A comprehensive catalogue of security and privacy controls, widely used as a control reference well beyond its original United States federal context.
United States federal systems and their suppliers by obligation, and a much wider set of organisations by choice, because the catalogue is thorough and freely published.
Its depth is both its strength and its difficulty. The catalogue is frequently used as a reference against which other frameworks are mapped, which is why it appears in cross-framework work far more often than as a compliance target in its own right.
Authorisation within a United States federal context, or an internal control position where it is adopted voluntarily.
SecureEdge Advisory prepares you and facilitates the process. The affirmation is made by an external auditor, a certification body or the regulator, never by us.
Control mappings exist between this framework and others in the library, so evidence gathered here may support work elsewhere. Mappings are published as draft, and a mapping shows a relationship rather than satisfied coverage. An auditor decides whether the evidence answers the requirement.