UUID: 5ba2a3ba-1aa2-47d8-ad69-5beef7372b98
Version: 5.2.0
Last Modified: 2025-08-26 14:33:16+00:00
OSCAL Version: 1.2.1
Control Groups
Total Controls
Click on any group, control, or parameter to expand/collapse. Supports nested sub-groups and sub-controls (enhancements). All data visible with no truncation.
ac-1_prm_1: organization-defined personnel or roles
ac-01_odp.01: personnel or roles
ac-01_odp.02: personnel or roles
ac-01_odp.03: No label Choices: 3
ac-01_odp.04: official
ac-01_odp.05: frequency
ac-01_odp.06: events
ac-01_odp.07: frequency
ac-01_odp.08: events
ac-02_odp.01: prerequisites and criteria
ac-02_odp.02: attributes (as required)
ac-02_odp.03: personnel or roles
ac-02_odp.04: policy, procedures, prerequisites, and criteria
ac-02_odp.05: personnel or roles
ac-02_odp.06: time period
ac-02_odp.07: time period
ac-02_odp.08: time period
ac-02_odp.09: attributes (as required)
ac-02_odp.10: frequency
ac-02.01_odp: automated mechanisms
ac-02.02_odp.01: No label Choices: 2
ac-02.02_odp.02: time period
ac-02.03_odp.01: time period
ac-02.03_odp.02: time period
ac-02.05_odp: time period of expected inactivity or description of when to log out
ac-02.06_odp: dynamic privilege management capabilities
ac-02.07_odp: No label Choices: 2
ac-02.08_odp: system accounts
ac-02.09_odp: conditions
No statement available
ac-02.11_odp.01: circumstances and/or usage conditions
ac-02.11_odp.02: system accounts
ac-02.12_odp.01: atypical usage
ac-02.12_odp.02: personnel or roles
ac-02.13_odp.01: time period
ac-02.13_odp.02: significant risks
No statement available
ac-03.02_odp: privileged commands and/or other actions
ac-3.3_prm_1: organization-defined mandatory access control policy
ac-03.03_odp.01: mandatory access control policy
ac-03.03_odp.02: mandatory access control policy
ac-03.03_odp.03: subjects
ac-03.03_odp.04: privileges
ac-3.4_prm_1: organization-defined discretionary access control policy
ac-03.04_odp.01: discretionary access control policy
ac-03.04_odp.02: discretionary access control policy
ac-03.05_odp: security-relevant information
No statement available
ac-3.7_prm_1: organization-defined roles and users authorized to assume such roles
ac-03.07_odp.01: roles
ac-03.07_odp.02: users authorized to assume such roles
ac-03.08_odp: rules
ac-03.09_odp.01: system or system component
ac-03.09_odp.02: controls
ac-03.09_odp.03: controls
ac-03.10_odp.01: conditions
ac-03.10_odp.02: roles
ac-03.11_odp: information types
ac-03.12_odp: system applications and functions
ac-03.13_odp: attributes
ac-03.14_odp.01: mechanisms
ac-03.14_odp.02: elements
ac-3.15_prm_1: organization-defined mandatory access control policy
ac-3.15_prm_2: organization-defined discretionary access control policy
ac-03.15_odp.01: mandatory access control policy
ac-03.15_odp.02: mandatory access control policy
ac-03.15_odp.03: discretionary access control policy
ac-03.15_odp.04: discretionary access control policy
ac-04_odp: information flow control policies
ac-4.1_prm_1: organization-defined security and privacy attributes
ac-4.1_prm_2: organization-defined information, source, and destination objects
ac-04.01_odp.01: security attributes
ac-04.01_odp.02: privacy attributes
ac-04.01_odp.03: information objects
ac-04.01_odp.04: information objects
ac-04.01_odp.05: source objects
ac-04.01_odp.06: source objects
ac-04.01_odp.07: destination objects
ac-04.01_odp.08: destination objects
ac-04.01_odp.09: information flow control policies
ac-04.02_odp: information flow control policies
ac-04.03_odp: information flow control policies
ac-04.04_odp.01: information flow control mechanisms
ac-04.04_odp.02: No label Choices: 4
ac-04.04_odp.03: organization-defined procedure or method
ac-04.05_odp: limitations
ac-04.06_odp: metadata
ac-4.8_prm_1: organization-defined security or privacy policy filters
ac-4.8_prm_2: organization-defined information flows
ac-4.8_prm_4: organization-defined security or privacy policy
ac-04.08_odp.01: security policy filter
ac-04.08_odp.02: privacy policy filter
ac-04.08_odp.03: information flows
ac-04.08_odp.04: information flows
ac-04.08_odp.05: No label Choices: 4
ac-04.08_odp.06: security policy
ac-04.08_odp.07: privacy policy
ac-04.09_odp.01: information flows
ac-04.09_odp.02: conditions
ac-4.10_prm_1: organization-defined security or privacy policy filters
ac-4.10_prm_2: organization-defined conditions
ac-04.10_odp.01: security filters
ac-04.10_odp.02: privacy filters
ac-04.10_odp.03: conditions
ac-04.10_odp.04: conditions
ac-4.11_prm_1: organization-defined security or privacy policy filters
ac-04.11_odp.01: security policy filters
ac-04.11_odp.02: privacy policy filters
ac-04.12_odp: data type identifiers
ac-04.13_odp: policy-relevant subcomponents
ac-4.14_prm_1: organization-defined security or privacy policy filters
ac-04.14_odp.01: security policy filters
ac-04.14_odp.02: privacy policy filters
ac-4.15_prm_2: organization-defined security or privacy policy
ac-04.15_odp.01: unsanctioned information
ac-04.15_odp.02: security policy
ac-04.15_odp.03: privacy policy
No statement available
ac-04.17_odp: No label Choices: 1
No statement available
ac-4.19_prm_1: organization-defined security or privacy policy filters
ac-04.19_odp.01: security policy filters
ac-04.19_odp.02: privacy policy filters
ac-04.20_odp.01: solutions in approved configurations
ac-04.20_odp.02: information
ac-4.21_prm_1: organization-defined mechanisms and/or techniques
ac-04.21_odp.01: mechanisms and/or techniques
ac-04.21_odp.02: mechanisms and/or techniques
ac-04.21_odp.03: required separations
ac-04.23_odp: modification action
ac-04.25_odp.01: No label Choices: 2
ac-04.25_odp.02: policy
ac-04.29_odp: policy
ac-05_odp: duties of individuals
ac-6.1_prm_2: organization-defined security functions (deployed in hardware, software, and firmware)
ac-06.01_odp.01: individuals and roles
ac-06.01_odp.02: security functions (deployed in hardware)
ac-06.01_odp.03: security functions (deployed in software)
ac-06.01_odp.04: security functions (deployed in firmware)
ac-06.01_odp.05: security-relevant information
ac-06.02_odp: security functions or security-relevant information
ac-06.03_odp.01: privileged commands
ac-06.03_odp.02: compelling operational needs
ac-06.05_odp: personnel or roles
ac-06.07_odp.01: frequency
ac-06.07_odp.02: roles and classes
ac-06.08_odp: software
ac-07_odp.01: number
ac-07_odp.02: time period
ac-07_odp.03: No label Choices: 5
ac-07_odp.04: time period
ac-07_odp.05: delay algorithm
ac-07_odp.06: action
No statement available
ac-07.02_odp.01: mobile devices
ac-07.02_odp.02: purging or wiping requirements and techniques
ac-07.02_odp.03: number
ac-07.03_odp: number
ac-07.04_odp.01: authentication factors
ac-07.04_odp.02: number
ac-07.04_odp.03: time period
ac-08_odp.01: system use notification
ac-08_odp.02: conditions
ac-09.02_odp.01: No label Choices: 3
ac-09.02_odp.02: time period
ac-09.03_odp.01: security-related characteristics or parameters
ac-09.03_odp.02: time period
ac-09.04_odp: additional information
ac-10_odp.01: account and/or account types
ac-10_odp.02: number
ac-11_odp.01: No label Choices: 2
ac-11_odp.02: time period
ac-12_odp: conditions or trigger events
ac-12.01_odp: information resources
ac-12.03_odp: time
No statement available
ac-14_odp: user actions
No statement available
No statement available
ac-16_prm_1: organization-defined types of security and privacy attributes
ac-16_prm_2: organization-defined security and privacy attribute values
ac-16_prm_3: organization-defined systems
ac-16_prm_4: organization-defined security and privacy attributes
ac-16_prm_6: organization-defined security and privacy attributes
ac-16_prm_7: organization-defined frequency
ac-16_odp.01: types of security attributes
ac-16_odp.02: types of privacy attributes
ac-16_odp.03: security attribute values
ac-16_odp.04: privacy attribute values
ac-16_odp.05: systems
ac-16_odp.06: systems
ac-16_odp.07: security attributes
ac-16_odp.08: privacy attributes
ac-16_odp.09: attribute values or ranges
ac-16_odp.10: frequency
ac-16_odp.11: frequency
ac-16.1_prm_1: organization-defined subjects and objects
ac-16.1_prm_2: organization-defined security and privacy policies
ac-16.01_odp.01: subjects
ac-16.01_odp.02: objects
ac-16.01_odp.03: subjects
ac-16.01_odp.04: objects
ac-16.01_odp.05: security policies
ac-16.01_odp.06: privacy policies
ac-16.3_prm_1: organization-defined security and privacy attributes
ac-16.3_prm_2: organization-defined subjects and objects
ac-16.03_odp.01: security attributes
ac-16.03_odp.02: privacy attributes
ac-16.03_odp.03: subjects
ac-16.03_odp.04: objects
ac-16.03_odp.05: subjects
ac-16.03_odp.06: objects
ac-16.4_prm_1: organization-defined security and privacy attributes
ac-16.4_prm_2: organization-defined subjects and objects
ac-16.04_odp.01: security attributes
ac-16.04_odp.02: security attributes
ac-16.04_odp.03: privacy attributes
ac-16.04_odp.04: privacy attributes
ac-16.04_odp.05: subjects
ac-16.04_odp.06: objects
ac-16.04_odp.07: subjects
ac-16.04_odp.08: objects
ac-16.05_odp.01: instructions
ac-16.05_odp.02: naming conventions
ac-16.6_prm_1: organization-defined security and privacy attributes
ac-16.6_prm_2: organization-defined subjects and objects
ac-16.6_prm_3: organization-defined security and privacy policies
ac-16.06_odp.01: security attributes
ac-16.06_odp.02: security attributes
ac-16.06_odp.03: privacy attributes
ac-16.06_odp.04: privacy attributes
ac-16.06_odp.05: subjects
ac-16.06_odp.06: objects
ac-16.06_odp.07: subjects
ac-16.06_odp.08: objects
ac-16.06_odp.09: security policies
ac-16.06_odp.10: privacy policies
ac-16.8_prm_1: organization-defined techniques and technologies
ac-16.08_odp.01: techniques and technologies
ac-16.08_odp.02: techniques and technologies
ac-16.9_prm_1: organization-defined techniques or procedures
ac-16.09_odp.01: techniques or procedures
ac-16.09_odp.02: techniques or procedures
ac-17.4_prm_1: organization-defined needs
ac-17.04_odp.01: needs requiring remote access
ac-17.04_odp.02: needs requiring remote access
No statement available
No statement available
No statement available
ac-17.09_odp: time period
ac-17.10_odp.01: mechanisms
ac-17.10_odp.02: remote commands
ac-18.01_odp: No label Choices: 2
No statement available
No statement available
No statement available
No statement available
ac-19.04_odp.01: security officials
ac-19.04_odp.02: security policies
ac-19.05_odp.01: No label Choices: 2
ac-19.05_odp.02: mobile devices
ac-20_odp.01: No label Choices: 2
ac-20_odp.02: terms and conditions
ac-20_odp.03: controls asserted
ac-20_odp.04: prohibited types of external systems
ac-20.02_odp: restrictions
ac-20.03_odp: restrictions
ac-20.04_odp: network-accessible storage devices
ac-21_odp.01: information-sharing circumstances
ac-21_odp.02: automated mechanisms
ac-21.01_odp: automated mechanisms
ac-21.02_odp: information-sharing restrictions
ac-22_odp: frequency
ac-23_odp.01: techniques
ac-23_odp.02: data storage objects
ac-24_odp.01: No label Choices: 2
ac-24_odp.02: access control decisions
ac-24.01_odp.01: access authorization information
ac-24.01_odp.02: controls
ac-24.01_odp.03: systems
ac-24.2_prm_1: organization-defined security or privacy attributes
ac-24.02_odp.01: security attributes
ac-24.02_odp.02: privacy attributes
ac-25_odp: access control policies
at-1_prm_1: organization-defined personnel or roles
at-01_odp.01: personnel or roles
at-01_odp.02: personnel or roles
at-01_odp.03: No label Choices: 3
at-01_odp.04: official
at-01_odp.05: frequency
at-01_odp.06: events
at-01_odp.07: frequency
at-01_odp.08: events
at-2_prm_1: organization-defined frequency
at-2_prm_2: organization-defined events
at-02_odp.01: frequency
at-02_odp.02: frequency
at-02_odp.03: events
at-02_odp.04: events
at-02_odp.05: awareness techniques
at-02_odp.06: frequency
at-02_odp.07: events
at-02.04_odp: indicators of malicious code
at-3_prm_1: organization-defined roles and responsibilities
at-03_odp.01: roles and responsibilities
at-03_odp.02: roles and responsibilities
at-03_odp.03: frequency
at-03_odp.04: frequency
at-03_odp.05: events
at-03.01_odp.01: personnel or roles
at-03.01_odp.02: frequency
at-03.02_odp.01: personnel or roles
at-03.02_odp.02: frequency
No statement available
at-03.05_odp.01: personnel or roles
at-03.05_odp.02: frequency
at-04_odp: time period
No statement available
at-06_odp.01: frequency
at-06_odp.02: personnel
au-1_prm_1: organization-defined personnel or roles
au-01_odp.01: personnel or roles
au-01_odp.02: personnel or roles
au-01_odp.03: No label Choices: 3
au-01_odp.04: official
au-01_odp.05: frequency
au-01_odp.06: events
au-01_odp.07: frequency
au-01_odp.08: events
au-2_prm_2: organization-defined event types (subset of the event types defined in [AU-2a.](#au-2_smt.a)) along with the frequency of (or situation requiring) logging for each identified event type
au-02_odp.01: event types
au-02_odp.02: event types (subset of AU-02_ODP[01])
au-02_odp.03: frequency or situation
au-02_odp.04: frequency
No statement available
No statement available
No statement available
No statement available
au-03.01_odp: additional information
No statement available
au-03.03_odp: elements
au-04_odp: audit log retention requirements
au-04.01_odp: frequency
au-05_odp.01: personnel or roles
au-05_odp.02: time period
au-05_odp.03: additional actions
au-05.01_odp.01: personnel, roles, and/or locations
au-05.01_odp.02: time period
au-05.01_odp.03: percentage
au-05.02_odp.01: real-time period
au-05.02_odp.02: personnel, roles, and/or locations
au-05.02_odp.03: audit logging failure events requiring real-time alerts
au-05.03_odp: No label Choices: 2
au-05.04_odp.01: No label Choices: 3
au-05.04_odp.02: audit logging failures
au-05.05_odp: alternate audit logging functionality
au-06_odp.01: frequency
au-06_odp.02: inappropriate or unusual activity
au-06_odp.03: personnel or roles
au-06.01_odp: automated mechanisms
No statement available
au-06.05_odp.01: No label Choices: 4
au-06.05_odp.02: data/information collected from other sources
au-06.07_odp: No label Choices: 3
No statement available
au-07.01_odp: fields within audit records
No statement available
au-08_odp: granularity of time measurement
No statement available
No statement available
au-09_odp: personnel or roles
au-09.02_odp: frequency
au-09.04_odp: subset of privileged users or roles
au-09.05_odp.01: No label Choices: 2
au-09.05_odp.02: audit information
au-09.06_odp: subset of privileged users or roles
au-10_odp: actions
au-10.01_odp: strength of binding
au-10.02_odp.01: frequency
au-10.02_odp.02: actions
au-10.04_odp.01: security domains
au-10.04_odp.02: actions
No statement available
au-11_odp: time period
au-11.01_odp: measures
au-12_odp.01: system components
au-12_odp.02: personnel or roles
au-12.01_odp.01: system components
au-12.01_odp.02: level of tolerance
au-12.03_odp.01: individuals or roles
au-12.03_odp.02: system components
au-12.03_odp.03: selectable event criteria
au-12.03_odp.04: time thresholds
au-13_odp.01: open-source information and/or information sites
au-13_odp.02: frequency
au-13_odp.03: personnel or roles
au-13_odp.04: additional actions
au-13.01_odp: automated mechanisms
au-13.02_odp: frequency
au-14_odp.01: users or roles
au-14_odp.02: No label Choices: 4
au-14_odp.03: circumstances
No statement available
No statement available
au-16_odp.01: methods
au-16_odp.02: audit information
au-16.02_odp.01: organizations
au-16.02_odp.02: cross-organizational sharing agreements
au-16.03_odp: measures
ca-1_prm_1: organization-defined personnel or roles
ca-01_odp.01: personnel or roles
ca-01_odp.02: personnel or roles
ca-01_odp.03: No label Choices: 3
ca-01_odp.04: official
ca-01_odp.05: frequency
ca-01_odp.06: events
ca-01_odp.07: frequency
ca-01_odp.08: events
ca-02_odp.01: assessment frequency
ca-02_odp.02: individuals or roles
ca-02.02_odp.01: specialized assessment frequency
ca-02.02_odp.02: No label Choices: 2
ca-02.02_odp.03: No label Choices: 9
ca-02.02_odp.04: other forms of assessment
ca-02.03_odp.01: external organization(s)
ca-02.03_odp.02: system
ca-02.03_odp.03: requirements
ca-03_odp.01: No label Choices: 7
ca-03_odp.02: type of agreement
ca-03_odp.03: frequency
No statement available
No statement available
No statement available
No statement available
No statement available
No statement available
ca-05_odp: frequency
ca-05.01_odp: automated mechanisms
ca-06_odp: frequency
ca-7_prm_4: organization-defined personnel or roles
ca-7_prm_5: organization-defined frequency
ca-07_odp.01: system-level metrics
ca-07_odp.02: frequencies
ca-07_odp.03: frequencies
ca-07_odp.04: personnel or roles
ca-07_odp.05: frequency
ca-07_odp.06: personnel or roles
ca-07_odp.07: frequency
No statement available
ca-7.5_prm_1: organization-defined actions
ca-07.05_odp.01: actions
ca-07.05_odp.02: actions
ca-07.06_odp: automated mechanisms
ca-08_odp.01: frequency
ca-08_odp.02: system(s) or system components
ca-08.02_odp: red team exercises
ca-08.03_odp.01: frequency
ca-08.03_odp.02: No label Choices: 2
ca-09_odp.01: system components
ca-09_odp.02: conditions
ca-09_odp.03: frequency
cm-1_prm_1: organization-defined personnel or roles
cm-01_odp.01: personnel or roles
cm-01_odp.02: personnel or roles
cm-01_odp.03: No label Choices: 3
cm-01_odp.04: official
cm-01_odp.05: frequency
cm-01_odp.06: events
cm-01_odp.07: frequency
cm-01_odp.08: events
cm-02_odp.01: frequency
cm-02_odp.02: circumstances
No statement available
cm-02.02_odp: automated mechanisms
cm-02.03_odp: number
No statement available
No statement available
cm-02.07_odp.01: systems or system components
cm-02.07_odp.02: configurations
cm-02.07_odp.03: controls
cm-03_odp.01: time period
cm-03_odp.02: configuration change control element
cm-03_odp.03: No label Choices: 2
cm-03_odp.04: frequency
cm-03_odp.05: configuration change conditions
cm-03.01_odp.01: automated mechanisms
cm-03.01_odp.02: approval authorities
cm-03.01_odp.03: time period
cm-03.01_odp.04: personnel
cm-03.03_odp: automated mechanisms
cm-3.4_prm_1: organization-defined security and privacy representatives
cm-03.04_odp.01: security representatives
cm-03.04_odp.02: privacy representatives
cm-03.04_odp.03: configuration change control element
cm-03.05_odp: security responses
cm-03.06_odp: controls
cm-03.07_odp.01: frequency
cm-03.07_odp.02: circumstances
cm-03.08_odp: circumstances
cm-05.01_odp: automated mechanisms
No statement available
No statement available
cm-5.4_prm_1: organization-defined system components and system-level information
cm-05.04_odp.01: system components
cm-05.04_odp.02: system-level information
cm-5.5_prm_1: organization-defined frequency
cm-05.05_odp.01: frequency
cm-05.05_odp.02: frequency
No statement available
cm-06_odp.01: common secure configurations
cm-06_odp.02: system components
cm-06_odp.03: operational requirements
cm-6.1_prm_2: organization-defined automated mechanisms
cm-06.01_odp.01: system components
cm-06.01_odp.02: automated mechanisms
cm-06.01_odp.03: automated mechanisms
cm-06.01_odp.04: automated mechanisms
cm-06.02_odp.01: actions
cm-06.02_odp.02: configuration settings
No statement available
No statement available
cm-7_prm_2: organization-defined prohibited or restricted functions, system ports, protocols, software, and/or services
cm-07_odp.01: mission-essential capabilities
cm-07_odp.02: functions
cm-07_odp.03: ports
cm-07_odp.04: protocols
cm-07_odp.05: software
cm-07_odp.06: services
cm-7.1_prm_2: organization-defined functions, ports, protocols, software, and services within the system deemed to be unnecessary and/or nonsecure
cm-07.01_odp.01: frequency
cm-07.01_odp.02: functions
cm-07.01_odp.03: ports
cm-07.01_odp.04: protocols
cm-07.01_odp.05: software
cm-07.01_odp.06: services
cm-07.02_odp.01: No label Choices: 2
cm-07.02_odp.02: policies, rules of behavior, and/or access agreements regarding software program usage and restrictions
cm-07.03_odp: registration requirements
cm-07.04_odp.01: software programs
cm-07.04_odp.02: frequency
cm-07.05_odp.01: software programs
cm-07.05_odp.02: frequency
cm-07.06_odp: user-installed software
cm-07.07_odp: personnel or roles
cm-07.09_odp.01: hardware components
cm-07.09_odp.02: frequency
cm-08_odp.01: information
cm-08_odp.02: frequency
cm-8.2_prm_1: organization-defined automated mechanisms
cm-08.02_odp.01: automated mechanisms
cm-08.02_odp.02: automated mechanisms
cm-08.02_odp.03: automated mechanisms
cm-08.02_odp.04: automated mechanisms
cm-8.3_prm_1: organization-defined automated mechanisms
cm-08.03_odp.01: automated mechanisms
cm-08.03_odp.02: automated mechanisms
cm-08.03_odp.03: automated mechanisms
cm-08.03_odp.04: frequency
cm-08.03_odp.05: No label Choices: 3
cm-08.03_odp.06: personnel or roles
cm-08.04_odp: No label Choices: 3
No statement available
cm-08.08_odp: automated mechanisms
cm-08.09_odp: personnel or roles
cm-09_odp: personnel or roles
cm-10.01_odp: restrictions
cm-11_odp.01: policies
cm-11_odp.02: methods
cm-11_odp.03: frequency
No statement available
cm-11.3_prm_1: organization-defined automated mechanisms
cm-11.03_odp.01: automated mechanisms
cm-11.03_odp.02: automated mechanisms
cm-12_odp: information
cm-12.01_odp.01: information by information type
cm-12.01_odp.02: system components
cm-14_prm_1: organization-defined software and firmware components
cm-14_odp.01: software components
cm-14_odp.02: firmware components
cp-1_prm_1: organization-defined personnel or roles
cp-01_odp.01: personnel or roles
cp-01_odp.02: personnel or roles
cp-01_odp.03: No label Choices: 3
cp-01_odp.04: official
cp-01_odp.05: frequency
cp-01_odp.06: events
cp-01_odp.07: frequency
cp-01_odp.08: events
cp-2_prm_1: organization-defined personnel or roles
cp-2_prm_2: organization-defined key contingency personnel (identified by name and/or by role) and organizational elements
cp-2_prm_4: organization-defined key contingency personnel (identified by name and/or by role) and organizational elements
cp-02_odp.01: personnel or roles
cp-02_odp.02: personnel or roles
cp-02_odp.03: key contingency personnel
cp-02_odp.04: organizational elements
cp-02_odp.05: frequency
cp-02_odp.06: key contingency personnel
cp-02_odp.07: organizational elements
cp-02.03_odp.01: No label Choices: 2
cp-02.03_odp.02: time period
No statement available
cp-02.05_odp: No label Choices: 2
cp-02.06_odp: No label Choices: 2
cp-02.08_odp: No label Choices: 2
cp-03_odp.01: time period
cp-03_odp.02: frequency
cp-03_odp.03: frequency
cp-03_odp.04: events
cp-4_prm_2: organization-defined tests
cp-04_odp.01: frequency
cp-04_odp.02: tests
cp-04_odp.03: tests
cp-04.03_odp: automated mechanisms
cp-04.05_odp.01: mechanisms
cp-04.05_odp.02: system or system component
No statement available
cp-07_odp.01: system operations
cp-07_odp.02: time period
No statement available
cp-08_odp.01: system operations
cp-08_odp.02: time period
cp-8.4_prm_1: organization-defined frequency
cp-08.04_odp.01: frequency
cp-08.04_odp.02: frequency
cp-08.05_odp: frequency
cp-09_odp.01: system components
cp-09_odp.02: frequency
cp-09_odp.03: frequency
cp-09_odp.04: frequency
cp-9.1_prm_1: organization-defined frequency
cp-09.01_odp.01: frequency
cp-09.01_odp.02: frequency
cp-09.03_odp: critical system software and other security-related information
No statement available
cp-9.5_prm_1: organization-defined time period and transfer rate consistent with the recovery time and recovery point objectives
cp-09.05_odp.01: time period
cp-09.05_odp.02: transfer rate
cp-09.07_odp: backup information
cp-09.08_odp: backup information
cp-10_prm_1: organization-defined time period consistent with recovery time and recovery point objectives
cp-10_odp.01: time period
cp-10_odp.02: time period
No statement available
cp-10.04_odp: restoration time periods
No statement available
cp-11_odp: alternative communications protocols
cp-12_odp.01: restrictions
cp-12_odp.02: conditions
cp-13_odp.01: alternative or supplemental security mechanisms
cp-13_odp.02: security functions
ia-1_prm_1: organization-defined personnel or roles
ia-01_odp.01: personnel or roles
ia-01_odp.02: personnel or roles
ia-01_odp.03: No label Choices: 3
ia-01_odp.04: official
ia-01_odp.05: frequency
ia-01_odp.06: events
ia-01_odp.07: frequency
ia-01_odp.08: events
No statement available
No statement available
ia-02.06_odp.01: No label Choices: 3
ia-02.06_odp.02: No label Choices: 2
ia-02.06_odp.03: strength of mechanism requirements
No statement available
ia-02.08_odp: No label Choices: 2
No statement available
ia-02.10_odp: system accounts and services
No statement available
ia-02.13_odp.01: out-of-band authentication
ia-02.13_odp.02: conditions
ia-03_odp.01: devices and/or types of devices
ia-03_odp.02: No label Choices: 3
ia-03.01_odp.01: devices and/or types of devices
ia-03.01_odp.02: No label Choices: 3
No statement available
ia-3.3_prm_1: organization-defined lease information and lease duration
ia-03.03_odp.01: lease information
ia-03.03_odp.02: lease duration
ia-03.04_odp: configuration management process
ia-04_odp.01: personnel or roles
ia-04_odp.02: time period
No statement available
No statement available
ia-04.04_odp: characteristics
ia-04.05_odp: dynamic identifier policy
ia-04.06_odp: external organizations
No statement available
ia-04.09_odp: protected central storage
ia-05_odp.01: time period by authenticator type
ia-05_odp.02: events
ia-05.01_odp.01: frequency
ia-05.01_odp.02: composition and complexity rules
No statement available
No statement available
ia-05.08_odp: security controls
ia-05.09_odp: external organizations
ia-05.10_odp: binding rules
No statement available
ia-05.12_odp: biometric quality requirements
ia-05.13_odp: time period
ia-05.16_odp.01: types of and/or specific authenticators
ia-05.16_odp.02: No label Choices: 2
ia-05.16_odp.03: registration authority
ia-05.16_odp.04: personnel or roles
ia-05.18_odp.01: password managers
ia-05.18_odp.02: controls
No statement available
ia-08.04_odp: identity management profiles
ia-08.05_odp: policy
ia-08.06_odp: measures
ia-09_odp: system services and applications
No statement available
No statement available
ia-10_odp.01: supplemental authentication techniques or mechanisms
ia-10_odp.02: circumstances or situations
ia-11_odp: circumstances or situations
ia-12.03_odp: methods of validation and verification
ia-12.05_odp: No label Choices: 2
ia-12.06_odp: identity assurance level
ia-13_odp.01: policy
ia-13_odp.02: mechanisms
ir-1_prm_1: organization-defined personnel or roles
ir-01_odp.01: personnel or roles
ir-01_odp.02: personnel or roles
ir-01_odp.03: No label Choices: 3
ir-01_odp.04: official
ir-01_odp.05: frequency
ir-01_odp.06: events
ir-01_odp.07: frequency
ir-01_odp.08: events
ir-02_odp.01: time period
ir-02_odp.02: frequency
ir-02_odp.03: frequency
ir-02_odp.04: events
ir-02.02_odp: automated mechanisms
ir-03_odp.01: frequency
ir-03_odp.02: tests
ir-03.01_odp: automated mechanisms
ir-04.01_odp: automated mechanisms
ir-04.02_odp.01: types of dynamic reconfiguration
ir-04.02_odp.02: system components
ir-04.03_odp.01: classes of incidents
ir-04.03_odp.02: actions
ir-04.05_odp: security violations
ir-04.07_odp: entities
ir-04.08_odp.01: external organizations
ir-04.08_odp.02: incident information
ir-04.09_odp: dynamic response capabilities
ir-04.11_odp: time period
ir-04.13_odp: environments or resources
ir-5.1_prm_1: organization-defined automated mechanisms
ir-05.01_odp.01: automated mechanisms
ir-05.01_odp.02: automated mechanisms
ir-05.01_odp.03: automated mechanisms
ir-06_odp.01: time period
ir-06_odp.02: authorities
ir-06.01_odp: automated mechanisms
ir-06.02_odp: personnel or roles
ir-07.01_odp: automated mechanisms
ir-8_prm_5: organization-defined incident response personnel (identified by name and/or by role) and organizational elements
ir-08_odp.01: personnel or roles
ir-08_odp.02: frequency
ir-08_odp.03: entities, personnel, or roles
ir-08_odp.04: incident response personnel
ir-08_odp.05: organizational elements
ir-08_odp.06: incident response personnel
ir-08_odp.07: organizational elements
ir-09_odp.01: personnel or roles
ir-09_odp.02: personnel or roles
ir-09_odp.03: actions
No statement available
ir-09.02_odp: frequency
ir-09.03_odp: procedures
ir-09.04_odp: controls
No statement available
ma-1_prm_1: organization-defined personnel or roles
ma-01_odp.01: personnel or roles
ma-01_odp.02: personnel or roles
ma-01_odp.03: No label Choices: 3
ma-01_odp.04: official
ma-01_odp.05: frequency
ma-01_odp.06: events
ma-01_odp.07: frequency
ma-01_odp.08: events
ma-02_odp.01: personnel or roles
ma-02_odp.02: information
ma-02_odp.03: information
No statement available
ma-2.2_prm_1: organization-defined automated mechanisms
ma-02.02_odp.01: automated mechanisms
ma-02.02_odp.02: automated mechanisms
ma-02.02_odp.03: automated mechanisms
ma-03_odp: frequency
ma-03.03_odp: personnel or roles
ma-4.1_prm_1: organization-defined audit events
ma-04.01_odp.01: audit events
ma-04.01_odp.02: audit events
No statement available
ma-04.04_odp: authenticators that are replay resistant
ma-04.05_odp.01: personnel or roles
ma-04.05_odp.02: personnel and roles
ma-04.06_odp: cryptographic mechanisms
ma-05.01_odp: alternate controls
ma-06_odp.01: system components
ma-06_odp.02: time period
ma-06.01_odp.01: system components
ma-06.01_odp.02: time intervals
ma-06.02_odp.01: system components
ma-06.02_odp.02: time intervals
ma-06.03_odp: automated mechanisms
ma-07_odp.01: systems or system components
ma-07_odp.02: trusted maintenance facilities
mp-1_prm_1: organization-defined personnel or roles
mp-01_odp.01: personnel or roles
mp-01_odp.02: personnel or roles
mp-01_odp.03: No label Choices: 3
mp-01_odp.04: official
mp-01_odp.05: frequency
mp-01_odp.06: events
mp-01_odp.07: frequency
mp-01_odp.08: events
mp-2_prm_1: organization-defined types of digital and/or non-digital media
mp-2_prm_2: organization-defined personnel or roles
mp-02_odp.01: types of digital media
mp-02_odp.02: personnel or roles
mp-02_odp.03: types of non-digital media
mp-02_odp.04: personnel or roles
No statement available
No statement available
mp-03_odp.01: types of media exempted from marking
mp-03_odp.02: controlled areas
mp-4_prm_1: organization-defined types of digital and/or non-digital media
mp-4_prm_2: organization-defined controlled areas
mp-04_odp.01: types of digital media
mp-04_odp.02: types of non-digital media
mp-04_odp.03: types of digital media
mp-04_odp.04: types of non-digital media
mp-04_odp.05: controlled areas
mp-04_odp.06: controlled areas
No statement available
mp-4.2_prm_1: organization-defined automated mechanisms
mp-04.02_odp.01: automated mechanisms
mp-04.02_odp.02: automated mechanisms
mp-04.02_odp.03: automated mechanisms
mp-5_prm_2: organization-defined controls
mp-05_odp.01: types of system media
mp-05_odp.02: controls
mp-05_odp.03: controls
No statement available
No statement available
No statement available
mp-6_prm_1: organization-defined system media
mp-6_prm_2: organization-defined sanitization techniques and procedures
mp-06_odp.01: system media
mp-06_odp.02: system media
mp-06_odp.03: system media
mp-06_odp.04: sanitization techniques and procedures
mp-06_odp.05: sanitization techniques and procedures
mp-06_odp.06: sanitization techniques and procedures
mp-6.2_prm_1: organization-defined frequency
mp-06.02_odp.01: frequency
mp-06.02_odp.02: frequency
mp-06.03_odp: circumstances
No statement available
No statement available
No statement available
mp-06.07_odp: system media
mp-06.08_odp.01: systems or system components
mp-06.08_odp.02: No label Choices: 2
mp-06.08_odp.03: conditions
mp-07_odp.01: types of system media
mp-07_odp.02: No label Choices: 2
mp-07_odp.03: systems or system components
mp-07_odp.04: controls
No statement available
mp-08_odp.01: system media downgrading process
mp-08_odp.02: system media requiring downgrading
mp-8.2_prm_1: organization-defined frequency
mp-08.02_odp.01: frequency
mp-08.02_odp.02: frequency
pe-1_prm_1: organization-defined personnel or roles
pe-01_odp.01: personnel or roles
pe-01_odp.02: personnel or roles
pe-01_odp.03: No label Choices: 3
pe-01_odp.04: official
pe-01_odp.05: frequency
pe-01_odp.06: events
pe-01_odp.07: frequency
pe-01_odp.08: events
pe-02_odp: frequency
pe-02.02_odp: list of acceptable forms of identification
pe-02.03_odp.01: No label Choices: 4
pe-02.03_odp.02: physical access authorizations
pe-3_prm_9: organization-defined frequency
pe-03_odp.01: entry and exit points
pe-03_odp.02: No label Choices: 2
pe-03_odp.03: systems or devices
pe-03_odp.04: entry or exit points
pe-03_odp.05: physical access controls
pe-03_odp.06: circumstances
pe-03_odp.07: physical access devices
pe-03_odp.08: frequency
pe-03_odp.09: frequency
pe-03_odp.10: frequency
pe-03.01_odp: physical spaces
pe-03.02_odp: frequency
pe-03.03_odp: physical access points
pe-03.04_odp: system components
pe-03.05_odp.01: anti-tamper technologies
pe-03.05_odp.02: No label Choices: 2
pe-03.05_odp.03: hardware components
No statement available
pe-03.08_odp: locations
pe-04_odp.01: system distribution and transmission lines
pe-04_odp.02: security controls
pe-05_odp: output devices
No statement available
No statement available
pe-06_odp.01: frequency
pe-06_odp.02: events
pe-06.02_odp.01: classes or types of intrusions
pe-06.02_odp.02: response actions
pe-06.02_odp.03: automated mechanisms
pe-06.03_odp.01: operational areas
pe-06.03_odp.02: frequency
pe-06.03_odp.03: time period
pe-06.04_odp: physical spaces
No statement available
pe-08_odp.01: time period
pe-08_odp.02: frequency
pe-08_odp.03: personnel
pe-8.1_prm_1: organization-defined automated mechanisms
pe-08.01_odp.01: automated mechanisms
pe-08.01_odp.02: automated mechanisms
No statement available
pe-08.03_odp: elements
pe-09.01_odp: distance
pe-09.02_odp: critical system components
pe-10_odp.01: system or individual system components
pe-10_odp.02: location
No statement available
pe-11_odp: No label Choices: 2
pe-11.01_odp: No label Choices: 2
pe-11.02_odp.01: No label Choices: 2
pe-11.02_odp.02: No label Choices: 2
pe-13.01_odp.01: personnel or roles
pe-13.01_odp.02: emergency responders
pe-13.02_odp.01: personnel or roles
pe-13.02_odp.02: emergency responders
No statement available
pe-13.04_odp.01: frequency
pe-13.04_odp.02: time period
pe-14_odp.01: No label Choices: 5
pe-14_odp.02: environmental control
pe-14_odp.03: acceptable levels
pe-14_odp.04: frequency
pe-14.01_odp: automatic environmental controls
pe-14.02_odp: personnel or roles
pe-15.01_odp.01: personnel or roles
pe-15.01_odp.02: automated mechanisms
pe-16_prm_1: organization-defined types of system components
pe-16_odp.01: types of system components
pe-16_odp.02: types of system components
pe-17_odp.01: alternate work sites
pe-17_odp.02: controls
pe-18_odp: physical and environmental hazards
No statement available
pe-20_odp.01: asset location technologies
pe-20_odp.02: assets
pe-20_odp.03: controlled areas
pe-21_odp.01: protective measures
pe-21_odp.02: system and system components
pe-22_odp: system hardware components
pl-1_prm_1: organization-defined personnel or roles
pl-01_odp.01: personnel or roles
pl-01_odp.02: personnel or roles
pl-01_odp.03: No label Choices: 3
pl-01_odp.04: official
pl-01_odp.05: frequency
pl-01_odp.06: events
pl-01_odp.07: frequency
pl-01_odp.08: events
pl-02_odp.01: individuals or groups
pl-02_odp.02: personnel or roles
pl-02_odp.03: frequency
No statement available
No statement available
No statement available
No statement available
pl-04_odp.01: frequency
pl-04_odp.02: No label Choices: 2
pl-04_odp.03: frequency
No statement available
No statement available
pl-07_odp: frequency
pl-08_odp: frequency
pl-08.01_odp.01: controls
pl-08.01_odp.02: locations and architectural layers
pl-08.02_odp.01: controls
pl-08.02_odp.02: locations and architectural layers
pl-09_odp: controls and related processes
pm-01_odp.01: frequency
pm-01_odp.02: events
pm-05_odp: frequency
pm-05.01_odp: frequency
pm-07.01_odp: non-essential functions or services
pm-09_odp: frequency
pm-11_odp: frequency
pm-17_prm_1: organization-defined frequency
pm-17_odp.01: frequency
pm-17_odp.02: frequency
pm-18_odp: frequency
pm-23_odp.01: roles
pm-23_odp.02: responsibilities
pm-25_prm_1: organization-defined frequency
pm-25_odp.01: frequency
pm-25_odp.02: frequency
pm-25_odp.03: frequency
pm-25_odp.04: frequency
pm-26_prm_1: organization-defined time period
pm-26_odp.01: time period
pm-26_odp.02: time period
pm-26_odp.03: time period
pm-26_odp.04: time period
pm-27_odp.01: privacy reports
pm-27_odp.02: oversight bodies
pm-27_odp.03: officials
pm-27_odp.04: frequency
pm-28_odp.01: personnel
pm-28_odp.02: frequency
pm-30_odp: frequency
pm-31_prm_4: organization-defined personnel or roles
pm-31_prm_5: organization-defined frequency
pm-31_odp.01: metrics
pm-31_odp.02: monitoring frequencies
pm-31_odp.03: assessment frequencies
pm-31_odp.04: personnel or roles
pm-31_odp.05: personnel or roles
pm-31_odp.06: frequency
pm-31_odp.07: frequency
pm-32_odp: systems or system components
ps-1_prm_1: organization-defined personnel or roles
ps-01_odp.01: personnel or roles
ps-01_odp.02: personnel or roles
ps-01_odp.03: No label Choices: 3
ps-01_odp.04: official
ps-01_odp.05: frequency
ps-01_odp.06: events
ps-01_odp.07: frequency
ps-01_odp.08: events
ps-02_odp: frequency
ps-3_prm_1: organization-defined conditions requiring rescreening and, where rescreening is so indicated, the frequency of rescreening
ps-03_odp.01: conditions requiring rescreening
ps-03_odp.02: frequency
ps-03.03_odp: additional personnel screening criteria
ps-03.04_odp.01: information types
ps-03.04_odp.02: citizenship requirements
ps-04_odp.01: time period
ps-04_odp.02: information security topics
ps-04.02_odp.01: automated mechanisms
ps-04.02_odp.02: No label Choices: 2
ps-04.02_odp.03: personnel or roles
ps-05_odp.01: transfer or reassignment actions
ps-05_odp.02: time period following the formal transfer action
ps-05_odp.03: personnel or roles
ps-05_odp.04: time period
ps-06_odp.01: frequency
ps-06_odp.02: frequency
No statement available
ps-07_odp.01: personnel or roles
ps-07_odp.02: time period
ps-08_odp.01: personnel or roles
ps-08_odp.02: time period
pt-1_prm_1: organization-defined personnel or roles
pt-01_odp.01: personnel or roles
pt-01_odp.02: personnel or roles
pt-01_odp.03: No label Choices: 3
pt-01_odp.04: official
pt-01_odp.05: frequency
pt-01_odp.06: events
pt-01_odp.07: frequency
pt-01_odp.08: events
pt-02_odp.01: authority
pt-02_odp.02: processing
pt-02_odp.03: processing
pt-02.01_odp.01: authorized processing
pt-02.01_odp.02: elements of personally identifiable information
pt-02.02_odp: automated mechanisms
pt-03_odp.01: purpose(s)
pt-03_odp.02: processing
pt-03_odp.03: mechanisms
pt-03_odp.04: requirements
pt-03.01_odp.01: processing purposes
pt-03.01_odp.02: elements of personally identifiable information
pt-03.02_odp: automated mechanisms
pt-04_odp: tools or mechanisms
pt-04.01_odp: mechanisms
pt-04.02_odp.01: consent mechanisms
pt-04.02_odp.02: frequency
pt-04.02_odp.03: personally identifiable information processing
pt-04.03_odp: tools or mechanisms
pt-05_odp.01: frequency
pt-05_odp.02: information
pt-05.01_odp: frequency
pt-06.01_odp: frequency
pt-06.02_odp: frequency
pt-07_odp: processing conditions
ra-1_prm_1: organization-defined personnel or roles
ra-01_odp.01: personnel or roles
ra-01_odp.02: personnel or roles
ra-01_odp.03: No label Choices: 3
ra-01_odp.04: official
ra-01_odp.05: frequency
ra-01_odp.06: events
ra-01_odp.07: frequency
ra-01_odp.08: events
ra-03_odp.01: No label Choices: 3
ra-03_odp.02: document
ra-03_odp.03: frequency
ra-03_odp.04: personnel or roles
ra-03_odp.05: frequency
ra-03.01_odp.01: systems, system components, and system services
ra-03.01_odp.02: frequency
ra-03.03_odp: means
ra-3.4_prm_2: organization-defined advanced automation and analytics capabilities
ra-03.04_odp.01: advanced automation capabilities
ra-03.04_odp.02: systems or system components
ra-03.04_odp.03: advanced analytics capabilities
No statement available
ra-5_prm_1: organization-defined frequency and/or randomly in accordance with organization-defined process
ra-05_odp.01: frequency and/or randomly in accordance with organization-defined process
ra-05_odp.02: frequency and/or randomly in accordance with organization-defined process
ra-05_odp.03: response times
ra-05_odp.04: personnel or roles
No statement available
ra-05.02_odp.01: No label Choices: 3
ra-05.02_odp.02: frequency
ra-05.04_odp: corrective actions
ra-05.05_odp.01: system components
ra-05.05_odp.02: vulnerability scanning activities
ra-05.06_odp: automated mechanisms
No statement available
ra-05.08_odp.01: system
ra-05.08_odp.02: time period
No statement available
ra-06_odp.01: locations
ra-06_odp.02: No label Choices: 2
ra-06_odp.03: frequency
ra-06_odp.04: events or indicators
ra-09_odp.01: systems, system components, or system services
ra-09_odp.02: decision points in the system development life cycle
ra-10_odp: frequency
sa-1_prm_1: organization-defined personnel or roles
sa-01_odp.01: personnel or roles
sa-01_odp.02: personnel or roles
sa-01_odp.03: No label Choices: 3
sa-01_odp.04: official
sa-01_odp.05: frequency
sa-01_odp.06: events
sa-01_odp.07: frequency
sa-01_odp.08: events
sa-03_odp: system-development life cycle
sa-04_odp.01: No label Choices: 2
sa-04_odp.02: contract language
sa-04.02_odp.01: No label Choices: 5
sa-04.02_odp.02: design and implementation information
sa-04.02_odp.03: level of detail
sa-04.03_odp.01: systems engineering methods
sa-04.03_odp.02: No label Choices: 2
sa-04.03_odp.03: system security engineering methods
sa-04.03_odp.04: privacy engineering methods
sa-04.03_odp.05: No label Choices: 3
sa-04.03_odp.06: software development methods
sa-04.03_odp.07: testing, evaluation, assessment, verification, and validation methods
sa-04.03_odp.08: quality control processes
No statement available
sa-04.05_odp: security configurations
sa-04.11_odp: Privacy Act requirements
sa-04.12_odp: time frame
sa-05_odp.01: actions
sa-05_odp.02: personnel or roles
No statement available
No statement available
No statement available
No statement available
No statement available
No statement available
No statement available
sa-8_prm_1: organization-defined systems security and privacy engineering principles
sa-08_odp.01: systems security engineering principles
sa-08_odp.02: privacy engineering principles
sa-08.02_odp: systems or system components
sa-8.3_prm_1: organization-defined systems or system components
sa-08.03_odp.01: systems or system components
sa-08.03_odp.02: systems or system components
sa-08.04_odp: systems or system components
sa-08.05_odp: systems or system components
sa-08.06_odp: systems or system components
sa-08.07_odp: systems or system components
sa-08.08_odp: systems or system components
sa-08.09_odp: systems or system components
sa-08.10_odp: systems or system components
sa-08.11_odp: systems or system components
sa-08.12_odp: systems or system components
sa-08.13_odp: systems or system components
sa-08.14_odp: systems or system components
sa-08.15_odp: systems or system components
sa-08.16_odp: systems or system components
sa-08.17_odp: systems or system components
sa-08.18_odp: systems or system components
sa-08.19_odp: systems or system components
sa-08.20_odp: systems or system components
sa-08.21_odp: systems or system components
sa-8.22_prm_1: organization-defined systems or system components
sa-08.22_odp.01: systems or system components
sa-08.22_odp.02: systems or system components
sa-08.23_odp: systems or system components
sa-8.24_prm_1: organization-defined systems or system components
sa-08.24_odp.01: systems or system components
sa-08.24_odp.02: systems or system components
sa-08.25_odp: systems or system components
sa-08.26_odp: systems or system components
sa-08.27_odp: systems or system components
sa-08.28_odp: systems or system components
sa-08.29_odp: systems or system components
sa-08.30_odp: systems or system components
sa-08.31_odp: systems or system components
sa-08.32_odp: systems or system components
sa-08.33_odp: processes
sa-09_odp.01: controls
sa-09_odp.02: processes, methods, and techniques
sa-09.01_odp: personnel or roles
sa-09.02_odp: external system services
sa-9.3_prm_1: organization-defined security and privacy requirements, properties, factors, or conditions defining acceptable trust relationships
sa-09.03_odp.01: security requirements, properties, factors, or conditions
sa-09.03_odp.02: privacy requirements, properties, factors, or conditions
sa-09.04_odp.01: external service providers
sa-09.04_odp.02: actions
sa-09.05_odp.01: No label Choices: 3
sa-09.05_odp.02: locations
sa-09.05_odp.03: requirements
sa-10_odp.01: No label Choices: 5
sa-10_odp.02: configuration items
sa-10_odp.03: personnel
sa-10.7_prm_1: organization-defined security and privacy representatives
sa-10.7_prm_2: organization-defined configuration change management and control process
sa-10.07_odp.01: security representatives
sa-10.07_odp.02: privacy representatives
sa-10.07_odp.03: configuration change management and control processes
sa-10.07_odp.04: configuration change management and control processes
sa-11_odp.01: No label Choices: 4
sa-11_odp.02: frequency to conduct
sa-11_odp.03: depth and coverage
sa-11.2_prm_3: organization-defined breadth and depth of modeling and analyses
sa-11.2_prm_4: organization-defined acceptance criteria
sa-11.02_odp.01: information
sa-11.02_odp.02: tools and methods
sa-11.02_odp.03: breadth and depth
sa-11.02_odp.04: breadth and depth
sa-11.02_odp.05: acceptance criteria
sa-11.02_odp.06: acceptance criteria
sa-11.03_odp: independence criteria
sa-11.04_odp.01: specific code
sa-11.04_odp.02: processes, procedures, and/or techniques
sa-11.5_prm_1: organization-defined breadth and depth of testing
sa-11.05_odp.01: breadth
sa-11.05_odp.02: depth
sa-11.05_odp.03: constraints
sa-11.7_prm_1: organization-defined breadth and depth of testing and evaluation
sa-11.07_odp.01: breadth
sa-11.07_odp.02: depth
No statement available
No statement available
No statement available
No statement available
No statement available
No statement available
No statement available
No statement available
No statement available
No statement available
No statement available
No statement available
No statement available
No statement available
No statement available
No statement available
No statement available
No statement available
No statement available
sa-15_prm_2: organization-defined security and privacy requirements
sa-15_odp.01: frequency
sa-15_odp.02: security requirements
sa-15_odp.03: privacy requirements
sa-15.01_odp.01: No label Choices: 3
sa-15.01_odp.02: frequency
sa-15.01_odp.03: program review
sa-15.3_prm_2: organization-defined breadth and depth of criticality analysis
sa-15.03_odp.01: decision points
sa-15.03_odp.02: breadth
sa-15.03_odp.03: depth
No statement available
sa-15.05_odp: thresholds
sa-15.07_odp.01: frequency
sa-15.07_odp.02: tools
sa-15.07_odp.03: personnel or roles
No statement available
sa-15.13_odp.01: secure logging format(s)
sa-15.13_odp.02: events types to log
sa-15.13_odp.03: level of detail to log
sa-16_odp: training
sa-17.1_prm_1: organization-defined elements of organizational security and privacy policy
sa-17.01_odp.01: organizational security policy
sa-17.01_odp.02: organizational privacy policy
sa-17.04_odp: No label Choices: 1
sa-17.08_odp.01: critical systems
sa-17.08_odp.02: capabilities
sa-17.09_odp: critical systems
No statement available
No statement available
No statement available
No statement available
No statement available
No statement available
No statement available
No statement available
sa-20_odp: critical system
sa-21_odp.01: system, systems component, or system service
sa-21_odp.02: official government duties
sa-21_odp.03: additional personnel screening criteria
No statement available
sa-22_odp.01: No label Choices: 2
sa-22_odp.02: support from external providers
No statement available
sa-23_odp.01: No label Choices: 3
sa-23_odp.02: systems or system components
sa-24_odp.01: cyber resiliency goals
sa-24_odp.02: cyber resiliency objectives
sa-24_odp.03: cyber resiliency techniques
sa-24_odp.04: cyber resiliency implementation approaches
sa-24_odp.05: cyber resiliency design principles
sc-1_prm_1: organization-defined personnel or roles
sc-01_odp.01: personnel or roles
sc-01_odp.02: personnel or roles
sc-01_odp.03: No label Choices: 3
sc-01_odp.04: official
sc-01_odp.05: frequency
sc-01_odp.06: events
sc-01_odp.07: frequency
sc-01_odp.08: events
No statement available
sc-04.02_odp: procedures
sc-05_odp.01: types of denial-of-service events
sc-05_odp.02: No label Choices: 2
sc-05_odp.03: controls by type of denial-of-service event
sc-05.01_odp: denial-of-service attacks
sc-05.03_odp.01: monitoring tools
sc-05.03_odp.02: system resources
sc-06_odp.01: resources
sc-06_odp.02: No label Choices: 3
sc-06_odp.03: controls
sc-07_odp: No label Choices: 2
No statement available
No statement available
sc-07.04_odp: frequency
sc-07.05_odp.01: No label Choices: 2
sc-07.05_odp.02: systems
No statement available
sc-07.07_odp: safeguards
sc-07.08_odp.01: internal communications traffic
sc-07.08_odp.02: external networks
sc-07.10_odp: frequency
sc-07.11_odp.01: authorized sources
sc-07.11_odp.02: authorized destinations
sc-07.12_odp.01: host-based boundary protection mechanisms
sc-07.12_odp.02: system components
sc-07.13_odp: information security tools, mechanisms, and support components
sc-07.14_odp: managed interfaces
sc-07.19_odp: communication clients
sc-07.20_odp: system components
sc-07.21_odp.01: system components
sc-07.21_odp.02: missions and/or business functions
sc-07.24_odp: processing rules
sc-07.25_odp.01: unclassified national security system
sc-07.25_odp.02: boundary protection device
sc-07.26_odp: boundary protection device
sc-07.27_odp.01: unclassified, non-national security system
sc-07.27_odp.02: boundary protection device
sc-07.28_odp: system
sc-07.29_odp.01: No label Choices: 2
sc-07.29_odp.02: critical system components and functions
sc-08_odp: No label Choices: 2
sc-08.01_odp: No label Choices: 2
sc-08.02_odp: No label Choices: 2
sc-08.03_odp: alternative physical controls
sc-08.04_odp: alternative physical controls
sc-08.05_odp.01: protected distribution system
sc-08.05_odp.02: No label Choices: 2
No statement available
sc-10_odp: time period
sc-11_odp.01: No label Choices: 2
sc-11_odp.02: security functions
sc-11.01_odp: security functions
sc-12_odp: requirements
sc-12.02_odp: No label Choices: 2
sc-12.03_odp: No label Choices: 5
No statement available
No statement available
sc-13_odp.01: cryptographic uses
sc-13_odp.02: types of cryptography
No statement available
No statement available
No statement available
No statement available
No statement available
sc-15_odp: exceptions where remote activation is to be allowed
sc-15.01_odp: No label Choices: 2
No statement available
sc-15.03_odp.01: systems or system components
sc-15.03_odp.02: secure work areas
sc-15.04_odp: online meetings and teleconferences
sc-16_prm_1: organization-defined security and privacy attributes
sc-16_odp.01: security attributes
sc-16_odp.02: privacy attributes
sc-16.03_odp: mechanisms or techniques
sc-17_odp: certificate policy
sc-18.01_odp.01: unacceptable mobile code
sc-18.01_odp.02: corrective actions
sc-18.02_odp: mobile code requirements
sc-18.03_odp: unacceptable mobile code
sc-18.04_odp.01: software applications
sc-18.04_odp.02: actions
No statement available
No statement available
No statement available
sc-23.03_odp: randomness requirements
No statement available
sc-23.05_odp: certificated authorities
sc-24_odp.01: types of system failures on system components
sc-24_odp.02: known system state
sc-24_odp.03: system state information
sc-25_odp: system components
No statement available
sc-27_odp: platform-independent applications
sc-28_odp.01: No label Choices: 2
sc-28_odp.02: information at rest
sc-28.01_odp.01: information
sc-28.01_odp.02: system components or media
sc-28.02_odp: information
sc-28.03_odp.01: No label Choices: 2
sc-28.03_odp.02: safeguards
sc-29_odp: system components
sc-29.01_odp: frequency
sc-30_odp.01: concealment and misdirection techniques
sc-30_odp.02: systems
sc-30_odp.03: time periods
No statement available
sc-30.02_odp: techniques
sc-30.03_odp.01: processing and/or storage
sc-30.03_odp.02: No label Choices: 2
sc-30.03_odp.03: time frequency
sc-30.04_odp: system components
sc-30.05_odp.01: techniques
sc-30.05_odp.02: system components
sc-31_odp: No label Choices: 2
sc-31.02_odp.01: No label Choices: 2
sc-31.02_odp.02: values
sc-31.03_odp: subset of identified covert channels
sc-32_odp.01: system components
sc-32_odp.02: No label Choices: 2
sc-32_odp.03: circumstances for the physical or logical separation of components
No statement available
sc-34_odp.01: system components
sc-34_odp.02: applications
sc-34.01_odp: system components
No statement available
sc-36_prm_1: No label Choices: 2
sc-36_prm_2: organization-defined processing and storage components
sc-36_odp.01: processing components
sc-36_odp.02: No label Choices: 2
sc-36_odp.03: storage components
sc-36_odp.04: No label Choices: 2
sc-36.01_odp.01: distributed processing and storage components
sc-36.01_odp.02: actions
sc-36.02_odp: duplicate systems or system components
sc-37_odp.01: out-of-band channels
sc-37_odp.02: information, system components, or devices
sc-37_odp.03: individuals or systems
sc-37.01_odp.01: controls
sc-37.01_odp.02: individuals or systems
sc-37.01_odp.03: information, system components, or devices
sc-38_odp: operations security controls
sc-39.02_odp: multi-threaded processing
sc-40_prm_1: organization-defined wireless links
sc-40_prm_2: organization-defined types of signal parameter attacks or references to sources for such attacks
sc-40_odp.01: wireless links
sc-40_odp.02: types of signal parameter attacks or references to sources for such attacks
sc-40_odp.03: wireless links
sc-40_odp.04: types of signal parameter attacks or references to sources for such attacks
sc-40.01_odp: level of protection
sc-40.02_odp: level of reduction
sc-40.04_odp: wireless transmitters
sc-41_odp.01: connection ports or input/output devices
sc-41_odp.02: No label Choices: 2
sc-41_odp.03: systems or system components
sc-42_odp.01: No label Choices: 2
sc-42_odp.02: environmental sensing capabilities
sc-42_odp.03: facilities, areas, or systems
sc-42_odp.04: exceptions where remote activation of sensors is allowed
sc-42_odp.05: group of users
sc-42.01_odp: sensors
sc-42.02_odp: measures
No statement available
sc-42.04_odp.01: measures
sc-42.04_odp.02: sensors
sc-42.05_odp: sensors
sc-43_odp: components
sc-44_odp: system, system component, or location
sc-45.01_odp.01: frequency
sc-45.01_odp.02: authoritative time source
sc-45.01_odp.03: time period
sc-46_odp: No label Choices: 2
sc-47_odp: alternate communication paths
sc-48_odp.01: sensors and monitoring capabilities
sc-48_odp.02: locations
sc-48_odp.03: conditions or circumstances
sc-48.01_odp.01: sensors and monitoring capabilities
sc-48.01_odp.02: locations
sc-48.01_odp.03: conditions or circumstances
sc-49_odp: security domains
sc-50_odp: security domains
sc-51_odp.01: system firmware components
sc-51_odp.02: authorized individuals
si-1_prm_1: organization-defined personnel or roles
si-01_odp.01: personnel or roles
si-01_odp.02: personnel or roles
si-01_odp.03: No label Choices: 3
si-01_odp.04: official
si-01_odp.05: frequency
si-01_odp.06: events
si-01_odp.07: frequency
si-01_odp.08: events
si-02_odp: time period
No statement available
si-02.02_odp.01: automated mechanisms
si-02.02_odp.02: frequency
si-02.03_odp: benchmarks
si-02.04_odp: components
si-02.05_odp.01: security-relevant software and firmware updates
si-02.05_odp.02: system components
si-02.06_odp: software and firmware components
si-03_odp.01: No label Choices: 2
si-03_odp.02: frequency
si-03_odp.03: No label Choices: 2
si-03_odp.04: No label Choices: 3
si-03_odp.05: action
si-03_odp.06: personnel or roles
No statement available
No statement available
No statement available
No statement available
si-03.06_odp: frequency
No statement available
si-03.08_odp.01: unauthorized operating system commands
si-03.08_odp.02: system hardware components
si-03.08_odp.03: No label Choices: 3
No statement available
si-03.10_odp: tools and techniques
si-04_odp.01: monitoring objectives
si-04_odp.02: techniques and methods
si-04_odp.03: system monitoring information
si-04_odp.04: personnel or roles
si-04_odp.05: No label Choices: 2
si-04_odp.06: frequency
si-4.4_prm_1: organization-defined frequency
si-4.4_prm_2: organization-defined unusual or unauthorized activities or conditions
si-04.04_odp.01: frequency
si-04.04_odp.02: unusual or unauthorized activities or conditions
si-04.04_odp.03: frequency
si-04.04_odp.04: unusual or unauthorized activities or conditions
si-04.05_odp.01: personnel or roles
si-04.05_odp.02: compromise indicators
No statement available
si-04.07_odp.01: incident response personnel
si-04.07_odp.02: least-disruptive actions
No statement available
si-04.09_odp: frequency
si-04.10_odp.01: encrypted communications traffic
si-04.10_odp.02: system monitoring tools and mechanisms
si-04.11_odp: interior points
si-04.12_odp.01: personnel or roles
si-04.12_odp.02: automated mechanisms
si-04.12_odp.03: activities that trigger alerts
si-04.18_odp: interior points
si-04.19_odp.01: additional monitoring
si-04.19_odp.02: sources
si-04.20_odp: additional monitoring
si-04.21_odp.01: additional monitoring
si-04.21_odp.02: probationary period
si-04.22_odp.01: authorization or approval processes
si-04.22_odp.02: No label Choices: 2
si-04.22_odp.03: personnel or roles
si-04.23_odp.01: host-based monitoring mechanisms
si-04.23_odp.02: system components
si-04.24_odp.01: sources
si-04.24_odp.02: personnel or roles
si-05_odp.01: external organizations
si-05_odp.02: No label Choices: 3
si-05_odp.03: personnel or roles
si-05_odp.04: elements
si-05_odp.05: external organizations
si-05.01_odp: automated mechanisms
si-6_prm_1: organization-defined security and privacy functions
si-06_odp.01: security functions
si-06_odp.02: privacy functions
si-06_odp.03: No label Choices: 3
si-06_odp.04: system transitional states
si-06_odp.05: frequency
si-06_odp.06: personnel or roles
si-06_odp.07: No label Choices: 3
si-06_odp.08: alternative action(s)
No statement available
si-06.03_odp: personnel or roles
si-7_prm_1: organization-defined software, firmware, and information
si-7_prm_2: organization-defined actions
si-07_odp.01: software
si-07_odp.02: firmware
si-07_odp.03: information
si-07_odp.04: actions
si-07_odp.05: actions
si-07_odp.06: actions
si-7.1_prm_1: organization-defined software, firmware, and information
si-7.1_prm_2: No label Choices: 3
si-7.1_prm_3: organization-defined transitional states or security-relevant events
si-7.1_prm_4: organization-defined frequency
si-07.01_odp.01: software
si-07.01_odp.02: No label Choices: 3
si-07.01_odp.03: transitional states or security-relevant events
si-07.01_odp.04: frequency
si-07.01_odp.05: firmware
si-07.01_odp.06: No label Choices: 3
si-07.01_odp.07: transitional states or security-relevant events
si-07.01_odp.08: frequency
si-07.01_odp.09: information
si-07.01_odp.10: No label Choices: 3
si-07.01_odp.11: transitional states or security-relevant events
si-07.01_odp.12: frequency
si-07.02_odp: personnel or roles
No statement available
si-07.05_odp.01: No label Choices: 3
si-07.05_odp.02: controls
si-07.07_odp: changes
si-07.08_odp.01: No label Choices: 4
si-07.08_odp.02: personnel or roles
si-07.08_odp.03: other actions
si-07.09_odp: system components
si-07.10_odp.01: mechanisms
si-07.10_odp.02: system components
No statement available
si-07.12_odp: user-installed software
No statement available
No statement available
si-07.15_odp: software or firmware components
si-07.16_odp: time period
si-07.17_odp: controls
No statement available
si-08.02_odp: frequency
No statement available
si-10_odp: information inputs
si-10.01_odp: authorized individuals
si-10.2_prm_1: organization-defined time period
si-10.02_odp.01: time period
si-10.02_odp.02: time period
si-10.05_odp.01: trusted sources
si-10.05_odp.02: formats
si-11_odp: personnel or roles
si-12.01_odp: elements of personally identifiable information
si-12.2_prm_1: organization-defined techniques
si-12.02_odp.01: techniques
si-12.02_odp.02: techniques
si-12.02_odp.03: techniques
si-12.3_prm_1: organization-defined techniques
si-12.03_odp.01: techniques
si-12.03_odp.02: techniques
si-12.03_odp.03: techniques
si-13_odp.01: system components
si-13_odp.02: mean time to failure (MTTF) substitution criteria
si-13.01_odp: fraction or percentage
No statement available
si-13.03_odp: percentage
si-13.04_odp.01: time period
si-13.04_odp.02: No label Choices: 3
si-13.04_odp.03: alarm
si-13.04_odp.04: action
si-13.05_odp.01: No label Choices: 2
si-13.05_odp.02: failover capability
si-14_odp.01: system components and services
si-14_odp.02: No label Choices: 2
si-14_odp.03: frequency
si-14.01_odp: trusted sources
si-14.02_odp.01: No label Choices: 2
si-14.02_odp.02: information
si-14.02_odp.03: frequency
si-14.02_odp.04: information
si-14.03_odp: No label Choices: 2
si-15_odp: software programs and/or applications
si-16_odp: controls
si-17_prm_1: organization-defined list of failure conditions and associated fail-safe procedures
si-17_odp.01: fail-safe procedures
si-17_odp.02: list of failure conditions
si-18_prm_1: organization-defined frequency
si-18_odp.01: frequency
si-18_odp.02: frequency
si-18_odp.03: frequency
si-18_odp.04: frequency
si-18.01_odp: automated mechanisms
si-18.05_odp: recipients
si-19_odp.01: elements
si-19_odp.02: frequency
si-20_odp: systems or system components
si-21_odp.01: information
si-21_odp.02: frequencies
si-22_odp.01: alternative information sources
si-22_odp.02: essential functions and services
si-22_odp.03: systems or system components
si-23_odp.01: circumstances
si-23_odp.02: information
si-23_odp.03: systems or system components
sr-1_prm_1: organization-defined personnel or roles
sr-01_odp.01: personnel or roles
sr-01_odp.02: personnel or roles
sr-01_odp.03: No label Choices: 3
sr-01_odp.04: official
sr-01_odp.05: frequency
sr-01_odp.06: events
sr-01_odp.07: frequency
sr-01_odp.08: events
sr-02_odp.01: systems, system components, or system services
sr-02_odp.02: frequency
sr-02.01_odp.01: personnel, roles and responsibilities
sr-02.01_odp.02: supply chain risk management activities
sr-03_odp.01: system or system component
sr-03_odp.02: supply chain personnel
sr-03_odp.03: supply chain controls
sr-03_odp.04: No label Choices: 3
sr-03_odp.05: document
sr-3.1_prm_1: organization-defined system components and services
sr-03.01_odp.01: system components
sr-03.01_odp.02: services
sr-03.02_odp: controls
sr-04_odp: systems, system components, and associated data
sr-04.01_odp: supply chain elements, processes, and personnel
sr-04.02_odp: systems and critical system components
sr-4.3_prm_1: organization-defined controls
sr-04.03_odp.01: controls
sr-04.03_odp.02: controls
sr-04.04_odp.01: controls
sr-04.04_odp.02: analysis method
sr-05_odp: strategies, tools, and methods
sr-05.01_odp.01: controls
sr-05.01_odp.02: critical system components
sr-06_odp: frequency
sr-06.01_odp.01: No label Choices: 4
sr-06.01_odp.02: supply chain elements, processes, and actors
sr-07_odp: OPSEC controls
sr-08_odp.01: No label Choices: 2
sr-08_odp.02: results of assessments or audits
sr-10_odp.01: systems or system components
sr-10_odp.02: No label Choices: 3
sr-10_odp.03: frequency
sr-10_odp.04: indications of need for inspection
sr-11_odp.01: No label Choices: 3
sr-11_odp.02: external reporting organizations
sr-11_odp.03: personnel or roles
sr-11.01_odp: personnel or roles
sr-11.02_odp: system components
sr-11.03_odp: frequency
sr-12_odp.01: data, documentation, tools, or system components
sr-12_odp.02: techniques and methods