NIST Special Publication 800-171 Revision 2
IDName
3.1.4Separate the duties of individuals to reduce the risk of malevolent activity without collusion
3.3.8Protect audit information and audit logging tools from unauthorized access, modification, and deletion
3.3.9Limit management of audit logging functionality to a subset of privileged users
3.4.1Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles
3.4.2Establish and enforce security configuration settings for information technology products employed in organizational systems
3.4.3Track, review, approve or disapprove, and log changes to organizational systems
3.4.5Define, document, approve, and enforce physical and logical access restrictions associated with changes to organizational systems
3.7.2Provide controls on the tools, techniques, mechanisms, and personnel used to conduct system maintenance
3.7.6Supervise the maintenance activities of maintenance personnel without required access authorization
3.8.1Protect (i.e., physically control and securely store) system media containing CUI, both paper and digital
3.10.1Limit physical access to organizational systems, equipment, and the respective operating environments to authorized individuals
3.10.2Protect and monitor the physical facility and support infrastructure for organizational systems
3.13.2Employ architectural designs, software development techniques, and systems engineering principles that promote effective information security within organizational systems
3.13.10Establish and manage cryptographic keys for cryptography employed in organizational systems
3.13.13Control and monitor the use of mobile code