J.P-13 A3 C-SCRM Plan Template V.2.docx

DOCX document 477 KB Posted

Attached to
Alliant 3 GWAC, Request for Proposal (RFP) Federal contract opportunity
Solicitation number
47QTCB24R0009
Issued by
GSA Federal Acquisition Service

About this file

This document is a Cybersecurity Supply Chain Risk Management (C-SCRM) Plan template for the Alliant 3 Governmentwide Acquisition Contract (GWAC) program. The C-SCRM Plan provides an overview of the security requirements and controls for the Alliant 3 system, including details on system description, information type and categorization, operational environment, information exchange, incident response, and roles and responsibilities. Key elements covered include access control, awareness and training, audit and accountability, configuration management, contingency planning, identification and authentication, incident response, maintenance, media protection, physical and environmental protection, planning, program management, personnel security, risk assessment, and supply chain risk management. The C-SCRM Plan is intended to be tailored and implemented by Alliant 3 contractors to address cybersecurity risks in the supply chain. This template is one of the attachments included in the Alliant 3 GWAC Request for Proposals.

View the file

Other files for this federal contract opportunity

Other files attached to Alliant 3 GWAC, Request for Proposal (RFP), newest first.
File Type Posted
Alliant 3 Phase One Award Notice.pdf PDF
SF30 Amend 0012 Alliant 3.pdf PDF
Alliant 3 RFP A0011 - Version11.pdf PDF
SF30 Amend 0011 Alliant 3.pdf PDF
SF30 Amend 0010 Alliant 3.pdf PDF
Alliant 3 RFP A0010 - Version10.pdf PDF
Alliant 3 RFP A0009 - Version 9.pdf PDF
J.P-16 A3 Self-Scoring Worksheet V.5.xlsx XLSX spreadsheet
J.P-10 A3 GSA Form 527 Contractor Qualification and Financial Information V.4.pdf PDF
SF30 Amend 0007 Alliant 3.pdf PDF
Alliant 3 Pre-proposal Conference.pdf PDF
Alliant 3 RFP A0006 - Version 6.pdf PDF
SF30 Amend 0006 Alliant 3.pdf PDF
J.P-16 A3 Self-Scoring Worksheet V.4.xlsx XLSX spreadsheet
Alliant 3 RFP A0005 - Version 5.pdf PDF
SF30 Amend 0005 Alliant 3.pdf PDF
J.P-10 A3 GSA Form 527 Contractor Qualification and Financial Information V.3.pdf PDF
SF30 Amend 0004 Alliant 3.pdf PDF
Alliant 3 RFP A0004 - Version 4.pdf PDF
SF30 Amend 0003 Alliant 3.pdf PDF
J.P-7 A3 Federal Contract FPDS Crosswalk Sample V2.pdf PDF
J.P-16 A3 Self-Scoring Worksheet V.3.xlsx XLSX spreadsheet
A3 GR Set 02_09.27.24.pdf PDF
J.P-9 A3 Model Individual Subcontracting Plan Template V.3.xlsx XLSX spreadsheet
J.P-11 A3 Contractor C-SCRM Responsibility Questionnaire V.2.pdf PDF
J.P-18 A3 Labor Rate Attestation V.2.pdf PDF
A3 GR Set 01_08.23.24.xlsx XLSX spreadsheet
J.P-9 A3 Model Individual Subcontracting Plan Template V.2.xlsx XLSX spreadsheet
J.P-12 A3 C-SCRM References V.2.pdf PDF
SF30 Amend 0001 Alliant 3.pdf PDF
J.P-10 A3 GSA Form 527 Contractor Qualification and Financial Information V.2.pdf PDF
A3 SF33 47QTCB24R0009.pdf PDF
J.P-1 A3 Contractor Teaming Arrangement (CTA) Template.pdf PDF
J.P-6 A3 Past Performance Rating Template.pdf PDF
J.P-14 A3 C-SCRM Control Selections.xlsx XLSX spreadsheet
J.P-18 A3 Labor Rate Attestation.pdf PDF
J.P-4 A3 Subcontractor Experience Project Template.pdf PDF
J.P-7 A3 Federal Contract FPDS Crosswalk Sample.pdf PDF
J.P-17 A3 C-SCRM Plan Preparation Guide.pdf PDF
J.P-8 A3 Price Template.xlsx XLSX spreadsheet
J.P-10 A3 GSA Form 527 Contractor Qualification and Financial Information.pdf PDF
J.P-13 A3 C-SCRM Plan Template.xlsx XLSX spreadsheet
Alliant 3 RFP 47QTCB24R0009.pdf PDF
J.P-3 A3 Emerging Technology Relevant Experience Project Template.pdf PDF
J.P-5 A3 Small Business Engagement Template.pdf PDF
J.P-9 A3 Model Individual Subcontracting Plan Template.xlsx XLSX spreadsheet
J.P-11 A3 Contractor C-SCRM Responsibility Questionnaire.xlsx XLSX spreadsheet
J.P-12 A3 C-SCRM References.pdf PDF
J.P-15 A3 Climate Change Risk Management Plan Criteria.pdf PDF
J.P-16 A3 Self-Scoring Worksheet.xlsx XLSX spreadsheet
Show all 50

Alliant 3 GWAC, Request for Proposal (RFP) has more files on GovTribe.

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

This page is intentionally left blank.

DOCUMENT CHANGE CONTROL

Version Release Date Summary of Changes Section / Pages Affected Author

REVIEW LOG

Date of Review Reviewer Organization

ALLIANT 3 GWAC CONTACT INFORMATION

For more information about the Alliant 3 GWAC, visit the website at: https://www.gsa.gov/technology/technology-purchasing-programs/governmentwide-acquisition-contracts/alliant-3

TABLE OF CONTENTS

1.SYSTEM NAME AND IDENTIFIER1
2.SYSTEM DESCRIPTION1
3.SYSTEM INFORMATION TYPE AND CATEGORIZATION1
4.REVISIONS AND MAINTENANCE2
5.SYSTEM OPERATIONAL STATUS2
6.SYSTEM ENVIRONMENT2
6.1. Operational Environment Type2
6.2. Network Diagrams3
6.3. System Component Inventory3
7.INFORMATION EXCHANGE AND SYSTEM CONNECTIONS3
8.CONTINGENCIES AND EMERGENCIES (OPTIONAL)3
9.APPLICABLE LAWS AND REGULATIONS4
10.ROLES AND RESPONSIBILITES4
11.C-SCRM CONTROL DETAILS6
11.1. FAMILY: ACCESS CONTROL (AC)6
11.1.1. AC-2 Account Management6
11.2. FAMILY: AWARENESS AND TRAINING (AT)8
11.2.1. AT-3 Role-Based Training8
11.3. FAMILY: AUDIT AND ACCOUNTABILITY (AU)10
11.3.1. AU-2 Event Logging10
11.3.2. AU-6 Audit Record Review, Analysis, and Reporting11
11.4. FAMILY: ASSESSMENT, AUTHORIZATION, AND MONITORING (CA)12
11.4.1. CA-5 Plan of Action and Milestones12
11.5. FAMILY: CONFIGURATION MANAGEMENT (CM)13
11.5.1. CM-2 Baseline Configuration13
11.5.2. CM-4 Impact Analyses14
11.5.3. CM-8 System Component Inventory15
11.6. FAMILY: CONTINGENCY PLANNING (CP)16
11.6.1. CP-2 Contingency Plan16
11.7. FAMILY: IDENTIFICATION AND AUTHENTICATION (IA)18
11.7.1. IA-2 Identification and Authentication (Organizational Users)18
11.8. FAMILY: INCIDENT RESPONSE (IR)19
11.8.1. IR-5 Incident Monitoring19
11.8.2. IR-8 Incident Response Plan19
11.9. FAMILY: MAINTENANCE (MA)21
11.9.1. MA-5 Maintenance Personnel21
11.10. FAMILY: MEDIA PROTECTION (MP)22
11.10.1. MP-6 Media Sanitization22
11.11. FAMILY: PHYSICAL AND ENVIRONMENTAL PROTECTION (PE)22
11.11.1. PE-3 Physical Access Control23
11.11.2. PE-6 Monitoring Physical Access24
11.12. FAMILY: PLANNING (PL)25
11.12.1. PL-8 Security and Privacy Architectures25
11.13. FAMILY: PROGRAM MANAGEMENT (PM)26
11.13.1. PM-31 Continuous Monitoring Strategy26
11.14. FAMILY: PERSONNEL SECURITY (PS)28
11.14.1. PS-3 Personnel Screening28
11.15. FAMILY: RISK ASSESSMENT (RA)29
11.15.1. RA-3 Risk Assessment29
11.15.2. RA-7 Risk Response30
11.16. FAMILY: SYSTEM AND SERVICES ACQUISITION (SA)31
11.16.1. SA-1 Policy and Procedures31
11.16.2. SA-2 Allocation of Resources33
11.16.3. SA-3 System Development Life Cycle33
11.16.4. SA-4 Acquisition Process34
11.16.5. SA-5 System Documentation36
11.16.6. SA-8 Security and Privacy Engineering Principles38
11.16.7. SA-22 Unsupported System Components39
11.17. FAMILY: SYSTEM AND COMMUNICATIONS PROTECTION (SC)39
11.17.1. SC-7 Boundary Protection39
11.17.2. SC-8 Transmission Confidentiality and Integrity41
11.18. FAMILY: SYSTEM AND INFORMATION INTEGRITY (SI)41
11.18.1. SI-3 Malicious Code Protection41
11.18.2. SI-5 Security Alerts, Advisories, and Directives42
11.19. FAMILY: SUPPLY CHAIN RISK MANAGEMENT (SR)43
11.19.1. SR-1 Policy and Procedures43
11.19.2. SR-4 Provenance45
11.19.3. SR-5 Acquisition Strategies, Tools, and Methods46
11.19.4. SR-8 Notification Agreements46
11.19.5. SR-9 Tamper Resistance and Detection46
11.19.6. SR-10 Inspection of Systems or Components47
11.19.7. SR-11 Component Authenticity48
11.19.8. SR-12 Component Disposal49
APPENDIX A - ACRONYMS50
APPENDIX B - RELATED LAWS AND REGULATIONS52
APPENDIX C - C-SCRM ACTIVITIES AND LIFE CYCLES56
APPENDIX D - ATTACHMENTS57
APPENDIX E - C-SCRM CONTROL IMPLEMENTATION SUMMARY (CIS)58

LIST OF TABLES

Table 1 – System Name and Identifier1
Table 2 – Offering and Provider Type1
Table 3 – System Operational Status2
Table 4 – Operational Environment Type2
Table 5 – System Interconnections3
Table 6 – Contingency and Emergency Contacts4
Table 7 – C-SCRM Roles and Responsibilities4

LIST OF FIGURES

Figure 1- System Security Categorization2
Figure 2- Network Diagram[s]3
Figure 3 - Integrated C-SCRM Activities56

[Contractor Name] [(Acronym)] Alliant 3 GWAC Program Minimum Control Baseline

C-SCRM Plan July 2024 [Version 0.00]

ALLIANT 3 Page i

ALLIANT 3 Page ii

1. SYSTEM NAME AND IDENTIFIER

This Cybersecurity Supply Chain Risk Management (C-SCRM) Plan is intended to communicate the [System Name] [Unique Identifier] commitment to continuously improve and strengthen its cybersecurity supply chain security posture and its strategy for addressing cyber supply chain risk.

This C-SCRM Plan provides an overview of the security requirements for [Unique Identifier] and describes the controls in place or planned for meeting those requirements.

The security safeguards implemented for [Unique Identifier] meet the requirements set forth in the enterprise’s C-SCRM strategy and policy guidance and are appropriate for the information to be securely transmitted, processed, or stored by the system.

Table 1 – System Name and Identifier

System Name
[System Name]
Unique Identifier
[Unique Identifier]

The C-SCRM control implementations described in this C-SCRM Plan are tailored for and applicable to the following offer and provider type:

Table 2 – Offering and Provider Type

Offering Type
Choose an item.
Provider Type
Choose an item.

1. SYSTEM DESCRIPTION

[Provide System Description]

SYSTEM INFORMATION TYPE AND CATEGORIZATION

The following table identifies the information types and impact levels that are processed, stored, or transmitted by the system and/or its in-boundary supply chain. The security impact levels for confidentiality, integrity, and availability for each of the information types are expressed as low, moderate, or high. The security impact levels are based on the potential impact definitions for each of the security objectives (i.e., confidentiality, integrity, and availability) discussed in NIST SP 800-60 Vol. 2, Rev. 1, Appendices to Guide for Mapping Types of Information and Information Systems to Security Categories; and Federal Information Processing Standards (FIPS) 199, Standards for Security Categorization of Federal Information and Information Systems.

Figure 1- System Security Categorization

REVISIONS AND MAINTENANCE

This C-SCRM Plan is reviewed and updated at least annually by the [Define personnel or group responsible]. To view the latest updates and reviews, refer to the Document Change Control and Review Log sections above.

SYSTEM OPERATIONAL STATUS

The system is currently in the operational status noted in the following table.

Table 3 – System Operational Status

Status One
Choose an item.
Status Two (Optional)
Choose an item.

Explanation

SYSTEM ENVIRONMENT

Operational Environment Type The system is currently in the operational environment noted in the following table.

Table 4 – Operational Environment Type

Type
Choose an item.

Custom\Other Explanation

Network Diagrams The following architectural diagram provides a visual depiction of the major hardware components of the [Unique Identifier].

Figure 2- Network Diagram[s] Instructions: Insert network diagram(s) here.

System Component Inventory The following spreadsheet identifies hardware, software, and firmware components of [Unique Identifier].

System Component Inventory

INFORMATION EXCHANGE AND SYSTEM CONNECTIONS

All interconnections between [Unique Identifier] and external entities including off-site contractors or Federal agency/departments are listed in Table 5.

Table 5 – System Interconnections

Agreement Date
Agreement Type
Name of System
Enterprise or Organization Name
Type of Connection or Information Exchange
FIPS 199 Categorization
Authorization Status
Authorization Official Name and Title

Click or tap to enter a date. Choose an item.

Choose an item. Choose an item.

Click or tap to enter a date. Choose an item.

Choose an item. Choose an item.

Click or tap to enter a date. Choose an item.

Choose an item. Choose an item.

CONTINGENCIES AND EMERGENCIES (OPTIONAL)

In the event of an emergency where equipment is urgently needed, the C-SCRM Project Management Office (PMO) will offer its assistance through C-SCRM Subject Matter Experts (SMEs) to provide help in the absence of the formal tasking and chain of command approval. The Chief Information Officer (CIO) has the authority to provide such waivers to bypass normal procedures. The current contact information for C-SCRM SMEs is provided below:

Table 6 – Contingency and Emergency Contacts

Point of Contact (POC)
Name
E-mail Address
Phone Number

C-SCRM SME POC

Acquisitions SME POC

Legal SME POC

APPLICABLE LAWS AND REGULATIONS

See Appendix B - Related Laws and Regulations

ROLES AND RESPONSIBILITES

Table 7 illustrates roles and responsibilities of various C-SCRM Program stakeholders. The following roles and associated responsibilities are relevant to the activities of this Plan.

Table 7 – C-SCRM Roles and Responsibilities

Role
Responsibilities

Level 1 Enterprise

Senior Leadership Team
· Endorse the enterprise’s C-SCRM strategic objectives and implementation plan.

· Provide oversight of C-SCRM implementation and effectiveness

· Communicate C-SCRM direction and decisions for priorities and resourcing needs.

· Determine the enterprise’s risk appetite and risk tolerance.

· Respond to high-risk C-SCRM issue escalations that could impact the enterprise’s risk posture in a timely manner.

Chief Acquisition Officer (CAO)
· Advise and assist the head of agency and other agency officials to ensure that the mission of the agency is achieved through the management of the agency’s acquisition activities.

· Monitor the performance of acquisition activities and programs

· Establish clear lines of authority, accountability, and responsibility for acquisition decision-making within the agency; manage the direction and implementation of acquisition policy for the agency.

· Establish policies, procedures, and practices that promote full and open competition from responsible sources to fulfill best value requirements considering the nature of the property or service procured.

· Coordinate with mission or business owners, authorizing officials, senior accountable official for risk management, system owners, common control providers, senior agency information security officer, senior agency official for privacy, and risk executive (function) to ensure that security and privacy requirements are defined in organizational procurements and acquisitions.

[Enter Role]
· [Enter Responsibilities]
[Enter Role]
· [Enter Responsibilities]

Level 2 Mission/Business Processes

Mission/Business Owners
· Determine mission-level risk appetite and tolerance, ensuring they are in line with enterprise expectations.

· Define supply chain risk management requirements and implementation of controls that support enterprise objectives.

· Maintain criticality analyses of mission functions and assets

· Perform risk assessments for mission/business-related procurements.

[Enter Role]
· [Enter Responsibilities]
[Enter Role]
· [Enter Responsibilities]
[Enter Role]
· [Enter Responsibilities]

Level 3 Operational

System Owners
· Determine whether an information system meets business, functional, and technical requirements and includes appropriately tailored controls.

· Develop C-SCRM plans.

· Implement C-SCRM policies and requirements.

· Adhere to constraints provided by Levels 1 and 2.

· Tailor C-SCRM to the context of the individual system and apply it throughout the SDLC.

· Report on C-SCRM to Level 2.

[Enter Role]
· [Enter Responsibilities]
[Enter Role]
· [Enter Responsibilities]
[Enter Role]
· [Enter Responsibilities]

C-SCRM CONTROL DETAILS

Minimum security controls for the [Unique Identifier] environment is contained in the following sections.

FAMILY: ACCESS CONTROL (AC)

AC-2 Account Management

ACCESS CONTROL (AC)

AC-2 ACCOUNT MANAGEMENT

IMPLEMENTATION STATUS
CONTROL ORIGINATION
Choose an item.Choose an item.
NIST SP 800-53 CONTROL BASELINE ALLOCATION:
N/A
Low
Moderate
High
NIST SP 800-161 CONTROL BASELINE ALLOCATION:
C-SCRM
N/A
Level 2
Level 3
Supplemental C-SCRM Guidance:
Use of this control helps establish traceability of actions and actors in the supply chain. This control also helps ensure access authorizations of actors in the supply chain is appropriate on a continuous basis. The enterprise may choose to define a set of roles and associate a level of authorization to ensure proper implementation. Enterprises must ensure that accounts for contractor personnel do not exceed the period of performance of the contract. Privileged accounts should only be established for appropriately vetted contractor personnel. Enterprises should also have processes in place to establish and manage temporary or emergency accounts for contractor personnel that require access to a mission-critical or mission-enabling system during a continuity or emergency event. For example, during a pandemic event, existing contractor personnel who are not able to work due to illness may need to be temporarily backfilled by new contractor staff. Enterprises should require their prime contractors to implement this control and flow down this requirement to relevant sub-tier contractors.
Part a
a. Define and document the types of accounts allowed and specifically prohibited for use within the system;

System-Specific

Common or Hybrid

Part b
b. Assign account managers;

System-Specific

Common or Hybrid

Part c

c. Require [Discretionary Access Control (DAC), Role Based Access Control (RBAC), or Mandatory Access Control (MAC)] for group and role membership;

System-Specific

Common or Hybrid

Part d
d. Specify:

1. Authorized users of the system;

2. Group and role membership; and

3. Access authorizations (i.e., privileges) and [system specific parameter, requiring organization to define] for each account;

System-Specific

Common or Hybrid

Part e
e. Require approvals by [designated account managers] for requests to create accounts;

System-Specific

Common or Hybrid

Part f

f. Create, enable, modify, disable, and remove accounts in accordance with [Center for Internet Security (CIS) Benchmark, Security Content Automation Protocol (SCAP) Benchmark, NIST Security Configuration Checklist, Defense Information System Agency (DISA) Security Technical Implementation Guides (STIGs) and/or National Security Agency (NSA) Guides];

System-Specific

Common or Hybrid

Part g
g. Monitor the use of accounts;

System-Specific

Common or Hybrid

Part h
h. Notify account managers and [organizational and government personnel (as applicable) or (as required) with access control responsibilities] within:

1. [5 business days] when accounts are no longer required;

2. [5 business days] when users are terminated or transferred; and

3. [5 business days] when system usage or need-to-know changes for an individual;

System-Specific

Common or Hybrid

Part i

i. Authorize access to the system based on:

1. A valid access authorization;

2. Intended system usage; and

3. [System specific parameter, requiring organization to define].

System-Specific

Common or Hybrid

Part j
j. Review accounts for compliance with account management requirements [monthly];

System-Specific

Common or Hybrid

Part k
k. Establish and implement a process for changing shared or group account authenticators (if deployed) when individuals are removed from the group; and

System-Specific

Common or Hybrid

Part l

l. Align account management processes with personnel termination and transfer processes.

System-Specific

Common or Hybrid

FAMILY: AWARENESS AND TRAINING (AT)

AT-3 Role-Based Training

AWARENESS AND TRAINING (AT)

AT-3 ROLE-BASED TRAINING

IMPLEMENTATION STATUS
CONTROL ORIGINATION
Choose an item.Choose an item.
NIST SP 800-53 CONTROL BASELINE ALLOCATION:
Privacy
Low
Moderate
High
NIST SP 800-161 CONTROL BASELINE ALLOCATION:
C-SCRM
N/A
Level 2
N/A
Supplemental C-SCRM Guidance:
Addressing cyber-supply chain risks throughout the acquisition process is essential to performing C-SCRM effectively. Personnel who are part of the acquisition workforce require training on what C-SCRM requirements, clauses, and evaluation factors are necessary to include when conducting a procurement and how to incorporate C-SCRM into each acquisition phase. Similar enhanced training requirements should be tailored for personnel responsible for conducting threat assessments. Responding to threats and identified risks require training in counterintelligence awareness and reporting. Enterprises should ensure that developers receive training on secure development practices as well as the use of vulnerability scanning tools. Enterprises should require their prime contractors to implement this control and flow down this requirement to relevant sub-tier contractors.
Part a
a. Provide role-based security and privacy training to personnel with the following roles and responsibilities: [Personnel who are part of the acquisition workforce or organizational and government personnel (as applicable) or (as required) with C-SCRM responsibilities.]:

1. Before authorizing access to the system, information, or performing assigned duties, and [annually] thereafter; and

2. 2. When required by system changes;

System-Specific

Common or Hybrid

Part b
b. Update role-based training content [annually] and following [assessment or audit findings, security incidents or breaches, or changes in applicable laws, executive orders, directives, regulations, policies, standards, and guidelines and the analysis of security and privacy trends, significant events, and user feedback]; and

System-Specific

Common or Hybrid

Part c
c. Incorporate lessons learned from internal or external security incidents or breaches into role-based training.

System-Specific

Common or Hybrid

FAMILY: AUDIT AND ACCOUNTABILITY (AU)

AU-2 Event Logging

AUDIT AND ACCOUNTABILITY (AU)

AU-2 EVENT LOGGING

IMPLEMENTATION STATUS
CONTROL ORIGINATION
Choose an item.Choose an item.
NIST SP 800-53 CONTROL BASELINE ALLOCATION:
Privacy
Low
Moderate
High
NIST SP 800-161 CONTROL BASELINE ALLOCATION:
C-SCRM
Level 1
Level 2
Level 3
Supplemental C-SCRM Guidance:
An observable occurrence within the information system or supply chain network should be identified as a supply chain auditable event, based on the enterprise’s SDLC context and requirements. Auditable events may include software/hardware changes, failed attempts to access supply chain information systems, or movement of source code. Information on such events should be captured by appropriate audit mechanisms and should be traceable and verifiable. Information captured may include the type of event, date/time, length, and frequency of occurrence. Among other things, auditing may help detect misuse of the supply chain information systems or network caused by insider threat. Logs are a key resource when identifying operational trends and long-term problems. As such enterprises should incorporate reviewing logs at contract renewal point for vendors to determine whether there is systemic problem. Enterprises should require their prime contractors to implement this control and flow down this requirement to relevant sub-tier contractors.
Part a
a. Identify the types of events that the system is capable of logging in support of the audit function: [Successful and unsuccessful account logon events, password changes, account management events, object access, policy change, administrative privilege usage, failed accesses to information system resources and applications, tracking, and system events; to include logging of all privileged user activity, authentication checks, authorization checks, data deletions, data access, data changes, and permission changes.];

System-Specific

Common or Hybrid

Part b
b. Coordinate the event logging function with other organizational entities requiring audit related information to guide and inform the selection criteria for events to be logged;

System-Specific

Common or Hybrid

Part c
c. Specify the following event types for logging within the system: [Implement audit configuration requirements as documented in applicable Security Technical Hardening Guides; to include logging of all privileged user activity, authentication checks, authorization checks, data deletions, data access, data changes, and permission changes. The implemented audit configuration settings and deviations (if any) from what is required in Security Hardening Guides must be documented in the C-SCRM Plan. The C-SCRM Plan should include a list of the auditable events, as well as providing in sufficient detail the rationale regarding why this list of events is suitable for security incident analysis. Frequency is continually.];

System-Specific

Common or Hybrid

Part d
d. Provide a rationale for why the event types selected for logging are deemed to be adequate to support after-the-fact investigations of incidents; and

System-Specific

Common or Hybrid

Part e
e. Review and update the event types selected for logging [annually or whenever there is a change in the system’s threat environment].

System-Specific

Common or Hybrid

AU-6 Audit Record Review, Analysis, and Reporting

AUDIT AND ACCOUNTABILITY (AU)

AU-6 AUDIT RECORD REVIEW, ANALYSIS, AND REPORTING

IMPLEMENTATION STATUS
CONTROL ORIGINATION
Choose an item.Choose an item.
NIST SP 800-53 CONTROL BASELINE ALLOCATION:
N/A
Low
Moderate
High
NIST SP 800-161 CONTROL BASELINE ALLOCATION:
C-SCRM
N/A
Level 2
Level 3
Supplemental C-SCRM Guidance:
The enterprise should ensure that both supply chain and information security auditable events are appropriately filtered and correlated for analysis and reporting. For example, if new maintenance or a patch upgrade is recognized to have an invalid digital signature, the identification of the patch arrival qualifies as a supply chain auditable event, while an invalid signature is an information security auditable event. The combination of these two events may provide information valuable to C-SCRM. The enterprise should adjust the level of audit record review based on risk changes (e.g., active threat intel, risk profile) on a specific vendor. Contracts should explicitly address how audit findings will be reported and adjudicated.
Part a
a. Review and analyze system audit records [daily] for indications of [any unusual or inappropriate activity with potential cybersecurity implications] and the potential impact of the inappropriate or unusual activity;

System-Specific

Common or Hybrid

Part b
b. Report findings to [organizational and government personnel (as applicable) or (as required) with information system audit record generation responsibilities and/or monitoring responsibilities]; and

System-Specific

Common or Hybrid

Part c
c. Adjust the level of audit record review, analysis, and reporting within the system when there is a change in risk based on law enforcement information, intelligence information, or other credible sources of information.

System-Specific

Common or Hybrid

FAMILY: ASSESSMENT, AUTHORIZATION, AND MONITORING (CA)

CA-5 Plan of Action and Milestones

ASSESSMENT, AUTHORIZATION, AND MONITORING (CA)

CA-5 PLAN OF ACTION AND MILESTONES

IMPLEMENTATION STATUS
CONTROL ORIGINATION
Choose an item.Choose an item.
NIST SP 800-53 CONTROL BASELINE ALLOCATION:
Privacy
Low
Moderate
High
NIST SP 800-161 CONTROL BASELINE ALLOCATION:
C-SCRM
N/A
Level 2
Level 3
Supplemental C-SCRM Guidance:
For system-level plan of actions and milestones (POA&Ms), enterprises need to ensure that a separate POA&M exists for C-SCRM and includes both information systems and the supply chain. The C-SCRM POA&M should include tasks to be accomplished with a recommendation for completion before or after system authorization; the resources required to accomplish the tasks; milestones established to meet the tasks; and the scheduled completion dates for the milestones and tasks. The enterprise should include in its C-SCRM POA&M relevant weaknesses, the impact of weaknesses on information systems or the supply chain, any remediation to address weaknesses, and any continuous monitoring activities. The C-SCRM POA&M should be included as part of the authorization package.
Part a
a. Develop a plan of action and milestones for the system to document the planned remediation actions of the organization to correct weaknesses or deficiencies noted during the assessment of the controls and to reduce or eliminate known vulnerabilities in the system; and

System-Specific

Common or Hybrid

Part b
b. Update existing plan of action and milestones [Living document; continually edited and updated] based on the findings from control assessments, independent audits or reviews, and continuous monitoring activities.

System-Specific

Common or Hybrid

FAMILY: CONFIGURATION MANAGEMENT (CM)

CM-2 Baseline Configuration

CONFIGURATION MANAGEMENT (CM)

CM-2 BASELINE CONFIGURATION

IMPLEMENTATION STATUS
CONTROL ORIGINATION
Choose an item.Choose an item.
NIST SP 800-53 CONTROL BASELINE ALLOCATION:
N/A
Low
Moderate
High
NIST SP 800-161 CONTROL BASELINE ALLOCATION:
C-SCRM
N/A
Level 2
Level 3
Supplemental C-SCRM Guidance:
Enterprises should establish a baseline configuration of both the information system and the development environment including documenting, formally reviewing, and securing the agreement of stakeholders. The purpose of the baseline is to provide a starting point for tracking the changes to components, code, and/or settings throughout the SDLC. Regular reviews and updates of baseline configurations (i.e., re-baselining) are critical for traceability and provenance. The baseline configuration must take into consideration the enterprise’s operational environment and any relevant supplier, developer, system integrator, external system service provider, and other Information and Communications Technology (ICT)/Operational Technology (OT)-related service providers’ involvement within the organization’s information systems and networks. If the system integrator, for example, uses the existing organization’s infrastructure, appropriate measures should be taken to establish a baseline that reflects an appropriate set of agreed-upon criteria for access and operation. Enterprises should require their prime contractors to implement this control and flow down this requirement to relevant sub-tier contractors.
Part a
a. Develop, document, and maintain under configuration control, a current baseline configuration of the system; and

System-Specific

Common or Hybrid

Part b
b. Review and update the baseline configuration of the system:

1. [At least annually];

2. When required due to [significant change as defined in NIST SP 800-37 Revision 2, Appendix F]; and

3. When system components are installed or upgraded.

System-Specific

Common or Hybrid

CM-4 Impact Analyses

CONFIGURATION MANAGEMENT (CM)

CM-4 IMPACT ANALYSES

IMPLEMENTATION STATUS
CONTROL ORIGINATION
Choose an item.Choose an item.
NIST SP 800-53 CONTROL BASELINE ALLOCATION:
Privacy
Low
Moderate
High
NIST SP 800-161 CONTROL BASELINE ALLOCATION:
C-SCRM
N/A
N/A
Level 3
Supplemental C-SCRM Guidance:
Enterprises should take under consideration changes to the information system and underlying or interoperable systems and networks to determine whether the impact of these changes affects existing security controls and warrants additional or different protection to maintain an acceptable level of cybersecurity risk in the supply chain. Ensure that stakeholders, such as system engineers and system security engineers, are included in the impact analysis activities to provide their perspectives for C-SCRM.
Control
Analyze changes to the system to determine potential security and privacy impacts prior to change implementation.

System-Specific

Common or Hybrid

CM-8 System Component Inventory

CONFIGURATION MANAGEMENT (CM)

CM-8 SYSTEM COMPONENT INVENTORY

IMPLEMENTATION STATUS
CONTROL ORIGINATION
Choose an item.Choose an item.
NIST SP 800-53 CONTROL BASELINE ALLOCATION:
N/A
Low
Moderate
High
NIST SP 800-161 CONTROL BASELINE ALLOCATION:
C-SCRM
N/A
Level 2
Level 3
Supplemental C-SCRM Guidance:
Enterprises should ensure that critical component assets within the information systems and networks are included in the asset inventory. The inventory must include information for critical component accountability. Inventory information includes, for example, hardware inventory specifications, software license information, software version numbers, component owners, and for networked components or devices, machine names, and network addresses. Inventory specifications may the manufacturer, device type, model, serial number, and physical location. Enterprises should require their prime contractors to implement this control and flow down this requirement to relevant sub-tier contractors. Enterprises should specify the requirements and how information flow is enforced to ensure that only the required information, and not more, is communicated to the various participants in the supply chain. If information is subsetted downstream, there should be information about who created the subset information. Enterprises should consider producing Software Bill of Materials (SBOMs) for applicable and appropriate classes of software including purchased software, open-source software, and in-house software. Refer to NIST SP 800-161 Rev.1 Appendix F for additional guidance on SBOMs.
Part a
a. Develop and document an inventory of system components that:

1. Accurately reflects the system;

2. Includes all components within the system;

3. Does not include duplicate accounting of components or components assigned to any other system;

4. Is at the level of granularity deemed necessary for tracking and reporting; and

5. Includes the following information to achieve system component accountability: [Hardware inventory specifications (manufacturer, type, model, serial number, physical location), software installation/license information, information system/component owner, and for networked components/device, the Domain Name System (DNS) name, Internet Protocol (IP) Address, Virtual Local Area Network (VLAN)/Subnet, Logical Location]; and

System-Specific

Common or Hybrid

Part b
b. Review and update the system component inventory [Living document; continually edited and updated].

System-Specific

Common or Hybrid

FAMILY: CONTINGENCY PLANNING (CP)

CP-2 Contingency Plan

CONTINGENCY PLANNING (CP)

CP-2 CONTINGENCY PLAN

IMPLEMENTATION STATUS
CONTROL ORIGINATION
Choose an item.Choose an item.
NIST SP 800-53 CONTROL BASELINE ALLOCATION:
N/A
Low
Moderate
High
NIST SP 800-161 CONTROL BASELINE ALLOCATION:
C-SCRM
N/A
Level 2
Level 3
Supplemental C-SCRM Guidance:
Enterprises should define and implement a contingency plan for the supply chain information systems and network to ensure that preparations are in place to mitigate against the loss or degradation of data or operations. Contingencies should be put in place for the supply chain, network, and information systems (especially critical components), and processes to ensure protection against compromise, provide appropriate failover, and timely recovery to an acceptable state of operations.
Part a
a. Develop a contingency plan for the system that:

1. Identifies essential mission and business functions and associated contingency requirements;

2. Provides recovery objectives, restoration priorities, and metrics;

3. Addresses contingency roles, responsibilities, assigned individuals with contact information;

4. Addresses maintaining essential mission and business functions despite a system disruption, compromise, or failure;

5. Addresses eventual, full system restoration without deterioration of the controls originally planned and implemented;

6. Addresses the sharing of contingency information; and

7. Is reviewed and approved by [System Owner (SO)];

System-Specific

Common or Hybrid

Part b
b. Distribute copies of the contingency plan to [Organizational and government personnel (as applicable) or (as required) with contingency planning responsibilities];

System-Specific

Common or Hybrid

Part c
c. Coordinate contingency planning activities with incident handling activities;

System-Specific

Common or Hybrid

Part d
d. Review the contingency plan for the system [at least annually];

System-Specific

Common or Hybrid

Part e
e. Update the contingency plan to address changes to the organization, system, or environment of operation and problems encountered during contingency plan implementation, execution, or testing;

System-Specific

Common or Hybrid

Part f
f. Communicate contingency plan changes to [Authorizing Official (AO), Information System Security Manager (ISSM), System Security and Privacy Officer (SSPO), Program Manager (PM), Senior Agency Information Security Officer (SAISO), and Emergency Response Coordinator (ERC)];

System-Specific

Common or Hybrid

Part g
g. Incorporate lessons learned from contingency plan testing, training, or actual contingency activities into contingency testing and training; and

System-Specific

Common or Hybrid

Part h
h. Protect the contingency plan from unauthorized disclosure and modification.

System-Specific

Common or Hybrid

FAMILY: IDENTIFICATION AND AUTHENTICATION (IA)

IA-2 Identification and Authentication (Organizational Users)

IDENTIFICATION AND AUTHENTICATION (IA)

IA-2 IDENTIFICATION AND AUTHENTICATION (ORGANIZATIONAL USERS)

IMPLEMENTATION STATUS
CONTROL ORIGINATION
Choose an item.Choose an item.
NIST SP 800-53 CONTROL BASELINE ALLOCATION:
N/A
Low
Moderate
High
NIST SP 800-161 CONTROL BASELINE ALLOCATION:
C-SCRM
Level 1
Level 2
Level 3
Supplemental C-SCRM Guidance:
Enterprises should ensure that identification and requirements are defined and applied for enterprise users accessing an ICT/OT system or supply chain network. An enterprise user may include employees, individuals deemed to have the equivalent status of employees (e.g., contractors, guest researchers, etc.), and system integrators fulfilling contractor roles. Criteria such as “duration in role” can aid in defining which identification and authentication mechanisms are used. The enterprise may choose to define a set of roles and associate a level of authorization to ensure proper implementation. Enterprises should require their prime contractors to implement this control and flow down this requirement to relevant sub-tier contractors.
Control
Uniquely identify and authenticate organizational users and associate that unique identification with processes acting on behalf of those users.

System-Specific

Common or Hybrid

FAMILY: INCIDENT RESPONSE (IR)

IR-5 Incident Monitoring

INCIDENT RESPONSE (IR)

IR-5 INCIDENT MONITORING

IMPLEMENTATION STATUS
CONTROL ORIGINATION
Choose an item.Choose an item.
NIST SP 800-53 CONTROL BASELINE ALLOCATION:
Privacy
Low
Moderate
High
NIST SP 800-161 CONTROL BASELINE ALLOCATION:
C-SCRM
N/A
Level 2
Level 3
Supplemental C-SCRM Guidance:
Enterprises should ensure agreements with suppliers include requirements to track and document incidents, response decisions, and activities.
Control
Track and document incidents.

System-Specific

Common or Hybrid

IR-8 Incident Response Plan

INCIDENT RESPONSE (IR)

IR-8 INCIDENT RESPONSE PLAN

IMPLEMENTATION STATUS
CONTROL ORIGINATION
Choose an item.Choose an item.
NIST SP 800-53 CONTROL BASELINE ALLOCATION:
Privacy
Low
Moderate
High
NIST SP 800-161 CONTROL BASELINE ALLOCATION:
C-SCRM
N/A
Level 2
Level 3
Supplemental C-SCRM Guidance:
Enterprises should coordinate, develop, and implement an incident response plan that includes information sharing responsibilities with critical suppliers and, in a federal context, interagency partners and the Federal Acquisition Security Council (FASC). Enterprises should require their prime contractors to implement this control and flow down this requirement to relevant sub-tier contractors.
Part a
a. Develop an incident response plan that:

1. Provides the organization with a roadmap for implementing its incident response capability;

2. Describes the structure and organization of the incident response capability;

3. Provides a high-level approach for how the incident response capability fits into the overall organization;

4. Meets the unique requirements of the organization, which relate to mission, size, structure, and functions;

5. Defines reportable incidents;

6. Provides metrics for measuring the incident response capability within the organization;

7. Defines the resources and management support needed to effectively maintain and mature an incident response capability;

8. Addresses the sharing of incident information;

9. Is reviewed and approved by [Organizational and government personnel (as applicable) or (as required) with incident response responsibilities] [at least annually]; and

10. Explicitly designates responsibility for incident response to [incident manager, with one or more designated alternates].

System-Specific

Common or Hybrid

Part b
b. Distribute copies of the incident response plan to [Organizational and government personnel (as applicable) or (as required) with incident response responsibilities and organizational elements];

System-Specific

Common or Hybrid

Part c
c. Update the incident response plan to address system and organizational changes or problems encountered during plan implementation, execution, or testing;

System-Specific

Common or Hybrid

Part d
d. Communicate incident response plan changes to [Organizational and government personnel (as applicable) or (as required) with incident response responsibilities]; and

System-Specific

Common or Hybrid

Part e
e. Protect the incident response plan from unauthorized disclosure and modification.

System-Specific

Common or Hybrid

FAMILY: MAINTENANCE (MA)

MA-5 Maintenance Personnel

MAINTENANCE (MA)

MA-5 MAINTENANCE PERSONNEL

IMPLEMENTATION STATUS
CONTROL ORIGINATION
Choose an item.Choose an item.
NIST SP 800-53 CONTROL BASELINE ALLOCATION:
N/A
Low
Moderate
High
NIST SP 800-161 CONTROL BASELINE ALLOCATION:
C-SCRM
N/A
Level 2
Level 3
Supplemental C-SCRM Guidance:
Maintenance personnel may be employed by suppliers, developers, system integrators, external system service providers, or other ICT/OT-related service providers. As such, appropriate protections should be in place to manage associated risks. The same controls applied to internal maintenance personnel should be applied to any contractor personnel performing a similar maintenance role and enforced through contractual agreements with their external service providers.
Part a
a. Establish a process for maintenance personnel authorization and maintain a list of authorized maintenance organizations or personnel;

System-Specific

Common or Hybrid

Part b
b. Verify that non-escorted personnel performing maintenance on the system possess the required access authorizations; and

System-Specific

Common or Hybrid

Part c
c. Designate organizational personnel with required access authorizations and technical competence to supervise the maintenance activities of personnel who do not possess the required access authorizations.

System-Specific

Common or Hybrid

FAMILY: MEDIA PROTECTION (MP)

MP-6 Media Sanitization

MEDIA PROTECTION (MP)

MP-6 MEDIA SANITIZATION

IMPLEMENTATION STATUS
CONTROL ORIGINATION
Choose an item.Choose an item.
NIST SP 800-53 CONTROL BASELINE ALLOCATION:
Privacy
Low
Moderate
High
NIST SP 800-161 CONTROL BASELINE ALLOCATION:
C-SCRM
N/A
Level 2
Level 3
Supplemental C-SCRM Guidance:
Enterprises should specify and include in agreements (e.g., contracting language) media sanitization policies for their suppliers, developers, system integrators, external system service providers, and other ICT/OT-related service providers. Media is used throughout the SDLC. Media traversing or residing in the supply chain may originate anywhere, including from suppliers, developers, system integrators, external system service providers, and other ICT/OT-related service providers. It can be new, refurbished, or reused. Media sanitization is critical to ensure that information is removed before the media is used, reused, or discarded. For media containing privacy or other sensitive information (e.g., Control Unclassified Information [CUI]), the enterprise should require its prime contractors to implement this control and flow down this requirement to relevant sub-tier contractors.
Part a
a. Sanitize [All information system media (digital and non-digital)] prior to disposal, release out of organizational control, or release for reuse using [All information technology resources must be sanitized before being re-purposed, removed, donated, sold, or disposed of outside its security domain according to NIST SP 800-88 and/or Department of Defense (DoD) 5200.1-R]; and

System-Specific

Common or Hybrid

Part b
b. Employ sanitization mechanisms with the strength and integrity commensurate with the security category or classification of the information.

System-Specific

Common or Hybrid

FAMILY: PHYSICAL AND ENVIRONMENTAL PROTECTION (PE)

PE-3 Physical Access Control

PHYSICAL AND ENVIRONMENTAL PROTECTION (PE)

PE-3 PHYSICAL ACCESS CONTROL

IMPLEMENTATION STATUS
CONTROL ORIGINATION
Choose an item.Choose an item.
NIST SP 800-53 CONTROL BASELINE ALLOCATION:
N/A
Low
Moderate
High
NIST SP 800-161 CONTROL BASELINE ALLOCATION:
C-SCRM
N/A
Level 2
Level 3
Supplemental C-SCRM Guidance:
Physical access control should include individuals and enterprises engaged in the enterprise’s supply chain. A vetting process should be in place based on enterprise-defined requirements and policy prior to granting access to the supply chain infrastructure and any relevant elements. Access establishment, maintenance, and revocation processes should meet enterprise access control policy rigor. The speed of revocation for suppliers, developers, system integrators, external system service providers, and other ICT/OT-related service providers needing access to physical facilities and data centers, either enterprise-owned or external service provider-owned, should be managed in accordance with the activities performed in their contracts. Prompt revocation is critical when either individual or enterprise need no longer exists.
Part a
a. Enforce physical access authorizations at [All entry and exit points to the building(s), server rooms and data center (including emergency exits and fire exits] by:

1. Verifying individual access authorizations before granting access to the facility; and

2. Controlling ingress and egress to the facility using [Physical access control systems/devices and guards];

System-Specific

Common or Hybrid

Part b
b. Maintain physical access audit logs for [Including but not limited to: Pedestrian entrances, visitor screening, shipping, and receiving areas, utility spaces, data center or server room entrance];

System-Specific

Common or Hybrid

Part c
c. Control access to areas within the facility designated as publicly accessible by implementing the following controls: [Guards, man traps, personal recognition, logbooks, access badges, escorts, card access systems, biometrics, video surveillance systems, intrusion detection systems, doors, and locks];

System-Specific

Common or Hybrid

Part d
d. Escort visitors and control visitor activity [Continuously];

System-Specific

Common or Hybrid

Part e
e. Secure keys, combinations, and other physical access devices;

System-Specific

Common or Hybrid

Part f
f. Inventory [Including but not limited to: Logbooks, access badges or cards, video surveillance recordings and keys] every [Minimum 30 Days]; and

System-Specific

Common or Hybrid

Part g
g. Change combinations and keys [At least annually] and/or when keys are lost, combinations are compromised, or when individuals possessing the keys or combinations are transferred or terminated.

System-Specific

Common or Hybrid

PE-6 Monitoring Physical Access

PHYSICAL AND ENVIRONMENTAL PROTECTION (PE)

PE-6 MONITORING PHYSICAL ACCESS

IMPLEMENTATION STATUS
CONTROL ORIGINATION
Choose an item.Choose an item.
NIST SP 800-53 CONTROL BASELINE ALLOCATION:
N/A
Low
Moderate
High
NIST SP 800-161 CONTROL BASELINE ALLOCATION:
C-SCRM
Level 1
Level 2
Level 3
Supplemental C-SCRM Guidance:
Individuals physically accessing the enterprise or external service provider’s facilities, data centers, information, or physical asset(s), including via the supply chain, may be employed by the enterprise’s employees, on-site or remotely located contractors, visitors, other third parties (e.g., maintenance personnel under contract with the contractor enterprise), or an individual affiliated with an enterprise in the upstream supply chain. The enterprise should monitor these individuals’ activities to reduce associated cybersecurity risk in the supply chain or require monitoring in agreements.
Part a
a. Monitor physical access to the facility where the system resides to detect and respond to physical security incidents;

System-Specific

Common or Hybrid

Part b
b. Review physical access logs [daily] and upon occurrence of [physical, human and/or environmental security incident or disaster]; and

System-Specific

Common or Hybrid

Part c
c. Coordinate results of reviews and investigations with the organizational incident response capability.

System-Specific

Common or Hybrid

FAMILY: PLANNING (PL)

PL-8 Security and Privacy Architectures

PLANNING (PL)

PL-8 SECURITY AND PRIVACY ARCHITECTURES

IMPLEMENTATION STATUS
CONTROL ORIGINATION
Choose an item.Choose an item.
NIST SP 800-53 CONTROL BASELINE ALLOCATION:
Privacy
N/A
Moderate
High
NIST SP 800-161 CONTROL BASELINE ALLOCATION:
N/A
N/A
Level 2
Level 3
Supplemental C-SCRM Guidance:
Security and privacy architecture defines and directs implementation of security and privacy-protection methods, mechanisms, and capabilities to the underlying systems and networks, as well as the information system that is being created. Security architecture is fundamental to C-SCRM because it helps to ensure security is built-in throughout the SDLC. Enterprises should consider implementing zero trust architectures and should ensure that the security architecture is well understood by system developers/engineers and system security engineers. This control applies to both federal agency and non-federal agency employees.
Part a
a. Develop security and privacy architectures for the system that:

1. Describe the requirements and approach to be taken for protecting the confidentiality, integrity, and availability of organizational information;

2. Describe the requirements and approach to be taken for processing personally identifiable information to minimize privacy risk to individuals;

3. Describe how the architectures are integrated into and support the enterprise architecture; and

4. Describe any assumptions about, and dependencies on, external systems and services;

System-Specific

Common or Hybrid

Part b
b. Review and update the architectures [at least annually] to reflect changes in the enterprise architecture; and

System-Specific

Common or Hybrid

Part c
c. Reflect planned architecture changes in security and privacy plans, Concept of Operations (CONOPS), criticality analysis, organizational procedures, and procurements and acquisitions.

System-Specific

Common or Hybrid

FAMILY: PROGRAM MANAGEMENT (PM)

PM-31 Continuous Monitoring Strategy

PROGRAM MANAGEMENT (PM)

PM-31 CONTINUOUS MONITORING STRATEGY

IMPLEMENTATION STATUS
CONTROL ORIGINATION
Choose an item.Choose an item.
NIST SP 800-53 CONTROL BASELINE ALLOCATION:
Privacy
N/A
N/A
N/A
NIST SP 800-161 CONTROL BASELINE ALLOCATION:
N/A
Level 1
Level 2
Level 3
Supplemental C-SCRM Guidance:
The continuous monitoring strategy and program should integrate C-SCRM controls at Levels 1, 2, and 3 in accordance with the Supply Chain Risk Management Strategy.
Part a
Develop an organization-wide continuous monitoring strategy and implement continuous monitoring programs that include:

a. Establishing the following organization-wide metrics to be monitored: [align monitoring metrics with organizational risk tolerance as defined in the continuous monitoring strategy and/or risk management strategy];

System-Specific

Common or Hybrid

Part b
b. Establishing [continuous/ongoing] for monitoring and [annually] for assessment of control effectiveness;

System-Specific

Common or Hybrid

Part c
c. Ongoing monitoring of organizationally defined metrics in accordance with the continuous monitoring strategy;

System-Specific

Common or Hybrid

Part d
d. Correlation and analysis of information generated by control assessments and monitoring;

System-Specific

Common or Hybrid

Part e
e. Response actions to address results of the analysis of control assessment and monitoring information; and

System-Specific

Common or Hybrid

Part f
f. Reporting the security and privacy status of organizational systems to [Organizational and government personnel (as applicable) or (as required) with continuous monitoring responsibilities] [Monthly].

System-Specific

Common or Hybrid

FAMILY: PERSONNEL SECURITY (PS)

PS-3 Personnel Screening

PERSONNEL SECURITY (PS)

PS-3 PERSONNEL SCREENING

IMPLEMENTATION STATUS
CONTROL ORIGINATION
Choose an item.Choose an item.
NIST SP 800-53 CONTROL BASELINE ALLOCATION:
N/A
Low
Moderate
High
NIST SP 800-161 CONTROL BASELINE ALLOCATION:
C-SCRM
N/A
Level 2
Level 3
Supplemental C-SCRM Guidance:
To mitigate insider threat risks, personnel screening policies and procedures should be extended to any contractor personnel with authorized access to information systems, system components, or information system services. Continuous monitoring activities should be commensurate with the contractor’s level of access to sensitive, classified, or regulated information and should be consistent with broader enterprise policies. Screening requirements should be incorporated into agreements and flow down to sub-tier contractors.
Part a
a. Screen individuals prior to authorizing access to the system; and

System-Specific

Common or Hybrid

Part b
b. Rescreen individuals in accordance with [government contract requirements, and for National security clearances; a reinvestigation is required during the 5th year for Top Secret security clearance, the 10th year for Secret security clearance, and 10th year for Confidential security clearance. For Moderate risk law enforcement and High-risk public trust level, a reinvestigation is required during the 5th year. There is no reinvestigation for other moderate risk positions nor any low-risk positions.].

System-Specific

Common or Hybrid

FAMILY: RISK ASSESSMENT (RA)

RA-3 Risk Assessment

RISK ASSESSMENT (RA)

RA-3 RISK ASSESSMENT

IMPLEMENTATION STATUS
CONTROL ORIGINATION
Choose an item.Choose an item.
NIST SP 800-53 CONTROL BASELINE ALLOCATION:
Privacy
Low
Moderate
High
NIST SP 800-161 CONTROL BASELINE ALLOCATION:
C-SCRM
Level 1
Level 2
Level 3
Supplemental C-SCRM Guidance:

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .