Knowledge is Power

Sitewide Search

Search Bare Metal Cyber

Search courses, individual lessons, wiki entries, books, podcasts, magazine articles, Daily Cyber News, and Darwin.

Cross-Framework Defense Map

Trace cybersecurity outcomes from risk to implementation.

Start with a NIST CSF 2.0 outcome, follow its informative references into NIST SP 800-53, then continue through CUI requirements, defensive techniques, adversary behavior, and practical learning resources.

NIST OLIR reference 186 · Relationship labels preserved · Inferred ATT&CK links clearly marked

Open the official informative reference ↗
One connected path

Move between outcomes, controls, defenses, and threats.

The layers do different jobs. The map preserves each relationship type instead of flattening them into a false equivalence or one-size-fits-all compliance chain.

01CSF outcome

What result matters?

02SP 800-53

What controls support it?

03CUI requirements

What applies to protected CUI?

04D3FEND

How can defenses work technically?

05ATT&CK

What adversary behavior is connected?

06Learn

Which book and audio resources go deeper?

Start with an outcome

Explore all 106 NIST CSF Subcategories.

Search by identifier, outcome, or topic. Each page explains the exact imported informative reference and the downstream relationships available in the local knowledge graph.

Detect

11 outcomes

DE.AE-02Analyze Potentially Adverse Events

Potentially adverse events are analyzed to better understand associated activities

4 mapped control references →
DE.AE-03Correlate Information from Multiple Sources

Information is correlated from multiple sources

7 mapped control references →
DE.AE-04Understand Event Impact and Scope

The estimated impact and scope of adverse events are understood

5 mapped control references →
DE.AE-06Provide Event Information to Authorized Staff and Tools

Information on adverse events is provided to authorized staff and tools

5 mapped control references →
DE.AE-07Integrate Threat Intelligence and Context

Cyber threat intelligence and other contextual information are integrated into the analysis

3 mapped control references →
DE.AE-08Declare Incidents Using Defined Criteria

Incidents are declared when adverse events meet the defined incident criteria

2 mapped control references →
DE.CM-01Monitor Networks and Network Services

Networks and network services are monitored to find potentially adverse events

7 mapped control references →
DE.CM-02Monitor the Physical Environment

The physical environment is monitored to find potentially adverse events

4 mapped control references →
DE.CM-03Monitor Personnel Activity and Technology Use

Personnel activity and technology usage are monitored to find potentially adverse events

6 mapped control references →
DE.CM-06Monitor External Service Providers

External service provider activities and services are monitored to find potentially adverse events

5 mapped control references →
DE.CM-09Monitor Computing and Runtime Environments

Computing hardware and software, runtime environments, and their data are monitored to find potentially adverse events

12 mapped control references →

Govern

31 outcomes

GV.OC-01Organizational Mission

The organizational mission is understood and informs cybersecurity risk management

1 mapped control references →
GV.OC-02Stakeholder Needs and Expectations

Internal and external stakeholders are understood, and their needs and expectations regarding cybersecurity risk management are understood

7 mapped control references →
GV.OC-03Legal, Regulatory, and Contractual Requirements

Legal, regulatory, and contractual requirements regarding cybersecurity — including privacy and civil liberties obligations — are understood and managed

21 mapped control references →
GV.OC-04External Stakeholder Dependencies

Critical objectives, capabilities, and services that external stakeholders depend on or expect from the organization are understood and communicated

5 mapped control references →
GV.OC-05Organizational Dependencies

Outcomes, capabilities, and services that the organization depends on are understood and communicated

5 mapped control references →
GV.OV-01Review Strategy Outcomes

Cybersecurity risk management strategy outcomes are reviewed to inform and adjust strategy and direction

26 mapped control references →
GV.OV-02Adjust Strategy Coverage

The cybersecurity risk management strategy is reviewed and adjusted to ensure coverage of organizational requirements and risks

6 mapped control references →
GV.OV-03Evaluate Cybersecurity Performance

Organizational cybersecurity risk management performance is evaluated and reviewed for adjustments needed

4 mapped control references →
GV.PO-01Establish and Enforce Cybersecurity Policy

Policy for managing cybersecurity risks is established based on organizational context, cybersecurity strategy, and priorities and is communicated and enforced

20 mapped control references →
GV.PO-02Review and Update Cybersecurity Policy

Policy for managing cybersecurity risks is reviewed, updated, communicated, and enforced to reflect changes in requirements, threats, technology, and organizational mission

20 mapped control references →
GV.RM-01Risk Management Objectives

Risk management objectives are established and agreed to by organizational stakeholders

3 mapped control references →
GV.RM-02Risk Appetite and Tolerance

Risk appetite and risk tolerance statements are established, communicated, and maintained

1 mapped control references →
GV.RM-03Cybersecurity in Enterprise Risk Management

Cybersecurity risk management activities and outcomes are included in enterprise risk management processes

6 mapped control references →
GV.RM-04Strategic Risk Response Direction

Strategic direction that describes appropriate risk response options is established and communicated

4 mapped control references →
GV.RM-05Cybersecurity Risk Communication

Lines of communication across the organization are established for cybersecurity risks, including risks from suppliers and other third parties

2 mapped control references →
GV.RM-06Standardized Risk Method

A standardized method for calculating, documenting, categorizing, and prioritizing cybersecurity risks is established and communicated

5 mapped control references →
GV.RM-07Strategic Opportunities

Strategic opportunities — positive risks — are characterized and are included in organizational cybersecurity risk discussions

5 mapped control references →
GV.RR-01Leadership Accountability and Risk-Aware Culture

Organizational leadership is responsible and accountable for cybersecurity risk and fosters a culture that is risk-aware, ethical, and continually improving

5 mapped control references →
GV.RR-02Roles, Responsibilities, and Authorities

Roles, responsibilities, and authorities related to cybersecurity risk management are established, communicated, understood, and enforced

6 mapped control references →
GV.RR-03Risk-Commensurate Resources

Adequate resources are allocated commensurate with the cybersecurity risk strategy, roles, responsibilities, and policies

1 mapped control references →
GV.RR-04Cybersecurity in Human Resources

Cybersecurity is included in human resources practices

4 mapped control references →
GV.SC-01C-SCRM Program and Strategy

A cybersecurity supply chain risk management program, strategy, objectives, policies, and processes are established and agreed to by organizational stakeholders

3 mapped control references →
GV.SC-02Supply Chain Roles and Responsibilities

Cybersecurity roles and responsibilities for suppliers, customers, and partners are established, communicated, and coordinated internally and externally

3 mapped control references →
GV.SC-03Integrate C-SCRM with Risk Management

Cybersecurity supply chain risk management is integrated into cybersecurity and enterprise risk management, risk assessment, and improvement processes

28 mapped control references →
GV.SC-04Prioritize Suppliers by Criticality

Suppliers are known and prioritized by criticality

3 mapped control references →
GV.SC-05Supply Chain Requirements in Agreements

Requirements to address cybersecurity risks in supply chains are established, prioritized, and integrated into contracts and other types of agreements with suppliers and other relevant third parties

6 mapped control references →
GV.SC-06Supplier Due Diligence

Planning and due diligence are performed to reduce risks before entering into formal supplier or other third-party relationships

4 mapped control references →
GV.SC-07Monitor Supplier and Third-Party Risk

The risks posed by a supplier, their products and services, and other third parties are understood, recorded, prioritized, assessed, responded to, and monitored over the course of the relationship

5 mapped control references →
GV.SC-08Include Suppliers in Incident Activities

Relevant suppliers and other third parties are included in incident planning, response, and recovery activities

7 mapped control references →
GV.SC-09Life-Cycle Supply Chain Security

Supply chain security practices are integrated into cybersecurity and enterprise risk management programs, and their performance is monitored throughout the technology product and service life cycle

13 mapped control references →
GV.SC-10Post-Relationship Supply Chain Provisions

Cybersecurity supply chain risk management plans include provisions for activities that occur after the conclusion of a partnership or service agreement

10 mapped control references →

Identify

21 outcomes

ID.AM-01Hardware Inventories

Inventories of hardware managed by the organization are maintained

2 mapped control references →
ID.AM-02Software, Service, and System Inventories

Inventories of software, services, and systems managed by the organization are maintained

5 mapped control references →
ID.AM-03Network Communication and Data Flow Representations

Representations of the organization’s authorized network communication and internal and external network data flows are maintained

6 mapped control references →
ID.AM-04Supplier-Provided Service Inventories

Inventories of services provided by suppliers are maintained

3 mapped control references →
ID.AM-05Asset Prioritization

Assets are prioritized based on classification, criticality, resources, and impact on the mission

3 mapped control references →
ID.AM-07Data and Metadata Inventories

Inventories of data and corresponding metadata for designated data types are maintained

3 mapped control references →
ID.AM-08Asset Life-Cycle Management

Systems, hardware, software, services, and data are managed throughout their life cycles

15 mapped control references →
ID.IM-01Improvements from Evaluations

Improvements are identified from evaluations

37 mapped control references →
ID.IM-02Improvements from Tests and Exercises

Improvements are identified from security tests and exercises, including those done in coordination with suppliers and relevant third parties

40 mapped control references →
ID.IM-03Improvements from Operations

Improvements are identified from execution of operational processes, procedures, and activities

39 mapped control references →
ID.IM-04Improve Incident Response and Cybersecurity Plans

Incident response plans and other cybersecurity plans that affect operations are established, communicated, maintained, and improved

4 mapped control references →
ID.RA-01Identify and Record Vulnerabilities

Vulnerabilities in assets are identified, validated, and recorded

10 mapped control references →
ID.RA-02Receive Cyber Threat Intelligence

Cyber threat intelligence is received from information sharing forums and sources

3 mapped control references →
ID.RA-03Identify Internal and External Threats

Internal and external threats to the organization are identified and recorded

4 mapped control references →
ID.RA-04Estimate Threat Likelihood and Impact

Potential impacts and likelihoods of threats exploiting vulnerabilities are identified and recorded

6 mapped control references →
ID.RA-05Understand Inherent Risk

Threats, vulnerabilities, likelihoods, and impacts are used to understand inherent risk and inform risk response prioritization

4 mapped control references →
ID.RA-06Select and Track Risk Responses

Risk responses are chosen, prioritized, planned, tracked, and communicated

4 mapped control references →
ID.RA-07Manage Changes and Exceptions

Changes and exceptions are managed, assessed for risk impact, recorded, and tracked

3 mapped control references →
ID.RA-08Vulnerability Disclosure Processes

Processes are established for receiving, analyzing, and responding to vulnerability disclosures

1 mapped control references →
ID.RA-09Assess Hardware and Software Authenticity

The authenticity and integrity of hardware and software are assessed prior to acquisition and use

11 mapped control references →
ID.RA-10Assess Critical Suppliers Before Acquisition

Critical suppliers are assessed prior to acquisition

1 mapped control references →

Protect

22 outcomes

PR.AA-01Manage Identities and Credentials

Identities and credentials for authorized users, services, and hardware are managed by the organization

14 mapped control references →
PR.AA-02Identity Proofing and Credential Binding

Identities are proofed and bound to credentials based on the context of interactions

1 mapped control references →
PR.AA-03Authenticate Users, Services, and Hardware

Users, services, and hardware are authenticated

10 mapped control references →
PR.AA-04Protect and Verify Identity Assertions

Identity assertions are protected, conveyed, and verified

1 mapped control references →
PR.AA-05Manage Permissions and Authorizations

Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties

12 mapped control references →
PR.AA-06Risk-Based Physical Access

Physical access to assets is managed, monitored, and enforced commensurate with risk

9 mapped control references →
PR.AT-01General Cybersecurity Awareness and Training

Personnel are provided with awareness and training so that they possess the knowledge and skills to perform general tasks with cybersecurity risks in mind

2 mapped control references →
PR.AT-02Specialized Role Training

Individuals in specialized roles are provided with awareness and training so that they possess the knowledge and skills to perform relevant tasks with cybersecurity risks in mind

1 mapped control references →
PR.DS-01Protect Data at Rest

The confidentiality, integrity, and availability of data-at-rest are protected

14 mapped control references →
PR.DS-02Protect Data in Transit

The confidentiality, integrity, and availability of data-in-transit are protected

14 mapped control references →
PR.DS-10Protect Data in Use

The confidentiality, integrity, and availability of data-in-use are protected

22 mapped control references →
PR.DS-11Create, Protect, Maintain, and Test Backups

Backups of data are created, protected, maintained, and tested

2 mapped control references →
PR.IR-01Protect Networks and Environments

Networks and environments are protected from unauthorized logical access and usage

5 mapped control references →
PR.IR-02Protect Technology from Environmental Threats

The organization’s technology assets are protected from environmental threats

10 mapped control references →
PR.IR-03Resilience Mechanisms

Mechanisms are implemented to achieve resilience requirements in normal and adverse situations

7 mapped control references →
PR.IR-04Maintain Resource Capacity

Adequate resource capacity to ensure availability is maintained

5 mapped control references →
PR.PS-01Configuration Management

Configuration management practices are established and applied

11 mapped control references →
PR.PS-02Software Maintenance and Removal

Software is maintained, replaced, and removed commensurate with risk

5 mapped control references →
PR.PS-03Hardware Maintenance and Removal

Hardware is maintained, replaced, and removed commensurate with risk

6 mapped control references →
PR.PS-04Generate and Provide Log Records

Log records are generated and made available for continuous monitoring

7 mapped control references →
PR.PS-05Prevent Unauthorized Software

Installation and execution of unauthorized software are prevented

4 mapped control references →
PR.PS-06Secure Software Development

Secure software development practices are integrated, and their performance is monitored throughout the software development life cycle

8 mapped control references →

Recover

8 outcomes

Respond

13 outcomes

RS.AN-03Establish Incident Facts and Root Cause

Analysis is performed to establish what has taken place during an incident and the root cause of the incident

3 mapped control references →
RS.AN-06Preserve Investigation Action Records

Actions performed during an investigation are recorded, and the records’ integrity and provenance are preserved

3 mapped control references →
RS.AN-07Preserve Incident Data and Metadata

Incident data and metadata are collected, and their integrity and provenance are preserved

3 mapped control references →
RS.AN-08Estimate and Validate Incident Magnitude

An incident’s magnitude is estimated and validated

4 mapped control references →
RS.CO-02Notify Stakeholders

Internal and external stakeholders are notified of incidents

5 mapped control references →
RS.CO-03Share Incident Information

Information is shared with designated internal and external stakeholders

5 mapped control references →
RS.MA-01Execute the Incident Response Plan

The incident response plan is executed in coordination with relevant third parties once an incident is declared

5 mapped control references →
RS.MA-02Triage and Validate Incident Reports

Incident reports are triaged and validated

3 mapped control references →
RS.MA-03Categorize and Prioritize Incidents

Incidents are categorized and prioritized

3 mapped control references →
RS.MA-04Escalate or Elevate Incidents

Incidents are escalated or elevated as needed

4 mapped control references →
RS.MA-05Apply Recovery Initiation Criteria

The criteria for initiating incident recovery are applied

2 mapped control references →
RS.MI-01Contain Incidents

Incidents are contained

1 mapped control references →
RS.MI-02Eradicate Incidents

Incidents are eradicated

1 mapped control references →
Start with a control

Open any SP 800-53 control in the map.

Use the control view when implementation or assessment work is already organized around SP 800-53 and you need to trace outcomes, CUI requirements, D3FEND techniques, and ATT&CK relationships.

AC-1Policy and Procedures

Access Control

10 linked CSF outcome references →
AC-10Concurrent Session Control

Access Control

1 linked CSF outcome references →
AC-11Device Lock

Access Control

0 linked CSF outcome references →
AC-12Session Termination

Access Control

1 linked CSF outcome references →
AC-13Supervision and Review — Access Control

Access Control

0 linked CSF outcome references →
AC-14Permitted Actions Without Identification or Authentication

Access Control

1 linked CSF outcome references →
AC-15Automated Marking

Access Control

0 linked CSF outcome references →
AC-16Security and Privacy Attributes

Access Control

1 linked CSF outcome references →
AC-17Remote Access

Access Control

1 linked CSF outcome references →
AC-18Wireless Access

Access Control

1 linked CSF outcome references →
AC-19Access Control for Mobile Devices

Access Control

1 linked CSF outcome references →
AC-2Account Management

Access Control

5 linked CSF outcome references →
AC-20Use of External Systems

Access Control

2 linked CSF outcome references →
AC-21Information Sharing

Access Control

0 linked CSF outcome references →
AC-22Publicly Accessible Content

Access Control

0 linked CSF outcome references →
AC-23Data Mining Protection

Access Control

0 linked CSF outcome references →
AC-24Access Control Decisions

Access Control

1 linked CSF outcome references →
AC-25Reference Monitor

Access Control

0 linked CSF outcome references →
AC-3Access Enforcement

Access Control

3 linked CSF outcome references →
AC-4Information Flow Enforcement

Access Control

4 linked CSF outcome references →
AC-5Separation of Duties

Access Control

1 linked CSF outcome references →
AC-6Least Privilege

Access Control

1 linked CSF outcome references →
AC-7Unsuccessful Logon Attempts

Access Control

1 linked CSF outcome references →
AC-8System Use Notification

Access Control

0 linked CSF outcome references →
AC-9Previous Logon Notification

Access Control

1 linked CSF outcome references →
AT-1Policy and Procedures

Awareness and Training

8 linked CSF outcome references →
AT-2Literacy Training and Awareness

Awareness and Training

1 linked CSF outcome references →
AT-3Role-based Training

Awareness and Training

2 linked CSF outcome references →
AT-4Training Records

Awareness and Training

0 linked CSF outcome references →
AT-5Contacts with Security Groups and Associations

Awareness and Training

0 linked CSF outcome references →
AT-6Training Feedback

Awareness and Training

0 linked CSF outcome references →
AU-1Policy and Procedures

Audit and Accountability

8 linked CSF outcome references →
AU-10Non-repudiation

Audit and Accountability

0 linked CSF outcome references →
AU-11Audit Record Retention

Audit and Accountability

1 linked CSF outcome references →
AU-12Audit Record Generation

Audit and Accountability

4 linked CSF outcome references →
AU-13Monitoring for Information Disclosure

Audit and Accountability

2 linked CSF outcome references →
AU-14Session Audit

Audit and Accountability

0 linked CSF outcome references →
AU-15Alternate Audit Logging Capability

Audit and Accountability

0 linked CSF outcome references →
AU-16Cross-organizational Audit Logging

Audit and Accountability

1 linked CSF outcome references →
AU-2Event Logging

Audit and Accountability

1 linked CSF outcome references →
AU-3Content of Audit Records

Audit and Accountability

1 linked CSF outcome references →
AU-4Audit Log Storage Capacity

Audit and Accountability

0 linked CSF outcome references →
AU-5Response to Audit Logging Process Failures

Audit and Accountability

0 linked CSF outcome references →
AU-6Audit Record Review, Analysis, and Reporting

Audit and Accountability

3 linked CSF outcome references →
AU-7Audit Record Reduction and Report Generation

Audit and Accountability

4 linked CSF outcome references →
AU-8Time Stamps

Audit and Accountability

0 linked CSF outcome references →
AU-9Protection of Audit Information

Audit and Accountability

1 linked CSF outcome references →
CA-1Policy and Procedures

Assessment, Authorization, and Monitoring

8 linked CSF outcome references →
CA-2Control Assessments

Assessment, Authorization, and Monitoring

4 linked CSF outcome references →
CA-3Information Exchange

Assessment, Authorization, and Monitoring

4 linked CSF outcome references →
CA-4Security Certification

Assessment, Authorization, and Monitoring

0 linked CSF outcome references →
CA-5Plan of Action and Milestones

Assessment, Authorization, and Monitoring

3 linked CSF outcome references →
CA-6Authorization

Assessment, Authorization, and Monitoring

0 linked CSF outcome references →
CA-7Continuous Monitoring

Assessment, Authorization, and Monitoring

12 linked CSF outcome references →
CA-8Penetration Testing

Assessment, Authorization, and Monitoring

4 linked CSF outcome references →
CA-9Internal System Connections

Assessment, Authorization, and Monitoring

1 linked CSF outcome references →
CM-1Policy and Procedures

Configuration Management

9 linked CSF outcome references →
CM-10Software Usage Restrictions

Configuration Management

3 linked CSF outcome references →
CM-11User-installed Software

Configuration Management

4 linked CSF outcome references →
CM-12Information Location

Configuration Management

1 linked CSF outcome references →
CM-13Data Action Mapping

Configuration Management

2 linked CSF outcome references →
CM-14Signed Components

Configuration Management

0 linked CSF outcome references →
CM-2Baseline Configuration

Configuration Management

1 linked CSF outcome references →
CM-3Configuration Change Control

Configuration Management

4 linked CSF outcome references →
CM-4Impact Analyses

Configuration Management

2 linked CSF outcome references →
CM-5Access Restrictions for Change

Configuration Management

1 linked CSF outcome references →
CM-6Configuration Settings

Configuration Management

2 linked CSF outcome references →
CM-7Least Functionality

Configuration Management

5 linked CSF outcome references →
CM-8System Component Inventory

Configuration Management

3 linked CSF outcome references →
CM-9Configuration Management Plan

Configuration Management

2 linked CSF outcome references →
CP-1Policy and Procedures

Contingency Planning

9 linked CSF outcome references →
CP-10System Recovery and Reconstitution

Contingency Planning

3 linked CSF outcome references →
CP-11Alternate Communications Protocols

Contingency Planning

0 linked CSF outcome references →
CP-12Safe Mode

Contingency Planning

0 linked CSF outcome references →
CP-13Alternative Security Mechanisms

Contingency Planning

0 linked CSF outcome references →
CP-2Contingency Plan

Contingency Planning

8 linked CSF outcome references →
CP-3Contingency Training

Contingency Planning

0 linked CSF outcome references →
CP-4Contingency Plan Testing

Contingency Planning

2 linked CSF outcome references →
CP-5Contingency Plan Update

Contingency Planning

0 linked CSF outcome references →
CP-6Alternate Storage Site

Contingency Planning

2 linked CSF outcome references →
CP-7Alternate Processing Site

Contingency Planning

1 linked CSF outcome references →
CP-8Telecommunications Services

Contingency Planning

1 linked CSF outcome references →
CP-9System Backup

Contingency Planning

4 linked CSF outcome references →
IA-1Policy and Procedures

Identification and Authentication

9 linked CSF outcome references →
IA-10Adaptive Authentication

Identification and Authentication

2 linked CSF outcome references →
IA-11Re-authentication

Identification and Authentication

2 linked CSF outcome references →
IA-12Identity Proofing

Identification and Authentication

1 linked CSF outcome references →
IA-13Identity Providers and Authorization Servers

Identification and Authentication

2 linked CSF outcome references →
IA-2Identification and Authentication (Organizational Users)

Identification and Authentication

2 linked CSF outcome references →
IA-3Device Identification and Authentication

Identification and Authentication

2 linked CSF outcome references →
IA-4Identifier Management

Identification and Authentication

1 linked CSF outcome references →
IA-5Authenticator Management

Identification and Authentication

2 linked CSF outcome references →
IA-6Authentication Feedback

Identification and Authentication

1 linked CSF outcome references →
IA-7Cryptographic Module Authentication

Identification and Authentication

2 linked CSF outcome references →
IA-8Identification and Authentication (Non-organizational Users)

Identification and Authentication

2 linked CSF outcome references →
IA-9Service Identification and Authentication

Identification and Authentication

2 linked CSF outcome references →
IR-1Policy and Procedures

Incident Response

10 linked CSF outcome references →
IR-10Integrated Information Security Analysis Team

Incident Response

0 linked CSF outcome references →
IR-2Incident Response Training

Incident Response

0 linked CSF outcome references →
IR-3Incident Response Testing

Incident Response

1 linked CSF outcome references →
IR-4Incident Handling

Incident Response

24 linked CSF outcome references →
IR-5Incident Monitoring

Incident Response

4 linked CSF outcome references →
IR-6Incident Reporting

Incident Response

9 linked CSF outcome references →
IR-7Incident Response Assistance

Incident Response

4 linked CSF outcome references →
IR-8Incident Response Plan

Incident Response

13 linked CSF outcome references →
IR-9Information Spillage Response

Incident Response

0 linked CSF outcome references →
MA-1Policy and Procedures

Maintenance

8 linked CSF outcome references →
MA-2Controlled Maintenance

Maintenance

1 linked CSF outcome references →
MA-3Maintenance Tools

Maintenance

1 linked CSF outcome references →
MA-4Nonlocal Maintenance

Maintenance

0 linked CSF outcome references →
MA-5Maintenance Personnel

Maintenance

0 linked CSF outcome references →
MA-6Timely Maintenance

Maintenance

1 linked CSF outcome references →
MA-7Field Maintenance

Maintenance

0 linked CSF outcome references →
MP-1Policy and Procedures

Media Protection

8 linked CSF outcome references →
MP-2Media Access

Media Protection

0 linked CSF outcome references →
MP-3Media Marking

Media Protection

0 linked CSF outcome references →
MP-4Media Storage

Media Protection

0 linked CSF outcome references →
MP-5Media Transport

Media Protection

0 linked CSF outcome references →
MP-6Media Sanitization

Media Protection

0 linked CSF outcome references →
MP-7Media Use

Media Protection

0 linked CSF outcome references →
MP-8Media Downgrading

Media Protection

1 linked CSF outcome references →
PE-1Policy and Procedures

Physical and Environmental Protection

8 linked CSF outcome references →
PE-10Emergency Shutoff

Physical and Environmental Protection

1 linked CSF outcome references →
PE-11Emergency Power

Physical and Environmental Protection

1 linked CSF outcome references →
PE-12Emergency Lighting

Physical and Environmental Protection

1 linked CSF outcome references →
PE-13Fire Protection

Physical and Environmental Protection

1 linked CSF outcome references →
PE-14Environmental Controls

Physical and Environmental Protection

1 linked CSF outcome references →
PE-15Water Damage Protection

Physical and Environmental Protection

1 linked CSF outcome references →
PE-16Delivery and Removal

Physical and Environmental Protection

0 linked CSF outcome references →
PE-17Alternate Work Site

Physical and Environmental Protection

0 linked CSF outcome references →
PE-18Location of System Components

Physical and Environmental Protection

2 linked CSF outcome references →
PE-19Information Leakage

Physical and Environmental Protection

1 linked CSF outcome references →
PE-2Physical Access Authorizations

Physical and Environmental Protection

1 linked CSF outcome references →
PE-20Asset Monitoring and Tracking

Physical and Environmental Protection

2 linked CSF outcome references →
PE-21Electromagnetic Pulse Protection

Physical and Environmental Protection

0 linked CSF outcome references →
PE-22Component Marking

Physical and Environmental Protection

0 linked CSF outcome references →
PE-23Facility Location

Physical and Environmental Protection

1 linked CSF outcome references →
PE-3Physical Access Control

Physical and Environmental Protection

2 linked CSF outcome references →
PE-4Access Control for Transmission

Physical and Environmental Protection

1 linked CSF outcome references →
PE-5Access Control for Output Devices

Physical and Environmental Protection

1 linked CSF outcome references →
PE-6Monitoring Physical Access

Physical and Environmental Protection

2 linked CSF outcome references →
PE-7Visitor Control

Physical and Environmental Protection

0 linked CSF outcome references →
PE-8Visitor Access Records

Physical and Environmental Protection

1 linked CSF outcome references →
PE-9Power Equipment and Cabling

Physical and Environmental Protection

1 linked CSF outcome references →
PL-1Policy and Procedures

Planning

8 linked CSF outcome references →
PL-10Baseline Selection

Planning

0 linked CSF outcome references →
PL-11Baseline Tailoring

Planning

0 linked CSF outcome references →
PL-2System Security and Privacy Plans

Planning

6 linked CSF outcome references →
PL-3System Security Plan Update

Planning

0 linked CSF outcome references →
PL-4Rules of Behavior

Planning

0 linked CSF outcome references →
PL-5Privacy Impact Assessment

Planning

0 linked CSF outcome references →
PL-6Security-related Activity Planning

Planning

0 linked CSF outcome references →
PL-7Concept of Operations

Planning

0 linked CSF outcome references →
PL-8Security and Privacy Architectures

Planning

1 linked CSF outcome references →
PL-9Central Management

Planning

0 linked CSF outcome references →
PM-1Information Security Program Plan

Program Management

8 linked CSF outcome references →
PM-10Authorization Process

Program Management

0 linked CSF outcome references →
PM-11Mission and Business Process Definition

Program Management

6 linked CSF outcome references →
PM-12Insider Threat Program

Program Management

1 linked CSF outcome references →
PM-13Security and Privacy Workforce

Program Management

2 linked CSF outcome references →
PM-14Testing, Training, and Monitoring

Program Management

0 linked CSF outcome references →
PM-15Security and Privacy Groups and Associations

Program Management

2 linked CSF outcome references →
PM-16Threat Awareness Program

Program Management

6 linked CSF outcome references →
PM-17Protecting Controlled Unclassified Information on External Systems

Program Management

0 linked CSF outcome references →
PM-18Privacy Program Plan

Program Management

7 linked CSF outcome references →
PM-19Privacy Program Leadership Role

Program Management

4 linked CSF outcome references →
PM-2Information Security Program Leadership Role

Program Management

2 linked CSF outcome references →
PM-20Dissemination of Privacy Program Information

Program Management

0 linked CSF outcome references →
PM-21Accounting of Disclosures

Program Management

0 linked CSF outcome references →
PM-22Personally Identifiable Information Quality Management

Program Management

1 linked CSF outcome references →
PM-23Data Governance Body

Program Management

3 linked CSF outcome references →
PM-24Data Integrity Board

Program Management

2 linked CSF outcome references →
PM-25Minimization of Personally Identifiable Information Used in Testing, Training, and Research

Program Management

0 linked CSF outcome references →
PM-26Complaint Management

Program Management

0 linked CSF outcome references →
PM-27Privacy Reporting

Program Management

0 linked CSF outcome references →
PM-28Risk Framing

Program Management

6 linked CSF outcome references →
PM-29Risk Management Program Leadership Roles

Program Management

2 linked CSF outcome references →
PM-3Information Security and Privacy Resources

Program Management

3 linked CSF outcome references →
PM-30Supply Chain Risk Management Strategy

Program Management

15 linked CSF outcome references →
PM-31Continuous Monitoring Strategy

Program Management

7 linked CSF outcome references →
PM-32Purposing

Program Management

0 linked CSF outcome references →
PM-4Plan of Action and Milestones Process

Program Management

3 linked CSF outcome references →
PM-5System Inventory

Program Management

2 linked CSF outcome references →
PM-6Measures of Performance

Program Management

1 linked CSF outcome references →
PM-7Enterprise Architecture

Program Management

1 linked CSF outcome references →
PM-8Critical Infrastructure Plan

Program Management

2 linked CSF outcome references →
PM-9Risk Management Strategy

Program Management

17 linked CSF outcome references →
PS-1Policy and Procedures

Personnel Security

9 linked CSF outcome references →
PS-2Position Risk Designation

Personnel Security

0 linked CSF outcome references →
PS-3Personnel Screening

Personnel Security

0 linked CSF outcome references →
PS-4Personnel Termination

Personnel Security

0 linked CSF outcome references →
PS-5Personnel Transfer

Personnel Security

0 linked CSF outcome references →
PS-6Access Agreements

Personnel Security

0 linked CSF outcome references →
PS-7External Personnel Security

Personnel Security

2 linked CSF outcome references →
PS-8Personnel Sanctions

Personnel Security

0 linked CSF outcome references →
PS-9Position Descriptions

Personnel Security

1 linked CSF outcome references →
PT-1Policy and Procedures

Personally Identifiable Information Processing and Transparency

8 linked CSF outcome references →
PT-2Authority to Process Personally Identifiable Information

Personally Identifiable Information Processing and Transparency

0 linked CSF outcome references →
PT-3Personally Identifiable Information Processing Purposes

Personally Identifiable Information Processing and Transparency

0 linked CSF outcome references →
PT-4Consent

Personally Identifiable Information Processing and Transparency

0 linked CSF outcome references →
PT-5Privacy Notice

Personally Identifiable Information Processing and Transparency

0 linked CSF outcome references →
PT-6System of Records Notice

Personally Identifiable Information Processing and Transparency

0 linked CSF outcome references →
PT-7Specific Categories of Personally Identifiable Information

Personally Identifiable Information Processing and Transparency

0 linked CSF outcome references →
PT-8Computer Matching Requirements

Personally Identifiable Information Processing and Transparency

0 linked CSF outcome references →
RA-1Policy and Procedures

Risk Assessment

8 linked CSF outcome references →
RA-10Threat Hunting

Risk Assessment

2 linked CSF outcome references →
RA-2Security Categorization

Risk Assessment

3 linked CSF outcome references →
RA-3Risk Assessment

Risk Assessment

15 linked CSF outcome references →
RA-4Risk Assessment Update

Risk Assessment

1 linked CSF outcome references →
RA-5Vulnerability Monitoring and Scanning

Risk Assessment

6 linked CSF outcome references →
RA-6Technical Surveillance Countermeasures Survey

Risk Assessment

0 linked CSF outcome references →
RA-7Risk Response

Risk Assessment

15 linked CSF outcome references →
RA-8Privacy Impact Assessments

Risk Assessment

1 linked CSF outcome references →
RA-9Criticality Analysis

Risk Assessment

5 linked CSF outcome references →
SA-1Policy and Procedures

System and Services Acquisition

8 linked CSF outcome references →
SA-10Developer Configuration Management

System and Services Acquisition

4 linked CSF outcome references →
SA-11Developer Testing and Evaluation

System and Services Acquisition

6 linked CSF outcome references →
SA-12Supply Chain Protection

System and Services Acquisition

0 linked CSF outcome references →
SA-13Trustworthiness

System and Services Acquisition

0 linked CSF outcome references →
SA-14Criticality Analysis

System and Services Acquisition

0 linked CSF outcome references →
SA-15Development Process, Standards, and Tools

System and Services Acquisition

6 linked CSF outcome references →
SA-16Developer-provided Training

System and Services Acquisition

0 linked CSF outcome references →
SA-17Developer Security and Privacy Architecture and Design

System and Services Acquisition

3 linked CSF outcome references →
SA-18Tamper Resistance and Detection

System and Services Acquisition

0 linked CSF outcome references →
SA-19Component Authenticity

System and Services Acquisition

0 linked CSF outcome references →
SA-2Allocation of Resources

System and Services Acquisition

0 linked CSF outcome references →
SA-20Customized Development of Critical Components

System and Services Acquisition

0 linked CSF outcome references →
SA-21Developer Screening

System and Services Acquisition

0 linked CSF outcome references →
SA-22Unsupported System Components

System and Services Acquisition

1 linked CSF outcome references →
SA-23Specialization

System and Services Acquisition

0 linked CSF outcome references →
SA-24Design For Cyber Resiliency

System and Services Acquisition

3 linked CSF outcome references →
SA-3System Development Life Cycle

System and Services Acquisition

2 linked CSF outcome references →
SA-4Acquisition Process

System and Services Acquisition

10 linked CSF outcome references →
SA-5System Documentation

System and Services Acquisition

2 linked CSF outcome references →
SA-6Software Usage Restrictions

System and Services Acquisition

0 linked CSF outcome references →
SA-7User-installed Software

System and Services Acquisition

0 linked CSF outcome references →
SA-8Security and Privacy Engineering Principles

System and Services Acquisition

7 linked CSF outcome references →
SA-9External System Services

System and Services Acquisition

11 linked CSF outcome references →
SC-1Policy and Procedures

System and Communications Protection

8 linked CSF outcome references →
SC-10Network Disconnect

System and Communications Protection

0 linked CSF outcome references →
SC-11Trusted Path

System and Communications Protection

2 linked CSF outcome references →
SC-12Cryptographic Key Establishment and Management

System and Communications Protection

2 linked CSF outcome references →
SC-13Cryptographic Protection

System and Communications Protection

3 linked CSF outcome references →
SC-14Public Access Protections

System and Communications Protection

0 linked CSF outcome references →
SC-15Collaborative Computing Devices and Applications

System and Communications Protection

0 linked CSF outcome references →
SC-16Transmission of Security and Privacy Attributes

System and Communications Protection

1 linked CSF outcome references →
SC-17Public Key Infrastructure Certificates

System and Communications Protection

0 linked CSF outcome references →
SC-18Mobile Code

System and Communications Protection

0 linked CSF outcome references →
SC-19Voice Over Internet Protocol

System and Communications Protection

0 linked CSF outcome references →
SC-2Separation of System and User Functionality

System and Communications Protection

0 linked CSF outcome references →
SC-20Secure Name/Address Resolution Service (Authoritative Source)

System and Communications Protection

0 linked CSF outcome references →
SC-21Secure Name/Address Resolution Service (Recursive or Caching Resolver)

System and Communications Protection

0 linked CSF outcome references →
SC-22Architecture and Provisioning for Name/Address Resolution Service

System and Communications Protection

0 linked CSF outcome references →
SC-23Session Authenticity

System and Communications Protection

0 linked CSF outcome references →
SC-24Fail in Known State

System and Communications Protection

2 linked CSF outcome references →
SC-25Thin Nodes

System and Communications Protection

0 linked CSF outcome references →
SC-26Decoys

System and Communications Protection

0 linked CSF outcome references →
SC-27Platform-independent Applications

System and Communications Protection

0 linked CSF outcome references →
SC-28Protection of Information at Rest

System and Communications Protection

1 linked CSF outcome references →
SC-29Heterogeneity

System and Communications Protection

0 linked CSF outcome references →
SC-3Security Function Isolation

System and Communications Protection

1 linked CSF outcome references →
SC-30Concealment and Misdirection

System and Communications Protection

0 linked CSF outcome references →
SC-31Covert Channel Analysis

System and Communications Protection

0 linked CSF outcome references →
SC-32System Partitioning

System and Communications Protection

2 linked CSF outcome references →
SC-33Transmission Preparation Integrity

System and Communications Protection

0 linked CSF outcome references →
SC-34Non-modifiable Executable Programs

System and Communications Protection

2 linked CSF outcome references →
SC-35External Malicious Code Identification

System and Communications Protection

1 linked CSF outcome references →
SC-36Distributed Processing and Storage

System and Communications Protection

1 linked CSF outcome references →
SC-37Out-of-band Channels

System and Communications Protection

0 linked CSF outcome references →
SC-38Operations Security

System and Communications Protection

0 linked CSF outcome references →
SC-39Process Isolation

System and Communications Protection

4 linked CSF outcome references →
SC-4Information in Shared System Resources

System and Communications Protection

4 linked CSF outcome references →
SC-40Wireless Link Protection

System and Communications Protection

2 linked CSF outcome references →
SC-41Port and I/O Device Access

System and Communications Protection

0 linked CSF outcome references →
SC-42Sensor Capability and Data

System and Communications Protection

0 linked CSF outcome references →
SC-43Usage Restrictions

System and Communications Protection

3 linked CSF outcome references →
SC-44Detonation Chambers

System and Communications Protection

0 linked CSF outcome references →
SC-45System Time Synchronization

System and Communications Protection

0 linked CSF outcome references →
SC-46Cross Domain Policy Enforcement

System and Communications Protection

0 linked CSF outcome references →
SC-47Alternate Communications Paths

System and Communications Protection

0 linked CSF outcome references →
SC-48Sensor Relocation

System and Communications Protection

0 linked CSF outcome references →
SC-49Hardware-enforced Separation and Policy Enforcement

System and Communications Protection

1 linked CSF outcome references →
SC-5Denial-of-service Protection

System and Communications Protection

2 linked CSF outcome references →
SC-50Software-enforced Separation and Policy Enforcement

System and Communications Protection

0 linked CSF outcome references →
SC-51Hardware-based Protection

System and Communications Protection

1 linked CSF outcome references →
SC-6Resource Availability

System and Communications Protection

1 linked CSF outcome references →
SC-7Boundary Protection

System and Communications Protection

5 linked CSF outcome references →
SC-8Transmission Confidentiality and Integrity

System and Communications Protection

1 linked CSF outcome references →
SC-9Transmission Confidentiality

System and Communications Protection

0 linked CSF outcome references →
SI-1Policy and Procedures

System and Information Integrity

8 linked CSF outcome references →
SI-10Information Input Validation

System and Information Integrity

1 linked CSF outcome references →
SI-11Error Handling

System and Information Integrity

0 linked CSF outcome references →
SI-12Information Management and Retention

System and Information Integrity

2 linked CSF outcome references →
SI-13Predictable Failure Prevention

System and Information Integrity

1 linked CSF outcome references →
SI-14Non-persistence

System and Information Integrity

0 linked CSF outcome references →
SI-15Information Output Filtering

System and Information Integrity

0 linked CSF outcome references →
SI-16Memory Protection

System and Information Integrity

1 linked CSF outcome references →
SI-17Fail-safe Procedures

System and Information Integrity

0 linked CSF outcome references →
SI-18Personally Identifiable Information Quality Operations

System and Information Integrity

1 linked CSF outcome references →
SI-19De-identification

System and Information Integrity

0 linked CSF outcome references →
SI-2Flaw Remediation

System and Information Integrity

5 linked CSF outcome references →
SI-20Tainting

System and Information Integrity

0 linked CSF outcome references →
SI-21Information Refresh

System and Information Integrity

0 linked CSF outcome references →
SI-22Information Diversity

System and Information Integrity

0 linked CSF outcome references →
SI-23Information Fragmentation

System and Information Integrity

0 linked CSF outcome references →
SI-3Malicious Code Protection

System and Information Integrity

3 linked CSF outcome references →
SI-4System Monitoring

System and Information Integrity

12 linked CSF outcome references →
SI-5Security Alerts, Advisories, and Directives

System and Information Integrity

3 linked CSF outcome references →
SI-6Security and Privacy Function Verification

System and Information Integrity

0 linked CSF outcome references →
SI-7Software, Firmware, and Information Integrity

System and Information Integrity

6 linked CSF outcome references →
SI-8Spam Protection

System and Information Integrity

0 linked CSF outcome references →
SI-9Information Input Restrictions

System and Information Integrity

0 linked CSF outcome references →
SR-1Policy and Procedures

Supply Chain Risk Management

8 linked CSF outcome references →
SR-10Inspection of Systems or Components

Supply Chain Risk Management

2 linked CSF outcome references →
SR-11Component Authenticity

Supply Chain Risk Management

1 linked CSF outcome references →
SR-12Component Disposal

Supply Chain Risk Management

1 linked CSF outcome references →
SR-2Supply Chain Risk Management Plan

Supply Chain Risk Management

11 linked CSF outcome references →
SR-3Supply Chain Controls and Processes

Supply Chain Risk Management

12 linked CSF outcome references →
SR-4Provenance

Supply Chain Risk Management

0 linked CSF outcome references →
SR-5Acquisition Strategies, Tools, and Methods

Supply Chain Risk Management

12 linked CSF outcome references →
SR-6Supplier Assessments and Reviews

Supply Chain Risk Management

12 linked CSF outcome references →
SR-7Supply Chain Operations Security

Supply Chain Risk Management

0 linked CSF outcome references →
SR-8Notification Agreements

Supply Chain Risk Management

6 linked CSF outcome references →
SR-9Tamper Resistance and Detection

Supply Chain Risk Management

0 linked CSF outcome references →
Read the relationship labels

A map is evidence, not a compliance shortcut.

Bare Metal Cyber is an independent educational publisher and is not affiliated with or endorsed by NIST or MITRE. Informative references and cross-framework relationships support navigation and analysis; they do not establish compliance, applicability, equivalence, control inheritance, or guaranteed mitigation effectiveness.