Skip to main content

Control Evidence Mappings

Each control mapping documents what evidence Vallum produces to support your compliance program, what it does not produce, known limitations, and what remains your responsibility.

Published (40)

AC-1: Establish access control policy and procedures for organizational systems

NIST SP 800-53 Rev 5 · SUPPORTED EVIDENCE · TESTED

Published

AC-2: Manage system accounts including establishment, activation, modification, review, disabling, and removal

NIST SP 800-53 Rev 5 · SUPPORTED EVIDENCE · TESTED

Published

AC-3: Enforce approved authorizations for logical access to information and system resources

NIST SP 800-53 Rev 5 · SUPPORTED EVIDENCE · TESTED

Published

AC-4: Enforce approved authorizations for controlling the flow of information within the system and between systems

NIST SP 800-53 Rev 5 · SUPPORTED EVIDENCE · TESTED

Published

AC-5: Separate duties of individuals to reduce risk of malevolent activity

NIST SP 800-53 Rev 5 · SUPPORTED EVIDENCE · TESTED

Published

AC-6: Employ the principle of least privilege allowing only authorized accesses necessary for assigned tasks

NIST SP 800-53 Rev 5 · SUPPORTED EVIDENCE · TESTED

Published

AC-7: Enforce a limit of consecutive invalid logon attempts and take action when maximum is exceeded

NIST SP 800-53 Rev 5 · SUPPORTED EVIDENCE · TESTED

Published

AC-8: Display system use notification message before granting access

NIST SP 800-53 Rev 5 · SUPPORTED EVIDENCE · TESTED

Published

AC-11: Prevent further access to the system by initiating a session lock after a defined period of inactivity

NIST SP 800-53 Rev 5 · SUPPORTED EVIDENCE · TESTED

Published

AC-12: Automatically terminate a user session after defined conditions

NIST SP 800-53 Rev 5 · SUPPORTED EVIDENCE · TESTED

Published

AC-14: Identify permitted actions without identification or authentication

NIST SP 800-53 Rev 5 · SUPPORTED EVIDENCE · TESTED

Published

AC-17: Establish usage restrictions and implementation guidance for remote access

NIST SP 800-53 Rev 5 · SUPPORTED EVIDENCE · TESTED

Published

AU-1: Develop and document audit and accountability policy and procedures

NIST SP 800-53 Rev 5 · SUPPORTED EVIDENCE · TESTED

Published

AU-2: Identify events that the system must be capable of auditing

NIST SP 800-53 Rev 5 · SUPPORTED EVIDENCE · TESTED

Published

AU-3: Ensure audit records contain sufficient information to establish what occurred, when, where, source, outcome, and identity

NIST SP 800-53 Rev 5 · SUPPORTED EVIDENCE · TESTED

Published

AU-4: Allocate audit log storage capacity

NIST SP 800-53 Rev 5 · SUPPORTED EVIDENCE · TESTED

Published

AU-5: Alert personnel or take action upon audit logging process failures

NIST SP 800-53 Rev 5 · SUPPORTED EVIDENCE · TESTED

Published

AU-6: Review and analyze audit records for indications of inappropriate or unusual activity

NIST SP 800-53 Rev 5 · SUPPORTED EVIDENCE · TESTED

Published

AU-7: Provide audit record reduction and report generation capability

NIST SP 800-53 Rev 5 · SUPPORTED EVIDENCE · TESTED

Published

AU-8: Use internal system clocks to generate time stamps for audit records

NIST SP 800-53 Rev 5 · SUPPORTED EVIDENCE · TESTED

Published

AU-9: Protect audit information and audit logging tools from unauthorized access, modification, and deletion

NIST SP 800-53 Rev 5 · SUPPORTED EVIDENCE · TESTED

Published

AU-10: Provide irrefutable evidence that actions were performed (non-repudiation)

NIST SP 800-53 Rev 5 · SUPPORTED EVIDENCE · TESTED

Published

AU-11: Retain audit records for a defined period to support after-the-fact investigations

NIST SP 800-53 Rev 5 · SUPPORTED EVIDENCE · TESTED

Published

AU-12: Provide audit record generation capability at system components

NIST SP 800-53 Rev 5 · SUPPORTED EVIDENCE · TESTED

Published

CA-2: Develop and implement security assessment plans

NIST SP 800-53 Rev 5 · SUPPORTED EVIDENCE · TESTED

Published

CA-7: Develop and implement a system-level continuous monitoring strategy

NIST SP 800-53 Rev 5 · SUPPORTED EVIDENCE · TESTED

Published

CM-2: Develop, document, and maintain a current baseline configuration of the system

NIST SP 800-53 Rev 5 · SUPPORTED EVIDENCE · TESTED

Published

CM-3: Determine and document types of changes to the system that are configuration-controlled

NIST SP 800-53 Rev 5 · SUPPORTED EVIDENCE · TESTED

Published

CM-6: Establish and document configuration settings for system components

NIST SP 800-53 Rev 5 · SUPPORTED EVIDENCE · TESTED

Published

CM-8: Develop and document an inventory of system components

NIST SP 800-53 Rev 5 · SUPPORTED EVIDENCE · TESTED

Published

IA-2: Uniquely identify and authenticate organizational users

NIST SP 800-53 Rev 5 · SUPPORTED EVIDENCE · TESTED

Published

IA-4: Manage system identifiers by receiving authorization, selecting, assigning, and preventing reuse

NIST SP 800-53 Rev 5 · SUPPORTED EVIDENCE · TESTED

Published

IA-5: Manage system authenticators including initial distribution, lost/compromised handling, and revocation

NIST SP 800-53 Rev 5 · SUPPORTED EVIDENCE · TESTED

Published

IA-8: Uniquely identify and authenticate non-organizational users

NIST SP 800-53 Rev 5 · SUPPORTED EVIDENCE · TESTED

Published

SC-4: Prevent unauthorized and unintended information transfer via shared system resources

NIST SP 800-53 Rev 5 · SUPPORTED EVIDENCE · TESTED

Published

SC-7: Monitor and control communications at external managed interfaces

NIST SP 800-53 Rev 5 · SUPPORTED EVIDENCE · TESTED

Published

SC-8: Protect the confidentiality and integrity of transmitted information

NIST SP 800-53 Rev 5 · SUPPORTED EVIDENCE · TESTED

Published

SC-12: Establish and manage cryptographic keys

NIST SP 800-53 Rev 5 · SUPPORTED EVIDENCE · TESTED

Published

SC-13: Implement cryptographic mechanisms in accordance with applicable laws and policies

NIST SP 800-53 Rev 5 · SUPPORTED EVIDENCE · TESTED

Published

SC-28: Protect the confidentiality and integrity of information at rest

NIST SP 800-53 Rev 5 · SUPPORTED EVIDENCE · TESTED

Published

In Progress (4)

These mappings are under editorial review and will be published after quality verification.

SI-4: Monitor the system to detect attacks, indicators of potential attacks, and unauthorized connections

NIST SP 800-53 · Under review

SI-7: Employ integrity verification tools to detect unauthorized changes to software, firmware, and information

NIST SP 800-53 · Under review

SI-10: Check the validity of information inputs

NIST SP 800-53 · Under review

SI-12: Manage and retain information within the system and output from the system in accordance with policies

NIST SP 800-53 · Under review