Implementation examples
110 examples
- AC.L2-3.1.2[a] [b]
App roles and denied APIs: users only get the transactions their job needs
AO coverage. Addresses both Transaction & Function Control objectives. Function catalog. For each CUI app, security and the app owner maintain a matrix of job functions → app roles (read, contribute,…
ControlVerdict Corpus@cv-corpusJul 31, 2026Not enough signal100% · 2 - AC.L2-3.1.1[a] [b] [c] [d] [e] [f]
Enclave allow-list: users, service principals, and compliant devices only
AO coverage. Addresses all Authorized Access Control objectives for users, processes, and devices that can reach CUI. Authorized users. Enclave membership is three Entra security groups (engineer,…
ControlVerdict Corpus@cv-corpusJul 31, 2026Contested58% · 3 - AC.L2-3.1.12[a] [b] [c]
Compliant-device VPN or SSO only; session recording for privileged remote admin
AO coverage. Claims objectives [a], [b], and [c] (permit, identify types, and control remote access). Objective [d] (monitor sessions) is only partially covered here: VPN connect/disconnect and…
ControlVerdict Corpus@cv-corpusJul 31, 2026No verdicts yet Org-approved crypto module list; BitLocker and TLS configured to approved modes
AO coverage. Addresses all FIPS-validated cryptography objectives claimed for in-scope systems in this pattern. Approved modules. Maintain an inventory of cryptographic modules in use (OS FDE, TLS…
ControlVerdict Corpus@cv-corpusJul 31, 2026No verdicts yet- CM.L2-3.4.2[a] [b]
CIS-aligned Windows baseline assigned by compliance; drift becomes a ticket
AO coverage. Addresses both Security Configuration Enforcement objectives for the Windows CUI fleet. Lab Windows IoT and macOS engineer devices use a reduced checklist under documented exceptions but…
ControlVerdict Corpus@cv-corpusJul 31, 2026No verdicts yet - AU.L2-3.3.1[a] [b] [c] [d] [e] [f]
Central SIEM with required event catalog and 90-day hot retention
AO coverage. Addresses all create/retain audit-record objectives for this practice. Event catalog (minimum). Successful/failed authentication (IdP + local), privileged role activation, changes to…
ControlVerdict Corpus@cv-corpusJul 31, 2026Not enough signal75% · 2 - MP.L2-3.8.3[a] [b]
Full-disk encryption plus cryptographic erase; destroy when CE cannot be verified
AO coverage. Addresses all media sanitization objectives for this practice. Prerequisite. All in-scope endpoints use full-disk encryption with keys escrowed to the directory/MDM. Removable media that…
ControlVerdict Corpus@cv-corpusJul 31, 2026No verdicts yet - IA.L2-3.5.4[a]
Network access requires FIDO2 or certificate; OTP not accepted for VPN or SSO
AO coverage. Addresses all replay-resistant authentication objectives for this practice. Policy. Authentication strength for all CUI applications and the VPN requires a phishing-/replay-resistant…
ControlVerdict Corpus@cv-corpusJul 31, 2026No verdicts yet - AC.L2-3.1.3[a] [b] [c] [d] [e]
CUI only in labeled libraries; DLP blocks unlabeled egress
AO coverage. Addresses all Control CUI Flow assessment objectives for this practice. Authoritative store. CUI for active contracts lives only in labeled libraries under a single enclave site. Desktop…
ControlVerdict Corpus@cv-corpusJul 31, 2026No verdicts yet - AC.L2-3.1.5[a] [b] [c] [d]
Just-in-time admin roles; standing privilege only for break-glass
AO coverage. Addresses all Least Privilege assessment objectives for this practice. Scope. All privileged roles that can change enclave configuration, read broad CUI stores, or administer identity…
ControlVerdict Corpus@cv-corpusJul 31, 2026Contested50% · 3