Controls
| Control ID | Name | Domain | Owner | Status | Type | Testing | |
|---|---|---|---|---|---|---|---|
CA001 | Security program establishment | Governance | — | In Progress | Preventive | Annual | |
CA002 | Security roles and responsibilities | Governance | — | In Progress | Preventive | Annual | |
CA003 | Policy library and version control | Governance | — | In Progress | Preventive | Annual | |
CA004 | Personnel policy acknowledgment | Governance | — | Not Implemented | Preventive | Per Event | |
CA005 | Leadership security program review | Governance | — | Not Implemented | Detective | Annual | |
CA006 | Risk assessment and risk register | Governance | — | Not Implemented | Detective | Annual | |
CA007 | Risk treatment and tracking | Governance | — | Not Implemented | Corrective | Quarterly | |
CA008 | Change and new tool risk assessment | Governance | — | Not Implemented | Preventive | Per Event | |
CA009 | Control effectiveness evaluation | Governance | — | Not Implemented | Detective | Annual | |
CA010 | User access and least privilege | Identity & Access | — | Not Implemented | Preventive | Per Event | |
CA011 | SSO and MFA enforcement | Identity & Access | — | Not Implemented | Preventive | Continuous | |
CA012 | Periodic access review | Identity & Access | — | Not Implemented | Detective | Quarterly | |
CA013 | Access removal on termination or role change | Identity & Access | — | Not Implemented | Preventive | Per Event | |
CA014 | Privileged account management | Identity & Access | — | Not Implemented | Preventive | Quarterly | |
CA015 | Endpoint EDR enforcement | Endpoint Security | — | Not Implemented | Preventive | Continuous | |
CA016 | Credential management | Identity & Access | — | Not Implemented | Preventive | Continuous | |
CA017 | Code of conduct | Personnel Security | — | Not Implemented | Preventive | Annual | |
CA018 | Personnel verification and screening | Personnel Security | — | Not Implemented | Preventive | Per Event | |
CA019 | Security awareness training | Personnel Security | — | Not Implemented | Preventive | Annual | |
CA020 | Disciplinary procedures | Personnel Security | — | Not Implemented | Corrective | Per Event | |
CA021 | Incident response plan | Incident Management | — | Not Implemented | Corrective | Annual | |
CA022 | IR tabletop exercise | Incident Management | — | Not Implemented | Detective | Annual | |
CA023 | Security incident logging and investigation | Incident Management | — | Not Implemented | Detective | Per Event | |
CA024 | Privacy incident escalation and breach notification | Incident Management | — | Not Implemented | Corrective | Per Event | |
CA025 | Internal and external reporting channels | Incident Management | — | Not Implemented | Preventive | Annual | |
CA026 | Audit logging and review | Security Operations | — | Not Implemented | Detective | Continuous | |
CA027 | Vulnerability management | Security Operations | — | Not Implemented | Detective | Continuous | |
CA028 | Endpoint security monitoring | Endpoint Security | — | Not Implemented | Detective | Continuous | |
CA029 | SaaS configuration baselines | Security Operations | — | Not Implemented | Detective | Quarterly | |
CA030 | Encryption in transit and at rest | Security Operations | — | Not Implemented | Preventive | Continuous | |
CA031 | Vendor and SaaS platform inventory | Vendor Management | — | Not Implemented | Preventive | Annual | |
CA032 | Vendor pre-onboarding assessment | Vendor Management | — | Not Implemented | Preventive | Per Event | |
CA033 | Business Associate Agreements and data processing agreements | Vendor Management | — | Not Implemented | Preventive | Per Event | |
CA034 | Annual vendor review | Vendor Management | — | Not Implemented | Detective | Annual | |
CA035 | Shadow IT detection and evaluation | Vendor Management | — | Not Implemented | Detective | Continuous | |
CA036 | Shared responsibility model documentation | Vendor Management | — | Not Implemented | Preventive | Annual | |
CA037 | Data classification policy | Data & Privacy | — | Not Implemented | Preventive | Annual | |
CA038 | Non-production data authorization | Data & Privacy | — | Not Implemented | Preventive | Per Event | |
CA039 | Data subject requests | Data & Privacy | — | Not Implemented | Corrective | Per Event | |
CA040 | Data retention and disposal | Data & Privacy | — | Not Implemented | Preventive | Per Event | |
CA041 | Secure coding standards | Secure Development | — | Not Implemented | Preventive | Continuous | |
CA042 | Code peer review via pull request | Secure Development | — | Not Implemented | Preventive | Continuous | |
CA043 | Secrets scanning in repositories | Secure Development | — | Not Implemented | Detective | Continuous | |
CA044 | Dependency vulnerability scanning | Secure Development | — | Not Implemented | Detective | Continuous | |
CA045 | Environment separation | Secure Development | — | Not Implemented | Preventive | Continuous | |
CA046 | Production deployment controls | Secure Development | — | Not Implemented | Preventive | Per Event | |
CA047 | Business continuity plan | Business Continuity | — | Not Implemented | Preventive | Annual | |
CA048 | Backup and recovery | Business Continuity | — | Not Implemented | Preventive | Annual | |
CA049 | Vendor outage response procedures | Business Continuity | — | Not Implemented | Preventive | Annual | |
CA050 | Business impact analysis | Business Continuity | — | Not Implemented | Detective | Annual | |
CA051 | BCP annual testing and review | Business Continuity | — | Not Implemented | Detective | Annual | |
CA052 | Critical supplier resilience | Business Continuity | — | Not Implemented | Detective | Annual | |
CA053 | AI governance program | AI Governance | — | Not Implemented | Preventive | Annual | |
CA054 | AI roles and accountability | AI Governance | — | Not Implemented | Preventive | Annual | |
CA055 | AI system inventory and documentation | AI Governance | — | Not Implemented | Preventive | Per Event | |
CA056 | AI risk assessment | AI Governance | — | Not Implemented | Detective | Annual | |
CA057 | AI lifecycle management | AI Governance | — | Not Implemented | Preventive | Per Event | |
CA058 | AI data governance and provenance | AI Governance | — | Not Implemented | Preventive | Per Event | |
CA059 | AI testing, validation, and bias evaluation | AI Governance | — | Not Implemented | Detective | Per Event | |
CA060 | Human oversight of AI | AI Governance | — | Not Implemented | Preventive | Continuous | |
CA061 | AI transparency and disclosure | AI Governance | — | Not Implemented | Preventive | Annual | |
CA062 | AI incident response | AI Governance | — | Not Implemented | Corrective | Per Event | |
CA063 | AI model monitoring and drift detection | AI Governance | — | Not Implemented | Detective | Continuous | |
CA064 | Third-party AI system risk | AI Governance | — | Not Implemented | Detective | Annual |