| Reference | Family | Title |
|---|---|---|
| PT-3(2) | Personally Identifiable Information Processing and Transparency | Automation |
| PT-4 | Personally Identifiable Information Processing and Transparency | Consent |
| PT-4(1) | Personally Identifiable Information Processing and Transparency | Tailored Consent |
| PT-4(2) | Personally Identifiable Information Processing and Transparency | Just-in-time Consent |
| PT-4(3) | Personally Identifiable Information Processing and Transparency | Revocation |
| PT-5 | Personally Identifiable Information Processing and Transparency | Privacy Notice |
| PT-5(1) | Personally Identifiable Information Processing and Transparency | Just-in-time Notice |
| PT-5(2) | Personally Identifiable Information Processing and Transparency | Privacy Act Statements |
| PT-6 | Personally Identifiable Information Processing and Transparency | System of Records Notice |
| PT-6(1) | Personally Identifiable Information Processing and Transparency | Routine Uses |
| PT-6(2) | Personally Identifiable Information Processing and Transparency | Exemption Rules |
| PT-7 | Personally Identifiable Information Processing and Transparency | Specific Categories of Personally Identifiable Information |
| PT-7(1) | Personally Identifiable Information Processing and Transparency | Social Security Numbers |
| PT-7(2) | Personally Identifiable Information Processing and Transparency | First Amendment Information |
| PT-8 | Personally Identifiable Information Processing and Transparency | Computer Matching Requirements |
| RA-1 | Risk Assessment | Policy and Procedures |
| RA-10 | Risk Assessment | Threat Hunting |
| RA-2 | Risk Assessment | Security Categorization |
| RA-2(1) | Risk Assessment | Impact-level Prioritization |
| RA-3 | Risk Assessment | Risk Assessment |
| RA-3(1) | Risk Assessment | Supply Chain Risk Assessment |
| RA-3(2) | Risk Assessment | Use of All-source Intelligence |
| RA-3(3) | Risk Assessment | Dynamic Threat Awareness |
| RA-3(4) | Risk Assessment | Predictive Cyber Analytics |
| RA-4 | Risk Assessment | Risk Assessment Update |
| RA-5 | Risk Assessment | Vulnerability Monitoring and Scanning |
| RA-5(1) | Risk Assessment | Update Tool Capability |
| RA-5(10) | Risk Assessment | Correlate Scanning Information |
| RA-5(11) | Risk Assessment | Public Disclosure Program |
| RA-5(2) | Risk Assessment | Update Vulnerabilities to Be Scanned |
| RA-5(3) | Risk Assessment | Breadth and Depth of Coverage |
| RA-5(4) | Risk Assessment | Discoverable Information |
| RA-5(5) | Risk Assessment | Privileged Access |
| RA-5(6) | Risk Assessment | Automated Trend Analyses |
| RA-5(7) | Risk Assessment | Automated Detection and Notification of Unauthorized Components |
| RA-5(8) | Risk Assessment | Review Historic Audit Logs |
| RA-5(9) | Risk Assessment | Penetration Testing and Analyses |
| RA-6 | Risk Assessment | Technical Surveillance Countermeasures Survey |
| RA-7 | Risk Assessment | Risk Response |
| RA-8 | Risk Assessment | Privacy Impact Assessments |
| RA-9 | Risk Assessment | Criticality Analysis |
| SA-1 | System and Services Acquisition | Policy and Procedures |
| SA-10 | System and Services Acquisition | Developer Configuration Management |
| SA-10(1) | System and Services Acquisition | Software and Firmware Integrity Verification |
| SA-10(2) | System and Services Acquisition | Alternative Configuration Management Processes |
| SA-10(3) | System and Services Acquisition | Hardware Integrity Verification |
| SA-10(4) | System and Services Acquisition | Trusted Generation |
| SA-10(5) | System and Services Acquisition | Mapping Integrity for Version Control |
| SA-10(6) | System and Services Acquisition | Trusted Distribution |
| SA-10(7) | System and Services Acquisition | Security and Privacy Representatives |
Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.