CMMC 2.0
Evidence request list. 110 controls, 110 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.
Access Control
Restrict system access so only identified, authorized users, the processes running on their behalf, and approved devices including other connected systems can connect.
- Account inventory listing authorized users, service/process accounts and approved devices
- Account provisioning and approval records showing authorization before access
- System configuration showing device and system-to-system connection allow lists
- Periodic account recertification results
- Service and machine accounts never authorized or reviewed
- Device-level access unrestricted while user access is controlled
- Stale accounts retained after staff depart
Lock the user session after a defined period of inactivity and conceal previously displayed content behind a pattern hiding display until the user reauthenticates.
- Configured inactivity timeout and session lock settings
- Evidence the lock hides screen content, for example screensaver policy
- Deployment coverage across workstations and servers
- Timeout configured but pattern hiding not enforced
- Users permitted to disable the lock locally
- Servers and shared terminals excluded
Automatically end a user session once a defined condition, such as an inactivity period or maximum session duration, is met.
- Defined session termination conditions in policy
- System and application configuration implementing automatic termination
- Evidence of sessions terminated in logs
- Session lock mistaken for session termination
- Conditions undefined so nothing terminates
- Application sessions persist after operating system termination
Monitor and control remote access sessions so each remote connection is authorized, visible to the organization and subject to enforcement.
- Remote access policy defining permitted methods and approval
- VPN or remote gateway configuration and connection logs
- Records of remote session monitoring and review
- Remote access permitted through unmanaged tools
- Connections logged but never reviewed
- Third party remote support paths outside the control
Apply cryptographic protection to remote access sessions so session confidentiality is preserved in transit.
- Remote access encryption configuration showing protocol and cipher settings
- Evidence that weak or plaintext remote protocols are disabled
- Certificate or key management records for the remote access service
- Legacy plaintext protocols still enabled as fallback
- Encryption terminated at an intermediary leaving segments in clear
- Cipher suites unreviewed and outdated
Force remote access traffic through a limited set of managed access control points rather than allowing arbitrary entry paths into the network.
- Network architecture identifying the managed remote access points
- Firewall rules restricting remote entry to those points
- Evidence that alternative ingress paths are blocked
- Multiple undocumented remote entry points
- Vendor appliances providing side channel access
- Split of remote traffic across unmanaged cloud services
Require explicit authorization before privileged commands may be executed remotely or security relevant information accessed remotely.
- Documented authorization for remote privileged operations
- Configuration restricting remote privileged command execution
- Logs of remote privileged sessions and the approvals behind them
- Remote administration allowed to anyone holding admin rights
- Authorization implied by role rather than explicitly granted
- No record tying remote privileged activity to an approval
Authorize each wireless connection before it is permitted to attach to the system.
- Wireless access authorization records and approved device list
- Wireless network configuration showing authorization enforcement
- Rogue access point detection results
- Wireless access granted by shared passphrase with no authorization step
- Guest wireless bridged to internal networks
- Unauthorized access points undetected
Protect wireless connections using authentication and encryption so wireless traffic and access are not open to nearby parties.
- Wireless security configuration showing authentication method and encryption
- Evidence that deprecated wireless protocols are disabled
- Wireless credential or certificate management records
- Pre shared keys shared widely and never rotated
- Legacy encryption retained for older devices
- Authentication not tied to individual identity
Control which mobile devices may connect to organizational systems, and manage those connections.
- Mobile device policy and approved device inventory
- Mobile device management enrolment and compliance records
- Configuration restricting connection to managed devices
- Personal devices connect without enrolment
- Inventory maintained but connection not technically restricted
- No removal process when a device is lost or retired
Encrypt CUI held on mobile devices and mobile computing platforms so the data stays protected if a device is lost or stolen.
- Device encryption configuration and compliance reporting
- Evidence of encryption status per enrolled device
- Policy identifying which mobile platforms may hold CUI
- Encryption assumed by default without verification
- Removable storage in mobile devices left unencrypted
- Devices holding CUI outside the managed estate
Confine each authorized user to the specific transactions and functions their role permits, so privileges bound what can be executed and not merely whether access is granted.
- Role definitions mapping roles to permitted transactions and functions
- Application and system permission matrices as configured
- Approval records for role assignment per user
- Evidence of enforcement testing on a restricted role
- Access granted at system level with no function-level restriction
- Roles defined on paper but not enforced in the application
- Broad default roles assigned for convenience
Verify, then control or limit, connections to and use of external systems that are outside organizational control.
- Inventory of approved external systems and connection terms
- Agreements or terms governing external system use
- Technical controls limiting external system connections
- External cloud services used without review
- Connections permitted with no verification of the external party
- No limit on what CUI may be processed externally
Restrict how organizational portable storage devices may be used when connected to systems outside organizational control.
- Policy stating limits on portable storage use on external systems
- Technical restriction or endpoint control evidence
- Records of approved exceptions
- Policy silent on external system use specifically
- Restriction applied internally but not to devices taken off site
- No mechanism to detect violation
Control CUI that is posted to or processed on publicly accessible systems so CUI is not released to the public.
- Review and approval process for content published publicly
- Designated reviewer authorizations and review records
- Evidence of periodic scanning of public sites for CUI
- Publication approval informal or undocumented
- No periodic check of already published content
- Public facing systems not identified as in scope
Enforce approved authorization rules on the movement of CUI between systems, components and destinations, so CUI flows only where policy permits.
- Documented CUI flow authorizations and approved flow paths
- Firewall, proxy, DLP or gateway rules enforcing those flows
- Data flow diagrams identifying CUI sources, stores and destinations
- Records of blocked or exception-approved transfers
- CUI flows documented but not technically enforced
- Egress to cloud and email paths unmonitored for CUI
- No defined authorization for flows to external partners
Divide security relevant duties among different individuals so no single person can both carry out and conceal a harmful action without collusion.
- Documented separation of duties matrix for security relevant tasks
- Access assignments demonstrating conflicting duties are held by different people
- Records of conflict analysis and any approved compensating controls
- Single administrator holds all privileged roles
- Separation defined but not tested against actual entitlements
- Small team treated as automatic exemption with no compensating control
Grant users and processes only the privileges their assigned tasks require, applying this specifically to security functions and to privileged accounts.
- Privileged account inventory with documented business justification
- Entitlement review results showing removal of excess rights
- Configuration showing security functions restricted to designated roles
- Standing administrative rights granted broadly
- Privilege reviews performed but findings not actioned
- Security functions accessible to general administrators
Require staff holding privileged accounts to use a non privileged account or role when performing work that does not need elevated rights.
- Policy requiring separate privileged and non privileged accounts
- Evidence that administrators hold distinct day-to-day accounts
- Logs showing routine activity performed under non privileged accounts
- Administrators use privileged accounts for email and browsing
- Dual accounts issued but daily use not enforced or monitored
- No detection of privileged account use for nonsecurity tasks
Block non privileged users from executing privileged functions, and capture every execution of such functions in the audit log.
- Configuration preventing privileged function execution by standard users
- Audit log samples showing captured privileged function execution
- Test results of an attempted privileged action by a non privileged account
- Privileged functions blocked but execution not logged
- Logging enabled without covering privileged function use
- Local administrator rights on endpoints bypass the restriction
Cap the number of consecutive failed logon attempts allowed and take a defined action, such as account lockout, once that limit is reached.
- Configured lockout threshold, duration and reset settings
- Policy stating the failed attempt limit and resulting action
- Evidence of enforcement across all authentication paths including remote
- Limit set in policy but not configured on all systems
- Remote and application logons exempt from lockout
- Lockout thresholds so high they never trigger
Display privacy and security notices to users at logon that reflect the CUI rules applicable to the system.
- Approved notice or banner text consistent with applicable CUI rules
- Screenshots showing the notice presented at logon
- Coverage list of systems where the banner is deployed
- Banner present on some systems only
- Generic notice not reflecting CUI requirements
- Notice bypassed on remote or application logon paths
Audit and Accountability
Generate and retain system audit logs in sufficient scope and detail to support monitoring, analysis, investigation and reporting of unlawful or unauthorized system activity.
- Defined auditable event list and rationale for its scope
- Logging configuration on in scope systems
- Retention settings and evidence logs are retained for the defined period
- Sample audit records showing captured content
- Logging enabled with default event sets never assessed for sufficiency
- Retention shorter than investigation needs
- In scope systems missing from logging coverage
Ensure actions taken on the system can be traced uniquely to the individual user responsible so users can be held accountable.
- Evidence of unique user identifiers with no shared accounts
- Audit records showing the individual user attributed to actions
- Controls tying privileged and service account use back to a person
- Shared or generic administrative accounts break attribution
- Privileged actions logged under a role rather than a person
- Service accounts used interactively
Review the set of events selected for logging and update it as the environment and threat picture change.
- Records of periodic review of the logged event set
- Change history showing updates to auditable events
- Defined review frequency and owner
- Event set defined once and never revisited
- Reviews performed with no resulting updates recorded
- New systems added without event set review
Raise an alert when the audit logging process itself fails, so a loss of logging is noticed rather than silent.
- Alert configuration for logging process failure and log storage exhaustion
- Evidence of alerts reaching a monitored destination
- Records of response to a logging failure
- Failure detection absent so logging stops unnoticed
- Alerts generated but routed to an unmonitored mailbox
- Storage capacity failures not treated as logging failures
Bring audit review, analysis and reporting together across sources so signs of unlawful, unauthorized, suspicious or unusual activity can be investigated and answered.
- Correlation capability configuration, for example SIEM rules
- Evidence logs from multiple sources are aggregated
- Investigation records showing correlated analysis
- Logs collected centrally but never correlated
- Correlation rules present but untuned and unreviewed
- Key sources absent from aggregation
Provide audit record reduction and report generation capability that supports analysis and reporting on demand.
- Tooling providing search, filter and report generation over audit records
- Sample generated reports
- Evidence reduction does not alter original records
- Raw logs only, with no practical analysis capability
- Reporting possible only through vendor support requests
- Reduction process modifies the source records
Synchronize internal system clocks against an authoritative time source so audit record time stamps are comparable across systems.
- Authoritative time source identified and documented
- Time synchronization configuration across in scope systems
- Evidence of synchronization status and drift monitoring
- Systems synchronized to differing or local sources
- Time zone handling inconsistent across log sources
- Synchronization failures unmonitored
Prevent unauthorized access to, modification of, and deletion of both audit records and the tools that produce them.
- Access controls on log stores and logging tools
- Evidence of write once, forwarding or integrity protection for logs
- Review showing administrators cannot silently delete their own activity
- Local administrators able to clear logs without trace
- Log integrity protection absent
- Logging tool configuration modifiable by general administrators
Restrict the ability to manage audit logging functionality to a limited subset of privileged users, separate from general administrators.
- List of users authorized to manage audit logging
- Configuration restricting audit management permissions
- Evidence of separation from general system administration
- All administrators hold audit management rights
- Subset defined on paper but not enforced technically
- No review of who holds audit management privileges
Awareness and Training
Make managers, system administrators and users aware of the security risks their activities create and of the policies, standards and procedures governing the systems they use.
- Security awareness materials covering risks, policies and procedures
- Completion records by role including managers and administrators
- Training schedule and refresher frequency
- Awareness aimed at general users only, omitting managers and administrators
- Completion not tracked to individuals
- Content generic and not tied to organizational policy
Train personnel to perform the specific information security duties and responsibilities assigned to their roles.
- Role to security duty mapping
- Role based training content and completion records
- Evidence training precedes assumption of the duty
- One generic course used for every role
- Training delivered after the duty is already being performed
- Specialized roles such as administrators given no additional training
Provide awareness training that teaches staff to recognize potential insider threat indicators and to report them.
- Insider threat awareness content covering indicators and reporting
- Completion records
- Defined reporting channel communicated to staff
- Insider threat omitted from awareness content
- Indicators taught with no reporting route given
- Training not refreshed
Configuration Management
Establish and maintain baseline configurations and inventories of systems, covering hardware, software, firmware and documentation, across the system life cycle.
- Documented baseline configurations per system type
- Asset inventory covering hardware, software and firmware
- Evidence baselines are updated as systems change
- Inventory maintained but no configuration baseline defined
- Baselines captured once and never maintained
- Firmware and documentation excluded from scope
Define security configuration settings for the IT products used in the system and enforce those settings in operation.
- Documented security configuration settings or hardening standards
- Evidence of enforcement, for example policy objects or configuration management tooling
- Compliance scan results against the defined settings
- Standards documented but drift never measured
- Settings applied at build with no ongoing enforcement
- Products in use with no defined hardening standard
Track changes to systems, review them, approve or reject them, and log the decision together with the change.
- Change records showing request, review, decision and implementation
- Change approval authority definition
- Evidence unapproved changes are detected
- Emergency changes bypass the process with no retrospective record
- Approvals recorded without evidence of review
- Infrastructure changes tracked but application changes not
Analyze the security impact of a proposed change before it is implemented.
- Security impact analysis recorded within change records
- Criteria defining when deeper analysis is required
- Evidence analysis occurs prior to implementation
- Impact analysis performed after deployment
- Analysis reduced to a checkbox with no substance
- Changes deemed routine exempted without criteria
Define, document, approve and enforce the physical and logical access restrictions that apply to making changes to systems.
- Documented and approved change access restrictions
- Access control configuration limiting who can implement changes
- Records showing enforcement, including physical restrictions where relevant
- Logical restrictions defined but physical access unaddressed
- Restrictions documented without technical enforcement
- Developers able to deploy directly to production
Configure systems to provide only the capabilities that are essential, applying the principle of least functionality.
- Documented determination of essential capabilities per system type
- Configuration evidence showing nonessential capabilities removed
- Periodic review of enabled capabilities
- Default installations left intact
- Essential capability never actually defined
- Review performed without removing anything
Prevent nonessential programs, functions, ports, protocols and services from being used, by restricting or disabling each one identified as unnecessary.
- List of prohibited or restricted programs, ports, protocols and services
- Configuration and scan evidence showing they are disabled or blocked
- Exception records with justification
- Ports and services addressed but programs and functions ignored
- Blocking at perimeter only while hosts remain open
- Exceptions granted permanently without review
Operate a software execution policy, either deny by exception blocking of unauthorized software or permit by exception allowing only authorized software.
- Documented decision on which policy approach is used
- Application control configuration implementing that policy
- Maintained allow or deny list and its review records
- Policy chosen but deployed in audit mode only
- Lists never maintained after initial deployment
- Coverage limited to a subset of endpoints
Control which software users are able to install, and monitor what has in fact been installed on organizational systems.
- Policy governing user installed software
- Technical control restricting installation rights
- Monitoring output identifying user installed software
- Users hold local administrator rights so installation is unrestricted
- Control present but no monitoring of what was installed
- Browser extensions and portable applications out of scope
Identification and Authentication
Identify system users, the processes acting on their behalf, and devices, so each is distinguishable before any access decision is made.
- Identifier assignment process and records
- Inventory of user, process and device identifiers
- Evidence identifiers are unique and not shared
- Devices and process accounts unidentified while users are covered
- Shared identifiers in use
- Identifier issuance undocumented
Store and transmit passwords only in cryptographically protected form.
- Evidence of password hashing or equivalent protection at rest
- Configuration showing authentication traffic is encrypted in transit
- Review confirming no plaintext credential storage
- Credentials stored in scripts or configuration files in plaintext
- Legacy protocols transmit credentials unprotected
- Reversible encryption used instead of one way protection
Obscure authentication feedback during entry so credentials cannot be read from the screen.
- Configuration or screenshots showing masked credential entry
- Coverage across systems, applications and mobile interfaces
- Evidence error messages do not disclose credential details
- Masking present in some applications only
- Error feedback reveals whether the username or password was wrong
- Show password features enabled by default
Authenticate or verify the identity of users, processes and devices as a precondition of granting access to organizational systems.
- Authentication mechanism configuration per system
- Evidence authentication precedes access in all paths
- Device and service authentication configuration
- Anonymous or unauthenticated access paths remain
- Device authentication absent
- Legacy applications bypass central authentication
Require more than one authentication factor for privileged account access both locally and across the network, and for non privileged account access across the network.
- Multifactor configuration showing coverage of the required access cases
- Enrolment records for privileged account holders
- Evidence of enforcement for network access by non privileged users
- Multifactor applied to remote access only, missing local privileged access
- Exemptions granted for service or legacy accounts without compensating control
- Second factor is another knowledge factor
Use authentication mechanisms that resist replay for network access to both privileged and non privileged accounts.
- Authentication protocol configuration demonstrating replay resistance
- Evidence deprecated protocols vulnerable to replay are disabled
- Coverage across network accessible services
- Legacy authentication protocols retained for compatibility
- Replay resistance assumed rather than verified
- Application level authentication outside the assessed scope
Prevent an identifier from being reissued to a different entity until a defined period has elapsed.
- Defined identifier reuse prohibition period
- Procedure or system setting preventing early reuse
- Evidence from identifier issuance history
- Reuse period undefined
- Email addresses or usernames recycled for new starters
- Prohibition stated but not enforced by the directory
Disable identifiers once they have been inactive for a defined period.
- Defined inactivity period for identifier disablement
- Automated or procedural disablement evidence
- Report of accounts disabled for inactivity
- Inactivity period undefined
- Detection exists but disablement is manual and lapses
- Service accounts excluded without justification
Set a minimum complexity for passwords, and require that a newly created password differ in its characters from the one it replaces.
- Configured password complexity settings
- Setting or procedure requiring changed characters on password creation
- Coverage across directories and standalone systems
- Complexity enforced centrally but not on local or application accounts
- Character change requirement absent so minor edits are accepted
- Policy documented without technical enforcement
Prohibit reuse of a password for a specified number of generations.
- Configured password history depth
- Policy stating the number of generations prohibited
- Coverage across all authentication stores
- History depth set to zero or unset
- Enforced in the directory only, not on local accounts
- Users cycle passwords rapidly to defeat history
Permit a temporary password for logon only where it must be changed to a permanent password immediately on use.
- Procedure for issuing temporary passwords
- Configuration forcing change at first logon
- Evidence of enforcement in account creation and reset workflows
- Temporary passwords remain valid indefinitely
- Change at first logon not enforced by the system
- Predictable temporary password patterns
Incident Response
Operate an incident handling capability covering preparation, detection, analysis, containment, recovery and user response.
- Incident response plan covering all named lifecycle activities
- Assigned incident response roles and contact details
- Records of handled incidents showing the lifecycle applied
- Plan covers detection and containment but omits recovery or user response
- Capability documented with no assigned or trained personnel
- No records demonstrating the plan is actually used
Track, document and report incidents to the designated internal officials and to external authorities where required.
- Incident register with tracking and documentation per incident
- Defined internal officials and external reporting obligations
- Evidence of reports made within required timeframes
- External reporting obligations unidentified
- Incidents handled informally and never documented
- Reporting timeframes undefined so notifications are late
Test the organizational incident response capability to confirm it works.
- Incident response test or exercise records
- Defined test frequency and scenario scope
- Lessons learned and resulting plan updates
- Testing never performed or long lapsed
- Exercises run without capturing findings
- Findings identified but the plan never updated
Maintenance
Carry out maintenance on organizational systems, so the scheduled and corrective upkeep those systems require is actually performed and recorded.
- Maintenance schedule covering in scope systems
- Completed maintenance records showing work performed and by whom
- Evidence maintenance covers both routine and corrective work
- Maintenance performed but never recorded
- Only corrective repair occurs with no scheduled maintenance
- Systems in scope for CUI omitted from the maintenance regime
Place controls over the tools, techniques and mechanisms used for system maintenance, and over the personnel who carry it out.
- Approved maintenance tool inventory and control procedure
- Authorization records for maintenance personnel
- Evidence maintenance tools are checked before use
- Personnel controlled while tools are unmanaged
- Technicians bring unapproved diagnostic tools on site
- No authorization list for who may perform maintenance
Remove CUI from equipment by sanitization before that equipment leaves the organization for off site maintenance.
- Sanitization procedure for equipment leaving for maintenance
- Sanitization records tied to specific equipment
- Verification step confirming CUI removal
- Equipment sent to vendors without sanitization
- Sanitization claimed but not verified or recorded
- Embedded storage in peripherals overlooked
Scan media holding diagnostic and test programs for malicious code before that media is connected to organizational systems.
- Procedure requiring scanning of diagnostic media
- Scan records for media used during maintenance
- Control preventing unscanned media from being connected
- Vendor supplied media trusted without scanning
- Procedure exists but no evidence of scans performed
- Scanning applied to organizational media only
Authenticate nonlocal maintenance sessions opened across external networks using multiple factors, and close those sessions once the maintenance work finishes.
- Multifactor configuration for nonlocal maintenance access
- Records of maintenance session establishment and termination
- Procedure requiring termination at completion
- Vendor maintenance accounts exempt from multifactor
- Sessions left open after work completes
- Termination relies on the vendor rather than the organization
Supervise maintenance personnel who do not hold the access authorization normally required, for the duration of their work.
- Procedure requiring supervision of unauthorized maintenance personnel
- Supervision or escort records naming the supervisor
- Authorization status check performed before work begins
- Vendor technicians left unattended
- Escort recorded at entry but not throughout the work
- No check of whether the technician is authorized
Media Protection
Physically control and securely store system media holding CUI, in both paper and digital form.
- Media storage arrangements and physical security of storage locations
- Media inventory covering paper and digital media holding CUI
- Access records for media storage areas
- Digital media controlled while paper records are not
- Media stored in unsecured shared areas
- No inventory so media cannot be accounted for
Limit access to CUI held on system media to users authorized to see it.
- Authorization list for access to CUI bearing media
- Access control mechanism for media storage and digital media
- Records of access granted and revoked
- Access limited by physical location rather than by authorization
- Authorization not revoked when roles change
- Backup media accessible to general operations staff
Sanitize or destroy system media containing CUI before the media is disposed of or released for reuse.
- Sanitization and destruction procedure with approved methods
- Sanitization or destruction certificates and records
- Evidence the method matches the media type
- Reformatting treated as sanitization
- Disposal handled by a third party without certificates
- Reuse within the organization skips sanitization
Mark media with the CUI markings and distribution limitations that apply to its contents.
- Marking procedure defining required markings and limitations
- Sample marked media, paper and digital
- Evidence marking is applied at creation
- Marking applied to documents but not to the media itself
- Distribution limitations omitted from markings
- Legacy media unmarked with no remediation plan
Restrict who may access media holding CUI, and keep that media accounted for whenever it moves beyond controlled areas.
- Transport procedure including custody and accountability steps
- Transport logs recording media, custodian and destination
- Evidence of receipt confirmation at destination
- Media transported without a custody record
- Accountability ends when media leaves the site
- Courier arrangements unassessed
Apply cryptographic protection to CUI held on digital media during transport, unless equivalent alternative physical safeguards protect it instead.
- Encryption configuration for portable and transported digital media
- Evidence of encryption status for media in transit
- Documented alternative physical safeguards where encryption is not used
- Encryption assumed but not verified per device
- Alternative safeguards claimed without documentation
- Backup media shipped unencrypted
Govern which removable media may be used on system components, and enforce that restriction at the components themselves.
- Removable media policy defining permitted use
- Technical control over removable media ports and devices
- Records of approved exceptions
- Policy exists with no technical enforcement
- Control applied to storage devices but not to other removable media
- Exceptions granted without expiry
Prohibit the use of portable storage devices that have no identifiable owner.
- Policy prohibiting unidentified portable storage
- Technical control blocking unknown devices
- Awareness material communicating the prohibition
- Prohibition stated but any device still mounts
- Ownership identification process undefined
- Found devices connected to check contents
Protect the confidentiality of backup copies of CUI at the locations where those backups are stored.
- Backup inventory identifying which backups contain CUI
- Protection applied at backup storage locations, encryption or physical control
- Access controls and records for backup storage
- Production data protected while backups are not
- Offsite and cloud backup locations unassessed
- Backup encryption keys stored alongside the backups
Personnel Security
Screen individuals before authorizing their access to systems containing CUI.
- Screening criteria and procedure
- Screening records for individuals granted access
- Evidence screening precedes access authorization
- Access granted before screening completes
- Contractors and vendors exempt from screening
- Screening performed but not recorded
Protect systems containing CUI during and after personnel actions such as termination or transfer, including timely revocation of access.
- Termination and transfer procedure covering access revocation and asset return
- Records showing revocation timing against departure date
- Evidence credentials and property are recovered
- Revocation delayed well beyond departure
- Transfers leave accumulated access from the previous role
- Physical access and assets not recovered
Physical Protection
Limit physical access to systems, equipment and their operating environments to authorized individuals.
- Physical access authorization list for controlled areas
- Access control mechanism evidence such as badge system configuration
- Periodic review of who holds physical access
- Access lists not reviewed so departed staff retain badges
- Server and equipment areas within general office access
- Authorization granted verbally without record
Protect and monitor the physical facility and the support infrastructure that organizational systems depend on.
- Facility protection measures and monitoring arrangements
- Evidence support infrastructure such as power and cabling is protected
- Monitoring records or alarm and camera coverage evidence
- Facility monitored while support infrastructure is not
- Monitoring equipment installed but recordings unreviewed
- Shared or landlord controlled infrastructure unassessed
Escort visitors and monitor visitor activity while they are on site.
- Visitor procedure requiring escort and monitoring
- Visitor logs recording escort assignment
- Evidence monitoring continues for the visit duration
- Visitors signed in but not escorted
- Contractors treated as staff and left unescorted
- Escort recorded at entry only
Maintain audit logs recording physical access to facilities holding organizational systems.
- Physical access logs, electronic or manual
- Defined retention period for physical access records
- Evidence logs are reviewed
- Logs captured but never retained or reviewed
- Manual visitor books used with incomplete entries
- Badge system logs overwritten quickly
Control and manage physical access devices such as keys, locks, combinations and badge readers.
- Inventory of physical access devices and their holders
- Issue, return and change records for keys and combinations
- Evidence combinations and locks are changed on personnel change
- Keys issued with no inventory or return process
- Combinations never changed after staff departures
- Master keys uncontrolled
Enforce safeguarding measures for CUI at alternate work sites such as home or remote offices.
- Alternate work site policy defining required safeguards
- Evidence safeguards are communicated and acknowledged
- Assessment or attestation of alternate work site conditions
- Remote work policy silent on physical safeguards for CUI
- Safeguards defined but compliance never checked
- Printing and paper CUI at home not addressed
Risk Assessment
Periodically assess the risk that operating organizational systems, and processing, storing or transmitting CUI, creates for operations, assets and individuals.
- Risk assessment methodology and defined frequency
- Completed risk assessment covering CUI processing, storage and transmission
- Evidence results are communicated and used
- Assessment covers technology risk only, omitting mission and individual impact
- Performed once with no defined recurrence
- Results not linked to remediation decisions
Scan systems and applications for vulnerabilities periodically and again when new vulnerabilities affecting them are identified.
- Scan schedule and scope covering systems and applications
- Scan reports across the defined period
- Evidence of additional scanning triggered by new vulnerability information
- Infrastructure scanned while applications are not
- Scanning periodic only, with no trigger on new vulnerability disclosure
- Authenticated scanning not used so coverage is shallow
Remediate identified vulnerabilities in line with the priorities set by risk assessment.
- Remediation procedure with risk based timeframes
- Evidence of remediation against identified findings
- Records of accepted risk with approval where remediation is deferred
- Findings tracked but remediation timeframes undefined
- Prioritization by scanner severity alone, ignoring organizational risk
- Deferred items accepted without documented approval
Security Assessment
Assess the security controls in place periodically to determine whether they are effective as implemented.
- Assessment plan defining scope, method and frequency
- Completed assessment results per control
- Evidence assessments cover effectiveness and not just presence
- Assessment confirms a control exists without testing whether it works
- Scope excludes parts of the CUI environment
- No defined periodicity so assessments lapse
Develop and carry out plans of action that correct identified deficiencies and reduce or eliminate vulnerabilities.
- Plan of action and milestones with owners and target dates
- Evidence of progress and closure for completed items
- Linkage from assessment findings to plan entries
- Plan maintained as a static list with no progress
- Findings closed without evidence of correction
- Deficiencies identified but never entered into the plan
Monitor security controls continuously so their effectiveness is known on an ongoing basis rather than only at assessment time.
- Continuous monitoring strategy naming controls, metrics and frequency
- Monitoring output such as dashboards or periodic reports
- Records of action taken when monitoring shows degradation
- Monitoring limited to the annual assessment
- Metrics collected but not evaluated against expectations
- Degradation detected without follow up
Develop, document and periodically update a system security plan describing system boundaries, the operating environment, how each requirement is implemented, and connections to other systems.
- Current system security plan covering boundary, environment, implementation and interconnections
- Version history showing periodic update
- Approval record for the current version
- Plan describes intent rather than actual implementation
- Boundary and interconnections omitted or stale
- No defined update trigger or cadence
System and Communications Protection
Monitor, control and protect communications at the external boundary of the system and at key internal boundaries.
- Network architecture identifying external and key internal boundaries
- Boundary device configuration such as firewall and gateway rulesets
- Monitoring evidence at those boundaries
- External boundary protected while internal boundaries are flat
- Boundary devices configured but traffic not monitored
- Cloud and remote boundaries omitted from the architecture
Establish and manage the cryptographic keys used by cryptography employed in organizational systems, across their life cycle.
- Key management procedure covering generation, distribution, storage, rotation and destruction
- Key inventory and custodian assignments
- Evidence of key rotation and secure storage
- Keys generated and then never rotated or inventoried
- Private keys stored alongside the data they protect
- Key custodianship undefined so departures leave keys orphaned
Use FIPS validated cryptography wherever cryptography is relied on to protect the confidentiality of CUI.
- Inventory of cryptographic modules protecting CUI with validation certificate references
- Configuration evidence showing validated modules and approved modes in use
- Evidence non validated cryptography is not relied on for CUI
- Cryptography strong but not FIPS validated
- Validated module present but operated outside its approved mode
- Certificate references stale or covering a different version
Prohibit remote activation of collaborative computing devices such as cameras and microphones, and indicate to people present when such a device is in use.
- Policy prohibiting remote activation of collaborative devices
- Configuration preventing remote activation
- Evidence of an in use indicator visible to those present
- Prohibition stated with no technical enforcement
- Indicator absent on conference room equipment
- Conferencing software permitted to auto enable cameras or microphones
Define which mobile code technologies are permitted, enforce that decision, and keep mobile code use under observation.
- Policy defining acceptable and prohibited mobile code technologies
- Technical controls restricting mobile code execution
- Monitoring evidence for mobile code use
- Mobile code technologies undefined so the policy is unenforceable
- Controls applied at the browser only, ignoring documents and email
- Use controlled but never monitored
Govern how Voice over Internet Protocol technology may be used, and keep its use under observation once deployed.
- Policy governing permitted VoIP use
- VoIP configuration and access controls
- Monitoring records for VoIP usage
- VoIP deployed with no governing policy
- Voice network not segmented from data
- Usage unmonitored and default credentials retained
Protect the authenticity of communications sessions so a session cannot be hijacked or spoofed.
- Session authenticity mechanism configuration, for example session tokens and mutual authentication
- Evidence sessions are bound and validated
- Configuration preventing session fixation and reuse
- Confidentiality protected while session authenticity is not
- Session identifiers predictable or not regenerated after authentication
- Application sessions outside the assessed scope
Protect the confidentiality of CUI while it is at rest in storage.
- Inventory of locations where CUI is stored at rest
- Encryption or equivalent protection configuration at those locations
- Evidence of protection coverage including databases, file shares and endpoints
- Endpoint encryption in place while servers and shares are unprotected
- Storage locations for CUI never fully inventoried
- Cloud storage protection assumed from the provider without verification
Apply architectural design, software development techniques and systems engineering principles that promote effective information security.
- Documented security architecture and design principles
- Secure development standards applied to in house software
- Evidence principles are applied in design reviews
- Principles documented but absent from actual design decisions
- Secure development standards not applied to acquired or outsourced code
- No design review step in the development process
Separate user functionality from system management functionality so ordinary users are not presented with administrative interfaces.
- Evidence of separation between user and management interfaces
- Configuration restricting administrative interface exposure
- Architecture showing management plane separation
- Administrative consoles reachable from user networks
- Separation logical in name only with shared credentials
- Management interfaces exposed to the internet
Prevent information from being transferred, intentionally or unintentionally, between users through shared system resources.
- Configuration evidence for object reuse and memory or storage clearing
- Evidence of isolation between users in shared and virtualized environments
- Testing results showing residual data is not accessible
- Shared and virtualized environments assumed isolated without verification
- Temporary files and shared directories accessible across users
- Object reuse protections disabled for performance
Place publicly accessible system components on subnetworks that are physically or logically separated from internal networks.
- Network diagram showing the separated subnetwork for public components
- Firewall or routing configuration enforcing the separation
- Inventory of publicly accessible components
- Public facing servers residing on internal networks
- Separation exists but permissive rules allow broad internal access
- New public services deployed outside the segmented zone
Deny network communications traffic by default and permit only traffic explicitly allowed by exception.
- Firewall and access control lists showing a default deny posture
- Documented and approved exceptions with justification
- Review records for permitted exceptions
- Default deny at perimeter only while internal traffic is permit all
- Any to any rules present alongside the deny default
- Exceptions accumulated with no periodic review
Prevent a remote device from holding a connection to organizational systems while simultaneously connecting through another path to external network resources, the split tunneling case.
- VPN or remote client configuration disabling split tunneling
- Evidence the setting is enforced and not user changeable
- Coverage across all remote client platforms
- Split tunneling disabled by policy but user configurable
- Some client platforms or vendor clients still permit it
- Exceptions granted for bandwidth with no compensating control
Apply cryptographic protection to prevent unauthorized disclosure of CUI during transmission, unless alternative physical safeguards protect it instead.
- Transmission encryption configuration for CUI bearing paths
- Inventory of CUI transmission paths, internal and external
- Documented alternative physical safeguards where used
- External transmission encrypted while internal paths are clear
- Email carrying CUI sent without protection
- Alternative safeguards asserted without documentation
Terminate network connections when the associated session ends or after a defined period of inactivity.
- Defined inactivity period for connection termination
- Configuration on network devices and services implementing termination
- Evidence of termination occurring in logs
- Inactivity period undefined
- Termination applied to remote access only
- Long lived connections exempt without justification
System and Information Integrity
Identify system flaws, report them, and correct them within a timely period.
- Flaw identification sources and process
- Patch and remediation records with dates showing timeliness
- Defined timeframes for correction by severity
- Flaws identified but remediation timeframes undefined
- Patching covers operating systems only, omitting applications and firmware
- Reporting step absent so flaws are not tracked
Provide malicious code protection at the points in the system where such code is likely to enter or execute.
- Identification of designated protection locations, endpoints and gateways
- Malicious code protection deployment and coverage reporting
- Configuration showing protection is active
- Endpoints covered while email and web gateways are not
- Coverage gaps on servers and non standard platforms
- Protection installed but disabled or in passive mode
Monitor security alerts and advisories and take action in response to them.
- Subscriptions or sources for security alerts and advisories
- Records of alerts received and assessed
- Evidence of action taken in response
- Advisories received but never triaged
- No defined owner for monitoring advisories
- Action taken informally with no record
Keep malicious code protection mechanisms current by applying new releases as they are issued.
- Update configuration for signatures and engine versions
- Reporting showing current update status across the estate
- Evidence of remediation for out of date endpoints
- Signatures updated while the engine version lags
- Offline or infrequently connected devices left stale
- Update failures unmonitored
Run periodic scans of systems and real time scans of files arriving from external sources as those files are downloaded, opened or executed.
- Scheduled scan configuration and completion records
- Real time scanning configuration covering download, open and execute events
- Coverage reporting across in scope systems
- Periodic scanning enabled while real time scanning is off
- Real time scanning limited to downloads only
- Scan exclusions broad and unreviewed
Watch organizational systems, and both inbound and outbound traffic, for attacks and for indicators that an attack may be developing.
- Monitoring capability configuration covering inbound and outbound traffic
- Detection rules or signatures and their tuning records
- Records of detected events and the response taken
- Inbound traffic monitored while outbound is not
- Monitoring deployed but alerts unreviewed
- Encrypted traffic unmonitored with no compensating visibility
Define what constitutes authorized use of organizational systems, and identify use that falls outside that definition.
- Documented definition of authorized system use
- Monitoring or detection capability identifying use outside that definition
- Records of identified unauthorized use and the response
- Authorized use never defined so unauthorized use cannot be identified
- Detection focused on external attack while insider misuse is unaddressed
- Identified misuse not recorded or acted on
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.