J.P-13 A3 C-SCRM Plan Template V.2.docx
DOCX document 477 KB Posted
- Attached to
- Alliant 3 GWAC, Request for Proposal (RFP) Federal contract opportunity
- Solicitation number
- 47QTCB24R0009
- Issued by
- GSA Federal Acquisition Service
About this file
This document is a Cybersecurity Supply Chain Risk Management (C-SCRM) Plan template for the Alliant 3 Governmentwide Acquisition Contract (GWAC) program. The C-SCRM Plan provides an overview of the security requirements and controls for the Alliant 3 system, including details on system description, information type and categorization, operational environment, information exchange, incident response, and roles and responsibilities. Key elements covered include access control, awareness and training, audit and accountability, configuration management, contingency planning, identification and authentication, incident response, maintenance, media protection, physical and environmental protection, planning, program management, personnel security, risk assessment, and supply chain risk management. The C-SCRM Plan is intended to be tailored and implemented by Alliant 3 contractors to address cybersecurity risks in the supply chain. This template is one of the attachments included in the Alliant 3 GWAC Request for Proposals.
View the file
Other files for this federal contract opportunity
Show all 50
Alliant 3 GWAC, Request for Proposal (RFP) has more files on GovTribe.
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
This page is intentionally left blank.
DOCUMENT CHANGE CONTROL
Version Release Date Summary of Changes Section / Pages Affected Author
REVIEW LOG
Date of Review Reviewer Organization
ALLIANT 3 GWAC CONTACT INFORMATION
For more information about the Alliant 3 GWAC, visit the website at: https://www.gsa.gov/technology/technology-purchasing-programs/governmentwide-acquisition-contracts/alliant-3
TABLE OF CONTENTS
| 1. | SYSTEM NAME AND IDENTIFIER | 1 |
| 2. | SYSTEM DESCRIPTION | 1 |
| 3. | SYSTEM INFORMATION TYPE AND CATEGORIZATION | 1 |
| 4. | REVISIONS AND MAINTENANCE | 2 |
| 5. | SYSTEM OPERATIONAL STATUS | 2 |
| 6. | SYSTEM ENVIRONMENT | 2 |
| 6.1. Operational Environment Type | 2 | |
| 6.2. Network Diagrams | 3 | |
| 6.3. System Component Inventory | 3 | |
| 7. | INFORMATION EXCHANGE AND SYSTEM CONNECTIONS | 3 |
| 8. | CONTINGENCIES AND EMERGENCIES (OPTIONAL) | 3 |
| 9. | APPLICABLE LAWS AND REGULATIONS | 4 |
| 10. | ROLES AND RESPONSIBILITES | 4 |
| 11. | C-SCRM CONTROL DETAILS | 6 |
| 11.1. FAMILY: ACCESS CONTROL (AC) | 6 | |
| 11.1.1. AC-2 Account Management | 6 | |
| 11.2. FAMILY: AWARENESS AND TRAINING (AT) | 8 | |
| 11.2.1. AT-3 Role-Based Training | 8 | |
| 11.3. FAMILY: AUDIT AND ACCOUNTABILITY (AU) | 10 | |
| 11.3.1. AU-2 Event Logging | 10 | |
| 11.3.2. AU-6 Audit Record Review, Analysis, and Reporting | 11 | |
| 11.4. FAMILY: ASSESSMENT, AUTHORIZATION, AND MONITORING (CA) | 12 | |
| 11.4.1. CA-5 Plan of Action and Milestones | 12 | |
| 11.5. FAMILY: CONFIGURATION MANAGEMENT (CM) | 13 | |
| 11.5.1. CM-2 Baseline Configuration | 13 | |
| 11.5.2. CM-4 Impact Analyses | 14 | |
| 11.5.3. CM-8 System Component Inventory | 15 | |
| 11.6. FAMILY: CONTINGENCY PLANNING (CP) | 16 | |
| 11.6.1. CP-2 Contingency Plan | 16 | |
| 11.7. FAMILY: IDENTIFICATION AND AUTHENTICATION (IA) | 18 | |
| 11.7.1. IA-2 Identification and Authentication (Organizational Users) | 18 | |
| 11.8. FAMILY: INCIDENT RESPONSE (IR) | 19 | |
| 11.8.1. IR-5 Incident Monitoring | 19 | |
| 11.8.2. IR-8 Incident Response Plan | 19 | |
| 11.9. FAMILY: MAINTENANCE (MA) | 21 | |
| 11.9.1. MA-5 Maintenance Personnel | 21 | |
| 11.10. FAMILY: MEDIA PROTECTION (MP) | 22 | |
| 11.10.1. MP-6 Media Sanitization | 22 | |
| 11.11. FAMILY: PHYSICAL AND ENVIRONMENTAL PROTECTION (PE) | 22 | |
| 11.11.1. PE-3 Physical Access Control | 23 | |
| 11.11.2. PE-6 Monitoring Physical Access | 24 | |
| 11.12. FAMILY: PLANNING (PL) | 25 | |
| 11.12.1. PL-8 Security and Privacy Architectures | 25 | |
| 11.13. FAMILY: PROGRAM MANAGEMENT (PM) | 26 | |
| 11.13.1. PM-31 Continuous Monitoring Strategy | 26 | |
| 11.14. FAMILY: PERSONNEL SECURITY (PS) | 28 | |
| 11.14.1. PS-3 Personnel Screening | 28 | |
| 11.15. FAMILY: RISK ASSESSMENT (RA) | 29 | |
| 11.15.1. RA-3 Risk Assessment | 29 | |
| 11.15.2. RA-7 Risk Response | 30 | |
| 11.16. FAMILY: SYSTEM AND SERVICES ACQUISITION (SA) | 31 | |
| 11.16.1. SA-1 Policy and Procedures | 31 | |
| 11.16.2. SA-2 Allocation of Resources | 33 | |
| 11.16.3. SA-3 System Development Life Cycle | 33 | |
| 11.16.4. SA-4 Acquisition Process | 34 | |
| 11.16.5. SA-5 System Documentation | 36 | |
| 11.16.6. SA-8 Security and Privacy Engineering Principles | 38 | |
| 11.16.7. SA-22 Unsupported System Components | 39 | |
| 11.17. FAMILY: SYSTEM AND COMMUNICATIONS PROTECTION (SC) | 39 | |
| 11.17.1. SC-7 Boundary Protection | 39 | |
| 11.17.2. SC-8 Transmission Confidentiality and Integrity | 41 | |
| 11.18. FAMILY: SYSTEM AND INFORMATION INTEGRITY (SI) | 41 | |
| 11.18.1. SI-3 Malicious Code Protection | 41 | |
| 11.18.2. SI-5 Security Alerts, Advisories, and Directives | 42 | |
| 11.19. FAMILY: SUPPLY CHAIN RISK MANAGEMENT (SR) | 43 | |
| 11.19.1. SR-1 Policy and Procedures | 43 | |
| 11.19.2. SR-4 Provenance | 45 | |
| 11.19.3. SR-5 Acquisition Strategies, Tools, and Methods | 46 | |
| 11.19.4. SR-8 Notification Agreements | 46 | |
| 11.19.5. SR-9 Tamper Resistance and Detection | 46 | |
| 11.19.6. SR-10 Inspection of Systems or Components | 47 | |
| 11.19.7. SR-11 Component Authenticity | 48 | |
| 11.19.8. SR-12 Component Disposal | 49 | |
| APPENDIX A - ACRONYMS | 50 | |
| APPENDIX B - RELATED LAWS AND REGULATIONS | 52 | |
| APPENDIX C - C-SCRM ACTIVITIES AND LIFE CYCLES | 56 | |
| APPENDIX D - ATTACHMENTS | 57 | |
| APPENDIX E - C-SCRM CONTROL IMPLEMENTATION SUMMARY (CIS) | 58 |
LIST OF TABLES
| Table 1 – System Name and Identifier | 1 |
| Table 2 – Offering and Provider Type | 1 |
| Table 3 – System Operational Status | 2 |
| Table 4 – Operational Environment Type | 2 |
| Table 5 – System Interconnections | 3 |
| Table 6 – Contingency and Emergency Contacts | 4 |
| Table 7 – C-SCRM Roles and Responsibilities | 4 |
LIST OF FIGURES
| Figure 1- System Security Categorization | 2 |
| Figure 2- Network Diagram[s] | 3 |
| Figure 3 - Integrated C-SCRM Activities | 56 |
[Contractor Name] [(Acronym)] Alliant 3 GWAC Program Minimum Control Baseline
C-SCRM Plan July 2024 [Version 0.00]
ALLIANT 3 Page i
ALLIANT 3 Page ii
1. SYSTEM NAME AND IDENTIFIER
This Cybersecurity Supply Chain Risk Management (C-SCRM) Plan is intended to communicate the [System Name] [Unique Identifier] commitment to continuously improve and strengthen its cybersecurity supply chain security posture and its strategy for addressing cyber supply chain risk.
This C-SCRM Plan provides an overview of the security requirements for [Unique Identifier] and describes the controls in place or planned for meeting those requirements.
The security safeguards implemented for [Unique Identifier] meet the requirements set forth in the enterprise’s C-SCRM strategy and policy guidance and are appropriate for the information to be securely transmitted, processed, or stored by the system.
Table 1 – System Name and Identifier
| System Name |
| [System Name] |
| Unique Identifier |
| [Unique Identifier] |
The C-SCRM control implementations described in this C-SCRM Plan are tailored for and applicable to the following offer and provider type:
Table 2 – Offering and Provider Type
| Offering Type |
| Choose an item. |
| Provider Type |
| Choose an item. |
1. SYSTEM DESCRIPTION
[Provide System Description]
SYSTEM INFORMATION TYPE AND CATEGORIZATION
The following table identifies the information types and impact levels that are processed, stored, or transmitted by the system and/or its in-boundary supply chain. The security impact levels for confidentiality, integrity, and availability for each of the information types are expressed as low, moderate, or high. The security impact levels are based on the potential impact definitions for each of the security objectives (i.e., confidentiality, integrity, and availability) discussed in NIST SP 800-60 Vol. 2, Rev. 1, Appendices to Guide for Mapping Types of Information and Information Systems to Security Categories; and Federal Information Processing Standards (FIPS) 199, Standards for Security Categorization of Federal Information and Information Systems.
Figure 1- System Security Categorization
REVISIONS AND MAINTENANCE
This C-SCRM Plan is reviewed and updated at least annually by the [Define personnel or group responsible]. To view the latest updates and reviews, refer to the Document Change Control and Review Log sections above.
SYSTEM OPERATIONAL STATUS
The system is currently in the operational status noted in the following table.
Table 3 – System Operational Status
| Status One |
| Choose an item. |
| Status Two (Optional) |
| Choose an item. |
Explanation
SYSTEM ENVIRONMENT
Operational Environment Type The system is currently in the operational environment noted in the following table.
Table 4 – Operational Environment Type
| Type |
| Choose an item. |
Custom\Other Explanation
Network Diagrams The following architectural diagram provides a visual depiction of the major hardware components of the [Unique Identifier].
Figure 2- Network Diagram[s] Instructions: Insert network diagram(s) here.
System Component Inventory The following spreadsheet identifies hardware, software, and firmware components of [Unique Identifier].
System Component Inventory
INFORMATION EXCHANGE AND SYSTEM CONNECTIONS
All interconnections between [Unique Identifier] and external entities including off-site contractors or Federal agency/departments are listed in Table 5.
Table 5 – System Interconnections
| Agreement Date |
| Agreement Type |
| Name of System |
| Enterprise or Organization Name |
| Type of Connection or Information Exchange |
| FIPS 199 Categorization |
| Authorization Status |
| Authorization Official Name and Title |
Click or tap to enter a date. Choose an item.
Choose an item. Choose an item.
Click or tap to enter a date. Choose an item.
Choose an item. Choose an item.
Click or tap to enter a date. Choose an item.
Choose an item. Choose an item.
CONTINGENCIES AND EMERGENCIES (OPTIONAL)
In the event of an emergency where equipment is urgently needed, the C-SCRM Project Management Office (PMO) will offer its assistance through C-SCRM Subject Matter Experts (SMEs) to provide help in the absence of the formal tasking and chain of command approval. The Chief Information Officer (CIO) has the authority to provide such waivers to bypass normal procedures. The current contact information for C-SCRM SMEs is provided below:
Table 6 – Contingency and Emergency Contacts
| Point of Contact (POC) |
| Name |
| E-mail Address |
| Phone Number |
C-SCRM SME POC
Acquisitions SME POC
Legal SME POC
APPLICABLE LAWS AND REGULATIONS
See Appendix B - Related Laws and Regulations
ROLES AND RESPONSIBILITES
Table 7 illustrates roles and responsibilities of various C-SCRM Program stakeholders. The following roles and associated responsibilities are relevant to the activities of this Plan.
Table 7 – C-SCRM Roles and Responsibilities
| Role |
| Responsibilities |
Level 1 Enterprise
| Senior Leadership Team |
| · Endorse the enterprise’s C-SCRM strategic objectives and implementation plan. |
· Provide oversight of C-SCRM implementation and effectiveness
· Communicate C-SCRM direction and decisions for priorities and resourcing needs.
· Determine the enterprise’s risk appetite and risk tolerance.
· Respond to high-risk C-SCRM issue escalations that could impact the enterprise’s risk posture in a timely manner.
| Chief Acquisition Officer (CAO) |
| · Advise and assist the head of agency and other agency officials to ensure that the mission of the agency is achieved through the management of the agency’s acquisition activities. |
· Monitor the performance of acquisition activities and programs
· Establish clear lines of authority, accountability, and responsibility for acquisition decision-making within the agency; manage the direction and implementation of acquisition policy for the agency.
· Establish policies, procedures, and practices that promote full and open competition from responsible sources to fulfill best value requirements considering the nature of the property or service procured.
· Coordinate with mission or business owners, authorizing officials, senior accountable official for risk management, system owners, common control providers, senior agency information security officer, senior agency official for privacy, and risk executive (function) to ensure that security and privacy requirements are defined in organizational procurements and acquisitions.
| [Enter Role] |
| · [Enter Responsibilities] |
| [Enter Role] |
| · [Enter Responsibilities] |
Level 2 Mission/Business Processes
| Mission/Business Owners |
| · Determine mission-level risk appetite and tolerance, ensuring they are in line with enterprise expectations. |
· Define supply chain risk management requirements and implementation of controls that support enterprise objectives.
· Maintain criticality analyses of mission functions and assets
· Perform risk assessments for mission/business-related procurements.
| [Enter Role] |
| · [Enter Responsibilities] |
| [Enter Role] |
| · [Enter Responsibilities] |
| [Enter Role] |
| · [Enter Responsibilities] |
Level 3 Operational
| System Owners |
| · Determine whether an information system meets business, functional, and technical requirements and includes appropriately tailored controls. |
· Develop C-SCRM plans.
· Implement C-SCRM policies and requirements.
· Adhere to constraints provided by Levels 1 and 2.
· Tailor C-SCRM to the context of the individual system and apply it throughout the SDLC.
· Report on C-SCRM to Level 2.
| [Enter Role] |
| · [Enter Responsibilities] |
| [Enter Role] |
| · [Enter Responsibilities] |
| [Enter Role] |
| · [Enter Responsibilities] |
C-SCRM CONTROL DETAILS
Minimum security controls for the [Unique Identifier] environment is contained in the following sections.
FAMILY: ACCESS CONTROL (AC)
AC-2 Account Management
ACCESS CONTROL (AC)
AC-2 ACCOUNT MANAGEMENT
| IMPLEMENTATION STATUS |
| CONTROL ORIGINATION |
| Choose an item. | Choose an item. |
| NIST SP 800-53 CONTROL BASELINE ALLOCATION: | |
| N/A | |
| Low | |
| Moderate | |
| High |
| NIST SP 800-161 CONTROL BASELINE ALLOCATION: |
| C-SCRM |
| N/A |
| Level 2 |
| Level 3 |
| Supplemental C-SCRM Guidance: |
| Use of this control helps establish traceability of actions and actors in the supply chain. This control also helps ensure access authorizations of actors in the supply chain is appropriate on a continuous basis. The enterprise may choose to define a set of roles and associate a level of authorization to ensure proper implementation. Enterprises must ensure that accounts for contractor personnel do not exceed the period of performance of the contract. Privileged accounts should only be established for appropriately vetted contractor personnel. Enterprises should also have processes in place to establish and manage temporary or emergency accounts for contractor personnel that require access to a mission-critical or mission-enabling system during a continuity or emergency event. For example, during a pandemic event, existing contractor personnel who are not able to work due to illness may need to be temporarily backfilled by new contractor staff. Enterprises should require their prime contractors to implement this control and flow down this requirement to relevant sub-tier contractors. |
| Part a |
| a. Define and document the types of accounts allowed and specifically prohibited for use within the system; |
System-Specific
Common or Hybrid
| Part b |
| b. Assign account managers; |
System-Specific
Common or Hybrid
Part c
c. Require [Discretionary Access Control (DAC), Role Based Access Control (RBAC), or Mandatory Access Control (MAC)] for group and role membership;
System-Specific
Common or Hybrid
| Part d |
| d. Specify: |
1. Authorized users of the system;
2. Group and role membership; and
3. Access authorizations (i.e., privileges) and [system specific parameter, requiring organization to define] for each account;
System-Specific
Common or Hybrid
| Part e |
| e. Require approvals by [designated account managers] for requests to create accounts; |
System-Specific
Common or Hybrid
Part f
f. Create, enable, modify, disable, and remove accounts in accordance with [Center for Internet Security (CIS) Benchmark, Security Content Automation Protocol (SCAP) Benchmark, NIST Security Configuration Checklist, Defense Information System Agency (DISA) Security Technical Implementation Guides (STIGs) and/or National Security Agency (NSA) Guides];
System-Specific
Common or Hybrid
| Part g |
| g. Monitor the use of accounts; |
System-Specific
Common or Hybrid
| Part h |
| h. Notify account managers and [organizational and government personnel (as applicable) or (as required) with access control responsibilities] within: |
1. [5 business days] when accounts are no longer required;
2. [5 business days] when users are terminated or transferred; and
3. [5 business days] when system usage or need-to-know changes for an individual;
System-Specific
Common or Hybrid
Part i
i. Authorize access to the system based on:
1. A valid access authorization;
2. Intended system usage; and
3. [System specific parameter, requiring organization to define].
System-Specific
Common or Hybrid
| Part j |
| j. Review accounts for compliance with account management requirements [monthly]; |
System-Specific
Common or Hybrid
| Part k |
| k. Establish and implement a process for changing shared or group account authenticators (if deployed) when individuals are removed from the group; and |
System-Specific
Common or Hybrid
Part l
l. Align account management processes with personnel termination and transfer processes.
System-Specific
Common or Hybrid
FAMILY: AWARENESS AND TRAINING (AT)
AT-3 Role-Based Training
AWARENESS AND TRAINING (AT)
AT-3 ROLE-BASED TRAINING
| IMPLEMENTATION STATUS |
| CONTROL ORIGINATION |
| Choose an item. | Choose an item. |
| NIST SP 800-53 CONTROL BASELINE ALLOCATION: | |
| Privacy | |
| Low | |
| Moderate | |
| High |
| NIST SP 800-161 CONTROL BASELINE ALLOCATION: |
| C-SCRM |
| N/A |
| Level 2 |
| N/A |
| Supplemental C-SCRM Guidance: |
| Addressing cyber-supply chain risks throughout the acquisition process is essential to performing C-SCRM effectively. Personnel who are part of the acquisition workforce require training on what C-SCRM requirements, clauses, and evaluation factors are necessary to include when conducting a procurement and how to incorporate C-SCRM into each acquisition phase. Similar enhanced training requirements should be tailored for personnel responsible for conducting threat assessments. Responding to threats and identified risks require training in counterintelligence awareness and reporting. Enterprises should ensure that developers receive training on secure development practices as well as the use of vulnerability scanning tools. Enterprises should require their prime contractors to implement this control and flow down this requirement to relevant sub-tier contractors. |
| Part a |
| a. Provide role-based security and privacy training to personnel with the following roles and responsibilities: [Personnel who are part of the acquisition workforce or organizational and government personnel (as applicable) or (as required) with C-SCRM responsibilities.]: |
1. Before authorizing access to the system, information, or performing assigned duties, and [annually] thereafter; and
2. 2. When required by system changes;
System-Specific
Common or Hybrid
| Part b |
| b. Update role-based training content [annually] and following [assessment or audit findings, security incidents or breaches, or changes in applicable laws, executive orders, directives, regulations, policies, standards, and guidelines and the analysis of security and privacy trends, significant events, and user feedback]; and |
System-Specific
Common or Hybrid
| Part c |
| c. Incorporate lessons learned from internal or external security incidents or breaches into role-based training. |
System-Specific
Common or Hybrid
FAMILY: AUDIT AND ACCOUNTABILITY (AU)
AU-2 Event Logging
AUDIT AND ACCOUNTABILITY (AU)
AU-2 EVENT LOGGING
| IMPLEMENTATION STATUS |
| CONTROL ORIGINATION |
| Choose an item. | Choose an item. |
| NIST SP 800-53 CONTROL BASELINE ALLOCATION: | |
| Privacy | |
| Low | |
| Moderate | |
| High |
| NIST SP 800-161 CONTROL BASELINE ALLOCATION: |
| C-SCRM |
| Level 1 |
| Level 2 |
| Level 3 |
| Supplemental C-SCRM Guidance: |
| An observable occurrence within the information system or supply chain network should be identified as a supply chain auditable event, based on the enterprise’s SDLC context and requirements. Auditable events may include software/hardware changes, failed attempts to access supply chain information systems, or movement of source code. Information on such events should be captured by appropriate audit mechanisms and should be traceable and verifiable. Information captured may include the type of event, date/time, length, and frequency of occurrence. Among other things, auditing may help detect misuse of the supply chain information systems or network caused by insider threat. Logs are a key resource when identifying operational trends and long-term problems. As such enterprises should incorporate reviewing logs at contract renewal point for vendors to determine whether there is systemic problem. Enterprises should require their prime contractors to implement this control and flow down this requirement to relevant sub-tier contractors. |
| Part a |
| a. Identify the types of events that the system is capable of logging in support of the audit function: [Successful and unsuccessful account logon events, password changes, account management events, object access, policy change, administrative privilege usage, failed accesses to information system resources and applications, tracking, and system events; to include logging of all privileged user activity, authentication checks, authorization checks, data deletions, data access, data changes, and permission changes.]; |
System-Specific
Common or Hybrid
| Part b |
| b. Coordinate the event logging function with other organizational entities requiring audit related information to guide and inform the selection criteria for events to be logged; |
System-Specific
Common or Hybrid
| Part c |
| c. Specify the following event types for logging within the system: [Implement audit configuration requirements as documented in applicable Security Technical Hardening Guides; to include logging of all privileged user activity, authentication checks, authorization checks, data deletions, data access, data changes, and permission changes. The implemented audit configuration settings and deviations (if any) from what is required in Security Hardening Guides must be documented in the C-SCRM Plan. The C-SCRM Plan should include a list of the auditable events, as well as providing in sufficient detail the rationale regarding why this list of events is suitable for security incident analysis. Frequency is continually.]; |
System-Specific
Common or Hybrid
| Part d |
| d. Provide a rationale for why the event types selected for logging are deemed to be adequate to support after-the-fact investigations of incidents; and |
System-Specific
Common or Hybrid
| Part e |
| e. Review and update the event types selected for logging [annually or whenever there is a change in the system’s threat environment]. |
System-Specific
Common or Hybrid
AU-6 Audit Record Review, Analysis, and Reporting
AUDIT AND ACCOUNTABILITY (AU)
AU-6 AUDIT RECORD REVIEW, ANALYSIS, AND REPORTING
| IMPLEMENTATION STATUS |
| CONTROL ORIGINATION |
| Choose an item. | Choose an item. |
| NIST SP 800-53 CONTROL BASELINE ALLOCATION: | |
| N/A | |
| Low | |
| Moderate | |
| High |
| NIST SP 800-161 CONTROL BASELINE ALLOCATION: |
| C-SCRM |
| N/A |
| Level 2 |
| Level 3 |
| Supplemental C-SCRM Guidance: |
| The enterprise should ensure that both supply chain and information security auditable events are appropriately filtered and correlated for analysis and reporting. For example, if new maintenance or a patch upgrade is recognized to have an invalid digital signature, the identification of the patch arrival qualifies as a supply chain auditable event, while an invalid signature is an information security auditable event. The combination of these two events may provide information valuable to C-SCRM. The enterprise should adjust the level of audit record review based on risk changes (e.g., active threat intel, risk profile) on a specific vendor. Contracts should explicitly address how audit findings will be reported and adjudicated. |
| Part a |
| a. Review and analyze system audit records [daily] for indications of [any unusual or inappropriate activity with potential cybersecurity implications] and the potential impact of the inappropriate or unusual activity; |
System-Specific
Common or Hybrid
| Part b |
| b. Report findings to [organizational and government personnel (as applicable) or (as required) with information system audit record generation responsibilities and/or monitoring responsibilities]; and |
System-Specific
Common or Hybrid
| Part c |
| c. Adjust the level of audit record review, analysis, and reporting within the system when there is a change in risk based on law enforcement information, intelligence information, or other credible sources of information. |
System-Specific
Common or Hybrid
FAMILY: ASSESSMENT, AUTHORIZATION, AND MONITORING (CA)
CA-5 Plan of Action and Milestones
ASSESSMENT, AUTHORIZATION, AND MONITORING (CA)
CA-5 PLAN OF ACTION AND MILESTONES
| IMPLEMENTATION STATUS |
| CONTROL ORIGINATION |
| Choose an item. | Choose an item. |
| NIST SP 800-53 CONTROL BASELINE ALLOCATION: | |
| Privacy | |
| Low | |
| Moderate | |
| High |
| NIST SP 800-161 CONTROL BASELINE ALLOCATION: |
| C-SCRM |
| N/A |
| Level 2 |
| Level 3 |
| Supplemental C-SCRM Guidance: |
| For system-level plan of actions and milestones (POA&Ms), enterprises need to ensure that a separate POA&M exists for C-SCRM and includes both information systems and the supply chain. The C-SCRM POA&M should include tasks to be accomplished with a recommendation for completion before or after system authorization; the resources required to accomplish the tasks; milestones established to meet the tasks; and the scheduled completion dates for the milestones and tasks. The enterprise should include in its C-SCRM POA&M relevant weaknesses, the impact of weaknesses on information systems or the supply chain, any remediation to address weaknesses, and any continuous monitoring activities. The C-SCRM POA&M should be included as part of the authorization package. |
| Part a |
| a. Develop a plan of action and milestones for the system to document the planned remediation actions of the organization to correct weaknesses or deficiencies noted during the assessment of the controls and to reduce or eliminate known vulnerabilities in the system; and |
System-Specific
Common or Hybrid
| Part b |
| b. Update existing plan of action and milestones [Living document; continually edited and updated] based on the findings from control assessments, independent audits or reviews, and continuous monitoring activities. |
System-Specific
Common or Hybrid
FAMILY: CONFIGURATION MANAGEMENT (CM)
CM-2 Baseline Configuration
CONFIGURATION MANAGEMENT (CM)
CM-2 BASELINE CONFIGURATION
| IMPLEMENTATION STATUS |
| CONTROL ORIGINATION |
| Choose an item. | Choose an item. |
| NIST SP 800-53 CONTROL BASELINE ALLOCATION: | |
| N/A | |
| Low | |
| Moderate | |
| High |
| NIST SP 800-161 CONTROL BASELINE ALLOCATION: |
| C-SCRM |
| N/A |
| Level 2 |
| Level 3 |
| Supplemental C-SCRM Guidance: |
| Enterprises should establish a baseline configuration of both the information system and the development environment including documenting, formally reviewing, and securing the agreement of stakeholders. The purpose of the baseline is to provide a starting point for tracking the changes to components, code, and/or settings throughout the SDLC. Regular reviews and updates of baseline configurations (i.e., re-baselining) are critical for traceability and provenance. The baseline configuration must take into consideration the enterprise’s operational environment and any relevant supplier, developer, system integrator, external system service provider, and other Information and Communications Technology (ICT)/Operational Technology (OT)-related service providers’ involvement within the organization’s information systems and networks. If the system integrator, for example, uses the existing organization’s infrastructure, appropriate measures should be taken to establish a baseline that reflects an appropriate set of agreed-upon criteria for access and operation. Enterprises should require their prime contractors to implement this control and flow down this requirement to relevant sub-tier contractors. |
| Part a |
| a. Develop, document, and maintain under configuration control, a current baseline configuration of the system; and |
System-Specific
Common or Hybrid
| Part b |
| b. Review and update the baseline configuration of the system: |
1. [At least annually];
2. When required due to [significant change as defined in NIST SP 800-37 Revision 2, Appendix F]; and
3. When system components are installed or upgraded.
System-Specific
Common or Hybrid
CM-4 Impact Analyses
CONFIGURATION MANAGEMENT (CM)
CM-4 IMPACT ANALYSES
| IMPLEMENTATION STATUS |
| CONTROL ORIGINATION |
| Choose an item. | Choose an item. |
| NIST SP 800-53 CONTROL BASELINE ALLOCATION: | |
| Privacy | |
| Low | |
| Moderate | |
| High |
| NIST SP 800-161 CONTROL BASELINE ALLOCATION: |
| C-SCRM |
| N/A |
| N/A |
| Level 3 |
| Supplemental C-SCRM Guidance: |
| Enterprises should take under consideration changes to the information system and underlying or interoperable systems and networks to determine whether the impact of these changes affects existing security controls and warrants additional or different protection to maintain an acceptable level of cybersecurity risk in the supply chain. Ensure that stakeholders, such as system engineers and system security engineers, are included in the impact analysis activities to provide their perspectives for C-SCRM. |
| Control |
| Analyze changes to the system to determine potential security and privacy impacts prior to change implementation. |
System-Specific
Common or Hybrid
CM-8 System Component Inventory
CONFIGURATION MANAGEMENT (CM)
CM-8 SYSTEM COMPONENT INVENTORY
| IMPLEMENTATION STATUS |
| CONTROL ORIGINATION |
| Choose an item. | Choose an item. |
| NIST SP 800-53 CONTROL BASELINE ALLOCATION: | |
| N/A | |
| Low | |
| Moderate | |
| High |
| NIST SP 800-161 CONTROL BASELINE ALLOCATION: |
| C-SCRM |
| N/A |
| Level 2 |
| Level 3 |
| Supplemental C-SCRM Guidance: |
| Enterprises should ensure that critical component assets within the information systems and networks are included in the asset inventory. The inventory must include information for critical component accountability. Inventory information includes, for example, hardware inventory specifications, software license information, software version numbers, component owners, and for networked components or devices, machine names, and network addresses. Inventory specifications may the manufacturer, device type, model, serial number, and physical location. Enterprises should require their prime contractors to implement this control and flow down this requirement to relevant sub-tier contractors. Enterprises should specify the requirements and how information flow is enforced to ensure that only the required information, and not more, is communicated to the various participants in the supply chain. If information is subsetted downstream, there should be information about who created the subset information. Enterprises should consider producing Software Bill of Materials (SBOMs) for applicable and appropriate classes of software including purchased software, open-source software, and in-house software. Refer to NIST SP 800-161 Rev.1 Appendix F for additional guidance on SBOMs. |
| Part a |
| a. Develop and document an inventory of system components that: |
1. Accurately reflects the system;
2. Includes all components within the system;
3. Does not include duplicate accounting of components or components assigned to any other system;
4. Is at the level of granularity deemed necessary for tracking and reporting; and
5. Includes the following information to achieve system component accountability: [Hardware inventory specifications (manufacturer, type, model, serial number, physical location), software installation/license information, information system/component owner, and for networked components/device, the Domain Name System (DNS) name, Internet Protocol (IP) Address, Virtual Local Area Network (VLAN)/Subnet, Logical Location]; and
System-Specific
Common or Hybrid
| Part b |
| b. Review and update the system component inventory [Living document; continually edited and updated]. |
System-Specific
Common or Hybrid
FAMILY: CONTINGENCY PLANNING (CP)
CP-2 Contingency Plan
CONTINGENCY PLANNING (CP)
CP-2 CONTINGENCY PLAN
| IMPLEMENTATION STATUS |
| CONTROL ORIGINATION |
| Choose an item. | Choose an item. |
| NIST SP 800-53 CONTROL BASELINE ALLOCATION: | |
| N/A | |
| Low | |
| Moderate | |
| High |
| NIST SP 800-161 CONTROL BASELINE ALLOCATION: |
| C-SCRM |
| N/A |
| Level 2 |
| Level 3 |
| Supplemental C-SCRM Guidance: |
| Enterprises should define and implement a contingency plan for the supply chain information systems and network to ensure that preparations are in place to mitigate against the loss or degradation of data or operations. Contingencies should be put in place for the supply chain, network, and information systems (especially critical components), and processes to ensure protection against compromise, provide appropriate failover, and timely recovery to an acceptable state of operations. |
| Part a |
| a. Develop a contingency plan for the system that: |
1. Identifies essential mission and business functions and associated contingency requirements;
2. Provides recovery objectives, restoration priorities, and metrics;
3. Addresses contingency roles, responsibilities, assigned individuals with contact information;
4. Addresses maintaining essential mission and business functions despite a system disruption, compromise, or failure;
5. Addresses eventual, full system restoration without deterioration of the controls originally planned and implemented;
6. Addresses the sharing of contingency information; and
7. Is reviewed and approved by [System Owner (SO)];
System-Specific
Common or Hybrid
| Part b |
| b. Distribute copies of the contingency plan to [Organizational and government personnel (as applicable) or (as required) with contingency planning responsibilities]; |
System-Specific
Common or Hybrid
| Part c |
| c. Coordinate contingency planning activities with incident handling activities; |
System-Specific
Common or Hybrid
| Part d |
| d. Review the contingency plan for the system [at least annually]; |
System-Specific
Common or Hybrid
| Part e |
| e. Update the contingency plan to address changes to the organization, system, or environment of operation and problems encountered during contingency plan implementation, execution, or testing; |
System-Specific
Common or Hybrid
| Part f |
| f. Communicate contingency plan changes to [Authorizing Official (AO), Information System Security Manager (ISSM), System Security and Privacy Officer (SSPO), Program Manager (PM), Senior Agency Information Security Officer (SAISO), and Emergency Response Coordinator (ERC)]; |
System-Specific
Common or Hybrid
| Part g |
| g. Incorporate lessons learned from contingency plan testing, training, or actual contingency activities into contingency testing and training; and |
System-Specific
Common or Hybrid
| Part h |
| h. Protect the contingency plan from unauthorized disclosure and modification. |
System-Specific
Common or Hybrid
FAMILY: IDENTIFICATION AND AUTHENTICATION (IA)
IA-2 Identification and Authentication (Organizational Users)
IDENTIFICATION AND AUTHENTICATION (IA)
IA-2 IDENTIFICATION AND AUTHENTICATION (ORGANIZATIONAL USERS)
| IMPLEMENTATION STATUS |
| CONTROL ORIGINATION |
| Choose an item. | Choose an item. |
| NIST SP 800-53 CONTROL BASELINE ALLOCATION: | |
| N/A | |
| Low | |
| Moderate | |
| High |
| NIST SP 800-161 CONTROL BASELINE ALLOCATION: |
| C-SCRM |
| Level 1 |
| Level 2 |
| Level 3 |
| Supplemental C-SCRM Guidance: |
| Enterprises should ensure that identification and requirements are defined and applied for enterprise users accessing an ICT/OT system or supply chain network. An enterprise user may include employees, individuals deemed to have the equivalent status of employees (e.g., contractors, guest researchers, etc.), and system integrators fulfilling contractor roles. Criteria such as “duration in role” can aid in defining which identification and authentication mechanisms are used. The enterprise may choose to define a set of roles and associate a level of authorization to ensure proper implementation. Enterprises should require their prime contractors to implement this control and flow down this requirement to relevant sub-tier contractors. |
| Control |
| Uniquely identify and authenticate organizational users and associate that unique identification with processes acting on behalf of those users. |
System-Specific
Common or Hybrid
FAMILY: INCIDENT RESPONSE (IR)
IR-5 Incident Monitoring
INCIDENT RESPONSE (IR)
IR-5 INCIDENT MONITORING
| IMPLEMENTATION STATUS |
| CONTROL ORIGINATION |
| Choose an item. | Choose an item. |
| NIST SP 800-53 CONTROL BASELINE ALLOCATION: | |
| Privacy | |
| Low | |
| Moderate | |
| High |
| NIST SP 800-161 CONTROL BASELINE ALLOCATION: |
| C-SCRM |
| N/A |
| Level 2 |
| Level 3 |
| Supplemental C-SCRM Guidance: |
| Enterprises should ensure agreements with suppliers include requirements to track and document incidents, response decisions, and activities. |
| Control |
| Track and document incidents. |
System-Specific
Common or Hybrid
IR-8 Incident Response Plan
INCIDENT RESPONSE (IR)
IR-8 INCIDENT RESPONSE PLAN
| IMPLEMENTATION STATUS |
| CONTROL ORIGINATION |
| Choose an item. | Choose an item. |
| NIST SP 800-53 CONTROL BASELINE ALLOCATION: | |
| Privacy | |
| Low | |
| Moderate | |
| High |
| NIST SP 800-161 CONTROL BASELINE ALLOCATION: |
| C-SCRM |
| N/A |
| Level 2 |
| Level 3 |
| Supplemental C-SCRM Guidance: |
| Enterprises should coordinate, develop, and implement an incident response plan that includes information sharing responsibilities with critical suppliers and, in a federal context, interagency partners and the Federal Acquisition Security Council (FASC). Enterprises should require their prime contractors to implement this control and flow down this requirement to relevant sub-tier contractors. |
| Part a |
| a. Develop an incident response plan that: |
1. Provides the organization with a roadmap for implementing its incident response capability;
2. Describes the structure and organization of the incident response capability;
3. Provides a high-level approach for how the incident response capability fits into the overall organization;
4. Meets the unique requirements of the organization, which relate to mission, size, structure, and functions;
5. Defines reportable incidents;
6. Provides metrics for measuring the incident response capability within the organization;
7. Defines the resources and management support needed to effectively maintain and mature an incident response capability;
8. Addresses the sharing of incident information;
9. Is reviewed and approved by [Organizational and government personnel (as applicable) or (as required) with incident response responsibilities] [at least annually]; and
10. Explicitly designates responsibility for incident response to [incident manager, with one or more designated alternates].
System-Specific
Common or Hybrid
| Part b |
| b. Distribute copies of the incident response plan to [Organizational and government personnel (as applicable) or (as required) with incident response responsibilities and organizational elements]; |
System-Specific
Common or Hybrid
| Part c |
| c. Update the incident response plan to address system and organizational changes or problems encountered during plan implementation, execution, or testing; |
System-Specific
Common or Hybrid
| Part d |
| d. Communicate incident response plan changes to [Organizational and government personnel (as applicable) or (as required) with incident response responsibilities]; and |
System-Specific
Common or Hybrid
| Part e |
| e. Protect the incident response plan from unauthorized disclosure and modification. |
System-Specific
Common or Hybrid
FAMILY: MAINTENANCE (MA)
MA-5 Maintenance Personnel
MAINTENANCE (MA)
MA-5 MAINTENANCE PERSONNEL
| IMPLEMENTATION STATUS |
| CONTROL ORIGINATION |
| Choose an item. | Choose an item. |
| NIST SP 800-53 CONTROL BASELINE ALLOCATION: | |
| N/A | |
| Low | |
| Moderate | |
| High |
| NIST SP 800-161 CONTROL BASELINE ALLOCATION: |
| C-SCRM |
| N/A |
| Level 2 |
| Level 3 |
| Supplemental C-SCRM Guidance: |
| Maintenance personnel may be employed by suppliers, developers, system integrators, external system service providers, or other ICT/OT-related service providers. As such, appropriate protections should be in place to manage associated risks. The same controls applied to internal maintenance personnel should be applied to any contractor personnel performing a similar maintenance role and enforced through contractual agreements with their external service providers. |
| Part a |
| a. Establish a process for maintenance personnel authorization and maintain a list of authorized maintenance organizations or personnel; |
System-Specific
Common or Hybrid
| Part b |
| b. Verify that non-escorted personnel performing maintenance on the system possess the required access authorizations; and |
System-Specific
Common or Hybrid
| Part c |
| c. Designate organizational personnel with required access authorizations and technical competence to supervise the maintenance activities of personnel who do not possess the required access authorizations. |
System-Specific
Common or Hybrid
FAMILY: MEDIA PROTECTION (MP)
MP-6 Media Sanitization
MEDIA PROTECTION (MP)
MP-6 MEDIA SANITIZATION
| IMPLEMENTATION STATUS |
| CONTROL ORIGINATION |
| Choose an item. | Choose an item. |
| NIST SP 800-53 CONTROL BASELINE ALLOCATION: | |
| Privacy | |
| Low | |
| Moderate | |
| High |
| NIST SP 800-161 CONTROL BASELINE ALLOCATION: |
| C-SCRM |
| N/A |
| Level 2 |
| Level 3 |
| Supplemental C-SCRM Guidance: |
| Enterprises should specify and include in agreements (e.g., contracting language) media sanitization policies for their suppliers, developers, system integrators, external system service providers, and other ICT/OT-related service providers. Media is used throughout the SDLC. Media traversing or residing in the supply chain may originate anywhere, including from suppliers, developers, system integrators, external system service providers, and other ICT/OT-related service providers. It can be new, refurbished, or reused. Media sanitization is critical to ensure that information is removed before the media is used, reused, or discarded. For media containing privacy or other sensitive information (e.g., Control Unclassified Information [CUI]), the enterprise should require its prime contractors to implement this control and flow down this requirement to relevant sub-tier contractors. |
| Part a |
| a. Sanitize [All information system media (digital and non-digital)] prior to disposal, release out of organizational control, or release for reuse using [All information technology resources must be sanitized before being re-purposed, removed, donated, sold, or disposed of outside its security domain according to NIST SP 800-88 and/or Department of Defense (DoD) 5200.1-R]; and |
System-Specific
Common or Hybrid
| Part b |
| b. Employ sanitization mechanisms with the strength and integrity commensurate with the security category or classification of the information. |
System-Specific
Common or Hybrid
FAMILY: PHYSICAL AND ENVIRONMENTAL PROTECTION (PE)
PE-3 Physical Access Control
PHYSICAL AND ENVIRONMENTAL PROTECTION (PE)
PE-3 PHYSICAL ACCESS CONTROL
| IMPLEMENTATION STATUS |
| CONTROL ORIGINATION |
| Choose an item. | Choose an item. |
| NIST SP 800-53 CONTROL BASELINE ALLOCATION: | |
| N/A | |
| Low | |
| Moderate | |
| High |
| NIST SP 800-161 CONTROL BASELINE ALLOCATION: |
| C-SCRM |
| N/A |
| Level 2 |
| Level 3 |
| Supplemental C-SCRM Guidance: |
| Physical access control should include individuals and enterprises engaged in the enterprise’s supply chain. A vetting process should be in place based on enterprise-defined requirements and policy prior to granting access to the supply chain infrastructure and any relevant elements. Access establishment, maintenance, and revocation processes should meet enterprise access control policy rigor. The speed of revocation for suppliers, developers, system integrators, external system service providers, and other ICT/OT-related service providers needing access to physical facilities and data centers, either enterprise-owned or external service provider-owned, should be managed in accordance with the activities performed in their contracts. Prompt revocation is critical when either individual or enterprise need no longer exists. |
| Part a |
| a. Enforce physical access authorizations at [All entry and exit points to the building(s), server rooms and data center (including emergency exits and fire exits] by: |
1. Verifying individual access authorizations before granting access to the facility; and
2. Controlling ingress and egress to the facility using [Physical access control systems/devices and guards];
System-Specific
Common or Hybrid
| Part b |
| b. Maintain physical access audit logs for [Including but not limited to: Pedestrian entrances, visitor screening, shipping, and receiving areas, utility spaces, data center or server room entrance]; |
System-Specific
Common or Hybrid
| Part c |
| c. Control access to areas within the facility designated as publicly accessible by implementing the following controls: [Guards, man traps, personal recognition, logbooks, access badges, escorts, card access systems, biometrics, video surveillance systems, intrusion detection systems, doors, and locks]; |
System-Specific
Common or Hybrid
| Part d |
| d. Escort visitors and control visitor activity [Continuously]; |
System-Specific
Common or Hybrid
| Part e |
| e. Secure keys, combinations, and other physical access devices; |
System-Specific
Common or Hybrid
| Part f |
| f. Inventory [Including but not limited to: Logbooks, access badges or cards, video surveillance recordings and keys] every [Minimum 30 Days]; and |
System-Specific
Common or Hybrid
| Part g |
| g. Change combinations and keys [At least annually] and/or when keys are lost, combinations are compromised, or when individuals possessing the keys or combinations are transferred or terminated. |
System-Specific
Common or Hybrid
PE-6 Monitoring Physical Access
PHYSICAL AND ENVIRONMENTAL PROTECTION (PE)
PE-6 MONITORING PHYSICAL ACCESS
| IMPLEMENTATION STATUS |
| CONTROL ORIGINATION |
| Choose an item. | Choose an item. |
| NIST SP 800-53 CONTROL BASELINE ALLOCATION: | |
| N/A | |
| Low | |
| Moderate | |
| High |
| NIST SP 800-161 CONTROL BASELINE ALLOCATION: |
| C-SCRM |
| Level 1 |
| Level 2 |
| Level 3 |
| Supplemental C-SCRM Guidance: |
| Individuals physically accessing the enterprise or external service provider’s facilities, data centers, information, or physical asset(s), including via the supply chain, may be employed by the enterprise’s employees, on-site or remotely located contractors, visitors, other third parties (e.g., maintenance personnel under contract with the contractor enterprise), or an individual affiliated with an enterprise in the upstream supply chain. The enterprise should monitor these individuals’ activities to reduce associated cybersecurity risk in the supply chain or require monitoring in agreements. |
| Part a |
| a. Monitor physical access to the facility where the system resides to detect and respond to physical security incidents; |
System-Specific
Common or Hybrid
| Part b |
| b. Review physical access logs [daily] and upon occurrence of [physical, human and/or environmental security incident or disaster]; and |
System-Specific
Common or Hybrid
| Part c |
| c. Coordinate results of reviews and investigations with the organizational incident response capability. |
System-Specific
Common or Hybrid
FAMILY: PLANNING (PL)
PL-8 Security and Privacy Architectures
PLANNING (PL)
PL-8 SECURITY AND PRIVACY ARCHITECTURES
| IMPLEMENTATION STATUS |
| CONTROL ORIGINATION |
| Choose an item. | Choose an item. |
| NIST SP 800-53 CONTROL BASELINE ALLOCATION: | |
| Privacy | |
| N/A | |
| Moderate | |
| High |
| NIST SP 800-161 CONTROL BASELINE ALLOCATION: |
| N/A |
| N/A |
| Level 2 |
| Level 3 |
| Supplemental C-SCRM Guidance: |
| Security and privacy architecture defines and directs implementation of security and privacy-protection methods, mechanisms, and capabilities to the underlying systems and networks, as well as the information system that is being created. Security architecture is fundamental to C-SCRM because it helps to ensure security is built-in throughout the SDLC. Enterprises should consider implementing zero trust architectures and should ensure that the security architecture is well understood by system developers/engineers and system security engineers. This control applies to both federal agency and non-federal agency employees. |
| Part a |
| a. Develop security and privacy architectures for the system that: |
1. Describe the requirements and approach to be taken for protecting the confidentiality, integrity, and availability of organizational information;
2. Describe the requirements and approach to be taken for processing personally identifiable information to minimize privacy risk to individuals;
3. Describe how the architectures are integrated into and support the enterprise architecture; and
4. Describe any assumptions about, and dependencies on, external systems and services;
System-Specific
Common or Hybrid
| Part b |
| b. Review and update the architectures [at least annually] to reflect changes in the enterprise architecture; and |
System-Specific
Common or Hybrid
| Part c |
| c. Reflect planned architecture changes in security and privacy plans, Concept of Operations (CONOPS), criticality analysis, organizational procedures, and procurements and acquisitions. |
System-Specific
Common or Hybrid
FAMILY: PROGRAM MANAGEMENT (PM)
PM-31 Continuous Monitoring Strategy
PROGRAM MANAGEMENT (PM)
PM-31 CONTINUOUS MONITORING STRATEGY
| IMPLEMENTATION STATUS |
| CONTROL ORIGINATION |
| Choose an item. | Choose an item. |
| NIST SP 800-53 CONTROL BASELINE ALLOCATION: | |
| Privacy | |
| N/A | |
| N/A | |
| N/A |
| NIST SP 800-161 CONTROL BASELINE ALLOCATION: |
| N/A |
| Level 1 |
| Level 2 |
| Level 3 |
| Supplemental C-SCRM Guidance: |
| The continuous monitoring strategy and program should integrate C-SCRM controls at Levels 1, 2, and 3 in accordance with the Supply Chain Risk Management Strategy. |
| Part a |
| Develop an organization-wide continuous monitoring strategy and implement continuous monitoring programs that include: |
a. Establishing the following organization-wide metrics to be monitored: [align monitoring metrics with organizational risk tolerance as defined in the continuous monitoring strategy and/or risk management strategy];
System-Specific
Common or Hybrid
| Part b |
| b. Establishing [continuous/ongoing] for monitoring and [annually] for assessment of control effectiveness; |
System-Specific
Common or Hybrid
| Part c |
| c. Ongoing monitoring of organizationally defined metrics in accordance with the continuous monitoring strategy; |
System-Specific
Common or Hybrid
| Part d |
| d. Correlation and analysis of information generated by control assessments and monitoring; |
System-Specific
Common or Hybrid
| Part e |
| e. Response actions to address results of the analysis of control assessment and monitoring information; and |
System-Specific
Common or Hybrid
| Part f |
| f. Reporting the security and privacy status of organizational systems to [Organizational and government personnel (as applicable) or (as required) with continuous monitoring responsibilities] [Monthly]. |
System-Specific
Common or Hybrid
FAMILY: PERSONNEL SECURITY (PS)
PS-3 Personnel Screening
PERSONNEL SECURITY (PS)
PS-3 PERSONNEL SCREENING
| IMPLEMENTATION STATUS |
| CONTROL ORIGINATION |
| Choose an item. | Choose an item. |
| NIST SP 800-53 CONTROL BASELINE ALLOCATION: | |
| N/A | |
| Low | |
| Moderate | |
| High |
| NIST SP 800-161 CONTROL BASELINE ALLOCATION: |
| C-SCRM |
| N/A |
| Level 2 |
| Level 3 |
| Supplemental C-SCRM Guidance: |
| To mitigate insider threat risks, personnel screening policies and procedures should be extended to any contractor personnel with authorized access to information systems, system components, or information system services. Continuous monitoring activities should be commensurate with the contractor’s level of access to sensitive, classified, or regulated information and should be consistent with broader enterprise policies. Screening requirements should be incorporated into agreements and flow down to sub-tier contractors. |
| Part a |
| a. Screen individuals prior to authorizing access to the system; and |
System-Specific
Common or Hybrid
| Part b |
| b. Rescreen individuals in accordance with [government contract requirements, and for National security clearances; a reinvestigation is required during the 5th year for Top Secret security clearance, the 10th year for Secret security clearance, and 10th year for Confidential security clearance. For Moderate risk law enforcement and High-risk public trust level, a reinvestigation is required during the 5th year. There is no reinvestigation for other moderate risk positions nor any low-risk positions.]. |
System-Specific
Common or Hybrid
FAMILY: RISK ASSESSMENT (RA)
RA-3 Risk Assessment
RISK ASSESSMENT (RA)
RA-3 RISK ASSESSMENT
| IMPLEMENTATION STATUS |
| CONTROL ORIGINATION |
| Choose an item. | Choose an item. |
| NIST SP 800-53 CONTROL BASELINE ALLOCATION: | |
| Privacy | |
| Low | |
| Moderate | |
| High |
| NIST SP 800-161 CONTROL BASELINE ALLOCATION: |
| C-SCRM |
| Level 1 |
| Level 2 |
| Level 3 |
| Supplemental C-SCRM Guidance: |
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .