Control Objectives: Operational management

No control objectives match the current filters.
Align critical Information Technology resource availability planning with capacity planning.
SNow
Classification: PreventiveState: Published
Align critical Information Technology resource availability planning with capacity planning.
Analyze security violations in Suspicious Activity Reports.
SNow
Classification: PreventiveState: Published
Analyze security violations in Suspicious Activity Reports.
Any domain controller connected to the manufacturing system must be hardened and comply with the established vulnerability scanning and patch management procedures.
SNow
Classification: ProtectState: Published
Any domain controller connected to the manufacturing system must be hardened and comply with the established vulnerability scanning and patch management procedures.
Approve change requests prior to implementing approved changes.
SNow
Classification: PreventiveState: Published
Approve change requests prior to implementing approved changes.
Assess all security incidents to determine what information was accessed.
SNow
Classification: CorrectiveState: Published
Assess all security incidents to determine what information was accessed.
Assign ownership of the information security governance program to the appropriate role.
SNow
Classification: PreventiveState: Published
Assign ownership of the information security governance program to the appropriate role.
Assign ownership of the internal control framework to the appropriate organizational role.
SNow
Classification: PreventiveState: Published
Assign ownership of the internal control framework to the appropriate organizational role.
Assign resources to implement the internal control framework.
SNow
Classification: PreventiveState: Published
Assign resources to implement the internal control framework.
Automatically respond when an integrity violation is detected.
SNow
Classification: CorrectiveState: Published
Automatically respond when an integrity violation is detected.
Budget appropriately for Information Security.
SNow
Classification: PreventiveState: Published
Budget appropriately for Information Security.
Collect evidence from the incident scene.
SNow
Classification: CorrectiveState: Published
Collect evidence from the incident scene.
Communicate proposed changes to all interested personnel and affected parties.
SNow
Classification: PreventiveState: Published
Communicate proposed changes to all interested personnel and affected parties.
Communicate updates to the Governance, Risk, and Compliance framework to interested personnel and affected parties, as necessary.
SNow
Classification: PreventiveState: Published
Communicate updates to the Governance, Risk, and Compliance framework to interested personnel and affected parties, as necessary.
Compare actual Information Technology costs to forecasted Information Technology budgets.
SNow
Classification: DetectiveState: Published
Compare actual Information Technology costs to forecasted Information Technology budgets.
Conduct maintenance with authorized personnel.
SNow
Classification: DetectiveState: Published
Conduct maintenance with authorized personnel.
Contain the incident to prevent further loss and preserve the system for forensic analysis.
SNow
Classification: CorrectiveState: Published
Contain the incident to prevent further loss and preserve the system for forensic analysis.
Control and monitor all maintenance tools.
SNow
Classification: DetectiveState: Published
Control and monitor all maintenance tools.
Control remote maintenance according to the system's asset classification.
SNow
Classification: PreventiveState: Published
Control remote maintenance according to the system's asset classification.
Coordinate backup procedures as defined in the system continuity plan with backup procedures necessary for incident response procedures.
SNow
Classification: PreventiveState: Published
Coordinate backup procedures as defined in the system continuity plan with backup procedures necessary for incident response procedures.
Correlate the Acceptable Use Policy with the approved product list.
SNow
Classification: PreventiveState: Published
Correlate the Acceptable Use Policy with the approved product list.
Deploy software patches.
SNow
Classification: CorrectiveState: Published
Deploy software patches.
Develop and maintain an archive of maintenance reports in a maintenance log.
SNow
Classification: PreventiveState: Published
Develop and maintain an archive of maintenance reports in a maintenance log.
Disassemble and shut down unnecessary systems or unused systems.
SNow
Classification: PreventiveState: Published
Disassemble and shut down unnecessary systems or unused systems.
Dispose of hardware and software at their life cycle end.
SNow
Classification: PreventiveState: Published
Dispose of hardware and software at their life cycle end.
Disseminate and communicate the Governance, Risk, and Compliance framework to all interested personnel and affected parties.
SNow
Classification: PreventiveState: Published
Disseminate and communicate the Governance, Risk, and Compliance framework to all interested personnel and affected parties.
Distribute the incident response procedures to all interested personnel and affected parties.
SNow
Classification: PreventiveState: Published
Distribute the incident response procedures to all interested personnel and affected parties.
Document all change requests in change request forms.
SNow
Classification: PreventiveState: Published
Document all change requests in change request forms.
Document approved configuration deviations.
SNow
Classification: CorrectiveState: Published
Document approved configuration deviations.
Document periodic maintenance in maintenance reports.
SNow
Classification: PreventiveState: Published
Document periodic maintenance in maintenance reports.
Establish and maintain Voice over Internet Protocol operating procedures.
SNow
Classification: PreventiveState: Published
Establish and maintain Voice over Internet Protocol operating procedures.
Establish and maintain a Configuration Management program.
SNow
Classification: PreventiveState: Published
Establish and maintain a Configuration Management program.
Establish and maintain a Standard Operating Procedures Manual.
SNow
Classification: PreventiveState: Published
Establish and maintain a Standard Operating Procedures Manual.
Establish and maintain a capacity management standard.
SNow
Classification: PreventiveState: Published
Establish and maintain a capacity management standard.
Establish and maintain a configuration change log.
SNow
Classification: DetectiveState: Published
Establish and maintain a configuration change log.
Establish and maintain a current configuration baseline based on the least functionality principle.
SNow
Classification: PreventiveState: Published
Establish and maintain a current configuration baseline based on the least functionality principle.
Establish and maintain a customer service business function.
SNow
Classification: PreventiveState: Published
Establish and maintain a customer service business function.
Establish and maintain a data processing continuity plan.
SNow
Classification: PreventiveState: Published
Establish and maintain a data processing continuity plan.
Establish and maintain a data processing run manual.
SNow
Classification: PreventiveState: Published
Establish and maintain a data processing run manual.
Establish and maintain a job schedule exceptions list.
SNow
Classification: PreventiveState: Published
Establish and maintain a job schedule exceptions list.
Establish and maintain a job scheduling methodology.
SNow
Classification: PreventiveState: Published
Establish and maintain a job scheduling methodology.
Establish and maintain a patch management program.
SNow
Classification: PreventiveState: Published
Establish and maintain a patch management program.
Establish and maintain a performance management standard.
SNow
Classification: PreventiveState: Published
Establish and maintain a performance management standard.
Establish and maintain a positive information control environment.
SNow
Classification: PreventiveState: Published
Establish and maintain a positive information control environment.
Establish and maintain a privacy policy.
SNow
Classification: PreventiveState: Published
Establish and maintain a privacy policy.
Establish and maintain a shared resources management program.
SNow
Classification: PreventiveState: Published
Establish and maintain a shared resources management program.
Establish and maintain a social media governance program.
SNow
Classification: PreventiveState: Published
Establish and maintain a social media governance program.
Establish and maintain a software release policy.
SNow
Classification: PreventiveState: Published
Establish and maintain a software release policy.
Establish and maintain a system redeployment or disposal program.
SNow
Classification: PreventiveState: Published
Establish and maintain a system redeployment or disposal program.
Establish and maintain an Information Technology financial management framework.
SNow
Classification: PreventiveState: Published
Establish and maintain an Information Technology financial management framework.
Establish and maintain an Intellectual Property Right program.
SNow
Classification: PreventiveState: Published
Establish and maintain an Intellectual Property Right program.
Establish and maintain an asset inventory database.
SNow
Classification: PreventiveState: Published
Establish and maintain an asset inventory database.
Establish and maintain an e-mail policy.
SNow
Classification: PreventiveState: Published
Establish and maintain an e-mail policy.
Establish and maintain an unauthorized software list.
SNow
Classification: PreventiveState: Published
Establish and maintain an unauthorized software list.
Establish and maintain application asset management procedures.
SNow
Classification: PreventiveState: Published
Establish and maintain application asset management procedures.
Establish and maintain compromised system reaccreditation procedures.
SNow
Classification: PreventiveState: Published
Establish and maintain compromised system reaccreditation procedures.
Establish and maintain emergency change procedures.
SNow
Classification: PreventiveState: Published
Establish and maintain emergency change procedures.
Establish and maintain future system capacity forecasting methods.
SNow
Classification: PreventiveState: Published
Establish and maintain future system capacity forecasting methods.
Establish and maintain help desk query clearance monitoring procedures.
SNow
Classification: PreventiveState: Published
Establish and maintain help desk query clearance monitoring procedures.
Establish and maintain help desk query escalation procedures.
SNow
Classification: PreventiveState: Published
Establish and maintain help desk query escalation procedures.
Establish and maintain help desk query trend analysis procedures.
SNow
Classification: PreventiveState: Published
Establish and maintain help desk query trend analysis procedures.
Establish and maintain incident response procedures.
SNow
Classification: DetectiveState: Published
Establish and maintain incident response procedures.
Establish and maintain nondisclosure agreements.
SNow
Classification: PreventiveState: Published
Establish and maintain nondisclosure agreements.
Establish and maintain rate limiting filters.
SNow
Classification: PreventiveState: Published
Establish and maintain rate limiting filters.
Establish and maintain software asset management procedures.
SNow
Classification: PreventiveState: Published
Establish and maintain software asset management procedures.
Establish and maintain software distribution procedures.
SNow
Classification: PreventiveState: Published
Establish and maintain software distribution procedures.
Establish and maintain software license management procedures.
SNow
Classification: PreventiveState: Published
Establish and maintain software license management procedures.
Establish and maintain system capacity monitoring procedures.
SNow
Classification: PreventiveState: Published
Establish and maintain system capacity monitoring procedures.
Follow the resource workload schedule.
SNow
Classification: DetectiveState: Published
Follow the resource workload schedule.
Forecast system workloads.
SNow
Classification: DetectiveState: Published
Forecast system workloads.
If applicable, use of "secure" (encrypted version like https or SMBv3 for example) network protocols. Alternatives may include the use of edge devices or similar devices
SNow
Classification: ProtectState: Published
If applicable, use of "secure" (encrypted version like https or SMBv3 for example) network protocols. Alternatives may include the use of edge devices or similar devices
Implement and comply with the Governance, Risk, and Compliance framework.
SNow
Classification: PreventiveState: Published
Implement and comply with the Governance, Risk, and Compliance framework.
Implement approved changes.
SNow
Classification: PreventiveState: Published
Implement approved changes.
Include that explicit management authorization must be given for the use of all technologies and their documentation in the Acceptable Use Policy.
SNow
Classification: PreventiveState: Published
Include that explicit management authorization must be given for the use of all technologies and their documentation in the Acceptable Use Policy.
Include Bring Your Own Device security guidelines in the Acceptable Use Policy.
SNow
Classification: PreventiveState: Published
Include Bring Your Own Device security guidelines in the Acceptable Use Policy.
Include a software installation policy in the Acceptable Use Policy.
SNow
Classification: PreventiveState: Published
Include a software installation policy in the Acceptable Use Policy.
Include access control mechanisms in the Acceptable Use Policy.
SNow
Classification: PreventiveState: Published
Include access control mechanisms in the Acceptable Use Policy.
Include after-action analysis procedures in the Incident Management program.
SNow
Classification: PreventiveState: Published
Include after-action analysis procedures in the Incident Management program.
Include asset tags in the Acceptable Use Policy.
SNow
Classification: PreventiveState: Published
Include asset tags in the Acceptable Use Policy.
Include asset use policies in the Acceptable Use Policy.
SNow
Classification: PreventiveState: Published
Include asset use policies in the Acceptable Use Policy.
Include assigning and approving operations in operational control procedures.
SNow
Classification: PreventiveState: Published
Include assigning and approving operations in operational control procedures.
Include business continuity procedures in the Incident Response program.
SNow
Classification: PreventiveState: Published
Include business continuity procedures in the Incident Response program.
Include continuous security warning monitoring procedures in the internal control framework.
SNow
Classification: PreventiveState: Published
Include continuous security warning monitoring procedures in the internal control framework.
Include continuous user account management procedures in the internal control framework.
SNow
Classification: PreventiveState: Published
Include continuous user account management procedures in the internal control framework.
Include data loss event notifications in the Incident Response program.
SNow
Classification: PreventiveState: Published
Include data loss event notifications in the Incident Response program.
Include emergency processing priorities in the Incident Management program.
SNow
Classification: PreventiveState: Published
Include emergency processing priorities in the Incident Management program.
Include explicit restrictions in the social media acceptable usage policy.
SNow
Classification: PreventiveState: Published
Include explicit restrictions in the social media acceptable usage policy.
Include incident escalation procedures in the Incident Management program.
SNow
Classification: PreventiveState: Published
Include incident escalation procedures in the Incident Management program.
Include incident monitoring procedures in the Incident Management program.
SNow
Classification: PreventiveState: Published
Include incident monitoring procedures in the Incident Management program.
Include incident record closure procedures in the Incident Management program.
SNow
Classification: PreventiveState: Published
Include incident record closure procedures in the Incident Management program.
Include incident reporting procedures in the Incident Management program.
SNow
Classification: PreventiveState: Published
Include incident reporting procedures in the Incident Management program.
Include incident response team services in the Incident Response program.
SNow
Classification: PreventiveState: Published
Include incident response team services in the Incident Response program.
Include incident response team structures in the Incident Response program.
SNow
Classification: PreventiveState: Published
Include incident response team structures in the Incident Response program.
Include personnel contact information in the event of an incident in the Incident Response program.
SNow
Classification: PreventiveState: Published
Include personnel contact information in the event of an incident in the Incident Response program.
Include personnel security procedures in the internal control framework.
SNow
Classification: PreventiveState: Published
Include personnel security procedures in the internal control framework.
Include procedures for continuous quality improvement in the internal control framework.
SNow
Classification: PreventiveState: Published
Include procedures for continuous quality improvement in the internal control framework.
Include security incident response procedures in the internal control framework.
SNow
Classification: PreventiveState: Published
Include security incident response procedures in the internal control framework.
Include security information sharing procedures in the internal control framework.
SNow
Classification: PreventiveState: Published
Include security information sharing procedures in the internal control framework.
Include startup processes in operational control procedures.
SNow
Classification: PreventiveState: Published
Include startup processes in operational control procedures.
Include temporary and emergency access authorization procedures in the Incident Management program.
SNow
Classification: CorrectiveState: Published
Include temporary and emergency access authorization procedures in the Incident Management program.
Include the consequences of non-compliance in the Acceptable Use Policy.
SNow
Classification: CorrectiveState: Published
Include the consequences of non-compliance in the Acceptable Use Policy.
Include the incident response team member's roles and responsibilities in the Incident Response program.
SNow
Classification: PreventiveState: Published
Include the incident response team member's roles and responsibilities in the Incident Response program.
Include the incident response training program in the Incident Response program.
SNow
Classification: PreventiveState: Published
Include the incident response training program in the Incident Response program.
Include threat assessment, vulnerability management, and risk assessment in the internal control framework.
SNow
Classification: PreventiveState: Published
Include threat assessment, vulnerability management, and risk assessment in the internal control framework.
Incorporate realistic exercises that are tested into the incident response training program.
SNow
Classification: PreventiveState: Published
Incorporate realistic exercises that are tested into the incident response training program.
Incorporate simulated events into the incident response training program.
SNow
Classification: PreventiveState: Published
Incorporate simulated events into the incident response training program.
Investigate and take action regarding help desk queries.
SNow
Classification: CorrectiveState: Published
Investigate and take action regarding help desk queries.
Isolate compromised systems from the network.
SNow
Classification: CorrectiveState: Published
Isolate compromised systems from the network.
Justify the system's cost and benefit.
SNow
Classification: DetectiveState: Published
Justify the system's cost and benefit.
Log help desk queries.
SNow
Classification: PreventiveState: Published
Log help desk queries.
Log incidents in the Incident Management audit log.
SNow
Classification: PreventiveState: Published
Log incidents in the Incident Management audit log.
Manage change requests.
SNow
Classification: PreventiveState: Published
Manage change requests.
Manage changes.
SNow
Classification: PreventiveState: Published
Manage changes.
Measure policy compliance when reviewing the internal control framework.
SNow
Classification: CorrectiveState: Published
Measure policy compliance when reviewing the internal control framework.
Monitor for and react to when suspicious activities are detected.
SNow
Classification: DetectiveState: Published
Monitor for and react to when suspicious activities are detected.
Monitor for sufficicient system capacity.
SNow
Classification: DetectiveState: Published
Monitor for sufficicient system capacity.
Notify organizational unit leaders prior to when the system is redeployed or the system is disposed.
SNow
Classification: PreventiveState: Published
Notify organizational unit leaders prior to when the system is redeployed or the system is disposed.
Perform a patch test prior to deploying a patch.
SNow
Classification: DetectiveState: Published
Perform a patch test prior to deploying a patch.
Perform maintenance in a timely manner.
SNow
Classification: PreventiveState: Published
Perform maintenance in a timely manner.
Perform risk assessments prior to approving change requests.
SNow
Classification: PreventiveState: Published
Perform risk assessments prior to approving change requests.
Plan and conduct maintenance so that it does not interfere with scheduled operations.
SNow
Classification: PreventiveState: Published
Plan and conduct maintenance so that it does not interfere with scheduled operations.
Prepare an annual Information Technology budget.
SNow
Classification: DetectiveState: Published
Prepare an annual Information Technology budget.
Prepare for incident response notifications.
SNow
Classification: PreventiveState: Published
Prepare for incident response notifications.
Prioritize deploying patches according to vulnerability risk metrics.
SNow
Classification: PreventiveState: Published
Prioritize deploying patches according to vulnerability risk metrics.
Record Configuration Management items in the Configuration Management database.
SNow
Classification: PreventiveState: Published
Record Configuration Management items in the Configuration Management database.
Record the manufacturer's serial number for applicable assets in the asset inventory.
SNow
Classification: PreventiveState: Published
Record the manufacturer's serial number for applicable assets in the asset inventory.
Record the owner for applicable assets in the asset inventory.
SNow
Classification: PreventiveState: Published
Record the owner for applicable assets in the asset inventory.
Record the physical location for applicable assets in the asset inventory.
SNow
Classification: PreventiveState: Published
Record the physical location for applicable assets in the asset inventory.
Report data loss events to breach notification organizations.
SNow
Classification: CorrectiveState: Published
Report data loss events to breach notification organizations.
Require interested personnel and affected parties to re-sign Acceptable Use Policies, as necessary.
SNow
Classification: PreventiveState: Published
Require interested personnel and affected parties to re-sign Acceptable Use Policies, as necessary.
Require interested personnel and affected parties to sign Acceptable Use Policies.
SNow
Classification: PreventiveState: Published
Require interested personnel and affected parties to sign Acceptable Use Policies.
Respond to all alerts from security systems in a timely manner.
SNow
Classification: CorrectiveState: Published
Respond to all alerts from security systems in a timely manner.
Respond to and triage when a security incident is detected.
SNow
Classification: DetectiveState: Published
Respond to and triage when a security incident is detected.
Respond to maintenance requests inside the organizationally established timeframe.
SNow
Classification: PreventiveState: Published
Respond to maintenance requests inside the organizationally established timeframe.
Restart systems when an integrity violation is detected, as necessary.
SNow
Classification: CorrectiveState: Published
Restart systems when an integrity violation is detected, as necessary.
Review and update the Governance, Risk, and Compliance framework, as necessary.
SNow
Classification: CorrectiveState: Published
Review and update the Governance, Risk, and Compliance framework, as necessary.
Review and update the incident response procedures after a security incident has been closed.
SNow
Classification: PreventiveState: Published
Review and update the incident response procedures after a security incident has been closed.
Review each system's operational readiness.
SNow
Classification: PreventiveState: Published
Review each system's operational readiness.
Review the configuration change log.
SNow
Classification: DetectiveState: Published
Review the configuration change log.
Review the internal control framework, as necessary.
SNow
Classification: DetectiveState: Published
Review the internal control framework, as necessary.
Share incident information with interested personnel and affected parties.
SNow
Classification: CorrectiveState: Published
Share incident information with interested personnel and affected parties.
Share relevant security information with Special Interest Groups, as necessary.
SNow
Classification: PreventiveState: Published
Share relevant security information with Special Interest Groups, as necessary.
Shut down systems when an integrity violation is detected, as necessary.
SNow
Classification: CorrectiveState: Published
Shut down systems when an integrity violation is detected, as necessary.
Test network access controls for proper Configuration Management settings.
SNow
Classification: DetectiveState: Published
Test network access controls for proper Configuration Management settings.
Test systems for malicious code prior to when the system will be redeployed.
SNow
Classification: DetectiveState: Published
Test systems for malicious code prior to when the system will be redeployed.
Test the incident response procedures.
SNow
Classification: DetectiveState: Published
Test the incident response procedures.
Test the system's operational functionality after implementing approved changes.
SNow
Classification: DetectiveState: Published
Test the system's operational functionality after implementing approved changes.
The manufacturing system and its components/peripherals (i.e. PLCs, HMIs, hubs, switches, etc.) should not utilize any default credentials.
SNow
Classification: ProtectState: Published
The manufacturing system and its components/peripherals (i.e. PLCs, HMIs, hubs, switches, etc.) should not utilize any default credentials.
The manufacturing system should diffenrenciate between standard user accounts and privileged user accounts (admins etc.). Privileged user accounts should be limited and the user should be trained in regard to of the elevated permissions and associat
SNow
State: Retired
The manufacturing system should diffenrenciate between standard user accounts and privileged user accounts (admins etc.). Privileged user accounts should be limited and the user should be trained in regard to of the elevated permissions and associated risks to their account.
The manufacturing system should have defined ownership (e.g. System Owner, System Manager) to address required cybersecurity measures.
SNow
Classification: RespondState: Published
The manufacturing system should have defined ownership (e.g. System Owner, System Manager) to address required cybersecurity measures.
Unencrypted/unsecure network traffic should not transit into other network zones/segments
SNow
State: Retired
Alternative solutions for data transfer should be evaluated or implemented (data gateway, secure storage media solutions...)
Update associated documentation after the system configuration has been changed.
SNow
Classification: PreventiveState: Published
Update associated documentation after the system configuration has been changed.
Update the incident response procedures using the lessons learned.
SNow
Classification: PreventiveState: Published
Update the incident response procedures using the lessons learned.
Update the system's backup procedures after an approved change has occurred.
SNow
Classification: PreventiveState: Published
Update the system's backup procedures after an approved change has occurred.
Utilize resource availability management controls.
SNow
Classification: DetectiveState: Published
Utilize resource availability management controls.
Utilize resource capacity management controls.
SNow
Classification: DetectiveState: Published
Utilize resource capacity management controls.
Validate the system before implementing approved changes.
SNow
Classification: PreventiveState: Published
Validate the system before implementing approved changes.
Wipe all data on systems prior to when the system is redeployed or the system is disposed.
SNow
Classification: PreventiveState: Published
Wipe all data on systems prior to when the system is redeployed or the system is disposed.
Graph Explorer