3.18/22 MAPPED
Access Control
Who and what may reach the system, and what they may do once inside: account authorization, least privilege, remote and wireless pathways, mobile devices, external systems, and public content. The largest family in Rev. 2, and the one where most small-business gaps concentrate.
3.22/3 MAPPED
Awareness and Training
People know the risks their role carries and are trained for their security duties — including recognizing insider-threat indicators. Three requirements, all of which depend on records to demonstrate.
3.33/9 MAPPED
Audit and Accountability
Actions on the system can be reconstructed and attributed: logs exist, are reviewed, are protected from tampering, alert when logging fails, and rest on synchronized clocks.
3.45/9 MAPPED
Configuration Management
Systems are built from known baselines, changed only through review, and stripped to essential functions. Inventory and baseline discipline here is what most other families silently assume.
3.55/11 MAPPED
Identification and Authentication
Every user, process, and device is identified and authenticated before access — with multifactor and replay-resistant authentication for the accounts attackers actually target, and password handling that limits what a stolen credential is worth.
3.63/3 MAPPED
Incident Response
An operational capability to prepare for, detect, analyze, contain, and recover from incidents — tracked, reported to the right officials, and tested rather than merely written down.
3.72/6 MAPPED
Maintenance
System maintenance happens under control: tools and personnel are supervised, equipment leaving for service is sanitized, and nonlocal maintenance sessions authenticate strongly and end when the work does.
3.81/9 MAPPED
Media Protection
CUI on media — paper, drives, removable storage, backups — is stored, marked, transported, sanitized, and destroyed under control, with cryptography where physical safeguards are absent.
3.90/2 MAPPED
Personnel Security
People are screened before receiving access to systems containing CUI, and access is handled deliberately through terminations and transfers.
3.100/6 MAPPED
Physical Protection
Physical access to systems and facilities is limited, monitored, and logged — including visitor control, access devices, and safeguarding CUI at alternate work sites.
3.113/3 MAPPED
Risk Assessment
Risk is assessed periodically, vulnerabilities are scanned for on a cadence and on new disclosures, and remediation follows the risk — not the scanner's default severity order.
3.123/4 MAPPED
Security Assessment
Controls are assessed for effectiveness, deficiencies get plans of action, monitoring is continuous, and the system security plan describing boundaries and implementations stays current. The family where documentation and reality meet.
3.135/16 MAPPED
System and Communications Protection
Communications are monitored and protected at boundaries, networks deny by default, remote sessions are encrypted, cryptography is FIPS-validated where it protects CUI confidentiality, and CUI is protected at rest. The architectural heart of Rev. 2.
3.144/7 MAPPED
System and Information Integrity
Flaws are identified and corrected in a timely manner, malicious code is caught at designated locations, advisories are acted on, and systems are monitored for attack indicators and unauthorized use.
“Mapped” counts requirements with at least one genuine practice relationship. Families with low counts — personnel, physical, media — are not gaps in this site’s analysis: the campaign simply has no practice working that ground, and pretending otherwise would make every other mapping less trustworthy.