Frameworks / ASD Strategies to Mitigate Cyber Security Incidents / ASD37-20 ASD Strategies to Mitigate Cyber Security Incidents
Limiting the Extent of Cyber Security Incidents
ASD Strategies to Mitigate Cyber Security Incidents ASD37-20: Multi-factor authentication (Essential) Multi-factor authentication including for VPNs, RDP, SSH and other remote access, and for all users when they perform a privileged action or access an important (sensitive/high-availability) data repository.
Maintained by Gerard Blokdyk · Verified against the published standard 31 May 2026 · Control text last updated 21 May 2026 What else in your programme already covers this This control maps to 429 controls across 167 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
NIST-CSF-PR.AA-01 Identities and credentials for authorized users, services, and hardware are managed by the organization NIST-CSF-PR.AA-02 Identities are proofed and bound to credentials based on the context of interactions NIST-CSF-PR.AA-03 Users, services, and hardware are authenticated NIST-CSF-PR.AA-05 Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties NIST-CSF-PR.DS-10 The confidentiality, integrity, and availability of data-in-use are protected NIST-CSF-PR.IR-01 Networks and environments are protected from unauthorized logical access and usage NIST-CSF-PR.IR-03 Mechanisms are implemented to achieve resilience requirements in normal and adverse situations NIST-CSF-PR.IR-04 Adequate resource capacity to ensure availability is maintained SOC2-A1.1 A1.1 Managing processing capacity SOC2-A1.2 A1.2 Environmental protection, backup and recovery infrastructure SOC2-A1.3 A1.3 Testing recovery plan procedures SOC2-CC6.1 CC6.1 Logical access security over protected information assets SOC2-CC6.2 CC6.2 Registering and authorising users before issuing credentials SOC2-CC6.3 CC6.3 Role-based access, least privilege and segregation of duties CIS-12.7 Ensure Remote Devices Utilize a VPN and are Connecting to an Enterprise’s AAA Infrastructure CIS-13.5 Manage Access Control for Remote Assets CIS-6.3 Require MFA for Externally-Exposed Applications CIS-6.4 Require MFA for Remote Network Access CIS-6.5 Require MFA for Administrative Access CPG-1.A Changing Default Passwords CPG-1.C Unique Credentials CPG-1.D Revoking Credentials for Departing Employees CPG-4.C Basic Cybersecurity Training CPG-8.A Network Segmentation 8.3.1 8.3.1 Access authenticated with at least one factor 8.4.1 8.4.1 MFA for non-console administrative CDE access 8.4.2 8.4.2 MFA for all non-console CDE access 8.4.3 8.4.3 MFA for remote access that could reach CDE 8.5.1 8.5.1 MFA system resistant to replay and bypass IM8-DAT.2 Data Protection IM8-DSS.2 Service Reliability Standards IM8-RES.4 Resilience Testing IM8-SEC.2 Access Control IM8-SEC.3 Network Security OB-API.4 MI Reporting Specification OB-CX.3 Strong Customer Authentication OB-DIR.1 Open Banking Directory OB-OPS.1 API Availability Requirements OB-SEC.4 Certificate Management AWWA-1.3 Security Awareness and Training AWWA-2.1 User Access Management AWWA-2.2 Authentication Mechanisms AWWA-3.1 Network Segmentation FFIEC-06 Network security and segmentation FFIEC-11 Business continuity planning and testing FFIEC-12 Disaster recovery procedures FFIEC-14 Critical service identification AC-17 Remote Access IA-2 Identification and Authentication (Organizational Users) IA-2(1) MFA to Privileged Accounts IA-2(2) MFA to Non-Privileged Accounts AC-17 Remote Access IA-2 Identification and Authentication (Organizational Users) IA-2(1) MFA to Privileged Accounts IA-2(2) MFA to Non-Privileged Accounts NISTPF-3 Control-P - Privacy Controls, Data Management, and Disassociated Processing NISTPF-5 Protect-P Access Control (PR.AC-P) NISTPF-6 Protect-P Data Security (PR.DS-P) NISTPF-7 Protect-P Maintenance and Protective Technology (PR.MA-P, PR.PT-P) NISTSP82-1 OT Security Program Governance, Policy, Roles, and Safety-Security Integration NISTSP82-2 OT Risk Assessment and Threat/Vulnerability Identification NISTSP82-4 OT Access Control, Identity, Authentication, and Remote Access NISTSP82-5 OT Configuration Management, Patching, Vulnerability Management, and Malware Protection OWASPLLM-1 Prompt Injection and System Prompt Leakage (LLM01 + LLM07) OWASPLLM-2 Improper Output Handling and Misinformation (LLM05 + LLM09) OWASPLLM-3 Sensitive Information Disclosure and Privacy (LLM02) OWASPLLM-6 Excessive Agency and Unbounded Consumption (LLM06 + LLM10) PCI-P2PE-06 Network security and segmentation PCI-P2PE-11 Business continuity planning and testing PCI-P2PE-12 Disaster recovery procedures PCI-P2PE-14 Critical service identification PCI-PIN-06 Network security and segmentation PCI-PIN-13 Third-party dependency management PCI-PIN-14 Critical service identification PCI-PIN-15 Communication and escalation procedures PCI-SSF-06 Network security and segmentation PCI-SSF-12 Disaster recovery procedures PCI-SSF-14 Critical service identification PCI-SSF-15 Communication and escalation procedures CE-AC.7 MFA for Administrative Accounts CE-AC.8 Passwordless Authentication CE-FW.3 Block Unauthenticated Inbound Connections CE-SC.6 Multi-Factor Authentication for Cloud Services E8-MFA-ML1 Multi-Factor Authentication - Maturity Level 1 E8-MFA-ML2 Multi-Factor Authentication - Maturity Level 2 E8-MFA-ML3 Multi-Factor Authentication - Maturity Level 3 4.3.2 Legal and Other Requirements 4.4.1 Resources, Roles, Responsibility, and Authority 4.4.2 Competence, Training, and Awareness ASBv3-IM-2 Protect identity and authentication systems IM-6 Use strong authentication controls IM-7 Restrict resource access based on conditions CAT-D3-1 Preventative controls CAT-D5-4 Resilience planning and testing CAT-IRP-4 Organizational characteristics 62351-12 Resilience and security recommendations for DER 62351-13 Cyber-physical generation and storage resilience 62351-8 Role-based access control (RBAC) 27011-6.3 Awareness and Training 27011-8.1 User Endpoint Devices 27011-8.2 Network security and segregation ISO27043-13 Authentication and password management ISO27043-14 Privileged access management ISO27043-27 Network security management 29115-11 Mapping other authentication schemes 29115-12.1 Exchanging authentication results 29115-12.2 Controls for mitigating threats ISO21434-13 Authentication and password management ISO21434-14 Privileged access management ISO21434-27 Network security management MTCS-Asset-IAM-Cryptography-Multi-Tier-Asset-Inventory-RBAC-MFA-PAM-FIPS-HSM-Quantum-Safe MTCS Asset Mgmt + IAM + Cryptography + Asset Inventory + RBAC + MFA + PAM + FIPS + HSM + Quantum-Safe MTCS-Incident-Business-Continuity-CSC-Data-Protection-72-Hour-Notification-BCP-DR-PDPA MTCS Incident + Business Continuity + CSC Data Protection + 72-Hour Notification + BCP + DR + PDPA MTCS-Logging-Monitoring-Compliance-Audit-SLA-Configuration-SIEM-SOAR-Cloud-Monitoring-CSPM MTCS Logging + Monitoring + Compliance + Audit + SLA + Configuration + SIEM + SOAR + CSPM MAS-TRM-Cyber-Resilience-Chapter-11-Threat-Intelligence-Penetration-Testing-Incident-Response-1-Hour-Notification MAS TRM Cyber Resilience + Chapter 11 + Threat Intelligence + Penetration Testing + Incident Response + 1-Hour Notification MAS-TRM-Project-SDLC-Service-Management-Chapters-4-5-6-IT-Project-Software-Lifecycle-Change-ITIL MAS TRM Project + SDLC + Service Management + Chapters 4-6 + IT Project + Software Lifecycle + ITIL MAS-TRM-Reliability-Data-Centre-Chapters-7-8-RTO-RPO-BCP-DR-System-Availability-4-Hours-12-Months MAS TRM Reliability + Data Centre + Chapters 7-8 + RTO + RPO + BCP + DR + System Availability 4 Hours 12 Months OSFIB13-3 Cyber Security: Identification, Protection, Detection, Response, Recovery OSFIB13-4 Third-Party Risk Management and Cloud OSFIB13-7 Incident Reporting to OSFI and Regulatory Coordination DSOMM-1 Culture, Organization, Education, and Governance DSOMM-3 Build, Deployment, Infrastructure Hardening, and Secrets Management DSOMM-4 Test and Verification - SAST, DAST, IAST, SCA, Penetration Testing OPENBANK-3 Mutual TLS, Token Binding, Request Signing (JWS), Key Management OPENBANK-4 Third Party Provider (TPP) Onboarding, Directory Integration, Due Diligence OPENBANK-8 Incident Detection, Response, Customer Notification, Post-Incident Review, BCM SUPCHAIN-1 Build Integrity - Source, Build, Provenance SUPCHAIN-2 Source Integrity - Branch Protection, Code Review, Two-Person Rule SUPCHAIN-3 Dependency Verification and SBOM SSAE18-A1.1 A1.1 - Availability Commitments and Requirements SSAE18-CC6.2 CC6.2 - New User Registration and Authorization SSAE18-SOC1-06 Transaction Processing Controls SOCI-CIRMP-SUPPLY CIRMP hazard vector: Supply chain SOCI-S30BC Notification of critical cyber security incidents (12 hours) SOCI-S30BD Notification of other cyber security incidents (72 hours) ISMSP-AC-01 Access Control Policy ISMSP-AC-03 Authentication Mechanisms ISMSP-AC-04 Network Access Control ANSSI-HYG-13 Prefer Strong Authentication Where Possible ANSSI-HYG-32 Secure the Network Connection of Devices Used for Mobile Working CPS234-14 Definition of Information Security Roles and Responsibilities CPS234-15 Information Security Capability BSI-02 Access enforcement and least privilege BSI-03 Multi-factor authentication requirements BE-CF-02 Access enforcement and least privilege BE-CF-03 Multi-factor authentication requirements DSO-3 Data Access Management RMD-1 Reference Data Management Part11.300 Controls for identification codes and passwords (21 CFR §11.300) Part11.AccessAndAuth Access control + authority + device checks (21 CFR §11.10(d) + (f) + (g) + (h)) FTC-Safeguards-9-Elements 9 Safeguard Elements - Access, Inventory, Encryption, Secure-Dev, MFA, Disposal, Change-Mgmt, Monitoring, Pen-Test (16 CFR 314.4(c)) FTC-Safeguards-Risk-Assessment Written Risk Assessment (16 CFR 314.4(b)) FDBR-Scope-Defs Scope, Applicability Thresholds and Definitions (Fla. Stat. 501.701, 501.702, 501.703, 501.704) FDBR-SensitiveData-Children-VoiceFacial Sensitive Data, Children's Privacy and Voice/Facial Recognition (Fla. Stat. 501.711, 501.1735) HKMA-SPM-OR-RR-SA-OperationalResilience HKMA SPM Operational Risk (OR-1), Operational Resilience (OR-2), Recovery Planning (RR-1), Outsourcing (SA-2) HKMA-SPM-TM-Technology-TM-G-1-CRAF-Coord HKMA SPM Technology Management Modules (TM-G-1 to TM-G-4, TM-E-1) + Coordination with C-RAF IACS-UR-E26-Protect-NetworkSegmentation-Zones-Conduits-Boundary IACS UR E26 Protect Goal - Network Segmentation + Zones + Conduits + Boundary Defence + Data Diodes IACS-UR-E27-Equipment-UserAuth-Authentication-Authorization IACS UR E27 - Equipment User Authentication + Authorization + Session Management + Privileged Access 6.7 Remote working 8.5 Secure authentication 6.7 Remote working 8.5 Secure authentication ISO27799-01 ePHI access controls and authorization ISO27799-12 Unique user identification and authentication 27031-8.1 Exercising and Testing 27031-B High availability embedded systems ITAR-Part123-125-ExportLicensing-DSP-5-DSP-73-DSP-61-MLA-TAA-Classified-Information-Routed ITAR Parts 123-125 Export Licensing - DSP-5 Permanent Export + DSP-73 Temporary Export + DSP-61 Temporary Import + DSP-83 + Manufacturing License Agreements (MLA) + Technical Assistance Agreements (TAA) + Classified Information + Routed Export Transactions ITAR-TechnicalData-DefenseServices-DeemedExport-ForeignPerson-Access-USPersons-FOC-AUKUS-Exemptions ITAR Technical Data + Defense Services + Deemed Export Rule + Foreign Person Access + US Persons Only + FOCI Foreign Ownership Control Influence + AUKUS Pillar 2 Exemptions + DD-2345 MCTL BIPA-SEC5-1 Biometric Identifier Definition BIPA-SEC5-2 Biometric Information Definition MDS2-PHI-Data-Handling-DATA-Storage-STCF-Transmission-TXCF-TXIG-Encryption-FIPS MDS2 PHI Handling + DATA + STCF Storage + TXCF Transmission + TXIG Integrity + Encryption + FIPS MDS2-Person-Node-Authentication-Authorization-Auto-Logoff-AUTH-PAUT-NAUT MDS2 Authentication + Authorization + Auto Logoff + PAUT + NAUT + AUTH + Identity Management NAIC-1 NAIC Model Law Adoption, Scope, and Licensee Definitions NAIC-6 Cybersecurity Event Investigation and Notification - Sections 6 and 7 NISTSP123-3 Authentication, Access Control, and Account Management NISTSP123-6 Network Security and Server Communications NISTSP144-1 Cloud Governance, Risk Assessment, and Provider Trust Evaluation NISTSP144-2 Cloud Architecture, Service Selection, and Tenant Isolation NISTSP145-6 Deployment Model Classification (Private, Community, Public, Hybrid) NISTSP145-8 Governance, Reporting, and Stakeholder Education on Cloud Definition NISTSP146-4 IaaS Operational Recommendations and Workload Hardening NISTSP146-6 Cloud Security and Privacy Recommendations NISTSP61-4 Detection and Analysis: Sources, Triage, Categorisation, Prioritisation NISTSP61-5 Containment, Eradication, and Recovery NISTSP63R4-3 Authentication: Authenticator Types, MFA, Phishing-Resistance, and Syncable Authenticators NISTSP63R4-5 Federation: Assertions, Trust Agreements, RP Validation, Pseudonymous Identifiers NISTSP88-1 Media Sanitization Policy, Roles, and Decision Framework NISTSP88-8 Cloud-Resident Data, Hosted Storage, and Scope Boundaries NISTSP92-3 Log Infrastructure: Architecture, Centralisation, Transport Security, SIEM Governance NISTSP92-4 Log Management: Time Synchronisation, Parsing, Storage, Integrity, Access Control OWASPSAMM-2 Design: Threat Assessment, Security Requirements, Security Architecture OWASPSAMM-5 Operations: Incident Management, Environment Management, Operational Management OMANCS-3 Identity and Access Management, Authentication, Privileged Access OMANCS-5 Network, Endpoint, System Development, and Configuration Security PSDTWO-1 Strong Customer Authentication (SCA) Core Requirements PSDTWO-2 SCA Exemptions and Risk-Based Authentication PTESPHASE-2 Intelligence Gathering (OSINT) PTESPHASE-4 Vulnerability Analysis SASB-1 Business Model + Innovation (BMI) SASB-BMI-2 Business Model Resilience SHAREASSESS-2 Access Control, Identity, Authentication SHAREASSESS-4 Vulnerability Management, Patching, Application Security SAM-1 Customer Information Confidentiality (Section 48) SAM-6 Legal Authorization Requirements SEMD-CS-3 Cyber Resilience SEMD-ER-1 Emergency Exercise and Testing CPSC-CS.1 Network Security for Connected Products CPSC-CS.2 Authentication and Access Controls CERT-1 RRA Certification to EPA USSDWA-2 Cybersecurity Practices (Assessment, Access, Network, IR) VP-2 Holder Binding W3CVCDM-4 Accessibility, Internationalization, Security AMLCTF-35 Identity Verification Standard API1164-13 Business Continuity and Recovery BS65000-RM-03 Leadership and Culture BMA-9 Information Technology Services Management COBIT-BAI04 Managed availability and capacity FISMA-CIRCIA-ZTA-EO14028 CIRCIA, Zero Trust Architecture, EO 14028 + 14110 + OMB Memoranda FedRAMP-Boundary Authorization Boundary, SSP, SAR, POA&M documentation GLBA-Subordinate-Rules-Operationalisation GLBA Operationalisation through FTC Safeguards Rule, Privacy Rule, SEC Reg S-P and Banking-Agency Guidelines GLI33-PAM-KYC-AML-Payments GLI-33 Player Account Management, KYC, AML, Payment Processing and Account Lifecycle GhCSA-CII-Designation-Plan-Audit-Risk CII Designation, Registration, Cybersecurity Plan, Audit and Risk Assessment 164.312(d) Person or Entity Authentication (Standard) HITECH-SubtitleD-StrengthIndividualRights HITECH Subtitle D - Strengthened Individual Rights (Electronic Access, Accounting of Disclosures, Restrictions, Sale Prohibition) HKMA-CRAF-Domain5-6-Response-Recovery-SitAwareness HKMA C-RAF Domain 5 (Response and Recovery) + Domain 6 (Situational Awareness) - Incident Response, Recovery, Threat Landscape, Information Sharing ICAO-ANX17-Chap4-SpecialCategories-Weapons-InFlightSecurity-CockpitDoor ICAO Annex 17 Chapter 4 - Special Categories of Passengers + Weapons + In-Flight Security Officers + Flight Crew Compartment Door IEC62443-13 Network security monitoring IEEE1686-Section5.2-5.3-AuditLog-Retention-Export-Monitoring IEEE 1686 Section 5.2 + 5.3 - Audit Trail Records + Retention + Export + Supervisory Monitoring and Control + Network Security Monitoring IEEE7000-EthicalRisk-Identification-Analysis-Treatment-ValidationOutcomes IEEE 7000 Clauses 8 + 8.1 + 8.2 - Ethical Risk Identification + Analysis + Treatment + Validation of Ethical Outcomes + AI Safety + Robustness + Adversarial Protection IMO-MSC-FAL-Respond-IncidentResponse-Communication-FlagState-PortAuthority-CIRT-USCGNVIC IMO MSC-FAL Respond Function - Incident Response Plan + Containment + Communication + Flag State + Port Authority + USCG NVIC + Class Society Notification + CIRT IRM-RiskCategories-Strategic-Financial-Operational-Knowledge-FOIL-External-Internal-DownsideUpside IRM Four Risk Categories - Strategic + Financial + Operational + Knowledge + FOIL Typology + External vs Internal + Downside Threats and Upside Opportunities + Risk Universe ISO-19650-2-5.7 Information model delivery ISO28001-PS-01 Facility Security ISO20000-03 Capacity and availability management 23837-1.7.3 Authentication and classical post-processing ISO-25012-4.13 Availability 27007-5.4 Establishing the Programme Resources 27010-13.1 Communications Security ISO27019-13 Network security monitoring 27400-6.1 Secure Device Design ITIL4-03 Capacity and availability management JP-AIG-Safety-Validation-Testing-Robustness-AISI-AI-Safety-Institute-Pre-Deployment-Evaluation-Red-Teaming Japan AI Guidelines Safety + Validation + Testing + Robustness + AISI AI Safety Institute (14 Feb 2024) + Pre-Deployment Evaluation + Red Teaming + Capability Evaluations + AI Incident Database + Safe Deployment + AI Safety Reports LAOS-CC-Network-Security-Information-Security-Obligations-Article-21-Service-Provider-Duties Laos Cybercrime Network Security + Information Security Obligations + Article 21 + Service Provider Duties MMCL-5 Content Moderation, Removal Requests, and Lawful Access NATO-NCIRC-8 Cyberspace as Operational Domain + Cyber Defence Pledge + Annual Self-Assessment NERCCIP-5 System Security Management + Configuration Change Management and Vulnerability Assessments (CIP-007 + CIP-010) NISTSP115-8 Operational Considerations - Tools, Reporting Templates, ISMS Integration, Annex Material NISTSP137-6 Malware, Identity Access, and Network Boundary Monitoring NISTSP66-6 Technical Safeguards: Access Control, Audit Controls, Integrity, Person Authentication 164.312(d) Person or Entity Authentication (Standard) NGCB-6 Incident Response, 72-Hour NGCB Notification, and Independent Investigation NZISM-5 Network Security, System Hardening, and Application Security ORANWG11-2 O-RAN Interface Security: E2, A1, O1, O2, Open Fronthaul OECDAI-3 Robustness, Security, Safety, and Adversarial Attack Protection OSSFSC-3 Build, CI/CD Security, Workflow Permissions, Dangerous Patterns PASONE-4 Technical Security: CDE Configuration, BIM Tools, Encryption, Aggregation, Mobile Working PSPF24-2 Information Security, Cybersecurity Maturity, Essential Eight RCEPEC-1 Online Personal Information Protection (12.13) EHDSREG-6 Phased Application and Enforcement SOC-CY-A1 Availability Commitments CISABD-1 Take Ownership of Customer Security Outcomes SIGSTORE-2 Transparency Log (Rekor) and Verification SAPAIA-2 Right of Access and Request Processes KRCSAP-1 CSAP Certification Tiers (IaaS, SaaS, DaaS, AI) TEFCAREC-1 Common Agreement Conformance and Onboarding TSAPIPE-2 OT/IT Network Segmentation and Access Control UKAI-3 Bias Detection, Fairness, Validation UKOPRES-5 Third-Party Risk, Concentration Risk UK-TSA-NET-02 Access Control and Authentication ACE-CR-4 Cargo Release Authorization CYB-2 Account Security Measures USMCADIGITAL-2 Personal Information Protection and Consumer Protection UGA-10 Sensitive Personal Data Prohibition WCAGREC-3 Principle 3: Understandable Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Other controls in Limiting the Extent of Cyber Security Incidents You are reading one control. How much of ASD Strategies to Mitigate Cyber Security Incidents have you already done? ASD Strategies to Mitigate Cyber Security Incidents ASD37-20 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of ASD Strategies to Mitigate Cyber Security Incidents your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 32 of 37 ASD Strategies to Mitigate Cyber Security Incidents controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 0 were rejected on the NIST SP 800-53 Rev 5 pair alone.
Query this from an agent The graph holds this control, the 429 it maps to, and the evidence behind each claim, over MCP and REST.