← All frameworks

CMMC

110 controls · Level 2, 32 CFR Part 170 (NIST SP 800-171 Rev. 2)

The standard the US Department of Defense holds its suppliers to when they handle Controlled Unclassified Information. Level 2 is all 110 practices. Certification comes from an assessment by an accredited third-party assessor - a C3PAO - so Virtosic can get you ready for one and can never grant it. Whether your contract wants that assessment or a self-assessment you file yourself is set by the clause in the contract, and the phase-in has moved before: read the clause rather than assuming. Either way the 110 practices are the same.

Access Control

AC.L2-3.1.1Authorized Access Control

Only the people, accounts and devices you have approved can reach these systems. Nothing gets in simply because it turned up on the network.

Limit system access to authorised users, to processes acting on behalf of authorised users, and to devices, including other systems.

Applies at level 1.

AC.L2-3.1.2Transaction & Function Control

Having an account is not the same as being able to do everything with it. Each person can only run the actions their job needs.

Limit system access to the types of transactions and functions that authorised users are permitted to execute.

Applies at level 1.

AC.L2-3.1.3Control CUI Flow

You have decided where this information is allowed to travel, and something stops it going somewhere you never approved.

Control the flow of controlled unclassified information within the system and between connected systems, according to approved authorisations.

Applies at level 2.

AC.L2-3.1.4Separation of Duties

No one person can start and finish a sensitive job alone. Splitting the steps means someone acting on their own cannot hide it.

Separate the duties of individuals to reduce the risk of malevolent activity without collusion.

Applies at level 2.

AC.L2-3.1.5Least Privilege

People hold the least access that lets them do their job, and administrator rights go only to those who genuinely need them.

Employ the principle of least privilege, including for specific security functions and for privileged accounts.

Applies at level 2.

AC.L2-3.1.6Non-Privileged Account Use

Your administrators have an ordinary second account for email and everyday work, and save the powerful one for the tasks that need it.

Use non-privileged accounts or roles when accessing functions that are not security functions.

Applies at level 2.

AC.L2-3.1.7Privileged Functions

Ordinary accounts cannot run administrator commands, and when someone does run one it is recorded.

Prevent non-privileged users from executing privileged functions, and capture the execution of such functions in audit logs.

Applies at level 2.

AC.L2-3.1.8Unsuccessful Logon Attempts

After a set number of failed logins the account locks. Guessing passwords should not be something anyone can keep doing all night.

Limit unsuccessful logon attempts.

Applies at level 2.

AC.L2-3.1.9Privacy & Security Notices

People see a notice when they log in saying the system holds protected information and what is expected of them while they are in it.

Provide privacy and security notices consistent with the rules that apply to controlled unclassified information.

Applies at level 2.

AC.L2-3.1.10Session Lock

Screens lock themselves after a few minutes and hide what was on them, so an unattended desk is not an open door.

Use session lock with pattern-hiding displays to prevent access to and viewing of data after a period of inactivity.

Applies at level 2.

AC.L2-3.1.11Session Termination

Sessions end on their own after a set time or condition, rather than staying open until someone remembers to log out.

Terminate a user session automatically after a defined condition.

Applies at level 2.

AC.L2-3.1.12Control Remote Access

You know who is connecting from outside the office, when, and from where, and you could cut a session off if you had to.

Monitor and control remote access sessions.

Applies at level 2.

AC.L2-3.1.13Remote Access Confidentiality

Remote connections are encrypted, so someone sharing the coffee shop network cannot read what is going past.

Employ cryptographic mechanisms to protect the confidentiality of remote access sessions.

Applies at level 2.

AC.L2-3.1.14Remote Access Routing

Remote workers come in through one or two controlled entry points you watch, not through a different door on every server.

Route remote access through managed access control points.

Applies at level 2.

AC.L2-3.1.15Privileged Remote Access

Running administrator commands from outside the office is approved in advance, not something anyone can decide to do on the spot.

Authorise the remote execution of privileged commands and remote access to security-relevant information.

Applies at level 2.

AC.L2-3.1.16Wireless Access Authorization

Wireless networks are approved before they go live, so you know which ones exist rather than discovering one somebody plugged in.

Authorise wireless access before allowing such connections.

Applies at level 2.

AC.L2-3.1.17Wireless Access Protection

Your Wi-Fi asks who you are and encrypts what it carries. An open guest network must not be able to reach the protected systems.

Protect wireless access using authentication and encryption.

Applies at level 2.

AC.L2-3.1.18Mobile Device Connection

You decide which phones and tablets may connect, so an unknown device cannot simply join and start pulling data down.

Control the connection of mobile devices.

Applies at level 2.

AC.L2-3.1.19Encrypt CUI on Mobile

Protected information on phones, tablets and laptops is encrypted, so a device left in a taxi stays a lost device rather than a breach.

Encrypt controlled unclassified information held on mobile devices and mobile computing platforms.

Applies at level 2.

AC.L2-3.1.20External Connections

You know which outside services and personal machines can reach your systems, and you have set limits on what they are allowed to do.

Verify and control or limit connections to, and use of, external systems.

Applies at level 1.

AC.L2-3.1.21Portable Storage Use

Your USB sticks and drives are not for plugging into machines you do not control, and your team knows that is the rule.

Limit the use of portable storage devices on external systems.

Applies at level 2.

AC.L2-3.1.22Control Public Information

Someone checks what goes onto your website and social accounts, so protected information never gets published by accident.

Control controlled unclassified information posted on, or processed by, publicly accessible systems.

Applies at level 1.

Awareness and Training

AT.L2-3.2.1Role-Based Risk Awareness

Everyone who touches these systems knows the risks their own work carries and where to find the rules that apply to them.

Ensure that managers, system administrators and users of organisational systems are made aware of the security risks associated with their activities, and of the policies, standards and procedures that apply to those systems.

Applies at level 2.

AT.L2-3.2.2Role-Based Training

People with a security job to do have been trained to do it, rather than handed the task and left to work it out.

Ensure that personnel are trained to carry out the information security duties and responsibilities assigned to them.

Applies at level 2.

AT.L2-3.2.3Insider Threat Awareness

Your team has been told what a problem from inside can look like, and who to tell, in a way that does not feel like accusing a colleague.

Provide security awareness training on recognising and reporting potential indicators of insider threat.

Applies at level 2.

Audit and Accountability

AU.L2-3.3.1System Auditing

Your systems keep logs detailed enough to work out what happened afterwards, and you keep them long enough to still be useful.

Create and retain system audit logs and records to the extent needed to enable the monitoring, analysis, investigation and reporting of unlawful or unauthorised system activity.

Applies at level 2.

AU.L2-3.3.2User Accountability

Every action traces back to one named person. A shared login makes that impossible, so it does not meet this one.

Ensure that the actions of individual system users can be traced uniquely to those users, so that they can be held accountable for their actions.

Applies at level 2.

AU.L2-3.3.3Event Review

You revisit what you are logging from time to time, so you are still recording the things that would matter now.

Review and update the set of logged events.

Applies at level 2.

AU.L2-3.3.4Audit Failure Alerting

If logging stops, someone finds out. Silent logs look exactly like a quiet week right up until you need them.

Alert in the event of an audit logging process failure.

Applies at level 2.

AU.L2-3.3.5Audit Correlation

You can line up logs from different systems to see one story, instead of checking each one separately and missing the pattern.

Correlate audit record review, analysis and reporting processes for the investigation of, and response to, indications of unlawful, unauthorised, suspicious or unusual activity.

Applies at level 2.

AU.L2-3.3.6Reduction & Reporting

You can search and filter your logs and get a readable report out, rather than scrolling through raw files.

Provide audit record reduction and report generation to support analysis and reporting on demand.

Applies at level 2.

AU.L2-3.3.7Authoritative Time Source

Your machines all take the time from the same trusted source, so timestamps in different logs can be compared and believed.

Provide a system capability that compares and synchronises internal system clocks with an authoritative source, to generate time stamps for audit records.

Applies at level 2.

AU.L2-3.3.8Audit Protection

Logs cannot be quietly edited or wiped, including by the person whose actions they record.

Protect audit information and audit logging tools from unauthorised access, modification and deletion.

Applies at level 2.

AU.L2-3.3.9Audit Management

Only a small, named group can change what is logged or turn logging off at all.

Limit the management of audit logging functionality to a subset of privileged users.

Applies at level 2.

Configuration Management

CM.L2-3.4.1System Baselining

You have a list of every machine and what is installed on it, plus a record of how each one is meant to be set up.

Establish and maintain baseline configurations and inventories of organisational systems, including hardware, software, firmware and documentation, throughout the respective system development life cycles.

Applies at level 2.

CM.L2-3.4.2Security Configuration Enforcement

You have written down the secure settings each type of machine should have, and something checks they stay that way.

Establish and enforce security configuration settings for the information technology products used in organisational systems.

Applies at level 2.

CM.L2-3.4.3System Change Management

Changes to your systems are approved by someone and written down, so you can say what changed and when.

Track, review, approve or disapprove, and log changes to organisational systems.

Applies at level 2.

CM.L2-3.4.4Security Impact Analysis

Before a change goes in, someone asks what it could break or expose, rather than finding out afterwards.

Analyse the security impact of changes before implementing them.

Applies at level 2.

CM.L2-3.4.5Access Restrictions for Change

Only certain people can actually make a change to your systems, and that limit is written down as well as switched on.

Define, document, approve and enforce physical and logical access restrictions associated with changes to organisational systems.

Applies at level 2.

CM.L2-3.4.6Least Functionality

Your machines run only what they need to. Every extra feature left switched on is another way in.

Employ the principle of least functionality by configuring organisational systems to provide only essential capabilities.

Applies at level 2.

CM.L2-3.4.7Nonessential Functionality

Software, ports and services nobody uses are turned off rather than left running quietly in the background.

Restrict, disable or prevent the use of nonessential programs, functions, ports, protocols and services.

Applies at level 2.

CM.L2-3.4.8Application Execution Policy

You have decided which programs may run, and the machine enforces that decision rather than trusting whoever is at the keyboard.

Apply a deny-by-exception policy to prevent the use of unauthorised software, or a deny-all, permit-by-exception policy to allow the execution of authorised software.

Applies at level 2.

CM.L2-3.4.9User-Installed Software

People cannot install whatever they like on a work machine, and you would know if something new appeared.

Control and monitor software installed by users.

Applies at level 2.

Identification and Authentication

IA.L2-3.5.1Identification

Every person, service and device that uses your systems has its own identity, so you can tell one from another.

Identify system users, processes acting on behalf of users, and devices.

Applies at level 1.

IA.L2-3.5.2Authentication

Before anything gets in, your systems check it really is who it claims to be. Claiming a name is not enough on its own.

Authenticate, or verify, the identities of users, processes and devices as a prerequisite to allowing access to organisational systems.

Applies at level 1.

IA.L2-3.5.3Multifactor Authentication

Administrator accounts, and anyone logging in over the network, need a second factor as well as a password.

Use multifactor authentication for local and network access to privileged accounts, and for network access to non-privileged accounts.

Applies at level 2.

IA.L2-3.5.4Replay-Resistant Authentication

Someone who records your login as it crosses the network cannot play it back later to get in as you.

Employ replay-resistant authentication mechanisms for network access to privileged and non-privileged accounts.

Applies at level 2.

IA.L2-3.5.5Identifier Reuse

When someone leaves, their username is not handed to the next new starter, so old records still point at the right person.

Prevent the reuse of identifiers for a defined period.

Applies at level 2.

IA.L2-3.5.6Identifier Handling

Accounts nobody has used for a while are switched off, rather than sitting there waiting for someone to find them.

Disable identifiers after a defined period of inactivity.

Applies at level 2.

IA.L2-3.5.7Password Complexity

Your systems require passwords that are hard to guess, and a new one has to be genuinely different from the old one.

Enforce a minimum password complexity, and a change of characters, when new passwords are created.

Applies at level 2.

IA.L2-3.5.8Password Reuse

People cannot cycle straight back to a password they were using before.

Prohibit password reuse for a specified number of generations.

Applies at level 2.

IA.L2-3.5.9Temporary Passwords

A password handed out for a first login works once, and the person has to set their own straight away.

Allow temporary password use for system logons, with an immediate change to a permanent password.

Applies at level 2.

IA.L2-3.5.10Cryptographically-Protected Passwords

Passwords are never held or sent anywhere in a form somebody could simply read.

Store and transmit only cryptographically protected passwords.

Applies at level 2.

IA.L2-3.5.11Obscure Feedback

Passwords show as dots as they are typed, and a failed login does not reveal whether it was the name or the password that was wrong.

Obscure the feedback of authentication information.

Applies at level 2.

Incident Response

IR.L2-3.6.1Incident Handling

You have a plan for a security incident covering how you spot it, stop it spreading, get back to normal, and what you tell people.

Establish an operational incident-handling capability for organisational systems that includes preparation, detection, analysis, containment, recovery and user response activities.

Applies at level 2.

IR.L2-3.6.2Incident Reporting

You write down what happened in each incident, and you know who outside the company has to be told, including your customer.

Track, document and report incidents to designated officials and authorities, both inside and outside the organisation.

Applies at level 2.

IR.L2-3.6.3Incident Response Testing

You have practised the plan rather than only written it, so the first time you use it is not during a real incident.

Test the organisational incident response capability.

Applies at level 2.

Maintenance

MA.L2-3.7.1Perform Maintenance

Your equipment gets looked after on a schedule, so no machine is quietly running years behind everything else.

Perform maintenance on organisational systems.

Applies at level 2.

MA.L2-3.7.2System Maintenance Control

You control what tools are used to work on your systems, and who is allowed to use them.

Provide controls on the tools, techniques, mechanisms and personnel used to carry out system maintenance.

Applies at level 2.

MA.L2-3.7.3Equipment Sanitization

Before a machine goes off to be repaired, the protected information comes off it first.

Ensure that equipment removed for off-site maintenance is sanitised of any controlled unclassified information.

Applies at level 2.

MA.L2-3.7.4Media Inspection

A repair engineer's USB stick gets scanned before it is allowed to touch your machines.

Check media containing diagnostic and test programs for malicious code before that media is used in organisational systems.

Applies at level 2.

MA.L2-3.7.5Nonlocal Maintenance

Remote support sessions need a second factor to start, and they are closed when the work is done rather than left open.

Require multifactor authentication to establish nonlocal maintenance sessions over external network connections, and terminate those connections when the maintenance is complete.

Applies at level 2.

MA.L2-3.7.6Maintenance Personnel

An engineer who is not cleared for this information is accompanied while they work, not left alone with the machine.

Supervise the maintenance activities of maintenance personnel who do not hold the required access authorisation.

Applies at level 2.

Media Protection

MP.L2-3.8.1Media Protection

Paper files and drives holding protected information are locked away, not left in an open cupboard or on a desk overnight.

Protect system media containing controlled unclassified information, both paper and digital, by physically controlling it and storing it securely.

Applies at level 2.

MP.L2-3.8.2Media Access

Only approved people can get at the drives, discs and printouts holding this information.

Limit access to controlled unclassified information held on system media to authorised users.

Applies at level 2.

MP.L2-3.8.3Media Disposal

Drives, discs and paper are wiped or shredded before they leave your hands. Deleting a file is not the same as wiping a disk.

Sanitise or destroy system media containing controlled unclassified information before disposal or release for reuse.

Applies at level 1.

MP.L2-3.8.4Media Markings

Anything holding protected information is labelled as such, so nobody has to guess how careful to be with it.

Mark media with the markings and distribution limitations required for controlled unclassified information.

Applies at level 2.

MP.L2-3.8.5Media Accountability

When a drive or a box of files leaves the building, you know who has it and it is signed for.

Control access to media containing controlled unclassified information, and maintain accountability for that media while it is transported outside controlled areas.

Applies at level 2.

MP.L2-3.8.6Portable Storage Encryption

Drives carrying protected information out of the building are encrypted, unless they are physically protected some other way.

Implement cryptographic mechanisms to protect the confidentiality of controlled unclassified information stored on digital media during transport, unless it is otherwise protected by alternative physical safeguards.

Applies at level 2.

MP.L2-3.8.7Removable Media

You have decided whether USB sticks and memory cards may be used at all, and your machines enforce that decision.

Control the use of removable media on system components.

Applies at level 2.

MP.L2-3.8.8Shared Media

A USB stick nobody owns does not go into a work machine. Dropped drives are a well-worn way in.

Prohibit the use of portable storage devices that have no identifiable owner.

Applies at level 2.

MP.L2-3.8.9Protect Backups

Your backup copies are protected as carefully as the live systems, wherever those copies are kept.

Protect the confidentiality of backup controlled unclassified information at storage locations.

Applies at level 2.

Personnel Security

PS.L2-3.9.1Screen Individuals

You check people out before giving them access to this information, and you can show what checks you did.

Screen individuals before authorising their access to organisational systems containing controlled unclassified information.

Applies at level 2.

PS.L2-3.9.2Personnel Actions

When someone leaves or moves team, their access changes that day, and the laptop, keys and phone come back.

Ensure that organisational systems containing controlled unclassified information are protected during and after personnel actions such as terminations and transfers.

Applies at level 2.

Physical Protection

PE.L2-3.10.1Limit Physical Access

Only approved people can walk up to the machines holding this information, or into the rooms those machines sit in.

Limit physical access to organisational systems, equipment and the respective operating environments to authorised individuals.

Applies at level 1.

PE.L2-3.10.2Monitor Facility

The building and the things it depends on - power, cabling, cooling - are protected and watched, not just the computers inside it.

Protect and monitor the physical facility and the support infrastructure for organisational systems.

Applies at level 2.

PE.L2-3.10.3Escort Visitors

Visitors are accompanied the whole time they are with you, rather than pointed at a room and left to it.

Escort visitors and monitor visitor activity.

Applies at level 1.

PE.L2-3.10.4Physical Access Logs

You keep a record of who came into the building and when, and you could still produce it months later.

Maintain audit logs of physical access.

Applies at level 1.

PE.L2-3.10.5Manage Physical Access

You know how many keys, fobs and door codes exist and who holds each one, and you get them back when someone leaves.

Control and manage physical access devices.

Applies at level 1.

PE.L2-3.10.6Alternative Work Sites

The rules still apply at somebody's kitchen table. You have said what working from home looks like for this information.

Enforce safeguarding measures for controlled unclassified information at alternate work sites.

Applies at level 2.

Risk Assessment

RA.L2-3.11.1Risk Assessments

You work out on a regular schedule what could go wrong with this information and how badly it would hurt, and you write it down.

Periodically assess the risk to organisational operations, assets and individuals arising from the operation of organisational systems and from the processing, storage or transmission of controlled unclassified information.

Applies at level 2.

RA.L2-3.11.2Vulnerability Scan

You scan your systems for known weaknesses on a schedule, and again when a new one is announced.

Scan for vulnerabilities in organisational systems and applications periodically, and when new vulnerabilities affecting them are identified.

Applies at level 2.

RA.L2-3.11.3Vulnerability Remediation

You fix what the scans find, worst first, rather than filing the report and moving on.

Remediate vulnerabilities, prioritised according to the risk assessments.

Applies at level 2.

Security Assessment

CA.L2-3.12.1Security Control Assessment

You check on a schedule whether each safeguard is actually working, not only whether it exists on paper.

Periodically assess the security controls in organisational systems to determine whether they are effective in their application.

Applies at level 2.

CA.L2-3.12.2Operational Plan of Action

For every gap you have found there is a written plan saying who is fixing it and by when, and you can show it was carried out.

Develop and implement plans of action designed to correct deficiencies and to reduce or eliminate vulnerabilities in organisational systems.

Applies at level 2.

CA.L2-3.12.3Security Control Monitoring

You keep an eye on your safeguards between the formal reviews, so you find out early when one has stopped working.

Monitor security controls on an ongoing basis to ensure that they remain effective.

Applies at level 2.

CA.L2-3.12.4System Security Plan

You have a written plan saying what is in scope, how each requirement is met, and what your systems connect to. An assessor asks for this first.

Develop, document and periodically update system security plans that describe system boundaries, system environments of operation, how the security requirements are implemented, and the relationships with or connections to other systems.

Applies at level 2.

System and Communications Protection

SC.L2-3.13.1Boundary Protection

You watch and control what crosses the edge of your network, and the important dividing lines inside it as well.

Monitor, control and protect communications at the external boundaries and at key internal boundaries of organisational systems.

Applies at level 1.

SC.L2-3.13.2Security Engineering

Security is considered while things are being designed and built, rather than added on at the end.

Employ architectural designs, software development techniques and systems engineering principles that promote effective information security within organisational systems.

Applies at level 2.

SC.L2-3.13.3Role Separation

The tools people use day to day are kept apart from the tools that administer the system.

Separate user functionality from system management functionality.

Applies at level 2.

SC.L2-3.13.4Shared Resource Control

One person's data does not leak to the next user through shared memory, disk space or a cached file.

Prevent unauthorised and unintended transfer of information through shared system resources.

Applies at level 2.

SC.L2-3.13.5Public-Access System Separation

Anything the public can reach sits on its own separate part of the network, not alongside your internal systems.

Implement subnetworks for publicly accessible system components that are physically or logically separated from internal networks.

Applies at level 1.

SC.L2-3.13.6Network Communication by Exception

Your firewalls block everything unless it has been specifically allowed, rather than allowing whatever you have not thought to block.

Deny network communications traffic by default and allow network communications traffic by exception.

Applies at level 2.

SC.L2-3.13.7Split Tunneling

A laptop on your remote connection cannot be joined to your systems and the open internet at the same time.

Prevent remote devices from simultaneously establishing a non-remote connection with organisational systems and communicating through some other connection to resources in external networks.

Applies at level 2.

SC.L2-3.13.8Data in Transit

This information is encrypted whenever it travels - in email, in file transfers, and across your own network.

Implement cryptographic mechanisms to prevent unauthorised disclosure of controlled unclassified information during transmission, unless it is otherwise protected by alternative physical safeguards.

Applies at level 2.

SC.L2-3.13.9Connections Termination

Connections close when the work is finished or the line goes quiet, instead of being left open indefinitely.

Terminate network connections associated with communications sessions at the end of those sessions, or after a defined period of inactivity.

Applies at level 2.

SC.L2-3.13.10Key Management

You know where your encryption keys and certificates live, who can use them, and how you would replace one in a hurry.

Establish and manage cryptographic keys for the cryptography used in organisational systems.

Applies at level 2.

SC.L2-3.13.11CUI Encryption

The encryption you rely on is a validated product from the approved list. Home-grown or unvalidated encryption does not count here.

Employ FIPS-validated cryptography when cryptography is used to protect the confidentiality of controlled unclassified information.

Applies at level 2.

SC.L2-3.13.12Collaborative Device Control

Nobody can switch on a camera or microphone remotely without the people in the room being able to see that it is live.

Prohibit the remote activation of collaborative computing devices, and give an indication of devices in use to the users present at the device.

Applies at level 2.

SC.L2-3.13.13Mobile Code

You have decided which active content - scripts, plug-ins, macros - is allowed to run, and the rest is blocked.

Control and monitor the use of mobile code.

Applies at level 2.

SC.L2-3.13.14Voice over Internet Protocol

Your internet phone system is set up deliberately and watched, rather than being one more thing somebody plugged into the network.

Control and monitor the use of Voice over Internet Protocol technologies.

Applies at level 2.

SC.L2-3.13.15Communications Authenticity

A connection cannot be hijacked halfway through, so what arrives really did come from who you think it did.

Protect the authenticity of communications sessions.

Applies at level 2.

SC.L2-3.13.16Data at Rest

This information is protected while it is just sitting there - on servers, laptops, phones and in cloud storage.

Protect the confidentiality of controlled unclassified information at rest.

Applies at level 2.

System and Information Integrity

SI.L2-3.14.1Flaw Remediation

You install security updates promptly, and you have a way of knowing which machines are still behind.

Identify, report and correct system flaws in a timely manner.

Applies at level 1.

SI.L2-3.14.2Malicious Code Protection

You have decided which points in your systems need malware protection, and it is installed and switched on at each of them.

Provide protection from malicious code at designated locations within organisational systems.

Applies at level 1.

SI.L2-3.14.3Security Alerts & Advisories

Someone reads the security notices for the products you use, and does something about the ones that matter to you.

Monitor system security alerts and advisories, and take action in response.

Applies at level 2.

SI.L2-3.14.4Update Malicious Code Protection

Your malware protection keeps itself up to date, so it still recognises what appeared last week.

Update malicious code protection mechanisms when new releases are available.

Applies at level 1.

SI.L2-3.14.5System & File Scanning

Full scans run on a schedule, and files arriving from outside are checked as they are downloaded or opened.

Perform periodic scans of organisational systems, and real-time scans of files from external sources as those files are downloaded, opened or executed.

Applies at level 1.

SI.L2-3.14.6Monitor Communications for Attacks

You watch the traffic going in and out for signs of an attack, including data heading somewhere it has no business going.

Monitor organisational systems, including inbound and outbound communications traffic, to detect attacks and indicators of potential attacks.

Applies at level 2.

SI.L2-3.14.7Identify Unauthorized Use

You would notice someone using your systems in a way they are not supposed to, including a real account behaving oddly.

Identify unauthorised use of organisational systems.

Applies at level 2.

What this page is

Our own summary of what each control area covers, written to be read by someone without a compliance background. It is not the text of the standard, and it is not a substitute for it - where a framework is a copyrighted document, you will need your own copy. Nothing here is legal advice or an assurance that following it satisfies an auditor.