What's changed
At Drata, we continuously improve our GRC catalog to reflect the latest security best practices. This page provides a centralized overview of recent updates to controls and monitoring tests.
Control Name Revisions
Expand to view Control Name Revisions
Expand to view Control Name Revisions
Code | Previous Name | Current Name | Frameworks | Last Updated |
DCF-3 | Require Encryption of Web-Based Admin Access | Encryption of Web-Based Management Interfaces | CCM, CYBER_ESSENTIALS, FEDRAMP, HIPAA, ISO27001, NIST80053, PCI | 2024-12-03 22:39:18 |
DCF-5 | Code Review Process | Change Review Process | CCM, CIS8, CMMC, DRATA_ESSENTIALS, FEDRAMP, ISO27001, ISO270012022, ISO27701, ISO420012023, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, PCI4, SOC_2 | 2024-12-03 22:39:18 |
DCF-6 | Production Code Changes Restricted | Production Changes Restricted | CCM, CIS8, CMMC, FEDRAMP, ISO27001, ISO270012022, ISO27701, NIST800171, NIST800171R3, NIST80053, NISTCSF2, PCI4, SOC_2 | 2024-12-03 22:39:18 |
DCF-7 | Separate Testing and Production Environments | Separate Environments | CCM, CIS8, CMMC, DORA, FEDRAMP, ISO27001, ISO270012022, ISO27701, NIS2, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, PCI, PCI4, SOC_2 | 2024-12-03 22:39:18 |
DCF-8 | Disclosure Process for Customers | External Communication Channels | CIS8, DORA, DRATA_ESSENTIALS, FEDRAMP, HIPAA, ISO27001, ISO420012023, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, PCI4, SOC_2 | 2024-12-03 22:39:18 |
DCF-9 | Employee Disclosure Process | Internal Communication Channels | CCM, CIS8, DORA, DRATA_ESSENTIALS, FEDRAMP, HIPAA, ISO27001, ISO270012022, ISO27701, ISO420012023, NIST800171R3, NIST80053, NISTCSF2, SOC_2 | 2024-12-03 22:39:18 |
DCF-10 | System Access Control Policy | Access Control Policy | CCM, CCPA, CIS8, CMMC, CYBER_ESSENTIALS, CYBER_ESSENTIALS_32, DORA, DRATA_ESSENTIALS, FEDRAMP, HIPAA, ISO27001, ISO270012022, ISO270172015, ISO270182019, ISO27701, NIS2, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, PCI4, SOC_2 | 2024-12-03 22:39:18 |
DCF-11 | Annual Access Control Review | Periodic Access Reviews | CCM, CIS8, CMMC, CYBER_ESSENTIALS, CYBER_ESSENTIALS_32, DORA, FEDRAMP, HIPAA, ISO27001, ISO270012022, ISO270172015, ISO270182019, ISO27701, NIS2, NIST800171, NIST80053, NISTCSF, NISTCSF2, PCI4, SOC_2 | 2024-12-03 22:39:18 |
DCF-12 | Hardening Standards in Place | Baseline Configuration and Hardening Standards | CCM, CIS8, CMMC, CYBER_ESSENTIALS, CYBER_ESSENTIALS_32, DORA, FEDRAMP, FEDRAMP20X, HIPAA, ISO27001, ISO270012022, ISO270172015, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, PCI, PCI4, SOC_2 | 2024-12-03 22:39:18 |
DCF-13 | Information Security Policy | Information Security Policies | CCM, CMMC, DORA, DRATA_ESSENTIALS, FEDRAMP, FEDRAMP20X, GDPR, HIPAA, ISO27001, ISO270012022, ISO270172015, ISO270182019, ISO27701, NIS2, NIST800171, NIST80053, NISTCSF, NISTCSF2, PCI, PCI4, SOC_2 | 2024-12-03 22:39:18 |
DCF-14 | Organizational Chart Maintained | Organizational Chart | CCM, DORA, FEDRAMP, ISO27001, ISO270012022, ISO270172015, ISO27701, ISO420012023, NIST80053, NISTCSF, NISTCSF2, SOC_2 | 2024-12-03 22:39:18 |
DCF-16 | Annual Risk Assessment | Periodic Risk Assessment | CCM, CMMC, DORA, FEDRAMP, HIPAA, ISO27001, ISO270012022, ISO27701, ISO420012023, NIS2, NIST800171, NIST80053, NISTCSF, NISTCSF2, PCI, SOC_2 | 2024-12-03 22:39:18 |
DCF-17 | Remediation Plan | Risk Treatment Plan | CCM, CCPA, CIS8, CMMC, DORA, FEDRAMP, HIPAA, ISO27001, ISO270012022, ISO27701, ISO420012023, NIST800171, NIST80053, NISTCSF, NISTCSF2, SOC_2 | 2024-12-03 22:39:18 |
DCF-18 | Quarterly Vulnerability Scan | Vulnerability Scans | CCM, CCPA, CIS8, CMMC, CYBER_ESSENTIALS, CYBER_ESSENTIALS_32, DORA, DRATA_ESSENTIALS, FEDRAMP, FEDRAMP20X, GDPR, HIPAA, ISO27001, ISO270012022, ISO27701, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, SOC_2 | 2024-12-03 22:39:18 |
DCF-19 | Annual Penetration Tests | Penetration Tests | CCPA, CIS8, CMMC, CYBER_ESSENTIALS, DORA, DRATA_ESSENTIALS, FEDRAMP, GDPR, HIPAA, ISO27001, ISO270012022, ISO27701, NIS2, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, SOC_2 | 2024-12-03 22:39:18 |
DCF-20 | Maintains Asset Inventory | Asset Inventory | CCM, CCPA, CIS8, CMMC, CYBER_ESSENTIALS, CYBER_ESSENTIALS_32, DORA, DRATA_ESSENTIALS, FEDRAMP, FEDRAMP20X, HIPAA, ISO27001, ISO270012022, ISO270172015, ISO27701, NIS2, NIST800171, NIST800171R3, NIST80053, NISTAI, NISTCSF, NISTCSF2, PCI, PCI4, SOC_2 | 2024-12-03 22:39:18 |
DCF-22 | Network segmentation in place | Network Diagram | CCM, CCPA, CIS8, CMMC, CYBER_ESSENTIALS_32, DORA, HIPAA, ISO27001, ISO270012022, ISO270172015, ISO27701, NIST800171, NIST80053, NISTCSF, NISTCSF2, PCI4, SOC_2 | 2024-12-03 22:39:18 |
DCF-26 | BCP/DR Tests Conducted Annually | BCP/DR Tests | CCM, CCPA, CIS8, DORA, FEDRAMP, FEDRAMP20X, HIPAA, ISO27001, ISO270012022, ISO27701, NIS2, NIST80053, NISTCSF, NISTCSF2, PCI, SOC_2 | 2024-12-03 22:39:18 |
DCF-27 | Multiple Availability Zones | Cloud Resources Availability | CIS8, DORA, DRATA_ESSENTIALS, FEDRAMP, FEDRAMP20X, HIPAA, ISO27001, ISO270012022, ISO27701, NIST80053, NISTCSF2, SOC_2 | 2024-12-03 22:39:18 |
DCF-28 | Follow-Ups Tracked | Security Events Tracked and Evaluated | CCM, CIS8, CMMC, CYBER_ESSENTIALS_32, DORA, FEDRAMP, FEDRAMP20X, HIPAA, ISO27001, ISO270012022, ISO27701, ISO420012023, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, PCI4, SOC_2 | 2024-12-03 22:39:18 |
DCF-30 | Lessons Learned | Incident Response Lessons Learned Documented | CCM, CCPA, CIS8, CMMC, DORA, FEDRAMP, FEDRAMP20X, ISO27001, ISO270012022, ISO27701, NIS2, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, PCI4, SOC_2 | 2024-12-03 22:39:18 |
DCF-31 | Software Development Life Cycle Policy | Software Development Policies | CCM, CCPA, CIS8, CMMC, DORA, DRATA_ESSENTIALS, FEDRAMP, FEDRAMP20X, HIPAA, ISO27001, ISO270012022, ISO270172015, ISO270182019, ISO27701, NIS2, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, PCI, SOC_2 | 2024-12-03 22:39:18 |
DCF-33 | Oversight of Security Controls | Periodic Policy Reviews | CCM, CIS8, DORA, HIPAA, ISO27001, ISO270012022, ISO270172015, ISO27701, ISO420012023, NIS2, NIST800171R3, NISTCSF, NISTCSF2, PCI4, SOC_2 | 2024-12-03 22:39:18 |
DCF-36 | Security Training | Periodic Security Training | CCM, CCPA, CIS8, CMMC, CYBER_ESSENTIALS, DORA, DRATA_ESSENTIALS, FEDRAMP, FEDRAMP20X, HIPAA, ISO27001, ISO270012022, ISO270182019, ISO27701, NIS2, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, PCI, PCI4, SOC_2 | 2024-12-03 22:39:18 |
DCF-38 | Annual Performance Evaluations | Performance Evaluations | ISO27001, NISTCSF, NISTCSF2, SOC_2 | 2024-12-03 22:39:18 |
DCF-42 | Defined Management Roles & Responsibilities | Defined Roles and Responsibilities | CCM, DORA, FEDRAMP, HIPAA, ISO27001, ISO270012022, ISO270172015, ISO27701, ISO420012023, NIS2, NIST80053, NISTCSF, NISTCSF2, PCI4, SOC_2 | 2024-12-03 22:39:18 |
DCF-46 | Formal Recruiting Process | Formal Screening Process | CMMC, DORA, FEDRAMP, ISO27001, ISO270012022, ISO27701, NIST800171, NIST800171R3, NISTCSF, NISTCSF2, PCI, PCI4, SOC_2 | 2024-12-03 22:39:18 |
DCF-48 | Session Lock | Screen Lockout | CCM, CCPA, CIS8, CMMC, CYBER_ESSENTIALS, CYBER_ESSENTIALS_32, DORA, FEDRAMP, HIPAA, ISO27001, ISO270012022, ISO27701, NIST800171, NIST800171R3, NIST80053, NISTCSF, PCI4, SOC_2 | 2024-12-03 22:39:18 |
DCF-50 | Malware Detection Software Installed | Antimalware Software on Devices | CCM, CCPA, CIS8, CMMC, CYBER_ESSENTIALS, CYBER_ESSENTIALS_32, DRATA_ESSENTIALS, FEDRAMP, HIPAA, ISO27001, ISO270012022, ISO27701, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, PCI, PCI4, SOC_2 | 2024-12-03 22:39:18 |
DCF-51 | Security Patches Automatically Applied | Automated Updates on Devices | CCM, CCPA, CIS8, CMMC, CYBER_ESSENTIALS, CYBER_ESSENTIALS_32, DORA, DRATA_ESSENTIALS, FEDRAMP, ISO27001, ISO270012022, ISO27701, NIST800171, NIST800171R3, NIST80053, NISTCSF, PCI, SOC_2 | 2024-12-03 22:39:18 |
DCF-54 | Data is Encrypted at Rest | Encryption at Rest | CCM, CCPA, CIS8, CMMC, DORA, DRATA_ESSENTIALS, FEDRAMP, FEDRAMP20X, GDPR, HIPAA, ISO27001, ISO270012022, ISO27701, NIS2, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, PCI4, SOC_2 | 2025-09-23 3:47:31 |
DCF-55 | SSL/TLS Enforced | Encryption in Transit | CCM, CCPA, CIS8, CMMC, DORA, DRATA_ESSENTIALS, FEDRAMP, FEDRAMP20X, HIPAA, ISO27001, ISO270012022, ISO270182019, ISO27701, NIS2, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, PCI4, SOC_2 | 2024-12-11 14:45:49 |
DCF-56 | Vendor Agreements Maintained | Vendor Register and Agreements | CCM, CCPA, CIS8, CMMC, DORA, DRATA_ESSENTIALS, FEDRAMP, FEDRAMP20X, HIPAA, ISO27001, ISO270012022, ISO270172015, ISO27701, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, PCI4, SOC_2 | 2024-12-03 22:39:18 |
DCF-57 | Vendor Compliance Reports | Vendor Compliance Monitoring | CCM, CCPA, CIS8, CMMC, DORA, FEDRAMP, HIPAA, ISO27001, ISO270012022, ISO270172015, ISO27701, NIS2, NIST800171, NIST800171R3, NIST80053, NISTAI, NISTCSF, NISTCSF2, PCI4, SOC_2 | 2024-12-03 22:39:18 |
DCF-58 | Authentication Protocol | Centralized Authentication and Account Management | CCM, CCPA, CIS8, CMMC, CYBER_ESSENTIALS, CYBER_ESSENTIALS_32, FEDRAMP, HIPAA, ISO27001, ISO270172015, NIS2, NIST800171, NIST800171R3, NIST80053, NISTCSF | 2024-12-03 22:39:18 |
DCF-59 | Role-Based Security Implementation | Privileged Access Restricted | CCM, CCPA, CIS8, CMMC, CYBER_ESSENTIALS, CYBER_ESSENTIALS_32, DORA, FEDRAMP, HIPAA, ISO27001, ISO270012022, ISO270172015, ISO270182019, ISO27701, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, PCI, PCI4, SOC_2 | 2024-12-03 22:39:18 |
DCF-60 | Password Storage | Secure Password Storage | CCM, DORA, HIPAA, ISO27001, NIST800171R3, SOC_2 | 2024-12-03 22:39:18 |
DCF-62 | Inactivity and Browser Exit Logout | Session Termination | CCPA, CIS8, CMMC, DORA, DRATA_ESSENTIALS, FEDRAMP, HIPAA, ISO27001, ISO270012022, ISO27701, NIST800171, NIST800171R3, NIST80053, NISTCSF2, PCI4, SOC_2 | 2024-12-03 22:39:18 |
DCF-63 | Accepting The Terms of Service | Terms of Service | ISO27001, SOC_2 | 2024-12-03 22:39:18 |
DCF-64 | Commitments Explained to Customers | Commitments Communicated to Customers | CCM, HIPAA, ISO27001, NISTCSF, NISTCSF2, SOC_2 | 2024-12-03 22:39:18 |
DCF-65 | Maintains a Privacy Policy | Public Privacy Policy | CCM, CCPA, GDPR, HIPAA, ISO27001, ISO270012022, ISO270182019, ISO27701, NIST80053, NISTCSF, SOC_2 | 2024-12-03 22:39:18 |
DCF-66 | Maintains a Terms of Service | Master Service Agreements | CCM, ISO27001, NISTCSF, SOC_2 | 2024-12-03 22:39:18 |
DCF-67 | MFA on Accounts | Multi-Factor Authentication | CCM, CCPA, CIS8, CMMC, CYBER_ESSENTIALS, CYBER_ESSENTIALS_32, FEDRAMP, FEDRAMP20X, ISO27001, ISO270012022, ISO27701, NIS2, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, PCI4, SOC_2 | 2024-12-03 22:39:18 |
DCF-68 | Password Policy | Password Policy and Configuration | CCM, CCPA, CMMC, CYBER_ESSENTIALS, CYBER_ESSENTIALS_32, DORA, DRATA_ESSENTIALS, FEDRAMP, FEDRAMP20X, HIPAA, ISO27001, ISO270012022, ISO270172015, ISO27701, NIS2, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, PCI, PCI4, SOC_2 | 2024-12-03 22:39:18 |
DCF-69 | System Access Granted | Access Provisioning | CCM, CIS8, CMMC, CYBER_ESSENTIALS, CYBER_ESSENTIALS_32, DORA, FEDRAMP, HIPAA, ISO27001, ISO270012022, ISO270182019, ISO27701, NIS2, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, PCI4, SOC_2 | 2024-12-03 22:39:18 |
DCF-70 | Terminated Employee Access Revoked Within One Business Day | Access Deprovisioning | CCM, CCPA, CIS8, CMMC, CYBER_ESSENTIALS, CYBER_ESSENTIALS_32, DORA, FEDRAMP, HIPAA, ISO27001, ISO270012022, ISO270182019, ISO27701, NIS2, NIST800171, NIST800171R3, NISTCSF, NISTCSF2, PCI, PCI4, SOC_2 | 2024-12-03 22:39:18 |
DCF-71 | Unique Accounts Used | Unique User IDs | CCM, CMMC, CYBER_ESSENTIALS, CYBER_ESSENTIALS_32, DORA, DRATA_ESSENTIALS, FEDRAMP, HIPAA, ISO27001, ISO270012022, ISO270172015, ISO270182019, ISO27701, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, PCI4, SOC_2 | 2024-12-03 22:39:18 |
DCF-72 | Unique SSH | Root Access Control | CCM, FEDRAMP, HIPAA, ISO27001, ISO270012022, NIST80053, SOC_2 | 2024-12-03 22:39:18 |
DCF-73 | Denial of Public SSH | Access to Remote Server Administration Ports Restricted | CCM, CCPA, CIS8, CMMC, CYBER_ESSENTIALS_32, DORA, DRATA_ESSENTIALS, FEDRAMP, HIPAA, ISO27001, ISO270012022, ISO27701, NIST800171, NIST800171R3, NIST80053, SOC_2 | 2024-12-11 14:45:49 |
DCF-74 | Customers Informed of Changes | Communication of System Changes | FEDRAMP, ISO27001, ISO270172015, ISO27701, NIST80053, NISTCSF, SOC_2 | 2024-12-03 22:39:18 |
DCF-75 | Cloud Data Storage Restricted | Restricted Public Access | CCM, DRATA_ESSENTIALS, FEDRAMP, ISO27001, ISO270012022, ISO270172015, NIS2, NIST800171R3, SOC_2 | 2025-01-30 19:06:48 |
DCF-77 | Daily Database Backups | Data Backups | CCM, CCPA, CIS8, CYBER_ESSENTIALS, DORA, DRATA_ESSENTIALS, FEDRAMP, HIPAA, ISO27001, ISO270012022, ISO27701, NIST80053, NISTAI, NISTCSF, NISTCSF2, SOC_2 | 2024-12-03 22:39:18 |
DCF-78 | Storage Buckets are Versioned | Storage Bucket Versioning | CIS8, FEDRAMP, ISO27001, ISO270012022, NIST80053, SOC_2 | 2024-12-03 22:39:18 |
DCF-79 | Logs Centrally Stored | Logging System | CCPA, CIS8, CMMC, DORA, DRATA_ESSENTIALS, FEDRAMP, FEDRAMP20X, HIPAA, ISO27001, ISO270012022, ISO27701, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, SOC_2 | 2024-12-03 22:39:18 |
DCF-85 | Firewalls | Network Security Controls | CCM, CCPA, CIS8, CMMC, CYBER_ESSENTIALS, CYBER_ESSENTIALS_32, DRATA_ESSENTIALS, FEDRAMP, FEDRAMP20X, ISO27001, ISO270012022, ISO27701, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, PCI4, SOC_2 | 2024-12-03 22:39:18 |
DCF-86 | Operational Audit | System Monitoring | CCM, CMMC, DORA, DRATA_ESSENTIALS, FEDRAMP, HIPAA, ISO27001, ISO270012022, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, SOC_2 | 2025-08-17 0:10:54 |
DCF-87 | Logging/Monitoring | Threat Detection System | CCM, CCPA, CIS8, CMMC, DORA, FEDRAMP, HIPAA, ISO27001, ISO270012022, ISO27701, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, SOC_2 | 2024-12-03 22:39:18 |
DCF-90 | Root Infrastructure Account Unused | Root Infrastructure Account Monitored | CYBER_ESSENTIALS_32, DORA, FEDRAMP, ISO270012022, NIST800171R3, NIST80053, SOC_2 | 2024-12-11 14:45:49 |
DCF-91 | Intrusion Detection System in Place | Intrusion Detection/Prevention System | CCM, CCPA, CIS8, CMMC, DORA, FEDRAMP, HIPAA, ISO27001, ISO270012022, ISO27701, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, PCI, PCI4, SOC_2 | 2024-12-03 22:39:18 |
DCF-94 | Physical Security | Physical Security Policy | CCM, CMMC, DORA, FEDRAMP, GDPR, HIPAA, ISO27001, ISO270012022, ISO27701, NIS2, NIST800171, NIST80053, NISTCSF, NISTCSF2, PCI, PCI4, SOC_2 | 2024-12-03 22:39:18 |
DCF-96 | Load Balancer Used | Load Balancer | CCM, DORA, FEDRAMP20X, ISO27001, ISO270012022, ISO270172015, ISO27701, NISTCSF, NISTCSF2, SOC_2 | 2024-12-03 22:39:18 |
DCF-97 | Auto-Scale Configuration | Autoscaling | DORA, FEDRAMP, ISO27001, ISO270012022, ISO270172015, ISO27701, NIST80053, NISTCSF, NISTCSF2, SOC_2 | 2024-12-03 22:39:18 |
DCF-98 | Daily Backup Statuses Monitored | Backup Storage | CCM, CIS8, CYBER_ESSENTIALS, DORA, FEDRAMP, HIPAA, ISO27001, NIS2, NIST80053, NISTCSF, NISTCSF2 | 2024-12-11 14:45:49 |
DCF-99 | Failed Backup Alert and Action | Backup Monitoring | CCM, CIS8, CYBER_ESSENTIALS, DORA, HIPAA, ISO27001, ISO270012022, NISTCSF, NISTCSF2, SOC_2 | 2024-12-11 14:45:49 |
DCF-100 | Backup Integrity and Completeness | Backup Restore Testing | CCM, CCPA, CIS8, CYBER_ESSENTIALS, DORA, FEDRAMP, HIPAA, ISO27001, ISO270012022, ISO27701, NIST80053, NISTCSF, NISTCSF2, SOC_2 | 2024-12-03 22:39:18 |
DCF-102 | Data Classification | Data Classification Policy | CCM, CCPA, CIS8, DORA, FEDRAMP, HIPAA, ISO27001, ISO270012022, ISO270172015, ISO27701, NIS2, NIST80053, NISTCSF, NISTCSF2, SOC_2 | 2024-12-03 22:39:18 |
DCF-104 | Test Data Used in Test Environment | Test Data | CCM, DORA, ISO27001, ISO270012022, ISO27701, NIS2, NISTCSF2, PCI, SOC_2 | 2024-12-03 22:39:18 |
DCF-105 | Employee Non-Disclosure Agreement (NDA) | Personnel Non-Disclosure Agreements (NDA) | CCM, ISO27001, ISO270012022, ISO270182019, ISO27701, NISTCSF2, SOC_2 | 2024-12-03 22:39:17 |
DCF-106 | Clean Desk Policy in Place | Clean Desk and Clear Screen Policies and Procedures | DORA, HIPAA, ISO27001, ISO270012022, ISO27701, PCI4 | 2024-12-03 22:39:17 |
DCF-108 | Storage of Sensitive Data on Paper | Secure Storage Mechanisms | CCM, CCPA, CMMC, DORA, HIPAA, ISO27001, ISO270012022, ISO270182019, ISO27701, NIST800171, NIST800171R3, NISTCSF2, PCI4, SOC_2 | 2024-12-03 22:39:17 |
DCF-110 | Application Edits | Acceptable Input Ranges | CIS8, FEDRAMP, ISO27701, NIST80053, SOC_2 | 2024-12-03 22:39:18 |
DCF-111 | System Edits | Mandatory Fields | CIS8, ISO27701, SOC_2 | 2024-12-03 22:39:17 |
DCF-112 | Provide Notice of Privacy Practices | Notice and Acknowledgement of Privacy Practices | HIPAA, ISO27001, ISO270012022, ISO27701, NIST80053, NISTCSF, SOC_2 | 2024-12-03 22:39:17 |
DCF-115 | Privacy Policy Inclusions | Privacy Policy Content | CCM, CCPA, GDPR, ISO27001, ISO27701, NIST80053, SOC_2 | 2024-12-03 22:39:17 |
DCF-116 | Accept The Privacy Policy | Acknowledge The Privacy Policy | ISO27001, NIST80053 | 2024-12-03 22:39:17 |
DCF-120 | Annual Review of Purposes | Periodic Review of Privacy Policy | CCM, DORA, GDPR, HIPAA, ISO27001, ISO270012022, ISO27701, NIST80053, NISTCSF, SOC_2 | 2024-12-03 22:39:18 |
DCF-122 | Requests for Deletion | Requests for Deletion of PII | NIST80053, SOC_2 | 2024-12-03 22:39:18 |
DCF-123 | Data Destruction Policy | Procedures for Information Disposal | CCM, CCPA, CIS8, DORA, FEDRAMP, HIPAA, ISO27001, ISO270012022, ISO270172015, ISO270182019, ISO27701, NIST80053, NISTCSF, NISTCSF2, SOC_2 | 2024-12-03 22:39:18 |
DCF-126 | Users Can Update their Information | Personal Information Accessible Through System Authentication | CYBER_ESSENTIALS_32, FEDRAMP, HIPAA, ISO27001, ISO270182019, ISO27701, NIS2, NIST80053, SOC_2 | 2024-12-03 22:39:18 |
DCF-127 | Communication to 3rd Parties | Privacy Requirements Communicated to Third parties | CCM, CCPA, HIPAA, ISO27001, NISTCSF, SOC_2 | 2024-12-03 22:39:18 |
DCF-130 | Tracking Breaches of PII | Documentation of Breaches or Unauthorized Disclosures of PII | CCM, FEDRAMP, GDPR, ISO27001, ISO27701, ISO420012023, NISTCSF, SOC_2 | 2024-12-03 22:39:18 |
DCF-135 | Notice of Breach to Affected Users | Notification of Incidents or Breaches | CCM, CCPA, CIS8, CMMC, DORA, FEDRAMP, FEDRAMP20X, GDPR, HIPAA, ISO27001, ISO270012022, ISO270182019, ISO27701, ISO420012023, NIS2, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, SOC_2 | 2024-12-03 22:39:18 |
DCF-136 | Privacy Policy Includes 3rd Party Vendors | Use of Subprocessors Communicated | HIPAA, ISO27001, ISO27701, SOC_2 | 2024-12-03 22:39:18 |
DCF-140 | Customer Portal | Point of Contact for Privacy Inquiries | CCPA, HIPAA, ISO27701, NIST80053, NISTCSF2, SOC_2 | 2024-12-03 22:39:18 |
DCF-141 | Customer Inquiries Tracked | Privacy Inquiries Tracked | HIPAA, ISO27701, NIST80053, SOC_2 | 2024-12-03 22:39:18 |
DCF-146 | Board Meetings Conducted | Board Meetings | ISO27701, NISTAI, NISTCSF2, SOC_2 | 2024-09-11 1:28:13 |
DCF-150 | DLP (Data Loss Prevention) Software is Used | Data Loss Prevention (DLP) Mechanisms | CCM, CCPA, CIS8, DORA, FEDRAMP, HIPAA, ISO27001, ISO270012022, NISTCSF, NISTCSF2, PCI4, SOC_2 | 2024-09-11 1:28:13 |
DCF-152 | Virtual Machine OS are Patched Monthly | Automated Security Updates | CIS8, CMMC, CYBER_ESSENTIALS_32, DORA, FEDRAMP, ISO27001, ISO270012022, ISO27701, NIST800171, NIST800171R3, NIST80053, NISTCSF, SOC_2 | 2024-09-05 21:51:55 |
DCF-154 | Annual Incident Response Test | Incident Response Test | CCPA, CIS8, CMMC, DORA, FEDRAMP, FEDRAMP20X, HIPAA, ISO27001, ISO270012022, ISO420012023, NIS2, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, PCI, PCI4, SOC_2 | 2024-09-05 21:51:55 |
DCF-155 | Code Changes are Tested | Testing of Changes | CCM, CIS8, CMMC, DORA, FEDRAMP, ISO27001, ISO270012022, ISO27701, ISO420012023, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, SOC_2 | 2024-05-07 19:18:26 |
DCF-156 | Production Code Released by Appropriate Personnel | Change Releases Approved | CCM, CIS8, CMMC, ISO27001, ISO270012022, ISO420012023, NIST800171, NIST800171R3, PCI4, SOC_2 | 2024-05-07 19:18:26 |
DCF-157 | Cybersecurity Insurance Maintained | Cybersecurity Insurance | NISTCSF2, SOC_2 | 2024-05-07 19:18:26 |
DCF-161 | ISMS Scope | Management System Scope | ISO27001, ISO270012022, ISO27701 | 2024-05-07 19:18:26 |
DCF-163 | Interested Parties and Legal Requirements | Legal Requirements | CCM, DORA, ISO27001, ISO270012022, ISO27701, ISO420012023, NISTAI, NISTCSF, NISTCSF2 | 2024-09-11 1:28:13 |
DCF-164 | ISMS Management Review | Management System Management Review | DORA, ISO27001, ISO270012022, ISO27701 | 2024-05-07 19:18:26 |
DCF-165 | Independent Assessment | Periodic Independent Assessments | CCM, CMMC, DORA, FEDRAMP, ISO27001, ISO270012022, ISO270172015, ISO270182019, ISO27701, ISO420012023, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2 | 2024-09-05 21:51:55 |
DCF-170 | Information Security Objectives | Management System Objectives | DORA, ISO27001, ISO270012022, ISO27701, NISTCSF | 2024-12-03 22:39:18 |
DCF-171 | Operating Procedures | Documented Operating Procedures | CCPA, DORA, FEDRAMP, ISO27001, ISO270012022, ISO27701, NIST800171R3, NIST80053, NISTCSF, PCI4 | 2024-12-03 22:39:18 |
DCF-175 | Communication Plan | Communications Plan | CCM, DORA, ISO27001, ISO270012022, ISO270172015, ISO27701, ISO420012023, NIS2, NISTCSF, NISTCSF2 | 2024-09-11 1:28:13 |
DCF-176 | Monitoring Plan | Measurement and Monitoring Plan | FEDRAMP, ISO27001, ISO270012022, ISO27701, NIST80053, NISTCSF | 2024-05-07 19:18:26 |
DCF-178 | ISMS Record Management and Doc Control | Record Management and Control | ISO27001, ISO270012022, ISO27701 | 2024-07-11 20:02:42 |
DCF-179 | Information Security Skills Matrix | Competence Records | DORA, HIPAA, ISO27001, ISO270012022, ISO27701, ISO420012023 | 2024-05-07 19:18:26 |
DCF-183 | Vulnerability Management | Vulnerability Management Policy | CCM, CCPA, CIS8, CMMC, CYBER_ESSENTIALS, CYBER_ESSENTIALS_32, DORA, DRATA_ESSENTIALS, FEDRAMP, FEDRAMP20X, GDPR, HIPAA, ISO27001, ISO270012022, ISO27701, NIS2, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, PCI, PCI4, SOC_2 | 2024-12-03 22:39:18 |
DCF-184 | Information Security Management System (ISMS) | Management System Plan | DORA, ISO27001, ISO270012022, ISO27701 | 2024-05-07 19:18:26 |
DCF-185 | Periodic Dynamic Threat Assessment | Threat Intelligence | DORA, FEDRAMP, ISO270012022, NIST80053, NISTCSF, NISTCSF2 | 2024-05-07 19:18:26 |
DCF-188 | Communication with Security and Privacy Organizations | Communication with Advisories and Special Interest Groups | CCM, CIS8, CMMC, DORA, FEDRAMP, ISO270012022, ISO27701, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, PCI4 | 2024-05-07 19:18:26 |
DCF-201 | Firewall and Router Configuration Standards | Network Security Controls Configuration Standards | CIS8, CMMC, CYBER_ESSENTIALS, CYBER_ESSENTIALS_32, DORA, NIS2, NIST800171, NIST800171R3, NIST80053, NISTCSF2, PCI, PCI4 | 2024-01-19 0:22:44 |
DCF-206 | Firewall Configuration | Network Security Controls Between Trusted and Untrusted Networks | CCM, CIS8, CMMC, CYBER_ESSENTIALS, CYBER_ESSENTIALS_32, DORA, FEDRAMP, NIST800171, NIST800171R3, NIST80053, PCI, PCI4 | 2024-01-19 0:22:44 |
DCF-210 | Insecure Services, Protocols, and Ports List | Insecure Services, Protocols, and Ports Documentation and Control | CIS8, CYBER_ESSENTIALS_32, DORA, FEDRAMP, NIST80053, PCI, PCI4 | 2024-01-19 0:22:44 |
DCF-212 | Firewall and Router Rule Review | Network Security Controls Review | CIS8, CYBER_ESSENTIALS, DORA, PCI, PCI4 | 2024-01-19 0:22:44 |
DCF-215 | Secured Router Configuration Files | Secured Configuration Files | CMMC, NIST800171, NISTCSF2, PCI, PCI4 | 2024-01-19 0:22:44 |
DCF-216 | Perimeter Firewalls between CDE and Wireless Networks | Network Security Controls Restricting Wireless Network Traffic | CIS8, CMMC, NIST800171, NIST800171R3, PCI, PCI4 | 2024-09-05 21:51:55 |
DCF-218 | DMZ Implemented | Inbound Traffic Restricted Between Untrusted and Trusted Networks | CIS8, CYBER_ESSENTIALS_32, DORA, FEDRAMP, NIS2, NIST80053, PCI, PCI4 | 2024-01-19 0:22:44 |
DCF-223 | Cardholder Data in Internal Network Zone | Sensitive Data Not Directly Accessible From Untrusted Networks | CIS8, CMMC, DORA, NIST800171, NIST800171R3, PCI, PCI4 | 2024-01-19 0:22:44 |
DCF-229 | Default Accounts Changed | Vendor Default Accounts Disabled, Removed or Changed | CCM, CIS8, CYBER_ESSENTIALS, CYBER_ESSENTIALS_32, ISO270012022, ISO27701, NIST800171R3, NIST80053, PCI, PCI4 | 2024-01-19 0:22:44 |
DCF-231 | Changes in Encryption Keys | Changes in Encryption Keys for Wireless Environments | CCM, DORA, NIST80053, PCI, PCI4 | 2024-01-19 0:22:44 |
DCF-233 | Default Passwords on Access Points Changed | Wireless Network Vendor Defaults Changed | CCM, CIS8, DORA, NIST800171R3, PCI, PCI4 | 2024-01-19 0:22:44 |
DCF-239 | One Primary Function per Virtual System Components | One Primary Function per System Component | NIST800171R3, PCI, PCI4 | 2024-01-19 0:22:44 |
DCF-240 | Enable Only Necessary System Function Services | Only Necessary System Function Services Used | CIS8, CMMC, CYBER_ESSENTIALS_32, FEDRAMP, NIST800171, NIST800171R3, NIST80053, NISTCSF2, PCI, PCI4 | 2024-09-05 21:51:55 |
DCF-241 | Justify Enabled Insecure Services | Documentation and Risk Mitigation for Insecure Services | CYBER_ESSENTIALS_32, PCI, PCI4 | 2024-01-19 0:22:44 |
DCF-244 | Common System Security Parameters in Configuration Standards | System Security Parameters in Configuration Standards | CIS8, CMMC, FEDRAMP, NIST800171, NIST800171R3, NIST80053, NISTCSF, PCI, PCI4 | 2024-09-05 21:51:55 |
DCF-253 | Cardholder Data Deleted Securely | Data Secure Disposal | CIS8, ISO270012022, ISO27701, NISTCSF2, PCI, PCI4, SOC_2 | 2024-05-07 19:18:26 |
DCF-255 | Quarterly Cardholder Data Retention Review | Quarterly Cardholder Data Disposal Review | PCI, PCI4 | 2024-01-19 0:22:44 |
DCF-260 | Full Track Contents Not Stored | Full Track Contents Not Retained | PCI, PCI4 | 2025-01-28 20:01:13 |
DCF-261 | Card Verification Code Not Stored | Card Verification Code Not Retained | PCI, PCI4 | 2025-01-28 20:01:13 |
DCF-264 | PAN is Unreadable Anywhere it is Stored | PAN Unreadable Where Stored | PCI, PCI4 | 2024-01-19 0:22:44 |
DCF-267 | Cardholder Data on Removable Media Encrypted | Sensitive Data on Removable Media Encrypted | CIS8, PCI, PCI4 | 2024-01-19 0:22:44 |
DCF-269 | Restricted Key Access | Restricted Cleartext Key Access | PCI, PCI4 | 2024-01-19 0:22:44 |
DCF-270 | Secret and Private Keys Used for Stored Data | Key-Encrypting Keys Secured | DORA, PCI, PCI4 | 2024-01-19 0:22:44 |
DCF-273 | Strong Key Generation Procedure | Strong Key Generation Policies and Procedures | CCM, CMMC, DORA, ISO270012022, ISO27701, NIST800171, NIST800171R3, PCI, PCI4, SOC_2 | 2024-01-19 0:22:44 |
DCF-278 | Replacement of Compromised Keys | Key Retirement Policies and Procedures | CCM, CMMC, DORA, NIS2, NIST800171, NIST800171R3, PCI, PCI4, SOC_2 | 2024-01-19 0:22:44 |
DCF-281 | Unauthorized Key Substitution | Prevention of Unauthorized Key Substitution | DORA, PCI, PCI4 | 2024-01-19 0:22:44 |
DCF-284 | Only Trusted Keys or Certificates Accepted | Key and Certificate Validation | CMMC, DORA, FEDRAMP, ISO270012022, NIST800171, NIST800171R3, NIST80053, PCI, PCI4 | 2024-09-05 21:51:55 |
DCF-289 | PAN Secured in Transmission via End-User Messaging Technologies | Sensitive Data Secured in Transmission via End-User Messaging Technologies | CIS8, DORA, ISO27701, NIS2, PCI, PCI4 | 2024-01-19 0:22:44 |
DCF-291 | Anti-Virus Capability | Anti-Malware on All System Components | CCM, CCPA, CIS8, CMMC, CYBER_ESSENTIALS, CYBER_ESSENTIALS_32, FEDRAMP, ISO27701, NIST800171, NIST800171R3, NIST80053, NISTCSF, PCI, PCI4 | 2024-09-05 21:51:55 |
DCF-293 | Anti-Virus Kept Current | Anti-Malware Capabilities and Automatic Updates | CCPA, CIS8, CMMC, CYBER_ESSENTIALS, CYBER_ESSENTIALS_32, DORA, ISO270012022, NIST800171, NIST800171R3, PCI, PCI4, SOC_2 | 2024-09-05 21:51:55 |
DCF-294 | Anti-Virus Automatic and Periodic Scans | Anti-Malware Tools Behavior | CCM, CIS8, CMMC, CYBER_ESSENTIALS, CYBER_ESSENTIALS_32, ISO270012022, NIST800171, NIST800171R3, NISTCSF, NISTCSF2, PCI, PCI4, SOC_2 | 2024-09-05 21:51:55 |
DCF-296 | Anti-Virus Configuration | Access to Anti-Virus Configuration | CYBER_ESSENTIALS, PCI, PCI4 | 2024-01-19 0:22:44 |
DCF-297 | Critical Patches Installed | Patch Management | CCM, CIS8, CMMC, CYBER_ESSENTIALS_32, DORA, FEDRAMP, NIST800171, NIST800171R3, NIST80053, NISTCSF, PCI, PCI4 | 2024-09-05 21:51:55 |
DCF-305 | Change Control Procedures | Production Components Change Control Procedures | CMMC, FEDRAMP20X, ISO270012022, ISO27701, NIST800171, NIST800171R3, NISTAI, NISTCSF2, PCI, PCI4, SOC_2 | 2024-09-05 21:51:55 |
DCF-310 | PCI Requirements Implemented Upon Completion of Significant Change | PCI Requirements Validation Upon Changes | PCI, PCI4 | 2024-01-19 0:22:44 |
DCF-312 | Annual Training for Developer Secure Coding Techniques | Secure Code Development Training | CCM, CIS8, CMMC, FEDRAMP, ISO270012022, NIS2, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, PCI, PCI4, SOC_2 | 2024-05-07 19:18:26 |
DCF-329 | Access Control System in Place | Access Control System | CCPA, CIS8, CYBER_ESSENTIALS_32, DORA, FEDRAMP20X, NIS2, NIST800171R3, NIST80053, PCI, PCI4 | 2024-09-17 22:20:24 |
DCF-330 | Role-Based Access Control System | Access Control Model | CCM, CCPA, CIS8, CMMC, DORA, FEDRAMP, FEDRAMP20X, ISO27701, NIS2, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, PCI | 2024-07-11 20:02:42 |
DCF-336 | Access Management of Accounts Used by Remote 3rd Parties | Third Party Remote Access Monitored | DORA, FEDRAMP, NIST800171R3, NIST80053, NISTCSF, PCI, PCI4 | 2024-01-19 0:22:44 |
DCF-339 | Non-consumer Customer Password Lockout after Invalid Access Attempts (Service Provider Only) | Account Lockout after Failed Logins | CIS8, CMMC, CYBER_ESSENTIALS_32, NIST800171, NIST800171R3, PCI, PCI4, SOC_2 | 2024-09-05 21:51:55 |
DCF-346 | Minimum Password Requirements | Minimum Strong Password Requirements | CCM, CIS8, CYBER_ESSENTIALS, CYBER_ESSENTIALS_32, PCI, PCI4 | 2025-01-28 20:01:13 |
DCF-348 | Periodic Password Change | Periodic Password Change for In-Scope Components Not In the CDE | PCI, PCI4 | 2024-01-19 0:22:44 |
DCF-349 | Periodic Password Change for Non-consumer Customer (Service Providers Only) | Guidance Provided to Customers for Password Changes | PCI, PCI4 | 2024-01-19 0:22:44 |
DCF-350 | Passwords Different from Last Four | Password History Enforcement | CMMC, CYBER_ESSENTIALS_32, ISO270012022, ISO27701, NIST800171, NIST800171R3, PCI, PCI4, SOC_2 | 2024-09-05 21:51:55 |
DCF-352 | Unique First-time Passwords | Unique First-time Passwords With One-Time Use | CIS8, CMMC, CYBER_ESSENTIALS, CYBER_ESSENTIALS_32, FEDRAMP, ISO270012022, ISO27701, NIST800171, NIST800171R3, PCI, PCI4 | 2024-01-19 0:22:44 |
DCF-354 | MFA for Non-console Access to CDE | MFA for Non-Console Admin Access | CIS8, CYBER_ESSENTIALS_32, NIS2, PCI, PCI4 | 2024-01-19 0:22:44 |
DCF-355 | MFA for Remote Network Access | MFA for Remote Access | CCPA, CIS8, CMMC, CYBER_ESSENTIALS_32, DORA, DRATA_ESSENTIALS, FEDRAMP, FEDRAMP20X, NIS2, NIST800171, NIST800171R3, NIST80053, NISTCSF, PCI, PCI4, SOC_2 | 2024-09-05 21:51:55 |
DCF-356 | Authentication Policy Inclusions | Communication of Authentication Best Practices | CIS8, CYBER_ESSENTIALS_32, FEDRAMP, ISO270012022, ISO27701, NIST80053, PCI, PCI4, SOC_2 | 2024-05-07 19:18:26 |
DCF-358 | Unique Authentication Credential for Service Providers with Remote Access (Service Providers Only) | Unique Authentication Credential for Service Providers with Remote Access | CYBER_ESSENTIALS_32, DORA, PCI, PCI4 | 2024-01-19 0:22:44 |
DCF-360 | Programmatic Methods for Database Access | Direct Query Access Restricted | PCI, PCI4 | 2024-01-19 0:22:44 |
DCF-364 | Physical Access Control to Sensitive Areas | Physical Access Controlled | CCM, CMMC, DORA, FEDRAMP, NIS2, NIST800171, NIST800171R3, NIST80053, NISTCSF, PCI | 2024-09-05 21:51:55 |
DCF-366 | Physical Access Control Mechanism Data Review | Physical Access Control Mechanism Periodic Data Review | CCM, DORA, FEDRAMP, NIS2, NIST800171R3, NIST80053, NISTCSF2, PCI, PCI4 | 2024-09-11 1:28:13 |
DCF-374 | Visitors Preauthorized and Escorted | Visitors Authorized and Escorted | CCM, CMMC, DORA, ISO270012022, ISO27701, NIST800171, NIST800171R3, NISTCSF2, PCI, PCI4, SOC_2 | 2024-09-05 21:51:55 |
DCF-375 | Visitor Badges | Personnel and Visitor Badges | CCM, CMMC, DORA, ISO270012022, ISO27701, NIST800171, NIST800171R3, NISTCSF2, PCI, PCI4, SOC_2 | 2024-01-19 0:22:44 |
DCF-378 | Visitor Log to Facility and Data Storage Areas | Visitor Log | CCM, CMMC, DORA, FEDRAMP, ISO270012022, ISO27701, NIST800171, NIST80053, NISTCSF2, PCI, PCI4, SOC_2 | 2024-09-05 21:51:55 |
DCF-382 | Security Review of Media Backup Storage Location | Security of Offline Media Backup Storage | CMMC, DORA, FEDRAMP, NIST800171, NIST800171R3, NIST80053, PCI, PCI4 | 2024-09-05 21:51:55 |
DCF-385 | Media Transferred Securely | Media Transported Securely | CMMC, DORA, FEDRAMP, ISO270012022, ISO270182019, ISO27701, NIST800171, NIST800171R3, NIST80053, PCI, PCI4 | 2024-07-11 20:02:42 |
DCF-386 | Manager Approval for Media Transfer | Management Approval for Media Transport | CMMC, DORA, ISO270012022, ISO270182019, ISO27701, NIST800171, NIST800171R3, PCI, PCI4 | 2024-07-11 20:02:42 |
DCF-391 | Periodic Media Destruction Policy | Media Destruction Policies and Procedures | CCM, FEDRAMP, NIST80053, NISTCSF, PCI, PCI4 | 2024-01-19 0:22:44 |
DCF-406 | Audit Trails Enabled and Active | Audit Logging | CIS8, CMMC, DORA, FEDRAMP, ISO270012022, NIST800171, NIST800171R3, NIST80053, NISTCSF2, PCI, PCI4, SOC_2 | 2025-10-06 23:16:27 |
DCF-407 | System Access Linked to Users | Audit Logs Data Points | CIS8, CMMC, ISO270012022, ISO27701, ISO420012023, NIST800171, NIST800171R3, NIST80053, NISTCSF2, PCI, PCI4, SOC_2 | 2025-10-06 23:16:27 |
DCF-409 | Audit Trail for Root Admin Privilege Access | Audit Trail for Privileged Access | CCM, CIS8, CMMC, CYBER_ESSENTIALS_32, DORA, FEDRAMP, ISO270012022, ISO27701, NIST800171, NIST800171R3, NIST80053, PCI, PCI4, SOC_2 | 2024-09-05 21:51:55 |
DCF-410 | Audit Trail Access | Audit Trail Access Logging | CIS8, CMMC, DORA, FEDRAMP, ISO27701, NIST800171, NIST80053, PCI, PCI4 | 2024-07-11 20:02:42 |
DCF-411 | Invalid Logical Access Attempts | Audit Trail for Invalid Access Attempts | CIS8, DORA, FEDRAMP, ISO270012022, NIST800171R3, NIST80053, NISTCSF2, PCI, PCI4, SOC_2 | 2024-01-19 0:22:44 |
DCF-414 | Audit Trail of System-Level Object Creation or Deletion | Audit Trail of System-Level Object Changes | CIS8, DORA, ISO270012022, PCI, PCI4, SOC_2 | 2024-05-07 19:18:26 |
DCF-421 | Critical Clock Synchronization and Update | Clock Synchronization | CCM, CIS8, CMMC, FEDRAMP, ISO270012022, ISO270172015, ISO27701, NIST800171, NIST800171R3, NIST80053, PCI, PCI4 | 2024-01-19 0:22:44 |
DCF-434 | Policy for Critical Systems Daily Log Review | Policies and Procedures for Logging | CIS8, CMMC, DORA, ISO270012022, ISO27701, ISO420012023, NIST800171, NIST800171R3, NIST80053, NISTCSF2, PCI, PCI4 | 2024-09-05 21:51:55 |
DCF-437 | Non-critical System Review Aligned with Risk Management | Periodic Review of Non-Critical Logs | CIS8, DORA, NISTCSF2, PCI, PCI4 | 2024-01-19 0:22:44 |
DCF-438 | Follow-up Procedures on Discovered Anomalies and Exceptions | Follow-up Procedures on Log Review Anomalies and Exceptions | DORA, NISTCSF2, PCI, PCI4 | 2024-01-19 0:22:44 |
DCF-455 | Quarterly Internal Vulnerability Scans | Internal Vulnerability Scans | CIS8, PCI, PCI4 | 2025-04-23 21:45:32 |
DCF-456 | High Risk Vulnerabilities Identified and Resolved | Vulnerabilities Identified and Resolved | CIS8, CMMC, CYBER_ESSENTIALS, CYBER_ESSENTIALS_32, DORA, FEDRAMP20X, ISO27701, NIS2, NIST800171, NIST800171R3, NISTCSF2, PCI, PCI4 | 2024-09-05 21:51:55 |
DCF-457 | Internal Vulnerability Scans by Competent and Independent Party | Independent Internal Vulnerability | PCI | 2025-05-12 19:53:26 |
DCF-458 | Quarterly External Vulnerability Scans | Quarterly External Vulnerability Scans (PCI) | PCI, PCI4 | 2024-01-19 0:22:44 |
DCF-461 | Vulnerability Scans After Significant Change | External Vulnerability Scans After Significant Change | DORA, PCI, PCI4 | 2024-01-19 0:22:44 |
DCF-463 | Vulnerability Rescans by Competent and Independent Party | Internal Vulnerability Scans by Competent and Independent Party | DORA, PCI, PCI4 | 2024-01-19 0:22:44 |
DCF-465 | External Penetration Testing Scope | External Penetration Testing Requirements | CIS8, DORA, NIST80053, NISTCSF, PCI, PCI4 | 2024-01-19 0:22:44 |
DCF-467 | Internal Penetration Testing Scope | Internal Penetration Testing Requirements | CIS8, DORA, NIST80053, NISTCSF, PCI, PCI4 | 2024-01-19 0:22:44 |
DCF-469 | Resolving Vulnerabilities from Pen Testing | Resolving Vulnerabilities from Penetration Testing | CIS8, NIS2, PCI, PCI4 | 2024-01-19 0:22:45 |
DCF-470 | Penetration Testing on All Segments | Periodic Penetration Testing on Segmentation Controls | PCI, PCI4 | 2024-01-19 0:22:45 |
DCF-473 | Periodic Segmentation Control Penetration Testing (Service Providers Only) | Periodic Segmentation Control Penetration Testing | PCI, PCI4 | 2024-01-19 0:22:45 |
DCF-478 | Change Detection Mechanism in Place | Change Detection Mechanism | CCM, CMMC, DORA, FEDRAMP, ISO270012022, ISO270172015, ISO27701, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, PCI, PCI4, SOC_2 | 2024-12-11 14:45:49 |
DCF-479 | Change Detection Mechanism Alerts | Periodic Critical File Comparisons | DORA, NIST80053, NISTCSF, PCI, PCI4 | 2024-01-19 0:22:45 |
DCF-482 | Explicit Approval for Technology Use | Acceptable Use Policy for End-User Technologies | CCM, CYBER_ESSENTIALS_32, DORA, FEDRAMP, PCI, PCI4 | 2024-01-19 0:22:45 |
DCF-488 | Automatic Disconnect of Inactive Remote-Access | Network Connection Termination | CMMC, DORA, FEDRAMP, NIS2, NIST800171, NIST800171R3, NIST80053, PCI | 2024-09-05 21:51:55 |
DCF-493 | PCI DSS Compliance Program (Service Providers Only) | PCI DSS Compliance Program Charter | PCI, PCI4 | 2024-01-19 0:22:45 |
DCF-499 | Designated Entity to Maintain Incident Response Procedures | Incident Response Plan (PCI) | CCM, ISO270172015, PCI, PCI4 | 2024-01-19 0:22:45 |
DCF-507 | Pre-Agreement Process for Service Providers | Vendor Due Diligence | CIS8, CMMC, DORA, FEDRAMP20X, ISO270012022, ISO27701, NIS2, NIST800171, NISTCSF2, PCI, PCI4, SOC_2 | 2024-09-05 21:51:55 |
DCF-509 | Specified PCI DSS Responsibilities of Service Providers | Documented PCI DSS Responsibilities of Service Providers | PCI, PCI4 | 2024-01-19 0:22:45 |
DCF-510 | Service Providers Acknowledge Security Responsibilities (Service Providers Only) | Service Providers Acknowledge Security Responsibilities | CIS8, DORA, PCI, PCI4 | 2024-01-19 0:22:45 |
DCF-516 | Security Breach Response Training | Incident Response Training | CCM, CMMC, DORA, NIS2, NIST800171, NIST800171R3, NIST80053, NISTCSF2, PCI, PCI4 | 2024-09-05 21:51:55 |
DCF-517 | Security Monitoring System Alerts | Monitoring Procedures for System Alerts | CCM, DORA, NIST80053, NISTCSF, PCI, PCI4 | 2024-01-19 0:22:45 |
DCF-519 | Incident Response Review Inclusions (Service Providers Only) | PCI DSS Compliance Periodic Reviews | CCM, PCI, PCI4 | 2024-01-19 0:22:45 |
DCF-521 | Quarterly Incident Response Plan Review Report (Service Providers Only) | PCI DSS Compliance Periodic Reviews Documentation | PCI, PCI4 | 2024-01-19 0:22:45 |
DCF-534 | Communication of Obligations to Data Subjects | Communication to Data Subjects | CCPA, GDPR, ISO27701 | 2024-07-11 20:02:42 |
DCF-537 | Data Processing Agreements in Place | Data Processing Agreements | CCPA, GDPR, ISO270182019, ISO27701, NIST80053, SOC_2 | 2024-05-07 19:18:26 |
DCF-540 | Tracking and Response to Data Subject Requests | Timely Response to Data Subject Requests or Inquiries | CCM, CCPA, GDPR, ISO27701, NIST80053, SOC_2 | 2024-05-07 19:18:26 |
DCF-541 | Management of Data Subject Rights | Procedures for Management of Data Subject Rights | CCM, CCPA, GDPR, ISO27701, SOC_2 | 2024-05-07 19:18:26 |
DCF-545 | Personal Data Management Policy | Policies for PII Management | CCPA, ISO27701 | 2024-07-11 20:02:42 |
DCF-558 | Allow-by-Exception Rule for Authorized Applications | Restrictions on Software Installation and Execution | CIS8, CMMC, CYBER_ESSENTIALS, CYBER_ESSENTIALS_32, FEDRAMP, ISO270012022, ISO27701, NIST800171, NIST800171R3, NIST80053, NISTCSF2, SOC_2 | 2024-09-05 21:51:55 |
DCF-562 | Procedures for Utility Program Use | Management of Utility Programs | CMMC, ISO270012022, ISO270172015, ISO27701, NIST800171, NIST800171R3, PCI4, SOC_2 | 2024-05-07 19:18:26 |
DCF-566 | Register of Non-conformities | Management of Nonconformities | CCM, CIS8, CMMC, DORA, ISO270012022, ISO27701, NIS2, NIST800171, NIST800171R3, NISTCSF2 | 2024-05-07 19:18:26 |
DCF-614 | Automated Maintenance Activities | Automated Maintenance Mechanisms | CMMC, FEDRAMP, NIST800171, NIST80053 | 2024-09-05 21:51:55 |
DCF-615 | Managed Use of Maintenance Tools | Approved Use of Maintenance Tools | CMMC, FEDRAMP, NIST800171, NIST80053, NISTCSF | 2024-09-05 21:51:55 |
DCF-635 | Approved PIV Products | Approved Sensitive Information Products | FEDRAMP, NIST80053 | 2023-02-02 18:20:03 |
DCF-643 | Remote Activation of Collaborative Devices Prohibited | Collaborative Computing Devices and Applications | CMMC, FEDRAMP, NIST800171, NIST800171R3, NIST80053 | 2024-09-05 21:51:55 |
DCF-677 | Software Updates Installed | Software Update and Patch Management | CIS8, CMMC, CYBER_ESSENTIALS, CYBER_ESSENTIALS_32, DORA, FEDRAMP20X, ISO27701, NIST800171, NISTCSF2, SOC_2 | 2024-05-07 19:18:26 |
DCF-678 | Global Network Firewall Policy | Network Security Policy | CMMC, CYBER_ESSENTIALS, CYBER_ESSENTIALS_32, DORA, ISO270012022, ISO27701, NIS2, NIST800171, NISTCSF2 | 2024-05-07 19:18:26 |
Control Description Revisions
Expand to view Control Description Revisions
Expand to view Control Description Revisions
Code | Previous Description | Current Description | Frameworks | Last Updated |
DCF-3 | %s uses encryption to protect user authentication and admin sessions of the internal admin tool transmitted over the Internet. | Administrator access to web-based management interfaces is encrypted with strong cryptographic algorithms. | CCM, CYBER_ESSENTIALS, FEDRAMP, HIPAA, ISO27001, NIST80053, PCI | 2024-12-03 22:39:18 |
DCF-4 | %s uses a version control system to manage source code, documentation, release labeling, and other change management tasks. Access to the system must be approved by a system admin. | %s uses a version control system to manage source code, change documentation and tracking, release labeling, and other change management tasks. Access to the version control system is restricted to authorized personnel. | CCM, CIS8, CMMC, FEDRAMP, FEDRAMP20X, ISO27001, ISO270012022, ISO270172015, ISO27701, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, SOC_2 | 2024-12-03 22:39:18 |
DCF-5 | When %s's application code changes, code reviews and tests are performed by someone other than the person who made the code change. | Changes are peer-reviewed and approved prior to deployment by an individual different from the developer to maintain segregation of duties. Review requirements are enforced through automated mechanisms such as branch protection settings in the production code repository. | CCM, CIS8, CMMC, DRATA_ESSENTIALS, FEDRAMP, ISO27001, ISO270012022, ISO27701, ISO420012023, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, PCI4, SOC_2 | 2024-12-03 22:39:18 |
DCF-6 | Only authorized %s personnel can push or make changes to production code. | Access to make changes in production environments is restricted to authorized personnel in accordance with segregation of duties principles and the company's documented policies and procedures. | CCM, CIS8, CMMC, FEDRAMP, ISO27001, ISO270012022, ISO27701, NIST800171, NIST800171R3, NIST80053, NISTCSF2, PCI4, SOC_2 | 2024-12-03 22:39:18 |
DCF-7 | Separate environments are used for testing and production for %s's application | Pre-production environments (e.g., development, testing, etc.) are separated from production environments and the separation is enforced with access controls. | CCM, CIS8, CMMC, DORA, FEDRAMP, ISO27001, ISO270012022, ISO27701, NIS2, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, PCI, PCI4, SOC_2 | 2024-12-03 22:39:18 |
DCF-8 | %s provides a process to external users for reporting security, confidentiality, integrity, and availability failures, incidents, concerns, and other complaints. | %s provides external communication mechanisms for customers and third parties (e.g., communication features, support portal, external ticketing system, etc.) to report complaints, failures, bugs, incidents, vulnerabilities, requests for information, etc. Customer communications are responded to within defined SLAs. | CIS8, DORA, DRATA_ESSENTIALS, FEDRAMP, HIPAA, ISO27001, ISO420012023, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, PCI4, SOC_2 | 2024-12-03 22:39:18 |
DCF-9 | %s provides a process to employees for reporting security, confidentiality, integrity, and availability features, incidents, and concerns, and other complaints to company management. | Internal communication channels are in place for employees to report failures, events, incidents, policy violations, concerns, and other issues to company management, including anonymous reporting channels if applicable. | CCM, CIS8, DORA, DRATA_ESSENTIALS, FEDRAMP, HIPAA, ISO27001, ISO270012022, ISO27701, ISO420012023, NIST800171R3, NIST80053, NISTCSF2, SOC_2 | 2024-12-03 22:39:18 |
DCF-10 | %s has a defined System Access Control Policy that requires annual access control reviews to be conducted and access request forms be filled out for new hires and employee transfers. | %s has developed and documented a policy that outlines requirements for access control. | CCM, CCPA, CIS8, CMMC, CYBER_ESSENTIALS, CYBER_ESSENTIALS_32, DORA, DRATA_ESSENTIALS, FEDRAMP, HIPAA, ISO27001, ISO270012022, ISO270172015, ISO270182019, ISO27701, NIS2, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, PCI4, SOC_2 | 2024-12-03 22:39:18 |
DCF-11 | %s performs annual access control reviews. | Management performs user access reviews periodically (as defined by policy and compliance requirements) to validate user accounts, including third party or vendor accounts, and their associated privileges remain appropriate. The review includes validation of logical and physical access as necessary. Changes resulting from the review, if any, are documented and implemented. | CCM, CIS8, CMMC, CYBER_ESSENTIALS, CYBER_ESSENTIALS_32, DORA, FEDRAMP, HIPAA, ISO27001, ISO270012022, ISO270172015, ISO270182019, ISO27701, NIS2, NIST800171, NIST80053, NISTCSF, NISTCSF2, PCI4, SOC_2 | 2024-12-03 22:39:18 |
DCF-12 | Hardening standards are in place to ensure that newly deployed server instances are appropriately secured. | %s has identified and documented baseline security configuration standards for all system components in accordance with industry-accepted hardening standards or vendor recommendations. These standards are reviewed periodically and updated as needed (e.g., when vulnerabilities are identified) and verified to be in place before or immediately after a production system component is installed or modified (e.g., through infrastructure as code, configuration checklists, etc.). | CCM, CIS8, CMMC, CYBER_ESSENTIALS, CYBER_ESSENTIALS_32, DORA, FEDRAMP, FEDRAMP20X, HIPAA, ISO27001, ISO270012022, ISO270172015, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, PCI, PCI4, SOC_2 | 2024-12-03 22:39:18 |
DCF-13 | %s has a defined Information Security Policy that covers policies and procedures to support the functioning of internal control. | %s has defined and documented an information security policy and other topic-specific policies as needed to support the functioning of internal control. | CCM, CMMC, DORA, DRATA_ESSENTIALS, FEDRAMP, FEDRAMP20X, GDPR, HIPAA, ISO27001, ISO270012022, ISO270172015, ISO270182019, ISO27701, NIS2, NIST800171, NIST80053, NISTCSF, NISTCSF2, PCI, PCI4, SOC_2 | 2024-12-03 22:39:18 |
DCF-14 | %s reviews its organizational structure, reporting lines, authorities, and responsibilities in terms of information security on an annual basis. | An organizational chart is in place to describe the organizational structure and reporting lines. The chart is available to all employees (e.g., through the company's HRMS, intranets, etc.) and is updated upon changes to the organizational structure. | CCM, DORA, FEDRAMP, ISO27001, ISO270012022, ISO270172015, ISO27701, ISO420012023, NIST80053, NISTCSF, NISTCSF2, SOC_2 | 2024-12-03 22:39:18 |
DCF-15 | %s has defined a formal risk management process that specifies risk tolerances and the process for evaluating risks based on identified threats and the specified tolerances. | %s has defined and documented a process for risk assessment and risk management that outlines the organization's approach for identifying risks and assigning risk owners, the risk acceptance criteria, and the approach for evaluating and treating risks based on the defined criteria. | CCM, CIS8, CMMC, DORA, FEDRAMP, GDPR, HIPAA, ISO27001, ISO270012022, ISO27701, ISO420012023, NIS2, NIST800171, NIST80053, NISTAI, NISTCSF, NISTCSF2, PCI, SOC_2 | 2024-12-03 22:39:18 |
DCF-16 | %s conducts a Risk Assessment at least annually. | %s conducts risks assessments periodically as required by company policy and compliance requirements. The risk assessment includes consideration of threats and vulnerabilities and an evaluation of the likelihood and impact for each risk. A risk owner is assigned to each risk, and every risk is assigned a risk treatment option. Results of the risk assessment are documented (e.g., in a risk register). | CCM, CMMC, DORA, FEDRAMP, HIPAA, ISO27001, ISO270012022, ISO27701, ISO420012023, NIS2, NIST800171, NIST80053, NISTCSF, NISTCSF2, PCI, SOC_2 | 2024-12-03 22:39:18 |
DCF-17 | %s's Management prepares a remediation plan to formally manage the resolution of findings identified in risk assessment activities. | %s's management has documented a risk treatment plan to formally manage risks identified in risk assessment activities. | CCM, CCPA, CIS8, CMMC, DORA, FEDRAMP, HIPAA, ISO27001, ISO270012022, ISO27701, ISO420012023, NIST800171, NIST80053, NISTCSF, NISTCSF2, SOC_2 | 2024-12-03 22:39:18 |
DCF-18 | %s engages with third-party to conduct vulnerability scans of the production environment at least quarterly. Results are reviewed by management and high priority findings are tracked to resolution. | %s conducts vulnerability scans of the production environment as dictated by company policy and compliance requirements. Results are reviewed by company personnel and vulnerabilities are tracked to resolution in accordance with company policies. | CCM, CCPA, CIS8, CMMC, CYBER_ESSENTIALS, CYBER_ESSENTIALS_32, DORA, DRATA_ESSENTIALS, FEDRAMP, FEDRAMP20X, GDPR, HIPAA, ISO27001, ISO270012022, ISO27701, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, SOC_2 | 2024-12-03 22:39:18 |
DCF-19 | %s engages with third-party to conduct penetration tests of the production environment at least annually. Results are reviewed by management and high priority findings are tracked to resolution. | An external penetration test of production environments is performed by an independent third party periodically or after any significant infrastructure or application changes. Results are reviewed by management and vulnerabilities are tracked to resolution in accordance with company policies. | CCPA, CIS8, CMMC, CYBER_ESSENTIALS, DORA, DRATA_ESSENTIALS, FEDRAMP, GDPR, HIPAA, ISO27001, ISO270012022, ISO27701, NIS2, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, SOC_2 | 2024-12-03 22:39:18 |
DCF-20 | %s maintains an asset register for physical, cloud, and other information assets that includes business description, owner, and other attributes deemed relevant by the organization. | A centralized asset register is maintained for physical, cloud, and other assets that includes descriptive attributes for asset accountability such as owner, description, location, classification, and/or other information based on the type of asset. Processes are in place to maintain an updated inventory through manual reviews (e.g., as a result of new purchases, installations, removals, system changes, etc.) or automated mechanisms. | CCM, CCPA, CIS8, CMMC, CYBER_ESSENTIALS, CYBER_ESSENTIALS_32, DORA, DRATA_ESSENTIALS, FEDRAMP, FEDRAMP20X, HIPAA, ISO27001, ISO270012022, ISO270172015, ISO27701, NIS2, NIST800171, NIST800171R3, NIST80053, NISTAI, NISTCSF, NISTCSF2, PCI, PCI4, SOC_2 | 2024-12-03 22:39:18 |
DCF-21 | %s maintains an accurate architectural diagram to document system boundaries to support the functioning of internal control. | A documented architectural diagram is in place to document system boundaries and support the functioning of internal control. The diagram is reviewed and approved by management at least annually and updated as necessary when there are changes to the environment. | CCM, CCPA, CIS8, DORA, DRATA_ESSENTIALS, FEDRAMP, HIPAA, ISO27001, ISO420012023, NIST80053, NISTCSF, PCI, SOC_2 | 2024-12-03 22:39:18 |
DCF-22 | %s maintains an accurate network diagram that is accessible to the engineering team and is reviewed by management on an annual basis. | A documented network diagram is in place to document system boundaries and connections to external networks. The diagram is reviewed and approved by management at least annually and updated as necessary when there are changes to the environment. | CCM, CCPA, CIS8, CMMC, CYBER_ESSENTIALS_32, DORA, HIPAA, ISO27001, ISO270012022, ISO270172015, ISO27701, NIST800171, NIST80053, NISTCSF, NISTCSF2, PCI4, SOC_2 | 2024-12-03 22:39:18 |
DCF-25 | %s has an established Disaster Recovery Plan that outlines roles and responsibilities and detailed procedures for recovery of systems. | %s has a documented disaster recovery plan that outlines roles, responsibilities and detailed procedures for recovery of systems in the event of a disaster scenario. | CCM, CCPA, CIS8, DORA, DRATA_ESSENTIALS, FEDRAMP, FEDRAMP20X, GDPR, HIPAA, ISO27001, ISO270012022, ISO27701, NIS2, NIST80053, NISTCSF, NISTCSF2, PCI, SOC_2 | 2024-12-03 22:39:18 |
DCF-26 | %s conducts annual BCP/DR tests and documents according to the BCDR Plan. | %s conducts tests of the business continuity/disaster recovery plans at least annually. Results and lessons learned are documented, and updates to the plans are made as necessary. | CCM, CCPA, CIS8, DORA, FEDRAMP, FEDRAMP20X, HIPAA, ISO27001, ISO270012022, ISO27701, NIS2, NIST80053, NISTCSF, NISTCSF2, PCI, SOC_2 | 2024-12-03 22:39:18 |
DCF-27 | %s utilizes multiple availability zones to replicate production data across different zones. | Business-critical cloud resources are deployed in accordance with high availability architecture principles (e.g., replicated across multiple availability zones or regions, configured for high-availability, etc.). | CIS8, DORA, DRATA_ESSENTIALS, FEDRAMP, FEDRAMP20X, HIPAA, ISO27001, ISO270012022, ISO27701, NIST80053, NISTCSF2, SOC_2 | 2024-12-03 22:39:18 |
DCF-28 | %s has implemented an Incident Response Plan that includes creating, prioritizing, assigning, and tracking follow-ups to completion and lending support to Business Continuity/Disaster Recovery. | %s evaluates security events to determine if they constitute an incident. Incidents are assigned a priority, categorized, documented, tracked, escalated, contained, eradicated, communicated, and resolved in accordance with company policies and procedures. | CCM, CIS8, CMMC, CYBER_ESSENTIALS_32, DORA, FEDRAMP, FEDRAMP20X, HIPAA, ISO27001, ISO270012022, ISO27701, ISO420012023, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, PCI4, SOC_2 | 2024-12-03 22:39:18 |
DCF-29 | %s has identified an incident response team that quantifies and monitors incidents involving security, availability, processing integrity, and confidentiality at the company. | %s has identified and documented roles and responsibilities for incident management (e.g., roles and responsibilities for invoking the incident management process, incident leads, incident handlers, communication coordinators, technical advisors, legal advisors, etc.). | CCM, CIS8, DORA, DRATA_ESSENTIALS, FEDRAMP, HIPAA, ISO27001, ISO270012022, ISO420012023, NIS2, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, PCI, SOC_2 | 2024-12-03 22:39:18 |
DCF-30 | %s has implemented an Incident Response Plan that includes documenting “Lessons Learned” and "Root Cause Analysis" after incidents and sharing them with the broader engineering team to support Business Continuity/Disaster Recovery. | %s documents a post-mortem review for identified incidents that includes incident metadata, root-cause analysis, documentation of evidence, summary of containment, eradication, and recovery actions, timelines, incident metrics, evidence of internal and external communications, estimation of impact and scope, and lessons learned, as applicable, in accordance with company policies and procedures. | CCM, CCPA, CIS8, CMMC, DORA, FEDRAMP, FEDRAMP20X, ISO27001, ISO270012022, ISO27701, NIS2, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, PCI4, SOC_2 | 2024-12-03 22:39:18 |
DCF-31 | %s has developed policies and procedures governing the system development life cycle, including documented policies for tracking, testing, approving, and validating changes. | %s has developed policies and procedures governing the system development life cycle, including requirements, design, implementation, testing, and deployment. | CCM, CCPA, CIS8, CMMC, DORA, DRATA_ESSENTIALS, FEDRAMP, FEDRAMP20X, HIPAA, ISO27001, ISO270012022, ISO270172015, ISO270182019, ISO27701, NIS2, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, PCI, SOC_2 | 2024-12-03 22:39:18 |
DCF-32 | %s Management has approved security policies, and all employees accept these procedures when hired. Management also ensures that security policies are accessible to all employees and contractors. | Company policies are accessible to all employees and, as applicable, third parties such as contractors. Personnel are required to acknowledge the information security policy and other topic-specific policies based on their job duties during onboarding and annually thereafter. | CCM, CYBER_ESSENTIALS_32, DORA, FEDRAMP, GDPR, ISO27001, ISO270012022, ISO270172015, ISO27701, NIS2, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, PCI, PCI4, SOC_2 | 2024-12-03 22:39:18 |
DCF-33 | Management reviews security policies on an annual basis. | Management reviews and approves company policies at least annually. Updates to the policies are made as deemed necessary (e.g., based on changes to business objectives, legal or regulatory requirements, organizational risks, etc.). | CCM, CIS8, DORA, HIPAA, ISO27001, ISO270012022, ISO270172015, ISO27701, ISO420012023, NIS2, NIST800171R3, NISTCSF, NISTCSF2, PCI4, SOC_2 | 2024-12-03 22:39:18 |
DCF-36 | %s has established training programs for privacy and information security to help employees understand their obligations and responsibilities to comply with %s's security policies and procedures, including the identification and reporting of incidents. All full-time employees are required to complete the training upon hire and annually thereafter. | %s has established training programs to help personnel gain awareness of information security best practices. Personnel (including employees and contractors as applicable) are required to complete the training during onboarding. Periodic refresher training is provided to personnel at least annually and as deemed necessary (e.g., upon changes in security requirements, policies, regulations, etc.). | CCM, CCPA, CIS8, CMMC, CYBER_ESSENTIALS, DORA, DRATA_ESSENTIALS, FEDRAMP, FEDRAMP20X, HIPAA, ISO27001, ISO270012022, ISO270182019, ISO27701, NIS2, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, PCI, PCI4, SOC_2 | 2024-12-03 22:39:18 |
DCF-37 | %s has policies and procedures in place to establish acceptable use of information assets approved by management, posted on the company wiki, and accessible to all employees. All employees must accept the Acceptable Use Policy upon hire. | %s has a documented acceptable use policy that outlines requirements for personnel's usage of company assets. | CCM, CCPA, CMMC, CYBER_ESSENTIALS, DORA, DRATA_ESSENTIALS, FEDRAMP, HIPAA, ISO27001, ISO270012022, ISO270172015, ISO27701, NIS2, NIST800171, NIST800171R3, NIST80053, PCI, SOC_2 | 2024-12-03 22:39:18 |
DCF-38 | %s evaluates the performance of all employees through a formal, annual performance evaluation. | Management conducts periodic evaluations of performance against established goals and objectives for eligible personnel in accordance with company policies and procedures. | ISO27001, NISTCSF, NISTCSF2, SOC_2 | 2024-12-03 22:39:18 |
DCF-39 | %s's new hires are required to pass a background check as a condition of their employment. | Background checks are conducted on eligible personnel (employees and third parties as deemed necessary by the organization) prior to hire as permitted by local laws. | CCM, CMMC, FEDRAMP, HIPAA, ISO27001, ISO270012022, ISO27701, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, PCI, PCI4, SOC_2 | 2024-12-03 22:39:18 |
DCF-40 | %s requires its contractors to read and accept the Code of Conduct, read and accept the Acceptable Use Policy, and pass a background check. | %s requires its contractors to read and acknowledge the Code of Conduct, read and acknowledge the Acceptable Use Policy, and pass a background check. | CCM, FEDRAMP, HIPAA, ISO27001, NIST80053, NISTCSF | 2024-12-03 22:39:18 |
DCF-41 | Members of the Board of Directors are independent of management. | The board of directors includes members independent from management who are not involved in control operations. | SOC_2 | 2024-12-03 22:39:18 |
DCF-42 | Management has established defined roles and responsibilities to oversee implementation of the information security policy across the organization. | Management has defined and documented roles and responsibilities for implementation and oversight of the risk management and compliance programs (e.g., security, privacy, AI, etc.). | CCM, DORA, FEDRAMP, HIPAA, ISO27001, ISO270012022, ISO270172015, ISO27701, ISO420012023, NIS2, NIST80053, NISTCSF, NISTCSF2, PCI4, SOC_2 | 2024-12-03 22:39:18 |
DCF-44 | %s has a formal Code of Conduct approved by management and accessible to all employees. All employees must accept the Code of Conduct upon hire. | %s maintains a documented code of conduct. Eligible personnel are required to acknowledge %s's code of conduct during onboarding and annually thereafter. | CCM, DORA, DRATA_ESSENTIALS, HIPAA, ISO27001, ISO270012022, ISO27701, NIS2, NISTCSF2, SOC_2 | 2024-12-03 22:39:18 |
DCF-45 | %s has established a Data Protection Policy and requires all employees to accept it upon hire. Management monitors employees' acceptance of the policy. | %s has a documented a policy that outlines the procedures and technical measures to be implemented at the organization to protect the confidentiality, integrity, and availability of data. | CCM, CCPA, CIS8, CMMC, DORA, DRATA_ESSENTIALS, FEDRAMP, GDPR, HIPAA, ISO27001, ISO270012022, ISO270172015, ISO270182019, ISO27701, NIS2, NIST800171, NIST80053, NISTCSF, NISTCSF2, PCI, SOC_2 | 2024-12-03 22:39:18 |
DCF-46 | %s's new hires and/or internal transfers are required to go through an official recruiting process during which their qualifications and experience are screened to ensure that they are competent and capable of fulfilling their responsibilities. | Management evaluates candidates for employment through a formal screening process. The process may include verification of academic and professional qualifications, identity verifications, validation of personal or professional references, technical interviews, or other steps as deemed applicable by the organization. | CMMC, DORA, FEDRAMP, ISO27001, ISO270012022, ISO27701, NIST800171, NIST800171R3, NISTCSF, NISTCSF2, PCI, PCI4, SOC_2 | 2024-12-03 22:39:18 |
DCF-47 | All %s positions have a detailed job description that lists qualifications, such as requisite skills and experience, which candidates must meet in order to be hired by %s. | %s has documented job descriptions for each position at the company, which include roles and responsibilities as well as required qualifications, skills, and experience for the role. | CCM, ISO27001, ISO270012022, ISO27701, NISTCSF, NISTCSF2, SOC_2 | 2024-12-03 22:39:18 |
DCF-48 | %s ensures that all company-issued computers use a screensaver lock with a timeout of no more than 15 minutes. | Company-managed devices are configured to enforce a screensaver lock with after a defined period of inactivity in accordance with company policies and compliance requirements. | CCM, CCPA, CIS8, CMMC, CYBER_ESSENTIALS, CYBER_ESSENTIALS_32, DORA, FEDRAMP, HIPAA, ISO27001, ISO270012022, ISO27701, NIST800171, NIST800171R3, NIST80053, NISTCSF, PCI4, SOC_2 | 2024-12-03 22:39:18 |
DCF-49 | %s ensures that a password manager is installed on all company-issued laptops. | A password manager is installed on all company-managed devices. | CCM, CYBER_ESSENTIALS, CYBER_ESSENTIALS_32, FEDRAMP, HIPAA, ISO27001, ISO270012022, SOC_2 | 2024-12-03 22:39:18 |
DCF-50 | %s requires antivirus software to be installed on workstations to protect the network against malware. | Anti-malware software is installed on all company-managed devices. | CCM, CCPA, CIS8, CMMC, CYBER_ESSENTIALS, CYBER_ESSENTIALS_32, DRATA_ESSENTIALS, FEDRAMP, HIPAA, ISO27001, ISO270012022, ISO27701, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, PCI, PCI4, SOC_2 | 2024-12-03 22:39:18 |
DCF-51 | %s's workstations operating system (OS) security patches are applied automatically. | Automated operating system (OS) updates are enabled on company-managed devices to install security patches. | CCM, CCPA, CIS8, CMMC, CYBER_ESSENTIALS, CYBER_ESSENTIALS_32, DORA, DRATA_ESSENTIALS, FEDRAMP, ISO27001, ISO270012022, ISO27701, NIST800171, NIST800171R3, NIST80053, NISTCSF, PCI, SOC_2 | 2024-12-03 22:39:18 |
DCF-52 | %s ensures that company-issued laptops have encrypted hard-disks. | Hard-disk encryption is enabled on all company-managed devices. | CCM, CCPA, CIS8, CMMC, CYBER_ESSENTIALS, CYBER_ESSENTIALS_32, DRATA_ESSENTIALS, FEDRAMP, HIPAA, ISO27001, ISO270012022, ISO27701, NIS2, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, SOC_2 | 2024-12-03 22:39:18 |
DCF-54 | %s stores data in databases that is encrypted at rest. | Data at rest is encrypted using strong cryptographic algorithms. | CCM, CCPA, CIS8, CMMC, DORA, DRATA_ESSENTIALS, FEDRAMP, FEDRAMP20X, GDPR, HIPAA, ISO27001, ISO270012022, ISO27701, NIS2, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, PCI4, SOC_2 | 2025-09-23 3:47:31 |
DCF-55 | %s ensures that all connections to its web application from its users are encrypted. | Data in transit is encrypted using strong cryptographic algorithms. | CCM, CCPA, CIS8, CMMC, DORA, DRATA_ESSENTIALS, FEDRAMP, FEDRAMP20X, HIPAA, ISO27001, ISO270012022, ISO270182019, ISO27701, NIS2, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, PCI4, SOC_2 | 2024-12-11 14:45:49 |
DCF-56 | %s maintains a directory of its key vendors, including its agreements that specify terms, conditions and responsibilities. | %s maintains a vendor/third party register that includes a complete and accurate list of vendors/third parties, relationship owners, description for each of the services provided, risk ratings, results of vendor/third party risk management activities, etc. %s executes agreements with vendors and service providers involved in accessing, processing, storing or managing information assets that outline the responsibilities of each vendor or service provider. | CCM, CCPA, CIS8, CMMC, DORA, DRATA_ESSENTIALS, FEDRAMP, FEDRAMP20X, HIPAA, ISO27001, ISO270012022, ISO270172015, ISO27701, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, PCI4, SOC_2 | 2024-12-03 22:39:18 |
DCF-57 | %s obtains and reviews compliance reports (e.g., SOC 2, ISO, PCI) or other evidence for critical vendors and service providers at least annually to monitor the third parties' compliance with industry frameworks, regulations, standards. Results of the review and action items, if any, are documented. | %s obtains and reviews compliance reports or other evidence for critical vendors and service providers at least annually to monitor the third parties' compliance with industry frameworks, regulations, standards (e.g., SOC 2, ISO, PCI DSS, etc.) and %s's requirements. Results of the review and action items, if any, are documented. | CCM, CCPA, CIS8, CMMC, DORA, FEDRAMP, HIPAA, ISO27001, ISO270012022, ISO270172015, ISO27701, NIS2, NIST800171, NIST800171R3, NIST80053, NISTAI, NISTCSF, NISTCSF2, PCI4, SOC_2 | 2024-12-03 22:39:18 |
DCF-58 | Username and password (password standard implemented) or SSO required to authenticate into application, MFA optional for external users, and MFA required for employee users. | %s has implemented systems or mechanisms to centralize authentication and account management across the organization (e.g., directory service, identity provider, etc.). | CCM, CCPA, CIS8, CMMC, CYBER_ESSENTIALS, CYBER_ESSENTIALS_32, FEDRAMP, HIPAA, ISO27001, ISO270172015, NIS2, NIST800171, NIST800171R3, NIST80053, NISTCSF | 2024-12-03 22:39:18 |
DCF-59 | Role-based security is in place for internal and external users, including super admin users. | Administrative or privileged access to systems, resources, and functions is restricted to authorized personnel. | CCM, CCPA, CIS8, CMMC, CYBER_ESSENTIALS, CYBER_ESSENTIALS_32, DORA, FEDRAMP, HIPAA, ISO27001, ISO270012022, ISO270172015, ISO270182019, ISO27701, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, PCI, PCI4, SOC_2 | 2024-12-03 22:39:18 |
DCF-60 | %s's application user passwords are stored using a salted password hash. | %s has implemented technical measures to protect stored user passwords for the system (e.g., encryption, hashing, salting, etc.). | CCM, DORA, HIPAA, ISO27001, NIST800171R3, SOC_2 | 2024-12-03 22:39:18 |
DCF-61 | %s's customer data is segregated from the data of other customers | %s has implemented segregation mechanisms so that customers cannot impact or access data or resources of other customers. | CIS8, DORA, ISO27001, ISO270172015, PCI4, SOC_2 | 2024-12-03 22:39:18 |
DCF-62 | %s automatically logs users out after a predefined inactivity interval and/or closure of the internet browser, and requires users to reauthenticate | %s's systems automatically terminate a user's logical session based on predefined conditions (e.g., predefined periods of inactivity, closure of the system or internet browser, etc.). | CCPA, CIS8, CMMC, DORA, DRATA_ESSENTIALS, FEDRAMP, HIPAA, ISO27001, ISO270012022, ISO27701, NIST800171, NIST800171R3, NIST80053, NISTCSF2, PCI4, SOC_2 | 2024-12-03 22:39:18 |
DCF-63 | External users must accept the Terms of Service prior to their account being created. | %s maintains a publicly available terms of service for use of the system. All users must agree to the terms of service prior to using the system. | ISO27001, SOC_2 | 2024-12-03 22:39:18 |
DCF-64 | %s's security commitments are communicated to external users, as appropriate. | %s communicates service commitments and system requirements to customers and other external parties, as appropriate, through contracts, agreements, company website, etc. %s provides notification to relevant parties of any changes to service commitments and system requirements. | CCM, HIPAA, ISO27001, NISTCSF, NISTCSF2, SOC_2 | 2024-12-03 22:39:18 |
DCF-65 | %s maintains a Privacy Policy that is available to all external users and internal employees, and it details the company's confidentiality and privacy commitments. | %s maintains a publicly available privacy policy/notice. | CCM, CCPA, GDPR, HIPAA, ISO27001, ISO270012022, ISO270182019, ISO27701, NIST80053, NISTCSF, SOC_2 | 2024-12-03 22:39:18 |
DCF-66 | %s maintains a Terms of Service that is available to all external users and internal employees, and the terms detail the company's security and availability commitments regarding the systems. Client Agreements or Master Service Agreements are in place for when the Terms of Service may not apply. | Master service agreements outlining specific requirements are executed with enterprise customers or when the standard terms of service may not apply. | CCM, ISO27001, NISTCSF, SOC_2 | 2024-12-03 22:39:18 |
DCF-67 | %s requires two factor authentication to access sensitive systems and applications in the form of user ID, password, OTP and/or certificate. | Authentication to systems requires the use of multi-factor authentication. | CCM, CCPA, CIS8, CMMC, CYBER_ESSENTIALS, CYBER_ESSENTIALS_32, FEDRAMP, FEDRAMP20X, ISO27001, ISO270012022, ISO27701, NIS2, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, PCI4, SOC_2 | 2024-12-03 22:39:18 |
DCF-68 | %s has established formal guidelines for passwords to govern the management and use of authentication mechanisms. | %s has a documented policy outlining the minimum requirements for passwords used for authentication to organizational systems. Password requirements are enforced for all systems in accordance with company policy. | CCM, CCPA, CMMC, CYBER_ESSENTIALS, CYBER_ESSENTIALS_32, DORA, DRATA_ESSENTIALS, FEDRAMP, FEDRAMP20X, HIPAA, ISO27001, ISO270012022, ISO270172015, ISO27701, NIS2, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, PCI, PCI4, SOC_2 | 2024-12-03 22:39:18 |
DCF-69 | Appropriate levels of access to infrastructure and code review tools are granted to new employees within one week of their start date. | Access requests to information resources, including physical access and access to systems and data, are documented and approved by management based on least privilege, need to know, and segregation of duties principles. | CCM, CIS8, CMMC, CYBER_ESSENTIALS, CYBER_ESSENTIALS_32, DORA, FEDRAMP, HIPAA, ISO27001, ISO270012022, ISO270182019, ISO27701, NIS2, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, PCI4, SOC_2 | 2024-12-03 22:39:18 |
DCF-70 | Access to infrastructure and code review tools is removed from terminated employees within one business day. | System and physical access is revoked within one business day of effective termination date for terminated users (including employees, third parties and vendors, and other personnel). | CCM, CCPA, CIS8, CMMC, CYBER_ESSENTIALS, CYBER_ESSENTIALS_32, DORA, FEDRAMP, HIPAA, ISO27001, ISO270012022, ISO270182019, ISO27701, NIS2, NIST800171, NIST800171R3, NISTCSF, NISTCSF2, PCI, PCI4, SOC_2 | 2024-12-03 22:39:18 |
DCF-71 | Access to corporate network, production machines, network devices, and support tools requires a unique ID. | Authentication to systems requires the use of unique identities. | CCM, CMMC, CYBER_ESSENTIALS, CYBER_ESSENTIALS_32, DORA, DRATA_ESSENTIALS, FEDRAMP, HIPAA, ISO27001, ISO270012022, ISO270172015, ISO270182019, ISO27701, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, PCI4, SOC_2 | 2024-12-03 22:39:18 |
DCF-72 | SSH users use unique accounts to access production machines. Additionally, the use of the “Root” account is not allowed. | Root password authentication to production resources (e.g., virtual machines, containers, etc.) is disabled and only allowed for under exceptional circumstances for a limited time duration based on documented business justification and approval from management. | CCM, FEDRAMP, HIPAA, ISO27001, ISO270012022, NIST80053, SOC_2 | 2024-12-03 22:39:18 |
DCF-73 | No public SSH is allowed. | Network security controls are in place to restrict public access to remote server administration ports (e.g., SSH, RDP) to authorized IP addresses or address ranges only. | CCM, CCPA, CIS8, CMMC, CYBER_ESSENTIALS_32, DORA, DRATA_ESSENTIALS, FEDRAMP, HIPAA, ISO27001, ISO270012022, ISO27701, NIST800171, NIST800171R3, NIST80053, SOC_2 | 2024-12-11 14:45:49 |
DCF-74 | %s communicates system changes to customers that may affect security, availability, processing integrity, or confidentiality. | %s communicates system changes via release notes or change log in the company's website or via periodic communications. | FEDRAMP, ISO27001, ISO270172015, ISO27701, NIST80053, NISTCSF, SOC_2 | 2024-12-03 22:39:18 |
DCF-75 | Read/Write access to cloud data storage is configured to restrict public access. | Cloud resources are configured to deny public access. | CCM, DRATA_ESSENTIALS, FEDRAMP, ISO27001, ISO270012022, ISO270172015, NIS2, NIST800171R3, SOC_2 | 2025-01-30 19:06:48 |
DCF-76 | %s authorizes designated member(s) with the autonomy to validate, change, and release critical security patches and bug fixes, outside of the standard change management process, when absolutely necessary to ensure security standards and availability of the systems. | Emergency changes or hot fixes implemented outside of the standard change management process are reviewed and approved by an authorized individual after implementation. | CCM, DORA, FEDRAMP, ISO27001, ISO270012022, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, SOC_2 | 2024-12-03 22:39:18 |
DCF-77 | Backups of production data are performed least daily and are retained per company policies and procedures. | Backups of production data are performed at least daily and are configured to be retained in accordance with the retention periods established in company policies and procedures. | CCM, CCPA, CIS8, CYBER_ESSENTIALS, DORA, DRATA_ESSENTIALS, FEDRAMP, HIPAA, ISO27001, ISO270012022, ISO27701, NIST80053, NISTAI, NISTCSF, NISTCSF2, SOC_2 | 2024-12-03 22:39:18 |
DCF-78 | Storage buckets that contain customer data are versioned. | Storage buckets that contain sensitive data have versioning enabled to preserve, retrieve, and restore versions of objects. | CIS8, FEDRAMP, ISO27001, ISO270012022, NIST80053, SOC_2 | 2024-12-03 22:39:18 |
DCF-79 | %s uses a system that collects and stores server logs in a central location. The system can be queried in an ad hoc fashion by authorized users. | %s uses a centralized system that collects and stores logs of system activity and sends alerts to personnel based on pre-configured rules. Access to logs is restricted to authorized personnel. | CCPA, CIS8, CMMC, DORA, DRATA_ESSENTIALS, FEDRAMP, FEDRAMP20X, HIPAA, ISO27001, ISO270012022, ISO27701, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, SOC_2 | 2024-12-03 22:39:18 |
DCF-85 | %s uses configurations that ensure only approved networking ports and protocols are implemented, including firewalls. | Network security controls are in place to limit inbound and outbound traffic to the environment to only what is necessary based on business justification. All other traffic is specifically denied. | CCM, CCPA, CIS8, CMMC, CYBER_ESSENTIALS, CYBER_ESSENTIALS_32, DRATA_ESSENTIALS, FEDRAMP, FEDRAMP20X, ISO27001, ISO270012022, ISO27701, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, PCI4, SOC_2 | 2024-12-03 22:39:18 |
DCF-86 | %s's cloud infrastructure is monitored through an operational audit system that sends alerts to appropriate personnel | Production systems and resources are monitored and automated alerts are sent out personnel based on pre-configured rules. Events are triaged to determine if they constitute an incident and escalated per policy if necessary. | CCM, CMMC, DORA, DRATA_ESSENTIALS, FEDRAMP, HIPAA, ISO27001, ISO270012022, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, SOC_2 | 2025-08-17 0:10:54 |
DCF-87 | %s has infrastructure logging configured to monitor web traffic and suspicious activity. When anomalous traffic activity is identified, alerts are automatically created, sent to appropriate personnel and resolved, as necessary. | A threat detection system is in place to monitor web traffic and suspicious activity. When anomalous traffic activity is identified, alerts are automatically sent to personnel, investigated, and escalated through the incident management process, if necessary. | CCM, CCPA, CIS8, CMMC, DORA, FEDRAMP, HIPAA, ISO27001, ISO270012022, ISO27701, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, SOC_2 | 2024-12-03 22:39:18 |
DCF-88 | WAF in place to protect %s's application from outside threats. | A web application firewall is in place to protect public-facing web applications from outside threats. | CCM, CCPA, CIS8, CMMC, CYBER_ESSENTIALS, CYBER_ESSENTIALS_32, DORA, DRATA_ESSENTIALS, FEDRAMP, FEDRAMP20X, ISO27001, ISO270012022, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, PCI4, SOC_2 | 2024-12-11 14:45:49 |
DCF-89 | %s is using Drata to monitor the security and compliance of its cloud infrastructure configuration | %s is using Drata to monitor the security and compliance of its cloud infrastructure configuration. | ISO27001 | 2024-12-03 22:39:18 |
DCF-90 | %s does not use Root Account on Infrastructure provider | Access to the root account in the cloud infrastructure provider is monitored. Login activity for the root account is investigated and validated for appropriateness. | CYBER_ESSENTIALS_32, DORA, FEDRAMP, ISO270012022, NIST800171R3, NIST80053, SOC_2 | 2024-12-11 14:45:49 |
DCF-91 | An intrusion detection system (IDS) is in place to detect potential intrusions, alert personnel when a potential intrusion is detected | An intrusion detection system (IDS)/intrusion prevention system (IPS) or equivalent is in place to detect real-time suspicious or anomalous network traffic that may be indicative of threat actor activity and is configured to alert personnel when a potential intrusion is detected. | CCM, CCPA, CIS8, CMMC, DORA, FEDRAMP, HIPAA, ISO27001, ISO270012022, ISO27701, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, PCI, PCI4, SOC_2 | 2024-12-03 22:39:18 |
DCF-92 | Users can only access the production system remotely through the use of encrypted communication systems. | Remote access to production systems is only available through an encrypted connection (e.g., encrypted virtual private network, SSH, etc.) | CCM, CCPA, CIS8, CMMC, DORA, FEDRAMP, HIPAA, ISO27001, ISO270012022, ISO27701, NIS2, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, SOC_2 | 2024-12-03 22:39:18 |
DCF-94 | %s has security policies that have been approved by management and detail how physical security for the company's headquarters is maintained. These policies are accessible to all employees and contractors. | %s has a documented policy that outlines requirements for physical security. | CCM, CMMC, DORA, FEDRAMP, GDPR, HIPAA, ISO27001, ISO270012022, ISO27701, NIS2, NIST800171, NIST80053, NISTCSF, NISTCSF2, PCI, PCI4, SOC_2 | 2024-12-03 22:39:18 |
DCF-95 | %s monitors its processing capacity and usage on a quarterly basis in order to appropriately manage capacity demand and to enable the implementation of additional capacity to meet availability commitments. | %s monitors processing capacity and use of resources continuously to manage demand and to enable the implementation of additional resources as necessary. | DORA, FEDRAMP, ISO27001, ISO270012022, ISO270172015, ISO27701, NIST80053, NISTCSF, NISTCSF2, SOC_2 | 2024-12-03 22:39:18 |
DCF-96 | %s uses a load balancer to automatically distribute incoming application traffic across multiple instances and availability zones. | %s uses a load balancer to automatically distribute incoming traffic across multiple targets. | CCM, DORA, FEDRAMP20X, ISO27001, ISO270012022, ISO270172015, ISO27701, NISTCSF, NISTCSF2, SOC_2 | 2024-12-03 22:39:18 |
DCF-97 | %s automatically provisions new server instances when predefined capacity thresholds are met. | %s has enabled auto-scaling configurations to provision new cloud resources when predefined capacity thresholds are met. | DORA, FEDRAMP, ISO27001, ISO270012022, ISO270172015, ISO27701, NIST80053, NISTCSF, NISTCSF2, SOC_2 | 2024-12-03 22:39:18 |
DCF-98 | %s monitors the status of backups on a daily basis and action is taken when the backup process fails. | Backups are encrypted and segmented from production systems (e.g., air-gapped, replicated to a different region, stored offsite, etc.) to ensure protection from a disaster or incident. | CCM, CIS8, CYBER_ESSENTIALS, DORA, FEDRAMP, HIPAA, ISO27001, NIS2, NIST80053, NISTCSF, NISTCSF2 | 2024-12-11 14:45:49 |
DCF-99 | %s has an automated email sent to appropriate personnel when the backup process fails. Failed backups are resolved in a timely manner. | Automated notifications are sent to personnel in the event of a backup failure. Backup failures are investigated and resolved by engineering personnel following company policies and procedures. | CCM, CIS8, CYBER_ESSENTIALS, DORA, HIPAA, ISO27001, ISO270012022, NISTCSF, NISTCSF2, SOC_2 | 2024-12-11 14:45:49 |
DCF-100 | %s tests the integrity and completeness of back-up information on an annual basis. | %s tests the integrity and recoverability of backed-up data at least annually. | CCM, CCPA, CIS8, CYBER_ESSENTIALS, DORA, FEDRAMP, HIPAA, ISO27001, ISO270012022, ISO27701, NIST80053, NISTCSF, NISTCSF2, SOC_2 | 2024-12-03 22:39:18 |
DCF-101 | %s has a documented policy for data retention defining the types of data (including company and customer data) and the period of time for which they should be retained. | %s has a documented and implemented a policy for data retention defining the types of data (including company and customer data) and the period of time for which they should be retained. | CCM, CIS8, FEDRAMP, HIPAA, ISO27001, ISO270012022, ISO270172015, ISO270182019, ISO27701, NIS2, NIST800171R3, NIST80053, NISTCSF2, PCI, PCI4, SOC_2 | 2024-12-03 22:39:18 |
DCF-102 | %s has established a data classification policy in order to identify the types of confidential information possessed by the entity and types of protection that are required. | %s has established a data classification policy in order to identify the types of information stored or processed by the organization and the protection measures that are required for each. | CCM, CCPA, CIS8, DORA, FEDRAMP, HIPAA, ISO27001, ISO270012022, ISO270172015, ISO27701, NIS2, NIST80053, NISTCSF, NISTCSF2, SOC_2 | 2024-12-03 22:39:18 |
DCF-103 | %s deletes customer data within 30 days of the customer terminating its contract. | %s disposes of customer data upon termination of services in accordance with contractual agreements. | CCM, HIPAA, ISO27001, ISO270012022, ISO27701, SOC_2 | 2024-12-03 22:39:18 |
DCF-104 | %s uses test data within test environments. | Test data is used in testing and development environments to prevent sensitive information from being copied to non-production environments. | CCM, DORA, ISO27001, ISO270012022, ISO27701, NIS2, NISTCSF2, PCI, SOC_2 | 2024-12-03 22:39:18 |
DCF-105 | %s's new hire contracts include a non-disclosure agreement (NDA) | Personnel, including employees and contractors, are required to sign an agreement that outlines confidentiality requirements (e.g., non-disclosure agreements) prior to hire. | CCM, ISO27001, ISO270012022, ISO270182019, ISO27701, NISTCSF2, SOC_2 | 2024-12-03 22:39:17 |
DCF-106 | %s has a clean desk policy in place to ensure that documents containing sensitive data are not in public areas or laying on unattended employee work areas | %s has defined clear desk and clear screen policies and procedures to protect confidential data (physical and electronic) which are communicated to personnel and enforced across the organization. | DORA, HIPAA, ISO27001, ISO270012022, ISO27701, PCI4 | 2024-12-03 22:39:17 |
DCF-107 | %s disposes of hardcopy material with sensitive data when no longer needed (for legal or business reasons, or upon expiration of their retention period) through secure means such as cross-cut shredding, incinerating, or pulping, so that the data cannot be reconstructed. | When %s disposes of hard copy materials, it does so through secure means such as cross-cut shredding, incinerating, or pulping, so that sensitive data cannot be reconstructed. | CCM, CCPA, CIS8, FEDRAMP, HIPAA, ISO27001, ISO270012022, ISO270182019, ISO27701, NIST80053, NISTCSF2, PCI4, SOC_2 | 2024-12-03 22:39:17 |
DCF-108 | %s places paper documents containing sensitive data in a secured storage bin | %s uses secure storage mechanisms for digital media and hardcopy materials that contain sensitive data (e.g., locked codes, combination locks to offices, rooms and facilities such as key cabinets, etc.) as well as critical equipment and other assets. Access to the secured storage mechanisms (including access to physical keys and knowledge of authentication information) is restricted to authorized personnel. | CCM, CCPA, CMMC, DORA, HIPAA, ISO27001, ISO270012022, ISO270182019, ISO27701, NIST800171, NIST800171R3, NISTCSF2, PCI4, SOC_2 | 2024-12-03 22:39:17 |
DCF-110 | %s's application edits limit input to acceptable value ranges | %s's has implemented automated edit checks in the system to limit input to defined value ranges and formats. | CIS8, FEDRAMP, ISO27701, NIST80053, SOC_2 | 2024-12-03 22:39:18 |
DCF-109 | %s has formal policies and procedures in place to guide personnel in the disposal of hardware containing sensitive data. | %s disposes of data on hardware through secure means, such as wiping and hard drive destruction, in accordance with documented policies and procedures. | CCM, CCPA, CIS8, FEDRAMP, HIPAA, ISO27001, ISO270012022, ISO270182019, ISO27701, NIST80053, NISTCSF2, SOC_2 | 2024-12-03 22:39:17 |
DCF-111 | %s system edits require mandatory fields to be complete before record entry is accepted. | Automated application checks are in place that require mandatory fields to be complete before data entry is accepted. | CIS8, ISO27701, SOC_2 | 2024-12-03 22:39:17 |
DCF-112 | %s provides notice of its privacy practices to users prior to users entering information into its application. | %s provides notice of its privacy practices to users prior to accessing the system. Users are required to explicitly acknowledge the privacy policy prior to entering information into the system. | HIPAA, ISO27001, ISO270012022, ISO27701, NIST80053, NISTCSF, SOC_2 | 2024-12-03 22:39:17 |
DCF-115 | %s's Privacy Policy includes: -Purpose for collecting personal information -Choice and consent -Types of personal information collected -Methods of collection (for example, use of cookies or other tracking techniques) -Use, retention, and disposal -Access -Disclosure to third parties -Security for privacy -Quality, including data subjects' responsibilities for quality -Monitoring and enforcement | %s's documented Privacy Policy includes information on: - Purpose for collecting/processing personal information - Lawful basis for collecting/processing personal information - Types of personal information collected or processed - Choice and consent - Methods of collection (for example, use of cookies or other tracking techniques) - Use, retention, and disposal - Data subject rights - Use of subprocessors - Technical and organizational measures - Quality, including data subjects' responsibilities for quality - Monitoring and enforcement | CCM, CCPA, GDPR, ISO27001, ISO27701, NIST80053, SOC_2 | 2024-12-03 22:39:17 |
DCF-116 | %s's users are required to explicitly accept the notice of privacy practices prior to entering information into the application. | %s's users are required to explicitly acknowledge the notice of privacy practices prior to entering information into the application. | ISO27001, NIST80053 | 2024-12-03 22:39:17 |
DCF-120 | %s's management reviews privacy policies and procedures annually to ensure that personal information is used in conformity with the purposes identified in the privacy notice. | %s's management reviews the online privacy policy and/or notice at least annually to validate its continued suitability and accuracy. The online privacy policy/notice includes the date it was last updated. %s notifies customers of changes to the privacy notice and the nature of the changes, including when personal information will be used for new purposes not previously identified. | CCM, DORA, GDPR, HIPAA, ISO27001, ISO270012022, ISO27701, NIST80053, NISTCSF, SOC_2 | 2024-12-03 22:39:18 |
DCF-122 | %s captures requests for deletion of personal information and information related to the requests is appropriately deleted. | %s complies with legitimate requests to delete PII from data subjects by permanently and completely erasing the personal information from its existing systems or de-identifying the personal information within the timelines established by regulatory requirements. %s provides notification to subprocessors and contractors of the need to delete and informs the data subject whether it has complied with the consumer’s request. Supporting documentation is retained. | NIST80053, SOC_2 | 2024-12-03 22:39:18 |
DCF-123 | %s implements policies and procedures to erase or otherwise destroy personal information that has been identified for destruction. | %s has documented policies and procedures for erasure or destruction of information that has been identified for disposal. | CCM, CCPA, CIS8, DORA, FEDRAMP, HIPAA, ISO27001, ISO270012022, ISO270172015, ISO270182019, ISO27701, NIST80053, NISTCSF, NISTCSF2, SOC_2 | 2024-12-03 22:39:18 |
DCF-126 | Users can correct, amend, or append their personal information by logging into the application and navigating to their settings and profile. | %s provides a mechanism for users to view, correct, and/or delete their personal information by authenticating into the system with a username and password and navigating to their profile settings. | CYBER_ESSENTIALS_32, FEDRAMP, HIPAA, ISO27001, ISO270182019, ISO27701, NIS2, NIST80053, SOC_2 | 2024-12-03 22:39:18 |
DCF-127 | %s's privacy policies or other specific instructions or requirements for handling personal information are communicated to third parties to whom personal information is disclosed. | %s's privacy policies or other specific instructions for handling personal information, including requirements and procedures to notify %s of breaches or unauthorized disclosures, are communicated to third parties to whom personal information is disclosed. | CCM, CCPA, HIPAA, ISO27001, NISTCSF, SOC_2 | 2024-12-03 22:39:18 |
DCF-130 | %s tracks and logs breaches involving unauthorized uses and disclosures of personal information in an incident tracking system. | %s maintains documentation of any personal data breaches or unauthorized disclosures of PII including the facts relating to the personal data breach or disclosure, its effects and impact, and the remedial action taken. | CCM, FEDRAMP, GDPR, ISO27001, ISO27701, ISO420012023, NISTCSF, SOC_2 | 2024-12-03 22:39:18 |
DCF-132 | %s ensures that information security requirements for handling data, especially sensitive privacy data (e.g., PII, PHI, Cardholder Data), are included in vendor and third-party agreements (e.g., Data Processing Agreements, Business Associates Agreements, Service Provider Agreements). | %s shares information with vendors and third parties only when an executed agreement (e.g., service agreements, business associate agreements, data processing agreements, etc.) is in place that includes security, confidentiality, and privacy requirements for the transfer and processing of information. | CCM, CIS8, DORA, HIPAA, ISO27001, ISO270012022, ISO27701, NIST800171R3, NISTAI, NISTCSF2, SOC_2 | 2024-12-03 22:39:18 |
DCF-135 | %s has a process for providing notice of breaches and incidents to affected data subjects to meet %s's objectives related to privacy. | %s provides communications about breaches and incidents to affected parties, organizational officials, authorities, and other internal and external stakeholders, in accordance with company policies and procedures and contractual and legal obligations. | CCM, CCPA, CIS8, CMMC, DORA, FEDRAMP, FEDRAMP20X, GDPR, HIPAA, ISO27001, ISO270012022, ISO270182019, ISO27701, ISO420012023, NIS2, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, SOC_2 | 2024-12-03 22:39:18 |
DCF-136 | %s's privacy practices posted on their website include the list of third parties authorized to receive personal information. | %s communicates to customers any use of subprocessors to process PII (e.g., through a list of subprocessors in the company website or data processing agreement, etc.). %s obtains authorization from customers for the use of subprocessors (e.g., through executed data processing agreements, accepting the terms in the website, etc.). | HIPAA, ISO27001, ISO27701, SOC_2 | 2024-12-03 22:39:18 |
DCF-140 | Data subjects can submit inquiries, complaints, and disputes via the customer portal. | %s provides a contact mechanism for data subjects to submit privacy-related requests or report privacy incidents (e.g., email address, customer portal, etc.). | CCPA, HIPAA, ISO27701, NIST80053, NISTCSF2, SOC_2 | 2024-12-03 22:39:18 |
DCF-141 | %s has a process for tracking users' inquiries, complaints, and disputes within the incident tracking system. | %s maintains records of privacy rights requests in ticket or log format that includes the date of request, nature of request, manner in which the request was made, the date of the business’s response, the nature of the response, and the basis for the denial of the request if the request is denied in whole or in part. Records are retained for a defined period in accordance with legal requirements. | HIPAA, ISO27701, NIST80053, SOC_2 | 2024-12-03 22:39:18 |
DCF-146 | The company's board of directors or a relevant subcommittee meets at least annually to discuss company performance, strategic objectives, compliance initiatives, and cybersecurity and privacy risk and mitigation strategies. | The company's board of directors, owners, senior leadership, or equivalent body, meets at least annually with management to review company performance, strategic objectives, compliance initiatives, and security and privacy risk and mitigation strategies. Meeting minutes, including decisions made and action items, are documented. | ISO27701, NISTAI, NISTCSF2, SOC_2 | 2024-09-11 1:28:13 |
DCF-149 | %s ensures that company-issued removable media devices (USB drives) are encrypted. | %s encrypts removable media devices, such as USB drives, digital video disks, compact disks, external or removable hard disks, etc., that contain sensitive data, to protect the confidentiality of the information during transport. | CCM, CIS8, CMMC, DORA, FEDRAMP, HIPAA, ISO27001, ISO270012022, ISO270182019, ISO27701, NIS2, NIST800171, NIST80053, NISTCSF, NISTCSF2, SOC_2 | 2024-07-11 20:02:42 |
DCF-150 | %s uses DLP (Data Loss Prevention) software to prevent unencrypted sensitive information from being transmitted over email | %s has implemented data leakage prevention mechanisms to systems that could process, store or transmit sensitive information (e.g., sending personal information via email). These mechanisms are configured to prevent data leakage and generate audit logs and alerts. | CCM, CCPA, CIS8, DORA, FEDRAMP, HIPAA, ISO27001, ISO270012022, NISTCSF, NISTCSF2, PCI4, SOC_2 | 2024-09-11 1:28:13 |
DCF-152 | %s ensures that virtual machine OS patches are applied monthly. | %s has implemented automated mechanisms (e.g., unattended upgrades, automated patching tools, etc.) to install security fixes to systems. | CIS8, CMMC, CYBER_ESSENTIALS_32, DORA, FEDRAMP, ISO27001, ISO270012022, ISO27701, NIST800171, NIST800171R3, NIST80053, NISTCSF, SOC_2 | 2024-09-05 21:51:55 |
DCF-154 | %s ensures that incident response plan testing is performed on an annual basis. | %s performs a test of all components of the incident response plan and procedures at least annually through different mechanisms (e.g., walk-through or tabletop exercises, simulations, etc.). The documented plan and procedures are updated if necessary based on the results of the test. | CCPA, CIS8, CMMC, DORA, FEDRAMP, FEDRAMP20X, HIPAA, ISO27001, ISO270012022, ISO420012023, NIS2, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, PCI, PCI4, SOC_2 | 2024-09-05 21:51:55 |
DCF-155 | %s ensures that code changes are tested prior to deployment to ensure quality and security. | Changes are tested in an environment separate from production prior to deployment in accordance with the nature of the change. Documented evidence of testing criteria and testing results is retained. | CCM, CIS8, CMMC, DORA, FEDRAMP, ISO27001, ISO270012022, ISO27701, ISO420012023, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, SOC_2 | 2024-05-07 19:18:26 |
DCF-156 | %s ensures that releases are approved by appropriate members of management prior to production release. | Change releases are approved by authorized personnel prior to deployment to production. | CCM, CIS8, CMMC, ISO27001, ISO270012022, ISO420012023, NIST800171, NIST800171R3, PCI4, SOC_2 | 2024-05-07 19:18:26 |
DCF-157 | %s maintains cybersecurity insurance to mitigate the financial impact of business disruptions. | %s maintains cybersecurity insurance to mitigate the financial impact of security incidents and business disruptions. | NISTCSF2, SOC_2 | 2024-05-07 19:18:26 |
DCF-159 | %s has a documented incident response plan that outlines roles, responsibilities, and procedures to respond to incidents. | %s has a documented an incident response plan that outlines roles, responsibilities, and procedures to document, analyze, categorize, and respond to incidents. The incident response plan reviewed periodically and updated as needed according to lessons learned from previous incidents and industry developments. | CCM, CCPA, CIS8, CMMC, DORA, DRATA_ESSENTIALS, FEDRAMP, FEDRAMP20X, GDPR, HIPAA, ISO27001, ISO270012022, ISO270172015, ISO270182019, ISO27701, ISO420012023, NIS2, NIST800171, NIST800171R3, NIST80053, NISTAI, NISTCSF, NISTCSF2, PCI, PCI4, SOC_2 | 2024-12-03 22:39:18 |
DCF-160 | %s conducts continuous monitoring of security controls using Drata, and addresses issues in a timely manner. | %s uses compliance automation software to identify, select, and continuously monitor internal controls. | CCM, CCPA, CMMC, DORA, FEDRAMP, HIPAA, ISO27001, ISO270012022, ISO27701, ISO420012023, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, SOC_2 | 2024-12-03 22:39:18 |
DCF-161 | %s has a well-defined documented scope that reflects the boundaries and applicability of its Information Security Management System | %s has documented the scope of its management system(s) that outlines the boundaries and applicability of the system(s) and considers internal and external issues, requirements of interested parties, and interfaces and dependencies with other organizations. | ISO27001, ISO270012022, ISO27701 | 2024-05-07 19:18:26 |
DCF-162 | %s has a documented statement of applicability, which defines and applies necessary controls for the implementation of an information security risk treatment process. | %s has a documented statement of applicability, which defines the controls deemed necessary by the organization as a result of the risk assessment to implement the risk treatment plan. | ISO27001, ISO270012022, ISO27701 | 2024-05-07 19:18:26 |
DCF-163 | %s has identified and documented the interested parties and the legal, statutory, regulatory and contractual requirements relevant to its security and privacy management program. | %s has identified and documented the legal, statutory, regulatory and contractual requirements relevant to the organization. %s has assigned responsibility and identified and implemented processes to satisfy these requirements and monitor and review changes. | CCM, DORA, ISO27001, ISO270012022, ISO27701, ISO420012023, NISTAI, NISTCSF, NISTCSF2 | 2024-09-11 1:28:13 |
DCF-164 | %s's top management conducts scheduled reviews of the ISMS to ensure effectiveness and relevance. | %s's top management conducts reviews of its management system(s) at planned intervals to evaluate suitability, adequacy and effectiveness. %s retains documentation of the results of management reviews. | DORA, ISO27001, ISO270012022, ISO27701 | 2024-05-07 19:18:26 |
DCF-165 | %s has an independent assessment (e.g., internal audit) process to ensure that its information security program is effectively implemented, maintained, and in conformance. | %s conducts evaluations and assessments at planned intervals to ensure that internal controls are effectively implemented and maintained in conformance with the organization's requirements (e.g., internal audits). %s retains documented information of the assessment program(s) and results. | CCM, CMMC, DORA, FEDRAMP, ISO27001, ISO270012022, ISO270172015, ISO270182019, ISO27701, ISO420012023, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2 | 2024-09-05 21:51:55 |
DCF-166 | %s has a defined Business Continuity Plan that outlines the proper procedures to respond, recover, resume, and restore operations following a disruption or significant change. | %s has a defined business continuity plan that outlines strategies for maintaining operations during a disruption. | CCM, CCPA, CIS8, DORA, FEDRAMP, FEDRAMP20X, GDPR, HIPAA, ISO27001, ISO270012022, ISO27701, NIS2, NIST80053, NISTCSF, NISTCSF2, PCI, SOC_2 | 2024-12-03 22:39:18 |
DCF-167 | %s has a Business Impact Analysis process to determine resources and time required to ensure business continuity after a disruptive incident. | %s performs a business impact analysis (BIA) periodically to identify criticality, business recovery order, and minimum service levels for key business processes and assets. Results of the business impact analysis are documented and incorporated into business continuity and disaster recovery plans. | CCM, DORA, FEDRAMP, HIPAA, ISO27001, ISO270012022, ISO27701, NIS2, NIST80053, NISTCSF, NISTCSF2 | 2024-12-03 22:39:18 |
DCF-168 | %s has a documented policy that outlines requirements for managing vendor and third party relationships. | %s has a documented policy that outlines requirements for managing vendor and third-party relationships through their entire life cycle. | CCM, CCPA, CIS8, CMMC, DORA, DRATA_ESSENTIALS, FEDRAMP, FEDRAMP20X, HIPAA, ISO27001, ISO270012022, ISO270172015, ISO270182019, ISO27701, ISO420012023, NIS2, NIST800171, NIST80053, NISTAI, NISTCSF, NISTCSF2, SOC_2 | 2024-12-03 22:39:18 |
DCF-169 | %s has a defined backup policy that establishes the requirements for backup information, software and systems. | %s has defined and documented a backup policy that establishes the requirements for backup information, software and systems. | CCM, CIS8, CYBER_ESSENTIALS, DORA, DRATA_ESSENTIALS, FEDRAMP, GDPR, HIPAA, ISO27001, ISO270012022, ISO270182019, ISO27701, NIS2, NIST80053, NISTAI, NISTCSF, NISTCSF2, PCI, SOC_2 | 2024-12-03 22:39:18 |
DCF-170 | %s has documented security objectives and procedures to achieve those objectives. | %s has documented objectives for its management system(s) (e.g., security objectives, privacy objectives, AI objectives, etc.) and plans to achieve them. | DORA, ISO27001, ISO270012022, ISO27701, NISTCSF | 2024-12-03 22:39:18 |
DCF-171 | %s has documented procedures for operations relating to information processing and communication facilities | %s maintains documented procedures that describe how to perform activities including controls, methods, and processes to be followed to achieve the company's policies objectives and compliance activities. The procedures are reviewed and updated as needed to address changes in processes, technologies, and business objectives, or at least annually, and are available to all relevant parties. | CCPA, DORA, FEDRAMP, ISO27001, ISO270012022, ISO27701, NIST800171R3, NIST80053, NISTCSF, PCI4 | 2024-12-03 22:39:18 |
DCF-173 | %s has an established Employment Terms and Conditions that defines obligations and responsibilities in line with information security policies. | Personnel responsibilities for information security (including confidentiality, legal, and data handling requirements), including responsibilities that remain after employment, are communicated to and acknowledged by personnel (e.g., through employment contracts, etc.) | CCM, CMMC, DORA, ISO27001, ISO270012022, ISO27701, NIST800171, NISTCSF2, SOC_2 | 2024-12-03 22:39:17 |
DCF-175 | %s has a defined communications plan that establishes procedures for internal and external communications relevant to its information security program. | %s has documented communication plans that establishes procedures for internal and external communications relevant to its information security, privacy, or other programs. | CCM, DORA, ISO27001, ISO270012022, ISO270172015, ISO27701, ISO420012023, NIS2, NISTCSF, NISTCSF2 | 2024-09-11 1:28:13 |
DCF-176 | %s has a defined process for evaluating information security performance and the effectiveness of its information security program. | %s has defined performance and/or effectiveness measurements for its management system(s) and implemented procedures to monitor these measurements periodically as determined by the organization. | FEDRAMP, ISO27001, ISO270012022, ISO27701, NIST80053, NISTCSF | 2024-05-07 19:18:26 |
DCF-178 | %s has an established system for record management and document control. | %s implemented procedures for the control of documented information relevant for its management system(s). | ISO27001, ISO270012022, ISO27701 | 2024-07-11 20:02:42 |
DCF-179 | %s has an established list of applicable information security roles and specified skill and competence level required for each role. | %s has identified and documented skill and competence requirements for personnel that contribute to the development, implementation and oversight of its management system(s) and retains documented evidence of competence. | DORA, HIPAA, ISO27001, ISO270012022, ISO27701, ISO420012023 | 2024-05-07 19:18:26 |
DCF-180 | %s has a defined process to ensure the secure transfer of information internally and externally. | %s has defined and documented policies and procedures for the secure transfer of information within the organization and with any external parties. | CCM, CMMC, DORA, FEDRAMP, ISO27001, ISO270012022, ISO270182019, ISO27701, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2 | 2024-12-03 22:39:18 |
DCF-181 | %s has a defined policy that establishes requirements for the use of cryptographic controls. | %s has a documented policy that establishes requirements for the use of cryptographic controls. | CCM, CMMC, DORA, FEDRAMP, GDPR, HIPAA, ISO27001, ISO270012022, ISO270172015, ISO27701, NIS2, NIST800171, NIST800171R3, NIST80053, PCI, SOC_2 | 2024-12-03 22:39:18 |
DCF-182 | %s has a defined policy that establishes requirements for the proper management and tracking of organizational assets. | %s has established and documented a policy that outlines requirements for the management and tracking of company assets. | CCM, CCPA, CIS8, CMMC, CYBER_ESSENTIALS, CYBER_ESSENTIALS_32, DORA, FEDRAMP, HIPAA, ISO27001, ISO270012022, ISO270172015, ISO27701, NIS2, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, SOC_2 | 2024-12-03 22:39:18 |
DCF-183 | %s has a defined policy that establishes requirements for vulnerability assessments and reporting. | %s has a defined policy that establishes requirements for vulnerability management across the organization, including monitoring, cataloging, and assigning risk ratings to vulnerabilities to prioritize remediation efforts. | CCM, CCPA, CIS8, CMMC, CYBER_ESSENTIALS, CYBER_ESSENTIALS_32, DORA, DRATA_ESSENTIALS, FEDRAMP, FEDRAMP20X, GDPR, HIPAA, ISO27001, ISO270012022, ISO27701, NIS2, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, PCI, PCI4, SOC_2 | 2024-12-03 22:39:18 |
DCF-184 | %s has a defined and documented Information Security Management System (ISMS) Plan, for the establishment, implementation, maintenance, and continuous improvement of its information security and risk management program. | %s has a defined and documented a plan for the establishment, implementation, maintenance, and continuous improvement of its management systems(s). | DORA, ISO27001, ISO270012022, ISO27701 | 2024-05-07 19:18:26 |
DCF-185 | %s has an established threat assessment process to continuously analyze threats and disseminate the information appropriately. | %s has implemented mechanisms to collect threat information and produce threat intelligence (e.g., commercial cyber threat intelligence tools, security product/vendor intelligence feeds, open source feeds, etc.) in accordance with defined threat intelligence objectives. | DORA, FEDRAMP, ISO270012022, NIST80053, NISTCSF, NISTCSF2 | 2024-05-07 19:18:26 |
DCF-186 | %s has a defined process for the de-identification of data that has been classified as sensitive. | %s has implemented mechanisms for the de-identification of data that has been classified as sensitive (e.g., data masking, anonymization, pseudonymization, etc.). | ISO270012022, NIST80053 | 2024-05-07 19:18:26 |
DCF-188 | %s has a process to communicate and exchange information with relevant security and privacy organizations. | %s exchanges information with relevant security and privacy organizations, professional associations, and other specialist forums, including information on newly identified threats and vulnerabilities, new technologies, etc. (e.g., through bulletin subscriptions, email alerts from security advisories, participation in conferences, etc.). | CCM, CIS8, CMMC, DORA, FEDRAMP, ISO270012022, ISO27701, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, PCI4 | 2024-05-07 19:18:26 |
DCF-190 | %s has identified and assigned members to appropriate information security roles | %s has formally assigned responsibility for information security in the organization to a Chief Information Security Officer or other security-knowledgeable member of management. | CIS8, DORA, FEDRAMP, HIPAA, NIST80053, NISTCSF2 | 2024-12-03 22:39:18 |
DCF-196 | %s has established a training program for the use and disclosure of protected health information (PHI) to help employees understand their obligations and responsibilities to comply with the %s's security policies and procedures, as they apply to HIPAA. All members of %s's workforce are required to complete this training upon hire and annually thereafter. | %s has established a training program for the use and disclosure of protected health information (PHI) to help personnel understand their obligations and responsibilities related to HIPAA. All eligible members of the workforce are required to complete this training during onboarding and annually thereafter. | HIPAA | 2024-12-11 14:37:26 |
DCF-197 | %s retains required documentation for 6 years from the date of the document's creation or when it was last in effect (whichever is later). | %s retains HIPAA-related policies and procedures for at least 6 years from the date of the document's creation or when it was last in effect (whichever is later). | HIPAA | 2024-12-11 14:37:26 |
DCF-201 | %s has a formal process for approving and testing all network connections and changes to the firewall and router configurations. | %s has defined, documented and implemented configuration standards for network security controls, including configurations for firewalls, routers configured with access control lists, and cloud virtual networks. All services, protocols, and ports allowed are identified, documented, approved, and have a defined business need. | CIS8, CMMC, CYBER_ESSENTIALS, CYBER_ESSENTIALS_32, DORA, NIS2, NIST800171, NIST800171R3, NIST80053, NISTCSF2, PCI, PCI4 | 2024-01-19 0:22:44 |
DCF-204 | %s has a current diagram that shows all data flows across systems and networks. | A dataflow diagram is maintained to show all account data flows across systems and networks. The diagram is reviewed and approved by management at least annually and updated as necessary when there are changes to the environment. | CCM, CCPA, CIS8, CMMC, DORA, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, PCI, PCI4, SOC_2 | 2024-05-07 19:18:26 |
DCF-206 | %s requires a firewall at each Internet connection and between any demilitarized zone (DMZ) and the internal network zone. | %s has implemented network security controls between trusted and untrusted networks to prevent unauthorized traffic from traversing network boundaries. | CCM, CIS8, CMMC, CYBER_ESSENTIALS, CYBER_ESSENTIALS_32, DORA, FEDRAMP, NIST800171, NIST800171R3, NIST80053, PCI, PCI4 | 2024-01-19 0:22:44 |
DCF-210 | %s identifies all insecure services, protocols, and ports identified, and security features are documented and implemented for each identified service. | %s identifies all services, protocols, and ports in use considered to be in use. %s identifies, documents and implements security features for each insecure service, protocol, or port in use, such that the risk is mitigated. | CIS8, CYBER_ESSENTIALS_32, DORA, FEDRAMP, NIST80053, PCI, PCI4 | 2024-01-19 0:22:44 |
DCF-212 | %s reviews firewall and router rule sets at least every six months. | %s performs a review of network security controls at least once every six months. Results of the review are documented and configurations identified as no longer being supported by a business justification are removed or updated. | CIS8, CYBER_ESSENTIALS, DORA, PCI, PCI4 | 2024-01-19 0:22:44 |
DCF-215 | %s secures and synchronizes router configuration files. | Configuration files for network security controls (including files, automated and system-based controls, scripts, settings, infrastructure as code, or other parameters used to configure and synchronize network security controls) are secured from unauthorized access and kept consistent with active network configurations. | CMMC, NIST800171, NISTCSF2, PCI, PCI4 | 2024-01-19 0:22:44 |
DCF-216 | %s has installed perimeter firewalls between all wireless networks and the cardholder data environment, and has configured these firewalls to deny or, if traffic is necessary for business purposes, permit only authorized traffic between the wireless environment and the cardholder data environment. | Network security controls are implemented to deny all traffic from wireless networks into the environment by default and only allow wireless traffic with authorized business purpose. | CIS8, CMMC, NIST800171, NIST800171R3, PCI, PCI4 | 2024-09-05 21:51:55 |
DCF-218 | %s has implemented a DMZ to limit inbound traffic to only system components that provide authorized publicly accessible services, protocols, and ports. | Inbound traffic from untrusted networks is restricted to communications with system components that are authorized to provide publicly accessible services, protocols, and ports, and to stateful responses to communications initiated by system components in a trusted network. All other traffic is denied. | CIS8, CYBER_ESSENTIALS_32, DORA, FEDRAMP, NIS2, NIST80053, PCI, PCI4 | 2024-01-19 0:22:44 |
DCF-220 | %s has implemented anti-spoofing measures to detect and block forged source IP addresses from entering the network. (For example, block traffic originating from the Internet with an internal source address.) | %s has implemented anti-spoofing measures to detect and block forged source IP addresses from entering the trusted network. | CMMC, NIST800171, NIST800171R3, PCI, PCI4 | 2024-01-19 0:22:44 |
DCF-223 | %s system components that store cardholder data (such as a database) are placed in an internal network zone, segregated from the DMZ and other untrusted networks. | Network security controls are in place such that system components storing sensitive data are not directly accessible from untrusted networks. | CIS8, CMMC, DORA, NIST800171, NIST800171R3, PCI, PCI4 | 2024-01-19 0:22:44 |
DCF-225 | %s restricts any disclosure of private IP addresses and routing information to external entities. | %s has implemented mechanisms to restrict disclosure of internal IP addresses and routing information to only authorized parties (for example, network address translation (NAT), proxy servers, etc.) | PCI, PCI4 | 2024-01-19 0:22:44 |
DCF-229 | %s ensures that vendor-supplied defaults are always changed and unnecessary default accounts are removed or disabled before installing a system on the network. This applies to ALL default passwords, including but not limited to those used by operating systems, software that provides security services, application and system accounts, point-of-sale (POS) terminals, payment applications, Simple Network Management Protocol (SNMP) community strings, etc.). | All vendor-supplied default accounts are either disabled or removed, or their default password is changed in accordance with the company's policy and compliance requirements. | CCM, CIS8, CYBER_ESSENTIALS, CYBER_ESSENTIALS_32, ISO270012022, ISO27701, NIST800171R3, NIST80053, PCI, PCI4 | 2024-01-19 0:22:44 |
DCF-231 | %s changes encryption keys from default at installation, and anytime anyone with knowledge of the keys leaves the company or changes positions. | For wireless environments connected to the environment or transmitting account data, encryption keys are changed whenever personnel with knowledge of the key leave the company or change roles and whenever a key is suspected of or known to be compromised. | CCM, DORA, NIST80053, PCI, PCI4 | 2024-01-19 0:22:44 |
DCF-233 | %s changes default passwords/passphrases on access points at installation. | For wireless environments connected to the environment or transmitting sensitive data, all wireless vendor defaults are changed at installation or are confirmed to be secure, including but not limited to default wireless encryption keys, passwords on wireless access points, simple network management protocol (SNMP) defaults, and any other security-related wireless vendor defaults. | CCM, CIS8, DORA, NIST800171R3, PCI, PCI4 | 2024-01-19 0:22:44 |
DCF-239 | %s has implemented only one primary function per virtual system component or device. | %s has implemented technical measures so that primary functions with lower security needs cannot affect the security of primary functions with higher security needs on the same system component (for example, assigning one primary function per system component, isolating functions that exist within the same system component, or securing all functions within the same system component to the level required by the function with the highest security need). | NIST800171R3, PCI, PCI4 | 2024-01-19 0:22:44 |
DCF-240 | %s has enabled only necessary services, protocols, daemons, etc., as required for the function of the system. | %s uses only necessary services, software programs, protocols, daemons, and functions in system components, and all unnecessary functionality (e.g., scripts, drivers, features, subsystems, file systems, interfaces, unused web servers, programs, etc.) is removed or disabled in accordance with documented configuration standards. | CIS8, CMMC, CYBER_ESSENTIALS_32, FEDRAMP, NIST800171, NIST800171R3, NIST80053, NISTCSF2, PCI, PCI4 | 2024-09-05 21:51:55 |
DCF-241 | All %s enabled insecure services, daemons, or protocols are justified per documented configuration standards. | %s has documented business justification and implemented additional security features for any required services, protocols, or daemons in use that are considered insecure so that the risk is mitigated. | CYBER_ESSENTIALS_32, PCI, PCI4 | 2024-01-19 0:22:44 |
DCF-244 | %s has included common system security parameters settings in the system configuration standards. | Security parameters in organizational systems are configured in accordance with documented secure configuration standards. | CIS8, CMMC, FEDRAMP, NIST800171, NIST800171R3, NIST80053, NISTCSF, PCI, PCI4 | 2024-09-05 21:51:55 |
DCF-249 | %s has encrypted all non-console administrative access using strong cryptography, and invokes strong encryption method before administrator's password is requested. | All non-console administrative access is encrypted using strong cryptography, including includes administrative access via browser-based interfaces and application programming interfaces (APIs). | DORA, NIST800171R3, PCI, PCI4 | 2024-01-19 0:22:44 |
DCF-253 | %s has defined processes in place for securely deleting cardholder data when no longer needed for legal, regulatory, and/or business reasons. | %s disposes of data securely upon expiration of the established retention periods, when requested by customers, or when no longer needed for legal, regulatory, and/or business reasons. | CIS8, ISO270012022, ISO27701, NISTCSF2, PCI, PCI4, SOC_2 | 2024-05-07 19:18:26 |
DCF-255 | %s has a quarterly process in place for identifying and securely deleting stored cardholder data that exceeds defined retention requirements. | %s verifies at least once every three months that stored account data exceeding the defined retention period has been securely deleted or rendered unrecoverable. Evidence of the verification is documented and retained. | PCI, PCI4 | 2024-01-19 0:22:44 |
DCF-257 | %s has a documented business justification for the storage of sensitive authentication data. | %s maintains documentation of the legitimate business justification to store sensitive authentication data (if sensitive authentication data is stored after the authorization process). | NIST800171R3, PCI, PCI4 | 2025-01-28 20:01:13 |
DCF-258 | %s ensures sensitive authentication data is secured. | %s encrypts sensitive authentication data (SAD) that is stored electronically prior to completion of authorization using strong cryptography. | NIST800171R3, PCI, PCI4 | 2024-01-19 0:22:44 |
DCF-259 | %s ensures sensitive authentication data is deleted or rendered unrecoverable upon completion of the authorization process. | If sensitive authentication data (SAD) is received, %s deletes and renders the data unrecoverable upon completion of the authorization process. | NIST800171R3, PCI, PCI4 | 2024-01-19 0:22:44 |
DCF-260 | %s does not store the full contents of any track (from the magnetic stripe located on the back of a card, equivalent data contained on a chip, or elsewhere) after authorization. This data is alternatively called full track, track, track 1, track 2, and magnetic-stripe data. | The full contents of any track are not stored upon completion of the authorization process. | PCI, PCI4 | 2025-01-28 20:01:13 |
DCF-261 | %s does not store the card verification code or value (three-digit or four-digit number printed on the front or back of a payment card used to verify card-not- present transactions) after authorization. | The card verification code is not stored upon completion of the authorization process. | PCI, PCI4 | 2025-01-28 20:01:13 |
DCF-262 | %s does not store the personal identification number (PIN) or the encrypted PIN block after authorization. | The personal identification number (PIN) and the PIN block are not stored upon completion of the authorization process. | PCI, PCI4 | 2025-01-28 20:01:13 |
DCF-263 | %s masks PAN when displayed (the first six and last four digits are the maximum number of digits to be displayed), such that only personnel with a legitimate business need can see more than the first six/last four digits of the PAN. | %s has implemented technical measures to mask primary account numbers (PANs) when displayed (on screen, paper receipts, etc.) such that only personnel with a legitimate business need can see more than the bank identification number (BIN) and last four digits of the PAN. | PCI, PCI4 | 2024-01-19 0:22:44 |
DCF-264 | %s has rendered PAN unreadable anywhere it is stored (including on portable digital media, backup media, and in logs) by using any of the following approaches: * One-way hashes based on strong cryptography, (hash must be of the entire PAN) * Truncation (hashing cannot be used to replace the truncated segment of PAN) * Index tokens and pads (pads must be securely stored) * Strong cryptography with associated key-management processes and procedures. | Primary account numbers (PANs) are rendered unreadable anywhere they are stored, including primary storage (databases, or flat files such as text files spreadsheets) as well as non-primary storage (backup, audit logs, exception, or troubleshooting logs). | PCI, PCI4 | 2024-01-19 0:22:44 |
DCF-265 | %s ensures that logical access to encrypted file systems is managed separately and independently of native operating system authentication and access control mechanisms (for example, by not using local user account databases or general network login credentials). | Disk encryption implementations are configured to require independent authentication and logical access controls for decryption to protect data in the event of physical loss of a disk. | DORA, FEDRAMP, NIS2, NIST800171R3, PCI, PCI4 | 2024-01-19 0:22:44 |
DCF-267 | %s ensures that cardholder data on removable media is encrypted wherever stored. | Sensitive data on removable storage media is encrypted wherever stored. | CIS8, PCI, PCI4 | 2024-01-19 0:22:44 |
DCF-268 | %s maintains a documented description of the cryptographic architecture, which includes: Details of all algorithms, protocols, and keys used for the protection of cardholder data, including key strength and expiry date; description of the key usage for each key; Inventory of any HSMs and other SCDs used for key management. | %s maintains a documented description of the cryptographic architecture in place, including details of all algorithms, protocols, and keys used for the protection of stored account data, including key strength and expiry date, preventing the use of the same cryptographic keys in production and test environments, description of the key usage for each key, and inventory of any hardware security modules (HSMs), key management systems (KMS), and other secure cryptographic devices (SCDs) used for key management, including type and location of devices. | PCI, PCI4 | 2024-01-19 0:22:44 |
DCF-269 | %s restricts access to cryptographic keys to the fewest number of custodians necessary. | %s restricts access to cleartext cryptographic key components to the fewest number of custodians necessary to reduce the risk of stored data being retrieved or rendered visible by unauthorized parties. | PCI, PCI4 | 2024-01-19 0:22:44 |
DCF-270 | %s ensures that secret and private cryptographic keys are used to encrypt/decrypt cardholder data stored in one or more of the following: Encrypted with a key-encrypting key that is at least as strong as the data-encrypting key, and that is stored separately from the data-encrypting key; within a secure cryptographic device (such as a hardware (host) security module (HSM) or PTS-approved point-of-interaction device); as at least two full-length key components or key shares, in accordance with an industry-accepted method. | Key-encrypting keys used are at least as strong as the data-encrypting keys they protect and are stored separately from data-encrypting keys. | DORA, PCI, PCI4 | 2024-01-19 0:22:44 |
DCF-271 | %s stores cryptographic keys in the fewest possible locations. | %s stores cryptographic keys in the fewest possible locations to minimize the potential for keys to be exposed to unauthorized parties. | DORA, ISO270012022, ISO27701, PCI, PCI4 | 2024-01-19 0:22:44 |
DCF-272 | %s ensures that if keys are shared with customers for transmission or storage of cardholder data, provide documentation to customers that includes guidance on how to securely transmit, store and update customer’s keys, in accordance with requirements 3.6.1 through 3.6.8. | Where %s shares cryptographic keys with its customers for transmission or storage of account data, the company documents and distributes guidance on secure transmission, storage and updating of such keys to those customers. | CCM, DORA, PCI, PCI4 | 2024-01-19 0:22:44 |
DCF-273 | %s's cryptographic key procedures include generation of strong cryptographic keys | Key-management policies and procedures are documented and implemented including: generation of strong cryptographic keys, secure distribution, and secure storage of cryptographic keys used to protect sensitive data. | CCM, CMMC, DORA, ISO270012022, ISO27701, NIST800171, NIST800171R3, PCI, PCI4, SOC_2 | 2024-01-19 0:22:44 |
DCF-276 | %s's cryptographic key procedures include cryptographic key changes for keys that have reached the end of their defined cryptoperiod, as defined by the associated application vendor or key owner, and based on industry best practices and guidelines. | A defined cryptoperiod for each key type in use as defined by the associated application vendor or key owner is documented. %s changes encryption keys when they reach the end of their cryptoperiod in accordance with documented policies and procedures. | CCM, DORA, NIS2, PCI, PCI4 | 2024-01-19 0:22:44 |
DCF-278 | %s's cryptographic key procedures include replacement of known or suspected compromised keys. | %s retires, replaces or destructs cryptographic keys that are no longer used or needed or when the key expires, the integrity of the key has been weakened, or the key is known or suspected to be compromised, in accordance with documented company policies and procedures. Retired or replaced keys are not used for encryption operations. | CCM, CMMC, DORA, NIS2, NIST800171, NIST800171R3, PCI, PCI4, SOC_2 | 2024-01-19 0:22:44 |
DCF-280 | %s ensures that if manual clear-text cryptographic key-management operations are used, these operations must be managed using split knowledge and dual control. | Split knowledge and dual control are used to manage operations where manual cleartext cryptographic key management is performed in accordance with documented company policies and procedures. | DORA, PCI, PCI4 | 2024-01-19 0:22:44 |
DCF-281 | %s's cryptographic key procedures include prevention of unauthorized substitution of cryptographic keys. | Key management policies and procedures are documented and implemented to include the prevention of unauthorized substitution of cryptographic keys. | DORA, PCI, PCI4 | 2024-01-19 0:22:44 |
DCF-282 | %s requires cryptographic key custodians to formally acknowledge that they understand and accept their key- custodian responsibilities. | %s requires cryptographic key custodians to formally acknowledge that they understand and accept their key-custodian responsibilities in accordance with documented company policies and procedures. | DORA, PCI, PCI4 | 2024-01-19 0:22:44 |
DCF-284 | %s accepts only trusted keys and/or certificates during transmission of cardholder data. | %s has implemented security mechanisms so that only trusted keys and/or certificates are accepted during transmission of sensitive data that are confirmed valid and not expired or revoked. | CMMC, DORA, FEDRAMP, ISO270012022, NIST800171, NIST800171R3, NIST80053, PCI, PCI4 | 2024-09-05 21:51:55 |
DCF-285 | %s has implemented security protocols to use only secure configurations, and to not support insecure versions or configurations, during transmission of cardholder data. | Security protocols in use for transmission of sensitive data support only secure versions or configurations and do not support fallback to, or use of insecure versions, algorithms, key sizes, or implementations. | CIS8, CMMC, DORA, NIST800171, NIST800171R3, NISTCSF2, PCI, PCI4 | 2024-12-11 14:45:49 |
DCF-286 | %s has implemented a proper encryption strength for the encryption methodology in use, during transmission of cardholder data. | %s has implemented a proper encryption strength for the encryption methodology in use, during transmission of sensitive information (e.g., PII, PHI, Cardholder Data, etc.). | CCM, NIS2, PCI | 2025-10-06 23:16:27 |
DCF-287 | %s enables TLS whenever cardholder data is transmitted or received. | %s enables TLS whenever sensitive information (e.g., PII, PHI, Cardholder Data, etc.) is transmitted or received. | CCM, CIS8, DORA, NIS2, PCI | 2025-10-06 23:16:27 |
DCF-288 | %s ensures that wireless networks transmitting cardholder data or connected to the cardholder data environment, use industry best practices to implement strong encryption for authentication and transmission. | Wireless networks transmitting sensitive data or connected to the environment use strong protocols for authentication and encryption of data transmissions. | CCM, CIS8, CMMC, DORA, NIS2, NIST800171, NIST800171R3, PCI, PCI4 | 2024-09-05 21:51:55 |
DCF-289 | %s ensures that PANs are rendered unreadable or secured with strong cryptography whenever they are sent via end-user messaging technologies. | %s encrypts sensitive data with strong cryptography when transmitted via e-mail, instant messaging, SMS, chat or other end-user messaging technologies. | CIS8, DORA, ISO27701, NIS2, PCI, PCI4 | 2024-01-19 0:22:44 |
DCF-291 | %s ensures that anti-virus programs are capable of detecting, removing, and protecting against all known types of malicious software. | An anti-malware solution is deployed on all system components, except for those system components identified through periodic risk assessments that concludes the system components are not at risk from malware. | CCM, CCPA, CIS8, CMMC, CYBER_ESSENTIALS, CYBER_ESSENTIALS_32, FEDRAMP, ISO27701, NIST800171, NIST800171R3, NIST80053, NISTCSF, PCI, PCI4 | 2024-09-05 21:51:55 |
DCF-292 | %s performs periodic evaluations to identify and evaluate evolving malware threats in order to confirm whether those systems considered to not be commonly affected by malicious software continue as such. | %s maintains a documented list of all system components evaluated as not at risk for malware that are not subjected to anti-malware controls. %s performs periodic evaluations to identify and assess evolving malware threats for those system components and to confirm whether such system components continue to not require anti-malware protection. Results of the periodic evaluation are documented. | CCPA, CYBER_ESSENTIALS, CYBER_ESSENTIALS_32, FEDRAMP, NIST80053, NISTCSF, PCI, PCI4 | 2024-01-19 0:22:44 |
DCF-293 | %s ensures that all anti-virus software and definitions are kept current. | The deployed anti-malware solution is kept current via automatic updates and configured to detect all known types of malware and to remove, block, or contain all known types of malware. | CCPA, CIS8, CMMC, CYBER_ESSENTIALS, CYBER_ESSENTIALS_32, DORA, ISO270012022, NIST800171, NIST800171R3, PCI, PCI4, SOC_2 | 2024-09-05 21:51:55 |
DCF-294 | %s ensures that automatic updates and periodic scans are enabled and being performed. | The implemented anti-malware solutions are configured to perform periodic scans and active/real-time scans (e.g., scanning files from external sources as they are downloaded, opened, or executed) or to perform continuous behavioral analysis of systems or processes. | CCM, CIS8, CMMC, CYBER_ESSENTIALS, CYBER_ESSENTIALS_32, ISO270012022, NIST800171, NIST800171R3, NISTCSF, NISTCSF2, PCI, PCI4, SOC_2 | 2024-09-05 21:51:55 |
DCF-296 | %s ensures that anti-virus mechanisms are actively running and cannot be disabled or altered by users, unless specifically authorized by management on a case-by-case basis for a limited time period. | %s restricts access to disable or alter anti-malware mechanisms to authorized personnel based on documented approval by management on a case-by-case basis for a limited time period. | CYBER_ESSENTIALS, PCI, PCI4 | 2024-01-19 0:22:44 |
DCF-297 | %s installs critical security patches within one month of release. | %s has implemented a formal patch management process where critical patches/updates (as identified per the entity's vulnerability risk analysis) are installed within one month of release. All other applicable security patches/updates are installed within the timeframe established by the entity per the risk analysis and company policies and procedures. | CCM, CIS8, CMMC, CYBER_ESSENTIALS_32, DORA, FEDRAMP, NIST800171, NIST800171R3, NIST80053, NISTCSF, PCI, PCI4 | 2024-09-05 21:51:55 |
DCF-304 | %s ensures the removal of test data and accounts from system components before the system becomes active / goes into production. | Test data and test accounts are removed from system components before the system goes into production. | FEDRAMP, NIS2, NIST80053, PCI, PCI4 | 2024-01-19 0:22:44 |
DCF-305 | Changes to all system components in the production environment (including software, code, infrastructure, network, configuration changes, etc.) are made according to established procedures that include documentation (change description, justification, evaluation of security impact, approval by authorized parties, rollback procedures) and testing (including security impact testing and code vulnerability testing for custom development changes). | Changes to all system components in the production environment (including software, code, infrastructure, network, configuration changes, etc.) are made according to established procedures that include documentation (change description, justification, evaluation of security requirements and impact, approval by authorized parties, rollback procedures, etc.) and testing (including acceptance and security impact testing). | CMMC, FEDRAMP20X, ISO270012022, ISO27701, NIST800171, NIST800171R3, NISTAI, NISTCSF2, PCI, PCI4, SOC_2 | 2024-09-05 21:51:55 |
DCF-310 | %s ensures that upon completion of a significant change, all relevant PCI DSS requirements must be implemented on all new or changed systems and networks, and documentation updated as applicable. | %s verifies all system components after a change to validate they are compliant with the applicable PCI DSS requirements. Record of the validation is documented and retained, and updates to PCI DSS requirements documentation are made as applicable based on the nature of the change. | PCI, PCI4 | 2024-01-19 0:22:44 |
DCF-312 | %s trains developers at least annually in up- to-date secure coding techniques, including how to avoid common coding vulnerabilities. | Developers are required to complete secure code development training at least once every 12 months, including training on software security relevant to their job function and development languages, secure software design and secure coding techniques, and how to use tools for detecting vulnerabilities in software if these are used in the organization. | CCM, CIS8, CMMC, FEDRAMP, ISO270012022, NIS2, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, PCI, PCI4, SOC_2 | 2024-05-07 19:18:26 |
DCF-324 | %s ensures that for public-facing web applications, new threats and vulnerabilities are addressed on an ongoing basis and ensure these applications are protected against known attacks by either of the following methods: Reviewing public-facing web applications via manual or automated application vulnerability security assessment tools or methods, at least annually and after any changes; installing an automated technical solution that detects and prevents web- based attacks in front of public- facing web applications, to continually check all traffic. | %s evaluates public-facing web applications via manual or automated application vulnerability security assessment tools at least once every 12 months and after significant changes. Vulnerabilities identified, if any, are risk-ranked and corrected, and the application is re-evaluated after the corrections. | CIS8, CYBER_ESSENTIALS, NIST80053, PCI, PCI4 | 2024-01-19 0:22:44 |
DCF-326 | %s limits access to system components and sensitive data to only those individuals whose job requires such access | %s restricts access to system components and data to only those individuals whose job requires such access. | CCM, CIS8, CMMC, CYBER_ESSENTIALS_32, DORA, FEDRAMP, ISO270012022, ISO27701, NIS2, NIST800171, NIST800171R3, NIST80053, NISTCSF2, PCI, PCI4, SOC_2 | 2024-07-11 20:02:42 |
DCF-329 | %s's access control system(s) covers all system components. | For all system components, access is managed via an access control system. The access control system(s) is configured to enforce permissions assigned to individuals, applications, and systems based on job classification and function and is set to “deny all” by default. | CCPA, CIS8, CYBER_ESSENTIALS_32, DORA, FEDRAMP20X, NIS2, NIST800171R3, NIST80053, PCI, PCI4 | 2024-09-17 22:20:24 |
DCF-330 | %s's access control system(s) is configured to enforce assignment of privileges to individuals based on job classification and function. | %s has defined and implemented an access control model for all system components (e.g., role-based access control (RBAC), attribute-based access control (ABAC), policy-based access control (PBAC), etc.). | CCM, CCPA, CIS8, CMMC, DORA, FEDRAMP, FEDRAMP20X, ISO27701, NIS2, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, PCI | 2024-07-11 20:02:42 |
DCF-335 | %s removes/disables inactive user accounts within 90 days. | %s removes or disables inactive accounts within a specified period of inactivity. | CIS8, CMMC, CYBER_ESSENTIALS_32, FEDRAMP, NIST800171, NIST800171R3, NIST80053, PCI, PCI4 | 2025-04-23 21:45:31 |
DCF-336 | %s ensures that accounts used by third parties to access, support, or maintain system components via remote access are enabled only during the time period needed, and disabled when not in use. | Accounts used by third parties to access, support, or maintain system components via remote access are enabled during the time period needed based on documented authorization by management and disabled when not in use. Third-party remote access is monitored by company personnel for unexpected activity. | DORA, FEDRAMP, NIST800171R3, NIST80053, NISTCSF, PCI, PCI4 | 2024-01-19 0:22:44 |
DCF-339 | %s ensures that non-consumer customer passwords are temporarily locked-out after not more than six invalid access attempts. | Invalid authentication attempts are limited by locking out the user ID after not more than 10 failed attempts. | CIS8, CMMC, CYBER_ESSENTIALS_32, NIST800171, NIST800171R3, PCI, PCI4, SOC_2 | 2024-09-05 21:51:55 |
DCF-340 | %s has set the lockout duration to a minimum of 30 minutes or until an administrator enables the user ID. | %s has configured account lockout duration following a set number of invalid authentication attempts to a minimum of 30 minutes or until the identity of the user is confirmed (for example, by a system administrator). | CIS8, CMMC, CYBER_ESSENTIALS_32, NIST800171, NIST800171R3, NIST80053, PCI, PCI4, SOC_2 | 2024-01-19 0:22:44 |
DCF-343 | %s uses strong cryptography to render all authentication credentials (such as passwords/phrases) unreadable during transmission and storage on all system components. | Strong cryptographic protocols are used to render all authentication credentials (e.g.,passwords, passphrases, etc.) unreadable during transmission and storage on all system components. | CCM, CMMC, NIS2, NIST800171, NIST800171R3, PCI, PCI4 | 2024-01-19 0:22:44 |
DCF-345 | %s verifies user identity before modifying any authentication credential—for example, performing password resets, provisioning new tokens, or generating new keys. | User identity is verified before allowing changes to any authentication factor (for example, performing password resets, provisioning new tokens, or generating new keys). Verification is done through secret question/answers, knowledge-based information, or other mechanisms. | CCPA, NIST800171R3, PCI, PCI4 | 2024-01-19 0:22:44 |
DCF-346 | %s ensures that passwords/passphrases must: Require a minimum length of at least seven characters; and contain both numeric and alphabetic characters. Alternatively, the passwords/ passphrases must have complexity and strength at least equivalent to the parameters specified above. | Minimum password requirements are enforced on system components including a minimum length of 12 characters (or if the system does not support 12 characters, a minimum length of eight characters) and complexity requirements to include both numbers and letters. | CCM, CIS8, CYBER_ESSENTIALS, CYBER_ESSENTIALS_32, PCI, PCI4 | 2025-01-28 20:01:13 |
DCF-348 | %s changes user passwords/passphrases at least once every 90 days. | For in-scope components that are not in the cardholder data environment (CDE) where passwords/passphrases are used as the only authentication factor, credentials are required to be changed at least once every 90 days. Alternatively, technical measures are implemented to dynamically analyze the security posture of accounts, and real-time access to resources is automatically determined accordingly. | PCI, PCI4 | 2024-01-19 0:22:44 |
DCF-349 | %s requires non-consumer customer passwords to be changed periodically, and non-consumer customers are given guidance as to when, and under what circumstances, passwords must change. | Where customer user access to cardholder data is achieved only through passwords/passphrases (i.e., single factor authentication), %s provides guidance to customer users as to how frequently, and under what circumstances, they should change their passwords. | PCI, PCI4 | 2024-01-19 0:22:44 |
DCF-350 | %s does not allow an individual to submit a new password/passphrase that is the same as any of the last four passwords/passphrases he or she has used. | System configuration settings are in place to prevent password reuse in accordance with company policy and compliance requirements. | CMMC, CYBER_ESSENTIALS_32, ISO270012022, ISO27701, NIST800171, NIST800171R3, PCI, PCI4, SOC_2 | 2024-09-05 21:51:55 |
DCF-352 | %s sets passwords/passphrases for first-time use and upon reset to a unique value for each user, and changes them immediately after the first use. | Passwords are set to a unique value for first-time use and upon reset. Temporary initial passwords are forced to be changed immediately after the first use. | CIS8, CMMC, CYBER_ESSENTIALS, CYBER_ESSENTIALS_32, FEDRAMP, ISO270012022, ISO27701, NIST800171, NIST800171R3, PCI, PCI4 | 2024-01-19 0:22:44 |
DCF-354 | %s has incorporated multi-factor authentication for all non-console access into the CDE for personnel with administrative access. | Multi-factor authentication (MFA) is required for all non-console access into the environment for personnel with administrative access. | CIS8, CYBER_ESSENTIALS_32, NIS2, PCI, PCI4 | 2024-01-19 0:22:44 |
DCF-355 | %s has incorporated multi-factor authentication for all remote network access (both user and administrator, and including third-party access for support or maintenance) originating from outside the entity’s network. | All remote access to the entity’s network and systems (including that of users, administrators, and external access from third parties or vendors including access for maintenance sessions) requires multi-factor authentication. | CCPA, CIS8, CMMC, CYBER_ESSENTIALS_32, DORA, DRATA_ESSENTIALS, FEDRAMP, FEDRAMP20X, NIS2, NIST800171, NIST800171R3, NIST80053, NISTCSF, PCI, PCI4, SOC_2 | 2024-09-05 21:51:55 |
DCF-356 | %s's authentication policies and procedures include: Guidance on selecting strong authentication credentials; guidance for how users should protect their authentication credentials; instructions not to reuse previously used passwords; instructions to change passwords if there is any suspicion the password could be compromised. | %s has documented policies and procedures for authentication that are communicated to all personnel. These documents include guidance on selecting strong authentication factors, guidance on protecting authentication credentials, instructions not to reuse previously used credentials, instructions to change authentication credentials in the event of known or suspected compromise along with guidance on how to report the incident, etc. | CIS8, CYBER_ESSENTIALS_32, FEDRAMP, ISO270012022, ISO27701, NIST80053, PCI, PCI4, SOC_2 | 2024-05-07 19:18:26 |
DCF-358 | %s ensures that service providers with remote access to customer premises must use a unique authentication credential for each customer. | %s's authentication factors and credentials used to access customer environments remotely are unique for each customer. | CYBER_ESSENTIALS_32, DORA, PCI, PCI4 | 2024-01-19 0:22:44 |
DCF-360 | %s restricts user database access, query, or action to programmatic methods. | Direct query access to cardholder data repositories is restricted via applications or other programmatic methods (e.g., stored procedures) with access and allowed actions based on user roles and least privileges, unless performed by an authorized administrator. | PCI, PCI4 | 2024-01-19 0:22:44 |
DCF-363 | %s uses appropriate facility entry controls to limit and monitor physical access to systems in the cardholder data environment. | Entry controls (e.g., badge access systems, biometrics readers, monitored reception areas or front desks, etc.) are in place to restrict physical access to corporate facilities, including systems or areas that may process or store sensitive data, to authorized personnel, and to log and monitor such access. | CCM, CMMC, DORA, FEDRAMP, ISO270012022, ISO27701, NIS2, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, PCI, PCI4, SOC_2 | 2024-09-05 21:51:55 |
DCF-364 | %s uses either video cameras or access control mechanisms (or both) to monitor individual physical access to points of entry, exits, and sensitive areas. Review collected data and correlate with other entries. Store for at least three months, unless otherwise restricted by law. | %s has developed and approved a list of individuals with authorized physical access to the facilities, equipment, and operating environments, which is maintained up-to-date and reviewed periodically to validate the ongoing appropriateness of access. Authorized individuals are issued physical authentication credentials (e.g., identification badges, identification cards, smart cards, etc.). | CCM, CMMC, DORA, FEDRAMP, NIS2, NIST800171, NIST800171R3, NIST80053, NISTCSF, PCI | 2024-09-05 21:51:55 |
DCF-365 | %s ensures that video cameras or access control mechanisms (or both) are protected from tampering or disabling. | %s physical surveillance mechanisms (e.g., video monitoring systems, sensors and detectors) are in place to deter and detect unauthorized physical access and are protected from tampering or disabling. | CCM, CMMC, DORA, FEDRAMP, ISO270012022, ISO27701, NIS2, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, PCI, PCI4, SOC_2 | 2024-01-19 0:22:44 |
DCF-366 | %s ensures that data collected from video cameras and/or access control mechanisms are reviewed and correlated with other entries. | Data collected from video cameras and/or access control mechanisms are reviewed and correlated with other entries (e.g., access logs) on a periodic basis and as needed (e.g., upon suspicious physical security activity). | CCM, DORA, FEDRAMP, NIS2, NIST800171R3, NIST80053, NISTCSF2, PCI, PCI4 | 2024-09-11 1:28:13 |
DCF-367 | %s ensures that data collected from video cameras and/or access control mechanisms is stored for at least three months unless otherwise restricted by law. | Data collected from video cameras and/or access control mechanisms is stored for at least three months unless otherwise restricted by law. | CCM, DORA, FEDRAMP, NIST80053, PCI, PCI4 | 2024-01-19 0:22:44 |
DCF-368 | %s has implemented physical and/or logical controls to restrict access to publicly accessible network jacks. Alternatively, processes could be implemented to ensure that visitors are escorted at all times in areas with active network jacks. | %s has implemented physical and/or logical controls to restrict access to publicly accessible network jacks. | CCM, DORA, FEDRAMP, NIST80053, PCI, PCI4 | 2024-01-19 0:22:44 |
DCF-369 | %s restricts physical access to wireless access points, gateways, handheld devices, networking/communications hardware, and telecommunication lines. | %s restricts physical access to wireless access points, gateways, networking/communications hardware, and telecommunication lines within the company facilities. | CCM, CMMC, DORA, ISO270012022, ISO27701, NIST800171, NIST800171R3, PCI, PCI4 | 2024-01-19 0:22:44 |
DCF-372 | %s limits access to the badge system to authorized personnel. | %s restricts access to the identification or badge system to authorized personnel based on need-to-know principles. | DORA, NIS2, PCI, PCI4, SOC_2 | 2024-01-19 0:22:44 |
DCF-374 | %s ensures that visitors are authorized before entering, and escorted at all times within, areas where cardholder data is processed or maintained. | Visitors are authorized before entering, and escorted at all times within company facilities including areas where sensitive data may be processed or stored. | CCM, CMMC, DORA, ISO270012022, ISO27701, NIST800171, NIST800171R3, NISTCSF2, PCI, PCI4, SOC_2 | 2024-09-05 21:51:55 |
DCF-375 | %s ensures that visitors are identified and given a badge or other identification that visibly distinguishes the visitors from onsite personnel. | %s personnel are required to wear a badge or other form of identification within company facilities. %s provides visitors with a badge or other form of identification that visibly distinguishes visitors from onsite personnel. | CCM, CMMC, DORA, ISO270012022, ISO27701, NIST800171, NIST800171R3, NISTCSF2, PCI, PCI4, SOC_2 | 2024-01-19 0:22:44 |
DCF-377 | %s ensures that visitors surrender the badge or identification before leaving the facility or at the date of expiration. | Visitor badges or identification are surrendered or deactivated before visitors leave the facility or at the date of expiration. | CCM, PCI, PCI4, SOC_2 | 2024-01-19 0:22:44 |
DCF-378 | %s has a visitor log to maintain a physical audit trail of visitor activity to the facility as well as computer rooms and data centers where cardholder data is stored or transmitted. | %s maintains visitor logs to keep an audit trail of visitor activity to the company facilities, computer rooms, or data centers where sensitive data may be stored or transmitted. | CCM, CMMC, DORA, FEDRAMP, ISO270012022, ISO27701, NIST800171, NIST80053, NISTCSF2, PCI, PCI4, SOC_2 | 2024-09-05 21:51:55 |
DCF-379 | %s's visitor log includes the visitor’s name, the firm represented, and the onsite personnel authorizing physical access on the log. | %s' visitor logs include, at a minimum, the visitor’s name and the organization represented, the date and time of the visit, and the name of the personnel authorizing physical access. | CCM, FEDRAMP, NIST80053, PCI, PCI4 | 2025-01-28 20:01:13 |
DCF-381 | %s physically secures all media. | Media with sensitive data is physically secured to prevent unauthorized persons from gaining access to it. | CCM, CMMC, DORA, FEDRAMP, ISO270012022, ISO27701, NIST800171, NIST800171R3, NIST80053, NISTCSF, PCI, PCI4, SOC_2 | 2024-09-05 21:51:55 |
DCF-382 | %s stores media backups in a secure location, preferably an off-site facility, such as an alternate or backup site, or a commercial storage facility. Review the location’s security at least annually. | %s stores offline media backups in a secure location (e.g., off-site facility, commercial storage facility, etc.) with security measures to protect the confidentiality of the information. The security of the location is reviewed at least once every 12 month through inspection of the facilities. Results of the review are documented. | CMMC, DORA, FEDRAMP, NIST800171, NIST800171R3, NIST80053, PCI, PCI4 | 2024-09-05 21:51:55 |
DCF-384 | %s classifies media so the sensitivity of the data can be determined. | All media with sensitive data is classified in accordance with the nature of the data and the company's data classification policy. | CCM, DORA, FEDRAMP, ISO270012022, ISO27701, NIST80053, PCI, PCI4 | 2024-01-19 0:22:44 |
DCF-385 | %s sends the media by secured courier or other delivery method that can be accurately tracked. | Media with sensitive data transported within or outside the company's facilities is logged, securely transported (e.g., via secure courier or other trackable method), and captured within tracking logs to include details about media location, responsible party, etc. | CMMC, DORA, FEDRAMP, ISO270012022, ISO270182019, ISO27701, NIST800171, NIST800171R3, NIST80053, PCI, PCI4 | 2024-07-11 20:02:42 |
DCF-386 | %s management approves any and all media that is moved from a secured area (including when media is distributed to individuals). | Management approves all assets (including media with sensitive data) that are moved within or outside the facility, including when the assets are distributed to individuals. Documentation of management's approval for the movement of assets is retained. | CMMC, DORA, ISO270012022, ISO270182019, ISO27701, NIST800171, NIST800171R3, PCI, PCI4 | 2024-07-11 20:02:42 |
DCF-388 | %s properly maintains inventory logs of all media. | %s maintains documented inventory all electronic media with sensitive data. A verification of the inventory is conducted at least once every 12 months in accordance with company procedures. | CMMC, ISO270012022, ISO27701, NIST800171, NIST800171R3, NIST80053, PCI, PCI4 | 2024-01-19 0:22:44 |
DCF-390 | %s destroys media when it is no longer needed for business or legal reasons. | Electronic media is destroyed or sensitive data is rendered unrecoverable so that it cannot be reconstructed when no longer needed for business or legal reasons. | CCM, CIS8, FEDRAMP, ISO270012022, ISO27701, NIST80053, NISTCSF, PCI, PCI4 | 2024-01-19 0:22:44 |
DCF-391 | %s has policies and procedures for the periodic destruction of media. | %s has policies and procedures for the destruction of electronic media when no longer needed for business or legal reasons. | CCM, FEDRAMP, NIST80053, NISTCSF, PCI, PCI4 | 2024-01-19 0:22:44 |
DCF-397 | %s ensures that policies and procedures require that devices are periodically inspected to look for tampering or substitution. | %s performs periodic inspections of point of interaction (POI) device surfaces to detect tampering and unauthorized substitution in accordance with documented company policies and procedures. | PCI, PCI4 | 2024-01-19 0:22:44 |
DCF-404 | %s's training materials for personnel at point-of-sale locations include the following: Verify the identity of any third-party persons claiming to be repair or maintenance personnel, prior to granting them access to modify or troubleshoot devices; do not install, replace, or return devices without verification; be aware of suspicious behavior around devices; report suspicious behavior and indications of device tampering or substitution to appropriate personnel. | %s provides periodic training for personnel in point-of-interaction (POI) environments to be aware of attempted tampering or replacement of POI devices including: verifying the identity of any third-party persons claiming to be repair or maintenance personnel prior to granting them access to modify or troubleshoot devices; procedures to ensure devices are not installed, replaced, or returned without verification; being aware of suspicious behavior around devices, and reporting suspicious behavior and indications of device tampering or substitution to appropriate personnel. | PCI, PCI4 | 2024-01-19 0:22:44 |
DCF-406 | %s's audit trails are enabled and active for system components. | Audit logs are enabled and active for all system components and sensitive data in accordance with company policies. | CIS8, CMMC, DORA, FEDRAMP, ISO270012022, NIST800171, NIST800171R3, NIST80053, NISTCSF2, PCI, PCI4, SOC_2 | 2025-10-06 23:16:27 |
DCF-407 | %s has implemented audit trails to link all access to system components to each individual user. | %s has configured audit logs to contain user or identity, type of event, date and time, success and failure indication, origination of event, affected data, and system component, resource, or service. | CIS8, CMMC, ISO270012022, ISO27701, ISO420012023, NIST800171, NIST800171R3, NIST80053, NISTCSF2, PCI, PCI4, SOC_2 | 2025-10-06 23:16:27 |
DCF-408 | %s ensures that automated audit trails are implemented for all system components to reconstruct all individual user accesses to cardholder data. | Automated audit trails or logs are implemented for all system components to capture all access to cardholder data. | CIS8, PCI, PCI4 | 2024-01-19 0:22:44 |
DCF-409 | %s ensures that automated audit trails are implemented for all system components to reconstruct all actions taken by any individual with root or administrative privileges. | Automated audit trails or logs are implemented for all system components to capture all actions taken by any identities with administrative access, including execution of privileged functions and any interactive use of application or system accounts. | CCM, CIS8, CMMC, CYBER_ESSENTIALS_32, DORA, FEDRAMP, ISO270012022, ISO27701, NIST800171, NIST800171R3, NIST80053, PCI, PCI4, SOC_2 | 2024-09-05 21:51:55 |
DCF-410 | %s ensures that automated audit trails are implemented for all system components to reconstruct access to all audit trails. | Automated audit trails or logs are implemented for all system components to capture all access to audit logs. | CIS8, CMMC, DORA, FEDRAMP, ISO27701, NIST800171, NIST80053, PCI, PCI4 | 2024-07-11 20:02:42 |
DCF-411 | %s ensures that automated audit trails are implemented for all system components to reconstruct invalid logical access attempts. | Automated audit trails or logs are implemented for all system components to capture all invalid access attempts. | CIS8, DORA, FEDRAMP, ISO270012022, NIST800171R3, NIST80053, NISTCSF2, PCI, PCI4, SOC_2 | 2024-01-19 0:22:44 |
DCF-412 | %s ensures that automated audit trails are implemented for all system components to reconstruct use of and changes to identification and authentication mechanisms⎯including but not limited to creation of new accounts and elevation of privileges⎯and all changes, additions, or deletions to accounts with root or administrative privileges. | Automated audit trails or logs are implemented to capture all changes to identification and authentication credentials (e.g., creation of new accounts, elevation of privileges, changes, additions, or deletions to accounts with administrative access, etc.). | CCM, CIS8, DORA, FEDRAMP, ISO270012022, NIST80053, NISTCSF2, PCI, PCI4, SOC_2 | 2024-01-19 0:22:44 |
DCF-413 | %s ensures that automated audit trails are implemented for all system components to reconstruct initialization, stopping, or pausing of the audit logs. | Automated audit trails or logs are implemented for all system components to capture initialization of new audit logs and all starting, stopping, or pausing of the existing audit logs. | CIS8, CMMC, DORA, FEDRAMP, NIST800171, NIST800171R3, NIST80053, PCI, PCI4 | 2024-01-19 0:22:44 |
DCF-414 | %s ensures that automated audit trails are implemented for all system components to reconstruct creation and deletion of system-level objects. | Automated audit trails or logs are implemented for all system components to capture all creation and deletion of system-level objects. | CIS8, DORA, ISO270012022, PCI, PCI4, SOC_2 | 2024-05-07 19:18:26 |
DCF-421 | %s synchronizes all critical system clocks and times using time-synchronization technology, and ensures that the following is implemented for acquiring, distributing, and storing time. | %s synchronizes all critical system clocks and times using time-synchronization technology such as Network Time Protocol (NTP). | CCM, CIS8, CMMC, FEDRAMP, ISO270012022, ISO270172015, ISO27701, NIST800171, NIST800171R3, NIST80053, PCI, PCI4 | 2024-01-19 0:22:44 |
DCF-422 | %s only designated central time server(s) receive time signals from external sources, and time signals from external sources are based on International Atomic Time or UTC. | Systems are configured so that one or more designated central time servers are in use and receiving time from industry-accepted external sources based on International Atomic Time or Coordinated Universal Time (UTC). | CIS8, CMMC, ISO270012022, ISO27701, NIST800171, NIST800171R3, PCI, PCI4 | 2024-01-19 0:22:44 |
DCF-423 | %s ensures that where there is more than one designated time server, the time servers peer with each other to keep accurate time. | Where there is more than one designated time server, the time servers peer with one another to keep accurate time. | CIS8, ISO270012022, ISO27701, PCI, PCI4 | 2024-01-19 0:22:44 |
DCF-424 | %s's systems receive time only from designated central time server(s). | Internal systems receive time information only from designated central time server or servers. | ISO270012022, ISO27701, NIST800171R3, PCI, PCI4 | 2024-01-19 0:22:44 |
DCF-425 | %s restricts access to time data to only personnel with a business need. | Access to modify time synchronization configurations or system time is restricted to authorized system administrators or personnel with a business need. | FEDRAMP, NIST80053, PCI, PCI4 | 2024-01-19 0:22:44 |
DCF-426 | %s ensures that changes to time settings on critical systems are logged, monitored, and reviewed. | Any changes to time synchronization configurations or system time on critical systems are logged, monitored, and reviewed in accordance with company policies and procedures. | PCI, PCI4 | 2024-01-19 0:22:44 |
DCF-429 | %s limits viewing of audit trails to those with a job-related need. | Access to audit log files and associated configurations is limited to those with a job-related need as authorized by management. | CCM, CMMC, FEDRAMP, ISO270012022, ISO27701, NIST800171, NIST800171R3, NIST80053, NISTCSF2, PCI, PCI4 | 2024-01-19 0:22:44 |
DCF-430 | %s protects audit trail files from unauthorized modifications. | Audit log files are protected to prevent modifications by individuals (e.g., via access control mechanisms, physical segregation, network segregation, etc.) | CMMC, FEDRAMP, ISO270012022, ISO27701, NIST800171, NIST800171R3, NIST80053, NISTCSF2, PCI, PCI4 | 2024-01-19 0:22:44 |
DCF-431 | %s promptly backs up audit trail files to a centralized log server or media that is difficult to alter. | Audit log files, including those for external facing technologies, are promptly backed up to a secure, central, internal log server(s) or other media that is difficult to modify. | NISTCSF2, PCI, PCI4 | 2024-01-19 0:22:44 |
DCF-434 | %s has policies and procedures for reviewing the following critical system logs: All security events; logs of all system components that store, process, or transmit CHD and/or SAD; logs of all critical system components; logs of all servers and system components that perform security functions | %s has documented policies and procedures for logging and monitoring that describe the events the organization must log and monitor, the general systems and system components that should be monitored, the specific information that must be captured in logs, the configuration of specific elements of the logging infrastructure, etc. The identified logged/monitored events are reviewed and updated periodically in accordance with company requirements. | CIS8, CMMC, DORA, ISO270012022, ISO27701, ISO420012023, NIST800171, NIST800171R3, NIST80053, NISTCSF2, PCI, PCI4 | 2024-09-05 21:51:55 |
DCF-435 | %s's critical system logs are reviewed at least daily. | %s performs reviews of the following critical audit logs at least daily (e.g., through the use of alerting mechanisms): all security events, logs of all system components that store, process, or transmit CHD and/or SAD, logs of all critical system components, and logs of all servers and system components that perform security functions. | CIS8, DORA, PCI, PCI4 | 2024-01-19 0:22:44 |
DCF-437 | %s reviews logs of all other system components periodically based on the organization’s policies and risk management strategy, as determined by the organization’s annual risk assessment. | %s performs reviews of non-critical system logs periodically based on the organization’s policies and risk management strategy, as determined by a risk assessment. | CIS8, DORA, NISTCSF2, PCI, PCI4 | 2024-01-19 0:22:44 |
DCF-438 | %s conducts follow up on exceptions and anomalies identified during the review process. | Exceptions and anomalies identified during the periodic log-review process are investigated, escalated, and resolved in accordance with the company's documented policies and procedures. | DORA, NISTCSF2, PCI, PCI4 | 2024-01-19 0:22:44 |
DCF-441 | %s retains audit logs for at least one year. | %s retains audit log history and historical records of activity for a specified frequency (e.g., minimum of 90 days for CIS 8; or at least 12 months, with at least the most recent three months immediately available for analysis, for PCI 4). | CIS8, CMMC, DORA, ISO270012022, ISO27701, NIST800171, PCI, PCI4 | 2025-04-23 21:45:32 |
DCF-444 | %s ensures that failure of a critical security control results in the generation of an alert. | %s has implemented alerting mechanisms to notify personnel of failures of critical security control systems (including network security controls, IDS/IPS, change-detection mechanisms, anti-malware solutions, physical access controls, logical access controls, audit logging mechanisms, segmentation controls, audit log review mechanisms, automated security testing tools, etc.). Failures of critical security control systems are evaluated as a security event and investigated in accordance with company policies and procedures. | CIS8, CMMC, DORA, FEDRAMP, NIST800171, NIST800171R3, NIST80053, NISTCSF, PCI, PCI4 | 2024-01-19 0:22:44 |
DCF-445 | %s has a processes for responding to critical security control failures defined and implemented, which includes: Restoring security functions; identifying and documenting the duration (date and time start to end) of the security failure; identifying and documenting cause(s) of failure, including root cause, and documenting remediation required to address root cause; identifying and addressing any security issues that arose during the failure; implementing controls to prevent cause of failure from reoccurring; resuming monitoring of security controls. | Failures of any critical security controls systems are addressed promptly based on the nature of the failure and monitoring of security controls is resumed. Documentation is maintained to include identification of the issue, start time and end time, root cause and required remediation, identification of any security issues that arose during the failure along with associated response, identification of follow-up actions are required as a result of the security failure, and implemented controls to prevent the cause of failure from reoccurring. | DORA, FEDRAMP, NIST800171R3, NIST80053, PCI, PCI4 | 2024-01-19 0:22:44 |
DCF-447 | %s has security policies and operational procedures for monitoring all access to network resources and cardholder data that are documented, in use, and known to all affected parties. | %s has security policies and operational procedures for monitoring all access to network resources and sensitive information (e.g., PII, PHI, Cardholder Data, etc.) that are documented, in use, and known to all affected parties. | DORA, FEDRAMP, NIST80053, PCI | 2025-10-06 23:16:27 |
DCF-448 | %s has implemented processes to test for the presence of wireless access points (802.11), and detects and identifies all authorized and unauthorized wireless access points on a quarterly basis. | %s conducts tests (either through manual verification or automated mechanisms) to identify the presence of authorized and unauthorized wireless (Wi-Fi) access points periodically per policy and compliance requirements. If automated monitoring is used, personnel are notified via generated alerts. Results are documented. | NIST80053, NISTCSF2, PCI, PCI4 | 2024-09-11 1:28:13 |
DCF-452 | %s maintains an inventory of authorized wireless access points including a documented business justification. | %s maintains a documented inventory of authorized wireless access points including business justification. | CMMC, CYBER_ESSENTIALS_32, FEDRAMP, NIST800171, NIST800171R3, NIST80053, PCI, PCI4 | 2024-09-05 21:51:55 |
DCF-454 | %s takes action when unauthorized wireless access points are found. | %s executes an incident response process in the event unauthorized wireless access points are detected in accordance with the company's documented policies and procedures. | NIS2, NIST80053, PCI, PCI4 | 2024-01-19 0:22:44 |
DCF-455 | %s performs quarterly internal vulnerability scans. | %s conducts internal vulnerability scans at least once every three months or upon significant changes to network or systems. The scan tool is kept up to date with latest vulnerability information. | CIS8, PCI, PCI4 | 2025-04-23 21:45:32 |
DCF-456 | %s addresses vulnerabilities and performs rescans to verify all “high risk” vulnerabilities are resolved in accordance with the entity’s vulnerability ranking. | All critical or high vulnerabilities identified are addressed immediately and a subsequent scan is performed to validate resolution. All other applicable vulnerabilities are addressed based on the company's evaluation of risk per documented policies and procedures and rescans are conducted as needed to confirm resolution. | CIS8, CMMC, CYBER_ESSENTIALS, CYBER_ESSENTIALS_32, DORA, FEDRAMP20X, ISO27701, NIS2, NIST800171, NIST800171R3, NISTCSF2, PCI, PCI4 | 2024-09-05 21:51:55 |
DCF-458 | %s performs quarterly external vulnerability scans, via an Approved Scanning Vendor (ASV) approved by the Payment Card Industry Security Standards Council (PCI SSC). | External vulnerability scans are performed at least once every three months by a PCI SSC Approved Scanning Vendor (ASV). Vulnerabilities are resolved and ASV Program Guide requirements for a passing scan are met. Rescans are performed as needed to confirm that vulnerabilities are resolved. | PCI, PCI4 | 2024-01-19 0:22:44 |
DCF-461 | %s performs internal and external scans, and rescans as needed, after any significant change. Scans are performed by qualified personnel. | External vulnerability scans are performed after any significant change in the environment by qualified personnel on all system components affected by the change. Organizational independence of the tester is maintained. Vulnerabilities that are scored 4.0 or higher by the CVSS are resolved and rescans are conducted as needed to validate corrections. | DORA, PCI, PCI4 | 2024-01-19 0:22:44 |
DCF-463 | %s ensures that vulnerability scans are performed by a qualified internal resource(s) or qualified external third party, and if applicable, organizational independence of the tester exists. | %s assigns a qualified internal resource(s) or qualified external third party to perform internal vulnerability scans. Organizational independence of the tester exists to maintain segregation of duties in the process. | DORA, PCI, PCI4 | 2024-01-19 0:22:44 |
DCF-464 | %s has implemented a methodology for penetration testing that: Is based on industry-accepted penetration testing approaches; includes coverage for the entire CDE perimeter and critical systems; includes testing from both inside and outside the network; includes testing to validate any segmentation and scope-reduction controls; defines application-layer penetration tests to include, at a minimum, the vulnerabilities listed in Requirement 6.5; defines network-layer penetration tests to include components that support network functions as well as operating systems; includes review and consideration of threats and vulnerabilities experienced in the last 12 months; specifies retention of penetration testing results and remediation activities results. | %s has defined and documented a penetration testing methodology for the organization. The methodology includes industry-accepted penetration testing approaches, coverage for the entire CDE perimeter and critical systems, testing from both inside and outside the network, testing to validate any segmentation and scope reduction controls, application-layer penetration testing, network layer penetration tests, review and consideration of threats and vulnerabilities experienced in the last 12 months, documented approach to assessing and addressing the risk posed by exploitable vulnerabilities and security weaknesses found during penetration testing, and retention of penetration testing results and remediation activities results for at least 12 months. | CIS8, NIST80053, NISTCSF, PCI, PCI4 | 2024-01-19 0:22:44 |
DCF-465 | %s perform external penetration testing per the defined methodology, at least annually, and after any significant infrastructure or application changes to the environment. | %s conducts external penetration tests at least once every 12 months or after any significant infrastructure or application upgrade or change per the company's defined methodology. Testing is performed by a qualified internal resource or qualified external third party and organizational independence of the tester is maintained. | CIS8, DORA, NIST80053, NISTCSF, PCI, PCI4 | 2024-01-19 0:22:44 |
DCF-467 | %s perform internal penetration testing at least annually and after any significant infrastructure or application upgrade or modification. | %s conducts internal penetration tests at least once every 12 months and after any significant infrastructure or application upgrade or change per the company's defined methodology. Testing is performed by a qualified internal resource or qualified external third-party and organizational independence of the tester is maintained. | CIS8, DORA, NIST80053, NISTCSF, PCI, PCI4 | 2024-01-19 0:22:44 |
DCF-469 | %s ensures that exploitable vulnerabilities found during penetration testing are corrected and testing is repeated to verify the corrections. | %s corrects exploitable vulnerabilities and security weaknesses found during penetration testing based on the assessment of the risk posed by the security issue and in accordance with company policies and procedures. Penetration testing is repeated to verify the corrections. | CIS8, NIS2, PCI, PCI4 | 2024-01-19 0:22:45 |
DCF-470 | %s's penetration-testing procedures are defined to test all segmentation methods, to confirm they are operational and effective, and isolate all out-of-scope systems from systems in the CDE. | Where segmentation is used to isolate the CDE from other networks, %s conducts penetration periodically and after any changes to segmentation controls/methods to validate segmentation and isolation mechanisms are operational and effective. Testing covers all methods in use per the company's defined methodology and is performed by a qualified internal resource or qualified external third party with organizational independence of the tester. | PCI, PCI4 | 2024-01-19 0:22:45 |
DCF-473 | %s ensures that PCI DSS scope is confirmed by performing penetration tests on segmentation controls at least every six months and after any changes to segmentation controls/methods. | For mutitenant service providers, a penetration test is performed at least every six months to validate the effectiveness of logical separation controls used to separate customer environments. | PCI, PCI4 | 2024-01-19 0:22:45 |
DCF-477 | %s keeps all intrusion-detection and prevention engines, baselines, and signatures up-to-date. | Intrusion-detection and/or intrusion-prevention techniques are configured to keep all engines, baselines, and signatures up to date. | CCM, CIS8, CMMC, CYBER_ESSENTIALS_32, NIST800171, NISTCSF2, PCI, PCI4 | 2024-01-19 0:22:45 |
DCF-478 | %s deploys a change-detection mechanism to detect unauthorized modification (including changes, additions, and deletions) of critical system files, configuration files, or content files. | %s has enabled file integrity monitoring or a change-detection mechanism to detect unauthorized modification (including changes, additions, and deletions) of critical system files, configuration files, audit files, or content files to ensure critical data cannot be changed without generating alerts. | CCM, CMMC, DORA, FEDRAMP, ISO270012022, ISO270172015, ISO27701, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, PCI, PCI4, SOC_2 | 2024-12-11 14:45:49 |
DCF-479 | %s deploys a change-detection mechanism to alert personnel to unauthorized modification (including changes, additions, and deletions) of critical system files, configuration files, or content files; and configure the software to perform critical file comparisons at least weekly. | %s file integrity monitoring or change-detection mechanism perform critical file comparisons at least once weekly. | DORA, NIST80053, NISTCSF, PCI, PCI4 | 2024-01-19 0:22:45 |
DCF-482 | %s has included explicit approval by authorized parties in critical technologies usage policy. | %s has documented and implemented acceptable use policies for end-user technologies (e.g., remote access and wireless technologies, laptops, tablets, mobile phones, removable electronic media, email usage, internet, etc.), which include explicit approval by authorized parties, acceptable uses of the technology, and list of products approved by the company for employee use, including hardware and software. | CCM, CYBER_ESSENTIALS_32, DORA, FEDRAMP, PCI, PCI4 | 2024-01-19 0:22:45 |
DCF-488 | %s has included automatic disconnect of sessions for remote-access technologies after a specific period of inactivity in critical technologies usage policy. | %s has implemented technical controls to terminate network connections (including remote connections) associated with communications sessions at the end of the session and after a defined period of inactivity in accordance with company policies and procedures (e.g., de-allocating associated TCP/IP address or port pairs at the operating system level). | CMMC, DORA, FEDRAMP, NIS2, NIST800171, NIST800171R3, NIST80053, PCI | 2024-09-05 21:51:55 |
DCF-490 | %s prohibits, for personnel accessing cardholder data via remote-access technologies, the copying, moving, and storage of cardholder data onto local hard drives and removable electronic media, unless explicitly authorized for a defined business need. Where there is an authorized business need, the usage policies must require the data be protected in accordance with all applicable PCI DSS Requirements. | %s prohibits, for personnel accessing sensitive information (e.g., PII, PHI, Cardholder Data, etc.) via remote-access technologies, the copying, moving, and storage of sensitive information (e.g., PII, PHI, Cardholder Data, etc.) onto local hard drives and removable electronic media, unless explicitly authorized for a defined business need. | DORA, FEDRAMP, NIST80053, PCI | 2025-10-06 23:16:27 |
DCF-493 | %s's executive management shall establish responsibility for the protection of cardholder data and a PCI DSS compliance program. | %s's executive management has defined a charter for the PCI DSS compliance program. The charter assigns responsibility within executive management for the protection of cardholder data and overall accountability for maintaining PCI DSS compliance, and establishes communication requirements to provide executive management and board of directors updates regarding PCI DSS compliance activities at least once every 12 months. | PCI, PCI4 | 2024-01-19 0:22:45 |
DCF-496 | %s has formally assigned the responsibility for information security to a Chief Security Officer or other security-knowledgeable member of management. | %s has formally assigned and documented the responsibility for information security to a Chief Security Officer or other security-knowledgeable member of management | PCI, PCI4 | 2024-01-19 0:22:45 |
DCF-499 | %s has established, documented, and distributed security incident response and escalation procedures to ensure timely and effective handling of all situations. | %s's incident response plan includes roles, responsibilities, and communication and contact strategies in the event of a suspected or confirmed security incident (including notification of payment brands and acquirers), incident response procedures with specific containment and mitigation activities for different types of incidents, business recovery and continuity procedures, data backup processes, analysis of legal requirements for reporting compromises, coverage and responses of all critical system components, and reference or inclusion of incident response procedures from the payment brands. | CCM, ISO270172015, PCI, PCI4 | 2024-01-19 0:22:45 |
DCF-503 | %s's security awareness program provides multiple methods of communicating awareness and educating personnel. | %s's security awareness program includes multiple methods of communicating awareness and educating personnel, such as newsletters, web-based training, in-person training, team meetings, phishing simulations, etc. Periodic security updates are provided to personnel through these multiple methods of communication. | CMMC, DORA, FEDRAMP, ISO270012022, ISO27701, NIS2, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, PCI, PCI4, SOC_2 | 2024-01-19 0:22:45 |
DCF-504 | %s's employees have completed awareness training and are aware of the importance of cardholder data security. | Security awareness training materials include information %s's security policy, phishing and related attacks, social engineering, awareness about the acceptable use of end-user technologies, and personnel's role in protecting cardholder data. | CIS8, NIST800171R3, PCI, PCI4 | 2024-01-19 0:22:45 |
DCF-507 | %s ensures that there is an established process for engaging service providers including proper due diligence prior to engagement. | %s performs due diligence activities prior to engaging with a new service provider or vendor (e.g., review of security questionnaires and compliance reports, review of vendor-provided policies, procedures, or other documents, analysis of delegated or shared responsibilities with the prospective vendor, etc.). Results of the due diligence activities including action items are documented. | CIS8, CMMC, DORA, FEDRAMP20X, ISO270012022, ISO27701, NIS2, NIST800171, NISTCSF2, PCI, PCI4, SOC_2 | 2024-09-05 21:51:55 |
DCF-509 | %s maintains information about which PCI DSS requirements are managed by each service provider, and which are managed by the entity. | %s maintains documented information about which PCI DSS requirements are managed by each service provider, which are managed by the entity, and any shared responsibilities between service providers and the entity. | PCI, PCI4 | 2024-01-19 0:22:45 |
DCF-510 | %s acknowledges in writing to customers that they are responsible for the security of cardholder data the service provider possesses or otherwise stores, processes, or transmits on behalf of the customer, or to the extent that they could impact the security of the customer’s cardholder data environment. | %s acknowledges in writing to customers through contracts, service agreements, or other means, that %s will be responsible for the security of account data it possesses or otherwise stores, processes, or transmits on behalf of its customers, or to the extent that the company could impact the security of the customer’s CDE. | CIS8, DORA, PCI, PCI4 | 2024-01-19 0:22:45 |
DCF-516 | %s provides appropriate training to staff with security breach response responsibilities. | %s provides incident response training to personnel consistent with their assigned roles and responsibilities (e.g., incident identification and reporting for all personnel vs. incident handling for incident response team members, etc.). Personnel complete training within the timelines established in policies and procedures upon receiving system access or assuming an incident response role or responsibility, when required by system changes, and at periodic intervals. | CCM, CMMC, DORA, NIS2, NIST800171, NIST800171R3, NIST80053, NISTCSF2, PCI, PCI4 | 2024-09-05 21:51:55 |
DCF-517 | %s includes alerts from security monitoring systems, including but not limited to intrusion-detection, intrusion-prevention, firewalls, and file-integrity monitoring systems. | %s's security incident response plan includes procedures for monitoring and responding to alerts from security monitoring systems including intrusion-detection and intrusion-prevention systems, network security controls, change-detection mechanisms for critical files, the change-and tamper-detection mechanism for payment pages, detection of unauthorized wireless access points, etc. | CCM, DORA, NIST80053, NISTCSF, PCI, PCI4 | 2024-01-19 0:22:45 |
DCF-519 | %s performs reviews to confirm personnel are following security policies and operational procedures. Reviews must cover the following processes: Daily log reviews; firewall rule-set reviews; applying configuration standards to new systems; responding to security alerts: change management processes. | Management performs reviews at least once every three months to confirm that personnel are performing their tasks in accordance with all security policies and operational procedures. Reviews are performed with segregation of duties and include the following tasks: daily log reviews, configuration reviews for network security controls, applying configuration standards to new systems, responding to security alerts, and change-management processes. Results of the reviews are documented and retained. | CCM, PCI, PCI4 | 2024-01-19 0:22:45 |
DCF-521 | %s maintain documentation of quarterly review process to include: Documenting results of the reviews: review and sign-off of results by personnel assigned responsibility for the PCI DSS compliance program. | Management documents the results of the reviews performed by management to confirm that personnel are performing their tasks in accordance with all security policies and operational procedures. The documentation includes remediation actions taken for any tasks that were found to not be performed and sign-off of results by personnel assigned responsibility for the PCI DSS compliance program. | PCI, PCI4 | 2024-01-19 0:22:45 |
DCF-527 | %s has formally assigned an independent and capable member to manage privacy-related matters. | %s has appointed and documented responsibilities of an individual (e.g., data protection officer) responsible for developing, implementing, maintaining and monitoring an organization-wide governance and privacy program and acting as a point of contact to authorities and data subjects to ensure compliance with all applicable laws and regulations regarding the processing of PII. | GDPR, ISO270012022, ISO27701, NIST80053, SOC_2 | 2024-05-07 19:18:26 |
DCF-529 | %s has established a process to obtain consent from a data subject prior to collecting PII. | %s has documented and implemented a process to obtain consent from data subjects prior to collecting PII. The organization obtains and records consent from data subjects according to the documented process. | CCPA, GDPR, ISO270182019, ISO27701, NIST80053, NISTAI, SOC_2 | 2024-05-07 19:18:26 |
DCF-530 | %s has an established process for acknowledging, logging and documenting withdrawal of consent. | %s provides mechanisms for data subjects to modify or withdraw their consent. %s acknowledges, logs, and documents instances of withdrawals of consent. | CCPA, GDPR, ISO270182019, ISO27701 | 2024-07-11 20:02:42 |
DCF-531 | %s properly reports and retains records of PII disclosures to include PII disclosed to third parties, requests for legally-binding PII disclosures, subcontractors/sub-processors used for PII processing in accordance with contractual requirements, and changes in subcontractors. | %s documents and maintains a record of authorized disclosures of PII to third parties (including what PII has been disclosed, to whom and when). %s also notifies customers of any legally binding requests for disclosure of PII, unless prohibited by law. | CCPA, GDPR, ISO270182019, ISO27701, SOC_2 | 2024-05-07 19:18:26 |
DCF-533 | %s has determined roles and responsibilities for the processing of PII with joint PII controllers. | %s has established and documented roles and responsibilities for the processing of PII (including PII protection and security requirements) with any joint PII controller (for example, through a joint controller agreement). The established roles and responsibilities are communicated to data subjects. | GDPR, ISO27701 | 2024-07-11 20:02:42 |
DCF-534 | %s communicates its obligations to data subjects in a clear and transparent manner. | %s provides data subjects with clear and easily accessible information identifying the PII controller and describing the processing of their PII. | CCPA, GDPR, ISO27701 | 2024-07-11 20:02:42 |
DCF-536 | %s has an established and documented record of processing activity (ROPA), which includes evidence of lawful collection and use, including defined purpose of processing. | %s has established and documented records of processing activity (ROPA), which includes descriptions of the of lawful collection and use of PII as well as the specific purposes for which PII is processed. | CCM, CCPA, GDPR, ISO270182019, ISO27701, NIST80053, SOC_2 | 2024-07-11 20:02:42 |
DCF-537 | %s has data processing agreements in place with data processing ecosystem parties which include minimum technical and organizational measures designed to meet the objectives of %s’s privacy program. | %s has data processing agreements (DPAs) in place with sub-processors that include the minimum technical and organizational measures that the third parties need to implement to meet the objectives of %s’s privacy program. | CCPA, GDPR, ISO270182019, ISO27701, NIST80053, SOC_2 | 2024-05-07 19:18:26 |
DCF-538 | %s conducts a data protection impact assessment when required or when planning for the processing of new, or changing the processing of existing, PII. | %s conducts a data protection impact assessment when planning for the processing of new PII, changing the processing of existing PII, or as otherwise required. Results of the assessment are documented and retained. | CCM, GDPR, ISO27701, NIST80053, NISTAI | 2024-07-11 20:02:42 |
DCF-540 | %s tracks and manages requests from data subjects, and provides a response to valid requests within appropriate time. | Upon receiving a privacy right request, privacy inquiry, or privacy incident report, %s provides confirmation of receipt and responds to the request, inquiry, or report within the timeframes established by regulatory requirements. | CCM, CCPA, GDPR, ISO27701, NIST80053, SOC_2 | 2024-05-07 19:18:26 |
DCF-541 | %s has an established processes to properly manage data subject rights. | %s has defined and documented policies and procedures for handling and responding to requests from data subjects to exercise their data subject rights. | CCM, CCPA, GDPR, ISO27701, SOC_2 | 2024-05-07 19:18:26 |
DCF-545 | %s has a defined Personal Data Management Policy that outlines how personal data will be managed across the organization, in accordance with applicable privacy laws and regulations. | %s has a defined a policy for the management of personally identifiable information (PII) that outlines how PII is managed by the organization, in accordance with applicable privacy laws and regulations. | CCPA, ISO27701 | 2024-07-11 20:02:42 |
DCF-549 | %s has an established process for identity verification for requests made by data subjects or authorized agents. | %s has established, documented, and implemented a method for verifying that the person making a privacy right request is the data subject or an authorized agent. If %s cannot confirm the identity or authorization of the requestor, %s notifies the requestor, denies the request, and retains supporting documentation. | CCPA, ISO27701, SOC_2 | 2024-05-07 19:18:26 |
DCF-557 | %s has an established process for managing shared and group accounts. | Group, shared, or generic account usage is prevented unless strictly necessary and supported by documented business justification and management approval. Mechanisms are in place to confirm individual user identity before access to the account is granted and to trace every action to an individual user. | CMMC, FEDRAMP, ISO270012022, ISO27701, NIST800171, NIST800171R3, NIST80053, PCI4, SOC_2 | 2024-01-19 0:22:45 |
DCF-558 | %s has a deny-all, allow-by-exception rule in place for authorized software applications and implements procedures to allow execution. | %s has identified allowed software programs in the organization and implemented mechanisms to restrict and monitor the installation and execution of unauthorized software (e.g., through procedural methods or automated mechanisms such as corporate app stores and deny-all, allow-by-exception rules). The list of allowed software is reviewed and updated periodically as determined by the organization. | CIS8, CMMC, CYBER_ESSENTIALS, CYBER_ESSENTIALS_32, FEDRAMP, ISO270012022, ISO27701, NIST800171, NIST800171R3, NIST80053, NISTCSF2, SOC_2 | 2024-09-05 21:51:55 |
DCF-562 | %s has an established process for managing the use of utility programs. | Access to manage utility programs (including anti-virus consoles and diagnostic, patching, backup, or network tools, or any other utility can be capable of overriding system and application controls) is restricted to authorized system administrators. Standard users cannot disable privileged utilities or modify their configurations. | CMMC, ISO270012022, ISO270172015, ISO27701, NIST800171, NIST800171R3, PCI4, SOC_2 | 2024-05-07 19:18:26 |
DCF-564 | %s ensures that the development and test environments are properly protected through appropriate measures (e.g., updates, monitoring and access control, backups). | %s ensures that the development and test environments are properly through appropriate measures (e.g., updates, monitoring and access control, backups). | CCM | 2024-05-07 19:18:26 |
DCF-566 | %s has an established process to properly manage and track non-conformities. | When a nonconformity is identified, %s performs a root-cause analysis and implements corrective actions to address the nonconformity. %s retains documentation of the analysis and subsequent actions taken and of the results of any corrective action. | CCM, CIS8, CMMC, DORA, ISO270012022, ISO27701, NIS2, NIST800171, NIST800171R3, NISTCSF2 | 2024-05-07 19:18:26 |
DCF-567 | %s has a defined Change Management Policy that covers policies and procedures to manage changes across the organization in a well-communicated, planned and predictable manner that minimizes unplanned outages and unforeseen system issues. | %s has a documented a policy that describes the requirements for managing changes across the organization, including changes to infrastructure, systems, and applications. | CCM, DORA, FEDRAMP, FEDRAMP20X, ISO270012022, ISO270172015, ISO27701, NIS2, NIST80053, NISTAI, NISTCSF, NISTCSF2, SOC_2 | 2024-05-07 19:18:26 |
DCF-575 | %s has a defined maintenance management policy to ensure that IT resources are maintained in compliance with security policies, standards, and procedures. | %s has a defined policies and procedures for maintenance management to ensure that maintenance on organizational systems are conducted periodically in accordance with security requirements. | CMMC, DORA, FEDRAMP, NIST800171, NIST800171R3, NIST80053, NISTCSF | 2024-09-05 21:51:55 |
DCF-583 | %s displays system use notification to users prior to granting access. | %s provides system use notifications to users prior to allowing access to the system, such as privacy and security notices, in accordance with applicable regulations. | CMMC, FEDRAMP, NIST800171, NIST800171R3, NIST80053 | 2024-09-05 21:51:55 |
DCF-586 | %s defines conditions for allowing remote access to security/privacy information and executing privileged commands. | %s authorizes remote execution of identified privileged commands and remote access to security-relevant information. | CMMC, DORA, FEDRAMP, NIST800171, NIST80053 | 2024-09-05 21:51:55 |
DCF-591 | %s has an established procedure for managing publicly accessible content, which includes proper content review, and properly-trained personnel to make information publicly accessible. | Content posted or processed on publicly accessible systems is reviewed by knowledgeable personnel prior to posting to validate it does not include nonpublic sensitive information in accordance with company policies and procedures and applicable regulations. If discovered, nonpublic sensitive information is removed. | CMMC, FEDRAMP, NIST800171, NIST800171R3, NIST80053 | 2024-09-05 21:51:55 |
DCF-606 | %s identifies and authenticates devices prior to establishing a connection. | Devices accessing the system are identified (e.g., through media access control (MAC) addresses, internal protocol (IP) addresses, device-unique token identifiers, etc.). The identity of each device accessing or connecting to the system is authenticated or verified as a prerequisite to system access. | CMMC, FEDRAMP, FEDRAMP20X, NIST800171, NIST800171R3, NIST80053, NISTCSF2 | 2024-09-05 21:51:55 |
DCF-607 | %s has a process in place to manage system identifiers and prevent their reuse. | %s has documented policies and procedures for assigning unique identifiers to individuals, groups, roles, services, or devices. Reuse of identifiers is restricted. | CMMC, FEDRAMP, ISO27701, NIST800171, NIST800171R3, NIST80053, NISTCSF2 | 2024-07-11 20:02:42 |
DCF-610 | %s protects authenticators based on the highest security category of information on the system. | %s protects authenticators based on the highest security category of information on the system. | FEDRAMP, NIST800171R3, NIST80053 | 2025-03-19 18:29:34 |
DCF-611 | %s obscures the feedback of authentication information during the authentication process. | %s has implemented mechanisms to obscure the feedback of authentication information, such as usernames/passwords, during the authentication process where technically feasible (e.g., in company-developed systems or applications, configurable third-party systems, etc.). | CMMC, FEDRAMP, ISO270012022, NIST800171, NIST800171R3, NIST80053 | 2024-05-07 19:18:26 |
DCF-614 | %s utilizes automated maintenance tools to perform maintenance activities. | %s has implemented automated mechanisms and tools to conduct maintenance, repairs, and replacement actions on organizational systems. | CMMC, FEDRAMP, NIST800171, NIST80053 | 2024-09-05 21:51:55 |
DCF-615 | %s requires that the use of maintenance tools be approved, controlled, and monitored. | Tools, techniques, or mechanisms used to perform system security maintenance are approved by management prior to use with supporting documentation. | CMMC, FEDRAMP, NIST800171, NIST80053, NISTCSF | 2024-09-05 21:51:55 |
DCF-616 | %s has an approval process for non local maintenance activities. | %s approves and monitors all nonlocal maintenance and diagnostic activities and retains documented evidence of the approval. %s validates that external session and network connections are terminated when nonlocal maintenance or diagnostic activities are completed. | CMMC, FEDRAMP, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2 | 2024-09-05 21:51:55 |
DCF-617 | %s has established procedures for maintenance personnel authorization. | %s has a documented process to authorize maintenance personnel or organizations to perform maintenance and keeps a documented list of authorized parties. %s assigns organizational personnel with required access authorizations and technical competence to supervise the maintenance activities of personnel without required access authorizations. | CMMC, FEDRAMP, NIST800171, NIST800171R3, NIST80053, NISTCSF2 | 2024-09-05 21:51:55 |
DCF-619 | %s review, approve, track, document, and verify media sanitization and disposal actions. | %s sanitizes equipment and system media that contain sensitive prior to disposal, release for reuse, or release out of organizational control (e.g., removed from premises for off-site maintenance). %s reviews, approves, tracks, documents, and verifies media sanitization and disposal actions in accordance with company policies and procedures. | CCM, CIS8, CMMC, FEDRAMP, ISO270012022, ISO27701, NIST800171, NIST800171R3, NIST80053 | 2024-09-05 21:51:55 |
DCF-635 | %s only allows information technology products approved under the Federal Information Processing Standards (FIPS) 201 to be used for Personal Identity Verification (PIV) capabilities. | %s only allows information technology products approved under the Federal Information Processing Standards (FIPS) 201 to be used for sensitive information capabilities. | FEDRAMP, NIST80053 | 2023-02-02 18:20:03 |
DCF-637 | %s has a documented secure development process for system developers. | %s has documented software development procedures that outline the company's processes for secure development. The documented processes include references to industry standards and/or best practices for secure development, security requirement considerations (for example, secure authentication and logging, etc.), and consideration for information security issues during each stage of the software development life cycle. | CCM, CIS8, CMMC, FEDRAMP, FEDRAMP20X, ISO270012022, ISO27701, NIS2, NIST800171, NIST80053, NISTCSF2, PCI4 | 2024-09-05 21:51:55 |
DCF-638 | %s ensures that user functions are separated from system management functions. | %s has implemented separation controls (physical or logical) so that user functionality is separated from system management functionality. | CIS8, CMMC, CYBER_ESSENTIALS, CYBER_ESSENTIALS_32, FEDRAMP, NIST800171, NIST80053 | 2024-09-05 21:51:55 |
DCF-639 | %s ensures that any unauthorized or unintended information transfers via shared system resources are prevented. | %s has implemented technical controls to prevent unauthorized and unintended information transfer via shared system resources such as registers, cache memory, main memory, hard disks, etc. | CMMC, DORA, FEDRAMP, NIST800171, NIST800171R3, NIST80053 | 2024-09-05 21:51:55 |
DCF-643 | %s prohibits the remote activation of collaborative computing devices and applications, unless explicitly defined otherwise. | Remote activation of collaborative computing devices and applications (e.g., networked white boards, cameras, microphones, etc.) is prohibited unless explicitly defined otherwise in company policies and procedures. Collaborative computing devices provide an explicit indication of use to users physically present at the devices (e.g., through pop-up menus, signals, etc.). | CMMC, FEDRAMP, NIST800171, NIST800171R3, NIST80053 | 2024-09-05 21:51:55 |
DCF-644 | %s manages the use of acceptable mobile code and mobile code technologies. | %s has defined acceptable and unacceptable mobile code and mobile code technologies in the enterprise (e.g., Java, JavaScript, ActiveX, Postscript, PDF, Flash animations, VBScript, etc.). %s has implemented usage restrictions for mobile code technologies to prevent the development, acquisition, and introduction of unacceptable mobile through policies, procedures, and/or technical mechanisms. | CMMC, FEDRAMP, NIST800171, NIST800171R3, NIST80053, NISTCSF | 2024-09-05 21:51:55 |
DCF-660 | %s has defined the amount of risk it is willing to accept to achieve its objectives. | %s has defined and approved risk appetite statements, including statements pertaining to cybersecurity risk, that convey expectations about the level of risk the organization is willing to accept in the pursuit of objectives. These statements are reviewed periodically and updated as necessary. | CCM, DORA, NIS2, NISTCSF2 | 2024-09-11 1:28:13 |
DCF-677 | %s installs software updates within 14 days of release. | %s has implemented a software update management process where critical patches and application updates are installed for all authorized software within priority SLAs established in company policies. | CIS8, CMMC, CYBER_ESSENTIALS, CYBER_ESSENTIALS_32, DORA, FEDRAMP20X, ISO27701, NIST800171, NISTCSF2, SOC_2 | 2024-05-07 19:18:26 |
DCF-678 | %s has a defined Global Network Firewall Policy that covers policies and procedures to manage firewalls across the organization in compliance with security policies, standards, and procedures. | %s has defined and documented a policy that outlines requirements for deployment, management and operation of network security controls at the company. | CMMC, CYBER_ESSENTIALS, CYBER_ESSENTIALS_32, DORA, ISO270012022, ISO27701, NIS2, NIST800171, NISTCSF2 | 2024-05-07 19:18:26 |
Test Mapping Revisions
Expand to view Test Mapping Revisions
Expand to view Test Mapping Revisions
For the Current Tests column, cells that are blank means the control was unmapped.
Code | Previous Tests | Current Tests | Frameworks | Last Updated |
DCF-1 | 1, 2 |
| CCM, FEDRAMP, HIPAA, ISO27001, ISO270172015, NIST80053 | 2024-12-03 22:39:18 |
DCF-2 | 3 |
| CCM, CCPA, CYBER_ESSENTIALS, FEDRAMP, HIPAA, ISO27001, NIST80053, NISTCSF, PCI | 2024-12-03 22:39:18 |
DCF-4 | 5, 6, 7 | 5, 7 | CCM, CIS8, CMMC, FEDRAMP, FEDRAMP20X, ISO27001, ISO270012022, ISO270172015, ISO27701, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, SOC_2 | 2024-12-03 22:39:18 |
DCF-7 | 10 |
| CCM, CIS8, CMMC, DORA, FEDRAMP, ISO27001, ISO270012022, ISO27701, NIS2, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, PCI, PCI4, SOC_2 | 2024-12-03 22:39:18 |
DCF-9 | 12 |
| CCM, CIS8, DORA, DRATA_ESSENTIALS, FEDRAMP, HIPAA, ISO27001, ISO270012022, ISO27701, ISO420012023, NIST800171R3, NIST80053, NISTCSF2, SOC_2 | 2024-12-03 22:39:18 |
DCF-11 | 14 |
| CCM, CIS8, CMMC, CYBER_ESSENTIALS, CYBER_ESSENTIALS_32, DORA, FEDRAMP, HIPAA, ISO27001, ISO270012022, ISO270172015, ISO270182019, ISO27701, NIS2, NIST800171, NIST80053, NISTCSF, NISTCSF2, PCI4, SOC_2 | 2024-12-03 22:39:18 |
DCF-12 | 15 | 292, 8018 | CCM, CIS8, CMMC, CYBER_ESSENTIALS, CYBER_ESSENTIALS_32, DORA, FEDRAMP, FEDRAMP20X, HIPAA, ISO27001, ISO270012022, ISO270172015, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, PCI, PCI4, SOC_2 | 2024-12-03 22:39:18 |
DCF-18 | 21 | 21, 212, 213, 235, 236, 237, 238, 239, 240, 241, 242, 282, 283, 284, 285, 286, 287, 288, 289, 313, 314, 315, 316, 317, 318, 319, 320, 321, 322 | CCM, CCPA, CIS8, CMMC, CYBER_ESSENTIALS, CYBER_ESSENTIALS_32, DORA, DRATA_ESSENTIALS, FEDRAMP, FEDRAMP20X, GDPR, HIPAA, ISO27001, ISO270012022, ISO27701, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, SOC_2 | 2024-12-03 22:39:18 |
DCF-20 | 23 |
| CCM, CCPA, CIS8, CMMC, CYBER_ESSENTIALS, CYBER_ESSENTIALS_32, DORA, DRATA_ESSENTIALS, FEDRAMP, FEDRAMP20X, HIPAA, ISO27001, ISO270012022, ISO270172015, ISO27701, NIS2, NIST800171, NIST800171R3, NIST80053, NISTAI, NISTCSF, NISTCSF2, PCI, PCI4, SOC_2 | 2024-12-03 22:39:18 |
DCF-22 | 25 |
| CCM, CCPA, CIS8, CMMC, CYBER_ESSENTIALS_32, DORA, HIPAA, ISO27001, ISO270012022, ISO270172015, ISO27701, NIST800171, NIST80053, NISTCSF, NISTCSF2, PCI4, SOC_2 | 2024-12-03 22:39:18 |
DCF-23 | 26 |
| CCM, CIS8, CYBER_ESSENTIALS, FEDRAMP, ISO27001, NIST80053, NISTCSF | 2024-12-03 22:39:18 |
DCF-24 | 27 |
| CIS8, CYBER_ESSENTIALS, FEDRAMP, ISO27001 | 2024-12-03 22:39:18 |
DCF-27 | 30, 31 | 30, 8004, 8036 | CIS8, DORA, DRATA_ESSENTIALS, FEDRAMP, FEDRAMP20X, HIPAA, ISO27001, ISO270012022, ISO27701, NIST80053, NISTCSF2, SOC_2 | 2024-12-03 22:39:18 |
DCF-28 | 32 | 26 | CCM, CIS8, CMMC, CYBER_ESSENTIALS_32, DORA, FEDRAMP, FEDRAMP20X, HIPAA, ISO27001, ISO270012022, ISO27701, ISO420012023, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, PCI4, SOC_2 | 2024-12-03 22:39:18 |
DCF-29 | 34 |
| CCM, CIS8, DORA, DRATA_ESSENTIALS, FEDRAMP, HIPAA, ISO27001, ISO270012022, ISO420012023, NIS2, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, PCI, SOC_2 | 2024-12-03 22:39:18 |
DCF-30 | 35 |
| CCM, CCPA, CIS8, CMMC, DORA, FEDRAMP, FEDRAMP20X, ISO27001, ISO270012022, ISO27701, NIS2, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, PCI4, SOC_2 | 2024-12-03 22:39:18 |
DCF-32 | 37, 38, 190 | 38, 49, 190 | CCM, CYBER_ESSENTIALS_32, DORA, FEDRAMP, GDPR, ISO27001, ISO270012022, ISO270172015, ISO27701, NIS2, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, PCI, PCI4, SOC_2 | 2024-12-03 22:39:18 |
DCF-34 | 40 |
| CCM, CCPA, FEDRAMP, HIPAA, ISO27001, NIST80053, NISTCSF | 2024-12-03 22:39:18 |
DCF-35 | 41 |
| CCM, FEDRAMP, HIPAA, ISO27001, NIST80053, NISTCSF | 2024-12-03 22:39:18 |
DCF-36 | 42, 43 | 43 | CCM, CCPA, CIS8, CMMC, CYBER_ESSENTIALS, DORA, DRATA_ESSENTIALS, FEDRAMP, FEDRAMP20X, HIPAA, ISO27001, ISO270012022, ISO270182019, ISO27701, NIS2, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, PCI, PCI4, SOC_2 | 2024-12-03 22:39:18 |
DCF-39 | 47 | 47, 50 | CCM, CMMC, FEDRAMP, HIPAA, ISO27001, ISO270012022, ISO27701, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, PCI, PCI4, SOC_2 | 2024-12-03 22:39:18 |
DCF-40 | 48, 49, 50 |
| CCM, FEDRAMP, HIPAA, ISO27001, NIST80053, NISTCSF | 2024-12-03 22:39:18 |
DCF-42 | 52 | 40 | CCM, DORA, FEDRAMP, HIPAA, ISO27001, ISO270012022, ISO270172015, ISO27701, ISO420012023, NIS2, NIST80053, NISTCSF, NISTCSF2, PCI4, SOC_2 | 2024-12-03 22:39:18 |
DCF-43 | 199 |
| CCM, CIS8, FEDRAMP, HIPAA, ISO27001, ISO270172015, NIST80053, NISTCSF | 2024-12-03 22:39:18 |
DCF-44 | 54, 55 | 48, 54, 55 | CCM, DORA, DRATA_ESSENTIALS, HIPAA, ISO27001, ISO270012022, ISO27701, NIS2, NISTCSF2, SOC_2 | 2024-12-03 22:39:18 |
DCF-45 | 56, 57, 191 | 56 | CCM, CCPA, CIS8, CMMC, DORA, DRATA_ESSENTIALS, FEDRAMP, GDPR, HIPAA, ISO27001, ISO270012022, ISO270172015, ISO270182019, ISO27701, NIS2, NIST800171, NIST80053, NISTCSF, NISTCSF2, PCI, SOC_2 | 2024-12-03 22:39:18 |
DCF-46 | 58 |
| CMMC, DORA, FEDRAMP, ISO27001, ISO270012022, ISO27701, NIST800171, NIST800171R3, NISTCSF, NISTCSF2, PCI, PCI4, SOC_2 | 2024-12-03 22:39:18 |
DCF-48 | 61, 194 | 61 | CCM, CCPA, CIS8, CMMC, CYBER_ESSENTIALS, CYBER_ESSENTIALS_32, DORA, FEDRAMP, HIPAA, ISO27001, ISO270012022, ISO27701, NIST800171, NIST800171R3, NIST80053, NISTCSF, PCI4, SOC_2 | 2024-12-03 22:39:18 |
DCF-49 | 62, 63, 195 | 63 | CCM, CYBER_ESSENTIALS, CYBER_ESSENTIALS_32, FEDRAMP, HIPAA, ISO27001, ISO270012022, SOC_2 | 2024-12-03 22:39:18 |
DCF-50 | 64, 196 | 64 | CCM, CCPA, CIS8, CMMC, CYBER_ESSENTIALS, CYBER_ESSENTIALS_32, DRATA_ESSENTIALS, FEDRAMP, HIPAA, ISO27001, ISO270012022, ISO27701, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, PCI, PCI4, SOC_2 | 2024-12-03 22:39:18 |
DCF-51 | 65, 197 | 65 | CCM, CCPA, CIS8, CMMC, CYBER_ESSENTIALS, CYBER_ESSENTIALS_32, DORA, DRATA_ESSENTIALS, FEDRAMP, ISO27001, ISO270012022, ISO27701, NIST800171, NIST800171R3, NIST80053, NISTCSF, PCI, SOC_2 | 2024-12-03 22:39:18 |
DCF-52 | 66, 145, 198 | 66 | CCM, CCPA, CIS8, CMMC, CYBER_ESSENTIALS, CYBER_ESSENTIALS_32, DRATA_ESSENTIALS, FEDRAMP, HIPAA, ISO27001, ISO270012022, ISO27701, NIS2, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, SOC_2 | 2024-12-03 22:39:18 |
DCF-53 | 67 |
| CCM, FEDRAMP, GDPR, HIPAA, ISO27001, ISO270172015, NIST80053 | 2024-12-03 22:39:18 |
DCF-54 | 68, 69 | 68, 69, 218, 222, 231, 270, 8002 | CCM, CCPA, CIS8, CMMC, DORA, DRATA_ESSENTIALS, FEDRAMP, FEDRAMP20X, GDPR, HIPAA, ISO27001, ISO270012022, ISO27701, NIS2, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, PCI4, SOC_2 | 2025-09-23 3:47:31 |
DCF-55 | 70, 71, 72, 73 | 70, 71, 72, 210, 234, 253, 263, 269, 299, 8008, 8015 | CCM, CCPA, CIS8, CMMC, DORA, DRATA_ESSENTIALS, FEDRAMP, FEDRAMP20X, HIPAA, ISO27001, ISO270012022, ISO270182019, ISO27701, NIS2, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, PCI4, SOC_2 | 2024-12-11 14:45:49 |
DCF-56 | 74 |
| CCM, CCPA, CIS8, CMMC, DORA, DRATA_ESSENTIALS, FEDRAMP, FEDRAMP20X, HIPAA, ISO27001, ISO270012022, ISO270172015, ISO27701, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, PCI4, SOC_2 | 2024-12-03 22:39:18 |
DCF-57 | 75 |
| CCM, CCPA, CIS8, CMMC, DORA, FEDRAMP, HIPAA, ISO27001, ISO270012022, ISO270172015, ISO27701, NIS2, NIST800171, NIST800171R3, NIST80053, NISTAI, NISTCSF, NISTCSF2, PCI4, SOC_2 | 2024-12-03 22:39:18 |
DCF-58 | 76, 77 |
| CCM, CCPA, CIS8, CMMC, CYBER_ESSENTIALS, CYBER_ESSENTIALS_32, FEDRAMP, HIPAA, ISO27001, ISO270172015, NIS2, NIST800171, NIST800171R3, NIST80053, NISTCSF | 2024-12-03 22:39:18 |
DCF-59 | 78 | 208 | CCM, CCPA, CIS8, CMMC, CYBER_ESSENTIALS, CYBER_ESSENTIALS_32, DORA, FEDRAMP, HIPAA, ISO27001, ISO270012022, ISO270172015, ISO270182019, ISO27701, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, PCI, PCI4, SOC_2 | 2024-12-03 22:39:18 |
DCF-60 | 79 |
| CCM, DORA, HIPAA, ISO27001, NIST800171R3, SOC_2 | 2024-12-03 22:39:18 |
DCF-61 | 80 |
| CIS8, DORA, ISO27001, ISO270172015, PCI4, SOC_2 | 2024-12-03 22:39:18 |
DCF-62 | 81 |
| CCPA, CIS8, CMMC, DORA, DRATA_ESSENTIALS, FEDRAMP, HIPAA, ISO27001, ISO270012022, ISO27701, NIST800171, NIST800171R3, NIST80053, NISTCSF2, PCI4, SOC_2 | 2024-12-03 22:39:18 |
DCF-63 | 82 | 85 | ISO27001, SOC_2 | 2024-12-03 22:39:18 |
DCF-64 | 83 |
| CCM, HIPAA, ISO27001, NISTCSF, NISTCSF2, SOC_2 | 2024-12-03 22:39:18 |
DCF-66 | 85 | 83 | CCM, ISO27001, NISTCSF, SOC_2 | 2024-12-03 22:39:18 |
DCF-68 | 89 | 89, 215 | CCM, CCPA, CMMC, CYBER_ESSENTIALS, CYBER_ESSENTIALS_32, DORA, DRATA_ESSENTIALS, FEDRAMP, FEDRAMP20X, HIPAA, ISO27001, ISO270012022, ISO270172015, ISO27701, NIS2, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, PCI, PCI4, SOC_2 | 2024-12-03 22:39:18 |
DCF-69 | 90, 91, 92, 93 |
| CCM, CIS8, CMMC, CYBER_ESSENTIALS, CYBER_ESSENTIALS_32, DORA, FEDRAMP, HIPAA, ISO27001, ISO270012022, ISO270182019, ISO27701, NIS2, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, PCI4, SOC_2 | 2024-12-03 22:39:18 |
DCF-70 | 94, 95 | 94, 95, 199 | CCM, CCPA, CIS8, CMMC, CYBER_ESSENTIALS, CYBER_ESSENTIALS_32, DORA, FEDRAMP, HIPAA, ISO27001, ISO270012022, ISO270182019, ISO27701, NIS2, NIST800171, NIST800171R3, NISTCSF, NISTCSF2, PCI, PCI4, SOC_2 | 2024-12-03 22:39:18 |
DCF-71 | 96, 97, 98, 99, 100 | 96, 97, 98 | CCM, CMMC, CYBER_ESSENTIALS, CYBER_ESSENTIALS_32, DORA, DRATA_ESSENTIALS, FEDRAMP, HIPAA, ISO27001, ISO270012022, ISO270172015, ISO270182019, ISO27701, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, PCI4, SOC_2 | 2024-12-03 22:39:18 |
DCF-72 | 101 |
| CCM, FEDRAMP, HIPAA, ISO27001, ISO270012022, NIST80053, SOC_2 | 2024-12-03 22:39:18 |
DCF-73 | 102 | 102, 227, 228, 268 | CCM, CCPA, CIS8, CMMC, CYBER_ESSENTIALS_32, DORA, DRATA_ESSENTIALS, FEDRAMP, HIPAA, ISO27001, ISO270012022, ISO27701, NIST800171, NIST800171R3, NIST80053, SOC_2 | 2024-12-11 14:45:49 |
DCF-74 | 103 |
| FEDRAMP, ISO27001, ISO270172015, ISO27701, NIST80053, NISTCSF, SOC_2 | 2024-12-03 22:39:18 |
DCF-75 | 104 | 104, 209, 220, 311, 312, 8011 | CCM, DRATA_ESSENTIALS, FEDRAMP, ISO27001, ISO270012022, ISO270172015, NIS2, NIST800171R3, SOC_2 | 2025-01-30 19:06:48 |
DCF-77 | 107 | 107, 8001, 8017 | CCM, CCPA, CIS8, CYBER_ESSENTIALS, DORA, DRATA_ESSENTIALS, FEDRAMP, HIPAA, ISO27001, ISO270012022, ISO27701, NIST80053, NISTAI, NISTCSF, NISTCSF2, SOC_2 | 2024-12-03 22:39:18 |
DCF-78 | 108 | 108, 8003 | CIS8, FEDRAMP, ISO27001, ISO270012022, NIST80053, SOC_2 | 2024-12-03 22:39:18 |
DCF-80 | 111 |
| CCM, CCPA, FEDRAMP, HIPAA, ISO27001, ISO270172015, ISO270182019, NIST80053, NISTCSF | 2024-12-03 22:39:18 |
DCF-81 | 112, 113, 114 |
| FEDRAMP, HIPAA, ISO27001, NIST80053, NISTCSF | 2024-12-03 22:39:18 |
DCF-82 | 115 |
| FEDRAMP, HIPAA, ISO27001, NIST80053 | 2024-12-03 22:39:18 |
DCF-83 | 116, 117 | 116 | FEDRAMP, HIPAA, ISO27001, NIST80053 | 2024-12-03 22:39:18 |
DCF-84 | 118 |
| CCM, CYBER_ESSENTIALS, FEDRAMP, HIPAA, ISO27001, NIST80053 | 2024-12-03 22:39:18 |
DCF-85 | 119 | 119, 209, 233, 291, 8007, 8009, 8010, 8012, 8016 | CCM, CCPA, CIS8, CMMC, CYBER_ESSENTIALS, CYBER_ESSENTIALS_32, DRATA_ESSENTIALS, FEDRAMP, FEDRAMP20X, ISO27001, ISO270012022, ISO27701, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, PCI4, SOC_2 | 2024-12-03 22:39:18 |
DCF-86 | 120, 206 | 112, 113, 114, 115, 117, 118, 206, 243, 244, 245, 246, 247, 248, 249, 250, 251, 252, 290, 293, 294, 295, 296, 297, 298, 300, 301 | CCM, CMMC, DORA, DRATA_ESSENTIALS, FEDRAMP, HIPAA, ISO27001, ISO270012022, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, SOC_2 | 2025-08-17 0:10:54 |
DCF-87 | 105, 121 | 105 | CCM, CCPA, CIS8, CMMC, DORA, FEDRAMP, HIPAA, ISO27001, ISO270012022, ISO27701, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, SOC_2 | 2024-12-03 22:39:18 |
DCF-88 | 122 | 122, 311, 312 | CCM, CCPA, CIS8, CMMC, CYBER_ESSENTIALS, CYBER_ESSENTIALS_32, DORA, DRATA_ESSENTIALS, FEDRAMP, FEDRAMP20X, ISO27001, ISO270012022, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, PCI4, SOC_2 | 2024-12-11 14:45:49 |
DCF-89 | 123 |
| ISO27001 | 2024-12-03 22:39:18 |
DCF-90 | 124 | 124, 214, 225 | CYBER_ESSENTIALS_32, DORA, FEDRAMP, ISO270012022, NIST800171R3, NIST80053, SOC_2 | 2024-12-11 14:45:49 |
DCF-91 | 125 |
| CCM, CCPA, CIS8, CMMC, DORA, FEDRAMP, HIPAA, ISO27001, ISO270012022, ISO27701, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, PCI, PCI4, SOC_2 | 2024-12-03 22:39:18 |
DCF-92 | 126 |
| CCM, CCPA, CIS8, CMMC, DORA, FEDRAMP, HIPAA, ISO27001, ISO270012022, ISO27701, NIS2, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, SOC_2 | 2024-12-03 22:39:18 |
DCF-93 | 127 |
| CCM, FEDRAMP, HIPAA, ISO27001, NIST80053, PCI | 2024-12-03 22:39:18 |
DCF-96 | 130 | 130, 8035 | CCM, DORA, FEDRAMP20X, ISO27001, ISO270012022, ISO270172015, ISO27701, NISTCSF, NISTCSF2, SOC_2 | 2024-12-03 22:39:18 |
DCF-97 | 131 | 131, 8000 | DORA, FEDRAMP, ISO27001, ISO270012022, ISO270172015, ISO27701, NIST80053, NISTCSF, NISTCSF2, SOC_2 | 2024-12-03 22:39:18 |
DCF-100 | 135 |
| CCM, CCPA, CIS8, CYBER_ESSENTIALS, DORA, FEDRAMP, HIPAA, ISO27001, ISO270012022, ISO27701, NIST80053, NISTCSF, NISTCSF2, SOC_2 | 2024-12-03 22:39:18 |
DCF-101 | 136 | 111, 136, 8019 | CCM, CIS8, FEDRAMP, HIPAA, ISO27001, ISO270012022, ISO270172015, ISO270182019, ISO27701, NIS2, NIST800171R3, NIST80053, NISTCSF2, PCI, PCI4, SOC_2 | 2024-12-03 22:39:18 |
DCF-103 | 138 |
| CCM, HIPAA, ISO27001, ISO270012022, ISO27701, SOC_2 | 2024-12-03 22:39:18 |
DCF-104 | 139 |
| CCM, DORA, ISO27001, ISO270012022, ISO27701, NIS2, NISTCSF2, PCI, SOC_2 | 2024-12-03 22:39:18 |
DCF-105 | 140 |
| CCM, ISO27001, ISO270012022, ISO270182019, ISO27701, NISTCSF2, SOC_2 | 2024-12-03 22:39:17 |
DCF-106 | 141, 142 |
| DORA, HIPAA, ISO27001, ISO270012022, ISO27701, PCI4 | 2024-12-03 22:39:17 |
DCF-107 | 143 |
| CCM, CCPA, CIS8, FEDRAMP, HIPAA, ISO27001, ISO270012022, ISO270182019, ISO27701, NIST80053, NISTCSF2, PCI4, SOC_2 | 2024-12-03 22:39:17 |
DCF-108 | 144 |
| CCM, CCPA, CMMC, DORA, HIPAA, ISO27001, ISO270012022, ISO270182019, ISO27701, NIST800171, NIST800171R3, NISTCSF2, PCI4, SOC_2 | 2024-12-03 22:39:17 |
DCF-110 | 147 |
| CIS8, FEDRAMP, ISO27701, NIST80053, SOC_2 | 2024-12-03 22:39:18 |
DCF-109 | 144 |
| CCM, CCPA, CIS8, FEDRAMP, HIPAA, ISO27001, ISO270012022, ISO270182019, ISO27701, NIST80053, NISTCSF2, SOC_2 | 2024-12-03 22:39:17 |
DCF-111 | 148 |
| CIS8, ISO27701, SOC_2 | 2024-12-03 22:39:17 |
DCF-112 | 159 |
| HIPAA, ISO27001, ISO270012022, ISO27701, NIST80053, NISTCSF, SOC_2 | 2024-12-03 22:39:17 |
DCF-113 | 160 |
| HIPAA, ISO27001 | 2024-12-03 22:39:17 |
DCF-114 | 161 |
| CCPA, HIPAA, ISO27001, NIST80053, NISTCSF | 2024-12-03 22:39:17 |
DCF-115 | 162 |
| CCM, CCPA, GDPR, ISO27001, ISO27701, NIST80053, SOC_2 | 2024-12-03 22:39:17 |
DCF-116 | 163 |
| ISO27001, NIST80053 | 2024-12-03 22:39:17 |
DCF-117 | 164 |
| CCM, CCPA, GDPR, ISO27001, NIST80053 | 2024-12-03 22:39:18 |
DCF-118 | 165 |
| CCM, ISO27001, NISTAI | 2024-12-03 22:39:18 |
DCF-119 | 166 |
| CCM, HIPAA, ISO27001 | 2024-12-03 22:39:18 |
DCF-120 | 167 |
| CCM, DORA, GDPR, HIPAA, ISO27001, ISO270012022, ISO27701, NIST80053, NISTCSF, SOC_2 | 2024-12-03 22:39:18 |
DCF-121 | 168 |
| CCM, CCPA, GDPR, ISO27001, ISO270182019, NIST80053 | 2024-12-03 22:39:18 |
DCF-122 | 169 |
| NIST80053, SOC_2 | 2024-12-03 22:39:18 |
DCF-123 | 170 |
| CCM, CCPA, CIS8, DORA, FEDRAMP, HIPAA, ISO27001, ISO270012022, ISO270172015, ISO270182019, ISO27701, NIST80053, NISTCSF, NISTCSF2, SOC_2 | 2024-12-03 22:39:18 |
DCF-124 | 171 |
| CCM, CYBER_ESSENTIALS, FEDRAMP, HIPAA, ISO27001, ISO270172015, NIST80053, NISTCSF | 2024-12-03 22:39:18 |
DCF-125 | 172 |
| CCM, FEDRAMP, HIPAA, ISO27001, ISO270182019 | 2024-12-03 22:39:18 |
DCF-126 | 173 |
| CYBER_ESSENTIALS_32, FEDRAMP, HIPAA, ISO27001, ISO270182019, ISO27701, NIS2, NIST80053, SOC_2 | 2024-12-03 22:39:18 |
DCF-127 | 175 |
| CCM, CCPA, HIPAA, ISO27001, NISTCSF, SOC_2 | 2024-12-03 22:39:18 |
DCF-128 | 176 |
| CCM, FEDRAMP, HIPAA, ISO27001, ISO270182019, NISTAI | 2024-12-03 22:39:18 |
DCF-129 | 177 |
| FEDRAMP, HIPAA, ISO27001, NISTAI | 2024-12-03 22:39:18 |
DCF-130 | 178 |
| CCM, FEDRAMP, GDPR, ISO27001, ISO27701, ISO420012023, NISTCSF, SOC_2 | 2024-12-03 22:39:18 |
DCF-131 | 179 |
| CIS8, FEDRAMP, HIPAA, ISO27001, NIST80053, NISTCSF | 2024-12-03 22:39:18 |
DCF-132 | 180 |
| CCM, CIS8, DORA, HIPAA, ISO27001, ISO270012022, ISO27701, NIST800171R3, NISTAI, NISTCSF2, SOC_2 | 2024-12-03 22:39:18 |
DCF-133 | 181 |
| CIS8, FEDRAMP, HIPAA, ISO27001, NISTAI | 2024-12-03 22:39:18 |
DCF-134 | 182 |
| CCM, CIS8, FEDRAMP, HIPAA, ISO27001, ISO270172015, NIST80053, NISTCSF | 2024-12-03 22:39:18 |
DCF-135 | 183 |
| CCM, CCPA, CIS8, CMMC, DORA, FEDRAMP, FEDRAMP20X, GDPR, HIPAA, ISO27001, ISO270012022, ISO270182019, ISO27701, ISO420012023, NIS2, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, SOC_2 | 2024-12-03 22:39:18 |
DCF-136 | 184 |
| HIPAA, ISO27001, ISO27701, SOC_2 | 2024-12-03 22:39:18 |
DCF-137 | 185 |
| FEDRAMP, ISO27001, NIST80053 | 2024-12-03 22:39:18 |
DCF-138 | 186 |
| NIST80053 | 2024-12-03 22:39:18 |
DCF-139 | 187 |
| HIPAA, NIST80053 | 2024-12-03 22:39:18 |
DCF-140 | 188 |
| CCPA, HIPAA, ISO27701, NIST80053, NISTCSF2, SOC_2 | 2024-12-03 22:39:18 |
DCF-141 | 189 |
| HIPAA, ISO27701, NIST80053, SOC_2 | 2024-12-03 22:39:18 |
DCF-145 | 201 |
| ISO27001 | 2022-06-21 21:57:20 |
DCF-148 | 146 |
| CCM, FEDRAMP, ISO27001, NIST80053, NISTCSF | 2021-06-16 3:53:16 |
DCF-152 |
| 219, 8013 | CIS8, CMMC, CYBER_ESSENTIALS_32, DORA, FEDRAMP, ISO27001, ISO270012022, ISO27701, NIST800171, NIST800171R3, NIST80053, NISTCSF, SOC_2 | 2024-09-05 21:51:55 |
DCF-154 | 200 |
| CCPA, CIS8, CMMC, DORA, FEDRAMP, FEDRAMP20X, HIPAA, ISO27001, ISO270012022, ISO420012023, NIS2, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, PCI, PCI4, SOC_2 | 2024-09-05 21:51:55 |
DCF-160 |
| 123 | CCM, CCPA, CMMC, DORA, FEDRAMP, HIPAA, ISO27001, ISO270012022, ISO27701, ISO420012023, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, SOC_2 | 2024-12-03 22:39:18 |
DCF-173 |
| 58 | CCM, CMMC, DORA, ISO27001, ISO270012022, ISO27701, NIST800171, NISTCSF2, SOC_2 | 2024-12-03 22:39:17 |
DCF-183 |
| 27 | CCM, CCPA, CIS8, CMMC, CYBER_ESSENTIALS, CYBER_ESSENTIALS_32, DORA, DRATA_ESSENTIALS, FEDRAMP, FEDRAMP20X, GDPR, HIPAA, ISO27001, ISO270012022, ISO27701, NIS2, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, PCI, PCI4, SOC_2 | 2024-12-03 22:39:18 |
DCF-196 | 192, 193 |
| HIPAA | 2024-12-11 14:37:26 |
DCF-218 |
| 209 | CIS8, CYBER_ESSENTIALS_32, DORA, FEDRAMP, NIS2, NIST80053, PCI, PCI4 | 2024-01-19 0:22:44 |
DCF-229 |
| 8020 | CCM, CIS8, CYBER_ESSENTIALS, CYBER_ESSENTIALS_32, ISO270012022, ISO27701, NIST800171R3, NIST80053, PCI, PCI4 | 2024-01-19 0:22:44 |
DCF-285 |
| 263, 8006, 8015 | CIS8, CMMC, DORA, NIST800171, NIST800171R3, NISTCSF2, PCI, PCI4 | 2024-12-11 14:45:49 |
DCF-326 |
| 208 | CCM, CIS8, CMMC, CYBER_ESSENTIALS_32, DORA, FEDRAMP, ISO270012022, ISO27701, NIS2, NIST800171, NIST800171R3, NIST80053, NISTCSF2, PCI, PCI4, SOC_2 | 2024-07-11 20:02:42 |
DCF-330 |
| 8037 | CCM, CCPA, CIS8, CMMC, DORA, FEDRAMP, FEDRAMP20X, ISO27701, NIS2, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, PCI | 2024-07-11 20:02:42 |
DCF-335 |
| 229 | CIS8, CMMC, CYBER_ESSENTIALS_32, FEDRAMP, NIST800171, NIST800171R3, NIST80053, PCI, PCI4 | 2025-04-23 21:45:31 |
DCF-346 |
| 215 | CCM, CIS8, CYBER_ESSENTIALS, CYBER_ESSENTIALS_32, PCI, PCI4 | 2025-01-28 20:01:13 |
DCF-350 |
| 216 | CMMC, CYBER_ESSENTIALS_32, ISO270012022, ISO27701, NIST800171, NIST800171R3, PCI, PCI4, SOC_2 | 2024-09-05 21:51:55 |
DCF-406 |
| 221, 224, 226, 243, 244, 245, 246, 247, 248, 249, 250, 251, 252, 256, 257, 310, 8005 | CIS8, CMMC, DORA, FEDRAMP, ISO270012022, NIST800171, NIST800171R3, NIST80053, NISTCSF2, PCI, PCI4, SOC_2 | 2025-10-06 23:16:27 |
DCF-407 |
| 243, 244, 245, 246, 247, 248, 249, 250, 251, 252, 256 | CIS8, CMMC, ISO270012022, ISO27701, ISO420012023, NIST800171, NIST800171R3, NIST80053, NISTCSF2, PCI, PCI4, SOC_2 | 2025-10-06 23:16:27 |
DCF-441 |
| 8019 | CIS8, CMMC, DORA, ISO270012022, ISO27701, NIST800171, PCI, PCI4 | 2025-04-23 21:45:32 |
DCF-478 | 205 | 205, 8014 | CCM, CMMC, DORA, FEDRAMP, ISO270012022, ISO270172015, ISO27701, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, PCI, PCI4, SOC_2 | 2024-12-11 14:45:49 |
DCF-614 |
| 8034 | CMMC, FEDRAMP, NIST800171, NIST80053 | 2024-09-05 21:51:55 |
Test Name Revisions
Expand to view Test Name Revisions
Expand to view Test Name Revisions
ID | Previous Name | Current Name | Last Updated |
21 | Records of Vulnerability Scans | Vulnerability Scanning | 2025-08-28 22:48:37 |
38 | Policies are Accepted by Employees | Policies are Acknowledged by Employees | 2025-08-28 22:48:37 |
190 | Policies are Accepted by Contractors | Policies are Acknowledged by Contractors | 2025-08-28 22:48:37 |
45 | Employees Accept the Acceptable Use Policy | Employees Acknowledge the Acceptable Use Policy | 2025-08-28 22:48:37 |
48 | Contractors Accept the Code of Conduct | Contractors Acknowledge The Code of Conduct | 2025-08-28 22:48:37 |
49 | Contractors Accept the Acceptable Use Policy | Contractors Acknowledge the Acceptable Use Policy | 2025-08-28 22:48:37 |
55 | Employees Accept the Code of Conduct | Employees Acknowledge the Code of Conduct | 2025-08-28 22:48:37 |
57 | Employees Accept the Data Protection Policy | Employees Acknowledge Data Protection Policy | 2025-08-28 22:48:37 |
191 | Contractors Accept the Data Protection Policy | Contractors Acknowledge the Data Protection Policy | 2025-08-28 22:48:37 |
132 | Daily backup job status monitored | Daily Backup Job Status Monitored | 2025-08-28 22:48:37 |
205 | CloudTrail log file integrity validation enabled | CloudTrail Log File Integrity Validation Enabled | 2025-08-28 22:48:37 |
Test Description Revisions
Expand to view Test Description Revisions
Expand to view Test Description Revisions
ID | Previous Description | Current Description | Last Updated |
21 | Drata inspected %s's report from the latest vulnerability scan, which was performed within the last 3 months. | Drata validated that a vulnerability scanning system is connected to Drata. | 2025-08-28 22:48:37 |
38 | Drata inspected %s's policy records and confirmed that assigned employees have accepted them. | Drata inspected %s's policy records and confirmed that assigned employees have acknowledged them. | 2025-08-28 22:48:37 |
190 | Drata inspected %s's policy records and confirmed that assigned contractors have accepted them. | Drata inspected %s's policy records and confirmed that assigned contractors have acknowledged them. | 2025-08-28 22:48:37 |
45 | Drata inspected %s's records and confirmed that all employees have accepted the Acceptable Use Policy. | Drata inspected %s's records and confirmed that assigned employees have acknowledged the Acceptable Use Policy. | 2025-08-28 22:48:37 |
48 | Drata inspected %s's records and confirmed that assigned contractors have accepted the company's Code of Conduct. | Drata inspected %s's records and confirmed that assigned contractors have acknowledged the company's Code of Conduct. | 2025-08-28 22:48:37 |
49 | Drata inspected %s's records and confirmed that all contractors have accepted the company's Acceptable Use Policy. | Drata inspected %s's records and confirmed that all employees have acknowledged the Acceptable Use Policy. | 2025-08-28 22:48:37 |
55 | Drata inspected %s's records and confirmed that all employees have accepted the company's Code of Conduct upon hire. | Drata inspected %s's records and confirmed that assigned employees have acknowledged the company's Code of Conduct upon hire. | 2025-08-28 22:48:37 |
57 | Drata inspected %s's records and confirmed that all employees have accepted the company's Data Protection Policy upon hire. | %s has established a Data Protection Policy and requires assigned employees to acknowledge it upon hire. Management monitors employees' acknowledgement of the policy. | 2025-08-28 22:48:37 |
191 | %s has established a Data Protection Policy and requires all contractors to accept it. Management monitors contractors' acceptance of the policy. | Drata inspected %s's records and confirmed that all contractors have acknowledged the company's Data Protection Policy. | 2025-08-28 22:48:37 |
205 | Drata inspected %s's trails and confirmed that log file integrity validation is enabled for every trail. | Drata confirmed that AWS CloudTrail log validation is enabled on all trails. | 2025-08-28 22:48:37 |
Download the revision logs
The control revision log is available in the file
controls-diff.csv,The test revision log can also be found in
control-tests.csv.
