• xPriority: P2: Implement P2 security controls after implementation of P1 controls.
IDNameBaselinesPriorityThreats
LowModerateHigh
AC-7Unsuccessful Logon Attempts
  • P2
STRIDE-LM
(2)Purge / Wipe Mobile Device   
  • P2
STRIDE-LM
AC-12Session Termination 
  • P2
STRIDE-LM
(1)User-Initiated Logouts / Message Displays   
  • P2
STRIDE-LM
AC-21Information Sharing 
  • P2
STRIDE-LM
(1)Automated Decision Support   
  • P2
STRIDE-LM
(2)Information Search And Retrieval   
  • P2
STRIDE-LM
AU-7Audit Reduction And Report Generation 
  • P2
STRIDE-LM
(1)Automatic Processing 
  • P2
STRIDE-LM
(2)Automatic Sort And Search   
  • P2
STRIDE-LM
AU-10Non-Repudiation  
  • P2
STRIDE-LM
(1)Association Of Identities   
  • P2
STRIDE-LM
(2)Validate Binding Of Information Producer Identity   
  • P2
STRIDE-LM
(3)Chain Of Custody   
  • P2
STRIDE-LM
(4)Validate Binding Of Information Reviewer Identity   
  • P2
STRIDE-LM
CA-2Security Assessments
  • P2
STRIDE-LM
(1)Independent Assessors 
  • P2
STRIDE-LM
(2)Specialized Assessments  
  • P2
STRIDE-LM
(3)External Organizations   
  • P2
STRIDE-LM
CA-6Security Authorization
  • P2
STRIDE-LM
CA-7Continuous Monitoring
  • P2
STRIDE-LM
(1)Independent Assessment 
  • P2
STRIDE-LM
(3)Trend Analyses   
  • P2
STRIDE-LM
CA-8Penetration Testing  
  • P2
STRIDE-LM
(1)Independent Penetration Agent Or Team   
  • P2
STRIDE-LM
(2)Red Team Exercises   
  • P2
STRIDE-LM
CA-9Internal System Connections
  • P2
STRIDE-LM
(1)Security Compliance Checks   
  • P2
STRIDE-LM
CM-4Security Impact Analysis
  • P2
STRIDE-LM
(1)Separate Test Environments  
  • P2
STRIDE-LM
(2)Verification Of Security Functions   
  • P2
STRIDE-LM
CM-10Software Usage Restrictions
  • P2
STRIDE-LM
(1)Open Source Software   
  • P2
STRIDE-LM
CP-3Contingency Training
  • P2
STRIDE-LM
(1)Simulated Events  
  • P2
STRIDE-LM
(2)Automated Training Environments   
  • P2
STRIDE-LM
CP-4Contingency Plan Testing
  • P2
STRIDE-LM
(1)Coordinate With Related Plans 
  • P2
STRIDE-LM
(2)Alternate Processing Site  
  • P2
STRIDE-LM
(3)Automated Testing   
  • P2
STRIDE-LM
(4)Full Recovery / Reconstitution   
  • P2
STRIDE-LM
IA-6Authenticator Feedback
  • P2
STRIDE-LM
IR-2Incident Response Training
  • P2
STRIDE-LM
(1)Simulated Events  
  • P2
STRIDE-LM
(2)Automated Training Environments  
  • P2
STRIDE-LM
IR-3Incident Response Testing 
  • P2
STRIDE-LM
(1)Automated Testing   
  • P2
STRIDE-LM
(2)Coordination With Related Plans 
  • P2
STRIDE-LM
IR-7Incident Response Assistance
  • P2
STRIDE-LM
(1)Automation Support For Availability Of Information / Support 
  • P2
STRIDE-LM