What result matters?
Trace cybersecurity outcomes from risk to implementation.
Start with a NIST CSF 2.0 outcome, follow its informative references into NIST SP 800-53, then continue through CUI requirements, defensive techniques, adversary behavior, and practical learning resources.
NIST OLIR reference 186 · Relationship labels preserved · Inferred ATT&CK links clearly marked
Open the official informative reference ↗Move between outcomes, controls, defenses, and threats.
The layers do different jobs. The map preserves each relationship type instead of flattening them into a false equivalence or one-size-fits-all compliance chain.
What controls support it?
What applies to protected CUI?
How can defenses work technically?
What adversary behavior is connected?
Which book and audio resources go deeper?
Explore all 106 NIST CSF Subcategories.
Search by identifier, outcome, or topic. Each page explains the exact imported informative reference and the downstream relationships available in the local knowledge graph.
Detect
11 outcomes
Potentially adverse events are analyzed to better understand associated activities
4 mapped control references →DE.AE-03Correlate Information from Multiple SourcesInformation is correlated from multiple sources
7 mapped control references →DE.AE-04Understand Event Impact and ScopeThe estimated impact and scope of adverse events are understood
5 mapped control references →DE.AE-06Provide Event Information to Authorized Staff and ToolsInformation on adverse events is provided to authorized staff and tools
5 mapped control references →DE.AE-07Integrate Threat Intelligence and ContextCyber threat intelligence and other contextual information are integrated into the analysis
3 mapped control references →DE.AE-08Declare Incidents Using Defined CriteriaIncidents are declared when adverse events meet the defined incident criteria
2 mapped control references →DE.CM-01Monitor Networks and Network ServicesNetworks and network services are monitored to find potentially adverse events
7 mapped control references →DE.CM-02Monitor the Physical EnvironmentThe physical environment is monitored to find potentially adverse events
4 mapped control references →DE.CM-03Monitor Personnel Activity and Technology UsePersonnel activity and technology usage are monitored to find potentially adverse events
6 mapped control references →DE.CM-06Monitor External Service ProvidersExternal service provider activities and services are monitored to find potentially adverse events
5 mapped control references →DE.CM-09Monitor Computing and Runtime EnvironmentsComputing hardware and software, runtime environments, and their data are monitored to find potentially adverse events
12 mapped control references →Govern
31 outcomes
The organizational mission is understood and informs cybersecurity risk management
1 mapped control references →GV.OC-02Stakeholder Needs and ExpectationsInternal and external stakeholders are understood, and their needs and expectations regarding cybersecurity risk management are understood
7 mapped control references →GV.OC-03Legal, Regulatory, and Contractual RequirementsLegal, regulatory, and contractual requirements regarding cybersecurity — including privacy and civil liberties obligations — are understood and managed
21 mapped control references →GV.OC-04External Stakeholder DependenciesCritical objectives, capabilities, and services that external stakeholders depend on or expect from the organization are understood and communicated
5 mapped control references →GV.OC-05Organizational DependenciesOutcomes, capabilities, and services that the organization depends on are understood and communicated
5 mapped control references →GV.OV-01Review Strategy OutcomesCybersecurity risk management strategy outcomes are reviewed to inform and adjust strategy and direction
26 mapped control references →GV.OV-02Adjust Strategy CoverageThe cybersecurity risk management strategy is reviewed and adjusted to ensure coverage of organizational requirements and risks
6 mapped control references →GV.OV-03Evaluate Cybersecurity PerformanceOrganizational cybersecurity risk management performance is evaluated and reviewed for adjustments needed
4 mapped control references →GV.PO-01Establish and Enforce Cybersecurity PolicyPolicy for managing cybersecurity risks is established based on organizational context, cybersecurity strategy, and priorities and is communicated and enforced
20 mapped control references →GV.PO-02Review and Update Cybersecurity PolicyPolicy for managing cybersecurity risks is reviewed, updated, communicated, and enforced to reflect changes in requirements, threats, technology, and organizational mission
20 mapped control references →GV.RM-01Risk Management ObjectivesRisk management objectives are established and agreed to by organizational stakeholders
3 mapped control references →GV.RM-02Risk Appetite and ToleranceRisk appetite and risk tolerance statements are established, communicated, and maintained
1 mapped control references →GV.RM-03Cybersecurity in Enterprise Risk ManagementCybersecurity risk management activities and outcomes are included in enterprise risk management processes
6 mapped control references →GV.RM-04Strategic Risk Response DirectionStrategic direction that describes appropriate risk response options is established and communicated
4 mapped control references →GV.RM-05Cybersecurity Risk CommunicationLines of communication across the organization are established for cybersecurity risks, including risks from suppliers and other third parties
2 mapped control references →GV.RM-06Standardized Risk MethodA standardized method for calculating, documenting, categorizing, and prioritizing cybersecurity risks is established and communicated
5 mapped control references →GV.RM-07Strategic OpportunitiesStrategic opportunities — positive risks — are characterized and are included in organizational cybersecurity risk discussions
5 mapped control references →GV.RR-01Leadership Accountability and Risk-Aware CultureOrganizational leadership is responsible and accountable for cybersecurity risk and fosters a culture that is risk-aware, ethical, and continually improving
5 mapped control references →GV.RR-02Roles, Responsibilities, and AuthoritiesRoles, responsibilities, and authorities related to cybersecurity risk management are established, communicated, understood, and enforced
6 mapped control references →GV.RR-03Risk-Commensurate ResourcesAdequate resources are allocated commensurate with the cybersecurity risk strategy, roles, responsibilities, and policies
1 mapped control references →GV.RR-04Cybersecurity in Human ResourcesCybersecurity is included in human resources practices
4 mapped control references →GV.SC-01C-SCRM Program and StrategyA cybersecurity supply chain risk management program, strategy, objectives, policies, and processes are established and agreed to by organizational stakeholders
3 mapped control references →GV.SC-02Supply Chain Roles and ResponsibilitiesCybersecurity roles and responsibilities for suppliers, customers, and partners are established, communicated, and coordinated internally and externally
3 mapped control references →GV.SC-03Integrate C-SCRM with Risk ManagementCybersecurity supply chain risk management is integrated into cybersecurity and enterprise risk management, risk assessment, and improvement processes
28 mapped control references →GV.SC-04Prioritize Suppliers by CriticalitySuppliers are known and prioritized by criticality
3 mapped control references →GV.SC-05Supply Chain Requirements in AgreementsRequirements to address cybersecurity risks in supply chains are established, prioritized, and integrated into contracts and other types of agreements with suppliers and other relevant third parties
6 mapped control references →GV.SC-06Supplier Due DiligencePlanning and due diligence are performed to reduce risks before entering into formal supplier or other third-party relationships
4 mapped control references →GV.SC-07Monitor Supplier and Third-Party RiskThe risks posed by a supplier, their products and services, and other third parties are understood, recorded, prioritized, assessed, responded to, and monitored over the course of the relationship
5 mapped control references →GV.SC-08Include Suppliers in Incident ActivitiesRelevant suppliers and other third parties are included in incident planning, response, and recovery activities
7 mapped control references →GV.SC-09Life-Cycle Supply Chain SecuritySupply chain security practices are integrated into cybersecurity and enterprise risk management programs, and their performance is monitored throughout the technology product and service life cycle
13 mapped control references →GV.SC-10Post-Relationship Supply Chain ProvisionsCybersecurity supply chain risk management plans include provisions for activities that occur after the conclusion of a partnership or service agreement
10 mapped control references →Identify
21 outcomes
Inventories of hardware managed by the organization are maintained
2 mapped control references →ID.AM-02Software, Service, and System InventoriesInventories of software, services, and systems managed by the organization are maintained
5 mapped control references →ID.AM-03Network Communication and Data Flow RepresentationsRepresentations of the organization’s authorized network communication and internal and external network data flows are maintained
6 mapped control references →ID.AM-04Supplier-Provided Service InventoriesInventories of services provided by suppliers are maintained
3 mapped control references →ID.AM-05Asset PrioritizationAssets are prioritized based on classification, criticality, resources, and impact on the mission
3 mapped control references →ID.AM-07Data and Metadata InventoriesInventories of data and corresponding metadata for designated data types are maintained
3 mapped control references →ID.AM-08Asset Life-Cycle ManagementSystems, hardware, software, services, and data are managed throughout their life cycles
15 mapped control references →ID.IM-01Improvements from EvaluationsImprovements are identified from evaluations
37 mapped control references →ID.IM-02Improvements from Tests and ExercisesImprovements are identified from security tests and exercises, including those done in coordination with suppliers and relevant third parties
40 mapped control references →ID.IM-03Improvements from OperationsImprovements are identified from execution of operational processes, procedures, and activities
39 mapped control references →ID.IM-04Improve Incident Response and Cybersecurity PlansIncident response plans and other cybersecurity plans that affect operations are established, communicated, maintained, and improved
4 mapped control references →ID.RA-01Identify and Record VulnerabilitiesVulnerabilities in assets are identified, validated, and recorded
10 mapped control references →ID.RA-02Receive Cyber Threat IntelligenceCyber threat intelligence is received from information sharing forums and sources
3 mapped control references →ID.RA-03Identify Internal and External ThreatsInternal and external threats to the organization are identified and recorded
4 mapped control references →ID.RA-04Estimate Threat Likelihood and ImpactPotential impacts and likelihoods of threats exploiting vulnerabilities are identified and recorded
6 mapped control references →ID.RA-05Understand Inherent RiskThreats, vulnerabilities, likelihoods, and impacts are used to understand inherent risk and inform risk response prioritization
4 mapped control references →ID.RA-06Select and Track Risk ResponsesRisk responses are chosen, prioritized, planned, tracked, and communicated
4 mapped control references →ID.RA-07Manage Changes and ExceptionsChanges and exceptions are managed, assessed for risk impact, recorded, and tracked
3 mapped control references →ID.RA-08Vulnerability Disclosure ProcessesProcesses are established for receiving, analyzing, and responding to vulnerability disclosures
1 mapped control references →ID.RA-09Assess Hardware and Software AuthenticityThe authenticity and integrity of hardware and software are assessed prior to acquisition and use
11 mapped control references →ID.RA-10Assess Critical Suppliers Before AcquisitionCritical suppliers are assessed prior to acquisition
1 mapped control references →Protect
22 outcomes
Identities and credentials for authorized users, services, and hardware are managed by the organization
14 mapped control references →PR.AA-02Identity Proofing and Credential BindingIdentities are proofed and bound to credentials based on the context of interactions
1 mapped control references →PR.AA-03Authenticate Users, Services, and HardwareUsers, services, and hardware are authenticated
10 mapped control references →PR.AA-04Protect and Verify Identity AssertionsIdentity assertions are protected, conveyed, and verified
1 mapped control references →PR.AA-05Manage Permissions and AuthorizationsAccess permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties
12 mapped control references →PR.AA-06Risk-Based Physical AccessPhysical access to assets is managed, monitored, and enforced commensurate with risk
9 mapped control references →PR.AT-01General Cybersecurity Awareness and TrainingPersonnel are provided with awareness and training so that they possess the knowledge and skills to perform general tasks with cybersecurity risks in mind
2 mapped control references →PR.AT-02Specialized Role TrainingIndividuals in specialized roles are provided with awareness and training so that they possess the knowledge and skills to perform relevant tasks with cybersecurity risks in mind
1 mapped control references →PR.DS-01Protect Data at RestThe confidentiality, integrity, and availability of data-at-rest are protected
14 mapped control references →PR.DS-02Protect Data in TransitThe confidentiality, integrity, and availability of data-in-transit are protected
14 mapped control references →PR.DS-10Protect Data in UseThe confidentiality, integrity, and availability of data-in-use are protected
22 mapped control references →PR.DS-11Create, Protect, Maintain, and Test BackupsBackups of data are created, protected, maintained, and tested
2 mapped control references →PR.IR-01Protect Networks and EnvironmentsNetworks and environments are protected from unauthorized logical access and usage
5 mapped control references →PR.IR-02Protect Technology from Environmental ThreatsThe organization’s technology assets are protected from environmental threats
10 mapped control references →PR.IR-03Resilience MechanismsMechanisms are implemented to achieve resilience requirements in normal and adverse situations
7 mapped control references →PR.IR-04Maintain Resource CapacityAdequate resource capacity to ensure availability is maintained
5 mapped control references →PR.PS-01Configuration ManagementConfiguration management practices are established and applied
11 mapped control references →PR.PS-02Software Maintenance and RemovalSoftware is maintained, replaced, and removed commensurate with risk
5 mapped control references →PR.PS-03Hardware Maintenance and RemovalHardware is maintained, replaced, and removed commensurate with risk
6 mapped control references →PR.PS-04Generate and Provide Log RecordsLog records are generated and made available for continuous monitoring
7 mapped control references →PR.PS-05Prevent Unauthorized SoftwareInstallation and execution of unauthorized software are prevented
4 mapped control references →PR.PS-06Secure Software DevelopmentSecure software development practices are integrated, and their performance is monitored throughout the software development life cycle
8 mapped control references →Recover
8 outcomes
Recovery activities and progress in restoring operational capabilities are communicated to designated internal and external stakeholders
3 mapped control references →RC.CO-04Share Public Recovery UpdatesPublic updates on incident recovery are shared using approved methods and messaging
2 mapped control references →RC.RP-01Execute the Recovery PlanThe recovery portion of the incident response plan is executed once initiated from the incident response process
3 mapped control references →RC.RP-02Select and Perform Recovery ActionsRecovery actions are selected, scoped, prioritized, and performed
3 mapped control references →RC.RP-03Verify Backups and Restoration AssetsThe integrity of backups and other restoration assets is verified before using them for restoration
3 mapped control references →RC.RP-04Establish Post-Incident Operational NormsCritical mission functions and cybersecurity risk management are considered to establish post-incident operational norms
5 mapped control references →RC.RP-05Verify Restored Assets and Normal OperationsThe integrity of restored assets is verified, systems and services are restored, and normal operating status is confirmed
1 mapped control references →RC.RP-06Declare the End of RecoveryThe end of incident recovery is declared based on criteria, and incident-related documentation is completed
2 mapped control references →Respond
13 outcomes
Analysis is performed to establish what has taken place during an incident and the root cause of the incident
3 mapped control references →RS.AN-06Preserve Investigation Action RecordsActions performed during an investigation are recorded, and the records’ integrity and provenance are preserved
3 mapped control references →RS.AN-07Preserve Incident Data and MetadataIncident data and metadata are collected, and their integrity and provenance are preserved
3 mapped control references →RS.AN-08Estimate and Validate Incident MagnitudeAn incident’s magnitude is estimated and validated
4 mapped control references →RS.CO-02Notify StakeholdersInternal and external stakeholders are notified of incidents
5 mapped control references →RS.CO-03Share Incident InformationInformation is shared with designated internal and external stakeholders
5 mapped control references →RS.MA-01Execute the Incident Response PlanThe incident response plan is executed in coordination with relevant third parties once an incident is declared
5 mapped control references →RS.MA-02Triage and Validate Incident ReportsIncident reports are triaged and validated
3 mapped control references →RS.MA-03Categorize and Prioritize IncidentsIncidents are categorized and prioritized
3 mapped control references →RS.MA-04Escalate or Elevate IncidentsIncidents are escalated or elevated as needed
4 mapped control references →RS.MA-05Apply Recovery Initiation CriteriaThe criteria for initiating incident recovery are applied
2 mapped control references →RS.MI-01Contain IncidentsIncidents are contained
1 mapped control references →RS.MI-02Eradicate IncidentsIncidents are eradicated
1 mapped control references →Open any SP 800-53 control in the map.
Use the control view when implementation or assessment work is already organized around SP 800-53 and you need to trace outcomes, CUI requirements, D3FEND techniques, and ATT&CK relationships.
Access Control
10 linked CSF outcome references →AC-10Concurrent Session ControlAccess Control
1 linked CSF outcome references →AC-11Device LockAccess Control
0 linked CSF outcome references →AC-12Session TerminationAccess Control
1 linked CSF outcome references →AC-13Supervision and Review — Access ControlAccess Control
0 linked CSF outcome references →AC-14Permitted Actions Without Identification or AuthenticationAccess Control
1 linked CSF outcome references →AC-15Automated MarkingAccess Control
0 linked CSF outcome references →AC-16Security and Privacy AttributesAccess Control
1 linked CSF outcome references →AC-17Remote AccessAccess Control
1 linked CSF outcome references →AC-18Wireless AccessAccess Control
1 linked CSF outcome references →AC-19Access Control for Mobile DevicesAccess Control
1 linked CSF outcome references →AC-2Account ManagementAccess Control
5 linked CSF outcome references →AC-20Use of External SystemsAccess Control
2 linked CSF outcome references →AC-21Information SharingAccess Control
0 linked CSF outcome references →AC-22Publicly Accessible ContentAccess Control
0 linked CSF outcome references →AC-23Data Mining ProtectionAccess Control
0 linked CSF outcome references →AC-24Access Control DecisionsAccess Control
1 linked CSF outcome references →AC-25Reference MonitorAccess Control
0 linked CSF outcome references →AC-3Access EnforcementAccess Control
3 linked CSF outcome references →AC-4Information Flow EnforcementAccess Control
4 linked CSF outcome references →AC-5Separation of DutiesAccess Control
1 linked CSF outcome references →AC-6Least PrivilegeAccess Control
1 linked CSF outcome references →AC-7Unsuccessful Logon AttemptsAccess Control
1 linked CSF outcome references →AC-8System Use NotificationAccess Control
0 linked CSF outcome references →AC-9Previous Logon NotificationAccess Control
1 linked CSF outcome references →AT-1Policy and ProceduresAwareness and Training
8 linked CSF outcome references →AT-2Literacy Training and AwarenessAwareness and Training
1 linked CSF outcome references →AT-3Role-based TrainingAwareness and Training
2 linked CSF outcome references →AT-4Training RecordsAwareness and Training
0 linked CSF outcome references →AT-5Contacts with Security Groups and AssociationsAwareness and Training
0 linked CSF outcome references →AT-6Training FeedbackAwareness and Training
0 linked CSF outcome references →AU-1Policy and ProceduresAudit and Accountability
8 linked CSF outcome references →AU-10Non-repudiationAudit and Accountability
0 linked CSF outcome references →AU-11Audit Record RetentionAudit and Accountability
1 linked CSF outcome references →AU-12Audit Record GenerationAudit and Accountability
4 linked CSF outcome references →AU-13Monitoring for Information DisclosureAudit and Accountability
2 linked CSF outcome references →AU-14Session AuditAudit and Accountability
0 linked CSF outcome references →AU-15Alternate Audit Logging CapabilityAudit and Accountability
0 linked CSF outcome references →AU-16Cross-organizational Audit LoggingAudit and Accountability
1 linked CSF outcome references →AU-2Event LoggingAudit and Accountability
1 linked CSF outcome references →AU-3Content of Audit RecordsAudit and Accountability
1 linked CSF outcome references →AU-4Audit Log Storage CapacityAudit and Accountability
0 linked CSF outcome references →AU-5Response to Audit Logging Process FailuresAudit and Accountability
0 linked CSF outcome references →AU-6Audit Record Review, Analysis, and ReportingAudit and Accountability
3 linked CSF outcome references →AU-7Audit Record Reduction and Report GenerationAudit and Accountability
4 linked CSF outcome references →AU-8Time StampsAudit and Accountability
0 linked CSF outcome references →AU-9Protection of Audit InformationAudit and Accountability
1 linked CSF outcome references →CA-1Policy and ProceduresAssessment, Authorization, and Monitoring
8 linked CSF outcome references →CA-2Control AssessmentsAssessment, Authorization, and Monitoring
4 linked CSF outcome references →CA-3Information ExchangeAssessment, Authorization, and Monitoring
4 linked CSF outcome references →CA-4Security CertificationAssessment, Authorization, and Monitoring
0 linked CSF outcome references →CA-5Plan of Action and MilestonesAssessment, Authorization, and Monitoring
3 linked CSF outcome references →CA-6AuthorizationAssessment, Authorization, and Monitoring
0 linked CSF outcome references →CA-7Continuous MonitoringAssessment, Authorization, and Monitoring
12 linked CSF outcome references →CA-8Penetration TestingAssessment, Authorization, and Monitoring
4 linked CSF outcome references →CA-9Internal System ConnectionsAssessment, Authorization, and Monitoring
1 linked CSF outcome references →CM-1Policy and ProceduresConfiguration Management
9 linked CSF outcome references →CM-10Software Usage RestrictionsConfiguration Management
3 linked CSF outcome references →CM-11User-installed SoftwareConfiguration Management
4 linked CSF outcome references →CM-12Information LocationConfiguration Management
1 linked CSF outcome references →CM-13Data Action MappingConfiguration Management
2 linked CSF outcome references →CM-14Signed ComponentsConfiguration Management
0 linked CSF outcome references →CM-2Baseline ConfigurationConfiguration Management
1 linked CSF outcome references →CM-3Configuration Change ControlConfiguration Management
4 linked CSF outcome references →CM-4Impact AnalysesConfiguration Management
2 linked CSF outcome references →CM-5Access Restrictions for ChangeConfiguration Management
1 linked CSF outcome references →CM-6Configuration SettingsConfiguration Management
2 linked CSF outcome references →CM-7Least FunctionalityConfiguration Management
5 linked CSF outcome references →CM-8System Component InventoryConfiguration Management
3 linked CSF outcome references →CM-9Configuration Management PlanConfiguration Management
2 linked CSF outcome references →CP-1Policy and ProceduresContingency Planning
9 linked CSF outcome references →CP-10System Recovery and ReconstitutionContingency Planning
3 linked CSF outcome references →CP-11Alternate Communications ProtocolsContingency Planning
0 linked CSF outcome references →CP-12Safe ModeContingency Planning
0 linked CSF outcome references →CP-13Alternative Security MechanismsContingency Planning
0 linked CSF outcome references →CP-2Contingency PlanContingency Planning
8 linked CSF outcome references →CP-3Contingency TrainingContingency Planning
0 linked CSF outcome references →CP-4Contingency Plan TestingContingency Planning
2 linked CSF outcome references →CP-5Contingency Plan UpdateContingency Planning
0 linked CSF outcome references →CP-6Alternate Storage SiteContingency Planning
2 linked CSF outcome references →CP-7Alternate Processing SiteContingency Planning
1 linked CSF outcome references →CP-8Telecommunications ServicesContingency Planning
1 linked CSF outcome references →CP-9System BackupContingency Planning
4 linked CSF outcome references →IA-1Policy and ProceduresIdentification and Authentication
9 linked CSF outcome references →IA-10Adaptive AuthenticationIdentification and Authentication
2 linked CSF outcome references →IA-11Re-authenticationIdentification and Authentication
2 linked CSF outcome references →IA-12Identity ProofingIdentification and Authentication
1 linked CSF outcome references →IA-13Identity Providers and Authorization ServersIdentification and Authentication
2 linked CSF outcome references →IA-2Identification and Authentication (Organizational Users)Identification and Authentication
2 linked CSF outcome references →IA-3Device Identification and AuthenticationIdentification and Authentication
2 linked CSF outcome references →IA-4Identifier ManagementIdentification and Authentication
1 linked CSF outcome references →IA-5Authenticator ManagementIdentification and Authentication
2 linked CSF outcome references →IA-6Authentication FeedbackIdentification and Authentication
1 linked CSF outcome references →IA-7Cryptographic Module AuthenticationIdentification and Authentication
2 linked CSF outcome references →IA-8Identification and Authentication (Non-organizational Users)Identification and Authentication
2 linked CSF outcome references →IA-9Service Identification and AuthenticationIdentification and Authentication
2 linked CSF outcome references →IR-1Policy and ProceduresIncident Response
10 linked CSF outcome references →IR-10Integrated Information Security Analysis TeamIncident Response
0 linked CSF outcome references →IR-2Incident Response TrainingIncident Response
0 linked CSF outcome references →IR-3Incident Response TestingIncident Response
1 linked CSF outcome references →IR-4Incident HandlingIncident Response
24 linked CSF outcome references →IR-5Incident MonitoringIncident Response
4 linked CSF outcome references →IR-6Incident ReportingIncident Response
9 linked CSF outcome references →IR-7Incident Response AssistanceIncident Response
4 linked CSF outcome references →IR-8Incident Response PlanIncident Response
13 linked CSF outcome references →IR-9Information Spillage ResponseIncident Response
0 linked CSF outcome references →MA-1Policy and ProceduresMaintenance
8 linked CSF outcome references →MA-2Controlled MaintenanceMaintenance
1 linked CSF outcome references →MA-3Maintenance ToolsMaintenance
1 linked CSF outcome references →MA-4Nonlocal MaintenanceMaintenance
0 linked CSF outcome references →MA-5Maintenance PersonnelMaintenance
0 linked CSF outcome references →MA-6Timely MaintenanceMaintenance
1 linked CSF outcome references →MA-7Field MaintenanceMaintenance
0 linked CSF outcome references →MP-1Policy and ProceduresMedia Protection
8 linked CSF outcome references →MP-2Media AccessMedia Protection
0 linked CSF outcome references →MP-3Media MarkingMedia Protection
0 linked CSF outcome references →MP-4Media StorageMedia Protection
0 linked CSF outcome references →MP-5Media TransportMedia Protection
0 linked CSF outcome references →MP-6Media SanitizationMedia Protection
0 linked CSF outcome references →MP-7Media UseMedia Protection
0 linked CSF outcome references →MP-8Media DowngradingMedia Protection
1 linked CSF outcome references →PE-1Policy and ProceduresPhysical and Environmental Protection
8 linked CSF outcome references →PE-10Emergency ShutoffPhysical and Environmental Protection
1 linked CSF outcome references →PE-11Emergency PowerPhysical and Environmental Protection
1 linked CSF outcome references →PE-12Emergency LightingPhysical and Environmental Protection
1 linked CSF outcome references →PE-13Fire ProtectionPhysical and Environmental Protection
1 linked CSF outcome references →PE-14Environmental ControlsPhysical and Environmental Protection
1 linked CSF outcome references →PE-15Water Damage ProtectionPhysical and Environmental Protection
1 linked CSF outcome references →PE-16Delivery and RemovalPhysical and Environmental Protection
0 linked CSF outcome references →PE-17Alternate Work SitePhysical and Environmental Protection
0 linked CSF outcome references →PE-18Location of System ComponentsPhysical and Environmental Protection
2 linked CSF outcome references →PE-19Information LeakagePhysical and Environmental Protection
1 linked CSF outcome references →PE-2Physical Access AuthorizationsPhysical and Environmental Protection
1 linked CSF outcome references →PE-20Asset Monitoring and TrackingPhysical and Environmental Protection
2 linked CSF outcome references →PE-21Electromagnetic Pulse ProtectionPhysical and Environmental Protection
0 linked CSF outcome references →PE-22Component MarkingPhysical and Environmental Protection
0 linked CSF outcome references →PE-23Facility LocationPhysical and Environmental Protection
1 linked CSF outcome references →PE-3Physical Access ControlPhysical and Environmental Protection
2 linked CSF outcome references →PE-4Access Control for TransmissionPhysical and Environmental Protection
1 linked CSF outcome references →PE-5Access Control for Output DevicesPhysical and Environmental Protection
1 linked CSF outcome references →PE-6Monitoring Physical AccessPhysical and Environmental Protection
2 linked CSF outcome references →PE-7Visitor ControlPhysical and Environmental Protection
0 linked CSF outcome references →PE-8Visitor Access RecordsPhysical and Environmental Protection
1 linked CSF outcome references →PE-9Power Equipment and CablingPhysical and Environmental Protection
1 linked CSF outcome references →PL-1Policy and ProceduresPlanning
8 linked CSF outcome references →PL-10Baseline SelectionPlanning
0 linked CSF outcome references →PL-11Baseline TailoringPlanning
0 linked CSF outcome references →PL-2System Security and Privacy PlansPlanning
6 linked CSF outcome references →PL-3System Security Plan UpdatePlanning
0 linked CSF outcome references →PL-4Rules of BehaviorPlanning
0 linked CSF outcome references →PL-5Privacy Impact AssessmentPlanning
0 linked CSF outcome references →PL-6Security-related Activity PlanningPlanning
0 linked CSF outcome references →PL-7Concept of OperationsPlanning
0 linked CSF outcome references →PL-8Security and Privacy ArchitecturesPlanning
1 linked CSF outcome references →PL-9Central ManagementPlanning
0 linked CSF outcome references →PM-1Information Security Program PlanProgram Management
8 linked CSF outcome references →PM-10Authorization ProcessProgram Management
0 linked CSF outcome references →PM-11Mission and Business Process DefinitionProgram Management
6 linked CSF outcome references →PM-12Insider Threat ProgramProgram Management
1 linked CSF outcome references →PM-13Security and Privacy WorkforceProgram Management
2 linked CSF outcome references →PM-14Testing, Training, and MonitoringProgram Management
0 linked CSF outcome references →PM-15Security and Privacy Groups and AssociationsProgram Management
2 linked CSF outcome references →PM-16Threat Awareness ProgramProgram Management
6 linked CSF outcome references →PM-17Protecting Controlled Unclassified Information on External SystemsProgram Management
0 linked CSF outcome references →PM-18Privacy Program PlanProgram Management
7 linked CSF outcome references →PM-19Privacy Program Leadership RoleProgram Management
4 linked CSF outcome references →PM-2Information Security Program Leadership RoleProgram Management
2 linked CSF outcome references →PM-20Dissemination of Privacy Program InformationProgram Management
0 linked CSF outcome references →PM-21Accounting of DisclosuresProgram Management
0 linked CSF outcome references →PM-22Personally Identifiable Information Quality ManagementProgram Management
1 linked CSF outcome references →PM-23Data Governance BodyProgram Management
3 linked CSF outcome references →PM-24Data Integrity BoardProgram Management
2 linked CSF outcome references →PM-25Minimization of Personally Identifiable Information Used in Testing, Training, and ResearchProgram Management
0 linked CSF outcome references →PM-26Complaint ManagementProgram Management
0 linked CSF outcome references →PM-27Privacy ReportingProgram Management
0 linked CSF outcome references →PM-28Risk FramingProgram Management
6 linked CSF outcome references →PM-29Risk Management Program Leadership RolesProgram Management
2 linked CSF outcome references →PM-3Information Security and Privacy ResourcesProgram Management
3 linked CSF outcome references →PM-30Supply Chain Risk Management StrategyProgram Management
15 linked CSF outcome references →PM-31Continuous Monitoring StrategyProgram Management
7 linked CSF outcome references →PM-32PurposingProgram Management
0 linked CSF outcome references →PM-4Plan of Action and Milestones ProcessProgram Management
3 linked CSF outcome references →PM-5System InventoryProgram Management
2 linked CSF outcome references →PM-6Measures of PerformanceProgram Management
1 linked CSF outcome references →PM-7Enterprise ArchitectureProgram Management
1 linked CSF outcome references →PM-8Critical Infrastructure PlanProgram Management
2 linked CSF outcome references →PM-9Risk Management StrategyProgram Management
17 linked CSF outcome references →PS-1Policy and ProceduresPersonnel Security
9 linked CSF outcome references →PS-2Position Risk DesignationPersonnel Security
0 linked CSF outcome references →PS-3Personnel ScreeningPersonnel Security
0 linked CSF outcome references →PS-4Personnel TerminationPersonnel Security
0 linked CSF outcome references →PS-5Personnel TransferPersonnel Security
0 linked CSF outcome references →PS-6Access AgreementsPersonnel Security
0 linked CSF outcome references →PS-7External Personnel SecurityPersonnel Security
2 linked CSF outcome references →PS-8Personnel SanctionsPersonnel Security
0 linked CSF outcome references →PS-9Position DescriptionsPersonnel Security
1 linked CSF outcome references →PT-1Policy and ProceduresPersonally Identifiable Information Processing and Transparency
8 linked CSF outcome references →PT-2Authority to Process Personally Identifiable InformationPersonally Identifiable Information Processing and Transparency
0 linked CSF outcome references →PT-3Personally Identifiable Information Processing PurposesPersonally Identifiable Information Processing and Transparency
0 linked CSF outcome references →PT-4ConsentPersonally Identifiable Information Processing and Transparency
0 linked CSF outcome references →PT-5Privacy NoticePersonally Identifiable Information Processing and Transparency
0 linked CSF outcome references →PT-6System of Records NoticePersonally Identifiable Information Processing and Transparency
0 linked CSF outcome references →PT-7Specific Categories of Personally Identifiable InformationPersonally Identifiable Information Processing and Transparency
0 linked CSF outcome references →PT-8Computer Matching RequirementsPersonally Identifiable Information Processing and Transparency
0 linked CSF outcome references →RA-1Policy and ProceduresRisk Assessment
8 linked CSF outcome references →RA-10Threat HuntingRisk Assessment
2 linked CSF outcome references →RA-2Security CategorizationRisk Assessment
3 linked CSF outcome references →RA-3Risk AssessmentRisk Assessment
15 linked CSF outcome references →RA-4Risk Assessment UpdateRisk Assessment
1 linked CSF outcome references →RA-5Vulnerability Monitoring and ScanningRisk Assessment
6 linked CSF outcome references →RA-6Technical Surveillance Countermeasures SurveyRisk Assessment
0 linked CSF outcome references →RA-7Risk ResponseRisk Assessment
15 linked CSF outcome references →RA-8Privacy Impact AssessmentsRisk Assessment
1 linked CSF outcome references →RA-9Criticality AnalysisRisk Assessment
5 linked CSF outcome references →SA-1Policy and ProceduresSystem and Services Acquisition
8 linked CSF outcome references →SA-10Developer Configuration ManagementSystem and Services Acquisition
4 linked CSF outcome references →SA-11Developer Testing and EvaluationSystem and Services Acquisition
6 linked CSF outcome references →SA-12Supply Chain ProtectionSystem and Services Acquisition
0 linked CSF outcome references →SA-13TrustworthinessSystem and Services Acquisition
0 linked CSF outcome references →SA-14Criticality AnalysisSystem and Services Acquisition
0 linked CSF outcome references →SA-15Development Process, Standards, and ToolsSystem and Services Acquisition
6 linked CSF outcome references →SA-16Developer-provided TrainingSystem and Services Acquisition
0 linked CSF outcome references →SA-17Developer Security and Privacy Architecture and DesignSystem and Services Acquisition
3 linked CSF outcome references →SA-18Tamper Resistance and DetectionSystem and Services Acquisition
0 linked CSF outcome references →SA-19Component AuthenticitySystem and Services Acquisition
0 linked CSF outcome references →SA-2Allocation of ResourcesSystem and Services Acquisition
0 linked CSF outcome references →SA-20Customized Development of Critical ComponentsSystem and Services Acquisition
0 linked CSF outcome references →SA-21Developer ScreeningSystem and Services Acquisition
0 linked CSF outcome references →SA-22Unsupported System ComponentsSystem and Services Acquisition
1 linked CSF outcome references →SA-23SpecializationSystem and Services Acquisition
0 linked CSF outcome references →SA-24Design For Cyber ResiliencySystem and Services Acquisition
3 linked CSF outcome references →SA-3System Development Life CycleSystem and Services Acquisition
2 linked CSF outcome references →SA-4Acquisition ProcessSystem and Services Acquisition
10 linked CSF outcome references →SA-5System DocumentationSystem and Services Acquisition
2 linked CSF outcome references →SA-6Software Usage RestrictionsSystem and Services Acquisition
0 linked CSF outcome references →SA-7User-installed SoftwareSystem and Services Acquisition
0 linked CSF outcome references →SA-8Security and Privacy Engineering PrinciplesSystem and Services Acquisition
7 linked CSF outcome references →SA-9External System ServicesSystem and Services Acquisition
11 linked CSF outcome references →SC-1Policy and ProceduresSystem and Communications Protection
8 linked CSF outcome references →SC-10Network DisconnectSystem and Communications Protection
0 linked CSF outcome references →SC-11Trusted PathSystem and Communications Protection
2 linked CSF outcome references →SC-12Cryptographic Key Establishment and ManagementSystem and Communications Protection
2 linked CSF outcome references →SC-13Cryptographic ProtectionSystem and Communications Protection
3 linked CSF outcome references →SC-14Public Access ProtectionsSystem and Communications Protection
0 linked CSF outcome references →SC-15Collaborative Computing Devices and ApplicationsSystem and Communications Protection
0 linked CSF outcome references →SC-16Transmission of Security and Privacy AttributesSystem and Communications Protection
1 linked CSF outcome references →SC-17Public Key Infrastructure CertificatesSystem and Communications Protection
0 linked CSF outcome references →SC-18Mobile CodeSystem and Communications Protection
0 linked CSF outcome references →SC-19Voice Over Internet ProtocolSystem and Communications Protection
0 linked CSF outcome references →SC-2Separation of System and User FunctionalitySystem and Communications Protection
0 linked CSF outcome references →SC-20Secure Name/Address Resolution Service (Authoritative Source)System and Communications Protection
0 linked CSF outcome references →SC-21Secure Name/Address Resolution Service (Recursive or Caching Resolver)System and Communications Protection
0 linked CSF outcome references →SC-22Architecture and Provisioning for Name/Address Resolution ServiceSystem and Communications Protection
0 linked CSF outcome references →SC-23Session AuthenticitySystem and Communications Protection
0 linked CSF outcome references →SC-24Fail in Known StateSystem and Communications Protection
2 linked CSF outcome references →SC-25Thin NodesSystem and Communications Protection
0 linked CSF outcome references →SC-26DecoysSystem and Communications Protection
0 linked CSF outcome references →SC-27Platform-independent ApplicationsSystem and Communications Protection
0 linked CSF outcome references →SC-28Protection of Information at RestSystem and Communications Protection
1 linked CSF outcome references →SC-29HeterogeneitySystem and Communications Protection
0 linked CSF outcome references →SC-3Security Function IsolationSystem and Communications Protection
1 linked CSF outcome references →SC-30Concealment and MisdirectionSystem and Communications Protection
0 linked CSF outcome references →SC-31Covert Channel AnalysisSystem and Communications Protection
0 linked CSF outcome references →SC-32System PartitioningSystem and Communications Protection
2 linked CSF outcome references →SC-33Transmission Preparation IntegritySystem and Communications Protection
0 linked CSF outcome references →SC-34Non-modifiable Executable ProgramsSystem and Communications Protection
2 linked CSF outcome references →SC-35External Malicious Code IdentificationSystem and Communications Protection
1 linked CSF outcome references →SC-36Distributed Processing and StorageSystem and Communications Protection
1 linked CSF outcome references →SC-37Out-of-band ChannelsSystem and Communications Protection
0 linked CSF outcome references →SC-38Operations SecuritySystem and Communications Protection
0 linked CSF outcome references →SC-39Process IsolationSystem and Communications Protection
4 linked CSF outcome references →SC-4Information in Shared System ResourcesSystem and Communications Protection
4 linked CSF outcome references →SC-40Wireless Link ProtectionSystem and Communications Protection
2 linked CSF outcome references →SC-41Port and I/O Device AccessSystem and Communications Protection
0 linked CSF outcome references →SC-42Sensor Capability and DataSystem and Communications Protection
0 linked CSF outcome references →SC-43Usage RestrictionsSystem and Communications Protection
3 linked CSF outcome references →SC-44Detonation ChambersSystem and Communications Protection
0 linked CSF outcome references →SC-45System Time SynchronizationSystem and Communications Protection
0 linked CSF outcome references →SC-46Cross Domain Policy EnforcementSystem and Communications Protection
0 linked CSF outcome references →SC-47Alternate Communications PathsSystem and Communications Protection
0 linked CSF outcome references →SC-48Sensor RelocationSystem and Communications Protection
0 linked CSF outcome references →SC-49Hardware-enforced Separation and Policy EnforcementSystem and Communications Protection
1 linked CSF outcome references →SC-5Denial-of-service ProtectionSystem and Communications Protection
2 linked CSF outcome references →SC-50Software-enforced Separation and Policy EnforcementSystem and Communications Protection
0 linked CSF outcome references →SC-51Hardware-based ProtectionSystem and Communications Protection
1 linked CSF outcome references →SC-6Resource AvailabilitySystem and Communications Protection
1 linked CSF outcome references →SC-7Boundary ProtectionSystem and Communications Protection
5 linked CSF outcome references →SC-8Transmission Confidentiality and IntegritySystem and Communications Protection
1 linked CSF outcome references →SC-9Transmission ConfidentialitySystem and Communications Protection
0 linked CSF outcome references →SI-1Policy and ProceduresSystem and Information Integrity
8 linked CSF outcome references →SI-10Information Input ValidationSystem and Information Integrity
1 linked CSF outcome references →SI-11Error HandlingSystem and Information Integrity
0 linked CSF outcome references →SI-12Information Management and RetentionSystem and Information Integrity
2 linked CSF outcome references →SI-13Predictable Failure PreventionSystem and Information Integrity
1 linked CSF outcome references →SI-14Non-persistenceSystem and Information Integrity
0 linked CSF outcome references →SI-15Information Output FilteringSystem and Information Integrity
0 linked CSF outcome references →SI-16Memory ProtectionSystem and Information Integrity
1 linked CSF outcome references →SI-17Fail-safe ProceduresSystem and Information Integrity
0 linked CSF outcome references →SI-18Personally Identifiable Information Quality OperationsSystem and Information Integrity
1 linked CSF outcome references →SI-19De-identificationSystem and Information Integrity
0 linked CSF outcome references →SI-2Flaw RemediationSystem and Information Integrity
5 linked CSF outcome references →SI-20TaintingSystem and Information Integrity
0 linked CSF outcome references →SI-21Information RefreshSystem and Information Integrity
0 linked CSF outcome references →SI-22Information DiversitySystem and Information Integrity
0 linked CSF outcome references →SI-23Information FragmentationSystem and Information Integrity
0 linked CSF outcome references →SI-3Malicious Code ProtectionSystem and Information Integrity
3 linked CSF outcome references →SI-4System MonitoringSystem and Information Integrity
12 linked CSF outcome references →SI-5Security Alerts, Advisories, and DirectivesSystem and Information Integrity
3 linked CSF outcome references →SI-6Security and Privacy Function VerificationSystem and Information Integrity
0 linked CSF outcome references →SI-7Software, Firmware, and Information IntegritySystem and Information Integrity
6 linked CSF outcome references →SI-8Spam ProtectionSystem and Information Integrity
0 linked CSF outcome references →SI-9Information Input RestrictionsSystem and Information Integrity
0 linked CSF outcome references →SR-1Policy and ProceduresSupply Chain Risk Management
8 linked CSF outcome references →SR-10Inspection of Systems or ComponentsSupply Chain Risk Management
2 linked CSF outcome references →SR-11Component AuthenticitySupply Chain Risk Management
1 linked CSF outcome references →SR-12Component DisposalSupply Chain Risk Management
1 linked CSF outcome references →SR-2Supply Chain Risk Management PlanSupply Chain Risk Management
11 linked CSF outcome references →SR-3Supply Chain Controls and ProcessesSupply Chain Risk Management
12 linked CSF outcome references →SR-4ProvenanceSupply Chain Risk Management
0 linked CSF outcome references →SR-5Acquisition Strategies, Tools, and MethodsSupply Chain Risk Management
12 linked CSF outcome references →SR-6Supplier Assessments and ReviewsSupply Chain Risk Management
12 linked CSF outcome references →SR-7Supply Chain Operations SecuritySupply Chain Risk Management
0 linked CSF outcome references →SR-8Notification AgreementsSupply Chain Risk Management
6 linked CSF outcome references →SR-9Tamper Resistance and DetectionSupply Chain Risk Management
0 linked CSF outcome references →A map is evidence, not a compliance shortcut.
Bare Metal Cyber is an independent educational publisher and is not affiliated with or endorsed by NIST or MITRE. Informative references and cross-framework relationships support navigation and analysis; they do not establish compliance, applicability, equivalence, control inheritance, or guaranteed mitigation effectiveness.