | Review and Resolve Errors | SI - System and Information Integrity | open |
| NIST800-SI-10(3) | SI-10(3) Information Input Validation | Predictable Behavior | SI - System and Information Integrity | open |
| NIST800-SI-10(4) | SI-10(4) Information Input Validation | Timing Interactions | SI - System and Information Integrity | open |
| NIST800-SI-10(5) | SI-10(5) Information Input Validation | Restrict Inputs to Trusted Sources and Approved Formats | SI - System and Information Integrity | open |
| NIST800-SI-10(6) | SI-10(6) Information Input Validation | Injection Prevention | SI - System and Information Integrity | open |
| NIST800-SI-11 | SI-11 Error Handling | SI - System and Information Integrity | open |
| NIST800-SI-12 | SI-12 Information Management and Retention | SI - System and Information Integrity | open |
| NIST800-SI-12(1) | SI-12(1) Information Management and Retention | Limit Personally Identifiable Information Elements | SI - System and Information Integrity | open |
| NIST800-SI-12(2) | SI-12(2) Information Management and Retention | Minimize Personally Identifiable Information in Testing, Training, and Research | SI - System and Information Integrity | open |
| NIST800-SI-12(3) | SI-12(3) Information Management and Retention | Information Disposal | SI - System and Information Integrity | open |
| NIST800-SI-13 | SI-13 Predictable Failure Prevention | SI - System and Information Integrity | open |
| NIST800-SI-13(1) | SI-13(1) Predictable Failure Prevention | Transferring Component Responsibilities | SI - System and Information Integrity | open |
| NIST800-SI-13(3) | SI-13(3) Predictable Failure Prevention | Manual Transfer Between Components | SI - System and Information Integrity | open |
| NIST800-SI-13(4) | SI-13(4) Predictable Failure Prevention | Standby Component Installation and Notification | SI - System and Information Integrity | open |
| NIST800-SI-13(5) | SI-13(5) Predictable Failure Prevention | Failover Capability | SI - System and Information Integrity | open |
| NIST800-SI-14 | SI-14 Non-persistence | SI - System and Information Integrity | open |
| NIST800-SI-14(1) | SI-14(1) Non-persistence | Refresh from Trusted Sources | SI - System and Information Integrity | open |
| NIST800-SI-14(2) | SI-14(2) Non-persistence | Non-persistent Information | SI - System and Information Integrity | open |
| NIST800-SI-14(3) | SI-14(3) Non-persistence | Non-persistent Connectivity | SI - System and Information Integrity | open |
| NIST800-SI-15 | SI-15 Information Output Filtering | SI - System and Information Integrity | open |
| NIST800-SI-16 | SI-16 Memory Protection | SI - System and Information Integrity | open |
| NIST800-SI-17 | SI-17 Fail-safe Procedures | SI - System and Information Integrity | open |
| NIST800-SI-18 | SI-18 Personally Identifiable Information Quality Operations | SI - System and Information Integrity | open |
| NIST800-SI-18(1) | SI-18(1) Personally Identifiable Information Quality Operations | Automation Support | SI - System and Information Integrity | open |
| NIST800-SI-18(2) | SI-18(2) Personally Identifiable Information Quality Operations | Data Tags | SI - System and Information Integrity | open |
| NIST800-SI-18(3) | SI-18(3) Personally Identifiable Information Quality Operations | Collection | SI - System and Information Integrity | open |
| NIST800-SI-18(4) | SI-18(4) Personally Identifiable Information Quality Operations | Individual Requests | SI - System and Information Integrity | open |
| NIST800-SI-18(5) | SI-18(5) Personally Identifiable Information Quality Operations | Notice of Correction or Deletion | SI - System and Information Integrity | open |
| NIST800-SI-19 | SI-19 De-identification | SI - System and Information Integrity | open |
| NIST800-SI-19(1) | SI-19(1) De-identification | Collection | SI - System and Information Integrity | open |
| NIST800-SI-19(2) | SI-19(2) De-identification | Archiving | SI - System and Information Integrity | open |
| NIST800-SI-19(3) | SI-19(3) De-identification | Release | SI - System and Information Integrity | open |
| NIST800-SI-19(4) | SI-19(4) De-identification | Removal, Masking, Encryption, Hashing, or Replacement of Direct Identifiers | SI - System and Information Integrity | open |
| NIST800-SI-19(5) | SI-19(5) De-identification | Statistical Disclosure Control | SI - System and Information Integrity | open |
| NIST800-SI-19(6) | SI-19(6) De-identification | Differential Privacy | SI - System and Information Integrity | open |
| NIST800-SI-19(7) | SI-19(7) De-identification | Validated Algorithms and Software | SI - System and Information Integrity | open |
| NIST800-SI-19(8) | SI-19(8) De-identification | Motivated Intruder | SI - System and Information Integrity | open |
| NIST800-SI-20 | SI-20 Tainting | SI - System and Information Integrity | open |
| NIST800-SI-21 | SI-21 Information Refresh | SI - System and Information Integrity | open |
| NIST800-SI-22 | SI-22 Information Diversity | SI - System and Information Integrity | open |
| NIST800-SI-23 | SI-23 Information Fragmentation | SI - System and Information Integrity | open |
| NIST800-SR-1 | SR-1 Policy and Procedures | SR - Supply Chain Risk Management | open |
| NIST800-SR-2 | SR-2 Supply Chain Risk Management Plan | SR - Supply Chain Risk Management | open |
| NIST800-SR-2(1) | SR-2(1) Supply Chain Risk Management Plan | Establish SCRM Team | SR - Supply Chain Risk Management | open |
| NIST800-SR-3 | SR-3 Supply Chain Controls and Processes | SR - Supply Chain Risk Management | open |
| NIST800-SR-3(1) | SR-3(1) Supply Chain Controls and Processes | Diverse Supply Base | SR - Supply Chain Risk Management | open |
| NIST800-SR-3(2) | SR-3(2) Supply Chain Controls and Processes | Limitation of Harm | SR - Supply Chain Risk Management | open |
| NIST800-SR-3(3) | SR-3(3) Supply Chain Controls and Processes | Sub-tier Flow Down | SR - Supply Chain Risk Management | open |
| NIST800-SR-4 | SR-4 Provenance | SR - Supply Chain Risk Management | open |
| NIST800-SR-4(1) | SR-4(1) Provenance | Identity | SR - Supply Chain Risk Management | open |
| NIST800-SR-4(2) | SR-4(2) Provenance | Track and Trace | SR - Supply Chain Risk Management | open |
| NIST800-SR-4(3) | SR-4(3) Provenance | Validate as Genuine and Not Altered | SR - Supply Chain Risk Management | open |
| NIST800-SR-4(4) | SR-4(4) Provenance | Supply Chain Integrity: Pedigree | SR - Supply Chain Risk Management | open |
| NIST800-SR-5 | SR-5 Acquisition Strategies, Tools, and Methods | SR - Supply Chain Risk Management | open |
| NIST800-SR-5(1) | SR-5(1) Acquisition Strategies, Tools, and Methods | Adequate Supply | SR - Supply Chain Risk Management | open |
| NIST800-SR-5(2) | SR-5(2) Acquisition Strategies, Tools, and Methods | Assessments Prior to Selection, Acceptance, Modification, or Update | SR - Supply Chain Risk Management | open |
| NIST800-SR-6 | SR-6 Supplier Assessments and Reviews | SR - Supply Chain Risk Management | open |
| NIST800-SR-6(1) | SR-6(1) Supplier Assessments and Reviews | Testing and Analysis | SR - Supply Chain Risk Management | open |
| NIST800-SR-7 | SR-7 Supply Chain Operations Security | SR - Supply Chain Risk Management | open |
| NIST800-SR-8 | SR-8 Notification Agreements | SR - Supply Chain Risk Management | open |
| NIST800-SR-9 | SR-9 Tamper Resistance and Detection | SR - Supply Chain Risk Management | open |
| NIST800-SR-9(1) | SR-9(1) Tamper Resistance and Detection | Multiple Stages of System Development Life Cycle | SR - Supply Chain Risk Management | open |
| NIST800-SR-10 | SR-10 Inspection of Systems or Components | SR - Supply Chain Risk Management | open |
| NIST800-SR-11 | SR-11 Component Authenticity | SR - Supply Chain Risk Management | open |
| NIST800-SR-11(1) | SR-11(1) Component Authenticity | Anti-counterfeit Training | SR - Supply Chain Risk Management | open |
| NIST800-SR-11(2) | SR-11(2) Component Authenticity | Configuration Control for Component Service and Repair | SR - Supply Chain Risk Management | open |
| NIST800-SR-11(3) | SR-11(3) Component Authenticity | Anti-counterfeit Scanning | SR - Supply Chain Risk Management | open |
| NIST800-SR-12 | SR-12 Component Disposal | SR - Supply Chain Risk Management | open |