Access control
- 03.01.01 Account management (Level 1)
- 03.01.02 Access enforcement (Level 1)
- 03.01.03 Information flow enforcement
- 03.01.04 Separation of duties
- 03.01.05 Least privilege
- 03.01.06 Least privilege (privileged accounts)
- 03.01.07 Least privilege (privileged functions)
- 03.01.08 Unsuccessful logon attempts
- 03.01.09 System use notification
- 03.01.10 Device lock
- 03.01.11 Session termination
- 03.01.12 Remote access
- 03.01.16 Wireless access
- 03.01.18 Access control for mobile devices
- 03.01.20 Use of external systems (Level 1)
- 03.01.22 Publicly accessible content (Level 1)
Awareness and training
Audit and accountability
- 03.03.01 Event logging
- 03.03.02 Audit record content
- 03.03.03 Audit record generation
- 03.03.04 Response to audit logging process failures
- 03.03.05 Audit record review, analysis, and reporting
- 03.03.06 Audit record reduction and report generation
- 03.03.07 Time stamps
- 03.03.08 Protection of audit information
Configuration management
- 03.04.01 Baseline configuration
- 03.04.02 Configuration settings
- 03.04.03 Configuration change control
- 03.04.04 Impact analyses
- 03.04.05 Access restrictions for change
- 03.04.06 Least functionality
- 03.04.08 Authorized software (allow by exception)
- 03.04.10 System component inventory
- 03.04.11 Information location
- 03.04.12 System and component configuration for high-risk areas
Identification and authentication
- 03.05.01 User identification, authentication, and re-authentication (Level 1)
- 03.05.02 Device identification and authentication (Level 1)
- 03.05.03 Multi-factor authentication (Level 1)
- 03.05.04 Replay-resistant authentication
- 03.05.05 Identifier management
- 03.05.07 Password management
- 03.05.11 Authentication feedback
- 03.05.12 Authenticator management
Incident response
- 03.06.01 Incident handling
- 03.06.02 Incident monitoring, reporting, and response assistance
- 03.06.03 Incident response testing
- 03.06.04 Incident response training
- 03.06.05 Incident response plan
Maintenance
Media protection
- 03.08.01 Media storage
- 03.08.02 Media access
- 03.08.03 Media sanitization (Level 1)
- 03.08.04 Media marking
- 03.08.05 Media transport
- 03.08.07 Media use
- 03.08.09 System backup (cryptographic protection)
Personnel security
Physical protection
- 03.10.01 Physical access authorizations (Level 1)
- 03.10.02 Monitoring physical access
- 03.10.06 Alternate work site
- 03.10.07 Physical access control (Level 1)
- 03.10.08 Access control for transmission
Risk assessment
Security assessment and monitoring
- 03.12.01 Security assessment
- 03.12.02 Plan of action and milestones
- 03.12.03 Continuous monitoring
- 03.12.05 Information exchange
System and communications protection
- 03.13.01 Boundary protection (Level 1)
- 03.13.04 Information in shared system resources
- 03.13.06 Network communications, deny by default, allow by exception
- 03.13.08 Transmission and storage confidentiality
- 03.13.09 Network disconnect
- 03.13.10 Cryptographic key establishment and management
- 03.13.11 Cryptographic protection
- 03.13.12 Collaborative computing devices and applications
- 03.13.13 Mobile code
- 03.13.15 Session authenticity
System and information integrity
- 03.14.01 Flaw remediation (Level 1)
- 03.14.02 Malicious code protection (Level 1)
- 03.14.03 Security alerts, advisories, and directives
- 03.14.06 System monitoring
- 03.14.08 Information management and retention
- 03.14.09 Dedicated administration workstation
Planning
System and services acquisition
- 03.16.01 Security engineering principles
- 03.16.02 Unsupported system components
- 03.16.03 External system services