Keyboard shortcuts

Press or to navigate between chapters

Press S or / to search in the book

Press ? to show this help

Press Esc to hide this help

Control ID Formats

Correct ID formatting is critical. The Pretorin API returns errors on malformed IDs. When unsure, discover IDs first with pretorin frameworks families <id> or pretorin frameworks controls <id>.

NIST 800-53 Rev 5 / FedRAMP

Framework IDs: nist-800-53-r5, fedramp-low, fedramp-moderate, fedramp-high

Family IDs

Family IDs are lowercase slugs, not short codes:

CorrectIncorrect
access-controlac
audit-and-accountabilityau
identification-and-authenticationia
system-and-communications-protectionsc
configuration-managementcm
incident-responseir
risk-assessmentra

Control IDs

Control IDs are zero-padded with a hyphen:

CorrectIncorrect
ac-01ac-1, AC-1, ac1
ac-02ac-2, AC-2, ac2
au-02au-2, AU-2
sc-07sc-7, SC-7

Enhancement IDs append a dot-suffix or parenthetical suffix. Both spellings are accepted on input, but the platform’s canonical form zero-pads the enhancement number too:

FormatExample inputCanonical ID returned
Dot notationac-02.1ac-02.01
Parentheticalac-02(1)ac-02.01
Already canonicalac-02.01ac-02.01

Compare returned IDs against the canonical form — pretorin frameworks control nist-800-53-r5 sc-07.1 succeeds, but the record it returns is sc-07.01, so an equality check against sc-07.1 will not match.

CMMC 2.0

Framework IDs: cmmc-l1, cmmc-l2, cmmc-l3

Family IDs

Level 2 and Level 3 family IDs carry a level suffix; Level 1 family IDs do not:

FrameworkCorrectIncorrect
cmmc-l1access-controlaccess-control-level-1, ac
cmmc-l1media-protectionmedia-protection-level-1, mp
cmmc-l2access-control-level-2access-control, ac-l2
cmmc-l2incident-response-level-2incident-response, ir
cmmc-l3system-and-communications-protection-level-3sc, sc-l3
cmmc-l3access-control-level-3-enhancedaccess-control-level-3

A wrong family slug is not an error — pretorin frameworks controls returns “No controls found for this selection”, so confirm the slug with pretorin frameworks families <framework_id> first.

Control IDs

CMMC control IDs use dotted notation with a level prefix and are case-sensitive:

CorrectIncorrect
AC.L2-3.1.1ac-01, 3.1.1
AC.L1-3.1.22ac.l1-3.1.22
SC.L3-3.13.4eSC.L3-3.13.4, sc-07, 3.13.4

Use uppercase for the family prefix (e.g., AC, not ac).

Every one of the 24 Level 3 control IDs ends in a lowercase e (for “enhanced”), mirroring the NIST SP 800-172 enhanced-requirement numbering. AC.L3-3.1.2e is a valid ID; AC.L3-3.1.2 is not. Dropping the suffix is the most common Level 3 ID error.

NIST 800-171 Rev 3

Framework ID: nist-800-171-r3

Family IDs

Family IDs use the same lowercase slug convention as NIST 800-53:

CorrectIncorrect
access-controlac, 3.1
incident-responseir, 3.6
identification-and-authenticationia, 3.5

Control IDs

Control IDs use dotted notation with leading zeros:

CorrectIncorrect
03.01.013.1.1, ac-01
03.01.023.1.2, ac-02
03.13.013.13.1, sc-01

SOC 2

Framework ID: soc2

Pretorin’s SOC 2 catalog is an expert-reviewed control register organized by trust-services domain, not by the raw Common Criteria codes.

Family IDs

SOC 2 family IDs are lowercase domain slugs (one per trust-services domain plus an AI-controls domain):

CorrectIncorrect
securityCC6, common-criteria, cc
availabilityA1, avail
confidentialityC1, conf
privacyP1
processing-integrityPI1, processing_integrity
ai-controlsAI, ai

Control IDs

SOC 2 control IDs use a prefixed, zero-padded format — PTR-SOC2-<DOMAIN>-NNN, where the domain code is uppercase and the number is three digits:

CorrectIncorrect
PTR-SOC2-SEC-001CC6.1, sec-1, 6.1
PTR-SOC2-AVL-004A1.4, avl-4
PTR-SOC2-AI-016AI.16, ai-16

Domain codes: SEC (security), AVL (availability), CONF (confidentiality), PRIV (privacy), PI (processing-integrity), AI (ai-controls). SOC 2 IDs are case-sensitive — keep the prefix and domain code uppercase. When unsure, discover the exact IDs with pretorin frameworks controls soc2 --family security.

800-53-Derived Baselines

Framework IDs: dod-cloud-il2, dod-cloud-il4, dod-cloud-il5, dod-onprem, nss-ic, ot-ics, iot-federal

These baselines are tailorings of the NIST 800-53 catalog and reuse its conventions exactly — lowercase family slugs (access-control, system-and-communications-protection) and zero-padded control IDs (ac-01, sc-07), enhancements included. Everything in the NIST 800-53 Rev 5 / FedRAMP section above applies unchanged, including auto-normalization.

They are subsets: a valid 800-53 ID is not necessarily present in the baseline. Confirm with pretorin frameworks controls <framework_id> --family <family_slug>.

Other Catalogs

The remaining catalogs each use their own convention. None of them match the auto-normalizer, so the format below is what you must pass. Discover exact IDs with pretorin frameworks families <framework_id> and pretorin frameworks controls <framework_id>.

FrameworkFamily formatControl formatExample call
iso-27001Theme slug — organizational, people, physical, technologicalA.<clause>.<n>pretorin frameworks control iso-27001 A.5.10
iso42001Domain slug — data, policies, lifecycle, third-party, …A.<clause>.<n>pretorin frameworks control iso42001 A.10.2
pci-dss-4req-PCI-<n>PCI-<req>.<sub>.<sub>pretorin frameworks control pci-dss-4 PCI-10.1.1
hipaaUppercase code — HIPAA-ADM, HIPAA-TEC, HIPAA-PHY, …HIPAA-<CFR citation>pretorin frameworks control hipaa 'HIPAA-164.308(a)(1)(i)'
hipaa-nistadministrative, physical, technicalHIPAA-<CODE>-NN[.NN]pretorin frameworks control hipaa-nist HIPAA-ADM-01.01
gdprUppercase code — GDPR-PRINC, GDPR-RIGHTS, GDPR-SEC, …GDPR-<zero-padded article>[.<para><letter>]pretorin frameworks control gdpr GDPR-05.1a
fedramp-20xKSI-<CODE>KSI-CNA, KSI-IAM, KSI-MLA, …KSI-<CODE>-<IND>pretorin frameworks control fedramp-20x KSI-CMT-LMC
nist-800-218Practice-group slug — prepare-the-organization, protect-software, …Six-digit dotted pairpretorin frameworks control nist-800-218 000001.000002
fips-140-3Requirement-area slug — self-tests, physical-security, …SRA-NNpretorin frameworks control fips-140-3 SRA-01
revised-section-508software, hardware, functional-performance-criteria, wcag-2-0-level-a, wcag-2-0-level-aa, support-documentation-and-servicesWCAG success-criterion or 508 clause numberpretorin frameworks control revised-section-508 602.4

Two traps in this set:

  • HIPAA and GDPR family IDs are uppercase codes, not lowercase slugs — the opposite of the 800-53 convention. hipaa-nist (the NIST Security Rule mapping) does use lowercase slugs, so the two HIPAA catalogs differ from each other.
  • pci-dss-4 exposes two family-slug series. Only the req-PCI-<n> slugs carry controls; the bare req-<n> slugs return zero results without erroring.

Auto-Normalization

The CLI and MCP tools automatically normalize control IDs that match the NIST/FedRAMP shape — a two-letter family code, a hyphen, and a number: uppercase is lowered and the base number is zero-padded. For example, AC-2 becomes ac-02 and SC-7.1 becomes sc-07.1. This covers NIST 800-53, FedRAMP, and every 800-53-derived baseline. Client-side normalization does not pad the enhancement number — the platform does that, so a lookup for sc-07.1 resolves to the canonical sc-07.01. All other IDs — CMMC, NIST 800-171, SOC 2, and everything in Other Catalogs — do not match the pattern and are passed through unchanged, so use the exact format shown above.

Discovery Workflow

When a user provides an informal control reference (e.g., “AC-2” or “access control”):

  1. Call pretorin frameworks families <framework_id> to find the correct family slug
  2. Call pretorin frameworks controls <framework_id> --family <family_slug> to find the correct control ID
  3. Use the discovered ID in subsequent calls

Quick Reference

FrameworkFamily FormatControl FormatExample
NIST 800-53access-controlac-01pretorin frameworks control nist-800-53-r5 ac-02
FedRAMPaccess-controlac-01pretorin frameworks control fedramp-moderate ac-02
CMMCaccess-control-level-2AC.L2-3.1.1pretorin frameworks control cmmc-l2 AC.L2-3.1.1
800-171access-control03.01.01pretorin frameworks control nist-800-171-r3 03.01.01
SOC 2securityPTR-SOC2-SEC-001pretorin frameworks control soc2 PTR-SOC2-SEC-001
DoD / NSS-IC / OT-ICS / IoTaccess-controlac-01pretorin frameworks control dod-cloud-il4 ac-02
ISO 27001 / 42001organizationalA.5.10pretorin frameworks control iso-27001 A.5.10
PCI DSS 4.0req-PCI-1PCI-1.1.1pretorin frameworks control pci-dss-4 PCI-10.1.1
HIPAAHIPAA-ADMHIPAA-164.308(a)(1)(i)pretorin frameworks control hipaa 'HIPAA-164.308(a)(1)(i)'
GDPRGDPR-PRINCGDPR-05.1apretorin frameworks control gdpr GDPR-05.1a
FedRAMP 20xKSI-CMTKSI-CMT-LMCpretorin frameworks control fedramp-20x KSI-CMT-LMC