EvidenceSheet

NIST SP 800-53 Rev 5: the evidence behind every control

300 controls. For each, the artefacts auditors ask for, which ones a system already holds, and the first move to stop evidencing it by periodic review.

AC - Access Control

AC-1Access control policy and procedures hardAC-2Account management easyAC-3Access enforcement moderateAC-4Information flow enforcement moderateAC-5Separation of duties moderateAC-6Least privilege moderateAC-7Unsuccessful logon attempts moderateAC-8System Use Notification. Display [organization-defined] to users before granting access to the system that provides privacy and security notices consistent with applicable laws, executive orders, directives, regulations, policies, standards, and guidelines and state that: hardAC-9Previous Logon Notification. Notify the user, upon successful logon to the system, of the date and time of the last logon moderateAC-10Concurrent Session Control. Limit the number of concurrent sessions for each [organization-defined] to [organization-defined] moderateAC-11Device lock moderateAC-12Session control easyAC-14Permitted actions without identification or authentication moderateAC-16Security and Privacy Attributes. Provide the means to associate [organization-defined] with [organization-defined] for information in storage, in process, and/or in transmission; Ensure that the attribute associations are made and retained with the information; Establish hardAC-17Remote access moderateAC-18Wireless access hardAC-19Access control for mobile devices hardAC-20Use of external systems hardAC-21Information Sharing. Enable authorized users to determine whether access authorizations assigned to a sharing partner match the information's access and use restrictions for [organization-defined] ; and Employ [organization-defined] to assist users in making information hardAC-22Publicly accessible content hardAC-23Data Mining Protection. Employ [organization-defined] for [organization-defined] to detect and protect against unauthorized data mining hardAC-24Access Control Decisions. [organization-defined] to ensure [organization-defined] are applied to each access request prior to access enforcement hardAC-25Reference Monitor. Implement a reference monitor for [organization-defined] that is tamperproof, always invoked, and small enough to be subject to analysis and testing, the completeness of which can be assured hard

AT - Awareness and Training

AT-1Policy and procedures for awareness and training hardAT-2Literacy training and awareness easyAT-3Role-based training moderateAT-4Training records easyAT-6Training feedback hard

AU - Audit and Accountability

AU-1Policy and procedures for audit and accountability hardAU-2Event logging moderateAU-3Content of audit records easyAU-4Audit log storage capacity easyAU-5Response to audit logging process failures easyAU-6Audit record review, analysis, and reporting hardAU-7Audit record reduction and report generation easyAU-8Time stamps easyAU-9Protection of audit information easyAU-10Non-repudiation. Provide irrefutable evidence that an individual (or process acting on behalf of an individual) has performed [organization-defined] hardAU-11Audit record retention easyAU-12Audit record generation easyAU-13Monitoring for Information Disclosure. Monitor [organization-defined] [organization-defined] for evidence of unauthorized disclosure of organizational information; and If an information disclosure is discovered: Notify [organization-defined] ; and Take the following additional actions: [organization-defined] moderateAU-14Session Audit. Provide and implement the capability for [organization-defined] to [organization-defined] the content of a user session under [organization-defined] ; and Develop, integrate, and use session auditing activities in consultation with legal counsel and hardAU-16Cross-organizational Audit Logging. Employ [organization-defined] for coordinating [organization-defined] among external organizations when audit information is transmitted across organizational boundaries hard

CA - Assessment, Authorization, and Monitoring

CA-1Policy and procedures for assessment, authorization, and monitoring hardCA-2Control assessments hardCA-3Information exchange hardCA-5Plan of action and milestones hardCA-6Authorization hardCA-7Continuous monitoring easyCA-8Penetration testing hardCA-9Internal system connections hard

CM - Configuration Management

CM-1Policy and procedures for configuration management hardCM-2Baseline configuration easyCM-3Configuration change control moderateCM-4Impact analyses hardCM-5Access restrictions for change easyCM-6Configuration settings easyCM-7Least functionality moderateCM-8System component inventory moderateCM-9Configuration management plan moderateCM-10Software usage restrictions hardCM-11User-installed software easyCM-12Information Location. Identify and document the location of [organization-defined] and the specific system components on which the information is processed and stored; Identify and document the users who have access to the system and hardCM-13Data Action Mapping. Develop and document a map of system data actions hardCM-14Signed Components. Prevent the installation of [organization-defined] without verification that the component has been digitally signed using a certificate that is recognized and approved by the organization moderate

CP - Contingency Planning

CP-1Policy and procedures for contingency planning hardCP-2Contingency plan hardCP-3Contingency training moderateCP-4Contingency plan testing hardCP-6Alternate storage site hardCP-7Alternate processing site hardCP-8Telecommunications services hardCP-9System backup moderateCP-10System recovery and reconstitution hardCP-11Alternate Communications Protocols. Provide the capability to employ [organization-defined] in support of maintaining continuity of operations moderateCP-12Safe Mode. When [organization-defined] are detected, enter a safe mode of operation with [organization-defined] hardCP-13Alternative Security Mechanisms. Employ [organization-defined] for satisfying [organization-defined] when the primary means of implementing the security function is unavailable or compromised hard

IA - Identification and Authentication

IA-1Policy and procedures for identification and authentication hardIA-2Identification and authentication of organizational users moderateIA-3Device identification and authentication easyIA-4Identifier management hardIA-5Authenticator management hardIA-6Authentication feedback hardIA-7Cryptographic module authentication moderateIA-8Identification and authentication of non-organizational users moderateIA-9Service Identification and Authentication. Uniquely identify and authenticate [organization-defined] before establishing communications with devices, users, or other services or applications moderateIA-10Adaptive Authentication. Require individuals accessing the system to employ [organization-defined] under specific [organization-defined] hardIA-11Re-authentication easyIA-12Identity proofing hardIA-13Identity Providers and Authorization Servers. Employ identity providers and authorization servers to manage user, device, and non-person entity (NPE) identities, attributes, and access rights supporting authentication and authorization decisions in accordance with [organization-defined] using hard

IR - Incident Response

IR-1Policy and procedures for incident response hardIR-2Incident response training moderateIR-3Incident response testing hardIR-4Incident handling moderateIR-5Incident monitoring moderateIR-6Incident reporting hardIR-7Incident response assistance hardIR-8Incident response plan hardIR-9Information Spillage Response. Respond to information spills by: Assigning [organization-defined] with responsibility for responding to information spills; Identifying the specific information involved in the system contamination; Alerting [organization-defined] of the information spill using a hard

MA - Maintenance

MA-1Policy and procedures for maintenance hardMA-2Controlled maintenance hardMA-3Maintenance tools moderateMA-4Nonlocal maintenance moderateMA-5Maintenance personnel moderateMA-6Timely Maintenance. Obtain maintenance support and/or spare parts for [organization-defined] within [organization-defined] of failure hardMA-7Field Maintenance. Restrict or prohibit field maintenance on [organization-defined] to [organization-defined] hard

MP - Media Protection

MP-1Policy and procedures for media protection hardMP-2Media access moderateMP-3Media marking hardMP-4Media storage hardMP-5Media transport moderateMP-6Media sanitization moderateMP-7Media use moderateMP-8Media Downgrading. Establish [organization-defined] that includes employing downgrading mechanisms with strength and integrity commensurate with the security category or classification of the information; Verify that the system media downgrading process is commensurate with the hard

PE - Physical and Environmental Protection

PE-1Policy and procedures for physical and environmental protection hardPE-2Physical access authorizations easyPE-3Physical access control hardPE-4Access control for transmission hardPE-5Access control for output devices easyPE-6Monitoring physical access moderatePE-8Visitor access records hardPE-9Power equipment and cabling hardPE-10Emergency shutoff hardPE-11Emergency power moderatePE-12Emergency lighting hardPE-13Fire protection hardPE-14Environmental controls easyPE-15Water damage protection moderatePE-16Delivery and Removal. Authorize and control [organization-defined] entering and exiting the facility; and Maintain records of the system components hardPE-17Alternate work site hardPE-18Location of System Components. Position system components within the facility to minimize potential damage from [organization-defined] and to minimize the opportunity for unauthorized access hardPE-19Information Leakage. Protect the system from information leakage due to electromagnetic signals emanations hardPE-20Asset Monitoring and Tracking. Employ [organization-defined] to track and monitor the location and movement of [organization-defined] within [organization-defined] hardPE-21Electromagnetic Pulse Protection. Employ [organization-defined] against electromagnetic pulse damage for [organization-defined] hardPE-22Component Marking. Mark [organization-defined] indicating the impact level or classification level of the information permitted to be processed, stored, or transmitted by the hardware component hardPE-23Facility Location. Plan the location or site of the facility where the system resides considering physical and environmental hazards; and For existing facilities, consider the physical and environmental hazards in the organizational risk management hard

PL - Planning

PL-1Policy and procedures for planning hardPL-2System security and privacy plans hardPL-4Rules of behavior hardPL-7Concept of Operations. Develop a Concept of Operations (CONOPS) for the system describing how the organization intends to operate the system from the perspective of information security and privacy; and Review and update the hardPL-8Security and privacy architectures hardPL-9Central Management. Centrally manage [organization-defined] hardPL-10Baseline selection hardPL-11Baseline tailoring hard

PM - Program Management

PM-1Information Security Program Plan. Develop and disseminate an organization-wide information security program plan that: Provides an overview of the requirements for the security program and a description of the security program management controls and hardPM-2Information Security Program Leadership Role. Appoint a senior agency information security officer with the mission and resources to coordinate, develop, implement, and maintain an organization-wide information security program hardPM-3Information Security and Privacy Resources. Include the resources needed to implement the information security and privacy programs in capital planning and investment requests and document all exceptions to this requirement; Prepare documentation required for hardPM-4Plan of Action and Milestones Process. Implement a process to ensure that plans of action and milestones for the information security, privacy, and supply chain risk management programs and associated organizational systems: Are developed hardPM-5System Inventory. Develop and update [organization-defined] an inventory of organizational systems hardPM-6Measures of Performance. Develop, monitor, and report on the results of information security and privacy measures of performance hardPM-7Enterprise Architecture. Develop and maintain an enterprise architecture with consideration for information security, privacy, and the resulting risk to organizational operations and assets, individuals, other organizations, and the Nation hardPM-8Critical Infrastructure Plan. Address information security and privacy issues in the development, documentation, and updating of a critical infrastructure and key resources protection plan hardPM-9Risk Management Strategy. Develops a comprehensive strategy to manage: Security risk to organizational operations and assets, individuals, other organizations, and the Nation associated with the operation and use of organizational systems; and Privacy risk hardPM-10Authorization Process. Manage the security and privacy state of organizational systems and the environments in which those systems operate through authorization processes; Designate individuals to fulfill specific roles and responsibilities within the organizational risk hardPM-11Mission and Business Process Definition. Define organizational mission and business processes with consideration for information security and privacy and the resulting risk to organizational operations, organizational assets, individuals, other organizations, and the Nation; and hardPM-12Insider Threat Program. Implement an insider threat program that includes a cross-discipline insider threat incident handling team hardPM-13Security and Privacy Workforce. Establish a security and privacy workforce development and improvement program hardPM-14Testing, Training, and Monitoring. Implement a process for ensuring that organizational plans for conducting security and privacy testing, training, and monitoring activities associated with organizational systems: Are developed and maintained; and Continue to be hardPM-15Security and Privacy Groups and Associations. Establish and institutionalize contact with selected groups and associations within the security and privacy communities: To facilitate ongoing security and privacy education and training for organizational personnel; To hardPM-16Threat Awareness Program. Implement a threat awareness program that includes a cross-organization information-sharing capability for threat intelligence hardPM-17Protecting Controlled Unclassified Information on External Systems. Establish policy and procedures to ensure that requirements for the protection of controlled unclassified information that is processed, stored or transmitted on external systems, are implemented in hardPM-18Privacy Program Plan. Develop and disseminate an organization-wide privacy program plan that provides an overview of the agency's privacy program, and: Includes a description of the structure of the privacy program and the resources hardPM-19Privacy Program Leadership Role. Appoint a senior agency official for privacy with the authority, mission, accountability, and resources to coordinate, develop, and implement, applicable privacy requirements and manage privacy risks through the organization-wide privacy hardPM-20Dissemination of Privacy Program Information. Maintain a central resource webpage on the organization's principal public website that serves as a central source of information about the organization's privacy program and that: Ensures that the hardPM-21Accounting of Disclosures. Develop and maintain an accurate accounting of disclosures of personally identifiable information, including: Date, nature, and purpose of each disclosure; and Name and address, or other contact information of the individual hardPM-22Personally Identifiable Information Quality Management. Develop and document organization-wide policies and procedures for: Reviewing for the accuracy, relevance, timeliness, and completeness of personally identifiable information across the information life cycle; Correcting or deleting inaccurate hardPM-23Data Governance Body. Establish a Data Governance Body consisting of [organization-defined] with [organization-defined] hardPM-24Data Integrity Board. Establish a Data Integrity Board to: Review proposals to conduct or participate in a matching program; and Conduct an annual review of all matching programs in which the agency has participated hardPM-25Minimization of Personally Identifiable Information Used in Testing, Training, and Research. Develop, document, and implement policies and procedures that address the use of personally identifiable information for internal testing, training, and research; Limit or hardPM-26Complaint Management. Implement a process for receiving and responding to complaints, concerns, or questions from individuals about the organizational security and privacy practices that includes: Mechanisms that are easy to use and readily accessible hardPM-27Privacy Reporting. Develop [organization-defined] and disseminate to: [organization-defined] to demonstrate accountability with statutory, regulatory, and policy privacy mandates; and [organization-defined] and other personnel with responsibility for monitoring privacy program compliance; and Review and update hardPM-28Risk Framing. Identify and document: Assumptions affecting risk assessments, risk responses, and risk monitoring; Constraints affecting risk assessments, risk responses, and risk monitoring; Priorities and trade-offs considered by the organization for managing risk; and hardPM-29Risk Management Program Leadership Roles. Appoint a Senior Accountable Official for Risk Management to align organizational information security and privacy management processes with strategic, operational, and budgetary planning processes; and Establish a Risk Executive hardPM-30Supply Chain Risk Management Strategy. Develop an organization-wide strategy for managing supply chain risks associated with the development, acquisition, maintenance, and disposal of systems, system components, and system services; Implement the supply chain risk hardPM-31Continuous Monitoring Strategy. Develop an organization-wide continuous monitoring strategy and implement continuous monitoring programs that include: Establishing the following organization-wide metrics to be monitored: [organization-defined]; Establishing [organization-defined] and [organization-defined] for control effectiveness; Ongoing monitoring moderatePM-32Purposing. Analyze [organization-defined] supporting mission essential services or functions to ensure that the information resources are being used consistent with their intended purpose hard

PS - Personnel Security

PS-1Policy and procedures for personnel security hardPS-2Position risk designation hardPS-3Personnel screening moderatePS-4Personnel termination moderatePS-5Personnel transfer hardPS-6Access agreements hardPS-7External personnel security hardPS-8Personnel sanctions hardPS-9Position descriptions moderate

PT - PII Processing and Transparency

PT-1Policy and Procedures. Develop, document, and disseminate to [organization-defined]: [organization-defined] personally identifiable information processing and transparency policy that: Addresses purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance; and Is consistent hardPT-2Authority to Process Personally Identifiable Information. Determine and document the [organization-defined] that permits the [organization-defined] of personally identifiable information; and Restrict the [organization-defined] of personally identifiable information to only that which is authorized hardPT-3Personally Identifiable Information Processing Purposes. Identify and document the [organization-defined] for processing personally identifiable information; Describe the purpose(s) in the public privacy notices and policies of the organization; Restrict the [organization-defined] of personally identifiable hardPT-4Consent. Implement [organization-defined] for individuals to consent to the processing of their personally identifiable information prior to its collection that facilitate individuals' informed decision-making hardPT-5Privacy Notice. Provide notice to individuals about the processing of personally identifiable information that: Is available to individuals upon first interacting with an organization, and subsequently at [organization-defined]; Is clear and easy-to-understand, expressing information hardPT-6System of Records Notice. For systems that process information that will be maintained in a Privacy Act system of records: Draft system of records notices in accordance with OMB guidance and submit new and hardPT-7Specific Categories of Personally Identifiable Information. Apply [organization-defined] for specific categories of personally identifiable information hardPT-8Computer Matching Requirements. When a system or organization processes information for the purpose of conducting a matching program: Obtain approval from the Data Integrity Board to conduct the matching program; Develop and enter into hard

RA - Risk Assessment

RA-1Policy and procedures for risk assessment hardRA-2Security categorization hardRA-3Risk assessment hardRA-5Vulnerability monitoring and scanning easyRA-6Technical Surveillance Countermeasures Survey. Employ a technical surveillance countermeasures survey at [organization-defined] [organization-defined] hardRA-7Risk response hardRA-8Privacy Impact Assessments. Conduct privacy impact assessments for systems, programs, or other activities before: Developing or procuring information technology that processes personally identifiable information; and Initiating a new collection of personally identifiable information that: hardRA-9Criticality analysis hardRA-10Threat hunting hard

SA - System and Services Acquisition

SA-1Policy and procedures for system and services acquisition hardSA-2Allocation of resources hardSA-3System development life cycle moderateSA-4Acquisition process hardSA-5System documentation moderateSA-8Security and privacy engineering principles hardSA-9External system services hardSA-10Developer configuration management easySA-11Developer testing and evaluation moderateSA-15Development process, standards, and tools hardSA-16Developer-provided Training. Require the developer of the system, system component, or system service to provide the following training on the correct use and operation of the implemented security and privacy functions, controls, and/or mechanisms: hardSA-17Developer Security and Privacy Architecture and Design. Require the developer of the system, system component, or system service to produce a design specification and security and privacy architecture that: Is consistent with the organization's hardSA-20Customized Development of Critical Components. Reimplement or custom develop the following critical system components: [organization-defined] hardSA-21Developer Screening. Require that the developer of [organization-defined]: Has appropriate access authorizations as determined by assigned [organization-defined] ; and Satisfies the following additional personnel screening criteria: [organization-defined] hardSA-22Unsupported System Components hardSA-23Specialization. Employ [organization-defined] on [organization-defined] supporting mission essential services or functions to increase the trustworthiness in those systems or components hardSA-24Design For Cyber Resiliency. Design organizational systems, system components, or system services to achieve cyber resiliency by: Defining the following cyber resiliency goals: [organization-defined]. Defining the following cyber resiliency objectives: [organization-defined]. Defining the following hard

SC - System and Communications Protection

SC-1Policy and procedures for system and communications protection hardSC-2Separation of system and user functionality moderateSC-3Security Function Isolation. Isolate security functions from nonsecurity functions hardSC-4Information in shared system resources moderateSC-5Denial-of-service protection easySC-6Resource Availability. Protect the availability of resources by allocating [organization-defined] by [organization-defined] moderateSC-7Boundary protection hardSC-8Transmission confidentiality and integrity easySC-10Network disconnect easySC-11Trusted Path. Provide a [organization-defined] isolated trusted communications path for communications between the user and the trusted components of the system; and Permit users to invoke the trusted communications path for communications between the hardSC-12Cryptographic key establishment and management hardSC-13Cryptographic protection moderateSC-15Collaborative computing devices and applications moderateSC-16Transmission of Security and Privacy Attributes. Associate [organization-defined] with information exchanged between systems and between system components hardSC-17Public key infrastructure certificates hardSC-18Mobile Code. Define acceptable and unacceptable mobile code and mobile code technologies; and Authorize, monitor, and control the use of mobile code within the system hardSC-20Secure name/address resolution service moderateSC-21Secure name/address resolution service (recursive) easySC-22Architecture and provisioning for name/address resolution service hardSC-23Session authenticity moderateSC-24Fail in Known State. Fail to a [organization-defined] for the following failures on the indicated components while preserving [organization-defined] in failure: [organization-defined] hardSC-25Thin Nodes. Employ minimal functionality and information storage on the following system components: [organization-defined] hardSC-26Decoys. Include components within organizational systems specifically designed to be the target of malicious attacks for detecting, deflecting, and analyzing such attacks hardSC-27Platform-independent Applications. Include within organizational systems the following platform independent applications: [organization-defined] hardSC-28Protection of information at rest easySC-29Heterogeneity. Employ a diverse set of information technologies for the following system components in the implementation of the system: [organization-defined] hardSC-30Concealment and Misdirection. Employ the following concealment and misdirection techniques for [organization-defined] at [organization-defined] to confuse and mislead adversaries: [organization-defined] hardSC-31Covert Channel Analysis. Perform a covert channel analysis to identify those aspects of communications within the system that are potential avenues for covert [organization-defined] channels; and Estimate the maximum bandwidth of those channels hardSC-32System Partitioning. Partition the system into [organization-defined] residing in separate [organization-defined] domains or environments based on [organization-defined] hardSC-34Non-modifiable Executable Programs. For [organization-defined] , load and execute: The operating environment from hardware-enforced, read-only media; and The following applications from hardware-enforced, read-only media: [organization-defined] hardSC-35External Malicious Code Identification. Include system components that proactively seek to identify network-based malicious code or malicious websites hardSC-36Distributed Processing and Storage. Distribute the following processing and storage components across multiple [organization-defined]: [organization-defined] hardSC-37Out-of-band Channels. Employ the following out-of-band channels for the physical delivery or electronic transmission of [organization-defined] to [organization-defined]: [organization-defined] hardSC-38Operations Security. Employ the following operations security controls to protect key organizational information throughout the system development life cycle: [organization-defined] hardSC-39Process isolation moderateSC-40Wireless Link Protection. Protect external and internal [organization-defined] from the following signal parameter attacks: [organization-defined] hardSC-41Port and I/O Device Access. [organization-defined] disable or remove [organization-defined] on the following systems or system components: [organization-defined] moderateSC-42Sensor Capability and Data. Prohibit [organization-defined] ; and Provide an explicit indication of sensor use to [organization-defined] hardSC-43Usage Restrictions. Establish usage restrictions and implementation guidelines for the following system components: [organization-defined] ; and Authorize, monitor, and control the use of such components within the system hardSC-44Detonation Chambers. Employ a detonation chamber capability within [organization-defined] hardSC-45System Time Synchronization. Synchronize system clocks within and between systems and system components easySC-46Cross Domain Policy Enforcement. Implement a policy enforcement mechanism [organization-defined] between the physical and/or network interfaces for the connecting security domains hardSC-47Alternate Communications Paths. Establish [organization-defined] for system operations organizational command and control hardSC-48Sensor Relocation. Relocate [organization-defined] to [organization-defined] under the following conditions or circumstances: [organization-defined] easySC-49Hardware-enforced Separation and Policy Enforcement. Implement hardware-enforced separation and policy enforcement mechanisms between [organization-defined] hardSC-50Software-enforced Separation and Policy Enforcement. Implement software-enforced separation and policy enforcement mechanisms between [organization-defined] hardSC-51Hardware-based Protection. Employ hardware-based, write-protect for [organization-defined] ; and Implement specific procedures for [organization-defined] to manually disable hardware write-protect for firmware modifications and re-enable the write-protect prior to returning to operational mode hard

SI - System and Information Integrity

SI-1Policy and procedures for system and information integrity hardSI-2Flaw remediation hardSI-3Malicious code protection moderateSI-4System monitoring easySI-5Security alerts, advisories, and directives easySI-6Security and Privacy Function Verification. Verify the correct operation of [organization-defined]; Perform the verification of the functions specified in SI-6a [organization-defined]; Alert [organization-defined] to failed security and privacy verification tests; and [organization-defined] when anomalies hardSI-7Software, firmware, and information integrity easySI-8Spam Protection. Employ spam protection mechanisms at system entry and exit points to detect and act on unsolicited messages; and Update spam protection mechanisms when new releases are available in accordance with organizational configuration moderateSI-10Information input validation hardSI-11Error Handling. Generate error messages that provide information necessary for corrective actions without revealing information that could be exploited; and Reveal error messages only to [organization-defined] easySI-12Information management and retention moderateSI-13Predictable Failure Prevention. Determine mean time to failure (MTTF) for the following system components in specific environments of operation: [organization-defined] ; and Provide substitute system components and a means to exchange active and standby hardSI-14Non-persistence. Implement non-persistent [organization-defined] that are initiated in a known state and terminated [organization-defined] hardSI-15Information Output Filtering. Validate information output from the following software programs and/or applications to ensure that the information is consistent with the expected content: [organization-defined] easySI-16Memory protection easySI-17Fail-safe Procedures. Implement the indicated fail-safe procedures when the indicated failures occur: [organization-defined] hardSI-18Personally Identifiable Information Quality Operations. Check the accuracy, relevance, timeliness, and completeness of personally identifiable information across the information life cycle [organization-defined] ; and Correct or delete inaccurate or outdated personally identifiable information hardSI-19De-identification. Remove the following elements of personally identifiable information from datasets: [organization-defined] ; and Evaluate [organization-defined] for effectiveness of de-identification hardSI-20Tainting. Embed data or capabilities in the following systems or system components to determine if organizational data has been exfiltrated or improperly removed from the organization: [organization-defined] hardSI-21Information Refresh. Refresh [organization-defined] at [organization-defined] or generate the information on demand and delete the information when no longer needed moderateSI-22Information Diversity. Identify the following alternative sources of information for [organization-defined]: [organization-defined] ; and Use an alternative information source for the execution of essential functions or services on [organization-defined] when the primary source of hardSI-23Information Fragmentation. Based on [organization-defined]: Fragment the following information: [organization-defined] ; and Distribute the fragmented information across the following systems or system components: [organization-defined] hard

SR - Supply Chain Risk Management

SR-1Policy and procedures for supply chain risk management hardSR-2Supply chain risk management plan hardSR-3Supply chain controls and processes hardSR-4Provenance. Document, monitor, and maintain valid provenance of the following systems, system components, and associated data: [organization-defined] hardSR-5Acquisition strategies, tools, and methods hardSR-6Supplier assessments and reviews hardSR-7Supply Chain Operations Security. Employ the following Operations Security (OPSEC) controls to protect supply chain-related information for the system, system component, or system service: [organization-defined] hardSR-8Notification agreements hardSR-9Tamper Resistance and Detection. Implement a tamper protection program for the system, system component, or system service hardSR-10Inspection of systems or components hardSR-11Component authenticity hardSR-12Component disposal hard