NIST - defines security controls for federal systems. Many private organizations adopt them too.
Control families for networking:
- AC: Access control and authorization
- AU: Audit and accountability
- CM: Configuration management
- IA: Identification and authentication
- SC: System and communications protection
- SI: System and information integrity
Control baselines (Low, Moderate, High) match controls to system sensitivity. Higher impact systems require more controls.