ACCESS-1Establish and Maintain Identities
ACCESS-2Control Logical and Physical Access
ARCH-1Establish a Cybersecurity Architecture Strategy
ARCH-2Implement Network Protections
ARCH-3Implement Data Security
ASSET-1Manage IT and OT Asset Inventory
ASSET-2Manage Asset Configuration and Changes
PROGRAM-1Establish and Maintain the Cybersecurity Program
RESPONSE-1Detect and Analyze Cybersecurity Events
RESPONSE-2Respond to and Recover from Cybersecurity Incidents
RESPONSE-3Plan for Continuity of Operations
RISK-1Establish a Cyber Risk Management Strategy and Program
RISK-2Identify and Analyze Cyber Risk
RISK-3Manage and Respond to Cyber Risk
SITUATION-1Perform Logging and Monitoring
SITUATION-2Establish and Maintain a Common Operating Picture
THIRD-1Identify and Manage Third-Party Risk
THIRD-2Manage Supplier Relationships and Incident Notification
THREAT-1Identify and Respond to Cyber Threats
THREAT-2Reduce Cybersecurity Vulnerabilities
WORKFORCE-1Establish Cybersecurity Responsibilities and Workforce
WORKFORCE-2Develop Cybersecurity Workforce and Awareness