The file's text, extracted by GovTribe without its formatting.
FOR OFFICIAL USE ONLY
[Insert Vendor Name] CBP Online Applicant Competency Assessment Service
(COACA)
Requirements Traceability Matrix
(RTM)
Prepared for
Department of Homeland Security, U.S. Customs and Border Protection (CBP) 11 June 2020
1. Introduction
The Requirements Traceability Matrix (RTM) relates requirements from requirement source documents to the security certification process. It ensures that all security requirements are identified and investigated. Each row of the matrix identifies a specific requirement and provides the details of how it was tested or analyzed and the results.
The table is arranged to display the system security requirements from the applicable regulation documents, which are listed below:
· NIST 800-53 w/ DHS 4300A Rev 4 - Department of Homeland Security Sensitive Systems Policy Directive 4300A Version 13.1 (with 800-53 Rev 4)
The columns of the RTM are defined as follows:
| Control Ref. |
| Refers to the name (short title) of the source document and the ID or paragraph number of the listed control or requirement. |
Security Req./
Control Short title describing the security control or requirement (and the text of the control/requirement, which may be paraphrased for brevity).
| Security Category |
| Category and class associated with the security control. |
| Control Type |
| Auto populated if the requirement is identified with two security control types: common and system-specific; i.e., a part of the requirement is identified as common type and another part of it is system-specific. |
· Common. Auto populated if the requirement is designated to one or more information systems.
· Hybrid. Auto populated if the requirement is identified with two security control types: common and system-specific; i.e., a part of the requirement is identified as common type and another part of it is system-specific.
· System-Specific. Auto populated if the requirement is assigned to a specific information system.
· Inherited. Auto populated if the requirement is inherited from another system.
· Not Specified. Auto populated if the requirement does not require any security control.
| Planned Imp. |
| Auto populated if the requirement is identified with two security control types: common and system-specific; i.e., a part of the requirement is identified as common type and another part of it is system-specific. |
· Common. Auto populated if the requirement is designated to one or more information systems.
· Hybrid. Auto populated if the requirement is identified with two security control types: common and system-specific; i.e., a part of the requirement is identified as common type and another part of it is system-specific.
· System-Specific. Auto populated if the requirement is assigned to a specific information system.
· Inherited. Auto populated if the requirement is inherited from another system.
· Not Specified. Auto populated if the requirement does not require any security control.
| Actual Imp. |
| Identification whether the control is in place and how it has been implemented, or differences in how the control was implemented compared to what was planned. |
· As Planned. Auto populated if Implemented control status is selected and Planned Implementation column does not read Not Entered.
· Pending Implementation. Auto populated if Planned control status is selected and Planned Implementation column does not read Not Entered.
· Partially Implemented. Auto populated if Partial control status is selected and Planned Implementation column does not read Not Entered.
· Not Entered. Auto populated if the Planned Implementation column reads Not Entered.
· Not Assigned. Auto populated if the Control Type and/or Control Status were not selected.
| Test #(s) |
| The ID number of the specific test procedure(s) that is used to validate the requirement or control. |
· -. The control is not applicable.
| Methods |
| The evaluation method (or methods) used to assess the requirement. |
· I. Interview.
· E. Examine.
· T. Testing.
· -. The control is not applicable.
| Tailored |
| The tailored control that modifies the control set. |
· In. The control was tailored in.
· Out. The control was tailored out.
· - . The control was not affected from tailoring.
| Overlays |
| The controls included or excluded from the controls already in the baseline. |
· In. The control was added in to the controls in the baseline.
· Out. The control was removed from the controls in the baseline.
· - . The control was not affected from overlay(s).
| Result |
| The summarized result for the test procedures that cover the requirement/control. |
· Met - Requirement fully satisfied.
· Not Met - Requirement not satisfied.
· Not Applicable - Requirement not applicable.
| Notes |
| Identifies the factor, and the basis for; any tailoring of controls from the NIST 800-53 w/ DHS 4300A Rev 4 baseline or organizational overlay that was used for the system. |
2. Requirements Traceability Matrix
| Control Ref. |
| Security Req./ |
Control
| Security Category |
| Control |
Type Planned
Imp.
Actual
Imp.
Test
#(s)
| Methods |
| Tailored |
| Result |
| Notes |
| NIST 800-53 w/ DHS 4300A Rev 4 AC-1 |
| Access Control Policy and Procedures |
| Access Control Policy and Procedures (T) |
| System-Specific |
| Not Entered |
| Not Assigned |
| AC-1.1, AC-1.1, AC-1.1, AC-1.2, AC-1.2, AC-1.2 |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 AC-1 (DHS-5.1.1.c) |
| Sharing of Personal Passwords |
| Access Control Policy and Procedures (T) |
| System-Specific |
| Not Entered |
| Not Assigned |
| AC-1(DHS-5.1.1.c), AC-1(DHS-5.1.1.c), AC-1(DHS-5.1.1.c) |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 AC-2 |
| Account Management |
| Account Management (T) |
| System-Specific |
| Not Entered |
| Not Assigned |
| AC-2.1, AC-2.1, AC-2.1 |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 AC-2 (1) |
| Automated System Account Management |
| Account Management (T) |
| System-Specific |
| Not Entered |
| Not Assigned |
| AC-2(1).1, AC-2(1).1, AC-2(1).1 |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 AC-2 (2) |
| Removal Of Temporary / Emergency Accounts |
| Account Management (T) |
| System-Specific |
| Not Entered |
| Not Assigned |
| AC-2(2).1, AC-2(2).1, AC-2(2).1 |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 AC-2 (3) |
| Disable Inactive Accounts |
| Account Management (T) |
| System-Specific |
| Not Entered |
| Not Assigned |
| AC-2(3).1, AC-2(3).1, AC-2(3).1 |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 AC-2 (4) |
| Automated Audit Actions |
| Account Management (T) |
| System-Specific |
| Not Entered |
| Not Assigned |
| AC-2(4).1, AC-2(4).1, AC-2(4).1 |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 AC-3 |
| Access Enforcement |
| Access Enforcement (T) |
| System-Specific |
| Not Entered |
| Not Assigned |
| AC-3.1, AC-3.1, AC-3.1 |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 AC-3 (DHS-5.1.1.d) |
| Use of group passwords |
| Access Enforcement (T) |
| System-Specific |
| Not Entered |
| Not Assigned |
| AC-3(DHS-5.1.1.d), AC-3(DHS-5.1.1.d), AC-3(DHS-5.1.1.d) |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 AC-4 |
| Information Flow Enforcement |
| Information Flow Enforcement (T) |
| System-Specific |
| Not Entered |
| Not Assigned |
| AC-4.1, AC-4.1, AC-4.1 |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 AC-5 |
| Separation of Duties |
| Separation of Duties (T) |
| System-Specific |
| Not Entered |
| Not Assigned |
| AC-5.1, AC-5.1, AC-5.1 |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 AC-6 |
| Least Privilege |
| Least Privilege (T) |
| System-Specific |
| Not Entered |
| Not Assigned |
| AC-6.1, AC-6.1, AC-6.1 |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 AC-6 (1) |
| Authorize Access To Security Functions |
| Least Privilege (T) |
| System-Specific |
| Not Entered |
| Not Assigned |
| AC-6(1).1, AC-6(1).1, AC-6(1).1 |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 AC-6 (2) |
| Non-Privileged Access For Nonsecurity Functions |
| Least Privilege (T) |
| System-Specific |
| Not Entered |
| Not Assigned |
| AC-6(2).1, AC-6(2).1, AC-6(2).1 |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 AC-6 (5) |
| Privileged Accounts |
| Least Privilege (T) |
| System-Specific |
| Not Entered |
| Not Assigned |
| AC-6(5).1, AC-6(5).1, AC-6(5).1 |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 AC-6 (9) |
| Auditing Use Of Privileged Functions |
| Least Privilege (T) |
| System-Specific |
| Not Entered |
| Not Assigned |
| AC-6(9).1, AC-6(9).1, AC-6(9).1 |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 AC-6 (10) |
| Prohibit Non-Privileged Users From Executing Privileged Functions |
| Least Privilege (T) |
| System-Specific |
| Not Entered |
| Not Assigned |
| AC-6(10).1, AC-6(10).1, AC-6(10).1 |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 AC-7 |
| Unsuccessful Logon Attempts |
| Unsuccessful Logon Attempts (T) |
| System-Specific |
| Not Entered |
| Not Assigned |
| AC-7.1, AC-7.1, AC-7.1 |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 AC-8 |
| System Use Notification |
| System Use Notification (T) |
| System-Specific |
| Not Entered |
| Not Assigned |
| AC-8.1, AC-8.1, AC-8.1, AC-8.2, AC-8.2, AC-8.2 |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 AC-8 (DHS-4.8.5.d) |
| Governement Funded Office Equipment |
| System Use Notification (T) |
| System-Specific |
| Not Entered |
| Not Assigned |
| AC-8(DHS-4.8.5.d), AC-8(DHS-4.8.5.d), AC-8(DHS-4.8.5.d) |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 AC-11 |
| Session Lock |
| Session Lock (T) |
| System-Specific |
| Not Entered |
| Not Assigned |
| AC-11.1, AC-11.1, AC-11.1 |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 AC-11 (1) |
| Pattern-Hiding Displays |
| Session Lock (T) |
| System-Specific |
| Not Entered |
| Not Assigned |
| AC-11(1).1, AC-11(1).1, AC-11(1).1 |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 AC-12 |
| Session Termination |
| Session Termination (T) |
| System-Specific |
| Not Entered |
| Not Assigned |
| AC-12.1, AC-12.1, AC-12.1 |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 AC-14 |
| Permitted Actions without Identification or Authentication |
| Permitted Actions without Identification or Authentication (T) |
| System-Specific |
| Not Entered |
| Not Assigned |
| AC-14.1, AC-14.1, AC-14.1 |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 AC-17 |
| Remote Access |
| Remote Access (T) |
| System-Specific |
| Not Entered |
| Not Assigned |
| AC-17.1, AC-17.1, AC-17.1 |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 AC-17 (1) |
| Automated Monitoring / Control |
| Remote Access (T) |
| System-Specific |
| Not Entered |
| Not Assigned |
| AC-17(1).1, AC-17(1).1, AC-17(1).1 |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 AC-17 (2) |
| Protection Of Confidentiality / Integrity Using Encryption |
| Remote Access (T) |
| System-Specific |
| Not Entered |
| Not Assigned |
| AC-17(2).1, AC-17(2).1, AC-17(2).1 |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 AC-17 (3) |
| Managed Access Control Points |
| Remote Access (T) |
| System-Specific |
| Not Entered |
| Not Assigned |
| AC-17(3).1, AC-17(3).1, AC-17(3).1 |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 AC-17 (4) |
| Privileged Commands / Access |
| Remote Access (T) |
| System-Specific |
| Not Entered |
| Not Assigned |
| AC-17(4).1, AC-17(4).1, AC-17(4).1 |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 AC-17 (DHS-5.4.1.b) |
| Remote Access Connection Management |
| Remote Access (T) |
| System-Specific |
| Not Entered |
| Not Assigned |
| AC-17(DHS-5.4.1.b), AC-17(DHS-5.4.1.b), AC-17(DHS-5.4.1.b) |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 AC-17 (DHS-5.4.1.c) |
| Remote Access of PII |
| Remote Access (T) |
| System-Specific |
| Not Entered |
| Not Assigned |
| AC-17(DHS-5.4.1.c), AC-17(DHS-5.4.1.c), AC-17(DHS-5.4.1.c) |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 AC-18 |
| Wireless Access |
| Wireless Access (T) |
| System-Specific |
| Not Entered |
| Not Assigned |
| AC-18.1, AC-18.1, AC-18.1 |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 AC-18 (1) |
| Authentication And Encryption |
| Wireless Access (T) |
| System-Specific |
| Not Entered |
| Not Assigned |
| AC-18(1).1, AC-18(1).1, AC-18(1).1 |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 AC-19 |
| Access Control for Mobile Devices |
| Access Control for Mobile Devices (T) |
| System-Specific |
| Not Entered |
| Not Assigned |
| AC-19.1, AC-19.1, AC-19.1 |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 AC-19 (5) |
| Full Device / Container-Based Encryption |
| Access Control for Mobile Devices (T) |
| System-Specific |
| Not Entered |
| Not Assigned |
| AC-19(5).1, AC-19(5).1, AC-19(5).1 |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 AC-20 |
| Use of External Information Systems |
| Use of External Information Systems (T) |
| System-Specific |
| Not Entered |
| Not Assigned |
| AC-20.1, AC-20.1, AC-20.1 |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 AC-20 (1) |
| Limits On Authorized Use |
| Use of External Information Systems (T) |
| System-Specific |
| Not Entered |
| Not Assigned |
| AC-20(1).1, AC-20(1).1, AC-20(1).1 |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 AC-20 (2) |
| Portable Storage Devices |
| Use of External Information Systems (T) |
| System-Specific |
| Not Entered |
| Not Assigned |
| AC-20(2).1, AC-20(2).1, AC-20(2).1 |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 AC-21 |
| Information Sharing |
| Information Sharing (T) |
| System-Specific |
| Not Entered |
| Not Assigned |
| AC-21.1, AC-21.1, AC-21.1 |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 AC-22 |
| Publicly Accessible Content |
| Publicly Accessible Content (T) |
| System-Specific |
| Not Entered |
| Not Assigned |
| AC-22.1, AC-22.1, AC-22.1 |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 AT-1 |
| Security Awareness and Training Policy and Procedures |
| Security Awareness and Training Policy and Procedures (O) |
| System-Specific |
| Not Entered |
| Not Assigned |
| AT-1.1, AT-1.1, AT-1.1, AT-1.2, AT-1.2, AT-1.2 |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 AT-2 |
| Security Awareness Training |
| Security Awareness Training (O) |
| System-Specific |
| Not Entered |
| Not Assigned |
| AT-2.1, AT-2.1, AT-2.1 |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 AT-2 (2) |
| Insider Threat |
| Security Awareness Training (O) |
| System-Specific |
| Not Entered |
| Not Assigned |
| AT-2(2).1, AT-2(2).1, AT-2(2).1 |
| - |
| - |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 AT-3 |
| Role-Based Security Training |
| Role-Based Security Training (O) |
| System-Specific |
| Not Entered |
| Not Assigned |
| AT-3.1, AT-3.1, AT-3.1 |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 AT-4 |
| Security Training Records |
| Security Training Records (O) |
| System-Specific |
| Not Entered |
| Not Assigned |
| AT-4.1, AT-4.1, AT-4.1 |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 AU-1 |
| Audit and Accountability Policy and Procedures |
| Audit and Accountability Policy and Procedures (T) |
| System-Specific |
| Not Entered |
| Not Assigned |
| AU-1.1, AU-1.1, AU-1.1, AU-1.2, AU-1.2, AU-1.2 |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 AU-2 |
| Audit Events |
| Audit Events (T) |
| System-Specific |
| Not Entered |
| Not Assigned |
| AU-2.1, AU-2.1, AU-2.1 |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 AU-2 (3) |
| Reviews And Updates |
| Audit Events (T) |
| System-Specific |
| Not Entered |
| Not Assigned |
| AU-2(3).1, AU-2(3).1, AU-2(3).1 |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 AU-3 |
| Content of Audit Records |
| Content of Audit Records (T) |
| System-Specific |
| Not Entered |
| Not Assigned |
| AU-3.1, AU-3.1, AU-3.1 |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 AU-3 (1) |
| Additional Audit Information |
| Content of Audit Records (T) |
| System-Specific |
| Not Entered |
| Not Assigned |
| AU-3(1).1, AU-3(1).1, AU-3(1).1 |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 AU-4 |
| Audit Storage Capacity |
| Audit Storage Capacity (T) |
| System-Specific |
| Not Entered |
| Not Assigned |
| AU-4.1, AU-4.1, AU-4.1 |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 AU-5 |
| Response to Audit Processing Failures |
| Response to Audit Processing Failures (T) |
| System-Specific |
| Not Entered |
| Not Assigned |
| AU-5.1, AU-5.1, AU-5.1 |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 AU-6 |
| Audit Review, Analysis, and Reporting |
| Audit Review, Analysis, and Reporting (T) |
| System-Specific |
| Not Entered |
| Not Assigned |
| AU-6.1, AU-6.1, AU-6.1, AU-6.2, AU-6.2, AU-6.2 |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 AU-6 (1) |
| Process Integration |
| Audit Review, Analysis, and Reporting (T) |
| System-Specific |
| Not Entered |
| Not Assigned |
| AU-6(1).1, AU-6(1).1, AU-6(1).1 |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 AU-6 (3) |
| Correlate Audit Repositories |
| Audit Review, Analysis, and Reporting (T) |
| System-Specific |
| Not Entered |
| Not Assigned |
| AU-6(3).1, AU-6(3).1, AU-6(3).1 |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 AU-6 (DHS-5.3.b) |
| Audit Records for Financial Systems and PII |
| Audit Review, Analysis, and Reporting (T) |
| System-Specific |
| Not Entered |
| Not Assigned |
| AU-6(DHS-5.3.b), AU-6(DHS-5.3.b), AU-6(DHS-5.3.b) |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 AU-6 (DHS-5.4.6.f) |
| Mail Server Administration |
| Audit Review, Analysis, and Reporting (T) |
| System-Specific |
| Not Entered |
| Not Assigned |
| AU-6(DHS-5.4.6.f), AU-6(DHS-5.4.6.f), AU-6(DHS-5.4.6.f) |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 AU-7 |
| Audit Reduction and Report Generation |
| Audit Reduction and Report Generation (T) |
| System-Specific |
| Not Entered |
| Not Assigned |
| AU-7.1, AU-7.1, AU-7.1 |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 AU-7 (1) |
| Automatic Processing |
| Audit Reduction and Report Generation (T) |
| System-Specific |
| Not Entered |
| Not Assigned |
| AU-7(1).1, AU-7(1).1, AU-7(1).1 |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 AU-8 |
| Time Stamps |
| Time Stamps (T) |
| System-Specific |
| Not Entered |
| Not Assigned |
| AU-8.1, AU-8.1, AU-8.1 |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 AU-8 (1) |
| Synchronization With Authoritative Time Source |
| Time Stamps (T) |
| System-Specific |
| Not Entered |
| Not Assigned |
| AU-8(1).1, AU-8(1).1, AU-8(1).1 |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 AU-9 |
| Protection of Audit Information |
| Protection of Audit Information (T) |
| System-Specific |
| Not Entered |
| Not Assigned |
| AU-9.1, AU-9.1, AU-9.1 |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 AU-9 (4) |
| Access By Subset Of Privileged Users |
| Protection of Audit Information (T) |
| System-Specific |
| Not Entered |
| Not Assigned |
| AU-9(4).1, AU-9(4).1, AU-9(4).1 |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 AU-11 |
| Audit Record Retention |
| Audit Record Retention (T) |
| System-Specific |
| Not Entered |
| Not Assigned |
| AU-11.1, AU-11.1, AU-11.1 |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 AU-11 (DHS-5.3.d) |
| Audit Log Retention |
| Audit Record Retention (T) |
| System-Specific |
| Not Entered |
| Not Assigned |
| AU-11(DHS-5.3.d), AU-11(DHS-5.3.d), AU-11(DHS-5.3.d) |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 AU-12 |
| Audit Generation |
| Audit Generation (T) |
| System-Specific |
| Not Entered |
| Not Assigned |
| AU-12.1, AU-12.1, AU-12.1 |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 CA-1 |
| Security Assessment and Authorization Policies and Procedures |
| Security Assessment and Authorization Policies and Procedures (M) |
| System-Specific |
| Not Entered |
| Not Assigned |
| CA-1.1, CA-1.1, CA-1.1, CA-1.2, CA-1.2, CA-1.2 |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 CA-1 (DHS-3.9.m) |
| Use of IACS for Security Authorization |
| Security Assessment and Authorization Policies and Procedures (M) |
| System-Specific |
| Not Entered |
| Not Assigned |
| CA-1(DHS-3.9.m), CA-1(DHS-3.9.m), CA-1(DHS-3.9.m) |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 CA-1 (DHS-3.18.c) |
| Cloud Environment Usage |
| Security Assessment and Authorization Policies and Procedures (M) |
| System-Specific |
| Not Entered |
| Not Assigned |
| CA-1(DHS-3.18.c), CA-1(DHS-3.18.c), CA-1(DHS-3.18.c) |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 CA-1 (DHS-3.18.d) |
| Usage of FedRAMP for Cloud Systems |
| Security Assessment and Authorization Policies and Procedures (M) |
| System-Specific |
| Not Entered |
| Not Assigned |
| CA-1(DHS-3.18.d), CA-1(DHS-3.18.d), CA-1(DHS-3.18.d) |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 CA-1 (DHS-3.18.e) |
| Usage of Public Cloud Service Provider |
| Security Assessment and Authorization Policies and Procedures (M) |
| System-Specific |
| Not Entered |
| Not Assigned |
| CA-1(DHS-3.18.e), CA-1(DHS-3.18.e), CA-1(DHS-3.18.e) |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 CA-2 |
| Security Assessments |
| Security Assessments (M) |
| System-Specific |
| Not Entered |
| Not Assigned |
| CA-2.1, CA-2.1, CA-2.1, CA-2.2, CA-2.2, CA-2.2 |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 CA-2 (1) |
| Independent Assessors |
| Security Assessments (M) |
| System-Specific |
| Not Entered |
| Not Assigned |
| CA-2(1).1, CA-2(1).1, CA-2(1).1 |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 CA-2 (DHS-3.18.b) |
| Cloud Systems Provided to External Departments |
| Security Assessments (M) |
| System-Specific |
| Not Entered |
| Not Assigned |
| CA-2(DHS-3.18.b), CA-2(DHS-3.18.b), CA-2(DHS-3.18.b) |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 CA-3 |
| System Interconnections |
| System Interconnections (M) |
| System-Specific |
| Not Entered |
| Not Assigned |
| CA-3.1, CA-3.1, CA-3.1 |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 CA-3 (5) |
| Restrictions On External System Connections |
| System Interconnections (M) |
| System-Specific |
| Not Entered |
| Not Assigned |
| CA-3(5).1, CA-3(5).1, CA-3(5).1 |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 CA-3 (DHS-5.4.3.b) |
| Interconnection Establishment Procedures |
| System Interconnections (M) |
| System-Specific |
| Not Entered |
| Not Assigned |
| CA-3(DHS-5.4.3.b), CA-3(DHS-5.4.3.b), CA-3(DHS-5.4.3.b) |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 CA-3 (DHS-5.4.3.c) |
| DHS OneNet Interconnections |
| System Interconnections (M) |
| System-Specific |
| Not Entered |
| Not Assigned |
| CA-3(DHS-5.4.3.c), CA-3(DHS-5.4.3.c), CA-3(DHS-5.4.3.c) |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 CA-3 (DHS-5.4.3.d) |
| ISA Reissuance |
| System Interconnections (M) |
| System-Specific |
| Not Entered |
| Not Assigned |
| CA-3(DHS-5.4.3.d), CA-3(DHS-5.4.3.d), CA-3(DHS-5.4.3.d) |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 CA-3 (DHS-5.4.3.f) |
| Interconnection Security Agreements |
| System Interconnections (M) |
| System-Specific |
| Not Entered |
| Not Assigned |
| CA-3(DHS-5.4.3.f), CA-3(DHS-5.4.3.f), CA-3(DHS-5.4.3.f) |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 CA-3 (DHS-5.4.3.m) |
| Interconnection Security Agreements |
| System Interconnections (M) |
| System-Specific |
| Not Entered |
| Not Assigned |
| CA-3(DHS-5.4.3.m), CA-3(DHS-5.4.3.m), CA-3(DHS-5.4.3.m) |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 CA-3 (DHS-5.4.3.n) |
| DHS Interconnections |
| System Interconnections (M) |
| System-Specific |
| Not Entered |
| Not Assigned |
| CA-3(DHS-5.4.3.n), CA-3(DHS-5.4.3.n), CA-3(DHS-5.4.3.n) |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 CA-5 |
| Plan of Action and Milestones |
| Plan of Action and Milestones (M) |
| System-Specific |
| Not Entered |
| Not Assigned |
| CA-5.1, CA-5.1, CA-5.1 |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 CA-5 (DHS-2.2.8.d) |
| DHS POA&M Requirements |
| Plan of Action and Milestones (M) |
| System-Specific |
| Not Entered |
| Not Assigned |
| CA-5(DHS-2.2.8.d), CA-5(DHS-2.2.8.d), CA-5(DHS-2.2.8.d) |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 CA-6 |
| Security Authorization |
| Security Authorization (M) |
| System-Specific |
| Not Entered |
| Not Assigned |
| CA-6.1, CA-6.1, CA-6.1 |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 CA-6 (DHS-3.9.h) |
| DHS Security Authorization |
| Security Authorization (M) |
| System-Specific |
| Not Entered |
| Not Assigned |
| CA-6(DHS-3.9.h), CA-6(DHS-3.9.h), CA-6(DHS-3.9.h) |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 CA-7 |
| Continuous Monitoring |
| Continuous Monitoring (M) |
| System-Specific |
| Not Entered |
| Not Assigned |
| CA-7.1, CA-7.1, CA-7.1 |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 CA-7 (1) |
| Independent Assessment |
| Continuous Monitoring (M) |
| System-Specific |
| Not Entered |
| Not Assigned |
| CA-7(1).1, CA-7(1).1, CA-7(1).1 |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 CA-7 (DHS-4.6.3.a) |
| AO Notification on Disabling Security Features |
| Continuous Monitoring (M) |
| System-Specific |
| Not Entered |
| Not Assigned |
| CA-7(DHS-4.6.3.a), CA-7(DHS-4.6.3.a), CA-7(DHS-4.6.3.a) |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 CA-9 |
| Internal System Connections |
| Internal System Connections (M) |
| System-Specific |
| Not Entered |
| Not Assigned |
| CA-9.1, CA-9.1, CA-9.1 |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 CM-1 |
| Configuration Management Policy and Procedures |
| Configuration Management Policy and Procedures (O) |
| System-Specific |
| Not Entered |
| Not Assigned |
| CM-1.1, CM-1.1, CM-1.1, CM-1.2, CM-1.2, CM-1.2 |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 CM-2 |
| Baseline Configuration |
| Baseline Configuration (O) |
| System-Specific |
| Not Entered |
| Not Assigned |
| CM-2.1, CM-2.1, CM-2.1 |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 CM-2 (1) |
| Reviews And Updates |
| Baseline Configuration (O) |
| System-Specific |
| Not Entered |
| Not Assigned |
| CM-2(1).1, CM-2(1).1, CM-2(1).1 |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 CM-2 (3) |
| Retention Of Previous Configurations |
| Baseline Configuration (O) |
| System-Specific |
| Not Entered |
| Not Assigned |
| CM-2(3).1, CM-2(3).1, CM-2(3).1 |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 CM-2 (7) |
| Configure Systems, Components, Or Devices For High-Risk Areas |
| Baseline Configuration (O) |
| System-Specific |
| Not Entered |
| Not Assigned |
| CM-2(7).1, CM-2(7).1, CM-2(7).1 |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 CM-2 (DHS-3.9.b) |
| FIPS 199 and FIPS 200 Usage |
| Baseline Configuration (O) |
| System-Specific |
| Not Entered |
| Not Assigned |
| CM-2(DHS-3.9.b), CM-2(DHS-3.9.b), CM-2(DHS-3.9.b) |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 CM-2 (DHS-4.12.b) |
| Network Printers and Facsimile Machines |
| Baseline Configuration (O) |
| System-Specific |
| Not Entered |
| Not Assigned |
| CM-2(DHS-4.12.b), CM-2(DHS-4.12.b), CM-2(DHS-4.12.b) |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 CM-3 |
| Configuration Change Control |
| Configuration Change Control (O) |
| System-Specific |
| Not Entered |
| Not Assigned |
| CM-3.1, CM-3.1, CM-3.1 |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 CM-3 (2) |
| Test / Validate / Document Changes |
| Configuration Change Control (O) |
| System-Specific |
| Not Entered |
| Not Assigned |
| CM-3(2).1, CM-3(2).1, CM-3(2).1 |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 CM-3 (DHS-2.1.8.g) |
| Timely Response to ICCB |
| Configuration Change Control (O) |
| System-Specific |
| Not Entered |
| Not Assigned |
| CM-3(DHS-2.1.8.g), CM-3(DHS-2.1.8.g), CM-3(DHS-2.1.8.g) |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 CM-3 (DHS-5.4.3.l) |
| DHS Change Control Boards (CCB) |
| Configuration Change Control (O) |
| System-Specific |
| Not Entered |
| Not Assigned |
| CM-3(DHS-5.4.3.l), CM-3(DHS-5.4.3.l), CM-3(DHS-5.4.3.l) |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 CM-4 |
| Security Impact Analysis |
| Security Impact Analysis (O) |
| System-Specific |
| Not Entered |
| Not Assigned |
| CM-4.1, CM-4.1, CM-4.1 |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 CM-5 |
| Access Restrictions for Change |
| Access Restrictions for Change (O) |
| System-Specific |
| Not Entered |
| Not Assigned |
| CM-5.1, CM-5.1, CM-5.1 |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 CM-6 |
| Configuration Settings |
| Configuration Settings (O) |
| System-Specific |
| Not Entered |
| Not Assigned |
| CM-6.1, CM-6.1, CM-6.1 |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 CM-6 (DHS-3.7.e) |
| USGCB Requirements |
| Configuration Settings (O) |
| System-Specific |
| Not Entered |
| Not Assigned |
| CM-6(DHS-3.7.e), CM-6(DHS-3.7.e), CM-6(DHS-3.7.e) |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 CM-6 (DHS-3.7.f) |
| USGCB Compliance |
| Configuration Settings (O) |
| System-Specific |
| Not Entered |
| Not Assigned |
| CM-6(DHS-3.7.f), CM-6(DHS-3.7.f), CM-6(DHS-3.7.f) |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 CM-6 (DHS-3.7.g) |
| Hardening and Configuration Guidance |
| Configuration Settings (O) |
| System-Specific |
| Not Entered |
| Not Assigned |
| CM-6(DHS-3.7.g), CM-6(DHS-3.7.g), CM-6(DHS-3.7.g) |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 CM-6 (DHS-4.5.2.b) |
| FAX Server Configuration |
| Configuration Settings (O) |
| System-Specific |
| Not Entered |
| Not Assigned |
| CM-6(DHS-4.5.2.b), CM-6(DHS-4.5.2.b), CM-6(DHS-4.5.2.b) |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 CM-6 (DHS-4.8.4.a) |
| Hardening and Configuration Guidance |
| Configuration Settings (O) |
| System-Specific |
| Not Entered |
| Not Assigned |
| CM-6(DHS-4.8.4.a), CM-6(DHS-4.8.4.a), CM-6(DHS-4.8.4.a) |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 CM-6 (DHS-4.12.f) |
| Network Printers, Copiers, and Facsimile Administration |
| Configuration Settings (O) |
| System-Specific |
| Not Entered |
| Not Assigned |
| CM-6(DHS-4.12.f), CM-6(DHS-4.12.f), CM-6(DHS-4.12.f) |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 CM-6 (DHS-4.12.j) |
| Multifunction Device Configuration |
| Configuration Settings (O) |
| System-Specific |
| Not Entered |
| Not Assigned |
| CM-6(DHS-4.12.j), CM-6(DHS-4.12.j), CM-6(DHS-4.12.j) |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 CM-6 (DHS-5.4.5.d) |
| Use of Telnet |
| Configuration Settings (O) |
| System-Specific |
| Not Entered |
| Not Assigned |
| CM-6(DHS-5.4.5.d), CM-6(DHS-5.4.5.d), CM-6(DHS-5.4.5.d) |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 CM-6 (DHS-5.4.5.e) |
| Use of File Transfer Protocol (FTP) Services |
| Configuration Settings (O) |
| System-Specific |
| Not Entered |
| Not Assigned |
| CM-6(DHS-5.4.5.e), CM-6(DHS-5.4.5.e), CM-6(DHS-5.4.5.e) |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 CM-7 |
| Least Functionality |
| Least Functionality (O) |
| System-Specific |
| Not Entered |
| Not Assigned |
| CM-7.1, CM-7.1, CM-7.1 |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 CM-7 (1) |
| Periodic Review |
| Least Functionality (O) |
| System-Specific |
| Not Entered |
| Not Assigned |
| CM-7(1).1, CM-7(1).1, CM-7(1).1 |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 CM-7 (2) |
| Prevent Program Execution |
| Least Functionality (O) |
| System-Specific |
| Not Entered |
| Not Assigned |
| CM-7(2).1, CM-7(2).1, CM-7(2).1 |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 CM-7 (4) |
| Unauthorized Software / Blacklisting |
| Least Functionality (O) |
| System-Specific |
| Not Entered |
| Not Assigned |
| CM-7(4).1, CM-7(4).1, CM-7(4).1 |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 CM-7 (DHS-4.8.6.a) |
| Wireless for Peripheral Equipment |
| Least Functionality (O) |
| System-Specific |
| Not Entered |
| Not Assigned |
| CM-7(DHS-4.8.6.a), CM-7(DHS-4.8.6.a), CM-7(DHS-4.8.6.a) |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 CM-7 (DHS-5.4.5.f) |
| Remote Desktop Connections |
| Least Functionality (O) |
| System-Specific |
| Not Entered |
| Not Assigned |
| CM-7(DHS-5.4.5.f), CM-7(DHS-5.4.5.f), CM-7(DHS-5.4.5.f) |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 CM-8 |
| Information System Component Inventory |
| Information System Component Inventory (O) |
| System-Specific |
| Not Entered |
| Not Assigned |
| CM-8.1, CM-8.1, CM-8.1 |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 CM-8 (1) |
| Updates During Installations / Removals |
| Information System Component Inventory (O) |
| System-Specific |
| Not Entered |
| Not Assigned |
| CM-8(1).1, CM-8(1).1, CM-8(1).1 |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 CM-8 (3) |
| Automated Unauthorized Component Detection |
| Information System Component Inventory (O) |
| System-Specific |
| Not Entered |
| Not Assigned |
| CM-8(3).1, CM-8(3).1, CM-8(3).1 |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 CM-8 (5) |
| No Duplicate Accounting Of Components |
| Information System Component Inventory (O) |
| System-Specific |
| Not Entered |
| Not Assigned |
| CM-8(5).1, CM-8(5).1, CM-8(5).1 |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 CM-9 |
| Configuration Management Plan |
| Configuration Management Plan (O) |
| System-Specific |
| Not Entered |
| Not Assigned |
| CM-9.1, CM-9.1, CM-9.1 |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 CM-10 |
| Software Usage Restrictions |
| SW Usage Restrictions (O) |
| System-Specific |
| Not Entered |
| Not Assigned |
| CM-10.1, CM-10.1, CM-10.1 |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 CM-11 |
| User-Installed Software |
| User-Installed SW (O) |
| System-Specific |
| Not Entered |
| Not Assigned |
| CM-11.1, CM-11.1, CM-11.1 |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 CP-1 |
| Contingency Planning Policy and Procedures |
| Contingency Planning Policy and Procedures (O) |
| System-Specific |
| Not Entered |
| Not Assigned |
| CP-1.1, CP-1.1, CP-1.1, CP-1.2, CP-1.2, CP-1.2 |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 CP-1 (DHS-3.5.1.a) |
| Continuity of Operations Planning |
| Contingency Planning Policy and Procedures (O) |
| System-Specific |
| Not Entered |
| Not Assigned |
| CP-1(DHS-3.5.1.a), CP-1(DHS-3.5.1.a), CP-1(DHS-3.5.1.a) |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 CP-1 (DHS-3.5.2.d) |
| DHS Contingency Guidance |
| Contingency Planning Policy and Procedures (O) |
| System-Specific |
| Not Entered |
| Not Assigned |
| CP-1(DHS-3.5.2.d), CP-1(DHS-3.5.2.d), CP-1(DHS-3.5.2.d) |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 CP-1 (DHS-3.15.f) |
| DHS Contingency Plan for CFO |
| Contingency Planning Policy and Procedures (O) |
| System-Specific |
| Not Entered |
| Not Assigned |
| CP-1(DHS-3.15.f), CP-1(DHS-3.15.f), CP-1(DHS-3.15.f) |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 CP-2 |
| Contingency Plan |
| Contingency Plan (O) |
| System-Specific |
| Not Entered |
| Not Assigned |
| CP-2.1, CP-2.1, CP-2.1, CP-2.2, CP-2.2, CP-2.2 |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 CP-2 (1) |
| Coordinate With Related Plans |
| Contingency Plan (O) |
| System-Specific |
| Not Entered |
| Not Assigned |
| CP-2(1).1, CP-2(1).1, CP-2(1).1 |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 CP-2 (3) |
| Resume Essential Missions / Business Functions |
| Contingency Plan (O) |
| System-Specific |
| Not Entered |
| Not Assigned |
| CP-2(3).1, CP-2(3).1, CP-2(3).1 |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 CP-2 (8) |
| Identify Critical Assets |
| Contingency Plan (O) |
| System-Specific |
| Not Entered |
| Not Assigned |
| CP-2(8).1, CP-2(8).1, CP-2(8).1 |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 CP-2 (DHS-3.5.2.e) |
| DHS Contingency Plan |
| Contingency Plan (O) |
| System-Specific |
| Not Entered |
| Not Assigned |
| CP-2(DHS-3.5.2.e), CP-2(DHS-3.5.2.e), CP-2(DHS-3.5.2.e) |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 CP-3 |
| Contingency Training |
| Contingency Training (O) |
| System-Specific |
| Not Entered |
| Not Assigned |
| CP-3.1, CP-3.1, CP-3.1 |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 CP-4 |
| Contingency Plan Testing |
| Contingency Plan Testing (O) |
| System-Specific |
| Not Entered |
| Not Assigned |
| CP-4.1, CP-4.1, CP-4.1 |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 CP-4 (1) |
| Coordinate With Related Plans |
| Contingency Plan Testing (O) |
| System-Specific |
| Not Entered |
| Not Assigned |
| CP-4(1).1, CP-4(1).1, CP-4(1).1 |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 CP-4 (DHS-3.5.2.f) |
| DHS Contingency Plan Testing |
| Contingency Plan Testing (O) |
| System-Specific |
| Not Entered |
| Not Assigned |
| CP-4(DHS-3.5.2.f), CP-4(DHS-3.5.2.f), CP-4(DHS-3.5.2.f) |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 CP-6 |
| Alternate Storage Site |
| Alternate Storage Site (O) |
| System-Specific |
| Not Entered |
| Not Assigned |
| CP-6.1, CP-6.1, CP-6.1 |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 CP-6 (1) |
| Separation From Primary Site |
| Alternate Storage Site (O) |
| System-Specific |
| Not Entered |
| Not Assigned |
| CP-6(1).1, CP-6(1).1, CP-6(1).1 |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 CP-6 (3) |
| Accessibility |
| Alternate Storage Site (O) |
| System-Specific |
| Not Entered |
| Not Assigned |
| CP-6(3).1, CP-6(3).1, CP-6(3).1 |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 CP-7 |
| Alternate Processing Site |
| Alternate Processing Site (O) |
| System-Specific |
| Not Entered |
| Not Assigned |
| CP-7.1, CP-7.1, CP-7.1 |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 CP-7 (1) |
| Separation From Primary Site |
| Alternate Processing Site (O) |
| System-Specific |
| Not Entered |
| Not Assigned |
| CP-7(1).1, CP-7(1).1, CP-7(1).1 |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 CP-7 (2) |
| Accessibility |
| Alternate Processing Site (O) |
| System-Specific |
| Not Entered |
| Not Assigned |
| CP-7(2).1, CP-7(2).1, CP-7(2).1 |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 CP-7 (3) |
| Priority Of Service |
| Alternate Processing Site (O) |
| System-Specific |
| Not Entered |
| Not Assigned |
| CP-7(3).1, CP-7(3).1, CP-7(3).1 |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 CP-8 |
| Telecommunications Services |
| Telecommunications Services (O) |
| System-Specific |
| Not Entered |
| Not Assigned |
| CP-8.1, CP-8.1, CP-8.1 |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 CP-8 (1) |
| Priority Of Service Provisions |
| Telecommunications Services (O) |
| System-Specific |
| Not Entered |
| Not Assigned |
| CP-8(1).1, CP-8(1).1, CP-8(1).1 |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 CP-8 (2) |
| Single Points Of Failure |
| Telecommunications Services (O) |
| System-Specific |
| Not Entered |
| Not Assigned |
| CP-8(2).1, CP-8(2).1, CP-8(2).1 |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 CP-9 |
| Information System Backup |
| Information System Backup (O) |
| System-Specific |
| Not Entered |
| Not Assigned |
| CP-9.1, CP-9.1, CP-9.1, CP-9.2, CP-9.2, CP-9.2 |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 CP-9 (1) |
| Testing For Reliability / Integrity |
| Information System Backup (O) |
| System-Specific |
| Not Entered |
| Not Assigned |
| CP-9(1).1, CP-9(1).1, CP-9(1).1 |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 CP-10 |
| Information System Recovery and Reconstitution |
| Information System Recovery and Reconstitution (O) |
| System-Specific |
| Not Entered |
| Not Assigned |
| CP-10.1, CP-10.1, CP-10.1 |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 CP-10 (2) |
| Transaction Recovery |
| Information System Recovery and Reconstitution (O) |
| System-Specific |
| Not Entered |
| Not Assigned |
| CP-10(2).1, CP-10(2).1, CP-10(2).1 |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 IA-1 |
| Identification and Authentication Policy and Procedures |
| Identification and Authentication Policy and Procedures (T) |
| System-Specific |
| Not Entered |
| Not Assigned |
| IA-1.1, IA-1.1, IA-1.1, IA-1.2, IA-1.2, IA-1.2 |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 IA-1 (DHS-1.6.d) |
| PIV Credentials |
| Identification and Authentication Policy and Procedures (T) |
| System-Specific |
| Not Entered |
| Not Assigned |
| IA-1(DHS-1.6.d), IA-1(DHS-1.6.d), IA-1(DHS-1.6.d) |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 IA-1 (DHS-3.14.7.a) |
| Online Transactions |
| Identification and Authentication Policy and Procedures (T) |
| System-Specific |
| Not Entered |
| Not Assigned |
| IA-1(DHS-3.14.7.a), IA-1(DHS-3.14.7.a), IA-1(DHS-3.14.7.a) |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 IA-1 (DHS-3.14.7.c) |
| E-Authentication |
| Identification and Authentication Policy and Procedures (T) |
| System-Specific |
| Not Entered |
| Not Assigned |
| IA-1(DHS-3.14.7.c), IA-1(DHS-3.14.7.c), IA-1(DHS-3.14.7.c) |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 IA-1 (DHS-3.14.7.f) |
| PIV Credentials |
| Identification and Authentication Policy and Procedures (T) |
| System-Specific |
| Not Entered |
| Not Assigned |
| IA-1(DHS-3.14.7.f), IA-1(DHS-3.14.7.f), IA-1(DHS-3.14.7.f) |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 IA-2 |
| Identification and Authentication (Organizational Users) |
| Identification and Authentication (Organizational Users) (T) |
| System-Specific |
| Not Entered |
| Not Assigned |
| IA-2.1, IA-2.1, IA-2.1 |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 IA-2 (1) |
| Network Access To Privileged Accounts |
| Identification and Authentication (Organizational Users) (T) |
| System-Specific |
| Not Entered |
| Not Assigned |
| IA-2(1).1, IA-2(1).1, IA-2(1).1 |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 IA-2 (2) |
| Network Access To Non-Privileged Accounts |
| Identification and Authentication (Organizational Users) (T) |
| System-Specific |
| Not Entered |
| Not Assigned |
| IA-2(2).1, IA-2(2).1, IA-2(2).1 |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 IA-2 (3) |
| Local Access To Privileged Accounts |
| Identification and Authentication (Organizational Users) (T) |
| System-Specific |
| Not Entered |
| Not Assigned |
| IA-2(3).1, IA-2(3).1, IA-2(3).1 |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 IA-2 (8) |
| Network Access To Privileged Accounts - Replay Resistant |
| Identification and Authentication (Organizational Users) (T) |
| System-Specific |
| Not Entered |
| Not Assigned |
| IA-2(8).1, IA-2(8).1, IA-2(8).1 |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 IA-2 (11) |
| Remote Access - Separate Device |
| Identification and Authentication (Organizational Users) (T) |
| System-Specific |
| Not Entered |
| Not Assigned |
| IA-2(11).1, IA-2(11).1, IA-2(11).1 |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 IA-2 (12) |
| Acceptance Of PIV Credentials |
| Identification and Authentication (Organizational Users) (T) |
| System-Specific |
| Not Entered |
| Not Assigned |
| IA-2(12).1, IA-2(12).1, IA-2(12).1 |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 IA-2 (DHS-5.1.d) |
| Usage of Identification or Authentication Materials |
| Identification and Authentication (Organizational Users) (T) |
| System-Specific |
| Not Entered |
| Not Assigned |
| IA-2(DHS-5.1.d), IA-2(DHS-5.1.d), IA-2(DHS-5.1.d) |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 IA-3 |
| Device Identification and Authentication |
| Device Identification and Authentication (T) |
| System-Specific |
| Not Entered |
| Not Assigned |
| IA-3.1, IA-3.1, IA-3.1 |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 IA-4 |
| Identifier Management |
| Identifier Management (T) |
| System-Specific |
| Not Entered |
| Not Assigned |
| IA-4.1, IA-4.1, IA-4.1 |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 IA-5 |
| Authenticator Management |
| Authenticator Management (T) |
| System-Specific |
| Not Entered |
| Not Assigned |
| IA-5.1, IA-5.1, IA-5.1 |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 IA-5 (1) |
| Password-Based Authentication |
| Authenticator Management (T) |
| System-Specific |
| Not Entered |
| Not Assigned |
| IA-5(1).1, IA-5(1).1, IA-5(1).1 |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 IA-5 (2) |
| PKI-Based Authentication |
| Authenticator Management (T) |
| System-Specific |
| Not Entered |
| Not Assigned |
| IA-5(2).1, IA-5(2).1, IA-5(2).1 |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 IA-5 (3) |
| In-Person Or Trusted Third-Party Registration |
| Authenticator Management (T) |
| System-Specific |
| Not Entered |
| Not Assigned |
| IA-5(3).1, IA-5(3).1, IA-5(3).1 |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 IA-5 (11) |
| Hardware Token-Based Authentication |
| Authenticator Management (T) |
| System-Specific |
| Not Entered |
| Not Assigned |
| IA-5(11).1, IA-5(11).1, IA-5(11).1 |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 IA-5 (DHS-5.1.e) |
| User Authentication Materials |
| Authenticator Management (T) |
| System-Specific |
| Not Entered |
| Not Assigned |
| IA-5(DHS-5.1.e), IA-5(DHS-5.1.e), IA-5(DHS-5.1.e) |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 IA-6 |
| Authenticator Feedback |
| Authenticator Feedback (T) |
| System-Specific |
| Not Entered |
| Not Assigned |
| IA-6.1, IA-6.1, IA-6.1 |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 IA-7 |
| Cryptographic Module Authentication |
| Cryptographic Module Authentication (T) |
| System-Specific |
| Not Entered |
| Not Assigned |
| IA-7.1, IA-7.1, IA-7.1 |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 IA-8 |
| Identification and Authentication (Non-Organizational Users) |
| Identification and Authentication (Non-Organizational Users) (T) |
| System-Specific |
| Not Entered |
| Not Assigned |
| IA-8.1, IA-8.1, IA-8.1 |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 IA-8 (1) |
| Acceptance Of PIV Credentials From Other Agencies |
| Identification and Authentication (Non-Organizational Users) (T) |
| System-Specific |
| Not Entered |
| Not Assigned |
| IA-8(1).1, IA-8(1).1, IA-8(1).1 |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 IA-8 (2) |
| Acceptance Of Third-Party Credentials |
| Identification and Authentication (Non-Organizational Users) (T) |
| System-Specific |
| Not Entered |
| Not Assigned |
| IA-8(2).1, IA-8(2).1, IA-8(2).1 |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 IA-8 (3) |
| Use Of FICAM-Approved Products |
| Identification and Authentication (Non-Organizational Users) (T) |
| System-Specific |
| Not Entered |
| Not Assigned |
| IA-8(3).1, IA-8(3).1, IA-8(3).1 |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 IA-8 (4) |
| Use Of Ficam-Issued Profiles |
| Identification and Authentication (Non-Organizational Users) (T) |
| System-Specific |
| Not Entered |
| Not Assigned |
| IA-8(4).1, IA-8(4).1, IA-8(4).1 |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 IA-8 (DHS-1.5.4.c) |
| Foreign Nationals |
| Identification and Authentication (Non-Organizational Users) (T) |
| System-Specific |
| Not Entered |
| Not Assigned |
| IA-8(DHS-1.5.4.c), IA-8(DHS-1.5.4.c), IA-8(DHS-1.5.4.c) |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 IR-1 |
| Incident Response Policy and Procedures |
| Incident Response Policy and Procedures (O) |
| System-Specific |
| Not Entered |
| Not Assigned |
| IR-1.1, IR-1.1, IR-1.1, IR-1.2, IR-1.2, IR-1.2 |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 IR-2 |
| Incident Response Training |
| Incident Response Training (O) |
| System-Specific |
| Not Entered |
| Not Assigned |
| IR-2.1, IR-2.1, IR-2.1 |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 IR-3 |
| Incident Response Testing |
| Incident Response Testing (O) |
| System-Specific |
| Not Entered |
| Not Assigned |
| IR-3.1, IR-3.1, IR-3.1 |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 IR-3 (2) |
| Coordination With Related Plans |
| Incident Response Testing (O) |
| System-Specific |
| Not Entered |
| Not Assigned |
| IR-3(2).1, IR-3(2).1, IR-3(2).1 |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 IR-4 |
| Incident Handling |
| Incident Handling (O) |
| System-Specific |
| Not Entered |
| Not Assigned |
| IR-4.1, IR-4.1, IR-4.1 |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 IR-4 (1) |
| Automated Incident Handling Processes |
| Incident Handling (O) |
| System-Specific |
| Not Entered |
| Not Assigned |
| IR-4(1).1, IR-4(1).1, IR-4(1).1 |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 IR-5 |
| Incident Monitoring |
| Incident Monitoring (O) |
| System-Specific |
| Not Entered |
| Not Assigned |
| IR-5.1, IR-5.1, IR-5.1 |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 IR-6 |
| Incident Reporting |
| Incident Reporting (O) |
| System-Specific |
| Not Entered |
| Not Assigned |
| IR-6.1, IR-6.1, IR-6.1 |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 IR-6 (1) |
| Automated Reporting |
| Incident Reporting (O) |
| System-Specific |
| Not Entered |
| Not Assigned |
| IR-6(1).1, IR-6(1).1, IR-6(1).1 |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 IR-7 |
| Incident Response Assistance |
| Incident Response Assistance (O) |
| System-Specific |
| Not Entered |
| Not Assigned |
| IR-7.1, IR-7.1, IR-7.1 |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 IR-7 (1) |
| Automation Support For Availability Of Information / Support |
| Incident Response Assistance (O) |
| System-Specific |
| Not Entered |
| Not Assigned |
| IR-7(1).1, IR-7(1).1, IR-7(1).1 |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 IR-8 |
| Incident Response Plan |
| Incident Response Plan (O) |
| System-Specific |
| Not Entered |
| Not Assigned |
| IR-8.1, IR-8.1, IR-8.1, IR-8.2, IR-8.2, IR-8.2 |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 MA-1 |
| System Maintenance Policy and Procedures |
| System Maintenance Policy and Procedures (O) |
| System-Specific |
| Not Entered |
| Not Assigned |
| MA-1.1, MA-1.1, MA-1.1, MA-1.2, MA-1.2, MA-1.2 |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 MA-2 |
| Controlled Maintenance |
| Controlled Maintenance (O) |
| System-Specific |
| Not Entered |
| Not Assigned |
| MA-2.1, MA-2.1, MA-2.1 |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 MA-3 |
| Maintenance Tools |
| Maintenance Tools (O) |
| System-Specific |
| Not Entered |
| Not Assigned |
| MA-3.1, MA-3.1, MA-3.1 |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 MA-3 (1) |
| Inspect Tools |
| Maintenance Tools (O) |
| System-Specific |
| Not Entered |
| Not Assigned |
| MA-3(1).1, MA-3(1).1, MA-3(1).1 |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 MA-3 (2) |
| Inspect Media |
| Maintenance Tools (O) |
| System-Specific |
| Not Entered |
| Not Assigned |
| MA-3(2).1, MA-3(2).1, MA-3(2).1 |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 MA-4 |
| Nonlocal Maintenance |
| Nonlocal Maintenance (O) |
| System-Specific |
| Not Entered |
| Not Assigned |
| MA-4.1, MA-4.1, MA-4.1 |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 MA-4 (2) |
| Document Nonlocal Maintenance |
| Nonlocal Maintenance (O) |
| System-Specific |
| Not Entered |
| Not Assigned |
| MA-4(2).1, MA-4(2).1, MA-4(2).1 |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 MA-4 (6) |
| Cryptographic Protection |
| Nonlocal Maintenance (O) |
| System-Specific |
| Not Entered |
| Not Assigned |
| MA-4(6).1, MA-4(6).1, MA-4(6).1 |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 MA-4 (DHS-5.4.4.c) |
| Remote Maintenance Paths |
| Nonlocal Maintenance (O) |
| System-Specific |
| Not Entered |
| Not Assigned |
| MA-4(DHS-5.4.4.c), MA-4(DHS-5.4.4.c), MA-4(DHS-5.4.4.c) |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 MA-5 |
| Maintenance Personnel |
| Maintenance Personnel (O) |
| System-Specific |
| Not Entered |
| Not Assigned |
| MA-5.1, MA-5.1, MA-5.1 |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 MA-6 |
| Timely Maintenance |
| Timely Maintenance (O) |
| System-Specific |
| Not Entered |
| Not Assigned |
| MA-6.1, MA-6.1, MA-6.1 |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 MP-1 |
| Media Protection Policy and Procedures |
| Media Protection Policy and Procedures (O) |
| System-Specific |
| Not Entered |
| Not Assigned |
| MP-1.1, MP-1.1, MP-1.1, MP-1.2, MP-1.2, MP-1.2 |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 MP-1 (DHS-3.14.5.b) |
| Removal of PII |
| Media Protection Policy and Procedures (O) |
| System-Specific |
| Not Entered |
| Not Assigned |
| MP-1(DHS-3.14.5.b), MP-1(DHS-3.14.5.b), MP-1(DHS-3.14.5.b) |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 MP-1 (DHS-4.3.1.g) |
| Protection of Printed Output |
| Media Protection Policy and Procedures (O) |
| System-Specific |
| Not Entered |
| Not Assigned |
| MP-1(DHS-4.3.1.g), MP-1(DHS-4.3.1.g), MP-1(DHS-4.3.1.g) |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 MP-1 (DHS-5.4.1.d) |
| PII Remote Access |
| Media Protection Policy and Procedures (O) |
| System-Specific |
| Not Entered |
| Not Assigned |
| MP-1(DHS-5.4.1.d), MP-1(DHS-5.4.1.d), MP-1(DHS-5.4.1.d) |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 MP-1 (DHS-5.6.c) |
| Media Scanning |
| Media Protection Policy and Procedures (O) |
| System-Specific |
| Not Entered |
| Not Assigned |
| MP-1(DHS-5.6.c), MP-1(DHS-5.6.c), MP-1(DHS-5.6.c) |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 MP-2 |
| Media Access |
| Media Access (O) |
| System-Specific |
| Not Entered |
| Not Assigned |
| MP-2.1, MP-2.1, MP-2.1 |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 MP-3 |
| Media Marking |
| Media Marking (O) |
| System-Specific |
| Not Entered |
| Not Assigned |
| MP-3.1, MP-3.1, MP-3.1 |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 MP-4 |
| Media Storage |
| Media Storage (O) |
| System-Specific |
| Not Entered |
| Not Assigned |
| MP-4.1, MP-4.1, MP-4.1 |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 MP-4 (DHS-3.14.5.f) |
| Rentention of Computer Readable Extracts (CREs) |
| Media Protection Policy and Procedures (O) |
| System-Specific |
| Not Entered |
| Not Assigned |
| MP-4(DHS-3.14.5.f), MP-4(DHS-3.14.5.f), MP-4(DHS-3.14.5.f) |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 MP-5 |
| Media Transport |
| Media Transport (O) |
| System-Specific |
| Not Entered |
| Not Assigned |
| MP-5.1, MP-5.1, MP-5.1 |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 MP-5 (4) |
| Cryptographic Protection |
| Media Transport (O) |
| System-Specific |
| Not Entered |
| Not Assigned |
| MP-5(4).1, MP-5(4).1, MP-5(4).1 |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 MP-5 (DHS-4.11.f) |
| Backup Media Shipping |
| Media Transport (O) |
| System-Specific |
| Not Entered |
| Not Assigned |
| MP-5(DHS-4.11.f), MP-5(DHS-4.11.f), MP-5(DHS-4.11.f) |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 MP-6 |
| Media Sanitization |
| Media Sanitization (O) |
| System-Specific |
| Not Entered |
| Not Assigned |
| MP-6.1, MP-6.1, MP-6.1 |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 MP-7 |
| Media Use |
| Media Use (O) |
| System-Specific |
| Not Entered |
| Not Assigned |
| MP-7.1, MP-7.1, MP-7.1 |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 MP-7 (1) |
| Prohibit Use Without Owner |
| Media Use (O) |
| System-Specific |
| Not Entered |
| Not Assigned |
| MP-7(1).1, MP-7(1).1, MP-7(1).1 |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 MP-7 (DHS-4.3.1.d) |
| USB Drive encryption |
| Media Use (O) |
| System-Specific |
| Not Entered |
| Not Assigned |
| MP-7(DHS-4.3.1.d), MP-7(DHS-4.3.1.d), MP-7(DHS-4.3.1.d) |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 MP-7 (DHS-4.3.1.e) |
| DHS owned Removable Media |
| Media Use (O) |
| System-Specific |
| Not Entered |
| Not Assigned |
| MP-7(DHS-4.3.1.e), MP-7(DHS-4.3.1.e), MP-7(DHS-4.3.1.e) |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 MP-7 (DHS-4.3.1.f) |
| Protection of Sensitive Paper and Electronic Outputs |
| Media Use (O) |
| System-Specific |
| Not Entered |
| Not Assigned |
| MP-7(DHS-4.3.1.f), MP-7(DHS-4.3.1.f), MP-7(DHS-4.3.1.f) |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 PE-1 |
| Physical and Environmental Protection Policy and Procedures |
| Physical and Environmental Protection Policy and Procedures (O) |
| System-Specific |
| Not Entered |
| Not Assigned |
| PE-1.1, PE-1.1, PE-1.1, PE-1.2, PE-1.2, PE-1.2 |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 PE-1 (DHS-3.3.c) |
| Sensitive Information at Contractor Sites |
| Physical and Environmental Protection Policy and Procedures (O) |
| System-Specific |
| Not Entered |
| Not Assigned |
| PE-1(DHS-3.3.c), PE-1(DHS-3.3.c), PE-1(DHS-3.3.c) |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 PE-1 (DHS-4.6.2.3.b) |
| Video, IR, and RF Signals |
| Physical and Environmental Protection Policy and Procedures (O) |
| System-Specific |
| Not Entered |
| Not Assigned |
| PE-1(DHS-4.6.2.3.b), PE-1(DHS-4.6.2.3.b), PE-1(DHS-4.6.2.3.b) |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 PE-2 |
| Physical Access Authorizations |
| Physical Access Authorizations (O) |
| System-Specific |
| Not Entered |
| Not Assigned |
| PE-2.1, PE-2.1, PE-2.1, PE-2.2, PE-2.2, PE-2.2 |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 PE-3 |
| Physical Access Control |
| Physical Access Control (O) |
| System-Specific |
| Not Entered |
| Not Assigned |
| PE-3.1, PE-3.1, PE-3.1, PE-3.2, PE-3.2, PE-3.2 |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 PE-4 |
| Access Control for Transmission Medium |
| Access Control for Transmission Medium (O) |
| System-Specific |
| Not Entered |
| Not Assigned |
| PE-4.1, PE-4.1, PE-4.1 |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 PE-5 |
| Access Control for Output Devices |
| Access Control for Output Devices (O) |
| System-Specific |
| Not Entered |
| Not Assigned |
| PE-5.1, PE-5.1, PE-5.1 |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 PE-6 |
| Monitoring Physical Access |
| Monitoring Physical Access (O) |
| System-Specific |
| Not Entered |
| Not Assigned |
| PE-6.1, PE-6.1, PE-6.1 |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 PE-6 (1) |
| Intrusion Alarms / Surveillance Equipment |
| Monitoring Physical Access (O) |
| System-Specific |
| Not Entered |
| Not Assigned |
| PE-6(1).1, PE-6(1).1, PE-6(1).1 |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 PE-8 |
| Visitor Access Records |
| Visitor Access Records (O) |
| System-Specific |
| Not Entered |
| Not Assigned |
| PE-8.1, PE-8.1, PE-8.1 |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 PE-9 |
| Power Equipment and Cabling |
| Power Equipment and Cabling (O) |
| System-Specific |
| Not Entered |
| Not Assigned |
| PE-9.1, PE-9.1, PE-9.1 |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 PE-10 |
| Emergency Shutoff |
| Emergency Shutoff (O) |
| System-Specific |
| Not Entered |
| Not Assigned |
| PE-10.1, PE-10.1, PE-10.1 |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 PE-11 |
| Emergency Power |
| Emergency Power (O) |
| System-Specific |
| Not Entered |
| Not Assigned |
| PE-11.1, PE-11.1, PE-11.1 |
| X |
| X |
| - |
| - |
| - |
| Not Met |
| None |
| NIST 800-53 w/ DHS 4300A Rev 4 PE-12 |
| Emergency Lighting |
| Emergency Lighting (O) |
| System-Specific |
| Not Entered |
| Not Assigned |
| PE-12.1, PE-12.1, PE-12.1 |
| X |
| X |
| - |
| - |
| - |
This is the start of the file's text. The full file is on GovTribe.