PCI DSS v4.0.1 to NIST SP 800-53 Rev 5 control mapping
PCI DSS v4.0.1 maps to 326 NIST SP 800-53 controls in the source dataset. Every one is listed below, with the PCI DSS v4.0.1 controls that map to it.
- Shared NIST 800-53 controls
- 326
- PCI DSS v4.0.1 controls involved
- 317
- NIST 800-53 families touched
- 20
How this pairing is derived
NIST SP 800-53 Rev 5 is the pivot this whole dataset is built on: every framework in it is mapped to NIST SP 800-53, which is what makes the other pairings on this site derivable at all. This page is the one case where nothing is derived. It lists the authored PCI DSS v4.0.1 to NIST SP 800-53 mapping itself, one row per NIST control, so the relationship on each row is the mapping the source states rather than an intersection inferred from two of them.
Shared controls in full
| NIST 800-53 control | Family | PCI DSS v4.0.1 controls |
|---|---|---|
| AC-1Policy and Procedures | ACAccess Control | 1.1.1, 10.1.1, 11.1.1, 12.1, 12.1.1, 12.1.2, 12.1.3, 2.1.1, 3.1.1, 3.7.1, 3.7.2, 3.7.3, 3.7.5, 3.7.6, 3.7.7, 3.7.8, 4.1.1, 5.1.1, 6.1.1, 7.1, 7.1.1, 7.2, 7.2.1, 7.3, 7.3.1, 7.3.2, 7.3.3, 8.1, 8.1.1, 8.2, 8.3.3, 8.3.8, 8.5.1, 8.6.1, 9.1.1, A3.4 |
| AC-2Account Management | ACAccess Control | 11.2, 4.1, 4.2.1, 8.2.4, 8.2.5, 8.3.10, 8.6, 8.6.1 |
| AC-2(3)Disable Accounts | ACAccess Control | 8.2.6 |
| AC-2(5)Inactivity Logout | ACAccess Control | 8.2.8 |
| AC-2(7)Privileged User Accounts | ACAccess Control | 1.3, 7.1, 7.2, 7.2.1, 7.2.2, 7.2.5, 7.3, 7.3.1, 7.3.2, 7.3.3 |
| AC-2(9)Restrictions on Use of Shared and Group Accounts | ACAccess Control | 8.2.2 |
| AC-2(12)Account Monitoring for Atypical Usage | ACAccess Control | 3.1, A3.2.6.1 |
| AC-2(13)Disable Accounts for High-risk Individuals | ACAccess Control | 8.2.5 |
| AC-3Access Enforcement | ACAccess Control | 11.2, 4.1, 4.2.1, 7.2.1, 7.2.2, 7.2.5, 7.2.6 |
| AC-3(8)Revocation of Access Authorizations | ACAccess Control | 8.2.5 |
| AC-4Information Flow Enforcement | ACAccess Control | 1.1, 1.3, 1.3.1, 1.3.2, 1.4.2, 1.4.3 |
| AC-4(8)Security and Privacy Policy Filters | ACAccess Control | 1.3.3 |
| AC-4(9)Human Reviews | ACAccess Control | 1.2.7 |
| AC-4(21)Physical or Logical Separation of Information Flows | ACAccess Control | 1.2.1, 1.2.3, 1.2.4, 1.2.5, 1.2.6, 1.2.7, 1.2.8, 1.3, 1.3.1, 1.3.2, 1.3.3, 1.4.1, 1.4.2, 11.4.5, 11.4.6, 12.5.2, A1.1.4, A3.2.1, A3.2.4 |
| AC-4(25)Data Sanitization | ACAccess Control | 10.5.1, 9.4.6, 9.4.7 |
| AC-5Separation of Duties | ACAccess Control | 11.2, 4.1, 4.2.1, 6.5.4 |
| AC-6Least Privilege | ACAccess Control | 1.3, 3.4, 3.4.2, 7.1, 7.2, 7.2.1, 7.2.2, 7.2.5, 7.2.6, 7.3, 7.3.1, 7.3.2, 7.3.3, 8.6, 8.6.1 |
| AC-6(5)Privileged Accounts | ACAccess Control | 7.2.3 |
| AC-6(7)Review of User Privileges | ACAccess Control | 7.2.4, 7.2.5.1, A3.4.1 |
| AC-6(9)Log Use of Privileged Functions | ACAccess Control | 10.2.1.2 |
| AC-7Unsuccessful Logon Attempts | ACAccess Control | 8.3.4 |
| AC-11Device Lock | ACAccess Control | 8.2.8 |
| AC-12Session Termination | ACAccess Control | 8.2.8 |
| AC-17Remote Access | ACAccess Control | 12.8.1, 3.4.2, 7.2.5, 8.2.3, 8.2.7 |
| AC-17(6)Protection of Mechanism Information | ACAccess Control | 12.8.1, 3.4.2, 7.2.5, 8.2.3, 8.2.7 |
| AC-18Wireless Access | ACAccess Control | 11.2, 11.2.1, 11.2.2, 2.3, 2.3.1, 2.3.2, 4.2.1.2 |
| AC-18(1)Authentication and Encryption | ACAccess Control | 1.3, 2.3.1, 2.3.2, 4.2.1 |
| AC-20(1)Limits on Authorized Use | ACAccess Control | 1.5.1 |
| AC-22Publicly Accessible Content | ACAccess Control | 1.4.4 |
| AC-23Data Mining Protection | ACAccess Control | 6.5.5 |
| AT-1Policy and Procedures | ATAwareness and Training | 1.1.1, 10.1.1, 11.1.1, 12.1, 12.1.1, 12.1.2, 12.1.3, 12.6, 12.6.1, 12.6.2, 12.6.3, 2.1.1, 3.1.1, 3.7.1, 3.7.2, 3.7.3, 3.7.5, 3.7.6, 3.7.7, 3.7.8, 4.1.1, 5.1.1, 6.1.1, 7.1.1, 8.1.1, 8.3.8, 9.1.1, 9.5.1, 9.5.1.3, A3.1.4 |
| AT-2Literacy Training and Awareness | ATAwareness and Training | 12.6, 12.6.1, 12.6.3, 12.6.3.1, 8.3.8, 9.5.1, 9.5.1.3 |
| AT-2(3)Social Engineering and Mining | ATAwareness and Training | 12.6.3.1 |
| AT-2(4)Suspicious Communications and Anomalous System Behavior | ATAwareness and Training | 11.5, 11.5.1, 11.5.1.1 |
| AT-2(5)Advanced Persistent Threat | ATAwareness and Training | 11.5, 11.5.1, 11.5.1.1 |
| AT-2(6)Cyber Threat Environment | ATAwareness and Training | 12.6.3, 12.6.3.1, 12.6.3.2, 9.5.1, 9.5.1.3 |
| AT-3Role-based Training | ATAwareness and Training | 1.1.2, 12.6, 12.6.1, 12.6.3, 12.6.3.1, 12.6.3.2, 6.2.2, 8.3.8, 9.5.1, 9.5.1.3 |
| AT-3(2)Physical Security Controls | ATAwareness and Training | 1.1.2, 12.6, 12.6.1, 12.6.3, 12.6.3.1, 12.6.3.2, 6.2.2, 8.3.8, 9.5.1, 9.5.1.3 |
| AT-3(5)Processing Personally Identifiable Information | ATAwareness and Training | 12.6.3.1, 12.6.3.2, 9.5.1, 9.5.1.3 |
| AT-4Training Records | ATAwareness and Training | 12.6, 12.6.1, 12.6.3 |
| AU-1Policy and Procedures | AUAudit and Accountability | 1.1.1, 10.1, 10.1.1, 10.4.3, 10.7, 10.7.1, 10.7.2, 10.7.3, 11.1.1, 12.1, 12.1.1, 12.1.2, 12.1.3, 2.1.1, 3.1.1, 3.7.1, 3.7.2, 3.7.3, 3.7.5, 3.7.6, 3.7.7, 3.7.8, 4.1.1, 5.1.1, 6.1.1, 7.1.1, 8.1.1, 8.3.8, 9.1.1, A3.3.1, A3.5 |
| AU-2Event Logging | AUAudit and Accountability | 10.3.3, 10.4, 10.4.1, 10.4.1.1, 10.4.2, 10.4.2.1, 10.4.3, 12.4.2 |
| AU-3Content of Audit Records | AUAudit and Accountability | 10.2, 10.2.1, 10.2.1.1, 10.2.1.2, 10.2.1.3, 10.2.1.4, 10.2.1.5, 10.2.1.6, 10.2.1.7, 10.2.2, 6.4.2 |
| AU-4(1)Transfer to Alternate Storage | AUAudit and Accountability | 10.3.3 |
| AU-5Response to Audit Logging Process Failures | AUAudit and Accountability | A3.3.1 |
| AU-6Audit Record Review, Analysis, and Reporting | AUAudit and Accountability | 10.3.3, 10.4, 10.4.1, 10.4.1.1 |
| AU-6(3)Correlate Audit Record Repositories | AUAudit and Accountability | 10.4.1.1, 12.10.5 |
| AU-6(4)Central Review and Analysis | AUAudit and Accountability | 10.3.3, 10.4, 10.4.1, 10.4.1.1 |
| AU-6(8)Full Text Analysis of Privileged Commands | AUAudit and Accountability | 10.2.1.1, 10.2.1.2, 10.2.1.3, 10.2.1.4, 10.2.1.5, 10.2.1.6, 10.2.1.7 |
| AU-6(9)Correlation with Information from Nontechnical Sources | AUAudit and Accountability | 10.4.1.1, 12.10.5 |
| AU-8Time Stamps | AUAudit and Accountability | 10.2, 10.6, 10.6.1, 10.6.2, 10.6.3 |
| AU-9Protection of Audit Information | AUAudit and Accountability | 10.3, 10.3.1, 10.3.2 |
| AU-9(2)Store on Separate Physical Systems or Components | AUAudit and Accountability | 10.3.3 |
| AU-9(4)Access by Subset of Privileged Users | AUAudit and Accountability | 10.3, 10.3.1, 10.3.2 |
| AU-11Audit Record Retention | AUAudit and Accountability | 10.5, 10.5.1 |
| AU-12(1)System-wide and Time-correlated Audit Trail | AUAudit and Accountability | 10.6, 10.6.1, 10.6.2, 10.6.3 |
| CA-1Policy and Procedures | CAAssessment, Authorization, and Monitoring | 1.1.1, 10.1.1, 11.1.1, 12.1, 12.1.1, 12.1.2, 12.1.3, 2.1.1, 3.1.1, 3.7.1, 3.7.2, 3.7.3, 3.7.5, 3.7.6, 3.7.7, 3.7.8, 4.1.1, 5.1.1, 6.1.1, 7.1.1, 8.1.1, 8.3.8, 9.1.1 |
| CA-2Control Assessments | CAAssessment, Authorization, and Monitoring | 1.1, 1.2.7, 10.7, 10.7.1, 10.7.2, 10.7.3, 11.1, 12.4.2 |
| CA-7Continuous Monitoring | CAAssessment, Authorization, and Monitoring | 10.7, 10.7.1, 10.7.2, 10.7.3 |
| CA-7(1)Independent Assessment | CAAssessment, Authorization, and Monitoring | 10.7, 10.7.1, 10.7.2, 10.7.3 |
| CA-8Penetration Testing | CAAssessment, Authorization, and Monitoring | 11.4, 11.4.1, 11.4.2, 11.4.3, 11.4.4, 11.4.5, 11.4.6, 11.4.7, A3.2.4 |
| CA-8(1)Independent Penetration Testing Agent or Team | CAAssessment, Authorization, and Monitoring | 11.4.1, 11.4.2, 11.4.3, 11.4.5, 11.4.6 |
| CM-1Policy and Procedures | CMConfiguration Management | 1.1.1, 10.1.1, 11.1.1, 12.1, 12.1.1, 12.1.2, 12.1.3, 2.1, 2.1.1, 2.2, 3.1.1, 3.7.1, 3.7.2, 3.7.3, 3.7.5, 3.7.6, 3.7.7, 3.7.8, 4.1.1, 5.1.1, 6.1.1, 7.1.1, 8.1.1, 8.3.8, 8.5, 9.1.1 |
| CM-2Baseline Configuration | CMConfiguration Management | 1.1, 1.2.1, 1.2.6, 10.2, 10.2.1, 10.2.1.1, 10.2.1.2, 10.2.1.3, 10.2.1.4, 10.2.1.5, 10.2.1.6, 10.2.1.7, 10.2.2, 10.6, 10.6.1, 10.6.2, 10.6.3, 11.2, 12.4.2, 2.2, 2.2.1, 8.3.2, 8.5 |
| CM-2(6)Development and Test Environments | CMConfiguration Management | 6.5.6 |
| CM-2(7)Configure Systems and Components for High-risk Areas | CMConfiguration Management | 1.2.1, 1.5, 1.5.1, 10.2, 10.2.1, 10.2.1.1, 10.2.1.2, 10.2.1.3, 10.2.1.4, 10.2.1.5, 10.2.1.6, 10.2.1.7, 10.2.2, 10.6, 10.6.1, 10.6.2, 10.6.3, 8.5 |
| CM-3Configuration Change Control | CMConfiguration Management | 1.2.2, 12.4.2, 6.5, 6.5.1, 6.5.2, 6.5.3, 6.5.6 |
| CM-3(1)Automated Documentation, Notification, and Prohibition of Changes | CMConfiguration Management | 1.2.2, 6.5, 6.5.1 |
| CM-3(2)Testing, Validation, and Documentation of Changes | CMConfiguration Management | 10.7.3, 6.5, 6.5.1, 6.5.2, A3.2.2.1 |
| CM-3(5)Automated Security Response | CMConfiguration Management | 10.7 |
| CM-3(7)Review System Changes | CMConfiguration Management | 6.5, 6.5.1, 6.5.2, A3.2.2.1 |
| CM-4Impact Analyses | CMConfiguration Management | 6.5.2, 6.5.6, A3.2.2, A3.2.3 |
| CM-4(1)Separate Test Environments | CMConfiguration Management | 6.5.3, 6.5.6 |
| CM-5Access Restrictions for Change | CMConfiguration Management | 1.2.8 |
| CM-6Configuration Settings | CMConfiguration Management | 1.1, 1.2.1, 1.2.6, 10.2, 10.2.1, 10.2.1.1, 10.2.1.2, 10.2.1.3, 10.2.1.4, 10.2.1.5, 10.2.1.6, 10.2.1.7, 10.2.2, 10.6, 10.6.1, 10.6.2, 10.6.3, 11.2, 2.2, 2.2.1, 8.3.2, 8.5 |
| CM-6(2)Respond to Unauthorized Changes | CMConfiguration Management | 10.7, 10.7.1, 10.7.2, 10.7.3 |
| CM-7Least Functionality | CMConfiguration Management | 1.2.5, 1.2.6, 1.4, 1.4.1, 1.4.2, 2.2.4 |
| CM-7(1)Periodic Review | CMConfiguration Management | 1.2.7, 11.6.1, 12.3.1, 12.3.4, 12.4.2, 12.5.2, 12.5.2.1, 12.6.2, 12.6.3 |
| CM-7(6)Confined Environments with Limited Privileges | CMConfiguration Management | 1.2.1, 1.5, 1.5.1, 10.2, 10.2.1, 10.2.1.1, 10.2.1.2, 10.2.1.3, 10.2.1.4, 10.2.1.5, 10.2.1.6, 10.2.1.7, 10.2.2, 10.6, 10.6.1, 10.6.2, 10.6.3, 8.5 |
| CM-7(7)Code Execution in Protected Environments | CMConfiguration Management | 1.2.1, 1.5, 1.5.1, 10.2, 10.2.1, 10.2.1.1, 10.2.1.2, 10.2.1.3, 10.2.1.4, 10.2.1.5, 10.2.1.6, 10.2.1.7, 10.2.2, 10.6, 10.6.1, 10.6.2, 10.6.3, 8.5 |
| CM-7(9)Prohibiting The Use of Unauthorized Hardware | CMConfiguration Management | 1.2.1, 1.5, 1.5.1, 10.2, 10.2.1, 10.2.1.1, 10.2.1.2, 10.2.1.3, 10.2.1.4, 10.2.1.5, 10.2.1.6, 10.2.1.7, 10.2.2, 10.6, 10.6.1, 10.6.2, 10.6.3, 8.5 |
| CM-8System Component Inventory | CMConfiguration Management | 11.2, 11.2.2, 6.3.2, 9.5.1, 9.5.1.1 |
| CM-9Configuration Management Plan | CMConfiguration Management | 2.1, 2.2, 8.5 |
| CM-9(1)Assignment of Responsibility | CMConfiguration Management | 2.1 |
| CP-1Policy and Procedures | CPContingency Planning | 1.1.1, 10.1.1, 11.1.1, 12.1, 12.1.1, 12.1.2, 12.1.3, 2.1.1, 3.1.1, 3.7.1, 3.7.2, 3.7.3, 3.7.5, 3.7.6, 3.7.7, 3.7.8, 4.1.1, 5.1.1, 6.1.1, 7.1.1, 8.1.1, 8.3.8, 9.1.1 |
| CP-9System Backup | CPContingency Planning | 12.10.1, 9.4.1.1, 9.4.1.2 |
| CP-9(3)Separate Storage for Critical Information | CPContingency Planning | 9.4.1.1 |
| IA-1Policy and Procedures | IAIdentification and Authentication | 1.1.1, 10.1.1, 11.1.1, 12.1, 12.1.1, 12.1.2, 12.1.3, 2.1.1, 3.1.1, 3.7.1, 3.7.2, 3.7.3, 3.7.5, 3.7.6, 3.7.7, 3.7.8, 4.1.1, 5.1.1, 6.1.1, 7.1, 7.1.1, 7.2, 7.2.1, 7.3, 7.3.1, 7.3.2, 7.3.3, 8.1, 8.1.1, 8.2, 8.3.3, 8.3.8, 8.5.1, 8.6.1, 9.1.1, A3.4 |
| IA-2Identification and Authentication (Organizational Users) | IAIdentification and Authentication | 7.1, 7.2, 7.2.1, 7.3, 7.3.1, 7.3.2, 7.3.3, 8.1, 8.2, 8.3, 8.3.3, 8.3.9 |
| IA-2(1)Multi-factor Authentication to Privileged Accounts | IAIdentification and Authentication | 8.2.3, 8.3.11, 8.4, 8.4.1, 8.4.2, 8.4.3, 8.5.1 |
| IA-2(2)Multi-factor Authentication to Non-privileged Accounts | IAIdentification and Authentication | 8.2.3, 8.3.11, 8.4, 8.4.1, 8.4.2, 8.4.3, 8.5.1 |
| IA-2(5)Individual Authentication with Group Authentication | IAIdentification and Authentication | 8.2.2 |
| IA-2(6)Access to Accounts —separate Device | IAIdentification and Authentication | 8.4.2 |
| IA-2(8)Access to Accounts — Replay Resistant | IAIdentification and Authentication | 8.5.1 |
| IA-4Identifier Management | IAIdentification and Authentication | 8.2, 8.2.1 |
| IA-4(4)Identify User Status | IAIdentification and Authentication | 8.2, 8.2.1 |
| IA-5Authenticator Management | IAIdentification and Authentication | 2.2.2, 2.3.1, 6.5.2, 8.2.4, 8.3, 8.3.1, 8.3.10.1, 8.3.11, 8.3.3, 8.3.5, 8.3.7, 8.3.9, 8.6.3 |
| IA-5(1)Password-based Authentication | IAIdentification and Authentication | 8.2.4, 8.3, 8.3.1, 8.3.10.1, 8.3.11, 8.3.3, 8.3.5, 8.3.6, 8.3.7, 8.3.9, 8.6.3 |
| IA-5(2)Public Key-based Authentication | IAIdentification and Authentication | 8.3.1, 8.3.11 |
| IA-5(5)Change Authenticators Prior to Delivery | IAIdentification and Authentication | 2.2.2, 2.3.1, 6.5.2 |
| IA-5(6)Protection of Authenticators | IAIdentification and Authentication | 8.3.11 |
| IA-5(7)No Embedded Unencrypted Static Authenticators | IAIdentification and Authentication | 8.6.2 |
| IA-7Cryptographic Module Authentication | IAIdentification and Authentication | 2.2.7, 3.6.1.1, 3.6.1.2 |
| IA-8Identification and Authentication (Non-organizational Users) | IAIdentification and Authentication | 7.2.1 |
| IA-8(2)Acceptance of External Authenticators | IAIdentification and Authentication | 8.2.3 |
| IA-9Service Identification and Authentication | IAIdentification and Authentication | 8.2.3 |
| IA-11Re-authentication | IAIdentification and Authentication | 8.2.8 |
| IA-12Identity Proofing | IAIdentification and Authentication | 8.3.3 |
| IA-12(4)In-person Validation and Verification | IAIdentification and Authentication | 7.2.3, 8.2.4, 8.3.5 |
| IR-1Policy and Procedures | IRIncident Response | 1.1.1, 10.1.1, 10.7, 10.7.1, 10.7.2, 10.7.3, 11.1.1, 12.1, 12.1.1, 12.1.2, 12.1.3, 12.10, 12.10.2, 12.10.6, 2.1.1, 3.1.1, 3.7.1, 3.7.2, 3.7.3, 3.7.5, 3.7.6, 3.7.7, 3.7.8, 4.1.1, 5.1.1, 6.1.1, 7.1.1, 8.1.1, 8.3.8, 9.1.1, A3.5 |
| IR-2Incident Response Training | IRIncident Response | 12.10.4, 12.10.4.1 |
| IR-2(3)Breach | IRIncident Response | 12.10.4, 12.10.4.1 |
| IR-3Incident Response Testing | IRIncident Response | 12.10.2 |
| IR-4Incident Handling | IRIncident Response | 12.10, 12.10.5 |
| IR-4(3)Continuity of Operations | IRIncident Response | 12.10 |
| IR-4(4)Information Correlation | IRIncident Response | 10.3.3, 10.4, 10.4.1, 10.4.1.1, 12.10.5 |
| IR-4(5)Automatic Disabling of System | IRIncident Response | A3.2.6.1, A3.5 |
| IR-4(10)Supply Chain Coordination | IRIncident Response | 10.7, 10.7.1, 10.7.2, 10.7.3 |
| IR-4(11)Integrated Incident Response Team | IRIncident Response | 12.10.3 |
| IR-4(12)Malicious Code and Forensic Analysis | IRIncident Response | 12.10.6 |
| IR-4(13)Behavior Analysis | IRIncident Response | 3.1, A3.2.6.1 |
| IR-5Incident Monitoring | IRIncident Response | A3.3.1 |
| IR-6Incident Reporting | IRIncident Response | 12.1.4, 12.10.1, A1.2.3 |
| IR-6(2)Vulnerabilities Related to Incidents | IRIncident Response | 12.10.6 |
| IR-8Incident Response Plan | IRIncident Response | 12.10, 12.10.1, 12.10.5, 12.10.7 |
| IR-9Information Spillage Response | IRIncident Response | 12.10.7, A3.2.5.2 |
| IR-9(3)Post-spill Operations | IRIncident Response | 12.10.7, A3.2.5.2 |
| MA-1Policy and Procedures | MAMaintenance | 1.1.1, 10.1.1, 11.1.1, 12.1, 12.1.1, 12.1.2, 12.1.3, 2.1.1, 3.1.1, 3.7.1, 3.7.2, 3.7.3, 3.7.5, 3.7.6, 3.7.7, 3.7.8, 4.1.1, 5.1.1, 6.1.1, 7.1.1, 8.1.1, 8.2.7, 8.3.8, 9.1.1 |
| MA-4Nonlocal Maintenance | MAMaintenance | 8.2.7 |
| MA-4(1)Logging and Review | MAMaintenance | 8.2.7 |
| MA-4(6)Cryptographic Protection | MAMaintenance | 2.2.7 |
| MA-4(7)Disconnect Verification | MAMaintenance | 8.2.7 |
| MA-6Timely Maintenance | MAMaintenance | 10.7, 11.3 |
| PE-1Policy and Procedures | PEPhysical and Environmental Protection | 1.1.1, 10.1.1, 11.1.1, 12.1, 12.1.1, 12.1.2, 12.1.3, 2.1.1, 3.1.1, 3.7.1, 3.7.2, 3.7.3, 3.7.5, 3.7.6, 3.7.7, 3.7.8, 4.1.1, 5.1.1, 6.1.1, 7.1.1, 8.1.1, 8.3.8, 9.1, 9.1.1, 9.2 |
| PE-2Physical Access Authorizations | PEPhysical and Environmental Protection | 8.3.11, 9.1, 9.2, 9.2.1, 9.3, 9.3.1 |
| PE-2(1)Access by Position or Role | PEPhysical and Environmental Protection | 8.3.11, 9.1, 9.2, 9.2.1, 9.3, 9.3.1, 9.3.1.1 |
| PE-2(2)Two Forms of Identification | PEPhysical and Environmental Protection | 9.3.2 |
| PE-2(3)Restrict Unescorted Access | PEPhysical and Environmental Protection | 9.3.2 |
| PE-3Physical Access Control | PEPhysical and Environmental Protection | 9.1, 9.1.2, 9.2, 9.2.1 |
| PE-3(2)Facility and Systems | PEPhysical and Environmental Protection | 9.1, 9.1.2, 9.2, 9.2.1 |
| PE-3(3)Continuous Guards | PEPhysical and Environmental Protection | 9.1, 9.1.2, 9.2, 9.2.1 |
| PE-3(4)Lockable Casings | PEPhysical and Environmental Protection | 9.2.4 |
| PE-4Access Control for Transmission | PEPhysical and Environmental Protection | 9.2.2, 9.2.3 |
| PE-5Access Control for Output Devices | PEPhysical and Environmental Protection | 9.2.2, 9.2.3 |
| PE-6Monitoring Physical Access | PEPhysical and Environmental Protection | 9.2.1.1 |
| PE-6(1)Intrusion Alarms and Surveillance Equipment | PEPhysical and Environmental Protection | 9.2.1.1 |
| PE-6(4)Monitoring Physical Access to Systems | PEPhysical and Environmental Protection | 9.2.1.1 |
| PE-8Visitor Access Records | PEPhysical and Environmental Protection | 9.2.1, 9.2.1.1 |
| PE-8(1)Automated Records Maintenance and Review | PEPhysical and Environmental Protection | 9.3.4 |
| PE-8(3)Limit Personally Identifiable Information Elements | PEPhysical and Environmental Protection | 9.3.4 |
| PE-18Location of System Components | PEPhysical and Environmental Protection | 9.2.2, 9.2.3, 9.2.4 |
| PE-22Component Marking | PEPhysical and Environmental Protection | A3.2.5 |
| PE-23Facility Location | PEPhysical and Environmental Protection | 12.5.2, 3.2.1, 9.1, 9.1.1, 9.2, 9.2.2, 9.2.3, 9.2.4 |
| PL-1Policy and Procedures | PLPlanning | 1.1.1, 10.1.1, 11.1.1, 12.1, 12.1.1, 12.1.2, 12.1.3, 12.4, 12.4.2, 2.1.1, 3.1.1, 3.7.1, 3.7.2, 3.7.3, 3.7.5, 3.7.6, 3.7.7, 3.7.8, 4.1.1, 5.1.1, 6.1.1, 6.2, 6.2.1, 7.1.1, 8.1.1, 8.3.8, 9.1.1, A3.1, A3.1.1 |
| PL-2System Security and Privacy Plans | PLPlanning | 1.2.3, 1.2.4 |
| PL-4Rules of Behavior | PLPlanning | 12.1.3, 12.2, 12.2.1 |
| PL-8Security and Privacy Architectures | PLPlanning | 1.2 |
| PL-8(1)Defense in Depth | PLPlanning | 1.2.1, 1.4.1 |
| PL-9Central Management | PLPlanning | 1.1, 1.1.2, 10.1.2, 10.7, 10.7.1, 10.7.2, 10.7.3, 11.1.2, 12.1.3, 12.1.4, 12.4, 2.1.2, 3.1.2, 4.1.2, 5.1.2, 5.3.4, 6.1.2, 6.3, 6.3.1, 6.3.2, 6.3.3, 6.4, 6.4.1, 6.4.2, 6.4.3, 7.1.2, 8.1.2, 9.1.2, A3.1.1, A3.1.3 |
| PL-10Baseline Selection | PLPlanning | 1.1, 1.2.1, 1.2.6, 10.2, 10.2.1, 10.2.1.1, 10.2.1.2, 10.2.1.3, 10.2.1.4, 10.2.1.5, 10.2.1.6, 10.2.1.7, 10.2.2, 10.6, 10.6.1, 10.6.2, 10.6.3, 11.2, 2.2, 2.2.1, 8.3.2, 8.5 |
| RA-1Policy and Procedures | RARisk Assessment | 1.1.1, 10.1.1, 11.1.1, 12.1, 12.1.1, 12.1.2, 12.1.3, 12.3, 2.1.1, 3.1.1, 3.7.1, 3.7.2, 3.7.3, 3.7.5, 3.7.6, 3.7.7, 3.7.8, 4.1.1, 5.1.1, 6.1.1, 7.1.1, 8.1.1, 8.3.8, 9.1.1 |
| RA-2Security Categorization | RARisk Assessment | 9.4.2 |
| RA-3Risk Assessment | RARisk Assessment | 1.2.7, 10.7, 10.7.1, 10.7.2, 10.7.3, 11.1, 12.3, 12.3.1, 12.3.2, 12.4.2 |
| RA-5Vulnerability Monitoring and Scanning | RARisk Assessment | 11.3, 11.3.1, 11.3.1.1, 11.3.1.2, 11.3.1.3, 11.3.2, 11.3.2.1, 6.4.1 |
| RA-5(2)Update Vulnerabilities to Be Scanned | RARisk Assessment | 11.3.1 |
| RA-5(3)Breadth and Depth of Coverage | RARisk Assessment | 11.3.1, 11.3.2.1 |
| RA-5(4)Discoverable Information | RARisk Assessment | 1.4.5 |
| RA-5(11)Public Disclosure Program | RARisk Assessment | 6.3.1 |
| RA-7Risk Response | RARisk Assessment | 10.7, 10.7.1, 10.7.2, 10.7.3 |
| RA-8Privacy Impact Assessments | RARisk Assessment | A3.2.2 |
| RA-9Criticality Analysis | RARisk Assessment | 1.1 |
| SA-1Policy and Procedures | SASystem and Services Acquisition | 1.1.1, 10.1.1, 11.1.1, 12.1, 12.1.1, 12.1.2, 12.1.3, 2.1.1, 3.1.1, 3.7.1, 3.7.2, 3.7.3, 3.7.5, 3.7.6, 3.7.7, 3.7.8, 4.1.1, 5.1.1, 6.1.1, 6.2, 6.2.1, 6.2.4, 7.1.1, 8.1.1, 8.3.8, 9.1.1 |
| SA-3System Development Life Cycle | SASystem and Services Acquisition | 12.3.4 |
| SA-3(1)Manage Preproduction Environment | SASystem and Services Acquisition | 11.4.5, 11.4.6, 12.3.4, 6.5.3 |
| SA-3(2)Use of Live or Operational Data | SASystem and Services Acquisition | 6.5.5 |
| SA-3(3)Technology Refresh | SASystem and Services Acquisition | 12.3.4 |
| SA-4Acquisition Process | SASystem and Services Acquisition | 12.8, 12.8.1, 12.9, 12.9.1, 12.9.2, 6.2, 6.2.1, 8.2.3, A2.1.3 |
| SA-4(1)Functional Properties of Controls | SASystem and Services Acquisition | 1.2.3, 1.2.4 |
| SA-4(2)Design and Implementation Information for Controls | SASystem and Services Acquisition | 1.2.3, 1.2.4 |
| SA-4(3)Development Methods, Techniques, and Practices | SASystem and Services Acquisition | 6.2, 6.2.1, 6.2.4 |
| SA-4(9)Functions, Ports, Protocols, and Services in Use | SASystem and Services Acquisition | 1.2.4 |
| SA-4(12)Data Ownership | SASystem and Services Acquisition | 2.2.2, 2.2.4, 2.2.5, 6.5.2, 9.4.1 |
| SA-5System Documentation | SASystem and Services Acquisition | A3.2.5 |
| SA-8Security and Privacy Engineering Principles | SASystem and Services Acquisition | 1.1, 1.2, 1.2.1, 1.2.6, 10.2, 10.2.1, 10.2.1.1, 10.2.1.2, 10.2.1.3, 10.2.1.4, 10.2.1.5, 10.2.1.6, 10.2.1.7, 10.2.2, 10.6, 10.6.1, 10.6.2, 10.6.3, 11.2, 2.2, 2.2.1, 6.1, 6.2, 6.2.1, 8.3.2, 8.5, 8.5.1 |
| SA-8(14)Least Privilege | SASystem and Services Acquisition | 1.3, 3.4, 3.4.2, 7.1, 7.2, 7.2.1, 7.2.2, 7.2.6, 7.3, 7.3.1, 7.3.2, 7.3.3, 8.6, 8.6.1 |
| SA-8(30)Procedural Rigor | SASystem and Services Acquisition | 12.3.4 |
| SA-8(31)Secure System Modification | SASystem and Services Acquisition | 1.2.2, 10.7.3, 12.4.2, 6.5, 6.5.1, 6.5.2, 6.5.6, A3.2.2.1 |
| SA-8(32)Sufficient Documentation | SASystem and Services Acquisition | 1.1.1, 10.1.1, 11.1.1, 2.1.1, 3.1.1, 3.7, 3.7.1, 3.7.2, 3.7.3, 3.7.5, 3.7.6, 3.7.7, 3.7.8, 4.1.1, 5.1.1, 6.1.1, 6.5.1, 7.1.1, 8.1.1, 8.3.8, 9.1.1, 9.3.2 |
| SA-8(33)Minimization | SASystem and Services Acquisition | 9.3.4 |
| SA-9External System Services | SASystem and Services Acquisition | 12.8.2, 12.9, 12.9.1, 12.9.2, 8.2.3 |
| SA-9(1)Risk Assessments and Organizational Approvals | SASystem and Services Acquisition | 12.8.3 |
| SA-9(2)Identification of Functions, Ports, Protocols, and Services | SASystem and Services Acquisition | 1.2.5 |
| SA-9(3)Establish and Maintain Trust Relationship with Providers | SASystem and Services Acquisition | 12.4.1, 12.8.2, 12.8.5, 12.9, 12.9.1, 12.9.2 |
| SA-9(5)Processing, Storage, and Service Location | SASystem and Services Acquisition | 12.5.2, 3.2.1 |
| SA-11Developer Testing and Evaluation | SASystem and Services Acquisition | 6.2.3, 6.2.3.1, 6.2.4, 6.5.6 |
| SA-11(1)Static Code Analysis | SASystem and Services Acquisition | 6.2.4 |
| SA-11(2)Threat Modeling and Vulnerability Analyses | SASystem and Services Acquisition | 11.4.1, 11.4.4, 12.4.2.1, 6.2.1, 6.2.2, 6.2.3, 6.2.3.1, 6.2.4, 6.3.1, 6.4.1, 6.4.2, A1.2.3 |
| SA-11(5)Penetration Testing | SASystem and Services Acquisition | 11.4, 11.4.1, 11.4.2, 11.4.3, 11.4.4, 11.4.5, 11.4.6, 11.4.7, 12.4.2.1, 6.2.1, 6.2.2, 6.2.3, 6.2.3.1, 6.2.4, 6.3.1, 6.4.1, 6.4.2, 6.5.6, A1.2.3, A3.2.4 |
| SA-11(6)Attack Surface Reviews | SASystem and Services Acquisition | 11.3.1, 11.3.1.1, 11.3.1.2, 11.3.1.3, 11.3.2, 11.3.2.1, 6.2.3, 6.2.3.1, 6.2.4, 6.3.1, 6.3.2, 6.5.6 |
| SA-11(7)Verify Scope of Testing and Evaluation | SASystem and Services Acquisition | 11.3.1, 11.3.1.1, 11.3.1.2, 11.3.1.3, 11.3.2, 11.3.2.1, 6.2.3, 6.2.3.1, 6.2.4, 6.3.1, 6.3.2, 6.5.6 |
| SA-11(8)Dynamic Code Analysis | SASystem and Services Acquisition | 6.2.4 |
| SA-15Development Process, Standards, and Tools | SASystem and Services Acquisition | 6.2, 6.2.1, 6.2.4 |
| SA-15(5)Attack Surface Reduction | SASystem and Services Acquisition | 1.1, 1.2, 1.2.1, 1.2.6, 10.2, 10.2.1, 10.2.1.1, 10.2.1.2, 10.2.1.3, 10.2.1.4, 10.2.1.5, 10.2.1.6, 10.2.1.7, 10.2.2, 10.6, 10.6.1, 10.6.2, 10.6.3, 11.2, 2.2, 2.2.1, 6.1, 6.2, 6.2.1, 8.3.2, 8.5, 8.5.1 |
| SA-17Developer Security and Privacy Architecture and Design | SASystem and Services Acquisition | 6.2, 6.2.1 |
| SA-21Developer Screening | SASystem and Services Acquisition | 6.2.2 |
| SA-23Specialization | SASystem and Services Acquisition | 6.2, 6.2.1 |
| SC-1Policy and Procedures | SCSystem and Communications Protection | 1.1, 1.1.1, 1.2, 10.1.1, 11.1.1, 11.2.1, 12.1, 12.1.1, 12.1.2, 12.1.3, 2.1.1, 3.1.1, 3.7.1, 3.7.2, 3.7.3, 3.7.5, 3.7.6, 3.7.7, 3.7.8, 4.1.1, 5.1.1, 6.1, 6.1.1, 6.2, 6.2.1, 7.1.1, 8.1.1, 8.3.8, 8.5, 8.5.1, 9.1.1 |
| SC-3Security Function Isolation | SCSystem and Communications Protection | 10.7.1, 11.4.5, 11.4.6, 2.2.3, 3.4.1 |
| SC-3(5)Layered Structures | SCSystem and Communications Protection | 1.2.1, 1.4.1 |
| SC-7Boundary Protection | SCSystem and Communications Protection | 1.3.3, 1.4, 1.4.1, 1.4.2, 11.5.1 |
| SC-7(3)Access Points | SCSystem and Communications Protection | 1.4.2, 11.2.1 |
| SC-7(5)Deny by Default — Allow by Exception | SCSystem and Communications Protection | 1.3, 1.3.1, 1.3.2, 1.3.3, 1.4.2 |
| SC-7(7)Split Tunneling for Remote Devices | SCSystem and Communications Protection | 1.5.1 |
| SC-7(9)Restrict Threatening Outgoing Communications Traffic | SCSystem and Communications Protection | 1.3.3, 1.4, 1.4.1, 1.4.2, 11.5.1 |
| SC-7(10)Prevent Exfiltration | SCSystem and Communications Protection | 1.3.2, A3.2.6 |
| SC-7(11)Restrict Incoming Communications Traffic | SCSystem and Communications Protection | 1.3, 1.3.1, 1.3.2, 1.3.3, 1.4, 1.4.1, 1.4.2, 11.5.1 |
| SC-7(12)Host-based Protection | SCSystem and Communications Protection | 2.2.3 |
| SC-7(14)Protect Against Unauthorized Physical Connections | SCSystem and Communications Protection | 9.2.2, 9.2.3, 9.2.4 |
| SC-7(16)Prevent Discovery of System Components | SCSystem and Communications Protection | 1.4.5 |
| SC-7(17)Automated Enforcement of Protocol Formats | SCSystem and Communications Protection | 6.4, 6.4.1, 6.4.2 |
| SC-7(18)Fail Secure | SCSystem and Communications Protection | 1.2, 6.1, 6.2, 6.2.1, 8.5, 8.5.1 |
| SC-7(21)Isolation of System Components | SCSystem and Communications Protection | 1.3.3 |
| SC-7(22)Separate Subnets for Connecting to Different Security Domains | SCSystem and Communications Protection | 1.4, 1.4.1 |
| SC-7(27)Unclassified Non-national Security System Connections | SCSystem and Communications Protection | 1.4.4 |
| SC-7(29)Separate Subnets to Isolate Functions | SCSystem and Communications Protection | 1.4, 1.4.1 |
| SC-8Transmission Confidentiality and Integrity | SCSystem and Communications Protection | 3.7.5, 4.2, 4.2.1, 4.2.1.2, 8.3.2, A2.1, A2.1.1, A2.1.2 |
| SC-8(1)Cryptographic Protection | SCSystem and Communications Protection | 12.3.3, 2.2.7, 3.3.2, 4.2, 4.2.1, 4.2.1.2, 8.3.2, A2.1, A2.1.1, A2.1.2 |
| SC-8(2)Pre- and Post-transmission Handling | SCSystem and Communications Protection | 12.3.3, 2.2.7, 3.3.2, 8.3.2 |
| SC-10Network Disconnect | SCSystem and Communications Protection | 8.2.8 |
| SC-12(1)Availability | SCSystem and Communications Protection | 2.3.2, 3.6.1, 3.7.5 |
| SC-13Cryptographic Protection | SCSystem and Communications Protection | 12.3.3, 2.2.7, 3.3.2, 3.5, 3.5.1.2, 3.5.1.3, 8.3.2, 9.4 |
| SC-16(1)Integrity Verification | SCSystem and Communications Protection | 3.7.5 |
| SC-18(1)Identify Unacceptable Code and Take Corrective Actions | SCSystem and Communications Protection | 11.3, 11.3.1, 11.3.1.1, 11.3.1.2, 11.3.1.3, 11.3.2, 11.3.2.1, 6.3.3 |
| SC-23Session Authenticity | SCSystem and Communications Protection | 1.4.1 |
| SC-28Protection of Information at Rest | SCSystem and Communications Protection | 1.5, 1.5.1, 3.3.2, 3.5, 3.5.1.2, 3.5.1.3, 8.3.2, 9.4 |
| SC-28(1)Cryptographic Protection | SCSystem and Communications Protection | 3.3.2, 3.5, 3.5.1.2, 3.5.1.3, 3.7.5, 8.3.2, 9.4 |
| SC-28(2)Offline Storage | SCSystem and Communications Protection | 12.10.1, 9.4.1.1, 9.4.1.2 |
| SC-28(3)Cryptographic Keys | SCSystem and Communications Protection | 3.5.1.1, 3.6, 3.6.1, 3.6.1.1, 3.6.1.2, 3.6.1.3, 3.6.1.4, 3.7, 3.7.1, 3.7.2, 3.7.3, 3.7.4, 3.7.5, 3.7.6, 3.7.7, 4.2.1.1 |
| SC-31Covert Channel Analysis | SCSystem and Communications Protection | 11.5.1.1 |
| SC-38Operations Security | SCSystem and Communications Protection | 1.1.1, 10.1.1, 11.1.1, 2.1.1, 3.1.1, 4.1.1, 5.1.1, 6.1.1, 7.1.1, 8.1.1, 8.3.8, 9.1.1, 9.3.2 |
| SC-40Wireless Link Protection | SCSystem and Communications Protection | 1.2.3, 1.3.3, 11.2, 11.2.1, 11.2.2, 12.10.1, 12.10.5, 2.3, 2.3.1, 2.3.2, 4.2.1.2 |
| SC-45System Time Synchronization | SCSystem and Communications Protection | 10.6, 10.6.1, 10.6.2, 10.6.3 |
| SC-45(1)Synchronization with Authoritative Time Source | SCSystem and Communications Protection | 10.6, 10.6.1, 10.6.2, 10.6.3 |
| SC-48Sensor Relocation | SCSystem and Communications Protection | 10.4, 10.4.1, 10.4.1.1 |
| SI-1Policy and Procedures | SISystem and Information Integrity | 1.1.1, 1.2, 10.1.1, 11.1.1, 12.1, 12.1.1, 12.1.2, 12.1.3, 2.1.1, 3.1.1, 3.7.1, 3.7.2, 3.7.3, 3.7.5, 3.7.6, 3.7.7, 3.7.8, 4.1.1, 5.1.1, 6.1, 6.1.1, 6.2, 6.2.1, 7.1.1, 8.1.1, 8.3.8, 8.5, 8.5.1, 9.1.1 |
| SI-2Flaw Remediation | SISystem and Information Integrity | 11.3, 5.3, 5.3.1, 6.3, 6.3.1, 6.3.3 |
| SI-2(4)Automated Patch Management Tools | SISystem and Information Integrity | 6.3, 6.3.1, 6.3.2, 6.3.3, 6.4, 6.4.1, 6.4.2, 6.4.3 |
| SI-3Malicious Code Protection | SISystem and Information Integrity | 11.2, 11.3, 4.1, 4.2.1, 5.2, 5.2.1, 5.2.2, 5.3, 5.3.1, 5.3.2, 5.3.2.1, 5.3.3, 5.3.4, 5.3.5, 6.3, 6.3.1, 6.3.3 |
| SI-4System Monitoring | SISystem and Information Integrity | 10.1, 10.3.3, 10.4, 10.4.1, 10.4.1.1, 10.4.3, 10.7, 10.7.1, 10.7.2, 10.7.3, 11.2, 4.1, 4.2.1, A3.3.1, A3.5 |
| SI-4(1)System-wide Intrusion Detection System | SISystem and Information Integrity | 1.4.3, 11.5, 11.5.1, 11.5.1.1 |
| SI-4(2)Automated Tools and Mechanisms for Real-time Analysis | SISystem and Information Integrity | 10.4, 10.4.1, 10.4.1.1 |
| SI-4(5)System-generated Alerts | SISystem and Information Integrity | 10.2, 10.4, 10.4.1, 10.4.1.1, 10.4.3, 10.7, 10.7.1, 10.7.2, 10.7.3 |
| SI-4(7)Automated Response to Suspicious Events | SISystem and Information Integrity | A3.2.6.1, A3.5 |
| SI-4(9)Testing of Monitoring Tools and Mechanisms | SISystem and Information Integrity | 12.10.2 |
| SI-4(11)Analyze Communications Traffic Anomalies | SISystem and Information Integrity | 3.1, A3.2.6.1 |
| SI-4(12)Automated Organization-generated Alerts | SISystem and Information Integrity | A3.2.6.1 |
| SI-4(14)Wireless Intrusion Detection | SISystem and Information Integrity | 11.2 |
| SI-4(15)Wireless to Wireline Communications | SISystem and Information Integrity | 1.4.3, 11.2 |
| SI-4(16)Correlate Monitoring Information | SISystem and Information Integrity | 10.4.1.1, 12.10.5 |
| SI-4(18)Analyze Traffic and Covert Exfiltration | SISystem and Information Integrity | 11.5.1.1, A3.2.6 |
| SI-4(24)Indicators of Compromise | SISystem and Information Integrity | 10.3.4, 10.4, 11.5, 11.5.2, 11.6.1 |
| SI-4(25)Optimize Network Traffic Analysis | SISystem and Information Integrity | 1.4.2, 1.4.3, 11.2.1, 11.5, 11.5.1, 11.5.1.1 |
| SI-5Security Alerts, Advisories, and Directives | SISystem and Information Integrity | 11.2, 4.1, 4.2.1, 6.3.1 |
| SI-5(1)Automated Alerts and Advisories | SISystem and Information Integrity | 6.3.1 |
| SI-6Security and Privacy Function Verification | SISystem and Information Integrity | 10.7.3, 6.5.2, A3.2.2.1 |
| SI-6(3)Report Verification Results | SISystem and Information Integrity | 6.5.2 |
| SI-7Software, Firmware, and Information Integrity | SISystem and Information Integrity | 10.3.4, 11.2, 11.5, 11.5.2, 11.6.1, 4.1, 4.2.1 |
| SI-7(6)Cryptographic Protection | SISystem and Information Integrity | 12.3.3, 2.2.7, 3.3.2, 8.3.2 |
| SI-7(7)Integration of Detection and Response | SISystem and Information Integrity | 10.7, 10.7.1, 10.7.2, 10.7.3 |
| SI-8Spam Protection | SISystem and Information Integrity | 5.4, 5.4.1 |
| SI-10Information Input Validation | SISystem and Information Integrity | 11.2, 4.1, 4.2.1 |
| SI-12Information Management and Retention | SISystem and Information Integrity | 10.5, 10.5.1, 11.4.1, 3.2, 3.2.1, 9.4.6, 9.4.7 |
| SI-12(1)Limit Personally Identifiable Information Elements | SISystem and Information Integrity | 6.5.5 |
| SI-12(2)Minimize Personally Identifiable Information in Testing, Training, and Research | SISystem and Information Integrity | 6.5.5 |
| SI-12(3)Information Disposal | SISystem and Information Integrity | 10.5.1, 9.4.6, 9.4.7 |
| SI-19(4)Removal, Masking, Encryption, Hashing, or Replacement of Direct Identifiers | SISystem and Information Integrity | 3.4.1 |
| MP-1Policy and Procedures | MPMedia Protection | 1.1.1, 10.1.1, 11.1.1, 12.1, 12.1.1, 12.1.2, 12.1.3, 2.1.1, 3.1.1, 3.7.1, 3.7.2, 3.7.3, 3.7.5, 3.7.6, 3.7.7, 3.7.8, 4.1.1, 5.1.1, 6.1.1, 7.1.1, 8.1.1, 8.3.8, 9.1.1, 9.4, 9.4.1 |
| MP-2Media Access | MPMedia Protection | 1.5, 1.5.1, 5.1 |
| MP-4Media Storage | MPMedia Protection | 9.1, 9.4, 9.4.1, 9.4.1.2 |
| MP-5Media Transport | MPMedia Protection | 9.4, 9.4.3 |
| MP-5(3)Custodians | MPMedia Protection | 9.4.3 |
| MP-6Media Sanitization | MPMedia Protection | 9.4, 9.4.6, 9.4.7 |
| MP-6(1)Review, Approve, Track, Document, and Verify | MPMedia Protection | 9.4.7 |
| MP-6(3)Nondestructive Techniques | MPMedia Protection | 9.4.7 |
| MP-7Media Use | MPMedia Protection | 10.5, 10.5.1, 11.4.1, 3.2, 3.2.1, 9.4.6, 9.4.7 |
| PS-1Policy and Procedures | PSPersonnel Security | 1.1.1, 10.1.1, 11.1.1, 12.1, 12.1.1, 12.1.2, 12.1.3, 12.2, 12.2.1, 12.7, 12.7.1, 2.1.1, 3.1.1, 3.7.1, 3.7.2, 3.7.3, 3.7.5, 3.7.6, 3.7.7, 3.7.8, 4.1.1, 5.1.1, 6.1.1, 7.1.1, 8.1.1, 8.3.8, 9.1.1 |
| PS-2Position Risk Designation | PSPersonnel Security | 12.7, 12.7.1, 6.2.2 |
| PS-3Personnel Screening | PSPersonnel Security | 12.7, 12.7.1 |
| PS-3(1)Classified Information | PSPersonnel Security | 12.7, 12.7.1 |
| PS-3(3)Information Requiring Special Protective Measures | PSPersonnel Security | 12.7, 12.7.1 |
| PS-4Personnel Termination | PSPersonnel Security | 8.2.5 |
| PS-9Position Descriptions | PSPersonnel Security | 1.1.2, 10.1.2, 11.1.2, 12.1.3, 12.10.1, 2.1.2, 3.1.2, 3.7.8, 4.1.2, 5.1.2, 6.1.2, 7.1.2, 8.1.2, 9.1.2, A3.1.3 |
| PM-1Information Security Program Plan | PMProgram Management | 1.1.1, 10.1.1, 11.1.1, 12.1, 12.1.1, 12.1.2, 12.1.3, 12.4, 2.1.1, 3.1.1, 3.7.1, 3.7.2, 3.7.3, 3.7.5, 3.7.6, 3.7.7, 3.7.8, 4.1.1, 5.1.1, 6.1.1, 7.1.1, 8.1.1, 8.3.8, 9.1.1, A3.1.2 |
| PM-2Information Security Program Leadership Role | PMProgram Management | 1.1.2, 10.1.2, 11.1.2, 12.1.3, 12.1.4, 12.4, 2.1.2, 3.1.2, 4.1.2, 5.1.2, 6.1.2, 7.1.2, 8.1.2, 9.1.2, A3.1.1, A3.1.3 |
| PM-4Plan of Action and Milestones Process | PMProgram Management | 11.3, 11.3.1, 11.3.1.1, 11.3.1.2, 11.3.1.3, 11.3.2, 11.3.2.1 |
| PM-5System Inventory | PMProgram Management | 11.2, 11.2.2, 6.3.2, 9.5.1, 9.5.1.1 |
| PM-5(1)Inventory of Personally Identifiable Information | PMProgram Management | 12.5.1 |
| PM-6Measures of Performance | PMProgram Management | 1.1.2, 10.1.2, 11.1.2, 12.1.3, 12.1.4, 12.4, 2.1.2, 3.1.2, 4.1.2, 5.1.2, 6.1.2, 7.1.2, 8.1.2, 9.1.2, A3.1.1, A3.1.3 |
| PM-7Enterprise Architecture | PMProgram Management | 1.2 |
| PM-8Critical Infrastructure Plan | PMProgram Management | 12.4, 12.4.2, A3.1, A3.1.1 |
| PM-9Risk Management Strategy | PMProgram Management | 12.3 |
| PM-13Security and Privacy Workforce | PMProgram Management | 1.1.2, 10.1.2, 11.1.2, 12.1.3, 12.10.1, 12.6, 12.6.1, 12.6.2, 12.6.3, 2.1.2, 3.1.2, 3.7.8, 4.1.2, 5.1.2, 6.1.2, 7.1.2, 8.1.2, 8.3.8, 9.1.2, 9.5.1, 9.5.1.3, A3.1.3, A3.1.4 |
| PM-14Testing, Training, and Monitoring | PMProgram Management | 10.7, 10.7.1, 10.7.2, 10.7.3, A3.1.4 |
| PM-15Security and Privacy Groups and Associations | PMProgram Management | 6.3, 6.3.1, A3.5.1 |
| PM-16Threat Awareness Program | PMProgram Management | 6.3, A3.5.1 |
| PM-16(1)Automated Means for Sharing Threat Intelligence | PMProgram Management | 6.3.1 |
| PM-23Data Governance Body | PMProgram Management | A3.2.5 |
| PM-24Data Integrity Board | PMProgram Management | A3.2.5 |
| PM-25Minimization of Personally Identifiable Information Used in Testing, Training, and Research | PMProgram Management | 6.5.5, 9.3.4 |
| PM-28Risk Framing | PMProgram Management | 12.3.1, 12.3.2 |
| PM-29Risk Management Program Leadership Roles | PMProgram Management | 1.1.2, 10.1.2, 11.1.2, 12.1.3, 12.1.4, 12.3, 12.4, 2.1.2, 3.1.2, 4.1.2, 5.1.2, 6.1.2, 7.1.2, 8.1.2, 9.1.2, A3.1.1, A3.1.3 |
| PM-31Continuous Monitoring Strategy | PMProgram Management | 10.1, 10.4.3, 10.7, 10.7.1, 10.7.2, 10.7.3, A3.3.1, A3.5 |
| PT-1Policy and Procedures | PTPII Processing and Transparency | 1.1.1, 1.2, 10.1.1, 11.1.1, 12.1, 12.1.1, 12.1.2, 12.1.3, 2.1.1, 3.1.1, 3.7.1, 3.7.2, 3.7.3, 3.7.5, 3.7.6, 3.7.7, 3.7.8, 4.1.1, 5.1.1, 6.1, 6.1.1, 6.2, 6.2.1, 7.1.1, 8.1.1, 8.3.8, 8.5, 8.5.1, 9.1.1 |
| PT-2Authority to Process Personally Identifiable Information | PTPII Processing and Transparency | 6.5.5 |
| PT-3Personally Identifiable Information Processing Purposes | PTPII Processing and Transparency | 6.5.5 |
| PT-7Specific Categories of Personally Identifiable Information | PTPII Processing and Transparency | 6.5.5 |
| SR-1Policy and Procedures | SRSupply Chain Risk Management | 1.1.1, 10.1.1, 11.1.1, 12.1, 12.1.1, 12.1.2, 12.1.3, 12.8, 12.8.1, 12.9, 12.9.1, 12.9.2, 2.1.1, 3.1.1, 3.7.1, 3.7.2, 3.7.3, 3.7.5, 3.7.6, 3.7.7, 3.7.8, 4.1.1, 5.1.1, 6.1.1, 7.1.1, 8.1.1, 8.2.3, 8.3.8, 9.1.1, A2.1.3 |
| SR-3(1)Diverse Supply Base | SRSupply Chain Risk Management | 6.2, 6.2.1 |
| SR-3(3)Sub-tier Flow Down | SRSupply Chain Risk Management | 12.4.2, 12.4.2.1, 12.8.2, 12.8.5, 12.9, 12.9.1, 12.9.2, 8.2.3 |
| SR-6Supplier Assessments and Reviews | SRSupply Chain Risk Management | 12.4.2, 12.4.2.1, 12.8.4 |
| SR-6(1)Testing and Analysis | SRSupply Chain Risk Management | 12.4.2, 12.4.2.1, 12.8.4 |
| SR-7Supply Chain Operations Security | SRSupply Chain Risk Management | 1.1.1, 10.1.1, 11.1.1, 2.1.1, 3.1.1, 4.1.1, 5.1.1, 6.1.1, 7.1.1, 8.1.1, 8.3.8, 9.1.1, 9.3.2 |
| SR-9Tamper Resistance and Detection | SRSupply Chain Risk Management | 9.5.1 |
| SR-9(1)Multiple Stages of System Development Life Cycle | SRSupply Chain Risk Management | 9.5.1 |
| SR-10Inspection of Systems or Components | SRSupply Chain Risk Management | 9.5.1, 9.5.1.2 |
| SR-12Component Disposal | SRSupply Chain Risk Management | 9.4.7 |
Source and method
Derived from the Top Floor framework mapping dataset: 4,123 cross-framework control mappings across 19 frameworks, every one pivoted through NIST SP 800-53 Rev 5.
Cross-framework mappings on this page are derived from the 2026.2 release of the Secure Controls Framework, used under CC BY-ND 4.0.
Mappings are illustrative aids for planning and are not a substitute for the official text of any framework or for an assessor’s judgment. Always verify control requirements against the authoritative publication. Where no official crosswalk exists, the mapping judgment is our own analysis.
Related pairings
- SOC 2 Type II to NIST SP 800-53 Rev 5 control mapping301 shared controls
- NIST CSF 2.0 to NIST SP 800-53 Rev 5 control mapping233 shared controls
- CMMC Level 2 to NIST SP 800-53 Rev 5 control mapping218 shared controls
- NIST SP 800-171 Rev 2 to NIST SP 800-53 Rev 5 control mapping218 shared controls
- SOC 2 Type II to PCI DSS v4.0.1 control mapping185 shared controls
- PCI DSS v4.0.1 to NIST CSF 2.0 control mapping166 shared controls