{"data":{"id":"SP-002","slug":"server-module","joomla_id":188,"title":"Server Module","description":"Reusable security module defining the standard control baseline for server systems including physical, virtual, and cloud-hosted instances. Referenced as a building block by other OSA patterns wherever a server component appears in the architecture.","url":"https://www.opensecurityarchitecture.org/patterns/sp-002","metadata":{"release":"26.02","classification":"Infrastructure","status":"published","type":"module","datePublished":"2008-01-11","dateModified":"2026-02-06","authors":["Aurelius","Vitruvius"],"reviewers":[]},"diagram":{"svg":"/images/patterns/08_02_10_Pattern_002_Server_Module.svg","png":"/images/OSA_images/patterns/08_02_10_Pattern_002_Server_Module.png"},"content":{"description":"The Server Module is the companion to the Client Module (SP-001) and represents the other fundamental building block in the OSA pattern library. It encapsulates the security controls that should be applied to any server system -- whether physical hardware in a data centre, a virtual machine on a hypervisor, or a cloud-hosted instance. Other OSA patterns reference this module wherever a server component appears, ensuring a consistent and comprehensive security baseline across web servers, application servers, database servers, and infrastructure services.\n\nServers are high-value targets because they concentrate data, processing capability, and administrative access. A compromised server typically grants an attacker access to multiple users' data, lateral movement pathways into the broader network, and persistence mechanisms that survive endpoint remediation. The controls in this module address server-specific risks across access control, audit and accountability, configuration management, physical and environmental protection, system integrity, incident response, and cryptographic services.\n\nWith 90 controls spanning 15 NIST 800-53 control families, the Server Module is the most control-dense module in the OSA library. Compared to the Client Module, it adds the entire Physical and Environmental Protection (PE) family -- 12 controls covering physical access, power, cooling, fire suppression, and environmental monitoring. This reflects the reality that servers, unlike mobile endpoints, typically reside in controlled physical environments where environmental controls are as important as logical ones. The module also includes AU-06 (Audit Monitoring, Analysis, and Reporting), SC-02 (Application Partitioning), SC-10 (Network Disconnect), and SI-10 (Information Accuracy, Completeness, Validity, and Authenticity) -- controls that are more relevant to multi-user, always-on server systems than to client endpoints.\n\nAs a module rather than a standalone pattern, the Server Module is designed for composition. It defines what controls apply to the server itself, but does not prescribe network architecture, perimeter defences, or client-side protections. Patterns like SP-008 (Public Web Server), SP-011 (Cloud Computing), SP-023 (Industrial Control Systems), and SP-026 (PCI Full Environment) reference this module to inherit its baseline, then add pattern-specific controls for their particular deployment context. This modular approach means that when the Server Module is strengthened, every referencing pattern inherits the improvement.\n\nPractitioners should focus on three foundational pillars when implementing this module: hardened baseline configuration (CM-02, CM-06, CM-07) to minimise the attack surface; comprehensive audit logging and monitoring (AU-02, AU-03, AU-06, SI-04) to detect and investigate compromise; and physical and environmental protection (PE-02 through PE-16) to ensure that the physical infrastructure supporting the server is resilient against environmental and physical access threats.","keyControlAreas":["Access Control and Privilege Management (AC-03, AC-05, AC-06, AC-07, AC-10): Server access control is fundamentally about restricting who can do what on a system that serves many users and processes. AC-03 enforces access decisions based on security policy, typically through OS-level permissions, application-level authorisation, and database access controls. AC-05 enforces separation of duties so that no single administrator can provision accounts, modify configurations, and suppress audit logs. AC-06 implements least privilege for both human administrators and service accounts -- the principle that a web server process should not run as root, a monitoring agent should not have write access to application data, and a database administrator should not have OS-level root. AC-07 defends against brute-force attacks on server authentication interfaces, which are frequently targeted by automated scanners. AC-10 limits concurrent sessions to prevent session-based resource exhaustion and detect credential sharing.","Audit Logging, Monitoring, and Analysis (AU-02, AU-03, AU-06, AU-08, AU-09, AU-11): Servers generate the richest and most security-relevant audit data in any architecture. AU-02 defines the events that must be logged: authentication attempts, privilege use, file and database access, configuration changes, process execution, and network connections. AU-03 specifies record content including timestamp, user identity, event type, resource accessed, and outcome. AU-06 is critical for servers -- it requires active monitoring, analysis, and reporting of audit logs rather than passive collection. This means SIEM integration, correlation rules, anomaly detection, and alerting on suspicious patterns such as unusual administrative access times, mass data access, or privilege escalation sequences. AU-08 ensures NTP-synchronised timestamps for cross-system correlation. AU-09 protects logs from tampering, and AU-11 defines retention aligned with compliance requirements. Servers should forward logs in near-real-time to a separate, protected log management infrastructure.","Configuration Management and Server Hardening (CM-02, CM-06, CM-07, CM-08): Server hardening is the single most impactful security investment for this module. CM-02 establishes a hardened baseline configuration -- built from CIS Benchmarks, vendor security guides, or organisational standards -- that every server is deployed from. Configuration-as-code approaches (Ansible, Puppet, Chef, Terraform) make baselines repeatable, auditable, and drift-detectable. CM-06 enforces specific settings: disabled unnecessary services, restricted network listeners, hardened kernel parameters, secure default file permissions, and removal of default credentials. CM-07 applies least functionality aggressively: a web server should not have a compiler installed, a database server should not run an FTP daemon, and no server should expose management interfaces to untrusted networks. CM-08 maintains inventory of all server components including OS version, installed software, firmware versions, and network interfaces, which is essential for vulnerability management at scale.","Physical and Environmental Protection (PE-02, PE-03, PE-05, PE-06, PE-09 through PE-16): This control area distinguishes the Server Module from the Client Module. Servers typically reside in data centres, server rooms, or colocation facilities where physical security is paramount. PE-02 and PE-03 control who can physically access server infrastructure through access authorisation lists, badge systems, biometric controls, and mantrap entries. PE-05 prevents unauthorised viewing of server console displays. PE-06 provides physical access monitoring through CCTV, access logs, and alarm systems. The environmental controls (PE-09 through PE-16) protect against power failures (redundant feeds, UPS, generators), fire (detection, suppression with clean agents), water damage (raised floors, leak detection), temperature and humidity excursions (precision cooling, monitoring, alerting), and controlled equipment delivery and removal (PE-16) to prevent unauthorised hardware installation or theft. For cloud-hosted servers, these controls are inherited from the cloud provider but should be validated through SOC 2 reports or equivalent attestations.","Vulnerability Management and Patch Lifecycle (RA-05, SI-02, SI-05, SI-07): Server vulnerability management requires a disciplined, risk-prioritised approach. RA-05 mandates regular vulnerability scanning -- both authenticated scans that inspect installed packages and configurations, and network-level scans that identify exposed services and known vulnerabilities. SI-02 requires timely flaw remediation with patching SLAs calibrated to severity and exposure: internet-facing servers demand faster patching cycles than internal infrastructure. SI-05 ensures that vendor advisories, CVE notifications, and CERT alerts are monitored and triaged. SI-07 verifies software and firmware integrity, detecting unauthorised modifications that could indicate rootkit installation, backdoor deployment, or supply chain compromise. Server patching is more complex than endpoint patching due to availability requirements -- change windows, rolling updates, blue-green deployments, and rollback procedures must be planned. Organisations should maintain a patching cadence of 72 hours for critical vulnerabilities on internet-facing servers and 14 days for internal systems.","Cryptographic Services and Secure Communications (SC-12, SC-13, SC-02, SC-10): Servers handle sensitive data at scale, requiring robust cryptographic infrastructure. SC-12 covers key management for TLS certificates, database encryption keys, API authentication tokens, and inter-service communication secrets. Automated certificate lifecycle management (ACME/Let's Encrypt, HashiCorp Vault, enterprise PKI) is essential to prevent certificate expiry outages and to enable short-lived certificates. SC-13 mandates approved algorithms: TLS 1.2+ with strong cipher suites, AES-256 for data at rest, and deprecation of legacy protocols (SSLv3, TLS 1.0/1.1, RC4, 3DES). SC-02 requires application partitioning -- separating user-facing functionality from administrative interfaces and security functions so that compromise of one component does not expose the others. SC-10 enforces network disconnect after defined inactivity periods, preventing stale connections from becoming attack vectors.","Incident Response and Recovery (IR-04, IR-05, IR-06, CP-09, CP-10): Server incident response must support rapid detection, containment, forensic preservation, and recovery. IR-04 defines server-specific incident handling: isolating compromised servers without disrupting dependent services, preserving volatile memory and disk state for forensics, and coordinating with network security to block attacker C2 channels. IR-05 provides continuous monitoring through host-based IDS, file integrity monitoring, and SIEM correlation. IR-06 defines escalation and reporting procedures for server compromises, which typically have higher impact than endpoint incidents. CP-09 covers server backup with attention to backup integrity verification, encryption of backup media, and air-gapped or immutable backup copies to resist ransomware. CP-10 addresses recovery and reconstitution -- the ability to rebuild a compromised server from known-good baselines and restore data from verified backups within defined recovery time objectives."],"assumptions":"The organisation operates a managed server infrastructure with centralised configuration management, patch deployment, and monitoring capabilities. Servers are deployed in environments with appropriate physical and environmental controls (data centres, server rooms, or cloud providers with equivalent attestations). Administrative access to servers is controlled through privileged access management, with individual accountability for all administrative actions. Network segmentation exists to separate server tiers (web, application, database) and restrict lateral movement. The organisation has defined service level objectives for availability that inform patching windows and recovery time targets. For cloud-hosted servers, the shared responsibility model is understood and documented.","typicalChallenges":"Server sprawl and configuration drift are persistent challenges: as the server estate grows through organic provisioning, maintaining consistent baselines becomes increasingly difficult without configuration-as-code and automated compliance scanning. Legacy servers running end-of-life operating systems or applications resist hardening and patching, creating risk pockets that compensating controls must address. Patching production servers requires careful change management to balance security urgency with availability requirements -- downtime windows are shrinking while patch volumes increase. Privileged access management is complex when multiple teams (infrastructure, application, database, security) require different levels of administrative access to the same server. Audit log volumes from servers can be enormous, and without proper tuning, critical security events are buried in noise. Physical and environmental controls in colocation or shared facilities may not meet organisational standards, requiring contractual enforcement and audit verification. Virtualisation and containerisation introduce new attack surfaces (hypervisor escape, container breakout) that traditional server controls may not fully address.","indications":"This module should be referenced by any OSA pattern that includes a server component in its architecture. It applies to physical servers, virtual machines, cloud instances (IaaS), and any system that provides services to other components rather than directly to end users. It is the standard server baseline for patterns including web server deployments, application platforms, database tiers, directory services, file servers, mail servers, and infrastructure services such as DNS, NTP, and DHCP.","contraIndications":"This module is not designed for client endpoints (see SP-001 Client Module), mobile devices, or network infrastructure devices (routers, switches, firewalls) which have distinct management models and control requirements. Container orchestration platforms (Kubernetes) and serverless/function-as-a-service deployments require adapted control sets where many traditional server controls are abstracted by the platform. Embedded systems and IoT devices with constrained operating environments cannot implement the full server control baseline. For PaaS and SaaS deployments where the server layer is fully managed by the provider, the physical and environmental controls and many OS-level controls are inherited rather than directly implemented.","threatResistance":"The Server Module addresses the full range of server-targeted threats. Remote exploitation of unpatched vulnerabilities is mitigated by RA-05 scanning, SI-02 patching, and CM-07 attack surface reduction. Privilege escalation and lateral movement are constrained by AC-06 least privilege, AC-05 separation of duties, and SC-02 application partitioning. Unauthorised administrative access is prevented by AC-03 access enforcement, AC-07 brute-force protection, and IA-02 strong authentication. Data exfiltration is detected by AU-06 log analysis, SI-04 monitoring, and IR-05 incident monitoring. Physical compromise and hardware theft are addressed by PE-02/PE-03 physical access controls and SC-12/SC-13 encryption of data at rest. Environmental threats (power failure, fire, flood, overheating) are mitigated by PE-09 through PE-15. Ransomware and destructive attacks are countered by CP-09 backup with integrity verification and CP-10 recovery procedures. Configuration drift and unauthorised changes are detected by CM-03/CM-04 change control and CA-07 continuous monitoring. Supply chain and integrity attacks are identified by SI-07 software integrity verification."},"examples":{"Server hardening and configuration":["CIS Benchmarks for Windows Server, Red Hat Enterprise Linux, Ubuntu Server, and other server OS platforms","DISA STIGs for server operating systems and common server applications (Apache, IIS, SQL Server, Oracle)","Ansible Lockdown and DevSec Hardening Framework for automated server baseline enforcement","HashiCorp Packer and Terraform for building and deploying hardened server images as code"],"Server monitoring and protection":["CrowdStrike Falcon for server EDR with workload protection across physical, virtual, and cloud","OSSEC/Wazuh for host-based intrusion detection, file integrity monitoring, and log analysis","Qualys Cloud Agent for continuous server vulnerability assessment and compliance monitoring","Datadog Infrastructure Monitoring for server performance, availability, and security event correlation"],"Physical and environmental controls":["Schneider Electric EcoStruxure for data centre environmental monitoring (power, cooling, humidity)","HID Global access control systems for server room badge and biometric authentication","Equinix IBX and similar colocation facilities providing SOC 2 attested physical security","AWS/Azure/GCP data centre physical security inherited through shared responsibility model"],"Backup and recovery":["Veeam Backup and Replication for server-level backup with immutable repository support","Commvault for enterprise server backup with ransomware detection and air-gapped copies","AWS Backup or Azure Backup for cloud-native server snapshot and recovery","Zerto or VMware Site Recovery for server disaster recovery and automated failover"],"Developing Areas":["Serverless and container security models are fundamentally challenging the traditional server hardening paradigm. When workloads run as ephemeral containers with sub-second lifetimes or as serverless functions with no visible OS, the entire CM family of controls (baseline configuration, hardening, least functionality) must be reimagined. Container-specific security tools (Aqua, Sysdig, Falco) and serverless security frameworks are emerging but the control mapping to NIST 800-53 is still being formalised by the community.","Confidential computing technologies -- Intel TDX, AMD SEV-SNP, and ARM CCA -- are moving from research prototypes toward production readiness, promising to protect data in use by encrypting memory at the hardware level. This addresses the long-standing gap where data is vulnerable during processing even when encrypted at rest and in transit. However, performance overhead of 5-15%, limited toolchain support, and the complexity of remote attestation workflows mean that adoption is concentrated in cloud provider managed offerings rather than general enterprise deployment.","Hardware root of trust and measured boot adoption is accelerating but remains inconsistent across server fleets. Technologies like Intel Boot Guard, AMD Platform Secure Boot, and TPM-based measured boot can provide cryptographic assurance that server firmware and OS have not been tampered with, directly addressing supply chain threats. The challenge is operationalising attestation at scale: collecting, validating, and acting on measurements from thousands of heterogeneous servers requires tooling that most organisations have not yet deployed.","Immutable infrastructure -- where servers are never patched in place but replaced entirely with freshly built, pre-hardened images -- is becoming the preferred model for cloud-native deployments, eliminating configuration drift by design. However, the transition from mutable to immutable infrastructure requires mature CI/CD pipelines, comprehensive image scanning, and rapid rebuild capabilities that many organisations lack. Hybrid estates where some workloads are immutable and others are traditionally patched create operational complexity and inconsistent security posture."]},"references":[{"title":"NIST SP 800-123: Guide to General Server Security","url":"https://csrc.nist.gov/publications/detail/sp/800-123/final","note":"The primary NIST guidance on server security covering OS hardening, patch management, access control, logging, and network configuration. Essential baseline reference for this module."},{"title":"CIS Benchmarks for Server Operating Systems","url":"https://www.cisecurity.org/cis-benchmarks","note":"Industry-standard hardening guides for Windows Server, RHEL, Ubuntu, SUSE, and other server platforms. Provides specific configuration settings mapped to security controls with audit procedures."},{"title":"NIST SP 800-128: Guide for Security-Focused Configuration Management of Information Systems","url":"https://csrc.nist.gov/publications/detail/sp/800-128/final","note":"Detailed guidance on implementing configuration management controls (CM family) for information systems including servers. Covers baseline development, change control, and monitoring."},{"title":"NIST SP 800-53A: Assessing Security and Privacy Controls","url":"https://csrc.nist.gov/publications/detail/sp/800-53a/rev-5/final","note":"Assessment procedures for all NIST 800-53 controls. Essential for validating that server module controls are implemented correctly and operating effectively."},{"title":"MITRE ATT&CK - Linux and Windows Server Techniques","url":"https://attack.mitre.org/matrices/enterprise/","note":"Comprehensive catalogue of adversary techniques targeting server operating systems. Maps to specific server attack patterns that the module's controls must resist."},{"title":"NIST SP 800-82 Rev 3: Guide to OT Security","url":"https://csrc.nist.gov/pubs/sp/800/82/r3/final","note":"Relevant for server modules deployed in industrial and operational technology environments where availability and safety requirements constrain traditional IT security controls."},{"title":"Uptime Institute Tier Standards for Data Centres","url":"https://uptimeinstitute.com/tiers","note":"Defines the physical infrastructure tiers (I-IV) for data centre resilience. Directly relevant to the PE family controls covering power, cooling, and environmental protection for server infrastructure."}],"relatedPatterns":["SP-001","SP-008","SP-011","SP-013","SP-016","SP-018","SP-023","SP-025","SP-026"],"relatedPatternNames":["Client Module","Public Web Server Pattern","Cloud Computing Pattern","Data Security Pattern","DMZ Module","Information Security Management System (ISMS) Module","Industrial Control Systems","Advanced Monitoring and Detection","PCI Full Environment"],"threats":[{"id":"T-SM-001","name":"Remote Exploitation of Unpatched Server Vulnerabilities","mitigatedBy":["RA-05","SI-02","SI-05","CM-07"]},{"id":"T-SM-002","name":"Privilege Escalation and Lateral Movement","mitigatedBy":["AC-06","AC-05","AC-03","SC-02"]},{"id":"T-SM-003","name":"Unauthorised Administrative Access","mitigatedBy":["AC-07","IA-02","AC-10","AU-06"]},{"id":"T-SM-004","name":"Data Exfiltration from Server-Hosted Repositories","mitigatedBy":["AU-02","AU-06","SI-04","IR-05","SC-13"]},{"id":"T-SM-005","name":"Ransomware and Destructive Malware Attack","mitigatedBy":["SI-03","CP-09","CP-10","SI-07","CM-07"]},{"id":"T-SM-006","name":"Physical Compromise and Hardware Theft","mitigatedBy":["PE-02","PE-03","PE-06","SC-12","SC-13"]},{"id":"T-SM-007","name":"Environmental Failure (Power, Cooling, Fire, Water)","mitigatedBy":["PE-09","PE-10","PE-11","PE-13","PE-14","PE-15"]},{"id":"T-SM-008","name":"Configuration Drift and Unauthorised System Changes","mitigatedBy":["CM-02","CM-03","CM-04","CM-06","CA-07"]},{"id":"T-SM-009","name":"Supply Chain Compromise and Software Integrity Tampering","mitigatedBy":["SI-07","SA-04","SA-08","SI-06"]},{"id":"T-SM-010","name":"Audit Log Evasion and Forensic Evidence Destruction","mitigatedBy":["AU-09","AU-05","AU-11","AU-10"]}],"controls":[{"id":"AC-03","name":"Access Enforcement","family":"AC","emphasis":"critical"},{"id":"AC-05","name":"Separation of Duties","family":"AC","emphasis":"important"},{"id":"AC-06","name":"Least Privilege","family":"AC","emphasis":"critical"},{"id":"AC-07","name":"Unsuccessful Logon Attempts","family":"AC","emphasis":"important"},{"id":"AC-08","name":"System Use Notification","family":"AC","emphasis":"standard"},{"id":"AC-09","name":"Previous Logon Notification","family":"AC","emphasis":"standard"},{"id":"AC-10","name":"Concurrent Session Control","family":"AC","emphasis":"standard"},{"id":"AC-12","name":"Session Termination","family":"AC","emphasis":"important"},{"id":"AT-03","name":"Role-based Training","family":"AT","emphasis":"standard"},{"id":"AT-04","name":"Training Records","family":"AT","emphasis":"standard"},{"id":"AU-02","name":"Event Logging","family":"AU","emphasis":"critical"},{"id":"AU-03","name":"Content of Audit Records","family":"AU","emphasis":"important"},{"id":"AU-04","name":"Audit Log Storage Capacity","family":"AU","emphasis":"standard"},{"id":"AU-05","name":"Response to Audit Logging Process Failures","family":"AU","emphasis":"important"},{"id":"AU-06","name":"Audit Record Review, Analysis, and Reporting","family":"AU","emphasis":"critical"},{"id":"AU-08","name":"Time Stamps","family":"AU","emphasis":"important"},{"id":"AU-09","name":"Protection of Audit Information","family":"AU","emphasis":"important"},{"id":"AU-10","name":"Non-repudiation","family":"AU","emphasis":"standard"},{"id":"AU-11","name":"Audit Record Retention","family":"AU","emphasis":"standard"},{"id":"CA-02","name":"Control Assessments","family":"CA","emphasis":"standard"},{"id":"CA-04","name":"Security Certification","family":"CA","emphasis":"standard"},{"id":"CA-06","name":"Authorization","family":"CA","emphasis":"standard"},{"id":"CA-07","name":"Continuous Monitoring","family":"CA","emphasis":"important"},{"id":"CM-02","name":"Baseline Configuration","family":"CM","emphasis":"critical"},{"id":"CM-03","name":"Configuration Change Control","family":"CM","emphasis":"important"},{"id":"CM-04","name":"Impact Analyses","family":"CM","emphasis":"important"},{"id":"CM-05","name":"Access Restrictions for Change","family":"CM","emphasis":"important"},{"id":"CM-06","name":"Configuration Settings","family":"CM","emphasis":"important"},{"id":"CM-07","name":"Least Functionality","family":"CM","emphasis":"important"},{"id":"CM-08","name":"System Component Inventory","family":"CM","emphasis":"important"},{"id":"CP-03","name":"Contingency Training","family":"CP","emphasis":"standard"},{"id":"CP-04","name":"Contingency Plan Testing","family":"CP","emphasis":"standard"},{"id":"CP-05","name":"Contingency Plan Update","family":"CP","emphasis":"standard"},{"id":"CP-09","name":"System Backup","family":"CP","emphasis":"important"},{"id":"CP-10","name":"System Recovery and Reconstitution","family":"CP","emphasis":"important"},{"id":"IA-02","name":"Identification and Authentication (Organizational Users)","family":"IA","emphasis":"important"},{"id":"IA-06","name":"Authentication Feedback","family":"IA","emphasis":"standard"},{"id":"IA-07","name":"Cryptographic Module Authentication","family":"IA","emphasis":"standard"},{"id":"IR-02","name":"Incident Response Training","family":"IR","emphasis":"standard"},{"id":"IR-03","name":"Incident Response Testing","family":"IR","emphasis":"standard"},{"id":"IR-04","name":"Incident Handling","family":"IR","emphasis":"important"},{"id":"IR-05","name":"Incident Monitoring","family":"IR","emphasis":"important"},{"id":"IR-06","name":"Incident Reporting","family":"IR","emphasis":"standard"},{"id":"IR-07","name":"Incident Response Assistance","family":"IR","emphasis":"standard"},{"id":"MA-02","name":"Controlled Maintenance","family":"MA","emphasis":"standard"},{"id":"MA-03","name":"Maintenance Tools","family":"MA","emphasis":"standard"},{"id":"MA-04","name":"Nonlocal Maintenance","family":"MA","emphasis":"important"},{"id":"MA-05","name":"Maintenance Personnel","family":"MA","emphasis":"standard"},{"id":"MA-06","name":"Timely Maintenance","family":"MA","emphasis":"standard"},{"id":"MP-02","name":"Media Access","family":"MP","emphasis":"standard"},{"id":"PE-02","name":"Physical Access Authorizations","family":"PE","emphasis":"important"},{"id":"PE-03","name":"Physical Access Control","family":"PE","emphasis":"important"},{"id":"PE-05","name":"Access Control for Output Devices","family":"PE","emphasis":"standard"},{"id":"PE-06","name":"Monitoring Physical Access","family":"PE","emphasis":"important"},{"id":"PE-09","name":"Power Equipment and Cabling","family":"PE","emphasis":"standard"},{"id":"PE-10","name":"Emergency Shutoff","family":"PE","emphasis":"standard"},{"id":"PE-11","name":"Emergency Power","family":"PE","emphasis":"important"},{"id":"PE-12","name":"Emergency Lighting","family":"PE","emphasis":"standard"},{"id":"PE-13","name":"Fire Protection","family":"PE","emphasis":"important"},{"id":"PE-14","name":"Environmental Controls","family":"PE","emphasis":"important"},{"id":"PE-15","name":"Water Damage Protection","family":"PE","emphasis":"standard"},{"id":"PE-16","name":"Delivery and Removal","family":"PE","emphasis":"standard"},{"id":"RA-02","name":"Security Categorization","family":"RA","emphasis":"standard"},{"id":"RA-03","name":"Risk Assessment","family":"RA","emphasis":"important"},{"id":"RA-04","name":"Risk Assessment Update","family":"RA","emphasis":"standard"},{"id":"RA-05","name":"Vulnerability Monitoring and Scanning","family":"RA","emphasis":"important"},{"id":"SA-02","name":"Allocation of Resources","family":"SA","emphasis":"standard"},{"id":"SA-03","name":"System Development Life Cycle","family":"SA","emphasis":"standard"},{"id":"SA-04","name":"Acquisition Process","family":"SA","emphasis":"standard"},{"id":"SA-05","name":"System Documentation","family":"SA","emphasis":"standard"},{"id":"SA-06","name":"Software Usage Restrictions","family":"SA","emphasis":"important"},{"id":"SA-08","name":"Security and Privacy Engineering Principles","family":"SA","emphasis":"standard"},{"id":"SC-02","name":"Separation of System and User Functionality","family":"SC","emphasis":"important"},{"id":"SC-03","name":"Security Function Isolation","family":"SC","emphasis":"standard"},{"id":"SC-04","name":"Information in Shared System Resources","family":"SC","emphasis":"standard"},{"id":"SC-05","name":"Denial-of-service Protection","family":"SC","emphasis":"important"},{"id":"SC-06","name":"Resource Availability","family":"SC","emphasis":"standard"},{"id":"SC-10","name":"Network Disconnect","family":"SC","emphasis":"standard"},{"id":"SC-12","name":"Cryptographic Key Establishment and Management","family":"SC","emphasis":"important"},{"id":"SC-13","name":"Cryptographic Protection","family":"SC","emphasis":"important"},{"id":"SC-14","name":"Public Access Protections","family":"SC","emphasis":"standard"},{"id":"SC-18","name":"Mobile Code","family":"SC","emphasis":"standard"},{"id":"SI-02","name":"Flaw Remediation","family":"SI","emphasis":"important"},{"id":"SI-03","name":"Malicious Code Protection","family":"SI","emphasis":"important"},{"id":"SI-04","name":"System Monitoring","family":"SI","emphasis":"important"},{"id":"SI-05","name":"Security Alerts, Advisories, and Directives","family":"SI","emphasis":"standard"},{"id":"SI-06","name":"Security and Privacy Function Verification","family":"SI","emphasis":"standard"},{"id":"SI-07","name":"Software, Firmware, and Information Integrity","family":"SI","emphasis":"important"},{"id":"SI-10","name":"Information Input Validation","family":"SI","emphasis":"standard"},{"id":"SI-11","name":"Error Handling","family":"SI","emphasis":"standard"}],"controlFamilySummary":{"AC":8,"AT":2,"AU":9,"CA":4,"CM":7,"CP":5,"IA":3,"IR":6,"MA":5,"MP":1,"PE":12,"RA":4,"SA":6,"SC":10,"SI":8}}}