| AC | Access policy, role matrix, access review, privileged access, remote access, separation of duties. | 09-access-audit-and-data-protection-plan.mdx, 13-policy-library.mdx | Draft |
| AT | Awareness and training policy, role-based training, annual acknowledgement. | 13-policy-library.mdx, 19-record-template-library.mdx | Draft |
| AU | Audit policy, auditable events, schema, retention, review, alerting, integrity protection. | 09-access-audit-and-data-protection-plan.mdx, 15-evidence-automation-map.mdx | Draft |
| CA | Assessment plan inputs, ConMon process, POA&M, authorization strategy. | 01-ato-path-and-assumptions.mdx, 05-evidence-and-conmon-plan.mdx | Draft |
| CM | Baseline, inventory, change control, drift detection, emergency changes. | 08-secure-sdlc-and-supply-chain-plan.mdx, 14-operational-procedure-library.mdx | Draft |
| CP | Contingency plan, backup, restore, RTO, RPO, exercises. | 07-incident-contingency-and-dr-plan.mdx | Draft |
| IA | Identity proofing where needed, MFA, account lifecycle, service accounts, credential management. | 09-access-audit-and-data-protection-plan.mdx | Draft |
| IR | Incident response plan, severity, roles, reporting, exercises, after-action review. | 07-incident-contingency-and-dr-plan.mdx, 19-record-template-library.mdx | Draft |
| MA | Maintenance policy, maintenance windows, remote maintenance, tool approval. | 13-policy-library.mdx, 14-operational-procedure-library.mdx | Draft |
| MP | Media handling, export, backup media, disposal, removable media restrictions. | 09-access-audit-and-data-protection-plan.mdx, 13-policy-library.mdx | Draft |
| PE | Physical and environmental inheritance from cloud or facility provider. | 02-fips-199-and-boundary.mdx, 12-official-fedramp-package-map.mdx | Draft |
| PL | SSP ownership, rules of behavior, architecture, security planning. | 03-system-security-plan-working-outline.mdx, 13-policy-library.mdx | Draft |
| PM | Program governance, inventory ownership, POA&M governance, risk strategy. | 01-ato-path-and-assumptions.mdx, 06-poam-and-risk-register.mdx | Draft |
| PS | Personnel screening, joiner-mover-leaver, termination access removal. | 13-policy-library.mdx, 14-operational-procedure-library.mdx | Draft |
| PT | PII authority, minimization, consent, retention, deletion, privacy review. | 09-access-audit-and-data-protection-plan.mdx | Draft |
| RA | Risk assessment, vulnerability scanning, remediation windows, acceptance. | 06-poam-and-risk-register.mdx, 15-evidence-automation-map.mdx | Draft |
| SA | Secure SDLC, supplier review, test requirements, development standards. | 08-secure-sdlc-and-supply-chain-plan.mdx | Draft |
| SC | Boundary protection, encryption, key management, network segmentation. | 09-access-audit-and-data-protection-plan.mdx, 10-ato-tooling-overview.mdx | Draft |
| SI | Flaw remediation, monitoring, malicious code protection, integrity, validation. | 08-secure-sdlc-and-supply-chain-plan.mdx, 15-evidence-automation-map.mdx | Draft |
| SR | Supplier review, SBOM, provenance, artifact signing, dependency governance. | 08-secure-sdlc-and-supply-chain-plan.mdx, 15-evidence-automation-map.mdx | Draft |