| 1.1 · Control categories and functions |
01 Security Principles and Controls |
| 1.2 · Core principles and zero trust |
01 Security Principles and Controls |
| 1.3 · Change control |
09 Governance, Risk and Assurance |
| 1.4 · Cryptographic choices |
03 Cryptography, Certificates and Keys |
| 2.1 · Actors and motivations |
02 Threats, Attacks and Indicators |
| 2.2 · Vectors and exposure |
02 Threats, Attacks and Indicators |
| 2.3 · Vulnerabilities |
02 Threats, Attacks and Indicators, 05 Hardening and Vulnerability Management |
| 2.4 · Attack indicators |
02 Threats, Attacks and Indicators, 08 Monitoring, Automation and Investigation |
| 2.5 · Mitigations |
04 Secure Architecture and Network Defences, 05 Hardening and Vulnerability Management |
| 3.1 · Architecture models |
04 Secure Architecture and Network Defences |
| 3.2 · Infrastructure protections |
04 Secure Architecture and Network Defences |
| 3.3 · Data protection |
03 Cryptography, Certificates and Keys, 10 Data Lifecycle, Privacy and Recovery |
| 3.4 · Resilience |
10 Data Lifecycle, Privacy and Recovery |
| 4.1 · Secure computing |
05 Hardening and Vulnerability Management |
| 4.2 · Asset lifecycle |
10 Data Lifecycle, Privacy and Recovery |
| 4.3 · Vulnerability management |
05 Hardening and Vulnerability Management |
| 4.4 · Monitoring |
08 Monitoring, Automation and Investigation |
| 4.5 · Enterprise protections |
04 Secure Architecture and Network Defences, 08 Monitoring, Automation and Investigation |
| 4.6 · Identity and access |
06 Identity, Authentication and Privileged Access |
| 4.7 · Automation |
08 Monitoring, Automation and Investigation |
| 4.8 · Incident handling |
07 Incident Response and Evidence |
| 4.9 · Investigation evidence |
07 Incident Response and Evidence, 08 Monitoring, Automation and Investigation |
| 5.1 · Governance |
09 Governance, Risk and Assurance |
| 5.2 · Risk management |
09 Governance, Risk and Assurance |
| 5.3 · Supplier assurance |
09 Governance, Risk and Assurance |
| 5.4 · Compliance and privacy |
09 Governance, Risk and Assurance, 10 Data Lifecycle, Privacy and Recovery |
| 5.5 · Assessment and audit |
05 Hardening and Vulnerability Management, 09 Governance, Risk and Assurance |
| 5.6 · Awareness |
02 Threats, Attacks and Indicators, 09 Governance, Risk and Assurance |