Browse
131 controls
Commitment to integrity and ethical values
Control Environment
Board independence and oversight of internal control
Control Environment
Organizational structure, reporting lines, and authority
Control Environment
Commitment to attract, develop, and retain competent individuals
Control Environment
Accountability for internal control responsibilities
Control Environment
Obtains or generates and uses relevant quality information
Communication and Information
Internal communication of information to support internal control
Communication and Information
External communication regarding matters affecting internal control
Communication and Information
Specifies objectives with sufficient clarity
Risk Assessment
Identifies and analyzes risks to achievement of objectives
Risk Assessment
Considers potential for fraud in assessing risks
Risk Assessment
Identifies and assesses significant changes
Risk Assessment
Selects, develops, and performs ongoing and separate evaluations
Monitoring Activities
Evaluates and communicates internal control deficiencies
Monitoring Activities
Selects and develops control activities that mitigate risks
Control Activities
Selects and develops general controls over technology
Control Activities
Deploys control activities through policies and procedures
Control Activities
Logical access security infrastructure
Logical and Physical Access Controls
Registration and authorization prior to issuing credentials
Logical and Physical Access Controls
Role-based access management
Logical and Physical Access Controls
Physical access restrictions
Logical and Physical Access Controls
Disposal and destruction of information assets
Logical and Physical Access Controls
Controls against threats from outside system boundaries
Logical and Physical Access Controls
Restricts transmission and movement of information
Logical and Physical Access Controls
Controls to prevent or detect unauthorized software
Logical and Physical Access Controls
Detection and monitoring for vulnerabilities
System Operations
Monitoring for anomalies and security events
System Operations
Evaluation of security events as security incidents
System Operations
Incident response program
System Operations
Recovery from security incidents
System Operations
Authorized change management process
Change Management
Risk mitigation for business disruptions
Risk Mitigation
Vendor and business partner risk management
Risk Mitigation
Account management
Access control
Access enforcement
Access control
Information flow enforcement
Access control
Separation of duties
Access control
Least privilege
Access control
Least privilege - privileged accounts
Access control
Least privilege - privileged functions
Access control
Unsuccessful logon attempts
Access control
System use notification
Access control
Device lock
Access control
Session termination
Access control
Remote access
Access control
Wireless access
Access control
Access control for mobile devices
Access control
Use of external systems
Access control
Publicly accessible content
Access control
Literacy training and awareness
Awareness and training
Role-based training
Awareness and training
Event logging
Audit and accountability
Audit record content
Audit and accountability
Audit record generation
Audit and accountability
Response to audit logging process failures
Audit and accountability
Audit record review, analysis, and reporting
Audit and accountability
Audit record reduction and report generation
Audit and accountability
Time stamps
Audit and accountability
Protection of audit information
Audit and accountability
Baseline configuration
Configuration management
Configuration settings
Configuration management
Configuration change control
Configuration management
Impact analyses
Configuration management
Access restrictions for change
Configuration management
Least functionality
Configuration management
Authorized software - allow by exception
Configuration management
System component inventory
Configuration management
Information location
Configuration management
System and component configuration for high-risk areas
Configuration management
User identification, authentication, and re-authentication
Identification and authentication
Device identification and authentication
Identification and authentication
Multi-factor authentication
Identification and authentication
Replay-resistant authentication
Identification and authentication
Identifier management
Identification and authentication
Password management
Identification and authentication
Authentication feedback
Identification and authentication
Authenticator management
Identification and authentication
Incident handling
Incident response
Incident monitoring, reporting, and response assistance
Incident response
Incident response testing
Incident response
Incident response training
Incident response
Incident response plan
Incident response
Maintenance tools
Maintenance
Non-local maintenance
Maintenance
Maintenance personnel
Maintenance
Media storage
Media protection
Media access
Media protection
Media sanitization
Media protection
Media marking
Media protection
Media transport
Media protection
Media use
Media protection
System backup - cryptographic protection
Media protection
Personnel screening
Personnel security
Personnel termination and transfer
Personnel security
Physical access authorizations
Physical protection
Monitoring physical access
Physical protection
Alternate work site
Physical protection
Physical access control
Physical protection
Access control for transmission
Physical protection
Risk assessment
Risk assessment
Vulnerability monitoring and scanning
Risk assessment
Risk response
Risk assessment
Security assessment
Security assessment and monitoring
Plan of action and milestones
Security assessment and monitoring
Continuous monitoring
Security assessment and monitoring
Information exchange
Security assessment and monitoring
Boundary protection
System and communications protection
Information in shared system resources
System and communications protection
Network communications - deny by default - allow by exception
System and communications protection
Transmission and storage confidentiality
System and communications protection
Network disconnect
System and communications protection
Cryptographic key establishment and management
System and communications protection
Cryptographic protection
System and communications protection
Collaborative computing devices and applications
System and communications protection
Mobile code
System and communications protection
Session authenticity
System and communications protection
Flaw remediation
System and information integrity
Malicious code protection
System and information integrity
Security alerts, advisories, and directives
System and information integrity
System monitoring
System and information integrity
Information management and retention
System and information integrity
Dedicated administration workstation
System and information integrity
Policy and procedures
Planning
System security plan
Planning
Rules of behaviour
Planning
Security engineering principles
System and services acquisition
Unsupported system components
System and services acquisition
External system services
System and services acquisition
Supply chain risk management plan
Supply chain risk management
Acquisition strategies, tools, and methods
Supply chain risk management
Supply chain requirements and processes
Supply chain risk management