| 3.1 Access Control | 03.01 Access Control | Six requirements consolidated into broader parents (remote access, wireless, mobile, external systems). |
|---|
| 3.2 Awareness and Training | 03.02 Awareness and Training | Insider-threat awareness folded into literacy training. |
|---|
| 3.3 Audit and Accountability | 03.03 Audit and Accountability | Restructured: event logging, record content, and generation become explicit requirements. |
|---|
| 3.4 Configuration Management | 03.04 Configuration Management | Component inventory, information location, and high-risk-travel configuration become standalone requirements. |
|---|
| 3.5 Identification and Authentication | 03.05 Identification and Authentication | Password requirements consolidated and modernized; authenticator management added. |
|---|
| 3.6 Incident Response | 03.06 Incident Response | Incident response training and a written plan become standalone requirements. |
|---|
| 3.7 Maintenance | 03.07 Maintenance | Reduced to tools, nonlocal sessions, and personnel; routine perform-maintenance expectations recategorized. |
|---|
| 3.8 Media Protection | 03.08 Media Protection | Transport encryption folds into transport; ownerless-media rule folds into media use. |
|---|
| 3.9 Personnel Security | 03.09 Personnel Security | Carried forward with organization-defined parameters. |
|---|
| 3.10 Physical Protection | 03.10 Physical Protection | Visitor, logging, and access-device rules consolidated; transmission-line access added. |
|---|
| 3.11 Risk Assessment | 03.11 Risk Assessment | Remediation folds into monitoring and scanning; risk response added. |
|---|
| 3.12 Security Assessment | 03.12 Security Assessment and Monitoring | Renamed; the system security plan moves to the new Planning family; information exchange added. |
|---|
| 3.13 System and Communications Protection | 03.13 System and Communications Protection | Transmission and at-rest confidentiality merge; several technology-specific requirements retire into boundary protection. |
|---|
| 3.14 System and Information Integrity | 03.14 System and Information Integrity | Malicious-code updates and scanning fold into one requirement; monitoring absorbs unauthorized-use identification; information retention added. |
|---|
| — | 03.15 Planning | New family: policies and procedures, the system security plan, rules of behavior. |
|---|
| — | 03.16 System and Services Acquisition | New family: security engineering, unsupported components, external system services. |
|---|
| — | 03.17 Supply Chain Risk Management | New family: SCRM plan, acquisition strategies, supply chain requirements and processes. |
|---|