Control Mapping Readerplace a control, see the map

NIST SP 800-53 Rev 5 controls

1014 controls held for NIST SP 800-53 Rev 5 (NIST). Edition: NIST SP 800-53 Rev 5, Release 5.2.0. Place a control statement and the reader picks the closest text here and the closest matches in the other frameworks. Open NIST SP 800-53 Rev 5 on the standards site.

CodeControlDomain
NIST800-AC-1AC-1 Policy and ProceduresAC - Access Controlopen
NIST800-AC-2AC-2 Account ManagementAC - Access Controlopen
NIST800-AC-2(1)AC-2(1) Account Management | Automated System Account ManagementAC - Access Controlopen
NIST800-AC-2(2)AC-2(2) Account Management | Automated Temporary and Emergency Account ManagementAC - Access Controlopen
NIST800-AC-2(3)AC-2(3) Account Management | Disable AccountsAC - Access Controlopen
NIST800-AC-2(4)AC-2(4) Account Management | Automated Audit ActionsAC - Access Controlopen
NIST800-AC-2(5)AC-2(5) Account Management | Inactivity LogoutAC - Access Controlopen
NIST800-AC-2(6)AC-2(6) Account Management | Dynamic Privilege ManagementAC - Access Controlopen
NIST800-AC-2(7)AC-2(7) Account Management | Privileged User AccountsAC - Access Controlopen
NIST800-AC-2(8)AC-2(8) Account Management | Dynamic Account ManagementAC - Access Controlopen
NIST800-AC-2(9)AC-2(9) Account Management | Restrictions on Use of Shared and Group AccountsAC - Access Controlopen
NIST800-AC-2(11)AC-2(11) Account Management | Usage ConditionsAC - Access Controlopen
NIST800-AC-2(12)AC-2(12) Account Management | Account Monitoring for Atypical UsageAC - Access Controlopen
NIST800-AC-2(13)AC-2(13) Account Management | Disable Accounts for High-risk IndividualsAC - Access Controlopen
NIST800-AC-3AC-3 Access EnforcementAC - Access Controlopen
NIST800-AC-3(2)AC-3(2) Access Enforcement | Dual AuthorizationAC - Access Controlopen
NIST800-AC-3(3)AC-3(3) Access Enforcement | Mandatory Access ControlAC - Access Controlopen
NIST800-AC-3(4)AC-3(4) Access Enforcement | Discretionary Access ControlAC - Access Controlopen
NIST800-AC-3(5)AC-3(5) Access Enforcement | Security-relevant InformationAC - Access Controlopen
NIST800-AC-3(7)AC-3(7) Access Enforcement | Role-based Access ControlAC - Access Controlopen
NIST800-AC-3(8)AC-3(8) Access Enforcement | Revocation of Access AuthorizationsAC - Access Controlopen
NIST800-AC-3(9)AC-3(9) Access Enforcement | Controlled ReleaseAC - Access Controlopen
NIST800-AC-3(10)AC-3(10) Access Enforcement | Audited Override of Access Control MechanismsAC - Access Controlopen
NIST800-AC-3(11)AC-3(11) Access Enforcement | Restrict Access to Specific Information TypesAC - Access Controlopen
NIST800-AC-3(12)AC-3(12) Access Enforcement | Assert and Enforce Application AccessAC - Access Controlopen
NIST800-AC-3(13)AC-3(13) Access Enforcement | Attribute-based Access ControlAC - Access Controlopen
NIST800-AC-3(14)AC-3(14) Access Enforcement | Individual AccessAC - Access Controlopen
NIST800-AC-3(15)AC-3(15) Access Enforcement | Discretionary and Mandatory Access ControlAC - Access Controlopen
NIST800-AC-4AC-4 Information Flow EnforcementAC - Access Controlopen
NIST800-AC-4(1)AC-4(1) Information Flow Enforcement | Object Security and Privacy AttributesAC - Access Controlopen
NIST800-AC-4(2)AC-4(2) Information Flow Enforcement | Processing DomainsAC - Access Controlopen
NIST800-AC-4(3)AC-4(3) Information Flow Enforcement | Dynamic Information Flow ControlAC - Access Controlopen
NIST800-AC-4(4)AC-4(4) Information Flow Enforcement | Flow Control of Encrypted InformationAC - Access Controlopen
NIST800-AC-4(5)AC-4(5) Information Flow Enforcement | Embedded Data TypesAC - Access Controlopen
NIST800-AC-4(6)AC-4(6) Information Flow Enforcement | MetadataAC - Access Controlopen
NIST800-AC-4(7)AC-4(7) Information Flow Enforcement | One-way Flow MechanismsAC - Access Controlopen
NIST800-AC-4(8)AC-4(8) Information Flow Enforcement | Security and Privacy Policy FiltersAC - Access Controlopen
NIST800-AC-4(9)AC-4(9) Information Flow Enforcement | Human ReviewsAC - Access Controlopen
NIST800-AC-4(10)AC-4(10) Information Flow Enforcement | Enable and Disable Security or Privacy Policy FiltersAC - Access Controlopen
NIST800-AC-4(11)AC-4(11) Information Flow Enforcement | Configuration of Security or Privacy Policy FiltersAC - Access Controlopen
NIST800-AC-4(12)AC-4(12) Information Flow Enforcement | Data Type IdentifiersAC - Access Controlopen
NIST800-AC-4(13)AC-4(13) Information Flow Enforcement | Decomposition into Policy-relevant SubcomponentsAC - Access Controlopen
NIST800-AC-4(14)AC-4(14) Information Flow Enforcement | Security or Privacy Policy Filter ConstraintsAC - Access Controlopen
NIST800-AC-4(15)AC-4(15) Information Flow Enforcement | Detection of Unsanctioned InformationAC - Access Controlopen
NIST800-AC-4(17)AC-4(17) Information Flow Enforcement | Domain AuthenticationAC - Access Controlopen
NIST800-AC-4(19)AC-4(19) Information Flow Enforcement | Validation of MetadataAC - Access Controlopen
NIST800-AC-4(20)AC-4(20) Information Flow Enforcement | Approved SolutionsAC - Access Controlopen
NIST800-AC-4(21)AC-4(21) Information Flow Enforcement | Physical or Logical Separation of Information FlowsAC - Access Controlopen
NIST800-AC-4(22)AC-4(22) Information Flow Enforcement | Access OnlyAC - Access Controlopen
NIST800-AC-4(23)AC-4(23) Information Flow Enforcement | Modify Non-releasable InformationAC - Access Controlopen
NIST800-AC-4(24)AC-4(24) Information Flow Enforcement | Internal Normalized FormatAC - Access Controlopen
NIST800-AC-4(25)AC-4(25) Information Flow Enforcement | Data SanitizationAC - Access Controlopen
NIST800-AC-4(26)AC-4(26) Information Flow Enforcement | Audit Filtering ActionsAC - Access Controlopen
NIST800-AC-4(27)AC-4(27) Information Flow Enforcement | Redundant/Independent Filtering MechanismsAC - Access Controlopen
NIST800-AC-4(28)AC-4(28) Information Flow Enforcement | Linear Filter PipelinesAC - Access Controlopen
NIST800-AC-4(29)AC-4(29) Information Flow Enforcement | Filter Orchestration EnginesAC - Access Controlopen
NIST800-AC-4(30)AC-4(30) Information Flow Enforcement | Filter Mechanisms Using Multiple ProcessesAC - Access Controlopen
NIST800-AC-4(31)AC-4(31) Information Flow Enforcement | Failed Content Transfer PreventionAC - Access Controlopen
NIST800-AC-4(32)AC-4(32) Information Flow Enforcement | Process Requirements for Information TransferAC - Access Controlopen
NIST800-AC-5AC-5 Separation of DutiesAC - Access Controlopen
NIST800-AC-6AC-6 Least PrivilegeAC - Access Controlopen
NIST800-AC-6(1)AC-6(1) Least Privilege | Authorize Access to Security FunctionsAC - Access Controlopen
NIST800-AC-6(2)AC-6(2) Least Privilege | Non-privileged Access for Nonsecurity FunctionsAC - Access Controlopen
NIST800-AC-6(3)AC-6(3) Least Privilege | Network Access to Privileged CommandsAC - Access Controlopen
NIST800-AC-6(4)AC-6(4) Least Privilege | Separate Processing DomainsAC - Access Controlopen
NIST800-AC-6(5)AC-6(5) Least Privilege | Privileged AccountsAC - Access Controlopen
NIST800-AC-6(6)AC-6(6) Least Privilege | Privileged Access by Non-organizational UsersAC - Access Controlopen
NIST800-AC-6(7)AC-6(7) Least Privilege | Review of User PrivilegesAC - Access Controlopen
NIST800-AC-6(8)AC-6(8) Least Privilege | Privilege Levels for Code ExecutionAC - Access Controlopen
NIST800-AC-6(9)AC-6(9) Least Privilege | Log Use of Privileged FunctionsAC - Access Controlopen
NIST800-AC-6(10)AC-6(10) Least Privilege | Prohibit Non-privileged Users from Executing Privileged FunctionsAC - Access Controlopen
NIST800-AC-7AC-7 Unsuccessful Logon AttemptsAC - Access Controlopen
NIST800-AC-7(2)AC-7(2) Unsuccessful Logon Attempts | Purge or Wipe Mobile DeviceAC - Access Controlopen
NIST800-AC-7(3)AC-7(3) Unsuccessful Logon Attempts | Biometric Attempt LimitingAC - Access Controlopen
NIST800-AC-7(4)AC-7(4) Unsuccessful Logon Attempts | Use of Alternate Authentication FactorAC - Access Controlopen
NIST800-AC-8AC-8 System Use NotificationAC - Access Controlopen
NIST800-AC-9AC-9 Previous Logon NotificationAC - Access Controlopen
NIST800-AC-9(1)AC-9(1) Previous Logon Notification | Unsuccessful LogonsAC - Access Controlopen
NIST800-AC-9(2)AC-9(2) Previous Logon Notification | Successful and Unsuccessful LogonsAC - Access Controlopen
NIST800-AC-9(3)AC-9(3) Previous Logon Notification | Notification of Account ChangesAC - Access Controlopen
NIST800-AC-9(4)AC-9(4) Previous Logon Notification | Additional Logon InformationAC - Access Controlopen
NIST800-AC-10AC-10 Concurrent Session ControlAC - Access Controlopen
NIST800-AC-11AC-11 Device LockAC - Access Controlopen
NIST800-AC-11(1)AC-11(1) Device Lock | Pattern-hiding DisplaysAC - Access Controlopen
NIST800-AC-12AC-12 Session TerminationAC - Access Controlopen
NIST800-AC-12(1)AC-12(1) Session Termination | User-initiated LogoutsAC - Access Controlopen
NIST800-AC-12(2)AC-12(2) Session Termination | Termination MessageAC - Access Controlopen
NIST800-AC-12(3)AC-12(3) Session Termination | Timeout Warning MessageAC - Access Controlopen
NIST800-AC-14AC-14 Permitted Actions Without Identification or AuthenticationAC - Access Controlopen
NIST800-AC-16AC-16 Security and Privacy AttributesAC - Access Controlopen
NIST800-AC-16(1)AC-16(1) Security and Privacy Attributes | Dynamic Attribute AssociationAC - Access Controlopen
NIST800-AC-16(2)AC-16(2) Security and Privacy Attributes | Attribute Value Changes by Authorized IndividualsAC - Access Controlopen
NIST800-AC-16(3)AC-16(3) Security and Privacy Attributes | Maintenance of Attribute Associations by SystemAC - Access Controlopen
NIST800-AC-16(4)AC-16(4) Security and Privacy Attributes | Association of Attributes by Authorized IndividualsAC - Access Controlopen
NIST800-AC-16(5)AC-16(5) Security and Privacy Attributes | Attribute Displays on Objects to Be OutputAC - Access Controlopen
NIST800-AC-16(6)AC-16(6) Security and Privacy Attributes | Maintenance of Attribute AssociationAC - Access Controlopen
NIST800-AC-16(7)AC-16(7) Security and Privacy Attributes | Consistent Attribute InterpretationAC - Access Controlopen
NIST800-AC-16(8)AC-16(8) Security and Privacy Attributes | Association Techniques and TechnologiesAC - Access Controlopen
NIST800-AC-16(9)AC-16(9) Security and Privacy Attributes | Attribute Reassignment: Regrading MechanismsAC - Access Controlopen
NIST800-AC-16(10)AC-16(10) Security and Privacy Attributes | Attribute Configuration by Authorized IndividualsAC - Access Controlopen
NIST800-AC-17AC-17 Remote AccessAC - Access Controlopen
NIST800-AC-17(1)AC-17(1) Remote Access | Monitoring and ControlAC - Access Controlopen
NIST800-AC-17(2)AC-17(2) Remote Access | Protection of Confidentiality and Integrity Using EncryptionAC - Access Controlopen
NIST800-AC-17(3)AC-17(3) Remote Access | Managed Access Control PointsAC - Access Controlopen
NIST800-AC-17(4)AC-17(4) Remote Access | Privileged Commands and AccessAC - Access Controlopen
NIST800-AC-17(6)AC-17(6) Remote Access | Protection of Mechanism InformationAC - Access Controlopen
NIST800-AC-17(9)AC-17(9) Remote Access | Disconnect or Disable AccessAC - Access Controlopen
NIST800-AC-17(10)AC-17(10) Remote Access | Authenticate Remote CommandsAC - Access Controlopen
NIST800-AC-18AC-18 Wireless AccessAC - Access Controlopen
NIST800-AC-18(1)AC-18(1) Wireless Access | Authentication and EncryptionAC - Access Controlopen
NIST800-AC-18(3)AC-18(3) Wireless Access | Disable Wireless NetworkingAC - Access Controlopen
NIST800-AC-18(4)AC-18(4) Wireless Access | Restrict Configurations by UsersAC - Access Controlopen
NIST800-AC-18(5)AC-18(5) Wireless Access | Antennas and Transmission Power LevelsAC - Access Controlopen
NIST800-AC-19AC-19 Access Control for Mobile DevicesAC - Access Controlopen
NIST800-AC-19(4)AC-19(4) Access Control for Mobile Devices | Restrictions for Classified InformationAC - Access Controlopen
NIST800-AC-19(5)AC-19(5) Access Control for Mobile Devices | Full Device or Container-based EncryptionAC - Access Controlopen
NIST800-AC-20AC-20 Use of External SystemsAC - Access Controlopen
NIST800-AC-20(1)AC-20(1) Use of External Systems | Limits on Authorized UseAC - Access Controlopen
NIST800-AC-20(2)AC-20(2) Use of External Systems | Portable Storage Devices: Restricted UseAC - Access Controlopen
NIST800-AC-20(3)AC-20(3) Use of External Systems | Non-organizationally Owned Systems: Restricted UseAC - Access Controlopen
NIST800-AC-20(4)AC-20(4) Use of External Systems | Network Accessible Storage Devices: Prohibited UseAC - Access Controlopen
NIST800-AC-20(5)AC-20(5) Use of External Systems | Portable Storage Devices: Prohibited UseAC - Access Controlopen
NIST800-AC-21AC-21 Information SharingAC - Access Controlopen
NIST800-AC-21(1)AC-21(1) Information Sharing | Automated Decision SupportAC - Access Controlopen
NIST800-AC-21(2)AC-21(2) Information Sharing | Information Search and RetrievalAC - Access Controlopen
NIST800-AC-22AC-22 Publicly Accessible ContentAC - Access Controlopen
NIST800-AC-23AC-23 Data Mining ProtectionAC - Access Controlopen
NIST800-AC-24AC-24 Access Control DecisionsAC - Access Controlopen
NIST800-AC-24(1)AC-24(1) Access Control Decisions | Transmit Access Authorization InformationAC - Access Controlopen
NIST800-AC-24(2)AC-24(2) Access Control Decisions | No User or Process IdentityAC - Access Controlopen
NIST800-AC-25AC-25 Reference MonitorAC - Access Controlopen
NIST800-AT-1AT-1 Policy and ProceduresAT - Awareness and Trainingopen
NIST800-AT-2AT-2 Literacy Training and AwarenessAT - Awareness and Trainingopen
NIST800-AT-2(1)AT-2(1) Literacy Training and Awareness | Practical ExercisesAT - Awareness and Trainingopen
NIST800-AT-2(2)AT-2(2) Literacy Training and Awareness | Insider ThreatAT - Awareness and Trainingopen
NIST800-AT-2(3)AT-2(3) Literacy Training and Awareness | Social Engineering and MiningAT - Awareness and Trainingopen
NIST800-AT-2(4)AT-2(4) Literacy Training and Awareness | Suspicious Communications and Anomalous System BehaviorAT - Awareness and Trainingopen
NIST800-AT-2(5)AT-2(5) Literacy Training and Awareness | Advanced Persistent ThreatAT - Awareness and Trainingopen
NIST800-AT-2(6)AT-2(6) Literacy Training and Awareness | Cyber Threat EnvironmentAT - Awareness and Trainingopen
NIST800-AT-3AT-3 Role-based TrainingAT - Awareness and Trainingopen
NIST800-AT-3(1)AT-3(1) Role-based Training | Environmental ControlsAT - Awareness and Trainingopen
NIST800-AT-3(2)AT-3(2) Role-based Training | Physical Security ControlsAT - Awareness and Trainingopen
NIST800-AT-3(3)AT-3(3) Role-based Training | Practical ExercisesAT - Awareness and Trainingopen
NIST800-AT-3(5)AT-3(5) Role-based Training | Processing Personally Identifiable InformationAT - Awareness and Trainingopen
NIST800-AT-4AT-4 Training RecordsAT - Awareness and Trainingopen
NIST800-AT-6AT-6 Training FeedbackAT - Awareness and Trainingopen
NIST800-AU-1AU-1 Policy and ProceduresAU - Audit and Accountabilityopen
NIST800-AU-2AU-2 Event LoggingAU - Audit and Accountabilityopen
NIST800-AU-3AU-3 Content of Audit RecordsAU - Audit and Accountabilityopen
NIST800-AU-3(1)AU-3(1) Content of Audit Records | Additional Audit InformationAU - Audit and Accountabilityopen
NIST800-AU-3(3)AU-3(3) Content of Audit Records | Limit Personally Identifiable Information ElementsAU - Audit and Accountabilityopen
NIST800-AU-4AU-4 Audit Log Storage CapacityAU - Audit and Accountabilityopen
NIST800-AU-4(1)AU-4(1) Audit Log Storage Capacity | Transfer to Alternate StorageAU - Audit and Accountabilityopen
NIST800-AU-5AU-5 Response to Audit Logging Process FailuresAU - Audit and Accountabilityopen
NIST800-AU-5(1)AU-5(1) Response to Audit Logging Process Failures | Storage Capacity WarningAU - Audit and Accountabilityopen
NIST800-AU-5(2)AU-5(2) Response to Audit Logging Process Failures | Real-time AlertsAU - Audit and Accountabilityopen
NIST800-AU-5(3)AU-5(3) Response to Audit Logging Process Failures | Configurable Traffic Volume ThresholdsAU - Audit and Accountabilityopen
NIST800-AU-5(4)AU-5(4) Response to Audit Logging Process Failures | Shutdown on FailureAU - Audit and Accountabilityopen
NIST800-AU-5(5)AU-5(5) Response to Audit Logging Process Failures | Alternate Audit Logging CapabilityAU - Audit and Accountabilityopen
NIST800-AU-6AU-6 Audit Record Review, Analysis, and ReportingAU - Audit and Accountabilityopen
NIST800-AU-6(1)AU-6(1) Audit Record Review, Analysis, and Reporting | Automated Process IntegrationAU - Audit and Accountabilityopen
NIST800-AU-6(3)AU-6(3) Audit Record Review, Analysis, and Reporting | Correlate Audit Record RepositoriesAU - Audit and Accountabilityopen
NIST800-AU-6(4)AU-6(4) Audit Record Review, Analysis, and Reporting | Central Review and AnalysisAU - Audit and Accountabilityopen
NIST800-AU-6(5)AU-6(5) Audit Record Review, Analysis, and Reporting | Integrated Analysis of Audit RecordsAU - Audit and Accountabilityopen
NIST800-AU-6(6)AU-6(6) Audit Record Review, Analysis, and Reporting | Correlation with Physical MonitoringAU - Audit and Accountabilityopen
NIST800-AU-6(7)AU-6(7) Audit Record Review, Analysis, and Reporting | Permitted ActionsAU - Audit and Accountabilityopen
NIST800-AU-6(8)AU-6(8) Audit Record Review, Analysis, and Reporting | Full Text Analysis of Privileged CommandsAU - Audit and Accountabilityopen
NIST800-AU-6(9)AU-6(9) Audit Record Review, Analysis, and Reporting | Correlation with Information from Nontechnical SourcesAU - Audit and Accountabilityopen
NIST800-AU-7AU-7 Audit Record Reduction and Report GenerationAU - Audit and Accountabilityopen
NIST800-AU-7(1)AU-7(1) Audit Record Reduction and Report Generation | Automatic ProcessingAU - Audit and Accountabilityopen
NIST800-AU-8AU-8 Time StampsAU - Audit and Accountabilityopen
NIST800-AU-9AU-9 Protection of Audit InformationAU - Audit and Accountabilityopen
NIST800-AU-9(1)AU-9(1) Protection of Audit Information | Hardware Write-once MediaAU - Audit and Accountabilityopen
NIST800-AU-9(2)AU-9(2) Protection of Audit Information | Store on Separate Physical Systems or ComponentsAU - Audit and Accountabilityopen
NIST800-AU-9(3)AU-9(3) Protection of Audit Information | Cryptographic ProtectionAU - Audit and Accountabilityopen
NIST800-AU-9(4)AU-9(4) Protection of Audit Information | Access by Subset of Privileged UsersAU - Audit and Accountabilityopen
NIST800-AU-9(5)AU-9(5) Protection of Audit Information | Dual AuthorizationAU - Audit and Accountabilityopen
NIST800-AU-9(6)AU-9(6) Protection of Audit Information | Read-only AccessAU - Audit and Accountabilityopen
NIST800-AU-9(7)AU-9(7) Protection of Audit Information | Store on Component with Different Operating SystemAU - Audit and Accountabilityopen
NIST800-AU-10AU-10 Non-repudiationAU - Audit and Accountabilityopen
NIST800-AU-10(1)AU-10(1) Non-repudiation | Association of IdentitiesAU - Audit and Accountabilityopen
NIST800-AU-10(2)AU-10(2) Non-repudiation | Validate Binding of Information Producer IdentityAU - Audit and Accountabilityopen
NIST800-AU-10(3)AU-10(3) Non-repudiation | Chain of CustodyAU - Audit and Accountabilityopen
NIST800-AU-10(4)AU-10(4) Non-repudiation | Validate Binding of Information Reviewer IdentityAU - Audit and Accountabilityopen
NIST800-AU-11AU-11 Audit Record RetentionAU - Audit and Accountabilityopen
NIST800-AU-11(1)AU-11(1) Audit Record Retention | Long-term Retrieval CapabilityAU - Audit and Accountabilityopen
NIST800-AU-12AU-12 Audit Record GenerationAU - Audit and Accountabilityopen
NIST800-AU-12(1)AU-12(1) Audit Record Generation | System-wide and Time-correlated Audit TrailAU - Audit and Accountabilityopen
NIST800-AU-12(2)AU-12(2) Audit Record Generation | Standardized FormatsAU - Audit and Accountabilityopen
NIST800-AU-12(3)AU-12(3) Audit Record Generation | Changes by Authorized IndividualsAU - Audit and Accountabilityopen
NIST800-AU-12(4)AU-12(4) Audit Record Generation | Query Parameter Audits of Personally Identifiable InformationAU - Audit and Accountabilityopen
NIST800-AU-13AU-13 Monitoring for Information DisclosureAU - Audit and Accountabilityopen
NIST800-AU-13(1)AU-13(1) Monitoring for Information Disclosure | Use of Automated ToolsAU - Audit and Accountabilityopen
NIST800-AU-13(2)AU-13(2) Monitoring for Information Disclosure | Review of Monitored SitesAU - Audit and Accountabilityopen
NIST800-AU-13(3)AU-13(3) Monitoring for Information Disclosure | Unauthorized Replication of InformationAU - Audit and Accountabilityopen
NIST800-AU-14AU-14 Session AuditAU - Audit and Accountabilityopen
NIST800-AU-14(1)AU-14(1) Session Audit | System Start-upAU - Audit and Accountabilityopen
NIST800-AU-14(3)AU-14(3) Session Audit | Remote Viewing and ListeningAU - Audit and Accountabilityopen
NIST800-AU-16AU-16 Cross-organizational Audit LoggingAU - Audit and Accountabilityopen
NIST800-AU-16(1)AU-16(1) Cross-organizational Audit Logging | Identity PreservationAU - Audit and Accountabilityopen
NIST800-AU-16(2)AU-16(2) Cross-organizational Audit Logging | Sharing of Audit InformationAU - Audit and Accountabilityopen
NIST800-AU-16(3)AU-16(3) Cross-organizational Audit Logging | DisassociabilityAU - Audit and Accountabilityopen
NIST800-CA-1CA-1 Policy and ProceduresCA - Assessment, Authorization, and Monitoringopen
NIST800-CA-2CA-2 Control AssessmentsCA - Assessment, Authorization, and Monitoringopen
NIST800-CA-2(1)CA-2(1) Control Assessments | Independent AssessorsCA - Assessment, Authorization, and Monitoringopen
NIST800-CA-2(2)CA-2(2) Control Assessments | Specialized AssessmentsCA - Assessment, Authorization, and Monitoringopen
NIST800-CA-2(3)CA-2(3) Control Assessments | Leveraging Results from External OrganizationsCA - Assessment, Authorization, and Monitoringopen
NIST800-CA-3CA-3 Information ExchangeCA - Assessment, Authorization, and Monitoringopen
NIST800-CA-3(6)CA-3(6) Information Exchange | Transfer AuthorizationsCA - Assessment, Authorization, and Monitoringopen
NIST800-CA-3(7)CA-3(7) Information Exchange | Transitive Information ExchangesCA - Assessment, Authorization, and Monitoringopen
NIST800-CA-5CA-5 Plan of Action and MilestonesCA - Assessment, Authorization, and Monitoringopen
NIST800-CA-5(1)CA-5(1) Plan of Action and Milestones | Automation Support for Accuracy and CurrencyCA - Assessment, Authorization, and Monitoringopen
NIST800-CA-6CA-6 AuthorizationCA - Assessment, Authorization, and Monitoringopen
NIST800-CA-6(1)CA-6(1) Authorization | Joint Authorization: Intra-organizationCA - Assessment, Authorization, and Monitoringopen
NIST800-CA-6(2)CA-6(2) Authorization | Joint Authorization: Inter-organizationCA - Assessment, Authorization, and Monitoringopen
NIST800-CA-7CA-7 Continuous MonitoringCA - Assessment, Authorization, and Monitoringopen
NIST800-CA-7(1)CA-7(1) Continuous Monitoring | Independent AssessmentCA - Assessment, Authorization, and Monitoringopen
NIST800-CA-7(3)CA-7(3) Continuous Monitoring | Trend AnalysesCA - Assessment, Authorization, and Monitoringopen
NIST800-CA-7(4)CA-7(4) Continuous Monitoring | Risk MonitoringCA - Assessment, Authorization, and Monitoringopen
NIST800-CA-7(5)CA-7(5) Continuous Monitoring | Consistency AnalysisCA - Assessment, Authorization, and Monitoringopen
NIST800-CA-7(6)CA-7(6) Continuous Monitoring | Automation Support for MonitoringCA - Assessment, Authorization, and Monitoringopen
NIST800-CA-8CA-8 Penetration TestingCA - Assessment, Authorization, and Monitoringopen
NIST800-CA-8(1)CA-8(1) Penetration Testing | Independent Penetration Testing Agent or TeamCA - Assessment, Authorization, and Monitoringopen
NIST800-CA-8(2)CA-8(2) Penetration Testing | Red Team ExercisesCA - Assessment, Authorization, and Monitoringopen
NIST800-CA-8(3)CA-8(3) Penetration Testing | Facility Penetration TestingCA - Assessment, Authorization, and Monitoringopen
NIST800-CA-9CA-9 Internal System ConnectionsCA - Assessment, Authorization, and Monitoringopen
NIST800-CA-9(1)CA-9(1) Internal System Connections | Compliance ChecksCA - Assessment, Authorization, and Monitoringopen
NIST800-CM-1CM-1 Policy and ProceduresCM - Configuration Managementopen
NIST800-CM-2CM-2 Baseline ConfigurationCM - Configuration Managementopen
NIST800-CM-2(2)CM-2(2) Baseline Configuration | Automation Support for Accuracy and CurrencyCM - Configuration Managementopen
NIST800-CM-2(3)CM-2(3) Baseline Configuration | Retention of Previous ConfigurationsCM - Configuration Managementopen
NIST800-CM-2(6)CM-2(6) Baseline Configuration | Development and Test EnvironmentsCM - Configuration Managementopen
NIST800-CM-2(7)CM-2(7) Baseline Configuration | Configure Systems and Components for High-risk AreasCM - Configuration Managementopen
NIST800-CM-3CM-3 Configuration Change ControlCM - Configuration Managementopen
NIST800-CM-3(1)CM-3(1) Configuration Change Control | Automated Documentation, Notification, and Prohibition of ChangesCM - Configuration Managementopen
NIST800-CM-3(2)CM-3(2) Configuration Change Control | Testing, Validation, and Documentation of ChangesCM - Configuration Managementopen
NIST800-CM-3(3)CM-3(3) Configuration Change Control | Automated Change ImplementationCM - Configuration Managementopen
NIST800-CM-3(4)CM-3(4) Configuration Change Control | Security and Privacy RepresentativesCM - Configuration Managementopen
NIST800-CM-3(5)CM-3(5) Configuration Change Control | Automated Security ResponseCM - Configuration Managementopen
NIST800-CM-3(6)CM-3(6) Configuration Change Control | Cryptography ManagementCM - Configuration Managementopen
NIST800-CM-3(7)CM-3(7) Configuration Change Control | Review System ChangesCM - Configuration Managementopen
NIST800-CM-3(8)CM-3(8) Configuration Change Control | Prevent or Restrict Configuration ChangesCM - Configuration Managementopen
NIST800-CM-4CM-4 Impact AnalysesCM - Configuration Managementopen
NIST800-CM-4(1)CM-4(1) Impact Analyses | Separate Test EnvironmentsCM - Configuration Managementopen
NIST800-CM-4(2)CM-4(2) Impact Analyses | Verification of ControlsCM - Configuration Managementopen
NIST800-CM-5CM-5 Access Restrictions for ChangeCM - Configuration Managementopen
NIST800-CM-5(1)CM-5(1) Access Restrictions for Change | Automated Access Enforcement and Audit RecordsCM - Configuration Managementopen
NIST800-CM-5(4)CM-5(4) Access Restrictions for Change | Dual AuthorizationCM - Configuration Managementopen
NIST800-CM-5(5)CM-5(5) Access Restrictions for Change | Privilege Limitation for Production and OperationCM - Configuration Managementopen
NIST800-CM-5(6)CM-5(6) Access Restrictions for Change | Limit Library PrivilegesCM - Configuration Managementopen
NIST800-CM-6CM-6 Configuration SettingsCM - Configuration Managementopen
NIST800-CM-6(1)CM-6(1) Configuration Settings | Automated Management, Application, and VerificationCM - Configuration Managementopen
NIST800-CM-6(2)CM-6(2) Configuration Settings | Respond to Unauthorized ChangesCM - Configuration Managementopen
NIST800-CM-7CM-7 Least FunctionalityCM - Configuration Managementopen
NIST800-CM-7(1)CM-7(1) Least Functionality | Periodic ReviewCM - Configuration Managementopen
NIST800-CM-7(2)CM-7(2) Least Functionality | Prevent Program ExecutionCM - Configuration Managementopen
NIST800-CM-7(3)CM-7(3) Least Functionality | Registration ComplianceCM - Configuration Managementopen
NIST800-CM-7(4)CM-7(4) Least Functionality | Unauthorized Software: Deny-by-exceptionCM - Configuration Managementopen
NIST800-CM-7(5)CM-7(5) Least Functionality | Authorized Software: Allow-by-exceptionCM - Configuration Managementopen
NIST800-CM-7(6)CM-7(6) Least Functionality | Confined Environments with Limited PrivilegesCM - Configuration Managementopen
NIST800-CM-7(7)CM-7(7) Least Functionality | Code Execution in Protected EnvironmentsCM - Configuration Managementopen
NIST800-CM-7(8)CM-7(8) Least Functionality | Binary or Machine Executable CodeCM - Configuration Managementopen
NIST800-CM-7(9)CM-7(9) Least Functionality | Prohibiting The Use of Unauthorized HardwareCM - Configuration Managementopen
NIST800-CM-8CM-8 System Component InventoryCM - Configuration Managementopen
NIST800-CM-8(1)CM-8(1) System Component Inventory | Updates During Installation and RemovalCM - Configuration Managementopen
NIST800-CM-8(2)CM-8(2) System Component Inventory | Automated MaintenanceCM - Configuration Managementopen
NIST800-CM-8(3)CM-8(3) System Component Inventory | Automated Unauthorized Component DetectionCM - Configuration Managementopen
NIST800-CM-8(4)CM-8(4) System Component Inventory | Accountability InformationCM - Configuration Managementopen
NIST800-CM-8(6)CM-8(6) System Component Inventory | Assessed Configurations and Approved DeviationsCM - Configuration Managementopen
NIST800-CM-8(7)CM-8(7) System Component Inventory | Centralized RepositoryCM - Configuration Managementopen
NIST800-CM-8(8)CM-8(8) System Component Inventory | Automated Location TrackingCM - Configuration Managementopen
NIST800-CM-8(9)CM-8(9) System Component Inventory | Assignment of Components to SystemsCM - Configuration Managementopen
NIST800-CM-9CM-9 Configuration Management PlanCM - Configuration Managementopen
NIST800-CM-9(1)CM-9(1) Configuration Management Plan | Assignment of ResponsibilityCM - Configuration Managementopen
NIST800-CM-10CM-10 Software Usage RestrictionsCM - Configuration Managementopen
NIST800-CM-10(1)CM-10(1) Software Usage Restrictions | Open-source SoftwareCM - Configuration Managementopen
NIST800-CM-11CM-11 User-installed SoftwareCM - Configuration Managementopen
NIST800-CM-11(2)CM-11(2) User-installed Software | Software Installation with Privileged StatusCM - Configuration Managementopen
NIST800-CM-11(3)CM-11(3) User-installed Software | Automated Enforcement and MonitoringCM - Configuration Managementopen
NIST800-CM-12CM-12 Information LocationCM - Configuration Managementopen
NIST800-CM-12(1)CM-12(1) Information Location | Automated Tools to Support Information LocationCM - Configuration Managementopen
NIST800-CM-13CM-13 Data Action MappingCM - Configuration Managementopen
NIST800-CM-14CM-14 Signed ComponentsCM - Configuration Managementopen
NIST800-CP-1CP-1 Policy and ProceduresCP - Contingency Planningopen
NIST800-CP-2CP-2 Contingency PlanCP - Contingency Planningopen
NIST800-CP-2(1)CP-2(1) Contingency Plan | Coordinate with Related PlansCP - Contingency Planningopen
NIST800-CP-2(2)CP-2(2) Contingency Plan | Capacity PlanningCP - Contingency Planningopen
NIST800-CP-2(3)CP-2(3) Contingency Plan | Resume Mission and Business FunctionsCP - Contingency Planningopen
NIST800-CP-2(5)CP-2(5) Contingency Plan | Continue Mission and Business FunctionsCP - Contingency Planningopen
NIST800-CP-2(6)CP-2(6) Contingency Plan | Alternate Processing and Storage SitesCP - Contingency Planningopen
NIST800-CP-2(7)CP-2(7) Contingency Plan | Coordinate with External Service ProvidersCP - Contingency Planningopen
NIST800-CP-2(8)CP-2(8) Contingency Plan | Identify Critical AssetsCP - Contingency Planningopen
NIST800-CP-3CP-3 Contingency TrainingCP - Contingency Planningopen
NIST800-CP-3(1)CP-3(1) Contingency Training | Simulated EventsCP - Contingency Planningopen
NIST800-CP-3(2)CP-3(2) Contingency Training | Mechanisms Used in Training EnvironmentsCP - Contingency Planningopen
NIST800-CP-4CP-4 Contingency Plan TestingCP - Contingency Planningopen
NIST800-CP-4(1)CP-4(1) Contingency Plan Testing | Coordinate with Related PlansCP - Contingency Planningopen
NIST800-CP-4(2)CP-4(2) Contingency Plan Testing | Alternate Processing SiteCP - Contingency Planningopen
NIST800-CP-4(3)CP-4(3) Contingency Plan Testing | Automated TestingCP - Contingency Planningopen
NIST800-CP-4(4)CP-4(4) Contingency Plan Testing | Full Recovery and ReconstitutionCP - Contingency Planningopen
NIST800-CP-4(5)CP-4(5) Contingency Plan Testing | Self-challengeCP - Contingency Planningopen
NIST800-CP-6CP-6 Alternate Storage SiteCP - Contingency Planningopen
NIST800-CP-6(1)CP-6(1) Alternate Storage Site | Separation from Primary SiteCP - Contingency Planningopen
NIST800-CP-6(2)CP-6(2) Alternate Storage Site | Recovery Time and Recovery Point ObjectivesCP - Contingency Planningopen
NIST800-CP-6(3)CP-6(3) Alternate Storage Site | AccessibilityCP - Contingency Planningopen
NIST800-CP-7CP-7 Alternate Processing SiteCP - Contingency Planningopen
NIST800-CP-7(1)CP-7(1) Alternate Processing Site | Separation from Primary SiteCP - Contingency Planningopen
NIST800-CP-7(2)CP-7(2) Alternate Processing Site | AccessibilityCP - Contingency Planningopen
NIST800-CP-7(3)CP-7(3) Alternate Processing Site | Priority of ServiceCP - Contingency Planningopen
NIST800-CP-7(4)CP-7(4) Alternate Processing Site | Preparation for UseCP - Contingency Planningopen
NIST800-CP-7(6)CP-7(6) Alternate Processing Site | Inability to Return to Primary SiteCP - Contingency Planningopen
NIST800-CP-8CP-8 Telecommunications ServicesCP - Contingency Planningopen
NIST800-CP-8(1)CP-8(1) Telecommunications Services | Priority of Service ProvisionsCP - Contingency Planningopen
NIST800-CP-8(2)CP-8(2) Telecommunications Services | Single Points of FailureCP - Contingency Planningopen
NIST800-CP-8(3)CP-8(3) Telecommunications Services | Separation of Primary and Alternate ProvidersCP - Contingency Planningopen
NIST800-CP-8(4)CP-8(4) Telecommunications Services | Provider Contingency PlanCP - Contingency Planningopen
NIST800-CP-8(5)CP-8(5) Telecommunications Services | Alternate Telecommunication Service TestingCP - Contingency Planningopen
NIST800-CP-9CP-9 System BackupCP - Contingency Planningopen
NIST800-CP-9(1)CP-9(1) System Backup | Testing for Reliability and IntegrityCP - Contingency Planningopen
NIST800-CP-9(2)CP-9(2) System Backup | Test Restoration Using SamplingCP - Contingency Planningopen
NIST800-CP-9(3)CP-9(3) System Backup | Separate Storage for Critical InformationCP - Contingency Planningopen
NIST800-CP-9(5)CP-9(5) System Backup | Transfer to Alternate Storage SiteCP - Contingency Planningopen
NIST800-CP-9(6)CP-9(6) System Backup | Redundant Secondary SystemCP - Contingency Planningopen
NIST800-CP-9(7)CP-9(7) System Backup | Dual Authorization for Deletion or DestructionCP - Contingency Planningopen
NIST800-CP-9(8)CP-9(8) System Backup | Cryptographic ProtectionCP - Contingency Planningopen
NIST800-CP-10CP-10 System Recovery and ReconstitutionCP - Contingency Planningopen
NIST800-CP-10(2)CP-10(2) System Recovery and Reconstitution | Transaction RecoveryCP - Contingency Planningopen
NIST800-CP-10(4)CP-10(4) System Recovery and Reconstitution | Restore Within Time PeriodCP - Contingency Planningopen
NIST800-CP-10(6)CP-10(6) System Recovery and Reconstitution | Component ProtectionCP - Contingency Planningopen
NIST800-CP-11CP-11 Alternate Communications ProtocolsCP - Contingency Planningopen
NIST800-CP-12CP-12 Safe ModeCP - Contingency Planningopen
NIST800-CP-13CP-13 Alternative Security MechanismsCP - Contingency Planningopen
NIST800-IA-1IA-1 Policy and ProceduresIA - Identification and Authenticationopen
NIST800-IA-2IA-2 Identification and Authentication (Organizational Users)IA - Identification and Authenticationopen
NIST800-IA-2(1)IA-2(1) Identification and Authentication (Organizational Users) | Multi-factor Authentication to Privileged AccountsIA - Identification and Authenticationopen
NIST800-IA-2(2)IA-2(2) Identification and Authentication (Organizational Users) | Multi-factor Authentication to Non-privileged AccountsIA - Identification and Authenticationopen
NIST800-IA-2(5)IA-2(5) Identification and Authentication (Organizational Users) | Individual Authentication with Group AuthenticationIA - Identification and Authenticationopen
NIST800-IA-2(6)IA-2(6) Identification and Authentication (Organizational Users) | Access to Accounts: separate DeviceIA - Identification and Authenticationopen
NIST800-IA-2(8)IA-2(8) Identification and Authentication (Organizational Users) | Access to Accounts: Replay ResistantIA - Identification and Authenticationopen
NIST800-IA-2(10)IA-2(10) Identification and Authentication (Organizational Users) | Single Sign-onIA - Identification and Authenticationopen
NIST800-IA-2(12)IA-2(12) Identification and Authentication (Organizational Users) | Acceptance of PIV CredentialsIA - Identification and Authenticationopen
NIST800-IA-2(13)IA-2(13) Identification and Authentication (Organizational Users) | Out-of-band AuthenticationIA - Identification and Authenticationopen
NIST800-IA-3IA-3 Device Identification and AuthenticationIA - Identification and Authenticationopen
NIST800-IA-3(1)IA-3(1) Device Identification and Authentication | Cryptographic Bidirectional AuthenticationIA - Identification and Authenticationopen
NIST800-IA-3(3)IA-3(3) Device Identification and Authentication | Dynamic Address AllocationIA - Identification and Authenticationopen
NIST800-IA-3(4)IA-3(4) Device Identification and Authentication | Device AttestationIA - Identification and Authenticationopen
NIST800-IA-4IA-4 Identifier ManagementIA - Identification and Authenticationopen
NIST800-IA-4(1)IA-4(1) Identifier Management | Prohibit Account Identifiers as Public IdentifiersIA - Identification and Authenticationopen
NIST800-IA-4(4)IA-4(4) Identifier Management | Identify User StatusIA - Identification and Authenticationopen
NIST800-IA-4(5)IA-4(5) Identifier Management | Dynamic ManagementIA - Identification and Authenticationopen
NIST800-IA-4(6)IA-4(6) Identifier Management | Cross-organization ManagementIA - Identification and Authenticationopen
NIST800-IA-4(8)IA-4(8) Identifier Management | Pairwise Pseudonymous IdentifiersIA - Identification and Authenticationopen
NIST800-IA-4(9)IA-4(9) Identifier Management | Attribute Maintenance and ProtectionIA - Identification and Authenticationopen
NIST800-IA-5IA-5 Authenticator ManagementIA - Identification and Authenticationopen
NIST800-IA-5(1)IA-5(1) Authenticator Management | Password-based AuthenticationIA - Identification and Authenticationopen
NIST800-IA-5(2)IA-5(2) Authenticator Management | Public Key-based AuthenticationIA - Identification and Authenticationopen
NIST800-IA-5(5)IA-5(5) Authenticator Management | Change Authenticators Prior to DeliveryIA - Identification and Authenticationopen
NIST800-IA-5(6)IA-5(6) Authenticator Management | Protection of AuthenticatorsIA - Identification and Authenticationopen
NIST800-IA-5(7)IA-5(7) Authenticator Management | No Embedded Unencrypted Static AuthenticatorsIA - Identification and Authenticationopen
NIST800-IA-5(8)IA-5(8) Authenticator Management | Multiple System AccountsIA - Identification and Authenticationopen
NIST800-IA-5(9)IA-5(9) Authenticator Management | Federated Credential ManagementIA - Identification and Authenticationopen
NIST800-IA-5(10)IA-5(10) Authenticator Management | Dynamic Credential BindingIA - Identification and Authenticationopen
NIST800-IA-5(12)IA-5(12) Authenticator Management | Biometric Authentication PerformanceIA - Identification and Authenticationopen
NIST800-IA-5(13)IA-5(13) Authenticator Management | Expiration of Cached AuthenticatorsIA - Identification and Authenticationopen
NIST800-IA-5(14)IA-5(14) Authenticator Management | Managing Content of PKI Trust StoresIA - Identification and Authenticationopen
NIST800-IA-5(15)IA-5(15) Authenticator Management | GSA-approved Products and ServicesIA - Identification and Authenticationopen
NIST800-IA-5(16)IA-5(16) Authenticator Management | In-person or Trusted External Party Authenticator IssuanceIA - Identification and Authenticationopen
NIST800-IA-5(17)IA-5(17) Authenticator Management | Presentation Attack Detection for Biometric AuthenticatorsIA - Identification and Authenticationopen
NIST800-IA-5(18)IA-5(18) Authenticator Management | Password ManagersIA - Identification and Authenticationopen
NIST800-IA-6IA-6 Authentication FeedbackIA - Identification and Authenticationopen
NIST800-IA-7IA-7 Cryptographic Module AuthenticationIA - Identification and Authenticationopen
NIST800-IA-8IA-8 Identification and Authentication (Non-organizational Users)IA - Identification and Authenticationopen
NIST800-IA-8(1)IA-8(1) Identification and Authentication (Non-organizational Users) | Acceptance of PIV Credentials from Other AgenciesIA - Identification and Authenticationopen
NIST800-IA-8(2)IA-8(2) Identification and Authentication (Non-organizational Users) | Acceptance of External AuthenticatorsIA - Identification and Authenticationopen
NIST800-IA-8(4)IA-8(4) Identification and Authentication (Non-organizational Users) | Use of Defined ProfilesIA - Identification and Authenticationopen
NIST800-IA-8(5)IA-8(5) Identification and Authentication (Non-organizational Users) | Acceptance of PIV-I CredentialsIA - Identification and Authenticationopen
NIST800-IA-8(6)IA-8(6) Identification and Authentication (Non-organizational Users) | DisassociabilityIA - Identification and Authenticationopen
NIST800-IA-9IA-9 Service Identification and AuthenticationIA - Identification and Authenticationopen
NIST800-IA-10IA-10 Adaptive AuthenticationIA - Identification and Authenticationopen
NIST800-IA-11IA-11 Re-authenticationIA - Identification and Authenticationopen
NIST800-IA-12IA-12 Identity ProofingIA - Identification and Authenticationopen
NIST800-IA-12(1)IA-12(1) Identity Proofing | Supervisor AuthorizationIA - Identification and Authenticationopen
NIST800-IA-12(2)IA-12(2) Identity Proofing | Identity EvidenceIA - Identification and Authenticationopen
NIST800-IA-12(3)IA-12(3) Identity Proofing | Identity Evidence Validation and VerificationIA - Identification and Authenticationopen
NIST800-IA-12(4)IA-12(4) Identity Proofing | In-person Validation and VerificationIA - Identification and Authenticationopen
NIST800-IA-12(5)IA-12(5) Identity Proofing | Address ConfirmationIA - Identification and Authenticationopen
NIST800-IA-12(6)IA-12(6) Identity Proofing | Accept Externally-proofed IdentitiesIA - Identification and Authenticationopen
NIST800-IA-13IA-13 Identity Providers and Authorization ServersIA - Identification and Authenticationopen
NIST800-IA-13(1)IA-13(1) Identity Providers and Authorization Servers | Protection of Cryptographic KeysIA - Identification and Authenticationopen
NIST800-IA-13(2)IA-13(2) Identity Providers and Authorization Servers | Verification of Identity Assertions and Access TokensIA - Identification and Authenticationopen
NIST800-IA-13(3)IA-13(3) Identity Providers and Authorization Servers | Token ManagementIA - Identification and Authenticationopen
NIST800-IR-1IR-1 Policy and ProceduresIR - Incident Responseopen
NIST800-IR-2IR-2 Incident Response TrainingIR - Incident Responseopen
NIST800-IR-2(1)IR-2(1) Incident Response Training | Simulated EventsIR - Incident Responseopen
NIST800-IR-2(2)IR-2(2) Incident Response Training | Automated Training EnvironmentsIR - Incident Responseopen
NIST800-IR-2(3)IR-2(3) Incident Response Training | BreachIR - Incident Responseopen
NIST800-IR-3IR-3 Incident Response TestingIR - Incident Responseopen
NIST800-IR-3(1)IR-3(1) Incident Response Testing | Automated TestingIR - Incident Responseopen
NIST800-IR-3(2)IR-3(2) Incident Response Testing | Coordination with Related PlansIR - Incident Responseopen
NIST800-IR-3(3)IR-3(3) Incident Response Testing | Continuous ImprovementIR - Incident Responseopen
NIST800-IR-4IR-4 Incident HandlingIR - Incident Responseopen
NIST800-IR-4(1)IR-4(1) Incident Handling | Automated Incident Handling ProcessesIR - Incident Responseopen
NIST800-IR-4(2)IR-4(2) Incident Handling | Dynamic ReconfigurationIR - Incident Responseopen
NIST800-IR-4(3)IR-4(3) Incident Handling | Continuity of OperationsIR - Incident Responseopen
NIST800-IR-4(4)IR-4(4) Incident Handling | Information CorrelationIR - Incident Responseopen
NIST800-IR-4(5)IR-4(5) Incident Handling | Automatic Disabling of SystemIR - Incident Responseopen
NIST800-IR-4(6)IR-4(6) Incident Handling | Insider ThreatsIR - Incident Responseopen
NIST800-IR-4(7)IR-4(7) Incident Handling | Insider Threats: Intra-organization CoordinationIR - Incident Responseopen
NIST800-IR-4(8)IR-4(8) Incident Handling | Correlation with External OrganizationsIR - Incident Responseopen
NIST800-IR-4(9)IR-4(9) Incident Handling | Dynamic Response CapabilityIR - Incident Responseopen
NIST800-IR-4(10)IR-4(10) Incident Handling | Supply Chain CoordinationIR - Incident Responseopen
NIST800-IR-4(11)IR-4(11) Incident Handling | Integrated Incident Response TeamIR - Incident Responseopen
NIST800-IR-4(12)IR-4(12) Incident Handling | Malicious Code and Forensic AnalysisIR - Incident Responseopen
NIST800-IR-4(13)IR-4(13) Incident Handling | Behavior AnalysisIR - Incident Responseopen
NIST800-IR-4(14)IR-4(14) Incident Handling | Security Operations CenterIR - Incident Responseopen
NIST800-IR-4(15)IR-4(15) Incident Handling | Public Relations and Reputation RepairIR - Incident Responseopen
NIST800-IR-5IR-5 Incident MonitoringIR - Incident Responseopen
NIST800-IR-5(1)IR-5(1) Incident Monitoring | Automated Tracking, Data Collection, and AnalysisIR - Incident Responseopen
NIST800-IR-6IR-6 Incident ReportingIR - Incident Responseopen
NIST800-IR-6(1)IR-6(1) Incident Reporting | Automated ReportingIR - Incident Responseopen
NIST800-IR-6(2)IR-6(2) Incident Reporting | Vulnerabilities Related to IncidentsIR - Incident Responseopen
NIST800-IR-6(3)IR-6(3) Incident Reporting | Supply Chain CoordinationIR - Incident Responseopen
NIST800-IR-7IR-7 Incident Response AssistanceIR - Incident Responseopen
NIST800-IR-7(1)IR-7(1) Incident Response Assistance | Automation Support for Availability of Information and SupportIR - Incident Responseopen
NIST800-IR-7(2)IR-7(2) Incident Response Assistance | Coordination with External ProvidersIR - Incident Responseopen
NIST800-IR-8IR-8 Incident Response PlanIR - Incident Responseopen
NIST800-IR-8(1)IR-8(1) Incident Response Plan | BreachesIR - Incident Responseopen
NIST800-IR-9IR-9 Information Spillage ResponseIR - Incident Responseopen
NIST800-IR-9(2)IR-9(2) Information Spillage Response | TrainingIR - Incident Responseopen
NIST800-IR-9(3)IR-9(3) Information Spillage Response | Post-spill OperationsIR - Incident Responseopen
NIST800-IR-9(4)IR-9(4) Information Spillage Response | Exposure to Unauthorized PersonnelIR - Incident Responseopen
NIST800-MA-1MA-1 Policy and ProceduresMA - Maintenanceopen
NIST800-MA-2MA-2 Controlled MaintenanceMA - Maintenanceopen
NIST800-MA-2(2)MA-2(2) Controlled Maintenance | Automated Maintenance ActivitiesMA - Maintenanceopen
NIST800-MA-3MA-3 Maintenance ToolsMA - Maintenanceopen
NIST800-MA-3(1)MA-3(1) Maintenance Tools | Inspect ToolsMA - Maintenanceopen
NIST800-MA-3(2)MA-3(2) Maintenance Tools | Inspect MediaMA - Maintenanceopen
NIST800-MA-3(3)MA-3(3) Maintenance Tools | Prevent Unauthorized RemovalMA - Maintenanceopen
NIST800-MA-3(4)MA-3(4) Maintenance Tools | Restricted Tool UseMA - Maintenanceopen
NIST800-MA-3(5)MA-3(5) Maintenance Tools | Execution with PrivilegeMA - Maintenanceopen
NIST800-MA-3(6)MA-3(6) Maintenance Tools | Software Updates and PatchesMA - Maintenanceopen
NIST800-MA-4MA-4 Nonlocal MaintenanceMA - Maintenanceopen
NIST800-MA-4(1)MA-4(1) Nonlocal Maintenance | Logging and ReviewMA - Maintenanceopen
NIST800-MA-4(3)MA-4(3) Nonlocal Maintenance | Comparable Security and SanitizationMA - Maintenanceopen
NIST800-MA-4(4)MA-4(4) Nonlocal Maintenance | Authentication and Separation of Maintenance SessionsMA - Maintenanceopen
NIST800-MA-4(5)MA-4(5) Nonlocal Maintenance | Approvals and NotificationsMA - Maintenanceopen
NIST800-MA-4(6)MA-4(6) Nonlocal Maintenance | Cryptographic ProtectionMA - Maintenanceopen
NIST800-MA-4(7)MA-4(7) Nonlocal Maintenance | Disconnect VerificationMA - Maintenanceopen
NIST800-MA-5MA-5 Maintenance PersonnelMA - Maintenanceopen
NIST800-MA-5(1)MA-5(1) Maintenance Personnel | Individuals Without Appropriate AccessMA - Maintenanceopen
NIST800-MA-5(2)MA-5(2) Maintenance Personnel | Security Clearances for Classified SystemsMA - Maintenanceopen
NIST800-MA-5(3)MA-5(3) Maintenance Personnel | Citizenship Requirements for Classified SystemsMA - Maintenanceopen
NIST800-MA-5(4)MA-5(4) Maintenance Personnel | Foreign NationalsMA - Maintenanceopen
NIST800-MA-5(5)MA-5(5) Maintenance Personnel | Non-system MaintenanceMA - Maintenanceopen
NIST800-MA-6MA-6 Timely MaintenanceMA - Maintenanceopen
NIST800-MA-6(1)MA-6(1) Timely Maintenance | Preventive MaintenanceMA - Maintenanceopen
NIST800-MA-6(2)MA-6(2) Timely Maintenance | Predictive MaintenanceMA - Maintenanceopen
NIST800-MA-6(3)MA-6(3) Timely Maintenance | Automated Support for Predictive MaintenanceMA - Maintenanceopen
NIST800-MA-7MA-7 Field MaintenanceMA - Maintenanceopen
NIST800-MP-1MP-1 Policy and ProceduresMP - Media Protectionopen
NIST800-MP-2MP-2 Media AccessMP - Media Protectionopen
NIST800-MP-3MP-3 Media MarkingMP - Media Protectionopen
NIST800-MP-4MP-4 Media StorageMP - Media Protectionopen
NIST800-MP-4(2)MP-4(2) Media Storage | Automated Restricted AccessMP - Media Protectionopen
NIST800-MP-5MP-5 Media TransportMP - Media Protectionopen
NIST800-MP-5(3)MP-5(3) Media Transport | CustodiansMP - Media Protectionopen
NIST800-MP-6MP-6 Media SanitizationMP - Media Protectionopen
NIST800-MP-6(1)MP-6(1) Media Sanitization | Review, Approve, Track, Document, and VerifyMP - Media Protectionopen
NIST800-MP-6(2)MP-6(2) Media Sanitization | Equipment TestingMP - Media Protectionopen
NIST800-MP-6(3)MP-6(3) Media Sanitization | Nondestructive TechniquesMP - Media Protectionopen
NIST800-MP-6(7)MP-6(7) Media Sanitization | Dual AuthorizationMP - Media Protectionopen
NIST800-MP-6(8)MP-6(8) Media Sanitization | Remote Purging or Wiping of InformationMP - Media Protectionopen
NIST800-MP-7MP-7 Media UseMP - Media Protectionopen
NIST800-MP-7(2)MP-7(2) Media Use | Prohibit Use of Sanitization-resistant MediaMP - Media Protectionopen
NIST800-MP-8MP-8 Media DowngradingMP - Media Protectionopen
NIST800-MP-8(1)MP-8(1) Media Downgrading | Documentation of ProcessMP - Media Protectionopen
NIST800-MP-8(2)MP-8(2) Media Downgrading | Equipment TestingMP - Media Protectionopen
NIST800-MP-8(3)MP-8(3) Media Downgrading | Controlled Unclassified InformationMP - Media Protectionopen
NIST800-MP-8(4)MP-8(4) Media Downgrading | Classified InformationMP - Media Protectionopen
NIST800-PE-1PE-1 Policy and ProceduresPE - Physical and Environmental Protectionopen
NIST800-PE-2PE-2 Physical Access AuthorizationsPE - Physical and Environmental Protectionopen
NIST800-PE-2(1)PE-2(1) Physical Access Authorizations | Access by Position or RolePE - Physical and Environmental Protectionopen
NIST800-PE-2(2)PE-2(2) Physical Access Authorizations | Two Forms of IdentificationPE - Physical and Environmental Protectionopen
NIST800-PE-2(3)PE-2(3) Physical Access Authorizations | Restrict Unescorted AccessPE - Physical and Environmental Protectionopen
NIST800-PE-3PE-3 Physical Access ControlPE - Physical and Environmental Protectionopen
NIST800-PE-3(1)PE-3(1) Physical Access Control | System AccessPE - Physical and Environmental Protectionopen
NIST800-PE-3(2)PE-3(2) Physical Access Control | Facility and SystemsPE - Physical and Environmental Protectionopen
NIST800-PE-3(3)PE-3(3) Physical Access Control | Continuous GuardsPE - Physical and Environmental Protectionopen
NIST800-PE-3(4)PE-3(4) Physical Access Control | Lockable CasingsPE - Physical and Environmental Protectionopen
NIST800-PE-3(5)PE-3(5) Physical Access Control | Tamper ProtectionPE - Physical and Environmental Protectionopen
NIST800-PE-3(7)PE-3(7) Physical Access Control | Physical BarriersPE - Physical and Environmental Protectionopen
NIST800-PE-3(8)PE-3(8) Physical Access Control | Access Control VestibulesPE - Physical and Environmental Protectionopen
NIST800-PE-4PE-4 Access Control for TransmissionPE - Physical and Environmental Protectionopen
NIST800-PE-5PE-5 Access Control for Output DevicesPE - Physical and Environmental Protectionopen
NIST800-PE-5(2)PE-5(2) Access Control for Output Devices | Link to Individual IdentityPE - Physical and Environmental Protectionopen
NIST800-PE-6PE-6 Monitoring Physical AccessPE - Physical and Environmental Protectionopen
NIST800-PE-6(1)PE-6(1) Monitoring Physical Access | Intrusion Alarms and Surveillance EquipmentPE - Physical and Environmental Protectionopen
NIST800-PE-6(2)PE-6(2) Monitoring Physical Access | Automated Intrusion Recognition and ResponsesPE - Physical and Environmental Protectionopen
NIST800-PE-6(3)PE-6(3) Monitoring Physical Access | Video SurveillancePE - Physical and Environmental Protectionopen
NIST800-PE-6(4)PE-6(4) Monitoring Physical Access | Monitoring Physical Access to SystemsPE - Physical and Environmental Protectionopen
NIST800-PE-8PE-8 Visitor Access RecordsPE - Physical and Environmental Protectionopen
NIST800-PE-8(1)PE-8(1) Visitor Access Records | Automated Records Maintenance and ReviewPE - Physical and Environmental Protectionopen
NIST800-PE-8(3)PE-8(3) Visitor Access Records | Limit Personally Identifiable Information ElementsPE - Physical and Environmental Protectionopen
NIST800-PE-9PE-9 Power Equipment and CablingPE - Physical and Environmental Protectionopen
NIST800-PE-9(1)PE-9(1) Power Equipment and Cabling | Redundant CablingPE - Physical and Environmental Protectionopen
NIST800-PE-9(2)PE-9(2) Power Equipment and Cabling | Automatic Voltage ControlsPE - Physical and Environmental Protectionopen
NIST800-PE-10PE-10 Emergency ShutoffPE - Physical and Environmental Protectionopen
NIST800-PE-11PE-11 Emergency PowerPE - Physical and Environmental Protectionopen
NIST800-PE-11(1)PE-11(1) Emergency Power | Alternate Power Supply: Minimal Operational CapabilityPE - Physical and Environmental Protectionopen
NIST800-PE-11(2)PE-11(2) Emergency Power | Alternate Power Supply: Self-containedPE - Physical and Environmental Protectionopen
NIST800-PE-12PE-12 Emergency LightingPE - Physical and Environmental Protectionopen
NIST800-PE-12(1)PE-12(1) Emergency Lighting | Essential Mission and Business FunctionsPE - Physical and Environmental Protectionopen
NIST800-PE-13PE-13 Fire ProtectionPE - Physical and Environmental Protectionopen
NIST800-PE-13(1)PE-13(1) Fire Protection | Detection Systems: Automatic Activation and NotificationPE - Physical and Environmental Protectionopen
NIST800-PE-13(2)PE-13(2) Fire Protection | Suppression Systems: Automatic Activation and NotificationPE - Physical and Environmental Protectionopen
NIST800-PE-13(4)PE-13(4) Fire Protection | InspectionsPE - Physical and Environmental Protectionopen
NIST800-PE-14PE-14 Environmental ControlsPE - Physical and Environmental Protectionopen
NIST800-PE-14(1)PE-14(1) Environmental Controls | Automatic ControlsPE - Physical and Environmental Protectionopen
NIST800-PE-14(2)PE-14(2) Environmental Controls | Monitoring with Alarms and NotificationsPE - Physical and Environmental Protectionopen
NIST800-PE-15PE-15 Water Damage ProtectionPE - Physical and Environmental Protectionopen
NIST800-PE-15(1)PE-15(1) Water Damage Protection | Automation SupportPE - Physical and Environmental Protectionopen
NIST800-PE-16PE-16 Delivery and RemovalPE - Physical and Environmental Protectionopen
NIST800-PE-17PE-17 Alternate Work SitePE - Physical and Environmental Protectionopen
NIST800-PE-18PE-18 Location of System ComponentsPE - Physical and Environmental Protectionopen
NIST800-PE-19PE-19 Information LeakagePE - Physical and Environmental Protectionopen
NIST800-PE-19(1)PE-19(1) Information Leakage | National Emissions Policies and ProceduresPE - Physical and Environmental Protectionopen
NIST800-PE-20PE-20 Asset Monitoring and TrackingPE - Physical and Environmental Protectionopen
NIST800-PE-21PE-21 Electromagnetic Pulse ProtectionPE - Physical and Environmental Protectionopen
NIST800-PE-22PE-22 Component MarkingPE - Physical and Environmental Protectionopen
NIST800-PE-23PE-23 Facility LocationPE - Physical and Environmental Protectionopen
NIST800-PL-1PL-1 Policy and ProceduresPL - Planningopen
NIST800-PL-2PL-2 System Security and Privacy PlansPL - Planningopen
NIST800-PL-4PL-4 Rules of BehaviorPL - Planningopen
NIST800-PL-4(1)PL-4(1) Rules of Behavior | Social Media and External Site/Application Usage RestrictionsPL - Planningopen
NIST800-PL-7PL-7 Concept of OperationsPL - Planningopen
NIST800-PL-8PL-8 Security and Privacy ArchitecturesPL - Planningopen
NIST800-PL-8(1)PL-8(1) Security and Privacy Architectures | Defense in DepthPL - Planningopen
NIST800-PL-8(2)PL-8(2) Security and Privacy Architectures | Supplier DiversityPL - Planningopen
NIST800-PL-9PL-9 Central ManagementPL - Planningopen
NIST800-PL-10PL-10 Baseline SelectionPL - Planningopen
NIST800-PL-11PL-11 Baseline TailoringPL - Planningopen
NIST800-PM-1PM-1 Information Security Program PlanPM - Program Managementopen
NIST800-PM-2PM-2 Information Security Program Leadership RolePM - Program Managementopen
NIST800-PM-3PM-3 Information Security and Privacy ResourcesPM - Program Managementopen
NIST800-PM-4PM-4 Plan of Action and Milestones ProcessPM - Program Managementopen
NIST800-PM-5PM-5 System InventoryPM - Program Managementopen
NIST800-PM-5(1)PM-5(1) System Inventory | Inventory of Personally Identifiable InformationPM - Program Managementopen
NIST800-PM-6PM-6 Measures of PerformancePM - Program Managementopen
NIST800-PM-7PM-7 Enterprise ArchitecturePM - Program Managementopen
NIST800-PM-7(1)PM-7(1) Enterprise Architecture | OffloadingPM - Program Managementopen
NIST800-PM-8PM-8 Critical Infrastructure PlanPM - Program Managementopen
NIST800-PM-9PM-9 Risk Management StrategyPM - Program Managementopen
NIST800-PM-10PM-10 Authorization ProcessPM - Program Managementopen
NIST800-PM-11PM-11 Mission and Business Process DefinitionPM - Program Managementopen
NIST800-PM-12PM-12 Insider Threat ProgramPM - Program Managementopen
NIST800-PM-13PM-13 Security and Privacy WorkforcePM - Program Managementopen
NIST800-PM-14PM-14 Testing, Training, and MonitoringPM - Program Managementopen
NIST800-PM-15PM-15 Security and Privacy Groups and AssociationsPM - Program Managementopen
NIST800-PM-16PM-16 Threat Awareness ProgramPM - Program Managementopen
NIST800-PM-16(1)PM-16(1) Threat Awareness Program | Automated Means for Sharing Threat IntelligencePM - Program Managementopen
NIST800-PM-17PM-17 Protecting Controlled Unclassified Information on External SystemsPM - Program Managementopen
NIST800-PM-18PM-18 Privacy Program PlanPM - Program Managementopen
NIST800-PM-19PM-19 Privacy Program Leadership RolePM - Program Managementopen
NIST800-PM-20PM-20 Dissemination of Privacy Program InformationPM - Program Managementopen
NIST800-PM-20(1)PM-20(1) Dissemination of Privacy Program Information | Privacy Policies on Websites, Applications, and Digital ServicesPM - Program Managementopen
NIST800-PM-21PM-21 Accounting of DisclosuresPM - Program Managementopen
NIST800-PM-22PM-22 Personally Identifiable Information Quality ManagementPM - Program Managementopen
NIST800-PM-23PM-23 Data Governance BodyPM - Program Managementopen
NIST800-PM-24PM-24 Data Integrity BoardPM - Program Managementopen
NIST800-PM-25PM-25 Minimization of Personally Identifiable Information Used in Testing, Training, and ResearchPM - Program Managementopen
NIST800-PM-26PM-26 Complaint ManagementPM - Program Managementopen
NIST800-PM-27PM-27 Privacy ReportingPM - Program Managementopen
NIST800-PM-28PM-28 Risk FramingPM - Program Managementopen
NIST800-PM-29PM-29 Risk Management Program Leadership RolesPM - Program Managementopen
NIST800-PM-30PM-30 Supply Chain Risk Management StrategyPM - Program Managementopen
NIST800-PM-30(1)PM-30(1) Supply Chain Risk Management Strategy | Suppliers of Critical or Mission-essential ItemsPM - Program Managementopen
NIST800-PM-31PM-31 Continuous Monitoring StrategyPM - Program Managementopen
NIST800-PM-32PM-32 PurposingPM - Program Managementopen
NIST800-PS-1PS-1 Policy and ProceduresPS - Personnel Securityopen
NIST800-PS-2PS-2 Position Risk DesignationPS - Personnel Securityopen
NIST800-PS-3PS-3 Personnel ScreeningPS - Personnel Securityopen
NIST800-PS-3(1)PS-3(1) Personnel Screening | Classified InformationPS - Personnel Securityopen
NIST800-PS-3(2)PS-3(2) Personnel Screening | Formal IndoctrinationPS - Personnel Securityopen
NIST800-PS-3(3)PS-3(3) Personnel Screening | Information Requiring Special Protective MeasuresPS - Personnel Securityopen
NIST800-PS-3(4)PS-3(4) Personnel Screening | Citizenship RequirementsPS - Personnel Securityopen
NIST800-PS-4PS-4 Personnel TerminationPS - Personnel Securityopen
NIST800-PS-4(1)PS-4(1) Personnel Termination | Post-employment RequirementsPS - Personnel Securityopen
NIST800-PS-4(2)PS-4(2) Personnel Termination | Automated ActionsPS - Personnel Securityopen
NIST800-PS-5PS-5 Personnel TransferPS - Personnel Securityopen
NIST800-PS-6PS-6 Access AgreementsPS - Personnel Securityopen
NIST800-PS-6(2)PS-6(2) Access Agreements | Classified Information Requiring Special ProtectionPS - Personnel Securityopen
NIST800-PS-6(3)PS-6(3) Access Agreements | Post-employment RequirementsPS - Personnel Securityopen
NIST800-PS-7PS-7 External Personnel SecurityPS - Personnel Securityopen
NIST800-PS-8PS-8 Personnel SanctionsPS - Personnel Securityopen
NIST800-PS-9PS-9 Position DescriptionsPS - Personnel Securityopen
NIST800-PT-1PT-1 Policy and ProceduresPT - PII Processing and Transparencyopen
NIST800-PT-2PT-2 Authority to Process Personally Identifiable InformationPT - PII Processing and Transparencyopen
NIST800-PT-2(1)PT-2(1) Authority to Process Personally Identifiable Information | Data TaggingPT - PII Processing and Transparencyopen
NIST800-PT-2(2)PT-2(2) Authority to Process Personally Identifiable Information | AutomationPT - PII Processing and Transparencyopen
NIST800-PT-3PT-3 Personally Identifiable Information Processing PurposesPT - PII Processing and Transparencyopen
NIST800-PT-3(1)PT-3(1) Personally Identifiable Information Processing Purposes | Data TaggingPT - PII Processing and Transparencyopen
NIST800-PT-3(2)PT-3(2) Personally Identifiable Information Processing Purposes | AutomationPT - PII Processing and Transparencyopen
NIST800-PT-4PT-4 ConsentPT - PII Processing and Transparencyopen
NIST800-PT-4(1)PT-4(1) Consent | Tailored ConsentPT - PII Processing and Transparencyopen
NIST800-PT-4(2)PT-4(2) Consent | Just-in-time ConsentPT - PII Processing and Transparencyopen
NIST800-PT-4(3)PT-4(3) Consent | RevocationPT - PII Processing and Transparencyopen
NIST800-PT-5PT-5 Privacy NoticePT - PII Processing and Transparencyopen
NIST800-PT-5(1)PT-5(1) Privacy Notice | Just-in-time NoticePT - PII Processing and Transparencyopen
NIST800-PT-5(2)PT-5(2) Privacy Notice | Privacy Act StatementsPT - PII Processing and Transparencyopen
NIST800-PT-6PT-6 System of Records NoticePT - PII Processing and Transparencyopen
NIST800-PT-6(1)PT-6(1) System of Records Notice | Routine UsesPT - PII Processing and Transparencyopen
NIST800-PT-6(2)PT-6(2) System of Records Notice | Exemption RulesPT - PII Processing and Transparencyopen
NIST800-PT-7PT-7 Specific Categories of Personally Identifiable InformationPT - PII Processing and Transparencyopen
NIST800-PT-7(1)PT-7(1) Specific Categories of Personally Identifiable Information | Social Security NumbersPT - PII Processing and Transparencyopen
NIST800-PT-7(2)PT-7(2) Specific Categories of Personally Identifiable Information | First Amendment InformationPT - PII Processing and Transparencyopen
NIST800-PT-8PT-8 Computer Matching RequirementsPT - PII Processing and Transparencyopen
NIST800-RA-1RA-1 Policy and ProceduresRA - Risk Assessmentopen
NIST800-RA-2RA-2 Security CategorizationRA - Risk Assessmentopen
NIST800-RA-2(1)RA-2(1) Security Categorization | Impact-level PrioritizationRA - Risk Assessmentopen
NIST800-RA-3RA-3 Risk AssessmentRA - Risk Assessmentopen
NIST800-RA-3(1)RA-3(1) Risk Assessment | Supply Chain Risk AssessmentRA - Risk Assessmentopen
NIST800-RA-3(2)RA-3(2) Risk Assessment | Use of All-source IntelligenceRA - Risk Assessmentopen
NIST800-RA-3(3)RA-3(3) Risk Assessment | Dynamic Threat AwarenessRA - Risk Assessmentopen
NIST800-RA-3(4)RA-3(4) Risk Assessment | Predictive Cyber AnalyticsRA - Risk Assessmentopen
NIST800-RA-5RA-5 Vulnerability Monitoring and ScanningRA - Risk Assessmentopen
NIST800-RA-5(2)RA-5(2) Vulnerability Monitoring and Scanning | Update Vulnerabilities to Be ScannedRA - Risk Assessmentopen
NIST800-RA-5(3)RA-5(3) Vulnerability Monitoring and Scanning | Breadth and Depth of CoverageRA - Risk Assessmentopen
NIST800-RA-5(4)RA-5(4) Vulnerability Monitoring and Scanning | Discoverable InformationRA - Risk Assessmentopen
NIST800-RA-5(5)RA-5(5) Vulnerability Monitoring and Scanning | Privileged AccessRA - Risk Assessmentopen
NIST800-RA-5(6)RA-5(6) Vulnerability Monitoring and Scanning | Automated Trend AnalysesRA - Risk Assessmentopen
NIST800-RA-5(8)RA-5(8) Vulnerability Monitoring and Scanning | Review Historic Audit LogsRA - Risk Assessmentopen
NIST800-RA-5(10)RA-5(10) Vulnerability Monitoring and Scanning | Correlate Scanning InformationRA - Risk Assessmentopen
NIST800-RA-5(11)RA-5(11) Vulnerability Monitoring and Scanning | Public Disclosure ProgramRA - Risk Assessmentopen
NIST800-RA-6RA-6 Technical Surveillance Countermeasures SurveyRA - Risk Assessmentopen
NIST800-RA-7RA-7 Risk ResponseRA - Risk Assessmentopen
NIST800-RA-8RA-8 Privacy Impact AssessmentsRA - Risk Assessmentopen
NIST800-RA-9RA-9 Criticality AnalysisRA - Risk Assessmentopen
NIST800-RA-10RA-10 Threat HuntingRA - Risk Assessmentopen
NIST800-SA-1SA-1 Policy and ProceduresSA - System and Services Acquisitionopen
NIST800-SA-2SA-2 Allocation of ResourcesSA - System and Services Acquisitionopen
NIST800-SA-3SA-3 System Development Life CycleSA - System and Services Acquisitionopen
NIST800-SA-3(1)SA-3(1) System Development Life Cycle | Manage Preproduction EnvironmentSA - System and Services Acquisitionopen
NIST800-SA-3(2)SA-3(2) System Development Life Cycle | Use of Live or Operational DataSA - System and Services Acquisitionopen
NIST800-SA-3(3)SA-3(3) System Development Life Cycle | Technology RefreshSA - System and Services Acquisitionopen
NIST800-SA-4SA-4 Acquisition ProcessSA - System and Services Acquisitionopen
NIST800-SA-4(1)SA-4(1) Acquisition Process | Functional Properties of ControlsSA - System and Services Acquisitionopen
NIST800-SA-4(2)SA-4(2) Acquisition Process | Design and Implementation Information for ControlsSA - System and Services Acquisitionopen
NIST800-SA-4(3)SA-4(3) Acquisition Process | Development Methods, Techniques, and PracticesSA - System and Services Acquisitionopen
NIST800-SA-4(5)SA-4(5) Acquisition Process | System, Component, and Service ConfigurationsSA - System and Services Acquisitionopen
NIST800-SA-4(6)SA-4(6) Acquisition Process | Use of Information Assurance ProductsSA - System and Services Acquisitionopen
NIST800-SA-4(7)SA-4(7) Acquisition Process | NIAP-approved Protection ProfilesSA - System and Services Acquisitionopen
NIST800-SA-4(8)SA-4(8) Acquisition Process | Continuous Monitoring Plan for ControlsSA - System and Services Acquisitionopen
NIST800-SA-4(9)SA-4(9) Acquisition Process | Functions, Ports, Protocols, and Services in UseSA - System and Services Acquisitionopen
NIST800-SA-4(10)SA-4(10) Acquisition Process | Use of Approved PIV ProductsSA - System and Services Acquisitionopen
NIST800-SA-4(11)SA-4(11) Acquisition Process | System of RecordsSA - System and Services Acquisitionopen
NIST800-SA-4(12)SA-4(12) Acquisition Process | Data OwnershipSA - System and Services Acquisitionopen
NIST800-SA-5SA-5 System DocumentationSA - System and Services Acquisitionopen
NIST800-SA-8SA-8 Security and Privacy Engineering PrinciplesSA - System and Services Acquisitionopen
NIST800-SA-8(1)SA-8(1) Security and Privacy Engineering Principles | Clear AbstractionsSA - System and Services Acquisitionopen
NIST800-SA-8(2)SA-8(2) Security and Privacy Engineering Principles | Least Common MechanismSA - System and Services Acquisitionopen
NIST800-SA-8(3)SA-8(3) Security and Privacy Engineering Principles | Modularity and LayeringSA - System and Services Acquisitionopen
NIST800-SA-8(4)SA-8(4) Security and Privacy Engineering Principles | Partially Ordered DependenciesSA - System and Services Acquisitionopen
NIST800-SA-8(5)SA-8(5) Security and Privacy Engineering Principles | Efficiently Mediated AccessSA - System and Services Acquisitionopen
NIST800-SA-8(6)SA-8(6) Security and Privacy Engineering Principles | Minimized SharingSA - System and Services Acquisitionopen
NIST800-SA-8(7)SA-8(7) Security and Privacy Engineering Principles | Reduced ComplexitySA - System and Services Acquisitionopen
NIST800-SA-8(8)SA-8(8) Security and Privacy Engineering Principles | Secure EvolvabilitySA - System and Services Acquisitionopen
NIST800-SA-8(9)SA-8(9) Security and Privacy Engineering Principles | Trusted ComponentsSA - System and Services Acquisitionopen
NIST800-SA-8(10)SA-8(10) Security and Privacy Engineering Principles | Hierarchical TrustSA - System and Services Acquisitionopen
NIST800-SA-8(11)SA-8(11) Security and Privacy Engineering Principles | Inverse Modification ThresholdSA - System and Services Acquisitionopen
NIST800-SA-8(12)SA-8(12) Security and Privacy Engineering Principles | Hierarchical ProtectionSA - System and Services Acquisitionopen
NIST800-SA-8(13)SA-8(13) Security and Privacy Engineering Principles | Minimized Security ElementsSA - System and Services Acquisitionopen
NIST800-SA-8(14)SA-8(14) Security and Privacy Engineering Principles | Least PrivilegeSA - System and Services Acquisitionopen
NIST800-SA-8(15)SA-8(15) Security and Privacy Engineering Principles | Predicate PermissionSA - System and Services Acquisitionopen
NIST800-SA-8(16)SA-8(16) Security and Privacy Engineering Principles | Self-reliant TrustworthinessSA - System and Services Acquisitionopen
NIST800-SA-8(17)SA-8(17) Security and Privacy Engineering Principles | Secure Distributed CompositionSA - System and Services Acquisitionopen
NIST800-SA-8(18)SA-8(18) Security and Privacy Engineering Principles | Trusted Communications ChannelsSA - System and Services Acquisitionopen
NIST800-SA-8(19)SA-8(19) Security and Privacy Engineering Principles | Continuous ProtectionSA - System and Services Acquisitionopen
NIST800-SA-8(20)SA-8(20) Security and Privacy Engineering Principles | Secure Metadata ManagementSA - System and Services Acquisitionopen
NIST800-SA-8(21)SA-8(21) Security and Privacy Engineering Principles | Self-analysisSA - System and Services Acquisitionopen
NIST800-SA-8(22)SA-8(22) Security and Privacy Engineering Principles | Accountability and TraceabilitySA - System and Services Acquisitionopen
NIST800-SA-8(23)SA-8(23) Security and Privacy Engineering Principles | Secure DefaultsSA - System and Services Acquisitionopen
NIST800-SA-8(24)SA-8(24) Security and Privacy Engineering Principles | Secure Failure and RecoverySA - System and Services Acquisitionopen
NIST800-SA-8(25)SA-8(25) Security and Privacy Engineering Principles | Economic SecuritySA - System and Services Acquisitionopen
NIST800-SA-8(26)SA-8(26) Security and Privacy Engineering Principles | Performance SecuritySA - System and Services Acquisitionopen
NIST800-SA-8(27)SA-8(27) Security and Privacy Engineering Principles | Human Factored SecuritySA - System and Services Acquisitionopen
NIST800-SA-8(28)SA-8(28) Security and Privacy Engineering Principles | Acceptable SecuritySA - System and Services Acquisitionopen
NIST800-SA-8(29)SA-8(29) Security and Privacy Engineering Principles | Repeatable and Documented ProceduresSA - System and Services Acquisitionopen
NIST800-SA-8(30)SA-8(30) Security and Privacy Engineering Principles | Procedural RigorSA - System and Services Acquisitionopen
NIST800-SA-8(31)SA-8(31) Security and Privacy Engineering Principles | Secure System ModificationSA - System and Services Acquisitionopen
NIST800-SA-8(32)SA-8(32) Security and Privacy Engineering Principles | Sufficient DocumentationSA - System and Services Acquisitionopen
NIST800-SA-8(33)SA-8(33) Security and Privacy Engineering Principles | MinimizationSA - System and Services Acquisitionopen
NIST800-SA-9SA-9 External System ServicesSA - System and Services Acquisitionopen
NIST800-SA-9(1)SA-9(1) External System Services | Risk Assessments and Organizational ApprovalsSA - System and Services Acquisitionopen
NIST800-SA-9(2)SA-9(2) External System Services | Identification of Functions, Ports, Protocols, and ServicesSA - System and Services Acquisitionopen
NIST800-SA-9(3)SA-9(3) External System Services | Establish and Maintain Trust Relationship with ProvidersSA - System and Services Acquisitionopen
NIST800-SA-9(4)SA-9(4) External System Services | Consistent Interests of Consumers and ProvidersSA - System and Services Acquisitionopen
NIST800-SA-9(5)SA-9(5) External System Services | Processing, Storage, and Service LocationSA - System and Services Acquisitionopen
NIST800-SA-9(6)SA-9(6) External System Services | Organization-controlled Cryptographic KeysSA - System and Services Acquisitionopen
NIST800-SA-9(7)SA-9(7) External System Services | Organization-controlled Integrity CheckingSA - System and Services Acquisitionopen
NIST800-SA-9(8)SA-9(8) External System Services | Processing and Storage Location: U.S. JurisdictionSA - System and Services Acquisitionopen
NIST800-SA-10SA-10 Developer Configuration ManagementSA - System and Services Acquisitionopen
NIST800-SA-10(1)SA-10(1) Developer Configuration Management | Software and Firmware Integrity VerificationSA - System and Services Acquisitionopen
NIST800-SA-10(2)SA-10(2) Developer Configuration Management | Alternative Configuration Management ProcessesSA - System and Services Acquisitionopen
NIST800-SA-10(3)SA-10(3) Developer Configuration Management | Hardware Integrity VerificationSA - System and Services Acquisitionopen
NIST800-SA-10(4)SA-10(4) Developer Configuration Management | Trusted GenerationSA - System and Services Acquisitionopen
NIST800-SA-10(5)SA-10(5) Developer Configuration Management | Mapping Integrity for Version ControlSA - System and Services Acquisitionopen
NIST800-SA-10(6)SA-10(6) Developer Configuration Management | Trusted DistributionSA - System and Services Acquisitionopen
NIST800-SA-10(7)SA-10(7) Developer Configuration Management | Security and Privacy RepresentativesSA - System and Services Acquisitionopen
NIST800-SA-11SA-11 Developer Testing and EvaluationSA - System and Services Acquisitionopen
NIST800-SA-11(1)SA-11(1) Developer Testing and Evaluation | Static Code AnalysisSA - System and Services Acquisitionopen
NIST800-SA-11(2)SA-11(2) Developer Testing and Evaluation | Threat Modeling and Vulnerability AnalysesSA - System and Services Acquisitionopen
NIST800-SA-11(3)SA-11(3) Developer Testing and Evaluation | Independent Verification of Assessment Plans and EvidenceSA - System and Services Acquisitionopen
NIST800-SA-11(4)SA-11(4) Developer Testing and Evaluation | Manual Code ReviewsSA - System and Services Acquisitionopen
NIST800-SA-11(5)SA-11(5) Developer Testing and Evaluation | Penetration TestingSA - System and Services Acquisitionopen
NIST800-SA-11(6)SA-11(6) Developer Testing and Evaluation | Attack Surface ReviewsSA - System and Services Acquisitionopen
NIST800-SA-11(7)SA-11(7) Developer Testing and Evaluation | Verify Scope of Testing and EvaluationSA - System and Services Acquisitionopen
NIST800-SA-11(8)SA-11(8) Developer Testing and Evaluation | Dynamic Code AnalysisSA - System and Services Acquisitionopen
NIST800-SA-11(9)SA-11(9) Developer Testing and Evaluation | Interactive Application Security TestingSA - System and Services Acquisitionopen
NIST800-SA-15SA-15 Development Process, Standards, and ToolsSA - System and Services Acquisitionopen
NIST800-SA-15(1)SA-15(1) Development Process, Standards, and Tools | Quality MetricsSA - System and Services Acquisitionopen
NIST800-SA-15(2)SA-15(2) Development Process, Standards, and Tools | Security and Privacy Tracking ToolsSA - System and Services Acquisitionopen
NIST800-SA-15(3)SA-15(3) Development Process, Standards, and Tools | Criticality AnalysisSA - System and Services Acquisitionopen
NIST800-SA-15(5)SA-15(5) Development Process, Standards, and Tools | Attack Surface ReductionSA - System and Services Acquisitionopen
NIST800-SA-15(6)SA-15(6) Development Process, Standards, and Tools | Continuous ImprovementSA - System and Services Acquisitionopen
NIST800-SA-15(7)SA-15(7) Development Process, Standards, and Tools | Automated Vulnerability AnalysisSA - System and Services Acquisitionopen
NIST800-SA-15(8)SA-15(8) Development Process, Standards, and Tools | Reuse of Threat and Vulnerability InformationSA - System and Services Acquisitionopen
NIST800-SA-15(10)SA-15(10) Development Process, Standards, and Tools | Incident Response PlanSA - System and Services Acquisitionopen
NIST800-SA-15(11)SA-15(11) Development Process, Standards, and Tools | Archive System or ComponentSA - System and Services Acquisitionopen
NIST800-SA-15(12)SA-15(12) Development Process, Standards, and Tools | Minimize Personally Identifiable InformationSA - System and Services Acquisitionopen
NIST800-SA-15(13)SA-15(13) Development Process, Standards, and Tools | Logging SyntaxSA - System and Services Acquisitionopen
NIST800-SA-16SA-16 Developer-provided TrainingSA - System and Services Acquisitionopen
NIST800-SA-17SA-17 Developer Security and Privacy Architecture and DesignSA - System and Services Acquisitionopen
NIST800-SA-17(1)SA-17(1) Developer Security and Privacy Architecture and Design | Formal Policy ModelSA - System and Services Acquisitionopen
NIST800-SA-17(2)SA-17(2) Developer Security and Privacy Architecture and Design | Security-relevant ComponentsSA - System and Services Acquisitionopen
NIST800-SA-17(3)SA-17(3) Developer Security and Privacy Architecture and Design | Formal CorrespondenceSA - System and Services Acquisitionopen
NIST800-SA-17(4)SA-17(4) Developer Security and Privacy Architecture and Design | Informal CorrespondenceSA - System and Services Acquisitionopen
NIST800-SA-17(5)SA-17(5) Developer Security and Privacy Architecture and Design | Conceptually Simple DesignSA - System and Services Acquisitionopen
NIST800-SA-17(6)SA-17(6) Developer Security and Privacy Architecture and Design | Structure for TestingSA - System and Services Acquisitionopen
NIST800-SA-17(7)SA-17(7) Developer Security and Privacy Architecture and Design | Structure for Least PrivilegeSA - System and Services Acquisitionopen
NIST800-SA-17(8)SA-17(8) Developer Security and Privacy Architecture and Design | OrchestrationSA - System and Services Acquisitionopen
NIST800-SA-17(9)SA-17(9) Developer Security and Privacy Architecture and Design | Design DiversitySA - System and Services Acquisitionopen
NIST800-SA-20SA-20 Customized Development of Critical ComponentsSA - System and Services Acquisitionopen
NIST800-SA-21SA-21 Developer ScreeningSA - System and Services Acquisitionopen
NIST800-SA-22SA-22 Unsupported System ComponentsSA - System and Services Acquisitionopen
NIST800-SA-23SA-23 SpecializationSA - System and Services Acquisitionopen
NIST800-SA-24SA-24 Design For Cyber ResiliencySA - System and Services Acquisitionopen
NIST800-SC-1SC-1 Policy and ProceduresSC - System and Communications Protectionopen
NIST800-SC-2SC-2 Separation of System and User FunctionalitySC - System and Communications Protectionopen
NIST800-SC-2(1)SC-2(1) Separation of System and User Functionality | Interfaces for Non-privileged UsersSC - System and Communications Protectionopen
NIST800-SC-2(2)SC-2(2) Separation of System and User Functionality | DisassociabilitySC - System and Communications Protectionopen
NIST800-SC-3SC-3 Security Function IsolationSC - System and Communications Protectionopen
NIST800-SC-3(1)SC-3(1) Security Function Isolation | Hardware SeparationSC - System and Communications Protectionopen
NIST800-SC-3(2)SC-3(2) Security Function Isolation | Access and Flow Control FunctionsSC - System and Communications Protectionopen
NIST800-SC-3(3)SC-3(3) Security Function Isolation | Minimize Nonsecurity FunctionalitySC - System and Communications Protectionopen
NIST800-SC-3(4)SC-3(4) Security Function Isolation | Module Coupling and CohesivenessSC - System and Communications Protectionopen
NIST800-SC-3(5)SC-3(5) Security Function Isolation | Layered StructuresSC - System and Communications Protectionopen
NIST800-SC-4SC-4 Information in Shared System ResourcesSC - System and Communications Protectionopen
NIST800-SC-4(2)SC-4(2) Information in Shared System Resources | Multilevel or Periods ProcessingSC - System and Communications Protectionopen
NIST800-SC-5SC-5 Denial-of-service ProtectionSC - System and Communications Protectionopen
NIST800-SC-5(1)SC-5(1) Denial-of-service Protection | Restrict Ability to Attack Other SystemsSC - System and Communications Protectionopen
NIST800-SC-5(2)SC-5(2) Denial-of-service Protection | Capacity, Bandwidth, and RedundancySC - System and Communications Protectionopen
NIST800-SC-5(3)SC-5(3) Denial-of-service Protection | Detection and MonitoringSC - System and Communications Protectionopen
NIST800-SC-6SC-6 Resource AvailabilitySC - System and Communications Protectionopen
NIST800-SC-7SC-7 Boundary ProtectionSC - System and Communications Protectionopen
NIST800-SC-7(3)SC-7(3) Boundary Protection | Access PointsSC - System and Communications Protectionopen
NIST800-SC-7(4)SC-7(4) Boundary Protection | External Telecommunications ServicesSC - System and Communications Protectionopen
NIST800-SC-7(5)SC-7(5) Boundary Protection | Deny by Default: Allow by ExceptionSC - System and Communications Protectionopen
NIST800-SC-7(7)SC-7(7) Boundary Protection | Split Tunneling for Remote DevicesSC - System and Communications Protectionopen
NIST800-SC-7(8)SC-7(8) Boundary Protection | Route Traffic to Authenticated Proxy ServersSC - System and Communications Protectionopen
NIST800-SC-7(9)SC-7(9) Boundary Protection | Restrict Threatening Outgoing Communications TrafficSC - System and Communications Protectionopen
NIST800-SC-7(10)SC-7(10) Boundary Protection | Prevent ExfiltrationSC - System and Communications Protectionopen
NIST800-SC-7(11)SC-7(11) Boundary Protection | Restrict Incoming Communications TrafficSC - System and Communications Protectionopen
NIST800-SC-7(12)SC-7(12) Boundary Protection | Host-based ProtectionSC - System and Communications Protectionopen
NIST800-SC-7(13)SC-7(13) Boundary Protection | Isolation of Security Tools, Mechanisms, and Support ComponentsSC - System and Communications Protectionopen
NIST800-SC-7(14)SC-7(14) Boundary Protection | Protect Against Unauthorized Physical ConnectionsSC - System and Communications Protectionopen
NIST800-SC-7(15)SC-7(15) Boundary Protection | Networked Privileged AccessesSC - System and Communications Protectionopen
NIST800-SC-7(16)SC-7(16) Boundary Protection | Prevent Discovery of System ComponentsSC - System and Communications Protectionopen
NIST800-SC-7(17)SC-7(17) Boundary Protection | Automated Enforcement of Protocol FormatsSC - System and Communications Protectionopen
NIST800-SC-7(18)SC-7(18) Boundary Protection | Fail SecureSC - System and Communications Protectionopen
NIST800-SC-7(19)SC-7(19) Boundary Protection | Block Communication from Non-organizationally Configured HostsSC - System and Communications Protectionopen
NIST800-SC-7(20)SC-7(20) Boundary Protection | Dynamic Isolation and SegregationSC - System and Communications Protectionopen
NIST800-SC-7(21)SC-7(21) Boundary Protection | Isolation of System ComponentsSC - System and Communications Protectionopen
NIST800-SC-7(22)SC-7(22) Boundary Protection | Separate Subnets for Connecting to Different Security DomainsSC - System and Communications Protectionopen
NIST800-SC-7(23)SC-7(23) Boundary Protection | Disable Sender Feedback on Protocol Validation FailureSC - System and Communications Protectionopen
NIST800-SC-7(24)SC-7(24) Boundary Protection | Personally Identifiable InformationSC - System and Communications Protectionopen
NIST800-SC-7(25)SC-7(25) Boundary Protection | Unclassified National Security System ConnectionsSC - System and Communications Protectionopen
NIST800-SC-7(26)SC-7(26) Boundary Protection | Classified National Security System ConnectionsSC - System and Communications Protectionopen
NIST800-SC-7(27)SC-7(27) Boundary Protection | Unclassified Non-national Security System ConnectionsSC - System and Communications Protectionopen
NIST800-SC-7(28)SC-7(28) Boundary Protection | Connections to Public NetworksSC - System and Communications Protectionopen
NIST800-SC-7(29)SC-7(29) Boundary Protection | Separate Subnets to Isolate FunctionsSC - System and Communications Protectionopen
NIST800-SC-8SC-8 Transmission Confidentiality and IntegritySC - System and Communications Protectionopen
NIST800-SC-8(1)SC-8(1) Transmission Confidentiality and Integrity | Cryptographic ProtectionSC - System and Communications Protectionopen
NIST800-SC-8(2)SC-8(2) Transmission Confidentiality and Integrity | Pre- and Post-transmission HandlingSC - System and Communications Protectionopen
NIST800-SC-8(3)SC-8(3) Transmission Confidentiality and Integrity | Cryptographic Protection for Message ExternalsSC - System and Communications Protectionopen
NIST800-SC-8(4)SC-8(4) Transmission Confidentiality and Integrity | Conceal or Randomize CommunicationsSC - System and Communications Protectionopen
NIST800-SC-8(5)SC-8(5) Transmission Confidentiality and Integrity | Protected Distribution SystemSC - System and Communications Protectionopen
NIST800-SC-10SC-10 Network DisconnectSC - System and Communications Protectionopen
NIST800-SC-11SC-11 Trusted PathSC - System and Communications Protectionopen
NIST800-SC-11(1)SC-11(1) Trusted Path | Irrefutable Communications PathSC - System and Communications Protectionopen
NIST800-SC-12SC-12 Cryptographic Key Establishment and ManagementSC - System and Communications Protectionopen
NIST800-SC-12(1)SC-12(1) Cryptographic Key Establishment and Management | AvailabilitySC - System and Communications Protectionopen
NIST800-SC-12(2)SC-12(2) Cryptographic Key Establishment and Management | Symmetric KeysSC - System and Communications Protectionopen
NIST800-SC-12(3)SC-12(3) Cryptographic Key Establishment and Management | Asymmetric KeysSC - System and Communications Protectionopen
NIST800-SC-12(6)SC-12(6) Cryptographic Key Establishment and Management | Physical Control of KeysSC - System and Communications Protectionopen
NIST800-SC-13SC-13 Cryptographic ProtectionSC - System and Communications Protectionopen
NIST800-SC-15SC-15 Collaborative Computing Devices and ApplicationsSC - System and Communications Protectionopen
NIST800-SC-15(1)SC-15(1) Collaborative Computing Devices and Applications | Physical or Logical DisconnectSC - System and Communications Protectionopen
NIST800-SC-15(3)SC-15(3) Collaborative Computing Devices and Applications | Disabling and Removal in Secure Work AreasSC - System and Communications Protectionopen
NIST800-SC-15(4)SC-15(4) Collaborative Computing Devices and Applications | Explicitly Indicate Current ParticipantsSC - System and Communications Protectionopen
NIST800-SC-16SC-16 Transmission of Security and Privacy AttributesSC - System and Communications Protectionopen
NIST800-SC-16(1)SC-16(1) Transmission of Security and Privacy Attributes | Integrity VerificationSC - System and Communications Protectionopen
NIST800-SC-16(2)SC-16(2) Transmission of Security and Privacy Attributes | Anti-spoofing MechanismsSC - System and Communications Protectionopen
NIST800-SC-16(3)SC-16(3) Transmission of Security and Privacy Attributes | Cryptographic BindingSC - System and Communications Protectionopen
NIST800-SC-17SC-17 Public Key Infrastructure CertificatesSC - System and Communications Protectionopen
NIST800-SC-18SC-18 Mobile CodeSC - System and Communications Protectionopen
NIST800-SC-18(1)SC-18(1) Mobile Code | Identify Unacceptable Code and Take Corrective ActionsSC - System and Communications Protectionopen
NIST800-SC-18(2)SC-18(2) Mobile Code | Acquisition, Development, and UseSC - System and Communications Protectionopen
NIST800-SC-18(3)SC-18(3) Mobile Code | Prevent Downloading and ExecutionSC - System and Communications Protectionopen
NIST800-SC-18(4)SC-18(4) Mobile Code | Prevent Automatic ExecutionSC - System and Communications Protectionopen
NIST800-SC-18(5)SC-18(5) Mobile Code | Allow Execution Only in Confined EnvironmentsSC - System and Communications Protectionopen
NIST800-SC-20SC-20 Secure Name/Address Resolution Service (Authoritative Source)SC - System and Communications Protectionopen
NIST800-SC-20(2)SC-20(2) Secure Name/Address Resolution Service (Authoritative Source) | Data Origin and IntegritySC - System and Communications Protectionopen
NIST800-SC-21SC-21 Secure Name/Address Resolution Service (Recursive or Caching Resolver)SC - System and Communications Protectionopen
NIST800-SC-22SC-22 Architecture and Provisioning for Name/Address Resolution ServiceSC - System and Communications Protectionopen
NIST800-SC-23SC-23 Session AuthenticitySC - System and Communications Protectionopen
NIST800-SC-23(1)SC-23(1) Session Authenticity | Invalidate Session Identifiers at LogoutSC - System and Communications Protectionopen
NIST800-SC-23(3)SC-23(3) Session Authenticity | Unique System-generated Session IdentifiersSC - System and Communications Protectionopen
NIST800-SC-23(5)SC-23(5) Session Authenticity | Allowed Certificate AuthoritiesSC - System and Communications Protectionopen
NIST800-SC-24SC-24 Fail in Known StateSC - System and Communications Protectionopen
NIST800-SC-25SC-25 Thin NodesSC - System and Communications Protectionopen
NIST800-SC-26SC-26 DecoysSC - System and Communications Protectionopen
NIST800-SC-27SC-27 Platform-independent ApplicationsSC - System and Communications Protectionopen
NIST800-SC-28SC-28 Protection of Information at RestSC - System and Communications Protectionopen
NIST800-SC-28(1)SC-28(1) Protection of Information at Rest | Cryptographic ProtectionSC - System and Communications Protectionopen
NIST800-SC-28(2)SC-28(2) Protection of Information at Rest | Offline StorageSC - System and Communications Protectionopen
NIST800-SC-28(3)SC-28(3) Protection of Information at Rest | Cryptographic KeysSC - System and Communications Protectionopen
NIST800-SC-29SC-29 HeterogeneitySC - System and Communications Protectionopen
NIST800-SC-29(1)SC-29(1) Heterogeneity | Virtualization TechniquesSC - System and Communications Protectionopen
NIST800-SC-30SC-30 Concealment and MisdirectionSC - System and Communications Protectionopen
NIST800-SC-30(2)SC-30(2) Concealment and Misdirection | RandomnessSC - System and Communications Protectionopen
NIST800-SC-30(3)SC-30(3) Concealment and Misdirection | Change Processing and Storage LocationsSC - System and Communications Protectionopen
NIST800-SC-30(4)SC-30(4) Concealment and Misdirection | Misleading InformationSC - System and Communications Protectionopen
NIST800-SC-30(5)SC-30(5) Concealment and Misdirection | Concealment of System ComponentsSC - System and Communications Protectionopen
NIST800-SC-31SC-31 Covert Channel AnalysisSC - System and Communications Protectionopen
NIST800-SC-31(1)SC-31(1) Covert Channel Analysis | Test Covert Channels for ExploitabilitySC - System and Communications Protectionopen
NIST800-SC-31(2)SC-31(2) Covert Channel Analysis | Maximum BandwidthSC - System and Communications Protectionopen
NIST800-SC-31(3)SC-31(3) Covert Channel Analysis | Measure Bandwidth in Operational EnvironmentsSC - System and Communications Protectionopen
NIST800-SC-32SC-32 System PartitioningSC - System and Communications Protectionopen
NIST800-SC-32(1)SC-32(1) System Partitioning | Separate Physical Domains for Privileged FunctionsSC - System and Communications Protectionopen
NIST800-SC-34SC-34 Non-modifiable Executable ProgramsSC - System and Communications Protectionopen
NIST800-SC-34(1)SC-34(1) Non-modifiable Executable Programs | No Writable StorageSC - System and Communications Protectionopen
NIST800-SC-34(2)SC-34(2) Non-modifiable Executable Programs | Integrity Protection on Read-only MediaSC - System and Communications Protectionopen
NIST800-SC-35SC-35 External Malicious Code IdentificationSC - System and Communications Protectionopen
NIST800-SC-36SC-36 Distributed Processing and StorageSC - System and Communications Protectionopen
NIST800-SC-36(1)SC-36(1) Distributed Processing and Storage | Polling TechniquesSC - System and Communications Protectionopen
NIST800-SC-36(2)SC-36(2) Distributed Processing and Storage | SynchronizationSC - System and Communications Protectionopen
NIST800-SC-37SC-37 Out-of-band ChannelsSC - System and Communications Protectionopen
NIST800-SC-37(1)SC-37(1) Out-of-band Channels | Ensure Delivery and TransmissionSC - System and Communications Protectionopen
NIST800-SC-38SC-38 Operations SecuritySC - System and Communications Protectionopen
NIST800-SC-39SC-39 Process IsolationSC - System and Communications Protectionopen
NIST800-SC-39(1)SC-39(1) Process Isolation | Hardware SeparationSC - System and Communications Protectionopen
NIST800-SC-39(2)SC-39(2) Process Isolation | Separate Execution Domain Per ThreadSC - System and Communications Protectionopen
NIST800-SC-40SC-40 Wireless Link ProtectionSC - System and Communications Protectionopen
NIST800-SC-40(1)SC-40(1) Wireless Link Protection | Electromagnetic InterferenceSC - System and Communications Protectionopen
NIST800-SC-40(2)SC-40(2) Wireless Link Protection | Reduce Detection PotentialSC - System and Communications Protectionopen
NIST800-SC-40(3)SC-40(3) Wireless Link Protection | Imitative or Manipulative Communications DeceptionSC - System and Communications Protectionopen
NIST800-SC-40(4)SC-40(4) Wireless Link Protection | Signal Parameter IdentificationSC - System and Communications Protectionopen
NIST800-SC-41SC-41 Port and I/O Device AccessSC - System and Communications Protectionopen
NIST800-SC-42SC-42 Sensor Capability and DataSC - System and Communications Protectionopen
NIST800-SC-42(1)SC-42(1) Sensor Capability and Data | Reporting to Authorized Individuals or RolesSC - System and Communications Protectionopen
NIST800-SC-42(2)SC-42(2) Sensor Capability and Data | Authorized UseSC - System and Communications Protectionopen
NIST800-SC-42(4)SC-42(4) Sensor Capability and Data | Notice of CollectionSC - System and Communications Protectionopen
NIST800-SC-42(5)SC-42(5) Sensor Capability and Data | Collection MinimizationSC - System and Communications Protectionopen
NIST800-SC-43SC-43 Usage RestrictionsSC - System and Communications Protectionopen
NIST800-SC-44SC-44 Detonation ChambersSC - System and Communications Protectionopen
NIST800-SC-45SC-45 System Time SynchronizationSC - System and Communications Protectionopen
NIST800-SC-45(1)SC-45(1) System Time Synchronization | Synchronization with Authoritative Time SourceSC - System and Communications Protectionopen
NIST800-SC-45(2)SC-45(2) System Time Synchronization | Secondary Authoritative Time SourceSC - System and Communications Protectionopen
NIST800-SC-46SC-46 Cross Domain Policy EnforcementSC - System and Communications Protectionopen
NIST800-SC-47SC-47 Alternate Communications PathsSC - System and Communications Protectionopen
NIST800-SC-48SC-48 Sensor RelocationSC - System and Communications Protectionopen
NIST800-SC-48(1)SC-48(1) Sensor Relocation | Dynamic Relocation of Sensors or Monitoring CapabilitiesSC - System and Communications Protectionopen
NIST800-SC-49SC-49 Hardware-enforced Separation and Policy EnforcementSC - System and Communications Protectionopen
NIST800-SC-50SC-50 Software-enforced Separation and Policy EnforcementSC - System and Communications Protectionopen
NIST800-SC-51SC-51 Hardware-based ProtectionSC - System and Communications Protectionopen
NIST800-SI-1SI-1 Policy and ProceduresSI - System and Information Integrityopen
NIST800-SI-2SI-2 Flaw RemediationSI - System and Information Integrityopen
NIST800-SI-2(2)SI-2(2) Flaw Remediation | Automated Flaw Remediation StatusSI - System and Information Integrityopen
NIST800-SI-2(3)SI-2(3) Flaw Remediation | Time to Remediate Flaws and Benchmarks for Corrective ActionsSI - System and Information Integrityopen
NIST800-SI-2(4)SI-2(4) Flaw Remediation | Automated Patch Management ToolsSI - System and Information Integrityopen
NIST800-SI-2(5)SI-2(5) Flaw Remediation | Automatic Software and Firmware UpdatesSI - System and Information Integrityopen
NIST800-SI-2(6)SI-2(6) Flaw Remediation | Removal of Previous Versions of Software and FirmwareSI - System and Information Integrityopen
NIST800-SI-2(7)SI-2(7) Flaw Remediation | Root Cause AnalysisSI - System and Information Integrityopen
NIST800-SI-3SI-3 Malicious Code ProtectionSI - System and Information Integrityopen
NIST800-SI-3(4)SI-3(4) Malicious Code Protection | Updates Only by Privileged UsersSI - System and Information Integrityopen
NIST800-SI-3(6)SI-3(6) Malicious Code Protection | Testing and VerificationSI - System and Information Integrityopen
NIST800-SI-3(8)SI-3(8) Malicious Code Protection | Detect Unauthorized CommandsSI - System and Information Integrityopen
NIST800-SI-3(10)SI-3(10) Malicious Code Protection | Malicious Code AnalysisSI - System and Information Integrityopen
NIST800-SI-4SI-4 System MonitoringSI - System and Information Integrityopen
NIST800-SI-4(1)SI-4(1) System Monitoring | System-wide Intrusion Detection SystemSI - System and Information Integrityopen
NIST800-SI-4(2)SI-4(2) System Monitoring | Automated Tools and Mechanisms for Real-time AnalysisSI - System and Information Integrityopen
NIST800-SI-4(3)SI-4(3) System Monitoring | Automated Tool and Mechanism IntegrationSI - System and Information Integrityopen
NIST800-SI-4(4)SI-4(4) System Monitoring | Inbound and Outbound Communications TrafficSI - System and Information Integrityopen
NIST800-SI-4(5)SI-4(5) System Monitoring | System-generated AlertsSI - System and Information Integrityopen
NIST800-SI-4(7)SI-4(7) System Monitoring | Automated Response to Suspicious EventsSI - System and Information Integrityopen
NIST800-SI-4(9)SI-4(9) System Monitoring | Testing of Monitoring Tools and MechanismsSI - System and Information Integrityopen
NIST800-SI-4(10)SI-4(10) System Monitoring | Visibility of Encrypted CommunicationsSI - System and Information Integrityopen
NIST800-SI-4(11)SI-4(11) System Monitoring | Analyze Communications Traffic AnomaliesSI - System and Information Integrityopen
NIST800-SI-4(12)SI-4(12) System Monitoring | Automated Organization-generated AlertsSI - System and Information Integrityopen
NIST800-SI-4(13)SI-4(13) System Monitoring | Analyze Traffic and Event PatternsSI - System and Information Integrityopen
NIST800-SI-4(14)SI-4(14) System Monitoring | Wireless Intrusion DetectionSI - System and Information Integrityopen
NIST800-SI-4(15)SI-4(15) System Monitoring | Wireless to Wireline CommunicationsSI - System and Information Integrityopen
NIST800-SI-4(16)SI-4(16) System Monitoring | Correlate Monitoring InformationSI - System and Information Integrityopen
NIST800-SI-4(17)SI-4(17) System Monitoring | Integrated Situational AwarenessSI - System and Information Integrityopen
NIST800-SI-4(18)SI-4(18) System Monitoring | Analyze Traffic and Covert ExfiltrationSI - System and Information Integrityopen
NIST800-SI-4(19)SI-4(19) System Monitoring | Risk for IndividualsSI - System and Information Integrityopen
NIST800-SI-4(20)SI-4(20) System Monitoring | Privileged UsersSI - System and Information Integrityopen
NIST800-SI-4(21)SI-4(21) System Monitoring | Probationary PeriodsSI - System and Information Integrityopen
NIST800-SI-4(22)SI-4(22) System Monitoring | Unauthorized Network ServicesSI - System and Information Integrityopen
NIST800-SI-4(23)SI-4(23) System Monitoring | Host-based DevicesSI - System and Information Integrityopen
NIST800-SI-4(24)SI-4(24) System Monitoring | Indicators of CompromiseSI - System and Information Integrityopen
NIST800-SI-4(25)SI-4(25) System Monitoring | Optimize Network Traffic AnalysisSI - System and Information Integrityopen
NIST800-SI-5SI-5 Security Alerts, Advisories, and DirectivesSI - System and Information Integrityopen
NIST800-SI-5(1)SI-5(1) Security Alerts, Advisories, and Directives | Automated Alerts and AdvisoriesSI - System and Information Integrityopen
NIST800-SI-6SI-6 Security and Privacy Function VerificationSI - System and Information Integrityopen
NIST800-SI-6(2)SI-6(2) Security and Privacy Function Verification | Automation Support for Distributed TestingSI - System and Information Integrityopen
NIST800-SI-6(3)SI-6(3) Security and Privacy Function Verification | Report Verification ResultsSI - System and Information Integrityopen
NIST800-SI-7SI-7 Software, Firmware, and Information IntegritySI - System and Information Integrityopen
NIST800-SI-7(1)SI-7(1) Software, Firmware, and Information Integrity | Integrity ChecksSI - System and Information Integrityopen
NIST800-SI-7(2)SI-7(2) Software, Firmware, and Information Integrity | Automated Notifications of Integrity ViolationsSI - System and Information Integrityopen
NIST800-SI-7(3)SI-7(3) Software, Firmware, and Information Integrity | Centrally Managed Integrity ToolsSI - System and Information Integrityopen
NIST800-SI-7(5)SI-7(5) Software, Firmware, and Information Integrity | Automated Response to Integrity ViolationsSI - System and Information Integrityopen
NIST800-SI-7(6)SI-7(6) Software, Firmware, and Information Integrity | Cryptographic ProtectionSI - System and Information Integrityopen
NIST800-SI-7(7)SI-7(7) Software, Firmware, and Information Integrity | Integration of Detection and ResponseSI - System and Information Integrityopen
NIST800-SI-7(8)SI-7(8) Software, Firmware, and Information Integrity | Auditing Capability for Significant EventsSI - System and Information Integrityopen
NIST800-SI-7(9)SI-7(9) Software, Firmware, and Information Integrity | Verify Boot ProcessSI - System and Information Integrityopen
NIST800-SI-7(10)SI-7(10) Software, Firmware, and Information Integrity | Protection of Boot FirmwareSI - System and Information Integrityopen
NIST800-SI-7(12)SI-7(12) Software, Firmware, and Information Integrity | Integrity VerificationSI - System and Information Integrityopen
NIST800-SI-7(15)SI-7(15) Software, Firmware, and Information Integrity | Code AuthenticationSI - System and Information Integrityopen
NIST800-SI-7(16)SI-7(16) Software, Firmware, and Information Integrity | Time Limit on Process Execution Without SupervisionSI - System and Information Integrityopen
NIST800-SI-7(17)SI-7(17) Software, Firmware, and Information Integrity | Runtime Application Self-protectionSI - System and Information Integrityopen
NIST800-SI-8SI-8 Spam ProtectionSI - System and Information Integrityopen
NIST800-SI-8(2)SI-8(2) Spam Protection | Automatic UpdatesSI - System and Information Integrityopen
NIST800-SI-8(3)SI-8(3) Spam Protection | Continuous Learning CapabilitySI - System and Information Integrityopen
NIST800-SI-10SI-10 Information Input ValidationSI - System and Information Integrityopen
NIST800-SI-10(1)SI-10(1) Information Input Validation | Manual Override CapabilitySI - System and Information Integrityopen
NIST800-SI-10(2)SI-10(2) Information Input Validation | Review and Resolve ErrorsSI - System and Information Integrityopen
NIST800-SI-10(3)SI-10(3) Information Input Validation | Predictable BehaviorSI - System and Information Integrityopen
NIST800-SI-10(4)SI-10(4) Information Input Validation | Timing InteractionsSI - System and Information Integrityopen
NIST800-SI-10(5)SI-10(5) Information Input Validation | Restrict Inputs to Trusted Sources and Approved FormatsSI - System and Information Integrityopen
NIST800-SI-10(6)SI-10(6) Information Input Validation | Injection PreventionSI - System and Information Integrityopen
NIST800-SI-11SI-11 Error HandlingSI - System and Information Integrityopen
NIST800-SI-12SI-12 Information Management and RetentionSI - System and Information Integrityopen
NIST800-SI-12(1)SI-12(1) Information Management and Retention | Limit Personally Identifiable Information ElementsSI - System and Information Integrityopen
NIST800-SI-12(2)SI-12(2) Information Management and Retention | Minimize Personally Identifiable Information in Testing, Training, and ResearchSI - System and Information Integrityopen
NIST800-SI-12(3)SI-12(3) Information Management and Retention | Information DisposalSI - System and Information Integrityopen
NIST800-SI-13SI-13 Predictable Failure PreventionSI - System and Information Integrityopen
NIST800-SI-13(1)SI-13(1) Predictable Failure Prevention | Transferring Component ResponsibilitiesSI - System and Information Integrityopen
NIST800-SI-13(3)SI-13(3) Predictable Failure Prevention | Manual Transfer Between ComponentsSI - System and Information Integrityopen
NIST800-SI-13(4)SI-13(4) Predictable Failure Prevention | Standby Component Installation and NotificationSI - System and Information Integrityopen
NIST800-SI-13(5)SI-13(5) Predictable Failure Prevention | Failover CapabilitySI - System and Information Integrityopen
NIST800-SI-14SI-14 Non-persistenceSI - System and Information Integrityopen
NIST800-SI-14(1)SI-14(1) Non-persistence | Refresh from Trusted SourcesSI - System and Information Integrityopen
NIST800-SI-14(2)SI-14(2) Non-persistence | Non-persistent InformationSI - System and Information Integrityopen
NIST800-SI-14(3)SI-14(3) Non-persistence | Non-persistent ConnectivitySI - System and Information Integrityopen
NIST800-SI-15SI-15 Information Output FilteringSI - System and Information Integrityopen
NIST800-SI-16SI-16 Memory ProtectionSI - System and Information Integrityopen
NIST800-SI-17SI-17 Fail-safe ProceduresSI - System and Information Integrityopen
NIST800-SI-18SI-18 Personally Identifiable Information Quality OperationsSI - System and Information Integrityopen
NIST800-SI-18(1)SI-18(1) Personally Identifiable Information Quality Operations | Automation SupportSI - System and Information Integrityopen
NIST800-SI-18(2)SI-18(2) Personally Identifiable Information Quality Operations | Data TagsSI - System and Information Integrityopen
NIST800-SI-18(3)SI-18(3) Personally Identifiable Information Quality Operations | CollectionSI - System and Information Integrityopen
NIST800-SI-18(4)SI-18(4) Personally Identifiable Information Quality Operations | Individual RequestsSI - System and Information Integrityopen
NIST800-SI-18(5)SI-18(5) Personally Identifiable Information Quality Operations | Notice of Correction or DeletionSI - System and Information Integrityopen
NIST800-SI-19SI-19 De-identificationSI - System and Information Integrityopen
NIST800-SI-19(1)SI-19(1) De-identification | CollectionSI - System and Information Integrityopen
NIST800-SI-19(2)SI-19(2) De-identification | ArchivingSI - System and Information Integrityopen
NIST800-SI-19(3)SI-19(3) De-identification | ReleaseSI - System and Information Integrityopen
NIST800-SI-19(4)SI-19(4) De-identification | Removal, Masking, Encryption, Hashing, or Replacement of Direct IdentifiersSI - System and Information Integrityopen
NIST800-SI-19(5)SI-19(5) De-identification | Statistical Disclosure ControlSI - System and Information Integrityopen
NIST800-SI-19(6)SI-19(6) De-identification | Differential PrivacySI - System and Information Integrityopen
NIST800-SI-19(7)SI-19(7) De-identification | Validated Algorithms and SoftwareSI - System and Information Integrityopen
NIST800-SI-19(8)SI-19(8) De-identification | Motivated IntruderSI - System and Information Integrityopen
NIST800-SI-20SI-20 TaintingSI - System and Information Integrityopen
NIST800-SI-21SI-21 Information RefreshSI - System and Information Integrityopen
NIST800-SI-22SI-22 Information DiversitySI - System and Information Integrityopen
NIST800-SI-23SI-23 Information FragmentationSI - System and Information Integrityopen
NIST800-SR-1SR-1 Policy and ProceduresSR - Supply Chain Risk Managementopen
NIST800-SR-2SR-2 Supply Chain Risk Management PlanSR - Supply Chain Risk Managementopen
NIST800-SR-2(1)SR-2(1) Supply Chain Risk Management Plan | Establish SCRM TeamSR - Supply Chain Risk Managementopen
NIST800-SR-3SR-3 Supply Chain Controls and ProcessesSR - Supply Chain Risk Managementopen
NIST800-SR-3(1)SR-3(1) Supply Chain Controls and Processes | Diverse Supply BaseSR - Supply Chain Risk Managementopen
NIST800-SR-3(2)SR-3(2) Supply Chain Controls and Processes | Limitation of HarmSR - Supply Chain Risk Managementopen
NIST800-SR-3(3)SR-3(3) Supply Chain Controls and Processes | Sub-tier Flow DownSR - Supply Chain Risk Managementopen
NIST800-SR-4SR-4 ProvenanceSR - Supply Chain Risk Managementopen
NIST800-SR-4(1)SR-4(1) Provenance | IdentitySR - Supply Chain Risk Managementopen
NIST800-SR-4(2)SR-4(2) Provenance | Track and TraceSR - Supply Chain Risk Managementopen
NIST800-SR-4(3)SR-4(3) Provenance | Validate as Genuine and Not AlteredSR - Supply Chain Risk Managementopen
NIST800-SR-4(4)SR-4(4) Provenance | Supply Chain Integrity: PedigreeSR - Supply Chain Risk Managementopen
NIST800-SR-5SR-5 Acquisition Strategies, Tools, and MethodsSR - Supply Chain Risk Managementopen
NIST800-SR-5(1)SR-5(1) Acquisition Strategies, Tools, and Methods | Adequate SupplySR - Supply Chain Risk Managementopen
NIST800-SR-5(2)SR-5(2) Acquisition Strategies, Tools, and Methods | Assessments Prior to Selection, Acceptance, Modification, or UpdateSR - Supply Chain Risk Managementopen
NIST800-SR-6SR-6 Supplier Assessments and ReviewsSR - Supply Chain Risk Managementopen
NIST800-SR-6(1)SR-6(1) Supplier Assessments and Reviews | Testing and AnalysisSR - Supply Chain Risk Managementopen
NIST800-SR-7SR-7 Supply Chain Operations SecuritySR - Supply Chain Risk Managementopen
NIST800-SR-8SR-8 Notification AgreementsSR - Supply Chain Risk Managementopen
NIST800-SR-9SR-9 Tamper Resistance and DetectionSR - Supply Chain Risk Managementopen
NIST800-SR-9(1)SR-9(1) Tamper Resistance and Detection | Multiple Stages of System Development Life CycleSR - Supply Chain Risk Managementopen
NIST800-SR-10SR-10 Inspection of Systems or ComponentsSR - Supply Chain Risk Managementopen
NIST800-SR-11SR-11 Component AuthenticitySR - Supply Chain Risk Managementopen
NIST800-SR-11(1)SR-11(1) Component Authenticity | Anti-counterfeit TrainingSR - Supply Chain Risk Managementopen
NIST800-SR-11(2)SR-11(2) Component Authenticity | Configuration Control for Component Service and RepairSR - Supply Chain Risk Managementopen
NIST800-SR-11(3)SR-11(3) Component Authenticity | Anti-counterfeit ScanningSR - Supply Chain Risk Managementopen
NIST800-SR-12SR-12 Component DisposalSR - Supply Chain Risk Managementopen