Risk Management Strategy (GV.RM)
- GV.RM-01
 - GV.RM-02
 - GV.RM-03
 - GV.RM-04
 - GV.RM-05
 - GV.RM-06
 - GV.RM-07
 
Oversight (GV.OV)
Asset Management (ID.AM)
- ID.AM-01
 - ID.AM-02
 - ID.AM-03
 - ID.AM-04
 - ID.AM-05
 - ID.AM-07
 - ID.AM-08
 
Risk Assessment (ID.RA)
- ID.RA-01
 - ID.RA-02
 - ID.RA-03
 - ID.RA-04
 - ID.RA-05
 - ID.RA-06
 - ID.RA-07
 - ID.RA-08
 - ID.RA-09
 
Identity Management, Authentication, and Access Control (PR.AA)
- PR.AA-01
 - PR.AA-02
 - PR.AA-03
 - PR.AA-04
 - PR.AA-05
 
Awareness and Training (PR.AT)
Data Security (PR.DS)
- PR.DS-01
 - PR.DS-02
 - PR.DS-09
 - PR.DS-10
 - PR.DS-11
 
Platform Security (PR.PS)
- PR.PS-01
 - PR.PS-02
 - PR.PS-03
 - PR.PS-04
 - PR.PS-05
 - PR.PS-06
 
Technology Infrastructure Resilience (PR.IR)
Continuous Monitoring (DE.CM)
- DE.CM-01
 - DE.CM-02
 - DE.CM-03
 - DE.CM-06
 - DE.CM-09
 
Adverse Event Analysis (DE.AE)
- DE.AE-02
 - DE.AE-03
 - DE.AE-04
 - DE.AE-06
 - DE.AE-07
 - DE.AE-08
 
Incident Management (RS.MA)
- RS.MA-01
 - RS.MA-02
 - RS.MA-03
 - RS.MA-04
 - RS.MA-05
 
Incident Analysis (RS.AN)
- RS.AN-03
 - RS.AN-06
 - RS.AN-07
 - RS.AN-08
 
Incident Response Reporting and Communication (RS.CO)
Incident Mitigation (RS.MI)
Incident Recovery Plan Execution (RC.RP)