IT Audit Factory · Evidence-first audit operationsFree · Professional · MSP
Products / Frameworks / 4.1.0

CMMC Level 2

Uses common technical evidence domains for CMMC Level 2 readiness. Final CMMC determinations remain assessor-controlled.

This is the MSP 4.1.0 catalog snapshot, not the full publisher standard and not an assertion of Free/Professional parity. All conclusions require scope, adequate evidence and an authorized reviewer.
110 catalog entries16 with exact test mappings74 family-support entries20 manual / unmapped

Control / requirementPackaged guidance & evidenceCoverage
AC.L2-3.1.1AC Access ControlLimit system access to authorized users, processes acting for users, and authorized devices.
Evidence and test details
  • ENTRA-GUEST-001 ENTRAEnabled guest identities are technical evidence supporting authorized-user access review.

Mapped in the package; actual collection depends on targets, permissions, dependencies and applicability. A successful test is not an automatic compliance result.

Mapped technical checks
AC.L2-3.1.2AC Access ControlLimit authorized users to permitted transactions and functions.
Evidence and test details

Applicable supporting collectors: ADSEC, ENTRA, GPO, NETWORK.

No exact requirement-to-test mapping is published for this row in the 4.1.0 mapping CSV. Family applicability is not proof that this requirement receives a mapped test result.

Family supporting scope
AC.L2-3.1.3AC Access ControlControl the flow of CUI according to approved authorizations.
Evidence and test details

Applicable supporting collectors: ADSEC, ENTRA, GPO, NETWORK.

No exact requirement-to-test mapping is published for this row in the 4.1.0 mapping CSV. Family applicability is not proof that this requirement receives a mapped test result.

Family supporting scope
AC.L2-3.1.4AC Access ControlSeparate duties to reduce risk of malevolent activity without collusion.
Evidence and test details

Applicable supporting collectors: ADSEC, ENTRA, GPO, NETWORK.

No exact requirement-to-test mapping is published for this row in the 4.1.0 mapping CSV. Family applicability is not proof that this requirement receives a mapped test result.

Family supporting scope
AC.L2-3.1.5AC Access ControlApply least privilege, including for specific security functions and privileged accounts.
Evidence and test details
  • AD-PRIV-001 ADSECPrivileged group membership is direct technical evidence supporting least privilege review.
  • AD-DELEGATION-001 ADSECKerberos delegation configuration is technical evidence supporting least privilege review.
  • ENTRA-ROLE-001 ENTRADirectory role assignments are technical evidence supporting least privilege review.

Mapped in the package; actual collection depends on targets, permissions, dependencies and applicability. A successful test is not an automatic compliance result.

Mapped technical checks
AC.L2-3.1.6AC Access ControlUse non-privileged accounts or roles when accessing nonsecurity functions.
Evidence and test details

Applicable supporting collectors: ADSEC, ENTRA, GPO, NETWORK.

No exact requirement-to-test mapping is published for this row in the 4.1.0 mapping CSV. Family applicability is not proof that this requirement receives a mapped test result.

Family supporting scope
AC.L2-3.1.7AC Access ControlPrevent non-privileged users from executing privileged functions and capture privileged execution in audit logs.
Evidence and test details

Applicable supporting collectors: ADSEC, ENTRA, GPO, NETWORK.

No exact requirement-to-test mapping is published for this row in the 4.1.0 mapping CSV. Family applicability is not proof that this requirement receives a mapped test result.

Family supporting scope
AC.L2-3.1.8AC Access ControlLimit unsuccessful logon attempts.
Evidence and test details

Applicable supporting collectors: ADSEC, ENTRA, GPO, NETWORK.

No exact requirement-to-test mapping is published for this row in the 4.1.0 mapping CSV. Family applicability is not proof that this requirement receives a mapped test result.

Family supporting scope
AC.L2-3.1.9AC Access ControlProvide privacy and security notices consistent with applicable CUI rules.
Evidence and test details

Applicable supporting collectors: ADSEC, ENTRA, GPO, NETWORK.

No exact requirement-to-test mapping is published for this row in the 4.1.0 mapping CSV. Family applicability is not proof that this requirement receives a mapped test result.

Family supporting scope
AC.L2-3.1.10AC Access ControlUse session lock with pattern-hiding displays after inactivity.
Evidence and test details

Applicable supporting collectors: ADSEC, ENTRA, GPO, NETWORK.

No exact requirement-to-test mapping is published for this row in the 4.1.0 mapping CSV. Family applicability is not proof that this requirement receives a mapped test result.

Family supporting scope
AC.L2-3.1.11AC Access ControlTerminate user sessions after defined conditions.
Evidence and test details

Applicable supporting collectors: ADSEC, ENTRA, GPO, NETWORK.

No exact requirement-to-test mapping is published for this row in the 4.1.0 mapping CSV. Family applicability is not proof that this requirement receives a mapped test result.

Family supporting scope
AC.L2-3.1.12AC Access ControlMonitor and control remote access sessions.
Evidence and test details

Applicable supporting collectors: ADSEC, ENTRA, GPO, NETWORK.

No exact requirement-to-test mapping is published for this row in the 4.1.0 mapping CSV. Family applicability is not proof that this requirement receives a mapped test result.

Family supporting scope
AC.L2-3.1.13AC Access ControlUse cryptographic mechanisms to protect confidentiality of remote access sessions.
Evidence and test details

Applicable supporting collectors: ADSEC, ENTRA, GPO, NETWORK.

No exact requirement-to-test mapping is published for this row in the 4.1.0 mapping CSV. Family applicability is not proof that this requirement receives a mapped test result.

Family supporting scope
AC.L2-3.1.14AC Access ControlRoute remote access through managed access control points.
Evidence and test details

Applicable supporting collectors: ADSEC, ENTRA, GPO, NETWORK.

No exact requirement-to-test mapping is published for this row in the 4.1.0 mapping CSV. Family applicability is not proof that this requirement receives a mapped test result.

Family supporting scope
AC.L2-3.1.15AC Access ControlAuthorize remote privileged commands and remote access to security-relevant information.
Evidence and test details

Applicable supporting collectors: ADSEC, ENTRA, GPO, NETWORK.

No exact requirement-to-test mapping is published for this row in the 4.1.0 mapping CSV. Family applicability is not proof that this requirement receives a mapped test result.

Family supporting scope
AC.L2-3.1.16AC Access ControlAuthorize wireless access before allowing connections.
Evidence and test details

Applicable supporting collectors: ADSEC, ENTRA, GPO, NETWORK.

No exact requirement-to-test mapping is published for this row in the 4.1.0 mapping CSV. Family applicability is not proof that this requirement receives a mapped test result.

Family supporting scope
AC.L2-3.1.17AC Access ControlProtect wireless access using authentication and encryption.
Evidence and test details

Applicable supporting collectors: ADSEC, ENTRA, GPO, NETWORK.

No exact requirement-to-test mapping is published for this row in the 4.1.0 mapping CSV. Family applicability is not proof that this requirement receives a mapped test result.

Family supporting scope
AC.L2-3.1.18AC Access ControlControl connection of mobile devices.
Evidence and test details

Applicable supporting collectors: ADSEC, ENTRA, GPO, NETWORK.

No exact requirement-to-test mapping is published for this row in the 4.1.0 mapping CSV. Family applicability is not proof that this requirement receives a mapped test result.

Family supporting scope
AC.L2-3.1.19AC Access ControlEncrypt CUI on mobile devices and mobile computing platforms.
Evidence and test details

Applicable supporting collectors: ADSEC, ENTRA, GPO, NETWORK.

No exact requirement-to-test mapping is published for this row in the 4.1.0 mapping CSV. Family applicability is not proof that this requirement receives a mapped test result.

Family supporting scope
AC.L2-3.1.20AC Access ControlVerify and control connections to external systems.
Evidence and test details

Applicable supporting collectors: ADSEC, ENTRA, GPO, NETWORK.

No exact requirement-to-test mapping is published for this row in the 4.1.0 mapping CSV. Family applicability is not proof that this requirement receives a mapped test result.

Family supporting scope
AC.L2-3.1.21AC Access ControlLimit use of portable storage devices on external systems.
Evidence and test details

Applicable supporting collectors: ADSEC, ENTRA, GPO, NETWORK.

No exact requirement-to-test mapping is published for this row in the 4.1.0 mapping CSV. Family applicability is not proof that this requirement receives a mapped test result.

Family supporting scope
AC.L2-3.1.22AC Access ControlControl CUI posted or processed on publicly accessible systems.
Evidence and test details

Applicable supporting collectors: ADSEC, ENTRA, GPO, NETWORK.

No exact requirement-to-test mapping is published for this row in the 4.1.0 mapping CSV. Family applicability is not proof that this requirement receives a mapped test result.

Family supporting scope
AT.L2-3.2.1AT Awareness & TrainingEnsure managers, administrators, and users know security risks and applicable policies and procedures.
Evidence and test details

No exact automated mapping is packaged for this entry. Supply and review policies, records, interviews, observations or other appropriate evidence; absence of a mapping is not PASS.

Manual / no exact mapping
AT.L2-3.2.2AT Awareness & TrainingTrain personnel to perform assigned information-security duties.
Evidence and test details

No exact automated mapping is packaged for this entry. Supply and review policies, records, interviews, observations or other appropriate evidence; absence of a mapping is not PASS.

Manual / no exact mapping
AT.L2-3.2.3AT Awareness & TrainingProvide awareness training for recognizing and reporting potential insider threats.
Evidence and test details

No exact automated mapping is packaged for this entry. Supply and review policies, records, interviews, observations or other appropriate evidence; absence of a mapping is not PASS.

Manual / no exact mapping
AU.L2-3.3.1AU Audit & AccountabilityCreate and retain system audit logs needed to monitor, analyze, investigate, and report unlawful or unauthorized activity.
Evidence and test details

Applicable supporting collectors: ADSEC, ENTRA, NETWORK, WINDOWS.

No exact requirement-to-test mapping is published for this row in the 4.1.0 mapping CSV. Family applicability is not proof that this requirement receives a mapped test result.

Family supporting scope
AU.L2-3.3.2AU Audit & AccountabilityEnsure individual user actions can be uniquely traced for accountability.
Evidence and test details

Applicable supporting collectors: ADSEC, ENTRA, NETWORK, WINDOWS.

No exact requirement-to-test mapping is published for this row in the 4.1.0 mapping CSV. Family applicability is not proof that this requirement receives a mapped test result.

Family supporting scope
AU.L2-3.3.3AU Audit & AccountabilityReview and update logged events.
Evidence and test details

Applicable supporting collectors: ADSEC, ENTRA, NETWORK, WINDOWS.

No exact requirement-to-test mapping is published for this row in the 4.1.0 mapping CSV. Family applicability is not proof that this requirement receives a mapped test result.

Family supporting scope
AU.L2-3.3.4AU Audit & AccountabilityAlert on audit logging process failures.
Evidence and test details

Applicable supporting collectors: ADSEC, ENTRA, NETWORK, WINDOWS.

No exact requirement-to-test mapping is published for this row in the 4.1.0 mapping CSV. Family applicability is not proof that this requirement receives a mapped test result.

Family supporting scope
AU.L2-3.3.5AU Audit & AccountabilityCorrelate audit review, analysis, and reporting processes for investigation and response.
Evidence and test details

Applicable supporting collectors: ADSEC, ENTRA, NETWORK, WINDOWS.

No exact requirement-to-test mapping is published for this row in the 4.1.0 mapping CSV. Family applicability is not proof that this requirement receives a mapped test result.

Family supporting scope
AU.L2-3.3.6AU Audit & AccountabilityProvide audit reduction and report generation supporting on-demand analysis.
Evidence and test details

Applicable supporting collectors: ADSEC, ENTRA, NETWORK, WINDOWS.

No exact requirement-to-test mapping is published for this row in the 4.1.0 mapping CSV. Family applicability is not proof that this requirement receives a mapped test result.

Family supporting scope
AU.L2-3.3.7AU Audit & AccountabilitySynchronize clocks with authoritative sources for audit timestamp generation.
Evidence and test details
  • VMW-TIME-001 VMWAREHypervisor time synchronization evidence supports authoritative audit timestamp generation.

Mapped in the package; actual collection depends on targets, permissions, dependencies and applicability. A successful test is not an automatic compliance result.

Mapped technical checks
AU.L2-3.3.8AU Audit & AccountabilityProtect audit information and audit tools from unauthorized access, modification, and deletion.
Evidence and test details

Applicable supporting collectors: ADSEC, ENTRA, NETWORK, WINDOWS.

No exact requirement-to-test mapping is published for this row in the 4.1.0 mapping CSV. Family applicability is not proof that this requirement receives a mapped test result.

Family supporting scope
AU.L2-3.3.9AU Audit & AccountabilityLimit management of audit logging functionality to privileged users.
Evidence and test details

Applicable supporting collectors: ADSEC, ENTRA, NETWORK, WINDOWS.

No exact requirement-to-test mapping is published for this row in the 4.1.0 mapping CSV. Family applicability is not proof that this requirement receives a mapped test result.

Family supporting scope
CM.L2-3.4.1CM Configuration ManagementEstablish and maintain baseline configurations and inventories throughout system life cycles.
Evidence and test details
  • AD-COMPUTER-INVENTORY-001 ADSECDirectory computer inventory supports system inventory and baseline configuration review.
  • ASSETREC-AD-001 ASSETRECCross-source server reconciliation supports system inventory and baseline configuration review.
  • WIN-INVENTORY-COVERAGE-001 WINDOWSCanonical Windows inventory coverage supports system inventory and baseline configuration review.
  • WIN-ROLE-INVENTORY-001 WINDOWSWindows role inventory supports system inventory and baseline configuration review.
  • GPO-INVENTORY-001 GPOGroup Policy inventory supports baseline configuration review.

Mapped in the package; actual collection depends on targets, permissions, dependencies and applicability. A successful test is not an automatic compliance result.

Mapped technical checks
CM.L2-3.4.2CM Configuration ManagementEstablish and enforce security configuration settings for IT products.
Evidence and test details
  • GPO-DETAIL-001 GPOGroup Policy configuration metadata supports secure configuration settings review.

Mapped in the package; actual collection depends on targets, permissions, dependencies and applicability. A successful test is not an automatic compliance result.

Mapped technical checks
CM.L2-3.4.3CM Configuration ManagementTrack, review, approve or disapprove, and log system changes.
Evidence and test details

Applicable supporting collectors: GPO, STORAGE, VMWARE, WINDOWS.

No exact requirement-to-test mapping is published for this row in the 4.1.0 mapping CSV. Family applicability is not proof that this requirement receives a mapped test result.

Family supporting scope
CM.L2-3.4.4CM Configuration ManagementAnalyze security impacts before implementing changes.
Evidence and test details

Applicable supporting collectors: GPO, STORAGE, VMWARE, WINDOWS.

No exact requirement-to-test mapping is published for this row in the 4.1.0 mapping CSV. Family applicability is not proof that this requirement receives a mapped test result.

Family supporting scope
CM.L2-3.4.5CM Configuration ManagementDefine, document, approve, and enforce physical and logical access restrictions associated with system changes.
Evidence and test details

Applicable supporting collectors: GPO, STORAGE, VMWARE, WINDOWS.

No exact requirement-to-test mapping is published for this row in the 4.1.0 mapping CSV. Family applicability is not proof that this requirement receives a mapped test result.

Family supporting scope
CM.L2-3.4.6CM Configuration ManagementApply least functionality by configuring systems to provide only essential capabilities.
Evidence and test details

Applicable supporting collectors: GPO, STORAGE, VMWARE, WINDOWS.

No exact requirement-to-test mapping is published for this row in the 4.1.0 mapping CSV. Family applicability is not proof that this requirement receives a mapped test result.

Family supporting scope
CM.L2-3.4.7CM Configuration ManagementRestrict or disable nonessential programs, functions, ports, protocols, and services.
Evidence and test details
  • WIN-SMB1-001 WINDOWSSMBv1 state directly supports review of nonessential protocols and services.

Mapped in the package; actual collection depends on targets, permissions, dependencies and applicability. A successful test is not an automatic compliance result.

Mapped technical checks
CM.L2-3.4.8CM Configuration ManagementUse deny-by-exception or allow-by-exception policies to prevent unauthorized program execution.
Evidence and test details

Applicable supporting collectors: GPO, STORAGE, VMWARE, WINDOWS.

No exact requirement-to-test mapping is published for this row in the 4.1.0 mapping CSV. Family applicability is not proof that this requirement receives a mapped test result.

Family supporting scope
CM.L2-3.4.9CM Configuration ManagementControl and monitor user-installed software.
Evidence and test details

Applicable supporting collectors: GPO, STORAGE, VMWARE, WINDOWS.

No exact requirement-to-test mapping is published for this row in the 4.1.0 mapping CSV. Family applicability is not proof that this requirement receives a mapped test result.

Family supporting scope
IA.L2-3.5.1IA Identification & AuthenticationIdentify system users, processes acting for users, and devices.
Evidence and test details

Applicable supporting collectors: ADSEC, ENTRA, GPO.

No exact requirement-to-test mapping is published for this row in the 4.1.0 mapping CSV. Family applicability is not proof that this requirement receives a mapped test result.

Family supporting scope
IA.L2-3.5.2IA Identification & AuthenticationAuthenticate identities before allowing access.
Evidence and test details

Applicable supporting collectors: ADSEC, ENTRA, GPO.

No exact requirement-to-test mapping is published for this row in the 4.1.0 mapping CSV. Family applicability is not proof that this requirement receives a mapped test result.

Family supporting scope
IA.L2-3.5.3IA Identification & AuthenticationUse multifactor authentication for local and network access to privileged accounts and for network access to non-privileged accounts.
Evidence and test details
  • ENTRA-MFA-REG-001 ENTRAMFA registration coverage is technical evidence supporting the MFA requirement; enforcement and full scope still require assessor validation.

Mapped in the package; actual collection depends on targets, permissions, dependencies and applicability. A successful test is not an automatic compliance result.

Mapped technical checks
IA.L2-3.5.4IA Identification & AuthenticationUse replay-resistant authentication for network access to privileged and non-privileged accounts.
Evidence and test details

Applicable supporting collectors: ADSEC, ENTRA, GPO.

No exact requirement-to-test mapping is published for this row in the 4.1.0 mapping CSV. Family applicability is not proof that this requirement receives a mapped test result.

Family supporting scope
IA.L2-3.5.5IA Identification & AuthenticationPrevent reuse of identifiers for a defined period.
Evidence and test details

Applicable supporting collectors: ADSEC, ENTRA, GPO.

No exact requirement-to-test mapping is published for this row in the 4.1.0 mapping CSV. Family applicability is not proof that this requirement receives a mapped test result.

Family supporting scope
IA.L2-3.5.6IA Identification & AuthenticationDisable identifiers after a defined period of inactivity.
Evidence and test details
  • AD-LIFECYCLE-001 ADSECStale enabled identifiers are direct technical evidence for identifier inactivity handling.

Mapped in the package; actual collection depends on targets, permissions, dependencies and applicability. A successful test is not an automatic compliance result.

Mapped technical checks
IA.L2-3.5.7IA Identification & AuthenticationEnforce password complexity and changed-character requirements.
Evidence and test details

Applicable supporting collectors: ADSEC, ENTRA, GPO.

No exact requirement-to-test mapping is published for this row in the 4.1.0 mapping CSV. Family applicability is not proof that this requirement receives a mapped test result.

Family supporting scope
IA.L2-3.5.8IA Identification & AuthenticationProhibit password reuse for a specified number of generations.
Evidence and test details

Applicable supporting collectors: ADSEC, ENTRA, GPO.

No exact requirement-to-test mapping is published for this row in the 4.1.0 mapping CSV. Family applicability is not proof that this requirement receives a mapped test result.

Family supporting scope
IA.L2-3.5.9IA Identification & AuthenticationAllow temporary passwords only for immediate logon and force permanent change.
Evidence and test details

Applicable supporting collectors: ADSEC, ENTRA, GPO.

No exact requirement-to-test mapping is published for this row in the 4.1.0 mapping CSV. Family applicability is not proof that this requirement receives a mapped test result.

Family supporting scope
IA.L2-3.5.10IA Identification & AuthenticationStore and transmit only cryptographically protected passwords.
Evidence and test details

Applicable supporting collectors: ADSEC, ENTRA, GPO.

No exact requirement-to-test mapping is published for this row in the 4.1.0 mapping CSV. Family applicability is not proof that this requirement receives a mapped test result.

Family supporting scope
IA.L2-3.5.11IA Identification & AuthenticationObscure authentication feedback.
Evidence and test details

Applicable supporting collectors: ADSEC, ENTRA, GPO.

No exact requirement-to-test mapping is published for this row in the 4.1.0 mapping CSV. Family applicability is not proof that this requirement receives a mapped test result.

Family supporting scope
IR.L2-3.6.1IR Incident ResponseEstablish an operational incident-handling capability covering preparation, detection, analysis, containment, recovery, and user response.
Evidence and test details

No exact automated mapping is packaged for this entry. Supply and review policies, records, interviews, observations or other appropriate evidence; absence of a mapping is not PASS.

Manual / no exact mapping
IR.L2-3.6.2IR Incident ResponseTrack, document, and report incidents to designated personnel and authorities.
Evidence and test details

No exact automated mapping is packaged for this entry. Supply and review policies, records, interviews, observations or other appropriate evidence; absence of a mapping is not PASS.

Manual / no exact mapping
IR.L2-3.6.3IR Incident ResponseTest the organizational incident-response capability.
Evidence and test details

No exact automated mapping is packaged for this entry. Supply and review policies, records, interviews, observations or other appropriate evidence; absence of a mapping is not PASS.

Manual / no exact mapping
MA.L2-3.7.1MA MaintenancePerform system maintenance.
Evidence and test details

No exact automated mapping is packaged for this entry. Supply and review policies, records, interviews, observations or other appropriate evidence; absence of a mapping is not PASS.

Manual / no exact mapping
MA.L2-3.7.2MA MaintenanceProvide controls over maintenance tools, techniques, mechanisms, and personnel.
Evidence and test details

No exact automated mapping is packaged for this entry. Supply and review policies, records, interviews, observations or other appropriate evidence; absence of a mapping is not PASS.

Manual / no exact mapping
MA.L2-3.7.3MA MaintenanceEnsure equipment removed for off-site maintenance is sanitized of CUI.
Evidence and test details

No exact automated mapping is packaged for this entry. Supply and review policies, records, interviews, observations or other appropriate evidence; absence of a mapping is not PASS.

Manual / no exact mapping
MA.L2-3.7.4MA MaintenanceCheck media containing diagnostic and test programs for malicious code before use.
Evidence and test details

No exact automated mapping is packaged for this entry. Supply and review policies, records, interviews, observations or other appropriate evidence; absence of a mapping is not PASS.

Manual / no exact mapping
MA.L2-3.7.5MA MaintenanceRequire multifactor authentication for nonlocal maintenance sessions and terminate them when maintenance is complete.
Evidence and test details

No exact automated mapping is packaged for this entry. Supply and review policies, records, interviews, observations or other appropriate evidence; absence of a mapping is not PASS.

Manual / no exact mapping
MA.L2-3.7.6MA MaintenanceSupervise maintenance personnel without required access authorization.
Evidence and test details

No exact automated mapping is packaged for this entry. Supply and review policies, records, interviews, observations or other appropriate evidence; absence of a mapping is not PASS.

Manual / no exact mapping
MP.L2-3.8.1MP Media ProtectionProtect system media containing CUI, both paper and digital.
Evidence and test details

Applicable supporting collectors: BACKUP, STORAGE.

No exact requirement-to-test mapping is published for this row in the 4.1.0 mapping CSV. Family applicability is not proof that this requirement receives a mapped test result.

Family supporting scope
MP.L2-3.8.2MP Media ProtectionLimit access to CUI on media to authorized users.
Evidence and test details

Applicable supporting collectors: BACKUP, STORAGE.

No exact requirement-to-test mapping is published for this row in the 4.1.0 mapping CSV. Family applicability is not proof that this requirement receives a mapped test result.

Family supporting scope
MP.L2-3.8.3MP Media ProtectionSanitize or destroy media before disposal or release for reuse.
Evidence and test details

Applicable supporting collectors: BACKUP, STORAGE.

No exact requirement-to-test mapping is published for this row in the 4.1.0 mapping CSV. Family applicability is not proof that this requirement receives a mapped test result.

Family supporting scope
MP.L2-3.8.4MP Media ProtectionMark media with required CUI markings and distribution limitations.
Evidence and test details

Applicable supporting collectors: BACKUP, STORAGE.

No exact requirement-to-test mapping is published for this row in the 4.1.0 mapping CSV. Family applicability is not proof that this requirement receives a mapped test result.

Family supporting scope
MP.L2-3.8.5MP Media ProtectionControl access to media during transport outside controlled areas and maintain accountability.
Evidence and test details

Applicable supporting collectors: BACKUP, STORAGE.

No exact requirement-to-test mapping is published for this row in the 4.1.0 mapping CSV. Family applicability is not proof that this requirement receives a mapped test result.

Family supporting scope
MP.L2-3.8.6MP Media ProtectionUse cryptography to protect confidentiality of CUI on digital media during transport unless otherwise physically protected.
Evidence and test details

Applicable supporting collectors: BACKUP, STORAGE.

No exact requirement-to-test mapping is published for this row in the 4.1.0 mapping CSV. Family applicability is not proof that this requirement receives a mapped test result.

Family supporting scope
MP.L2-3.8.7MP Media ProtectionControl removable media use on system components.
Evidence and test details

Applicable supporting collectors: BACKUP, STORAGE.

No exact requirement-to-test mapping is published for this row in the 4.1.0 mapping CSV. Family applicability is not proof that this requirement receives a mapped test result.

Family supporting scope
MP.L2-3.8.8MP Media ProtectionProhibit use of portable storage devices without identifiable owners.
Evidence and test details

Applicable supporting collectors: BACKUP, STORAGE.

No exact requirement-to-test mapping is published for this row in the 4.1.0 mapping CSV. Family applicability is not proof that this requirement receives a mapped test result.

Family supporting scope
MP.L2-3.8.9MP Media ProtectionProtect backup CUI at storage locations.
Evidence and test details
  • VEEAM-REPO-001 BACKUPBackup repository evidence supports protection of backup CUI at storage locations.
  • VEEAM-JOB-001 BACKUPBackup job results support protection and availability review for backup CUI.
  • VEEAM-REST-JOB-001 BACKUPBackup job results support protection and availability review for backup CUI.

Mapped in the package; actual collection depends on targets, permissions, dependencies and applicability. A successful test is not an automatic compliance result.

Mapped technical checks
PS.L2-3.9.1PS Personnel SecurityScreen individuals before authorizing access to systems containing CUI.
Evidence and test details

No exact automated mapping is packaged for this entry. Supply and review policies, records, interviews, observations or other appropriate evidence; absence of a mapping is not PASS.

Manual / no exact mapping
PS.L2-3.9.2PS Personnel SecurityProtect systems containing CUI during and after personnel actions such as termination and transfer.
Evidence and test details

No exact automated mapping is packaged for this entry. Supply and review policies, records, interviews, observations or other appropriate evidence; absence of a mapping is not PASS.

Manual / no exact mapping
PE.L2-3.10.1PE Physical ProtectionLimit physical access to systems, equipment, and operating environments to authorized individuals.
Evidence and test details

No exact automated mapping is packaged for this entry. Supply and review policies, records, interviews, observations or other appropriate evidence; absence of a mapping is not PASS.

Manual / no exact mapping
PE.L2-3.10.2PE Physical ProtectionProtect and monitor physical facilities and support infrastructure.
Evidence and test details

No exact automated mapping is packaged for this entry. Supply and review policies, records, interviews, observations or other appropriate evidence; absence of a mapping is not PASS.

Manual / no exact mapping
PE.L2-3.10.3PE Physical ProtectionEscort visitors and monitor visitor activity.
Evidence and test details

No exact automated mapping is packaged for this entry. Supply and review policies, records, interviews, observations or other appropriate evidence; absence of a mapping is not PASS.

Manual / no exact mapping
PE.L2-3.10.4PE Physical ProtectionMaintain audit logs of physical access.
Evidence and test details

No exact automated mapping is packaged for this entry. Supply and review policies, records, interviews, observations or other appropriate evidence; absence of a mapping is not PASS.

Manual / no exact mapping
PE.L2-3.10.5PE Physical ProtectionControl and manage physical access devices.
Evidence and test details

No exact automated mapping is packaged for this entry. Supply and review policies, records, interviews, observations or other appropriate evidence; absence of a mapping is not PASS.

Manual / no exact mapping
PE.L2-3.10.6PE Physical ProtectionEnforce safeguarding measures for CUI at alternate work sites.
Evidence and test details

No exact automated mapping is packaged for this entry. Supply and review policies, records, interviews, observations or other appropriate evidence; absence of a mapping is not PASS.

Manual / no exact mapping
RA.L2-3.11.1RA Risk AssessmentPeriodically assess risk to operations, assets, and individuals from operation of systems and processing/storage/transmission of CUI.
Evidence and test details

Applicable supporting collectors: VULN.

No exact requirement-to-test mapping is published for this row in the 4.1.0 mapping CSV. Family applicability is not proof that this requirement receives a mapped test result.

Family supporting scope
RA.L2-3.11.2RA Risk AssessmentScan for vulnerabilities periodically and when new vulnerabilities are identified.
Evidence and test details
  • VULN-IMPORT-001 VULNSuccessful vulnerability scanner evidence ingestion supports vulnerability scanning review.
  • VULN-HIGH-001 VULNScanner findings are technical evidence supporting vulnerability scanning review.

Mapped in the package; actual collection depends on targets, permissions, dependencies and applicability. A successful test is not an automatic compliance result.

Mapped technical checks
RA.L2-3.11.3RA Risk AssessmentRemediate vulnerabilities according to risk assessments.
Evidence and test details
  • VULN-AGING-001 VULNAged high-risk findings are technical evidence supporting risk-based vulnerability remediation.

Mapped in the package; actual collection depends on targets, permissions, dependencies and applicability. A successful test is not an automatic compliance result.

Mapped technical checks
CA.L2-3.12.1CA Security AssessmentPeriodically assess security controls to determine whether they are effective.
Evidence and test details

Applicable supporting collectors: ASSETREC, VULN.

No exact requirement-to-test mapping is published for this row in the 4.1.0 mapping CSV. Family applicability is not proof that this requirement receives a mapped test result.

Family supporting scope
CA.L2-3.12.2CA Security AssessmentDevelop and implement plans of action to correct deficiencies and reduce or eliminate vulnerabilities.
Evidence and test details

Applicable supporting collectors: ASSETREC, VULN.

No exact requirement-to-test mapping is published for this row in the 4.1.0 mapping CSV. Family applicability is not proof that this requirement receives a mapped test result.

Family supporting scope
CA.L2-3.12.3CA Security AssessmentMonitor security controls continuously to ensure ongoing effectiveness.
Evidence and test details

Applicable supporting collectors: ASSETREC, VULN.

No exact requirement-to-test mapping is published for this row in the 4.1.0 mapping CSV. Family applicability is not proof that this requirement receives a mapped test result.

Family supporting scope
CA.L2-3.12.4CA Security AssessmentDevelop, document, and periodically update system security plans describing boundaries, operating environments, implementation, and relationships.
Evidence and test details

Applicable supporting collectors: ASSETREC, VULN.

No exact requirement-to-test mapping is published for this row in the 4.1.0 mapping CSV. Family applicability is not proof that this requirement receives a mapped test result.

Family supporting scope
SC.L2-3.13.1SC System & Communications ProtectionMonitor, control, and protect communications at external and key internal system boundaries.
Evidence and test details
  • WIN-FW-001 WINDOWSHost firewall profile state is technical evidence supporting boundary protection.

Mapped in the package; actual collection depends on targets, permissions, dependencies and applicability. A successful test is not an automatic compliance result.

Mapped technical checks
SC.L2-3.13.2SC System & Communications ProtectionUse secure architectural designs and engineering principles promoting effective information security.
Evidence and test details

Applicable supporting collectors: CERTTLS, ENTRA, NETWORK, VMWARE.

No exact requirement-to-test mapping is published for this row in the 4.1.0 mapping CSV. Family applicability is not proof that this requirement receives a mapped test result.

Family supporting scope
SC.L2-3.13.3SC System & Communications ProtectionSeparate user functionality from system-management functionality.
Evidence and test details

Applicable supporting collectors: CERTTLS, ENTRA, NETWORK, VMWARE.

No exact requirement-to-test mapping is published for this row in the 4.1.0 mapping CSV. Family applicability is not proof that this requirement receives a mapped test result.

Family supporting scope
SC.L2-3.13.4SC System & Communications ProtectionPrevent unauthorized and unintended information transfer through shared system resources.
Evidence and test details

Applicable supporting collectors: CERTTLS, ENTRA, NETWORK, VMWARE.

No exact requirement-to-test mapping is published for this row in the 4.1.0 mapping CSV. Family applicability is not proof that this requirement receives a mapped test result.

Family supporting scope
SC.L2-3.13.5SC System & Communications ProtectionImplement subnetworks for publicly accessible components separated from internal networks.
Evidence and test details

Applicable supporting collectors: CERTTLS, ENTRA, NETWORK, VMWARE.

No exact requirement-to-test mapping is published for this row in the 4.1.0 mapping CSV. Family applicability is not proof that this requirement receives a mapped test result.

Family supporting scope
SC.L2-3.13.6SC System & Communications ProtectionDeny network communications traffic by default and allow by exception at external boundaries.
Evidence and test details

Applicable supporting collectors: CERTTLS, ENTRA, NETWORK, VMWARE.

No exact requirement-to-test mapping is published for this row in the 4.1.0 mapping CSV. Family applicability is not proof that this requirement receives a mapped test result.

Family supporting scope
SC.L2-3.13.7SC System & Communications ProtectionPrevent remote devices from simultaneously connecting to organizational systems and external networks via split tunneling.
Evidence and test details

Applicable supporting collectors: CERTTLS, ENTRA, NETWORK, VMWARE.

No exact requirement-to-test mapping is published for this row in the 4.1.0 mapping CSV. Family applicability is not proof that this requirement receives a mapped test result.

Family supporting scope
SC.L2-3.13.8SC System & Communications ProtectionUse cryptographic mechanisms to prevent unauthorized disclosure of CUI during transmission unless otherwise physically protected.
Evidence and test details
  • CERTTLS-POSTURE-001 CERTTLSTLS protocol and certificate posture supports cryptographic protection of CUI in transit when the assessed service is in scope.
  • STOR-DATA-IN-FLIGHT-ENCRYPTION-001 STORAGEStorage data-plane encryption evidence supports cryptographic protection of CUI in transit.
  • STOR-MGMT-TRANSIT-ENCRYPTION-001 STORAGEStorage management-plane encryption evidence supports protected management communications.

Mapped in the package; actual collection depends on targets, permissions, dependencies and applicability. A successful test is not an automatic compliance result.

Mapped technical checks
SC.L2-3.13.9SC System & Communications ProtectionTerminate network connections at the end of sessions or after defined inactivity.
Evidence and test details

Applicable supporting collectors: CERTTLS, ENTRA, NETWORK, VMWARE.

No exact requirement-to-test mapping is published for this row in the 4.1.0 mapping CSV. Family applicability is not proof that this requirement receives a mapped test result.

Family supporting scope
SC.L2-3.13.10SC System & Communications ProtectionEstablish and manage cryptographic keys when cryptography is used.
Evidence and test details

Applicable supporting collectors: CERTTLS, ENTRA, NETWORK, VMWARE.

No exact requirement-to-test mapping is published for this row in the 4.1.0 mapping CSV. Family applicability is not proof that this requirement receives a mapped test result.

Family supporting scope
SC.L2-3.13.11SC System & Communications ProtectionUse FIPS-validated cryptography when protecting confidentiality of CUI.
Evidence and test details

Applicable supporting collectors: CERTTLS, ENTRA, NETWORK, VMWARE.

No exact requirement-to-test mapping is published for this row in the 4.1.0 mapping CSV. Family applicability is not proof that this requirement receives a mapped test result.

Family supporting scope
SC.L2-3.13.12SC System & Communications ProtectionProhibit remote activation of collaborative computing devices and provide indication when they are in use.
Evidence and test details

Applicable supporting collectors: CERTTLS, ENTRA, NETWORK, VMWARE.

No exact requirement-to-test mapping is published for this row in the 4.1.0 mapping CSV. Family applicability is not proof that this requirement receives a mapped test result.

Family supporting scope
SC.L2-3.13.13SC System & Communications ProtectionControl and monitor mobile code use.
Evidence and test details

Applicable supporting collectors: CERTTLS, ENTRA, NETWORK, VMWARE.

No exact requirement-to-test mapping is published for this row in the 4.1.0 mapping CSV. Family applicability is not proof that this requirement receives a mapped test result.

Family supporting scope
SC.L2-3.13.14SC System & Communications ProtectionControl and monitor use of Voice over Internet Protocol technologies.
Evidence and test details

Applicable supporting collectors: CERTTLS, ENTRA, NETWORK, VMWARE.

No exact requirement-to-test mapping is published for this row in the 4.1.0 mapping CSV. Family applicability is not proof that this requirement receives a mapped test result.

Family supporting scope
SC.L2-3.13.15SC System & Communications ProtectionProtect authenticity of communications sessions.
Evidence and test details

Applicable supporting collectors: CERTTLS, ENTRA, NETWORK, VMWARE.

No exact requirement-to-test mapping is published for this row in the 4.1.0 mapping CSV. Family applicability is not proof that this requirement receives a mapped test result.

Family supporting scope
SC.L2-3.13.16SC System & Communications ProtectionProtect confidentiality of CUI at rest.
Evidence and test details
  • STOR-AT-REST-ENCRYPTION-001 STORAGEStorage encryption evidence supports confidentiality of CUI at rest.

Mapped in the package; actual collection depends on targets, permissions, dependencies and applicability. A successful test is not an automatic compliance result.

Mapped technical checks
SI.L2-3.14.1SI System & Information IntegrityIdentify, report, and correct system flaws in a timely manner.
Evidence and test details
  • WIN-PATCH-FRESHNESS-001 WINDOWSSecurity update freshness is technical evidence supporting timely flaw correction.
  • WIN-PATCH-COHORT-001 WINDOWSPatch cohort consistency is technical evidence supporting timely flaw correction.
  • AD-DC-MAINTENANCE-001 ADSECDomain controller patch evidence supports timely flaw correction.

Mapped in the package; actual collection depends on targets, permissions, dependencies and applicability. A successful test is not an automatic compliance result.

Mapped technical checks
SI.L2-3.14.2SI System & Information IntegrityProtect systems from malicious code at designated locations.
Evidence and test details
  • WIN-AV-001 WINDOWSEndpoint anti-malware protection state directly supports malicious-code protection review.

Mapped in the package; actual collection depends on targets, permissions, dependencies and applicability. A successful test is not an automatic compliance result.

Mapped technical checks
SI.L2-3.14.3SI System & Information IntegrityMonitor security alerts and advisories and take appropriate action.
Evidence and test details

Applicable supporting collectors: VULN, WINDOWS.

No exact requirement-to-test mapping is published for this row in the 4.1.0 mapping CSV. Family applicability is not proof that this requirement receives a mapped test result.

Family supporting scope
SI.L2-3.14.4SI System & Information IntegrityUpdate malicious code protection mechanisms when new releases are available.
Evidence and test details

Applicable supporting collectors: VULN, WINDOWS.

No exact requirement-to-test mapping is published for this row in the 4.1.0 mapping CSV. Family applicability is not proof that this requirement receives a mapped test result.

Family supporting scope
SI.L2-3.14.5SI System & Information IntegrityPerform periodic and real-time scans of files from external sources as files are downloaded, opened, or executed.
Evidence and test details

Applicable supporting collectors: VULN, WINDOWS.

No exact requirement-to-test mapping is published for this row in the 4.1.0 mapping CSV. Family applicability is not proof that this requirement receives a mapped test result.

Family supporting scope
SI.L2-3.14.6SI System & Information IntegrityMonitor systems, including inbound and outbound communications traffic, to detect attacks and indicators of potential attacks.
Evidence and test details

Applicable supporting collectors: VULN, WINDOWS.

No exact requirement-to-test mapping is published for this row in the 4.1.0 mapping CSV. Family applicability is not proof that this requirement receives a mapped test result.

Family supporting scope
SI.L2-3.14.7SI System & Information IntegrityIdentify unauthorized use of systems.
Evidence and test details

Applicable supporting collectors: VULN, WINDOWS.

No exact requirement-to-test mapping is published for this row in the 4.1.0 mapping CSV. Family applicability is not proof that this requirement receives a mapped test result.

Family supporting scope