| CA-6(1) | Assessment, Authorization, and Monitoring | Joint Authorization — Intra-organization |
| CA-6(2) | Assessment, Authorization, and Monitoring | Joint Authorization — Inter-organization |
| CA-7 | Assessment, Authorization, and Monitoring | Continuous Monitoring |
| CA-7(1) | Assessment, Authorization, and Monitoring | Independent Assessment |
| CA-7(2) | Assessment, Authorization, and Monitoring | Types of Assessments |
| CA-7(3) | Assessment, Authorization, and Monitoring | Trend Analyses |
| CA-7(4) | Assessment, Authorization, and Monitoring | Risk Monitoring |
| CA-7(5) | Assessment, Authorization, and Monitoring | Consistency Analysis |
| CA-7(6) | Assessment, Authorization, and Monitoring | Automation Support for Monitoring |
| CA-8 | Assessment, Authorization, and Monitoring | Penetration Testing |
| CA-8(1) | Assessment, Authorization, and Monitoring | Independent Penetration Testing Agent or Team |
| CA-8(2) | Assessment, Authorization, and Monitoring | Red Team Exercises |
| CA-8(3) | Assessment, Authorization, and Monitoring | Facility Penetration Testing |
| CA-9 | Assessment, Authorization, and Monitoring | Internal System Connections |
| CA-9(1) | Assessment, Authorization, and Monitoring | Compliance Checks |
| CM-1 | Configuration Management | Policy and Procedures |
| CM-10 | Configuration Management | Software Usage Restrictions |
| CM-10(1) | Configuration Management | Open-source Software |
| CM-11 | Configuration Management | User-installed Software |
| CM-11(1) | Configuration Management | Alerts for Unauthorized Installations |
| CM-11(2) | Configuration Management | Software Installation with Privileged Status |
| CM-11(3) | Configuration Management | Automated Enforcement and Monitoring |
| CM-12 | Configuration Management | Information Location |
| CM-12(1) | Configuration Management | Automated Tools to Support Information Location |
| CM-13 | Configuration Management | Data Action Mapping |
| CM-14 | Configuration Management | Signed Components |
| CM-2 | Configuration Management | Baseline Configuration |
| CM-2(1) | Configuration Management | Reviews and Updates |
| CM-2(2) | Configuration Management | Automation Support for Accuracy and Currency |
| CM-2(3) | Configuration Management | Retention of Previous Configurations |
| CM-2(4) | Configuration Management | Unauthorized Software |
| CM-2(5) | Configuration Management | Authorized Software |
| CM-2(6) | Configuration Management | Development and Test Environments |
| CM-2(7) | Configuration Management | Configure Systems and Components for High-risk Areas |
| CM-3 | Configuration Management | Configuration Change Control |
| CM-3(1) | Configuration Management | Automated Documentation, Notification, and Prohibition of Changes |
| CM-3(2) | Configuration Management | Testing, Validation, and Documentation of Changes |
| CM-3(3) | Configuration Management | Automated Change Implementation |
| CM-3(4) | Configuration Management | Security and Privacy Representatives |
| CM-3(5) | Configuration Management | Automated Security Response |
| CM-3(6) | Configuration Management | Cryptography Management |
| CM-3(7) | Configuration Management | Review System Changes |
| CM-3(8) | Configuration Management | Prevent or Restrict Configuration Changes |
| CM-4 | Configuration Management | Impact Analyses |
| CM-4(1) | Configuration Management | Separate Test Environments |
| CM-4(2) | Configuration Management | Verification of Controls |
| CM-5 | Configuration Management | Access Restrictions for Change |
| CM-5(1) | Configuration Management | Automated Access Enforcement and Audit Records |
| CM-5(2) | Configuration Management | Review System Changes |
| CM-5(3) | Configuration Management | Signed Components |