CS2 FO RFP Sec J Attachment J-3_Final.pdf
PDF 1 MB Posted
- Attached to
- FCSA CS2 Full & Open Solicitation Federal contract opportunity
- Solicitation number
- CS2_(QTA)(010)(CTA)(0003)
- Issued by
- GSA Federal Acquisition Service
About this file
CS2 Section J Attachment J-3
View the file
Other files for this federal contract opportunity
Show all 50
FCSA CS2 Full & Open Solicitation has more files on GovTribe.
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
QTA-010-CTA-0003
ATTACHMENT J-3
Security Controls for Information Systems
Definitions from NIST Special Publication 800-53
References
CONTROL NAME
Task Order Requirement
DoDI 8500.2
NIST
800-53
High-Impact Information System (FIPS Pub 200 / NIST SP 800-53)
MAC I (DoDI 8500.2)
Moderate-Impact Information System (FIPS Pub 200 / NIST SP
800-53) MAC II (DoDI 8500.2)
Low-Impact Information System (FIPS Pub 200 / NIST SP 800-53)
MAC III (DoDI 8500.2) (generally commercial best practices)
FIPS Pub 200 Definition for High/Moderate/Low Impact Information System:
FIPS Publication 199 requires agencies to categorize their information systems as low-impact, moderate-impact, or high-impact for the security objectives of confidentiality, integrity, and availability.
Since the potential impact values for confidentiality, integrity, and availability may not always be the same for a particular information system, the high water mark concept must be used to determine the overall impact level of the information system. Thus, a low-impact system is an information system in which all three of the security objectives are low. A moderate-impact system is an information system in which at least one of the security objectives is moderate and no security objective is greater than moderate. And finally, a high-impact system is an information system in which at least one security objective is high.
The determination of information system impact levels must be accomplished prior to the consideration of minimum security requirements and the selection of appropriate security controls for those information systems.
DoDI 8500.2 Mission Assurance Category (MAC) Definitions:
Systems handling information that is determined to be vital to the operational readiness or mission effectiveness of deployed and contingency forces in terms of both content and timeliness.
The consequences of loss of integrity or availability of a MAC I system are unacceptable and could include the immediate and sustained loss of mission effectiveness.
Mission Assurance Category I systems require the most stringent protection measures.
Systems handling information that is important to the support of deployed and contingency forces. The consequences of loss of integrity are unacceptable. Loss of availability is difficult to deal with and can only be tolerated for a short time. The consequences could include delay or degradation in providing important support services or commodities that may seriously impact mission effectiveness or operational readiness.
Mission Assurance Category II systems require additional safeguards beyond best practices to ensure assurance.
Systems handling information that is necessary for the conduct of day-to-day business, but does not materially affect support to deployed or contingency forces in the short-term. The consequences of loss of integrity or availability can be tolerated or overcome without significant impacts on mission effectiveness or operational readiness. The consequences could include the delay or degradation of services or commodities enabling routine activities.
Mission Assurance Category III systems require protective measures, techniques, or procedures generally
CONTROL NAME
Task Order Requirement
DoDI 8500.2
NIST
800-53
High-Impact Information System (FIPS Pub 200 / NIST SP 800-53)
MAC I (DoDI 8500.2)
Moderate-Impact Information System (FIPS Pub 200 / NIST SP
800-53) MAC II (DoDI 8500.2)
Low-Impact Information System (FIPS Pub 200 / NIST SP 800-53)
MAC III (DoDI 8500.2) (generally commercial best practices) commensurate with commercial best practices.
Access Control
ECAN-1
ECPA-1
PRAS-1
DCAR-1
AC-1 ACCESS
CONTROL POLICY
AND
PROCEDURES
The organization develops, disseminates, and reviews/updates [Assignment: organization-defined frequency]:
a. A formal, documented access control policy that addresses purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance;
and
b. Formal, documented procedures to facilitate the implementation of the access control policy and associated access controls.
The organization develops, disseminates, and reviews/updates [Assignment: organization-defined frequency]:
a. A formal, documented access control policy that addresses purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance; and
b. Formal, documented procedures to facilitate the implementation of the access control policy and associated access controls.
The organization develops, disseminates, and reviews/updates [Assignment: organization-defined frequency]:
a. A formal, documented access control policy that addresses purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance; and
b. Formal, documented procedures to facilitate the implementation of the access control policy and associated access controls.
IAAC-1 AC-2 ACCOUNT
MANAGEMENT
The organization manages information system accounts, including:
a. Identifying account types (i.e., individual, group, system, application, guest/anonymous, and temporary);
b. Establishing conditions for group membership;
c. Identifying authorized users of the information system and specifying access privileges;
d. Requiring appropriate approvals for requests to establish accounts;
e. Establishing, activating, modifying, disabling, and removing accounts;
f. Specifically authorizing and
The organization manages information system accounts, including:
a. Identifying account types (i.e., individual, group, system, application, guest/anonymous, and temporary);
b. Establishing conditions for group membership;
c. Identifying authorized users of the information system and specifying access privileges;
d. Requiring appropriate approvals for requests to establish accounts;
e. Establishing, activating, modifying, disabling, and removing accounts;
The organization manages information system accounts, including:
a. Identifying account types (i.e., individual, group, system, application, guest/anonymous, and temporary);
b. Establishing conditions for group membership;
c. Identifying authorized users of the information system and specifying access privileges;
d. Requiring appropriate approvals for requests to establish accounts;
e. Establishing, activating, CONTROL NAME
Task Order Requirement
DoDI 8500.2
NIST
800-53
High-Impact Information System (FIPS Pub 200 / NIST SP 800-53)
MAC I (DoDI 8500.2)
Moderate-Impact Information System (FIPS Pub 200 / NIST SP
800-53) MAC II (DoDI 8500.2)
Low-Impact Information System (FIPS Pub 200 / NIST SP 800-53)
MAC III (DoDI 8500.2) (generally commercial best practices) monitoring the use of guest/anonymous and temporary accounts;
g. Notifying account managers when temporary accounts are no longer required and when information system users are terminated, transferred, or information system usage or need-to-know/need-to-share changes;
h. Deactivating: (i) temporary accounts that are no longer required; and (ii) accounts of terminated or transferred users;
i. Granting access to the system based on: (i) a valid access authorization; (ii) intended system usage; and (iii) other attributes as required by the organization or associated missions/business functions; and
j. Reviewing accounts [Assignment:
organization-defined frequency].
Control Enhancements:
(1) The organization employs automated mechanisms to support the management of information system accounts.
(2) The information system automatically terminates temporary and emergency accounts after [Assignment:
organization-defined time period for each type of account].
(3) The information system
f. Specifically authorizing and monitoring the use of guest/anonymous and temporary accounts;
g. Notifying account managers when temporary accounts are no longer required and when information system users are terminated, transferred, or information system usage or need-to-know/need-to-share changes;
h. Deactivating: (i) temporary accounts that are no longer required;
and (ii) accounts of terminated or transferred users;
i. Granting access to the system based on: (i) a valid access authorization; (ii) intended system usage; and (iii) other attributes as required by the organization or associated missions/business functions; and automated mechanisms to support the management of information system accounts.
(2) The information system automatically terminates temporary modifying, disabling, and removing accounts;
f. Specifically authorizing and monitoring the use of guest/anonymous and temporary accounts;
g. Notifying account managers when temporary accounts are no longer required and when information system users are terminated, transferred, or information system usage or need-to-know/need-to-share changes;
h. Deactivating: (i) temporary accounts that are no longer required; and (ii) accounts of terminated or transferred users;
i. Granting access to the system based on: (i) a valid access authorization; (ii) intended system usage; and (iii) other attributes as required by the organization or associated missions/business functions; and
CONTROL NAME
Task Order Requirement
DoDI 8500.2
NIST
800-53
High-Impact Information System (FIPS Pub 200 / NIST SP 800-53)
MAC I (DoDI 8500.2)
Moderate-Impact Information System (FIPS Pub 200 / NIST SP
800-53) MAC II (DoDI 8500.2)
Low-Impact Information System (FIPS Pub 200 / NIST SP 800-53)
MAC III (DoDI 8500.2) (generally commercial best practices) automatically disables inactive accounts after [Assignment: organization-defined time period].
(4) The information system automatically audits account creation, modification, disabling, and termination actions and notifies, as required, appropriate individuals.
and emergency accounts after [Assignment: organization-defined time period for each type of account].
(3) The information system automatically disables inactive accounts after [Assignment:
organization-defined time period].
(4) The information system automatically audits account creation, modification, disabling, and termination actions and notifies, as required, appropriate individuals.
DCFA-1
ECAN-1
EBRU-1
PRNK-1
ECCD-1
ECSD-2
AC-3 ACCESS
ENFORCEMENT
The information system enforces approved authorizations for logical access to the system in accordance with applicable policy.
The information system enforces approved authorizations for logical access to the system in accordance with applicable policy.
The information system enforces approved authorizations for logical access to the system in accordance with applicable policy.
EBBD-1
EBBD-2
AC-4 INFORMATION
FLOW
ENFORCEMENT
The information system enforces assigned authorizations for controlling the flow of information within the system and between interconnected systems in accordance with applicable policy
The information system enforces assigned authorizations for controlling the flow of information within the system and between interconnected systems in accordance with applicable policy.
Not Applicable
ECLP-1 AC-5 SEPARATION OF
DUTIES
The organization:
a. Separates duties of individuals as necessary, to prevent malevolent activity without collusion;
The organization:
a. Separates duties of individuals as necessary, to prevent malevolent activity without collusion;
Not Applicable
CONTROL NAME
Task Order Requirement
DoDI 8500.2
NIST
800-53
High-Impact Information System (FIPS Pub 200 / NIST SP 800-53)
MAC I (DoDI 8500.2)
Moderate-Impact Information System (FIPS Pub 200 / NIST SP
800-53) MAC II (DoDI 8500.2)
Low-Impact Information System (FIPS Pub 200 / NIST SP 800-53)
MAC III (DoDI 8500.2) (generally commercial best practices)
b. Documents separation of duties; and
c. Implements separation of duties through assigned information system access authorizations.
b. Documents separation of duties;
and
c. Implements separation of duties through assigned information system access authorizations.
ECLP-1 AC-6 LEAST PRIVILEGE The organization employs the concept of least privilege, allowing only authorized accesses for users (and processes acting on behalf of users) which are necessary to accomplish assigned tasks in accordance with organizational missions and business functions.
Control Enhancements:
(1) The organization explicitly authorizes access to [Assignment:
organization-defined list of security functions (deployed in hardware, software, and firmware) and security-relevant information].
(2) The organization requires that users of information system accounts, or roles, with access to [Assignment:
organization-defined list of security functions or security-relevant information], use non-privileged accounts, or roles, when accessing other system functions, and if feasible, audits any use of privileged accounts, or roles, for such functions.
The organization employs the concept of least privilege, allowing only authorized accesses for users (and processes acting on behalf of users) which are necessary to accomplish assigned tasks in accordance with organizational missions and business functions.
Control Enhancements:
(1) The organization explicitly authorizes access to [Assignment:
organization-defined list of security functions (deployed in hardware, software, and firmware) and security-relevant information].
(2) The organization requires that users of information system accounts, or roles, with access to [Assignment:
organization-defined list of security functions or security-relevant information], use non-privileged accounts, or roles, when accessing other system functions, and if feasible, audits any use of privileged accounts, or roles, for such functions.
CONTROL NAME
Task Order Requirement
DoDI 8500.2
NIST
800-53
High-Impact Information System (FIPS Pub 200 / NIST SP 800-53)
MAC I (DoDI 8500.2)
Moderate-Impact Information System (FIPS Pub 200 / NIST SP
800-53) MAC II (DoDI 8500.2)
Low-Impact Information System (FIPS Pub 200 / NIST SP 800-53)
MAC III (DoDI 8500.2) (generally commercial best practices)
ECLO-1 AC-7 UNSUCCESSFUL
LOGIN ATTEMPTS
The information system:
a. Enforces a limit of [Assignment:
organization-defined number] consecutive invalid access attempts by a user during a [Assignment:
organization-defined time period]; and
b. Automatically [Selection: locks the account/node for an [Assignment:
organization-defined time period]; locks the account/node until released by an administrator; delays next login prompt according to [Assignment: organization-defined delay algorithm]] when the maximum number of unsuccessful attempts is exceeded. The control applies regardless of whether the login occurs via a local or network connection.
The information system:
a. Enforces a limit of [Assignment:
organization-defined number] consecutive invalid access attempts by a user during a [Assignment:
organization-defined time period]; and
b. Automatically [Selection: locks the account/node for an [Assignment:
organization-defined time period];
locks the account/node until released by an administrator; delays next login prompt according to [Assignment:
organization-defined delay algorithm]] when the maximum number of unsuccessful attempts is exceeded.
The control applies regardless of whether the login occurs via a local or network connection.
The information system:
a. Enforces a limit of [Assignment:
organization-defined number] consecutive invalid access attempts by a user during a [Assignment:
organization-defined time period];
and
b. Automatically [Selection: locks the account/node for an [Assignment: organization-defined time period]; locks the account/node until released by an administrator;
delays next login prompt according to [Assignment: organization-defined delay algorithm]] when the maximum number of unsuccessful attempts is exceeded. The control applies regardless of whether the login occurs via a local or network connection.
ECWM-
AC-8 SYSTEM USE
NOTIFICATION
The information system:
a. Displays an approved system use notification message or banner before granting access to the system that provides privacy and security notices consistent with applicable federal laws, Executive Orders, directives, policies, regulations, standards, and guidance and states that: (i) users are accessing a U.S. Government information system;
(ii) system usage may be monitored, recorded, and subject to audit; (iii) unauthorized use of the system is
The information system:
a. Displays an approved system use notification message or banner before granting access to the system that provides privacy and security notices consistent with applicable federal laws, Executive Orders, directives, policies, regulations, standards, and guidance and states that: (i) users are accessing a U.S. Government information system; (ii) system usage may be monitored, recorded, and subject to audit; (iii) unauthorized use
The information system:
a. Displays an approved system use notification message or banner before granting access to the system that provides privacy and security notices consistent with applicable federal laws, Executive Orders, directives, policies, regulations, standards, and guidance and states that: (i) users are accessing a U.S. Government information system; (ii) system usage may be monitored, recorded, CONTROL NAME
Task Order Requirement
DoDI 8500.2
NIST
800-53
High-Impact Information System (FIPS Pub 200 / NIST SP 800-53)
MAC I (DoDI 8500.2)
Moderate-Impact Information System (FIPS Pub 200 / NIST SP
800-53) MAC II (DoDI 8500.2)
Low-Impact Information System (FIPS Pub 200 / NIST SP 800-53)
MAC III (DoDI 8500.2) (generally commercial best practices) prohibited and subject to criminal and civil penalties; and (iv) use of the system indicates consent to monitoring and recording;
b. Retains the notification message or banner on the screen until users take explicit actions to log on to or further access the information system; and
c. For publicly accessible systems: (i) displays the system use information when appropriate, before granting further access; (ii) displays references, if any, to monitoring, recording, or auditing that are consistent with privacy accommodations for such systems that generally prohibit those activities; and
(iii) includes in the notice given to public users of the information system, a description of the authorized uses of the system.
of the system is prohibited and subject to criminal and civil penalties;
and (iv) use of the system indicates consent to monitoring and recording;
b. Retains the notification message or banner on the screen until users take explicit actions to log on to or further access the information system; and
c. For publicly accessible systems: (i) displays the system use information when appropriate, before granting further access; (ii) displays references, if any, to monitoring, recording, or auditing that are consistent with privacy accommodations for such systems that generally prohibit those activities;
and (iii) includes in the notice given to public users of the information system, a description of the authorized uses of the system.
and subject to audit; (iii) unauthorized use of the system is prohibited and subject to criminal and civil penalties; and (iv) use of the system indicates consent to monitoring and recording;
b. Retains the notification message or banner on the screen until users take explicit actions to log on to or further access the information system; and
c. For publicly accessible systems:
(i) displays the system use information when appropriate, before granting further access; (ii) displays references, if any, to monitoring, recording, or auditing that are consistent with privacy accommodations for such systems that generally prohibit those activities; and (iii) includes in the notice given to public users of the information system, a description of the authorized uses of the system.
AC-9 PREVIOUS LOGON
(ACCESS)
NOTIFICATION
Not Applicable Not Applicable Not Applicable
ECLO-1 AC-10 CONCURRENT
SESSION
CONTROL
The information system limits the number of concurrent sessions for each system account to [Assignment:
organization-defined number].
Not Applicable Not Applicable
CONTROL NAME
Task Order Requirement
DoDI 8500.2
NIST
800-53
High-Impact Information System (FIPS Pub 200 / NIST SP 800-53)
MAC I (DoDI 8500.2)
Moderate-Impact Information System (FIPS Pub 200 / NIST SP
800-53) MAC II (DoDI 8500.2)
Low-Impact Information System (FIPS Pub 200 / NIST SP 800-53)
MAC III (DoDI 8500.2) (generally commercial best practices)
PESL-1 AC-11 SESSION LOCK
The information system:
a. Prevents further access to the system by initiating a session lock after [Assignment: organization-defined time period] of inactivity or upon receiving a request from a user; and
b. Retains the session lock until the user reestablishes access using established identification and authentication procedures.
The information system:
a. Prevents further access to the system by initiating a session lock after [Assignment: organization-defined time period] of inactivity or upon receiving a request from a user;
and
b. Retains the session lock until the user reestablishes access using established identification and authentication procedures.
Not Applicable
--- AC-12 SESSION
TERMINATION
Withdrawn: Incorporated into SC-10. Withdrawn: Incorporated into SC-10. Withdrawn: Incorporated into SC-10
ECAT-1
ECAT-2
E3.3.9
AC-13 SUPERVISION AND
REVIEW —
ACCESS
CONTROL
Withdrawn: Incorporated into AC-2 and
AU-6.
Withdrawn: Incorporated into AC-2 and AU-6.
Withdrawn: Incorporated into AC-2 and AU-6.
--- AC-14 PERMITTED
ACTIONS
WITHOUT
IDENTIFICATION
OR
AUTHENTICATION
The organization:
a. Identifies specific user actions that can be performed on the information system without identification or authentication; and
b. Documents and provides supporting rationale in the security plan for the information system, user actions not requiring identification and authentication.
Control Enhancement:
(1) The organization permits actions to be performed without identification and
The organization:
a. Identifies specific user actions that can be performed on the information system without identification or authentication; and
b. Documents and provides supporting rationale in the security plan for the information system, user actions not requiring identification and authentication.
Control Enhancement:
(1) The organization permits actions to be performed without identification
The organization:
a. Identifies specific user actions that can be performed on the information system without identification or authentication; and
b. Documents and provides supporting rationale in the security plan for the information system, user actions not requiring identification and authentication.
CONTROL NAME
Task Order Requirement
DoDI 8500.2
NIST
800-53
High-Impact Information System (FIPS Pub 200 / NIST SP 800-53)
MAC I (DoDI 8500.2)
Moderate-Impact Information System (FIPS Pub 200 / NIST SP
800-53) MAC II (DoDI 8500.2)
Low-Impact Information System (FIPS Pub 200 / NIST SP 800-53)
MAC III (DoDI 8500.2) (generally commercial best practices) authentication only to the extent necessary to accomplish mission/business objectives.
and authentication only to the extent necessary to accomplish mission/business objectives.
ECML-1 AC-15 AUTOMATED
MARKING
Withdrawn: Incorporated into MP-3. Withdrawn: Incorporated into MP-3. Withdrawn: Incorporated into MP-3.
AC-16 SECURITY
ATTRIBUTES
Not Applicable Not Applicable Not Applicable
EBRP-1
EBRU-1
AC-17 REMOTE ACCESS
The organization:
a. Documents allowed methods of remote access to the information system;
b. Establishes usage restrictions and implementation guidance for each allowed remote access method;
c. Monitors for unauthorized remote access to the information system;
d. Authorizes remote access to the information system prior to connection;
and
e. Enforces requirements for remote connections to the information system.
Control Enhancements:
(1) The organization employs automated mechanisms to facilitate the monitoring and control of remote access methods.
(2) The organization uses cryptography to protect the confidentiality and
The organization:
a. Documents allowed methods of remote access to the information system;
b. Establishes usage restrictions and implementation guidance for each allowed remote access method;
c. Monitors for unauthorized remote access to the information system;
d. Authorizes remote access to the information system prior to connection; and
e. Enforces requirements for remote connections to the information system.
Control Enhancements:
(1) The organization employs automated mechanisms to facilitate the monitoring and control of remote access methods.
(2) The organization uses
The organization:
a. Documents allowed methods of remote access to the information system;
b. Establishes usage restrictions and implementation guidance for each allowed remote access method;
c. Monitors for unauthorized remote access to the information system;
d. Authorizes remote access to the information system prior to connection; and
e. Enforces requirements for remote connections to the information system.
CONTROL NAME
Task Order Requirement
DoDI 8500.2
NIST
800-53
High-Impact Information System (FIPS Pub 200 / NIST SP 800-53)
MAC I (DoDI 8500.2)
Moderate-Impact Information System (FIPS Pub 200 / NIST SP
800-53) MAC II (DoDI 8500.2)
Low-Impact Information System (FIPS Pub 200 / NIST SP 800-53)
MAC III (DoDI 8500.2) (generally commercial best practices) integrity of remote access sessions.
(3) The information system routes all remote accesses through a limited number of managed access control points.
(4) The organization authorizes the execution of privileged commands and access to security-relevant information via remote access only for compelling operational needs and documents the rationale for such access in the security plan for the information system.
(5) The organization monitors for unauthorized remote connections to the information system [Assignment:
organization-defined frequency], and takes appropriate action if an unauthorized connection is discovered.
(7) The organization ensures that remote sessions for accessing [Assignment: organization-defined list of security functions and security-relevant information] employ [Assignment:
organization-defined additional security measures] and are audited.
(8) The organization disables networking protocols within the information system deemed to be nonsecure except for explicitly identified components in support of specific operational requirements.
cryptography to protect the confidentiality and integrity of remote access sessions.
(3) The information system routes all remote accesses through a limited number of managed access control points.
(4) The organization authorizes the execution of privileged commands and access to security-relevant information via remote access only for compelling operational needs and documents the rationale for such access in the security plan for the information system.
(5) The organization monitors for unauthorized remote connections to the information system [Assignment:
organization-defined frequency], and takes appropriate action if an unauthorized connection is discovered.
(7) The organization ensures that remote sessions for accessing [Assignment: organization-defined list of security functions and security-relevant information] employ [Assignment: organization-defined additional security measures] and are audited.
(8) The organization disables networking protocols within the information system deemed to be
CONTROL NAME
Task Order Requirement
DoDI 8500.2
NIST
800-53
High-Impact Information System (FIPS Pub 200 / NIST SP 800-53)
MAC I (DoDI 8500.2)
Moderate-Impact Information System (FIPS Pub 200 / NIST SP
800-53) MAC II (DoDI 8500.2)
Low-Impact Information System (FIPS Pub 200 / NIST SP 800-53)
MAC III (DoDI 8500.2) (generally commercial best practices) nonsecure except for explicitly identified components in support of specific operational requirements.
ECCT-1
ECWN-1
AC-18 WIRELESS
ACCESS
The organization:
a. Establishes usage restrictions and implementation guidance for wireless access;
b. Monitors for unauthorized wireless access to the information system;
c. Authorizes wireless access to the information system prior to connection;
and
d. Enforces requirements for wireless connections to the information system.
Control Enhancements:
(1) The information system protects wireless access to the system using authentication and encryption.
(2) The organization monitors for unauthorized wireless connections to the information system, including scanning for unauthorized wireless access points [Assignment:
organization-defined frequency], and takes appropriate action if an unauthorized connection is discovered.
(4) The organization does not allow users to independently configure wireless networking capabilities.
(5) The organization confines wireless
The organization:
a. Establishes usage restrictions and implementation guidance for wireless access;
b. Monitors for unauthorized wireless access to the information system;
c. Authorizes wireless access to the information system prior to connection; and
d. Enforces requirements for wireless connections to the information system.
Control Enhancement:
(1) The information system protects wireless access to the system using authentication and encryption.
The organization:
a. Establishes usage restrictions and implementation guidance for wireless access;
b. Monitors for unauthorized wireless access to the information system;
c. Authorizes wireless access to the information system prior to connection; and
d. Enforces requirements for wireless connections to the information system.
CONTROL NAME
Task Order Requirement
DoDI 8500.2
NIST
800-53
High-Impact Information System (FIPS Pub 200 / NIST SP 800-53)
MAC I (DoDI 8500.2)
Moderate-Impact Information System (FIPS Pub 200 / NIST SP
800-53) MAC II (DoDI 8500.2)
Low-Impact Information System (FIPS Pub 200 / NIST SP 800-53)
MAC III (DoDI 8500.2) (generally commercial best practices) communications to organization-controlled boundaries.
ECWN-1 AC-19 ACCESS
CONTROL FOR
MOBILE DEVICES
The organization:
a. Establishes usage restrictions and implementation guidance for organization-controlled mobile devices;
b. Authorizes connection of mobile devices meeting organizational usage restrictions and implementation guidance to organizational information systems;
c. Monitors for unauthorized connections of mobile devices to organizational information systems;
d. Enforces requirements for the connection of mobile devices to organizational information systems;
e. Disables information system functionality that provides the capability for automatic execution of code on mobile devices without user direction;
f. Issues specially configured mobile devices to individuals traveling to locations that the organization deems to be of significant risk in accordance with organizational policies and procedures;
and
g. Applies [Assignment: organization-defined inspection and preventative measures] to mobile devices returning from locations that the organization deems to be of significant risk in
The organization:
a. Establishes usage restrictions and implementation guidance for organization-controlled mobile devices;
b. Authorizes connection of mobile devices meeting organizational usage restrictions and implementation guidance to organizational information systems;
c. Monitors for unauthorized connections of mobile devices to organizational information systems;
d. Enforces requirements for the connection of mobile devices to organizational information systems;
e. Disables information system functionality that provides the capability for automatic execution of code on mobile devices without user direction;
f. Issues specially configured mobile devices to individuals traveling to locations that the organization deems to be of significant risk in accordance with organizational policies and procedures; and
g. Applies [Assignment: organization-defined inspection and preventative measures] to mobile devices returning
The organization:
a. Establishes usage restrictions and implementation guidance for organization-controlled mobile devices;
b. Authorizes connection of mobile devices meeting organizational usage restrictions and implementation guidance to organizational information systems;
c. Monitors for unauthorized connections of mobile devices to organizational information systems;
d. Enforces requirements for the connection of mobile devices to organizational information systems;
e. Disables information system functionality that provides the capability for automatic execution of code on mobile devices without user direction;
f. Issues specially configured mobile devices to individuals traveling to locations that the organization deems to be of significant risk in accordance with organizational policies and procedures; and
g. Applies [Assignment:
organization-defined inspection and preventative measures] to mobile
CONTROL NAME
Task Order Requirement
DoDI 8500.2
NIST
800-53
High-Impact Information System (FIPS Pub 200 / NIST SP 800-53)
MAC I (DoDI 8500.2)
Moderate-Impact Information System (FIPS Pub 200 / NIST SP
800-53) MAC II (DoDI 8500.2)
Low-Impact Information System (FIPS Pub 200 / NIST SP 800-53)
MAC III (DoDI 8500.2) (generally commercial best practices) accordance with organizational policies and procedures.
Control Enhancements:
(1) The organization restricts the use of writable, removable media in organizational information systems.
(2) The organization prohibits the use of personally owned, removable media in organizational information systems.
(3) The organization prohibits the use of removable media in organizational information systems when the media has no identifiable owner.
from locations that the organization deems to be of significant risk in accordance with organizational policies and procedures.
(1) The organization restricts the use of writable, removable media in organizational information systems.
(2) The organization prohibits the use of personally owned, removable media in organizational information systems.
(3) The organization prohibits the use of removable media in organizational information systems when the media has no identifiable owner.
devices returning from locations that the organization deems to be of significant risk in accordance with organizational policies and procedures.
--- AC-20 USE OF
EXTERNAL
INFORMATION
SYSTEMS
The organization establishes terms and conditions, consistent with any trust relationships established with other organizations owning, operating, and/or maintaining external information systems, allowing authorized individuals to:
a. Access the information system from the external information systems; and
b. Process, store, and/or transmit organization-controlled information using the external information systems.
Control Enhancements:
The organization establishes terms and conditions, consistent with any trust relationships established with other organizations owning, operating, and/or maintaining external information systems, allowing authorized individuals to:
a. Access the information system from the external information systems; and
b. Process, store, and/or transmit organization-controlled information using the external information systems.
The organization establishes terms and conditions, consistent with any trust relationships established with other organizations owning, operating, and/or maintaining external information systems, allowing authorized individuals to:
a. Access the information system from the external information systems; and
b. Process, store, and/or transmit organization-controlled information using the external information
CONTROL NAME
Task Order Requirement
DoDI 8500.2
NIST
800-53
High-Impact Information System (FIPS Pub 200 / NIST SP 800-53)
MAC I (DoDI 8500.2)
Moderate-Impact Information System (FIPS Pub 200 / NIST SP
800-53) MAC II (DoDI 8500.2)
Low-Impact Information System (FIPS Pub 200 / NIST SP 800-53)
MAC III (DoDI 8500.2) (generally commercial best practices)
(1) The organization permits authorized individuals to use an external information system to access the information system or to process, store, or transmit organization-controlled information only when the organization:
(a) Can verify the implementation of required security controls on the external system as specified in the organization’s information security policy and security plan; or
(b) Has approved information system connection or processing agreements with the organizational entity hosting the external information system.
(2) The organization limits the use of organization-controlled portable storage media by authorized individuals on external information systems.
Control Enhancements:
(1) The organization permits authorized individuals to use an external information system to access the information system or to process, store, or transmit organization-controlled information only when the organization:
(a) Can verify the implementation of required security controls on the external system as specified in the organization’s information security policy and security plan; or
(b) Has approved information system connection or processing agreements with the organizational entity hosting the external information system.
(2) The organization limits the use of organization-controlled portable storage media by authorized individuals on external information
AC-21 USER-BASED
COLLABORATION
AND
INFORMATION
SHARING
Not Applicable Not Applicable Not Applicable
AC-22 PUBLICLY
ACCESSIBLE
CONTENT
The organization:
a. Designates individuals authorized to post information onto an organizational information system that is publicly
The organization:
a. Designates individuals authorized to post information onto an organizational information system that
The organization:
a. Designates individuals authorized to post information onto an organizational information system
CONTROL NAME
Task Order Requirement
DoDI 8500.2
NIST
800-53
High-Impact Information System (FIPS Pub 200 / NIST SP 800-53)
MAC I (DoDI 8500.2)
Moderate-Impact Information System (FIPS Pub 200 / NIST SP
800-53) MAC II (DoDI 8500.2)
Low-Impact Information System (FIPS Pub 200 / NIST SP 800-53)
MAC III (DoDI 8500.2) (generally commercial best practices) accessible;
b. Trains authorized individuals to ensure that publicly accessible information does not contain nonpublic information;
c. Reviews the proposed content of publicly accessible information for nonpublic information prior to posting onto the organizational information system;
d. Reviews the content on the publicly accessible organizational information system for nonpublic information [Assignment: organization-defined frequency]; and
e. Removes nonpublic information from the publicly accessible organizational information system, if discovered.
is publicly accessible;
b. Trains authorized individuals to ensure that publicly accessible information does not contain nonpublic information;
c. Reviews the proposed content of publicly accessible information for nonpublic information prior to posting onto the organizational information system;
d. Reviews the content on the publicly accessible organizational information system for nonpublic information [Assignment: organization-defined frequency]; and
e. Removes nonpublic information from the publicly accessible organizational information system, if discovered.
that is publicly accessible;
b. Trains authorized individuals to ensure that publicly accessible information does not contain nonpublic information;
c. Reviews the proposed content of publicly accessible information for nonpublic information prior to posting onto the organizational information system;
d. Reviews the content on the publicly accessible organizational information system for nonpublic information [Assignment:
organization-defined frequency];
and
e. Removes nonpublic information from the publicly accessible organizational information system, if discovered.
Awareness and Training
PRTN-1
DCAR-1
AT-1 SECURITY
AWARENESS AND
TRAINING POLICY
AND
PROCEDURES
The organization develops, disseminates, and reviews/updates [Assignment: organization-defined frequency]:
a. A formal, documented security awareness and training policy that addresses purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance;
and
The organization develops, disseminates, and reviews/updates [Assignment: organization-defined frequency]:
a. A formal, documented security awareness and training policy that addresses purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance; and
The organization develops, disseminates, and reviews/updates [Assignment: organization-defined frequency]:
a. A formal, documented security awareness and training policy that addresses purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance; and
CONTROL NAME
Task Order Requirement
DoDI 8500.2
NIST
800-53
High-Impact Information System (FIPS Pub 200 / NIST SP 800-53)
MAC I (DoDI 8500.2)
Moderate-Impact Information System (FIPS Pub 200 / NIST SP
800-53) MAC II (DoDI 8500.2)
Low-Impact Information System (FIPS Pub 200 / NIST SP 800-53)
MAC III (DoDI 8500.2) (generally commercial best practices)
b. Formal, documented procedures to facilitate the implementation of the security awareness and training policy and associated security awareness and training controls.
b. Formal, documented procedures to facilitate the implementation of the security awareness and training policy and associated security awareness and training controls.
b. Formal, documented procedures to facilitate the implementation of the security awareness and training policy and associated security awareness and training controls.
AT-2 SECURITY
AWARENESS
The organization provides basic security awareness training to all information system users (including managers, senior executives, and contractors) as part of initial training for new users, when required by system changes, and [Assignment:
organization-defined frequency] thereafter.
The organization provides basic security awareness training to all information system users (including managers, senior executives, and contractors) as part of initial training for new users, when required by system changes, and [Assignment:
organization-defined frequency] thereafter.
The organization provides basic security awareness training to all information system users (including managers, senior executives, and contractors) as part of initial training for new users, when required by system changes, and [Assignment:
organization-defined frequency] thereafter.
AT-3 SECURITY
TRAINING
The organization provides role-based security-related training: (i) before authorizing access to the system or performing assigned duties; (ii) when required by system changes; and (iii) [Assignment: organization-defined frequency] thereafter.
The organization provides role-based security-related training: (i) before authorizing access to the system or performing assigned duties; (ii) when required by system changes; and (iii) [Assignment: organization-defined frequency] thereafter.
The organization provides role-based security-related training: (i) before authorizing access to the system or performing assigned duties; (ii) when required by system changes; and (iii) [Assignment:
organization-defined frequency] thereafter.
--- AT-4 SECURITY
TRAINING
RECORDS
The organization:
a. Documents and monitors individual information system security training activities including basic security awareness training and specific information system security training;
and
b. Retains individual training records for [Assignment: organization-defined time period].
The organization:
a. Documents and monitors individual information system security training activities including basic security awareness training and specific information system security training;
and
b. Retains individual training records for [Assignment: organization-defined time period].
The organization:
a. Documents and monitors individual information system security training activities including basic security awareness training and specific information system security training; and
b. Retains individual training records for [Assignment: organization-defined time period].
CONTROL NAME
Task Order Requirement
DoDI 8500.2
NIST
800-53
High-Impact Information System (FIPS Pub 200 / NIST SP 800-53)
MAC I (DoDI 8500.2)
Moderate-Impact Information System (FIPS Pub 200 / NIST SP
800-53) MAC II (DoDI 8500.2)
Low-Impact Information System (FIPS Pub 200 / NIST SP 800-53)
MAC III (DoDI 8500.2) (generally commercial best practices)
AT-5 CONTACTS WITH
SECURITY
GROUPS AND
ASSOCIATIONS
Not Applicable Not Applicable Not Applicable
Audit and Accountability
ECAT-1
ECTB-1
DCAR-1
AU-1 AUDIT AND
ACCOUNTABILITY
POLICY AND
PROCEDURES
The organization develops, disseminates, and reviews/updates [Assignment: organization-defined frequency]:
a. A formal, documented audit and accountability policy that addresses purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance; and
b. Formal, documented procedures to facilitate the implementation of the audit and accountability policy and associated audit and accountability controls.
The organization develops, disseminates, and reviews/updates [Assignment: organization-defined frequency]:
a. A formal, documented audit and accountability policy that addresses purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance; and
b. Formal, documented procedures to facilitate the implementation of the audit and accountability policy and associated audit and accountability controls.
The organization develops, disseminates, and reviews/updates [Assignment: organization-defined frequency]:
a. A formal, documented audit and accountability policy that addresses purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance; and
b. Formal, documented procedures to facilitate the implementation of the audit and accountability policy and associated audit and accountability controls.
ECAR-3 AU-2 AUDITABLE
EVENTS
The organization:
a. Determines, based on a risk assessment and mission/business needs, that the information system must be capable of auditing the following events: [Assignment: organization-defined list of auditable events];
b. Coordinates the security audit function with other organizational entities requiring audit-related
The organization:
a. Determines, based on a risk assessment and mission/business needs, that the information system must be capable of auditing the following events: [Assignment:
organization-defined list of auditable events];
b. Coordinates the security audit function with other organizational
The organization:
a. Determines, based on a risk assessment and mission/business needs, that the information system must be capable of auditing the following events: [Assignment:
organization-defined list of auditable events];
b. Coordinates the security audit function with other organizational
CONTROL NAME
Task Order Requirement
DoDI 8500.2
NIST
800-53
High-Impact Information System (FIPS Pub 200 / NIST SP 800-53)
MAC I (DoDI 8500.2)
Moderate-Impact Information System (FIPS Pub 200 / NIST SP
800-53) MAC II (DoDI 8500.2)
Low-Impact Information System (FIPS Pub 200 / NIST SP 800-53)
MAC III (DoDI 8500.2) (generally commercial best practices) information to enhance mutual support and to help guide the selection of auditable events;
c. Provides a rationale for why the list of auditable events are deemed to be adequate to support after-the-fact investigations of security incidents; and
d. Determines, based on current threat information and ongoing assessment of risk, that the following events are to be audited within the information system:
[Assignment: organization-defined subset of the auditable events defined in AU-2 a. to be audited along with the frequency of (or situation requiring) auditing for each identified event].
Control Enhancements:
(3) The organization reviews and updates the list of auditable events [Assignment: organization-defined frequency].
(4) The organization includes execution of privileged functions in the list of events to be audited by the information system.
entities requiring audit-related information to enhance mutual support and to help guide the selection of auditable events;
c. Provides a rationale for why the list of auditable events are deemed to be adequate to support after-the-fact investigations of security incidents;
and
d. Determines, based on current threat information and ongoing assessment of risk, that the following events are to be audited within the information system: [Assignment:
organization-defined subset of the auditable events defined in AU-2 a. to be audited along with the frequency of (or situation requiring) auditing for each identified event].
Control Enhancements:
(3) The organization reviews and updates the list of auditable events [Assignment: organization-defined frequency].
(4) The organization includes execution of privileged functions in the list of events to be audited by the information system.
entities requiring audit-related information to enhance mutual support and to help guide the selection of auditable events;
c. Provides a rationale for why the list of auditable events are deemed to be adequate to support after-the-fact investigations of security incidents; and
d. Determines, based on current threat information and ongoing assessment of risk, that the following events are to be audited within the information system:
[Assignment: organization-defined subset of the auditable events defined in AU-2 a. to be audited along with the frequency of (or situation requiring) auditing for each identified event].
ECAR-1
ECAR-2
AU-3 CONTENT OF
AUDIT RECORDS
The information system produces audit records that contain sufficient information to, at a minimum, establish what type of event occurred, when (date
The information system produces audit records that contain sufficient information to, at a minimum, establish what type of event occurred, The information system produces audit records that contain sufficient information to, at a minimum, establish what type of event
CONTROL NAME
Task Order Requirement
DoDI 8500.2
NIST
800-53
High-Impact Information System (FIPS Pub 200 / NIST SP 800-53)
MAC I (DoDI…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .