UUID: 2963c2d8-9641-4ccf-9cbf-218ea75cd563
Version: Rev5-Low
Last Modified: 2026-04-13 19:36:41+00:00
OSCAL Version: 1.2.1
Control Groups
Total Controls
Click on any group, control, or parameter to expand/collapse. Supports nested sub-groups and sub-controls (enhancements). All data visible with no truncation.
ac-1_prm_1: organization-defined personnel or roles
ac-01_odp.01: personnel or roles
ac-01_odp.02: personnel or roles
ac-01_odp.03: No label Choices: 3
ac-01_odp.04: official
ac-01_odp.05: frequency Values: 1
ac-01_odp.06: events
ac-01_odp.07: frequency Values: 1
ac-01_odp.08: events Values: 1
ac-14_odp: user actions
ac-02_odp.01: prerequisites and criteria
ac-02_odp.02: attributes (as required)
ac-02_odp.03: personnel or roles
ac-02_odp.04: policy, procedures, prerequisites, and criteria
ac-02_odp.05: personnel or roles
ac-02_odp.06: time period Values: 1
ac-02_odp.07: time period Values: 1
ac-02_odp.08: time period Values: 1
ac-02_odp.09: attributes (as required)
ac-02_odp.10: frequency Values: 1
ac-20_odp.01: No label Choices: 2
ac-20_odp.02: terms and conditions
ac-20_odp.03: controls asserted
ac-20_odp.04: prohibited types of external systems
ac-22_odp: frequency Values: 1
ac-07_odp.01: number
ac-07_odp.02: time period
ac-07_odp.03: No label Choices: 5
ac-07_odp.04: time period
ac-07_odp.05: delay algorithm
ac-07_odp.06: action
ac-08_odp.01: system use notification Values: 1
ac-08_odp.02: conditions Values: 1
at-1_prm_1: organization-defined personnel or roles
at-01_odp.01: personnel or roles
at-01_odp.02: personnel or roles
at-01_odp.03: No label Choices: 3
at-01_odp.04: official
at-01_odp.05: frequency Values: 1
at-01_odp.06: events
at-01_odp.07: frequency Values: 1
at-01_odp.08: events Values: 1
at-2_prm_1: organization-defined frequency Values: 1
at-2_prm_2: organization-defined events
at-02_odp.01: frequency
at-02_odp.02: frequency
at-02_odp.03: events
at-02_odp.04: events
at-02_odp.05: awareness techniques
at-02_odp.06: frequency Values: 1
at-02_odp.07: events
at-3_prm_1: organization-defined roles and responsibilities
at-03_odp.01: roles and responsibilities
at-03_odp.02: roles and responsibilities
at-03_odp.03: frequency Values: 1
at-03_odp.04: frequency Values: 1
at-03_odp.05: events
at-04_odp: time period Values: 1
au-1_prm_1: organization-defined personnel or roles
au-01_odp.01: personnel or roles
au-01_odp.02: personnel or roles
au-01_odp.03: No label Choices: 3
au-01_odp.04: official
au-01_odp.05: frequency Values: 1
au-01_odp.06: events
au-01_odp.07: frequency Values: 1
au-01_odp.08: events Values: 1
au-11_odp: time period Values: 1
au-12_odp.01: system components Values: 1
au-12_odp.02: personnel or roles
au-2_prm_2: organization-defined event types (subset of the event types defined in [AU-2a.](#au-2_smt.a)) along with the frequency of (or situation requiring) logging for each identified event type Values: 1
au-02_odp.01: event types Values: 1
au-02_odp.02: event types (subset of AU-02_ODP[01])
au-02_odp.03: frequency or situation
au-02_odp.04: frequency Values: 1
au-04_odp: audit log retention requirements
au-05_odp.01: personnel or roles
au-05_odp.02: time period
au-05_odp.03: additional actions Values: 1
au-06_odp.01: frequency Values: 1
au-06_odp.02: inappropriate or unusual activity
au-06_odp.03: personnel or roles
au-08_odp: granularity of time measurement Values: 1
au-09_odp: personnel or roles
ca-1_prm_1: organization-defined personnel or roles
ca-01_odp.01: personnel or roles
ca-01_odp.02: personnel or roles
ca-01_odp.03: No label Choices: 3
ca-01_odp.04: official
ca-01_odp.05: frequency Values: 1
ca-01_odp.06: events
ca-01_odp.07: frequency Values: 1
ca-01_odp.08: events Values: 1
ca-02_odp.01: assessment frequency Values: 1
ca-02_odp.02: individuals or roles Values: 1
ca-03_odp.01: No label Choices: 7
ca-03_odp.02: type of agreement
ca-03_odp.03: frequency Values: 1
ca-05_odp: frequency Values: 1
ca-06_odp: frequency Values: 1
ca-7_prm_4: organization-defined personnel or roles
ca-7_prm_5: organization-defined frequency
ca-07_odp.01: system-level metrics
ca-07_odp.02: frequencies
ca-07_odp.03: frequencies
ca-07_odp.04: personnel or roles
ca-07_odp.05: frequency
ca-07_odp.06: personnel or roles
ca-07_odp.07: frequency
ca-08_odp.01: frequency Values: 1
ca-08_odp.02: system(s) or system components
ca-09_odp.01: system components
ca-09_odp.02: conditions
ca-09_odp.03: frequency
cm-1_prm_1: organization-defined personnel or roles
cm-01_odp.01: personnel or roles
cm-01_odp.02: personnel or roles
cm-01_odp.03: No label Choices: 3
cm-01_odp.04: official
cm-01_odp.05: frequency Values: 1
cm-01_odp.06: events
cm-01_odp.07: frequency Values: 1
cm-01_odp.08: events Values: 1
cm-11_odp.01: policies
cm-11_odp.02: methods
cm-11_odp.03: frequency Values: 1
cm-02_odp.01: frequency Values: 1
cm-02_odp.02: circumstances
cm-06_odp.01: common secure configurations
cm-06_odp.02: system components
cm-06_odp.03: operational requirements
cm-7_prm_2: organization-defined prohibited or restricted functions, system ports, protocols, software, and/or services
cm-07_odp.01: mission-essential capabilities
cm-07_odp.02: functions
cm-07_odp.03: ports
cm-07_odp.04: protocols
cm-07_odp.05: software
cm-07_odp.06: services
cm-08_odp.01: information
cm-08_odp.02: frequency Values: 1
cp-1_prm_1: organization-defined personnel or roles
cp-01_odp.01: personnel or roles
cp-01_odp.02: personnel or roles
cp-01_odp.03: No label Choices: 3
cp-01_odp.04: official
cp-01_odp.05: frequency Values: 1
cp-01_odp.06: events
cp-01_odp.07: frequency Values: 1
cp-01_odp.08: events Values: 1
cp-10_prm_1: organization-defined time period consistent with recovery time and recovery point objectives
cp-10_odp.01: time period
cp-10_odp.02: time period
cp-2_prm_1: organization-defined personnel or roles
cp-2_prm_2: organization-defined key contingency personnel (identified by name and/or by role) and organizational elements
cp-2_prm_4: organization-defined key contingency personnel (identified by name and/or by role) and organizational elements
cp-02_odp.01: personnel or roles
cp-02_odp.02: personnel or roles
cp-02_odp.03: key contingency personnel
cp-02_odp.04: organizational elements
cp-02_odp.05: frequency Values: 1
cp-02_odp.06: key contingency personnel
cp-02_odp.07: organizational elements
cp-03_odp.01: time period Values: 1
cp-03_odp.02: frequency Values: 1
cp-03_odp.03: frequency Values: 1
cp-03_odp.04: events
cp-4_prm_2: organization-defined tests Values: 1
cp-04_odp.01: frequency Values: 1
cp-04_odp.02: tests
cp-04_odp.03: tests
cp-09_odp.01: system components
cp-09_odp.02: frequency Values: 1
cp-09_odp.03: frequency Values: 1
cp-09_odp.04: frequency Values: 1
ia-1_prm_1: organization-defined personnel or roles
ia-01_odp.01: personnel or roles
ia-01_odp.02: personnel or roles
ia-01_odp.03: No label Choices: 3
ia-01_odp.04: official
ia-01_odp.05: frequency Values: 1
ia-01_odp.06: events
ia-01_odp.07: frequency Values: 1
ia-01_odp.08: events Values: 1
ia-11_odp: circumstances or situations
ia-02.08_odp: No label Choices: 2
ia-04_odp.01: personnel or roles Values: 1
ia-04_odp.02: time period Values: 1
ia-05_odp.01: time period by authenticator type
ia-05_odp.02: events
ia-05.01_odp.01: frequency
ia-05.01_odp.02: composition and complexity rules
ia-08.04_odp: identity management profiles
ir-1_prm_1: organization-defined personnel or roles
ir-01_odp.01: personnel or roles
ir-01_odp.02: personnel or roles
ir-01_odp.03: No label Choices: 3
ir-01_odp.04: official
ir-01_odp.05: frequency Values: 1
ir-01_odp.06: events
ir-01_odp.07: frequency Values: 1
ir-01_odp.08: events Values: 1
ir-02_odp.01: time period Values: 1
ir-02_odp.02: frequency Values: 1
ir-02_odp.03: frequency Values: 1
ir-02_odp.04: events
ir-06_odp.01: time period Values: 1
ir-06_odp.02: authorities
ir-8_prm_5: organization-defined incident response personnel (identified by name and/or by role) and organizational elements Values: 1
ir-08_odp.01: personnel or roles
ir-08_odp.02: frequency Values: 1
ir-08_odp.03: entities, personnel, or roles
ir-08_odp.04: incident response personnel Values: 1
ir-08_odp.05: organizational elements
ir-08_odp.06: incident response personnel
ir-08_odp.07: organizational elements
ma-1_prm_1: organization-defined personnel or roles
ma-01_odp.01: personnel or roles
ma-01_odp.02: personnel or roles
ma-01_odp.03: No label Choices: 3
ma-01_odp.04: official
ma-01_odp.05: frequency Values: 1
ma-01_odp.06: events
ma-01_odp.07: frequency Values: 1
ma-01_odp.08: events Values: 1
ma-02_odp.01: personnel or roles
ma-02_odp.02: information
ma-02_odp.03: information
mp-1_prm_1: organization-defined personnel or roles
mp-01_odp.01: personnel or roles
mp-01_odp.02: personnel or roles
mp-01_odp.03: No label Choices: 3
mp-01_odp.04: official
mp-01_odp.05: frequency Values: 1
mp-01_odp.06: events
mp-01_odp.07: frequency Values: 1
mp-01_odp.08: events Values: 1
mp-2_prm_1: organization-defined types of digital and/or non-digital media
mp-2_prm_2: organization-defined personnel or roles
mp-02_odp.01: types of digital media
mp-02_odp.02: personnel or roles
mp-02_odp.03: types of non-digital media
mp-02_odp.04: personnel or roles
mp-6_prm_1: organization-defined system media
mp-6_prm_2: organization-defined sanitization techniques and procedures Values: 1
mp-06_odp.01: system media
mp-06_odp.02: system media
mp-06_odp.03: system media
mp-06_odp.04: sanitization techniques and procedures
mp-06_odp.05: sanitization techniques and procedures
mp-06_odp.06: sanitization techniques and procedures
mp-07_odp.01: types of system media
mp-07_odp.02: No label Choices: 2
mp-07_odp.03: systems or system components
mp-07_odp.04: controls
pe-1_prm_1: organization-defined personnel or roles
pe-01_odp.01: personnel or roles
pe-01_odp.02: personnel or roles
pe-01_odp.03: No label Choices: 3
pe-01_odp.04: official
pe-01_odp.05: frequency Values: 1
pe-01_odp.06: events
pe-01_odp.07: frequency Values: 1
pe-01_odp.08: events Values: 1
pe-14_odp.01: No label Choices: 5
pe-14_odp.02: environmental control
pe-14_odp.03: acceptable levels
pe-14_odp.04: frequency Values: 1
pe-16_prm_1: organization-defined types of system components Values: 1
pe-16_odp.01: types of system components
pe-16_odp.02: types of system components
pe-02_odp: frequency Values: 1
pe-3_prm_9: organization-defined frequency Values: 1
pe-03_odp.01: entry and exit points
pe-03_odp.02: No label Choices: 2
pe-03_odp.03: systems or devices
pe-03_odp.04: entry or exit points
pe-03_odp.05: physical access controls
pe-03_odp.06: circumstances Values: 1
pe-03_odp.07: physical access devices
pe-03_odp.08: frequency Values: 1
pe-03_odp.09: frequency
pe-03_odp.10: frequency
pe-06_odp.01: frequency Values: 1
pe-06_odp.02: events
pe-08_odp.01: time period Values: 1
pe-08_odp.02: frequency Values: 1
pe-08_odp.03: personnel
pl-1_prm_1: organization-defined personnel or roles
pl-01_odp.01: personnel or roles
pl-01_odp.02: personnel or roles
pl-01_odp.03: No label Choices: 3
pl-01_odp.04: official
pl-01_odp.05: frequency Values: 1
pl-01_odp.06: events
pl-01_odp.07: frequency Values: 1
pl-01_odp.08: events Values: 1
pl-02_odp.01: individuals or groups
pl-02_odp.02: personnel or roles
pl-02_odp.03: frequency Values: 1
pl-04_odp.01: frequency Values: 1
pl-04_odp.02: No label Choices: 2
pl-04_odp.03: frequency
pl-08_odp: frequency Values: 1
ps-1_prm_1: organization-defined personnel or roles
ps-01_odp.01: personnel or roles
ps-01_odp.02: personnel or roles
ps-01_odp.03: No label Choices: 3
ps-01_odp.04: official
ps-01_odp.05: frequency Values: 1
ps-01_odp.06: events
ps-01_odp.07: frequency Values: 1
ps-01_odp.08: events Values: 1
ps-02_odp: frequency Values: 1
ps-3_prm_1: organization-defined conditions requiring rescreening and, where rescreening is so indicated, the frequency of rescreening
ps-03_odp.01: conditions requiring rescreening
ps-03_odp.02: frequency
ps-04_odp.01: time period Values: 1
ps-04_odp.02: information security topics
ps-05_odp.01: transfer or reassignment actions
ps-05_odp.02: time period following the formal transfer action Values: 1
ps-05_odp.03: personnel or roles
ps-05_odp.04: time period Values: 1
ps-06_odp.01: frequency Values: 1
ps-06_odp.02: frequency Values: 1
ps-07_odp.01: personnel or roles Values: 1
ps-07_odp.02: time period Values: 1
ps-08_odp.01: personnel or roles Values: 1
ps-08_odp.02: time period
ra-1_prm_1: organization-defined personnel or roles
ra-01_odp.01: personnel or roles
ra-01_odp.02: personnel or roles
ra-01_odp.03: No label Choices: 3
ra-01_odp.04: official
ra-01_odp.05: frequency Values: 1
ra-01_odp.06: events
ra-01_odp.07: frequency Values: 1
ra-01_odp.08: events Values: 1
ra-03_odp.01: No label Choices: 3
ra-03_odp.02: document
ra-03_odp.03: frequency Values: 1
ra-03_odp.04: personnel or roles
ra-03_odp.05: frequency Values: 1
ra-03.01_odp.01: systems, system components, and system services
ra-03.01_odp.02: frequency
ra-5_prm_1: organization-defined frequency and/or randomly in accordance with organization-defined process Values: 1
ra-05_odp.01: frequency and/or randomly in accordance with organization-defined process
ra-05_odp.02: frequency and/or randomly in accordance with organization-defined process
ra-05_odp.03: response times Values: 1
ra-05_odp.04: personnel or roles
ra-05.02_odp.01: No label Choices: 3
ra-05.02_odp.02: frequency
sa-1_prm_1: organization-defined personnel or roles
sa-01_odp.01: personnel or roles
sa-01_odp.02: personnel or roles
sa-01_odp.03: No label Choices: 3
sa-01_odp.04: official
sa-01_odp.05: frequency Values: 1
sa-01_odp.06: events
sa-01_odp.07: frequency Values: 1
sa-01_odp.08: events Values: 1
sa-22_odp.01: No label Choices: 2
sa-22_odp.02: support from external providers
sa-03_odp: system-development life cycle
sa-04_odp.01: No label Choices: 2
sa-04_odp.02: contract language
sa-05_odp.01: actions
sa-05_odp.02: personnel or roles Values: 1
sa-8_prm_1: organization-defined systems security and privacy engineering principles
sa-08_odp.01: systems security engineering principles
sa-08_odp.02: privacy engineering principles
sa-09_odp.01: controls Values: 1
sa-09_odp.02: processes, methods, and techniques Values: 1
sc-1_prm_1: organization-defined personnel or roles
sc-01_odp.01: personnel or roles
sc-01_odp.02: personnel or roles
sc-01_odp.03: No label Choices: 3
sc-01_odp.04: official
sc-01_odp.05: frequency Values: 1
sc-01_odp.06: events
sc-01_odp.07: frequency Values: 1
sc-01_odp.08: events Values: 1
sc-12_odp: requirements Values: 1
sc-13_odp.01: cryptographic uses
sc-13_odp.02: types of cryptography Values: 1
sc-15_odp: exceptions where remote activation is to be allowed Values: 1
sc-28_odp.01: No label Choices: 2
sc-28_odp.02: information at rest
sc-28.01_odp.01: information
sc-28.01_odp.02: system components or media Values: 1
sc-05_odp.01: types of denial-of-service events Values: 1
sc-05_odp.02: No label Choices: 2
sc-05_odp.03: controls by type of denial-of-service event
sc-07_odp: No label Choices: 2
sc-08_odp: No label Choices: 2
sc-08.01_odp: No label Choices: 2
si-1_prm_1: organization-defined personnel or roles
si-01_odp.01: personnel or roles
si-01_odp.02: personnel or roles
si-01_odp.03: No label Choices: 3
si-01_odp.04: official
si-01_odp.05: frequency Values: 1
si-01_odp.06: events
si-01_odp.07: frequency Values: 1
si-01_odp.08: events Values: 1
si-02_odp: time period Values: 1
si-03_odp.01: No label Choices: 2
si-03_odp.02: frequency Values: 1
si-03_odp.03: No label Choices: 2
si-03_odp.04: No label Choices: 3
si-03_odp.05: action
si-03_odp.06: personnel or roles Values: 1
si-04_odp.01: monitoring objectives
si-04_odp.02: techniques and methods
si-04_odp.03: system monitoring information
si-04_odp.04: personnel or roles
si-04_odp.05: No label Choices: 2
si-04_odp.06: frequency
si-05_odp.01: external organizations Values: 1
si-05_odp.02: No label Choices: 3
si-05_odp.03: personnel or roles
si-05_odp.04: elements
si-05_odp.05: external organizations
sr-1_prm_1: organization-defined personnel or roles Values: 1
sr-01_odp.01: personnel or roles
sr-01_odp.02: personnel or roles
sr-01_odp.03: No label Choices: 3
sr-01_odp.04: official
sr-01_odp.05: frequency Values: 1
sr-01_odp.06: events
sr-01_odp.07: frequency Values: 1
sr-01_odp.08: events Values: 1
sr-10_odp.01: systems or system components
sr-10_odp.02: No label Choices: 3
sr-10_odp.03: frequency
sr-10_odp.04: indications of need for inspection
sr-11_odp.01: No label Choices: 3
sr-11_odp.02: external reporting organizations
sr-11_odp.03: personnel or roles
sr-11.01_odp: personnel or roles
sr-11.02_odp: system components Values: 1
sr-12_odp.01: data, documentation, tools, or system components
sr-12_odp.02: techniques and methods
sr-02_odp.01: systems, system components, or system services
sr-02_odp.02: frequency Values: 1
sr-02.01_odp.01: personnel, roles and responsibilities
sr-02.01_odp.02: supply chain risk management activities
sr-03_odp.01: system or system component
sr-03_odp.02: supply chain personnel
sr-03_odp.03: supply chain controls
sr-03_odp.04: No label Choices: 3
sr-03_odp.05: document
sr-05_odp: strategies, tools, and methods
sr-08_odp.01: No label Choices: 2
sr-08_odp.02: results of assessments or audits