Controls & assessment objectives
110 controls
- AU.L2-3.3.1AU · Audit and AccountabilityLevel 2CMMC L2
System Auditing
Create and retain system audit logs and records to the extent needed to enable the monitoring, analysis, investigation, and reporting of unlawful or unauthorized system activity.
- 6objectives
- 1examples
- 0threads
- AU.L2-3.3.2AU · Audit and AccountabilityLevel 2CMMC L2
User Accountability
Ensure that the actions of individual system users can be uniquely traced to those users so they can be held accountable for their actions.
- 2objectives
- 1examples
- 0threads
- AU.L2-3.3.3AU · Audit and AccountabilityLevel 2CMMC L2
Event Review
Review and update logged events.
- 3objectives
- 1examples
- 0threads
- AU.L2-3.3.4AU · Audit and AccountabilityLevel 2CMMC L2
Audit Failure Alerting
Alert in the event of an audit logging process failure.
- 3objectives
- 1examples
- 0threads
- AU.L2-3.3.5AU · Audit and AccountabilityLevel 2CMMC L2
Audit Correlation
Correlate audit record review, analysis, and reporting processes for investigation and response to indications of unlawful, unauthorized, suspicious, or unusual activity.
- 2objectives
- 1examples
- 0threads
- AU.L2-3.3.6AU · Audit and AccountabilityLevel 2CMMC L2
Reduction & Reporting
Provide audit record reduction and report generation to support on-demand analysis and reporting.
- 2objectives
- 1examples
- 0threads
- AU.L2-3.3.7AU · Audit and AccountabilityLevel 2CMMC L2
Authoritative Time Source
Provide a system capability that compares and synchronizes internal system clocks with an authoritative source to generate time stamps for audit records.
- 3objectives
- 1examples
- 0threads
- AU.L2-3.3.8AU · Audit and AccountabilityLevel 2CMMC L2
Audit Protection
Protect audit information and audit logging tools from unauthorized access, modification, and deletion.
- 6objectives
- 1examples
- 0threads
- AU.L2-3.3.9AU · Audit and AccountabilityLevel 2CMMC L2
Audit Management
Limit management of audit logging functionality to a subset of privileged users.
- 2objectives
- 1examples
- 0threads
- CM.L2-3.4.1CM · Configuration ManagementLevel 2CMMC L2
System Baselining
Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles.
- 6objectives
- 1examples
- 0threads
- CM.L2-3.4.2CM · Configuration ManagementLevel 2CMMC L2
Security Configuration Enforcement
Establish and enforce security configuration settings for information technology products employed in organizational systems.
- 2objectives
- 1examples
- 0threads
- CM.L2-3.4.3CM · Configuration ManagementLevel 2CMMC L2
System Change Management
Track, review, approve or disapprove, and log changes to organizational systems.
- 4objectives
- 1examples
- 0threads
- CM.L2-3.4.4CM · Configuration ManagementLevel 2CMMC L2
Security Impact Analysis
Analyze the security impact of changes prior to implementation.
- 1objectives
- 1examples
- 0threads
- CM.L2-3.4.5CM · Configuration ManagementLevel 2CMMC L2
Access Restrictions for Change
Define, document, approve, and enforce physical and logical access restrictions associated with changes to organizational systems.
- 8objectives
- 1examples
- 0threads
- CM.L2-3.4.6CM · Configuration ManagementLevel 2CMMC L2
Least Functionality
Employ the principle of least functionality by configuring organizational systems to provide only essential capabilities.
- 2objectives
- 1examples
- 0threads
- CM.L2-3.4.7CM · Configuration ManagementLevel 2CMMC L2
Nonessential Functionality
Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services.
- 15objectives
- 1examples
- 0threads
- CM.L2-3.4.8CM · Configuration ManagementLevel 2CMMC L2
Application Execution Policy
Apply deny-by-exception (blacklisting) policy to prevent the use of unauthorized software or deny-all, permit-by-exception (whitelisting) policy to allow the execution of authorized software.
- 3objectives
- 1examples
- 0threads
- CM.L2-3.4.9CM · Configuration ManagementLevel 2CMMC L2
User-installed Software
Control and monitor user-installed software.
- 3objectives
- 1examples
- 0threads
- IA.L2-3.5.1IA · Identification and AuthenticationLevel 2CMMC L2
Identification [CUI Data]
Identify system users, processes acting on behalf of users, and devices.
- 3objectives
- 1examples
- 1threads
- IA.L2-3.5.2IA · Identification and AuthenticationLevel 2CMMC L2
Authentication [CUI Data]
Authenticate (or verify) the identities of users, processes, or devices, as a prerequisite to allowing access to organizational systems.
- 3objectives
- 1examples
- 0threads
- IA.L2-3.5.3IA · Identification and AuthenticationLevel 2CMMC L2
Multifactor Authentication
Use multifactor authentication for local and network access to privileged accounts and for network access to non-privileged accounts.
- 4objectives
- 1examples
- 0threads
- IA.L2-3.5.4IA · Identification and AuthenticationLevel 2CMMC L2
Replay-resistant Authentication
Employ replay-resistant authentication mechanisms for network access to privileged and non-privileged accounts.
- 1objectives
- 1examples
- 0threads
- IA.L2-3.5.5IA · Identification and AuthenticationLevel 2CMMC L2
Identifier Reuse
Prevent reuse of identifiers for a defined period.
- 2objectives
- 1examples
- 0threads
- IA.L2-3.5.6IA · Identification and AuthenticationLevel 2CMMC L2
Identifier Handling
Disable identifiers after a defined period of inactivity.
- 2objectives
- 1examples
- 0threads
- IA.L2-3.5.7IA · Identification and AuthenticationLevel 2CMMC L2
Password Complexity
Enforce a minimum password complexity and change of characters when new passwords are created.
- 4objectives
- 1examples
- 0threads