FFIEC Cybersecurity Assessment Tool (CAT)
Domain 3: Cybersecurity Controls

FFIEC Cybersecurity Assessment Tool (CAT) CAT-D3-1: Preventative controls

Maturity of preventative controls including access management, device security, and network security

Maintained by Gerard BlokdykControl text last updated

What else in your programme already covers this

This control maps to 299 controls across 148 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • ASD37-12 Antivirus software with heuristics (Very Good)
  • ASD37-16 Antivirus software with signatures (Limited)
  • ASD37-20 Multi-factor authentication (Essential)
  • ASD37-22 Network segmentation (Excellent)
  • ASD37-25 Software firewall - inbound (Very Good)

API 1164 · 4 controls

IEC 62443 · 4 controls

ISO 27019 · 4 controls

ISO 27043 · 4 controls

ISO/IEC 27011:2024 · 4 controls

ISO/SAE 21434 · 4 controls

MARS-E · 4 controls

NIST SP 1800-32 · 4 controls

BSI IT-Grundschutz · 3 controls

  • BSI-03 Multi-factor authentication requirements
  • BSI-04 Remote access controls
  • BSI-05 Wireless access restrictions

ISO 13485 · 3 controls

ISO 27799 · 3 controls

ISO/IEC 27010:2015 · 3 controls

MDS2 (Medical Device) · 3 controls

MITRE ATT&CK · 3 controls

NIST SP 800-53 Rev 5 · 3 controls

NIST SP 800-66 · 3 controls

  • NISTSP66-2 Workforce Security, Information Access Management, and Awareness Training
  • NISTSP66-5 Physical Safeguards: Facility Access, Workstation Use and Security, Device and Media Controls
  • NISTSP66-6 Technical Safeguards: Access Control, Audit Controls, Integrity, Person Authentication

SLSA · 3 controls

  • SUPCHAIN-1 Build Integrity - Source, Build, Provenance
  • SUPCHAIN-2 Source Integrity - Branch Protection, Code Review, Two-Person Rule
  • SUPCHAIN-3 Dependency Verification and SBOM
  • CPG-1.D Revoking Credentials for Departing Employees
  • CPG-8.A Network Segmentation
  • FFIEC-06 Network security and segmentation
  • FFIEC-07 Endpoint protection and detection

IEEE 1686 · 2 controls

MITRE D3FEND · 2 controls

  • NIS2I-6 Access Control, Asset Management, and Physical Security
  • NIS2I-7 Network Security, Logging, Monitoring, and Vulnerability Handling
  • NISTPF-5 Protect-P Access Control (PR.AC-P)
  • NISTPF-8 Protect-P Information Protection Processes (PR.PO-P)

NIST SP 800-123 · 2 controls

  • NISTSP123-3 Authentication, Access Control, and Account Management
  • NISTSP123-6 Network Security and Server Communications

NIST SP 800-61 · 2 controls

  • NISTSP61-4 Detection and Analysis: Sources, Triage, Categorisation, Prioritisation
  • NISTSP61-5 Containment, Eradication, and Recovery

NIST SP 800-63-4 · 2 controls

  • NISTSP63R4-3 Authentication: Authenticator Types, MFA, Phishing-Resistance, and Syncable Authenticators
  • NISTSP63R4-5 Federation: Assertions, Trust Agreements, RP Validation, Pseudonymous Identifiers
  • NISTSP82-4 OT Access Control, Identity, Authentication, and Remote Access
  • NISTSP82-5 OT Configuration Management, Patching, Vulnerability Management, and Malware Protection

NIST SP 800-88 · 2 controls

  • NISTSP88-1 Media Sanitization Policy, Roles, and Decision Framework
  • NISTSP88-8 Cloud-Resident Data, Hosted Storage, and Scope Boundaries

NIST SP 800-92 · 2 controls

  • NISTSP92-3 Log Infrastructure: Architecture, Centralisation, Transport Security, SIEM Governance
  • NISTSP92-4 Log Management: Time Synchronisation, Parsing, Storage, Integrity, Access Control
  • NDPA-1 Applicability, Scope, and Carve-Outs
  • NDPA-2 Consumer Rights - Access, Correct, Delete, Portability, Appeal
  • NG-NDPA-1 Scope, Applicability, and Establishment of Nigeria Data Protection Commission
  • NG-NDPA-2 Lawful Basis, Consent, and Data Protection Principles

OWASP MASVS · 2 controls

OWASP SAMM · 2 controls

  • OWASPSAMM-2 Design: Threat Assessment, Security Requirements, Security Architecture
  • OWASPSAMM-5 Operations: Incident Management, Environment Management, Operational Management
  • OMANCS-3 Identity and Access Management, Authentication, Privileged Access
  • OMANCS-5 Network, Endpoint, System Development, and Configuration Security

PCI P2PE · 2 controls

PCI PIN Security · 2 controls

PCI SSF · 2 controls

PTES · 2 controls

  • PSPF24-2 Information Security, Cybersecurity Maturity, Essential Eight
  • PSPF24-4 Physical Security

South Korea ISMS-P · 2 controls

  • CPSC-CS.1 Network Security for Connected Products
  • CPSC-CS.2 Authentication and Access Controls

APPI · 1 control

  • APPI-A26 Report of Leakage to the Commission and Notification to the Person

Bahrain PDPL · 1 control

FDA 21 CFR Part 11 · 1 control

  • Part11.AccessAndAuth Access control + authority + device checks (21 CFR §11.10(d) + (f) + (g) + (h))

FISMA · 1 control

  • FTC-Safeguards-9-Elements 9 Safeguard Elements - Access, Inventory, Encryption, Secure-Dev, MFA, Disposal, Change-Mgmt, Monitoring, Pen-Test (16 CFR 314.4(c))
  • FERPA-Safeguards-PTAC Data Security Safeguards for PII in Education Records (PTAC Best Practices, SPPO Guidance)

FedRAMP Rev 5 · 1 control

  • UAE-PDPL-Art.6_7 Sensitive personal data and children's data (UAE PDPL Articles 6-7)

GLBA · 1 control

HITECH Act · 1 control

HKMA SPM · 1 control

  • 62351-8 Role-based access control (RBAC)

ISMAP (Japan) · 1 control

ISO 20000-1 · 1 control

ISO 27017 · 1 control

ISO 27018 · 1 control

ITIL 4 · 1 control

India DPDP Act · 1 control

Indonesia PDP Law · 1 control

LGPD · 1 control

Liechtenstein DPA · 1 control

MTCS (Singapore) · 1 control

Malaysia PDPA 2010 · 1 control

Mauritius DPA · 1 control

Mexico LFPDPPP · 1 control

  • MMCL-5 Content Moderation, Removal Requests, and Lawful Access
  • NAIC-2 Information Security Program (ISP) - Section 4

NERC CIP · 1 control

  • NERCCIP-5 System Security Management + Configuration Change Management and Vulnerability Assessments (CIP-007 + CIP-010)
  • NISTSP115-8 Operational Considerations - Tools, Reporting Templates, ISMS Integration, Annex Material

NIST SP 800-122 · 1 control

  • NISTSP122-5 PII Security Controls - Encryption, Access Control, Storage, Audit

NIST SP 800-137 · 1 control

  • NISTSP137-6 Malware, Identity Access, and Network Boundary Monitoring

NIST SP 800-144 · 1 control

  • NISTSP144-2 Cloud Architecture, Service Selection, and Tenant Isolation

NIST SP 800-145 · 1 control

  • NISTSP145-6 Deployment Model Classification (Private, Community, Public, Hybrid)

NIST SP 800-146 · 1 control

  • NISTSP146-4 IaaS Operational Recommendations and Workload Hardening
  • 3.10 Encrypt Sensitive Data in Transit

NIST SP 800-190 · 1 control

  • NHPA-7 Data Protection Assessments and Processor Contracts
  • NJDPA-2 Consumer Rights - Access, Correct, Delete, Portability, Appeal
  • NZISM-5 Network Security, System Hardening, and Application Security
  • NGNDPR-5 Security of Personal Data, Breach Notification, and DPIA under NDPR Section 2.6-Security
  • ORANWG11-2 O-RAN Interface Security: E2, A1, O1, O2, Open Fronthaul

OSFI B-13 · 1 control

  • OSFIB13-3 Cyber Security: Identification, Protection, Detection, Response, Recovery
  • DSOMM-3 Build, Deployment, Infrastructure Hardening, and Secrets Management

OWASP Top 10:2025 · 1 control

  • OPENBANK-3 Mutual TLS, Token Binding, Request Signing (JWS), Key Management

OpenSSF Scorecard · 1 control

  • OSSFSC-3 Build, CI/CD Security, Workflow Permissions, Dangerous Patterns
  • OREGONCPA-5 Data Protection Assessments, Privacy by Design, Security Practices
  • PASONE-4 Technical Security: CDE Configuration, BIM Tools, Encryption, Aggregation, Mobile Working

PDPA Singapore · 1 control

  • PDPASG-5 Protection, Accuracy, and Security of Personal Data

PDPA Thailand · 1 control

  • PDPATH-5 Security Measures and Data Protection

POPIA · 1 control

  • POPIASA-5 Security Safeguards, Encryption, Access Control, Operator Obligations

PSD2 SCA · 1 control

  • PSDTWO-1 Strong Customer Authentication (SCA) Core Requirements
  • NORWAY-5 Security of Processing, Encryption, Pseudonymization, Access Control

Peru DPL · 1 control

  • PERU-7 DPO, Records, Retention, Marketing, Training

Privacy Act 2020 · 1 control

  • NZPRV-2 IPP 5 Storage and Security of Personal Information

Qatar DPL · 1 control

SOC 2 · 1 control

  • SOC2-CC6.3 Role-based access and least privilege are enforced
  • SOC-CY-S1 Logical and Physical Access Controls

Saudi Arabia PDPL · 1 control

  • SIGSTORE-2 Transparency Log (Rekor) and Verification

South Korea PIPA · 1 control

  • TSAPIPE-2 OT/IT Network Segmentation and Access Control

Taiwan PDPA · 1 control

Turkey KVKK · 1 control

  • USSDWA-2 Cybersecurity Practices (Assessment, Access, Network, IR)

Uruguay DPL · 1 control

  • URUGUAY-3 Sensitive Data, Health Data, Children

Vietnam PDPD · 1 control

Virginia CDPA · 1 control

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Domain 3: Cybersecurity Controls

Query this from an agent

The graph holds this control, the 299 it maps to, and the evidence behind each claim, over MCP and REST.