MARS-E
Contingency Media Protection System Integrity - MARS-E v2.0

MARS-E MARS-E-Contingency-Media-Protection-System-Integrity-CP-MP-SI-Families-DR-COOP-Encryption-Sanitization: MARS-E Contingency + Media Protection + System Integrity + CP + MP + SI Families + DR + COOP

Implement NIST 800-53 CP Contingency Planning + MP Media Protection + SI System and Information Integrity families per MARS-E v2.0. Contingency Planning with Business Impact Analysis (BIA) + Recovery Time Objective (RTO) of 24 hours for Exchange consumer-facing systems + 48 hours for administrative + Recovery Point Objective (RPO) of 4 hours. Backup strategy with daily incremental + weekly full + off-site replication + tested restore quarterly. Disaster Recovery (DR) site geographically separated + tested annually full-scale. Continuity of Operations Plan (COOP) for Exchange essential functions during open enrolment + special enrolment periods. Media Protection with media marking + access controls + sanitisation per NIST 800-88 (clear + purge + destroy) + media transport protections + media accountability. Encryption FIPS 140-2 / 140-3 validated cryptographic modules for PII + PHI + FTI at rest and in transit + TLS 1.2 minimum (1.3 preferred) + AES-256 for data at rest. System Integrity with flaw remediation within 30 days for critical + 90 days for high + malicious code protection + information system monitoring + software firmware integrity verification + anti-tampering. Vulnerability disclosure programme aligned with CISA Binding Operational Directive 20-01 where applicable.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 118 controls across 52 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

ISO/IEC 27043:2015 · 5 controls

  • ISO27043-13 Authentication and password management
  • ISO27043-17 Encryption of data at rest
  • ISO27043-18 Encryption of data in transit
  • ISO27043-19 Certificate management
  • ISO27043-20 Key lifecycle management

ISO/SAE 21434 · 5 controls

  • ISO21434-13 Authentication and password management
  • ISO21434-16 Cryptographic policy and key management
  • ISO21434-17 Encryption of data at rest
  • ISO21434-18 Encryption of data in transit
  • ISO21434-19 Certificate management

ISO/IEC 23837:2023 · 4 controls

  • 23837-1.2 Normative references
  • 23837-1.5.2 Cryptographic module requirements
  • 23837-1.5.3 Network device testing requirements
  • 23837-1.7.3 Authentication and classical post-processing
  • 29115-11 Mapping other authentication schemes
  • 29115-12.1 Exchanging authentication results
  • 29115-12.2 Controls for mitigating threats
  • 29115-7.4 Level of Assurance 4 (LoA4)
  • PQC-2 FIPS 203 ML-KEM Implementation - Module-Lattice Key-Encapsulation Mechanism
  • PQC-5 Cryptographic Inventory and PQC Migration Roadmap
  • PQC-7 FIPS Validated Modules, HSM Readiness, and Algorithm Validation
  • PQC-8 Implementation Requirements - RNG, Side-Channel, Key Management, Operations, Incident Response
  • ASD37-17 TLS encryption between email servers (Limited)
  • ASD37-20 Multi-factor authentication (Essential)
  • ASD37-23 Protect authentication credentials (Excellent)
  • AWWA-2.2 Authentication Mechanisms
  • AWWA-3.2 Remote Access Security
  • AWWA-3.4 Encryption and Data Protection

FedRAMP Rev 5 · 3 controls

  • FEDRAMP-SC-13 Cryptographic Protection
  • FEDRAMP-SC-28 Protection of Information at Rest
  • FEDRAMP-SC-8 Transmission Confidentiality and Integrity

ISO 27799:2025 · 3 controls

  • ISO27799-02 ePHI encryption at rest and in transit
  • ISO27799-12 Unique user identification and authentication
  • ISO27799-16 Transmission security and encryption

OWASP ASVS · 3 controls

OWASP Top 10:2025 · 3 controls

  • OWASPTOP10-2 A02:2025 Cryptographic Failures and Secret Management
  • OWASPTOP10-4 A04:2025 Insecure Design and Business Logic (incl. A11 API Abuse)
  • OWASPTOP10-7 A07:2025 Identification and Authentication Failures

BSI IT-Grundschutz · 2 controls

  • BSI-03 Multi-factor authentication requirements
  • BSI-08 Cryptographic protection of data
  • CJIS-8 Media Protection
  • CJIS-9 System and Communications Protection
  • FDBR-Scope-Defs Scope, Applicability Thresholds and Definitions (Fla. Stat. 501.701, 501.702, 501.703, 501.704)
  • FDBR-SensitiveData-Children-VoiceFacial Sensitive Data, Children's Privacy and Voice/Facial Recognition (Fla. Stat. 501.711, 501.1735)

ISO/IEC 27400:2022 · 2 controls

  • 27400-6.1 Secure Device Design
  • 27400-6.2 Device Identity and Authentication
  • BIPA-SEC5-1 Biometric Identifier Definition
  • BIPA-SEC5-2 Biometric Information Definition
  • OWASPAPI-2 Broken Authentication and Token Management
  • OWASPAPI-6 Security Misconfiguration and Secure API Design
  • OWASPLLM-1 Prompt Injection and System Prompt Leakage (LLM01 + LLM07)
  • OWASPLLM-3 Sensitive Information Disclosure and Privacy (LLM02)

South Korea ISMS-P · 2 controls

  • ISMSP-AC-03 Authentication Mechanisms
  • ISMSP-SYS-02 Encryption Implementation
  • AMLCTF-35 Identity Verification Standard

APPI · 1 control

  • APPI-A34 Request for Correction, Addition or Deletion

Bahrain PDPL · 1 control

  • DSO-3 Data Access Management
  • FFIEC-09 Encryption and key management

FIDO2 / WebAuthn · 1 control

  • FTC-Safeguards-9-Elements 9 Safeguard Elements - Access, Inventory, Encryption, Secure-Dev, MFA, Disposal, Change-Mgmt, Monitoring, Pen-Test (16 CFR 314.4(c))
  • UAE-PDPL-Art.4_5 Lawful basis and principles for processing personal data (UAE PDPL Articles 4-5)
  • 62351-9 Cyber security key management

ISO/IEC 27010:2015 · 1 control

  • 27010-10.1 Cryptographic Protection

ISO/IEC 27011:2024 · 1 control

  • 27011-8.3 Cryptography and key management

MITRE D3FEND · 1 control

Malaysia PDPA 2010 · 1 control

  • MY-PDPA-Sensitive-Personal-Data-Section-40-Health-Religious-Political-Sexual-Children-Explicit-Consent Malaysia PDPA Sensitive Personal Data + Section 40 + Health + Religious + Political + Children + Explicit Consent
  • NISTSP34-3 Preventive Controls and Recovery Strategies: Backup, Alternate Sites, Equipment
  • DSOMM-4 Test and Verification - SAST, DAST, IAST, SCA, Penetration Testing
  • AUPRV-4 APP 10-11 Quality, Security of Personal Information
  • EHDSREG-6 Phased Application and Enforcement
  • RUSPD-2 Lawful Basis, Consent, Notice

SWIFT CSCF · 1 control

  • IM8-CLD.2 Cloud Security Controls
  • TEFCAREC-1 Common Agreement Conformance and Onboarding

Turkey KVKK · 1 control

  • TURKEYKVKK-2 Information Notice and Data Subject Rights
  • CPSC-CS.2 Authentication and Access Controls
  • USSDWA-2 Cybersecurity Practices (Assessment, Access, Network, IR)
  • USMCADIGITAL-2 Personal Information Protection and Consumer Protection
  • VERMONTAICDA-3 Bias Testing, Discrimination Prevention, Transparency

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 118 it maps to, and the evidence behind each claim, over MCP and REST.