The fourteen families
The 110 requirements are grouped into fourteen families. A family is a reading unit, not a scoring unit: SPRS points attach to individual requirements, and a family with many one-point requirements can matter less to your score than a family with three five-point ones.
-
AC Access Control
Access control is the largest family and the one most assessments start with. It asks who and what may use your systems, what each of them may do once inside, how CUI is allowed to move, and how remote, wireless and mobile access are kept on a leash. Four of its requirements are also Level 1 practices, and seven carry the full five points.
22 requirements 7 × 5 pt 2 × 3 pt 13 × 1 pt 4 at Level 1
-
AT Awareness and Training
Three requirements about people rather than machines: everyone knows the risks, the people with security duties are trained for them, and staff can recognise an insider threat. Small family, but two of the three are five-point requirements, and an assessor will ask to see the records.
3 requirements 2 × 5 pt 1 × 1 pt
-
AU Audit and Accountability
Audit and accountability is about keeping logs that are good enough to reconstruct what happened, tying actions to named users, protecting the logs from tampering, and actually reviewing them. It is where many small contractors discover that the logs they have are not the logs they need.
9 requirements 2 × 5 pt 1 × 3 pt 6 × 1 pt
-
CM Configuration Management
Configuration management asks you to know what you run, keep it in a known state, change it deliberately, and strip out what is not needed. Baselines, inventories, change control and software restrictions live here. Six of its nine requirements carry five points.
9 requirements 6 × 5 pt 3 × 1 pt
-
IA Identification and Authentication
Identification and authentication is the family that contains multi-factor authentication. It covers unique identities for users and devices, how authenticators are issued and protected, password rules, and replay resistance. Two of its requirements are Level 1 practices.
11 requirements 4 × 5 pt 7 × 1 pt 2 at Level 1
-
IR Incident Response
Incident response asks for a capability, not a document: you can detect, contain, recover and report, you test that capability, and you track incidents through to closure. DFARS 252.204-7012 adds its own 72-hour reporting duty on top.
3 requirements 2 × 5 pt 1 × 1 pt
-
MA Maintenance
Maintenance covers how systems and equipment are repaired: who does it, with what tools, what leaves the building and what comes back, and how remote maintenance sessions are controlled. It is easy to overlook and easy to evidence once you have a process.
6 requirements 2 × 5 pt 2 × 3 pt 2 × 1 pt
-
MP Media Protection
Media protection is about the physical and digital media that carry CUI: how they are protected, marked, controlled in transit, sanitised or destroyed, and how removable media and backups are handled. Marking and sanitisation are the requirements assessors probe first.
9 requirements 2 × 5 pt 3 × 3 pt 4 × 1 pt 1 at Level 1
-
PS Personnel Security
Personnel security has two requirements: screen people before they get access, and remove that access when they leave or move. Both are simple to state and often weakly evidenced.
2 requirements 1 × 5 pt 1 × 3 pt
-
PE Physical Protection
Physical protection asks who can walk up to the systems that hold CUI, how visitors are escorted and logged, how physical access devices are controlled, and how alternate work sites are safeguarded. Four of its six requirements are Level 1 practices.
6 requirements 2 × 5 pt 4 × 1 pt 4 at Level 1
-
RA Risk Assessment
Risk assessment asks you to look for the risks and the vulnerabilities on a schedule, and to fix what the scans find. It is three requirements, one of them worth five points, and it is where scanning cadence and remediation records are examined.
3 requirements 1 × 5 pt 1 × 3 pt 1 × 1 pt
-
CA Security Assessment
Security assessment holds the system security plan and the plan of action, the two documents every other family reports into, plus periodic self-assessment and continuous monitoring. The plan itself is not scored, because without it an assessment cannot proceed at all.
4 requirements 2 × 5 pt 1 × 3 pt
-
SC System and Communications Protection
System and communications protection is the second largest family and the home of encryption, network boundaries, session protection and FIPS-validated cryptography. It has more five-point requirements than any family except access control, and 3.13.11 carries one of the two partial-credit rules.
16 requirements 6 × 5 pt 1 × 3 pt 9 × 1 pt 2 at Level 1
-
SI System and Information Integrity
System and information integrity covers patching, malware protection, monitoring for attacks and acting on advisories. Four of its seven requirements are Level 1 practices, and five of the seven carry the full five points, so it moves the score more than its size suggests.
7 requirements 5 × 5 pt 2 × 3 pt 4 at Level 1