Frameworks / NIST SP 800-137 / NISTSP137-6 NIST SP 800-137
Malware and Access Monitoring
NIST SP 800-137 NISTSP137-6: Malware, Identity Access, and Network Boundary Monitoring Monitor malware per Section 4.4 including signature-based AV + behavioral EDR + sandboxing + threat intel feed integration + Indicators of Compromise (IOCs) + Indicators of Attack (IOAs). Monitor identity and access per Section 4.5 including failed authentications + anomalous access + privilege escalations + after-hours access + UEBA (User and Entity Behavior Analytics) + impossible travel + dormant account use. Monitor network boundary per Section 4.6 including firewall logs + IDS/IPS + DLP + DNS + proxy + VPN + zero trust network access (ZTNA) + east-west traffic + microsegmentation effectiveness.
Maintained by Gerard Blokdyk · Verified against the published standard 31 May 2026 · Control text last updated 21 May 2026 What else in your programme already covers this This control maps to 204 controls across 69 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
ASD37-06 Email content filtering (Excellent) ASD37-12 Antivirus software with heuristics (Very Good) ASD37-16 Antivirus software with signatures (Limited) ASD37-18 Restrict administrative privileges (Essential) ASD37-20 Multi-factor authentication (Essential) ASD37-22 Network segmentation (Excellent) ASD37-23 Protect authentication credentials (Excellent) ASD37-25 Software firewall - inbound (Very Good) AWWA-1.3 Security Awareness and Training AWWA-2.1 User Access Management AWWA-2.2 Authentication Mechanisms AWWA-2.3 Account Management AWWA-2.4 Physical Access Controls AWWA-3.1 Network Segmentation AWWA-4.1 Malware Protection ISO27043-11 Access control policy and enforcement ISO27043-12 User access management and provisioning ISO27043-13 Authentication and password management ISO27043-14 Privileged access management ISO27043-15 Access review and recertification ISO27043-22 Protection from malware ISO27043-27 Network security management ISO21434-12 User access management and provisioning ISO21434-13 Authentication and password management ISO21434-14 Privileged access management ISO21434-15 Access review and recertification ISO21434-22 Protection from malware ISO21434-27 Network security management API1164-06 Access Control API1164-07 Remote Access API1164-09 Patch and Vulnerability Management API1164-12 Incident Response API1164-13 Business Continuity and Recovery BSI-01 Account management and provisioning BSI-02 Access enforcement and least privilege BSI-03 Multi-factor authentication requirements BSI-04 Remote access controls BSI-05 Wireless access restrictions CPG-1.A Changing Default Passwords CPG-1.C Unique Credentials CPG-1.D Revoking Credentials for Departing Employees CPG-4.C Basic Cybersecurity Training CPG-8.A Network Segmentation IEC62443-07 Personnel risk assessment IEC62443-08 Electronic access perimeter management IEC62443-10 Revocation of access procedures IEC62443-12 Malware prevention for operational systems IEC62443-13 Network security monitoring 27011-5.3 Segregation of duties 27011-6.3 Awareness and Training 27011-8.1 User Endpoint Devices 27011-8.2 Network security and segregation 27011-8.5 Vulnerability and malware management ISO27019-07 Personnel risk assessment ISO27019-08 Electronic access perimeter management ISO27019-10 Revocation of access procedures ISO27019-12 Malware prevention for operational systems ISO27019-13 Network security monitoring ISO27799-01 ePHI access controls and authorization ISO27799-08 Information access management ISO27799-12 Unique user identification and authentication ISO27799-17 Facility access controls 27010-12.2 Protection from malware 27010-13.1 Communications Security 27010-9.1 Access Control to Shared Information 27010-9.2 Authentication of Sources OWASPLLM-1 Prompt Injection and System Prompt Leakage (LLM01 + LLM07) OWASPLLM-2 Improper Output Handling and Misinformation (LLM05 + LLM09) OWASPLLM-3 Sensitive Information Disclosure and Privacy (LLM02) OWASPLLM-6 Excessive Agency and Unbounded Consumption (LLM06 + LLM10) ISMSP-AC-01 Access Control Policy ISMSP-AC-02 User Account Management ISMSP-AC-03 Authentication Mechanisms ISMSP-AC-04 Network Access Control CAT-D3-1 Preventative controls CAT-D4-3 Third-party access controls CAT-IRP-4 Organizational characteristics 29115-11 Mapping other authentication schemes 29115-12.1 Exchanging authentication results 29115-12.2 Controls for mitigating threats NIST-CSF-PR.AA-01 Identities and credentials for authorized users, services, and hardware are managed by the organization NIST-CSF-PR.AA-02 Identities are proofed and bound to credentials based on the context of interactions NIST-CSF-PR.AA-05 Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties OWASPAPI-1 Broken Object Level Authorization (BOLA) and BFLA OWASPAPI-2 Broken Authentication and Token Management OWASPAPI-3 Broken Object Property Level Authorization (BOPLA) DSOMM-1 Culture, Organization, Education, and Governance DSOMM-3 Build, Deployment, Infrastructure Hardening, and Secrets Management DSOMM-4 Test and Verification - SAST, DAST, IAST, SCA, Penetration Testing DSO-2 Data Security DSO-3 Data Access Management FDBR-Scope-Defs Scope, Applicability Thresholds and Definitions (Fla. Stat. 501.701, 501.702, 501.703, 501.704) FDBR-SensitiveData-Children-VoiceFacial Sensitive Data, Children's Privacy and Voice/Facial Recognition (Fla. Stat. 501.711, 501.1735) BIPA-SEC5-1 Biometric Identifier Definition BIPA-SEC5-2 Biometric Information Definition NISTPF-3 Control-P - Privacy Controls, Data Management, and Disassociated Processing NISTPF-5 Protect-P Access Control (PR.AC-P) PSPF24-2 Information Security, Cybersecurity Maturity, Essential Eight PSPF24-4 Physical Security IM8-SEC.2 Access Control IM8-SEC.3 Network Security CPSC-CS.1 Network Security for Connected Products CPSC-CS.2 Authentication and Access Controls AMLCTF-35 Identity Verification Standard APPI-A26 Report of Leakage to the Commission and Notification to the Person CA-ITSG33-SC-01 Security Control Catalogue CJIS-10 System and Information Integrity FFIEC-06 Network security and segmentation FTC-Safeguards-9-Elements 9 Safeguard Elements - Access, Inventory, Encryption, Secure-Dev, MFA, Disposal, Change-Mgmt, Monitoring, Pen-Test (16 CFR 314.4(c)) UAE-PDPL-Art.6_7 Sensitive personal data and children's data (UAE PDPL Articles 6-7) IATA-IOSA-Section8-SEC-SecurityManagement-AVSEC IATA IOSA Section 8 - SEC Security Management + Aviation Security Programme (AVSEC) + ICAO Annex 17 Alignment ICAO-ANX17-Chap2-ThreatAssessment-RiskManagement-Cyber-GASeP ICAO Annex 17 Chapter 2 - Threat Assessment + Risk Management + Cyber Threats to Critical Aviation Systems (Amendment 17/18) 62351-8 Role-based access control (RBAC) ISO-19650-2-5.7 Information model delivery ISO28001-PS-01 Facility Security ISO20000-15 Access management for services 23837-1.7.3 Authentication and classical post-processing 27400-6.1 Secure Device Design ITIL4-15 Access management for services NJDPA-2 Consumer Rights - Access, Correct, Delete, Portability, Appeal NZISM-5 Network Security, System Hardening, and Application Security AUPRV-4 APP 10-11 Quality, Security of Personal Information EHDSREG-6 Phased Application and Enforcement RUSPD-2 Lawful Basis, Consent, Notice PIPA-Cross-Border-Transfer-Articles-28-8-28-9-Adequacy-Standard-Contract-Certification-EU Korea PIPA Cross-Border Transfer + Articles 28-8 + 28-9 + Adequacy + EU 2021 TEFCAREC-1 Common Agreement Conformance and Onboarding TURKEYKVKK-2 Information Notice and Data Subject Rights ACE-CR-4 Cargo Release Authorization USSDWA-2 Cybersecurity Practices (Assessment, Access, Network, IR) CYB-2 Account Security Measures USMCADIGITAL-2 Personal Information Protection and Consumer Protection VERMONTAICDA-3 Bias Testing, Discrimination Prevention, Transparency Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Query this from an agent The graph holds this control, the 204 it maps to, and the evidence behind each claim, over MCP and REST.