NIST Special Publication 800-53 Revision 4
IDNameBaselinesPriorityThreats
LowModerateHigh
AC-3(2)Dual Authorization   
  • P1
STRIDE-LM
AC-4(19)Validation Of Metadata   
  • P1
STRIDE-LM
AC-16(2)Attribute Value Changes By Authorized Individuals   
  • P0
STRIDE-LM
(6)Maintenance Of Attribute Association By Organization   
  • P0
STRIDE-LM
(10)Attribute Configuration By Authorized Individuals   
  • P0
STRIDE-LM
AC-17(2)Protection Of Confidentiality / Integrity Using Encryption ••
  • P1
STRIDE-LM
AC-25Reference Monitor   
  • P0
STRIDE-LM
AU-9Protection Of Audit Information•••
  • P1
STRIDE-LM
(1)Hardware Write-Once Media   
  • P1
STRIDE-LM
(2)Audit Backup On Separate Physical Systems / Components  •
  • P1
STRIDE-LM
(3)Cryptographic Protection  •
  • P1
STRIDE-LM
(4)Access By Subset Of Privileged Users ••
  • P1
STRIDE-LM
(5)Dual Authorization   
  • P1
STRIDE-LM
(6)Read Only Access   
  • P1
STRIDE-LM
AU-10(3)Chain Of Custody   
  • P2
STRIDE-LM
CM-1Configuration Management Policy And Procedures•••
  • P1
STRIDE-LM
CM-2(3)Retention Of Previous Configurations ••
  • P1
STRIDE-LM
CM-3Configuration Change Control ••
  • P1
STRIDE-LM
(1)Automated Document / Notification / Prohibition Of Changes  •
  • P1
STRIDE-LM
(2)Test / Validate / Document Changes ••
  • P1
STRIDE-LM
(6)Cryptography Management   
  • P1
STRIDE-LM
CM-5Access Restrictions For Change ••
  • P1
STRIDE-LM
(2)Review System Changes  •
  • P1
STRIDE-LM
(3)Signed Components  •
  • P1
STRIDE-LM
(4)Dual Authorization   
  • P1
STRIDE-LM
CM-6Configuration Settings•••
  • P1
STRIDE-LM
(2)Respond To Unauthorized Changes  •
  • P1
STRIDE-LM
CM-9Configuration Management Plan ••
  • P1
STRIDE-LM
CM-11(1)Alerts For Unauthorized Installations   
  • P1
STRIDE-LM
CP-9Information System Backup•••
  • P1
STRIDE-LM
(1)Testing For Reliability / Integrity ••
  • P1
STRIDE-LM
CP-10Information System Recovery And Reconstitution•••
  • P1
STRIDE-LM
(6)Component Protection   
  • P1
STRIDE-LM
IA-3(4)Device Attestation   
  • P1
STRIDE-LM
IA-9(2)Transmission Of Decisions   
  • P0
STRIDE-LM
IR-4(6)Insider Threats - Specific Capabilities   
  • P1
STRIDE-LM
MA-3Maintenance Tools ••
  • P3
STRIDE-LM
(1)Inspect Tools ••
  • P3
STRIDE-LM
(2)Inspect Media ••
  • P3
STRIDE-LM
(4)Restricted Tool Use   
  • P3
STRIDE-LM
MA-4(6)Cryptographic Protection   
  • P2
STRIDE-LM
MP-5Media Transport ••
  • P1
STRIDE-LM
(4)Cryptographic Protection ••
  • P1
STRIDE-LM
PE-2(3)Restrict Unescorted Access   
  • P1
STRIDE-LM
PE-3Physical Access Control•••
  • P1
STRIDE-LM
(4)Lockable Casings   
  • P1
STRIDE-LM
(5)Tamper Protection   
  • P1
STRIDE-LM
PE-4Access Control For Transmission Medium ••
  • P1
STRIDE-LM
PE-6Monitoring Physical Access•••
  • P1
STRIDE-LM
PL-8(1)Defense-In-Depth   
  • P1
STRIDE-LM