Frameworks / NIST SP 800-66 Rev 2 / 164.308(a)(1)(ii)(A) What else in your programme already covers this This control maps to 167 controls across 30 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
1.2.3 1.2.3 Accurate network diagram of CDE connections 1.2.5 1.2.5 Allowed services, protocols and ports justified 1.2.7 1.2.7 Six-monthly review of NSC configurations 1.4.4 1.4.4 Cardholder data stores not reachable from untrusted networks 10.4.2.1 10.4.2.1 Periodic log review frequency set by targeted risk analysis 10.7.3 10.7.3 Respond promptly to critical security control failures 11.2.1 11.2.1 Detect authorized and rogue wireless access points 11.3.1 11.3.1 Quarterly internal vulnerability scans 11.3.2 11.3.2 Quarterly ASV external vulnerability scans 11.3.2.1 11.3.2.1 External scans after significant change 11.4.1 11.4.1 Penetration testing methodology defined and implemented 11.4.3 11.4.3 External penetration testing annually and after change 11.4.5 11.4.5 Annual segmentation penetration testing 11.4.6 11.4.6 Service provider segmentation testing every six months 12.3.2 12.3.2 Targeted risk analysis for each customized-approach requirement 12.3.3 12.3.3 Cryptographic cipher suite and protocol inventory reviewed annually 12.5.3 12.5.3 Scope review after significant organisational change 12.6.1 12.6.1 Formal security awareness program 3.3.3 3.3.3 Issuer SAD storage limited, justified and encrypted 3.5.1.3 3.5.1.3 Disk encryption access independent of OS authentication 5.2.3.1 5.2.3.1 Targeted risk analysis sets evaluation frequency 5.3.2.1 5.3.2.1 Targeted risk analysis sets malware scan frequency 6.2.1 6.2.1 Secure development of bespoke and custom software 6.4.1 6.4.1 Public web application review or automated protection 9.4.5.1 9.4.5.1 Annual inventories of electronic media 5.2.3 5.2.3 Periodic evaluation of components not at risk from malware 6.3.1 6.3.1 Vulnerability identification and risk ranking 6.3.2 6.3.2 Inventory of bespoke software and components 8.6.3 8.6.3 System account passwords protected against misuse CIS-1.3 Utilize an Active Discovery Tool CIS-1.5 Use a Passive Asset Discovery Tool CIS-13.8 Deploy a Network Intrusion Prevention Solution CIS-16.1 Establish and Maintain a Secure Application Development Process CIS-16.14 Conduct Threat Modeling CIS-16.4 Establish and Manage an Inventory of Third-Party Software Components CIS-16.5 Use Up-to-Date and Trusted Third-Party Software Components CIS-2.1 Establish and Maintain a Software Inventory CIS-2.2 Ensure Authorized Software is Currently Supported CIS-2.6 Allowlist Authorized Libraries CIS-3.13 Deploy a Data Loss Prevention Solution CIS-4.4 Implement and Manage a Firewall on Servers CIS-6.6 Establish and Maintain an Inventory of Authentication and Authorization Systems CIS-7.1 Establish and Maintain a Vulnerability Management Process CIS-7.5 Perform Automated Vulnerability Scans of Internal Enterprise Assets CIS-7.6 Perform Automated Vulnerability Scans of Externally-Exposed Enterprise Assets CIS-9.1 Ensure Use of Only Fully Supported Browsers and Email Clients 5.2.1 Understanding the organization and its context 5.4 Planning 5.4.1 Actions to address risks and opportunities 5.6.2 Information security risk assessment 6.10.1 Network security management 6.11 Systems acquisition, development and maintenance 6.11.1 Security requirements of information systems 6.9 Operations security 6.9.6 Technical vulnerability management 7.2.5 Privacy impact assessment 7.4 Privacy by design and privacy by default 7.4.4 PII minimization objectives 8.2 Conditions for collection and processing 8.4 Privacy by design and privacy by default NIST-CSF-DE.AE-07 Cyber threat intelligence and other contextual information are integrated into the analysis NIST-CSF-GV.OC-01 The organizational mission is understood and informs cybersecurity risk management NIST-CSF-GV.OV-02 The cybersecurity risk management strategy is reviewed and adjusted to ensure coverage of organizational requirements and risks NIST-CSF-GV.RM-06 A standardized method for calculating, documenting, categorizing, and prioritizing cybersecurity risks is established and communicated NIST-CSF-GV.RM-07 Strategic opportunities (i.e., positive risks) are characterized and are included in organizational cybersecurity risk discussions NIST-CSF-ID.RA-01 Vulnerabilities in assets are identified, validated, and recorded NIST-CSF-ID.RA-03 Internal and external threats to the organization are identified and recorded NIST-CSF-ID.RA-04 Potential impacts and likelihoods of threats exploiting vulnerabilities are identified and recorded NIST-CSF-ID.RA-05 Threats, vulnerabilities, likelihoods, and impacts are used to understand inherent risk and inform risk response prioritization NIST-CSF-ID.RA-10 Critical suppliers are assessed prior to acquisition 5.23 Information security for use of cloud services 5.34 Privacy and protection of personal identifiable information (PII) 5.7 Threat intelligence 5.9 Inventory of information and other associated assets 8.19 Installation of software on operational systems 8.27 Secure system architecture and engineering principles 8.29 Security testing in development and acceptance 8.8 Management of technical vulnerabilities 8.9 Configuration management 4.2.1 General 6.1 Actions to address risks and opportunities 6.1.1 Determining risks and opportunities 6.1.2 Addressing risks and opportunities 8.1 Operational planning and control 8.2 Business impact analysis and risk assessment 8.2.1 General 8.2.3 Risk assessment 5.34 Privacy and protection of PII 5.35 Independent review of information security 5.7 Threat intelligence 5.9 Inventory of information and other associated assets 8.19 Installation of software on operational systems 8.26 Application security requirements 8.27 Secure system architecture and engineering principles 8.8 Management of technical vulnerabilities SOC2-C1.1 C1.1 Identifying and maintaining confidential information SOC2-CC2.1 CC2.1 Relevant, quality information to support internal control (COSO principle 13) SOC2-CC3.2 CC3.2 Identifying and analysing risks to objectives (COSO principle 7) SOC2-CC3.4 CC3.4 Identifying and assessing significant changes (COSO principle 9) SOC2-CC5.2 CC5.2 General controls over technology (COSO principle 11) SOC2-CC6.6 CC6.6 Protection against threats from outside the system boundary SOC2-CC6.8 CC6.8 Preventing and detecting unauthorised or malicious software SOC2-PI1.1 PI1.1 Quality information about processing objectives, data definitions and specifications ASBv3-AM-1 Track asset inventory and their risks ASBv3-DP-1 Discover, classify, and label sensitive data ASBv3-DS-1 Conduct threat modeling PV-5 Perform vulnerability assessments AUCDR-IS-4 Formal vulnerability management program AUCDR-IS-STEP2 Step 2 - Define the boundaries of the CDR data environment AUCDR-IS-STEP3 Step 3 - Have and maintain an information security capability CFTC-SS-1 Program of Risk Analysis and Oversight CFTC-SS-17 Enterprise Technology Risk Assessment CFTC-SS-2 Enterprise Risk Management and Governance Category CPS220-07 Material Risk Categories the Framework Must Address CPS220-P22 Framework Structure for Managing Each Material Risk SEC01-BP07 Identify threats and prioritize mitigations using a threat model SEC06-BP01 Perform vulnerability management CPS230-11 Identification, Assessment and Management of Operational Risk CPS234-20 Information Asset Classification 3.11.1e Threat-Aware Risk Assessment Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Other controls in Administrative Query this from an agent The graph holds this control, the 167 it maps to, and the evidence behind each claim, over MCP and REST.