Skip to main content
Framework · ARC-AMPE

DE-Entity Mandatory Baseline

Volume II — SSPP DE-Entity Mandatory Baseline (v1.0) · NIST SP 800-53 Rev 5 tailoring (CMS ARC-AMPE) · supersedes MARS-E ·  compliance date 2026-03-04

The parsed catalog, as ingested from the CMS workbook. Evidence state against these controls is a tenant fact and is shown inside the workspace, not here.

Module page & standingVersion history & changes41 added · 26 removed · 76 renumbered or retitled since MARS-E 2.2
BASELINE2550ba9a · 2025-04-10
308
Mandatory controls
175
Base controls
133
Enhancements
20
Families
Source
ARC-AMPE_Vol2_SSPP-DE-Entity_v1.0-508_07072025.xlsx, sheet “DEE Mandatory Baseline
ACAccess Control46 controls
AC-01Policy and ProceduresBase
AC-02Account ManagementBase
AC-02(01)Automated System Account ManagementEnh · AC-02
AC-02(02)Automated Temporary and Emergency Account ManagementEnh · AC-02
AC-02(03)Disable AccountsEnh · AC-02
AC-02(04)Automated Audit ActionsEnh · AC-02
AC-02(05)Inactivity LogoutEnh · AC-02
AC-02(07)Privileged User AccountsEnh · AC-02
AC-02(12)Account Monitoring for Atypical UsageEnh · AC-02
AC-02(13)Disable Accounts for High-Risk IndividualsEnh · AC-02
AC-03Access EnforcementBase
AC-03(14)Individual AccessEnh · AC-03
AC-04Information Flow EnforcementBase
AC-05Separation of DutiesBase
AC-06Least PrivilegeBase
AC-06(01)Authorize Access to Security FunctionsEnh · AC-06
AC-06(02)Non-privileged Access for Nonsecurity FunctionsEnh · AC-06
AC-06(05)Privileged AccountsEnh · AC-06
AC-06(07)Review of User PrivilegesEnh · AC-06
AC-06(09)Log Use of Privileged FunctionsEnh · AC-06
AC-06(10)Prohibit Non-privileged Users from Executing Privileged FunctionsEnh · AC-06
AC-07Unsuccessful Logon AttemptsBase
AC-08System Use NotificationBase
AC-10Concurrent Session ControlBase
AC-11Device LockBase
AC-12Session TerminationBase
AC-12(01)User-Initiated LogoutsEnh · AC-12
AC-12(02)Termination MessageEnh · AC-12
AC-12(03)Timeout Warning MessageEnh · AC-12
AC-14Permitted Actions Without Identification or AuthenticationBase
AC-17Remote AccessBase
AC-17(01)Monitoring and ControlEnh · AC-17
AC-17(02)Protection of Confidentiality and Integrity Using EncryptionEnh · AC-17
AC-17(03)Managed Access Control PointsEnh · AC-17
AC-17(04)Privileged Commands and AccessEnh · AC-17
AC-17(09)Disconnect or Disable AccessEnh · AC-17
AC-18Wireless AccessBase
AC-18(01)Authentication and EncryptionEnh · AC-18
AC-18(03)Disable Wireless NetworkingEnh · AC-18
AC-19Access Control for Mobile DevicesBase
AC-19(05)Full Device and Container-based EncryptionEnh · AC-19
AC-20Use of External SystemsBase
AC-20(01)Limits on Authorized UseEnh · AC-20
AC-20(02)Portable Storage Devices — Restricted UseEnh · AC-20
AC-21Information SharingBase
AC-22Publicly Accessible ContentBase
ATAwareness and Training9 controls
AT-01Policy and ProceduresBase
AT-02Literacy Training and AwarenessBase
AT-02(02)Insider ThreatEnh · AT-02
AT-02(03)Social Engineering and MiningEnh · AT-02
AT-02(04)Suspicious Communications and Anomalous System BehaviorEnh · AT-02
AT-02(05)Advanced Persistent ThreatEnh · AT-02
AT-03Role-Based TrainingBase
AT-03(05)Processing Personally Identifiable InformationEnh · AT-03
AT-04Training RecordsBase
AUAudit and Accountability18 controls
AU-01Policy and ProceduresBase
AU-02Event LoggingBase
AU-03Content of Audit RecordsBase
AU-03(01)Additional Audit InformationEnh · AU-03
AU-03(03)Limit Personally Identifiable Information ElementsEnh · AU-03
AU-04Audit Log Storage CapacityBase
AU-05Response to Audit Logging Processing FailuresBase
AU-06Audit Record Review, Analysis, and ReportingBase
AU-06(01)Automated Process IntegrationEnh · AU-06
AU-06(03)Correlate Audit Record RepositoriesEnh · AU-06
AU-07Audit Record Reduction and Report GenerationBase
AU-07(01)Automatic ProcessingEnh · AU-07
AU-08Time StampsBase
AU-09Protection of Audit InformationBase
AU-09(04)Access by Subset of Privileged UsersEnh · AU-09
AU-10Non-RepudiationBase
AU-11Audit Record RetentionBase
AU-12Audit Record GenerationBase
CAAssessment, Authorization, and Monitoring12 controls
CA-01Policies and ProceduresBase
CA-02Control AssessmentsBase
CA-02(01)Independent AssessorsEnh · CA-02
CA-03Information ExchangeBase
CA-05Plan of Action and MilestonesBase
CA-06AuthorizationBase
CA-07Continuous MonitoringBase
CA-07(01)Independent AssessmentEnh · CA-07
CA-07(04)Risk MonitoringEnh · CA-07
CA-08Penetration TestingBase
CA-08(01)Independent Penetration Testing Agent or TeamEnh · CA-08
CA-09Internal System ConnectionsBase
CMConfiguration Management25 controls
CM-01Policy and ProceduresBase
CM-02Baseline ConfigurationBase
CM-02(03)Retention of Previous ConfigurationsEnh · CM-02
CM-03Configuration Change ControlBase
CM-03(02)Testing, Validation, and Documentation of ChangesEnh · CM-03
CM-04Impact AnalysesBase
CM-04(01)Separate Test EnvironmentsEnh · CM-04
CM-04(02)Verification of ControlsEnh · CM-04
CM-05Access Restrictions for ChangeBase
CM-05(01)Automated Access Enforcement and Audit RecordsEnh · CM-05
CM-05(05)Privilege Limitation for Production and OperationEnh · CM-05
CM-06Configuration SettingsBase
CM-06(01)Automated Management, Application, and VerificationEnh · CM-06
CM-07Least FunctionalityBase
CM-07(01)Periodic ReviewEnh · CM-07
CM-07(02)Prevent Program ExecutionEnh · CM-07
CM-07(05)Authorized Software - Allow by ExceptionEnh · CM-07
CM-08System Component InventoryBase
CM-08(01)Updates During Installation and RemovalEnh · CM-08
CM-08(03)Automated Unauthorized Component DetectionEnh · CM-08
CM-09Configuration Management PlanBase
CM-10Software Usage RestrictionsBase
CM-11User-Installed SoftwareBase
CM-12Information LocationBase
CM-13Data Action MappingBase
CPContingency Planning16 controls
CP-01Policy and ProceduresBase
CP-02Contingency PlanBase
CP-02(01)Coordinate with Related PlansEnh · CP-02
CP-02(03)Resume Missions and Business FunctionsEnh · CP-02
CP-02(08)Identify Critical AssetsEnh · CP-02
CP-03Contingency TrainingBase
CP-04Contingency Plan TestingBase
CP-04(01)Coordinate with Related PlansEnh · CP-04
CP-06Alternate Storage SiteBase
CP-06(01)Separation from Primary SiteEnh · CP-06
CP-06(03)AccessibilityEnh · CP-06
CP-09System BackupBase
CP-09(01)Testing for Reliability and IntegrityEnh · CP-09
CP-09(08)Cryptographic ProtectionEnh · CP-09
CP-10System Recovery and ReconstitutionBase
CP-10(02)Transaction RecoveryEnh · CP-10
IAIdentification and Authentication21 controls
IA-01Policy and ProceduresBase
IA-02Identification and Authentication (Organizational Users)Base
IA-02(01)Multifactor Access to Privileged AccountsEnh · IA-02
IA-02(02)Multifactor Access to Non-Privileged AccountsEnh · IA-02
IA-02(06)Access to Accounts - Separate DeviceEnh · IA-02
IA-02(08)Access to Accounts - Replay ResistantEnh · IA-02
IA-03Device Identification and AuthenticationBase
IA-04Identifier ManagementBase
IA-04(04)Identify User StatusEnh · IA-04
IA-05Authenticator ManagementBase
IA-05(01)Password-Based AuthenticationEnh · IA-05
IA-05(06)Protection of AuthenticatorsEnh · IA-05
IA-05(07)Authenticator Management | No Embedded Unencrypted Static AuthenticatorsEnh · IA-05
IA-06Authenticator FeedbackBase
IA-07Cryptographic Module AuthenticationBase
IA-08Identification and Authentication (Non-Organizational Users)Base
IA-08(02)Identification and Authentication (Non-Organizational Users) |Acceptance of External Party CredentialsEnh · IA-08
IA-11Re-AuthenticationBase
IA-12Identity ProofingBase
IA-12(01)Supervisor AuthorizationEnh · IA-12
IA-12(03)Identity Evidence Validation and VerificationEnh · IA-12
IRIncident Response15 controls
IR-01Policy and ProceduresBase
IR-02Incident Response TrainingBase
IR-02(03)BreachEnh · IR-02
IR-03Incident Response TestingBase
IR-03(02)Coordination with Related PlansEnh · IR-03
IR-04Incident HandlingBase
IR-04(03)Continuity of OperationsEnh · IR-04
IR-04(06)Insider Threats – Specific CapabilitiesEnh · IR-04
IR-05Incident MonitoringBase
IR-06Incident ReportingBase
IR-06(01)Automated ReportingEnh · IR-06
IR-07Incident Response AssistanceBase
IR-07(01)Automation Support for Availability of Information and SupportEnh · IR-07
IR-08Incident Response PlanBase
IR-08(01)BreachesEnh · IR-08
MAMaintenance12 controls
MA-01Policy and ProceduresBase
MA-02Controlled MaintenanceBase
MA-03Maintenance ToolsBase
MA-03(01)Inspect ToolsEnh · MA-03
MA-03(02)Inspect MediaEnh · MA-03
MA-03(03)Prevent Unauthorized RemovalEnh · MA-03
MA-03(05)Execution with PrivilegeEnh · MA-03
MA-03(06)Software Updates and PatchesEnh · MA-03
MA-04Nonlocal MaintenanceBase
MA-04(01)Logging and ReviewEnh · MA-04
MA-05Maintenance PersonnelBase
MA-06Timely MaintenanceBase
MPMedia Protection8 controls
MP-01Policy and ProceduresBase
MP-02Media AccessBase
MP-03Media MarkingBase
MP-04Media StorageBase
MP-05Media TransportBase
MP-06Media SanitizationBase
MP-06(01)Review, Approve, Track, Document, and VerifyEnh · MP-06
MP-07Media UseBase
PEPhysical and Environmental Protection9 controls
PE-01Policy and ProceduresBase
PE-02Physical Access AuthorizationsBase
PE-03Physical Access ControlBase
PE-04Access Control for TransmissionBase
PE-05Access Control for Output DevicesBase
PE-06Monitoring Physical AccessBase
PE-06(01)Intrusion Alarms and Surveillance EquipmentEnh · PE-06
PE-08Visitor Access RecordsBase
PE-16Delivery and RemovalBase
PLPlanning6 controls
PL-01Policy and ProceduresBase
PL-02System Security and Privacy PlanBase
PL-04Rules of BehaviorBase
PL-04(01)Social Media and External Site / Application Usage RestrictionsEnh · PL-04
PL-08Security and Privacy ArchitecturesBase
PL-11Baseline TailoringBase
PMProgram Management5 controls
PM-04Plan of Action and Milestones ProcessBase
PM-05System InventoryBase
PM-05(01)Inventory of Personally Identifiable InformationEnh · PM-05
PM-21Accounting of DisclosuresBase
PM-25Minimization of PII Used in Testing, Training, and ResearchBase
PSPersonnel Security8 controls
PS-01Policy and ProceduresBase
PS-02Position Risk DesignationBase
PS-03Personnel ScreeningBase
PS-04Personnel TerminationBase
PS-05Personnel TransferBase
PS-06Access AgreementsBase
PS-07External Personnel SecurityBase
PS-08Personnel SanctionsBase
PTPersonally Identifiable Information Processing and Transparency10 controls
PT-01Policy and ProceduresBase
PT-02Authority to Process Personally Identifiable InformationBase
PT-03Personally Identifiable Information Processing PurposesBase
PT-04ConsentBase
PT-04(03)RevocationEnh · PT-04
PT-05Privacy NoticeBase
PT-05(01)Just-in-time NoticeEnh · PT-05
PT-05(02)Privacy Act StatementsEnh · PT-05
PT-07Specific Categories of Personally Identifiable InformationBase
PT-07(01)Social Security NumbersEnh · PT-07
RARisk Assessment8 controls
RA-01Policy and ProceduresBase
RA-02Security CategorizationBase
RA-03Risk AssessmentBase
RA-05Vulnerability Monitoring and ScanningBase
RA-05(02)Update Vulnerabilities to be ScannedEnh · RA-05
RA-05(05)Privileged AccessEnh · RA-05
RA-07Risk ResponseBase
RA-08Privacy Impact AssessmentsBase
SASystem and Services Acquisition18 controls
SA-01Policy and ProceduresBase
SA-02Allocation of ResourcesBase
SA-03System Development Life CycleBase
SA-04Acquisition ProcessBase
SA-04(01)Functional Properties of ControlsEnh · SA-04
SA-04(02)Design and Implementation Information for Security ControlsEnh · SA-04
SA-04(09)Functions, Ports, Protocols, and Services in UseEnh · SA-04
SA-05System DocumentationBase
SA-08Security and Privacy Engineering PrinciplesBase
SA-09External System ServicesBase
SA-09(05)Processing, Storage, and Service LocationEnh · SA-09
SA-09(08)Processing and Storage Location - U.S. JurisdictionEnh · SA-09
SA-10Developer Configuration ManagementBase
SA-11Developer Testing and EvaluationBase
SA-15Development Process, Standards, and ToolsBase
SA-15(12)Minimize Personally Identifiable InformationEnh · SA-15
SA-17Developer Security Architecture and DesignBase
SA-22Unsupported System ComponentsBase
SCSystem and Communications Protection28 controls
SC-01Policy and ProceduresBase
SC-02Separation of System and User FunctionalityBase
SC-04Information in Shared System ResourcesBase
SC-05Denial-of-Service ProtectionBase
SC-07Boundary ProtectionBase
SC-07(03)Access PointsEnh · SC-07
SC-07(04)External Telecommunications ServicesEnh · SC-07
SC-07(05)Deny By Default — Allow By ExceptionEnh · SC-07
SC-07(07)Split Tunneling for Remote DevicesEnh · SC-07
SC-07(08)Route Traffic to Authenticated Proxy ServersEnh · SC-07
SC-07(12)Host-Based ProtectionEnh · SC-07
SC-07(18)Fail SecureEnh · SC-07
SC-07(24)Boundary Protection | Personally Identifiable InformationEnh · SC-07
SC-07(29)Boundary Protection | Separate Subnets to Isolate FunctionsEnh · SC-07
SC-08Transmission Confidentiality and IntegrityBase
SC-08(01)Cryptographic ProtectionEnh · SC-08
SC-08(02)Pre- and Post-Transmission HandlingEnh · SC-08
SC-10Network DisconnectBase
SC-12Cryptographic Key Establishment and ManagementBase
SC-13Cryptographic ProtectionBase
SC-17Public Key Infrastructure CertificatesBase
SC-18Mobile CodeBase
SC-20Secure Name/Address Resolution Service (Authoritative Source)Base
SC-21Secure Name/Address Resolution Service (Recursive or Caching Resolver)Base
SC-22Architecture and Provisioning for Name/Address Resolution ServiceBase
SC-23Session AuthenticityBase
SC-28Protection of Information At RestBase
SC-28(01)Cryptographic ProtectionEnh · SC-28
SISystem and Information Integrity30 controls
SI-01Policy and ProceduresBase
SI-02Flaw RemediationBase
SI-02(02)Automated Flaw Remediation StatusEnh · SI-02
SI-02(06)Removal of Previous Versions of Software and FirmwareEnh · SI-02
SI-03Malicious Code ProtectionBase
SI-04System MonitoringBase
SI-04(01)System-Wide Intrusion Detection SystemEnh · SI-04
SI-04(04)Inbound and Outbound Communications TrafficEnh · SI-04
SI-04(05)System-Generated AlertsEnh · SI-04
SI-04(23)Host-Based DevicesEnh · SI-04
SI-05Security Alerts, Advisories, and DirectivesBase
SI-06Security and Privacy Function VerificationBase
SI-07Software, Firmware, and Information IntegrityBase
SI-07(01)Integrity ChecksEnh · SI-07
SI-07(07)Integration of Detection and ResponseEnh · SI-07
SI-08Spam ProtectionBase
SI-08(02)Automatic UpdatesEnh · SI-08
SI-10Information Input ValidationBase
SI-11Error HandlingBase
SI-12Information Management and RetentionBase
SI-12(01)Limit Personally Identifiable Information ElementsEnh · SI-12
SI-12(02)Minimize Personally Identifiable Information in Testing, Training, and ResearchEnh · SI-12
SI-12(03)Information DisposalEnh · SI-12
SI-16Memory ProtectionBase
SI-18Personally Identifiable Information Quality OperationsBase
SI-18(04)Individual RequestsEnh · SI-18
SI-18(05)Notice of Collection or DeletionEnh · SI-18
SI-19De-IdentificationBase
SI-19(03)ReleaseEnh · SI-19
SI-19(04)Removal, Masking, Encryption, Hashing, or Replacement of Direct IdentifiersEnh · SI-19
SRSupply Chain Risk Management4 controls
SR-01Policy and ProceduresBase
SR-02Supply Chain Risk Management PlanBase
SR-02(01)Establish SCRM TeamEnh · SR-02
SR-03Supply Chain Controls and ProcessesBase
ARC-AMPE — DE-Entity Mandatory Baseline | ControlFrame