Skip to main content

Controls and Tests Updated Between January 2024 and October 2025

Summary of Controls and Tests Updated from January 2024 Through October 2025

What's changed

At Drata, we continuously improve our GRC catalog to reflect the latest security best practices. This page provides a centralized overview of recent updates to controls and monitoring tests.

Control Name Revisions

Expand to view Control Name Revisions

Code

Previous Name

Current Name

Frameworks

Last Updated

DCF-3

Require Encryption of Web-Based Admin Access

Encryption of Web-Based Management Interfaces

CCM, CYBER_ESSENTIALS, FEDRAMP, HIPAA, ISO27001, NIST80053, PCI

2024-12-03 22:39:18

DCF-5

Code Review Process

Change Review Process

CCM, CIS8, CMMC, DRATA_ESSENTIALS, FEDRAMP, ISO27001, ISO270012022, ISO27701, ISO420012023, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, PCI4, SOC_2

2024-12-03 22:39:18

DCF-6

Production Code Changes Restricted

Production Changes Restricted

CCM, CIS8, CMMC, FEDRAMP, ISO27001, ISO270012022, ISO27701, NIST800171, NIST800171R3, NIST80053, NISTCSF2, PCI4, SOC_2

2024-12-03 22:39:18

DCF-7

Separate Testing and Production Environments

Separate Environments

CCM, CIS8, CMMC, DORA, FEDRAMP, ISO27001, ISO270012022, ISO27701, NIS2, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, PCI, PCI4, SOC_2

2024-12-03 22:39:18

DCF-8

Disclosure Process for Customers

External Communication Channels

CIS8, DORA, DRATA_ESSENTIALS, FEDRAMP, HIPAA, ISO27001, ISO420012023, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, PCI4, SOC_2

2024-12-03 22:39:18

DCF-9

Employee Disclosure Process

Internal Communication Channels

CCM, CIS8, DORA, DRATA_ESSENTIALS, FEDRAMP, HIPAA, ISO27001, ISO270012022, ISO27701, ISO420012023, NIST800171R3, NIST80053, NISTCSF2, SOC_2

2024-12-03 22:39:18

DCF-10

System Access Control Policy

Access Control Policy

CCM, CCPA, CIS8, CMMC, CYBER_ESSENTIALS, CYBER_ESSENTIALS_32, DORA, DRATA_ESSENTIALS, FEDRAMP, HIPAA, ISO27001, ISO270012022, ISO270172015, ISO270182019, ISO27701, NIS2, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, PCI4, SOC_2

2024-12-03 22:39:18

DCF-11

Annual Access Control Review

Periodic Access Reviews

CCM, CIS8, CMMC, CYBER_ESSENTIALS, CYBER_ESSENTIALS_32, DORA, FEDRAMP, HIPAA, ISO27001, ISO270012022, ISO270172015, ISO270182019, ISO27701, NIS2, NIST800171, NIST80053, NISTCSF, NISTCSF2, PCI4, SOC_2

2024-12-03 22:39:18

DCF-12

Hardening Standards in Place

Baseline Configuration and Hardening Standards

CCM, CIS8, CMMC, CYBER_ESSENTIALS, CYBER_ESSENTIALS_32, DORA, FEDRAMP, FEDRAMP20X, HIPAA, ISO27001, ISO270012022, ISO270172015, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, PCI, PCI4, SOC_2

2024-12-03 22:39:18

DCF-13

Information Security Policy

Information Security Policies

CCM, CMMC, DORA, DRATA_ESSENTIALS, FEDRAMP, FEDRAMP20X, GDPR, HIPAA, ISO27001, ISO270012022, ISO270172015, ISO270182019, ISO27701, NIS2, NIST800171, NIST80053, NISTCSF, NISTCSF2, PCI, PCI4, SOC_2

2024-12-03 22:39:18

DCF-14

Organizational Chart Maintained

Organizational Chart

CCM, DORA, FEDRAMP, ISO27001, ISO270012022, ISO270172015, ISO27701, ISO420012023, NIST80053, NISTCSF, NISTCSF2, SOC_2

2024-12-03 22:39:18

DCF-16

Annual Risk Assessment

Periodic Risk Assessment

CCM, CMMC, DORA, FEDRAMP, HIPAA, ISO27001, ISO270012022, ISO27701, ISO420012023, NIS2, NIST800171, NIST80053, NISTCSF, NISTCSF2, PCI, SOC_2

2024-12-03 22:39:18

DCF-17

Remediation Plan

Risk Treatment Plan

CCM, CCPA, CIS8, CMMC, DORA, FEDRAMP, HIPAA, ISO27001, ISO270012022, ISO27701, ISO420012023, NIST800171, NIST80053, NISTCSF, NISTCSF2, SOC_2

2024-12-03 22:39:18

DCF-18

Quarterly Vulnerability Scan

Vulnerability Scans

CCM, CCPA, CIS8, CMMC, CYBER_ESSENTIALS, CYBER_ESSENTIALS_32, DORA, DRATA_ESSENTIALS, FEDRAMP, FEDRAMP20X, GDPR, HIPAA, ISO27001, ISO270012022, ISO27701, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, SOC_2

2024-12-03 22:39:18

DCF-19

Annual Penetration Tests

Penetration Tests

CCPA, CIS8, CMMC, CYBER_ESSENTIALS, DORA, DRATA_ESSENTIALS, FEDRAMP, GDPR, HIPAA, ISO27001, ISO270012022, ISO27701, NIS2, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, SOC_2

2024-12-03 22:39:18

DCF-20

Maintains Asset Inventory

Asset Inventory

CCM, CCPA, CIS8, CMMC, CYBER_ESSENTIALS, CYBER_ESSENTIALS_32, DORA, DRATA_ESSENTIALS, FEDRAMP, FEDRAMP20X, HIPAA, ISO27001, ISO270012022, ISO270172015, ISO27701, NIS2, NIST800171, NIST800171R3, NIST80053, NISTAI, NISTCSF, NISTCSF2, PCI, PCI4, SOC_2

2024-12-03 22:39:18

DCF-22

Network segmentation in place

Network Diagram

CCM, CCPA, CIS8, CMMC, CYBER_ESSENTIALS_32, DORA, HIPAA, ISO27001, ISO270012022, ISO270172015, ISO27701, NIST800171, NIST80053, NISTCSF, NISTCSF2, PCI4, SOC_2

2024-12-03 22:39:18

DCF-26

BCP/DR Tests Conducted Annually

BCP/DR Tests

CCM, CCPA, CIS8, DORA, FEDRAMP, FEDRAMP20X, HIPAA, ISO27001, ISO270012022, ISO27701, NIS2, NIST80053, NISTCSF, NISTCSF2, PCI, SOC_2

2024-12-03 22:39:18

DCF-27

Multiple Availability Zones

Cloud Resources Availability

CIS8, DORA, DRATA_ESSENTIALS, FEDRAMP, FEDRAMP20X, HIPAA, ISO27001, ISO270012022, ISO27701, NIST80053, NISTCSF2, SOC_2

2024-12-03 22:39:18

DCF-28

Follow-Ups Tracked

Security Events Tracked and Evaluated

CCM, CIS8, CMMC, CYBER_ESSENTIALS_32, DORA, FEDRAMP, FEDRAMP20X, HIPAA, ISO27001, ISO270012022, ISO27701, ISO420012023, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, PCI4, SOC_2

2024-12-03 22:39:18

DCF-30

Lessons Learned

Incident Response Lessons Learned Documented

CCM, CCPA, CIS8, CMMC, DORA, FEDRAMP, FEDRAMP20X, ISO27001, ISO270012022, ISO27701, NIS2, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, PCI4, SOC_2

2024-12-03 22:39:18

DCF-31

Software Development Life Cycle Policy

Software Development Policies

CCM, CCPA, CIS8, CMMC, DORA, DRATA_ESSENTIALS, FEDRAMP, FEDRAMP20X, HIPAA, ISO27001, ISO270012022, ISO270172015, ISO270182019, ISO27701, NIS2, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, PCI, SOC_2

2024-12-03 22:39:18

DCF-33

Oversight of Security Controls

Periodic Policy Reviews

CCM, CIS8, DORA, HIPAA, ISO27001, ISO270012022, ISO270172015, ISO27701, ISO420012023, NIS2, NIST800171R3, NISTCSF, NISTCSF2, PCI4, SOC_2

2024-12-03 22:39:18

DCF-36

Security Training

Periodic Security Training

CCM, CCPA, CIS8, CMMC, CYBER_ESSENTIALS, DORA, DRATA_ESSENTIALS, FEDRAMP, FEDRAMP20X, HIPAA, ISO27001, ISO270012022, ISO270182019, ISO27701, NIS2, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, PCI, PCI4, SOC_2

2024-12-03 22:39:18

DCF-38

Annual Performance Evaluations

Performance Evaluations

ISO27001, NISTCSF, NISTCSF2, SOC_2

2024-12-03 22:39:18

DCF-42

Defined Management Roles & Responsibilities

Defined Roles and Responsibilities

CCM, DORA, FEDRAMP, HIPAA, ISO27001, ISO270012022, ISO270172015, ISO27701, ISO420012023, NIS2, NIST80053, NISTCSF, NISTCSF2, PCI4, SOC_2

2024-12-03 22:39:18

DCF-46

Formal Recruiting Process

Formal Screening Process

CMMC, DORA, FEDRAMP, ISO27001, ISO270012022, ISO27701, NIST800171, NIST800171R3, NISTCSF, NISTCSF2, PCI, PCI4, SOC_2

2024-12-03 22:39:18

DCF-48

Session Lock

Screen Lockout

CCM, CCPA, CIS8, CMMC, CYBER_ESSENTIALS, CYBER_ESSENTIALS_32, DORA, FEDRAMP, HIPAA, ISO27001, ISO270012022, ISO27701, NIST800171, NIST800171R3, NIST80053, NISTCSF, PCI4, SOC_2

2024-12-03 22:39:18

DCF-50

Malware Detection Software Installed

Antimalware Software on Devices

CCM, CCPA, CIS8, CMMC, CYBER_ESSENTIALS, CYBER_ESSENTIALS_32, DRATA_ESSENTIALS, FEDRAMP, HIPAA, ISO27001, ISO270012022, ISO27701, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, PCI, PCI4, SOC_2

2024-12-03 22:39:18

DCF-51

Security Patches Automatically Applied

Automated Updates on Devices

CCM, CCPA, CIS8, CMMC, CYBER_ESSENTIALS, CYBER_ESSENTIALS_32, DORA, DRATA_ESSENTIALS, FEDRAMP, ISO27001, ISO270012022, ISO27701, NIST800171, NIST800171R3, NIST80053, NISTCSF, PCI, SOC_2

2024-12-03 22:39:18

DCF-54

Data is Encrypted at Rest

Encryption at Rest

CCM, CCPA, CIS8, CMMC, DORA, DRATA_ESSENTIALS, FEDRAMP, FEDRAMP20X, GDPR, HIPAA, ISO27001, ISO270012022, ISO27701, NIS2, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, PCI4, SOC_2

2025-09-23 3:47:31

DCF-55

SSL/TLS Enforced

Encryption in Transit

CCM, CCPA, CIS8, CMMC, DORA, DRATA_ESSENTIALS, FEDRAMP, FEDRAMP20X, HIPAA, ISO27001, ISO270012022, ISO270182019, ISO27701, NIS2, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, PCI4, SOC_2

2024-12-11 14:45:49

DCF-56

Vendor Agreements Maintained

Vendor Register and Agreements

CCM, CCPA, CIS8, CMMC, DORA, DRATA_ESSENTIALS, FEDRAMP, FEDRAMP20X, HIPAA, ISO27001, ISO270012022, ISO270172015, ISO27701, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, PCI4, SOC_2

2024-12-03 22:39:18

DCF-57

Vendor Compliance Reports

Vendor Compliance Monitoring

CCM, CCPA, CIS8, CMMC, DORA, FEDRAMP, HIPAA, ISO27001, ISO270012022, ISO270172015, ISO27701, NIS2, NIST800171, NIST800171R3, NIST80053, NISTAI, NISTCSF, NISTCSF2, PCI4, SOC_2

2024-12-03 22:39:18

DCF-58

Authentication Protocol

Centralized Authentication and Account Management

CCM, CCPA, CIS8, CMMC, CYBER_ESSENTIALS, CYBER_ESSENTIALS_32, FEDRAMP, HIPAA, ISO27001, ISO270172015, NIS2, NIST800171, NIST800171R3, NIST80053, NISTCSF

2024-12-03 22:39:18

DCF-59

Role-Based Security Implementation

Privileged Access Restricted

CCM, CCPA, CIS8, CMMC, CYBER_ESSENTIALS, CYBER_ESSENTIALS_32, DORA, FEDRAMP, HIPAA, ISO27001, ISO270012022, ISO270172015, ISO270182019, ISO27701, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, PCI, PCI4, SOC_2

2024-12-03 22:39:18

DCF-60

Password Storage

Secure Password Storage

CCM, DORA, HIPAA, ISO27001, NIST800171R3, SOC_2

2024-12-03 22:39:18

DCF-62

Inactivity and Browser Exit Logout

Session Termination

CCPA, CIS8, CMMC, DORA, DRATA_ESSENTIALS, FEDRAMP, HIPAA, ISO27001, ISO270012022, ISO27701, NIST800171, NIST800171R3, NIST80053, NISTCSF2, PCI4, SOC_2

2024-12-03 22:39:18

DCF-63

Accepting The Terms of Service

Terms of Service

ISO27001, SOC_2

2024-12-03 22:39:18

DCF-64

Commitments Explained to Customers

Commitments Communicated to Customers

CCM, HIPAA, ISO27001, NISTCSF, NISTCSF2, SOC_2

2024-12-03 22:39:18

DCF-65

Maintains a Privacy Policy

Public Privacy Policy

CCM, CCPA, GDPR, HIPAA, ISO27001, ISO270012022, ISO270182019, ISO27701, NIST80053, NISTCSF, SOC_2

2024-12-03 22:39:18

DCF-66

Maintains a Terms of Service

Master Service Agreements

CCM, ISO27001, NISTCSF, SOC_2

2024-12-03 22:39:18

DCF-67

MFA on Accounts

Multi-Factor Authentication

CCM, CCPA, CIS8, CMMC, CYBER_ESSENTIALS, CYBER_ESSENTIALS_32, FEDRAMP, FEDRAMP20X, ISO27001, ISO270012022, ISO27701, NIS2, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, PCI4, SOC_2

2024-12-03 22:39:18

DCF-68

Password Policy

Password Policy and Configuration

CCM, CCPA, CMMC, CYBER_ESSENTIALS, CYBER_ESSENTIALS_32, DORA, DRATA_ESSENTIALS, FEDRAMP, FEDRAMP20X, HIPAA, ISO27001, ISO270012022, ISO270172015, ISO27701, NIS2, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, PCI, PCI4, SOC_2

2024-12-03 22:39:18

DCF-69

System Access Granted

Access Provisioning

CCM, CIS8, CMMC, CYBER_ESSENTIALS, CYBER_ESSENTIALS_32, DORA, FEDRAMP, HIPAA, ISO27001, ISO270012022, ISO270182019, ISO27701, NIS2, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, PCI4, SOC_2

2024-12-03 22:39:18

DCF-70

Terminated Employee Access Revoked Within One Business Day

Access Deprovisioning

CCM, CCPA, CIS8, CMMC, CYBER_ESSENTIALS, CYBER_ESSENTIALS_32, DORA, FEDRAMP, HIPAA, ISO27001, ISO270012022, ISO270182019, ISO27701, NIS2, NIST800171, NIST800171R3, NISTCSF, NISTCSF2, PCI, PCI4, SOC_2

2024-12-03 22:39:18

DCF-71

Unique Accounts Used

Unique User IDs

CCM, CMMC, CYBER_ESSENTIALS, CYBER_ESSENTIALS_32, DORA, DRATA_ESSENTIALS, FEDRAMP, HIPAA, ISO27001, ISO270012022, ISO270172015, ISO270182019, ISO27701, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, PCI4, SOC_2

2024-12-03 22:39:18

DCF-72

Unique SSH

Root Access Control

CCM, FEDRAMP, HIPAA, ISO27001, ISO270012022, NIST80053, SOC_2

2024-12-03 22:39:18

DCF-73

Denial of Public SSH

Access to Remote Server Administration Ports Restricted

CCM, CCPA, CIS8, CMMC, CYBER_ESSENTIALS_32, DORA, DRATA_ESSENTIALS, FEDRAMP, HIPAA, ISO27001, ISO270012022, ISO27701, NIST800171, NIST800171R3, NIST80053, SOC_2

2024-12-11 14:45:49

DCF-74

Customers Informed of Changes

Communication of System Changes

FEDRAMP, ISO27001, ISO270172015, ISO27701, NIST80053, NISTCSF, SOC_2

2024-12-03 22:39:18

DCF-75

Cloud Data Storage Restricted

Restricted Public Access

CCM, DRATA_ESSENTIALS, FEDRAMP, ISO27001, ISO270012022, ISO270172015, NIS2, NIST800171R3, SOC_2

2025-01-30 19:06:48

DCF-77

Daily Database Backups

Data Backups

CCM, CCPA, CIS8, CYBER_ESSENTIALS, DORA, DRATA_ESSENTIALS, FEDRAMP, HIPAA, ISO27001, ISO270012022, ISO27701, NIST80053, NISTAI, NISTCSF, NISTCSF2, SOC_2

2024-12-03 22:39:18

DCF-78

Storage Buckets are Versioned

Storage Bucket Versioning

CIS8, FEDRAMP, ISO27001, ISO270012022, NIST80053, SOC_2

2024-12-03 22:39:18

DCF-79

Logs Centrally Stored

Logging System

CCPA, CIS8, CMMC, DORA, DRATA_ESSENTIALS, FEDRAMP, FEDRAMP20X, HIPAA, ISO27001, ISO270012022, ISO27701, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, SOC_2

2024-12-03 22:39:18

DCF-85

Firewalls

Network Security Controls

CCM, CCPA, CIS8, CMMC, CYBER_ESSENTIALS, CYBER_ESSENTIALS_32, DRATA_ESSENTIALS, FEDRAMP, FEDRAMP20X, ISO27001, ISO270012022, ISO27701, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, PCI4, SOC_2

2024-12-03 22:39:18

DCF-86

Operational Audit

System Monitoring

CCM, CMMC, DORA, DRATA_ESSENTIALS, FEDRAMP, HIPAA, ISO27001, ISO270012022, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, SOC_2

2025-08-17 0:10:54

DCF-87

Logging/Monitoring

Threat Detection System

CCM, CCPA, CIS8, CMMC, DORA, FEDRAMP, HIPAA, ISO27001, ISO270012022, ISO27701, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, SOC_2

2024-12-03 22:39:18

DCF-90

Root Infrastructure Account Unused

Root Infrastructure Account Monitored

CYBER_ESSENTIALS_32, DORA, FEDRAMP, ISO270012022, NIST800171R3, NIST80053, SOC_2

2024-12-11 14:45:49

DCF-91

Intrusion Detection System in Place

Intrusion Detection/Prevention System

CCM, CCPA, CIS8, CMMC, DORA, FEDRAMP, HIPAA, ISO27001, ISO270012022, ISO27701, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, PCI, PCI4, SOC_2

2024-12-03 22:39:18

DCF-94

Physical Security

Physical Security Policy

CCM, CMMC, DORA, FEDRAMP, GDPR, HIPAA, ISO27001, ISO270012022, ISO27701, NIS2, NIST800171, NIST80053, NISTCSF, NISTCSF2, PCI, PCI4, SOC_2

2024-12-03 22:39:18

DCF-96

Load Balancer Used

Load Balancer

CCM, DORA, FEDRAMP20X, ISO27001, ISO270012022, ISO270172015, ISO27701, NISTCSF, NISTCSF2, SOC_2

2024-12-03 22:39:18

DCF-97

Auto-Scale Configuration

Autoscaling

DORA, FEDRAMP, ISO27001, ISO270012022, ISO270172015, ISO27701, NIST80053, NISTCSF, NISTCSF2, SOC_2

2024-12-03 22:39:18

DCF-98

Daily Backup Statuses Monitored

Backup Storage

CCM, CIS8, CYBER_ESSENTIALS, DORA, FEDRAMP, HIPAA, ISO27001, NIS2, NIST80053, NISTCSF, NISTCSF2

2024-12-11 14:45:49

DCF-99

Failed Backup Alert and Action

Backup Monitoring

CCM, CIS8, CYBER_ESSENTIALS, DORA, HIPAA, ISO27001, ISO270012022, NISTCSF, NISTCSF2, SOC_2

2024-12-11 14:45:49

DCF-100

Backup Integrity and Completeness

Backup Restore Testing

CCM, CCPA, CIS8, CYBER_ESSENTIALS, DORA, FEDRAMP, HIPAA, ISO27001, ISO270012022, ISO27701, NIST80053, NISTCSF, NISTCSF2, SOC_2

2024-12-03 22:39:18

DCF-102

Data Classification

Data Classification Policy

CCM, CCPA, CIS8, DORA, FEDRAMP, HIPAA, ISO27001, ISO270012022, ISO270172015, ISO27701, NIS2, NIST80053, NISTCSF, NISTCSF2, SOC_2

2024-12-03 22:39:18

DCF-104

Test Data Used in Test Environment

Test Data

CCM, DORA, ISO27001, ISO270012022, ISO27701, NIS2, NISTCSF2, PCI, SOC_2

2024-12-03 22:39:18

DCF-105

Employee Non-Disclosure Agreement (NDA)

Personnel Non-Disclosure Agreements (NDA)

CCM, ISO27001, ISO270012022, ISO270182019, ISO27701, NISTCSF2, SOC_2

2024-12-03 22:39:17

DCF-106

Clean Desk Policy in Place

Clean Desk and Clear Screen Policies and Procedures

DORA, HIPAA, ISO27001, ISO270012022, ISO27701, PCI4

2024-12-03 22:39:17

DCF-108

Storage of Sensitive Data on Paper

Secure Storage Mechanisms

CCM, CCPA, CMMC, DORA, HIPAA, ISO27001, ISO270012022, ISO270182019, ISO27701, NIST800171, NIST800171R3, NISTCSF2, PCI4, SOC_2

2024-12-03 22:39:17

DCF-110

Application Edits

Acceptable Input Ranges

CIS8, FEDRAMP, ISO27701, NIST80053, SOC_2

2024-12-03 22:39:18

DCF-111

System Edits

Mandatory Fields

CIS8, ISO27701, SOC_2

2024-12-03 22:39:17

DCF-112

Provide Notice of Privacy Practices

Notice and Acknowledgement of Privacy Practices

HIPAA, ISO27001, ISO270012022, ISO27701, NIST80053, NISTCSF, SOC_2

2024-12-03 22:39:17

DCF-115

Privacy Policy Inclusions

Privacy Policy Content

CCM, CCPA, GDPR, ISO27001, ISO27701, NIST80053, SOC_2

2024-12-03 22:39:17

DCF-116

Accept The Privacy Policy

Acknowledge The Privacy Policy

ISO27001, NIST80053

2024-12-03 22:39:17

DCF-120

Annual Review of Purposes

Periodic Review of Privacy Policy

CCM, DORA, GDPR, HIPAA, ISO27001, ISO270012022, ISO27701, NIST80053, NISTCSF, SOC_2

2024-12-03 22:39:18

DCF-122

Requests for Deletion

Requests for Deletion of PII

NIST80053, SOC_2

2024-12-03 22:39:18

DCF-123

Data Destruction Policy

Procedures for Information Disposal

CCM, CCPA, CIS8, DORA, FEDRAMP, HIPAA, ISO27001, ISO270012022, ISO270172015, ISO270182019, ISO27701, NIST80053, NISTCSF, NISTCSF2, SOC_2

2024-12-03 22:39:18

DCF-126

Users Can Update their Information

Personal Information Accessible Through System Authentication

CYBER_ESSENTIALS_32, FEDRAMP, HIPAA, ISO27001, ISO270182019, ISO27701, NIS2, NIST80053, SOC_2

2024-12-03 22:39:18

DCF-127

Communication to 3rd Parties

Privacy Requirements Communicated to Third parties

CCM, CCPA, HIPAA, ISO27001, NISTCSF, SOC_2

2024-12-03 22:39:18

DCF-130

Tracking Breaches of PII

Documentation of Breaches or Unauthorized Disclosures of PII

CCM, FEDRAMP, GDPR, ISO27001, ISO27701, ISO420012023, NISTCSF, SOC_2

2024-12-03 22:39:18

DCF-135

Notice of Breach to Affected Users

Notification of Incidents or Breaches

CCM, CCPA, CIS8, CMMC, DORA, FEDRAMP, FEDRAMP20X, GDPR, HIPAA, ISO27001, ISO270012022, ISO270182019, ISO27701, ISO420012023, NIS2, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, SOC_2

2024-12-03 22:39:18

DCF-136

Privacy Policy Includes 3rd Party Vendors

Use of Subprocessors Communicated

HIPAA, ISO27001, ISO27701, SOC_2

2024-12-03 22:39:18

DCF-140

Customer Portal

Point of Contact for Privacy Inquiries

CCPA, HIPAA, ISO27701, NIST80053, NISTCSF2, SOC_2

2024-12-03 22:39:18

DCF-141

Customer Inquiries Tracked

Privacy Inquiries Tracked

HIPAA, ISO27701, NIST80053, SOC_2

2024-12-03 22:39:18

DCF-146

Board Meetings Conducted

Board Meetings

ISO27701, NISTAI, NISTCSF2, SOC_2

2024-09-11 1:28:13

DCF-150

DLP (Data Loss Prevention) Software is Used

Data Loss Prevention (DLP) Mechanisms

CCM, CCPA, CIS8, DORA, FEDRAMP, HIPAA, ISO27001, ISO270012022, NISTCSF, NISTCSF2, PCI4, SOC_2

2024-09-11 1:28:13

DCF-152

Virtual Machine OS are Patched Monthly

Automated Security Updates

CIS8, CMMC, CYBER_ESSENTIALS_32, DORA, FEDRAMP, ISO27001, ISO270012022, ISO27701, NIST800171, NIST800171R3, NIST80053, NISTCSF, SOC_2

2024-09-05 21:51:55

DCF-154

Annual Incident Response Test

Incident Response Test

CCPA, CIS8, CMMC, DORA, FEDRAMP, FEDRAMP20X, HIPAA, ISO27001, ISO270012022, ISO420012023, NIS2, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, PCI, PCI4, SOC_2

2024-09-05 21:51:55

DCF-155

Code Changes are Tested

Testing of Changes

CCM, CIS8, CMMC, DORA, FEDRAMP, ISO27001, ISO270012022, ISO27701, ISO420012023, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, SOC_2

2024-05-07 19:18:26

DCF-156

Production Code Released by Appropriate Personnel

Change Releases Approved

CCM, CIS8, CMMC, ISO27001, ISO270012022, ISO420012023, NIST800171, NIST800171R3, PCI4, SOC_2

2024-05-07 19:18:26

DCF-157

Cybersecurity Insurance Maintained

Cybersecurity Insurance

NISTCSF2, SOC_2

2024-05-07 19:18:26

DCF-161

ISMS Scope

Management System Scope

ISO27001, ISO270012022, ISO27701

2024-05-07 19:18:26

DCF-163

Interested Parties and Legal Requirements

Legal Requirements

CCM, DORA, ISO27001, ISO270012022, ISO27701, ISO420012023, NISTAI, NISTCSF, NISTCSF2

2024-09-11 1:28:13

DCF-164

ISMS Management Review

Management System Management Review

DORA, ISO27001, ISO270012022, ISO27701

2024-05-07 19:18:26

DCF-165

Independent Assessment

Periodic Independent Assessments

CCM, CMMC, DORA, FEDRAMP, ISO27001, ISO270012022, ISO270172015, ISO270182019, ISO27701, ISO420012023, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2

2024-09-05 21:51:55

DCF-170

Information Security Objectives

Management System Objectives

DORA, ISO27001, ISO270012022, ISO27701, NISTCSF

2024-12-03 22:39:18

DCF-171

Operating Procedures

Documented Operating Procedures

CCPA, DORA, FEDRAMP, ISO27001, ISO270012022, ISO27701, NIST800171R3, NIST80053, NISTCSF, PCI4

2024-12-03 22:39:18

DCF-175

Communication Plan

Communications Plan

CCM, DORA, ISO27001, ISO270012022, ISO270172015, ISO27701, ISO420012023, NIS2, NISTCSF, NISTCSF2

2024-09-11 1:28:13

DCF-176

Monitoring Plan

Measurement and Monitoring Plan

FEDRAMP, ISO27001, ISO270012022, ISO27701, NIST80053, NISTCSF

2024-05-07 19:18:26

DCF-178

ISMS Record Management and Doc Control

Record Management and Control

ISO27001, ISO270012022, ISO27701

2024-07-11 20:02:42

DCF-179

Information Security Skills Matrix

Competence Records

DORA, HIPAA, ISO27001, ISO270012022, ISO27701, ISO420012023

2024-05-07 19:18:26

DCF-183

Vulnerability Management

Vulnerability Management Policy

CCM, CCPA, CIS8, CMMC, CYBER_ESSENTIALS, CYBER_ESSENTIALS_32, DORA, DRATA_ESSENTIALS, FEDRAMP, FEDRAMP20X, GDPR, HIPAA, ISO27001, ISO270012022, ISO27701, NIS2, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, PCI, PCI4, SOC_2

2024-12-03 22:39:18

DCF-184

Information Security Management System (ISMS)

Management System Plan

DORA, ISO27001, ISO270012022, ISO27701

2024-05-07 19:18:26

DCF-185

Periodic Dynamic Threat Assessment

Threat Intelligence

DORA, FEDRAMP, ISO270012022, NIST80053, NISTCSF, NISTCSF2

2024-05-07 19:18:26

DCF-188

Communication with Security and Privacy Organizations

Communication with Advisories and Special Interest Groups

CCM, CIS8, CMMC, DORA, FEDRAMP, ISO270012022, ISO27701, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, PCI4

2024-05-07 19:18:26

DCF-201

Firewall and Router Configuration Standards

Network Security Controls Configuration Standards

CIS8, CMMC, CYBER_ESSENTIALS, CYBER_ESSENTIALS_32, DORA, NIS2, NIST800171, NIST800171R3, NIST80053, NISTCSF2, PCI, PCI4

2024-01-19 0:22:44

DCF-206

Firewall Configuration

Network Security Controls Between Trusted and Untrusted Networks

CCM, CIS8, CMMC, CYBER_ESSENTIALS, CYBER_ESSENTIALS_32, DORA, FEDRAMP, NIST800171, NIST800171R3, NIST80053, PCI, PCI4

2024-01-19 0:22:44

DCF-210

Insecure Services, Protocols, and Ports List

Insecure Services, Protocols, and Ports Documentation and Control

CIS8, CYBER_ESSENTIALS_32, DORA, FEDRAMP, NIST80053, PCI, PCI4

2024-01-19 0:22:44

DCF-212

Firewall and Router Rule Review

Network Security Controls Review

CIS8, CYBER_ESSENTIALS, DORA, PCI, PCI4

2024-01-19 0:22:44

DCF-215

Secured Router Configuration Files

Secured Configuration Files

CMMC, NIST800171, NISTCSF2, PCI, PCI4

2024-01-19 0:22:44

DCF-216

Perimeter Firewalls between CDE and Wireless Networks

Network Security Controls Restricting Wireless Network Traffic

CIS8, CMMC, NIST800171, NIST800171R3, PCI, PCI4

2024-09-05 21:51:55

DCF-218

DMZ Implemented

Inbound Traffic Restricted Between Untrusted and Trusted Networks

CIS8, CYBER_ESSENTIALS_32, DORA, FEDRAMP, NIS2, NIST80053, PCI, PCI4

2024-01-19 0:22:44

DCF-223

Cardholder Data in Internal Network Zone

Sensitive Data Not Directly Accessible From Untrusted Networks

CIS8, CMMC, DORA, NIST800171, NIST800171R3, PCI, PCI4

2024-01-19 0:22:44

DCF-229

Default Accounts Changed

Vendor Default Accounts Disabled, Removed or Changed

CCM, CIS8, CYBER_ESSENTIALS, CYBER_ESSENTIALS_32, ISO270012022, ISO27701, NIST800171R3, NIST80053, PCI, PCI4

2024-01-19 0:22:44

DCF-231

Changes in Encryption Keys

Changes in Encryption Keys for Wireless Environments

CCM, DORA, NIST80053, PCI, PCI4

2024-01-19 0:22:44

DCF-233

Default Passwords on Access Points Changed

Wireless Network Vendor Defaults Changed

CCM, CIS8, DORA, NIST800171R3, PCI, PCI4

2024-01-19 0:22:44

DCF-239

One Primary Function per Virtual System Components

One Primary Function per System Component

NIST800171R3, PCI, PCI4

2024-01-19 0:22:44

DCF-240

Enable Only Necessary System Function Services

Only Necessary System Function Services Used

CIS8, CMMC, CYBER_ESSENTIALS_32, FEDRAMP, NIST800171, NIST800171R3, NIST80053, NISTCSF2, PCI, PCI4

2024-09-05 21:51:55

DCF-241

Justify Enabled Insecure Services

Documentation and Risk Mitigation for Insecure Services

CYBER_ESSENTIALS_32, PCI, PCI4

2024-01-19 0:22:44

DCF-244

Common System Security Parameters in Configuration Standards

System Security Parameters in Configuration Standards

CIS8, CMMC, FEDRAMP, NIST800171, NIST800171R3, NIST80053, NISTCSF, PCI, PCI4

2024-09-05 21:51:55

DCF-253

Cardholder Data Deleted Securely

Data Secure Disposal

CIS8, ISO270012022, ISO27701, NISTCSF2, PCI, PCI4, SOC_2

2024-05-07 19:18:26

DCF-255

Quarterly Cardholder Data Retention Review

Quarterly Cardholder Data Disposal Review

PCI, PCI4

2024-01-19 0:22:44

DCF-260

Full Track Contents Not Stored

Full Track Contents Not Retained

PCI, PCI4

2025-01-28 20:01:13

DCF-261

Card Verification Code Not Stored

Card Verification Code Not Retained

PCI, PCI4

2025-01-28 20:01:13

DCF-264

PAN is Unreadable Anywhere it is Stored

PAN Unreadable Where Stored

PCI, PCI4

2024-01-19 0:22:44

DCF-267

Cardholder Data on Removable Media Encrypted

Sensitive Data on Removable Media Encrypted

CIS8, PCI, PCI4

2024-01-19 0:22:44

DCF-269

Restricted Key Access

Restricted Cleartext Key Access

PCI, PCI4

2024-01-19 0:22:44

DCF-270

Secret and Private Keys Used for Stored Data

Key-Encrypting Keys Secured

DORA, PCI, PCI4

2024-01-19 0:22:44

DCF-273

Strong Key Generation Procedure

Strong Key Generation Policies and Procedures

CCM, CMMC, DORA, ISO270012022, ISO27701, NIST800171, NIST800171R3, PCI, PCI4, SOC_2

2024-01-19 0:22:44

DCF-278

Replacement of Compromised Keys

Key Retirement Policies and Procedures

CCM, CMMC, DORA, NIS2, NIST800171, NIST800171R3, PCI, PCI4, SOC_2

2024-01-19 0:22:44

DCF-281

Unauthorized Key Substitution

Prevention of Unauthorized Key Substitution

DORA, PCI, PCI4

2024-01-19 0:22:44

DCF-284

Only Trusted Keys or Certificates Accepted

Key and Certificate Validation

CMMC, DORA, FEDRAMP, ISO270012022, NIST800171, NIST800171R3, NIST80053, PCI, PCI4

2024-09-05 21:51:55

DCF-289

PAN Secured in Transmission via End-User Messaging Technologies

Sensitive Data Secured in Transmission via End-User Messaging Technologies

CIS8, DORA, ISO27701, NIS2, PCI, PCI4

2024-01-19 0:22:44

DCF-291

Anti-Virus Capability

Anti-Malware on All System Components

CCM, CCPA, CIS8, CMMC, CYBER_ESSENTIALS, CYBER_ESSENTIALS_32, FEDRAMP, ISO27701, NIST800171, NIST800171R3, NIST80053, NISTCSF, PCI, PCI4

2024-09-05 21:51:55

DCF-293

Anti-Virus Kept Current

Anti-Malware Capabilities and Automatic Updates

CCPA, CIS8, CMMC, CYBER_ESSENTIALS, CYBER_ESSENTIALS_32, DORA, ISO270012022, NIST800171, NIST800171R3, PCI, PCI4, SOC_2

2024-09-05 21:51:55

DCF-294

Anti-Virus Automatic and Periodic Scans

Anti-Malware Tools Behavior

CCM, CIS8, CMMC, CYBER_ESSENTIALS, CYBER_ESSENTIALS_32, ISO270012022, NIST800171, NIST800171R3, NISTCSF, NISTCSF2, PCI, PCI4, SOC_2

2024-09-05 21:51:55

DCF-296

Anti-Virus Configuration

Access to Anti-Virus Configuration

CYBER_ESSENTIALS, PCI, PCI4

2024-01-19 0:22:44

DCF-297

Critical Patches Installed

Patch Management

CCM, CIS8, CMMC, CYBER_ESSENTIALS_32, DORA, FEDRAMP, NIST800171, NIST800171R3, NIST80053, NISTCSF, PCI, PCI4

2024-09-05 21:51:55

DCF-305

Change Control Procedures

Production Components Change Control Procedures

CMMC, FEDRAMP20X, ISO270012022, ISO27701, NIST800171, NIST800171R3, NISTAI, NISTCSF2, PCI, PCI4, SOC_2

2024-09-05 21:51:55

DCF-310

PCI Requirements Implemented Upon Completion of Significant Change

PCI Requirements Validation Upon Changes

PCI, PCI4

2024-01-19 0:22:44

DCF-312

Annual Training for Developer Secure Coding Techniques

Secure Code Development Training

CCM, CIS8, CMMC, FEDRAMP, ISO270012022, NIS2, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, PCI, PCI4, SOC_2

2024-05-07 19:18:26

DCF-329

Access Control System in Place

Access Control System

CCPA, CIS8, CYBER_ESSENTIALS_32, DORA, FEDRAMP20X, NIS2, NIST800171R3, NIST80053, PCI, PCI4

2024-09-17 22:20:24

DCF-330

Role-Based Access Control System

Access Control Model

CCM, CCPA, CIS8, CMMC, DORA, FEDRAMP, FEDRAMP20X, ISO27701, NIS2, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, PCI

2024-07-11 20:02:42

DCF-336

Access Management of Accounts Used by Remote 3rd Parties

Third Party Remote Access Monitored

DORA, FEDRAMP, NIST800171R3, NIST80053, NISTCSF, PCI, PCI4

2024-01-19 0:22:44

DCF-339

Non-consumer Customer Password Lockout after Invalid Access Attempts (Service Provider Only)

Account Lockout after Failed Logins

CIS8, CMMC, CYBER_ESSENTIALS_32, NIST800171, NIST800171R3, PCI, PCI4, SOC_2

2024-09-05 21:51:55

DCF-346

Minimum Password Requirements

Minimum Strong Password Requirements

CCM, CIS8, CYBER_ESSENTIALS, CYBER_ESSENTIALS_32, PCI, PCI4

2025-01-28 20:01:13

DCF-348

Periodic Password Change

Periodic Password Change for In-Scope Components Not In the CDE

PCI, PCI4

2024-01-19 0:22:44

DCF-349

Periodic Password Change for Non-consumer Customer (Service Providers Only)

Guidance Provided to Customers for Password Changes

PCI, PCI4

2024-01-19 0:22:44

DCF-350

Passwords Different from Last Four

Password History Enforcement

CMMC, CYBER_ESSENTIALS_32, ISO270012022, ISO27701, NIST800171, NIST800171R3, PCI, PCI4, SOC_2

2024-09-05 21:51:55

DCF-352

Unique First-time Passwords

Unique First-time Passwords With One-Time Use

CIS8, CMMC, CYBER_ESSENTIALS, CYBER_ESSENTIALS_32, FEDRAMP, ISO270012022, ISO27701, NIST800171, NIST800171R3, PCI, PCI4

2024-01-19 0:22:44

DCF-354

MFA for Non-console Access to CDE

MFA for Non-Console Admin Access

CIS8, CYBER_ESSENTIALS_32, NIS2, PCI, PCI4

2024-01-19 0:22:44

DCF-355

MFA for Remote Network Access

MFA for Remote Access

CCPA, CIS8, CMMC, CYBER_ESSENTIALS_32, DORA, DRATA_ESSENTIALS, FEDRAMP, FEDRAMP20X, NIS2, NIST800171, NIST800171R3, NIST80053, NISTCSF, PCI, PCI4, SOC_2

2024-09-05 21:51:55

DCF-356

Authentication Policy Inclusions

Communication of Authentication Best Practices

CIS8, CYBER_ESSENTIALS_32, FEDRAMP, ISO270012022, ISO27701, NIST80053, PCI, PCI4, SOC_2

2024-05-07 19:18:26

DCF-358

Unique Authentication Credential for Service Providers with Remote Access (Service Providers Only)

Unique Authentication Credential for Service Providers with Remote Access

CYBER_ESSENTIALS_32, DORA, PCI, PCI4

2024-01-19 0:22:44

DCF-360

Programmatic Methods for Database Access

Direct Query Access Restricted

PCI, PCI4

2024-01-19 0:22:44

DCF-364

Physical Access Control to Sensitive Areas

Physical Access Controlled

CCM, CMMC, DORA, FEDRAMP, NIS2, NIST800171, NIST800171R3, NIST80053, NISTCSF, PCI

2024-09-05 21:51:55

DCF-366

Physical Access Control Mechanism Data Review

Physical Access Control Mechanism Periodic Data Review

CCM, DORA, FEDRAMP, NIS2, NIST800171R3, NIST80053, NISTCSF2, PCI, PCI4

2024-09-11 1:28:13

DCF-374

Visitors Preauthorized and Escorted

Visitors Authorized and Escorted

CCM, CMMC, DORA, ISO270012022, ISO27701, NIST800171, NIST800171R3, NISTCSF2, PCI, PCI4, SOC_2

2024-09-05 21:51:55

DCF-375

Visitor Badges

Personnel and Visitor Badges

CCM, CMMC, DORA, ISO270012022, ISO27701, NIST800171, NIST800171R3, NISTCSF2, PCI, PCI4, SOC_2

2024-01-19 0:22:44

DCF-378

Visitor Log to Facility and Data Storage Areas

Visitor Log

CCM, CMMC, DORA, FEDRAMP, ISO270012022, ISO27701, NIST800171, NIST80053, NISTCSF2, PCI, PCI4, SOC_2

2024-09-05 21:51:55

DCF-382

Security Review of Media Backup Storage Location

Security of Offline Media Backup Storage

CMMC, DORA, FEDRAMP, NIST800171, NIST800171R3, NIST80053, PCI, PCI4

2024-09-05 21:51:55

DCF-385

Media Transferred Securely

Media Transported Securely

CMMC, DORA, FEDRAMP, ISO270012022, ISO270182019, ISO27701, NIST800171, NIST800171R3, NIST80053, PCI, PCI4

2024-07-11 20:02:42

DCF-386

Manager Approval for Media Transfer

Management Approval for Media Transport

CMMC, DORA, ISO270012022, ISO270182019, ISO27701, NIST800171, NIST800171R3, PCI, PCI4

2024-07-11 20:02:42

DCF-391

Periodic Media Destruction Policy

Media Destruction Policies and Procedures

CCM, FEDRAMP, NIST80053, NISTCSF, PCI, PCI4

2024-01-19 0:22:44

DCF-406

Audit Trails Enabled and Active

Audit Logging

CIS8, CMMC, DORA, FEDRAMP, ISO270012022, NIST800171, NIST800171R3, NIST80053, NISTCSF2, PCI, PCI4, SOC_2

2025-10-06 23:16:27

DCF-407

System Access Linked to Users

Audit Logs Data Points

CIS8, CMMC, ISO270012022, ISO27701, ISO420012023, NIST800171, NIST800171R3, NIST80053, NISTCSF2, PCI, PCI4, SOC_2

2025-10-06 23:16:27

DCF-409

Audit Trail for Root Admin Privilege Access

Audit Trail for Privileged Access

CCM, CIS8, CMMC, CYBER_ESSENTIALS_32, DORA, FEDRAMP, ISO270012022, ISO27701, NIST800171, NIST800171R3, NIST80053, PCI, PCI4, SOC_2

2024-09-05 21:51:55

DCF-410

Audit Trail Access

Audit Trail Access Logging

CIS8, CMMC, DORA, FEDRAMP, ISO27701, NIST800171, NIST80053, PCI, PCI4

2024-07-11 20:02:42

DCF-411

Invalid Logical Access Attempts

Audit Trail for Invalid Access Attempts

CIS8, DORA, FEDRAMP, ISO270012022, NIST800171R3, NIST80053, NISTCSF2, PCI, PCI4, SOC_2

2024-01-19 0:22:44

DCF-414

Audit Trail of System-Level Object Creation or Deletion

Audit Trail of System-Level Object Changes

CIS8, DORA, ISO270012022, PCI, PCI4, SOC_2

2024-05-07 19:18:26

DCF-421

Critical Clock Synchronization and Update

Clock Synchronization

CCM, CIS8, CMMC, FEDRAMP, ISO270012022, ISO270172015, ISO27701, NIST800171, NIST800171R3, NIST80053, PCI, PCI4

2024-01-19 0:22:44

DCF-434

Policy for Critical Systems Daily Log Review

Policies and Procedures for Logging

CIS8, CMMC, DORA, ISO270012022, ISO27701, ISO420012023, NIST800171, NIST800171R3, NIST80053, NISTCSF2, PCI, PCI4

2024-09-05 21:51:55

DCF-437

Non-critical System Review Aligned with Risk Management

Periodic Review of Non-Critical Logs

CIS8, DORA, NISTCSF2, PCI, PCI4

2024-01-19 0:22:44

DCF-438

Follow-up Procedures on Discovered Anomalies and Exceptions

Follow-up Procedures on Log Review Anomalies and Exceptions

DORA, NISTCSF2, PCI, PCI4

2024-01-19 0:22:44

DCF-455

Quarterly Internal Vulnerability Scans

Internal Vulnerability Scans

CIS8, PCI, PCI4

2025-04-23 21:45:32

DCF-456

High Risk Vulnerabilities Identified and Resolved

Vulnerabilities Identified and Resolved

CIS8, CMMC, CYBER_ESSENTIALS, CYBER_ESSENTIALS_32, DORA, FEDRAMP20X, ISO27701, NIS2, NIST800171, NIST800171R3, NISTCSF2, PCI, PCI4

2024-09-05 21:51:55

DCF-457

Internal Vulnerability Scans by Competent and Independent Party

Independent Internal Vulnerability

PCI

2025-05-12 19:53:26

DCF-458

Quarterly External Vulnerability Scans

Quarterly External Vulnerability Scans (PCI)

PCI, PCI4

2024-01-19 0:22:44

DCF-461

Vulnerability Scans After Significant Change

External Vulnerability Scans After Significant Change

DORA, PCI, PCI4

2024-01-19 0:22:44

DCF-463

Vulnerability Rescans by Competent and Independent Party

Internal Vulnerability Scans by Competent and Independent Party

DORA, PCI, PCI4

2024-01-19 0:22:44

DCF-465

External Penetration Testing Scope

External Penetration Testing Requirements

CIS8, DORA, NIST80053, NISTCSF, PCI, PCI4

2024-01-19 0:22:44

DCF-467

Internal Penetration Testing Scope

Internal Penetration Testing Requirements

CIS8, DORA, NIST80053, NISTCSF, PCI, PCI4

2024-01-19 0:22:44

DCF-469

Resolving Vulnerabilities from Pen Testing

Resolving Vulnerabilities from Penetration Testing

CIS8, NIS2, PCI, PCI4

2024-01-19 0:22:45

DCF-470

Penetration Testing on All Segments

Periodic Penetration Testing on Segmentation Controls

PCI, PCI4

2024-01-19 0:22:45

DCF-473

Periodic Segmentation Control Penetration Testing (Service Providers Only)

Periodic Segmentation Control Penetration Testing

PCI, PCI4

2024-01-19 0:22:45

DCF-478

Change Detection Mechanism in Place

Change Detection Mechanism

CCM, CMMC, DORA, FEDRAMP, ISO270012022, ISO270172015, ISO27701, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, PCI, PCI4, SOC_2

2024-12-11 14:45:49

DCF-479

Change Detection Mechanism Alerts

Periodic Critical File Comparisons

DORA, NIST80053, NISTCSF, PCI, PCI4

2024-01-19 0:22:45

DCF-482

Explicit Approval for Technology Use

Acceptable Use Policy for End-User Technologies

CCM, CYBER_ESSENTIALS_32, DORA, FEDRAMP, PCI, PCI4

2024-01-19 0:22:45

DCF-488

Automatic Disconnect of Inactive Remote-Access

Network Connection Termination

CMMC, DORA, FEDRAMP, NIS2, NIST800171, NIST800171R3, NIST80053, PCI

2024-09-05 21:51:55

DCF-493

PCI DSS Compliance Program (Service Providers Only)

PCI DSS Compliance Program Charter

PCI, PCI4

2024-01-19 0:22:45

DCF-499

Designated Entity to Maintain Incident Response Procedures

Incident Response Plan (PCI)

CCM, ISO270172015, PCI, PCI4

2024-01-19 0:22:45

DCF-507

Pre-Agreement Process for Service Providers

Vendor Due Diligence

CIS8, CMMC, DORA, FEDRAMP20X, ISO270012022, ISO27701, NIS2, NIST800171, NISTCSF2, PCI, PCI4, SOC_2

2024-09-05 21:51:55

DCF-509

Specified PCI DSS Responsibilities of Service Providers

Documented PCI DSS Responsibilities of Service Providers

PCI, PCI4

2024-01-19 0:22:45

DCF-510

Service Providers Acknowledge Security Responsibilities (Service Providers Only)

Service Providers Acknowledge Security Responsibilities

CIS8, DORA, PCI, PCI4

2024-01-19 0:22:45

DCF-516

Security Breach Response Training

Incident Response Training

CCM, CMMC, DORA, NIS2, NIST800171, NIST800171R3, NIST80053, NISTCSF2, PCI, PCI4

2024-09-05 21:51:55

DCF-517

Security Monitoring System Alerts

Monitoring Procedures for System Alerts

CCM, DORA, NIST80053, NISTCSF, PCI, PCI4

2024-01-19 0:22:45

DCF-519

Incident Response Review Inclusions (Service Providers Only)

PCI DSS Compliance Periodic Reviews

CCM, PCI, PCI4

2024-01-19 0:22:45

DCF-521

Quarterly Incident Response Plan Review Report (Service Providers Only)

PCI DSS Compliance Periodic Reviews Documentation

PCI, PCI4

2024-01-19 0:22:45

DCF-534

Communication of Obligations to Data Subjects

Communication to Data Subjects

CCPA, GDPR, ISO27701

2024-07-11 20:02:42

DCF-537

Data Processing Agreements in Place

Data Processing Agreements

CCPA, GDPR, ISO270182019, ISO27701, NIST80053, SOC_2

2024-05-07 19:18:26

DCF-540

Tracking and Response to Data Subject Requests

Timely Response to Data Subject Requests or Inquiries

CCM, CCPA, GDPR, ISO27701, NIST80053, SOC_2

2024-05-07 19:18:26

DCF-541

Management of Data Subject Rights

Procedures for Management of Data Subject Rights

CCM, CCPA, GDPR, ISO27701, SOC_2

2024-05-07 19:18:26

DCF-545

Personal Data Management Policy

Policies for PII Management

CCPA, ISO27701

2024-07-11 20:02:42

DCF-558

Allow-by-Exception Rule for Authorized Applications

Restrictions on Software Installation and Execution

CIS8, CMMC, CYBER_ESSENTIALS, CYBER_ESSENTIALS_32, FEDRAMP, ISO270012022, ISO27701, NIST800171, NIST800171R3, NIST80053, NISTCSF2, SOC_2

2024-09-05 21:51:55

DCF-562

Procedures for Utility Program Use

Management of Utility Programs

CMMC, ISO270012022, ISO270172015, ISO27701, NIST800171, NIST800171R3, PCI4, SOC_2

2024-05-07 19:18:26

DCF-566

Register of Non-conformities

Management of Nonconformities

CCM, CIS8, CMMC, DORA, ISO270012022, ISO27701, NIS2, NIST800171, NIST800171R3, NISTCSF2

2024-05-07 19:18:26

DCF-614

Automated Maintenance Activities

Automated Maintenance Mechanisms

CMMC, FEDRAMP, NIST800171, NIST80053

2024-09-05 21:51:55

DCF-615

Managed Use of Maintenance Tools

Approved Use of Maintenance Tools

CMMC, FEDRAMP, NIST800171, NIST80053, NISTCSF

2024-09-05 21:51:55

DCF-635

Approved PIV Products

Approved Sensitive Information Products

FEDRAMP, NIST80053

2023-02-02 18:20:03

DCF-643

Remote Activation of Collaborative Devices Prohibited

Collaborative Computing Devices and Applications

CMMC, FEDRAMP, NIST800171, NIST800171R3, NIST80053

2024-09-05 21:51:55

DCF-677

Software Updates Installed

Software Update and Patch Management

CIS8, CMMC, CYBER_ESSENTIALS, CYBER_ESSENTIALS_32, DORA, FEDRAMP20X, ISO27701, NIST800171, NISTCSF2, SOC_2

2024-05-07 19:18:26

DCF-678

Global Network Firewall Policy

Network Security Policy

CMMC, CYBER_ESSENTIALS, CYBER_ESSENTIALS_32, DORA, ISO270012022, ISO27701, NIS2, NIST800171, NISTCSF2

2024-05-07 19:18:26

Control Description Revisions

Expand to view Control Description Revisions

Code

Previous Description

Current Description

Frameworks

Last Updated

DCF-3

%s uses encryption to protect user authentication and admin sessions of the internal admin tool transmitted over the Internet.

Administrator access to web-based management interfaces is encrypted with strong cryptographic algorithms.

CCM, CYBER_ESSENTIALS, FEDRAMP, HIPAA, ISO27001, NIST80053, PCI

2024-12-03 22:39:18

DCF-4

%s uses a version control system to manage source code, documentation, release labeling, and other change management tasks. Access to the system must be approved by a system admin.

%s uses a version control system to manage source code, change documentation and tracking, release labeling, and other change management tasks. Access to the version control system is restricted to authorized personnel.

CCM, CIS8, CMMC, FEDRAMP, FEDRAMP20X, ISO27001, ISO270012022, ISO270172015, ISO27701, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, SOC_2

2024-12-03 22:39:18

DCF-5

When %s's application code changes, code reviews and tests are performed by someone other than the person who made the code change.

Changes are peer-reviewed and approved prior to deployment by an individual different from the developer to maintain segregation of duties. Review requirements are enforced through automated mechanisms such as branch protection settings in the production code repository.

CCM, CIS8, CMMC, DRATA_ESSENTIALS, FEDRAMP, ISO27001, ISO270012022, ISO27701, ISO420012023, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, PCI4, SOC_2

2024-12-03 22:39:18

DCF-6

Only authorized %s personnel can push or make changes to production code.

Access to make changes in production environments is restricted to authorized personnel in accordance with segregation of duties principles and the company's documented policies and procedures.

CCM, CIS8, CMMC, FEDRAMP, ISO27001, ISO270012022, ISO27701, NIST800171, NIST800171R3, NIST80053, NISTCSF2, PCI4, SOC_2

2024-12-03 22:39:18

DCF-7

Separate environments are used for testing and production for %s's application

Pre-production environments (e.g., development, testing, etc.) are separated from production environments and the separation is enforced with access controls.

CCM, CIS8, CMMC, DORA, FEDRAMP, ISO27001, ISO270012022, ISO27701, NIS2, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, PCI, PCI4, SOC_2

2024-12-03 22:39:18

DCF-8

%s provides a process to external users for reporting security, confidentiality, integrity, and availability failures, incidents, concerns, and other complaints.

%s provides external communication mechanisms for customers and third parties (e.g., communication features, support portal, external ticketing system, etc.) to report complaints, failures, bugs, incidents, vulnerabilities, requests for information, etc. Customer communications are responded to within defined SLAs.

CIS8, DORA, DRATA_ESSENTIALS, FEDRAMP, HIPAA, ISO27001, ISO420012023, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, PCI4, SOC_2

2024-12-03 22:39:18

DCF-9

%s provides a process to employees for reporting security, confidentiality, integrity, and availability features, incidents, and concerns, and other complaints to company management.

Internal communication channels are in place for employees to report failures, events, incidents, policy violations, concerns, and other issues to company management, including anonymous reporting channels if applicable.

CCM, CIS8, DORA, DRATA_ESSENTIALS, FEDRAMP, HIPAA, ISO27001, ISO270012022, ISO27701, ISO420012023, NIST800171R3, NIST80053, NISTCSF2, SOC_2

2024-12-03 22:39:18

DCF-10

%s has a defined System Access Control Policy that requires annual access control reviews to be conducted and access request forms be filled out for new hires and employee transfers.

%s has developed and documented a policy that outlines requirements for access control.

CCM, CCPA, CIS8, CMMC, CYBER_ESSENTIALS, CYBER_ESSENTIALS_32, DORA, DRATA_ESSENTIALS, FEDRAMP, HIPAA, ISO27001, ISO270012022, ISO270172015, ISO270182019, ISO27701, NIS2, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, PCI4, SOC_2

2024-12-03 22:39:18

DCF-11

%s performs annual access control reviews.

Management performs user access reviews periodically (as defined by policy and compliance requirements) to validate user accounts, including third party or vendor accounts, and their associated privileges remain appropriate. The review includes validation of logical and physical access as necessary. Changes resulting from the review, if any, are documented and implemented.

CCM, CIS8, CMMC, CYBER_ESSENTIALS, CYBER_ESSENTIALS_32, DORA, FEDRAMP, HIPAA, ISO27001, ISO270012022, ISO270172015, ISO270182019, ISO27701, NIS2, NIST800171, NIST80053, NISTCSF, NISTCSF2, PCI4, SOC_2

2024-12-03 22:39:18

DCF-12

Hardening standards are in place to ensure that newly deployed server instances are appropriately secured.

%s has identified and documented baseline security configuration standards for all system components in accordance with industry-accepted hardening standards or vendor recommendations. These standards are reviewed periodically and updated as needed (e.g., when vulnerabilities are identified) and verified to be in place before or immediately after a production system component is installed or modified (e.g., through infrastructure as code, configuration checklists, etc.).

CCM, CIS8, CMMC, CYBER_ESSENTIALS, CYBER_ESSENTIALS_32, DORA, FEDRAMP, FEDRAMP20X, HIPAA, ISO27001, ISO270012022, ISO270172015, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, PCI, PCI4, SOC_2

2024-12-03 22:39:18

DCF-13

%s has a defined Information Security Policy that covers policies and procedures to support the functioning of internal control.

%s has defined and documented an information security policy and other topic-specific policies as needed to support the functioning of internal control.

CCM, CMMC, DORA, DRATA_ESSENTIALS, FEDRAMP, FEDRAMP20X, GDPR, HIPAA, ISO27001, ISO270012022, ISO270172015, ISO270182019, ISO27701, NIS2, NIST800171, NIST80053, NISTCSF, NISTCSF2, PCI, PCI4, SOC_2

2024-12-03 22:39:18

DCF-14

%s reviews its organizational structure, reporting lines, authorities, and responsibilities in terms of information security on an annual basis.

An organizational chart is in place to describe the organizational structure and reporting lines. The chart is available to all employees (e.g., through the company's HRMS, intranets, etc.) and is updated upon changes to the organizational structure.

CCM, DORA, FEDRAMP, ISO27001, ISO270012022, ISO270172015, ISO27701, ISO420012023, NIST80053, NISTCSF, NISTCSF2, SOC_2

2024-12-03 22:39:18

DCF-15

%s has defined a formal risk management process that specifies risk tolerances and the process for evaluating risks based on identified threats and the specified tolerances.

%s has defined and documented a process for risk assessment and risk management that outlines the organization's approach for identifying risks and assigning risk owners, the risk acceptance criteria, and the approach for evaluating and treating risks based on the defined criteria.

CCM, CIS8, CMMC, DORA, FEDRAMP, GDPR, HIPAA, ISO27001, ISO270012022, ISO27701, ISO420012023, NIS2, NIST800171, NIST80053, NISTAI, NISTCSF, NISTCSF2, PCI, SOC_2

2024-12-03 22:39:18

DCF-16

%s conducts a Risk Assessment at least annually.

%s conducts risks assessments periodically as required by company policy and compliance requirements. The risk assessment includes consideration of threats and vulnerabilities and an evaluation of the likelihood and impact for each risk. A risk owner is assigned to each risk, and every risk is assigned a risk treatment option. Results of the risk assessment are documented (e.g., in a risk register).

CCM, CMMC, DORA, FEDRAMP, HIPAA, ISO27001, ISO270012022, ISO27701, ISO420012023, NIS2, NIST800171, NIST80053, NISTCSF, NISTCSF2, PCI, SOC_2

2024-12-03 22:39:18

DCF-17

%s's Management prepares a remediation plan to formally manage the resolution of findings identified in risk assessment activities.

%s's management has documented a risk treatment plan to formally manage risks identified in risk assessment activities.

CCM, CCPA, CIS8, CMMC, DORA, FEDRAMP, HIPAA, ISO27001, ISO270012022, ISO27701, ISO420012023, NIST800171, NIST80053, NISTCSF, NISTCSF2, SOC_2

2024-12-03 22:39:18

DCF-18

%s engages with third-party to conduct vulnerability scans of the production environment at least quarterly. Results are reviewed by management and high priority findings are tracked to resolution.

%s conducts vulnerability scans of the production environment as dictated by company policy and compliance requirements. Results are reviewed by company personnel and vulnerabilities are tracked to resolution in accordance with company policies.

CCM, CCPA, CIS8, CMMC, CYBER_ESSENTIALS, CYBER_ESSENTIALS_32, DORA, DRATA_ESSENTIALS, FEDRAMP, FEDRAMP20X, GDPR, HIPAA, ISO27001, ISO270012022, ISO27701, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, SOC_2

2024-12-03 22:39:18

DCF-19

%s engages with third-party to conduct penetration tests of the production environment at least annually. Results are reviewed by management and high priority findings are tracked to resolution.

An external penetration test of production environments is performed by an independent third party periodically or after any significant infrastructure or application changes. Results are reviewed by management and vulnerabilities are tracked to resolution in accordance with company policies.

CCPA, CIS8, CMMC, CYBER_ESSENTIALS, DORA, DRATA_ESSENTIALS, FEDRAMP, GDPR, HIPAA, ISO27001, ISO270012022, ISO27701, NIS2, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, SOC_2

2024-12-03 22:39:18

DCF-20

%s maintains an asset register for physical, cloud, and other information assets that includes business description, owner, and other attributes deemed relevant by the organization.

A centralized asset register is maintained for physical, cloud, and other assets that includes descriptive attributes for asset accountability such as owner, description, location, classification, and/or other information based on the type of asset. Processes are in place to maintain an updated inventory through manual reviews (e.g., as a result of new purchases, installations, removals, system changes, etc.) or automated mechanisms.

CCM, CCPA, CIS8, CMMC, CYBER_ESSENTIALS, CYBER_ESSENTIALS_32, DORA, DRATA_ESSENTIALS, FEDRAMP, FEDRAMP20X, HIPAA, ISO27001, ISO270012022, ISO270172015, ISO27701, NIS2, NIST800171, NIST800171R3, NIST80053, NISTAI, NISTCSF, NISTCSF2, PCI, PCI4, SOC_2

2024-12-03 22:39:18

DCF-21

%s maintains an accurate architectural diagram to document system boundaries to support the functioning of internal control.

A documented architectural diagram is in place to document system boundaries and support the functioning of internal control. The diagram is reviewed and approved by management at least annually and updated as necessary when there are changes to the environment.

CCM, CCPA, CIS8, DORA, DRATA_ESSENTIALS, FEDRAMP, HIPAA, ISO27001, ISO420012023, NIST80053, NISTCSF, PCI, SOC_2

2024-12-03 22:39:18

DCF-22

%s maintains an accurate network diagram that is accessible to the engineering team and is reviewed by management on an annual basis.

A documented network diagram is in place to document system boundaries and connections to external networks. The diagram is reviewed and approved by management at least annually and updated as necessary when there are changes to the environment.

CCM, CCPA, CIS8, CMMC, CYBER_ESSENTIALS_32, DORA, HIPAA, ISO27001, ISO270012022, ISO270172015, ISO27701, NIST800171, NIST80053, NISTCSF, NISTCSF2, PCI4, SOC_2

2024-12-03 22:39:18

DCF-25

%s has an established Disaster Recovery Plan that outlines roles and responsibilities and detailed procedures for recovery of systems.

%s has a documented disaster recovery plan that outlines roles, responsibilities and detailed procedures for recovery of systems in the event of a disaster scenario.

CCM, CCPA, CIS8, DORA, DRATA_ESSENTIALS, FEDRAMP, FEDRAMP20X, GDPR, HIPAA, ISO27001, ISO270012022, ISO27701, NIS2, NIST80053, NISTCSF, NISTCSF2, PCI, SOC_2

2024-12-03 22:39:18

DCF-26

%s conducts annual BCP/DR tests and documents according to the BCDR Plan.

%s conducts tests of the business continuity/disaster recovery plans at least annually. Results and lessons learned are documented, and updates to the plans are made as necessary.

CCM, CCPA, CIS8, DORA, FEDRAMP, FEDRAMP20X, HIPAA, ISO27001, ISO270012022, ISO27701, NIS2, NIST80053, NISTCSF, NISTCSF2, PCI, SOC_2

2024-12-03 22:39:18

DCF-27

%s utilizes multiple availability zones to replicate production data across different zones.

Business-critical cloud resources are deployed in accordance with high availability architecture principles (e.g., replicated across multiple availability zones or regions, configured for high-availability, etc.).

CIS8, DORA, DRATA_ESSENTIALS, FEDRAMP, FEDRAMP20X, HIPAA, ISO27001, ISO270012022, ISO27701, NIST80053, NISTCSF2, SOC_2

2024-12-03 22:39:18

DCF-28

%s has implemented an Incident Response Plan that includes creating, prioritizing, assigning, and tracking follow-ups to completion and lending support to Business Continuity/Disaster Recovery.

%s evaluates security events to determine if they constitute an incident. Incidents are assigned a priority, categorized, documented, tracked, escalated, contained, eradicated, communicated, and resolved in accordance with company policies and procedures.

CCM, CIS8, CMMC, CYBER_ESSENTIALS_32, DORA, FEDRAMP, FEDRAMP20X, HIPAA, ISO27001, ISO270012022, ISO27701, ISO420012023, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, PCI4, SOC_2

2024-12-03 22:39:18

DCF-29

%s has identified an incident response team that quantifies and monitors incidents involving security, availability, processing integrity, and confidentiality at the company.

%s has identified and documented roles and responsibilities for incident management (e.g., roles and responsibilities for invoking the incident management process, incident leads, incident handlers, communication coordinators, technical advisors, legal advisors, etc.).

CCM, CIS8, DORA, DRATA_ESSENTIALS, FEDRAMP, HIPAA, ISO27001, ISO270012022, ISO420012023, NIS2, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, PCI, SOC_2

2024-12-03 22:39:18

DCF-30

%s has implemented an Incident Response Plan that includes documenting “Lessons Learned” and "Root Cause Analysis" after incidents and sharing them with the broader engineering team to support Business Continuity/Disaster Recovery.

%s documents a post-mortem review for identified incidents that includes incident metadata, root-cause analysis, documentation of evidence, summary of containment, eradication, and recovery actions, timelines, incident metrics, evidence of internal and external communications, estimation of impact and scope, and lessons learned, as applicable, in accordance with company policies and procedures.

CCM, CCPA, CIS8, CMMC, DORA, FEDRAMP, FEDRAMP20X, ISO27001, ISO270012022, ISO27701, NIS2, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, PCI4, SOC_2

2024-12-03 22:39:18

DCF-31

%s has developed policies and procedures governing the system development life cycle, including documented policies for tracking, testing, approving, and validating changes.

%s has developed policies and procedures governing the system development life cycle, including requirements, design, implementation, testing, and deployment.

CCM, CCPA, CIS8, CMMC, DORA, DRATA_ESSENTIALS, FEDRAMP, FEDRAMP20X, HIPAA, ISO27001, ISO270012022, ISO270172015, ISO270182019, ISO27701, NIS2, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, PCI, SOC_2

2024-12-03 22:39:18

DCF-32

%s Management has approved security policies, and all employees accept these procedures when hired. Management also ensures that security policies are accessible to all employees and contractors.

Company policies are accessible to all employees and, as applicable, third parties such as contractors. Personnel are required to acknowledge the information security policy and other topic-specific policies based on their job duties during onboarding and annually thereafter.

CCM, CYBER_ESSENTIALS_32, DORA, FEDRAMP, GDPR, ISO27001, ISO270012022, ISO270172015, ISO27701, NIS2, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, PCI, PCI4, SOC_2

2024-12-03 22:39:18

DCF-33

Management reviews security policies on an annual basis.

Management reviews and approves company policies at least annually. Updates to the policies are made as deemed necessary (e.g., based on changes to business objectives, legal or regulatory requirements, organizational risks, etc.).

CCM, CIS8, DORA, HIPAA, ISO27001, ISO270012022, ISO270172015, ISO27701, ISO420012023, NIS2, NIST800171R3, NISTCSF, NISTCSF2, PCI4, SOC_2

2024-12-03 22:39:18

DCF-36

%s has established training programs for privacy and information security to help employees understand their obligations and responsibilities to comply with %s's security policies and procedures, including the identification and reporting of incidents. All full-time employees are required to complete the training upon hire and annually thereafter.

%s has established training programs to help personnel gain awareness of information security best practices. Personnel (including employees and contractors as applicable) are required to complete the training during onboarding. Periodic refresher training is provided to personnel at least annually and as deemed necessary (e.g., upon changes in security requirements, policies, regulations, etc.).

CCM, CCPA, CIS8, CMMC, CYBER_ESSENTIALS, DORA, DRATA_ESSENTIALS, FEDRAMP, FEDRAMP20X, HIPAA, ISO27001, ISO270012022, ISO270182019, ISO27701, NIS2, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, PCI, PCI4, SOC_2

2024-12-03 22:39:18

DCF-37

%s has policies and procedures in place to establish acceptable use of information assets approved by management, posted on the company wiki, and accessible to all employees. All employees must accept the Acceptable Use Policy upon hire.

%s has a documented acceptable use policy that outlines requirements for personnel's usage of company assets.

CCM, CCPA, CMMC, CYBER_ESSENTIALS, DORA, DRATA_ESSENTIALS, FEDRAMP, HIPAA, ISO27001, ISO270012022, ISO270172015, ISO27701, NIS2, NIST800171, NIST800171R3, NIST80053, PCI, SOC_2

2024-12-03 22:39:18

DCF-38

%s evaluates the performance of all employees through a formal, annual performance evaluation.

Management conducts periodic evaluations of performance against established goals and objectives for eligible personnel in accordance with company policies and procedures.

ISO27001, NISTCSF, NISTCSF2, SOC_2

2024-12-03 22:39:18

DCF-39

%s's new hires are required to pass a background check as a condition of their employment.

Background checks are conducted on eligible personnel (employees and third parties as deemed necessary by the organization) prior to hire as permitted by local laws.

CCM, CMMC, FEDRAMP, HIPAA, ISO27001, ISO270012022, ISO27701, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, PCI, PCI4, SOC_2

2024-12-03 22:39:18

DCF-40

%s requires its contractors to read and accept the Code of Conduct, read and accept the Acceptable Use Policy, and pass a background check.

%s requires its contractors to read and acknowledge the Code of Conduct, read and acknowledge the Acceptable Use Policy, and pass a background check.

CCM, FEDRAMP, HIPAA, ISO27001, NIST80053, NISTCSF

2024-12-03 22:39:18

DCF-41

Members of the Board of Directors are independent of management.

The board of directors includes members independent from management who are not involved in control operations.

SOC_2

2024-12-03 22:39:18

DCF-42

Management has established defined roles and responsibilities to oversee implementation of the information security policy across the organization.

Management has defined and documented roles and responsibilities for implementation and oversight of the risk management and compliance programs (e.g., security, privacy, AI, etc.).

CCM, DORA, FEDRAMP, HIPAA, ISO27001, ISO270012022, ISO270172015, ISO27701, ISO420012023, NIS2, NIST80053, NISTCSF, NISTCSF2, PCI4, SOC_2

2024-12-03 22:39:18

DCF-44

%s has a formal Code of Conduct approved by management and accessible to all employees. All employees must accept the Code of Conduct upon hire.

%s maintains a documented code of conduct. Eligible personnel are required to acknowledge %s's code of conduct during onboarding and annually thereafter.

CCM, DORA, DRATA_ESSENTIALS, HIPAA, ISO27001, ISO270012022, ISO27701, NIS2, NISTCSF2, SOC_2

2024-12-03 22:39:18

DCF-45

%s has established a Data Protection Policy and requires all employees to accept it upon hire. Management monitors employees' acceptance of the policy.

%s has a documented a policy that outlines the procedures and technical measures to be implemented at the organization to protect the confidentiality, integrity, and availability of data.

CCM, CCPA, CIS8, CMMC, DORA, DRATA_ESSENTIALS, FEDRAMP, GDPR, HIPAA, ISO27001, ISO270012022, ISO270172015, ISO270182019, ISO27701, NIS2, NIST800171, NIST80053, NISTCSF, NISTCSF2, PCI, SOC_2

2024-12-03 22:39:18

DCF-46

%s's new hires and/or internal transfers are required to go through an official recruiting process during which their qualifications and experience are screened to ensure that they are competent and capable of fulfilling their responsibilities.

Management evaluates candidates for employment through a formal screening process. The process may include verification of academic and professional qualifications, identity verifications, validation of personal or professional references, technical interviews, or other steps as deemed applicable by the organization.

CMMC, DORA, FEDRAMP, ISO27001, ISO270012022, ISO27701, NIST800171, NIST800171R3, NISTCSF, NISTCSF2, PCI, PCI4, SOC_2

2024-12-03 22:39:18

DCF-47

All %s positions have a detailed job description that lists qualifications, such as requisite skills and experience, which candidates must meet in order to be hired by %s.

%s has documented job descriptions for each position at the company, which include roles and responsibilities as well as required qualifications, skills, and experience for the role.

CCM, ISO27001, ISO270012022, ISO27701, NISTCSF, NISTCSF2, SOC_2

2024-12-03 22:39:18

DCF-48

%s ensures that all company-issued computers use a screensaver lock with a timeout of no more than 15 minutes.

Company-managed devices are configured to enforce a screensaver lock with after a defined period of inactivity in accordance with company policies and compliance requirements.

CCM, CCPA, CIS8, CMMC, CYBER_ESSENTIALS, CYBER_ESSENTIALS_32, DORA, FEDRAMP, HIPAA, ISO27001, ISO270012022, ISO27701, NIST800171, NIST800171R3, NIST80053, NISTCSF, PCI4, SOC_2

2024-12-03 22:39:18

DCF-49

%s ensures that a password manager is installed on all company-issued laptops.

A password manager is installed on all company-managed devices.

CCM, CYBER_ESSENTIALS, CYBER_ESSENTIALS_32, FEDRAMP, HIPAA, ISO27001, ISO270012022, SOC_2

2024-12-03 22:39:18

DCF-50

%s requires antivirus software to be installed on workstations to protect the network against malware.

Anti-malware software is installed on all company-managed devices.

CCM, CCPA, CIS8, CMMC, CYBER_ESSENTIALS, CYBER_ESSENTIALS_32, DRATA_ESSENTIALS, FEDRAMP, HIPAA, ISO27001, ISO270012022, ISO27701, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, PCI, PCI4, SOC_2

2024-12-03 22:39:18

DCF-51

%s's workstations operating system (OS) security patches are applied automatically.

Automated operating system (OS) updates are enabled on company-managed devices to install security patches.

CCM, CCPA, CIS8, CMMC, CYBER_ESSENTIALS, CYBER_ESSENTIALS_32, DORA, DRATA_ESSENTIALS, FEDRAMP, ISO27001, ISO270012022, ISO27701, NIST800171, NIST800171R3, NIST80053, NISTCSF, PCI, SOC_2

2024-12-03 22:39:18

DCF-52

%s ensures that company-issued laptops have encrypted hard-disks.

Hard-disk encryption is enabled on all company-managed devices.

CCM, CCPA, CIS8, CMMC, CYBER_ESSENTIALS, CYBER_ESSENTIALS_32, DRATA_ESSENTIALS, FEDRAMP, HIPAA, ISO27001, ISO270012022, ISO27701, NIS2, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, SOC_2

2024-12-03 22:39:18

DCF-54

%s stores data in databases that is encrypted at rest.

Data at rest is encrypted using strong cryptographic algorithms.

CCM, CCPA, CIS8, CMMC, DORA, DRATA_ESSENTIALS, FEDRAMP, FEDRAMP20X, GDPR, HIPAA, ISO27001, ISO270012022, ISO27701, NIS2, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, PCI4, SOC_2

2025-09-23 3:47:31

DCF-55

%s ensures that all connections to its web application from its users are encrypted.

Data in transit is encrypted using strong cryptographic algorithms.

CCM, CCPA, CIS8, CMMC, DORA, DRATA_ESSENTIALS, FEDRAMP, FEDRAMP20X, HIPAA, ISO27001, ISO270012022, ISO270182019, ISO27701, NIS2, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, PCI4, SOC_2

2024-12-11 14:45:49

DCF-56

%s maintains a directory of its key vendors, including its agreements that specify terms, conditions and responsibilities.

%s maintains a vendor/third party register that includes a complete and accurate list of vendors/third parties, relationship owners, description for each of the services provided, risk ratings, results of vendor/third party risk management activities, etc. %s executes agreements with vendors and service providers involved in accessing, processing, storing or managing information assets that outline the responsibilities of each vendor or service provider.

CCM, CCPA, CIS8, CMMC, DORA, DRATA_ESSENTIALS, FEDRAMP, FEDRAMP20X, HIPAA, ISO27001, ISO270012022, ISO270172015, ISO27701, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, PCI4, SOC_2

2024-12-03 22:39:18

DCF-57

%s obtains and reviews compliance reports (e.g., SOC 2, ISO, PCI) or other evidence for critical vendors and service providers at least annually to monitor the third parties' compliance with industry frameworks, regulations, standards. Results of the review and action items, if any, are documented.

%s obtains and reviews compliance reports or other evidence for critical vendors and service providers at least annually to monitor the third parties' compliance with industry frameworks, regulations, standards (e.g., SOC 2, ISO, PCI DSS, etc.) and %s's requirements. Results of the review and action items, if any, are documented.

CCM, CCPA, CIS8, CMMC, DORA, FEDRAMP, HIPAA, ISO27001, ISO270012022, ISO270172015, ISO27701, NIS2, NIST800171, NIST800171R3, NIST80053, NISTAI, NISTCSF, NISTCSF2, PCI4, SOC_2

2024-12-03 22:39:18

DCF-58

Username and password (password standard implemented) or SSO required to authenticate into application, MFA optional for external users, and MFA required for employee users.

%s has implemented systems or mechanisms to centralize authentication and account management across the organization (e.g., directory service, identity provider, etc.).

CCM, CCPA, CIS8, CMMC, CYBER_ESSENTIALS, CYBER_ESSENTIALS_32, FEDRAMP, HIPAA, ISO27001, ISO270172015, NIS2, NIST800171, NIST800171R3, NIST80053, NISTCSF

2024-12-03 22:39:18

DCF-59

Role-based security is in place for internal and external users, including super admin users.

Administrative or privileged access to systems, resources, and functions is restricted to authorized personnel.

CCM, CCPA, CIS8, CMMC, CYBER_ESSENTIALS, CYBER_ESSENTIALS_32, DORA, FEDRAMP, HIPAA, ISO27001, ISO270012022, ISO270172015, ISO270182019, ISO27701, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, PCI, PCI4, SOC_2

2024-12-03 22:39:18

DCF-60

%s's application user passwords are stored using a salted password hash.

%s has implemented technical measures to protect stored user passwords for the system (e.g., encryption, hashing, salting, etc.).

CCM, DORA, HIPAA, ISO27001, NIST800171R3, SOC_2

2024-12-03 22:39:18

DCF-61

%s's customer data is segregated from the data of other customers

%s has implemented segregation mechanisms so that customers cannot impact or access data or resources of other customers.

CIS8, DORA, ISO27001, ISO270172015, PCI4, SOC_2

2024-12-03 22:39:18

DCF-62

%s automatically logs users out after a predefined inactivity interval and/or closure of the internet browser, and requires users to reauthenticate

%s's systems automatically terminate a user's logical session based on predefined conditions (e.g., predefined periods of inactivity, closure of the system or internet browser, etc.).

CCPA, CIS8, CMMC, DORA, DRATA_ESSENTIALS, FEDRAMP, HIPAA, ISO27001, ISO270012022, ISO27701, NIST800171, NIST800171R3, NIST80053, NISTCSF2, PCI4, SOC_2

2024-12-03 22:39:18

DCF-63

External users must accept the Terms of Service prior to their account being created.

%s maintains a publicly available terms of service for use of the system. All users must agree to the terms of service prior to using the system.

ISO27001, SOC_2

2024-12-03 22:39:18

DCF-64

%s's security commitments are communicated to external users, as appropriate.

%s communicates service commitments and system requirements to customers and other external parties, as appropriate, through contracts, agreements, company website, etc. %s provides notification to relevant parties of any changes to service commitments and system requirements.

CCM, HIPAA, ISO27001, NISTCSF, NISTCSF2, SOC_2

2024-12-03 22:39:18

DCF-65

%s maintains a Privacy Policy that is available to all external users and internal employees, and it details the company's confidentiality and privacy commitments.

%s maintains a publicly available privacy policy/notice.

CCM, CCPA, GDPR, HIPAA, ISO27001, ISO270012022, ISO270182019, ISO27701, NIST80053, NISTCSF, SOC_2

2024-12-03 22:39:18

DCF-66

%s maintains a Terms of Service that is available to all external users and internal employees, and the terms detail the company's security and availability commitments regarding the systems. Client Agreements or Master Service Agreements are in place for when the Terms of Service may not apply.

Master service agreements outlining specific requirements are executed with enterprise customers or when the standard terms of service may not apply.

CCM, ISO27001, NISTCSF, SOC_2

2024-12-03 22:39:18

DCF-67

%s requires two factor authentication to access sensitive systems and applications in the form of user ID, password, OTP and/or certificate.

Authentication to systems requires the use of multi-factor authentication.

CCM, CCPA, CIS8, CMMC, CYBER_ESSENTIALS, CYBER_ESSENTIALS_32, FEDRAMP, FEDRAMP20X, ISO27001, ISO270012022, ISO27701, NIS2, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, PCI4, SOC_2

2024-12-03 22:39:18

DCF-68

%s has established formal guidelines for passwords to govern the management and use of authentication mechanisms.

%s has a documented policy outlining the minimum requirements for passwords used for authentication to organizational systems. Password requirements are enforced for all systems in accordance with company policy.

CCM, CCPA, CMMC, CYBER_ESSENTIALS, CYBER_ESSENTIALS_32, DORA, DRATA_ESSENTIALS, FEDRAMP, FEDRAMP20X, HIPAA, ISO27001, ISO270012022, ISO270172015, ISO27701, NIS2, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, PCI, PCI4, SOC_2

2024-12-03 22:39:18

DCF-69

Appropriate levels of access to infrastructure and code review tools are granted to new employees within one week of their start date.

Access requests to information resources, including physical access and access to systems and data, are documented and approved by management based on least privilege, need to know, and segregation of duties principles.

CCM, CIS8, CMMC, CYBER_ESSENTIALS, CYBER_ESSENTIALS_32, DORA, FEDRAMP, HIPAA, ISO27001, ISO270012022, ISO270182019, ISO27701, NIS2, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, PCI4, SOC_2

2024-12-03 22:39:18

DCF-70

Access to infrastructure and code review tools is removed from terminated employees within one business day.

System and physical access is revoked within one business day of effective termination date for terminated users (including employees, third parties and vendors, and other personnel).

CCM, CCPA, CIS8, CMMC, CYBER_ESSENTIALS, CYBER_ESSENTIALS_32, DORA, FEDRAMP, HIPAA, ISO27001, ISO270012022, ISO270182019, ISO27701, NIS2, NIST800171, NIST800171R3, NISTCSF, NISTCSF2, PCI, PCI4, SOC_2

2024-12-03 22:39:18

DCF-71

Access to corporate network, production machines, network devices, and support tools requires a unique ID.

Authentication to systems requires the use of unique identities.

CCM, CMMC, CYBER_ESSENTIALS, CYBER_ESSENTIALS_32, DORA, DRATA_ESSENTIALS, FEDRAMP, HIPAA, ISO27001, ISO270012022, ISO270172015, ISO270182019, ISO27701, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, PCI4, SOC_2

2024-12-03 22:39:18

DCF-72

SSH users use unique accounts to access production machines. Additionally, the use of the “Root” account is not allowed.

Root password authentication to production resources (e.g., virtual machines, containers, etc.) is disabled and only allowed for under exceptional circumstances for a limited time duration based on documented business justification and approval from management.

CCM, FEDRAMP, HIPAA, ISO27001, ISO270012022, NIST80053, SOC_2

2024-12-03 22:39:18

DCF-73

No public SSH is allowed.

Network security controls are in place to restrict public access to remote server administration ports (e.g., SSH, RDP) to authorized IP addresses or address ranges only.

CCM, CCPA, CIS8, CMMC, CYBER_ESSENTIALS_32, DORA, DRATA_ESSENTIALS, FEDRAMP, HIPAA, ISO27001, ISO270012022, ISO27701, NIST800171, NIST800171R3, NIST80053, SOC_2

2024-12-11 14:45:49

DCF-74

%s communicates system changes to customers that may affect security, availability, processing integrity, or confidentiality.

%s communicates system changes via release notes or change log in the company's website or via periodic communications.

FEDRAMP, ISO27001, ISO270172015, ISO27701, NIST80053, NISTCSF, SOC_2

2024-12-03 22:39:18

DCF-75

Read/Write access to cloud data storage is configured to restrict public access.

Cloud resources are configured to deny public access.

CCM, DRATA_ESSENTIALS, FEDRAMP, ISO27001, ISO270012022, ISO270172015, NIS2, NIST800171R3, SOC_2

2025-01-30 19:06:48

DCF-76

%s authorizes designated member(s) with the autonomy to validate, change, and release critical security patches and bug fixes, outside of the standard change management process, when absolutely necessary to ensure security standards and availability of the systems.

Emergency changes or hot fixes implemented outside of the standard change management process are reviewed and approved by an authorized individual after implementation.

CCM, DORA, FEDRAMP, ISO27001, ISO270012022, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, SOC_2

2024-12-03 22:39:18

DCF-77

Backups of production data are performed least daily and are retained per company policies and procedures.

Backups of production data are performed at least daily and are configured to be retained in accordance with the retention periods established in company policies and procedures.

CCM, CCPA, CIS8, CYBER_ESSENTIALS, DORA, DRATA_ESSENTIALS, FEDRAMP, HIPAA, ISO27001, ISO270012022, ISO27701, NIST80053, NISTAI, NISTCSF, NISTCSF2, SOC_2

2024-12-03 22:39:18

DCF-78

Storage buckets that contain customer data are versioned.

Storage buckets that contain sensitive data have versioning enabled to preserve, retrieve, and restore versions of objects.

CIS8, FEDRAMP, ISO27001, ISO270012022, NIST80053, SOC_2

2024-12-03 22:39:18

DCF-79

%s uses a system that collects and stores server logs in a central location. The system can be queried in an ad hoc fashion by authorized users.

%s uses a centralized system that collects and stores logs of system activity and sends alerts to personnel based on pre-configured rules. Access to logs is restricted to authorized personnel.

CCPA, CIS8, CMMC, DORA, DRATA_ESSENTIALS, FEDRAMP, FEDRAMP20X, HIPAA, ISO27001, ISO270012022, ISO27701, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, SOC_2

2024-12-03 22:39:18

DCF-85

%s uses configurations that ensure only approved networking ports and protocols are implemented, including firewalls.

Network security controls are in place to limit inbound and outbound traffic to the environment to only what is necessary based on business justification. All other traffic is specifically denied.

CCM, CCPA, CIS8, CMMC, CYBER_ESSENTIALS, CYBER_ESSENTIALS_32, DRATA_ESSENTIALS, FEDRAMP, FEDRAMP20X, ISO27001, ISO270012022, ISO27701, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, PCI4, SOC_2

2024-12-03 22:39:18

DCF-86

%s's cloud infrastructure is monitored through an operational audit system that sends alerts to appropriate personnel

Production systems and resources are monitored and automated alerts are sent out personnel based on pre-configured rules. Events are triaged to determine if they constitute an incident and escalated per policy if necessary.

CCM, CMMC, DORA, DRATA_ESSENTIALS, FEDRAMP, HIPAA, ISO27001, ISO270012022, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, SOC_2

2025-08-17 0:10:54

DCF-87

%s has infrastructure logging configured to monitor web traffic and suspicious activity. When anomalous traffic activity is identified, alerts are automatically created, sent to appropriate personnel and resolved, as necessary.

A threat detection system is in place to monitor web traffic and suspicious activity. When anomalous traffic activity is identified, alerts are automatically sent to personnel, investigated, and escalated through the incident management process, if necessary.

CCM, CCPA, CIS8, CMMC, DORA, FEDRAMP, HIPAA, ISO27001, ISO270012022, ISO27701, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, SOC_2

2024-12-03 22:39:18

DCF-88

WAF in place to protect %s's application from outside threats.

A web application firewall is in place to protect public-facing web applications from outside threats.

CCM, CCPA, CIS8, CMMC, CYBER_ESSENTIALS, CYBER_ESSENTIALS_32, DORA, DRATA_ESSENTIALS, FEDRAMP, FEDRAMP20X, ISO27001, ISO270012022, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, PCI4, SOC_2

2024-12-11 14:45:49

DCF-89

%s is using Drata to monitor the security and compliance of its cloud infrastructure configuration

%s is using Drata to monitor the security and compliance of its cloud infrastructure configuration.

ISO27001

2024-12-03 22:39:18

DCF-90

%s does not use Root Account on Infrastructure provider

Access to the root account in the cloud infrastructure provider is monitored. Login activity for the root account is investigated and validated for appropriateness.

CYBER_ESSENTIALS_32, DORA, FEDRAMP, ISO270012022, NIST800171R3, NIST80053, SOC_2

2024-12-11 14:45:49

DCF-91

An intrusion detection system (IDS) is in place to detect potential intrusions, alert personnel when a potential intrusion is detected

An intrusion detection system (IDS)/intrusion prevention system (IPS) or equivalent is in place to detect real-time suspicious or anomalous network traffic that may be indicative of threat actor activity and is configured to alert personnel when a potential intrusion is detected.

CCM, CCPA, CIS8, CMMC, DORA, FEDRAMP, HIPAA, ISO27001, ISO270012022, ISO27701, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, PCI, PCI4, SOC_2

2024-12-03 22:39:18

DCF-92

Users can only access the production system remotely through the use of encrypted communication systems.

Remote access to production systems is only available through an encrypted connection (e.g., encrypted virtual private network, SSH, etc.)

CCM, CCPA, CIS8, CMMC, DORA, FEDRAMP, HIPAA, ISO27001, ISO270012022, ISO27701, NIS2, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, SOC_2

2024-12-03 22:39:18

DCF-94

%s has security policies that have been approved by management and detail how physical security for the company's headquarters is maintained. These policies are accessible to all employees and contractors.

%s has a documented policy that outlines requirements for physical security.

CCM, CMMC, DORA, FEDRAMP, GDPR, HIPAA, ISO27001, ISO270012022, ISO27701, NIS2, NIST800171, NIST80053, NISTCSF, NISTCSF2, PCI, PCI4, SOC_2

2024-12-03 22:39:18

DCF-95

%s monitors its processing capacity and usage on a quarterly basis in order to appropriately manage capacity demand and to enable the implementation of additional capacity to meet availability commitments.

%s monitors processing capacity and use of resources continuously to manage demand and to enable the implementation of additional resources as necessary.

DORA, FEDRAMP, ISO27001, ISO270012022, ISO270172015, ISO27701, NIST80053, NISTCSF, NISTCSF2, SOC_2

2024-12-03 22:39:18

DCF-96

%s uses a load balancer to automatically distribute incoming application traffic across multiple instances and availability zones.

%s uses a load balancer to automatically distribute incoming traffic across multiple targets.

CCM, DORA, FEDRAMP20X, ISO27001, ISO270012022, ISO270172015, ISO27701, NISTCSF, NISTCSF2, SOC_2

2024-12-03 22:39:18

DCF-97

%s automatically provisions new server instances when predefined capacity thresholds are met.

%s has enabled auto-scaling configurations to provision new cloud resources when predefined capacity thresholds are met.

DORA, FEDRAMP, ISO27001, ISO270012022, ISO270172015, ISO27701, NIST80053, NISTCSF, NISTCSF2, SOC_2

2024-12-03 22:39:18

DCF-98

%s monitors the status of backups on a daily basis and action is taken when the backup process fails.

Backups are encrypted and segmented from production systems (e.g., air-gapped, replicated to a different region, stored offsite, etc.) to ensure protection from a disaster or incident.

CCM, CIS8, CYBER_ESSENTIALS, DORA, FEDRAMP, HIPAA, ISO27001, NIS2, NIST80053, NISTCSF, NISTCSF2

2024-12-11 14:45:49

DCF-99

%s has an automated email sent to appropriate personnel when the backup process fails. Failed backups are resolved in a timely manner.

Automated notifications are sent to personnel in the event of a backup failure. Backup failures are investigated and resolved by engineering personnel following company policies and procedures.

CCM, CIS8, CYBER_ESSENTIALS, DORA, HIPAA, ISO27001, ISO270012022, NISTCSF, NISTCSF2, SOC_2

2024-12-11 14:45:49

DCF-100

%s tests the integrity and completeness of back-up information on an annual basis.

%s tests the integrity and recoverability of backed-up data at least annually.

CCM, CCPA, CIS8, CYBER_ESSENTIALS, DORA, FEDRAMP, HIPAA, ISO27001, ISO270012022, ISO27701, NIST80053, NISTCSF, NISTCSF2, SOC_2

2024-12-03 22:39:18

DCF-101

%s has a documented policy for data retention defining the types of data (including company and customer data) and the period of time for which they should be retained.

%s has a documented and implemented a policy for data retention defining the types of data (including company and customer data) and the period of time for which they should be retained.

CCM, CIS8, FEDRAMP, HIPAA, ISO27001, ISO270012022, ISO270172015, ISO270182019, ISO27701, NIS2, NIST800171R3, NIST80053, NISTCSF2, PCI, PCI4, SOC_2

2024-12-03 22:39:18

DCF-102

%s has established a data classification policy in order to identify the types of confidential information possessed by the entity and types of protection that are required.

%s has established a data classification policy in order to identify the types of information stored or processed by the organization and the protection measures that are required for each.

CCM, CCPA, CIS8, DORA, FEDRAMP, HIPAA, ISO27001, ISO270012022, ISO270172015, ISO27701, NIS2, NIST80053, NISTCSF, NISTCSF2, SOC_2

2024-12-03 22:39:18

DCF-103

%s deletes customer data within 30 days of the customer terminating its contract.

%s disposes of customer data upon termination of services in accordance with contractual agreements.

CCM, HIPAA, ISO27001, ISO270012022, ISO27701, SOC_2

2024-12-03 22:39:18

DCF-104

%s uses test data within test environments.

Test data is used in testing and development environments to prevent sensitive information from being copied to non-production environments.

CCM, DORA, ISO27001, ISO270012022, ISO27701, NIS2, NISTCSF2, PCI, SOC_2

2024-12-03 22:39:18

DCF-105

%s's new hire contracts include a non-disclosure agreement (NDA)

Personnel, including employees and contractors, are required to sign an agreement that outlines confidentiality requirements (e.g., non-disclosure agreements) prior to hire.

CCM, ISO27001, ISO270012022, ISO270182019, ISO27701, NISTCSF2, SOC_2

2024-12-03 22:39:17

DCF-106

%s has a clean desk policy in place to ensure that documents containing sensitive data are not in public areas or laying on unattended employee work areas

%s has defined clear desk and clear screen policies and procedures to protect confidential data (physical and electronic) which are communicated to personnel and enforced across the organization.

DORA, HIPAA, ISO27001, ISO270012022, ISO27701, PCI4

2024-12-03 22:39:17

DCF-107

%s disposes of hardcopy material with sensitive data when no longer needed (for legal or business reasons, or upon expiration of their retention period) through secure means such as cross-cut shredding, incinerating, or pulping, so that the data cannot be reconstructed.

When %s disposes of hard copy materials, it does so through secure means such as cross-cut shredding, incinerating, or pulping, so that sensitive data cannot be reconstructed.

CCM, CCPA, CIS8, FEDRAMP, HIPAA, ISO27001, ISO270012022, ISO270182019, ISO27701, NIST80053, NISTCSF2, PCI4, SOC_2

2024-12-03 22:39:17

DCF-108

%s places paper documents containing sensitive data in a secured storage bin

%s uses secure storage mechanisms for digital media and hardcopy materials that contain sensitive data (e.g., locked codes, combination locks to offices, rooms and facilities such as key cabinets, etc.) as well as critical equipment and other assets. Access to the secured storage mechanisms (including access to physical keys and knowledge of authentication information) is restricted to authorized personnel.

CCM, CCPA, CMMC, DORA, HIPAA, ISO27001, ISO270012022, ISO270182019, ISO27701, NIST800171, NIST800171R3, NISTCSF2, PCI4, SOC_2

2024-12-03 22:39:17

DCF-110

%s's application edits limit input to acceptable value ranges

%s's has implemented automated edit checks in the system to limit input to defined value ranges and formats.

CIS8, FEDRAMP, ISO27701, NIST80053, SOC_2

2024-12-03 22:39:18

DCF-109

%s has formal policies and procedures in place to guide personnel in the disposal of hardware containing sensitive data.

%s disposes of data on hardware through secure means, such as wiping and hard drive destruction, in accordance with documented policies and procedures.

CCM, CCPA, CIS8, FEDRAMP, HIPAA, ISO27001, ISO270012022, ISO270182019, ISO27701, NIST80053, NISTCSF2, SOC_2

2024-12-03 22:39:17

DCF-111

%s system edits require mandatory fields to be complete before record entry is accepted.

Automated application checks are in place that require mandatory fields to be complete before data entry is accepted.

CIS8, ISO27701, SOC_2

2024-12-03 22:39:17

DCF-112

%s provides notice of its privacy practices to users prior to users entering information into its application.

%s provides notice of its privacy practices to users prior to accessing the system. Users are required to explicitly acknowledge the privacy policy prior to entering information into the system.

HIPAA, ISO27001, ISO270012022, ISO27701, NIST80053, NISTCSF, SOC_2

2024-12-03 22:39:17

DCF-115

%s's Privacy Policy includes: -Purpose for collecting personal information -Choice and consent -Types of personal information collected -Methods of collection (for example, use of cookies or other tracking techniques) -Use, retention, and disposal -Access -Disclosure to third parties -Security for privacy -Quality, including data subjects' responsibilities for quality -Monitoring and enforcement

%s's documented Privacy Policy includes information on: - Purpose for collecting/processing personal information - Lawful basis for collecting/processing personal information - Types of personal information collected or processed - Choice and consent - Methods of collection (for example, use of cookies or other tracking techniques) - Use, retention, and disposal - Data subject rights - Use of subprocessors - Technical and organizational measures - Quality, including data subjects' responsibilities for quality - Monitoring and enforcement

CCM, CCPA, GDPR, ISO27001, ISO27701, NIST80053, SOC_2

2024-12-03 22:39:17

DCF-116

%s's users are required to explicitly accept the notice of privacy practices prior to entering information into the application.

%s's users are required to explicitly acknowledge the notice of privacy practices prior to entering information into the application.

ISO27001, NIST80053

2024-12-03 22:39:17

DCF-120

%s's management reviews privacy policies and procedures annually to ensure that personal information is used in conformity with the purposes identified in the privacy notice.

%s's management reviews the online privacy policy and/or notice at least annually to validate its continued suitability and accuracy. The online privacy policy/notice includes the date it was last updated. %s notifies customers of changes to the privacy notice and the nature of the changes, including when personal information will be used for new purposes not previously identified.

CCM, DORA, GDPR, HIPAA, ISO27001, ISO270012022, ISO27701, NIST80053, NISTCSF, SOC_2

2024-12-03 22:39:18

DCF-122

%s captures requests for deletion of personal information and information related to the requests is appropriately deleted.

%s complies with legitimate requests to delete PII from data subjects by permanently and completely erasing the personal information from its existing systems or de-identifying the personal information within the timelines established by regulatory requirements. %s provides notification to subprocessors and contractors of the need to delete and informs the data subject whether it has complied with the consumer’s request. Supporting documentation is retained.

NIST80053, SOC_2

2024-12-03 22:39:18

DCF-123

%s implements policies and procedures to erase or otherwise destroy personal information that has been identified for destruction.

%s has documented policies and procedures for erasure or destruction of information that has been identified for disposal.

CCM, CCPA, CIS8, DORA, FEDRAMP, HIPAA, ISO27001, ISO270012022, ISO270172015, ISO270182019, ISO27701, NIST80053, NISTCSF, NISTCSF2, SOC_2

2024-12-03 22:39:18

DCF-126

Users can correct, amend, or append their personal information by logging into the application and navigating to their settings and profile.

%s provides a mechanism for users to view, correct, and/or delete their personal information by authenticating into the system with a username and password and navigating to their profile settings.

CYBER_ESSENTIALS_32, FEDRAMP, HIPAA, ISO27001, ISO270182019, ISO27701, NIS2, NIST80053, SOC_2

2024-12-03 22:39:18

DCF-127

%s's privacy policies or other specific instructions or requirements for handling personal information are communicated to third parties to whom personal information is disclosed.

%s's privacy policies or other specific instructions for handling personal information, including requirements and procedures to notify %s of breaches or unauthorized disclosures, are communicated to third parties to whom personal information is disclosed.

CCM, CCPA, HIPAA, ISO27001, NISTCSF, SOC_2

2024-12-03 22:39:18

DCF-130

%s tracks and logs breaches involving unauthorized uses and disclosures of personal information in an incident tracking system.

%s maintains documentation of any personal data breaches or unauthorized disclosures of PII including the facts relating to the personal data breach or disclosure, its effects and impact, and the remedial action taken.

CCM, FEDRAMP, GDPR, ISO27001, ISO27701, ISO420012023, NISTCSF, SOC_2

2024-12-03 22:39:18

DCF-132

%s ensures that information security requirements for handling data, especially sensitive privacy data (e.g., PII, PHI, Cardholder Data), are included in vendor and third-party agreements (e.g., Data Processing Agreements, Business Associates Agreements, Service Provider Agreements).

%s shares information with vendors and third parties only when an executed agreement (e.g., service agreements, business associate agreements, data processing agreements, etc.) is in place that includes security, confidentiality, and privacy requirements for the transfer and processing of information.

CCM, CIS8, DORA, HIPAA, ISO27001, ISO270012022, ISO27701, NIST800171R3, NISTAI, NISTCSF2, SOC_2

2024-12-03 22:39:18

DCF-135

%s has a process for providing notice of breaches and incidents to affected data subjects to meet %s's objectives related to privacy.

%s provides communications about breaches and incidents to affected parties, organizational officials, authorities, and other internal and external stakeholders, in accordance with company policies and procedures and contractual and legal obligations.

CCM, CCPA, CIS8, CMMC, DORA, FEDRAMP, FEDRAMP20X, GDPR, HIPAA, ISO27001, ISO270012022, ISO270182019, ISO27701, ISO420012023, NIS2, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, SOC_2

2024-12-03 22:39:18

DCF-136

%s's privacy practices posted on their website include the list of third parties authorized to receive personal information.

%s communicates to customers any use of subprocessors to process PII (e.g., through a list of subprocessors in the company website or data processing agreement, etc.). %s obtains authorization from customers for the use of subprocessors (e.g., through executed data processing agreements, accepting the terms in the website, etc.).

HIPAA, ISO27001, ISO27701, SOC_2

2024-12-03 22:39:18

DCF-140

Data subjects can submit inquiries, complaints, and disputes via the customer portal.

%s provides a contact mechanism for data subjects to submit privacy-related requests or report privacy incidents (e.g., email address, customer portal, etc.).

CCPA, HIPAA, ISO27701, NIST80053, NISTCSF2, SOC_2

2024-12-03 22:39:18

DCF-141

%s has a process for tracking users' inquiries, complaints, and disputes within the incident tracking system.

%s maintains records of privacy rights requests in ticket or log format that includes the date of request, nature of request, manner in which the request was made, the date of the business’s response, the nature of the response, and the basis for the denial of the request if the request is denied in whole or in part. Records are retained for a defined period in accordance with legal requirements.

HIPAA, ISO27701, NIST80053, SOC_2

2024-12-03 22:39:18

DCF-146

The company's board of directors or a relevant subcommittee meets at least annually to discuss company performance, strategic objectives, compliance initiatives, and cybersecurity and privacy risk and mitigation strategies.

The company's board of directors, owners, senior leadership, or equivalent body, meets at least annually with management to review company performance, strategic objectives, compliance initiatives, and security and privacy risk and mitigation strategies. Meeting minutes, including decisions made and action items, are documented.

ISO27701, NISTAI, NISTCSF2, SOC_2

2024-09-11 1:28:13

DCF-149

%s ensures that company-issued removable media devices (USB drives) are encrypted.

%s encrypts removable media devices, such as USB drives, digital video disks, compact disks, external or removable hard disks, etc., that contain sensitive data, to protect the confidentiality of the information during transport.

CCM, CIS8, CMMC, DORA, FEDRAMP, HIPAA, ISO27001, ISO270012022, ISO270182019, ISO27701, NIS2, NIST800171, NIST80053, NISTCSF, NISTCSF2, SOC_2

2024-07-11 20:02:42

DCF-150

%s uses DLP (Data Loss Prevention) software to prevent unencrypted sensitive information from being transmitted over email

%s has implemented data leakage prevention mechanisms to systems that could process, store or transmit sensitive information (e.g., sending personal information via email). These mechanisms are configured to prevent data leakage and generate audit logs and alerts.

CCM, CCPA, CIS8, DORA, FEDRAMP, HIPAA, ISO27001, ISO270012022, NISTCSF, NISTCSF2, PCI4, SOC_2

2024-09-11 1:28:13

DCF-152

%s ensures that virtual machine OS patches are applied monthly.

%s has implemented automated mechanisms (e.g., unattended upgrades, automated patching tools, etc.) to install security fixes to systems.

CIS8, CMMC, CYBER_ESSENTIALS_32, DORA, FEDRAMP, ISO27001, ISO270012022, ISO27701, NIST800171, NIST800171R3, NIST80053, NISTCSF, SOC_2

2024-09-05 21:51:55

DCF-154

%s ensures that incident response plan testing is performed on an annual basis.

%s performs a test of all components of the incident response plan and procedures at least annually through different mechanisms (e.g., walk-through or tabletop exercises, simulations, etc.). The documented plan and procedures are updated if necessary based on the results of the test.

CCPA, CIS8, CMMC, DORA, FEDRAMP, FEDRAMP20X, HIPAA, ISO27001, ISO270012022, ISO420012023, NIS2, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, PCI, PCI4, SOC_2

2024-09-05 21:51:55

DCF-155

%s ensures that code changes are tested prior to deployment to ensure quality and security.

Changes are tested in an environment separate from production prior to deployment in accordance with the nature of the change. Documented evidence of testing criteria and testing results is retained.

CCM, CIS8, CMMC, DORA, FEDRAMP, ISO27001, ISO270012022, ISO27701, ISO420012023, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, SOC_2

2024-05-07 19:18:26

DCF-156

%s ensures that releases are approved by appropriate members of management prior to production release.

Change releases are approved by authorized personnel prior to deployment to production.

CCM, CIS8, CMMC, ISO27001, ISO270012022, ISO420012023, NIST800171, NIST800171R3, PCI4, SOC_2

2024-05-07 19:18:26

DCF-157

%s maintains cybersecurity insurance to mitigate the financial impact of business disruptions.

%s maintains cybersecurity insurance to mitigate the financial impact of security incidents and business disruptions.

NISTCSF2, SOC_2

2024-05-07 19:18:26

DCF-159

%s has a documented incident response plan that outlines roles, responsibilities, and procedures to respond to incidents.

%s has a documented an incident response plan that outlines roles, responsibilities, and procedures to document, analyze, categorize, and respond to incidents. The incident response plan reviewed periodically and updated as needed according to lessons learned from previous incidents and industry developments.

CCM, CCPA, CIS8, CMMC, DORA, DRATA_ESSENTIALS, FEDRAMP, FEDRAMP20X, GDPR, HIPAA, ISO27001, ISO270012022, ISO270172015, ISO270182019, ISO27701, ISO420012023, NIS2, NIST800171, NIST800171R3, NIST80053, NISTAI, NISTCSF, NISTCSF2, PCI, PCI4, SOC_2

2024-12-03 22:39:18

DCF-160

%s conducts continuous monitoring of security controls using Drata, and addresses issues in a timely manner.

%s uses compliance automation software to identify, select, and continuously monitor internal controls.

CCM, CCPA, CMMC, DORA, FEDRAMP, HIPAA, ISO27001, ISO270012022, ISO27701, ISO420012023, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, SOC_2

2024-12-03 22:39:18

DCF-161

%s has a well-defined documented scope that reflects the boundaries and applicability of its Information Security Management System

%s has documented the scope of its management system(s) that outlines the boundaries and applicability of the system(s) and considers internal and external issues, requirements of interested parties, and interfaces and dependencies with other organizations.

ISO27001, ISO270012022, ISO27701

2024-05-07 19:18:26

DCF-162

%s has a documented statement of applicability, which defines and applies necessary controls for the implementation of an information security risk treatment process.

%s has a documented statement of applicability, which defines the controls deemed necessary by the organization as a result of the risk assessment to implement the risk treatment plan.

ISO27001, ISO270012022, ISO27701

2024-05-07 19:18:26

DCF-163

%s has identified and documented the interested parties and the legal, statutory, regulatory and contractual requirements relevant to its security and privacy management program.

%s has identified and documented the legal, statutory, regulatory and contractual requirements relevant to the organization. %s has assigned responsibility and identified and implemented processes to satisfy these requirements and monitor and review changes.

CCM, DORA, ISO27001, ISO270012022, ISO27701, ISO420012023, NISTAI, NISTCSF, NISTCSF2

2024-09-11 1:28:13

DCF-164

%s's top management conducts scheduled reviews of the ISMS to ensure effectiveness and relevance.

%s's top management conducts reviews of its management system(s) at planned intervals to evaluate suitability, adequacy and effectiveness. %s retains documentation of the results of management reviews.

DORA, ISO27001, ISO270012022, ISO27701

2024-05-07 19:18:26

DCF-165

%s has an independent assessment (e.g., internal audit) process to ensure that its information security program is effectively implemented, maintained, and in conformance.

%s conducts evaluations and assessments at planned intervals to ensure that internal controls are effectively implemented and maintained in conformance with the organization's requirements (e.g., internal audits). %s retains documented information of the assessment program(s) and results.

CCM, CMMC, DORA, FEDRAMP, ISO27001, ISO270012022, ISO270172015, ISO270182019, ISO27701, ISO420012023, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2

2024-09-05 21:51:55

DCF-166

%s has a defined Business Continuity Plan that outlines the proper procedures to respond, recover, resume, and restore operations following a disruption or significant change.

%s has a defined business continuity plan that outlines strategies for maintaining operations during a disruption.

CCM, CCPA, CIS8, DORA, FEDRAMP, FEDRAMP20X, GDPR, HIPAA, ISO27001, ISO270012022, ISO27701, NIS2, NIST80053, NISTCSF, NISTCSF2, PCI, SOC_2

2024-12-03 22:39:18

DCF-167

%s has a Business Impact Analysis process to determine resources and time required to ensure business continuity after a disruptive incident.

%s performs a business impact analysis (BIA) periodically to identify criticality, business recovery order, and minimum service levels for key business processes and assets. Results of the business impact analysis are documented and incorporated into business continuity and disaster recovery plans.

CCM, DORA, FEDRAMP, HIPAA, ISO27001, ISO270012022, ISO27701, NIS2, NIST80053, NISTCSF, NISTCSF2

2024-12-03 22:39:18

DCF-168

%s has a documented policy that outlines requirements for managing vendor and third party relationships.

%s has a documented policy that outlines requirements for managing vendor and third-party relationships through their entire life cycle.

CCM, CCPA, CIS8, CMMC, DORA, DRATA_ESSENTIALS, FEDRAMP, FEDRAMP20X, HIPAA, ISO27001, ISO270012022, ISO270172015, ISO270182019, ISO27701, ISO420012023, NIS2, NIST800171, NIST80053, NISTAI, NISTCSF, NISTCSF2, SOC_2

2024-12-03 22:39:18

DCF-169

%s has a defined backup policy that establishes the requirements for backup information, software and systems.

%s has defined and documented a backup policy that establishes the requirements for backup information, software and systems.

CCM, CIS8, CYBER_ESSENTIALS, DORA, DRATA_ESSENTIALS, FEDRAMP, GDPR, HIPAA, ISO27001, ISO270012022, ISO270182019, ISO27701, NIS2, NIST80053, NISTAI, NISTCSF, NISTCSF2, PCI, SOC_2

2024-12-03 22:39:18

DCF-170

%s has documented security objectives and procedures to achieve those objectives.

%s has documented objectives for its management system(s) (e.g., security objectives, privacy objectives, AI objectives, etc.) and plans to achieve them.

DORA, ISO27001, ISO270012022, ISO27701, NISTCSF

2024-12-03 22:39:18

DCF-171

%s has documented procedures for operations relating to information processing and communication facilities

%s maintains documented procedures that describe how to perform activities including controls, methods, and processes to be followed to achieve the company's policies objectives and compliance activities. The procedures are reviewed and updated as needed to address changes in processes, technologies, and business objectives, or at least annually, and are available to all relevant parties.

CCPA, DORA, FEDRAMP, ISO27001, ISO270012022, ISO27701, NIST800171R3, NIST80053, NISTCSF, PCI4

2024-12-03 22:39:18

DCF-173

%s has an established Employment Terms and Conditions that defines obligations and responsibilities in line with information security policies.

Personnel responsibilities for information security (including confidentiality, legal, and data handling requirements), including responsibilities that remain after employment, are communicated to and acknowledged by personnel (e.g., through employment contracts, etc.)

CCM, CMMC, DORA, ISO27001, ISO270012022, ISO27701, NIST800171, NISTCSF2, SOC_2

2024-12-03 22:39:17

DCF-175

%s has a defined communications plan that establishes procedures for internal and external communications relevant to its information security program.

%s has documented communication plans that establishes procedures for internal and external communications relevant to its information security, privacy, or other programs.

CCM, DORA, ISO27001, ISO270012022, ISO270172015, ISO27701, ISO420012023, NIS2, NISTCSF, NISTCSF2

2024-09-11 1:28:13

DCF-176

%s has a defined process for evaluating information security performance and the effectiveness of its information security program.

%s has defined performance and/or effectiveness measurements for its management system(s) and implemented procedures to monitor these measurements periodically as determined by the organization.

FEDRAMP, ISO27001, ISO270012022, ISO27701, NIST80053, NISTCSF

2024-05-07 19:18:26

DCF-178

%s has an established system for record management and document control.

%s implemented procedures for the control of documented information relevant for its management system(s).

ISO27001, ISO270012022, ISO27701

2024-07-11 20:02:42

DCF-179

%s has an established list of applicable information security roles and specified skill and competence level required for each role.

%s has identified and documented skill and competence requirements for personnel that contribute to the development, implementation and oversight of its management system(s) and retains documented evidence of competence.

DORA, HIPAA, ISO27001, ISO270012022, ISO27701, ISO420012023

2024-05-07 19:18:26

DCF-180

%s has a defined process to ensure the secure transfer of information internally and externally.

%s has defined and documented policies and procedures for the secure transfer of information within the organization and with any external parties.

CCM, CMMC, DORA, FEDRAMP, ISO27001, ISO270012022, ISO270182019, ISO27701, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2

2024-12-03 22:39:18

DCF-181

%s has a defined policy that establishes requirements for the use of cryptographic controls.

%s has a documented policy that establishes requirements for the use of cryptographic controls.

CCM, CMMC, DORA, FEDRAMP, GDPR, HIPAA, ISO27001, ISO270012022, ISO270172015, ISO27701, NIS2, NIST800171, NIST800171R3, NIST80053, PCI, SOC_2

2024-12-03 22:39:18

DCF-182

%s has a defined policy that establishes requirements for the proper management and tracking of organizational assets.

%s has established and documented a policy that outlines requirements for the management and tracking of company assets.

CCM, CCPA, CIS8, CMMC, CYBER_ESSENTIALS, CYBER_ESSENTIALS_32, DORA, FEDRAMP, HIPAA, ISO27001, ISO270012022, ISO270172015, ISO27701, NIS2, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, SOC_2

2024-12-03 22:39:18

DCF-183

%s has a defined policy that establishes requirements for vulnerability assessments and reporting.

%s has a defined policy that establishes requirements for vulnerability management across the organization, including monitoring, cataloging, and assigning risk ratings to vulnerabilities to prioritize remediation efforts.

CCM, CCPA, CIS8, CMMC, CYBER_ESSENTIALS, CYBER_ESSENTIALS_32, DORA, DRATA_ESSENTIALS, FEDRAMP, FEDRAMP20X, GDPR, HIPAA, ISO27001, ISO270012022, ISO27701, NIS2, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, PCI, PCI4, SOC_2

2024-12-03 22:39:18

DCF-184

%s has a defined and documented Information Security Management System (ISMS) Plan, for the establishment, implementation, maintenance, and continuous improvement of its information security and risk management program.

%s has a defined and documented a plan for the establishment, implementation, maintenance, and continuous improvement of its management systems(s).

DORA, ISO27001, ISO270012022, ISO27701

2024-05-07 19:18:26

DCF-185

%s has an established threat assessment process to continuously analyze threats and disseminate the information appropriately.

%s has implemented mechanisms to collect threat information and produce threat intelligence (e.g., commercial cyber threat intelligence tools, security product/vendor intelligence feeds, open source feeds, etc.) in accordance with defined threat intelligence objectives.

DORA, FEDRAMP, ISO270012022, NIST80053, NISTCSF, NISTCSF2

2024-05-07 19:18:26

DCF-186

%s has a defined process for the de-identification of data that has been classified as sensitive.

%s has implemented mechanisms for the de-identification of data that has been classified as sensitive (e.g., data masking, anonymization, pseudonymization, etc.).

ISO270012022, NIST80053

2024-05-07 19:18:26

DCF-188

%s has a process to communicate and exchange information with relevant security and privacy organizations.

%s exchanges information with relevant security and privacy organizations, professional associations, and other specialist forums, including information on newly identified threats and vulnerabilities, new technologies, etc. (e.g., through bulletin subscriptions, email alerts from security advisories, participation in conferences, etc.).

CCM, CIS8, CMMC, DORA, FEDRAMP, ISO270012022, ISO27701, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, PCI4

2024-05-07 19:18:26

DCF-190

%s has identified and assigned members to appropriate information security roles

%s has formally assigned responsibility for information security in the organization to a Chief Information Security Officer or other security-knowledgeable member of management.

CIS8, DORA, FEDRAMP, HIPAA, NIST80053, NISTCSF2

2024-12-03 22:39:18

DCF-196

%s has established a training program for the use and disclosure of protected health information (PHI) to help employees understand their obligations and responsibilities to comply with the %s's security policies and procedures, as they apply to HIPAA. All members of %s's workforce are required to complete this training upon hire and annually thereafter.

%s has established a training program for the use and disclosure of protected health information (PHI) to help personnel understand their obligations and responsibilities related to HIPAA. All eligible members of the workforce are required to complete this training during onboarding and annually thereafter.

HIPAA

2024-12-11 14:37:26

DCF-197

%s retains required documentation for 6 years from the date of the document's creation or when it was last in effect (whichever is later).

%s retains HIPAA-related policies and procedures for at least 6 years from the date of the document's creation or when it was last in effect (whichever is later).

HIPAA

2024-12-11 14:37:26

DCF-201

%s has a formal process for approving and testing all network connections and changes to the firewall and router configurations.

%s has defined, documented and implemented configuration standards for network security controls, including configurations for firewalls, routers configured with access control lists, and cloud virtual networks. All services, protocols, and ports allowed are identified, documented, approved, and have a defined business need.

CIS8, CMMC, CYBER_ESSENTIALS, CYBER_ESSENTIALS_32, DORA, NIS2, NIST800171, NIST800171R3, NIST80053, NISTCSF2, PCI, PCI4

2024-01-19 0:22:44

DCF-204

%s has a current diagram that shows all data flows across systems and networks.

A dataflow diagram is maintained to show all account data flows across systems and networks. The diagram is reviewed and approved by management at least annually and updated as necessary when there are changes to the environment.

CCM, CCPA, CIS8, CMMC, DORA, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, PCI, PCI4, SOC_2

2024-05-07 19:18:26

DCF-206

%s requires a firewall at each Internet connection and between any demilitarized zone (DMZ) and the internal network zone.

%s has implemented network security controls between trusted and untrusted networks to prevent unauthorized traffic from traversing network boundaries.

CCM, CIS8, CMMC, CYBER_ESSENTIALS, CYBER_ESSENTIALS_32, DORA, FEDRAMP, NIST800171, NIST800171R3, NIST80053, PCI, PCI4

2024-01-19 0:22:44

DCF-210

%s identifies all insecure services, protocols, and ports identified, and security features are documented and implemented for each identified service.

%s identifies all services, protocols, and ports in use considered to be in use. %s identifies, documents and implements security features for each insecure service, protocol, or port in use, such that the risk is mitigated.

CIS8, CYBER_ESSENTIALS_32, DORA, FEDRAMP, NIST80053, PCI, PCI4

2024-01-19 0:22:44

DCF-212

%s reviews firewall and router rule sets at least every six months.

%s performs a review of network security controls at least once every six months. Results of the review are documented and configurations identified as no longer being supported by a business justification are removed or updated.

CIS8, CYBER_ESSENTIALS, DORA, PCI, PCI4

2024-01-19 0:22:44

DCF-215

%s secures and synchronizes router configuration files.

Configuration files for network security controls (including files, automated and system-based controls, scripts, settings, infrastructure as code, or other parameters used to configure and synchronize network security controls) are secured from unauthorized access and kept consistent with active network configurations.

CMMC, NIST800171, NISTCSF2, PCI, PCI4

2024-01-19 0:22:44

DCF-216

%s has installed perimeter firewalls between all wireless networks and the cardholder data environment, and has configured these firewalls to deny or, if traffic is necessary for business purposes, permit only authorized traffic between the wireless environment and the cardholder data environment.

Network security controls are implemented to deny all traffic from wireless networks into the environment by default and only allow wireless traffic with authorized business purpose.

CIS8, CMMC, NIST800171, NIST800171R3, PCI, PCI4

2024-09-05 21:51:55

DCF-218

%s has implemented a DMZ to limit inbound traffic to only system components that provide authorized publicly accessible services, protocols, and ports.

Inbound traffic from untrusted networks is restricted to communications with system components that are authorized to provide publicly accessible services, protocols, and ports, and to stateful responses to communications initiated by system components in a trusted network. All other traffic is denied.

CIS8, CYBER_ESSENTIALS_32, DORA, FEDRAMP, NIS2, NIST80053, PCI, PCI4

2024-01-19 0:22:44

DCF-220

%s has implemented anti-spoofing measures to detect and block forged source IP addresses from entering the network. (For example, block traffic originating from the Internet with an internal source address.)

%s has implemented anti-spoofing measures to detect and block forged source IP addresses from entering the trusted network.

CMMC, NIST800171, NIST800171R3, PCI, PCI4

2024-01-19 0:22:44

DCF-223

%s system components that store cardholder data (such as a database) are placed in an internal network zone, segregated from the DMZ and other untrusted networks.

Network security controls are in place such that system components storing sensitive data are not directly accessible from untrusted networks.

CIS8, CMMC, DORA, NIST800171, NIST800171R3, PCI, PCI4

2024-01-19 0:22:44

DCF-225

%s restricts any disclosure of private IP addresses and routing information to external entities.

%s has implemented mechanisms to restrict disclosure of internal IP addresses and routing information to only authorized parties (for example, network address translation (NAT), proxy servers, etc.)

PCI, PCI4

2024-01-19 0:22:44

DCF-229

%s ensures that vendor-supplied defaults are always changed and unnecessary default accounts are removed or disabled before installing a system on the network. This applies to ALL default passwords, including but not limited to those used by operating systems, software that provides security services, application and system accounts, point-of-sale (POS) terminals, payment applications, Simple Network Management Protocol (SNMP) community strings, etc.).

All vendor-supplied default accounts are either disabled or removed, or their default password is changed in accordance with the company's policy and compliance requirements.

CCM, CIS8, CYBER_ESSENTIALS, CYBER_ESSENTIALS_32, ISO270012022, ISO27701, NIST800171R3, NIST80053, PCI, PCI4

2024-01-19 0:22:44

DCF-231

%s changes encryption keys from default at installation, and anytime anyone with knowledge of the keys leaves the company or changes positions.

For wireless environments connected to the environment or transmitting account data, encryption keys are changed whenever personnel with knowledge of the key leave the company or change roles and whenever a key is suspected of or known to be compromised.

CCM, DORA, NIST80053, PCI, PCI4

2024-01-19 0:22:44

DCF-233

%s changes default passwords/passphrases on access points at installation.

For wireless environments connected to the environment or transmitting sensitive data, all wireless vendor defaults are changed at installation or are confirmed to be secure, including but not limited to default wireless encryption keys, passwords on wireless access points, simple network management protocol (SNMP) defaults, and any other security-related wireless vendor defaults.

CCM, CIS8, DORA, NIST800171R3, PCI, PCI4

2024-01-19 0:22:44

DCF-239

%s has implemented only one primary function per virtual system component or device.

%s has implemented technical measures so that primary functions with lower security needs cannot affect the security of primary functions with higher security needs on the same system component (for example, assigning one primary function per system component, isolating functions that exist within the same system component, or securing all functions within the same system component to the level required by the function with the highest security need).

NIST800171R3, PCI, PCI4

2024-01-19 0:22:44

DCF-240

%s has enabled only necessary services, protocols, daemons, etc., as required for the function of the system.

%s uses only necessary services, software programs, protocols, daemons, and functions in system components, and all unnecessary functionality (e.g., scripts, drivers, features, subsystems, file systems, interfaces, unused web servers, programs, etc.) is removed or disabled in accordance with documented configuration standards.

CIS8, CMMC, CYBER_ESSENTIALS_32, FEDRAMP, NIST800171, NIST800171R3, NIST80053, NISTCSF2, PCI, PCI4

2024-09-05 21:51:55

DCF-241

All %s enabled insecure services, daemons, or protocols are justified per documented configuration standards.

%s has documented business justification and implemented additional security features for any required services, protocols, or daemons in use that are considered insecure so that the risk is mitigated.

CYBER_ESSENTIALS_32, PCI, PCI4

2024-01-19 0:22:44

DCF-244

%s has included common system security parameters settings in the system configuration standards.

Security parameters in organizational systems are configured in accordance with documented secure configuration standards.

CIS8, CMMC, FEDRAMP, NIST800171, NIST800171R3, NIST80053, NISTCSF, PCI, PCI4

2024-09-05 21:51:55

DCF-249

%s has encrypted all non-console administrative access using strong cryptography, and invokes strong encryption method before administrator's password is requested.

All non-console administrative access is encrypted using strong cryptography, including includes administrative access via browser-based interfaces and application programming interfaces (APIs).

DORA, NIST800171R3, PCI, PCI4

2024-01-19 0:22:44

DCF-253

%s has defined processes in place for securely deleting cardholder data when no longer needed for legal, regulatory, and/or business reasons.

%s disposes of data securely upon expiration of the established retention periods, when requested by customers, or when no longer needed for legal, regulatory, and/or business reasons.

CIS8, ISO270012022, ISO27701, NISTCSF2, PCI, PCI4, SOC_2

2024-05-07 19:18:26

DCF-255

%s has a quarterly process in place for identifying and securely deleting stored cardholder data that exceeds defined retention requirements.

%s verifies at least once every three months that stored account data exceeding the defined retention period has been securely deleted or rendered unrecoverable. Evidence of the verification is documented and retained.

PCI, PCI4

2024-01-19 0:22:44

DCF-257

%s has a documented business justification for the storage of sensitive authentication data.

%s maintains documentation of the legitimate business justification to store sensitive authentication data (if sensitive authentication data is stored after the authorization process).

NIST800171R3, PCI, PCI4

2025-01-28 20:01:13

DCF-258

%s ensures sensitive authentication data is secured.

%s encrypts sensitive authentication data (SAD) that is stored electronically prior to completion of authorization using strong cryptography.

NIST800171R3, PCI, PCI4

2024-01-19 0:22:44

DCF-259

%s ensures sensitive authentication data is deleted or rendered unrecoverable upon completion of the authorization process.

If sensitive authentication data (SAD) is received, %s deletes and renders the data unrecoverable upon completion of the authorization process.

NIST800171R3, PCI, PCI4

2024-01-19 0:22:44

DCF-260

%s does not store the full contents of any track (from the magnetic stripe located on the back of a card, equivalent data contained on a chip, or elsewhere) after authorization. This data is alternatively called full track, track, track 1, track 2, and magnetic-stripe data.

The full contents of any track are not stored upon completion of the authorization process.

PCI, PCI4

2025-01-28 20:01:13

DCF-261

%s does not store the card verification code or value (three-digit or four-digit number printed on the front or back of a payment card used to verify card-not- present transactions) after authorization.

The card verification code is not stored upon completion of the authorization process.

PCI, PCI4

2025-01-28 20:01:13

DCF-262

%s does not store the personal identification number (PIN) or the encrypted PIN block after authorization.

The personal identification number (PIN) and the PIN block are not stored upon completion of the authorization process.

PCI, PCI4

2025-01-28 20:01:13

DCF-263

%s masks PAN when displayed (the first six and last four digits are the maximum number of digits to be displayed), such that only personnel with a legitimate business need can see more than the first six/last four digits of the PAN.

%s has implemented technical measures to mask primary account numbers (PANs) when displayed (on screen, paper receipts, etc.) such that only personnel with a legitimate business need can see more than the bank identification number (BIN) and last four digits of the PAN.

PCI, PCI4

2024-01-19 0:22:44

DCF-264

%s has rendered PAN unreadable anywhere it is stored (including on portable digital media, backup media, and in logs) by using any of the following approaches: * One-way hashes based on strong cryptography, (hash must be of the entire PAN) * Truncation (hashing cannot be used to replace the truncated segment of PAN) * Index tokens and pads (pads must be securely stored) * Strong cryptography with associated key-management processes and procedures.

Primary account numbers (PANs) are rendered unreadable anywhere they are stored, including primary storage (databases, or flat files such as text files spreadsheets) as well as non-primary storage (backup, audit logs, exception, or troubleshooting logs).

PCI, PCI4

2024-01-19 0:22:44

DCF-265

%s ensures that logical access to encrypted file systems is managed separately and independently of native operating system authentication and access control mechanisms (for example, by not using local user account databases or general network login credentials).

Disk encryption implementations are configured to require independent authentication and logical access controls for decryption to protect data in the event of physical loss of a disk.

DORA, FEDRAMP, NIS2, NIST800171R3, PCI, PCI4

2024-01-19 0:22:44

DCF-267

%s ensures that cardholder data on removable media is encrypted wherever stored.

Sensitive data on removable storage media is encrypted wherever stored.

CIS8, PCI, PCI4

2024-01-19 0:22:44

DCF-268

%s maintains a documented description of the cryptographic architecture, which includes: Details of all algorithms, protocols, and keys used for the protection of cardholder data, including key strength and expiry date; description of the key usage for each key; Inventory of any HSMs and other SCDs used for key management.

%s maintains a documented description of the cryptographic architecture in place, including details of all algorithms, protocols, and keys used for the protection of stored account data, including key strength and expiry date, preventing the use of the same cryptographic keys in production and test environments, description of the key usage for each key, and inventory of any hardware security modules (HSMs), key management systems (KMS), and other secure cryptographic devices (SCDs) used for key management, including type and location of devices.

PCI, PCI4

2024-01-19 0:22:44

DCF-269

%s restricts access to cryptographic keys to the fewest number of custodians necessary.

%s restricts access to cleartext cryptographic key components to the fewest number of custodians necessary to reduce the risk of stored data being retrieved or rendered visible by unauthorized parties.

PCI, PCI4

2024-01-19 0:22:44

DCF-270

%s ensures that secret and private cryptographic keys are used to encrypt/decrypt cardholder data stored in one or more of the following: Encrypted with a key-encrypting key that is at least as strong as the data-encrypting key, and that is stored separately from the data-encrypting key; within a secure cryptographic device (such as a hardware (host) security module (HSM) or PTS-approved point-of-interaction device); as at least two full-length key components or key shares, in accordance with an industry-accepted method.

Key-encrypting keys used are at least as strong as the data-encrypting keys they protect and are stored separately from data-encrypting keys.

DORA, PCI, PCI4

2024-01-19 0:22:44

DCF-271

%s stores cryptographic keys in the fewest possible locations.

%s stores cryptographic keys in the fewest possible locations to minimize the potential for keys to be exposed to unauthorized parties.

DORA, ISO270012022, ISO27701, PCI, PCI4

2024-01-19 0:22:44

DCF-272

%s ensures that if keys are shared with customers for transmission or storage of cardholder data, provide documentation to customers that includes guidance on how to securely transmit, store and update customer’s keys, in accordance with requirements 3.6.1 through 3.6.8.

Where %s shares cryptographic keys with its customers for transmission or storage of account data, the company documents and distributes guidance on secure transmission, storage and updating of such keys to those customers.

CCM, DORA, PCI, PCI4

2024-01-19 0:22:44

DCF-273

%s's cryptographic key procedures include generation of strong cryptographic keys

Key-management policies and procedures are documented and implemented including: generation of strong cryptographic keys, secure distribution, and secure storage of cryptographic keys used to protect sensitive data.

CCM, CMMC, DORA, ISO270012022, ISO27701, NIST800171, NIST800171R3, PCI, PCI4, SOC_2

2024-01-19 0:22:44

DCF-276

%s's cryptographic key procedures include cryptographic key changes for keys that have reached the end of their defined cryptoperiod, as defined by the associated application vendor or key owner, and based on industry best practices and guidelines.

A defined cryptoperiod for each key type in use as defined by the associated application vendor or key owner is documented. %s changes encryption keys when they reach the end of their cryptoperiod in accordance with documented policies and procedures.

CCM, DORA, NIS2, PCI, PCI4

2024-01-19 0:22:44

DCF-278

%s's cryptographic key procedures include replacement of known or suspected compromised keys.

%s retires, replaces or destructs cryptographic keys that are no longer used or needed or when the key expires, the integrity of the key has been weakened, or the key is known or suspected to be compromised, in accordance with documented company policies and procedures. Retired or replaced keys are not used for encryption operations.

CCM, CMMC, DORA, NIS2, NIST800171, NIST800171R3, PCI, PCI4, SOC_2

2024-01-19 0:22:44

DCF-280

%s ensures that if manual clear-text cryptographic key-management operations are used, these operations must be managed using split knowledge and dual control.

Split knowledge and dual control are used to manage operations where manual cleartext cryptographic key management is performed in accordance with documented company policies and procedures.

DORA, PCI, PCI4

2024-01-19 0:22:44

DCF-281

%s's cryptographic key procedures include prevention of unauthorized substitution of cryptographic keys.

Key management policies and procedures are documented and implemented to include the prevention of unauthorized substitution of cryptographic keys.

DORA, PCI, PCI4

2024-01-19 0:22:44

DCF-282

%s requires cryptographic key custodians to formally acknowledge that they understand and accept their key- custodian responsibilities.

%s requires cryptographic key custodians to formally acknowledge that they understand and accept their key-custodian responsibilities in accordance with documented company policies and procedures.

DORA, PCI, PCI4

2024-01-19 0:22:44

DCF-284

%s accepts only trusted keys and/or certificates during transmission of cardholder data.

%s has implemented security mechanisms so that only trusted keys and/or certificates are accepted during transmission of sensitive data that are confirmed valid and not expired or revoked.

CMMC, DORA, FEDRAMP, ISO270012022, NIST800171, NIST800171R3, NIST80053, PCI, PCI4

2024-09-05 21:51:55

DCF-285

%s has implemented security protocols to use only secure configurations, and to not support insecure versions or configurations, during transmission of cardholder data.

Security protocols in use for transmission of sensitive data support only secure versions or configurations and do not support fallback to, or use of insecure versions, algorithms, key sizes, or implementations.

CIS8, CMMC, DORA, NIST800171, NIST800171R3, NISTCSF2, PCI, PCI4

2024-12-11 14:45:49

DCF-286

%s has implemented a proper encryption strength for the encryption methodology in use, during transmission of cardholder data.

%s has implemented a proper encryption strength for the encryption methodology in use, during transmission of sensitive information (e.g., PII, PHI, Cardholder Data, etc.).

CCM, NIS2, PCI

2025-10-06 23:16:27

DCF-287

%s enables TLS whenever cardholder data is transmitted or received.

%s enables TLS whenever sensitive information (e.g., PII, PHI, Cardholder Data, etc.) is transmitted or received.

CCM, CIS8, DORA, NIS2, PCI

2025-10-06 23:16:27

DCF-288

%s ensures that wireless networks transmitting cardholder data or connected to the cardholder data environment, use industry best practices to implement strong encryption for authentication and transmission.

Wireless networks transmitting sensitive data or connected to the environment use strong protocols for authentication and encryption of data transmissions.

CCM, CIS8, CMMC, DORA, NIS2, NIST800171, NIST800171R3, PCI, PCI4

2024-09-05 21:51:55

DCF-289

%s ensures that PANs are rendered unreadable or secured with strong cryptography whenever they are sent via end-user messaging technologies.

%s encrypts sensitive data with strong cryptography when transmitted via e-mail, instant messaging, SMS, chat or other end-user messaging technologies.

CIS8, DORA, ISO27701, NIS2, PCI, PCI4

2024-01-19 0:22:44

DCF-291

%s ensures that anti-virus programs are capable of detecting, removing, and protecting against all known types of malicious software.

An anti-malware solution is deployed on all system components, except for those system components identified through periodic risk assessments that concludes the system components are not at risk from malware.

CCM, CCPA, CIS8, CMMC, CYBER_ESSENTIALS, CYBER_ESSENTIALS_32, FEDRAMP, ISO27701, NIST800171, NIST800171R3, NIST80053, NISTCSF, PCI, PCI4

2024-09-05 21:51:55

DCF-292

%s performs periodic evaluations to identify and evaluate evolving malware threats in order to confirm whether those systems considered to not be commonly affected by malicious software continue as such.

%s maintains a documented list of all system components evaluated as not at risk for malware that are not subjected to anti-malware controls. %s performs periodic evaluations to identify and assess evolving malware threats for those system components and to confirm whether such system components continue to not require anti-malware protection. Results of the periodic evaluation are documented.

CCPA, CYBER_ESSENTIALS, CYBER_ESSENTIALS_32, FEDRAMP, NIST80053, NISTCSF, PCI, PCI4

2024-01-19 0:22:44

DCF-293

%s ensures that all anti-virus software and definitions are kept current.

The deployed anti-malware solution is kept current via automatic updates and configured to detect all known types of malware and to remove, block, or contain all known types of malware.

CCPA, CIS8, CMMC, CYBER_ESSENTIALS, CYBER_ESSENTIALS_32, DORA, ISO270012022, NIST800171, NIST800171R3, PCI, PCI4, SOC_2

2024-09-05 21:51:55

DCF-294

%s ensures that automatic updates and periodic scans are enabled and being performed.

The implemented anti-malware solutions are configured to perform periodic scans and active/real-time scans (e.g., scanning files from external sources as they are downloaded, opened, or executed) or to perform continuous behavioral analysis of systems or processes.

CCM, CIS8, CMMC, CYBER_ESSENTIALS, CYBER_ESSENTIALS_32, ISO270012022, NIST800171, NIST800171R3, NISTCSF, NISTCSF2, PCI, PCI4, SOC_2

2024-09-05 21:51:55

DCF-296

%s ensures that anti-virus mechanisms are actively running and cannot be disabled or altered by users, unless specifically authorized by management on a case-by-case basis for a limited time period.

%s restricts access to disable or alter anti-malware mechanisms to authorized personnel based on documented approval by management on a case-by-case basis for a limited time period.

CYBER_ESSENTIALS, PCI, PCI4

2024-01-19 0:22:44

DCF-297

%s installs critical security patches within one month of release.

%s has implemented a formal patch management process where critical patches/updates (as identified per the entity's vulnerability risk analysis) are installed within one month of release. All other applicable security patches/updates are installed within the timeframe established by the entity per the risk analysis and company policies and procedures.

CCM, CIS8, CMMC, CYBER_ESSENTIALS_32, DORA, FEDRAMP, NIST800171, NIST800171R3, NIST80053, NISTCSF, PCI, PCI4

2024-09-05 21:51:55

DCF-304

%s ensures the removal of test data and accounts from system components before the system becomes active / goes into production.

Test data and test accounts are removed from system components before the system goes into production.

FEDRAMP, NIS2, NIST80053, PCI, PCI4

2024-01-19 0:22:44

DCF-305

Changes to all system components in the production environment (including software, code, infrastructure, network, configuration changes, etc.) are made according to established procedures that include documentation (change description, justification, evaluation of security impact, approval by authorized parties, rollback procedures) and testing (including security impact testing and code vulnerability testing for custom development changes).

Changes to all system components in the production environment (including software, code, infrastructure, network, configuration changes, etc.) are made according to established procedures that include documentation (change description, justification, evaluation of security requirements and impact, approval by authorized parties, rollback procedures, etc.) and testing (including acceptance and security impact testing).

CMMC, FEDRAMP20X, ISO270012022, ISO27701, NIST800171, NIST800171R3, NISTAI, NISTCSF2, PCI, PCI4, SOC_2

2024-09-05 21:51:55

DCF-310

%s ensures that upon completion of a significant change, all relevant PCI DSS requirements must be implemented on all new or changed systems and networks, and documentation updated as applicable.

%s verifies all system components after a change to validate they are compliant with the applicable PCI DSS requirements. Record of the validation is documented and retained, and updates to PCI DSS requirements documentation are made as applicable based on the nature of the change.

PCI, PCI4

2024-01-19 0:22:44

DCF-312

%s trains developers at least annually in up- to-date secure coding techniques, including how to avoid common coding vulnerabilities.

Developers are required to complete secure code development training at least once every 12 months, including training on software security relevant to their job function and development languages, secure software design and secure coding techniques, and how to use tools for detecting vulnerabilities in software if these are used in the organization.

CCM, CIS8, CMMC, FEDRAMP, ISO270012022, NIS2, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, PCI, PCI4, SOC_2

2024-05-07 19:18:26

DCF-324

%s ensures that for public-facing web applications, new threats and vulnerabilities are addressed on an ongoing basis and ensure these applications are protected against known attacks by either of the following methods: Reviewing public-facing web applications via manual or automated application vulnerability security assessment tools or methods, at least annually and after any changes; installing an automated technical solution that detects and prevents web- based attacks in front of public- facing web applications, to continually check all traffic.

%s evaluates public-facing web applications via manual or automated application vulnerability security assessment tools at least once every 12 months and after significant changes. Vulnerabilities identified, if any, are risk-ranked and corrected, and the application is re-evaluated after the corrections.

CIS8, CYBER_ESSENTIALS, NIST80053, PCI, PCI4

2024-01-19 0:22:44

DCF-326

%s limits access to system components and sensitive data to only those individuals whose job requires such access

%s restricts access to system components and data to only those individuals whose job requires such access.

CCM, CIS8, CMMC, CYBER_ESSENTIALS_32, DORA, FEDRAMP, ISO270012022, ISO27701, NIS2, NIST800171, NIST800171R3, NIST80053, NISTCSF2, PCI, PCI4, SOC_2

2024-07-11 20:02:42

DCF-329

%s's access control system(s) covers all system components.

For all system components, access is managed via an access control system. The access control system(s) is configured to enforce permissions assigned to individuals, applications, and systems based on job classification and function and is set to “deny all” by default.

CCPA, CIS8, CYBER_ESSENTIALS_32, DORA, FEDRAMP20X, NIS2, NIST800171R3, NIST80053, PCI, PCI4

2024-09-17 22:20:24

DCF-330

%s's access control system(s) is configured to enforce assignment of privileges to individuals based on job classification and function.

%s has defined and implemented an access control model for all system components (e.g., role-based access control (RBAC), attribute-based access control (ABAC), policy-based access control (PBAC), etc.).

CCM, CCPA, CIS8, CMMC, DORA, FEDRAMP, FEDRAMP20X, ISO27701, NIS2, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, PCI

2024-07-11 20:02:42

DCF-335

%s removes/disables inactive user accounts within 90 days.

%s removes or disables inactive accounts within a specified period of inactivity.

CIS8, CMMC, CYBER_ESSENTIALS_32, FEDRAMP, NIST800171, NIST800171R3, NIST80053, PCI, PCI4

2025-04-23 21:45:31

DCF-336

%s ensures that accounts used by third parties to access, support, or maintain system components via remote access are enabled only during the time period needed, and disabled when not in use.

Accounts used by third parties to access, support, or maintain system components via remote access are enabled during the time period needed based on documented authorization by management and disabled when not in use. Third-party remote access is monitored by company personnel for unexpected activity.

DORA, FEDRAMP, NIST800171R3, NIST80053, NISTCSF, PCI, PCI4

2024-01-19 0:22:44

DCF-339

%s ensures that non-consumer customer passwords are temporarily locked-out after not more than six invalid access attempts.

Invalid authentication attempts are limited by locking out the user ID after not more than 10 failed attempts.

CIS8, CMMC, CYBER_ESSENTIALS_32, NIST800171, NIST800171R3, PCI, PCI4, SOC_2

2024-09-05 21:51:55

DCF-340

%s has set the lockout duration to a minimum of 30 minutes or until an administrator enables the user ID.

%s has configured account lockout duration following a set number of invalid authentication attempts to a minimum of 30 minutes or until the identity of the user is confirmed (for example, by a system administrator).

CIS8, CMMC, CYBER_ESSENTIALS_32, NIST800171, NIST800171R3, NIST80053, PCI, PCI4, SOC_2

2024-01-19 0:22:44

DCF-343

%s uses strong cryptography to render all authentication credentials (such as passwords/phrases) unreadable during transmission and storage on all system components.

Strong cryptographic protocols are used to render all authentication credentials (e.g.,passwords, passphrases, etc.) unreadable during transmission and storage on all system components.

CCM, CMMC, NIS2, NIST800171, NIST800171R3, PCI, PCI4

2024-01-19 0:22:44

DCF-345

%s verifies user identity before modifying any authentication credential—for example, performing password resets, provisioning new tokens, or generating new keys.

User identity is verified before allowing changes to any authentication factor (for example, performing password resets, provisioning new tokens, or generating new keys). Verification is done through secret question/answers, knowledge-based information, or other mechanisms.

CCPA, NIST800171R3, PCI, PCI4

2024-01-19 0:22:44

DCF-346

%s ensures that passwords/passphrases must: Require a minimum length of at least seven characters; and contain both numeric and alphabetic characters. Alternatively, the passwords/ passphrases must have complexity and strength at least equivalent to the parameters specified above.

Minimum password requirements are enforced on system components including a minimum length of 12 characters (or if the system does not support 12 characters, a minimum length of eight characters) and complexity requirements to include both numbers and letters.

CCM, CIS8, CYBER_ESSENTIALS, CYBER_ESSENTIALS_32, PCI, PCI4

2025-01-28 20:01:13

DCF-348

%s changes user passwords/passphrases at least once every 90 days.

For in-scope components that are not in the cardholder data environment (CDE) where passwords/passphrases are used as the only authentication factor, credentials are required to be changed at least once every 90 days. Alternatively, technical measures are implemented to dynamically analyze the security posture of accounts, and real-time access to resources is automatically determined accordingly.

PCI, PCI4

2024-01-19 0:22:44

DCF-349

%s requires non-consumer customer passwords to be changed periodically, and non-consumer customers are given guidance as to when, and under what circumstances, passwords must change.

Where customer user access to cardholder data is achieved only through passwords/passphrases (i.e., single factor authentication), %s provides guidance to customer users as to how frequently, and under what circumstances, they should change their passwords.

PCI, PCI4

2024-01-19 0:22:44

DCF-350

%s does not allow an individual to submit a new password/passphrase that is the same as any of the last four passwords/passphrases he or she has used.

System configuration settings are in place to prevent password reuse in accordance with company policy and compliance requirements.

CMMC, CYBER_ESSENTIALS_32, ISO270012022, ISO27701, NIST800171, NIST800171R3, PCI, PCI4, SOC_2

2024-09-05 21:51:55

DCF-352

%s sets passwords/passphrases for first-time use and upon reset to a unique value for each user, and changes them immediately after the first use.

Passwords are set to a unique value for first-time use and upon reset. Temporary initial passwords are forced to be changed immediately after the first use.

CIS8, CMMC, CYBER_ESSENTIALS, CYBER_ESSENTIALS_32, FEDRAMP, ISO270012022, ISO27701, NIST800171, NIST800171R3, PCI, PCI4

2024-01-19 0:22:44

DCF-354

%s has incorporated multi-factor authentication for all non-console access into the CDE for personnel with administrative access.

Multi-factor authentication (MFA) is required for all non-console access into the environment for personnel with administrative access.

CIS8, CYBER_ESSENTIALS_32, NIS2, PCI, PCI4

2024-01-19 0:22:44

DCF-355

%s has incorporated multi-factor authentication for all remote network access (both user and administrator, and including third-party access for support or maintenance) originating from outside the entity’s network.

All remote access to the entity’s network and systems (including that of users, administrators, and external access from third parties or vendors including access for maintenance sessions) requires multi-factor authentication.

CCPA, CIS8, CMMC, CYBER_ESSENTIALS_32, DORA, DRATA_ESSENTIALS, FEDRAMP, FEDRAMP20X, NIS2, NIST800171, NIST800171R3, NIST80053, NISTCSF, PCI, PCI4, SOC_2

2024-09-05 21:51:55

DCF-356

%s's authentication policies and procedures include: Guidance on selecting strong authentication credentials; guidance for how users should protect their authentication credentials; instructions not to reuse previously used passwords; instructions to change passwords if there is any suspicion the password could be compromised.

%s has documented policies and procedures for authentication that are communicated to all personnel. These documents include guidance on selecting strong authentication factors, guidance on protecting authentication credentials, instructions not to reuse previously used credentials, instructions to change authentication credentials in the event of known or suspected compromise along with guidance on how to report the incident, etc.

CIS8, CYBER_ESSENTIALS_32, FEDRAMP, ISO270012022, ISO27701, NIST80053, PCI, PCI4, SOC_2

2024-05-07 19:18:26

DCF-358

%s ensures that service providers with remote access to customer premises must use a unique authentication credential for each customer.

%s's authentication factors and credentials used to access customer environments remotely are unique for each customer.

CYBER_ESSENTIALS_32, DORA, PCI, PCI4

2024-01-19 0:22:44

DCF-360

%s restricts user database access, query, or action to programmatic methods.

Direct query access to cardholder data repositories is restricted via applications or other programmatic methods (e.g., stored procedures) with access and allowed actions based on user roles and least privileges, unless performed by an authorized administrator.

PCI, PCI4

2024-01-19 0:22:44

DCF-363

%s uses appropriate facility entry controls to limit and monitor physical access to systems in the cardholder data environment.

Entry controls (e.g., badge access systems, biometrics readers, monitored reception areas or front desks, etc.) are in place to restrict physical access to corporate facilities, including systems or areas that may process or store sensitive data, to authorized personnel, and to log and monitor such access.

CCM, CMMC, DORA, FEDRAMP, ISO270012022, ISO27701, NIS2, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, PCI, PCI4, SOC_2

2024-09-05 21:51:55

DCF-364

%s uses either video cameras or access control mechanisms (or both) to monitor individual physical access to points of entry, exits, and sensitive areas. Review collected data and correlate with other entries. Store for at least three months, unless otherwise restricted by law.

%s has developed and approved a list of individuals with authorized physical access to the facilities, equipment, and operating environments, which is maintained up-to-date and reviewed periodically to validate the ongoing appropriateness of access. Authorized individuals are issued physical authentication credentials (e.g., identification badges, identification cards, smart cards, etc.).

CCM, CMMC, DORA, FEDRAMP, NIS2, NIST800171, NIST800171R3, NIST80053, NISTCSF, PCI

2024-09-05 21:51:55

DCF-365

%s ensures that video cameras or access control mechanisms (or both) are protected from tampering or disabling.

%s physical surveillance mechanisms (e.g., video monitoring systems, sensors and detectors) are in place to deter and detect unauthorized physical access and are protected from tampering or disabling.

CCM, CMMC, DORA, FEDRAMP, ISO270012022, ISO27701, NIS2, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, PCI, PCI4, SOC_2

2024-01-19 0:22:44

DCF-366

%s ensures that data collected from video cameras and/or access control mechanisms are reviewed and correlated with other entries.

Data collected from video cameras and/or access control mechanisms are reviewed and correlated with other entries (e.g., access logs) on a periodic basis and as needed (e.g., upon suspicious physical security activity).

CCM, DORA, FEDRAMP, NIS2, NIST800171R3, NIST80053, NISTCSF2, PCI, PCI4

2024-09-11 1:28:13

DCF-367

%s ensures that data collected from video cameras and/or access control mechanisms is stored for at least three months unless otherwise restricted by law.

Data collected from video cameras and/or access control mechanisms is stored for at least three months unless otherwise restricted by law.

CCM, DORA, FEDRAMP, NIST80053, PCI, PCI4

2024-01-19 0:22:44

DCF-368

%s has implemented physical and/or logical controls to restrict access to publicly accessible network jacks. Alternatively, processes could be implemented to ensure that visitors are escorted at all times in areas with active network jacks.

%s has implemented physical and/or logical controls to restrict access to publicly accessible network jacks.

CCM, DORA, FEDRAMP, NIST80053, PCI, PCI4

2024-01-19 0:22:44

DCF-369

%s restricts physical access to wireless access points, gateways, handheld devices, networking/communications hardware, and telecommunication lines.

%s restricts physical access to wireless access points, gateways, networking/communications hardware, and telecommunication lines within the company facilities.

CCM, CMMC, DORA, ISO270012022, ISO27701, NIST800171, NIST800171R3, PCI, PCI4

2024-01-19 0:22:44

DCF-372

%s limits access to the badge system to authorized personnel.

%s restricts access to the identification or badge system to authorized personnel based on need-to-know principles.

DORA, NIS2, PCI, PCI4, SOC_2

2024-01-19 0:22:44

DCF-374

%s ensures that visitors are authorized before entering, and escorted at all times within, areas where cardholder data is processed or maintained.

Visitors are authorized before entering, and escorted at all times within company facilities including areas where sensitive data may be processed or stored.

CCM, CMMC, DORA, ISO270012022, ISO27701, NIST800171, NIST800171R3, NISTCSF2, PCI, PCI4, SOC_2

2024-09-05 21:51:55

DCF-375

%s ensures that visitors are identified and given a badge or other identification that visibly distinguishes the visitors from onsite personnel.

%s personnel are required to wear a badge or other form of identification within company facilities. %s provides visitors with a badge or other form of identification that visibly distinguishes visitors from onsite personnel.

CCM, CMMC, DORA, ISO270012022, ISO27701, NIST800171, NIST800171R3, NISTCSF2, PCI, PCI4, SOC_2

2024-01-19 0:22:44

DCF-377

%s ensures that visitors surrender the badge or identification before leaving the facility or at the date of expiration.

Visitor badges or identification are surrendered or deactivated before visitors leave the facility or at the date of expiration.

CCM, PCI, PCI4, SOC_2

2024-01-19 0:22:44

DCF-378

%s has a visitor log to maintain a physical audit trail of visitor activity to the facility as well as computer rooms and data centers where cardholder data is stored or transmitted.

%s maintains visitor logs to keep an audit trail of visitor activity to the company facilities, computer rooms, or data centers where sensitive data may be stored or transmitted.

CCM, CMMC, DORA, FEDRAMP, ISO270012022, ISO27701, NIST800171, NIST80053, NISTCSF2, PCI, PCI4, SOC_2

2024-09-05 21:51:55

DCF-379

%s's visitor log includes the visitor’s name, the firm represented, and the onsite personnel authorizing physical access on the log.

%s' visitor logs include, at a minimum, the visitor’s name and the organization represented, the date and time of the visit, and the name of the personnel authorizing physical access.

CCM, FEDRAMP, NIST80053, PCI, PCI4

2025-01-28 20:01:13

DCF-381

%s physically secures all media.

Media with sensitive data is physically secured to prevent unauthorized persons from gaining access to it.

CCM, CMMC, DORA, FEDRAMP, ISO270012022, ISO27701, NIST800171, NIST800171R3, NIST80053, NISTCSF, PCI, PCI4, SOC_2

2024-09-05 21:51:55

DCF-382

%s stores media backups in a secure location, preferably an off-site facility, such as an alternate or backup site, or a commercial storage facility. Review the location’s security at least annually.

%s stores offline media backups in a secure location (e.g., off-site facility, commercial storage facility, etc.) with security measures to protect the confidentiality of the information. The security of the location is reviewed at least once every 12 month through inspection of the facilities. Results of the review are documented.

CMMC, DORA, FEDRAMP, NIST800171, NIST800171R3, NIST80053, PCI, PCI4

2024-09-05 21:51:55

DCF-384

%s classifies media so the sensitivity of the data can be determined.

All media with sensitive data is classified in accordance with the nature of the data and the company's data classification policy.

CCM, DORA, FEDRAMP, ISO270012022, ISO27701, NIST80053, PCI, PCI4

2024-01-19 0:22:44

DCF-385

%s sends the media by secured courier or other delivery method that can be accurately tracked.

Media with sensitive data transported within or outside the company's facilities is logged, securely transported (e.g., via secure courier or other trackable method), and captured within tracking logs to include details about media location, responsible party, etc.

CMMC, DORA, FEDRAMP, ISO270012022, ISO270182019, ISO27701, NIST800171, NIST800171R3, NIST80053, PCI, PCI4

2024-07-11 20:02:42

DCF-386

%s management approves any and all media that is moved from a secured area (including when media is distributed to individuals).

Management approves all assets (including media with sensitive data) that are moved within or outside the facility, including when the assets are distributed to individuals. Documentation of management's approval for the movement of assets is retained.

CMMC, DORA, ISO270012022, ISO270182019, ISO27701, NIST800171, NIST800171R3, PCI, PCI4

2024-07-11 20:02:42

DCF-388

%s properly maintains inventory logs of all media.

%s maintains documented inventory all electronic media with sensitive data. A verification of the inventory is conducted at least once every 12 months in accordance with company procedures.

CMMC, ISO270012022, ISO27701, NIST800171, NIST800171R3, NIST80053, PCI, PCI4

2024-01-19 0:22:44

DCF-390

%s destroys media when it is no longer needed for business or legal reasons.

Electronic media is destroyed or sensitive data is rendered unrecoverable so that it cannot be reconstructed when no longer needed for business or legal reasons.

CCM, CIS8, FEDRAMP, ISO270012022, ISO27701, NIST80053, NISTCSF, PCI, PCI4

2024-01-19 0:22:44

DCF-391

%s has policies and procedures for the periodic destruction of media.

%s has policies and procedures for the destruction of electronic media when no longer needed for business or legal reasons.

CCM, FEDRAMP, NIST80053, NISTCSF, PCI, PCI4

2024-01-19 0:22:44

DCF-397

%s ensures that policies and procedures require that devices are periodically inspected to look for tampering or substitution.

%s performs periodic inspections of point of interaction (POI) device surfaces to detect tampering and unauthorized substitution in accordance with documented company policies and procedures.

PCI, PCI4

2024-01-19 0:22:44

DCF-404

%s's training materials for personnel at point-of-sale locations include the following: Verify the identity of any third-party persons claiming to be repair or maintenance personnel, prior to granting them access to modify or troubleshoot devices; do not install, replace, or return devices without verification; be aware of suspicious behavior around devices; report suspicious behavior and indications of device tampering or substitution to appropriate personnel.

%s provides periodic training for personnel in point-of-interaction (POI) environments to be aware of attempted tampering or replacement of POI devices including: verifying the identity of any third-party persons claiming to be repair or maintenance personnel prior to granting them access to modify or troubleshoot devices; procedures to ensure devices are not installed, replaced, or returned without verification; being aware of suspicious behavior around devices, and reporting suspicious behavior and indications of device tampering or substitution to appropriate personnel.

PCI, PCI4

2024-01-19 0:22:44

DCF-406

%s's audit trails are enabled and active for system components.

Audit logs are enabled and active for all system components and sensitive data in accordance with company policies.

CIS8, CMMC, DORA, FEDRAMP, ISO270012022, NIST800171, NIST800171R3, NIST80053, NISTCSF2, PCI, PCI4, SOC_2

2025-10-06 23:16:27

DCF-407

%s has implemented audit trails to link all access to system components to each individual user.

%s has configured audit logs to contain user or identity, type of event, date and time, success and failure indication, origination of event, affected data, and system component, resource, or service.

CIS8, CMMC, ISO270012022, ISO27701, ISO420012023, NIST800171, NIST800171R3, NIST80053, NISTCSF2, PCI, PCI4, SOC_2

2025-10-06 23:16:27

DCF-408

%s ensures that automated audit trails are implemented for all system components to reconstruct all individual user accesses to cardholder data.

Automated audit trails or logs are implemented for all system components to capture all access to cardholder data.

CIS8, PCI, PCI4

2024-01-19 0:22:44

DCF-409

%s ensures that automated audit trails are implemented for all system components to reconstruct all actions taken by any individual with root or administrative privileges.

Automated audit trails or logs are implemented for all system components to capture all actions taken by any identities with administrative access, including execution of privileged functions and any interactive use of application or system accounts.

CCM, CIS8, CMMC, CYBER_ESSENTIALS_32, DORA, FEDRAMP, ISO270012022, ISO27701, NIST800171, NIST800171R3, NIST80053, PCI, PCI4, SOC_2

2024-09-05 21:51:55

DCF-410

%s ensures that automated audit trails are implemented for all system components to reconstruct access to all audit trails.

Automated audit trails or logs are implemented for all system components to capture all access to audit logs.

CIS8, CMMC, DORA, FEDRAMP, ISO27701, NIST800171, NIST80053, PCI, PCI4

2024-07-11 20:02:42

DCF-411

%s ensures that automated audit trails are implemented for all system components to reconstruct invalid logical access attempts.

Automated audit trails or logs are implemented for all system components to capture all invalid access attempts.

CIS8, DORA, FEDRAMP, ISO270012022, NIST800171R3, NIST80053, NISTCSF2, PCI, PCI4, SOC_2

2024-01-19 0:22:44

DCF-412

%s ensures that automated audit trails are implemented for all system components to reconstruct use of and changes to identification and authentication mechanisms⎯including but not limited to creation of new accounts and elevation of privileges⎯and all changes, additions, or deletions to accounts with root or administrative privileges.

Automated audit trails or logs are implemented to capture all changes to identification and authentication credentials (e.g., creation of new accounts, elevation of privileges, changes, additions, or deletions to accounts with administrative access, etc.).

CCM, CIS8, DORA, FEDRAMP, ISO270012022, NIST80053, NISTCSF2, PCI, PCI4, SOC_2

2024-01-19 0:22:44

DCF-413

%s ensures that automated audit trails are implemented for all system components to reconstruct initialization, stopping, or pausing of the audit logs.

Automated audit trails or logs are implemented for all system components to capture initialization of new audit logs and all starting, stopping, or pausing of the existing audit logs.

CIS8, CMMC, DORA, FEDRAMP, NIST800171, NIST800171R3, NIST80053, PCI, PCI4

2024-01-19 0:22:44

DCF-414

%s ensures that automated audit trails are implemented for all system components to reconstruct creation and deletion of system-level objects.

Automated audit trails or logs are implemented for all system components to capture all creation and deletion of system-level objects.

CIS8, DORA, ISO270012022, PCI, PCI4, SOC_2

2024-05-07 19:18:26

DCF-421

%s synchronizes all critical system clocks and times using time-synchronization technology, and ensures that the following is implemented for acquiring, distributing, and storing time.

%s synchronizes all critical system clocks and times using time-synchronization technology such as Network Time Protocol (NTP).

CCM, CIS8, CMMC, FEDRAMP, ISO270012022, ISO270172015, ISO27701, NIST800171, NIST800171R3, NIST80053, PCI, PCI4

2024-01-19 0:22:44

DCF-422

%s only designated central time server(s) receive time signals from external sources, and time signals from external sources are based on International Atomic Time or UTC.

Systems are configured so that one or more designated central time servers are in use and receiving time from industry-accepted external sources based on International Atomic Time or Coordinated Universal Time (UTC).

CIS8, CMMC, ISO270012022, ISO27701, NIST800171, NIST800171R3, PCI, PCI4

2024-01-19 0:22:44

DCF-423

%s ensures that where there is more than one designated time server, the time servers peer with each other to keep accurate time.

Where there is more than one designated time server, the time servers peer with one another to keep accurate time.

CIS8, ISO270012022, ISO27701, PCI, PCI4

2024-01-19 0:22:44

DCF-424

%s's systems receive time only from designated central time server(s).

Internal systems receive time information only from designated central time server or servers.

ISO270012022, ISO27701, NIST800171R3, PCI, PCI4

2024-01-19 0:22:44

DCF-425

%s restricts access to time data to only personnel with a business need.

Access to modify time synchronization configurations or system time is restricted to authorized system administrators or personnel with a business need.

FEDRAMP, NIST80053, PCI, PCI4

2024-01-19 0:22:44

DCF-426

%s ensures that changes to time settings on critical systems are logged, monitored, and reviewed.

Any changes to time synchronization configurations or system time on critical systems are logged, monitored, and reviewed in accordance with company policies and procedures.

PCI, PCI4

2024-01-19 0:22:44

DCF-429

%s limits viewing of audit trails to those with a job-related need.

Access to audit log files and associated configurations is limited to those with a job-related need as authorized by management.

CCM, CMMC, FEDRAMP, ISO270012022, ISO27701, NIST800171, NIST800171R3, NIST80053, NISTCSF2, PCI, PCI4

2024-01-19 0:22:44

DCF-430

%s protects audit trail files from unauthorized modifications.

Audit log files are protected to prevent modifications by individuals (e.g., via access control mechanisms, physical segregation, network segregation, etc.)

CMMC, FEDRAMP, ISO270012022, ISO27701, NIST800171, NIST800171R3, NIST80053, NISTCSF2, PCI, PCI4

2024-01-19 0:22:44

DCF-431

%s promptly backs up audit trail files to a centralized log server or media that is difficult to alter.

Audit log files, including those for external facing technologies, are promptly backed up to a secure, central, internal log server(s) or other media that is difficult to modify.

NISTCSF2, PCI, PCI4

2024-01-19 0:22:44

DCF-434

%s has policies and procedures for reviewing the following critical system logs: All security events; logs of all system components that store, process, or transmit CHD and/or SAD; logs of all critical system components; logs of all servers and system components that perform security functions

%s has documented policies and procedures for logging and monitoring that describe the events the organization must log and monitor, the general systems and system components that should be monitored, the specific information that must be captured in logs, the configuration of specific elements of the logging infrastructure, etc. The identified logged/monitored events are reviewed and updated periodically in accordance with company requirements.

CIS8, CMMC, DORA, ISO270012022, ISO27701, ISO420012023, NIST800171, NIST800171R3, NIST80053, NISTCSF2, PCI, PCI4

2024-09-05 21:51:55

DCF-435

%s's critical system logs are reviewed at least daily.

%s performs reviews of the following critical audit logs at least daily (e.g., through the use of alerting mechanisms): all security events, logs of all system components that store, process, or transmit CHD and/or SAD, logs of all critical system components, and logs of all servers and system components that perform security functions.

CIS8, DORA, PCI, PCI4

2024-01-19 0:22:44

DCF-437

%s reviews logs of all other system components periodically based on the organization’s policies and risk management strategy, as determined by the organization’s annual risk assessment.

%s performs reviews of non-critical system logs periodically based on the organization’s policies and risk management strategy, as determined by a risk assessment.

CIS8, DORA, NISTCSF2, PCI, PCI4

2024-01-19 0:22:44

DCF-438

%s conducts follow up on exceptions and anomalies identified during the review process.

Exceptions and anomalies identified during the periodic log-review process are investigated, escalated, and resolved in accordance with the company's documented policies and procedures.

DORA, NISTCSF2, PCI, PCI4

2024-01-19 0:22:44

DCF-441

%s retains audit logs for at least one year.

%s retains audit log history and historical records of activity for a specified frequency (e.g., minimum of 90 days for CIS 8; or at least 12 months, with at least the most recent three months immediately available for analysis, for PCI 4).

CIS8, CMMC, DORA, ISO270012022, ISO27701, NIST800171, PCI, PCI4

2025-04-23 21:45:32

DCF-444

%s ensures that failure of a critical security control results in the generation of an alert.

%s has implemented alerting mechanisms to notify personnel of failures of critical security control systems (including network security controls, IDS/IPS, change-detection mechanisms, anti-malware solutions, physical access controls, logical access controls, audit logging mechanisms, segmentation controls, audit log review mechanisms, automated security testing tools, etc.). Failures of critical security control systems are evaluated as a security event and investigated in accordance with company policies and procedures.

CIS8, CMMC, DORA, FEDRAMP, NIST800171, NIST800171R3, NIST80053, NISTCSF, PCI, PCI4

2024-01-19 0:22:44

DCF-445

%s has a processes for responding to critical security control failures defined and implemented, which includes: Restoring security functions; identifying and documenting the duration (date and time start to end) of the security failure; identifying and documenting cause(s) of failure, including root cause, and documenting remediation required to address root cause; identifying and addressing any security issues that arose during the failure; implementing controls to prevent cause of failure from reoccurring; resuming monitoring of security controls.

Failures of any critical security controls systems are addressed promptly based on the nature of the failure and monitoring of security controls is resumed. Documentation is maintained to include identification of the issue, start time and end time, root cause and required remediation, identification of any security issues that arose during the failure along with associated response, identification of follow-up actions are required as a result of the security failure, and implemented controls to prevent the cause of failure from reoccurring.

DORA, FEDRAMP, NIST800171R3, NIST80053, PCI, PCI4

2024-01-19 0:22:44

DCF-447

%s has security policies and operational procedures for monitoring all access to network resources and cardholder data that are documented, in use, and known to all affected parties.

%s has security policies and operational procedures for monitoring all access to network resources and sensitive information (e.g., PII, PHI, Cardholder Data, etc.) that are documented, in use, and known to all affected parties.

DORA, FEDRAMP, NIST80053, PCI

2025-10-06 23:16:27

DCF-448

%s has implemented processes to test for the presence of wireless access points (802.11), and detects and identifies all authorized and unauthorized wireless access points on a quarterly basis.

%s conducts tests (either through manual verification or automated mechanisms) to identify the presence of authorized and unauthorized wireless (Wi-Fi) access points periodically per policy and compliance requirements. If automated monitoring is used, personnel are notified via generated alerts. Results are documented.

NIST80053, NISTCSF2, PCI, PCI4

2024-09-11 1:28:13

DCF-452

%s maintains an inventory of authorized wireless access points including a documented business justification.

%s maintains a documented inventory of authorized wireless access points including business justification.

CMMC, CYBER_ESSENTIALS_32, FEDRAMP, NIST800171, NIST800171R3, NIST80053, PCI, PCI4

2024-09-05 21:51:55

DCF-454

%s takes action when unauthorized wireless access points are found.

%s executes an incident response process in the event unauthorized wireless access points are detected in accordance with the company's documented policies and procedures.

NIS2, NIST80053, PCI, PCI4

2024-01-19 0:22:44

DCF-455

%s performs quarterly internal vulnerability scans.

%s conducts internal vulnerability scans at least once every three months or upon significant changes to network or systems. The scan tool is kept up to date with latest vulnerability information.

CIS8, PCI, PCI4

2025-04-23 21:45:32

DCF-456

%s addresses vulnerabilities and performs rescans to verify all “high risk” vulnerabilities are resolved in accordance with the entity’s vulnerability ranking.

All critical or high vulnerabilities identified are addressed immediately and a subsequent scan is performed to validate resolution. All other applicable vulnerabilities are addressed based on the company's evaluation of risk per documented policies and procedures and rescans are conducted as needed to confirm resolution.

CIS8, CMMC, CYBER_ESSENTIALS, CYBER_ESSENTIALS_32, DORA, FEDRAMP20X, ISO27701, NIS2, NIST800171, NIST800171R3, NISTCSF2, PCI, PCI4

2024-09-05 21:51:55

DCF-458

%s performs quarterly external vulnerability scans, via an Approved Scanning Vendor (ASV) approved by the Payment Card Industry Security Standards Council (PCI SSC).

External vulnerability scans are performed at least once every three months by a PCI SSC Approved Scanning Vendor (ASV). Vulnerabilities are resolved and ASV Program Guide requirements for a passing scan are met. Rescans are performed as needed to confirm that vulnerabilities are resolved.

PCI, PCI4

2024-01-19 0:22:44

DCF-461

%s performs internal and external scans, and rescans as needed, after any significant change. Scans are performed by qualified personnel.

External vulnerability scans are performed after any significant change in the environment by qualified personnel on all system components affected by the change. Organizational independence of the tester is maintained. Vulnerabilities that are scored 4.0 or higher by the CVSS are resolved and rescans are conducted as needed to validate corrections.

DORA, PCI, PCI4

2024-01-19 0:22:44

DCF-463

%s ensures that vulnerability scans are performed by a qualified internal resource(s) or qualified external third party, and if applicable, organizational independence of the tester exists.

%s assigns a qualified internal resource(s) or qualified external third party to perform internal vulnerability scans. Organizational independence of the tester exists to maintain segregation of duties in the process.

DORA, PCI, PCI4

2024-01-19 0:22:44

DCF-464

%s has implemented a methodology for penetration testing that: Is based on industry-accepted penetration testing approaches; includes coverage for the entire CDE perimeter and critical systems; includes testing from both inside and outside the network; includes testing to validate any segmentation and scope-reduction controls; defines application-layer penetration tests to include, at a minimum, the vulnerabilities listed in Requirement 6.5; defines network-layer penetration tests to include components that support network functions as well as operating systems; includes review and consideration of threats and vulnerabilities experienced in the last 12 months; specifies retention of penetration testing results and remediation activities results.

%s has defined and documented a penetration testing methodology for the organization. The methodology includes industry-accepted penetration testing approaches, coverage for the entire CDE perimeter and critical systems, testing from both inside and outside the network, testing to validate any segmentation and scope reduction controls, application-layer penetration testing, network layer penetration tests, review and consideration of threats and vulnerabilities experienced in the last 12 months, documented approach to assessing and addressing the risk posed by exploitable vulnerabilities and security weaknesses found during penetration testing, and retention of penetration testing results and remediation activities results for at least 12 months.

CIS8, NIST80053, NISTCSF, PCI, PCI4

2024-01-19 0:22:44

DCF-465

%s perform external penetration testing per the defined methodology, at least annually, and after any significant infrastructure or application changes to the environment.

%s conducts external penetration tests at least once every 12 months or after any significant infrastructure or application upgrade or change per the company's defined methodology. Testing is performed by a qualified internal resource or qualified external third party and organizational independence of the tester is maintained.

CIS8, DORA, NIST80053, NISTCSF, PCI, PCI4

2024-01-19 0:22:44

DCF-467

%s perform internal penetration testing at least annually and after any significant infrastructure or application upgrade or modification.

%s conducts internal penetration tests at least once every 12 months and after any significant infrastructure or application upgrade or change per the company's defined methodology. Testing is performed by a qualified internal resource or qualified external third-party and organizational independence of the tester is maintained.

CIS8, DORA, NIST80053, NISTCSF, PCI, PCI4

2024-01-19 0:22:44

DCF-469

%s ensures that exploitable vulnerabilities found during penetration testing are corrected and testing is repeated to verify the corrections.

%s corrects exploitable vulnerabilities and security weaknesses found during penetration testing based on the assessment of the risk posed by the security issue and in accordance with company policies and procedures. Penetration testing is repeated to verify the corrections.

CIS8, NIS2, PCI, PCI4

2024-01-19 0:22:45

DCF-470

%s's penetration-testing procedures are defined to test all segmentation methods, to confirm they are operational and effective, and isolate all out-of-scope systems from systems in the CDE.

Where segmentation is used to isolate the CDE from other networks, %s conducts penetration periodically and after any changes to segmentation controls/methods to validate segmentation and isolation mechanisms are operational and effective. Testing covers all methods in use per the company's defined methodology and is performed by a qualified internal resource or qualified external third party with organizational independence of the tester.

PCI, PCI4

2024-01-19 0:22:45

DCF-473

%s ensures that PCI DSS scope is confirmed by performing penetration tests on segmentation controls at least every six months and after any changes to segmentation controls/methods.

For mutitenant service providers, a penetration test is performed at least every six months to validate the effectiveness of logical separation controls used to separate customer environments.

PCI, PCI4

2024-01-19 0:22:45

DCF-477

%s keeps all intrusion-detection and prevention engines, baselines, and signatures up-to-date.

Intrusion-detection and/or intrusion-prevention techniques are configured to keep all engines, baselines, and signatures up to date.

CCM, CIS8, CMMC, CYBER_ESSENTIALS_32, NIST800171, NISTCSF2, PCI, PCI4

2024-01-19 0:22:45

DCF-478

%s deploys a change-detection mechanism to detect unauthorized modification (including changes, additions, and deletions) of critical system files, configuration files, or content files.

%s has enabled file integrity monitoring or a change-detection mechanism to detect unauthorized modification (including changes, additions, and deletions) of critical system files, configuration files, audit files, or content files to ensure critical data cannot be changed without generating alerts.

CCM, CMMC, DORA, FEDRAMP, ISO270012022, ISO270172015, ISO27701, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, PCI, PCI4, SOC_2

2024-12-11 14:45:49

DCF-479

%s deploys a change-detection mechanism to alert personnel to unauthorized modification (including changes, additions, and deletions) of critical system files, configuration files, or content files; and configure the software to perform critical file comparisons at least weekly.

%s file integrity monitoring or change-detection mechanism perform critical file comparisons at least once weekly.

DORA, NIST80053, NISTCSF, PCI, PCI4

2024-01-19 0:22:45

DCF-482

%s has included explicit approval by authorized parties in critical technologies usage policy.

%s has documented and implemented acceptable use policies for end-user technologies (e.g., remote access and wireless technologies, laptops, tablets, mobile phones, removable electronic media, email usage, internet, etc.), which include explicit approval by authorized parties, acceptable uses of the technology, and list of products approved by the company for employee use, including hardware and software.

CCM, CYBER_ESSENTIALS_32, DORA, FEDRAMP, PCI, PCI4

2024-01-19 0:22:45

DCF-488

%s has included automatic disconnect of sessions for remote-access technologies after a specific period of inactivity in critical technologies usage policy.

%s has implemented technical controls to terminate network connections (including remote connections) associated with communications sessions at the end of the session and after a defined period of inactivity in accordance with company policies and procedures (e.g., de-allocating associated TCP/IP address or port pairs at the operating system level).

CMMC, DORA, FEDRAMP, NIS2, NIST800171, NIST800171R3, NIST80053, PCI

2024-09-05 21:51:55

DCF-490

%s prohibits, for personnel accessing cardholder data via remote-access technologies, the copying, moving, and storage of cardholder data onto local hard drives and removable electronic media, unless explicitly authorized for a defined business need. Where there is an authorized business need, the usage policies must require the data be protected in accordance with all applicable PCI DSS Requirements.

%s prohibits, for personnel accessing sensitive information (e.g., PII, PHI, Cardholder Data, etc.) via remote-access technologies, the copying, moving, and storage of sensitive information (e.g., PII, PHI, Cardholder Data, etc.) onto local hard drives and removable electronic media, unless explicitly authorized for a defined business need.

DORA, FEDRAMP, NIST80053, PCI

2025-10-06 23:16:27

DCF-493

%s's executive management shall establish responsibility for the protection of cardholder data and a PCI DSS compliance program.

%s's executive management has defined a charter for the PCI DSS compliance program. The charter assigns responsibility within executive management for the protection of cardholder data and overall accountability for maintaining PCI DSS compliance, and establishes communication requirements to provide executive management and board of directors updates regarding PCI DSS compliance activities at least once every 12 months.

PCI, PCI4

2024-01-19 0:22:45

DCF-496

%s has formally assigned the responsibility for information security to a Chief Security Officer or other security-knowledgeable member of management.

%s has formally assigned and documented the responsibility for information security to a Chief Security Officer or other security-knowledgeable member of management

PCI, PCI4

2024-01-19 0:22:45

DCF-499

%s has established, documented, and distributed security incident response and escalation procedures to ensure timely and effective handling of all situations.

%s's incident response plan includes roles, responsibilities, and communication and contact strategies in the event of a suspected or confirmed security incident (including notification of payment brands and acquirers), incident response procedures with specific containment and mitigation activities for different types of incidents, business recovery and continuity procedures, data backup processes, analysis of legal requirements for reporting compromises, coverage and responses of all critical system components, and reference or inclusion of incident response procedures from the payment brands.

CCM, ISO270172015, PCI, PCI4

2024-01-19 0:22:45

DCF-503

%s's security awareness program provides multiple methods of communicating awareness and educating personnel.

%s's security awareness program includes multiple methods of communicating awareness and educating personnel, such as newsletters, web-based training, in-person training, team meetings, phishing simulations, etc. Periodic security updates are provided to personnel through these multiple methods of communication.

CMMC, DORA, FEDRAMP, ISO270012022, ISO27701, NIS2, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, PCI, PCI4, SOC_2

2024-01-19 0:22:45

DCF-504

%s's employees have completed awareness training and are aware of the importance of cardholder data security.

Security awareness training materials include information %s's security policy, phishing and related attacks, social engineering, awareness about the acceptable use of end-user technologies, and personnel's role in protecting cardholder data.

CIS8, NIST800171R3, PCI, PCI4

2024-01-19 0:22:45

DCF-507

%s ensures that there is an established process for engaging service providers including proper due diligence prior to engagement.

%s performs due diligence activities prior to engaging with a new service provider or vendor (e.g., review of security questionnaires and compliance reports, review of vendor-provided policies, procedures, or other documents, analysis of delegated or shared responsibilities with the prospective vendor, etc.). Results of the due diligence activities including action items are documented.

CIS8, CMMC, DORA, FEDRAMP20X, ISO270012022, ISO27701, NIS2, NIST800171, NISTCSF2, PCI, PCI4, SOC_2

2024-09-05 21:51:55

DCF-509

%s maintains information about which PCI DSS requirements are managed by each service provider, and which are managed by the entity.

%s maintains documented information about which PCI DSS requirements are managed by each service provider, which are managed by the entity, and any shared responsibilities between service providers and the entity.

PCI, PCI4

2024-01-19 0:22:45

DCF-510

%s acknowledges in writing to customers that they are responsible for the security of cardholder data the service provider possesses or otherwise stores, processes, or transmits on behalf of the customer, or to the extent that they could impact the security of the customer’s cardholder data environment.

%s acknowledges in writing to customers through contracts, service agreements, or other means, that %s will be responsible for the security of account data it possesses or otherwise stores, processes, or transmits on behalf of its customers, or to the extent that the company could impact the security of the customer’s CDE.

CIS8, DORA, PCI, PCI4

2024-01-19 0:22:45

DCF-516

%s provides appropriate training to staff with security breach response responsibilities.

%s provides incident response training to personnel consistent with their assigned roles and responsibilities (e.g., incident identification and reporting for all personnel vs. incident handling for incident response team members, etc.). Personnel complete training within the timelines established in policies and procedures upon receiving system access or assuming an incident response role or responsibility, when required by system changes, and at periodic intervals.

CCM, CMMC, DORA, NIS2, NIST800171, NIST800171R3, NIST80053, NISTCSF2, PCI, PCI4

2024-09-05 21:51:55

DCF-517

%s includes alerts from security monitoring systems, including but not limited to intrusion-detection, intrusion-prevention, firewalls, and file-integrity monitoring systems.

%s's security incident response plan includes procedures for monitoring and responding to alerts from security monitoring systems including intrusion-detection and intrusion-prevention systems, network security controls, change-detection mechanisms for critical files, the change-and tamper-detection mechanism for payment pages, detection of unauthorized wireless access points, etc.

CCM, DORA, NIST80053, NISTCSF, PCI, PCI4

2024-01-19 0:22:45

DCF-519

%s performs reviews to confirm personnel are following security policies and operational procedures. Reviews must cover the following processes: Daily log reviews; firewall rule-set reviews; applying configuration standards to new systems; responding to security alerts: change management processes.

Management performs reviews at least once every three months to confirm that personnel are performing their tasks in accordance with all security policies and operational procedures. Reviews are performed with segregation of duties and include the following tasks: daily log reviews, configuration reviews for network security controls, applying configuration standards to new systems, responding to security alerts, and change-management processes. Results of the reviews are documented and retained.

CCM, PCI, PCI4

2024-01-19 0:22:45

DCF-521

%s maintain documentation of quarterly review process to include: Documenting results of the reviews: review and sign-off of results by personnel assigned responsibility for the PCI DSS compliance program.

Management documents the results of the reviews performed by management to confirm that personnel are performing their tasks in accordance with all security policies and operational procedures. The documentation includes remediation actions taken for any tasks that were found to not be performed and sign-off of results by personnel assigned responsibility for the PCI DSS compliance program.

PCI, PCI4

2024-01-19 0:22:45

DCF-527

%s has formally assigned an independent and capable member to manage privacy-related matters.

%s has appointed and documented responsibilities of an individual (e.g., data protection officer) responsible for developing, implementing, maintaining and monitoring an organization-wide governance and privacy program and acting as a point of contact to authorities and data subjects to ensure compliance with all applicable laws and regulations regarding the processing of PII.

GDPR, ISO270012022, ISO27701, NIST80053, SOC_2

2024-05-07 19:18:26

DCF-529

%s has established a process to obtain consent from a data subject prior to collecting PII.

%s has documented and implemented a process to obtain consent from data subjects prior to collecting PII. The organization obtains and records consent from data subjects according to the documented process.

CCPA, GDPR, ISO270182019, ISO27701, NIST80053, NISTAI, SOC_2

2024-05-07 19:18:26

DCF-530

%s has an established process for acknowledging, logging and documenting withdrawal of consent.

%s provides mechanisms for data subjects to modify or withdraw their consent. %s acknowledges, logs, and documents instances of withdrawals of consent.

CCPA, GDPR, ISO270182019, ISO27701

2024-07-11 20:02:42

DCF-531

%s properly reports and retains records of PII disclosures to include PII disclosed to third parties, requests for legally-binding PII disclosures, subcontractors/sub-processors used for PII processing in accordance with contractual requirements, and changes in subcontractors.

%s documents and maintains a record of authorized disclosures of PII to third parties (including what PII has been disclosed, to whom and when). %s also notifies customers of any legally binding requests for disclosure of PII, unless prohibited by law.

CCPA, GDPR, ISO270182019, ISO27701, SOC_2

2024-05-07 19:18:26

DCF-533

%s has determined roles and responsibilities for the processing of PII with joint PII controllers.

%s has established and documented roles and responsibilities for the processing of PII (including PII protection and security requirements) with any joint PII controller (for example, through a joint controller agreement). The established roles and responsibilities are communicated to data subjects.

GDPR, ISO27701

2024-07-11 20:02:42

DCF-534

%s communicates its obligations to data subjects in a clear and transparent manner.

%s provides data subjects with clear and easily accessible information identifying the PII controller and describing the processing of their PII.

CCPA, GDPR, ISO27701

2024-07-11 20:02:42

DCF-536

%s has an established and documented record of processing activity (ROPA), which includes evidence of lawful collection and use, including defined purpose of processing.

%s has established and documented records of processing activity (ROPA), which includes descriptions of the of lawful collection and use of PII as well as the specific purposes for which PII is processed.

CCM, CCPA, GDPR, ISO270182019, ISO27701, NIST80053, SOC_2

2024-07-11 20:02:42

DCF-537

%s has data processing agreements in place with data processing ecosystem parties which include minimum technical and organizational measures designed to meet the objectives of %s’s privacy program.

%s has data processing agreements (DPAs) in place with sub-processors that include the minimum technical and organizational measures that the third parties need to implement to meet the objectives of %s’s privacy program.

CCPA, GDPR, ISO270182019, ISO27701, NIST80053, SOC_2

2024-05-07 19:18:26

DCF-538

%s conducts a data protection impact assessment when required or when planning for the processing of new, or changing the processing of existing, PII.

%s conducts a data protection impact assessment when planning for the processing of new PII, changing the processing of existing PII, or as otherwise required. Results of the assessment are documented and retained.

CCM, GDPR, ISO27701, NIST80053, NISTAI

2024-07-11 20:02:42

DCF-540

%s tracks and manages requests from data subjects, and provides a response to valid requests within appropriate time.

Upon receiving a privacy right request, privacy inquiry, or privacy incident report, %s provides confirmation of receipt and responds to the request, inquiry, or report within the timeframes established by regulatory requirements.

CCM, CCPA, GDPR, ISO27701, NIST80053, SOC_2

2024-05-07 19:18:26

DCF-541

%s has an established processes to properly manage data subject rights.

%s has defined and documented policies and procedures for handling and responding to requests from data subjects to exercise their data subject rights.

CCM, CCPA, GDPR, ISO27701, SOC_2

2024-05-07 19:18:26

DCF-545

%s has a defined Personal Data Management Policy that outlines how personal data will be managed across the organization, in accordance with applicable privacy laws and regulations.

%s has a defined a policy for the management of personally identifiable information (PII) that outlines how PII is managed by the organization, in accordance with applicable privacy laws and regulations.

CCPA, ISO27701

2024-07-11 20:02:42

DCF-549

%s has an established process for identity verification for requests made by data subjects or authorized agents.

%s has established, documented, and implemented a method for verifying that the person making a privacy right request is the data subject or an authorized agent. If %s cannot confirm the identity or authorization of the requestor, %s notifies the requestor, denies the request, and retains supporting documentation.

CCPA, ISO27701, SOC_2

2024-05-07 19:18:26

DCF-557

%s has an established process for managing shared and group accounts.

Group, shared, or generic account usage is prevented unless strictly necessary and supported by documented business justification and management approval. Mechanisms are in place to confirm individual user identity before access to the account is granted and to trace every action to an individual user.

CMMC, FEDRAMP, ISO270012022, ISO27701, NIST800171, NIST800171R3, NIST80053, PCI4, SOC_2

2024-01-19 0:22:45

DCF-558

%s has a deny-all, allow-by-exception rule in place for authorized software applications and implements procedures to allow execution.

%s has identified allowed software programs in the organization and implemented mechanisms to restrict and monitor the installation and execution of unauthorized software (e.g., through procedural methods or automated mechanisms such as corporate app stores and deny-all, allow-by-exception rules). The list of allowed software is reviewed and updated periodically as determined by the organization.

CIS8, CMMC, CYBER_ESSENTIALS, CYBER_ESSENTIALS_32, FEDRAMP, ISO270012022, ISO27701, NIST800171, NIST800171R3, NIST80053, NISTCSF2, SOC_2

2024-09-05 21:51:55

DCF-562

%s has an established process for managing the use of utility programs.

Access to manage utility programs (including anti-virus consoles and diagnostic, patching, backup, or network tools, or any other utility can be capable of overriding system and application controls) is restricted to authorized system administrators. Standard users cannot disable privileged utilities or modify their configurations.

CMMC, ISO270012022, ISO270172015, ISO27701, NIST800171, NIST800171R3, PCI4, SOC_2

2024-05-07 19:18:26

DCF-564

%s ensures that the development and test environments are properly protected through appropriate measures (e.g., updates, monitoring and access control, backups).

%s ensures that the development and test environments are properly through appropriate measures (e.g., updates, monitoring and access control, backups).

CCM

2024-05-07 19:18:26

DCF-566

%s has an established process to properly manage and track non-conformities.

When a nonconformity is identified, %s performs a root-cause analysis and implements corrective actions to address the nonconformity. %s retains documentation of the analysis and subsequent actions taken and of the results of any corrective action.

CCM, CIS8, CMMC, DORA, ISO270012022, ISO27701, NIS2, NIST800171, NIST800171R3, NISTCSF2

2024-05-07 19:18:26

DCF-567

%s has a defined Change Management Policy that covers policies and procedures to manage changes across the organization in a well-communicated, planned and predictable manner that minimizes unplanned outages and unforeseen system issues.

%s has a documented a policy that describes the requirements for managing changes across the organization, including changes to infrastructure, systems, and applications.

CCM, DORA, FEDRAMP, FEDRAMP20X, ISO270012022, ISO270172015, ISO27701, NIS2, NIST80053, NISTAI, NISTCSF, NISTCSF2, SOC_2

2024-05-07 19:18:26

DCF-575

%s has a defined maintenance management policy to ensure that IT resources are maintained in compliance with security policies, standards, and procedures.

%s has a defined policies and procedures for maintenance management to ensure that maintenance on organizational systems are conducted periodically in accordance with security requirements.

CMMC, DORA, FEDRAMP, NIST800171, NIST800171R3, NIST80053, NISTCSF

2024-09-05 21:51:55

DCF-583

%s displays system use notification to users prior to granting access.

%s provides system use notifications to users prior to allowing access to the system, such as privacy and security notices, in accordance with applicable regulations.

CMMC, FEDRAMP, NIST800171, NIST800171R3, NIST80053

2024-09-05 21:51:55

DCF-586

%s defines conditions for allowing remote access to security/privacy information and executing privileged commands.

%s authorizes remote execution of identified privileged commands and remote access to security-relevant information.

CMMC, DORA, FEDRAMP, NIST800171, NIST80053

2024-09-05 21:51:55

DCF-591

%s has an established procedure for managing publicly accessible content, which includes proper content review, and properly-trained personnel to make information publicly accessible.

Content posted or processed on publicly accessible systems is reviewed by knowledgeable personnel prior to posting to validate it does not include nonpublic sensitive information in accordance with company policies and procedures and applicable regulations. If discovered, nonpublic sensitive information is removed.

CMMC, FEDRAMP, NIST800171, NIST800171R3, NIST80053

2024-09-05 21:51:55

DCF-606

%s identifies and authenticates devices prior to establishing a connection.

Devices accessing the system are identified (e.g., through media access control (MAC) addresses, internal protocol (IP) addresses, device-unique token identifiers, etc.). The identity of each device accessing or connecting to the system is authenticated or verified as a prerequisite to system access.

CMMC, FEDRAMP, FEDRAMP20X, NIST800171, NIST800171R3, NIST80053, NISTCSF2

2024-09-05 21:51:55

DCF-607

%s has a process in place to manage system identifiers and prevent their reuse.

%s has documented policies and procedures for assigning unique identifiers to individuals, groups, roles, services, or devices. Reuse of identifiers is restricted.

CMMC, FEDRAMP, ISO27701, NIST800171, NIST800171R3, NIST80053, NISTCSF2

2024-07-11 20:02:42

DCF-610

%s protects authenticators based on the highest security category of information on the system.

%s protects authenticators based on the highest security category of information on the system.

FEDRAMP, NIST800171R3, NIST80053

2025-03-19 18:29:34

DCF-611

%s obscures the feedback of authentication information during the authentication process.

%s has implemented mechanisms to obscure the feedback of authentication information, such as usernames/passwords, during the authentication process where technically feasible (e.g., in company-developed systems or applications, configurable third-party systems, etc.).

CMMC, FEDRAMP, ISO270012022, NIST800171, NIST800171R3, NIST80053

2024-05-07 19:18:26

DCF-614

%s utilizes automated maintenance tools to perform maintenance activities.

%s has implemented automated mechanisms and tools to conduct maintenance, repairs, and replacement actions on organizational systems.

CMMC, FEDRAMP, NIST800171, NIST80053

2024-09-05 21:51:55

DCF-615

%s requires that the use of maintenance tools be approved, controlled, and monitored.

Tools, techniques, or mechanisms used to perform system security maintenance are approved by management prior to use with supporting documentation.

CMMC, FEDRAMP, NIST800171, NIST80053, NISTCSF

2024-09-05 21:51:55

DCF-616

%s has an approval process for non local maintenance activities.

%s approves and monitors all nonlocal maintenance and diagnostic activities and retains documented evidence of the approval. %s validates that external session and network connections are terminated when nonlocal maintenance or diagnostic activities are completed.

CMMC, FEDRAMP, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2

2024-09-05 21:51:55

DCF-617

%s has established procedures for maintenance personnel authorization.

%s has a documented process to authorize maintenance personnel or organizations to perform maintenance and keeps a documented list of authorized parties. %s assigns organizational personnel with required access authorizations and technical competence to supervise the maintenance activities of personnel without required access authorizations.

CMMC, FEDRAMP, NIST800171, NIST800171R3, NIST80053, NISTCSF2

2024-09-05 21:51:55

DCF-619

%s review, approve, track, document, and verify media sanitization and disposal actions.

%s sanitizes equipment and system media that contain sensitive prior to disposal, release for reuse, or release out of organizational control (e.g., removed from premises for off-site maintenance). %s reviews, approves, tracks, documents, and verifies media sanitization and disposal actions in accordance with company policies and procedures.

CCM, CIS8, CMMC, FEDRAMP, ISO270012022, ISO27701, NIST800171, NIST800171R3, NIST80053

2024-09-05 21:51:55

DCF-635

%s only allows information technology products approved under the Federal Information Processing Standards (FIPS) 201 to be used for Personal Identity Verification (PIV) capabilities.

%s only allows information technology products approved under the Federal Information Processing Standards (FIPS) 201 to be used for sensitive information capabilities.

FEDRAMP, NIST80053

2023-02-02 18:20:03

DCF-637

%s has a documented secure development process for system developers.

%s has documented software development procedures that outline the company's processes for secure development. The documented processes include references to industry standards and/or best practices for secure development, security requirement considerations (for example, secure authentication and logging, etc.), and consideration for information security issues during each stage of the software development life cycle.

CCM, CIS8, CMMC, FEDRAMP, FEDRAMP20X, ISO270012022, ISO27701, NIS2, NIST800171, NIST80053, NISTCSF2, PCI4

2024-09-05 21:51:55

DCF-638

%s ensures that user functions are separated from system management functions.

%s has implemented separation controls (physical or logical) so that user functionality is separated from system management functionality.

CIS8, CMMC, CYBER_ESSENTIALS, CYBER_ESSENTIALS_32, FEDRAMP, NIST800171, NIST80053

2024-09-05 21:51:55

DCF-639

%s ensures that any unauthorized or unintended information transfers via shared system resources are prevented.

%s has implemented technical controls to prevent unauthorized and unintended information transfer via shared system resources such as registers, cache memory, main memory, hard disks, etc.

CMMC, DORA, FEDRAMP, NIST800171, NIST800171R3, NIST80053

2024-09-05 21:51:55

DCF-643

%s prohibits the remote activation of collaborative computing devices and applications, unless explicitly defined otherwise.

Remote activation of collaborative computing devices and applications (e.g., networked white boards, cameras, microphones, etc.) is prohibited unless explicitly defined otherwise in company policies and procedures. Collaborative computing devices provide an explicit indication of use to users physically present at the devices (e.g., through pop-up menus, signals, etc.).

CMMC, FEDRAMP, NIST800171, NIST800171R3, NIST80053

2024-09-05 21:51:55

DCF-644

%s manages the use of acceptable mobile code and mobile code technologies.

%s has defined acceptable and unacceptable mobile code and mobile code technologies in the enterprise (e.g., Java, JavaScript, ActiveX, Postscript, PDF, Flash animations, VBScript, etc.). %s has implemented usage restrictions for mobile code technologies to prevent the development, acquisition, and introduction of unacceptable mobile through policies, procedures, and/or technical mechanisms.

CMMC, FEDRAMP, NIST800171, NIST800171R3, NIST80053, NISTCSF

2024-09-05 21:51:55

DCF-660

%s has defined the amount of risk it is willing to accept to achieve its objectives.

%s has defined and approved risk appetite statements, including statements pertaining to cybersecurity risk, that convey expectations about the level of risk the organization is willing to accept in the pursuit of objectives. These statements are reviewed periodically and updated as necessary.

CCM, DORA, NIS2, NISTCSF2

2024-09-11 1:28:13

DCF-677

%s installs software updates within 14 days of release.

%s has implemented a software update management process where critical patches and application updates are installed for all authorized software within priority SLAs established in company policies.

CIS8, CMMC, CYBER_ESSENTIALS, CYBER_ESSENTIALS_32, DORA, FEDRAMP20X, ISO27701, NIST800171, NISTCSF2, SOC_2

2024-05-07 19:18:26

DCF-678

%s has a defined Global Network Firewall Policy that covers policies and procedures to manage firewalls across the organization in compliance with security policies, standards, and procedures.

%s has defined and documented a policy that outlines requirements for deployment, management and operation of network security controls at the company.

CMMC, CYBER_ESSENTIALS, CYBER_ESSENTIALS_32, DORA, ISO270012022, ISO27701, NIS2, NIST800171, NISTCSF2

2024-05-07 19:18:26

Test Mapping Revisions

Expand to view Test Mapping Revisions

For the Current Tests column, cells that are blank means the control was unmapped.

Code

Previous Tests

Current Tests

Frameworks

Last Updated

DCF-1

1, 2

CCM, FEDRAMP, HIPAA, ISO27001, ISO270172015, NIST80053

2024-12-03 22:39:18

DCF-2

3

CCM, CCPA, CYBER_ESSENTIALS, FEDRAMP, HIPAA, ISO27001, NIST80053, NISTCSF, PCI

2024-12-03 22:39:18

DCF-4

5, 6, 7

5, 7

CCM, CIS8, CMMC, FEDRAMP, FEDRAMP20X, ISO27001, ISO270012022, ISO270172015, ISO27701, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, SOC_2

2024-12-03 22:39:18

DCF-7

10

CCM, CIS8, CMMC, DORA, FEDRAMP, ISO27001, ISO270012022, ISO27701, NIS2, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, PCI, PCI4, SOC_2

2024-12-03 22:39:18

DCF-9

12

CCM, CIS8, DORA, DRATA_ESSENTIALS, FEDRAMP, HIPAA, ISO27001, ISO270012022, ISO27701, ISO420012023, NIST800171R3, NIST80053, NISTCSF2, SOC_2

2024-12-03 22:39:18

DCF-11

14

CCM, CIS8, CMMC, CYBER_ESSENTIALS, CYBER_ESSENTIALS_32, DORA, FEDRAMP, HIPAA, ISO27001, ISO270012022, ISO270172015, ISO270182019, ISO27701, NIS2, NIST800171, NIST80053, NISTCSF, NISTCSF2, PCI4, SOC_2

2024-12-03 22:39:18

DCF-12

15

292, 8018

CCM, CIS8, CMMC, CYBER_ESSENTIALS, CYBER_ESSENTIALS_32, DORA, FEDRAMP, FEDRAMP20X, HIPAA, ISO27001, ISO270012022, ISO270172015, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, PCI, PCI4, SOC_2

2024-12-03 22:39:18

DCF-18

21

21, 212, 213, 235, 236, 237, 238, 239, 240, 241, 242, 282, 283, 284, 285, 286, 287, 288, 289, 313, 314, 315, 316, 317, 318, 319, 320, 321, 322

CCM, CCPA, CIS8, CMMC, CYBER_ESSENTIALS, CYBER_ESSENTIALS_32, DORA, DRATA_ESSENTIALS, FEDRAMP, FEDRAMP20X, GDPR, HIPAA, ISO27001, ISO270012022, ISO27701, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, SOC_2

2024-12-03 22:39:18

DCF-20

23

CCM, CCPA, CIS8, CMMC, CYBER_ESSENTIALS, CYBER_ESSENTIALS_32, DORA, DRATA_ESSENTIALS, FEDRAMP, FEDRAMP20X, HIPAA, ISO27001, ISO270012022, ISO270172015, ISO27701, NIS2, NIST800171, NIST800171R3, NIST80053, NISTAI, NISTCSF, NISTCSF2, PCI, PCI4, SOC_2

2024-12-03 22:39:18

DCF-22

25

CCM, CCPA, CIS8, CMMC, CYBER_ESSENTIALS_32, DORA, HIPAA, ISO27001, ISO270012022, ISO270172015, ISO27701, NIST800171, NIST80053, NISTCSF, NISTCSF2, PCI4, SOC_2

2024-12-03 22:39:18

DCF-23

26

CCM, CIS8, CYBER_ESSENTIALS, FEDRAMP, ISO27001, NIST80053, NISTCSF

2024-12-03 22:39:18

DCF-24

27

CIS8, CYBER_ESSENTIALS, FEDRAMP, ISO27001

2024-12-03 22:39:18

DCF-27

30, 31

30, 8004, 8036

CIS8, DORA, DRATA_ESSENTIALS, FEDRAMP, FEDRAMP20X, HIPAA, ISO27001, ISO270012022, ISO27701, NIST80053, NISTCSF2, SOC_2

2024-12-03 22:39:18

DCF-28

32

26

CCM, CIS8, CMMC, CYBER_ESSENTIALS_32, DORA, FEDRAMP, FEDRAMP20X, HIPAA, ISO27001, ISO270012022, ISO27701, ISO420012023, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, PCI4, SOC_2

2024-12-03 22:39:18

DCF-29

34

CCM, CIS8, DORA, DRATA_ESSENTIALS, FEDRAMP, HIPAA, ISO27001, ISO270012022, ISO420012023, NIS2, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, PCI, SOC_2

2024-12-03 22:39:18

DCF-30

35

CCM, CCPA, CIS8, CMMC, DORA, FEDRAMP, FEDRAMP20X, ISO27001, ISO270012022, ISO27701, NIS2, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, PCI4, SOC_2

2024-12-03 22:39:18

DCF-32

37, 38, 190

38, 49, 190

CCM, CYBER_ESSENTIALS_32, DORA, FEDRAMP, GDPR, ISO27001, ISO270012022, ISO270172015, ISO27701, NIS2, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, PCI, PCI4, SOC_2

2024-12-03 22:39:18

DCF-34

40

CCM, CCPA, FEDRAMP, HIPAA, ISO27001, NIST80053, NISTCSF

2024-12-03 22:39:18

DCF-35

41

CCM, FEDRAMP, HIPAA, ISO27001, NIST80053, NISTCSF

2024-12-03 22:39:18

DCF-36

42, 43

43

CCM, CCPA, CIS8, CMMC, CYBER_ESSENTIALS, DORA, DRATA_ESSENTIALS, FEDRAMP, FEDRAMP20X, HIPAA, ISO27001, ISO270012022, ISO270182019, ISO27701, NIS2, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, PCI, PCI4, SOC_2

2024-12-03 22:39:18

DCF-39

47

47, 50

CCM, CMMC, FEDRAMP, HIPAA, ISO27001, ISO270012022, ISO27701, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, PCI, PCI4, SOC_2

2024-12-03 22:39:18

DCF-40

48, 49, 50

CCM, FEDRAMP, HIPAA, ISO27001, NIST80053, NISTCSF

2024-12-03 22:39:18

DCF-42

52

40

CCM, DORA, FEDRAMP, HIPAA, ISO27001, ISO270012022, ISO270172015, ISO27701, ISO420012023, NIS2, NIST80053, NISTCSF, NISTCSF2, PCI4, SOC_2

2024-12-03 22:39:18

DCF-43

199

CCM, CIS8, FEDRAMP, HIPAA, ISO27001, ISO270172015, NIST80053, NISTCSF

2024-12-03 22:39:18

DCF-44

54, 55

48, 54, 55

CCM, DORA, DRATA_ESSENTIALS, HIPAA, ISO27001, ISO270012022, ISO27701, NIS2, NISTCSF2, SOC_2

2024-12-03 22:39:18

DCF-45

56, 57, 191

56

CCM, CCPA, CIS8, CMMC, DORA, DRATA_ESSENTIALS, FEDRAMP, GDPR, HIPAA, ISO27001, ISO270012022, ISO270172015, ISO270182019, ISO27701, NIS2, NIST800171, NIST80053, NISTCSF, NISTCSF2, PCI, SOC_2

2024-12-03 22:39:18

DCF-46

58

CMMC, DORA, FEDRAMP, ISO27001, ISO270012022, ISO27701, NIST800171, NIST800171R3, NISTCSF, NISTCSF2, PCI, PCI4, SOC_2

2024-12-03 22:39:18

DCF-48

61, 194

61

CCM, CCPA, CIS8, CMMC, CYBER_ESSENTIALS, CYBER_ESSENTIALS_32, DORA, FEDRAMP, HIPAA, ISO27001, ISO270012022, ISO27701, NIST800171, NIST800171R3, NIST80053, NISTCSF, PCI4, SOC_2

2024-12-03 22:39:18

DCF-49

62, 63, 195

63

CCM, CYBER_ESSENTIALS, CYBER_ESSENTIALS_32, FEDRAMP, HIPAA, ISO27001, ISO270012022, SOC_2

2024-12-03 22:39:18

DCF-50

64, 196

64

CCM, CCPA, CIS8, CMMC, CYBER_ESSENTIALS, CYBER_ESSENTIALS_32, DRATA_ESSENTIALS, FEDRAMP, HIPAA, ISO27001, ISO270012022, ISO27701, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, PCI, PCI4, SOC_2

2024-12-03 22:39:18

DCF-51

65, 197

65

CCM, CCPA, CIS8, CMMC, CYBER_ESSENTIALS, CYBER_ESSENTIALS_32, DORA, DRATA_ESSENTIALS, FEDRAMP, ISO27001, ISO270012022, ISO27701, NIST800171, NIST800171R3, NIST80053, NISTCSF, PCI, SOC_2

2024-12-03 22:39:18

DCF-52

66, 145, 198

66

CCM, CCPA, CIS8, CMMC, CYBER_ESSENTIALS, CYBER_ESSENTIALS_32, DRATA_ESSENTIALS, FEDRAMP, HIPAA, ISO27001, ISO270012022, ISO27701, NIS2, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, SOC_2

2024-12-03 22:39:18

DCF-53

67

CCM, FEDRAMP, GDPR, HIPAA, ISO27001, ISO270172015, NIST80053

2024-12-03 22:39:18

DCF-54

68, 69

68, 69, 218, 222, 231, 270, 8002

CCM, CCPA, CIS8, CMMC, DORA, DRATA_ESSENTIALS, FEDRAMP, FEDRAMP20X, GDPR, HIPAA, ISO27001, ISO270012022, ISO27701, NIS2, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, PCI4, SOC_2

2025-09-23 3:47:31

DCF-55

70, 71, 72, 73

70, 71, 72, 210, 234, 253, 263, 269, 299, 8008, 8015

CCM, CCPA, CIS8, CMMC, DORA, DRATA_ESSENTIALS, FEDRAMP, FEDRAMP20X, HIPAA, ISO27001, ISO270012022, ISO270182019, ISO27701, NIS2, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, PCI4, SOC_2

2024-12-11 14:45:49

DCF-56

74

CCM, CCPA, CIS8, CMMC, DORA, DRATA_ESSENTIALS, FEDRAMP, FEDRAMP20X, HIPAA, ISO27001, ISO270012022, ISO270172015, ISO27701, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, PCI4, SOC_2

2024-12-03 22:39:18

DCF-57

75

CCM, CCPA, CIS8, CMMC, DORA, FEDRAMP, HIPAA, ISO27001, ISO270012022, ISO270172015, ISO27701, NIS2, NIST800171, NIST800171R3, NIST80053, NISTAI, NISTCSF, NISTCSF2, PCI4, SOC_2

2024-12-03 22:39:18

DCF-58

76, 77

CCM, CCPA, CIS8, CMMC, CYBER_ESSENTIALS, CYBER_ESSENTIALS_32, FEDRAMP, HIPAA, ISO27001, ISO270172015, NIS2, NIST800171, NIST800171R3, NIST80053, NISTCSF

2024-12-03 22:39:18

DCF-59

78

208

CCM, CCPA, CIS8, CMMC, CYBER_ESSENTIALS, CYBER_ESSENTIALS_32, DORA, FEDRAMP, HIPAA, ISO27001, ISO270012022, ISO270172015, ISO270182019, ISO27701, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, PCI, PCI4, SOC_2

2024-12-03 22:39:18

DCF-60

79

CCM, DORA, HIPAA, ISO27001, NIST800171R3, SOC_2

2024-12-03 22:39:18

DCF-61

80

CIS8, DORA, ISO27001, ISO270172015, PCI4, SOC_2

2024-12-03 22:39:18

DCF-62

81

CCPA, CIS8, CMMC, DORA, DRATA_ESSENTIALS, FEDRAMP, HIPAA, ISO27001, ISO270012022, ISO27701, NIST800171, NIST800171R3, NIST80053, NISTCSF2, PCI4, SOC_2

2024-12-03 22:39:18

DCF-63

82

85

ISO27001, SOC_2

2024-12-03 22:39:18

DCF-64

83

CCM, HIPAA, ISO27001, NISTCSF, NISTCSF2, SOC_2

2024-12-03 22:39:18

DCF-66

85

83

CCM, ISO27001, NISTCSF, SOC_2

2024-12-03 22:39:18

DCF-68

89

89, 215

CCM, CCPA, CMMC, CYBER_ESSENTIALS, CYBER_ESSENTIALS_32, DORA, DRATA_ESSENTIALS, FEDRAMP, FEDRAMP20X, HIPAA, ISO27001, ISO270012022, ISO270172015, ISO27701, NIS2, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, PCI, PCI4, SOC_2

2024-12-03 22:39:18

DCF-69

90, 91, 92, 93

CCM, CIS8, CMMC, CYBER_ESSENTIALS, CYBER_ESSENTIALS_32, DORA, FEDRAMP, HIPAA, ISO27001, ISO270012022, ISO270182019, ISO27701, NIS2, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, PCI4, SOC_2

2024-12-03 22:39:18

DCF-70

94, 95

94, 95, 199

CCM, CCPA, CIS8, CMMC, CYBER_ESSENTIALS, CYBER_ESSENTIALS_32, DORA, FEDRAMP, HIPAA, ISO27001, ISO270012022, ISO270182019, ISO27701, NIS2, NIST800171, NIST800171R3, NISTCSF, NISTCSF2, PCI, PCI4, SOC_2

2024-12-03 22:39:18

DCF-71

96, 97, 98, 99, 100

96, 97, 98

CCM, CMMC, CYBER_ESSENTIALS, CYBER_ESSENTIALS_32, DORA, DRATA_ESSENTIALS, FEDRAMP, HIPAA, ISO27001, ISO270012022, ISO270172015, ISO270182019, ISO27701, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, PCI4, SOC_2

2024-12-03 22:39:18

DCF-72

101

CCM, FEDRAMP, HIPAA, ISO27001, ISO270012022, NIST80053, SOC_2

2024-12-03 22:39:18

DCF-73

102

102, 227, 228, 268

CCM, CCPA, CIS8, CMMC, CYBER_ESSENTIALS_32, DORA, DRATA_ESSENTIALS, FEDRAMP, HIPAA, ISO27001, ISO270012022, ISO27701, NIST800171, NIST800171R3, NIST80053, SOC_2

2024-12-11 14:45:49

DCF-74

103

FEDRAMP, ISO27001, ISO270172015, ISO27701, NIST80053, NISTCSF, SOC_2

2024-12-03 22:39:18

DCF-75

104

104, 209, 220, 311, 312, 8011

CCM, DRATA_ESSENTIALS, FEDRAMP, ISO27001, ISO270012022, ISO270172015, NIS2, NIST800171R3, SOC_2

2025-01-30 19:06:48

DCF-77

107

107, 8001, 8017

CCM, CCPA, CIS8, CYBER_ESSENTIALS, DORA, DRATA_ESSENTIALS, FEDRAMP, HIPAA, ISO27001, ISO270012022, ISO27701, NIST80053, NISTAI, NISTCSF, NISTCSF2, SOC_2

2024-12-03 22:39:18

DCF-78

108

108, 8003

CIS8, FEDRAMP, ISO27001, ISO270012022, NIST80053, SOC_2

2024-12-03 22:39:18

DCF-80

111

CCM, CCPA, FEDRAMP, HIPAA, ISO27001, ISO270172015, ISO270182019, NIST80053, NISTCSF

2024-12-03 22:39:18

DCF-81

112, 113, 114

FEDRAMP, HIPAA, ISO27001, NIST80053, NISTCSF

2024-12-03 22:39:18

DCF-82

115

FEDRAMP, HIPAA, ISO27001, NIST80053

2024-12-03 22:39:18

DCF-83

116, 117

116

FEDRAMP, HIPAA, ISO27001, NIST80053

2024-12-03 22:39:18

DCF-84

118

CCM, CYBER_ESSENTIALS, FEDRAMP, HIPAA, ISO27001, NIST80053

2024-12-03 22:39:18

DCF-85

119

119, 209, 233, 291, 8007, 8009, 8010, 8012, 8016

CCM, CCPA, CIS8, CMMC, CYBER_ESSENTIALS, CYBER_ESSENTIALS_32, DRATA_ESSENTIALS, FEDRAMP, FEDRAMP20X, ISO27001, ISO270012022, ISO27701, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, PCI4, SOC_2

2024-12-03 22:39:18

DCF-86

120, 206

112, 113, 114, 115, 117, 118, 206, 243, 244, 245, 246, 247, 248, 249, 250, 251, 252, 290, 293, 294, 295, 296, 297, 298, 300, 301

CCM, CMMC, DORA, DRATA_ESSENTIALS, FEDRAMP, HIPAA, ISO27001, ISO270012022, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, SOC_2

2025-08-17 0:10:54

DCF-87

105, 121

105

CCM, CCPA, CIS8, CMMC, DORA, FEDRAMP, HIPAA, ISO27001, ISO270012022, ISO27701, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, SOC_2

2024-12-03 22:39:18

DCF-88

122

122, 311, 312

CCM, CCPA, CIS8, CMMC, CYBER_ESSENTIALS, CYBER_ESSENTIALS_32, DORA, DRATA_ESSENTIALS, FEDRAMP, FEDRAMP20X, ISO27001, ISO270012022, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, PCI4, SOC_2

2024-12-11 14:45:49

DCF-89

123

ISO27001

2024-12-03 22:39:18

DCF-90

124

124, 214, 225

CYBER_ESSENTIALS_32, DORA, FEDRAMP, ISO270012022, NIST800171R3, NIST80053, SOC_2

2024-12-11 14:45:49

DCF-91

125

CCM, CCPA, CIS8, CMMC, DORA, FEDRAMP, HIPAA, ISO27001, ISO270012022, ISO27701, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, PCI, PCI4, SOC_2

2024-12-03 22:39:18

DCF-92

126

CCM, CCPA, CIS8, CMMC, DORA, FEDRAMP, HIPAA, ISO27001, ISO270012022, ISO27701, NIS2, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, SOC_2

2024-12-03 22:39:18

DCF-93

127

CCM, FEDRAMP, HIPAA, ISO27001, NIST80053, PCI

2024-12-03 22:39:18

DCF-96

130

130, 8035

CCM, DORA, FEDRAMP20X, ISO27001, ISO270012022, ISO270172015, ISO27701, NISTCSF, NISTCSF2, SOC_2

2024-12-03 22:39:18

DCF-97

131

131, 8000

DORA, FEDRAMP, ISO27001, ISO270012022, ISO270172015, ISO27701, NIST80053, NISTCSF, NISTCSF2, SOC_2

2024-12-03 22:39:18

DCF-100

135

CCM, CCPA, CIS8, CYBER_ESSENTIALS, DORA, FEDRAMP, HIPAA, ISO27001, ISO270012022, ISO27701, NIST80053, NISTCSF, NISTCSF2, SOC_2

2024-12-03 22:39:18

DCF-101

136

111, 136, 8019

CCM, CIS8, FEDRAMP, HIPAA, ISO27001, ISO270012022, ISO270172015, ISO270182019, ISO27701, NIS2, NIST800171R3, NIST80053, NISTCSF2, PCI, PCI4, SOC_2

2024-12-03 22:39:18

DCF-103

138

CCM, HIPAA, ISO27001, ISO270012022, ISO27701, SOC_2

2024-12-03 22:39:18

DCF-104

139

CCM, DORA, ISO27001, ISO270012022, ISO27701, NIS2, NISTCSF2, PCI, SOC_2

2024-12-03 22:39:18

DCF-105

140

CCM, ISO27001, ISO270012022, ISO270182019, ISO27701, NISTCSF2, SOC_2

2024-12-03 22:39:17

DCF-106

141, 142

DORA, HIPAA, ISO27001, ISO270012022, ISO27701, PCI4

2024-12-03 22:39:17

DCF-107

143

CCM, CCPA, CIS8, FEDRAMP, HIPAA, ISO27001, ISO270012022, ISO270182019, ISO27701, NIST80053, NISTCSF2, PCI4, SOC_2

2024-12-03 22:39:17

DCF-108

144

CCM, CCPA, CMMC, DORA, HIPAA, ISO27001, ISO270012022, ISO270182019, ISO27701, NIST800171, NIST800171R3, NISTCSF2, PCI4, SOC_2

2024-12-03 22:39:17

DCF-110

147

CIS8, FEDRAMP, ISO27701, NIST80053, SOC_2

2024-12-03 22:39:18

DCF-109

144

CCM, CCPA, CIS8, FEDRAMP, HIPAA, ISO27001, ISO270012022, ISO270182019, ISO27701, NIST80053, NISTCSF2, SOC_2

2024-12-03 22:39:17

DCF-111

148

CIS8, ISO27701, SOC_2

2024-12-03 22:39:17

DCF-112

159

HIPAA, ISO27001, ISO270012022, ISO27701, NIST80053, NISTCSF, SOC_2

2024-12-03 22:39:17

DCF-113

160

HIPAA, ISO27001

2024-12-03 22:39:17

DCF-114

161

CCPA, HIPAA, ISO27001, NIST80053, NISTCSF

2024-12-03 22:39:17

DCF-115

162

CCM, CCPA, GDPR, ISO27001, ISO27701, NIST80053, SOC_2

2024-12-03 22:39:17

DCF-116

163

ISO27001, NIST80053

2024-12-03 22:39:17

DCF-117

164

CCM, CCPA, GDPR, ISO27001, NIST80053

2024-12-03 22:39:18

DCF-118

165

CCM, ISO27001, NISTAI

2024-12-03 22:39:18

DCF-119

166

CCM, HIPAA, ISO27001

2024-12-03 22:39:18

DCF-120

167

CCM, DORA, GDPR, HIPAA, ISO27001, ISO270012022, ISO27701, NIST80053, NISTCSF, SOC_2

2024-12-03 22:39:18

DCF-121

168

CCM, CCPA, GDPR, ISO27001, ISO270182019, NIST80053

2024-12-03 22:39:18

DCF-122

169

NIST80053, SOC_2

2024-12-03 22:39:18

DCF-123

170

CCM, CCPA, CIS8, DORA, FEDRAMP, HIPAA, ISO27001, ISO270012022, ISO270172015, ISO270182019, ISO27701, NIST80053, NISTCSF, NISTCSF2, SOC_2

2024-12-03 22:39:18

DCF-124

171

CCM, CYBER_ESSENTIALS, FEDRAMP, HIPAA, ISO27001, ISO270172015, NIST80053, NISTCSF

2024-12-03 22:39:18

DCF-125

172

CCM, FEDRAMP, HIPAA, ISO27001, ISO270182019

2024-12-03 22:39:18

DCF-126

173

CYBER_ESSENTIALS_32, FEDRAMP, HIPAA, ISO27001, ISO270182019, ISO27701, NIS2, NIST80053, SOC_2

2024-12-03 22:39:18

DCF-127

175

CCM, CCPA, HIPAA, ISO27001, NISTCSF, SOC_2

2024-12-03 22:39:18

DCF-128

176

CCM, FEDRAMP, HIPAA, ISO27001, ISO270182019, NISTAI

2024-12-03 22:39:18

DCF-129

177

FEDRAMP, HIPAA, ISO27001, NISTAI

2024-12-03 22:39:18

DCF-130

178

CCM, FEDRAMP, GDPR, ISO27001, ISO27701, ISO420012023, NISTCSF, SOC_2

2024-12-03 22:39:18

DCF-131

179

CIS8, FEDRAMP, HIPAA, ISO27001, NIST80053, NISTCSF

2024-12-03 22:39:18

DCF-132

180

CCM, CIS8, DORA, HIPAA, ISO27001, ISO270012022, ISO27701, NIST800171R3, NISTAI, NISTCSF2, SOC_2

2024-12-03 22:39:18

DCF-133

181

CIS8, FEDRAMP, HIPAA, ISO27001, NISTAI

2024-12-03 22:39:18

DCF-134

182

CCM, CIS8, FEDRAMP, HIPAA, ISO27001, ISO270172015, NIST80053, NISTCSF

2024-12-03 22:39:18

DCF-135

183

CCM, CCPA, CIS8, CMMC, DORA, FEDRAMP, FEDRAMP20X, GDPR, HIPAA, ISO27001, ISO270012022, ISO270182019, ISO27701, ISO420012023, NIS2, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, SOC_2

2024-12-03 22:39:18

DCF-136

184

HIPAA, ISO27001, ISO27701, SOC_2

2024-12-03 22:39:18

DCF-137

185

FEDRAMP, ISO27001, NIST80053

2024-12-03 22:39:18

DCF-138

186

NIST80053

2024-12-03 22:39:18

DCF-139

187

HIPAA, NIST80053

2024-12-03 22:39:18

DCF-140

188

CCPA, HIPAA, ISO27701, NIST80053, NISTCSF2, SOC_2

2024-12-03 22:39:18

DCF-141

189

HIPAA, ISO27701, NIST80053, SOC_2

2024-12-03 22:39:18

DCF-145

201

ISO27001

2022-06-21 21:57:20

DCF-148

146

CCM, FEDRAMP, ISO27001, NIST80053, NISTCSF

2021-06-16 3:53:16

DCF-152

219, 8013

CIS8, CMMC, CYBER_ESSENTIALS_32, DORA, FEDRAMP, ISO27001, ISO270012022, ISO27701, NIST800171, NIST800171R3, NIST80053, NISTCSF, SOC_2

2024-09-05 21:51:55

DCF-154

200

CCPA, CIS8, CMMC, DORA, FEDRAMP, FEDRAMP20X, HIPAA, ISO27001, ISO270012022, ISO420012023, NIS2, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, PCI, PCI4, SOC_2

2024-09-05 21:51:55

DCF-160

123

CCM, CCPA, CMMC, DORA, FEDRAMP, HIPAA, ISO27001, ISO270012022, ISO27701, ISO420012023, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, SOC_2

2024-12-03 22:39:18

DCF-173

58

CCM, CMMC, DORA, ISO27001, ISO270012022, ISO27701, NIST800171, NISTCSF2, SOC_2

2024-12-03 22:39:17

DCF-183

27

CCM, CCPA, CIS8, CMMC, CYBER_ESSENTIALS, CYBER_ESSENTIALS_32, DORA, DRATA_ESSENTIALS, FEDRAMP, FEDRAMP20X, GDPR, HIPAA, ISO27001, ISO270012022, ISO27701, NIS2, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, PCI, PCI4, SOC_2

2024-12-03 22:39:18

DCF-196

192, 193

HIPAA

2024-12-11 14:37:26

DCF-218

209

CIS8, CYBER_ESSENTIALS_32, DORA, FEDRAMP, NIS2, NIST80053, PCI, PCI4

2024-01-19 0:22:44

DCF-229

8020

CCM, CIS8, CYBER_ESSENTIALS, CYBER_ESSENTIALS_32, ISO270012022, ISO27701, NIST800171R3, NIST80053, PCI, PCI4

2024-01-19 0:22:44

DCF-285

263, 8006, 8015

CIS8, CMMC, DORA, NIST800171, NIST800171R3, NISTCSF2, PCI, PCI4

2024-12-11 14:45:49

DCF-326

208

CCM, CIS8, CMMC, CYBER_ESSENTIALS_32, DORA, FEDRAMP, ISO270012022, ISO27701, NIS2, NIST800171, NIST800171R3, NIST80053, NISTCSF2, PCI, PCI4, SOC_2

2024-07-11 20:02:42

DCF-330

8037

CCM, CCPA, CIS8, CMMC, DORA, FEDRAMP, FEDRAMP20X, ISO27701, NIS2, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, PCI

2024-07-11 20:02:42

DCF-335

229

CIS8, CMMC, CYBER_ESSENTIALS_32, FEDRAMP, NIST800171, NIST800171R3, NIST80053, PCI, PCI4

2025-04-23 21:45:31

DCF-346

215

CCM, CIS8, CYBER_ESSENTIALS, CYBER_ESSENTIALS_32, PCI, PCI4

2025-01-28 20:01:13

DCF-350

216

CMMC, CYBER_ESSENTIALS_32, ISO270012022, ISO27701, NIST800171, NIST800171R3, PCI, PCI4, SOC_2

2024-09-05 21:51:55

DCF-406

221, 224, 226, 243, 244, 245, 246, 247, 248, 249, 250, 251, 252, 256, 257, 310, 8005

CIS8, CMMC, DORA, FEDRAMP, ISO270012022, NIST800171, NIST800171R3, NIST80053, NISTCSF2, PCI, PCI4, SOC_2

2025-10-06 23:16:27

DCF-407

243, 244, 245, 246, 247, 248, 249, 250, 251, 252, 256

CIS8, CMMC, ISO270012022, ISO27701, ISO420012023, NIST800171, NIST800171R3, NIST80053, NISTCSF2, PCI, PCI4, SOC_2

2025-10-06 23:16:27

DCF-441

8019

CIS8, CMMC, DORA, ISO270012022, ISO27701, NIST800171, PCI, PCI4

2025-04-23 21:45:32

DCF-478

205

205, 8014

CCM, CMMC, DORA, FEDRAMP, ISO270012022, ISO270172015, ISO27701, NIST800171, NIST800171R3, NIST80053, NISTCSF, NISTCSF2, PCI, PCI4, SOC_2

2024-12-11 14:45:49

DCF-614

8034

CMMC, FEDRAMP, NIST800171, NIST80053

2024-09-05 21:51:55

Test Name Revisions

Expand to view Test Name Revisions

ID

Previous Name

Current Name

Last Updated

21

Records of Vulnerability Scans

Vulnerability Scanning

2025-08-28 22:48:37

38

Policies are Accepted by Employees

Policies are Acknowledged by Employees

2025-08-28 22:48:37

190

Policies are Accepted by Contractors

Policies are Acknowledged by Contractors

2025-08-28 22:48:37

45

Employees Accept the Acceptable Use Policy

Employees Acknowledge the Acceptable Use Policy

2025-08-28 22:48:37

48

Contractors Accept the Code of Conduct

Contractors Acknowledge The Code of Conduct

2025-08-28 22:48:37

49

Contractors Accept the Acceptable Use Policy

Contractors Acknowledge the Acceptable Use Policy

2025-08-28 22:48:37

55

Employees Accept the Code of Conduct

Employees Acknowledge the Code of Conduct

2025-08-28 22:48:37

57

Employees Accept the Data Protection Policy

Employees Acknowledge Data Protection Policy

2025-08-28 22:48:37

191

Contractors Accept the Data Protection Policy

Contractors Acknowledge the Data Protection Policy

2025-08-28 22:48:37

132

Daily backup job status monitored

Daily Backup Job Status Monitored

2025-08-28 22:48:37

205

CloudTrail log file integrity validation enabled

CloudTrail Log File Integrity Validation Enabled

2025-08-28 22:48:37

Test Description Revisions

Expand to view Test Description Revisions

ID

Previous Description

Current Description

Last Updated

21

Drata inspected %s's report from the latest vulnerability scan, which was performed within the last 3 months.

Drata validated that a vulnerability scanning system is connected to Drata.

2025-08-28 22:48:37

38

Drata inspected %s's policy records and confirmed that assigned employees have accepted them.

Drata inspected %s's policy records and confirmed that assigned employees have acknowledged them.

2025-08-28 22:48:37

190

Drata inspected %s's policy records and confirmed that assigned contractors have accepted them.

Drata inspected %s's policy records and confirmed that assigned contractors have acknowledged them.

2025-08-28 22:48:37

45

Drata inspected %s's records and confirmed that all employees have accepted the Acceptable Use Policy.

Drata inspected %s's records and confirmed that assigned employees have acknowledged the Acceptable Use Policy.

2025-08-28 22:48:37

48

Drata inspected %s's records and confirmed that assigned contractors have accepted the company's Code of Conduct.

Drata inspected %s's records and confirmed that assigned contractors have acknowledged the company's Code of Conduct.

2025-08-28 22:48:37

49

Drata inspected %s's records and confirmed that all contractors have accepted the company's Acceptable Use Policy.

Drata inspected %s's records and confirmed that all employees have acknowledged the Acceptable Use Policy.

2025-08-28 22:48:37

55

Drata inspected %s's records and confirmed that all employees have accepted the company's Code of Conduct upon hire.

Drata inspected %s's records and confirmed that assigned employees have acknowledged the company's Code of Conduct upon hire.

2025-08-28 22:48:37

57

Drata inspected %s's records and confirmed that all employees have accepted the company's Data Protection Policy upon hire.

%s has established a Data Protection Policy and requires assigned employees to acknowledge it upon hire. Management monitors employees' acknowledgement of the policy.

2025-08-28 22:48:37

191

%s has established a Data Protection Policy and requires all contractors to accept it. Management monitors contractors' acceptance of the policy.

Drata inspected %s's records and confirmed that all contractors have acknowledged the company's Data Protection Policy.

2025-08-28 22:48:37

205

Drata inspected %s's trails and confirmed that log file integrity validation is enabled for every trail.

Drata confirmed that AWS CloudTrail log validation is enabled on all trails.

2025-08-28 22:48:37

Download the revision logs

  • The control revision log is available in the file controls-diff.csv,

  • The test revision log can also be found in control-tests.csv.

Attachment icon
Attachment icon
Did this answer your question?