Control Objectives: Leadership and high level objectives

No control objectives match the current filters.
Add inventoried assets to the asset register database, as necessary.
SNow
Classification: PreventiveState: Published
Add inventoried assets to the asset register database, as necessary.
Approve all compliance documents.
SNow
Classification: PreventiveState: Published
Approve all compliance documents.
Assign the corporate governance of Information Technology to the compliance oversight committee.
SNow
Classification: PreventiveState: Published
Assign the corporate governance of Information Technology to the compliance oversight committee.
Assign the review of Information Technology policies and procedures to the compliance oversight committee.
SNow
Classification: PreventiveState: Published
Assign the review of Information Technology policies and procedures to the compliance oversight committee.
Communicate the Information Technology plans to all interested personnel and affected parties.
SNow
Classification: PreventiveState: Published
Communicate the Information Technology plans to all interested personnel and affected parties.
Conduct Quality Control to ensure adherence to Information Technology policies, standards, and procedures.
SNow
Classification: DetectiveState: Published
Conduct Quality Control to ensure adherence to Information Technology policies, standards, and procedures.
Define the Information Assurance strategic roles and responsibilities.
SNow
Classification: PreventiveState: Published
Define the Information Assurance strategic roles and responsibilities.
Document organizational objectives.
SNow
Classification: PreventiveState: Published
Document organizational objectives.
Enforce a continuous Quality Control system.
SNow
Classification: DetectiveState: Published
Enforce a continuous Quality Control system.
Establish and maintain a Compliance Exception standard for compliance exceptions.
SNow
Classification: PreventiveState: Published
Establish and maintain a Compliance Exception standard for compliance exceptions.
Establish and maintain a Governance, Risk, and Compliance awareness and training program.
SNow
Classification: PreventiveState: Published
Establish and maintain a Governance, Risk, and Compliance awareness and training program.
Establish and maintain a Quality Management framework.
SNow
Classification: PreventiveState: Published
Establish and maintain a Quality Management framework.
Establish and maintain a Quality Management program.
SNow
Classification: PreventiveState: Published
Establish and maintain a Quality Management program.
Establish and maintain a compliance oversight committee.
SNow
Classification: DetectiveState: Published
Establish and maintain a compliance oversight committee.
Establish and maintain a data classification scheme.
SNow
Classification: PreventiveState: Published
Establish and maintain a data classification scheme.
Establish and maintain a hardware asset inventory.
SNow
Classification: PreventiveState: Published
Establish and maintain a hardware asset inventory.
Establish and maintain a high-level Strategic Information Technology Plan.
SNow
Classification: PreventiveState: Published
Establish and maintain a high-level Strategic Information Technology Plan.
Establish and maintain a rapport with business and technical communities throughout the organization to promote the value and importance of Information Security.
SNow
Classification: PreventiveState: Published
Establish and maintain a rapport with business and technical communities throughout the organization to promote the value and importance of Information Security.
Establish and maintain a storage media inventory.
SNow
Classification: PreventiveState: Published
Establish and maintain a storage media inventory.
Establish and maintain an Information Architecture model.
SNow
Classification: PreventiveState: Published
Establish and maintain an Information Architecture model.
Establish and maintain an Information Technology inventory with asset discovery audit trails.
SNow
Classification: PreventiveState: Published
Establish and maintain an Information Technology inventory with asset discovery audit trails.
Establish and maintain an information classification scheme.
SNow
Classification: PreventiveState: Published
Establish and maintain an information classification scheme.
Establish and maintain an information classification standard to use when establishing information impact levels.
SNow
Classification: PreventiveState: Published
Establish and maintain an information classification standard to use when establishing information impact levels.
Establish and maintain an organizational data dictionary, including data syntax rules.
SNow
Classification: PreventiveState: Published
Establish and maintain an organizational data dictionary, including data syntax rules.
Establish and maintain an overall Quality Management standard.
SNow
Classification: PreventiveState: Published
Establish and maintain an overall Quality Management standard.
Establish and maintain full documentation of all policies, standards, and procedures that support the organization's compliance framework.
SNow
Classification: PreventiveState: Published
Establish and maintain full documentation of all policies, standards, and procedures that support the organization's compliance framework.
Establish and maintain policies, standards, and procedures used to manage compliance documents.
SNow
Classification: PreventiveState: Published
Establish and maintain policies, standards, and procedures used to manage compliance documents.
Establish and maintain sustainable infrastructure planning.
SNow
Classification: PreventiveState: Published
Establish and maintain sustainable infrastructure planning.
Establish and maintain tactical Information Technology plans and Information Technology projects in support of the Strategic Information Technology Plan.
SNow
Classification: PreventiveState: Published
Establish and maintain tactical Information Technology plans and Information Technology projects in support of the Strategic Information Technology Plan.
Establish and maintain tactical Information Technology plans derived from the Strategic Information Technology Plan.
SNow
Classification: PreventiveState: Published
Establish and maintain tactical Information Technology plans derived from the Strategic Information Technology Plan.
Establish and maintain the scope of the organizational compliance framework and Information Assurance controls.
SNow
Classification: PreventiveState: Published
Establish and maintain the scope of the organizational compliance framework and Information Assurance controls.
Identify discrepancies between the asset register database and the Information Technology inventory, as necessary.
SNow
Classification: CorrectiveState: Published
Identify discrepancies between the asset register database and the Information Technology inventory, as necessary.
Identify processes, Information Systems, and third parties that transmit, store, or process Personally Identifiable Information.
SNow
Classification: PreventiveState: Published
Identify processes, Information Systems, and third parties that transmit, store, or process Personally Identifiable Information.
Identify roles, tasks, information, systems, and assets that fall under the organization's mandated Authority Documents.
SNow
Classification: PreventiveState: Published
Identify roles, tasks, information, systems, and assets that fall under the organization's mandated Authority Documents.
Include each Information System's system boundaries in the Information Technology inventory.
SNow
Classification: PreventiveState: Published
Include each Information System's system boundaries in the Information Technology inventory.
Include explanations, compensating controls, or risk acceptance in the compliance exceptions Exceptions document.
SNow
Classification: PreventiveState: Published
Include explanations, compensating controls, or risk acceptance in the compliance exceptions Exceptions document.
Include network equipment in the Information Technology inventory.
SNow
Classification: PreventiveState: Published
Include network equipment in the Information Technology inventory.
Include portable computing devices that store restricted data or restricted information in the Information Technology inventory.
SNow
Classification: PreventiveState: Published
Include portable computing devices that store restricted data or restricted information in the Information Technology inventory.
Include software in the Information Technology inventory.
SNow
Classification: PreventiveState: Published
Include software in the Information Technology inventory.
Include the General Support Systems and security support structure in the Information Technology inventory.
SNow
Classification: PreventiveState: Published
Include the General Support Systems and security support structure in the Information Technology inventory.
Involve the Board of Directors in Information Governance.
SNow
Classification: PreventiveState: Published
Involve the Board of Directors in Information Governance.
Mirror the organization's business strategy during Information Technology planning in the Strategic Information Technology Plan.
SNow
Classification: PreventiveState: Published
Mirror the organization's business strategy during Information Technology planning in the Strategic Information Technology Plan.
Monitor and evaluate the implementation and effectiveness of Information Technology Plans.
SNow
Classification: DetectiveState: Published
Monitor and evaluate the implementation and effectiveness of Information Technology Plans.
Review the compliance exceptions Exceptions document annually.
SNow
Classification: PreventiveState: Published
Review the compliance exceptions Exceptions document annually.
Use automated tools to collect Information Technology inventory information, as necessary.
SNow
Classification: PreventiveState: Published
Use automated tools to collect Information Technology inventory information, as necessary.
Graph Explorer