Skip to content

Evidence request lists

CMMC 2.0

Evidence request list. 110 controls, 110 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.

Access Control

AC.L2-3.1.1
Authorized Access Control

Restrict system access so only identified, authorized users, the processes running on their behalf, and approved devices including other connected systems can connect.

Artefacts an auditor will ask for
  • Account inventory listing authorized users, service/process accounts and approved devices
  • Account provisioning and approval records showing authorization before access
  • System configuration showing device and system-to-system connection allow lists
  • Periodic account recertification results
Where this commonly fails
  • Service and machine accounts never authorized or reviewed
  • Device-level access unrestricted while user access is controlled
  • Stale accounts retained after staff depart
AC.L2-3.1.10
Session Lock

Lock the user session after a defined period of inactivity and conceal previously displayed content behind a pattern hiding display until the user reauthenticates.

Artefacts an auditor will ask for
  • Configured inactivity timeout and session lock settings
  • Evidence the lock hides screen content, for example screensaver policy
  • Deployment coverage across workstations and servers
Where this commonly fails
  • Timeout configured but pattern hiding not enforced
  • Users permitted to disable the lock locally
  • Servers and shared terminals excluded
AC.L2-3.1.11
Session Termination

Automatically end a user session once a defined condition, such as an inactivity period or maximum session duration, is met.

Artefacts an auditor will ask for
  • Defined session termination conditions in policy
  • System and application configuration implementing automatic termination
  • Evidence of sessions terminated in logs
Where this commonly fails
  • Session lock mistaken for session termination
  • Conditions undefined so nothing terminates
  • Application sessions persist after operating system termination
AC.L2-3.1.12
Control Remote Access

Monitor and control remote access sessions so each remote connection is authorized, visible to the organization and subject to enforcement.

Artefacts an auditor will ask for
  • Remote access policy defining permitted methods and approval
  • VPN or remote gateway configuration and connection logs
  • Records of remote session monitoring and review
Where this commonly fails
  • Remote access permitted through unmanaged tools
  • Connections logged but never reviewed
  • Third party remote support paths outside the control
AC.L2-3.1.13
Remote Access Confidentiality

Apply cryptographic protection to remote access sessions so session confidentiality is preserved in transit.

Artefacts an auditor will ask for
  • Remote access encryption configuration showing protocol and cipher settings
  • Evidence that weak or plaintext remote protocols are disabled
  • Certificate or key management records for the remote access service
Where this commonly fails
  • Legacy plaintext protocols still enabled as fallback
  • Encryption terminated at an intermediary leaving segments in clear
  • Cipher suites unreviewed and outdated
AC.L2-3.1.14
Remote Access Routing

Force remote access traffic through a limited set of managed access control points rather than allowing arbitrary entry paths into the network.

Artefacts an auditor will ask for
  • Network architecture identifying the managed remote access points
  • Firewall rules restricting remote entry to those points
  • Evidence that alternative ingress paths are blocked
Where this commonly fails
  • Multiple undocumented remote entry points
  • Vendor appliances providing side channel access
  • Split of remote traffic across unmanaged cloud services
AC.L2-3.1.15
Privileged Remote Access

Require explicit authorization before privileged commands may be executed remotely or security relevant information accessed remotely.

Artefacts an auditor will ask for
  • Documented authorization for remote privileged operations
  • Configuration restricting remote privileged command execution
  • Logs of remote privileged sessions and the approvals behind them
Where this commonly fails
  • Remote administration allowed to anyone holding admin rights
  • Authorization implied by role rather than explicitly granted
  • No record tying remote privileged activity to an approval
AC.L2-3.1.16
Wireless Access Authorization

Authorize each wireless connection before it is permitted to attach to the system.

Artefacts an auditor will ask for
  • Wireless access authorization records and approved device list
  • Wireless network configuration showing authorization enforcement
  • Rogue access point detection results
Where this commonly fails
  • Wireless access granted by shared passphrase with no authorization step
  • Guest wireless bridged to internal networks
  • Unauthorized access points undetected
AC.L2-3.1.17
Wireless Access Protection

Protect wireless connections using authentication and encryption so wireless traffic and access are not open to nearby parties.

Artefacts an auditor will ask for
  • Wireless security configuration showing authentication method and encryption
  • Evidence that deprecated wireless protocols are disabled
  • Wireless credential or certificate management records
Where this commonly fails
  • Pre shared keys shared widely and never rotated
  • Legacy encryption retained for older devices
  • Authentication not tied to individual identity
AC.L2-3.1.18
Mobile Device Connection

Control which mobile devices may connect to organizational systems, and manage those connections.

Artefacts an auditor will ask for
  • Mobile device policy and approved device inventory
  • Mobile device management enrolment and compliance records
  • Configuration restricting connection to managed devices
Where this commonly fails
  • Personal devices connect without enrolment
  • Inventory maintained but connection not technically restricted
  • No removal process when a device is lost or retired
AC.L2-3.1.19
Encrypt CUI on Mobile

Encrypt CUI held on mobile devices and mobile computing platforms so the data stays protected if a device is lost or stolen.

Artefacts an auditor will ask for
  • Device encryption configuration and compliance reporting
  • Evidence of encryption status per enrolled device
  • Policy identifying which mobile platforms may hold CUI
Where this commonly fails
  • Encryption assumed by default without verification
  • Removable storage in mobile devices left unencrypted
  • Devices holding CUI outside the managed estate
AC.L2-3.1.2
Transaction & Function Control

Confine each authorized user to the specific transactions and functions their role permits, so privileges bound what can be executed and not merely whether access is granted.

Artefacts an auditor will ask for
  • Role definitions mapping roles to permitted transactions and functions
  • Application and system permission matrices as configured
  • Approval records for role assignment per user
  • Evidence of enforcement testing on a restricted role
Where this commonly fails
  • Access granted at system level with no function-level restriction
  • Roles defined on paper but not enforced in the application
  • Broad default roles assigned for convenience
AC.L2-3.1.20
External Connections

Verify, then control or limit, connections to and use of external systems that are outside organizational control.

Artefacts an auditor will ask for
  • Inventory of approved external systems and connection terms
  • Agreements or terms governing external system use
  • Technical controls limiting external system connections
Where this commonly fails
  • External cloud services used without review
  • Connections permitted with no verification of the external party
  • No limit on what CUI may be processed externally
AC.L2-3.1.21
Portable Storage Use

Restrict how organizational portable storage devices may be used when connected to systems outside organizational control.

Artefacts an auditor will ask for
  • Policy stating limits on portable storage use on external systems
  • Technical restriction or endpoint control evidence
  • Records of approved exceptions
Where this commonly fails
  • Policy silent on external system use specifically
  • Restriction applied internally but not to devices taken off site
  • No mechanism to detect violation
AC.L2-3.1.22
Control Public Information

Control CUI that is posted to or processed on publicly accessible systems so CUI is not released to the public.

Artefacts an auditor will ask for
  • Review and approval process for content published publicly
  • Designated reviewer authorizations and review records
  • Evidence of periodic scanning of public sites for CUI
Where this commonly fails
  • Publication approval informal or undocumented
  • No periodic check of already published content
  • Public facing systems not identified as in scope
AC.L2-3.1.3
Control CUI Flow

Enforce approved authorization rules on the movement of CUI between systems, components and destinations, so CUI flows only where policy permits.

Artefacts an auditor will ask for
  • Documented CUI flow authorizations and approved flow paths
  • Firewall, proxy, DLP or gateway rules enforcing those flows
  • Data flow diagrams identifying CUI sources, stores and destinations
  • Records of blocked or exception-approved transfers
Where this commonly fails
  • CUI flows documented but not technically enforced
  • Egress to cloud and email paths unmonitored for CUI
  • No defined authorization for flows to external partners
AC.L2-3.1.4
Separation of Duties

Divide security relevant duties among different individuals so no single person can both carry out and conceal a harmful action without collusion.

Artefacts an auditor will ask for
  • Documented separation of duties matrix for security relevant tasks
  • Access assignments demonstrating conflicting duties are held by different people
  • Records of conflict analysis and any approved compensating controls
Where this commonly fails
  • Single administrator holds all privileged roles
  • Separation defined but not tested against actual entitlements
  • Small team treated as automatic exemption with no compensating control
AC.L2-3.1.5
Least Privilege

Grant users and processes only the privileges their assigned tasks require, applying this specifically to security functions and to privileged accounts.

Artefacts an auditor will ask for
  • Privileged account inventory with documented business justification
  • Entitlement review results showing removal of excess rights
  • Configuration showing security functions restricted to designated roles
Where this commonly fails
  • Standing administrative rights granted broadly
  • Privilege reviews performed but findings not actioned
  • Security functions accessible to general administrators
AC.L2-3.1.6
Non-Privileged Account Use

Require staff holding privileged accounts to use a non privileged account or role when performing work that does not need elevated rights.

Artefacts an auditor will ask for
  • Policy requiring separate privileged and non privileged accounts
  • Evidence that administrators hold distinct day-to-day accounts
  • Logs showing routine activity performed under non privileged accounts
Where this commonly fails
  • Administrators use privileged accounts for email and browsing
  • Dual accounts issued but daily use not enforced or monitored
  • No detection of privileged account use for nonsecurity tasks
AC.L2-3.1.7
Privileged Functions

Block non privileged users from executing privileged functions, and capture every execution of such functions in the audit log.

Artefacts an auditor will ask for
  • Configuration preventing privileged function execution by standard users
  • Audit log samples showing captured privileged function execution
  • Test results of an attempted privileged action by a non privileged account
Where this commonly fails
  • Privileged functions blocked but execution not logged
  • Logging enabled without covering privileged function use
  • Local administrator rights on endpoints bypass the restriction
AC.L2-3.1.8
Unsuccessful Logon Attempts

Cap the number of consecutive failed logon attempts allowed and take a defined action, such as account lockout, once that limit is reached.

Artefacts an auditor will ask for
  • Configured lockout threshold, duration and reset settings
  • Policy stating the failed attempt limit and resulting action
  • Evidence of enforcement across all authentication paths including remote
Where this commonly fails
  • Limit set in policy but not configured on all systems
  • Remote and application logons exempt from lockout
  • Lockout thresholds so high they never trigger
AC.L2-3.1.9
Privacy & Security Notices

Display privacy and security notices to users at logon that reflect the CUI rules applicable to the system.

Artefacts an auditor will ask for
  • Approved notice or banner text consistent with applicable CUI rules
  • Screenshots showing the notice presented at logon
  • Coverage list of systems where the banner is deployed
Where this commonly fails
  • Banner present on some systems only
  • Generic notice not reflecting CUI requirements
  • Notice bypassed on remote or application logon paths

Audit and Accountability

AU.L2-3.3.1
System Auditing

Generate and retain system audit logs in sufficient scope and detail to support monitoring, analysis, investigation and reporting of unlawful or unauthorized system activity.

Artefacts an auditor will ask for
  • Defined auditable event list and rationale for its scope
  • Logging configuration on in scope systems
  • Retention settings and evidence logs are retained for the defined period
  • Sample audit records showing captured content
Where this commonly fails
  • Logging enabled with default event sets never assessed for sufficiency
  • Retention shorter than investigation needs
  • In scope systems missing from logging coverage
AU.L2-3.3.2
User Accountability

Ensure actions taken on the system can be traced uniquely to the individual user responsible so users can be held accountable.

Artefacts an auditor will ask for
  • Evidence of unique user identifiers with no shared accounts
  • Audit records showing the individual user attributed to actions
  • Controls tying privileged and service account use back to a person
Where this commonly fails
  • Shared or generic administrative accounts break attribution
  • Privileged actions logged under a role rather than a person
  • Service accounts used interactively
AU.L2-3.3.3
Event Review

Review the set of events selected for logging and update it as the environment and threat picture change.

Artefacts an auditor will ask for
  • Records of periodic review of the logged event set
  • Change history showing updates to auditable events
  • Defined review frequency and owner
Where this commonly fails
  • Event set defined once and never revisited
  • Reviews performed with no resulting updates recorded
  • New systems added without event set review
AU.L2-3.3.4
Audit Failure Alerting

Raise an alert when the audit logging process itself fails, so a loss of logging is noticed rather than silent.

Artefacts an auditor will ask for
  • Alert configuration for logging process failure and log storage exhaustion
  • Evidence of alerts reaching a monitored destination
  • Records of response to a logging failure
Where this commonly fails
  • Failure detection absent so logging stops unnoticed
  • Alerts generated but routed to an unmonitored mailbox
  • Storage capacity failures not treated as logging failures
AU.L2-3.3.5
Audit Correlation

Bring audit review, analysis and reporting together across sources so signs of unlawful, unauthorized, suspicious or unusual activity can be investigated and answered.

Artefacts an auditor will ask for
  • Correlation capability configuration, for example SIEM rules
  • Evidence logs from multiple sources are aggregated
  • Investigation records showing correlated analysis
Where this commonly fails
  • Logs collected centrally but never correlated
  • Correlation rules present but untuned and unreviewed
  • Key sources absent from aggregation
AU.L2-3.3.6
Reduction & Reporting

Provide audit record reduction and report generation capability that supports analysis and reporting on demand.

Artefacts an auditor will ask for
  • Tooling providing search, filter and report generation over audit records
  • Sample generated reports
  • Evidence reduction does not alter original records
Where this commonly fails
  • Raw logs only, with no practical analysis capability
  • Reporting possible only through vendor support requests
  • Reduction process modifies the source records
AU.L2-3.3.7
Time Stamps & Synchronization

Synchronize internal system clocks against an authoritative time source so audit record time stamps are comparable across systems.

Artefacts an auditor will ask for
  • Authoritative time source identified and documented
  • Time synchronization configuration across in scope systems
  • Evidence of synchronization status and drift monitoring
Where this commonly fails
  • Systems synchronized to differing or local sources
  • Time zone handling inconsistent across log sources
  • Synchronization failures unmonitored
AU.L2-3.3.8
Audit Protection

Prevent unauthorized access to, modification of, and deletion of both audit records and the tools that produce them.

Artefacts an auditor will ask for
  • Access controls on log stores and logging tools
  • Evidence of write once, forwarding or integrity protection for logs
  • Review showing administrators cannot silently delete their own activity
Where this commonly fails
  • Local administrators able to clear logs without trace
  • Log integrity protection absent
  • Logging tool configuration modifiable by general administrators
AU.L2-3.3.9
Audit Management

Restrict the ability to manage audit logging functionality to a limited subset of privileged users, separate from general administrators.

Artefacts an auditor will ask for
  • List of users authorized to manage audit logging
  • Configuration restricting audit management permissions
  • Evidence of separation from general system administration
Where this commonly fails
  • All administrators hold audit management rights
  • Subset defined on paper but not enforced technically
  • No review of who holds audit management privileges

Awareness and Training

AT.L2-3.2.1
Role-Based Risk Awareness

Make managers, system administrators and users aware of the security risks their activities create and of the policies, standards and procedures governing the systems they use.

Artefacts an auditor will ask for
  • Security awareness materials covering risks, policies and procedures
  • Completion records by role including managers and administrators
  • Training schedule and refresher frequency
Where this commonly fails
  • Awareness aimed at general users only, omitting managers and administrators
  • Completion not tracked to individuals
  • Content generic and not tied to organizational policy
AT.L2-3.2.2
Role-Based Training

Train personnel to perform the specific information security duties and responsibilities assigned to their roles.

Artefacts an auditor will ask for
  • Role to security duty mapping
  • Role based training content and completion records
  • Evidence training precedes assumption of the duty
Where this commonly fails
  • One generic course used for every role
  • Training delivered after the duty is already being performed
  • Specialized roles such as administrators given no additional training
AT.L2-3.2.3
Insider Threat Awareness

Provide awareness training that teaches staff to recognize potential insider threat indicators and to report them.

Artefacts an auditor will ask for
  • Insider threat awareness content covering indicators and reporting
  • Completion records
  • Defined reporting channel communicated to staff
Where this commonly fails
  • Insider threat omitted from awareness content
  • Indicators taught with no reporting route given
  • Training not refreshed

Configuration Management

CM.L2-3.4.1
System Baselining

Establish and maintain baseline configurations and inventories of systems, covering hardware, software, firmware and documentation, across the system life cycle.

Artefacts an auditor will ask for
  • Documented baseline configurations per system type
  • Asset inventory covering hardware, software and firmware
  • Evidence baselines are updated as systems change
Where this commonly fails
  • Inventory maintained but no configuration baseline defined
  • Baselines captured once and never maintained
  • Firmware and documentation excluded from scope
CM.L2-3.4.2
Security Configuration Enforcement

Define security configuration settings for the IT products used in the system and enforce those settings in operation.

Artefacts an auditor will ask for
  • Documented security configuration settings or hardening standards
  • Evidence of enforcement, for example policy objects or configuration management tooling
  • Compliance scan results against the defined settings
Where this commonly fails
  • Standards documented but drift never measured
  • Settings applied at build with no ongoing enforcement
  • Products in use with no defined hardening standard
CM.L2-3.4.3
System Change Management

Track changes to systems, review them, approve or reject them, and log the decision together with the change.

Artefacts an auditor will ask for
  • Change records showing request, review, decision and implementation
  • Change approval authority definition
  • Evidence unapproved changes are detected
Where this commonly fails
  • Emergency changes bypass the process with no retrospective record
  • Approvals recorded without evidence of review
  • Infrastructure changes tracked but application changes not
CM.L2-3.4.4
Security Impact Analysis

Analyze the security impact of a proposed change before it is implemented.

Artefacts an auditor will ask for
  • Security impact analysis recorded within change records
  • Criteria defining when deeper analysis is required
  • Evidence analysis occurs prior to implementation
Where this commonly fails
  • Impact analysis performed after deployment
  • Analysis reduced to a checkbox with no substance
  • Changes deemed routine exempted without criteria
CM.L2-3.4.5
Access Restrictions for Change

Define, document, approve and enforce the physical and logical access restrictions that apply to making changes to systems.

Artefacts an auditor will ask for
  • Documented and approved change access restrictions
  • Access control configuration limiting who can implement changes
  • Records showing enforcement, including physical restrictions where relevant
Where this commonly fails
  • Logical restrictions defined but physical access unaddressed
  • Restrictions documented without technical enforcement
  • Developers able to deploy directly to production
CM.L2-3.4.6
Least Functionality

Configure systems to provide only the capabilities that are essential, applying the principle of least functionality.

Artefacts an auditor will ask for
  • Documented determination of essential capabilities per system type
  • Configuration evidence showing nonessential capabilities removed
  • Periodic review of enabled capabilities
Where this commonly fails
  • Default installations left intact
  • Essential capability never actually defined
  • Review performed without removing anything
CM.L2-3.4.7
Nonessential Functionality

Prevent nonessential programs, functions, ports, protocols and services from being used, by restricting or disabling each one identified as unnecessary.

Artefacts an auditor will ask for
  • List of prohibited or restricted programs, ports, protocols and services
  • Configuration and scan evidence showing they are disabled or blocked
  • Exception records with justification
Where this commonly fails
  • Ports and services addressed but programs and functions ignored
  • Blocking at perimeter only while hosts remain open
  • Exceptions granted permanently without review
CM.L2-3.4.8
Application Execution Policy

Operate a software execution policy, either deny by exception blocking of unauthorized software or permit by exception allowing only authorized software.

Artefacts an auditor will ask for
  • Documented decision on which policy approach is used
  • Application control configuration implementing that policy
  • Maintained allow or deny list and its review records
Where this commonly fails
  • Policy chosen but deployed in audit mode only
  • Lists never maintained after initial deployment
  • Coverage limited to a subset of endpoints
CM.L2-3.4.9
User-Installed Software

Control which software users are able to install, and monitor what has in fact been installed on organizational systems.

Artefacts an auditor will ask for
  • Policy governing user installed software
  • Technical control restricting installation rights
  • Monitoring output identifying user installed software
Where this commonly fails
  • Users hold local administrator rights so installation is unrestricted
  • Control present but no monitoring of what was installed
  • Browser extensions and portable applications out of scope

Identification and Authentication

IA.L2-3.5.1
Identification

Identify system users, the processes acting on their behalf, and devices, so each is distinguishable before any access decision is made.

Artefacts an auditor will ask for
  • Identifier assignment process and records
  • Inventory of user, process and device identifiers
  • Evidence identifiers are unique and not shared
Where this commonly fails
  • Devices and process accounts unidentified while users are covered
  • Shared identifiers in use
  • Identifier issuance undocumented
IA.L2-3.5.10
Cryptographically-Protected Passwords

Store and transmit passwords only in cryptographically protected form.

Artefacts an auditor will ask for
  • Evidence of password hashing or equivalent protection at rest
  • Configuration showing authentication traffic is encrypted in transit
  • Review confirming no plaintext credential storage
Where this commonly fails
  • Credentials stored in scripts or configuration files in plaintext
  • Legacy protocols transmit credentials unprotected
  • Reversible encryption used instead of one way protection
IA.L2-3.5.11
Obscure Feedback

Obscure authentication feedback during entry so credentials cannot be read from the screen.

Artefacts an auditor will ask for
  • Configuration or screenshots showing masked credential entry
  • Coverage across systems, applications and mobile interfaces
  • Evidence error messages do not disclose credential details
Where this commonly fails
  • Masking present in some applications only
  • Error feedback reveals whether the username or password was wrong
  • Show password features enabled by default
IA.L2-3.5.2
Authentication

Authenticate or verify the identity of users, processes and devices as a precondition of granting access to organizational systems.

Artefacts an auditor will ask for
  • Authentication mechanism configuration per system
  • Evidence authentication precedes access in all paths
  • Device and service authentication configuration
Where this commonly fails
  • Anonymous or unauthenticated access paths remain
  • Device authentication absent
  • Legacy applications bypass central authentication
IA.L2-3.5.3
Multifactor Authentication

Require more than one authentication factor for privileged account access both locally and across the network, and for non privileged account access across the network.

Artefacts an auditor will ask for
  • Multifactor configuration showing coverage of the required access cases
  • Enrolment records for privileged account holders
  • Evidence of enforcement for network access by non privileged users
Where this commonly fails
  • Multifactor applied to remote access only, missing local privileged access
  • Exemptions granted for service or legacy accounts without compensating control
  • Second factor is another knowledge factor
IA.L2-3.5.4
Replay-Resistant Authentication

Use authentication mechanisms that resist replay for network access to both privileged and non privileged accounts.

Artefacts an auditor will ask for
  • Authentication protocol configuration demonstrating replay resistance
  • Evidence deprecated protocols vulnerable to replay are disabled
  • Coverage across network accessible services
Where this commonly fails
  • Legacy authentication protocols retained for compatibility
  • Replay resistance assumed rather than verified
  • Application level authentication outside the assessed scope
IA.L2-3.5.5
Identifier Reuse

Prevent an identifier from being reissued to a different entity until a defined period has elapsed.

Artefacts an auditor will ask for
  • Defined identifier reuse prohibition period
  • Procedure or system setting preventing early reuse
  • Evidence from identifier issuance history
Where this commonly fails
  • Reuse period undefined
  • Email addresses or usernames recycled for new starters
  • Prohibition stated but not enforced by the directory
IA.L2-3.5.6
Identifier Handling

Disable identifiers once they have been inactive for a defined period.

Artefacts an auditor will ask for
  • Defined inactivity period for identifier disablement
  • Automated or procedural disablement evidence
  • Report of accounts disabled for inactivity
Where this commonly fails
  • Inactivity period undefined
  • Detection exists but disablement is manual and lapses
  • Service accounts excluded without justification
IA.L2-3.5.7
Password Complexity

Set a minimum complexity for passwords, and require that a newly created password differ in its characters from the one it replaces.

Artefacts an auditor will ask for
  • Configured password complexity settings
  • Setting or procedure requiring changed characters on password creation
  • Coverage across directories and standalone systems
Where this commonly fails
  • Complexity enforced centrally but not on local or application accounts
  • Character change requirement absent so minor edits are accepted
  • Policy documented without technical enforcement
IA.L2-3.5.8
Password Reuse

Prohibit reuse of a password for a specified number of generations.

Artefacts an auditor will ask for
  • Configured password history depth
  • Policy stating the number of generations prohibited
  • Coverage across all authentication stores
Where this commonly fails
  • History depth set to zero or unset
  • Enforced in the directory only, not on local accounts
  • Users cycle passwords rapidly to defeat history
IA.L2-3.5.9
Temporary Passwords

Permit a temporary password for logon only where it must be changed to a permanent password immediately on use.

Artefacts an auditor will ask for
  • Procedure for issuing temporary passwords
  • Configuration forcing change at first logon
  • Evidence of enforcement in account creation and reset workflows
Where this commonly fails
  • Temporary passwords remain valid indefinitely
  • Change at first logon not enforced by the system
  • Predictable temporary password patterns

Incident Response

IR.L2-3.6.1
Incident Handling

Operate an incident handling capability covering preparation, detection, analysis, containment, recovery and user response.

Artefacts an auditor will ask for
  • Incident response plan covering all named lifecycle activities
  • Assigned incident response roles and contact details
  • Records of handled incidents showing the lifecycle applied
Where this commonly fails
  • Plan covers detection and containment but omits recovery or user response
  • Capability documented with no assigned or trained personnel
  • No records demonstrating the plan is actually used
IR.L2-3.6.2
Incident Reporting

Track, document and report incidents to the designated internal officials and to external authorities where required.

Artefacts an auditor will ask for
  • Incident register with tracking and documentation per incident
  • Defined internal officials and external reporting obligations
  • Evidence of reports made within required timeframes
Where this commonly fails
  • External reporting obligations unidentified
  • Incidents handled informally and never documented
  • Reporting timeframes undefined so notifications are late
IR.L2-3.6.3
Incident Response Testing

Test the organizational incident response capability to confirm it works.

Artefacts an auditor will ask for
  • Incident response test or exercise records
  • Defined test frequency and scenario scope
  • Lessons learned and resulting plan updates
Where this commonly fails
  • Testing never performed or long lapsed
  • Exercises run without capturing findings
  • Findings identified but the plan never updated

Maintenance

MA.L2-3.7.1
Perform Maintenance

Carry out maintenance on organizational systems, so the scheduled and corrective upkeep those systems require is actually performed and recorded.

Artefacts an auditor will ask for
  • Maintenance schedule covering in scope systems
  • Completed maintenance records showing work performed and by whom
  • Evidence maintenance covers both routine and corrective work
Where this commonly fails
  • Maintenance performed but never recorded
  • Only corrective repair occurs with no scheduled maintenance
  • Systems in scope for CUI omitted from the maintenance regime
MA.L2-3.7.2
System Maintenance Control

Place controls over the tools, techniques and mechanisms used for system maintenance, and over the personnel who carry it out.

Artefacts an auditor will ask for
  • Approved maintenance tool inventory and control procedure
  • Authorization records for maintenance personnel
  • Evidence maintenance tools are checked before use
Where this commonly fails
  • Personnel controlled while tools are unmanaged
  • Technicians bring unapproved diagnostic tools on site
  • No authorization list for who may perform maintenance
MA.L2-3.7.3
Equipment Sanitization

Remove CUI from equipment by sanitization before that equipment leaves the organization for off site maintenance.

Artefacts an auditor will ask for
  • Sanitization procedure for equipment leaving for maintenance
  • Sanitization records tied to specific equipment
  • Verification step confirming CUI removal
Where this commonly fails
  • Equipment sent to vendors without sanitization
  • Sanitization claimed but not verified or recorded
  • Embedded storage in peripherals overlooked
MA.L2-3.7.4
Media Inspection

Scan media holding diagnostic and test programs for malicious code before that media is connected to organizational systems.

Artefacts an auditor will ask for
  • Procedure requiring scanning of diagnostic media
  • Scan records for media used during maintenance
  • Control preventing unscanned media from being connected
Where this commonly fails
  • Vendor supplied media trusted without scanning
  • Procedure exists but no evidence of scans performed
  • Scanning applied to organizational media only
MA.L2-3.7.5
Nonlocal Maintenance

Authenticate nonlocal maintenance sessions opened across external networks using multiple factors, and close those sessions once the maintenance work finishes.

Artefacts an auditor will ask for
  • Multifactor configuration for nonlocal maintenance access
  • Records of maintenance session establishment and termination
  • Procedure requiring termination at completion
Where this commonly fails
  • Vendor maintenance accounts exempt from multifactor
  • Sessions left open after work completes
  • Termination relies on the vendor rather than the organization
MA.L2-3.7.6
Maintenance Personnel

Supervise maintenance personnel who do not hold the access authorization normally required, for the duration of their work.

Artefacts an auditor will ask for
  • Procedure requiring supervision of unauthorized maintenance personnel
  • Supervision or escort records naming the supervisor
  • Authorization status check performed before work begins
Where this commonly fails
  • Vendor technicians left unattended
  • Escort recorded at entry but not throughout the work
  • No check of whether the technician is authorized

Media Protection

MP.L2-3.8.1
Media Protection

Physically control and securely store system media holding CUI, in both paper and digital form.

Artefacts an auditor will ask for
  • Media storage arrangements and physical security of storage locations
  • Media inventory covering paper and digital media holding CUI
  • Access records for media storage areas
Where this commonly fails
  • Digital media controlled while paper records are not
  • Media stored in unsecured shared areas
  • No inventory so media cannot be accounted for
MP.L2-3.8.2
Media Access

Limit access to CUI held on system media to users authorized to see it.

Artefacts an auditor will ask for
  • Authorization list for access to CUI bearing media
  • Access control mechanism for media storage and digital media
  • Records of access granted and revoked
Where this commonly fails
  • Access limited by physical location rather than by authorization
  • Authorization not revoked when roles change
  • Backup media accessible to general operations staff
MP.L2-3.8.3
Media Disposal

Sanitize or destroy system media containing CUI before the media is disposed of or released for reuse.

Artefacts an auditor will ask for
  • Sanitization and destruction procedure with approved methods
  • Sanitization or destruction certificates and records
  • Evidence the method matches the media type
Where this commonly fails
  • Reformatting treated as sanitization
  • Disposal handled by a third party without certificates
  • Reuse within the organization skips sanitization
MP.L2-3.8.4
Media Markings

Mark media with the CUI markings and distribution limitations that apply to its contents.

Artefacts an auditor will ask for
  • Marking procedure defining required markings and limitations
  • Sample marked media, paper and digital
  • Evidence marking is applied at creation
Where this commonly fails
  • Marking applied to documents but not to the media itself
  • Distribution limitations omitted from markings
  • Legacy media unmarked with no remediation plan
MP.L2-3.8.5
Media Accountability

Restrict who may access media holding CUI, and keep that media accounted for whenever it moves beyond controlled areas.

Artefacts an auditor will ask for
  • Transport procedure including custody and accountability steps
  • Transport logs recording media, custodian and destination
  • Evidence of receipt confirmation at destination
Where this commonly fails
  • Media transported without a custody record
  • Accountability ends when media leaves the site
  • Courier arrangements unassessed
MP.L2-3.8.6
Portable Storage Encryption

Apply cryptographic protection to CUI held on digital media during transport, unless equivalent alternative physical safeguards protect it instead.

Artefacts an auditor will ask for
  • Encryption configuration for portable and transported digital media
  • Evidence of encryption status for media in transit
  • Documented alternative physical safeguards where encryption is not used
Where this commonly fails
  • Encryption assumed but not verified per device
  • Alternative safeguards claimed without documentation
  • Backup media shipped unencrypted
MP.L2-3.8.7
Removable Media

Govern which removable media may be used on system components, and enforce that restriction at the components themselves.

Artefacts an auditor will ask for
  • Removable media policy defining permitted use
  • Technical control over removable media ports and devices
  • Records of approved exceptions
Where this commonly fails
  • Policy exists with no technical enforcement
  • Control applied to storage devices but not to other removable media
  • Exceptions granted without expiry
MP.L2-3.8.8
Shared Media

Prohibit the use of portable storage devices that have no identifiable owner.

Artefacts an auditor will ask for
  • Policy prohibiting unidentified portable storage
  • Technical control blocking unknown devices
  • Awareness material communicating the prohibition
Where this commonly fails
  • Prohibition stated but any device still mounts
  • Ownership identification process undefined
  • Found devices connected to check contents
MP.L2-3.8.9
Protect Backups

Protect the confidentiality of backup copies of CUI at the locations where those backups are stored.

Artefacts an auditor will ask for
  • Backup inventory identifying which backups contain CUI
  • Protection applied at backup storage locations, encryption or physical control
  • Access controls and records for backup storage
Where this commonly fails
  • Production data protected while backups are not
  • Offsite and cloud backup locations unassessed
  • Backup encryption keys stored alongside the backups

Personnel Security

PS.L2-3.9.1
Screen Individuals

Screen individuals before authorizing their access to systems containing CUI.

Artefacts an auditor will ask for
  • Screening criteria and procedure
  • Screening records for individuals granted access
  • Evidence screening precedes access authorization
Where this commonly fails
  • Access granted before screening completes
  • Contractors and vendors exempt from screening
  • Screening performed but not recorded
PS.L2-3.9.2
Personnel Actions

Protect systems containing CUI during and after personnel actions such as termination or transfer, including timely revocation of access.

Artefacts an auditor will ask for
  • Termination and transfer procedure covering access revocation and asset return
  • Records showing revocation timing against departure date
  • Evidence credentials and property are recovered
Where this commonly fails
  • Revocation delayed well beyond departure
  • Transfers leave accumulated access from the previous role
  • Physical access and assets not recovered

Physical Protection

PE.L2-3.10.1
Limit Physical Access

Limit physical access to systems, equipment and their operating environments to authorized individuals.

Artefacts an auditor will ask for
  • Physical access authorization list for controlled areas
  • Access control mechanism evidence such as badge system configuration
  • Periodic review of who holds physical access
Where this commonly fails
  • Access lists not reviewed so departed staff retain badges
  • Server and equipment areas within general office access
  • Authorization granted verbally without record
PE.L2-3.10.2
Monitor Facility

Protect and monitor the physical facility and the support infrastructure that organizational systems depend on.

Artefacts an auditor will ask for
  • Facility protection measures and monitoring arrangements
  • Evidence support infrastructure such as power and cabling is protected
  • Monitoring records or alarm and camera coverage evidence
Where this commonly fails
  • Facility monitored while support infrastructure is not
  • Monitoring equipment installed but recordings unreviewed
  • Shared or landlord controlled infrastructure unassessed
PE.L2-3.10.3
Escort Visitors

Escort visitors and monitor visitor activity while they are on site.

Artefacts an auditor will ask for
  • Visitor procedure requiring escort and monitoring
  • Visitor logs recording escort assignment
  • Evidence monitoring continues for the visit duration
Where this commonly fails
  • Visitors signed in but not escorted
  • Contractors treated as staff and left unescorted
  • Escort recorded at entry only
PE.L2-3.10.4
Physical Access Logs

Maintain audit logs recording physical access to facilities holding organizational systems.

Artefacts an auditor will ask for
  • Physical access logs, electronic or manual
  • Defined retention period for physical access records
  • Evidence logs are reviewed
Where this commonly fails
  • Logs captured but never retained or reviewed
  • Manual visitor books used with incomplete entries
  • Badge system logs overwritten quickly
PE.L2-3.10.5
Manage Physical Access

Control and manage physical access devices such as keys, locks, combinations and badge readers.

Artefacts an auditor will ask for
  • Inventory of physical access devices and their holders
  • Issue, return and change records for keys and combinations
  • Evidence combinations and locks are changed on personnel change
Where this commonly fails
  • Keys issued with no inventory or return process
  • Combinations never changed after staff departures
  • Master keys uncontrolled
PE.L2-3.10.6
Alternative Work Sites

Enforce safeguarding measures for CUI at alternate work sites such as home or remote offices.

Artefacts an auditor will ask for
  • Alternate work site policy defining required safeguards
  • Evidence safeguards are communicated and acknowledged
  • Assessment or attestation of alternate work site conditions
Where this commonly fails
  • Remote work policy silent on physical safeguards for CUI
  • Safeguards defined but compliance never checked
  • Printing and paper CUI at home not addressed

Risk Assessment

RA.L2-3.11.1
Risk Assessments

Periodically assess the risk that operating organizational systems, and processing, storing or transmitting CUI, creates for operations, assets and individuals.

Artefacts an auditor will ask for
  • Risk assessment methodology and defined frequency
  • Completed risk assessment covering CUI processing, storage and transmission
  • Evidence results are communicated and used
Where this commonly fails
  • Assessment covers technology risk only, omitting mission and individual impact
  • Performed once with no defined recurrence
  • Results not linked to remediation decisions
RA.L2-3.11.2
Vulnerability Scan

Scan systems and applications for vulnerabilities periodically and again when new vulnerabilities affecting them are identified.

Artefacts an auditor will ask for
  • Scan schedule and scope covering systems and applications
  • Scan reports across the defined period
  • Evidence of additional scanning triggered by new vulnerability information
Where this commonly fails
  • Infrastructure scanned while applications are not
  • Scanning periodic only, with no trigger on new vulnerability disclosure
  • Authenticated scanning not used so coverage is shallow
RA.L2-3.11.3
Vulnerability Remediation

Remediate identified vulnerabilities in line with the priorities set by risk assessment.

Artefacts an auditor will ask for
  • Remediation procedure with risk based timeframes
  • Evidence of remediation against identified findings
  • Records of accepted risk with approval where remediation is deferred
Where this commonly fails
  • Findings tracked but remediation timeframes undefined
  • Prioritization by scanner severity alone, ignoring organizational risk
  • Deferred items accepted without documented approval

Security Assessment

CA.L2-3.12.1
Security Control Assessment

Assess the security controls in place periodically to determine whether they are effective as implemented.

Artefacts an auditor will ask for
  • Assessment plan defining scope, method and frequency
  • Completed assessment results per control
  • Evidence assessments cover effectiveness and not just presence
Where this commonly fails
  • Assessment confirms a control exists without testing whether it works
  • Scope excludes parts of the CUI environment
  • No defined periodicity so assessments lapse
CA.L2-3.12.2
Plan of Action

Develop and carry out plans of action that correct identified deficiencies and reduce or eliminate vulnerabilities.

Artefacts an auditor will ask for
  • Plan of action and milestones with owners and target dates
  • Evidence of progress and closure for completed items
  • Linkage from assessment findings to plan entries
Where this commonly fails
  • Plan maintained as a static list with no progress
  • Findings closed without evidence of correction
  • Deficiencies identified but never entered into the plan
CA.L2-3.12.3
Security Control Monitoring

Monitor security controls continuously so their effectiveness is known on an ongoing basis rather than only at assessment time.

Artefacts an auditor will ask for
  • Continuous monitoring strategy naming controls, metrics and frequency
  • Monitoring output such as dashboards or periodic reports
  • Records of action taken when monitoring shows degradation
Where this commonly fails
  • Monitoring limited to the annual assessment
  • Metrics collected but not evaluated against expectations
  • Degradation detected without follow up
CA.L2-3.12.4
System Security Plan

Develop, document and periodically update a system security plan describing system boundaries, the operating environment, how each requirement is implemented, and connections to other systems.

Artefacts an auditor will ask for
  • Current system security plan covering boundary, environment, implementation and interconnections
  • Version history showing periodic update
  • Approval record for the current version
Where this commonly fails
  • Plan describes intent rather than actual implementation
  • Boundary and interconnections omitted or stale
  • No defined update trigger or cadence

System and Communications Protection

SC.L2-3.13.1
Boundary Protection

Monitor, control and protect communications at the external boundary of the system and at key internal boundaries.

Artefacts an auditor will ask for
  • Network architecture identifying external and key internal boundaries
  • Boundary device configuration such as firewall and gateway rulesets
  • Monitoring evidence at those boundaries
Where this commonly fails
  • External boundary protected while internal boundaries are flat
  • Boundary devices configured but traffic not monitored
  • Cloud and remote boundaries omitted from the architecture
SC.L2-3.13.10
Key Management

Establish and manage the cryptographic keys used by cryptography employed in organizational systems, across their life cycle.

Artefacts an auditor will ask for
  • Key management procedure covering generation, distribution, storage, rotation and destruction
  • Key inventory and custodian assignments
  • Evidence of key rotation and secure storage
Where this commonly fails
  • Keys generated and then never rotated or inventoried
  • Private keys stored alongside the data they protect
  • Key custodianship undefined so departures leave keys orphaned
SC.L2-3.13.11
CUI Encryption

Use FIPS validated cryptography wherever cryptography is relied on to protect the confidentiality of CUI.

Artefacts an auditor will ask for
  • Inventory of cryptographic modules protecting CUI with validation certificate references
  • Configuration evidence showing validated modules and approved modes in use
  • Evidence non validated cryptography is not relied on for CUI
Where this commonly fails
  • Cryptography strong but not FIPS validated
  • Validated module present but operated outside its approved mode
  • Certificate references stale or covering a different version
SC.L2-3.13.12
Collaborative Device Control

Prohibit remote activation of collaborative computing devices such as cameras and microphones, and indicate to people present when such a device is in use.

Artefacts an auditor will ask for
  • Policy prohibiting remote activation of collaborative devices
  • Configuration preventing remote activation
  • Evidence of an in use indicator visible to those present
Where this commonly fails
  • Prohibition stated with no technical enforcement
  • Indicator absent on conference room equipment
  • Conferencing software permitted to auto enable cameras or microphones
SC.L2-3.13.13
Mobile Code

Define which mobile code technologies are permitted, enforce that decision, and keep mobile code use under observation.

Artefacts an auditor will ask for
  • Policy defining acceptable and prohibited mobile code technologies
  • Technical controls restricting mobile code execution
  • Monitoring evidence for mobile code use
Where this commonly fails
  • Mobile code technologies undefined so the policy is unenforceable
  • Controls applied at the browser only, ignoring documents and email
  • Use controlled but never monitored
SC.L2-3.13.14
Voice over Internet Protocol

Govern how Voice over Internet Protocol technology may be used, and keep its use under observation once deployed.

Artefacts an auditor will ask for
  • Policy governing permitted VoIP use
  • VoIP configuration and access controls
  • Monitoring records for VoIP usage
Where this commonly fails
  • VoIP deployed with no governing policy
  • Voice network not segmented from data
  • Usage unmonitored and default credentials retained
SC.L2-3.13.15
Communications Authenticity

Protect the authenticity of communications sessions so a session cannot be hijacked or spoofed.

Artefacts an auditor will ask for
  • Session authenticity mechanism configuration, for example session tokens and mutual authentication
  • Evidence sessions are bound and validated
  • Configuration preventing session fixation and reuse
Where this commonly fails
  • Confidentiality protected while session authenticity is not
  • Session identifiers predictable or not regenerated after authentication
  • Application sessions outside the assessed scope
SC.L2-3.13.16
Data at Rest

Protect the confidentiality of CUI while it is at rest in storage.

Artefacts an auditor will ask for
  • Inventory of locations where CUI is stored at rest
  • Encryption or equivalent protection configuration at those locations
  • Evidence of protection coverage including databases, file shares and endpoints
Where this commonly fails
  • Endpoint encryption in place while servers and shares are unprotected
  • Storage locations for CUI never fully inventoried
  • Cloud storage protection assumed from the provider without verification
SC.L2-3.13.2
Security Engineering

Apply architectural design, software development techniques and systems engineering principles that promote effective information security.

Artefacts an auditor will ask for
  • Documented security architecture and design principles
  • Secure development standards applied to in house software
  • Evidence principles are applied in design reviews
Where this commonly fails
  • Principles documented but absent from actual design decisions
  • Secure development standards not applied to acquired or outsourced code
  • No design review step in the development process
SC.L2-3.13.3
Role Separation

Separate user functionality from system management functionality so ordinary users are not presented with administrative interfaces.

Artefacts an auditor will ask for
  • Evidence of separation between user and management interfaces
  • Configuration restricting administrative interface exposure
  • Architecture showing management plane separation
Where this commonly fails
  • Administrative consoles reachable from user networks
  • Separation logical in name only with shared credentials
  • Management interfaces exposed to the internet
SC.L2-3.13.4
Shared Resource Control

Prevent information from being transferred, intentionally or unintentionally, between users through shared system resources.

Artefacts an auditor will ask for
  • Configuration evidence for object reuse and memory or storage clearing
  • Evidence of isolation between users in shared and virtualized environments
  • Testing results showing residual data is not accessible
Where this commonly fails
  • Shared and virtualized environments assumed isolated without verification
  • Temporary files and shared directories accessible across users
  • Object reuse protections disabled for performance
SC.L2-3.13.5
Public-Access System Separation

Place publicly accessible system components on subnetworks that are physically or logically separated from internal networks.

Artefacts an auditor will ask for
  • Network diagram showing the separated subnetwork for public components
  • Firewall or routing configuration enforcing the separation
  • Inventory of publicly accessible components
Where this commonly fails
  • Public facing servers residing on internal networks
  • Separation exists but permissive rules allow broad internal access
  • New public services deployed outside the segmented zone
SC.L2-3.13.6
Network Communication by Exception

Deny network communications traffic by default and permit only traffic explicitly allowed by exception.

Artefacts an auditor will ask for
  • Firewall and access control lists showing a default deny posture
  • Documented and approved exceptions with justification
  • Review records for permitted exceptions
Where this commonly fails
  • Default deny at perimeter only while internal traffic is permit all
  • Any to any rules present alongside the deny default
  • Exceptions accumulated with no periodic review
SC.L2-3.13.7
Split Tunneling

Prevent a remote device from holding a connection to organizational systems while simultaneously connecting through another path to external network resources, the split tunneling case.

Artefacts an auditor will ask for
  • VPN or remote client configuration disabling split tunneling
  • Evidence the setting is enforced and not user changeable
  • Coverage across all remote client platforms
Where this commonly fails
  • Split tunneling disabled by policy but user configurable
  • Some client platforms or vendor clients still permit it
  • Exceptions granted for bandwidth with no compensating control
SC.L2-3.13.8
Data in Transit

Apply cryptographic protection to prevent unauthorized disclosure of CUI during transmission, unless alternative physical safeguards protect it instead.

Artefacts an auditor will ask for
  • Transmission encryption configuration for CUI bearing paths
  • Inventory of CUI transmission paths, internal and external
  • Documented alternative physical safeguards where used
Where this commonly fails
  • External transmission encrypted while internal paths are clear
  • Email carrying CUI sent without protection
  • Alternative safeguards asserted without documentation
SC.L2-3.13.9
Connections Termination

Terminate network connections when the associated session ends or after a defined period of inactivity.

Artefacts an auditor will ask for
  • Defined inactivity period for connection termination
  • Configuration on network devices and services implementing termination
  • Evidence of termination occurring in logs
Where this commonly fails
  • Inactivity period undefined
  • Termination applied to remote access only
  • Long lived connections exempt without justification

System and Information Integrity

SI.L2-3.14.1
Flaw Remediation

Identify system flaws, report them, and correct them within a timely period.

Artefacts an auditor will ask for
  • Flaw identification sources and process
  • Patch and remediation records with dates showing timeliness
  • Defined timeframes for correction by severity
Where this commonly fails
  • Flaws identified but remediation timeframes undefined
  • Patching covers operating systems only, omitting applications and firmware
  • Reporting step absent so flaws are not tracked
SI.L2-3.14.2
Malicious Code Protection

Provide malicious code protection at the points in the system where such code is likely to enter or execute.

Artefacts an auditor will ask for
  • Identification of designated protection locations, endpoints and gateways
  • Malicious code protection deployment and coverage reporting
  • Configuration showing protection is active
Where this commonly fails
  • Endpoints covered while email and web gateways are not
  • Coverage gaps on servers and non standard platforms
  • Protection installed but disabled or in passive mode
SI.L2-3.14.3
Security Alerts & Advisories

Monitor security alerts and advisories and take action in response to them.

Artefacts an auditor will ask for
  • Subscriptions or sources for security alerts and advisories
  • Records of alerts received and assessed
  • Evidence of action taken in response
Where this commonly fails
  • Advisories received but never triaged
  • No defined owner for monitoring advisories
  • Action taken informally with no record
SI.L2-3.14.4
Update Malicious Code Protection

Keep malicious code protection mechanisms current by applying new releases as they are issued.

Artefacts an auditor will ask for
  • Update configuration for signatures and engine versions
  • Reporting showing current update status across the estate
  • Evidence of remediation for out of date endpoints
Where this commonly fails
  • Signatures updated while the engine version lags
  • Offline or infrequently connected devices left stale
  • Update failures unmonitored
SI.L2-3.14.5
System & File Scanning

Run periodic scans of systems and real time scans of files arriving from external sources as those files are downloaded, opened or executed.

Artefacts an auditor will ask for
  • Scheduled scan configuration and completion records
  • Real time scanning configuration covering download, open and execute events
  • Coverage reporting across in scope systems
Where this commonly fails
  • Periodic scanning enabled while real time scanning is off
  • Real time scanning limited to downloads only
  • Scan exclusions broad and unreviewed
SI.L2-3.14.6
Monitor Communications for Attacks

Watch organizational systems, and both inbound and outbound traffic, for attacks and for indicators that an attack may be developing.

Artefacts an auditor will ask for
  • Monitoring capability configuration covering inbound and outbound traffic
  • Detection rules or signatures and their tuning records
  • Records of detected events and the response taken
Where this commonly fails
  • Inbound traffic monitored while outbound is not
  • Monitoring deployed but alerts unreviewed
  • Encrypted traffic unmonitored with no compensating visibility
SI.L2-3.14.7
Identify Unauthorized Use

Define what constitutes authorized use of organizational systems, and identify use that falls outside that definition.

Artefacts an auditor will ask for
  • Documented definition of authorized system use
  • Monitoring or detection capability identifying use outside that definition
  • Records of identified unauthorized use and the response
Where this commonly fails
  • Authorized use never defined so unauthorized use cannot be identified
  • Detection focused on external attack while insider misuse is unaddressed
  • Identified misuse not recorded or acted on
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.