CMMC Level 2
Uses common technical evidence domains for CMMC Level 2 readiness. Final CMMC determinations remain assessor-controlled.
| Control / requirement | Packaged guidance & evidence | Coverage |
|---|---|---|
AC.L2-3.1.1AC Access Control | Limit system access to authorized users, processes acting for users, and authorized devices.Evidence and test details
Mapped in the package; actual collection depends on targets, permissions, dependencies and applicability. A successful test is not an automatic compliance result. | Mapped technical checks |
AC.L2-3.1.2AC Access Control | Limit authorized users to permitted transactions and functions.Evidence and test detailsApplicable supporting collectors: ADSEC, ENTRA, GPO, NETWORK. No exact requirement-to-test mapping is published for this row in the 4.1.0 mapping CSV. Family applicability is not proof that this requirement receives a mapped test result. | Family supporting scope |
AC.L2-3.1.3AC Access Control | Control the flow of CUI according to approved authorizations.Evidence and test detailsApplicable supporting collectors: ADSEC, ENTRA, GPO, NETWORK. No exact requirement-to-test mapping is published for this row in the 4.1.0 mapping CSV. Family applicability is not proof that this requirement receives a mapped test result. | Family supporting scope |
AC.L2-3.1.4AC Access Control | Separate duties to reduce risk of malevolent activity without collusion.Evidence and test detailsApplicable supporting collectors: ADSEC, ENTRA, GPO, NETWORK. No exact requirement-to-test mapping is published for this row in the 4.1.0 mapping CSV. Family applicability is not proof that this requirement receives a mapped test result. | Family supporting scope |
AC.L2-3.1.5AC Access Control | Apply least privilege, including for specific security functions and privileged accounts.Evidence and test details
Mapped in the package; actual collection depends on targets, permissions, dependencies and applicability. A successful test is not an automatic compliance result. | Mapped technical checks |
AC.L2-3.1.6AC Access Control | Use non-privileged accounts or roles when accessing nonsecurity functions.Evidence and test detailsApplicable supporting collectors: ADSEC, ENTRA, GPO, NETWORK. No exact requirement-to-test mapping is published for this row in the 4.1.0 mapping CSV. Family applicability is not proof that this requirement receives a mapped test result. | Family supporting scope |
AC.L2-3.1.7AC Access Control | Prevent non-privileged users from executing privileged functions and capture privileged execution in audit logs.Evidence and test detailsApplicable supporting collectors: ADSEC, ENTRA, GPO, NETWORK. No exact requirement-to-test mapping is published for this row in the 4.1.0 mapping CSV. Family applicability is not proof that this requirement receives a mapped test result. | Family supporting scope |
AC.L2-3.1.8AC Access Control | Limit unsuccessful logon attempts.Evidence and test detailsApplicable supporting collectors: ADSEC, ENTRA, GPO, NETWORK. No exact requirement-to-test mapping is published for this row in the 4.1.0 mapping CSV. Family applicability is not proof that this requirement receives a mapped test result. | Family supporting scope |
AC.L2-3.1.9AC Access Control | Provide privacy and security notices consistent with applicable CUI rules.Evidence and test detailsApplicable supporting collectors: ADSEC, ENTRA, GPO, NETWORK. No exact requirement-to-test mapping is published for this row in the 4.1.0 mapping CSV. Family applicability is not proof that this requirement receives a mapped test result. | Family supporting scope |
AC.L2-3.1.10AC Access Control | Use session lock with pattern-hiding displays after inactivity.Evidence and test detailsApplicable supporting collectors: ADSEC, ENTRA, GPO, NETWORK. No exact requirement-to-test mapping is published for this row in the 4.1.0 mapping CSV. Family applicability is not proof that this requirement receives a mapped test result. | Family supporting scope |
AC.L2-3.1.11AC Access Control | Terminate user sessions after defined conditions.Evidence and test detailsApplicable supporting collectors: ADSEC, ENTRA, GPO, NETWORK. No exact requirement-to-test mapping is published for this row in the 4.1.0 mapping CSV. Family applicability is not proof that this requirement receives a mapped test result. | Family supporting scope |
AC.L2-3.1.12AC Access Control | Monitor and control remote access sessions.Evidence and test detailsApplicable supporting collectors: ADSEC, ENTRA, GPO, NETWORK. No exact requirement-to-test mapping is published for this row in the 4.1.0 mapping CSV. Family applicability is not proof that this requirement receives a mapped test result. | Family supporting scope |
AC.L2-3.1.13AC Access Control | Use cryptographic mechanisms to protect confidentiality of remote access sessions.Evidence and test detailsApplicable supporting collectors: ADSEC, ENTRA, GPO, NETWORK. No exact requirement-to-test mapping is published for this row in the 4.1.0 mapping CSV. Family applicability is not proof that this requirement receives a mapped test result. | Family supporting scope |
AC.L2-3.1.14AC Access Control | Route remote access through managed access control points.Evidence and test detailsApplicable supporting collectors: ADSEC, ENTRA, GPO, NETWORK. No exact requirement-to-test mapping is published for this row in the 4.1.0 mapping CSV. Family applicability is not proof that this requirement receives a mapped test result. | Family supporting scope |
AC.L2-3.1.15AC Access Control | Authorize remote privileged commands and remote access to security-relevant information.Evidence and test detailsApplicable supporting collectors: ADSEC, ENTRA, GPO, NETWORK. No exact requirement-to-test mapping is published for this row in the 4.1.0 mapping CSV. Family applicability is not proof that this requirement receives a mapped test result. | Family supporting scope |
AC.L2-3.1.16AC Access Control | Authorize wireless access before allowing connections.Evidence and test detailsApplicable supporting collectors: ADSEC, ENTRA, GPO, NETWORK. No exact requirement-to-test mapping is published for this row in the 4.1.0 mapping CSV. Family applicability is not proof that this requirement receives a mapped test result. | Family supporting scope |
AC.L2-3.1.17AC Access Control | Protect wireless access using authentication and encryption.Evidence and test detailsApplicable supporting collectors: ADSEC, ENTRA, GPO, NETWORK. No exact requirement-to-test mapping is published for this row in the 4.1.0 mapping CSV. Family applicability is not proof that this requirement receives a mapped test result. | Family supporting scope |
AC.L2-3.1.18AC Access Control | Control connection of mobile devices.Evidence and test detailsApplicable supporting collectors: ADSEC, ENTRA, GPO, NETWORK. No exact requirement-to-test mapping is published for this row in the 4.1.0 mapping CSV. Family applicability is not proof that this requirement receives a mapped test result. | Family supporting scope |
AC.L2-3.1.19AC Access Control | Encrypt CUI on mobile devices and mobile computing platforms.Evidence and test detailsApplicable supporting collectors: ADSEC, ENTRA, GPO, NETWORK. No exact requirement-to-test mapping is published for this row in the 4.1.0 mapping CSV. Family applicability is not proof that this requirement receives a mapped test result. | Family supporting scope |
AC.L2-3.1.20AC Access Control | Verify and control connections to external systems.Evidence and test detailsApplicable supporting collectors: ADSEC, ENTRA, GPO, NETWORK. No exact requirement-to-test mapping is published for this row in the 4.1.0 mapping CSV. Family applicability is not proof that this requirement receives a mapped test result. | Family supporting scope |
AC.L2-3.1.21AC Access Control | Limit use of portable storage devices on external systems.Evidence and test detailsApplicable supporting collectors: ADSEC, ENTRA, GPO, NETWORK. No exact requirement-to-test mapping is published for this row in the 4.1.0 mapping CSV. Family applicability is not proof that this requirement receives a mapped test result. | Family supporting scope |
AC.L2-3.1.22AC Access Control | Control CUI posted or processed on publicly accessible systems.Evidence and test detailsApplicable supporting collectors: ADSEC, ENTRA, GPO, NETWORK. No exact requirement-to-test mapping is published for this row in the 4.1.0 mapping CSV. Family applicability is not proof that this requirement receives a mapped test result. | Family supporting scope |
AT.L2-3.2.1AT Awareness & Training | Ensure managers, administrators, and users know security risks and applicable policies and procedures.Evidence and test detailsNo exact automated mapping is packaged for this entry. Supply and review policies, records, interviews, observations or other appropriate evidence; absence of a mapping is not PASS. | Manual / no exact mapping |
AT.L2-3.2.2AT Awareness & Training | Train personnel to perform assigned information-security duties.Evidence and test detailsNo exact automated mapping is packaged for this entry. Supply and review policies, records, interviews, observations or other appropriate evidence; absence of a mapping is not PASS. | Manual / no exact mapping |
AT.L2-3.2.3AT Awareness & Training | Provide awareness training for recognizing and reporting potential insider threats.Evidence and test detailsNo exact automated mapping is packaged for this entry. Supply and review policies, records, interviews, observations or other appropriate evidence; absence of a mapping is not PASS. | Manual / no exact mapping |
AU.L2-3.3.1AU Audit & Accountability | Create and retain system audit logs needed to monitor, analyze, investigate, and report unlawful or unauthorized activity.Evidence and test detailsApplicable supporting collectors: ADSEC, ENTRA, NETWORK, WINDOWS. No exact requirement-to-test mapping is published for this row in the 4.1.0 mapping CSV. Family applicability is not proof that this requirement receives a mapped test result. | Family supporting scope |
AU.L2-3.3.2AU Audit & Accountability | Ensure individual user actions can be uniquely traced for accountability.Evidence and test detailsApplicable supporting collectors: ADSEC, ENTRA, NETWORK, WINDOWS. No exact requirement-to-test mapping is published for this row in the 4.1.0 mapping CSV. Family applicability is not proof that this requirement receives a mapped test result. | Family supporting scope |
AU.L2-3.3.3AU Audit & Accountability | Review and update logged events.Evidence and test detailsApplicable supporting collectors: ADSEC, ENTRA, NETWORK, WINDOWS. No exact requirement-to-test mapping is published for this row in the 4.1.0 mapping CSV. Family applicability is not proof that this requirement receives a mapped test result. | Family supporting scope |
AU.L2-3.3.4AU Audit & Accountability | Alert on audit logging process failures.Evidence and test detailsApplicable supporting collectors: ADSEC, ENTRA, NETWORK, WINDOWS. No exact requirement-to-test mapping is published for this row in the 4.1.0 mapping CSV. Family applicability is not proof that this requirement receives a mapped test result. | Family supporting scope |
AU.L2-3.3.5AU Audit & Accountability | Correlate audit review, analysis, and reporting processes for investigation and response.Evidence and test detailsApplicable supporting collectors: ADSEC, ENTRA, NETWORK, WINDOWS. No exact requirement-to-test mapping is published for this row in the 4.1.0 mapping CSV. Family applicability is not proof that this requirement receives a mapped test result. | Family supporting scope |
AU.L2-3.3.6AU Audit & Accountability | Provide audit reduction and report generation supporting on-demand analysis.Evidence and test detailsApplicable supporting collectors: ADSEC, ENTRA, NETWORK, WINDOWS. No exact requirement-to-test mapping is published for this row in the 4.1.0 mapping CSV. Family applicability is not proof that this requirement receives a mapped test result. | Family supporting scope |
AU.L2-3.3.7AU Audit & Accountability | Synchronize clocks with authoritative sources for audit timestamp generation.Evidence and test details
Mapped in the package; actual collection depends on targets, permissions, dependencies and applicability. A successful test is not an automatic compliance result. | Mapped technical checks |
AU.L2-3.3.8AU Audit & Accountability | Protect audit information and audit tools from unauthorized access, modification, and deletion.Evidence and test detailsApplicable supporting collectors: ADSEC, ENTRA, NETWORK, WINDOWS. No exact requirement-to-test mapping is published for this row in the 4.1.0 mapping CSV. Family applicability is not proof that this requirement receives a mapped test result. | Family supporting scope |
AU.L2-3.3.9AU Audit & Accountability | Limit management of audit logging functionality to privileged users.Evidence and test detailsApplicable supporting collectors: ADSEC, ENTRA, NETWORK, WINDOWS. No exact requirement-to-test mapping is published for this row in the 4.1.0 mapping CSV. Family applicability is not proof that this requirement receives a mapped test result. | Family supporting scope |
CM.L2-3.4.1CM Configuration Management | Establish and maintain baseline configurations and inventories throughout system life cycles.Evidence and test details
Mapped in the package; actual collection depends on targets, permissions, dependencies and applicability. A successful test is not an automatic compliance result. | Mapped technical checks |
CM.L2-3.4.2CM Configuration Management | Establish and enforce security configuration settings for IT products.Evidence and test details
Mapped in the package; actual collection depends on targets, permissions, dependencies and applicability. A successful test is not an automatic compliance result. | Mapped technical checks |
CM.L2-3.4.3CM Configuration Management | Track, review, approve or disapprove, and log system changes.Evidence and test detailsApplicable supporting collectors: GPO, STORAGE, VMWARE, WINDOWS. No exact requirement-to-test mapping is published for this row in the 4.1.0 mapping CSV. Family applicability is not proof that this requirement receives a mapped test result. | Family supporting scope |
CM.L2-3.4.4CM Configuration Management | Analyze security impacts before implementing changes.Evidence and test detailsApplicable supporting collectors: GPO, STORAGE, VMWARE, WINDOWS. No exact requirement-to-test mapping is published for this row in the 4.1.0 mapping CSV. Family applicability is not proof that this requirement receives a mapped test result. | Family supporting scope |
CM.L2-3.4.5CM Configuration Management | Define, document, approve, and enforce physical and logical access restrictions associated with system changes.Evidence and test detailsApplicable supporting collectors: GPO, STORAGE, VMWARE, WINDOWS. No exact requirement-to-test mapping is published for this row in the 4.1.0 mapping CSV. Family applicability is not proof that this requirement receives a mapped test result. | Family supporting scope |
CM.L2-3.4.6CM Configuration Management | Apply least functionality by configuring systems to provide only essential capabilities.Evidence and test detailsApplicable supporting collectors: GPO, STORAGE, VMWARE, WINDOWS. No exact requirement-to-test mapping is published for this row in the 4.1.0 mapping CSV. Family applicability is not proof that this requirement receives a mapped test result. | Family supporting scope |
CM.L2-3.4.7CM Configuration Management | Restrict or disable nonessential programs, functions, ports, protocols, and services.Evidence and test details
Mapped in the package; actual collection depends on targets, permissions, dependencies and applicability. A successful test is not an automatic compliance result. | Mapped technical checks |
CM.L2-3.4.8CM Configuration Management | Use deny-by-exception or allow-by-exception policies to prevent unauthorized program execution.Evidence and test detailsApplicable supporting collectors: GPO, STORAGE, VMWARE, WINDOWS. No exact requirement-to-test mapping is published for this row in the 4.1.0 mapping CSV. Family applicability is not proof that this requirement receives a mapped test result. | Family supporting scope |
CM.L2-3.4.9CM Configuration Management | Control and monitor user-installed software.Evidence and test detailsApplicable supporting collectors: GPO, STORAGE, VMWARE, WINDOWS. No exact requirement-to-test mapping is published for this row in the 4.1.0 mapping CSV. Family applicability is not proof that this requirement receives a mapped test result. | Family supporting scope |
IA.L2-3.5.1IA Identification & Authentication | Identify system users, processes acting for users, and devices.Evidence and test detailsApplicable supporting collectors: ADSEC, ENTRA, GPO. No exact requirement-to-test mapping is published for this row in the 4.1.0 mapping CSV. Family applicability is not proof that this requirement receives a mapped test result. | Family supporting scope |
IA.L2-3.5.2IA Identification & Authentication | Authenticate identities before allowing access.Evidence and test detailsApplicable supporting collectors: ADSEC, ENTRA, GPO. No exact requirement-to-test mapping is published for this row in the 4.1.0 mapping CSV. Family applicability is not proof that this requirement receives a mapped test result. | Family supporting scope |
IA.L2-3.5.3IA Identification & Authentication | Use multifactor authentication for local and network access to privileged accounts and for network access to non-privileged accounts.Evidence and test details
Mapped in the package; actual collection depends on targets, permissions, dependencies and applicability. A successful test is not an automatic compliance result. | Mapped technical checks |
IA.L2-3.5.4IA Identification & Authentication | Use replay-resistant authentication for network access to privileged and non-privileged accounts.Evidence and test detailsApplicable supporting collectors: ADSEC, ENTRA, GPO. No exact requirement-to-test mapping is published for this row in the 4.1.0 mapping CSV. Family applicability is not proof that this requirement receives a mapped test result. | Family supporting scope |
IA.L2-3.5.5IA Identification & Authentication | Prevent reuse of identifiers for a defined period.Evidence and test detailsApplicable supporting collectors: ADSEC, ENTRA, GPO. No exact requirement-to-test mapping is published for this row in the 4.1.0 mapping CSV. Family applicability is not proof that this requirement receives a mapped test result. | Family supporting scope |
IA.L2-3.5.6IA Identification & Authentication | Disable identifiers after a defined period of inactivity.Evidence and test details
Mapped in the package; actual collection depends on targets, permissions, dependencies and applicability. A successful test is not an automatic compliance result. | Mapped technical checks |
IA.L2-3.5.7IA Identification & Authentication | Enforce password complexity and changed-character requirements.Evidence and test detailsApplicable supporting collectors: ADSEC, ENTRA, GPO. No exact requirement-to-test mapping is published for this row in the 4.1.0 mapping CSV. Family applicability is not proof that this requirement receives a mapped test result. | Family supporting scope |
IA.L2-3.5.8IA Identification & Authentication | Prohibit password reuse for a specified number of generations.Evidence and test detailsApplicable supporting collectors: ADSEC, ENTRA, GPO. No exact requirement-to-test mapping is published for this row in the 4.1.0 mapping CSV. Family applicability is not proof that this requirement receives a mapped test result. | Family supporting scope |
IA.L2-3.5.9IA Identification & Authentication | Allow temporary passwords only for immediate logon and force permanent change.Evidence and test detailsApplicable supporting collectors: ADSEC, ENTRA, GPO. No exact requirement-to-test mapping is published for this row in the 4.1.0 mapping CSV. Family applicability is not proof that this requirement receives a mapped test result. | Family supporting scope |
IA.L2-3.5.10IA Identification & Authentication | Store and transmit only cryptographically protected passwords.Evidence and test detailsApplicable supporting collectors: ADSEC, ENTRA, GPO. No exact requirement-to-test mapping is published for this row in the 4.1.0 mapping CSV. Family applicability is not proof that this requirement receives a mapped test result. | Family supporting scope |
IA.L2-3.5.11IA Identification & Authentication | Obscure authentication feedback.Evidence and test detailsApplicable supporting collectors: ADSEC, ENTRA, GPO. No exact requirement-to-test mapping is published for this row in the 4.1.0 mapping CSV. Family applicability is not proof that this requirement receives a mapped test result. | Family supporting scope |
IR.L2-3.6.1IR Incident Response | Establish an operational incident-handling capability covering preparation, detection, analysis, containment, recovery, and user response.Evidence and test detailsNo exact automated mapping is packaged for this entry. Supply and review policies, records, interviews, observations or other appropriate evidence; absence of a mapping is not PASS. | Manual / no exact mapping |
IR.L2-3.6.2IR Incident Response | Track, document, and report incidents to designated personnel and authorities.Evidence and test detailsNo exact automated mapping is packaged for this entry. Supply and review policies, records, interviews, observations or other appropriate evidence; absence of a mapping is not PASS. | Manual / no exact mapping |
IR.L2-3.6.3IR Incident Response | Test the organizational incident-response capability.Evidence and test detailsNo exact automated mapping is packaged for this entry. Supply and review policies, records, interviews, observations or other appropriate evidence; absence of a mapping is not PASS. | Manual / no exact mapping |
MA.L2-3.7.1MA Maintenance | Perform system maintenance.Evidence and test detailsNo exact automated mapping is packaged for this entry. Supply and review policies, records, interviews, observations or other appropriate evidence; absence of a mapping is not PASS. | Manual / no exact mapping |
MA.L2-3.7.2MA Maintenance | Provide controls over maintenance tools, techniques, mechanisms, and personnel.Evidence and test detailsNo exact automated mapping is packaged for this entry. Supply and review policies, records, interviews, observations or other appropriate evidence; absence of a mapping is not PASS. | Manual / no exact mapping |
MA.L2-3.7.3MA Maintenance | Ensure equipment removed for off-site maintenance is sanitized of CUI.Evidence and test detailsNo exact automated mapping is packaged for this entry. Supply and review policies, records, interviews, observations or other appropriate evidence; absence of a mapping is not PASS. | Manual / no exact mapping |
MA.L2-3.7.4MA Maintenance | Check media containing diagnostic and test programs for malicious code before use.Evidence and test detailsNo exact automated mapping is packaged for this entry. Supply and review policies, records, interviews, observations or other appropriate evidence; absence of a mapping is not PASS. | Manual / no exact mapping |
MA.L2-3.7.5MA Maintenance | Require multifactor authentication for nonlocal maintenance sessions and terminate them when maintenance is complete.Evidence and test detailsNo exact automated mapping is packaged for this entry. Supply and review policies, records, interviews, observations or other appropriate evidence; absence of a mapping is not PASS. | Manual / no exact mapping |
MA.L2-3.7.6MA Maintenance | Supervise maintenance personnel without required access authorization.Evidence and test detailsNo exact automated mapping is packaged for this entry. Supply and review policies, records, interviews, observations or other appropriate evidence; absence of a mapping is not PASS. | Manual / no exact mapping |
MP.L2-3.8.1MP Media Protection | Protect system media containing CUI, both paper and digital.Evidence and test detailsApplicable supporting collectors: BACKUP, STORAGE. No exact requirement-to-test mapping is published for this row in the 4.1.0 mapping CSV. Family applicability is not proof that this requirement receives a mapped test result. | Family supporting scope |
MP.L2-3.8.2MP Media Protection | Limit access to CUI on media to authorized users.Evidence and test detailsApplicable supporting collectors: BACKUP, STORAGE. No exact requirement-to-test mapping is published for this row in the 4.1.0 mapping CSV. Family applicability is not proof that this requirement receives a mapped test result. | Family supporting scope |
MP.L2-3.8.3MP Media Protection | Sanitize or destroy media before disposal or release for reuse.Evidence and test detailsApplicable supporting collectors: BACKUP, STORAGE. No exact requirement-to-test mapping is published for this row in the 4.1.0 mapping CSV. Family applicability is not proof that this requirement receives a mapped test result. | Family supporting scope |
MP.L2-3.8.4MP Media Protection | Mark media with required CUI markings and distribution limitations.Evidence and test detailsApplicable supporting collectors: BACKUP, STORAGE. No exact requirement-to-test mapping is published for this row in the 4.1.0 mapping CSV. Family applicability is not proof that this requirement receives a mapped test result. | Family supporting scope |
MP.L2-3.8.5MP Media Protection | Control access to media during transport outside controlled areas and maintain accountability.Evidence and test detailsApplicable supporting collectors: BACKUP, STORAGE. No exact requirement-to-test mapping is published for this row in the 4.1.0 mapping CSV. Family applicability is not proof that this requirement receives a mapped test result. | Family supporting scope |
MP.L2-3.8.6MP Media Protection | Use cryptography to protect confidentiality of CUI on digital media during transport unless otherwise physically protected.Evidence and test detailsApplicable supporting collectors: BACKUP, STORAGE. No exact requirement-to-test mapping is published for this row in the 4.1.0 mapping CSV. Family applicability is not proof that this requirement receives a mapped test result. | Family supporting scope |
MP.L2-3.8.7MP Media Protection | Control removable media use on system components.Evidence and test detailsApplicable supporting collectors: BACKUP, STORAGE. No exact requirement-to-test mapping is published for this row in the 4.1.0 mapping CSV. Family applicability is not proof that this requirement receives a mapped test result. | Family supporting scope |
MP.L2-3.8.8MP Media Protection | Prohibit use of portable storage devices without identifiable owners.Evidence and test detailsApplicable supporting collectors: BACKUP, STORAGE. No exact requirement-to-test mapping is published for this row in the 4.1.0 mapping CSV. Family applicability is not proof that this requirement receives a mapped test result. | Family supporting scope |
MP.L2-3.8.9MP Media Protection | Protect backup CUI at storage locations.Evidence and test details
Mapped in the package; actual collection depends on targets, permissions, dependencies and applicability. A successful test is not an automatic compliance result. | Mapped technical checks |
PS.L2-3.9.1PS Personnel Security | Screen individuals before authorizing access to systems containing CUI.Evidence and test detailsNo exact automated mapping is packaged for this entry. Supply and review policies, records, interviews, observations or other appropriate evidence; absence of a mapping is not PASS. | Manual / no exact mapping |
PS.L2-3.9.2PS Personnel Security | Protect systems containing CUI during and after personnel actions such as termination and transfer.Evidence and test detailsNo exact automated mapping is packaged for this entry. Supply and review policies, records, interviews, observations or other appropriate evidence; absence of a mapping is not PASS. | Manual / no exact mapping |
PE.L2-3.10.1PE Physical Protection | Limit physical access to systems, equipment, and operating environments to authorized individuals.Evidence and test detailsNo exact automated mapping is packaged for this entry. Supply and review policies, records, interviews, observations or other appropriate evidence; absence of a mapping is not PASS. | Manual / no exact mapping |
PE.L2-3.10.2PE Physical Protection | Protect and monitor physical facilities and support infrastructure.Evidence and test detailsNo exact automated mapping is packaged for this entry. Supply and review policies, records, interviews, observations or other appropriate evidence; absence of a mapping is not PASS. | Manual / no exact mapping |
PE.L2-3.10.3PE Physical Protection | Escort visitors and monitor visitor activity.Evidence and test detailsNo exact automated mapping is packaged for this entry. Supply and review policies, records, interviews, observations or other appropriate evidence; absence of a mapping is not PASS. | Manual / no exact mapping |
PE.L2-3.10.4PE Physical Protection | Maintain audit logs of physical access.Evidence and test detailsNo exact automated mapping is packaged for this entry. Supply and review policies, records, interviews, observations or other appropriate evidence; absence of a mapping is not PASS. | Manual / no exact mapping |
PE.L2-3.10.5PE Physical Protection | Control and manage physical access devices.Evidence and test detailsNo exact automated mapping is packaged for this entry. Supply and review policies, records, interviews, observations or other appropriate evidence; absence of a mapping is not PASS. | Manual / no exact mapping |
PE.L2-3.10.6PE Physical Protection | Enforce safeguarding measures for CUI at alternate work sites.Evidence and test detailsNo exact automated mapping is packaged for this entry. Supply and review policies, records, interviews, observations or other appropriate evidence; absence of a mapping is not PASS. | Manual / no exact mapping |
RA.L2-3.11.1RA Risk Assessment | Periodically assess risk to operations, assets, and individuals from operation of systems and processing/storage/transmission of CUI.Evidence and test detailsApplicable supporting collectors: VULN. No exact requirement-to-test mapping is published for this row in the 4.1.0 mapping CSV. Family applicability is not proof that this requirement receives a mapped test result. | Family supporting scope |
RA.L2-3.11.2RA Risk Assessment | Scan for vulnerabilities periodically and when new vulnerabilities are identified.Evidence and test details
Mapped in the package; actual collection depends on targets, permissions, dependencies and applicability. A successful test is not an automatic compliance result. | Mapped technical checks |
RA.L2-3.11.3RA Risk Assessment | Remediate vulnerabilities according to risk assessments.Evidence and test details
Mapped in the package; actual collection depends on targets, permissions, dependencies and applicability. A successful test is not an automatic compliance result. | Mapped technical checks |
CA.L2-3.12.1CA Security Assessment | Periodically assess security controls to determine whether they are effective.Evidence and test detailsApplicable supporting collectors: ASSETREC, VULN. No exact requirement-to-test mapping is published for this row in the 4.1.0 mapping CSV. Family applicability is not proof that this requirement receives a mapped test result. | Family supporting scope |
CA.L2-3.12.2CA Security Assessment | Develop and implement plans of action to correct deficiencies and reduce or eliminate vulnerabilities.Evidence and test detailsApplicable supporting collectors: ASSETREC, VULN. No exact requirement-to-test mapping is published for this row in the 4.1.0 mapping CSV. Family applicability is not proof that this requirement receives a mapped test result. | Family supporting scope |
CA.L2-3.12.3CA Security Assessment | Monitor security controls continuously to ensure ongoing effectiveness.Evidence and test detailsApplicable supporting collectors: ASSETREC, VULN. No exact requirement-to-test mapping is published for this row in the 4.1.0 mapping CSV. Family applicability is not proof that this requirement receives a mapped test result. | Family supporting scope |
CA.L2-3.12.4CA Security Assessment | Develop, document, and periodically update system security plans describing boundaries, operating environments, implementation, and relationships.Evidence and test detailsApplicable supporting collectors: ASSETREC, VULN. No exact requirement-to-test mapping is published for this row in the 4.1.0 mapping CSV. Family applicability is not proof that this requirement receives a mapped test result. | Family supporting scope |
SC.L2-3.13.1SC System & Communications Protection | Monitor, control, and protect communications at external and key internal system boundaries.Evidence and test details
Mapped in the package; actual collection depends on targets, permissions, dependencies and applicability. A successful test is not an automatic compliance result. | Mapped technical checks |
SC.L2-3.13.2SC System & Communications Protection | Use secure architectural designs and engineering principles promoting effective information security.Evidence and test detailsApplicable supporting collectors: CERTTLS, ENTRA, NETWORK, VMWARE. No exact requirement-to-test mapping is published for this row in the 4.1.0 mapping CSV. Family applicability is not proof that this requirement receives a mapped test result. | Family supporting scope |
SC.L2-3.13.3SC System & Communications Protection | Separate user functionality from system-management functionality.Evidence and test detailsApplicable supporting collectors: CERTTLS, ENTRA, NETWORK, VMWARE. No exact requirement-to-test mapping is published for this row in the 4.1.0 mapping CSV. Family applicability is not proof that this requirement receives a mapped test result. | Family supporting scope |
SC.L2-3.13.4SC System & Communications Protection | Prevent unauthorized and unintended information transfer through shared system resources.Evidence and test detailsApplicable supporting collectors: CERTTLS, ENTRA, NETWORK, VMWARE. No exact requirement-to-test mapping is published for this row in the 4.1.0 mapping CSV. Family applicability is not proof that this requirement receives a mapped test result. | Family supporting scope |
SC.L2-3.13.5SC System & Communications Protection | Implement subnetworks for publicly accessible components separated from internal networks.Evidence and test detailsApplicable supporting collectors: CERTTLS, ENTRA, NETWORK, VMWARE. No exact requirement-to-test mapping is published for this row in the 4.1.0 mapping CSV. Family applicability is not proof that this requirement receives a mapped test result. | Family supporting scope |
SC.L2-3.13.6SC System & Communications Protection | Deny network communications traffic by default and allow by exception at external boundaries.Evidence and test detailsApplicable supporting collectors: CERTTLS, ENTRA, NETWORK, VMWARE. No exact requirement-to-test mapping is published for this row in the 4.1.0 mapping CSV. Family applicability is not proof that this requirement receives a mapped test result. | Family supporting scope |
SC.L2-3.13.7SC System & Communications Protection | Prevent remote devices from simultaneously connecting to organizational systems and external networks via split tunneling.Evidence and test detailsApplicable supporting collectors: CERTTLS, ENTRA, NETWORK, VMWARE. No exact requirement-to-test mapping is published for this row in the 4.1.0 mapping CSV. Family applicability is not proof that this requirement receives a mapped test result. | Family supporting scope |
SC.L2-3.13.8SC System & Communications Protection | Use cryptographic mechanisms to prevent unauthorized disclosure of CUI during transmission unless otherwise physically protected.Evidence and test details
Mapped in the package; actual collection depends on targets, permissions, dependencies and applicability. A successful test is not an automatic compliance result. | Mapped technical checks |
SC.L2-3.13.9SC System & Communications Protection | Terminate network connections at the end of sessions or after defined inactivity.Evidence and test detailsApplicable supporting collectors: CERTTLS, ENTRA, NETWORK, VMWARE. No exact requirement-to-test mapping is published for this row in the 4.1.0 mapping CSV. Family applicability is not proof that this requirement receives a mapped test result. | Family supporting scope |
SC.L2-3.13.10SC System & Communications Protection | Establish and manage cryptographic keys when cryptography is used.Evidence and test detailsApplicable supporting collectors: CERTTLS, ENTRA, NETWORK, VMWARE. No exact requirement-to-test mapping is published for this row in the 4.1.0 mapping CSV. Family applicability is not proof that this requirement receives a mapped test result. | Family supporting scope |
SC.L2-3.13.11SC System & Communications Protection | Use FIPS-validated cryptography when protecting confidentiality of CUI.Evidence and test detailsApplicable supporting collectors: CERTTLS, ENTRA, NETWORK, VMWARE. No exact requirement-to-test mapping is published for this row in the 4.1.0 mapping CSV. Family applicability is not proof that this requirement receives a mapped test result. | Family supporting scope |
SC.L2-3.13.12SC System & Communications Protection | Prohibit remote activation of collaborative computing devices and provide indication when they are in use.Evidence and test detailsApplicable supporting collectors: CERTTLS, ENTRA, NETWORK, VMWARE. No exact requirement-to-test mapping is published for this row in the 4.1.0 mapping CSV. Family applicability is not proof that this requirement receives a mapped test result. | Family supporting scope |
SC.L2-3.13.13SC System & Communications Protection | Control and monitor mobile code use.Evidence and test detailsApplicable supporting collectors: CERTTLS, ENTRA, NETWORK, VMWARE. No exact requirement-to-test mapping is published for this row in the 4.1.0 mapping CSV. Family applicability is not proof that this requirement receives a mapped test result. | Family supporting scope |
SC.L2-3.13.14SC System & Communications Protection | Control and monitor use of Voice over Internet Protocol technologies.Evidence and test detailsApplicable supporting collectors: CERTTLS, ENTRA, NETWORK, VMWARE. No exact requirement-to-test mapping is published for this row in the 4.1.0 mapping CSV. Family applicability is not proof that this requirement receives a mapped test result. | Family supporting scope |
SC.L2-3.13.15SC System & Communications Protection | Protect authenticity of communications sessions.Evidence and test detailsApplicable supporting collectors: CERTTLS, ENTRA, NETWORK, VMWARE. No exact requirement-to-test mapping is published for this row in the 4.1.0 mapping CSV. Family applicability is not proof that this requirement receives a mapped test result. | Family supporting scope |
SC.L2-3.13.16SC System & Communications Protection | Protect confidentiality of CUI at rest.Evidence and test details
Mapped in the package; actual collection depends on targets, permissions, dependencies and applicability. A successful test is not an automatic compliance result. | Mapped technical checks |
SI.L2-3.14.1SI System & Information Integrity | Identify, report, and correct system flaws in a timely manner.Evidence and test details
Mapped in the package; actual collection depends on targets, permissions, dependencies and applicability. A successful test is not an automatic compliance result. | Mapped technical checks |
SI.L2-3.14.2SI System & Information Integrity | Protect systems from malicious code at designated locations.Evidence and test details
Mapped in the package; actual collection depends on targets, permissions, dependencies and applicability. A successful test is not an automatic compliance result. | Mapped technical checks |
SI.L2-3.14.3SI System & Information Integrity | Monitor security alerts and advisories and take appropriate action.Evidence and test detailsApplicable supporting collectors: VULN, WINDOWS. No exact requirement-to-test mapping is published for this row in the 4.1.0 mapping CSV. Family applicability is not proof that this requirement receives a mapped test result. | Family supporting scope |
SI.L2-3.14.4SI System & Information Integrity | Update malicious code protection mechanisms when new releases are available.Evidence and test detailsApplicable supporting collectors: VULN, WINDOWS. No exact requirement-to-test mapping is published for this row in the 4.1.0 mapping CSV. Family applicability is not proof that this requirement receives a mapped test result. | Family supporting scope |
SI.L2-3.14.5SI System & Information Integrity | Perform periodic and real-time scans of files from external sources as files are downloaded, opened, or executed.Evidence and test detailsApplicable supporting collectors: VULN, WINDOWS. No exact requirement-to-test mapping is published for this row in the 4.1.0 mapping CSV. Family applicability is not proof that this requirement receives a mapped test result. | Family supporting scope |
SI.L2-3.14.6SI System & Information Integrity | Monitor systems, including inbound and outbound communications traffic, to detect attacks and indicators of potential attacks.Evidence and test detailsApplicable supporting collectors: VULN, WINDOWS. No exact requirement-to-test mapping is published for this row in the 4.1.0 mapping CSV. Family applicability is not proof that this requirement receives a mapped test result. | Family supporting scope |
SI.L2-3.14.7SI System & Information Integrity | Identify unauthorized use of systems.Evidence and test detailsApplicable supporting collectors: VULN, WINDOWS. No exact requirement-to-test mapping is published for this row in the 4.1.0 mapping CSV. Family applicability is not proof that this requirement receives a mapped test result. | Family supporting scope |
No controls match these filters.