Skip to content

PROTECT (PR)

Safeguards to manage the organization's cybersecurity risks are used

Informative References

  • CRI Profile v2.0: PR
  • CSF v1.1: PR
  • ISO/IEC 27001:2022: Mandatory Clause: 8.3
  • ISO/IEC 27001:2022: Annex A Controls: All applicable controls
  • SCF: GOV-01
  • SCF: CPL-01
  • SCF: RSK-01
  • SCF: RSK-09

Identity Management, Authentication, and Access Control (PR.AA)

Access to physical and logical assets is limited to authorized users, services, and hardware and managed commensurate with the assessed risk of unauthorized access

Informative References

  • CRI Profile v2.0: PR.AA
  • CSF v1.1: PR.AC
  • ISO/IEC 27001:2022: Mandatory Clause: None
  • ISO/IEC 27001:2022: Annex A Controls: 5.15
  • ISO/IEC 27001:2022: Annex A Controls: 5.18
  • ISO/IEC 27001:2022: Annex A Controls: 8.2
  • ISO/IEC 27001:2022: Annex A Controls: 8.3
  • NICE Framework: DD-WRL-001
  • NICE Framework: DD-WRL-004
  • NICE Framework: IO-WRL-002
  • NICE Framework: IO-WRL-003
  • NICE Framework: IO-WRL-005
  • NICE Framework: OG-WRL-002
  • NICE Framework: OG-WRL-013
  • NICE Framework: OG-WRL-014
  • NICE Framework: PD-WRL-004
  • SCF: IAC-01
  • SCF: IAC-01.2
  • SCF: PES-01
  • SCF: PES-02
  • SCF: PES-03

PR.AA-01

Identities and credentials for authorized users, services, and hardware are managed by the organization

Implementation Examples

  • Ex1: Initiate requests for new access or additional access for employees, contractors, and others, and track, review, and fulfill the requests, with permission from system or data owners when needed
  • Ex2: Issue, manage, and revoke cryptographic certificates and identity tokens, cryptographic keys (i.e., key management), and other credentials
  • Ex3: Select a unique identifier for each device from immutable hardware characteristics or an identifier securely provisioned to the device
  • Ex4: Physically label authorized hardware with an identifier for inventory and servicing purposes

Informative References

  • CCMv4.0: CEK-01
  • CCMv4.0: CEK-10
  • CCMv4.0: CEK-11
  • CCMv4.0: CEK-12
  • CCMv4.0: CEK-13
  • CCMv4.0: CEK-14
  • CCMv4.0: CEK-15
  • CCMv4.0: CEK-16
  • CCMv4.0: CEK-17
  • CCMv4.0: CEK-18
  • CCMv4.0: CEK-19
  • CCMv4.0: CEK-20
  • CCMv4.0: CEK-21
  • CCMv4.0: DCS-08
  • CCMv4.0: IAM-01
  • CCMv4.0: IAM-03
  • CCMv4.0: IAM-06
  • CCMv4.0: IAM-07
  • CCMv4.0: IAM-09
  • CCMv4.0: IAM-13
  • CCMv4.0: IAM-14
  • CCMv4.0: IAM-15
  • CCMv4.0: IAM-16
  • CCMv4.0: UEM-14
  • CIS Controls v8.0: 5.1
  • CIS Controls v8.0: 6.7
  • CIS Controls v8.1: 5.1
  • CIS Controls v8.1: 5.6
  • CIS Controls v8.1: 6.7
  • CRI Profile v2.0: PR.AA-01
  • CRI Profile v2.0: PR.AA-01.01
  • CRI Profile v2.0: PR.AA-01.02
  • CSF v1.1: PR.AC-1
  • IRP: IRP-Sec-4
  • ISO/IEC 27001:2022: Mandatory Clause: None
  • ISO/IEC 27001:2022: Annex A Controls: 5.15
  • ISO/IEC 27001:2022: Annex A Controls: 5.18
  • ISO/IEC 27001:2022: Annex A Controls: 8.2
  • ISO/IEC 27001:2022: Annex A Controls: 8.5
  • ISO/IEC 27001:2022: Control 5.16
  • NICE Framework: DD-WRL-001
  • NICE Framework: IO-WRL-003
  • NICE Framework: IO-WRL-005
  • NICE Framework: OG-WRL-013
  • NICE Framework: OG-WRL-014
  • NICE Framework: PD-WRL-004
  • OWASP Top 10 LLM Applications: LLM02-2025
  • OWASP Top 10 LLM Applications: LLM06-2025
  • PCI DSS: 8.2.1
  • PCI DSS: 8.6.2
  • PCI DSS: 8.6.3
  • PCI DSS: 3.6.1
  • PCI DSS: 3.6.1.1
  • PCI DSS: 3.6.1.2
  • PCI DSS: 3.6.1.3
  • PCI DSS: 3.6.1.4
  • PCI DSS: 9.5.1.1
  • PCI DSS: 12.5.1
  • SCF: IAC-02
  • SCF: IAC-03
  • SCF: IAC-04
  • SCF: IAC-05
  • SDOS: SDOS-IA-01
  • SDOS: SDOS-IA-02
  • SP 800-171 Rev 3: 03.01.01
  • SP 800-171 Rev 3: 03.05.01
  • SP 800-171 Rev 3: 03.05.02
  • SP 800-171 Rev 3: 03.05.03
  • SP 800-171 Rev 3: 03.05.04
  • SP 800-171 Rev 3: 03.05.05
  • SP 800-171 Rev 3: 03.05.07
  • SP 800-171 Rev 3: 03.05.11
  • SP 800-171 Rev 3: 03.05.12
  • SP 800-171 Rev 3: 03.15.01
  • SP 800-53 Rev 5.1.1: AC-01
  • SP 800-53 Rev 5.1.1: AC-02
  • SP 800-53 Rev 5.1.1: AC-14
  • SP 800-53 Rev 5.1.1: IA-01
  • SP 800-53 Rev 5.1.1: IA-02
  • SP 800-53 Rev 5.1.1: IA-03
  • SP 800-53 Rev 5.1.1: IA-04
  • SP 800-53 Rev 5.1.1: IA-05
  • SP 800-53 Rev 5.1.1: IA-06
  • SP 800-53 Rev 5.1.1: IA-07
  • SP 800-53 Rev 5.1.1: IA-08
  • SP 800-53 Rev 5.1.1: IA-09
  • SP 800-53 Rev 5.1.1: IA-10
  • SP 800-53 Rev 5.1.1: IA-11
  • SP 800-53 Rev 5.2.0: AC-01
  • SP 800-53 Rev 5.2.0: AC-02
  • SP 800-53 Rev 5.2.0: AC-14
  • SP 800-53 Rev 5.2.0: IA-01
  • SP 800-53 Rev 5.2.0: IA-02
  • SP 800-53 Rev 5.2.0: IA-03
  • SP 800-53 Rev 5.2.0: IA-04
  • SP 800-53 Rev 5.2.0: IA-05
  • SP 800-53 Rev 5.2.0: IA-06
  • SP 800-53 Rev 5.2.0: IA-07
  • SP 800-53 Rev 5.2.0: IA-08
  • SP 800-53 Rev 5.2.0: IA-09
  • SP 800-53 Rev 5.2.0: IA-10
  • SP 800-53 Rev 5.2.0: IA-11

PR.AA-02

Identities are proofed and bound to credentials based on the context of interactions

Implementation Examples

  • Ex1: Verify a person's claimed identity at enrollment time using government-issued identity credentials (e.g., passport, visa, driver's license)
  • Ex2: Issue a different credential for each person (i.e., no credential sharing)

Informative References

  • CCMv4.0: IAM-01
  • CCMv4.0: IAM-03
  • CCMv4.0: IAM-13
  • CCMv4.0: IAM-14
  • CCMv4.0: IAM-16
  • CCMv4.0: UEM-14
  • CRI Profile v2.0: PR.AA-02
  • CRI Profile v2.0: PR.AA-02.01
  • CSF v1.1: PR.AC-6
  • ISO/IEC 27001:2022: Mandatory Clause: None
  • ISO/IEC 27001:2022: Annex A Controls: 8.2
  • ISO/IEC 27001:2022: Annex A Controls: 8.3
  • ISO/IEC 27001:2022: Annex A Controls: 8.5
  • NICE Framework: DD-WRL-001
  • NICE Framework: IO-WRL-003
  • NICE Framework: IO-WRL-005
  • NICE Framework: OG-WRL-013
  • NICE Framework: OG-WRL-014
  • NICE Framework: PD-WRL-004
  • OWASP Top 10 LLM Applications: LLM06-2025
  • PCI DSS: 12.7.1
  • PCI DSS: 8.2.1
  • PCI DSS: 8.3.5
  • PCI DSS: 8.2.2
  • SCF: IAC-28
  • SDOS: SDOS-IA-01
  • SDOS: SDOS-IA-02
  • SP 800-53 Rev 5.1.1: IA-12
  • SP 800-53 Rev 5.2.0: IA-12

PR.AA-03

Users, services, and hardware are authenticated

Implementation Examples

  • Ex1: Require multifactor authentication
  • Ex2: Enforce policies for the minimum strength of passwords, PINs, and similar authenticators
  • Ex3: Periodically reauthenticate users, services, and hardware based on risk (e.g., in zero trust architectures)
  • Ex4: Ensure that authorized personnel can access accounts essential for protecting safety under emergency conditions

Informative References

  • CCMv4.0: DCS-08
  • CCMv4.0: IAM-01
  • CCMv4.0: IAM-02
  • CCMv4.0: IAM-14
  • CCMv4.0: IAM-16
  • CCMv4.0: IVS-03
  • CCMv4.0: UEM-05
  • CCMv4.0: UEM-06
  • CCMv4.0: UEM-14
  • CRI Profile v2.0: PR.AA-03
  • CRI Profile v2.0: PR.AA-03.01
  • CRI Profile v2.0: PR.AA-03.02
  • CRI Profile v2.0: PR.AA-03.03
  • CSF v1.1: PR.AC-3
  • CSF v1.1: PR.AC-7
  • ISO/IEC 27001:2022: Mandatory Clause: None
  • ISO/IEC 27001:2022: Annex A Controls: 5.15
  • ISO/IEC 27001:2022: Annex A Controls: 5.16
  • ISO/IEC 27001:2022: Annex A Controls: 5.17
  • ISO/IEC 27001:2022: Annex A Controls: 5.18
  • ISO/IEC 27001:2022: Annex A Controls: 8.5
  • ISO/IEC 27001:2022: Control 5.17
  • ISO/IEC 27001:2022: Control 8.5
  • NICE Framework: DD-WRL-001
  • NICE Framework: IO-WRL-002
  • NICE Framework: IO-WRL-003
  • NICE Framework: IO-WRL-005
  • NICE Framework: OG-WRL-013
  • NICE Framework: OG-WRL-014
  • NICE Framework: PD-WRL-004
  • OWASP Top 10 LLM Applications: LLM06-2025
  • OWASP Top 10 LLM Applications: LLM10-2025
  • PCI DSS: 8.3.1
  • PCI DSS: 8.3.6
  • PCI DSS: 8.3.7
  • PCI DSS: 8.3.8
  • PCI DSS: 8.3.9
  • PCI DSS: 8.2.8
  • PCI DSS: 9.2.4
  • PCI DSS: 2.2.2
  • PCI DSS: 2.3.1
  • PCI DSS: 3.5.1.3
  • PCI DSS: 8.3.10
  • PCI DSS: 8.3.10.1
  • SCF: IAC-01.2
  • SCF: IAC-02
  • SCF: IAC-03
  • SCF: IAC-04
  • SCF: IAC-05
  • SDOS: SDOS-AD-01
  • SDOS: SDOS-IA-01
  • SP 800-171 Rev 3: 03.01.11
  • SP 800-171 Rev 3: 03.05.01
  • SP 800-171 Rev 3: 03.05.02
  • SP 800-171 Rev 3: 03.05.03
  • SP 800-171 Rev 3: 03.05.04
  • SP 800-171 Rev 3: 03.05.07
  • SP 800-171 Rev 3: 03.05.12
  • SP 800-53 Rev 5.1.1: AC-07
  • SP 800-53 Rev 5.1.1: AC-12
  • SP 800-53 Rev 5.1.1: IA-02
  • SP 800-53 Rev 5.1.1: IA-03
  • SP 800-53 Rev 5.1.1: IA-05
  • SP 800-53 Rev 5.1.1: IA-07
  • SP 800-53 Rev 5.1.1: IA-08
  • SP 800-53 Rev 5.1.1: IA-09
  • SP 800-53 Rev 5.1.1: IA-10
  • SP 800-53 Rev 5.1.1: IA-11
  • SP 800-53 Rev 5.2.0: AC-07
  • SP 800-53 Rev 5.2.0: AC-12
  • SP 800-53 Rev 5.2.0: IA-02
  • SP 800-53 Rev 5.2.0: IA-03
  • SP 800-53 Rev 5.2.0: IA-05
  • SP 800-53 Rev 5.2.0: IA-07
  • SP 800-53 Rev 5.2.0: IA-08
  • SP 800-53 Rev 5.2.0: IA-09
  • SP 800-53 Rev 5.2.0: IA-10
  • SP 800-53 Rev 5.2.0: IA-11
  • SP 800-81r3: 3.1
  • SP 800-81r3: 3.3.2
  • SP 800-81r3: 3.4.2
  • SSDF: PO.5.2

PR.AA-04

Identity assertions are protected, conveyed, and verified

Implementation Examples

  • Ex1: Protect identity assertions that are used to convey authentication and user information through single sign-on systems
  • Ex2: Protect identity assertions that are used to convey authentication and user information between federated systems
  • Ex3: Implement standards-based approaches for identity assertions in all contexts, and follow all guidance for the generation (e.g., data models, metadata), protection (e.g., digital signing, encryption), and verification (e.g., signature validation) of identity assertions

Informative References

  • CCMv4.0: IAM-01
  • CCMv4.0: IAM-03
  • CCMv4.0: IAM-16
  • CRI Profile v2.0: PR.AA-04
  • CRI Profile v2.0: PR.AA-04.01
  • ISO/IEC 27001:2022: Mandatory Clause: None
  • ISO/IEC 27001:2022: Annex A Controls: 5.16
  • NICE Framework: DD-WRL-001
  • NICE Framework: IO-WRL-002
  • NICE Framework: IO-WRL-003
  • NICE Framework: IO-WRL-005
  • NICE Framework: OG-WRL-013
  • NICE Framework: OG-WRL-014
  • NICE Framework: PD-WRL-004
  • OWASP Top 10 LLM Applications: LLM06-2025
  • PCI DSS: 12.3.3
  • PCI DSS: 3.6.1
  • PCI DSS: 3.6.1.1
  • PCI DSS: 3.6.1.2
  • PCI DSS: 3.6.1.3
  • PCI DSS: 3.6.1.4
  • PCI DSS: 4.2.1
  • SCF: IAC-01.2
  • SCF: IAC-02.2
  • SDOS: SDOS-AU-01
  • SDOS: SDOS-IA-01
  • SP 800-53 Rev 5.1.1: IA-13
  • SP 800-53 Rev 5.2.0: IA-13

PR.AA-05

Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties

Implementation Examples

  • Ex1: Review logical and physical access privileges periodically and whenever someone changes roles or leaves the organization, and promptly rescind privileges that are no longer needed
  • Ex2: Take attributes of the requester and the requested resource into account for authorization decisions (e.g., geolocation, day/time, requester endpoint's cyber health)
  • Ex3: Restrict access and privileges to the minimum necessary (e.g., zero trust architecture)
  • Ex4: Periodically review the privileges associated with critical business functions to confirm proper separation of duties

Informative References

  • BXAIOS: Chapter 6 - Install the Router
  • CCMv4.0: CCC-04
  • CCMv4.0: CEK-10
  • CCMv4.0: CEK-11
  • CCMv4.0: CEK-12
  • CCMv4.0: CEK-13
  • CCMv4.0: CEK-14
  • CCMv4.0: CEK-15
  • CCMv4.0: CEK-16
  • CCMv4.0: CEK-17
  • CCMv4.0: CEK-18
  • CCMv4.0: CEK-19
  • CCMv4.0: CEK-20
  • CCMv4.0: CEK-21
  • CCMv4.0: IAM-01
  • CCMv4.0: IAM-03
  • CCMv4.0: IAM-04
  • CCMv4.0: IAM-05
  • CCMv4.0: IAM-06
  • CCMv4.0: IAM-07
  • CCMv4.0: IAM-08
  • CCMv4.0: IAM-09
  • CCMv4.0: IAM-10
  • CCMv4.0: IAM-11
  • CCMv4.0: IAM-12
  • CCMv4.0: IAM-16
  • CCMv4.0: IVS-03
  • CCMv4.0: IVS-06
  • CCMv4.0: LOG-02
  • CCMv4.0: LOG-04
  • CCMv4.0: LOG-09
  • CCMv4.0: UEM-05
  • CCMv4.0: UEM-14
  • CIS Controls v8.0: 3.3
  • CIS Controls v8.0: 6.8
  • CIS Controls v8.1: 3.3
  • CIS Controls v8.1: 5.1
  • CIS Controls v8.1: 6.8
  • CRI Profile v2.0: PR.AA-05
  • CRI Profile v2.0: PR.AA-05.01
  • CRI Profile v2.0: PR.AA-05.02
  • CRI Profile v2.0: PR.AA-05.03
  • CRI Profile v2.0: PR.AA-05.04
  • CSF v1.1: PR.AC-1
  • CSF v1.1: PR.AC-3
  • CSF v1.1: PR.AC-4
  • ISO/IEC 27001:2022: Mandatory Clause: None
  • ISO/IEC 27001:2022: Annex A Controls: 5.1
  • ISO/IEC 27001:2022: Annex A Controls: 5.3
  • ISO/IEC 27001:2022: Annex A Controls: 5.14
  • ISO/IEC 27001:2022: Annex A Controls: 5.15
  • ISO/IEC 27001:2022: Annex A Controls: 5.16
  • ISO/IEC 27001:2022: Annex A Controls: 5.17
  • ISO/IEC 27001:2022: Annex A Controls: 5.18
  • ISO/IEC 27001:2022: Annex A Controls: 8.2
  • ISO/IEC 27001:2022: Annex A Controls: 8.3
  • ISO/IEC 27001:2022: Annex A Controls: 8.5
  • ISO/IEC 27001:2022: Annex A Controls: 8.18
  • ISO/IEC 27001:2022: Control 5.15
  • ISO/IEC 27001:2022: Control 5.18
  • ISO/IEC 27001:2022: Control 8.2
  • ISO/IEC 27001:2022: Control 8.3
  • ISO/IEC 27001:2022: Control 8.4
  • ISO/IEC 27001:2022: Control 8.18
  • NICE Framework: DD-WRL-001
  • NICE Framework: DD-WRL-004
  • NICE Framework: IO-WRL-003
  • NICE Framework: IO-WRL-005
  • NICE Framework: OG-WRL-002
  • NICE Framework: OG-WRL-013
  • NICE Framework: OG-WRL-014
  • NICE Framework: PD-WRL-004
  • OWASP Top 10 LLM Applications: LLM01-2025
  • OWASP Top 10 LLM Applications: LLM02-2025
  • OWASP Top 10 LLM Applications: LLM06-2025
  • OWASP Top 10 LLM Applications: LLM07-2025
  • OWASP Top 10 LLM Applications: LLM08-2025
  • OWASP Top 10 LLM Applications: LLM10-2025
  • PCI DSS: 7.2.2
  • PCI DSS: 7.2.4
  • PCI DSS: 7.2.5.1
  • PCI DSS: 8.2.6
  • PCI DSS: 12.1.3
  • PCI DSS: 8.1.1
  • PCI DSS: 7.1.1
  • PCI DSS: 7.2.1
  • SCF: HRS-02
  • SCF: HRS-11
  • SCF: IAC-01
  • SCF: IAC-01.2
  • SCF: IAC-02
  • SCF: IAC-03
  • SCF: IAC-04
  • SCF: IAC-05
  • SCF: IAC-08
  • SCF: IAC-21
  • SDOS: SDOS-AD-01
  • SDOS: SDOS-EN-02
  • SDOS: SDOS-GV-01
  • SDOS: SDOS-GV-05
  • SP 800-171 Rev 3: 03.01.01
  • SP 800-171 Rev 3: 03.01.02
  • SP 800-171 Rev 3: 03.01.04
  • SP 800-171 Rev 3: 03.01.05
  • SP 800-171 Rev 3: 03.01.06
  • SP 800-171 Rev 3: 03.01.07
  • SP 800-171 Rev 3: 03.01.12
  • SP 800-171 Rev 3: 03.01.16
  • SP 800-171 Rev 3: 03.01.18
  • SP 800-171 Rev 3: 03.13.08
  • SP 800-171 Rev 3: 03.15.01
  • SP 800-53 Rev 5.1.1: AC-01
  • SP 800-53 Rev 5.1.1: AC-02
  • SP 800-53 Rev 5.1.1: AC-03
  • SP 800-53 Rev 5.1.1: AC-05
  • SP 800-53 Rev 5.1.1: AC-06
  • SP 800-53 Rev 5.1.1: AC-10
  • SP 800-53 Rev 5.1.1: AC-16
  • SP 800-53 Rev 5.1.1: AC-17
  • SP 800-53 Rev 5.1.1: AC-18
  • SP 800-53 Rev 5.1.1: AC-19
  • SP 800-53 Rev 5.1.1: AC-24
  • SP 800-53 Rev 5.1.1: IA-13
  • SP 800-53 Rev 5.2.0: AC-01
  • SP 800-53 Rev 5.2.0: AC-02
  • SP 800-53 Rev 5.2.0: AC-03
  • SP 800-53 Rev 5.2.0: AC-05
  • SP 800-53 Rev 5.2.0: AC-06
  • SP 800-53 Rev 5.2.0: AC-10
  • SP 800-53 Rev 5.2.0: AC-16
  • SP 800-53 Rev 5.2.0: AC-17
  • SP 800-53 Rev 5.2.0: AC-18
  • SP 800-53 Rev 5.2.0: AC-19
  • SP 800-53 Rev 5.2.0: AC-24
  • SP 800-53 Rev 5.2.0: IA-13
  • SP 800-81r3: 3.1.1
  • SSDF: PO.5.2
  • SSDF: PS.1.1

PR.AA-06

Physical access to assets is managed, monitored, and enforced commensurate with risk

Implementation Examples

  • Ex1: Use security guards, security cameras, locked entrances, alarm systems, and other physical controls to monitor facilities and restrict access
  • Ex2: Employ additional physical security controls for areas that contain high-risk assets
  • Ex3: Escort guests, vendors, and other third parties within areas that contain business-critical assets

Informative References

  • CCMv4.0: DCS-03
  • CCMv4.0: DCS-07
  • CCMv4.0: DCS-09
  • CCMv4.0: DCS-10
  • CCMv4.0: DCS-12
  • CCMv4.0: DCS-14
  • CCMv4.0: HRS-04
  • CCMv4.0: LOG-12
  • CCMv4.0: UEM-05
  • CCMv4.0: UEM-06
  • CCMv4.0: UEM-14
  • CRI Profile v2.0: PR.AA-06
  • CRI Profile v2.0: PR.AA-06.01
  • CRI Profile v2.0: PR.AA-06.02
  • CSF v1.1: PR.AC-2
  • CSF v1.1: PR.PT-4
  • ISO/IEC 27001:2022: Mandatory Clause: None
  • ISO/IEC 27001:2022: Annex A Controls: 7.1
  • ISO/IEC 27001:2022: Annex A Controls: 7.2
  • ISO/IEC 27001:2022: Annex A Controls: 7.3
  • ISO/IEC 27001:2022: Annex A Controls: 7.4
  • ISO/IEC 27001:2022: Annex A Controls: 7.12
  • ISO/IEC 27001:2022: Control 7.1
  • ISO/IEC 27001:2022: Control 7.2
  • ISO/IEC 27001:2022: Control 7.3
  • ISO/IEC 27001:2022: Control 7.4
  • NICE Framework: DD-WRL-001
  • NICE Framework: IO-WRL-005
  • NICE Framework: OG-WRL-013
  • NICE Framework: OG-WRL-014
  • PCI DSS: 9.3.1.1
  • PCI DSS: 9.2.4
  • PCI DSS: 9.2.3
  • PCI DSS: 9.5.1.2
  • SCF: PES-01
  • SCF: PES-02
  • SCF: PES-02.1
  • SCF: PES-03
  • SP 800-171 Rev 3: 03.10.01
  • SP 800-171 Rev 3: 03.10.02
  • SP 800-171 Rev 3: 03.10.07
  • SP 800-171 Rev 3: 03.10.08
  • SP 800-53 Rev 5.1.1: PE-02
  • SP 800-53 Rev 5.1.1: PE-03
  • SP 800-53 Rev 5.1.1: PE-04
  • SP 800-53 Rev 5.1.1: PE-05
  • SP 800-53 Rev 5.1.1: PE-06
  • SP 800-53 Rev 5.1.1: PE-08
  • SP 800-53 Rev 5.1.1: PE-18
  • SP 800-53 Rev 5.1.1: PE-19
  • SP 800-53 Rev 5.1.1: PE-20
  • SP 800-53 Rev 5.2.0: PE-02
  • SP 800-53 Rev 5.2.0: PE-03
  • SP 800-53 Rev 5.2.0: PE-04
  • SP 800-53 Rev 5.2.0: PE-05
  • SP 800-53 Rev 5.2.0: PE-06
  • SP 800-53 Rev 5.2.0: PE-08
  • SP 800-53 Rev 5.2.0: PE-18
  • SP 800-53 Rev 5.2.0: PE-19
  • SP 800-53 Rev 5.2.0: PE-20
  • SSDF: PO.5.2

Awareness and Training (PR.AT)

The organization's personnel are provided with cybersecurity awareness and training so that they can perform their cybersecurity-related tasks

Informative References

  • CRI Profile v2.0: PR.AT
  • CSF v1.1: PR.AT
  • ISO/IEC 27001:2022: Mandatory Clause: 7.3
  • ISO/IEC 27001:2022: Annex A Controls: 6.3
  • NICE Framework: IO-WRL-007
  • NICE Framework: OG-WRL-002
  • NICE Framework: OG-WRL-003
  • NICE Framework: OG-WRL-004
  • NICE Framework: OG-WRL-005
  • SCF: SAT-01
  • SCF: SAT-02
  • SCF: SAT-03
  • SP-800-37 Rev 2: RMF Prepare Step (Organization & Mission/Business Levels): TASK P-1 Risk Management Roles
  • SP-800-37 Rev 2: RMF Prepare Step (Organization & Mission/Business Levels): TASK P-2 Risk Management Strategy
  • SP-800-37 Rev 2: RMF Select Step
  • SP-800-37 Rev 2: RMF Implement Step
  • SSDF: PO.2.2

PR.AT-01

Personnel are provided with awareness and training so that they possess the knowledge and skills to perform general tasks with cybersecurity risks in mind

Implementation Examples

  • Ex1: Provide basic cybersecurity awareness and training to employees, contractors, partners, suppliers, and all other users of the organization's non-public resources
  • Ex2: Train personnel to recognize social engineering attempts and other common attacks, report attacks and suspicious activity, comply with acceptable use policies, and perform basic cyber hygiene tasks (e.g., patching software, choosing passwords, protecting credentials)
  • Ex3: Explain the consequences of cybersecurity policy violations, both to individual users and the organization as a whole
  • Ex4: Periodically assess or test users on their understanding of basic cybersecurity practices
  • Ex5: Require annual refreshers to reinforce existing practices and introduce new practices

Informative References

  • AI-SOC: AI-SOC-29
  • CCMv4.0: DCS-11
  • CCMv4.0: HRS-09
  • CCMv4.0: HRS-11
  • CCMv4.0: HRS-12
  • CCMv4.0: HRS-13
  • CCMv4.0: SEF-02
  • CCMv4.0: SEF-03
  • CCMv4.0: UEM-14
  • CIS Controls v8.0: 14.1
  • CIS Controls v8.1: 14.1
  • CRI Profile v2.0: PR.AT-01
  • CRI Profile v2.0: PR.AT-01.01
  • CRI Profile v2.0: PR.AT-01.02
  • CRI Profile v2.0: PR.AT-01.03
  • CRI Profile v2.0: PR.AT-01.04
  • CSF v1.1: PR.AT-1
  • CSF v1.1: PR.AT-3
  • CSF v1.1: RS.CO-1
  • CoP: C3
  • CoP: C4
  • ISO/IEC 27001:2022: Mandatory Clause: 7.3
  • ISO/IEC 27001:2022: Annex A Controls: 6.3
  • ISO/IEC 27001:2022: Control 6.3
  • NICE Framework: IO-WRL-007
  • NICE Framework: OG-WRL-002
  • NICE Framework: OG-WRL-003
  • NICE Framework: OG-WRL-004
  • NICE Framework: OG-WRL-005
  • OWASP Top 10 LLM Applications: LLM01-2025
  • OWASP Top 10 LLM Applications: LLM02-2025
  • OWASP Top 10 LLM Applications: LLM09-2025
  • PCI DSS: 12.6.1
  • PCI DSS: 12.6.3
  • SCF: SAT-02
  • SCF: SAT-03
  • SCF: SAT-03.6
  • SP 800-171 Rev 3: 03.02.02
  • SP 800-221A: GV.CT-3
  • SP 800-221A: GV.RR-2
  • SP 800-53 Rev 5.1.1: AT-02
  • SP 800-53 Rev 5.1.1: AT-03
  • SP 800-53 Rev 5.2.0: AT-02
  • SP 800-53 Rev 5.2.0: AT-03
  • SP 800-81r3: 4.2.1.2
  • SSDF: PO.2.2

PR.AT-02

Individuals in specialized roles are provided with awareness and training so that they possess the knowledge and skills to perform relevant tasks with cybersecurity risks in mind

Implementation Examples

  • Ex1: Identify the specialized roles within the organization that require additional cybersecurity training, such as physical and cybersecurity personnel, finance personnel, senior leadership, and anyone with access to business-critical data
  • Ex2: Provide role-based cybersecurity awareness and training to all those in specialized roles, including contractors, partners, suppliers, and other third parties
  • Ex3: Periodically assess or test users on their understanding of cybersecurity practices for their specialized roles
  • Ex4: Require annual refreshers to reinforce existing practices and introduce new practices

Informative References

  • AI-SOC: AI-SOC-29
  • CCMv4.0: DCS-11
  • CCMv4.0: HRS-09
  • CCMv4.0: HRS-12
  • CCMv4.0: HRS-13
  • CCMv4.0: SEF-03
  • CCMv4.0: UEM-14
  • CIS Controls v8.0: 14.9
  • CIS Controls v8.1: 14.9
  • CRI Profile v2.0: PR.AT-02
  • CRI Profile v2.0: PR.AT-02.01
  • CRI Profile v2.0: PR.AT-02.02
  • CRI Profile v2.0: PR.AT-02.03
  • CRI Profile v2.0: PR.AT-02.04
  • CRI Profile v2.0: PR.AT-02.05
  • CRI Profile v2.0: PR.AT-02.06
  • CRI Profile v2.0: PR.AT-02.07
  • CRI Profile v2.0: PR.AT-02.08
  • CSF v1.1: PR.AT-2
  • CSF v1.1: PR.AT-3
  • CSF v1.1: PR.AT-4
  • CSF v1.1: PR.AT-5
  • CoP: C3
  • CoP: C4
  • ISO/IEC 27001:2022: Mandatory Clause: 7.3
  • ISO/IEC 27001:2022: Annex A Controls: 5.2
  • ISO/IEC 27001:2022: Annex A Controls: 6.3
  • NICE Framework: IO-WRL-007
  • NICE Framework: OG-WRL-002
  • NICE Framework: OG-WRL-003
  • NICE Framework: OG-WRL-004
  • NICE Framework: OG-WRL-005
  • OWASP Top 10 LLM Applications: LLM01-2025
  • OWASP Top 10 LLM Applications: LLM04-2025
  • OWASP Top 10 LLM Applications: LLM05-2025
  • PCI DSS: 6.2.2
  • PCI DSS: 12.10.4
  • PCI DSS: 12.10.4.1
  • SCF: SAT-03
  • SCF: SAT-03.6
  • SP 800-171 Rev 3: 03.02.02
  • SP 800-221A: GV.CT-3
  • SP 800-221A: GV.CT-4
  • SP 800-221A: GV.RR-2
  • SP 800-53 Rev 5.1.1: AT-03
  • SP 800-53 Rev 5.2.0: AT-03
  • SP 800-81r3: 4.2.1.2
  • SP 800-81r3: 5.2
  • SSDF: PO.2.2

PR.AT-03

[Withdrawn: Incorporated into PR.AT-01, PR.AT-02]

PR.AT-04

[Withdrawn: Incorporated into PR.AT-02]

PR.AT-05

[Withdrawn: Incorporated into PR.AT-02]

Data Security (PR.DS)

Data are managed consistent with the organization's risk strategy to protect the confidentiality, integrity, and availability of information

Informative References

  • CRI Profile v2.0: PR.DS
  • CSF v1.1: PR.DS
  • ISO/IEC 27001:2022: Mandatory Clause: 6.1.1
  • ISO/IEC 27001:2022: Annex A Controls: 5.1
  • ISO/IEC 27001:2022: Annex A Controls: 5.33
  • NICE Framework: DD-WRL-003
  • NICE Framework: DD-WRL-004
  • NICE Framework: DD-WRL-007
  • NICE Framework: IO-WRL-002
  • NICE Framework: IO-WRL-004
  • NICE Framework: IO-WRL-005
  • NICE Framework: IO-WRL-006
  • NICE Framework: PD-WRL-001
  • SCF: DCH-01
  • SCF: DCH-01.1
  • SCF: DCH-03
  • SP-800-37 Rev 2: RMF Prepare Step (Organization & Mission/Business Levels): TASK P-2 Risk Management Strategy
  • SP-800-37 Rev 2: RMF Select Step
  • SP-800-37 Rev 2: RMF Implement Step
  • SP-800-37 Rev 2: RMF Monitor Step

PR.DS-01

The confidentiality, integrity, and availability of data-at-rest are protected

Implementation Examples

  • Ex1: Use encryption, digital signatures, and cryptographic hashes to protect the confidentiality and integrity of stored data in files, databases, virtual machine disk images, container images, and other resources
  • Ex2: Use full disk encryption to protect data stored on user endpoints
  • Ex3: Confirm the integrity of software by validating signatures
  • Ex4: Restrict the use of removable media to prevent data exfiltration
  • Ex5: Physically secure removable media containing unencrypted sensitive information, such as within locked offices or file cabinets

Informative References

  • BXAIOS: Chapter 4 - The Receipts (Evidence Packets)
  • CCMv4.0: BCR-08
  • CCMv4.0: CEK-03
  • CCMv4.0: CEK-04
  • CCMv4.0: CEK-18
  • CCMv4.0: CEK-19
  • CCMv4.0: DCS-04
  • CCMv4.0: DSP-17
  • CCMv4.0: HRS-04
  • CCMv4.0: LOG-02
  • CCMv4.0: LOG-09
  • CCMv4.0: UEM-05
  • CCMv4.0: UEM-08
  • CIS Controls v8.0: 3.11
  • CIS Controls v8.1: 3.11
  • CRI Profile v2.0: PR.DS-01
  • CRI Profile v2.0: PR.DS-01.01
  • CRI Profile v2.0: PR.DS-01.02
  • CRI Profile v2.0: PR.DS-01.03
  • CSF v1.1: PR.DS-1
  • CSF v1.1: PR.DS-5
  • CSF v1.1: PR.DS-6
  • CSF v1.1: PR.PT-2
  • Guardian-SDK: GS-TT-05
  • ISO/IEC 27001:2022: Mandatory Clause: 4.2(b)
  • ISO/IEC 27001:2022: Mandatory Clause: 5.2
  • ISO/IEC 27001:2022: Annex A Controls: 5.1
  • ISO/IEC 27001:2022: Annex A Controls: 5.3
  • ISO/IEC 27001:2022: Annex A Controls: 5.10
  • ISO/IEC 27001:2022: Annex A Controls: 5.13
  • ISO/IEC 27001:2022: Annex A Controls: 5.14
  • ISO/IEC 27001:2022: Annex A Controls: 5.15
  • ISO/IEC 27001:2022: Annex A Controls: 6.1
  • ISO/IEC 27001:2022: Annex A Controls: 6.2
  • ISO/IEC 27001:2022: Annex A Controls: 6.5
  • ISO/IEC 27001:2022: Annex A Controls: 7.7
  • ISO/IEC 27001:2022: Annex A Controls: 7.10
  • ISO/IEC 27001:2022: Annex A Controls: 8.2
  • ISO/IEC 27001:2022: Annex A Controls: 8.3
  • ISO/IEC 27001:2022: Annex A Controls: 8.4
  • ISO/IEC 27001:2022: Annex A Controls: 8.7
  • ISO/IEC 27001:2022: Annex A Controls: 8.8
  • ISO/IEC 27001:2022: Annex A Controls: 8.17
  • ISO/IEC 27001:2022: Annex A Controls: 8.19
  • ISO/IEC 27001:2022: Annex A Controls: 8.22
  • ISO/IEC 27001:2022: Annex A Controls: 8.26
  • ISO/IEC 27001:2022: Control 5.10
  • ISO/IEC 27001:2022: Control 5.12
  • ISO/IEC 27001:2022: Control 5.13
  • ISO/IEC 27001:2022: Control 5.33
  • ISO/IEC 27001:2022: Control 7.9
  • ISO/IEC 27001:2022: Control 7.10
  • ISO/IEC 27001:2022: Control 8.10
  • ISO/IEC 27001:2022: Control 8.11
  • ISO/IEC 27001:2022: Control 8.12
  • ISO/IEC 27001:2022: Control 8.13
  • ISO/IEC 27001:2022: Control 8.33
  • NICE Framework: DD-WRL-003
  • NICE Framework: DD-WRL-004
  • NICE Framework: DD-WRL-007
  • NICE Framework: IO-WRL-002
  • NICE Framework: IO-WRL-005
  • NICE Framework: IO-WRL-006
  • NICE Framework: PD-WRL-001
  • OWASP Top 10 LLM Applications: LLM02-2025
  • OWASP Top 10 LLM Applications: LLM04-2025
  • OWASP Top 10 LLM Applications: LLM07-2025
  • OWASP Top 10 LLM Applications: LLM08-2025
  • PCI DSS: 3.5.1
  • PCI DSS: 3.6.1
  • PCI DSS: 3.6.1.1
  • PCI DSS: 3.6.1.2
  • PCI DSS: 3.6.1.3
  • PCI DSS: 3.6.1.4
  • PCI DSS: 3.5.1.3
  • PCI DSS: 3.3.1
  • PCI DSS: 9.4.7
  • PCI DSS: 9.4.6
  • SCF: DCH-01
  • SCF: CRY-01
  • SCF: CRY-01.1
  • SCF: CRY-05
  • SDOS: SDOS-IN-01
  • SDOS: SDOS-IN-02
  • SP 800-171 Rev 3: 03.08.09
  • SP 800-171 Rev 3: 03.12.05
  • SP 800-171 Rev 3: 03.13.01
  • SP 800-171 Rev 3: 03.13.04
  • SP 800-171 Rev 3: 03.13.06
  • SP 800-171 Rev 3: 03.13.08
  • SP 800-171 Rev 3: 03.13.10
  • SP 800-171 Rev 3: 03.13.11
  • SP 800-171 Rev 3: 03.14.02
  • SP 800-171 Rev 3: 03.14.06
  • SP 800-53 Rev 5.1.1: CA-03
  • SP 800-53 Rev 5.1.1: CP-09
  • SP 800-53 Rev 5.1.1: MP-08
  • SP 800-53 Rev 5.1.1: SC-04
  • SP 800-53 Rev 5.1.1: SC-07
  • SP 800-53 Rev 5.1.1: SC-12
  • SP 800-53 Rev 5.1.1: SC-13
  • SP 800-53 Rev 5.1.1: SC-28
  • SP 800-53 Rev 5.1.1: SC-32
  • SP 800-53 Rev 5.1.1: SC-39
  • SP 800-53 Rev 5.1.1: SC-43
  • SP 800-53 Rev 5.1.1: SI-03
  • SP 800-53 Rev 5.1.1: SI-04
  • SP 800-53 Rev 5.1.1: SI-07
  • SP 800-53 Rev 5.2.0: CA-03
  • SP 800-53 Rev 5.2.0: CP-09
  • SP 800-53 Rev 5.2.0: MP-08
  • SP 800-53 Rev 5.2.0: SC-04
  • SP 800-53 Rev 5.2.0: SC-07
  • SP 800-53 Rev 5.2.0: SC-12
  • SP 800-53 Rev 5.2.0: SC-13
  • SP 800-53 Rev 5.2.0: SC-28
  • SP 800-53 Rev 5.2.0: SC-32
  • SP 800-53 Rev 5.2.0: SC-39
  • SP 800-53 Rev 5.2.0: SC-43
  • SP 800-53 Rev 5.2.0: SI-03
  • SP 800-53 Rev 5.2.0: SI-04
  • SP 800-53 Rev 5.2.0: SI-07
  • SP 800-81r3: 3.8.2
  • SP 800-81r3: 3.8.6
  • SSDF: PS.1.1
  • SSDF: PS.2.1
  • SSDF: PS.3.1

PR.DS-02

The confidentiality, integrity, and availability of data-in-transit are protected

Implementation Examples

  • Ex1: Use encryption, digital signatures, and cryptographic hashes to protect the confidentiality and integrity of network communications
  • Ex2: Automatically encrypt or block outbound emails and other communications that contain sensitive data, depending on the data classification
  • Ex3: Block access to personal email, file sharing, file storage services, and other personal communications applications and services from organizational systems and networks
  • Ex4: Prevent reuse of sensitive data from production environments (e.g., customer records) in development, testing, and other non-production environments

Informative References

  • CCMv4.0: CEK-03
  • CCMv4.0: CEK-04
  • CCMv4.0: CEK-19
  • CCMv4.0: DCS-02
  • CCMv4.0: DSP-10
  • CCMv4.0: DSP-17
  • CCMv4.0: HRS-04
  • CCMv4.0: IPY-03
  • CCMv4.0: IVS-03
  • CCMv4.0: IVS-07
  • CCMv4.0: LOG-02
  • CCMv4.0: LOG-09
  • CCMv4.0: UEM-05
  • CCMv4.0: UEM-11
  • CIS Controls v8.0: 3.10
  • CIS Controls v8.1: 3.10
  • CRI Profile v2.0: PR.DS-02
  • CRI Profile v2.0: PR.DS-02.01
  • CSF v1.1: PR.DS-2
  • CSF v1.1: PR.DS-5
  • Guardian-SDK: GS-CF-03
  • IRP: IRP-Sec-3
  • ISO/IEC 27001:2022: Mandatory Clause: 4.2(b)
  • ISO/IEC 27001:2022: Mandatory Clause: 5.2
  • ISO/IEC 27001:2022: Annex A Controls: 5.3
  • ISO/IEC 27001:2022: Annex A Controls: 5.10
  • ISO/IEC 27001:2022: Annex A Controls: 5.13
  • ISO/IEC 27001:2022: Annex A Controls: 5.14
  • ISO/IEC 27001:2022: Annex A Controls: 5.15
  • ISO/IEC 27001:2022: Annex A Controls: 6.1
  • ISO/IEC 27001:2022: Annex A Controls: 6.2
  • ISO/IEC 27001:2022: Annex A Controls: 6.5
  • ISO/IEC 27001:2022: Annex A Controls: 8.2
  • ISO/IEC 27001:2022: Annex A Controls: 8.3
  • ISO/IEC 27001:2022: Annex A Controls: 8.4
  • ISO/IEC 27001:2022: Annex A Controls: 8.17
  • ISO/IEC 27001:2022: Annex A Controls: 8.20
  • ISO/IEC 27001:2022: Annex A Controls: 8.22
  • ISO/IEC 27001:2022: Annex A Controls: 8.26
  • ISO/IEC 27001:2022: Control 5.14
  • ISO/IEC 27001:2022: Control 8.24
  • NICE Framework: DD-WRL-003
  • NICE Framework: DD-WRL-004
  • NICE Framework: DD-WRL-007
  • NICE Framework: IO-WRL-002
  • NICE Framework: IO-WRL-004
  • NICE Framework: IO-WRL-005
  • NICE Framework: IO-WRL-006
  • NICE Framework: PD-WRL-001
  • OWASP Top 10 LLM Applications: LLM01-2025
  • OWASP Top 10 LLM Applications: LLM02-2025
  • OWASP Top 10 LLM Applications: LLM04-2025
  • PCI DSS: 4.2.1
  • PCI DSS: 12.3.3
  • PCI DSS: 2.3.1
  • SCF: DCH-01
  • SCF: CRY-01
  • SCF: CRY-03
  • SCF: CRY-04
  • SDOS: SDOS-EN-01
  • SDOS: SDOS-EN-04
  • SP 800-171 Rev 3: 03.12.05
  • SP 800-171 Rev 3: 03.13.01
  • SP 800-171 Rev 3: 03.13.04
  • SP 800-171 Rev 3: 03.13.06
  • SP 800-171 Rev 3: 03.13.08
  • SP 800-171 Rev 3: 03.13.10
  • SP 800-171 Rev 3: 03.13.11
  • SP 800-171 Rev 3: 03.14.02
  • SP 800-171 Rev 3: 03.14.06
  • SP 800-53 Rev 5.1.1: AU-16
  • SP 800-53 Rev 5.1.1: CA-03
  • SP 800-53 Rev 5.1.1: SC-04
  • SP 800-53 Rev 5.1.1: SC-07
  • SP 800-53 Rev 5.1.1: SC-08
  • SP 800-53 Rev 5.1.1: SC-11
  • SP 800-53 Rev 5.1.1: SC-12
  • SP 800-53 Rev 5.1.1: SC-13
  • SP 800-53 Rev 5.1.1: SC-16
  • SP 800-53 Rev 5.1.1: SC-40
  • SP 800-53 Rev 5.1.1: SC-43
  • SP 800-53 Rev 5.1.1: SI-03
  • SP 800-53 Rev 5.1.1: SI-04
  • SP 800-53 Rev 5.1.1: SI-07
  • SP 800-53 Rev 5.2.0: AU-16
  • SP 800-53 Rev 5.2.0: CA-03
  • SP 800-53 Rev 5.2.0: SC-04
  • SP 800-53 Rev 5.2.0: SC-07
  • SP 800-53 Rev 5.2.0: SC-08
  • SP 800-53 Rev 5.2.0: SC-11
  • SP 800-53 Rev 5.2.0: SC-12
  • SP 800-53 Rev 5.2.0: SC-13
  • SP 800-53 Rev 5.2.0: SC-16
  • SP 800-53 Rev 5.2.0: SC-40
  • SP 800-53 Rev 5.2.0: SC-43
  • SP 800-53 Rev 5.2.0: SI-03
  • SP 800-53 Rev 5.2.0: SI-04
  • SP 800-53 Rev 5.2.0: SI-07
  • SP 800-81r3: 2.2.2
  • SP 800-81r3: 3.5
  • SP 800-81r3: 3.8.1
  • SP 800-81r3: 4.2.1.3
  • SP 800-81r3: 4.2.5

PR.DS-03

[Withdrawn: Incorporated into ID.AM-08, PR.PS-03]

PR.DS-04

[Withdrawn: Moved to PR.IR-04]

PR.DS-05

[Withdrawn: Incorporated into PR.DS-01, PR.DS-02, PR.DS-10]

PR.DS-06

[Withdrawn: Incorporated into PR.DS-01, DE.CM-09]

PR.DS-07

[Withdrawn: Incorporated into PR.IR-01]

PR.DS-08

[Withdrawn: Incorporated into ID.RA-09, DE.CM-09]

PR.DS-10

The confidentiality, integrity, and availability of data-in-use are protected

Implementation Examples

  • Ex1: Remove data that must remain confidential (e.g., from processors and memory) as soon as it is no longer needed
  • Ex2: Protect data in use from access by other users and processes of the same platform

Informative References

  • CCMv4.0: DSP-17
  • CCMv4.0: HRS-04
  • CCMv4.0: UEM-11
  • CRI Profile v2.0: PR.DS-10
  • CRI Profile v2.0: PR.DS-10.01
  • CSF v1.1: PR.DS-5
  • ISO/IEC 27001:2022: Mandatory Clause: 4.2(b)
  • ISO/IEC 27001:2022: Mandatory Clause: 5.2
  • ISO/IEC 27001:2022: Annex A Controls: 5.3
  • ISO/IEC 27001:2022: Annex A Controls: 5.10
  • ISO/IEC 27001:2022: Annex A Controls: 5.13
  • ISO/IEC 27001:2022: Annex A Controls: 5.14
  • ISO/IEC 27001:2022: Annex A Controls: 5.15
  • ISO/IEC 27001:2022: Annex A Controls: 6.1
  • ISO/IEC 27001:2022: Annex A Controls: 6.2
  • ISO/IEC 27001:2022: Annex A Controls: 6.5
  • ISO/IEC 27001:2022: Annex A Controls: 8.2
  • ISO/IEC 27001:2022: Annex A Controls: 8.3
  • ISO/IEC 27001:2022: Annex A Controls: 8.4
  • ISO/IEC 27001:2022: Annex A Controls: 8.17
  • ISO/IEC 27001:2022: Annex A Controls: 8.22
  • ISO/IEC 27001:2022: Annex A Controls: 8.26
  • ISO/IEC 27001:2022: Control 5.23
  • NICE Framework: DD-WRL-003
  • NICE Framework: DD-WRL-004
  • NICE Framework: DD-WRL-007
  • NICE Framework: IO-WRL-002
  • NICE Framework: IO-WRL-005
  • NICE Framework: IO-WRL-006
  • NICE Framework: PD-WRL-001
  • OWASP Top 10 LLM Applications: LLM01-2025
  • OWASP Top 10 LLM Applications: LLM02-2025
  • OWASP Top 10 LLM Applications: LLM07-2025
  • OWASP Top 10 LLM Applications: LLM08-2025
  • PCI DSS: 3.2.1
  • PCI DSS: 7.2.2
  • PCI DSS: 8.2.8
  • PCI DSS: 3.4.1
  • SCF: DCH-01
  • SCF: CRY-01
  • SCF: CFG-02
  • SCF: IAC-21
  • SDOS: SDOS-EN-01
  • SDOS: SDOS-EN-04
  • SDOS: SDOS-GV-05
  • SP 800-171 Rev 3: 03.01.01
  • SP 800-171 Rev 3: 03.01.02
  • SP 800-171 Rev 3: 03.01.03
  • SP 800-171 Rev 3: 03.03.08
  • SP 800-171 Rev 3: 03.08.09
  • SP 800-171 Rev 3: 03.12.05
  • SP 800-171 Rev 3: 03.13.01
  • SP 800-171 Rev 3: 03.13.04
  • SP 800-171 Rev 3: 03.13.06
  • SP 800-171 Rev 3: 03.13.11
  • SP 800-171 Rev 3: 03.14.02
  • SP 800-171 Rev 3: 03.14.06
  • SP 800-171 Rev 3: 03.16.01
  • SP 800-53 Rev 5.1.1: AC-02
  • SP 800-53 Rev 5.1.1: AC-03
  • SP 800-53 Rev 5.1.1: AC-04
  • SP 800-53 Rev 5.1.1: AU-09
  • SP 800-53 Rev 5.1.1: AU-13
  • SP 800-53 Rev 5.1.1: CA-03
  • SP 800-53 Rev 5.1.1: CP-09
  • SP 800-53 Rev 5.1.1: SA-08
  • SP 800-53 Rev 5.1.1: SC-04
  • SP 800-53 Rev 5.1.1: SC-07
  • SP 800-53 Rev 5.1.1: SC-11
  • SP 800-53 Rev 5.1.1: SC-13
  • SP 800-53 Rev 5.1.1: SC-24
  • SP 800-53 Rev 5.1.1: SC-32
  • SP 800-53 Rev 5.1.1: SC-39
  • SP 800-53 Rev 5.1.1: SC-40
  • SP 800-53 Rev 5.1.1: SC-43
  • SP 800-53 Rev 5.1.1: SI-03
  • SP 800-53 Rev 5.1.1: SI-04
  • SP 800-53 Rev 5.1.1: SI-07
  • SP 800-53 Rev 5.1.1: SI-10
  • SP 800-53 Rev 5.1.1: SI-16
  • SP 800-53 Rev 5.2.0: AC-02
  • SP 800-53 Rev 5.2.0: AC-03
  • SP 800-53 Rev 5.2.0: AC-04
  • SP 800-53 Rev 5.2.0: AU-09
  • SP 800-53 Rev 5.2.0: AU-13
  • SP 800-53 Rev 5.2.0: CA-03
  • SP 800-53 Rev 5.2.0: CP-09
  • SP 800-53 Rev 5.2.0: SA-08
  • SP 800-53 Rev 5.2.0: SC-04
  • SP 800-53 Rev 5.2.0: SC-07
  • SP 800-53 Rev 5.2.0: SC-11
  • SP 800-53 Rev 5.2.0: SC-13
  • SP 800-53 Rev 5.2.0: SC-24
  • SP 800-53 Rev 5.2.0: SC-32
  • SP 800-53 Rev 5.2.0: SC-39
  • SP 800-53 Rev 5.2.0: SC-40
  • SP 800-53 Rev 5.2.0: SC-43
  • SP 800-53 Rev 5.2.0: SI-03
  • SP 800-53 Rev 5.2.0: SI-04
  • SP 800-53 Rev 5.2.0: SI-07
  • SP 800-53 Rev 5.2.0: SI-10
  • SP 800-53 Rev 5.2.0: SI-16
  • SP 800-81r3: 3.5

PR.DS-11

Backups of data are created, protected, maintained, and tested

Implementation Examples

  • Ex1: Continuously back up critical data in near-real-time, and back up other data frequently at agreed-upon schedules
  • Ex2: Test backups and restores for all types of data sources at least annually
  • Ex3: Securely store some backups offline and offsite so that an incident or disaster will not damage them
  • Ex4: Enforce geographic separation and geolocation restrictions for data backup storage

Informative References

  • CCMv4.0: BCR-08
  • CCMv4.0: CEK-18
  • CCMv4.0: DSP-16
  • CCMv4.0: DSP-19
  • CCMv4.0: LOG-02
  • CCMv4.0: LOG-09
  • CIS Controls v8.0: 11.2
  • CIS Controls v8.0: 11.3
  • CIS Controls v8.0: 11.5
  • CIS Controls v8.1: 11.2
  • CIS Controls v8.1: 11.3
  • CIS Controls v8.1: 11.5
  • CRI Profile v2.0: PR.DS-11
  • CRI Profile v2.0: PR.DS-11.01
  • CSF v1.1: PR.IP-4
  • IRP: IRP-Sec-6
  • ISO/IEC 27001:2022: Mandatory Clause: None
  • ISO/IEC 27001:2022: Annex A Controls: 8.13
  • NICE Framework: DD-WRL-007
  • NICE Framework: IO-WRL-002
  • NICE Framework: IO-WRL-005
  • NICE Framework: IO-WRL-006
  • NICE Framework: PD-WRL-001
  • OWASP Top 10 LLM Applications: LLM04-2025
  • PCI DSS: 12.10.1
  • PCI DSS: 9.4.7
  • PCI DSS: 9.3.1.1
  • PCI DSS: 9.4.1.1
  • PCI DSS: 9.4.1.2
  • SCF: BCD-11
  • SCF: BCD-11.1
  • SCF: BCD-11.5
  • SCF: BCD-11.6
  • SDOS: SDOS-IN-01
  • SDOS: SDOS-IN-02
  • SP 800-171 Rev 3: 03.08.09
  • SP 800-53 Rev 5.1.1: CP-06
  • SP 800-53 Rev 5.1.1: CP-09
  • SP 800-53 Rev 5.2.0: CP-06
  • SP 800-53 Rev 5.2.0: CP-09
  • SSDF: PS.3.1

Platform Security (PR.PS)

The hardware, software (e.g., firmware, operating systems, applications), and services of physical and virtual platforms are managed consistent with the organization's risk strategy to protect their confidentiality, integrity, and availability

Informative References

  • CRI Profile v2.0: PR.PS
  • ISO/IEC 27001:2022: Mandatory Clause: 8.1
  • ISO/IEC 27001:2022: Annex A Controls: 8.5
  • ISO/IEC 27001:2022: Annex A Controls: 8.8
  • ISO/IEC 27001:2022: Annex A Controls: 8.9
  • ISO/IEC 27001:2022: Annex A Controls: 8.14
  • NICE Framework: DD-WRL-001
  • NICE Framework: DD-WRL-002
  • NICE Framework: DD-WRL-003
  • NICE Framework: DD-WRL-005
  • NICE Framework: DD-WRL-006
  • NICE Framework: DD-WRL-008
  • NICE Framework: IO-WRL-003
  • NICE Framework: IO-WRL-005
  • NICE Framework: IO-WRL-007
  • NICE Framework: OG-WRL-001
  • NICE Framework: OG-WRL-013
  • NICE Framework: OG-WRL-016
  • NICE Framework: PD-WRL-004
  • NICE Framework: PD-WRL-007
  • SCF: CFG-01
  • SCF: CFG-02
  • SCF: CFG-02.1
  • SCF: CFG-02.5
  • SCF: MNT-01
  • SCF: MNT-02
  • SP-800-37 Rev 2: RMF Select Step
  • SP-800-37 Rev 2: RMF Implement Step
  • SP-800-37 Rev 2: RMF Monitor Step

PR.PS-01

Configuration management practices are established and applied

Implementation Examples

  • Ex1: Establish, test, deploy, and maintain hardened baselines that enforce the organization's cybersecurity policies and provide only essential capabilities (i.e., principle of least functionality)
  • Ex2: Review all default configuration settings that may potentially impact cybersecurity when installing or upgrading software
  • Ex3: Monitor implemented software for deviations from approved baselines

Informative References

  • AI-SOC: AI-SOC-08
  • AI-SOC: AI-SOC-22
  • CCMv4.0: AIS-02
  • CCMv4.0: AIS-04
  • CCMv4.0: AIS-05
  • CCMv4.0: AIS-06
  • CCMv4.0: CCC-01
  • CCMv4.0: CCC-02
  • CCMv4.0: CCC-06
  • CCMv4.0: CCC-07
  • CCMv4.0: IVS-04
  • CCMv4.0: IVS-06
  • CCMv4.0: UEM-05
  • CCMv4.0: UEM-06
  • CCMv4.0: UEM-07
  • CCMv4.0: UEM-09
  • CCMv4.0: UEM-10
  • CCMv4.0: UEM-11
  • CCMv4.0: UEM-12
  • CCMv4.0: UEM-13
  • CIS Controls v8.0: 4.1
  • CIS Controls v8.0: 4.2
  • CIS Controls v8.1: 4.1
  • CIS Controls v8.1: 4.2
  • CRI Profile v2.0: PR.PS-01
  • CRI Profile v2.0: PR.PS-01.01
  • CRI Profile v2.0: PR.PS-01.02
  • CRI Profile v2.0: PR.PS-01.03
  • CRI Profile v2.0: PR.PS-01.04
  • CRI Profile v2.0: PR.PS-01.05
  • CRI Profile v2.0: PR.PS-01.06
  • CRI Profile v2.0: PR.PS-01.07
  • CRI Profile v2.0: PR.PS-01.08
  • CRI Profile v2.0: PR.PS-01.09
  • CSF v1.1: PR.IP-1
  • CSF v1.1: PR.IP-3
  • CSF v1.1: PR.PT-2
  • CSF v1.1: PR.PT-3
  • Guardian-SDK: GS-CF-01
  • ISO/IEC 27001:2022: Mandatory Clause: 9.3
  • ISO/IEC 27001:2022: Annex A Controls: 8.9
  • ISO/IEC 27001:2022: Control 8.8
  • ISO/IEC 27001:2022: Control 8.9
  • NICE Framework: DD-WRL-001
  • NICE Framework: DD-WRL-002
  • NICE Framework: IO-WRL-005
  • NICE Framework: OG-WRL-013
  • NICE Framework: PD-WRL-004
  • OWASP Top 10 LLM Applications: LLM06-2025
  • OWASP Top 10 LLM Applications: LLM07-2025
  • OWASP Top 10 LLM Applications: LLM10-2025
  • PCI DSS: 2.2.1
  • PCI DSS: 2.2.2
  • SCF: CFG-01
  • SDOS: SDOS-GV-01
  • SDOS: SDOS-GV-04
  • SDOS: SDOS-IN-01
  • SP 800-171 Rev 3: 03.04.01
  • SP 800-171 Rev 3: 03.04.02
  • SP 800-171 Rev 3: 03.04.03
  • SP 800-171 Rev 3: 03.04.04
  • SP 800-171 Rev 3: 03.04.05
  • SP 800-171 Rev 3: 03.04.06
  • SP 800-171 Rev 3: 03.04.08
  • SP 800-171 Rev 3: 03.04.10
  • SP 800-171 Rev 3: 03.04.12
  • SP 800-171 Rev 3: 03.15.01
  • SP 800-53 Rev 5.1.1: CM-01
  • SP 800-53 Rev 5.1.1: CM-02
  • SP 800-53 Rev 5.1.1: CM-03
  • SP 800-53 Rev 5.1.1: CM-04
  • SP 800-53 Rev 5.1.1: CM-05
  • SP 800-53 Rev 5.1.1: CM-06
  • SP 800-53 Rev 5.1.1: CM-07
  • SP 800-53 Rev 5.1.1: CM-08
  • SP 800-53 Rev 5.1.1: CM-09
  • SP 800-53 Rev 5.1.1: CM-10
  • SP 800-53 Rev 5.1.1: CM-11
  • SP 800-53 Rev 5.2.0: CM-01
  • SP 800-53 Rev 5.2.0: CM-02
  • SP 800-53 Rev 5.2.0: CM-03
  • SP 800-53 Rev 5.2.0: CM-04
  • SP 800-53 Rev 5.2.0: CM-05
  • SP 800-53 Rev 5.2.0: CM-06
  • SP 800-53 Rev 5.2.0: CM-07
  • SP 800-53 Rev 5.2.0: CM-08
  • SP 800-53 Rev 5.2.0: CM-09
  • SP 800-53 Rev 5.2.0: CM-10
  • SP 800-53 Rev 5.2.0: CM-11
  • SP 800-81r3: 2.2.3
  • SP 800-81r3: 2.3.1
  • SP 800-81r3: 2.3.3
  • SP 800-81r3: 3.5.1
  • SP 800-81r3: 3.6.1
  • SP 800-81r3: 3.6.2
  • SP 800-81r3: 3.7.1
  • SP 800-81r3: 3.8.3
  • SP 800-81r3: 4.2.1.3
  • SP 800-81r3: 4.2.2
  • SSDF: PO.5.2
  • SSDF: PS.1.1

PR.PS-02

Software is maintained, replaced, and removed commensurate with risk

Implementation Examples

  • Ex1: Perform routine and emergency patching within the timeframes specified in the vulnerability management plan
  • Ex2: Update container images, and deploy new container instances to replace rather than update existing instances
  • Ex3: Replace end-of-life software and service versions with supported, maintained versions
  • Ex4: Uninstall and remove unauthorized software and services that pose undue risks
  • Ex5: Uninstall and remove any unnecessary software components (e.g., operating system utilities) that attackers might misuse
  • Ex6: Define and implement plans for software and service end-of-life maintenance support and obsolescence

Informative References

  • AI-SOC: AI-SOC-08
  • AI-SOC: AI-SOC-22
  • CCMv4.0: AIS-04
  • CCMv4.0: AIS-05
  • CCMv4.0: AIS-07
  • CCMv4.0: CCC-04
  • CCMv4.0: CCC-09
  • CCMv4.0: DSP-02
  • CCMv4.0: TVM-03
  • CCMv4.0: TVM-04
  • CCMv4.0: TVM-05
  • CCMv4.0: TVM-08
  • CCMv4.0: UEM-02
  • CCMv4.0: UEM-03
  • CCMv4.0: UEM-07
  • CIS Controls v8.0: 2.2
  • CIS Controls v8.0: 2.3
  • CIS Controls v8.1: 2.2
  • CIS Controls v8.1: 2.3
  • CRI Profile v2.0: PR.PS-02
  • CRI Profile v2.0: PR.PS-02.01
  • CRI Profile v2.0: PR.PS-02.02
  • CRI Profile v2.0: PR.PS-02.03
  • CSF v1.1: PR.IP-12
  • CSF v1.1: PR.MA-2
  • ISO/IEC 27001:2022: Mandatory Clause: None
  • ISO/IEC 27001:2022: Annex A Controls: 5.9
  • ISO/IEC 27001:2022: Control 8.7
  • NICE Framework: DD-WRL-001
  • NICE Framework: DD-WRL-002
  • NICE Framework: DD-WRL-005
  • NICE Framework: DD-WRL-006
  • NICE Framework: IO-WRL-005
  • NICE Framework: IO-WRL-007
  • NICE Framework: OG-WRL-013
  • NICE Framework: PD-WRL-004
  • OWASP Top 10 LLM Applications: LLM03-2025
  • PCI DSS: 6.3.3
  • PCI DSS: 6.3.1
  • PCI DSS: 6.3.2
  • PCI DSS: 12.3.4
  • SCF: MNT-01
  • SCF: MNT-02
  • SCF: MNT-03
  • SCF: MNT-03.1
  • SCF: PRM-07
  • SCF: SEA-07.1
  • SCF: TDA-17
  • SCF: VPM-01
  • SCF: VPM-01.1
  • SCF: VPM-02
  • SCF: VPM-05
  • SDOS: SDOS-IA-02
  • SDOS: SDOS-IN-03
  • SP 800-171 Rev 3: 03.14.01
  • SP 800-53 Rev 5.1.1: CM-11
  • SP 800-53 Rev 5.1.1: MA-03(06)
  • SP 800-53 Rev 5.1.1: SA-10(01)
  • SP 800-53 Rev 5.1.1: SI-02
  • SP 800-53 Rev 5.1.1: SI-07
  • SP 800-53 Rev 5.2.0: CM-11
  • SP 800-53 Rev 5.2.0: MA-03(06)
  • SP 800-53 Rev 5.2.0: SA-10(01)
  • SP 800-53 Rev 5.2.0: SI-02
  • SP 800-53 Rev 5.2.0: SI-07
  • SP 800-81r3: 2.2.3
  • SP 800-81r3: 3.8.2
  • SP 800-81r3: 4.2.6
  • SSDF: PO.5.2

PR.PS-03

Hardware is maintained, replaced, and removed commensurate with risk

Implementation Examples

  • Ex1: Replace hardware when it lacks needed security capabilities or when it cannot support software with needed security capabilities
  • Ex2: Define and implement plans for hardware end-of-life maintenance support and obsolescence
  • Ex3: Perform hardware disposal in a secure, responsible, and auditable manner

Informative References

  • CCMv4.0: CCC-04
  • CCMv4.0: DCS-01
  • CCMv4.0: DSP-02
  • CCMv4.0: TVM-03
  • CCMv4.0: TVM-08
  • CIS Controls v8.0: 1.2
  • CIS Controls v8.1: 1.2
  • CRI Profile v2.0: PR.PS-03
  • CRI Profile v2.0: PR.PS-03.01
  • CSF v1.1: PR.MA-1
  • CSF v1.1: PR.DS-3
  • ISO/IEC 27001:2022: Mandatory Clause: None
  • ISO/IEC 27001:2022: Annex A Controls: 5.9
  • ISO/IEC 27001:2022: Control 8.1
  • NICE Framework: DD-WRL-001
  • NICE Framework: DD-WRL-002
  • NICE Framework: IO-WRL-005
  • NICE Framework: IO-WRL-007
  • NICE Framework: OG-WRL-013
  • NICE Framework: PD-WRL-004
  • PCI DSS: 12.3.4
  • PCI DSS: 9.4.7
  • PCI DSS: 9.5.1.1
  • SCF: MNT-01
  • SCF: MNT-02
  • SCF: MNT-03
  • SCF: MNT-03.1
  • SCF: PRM-07
  • SCF: SEA-07.1
  • SCF: TDA-17
  • SP 800-53 Rev 5.1.1: CM-07(09)
  • SP 800-53 Rev 5.1.1: SA-10(03)
  • SP 800-53 Rev 5.1.1: SC-03(01)
  • SP 800-53 Rev 5.1.1: SC-39(01)
  • SP 800-53 Rev 5.1.1: SC-49
  • SP 800-53 Rev 5.1.1: SC-51
  • SP 800-53 Rev 5.2.0: CM-07(09)
  • SP 800-53 Rev 5.2.0: SA-10(03)
  • SP 800-53 Rev 5.2.0: SC-03(01)
  • SP 800-53 Rev 5.2.0: SC-39(01)
  • SP 800-53 Rev 5.2.0: SC-49
  • SP 800-53 Rev 5.2.0: SC-51
  • SSDF: PO.5.2

PR.PS-04

Log records are generated and made available for continuous monitoring

Implementation Examples

  • Ex1: Configure all operating systems, applications, and services (including cloud-based services) to generate log records
  • Ex2: Configure log generators to securely share their logs with the organization's logging infrastructure systems and services
  • Ex3: Configure log generators to record the data needed by zero-trust architectures

Informative References

  • AI-SOC: AI-SOC-02
  • AI-SOC: AI-SOC-22
  • CCMv4.0: IAM-16
  • CCMv4.0: LOG-01
  • CCMv4.0: LOG-02
  • CCMv4.0: LOG-03
  • CCMv4.0: LOG-04
  • CCMv4.0: LOG-05
  • CCMv4.0: LOG-07
  • CCMv4.0: LOG-08
  • CCMv4.0: LOG-10
  • CCMv4.0: LOG-11
  • CCMv4.0: LOG-12
  • CCMv4.0: LOG-13
  • CIS Controls v8.0: 8.2
  • CIS Controls v8.1: 8.2
  • CRI Profile v2.0: PR.PS-04
  • CRI Profile v2.0: PR.PS-04.01
  • CRI Profile v2.0: PR.PS-04.02
  • CRI Profile v2.0: PR.PS-04.03
  • CSF v1.1: PR.PT-1
  • Guardian-SDK: GS-CF-02
  • ISO/IEC 27001:2022: Mandatory Clause: None
  • ISO/IEC 27001:2022: Annex A Controls: 8.15
  • ISO/IEC 27001:2022: Annex A Controls: 8.17
  • NICE Framework: DD-WRL-001
  • NICE Framework: DD-WRL-002
  • NICE Framework: IO-WRL-003
  • NICE Framework: IO-WRL-005
  • NICE Framework: OG-WRL-013
  • NICE Framework: PD-WRL-004
  • OWASP Top 10 LLM Applications: LLM01-2025
  • OWASP Top 10 LLM Applications: LLM02-2025
  • OWASP Top 10 LLM Applications: LLM06-2025
  • OWASP Top 10 LLM Applications: LLM10-2025
  • PCI DSS: 10.2.1
  • PCI DSS: 10.3.1
  • PCI DSS: 10.3.2
  • PCI DSS: 10.3.3
  • PCI DSS: 10.3.4
  • PCI DSS: 10.4.2.1
  • PCI DSS: 10.6.1
  • PCI DSS: 10.6.3
  • SCF: MON-01
  • SCF: MON-01.4
  • SCF: MON-03
  • SDOS: SDOS-AU-01
  • SDOS: SDOS-AU-02
  • SDOS: SDOS-AU-03
  • SDOS: SDOS-EN-04
  • SP 800-171 Rev 3: 03.03.02
  • SP 800-171 Rev 3: 03.03.03
  • SP 800-171 Rev 3: 03.03.05
  • SP 800-171 Rev 3: 03.03.06
  • SP 800-53 Rev 5.1.1: AU-02
  • SP 800-53 Rev 5.1.1: AU-03
  • SP 800-53 Rev 5.1.1: AU-06
  • SP 800-53 Rev 5.1.1: AU-07
  • SP 800-53 Rev 5.1.1: AU-11
  • SP 800-53 Rev 5.1.1: AU-12
  • SP 800-53 Rev 5.2.0: AU-02
  • SP 800-53 Rev 5.2.0: AU-03
  • SP 800-53 Rev 5.2.0: AU-06
  • SP 800-53 Rev 5.2.0: AU-07
  • SP 800-53 Rev 5.2.0: AU-11
  • SP 800-53 Rev 5.2.0: AU-12
  • SP 800-53 Rev 5.2.0: SA-15(13)
  • SP 800-81r3: 2.1.2
  • SP 800-81r3: 2.1.3
  • SSDF: PO.3.3

PR.PS-05

Installation and execution of unauthorized software are prevented

Implementation Examples

  • Ex1: When risk warrants it, restrict software execution to permitted products only or deny the execution of prohibited and unauthorized software
  • Ex2: Verify the source of new software and the software's integrity before installing it
  • Ex3: Configure platforms to use only approved DNS services that block access to known malicious domains
  • Ex4: Configure platforms to allow the installation of organization-approved software only

Informative References

  • AI-SOC: AI-SOC-03
  • AI-SOC: AI-SOC-20
  • CCMv4.0: CCC-04
  • CCMv4.0: UEM-02
  • CCMv4.0: UEM-09
  • CIS Controls v8.0: 2.5
  • CIS Controls v8.1: 2.5
  • CRI Profile v2.0: PR.PS-05
  • CRI Profile v2.0: PR.PS-05.01
  • CRI Profile v2.0: PR.PS-05.02
  • CRI Profile v2.0: PR.PS-05.03
  • ISO/IEC 27001:2022: Mandatory Clause: None
  • ISO/IEC 27001:2022: Annex A Controls: 8.19
  • ISO/IEC 27001:2022: Control 8.19
  • NICE Framework: DD-WRL-001
  • NICE Framework: DD-WRL-002
  • NICE Framework: IO-WRL-005
  • NICE Framework: IO-WRL-007
  • NICE Framework: OG-WRL-001
  • NICE Framework: OG-WRL-013
  • NICE Framework: PD-WRL-004
  • NICE Framework: PD-WRL-007
  • OWASP Top 10 LLM Applications: LLM03-2025
  • PCI DSS: 2.2.1
  • PCI DSS: 5.3.2
  • PCI DSS: 6.4.3
  • SCF: CFG-01
  • SCF: CFG-02
  • SCF: CFG-03
  • SCF: CFG-03.2
  • SCF: CFG-05
  • SCF: END-03
  • SDOS: SDOS-AD-01
  • SDOS: SDOS-GV-01
  • SDOS: SDOS-GV-05
  • SDOS: SDOS-IN-03
  • SP 800-53 Rev 5.1.1: CM-07(02)
  • SP 800-53 Rev 5.1.1: CM-07(04)
  • SP 800-53 Rev 5.1.1: CM-07(05)
  • SP 800-53 Rev 5.1.1: SC-34
  • SP 800-53 Rev 5.2.0: CM-07(02)
  • SP 800-53 Rev 5.2.0: CM-07(04)
  • SP 800-53 Rev 5.2.0: CM-07(05)
  • SP 800-53 Rev 5.2.0: SC-34

PR.PS-06

Secure software development practices are integrated, and their performance is monitored throughout the software development life cycle

Implementation Examples

  • Ex1: Protect all components of organization-developed software from tampering and unauthorized access
  • Ex2: Secure all software produced by the organization, with minimal vulnerabilities in their releases
  • Ex3: Maintain the software used in production environments, and securely dispose of software once it is no longer needed

Informative References

  • AI-SOC: AI-SOC-08
  • AI-SOC: AI-SOC-22
  • CCMv4.0: AIS-04
  • CCMv4.0: AIS-06
  • CCMv4.0: AIS-07
  • CCMv4.0: DSP-07
  • CCMv4.0: IVS-06
  • CIS Controls v8.0: 16.1
  • CIS Controls v8.1: 16.1
  • CRI Profile v2.0: PR.PS-06
  • CRI Profile v2.0: PR.PS-06.01
  • CRI Profile v2.0: PR.PS-06.02
  • CRI Profile v2.0: PR.PS-06.03
  • CRI Profile v2.0: PR.PS-06.04
  • CRI Profile v2.0: PR.PS-06.05
  • CRI Profile v2.0: PR.PS-06.06
  • CRI Profile v2.0: PR.PS-06.07
  • CRI Profile v2.0: PR.PS-06.08
  • CRI Profile v2.0: PR.PS-06.09
  • CRI Profile v2.0: PR.PS-06.10
  • CSF v1.1: PR.IP-2
  • IRP: IRP-Sec-4
  • ISO/IEC 27001:2022: Mandatory Clause: None
  • ISO/IEC 27001:2022: Annex A Controls: 8.25
  • ISO/IEC 27001:2022: Annex A Controls: 8.28
  • ISO/IEC 27001:2022: Control 8.25
  • ISO/IEC 27001:2022: Control 8.26
  • ISO/IEC 27001:2022: Control 8.28
  • ISO/IEC 27001:2022: Control 8.29
  • ISO/IEC 27001:2022: Control 8.31
  • NICE Framework: DD-WRL-001
  • NICE Framework: DD-WRL-002
  • NICE Framework: DD-WRL-003
  • NICE Framework: DD-WRL-005
  • NICE Framework: DD-WRL-008
  • NICE Framework: IO-WRL-005
  • NICE Framework: OG-WRL-016
  • NICE Framework: PD-WRL-004
  • OWASP Top 10 LLM Applications: LLM01-2025
  • OWASP Top 10 LLM Applications: LLM05-2025
  • OWASP Top 10 LLM Applications: LLM06-2025
  • PCI DSS: 6.2.3
  • PCI DSS: 6.2.2
  • PCI DSS: 6.3.2
  • PCI DSS: 11.4.4
  • SCF: TDA-01
  • SCF: TDA-01.1
  • SCF: TDA-06
  • SCF: TDA-06.1
  • SCF: TDA-06.2
  • SCF: TDA-09
  • SP 800-171 Rev 3: 03.16.01
  • SP 800-53 Rev 5.1.1: SA-03
  • SP 800-53 Rev 5.1.1: SA-08
  • SP 800-53 Rev 5.1.1: SA-10
  • SP 800-53 Rev 5.1.1: SA-11
  • SP 800-53 Rev 5.1.1: SA-15
  • SP 800-53 Rev 5.1.1: SA-17
  • SP 800-53 Rev 5.2.0: SA-03
  • SP 800-53 Rev 5.2.0: SA-08
  • SP 800-53 Rev 5.2.0: SA-10
  • SP 800-53 Rev 5.2.0: SA-11
  • SP 800-53 Rev 5.2.0: SA-15
  • SP 800-53 Rev 5.2.0: SA-15(13)
  • SP 800-53 Rev 5.2.0: SA-17
  • SP 800-53 Rev 5.2.0: SA-24

Technology Infrastructure Resilience (PR.IR)

Security architectures are managed with the organization's risk strategy to protect asset confidentiality, integrity, and availability, and organizational resilience

Informative References

  • CRI Profile v2.0: PR.IR
  • ISO/IEC 27001:2022: Mandatory Clause: None
  • ISO/IEC 27001:2022: Annex A Controls: 6.6
  • ISO/IEC 27001:2022: Annex A Controls: 8.27
  • NICE Framework: DD-WRL-001
  • NICE Framework: DD-WRL-002
  • NICE Framework: DD-WRL-004
  • NICE Framework: DD-WRL-006
  • NICE Framework: DD-WRL-009
  • NICE Framework: IO-WRL-004
  • NICE Framework: OG-WRL-001
  • NICE Framework: OG-WRL-002
  • NICE Framework: OG-WRL-014
  • SCF: GOV-01
  • SCF: RSK-01
  • SCF: SEA-01
  • SCF: SEA-01.1
  • SCF: SEA-02
  • SP-800-37 Rev 2: RMF Prepare Step (Organization & Mission/Business Levels): TASK P-2 Risk Management Strategy
  • SP-800-37 Rev 2: RMF Prepare Step (System Level): TASK P-15 Requirements Definition
  • SP-800-37 Rev 2: RMF Prepare Step (System Level): TASK P-16 Enterprise Architecture
  • SP-800-37 Rev 2: RMF Prepare Step (System Level): TASK P-17 Requirements Allocation
  • SP-800-37 Rev 2: RMF Select Step
  • SP-800-37 Rev 2: RMF Implement Step

PR.IR-01

Networks and environments are protected from unauthorized logical access and usage

Implementation Examples

  • Ex1: Logically segment organization networks and cloud-based platforms according to trust boundaries and platform types (e.g., IT, IoT, OT, mobile, guests), and permit required communications only between segments
  • Ex2: Logically segment organization networks from external networks, and permit only necessary communications to enter the organization's networks from the external networks
  • Ex3: Implement zero trust architectures to restrict network access to each resource to the minimum necessary
  • Ex4: Check the cyber health of endpoints before allowing them to access and use production resources

Informative References

  • AI-SOC: AI-SOC-07
  • AI-SOC: AI-SOC-24
  • CCMv4.0: AIS-04
  • CCMv4.0: AIS-06
  • CCMv4.0: DCS-12
  • CCMv4.0: DSP-10
  • CCMv4.0: DSP-15
  • CCMv4.0: IVS-03
  • CCMv4.0: IVS-05
  • CCMv4.0: IVS-06
  • CCMv4.0: IVS-09
  • CCMv4.0: UEM-05
  • CCMv4.0: UEM-14
  • CIS Controls v8.0: 3.12
  • CIS Controls v8.0: 12.2
  • CIS Controls v8.1: 3.12
  • CIS Controls v8.1: 12.2
  • CRI Profile v2.0: PR.IR-01
  • CRI Profile v2.0: PR.IR-01.01
  • CRI Profile v2.0: PR.IR-01.02
  • CRI Profile v2.0: PR.IR-01.03
  • CRI Profile v2.0: PR.IR-01.04
  • CRI Profile v2.0: PR.IR-01.05
  • CRI Profile v2.0: PR.IR-01.06
  • CRI Profile v2.0: PR.IR-01.07
  • CRI Profile v2.0: PR.IR-01.08
  • CSF v1.1: PR.AC-3
  • CSF v1.1: PR.AC-5
  • CSF v1.1: PR.DS-7
  • CSF v1.1: PR.PT-4
  • Guardian-SDK: GS-PF-01
  • ISO/IEC 27001:2022: Mandatory Clause: None
  • ISO/IEC 27001:2022: Annex A Controls: 8.20
  • ISO/IEC 27001:2022: Annex A Controls: 8.21
  • ISO/IEC 27001:2022: Annex A Controls: 8.22
  • ISO/IEC 27001:2022: Control 8.20
  • ISO/IEC 27001:2022: Control 8.21
  • ISO/IEC 27001:2022: Control 8.22
  • ISO/IEC 27001:2022: Control 8.23
  • NICE Framework: DD-WRL-001
  • NICE Framework: DD-WRL-002
  • NICE Framework: DD-WRL-004
  • NICE Framework: DD-WRL-006
  • NICE Framework: DD-WRL-009
  • NICE Framework: IO-WRL-004
  • NICE Framework: OG-WRL-001
  • NICE Framework: OG-WRL-014
  • OWASP Top 10 LLM Applications: LLM01-2025
  • OWASP Top 10 LLM Applications: LLM06-2025
  • OWASP Top 10 LLM Applications: LLM10-2025
  • PCI DSS: 1.2.3
  • PCI DSS: 1.2.4
  • PCI DSS: 10.2.1
  • PCI DSS: 5.2.1
  • PCI DSS: 5.2.2
  • PCI DSS: 5.2.3
  • PCI DSS: 5.2.3.1
  • PCI DSS: 11.2.1
  • SCF: NET-01
  • SCF: SEA-01
  • SCF: SEA-02
  • SDOS: SDOS-AD-01
  • SDOS: SDOS-EN-02
  • SP 800-171 Rev 3: 03.01.02
  • SP 800-171 Rev 3: 03.01.03
  • SP 800-171 Rev 3: 03.13.01
  • SP 800-171 Rev 3: 03.13.04
  • SP 800-171 Rev 3: 03.13.06
  • SP 800-53 Rev 5.1.1: AC-03
  • SP 800-53 Rev 5.1.1: AC-04
  • SP 800-53 Rev 5.1.1: SC-04
  • SP 800-53 Rev 5.1.1: SC-05
  • SP 800-53 Rev 5.1.1: SC-07
  • SP 800-53 Rev 5.2.0: AC-03
  • SP 800-53 Rev 5.2.0: AC-04
  • SP 800-53 Rev 5.2.0: SC-04
  • SP 800-53 Rev 5.2.0: SC-05
  • SP 800-53 Rev 5.2.0: SC-07
  • SP 800-81r3: 4.2.2
  • SP 800-81r3: 4.3
  • SSDF: PO.5.1

PR.IR-02

The organization's technology assets are protected from environmental threats

Implementation Examples

  • Ex1: Protect organizational equipment from known environmental threats, such as flooding, fire, wind, and excessive heat and humidity
  • Ex2: Include protection from environmental threats and provisions for adequate operating infrastructure in requirements for service providers that operate systems on the organization's behalf

Informative References

  • CCMv4.0: DCS-03
  • CCMv4.0: DCS-13
  • CCMv4.0: DCS-14
  • CCMv4.0: DCS-15
  • CRI Profile v2.0: PR.IR-02
  • CRI Profile v2.0: PR.IR-02.01
  • CSF v1.1: PR.IP-5
  • ISO/IEC 27001:2022: Mandatory Clause: None
  • ISO/IEC 27001:2022: Annex A Controls: 7.5
  • ISO/IEC 27001:2022: Control 7.5
  • ISO/IEC 27001:2022: Control 7.6
  • ISO/IEC 27001:2022: Control 7.7
  • ISO/IEC 27001:2022: Control 7.8
  • ISO/IEC 27001:2022: Control 7.11
  • ISO/IEC 27001:2022: Control 7.12
  • ISO/IEC 27001:2022: Control 7.13
  • ISO/IEC 27001:2022: Control 7.14
  • NICE Framework: DD-WRL-001
  • NICE Framework: DD-WRL-002
  • NICE Framework: DD-WRL-004
  • NICE Framework: DD-WRL-006
  • NICE Framework: DD-WRL-009
  • NICE Framework: IO-WRL-004
  • NICE Framework: OG-WRL-014
  • PCI DSS: 9.1.1
  • PCI DSS: 9.1.2
  • PCI DSS: 12.10.1
  • SCF: BCD-01
  • SCF: PES-01
  • SCF: PES-07
  • SCF: PES-07.5
  • SCF: PES-08
  • SCF: PES-09
  • SP 800-53 Rev 5.1.1: CP-02
  • SP 800-53 Rev 5.1.1: PE-09
  • SP 800-53 Rev 5.1.1: PE-10
  • SP 800-53 Rev 5.1.1: PE-11
  • SP 800-53 Rev 5.1.1: PE-12
  • SP 800-53 Rev 5.1.1: PE-13
  • SP 800-53 Rev 5.1.1: PE-14
  • SP 800-53 Rev 5.1.1: PE-15
  • SP 800-53 Rev 5.1.1: PE-18
  • SP 800-53 Rev 5.1.1: PE-23
  • SP 800-53 Rev 5.2.0: CP-02
  • SP 800-53 Rev 5.2.0: PE-09
  • SP 800-53 Rev 5.2.0: PE-10
  • SP 800-53 Rev 5.2.0: PE-11
  • SP 800-53 Rev 5.2.0: PE-12
  • SP 800-53 Rev 5.2.0: PE-13
  • SP 800-53 Rev 5.2.0: PE-14
  • SP 800-53 Rev 5.2.0: PE-15
  • SP 800-53 Rev 5.2.0: PE-18
  • SP 800-53 Rev 5.2.0: PE-23

PR.IR-03

Mechanisms are implemented to achieve resilience requirements in normal and adverse situations

Implementation Examples

  • Ex1: Avoid single points of failure in systems and infrastructure
  • Ex2: Use load balancing to increase capacity and improve reliability
  • Ex3: Use high-availability components like redundant storage and power supplies to improve system reliability

Informative References

  • AI-SOC: AI-SOC-07
  • AI-SOC: AI-SOC-24
  • CCMv4.0: BCR-11
  • CRI Profile v2.0: PR.IR-03
  • CRI Profile v2.0: PR.IR-03.01
  • CSF v1.1: PR.PT-5
  • ISO/IEC 27001:2022: Mandatory Clause: 4.2(b)
  • ISO/IEC 27001:2022: Mandatory Clause: 6.1.1
  • ISO/IEC 27001:2022: Annex A Controls: 5.29
  • ISO/IEC 27001:2022: Annex A Controls: 8.14
  • ISO/IEC 27001:2022: Control 8.14
  • ISO/IEC 27001:2022: Control 8.17
  • ISO/IEC 27001:2022: Control 8.27
  • NICE Framework: DD-WRL-001
  • NICE Framework: DD-WRL-002
  • NICE Framework: DD-WRL-004
  • NICE Framework: DD-WRL-006
  • NICE Framework: DD-WRL-009
  • NICE Framework: IO-WRL-004
  • NICE Framework: OG-WRL-002
  • NICE Framework: OG-WRL-014
  • OWASP Top 10 LLM Applications: LLM10-2025
  • PCI DSS: 12.10.1
  • PCI DSS: 12.10.2
  • PCI DSS: 12.10.6
  • SCF: BCD-01
  • SCF: SEA-01
  • SCF: SEA-02
  • SDOS: SDOS-EN-03
  • SDOS: SDOS-IN-01
  • SDOS: SDOS-IN-02
  • SP 800-171 Rev 3: 03.16.01
  • SP 800-53 Rev 5.1.1: CP
  • SP 800-53 Rev 5.1.1: IR
  • SP 800-53 Rev 5.1.1: SA-08
  • SP 800-53 Rev 5.1.1: SC-06
  • SP 800-53 Rev 5.1.1: SC-24
  • SP 800-53 Rev 5.1.1: SC-36
  • SP 800-53 Rev 5.1.1: SC-39
  • SP 800-53 Rev 5.1.1: SI-13
  • SP 800-53 Rev 5.2.0: CP
  • SP 800-53 Rev 5.2.0: IR
  • SP 800-53 Rev 5.2.0: SA-08
  • SP 800-53 Rev 5.2.0: SA-24
  • SP 800-53 Rev 5.2.0: SC-06
  • SP 800-53 Rev 5.2.0: SC-24
  • SP 800-53 Rev 5.2.0: SC-36
  • SP 800-53 Rev 5.2.0: SC-39
  • SP 800-53 Rev 5.2.0: SI-13
  • SP 800-81r3: 1.2
  • SP 800-81r3: 2.2.2
  • SP 800-81r3: 2.3.1
  • SP 800-81r3: 2.3.2
  • SP 800-81r3: 3.8.6
  • SP 800-81r3: 5.1
  • SP 800-81r3: 5.3

PR.IR-04

Adequate resource capacity to ensure availability is maintained

Implementation Examples

  • Ex1: Monitor usage of storage, power, compute, network bandwidth, and other resources
  • Ex2: Forecast future needs, and scale resources accordingly

Informative References

  • AI-SOC: AI-SOC-07
  • AI-SOC: AI-SOC-24
  • CCMv4.0: IVS-02
  • CRI Profile v2.0: PR.IR-04
  • CRI Profile v2.0: PR.IR-04.01
  • CRI Profile v2.0: PR.IR-04.02
  • CSF v1.1: PR.DS-4
  • ISO/IEC 27001:2022: Mandatory Clause: None
  • ISO/IEC 27001:2022: Annex A Controls: 8.6
  • NICE Framework: DD-WRL-001
  • NICE Framework: DD-WRL-002
  • NICE Framework: DD-WRL-004
  • NICE Framework: DD-WRL-006
  • NICE Framework: DD-WRL-009
  • NICE Framework: IO-WRL-004
  • NICE Framework: OG-WRL-014
  • OWASP Top 10 LLM Applications: LLM10-2025
  • SCF: CAP-01
  • SCF: CAP-02
  • SCF: CAP-03
  • SDOS: SDOS-EN-03
  • SDOS: SDOS-RM-02
  • SDOS: SDOS-RM-03
  • SP 800-53 Rev 5.1.1: CP-06
  • SP 800-53 Rev 5.1.1: CP-07
  • SP 800-53 Rev 5.1.1: CP-08
  • SP 800-53 Rev 5.1.1: PM-03
  • SP 800-53 Rev 5.1.1: PM-09
  • SP 800-53 Rev 5.2.0: CP-06
  • SP 800-53 Rev 5.2.0: CP-07
  • SP 800-53 Rev 5.2.0: CP-08
  • SP 800-53 Rev 5.2.0: PM-03
  • SP 800-53 Rev 5.2.0: PM-09
  • SP 800-81r3: 2.1.2
  • SP 800-81r3: 2.3.2

Identity Management, Authentication and Access Control (PR.AC)

[Withdrawn: Moved to PR.AA]

PR.AC-01

[Withdrawn: Incorporated into PR.AA-01, PR.AA-05]

PR.AC-02

[Withdrawn: Moved to PR.AA-06]

PR.AC-03

[Withdrawn: Incorporated into PR.AA-03, PR.AA-05, PR.IR-01]

PR.AC-04

[Withdrawn: Moved to PR.AA-05]

PR.AC-05

[Withdrawn: Incorporated into PR.IR-01]

PR.AC-06

[Withdrawn: Moved to PR.AA-02]

PR.AC-07

[Withdrawn: Moved to PR.AA-03]

Information Protection Processes and Procedures (PR.IP)

[Withdrawn: Incorporated into other Categories and Functions]

PR.IP-01

[Withdrawn: Incorporated into PR.PS-01]

PR.IP-02

[Withdrawn: Incorporated into ID.AM-08, PR.PS-06]

PR.IP-03

[Withdrawn: Incorporated into PR.PS-01, ID.RA-07]

PR.IP-04

[Withdrawn: Moved to PR.DS-11]

PR.IP-05

[Withdrawn: Moved to PR.IR-02]

PR.IP-06

[Withdrawn: Incorporated into ID.AM-08]

PR.IP-07

[Withdrawn: Incorporated into ID.IM, ID.IM-03]

PR.IP-08

[Withdrawn: Moved to ID.IM-03]

PR.IP-09

[Withdrawn: Moved to ID.IM-04]

PR.IP-10

[Withdrawn: Incorporated into ID.IM-02, ID.IM-04]

PR.IP-11

[Withdrawn: Moved to GV.RR-04]

PR.IP-12

[Withdrawn: Incorporated into ID.RA-01, PR.PS-02]

Maintenance (PR.MA)

[Withdrawn: Incorporated into ID.AM-08]

PR.MA-01

[Withdrawn: Incorporated into ID.AM-08, PR.PS-03]

PR.MA-02

[Withdrawn: Incorporated into ID.AM-08, PR.PS-02]

Protective Technology (PR.PT)

[Withdrawn: Incorporated into other Protect Categories]

PR.PT-01

[Withdrawn: Incorporated into PR.PS-04]

PR.PT-02

[Withdrawn: Incorporated into PR.DS-01, PR.PS-01]

PR.PT-03

[Withdrawn: Incorporated into PR.PS-01]

PR.PT-04

[Withdrawn: Incorporated into PR.AA-06, PR.IR-01]

PR.PT-05

[Withdrawn: Moved to PR.IR-03]