UUID: 45d9e588-2f43-4317-af05-da08f438c52c
Version: Rev5-High
Last Modified: 2026-04-04 10:38:06+00:00
OSCAL Version: 1.2.1
Control Groups
Total Controls
Click on any group, control, or parameter to expand/collapse. Supports nested sub-groups and sub-controls (enhancements). All data visible with no truncation.
ac-1_prm_1: organization-defined personnel or roles
ac-01_odp.01: personnel or roles
ac-01_odp.02: personnel or roles
ac-01_odp.03: No label Choices: 3
ac-01_odp.04: official
ac-01_odp.05: frequency Values: 1
ac-01_odp.06: events
ac-01_odp.07: frequency Values: 1
ac-01_odp.08: events Values: 1
ac-10_odp.01: account and/or account types Values: 1
ac-10_odp.02: number
ac-11_odp.01: No label Choices: 2
ac-11_odp.02: time period
ac-12_odp: conditions or trigger events
ac-14_odp: user actions
ac-17.4_prm_1: organization-defined needs
ac-17.04_odp.01: needs requiring remote access
ac-17.04_odp.02: needs requiring remote access
ac-18.01_odp: No label Choices: 2
ac-19.05_odp.01: No label Choices: 2
ac-19.05_odp.02: mobile devices
ac-02_odp.01: prerequisites and criteria
ac-02_odp.02: attributes (as required)
ac-02_odp.03: personnel or roles
ac-02_odp.04: policy, procedures, prerequisites, and criteria
ac-02_odp.05: personnel or roles
ac-02_odp.06: time period Values: 1
ac-02_odp.07: time period Values: 1
ac-02_odp.08: time period Values: 1
ac-02_odp.09: attributes (as required)
ac-02_odp.10: frequency Values: 1
ac-02.01_odp: automated mechanisms
ac-02.02_odp.01: No label Choices: 2
ac-02.02_odp.02: time period
ac-02.03_odp.01: time period Values: 1
ac-02.03_odp.02: time period Values: 1
ac-02.05_odp: time period of expected inactivity or description of when to log out Values: 1
ac-02.07_odp: No label Choices: 2
ac-02.09_odp: conditions Values: 1
ac-02.11_odp.01: circumstances and/or usage conditions
ac-02.11_odp.02: system accounts
ac-02.12_odp.01: atypical usage
ac-02.12_odp.02: personnel or roles Values: 1
ac-02.13_odp.01: time period Values: 1
ac-02.13_odp.02: significant risks
ac-20_odp.01: No label Choices: 2
ac-20_odp.02: terms and conditions
ac-20_odp.03: controls asserted
ac-20_odp.04: prohibited types of external systems
ac-20.02_odp: restrictions
ac-21_odp.01: information-sharing circumstances
ac-21_odp.02: automated mechanisms
ac-22_odp: frequency Values: 1
ac-04_odp: information flow control policies
ac-04.04_odp.01: information flow control mechanisms Values: 1
ac-04.04_odp.02: No label Choices: 4
ac-04.04_odp.03: organization-defined procedure or method
ac-4.21_prm_1: organization-defined mechanisms and/or techniques
ac-04.21_odp.01: mechanisms and/or techniques
ac-04.21_odp.02: mechanisms and/or techniques
ac-04.21_odp.03: required separations
ac-05_odp: duties of individuals
ac-6.1_prm_2: organization-defined security functions (deployed in hardware, software, and firmware) Values: 1
ac-06.01_odp.01: individuals and roles
ac-06.01_odp.02: security functions (deployed in hardware)
ac-06.01_odp.03: security functions (deployed in software)
ac-06.01_odp.04: security functions (deployed in firmware)
ac-06.01_odp.05: security-relevant information Values: 1
ac-06.02_odp: security functions or security-relevant information Values: 1
ac-06.03_odp.01: privileged commands Values: 1
ac-06.03_odp.02: compelling operational needs
ac-06.05_odp: personnel or roles
ac-06.07_odp.01: frequency Values: 1
ac-06.07_odp.02: roles and classes Values: 1
ac-06.08_odp: software Values: 1
ac-07_odp.01: number
ac-07_odp.02: time period
ac-07_odp.03: No label Choices: 5
ac-07_odp.04: time period
ac-07_odp.05: delay algorithm
ac-07_odp.06: action
ac-08_odp.01: system use notification Values: 1
ac-08_odp.02: conditions Values: 1
at-1_prm_1: organization-defined personnel or roles
at-01_odp.01: personnel or roles
at-01_odp.02: personnel or roles
at-01_odp.03: No label Choices: 3
at-01_odp.04: official
at-01_odp.05: frequency Values: 1
at-01_odp.06: events
at-01_odp.07: frequency Values: 1
at-01_odp.08: events Values: 1
at-2_prm_1: organization-defined frequency Values: 1
at-2_prm_2: organization-defined events
at-02_odp.01: frequency
at-02_odp.02: frequency
at-02_odp.03: events
at-02_odp.04: events
at-02_odp.05: awareness techniques
at-02_odp.06: frequency Values: 1
at-02_odp.07: events
at-3_prm_1: organization-defined roles and responsibilities
at-03_odp.01: roles and responsibilities
at-03_odp.02: roles and responsibilities
at-03_odp.03: frequency Values: 1
at-03_odp.04: frequency Values: 1
at-03_odp.05: events
at-04_odp: time period Values: 1
au-1_prm_1: organization-defined personnel or roles
au-01_odp.01: personnel or roles
au-01_odp.02: personnel or roles
au-01_odp.03: No label Choices: 3
au-01_odp.04: official
au-01_odp.05: frequency Values: 1
au-01_odp.06: events
au-01_odp.07: frequency Values: 1
au-01_odp.08: events Values: 1
au-10_odp: actions Values: 1
au-11_odp: time period Values: 1
au-12_odp.01: system components Values: 1
au-12_odp.02: personnel or roles
au-12.01_odp.01: system components Values: 1
au-12.01_odp.02: level of tolerance
au-12.03_odp.01: individuals or roles Values: 2
au-12.03_odp.02: system components
au-12.03_odp.03: selectable event criteria
au-12.03_odp.04: time thresholds
au-2_prm_2: organization-defined event types (subset of the event types defined in [AU-2a.](#au-2_smt.a)) along with the frequency of (or situation requiring) logging for each identified event type Values: 1
au-02_odp.01: event types Values: 1
au-02_odp.02: event types (subset of AU-02_ODP[01])
au-02_odp.03: frequency or situation
au-02_odp.04: frequency Values: 1
au-03.01_odp: additional information Values: 1
au-04_odp: audit log retention requirements
au-05_odp.01: personnel or roles
au-05_odp.02: time period
au-05_odp.03: additional actions Values: 1
au-05.01_odp.01: personnel, roles, and/or locations Values: 1
au-05.01_odp.02: time period
au-05.01_odp.03: percentage
au-05.02_odp.01: real-time period Values: 3
au-05.02_odp.02: personnel, roles, and/or locations
au-05.02_odp.03: audit logging failure events requiring real-time alerts
au-06_odp.01: frequency Values: 1
au-06_odp.02: inappropriate or unusual activity
au-06_odp.03: personnel or roles
au-06.01_odp: automated mechanisms
au-06.05_odp.01: No label Choices: 4
au-06.05_odp.02: data/information collected from other sources
au-06.07_odp: No label Choices: 3
au-07.01_odp: fields within audit records
au-08_odp: granularity of time measurement Values: 1
au-09_odp: personnel or roles
au-09.02_odp: frequency Values: 1
au-09.04_odp: subset of privileged users or roles
ca-1_prm_1: organization-defined personnel or roles
ca-01_odp.01: personnel or roles
ca-01_odp.02: personnel or roles
ca-01_odp.03: No label Choices: 3
ca-01_odp.04: official
ca-01_odp.05: frequency Values: 1
ca-01_odp.06: events
ca-01_odp.07: frequency Values: 1
ca-01_odp.08: events Values: 1
ca-02_odp.01: assessment frequency Values: 1
ca-02_odp.02: individuals or roles Values: 1
ca-02.02_odp.01: specialized assessment frequency Values: 1
ca-02.02_odp.02: No label Choices: 2
ca-02.02_odp.03: No label Choices: 9
ca-02.02_odp.04: other forms of assessment
ca-02.03_odp.01: external organization(s) Values: 1
ca-02.03_odp.02: system
ca-02.03_odp.03: requirements
ca-03_odp.01: No label Choices: 7
ca-03_odp.02: type of agreement
ca-03_odp.03: frequency Values: 1
ca-05_odp: frequency Values: 1
ca-06_odp: frequency Values: 1
ca-7_prm_4: organization-defined personnel or roles
ca-7_prm_5: organization-defined frequency
ca-07_odp.01: system-level metrics
ca-07_odp.02: frequencies
ca-07_odp.03: frequencies
ca-07_odp.04: personnel or roles
ca-07_odp.05: frequency
ca-07_odp.06: personnel or roles
ca-07_odp.07: frequency
ca-08_odp.01: frequency Values: 1
ca-08_odp.02: system(s) or system components
ca-08.02_odp: red team exercises
ca-09_odp.01: system components
ca-09_odp.02: conditions
ca-09_odp.03: frequency Values: 1
cm-1_prm_1: organization-defined personnel or roles
cm-01_odp.01: personnel or roles
cm-01_odp.02: personnel or roles
cm-01_odp.03: No label Choices: 3
cm-01_odp.04: official
cm-01_odp.05: frequency Values: 1
cm-01_odp.06: events
cm-01_odp.07: frequency Values: 1
cm-01_odp.08: events Values: 1
cm-11_odp.01: policies
cm-11_odp.02: methods
cm-11_odp.03: frequency Values: 1
cm-12_odp: information
cm-12.01_odp.01: information by information type Values: 1
cm-12.01_odp.02: system components
cm-14_prm_1: organization-defined software and firmware components
cm-14_odp.01: software components
cm-14_odp.02: firmware components
cm-02_odp.01: frequency Values: 1
cm-02_odp.02: circumstances
cm-02.02_odp: automated mechanisms
cm-02.03_odp: number Values: 1
cm-02.07_odp.01: systems or system components
cm-02.07_odp.02: configurations
cm-02.07_odp.03: controls
cm-03_odp.01: time period
cm-03_odp.02: configuration change control element
cm-03_odp.03: No label Choices: 2
cm-03_odp.04: frequency
cm-03_odp.05: configuration change conditions
cm-03.01_odp.01: automated mechanisms
cm-03.01_odp.02: approval authorities
cm-03.01_odp.03: time period Values: 1
cm-03.01_odp.04: personnel Values: 1
cm-3.4_prm_1: organization-defined security and privacy representatives Values: 1
cm-03.04_odp.01: security representatives
cm-03.04_odp.02: privacy representatives
cm-03.04_odp.03: configuration change control element
cm-03.06_odp: controls
cm-05.01_odp: automated mechanisms
cm-5.5_prm_1: organization-defined frequency Values: 1
cm-05.05_odp.01: frequency
cm-05.05_odp.02: frequency
cm-06_odp.01: common secure configurations
cm-06_odp.02: system components
cm-06_odp.03: operational requirements
cm-6.1_prm_2: organization-defined automated mechanisms
cm-06.01_odp.01: system components
cm-06.01_odp.02: automated mechanisms
cm-06.01_odp.03: automated mechanisms
cm-06.01_odp.04: automated mechanisms
cm-06.02_odp.01: actions
cm-06.02_odp.02: configuration settings
cm-7_prm_2: organization-defined prohibited or restricted functions, system ports, protocols, software, and/or services
cm-07_odp.01: mission-essential capabilities
cm-07_odp.02: functions
cm-07_odp.03: ports
cm-07_odp.04: protocols
cm-07_odp.05: software
cm-07_odp.06: services
cm-7.1_prm_2: organization-defined functions, ports, protocols, software, and services within the system deemed to be unnecessary and/or nonsecure
cm-07.01_odp.01: frequency Values: 1
cm-07.01_odp.02: functions
cm-07.01_odp.03: ports
cm-07.01_odp.04: protocols
cm-07.01_odp.05: software
cm-07.01_odp.06: services
cm-07.02_odp.01: No label Choices: 2
cm-07.02_odp.02: policies, rules of behavior, and/or access agreements regarding software program usage and restrictions
cm-07.05_odp.01: software programs
cm-07.05_odp.02: frequency Values: 1
cm-08_odp.01: information
cm-08_odp.02: frequency Values: 1
cm-8.2_prm_1: organization-defined automated mechanisms
cm-08.02_odp.01: automated mechanisms
cm-08.02_odp.02: automated mechanisms
cm-08.02_odp.03: automated mechanisms
cm-08.02_odp.04: automated mechanisms
cm-8.3_prm_1: organization-defined automated mechanisms Values: 1
cm-08.03_odp.01: automated mechanisms
cm-08.03_odp.02: automated mechanisms
cm-08.03_odp.03: automated mechanisms
cm-08.03_odp.04: frequency Values: 1
cm-08.03_odp.05: No label Choices: 3
cm-08.03_odp.06: personnel or roles
cm-08.04_odp: No label Choices: 3
cm-09_odp: personnel or roles
cp-1_prm_1: organization-defined personnel or roles
cp-01_odp.01: personnel or roles
cp-01_odp.02: personnel or roles
cp-01_odp.03: No label Choices: 3
cp-01_odp.04: official
cp-01_odp.05: frequency Values: 1
cp-01_odp.06: events
cp-01_odp.07: frequency Values: 1
cp-01_odp.08: events Values: 1
cp-10_prm_1: organization-defined time period consistent with recovery time and recovery point objectives
cp-10_odp.01: time period
cp-10_odp.02: time period
cp-10.04_odp: restoration time periods Values: 1
cp-2_prm_1: organization-defined personnel or roles
cp-2_prm_2: organization-defined key contingency personnel (identified by name and/or by role) and organizational elements
cp-2_prm_4: organization-defined key contingency personnel (identified by name and/or by role) and organizational elements
cp-02_odp.01: personnel or roles
cp-02_odp.02: personnel or roles
cp-02_odp.03: key contingency personnel
cp-02_odp.04: organizational elements
cp-02_odp.05: frequency Values: 1
cp-02_odp.06: key contingency personnel
cp-02_odp.07: organizational elements
cp-02.03_odp.01: No label Choices: 2
cp-02.03_odp.02: time period
cp-02.05_odp: No label Choices: 2
cp-02.08_odp: No label Choices: 2
cp-03_odp.01: time period Values: 1
cp-03_odp.02: frequency Values: 1
cp-03_odp.03: frequency Values: 1
cp-03_odp.04: events
cp-4_prm_2: organization-defined tests Values: 1
cp-04_odp.01: frequency Values: 1
cp-04_odp.02: tests
cp-04_odp.03: tests
cp-07_odp.01: system operations
cp-07_odp.02: time period
cp-08_odp.01: system operations
cp-08_odp.02: time period
cp-8.4_prm_1: organization-defined frequency Values: 1
cp-08.04_odp.01: frequency
cp-08.04_odp.02: frequency
cp-09_odp.01: system components
cp-09_odp.02: frequency Values: 1
cp-09_odp.03: frequency Values: 1
cp-09_odp.04: frequency Values: 1
cp-9.1_prm_1: organization-defined frequency Values: 1
cp-09.01_odp.01: frequency
cp-09.01_odp.02: frequency
cp-09.03_odp: critical system software and other security-related information
cp-9.5_prm_1: organization-defined time period and transfer rate consistent with the recovery time and recovery point objectives Values: 1
cp-09.05_odp.01: time period
cp-09.05_odp.02: transfer rate
cp-09.08_odp: backup information Values: 1
ia-1_prm_1: organization-defined personnel or roles
ia-01_odp.01: personnel or roles
ia-01_odp.02: personnel or roles
ia-01_odp.03: No label Choices: 3
ia-01_odp.04: official
ia-01_odp.05: frequency Values: 1
ia-01_odp.06: events
ia-01_odp.07: frequency Values: 1
ia-01_odp.08: events Values: 1
ia-11_odp: circumstances or situations
ia-12.03_odp: methods of validation and verification
ia-12.05_odp: No label Choices: 2
ia-02.06_odp.01: No label Choices: 3
ia-02.06_odp.02: No label Choices: 2
ia-02.06_odp.03: strength of mechanism requirements Values: 1
ia-02.08_odp: No label Choices: 2
ia-03_odp.01: devices and/or types of devices
ia-03_odp.02: No label Choices: 3
ia-04_odp.01: personnel or roles Values: 1
ia-04_odp.02: time period Values: 1
ia-04.04_odp: characteristics Values: 1
ia-05_odp.01: time period by authenticator type
ia-05_odp.02: events
ia-05.01_odp.01: frequency
ia-05.01_odp.02: composition and complexity rules
ia-05.08_odp: security controls Values: 1
ia-05.13_odp: time period
ia-08.04_odp: identity management profiles
ir-1_prm_1: organization-defined personnel or roles
ir-01_odp.01: personnel or roles
ir-01_odp.02: personnel or roles
ir-01_odp.03: No label Choices: 3
ir-01_odp.04: official
ir-01_odp.05: frequency Values: 1
ir-01_odp.06: events
ir-01_odp.07: frequency Values: 1
ir-01_odp.08: events Values: 1
ir-02_odp.01: time period Values: 1
ir-02_odp.02: frequency Values: 1
ir-02_odp.03: frequency Values: 1
ir-02_odp.04: events
ir-02.02_odp: automated mechanisms
ir-03_odp.01: frequency Values: 1
ir-03_odp.02: tests
ir-04.01_odp: automated mechanisms
ir-04.02_odp.01: types of dynamic reconfiguration
ir-04.02_odp.02: system components Values: 1
ir-04.11_odp: time period
ir-5.1_prm_1: organization-defined automated mechanisms
ir-05.01_odp.01: automated mechanisms
ir-05.01_odp.02: automated mechanisms
ir-05.01_odp.03: automated mechanisms
ir-06_odp.01: time period Values: 1
ir-06_odp.02: authorities
ir-06.01_odp: automated mechanisms
ir-07.01_odp: automated mechanisms
ir-8_prm_5: organization-defined incident response personnel (identified by name and/or by role) and organizational elements Values: 1
ir-08_odp.01: personnel or roles
ir-08_odp.02: frequency Values: 1
ir-08_odp.03: entities, personnel, or roles
ir-08_odp.04: incident response personnel Values: 1
ir-08_odp.05: organizational elements
ir-08_odp.06: incident response personnel
ir-08_odp.07: organizational elements
ir-09_odp.01: personnel or roles
ir-09_odp.02: personnel or roles
ir-09_odp.03: actions
ir-09.02_odp: frequency Values: 1
ir-09.03_odp: procedures
ir-09.04_odp: controls
ma-1_prm_1: organization-defined personnel or roles
ma-01_odp.01: personnel or roles
ma-01_odp.02: personnel or roles
ma-01_odp.03: No label Choices: 3
ma-01_odp.04: official
ma-01_odp.05: frequency Values: 1
ma-01_odp.06: events
ma-01_odp.07: frequency Values: 1
ma-01_odp.08: events Values: 1
ma-02_odp.01: personnel or roles
ma-02_odp.02: information
ma-02_odp.03: information
ma-2.2_prm_1: organization-defined automated mechanisms
ma-02.02_odp.01: automated mechanisms
ma-02.02_odp.02: automated mechanisms
ma-02.02_odp.03: automated mechanisms
ma-03_odp: frequency Values: 1
ma-03.03_odp: personnel or roles Values: 1
ma-05.01_odp: alternate controls
ma-06_odp.01: system components Values: 1
ma-06_odp.02: time period
mp-1_prm_1: organization-defined personnel or roles
mp-01_odp.01: personnel or roles
mp-01_odp.02: personnel or roles
mp-01_odp.03: No label Choices: 3
mp-01_odp.04: official
mp-01_odp.05: frequency Values: 1
mp-01_odp.06: events
mp-01_odp.07: frequency Values: 1
mp-01_odp.08: events Values: 1
mp-2_prm_1: organization-defined types of digital and/or non-digital media Values: 1
mp-2_prm_2: organization-defined personnel or roles
mp-02_odp.01: types of digital media
mp-02_odp.02: personnel or roles
mp-02_odp.03: types of non-digital media
mp-02_odp.04: personnel or roles
mp-03_odp.01: types of media exempted from marking Values: 1
mp-03_odp.02: controlled areas Values: 1
mp-4_prm_1: organization-defined types of digital and/or non-digital media Values: 1
mp-4_prm_2: organization-defined controlled areas Values: 1
mp-04_odp.01: types of digital media
mp-04_odp.02: types of non-digital media
mp-04_odp.03: types of digital media
mp-04_odp.04: types of non-digital media
mp-04_odp.05: controlled areas
mp-04_odp.06: controlled areas
mp-5_prm_2: organization-defined controls Values: 1
mp-05_odp.01: types of system media Values: 1
mp-05_odp.02: controls
mp-05_odp.03: controls
mp-6_prm_1: organization-defined system media
mp-6_prm_2: organization-defined sanitization techniques and procedures Values: 1
mp-06_odp.01: system media
mp-06_odp.02: system media
mp-06_odp.03: system media
mp-06_odp.04: sanitization techniques and procedures
mp-06_odp.05: sanitization techniques and procedures
mp-06_odp.06: sanitization techniques and procedures
mp-6.2_prm_1: organization-defined frequency Values: 1
mp-06.02_odp.01: frequency
mp-06.02_odp.02: frequency
mp-06.03_odp: circumstances
mp-07_odp.01: types of system media
mp-07_odp.02: No label Choices: 2
mp-07_odp.03: systems or system components
mp-07_odp.04: controls
pe-1_prm_1: organization-defined personnel or roles
pe-01_odp.01: personnel or roles
pe-01_odp.02: personnel or roles
pe-01_odp.03: No label Choices: 3
pe-01_odp.04: official
pe-01_odp.05: frequency Values: 1
pe-01_odp.06: events
pe-01_odp.07: frequency Values: 1
pe-01_odp.08: events Values: 1
pe-10_odp.01: system or individual system components
pe-10_odp.02: location Values: 1
pe-11_odp: No label Choices: 2
pe-11.01_odp: No label Choices: 2
pe-13.01_odp.01: personnel or roles Values: 2
pe-13.01_odp.02: emergency responders
pe-13.02_odp.01: personnel or roles
pe-13.02_odp.02: emergency responders
pe-14_odp.01: No label Choices: 5
pe-14_odp.02: environmental control
pe-14_odp.03: acceptable levels
pe-14_odp.04: frequency Values: 1
pe-14.02_odp: personnel or roles
pe-15.01_odp.01: personnel or roles Values: 1
pe-15.01_odp.02: automated mechanisms
pe-16_prm_1: organization-defined types of system components Values: 1
pe-16_odp.01: types of system components
pe-16_odp.02: types of system components
pe-17_odp.01: alternate work sites
pe-17_odp.02: controls
pe-18_odp: physical and environmental hazards Values: 1
pe-02_odp: frequency Values: 1
pe-3_prm_9: organization-defined frequency Values: 1
pe-03_odp.01: entry and exit points
pe-03_odp.02: No label Choices: 2
pe-03_odp.03: systems or devices
pe-03_odp.04: entry or exit points
pe-03_odp.05: physical access controls
pe-03_odp.06: circumstances Values: 1
pe-03_odp.07: physical access devices
pe-03_odp.08: frequency Values: 1
pe-03_odp.09: frequency
pe-03_odp.10: frequency
pe-03.01_odp: physical spaces
pe-04_odp.01: system distribution and transmission lines
pe-04_odp.02: security controls
pe-05_odp: output devices
pe-06_odp.01: frequency Values: 1
pe-06_odp.02: events
pe-06.04_odp: physical spaces
pe-08_odp.01: time period Values: 1
pe-08_odp.02: frequency Values: 1
pe-08_odp.03: personnel
pe-8.1_prm_1: organization-defined automated mechanisms
pe-08.01_odp.01: automated mechanisms
pe-08.01_odp.02: automated mechanisms
pl-1_prm_1: organization-defined personnel or roles
pl-01_odp.01: personnel or roles
pl-01_odp.02: personnel or roles
pl-01_odp.03: No label Choices: 3
pl-01_odp.04: official
pl-01_odp.05: frequency Values: 1
pl-01_odp.06: events
pl-01_odp.07: frequency Values: 1
pl-01_odp.08: events Values: 1
pl-02_odp.01: individuals or groups Values: 1
pl-02_odp.02: personnel or roles Values: 1
pl-02_odp.03: frequency Values: 1
pl-04_odp.01: frequency Values: 1
pl-04_odp.02: No label Choices: 2
pl-04_odp.03: frequency
pl-08_odp: frequency Values: 1
ps-1_prm_1: organization-defined personnel or roles
ps-01_odp.01: personnel or roles
ps-01_odp.02: personnel or roles
ps-01_odp.03: No label Choices: 3
ps-01_odp.04: official
ps-01_odp.05: frequency Values: 1
ps-01_odp.06: events
ps-01_odp.07: frequency Values: 1
ps-01_odp.08: events Values: 1
ps-02_odp: frequency Values: 1
ps-3_prm_1: organization-defined conditions requiring rescreening and, where rescreening is so indicated, the frequency of rescreening
ps-03_odp.01: conditions requiring rescreening
ps-03_odp.02: frequency
ps-03.03_odp: additional personnel screening criteria Values: 1
ps-04_odp.01: time period Values: 1
ps-04_odp.02: information security topics
ps-04.02_odp.01: automated mechanisms Values: 1
ps-04.02_odp.02: No label Choices: 2
ps-04.02_odp.03: personnel or roles
ps-05_odp.01: transfer or reassignment actions
ps-05_odp.02: time period following the formal transfer action Values: 1
ps-05_odp.03: personnel or roles Values: 1
ps-05_odp.04: time period Values: 1
ps-06_odp.01: frequency Values: 1
ps-06_odp.02: frequency Values: 1
ps-07_odp.01: personnel or roles Values: 1
ps-07_odp.02: time period Values: 1
ps-08_odp.01: personnel or roles Values: 1
ps-08_odp.02: time period Values: 1
ra-1_prm_1: organization-defined personnel or roles
ra-01_odp.01: personnel or roles
ra-01_odp.02: personnel or roles
ra-01_odp.03: No label Choices: 3
ra-01_odp.04: official
ra-01_odp.05: frequency Values: 1
ra-01_odp.06: events
ra-01_odp.07: frequency Values: 1
ra-01_odp.08: events Values: 1
ra-03_odp.01: No label Choices: 3
ra-03_odp.02: document
ra-03_odp.03: frequency Values: 1
ra-03_odp.04: personnel or roles
ra-03_odp.05: frequency Values: 1
ra-03.01_odp.01: systems, system components, and system services
ra-03.01_odp.02: frequency
ra-5_prm_1: organization-defined frequency and/or randomly in accordance with organization-defined process Values: 1
ra-05_odp.01: frequency and/or randomly in accordance with organization-defined process
ra-05_odp.02: frequency and/or randomly in accordance with organization-defined process
ra-05_odp.03: response times Values: 1
ra-05_odp.04: personnel or roles
ra-05.02_odp.01: No label Choices: 3
ra-05.02_odp.02: frequency
ra-05.04_odp: corrective actions Values: 1
ra-05.05_odp.01: system components Values: 2
ra-05.05_odp.02: vulnerability scanning activities
ra-05.08_odp.01: system
ra-05.08_odp.02: time period
ra-09_odp.01: systems, system components, or system services
ra-09_odp.02: decision points in the system development life cycle
sa-1_prm_1: organization-defined personnel or roles
sa-01_odp.01: personnel or roles
sa-01_odp.02: personnel or roles
sa-01_odp.03: No label Choices: 3
sa-01_odp.04: official
sa-01_odp.05: frequency Values: 1
sa-01_odp.06: events
sa-01_odp.07: frequency Values: 1
sa-01_odp.08: events Values: 1
sa-10_odp.01: No label Choices: 5
sa-10_odp.02: configuration items
sa-10_odp.03: personnel
sa-11_odp.01: No label Choices: 4
sa-11_odp.02: frequency to conduct
sa-11_odp.03: depth and coverage
sa-11.2_prm_3: organization-defined breadth and depth of modeling and analyses
sa-11.2_prm_4: organization-defined acceptance criteria
sa-11.02_odp.01: information
sa-11.02_odp.02: tools and methods
sa-11.02_odp.03: breadth and depth
sa-11.02_odp.04: breadth and depth
sa-11.02_odp.05: acceptance criteria
sa-11.02_odp.06: acceptance criteria
sa-15_prm_2: organization-defined security and privacy requirements Values: 1
sa-15_odp.01: frequency Values: 1
sa-15_odp.02: security requirements
sa-15_odp.03: privacy requirements
sa-15.3_prm_2: organization-defined breadth and depth of criticality analysis
sa-15.03_odp.01: decision points
sa-15.03_odp.02: breadth
sa-15.03_odp.03: depth
sa-16_odp: training
sa-21_odp.01: system, systems component, or system service
sa-21_odp.02: official government duties
sa-21_odp.03: additional personnel screening criteria
sa-22_odp.01: No label Choices: 2
sa-22_odp.02: support from external providers
sa-03_odp: system-development life cycle
sa-04_odp.01: No label Choices: 2
sa-04_odp.02: contract language
sa-04.02_odp.01: No label Choices: 5
sa-04.02_odp.02: design and implementation information
sa-04.02_odp.03: level of detail
sa-04.05_odp: security configurations
sa-05_odp.01: actions
sa-05_odp.02: personnel or roles Values: 1
sa-8_prm_1: organization-defined systems security and privacy engineering principles
sa-08_odp.01: systems security engineering principles
sa-08_odp.02: privacy engineering principles
sa-09_odp.01: controls Values: 1
sa-09_odp.02: processes, methods, and techniques Values: 1
sa-09.01_odp: personnel or roles
sa-09.02_odp: external system services Values: 1
sa-09.05_odp.01: No label Choices: 3
sa-09.05_odp.02: locations
sa-09.05_odp.03: requirements
sc-1_prm_1: organization-defined personnel or roles
sc-01_odp.01: personnel or roles
sc-01_odp.02: personnel or roles
sc-01_odp.03: No label Choices: 3
sc-01_odp.04: official
sc-01_odp.05: frequency Values: 1
sc-01_odp.06: events
sc-01_odp.07: frequency Values: 1
sc-01_odp.08: events Values: 1
sc-10_odp: time period Values: 1
sc-12_odp: requirements Values: 1
sc-13_odp.01: cryptographic uses
sc-13_odp.02: types of cryptography Values: 1
sc-15_odp: exceptions where remote activation is to be allowed Values: 1
sc-17_odp: certificate policy
sc-24_odp.01: types of system failures on system components
sc-24_odp.02: known system state
sc-24_odp.03: system state information
sc-28_odp.01: No label Choices: 2
sc-28_odp.02: information at rest
sc-28.01_odp.01: information
sc-28.01_odp.02: system components or media Values: 1
sc-45.01_odp.01: frequency Values: 1
sc-45.01_odp.02: authoritative time source Values: 1
sc-45.01_odp.03: time period Values: 1
sc-05_odp.01: types of denial-of-service events Values: 1
sc-05_odp.02: No label Choices: 2
sc-05_odp.03: controls by type of denial-of-service event
sc-07_odp: No label Choices: 2
sc-07.04_odp: frequency Values: 1
sc-07.05_odp.01: No label Choices: 2
sc-07.05_odp.02: systems
sc-07.07_odp: safeguards
sc-07.08_odp.01: internal communications traffic Values: 1
sc-07.08_odp.02: external networks
sc-07.10_odp: frequency
sc-07.12_odp.01: host-based boundary protection mechanisms Values: 1
sc-07.12_odp.02: system components
sc-07.20_odp: system components
sc-07.21_odp.01: system components
sc-07.21_odp.02: missions and/or business functions
sc-08_odp: No label Choices: 2
sc-08.01_odp: No label Choices: 2
si-1_prm_1: organization-defined personnel or roles
si-01_odp.01: personnel or roles
si-01_odp.02: personnel or roles
si-01_odp.03: No label Choices: 3
si-01_odp.04: official
si-01_odp.05: frequency Values: 1
si-01_odp.06: events
si-01_odp.07: frequency Values: 1
si-01_odp.08: events Values: 1
si-10_odp: information inputs
si-11_odp: personnel or roles Values: 1
si-16_odp: controls
si-02_odp: time period Values: 1
si-02.02_odp.01: automated mechanisms Values: 1
si-02.02_odp.02: frequency
si-02.03_odp: benchmarks
si-03_odp.01: No label Choices: 2
si-03_odp.02: frequency Values: 1
si-03_odp.03: No label Choices: 2
si-03_odp.04: No label Choices: 3
si-03_odp.05: action
si-03_odp.06: personnel or roles Values: 1
si-04_odp.01: monitoring objectives
si-04_odp.02: techniques and methods
si-04_odp.03: system monitoring information
si-04_odp.04: personnel or roles
si-04_odp.05: No label Choices: 2
si-04_odp.06: frequency
si-4.4_prm_1: organization-defined frequency Values: 1
si-4.4_prm_2: organization-defined unusual or unauthorized activities or conditions
si-04.04_odp.01: frequency
si-04.04_odp.02: unusual or unauthorized activities or conditions
si-04.04_odp.03: frequency
si-04.04_odp.04: unusual or unauthorized activities or conditions
si-04.05_odp.01: personnel or roles
si-04.05_odp.02: compromise indicators
si-04.10_odp.01: encrypted communications traffic
si-04.10_odp.02: system monitoring tools and mechanisms
si-04.11_odp: interior points
si-04.12_odp.01: personnel or roles
si-04.12_odp.02: automated mechanisms
si-04.12_odp.03: activities that trigger alerts
si-04.18_odp: interior points
si-04.19_odp.01: additional monitoring
si-04.19_odp.02: sources
si-04.20_odp: additional monitoring
si-04.22_odp.01: authorization or approval processes
si-04.22_odp.02: No label Choices: 2
si-04.22_odp.03: personnel or roles
si-04.23_odp.01: host-based monitoring mechanisms
si-04.23_odp.02: system components
si-05_odp.01: external organizations Values: 1
si-05_odp.02: No label Choices: 3
si-05_odp.03: personnel or roles
si-05_odp.04: elements
si-05_odp.05: external organizations
si-05.01_odp: automated mechanisms
si-6_prm_1: organization-defined security and privacy functions
si-06_odp.01: security functions
si-06_odp.02: privacy functions
si-06_odp.03: No label Choices: 3
si-06_odp.04: system transitional states
si-06_odp.05: frequency
si-06_odp.06: personnel or roles Values: 1
si-06_odp.07: No label Choices: 3
si-06_odp.08: alternative action(s)
si-7_prm_1: organization-defined software, firmware, and information
si-7_prm_2: organization-defined actions
si-07_odp.01: software
si-07_odp.02: firmware
si-07_odp.03: information
si-07_odp.04: actions
si-07_odp.05: actions
si-07_odp.06: actions
si-7.1_prm_1: organization-defined software, firmware, and information Values: 2
si-7.1_prm_2: No label Choices: 3
si-7.1_prm_3: organization-defined transitional states or security-relevant events
si-7.1_prm_4: organization-defined frequency
si-07.01_odp.01: software
si-07.01_odp.02: No label Choices: 3
si-07.01_odp.03: transitional states or security-relevant events
si-07.01_odp.04: frequency
si-07.01_odp.05: firmware
si-07.01_odp.06: No label Choices: 3
si-07.01_odp.07: transitional states or security-relevant events
si-07.01_odp.08: frequency
si-07.01_odp.09: information
si-07.01_odp.10: No label Choices: 3
si-07.01_odp.11: transitional states or security-relevant events
si-07.01_odp.12: frequency
si-07.02_odp: personnel or roles Values: 1
si-07.05_odp.01: No label Choices: 3
si-07.05_odp.02: controls
si-07.07_odp: changes
si-07.15_odp: software or firmware components Values: 1
si-08.02_odp: frequency
sr-1_prm_1: organization-defined personnel or roles Values: 1
sr-01_odp.01: personnel or roles
sr-01_odp.02: personnel or roles
sr-01_odp.03: No label Choices: 3
sr-01_odp.04: official
sr-01_odp.05: frequency Values: 1
sr-01_odp.06: events
sr-01_odp.07: frequency Values: 1
sr-01_odp.08: events Values: 1
sr-10_odp.01: systems or system components
sr-10_odp.02: No label Choices: 3
sr-10_odp.03: frequency
sr-10_odp.04: indications of need for inspection
sr-11_odp.01: No label Choices: 3
sr-11_odp.02: external reporting organizations
sr-11_odp.03: personnel or roles
sr-11.01_odp: personnel or roles
sr-11.02_odp: system components Values: 1
sr-12_odp.01: data, documentation, tools, or system components
sr-12_odp.02: techniques and methods
sr-02_odp.01: systems, system components, or system services
sr-02_odp.02: frequency Values: 1
sr-02.01_odp.01: personnel, roles and responsibilities
sr-02.01_odp.02: supply chain risk management activities
sr-03_odp.01: system or system component
sr-03_odp.02: supply chain personnel
sr-03_odp.03: supply chain controls
sr-03_odp.04: No label Choices: 3
sr-03_odp.05: document
sr-05_odp: strategies, tools, and methods
sr-06_odp: frequency Values: 1
sr-08_odp.01: No label Choices: 2
sr-08_odp.02: results of assessments or audits