OWASP SAMM
Operations

OWASP SAMM OWASPSAMM-5: Operations: Incident Management, Environment Management, Operational Management

Per OWASP SAMM v2 Operations business function: secure operations practices. Security Practices: (1) Incident Management including incident detection + response + forensic readiness + (2) Environment Management including configuration hardening + patch + update management + (3) Operational Management including data protection + system de-commissioning + legacy management. Requirements include (a) operate incident detection + response capability including alerting + triage + investigation + remediation + (b) maintain forensic readiness including log retention + evidence handling + (c) maintain configuration hardening baselines including drift detection + remediation + (d) operate patch + update management including testing + deployment + verification + (e) implement data protection across operational lifecycle including classification + handling + retention + secure deletion + (f) operate secure system decommissioning + legacy management.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 172 controls across 52 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • ASD37-06 Email content filtering (Excellent)
  • ASD37-12 Antivirus software with heuristics (Very Good)
  • ASD37-16 Antivirus software with signatures (Limited)
  • ASD37-20 Multi-factor authentication (Essential)
  • ASD37-22 Network segmentation (Excellent)
  • ASD37-25 Software firewall - inbound (Very Good)
  • ASD37-34 Regular backups (Essential)
  • ASD37-35 Business continuity and disaster recovery plans (Very Good)
  • ASD37-36 System recovery capabilities (Very Good)

ISO/IEC 27043:2015 · 7 controls

  • ISO27043-06 Asset inventory and ownership
  • ISO27043-08 Information classification and labeling
  • ISO27043-10 Media management and disposal
  • ISO27043-22 Protection from malware
  • ISO27043-23 Backup and recovery procedures
  • ISO27043-24 Logging and monitoring
  • ISO27043-27 Network security management

ISO/SAE 21434 · 7 controls

  • ISO21434-07 Acceptable use of assets
  • ISO21434-08 Information classification and labeling
  • ISO21434-09 Asset handling procedures
  • ISO21434-22 Protection from malware
  • ISO21434-23 Backup and recovery procedures
  • ISO21434-24 Logging and monitoring
  • ISO21434-27 Network security management

API 1164 · 5 controls

  • API1164-12 Incident Response
  • API1164-13 Business Continuity and Recovery
  • API1164-17 Wireless and Field Communications
  • API1164-18 Field Device Security
  • API1164-19 Safety Instrumented Systems Interface

IEC 62443 · 5 controls

  • IEC62443-12 Malware prevention for operational systems
  • IEC62443-13 Network security monitoring
  • IEC62443-16 Incident response plan for operational disruptions
  • IEC62443-17 Recovery plan for critical systems
  • IEC62443-20 Exercises and drills for OT incidents

ISO/IEC 27011:2024 · 5 controls

  • 27011-6.3 Awareness and Training
  • 27011-8.2 Network security and segregation
  • 27011-8.4 Logging and monitoring
  • 27011-8.5 Vulnerability and malware management
  • 27011-8.6 Data protection and backup

ISO/IEC 27019:2024 · 5 controls

  • ISO27019-12 Malware prevention for operational systems
  • ISO27019-13 Network security monitoring
  • ISO27019-16 Incident response plan for operational disruptions
  • ISO27019-18 Reporting obligations to authorities
  • ISO27019-20 Exercises and drills for OT incidents

NIST SP 1800-32 · 5 controls

NIST SP 800-53 Rev 5 · 5 controls

  • CPG-1.D Revoking Credentials for Departing Employees
  • CPG-2.A Asset Inventory
  • CPG-2.B Prohibit Connection of Unauthorized Devices
  • CPG-8.A Network Segmentation
  • PICERL-C2 System Backup
  • PICERL-E1 Threat Removal
  • PICERL-R1 System Restoration
  • PICERL-R2 Security Verification

South Korea ISMS-P · 4 controls

  • ISMSP-AC-04 Network Access Control
  • ISMSP-PI-06 Personal Information Destruction
  • ISMSP-SYS-03 Security Monitoring and Log Management
  • ISMSP-SYS-06 Business Continuity and Disaster Recovery
  • AWWA-3.1 Network Segmentation
  • AWWA-4.1 Malware Protection
  • AWWA-4.4 Audit Logging and Monitoring

BSI IT-Grundschutz · 3 controls

  • BSI-28 Audit event logging and storage
  • BSI-29 Audit record review and analysis
  • BSI-31 Audit log protection and retention

ISO/IEC 27010:2015 · 3 controls

  • 27010-12.2 Protection from malware
  • 27010-13.1 Communications Security
  • 27010-8.1 Membership Onboarding

ISO/IEC 27031:2011 · 3 controls

  • 27031-8.1 Exercising and Testing
  • 27031-8.2 Maintaining IRBC
  • 27031-9.3 Management Review
  • NIST-CSF-RC.RP-01 The recovery portion of the incident response plan is executed once initiated from the incident response process
  • NIST-CSF-RC.RP-06 The end of incident recovery is declared based on criteria, and incident-related documentation is completed
  • NIST-CSF-RS.MA-05 The criteria for initiating incident recovery are applied

NIST SP 800-190 · 3 controls

PTES · 3 controls

  • PTESPHASE-1 Pre-Engagement Interactions and Scoping
  • PTESPHASE-3 Threat Modeling
  • PTESPHASE-4 Vulnerability Analysis
  • IM8-RES.2 Disaster Recovery
  • IM8-RES.4 Resilience Testing
  • IM8-SEC.3 Network Security
  • CAT-D3-1 Preventative controls
  • CAT-D3-2 Detective controls
  • FFIEC-06 Network security and segmentation
  • FFIEC-12 Disaster recovery procedures

ISO 22316 · 2 controls

  • ISO22316-08 Recovery time and point objectives
  • ISO22316-12 Recovery strategy for critical activities

ISO/TS 22317:2021 · 2 controls

  • ISO22317-08 Recovery time and point objectives
  • ISO22317-12 Recovery strategy for critical activities

ISO/TS 22318:2021 · 2 controls

  • ISO22318-08 Recovery time and point objectives
  • ISO22318-12 Recovery strategy for critical activities
  • NFPA1600-5.3 Resource Needs Assessment
  • NFPA1600-6.4 Continuity and Recovery

PCI P2PE · 2 controls

  • PCI-P2PE-06 Network security and segmentation
  • PCI-P2PE-12 Disaster recovery procedures

PCI PIN Security · 2 controls

  • PCI-PIN-06 Network security and segmentation
  • PCI-PIN-12 Disaster recovery procedures

PCI SSF · 2 controls

  • PCI-SSF-06 Network security and segmentation
  • PCI-SSF-12 Disaster recovery procedures

PSD2 SCA · 2 controls

  • PSDTWO-1 Strong Customer Authentication (SCA) Core Requirements
  • PSDTWO-2 SCA Exemptions and Risk-Based Authentication
  • D.3 Backup and Recovery
  • UKDEFSTD-1 Cyber Defence Cyber Risk Profile (CRP)
  • 4.4.8 Business Continuity and Recovery
  • DIQ-1 Data Integration and Interoperability
  • CJIS-10 System and Information Integrity
  • FTC-Safeguards-9-Elements 9 Safeguard Elements - Access, Inventory, Encryption, Secure-Dev, MFA, Disposal, Change-Mgmt, Monitoring, Pen-Test (16 CFR 314.4(c))

FedRAMP Rev 5 · 1 control

  • FEDRAMP-CP-9 System Backup
  • 62351-14 Cyber security event logging

ISO 22320:2018 · 1 control

  • ISO-22320-5.2 Incident management process

ISO 27799:2025 · 1 control

  • ISO27799-05 Audit trail for ePHI access
  • ISO28001-PS-01 Facility Security
  • ISO-25012-4.11 Traceability
  • QRCM-1.1 Cryptographic Asset Inventory

OWASP Top 10:2025 · 1 control

  • OWASPTOP10-9 A09:2025 Security Logging and Monitoring Failures
  • PASONE-4 Technical Security: CDE Configuration, BIM Tools, Encryption, Aggregation, Mobile Working
  • PICSGMP-4 Chapter 4: Documentation - System, Record-Keeping, Data Integrity
  • CPSC-CS.1 Network Security for Connected Products
  • USSDWA-2 Cybersecurity Practices (Assessment, Access, Network, IR)

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 172 it maps to, and the evidence behind each claim, over MCP and REST.