PlumbTrackLive demoGRC Risk System

Internal audit

Work each framework control and governance document through its audit checklist — grounded in NIST SP 800-53A assessment methods (Examine / Interview / Test) — to confirm the organization is in compliance. A failed check is a finding; track open findings to closure on the POA&M.

188
Auditable items
0
Items audited
0
Open findings
0/867
Checks completed

Controls — NIST SP 800-53 NIST SP 800-53 Rev.5

IDControlAudit status
Access Control
AC-1Policy and Proceduresnot started
AC-2Account Managementnot started
AC-3Access Enforcementnot started
AC-4Information Flow Enforcementnot started
AC-5Separation of Dutiesnot started
AC-6Least Privilegenot started
AC-7Unsuccessful Logon Attemptsnot started
AC-8System Use Notificationnot started
AC-10Concurrent Session Controlnot started
AC-11Device Locknot started
AC-12Session Terminationnot started
AC-14Permitted Actions Without Identification or Authenticationnot started
AC-17Remote Accessnot started
AC-18Wireless Accessnot started
AC-19Access Control for Mobile Devicesnot started
AC-20Use of External Systemsnot started
AC-21Information Sharingnot started
AC-22Publicly Accessible Contentnot started
Awareness and Training
AT-1Policy and Proceduresnot started
AT-2Literacy Training and Awarenessnot started
AT-3Role-based Trainingnot started
AT-4Training Recordsnot started
Audit and Accountability
AU-1Policy and Proceduresnot started
AU-2Event Loggingnot started
AU-3Content of Audit Recordsnot started
AU-4Audit Log Storage Capacitynot started
AU-5Response to Audit Logging Process Failuresnot started
AU-6Audit Record Review, Analysis, and Reportingnot started
AU-7Audit Record Reduction and Report Generationnot started
AU-8Time Stampsnot started
AU-9Protection of Audit Informationnot started
AU-10Non-repudiationnot started
AU-11Audit Record Retentionnot started
AU-12Audit Record Generationnot started
Assessment, Authorization, and Monitoring
CA-1Policy and Proceduresnot started
CA-2Control Assessmentsnot started
CA-3Information Exchangenot started
CA-5Plan of Action and Milestonesnot started
CA-6Authorizationnot started
CA-7Continuous Monitoringnot started
CA-8Penetration Testingnot started
CA-9Internal System Connectionsnot started
Configuration Management
CM-1Policy and Proceduresnot started
CM-2Baseline Configurationnot started
CM-3Configuration Change Controlnot started
CM-4Impact Analysesnot started
CM-5Access Restrictions for Changenot started
CM-6Configuration Settingsnot started
CM-7Least Functionalitynot started
CM-8System Component Inventorynot started
CM-9Configuration Management Plannot started
CM-10Software Usage Restrictionsnot started
CM-11User-installed Softwarenot started
CM-12Information Locationnot started
Contingency Planning
CP-1Policy and Proceduresnot started
CP-2Contingency Plannot started
CP-3Contingency Trainingnot started
CP-4Contingency Plan Testingnot started
CP-6Alternate Storage Sitenot started
CP-7Alternate Processing Sitenot started
CP-8Telecommunications Servicesnot started
CP-9System Backupnot started
CP-10System Recovery and Reconstitutionnot started
Identification and Authentication
IA-1Policy and Proceduresnot started
IA-2Identification and Authentication (Organizational Users)not started
IA-3Device Identification and Authenticationnot started
IA-4Identifier Managementnot started
IA-5Authenticator Managementnot started
IA-6Authentication Feedbacknot started
IA-7Cryptographic Module Authenticationnot started
IA-8Identification and Authentication (Non-organizational Users)not started
IA-11Re-authenticationnot started
IA-12Identity Proofingnot started
Incident Response
IR-1Policy and Proceduresnot started
IR-2Incident Response Trainingnot started
IR-3Incident Response Testingnot started
IR-4Incident Handlingnot started
IR-5Incident Monitoringnot started
IR-6Incident Reportingnot started
IR-7Incident Response Assistancenot started
IR-8Incident Response Plannot started
Maintenance
MA-1Policy and Proceduresnot started
MA-2Controlled Maintenancenot started
MA-3Maintenance Toolsnot started
MA-4Nonlocal Maintenancenot started
MA-5Maintenance Personnelnot started
MA-6Timely Maintenancenot started
Media Protection
MP-1Policy and Proceduresnot started
MP-2Media Accessnot started
MP-3Media Markingnot started
MP-4Media Storagenot started
MP-5Media Transportnot started
MP-6Media Sanitizationnot started
MP-7Media Usenot started
Physical and Environmental Protection
PE-1Policy and Proceduresnot started
PE-2Physical Access Authorizationsnot started
PE-3Physical Access Controlnot started
PE-4Access Control for Transmissionnot started
PE-5Access Control for Output Devicesnot started
PE-6Monitoring Physical Accessnot started
PE-8Visitor Access Recordsnot started
PE-9Power Equipment and Cablingnot started
PE-10Emergency Shutoffnot started
PE-11Emergency Powernot started
PE-12Emergency Lightingnot started
PE-13Fire Protectionnot started
PE-14Environmental Controlsnot started
PE-15Water Damage Protectionnot started
PE-16Delivery and Removalnot started
PE-17Alternate Work Sitenot started
PE-18Location of System Componentsnot started
Planning
PL-1Policy and Proceduresnot started
PL-2System Security and Privacy Plansnot started
PL-4Rules of Behaviornot started
PL-8Security and Privacy Architecturesnot started
PL-10Baseline Selectionnot started
PL-11Baseline Tailoringnot started
Personnel Security
PS-1Policy and Proceduresnot started
PS-2Position Risk Designationnot started
PS-3Personnel Screeningnot started
PS-4Personnel Terminationnot started
PS-5Personnel Transfernot started
PS-6Access Agreementsnot started
PS-7External Personnel Securitynot started
PS-8Personnel Sanctionsnot started
PS-9Position Descriptionsnot started
Risk Assessment
RA-1Policy and Proceduresnot started
RA-2Security Categorizationnot started
RA-3Risk Assessmentnot started
RA-5Vulnerability Monitoring and Scanningnot started
RA-7Risk Responsenot started
RA-9Criticality Analysisnot started
System and Services Acquisition
SA-1Policy and Proceduresnot started
SA-2Allocation of Resourcesnot started
SA-3System Development Life Cyclenot started
SA-4Acquisition Processnot started
SA-5System Documentationnot started
SA-8Security and Privacy Engineering Principlesnot started
SA-9External System Servicesnot started
SA-10Developer Configuration Managementnot started
SA-11Developer Testing and Evaluationnot started
SA-15Development Process, Standards, and Toolsnot started
SA-16Developer-Provided Trainingnot started
SA-17Developer Security and Privacy Architecture and Designnot started
SA-21Developer Screeningnot started
SA-22Unsupported System Componentsnot started
System and Communications Protection
SC-1Policy and Proceduresnot started
SC-2Separation of System and User Functionalitynot started
SC-3Security Function Isolationnot started
SC-4Information in Shared System Resourcesnot started
SC-5Denial-of-service Protectionnot started
SC-7Boundary Protectionnot started
SC-8Transmission Confidentiality and Integritynot started
SC-10Network Disconnectnot started
SC-12Cryptographic Key Establishment and Managementnot started
SC-13Cryptographic Protectionnot started
SC-15Collaborative Computing Devices and Applicationsnot started
SC-17Public Key Infrastructure Certificatesnot started
SC-18Mobile Codenot started
SC-20Secure Name/Address Resolution Service (Authoritative Source)not started
SC-21Secure Name/Address Resolution Service (Recursive or Caching Resolver)not started
SC-22Architecture and Provisioning for Name/Address Resolution Servicenot started
SC-23Session Authenticitynot started
SC-24Fail in Known Statenot started
SC-28Protection of Information at Restnot started
SC-39Process Isolationnot started
System and Information Integrity
SI-1Policy and Proceduresnot started
SI-2Flaw Remediationnot started
SI-3Malicious Code Protectionnot started
SI-4System Monitoringnot started
SI-5Security Alerts, Advisories, and Directivesnot started
SI-6Security and Privacy Function Verificationnot started
SI-7Software, Firmware, and Information Integritynot started
SI-8Spam Protectionnot started
SI-10Information Input Validationnot started
SI-11Error Handlingnot started
SI-12Information Management and Retentionnot started
SI-16Memory Protectionnot started
Supply Chain Risk Management
SR-1Policy and Proceduresnot started
SR-2Supply Chain Risk Management Plannot started
SR-3Supply Chain Controls and Processesnot started
SR-5Acquisition Strategies, Tools, and Methodsnot started
SR-6Supplier Assessments and Reviewsnot started
SR-8Notification Agreementsnot started
SR-9Tamper Resistance and Detectionnot started
SR-10Inspection of Systems or Componentsnot started
SR-11Component Authenticitynot started
SR-12Component Disposalnot started

Governance documents

IDDocumentAudit status
no documents