Frameworks / OWASP SAMM / OWASPSAMM-5 OWASP SAMM OWASPSAMM-5: Operations: Incident Management, Environment Management, Operational Management Per OWASP SAMM v2 Operations business function: secure operations practices. Security Practices: (1) Incident Management including incident detection + response + forensic readiness + (2) Environment Management including configuration hardening + patch + update management + (3) Operational Management including data protection + system de-commissioning + legacy management. Requirements include (a) operate incident detection + response capability including alerting + triage + investigation + remediation + (b) maintain forensic readiness including log retention + evidence handling + (c) maintain configuration hardening baselines including drift detection + remediation + (d) operate patch + update management including testing + deployment + verification + (e) implement data protection across operational lifecycle including classification + handling + retention + secure deletion + (f) operate secure system decommissioning + legacy management.
Maintained by Gerard Blokdyk · Verified against the published standard 31 May 2026 · Control text last updated 21 May 2026 What else in your programme already covers this This control maps to 172 controls across 52 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
ASD37-06 Email content filtering (Excellent) ASD37-12 Antivirus software with heuristics (Very Good) ASD37-16 Antivirus software with signatures (Limited) ASD37-20 Multi-factor authentication (Essential) ASD37-22 Network segmentation (Excellent) ASD37-25 Software firewall - inbound (Very Good) ASD37-34 Regular backups (Essential) ASD37-35 Business continuity and disaster recovery plans (Very Good) ASD37-36 System recovery capabilities (Very Good) ISO27043-06 Asset inventory and ownership ISO27043-08 Information classification and labeling ISO27043-10 Media management and disposal ISO27043-22 Protection from malware ISO27043-23 Backup and recovery procedures ISO27043-24 Logging and monitoring ISO27043-27 Network security management ISO21434-07 Acceptable use of assets ISO21434-08 Information classification and labeling ISO21434-09 Asset handling procedures ISO21434-22 Protection from malware ISO21434-23 Backup and recovery procedures ISO21434-24 Logging and monitoring ISO21434-27 Network security management API1164-12 Incident Response API1164-13 Business Continuity and Recovery API1164-17 Wireless and Field Communications API1164-18 Field Device Security API1164-19 Safety Instrumented Systems Interface IEC62443-12 Malware prevention for operational systems IEC62443-13 Network security monitoring IEC62443-16 Incident response plan for operational disruptions IEC62443-17 Recovery plan for critical systems IEC62443-20 Exercises and drills for OT incidents 27011-6.3 Awareness and Training 27011-8.2 Network security and segregation 27011-8.4 Logging and monitoring 27011-8.5 Vulnerability and malware management 27011-8.6 Data protection and backup ISO27019-12 Malware prevention for operational systems ISO27019-13 Network security monitoring ISO27019-16 Incident response plan for operational disruptions ISO27019-18 Reporting obligations to authorities ISO27019-20 Exercises and drills for OT incidents CPG-1.D Revoking Credentials for Departing Employees CPG-2.A Asset Inventory CPG-2.B Prohibit Connection of Unauthorized Devices CPG-8.A Network Segmentation PICERL-C2 System Backup PICERL-E1 Threat Removal PICERL-R1 System Restoration PICERL-R2 Security Verification ISMSP-AC-04 Network Access Control ISMSP-PI-06 Personal Information Destruction ISMSP-SYS-03 Security Monitoring and Log Management ISMSP-SYS-06 Business Continuity and Disaster Recovery AWWA-3.1 Network Segmentation AWWA-4.1 Malware Protection AWWA-4.4 Audit Logging and Monitoring BSI-28 Audit event logging and storage BSI-29 Audit record review and analysis BSI-31 Audit log protection and retention 27010-12.2 Protection from malware 27010-13.1 Communications Security 27010-8.1 Membership Onboarding 27031-8.1 Exercising and Testing 27031-8.2 Maintaining IRBC 27031-9.3 Management Review NIST-CSF-RC.RP-01 The recovery portion of the incident response plan is executed once initiated from the incident response process NIST-CSF-RC.RP-06 The end of incident recovery is declared based on criteria, and incident-related documentation is completed NIST-CSF-RS.MA-05 The criteria for initiating incident recovery are applied PTESPHASE-1 Pre-Engagement Interactions and Scoping PTESPHASE-3 Threat Modeling PTESPHASE-4 Vulnerability Analysis IM8-RES.2 Disaster Recovery IM8-RES.4 Resilience Testing IM8-SEC.3 Network Security CAT-D3-1 Preventative controls CAT-D3-2 Detective controls FFIEC-06 Network security and segmentation FFIEC-12 Disaster recovery procedures ISO22316-08 Recovery time and point objectives ISO22316-12 Recovery strategy for critical activities ISO22317-08 Recovery time and point objectives ISO22317-12 Recovery strategy for critical activities ISO22318-08 Recovery time and point objectives ISO22318-12 Recovery strategy for critical activities NFPA1600-5.3 Resource Needs Assessment NFPA1600-6.4 Continuity and Recovery PCI-P2PE-06 Network security and segmentation PCI-P2PE-12 Disaster recovery procedures PCI-PIN-06 Network security and segmentation PCI-PIN-12 Disaster recovery procedures PCI-SSF-06 Network security and segmentation PCI-SSF-12 Disaster recovery procedures PSDTWO-1 Strong Customer Authentication (SCA) Core Requirements PSDTWO-2 SCA Exemptions and Risk-Based Authentication D.3 Backup and Recovery UKDEFSTD-1 Cyber Defence Cyber Risk Profile (CRP) 4.4.8 Business Continuity and Recovery DIQ-1 Data Integration and Interoperability CJIS-10 System and Information Integrity FTC-Safeguards-9-Elements 9 Safeguard Elements - Access, Inventory, Encryption, Secure-Dev, MFA, Disposal, Change-Mgmt, Monitoring, Pen-Test (16 CFR 314.4(c)) FEDRAMP-CP-9 System Backup 62351-14 Cyber security event logging ISO-19650-1-5 Delivery team and task team concepts ISO-22320-5.2 Incident management process ISO27799-05 Audit trail for ePHI access ISO28001-PS-01 Facility Security ISO-25012-4.11 Traceability QRCM-1.1 Cryptographic Asset Inventory OWASPTOP10-9 A09:2025 Security Logging and Monitoring Failures PASONE-4 Technical Security: CDE Configuration, BIM Tools, Encryption, Aggregation, Mobile Working PICSGMP-4 Chapter 4: Documentation - System, Record-Keeping, Data Integrity CPSC-CS.1 Network Security for Connected Products USSDWA-2 Cybersecurity Practices (Assessment, Access, Network, IR) CYB-5 Cyber Incident Response Plan Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Query this from an agent The graph holds this control, the 172 it maps to, and the evidence behind each claim, over MCP and REST.