CS2 FO RFP Sec J Attachment J-2_Final.pdf

PDF 518 KB Posted

Attached to
FCSA CS2 Full & Open Solicitation Federal contract opportunity
Solicitation number
CS2_(QTA)(010)(CTA)(0003)
Issued by
GSA Federal Acquisition Service

About this file

CS2 Section J Attachment J-2

View the file

Other files for this federal contract opportunity

Other files attached to FCSA CS2 Full & Open Solicitation, newest first.
File Type Posted
CS2 RFP Sec A_SF33_Amendment 09.pdf PDF
CS2 SF30_Amendment 09.pdf PDF
CS2 SF30_Amendment 08.pdf PDF
CS2_CS2-SB General Q A-part 9.pdf PDF
CS2 and CS2-SB Q A-part 9_CS2 specific.pdf PDF
CS2 SF30_Amendment 07.pdf PDF
CS2 SF30_Amendment 06.pdf PDF
CS2 RFP Sec J Attachment J-9_Amendment 05.pdf PDF
CS2 SF30_Amendment 05.pdf PDF
CS2 RFP Sec L_Amendment 05.pdf PDF
CS2 RFP Sec M_Amendment 05.pdf PDF
CS2 RFP Sec J Attachment J-12_Amendment 05.pdf PDF
CS2 SF30_Amendment 4.pdf PDF
CS2 and CS2-SB Q A-part 6_draft.pdf PDF
CS2 and CS2-SB Q A-part 6_CS2 specific_draft.pdf PDF
CS2 SF30_Amendment 3.pdf PDF
CS2 and CS2-SB Q A-part 5.pdf PDF
CS2 SF30_Amendment 2.pdf PDF
CS2 and CS2-SB Q A-part 5_CS2 specific.pdf PDF
CS2 and CS2-SB Q A-part 4_CS2 specific.pdf PDF
CS2 SF30_Amendment 1.pdf PDF
CS2 and CS2-SB Q A-part 4.pdf PDF
CS2 and CS2-SB Q A-part 3.pdf PDF
CS2 and CS2-SB Q A-part 3_CS2 specific.pdf PDF
CS2 Q A.pdf PDF
CS2 and CS2-SB Q A.pdf PDF
CS2 FO RFP Sec J Attachment J-5_Final.pdf PDF
CS2 FO RFP Sec J Attachment J-9_Final.pdf PDF
CS2 FO RFP Sec H_Final.pdf PDF
CS2 FO RFP Sec J Attachment J-7_Final.pdf PDF
CS2 FO RFP Sec J Attachment J-6_Final.pdf PDF
CS2 FO RFP Sec G_Final.pdf PDF
CS2 FO RFP Sec J Attachment J-1_Final.pdf PDF
CS2 FO RFP Sec B_Final.pdf PDF
CS2 FO RFP Sec J Attachment J-12_Final.pdf PDF
CS2 FO RFP Sec L_Final.pdf PDF
CS2 FO RFP Sec I_Final.pdf PDF
CS2 FO RFP Sec J_Final.pdf PDF
CS2 FO RFP Sec J Attachment J-10_Final.pdf PDF
CS2 FO RFP Sec A_SF33_Final.pdf PDF
CS2 FO RFP Sec M_Final.pdf PDF
CS2 FO RFP Sec D_Final.pdf PDF
CS2 FO RFP Sec J Attachment J-11_Final.pdf PDF
CS2 FO RFP Sec J Attachment J-8_Final.pdf PDF
CS2 FO RFP Sec K_Final.pdf PDF
CS2 FO RFP Sec F_Final.pdf PDF
CS2 FO RFP Sec J Attachment J-3_Final.pdf PDF
CS2 FO RFP Sec E_Final.pdf PDF
CS2 FO RFP Sec C_Final.pdf PDF
CS2 FO RFP Sec J Attachment J-4_Final.pdf PDF
Show all 50

FCSA CS2 Full & Open Solicitation has more files on GovTribe.

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

QTA-010-CTA-0003

ATTACHMENT J-2

INFORMATION ASSURANCE MINIMUM SECURITY CONTROLS CHECKLIST

References

CONTROL NAME

Threshold Compliance

DoDI 8500.2

NIST

800-53

Low-Impact Information System (FIPS 200 / NIST SP 800-53)

MAC III (DoDI 8500.2) (generally commercial best practices)

Explain Your Current Compliance OR Actions to Become Compliant

Access Control

ECAN-1

ECPA-1

PRAS-1

DCAR-1

AC-1 ACCESS

CONTROL POLICY

AND

PROCEDURES

The organization develops, disseminates, and reviews/updates [Assignment: organization-defined frequency]:

a. A formal, documented access control policy that addresses purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance; and

b. Formal, documented procedures to facilitate the implementation of the access control policy and associated access controls.

IAAC-1 AC-2 ACCOUNT

MANAGEMENT

The organization manages information system accounts, including:

a. Identifying account types (i.e., individual, group, system, application, guest/anonymous, and temporary);

b. Establishing conditions for group membership;

c. Identifying authorized users of the information system and specifying access privileges;

d. Requiring appropriate approvals for requests to establish accounts;

e. Establishing, activating, modifying, disabling, and removing accounts;

f. Specifically authorizing and monitoring the use of guest/anonymous and temporary accounts;

g. Notifying account managers when temporary accounts are no longer required and when information system users are terminated, transferred, or information system usage or need-to-know/need-to-share changes;

h. Deactivating: (i) temporary accounts that are no longer required; and (ii) accounts of terminated or

References

CONTROL NAME

Threshold Compliance

DoDI 8500.2

NIST

800-53

Low-Impact Information System (FIPS 200 / NIST SP 800-53)

MAC III (DoDI 8500.2) (generally commercial best practices)

Explain Your Current Compliance OR Actions to Become Compliant transferred users;

i. Granting access to the system based on: (i) a valid access authorization; (ii) intended system usage; and

(iii) other attributes as required by the organization or associated missions/business functions; and

j. Reviewing accounts [Assignment: organization-defined frequency].

DCFA-1

ECAN-1

EBRU-1

PRNK-1

ECCD-1

ECSD-2

AC-3 ACCESS

ENFORCEMENT

The information system enforces approved authorizations for logical access to the system in accordance with applicable policy.

EBBD-1

EBBD-2

AC-4 INFORMATION

FLOW

ENFORCEMENT

Not Applicable Optional: (May be applicable for NIST Moderate or High Impact, or DoD MAC I or MAC II))

ECLP-1 AC-5 SEPARATION OF

DUTIES

Not Applicable Optional: (May be applicable for NIST Moderate or High Impact, or DoD MAC I or MAC II))

ECLP-1 AC-6 LEAST PRIVILEGE Not Applicable Optional: (May be applicable for NIST Moderate or High Impact, or DoD MAC I or MAC II))

References

CONTROL NAME

Threshold Compliance

DoDI 8500.2

NIST

800-53

Low-Impact Information System (FIPS 200 / NIST SP 800-53)

MAC III (DoDI 8500.2) (generally commercial best practices)

Explain Your Current Compliance OR Actions to Become Compliant

ECLO-1 AC-7 UNSUCCESSFUL

LOGIN ATTEMPTS

The information system:

a. Enforces a limit of [Assignment: organization-defined number] consecutive invalid access attempts by a user during a [Assignment: organization-defined time period];

and

b. Automatically [Selection: locks the account/node for an [Assignment: organization-defined time period]; locks the account/node until released by an administrator;

delays next login prompt according to [Assignment:

organization-defined delay algorithm]] when the maximum number of unsuccessful attempts is exceeded. The control applies regardless of whether the login occurs via a local or network connection.

References

CONTROL NAME

Threshold Compliance

DoDI 8500.2

NIST

800-53

Low-Impact Information System (FIPS 200 / NIST SP 800-53)

MAC III (DoDI 8500.2) (generally commercial best practices)

Explain Your Current Compliance OR Actions to Become Compliant

ECWM-1 AC-8 SYSTEM USE

NOTIFICATION

The information system:

a. Displays an approved system use notification message or banner before granting access to the system that provides privacy and security notices consistent with applicable federal laws, Executive Orders, directives, policies, regulations, standards, and guidance and states that: (i) users are accessing a U.S.

Government information system; (ii) system usage may be monitored, recorded, and subject to audit; (iii) unauthorized use of the system is prohibited and subject to criminal and civil penalties; and (iv) use of the system indicates consent to monitoring and recording;

b. Retains the notification message or banner on the screen until users take explicit actions to log on to or further access the information system; and

c. For publicly accessible systems: (i) displays the system use information when appropriate, before granting further access; (ii) displays references, if any, to monitoring, recording, or auditing that are consistent with privacy accommodations for such systems that generally prohibit those activities; and (iii) includes in the notice given to public users of the information system, a description of the authorized uses of the system.

AC-9 PREVIOUS LOGON

(ACCESS)

NOTIFICATION

Not Applicable Optional: (May be applicable for DoD MAC I or MAC II)

ECLO-1 AC-10 CONCURRENT

SESSION

CONTROL

Not Applicable Optional: (May be applicable for NIST Moderate or High Impact, or DoD MAC I or MAC II)

References

CONTROL NAME

Threshold Compliance

DoDI 8500.2

NIST

800-53

Low-Impact Information System (FIPS 200 / NIST SP 800-53)

MAC III (DoDI 8500.2) (generally commercial best practices)

Explain Your Current Compliance OR Actions to Become Compliant

PESL-1 AC-11 SESSION LOCK Not Applicable Optional: (May be applicable for NIST Moderate or High Impact, or DoD MAC I or MAC II)

--- AC-12 SESSION

TERMINATION

Withdrawn: Incorporated into SC-10 Optional: (May be applicable for DoD MAC I or MAC II)

ECAT-1

ECAT-2

E3.3.9

AC-13 SUPERVISION AND

REVIEW —

ACCESS

CONTROL

Withdrawn: Incorporated into AC-2 and AU-6. Optional: (May be applicable for DoD MAC I or MAC II)

--- AC-14 PERMITTED

ACTIONS

WITHOUT

IDENTIFICATION

OR

AUTHENTICATION

The organization:

a. Identifies specific user actions that can be performed on the information system without identification or authentication; and

b. Documents and provides supporting rationale in the security plan for the information system, user actions not requiring identification and authentication.

ECML-1 AC-15 AUTOMATED

MARKING

Withdrawn: Incorporated into MP-3. Optional: (May be applicable for DoD MAC I or MAC II)

AC-16 SECURITY

ATTRIBUTES

Not Applicable Optional: (May be applicable for DoD MAC I or MAC II)

References

CONTROL NAME

Threshold Compliance

DoDI 8500.2

NIST

800-53

Low-Impact Information System (FIPS 200 / NIST SP 800-53)

MAC III (DoDI 8500.2) (generally commercial best practices)

Explain Your Current Compliance OR Actions to Become Compliant

EBRP-1

EBRU-1

AC-17 REMOTE ACCESS

The organization:

a. Documents allowed methods of remote access to the information system;

b. Establishes usage restrictions and implementation guidance for each allowed remote access method;

c. Monitors for unauthorized remote access to the information system;

d. Authorizes remote access to the information system prior to connection; and

e. Enforces requirements for remote connections to the information system.

ECCT-1

ECWN-1

AC-18 WIRELESS

ACCESS

The organization:

a. Establishes usage restrictions and implementation guidance for wireless access;

b. Monitors for unauthorized wireless access to the information system;

c. Authorizes wireless access to the information system prior to connection; and

d. Enforces requirements for wireless connections to the

References

CONTROL NAME

Threshold Compliance

DoDI 8500.2

NIST

800-53

Low-Impact Information System (FIPS 200 / NIST SP 800-53)

MAC III (DoDI 8500.2) (generally commercial best practices)

Explain Your Current Compliance OR Actions to Become Compliant

ECWN-1 AC-19 ACCESS

CONTROL FOR

MOBILE DEVICES

The organization:

a. Establishes usage restrictions and implementation guidance for organization-controlled mobile devices;

b. Authorizes connection of mobile devices meeting organizational usage restrictions and implementation guidance to organizational information systems;

c. Monitors for unauthorized connections of mobile devices to organizational information systems;

d. Enforces requirements for the connection of mobile devices to organizational information systems;

e. Disables information system functionality that provides the capability for automatic execution of code on mobile devices without user direction;

f. Issues specially configured mobile devices to individuals traveling to locations that the organization deems to be of significant risk in accordance with organizational policies and procedures; and

g. Applies [Assignment: organization-defined inspection and preventative measures] to mobile devices returning from locations that the organization deems to be of significant risk in accordance with organizational policies and procedures.

References

CONTROL NAME

Threshold Compliance

DoDI 8500.2

NIST

800-53

Low-Impact Information System (FIPS 200 / NIST SP 800-53)

MAC III (DoDI 8500.2) (generally commercial best practices)

Explain Your Current Compliance OR Actions to Become Compliant

--- AC-20 USE OF

EXTERNAL

INFORMATION

SYSTEMS

The organization establishes terms and conditions, consistent with any trust relationships established with other organizations owning, operating, and/or maintaining external information systems, allowing authorized individuals to:

a. Access the information system from the external information systems; and

b. Process, store, and/or transmit organization-controlled information using the external information systems.

AC-21 USER-BASED

COLLABORATION

AND

INFORMATION

SHARING

References

CONTROL NAME

Threshold Compliance

DoDI 8500.2

NIST

800-53

Low-Impact Information System (FIPS 200 / NIST SP 800-53)

MAC III (DoDI 8500.2) (generally commercial best practices)

Explain Your Current Compliance OR Actions to Become Compliant

AC-22 PUBLICLY

ACCESSIBLE

CONTENT

The organization:

a. Designates individuals authorized to post information onto an organizational information system that is publicly accessible;

b. Trains authorized individuals to ensure that publicly accessible information does not contain nonpublic information;

c. Reviews the proposed content of publicly accessible information for nonpublic information prior to posting onto the organizational information system;

d. Reviews the content on the publicly accessible organizational information system for nonpublic information [Assignment: organization-defined frequency]; and

e. Removes nonpublic information from the publicly accessible organizational information system, if discovered.

Awareness and Training

PRTN-1

DCAR-1

AT-1 SECURITY

AWARENESS AND

TRAINING POLICY

AND

PROCEDURES

The organization develops, disseminates, and reviews/updates [Assignment: organization-defined frequency]:

a. A formal, documented security awareness and training policy that addresses purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance; and

b. Formal, documented procedures to facilitate the implementation of the security awareness and training policy and associated security awareness and training controls.

References

CONTROL NAME

Threshold Compliance

DoDI 8500.2

NIST

800-53

Low-Impact Information System (FIPS 200 / NIST SP 800-53)

MAC III (DoDI 8500.2) (generally commercial best practices)

Explain Your Current Compliance OR Actions to

AT-2 SECURITY

AWARENESS

The organization provides basic security awareness training to all information system users (including managers, senior executives, and contractors) as part of initial training for new users, when required by system changes, and [Assignment: organization-defined frequency] thereafter.

AT-3 SECURITY

TRAINING

The organization provides role-based security-related training: (i) before authorizing access to the system or performing assigned duties; (ii) when required by system changes; and (iii) [Assignment: organization-defined frequency] thereafter.

--- AT-4 SECURITY

TRAINING

RECORDS

The organization:

a. Documents and monitors individual information system security training activities including basic security awareness training and specific information system security training; and

b. Retains individual training records for [Assignment:

organization-defined time period].

AT-5 CONTACTS WITH

SECURITY

GROUPS AND

ASSOCIATIONS

Audit and Accountability

References

CONTROL NAME

Threshold Compliance

DoDI 8500.2

NIST

800-53

Low-Impact Information System (FIPS 200 / NIST SP 800-53)

MAC III (DoDI 8500.2) (generally commercial best practices)

Explain Your Current Compliance OR Actions to Become Compliant

ECAT-1

ECTB-1

DCAR-1

AU-1 AUDIT AND

ACCOUNTABILITY

POLICY AND

PROCEDURES

The organization develops, disseminates, and reviews/updates [Assignment: organization-defined frequency]:

a. A formal, documented audit and accountability policy that addresses purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance; and

b. Formal, documented procedures to facilitate the implementation of the audit and accountability policy and associated audit and accountability controls.

ECAR-3 AU-2 AUDITABLE

EVENTS

The organization:

a. Determines, based on a risk assessment and mission/business needs, that the information system must be capable of auditing the following events:

[Assignment: organization-defined list of auditable events];

b. Coordinates the security audit function with other organizational entities requiring audit-related information to enhance mutual support and to help guide the selection of auditable events;

c. Provides a rationale for why the list of auditable events are deemed to be adequate to support after-the-fact investigations of security incidents; and

d. Determines, based on current threat information and ongoing assessment of risk, that the following events are to be audited within the information system:

[Assignment: organization-defined subset of the auditable events defined in AU-2 a. to be audited along with the frequency of (or situation requiring) auditing for each identified event].

References

CONTROL NAME

Threshold Compliance

DoDI 8500.2

NIST

800-53

Low-Impact Information System (FIPS 200 / NIST SP 800-53)

MAC III (DoDI 8500.2) (generally commercial best practices)

Explain Your Current Compliance OR Actions to Become Compliant

ECAR-1

ECAR-2

ECAR-3

ECLC-1

AU-3 CONTENT OF

AUDIT RECORDS

The information system produces audit records that contain sufficient information to, at a minimum, establish what type of event occurred, when (date and time) the event occurred, where the event occurred, the source of the event, the outcome (success or failure) of the event, and the identity of any user/subject associated with the event.

--- AU-4 AUDIT STORAGE

CAPACITY

The organization allocates audit record storage capacity and configures auditing to reduce the likelihood of such capacity being exceeded.

--- AU-5 RESPONSE TO

AUDIT

PROCESSING

FAILURES

The information system: a. Alerts designated organizational officials in the event of an audit processing failure; and

b. Takes the following additional actions: [Assignment:

organization-defined actions to be taken (e.g., shut down information system, overwrite oldest audit records, stop generating audit records)].

ECAT-1

E3.3.9

AU-6 AUDIT REVIEW,

ANALYSIS, AND

REPORTING

The organization:

a. Reviews and analyzes information system audit records [Assignment: organization-defined frequency] for indications of inappropriate or unusual activity, and reports findings to designated organizational officials;

and

b. Adjusts the level of audit review, analysis, and reporting within the information system when there is a change in risk to organizational operations, organizational assets, individuals, other organizations, or the Nation based on law enforcement information, intelligence information, or other credible sources of information.

References

CONTROL NAME

Threshold Compliance

DoDI 8500.2

NIST

800-53

Low-Impact Information System (FIPS 200 / NIST SP 800-53)

MAC III (DoDI 8500.2) (generally commercial best practices)

Explain Your Current Compliance OR Actions to Become Compliant

ECRG-1 AU-7 AUDIT REDUCTION

AND REPORT

GENERATION

Not Applicable Optional: (May be applicable for NIST Moderate or High Impact, or DoD MAC I or MAC II)

ECAR-1 AU-8 TIME STAMPS

The information system uses internal system clocks to generate time stamps for audit records.

ECTP-1 AU-9 PROTECTION OF

AUDIT

INFORMATION

The information system protects audit information and audit tools from unauthorized access, modification, and deletion.

AU-10 NON-

REPUDIATION

Not Applicable Optional: (May be applicable for NIST Moderate or High Impact, or DoD MAC I or MAC II)

ECRR-1 AU-11 AUDIT RECORD

RETENTION

The organization retains audit records for [Assignment:

organization-defined time period consistent with records retention policy] to provide support for after-the-fact investigations of security incidents and to meet regulatory and organizational information retention requirements.

AU-12 AUDIT

GENERATION

The information system:

a. Provides audit record generation capability for the list of auditable events defined in AU-2 at [Assignment:

organization-defined information system components];

b. Allows designated organizational personnel to select which auditable events are to be audited by specific components of the system; and

c. Generates audit records for the list of audited events defined in AU-2 with the content as defined in AU-3.

AU-13 MONITORING FOR

INFORMATION

DISCLOSURE

References

CONTROL NAME

Threshold Compliance

DoDI 8500.2

NIST

800-53

Low-Impact Information System (FIPS 200 / NIST SP 800-53)

MAC III (DoDI 8500.2) (generally commercial best practices)

Explain Your Current Compliance OR Actions to Become Compliant

AU-14 SESSION AUDIT

Not Applicable Optional: (May be applicable for DoD MAC I or MAC II)

Security Assessment and Authorization

DCAR-1

DCII-1

CA-1 SECURITY

ASSESSMENT AND

AUTHORIZATION

POLICIES AND

PROCEDURES

The organization develops, disseminates, and reviews/updates [Assignment: organization-defined frequency]:

a. Formal, documented security assessment and authorization policies that address purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance; and

b. Formal, documented procedures to facilitate the implementation of the security assessment and authorization policies and associated security assessment and authorization controls.

References

CONTROL NAME

Threshold Compliance

DoDI 8500.2

NIST

800-53

Low-Impact Information System (FIPS 200 / NIST SP 800-53)

MAC III (DoDI 8500.2) (generally commercial best practices)

Explain Your Current Compliance OR Actions to Become Compliant

DCII-1

ECMT-1

PEPS-1

E3.3.10

CA-2 SECURITY

ASSESSMENTS

The organization:

a. Develops a security assessment plan that describes the scope of the assessment including:

- Security controls and control enhancements under assessment;

- Assessment procedures to be used to determine security control effectiveness; and

- Assessment environment, assessment team, and assessment roles and responsibilities;

b. Assesses the security controls in the information system [Assignment: organization-defined frequency] to determine the extent to which the controls are implemented correctly, operating as intended, and producing the desired outcome with respect to meeting the security requirements for the system;

c. Produces a security assessment report that documents the results of the assessment; and

d. Provides the results of the security control assessment, in writing, to the authorizing official or authorizing official designated representative. .

DCID-1

EBCR-1

EBRU-1

EBPW-1

ECIC-1

CA-3 INFORMATION

SYSTEM

CONNECTIONS

The organization:

a. Authorizes connections from the information system to other information systems outside of the authorization boundary through the use of Interconnection Security Agreements;

b. Documents, for each connection, the interface characteristics, security requirements, and the nature of the information communicated; and

c. Monitors the information system connections on an ongoing basis verifying enforcement of security

References

CONTROL NAME

Threshold Compliance

DoDI 8500.2

NIST

800-53

Low-Impact Information System (FIPS 200 / NIST SP 800-53)

MAC III (DoDI 8500.2) (generally commercial best practices)

Explain Your Current Compliance OR Actions to Become Compliant

DCAR-1

5.7.5

CA-4 SECURITY

CERTIFICATION

Withdrawn: Incorporated into CA-2. Optional: (May be applicable for DoD MAC I or MAC II)

5.7.5

CA-5 PLAN OF ACTION

AND MILESTONES

The organization:

a. Develops a plan of action and milestones for the information system to document the organization’s planned remedial actions to correct weaknesses or deficiencies noted during the assessment of the security controls and to reduce or eliminate known vulnerabilities in the system; and

b. Updates existing plan of action and milestones [Assignment: organization-defined frequency] based on the findings from security controls assessments, security impact analyses, and continuous monitoring activities.

CA-6 SECURITY

AUTHORIZATION

The organization:

a. Assigns a senior-level executive or manager to the role of authorizing official for the information system;

b. Ensures that the authorizing official authorizes the information system for processing before commencing operations; and

c. Updates the security authorization [Assignment:

organization-defined frequency].

References

CONTROL NAME

Threshold Compliance

DoDI 8500.2

NIST

800-53

Low-Impact Information System (FIPS 200 / NIST SP 800-53)

MAC III (DoDI 8500.2) (generally commercial best practices)

Explain Your Current Compliance OR Actions to Become Compliant

DCCB-1

DCPR-1

E3.3.9

CA-7 CONTINUOUS

MONITORING

The organization establishes a continuous monitoring strategy and implements a continuous monitoring program that includes:

a. A configuration management process for the information system and its constituent components;

b. A determination of the security impact of changes to the information system and environment of operation;

c. Ongoing security control assessments in accordance with the organizational continuous monitoring strategy;

and

d. Reporting the security state of the information system to appropriate organizational officials [Assignment:

Configuration Management

DCCB-1

DCPR-1

E3.3.8

CM-1 CONFIGURATION

POLICY AND

PROCEDURES

The organization develops, disseminates, and reviews/updates [Assignment: organization-defined frequency]:

a. A formal, documented configuration management policy that addresses purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance; and

b. Formal, documented procedures to facilitate the implementation of the configuration management policy and associated configuration management controls.

DCHW-1

DCSW-1

CM-2 BASELINE

CONFIGURATION

The organization develops, documents, and maintains under configuration control, a current baseline configuration of the information system.

DCPR-1

CM-3 CONFIGURATION

CHANGE

CONTROL

References

CONTROL NAME

Threshold Compliance

DoDI 8500.2

NIST

800-53

Low-Impact Information System (FIPS 200 / NIST SP 800-53)

MAC III (DoDI 8500.2) (generally commercial best practices)

Explain Your Current Compliance OR Actions to Become Compliant

DCPR-1

E3.3.8

CM-4 SECURITY IMPACT

ANALYSIS

The organization analyzes changes to the information system to determine potential security impacts prior to change implementation.

DCPR-1

ECSD-2

CM-5 ACCESS

RESTRICTIONS

FOR CHANGE

Not Applicable Optional: (May be applicable for NIST Moderate or High Impact, or DoD MAC I or MAC II)

DCSS-1

ECSC-1

E3.3.8

CM-6 CONFIGURATION

SETTINGS

The organization:

a. Establishes and documents mandatory configuration settings for information technology products employed within the information system using [Assignment:

organization-defined security configuration checklists] that reflect the most restrictive mode consistent with operational requirements;

b. Implements the configuration settings;

c. Identifies, documents, and approves exceptions from the mandatory configuration settings for individual components within the information system based on explicit operational requirements; and

d. Monitors and controls changes to the configuration settings in accordance with organizational policies and procedures.

DCPP-1

ECIM-1

ECVI-1

E3.3.8

CM-7 LEAST

FUNCTIONALITY

The organization configures the information system to provide only essential capabilities and specifically prohibits or restricts the use of the following functions, ports, protocols, and/or services: [Assignment:

organization-defined list of prohibited or restricted functions, ports, protocols, and/or services].

References

CONTROL NAME

Threshold Compliance

DoDI 8500.2

NIST

800-53

Low-Impact Information System (FIPS 200 / NIST SP 800-53)

MAC III (DoDI 8500.2) (generally commercial best practices)

Explain Your Current Compliance OR Actions to Become Compliant

CM-8 INFORMATION

SYSTEM

COMPONENT

INVENTORY

The organization develops, documents, and maintains an inventory of information system components that:

a. Accurately reflects the current information system;

b. Is consistent with the authorization boundary of the information system;

c. Is at the level of granularity deemed necessary for tracking and reporting;

d. Includes [Assignment: organization-defined information deemed necessary to achieve effective property accountability]; and

e. Is available for review and audit by designated organizational officials.

CM-9 CONFIGURATION

PLAN

Not Applicable Optional: (May be applicable for NIST Moderate or High Impact, or DoD MAC I or MAC II)

Contingency Planning

COBR-1

DCAR-1

CP-1 CONTINGENCY

PLANNING POLICY

AND

PROCEDURES

The organization develops, disseminates, and reviews/updates [Assignment: organization-defined frequency]:

a. A formal, documented contingency planning policy that addresses purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance; and

b. Formal, documented procedures to facilitate the implementation of the contingency planning policy and associated contingency planning controls.

References

CONTROL NAME

Threshold Compliance

DoDI 8500.2

NIST

800-53

Low-Impact Information System (FIPS 200 / NIST SP 800-53)

MAC III (DoDI 8500.2) (generally commercial best practices)

Explain Your Current Compliance OR Actions to Become Compliant

CODP-1

COEF-1

CP-2 CONTINGENCY

PLAN

The organization:

a. Develops a contingency plan for the information system that:

- Identifies essential missions and business functions and associated contingency requirements;

- Provides recovery objectives, restoration priorities, and metrics;

- Addresses contingency roles, responsibilities, assigned individuals with contact information;

- Addresses maintaining essential missions and business functions despite an information system disruption, compromise, or failure;

- Addresses eventual, full information system restoration without deterioration of the security measures originally planned and implemented; and

- Is reviewed and approved by designated officials within the organization;

b. Distributes copies of the contingency plan to [Assignment: organization-defined list of key contingency personnel (identified by name and/or by role) and organizational elements];

c. Coordinates contingency planning activities with incident handling activities;

d. Reviews the contingency plan for the information system [Assignment: organization-defined frequency];

e. Revises the contingency plan to address changes to the organization, information system, or environment of operation and problems encountered during contingency plan implementation, execution, or testing; and

f. Communicates contingency plan changes to [Assignment: organization-defined list of key contingency personnel (identified by name and/or by role) and organizational elements].

References

CONTROL NAME

Threshold Compliance

DoDI 8500.2

NIST

800-53

Low-Impact Information System (FIPS 200 / NIST SP 800-53)

MAC III (DoDI 8500.2) (generally commercial best practices)

Explain Your Current Compliance OR Actions to Become Compliant

PRTN-1 CP-3 CONTINGENCY

TRAINING

The organization trains personnel in their contingency roles and responsibilities with respect to the information system and provides refresher training [Assignment:

COED-1 CP-4 CONTINGENCY

PLAN TESTING

AND EXERCISES

The organization:

a. Tests and/or exercises the contingency plan for the information system [Assignment: organization-defined frequency] using [Assignment: organization-defined tests and/or exercises] to determine the plan’s effectiveness and the organization’s readiness to execute the plan; and

b. Reviews the contingency plan test/exercise results and initiates corrective actions.

DCAR-1 CP-5 CONTINGENCY

PLAN UPDATE

Withdrawn: Incorporated into CP-2. May be applicable for DoD MAC I or MAC II)

CODB-2 CP-6 ALTERNATE

STORAGE SITE

Not Applicable May be applicable for NIST Moderate or High Impact, or DoD MAC I or MAC II)

COAS-1

COEB-1

COSP-1

COSP-2

CP-7 ALTERNATE

PROCESSING SITE

Not Applicable Optional: (May be applicable for NIST Moderate or High Impact, or DoD MAC I or MAC II)

--- CP-8 TELECOMMUNICA-

TIONS SERVICES

References

CONTROL NAME

Threshold Compliance

DoDI 8500.2

NIST

800-53

Low-Impact Information System (FIPS 200 / NIST SP 800-53)

MAC III (DoDI 8500.2) (generally commercial best practices)

Explain Your Current Compliance OR Actions to Become Compliant

CODB-1

CODB-2

COSW-1

CP-9 INFORMATION

SYSTEM BACKUP

The organization:

a. Conducts backups of user-level information contained in the information system [Assignment: organization-defined frequency consistent with recovery time and recovery point objectives];

b. Conducts backups of system-level information contained in the information system [Assignment:

organization-defined frequency consistent with recovery time and recovery point objectives];

c. Conducts backups of information system documentation including security-related documentation [Assignment: organization-defined frequency consistent with recovery time and recovery point objectives]; and

d. Protects the confidentiality and integrity of backup information at the storage location.

COTR-1

ECND-1

CP-10 INFORMATION

SYSTEM

RECOVERY AND

RECONSTITUTION

The organization provides for the recovery and reconstitution of the information system to a known state after a disruption, compromise, or failure.

Identification and Authentication

References

CONTROL NAME

Threshold Compliance

DoDI 8500.2

NIST

800-53

Low-Impact Information System (FIPS 200 / NIST SP 800-53)

MAC III (DoDI 8500.2) (generally commercial best practices)

Explain Your Current Compliance OR Actions to Become Compliant

IAIA-1

IA-1 IDENTIFICATION

AND

AUTHENTICATION

POLICY AND

PROCEDURES

The organization develops, disseminates, and reviews/updates [Assignment: organization-defined frequency]:

a. A formal, documented identification and authentication policy that addresses purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance; and

b. Formal, documented procedures to facilitate the implementation of the identification and authentication policy and associated identification and authentication

IA-2 IDENTIFICATION

AUTHENTICATION

(Organizational Users)

The information system uniquely identifies and authenticates organizational users (or processes acting on behalf of organizational users).

Control Enhancement:

(1) The information system uses multifactor authentication for network access to privileged accounts.

--- IA-3 DEVICE

IDENTIFICATION

AND

AUTHENTICATION

References

CONTROL NAME

Threshold Compliance

DoDI 8500.2

NIST

800-53

Low-Impact Information System (FIPS 200 / NIST SP 800-53)

MAC III (DoDI 8500.2) (generally commercial best practices)

Explain Your Current Compliance OR Actions to Become Compliant

IAGA-1

IA-4 IDENTIFIER

The organization manages information system identifiers for users and devices by:

a. Receiving authorization from a designated organizational official to assign a user or device identifier;

b. Selecting an identifier that uniquely identifies an individual or device;

c. Assigning the user identifier to the intended party or the device identifier to the intended device;

d. Preventing reuse of user or device identifiers for [Assignment: organization-defined time period]; and

e. Disabling the user identifier after [Assignment:

organization-defined time period of inactivity].

References

CONTROL NAME

Threshold Compliance

DoDI 8500.2

NIST

800-53

Low-Impact Information System (FIPS 200 / NIST SP 800-53)

MAC III (DoDI 8500.2) (generally commercial best practices)

Explain Your Current Compliance OR Actions to Become Compliant

IAKM-1

IATS-1

IA-5 AUTHENTICATOR

The organization manages information system authenticators for users and devices by:

a. Verifying, as part of the initial authenticator distribution, the identity of the individual and/or device receiving the authenticator;

b. Establishing initial authenticator content for authenticators defined by the organization;

c. Ensuring that authenticators have sufficient strength of mechanism for their intended use;

d. Establishing and implementing administrative procedures for initial authenticator distribution, for lost/compromised or damaged authenticators, and for revoking authenticators;

e. Changing default content of authenticators upon information system installation;

f. Establishing minimum and maximum lifetime restrictions and reuse conditions for authenticators (if appropriate);

g. Changing/refreshing authenticators [Assignment:

organization-defined time period by authenticator type];

h. Protecting authenticator content from unauthorized disclosure and modification; and

i. Requiring users to take, and having devices implement, specific measures to safeguard authenticators.

Control Enhancement:

(1) The information system, for password-based authentication:

(a) Enforces minimum password complexity of [Assignment: organization-defined requirements for case sensitivity, number of characters, mix of upper-case letters, lower-case letters, numbers, and special characters, including minimum requirements for each type];

(b) Enforces at least a [Assignment: organization-

References

CONTROL NAME

Threshold Compliance

DoDI 8500.2

NIST

800-53

Low-Impact Information System (FIPS 200 / NIST SP 800-53)

MAC III (DoDI 8500.2) (generally commercial best practices)

Explain Your Current Compliance OR Actions to Become Compliant

--- IA-6 AUTHENTICATOR

FEEDBACK

The information system obscures feedback of authentication information during the authentication process to protect the information from possible exploitation/use by unauthorized individuals.

--- IA-7 CRYPTOGRAPHIC

MODULE

AUTHENTICATION

The information system uses mechanisms for authentication to a cryptographic module that meet the requirements of applicable federal laws, Executive Orders, directives, policies, regulations, standards, and guidance for such authentication.

IA-8 IDENTIFICATION

AUTHENTICATION

(Non-Organizational Users)

The information system uniquely identifies and authenticates non-organizational users (or processes acting on behalf of non-organizational users).

Incident Response

VIIR-1

DCAR-1

IR-1 INCIDENT

RESPONSE

POLICY AND

PROCEDURES

The organization develops, disseminates, and reviews/updates

[Assignment: organization-defined frequency]:

a. A formal, documented incident response policy that addresses purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance; and

b. Formal, documented procedures to facilitate the implementation of the incident response policy and associated incident response controls.

VIIR-1 IR-2 INCIDENT

RESPONSE

TRAINING

The organization:

a. Trains personnel in their incident response roles and responsibilities with respect to the information system;

and

b. Provides refresher training [Assignment: organization-defined frequency].

References

CONTROL NAME

Threshold Compliance

DoDI 8500.2

NIST

800-53

Low-Impact Information System (FIPS 200 / NIST SP 800-53)

MAC III (DoDI 8500.2) (generally commercial best practices)

Explain Your Current Compliance OR Actions to Become Compliant

VIIR-1 IR-3 INCIDENT

RESPONSE

TESTING AND

EXERCISES

Not Applicable Optional: (May be applicable for NIST Moderate or High Impact, or DoD MAC I or MAC II)

VIIR-1

E3.3.9

IR-4 INCIDENT

HANDLING

The organization:

a. Implements an incident handling capability for security incidents that includes preparation, detection and analysis, containment, eradication, and recovery;

b. Coordinates incident handling activities with contingency planning activities; and

c. Incorporates lessons learned from ongoing incident handling activities into incident response procedures, training, and testing/exercises, and implements the resulting changes accordingly.

VIIR-1 IR-5 INCIDENT

MONITORING

The organization tracks and documents information system security incidents.

VIIR-1

E3.3.9

IR-6 INCIDENT

REPORTING

The organization:

a. Requires personnel to report suspected security incidents to the organizational incident response capability within [Assignment: organization-defined time-period]; and

b. Reports security incident information to designated authorities.

--- IR-7 INCIDENT

RESPONSE

ASSISTANCE

The organization provides an incident response support resource, integral to the organizational incident response capability, that offers advice and assistance to users of the information system for the handling and reporting of security incidents.

References

CONTROL NAME

Threshold Compliance

DoDI 8500.2

NIST

800-53

Low-Impact Information System (FIPS 200 / NIST SP 800-53)

MAC III (DoDI 8500.2) (generally commercial best practices)

Explain Your Current Compliance OR Actions to Become Compliant

IR-8 INCIDENT

RESPONSE PLAN

The organization:

a. Develops an incident response plan that:

- Provides the organization with a roadmap for implementing its incident response capability;

- Describes the structure and organization of the incident response capability;

- Provides a high-level approach for how the incident response capability fits into the overall organization;

- Meets the unique requirements of the organization, which relate to mission, size, structure, and functions;

- Defines reportable incidents;

- Provides metrics for measuring the incident response capability within the organization.

- Defines the resources and management support needed to effectively maintain and mature an incident response capability; and

- Is reviewed and approved by designated officials within the organization;

b. Distributes copies of the incident response plan to [Assignment: organization-defined list of incident response personnel (identified by name and/or by role) and organizational elements];

c. Reviews the incident response plan [Assignment:

organization-defined frequency];

d. Revises the incident response plan to address system/organizational changes or problems encountered during plan implementation, execution, or testing; and

e. Communicates incident response plan changes to [Assignment: organization-defined list of incident response personnel (identified by name and/or by role) and organizational elements].

References

CONTROL NAME

Threshold Compliance

DoDI 8500.2

NIST

800-53

Low-Impact Information System (FIPS 200 / NIST SP 800-53)

MAC III (DoDI 8500.2) (generally commercial best practices)

Explain Your Current Compliance OR Actions to Become Compliant

Maintenance

PRMP-1

MA-1 SYSTEM

MAINTENANCE

POLICY AND

PROCEDURES

The organization develops, disseminates, and periodically reviews/updates: (i) a formal, documented, information system maintenance policy that addresses purpose, scope, roles, responsibilities, and compliance;

and (ii) formal, documented procedures to facilitate the implementation of the information system maintenance policy and associated system maintenance controls.

--- MA-2 CONTROLLED

The organization:

(a) schedules, performs, documents and reviews records of maintenance and repairs on information system components in accordance with manufacturer or vendor specifications and/or organizational requirements;

(b) controls all maintenance activities, whether performed on site or remotely and whether the equipment is serviced on site or removed to another location; (c) requires that a designated official explicitly approve the removal of the information system or system components from organizational facilities for off-site maintenance or repairs;

(d) sanitizes equipment to remove all information from associated media prior to removal from organizational facilities for off-site maintenance or repairs; and

(e) checks all potentially impacted security controls to verify that the controls are still functioning properly following maintenance or repair actions.

--- MA-3 MAINTENANCE

TOOLS

References

CONTROL NAME

Threshold Compliance

DoDI 8500.2

NIST

800-53

Low-Impact Information System (FIPS 200 / NIST SP 800-53)

MAC III (DoDI 8500.2) (generally commercial best practices)

Explain Your Current Compliance OR Actions to

EBRP-1

MA-4 NON-LOCAL

The organization:

a. Authorizes, monitors, and controls non-local maintenance and diagnostic activities;

b. Allows the use of non-local maintenance and diagnostic tools only as consistent with organizational policy and documented in the security plan for the information system;

c. Employs strong identification and authentication techniques in the establishment of non-local maintenance and diagnostic sessions;

d. Maintains records for non-local maintenance and diagnostic activities; and

e. Terminates all sessions and network connections when non-local maintenance is completed.

PRMP-1 MA-5 MAINTENANCE

PERSONNEL

The organization:

a. Establishes a process for maintenance personnel authorization and maintains a current list of authorized maintenance organizations or personnel; and

b. Ensures that personnel performing maintenance on the information system have required access authorizations or designates organizational personnel with required access authorizations and technical competence deemed necessary to supervise information system maintenance when maintenance personnel do not possess the required access authorizations.

COMS-1

COSP-1

MA-6 TIMELY

MAINTENANCE

Not Applicable Optional: (May be applicable for NIST Moderate or

Media Protection

References

CONTROL NAME

Threshold Compliance

DoDI 8500.2

NIST

800-53

Low-Impact Information System (FIPS 200 / NIST SP 800-53)

MAC III (DoDI 8500.2) (generally commercial best practices)

Explain Your Current Compliance OR Actions to Become Compliant

PESP-1

MP-1 MEDIA

PROTECTION

POLICY AND

PROCEDURES

The organization develops, disseminates, and reviews/updates [Assignment: organization-defined frequency]:

a. A formal, documented media protection policy that addresses purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance; and

b. Formal, documented procedures to facilitate the implementation of the media protection policy and associated media protection controls.

PEDI-1

PEPF-1

MP-2 MEDIA ACCESS The organization restricts access to [Assignment:

organization-defined types of digital and non-digital media] to [Assignment: organization-defined list of authorized individuals] using [Assignment: organization-defined security measures].

ECML-1

MP-3 MEDIA MARKING Not Applicable Optional: (May be applicable for NIST Moderate or

PESS-1

MP-4 MEDIA STORAGE Not Applicable Optional: (May be applicable for NIST Moderate or

--- MP-5 MEDIA

TRANSPORT

Not Applicable Optional: (May be applicable for NIST Moderate or High Impact, or DoD MAC I or MAC II)

PECS-1

PEDD-1

MP-6 MEDIA

SANITIZATION

The organization sanitizes information system media, both digital and non-digital, prior to disposal, release out of organizational control, or release for reuse.

PEDD-1

MP-7 MEDIA

DESTRUCTION

AND DISPOSAL

Withdrawn from SP 800-53, Rev. 3 Optional: (May be applicable for DoD MAC I or MAC II)

References

CONTROL NAME

Threshold Compliance

DoDI 8500.2

NIST

800-53

Low-Impact Information System (FIPS 200 / NIST SP 800-53)

MAC III (DoDI 8500.2) (generally commercial best practices)

Explain Your Current Compliance OR Actions to Become Compliant

Physical and Environmental Protection

PETN-1

PE-1 PHYSICAL AND

ENVIRONMENTAL

PROTECTION

POLICY AND

PROCEDURES

The organization develops, disseminates, and reviews/updates [Assignment: organization-defined frequency]:

a. A formal, documented physical and environmental protection policy that addresses purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance; and

b. Formal, documented procedures to facilitate the implementation of the physical and environmental protection policy and associated physical and environmental protection controls.

PECF-1

PE-2 PHYSICAL

ACCESS

AUTHORIZATIONS

The organization:

a. Develops and keeps current a list of personnel with authorized access to the facility where the information system resides (except for those areas within the facility officially designated as publicly accessible);

b. Issues authorization credentials;

c. Reviews and approves the access list and authorization credentials [Assignment: organization-defined frequency], removing from the access list personnel no longer requiring access.

References

CONTROL NAME

Threshold Compliance

DoDI 8500.2

NIST

800-53

Low-Impact Information System (FIPS 200 / NIST SP 800-53)

MAC III (DoDI 8500.2) (generally commercial best practices)

Explain Your Current Compliance OR Actions to

PEPF-1

PE-3 PHYSICAL

ACCESS

CONTROL

The organization:

a. Enforces physical access authorizations for all physical access points (including designated entry/exit points) to the facility where the information system resides (excluding those areas within the facility officially designated as publicly accessible);

b. Verifies individual access authorizations before granting access to the facility;

c. Controls entry to the facility containing the information system using physical access devices and/or guards;

d. Controls access to areas officially designated as publicly accessible in accordance with the organization’s assessment of risk;

e. Secures keys, combinations, and other physical access devices;

f. Inventories physical access devices [Assignment:

organization-defined frequency]; and

g. Changes combinations and keys [Assignment:

organization-defined frequency] and when keys are lost, combinations are compromised, or individuals are transferred or terminated.

PE-4 ACCESS

CONTROL FOR

TRANSMISSION

MEDIUM

Not Applicable Optional: (May be applicable for NIST Moderate or High Impact, or DoD MAC I or MAC II)

PEDI-1

PEPF-1

PE-5 ACCESS

CONTROL FOR

OUTPUT DEVICES

References

CONTROL NAME

Threshold Compliance

DoDI 8500.2

NIST

800-53

Low-Impact Information System (FIPS 200 / NIST SP 800-53)

MAC III (DoDI 8500.2) (generally commercial best practices)

Explain Your Current Compliance OR Actions to Become Compliant

PEPF-2 PE-6 MONITORING

PHYSICAL

ACCESS

The organization:

a. Monitors physical access to the information system to detect and respond to physical security incidents;

b. Reviews physical access logs [Assignment:

organization-defined frequency]; and

c. Coordinates results of reviews and investigations with the organization’s incident response capability.

PEVC-1

PE-7 VISITOR CONTROL The organization controls physical access to the information system by authenticating visitors before authorizing access to the facility where the information system resides other than areas designated as publicly accessible.

PEPF-2

PEVC-1

PE-8 ACCESS

RECORDS

The organization:

a. Maintains visitor access records to the facility where the information system resides (except for those areas within the facility officially designated as publicly accessible); and

b. Reviews visitor access records [Assignment:

--- PE-9 POWER

EQUIPMENT AND

POWER CABLING

Not Applicable Optional: (May be applicable for NIST Moderate or High Impact, or DoD MAC I or MAC II)

PEMS-1

PE-10 EMERGENCY

SHUTOFF

Not Applicable Optional: (May be applicable for NIST Moderate or High Impact, or DoD MAC I or MAC II)

COPS-1

COPS-2

COPS-3

PE-11 EMERGENCY

POWER

References

CONTROL NAME

Threshold Compliance

DoDI 8500.2

NIST

800-53

Low-Impact Information System (FIPS 200 / NIST SP 800-53)

MAC III (DoDI 8500.2) (generally commercial best practices)

Explain Your Current Compliance OR Actions to

PEEL-1

PE-12 EMERGENCY

LIGHTING

The organization employs and maintains automatic emergency lighting for the information system that activates in the event of a power outage or disruption and that covers emergency exits and evacuation routes within the facility.

PEFD-1

PEFS-1

PE-13 FIRE PROTECTION The organization employs and maintains fire suppression and detection devices/systems for the information system that are supported by an independent energy source.

PEHC-1

PETC-1

PE-14 TEMPERATURE

AND HUMIDITY

CONTROLS

The organization:

a. Maintains temperature and humidity levels within the facility where the information system resides at [Assignment: organization-defined acceptable levels];

and

b. Monitors temperature and humidity levels [Assignment: organization-defined frequency].

--- PE-15 WATER DAMAGE

The organization protects the information system from damage resulting from water leakage by providing master shutoff valves that are accessible, working properly, and known to key personnel.

--- PE-16 DELIVERY AND

REMOVAL

The organization authorizes, monitors, and controls [Assignment: organization-defined types of information system components] entering and exiting the facility and maintains records of those items.

EBRU-1 PE-17 ALTERNATE

WORK SITE

References

CONTROL NAME

Threshold Compliance

DoDI 8500.2

NIST

800-53

Low-Impact Information System (FIPS 200 / NIST SP 800-53)

MAC III (DoDI 8500.2) (generally commercial best practices)

Explain Your Current Compliance OR Actions to Become Compliant

PE-18 LOCATION OF

INFORMATION

SYSTEM

COMPONENTS

Not Applicable Optional: (May be applicable for NIST Moderate or High Impact, or DoD MAC I or MAC II)

PE-19 INFORMATION

LEAKAGE

Not Applicable Optional: (May be applicable for DoD MAC I or MAC II)

Planning

E3.4.6

PL-1 SECURITY

PLANNING POLICY

AND

PROCEDURES

The organization develops, disseminates, and reviews/updates [Assignment: organization-defined frequency]:

a. A formal, documented security planning policy that addresses purpose, scope, roles, responsibilities, management commitment, coordination…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .