relative Control Weighting = 09

Linked Issues

Issuelinks
Linktype Issue
is related to Data Governance
is related to Operationalizing Security, Compliance & Resilience Capabilities
is related to Implement Controls
is related to Situational Awareness of AI & Autonomous Technologies
is related to AI & Autonomous Technologies Risk Mapping
is related to AI & Autonomous Technologies Internal Controls
is related to AI & Autonomous Technologies Fairness & Bias
is related to Assigned Responsibilities for AI & Autonomous Technologies
is related to AI & Autonomous Technologies Risk Profiling
is related to AI TEVV Trustworthiness Demonstration
is related to AI TEVV Privacy Assessment
is related to AI TEVV Fairness & Bias Assessment
is related to AI TEVV Post-Deployment Monitoring
is related to Updating AI & Autonomous Technologies
is related to Robust Stakeholder Engagement for AI & Autonomous Technologies
is related to AI & Autonomous Technologies Stakeholder Feedback Integration
is related to AI & Autonomous Technologies Ongoing Assessments
is related to AI & Autonomous Technologies Incident & Error Reporting
is related to Data Source Lineage & Origin Disclosure
is related to Digital Content Modification Logging
is related to AI & Autonomous Technologies Stakeholder Competencies
is related to AI & Autonomous Technologies Negative Residual Risks
is related to AI & Autonomous Technologies Production Monitoring
is related to AI & Autonomous Technologies Environmental Impact & Sustainability
is related to Previously Unknown AI & Autonomous Technologies Threats & Risks
is related to Fine Tuning Risk Mitigation
is related to AI & Autonomous Technologies Risk Tracking Approaches
is related to AI & Autonomous Technologies Conformity
is related to Manipulative or Deceptive Techniques
is related to Materially Distorting Behaviors
is related to Social Scoring
is related to Detrimental or Unfavorable Treatment
is related to Populating Facial Recognition Databases
is related to AI & Autonomous Technologies Transparency
is related to AI & Autonomous Technologies Implementation Documentation
is related to AI & Autonomous Technologies Human Oversight
is related to AI & Autonomous Technologies Oversight Measures
is related to AI & Autonomous Technologies Separate Verification
is related to AI & Autonomous Technologies Oversight Functions Competency
is related to Data Action Mapping
is related to Unattended End-User Equipment
is related to Physical Tampering Detection
is related to Use of Third-Party Devices
is related to Prohibited Equipment & Services
is related to Telecommunications Equipment
is related to System Administrative Processes
is related to Database Administrative Processes
is related to Asset Categorization
is related to Categorize Artificial Intelligence (AI)-Related Technologies
is related to High-Risk Asset Categorization
is related to Business Continuity & Disaster Recovery (BC/DR) Plans
is related to Identify Critical Assets
is related to Contingency Plan Root Cause Analysis (RCA) & Lessons Learned
is related to Alternative Security Measures
is related to Alternate Storage Site
is related to Alternate Processing Site
is related to Testing for Reliability & Integrity
is related to Cryptographic Protection
is related to Backup Access
is related to Backup Modification and/or Destruction
is related to Technology Assets, Applications and/or Services (TAAS) Recovery & Reconstitution
is related to Transaction Recovery
is related to Test, Validate & Document Changes
is related to Security Impact Analysis for Changes
is related to Stakeholder Notification of Changes
is related to Control Functionality Verification
is related to Emergency Changes
is related to Dual Approval For High-Impact Environments
is related to Cloud Infrastructure Onboarding
is related to Cloud Infrastructure Offboarding
is related to Application Programming Interface (API) Security
is related to Multi-Tenant Environments
is related to Hosted Assets, Applications & Services
is related to Authorized Individuals For Hosted Assets, Applications & Services
is related to Sensitive / Regulated Data On Hosted Assets, Applications & Services
is related to Non-Compliance Oversight
is related to Conformity Assessment
is related to Configuration Management Program
is related to Approved Configuration Deviations
is related to Respond To Unauthorized Changes
is related to Baseline Tailoring
is related to Software Usage Restrictions
is related to Open Source Software
is related to Restrict Roles Permitted To Install Software
is related to Intrusion Detection & Prevention Systems (IDS & IPS)
is related to Automated Tools for Real-Time Analysis
is related to Inbound & Outbound Communications Traffic
is related to File Integrity Monitoring (FIM)
is related to Deactivated Account Activity
is related to Correlate Monitoring Information
is related to Cryptographic Cipher Suites and Protocols Inventory
is related to Non-Console Administrative Access
is related to Wireless Access Authentication & Encryption
is related to Public Key Infrastructure (PKI)
is related to Availability
is related to Symmetric Keys
is related to Asymmetric Keys
is related to Control & Distribution of Cryptographic Keys
is related to Sensitive / Regulated Data Protection
is related to Defining Access Authorizations for Sensitive / Regulated Data
is related to Physically Secure All Media
is related to Sensitive Data Inventories
is related to Making Sensitive Data Unreadable In Storage
is related to Media Transportation
is related to Custodians
is related to Sanitization of Personal Data (PD)
is related to Use of External Technology Assets, Applications and/or Services (TAAS)
is related to Portable Storage Devices
is related to Information Sharing
is related to Data Access Mapping
is related to Geographic Location of Data
is related to Internet of Things (IOT)
is related to Operational Technology (OT)
is related to Operating Environment Certification
is related to Safety Assessment
is related to Safe Operations
is related to Endpoint Protection Measures
is related to Prohibit Installation Without Privileged Status
is related to Automatic Antimalware Signature Updates
is related to Always On Protection
is related to Software Firewall
is related to Endpoint Detection & Response (EDR)
is related to Host Intrusion Detection and Prevention Systems (HIDS / HIPS)
is related to Trusted Path
is related to Collaborative Computing Devices
is related to Hypervisor Access
is related to Onboarding, Transferring & Offboarding Personnel
is related to User Awareness
is related to Competency Requirements for Security-Related Positions
is related to Roles With Special Protection Measures
is related to Social Media & Social Networking Restrictions
is related to Use of Critical Technologies
is related to Use of Mobile Devices
is related to Personnel Sanctions
is related to Personnel Transfer
is related to Personnel Termination
is related to Asset Collection
is related to High-Risk Terminations
is related to Authenticate, Authorize and Audit (AAA)
is related to Identification & Authentication for Organizational Users
is related to Replay-Resistant Authentication
is related to Identification & Authentication for Non-Organizational Users
is related to Identification & Authentication for Devices
is related to Identification & Authentication for Third-Party Technology Assets, Applications and/or Services (TAAS)
is related to Privileged Access by Non-Organizational Users
is related to Multi-Factor Authentication (MFA)
is related to Network Access to Privileged Accounts
is related to Role-Based Access Control (RBAC)
is related to Identifier Management (User Names)
is related to User Identity (ID) Management
is related to Privileged Account Identifiers
is related to Password-Based Authentication
is related to PKI-Based Authentication
is related to In-Person or Trusted Third-Party Registration
is related to Hardware Token-Based Authentication
is related to Events Requiring Authenticator Change
is related to Removal of Temporary / Emergency Accounts
is related to Use of Privileged Utility Programs
is related to Revocation of Access Authorizations
is related to Authorized System Accounts
is related to Authorize Access to Security Functions
is related to Non-Privileged Access for Non-Security Functions
is related to Auditing Use of Privileged Functions
is related to Prohibit Non-Privileged Users from Executing Privileged Functions
is related to Account Lockout
is related to Session Lock
is related to Pattern-Hiding Displays
is related to Session Termination
is related to Incident Response Operations
is related to Incident Response Plan (IRP)
is related to Incident Response Training
is related to Incident Response Testing
is related to Integrated Security Incident Response Team (ISIRT)
is related to Chain of Custody & Forensics
is related to Licensed Forensic Investigators
is related to Incident Stakeholder Reporting
is related to Automated Reporting
is related to Cyber Incident Reporting for Sensitive / Regulated Data
is related to Regulatory & Law Enforcement Contacts
is related to Assessment Boundaries
is related to Assessor Independence
is related to Specialized Assessments
is related to Third-Party Assessment Reciprocity
is related to Capabilities Deficiency Tracking
is related to Maintenance Operations
is related to Timely Maintenance
is related to Prevent Unauthorized Removal
is related to Remote Maintenance
is related to Auditing Remote Maintenance
is related to Remote Maintenance Notifications
is related to Remote Maintenance Cryptographic Protection
is related to Remote Maintenance Disconnect Verification
is related to Authorized Maintenance Personnel
is related to Access Control For Mobile Devices
is related to Full Device & Container-Based Encryption
is related to Mobile Device Tampering
is related to Remote Purging
is related to Layered Network Defenses
is related to Denial of Service (DoS) Protection
is related to Limit Network Connections
is related to Human Reviews
is related to Interconnection Security Agreements (ISAs)
is related to Security Management Subnets
is related to Virtual Local Area Network (VLAN) Separation
is related to Network Intrusion Detection / Prevention Systems (NIDS / NIPS)
is related to Architecture & Provisioning for Name / Address Resolution Service
is related to Secure Name / Address Resolution Service (Recursive or Caching Resolver)
is related to Domain Registrar Security
is related to Out-of-Band Channels
is related to End-User Messaging Technologies
is related to Protection of Confidentiality / Integrity Using Encryption
is related to Managed Access Control Points
is related to Wireless Networking
is related to Authentication & Encryption
is related to DNS & Content Filtering
is related to Route Internal Traffic to Proxy Servers
is related to Physical & Environmental Protections
is related to Role-Based Physical Access
is related to Controlled Ingress & Egress Points
is related to Intrusion Alarms / Surveillance Equipment
is related to Visitor Control
is related to Supporting Utilities
is related to Fire Detection Devices
is related to Temperature & Humidity Controls
is related to Equipment Siting & Protection
is related to Transmission Medium Security
is related to Proximity Sensor
is related to Physical Access Device Inventories
is related to Reasonable Data Privacy Practices
is related to Information Sharing With Third Parties
is related to Updating Personal Data (PD) Process
is related to Security, Compliance & Resilience Requirements Definition
is related to Risk Framing
is related to Risk Tolerance
is related to Risk Threshold
is related to Risk Appetite
is related to Risk-Based Security Categorization
is related to Impact-Level Prioritization
is related to Risk Identification
is related to Instances Requiring A Risk Assessment
is related to Risk Ranking
is related to Risk Response
is related to Compensating Countermeasures
is related to Risk Treatment Options
is related to Risk Treatment Plan (RTP)
is related to Risk Assessment Update
is related to Supply Chain Risk Assessment
is related to Data Protection Impact Assessment (DPIA)
is related to Risk Monitoring
is related to Executive Leadership Approval For Managing Material Risk
is related to Documented Alternatives
is related to Documented Justification For Material Risk Management Decisions
is related to Centralized Management of Security, Compliance & Resilience Controls
is related to Alignment With Enterprise Architecture
is related to Technical Debt Reviews
is related to Non-Persistence
is related to System Use Notification (Logon Banner)
is related to Standardized Microsoft Windows Banner
is related to Truncated Banner
is related to Clock Synchronization
is related to Standardized Operating Procedures (SOP)
is related to Security Concept Of Operations (CONOPS)
is related to Suspicious Communications & Anomalous System Behavior
is related to Sensitive / Regulated Data Storage, Handling & Processing
is related to Privileged Users
is related to Security, Compliance & Resilience Training Records
is related to Malware Testing Prior to Release
is related to Minimum Viable Product (MVP) Security Requirements
is related to Insecure Ports, Protocols & Services
is related to Minimizing Attack Surfaces
is related to Ongoing Product Security Support
is related to Product Testing & Reviews
is related to Software Bill of Materials (SBOM)
is related to Criticality Analysis During Development
is related to Software Assurance Maturity Model (SAMM)
is related to Secure Development Environments
is related to Security, Compliance & Resilience Testing Throughout Development
is related to Continuous Monitoring Plan
is related to Static Code Analysis
is related to Dynamic Code Analysis
is related to Application Penetration Testing
is related to Secure Settings By Default
is related to Use of Live Data
is related to Product Tampering and Counterfeiting (PTC)
is related to Developer Screening
is related to Developer Configuration Management
is related to Developer Threat Analysis & Flaw Remediation
is related to Developer-Provided Training
is related to Input Data Validation
is related to Error Handling
is related to Access to Program Source Code
is related to Product Conformity Governance
is related to Third-Party Criticality Assessments
is related to Supply Chain Risk Management (SCRM)
is related to Acquisition Strategies, Tools & Methods
is related to Limit Potential Harm
is related to Processes To Address Weaknesses or Deficiencies
is related to Adequate Supply
is related to Third-Party Risk Assessments & Approvals
is related to Security Compromise Notification Agreements
is related to Contract Flow-Down Requirements
is related to Break Clauses
is related to Third-Party Personnel Security
is related to Review of Third-Party Services
is related to Third-Party Deficiency Remediation
is related to Vulnerability & Patch Management Program (VPMP)
is related to Centralized Management of Flaw Remediation Processes
is related to Automated Remediation Status
is related to Software Patch Integrity
is related to Vulnerability Scanning
is related to Privileged Access
is related to Trend Analysis
is related to Review Historical Event logs
is related to External Vulnerability Assessment Scans
is related to Internal Vulnerability Assessment Scans
is related to Penetration Testing
is related to Unauthorized Code
is related to Use of Demilitarized Zones (DMZ)
is related to Web Security Standard
is related to Web Application Framework
is related to Validation & Sanitization
is related to Secure Web Traffic
is related to Output Encoding
is related to Web Browser Security
Impressum German English