ENCLOSURE 3C - Security Categorization and Control Selection.pdf
PDF 2 MB Posted
- Attached to
- Protected Tactical Enterprise Service (PTES) Protected Tactical Waveform over Commercial (PTWoC) Joint Hub Variant Technical Capability Sources Sought RFI Federal contract opportunity
- Solicitation number
- FA8807-PTWOC-RFI-001
- Issued by
- Department of the Air Force
About this file
This file is Committee on National Security Systems Instruction (CNSSI) No. 1253, which provides guidance on security categorization and control selection for national security systems (NSS). The document prescribes minimum standards for federal departments and agencies regarding the first two steps of the Risk Management Framework (RMF): Categorize and Select. It builds upon and complements NIST Special Publication 800-53, establishing security controls and baselines specific to NSS.
The instruction adopts FIPS 199 security categorization methodology but differs from NIST guidance by maintaining three discrete impact values (low, moderate, high) for confidentiality, integrity, and availability rather than using a high water mark approach. It includes detailed security control tables and parameter values specific to NSS, with additional controls beyond the NIST baseline marked with "+" symbols. The document addresses NSS-specific assumptions including insider threats and advanced persistent threats, while providing guidance on developing and applying security control overlays to address factors beyond impact levels. This is a reference document defining security standards rather than a solicitation for products or services.
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| ENCLOSURE 3A - DoD Risk Management Framework Public Disclourse.pdf | ||
| ENCLOSURE 1 - JH Variant Requirements.pdf | ||
| ENCLOSURE 2 - MIL-STD-188-164C.pdf_safe.pdf | ||
| ENCLOSURE 3B - Security and Policy NIST.pdf |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
CNSSI No. 1253
27 March 2014
SECURITY CATEGORIZATION AND
CONTROL SELECTION FOR
NATIONAL SECURITY SYSTEMS
THIS INSTRUCTION PRESCRIBES MINIMUM STANDARDS
YOUR DEPARTMENT OR AGENCY MAY REQUIRE FURTHER
IMPLEMENTATION
i
NATIONAL MANAGER
FOREWORD
1. The Committee on National Security Systems (CNSS) Instruction No. 1253, Security
Categorization and Control Selection for National Security Systems, provides all Federal Government departments, agencies, bureaus, and offices with guidance on the first two steps of the Risk Management Framework (RMF), Categorize and Select, for national security systems (NSS). This Instruction builds on and is a companion document to National Institute of
Standards and Technology (NIST) Special Publication (SP), 800-53, Security and Privacy
Controls for Federal Information Systems and Organizations; therefore, it is formatted to align with that document’s section numbering scheme. This Instruction should be used by information systems security engineers, authorizing officials, senior information security officers, and others to select and agree upon appropriate protections for an NSS.
2. The authority to issue this Instruction derives its authority from National Security Directive 42, National Policy for the Security of National Security Telecommunications and Information
Systems, which outlines the roles and responsibilities for securing NSS, consistent with applicable law, E.O. 12333, as amended, and other Presidential directives. Nothing in this
Instruction shall alter or supersede the authorities of the Director of National Intelligence.
3. This Instruction supersedes CNSSI No. 1253 dated March 15, 2012.
4. All CNSS member organizations should plan their transition to new versions of this
Instruction, including periodic updates of the security control allocations. The transition should account for new overlays that are published independently as attachments to Appendix F of this Instruction.
5. CNSSI No. 1253 appendices will be reviewed and administratively updated, as required, on a quarterly basis to reflect changes to protect NSS.
6. Additional copies of this Instruction may be obtained from the CNSS Secretariat or the CNSS website: https://www.cnss.gov.
FOR THE NATIONAL MANAGER
/s/
DEBORA A. PLUNKETT
CNSS Secretariat (IE32). National Security Agency. 9800 Savage Road, STE 6716. Ft Meade, MD 20755-6716 Office: (410) 854-6805 Unclassified FAX: (410) 854-6814
CNSS@nsa.gov https://www.cnss.gov/ ii
TABLE OF CONTENTS
CHAPTER ONE: INTRODUCTION
1.1 PURPOSE AND SCOPE
1.2 DIFFERENCES BETWEEN CNSSI NO. 1253 AND NIST PUBLICATIONS
CHAPTER TWO: THE FUNDAMENTALS
2.1 ADOPTION OF NIST SP 800-53 AND FIPS 199
2.2 ASSUMPTIONS RELATED TO SECURITY CONTROL BASELINES
2.3 RELATIONSHIP BETWEEN BASELINES AND OVERLAYS
CHAPTER THREE: THE CATEGORIZE AND SELECT PROCESSES
3.1 RMF STEP 1: CATEGORIZE INFORMATION SYSTEM
3.2 RMF STEP 2: SELECT SECURITY CONTROLS
APPENDIX A REFERENCES ................................................................................................ A-1
APPENDIX B GLOSSARY ......................................................................................................B-1
APPENDIX C ACRONYMS ....................................................................................................C-1
APPENDIX D SECURITY CONTROL TABLES ................................................................ D-1
APPENDIX E SECURITY CONTROL PARAMETER VALUES ...................................... E-1
APPENDIX F OVERLAYS ...................................................................................................... F-1
TABLE OF FIGURES AND TABLES
Table D-1: NSS Security Control Baselines .............................................................................. D-1
Table D-2: Additional Security Control Information ............................................................... D-37
Table E-1: Security Control Parameter Values for NSS ............................................................. E-1
CHAPTER ONE
INTRODUCTION
The CNSS has worked with representatives from the Civil, Defense, and Intelligence
Communities, as part of the Joint Task Force Transformation Initiative Working Group (JTF) to produce a unified information security framework. As a result of this collaboration, NIST published the following five transformational documents:
NIST SP 800-30, Guide for Conducting Risk Assessments;
NIST SP 800-37, Guide for Applying the Risk Management Framework to Federal Information Systems: A Security Life Cycle Approach;
NIST SP 800-39, Managing Information Security Risk: Organization, Mission, and Information System View;
NIST SP 800-53, Security and Privacy Controls for Federal Information Systems and
Organizations; and
NIST SP 800-53A, Guide for Assessing the Security Controls in Federal Information
Systems and Organizations: Building Effective Security Assessment Plans.
The intent of this common framework is to improve information security, strengthen risk management processes, and encourage reciprocity among federal agencies.
1.1 PURPOSE AND SCOPE
The CNSS collaborates with NIST to ensure NIST SP 800-53 contains security controls to meet the requirements of NSS and provides a common foundation for information security across the
U.S. Federal Government. CNSSI No. 1253 is a companion document to the NIST publications relevant to categorization and selection (i.e., NIST SP 800-53; NIST SP 800-37; NIST SP 800- 60, Guide for Mapping Types of Information and Information Systems to Security Categories;
and Federal Information Processing Standards [FIPS] 199, Standards for Security Categorization of Federal Information and Information Systems) and applies to all NSS. This Instruction also provides NSS-specific information on developing and applying overlays for the national security community and parameter values for NIST SP 800-53 security controls that are applicable to all
NSS.
For NSS, where differences between the NIST documentation and this Instruction occur, this
Instruction takes precedence.
1 NIST SP 800-59, Guidelines for Identifying an Information System as a National Security System, provides guidelines developed in conjunction with the Department of Defense, including the National Security Agency, for identifying an information system as a national security system. The basis for these guidelines is the Federal Information Security Management
Act of 2002 (Title III, Public Law 107-347, December 17, 2002), which defines the phrase “national security system,” and provides government-wide requirements for information security.
1.2 DIFFERENCES BETWEEN CNSSI NO. 1253 AND NIST PUBLICATIONS
The major differences between this Instruction and the NIST publications relevant to categorization and selection are below.
This Instruction does not adopt the high water mark (HWM) concept from FIPS 200, Minimum Security Requirements for Federal Information and Information Systems, for categorizing information systems (see Section 2.1).
The definitions for moderate and high impact are refined from those provided in FIPS 199 (see Section 3.1).
The associations of confidentiality, integrity, and/or availability to security controls are explicitly defined in this Instruction (see Appendix D, Table D-2).
The use of security control overlays is refined in this Instruction for the national security community (see Section 3.2 and Appendix F).
CHAPTER TWO
THE FUNDAMENTALS
This chapter presents the fundamental concepts associated with categorization and security control selection.
2.1 ADOPTION OF NIST SP 800-53 AND FIPS 199
The CNSS adopts NIST SP 800-53, as documented in this Instruction, for the national security community. The CNSS adopts FIPS 199, establishing the security category for NSS with three discrete components: one impact value (low, moderate, or high) for each of the three security objectives (confidentiality, integrity, and availability). Preserving the three discrete components, rather than using the FIPS 200 HWM, provides granularity in allocating security controls to baselines and reduces the need for subsequent tailoring. Table D-1 in Appendix D represents this in a 3-by-3 matrix.
2.2 ASSUMPTIONS RELATED TO SECURITY CONTROL BASELINES
Assumptions related to security control baselines are intended to represent a majority of federal information systems and serve as the basis to justify the allocation of controls in the baselines.
While some federal information systems do not share these characteristics, it is more efficient for organizations to start with a baseline and tailor it to meet the needs of those information systems.
Systems or environments that diverge from the assumptions listed below may require the application of an overlay (see Section 3.2.1) or tailoring of the selected controls and enhancements (see Section 3.2.2).
This Instruction accepts all assumptions from NIST SP 800-53 by adopting the NIST security control baselines as the foundation for the NSS baselines defined in Table D-1, in Appendix D.
The NIST SP 800-53 assumptions are:
Information systems are located in physical facilities.
User data/information in organizational information systems is relatively persistent.
Information systems are multi-user (either serially or concurrently) in operation.
Some user data/information in organizational information systems is not shareable with other users who have authorized access to the same systems.
Information systems exist in networked environments.
Information systems are general purpose in nature.
Organizations have the structure, resources, and infrastructure to implement the controls.
This Instruction also addresses assumptions specific to NSS through the NSS baselines. The
NSS baselines are not intended to address these assumptions completely, but rather to a degree that represents the minimal protection that should be provided. The additional, NSS-specific assumptions are:
2 Examples of systems that may diverge from the assumptions include systems not located in physical facilities, systems in resource constrained environments, and stand-alone systems.
Insider threats exist within NSS organizations.
Advanced persistent threats (APTs) are targeting NSS and may already exist within NSS organizations.
Additional best practices beyond those defined in the NIST baselines are necessary to protect NSS.
Conversely, there are also some possible situations that are specifically not addressed in the baselines. These include:
Classified data/information is processed, stored, or transmitted by information systems;
Selected data/information requires specialized protection based on federal legislation, directives, regulations, or policies; and
Information systems need to communicate with other systems across different security domains.
2.3 RELATIONSHIP BETWEEN BASELINES AND OVERLAYS
NSS baselines, which are comprised of NIST SP 800-53 baselines coupled with the additional
NIST SP 800-53 security controls required for NSS, and applicable overlays together constitute the initial security control set. NSS baselines represent the security controls necessary to address the impact on organizations or individuals should there be a loss of confidentiality, integrity, or availability, as reflected by the system’s security category. Overlays are intended to address additional factors (beyond impact) or diverge from the assumptions used to create the security control baselines (see Section 2.2), the use of which is determined by answering the applicability questions in each overlay.
Overlays are baseline independent, meaning that they can be applied to any NSS baseline (e.g., High-Moderate-Moderate or Low-Low-Low). As a result, there may be overlap of security controls between an NSS baseline and security controls identified in an overlay(s).
Together, the combination of an NSS baseline and applicable overlay(s) represents the initial security control set prior to system-specific tailoring.
All security controls, regardless of source (baseline or overlays), may be tailored to address the risk associated with the specific system. All security controls, whether from a baseline or an overlay, are implemented in a system and tested during the security control assessment process.
3 If the use of multiple overlays results in conflicts between the application and removal of security controls, see Section 3.2.1 for guidance.
CHAPTER THREE
THE CATEGORIZE AND SELECT PROCESSES
This chapter describes the processes of categorization and security control selection. Except where the guidance in this document differs from that in NIST SP 800-37, the national security community will implement the RMF Categorize and Select Steps consistent with NIST SP 800- 37.
3.1 RMF STEP 1: CATEGORIZE INFORMATION SYSTEM
For NSS, the Security Categorization Task (RMF Step 1, Task 1-1) is a two-step process:
1. Determine impact values: (i) for the information type(s) processed, stored, transmitted, or protected by the information system; and (ii) for the information system.
2. Identify overlays that apply to the information system and its operating environment to account for additional factors (beyond impact) that influence the selection of security controls.
Within the national security community, it is understood that certain losses are to be expected when performing particular missions. Therefore, for NSS interpret the FIPS 199 amplification for the moderate and high potential impact values, as if the phrase “…exceeding mission expectations.” is appended to the end of the sentence in FIPS 199, Section 3.
3.1.1 Determine Impact Values for Information Types and the Information System
In preparation for selecting and specifying the appropriate security controls for organizational information systems and their respective environments of operation, organizations categorize their information and information system. To categorize the information and information system, complete the following activities:
1. Identify all the types of information processed, stored, or transmitted by an information system, determine their provisional security impact values, and adjust the information types’ provisional security impact values (see FIPS 199, NIST SP 800-60, Volume I, Section 4, and NIST SP 800-60, Volume II)
. If the information type is not identified in
NIST SP 800-60 Volume II, document the information type consistent with the guidance in NIST SP 800-60, Volume I.
2. Determine the security category for the information system (see FIPS 199) and make any necessary adjustments (see NIST SP 800-60, Volume I, Section 4.4.2). The security category of a system should not be changed or modified to reflect management decisions
4 An information type is a specific category of information (e.g., privacy, medical, proprietary, financial, investigative, contractor-sensitive, security management), defined by an organization or, in some instances, by a public law, executive order, directive, policy, or regulation.
5 Controlled interfaces protect information that is processed, stored, or transmitted on interconnected systems. That information should be considered when categorizing the controlled interface.
6 For the confidentiality impact value, each organization should ensure that it categorizes specific information based on its potential worst case impact to i) its organization and ii) any and all other U.S. organizations with that specific information.
7 As appropriate, supplement NIST SP 800-60 with organization-defined guidance.
to allocate more stringent or less stringent security controls. The tailoring guidance in
Section 3.2.2 should be used to address these issues.
3. Document the security category in the security plan.
3.1.2 Identify Applicable Overlays
Overlays identify additional factors (beyond impact) that influence the initial selection of security controls. As CNSS overlays are developed, they are published as attachments to
Appendix F of this Instruction. Each overlay includes an applicability section with a series of questions used to identify whether or not the overlay is applicable to an information system.
Review the questions in each overlay identified in Appendix F to determine whether or not the overlay applies. Document the applicable overlay(s) in the security plan.
3.2 RMF STEP 2: SELECT SECURITY CONTROLS
For NSS, Security Control Selection (RMF Step 2, Task 2-2) is a two-step process:
1. Select the initial security control set.
2. Tailor the initial security control set.
3.2.1 Select the Initial Security Control Set
Once the security category of the information system is determined, organizations begin the security control selection process. To identify the initial security control set, complete the following activities:
1. Select the baseline security controls identified from Table D-1 in Appendix D corresponding to the security category of the system (i.e., the impact values determined for each security objective [confidentiality, integrity, and availability]).
2. Apply any overlay(s) identified as applicable during security categorization. If the use of multiple overlays results in conflicts between the application or removal of security controls, the authorizing official (or designee), in coordination with the information owner/steward, information system owner, and risk executive (function) resolves the conflict.
3. Document the initial security control set and the rationale for adding or removing security controls from the baseline by referencing the applicable overlay(s) in the security plan.
3.2.2 Tailor the Initial Security Control Set
Organizations initiate the tailoring process to modify and align the initial control set to more closely account for conditions affecting the specific system (i.e., conditions related to organizational missions/business functions, information systems, or environments of operation).
Organizations should remove security controls only as a function of specified, risk-based determinations. During the tailoring process, a risk assessment – either informal or formal – should be conducted. The results from a risk assessment provide information about the necessity and sufficiency of security controls and enhancements during the tailoring process. To tailor the initial security control set, complete the following activities:
1. Tailor the initial security control set using Table D-2, Appendix E, and NIST SP 800-53, Section 3.2.
2. Determine whether or not additional assurance–related controls are needed to increase the level of trustworthiness in the information system. If so, tailor the set of controls accordingly. (See NIST SP 800-53, Appendix E.)
3. Document in the security plan the relevant decisions made during the tailoring process, providing a sound rationale for those decisions.
4. Document and justify in the security plan any security controls from the initial security control set that cannot or will not be implemented in the system and for which no compensating control(s) will be substituted. At the discretion of the authorizing official, this information may be included in the plan of action and milestones.
8All of the guidance in NIST SP 800-53, Section 3.2 applies to NSS except for the subsection titled “Security Objective-Related
Considerations.” This subsection is specific to the NIST baselines and does not apply to NSS.
A-1
APPENDIX A
REFERENCES
LAWS, POLICIES, DIRECTIVES, REGULATIONS, MEMORANDA, STANDARDS, AND
GUIDELINES
Appendix A provides the references used within CNSSI No. 1253.
1. 44 U.S.C. § 3542, January 2012.
2. Committee on National Security Systems Instruction 4009, National Information
Assurance Glossary, April 2010.
3. Federal Information Processing Standards Publication 199, Standards for Security
Categorization of Federal Information and Information Systems, February 2004.
4. Federal Information Processing Standards Publication 200, Minimum Security
Requirements for Federal Information and Information Systems, March 2006.
5. Federal Information Security Management Act (P.L. 107-347, Title III), December 2002.
6. National Institute of Standards and Technology Special Publication 800-30, Guide for
Conducting Risk Assessments, September 2012.
7. National Institute of Standards and Technology Special Publication 800-37, Revision 1, Guide for Applying the Risk Management Framework to Federal Information Systems: A
Security Life Cycle Approach, February 2010.
8. National Institute of Standards and Technology Special Publication 800-39, Managing
Information Security Risk: Organization, Mission, and Information System View, March 2011.
9. National Institute of Standards and Technology Special Publication 800-53, Revision 4, Security and Privacy Controls for Federal Information Systems and Organizations, April 2013.
10. National Institute of Standards and Technology Special Publication 800-53A, Guide for Assessing the Security Controls in Federal Information Systems and Organizations:
Building Effective Security Assessment Plans, June 2010.
11. National Institute of Standards and Technology Special Publication 800-59, Guideline for Identifying an Information System as a National Security System, August 2003.
12. National Institute of Standards and Technology Special Publication 800-60, Revision 1, Volume I: Guide for Mapping Types of Information and Information Systems to Security
Categories, August 2008.
13. National Institute of Standards and Technology Special Publication 800-60, Revision 1, Volume II: Appendices to Guide for Mapping Types of Information and Information
Systems to Security Categories, August 2008
14. National Security Directive 42, National Policy for the Security of National Security
Telecommunications and Information Systems, July 1990.
9 Includes errata update as of 7 May 2013.
B-1
APPENDIX B
GLOSSARY
COMMON TERMS AND DEFINITIONS
The terms in this document are defined in the NIST JTF documents and CNSSI No. 4009, except for those listed below.
Initial Security Control Set The set of security controls resulting from the combination of a baseline and applicable overlays prior to system specific tailoring.
NSS baselines
The combination of NIST 800-53 baselines (represented by an “X”) and the additional NIST SP 800-53 security controls required for NSS (represented by a “+”) that are applicable to NSS.
Provisional security impact values
[NIST SP 800-60,
Adapted]
The initial or conditional impact determinations made until all considerations are fully reviewed, analyzed, and accepted in the subsequent categorization steps by appropriate officials.
Security Control Extension A statement, used in security control overlays, that extends the basic capability of a security control by specifying additional functionality, altering the strength mechanism, or adding or limiting implementation options.
C-1
APPENDIX C
ACRONYMS
COMMON ABBREVIATIONS
The acronyms and abbreviations used in this Instruction are included below. Control related acronyms included in the tables of appendices D and E are defined in NIST SP 800-53.
APT Advanced Persistent Threat
CNSS Committee on National Security Systems
CNSSI
Committee on National Security Systems Instruction
EO Executive Order
FIPS
Federal Information Processing Standards
FISMA Federal Information Security Management Act
HWM High Water Mark
JTF Joint Task Force Transformation Initiative Working Group
NIST National Institute of Standards and Technology
NSS National Security System
RMF Risk Management Framework
P.L. Public Law
SC Security Category
SDLC System Development Life Cycle
SP Special Publication
U.S. United States
U.S.C. United States Code
D-1
APPENDIX D
SECURITY CONTROL TABLES
D.1 NSS SECURITY CONTROL BASELINES
Table D-1 uses a 3-by-3 matrix to identify applicability of security controls in the NIST SP 800- 53, Revision 4 baselines for NSS. The matrix also identifies the additional security controls needed to protect NSS. This table represents the security controls applicable to NSS based on impact values.
The 3-by-3 matrix has nine columns showing three possible impact values (low, moderate, or high) for each of the three security objectives (confidentiality, integrity, or availability). The
"X"s in the table reflect the NIST specifications by impact value (i.e., low, moderate, and high).
The "+"s in the table reflect the additional CNSS specifications by impact value for all NSS. The association of security controls to security objectives is detailed in table D-2. A blank space in the table signifies the control was either not selected or not allocated to a particular security objective for the purposes of this Instruction. Controls that are designated as “withdrawn” indicate that they are no longer in the NIST SP 800-53 security control catalog
Table D-1: NSS Security Control Baselines
ID TITLE
Confidentiality Integrity Availability
L M H L M H L M H
AC-1 Access Control Policy and Procedures X X X X X X X X X
AC-2 Account Management X X X X X X
AC-2(1) Account Management | Automated System
Account Management X X X X
AC-2(2) Account Management | Removal of
Temporary / Emergency Accounts X X X X
AC-2(3) Account Management | Disable Inactive
Accounts X X X X
AC-2(4) Account Management | Automated Audit
Actions + X X + X X
AC-2(5) Account Management | Inactivity Logout + + X + + X + + X
AC-2(6) Account Management | Dynamic Privilege
Management
AC-2(7) Account Management | Role-Based Schemes + + + + + +
AC-2(8) Account Management | Dynamic Account
Creation
AC-2(9) Account Management | Restrictions on Use of
Shared Groups / Accounts + + + + + +
AC-2(10) Account Management | Shared / Group
Account Credential Termination + + + + + +
AC-2(11) Account Management | Usage Conditions X X
AC-2(12) Account Management | Account Monitoring / + + X + + X
10 Changes to the security control catalog are under the authority of NIST.
D-2
L M H L M H L M H
Atypical Usage
AC-2(13) Account Management | Disable Accounts For
High-Risk Individuals + + X + + X
AC-3 Access Enforcement X X X X X X
AC-3(1) Access Enforcement | Restricted Access to
Privileged Functions Withdrawn
AC-3(2) Access Enforcement | Dual Authorization
AC-3(3) Access Enforcement | Mandatory Access
Control
AC-3(4) Access Enforcement | Discretionary Access
AC-3(5) Access Enforcement | Security-Relevant
Information
AC-3(6) Access Enforcement | Protection of User and
System Information Withdrawn
AC-3(7) Access Enforcement | Role-Based Access
AC-3(8) Access Enforcement | Revocation of Access
Authorizations
AC-3(9) Access Enforcement | Controlled Release
AC-3(10) Access Enforcement | Audited Override of
Access Control Mechanisms
AC-4 Information Flow Enforcement X X X X
AC-4(1) Information Flow Enforcement | Object
Security Attributes
AC-4(2) Information Flow Enforcement | Processing
Domains
AC-4(3) Information Flow Enforcement | Dynamic
Information Flow Control
AC-4(4) Information Flow Enforcement | Content
Check Encrypted Information
AC-4(5) Information Flow Enforcement | Embedded
Data Types
AC-4(6) Information Flow Enforcement | Metadata
AC-4(7) Information Flow Enforcement | One-Way
Flow Mechanisms
AC-4(8) Information Flow Enforcement | Security
Policy Filters
AC-4(9) Information Flow Enforcement | Human
Reviews
AC-4(10) Information Flow Enforcement | Enable /
Disable Security Policy Filters
AC-4(11) Information Flow Enforcement |
Configuration of Security Policy Filters
AC-4(12) Information Flow Enforcement | Data Type
Identifiers
AC-4(13) Information Flow Enforcement |
Decomposition Into Policy-Relevant
D-3
L M H L M H L M H
Subcomponents
AC-4(14) Information Flow Enforcement | Security
Policy Filter Constraints
AC-4(15) Information Flow Enforcement | Detection of
Unsanctioned Information
AC-4(16) Information Flow Enforcement | Information
Transfers on Interconnected Systems Withdrawn
AC-4(17) Information Flow Enforcement | Domain
Authentication
AC-4(18) Information Flow Enforcement | Security
Attribute Binding
AC-4(19) Information Flow Enforcement | Validation of Metadata
AC-4(20) Information Flow Enforcement | Approved
Solutions
AC-4(21) Information Flow Enforcement | Physical /
Logical Separation of Information Flows
AC-4(22) Information Flow Enforcement | Access Only
AC-5 Separation of Duties + X X + X X
AC-6 Least Privilege + X X + X X
AC-6(1) Least Privilege | Authorize Access to Security
Functions + X X + X X
AC-6(2) Least Privilege | Non-Privileged Access For
Nonsecurity Functions + X X + X X
AC-6(3) Least Privilege | Network Access to
Privileged Commands X X
AC-6(4) Least Privilege | Separate Processing
Domains
AC-6(5) Least Privilege | Privileged Accounts + X X + X X
AC-6(6) Least Privilege | Privileged Access by Non-
Organizational Users
AC-6(7) Least Privilege | Review of User Privileges + + + + + +
AC-6(8) Least Privilege | Privilege Levels For Code
Execution
AC-6(9) Least Privilege | Auditing Use of Privileged
Functions + X X + X X
AC-6(10) Least Privilege | Prohibit Nonprivileged
Users from Executing Privileged Functions + X X + X X
AC-7 Unsuccessful Logon Attempts X X X X X X X X X
AC-7(1) Unsuccessful Logon Attempts | Automatic
Account Lock Withdrawn
AC-7(2) Unsuccessful Logon Attempts | Purge/Wipe
Mobile Device
AC-8 System Use Notification X X X X X X
AC-9 Previous Logon (Access) Notification
AC-9(1) Previous Logon Notification | Unsuccessful
D-4
L M H L M H L M H
Logons
AC-9(2) Previous Logon Notification | Successful /
Unsuccessful Logons
AC-9(3) Previous Logon Notification | Notification of
Account Changes
AC-9(4) Previous Logon Notification | Additional
Logon Information
AC-10 Concurrent Session Control + X + X + X
AC-11 Session Lock + X X + X X
AC-11(1) Session Lock | Pattern-Hiding Displays + X X
AC-12 Session Termination X X X X
AC-12(1) Session Termination | User-initiated Logouts
/ Message Displays + + + +
AC-13 Supervision and Review — Access Control Withdrawn
AC-14 Permitted Actions Without Identification or
Authentication X X X X X X
AC-14(1) Permitted Actions Without Identification or
Authentication | Necessary Uses Withdrawn
AC-15 Automated Marking Withdrawn
AC-16 Security Attributes + + + +
AC-16(1) Security Attributes | Dynamic Attribute
Association
AC-16(2) Security Attributes | Attribute Value Changes by Authorized Individuals
AC-16(3) Security Attributes | Maintenance of Attribute
Associations by Information System
AC-16(4) Security Attributes | Association of Attributes by Authorized Individuals
AC-16(5) Security Attributes | Attribute Displays For
Output Devices
AC-16(6) Security Attributes | Maintenance of Attribute
Association by Organization + + + +
AC-16(7) Security Attributes | Consistent Attribute
Interpretation
AC-16(8) Security Attributes | Association Techniques /
Technologies
AC-16(9) Security Attributes | Attribute Reassignment
AC-
16(10)
Security Attributes | Attribute Configuration by Authorized Individuals
AC-17 Remote Access X X X X X X
AC-17(1) Remote Access | Automated Monitoring /
Control + X X + X X
AC-17(2) Remote Access | Protection of Confidentiality
/ Integrity Using Encryption + X X + X X
AC-17(3) Remote Access | Managed Access Control
Points + X X + X X
D-5
L M H L M H L M H
AC-17(4) Remote Access | Privileged Commands /
Access + X X + X X
AC-17(5) Remote Access | Monitoring For
Unauthorized Connections Withdrawn
AC-17(6) Remote Access | Protection of Information + + +
AC-17(7) Remote Access | Additional Protection For
Security Function Access Withdrawn
AC-17(8) Remote Access | Disable Nonsecure Network
Protocols Withdrawn
AC-17(9) Remote Access | Disconnect / Disable Access + + + + + +
AC-18 Wireless Access X X X X X X
AC-18(1) Wireless Access | Authentication and
Encryption + X X + X X
AC-18(2) Wireless Access | Monitoring Unauthorized
Connections Withdrawn
AC-18(3) Wireless Access | Disable Wireless
Networking
AC-18(4) Wireless Access | Restrict Configurations by
Users + + X + + X
AC-18(5) Wireless Access | Antennas / Transmission
Power Levels X X
AC-19 Access Control For Mobile Devices X X X X X X
AC-19(1) Access Control For Mobile Devices | Use of
Writable / Portable Storage Devices Withdrawn
AC-19(2) Access Control For Mobile Devices | Use of
Personally Owned Portable Storage Devices Withdrawn
AC-19(3) Access Control For Mobile Devices | Use of
Portable Storage Devices with No
Identifiable Owner
Withdrawn
AC-19(4) Access Control For Mobile Devices |
Restrictions For Classified Information
AC-19(5) Access Control For Mobile Devices | Full
Device / Container-Based Encryption X X X X
AC-20 Use of External Information Systems X X X X X X
AC-20(1) Use of External Information Systems | Limits on Authorized Use + X X + X X
AC-20(2) Use of External Information Systems |
Portable Storage Devices + X X
AC-20(3) Use of External Information Systems | Non-
Organizationally Owned Systems / /
Components / Devices
AC-20(4) Use of External Information Systems |
Network Accessible Storage Devices
AC-21 Information Sharing X X
AC-21(1) Information Sharing | Automated Decision
Support
AC-21(2) Information Sharing | Information Search and
Retrieval
D-6
L M H L M H L M H
AC-22 Publicly Accessible Content X X X
AC-23 Data Mining Protection + +
AC-24 Access Control Decisions
AC-24(1) Access Control Decisions | Transmit Access
Authorization Information
AC-24(2) Access Control Decisions | No User or
Process Identity
AC-25 Reference Monitor
AT-1 Security Awareness and Training Policy and
Procedures X X X X X X X X X
AT-2 Security Awareness Training X X X X X X X X X
AT-2(1) Security Awareness | Practical Exercises
AT-2(2) Security Awareness | Insider Threat + X X + X X + X X
AT-3 Role-Based Security Training X X X X X X X X X
AT-3(1) Security Training | Environmental Controls
AT-3(2) Security Training | Physical Security Controls + + + + + + + + +
AT-3(3) Security Training | Practical Exercises
AT-3(4) Security Training | Suspicious
Communications and Anomalous System
Behavior
AT-4 Security Training Records X X X X X X X X X
AT-5 Contacts With Security Groups and
Associations Withdrawn
AU-1 Audit and Accountability Policy and
Procedures X X X X X X X X X
AU-2 Audit Events X X X X X X
AU-2(1) Audit Events | Compilation of Audit Records
From Multiple Sources Withdrawn
AU-2(2) Audit Events | Selection of Audit Events by
Component Withdrawn
AU-2(3) Audit Events | Reviews and Updates + X X + X X
AU-2(4) Audit Events | Privileged Functions Withdrawn
AU-3 Content of Audit Records X X X X X X
AU-3(1) Content of Audit Records | Additional Audit
Information + X X + X X
AU-3(2) Content of Audit Records | Centralized
Management of Planned Audit Record
Content
X X
AU-4 Audit Storage Capacity X X X
AU-4(1) Audit Storage Capacity | Transfer to Alternate
Storage
AU-5 Response to Audit Processing Failures X X X
AU-5(1) Response to Audit Processing Failures | Audit
Storage Capacity + + X
AU-5(2) Response to Audit Processing Failures | Real- X
D-7
L M H L M H L M H
Time Alerts
AU-5(3) Response to Audit Processing Failures |
Configurable Traffic Volume Thresholds
AU-5(4) Response to Audit Processing Failures |
Shutdown on Failure
AU-6 Audit Review, Analysis, and Reporting X X X X X X
AU-6(1) Audit Review, Analysis, and Reporting |
Process Integration + X X + X X
AU-6(2) Audit Review, Analysis, and Reporting |
Automated Security Alerts Withdrawn
AU-6(3) Audit Review, Analysis, and Reporting |
Correlate Audit Repositories + X X + X X
AU-6(4) Audit Review, Analysis, and Reporting |
Central Review and Analysis + + + + + +
AU-6(5) Audit Review, Analysis, and Reporting |
Integration / Scanning and Monitoring
Capabilities
X X
AU-6(6) Audit Review, Analysis, and Reporting |
Correlation With Physical Monitoring X X
AU-6(7) Audit Review, Analysis, and Reporting |
Permitted Actions
AU-6(8) Audit Review, Analysis, and Reporting | Full
Text Analysis of Privileged Commands
AU-6(9) Audit Review, Analysis, and Reporting |
Correlation with Information from
Nontechnical Sources
AU-6(10) Audit Review, Analysis, and Reporting |
Audit Level Adjustment + + + + + +
AU-7 Audit Reduction and Report Generation X X X X
AU-7(1) Audit Reduction and Report Generation |
Automatic Processing X X X X
AU-7(2) Audit Reduction and Report Generation |
Automatic Sort and Search
AU-8 Time Stamps X X X
AU-8(1) Time Stamps | Synchronization With
Authoritative Time Source + X X
AU-8(2) Time Stamps | Secondary Authoritative Time
Source
AU-9 Protection of Audit Information X X X X X X X X X
AU-9(1) Protection of Audit Information | Hardware
Write-Once Media
AU-9(2) Protection of Audit Information | Audit
Backup on Separate Physical Systems /
Components
X
AU-9(3) Protection of Audit Information |
Cryptographic Protection X
AU-9(4) Protection of Audit Information | Access by
Subset of Privileged Users + X X + X X
D-8
L M H L M H L M H
AU-9(5) Protection of Audit Information | Dual
Authorization
AU-9(6) Protection of Audit Information | Read Only
Access
AU-10 Non-Repudiation + X
AU-10(1) Non-Repudiation | Association of Identities
AU-10(2) Non-Repudiation | Validate Binding of
Information Producer Identity
AU-10(3) Non-Repudiation | Chain of Custody
AU-10(4) Non-Repudiation | Validate Binding of
Information Reviewer Identity
AU-10(5) Non-Repudiation | Digital Signatures Withdrawn
AU-11 Audit Record Retention X X X
AU-11(1) Audit Record Retention | Long-Term
Retrieval Capability
AU-12 Audit Generation X X X X X X
AU-12(1) Audit Generation | System-Wide / Time-
Correlated Audit Trail + + X
AU-12(2) Audit Generation | Standardized Formats
AU-12(3) Audit Generation | Changes by Authorized
Individuals + + X + + X
AU-13 Monitoring For Information Disclosure
AU-13(1) Monitoring For Information Disclosure | Use of Automated Tools
AU-13(2) Monitoring For Information Disclosure |
Review of Monitored Sites
AU-14 Session Audit + + + + + +
AU-14(1) Session Audit | System Start-Up + + + + + +
AU-14(2) Session Audit | Capture/Record and Log
Content
AU-14(3) Session Audit | Remote Viewing / Listening + + +
AU-15 Alternate Audit Capability
AU-16 Cross-Organizational Auditing
AU-16(1) Cross-Organizational Auditing | Identity
Preservation
AU-16(2) Cross-Organizational Auditing | Sharing of
Audit Information
CA-1 Security Assessment and Authorization
Policies and Procedures X X X X X X X X X
CA-2 Security Assessments X X X X X X X X X
CA-2(1) Security Assessments | Independent
Assessors + X X + X X + X X
CA-2(2) Security Assessments | Specialized
Assessments X X X
CA-2(3) Security Assessments | External
Organizations
D-9
L M H L M H L M H
CA-3 System Interconnections X X X X X X
CA-3(1) System Interconnections | Unclassified
National Security System Connections + + +
CA-3(2) System Interconnections | Classified National
Security System Connections
CA-3(3) System Interconnections | Unclassified Non-
National Security System Connections
CA-3(4) System Interconnections | Connections to
Public Networks
CA-3(5) System Interconnections | Restrictions on
External Network Connections + X X + X X
CA-4 Security Certification Withdrawn
CA-5 Plan of Action and Milestones X X X X X X X X X
CA-5(1) Plan of Action and Milestones | Automation
Support For Accuracy / Currency
CA-6 Security Authorization X X X X X X X X X
CA-7 Continuous Monitoring X X X X X X X X X
CA-7(1) Continuous Monitoring | Independent
Assessment X X X X X X
CA-7(2) Continuous Monitoring | Types of
Assessments Withdrawn
CA-7(3) Continuous Monitoring | Trend Analyses
CA-8 Penetration Testing X
CA-8(1) Penetration Testing | Independent Penetration
Agent or Team
CA-8(2) Penetration Testing | Red Team Exercises
CA-9 Internal System Connections X X X X X X
CA-9(1) Internal System Connections | Security
Compliance Checks
CM-1 Configuration Management Policy and
Procedures X X X X X X
CM-2 Baseline Configuration X X X
CM-2(1) Baseline Configuration | Reviews and
Updates + X X
CM-2(2) Baseline Configuration | Automation Support
For Accuracy / Currency X
CM-2(3) Baseline Configuration | Retention of
Previous Configurations X X
CM-2(4) Baseline Configuration | Unauthorized
Software Withdrawn
CM-2(5) Baseline Configuration | Authorized Software Withdrawn
CM-2(6) Baseline Configuration | Development and
Test Environments
CM-2(7) Baseline Configuration | Configure Systems, Components, or Devices for High-Risk Areas X X
CM-3 Configuration Change Control + X X
D-10
L M H L M H L M H
CM-3(1) Configuration Change Control | Automated
Document / Notification / Prohibition of
Changes
X
CM-3(2) Configuration Change Control | Test /
Validate / Document Changes X X
CM-3(3) Configuration Change Control | Automated
Change Implementation
CM-3(4) Configuration Change Control | Security
Representative
CM-3(5) Configuration Change Control | Automated
Security Response
CM-3(6) Configuration Change Control | Cryptography
Management
CM-4 Security Impact Analysis X X X
CM-4(1) Security Impact Analysis | Separate Test
Environments + X
CM-4(2) Security Impact Analysis | Verification of
Security Functions
CM-5 Access Restrictions For Change + X X
CM-5(1) Access Restrictions For Change | Automated
Access Enforcement / Auditing + X
CM-5(2) Access Restrictions For Change | Review
System Changes + X
CM-5(3) Access Restrictions For Change | Signed
Components X
CM-5(4) Access Restrictions For Change | Dual
CM-5(5) Access Restrictions For Change | Limit
Production / Operational Privileges + + +
CM-5(6) Access Restrictions For Change | Limit
Library Privileges
CM-5(7) Access Restrictions For Change | Automatic
Implementation of Security Safeguards Withdrawn
CM-6 Configuration Settings X X X
CM-6(1) Configuration Settings | Automated Central
Management / Application / Verification + X
CM-6(2) Configuration Settings | Respond to
Unauthorized Changes X
CM-6(3) Configuration Settings | Unauthorized
Change Detection Withdrawn
CM-6(4) Configuration Settings | Conformance
Demonstration Withdrawn
CM-7 Least Functionality X X X X X X
CM-7(1) Least Functionality | Periodic Review + X X + X X
CM-7(2) Least Functionality | Prevent Program
Execution + X X + X X
CM-7(3) Least Functionality | Registration Compliance + + + + + +
CM-7(4) Least Functionality | Unauthorized Software /
D-11
L M H L M H L M H
Blacklisting
CM-7(5) Least Functionality | Authorized Software /
Whitelisting + + X + + X
CM-8 Information System Component Inventory X X X
CM-8(1) Information System Component Inventory |
Updates During Installations / Removals X X
CM-8(2) Information System Component Inventory |
Automated Maintenance + + X
CM-8(3) Information System Component Inventory |
Automated Unauthorized Component
Detection
+ X X
CM-8(4) Information System Component Inventory |
Accountability Information X X
CM-8(5) Information System Component Inventory |
No Duplicate Accounting of Components X X
CM-8(6) Information System Component Inventory |
Assessed Configurations / Approved
Deviations
CM-8(7) Information System Component Inventory |
Centralized Repository
CM-8(8) Information System Component Inventory |
Automated Location Tracking
CM-8(9) Information System Component Inventory |
Assignment of Components to Systems
CM-9 Configuration Management Plan + X X
CM-9(1) Configuration Management Plan |
Assignment of Responsibility
CM-10 Software Usage Restrictions X X X
CM-10(1) Software Usage Restrictions | Open Source
Software
CM-11 User-Installed Software X X X X X X
CM-11(1) User-Installed Software | Alerts For
Unauthorized Installations
CM-11(2) User-Installed Software | Prohibit Installation without Privileged Status + + + + + +
CP-1 Contingency Planning Policy and Procedures X X X X X X X X X
CP-2 Contingency Plan X X X
CP-2(1) Contingency Plan | Coordinate With Related
Plans X X
CP-2(2) Contingency Plan | Capacity Planning X
CP-2(3) Contingency Plan | Resume Essential
Missions / Business Functions X X
CP-2(4) Contingency Plan | Resume All Missions /
Business Functions X
CP-2(5) Contingency Plan | Continue Essential
Missions / Business Functions X
CP-2(6) Contingency Plan | Alternate Processing /
D-12
L M H L M H L M H
Storage Site
CP-2(7) Contingency Plan | Coordinate With External
Service Providers
CP-2(8) Contingency Plan | Identify Critical Assets X X
CP-3 Contingency Training X X X
CP-3(1) Contingency Training | Simulated Events X
CP-3(2) Contingency Training | Automated Training
Environments
CP-4 Contingency Plan Testing X X X
CP-4(1) Contingency Plan Testing | Coordinate With
Related Plans X X
CP-4(2) Contingency Plan Testing | Alternate
Processing Site X
CP-4(3) Contingency Plan Testing | Automated
Testing
CP-4(4) Contingency Plan Testing | Full Recovery /
Reconstitution
CP-5 Contingency Plan Update Withdrawn
CP-6 Alternate Storage Site X X
CP-6(1) Alternate Storage Site | Separation From
Primary Site X X
CP-6(2) Alternate Storage Site | Recovery Time /
Point Objectives X
CP-6(3) Alternate Storage Site | Accessibility X X
CP-7 Alternate Processing Site X X X X X X
CP-7(1) Alternate Processing Site | Separation From
Primary Site X X
CP-7(2) Alternate Processing Site | Accessibility X X
CP-7(3) Alternate Processing Site | Priority of Service X X
CP-7(4) Alternate Processing Site | Preparation for
Use X
CP-7(5) Alternate Processing Site | Equivalent
Information Security Safeguards Withdrawn
CP-7(6) Alternate Processing Site | Inability to Return to Primary Site
CP-8 Telecommunications Services X X
CP-8(1) Telecommunications Services | Priority of
Service Provisions X X
CP-8(2) Telecommunications Services | Single Points of Failure X X
CP-8(3) Telecommunications Services | Separation of
Primary / Alternate Providers X
CP-8(4) Telecommunications Services | Provider
Contingency Plan X
CP-8(5) Telecommunications Services | Alternate
Telecommunication Service Testing +
CP-9 Information System Backup X X X X X X X X X
D-13
L M H L M H L M H
CP-9(1) Information System Backup | Testing For
Reliability / Integrity X X X X
CP-9(2) Information System Backup | Test
Restoration Using Sampling X
CP-9(3) Information System Backup | Separate
Storage for Critical Information X
CP-9(4) Information System Backup | Protection
From Unauthorized Modification Withdrawn
CP-9(5) Information System Backup | Transfer to
Alternate Storage Site + X
CP-9(6) Information System Backup | Redundant
Secondary System
CP-9(7) Information System Backup | Dual
CP-10 Information System Recovery and
Reconstitution X X X
CP-10(1) Information System Recovery and
Reconstitution | Contingency Plan Testing Withdrawn
CP-10(2) Information System Recovery and
Reconstitution | Transaction Recovery X X X X
CP-10(3) Information System Recovery and
Reconstitution | Compensating Security
Controls
Withdrawn
CP-10(4) Information System Recovery and
Reconstitution | Restore Within Time Period X X
CP-10(5) Information System Recovery and
Reconstitution | Failover Capability Withdrawn
CP-10(6) Information System Recovery and
Reconstitution | Component Protection
CP-11 Alternate Communications Protocols
CP-12 Safe Mode
CP-13 Alternative Security Mechanisms
IA-1 Identification and Authentication Policy and
Procedures X X X X X X
IA-2 Identification and Authentication
(Organizational Users) X X X X X X
IA-2(1) Identification and Authentication
(Organizational Users) | Network Access to
Privileged Accounts
X X X X X X
IA-2(2) Identification and Authentication
(Organizational Users) | Network Access to
Non-Privileged Accounts
+ X X + X X
IA-2(3) Identification and Authentication
(Organizational Users) | Local Access to
Privileged Accounts
X X X X
IA-2(4) Identification and Authentication
(Organizational Users) | Local Access to
Non-Privileged Accounts
+ X + X
D-14
L M H L M H L M H
IA-2(5) Identification and Authentication
(Organizational Users) | Group
Authentication
IA-2(6) Identification and Authentication
(Organizational Users) | Network Access to
Privileged Accounts - Separate Device
IA-2(7) Identification and Authentication
Non-Privileged Accounts - Separate Device
IA-2(8) Identification and Authentication
Privileged Accounts - Replay Resistant
+ X X + X X
IA-2(9) Identification and Authentication
(Organizational Users) | Network Access to
Non-Privileged Accounts - Replay Resistant
+ X + X
IA-2(10) Identification and Authentication
(Organizational Users) | Single Sign-On
IA-2(11) Identification and Authentication
(Organizational Users) | Remote Access -
Separate Device
+ X X + X X
IA-2(12) Identification and Authentication
(Organizational Users) | Acceptance of PIV
Credentials
X X X X X X
IA-2(13) Identification and Authentication | Out-of-
Band Authentication
IA-3 Device Identification and Authentication + X X + X X
IA-3(1) Device Identification and Authentication |
Cryptographic Bidirectional Authentication + + + +
IA-3(2) Device Identification and Authentication |
Cryptographic Bidirectional Network
Authentication
Withdrawn
IA-3(3) Device Identification and Authentication |
Dynamic Address Allocation
IA-3(4) Device Identification and Authentication |
Device Attestation
IA-4 Identifier Management X X X X X X
IA-4(1) Identifier Management | Prohibit Account
Identifiers As Public Identifiers
IA-4(2) Identifier Management | Supervisor
IA-4(3) Identifier Management | Multiple Forms of
Certification
IA-4(4) Identifier Management | Identify User Status + + + + + +
IA-4(5) Identifier Management | Dynamic
IA-4(6) Identifier Management | Cross-Organization
IA-4(7) Identifier Management | In Person
Registration
IA-5 Authenticator Management X X X X X X
D-15
L M H L M H L M H
IA-5(1) Authenticator Management | Password-Based
Authentication X X X X X X
IA-5(2) Authenticator Management | PKI-Based
Authentication X X X X
IA-5(3) Authenticator Management | In Person or
Trusted Third-Party Registration X X
IA-5(4) Authenticator Management | Automated
Support for Password Strength Determination + + + + + +
IA-5(5) Authenticator Management | Change
Authenticators Prior to Delivery
IA-5(6) Authenticator Management | Protection of
Authenticators
IA-5(7) Authenticator Management | No Embedded
Unencrypted Static Authenticators + + +
IA-5(8) Authenticator Management | Multiple
Information System Accounts + + + + + +
IA-5(9) Authenticator Management | Cross-
Organization Credential Management
IA-5(10) Authenticator Management | Dynamic
Credential Association
IA-5(11) Authenticator Management | Hardware
Token-Based Authentication X X X
IA-5(12) Authenticator Management | Biometric
Authentication
IA-5(13) Authenticator Management | Expiration of
Cached Authenticators + + + + + +
IA-5(14) Authenticator Management | Managing
Content of PKI Trust stores + + + + + +
IA-5(15) Authenticator Management | FICAM-
Approved Products and Services
IA-6 Authenticator Feedback X X X
IA-7 Cryptographic Module Authentication X X X X X X
IA-8 Identification and Authentication (Non-
Organizational Users) X X X X X X
IA-8(1) Identification and Authentication (Non-
Organizational Users) | Acceptance of PIV
Credentials from Other Agencies
X X X X X X
IA-8(2) Identification and Authentication (Non-
Organizational Users) | Acceptance of Third-
Party Credentials
X X X
IA-8(3) Identification and Authentication (Non-
Organizational Users) | Use of FICAM-
Approved Products
X X X
IA-8…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .