IDNameBaselinesThreats
    LowModerateHighPrivacy
    AC-4(24)Internal Normalized Format    STRIDE-LM
    (25)Data Sanitization    STRIDE-LM
    (26)Audit Filtering Actions    STRIDE-LM
    (27)Redundant/independent Filtering Mechanisms    STRIDE-LM
    (28)Linear Filter Pipelines    STRIDE-LM
    (29)Filter Orchestration Engines    STRIDE-LM
    (30)Filter Mechanisms Using Multiple Processes    STRIDE-LM
    (31)Failed Content Transfer Prevention    STRIDE-LM
    (32)Process Requirements for Information Transfer    STRIDE-LM
    AC-5Separation of Duties  STRIDE-LM
    AC-6Least Privilege  STRIDE-LM
    (1)Authorize Access to Security Functions  STRIDE-LM
    (2)Non-privileged Access for Nonsecurity Functions  STRIDE-LM
    (3)Network Access to Privileged Commands   STRIDE-LM
    (4)Separate Processing Domains    STRIDE-LM
    (5)Privileged Accounts  STRIDE-LM
    (6)Privileged Access by Non-organizational Users    STRIDE-LM
    (7)Review of User Privileges  STRIDE-LM
    (8)Privilege Levels for Code Execution    STRIDE-LM
    (9)Log Use of Privileged Functions  STRIDE-LM
    (10)Prohibit Non-privileged Users from Executing Privileged Functions  STRIDE-LM
    AC-7Unsuccessful Logon Attempts STRIDE-LM
    (2)Purge or Wipe Mobile Device    STRIDE-LM
    (3)Biometric Attempt Limiting    STRIDE-LM
    (4)Use of Alternate Authentication Factor    STRIDE-LM
    AC-8System Use Notification STRIDE-LM
    AC-9Previous Logon Notification    STRIDE-LM
    (1)Unsuccessful Logons    STRIDE-LM
    (2)Successful and Unsuccessful Logons    STRIDE-LM
    (3)Notification of Account Changes    STRIDE-LM
    (4)Additional Logon Information    STRIDE-LM
    AC-10Concurrent Session Control   STRIDE-LM
    AC-11Device Lock  STRIDE-LM
    (1)Pattern-hiding Displays  STRIDE-LM
    AC-12Session Termination  STRIDE-LM
    (1)User-initiated Logouts    STRIDE-LM
    (2)Termination Message    STRIDE-LM
    (3)Timeout Warning Message    STRIDE-LM
    AC-14Permitted Actions Without Identification or Authentication STRIDE-LM
    AC-16Security and Privacy Attributes    STRIDE-LM
    (1)Dynamic Attribute Association    STRIDE-LM
    (2)Attribute Value Changes by Authorized Individuals    STRIDE-LM
    (3)Maintenance of Attribute Associations by System    STRIDE-LM
    (4)Association of Attributes by Authorized Individuals    STRIDE-LM
    (5)Attribute Displays on Objects to Be Output    STRIDE-LM
    (6)Maintenance of Attribute Association    STRIDE-LM
    (7)Consistent Attribute Interpretation    STRIDE-LM
    (8)Association Techniques and Technologies    STRIDE-LM
    (9)Attribute Reassignment - Regrading Mechanisms    STRIDE-LM
    (10)Attribute Configuration by Authorized Individuals    STRIDE-LM