Skip to content

    PCI DSS v4.0.1 to NIST SP 800-53 Rev 5 control mapping

    PCI DSS v4.0.1 maps to 326 NIST SP 800-53 controls in the source dataset. Every one is listed below, with the PCI DSS v4.0.1 controls that map to it.

    Shared NIST 800-53 controls
    326
    PCI DSS v4.0.1 controls involved
    317
    NIST 800-53 families touched
    20

    How this pairing is derived

    NIST SP 800-53 Rev 5 is the pivot this whole dataset is built on: every framework in it is mapped to NIST SP 800-53, which is what makes the other pairings on this site derivable at all. This page is the one case where nothing is derived. It lists the authored PCI DSS v4.0.1 to NIST SP 800-53 mapping itself, one row per NIST control, so the relationship on each row is the mapping the source states rather than an intersection inferred from two of them.

    Shared controls in full

    NIST SP 800-53 Rev 5 controls that PCI DSS v4.0.1 maps to, with the PCI DSS v4.0.1 controls that map to each one.
    NIST 800-53 controlFamilyPCI DSS v4.0.1 controls
    AC-1Policy and ProceduresACAccess Control1.1.1, 10.1.1, 11.1.1, 12.1, 12.1.1, 12.1.2, 12.1.3, 2.1.1, 3.1.1, 3.7.1, 3.7.2, 3.7.3, 3.7.5, 3.7.6, 3.7.7, 3.7.8, 4.1.1, 5.1.1, 6.1.1, 7.1, 7.1.1, 7.2, 7.2.1, 7.3, 7.3.1, 7.3.2, 7.3.3, 8.1, 8.1.1, 8.2, 8.3.3, 8.3.8, 8.5.1, 8.6.1, 9.1.1, A3.4
    AC-2Account ManagementACAccess Control11.2, 4.1, 4.2.1, 8.2.4, 8.2.5, 8.3.10, 8.6, 8.6.1
    AC-2(3)Disable AccountsACAccess Control8.2.6
    AC-2(5)Inactivity LogoutACAccess Control8.2.8
    AC-2(7)Privileged User AccountsACAccess Control1.3, 7.1, 7.2, 7.2.1, 7.2.2, 7.2.5, 7.3, 7.3.1, 7.3.2, 7.3.3
    AC-2(9)Restrictions on Use of Shared and Group AccountsACAccess Control8.2.2
    AC-2(12)Account Monitoring for Atypical UsageACAccess Control3.1, A3.2.6.1
    AC-2(13)Disable Accounts for High-risk IndividualsACAccess Control8.2.5
    AC-3Access EnforcementACAccess Control11.2, 4.1, 4.2.1, 7.2.1, 7.2.2, 7.2.5, 7.2.6
    AC-3(8)Revocation of Access AuthorizationsACAccess Control8.2.5
    AC-4Information Flow EnforcementACAccess Control1.1, 1.3, 1.3.1, 1.3.2, 1.4.2, 1.4.3
    AC-4(8)Security and Privacy Policy FiltersACAccess Control1.3.3
    AC-4(9)Human ReviewsACAccess Control1.2.7
    AC-4(21)Physical or Logical Separation of Information FlowsACAccess Control1.2.1, 1.2.3, 1.2.4, 1.2.5, 1.2.6, 1.2.7, 1.2.8, 1.3, 1.3.1, 1.3.2, 1.3.3, 1.4.1, 1.4.2, 11.4.5, 11.4.6, 12.5.2, A1.1.4, A3.2.1, A3.2.4
    AC-4(25)Data SanitizationACAccess Control10.5.1, 9.4.6, 9.4.7
    AC-5Separation of DutiesACAccess Control11.2, 4.1, 4.2.1, 6.5.4
    AC-6Least PrivilegeACAccess Control1.3, 3.4, 3.4.2, 7.1, 7.2, 7.2.1, 7.2.2, 7.2.5, 7.2.6, 7.3, 7.3.1, 7.3.2, 7.3.3, 8.6, 8.6.1
    AC-6(5)Privileged AccountsACAccess Control7.2.3
    AC-6(7)Review of User PrivilegesACAccess Control7.2.4, 7.2.5.1, A3.4.1
    AC-6(9)Log Use of Privileged FunctionsACAccess Control10.2.1.2
    AC-7Unsuccessful Logon AttemptsACAccess Control8.3.4
    AC-11Device LockACAccess Control8.2.8
    AC-12Session TerminationACAccess Control8.2.8
    AC-17Remote AccessACAccess Control12.8.1, 3.4.2, 7.2.5, 8.2.3, 8.2.7
    AC-17(6)Protection of Mechanism InformationACAccess Control12.8.1, 3.4.2, 7.2.5, 8.2.3, 8.2.7
    AC-18Wireless AccessACAccess Control11.2, 11.2.1, 11.2.2, 2.3, 2.3.1, 2.3.2, 4.2.1.2
    AC-18(1)Authentication and EncryptionACAccess Control1.3, 2.3.1, 2.3.2, 4.2.1
    AC-20(1)Limits on Authorized UseACAccess Control1.5.1
    AC-22Publicly Accessible ContentACAccess Control1.4.4
    AC-23Data Mining ProtectionACAccess Control6.5.5
    AT-1Policy and ProceduresATAwareness and Training1.1.1, 10.1.1, 11.1.1, 12.1, 12.1.1, 12.1.2, 12.1.3, 12.6, 12.6.1, 12.6.2, 12.6.3, 2.1.1, 3.1.1, 3.7.1, 3.7.2, 3.7.3, 3.7.5, 3.7.6, 3.7.7, 3.7.8, 4.1.1, 5.1.1, 6.1.1, 7.1.1, 8.1.1, 8.3.8, 9.1.1, 9.5.1, 9.5.1.3, A3.1.4
    AT-2Literacy Training and AwarenessATAwareness and Training12.6, 12.6.1, 12.6.3, 12.6.3.1, 8.3.8, 9.5.1, 9.5.1.3
    AT-2(3)Social Engineering and MiningATAwareness and Training12.6.3.1
    AT-2(4)Suspicious Communications and Anomalous System BehaviorATAwareness and Training11.5, 11.5.1, 11.5.1.1
    AT-2(5)Advanced Persistent ThreatATAwareness and Training11.5, 11.5.1, 11.5.1.1
    AT-2(6)Cyber Threat EnvironmentATAwareness and Training12.6.3, 12.6.3.1, 12.6.3.2, 9.5.1, 9.5.1.3
    AT-3Role-based TrainingATAwareness and Training1.1.2, 12.6, 12.6.1, 12.6.3, 12.6.3.1, 12.6.3.2, 6.2.2, 8.3.8, 9.5.1, 9.5.1.3
    AT-3(2)Physical Security ControlsATAwareness and Training1.1.2, 12.6, 12.6.1, 12.6.3, 12.6.3.1, 12.6.3.2, 6.2.2, 8.3.8, 9.5.1, 9.5.1.3
    AT-3(5)Processing Personally Identifiable InformationATAwareness and Training12.6.3.1, 12.6.3.2, 9.5.1, 9.5.1.3
    AT-4Training RecordsATAwareness and Training12.6, 12.6.1, 12.6.3
    AU-1Policy and ProceduresAUAudit and Accountability1.1.1, 10.1, 10.1.1, 10.4.3, 10.7, 10.7.1, 10.7.2, 10.7.3, 11.1.1, 12.1, 12.1.1, 12.1.2, 12.1.3, 2.1.1, 3.1.1, 3.7.1, 3.7.2, 3.7.3, 3.7.5, 3.7.6, 3.7.7, 3.7.8, 4.1.1, 5.1.1, 6.1.1, 7.1.1, 8.1.1, 8.3.8, 9.1.1, A3.3.1, A3.5
    AU-2Event LoggingAUAudit and Accountability10.3.3, 10.4, 10.4.1, 10.4.1.1, 10.4.2, 10.4.2.1, 10.4.3, 12.4.2
    AU-3Content of Audit RecordsAUAudit and Accountability10.2, 10.2.1, 10.2.1.1, 10.2.1.2, 10.2.1.3, 10.2.1.4, 10.2.1.5, 10.2.1.6, 10.2.1.7, 10.2.2, 6.4.2
    AU-4(1)Transfer to Alternate StorageAUAudit and Accountability10.3.3
    AU-5Response to Audit Logging Process FailuresAUAudit and AccountabilityA3.3.1
    AU-6Audit Record Review, Analysis, and ReportingAUAudit and Accountability10.3.3, 10.4, 10.4.1, 10.4.1.1
    AU-6(3)Correlate Audit Record RepositoriesAUAudit and Accountability10.4.1.1, 12.10.5
    AU-6(4)Central Review and AnalysisAUAudit and Accountability10.3.3, 10.4, 10.4.1, 10.4.1.1
    AU-6(8)Full Text Analysis of Privileged CommandsAUAudit and Accountability10.2.1.1, 10.2.1.2, 10.2.1.3, 10.2.1.4, 10.2.1.5, 10.2.1.6, 10.2.1.7
    AU-6(9)Correlation with Information from Nontechnical SourcesAUAudit and Accountability10.4.1.1, 12.10.5
    AU-8Time StampsAUAudit and Accountability10.2, 10.6, 10.6.1, 10.6.2, 10.6.3
    AU-9Protection of Audit InformationAUAudit and Accountability10.3, 10.3.1, 10.3.2
    AU-9(2)Store on Separate Physical Systems or ComponentsAUAudit and Accountability10.3.3
    AU-9(4)Access by Subset of Privileged UsersAUAudit and Accountability10.3, 10.3.1, 10.3.2
    AU-11Audit Record RetentionAUAudit and Accountability10.5, 10.5.1
    AU-12(1)System-wide and Time-correlated Audit TrailAUAudit and Accountability10.6, 10.6.1, 10.6.2, 10.6.3
    CA-1Policy and ProceduresCAAssessment, Authorization, and Monitoring1.1.1, 10.1.1, 11.1.1, 12.1, 12.1.1, 12.1.2, 12.1.3, 2.1.1, 3.1.1, 3.7.1, 3.7.2, 3.7.3, 3.7.5, 3.7.6, 3.7.7, 3.7.8, 4.1.1, 5.1.1, 6.1.1, 7.1.1, 8.1.1, 8.3.8, 9.1.1
    CA-2Control AssessmentsCAAssessment, Authorization, and Monitoring1.1, 1.2.7, 10.7, 10.7.1, 10.7.2, 10.7.3, 11.1, 12.4.2
    CA-7Continuous MonitoringCAAssessment, Authorization, and Monitoring10.7, 10.7.1, 10.7.2, 10.7.3
    CA-7(1)Independent AssessmentCAAssessment, Authorization, and Monitoring10.7, 10.7.1, 10.7.2, 10.7.3
    CA-8Penetration TestingCAAssessment, Authorization, and Monitoring11.4, 11.4.1, 11.4.2, 11.4.3, 11.4.4, 11.4.5, 11.4.6, 11.4.7, A3.2.4
    CA-8(1)Independent Penetration Testing Agent or TeamCAAssessment, Authorization, and Monitoring11.4.1, 11.4.2, 11.4.3, 11.4.5, 11.4.6
    CM-1Policy and ProceduresCMConfiguration Management1.1.1, 10.1.1, 11.1.1, 12.1, 12.1.1, 12.1.2, 12.1.3, 2.1, 2.1.1, 2.2, 3.1.1, 3.7.1, 3.7.2, 3.7.3, 3.7.5, 3.7.6, 3.7.7, 3.7.8, 4.1.1, 5.1.1, 6.1.1, 7.1.1, 8.1.1, 8.3.8, 8.5, 9.1.1
    CM-2Baseline ConfigurationCMConfiguration Management1.1, 1.2.1, 1.2.6, 10.2, 10.2.1, 10.2.1.1, 10.2.1.2, 10.2.1.3, 10.2.1.4, 10.2.1.5, 10.2.1.6, 10.2.1.7, 10.2.2, 10.6, 10.6.1, 10.6.2, 10.6.3, 11.2, 12.4.2, 2.2, 2.2.1, 8.3.2, 8.5
    CM-2(6)Development and Test EnvironmentsCMConfiguration Management6.5.6
    CM-2(7)Configure Systems and Components for High-risk AreasCMConfiguration Management1.2.1, 1.5, 1.5.1, 10.2, 10.2.1, 10.2.1.1, 10.2.1.2, 10.2.1.3, 10.2.1.4, 10.2.1.5, 10.2.1.6, 10.2.1.7, 10.2.2, 10.6, 10.6.1, 10.6.2, 10.6.3, 8.5
    CM-3Configuration Change ControlCMConfiguration Management1.2.2, 12.4.2, 6.5, 6.5.1, 6.5.2, 6.5.3, 6.5.6
    CM-3(1)Automated Documentation, Notification, and Prohibition of ChangesCMConfiguration Management1.2.2, 6.5, 6.5.1
    CM-3(2)Testing, Validation, and Documentation of ChangesCMConfiguration Management10.7.3, 6.5, 6.5.1, 6.5.2, A3.2.2.1
    CM-3(5)Automated Security ResponseCMConfiguration Management10.7
    CM-3(7)Review System ChangesCMConfiguration Management6.5, 6.5.1, 6.5.2, A3.2.2.1
    CM-4Impact AnalysesCMConfiguration Management6.5.2, 6.5.6, A3.2.2, A3.2.3
    CM-4(1)Separate Test EnvironmentsCMConfiguration Management6.5.3, 6.5.6
    CM-5Access Restrictions for ChangeCMConfiguration Management1.2.8
    CM-6Configuration SettingsCMConfiguration Management1.1, 1.2.1, 1.2.6, 10.2, 10.2.1, 10.2.1.1, 10.2.1.2, 10.2.1.3, 10.2.1.4, 10.2.1.5, 10.2.1.6, 10.2.1.7, 10.2.2, 10.6, 10.6.1, 10.6.2, 10.6.3, 11.2, 2.2, 2.2.1, 8.3.2, 8.5
    CM-6(2)Respond to Unauthorized ChangesCMConfiguration Management10.7, 10.7.1, 10.7.2, 10.7.3
    CM-7Least FunctionalityCMConfiguration Management1.2.5, 1.2.6, 1.4, 1.4.1, 1.4.2, 2.2.4
    CM-7(1)Periodic ReviewCMConfiguration Management1.2.7, 11.6.1, 12.3.1, 12.3.4, 12.4.2, 12.5.2, 12.5.2.1, 12.6.2, 12.6.3
    CM-7(6)Confined Environments with Limited PrivilegesCMConfiguration Management1.2.1, 1.5, 1.5.1, 10.2, 10.2.1, 10.2.1.1, 10.2.1.2, 10.2.1.3, 10.2.1.4, 10.2.1.5, 10.2.1.6, 10.2.1.7, 10.2.2, 10.6, 10.6.1, 10.6.2, 10.6.3, 8.5
    CM-7(7)Code Execution in Protected EnvironmentsCMConfiguration Management1.2.1, 1.5, 1.5.1, 10.2, 10.2.1, 10.2.1.1, 10.2.1.2, 10.2.1.3, 10.2.1.4, 10.2.1.5, 10.2.1.6, 10.2.1.7, 10.2.2, 10.6, 10.6.1, 10.6.2, 10.6.3, 8.5
    CM-7(9)Prohibiting The Use of Unauthorized HardwareCMConfiguration Management1.2.1, 1.5, 1.5.1, 10.2, 10.2.1, 10.2.1.1, 10.2.1.2, 10.2.1.3, 10.2.1.4, 10.2.1.5, 10.2.1.6, 10.2.1.7, 10.2.2, 10.6, 10.6.1, 10.6.2, 10.6.3, 8.5
    CM-8System Component InventoryCMConfiguration Management11.2, 11.2.2, 6.3.2, 9.5.1, 9.5.1.1
    CM-9Configuration Management PlanCMConfiguration Management2.1, 2.2, 8.5
    CM-9(1)Assignment of ResponsibilityCMConfiguration Management2.1
    CP-1Policy and ProceduresCPContingency Planning1.1.1, 10.1.1, 11.1.1, 12.1, 12.1.1, 12.1.2, 12.1.3, 2.1.1, 3.1.1, 3.7.1, 3.7.2, 3.7.3, 3.7.5, 3.7.6, 3.7.7, 3.7.8, 4.1.1, 5.1.1, 6.1.1, 7.1.1, 8.1.1, 8.3.8, 9.1.1
    CP-9System BackupCPContingency Planning12.10.1, 9.4.1.1, 9.4.1.2
    CP-9(3)Separate Storage for Critical InformationCPContingency Planning9.4.1.1
    IA-1Policy and ProceduresIAIdentification and Authentication1.1.1, 10.1.1, 11.1.1, 12.1, 12.1.1, 12.1.2, 12.1.3, 2.1.1, 3.1.1, 3.7.1, 3.7.2, 3.7.3, 3.7.5, 3.7.6, 3.7.7, 3.7.8, 4.1.1, 5.1.1, 6.1.1, 7.1, 7.1.1, 7.2, 7.2.1, 7.3, 7.3.1, 7.3.2, 7.3.3, 8.1, 8.1.1, 8.2, 8.3.3, 8.3.8, 8.5.1, 8.6.1, 9.1.1, A3.4
    IA-2Identification and Authentication (Organizational Users)IAIdentification and Authentication7.1, 7.2, 7.2.1, 7.3, 7.3.1, 7.3.2, 7.3.3, 8.1, 8.2, 8.3, 8.3.3, 8.3.9
    IA-2(1)Multi-factor Authentication to Privileged AccountsIAIdentification and Authentication8.2.3, 8.3.11, 8.4, 8.4.1, 8.4.2, 8.4.3, 8.5.1
    IA-2(2)Multi-factor Authentication to Non-privileged AccountsIAIdentification and Authentication8.2.3, 8.3.11, 8.4, 8.4.1, 8.4.2, 8.4.3, 8.5.1
    IA-2(5)Individual Authentication with Group AuthenticationIAIdentification and Authentication8.2.2
    IA-2(6)Access to Accounts —separate DeviceIAIdentification and Authentication8.4.2
    IA-2(8)Access to Accounts — Replay ResistantIAIdentification and Authentication8.5.1
    IA-4Identifier ManagementIAIdentification and Authentication8.2, 8.2.1
    IA-4(4)Identify User StatusIAIdentification and Authentication8.2, 8.2.1
    IA-5Authenticator ManagementIAIdentification and Authentication2.2.2, 2.3.1, 6.5.2, 8.2.4, 8.3, 8.3.1, 8.3.10.1, 8.3.11, 8.3.3, 8.3.5, 8.3.7, 8.3.9, 8.6.3
    IA-5(1)Password-based AuthenticationIAIdentification and Authentication8.2.4, 8.3, 8.3.1, 8.3.10.1, 8.3.11, 8.3.3, 8.3.5, 8.3.6, 8.3.7, 8.3.9, 8.6.3
    IA-5(2)Public Key-based AuthenticationIAIdentification and Authentication8.3.1, 8.3.11
    IA-5(5)Change Authenticators Prior to DeliveryIAIdentification and Authentication2.2.2, 2.3.1, 6.5.2
    IA-5(6)Protection of AuthenticatorsIAIdentification and Authentication8.3.11
    IA-5(7)No Embedded Unencrypted Static AuthenticatorsIAIdentification and Authentication8.6.2
    IA-7Cryptographic Module AuthenticationIAIdentification and Authentication2.2.7, 3.6.1.1, 3.6.1.2
    IA-8Identification and Authentication (Non-organizational Users)IAIdentification and Authentication7.2.1
    IA-8(2)Acceptance of External AuthenticatorsIAIdentification and Authentication8.2.3
    IA-9Service Identification and AuthenticationIAIdentification and Authentication8.2.3
    IA-11Re-authenticationIAIdentification and Authentication8.2.8
    IA-12Identity ProofingIAIdentification and Authentication8.3.3
    IA-12(4)In-person Validation and VerificationIAIdentification and Authentication7.2.3, 8.2.4, 8.3.5
    IR-1Policy and ProceduresIRIncident Response1.1.1, 10.1.1, 10.7, 10.7.1, 10.7.2, 10.7.3, 11.1.1, 12.1, 12.1.1, 12.1.2, 12.1.3, 12.10, 12.10.2, 12.10.6, 2.1.1, 3.1.1, 3.7.1, 3.7.2, 3.7.3, 3.7.5, 3.7.6, 3.7.7, 3.7.8, 4.1.1, 5.1.1, 6.1.1, 7.1.1, 8.1.1, 8.3.8, 9.1.1, A3.5
    IR-2Incident Response TrainingIRIncident Response12.10.4, 12.10.4.1
    IR-2(3)BreachIRIncident Response12.10.4, 12.10.4.1
    IR-3Incident Response TestingIRIncident Response12.10.2
    IR-4Incident HandlingIRIncident Response12.10, 12.10.5
    IR-4(3)Continuity of OperationsIRIncident Response12.10
    IR-4(4)Information CorrelationIRIncident Response10.3.3, 10.4, 10.4.1, 10.4.1.1, 12.10.5
    IR-4(5)Automatic Disabling of SystemIRIncident ResponseA3.2.6.1, A3.5
    IR-4(10)Supply Chain CoordinationIRIncident Response10.7, 10.7.1, 10.7.2, 10.7.3
    IR-4(11)Integrated Incident Response TeamIRIncident Response12.10.3
    IR-4(12)Malicious Code and Forensic AnalysisIRIncident Response12.10.6
    IR-4(13)Behavior AnalysisIRIncident Response3.1, A3.2.6.1
    IR-5Incident MonitoringIRIncident ResponseA3.3.1
    IR-6Incident ReportingIRIncident Response12.1.4, 12.10.1, A1.2.3
    IR-6(2)Vulnerabilities Related to IncidentsIRIncident Response12.10.6
    IR-8Incident Response PlanIRIncident Response12.10, 12.10.1, 12.10.5, 12.10.7
    IR-9Information Spillage ResponseIRIncident Response12.10.7, A3.2.5.2
    IR-9(3)Post-spill OperationsIRIncident Response12.10.7, A3.2.5.2
    MA-1Policy and ProceduresMAMaintenance1.1.1, 10.1.1, 11.1.1, 12.1, 12.1.1, 12.1.2, 12.1.3, 2.1.1, 3.1.1, 3.7.1, 3.7.2, 3.7.3, 3.7.5, 3.7.6, 3.7.7, 3.7.8, 4.1.1, 5.1.1, 6.1.1, 7.1.1, 8.1.1, 8.2.7, 8.3.8, 9.1.1
    MA-4Nonlocal MaintenanceMAMaintenance8.2.7
    MA-4(1)Logging and ReviewMAMaintenance8.2.7
    MA-4(6)Cryptographic ProtectionMAMaintenance2.2.7
    MA-4(7)Disconnect VerificationMAMaintenance8.2.7
    MA-6Timely MaintenanceMAMaintenance10.7, 11.3
    PE-1Policy and ProceduresPEPhysical and Environmental Protection1.1.1, 10.1.1, 11.1.1, 12.1, 12.1.1, 12.1.2, 12.1.3, 2.1.1, 3.1.1, 3.7.1, 3.7.2, 3.7.3, 3.7.5, 3.7.6, 3.7.7, 3.7.8, 4.1.1, 5.1.1, 6.1.1, 7.1.1, 8.1.1, 8.3.8, 9.1, 9.1.1, 9.2
    PE-2Physical Access AuthorizationsPEPhysical and Environmental Protection8.3.11, 9.1, 9.2, 9.2.1, 9.3, 9.3.1
    PE-2(1)Access by Position or RolePEPhysical and Environmental Protection8.3.11, 9.1, 9.2, 9.2.1, 9.3, 9.3.1, 9.3.1.1
    PE-2(2)Two Forms of IdentificationPEPhysical and Environmental Protection9.3.2
    PE-2(3)Restrict Unescorted AccessPEPhysical and Environmental Protection9.3.2
    PE-3Physical Access ControlPEPhysical and Environmental Protection9.1, 9.1.2, 9.2, 9.2.1
    PE-3(2)Facility and SystemsPEPhysical and Environmental Protection9.1, 9.1.2, 9.2, 9.2.1
    PE-3(3)Continuous GuardsPEPhysical and Environmental Protection9.1, 9.1.2, 9.2, 9.2.1
    PE-3(4)Lockable CasingsPEPhysical and Environmental Protection9.2.4
    PE-4Access Control for TransmissionPEPhysical and Environmental Protection9.2.2, 9.2.3
    PE-5Access Control for Output DevicesPEPhysical and Environmental Protection9.2.2, 9.2.3
    PE-6Monitoring Physical AccessPEPhysical and Environmental Protection9.2.1.1
    PE-6(1)Intrusion Alarms and Surveillance EquipmentPEPhysical and Environmental Protection9.2.1.1
    PE-6(4)Monitoring Physical Access to SystemsPEPhysical and Environmental Protection9.2.1.1
    PE-8Visitor Access RecordsPEPhysical and Environmental Protection9.2.1, 9.2.1.1
    PE-8(1)Automated Records Maintenance and ReviewPEPhysical and Environmental Protection9.3.4
    PE-8(3)Limit Personally Identifiable Information ElementsPEPhysical and Environmental Protection9.3.4
    PE-18Location of System ComponentsPEPhysical and Environmental Protection9.2.2, 9.2.3, 9.2.4
    PE-22Component MarkingPEPhysical and Environmental ProtectionA3.2.5
    PE-23Facility LocationPEPhysical and Environmental Protection12.5.2, 3.2.1, 9.1, 9.1.1, 9.2, 9.2.2, 9.2.3, 9.2.4
    PL-1Policy and ProceduresPLPlanning1.1.1, 10.1.1, 11.1.1, 12.1, 12.1.1, 12.1.2, 12.1.3, 12.4, 12.4.2, 2.1.1, 3.1.1, 3.7.1, 3.7.2, 3.7.3, 3.7.5, 3.7.6, 3.7.7, 3.7.8, 4.1.1, 5.1.1, 6.1.1, 6.2, 6.2.1, 7.1.1, 8.1.1, 8.3.8, 9.1.1, A3.1, A3.1.1
    PL-2System Security and Privacy PlansPLPlanning1.2.3, 1.2.4
    PL-4Rules of BehaviorPLPlanning12.1.3, 12.2, 12.2.1
    PL-8Security and Privacy ArchitecturesPLPlanning1.2
    PL-8(1)Defense in DepthPLPlanning1.2.1, 1.4.1
    PL-9Central ManagementPLPlanning1.1, 1.1.2, 10.1.2, 10.7, 10.7.1, 10.7.2, 10.7.3, 11.1.2, 12.1.3, 12.1.4, 12.4, 2.1.2, 3.1.2, 4.1.2, 5.1.2, 5.3.4, 6.1.2, 6.3, 6.3.1, 6.3.2, 6.3.3, 6.4, 6.4.1, 6.4.2, 6.4.3, 7.1.2, 8.1.2, 9.1.2, A3.1.1, A3.1.3
    PL-10Baseline SelectionPLPlanning1.1, 1.2.1, 1.2.6, 10.2, 10.2.1, 10.2.1.1, 10.2.1.2, 10.2.1.3, 10.2.1.4, 10.2.1.5, 10.2.1.6, 10.2.1.7, 10.2.2, 10.6, 10.6.1, 10.6.2, 10.6.3, 11.2, 2.2, 2.2.1, 8.3.2, 8.5
    RA-1Policy and ProceduresRARisk Assessment1.1.1, 10.1.1, 11.1.1, 12.1, 12.1.1, 12.1.2, 12.1.3, 12.3, 2.1.1, 3.1.1, 3.7.1, 3.7.2, 3.7.3, 3.7.5, 3.7.6, 3.7.7, 3.7.8, 4.1.1, 5.1.1, 6.1.1, 7.1.1, 8.1.1, 8.3.8, 9.1.1
    RA-2Security CategorizationRARisk Assessment9.4.2
    RA-3Risk AssessmentRARisk Assessment1.2.7, 10.7, 10.7.1, 10.7.2, 10.7.3, 11.1, 12.3, 12.3.1, 12.3.2, 12.4.2
    RA-5Vulnerability Monitoring and ScanningRARisk Assessment11.3, 11.3.1, 11.3.1.1, 11.3.1.2, 11.3.1.3, 11.3.2, 11.3.2.1, 6.4.1
    RA-5(2)Update Vulnerabilities to Be ScannedRARisk Assessment11.3.1
    RA-5(3)Breadth and Depth of CoverageRARisk Assessment11.3.1, 11.3.2.1
    RA-5(4)Discoverable InformationRARisk Assessment1.4.5
    RA-5(11)Public Disclosure ProgramRARisk Assessment6.3.1
    RA-7Risk ResponseRARisk Assessment10.7, 10.7.1, 10.7.2, 10.7.3
    RA-8Privacy Impact AssessmentsRARisk AssessmentA3.2.2
    RA-9Criticality AnalysisRARisk Assessment1.1
    SA-1Policy and ProceduresSASystem and Services Acquisition1.1.1, 10.1.1, 11.1.1, 12.1, 12.1.1, 12.1.2, 12.1.3, 2.1.1, 3.1.1, 3.7.1, 3.7.2, 3.7.3, 3.7.5, 3.7.6, 3.7.7, 3.7.8, 4.1.1, 5.1.1, 6.1.1, 6.2, 6.2.1, 6.2.4, 7.1.1, 8.1.1, 8.3.8, 9.1.1
    SA-3System Development Life CycleSASystem and Services Acquisition12.3.4
    SA-3(1)Manage Preproduction EnvironmentSASystem and Services Acquisition11.4.5, 11.4.6, 12.3.4, 6.5.3
    SA-3(2)Use of Live or Operational DataSASystem and Services Acquisition6.5.5
    SA-3(3)Technology RefreshSASystem and Services Acquisition12.3.4
    SA-4Acquisition ProcessSASystem and Services Acquisition12.8, 12.8.1, 12.9, 12.9.1, 12.9.2, 6.2, 6.2.1, 8.2.3, A2.1.3
    SA-4(1)Functional Properties of ControlsSASystem and Services Acquisition1.2.3, 1.2.4
    SA-4(2)Design and Implementation Information for ControlsSASystem and Services Acquisition1.2.3, 1.2.4
    SA-4(3)Development Methods, Techniques, and PracticesSASystem and Services Acquisition6.2, 6.2.1, 6.2.4
    SA-4(9)Functions, Ports, Protocols, and Services in UseSASystem and Services Acquisition1.2.4
    SA-4(12)Data OwnershipSASystem and Services Acquisition2.2.2, 2.2.4, 2.2.5, 6.5.2, 9.4.1
    SA-5System DocumentationSASystem and Services AcquisitionA3.2.5
    SA-8Security and Privacy Engineering PrinciplesSASystem and Services Acquisition1.1, 1.2, 1.2.1, 1.2.6, 10.2, 10.2.1, 10.2.1.1, 10.2.1.2, 10.2.1.3, 10.2.1.4, 10.2.1.5, 10.2.1.6, 10.2.1.7, 10.2.2, 10.6, 10.6.1, 10.6.2, 10.6.3, 11.2, 2.2, 2.2.1, 6.1, 6.2, 6.2.1, 8.3.2, 8.5, 8.5.1
    SA-8(14)Least PrivilegeSASystem and Services Acquisition1.3, 3.4, 3.4.2, 7.1, 7.2, 7.2.1, 7.2.2, 7.2.6, 7.3, 7.3.1, 7.3.2, 7.3.3, 8.6, 8.6.1
    SA-8(30)Procedural RigorSASystem and Services Acquisition12.3.4
    SA-8(31)Secure System ModificationSASystem and Services Acquisition1.2.2, 10.7.3, 12.4.2, 6.5, 6.5.1, 6.5.2, 6.5.6, A3.2.2.1
    SA-8(32)Sufficient DocumentationSASystem and Services Acquisition1.1.1, 10.1.1, 11.1.1, 2.1.1, 3.1.1, 3.7, 3.7.1, 3.7.2, 3.7.3, 3.7.5, 3.7.6, 3.7.7, 3.7.8, 4.1.1, 5.1.1, 6.1.1, 6.5.1, 7.1.1, 8.1.1, 8.3.8, 9.1.1, 9.3.2
    SA-8(33)MinimizationSASystem and Services Acquisition9.3.4
    SA-9External System ServicesSASystem and Services Acquisition12.8.2, 12.9, 12.9.1, 12.9.2, 8.2.3
    SA-9(1)Risk Assessments and Organizational ApprovalsSASystem and Services Acquisition12.8.3
    SA-9(2)Identification of Functions, Ports, Protocols, and ServicesSASystem and Services Acquisition1.2.5
    SA-9(3)Establish and Maintain Trust Relationship with ProvidersSASystem and Services Acquisition12.4.1, 12.8.2, 12.8.5, 12.9, 12.9.1, 12.9.2
    SA-9(5)Processing, Storage, and Service LocationSASystem and Services Acquisition12.5.2, 3.2.1
    SA-11Developer Testing and EvaluationSASystem and Services Acquisition6.2.3, 6.2.3.1, 6.2.4, 6.5.6
    SA-11(1)Static Code AnalysisSASystem and Services Acquisition6.2.4
    SA-11(2)Threat Modeling and Vulnerability AnalysesSASystem and Services Acquisition11.4.1, 11.4.4, 12.4.2.1, 6.2.1, 6.2.2, 6.2.3, 6.2.3.1, 6.2.4, 6.3.1, 6.4.1, 6.4.2, A1.2.3
    SA-11(5)Penetration TestingSASystem and Services Acquisition11.4, 11.4.1, 11.4.2, 11.4.3, 11.4.4, 11.4.5, 11.4.6, 11.4.7, 12.4.2.1, 6.2.1, 6.2.2, 6.2.3, 6.2.3.1, 6.2.4, 6.3.1, 6.4.1, 6.4.2, 6.5.6, A1.2.3, A3.2.4
    SA-11(6)Attack Surface ReviewsSASystem and Services Acquisition11.3.1, 11.3.1.1, 11.3.1.2, 11.3.1.3, 11.3.2, 11.3.2.1, 6.2.3, 6.2.3.1, 6.2.4, 6.3.1, 6.3.2, 6.5.6
    SA-11(7)Verify Scope of Testing and EvaluationSASystem and Services Acquisition11.3.1, 11.3.1.1, 11.3.1.2, 11.3.1.3, 11.3.2, 11.3.2.1, 6.2.3, 6.2.3.1, 6.2.4, 6.3.1, 6.3.2, 6.5.6
    SA-11(8)Dynamic Code AnalysisSASystem and Services Acquisition6.2.4
    SA-15Development Process, Standards, and ToolsSASystem and Services Acquisition6.2, 6.2.1, 6.2.4
    SA-15(5)Attack Surface ReductionSASystem and Services Acquisition1.1, 1.2, 1.2.1, 1.2.6, 10.2, 10.2.1, 10.2.1.1, 10.2.1.2, 10.2.1.3, 10.2.1.4, 10.2.1.5, 10.2.1.6, 10.2.1.7, 10.2.2, 10.6, 10.6.1, 10.6.2, 10.6.3, 11.2, 2.2, 2.2.1, 6.1, 6.2, 6.2.1, 8.3.2, 8.5, 8.5.1
    SA-17Developer Security and Privacy Architecture and DesignSASystem and Services Acquisition6.2, 6.2.1
    SA-21Developer ScreeningSASystem and Services Acquisition6.2.2
    SA-23SpecializationSASystem and Services Acquisition6.2, 6.2.1
    SC-1Policy and ProceduresSCSystem and Communications Protection1.1, 1.1.1, 1.2, 10.1.1, 11.1.1, 11.2.1, 12.1, 12.1.1, 12.1.2, 12.1.3, 2.1.1, 3.1.1, 3.7.1, 3.7.2, 3.7.3, 3.7.5, 3.7.6, 3.7.7, 3.7.8, 4.1.1, 5.1.1, 6.1, 6.1.1, 6.2, 6.2.1, 7.1.1, 8.1.1, 8.3.8, 8.5, 8.5.1, 9.1.1
    SC-3Security Function IsolationSCSystem and Communications Protection10.7.1, 11.4.5, 11.4.6, 2.2.3, 3.4.1
    SC-3(5)Layered StructuresSCSystem and Communications Protection1.2.1, 1.4.1
    SC-7Boundary ProtectionSCSystem and Communications Protection1.3.3, 1.4, 1.4.1, 1.4.2, 11.5.1
    SC-7(3)Access PointsSCSystem and Communications Protection1.4.2, 11.2.1
    SC-7(5)Deny by Default — Allow by ExceptionSCSystem and Communications Protection1.3, 1.3.1, 1.3.2, 1.3.3, 1.4.2
    SC-7(7)Split Tunneling for Remote DevicesSCSystem and Communications Protection1.5.1
    SC-7(9)Restrict Threatening Outgoing Communications TrafficSCSystem and Communications Protection1.3.3, 1.4, 1.4.1, 1.4.2, 11.5.1
    SC-7(10)Prevent ExfiltrationSCSystem and Communications Protection1.3.2, A3.2.6
    SC-7(11)Restrict Incoming Communications TrafficSCSystem and Communications Protection1.3, 1.3.1, 1.3.2, 1.3.3, 1.4, 1.4.1, 1.4.2, 11.5.1
    SC-7(12)Host-based ProtectionSCSystem and Communications Protection2.2.3
    SC-7(14)Protect Against Unauthorized Physical ConnectionsSCSystem and Communications Protection9.2.2, 9.2.3, 9.2.4
    SC-7(16)Prevent Discovery of System ComponentsSCSystem and Communications Protection1.4.5
    SC-7(17)Automated Enforcement of Protocol FormatsSCSystem and Communications Protection6.4, 6.4.1, 6.4.2
    SC-7(18)Fail SecureSCSystem and Communications Protection1.2, 6.1, 6.2, 6.2.1, 8.5, 8.5.1
    SC-7(21)Isolation of System ComponentsSCSystem and Communications Protection1.3.3
    SC-7(22)Separate Subnets for Connecting to Different Security DomainsSCSystem and Communications Protection1.4, 1.4.1
    SC-7(27)Unclassified Non-national Security System ConnectionsSCSystem and Communications Protection1.4.4
    SC-7(29)Separate Subnets to Isolate FunctionsSCSystem and Communications Protection1.4, 1.4.1
    SC-8Transmission Confidentiality and IntegritySCSystem and Communications Protection3.7.5, 4.2, 4.2.1, 4.2.1.2, 8.3.2, A2.1, A2.1.1, A2.1.2
    SC-8(1)Cryptographic ProtectionSCSystem and Communications Protection12.3.3, 2.2.7, 3.3.2, 4.2, 4.2.1, 4.2.1.2, 8.3.2, A2.1, A2.1.1, A2.1.2
    SC-8(2)Pre- and Post-transmission HandlingSCSystem and Communications Protection12.3.3, 2.2.7, 3.3.2, 8.3.2
    SC-10Network DisconnectSCSystem and Communications Protection8.2.8
    SC-12(1)AvailabilitySCSystem and Communications Protection2.3.2, 3.6.1, 3.7.5
    SC-13Cryptographic ProtectionSCSystem and Communications Protection12.3.3, 2.2.7, 3.3.2, 3.5, 3.5.1.2, 3.5.1.3, 8.3.2, 9.4
    SC-16(1)Integrity VerificationSCSystem and Communications Protection3.7.5
    SC-18(1)Identify Unacceptable Code and Take Corrective ActionsSCSystem and Communications Protection11.3, 11.3.1, 11.3.1.1, 11.3.1.2, 11.3.1.3, 11.3.2, 11.3.2.1, 6.3.3
    SC-23Session AuthenticitySCSystem and Communications Protection1.4.1
    SC-28Protection of Information at RestSCSystem and Communications Protection1.5, 1.5.1, 3.3.2, 3.5, 3.5.1.2, 3.5.1.3, 8.3.2, 9.4
    SC-28(1)Cryptographic ProtectionSCSystem and Communications Protection3.3.2, 3.5, 3.5.1.2, 3.5.1.3, 3.7.5, 8.3.2, 9.4
    SC-28(2)Offline StorageSCSystem and Communications Protection12.10.1, 9.4.1.1, 9.4.1.2
    SC-28(3)Cryptographic KeysSCSystem and Communications Protection3.5.1.1, 3.6, 3.6.1, 3.6.1.1, 3.6.1.2, 3.6.1.3, 3.6.1.4, 3.7, 3.7.1, 3.7.2, 3.7.3, 3.7.4, 3.7.5, 3.7.6, 3.7.7, 4.2.1.1
    SC-31Covert Channel AnalysisSCSystem and Communications Protection11.5.1.1
    SC-38Operations SecuritySCSystem and Communications Protection1.1.1, 10.1.1, 11.1.1, 2.1.1, 3.1.1, 4.1.1, 5.1.1, 6.1.1, 7.1.1, 8.1.1, 8.3.8, 9.1.1, 9.3.2
    SC-40Wireless Link ProtectionSCSystem and Communications Protection1.2.3, 1.3.3, 11.2, 11.2.1, 11.2.2, 12.10.1, 12.10.5, 2.3, 2.3.1, 2.3.2, 4.2.1.2
    SC-45System Time SynchronizationSCSystem and Communications Protection10.6, 10.6.1, 10.6.2, 10.6.3
    SC-45(1)Synchronization with Authoritative Time SourceSCSystem and Communications Protection10.6, 10.6.1, 10.6.2, 10.6.3
    SC-48Sensor RelocationSCSystem and Communications Protection10.4, 10.4.1, 10.4.1.1
    SI-1Policy and ProceduresSISystem and Information Integrity1.1.1, 1.2, 10.1.1, 11.1.1, 12.1, 12.1.1, 12.1.2, 12.1.3, 2.1.1, 3.1.1, 3.7.1, 3.7.2, 3.7.3, 3.7.5, 3.7.6, 3.7.7, 3.7.8, 4.1.1, 5.1.1, 6.1, 6.1.1, 6.2, 6.2.1, 7.1.1, 8.1.1, 8.3.8, 8.5, 8.5.1, 9.1.1
    SI-2Flaw RemediationSISystem and Information Integrity11.3, 5.3, 5.3.1, 6.3, 6.3.1, 6.3.3
    SI-2(4)Automated Patch Management ToolsSISystem and Information Integrity6.3, 6.3.1, 6.3.2, 6.3.3, 6.4, 6.4.1, 6.4.2, 6.4.3
    SI-3Malicious Code ProtectionSISystem and Information Integrity11.2, 11.3, 4.1, 4.2.1, 5.2, 5.2.1, 5.2.2, 5.3, 5.3.1, 5.3.2, 5.3.2.1, 5.3.3, 5.3.4, 5.3.5, 6.3, 6.3.1, 6.3.3
    SI-4System MonitoringSISystem and Information Integrity10.1, 10.3.3, 10.4, 10.4.1, 10.4.1.1, 10.4.3, 10.7, 10.7.1, 10.7.2, 10.7.3, 11.2, 4.1, 4.2.1, A3.3.1, A3.5
    SI-4(1)System-wide Intrusion Detection SystemSISystem and Information Integrity1.4.3, 11.5, 11.5.1, 11.5.1.1
    SI-4(2)Automated Tools and Mechanisms for Real-time AnalysisSISystem and Information Integrity10.4, 10.4.1, 10.4.1.1
    SI-4(5)System-generated AlertsSISystem and Information Integrity10.2, 10.4, 10.4.1, 10.4.1.1, 10.4.3, 10.7, 10.7.1, 10.7.2, 10.7.3
    SI-4(7)Automated Response to Suspicious EventsSISystem and Information IntegrityA3.2.6.1, A3.5
    SI-4(9)Testing of Monitoring Tools and MechanismsSISystem and Information Integrity12.10.2
    SI-4(11)Analyze Communications Traffic AnomaliesSISystem and Information Integrity3.1, A3.2.6.1
    SI-4(12)Automated Organization-generated AlertsSISystem and Information IntegrityA3.2.6.1
    SI-4(14)Wireless Intrusion DetectionSISystem and Information Integrity11.2
    SI-4(15)Wireless to Wireline CommunicationsSISystem and Information Integrity1.4.3, 11.2
    SI-4(16)Correlate Monitoring InformationSISystem and Information Integrity10.4.1.1, 12.10.5
    SI-4(18)Analyze Traffic and Covert ExfiltrationSISystem and Information Integrity11.5.1.1, A3.2.6
    SI-4(24)Indicators of CompromiseSISystem and Information Integrity10.3.4, 10.4, 11.5, 11.5.2, 11.6.1
    SI-4(25)Optimize Network Traffic AnalysisSISystem and Information Integrity1.4.2, 1.4.3, 11.2.1, 11.5, 11.5.1, 11.5.1.1
    SI-5Security Alerts, Advisories, and DirectivesSISystem and Information Integrity11.2, 4.1, 4.2.1, 6.3.1
    SI-5(1)Automated Alerts and AdvisoriesSISystem and Information Integrity6.3.1
    SI-6Security and Privacy Function VerificationSISystem and Information Integrity10.7.3, 6.5.2, A3.2.2.1
    SI-6(3)Report Verification ResultsSISystem and Information Integrity6.5.2
    SI-7Software, Firmware, and Information IntegritySISystem and Information Integrity10.3.4, 11.2, 11.5, 11.5.2, 11.6.1, 4.1, 4.2.1
    SI-7(6)Cryptographic ProtectionSISystem and Information Integrity12.3.3, 2.2.7, 3.3.2, 8.3.2
    SI-7(7)Integration of Detection and ResponseSISystem and Information Integrity10.7, 10.7.1, 10.7.2, 10.7.3
    SI-8Spam ProtectionSISystem and Information Integrity5.4, 5.4.1
    SI-10Information Input ValidationSISystem and Information Integrity11.2, 4.1, 4.2.1
    SI-12Information Management and RetentionSISystem and Information Integrity10.5, 10.5.1, 11.4.1, 3.2, 3.2.1, 9.4.6, 9.4.7
    SI-12(1)Limit Personally Identifiable Information ElementsSISystem and Information Integrity6.5.5
    SI-12(2)Minimize Personally Identifiable Information in Testing, Training, and ResearchSISystem and Information Integrity6.5.5
    SI-12(3)Information DisposalSISystem and Information Integrity10.5.1, 9.4.6, 9.4.7
    SI-19(4)Removal, Masking, Encryption, Hashing, or Replacement of Direct IdentifiersSISystem and Information Integrity3.4.1
    MP-1Policy and ProceduresMPMedia Protection1.1.1, 10.1.1, 11.1.1, 12.1, 12.1.1, 12.1.2, 12.1.3, 2.1.1, 3.1.1, 3.7.1, 3.7.2, 3.7.3, 3.7.5, 3.7.6, 3.7.7, 3.7.8, 4.1.1, 5.1.1, 6.1.1, 7.1.1, 8.1.1, 8.3.8, 9.1.1, 9.4, 9.4.1
    MP-2Media AccessMPMedia Protection1.5, 1.5.1, 5.1
    MP-4Media StorageMPMedia Protection9.1, 9.4, 9.4.1, 9.4.1.2
    MP-5Media TransportMPMedia Protection9.4, 9.4.3
    MP-5(3)CustodiansMPMedia Protection9.4.3
    MP-6Media SanitizationMPMedia Protection9.4, 9.4.6, 9.4.7
    MP-6(1)Review, Approve, Track, Document, and VerifyMPMedia Protection9.4.7
    MP-6(3)Nondestructive TechniquesMPMedia Protection9.4.7
    MP-7Media UseMPMedia Protection10.5, 10.5.1, 11.4.1, 3.2, 3.2.1, 9.4.6, 9.4.7
    PS-1Policy and ProceduresPSPersonnel Security1.1.1, 10.1.1, 11.1.1, 12.1, 12.1.1, 12.1.2, 12.1.3, 12.2, 12.2.1, 12.7, 12.7.1, 2.1.1, 3.1.1, 3.7.1, 3.7.2, 3.7.3, 3.7.5, 3.7.6, 3.7.7, 3.7.8, 4.1.1, 5.1.1, 6.1.1, 7.1.1, 8.1.1, 8.3.8, 9.1.1
    PS-2Position Risk DesignationPSPersonnel Security12.7, 12.7.1, 6.2.2
    PS-3Personnel ScreeningPSPersonnel Security12.7, 12.7.1
    PS-3(1)Classified InformationPSPersonnel Security12.7, 12.7.1
    PS-3(3)Information Requiring Special Protective MeasuresPSPersonnel Security12.7, 12.7.1
    PS-4Personnel TerminationPSPersonnel Security8.2.5
    PS-9Position DescriptionsPSPersonnel Security1.1.2, 10.1.2, 11.1.2, 12.1.3, 12.10.1, 2.1.2, 3.1.2, 3.7.8, 4.1.2, 5.1.2, 6.1.2, 7.1.2, 8.1.2, 9.1.2, A3.1.3
    PM-1Information Security Program PlanPMProgram Management1.1.1, 10.1.1, 11.1.1, 12.1, 12.1.1, 12.1.2, 12.1.3, 12.4, 2.1.1, 3.1.1, 3.7.1, 3.7.2, 3.7.3, 3.7.5, 3.7.6, 3.7.7, 3.7.8, 4.1.1, 5.1.1, 6.1.1, 7.1.1, 8.1.1, 8.3.8, 9.1.1, A3.1.2
    PM-2Information Security Program Leadership RolePMProgram Management1.1.2, 10.1.2, 11.1.2, 12.1.3, 12.1.4, 12.4, 2.1.2, 3.1.2, 4.1.2, 5.1.2, 6.1.2, 7.1.2, 8.1.2, 9.1.2, A3.1.1, A3.1.3
    PM-4Plan of Action and Milestones ProcessPMProgram Management11.3, 11.3.1, 11.3.1.1, 11.3.1.2, 11.3.1.3, 11.3.2, 11.3.2.1
    PM-5System InventoryPMProgram Management11.2, 11.2.2, 6.3.2, 9.5.1, 9.5.1.1
    PM-5(1)Inventory of Personally Identifiable InformationPMProgram Management12.5.1
    PM-6Measures of PerformancePMProgram Management1.1.2, 10.1.2, 11.1.2, 12.1.3, 12.1.4, 12.4, 2.1.2, 3.1.2, 4.1.2, 5.1.2, 6.1.2, 7.1.2, 8.1.2, 9.1.2, A3.1.1, A3.1.3
    PM-7Enterprise ArchitecturePMProgram Management1.2
    PM-8Critical Infrastructure PlanPMProgram Management12.4, 12.4.2, A3.1, A3.1.1
    PM-9Risk Management StrategyPMProgram Management12.3
    PM-13Security and Privacy WorkforcePMProgram Management1.1.2, 10.1.2, 11.1.2, 12.1.3, 12.10.1, 12.6, 12.6.1, 12.6.2, 12.6.3, 2.1.2, 3.1.2, 3.7.8, 4.1.2, 5.1.2, 6.1.2, 7.1.2, 8.1.2, 8.3.8, 9.1.2, 9.5.1, 9.5.1.3, A3.1.3, A3.1.4
    PM-14Testing, Training, and MonitoringPMProgram Management10.7, 10.7.1, 10.7.2, 10.7.3, A3.1.4
    PM-15Security and Privacy Groups and AssociationsPMProgram Management6.3, 6.3.1, A3.5.1
    PM-16Threat Awareness ProgramPMProgram Management6.3, A3.5.1
    PM-16(1)Automated Means for Sharing Threat IntelligencePMProgram Management6.3.1
    PM-23Data Governance BodyPMProgram ManagementA3.2.5
    PM-24Data Integrity BoardPMProgram ManagementA3.2.5
    PM-25Minimization of Personally Identifiable Information Used in Testing, Training, and ResearchPMProgram Management6.5.5, 9.3.4
    PM-28Risk FramingPMProgram Management12.3.1, 12.3.2
    PM-29Risk Management Program Leadership RolesPMProgram Management1.1.2, 10.1.2, 11.1.2, 12.1.3, 12.1.4, 12.3, 12.4, 2.1.2, 3.1.2, 4.1.2, 5.1.2, 6.1.2, 7.1.2, 8.1.2, 9.1.2, A3.1.1, A3.1.3
    PM-31Continuous Monitoring StrategyPMProgram Management10.1, 10.4.3, 10.7, 10.7.1, 10.7.2, 10.7.3, A3.3.1, A3.5
    PT-1Policy and ProceduresPTPII Processing and Transparency1.1.1, 1.2, 10.1.1, 11.1.1, 12.1, 12.1.1, 12.1.2, 12.1.3, 2.1.1, 3.1.1, 3.7.1, 3.7.2, 3.7.3, 3.7.5, 3.7.6, 3.7.7, 3.7.8, 4.1.1, 5.1.1, 6.1, 6.1.1, 6.2, 6.2.1, 7.1.1, 8.1.1, 8.3.8, 8.5, 8.5.1, 9.1.1
    PT-2Authority to Process Personally Identifiable InformationPTPII Processing and Transparency6.5.5
    PT-3Personally Identifiable Information Processing PurposesPTPII Processing and Transparency6.5.5
    PT-7Specific Categories of Personally Identifiable InformationPTPII Processing and Transparency6.5.5
    SR-1Policy and ProceduresSRSupply Chain Risk Management1.1.1, 10.1.1, 11.1.1, 12.1, 12.1.1, 12.1.2, 12.1.3, 12.8, 12.8.1, 12.9, 12.9.1, 12.9.2, 2.1.1, 3.1.1, 3.7.1, 3.7.2, 3.7.3, 3.7.5, 3.7.6, 3.7.7, 3.7.8, 4.1.1, 5.1.1, 6.1.1, 7.1.1, 8.1.1, 8.2.3, 8.3.8, 9.1.1, A2.1.3
    SR-3(1)Diverse Supply BaseSRSupply Chain Risk Management6.2, 6.2.1
    SR-3(3)Sub-tier Flow DownSRSupply Chain Risk Management12.4.2, 12.4.2.1, 12.8.2, 12.8.5, 12.9, 12.9.1, 12.9.2, 8.2.3
    SR-6Supplier Assessments and ReviewsSRSupply Chain Risk Management12.4.2, 12.4.2.1, 12.8.4
    SR-6(1)Testing and AnalysisSRSupply Chain Risk Management12.4.2, 12.4.2.1, 12.8.4
    SR-7Supply Chain Operations SecuritySRSupply Chain Risk Management1.1.1, 10.1.1, 11.1.1, 2.1.1, 3.1.1, 4.1.1, 5.1.1, 6.1.1, 7.1.1, 8.1.1, 8.3.8, 9.1.1, 9.3.2
    SR-9Tamper Resistance and DetectionSRSupply Chain Risk Management9.5.1
    SR-9(1)Multiple Stages of System Development Life CycleSRSupply Chain Risk Management9.5.1
    SR-10Inspection of Systems or ComponentsSRSupply Chain Risk Management9.5.1, 9.5.1.2
    SR-12Component DisposalSRSupply Chain Risk Management9.4.7

    Source and method

    Derived from the Top Floor framework mapping dataset: 4,123 cross-framework control mappings across 19 frameworks, every one pivoted through NIST SP 800-53 Rev 5.

    Cross-framework mappings on this page are derived from the 2026.2 release of the Secure Controls Framework, used under CC BY-ND 4.0.

    Mappings are illustrative aids for planning and are not a substitute for the official text of any framework or for an assessor’s judgment. Always verify control requirements against the authoritative publication. Where no official crosswalk exists, the mapping judgment is our own analysis.