← All frameworks
US US · pass_fail · United States

CJIS

CJIS Security Policy

6.0

172 controls · 18 domains · 116 control enhancements
Start assessment in platform →

About this framework

The FBI CJIS Security Policy sets the minimum information-security requirements for any agency that accesses, stores, processes, or transmits Criminal Justice Information (CJI). Version 6.x aligns to NIST SP 800-53, organised into 18 control families spanning access control, audit, incident response, media/physical protection and supply-chain risk.

Who needs this

US law-enforcement and criminal-justice agencies — and their contractors, vendors and cloud providers — that access CJI (e.g. NCIC / III / NICS data). Compliance is audited by the FBI CJIS Division and state CJIS Systems Agencies.

Cross-framework coverage

Controls in CJIS also cover:

ADHICS 20 shared
CIS Controls 20 shared
NCA ECC-2 20 shared
Qatar NIA 20 shared
ISO 27001 19 shared

See how CJIS connects to the rest → the Security Universe

Control domains

AC · Access Control 17
AC-1
Policy and Procedures
a. Develop, document, and disseminate to: organizational personnel with access control responsibilities 1. Agency-level access control policy that: (a) Addresses purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance; and (b) Is consistent with applicable laws, executive orders, directives, regulations, policies, standards, and guidelines; and 2. Procedures to facilitate the implementation of the access control policy and the associated access controls;
Official crosswalk CIS Controls 6.1 (superset) CIS Controls 6.2 (superset)
ADHICSCIS ControlsHIPAA Security RuleISO 27001NCA CCCNCA ECC-2NCA OTCCNIST CSFQatar NIASAMA CSFUAE IAPCI DSS 4.0.1
AC-2
Account Management
a. Define and document the types of accounts allowed and specifically prohibited for use within the system;
Official crosswalk CIS Controls 4.3 (superset) CIS Controls 5.1 (superset) CIS Controls 5.3 (superset) CIS Controls 5.6 (superset) CIS Controls 6.1 (superset) CIS Controls 6.2 (superset) CIS Controls 6.7 (superset) CIS Controls 12.5 (superset)
6 control enhancements
  • AC-2(1) Automated System Account Management Support the management of system accounts using automated mechanisms including email, phone, and text notifications.
  • AC-2(2) Automated Temporary and Emergency Account Management Automatically remove temporary and emergency accounts within 72 hours.
  • AC-2(3) Disable Accounts Disable accounts within one (1) week when the accounts: a. Have expired; b. Are no longer associated with a user or individual; c. Are in violation of organizational policy; or d. Have been inactive for 90 calendar days.
  • AC-2(4) Automated Audit Actions Automatically audit account creation, modification, enabling, disabling, and removal actions.
  • AC-2(5) Inactivity Logout Require that users log out when a work period has been completed.
  • AC-2(13) Disable Accounts for High-risk Individuals Disable accounts of individuals within 30 minutes of discovery of direct threats to the confidentiality, integrity, or availability of CJI.
ADHICSCIS ControlsCyber EssentialsCyber Essentials PlusGDPR (EU)HIPAA Security RuleISO 27001NCA ECC-2NCA OTCCNIS2NIST CSFPCI DSS 4.0.1PDPLData-protection rulesPDPPLPDPL – Federal Decree-Law 45/2021Qatar NIASAMA CSFUAE IAUK GDPRNCA CCC
AC-3
Access Enforcement
Enforce approved authorizations for logical access to information and system resources in accordance with applicable access control policies.
Official crosswalk CIS Controls 3.3 (superset) CIS Controls 6.7 (superset)
1 control enhancement
  • AC-3(14) Individual Access Provide automated or manual processes to enable individuals to have access to elements of their personally identifiable information.
ADHICSCIS ControlsCyber EssentialsCyber Essentials PlusGDPR (EU)HIPAA Security RuleISO 27001NCA ECC-2NCA OTCCNIS2NIST CSFPCI DSS 4.0.1PDPLData-protection rulesPDPPLPDPL – Federal Decree-Law 45/2021Qatar NIASAMA CSFUAE IAUK GDPR
AC-4
Information Flow Enforcement
Enforce approved authorizations for controlling the flow of information within the system and between connected systems based on [Assignment: organization-defined information flow control policies].
Official crosswalk CIS Controls 3.8 (superset)
ADHICSCIS ControlsGDPR (EU)ISO 27001NCA ECC-2NCA OTCCNIST CSFPCI DSS 4.0.1PDPLData-protection rulesPDPPLQatar NIAPDPL – Federal Decree-Law 45/2021UAE IAUK GDPRNCA CCCDORAHIPAA Security RuleNIS2SAMA CSF
AC-5
Separation of Duties
a. Identify and document separation of duties based on specific duties, operations, or information systems, as necessary, to mitigate risk to CJI; and b. Define system access authorizations to support separation of duties.
Official crosswalk CIS Controls 3.3 (superset) CIS Controls 6.8 (superset)
ADHICSCIS ControlsCyber EssentialsCyber Essentials PlusGDPR (EU)HIPAA Security RuleISO 27001NCA ECC-2NCA OTCCNIS2NIST CSFPCI DSS 4.0.1PDPLData-protection rulesPDPPLPDPL – Federal Decree-Law 45/2021Qatar NIASAMA CSFUAE IAUK GDPR
AC-6
Least Privilege
Employ the principle of least privilege, allowing only authorized accesses for users (or processes acting on behalf of users) that are necessary to accomplish assigned organizational tasks.
Official crosswalk CIS Controls 3.3 (superset) CIS Controls 3.14 (superset) CIS Controls 5.4 (subset) CIS Controls 6.8 (superset) CIS Controls 6.8 (subset)
6 control enhancements
  • AC-6(1) Authorize Access to Security Functions Authorize access for personnel including security administrators, system and network administrators, and other privileged users with access to system control, monitoring, or administration functions (e.g., system administrators, information security personnel, maintainers, system programmers, etc.) to: a. Established system accounts, configured access authorizations (i.e., permissions, privileges), set events to be audited, set intrusion detection parameters, and other security functions; and b. Security-relevant information in hardware, software, and firmware.
  • AC-6(2) Non-privileged Access for Nonsecurity Functions Require that users of system accounts (or roles) with access to privileged security functions or security-relevant information (e.g., audit logs), use non-privileged accounts or roles, when accessing non-security functions.
  • AC-6(5) Privileged Accounts Restrict privileged accounts on the system to privileged users.
  • AC-6(7) Review of User Privileges a. Review annually the privileges assigned to non-privileged and privileged users to validate the need for such privileges; and b. Reassign or remove privileges, if necessary, to correctly reflect organizational mission and business needs.
  • AC-6(9) Log Use of Privileged Functions Log the execution of privileged functions.
  • AC-6(10) Prohibit Non-privileged Users from Executing Privileged Functions Prevent non-privileged users from executing privileged functions.
ADHICSCIS ControlsCyber EssentialsCyber Essentials PlusGDPR (EU)HIPAA Security RuleISO 27001NCA ECC-2NCA OTCCNIS2NIST CSFPCI DSS 4.0.1PDPLData-protection rulesPDPPLPDPL – Federal Decree-Law 45/2021Qatar NIASAMA CSFUAE IAUK GDPRNCA CCCDORA
AC-7
Unsuccessful Logon Attempts
a. Enforce a limit of five (5) consecutive invalid logon attempts by a user during a 15-minute time period; and30F30F30F b. Automatically lock the account or node until released by an administrator when the maximum number of unsuccessful attempts is exceeded.
Official crosswalk CIS Controls 4.10 (superset)
ADHICSCIS ControlsCyber EssentialsCyber Essentials PlusGDPR (EU)HIPAA Security RuleISO 27001NCA ECC-2NCA OTCCNIS2NIST CSFPCI DSS 4.0.1PDPLData-protection rulesPDPPLPDPL – Federal Decree-Law 45/2021Qatar NIASAMA CSFUAE IAUK GDPR
AC-8
System Use Notification
a. Display a system use notification message to users before granting access to the system that provides privacy and security notices consistent with applicable laws, executive orders, directives, regulations, policies, standards, and guidelines and state that: 1. Users are accessing a restricted information system; 2. System usage may be monitored, recorded, and subject to audit; 3. Unauthorized use of the system is prohibited and subject to criminal and civil penalties; and 4. Use of the system indicates consent to monitoring and recording; b. Retain the notification message or banner on the screen until users acknowledge the usage conditions and take explicit actions to log on to or further access the system; and c. For publicly accessible systems: 1. Display system use information consistent with applicable laws, executive orders, directives, regulations, policies, standards, and guidelines, before granting further access to the publicly accessible system; 2. Display references, if any, to monitoring, recording, or auditing that are consistent with privacy accommodations for such systems that generally prohibit those activities; and 3. Include a description of the authorized uses of the system.
AC-11
Device Lock
a. Prevent further access to the system by initiating a device lock after a maximum of 30 minutes of inactivity and requiring the user to initiate a device lock before leaving the system unattended. NOTE: In the interest of safety, devices that are: (1) part of a criminal justice conveyance; or (2) used to perform dispatch functions and located within a physically secure location; or (3) terminals designated solely for the purpose of receiving alert notifications (i.e., receive only terminals or ROT) used within physically secure location facilities that remain staffed when in operation, are exempt from this requirement. b. Retain the device lock until the user reestablishes access using established identification and authentication procedures.
Official crosswalk CIS Controls 4.3 (equivalent)
1 control enhancement
  • AC-11(1) Pattern Hiding Displays Conceal, via the device lock, information previously visible on the display with a publicly viewable image.
ADHICSCIS ControlsCyber EssentialsCyber Essentials PlusGDPR (EU)HIPAA Security RuleISO 27001NCA ECC-2NCA OTCCNIS2NIST CSFPCI DSS 4.0.1PDPLData-protection rulesPDPPLPDPL – Federal Decree-Law 45/2021Qatar NIASAMA CSFUAE IAUK GDPR
AC-12
Session Termination
Automatically terminate a user session after a user has been logged out.
AC-14
Permitted Actions Without Identification or Authentication
a. Identify any specific user actions that can be performed on the system without identification or authentication consistent with organizational mission and business functions; and b. Document and provide supporting rationale in the security plan for the system, user actions not requiring identification or authentication.
AC-17
Remote Access
Establish and document usage restrictions, configuration/connection requirements, and implementation guidance for each type of remote access allowed; and b. Authorize each type of remote access to the system prior to allowing such connections.
Official crosswalk CIS Controls 3.10 (superset) CIS Controls 6.4 (superset) CIS Controls 12.7 (superset) CIS Controls 13.5 (superset)
4 control enhancements
  • AC-17(1) Monitoring and Control Employ automated mechanisms to monitor and control remote access methods.
  • AC-17(2) Protection of Confidentiality and Integrity Using Encryption Implement cryptographic mechanisms to protect the confidentiality and integrity of remote access sessions.
  • AC-17(3) Managed Access Control Points Route remote accesses through authorized and managed network access control points.
  • AC-17(4) Privileged Commands and Access a. Authorize the execution of privileged commands and access to security-relevant information via remote access only in a format that provides assessable evidence and for the following needs: compelling operational needs; and b. Document the rationale for remote access in the security plan for the system.
UAE IAADHICSCIS ControlsGDPR (EU)HIPAA Security RuleISO 27001NCA CCCNCA ECC-2NCA OTCCNIS2NIST CSFPCI DSS 4.0.1PDPLData-protection rulesPDPPLPDPL – Federal Decree-Law 45/2021Qatar NIASAMA CSFUK GDPRCyber EssentialsCyber Essentials Plus
AC-18
Wireless Access
a. Establish configuration requirements, connection requirements, and implementation guidance for each type of wireless access; and b. Authorize each type of wireless access to the system prior to allowing such connections.
Official crosswalk CIS Controls 4.2 (subset) CIS Controls 12.6 (superset)
2 control enhancements
  • AC-18(1) Authentication and Encryption Protect wireless access to the system using authentication of authorized users and agency-controlled devices, and encryption.
  • AC-18(3) Disable Wireless Networking Disable, when not intended for use, wireless networking capabilities embedded within system components prior to issuance and deployment.
ADHICSCIS ControlsCyber EssentialsCyber Essentials PlusDORAGDPR (EU)HIPAA Security RuleISO 27001NCA CCCNCA ECC-2NCA OTCCNIS2NIST CSFPCI DSS 4.0.1PDPLData-protection rulesPDPPLPDPL – Federal Decree-Law 45/2021Qatar NIASAMA CSFUAE IAUK GDPR
AC-19
Access Control for Mobile Devices
a. Establish configuration requirements, connection requirements, and implementation guidance for organization-controlled mobile devices, to include when such devices are outside of controlled areas; and b. Authorize the connection of mobile devices to organizational systems.
Official crosswalk CIS Controls 4.10 (superset) CIS Controls 4.11 (superset) CIS Controls 4.12 (equivalent) CIS Controls 6.4 (superset)
1 control enhancement
  • AC-19(5) Full Device or Container-based Encryption Employ full-device encryption to protect the confidentiality and integrity of information on full- and limited-feature operating system mobile devices authorized to process, store, or transmit CJI.
ADHICSCIS ControlsCyber EssentialsCyber Essentials PlusGDPR (EU)HIPAA Security RuleISO 27001NCA ECC-2NCA OTCCNIS2NIST CSFPCI DSS 4.0.1PDPLData-protection rulesPDPPLPDPL – Federal Decree-Law 45/2021Qatar NIASAMA CSFUAE IAUK GDPRDORANCA CCC
AC-20
Use of External Systems
a. Establish agency-level policies governing the use of external systems consistent with the trust relationships established with other organizations owning, operating, and/or maintaining external systems, allowing authorized individuals to: 1. Access the system from external systems; and 2. Process, store, or transmit organization-controlled information using external systems; or b. Prohibit the use of personally-owned information systems including mobile devices (i.e., bring your own device [BYOD]) and publicly accessible systems for accessing, processing, storing, or transmitting CJI. 33F33F33F
Official crosswalk CIS Controls 4.11 (superset) CIS Controls 15.2 (superset) CIS Controls 15.3 (superset) CIS Controls 15.5 (superset)
1 control enhancement
  • AC-20(1) Limits on Authorized Use Permit authorized individuals to use an external system to access the system or to process, store, or transmit organization-controlled information only after: a. Verification of the implementation of controls on the external system as specified in the organization’s security and privacy policies and security and privacy plans; or b. Retention of approved system connection or processing agreements with the organizational entity hosting the external system.
ADHICSCIS ControlsDORAGDPR (EU)HIPAA Security RuleISO 27001NCA ECC-2NCA OTCCNIS2NIST CSFPCI DSS 4.0.1PDPLData-protection rulesPDPPLPDPL – Federal Decree-Law 45/2021Qatar NIASAMA CSFUAE IAUK GDPRNCA CCCCyber EssentialsCyber Essentials Plus
AC-21
Information Sharing
a. Enable authorized users to determine whether access authorizations assigned to a sharing partner match the information’s access and use restrictions for as defined in an executed information exchange agreement; and b. Employ attribute-based access control (see AC-2(d)(3)) or manual processes as defined in information exchange agreements to assist users in making information sharing and collaboration decisions.
Official crosswalk CIS Controls 15.2 (subset)
ADHICSCIS ControlsDORAGDPR (EU)HIPAA Security RuleISO 27001NCA CCCNCA ECC-2NCA OTCCNIS2NIST CSFPCI DSS 4.0.1PDPLData-protection rulesPDPPLPDPL – Federal Decree-Law 45/2021Qatar NIASAMA CSFUAE IAUK GDPR
AC-22
Publicly Accessible Content
a. Designate individuals authorized to make information publicly accessible; b. Train authorized individuals to ensure that publicly accessible information does not contain nonpublic information; c. Review the proposed content of information prior to posting onto the publicly accessible system to ensure that nonpublic information is not included; and d. Review the content on the publicly accessible system for nonpublic information quarterly and remove such information, if discovered.
Official crosswalk CIS Controls 14.5 (superset)
ADHICSCIS ControlsGDPR (EU)HIPAA Security RuleISO 27001NCA ECC-2NCA OTCCNIS2NIST CSFPCI DSS 4.0.1Qatar NIASAMA CSFUAE IAUK GDPR
AT · Awareness and Training 4
AT-1
Policy and Procedures
a. Develop, document, and disseminate to all personnel when their unescorted logical or physical access to any information system results in the ability, right, or privilege to view, modify, or make use of unencrypted CJI: 1. Organization-level awareness and training policy that: a. Addresses purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance; and b. Is consistent with applicable laws, executive orders, directives, regulations, policies, standards, and guidelines; and 2. Procedures to facilitate the implementation of the awareness and training policy and the associated awareness and training controls; b. Designate organizational personnel with information security awareness and training responsibilities to manage the development, documentation, and dissemination of the awareness and training policy and procedures; and c. Review and update the current awareness and training: 1. Policy annually and following changes in the information system operating environment, when security incidents occur, or when changes to the CJIS Security Policy are made; and 2. Procedures annually and following changes in the information system operating environment, when security incidents occur, or when changes to the CJIS Security Policy are made.
Official crosswalk CIS Controls 14.1 (superset)
ADHICSCIS ControlsGDPR (EU)HIPAA Security RuleISO 27001NCA ECC-2NCA OTCCNIS2NIST CSFPCI DSS 4.0.1Qatar NIASAMA CSFUAE IAUK GDPR
AT-2
Literacy Training and Awareness
a. Provide security and privacy literacy training to system users (including managers, senior executives, and contractors): 1. As part of initial training for new users prior to accessing CJI and annually thereafter; and 2. When required by system changes or within 30 days of any security event for individuals involved in the event; b. Employ one or more of the following techniques to increase the security and privacy awareness of system users: 1. Displaying posters 2. Offering supplies inscribed with security and privacy reminders 3. Displaying logon screen messages 4. Generating email advisories or notices from organizational officials 5. Conducting awareness events c. Update literacy training and awareness content annually and following changes in the information system operating environment, when security incidents occur, or when changes are made in the CJIS Security Policy; and d. Incorporate lessons learned from internal or external security incidents or breaches into literacy training and awareness techniques.
Official crosswalk CIS Controls 14.1 (superset) CIS Controls 14.1 (subset) CIS Controls 14.2 (equivalent)
2 control enhancements
  • AT-2(2) Insider Threat Provide literacy training on recognizing and reporting potential indicators of insider threat.
  • AT-2(3) Social Engineering and Mining Provide literacy training on recognizing and reporting potential and actual instances of social engineering and social mining.
ADHICSCIS ControlsGDPR (EU)HIPAA Security RuleISO 27001NCA ECC-2NCA OTCCNIS2NIST CSFPCI DSS 4.0.1Qatar NIASAMA CSFUAE IAUK GDPR
AT-3
Role-based Training
g. Audit Monitoring, Analysis, and Reporting h. Access Enforcement i. Least Privilege j. System Access Control k. Access Control Criteria l. System Use Notification m. Session Lock n. Personally Owned Information Systems o. Password p. Access Control
Official crosswalk CIS Controls 14.3 (superset) CIS Controls 14.4 (superset) CIS Controls 14.6 (superset) CIS Controls 14.7 (superset) CIS Controls 14.8 (superset) CIS Controls 14.9 (equivalent) CIS Controls 14.9 (subset)
1 control enhancement
  • AT-3(5) Processing Personally Identifiable Information Provide all personnel when their unescorted logical or physical access to any information system results in the ability, right, or privilege to view, modify, or make use of unencrypted CJI with initial and annual training in the employment and operation of personally identifiable information processing and transparency controls.
ADHICSCIS ControlsGDPR (EU)HIPAA Security RuleISO 27001NCA ECC-2NCA OTCCNIS2NIST CSFPCI DSS 4.0.1Qatar NIASAMA CSFUAE IAUK GDPRPDPLData-protection rulesPDPPLPDPL – Federal Decree-Law 45/2021NCA CCCDORACyber EssentialsCyber Essentials Plus
AT-4
Training Records
a. Document and monitor information security and privacy training activities, including security and privacy awareness training and specific role-based security and privacy training; and b. Retain individual training records for a minimum of three years.
Official crosswalk CIS Controls 14.1 (subset)
ADHICSCIS ControlsGDPR (EU)HIPAA Security RuleISO 27001NCA ECC-2NCA OTCCNIS2NIST CSFPCI DSS 4.0.1Qatar NIASAMA CSFUAE IAUK GDPR
AU · Audit and Accountability 11
AU-1
Policy and Procedures
2. Procedures to facilitate the implementation of the audit and accountability policy and the associated audit and accountability controls;
Official crosswalk CIS Controls 8.1 (equivalent)
ADHICSCIS ControlsDORAGDPR (EU)HIPAA Security RuleISO 27001NCA CCCNCA ECC-2NCA OTCCNIS2NIST CSFPCI DSS 4.0.1PDPLData-protection rulesPDPPLPDPL – Federal Decree-Law 45/2021Qatar NIASAMA CSFUAE IAUK GDPR
AU-2
Event Logging
4. Actions by privileged accounts (i.e., root, Oracle, DBA, admin, etc.)
Official crosswalk CIS Controls 3.14 (superset) CIS Controls 8.1 (subset) CIS Controls 8.2 (equivalent) CIS Controls 8.6 (superset) CIS Controls 8.7 (superset) CIS Controls 8.8 (superset) CIS Controls 8.12 (superset)
ADHICSCIS ControlsGDPR (EU)ISO 27001NCA ECC-2NCA OTCCNIST CSFPCI DSS 4.0.1PDPLData-protection rulesPDPPLQatar NIAPDPL – Federal Decree-Law 45/2021UAE IAUK GDPRNCA CCCDORAHIPAA Security RuleNIS2SAMA CSF
AU-3
Content of Audit Records
Ensure that audit records contain information that establishes the following: a. What type of event occurred; b. When the event occurred; c. Where the event occurred; d. Source of the event; e. Outcome of the event; and f. Identity of any individuals, subjects, or objects/entities associated with the event.
Official crosswalk CIS Controls 8.5 (equivalent) CIS Controls 8.5 (superset)
2 control enhancements
  • AU-3(1) Additional Audit Information Generate audit records containing the following additional information: a. Session, connection, transaction, and activity duration; b. Source and destination addresses; c. Object or filename involved; and d. Number of bytes received and bytes sent (for client-server transactions) in the audit records for audit events identified by type, location, or subject. e. The III portion of the log shall clearly identify: 1. The operator 2. The authorized receiving agency 3. The requestor 4. The secondary recipient
  • AU-3(3) Limit Personally Identifiable Information Elements Limit personally identifiable information contained in audit records to the following elements identified in the privacy risk assessment: minimum PII necessary to achieve the purpose for which it is collected (see Section 4.3).
ADHICSCIS ControlsDORAGDPR (EU)HIPAA Security RuleISO 27001NCA CCCNCA ECC-2NCA OTCCNIS2NIST CSFPCI DSS 4.0.1PDPLData-protection rulesPDPPLPDPL – Federal Decree-Law 45/2021Qatar NIASAMA CSFUAE IAUK GDPR
AU-4
Audit Log Storage Capacity
Allocate audit log storage capacity to accommodate the collection of audit logs to meet retention requirements (AU-11).
Official crosswalk CIS Controls 8.3 (equivalent)
ADHICSCIS ControlsDORAGDPR (EU)HIPAA Security RuleISO 27001NCA CCCNCA ECC-2NCA OTCCNIS2NIST CSFPCI DSS 4.0.1PDPLData-protection rulesPDPPLPDPL – Federal Decree-Law 45/2021Qatar NIASAMA CSFUAE IAUK GDPR
AU-5
Response to Audit Logging Process Failures
a. Alert organizational personnel with audit and accountability responsibilities and system/network administrators within one (1) hour in the event of an audit logging process failure; and b. Take the following additional actions: restart all audit logging processes and verify system(s) are logging properly.
AU-6
Audit Record Review, Analysis, and Reporting
a. Review and analyze system audit records weekly for indications of inappropriate or unusual activity and the potential impact of the inappropriate or unusual activity; b. Report findings to organizational personnel with audit review, analysis, and reporting responsibilities and organizational personnel with information security and privacy responsibilities; and c. Adjust the level of audit record review, analysis, and reporting within the system when there is a change in risk based on law enforcement information, intelligence information, or other credible sources of information.
Official crosswalk CIS Controls 8.9 (superset) CIS Controls 8.11 (equivalent) CIS Controls 8.11 (superset) CIS Controls 13.1 (superset)
2 control enhancements
  • AU-6(1) Automated Process Integration Integrate audit record review, analysis, and reporting processes using automated mechanisms.
  • AU-6(3) Correlate Audit Record Repositories Analyze and correlate audit records across different repositories to gain organization-wide situational awareness.
ADHICSCIS ControlsDORAGDPR (EU)HIPAA Security RuleISO 27001NCA CCCNCA ECC-2NCA OTCCNIS2NIST CSFPCI DSS 4.0.1PDPLData-protection rulesPDPPLPDPL – Federal Decree-Law 45/2021Qatar NIASAMA CSFUAE IAUK GDPR
AU-7
Audit Record Reduction and Report Generation
Provide and implement an audit record reduction and report generation capability that: a. Supports on-demand audit record review, analysis, and reporting requirements and after- the-fact investigations of incidents; and b. Does not alter the original content or time ordering of audit records.
Official crosswalk CIS Controls 8.2 (superset) CIS Controls 8.11 (superset) CIS Controls 13.1 (superset)
1 control enhancement
  • AU-7(1) Automatic Processing Provide and implement the capability to process, sort, and search audit records for events of interest based on the following content: information included in AU-3.
ADHICSCIS ControlsDORAGDPR (EU)HIPAA Security RuleISO 27001NCA CCCNCA ECC-2NCA OTCCNIS2NIST CSFPCI DSS 4.0.1PDPLData-protection rulesPDPPLPDPL – Federal Decree-Law 45/2021Qatar NIASAMA CSFUAE IAUK GDPR
AU-8
Time Stamps
a. Use internal system clocks to generate time stamps for audit records; and b. Record time stamps for audit records that meet [Assignment: organization-defined granularity of time measurement] and that use Coordinated Universal Time, have a fixed local time offset from Coordinated Universal Time, or that include the local time offset as part of the time stamp.
Official crosswalk CIS Controls 8.4 (superset)
ADHICSCIS ControlsDORAGDPR (EU)HIPAA Security RuleISO 27001NCA CCCNCA ECC-2NCA OTCCNIS2NIST CSFPCI DSS 4.0.1PDPLData-protection rulesPDPPLPDPL – Federal Decree-Law 45/2021Qatar NIASAMA CSFUAE IAUK GDPR
AU-9
Protection of Audit Information
a. Protect audit information and audit logging tools from unauthorized access, modification, and deletion; and b. Alert organizational personnel with audit and accountability responsibilities, organizational personnel with information security and privacy responsibilities, and system/network administrators upon detection of unauthorized access, modification, or deletion of audit information.
Official crosswalk CIS Controls 6.8 (subset)
1 control enhancement
  • AU-9(4) Access by Subset of Privileged Users Authorize access to management of audit logging functionality to only organizational personnel with audit and accountability responsibilities, organizational personnel with information security and privacy responsibilities, and system/network administrators.
ADHICSCIS ControlsCyber EssentialsCyber Essentials PlusGDPR (EU)HIPAA Security RuleISO 27001NCA ECC-2NCA OTCCNIS2NIST CSFPCI DSS 4.0.1PDPLData-protection rulesPDPPLPDPL – Federal Decree-Law 45/2021Qatar NIASAMA CSFUAE IAUK GDPR
AU-11
Audit Record Retention
Retain audit records for a minimum of one (1) year or until it is determined they are no longer needed for administrative, legal, audit, or other operational purposes to provide support for after-the-fact investigations of incidents and to meet regulatory and organizational information retention requirements.
Official crosswalk CIS Controls 3.1 (subset) CIS Controls 3.4 (superset) CIS Controls 8.10 (equivalent)
ADHICSCIS ControlsGDPR (EU)ISO 27001NCA ECC-2NCA OTCCNIST CSFPCI DSS 4.0.1PDPLData-protection rulesPDPPLQatar NIAPDPL – Federal Decree-Law 45/2021UAE IAUK GDPRNCA CCCDORAHIPAA Security RuleNIS2SAMA CSF
AU-12
Audit Record Generation
a. Provide audit record generation capability for the event types the system is capable of auditing as defined in AU-2a on all systems generating required audit logs; b. Allow organizational personnel with audit record generation responsibilities, organizational personnel with information security and privacy responsibilities, and system/network administrators to select the event types that are to be logged by specific components of the system; and c. Generate audit records for the event types defined in AU-2c that include the audit record content defined in AU-3.
Official crosswalk CIS Controls 3.14 (superset) CIS Controls 8.2 (equivalent) CIS Controls 8.5 (superset)
ADHICSCIS ControlsGDPR (EU)ISO 27001NCA ECC-2NCA OTCCNIST CSFPCI DSS 4.0.1PDPLData-protection rulesPDPPLQatar NIAPDPL – Federal Decree-Law 45/2021UAE IAUK GDPRNCA CCCDORAHIPAA Security RuleNIS2SAMA CSF
CA · Assessment, Authorization, and Monitoring 7
CA-1
Policy and Procedures
a. Develop, document, and disseminate to organizational personnel with assessment, authorization, and monitoring policy responsibilities: 1. An assessment, authorization, and monitoring policy that: (a) Addresses purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance; and (b) Is consistent with applicable laws, executive orders, directives, regulations, policies, standards, and guidelines; and 2. Procedures to facilitate the implementation of the assessment, authorization, and monitoring policy and the associated assessment, authorization, and monitoring controls; b. Designate organizational personnel with information security responsibilities to manage the development, documentation, and dissemination of the assessment, authorization, and monitoring policy and procedures; and c. Review and update the current assessment, authorization, and monitoring: 1. Policy annually and following changes to the assessment criteria and 2. Procedures annually and following changes to the assessment criteria.
CA-2
Control Assessments
a. Select the appropriate assessor or assessment team for the type of assessment to be conducted; b. Develop a control assessment plan that describes the scope of the assessment including: 1. Controls and control enhancements under assessment; 2. Assessment procedures to be used to determine control effectiveness; and 3. Assessment environment, assessment team, and assessment roles and responsibilities; c. Ensure the control assessment plan is reviewed and approved by the authorizing official or designated representative prior to conducting the assessment; d. Assess the controls in the system and its environment of operation and any controls that have been impacted by evolving threats at least once every three years to determine the extent to which the controls are implemented correctly, operating as intended, and producing the desired outcome with respect to meeting established security and privacy requirements; e. Produce a control assessment report that documents the results of the assessment; and f. Provide the results of the control assessment report to the individual who executed the CJIS User Agreement or is in contract with the FBI.
1 control enhancement
  • CA-2(1) Independent Assessors Employ independent assessors or assessment teams to conduct control assessments.
CA-3
Information Exchange
a. Approve and manage the exchange of information between the agency system and external systems using the following agreements when applicable; 1. Executed CJIS User Agreements a. Each CSA, SIB, or IA shall execute a signed written agreement (see Appendix D.1) with the FBI CJIS Division stating their willingness to demonstrate conformity with the CJISSECPOL before accessing and consuming CJIS systems and services as set forth in the agreement. b. The agreement shall include the standards, audit, and sanctions governing utilization of CJIS systems and services. c. The FBI CJIS Division is authorized to periodically test the ability to penetrate the FBI’s network through the external connection or system upon proper notification of all signatories in the user agreement. 2. Criminal Justice Agency User Agreements a. Any CJA receiving access to CJI shall enter into a signed written agreement with the appropriate signatory authority of the CSA providing the access. b. The written agreement shall specify the FBI CJIS systems and services to which the agency will have access, and the FBI CJIS Division policies to which the agency must adhere. These agreements shall include: i. Audit ii. Dissemination iii. Hit confirmation iv. Logging v. Quality Assurance (QA) vi. Screening (Criminal Justice Employment) vii. Security viii. Timeliness ix. Training x. Use of the system xi. Validation
CA-5
Plan of Action and Milestones
a. Develop a plan of action and milestones for the system to document the planned remediation actions of the organization to correct weaknesses or deficiencies noted during the assessment of the controls and to reduce or eliminate known vulnerabilities in the system; and b. Update existing plan of action and milestones at least every six (6) months or when new information is available based on the findings from control assessments, independent audits or reviews, and continuous monitoring activities.
CA-6
Authorization
a. Assign a senior official as the responsible official for the system; b. Assign the CSO, SIB Chief, or IA Official as the authorizing official for common controls available for inheritance by organizational systems; c. Ensure that the authorizing official for the system, before commencing operations: 1. Accepts the use of common controls inherited by the system; and 2. Authorizes the system to operate; d. Ensure that the authorizing official for common controls authorizes the use of those controls for inheritance by organizational systems; e. Update the authorizations at least every three (3) years.
CA-7
Continuous Monitoring
Develop a system-level continuous monitoring strategy and implement continuous monitoring in accordance with the organization-level continuous monitoring strategy that includes:
Official crosswalk CIS Controls 13.2 (superset) CIS Controls 13.6 (subset) CIS Controls 15.6 (superset)
2 control enhancements
  • CA-7(1) Independent Assessment Employ independent assessors or assessment teams to monitor the controls in the system on an ongoing basis.
  • CA-7(4) Risk Monitoring Ensure risk monitoring is an integral part of the continuous monitoring strategy that includes the following: a. Effectiveness monitoring; b. Compliance monitoring; and c. Change monitoring.
ADHICSCIS ControlsDORAGDPR (EU)HIPAA Security RuleISO 27001NCA CCCNCA ECC-2NCA OTCCNIS2NIST CSFPCI DSS 4.0.1PDPLData-protection rulesPDPPLPDPL – Federal Decree-Law 45/2021Qatar NIASAMA CSFUAE IAUK GDPR
CA-9
Internal System Connections
a. Authorize internal connections of components with the capability to process, store, or transmit CJI to the system; b. Document, for each internal connection, the interface characteristics, security and privacy requirements, and the nature of the information communicated; c. Terminate internal system connections when no longer required or authorized; and d. Review at least annually the continued need for each internal connection.
Official crosswalk CIS Controls 3.12 (subset) CIS Controls 12.2 (subset) CIS Controls 13.4 (superset)
ADHICSCIS ControlsGDPR (EU)ISO 27001NCA ECC-2NCA OTCCNIST CSFPCI DSS 4.0.1PDPLData-protection rulesPDPPLQatar NIAPDPL – Federal Decree-Law 45/2021UAE IAUK GDPRNCA CCCCyber EssentialsCyber Essentials PlusHIPAA Security RuleNIS2SAMA CSF
CM · Configuration Management 12
CM-1
Policy and Procedures
2. Procedures to facilitate the implementation of the configuration management policy and the associated configuration management controls;
Official crosswalk CIS Controls 4.1 (equivalent)
ADHICSCIS ControlsCyber EssentialsCyber Essentials PlusDORAGDPR (EU)HIPAA Security RuleISO 27001NCA CCCNCA ECC-2NCA OTCCNIS2NIST CSFPCI DSS 4.0.1PDPLData-protection rulesPDPPLPDPL – Federal Decree-Law 45/2021Qatar NIASAMA CSFUAE IAUK GDPR
CM-2
Baseline Configuration
a. Develop, document, and maintain under configuration control, a current baseline configuration of the system;
Official crosswalk CIS Controls 4.1 (subset) CIS Controls 4.2 (subset)
3 control enhancements
  • CM-2(2) Automation Support for Accuracy and Currency Maintain the currency, completeness, accuracy, and availability of the baseline configuration of the system using automated mechanisms such as configuration management tools, hardware, software, firmware inventory tools, and network management tools.
  • CM-2(3) Retention of Previous Configurations Retain at least one (1) previous version of baseline configurations of the system to support rollback.
  • CM-2(7) Configure Systems and Components for High-risk Areas a. Issue devices (e.g., mobile devices) with CJISSECPOL compliant configurations to individuals traveling to locations that the organization deems to be of significant risk; and b. Apply the following controls to the systems or components when the individuals return from travel: examine the device for signs of physical tampering, purge and reimage disk drives and/or devices as required, and ensure all security controls are in place and functional.
ADHICSCIS ControlsCyber EssentialsCyber Essentials PlusDORAGDPR (EU)HIPAA Security RuleISO 27001NCA CCCNCA ECC-2NCA OTCCNIS2NIST CSFPCI DSS 4.0.1PDPLData-protection rulesPDPPLPDPL – Federal Decree-Law 45/2021Qatar NIASAMA CSFUAE IAUK GDPR
CM-3
Configuration Change Control
a. Determine and document the types of changes to the system that are configuration-controlled; b. Review proposed configuration-controlled changes to the system and approve or disapprove such changes with explicit consideration for security and privacy impact analyses; c. Document configuration change decisions associated with the system; d. Implement approved configuration-controlled changes to the system; e. Retain records of configuration-controlled changes to the system for two (2) years; f. Monitor and review activities associated with configuration-controlled changes to the system; and g. Coordinate and provide oversight for configuration change control activities through personnel with configuration management responsibilities, a Configuration Control Board, or Change Advisory Board that convenes regularly or when hardware or software changes (i.e., updates, upgrades, replacements, etc.) to the information system are required.
2 control enhancements
  • CM-3(2) Testing, Validation, and Documentation of Changes Test, validate, and document changes to the system before finalizing the implementation of the changes.
  • CM-3(4) Security and Privacy Representatives Require organizational personnel with information security and privacy responsibilities to be members of the Configuration Control Board or Change Advisory Board.
CM-4
Impact Analyses
Analyze changes to the system to determine potential security and privacy impacts prior to change implementation.
1 control enhancement
  • CM-4(2) Verification of Controls After-system changes, verify that the impacted controls are implemented correctly, operating as intended, and producing the desired outcome with regard to meeting the security and privacy requirements for the system.
CM-5
Access Restrictions for Change
Define, document, approve, and enforce physical and logical access restrictions associated with changes to the system.
CM-6
Configuration Settings
a. Establish and document configuration settings for components employed within the system that reflect the most restrictive mode consistent with operational requirements using [Assignment: organization-defined common secure configurations]; b. Implement the configuration settings;
Official crosswalk CIS Controls 4.1 (subset) CIS Controls 4.2 (subset) CIS Controls 4.8 (superset) CIS Controls 12.3 (superset) CIS Controls 13.9 (superset) CIS Controls 16.7 (superset)
ADHICSCIS ControlsCyber EssentialsCyber Essentials PlusDORAGDPR (EU)HIPAA Security RuleISO 27001NCA CCCNCA ECC-2NCA OTCCNIS2NIST CSFPCI DSS 4.0.1PDPLData-protection rulesPDPPLPDPL – Federal Decree-Law 45/2021Qatar NIASAMA CSFUAE IAUK GDPR
CM-7
Least Functionality
a. Configure the system to provide only essential capabilities to meet operational requirements; and b. Prohibit or restrict the use of specified functions, ports, protocols, software, and/or services which are not required.
Official crosswalk CIS Controls 2.1 (superset) CIS Controls 2.5 (equivalent) CIS Controls 2.6 (superset) CIS Controls 2.6 (subset) CIS Controls 2.7 (superset) CIS Controls 2.7 (subset) CIS Controls 4.1 (superset) CIS Controls 4.1 (subset) CIS Controls 4.2 (superset) CIS Controls 4.8 (superset) CIS Controls 12.2 (subset) CIS Controls 12.3 (superset) CIS Controls 13.9 (superset) CIS Controls 16.7 (superset)
3 control enhancements
  • CM-7(1) Periodic Review a. Review the system annually, as the system changes, or incidents occur to identify unnecessary and/or nonsecure functions, ports, protocols, software, and services; and b. Disable or remove functions, ports, protocols, software, and/or services within the system deemed to be unnecessary and/or unsecure.
  • CM-7(2) Prevent Program Execution Prevent program execution in accordance with rules of behavior and/or rules authorizing the terms and conditions of software program usage.
  • CM-7(5) Authorized Software — Allow-by-exception a. Identify software programs authorized to execute on the system; b. Employ a deny-all, permit-by-exception policy to allow the execution of authorized software programs on the system; and c. Review and update the list of authorized software programs annually.
ADHICSCIS ControlsCyber EssentialsCyber Essentials PlusDORAGDPR (EU)HIPAA Security RuleISO 27001NCA CCCNCA ECC-2NCA OTCCNIS2NIST CSFPCI DSS 4.0.1PDPLData-protection rulesPDPPLPDPL – Federal Decree-Law 45/2021Qatar NIASAMA CSFUAE IAUK GDPR
CM-8
System Component Inventory
a. Develop and document an inventory of system components that: 1. Accurately reflects the system 2. Includes all components within the system
Official crosswalk CIS Controls 1.1 (superset) CIS Controls 1.1 (subset) CIS Controls 1.2 (superset) CIS Controls 1.4 (superset) CIS Controls 1.5 (superset) CIS Controls 2.1 (superset) CIS Controls 2.3 (superset) CIS Controls 2.4 (superset) CIS Controls 6.6 (superset) CIS Controls 12.1 (superset) CIS Controls 16.4 (superset)
2 control enhancements
  • CM-8(1) Updates During Installation and Removal Update the inventory of system components as part of component installations, removals, and system updates.
  • CM-8(3) Automated Unauthorized Component Detection (a) Detect the presence of unauthorized hardware, software, and firmware components within the system using [Assignment: organization-defined automated mechanisms] [Assignment: organization-defined frequency]; and (b) Take the following actions when unauthorized components are detected: [Selection (one or more): disable network access by such components; isolate the components; notify [Assignment: organization-defined personnel or roles]].
ADHICSCIS ControlsCyber EssentialsCyber Essentials PlusDORAGDPR (EU)HIPAA Security RuleISO 27001NCA CCCNCA ECC-2NCA OTCCNIS2NIST CSFPCI DSS 4.0.1PDPLData-protection rulesPDPPLPDPL – Federal Decree-Law 45/2021Qatar NIASAMA CSFUAE IAUK GDPR
CM-9
Configuration Management Plan
Develop, document, and implement a configuration management plan for the system that: a. Addresses roles, responsibilities, and configuration management processes and procedures; b. Establishes a process for identifying configuration items throughout the system development life cycle and for managing the configuration of the configuration items; c. Defines the configuration items for the system and places the configuration items under configuration management; d. Is reviewed and approved by organizational personnel with information security responsibilities and organizational personnel with configuration management responsibilities; and e. Protects the configuration management plan from unauthorized disclosure and modification.
Official crosswalk CIS Controls 4.1 (equivalent) CIS Controls 4.2 (equivalent)
ADHICSCIS ControlsCyber EssentialsCyber Essentials PlusDORAGDPR (EU)HIPAA Security RuleISO 27001NCA CCCNCA ECC-2NCA OTCCNIS2NIST CSFPCI DSS 4.0.1PDPLData-protection rulesPDPPLPDPL – Federal Decree-Law 45/2021Qatar NIASAMA CSFUAE IAUK GDPR
CM-10
Software Usage Restrictions
a. Use software and associated documentation in accordance with contract agreements and copyright laws; b. Track the use of software and associated documentation protected by quantity licenses to control copying and distribution; and c. Control and document the use of peer-to-peer file sharing technology to ensure that this capability is not used for the unauthorized distribution, display, performance, or reproduction of copyrighted work.
Official crosswalk CIS Controls 2.3 (superset) CIS Controls 2.5 (subset) CIS Controls 9.1 (superset) CIS Controls 9.4 (superset)
ADHICSCIS ControlsCyber EssentialsCyber Essentials PlusDORAGDPR (EU)HIPAA Security RuleISO 27001NCA CCCNCA ECC-2NCA OTCCNIS2NIST CSFPCI DSS 4.0.1PDPLData-protection rulesPDPPLPDPL – Federal Decree-Law 45/2021Qatar NIASAMA CSFUAE IAUK GDPR
CM-11
User-installed Software
a. Establish agency-level policies governing the installation of software by users; b. Enforce software installation policies through automated methods; and c. Monitor policy compliance through automated methods at least weekly.
Official crosswalk CIS Controls 2.3 (superset) CIS Controls 9.4 (superset)
ADHICSCIS ControlsCyber EssentialsCyber Essentials PlusDORAGDPR (EU)HIPAA Security RuleISO 27001NCA CCCNCA ECC-2NCA OTCCNIS2NIST CSFPCI DSS 4.0.1PDPLData-protection rulesPDPPLPDPL – Federal Decree-Law 45/2021Qatar NIASAMA CSFUAE IAUK GDPR
CM-12
Information Location
a. Identify and document the location of CJI and the specific system components on which the information is processed, stored, or transmitted; b. Identify and document the users who have access to the system and system components where the information is processed and stored; and c. Document changes to the location (i.e., system or system components) where the information is processed and stored.
Official crosswalk CIS Controls 3.1 (superset) CIS Controls 3.2 (subset) CIS Controls 3.8 (superset) CIS Controls 3.13 (superset)
1 control enhancement
  • CM-12(1) Automated Tools to Support Information Location Use automated tools to identify CJI on software and hardware system components to ensure controls are in place to protect organizational information and individual privacy.
ADHICSCIS ControlsGDPR (EU)ISO 27001NCA ECC-2NCA OTCCNIST CSFPCI DSS 4.0.1PDPLData-protection rulesPDPPLQatar NIAPDPL – Federal Decree-Law 45/2021UAE IAUK GDPRNCA CCCDORAHIPAA Security RuleNIS2SAMA CSF
CP · Contingency Planning 8
CP-2
Contingency Plan
a. Develop, document, and disseminate to organizational personnel with contingency planning responsibilities: 1. Agency-level contingency planning policy that: (a) Addresses purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance; and (b) Is consistent with applicable laws, executive orders, directives, regulations, policies, standards, and guidelines; and 2. Procedures to facilitate the implementation of the contingency planning policy and the associated contingency planning controls; b. Designate organizational personnel with information security responsibilities to manage the development, documentation, and dissemination of the contingency planning policy and procedures; and c. Review and update the current contingency planning: 1. Policy annually and following any security incidents involving unauthorized access to CJI or systems used to process, store, or transmit CJI, or training simulations or exercises; and 2. Procedures annually and following any security incidents involving unauthorized access to CJI or systems used to process, store, or transmit CJI, or training simulations or exercises.
Official crosswalk CIS Controls 11.1 (superset)
3 control enhancements
  • CP-2(1) Coordinate with Related Plans Coordinate contingency plan development with organizational elements responsible for related plans.
  • CP-2(3) Resume Mission and Business Functions Plan for the resumption of essential mission and business functions within twenty-four (24) hours of contingency plan activation.
  • CP-2(8) Identify Critical Assets Identify critical system assets supporting essential mission and business functions.
ADHICSCIS ControlsDORAGDPR (EU)HIPAA Security RuleISO 27001NCA CCCNCA ECC-2NCA OTCCNIS2NIST CSFPDPLData-protection rulesPDPPLPDPL – Federal Decree-Law 45/2021Qatar NIAUAE IAUK GDPR
CP-3
Contingency Training
a. Provide contingency training to system users consistent with assigned roles and responsibilities: 1. Within thirty (30) days of assuming a contingency role or responsibility; 2. When required by system changes; and 3. Annually thereafter; and b. Review and update contingency training content annually and following any security incidents involving unauthorized access to CJI or systems used to process, store, or transmit CJI, or training simulations or exercises.
CP-4
Contingency Plan Testing
a. Test the contingency plan for the system annually using the following tests to determine the effectiveness of the plan and the readiness to execute the plan: checklists, walk-through and tabletop exercises, simulations (parallel or full interrupt), or comprehensive exercises.
Official crosswalk CIS Controls 11.5 (superset)
1 control enhancement
  • CP-4(1) Coordinate with Related Plans Coordinate contingency plan testing with organizational elements responsible for related plans.
ADHICSCIS ControlsDORAGDPR (EU)HIPAA Security RuleISO 27001NCA CCCNCA ECC-2NCA OTCCNIS2NIST CSFPDPLData-protection rulesPDPPLPDPL – Federal Decree-Law 45/2021Qatar NIAUAE IAUK GDPR
CP-6
Alternate Storage Site
a. Establish an alternate storage site, including necessary agreements to permit the storage and retrieval of system backup information; and b. Ensure that the alternate storage site provides controls equivalent to that of the primary site.
Official crosswalk CIS Controls 11.4 (subset)
2 control enhancements
  • CP-6(1) Separation from Primary Site Identify an alternate storage site that is sufficiently separated from the primary storage site to reduce susceptibility to the same threats.
  • CP-6(3) Accessibility Identify potential accessibility problems to the alternate storage site in the event of an area-wide disruption or disaster and outline explicit mitigation actions.
ADHICSCIS ControlsDORAGDPR (EU)HIPAA Security RuleISO 27001NCA CCCNCA ECC-2NCA OTCCNIS2NIST CSFPDPLData-protection rulesPDPPLPDPL – Federal Decree-Law 45/2021Qatar NIAUAE IAUK GDPR
CP-7
Alternate Processing Site
a. Establish an alternate processing site, including necessary agreements to permit the transfer and resumption of operations for essential mission and business functions within the time period defined in the system contingency plan(s) when the primary processing capabilities are unavailable; b. Make available at the alternate processing site, the equipment and supplies required to transfer and resume operations or put contracts in place to support delivery to the site within the organization-defined time period for transfer and resumption; and c. Provide controls at the alternate processing site that are equivalent to those at the primary site.
3 control enhancements
  • CP-7(1) Separation from Primary Site Identify an alternate processing site that is sufficiently separated from the primary processing site to reduce susceptibility to the same threats.
  • CP-7(2) Accessibility Identify potential accessibility problems to alternate processing sites in the event of an area-wide disruption or disaster and outlines explicit mitigation actions.
  • CP-7(3) Priority of Service Develop alternate processing site agreements that contain priority-of-service provisions in accordance with availability requirements (including recovery time objectives).
CP-8
Telecommunications Services
Establish alternate telecommunications services, including necessary agreements to permit the resumption of system operations for essential mission and business functions within the time period as defined in the system contingency plan(s) when the primary telecommunications capabilities are unavailable at either the primary or alternate processing or storage sites.
Official crosswalk CIS Controls 17.6 (subset)
2 control enhancements
  • CP-8(1) Priority of Service Provisions (a) Develop primary and alternate telecommunications service agreements that contain priority-of-service provisions in accordance with availability requirements (including recovery time objectives); and (b) Request Telecommunications Service Priority for all telecommunications services used for national security emergency preparedness if the primary and/or alternate telecommunications services are provided by a common carrier.
  • CP-8(2) Single Points of Failure Obtain alternate telecommunications services to reduce the likelihood of sharing a single point of failure with primary telecommunications services.
ADHICSCIS ControlsDORAGDPR (EU)HIPAA Security RuleISO 27001NCA ECC-2NCA OTCCNIS2NIST CSFPCI DSS 4.0.1PDPLData-protection rulesPDPPLPDPL – Federal Decree-Law 45/2021Qatar NIASAMA CSFUAE IAUK GDPR
CP-9
System Backup
a. Conduct backups of user-level information contained in operational systems for essential business functions as required by the contingency plans; b. Conduct backups of system-level information contained in the system as required by the contingency plans; c. Conduct backups of system documentation, including security- and privacy-related documentation as required by the contingency plans; and
Official crosswalk CIS Controls 11.2 (superset) CIS Controls 11.3 (superset) CIS Controls 11.5 (superset)
2 control enhancements
  • CP-9(1) Testing for Reliability and Integrity Test backup information as required by the contingency plans to verify media reliability and information integrity.
  • CP-9(8) Cryptographic Protection Implement cryptographic mechanisms to prevent unauthorized disclosure and modification of CJI.
ADHICSCIS ControlsDORAGDPR (EU)HIPAA Security RuleISO 27001NCA CCCNCA ECC-2NCA OTCCNIS2NIST CSFPDPLData-protection rulesPDPPLPDPL – Federal Decree-Law 45/2021Qatar NIAUAE IAUK GDPRPCI DSS 4.0.1SAMA CSF
CP-10
System Recovery and Reconstitution
Provide for the recovery and reconstitution of the system to a known state within the timeframe as required by the contingency plans after a disruption, compromise, or failure.
Official crosswalk CIS Controls 11.1 (superset) CIS Controls 11.2 (superset)
1 control enhancement
  • CP-10(2) Transaction Recovery Implement transaction recovery for systems that are transaction-based.
ADHICSCIS ControlsDORAGDPR (EU)HIPAA Security RuleISO 27001NCA CCCNCA ECC-2NCA OTCCNIS2NIST CSFPDPLData-protection rulesPDPPLPDPL – Federal Decree-Law 45/2021Qatar NIAUAE IAUK GDPR
IA · Identification and Authentication 10
IA-1
Policy and Procedures
a. Develop, document, and disseminate to authorized personnel: 1. Agency/Entity identification and authentication policy that: (a) Addresses purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance; and (b) Is consistent with applicable laws, executive orders, directives, regulations, policies, standards, and guidelines; and 2. Procedures to facilitate the implementation of the identification and authentication policy and the associated identification and authentication controls; b. Designate an individual with security responsibilities to manage the development, documentation, and dissemination of the identification and authentication policy and procedures; and c. Review and update the current identification and authentication: 1. Policy annually and following any security incidents involving unauthorized access to CJI or systems used to process, store, or transmit CJI; and 2. Procedures annually and following any security incidents involving unauthorized access to CJI or systems used to process, store, or transmit CJI.
IA-2
Identification and Authentication (organizational Users)
Uniquely identify and authenticate organizational users and associate that unique identification with processes acting on behalf of those users.
Official crosswalk CIS Controls 6.3 (superset) CIS Controls 6.4 (superset) CIS Controls 6.5 (equivalent)
4 control enhancements
  • IA-2(1) Multi-factor Authentication to Privileged Accounts Implement multi-factor authentication for access to privileged accounts.
  • IA-2(2) Multi-factor Authentication to Non-privileged Accounts Implement multi-factor authentication for access to non-privileged accounts.
  • IA-2(8) Access to Accounts — Replay Resistant Implement replay-resistant authentication mechanisms for access to privileged and non-privileged accounts.
  • IA-2(12) Acceptance of PIV Credentials Accept and electronically verify Personal Identity Verification-compliant credentials.
ADHICSCIS ControlsCyber EssentialsCyber Essentials PlusHIPAA Security RuleNCA ECC-2NCA OTCCNIS2NIST CSFPCI DSS 4.0.1Qatar NIA
IA-3
Device Identification and Authentication
Uniquely identify and authenticate agency-managed devices before establishing network connections. In the instance of local connection, the device must be approved by the agency and the device must be identified and authenticated prior to connection to an agency asset.
IA-4
Identifier Management
Manage system identifiers by: a. Receiving authorization from organizational personnel with identifier management responsibilities to assign an individual, group, role, service, or device identifier; b. Selecting an identifier that identifies an individual, group, role, service, or device; c. Assigning the identifier to the intended individual, group, role, service, or device; and d. Preventing reuse of identifiers for one (1) year.41F41F41F
Official crosswalk CIS Controls 6.1 (superset)
1 control enhancement
  • IA-4(4) Identify User Status Manage individual identifiers by uniquely identifying each individual as agency or nonagency.
ADHICSCIS ControlsHIPAA Security RuleISO 27001NCA CCCNCA ECC-2NCA OTCCNIST CSFQatar NIASAMA CSFUAE IAPCI DSS 4.0.1
IA-5
Authenticator Management
g. Protecting authenticator content from unauthorized disclosure and modification;
Official crosswalk CIS Controls 3.10 (superset) CIS Controls 4.7 (superset) CIS Controls 5.2 (superset) CIS Controls 6.1 (superset)
3 control enhancements
  • IA-5(1) Authenticator Types (a) Memorized Secret Authenticators and Verifiers: 1. Maintain a list of commonly-used, expected, or compromised passwords and update the list quarterly and when organizational passwords are suspected to have been compromised directly or indirectly; 2. Require immediate selection of a new password upon account recovery;53F53F53F 3. Allow user selection of long passwords and passphrases, including spaces and all printable characters;54F54F54F 4. Employ automated tools to assist the user in selecting strong password authenticators;55F55F55F 5. Enforce the following composition and complexity rules when agencies elect to follow basic password standards: (a) Not be a proper name. (b) Not be the same as the Userid. (c) Expire within a maximum of 90 calendar days. (d) Not be identical to the previous ten (10) passwords. (e) Not be displayed when entered.
  • IA-5(2) Public Key-based Authentication (a) For public key-based authentication: (1) Enforce authorized access to the corresponding private key; and (2) Map the authenticated identity to the account of the individual or group; and (b) When public key infrastructure (PKI) is used: (1) Validate certificates by constructing and verifying a certification path to an accepted trust anchor, including checking certificate status information; and (2) Implement a local cache of revocation data to support path discovery and validation.
  • IA-5(6) Protection of Authenticators Protect authenticators commensurate with the security category of the information to which use of the authenticator permits access.
UAE IAADHICSCIS ControlsGDPR (EU)HIPAA Security RuleISO 27001NCA CCCNCA ECC-2NCA OTCCNIS2NIST CSFPCI DSS 4.0.1PDPLData-protection rulesPDPPLPDPL – Federal Decree-Law 45/2021Qatar NIASAMA CSFUK GDPRCyber EssentialsCyber Essentials PlusDORA
IA-6
Authentication Feedback
Obscure feedback of authentication information during the authentication process to protect the information from possible exploitation and use by unauthorized individuals.
IA-7
Cryptographic Module Authentication
Implement mechanisms for authentication to a cryptographic module that meet the requirements of applicable laws, executive orders, directives, policies, regulations, standards, and guidelines for such authentication.
IA-8
Identification and Authentication (non-organizational Users)
Uniquely identify and authenticate non-organizational users or processes acting on behalf of non-organizational users.
Official crosswalk CIS Controls 6.6 (superset)
3 control enhancements
  • IA-8(1) Acceptance of PIV Credentials from Other Agencies Accept and electronically verify Personal Identity Verification-compliant credentials from other federal agencies.
  • IA-8(2) Acceptance of External Authenticators (a) Accept only external authenticators that are NIST-compliant; and (b) Document and maintain a list of accepted external authenticators.
  • IA-8(4) Use of Defined Profiles Conform to the following profiles for identity management: Security Assertion Markup Language (SAML) or OpenID Connect.
ADHICSCIS ControlsCyber EssentialsCyber Essentials PlusGDPR (EU)HIPAA Security RuleISO 27001NCA ECC-2NCA OTCCNIS2NIST CSFPCI DSS 4.0.1PDPLData-protection rulesPDPPLPDPL – Federal Decree-Law 45/2021Qatar NIASAMA CSFUAE IAUK GDPRDORANCA CCC
IA-11
Re-authentication
Require users to re-authenticate when: roles, authenticators, or credentials change, security categories of systems change, the execution of privileged functions occur, or every 12 hours.
IA-12
Identity Evidence
3 control enhancements
  • IA-12(2) Identity Evidence Require evidence of individual identification be presented to the registration authority.
  • IA-12(3) Identity Evidence Validation and Verification Require that the presented identity evidence be validated and verified through agency-defined resolution, validation, and verification methods.
  • IA-12(5) Address Confirmation Require that a registration code or notice of proofing be delivered through an out-of-band channel to verify the users address (physical or digital) of record.
IR · Incident Response 8
IR-1
Policy and Procedures
Designate an individual with security responsibilities to manage the development, documentation, and dissemination of the incident response policy and procedures;
Official crosswalk CIS Controls 17.1 (superset) CIS Controls 17.4 (superset) CIS Controls 17.5 (superset)
ADHICSCIS ControlsDORAGDPR (EU)HIPAA Security RuleISO 27001NCA ECC-2NCA OTCCNIS2NIST CSFPCI DSS 4.0.1PDPLData-protection rulesPDPPLPDPL – Federal Decree-Law 45/2021Qatar NIASAMA CSFUAE IAUK GDPRNCA CCC
IR-2
Incident Response Training
a. Provide incident response training to system users consistent with assigned roles and responsibilities: 1. Prior to assuming an incident response role or responsibility or acquiring system access; 2. When required by system changes; and 3. Annually thereafter; and b. Review and update incident response training content annually and following any security incidents involving unauthorized access to CJI or systems used to process, store, or transmit CJI. 5F5F5F
Official crosswalk CIS Controls 14.9 (subset) CIS Controls 17.3 (superset) CIS Controls 17.5 (superset)
1 control enhancement
  • IR-2(3) Breach Provide incident response training on how to identify and respond to a breach, including the organization’s process for reporting a breach.
ADHICSCIS ControlsGDPR (EU)HIPAA Security RuleISO 27001NCA ECC-2NCA OTCCNIS2NIST CSFPCI DSS 4.0.1Qatar NIASAMA CSFUAE IAUK GDPRDORAPDPLData-protection rulesPDPPLPDPL – Federal Decree-Law 45/2021NCA CCC
IR-3
Incident Response Testing
Test the effectiveness of the incident response capability for the system annually using the following tests: tabletop or walk-through exercises; simulations; or other agency-appropriate tests.
Official crosswalk CIS Controls 17.7 (equivalent)
1 control enhancement
  • IR-3(2) Coordination with Relatated Plans Coordinate incident response testing with organizational elements responsible for related plans.
ADHICSCIS ControlsDORAGDPR (EU)HIPAA Security RuleISO 27001NCA ECC-2NCA OTCCNIS2NIST CSFPCI DSS 4.0.1PDPLData-protection rulesPDPPLPDPL – Federal Decree-Law 45/2021Qatar NIASAMA CSFUAE IAUK GDPR
IR-4
Incident Handling
c. Incorporate lessons learned from ongoing incident handling activities into incident response procedures, training, and testing, and implement the resulting changes accordingly;
Official crosswalk CIS Controls 13.1 (subset) CIS Controls 17.8 (superset) CIS Controls 17.9 (superset)
1 control enhancement
  • IR-4(1) Automated Incident Handling Processes Support the incident handling process using automated mechanisms (e.g., online incident management systems and tools that support the collection of live response data, full network packet capture, and forensic analysis.
ADHICSCIS ControlsDORAGDPR (EU)HIPAA Security RuleISO 27001NCA CCCNCA ECC-2NCA OTCCNIS2NIST CSFPCI DSS 4.0.1PDPLData-protection rulesPDPPLPDPL – Federal Decree-Law 45/2021Qatar NIASAMA CSFUAE IAUK GDPR
IR-5
Incident Monitoring
Track and document incidents.
Official crosswalk CIS Controls 17.3 (superset) CIS Controls 17.4 (superset)
ADHICSCIS ControlsDORAGDPR (EU)HIPAA Security RuleISO 27001NCA ECC-2NCA OTCCNIS2NIST CSFPCI DSS 4.0.1PDPLData-protection rulesPDPPLPDPL – Federal Decree-Law 45/2021Qatar NIASAMA CSFUAE IAUK GDPR
IR-6
Incident Reporting
a. Require personnel to report suspected incidents to the organizational incident response capability immediately but not to exceed one (1) hour after discovery; and b. Report incident information to organizational personnel with incident handling responsibilities, and if confirmed, notify the CSO, SIB Chief, or Interface Agency Official.
Official crosswalk CIS Controls 17.2 (superset) CIS Controls 17.2 (subset) CIS Controls 17.3 (superset) CIS Controls 17.3 (subset) CIS Controls 17.4 (subset)
2 control enhancements
  • IR-6(1) Automated Reporting Report incidents using automated mechanisms.
  • IR-6(3) Supply Chain Coordination Provide incident information to the provider of the product or service and other organizations involved in the supply chain or supply chain governance for systems or system components related to the incident.
ADHICSCIS ControlsDORAGDPR (EU)HIPAA Security RuleISO 27001NCA ECC-2NCA OTCCNIS2NIST CSFPCI DSS 4.0.1PDPLData-protection rulesPDPPLPDPL – Federal Decree-Law 45/2021Qatar NIASAMA CSFUAE IAUK GDPR
IR-7
Incident Response Assistance
Provide an incident response support resource, integral to the organizational incident response capability, that offers advice and assistance to users of the system for the handling and reporting of incidents.
Official crosswalk CIS Controls 17.1 (subset)
1 control enhancement
  • IR-7(1) Automation Support for Availability of Information and Support Increase the availability of incident response information and support using automated mechanisms described in the discussion.
ADHICSCIS ControlsDORAGDPR (EU)HIPAA Security RuleISO 27001NCA ECC-2NCA OTCCNIS2NIST CSFPCI DSS 4.0.1PDPLData-protection rulesPDPPLPDPL – Federal Decree-Law 45/2021Qatar NIASAMA CSFUAE IAUK GDPR
IR-8
Incident Response Plan
10. Explicitly designates responsibility for incident response to organizational personnel with incident reporting responsibilities and CSO or CJIS WAN Official.
Official crosswalk CIS Controls 17.1 (superset) CIS Controls 17.4 (superset) CIS Controls 17.5 (superset) CIS Controls 17.9 (superset)
1 control enhancement
  • IR-8(1) Breaches Include the following in the Incident Response Plan for breaches involving personally identifiable information: a. A process to determine if notice to individuals or other organizations, including oversight organizations, is needed; b. An assessment process to determine the extent of the harm, embarrassment, inconvenience, or unfairness to affected individuals and any mechanisms to mitigate such harms; and c. Identification of applicable privacy requirements.
ADHICSCIS ControlsDORAGDPR (EU)HIPAA Security RuleISO 27001NCA ECC-2NCA OTCCNIS2NIST CSFPCI DSS 4.0.1PDPLData-protection rulesPDPPLPDPL – Federal Decree-Law 45/2021Qatar NIASAMA CSFUAE IAUK GDPRNCA CCC
MA · Maintenance 6
MA-1
Policy and Procedures
a. Develop, document, and disseminate to organizational personnel with system maintenance responsibilities: 1. Agency-level maintenance policy that: (a) Addresses purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance; and (b) Is consistent with applicable laws, executive orders, directives, regulations, policies, standards, and guidelines; and 2. Procedures to facilitate the implementation of the maintenance policy and the associated maintenance controls; b. Designate an individual with security responsibilities to manage the development, documentation, and dissemination of the maintenance policy and procedures; and c. Review and update the current maintenance: 1. Policy annually and following any security incidents involving unauthorized access to CJI or systems used to process, store, or transmit CJI; and 2. Procedures annually and following any security incidents involving unauthorized access to CJI or systems used to process, store, or transmit CJI.
MA-2
Controlled Maintenance
a. Schedule, document, and review records of maintenance, repair, and replacement on system components in accordance with manufacturer or vendor specifications and/or organizational requirements; b. Approve and monitor all maintenance activities, whether performed on site or remotely and whether the system or system components are serviced on site or removed to another location; c. Require that organizational personnel with information security and privacy responsibilities explicitly approve the removal of the system or system components from organizational facilities for off-site maintenance, repair, or replacement; d. Sanitize equipment to remove information from associated media prior to removal from organizational facilities for off-site maintenance, repair, replacement, or destruction; e. Check all potentially impacted controls to verify that the controls are still functioning properly following maintenance, repair, or replacement actions; and f. Include the following information in organizational maintenance records: 1. Component name 2. Component serial number 3. Date/time of maintenance 4. Maintenance performed 5. Name(s) of entity performing maintenance including escort if required.
MA-3
Maintenance Tools
a. Approve, control, and monitor the use of system maintenance tools; and b. Review previously approved system maintenance tools prior to each use.
Official crosswalk CIS Controls 2.1 (subset)
3 control enhancements
  • MA-3(1) Inspect Tools Inspect the maintenance tools used by maintenance personnel for improper or unauthorized modifications.
  • MA-3(2) Inspect Media Check media containing diagnostic and test programs for malicious code before the media are used in the system.
  • MA-3(3) Prevent Unauthorized Removal Prevent the removal of maintenance equipment containing organizational information by: a. Verifying that there is no organizational information contained on the equipment; b. Sanitizing or destroying the equipment; c. Retaining the equipment within the facility; or d. Obtaining an exemption from organizational personnel with system maintenance responsibilities explicitly authorizing removal of the equipment from the facility.
ADHICSCIS ControlsCyber EssentialsCyber Essentials PlusDORAGDPR (EU)HIPAA Security RuleISO 27001NCA CCCNCA ECC-2NCA OTCCNIS2NIST CSFPCI DSS 4.0.1PDPLData-protection rulesPDPPLPDPL – Federal Decree-Law 45/2021Qatar NIASAMA CSFUAE IAUK GDPR
MA-4
Nonlocal Maintenance
a. Approve and monitor nonlocal maintenance and diagnostic activities; b. Allow the use of nonlocal maintenance and diagnostic tools only as consistent with organizational policy and documented in the security plan for the system; c. Employ strong authentication in the establishment of nonlocal maintenance and diagnostic sessions; d. Maintain records for nonlocal maintenance and diagnostic activities; and e. Terminate session and network connections when nonlocal maintenance is completed.
MA-5
Maintenance Personnel
a. Establish a process for maintenance personnel authorization and maintain a list of authorized maintenance organizations or personnel; b. Verify that non-escorted personnel performing maintenance on the system possess the required access authorizations; and c. Designate organizational personnel with required access authorizations and technical competence to supervise the maintenance activities of personnel who do not possess the required access authorizations.
MA-6
Timely Maintenance
Obtain maintenance support and/or spare parts for critical system components that process, store, and transmit CJI within agency-defined recovery time and recovery point objectives of failure.
MP · Media Protection 6
MP-1
Policy and Procedures
a. Develop, document, and disseminate to authorized individuals: 1. Agency-level media protection policy that: (a) Addresses purpose, scope, roles, responsibilities, management commitment, coordination among agency entities, and compliance; and (b) Is consistent with applicable laws, executive orders, directives, regulations, policies, standards, and guidelines; and 2. Procedures to facilitate the implementation of the media protection policy and the associated media protection controls; b. Designate an individual with security responsibilities to manage the development, documentation, and dissemination of the media protection policy and procedures; and c. Review and update the current media protection: 82F82F82F 1. Policy at least annually and following any security incidents involving digital and/or non-digital media; and 2. Procedures at least annually and following any security incidents involving digital and/or non-digital media.
MP-2
Media Access
Restrict access to digital and non-digital media to authorized individuals.
Official crosswalk CIS Controls 3.3 (subset)
ADHICSCIS ControlsCyber EssentialsCyber Essentials PlusGDPR (EU)HIPAA Security RuleISO 27001NCA ECC-2NCA OTCCNIS2NIST CSFPCI DSS 4.0.1PDPLData-protection rulesPDPPLPDPL – Federal Decree-Law 45/2021Qatar NIASAMA CSFUAE IAUK GDPR
MP-4
Media Storage
a. Physically control and securely store digital and non-digital media within physically secure locations or controlled areas and encrypt CJI on digital media when physical and personnel restrictions are not feasible; and b. Protect system media types defined in MP-4a until the media are destroyed or sanitized using approved equipment, techniques, and procedures.
MP-5
Media Transport
a. Protect and control digital and non-digital media to help prevent compromise of the data during transport outside of the physically secure locations or controlled areas using encryption, as defined in SC-13 and SC-28 of this Policy. Physical media will be protected at the same level as the information would be protected in electronic form. Restrict the activities associated with transport of electronic and physical media to authorized personnel;
Official crosswalk CIS Controls 3.9 (superset)
UAE IAADHICSCIS ControlsGDPR (EU)HIPAA Security RuleISO 27001NCA CCCNCA ECC-2NCA OTCCNIS2NIST CSFPCI DSS 4.0.1PDPLData-protection rulesPDPPLPDPL – Federal Decree-Law 45/2021Qatar NIASAMA CSFUK GDPR
MP-6
Media Sanitization
Sanitize or destroy digital and non-digital media prior to disposal, release out of agency control, or release for reuse using overwrite technology at least three times or degauss digital media prior to disposal or release for reuse by unauthorized individuals. Inoperable digital media will be destroyed (cut up, shredded, etc.). Physical media will be securely disposed of when no longer needed for investigative or security purposes, whichever is later. Physical media will be destroyed by crosscut shredding or incineration; and b. Employ sanitization mechanisms with the strength and integrity commensurate with the security category or classification of the information.
Official crosswalk CIS Controls 3.5 (superset)
ADHICSCIS ControlsGDPR (EU)ISO 27001NCA ECC-2NCA OTCCNIST CSFPCI DSS 4.0.1PDPLData-protection rulesPDPPLQatar NIAPDPL – Federal Decree-Law 45/2021UAE IAUK GDPRNCA CCC
MP-7
Media Use
a. Restrict the use of digital and non-digital media on agency owned systems that have been approved for use in the storage, processing, or transmission of criminal justice information by using technical, physical, or administrative controls (examples below);
Official crosswalk CIS Controls 3.9 (superset)
UAE IAADHICSCIS ControlsGDPR (EU)HIPAA Security RuleISO 27001NCA CCCNCA ECC-2NCA OTCCNIS2NIST CSFPCI DSS 4.0.1PDPLData-protection rulesPDPPLPDPL – Federal Decree-Law 45/2021Qatar NIASAMA CSFUK GDPR
PE · Physical and Environmental Protection 16
PE-1
Policy and Procedures
a. Develop, document, and disseminate to [Assignment: organization-defined personnel or roles]: 1. [Selection (one or more): Organization-level; Mission/business process-level; System-level] physical and environmental protection policy that: (a) Addresses purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance; and (b) Is consistent with applicable laws, executive orders, directives, regulations, policies, standards, and guidelines; and 2. Procedures to facilitate the implementation of the physical and environmental protection policy and the associated physical and environmental protection controls; b. Designate an [Assignment: organization-defined official] to manage the development, documentation, and dissemination of the physical and environmental protection policy and procedures; and c. Review and update the current physical and environmental protection: 1. Policy [Assignment: organization-defined frequency] and following [Assignment: organization-defined events]; and 2. Procedures [Assignment: organization-defined frequency] and following [Assignment: organization-defined events].
PE-2
Physical Access Authorizations
a. Develop, approve, and maintain a list of individuals with authorized access to the facility where the system resides; b. Issue authorization credentials for facility access; c. Review the access list detailing authorized facility access by individuals [Assignment: organization-defined frequency]; and d. Remove individuals from the facility access list when access is no longer required.
PE-3
Physical Access Control
a. Enforce physical access authorizations at [Assignment: organization-defined entry and exit points to the facility where the system resides] by: 1. Verifying individual access authorizations before granting access to the facility; and 2. Controlling ingress and egress to the facility using [Selection (one or more): [Assignment: organization-defined physical access control systems or devices]; guards]; b. Maintain physical access audit logs for [Assignment: organization-defined entry or exit points]; c. Control access to areas within the facility designated as publicly accessible by implementing the following controls: [Assignment: organization-defined physical access controls]; d. Escort visitors and control visitor activity [Assignment: organization-defined circumstances requiring visitor escorts and control of visitor activity]; e. Secure keys, combinations, and other physical access devices; f. Inventory [Assignment: organization-defined physical access devices] every [Assignment: organization-defined frequency]; and g. Change combinations and keys [Assignment: organization-defined frequency] and/or when keys are lost, combinations are compromised, or when individuals possessing the keys or combinations are transferred or terminated.
PE-4
Access Control for Transmission
Control physical access to [Assignment: organization-defined system distribution and transmission lines] within organizational facilities using [Assignment: organization-defined security controls].
PE-5
Access Control for Output Devices
Control physical access to output from [Assignment: organization-defined output devices] to prevent unauthorized individuals from obtaining the output.
PE-6
Monitoring Physical Access
a. Monitor physical access to the facility where the system resides to detect and respond to physical security incidents; b. Review physical access logs [Assignment: organization-defined frequency] and upon occurrence of [Assignment: organization-defined events or potential indications of events]; and c. Coordinate results of reviews and investigations with the organizational incident response capability.
1 control enhancement
  • PE-6(1) Intrusion Alarms and Surveillance Equipment Monitor physical access to the facility where the system resides using physical intrusion alarms and surveillance equipment.
PE-8
Visitor Access Records
a. Maintain visitor access records to the facility where the system resides for [Assignment: organization-defined time period]; b. Review visitor access records [Assignment: organization-defined frequency]; and c. Report anomalies in visitor access records to [Assignment: organization-defined personnel].
PE-9
Power Equipment and Cabling
Protect power equipment and power cabling for the system from damage and destruction.
PE-10
Emergency Shutoff
a. Provide the capability of shutting off power to [Assignment: organization-defined system or individual system components] in emergency situations; b. Place emergency shutoff switches or devices in [Assignment: organization-defined location by system or system component] to facilitate access for authorized personnel; and c. Protect emergency power shutoff capability from unauthorized activation.
PE-11
Emergency Power
Provide an uninterruptible power supply to facilitate [Selection (one or more): an orderly shutdown of the system; transition of the system to long-term alternate power] in the event of a primary power source loss.
PE-12
Emergency Lighting
Employ and maintain automatic emergency lighting for the system that activates in the event of a power outage or disruption and that covers emergency exits and evacuation routes within the facility.
PE-13
Fire Protection
Employ and maintain fire detection and suppression systems that are supported by an independent energy source.
1 control enhancement
  • PE-13(1) Detection Systems — Automatic Activation and Notification Employ fire detection systems that activate automatically and notify [Assignment: organization-defined personnel or roles] and [Assignment: organization-defined emergency responders] in the event of a fire.
PE-14
Environmental Controls
a. Maintain [Selection (one or more): temperature; humidity; pressure; radiation; [Assignment: organization-defined environmental control]] levels within the facility where the system resides at [Assignment: organization-defined acceptable levels]; and b. Monitor environmental control levels [Assignment: organization-defined frequency].
PE-15
Water Damage Protection
Protect the system from damage resulting from water leakage by providing master shutoff or isolation valves that are accessible, working properly, and known to key personnel.
PE-16
Delivery and Removal
a. Authorize and control [Assignment: organization-defined types of system components] entering and exiting the facility; and b. Maintain records of the system components.
PE-17
Alternate Work Site
a. Determine and document the [Assignment: organization-defined alternate work sites] allowed for use by employees; b. Employ the following controls at alternate work sites: [Assignment: organization-defined controls]; c. Assess the effectiveness of controls at alternate work sites; and d. Provide a means for employees to communicate with information security and privacy personnel in case of incidents.
PL · Planning 7
PL-1
Policy and Procedures
a. Develop, document, and disseminate to organizational personnel with planning responsibilities: 1. Agency-level planning policy that: (c) Addresses purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance; and (d) Is consistent with applicable laws, executive orders, directives, regulations, policies, standards, and guidelines; and 2. Procedures to facilitate the implementation of the planning policy and the associated planning controls; b. Designate organizational personnel with information security and privacy responsibilities to manage the development, documentation, and dissemination of the planning policy and procedures; and c. Review and update the current planning: 1. Policy annually and following; any security incidents involving unauthorized access to CJI or systems used to process, store, or transmit CJI and 2. Procedures annually and following any security incidents involving unauthorized access to CJI or systems used to process, store, or transmit CJI.
PL-2
System Security and Privacy Plans
a. Develop security and privacy plans for the system that: 1. Are consistent with the organization’s enterprise architecture; 2. Explicitly define the constituent system components; 3. Describe the operational context of the system in terms of mission and business processes; 4. Identify the individuals that fulfill system roles and responsibilities; 5. Identify the information types processed, stored, and transmitted by the system; 6. Provide the security categorization of the system, including supporting rationale; 7. Describe any specific threats to the system that are of concern to the organization; 8. Provide the results of a privacy risk assessment for systems processing personally identifiable information; 9. Describe the operational environment for the system and any dependencies on or connections to other systems or system components; 10. Provide an overview of the security and privacy requirements for the system; 11. Identify any relevant control baselines or overlays, if applicable; 12. Describe the controls in place or planned for meeting the security and privacy requirements, including a rationale for any tailoring decisions; 13. Include risk determinations for security and privacy architecture and design decisions; 14. Include security- and privacy-related activities affecting the system that require planning and coordination with organizational personnel with system security and privacy planning and plan implementation responsibilities; system developers; organizational personnel with information security and privacy responsibilities; and 15. Are reviewed and approved by the authorizing official or designated representative prior to plan implementation.
PL-4
Rules of Behavior
a. Establish and provide to individuals requiring access to the system, the rules that describe their responsibilities and expected behavior for information and system usage, security, and privacy; b. Receive a documented acknowledgment from such individuals, indicating that they have read, understand, and agree to abide by the rules of behavior, before authorizing access to information and the system; c. Review and update the rules of behavior at least annually; and d. Require individuals who have acknowledged a previous version of the rules of behavior to read and re-acknowledge annually, or when the rules are revised or updated.
1 control enhancement
  • PL-4(1) Social Media and External Site/application Usage Restrictions Include in the rules of behavior, restrictions on: a. Use of social media, social networking sites, and external sites/applications; b. Posting organizational information on public websites; and c. Use of organization-provided identifiers (e.g., email addresses) and authentication secrets (e.g., passwords) for creating accounts on external sites/applications.
PL-8
Security and Privacy Architectures
a. Develop security and privacy architectures for the system that: 1. Describe the requirements and approach to be taken for protecting the confidentiality, integrity, and availability of organizational information; 2. Describe the requirements and approach to be taken for processing personally identifiable information to minimize privacy risk to individuals; 3. Describe how the architectures are integrated into and support the enterprise architecture; and 4. Describe any assumptions about, and dependencies on, external systems and services; b. Review and update the architectures at least annually or when changes to the system or its environment occur to reflect changes in the enterprise architecture; and c. Reflect planned architecture changes in security and privacy plans, Concept of Operations (CONOPS), criticality analysis, organizational procedures, and procurements and acquisitions.
Official crosswalk CIS Controls 12.2 (superset) CIS Controls 12.4 (superset) CIS Controls 16.10 (superset)
ADHICSCIS ControlsCyber EssentialsCyber Essentials PlusGDPR (EU)HIPAA Security RuleISO 27001NCA ECC-2NCA OTCCNIS2NIST CSFPCI DSS 4.0.1PDPLData-protection rulesPDPPLPDPL – Federal Decree-Law 45/2021Qatar NIASAMA CSFUAE IAUK GDPRDORANCA CCC
PL-9
Central Management
The CJISSECPOL is centrally managed by the FBI CJIS ISO.
PL-10
Baseline Selection
Select a control baseline for the system.
PL-11
Baseline Tailoring
Tailor the selected control baseline by applying specified tailoring actions
PS · Personnel Security 8
PS-1
Policy and Procedures
a. Develop, document, and disseminate to organizational personnel with personnel security responsibilities: 1. Agency-level personnel security policy that: a. Addresses purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance; and b. Is consistent with applicable laws, executive orders, directives, regulations, policies, standards, and guidelines; and 2. Procedures to facilitate the implementation of the personnel security policy and the associated personnel security controls; b. Designate organizational personnel with information security responsibilities to manage the development, documentation, and dissemination of the personnel security policy and procedures; and c. Review and update the current personnel security: 1. Policy annually and following assessment or audit findings, security incidents or breaches, or changes in applicable laws, executive orders, directives, regulations, policies, standards, and guidelines; and 2. Procedures annually and following assessment or audit findings, security incidents or breaches, or changes in applicable laws, executive orders, directives, regulations, policies, standards, and guidelines.
PS-2
Position Risk Designation
a. Assign a risk designation to all organizational positions; b. Establish screening criteria for individuals filling those positions; and c. Review and update position risk designations as required.
PS-3
Personnel Screening
a. Screen individuals prior to authorizing access to the information system;
PS-4
Personnel Termination
Upon termination of individual employment: a. Disable system access within twenty-four (24) hours; b. Terminate or revoke any authenticators and credentials associated with the individual; c. Conduct exit interviews that include a discussion of non-disclosure of CJI and PII; d. Retrieve all security-related organizational system-related property; and e. Retain access to organizational information and systems formerly controlled by terminated individual.
Official crosswalk CIS Controls 6.2 (superset)
ADHICSCIS ControlsHIPAA Security RuleISO 27001NCA CCCNCA ECC-2NCA OTCCNIST CSFQatar NIASAMA CSFUAE IAPCI DSS 4.0.1
PS-6
Access Agreements
a. Develop and document access agreements for organizational systems; b. Review and update the access agreements at least annually; and c. Verify that individuals requiring access to organizational information and systems: 1. Sign appropriate access agreements prior to being granted access; and 2. Re-sign access agreements to maintain access to organizational systems when access agreements have been updated or when signatories change.
PS-7
External Personnel Security
a. Establish personnel security requirements, including security roles and responsibilities for external providers; b. Require external providers to comply with personnel security policies and procedures established by the organization; c. Document personnel security requirements; d. Require external providers to notify organizational personnel with information security responsibilities, organizational personnel with personnel security responsibilities, system/network administrators, or organizational personnel with account management responsibilities of any personnel transfers or terminations of external personnel who possess organizational credentials and/or badges, or who have system privileges within twenty-four (24) hours; and e. Monitor provider compliance with personnel security requirements.
PS-8
Personnel Sanctions
a. Employ a formal sanctions process for individuals failing to comply with established information security and privacy policies and procedures; and b. Notify organizational personnel with information security responsibilities, organizational personnel with personnel security responsibilities, system/network administrators, or organizational personnel with account management responsibilities within twenty-four (24) hours when a formal employee sanctions process is initiated, identifying the individual sanctioned and the reason for the sanction.
PS-9
Position Descriptions
Incorporate security and privacy roles and responsibilities into organizational position descriptions.
RA · Risk Assessment 6
RA-1
Policy and Procedures
a. Develop, document, and disseminate to organizational personnel with risk assessment responsibilities: 1. Agency Level risk assessment policy that: (a) Addresses purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance; and (b) Is consistent with applicable laws, executive orders, directives, regulations, policies, standards, and guidelines; and 2. Procedures to facilitate the implementation of the risk assessment policy and the associated risk assessment controls; b. Designate organizational personnel with security and privacy responsibilities to manage the development, documentation, and dissemination of the risk assessment policy and procedures; and c. Review and update the current risk assessment: 1. Policy annually and following any security incidents involving unauthorized access to CJI or systems used to process, store, or transmit CJI; and 2. Procedures annually and following any security incidents involving unauthorized access to CJI or systems used to process, store, or transmit CJI.
RA-2
Security Categorization
a. Categorize the system and information it processes, stores, and transmits; b. Document the security categorization results, including supporting rationale, in the security plan for the system; and c. Verify that the authorizing official or authorizing official designated representative reviews and approves the security categorization decision.
Official crosswalk CIS Controls 3.2 (superset) CIS Controls 3.7 (superset)
ADHICSCIS ControlsGDPR (EU)ISO 27001NCA ECC-2NCA OTCCNIST CSFPCI DSS 4.0.1PDPLData-protection rulesPDPPLQatar NIAPDPL – Federal Decree-Law 45/2021UAE IAUK GDPRNCA CCC
RA-3
Risk Assessment
a. Conduct a risk assessment, including: 1. Identifying threats to and vulnerabilities in the system; 2. Determining the likelihood and magnitude of harm from unauthorized access, use, disclosure, disruption, modification, or destruction of the system, the information it processes, stores, or transmits, and any related information; and 3. Determining the likelihood and impact of adverse effects on individuals arising from the processing of personally identifiable information; b. Integrate risk assessment results and risk management decisions from the organization and mission or business process perspectives with system-level risk assessments; c. Document risk assessment results in a risk assessment report; d. Review risk assessment results at least quarterly; e. Disseminate risk assessment results to organizational personnel with risk assessment responsibilities and organizational personnel with security and privacy responsibilities; and f. Update the risk assessment at least quarterly or when there are significant changes to the system, its environment of operation, or other conditions that may impact the security or privacy state of the system.
RA-5
Vulnerability Monitoring and Scanning
a. Monitor and scan for vulnerabilities in the system and hosted applications at least monthly and when new vulnerabilities potentially affecting the system are identified and reported; b. Employ vulnerability monitoring tools and techniques that facilitate interoperability among tools and automate parts of the vulnerability management process by using standards for: 1. Enumerating platforms, software flaws, and improper configurations; 2. Formatting checklists and test procedures; and 3. Measuring vulnerability impact; c. Analyze vulnerability scan reports and results from vulnerability monitoring;
Official crosswalk CIS Controls 7.1 (subset) CIS Controls 7.2 (subset) CIS Controls 7.3 (superset) CIS Controls 7.4 (superset) CIS Controls 7.5 (superset) CIS Controls 7.6 (superset) CIS Controls 7.7 (superset) CIS Controls 7.7 (subset) CIS Controls 16.2 (superset)
3 control enhancements
  • RA-5(2) Update Vulnerabilities to Be Scanned Update the system vulnerabilities to be scanned within 24 hours prior to running a new scan or when new vulnerabilities are identified and reported.
  • RA-5(5) Privileged Access Implement privileged access authorization to information system components containing or processing CJI for vulnerability scanning activities requiring privileged access.
  • RA-5(11) Public Disclosure Program Establish a public reporting channel for receiving reports of vulnerabilities in organizational systems and system components.
ADHICSCIS ControlsCyber EssentialsCyber Essentials PlusDORAISO 27001NCA CCCNCA ECC-2NCA OTCCNIS2NIST CSFPCI DSS 4.0.1Qatar NIASAMA CSFUAE IAGDPR (EU)HIPAA Security RulePDPLData-protection rulesPDPPLPDPL – Federal Decree-Law 45/2021UK GDPR
RA-7
Risk Response
Respond to findings from security and privacy assessments, monitoring, and audits in accordance with organizational risk tolerance.
Official crosswalk CIS Controls 7.3 (superset) CIS Controls 7.4 (superset) CIS Controls 7.7 (superset) CIS Controls 16.2 (superset)
ADHICSCIS ControlsCyber EssentialsCyber Essentials PlusDORAISO 27001NCA CCCNCA ECC-2NCA OTCCNIS2NIST CSFPCI DSS 4.0.1Qatar NIASAMA CSFUAE IA
RA-9
Criticality Analysis
Identify critical system components and functions by performing a criticality analysis for information system components containing or processing CJI at the planning, design, development, testing, implementation, and maintenance stages of the system development life cycle.
SA · System and Services Acquisition 11
SA-1
Policy and Procedures
a. Develop, document, and disseminate to: organizational personnel with system and services acquisition responsibilities; organizational personnel with information security and privacy responsibilities; organizational personnel with supply chain risk management responsibilities: 1. Agency/Entity information systems and services acquisition policy for systems used to process, store, or transmit CJI that: (a) Addresses purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance; and (b) Is consistent with applicable laws, executive orders, directives, regulations, policies, standards, and guidelines; and 2. Procedures to facilitate the implementation of the system and services acquisition policy and the associated system and services acquisition controls; b. Designate organizational personnel with information security responsibilities and organizational personnel with system and services acquisition responsibilities to manage the development, documentation, and dissemination of the system and services acquisition policy and procedures; and c. Review and update the current system and services acquisition: 1. Policy following any security incidents involving unauthorized access to CJI or systems used to process, store, or transmit CJI; and 2. Procedures following any security incidents involving unauthorized access to CJI or systems used to process, store, or transmit CJI.
Official crosswalk CIS Controls 15.2 (superset)
ADHICSCIS ControlsDORAGDPR (EU)HIPAA Security RuleISO 27001NCA ECC-2NCA OTCCNIS2NIST CSFPCI DSS 4.0.1PDPLData-protection rulesPDPPLPDPL – Federal Decree-Law 45/2021Qatar NIASAMA CSFUAE IAUK GDPRNCA CCC
SA-2
Allocation of Resources
a. Determine the high-level information security and privacy requirements for the system or system service in mission and business process planning; b. Determine, document, and allocate the resources required to protect the system or system service as part of the organizational capital planning and investment control process;
Official crosswalk CIS Controls 15.2 (superset)
ADHICSCIS ControlsDORAGDPR (EU)HIPAA Security RuleISO 27001NCA ECC-2NCA OTCCNIS2NIST CSFPCI DSS 4.0.1PDPLData-protection rulesPDPPLPDPL – Federal Decree-Law 45/2021Qatar NIASAMA CSFUAE IAUK GDPRNCA CCC
SA-3
System Development Life Cycle
a. Acquire, develop, and manage the system using an agency documented system development lifecycle process that incorporates information security and privacy considerations; b. Define and document information security and privacy roles and responsibilities throughout the system development life cycle; c. Identify individuals having information security and privacy roles and responsibilities; and d. Integrate the organizational information security and privacy risk management process into system development life cycle activities.
Official crosswalk CIS Controls 16.1 (superset)
ADHICSCIS ControlsGDPR (EU)HIPAA Security RuleISO 27001NCA ECC-2NCA OTCCNIS2NIST CSFPCI DSS 4.0.1Qatar NIASAMA CSFUAE IAUK GDPRCyber EssentialsCyber Essentials PlusDORANCA CCCPDPLData-protection rulesPDPPLPDPL – Federal Decree-Law 45/2021
SA-4
Acquisition Process
Include the following requirements, descriptions, and criteria, explicitly or by reference, using agency defined contract language in the acquisition contract for the system, system component, or system service: a. Security and privacy functional requirements; b. Strength of mechanism requirements; c. Security and privacy assurance requirements; d. Controls needed to satisfy the security and privacy requirements. e. Security and privacy documentation requirements; f. Requirements for protecting security and privacy documentation; g. Description of the system development environment and environment in which the system is intended to operate; h. Allocation of responsibility or identification of parties responsible for information security, privacy, and supply chain risk management; and i. Acceptance criteria.
Official crosswalk CIS Controls 15.4 (equivalent) CIS Controls 15.4 (subset)
4 control enhancements
  • SA-4(1) Functional Properties of Controls Require the developer of the system, system component, or system service to provide a description of the functional properties of the controls to be implemented.
  • SA-4(2) Design and Implementation Information for Controls Require the developer of the system, system component, or system service to provide design and implementation information for the controls that includes: security-relevant external system interfaces; high-level design and a project plan that addresses sufficient detail to permit analysis and testing of the controls.
  • SA-4(9) Functions, Ports, Protocols, and Services in Use Require the developer of the system, system component, or system service to identify the functions, ports, protocols, and services intended for organizational use.
  • SA-4(10) Use of Approved PIV Products Employ only information technology products on the FIPS 201-approved products list for Personal Identity Verification (PIV) capability implemented within organizational systems.
ADHICSCIS ControlsDORAGDPR (EU)HIPAA Security RuleISO 27001NCA CCCNCA ECC-2NCA OTCCNIS2NIST CSFPCI DSS 4.0.1PDPLData-protection rulesPDPPLPDPL – Federal Decree-Law 45/2021Qatar NIASAMA CSFUAE IAUK GDPR
SA-5
System Documentation
a. Obtain or develop administrator documentation for the system, system component, or system service that describes: 1. Secure configuration, installation, and operation of the system, component, or service; 2. Effective use and maintenance of security and privacy functions and mechanisms; and 3. Known vulnerabilities regarding configuration and use of administrative or privileged functions; b. Obtain or develop user documentation for the system, system component, or system service that describes: 1. User-accessible security and privacy functions and mechanisms and how to effectively use those functions and mechanisms; 2. Methods for user interaction, which enables individuals to use the system, component, or service in a more secure manner and protect individual privacy; and 3. User responsibilities in maintaining the security of the system, component, or service and privacy of individuals; c. Document steps to obtain system, system component, or system service documentation when such documentation is either unavailable or nonexistent by contacting manufacturers, suppliers, or developers and conducting web-based searches in response; and d. Distribute documentation to organizational personnel with system and services responsibilities.
SA-8
Security and Privacy Engineering Principles
Apply agency documented systems security and privacy engineering principles in the specification, design, development, implementation, and modification of the system and system components.
Official crosswalk CIS Controls 12.2 (subset)
1 control enhancement
  • SA-8(33) Minimization Implement the privacy principle of minimization using only the Personally Identifiable Information necessary to perform system engineering.
ADHICSCIS ControlsCyber EssentialsCyber Essentials PlusGDPR (EU)HIPAA Security RuleISO 27001NCA ECC-2NCA OTCCNIS2NIST CSFPCI DSS 4.0.1PDPLData-protection rulesPDPPLPDPL – Federal Decree-Law 45/2021Qatar NIASAMA CSFUAE IAUK GDPR
SA-9
External System Services
a. Require that providers of external system services comply with organizational security and privacy requirements and employ system and services acquisition security controls in accordance with the CJISSECPOL including the following agreements when applicable:
Official crosswalk CIS Controls 15.2 (superset)
1 control enhancement
  • SA-9(2) Identification of Functions, Ports, Protocols, and Services Require providers of the following external system services to identify the functions, ports, protocols, and other services required for the use of such services: any system with a local, network, or remote connection to an agency information system.
ADHICSCIS ControlsDORAGDPR (EU)HIPAA Security RuleISO 27001NCA ECC-2NCA OTCCNIS2NIST CSFPCI DSS 4.0.1PDPLData-protection rulesPDPPLPDPL – Federal Decree-Law 45/2021Qatar NIASAMA CSFUAE IAUK GDPRNCA CCC
SA-10
Developer Configuration Management
Require the developer of the system, system component, or system service to: a. Perform configuration management during system, component, or service during design, development, implementation, operation, and disposal; b. Document, manage, and control the integrity of changes to security configuration, network diagrams, and system components (hardware, software, firmware) by implementing access restrictions such as least privilege for changes; c. Implement only organization-approved changes to the system, component, or service; d. Document approved changes to the system, component, or service and the potential security and privacy impacts of such changes; and e. Track security flaws and flaw resolution within the system, component, or service and report findings to the individual(s) with information security responsibilities and an individual(s) with system and services acquisition responsibilities.
Official crosswalk CIS Controls 4.1 (subset)
ADHICSCIS ControlsCyber EssentialsCyber Essentials PlusDORAGDPR (EU)HIPAA Security RuleISO 27001NCA CCCNCA ECC-2NCA OTCCNIS2NIST CSFPCI DSS 4.0.1PDPLData-protection rulesPDPPLPDPL – Federal Decree-Law 45/2021Qatar NIASAMA CSFUAE IAUK GDPR
SA-11
Developer Testing and Evaluation
Require the developer of the system, system component, or system service, at all post-design stages of the system development life cycle, to: a. Develop and implement a plan for ongoing security and privacy control assessments; b. Perform system and regression testing/evaluation at a level of comprehensive testing; c. Produce evidence of the execution of the assessment plan and the results of the testing and evaluation; d. Implement a verifiable flaw remediation process; and e. Correct flaws identified during testing and evaluation.
Official crosswalk CIS Controls 16.12 (superset)
UAE IACIS ControlsNCA ECC-2ADHICSISO 27001NCA CCCPCI DSS 4.0.1Qatar NIASAMA CSF
SA-15
Development Process, Standards, and Tools
a. Require the developer of the system, system component, or system service to follow a documented development process that: 1. Explicitly addresses security and privacy requirements; 2. Identifies the standards and tools used in the development process; 3. Documents the specific tool options and tool configurations used in the development process; and 4. Documents, manages, and ensures the integrity of changes to the process and/or tools used in development; and b. Review the development process, standards, tools, tool options, and tool configurations to determine if the process, standards, tools, tool options and tool configurations selected and employed can satisfy security and privacy requirements during design, development, implementation, operation, and disposal.
Official crosswalk CIS Controls 16.1 (superset) CIS Controls 16.11 (superset)
1 control enhancement
  • SA-15(1) Criticality Analysis Require the developer of the system, system component, or system service to perform a criticality analysis: a. At the following decision points in the system development life cycle: design, development, implementation, and operational; and b. At the following level of rigor: comprehensive testing.
ADHICSCIS ControlsGDPR (EU)HIPAA Security RuleISO 27001NCA ECC-2NCA OTCCNIS2NIST CSFPCI DSS 4.0.1Qatar NIASAMA CSFUAE IAUK GDPRCyber EssentialsCyber Essentials PlusDORANCA CCCPDPLData-protection rulesPDPPLPDPL – Federal Decree-Law 45/2021
SA-22
Unsupported System Components
a. Replace system components when support for the components is no longer available from the developer, vendor, or manufacturer; or b. Provide the following options for alternative sources for continued support for unsupported components: original manufacturer support, or original contracted vendor support.
Official crosswalk CIS Controls 2.2 (superset) CIS Controls 16.11 (superset)
ADHICSCIS ControlsCyber EssentialsCyber Essentials PlusDORAGDPR (EU)HIPAA Security RuleISO 27001NCA CCCNCA ECC-2NCA OTCCNIS2NIST CSFPCI DSS 4.0.1PDPLData-protection rulesPDPPLPDPL – Federal Decree-Law 45/2021Qatar NIASAMA CSFUAE IAUK GDPR
SC · System and Communications Protection 18
SC-1
Policy and Procedures
a. Develop, document, and disseminate to organizational personnel with system and communications protection responsibilities: 1. Agency-level system and communications protection policy that: (a) Addresses purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance; and (b) Is consistent with applicable laws, executive orders, directives, regulations, policies, standards, and guidelines; and 2. Procedures to facilitate the implementation of the system and communications protection policy and the associated system and communications protection controls; b. Designate organizational personnel with information security responsibilities to manage the development, documentation, and dissemination of the system and communications protection policy and procedures; and c. Review and update the current system and communications protection: 1. Policy annually and following any changes and security incidents involving unauthorized access to CJI or systems used to process, store, or transmit CJI; and 2. Procedures annually and following any changes and security incidents involving unauthorized access to CJI or systems used to process, store, or transmit CJI.
SC-2
Separation of System and User Functionality
Separate user functionality, including user interface services, from system management functionality.
SC-4
Information in Shared System Resources
Prevent unauthorized and unintended information transfer via shared system resources.
Official crosswalk CIS Controls 3.13 (superset)
ADHICSCIS ControlsGDPR (EU)ISO 27001NCA ECC-2NCA OTCCNIST CSFPCI DSS 4.0.1PDPLData-protection rulesPDPPLQatar NIAPDPL – Federal Decree-Law 45/2021UAE IAUK GDPRNCA CCC
SC-5
Denial-of-service Protection
a. Protect against or limit the effects of the following types of denial-of-service events: distributed denial of service, DNS Denial of Service, etc.; and b. Employ the following controls to achieve the denial-of-service objective: boundary protection devices and intrusion detection or prevention devices.
SC-7
Boundary Protection
a. Monitor and control communications at the external managed interfaces to the system and at key internal managed interfaces within the system; b. Implement subnetworks for publicly accessible system components that are physically or logically separated from internal organizational networks; and c. Connect to external networks or systems only through managed interfaces consisting of boundary protection devices arranged in accordance with an organizational security and privacy architecture.
Official crosswalk CIS Controls 4.4 (superset) CIS Controls 4.5 (superset) CIS Controls 9.3 (superset) CIS Controls 9.5 (superset) CIS Controls 12.2 (subset) CIS Controls 13.4 (superset) CIS Controls 13.5 (superset) CIS Controls 13.10 (subset)
6 control enhancements
  • SC-7(3) Access Points Limit the number of external network connections to the system.
  • SC-7(4) External Telecommunications Services (a) Implement a managed interface for each external telecommunication service; (b) Establish a traffic flow policy for each managed interface; (c) Protect the confidentiality and integrity of the information being transmitted across each interface; (d) Document each exception to the traffic flow policy with a supporting mission or business need and duration of that need; (e) Review exceptions to the traffic flow policy [Assignment: organization-defined frequency] and remove exceptions that are no longer supported by an explicit mission or business need; (f) Prevent unauthorized exchange of control plane traffic with external networks; (g) Publish information to enable remote networks to detect unauthorized control plane traffic from internal networks; and (h) Filter unauthorized control plane traffic from external networks.
  • SC-7(5) Deny by Default — Allow by Exception Deny network communications traffic by default and allow network communications traffic by exception at boundary devices for information systems used to process, store, or transmit CJI.
  • SC-7(7) Split Tunneling for Remote Devices Prevent split tunneling for remote devices connecting to organizational systems.
  • SC-7(8) Route Traffic to Authenticated Proxy Servers Route [Assignment: organization-defined internal communications traffic] to [Assignment: organization-defined external networks] through authenticated proxy servers at managed interfaces.
  • SC-7(24) Personally Identifiable Information For systems that process personally identifiable information: a. Apply the following processing rules to data elements of personally identifiable information: all applicable laws, executive orders, directives, regulations, policies, standards, and guidelines; b. Monitor for permitted processing at the external interfaces to the system and at key internal boundaries within the system; c. Document each processing exception; and d. Review and remove exceptions that are no longer supported.
ADHICSCIS ControlsCyber EssentialsCyber Essentials PlusNCA CCCNCA ECC-2NCA OTCCNIST CSFPCI DSS 4.0.1Qatar NIAUAE IAISO 27001GDPR (EU)HIPAA Security RuleNIS2PDPLData-protection rulesPDPPLPDPL – Federal Decree-Law 45/2021SAMA CSFUK GDPR
SC-8
Transmission Confidentiality and Integrity
Protect the confidentiality and integrity of transmitted information. Metadata derived from unencrypted CJI shall be protected in the same manner as CJI and shall not be used for any advertising or other commercial purposes by any cloud service provider or other associated entity.
Official crosswalk CIS Controls 3.10 (superset)
1 control enhancement
  • SC-8(1) Cryptographic Protection Implement cryptographic mechanisms to prevent unauthorized disclosure and detect unauthorized changes or access to CJI during transmission.
UAE IAADHICSCIS ControlsGDPR (EU)HIPAA Security RuleISO 27001NCA CCCNCA ECC-2NCA OTCCNIS2NIST CSFPCI DSS 4.0.1PDPLData-protection rulesPDPPLPDPL – Federal Decree-Law 45/2021Qatar NIASAMA CSFUK GDPR
SC-10
Network Disconnect
Terminate the network connection associated with a communications session at the end of the session or after one (1) hour of inactivity.
SC-12
Cryptographic Key Establishment and Management
Establish and manage cryptographic keys when cryptography is employed within the system in accordance with the following key management requirements: encryption key generation, distribution, storage, access, and destruction is controlled by the agency.
SC-13
Cryptographic Protection
a. Determine the use of encryption for CJI in-transit when outside a physically secure location; and b. Implement the following types of cryptography required for each specified cryptographic use: cryptographic modules which are Federal Information Processing Standard (FIPS) 140-3 certified, or FIPS validated algorithm for symmetric key encryption and decryption (FIPS 197 [AES]), with a symmetric cipher key of at least 128-bit strength for CJI in-transit.
SC-15
Collaborative Computing Devices and Applications
a. Prohibit remote activation of collaborative computing devices and applications; and b. Provide an explicit indication of use to users physically present at the devices.
SC-17
Public Key Infrastructure Certificates
a. Issue public key certificates under an agency-level certificate authority or obtain public key certificates from an approved service provider; and b. Include only approved trust anchors in trust stores or certificate stores managed by the organization.
SC-18
Mobile Code
a. Define acceptable and unacceptable mobile code and mobile code technologies; and b. Authorize, monitor, and control the use of mobile code within the system.
Official crosswalk CIS Controls 9.4 (superset)
ADHICSCIS ControlsCyber EssentialsCyber Essentials PlusGDPR (EU)HIPAA Security RuleISO 27001NCA ECC-2NCA OTCCNIS2NIST CSFPCI DSS 4.0.1PDPLData-protection rulesPDPPLPDPL – Federal Decree-Law 45/2021Qatar NIASAMA CSFUAE IAUK GDPR
SC-20
Secure Name/address Resolution Service (authoritative Source)
a. Provide additional data origin authentication and integrity verification artifacts along with the authoritative name resolution data the system returns in response to external name/address resolution queries; and b. Provide the means to indicate the security status of child zones and (if the child supports secure resolution services) to enable verification of a chain of trust among parent and child domains, when operating as part of a distributed, hierarchical namespace.
Official crosswalk CIS Controls 4.9 (superset)
ADHICSCIS ControlsCyber EssentialsCyber Essentials PlusDORAGDPR (EU)HIPAA Security RuleISO 27001NCA CCCNCA ECC-2NCA OTCCNIS2NIST CSFPCI DSS 4.0.1PDPLData-protection rulesPDPPLPDPL – Federal Decree-Law 45/2021Qatar NIASAMA CSFUAE IAUK GDPR
SC-21
Secure Name/address Resolution Service (recursive or Caching Resolver)
Request and perform data origin authentication and data integrity verification on the name/address resolution responses the system receives from authoritative sources.
Official crosswalk CIS Controls 4.9 (superset)
ADHICSCIS ControlsCyber EssentialsCyber Essentials PlusDORAGDPR (EU)HIPAA Security RuleISO 27001NCA CCCNCA ECC-2NCA OTCCNIS2NIST CSFPCI DSS 4.0.1PDPLData-protection rulesPDPPLPDPL – Federal Decree-Law 45/2021Qatar NIASAMA CSFUAE IAUK GDPR
SC-22
Architecture and Provisioning for Name/address Resolution Service
Ensure the systems that collectively provide name/address resolution service for an organization are fault-tolerant and implement internal and external role separation.
Official crosswalk CIS Controls 4.9 (superset)
ADHICSCIS ControlsCyber EssentialsCyber Essentials PlusDORAGDPR (EU)HIPAA Security RuleISO 27001NCA CCCNCA ECC-2NCA OTCCNIS2NIST CSFPCI DSS 4.0.1PDPLData-protection rulesPDPPLPDPL – Federal Decree-Law 45/2021Qatar NIASAMA CSFUAE IAUK GDPR
SC-23
Session Authenticity
Protect the authenticity of communications sessions.
Official crosswalk CIS Controls 12.3 (superset) CIS Controls 12.6 (superset)
ADHICSCIS ControlsCyber EssentialsCyber Essentials PlusDORAGDPR (EU)HIPAA Security RuleISO 27001NCA CCCNCA ECC-2NCA OTCCNIS2NIST CSFPCI DSS 4.0.1PDPLData-protection rulesPDPPLPDPL – Federal Decree-Law 45/2021Qatar NIASAMA CSFUAE IAUK GDPR
SC-28
Protection of Information at Rest
Protect the confidentiality and integrity of the following information at rest: CJI when outside physically secure locations using cryptographic modules which are certified FIPS 140-3 with a symmetric cipher key of at least 128-bit strength, or FIPS 197 with a symmetric cipher key of at least 256-bit strength.
Official crosswalk CIS Controls 3.6 (superset) CIS Controls 3.11 (equivalent) CIS Controls 3.11 (subset) CIS Controls 11.3 (superset)
1 control enhancement
  • SC-28(1) Cryptographic Protection Implement cryptographic mechanisms to prevent unauthorized disclosure and modification of the following information at rest on information systems and digital media outside physically secure locations: CJI.
UAE IAADHICSCIS ControlsGDPR (EU)HIPAA Security RuleISO 27001NCA CCCNCA ECC-2NCA OTCCNIS2NIST CSFPCI DSS 4.0.1PDPLData-protection rulesPDPPLPDPL – Federal Decree-Law 45/2021Qatar NIASAMA CSFUK GDPR
SC-39
Process Isolation
Maintain a separate execution domain for each executing system process.
Official crosswalk CIS Controls 4.12 (superset)
ADHICSCIS ControlsCyber EssentialsCyber Essentials PlusDORAGDPR (EU)HIPAA Security RuleISO 27001NCA CCCNCA ECC-2NCA OTCCNIS2NIST CSFPCI DSS 4.0.1PDPLData-protection rulesPDPPLPDPL – Federal Decree-Law 45/2021Qatar NIASAMA CSFUAE IAUK GDPR
SI · System and Information Integrity 11
SI-1
Policy and Procedures
a. Develop, document, and disseminate to all organizational personnel with system and information integrity responsibilities and information system owners: 1. Agency-level system and information integrity policy that: (a) Addresses purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance; and (b) Is consistent with applicable laws, executive orders, directives, regulations, policies, standards, and guidelines; and 2. Procedures to facilitate the implementation of the system and information integrity policy and the associated system and information integrity controls; b. Designate organizational personnel with system and information integrity responsibilities to manage the development, documentation, and dissemination of the system and information integrity policy and procedures; and c. Review and update the current system and information integrity: 1. Policy annually and following any security incidents involving unauthorized access to CJI or systems used to process, store, or transmit CJI; and 2. Procedures annually and following any security incidents involving unauthorized access to CJI or systems used to process, store, or transmit CJI.
SI-2
Flaw Remediation
c. Install security-relevant software and firmware updates within [Assignment: organization-defined time period] of the release of the updates; and
Official crosswalk CIS Controls 7.3 (superset) CIS Controls 7.4 (superset) CIS Controls 7.7 (superset) CIS Controls 16.3 (superset)
1 control enhancement
  • SI-2(2) Automated Flaw Remediation Status Determine if system components have applicable security-relevant software and firmware updates installed using vulnerability scanning tools as least quarterly or following any security incidents involving CJI or systems used to process, store, or transmit CJI.
ADHICSCIS ControlsCyber EssentialsCyber Essentials PlusDORAISO 27001NCA CCCNCA ECC-2NCA OTCCNIS2NIST CSFPCI DSS 4.0.1Qatar NIASAMA CSFUAE IA
SI-3
Malicious Code Protection
2. Block or quarantine malicious code, take mitigating action(s), and when necessary, implement incident response procedures; and send alert to system/network administrators and/or organizational personnel with information security responsibilities in response to malicious code detection; and118F118F118F
Official crosswalk CIS Controls 9.6 (superset) CIS Controls 9.7 (superset) CIS Controls 10.1 (superset) CIS Controls 10.2 (superset) CIS Controls 10.4 (superset) CIS Controls 10.6 (superset)
ADHICSCIS ControlsCyber EssentialsCyber Essentials PlusNCA CCCNCA ECC-2NCA OTCCNIST CSFPCI DSS 4.0.1Qatar NIAUAE IAISO 27001
SI-4
System Monitoring
a. Monitor the system to detect: 2. Unauthorized local, network, and remote connections;
Official crosswalk CIS Controls 1.3 (superset) CIS Controls 1.5 (superset) CIS Controls 10.7 (superset) CIS Controls 13.1 (subset) CIS Controls 13.1 (superset) CIS Controls 13.3 (superset) CIS Controls 13.5 (superset) CIS Controls 13.6 (superset) CIS Controls 13.6 (subset) CIS Controls 13.8 (superset) CIS Controls 13.11 (superset)
3 control enhancements
  • SI-4(2) Automated Tools and Mechanisms for Real-time Analysis Employ automated tools and mechanisms to support near real-time analysis of events.
  • SI-4(4) Inbound and Outbound Communications Traffic a. Determine criteria for unusual or unauthorized activities or conditions for inbound and outbound communications traffic; b. Monitor inbound and outbound communications traffic continuously for unusual or unauthorized activities or conditions such as: the presence of malicious code or unauthorized use of legitimate code or credentials within organizational systems or propagating among system components, signaling to external systems, and the unauthorized exporting of information.
  • SI-4(5) System-generated Alerts Alert organizational personnel with system monitoring responsibilities when the following system-generated indications of compromise or potential compromise occur: inappropriate or unusual activities with security or privacy implications.
ADHICSCIS ControlsCyber EssentialsCyber Essentials PlusDORAGDPR (EU)HIPAA Security RuleISO 27001NCA CCCNCA ECC-2NCA OTCCNIS2NIST CSFPCI DSS 4.0.1PDPLData-protection rulesPDPPLPDPL – Federal Decree-Law 45/2021Qatar NIASAMA CSFUAE IAUK GDPR
SI-5
Security Alerts, Advisories, and Directives
a. Receive system security alerts, advisories, and directives from external source(s) (e.g., CISA, Multi-State Information Sharing & Analysis Center [MS-ISAC], U.S. Computer Emergency Readiness Team [USCERT], hardware/software providers, federal/state advisories, etc.) on an ongoing basis; b. Generate internal security alerts, advisories, and directives as deemed necessary; c. Disseminate security alerts, advisories, and directives to: organizational personnel implementing, operating, maintaining, and using the system; and d. Implement security directives in accordance with established time frames, or notify the issuing organization of the degree of noncompliance.
SI-7
Software, Firmware, and Information Integrity
a. Employ integrity verification tools to detect unauthorized changes to software, firmware, and information systems that contain or process CJI; and b. Take the following actions when unauthorized changes to the software, firmware, and information are detected: notify organizational personnel responsible for software, firmware, and/or information integrity and implement incident response procedures as appropriate.
Official crosswalk CIS Controls 2.7 (subset)
2 control enhancements
  • SI-7(1) Integrity Checks Perform an integrity check of software, firmware, and information systems that contain or process CJI at agency-defined transitional states or security relevant events at least weekly or in an automated fashion.
  • SI-7(7) Integration of Detection and Response Incorporate the detection of the following unauthorized changes into the organizational incident response capability: unauthorized changes to established configuration setting or the unauthorized elevation of system privileges.
ADHICSCIS ControlsCyber EssentialsCyber Essentials PlusGDPR (EU)HIPAA Security RuleISO 27001NCA ECC-2NCA OTCCNIS2NIST CSFPCI DSS 4.0.1PDPLData-protection rulesPDPPLPDPL – Federal Decree-Law 45/2021Qatar NIASAMA CSFUAE IAUK GDPRNCA CCC
SI-8
Spam Protection
a. Employ spam protection mechanisms at system entry and exit points to detect and act on unsolicited messages; and b. Update spam protection mechanisms when new releases are available in accordance with organizational configuration management policy and procedures.
Official crosswalk CIS Controls 9.2 (subset) CIS Controls 9.6 (superset) CIS Controls 9.7 (superset)
1 control enhancement
  • SI-8(2) Automatic updates Automatically update spam protection mechanisms at least daily.
ADHICSCIS ControlsCyber EssentialsCyber Essentials PlusNCA CCCNCA ECC-2NCA OTCCNIST CSFPCI DSS 4.0.1Qatar NIAUAE IAISO 27001
SI-10
Information Input Validation
Check the validity of the following information inputs: all inputs to web/application servers, database servers, and any system or application input that might receive or process CJI.
SI-11
Error Handling
a. Generate error messages that provide information necessary for corrective actions without revealing information that could be exploited; and b. Reveal error messages only to organizational personnel with information security responsibilities.
SI-12
Information Management and Retention
Manage and retain information within the system and information output from the system in accordance with applicable laws, executive orders, directives, regulations, policies, standards, guidelines and operational requirements.
Official crosswalk CIS Controls 3.1 (equivalent) CIS Controls 3.4 (superset) CIS Controls 3.5 (superset)
3 control enhancements
  • SI-12(1) Limit Personally Identifiable Information Elements Limit personally identifiable information being processed in the information life cycle to the minimum PII necessary to achieve the purpose for which it is collected (see Section 4.3).
  • SI-12(2) Minimize Personally Identifiable Information in Testing, Training and Research Use the following techniques to minimize the use of personally identifiable information for research, testing, or training: data obfuscation, randomization, anonymization, or use of synthetic data.
  • SI-12(3) Information Disposal Use the following techniques to dispose of, destroy, or erase information following the retention period: as defined in MP-6.
ADHICSCIS ControlsGDPR (EU)ISO 27001NCA ECC-2NCA OTCCNIST CSFPCI DSS 4.0.1PDPLData-protection rulesPDPPLQatar NIAPDPL – Federal Decree-Law 45/2021UAE IAUK GDPRNCA CCC
SI-16
Memory Protection
Implement the following controls to protect the system memory from unauthorized code execution: data execution prevention and address space layout randomization.
Official crosswalk CIS Controls 10.5 (subset)
ADHICSCIS ControlsCyber EssentialsCyber Essentials PlusISO 27001NCA CCCNCA ECC-2NCA OTCCNIST CSFPCI DSS 4.0.1Qatar NIAUAE IA
SR · Supply Chain Risk Management 6
SR-1
Policy and Procedures
a. Develop, document, and disseminate to organizational personnel with supply chain risk management responsibilities: 1. Agency-level supply chain risk management policy that: a. Addresses purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance; and b. Is consistent with applicable laws, executive orders, directives, regulations, policies, standards, and guidelines; and 2. Procedures to facilitate the implementation of the supply chain risk management policy and the associated supply chain risk management controls; b. Designate organizational personnel with security responsibilities to manage the development, documentation, and dissemination of the supply chain risk management policy and procedures; and c. Review and update the current supply chain risk management: 1. Policy annually and following any security incidents involving unauthorized access to CJI or systems used to process, store, or transmit CJI; and 2. Procedures annually and following any security incidents involving unauthorized access to CJI or systems used to process, store, or transmit CJI.
Official crosswalk CIS Controls 15.2 (superset)
ADHICSCIS ControlsDORAGDPR (EU)HIPAA Security RuleISO 27001NCA ECC-2NCA OTCCNIS2NIST CSFPCI DSS 4.0.1PDPLData-protection rulesPDPPLPDPL – Federal Decree-Law 45/2021Qatar NIASAMA CSFUAE IAUK GDPRNCA CCC
SR-2
Supply Chain Risk Management Plan
a. Develop a plan for managing supply chain risks associated with the research and development, design, manufacturing, acquisition, delivery, integration, operations and maintenance, and disposal of the following systems, system components or system services: systems used to process, store, or transmit CJI; b. Review and update the supply chain risk management plan annually or as required, to address threat, organizational or environmental changes; and c. Protect the supply chain risk management plan from unauthorized disclosure and modification.
Official crosswalk CIS Controls 15.3 (superset)
1 control enhancement
  • SR-2(1) Establish SCRM Team Establish a supply chain risk management team consisting of individuals with security responsibilities and supply chain risk management responsibilities to lead and support the following SCRM activities: information technology, contracting, information security, privacy, mission or business, legal, supply chain and logistics, acquisition, business continuity, and other relevant functions.
ADHICSCIS ControlsDORAGDPR (EU)HIPAA Security RuleISO 27001NCA CCCNCA ECC-2NCA OTCCNIS2NIST CSFPCI DSS 4.0.1PDPLData-protection rulesPDPPLPDPL – Federal Decree-Law 45/2021Qatar NIASAMA CSFUAE IAUK GDPR
SR-5
ACQUISITION STRATEGIES, TOOLS, AND METHODS
Employ the following acquisition strategies, contract tools, and procurement methods to protect against, identify, and mitigate supply chain risks: use preferred suppliers who can provide attestation or demonstration of compliance with state or federal standards.
Official crosswalk CIS Controls 15.5 (superset)
ADHICSCIS ControlsDORAGDPR (EU)HIPAA Security RuleISO 27001NCA CCCNCA ECC-2NCA OTCCNIS2NIST CSFPCI DSS 4.0.1PDPLData-protection rulesPDPPLPDPL – Federal Decree-Law 45/2021Qatar NIASAMA CSFUAE IAUK GDPR
SR-8
Notification Agreements
Establish agreements and procedures with entities involved in the supply chain for the system, system component, or system service for the notification of supply chain compromises to systems used to process, store, or transmit CJI.
Official crosswalk CIS Controls 15.4 (subset)
ADHICSCIS ControlsDORAGDPR (EU)HIPAA Security RuleISO 27001NCA CCCNCA ECC-2NCA OTCCNIS2NIST CSFPCI DSS 4.0.1PDPLData-protection rulesPDPPLPDPL – Federal Decree-Law 45/2021Qatar NIASAMA CSFUAE IAUK GDPR
SR-10
Inspection of Systems or Components
Inspect the following systems or system components upon initial procurement and periodically as needed to detect tampering: systems used to access, process, store, or transmit CJI.
SR-12
COMPONENT DISPOSAL
Dispose of CJI using the techniques and methods as described in Media Protection (MP).
Official crosswalk CIS Controls 15.7 (superset)
ADHICSCIS ControlsDORAGDPR (EU)HIPAA Security RuleISO 27001NCA CCCNCA ECC-2NCA OTCCNIS2NIST CSFPCI DSS 4.0.1PDPLData-protection rulesPDPPLPDPL – Federal Decree-Law 45/2021Qatar NIASAMA CSFUAE IAUK GDPR

Ready to assess against CJIS?

Start free trial →

Where to go next

See it priced

Map CJIS on any plan — active frameworks scale by tier.

Pricing →

Talk to us

Book a walkthrough with someone who knows the platform.

Book a walkthrough →