Appendix B: Control Families and Classes

The following table lists the eighteen control families and each control’s associated class: operational, managerial, or technical. The two-letter identifier for each family is also listed. All the families in this table are closely related to the seventeen minimum security requirements for federal information and information systems required by FISMA that are detailed in FIPS 200, with the exception of Program Management (PM). The PM family provides organizational-level security controls that are normally not implemented by information systems but rather by the overall organization.

IdFamilyClass
ACAccess ControlTechnical
ATAwareness and TrainingOperational
AUAudit and AccountabilityTechnical
CASecurity Assessment and AuthorizationManagement
CMConfiguration ManagementOperational
CPContingency PlanningOperational
IAIdentification and AuthenticationTechnical
IRIncident ResponseOperational
MAMaintenanceOperational
MPMedia ProtectionOperational
PEPhysical and Environmental ProtectionOperational
PLPlanningManagement
PMProgram ManagementManagement
PSPersonnel SecurityOperational
RARisk AssessmentManagement
SASystem and Services AcquisitionManagement
SCSystem and Communications ProtectionTechnical
SISystem and Information IntegrityOperational
..................Content has been hidden....................

You can't read the all page of ebook, please click here login for view all page.
Reset