Back to catalog
END-03.2ENDEndpoint Security
Governing Access Restriction for Change
Description
Mechanisms exist to define, document, approve and enforce access restrictions associated with changes to Technology Assets, Applications and/or Services (TAAS).
Cross-Mappings
30 paths across 4 frameworks
Cross-Mappings
NIST 800-531 mapping
CM-5
0.50
- Secure Controls Framework · 2026.2 · scf_strm · related
NIST 800-1711 mapping
3.4.5
0.50
- Secure Controls Framework · 2026.2 · scf_strm · related
- NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
CCI10 mappings
CCI-000338
0.50
- Secure Controls Framework · 2026.2 · scf_strm · related
- DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-000339
0.50
- Secure Controls Framework · 2026.2 · scf_strm · related
- DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-000340
0.50
- Secure Controls Framework · 2026.2 · scf_strm · related
- DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-000341
0.50
- Secure Controls Framework · 2026.2 · scf_strm · related
- DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-000342
0.50
- Secure Controls Framework · 2026.2 · scf_strm · related
- DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-000343
0.50
- Secure Controls Framework · 2026.2 · scf_strm · related
- DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-000344
0.50
- Secure Controls Framework · 2026.2 · scf_strm · related
- DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-000345
0.50
- Secure Controls Framework · 2026.2 · scf_strm · related
- DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-003935
0.50
- Secure Controls Framework · 2026.2 · scf_strm · related
- DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-003936
0.50
- Secure Controls Framework · 2026.2 · scf_strm · related
- DISA · 2025-01-23 · disa_cci_list · equivalent
STIG14 mappings
SV-202131r961863_ruleThe network device must enforce access restrictions associated with changes to the system components.
0.50
- Secure Controls Framework · 2026.2 · scf_strm · related
- DISA · 2025-01-23 · disa_cci_list · equivalent
- DISA · V5R3 · disa_xccdf · related
SV-217480r961863_ruleThe HP FlexFabric Switch must enforce access restrictions associated with changes to the system components.
0.50
- Secure Controls Framework · 2026.2 · scf_strm · related
- DISA · 2025-01-23 · disa_cci_list · equivalent
- DISA · V1R4 · disa_xccdf · related
SV-222626r961863_ruleThe designer must ensure the application does not store configuration and control files in the same directory as user data.
0.50
- Secure Controls Framework · 2026.2 · scf_strm · related
- DISA · 2025-01-23 · disa_cci_list · equivalent
- DISA · 6 · disa_xccdf · related
SV-230951r961863_ruleForescout must enforce access restrictions associated with changes to the firmware, OS, USB port, and console port.
0.50
- Secure Controls Framework · 2026.2 · scf_strm · related
- DISA · 2025-01-23 · disa_cci_list · equivalent
- DISA · V2R3 · disa_xccdf · related
SV-234191r879887_ruleThe FortiGate device must enforce access restrictions associated with changes to the system components.
0.50
- Secure Controls Framework · 2026.2 · scf_strm · related
- DISA · 2025-01-23 · disa_cci_list · equivalent
- DISA · 1 · disa_xccdf · related
SV-234191r961863_ruleThe FortiGate device must enforce access restrictions associated with changes to the system components.
0.50
- Secure Controls Framework · 2026.2 · scf_strm · related
- DISA · 2025-01-23 · disa_cci_list · equivalent
- DISA · V1R5 · disa_xccdf · related
SV-242632r961863_ruleThe Cisco ISE must enforce access restrictions associated with changes to the firmware, OS, and hardware components.
0.50
- Secure Controls Framework · 2026.2 · scf_strm · related
- DISA · 2025-01-23 · disa_cci_list · equivalent
- DISA · 2 · disa_xccdf · related
SV-243151r879887_ruleThe network device must be configured with both an ingress and egress ACL.
0.50
- Secure Controls Framework · 2026.2 · scf_strm · related
- DISA · 2025-01-23 · disa_cci_list · equivalent
- DISA · V7R2 · disa_xccdf · related
SV-243169r879887_ruleThe network device must be configured with both an ingress and egress ACL.
0.50
- Secure Controls Framework · 2026.2 · scf_strm · related
- DISA · 2025-01-23 · disa_cci_list · equivalent
- DISA · V7R2 · disa_xccdf · related
SV-243187r879887_ruleThe network device must be configured with both an ingress and egress ACL.
0.50
- Secure Controls Framework · 2026.2 · scf_strm · related
- DISA · 2025-01-23 · disa_cci_list · equivalent
- DISA · V7R2 · disa_xccdf · related
+4 more (top 10 by confidence shown)
Control mappings provided by the Secure Controls Framework (SCF).
SCF
Powered by the Secure Controls Framework
The control catalog, cross-mappings, and STRM relationship data shown here are provided by the Secure Controls Framework (SCF), 2026.2. Every mapping is credited to SCF as the methodology, with the SCF reference and version stored alongside it.
© SCF Council, LLC. Secure Controls Framework content is free and shown here with attribution. securecontrolsframework.com · About SCF on STIGViewer