Responsibility matrix
Who carries each NIST SP 800-171 requirement — MacTech as vault operator, you, or both — and, per assessment objective, how that answer was arrived at. Objective-level counts are published only once every one of the 320 is authored.
Authored
2
of 320 objectives
Heuristic
88
wording-derived suggestions
Inherited
230
from the control's answer
MacTech · Shared · You
221 · 41 · 58
per objective, derived
Authored coverage1%
Read-only view. Admin or Compliance can edit objective responsibility.
| Control | Title | Vault axis | Objectives | Azure axis (312) |
|---|---|---|---|---|
| 3.1.1 | Limit system access to authorized users, processes, devices | Sharedvault-platform | 6 · 0 authored | shared(template) |
| 3.1.2 | Limit access to types of transactions and functions | Sharedvault-platform | 2 · 0 authored | shared(template) |
| 3.1.3 | Control the flow of CUI | Sharedvault-platform | 5 · 0 authored | shared(template) |
| 3.1.4 | Separate duties of individuals | Sharedvault-platform | 3 · 0 authored | shared(template) |
| 3.1.5 | Employ least privilege | Sharedvault-platform | 4 · 0 authored | shared(template) |
| 3.1.6 | Use non-privileged accounts for non-privileged activities | Sharedvault-platform | 2 · 0 authored | shared(template) |
| 3.1.7 | Prevent non-privileged users from executing privileged functions | MacTechvault-platform | 4 · 0 authored | shared(template) |
| 3.1.8 | Limit unsuccessful logon attempts | MacTechvault-platform | 2 · 0 authored | shared(template) |
| 3.1.9 | Display privacy and security notices | MacTechvault-platform | 2 · 0 authored | shared(template) |
| 3.1.10 | Use session lock after inactivity period | Sharedvault-platform | 3 · 0 authored | shared(template) |
| 3.1.11 | Terminate sessions after defined conditions | MacTechvault-platform | 2 · 0 authored | shared(template) |
| 3.1.12 | Monitor and control remote access sessions | Sharedvault-platform | 4 · 0 authored | shared(template) |
| 3.1.13 | Use cryptographic mechanisms for remote access | MacTechvault-platform | 2 · 0 authored | shared(template) |
| 3.1.14 | Route remote access via managed access control points | MacTechvault-platform | 2 · 0 authored | shared(template) |
| 3.1.15 | Authorize remote execution of privileged commands via remote access | MacTechvault-platform | 4 · 0 authored | shared(template) |
| 3.1.16 | Authorize wireless access prior to connecting | MacTechazure-per-MAC-SEC-312 | 2 · 0 authored | shared(template) |
| 3.1.17 | Protect wireless access using authentication and encryption | MacTechazure-per-MAC-SEC-312 | 2 · 0 authored | shared(template) |
| 3.1.18 | Control connection of mobile devices | Sharedvault-platform | 3 · 0 authored | shared(template) |
| 3.1.19 | Encrypt CUI on mobile devices and mobile computing platforms | Sharedvault-platform | 2 · 0 authored | shared(template) |
| 3.1.20 | Verify and control all external system connections | Sharedvault-platform | 6 · 0 authored | shared(template) |
| 3.1.21 | Limit use of portable storage devices | Sharedvault-platform | 3 · 0 authored | shared(template) |
| 3.1.22 | Control CUI posted or processed on publicly accessible systems | Sharedvault-platform | 5 · 0 authored | shared(template) |
| 3.2.1 | Ensure personnel are aware of security risks | Sharedvault-platform | 4 · 0 authored | customer_managed(template) |
| 3.2.2 | Train personnel to carry out assigned security responsibilities | Customer | 3 · 0 authored | customer_managed(template) |
| 3.2.3 | Provide security awareness training on recognizing threats | Sharedvault-platform | 2 · 0 authored | customer_managed(template) |
| 3.3.1 | Create and retain system audit logs | MacTechvault-platform | 6 · 0 authored | shared(template) |
| 3.3.2 | Ensure actions of individual users are traceable | Sharedvault-platform | 2 · 0 authored | shared(template) |
| 3.3.3 | Review and update logged events | MacTechvault-platform | 3 · 0 authored | shared(template) |
| 3.3.4 | Alert in the event of an audit logging process failure | MacTechvault-platform | 3 · 0 authored | shared(template) |
| 3.3.5 | Correlate audit record review, analysis, and reporting processes | MacTechvault-platform | 2 · 0 authored | shared(template) |
| 3.3.6 | Provide audit record reduction and report generation | MacTechvault-platform | 2 · 0 authored | shared(template) |
| 3.3.7 | Provide system capability that compares and synchronizes internal clocks | MacTechvault-platform | 3 · 0 authored | shared(template) |
| 3.3.8 | Protect audit information and tools from unauthorized access | MacTechvault-platform | 6 · 0 authored | shared(template) |
| 3.3.9 | Limit management of audit logging to subset of privileged users | MacTechvault-platform | 2 · 0 authored | shared(template) |
| 3.4.1 | Establish and maintain baseline configurations | MacTechvault-platform | 6 · 0 authored | shared(template) |
| 3.4.2 | Establish and enforce security configuration settings | MacTechvault-platform | 2 · 0 authored | shared(template) |
| 3.4.3 | Track, review, approve, and log changes to systems | MacTechvault-platform | 4 · 0 authored | shared(template) |
| 3.4.4 | Analyze security impact of changes before implementation | MacTechvault-platform | 1 · 0 authored | shared(template) |
| 3.4.5 | Define and document access restrictions for changes | MacTechvault-platform | 8 · 0 authored | shared(template) |
| 3.4.6 | Employ principle of least functionality | MacTechvault-platform | 2 · 0 authored | shared(template) |
| 3.4.7 | Restrict, disable, or prevent the use of nonessential programs | MacTechvault-platform | 15 · 0 authored | shared(template) |
| 3.4.8 | Apply deny-by-exception policy for unauthorized software | MacTechvault-platform | 3 · 0 authored | shared(template) |
| 3.4.9 | Control and monitor user-installed software | MacTechvault-platform | 3 · 0 authored | shared(template) |
| 3.5.1 | Identify system users, processes, and devices | Sharedvault-platform | 3 · 0 authored | shared(template) |
| 3.5.2 | Authenticate the identities of those users, processes, or devices | Sharedvault-platform | 3 · 0 authored | shared(template) |
| 3.5.3 | Use multifactor authentication for local and network access to privileged accounts | Sharedvault-platform | 4 · 0 authored | shared(template) |
| 3.5.4 | Employ replay-resistant authentication mechanisms | MacTechvault-platform | 1 · 0 authored | shared(template) |
| 3.5.5 | Employ identifier management practices to prevent reuse | MacTechvault-platform | 2 · 0 authored | shared(template) |
| 3.5.6 | Disable identifiers after defined inactivity period | Sharedvault-platform | 2 · 0 authored | shared(template) |
| 3.5.7 | Enforce minimum password complexity and change requirements | MacTechvault-platform | 4 · 0 authored | shared(template) |
| 3.5.8 | Prohibit password reuse for a specified number of generations | MacTechvault-platform | 2 · 0 authored | shared(template) |
| 3.5.9 | Allow temporary password use with immediate change requirement | MacTechvault-platform | 1 · 0 authored | shared(template) |
| 3.5.10 | Store and transmit only cryptographically-protected passwords | MacTechvault-platform | 2 · 0 authored | shared(template) |
| 3.5.11 | Obscure feedback of authentication information | MacTechvault-platform | 1 · 0 authored | shared(template) |
| 3.6.1 | Establish operational incident-handling capability | Sharedvault-platform | 7 · 0 authored | shared(template) |
| 3.6.2 | Track, document, and report incidents | Sharedazure-per-MAC-SEC-312 | 6 · 0 authored | shared(template) |
| 3.6.3 | Test the organizational incident response capability | Sharedvault-platform | 1 · 0 authored | shared(template) |
| 3.7.1 | Perform maintenance on organizational systems | MacTechazure-per-MAC-SEC-312 | 1 · 0 authored | shared(template) |
| 3.7.2 | Provide controls on the tools, techniques, mechanisms, and personnel for maintenance | MacTechazure-per-MAC-SEC-312 | 4 · 0 authored | shared(template) |
| 3.7.3 | Ensure equipment removed for off-site maintenance is sanitized | Sharedazure-per-MAC-SEC-312 | 1 · 0 authored | shared(template) |
| 3.7.4 | Check media containing diagnostic programs for malicious code | MacTechazure-per-MAC-SEC-312 | 1 · 0 authored | shared(template) |
| 3.7.5 | Require MFA to establish remote maintenance sessions | MacTechvault-platform | 2 · 0 authored | shared(template) |
| 3.7.6 | Supervise maintenance activities of personnel without required access authorization | Sharedazure-per-MAC-SEC-312 | 1 · 0 authored | shared(template) |
| 3.8.1 | Protect system media containing CUI, both paper and digital | Sharedazure-per-MAC-SEC-312 | 4 · 0 authored | shared(template) |
| 3.8.2 | Limit access to CUI on system media to authorized users | Sharedvault-platform | 1 · 0 authored | shared(template) |
| 3.8.3 | Sanitize or destroy system media before disposal or reuse | Sharedazure-per-MAC-SEC-312 | 2 · 0 authored | shared(template) |
| 3.8.4 | Mark media with necessary CUI markings and distribution limitations | Customer | 2 · 0 authored | shared(template) |
| 3.8.5 | Control access to media containing CUI during transport | MacTechazure-per-MAC-SEC-312 | 2 · 0 authored | shared(template) |
| 3.8.6 | Implement cryptographic mechanisms to protect CUI during transport | MacTechvault-platform | 1 · 0 authored | shared(template) |
| 3.8.7 | Control the use of removable media on system components | MacTechvault-platform | 1 · 0 authored | shared(template) |
| 3.8.8 | Prohibit the use of portable storage without identifiable owner | Sharedvault-platform | 1 · 0 authored | shared(template) |
| 3.8.9 | Protect the backup copies of CUI | Sharedazure-per-MAC-SEC-312 | 1 · 0 authored | shared(template) |
| 3.9.1 | Screen individuals prior to authorizing access to organizational systems containing CUI | Sharedvault-platform | 1 · 0 authored | customer_managed(template) |
| 3.9.2 | Ensure CUI is protected during and after personnel actions (termination/transfer) | Sharedvault-platform | 3 · 0 authored | customer_managed(template) |
| 3.10.1 | Limit physical access to authorized individuals | Sharedazure-per-MAC-SEC-312 | 4 · 2 authored | azure_inherited(template) |
| 3.10.2 | Protect and monitor the physical facility and support infrastructure | Sharedazure-per-MAC-SEC-312 | 4 · 0 authored | azure_inherited(template) |
| 3.10.3 | Escort visitors and monitor visitor activity | Sharedazure-per-MAC-SEC-312 | 2 · 0 authored | azure_inherited(template) |
| 3.10.4 | Maintain audit logs of physical access | Sharedazure-per-MAC-SEC-312 | 1 · 0 authored | azure_inherited(template) |
| 3.10.5 | Control and manage physical access devices | Sharedazure-per-MAC-SEC-312 | 3 · 0 authored | azure_inherited(template) |
| 3.10.6 | Enforce safeguarding measures for CUI at alternate work sites | Sharedvault-platform | 2 · 0 authored | azure_inherited(template) |
| 3.11.1 | Periodically assess risk to organizational operations and assets | Sharedvault-platform | 2 · 0 authored | shared(template) |
| 3.11.2 | Scan for vulnerabilities in organizational systems and applications | MacTechvault-platform | 5 · 0 authored | shared(template) |
| 3.11.3 | Remediate vulnerabilities in accordance with assessments of risk | MacTechvault-platform | 2 · 0 authored | shared(template) |
| 3.12.1 | Periodically assess the security controls in organizational systems | Sharedvault-platform | 2 · 0 authored | shared(template) |
| 3.12.2 | Develop and implement plans of action to correct deficiencies | Sharedvault-platform | 3 · 0 authored | shared(template) |
| 3.12.3 | Monitor security controls on an ongoing basis | Sharedvault-platform | 1 · 0 authored | shared(template) |
| 3.12.4 | Develop, document, and periodically update system security plans | Sharedvault-platform | 8 · 0 authored | shared(template) |
| 3.13.1 | Monitor, control, and protect communications at external boundaries | MacTechazure-per-MAC-SEC-312 | 8 · 0 authored | shared(template) |
| 3.13.2 | Employ architectural designs to separate CUI from non-CUI | MacTechvault-platform | 6 · 0 authored | shared(template) |
| 3.13.3 | Separate user functionality from system management functionality | MacTechvault-platform | 3 · 0 authored | shared(template) |
| 3.13.4 | Prevent unauthorized and unintended information transfer | MacTechazure-per-MAC-SEC-312 | 1 · 0 authored | shared(template) |
| 3.13.5 | Implement subnetworks for publicly accessible system components | MacTechvault-platform | 2 · 0 authored | shared(template) |
| 3.13.6 | Deny network communications traffic by default | MacTechvault-platform | 2 · 0 authored | shared(template) |
| 3.13.7 | Prevent remote devices from simultaneously connecting to the system and other resources | MacTechvault-platform | 1 · 0 authored | shared(template) |
| 3.13.8 | Implement cryptographic mechanisms to prevent unauthorized disclosure of CUI in transit | MacTechvault-platform | 3 · 0 authored | shared(template) |
| 3.13.9 | Terminate network connections after defined period of inactivity | MacTechvault-platform | 3 · 0 authored | shared(template) |
| 3.13.10 | Establish and manage cryptographic keys | MacTechazure-per-MAC-SEC-312 | 2 · 0 authored | shared(template) |
| 3.13.11 | Employ FIPS-validated cryptography | MacTechazure-per-MAC-SEC-312 | 1 · 0 authored | shared(template) |
| 3.13.12 | Prohibit remote activation of collaborative computing devices | MacTechvault-platform | 3 · 0 authored | shared(template) |
| 3.13.13 | Control and monitor the use of mobile code | MacTechvault-platform | 2 · 0 authored | shared(template) |
| 3.13.14 | Control and monitor the use of VoIP | MacTechvault-platform | 2 · 0 authored | shared(template) |
| 3.13.15 | Protect the authenticity of communications sessions | MacTechvault-platform | 1 · 0 authored | shared(template) |
| 3.13.16 | Protect CUI at rest | MacTechazure-per-MAC-SEC-312 | 1 · 0 authored | shared(template) |
| 3.14.1 | Identify, report, and correct system flaws in a timely manner | MacTechvault-platform | 6 · 0 authored | shared(template) |
| 3.14.2 | Provide protection from malicious code at appropriate locations | MacTechvault-platform | 2 · 0 authored | shared(template) |
| 3.14.3 | Monitor system security alerts and advisories | MacTechvault-platform | 3 · 0 authored | shared(template) |
| 3.14.4 | Update malicious code protection mechanisms | MacTechvault-platform | 1 · 0 authored | shared(template) |
| 3.14.5 | Perform periodic scans and real-time scans of files from external sources | MacTechvault-platform | 3 · 0 authored | shared(template) |
| 3.14.6 | Monitor systems to detect attacks and indicators of potential attacks | MacTechvault-platform | 3 · 0 authored | shared(template) |
| 3.14.7 | Identify unauthorized use of organizational systems | Sharedvault-platform | 2 · 0 authored | shared(template) |