ASD Strategies to Mitigate Cyber Security Incidents
Limiting the Extent of Cyber Security Incidents

ASD Strategies to Mitigate Cyber Security Incidents ASD37-20: Multi-factor authentication (Essential)

Multi-factor authentication including for VPNs, RDP, SSH and other remote access, and for all users when they perform a privileged action or access an important (sensitive/high-availability) data repository.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 429 controls across 167 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • NIST-CSF-PR.AA-01 Identities and credentials for authorized users, services, and hardware are managed by the organization
  • NIST-CSF-PR.AA-02 Identities are proofed and bound to credentials based on the context of interactions
  • NIST-CSF-PR.AA-03 Users, services, and hardware are authenticated
  • NIST-CSF-PR.AA-05 Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties
  • NIST-CSF-PR.DS-10 The confidentiality, integrity, and availability of data-in-use are protected
  • NIST-CSF-PR.IR-01 Networks and environments are protected from unauthorized logical access and usage
  • NIST-CSF-PR.IR-03 Mechanisms are implemented to achieve resilience requirements in normal and adverse situations
  • NIST-CSF-PR.IR-04 Adequate resource capacity to ensure availability is maintained

NIST SP 800-53 Rev 5 · 8 controls

CMMC 2.0 · 6 controls

SOC 2 · 6 controls

  • SOC2-A1.1 A1.1 Managing processing capacity
  • SOC2-A1.2 A1.2 Environmental protection, backup and recovery infrastructure
  • SOC2-A1.3 A1.3 Testing recovery plan procedures
  • SOC2-CC6.1 CC6.1 Logical access security over protected information assets
  • SOC2-CC6.2 CC6.2 Registering and authorising users before issuing credentials
  • SOC2-CC6.3 CC6.3 Role-based access, least privilege and segregation of duties

CIS Controls v8 · 5 controls

  • CIS-12.7 Ensure Remote Devices Utilize a VPN and are Connecting to an Enterprise’s AAA Infrastructure
  • CIS-13.5 Manage Access Control for Remote Assets
  • CIS-6.3 Require MFA for Externally-Exposed Applications
  • CIS-6.4 Require MFA for Remote Network Access
  • CIS-6.5 Require MFA for Administrative Access
  • CPG-1.A Changing Default Passwords
  • CPG-1.C Unique Credentials
  • CPG-1.D Revoking Credentials for Departing Employees
  • CPG-4.C Basic Cybersecurity Training
  • CPG-8.A Network Segmentation

PCI DSS 4.0 · 5 controls

  • 8.3.1 8.3.1 Access authenticated with at least one factor
  • 8.4.1 8.4.1 MFA for non-console administrative CDE access
  • 8.4.2 8.4.2 MFA for all non-console CDE access
  • 8.4.3 8.4.3 MFA for remote access that could reach CDE
  • 8.5.1 8.5.1 MFA system resistant to replay and bypass
  • IM8-DAT.2 Data Protection
  • IM8-DSS.2 Service Reliability Standards
  • IM8-RES.4 Resilience Testing
  • IM8-SEC.2 Access Control
  • IM8-SEC.3 Network Security
  • OB-API.4 MI Reporting Specification
  • OB-CX.3 Strong Customer Authentication
  • OB-DIR.1 Open Banking Directory
  • OB-OPS.1 API Availability Requirements
  • OB-SEC.4 Certificate Management
  • AWWA-1.3 Security Awareness and Training
  • AWWA-2.1 User Access Management
  • AWWA-2.2 Authentication Mechanisms
  • AWWA-3.1 Network Segmentation
  • FFIEC-06 Network security and segmentation
  • FFIEC-11 Business continuity planning and testing
  • FFIEC-12 Disaster recovery procedures
  • FFIEC-14 Critical service identification

FedRAMP High · 4 controls

  • AC-17 Remote Access
  • IA-2 Identification and Authentication (Organizational Users)
  • IA-2(1) MFA to Privileged Accounts
  • IA-2(2) MFA to Non-Privileged Accounts

FedRAMP Moderate · 4 controls

  • AC-17 Remote Access
  • IA-2 Identification and Authentication (Organizational Users)
  • IA-2(1) MFA to Privileged Accounts
  • IA-2(2) MFA to Non-Privileged Accounts
  • NISTPF-3 Control-P - Privacy Controls, Data Management, and Disassociated Processing
  • NISTPF-5 Protect-P Access Control (PR.AC-P)
  • NISTPF-6 Protect-P Data Security (PR.DS-P)
  • NISTPF-7 Protect-P Maintenance and Protective Technology (PR.MA-P, PR.PT-P)

NIST SP 800-171 Rev 3 · 4 controls

  • NISTSP82-1 OT Security Program Governance, Policy, Roles, and Safety-Security Integration
  • NISTSP82-2 OT Risk Assessment and Threat/Vulnerability Identification
  • NISTSP82-4 OT Access Control, Identity, Authentication, and Remote Access
  • NISTSP82-5 OT Configuration Management, Patching, Vulnerability Management, and Malware Protection
  • OWASPLLM-1 Prompt Injection and System Prompt Leakage (LLM01 + LLM07)
  • OWASPLLM-2 Improper Output Handling and Misinformation (LLM05 + LLM09)
  • OWASPLLM-3 Sensitive Information Disclosure and Privacy (LLM02)
  • OWASPLLM-6 Excessive Agency and Unbounded Consumption (LLM06 + LLM10)

PCI P2PE · 4 controls

  • PCI-P2PE-06 Network security and segmentation
  • PCI-P2PE-11 Business continuity planning and testing
  • PCI-P2PE-12 Disaster recovery procedures
  • PCI-P2PE-14 Critical service identification

PCI PIN Security · 4 controls

  • PCI-PIN-06 Network security and segmentation
  • PCI-PIN-13 Third-party dependency management
  • PCI-PIN-14 Critical service identification
  • PCI-PIN-15 Communication and escalation procedures

PCI SSF · 4 controls

  • PCI-SSF-06 Network security and segmentation
  • PCI-SSF-12 Disaster recovery procedures
  • PCI-SSF-14 Critical service identification
  • PCI-SSF-15 Communication and escalation procedures

UK Cyber Essentials · 4 controls

  • CE-AC.7 MFA for Administrative Accounts
  • CE-AC.8 Passwordless Authentication
  • CE-FW.3 Block Unauthenticated Inbound Connections
  • CE-SC.6 Multi-Factor Authentication for Cloud Services

ACSC Essential Eight · 3 controls

  • E8-MFA-ML1 Multi-Factor Authentication - Maturity Level 1
  • E8-MFA-ML2 Multi-Factor Authentication - Maturity Level 2
  • E8-MFA-ML3 Multi-Factor Authentication - Maturity Level 3
  • 4.3.2 Legal and Other Requirements
  • 4.4.1 Resources, Roles, Responsibility, and Authority
  • 4.4.2 Competence, Training, and Awareness
  • ASBv3-IM-2 Protect identity and authentication systems
  • IM-6 Use strong authentication controls
  • IM-7 Restrict resource access based on conditions

C5 (Germany) · 3 controls

  • CAT-D3-1 Preventative controls
  • CAT-D5-4 Resilience planning and testing
  • CAT-IRP-4 Organizational characteristics
  • 62351-12 Resilience and security recommendations for DER
  • 62351-13 Cyber-physical generation and storage resilience
  • 62351-8 Role-based access control (RBAC)

ISO/IEC 27011:2024 · 3 controls

  • 27011-6.3 Awareness and Training
  • 27011-8.1 User Endpoint Devices
  • 27011-8.2 Network security and segregation

ISO/IEC 27043:2015 · 3 controls

  • ISO27043-13 Authentication and password management
  • ISO27043-14 Privileged access management
  • ISO27043-27 Network security management
  • 29115-11 Mapping other authentication schemes
  • 29115-12.1 Exchanging authentication results
  • 29115-12.2 Controls for mitigating threats

ISO/SAE 21434 · 3 controls

  • ISO21434-13 Authentication and password management
  • ISO21434-14 Privileged access management
  • ISO21434-27 Network security management

MARS-E · 3 controls

MTCS (Singapore) · 3 controls

  • MTCS-Asset-IAM-Cryptography-Multi-Tier-Asset-Inventory-RBAC-MFA-PAM-FIPS-HSM-Quantum-Safe MTCS Asset Mgmt + IAM + Cryptography + Asset Inventory + RBAC + MFA + PAM + FIPS + HSM + Quantum-Safe
  • MTCS-Incident-Business-Continuity-CSC-Data-Protection-72-Hour-Notification-BCP-DR-PDPA MTCS Incident + Business Continuity + CSC Data Protection + 72-Hour Notification + BCP + DR + PDPA
  • MTCS-Logging-Monitoring-Compliance-Audit-SLA-Configuration-SIEM-SOAR-Cloud-Monitoring-CSPM MTCS Logging + Monitoring + Compliance + Audit + SLA + Configuration + SIEM + SOAR + CSPM
  • MAS-TRM-Cyber-Resilience-Chapter-11-Threat-Intelligence-Penetration-Testing-Incident-Response-1-Hour-Notification MAS TRM Cyber Resilience + Chapter 11 + Threat Intelligence + Penetration Testing + Incident Response + 1-Hour Notification
  • MAS-TRM-Project-SDLC-Service-Management-Chapters-4-5-6-IT-Project-Software-Lifecycle-Change-ITIL MAS TRM Project + SDLC + Service Management + Chapters 4-6 + IT Project + Software Lifecycle + ITIL
  • MAS-TRM-Reliability-Data-Centre-Chapters-7-8-RTO-RPO-BCP-DR-System-Availability-4-Hours-12-Months MAS TRM Reliability + Data Centre + Chapters 7-8 + RTO + RPO + BCP + DR + System Availability 4 Hours 12 Months

NIST SP 800-190 · 3 controls

OSFI B-13 · 3 controls

  • OSFIB13-3 Cyber Security: Identification, Protection, Detection, Response, Recovery
  • OSFIB13-4 Third-Party Risk Management and Cloud
  • OSFIB13-7 Incident Reporting to OSFI and Regulatory Coordination

OWASP ASVS · 3 controls

  • DSOMM-1 Culture, Organization, Education, and Governance
  • DSOMM-3 Build, Deployment, Infrastructure Hardening, and Secrets Management
  • DSOMM-4 Test and Verification - SAST, DAST, IAST, SCA, Penetration Testing

Open Banking Security · 3 controls

  • OPENBANK-3 Mutual TLS, Token Binding, Request Signing (JWS), Key Management
  • OPENBANK-4 Third Party Provider (TPP) Onboarding, Directory Integration, Due Diligence
  • OPENBANK-8 Incident Detection, Response, Customer Notification, Post-Incident Review, BCM

SLSA · 3 controls

  • SUPCHAIN-1 Build Integrity - Source, Build, Provenance
  • SUPCHAIN-2 Source Integrity - Branch Protection, Code Review, Two-Person Rule
  • SUPCHAIN-3 Dependency Verification and SBOM
  • SSAE18-A1.1 A1.1 - Availability Commitments and Requirements
  • SSAE18-CC6.2 CC6.2 - New User Registration and Authorization
  • SSAE18-SOC1-06 Transaction Processing Controls
  • SOCI-CIRMP-SUPPLY CIRMP hazard vector: Supply chain
  • SOCI-S30BC Notification of critical cyber security incidents (12 hours)
  • SOCI-S30BD Notification of other cyber security incidents (72 hours)

South Korea ISMS-P · 3 controls

  • ISMSP-AC-01 Access Control Policy
  • ISMSP-AC-03 Authentication Mechanisms
  • ISMSP-AC-04 Network Access Control
  • ANSSI-HYG-13 Prefer Strong Authentication Where Possible
  • ANSSI-HYG-32 Secure the Network Connection of Devices Used for Mobile Working

APRA CPS 234 · 2 controls

  • CPS234-14 Definition of Information Security Roles and Responsibilities
  • CPS234-15 Information Security Capability

BSI IT-Grundschutz · 2 controls

  • BSI-02 Access enforcement and least privilege
  • BSI-03 Multi-factor authentication requirements
  • BE-CF-02 Access enforcement and least privilege
  • BE-CF-03 Multi-factor authentication requirements
  • DSO-3 Data Access Management
  • RMD-1 Reference Data Management

FDA 21 CFR Part 11 · 2 controls

  • Part11.300 Controls for identification codes and passwords (21 CFR §11.300)
  • Part11.AccessAndAuth Access control + authority + device checks (21 CFR §11.10(d) + (f) + (g) + (h))

FIDO2 / WebAuthn · 2 controls

  • FTC-Safeguards-9-Elements 9 Safeguard Elements - Access, Inventory, Encryption, Secure-Dev, MFA, Disposal, Change-Mgmt, Monitoring, Pen-Test (16 CFR 314.4(c))
  • FTC-Safeguards-Risk-Assessment Written Risk Assessment (16 CFR 314.4(b))
  • FDBR-Scope-Defs Scope, Applicability Thresholds and Definitions (Fla. Stat. 501.701, 501.702, 501.703, 501.704)
  • FDBR-SensitiveData-Children-VoiceFacial Sensitive Data, Children's Privacy and Voice/Facial Recognition (Fla. Stat. 501.711, 501.1735)

HKMA SPM · 2 controls

  • HKMA-SPM-OR-RR-SA-OperationalResilience HKMA SPM Operational Risk (OR-1), Operational Resilience (OR-2), Recovery Planning (RR-1), Outsourcing (SA-2)
  • HKMA-SPM-TM-Technology-TM-G-1-CRAF-Coord HKMA SPM Technology Management Modules (TM-G-1 to TM-G-4, TM-E-1) + Coordination with C-RAF
  • IACS-UR-E26-Protect-NetworkSegmentation-Zones-Conduits-Boundary IACS UR E26 Protect Goal - Network Segmentation + Zones + Conduits + Boundary Defence + Data Diodes
  • IACS-UR-E27-Equipment-UserAuth-Authentication-Authorization IACS UR E27 - Equipment User Authentication + Authorization + Session Management + Privileged Access

ISMAP (Japan) · 2 controls

ISO 27001:2022 · 2 controls

  • 6.7 Remote working
  • 8.5 Secure authentication

ISO 27002:2022 · 2 controls

  • 6.7 Remote working
  • 8.5 Secure authentication

ISO 27799:2025 · 2 controls

  • ISO27799-01 ePHI access controls and authorization
  • ISO27799-12 Unique user identification and authentication

ISO/IEC 27031:2011 · 2 controls

  • 27031-8.1 Exercising and Testing
  • 27031-B High availability embedded systems
  • ITAR-Part123-125-ExportLicensing-DSP-5-DSP-73-DSP-61-MLA-TAA-Classified-Information-Routed ITAR Parts 123-125 Export Licensing - DSP-5 Permanent Export + DSP-73 Temporary Export + DSP-61 Temporary Import + DSP-83 + Manufacturing License Agreements (MLA) + Technical Assistance Agreements (TAA) + Classified Information + Routed Export Transactions
  • ITAR-TechnicalData-DefenseServices-DeemedExport-ForeignPerson-Access-USPersons-FOC-AUKUS-Exemptions ITAR Technical Data + Defense Services + Deemed Export Rule + Foreign Person Access + US Persons Only + FOCI Foreign Ownership Control Influence + AUKUS Pillar 2 Exemptions + DD-2345 MCTL
  • BIPA-SEC5-1 Biometric Identifier Definition
  • BIPA-SEC5-2 Biometric Information Definition

MDS2 (Medical Device) · 2 controls

  • MDS2-PHI-Data-Handling-DATA-Storage-STCF-Transmission-TXCF-TXIG-Encryption-FIPS MDS2 PHI Handling + DATA + STCF Storage + TXCF Transmission + TXIG Integrity + Encryption + FIPS
  • MDS2-Person-Node-Authentication-Authorization-Auto-Logoff-AUTH-PAUT-NAUT MDS2 Authentication + Authorization + Auto Logoff + PAUT + NAUT + AUTH + Identity Management

MITRE ATT&CK · 2 controls

MITRE D3FEND · 2 controls

  • NAIC-1 NAIC Model Law Adoption, Scope, and Licensee Definitions
  • NAIC-6 Cybersecurity Event Investigation and Notification - Sections 6 and 7

NIST SP 800-123 · 2 controls

  • NISTSP123-3 Authentication, Access Control, and Account Management
  • NISTSP123-6 Network Security and Server Communications

NIST SP 800-144 · 2 controls

  • NISTSP144-1 Cloud Governance, Risk Assessment, and Provider Trust Evaluation
  • NISTSP144-2 Cloud Architecture, Service Selection, and Tenant Isolation

NIST SP 800-145 · 2 controls

  • NISTSP145-6 Deployment Model Classification (Private, Community, Public, Hybrid)
  • NISTSP145-8 Governance, Reporting, and Stakeholder Education on Cloud Definition

NIST SP 800-146 · 2 controls

  • NISTSP146-4 IaaS Operational Recommendations and Workload Hardening
  • NISTSP146-6 Cloud Security and Privacy Recommendations

NIST SP 800-161 Rev 1 · 2 controls

NIST SP 800-61 Rev. 3 · 2 controls

  • NISTSP61-4 Detection and Analysis: Sources, Triage, Categorisation, Prioritisation
  • NISTSP61-5 Containment, Eradication, and Recovery

NIST SP 800-63-4 · 2 controls

  • NISTSP63R4-3 Authentication: Authenticator Types, MFA, Phishing-Resistance, and Syncable Authenticators
  • NISTSP63R4-5 Federation: Assertions, Trust Agreements, RP Validation, Pseudonymous Identifiers

NIST SP 800-88 · 2 controls

  • NISTSP88-1 Media Sanitization Policy, Roles, and Decision Framework
  • NISTSP88-8 Cloud-Resident Data, Hosted Storage, and Scope Boundaries

NIST SP 800-92 · 2 controls

  • NISTSP92-3 Log Infrastructure: Architecture, Centralisation, Transport Security, SIEM Governance
  • NISTSP92-4 Log Management: Time Synchronisation, Parsing, Storage, Integrity, Access Control

OWASP MASVS · 2 controls

OWASP SAMM · 2 controls

  • OWASPSAMM-2 Design: Threat Assessment, Security Requirements, Security Architecture
  • OWASPSAMM-5 Operations: Incident Management, Environment Management, Operational Management
  • OMANCS-3 Identity and Access Management, Authentication, Privileged Access
  • OMANCS-5 Network, Endpoint, System Development, and Configuration Security

PSD2 SCA · 2 controls

  • PSDTWO-1 Strong Customer Authentication (SCA) Core Requirements
  • PSDTWO-2 SCA Exemptions and Risk-Based Authentication

PTES · 2 controls

  • PTESPHASE-2 Intelligence Gathering (OSINT)
  • PTESPHASE-4 Vulnerability Analysis

SASB Standards · 2 controls

  • SASB-1 Business Model + Innovation (BMI)
  • SASB-BMI-2 Business Model Resilience
  • SHAREASSESS-2 Access Control, Identity, Authentication
  • SHAREASSESS-4 Vulnerability Management, Patching, Application Security
  • SAM-1 Customer Information Confidentiality (Section 48)
  • SAM-6 Legal Authorization Requirements
  • SEMD-CS-3 Cyber Resilience
  • SEMD-ER-1 Emergency Exercise and Testing
  • CPSC-CS.1 Network Security for Connected Products
  • CPSC-CS.2 Authentication and Access Controls
  • CERT-1 RRA Certification to EPA
  • USSDWA-2 Cybersecurity Practices (Assessment, Access, Network, IR)
  • VP-2 Holder Binding
  • W3CVCDM-4 Accessibility, Internationalization, Security
  • AMLCTF-35 Identity Verification Standard

API 1164 · 1 control

  • API1164-13 Business Continuity and Recovery
  • BS65000-RM-03 Leadership and Culture
  • BMA-9 Information Technology Services Management

COBIT 2019 · 1 control

  • COBIT-BAI04 Managed availability and capacity

FISMA · 1 control

  • FISMA-CIRCIA-ZTA-EO14028 CIRCIA, Zero Trust Architecture, EO 14028 + 14110 + OMB Memoranda

FedRAMP Rev 5 · 1 control

  • FedRAMP-Boundary Authorization Boundary, SSP, SAR, POA&M documentation

GLBA · 1 control

  • GLBA-Subordinate-Rules-Operationalisation GLBA Operationalisation through FTC Safeguards Rule, Privacy Rule, SEC Reg S-P and Banking-Agency Guidelines
  • GLI33-PAM-KYC-AML-Payments GLI-33 Player Account Management, KYC, AML, Payment Processing and Account Lifecycle
  • GhCSA-CII-Designation-Plan-Audit-Risk CII Designation, Registration, Cybersecurity Plan, Audit and Risk Assessment

HIPAA Security Rule · 1 control

  • 164.312(d) Person or Entity Authentication (Standard)

HITECH Act · 1 control

  • HITECH-SubtitleD-StrengthIndividualRights HITECH Subtitle D - Strengthened Individual Rights (Electronic Access, Accounting of Disclosures, Restrictions, Sale Prohibition)
  • HKMA-CRAF-Domain5-6-Response-Recovery-SitAwareness HKMA C-RAF Domain 5 (Response and Recovery) + Domain 6 (Situational Awareness) - Incident Response, Recovery, Threat Landscape, Information Sharing
  • ICAO-ANX17-Chap4-SpecialCategories-Weapons-InFlightSecurity-CockpitDoor ICAO Annex 17 Chapter 4 - Special Categories of Passengers + Weapons + In-Flight Security Officers + Flight Crew Compartment Door

IEC 62443 · 1 control

  • IEC62443-13 Network security monitoring

IEEE 1686 · 1 control

  • IEEE1686-Section5.2-5.3-AuditLog-Retention-Export-Monitoring IEEE 1686 Section 5.2 + 5.3 - Audit Trail Records + Retention + Export + Supervisory Monitoring and Control + Network Security Monitoring

IEEE 7000 · 1 control

  • IEEE7000-EthicalRisk-Identification-Analysis-Treatment-ValidationOutcomes IEEE 7000 Clauses 8 + 8.1 + 8.2 - Ethical Risk Identification + Analysis + Treatment + Validation of Ethical Outcomes + AI Safety + Robustness + Adversarial Protection
  • IMO-MSC-FAL-Respond-IncidentResponse-Communication-FlagState-PortAuthority-CIRT-USCGNVIC IMO MSC-FAL Respond Function - Incident Response Plan + Containment + Communication + Flag State + Port Authority + USCG NVIC + Class Society Notification + CIRT
  • IRM-RiskCategories-Strategic-Financial-Operational-Knowledge-FOIL-External-Internal-DownsideUpside IRM Four Risk Categories - Strategic + Financial + Operational + Knowledge + FOIL Typology + External vs Internal + Downside Threats and Upside Opportunities + Risk Universe
  • ISO28001-PS-01 Facility Security
  • ISO20000-03 Capacity and availability management

ISO/IEC 23837:2023 · 1 control

  • 23837-1.7.3 Authentication and classical post-processing
  • ISO-25012-4.13 Availability

ISO/IEC 27007:2020 · 1 control

  • 27007-5.4 Establishing the Programme Resources

ISO/IEC 27010:2015 · 1 control

  • 27010-13.1 Communications Security

ISO/IEC 27019:2024 · 1 control

  • ISO27019-13 Network security monitoring

ISO/IEC 27400:2022 · 1 control

  • 27400-6.1 Secure Device Design

ITIL 4 · 1 control

  • ITIL4-03 Capacity and availability management

Japan AI Guidelines · 1 control

  • JP-AIG-Safety-Validation-Testing-Robustness-AISI-AI-Safety-Institute-Pre-Deployment-Evaluation-Red-Teaming Japan AI Guidelines Safety + Validation + Testing + Robustness + AISI AI Safety Institute (14 Feb 2024) + Pre-Deployment Evaluation + Red Teaming + Capability Evaluations + AI Incident Database + Safe Deployment + AI Safety Reports
  • LAOS-CC-Network-Security-Information-Security-Obligations-Article-21-Service-Provider-Duties Laos Cybercrime Network Security + Information Security Obligations + Article 21 + Service Provider Duties

MiFID II / MiFIR · 1 control

  • MMCL-5 Content Moderation, Removal Requests, and Lawful Access
  • NATO-NCIRC-8 Cyberspace as Operational Domain + Cyber Defence Pledge + Annual Self-Assessment

NERC CIP · 1 control

  • NERCCIP-5 System Security Management + Configuration Change Management and Vulnerability Assessments (CIP-007 + CIP-010)

NIST SP 1800-32 · 1 control

  • NISTSP115-8 Operational Considerations - Tools, Reporting Templates, ISMS Integration, Annex Material

NIST SP 800-137 · 1 control

  • NISTSP137-6 Malware, Identity Access, and Network Boundary Monitoring

NIST SP 800-66 · 1 control

  • NISTSP66-6 Technical Safeguards: Access Control, Audit Controls, Integrity, Person Authentication
  • 164.312(d) Person or Entity Authentication (Standard)
  • NGCB-6 Incident Response, 72-Hour NGCB Notification, and Independent Investigation
  • NZISM-5 Network Security, System Hardening, and Application Security
  • ORANWG11-2 O-RAN Interface Security: E2, A1, O1, O2, Open Fronthaul

OECD AI Principles · 1 control

  • OECDAI-3 Robustness, Security, Safety, and Adversarial Attack Protection

OWASP Top 10:2025 · 1 control

OpenSSF Scorecard · 1 control

  • OSSFSC-3 Build, CI/CD Security, Workflow Permissions, Dangerous Patterns
  • PASONE-4 Technical Security: CDE Configuration, BIM Tools, Encryption, Aggregation, Mobile Working
  • PSPF24-2 Information Security, Cybersecurity Maturity, Essential Eight
  • RCEPEC-1 Online Personal Information Protection (12.13)
  • EHDSREG-6 Phased Application and Enforcement
  • SOC-CY-A1 Availability Commitments
  • CISABD-1 Take Ownership of Customer Security Outcomes
  • SIGSTORE-2 Transparency Log (Rekor) and Verification
  • SAPAIA-2 Right of Access and Request Processes
  • KRCSAP-1 CSAP Certification Tiers (IaaS, SaaS, DaaS, AI)
  • TEFCAREC-1 Common Agreement Conformance and Onboarding
  • TSAPIPE-2 OT/IT Network Segmentation and Access Control
  • UKAI-3 Bias Detection, Fairness, Validation
  • UKOPRES-5 Third-Party Risk, Concentration Risk
  • UK-TSA-NET-02 Access Control and Authentication
  • ACE-CR-4 Cargo Release Authorization
  • USMCADIGITAL-2 Personal Information Protection and Consumer Protection
  • UGA-10 Sensitive Personal Data Prohibition

WCAG 2.2 · 1 control

  • WCAGREC-3 Principle 3: Understandable

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Limiting the Extent of Cyber Security Incidents

You are reading one control. How much of ASD Strategies to Mitigate Cyber Security Incidents have you already done?

ASD Strategies to Mitigate Cyber Security Incidents ASD37-20 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of ASD Strategies to Mitigate Cyber Security Incidents your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 32 of 37 ASD Strategies to Mitigate Cyber Security Incidents controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 0 were rejected on the NIST SP 800-53 Rev 5 pair alone.

Query this from an agent

The graph holds this control, the 429 it maps to, and the evidence behind each claim, over MCP and REST.