| 1.1 · Ethics |
01 Security Principles and Controls, 09 Governance, Risk and Assurance, 10 Data Lifecycle, Privacy and Recovery, 11 Security Leadership, Ethics and Business Risk |
| 1.2 · Security properties |
01 Security Principles and Controls, 09 Governance, Risk and Assurance, 10 Data Lifecycle, Privacy and Recovery, 11 Security Leadership, Ethics and Business Risk |
| 1.3 · Business alignment |
01 Security Principles and Controls, 09 Governance, Risk and Assurance, 10 Data Lifecycle, Privacy and Recovery, 11 Security Leadership, Ethics and Business Risk |
| 1.4 · Legal context |
01 Security Principles and Controls, 09 Governance, Risk and Assurance, 10 Data Lifecycle, Privacy and Recovery, 11 Security Leadership, Ethics and Business Risk |
| 1.5 · Investigation authority |
01 Security Principles and Controls, 09 Governance, Risk and Assurance, 10 Data Lifecycle, Privacy and Recovery, 11 Security Leadership, Ethics and Business Risk |
| 1.6 · Policy hierarchy |
01 Security Principles and Controls, 09 Governance, Risk and Assurance, 10 Data Lifecycle, Privacy and Recovery, 11 Security Leadership, Ethics and Business Risk |
| 1.7 · Continuity requirements |
01 Security Principles and Controls, 09 Governance, Risk and Assurance, 10 Data Lifecycle, Privacy and Recovery, 11 Security Leadership, Ethics and Business Risk |
| 1.8 · Personnel lifecycle |
01 Security Principles and Controls, 09 Governance, Risk and Assurance, 10 Data Lifecycle, Privacy and Recovery, 11 Security Leadership, Ethics and Business Risk |
| 1.9 · Risk treatment |
01 Security Principles and Controls, 09 Governance, Risk and Assurance, 10 Data Lifecycle, Privacy and Recovery, 11 Security Leadership, Ethics and Business Risk |
| 1.10 · Threat models |
01 Security Principles and Controls, 09 Governance, Risk and Assurance, 10 Data Lifecycle, Privacy and Recovery, 11 Security Leadership, Ethics and Business Risk |
| 1.11 · Supplier risk |
01 Security Principles and Controls, 09 Governance, Risk and Assurance, 10 Data Lifecycle, Privacy and Recovery, 11 Security Leadership, Ethics and Business Risk |
| 1.12 · Awareness outcomes |
01 Security Principles and Controls, 09 Governance, Risk and Assurance, 10 Data Lifecycle, Privacy and Recovery, 11 Security Leadership, Ethics and Business Risk |
| 2.1 · Classification |
10 Data Lifecycle, Privacy and Recovery |
| 2.2 · Handling |
10 Data Lifecycle, Privacy and Recovery |
| 2.3 · Ownership and inventory |
10 Data Lifecycle, Privacy and Recovery |
| 2.4 · Data lifecycle |
10 Data Lifecycle, Privacy and Recovery |
| 2.5 · Retention |
10 Data Lifecycle, Privacy and Recovery |
| 2.6 · Data safeguards |
10 Data Lifecycle, Privacy and Recovery |
| 3.1 · Secure design |
03 Cryptography, Certificates and Keys, 04 Secure Architecture and Network Defences, 12 Security Models, Trusted Computing and Cryptanalysis, 13 Network, Facility and Distributed-System Design |
| 3.2 · Security models |
03 Cryptography, Certificates and Keys, 04 Secure Architecture and Network Defences, 12 Security Models, Trusted Computing and Cryptanalysis, 13 Network, Facility and Distributed-System Design |
| 3.3 · Control selection |
03 Cryptography, Certificates and Keys, 04 Secure Architecture and Network Defences, 12 Security Models, Trusted Computing and Cryptanalysis, 13 Network, Facility and Distributed-System Design |
| 3.4 · Platform trust |
03 Cryptography, Certificates and Keys, 04 Secure Architecture and Network Defences, 12 Security Models, Trusted Computing and Cryptanalysis, 13 Network, Facility and Distributed-System Design |
| 3.5 · Architecture weaknesses |
03 Cryptography, Certificates and Keys, 04 Secure Architecture and Network Defences, 12 Security Models, Trusted Computing and Cryptanalysis, 13 Network, Facility and Distributed-System Design |
| 3.6 · Cryptography |
03 Cryptography, Certificates and Keys, 04 Secure Architecture and Network Defences, 12 Security Models, Trusted Computing and Cryptanalysis, 13 Network, Facility and Distributed-System Design |
| 3.7 · Cryptanalysis |
03 Cryptography, Certificates and Keys, 04 Secure Architecture and Network Defences, 12 Security Models, Trusted Computing and Cryptanalysis, 13 Network, Facility and Distributed-System Design |
| 3.8 · Facility planning |
03 Cryptography, Certificates and Keys, 04 Secure Architecture and Network Defences, 12 Security Models, Trusted Computing and Cryptanalysis, 13 Network, Facility and Distributed-System Design |
| 3.9 · Facility controls |
03 Cryptography, Certificates and Keys, 04 Secure Architecture and Network Defences, 12 Security Models, Trusted Computing and Cryptanalysis, 13 Network, Facility and Distributed-System Design |
| 3.10 · System lifecycle |
03 Cryptography, Certificates and Keys, 04 Secure Architecture and Network Defences, 12 Security Models, Trusted Computing and Cryptanalysis, 13 Network, Facility and Distributed-System Design |
| 4.1 · Network design |
04 Secure Architecture and Network Defences, 13 Network, Facility and Distributed-System Design |
| 4.2 · Network components |
04 Secure Architecture and Network Defences, 13 Network, Facility and Distributed-System Design |
| 4.3 · Protected channels |
04 Secure Architecture and Network Defences, 13 Network, Facility and Distributed-System Design |
| 5.1 · Access scope |
06 Identity, Authentication and Privileged Access, 14 Identity Assurance and Access Models |
| 5.2 · Identity proofing |
06 Identity, Authentication and Privileged Access, 14 Identity Assurance and Access Models |
| 5.3 · Federation |
06 Identity, Authentication and Privileged Access, 14 Identity Assurance and Access Models |
| 5.4 · Authorization models |
06 Identity, Authentication and Privileged Access, 14 Identity Assurance and Access Models |
| 5.5 · Account lifecycle |
06 Identity, Authentication and Privileged Access, 14 Identity Assurance and Access Models |
| 5.6 · Authentication implementation |
06 Identity, Authentication and Privileged Access, 14 Identity Assurance and Access Models |
| 6.1 · Assurance strategy |
05 Hardening and Vulnerability Management, 09 Governance, Risk and Assurance, 15 Security Assessment and Assurance |
| 6.2 · Control testing |
05 Hardening and Vulnerability Management, 09 Governance, Risk and Assurance, 15 Security Assessment and Assurance |
| 6.3 · Metrics and evidence |
05 Hardening and Vulnerability Management, 09 Governance, Risk and Assurance, 15 Security Assessment and Assurance |
| 6.4 · Findings and reporting |
05 Hardening and Vulnerability Management, 09 Governance, Risk and Assurance, 15 Security Assessment and Assurance |
| 6.5 · Audit delivery |
05 Hardening and Vulnerability Management, 09 Governance, Risk and Assurance, 15 Security Assessment and Assurance |
| 7.1 · Investigations |
05 Hardening and Vulnerability Management, 07 Incident Response and Evidence, 08 Monitoring, Automation and Investigation, 09 Governance, Risk and Assurance, 10 Data Lifecycle, Privacy and Recovery, 13 Network, Facility and Distributed-System Design |
| 7.2 · Monitoring |
05 Hardening and Vulnerability Management, 07 Incident Response and Evidence, 08 Monitoring, Automation and Investigation, 09 Governance, Risk and Assurance, 10 Data Lifecycle, Privacy and Recovery, 13 Network, Facility and Distributed-System Design |
| 7.3 · Configuration |
05 Hardening and Vulnerability Management, 07 Incident Response and Evidence, 08 Monitoring, Automation and Investigation, 09 Governance, Risk and Assurance, 10 Data Lifecycle, Privacy and Recovery, 13 Network, Facility and Distributed-System Design |
| 7.4 · Operational discipline |
05 Hardening and Vulnerability Management, 07 Incident Response and Evidence, 08 Monitoring, Automation and Investigation, 09 Governance, Risk and Assurance, 10 Data Lifecycle, Privacy and Recovery, 13 Network, Facility and Distributed-System Design |
| 7.5 · Resource safeguards |
05 Hardening and Vulnerability Management, 07 Incident Response and Evidence, 08 Monitoring, Automation and Investigation, 09 Governance, Risk and Assurance, 10 Data Lifecycle, Privacy and Recovery, 13 Network, Facility and Distributed-System Design |
| 7.6 · Incidents |
05 Hardening and Vulnerability Management, 07 Incident Response and Evidence, 08 Monitoring, Automation and Investigation, 09 Governance, Risk and Assurance, 10 Data Lifecycle, Privacy and Recovery, 13 Network, Facility and Distributed-System Design |
| 7.7 · Detection controls |
05 Hardening and Vulnerability Management, 07 Incident Response and Evidence, 08 Monitoring, Automation and Investigation, 09 Governance, Risk and Assurance, 10 Data Lifecycle, Privacy and Recovery, 13 Network, Facility and Distributed-System Design |
| 7.8 · Patching |
05 Hardening and Vulnerability Management, 07 Incident Response and Evidence, 08 Monitoring, Automation and Investigation, 09 Governance, Risk and Assurance, 10 Data Lifecycle, Privacy and Recovery, 13 Network, Facility and Distributed-System Design |
| 7.9 · Changes |
05 Hardening and Vulnerability Management, 07 Incident Response and Evidence, 08 Monitoring, Automation and Investigation, 09 Governance, Risk and Assurance, 10 Data Lifecycle, Privacy and Recovery, 13 Network, Facility and Distributed-System Design |
| 7.10 · Recovery strategy |
05 Hardening and Vulnerability Management, 07 Incident Response and Evidence, 08 Monitoring, Automation and Investigation, 09 Governance, Risk and Assurance, 10 Data Lifecycle, Privacy and Recovery, 13 Network, Facility and Distributed-System Design |
| 7.11 · Recovery execution |
05 Hardening and Vulnerability Management, 07 Incident Response and Evidence, 08 Monitoring, Automation and Investigation, 09 Governance, Risk and Assurance, 10 Data Lifecycle, Privacy and Recovery, 13 Network, Facility and Distributed-System Design |
| 7.12 · Recovery exercises |
05 Hardening and Vulnerability Management, 07 Incident Response and Evidence, 08 Monitoring, Automation and Investigation, 09 Governance, Risk and Assurance, 10 Data Lifecycle, Privacy and Recovery, 13 Network, Facility and Distributed-System Design |
| 7.13 · Business continuity |
05 Hardening and Vulnerability Management, 07 Incident Response and Evidence, 08 Monitoring, Automation and Investigation, 09 Governance, Risk and Assurance, 10 Data Lifecycle, Privacy and Recovery, 13 Network, Facility and Distributed-System Design |
| 7.14 · Physical protection |
05 Hardening and Vulnerability Management, 07 Incident Response and Evidence, 08 Monitoring, Automation and Investigation, 09 Governance, Risk and Assurance, 10 Data Lifecycle, Privacy and Recovery, 13 Network, Facility and Distributed-System Design |
| 7.15 · People safety |
05 Hardening and Vulnerability Management, 07 Incident Response and Evidence, 08 Monitoring, Automation and Investigation, 09 Governance, Risk and Assurance, 10 Data Lifecycle, Privacy and Recovery, 13 Network, Facility and Distributed-System Design |
| 8.1 · Secure lifecycle |
02 Threats, Attacks and Indicators, 16 Secure Software Lifecycle and Supply Chains |
| 8.2 · Development ecosystem |
02 Threats, Attacks and Indicators, 16 Secure Software Lifecycle and Supply Chains |
| 8.3 · Security effectiveness |
02 Threats, Attacks and Indicators, 16 Secure Software Lifecycle and Supply Chains |
| 8.4 · Acquired software |
02 Threats, Attacks and Indicators, 16 Secure Software Lifecycle and Supply Chains |
| 8.5 · Coding standards |
02 Threats, Attacks and Indicators, 16 Secure Software Lifecycle and Supply Chains |