Control Objectives for Information Technologies
Framework for IT governance and management. Helps organizations develop, implement, and improve IT governance and management practices.
| Clause | Title | SP 800-53 Controls |
|---|---|---|
| APO01 | Managed I&T Management Framework | |
| APO02 | Managed Strategy | |
| APO03 | Managed Enterprise Architecture | |
| APO04 | Managed Innovation | |
| APO05 | Managed Portfolio | |
| APO06 | Managed Budget and Costs | |
| APO07 | Managed Human Resources | |
| APO08 | Managed Relationships | |
| APO09 | Managed Service Level Agreements | |
| APO10 | Managed Vendors | |
| APO11 | Managed Quality | |
| APO12 | Managed Risk | |
| APO13 | Managed Security | |
| APO14 | Managed Data | |
| BAI01 | Managed Programs and Projects | |
| BAI02 | Managed Requirements Definition | |
| BAI03 | Managed Solutions Identification and Build | |
| BAI04 | Managed Availability and Capacity | |
| BAI05 | Managed Organizational Change | |
| BAI06 | Managed IT Changes | |
| BAI07 | Managed IT Change Acceptance and Transitioning | |
| BAI08 | Managed Knowledge | |
| BAI09 | Managed Assets | |
| BAI10 | Managed Configuration | |
| BAI11 | Managed IT Projects | |
| DSS01 | Managed Operations | |
| DSS02 | Managed Service Requests and Incidents | |
| DSS03 | Managed Problems | |
| DSS04 | Managed Continuity | |
| DSS05 | Managed Security Services | SC-07 SC-24 SC-44 SC-41 SI-03 SI-04 SI-16 CM-14 AC-01 AC-02 AC-03 AC-04 AC-05 AC-06 AC-07 AC-08 AC-09 AC-10 AC-11 AC-12 AC-13 AC-14 AC-15 AC-16 AC-17 AC-18 AC-19 AC-20 AC-21 AC-22 AC-23 AC-24 AC-25 IA-01 IA-02 IA-03 IA-04 IA-05 IA-06 IA-07 IA-08 IA-09 IA-10 IA-11 IA-12 PE-01 PE-02 PE-03 PE-04 PE-05 PE-06 PE-07 PE-08 PE-09 PE-10 PE-11 PE-12 PE-13 PE-14 PE-15 PE-16 PE-17 PE-18 |
| DSS06 | Managed Business Process Controls | |
| EDM01 | Ensured Governance Framework Setting and Maintenance | |
| EDM02 | Ensured Benefits Delivery | |
| EDM03 | Ensured Risk Optimization | |
| EDM04 | Ensured Resource Optimization | |
| EDM05 | Ensured Stakeholder Engagement | |
| MEA01 | Managed Performance and Conformance Monitoring | |
| MEA02 | Managed System of Internal Control | |
| MEA03 | Managed Compliance with External Requirements | |
| MEA04 | Managed Assurance |