C2M2
Evidence request list. 22 controls, 22 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.
C2M2 Domain: Asset, Change and Configuration Management (ASSET)
ASSET domain. Establish and maintain an inventory of IT and OT assets (hardware, software, information) within the function, prioritised by importance, as the basis for cybersecurity activities.
- IT and OT asset inventory with ownership and criticality
- Process to keep the inventory current
- Prioritisation of assets by importance to the function
- OT assets omitted from inventory
- Inventory stale
- Assets not prioritised
ASSET domain. Establish and maintain configuration baselines for assets and manage changes to assets through a defined change-management process.
- Configuration baselines for IT/OT assets
- Change-management process and records
- Review of changes for cybersecurity impact
- No configuration baselines
- Changes made without change control
- OT change constraints ignored
C2M2 Domain: Cybersecurity Architecture (ARCHITECTURE)
ARCHITECTURE domain. Establish and maintain a cybersecurity architecture strategy and program to guide the secure design of IT and OT systems.
- Documented cybersecurity architecture strategy/program
- Secure-design standards for IT/OT
- Architecture review of new systems
- No architecture strategy
- No secure-design standards
- Architecture not reviewed
ARCHITECTURE domain. Implement network protections including segmentation between IT and OT, boundary protection, and network monitoring.
- Network segmentation between IT, OT and external networks
- Boundary protection (firewalls, DMZ) configurations
- Network monitoring
- No IT/OT segmentation
- Weak boundary protection
- No network monitoring
ARCHITECTURE domain. Implement data security protections including data protection, integrity, and cryptography for data at rest and in transit.
- Data protection and classification
- Encryption of data at rest and in transit
- Key management
- Data not protected by classification
- No encryption
- No key management
C2M2 Domain: Cybersecurity Program Management (PROGRAM)
PROGRAM domain. Establish and maintain an enterprise cybersecurity program with governance, sponsorship, resourcing and periodic management review, and an information-sharing capability.
- Board/executive-sponsored cybersecurity program
- Program governance, funding and management review
- Participation in information-sharing forums (e.g. ISACs)
- No program governance/sponsorship
- Program not reviewed
- No information sharing
C2M2 Domain: Event and Incident Response, Continuity of Operations (RESPONSE)
RESPONSE domain. Detect cybersecurity events and analyse them to determine whether they are incidents requiring response.
- Event detection and triage procedures
- Criteria for declaring incidents
- Records of event analysis
- Events not detected/triaged
- No incident-declaration criteria
- Analysis not recorded
RESPONSE domain. Establish and maintain incident response capabilities to respond to, recover from, and report cybersecurity incidents, including coordination with authorities.
- Incident response plan and playbooks
- Incident records, post-incident reviews and reporting to authorities
- Exercises/drills (including OT scenarios)
- No incident response plan
- Incidents not reported
- No exercises
RESPONSE domain. Establish and maintain continuity of operations plans to sustain or restore the function's operations following a cybersecurity incident or disruption.
- Continuity of operations / disaster recovery plans
- Recovery objectives (RTO/RPO) and backups
- Continuity testing records
- No continuity plan
- Recovery objectives undefined
- Continuity untested
C2M2 Domain: Identity and Access Management (ACCESS)
ACCESS domain. Establish and maintain identities for personnel, services and devices, governing the identity lifecycle (provisioning, change, de-provisioning).
- Identity lifecycle (joiner/mover/leaver) process and records
- Identity inventory for personnel/services/devices
- De-provisioning on separation
- Identities not lifecycle-managed
- Orphan/stale identities
- De-provisioning delayed
ACCESS domain. Control logical and physical access to assets commensurate with risk, including least privilege, privileged access management and remote access controls.
- Least-privilege and segregation-of-duties controls
- Privileged access management
- Logical and physical access reviews
- Excessive privilege
- Privileged access uncontrolled
- Access not reviewed
C2M2 Domain: Risk Management (RISK)
RISK domain. Establish and maintain a cyber risk management strategy and program, including governance, risk appetite/tolerance, and integration with enterprise risk management.
- Documented cyber risk management strategy and program
- Risk appetite/tolerance statements
- Integration with enterprise risk management
- No risk strategy
- Risk appetite undefined
- Cyber risk not integrated with ERM
RISK domain. Identify and analyse cybersecurity risk to the function, considering threats, vulnerabilities, likelihood and impact.
- Cyber risk register with analysed risks
- Risk assessment methodology
- Periodic reassessment
- Risks not identified/analysed
- No methodology
- Assessment not updated
RISK domain. Manage cybersecurity risk through prioritised risk responses (accept, mitigate, transfer, avoid) and monitoring of residual risk.
- Documented risk responses and treatment plans
- Residual risk monitoring
- Risk acceptance approvals
- Risks not treated
- Residual risk unmonitored
- No documented acceptance
C2M2 Domain: Situational Awareness (SITUATION)
SITUATION domain. Perform logging and monitoring of IT and OT to support detection of anomalies and cybersecurity events.
- Logging configured across IT/OT where feasible
- Monitoring/alerting for anomalies
- Log retention and protection
- Inadequate logging (esp. OT)
- No monitoring/alerting
- Logs not retained/protected
SITUATION domain. Establish and maintain situational awareness through a common operating picture that aggregates monitoring, threat and status information for decision-making.
- Aggregated situational-awareness/COP capability
- Correlation of monitoring and threat data
- Reporting to decision-makers
- No common operating picture
- Data not correlated
- Decision-makers not informed
C2M2 Domain: Third-Party Risk Management (THIRD-PARTIES)
THIRD-PARTIES domain. Identify and manage cybersecurity risks arising from third parties and external dependencies (suppliers, service providers, vendors).
- Inventory of third parties and external dependencies
- Third-party cyber risk assessments
- Security requirements in third-party agreements
- Third parties not inventoried
- No third-party risk assessment
- No security terms in agreements
THIRD-PARTIES domain. Manage ongoing supplier relationships, monitor third-party security, and require notification of third-party cybersecurity incidents affecting the function.
- Ongoing third-party monitoring
- Incident-notification clauses and records
- Exit/transition arrangements for critical suppliers
- No ongoing monitoring
- No incident-notification requirement
- No exit planning
C2M2 Domain: Threat and Vulnerability Management (THREAT)
THREAT domain. Establish and maintain a threat profile and the practices to identify, analyse and respond to cybersecurity threats relevant to the function.
- Documented threat profile for the function
- Threat intelligence sources and analysis
- Threat-informed response actions
- No threat profile
- No threat intelligence
- Threats not acted upon
THREAT domain. Establish and maintain practices to identify, analyse and reduce cybersecurity vulnerabilities (vulnerability assessment, remediation, and management).
- Vulnerability assessment/scanning of IT and OT
- Remediation tracking with risk-based prioritisation
- Patch and mitigation records
- No vulnerability assessment
- Vulnerabilities not remediated
- OT vulnerabilities unmanaged
C2M2 Domain: Workforce Management (WORKFORCE)
WORKFORCE domain. Assign cybersecurity responsibilities and manage the cybersecurity workforce (roles, accountability, resourcing).
- Defined cybersecurity roles and responsibilities
- Workforce/resourcing plan for cybersecurity
- Accountability assignments
- Responsibilities undefined
- Cyber roles unstaffed
- No accountability
WORKFORCE domain. Develop the cybersecurity workforce through training and conduct security awareness activities for all personnel.
- Cybersecurity training program and completion records
- Role-based training for cyber staff
- Security awareness activities
- No training program
- Awareness not delivered
- Cyber staff not developed
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.