Frameworks / NIST SP 800-66 Rev 2 / 164.308(a)(1)(i) NIST SP 800-66 Rev 2
Administrative
NIST SP 800-66 Rev 2 164.308(a)(1)(i): Security Management Process (Standard) Implement policies and procedures to prevent, detect, contain, and correct security violations. NIST recommends establishing an enterprise security governance program with defined roles and risk-based decision making.
Maintained by Gerard Blokdyk · Verified against the published standard 31 May 2026 · Control text last updated 21 May 2026 What else in your programme already covers this This control maps to 84 controls across 29 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
SOC2-CC3.1 CC3.1 Objectives specified clearly enough to assess risk (COSO principle 6) SOC2-CC3.2 CC3.2 Identifying and analysing risks to objectives (COSO principle 7) SOC2-CC4.1 CC4.1 Ongoing and separate evaluations of control (COSO principle 16) SOC2-CC5.1 CC5.1 Selecting control activities that mitigate risk (COSO principle 10) SOC2-CC5.3 CC5.3 Deploying controls through policies and procedures (COSO principle 12) SOC2-CC7.1 CC7.1 Detecting configuration changes and new vulnerabilities SOC2-CC7.4 CC7.4 Responding to security incidents 5.4.1 Actions to address risks and opportunities 5.6.2 Information security risk assessment 5.8.1 Nonconformity and corrective action 6.13.1 Management of information security incidents and improvements 6.3 Organization of information security 6.9.1 Operational procedures and responsibilities NIST-CSF-GV.PO-01 Policy for managing cybersecurity risks is established based on organizational context, cybersecurity strategy, and priorities and is communicated and enforced NIST-CSF-GV.RM-01 Risk management objectives are established and agreed to by organizational stakeholders NIST-CSF-GV.RR-02 Roles, responsibilities, and authorities related to cybersecurity risk management are established, communicated, understood, and enforced NIST-CSF-ID.RA-06 Risk responses are chosen, prioritized, planned, tracked, and communicated NIST-CSF-RS.MI-01 Incidents are contained NIST-CSF-RS.MI-02 Incidents are eradicated CIS-17.1 Designate Personnel to Manage Incident Handling CIS-17.4 Establish and Maintain an Incident Response Process CIS-3.13 Deploy a Data Loss Prevention Solution CIS-7.1 Establish and Maintain a Vulnerability Management Process CIS-8.1 Establish and Maintain an Audit Log Management Process 11.3.1 11.3.1 Quarterly internal vulnerability scans 12.1.1 12.1.1 Overall information security policy established and disseminated 12.1.2 12.1.2 Security policy reviewed annually and updated as needed 12.10.1 12.10.1 Incident response plan ready for activation 6.3.3 6.3.3 Timely installation of security patches CPS234-14 Definition of Information Security Roles and Responsibilities CPS234-19 Information Security Policy Framework CPS234-21 Implementation of Information Security Controls CPS234-30 Detection and Response Mechanisms 5.1 Policies for information security 5.2 Information security roles and responsibilities 5.24 Information security incident management planning and preparation 5.36 Compliance with policies, rules and standards for information security 5.1 Policies for information security 5.2 Information security roles and responsibilities 5.24 Information security incident management planning and preparation 5.35 Independent review of information security CPS230-11 Identification, Assessment and Management of Operational Risk CPS230-15 Operational Risk Elements of the Risk Management Framework CPS230-24 Design and Embedding of Internal Controls IR-4 Incident Handling PL-1 Policy and Procedures RA-1 Policy and Procedures IR-4 Incident Handling PL-1 Policy and Procedures RA-1 Policy and Procedures SEC01-BP03 Identify and validate control objectives SEC01-BP06 Automate deployment of standard security controls CFTC-SS-1 Program of Risk Analysis and Oversight CFTC-SS-2 Enterprise Risk Management and Governance Category E8-APP-ML2 Application Control (ML2) ANSSI-HYG-40 Define a Security Incident Management Procedure CPS220-04 Maintenance of a Risk Management Framework AUCDR-IS-STEP1 Step 1 - Define and implement security governance for CDR data ASBv3-GS-5 Define and implement security posture management strategy 3.6.2e Establish and Maintain a Cyber Incident Response Team Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Other controls in Administrative Query this from an agent The graph holds this control, the 84 it maps to, and the evidence behind each claim, over MCP and REST.