ENCLOSURE 3C - Security Categorization and Control Selection.pdf

PDF 2 MB Posted

Attached to
Protected Tactical Enterprise Service (PTES) Protected Tactical Waveform over Commercial (PTWoC) Joint Hub Variant Technical Capability Sources Sought RFI Federal contract opportunity
Solicitation number
FA8807-PTWOC-RFI-001
Issued by
Department of the Air Force

About this file

This file is Committee on National Security Systems Instruction (CNSSI) No. 1253, which provides guidance on security categorization and control selection for national security systems (NSS). The document prescribes minimum standards for federal departments and agencies regarding the first two steps of the Risk Management Framework (RMF): Categorize and Select. It builds upon and complements NIST Special Publication 800-53, establishing security controls and baselines specific to NSS.

The instruction adopts FIPS 199 security categorization methodology but differs from NIST guidance by maintaining three discrete impact values (low, moderate, high) for confidentiality, integrity, and availability rather than using a high water mark approach. It includes detailed security control tables and parameter values specific to NSS, with additional controls beyond the NIST baseline marked with "+" symbols. The document addresses NSS-specific assumptions including insider threats and advanced persistent threats, while providing guidance on developing and applying security control overlays to address factors beyond impact levels. This is a reference document defining security standards rather than a solicitation for products or services.

View the file

Other files for this federal contract opportunity

Other files attached to Protected Tactical Enterprise Service (PTES) Protected Tactical Waveform over Commercial (PTWoC) Joint Hub Variant Technical Capability Sources Sought RFI, newest first.
File Type Posted
ENCLOSURE 3A - DoD Risk Management Framework Public Disclourse.pdf PDF
ENCLOSURE 1 - JH Variant Requirements.pdf PDF
ENCLOSURE 2 - MIL-STD-188-164C.pdf_safe.pdf PDF
ENCLOSURE 3B - Security and Policy NIST.pdf PDF

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

CNSSI No. 1253

27 March 2014

SECURITY CATEGORIZATION AND

CONTROL SELECTION FOR

NATIONAL SECURITY SYSTEMS

THIS INSTRUCTION PRESCRIBES MINIMUM STANDARDS

YOUR DEPARTMENT OR AGENCY MAY REQUIRE FURTHER

IMPLEMENTATION

i

NATIONAL MANAGER

FOREWORD

1. The Committee on National Security Systems (CNSS) Instruction No. 1253, Security

Categorization and Control Selection for National Security Systems, provides all Federal Government departments, agencies, bureaus, and offices with guidance on the first two steps of the Risk Management Framework (RMF), Categorize and Select, for national security systems (NSS). This Instruction builds on and is a companion document to National Institute of

Standards and Technology (NIST) Special Publication (SP), 800-53, Security and Privacy

Controls for Federal Information Systems and Organizations; therefore, it is formatted to align with that document’s section numbering scheme. This Instruction should be used by information systems security engineers, authorizing officials, senior information security officers, and others to select and agree upon appropriate protections for an NSS.

2. The authority to issue this Instruction derives its authority from National Security Directive 42, National Policy for the Security of National Security Telecommunications and Information

Systems, which outlines the roles and responsibilities for securing NSS, consistent with applicable law, E.O. 12333, as amended, and other Presidential directives. Nothing in this

Instruction shall alter or supersede the authorities of the Director of National Intelligence.

3. This Instruction supersedes CNSSI No. 1253 dated March 15, 2012.

4. All CNSS member organizations should plan their transition to new versions of this

Instruction, including periodic updates of the security control allocations. The transition should account for new overlays that are published independently as attachments to Appendix F of this Instruction.

5. CNSSI No. 1253 appendices will be reviewed and administratively updated, as required, on a quarterly basis to reflect changes to protect NSS.

6. Additional copies of this Instruction may be obtained from the CNSS Secretariat or the CNSS website: https://www.cnss.gov.

FOR THE NATIONAL MANAGER

/s/

DEBORA A. PLUNKETT

CNSS Secretariat (IE32). National Security Agency. 9800 Savage Road, STE 6716. Ft Meade, MD 20755-6716 Office: (410) 854-6805 Unclassified FAX: (410) 854-6814

CNSS@nsa.gov https://www.cnss.gov/ ii

TABLE OF CONTENTS

CHAPTER ONE: INTRODUCTION

1.1 PURPOSE AND SCOPE

1.2 DIFFERENCES BETWEEN CNSSI NO. 1253 AND NIST PUBLICATIONS

CHAPTER TWO: THE FUNDAMENTALS

2.1 ADOPTION OF NIST SP 800-53 AND FIPS 199

2.2 ASSUMPTIONS RELATED TO SECURITY CONTROL BASELINES

2.3 RELATIONSHIP BETWEEN BASELINES AND OVERLAYS

CHAPTER THREE: THE CATEGORIZE AND SELECT PROCESSES

3.1 RMF STEP 1: CATEGORIZE INFORMATION SYSTEM

3.2 RMF STEP 2: SELECT SECURITY CONTROLS

APPENDIX A REFERENCES ................................................................................................ A-1

APPENDIX B GLOSSARY ......................................................................................................B-1

APPENDIX C ACRONYMS ....................................................................................................C-1

APPENDIX D SECURITY CONTROL TABLES ................................................................ D-1

APPENDIX E SECURITY CONTROL PARAMETER VALUES ...................................... E-1

APPENDIX F OVERLAYS ...................................................................................................... F-1

TABLE OF FIGURES AND TABLES

Table D-1: NSS Security Control Baselines .............................................................................. D-1

Table D-2: Additional Security Control Information ............................................................... D-37

Table E-1: Security Control Parameter Values for NSS ............................................................. E-1

CHAPTER ONE

INTRODUCTION

The CNSS has worked with representatives from the Civil, Defense, and Intelligence

Communities, as part of the Joint Task Force Transformation Initiative Working Group (JTF) to produce a unified information security framework. As a result of this collaboration, NIST published the following five transformational documents:

NIST SP 800-30, Guide for Conducting Risk Assessments;

NIST SP 800-37, Guide for Applying the Risk Management Framework to Federal Information Systems: A Security Life Cycle Approach;

NIST SP 800-39, Managing Information Security Risk: Organization, Mission, and Information System View;

NIST SP 800-53, Security and Privacy Controls for Federal Information Systems and

Organizations; and

NIST SP 800-53A, Guide for Assessing the Security Controls in Federal Information

Systems and Organizations: Building Effective Security Assessment Plans.

The intent of this common framework is to improve information security, strengthen risk management processes, and encourage reciprocity among federal agencies.

1.1 PURPOSE AND SCOPE

The CNSS collaborates with NIST to ensure NIST SP 800-53 contains security controls to meet the requirements of NSS and provides a common foundation for information security across the

U.S. Federal Government. CNSSI No. 1253 is a companion document to the NIST publications relevant to categorization and selection (i.e., NIST SP 800-53; NIST SP 800-37; NIST SP 800- 60, Guide for Mapping Types of Information and Information Systems to Security Categories;

and Federal Information Processing Standards [FIPS] 199, Standards for Security Categorization of Federal Information and Information Systems) and applies to all NSS. This Instruction also provides NSS-specific information on developing and applying overlays for the national security community and parameter values for NIST SP 800-53 security controls that are applicable to all

NSS.

For NSS, where differences between the NIST documentation and this Instruction occur, this

Instruction takes precedence.

1 NIST SP 800-59, Guidelines for Identifying an Information System as a National Security System, provides guidelines developed in conjunction with the Department of Defense, including the National Security Agency, for identifying an information system as a national security system. The basis for these guidelines is the Federal Information Security Management

Act of 2002 (Title III, Public Law 107-347, December 17, 2002), which defines the phrase “national security system,” and provides government-wide requirements for information security.

1.2 DIFFERENCES BETWEEN CNSSI NO. 1253 AND NIST PUBLICATIONS

The major differences between this Instruction and the NIST publications relevant to categorization and selection are below.

This Instruction does not adopt the high water mark (HWM) concept from FIPS 200, Minimum Security Requirements for Federal Information and Information Systems, for categorizing information systems (see Section 2.1).

The definitions for moderate and high impact are refined from those provided in FIPS 199 (see Section 3.1).

The associations of confidentiality, integrity, and/or availability to security controls are explicitly defined in this Instruction (see Appendix D, Table D-2).

The use of security control overlays is refined in this Instruction for the national security community (see Section 3.2 and Appendix F).

CHAPTER TWO

THE FUNDAMENTALS

This chapter presents the fundamental concepts associated with categorization and security control selection.

2.1 ADOPTION OF NIST SP 800-53 AND FIPS 199

The CNSS adopts NIST SP 800-53, as documented in this Instruction, for the national security community. The CNSS adopts FIPS 199, establishing the security category for NSS with three discrete components: one impact value (low, moderate, or high) for each of the three security objectives (confidentiality, integrity, and availability). Preserving the three discrete components, rather than using the FIPS 200 HWM, provides granularity in allocating security controls to baselines and reduces the need for subsequent tailoring. Table D-1 in Appendix D represents this in a 3-by-3 matrix.

2.2 ASSUMPTIONS RELATED TO SECURITY CONTROL BASELINES

Assumptions related to security control baselines are intended to represent a majority of federal information systems and serve as the basis to justify the allocation of controls in the baselines.

While some federal information systems do not share these characteristics, it is more efficient for organizations to start with a baseline and tailor it to meet the needs of those information systems.

Systems or environments that diverge from the assumptions listed below may require the application of an overlay (see Section 3.2.1) or tailoring of the selected controls and enhancements (see Section 3.2.2).

This Instruction accepts all assumptions from NIST SP 800-53 by adopting the NIST security control baselines as the foundation for the NSS baselines defined in Table D-1, in Appendix D.

The NIST SP 800-53 assumptions are:

Information systems are located in physical facilities.

User data/information in organizational information systems is relatively persistent.

Information systems are multi-user (either serially or concurrently) in operation.

Some user data/information in organizational information systems is not shareable with other users who have authorized access to the same systems.

Information systems exist in networked environments.

Information systems are general purpose in nature.

Organizations have the structure, resources, and infrastructure to implement the controls.

This Instruction also addresses assumptions specific to NSS through the NSS baselines. The

NSS baselines are not intended to address these assumptions completely, but rather to a degree that represents the minimal protection that should be provided. The additional, NSS-specific assumptions are:

2 Examples of systems that may diverge from the assumptions include systems not located in physical facilities, systems in resource constrained environments, and stand-alone systems.

Insider threats exist within NSS organizations.

Advanced persistent threats (APTs) are targeting NSS and may already exist within NSS organizations.

Additional best practices beyond those defined in the NIST baselines are necessary to protect NSS.

Conversely, there are also some possible situations that are specifically not addressed in the baselines. These include:

Classified data/information is processed, stored, or transmitted by information systems;

Selected data/information requires specialized protection based on federal legislation, directives, regulations, or policies; and

Information systems need to communicate with other systems across different security domains.

2.3 RELATIONSHIP BETWEEN BASELINES AND OVERLAYS

NSS baselines, which are comprised of NIST SP 800-53 baselines coupled with the additional

NIST SP 800-53 security controls required for NSS, and applicable overlays together constitute the initial security control set. NSS baselines represent the security controls necessary to address the impact on organizations or individuals should there be a loss of confidentiality, integrity, or availability, as reflected by the system’s security category. Overlays are intended to address additional factors (beyond impact) or diverge from the assumptions used to create the security control baselines (see Section 2.2), the use of which is determined by answering the applicability questions in each overlay.

Overlays are baseline independent, meaning that they can be applied to any NSS baseline (e.g., High-Moderate-Moderate or Low-Low-Low). As a result, there may be overlap of security controls between an NSS baseline and security controls identified in an overlay(s).

Together, the combination of an NSS baseline and applicable overlay(s) represents the initial security control set prior to system-specific tailoring.

All security controls, regardless of source (baseline or overlays), may be tailored to address the risk associated with the specific system. All security controls, whether from a baseline or an overlay, are implemented in a system and tested during the security control assessment process.

3 If the use of multiple overlays results in conflicts between the application and removal of security controls, see Section 3.2.1 for guidance.

CHAPTER THREE

THE CATEGORIZE AND SELECT PROCESSES

This chapter describes the processes of categorization and security control selection. Except where the guidance in this document differs from that in NIST SP 800-37, the national security community will implement the RMF Categorize and Select Steps consistent with NIST SP 800- 37.

3.1 RMF STEP 1: CATEGORIZE INFORMATION SYSTEM

For NSS, the Security Categorization Task (RMF Step 1, Task 1-1) is a two-step process:

1. Determine impact values: (i) for the information type(s) processed, stored, transmitted, or protected by the information system; and (ii) for the information system.

2. Identify overlays that apply to the information system and its operating environment to account for additional factors (beyond impact) that influence the selection of security controls.

Within the national security community, it is understood that certain losses are to be expected when performing particular missions. Therefore, for NSS interpret the FIPS 199 amplification for the moderate and high potential impact values, as if the phrase “…exceeding mission expectations.” is appended to the end of the sentence in FIPS 199, Section 3.

3.1.1 Determine Impact Values for Information Types and the Information System

In preparation for selecting and specifying the appropriate security controls for organizational information systems and their respective environments of operation, organizations categorize their information and information system. To categorize the information and information system, complete the following activities:

1. Identify all the types of information processed, stored, or transmitted by an information system, determine their provisional security impact values, and adjust the information types’ provisional security impact values (see FIPS 199, NIST SP 800-60, Volume I, Section 4, and NIST SP 800-60, Volume II)

. If the information type is not identified in

NIST SP 800-60 Volume II, document the information type consistent with the guidance in NIST SP 800-60, Volume I.

2. Determine the security category for the information system (see FIPS 199) and make any necessary adjustments (see NIST SP 800-60, Volume I, Section 4.4.2). The security category of a system should not be changed or modified to reflect management decisions

4 An information type is a specific category of information (e.g., privacy, medical, proprietary, financial, investigative, contractor-sensitive, security management), defined by an organization or, in some instances, by a public law, executive order, directive, policy, or regulation.

5 Controlled interfaces protect information that is processed, stored, or transmitted on interconnected systems. That information should be considered when categorizing the controlled interface.

6 For the confidentiality impact value, each organization should ensure that it categorizes specific information based on its potential worst case impact to i) its organization and ii) any and all other U.S. organizations with that specific information.

7 As appropriate, supplement NIST SP 800-60 with organization-defined guidance.

to allocate more stringent or less stringent security controls. The tailoring guidance in

Section 3.2.2 should be used to address these issues.

3. Document the security category in the security plan.

3.1.2 Identify Applicable Overlays

Overlays identify additional factors (beyond impact) that influence the initial selection of security controls. As CNSS overlays are developed, they are published as attachments to

Appendix F of this Instruction. Each overlay includes an applicability section with a series of questions used to identify whether or not the overlay is applicable to an information system.

Review the questions in each overlay identified in Appendix F to determine whether or not the overlay applies. Document the applicable overlay(s) in the security plan.

3.2 RMF STEP 2: SELECT SECURITY CONTROLS

For NSS, Security Control Selection (RMF Step 2, Task 2-2) is a two-step process:

1. Select the initial security control set.

2. Tailor the initial security control set.

3.2.1 Select the Initial Security Control Set

Once the security category of the information system is determined, organizations begin the security control selection process. To identify the initial security control set, complete the following activities:

1. Select the baseline security controls identified from Table D-1 in Appendix D corresponding to the security category of the system (i.e., the impact values determined for each security objective [confidentiality, integrity, and availability]).

2. Apply any overlay(s) identified as applicable during security categorization. If the use of multiple overlays results in conflicts between the application or removal of security controls, the authorizing official (or designee), in coordination with the information owner/steward, information system owner, and risk executive (function) resolves the conflict.

3. Document the initial security control set and the rationale for adding or removing security controls from the baseline by referencing the applicable overlay(s) in the security plan.

3.2.2 Tailor the Initial Security Control Set

Organizations initiate the tailoring process to modify and align the initial control set to more closely account for conditions affecting the specific system (i.e., conditions related to organizational missions/business functions, information systems, or environments of operation).

Organizations should remove security controls only as a function of specified, risk-based determinations. During the tailoring process, a risk assessment – either informal or formal – should be conducted. The results from a risk assessment provide information about the necessity and sufficiency of security controls and enhancements during the tailoring process. To tailor the initial security control set, complete the following activities:

1. Tailor the initial security control set using Table D-2, Appendix E, and NIST SP 800-53, Section 3.2.

2. Determine whether or not additional assurance–related controls are needed to increase the level of trustworthiness in the information system. If so, tailor the set of controls accordingly. (See NIST SP 800-53, Appendix E.)

3. Document in the security plan the relevant decisions made during the tailoring process, providing a sound rationale for those decisions.

4. Document and justify in the security plan any security controls from the initial security control set that cannot or will not be implemented in the system and for which no compensating control(s) will be substituted. At the discretion of the authorizing official, this information may be included in the plan of action and milestones.

8All of the guidance in NIST SP 800-53, Section 3.2 applies to NSS except for the subsection titled “Security Objective-Related

Considerations.” This subsection is specific to the NIST baselines and does not apply to NSS.

A-1

APPENDIX A

REFERENCES

LAWS, POLICIES, DIRECTIVES, REGULATIONS, MEMORANDA, STANDARDS, AND

GUIDELINES

Appendix A provides the references used within CNSSI No. 1253.

1. 44 U.S.C. § 3542, January 2012.

2. Committee on National Security Systems Instruction 4009, National Information

Assurance Glossary, April 2010.

3. Federal Information Processing Standards Publication 199, Standards for Security

Categorization of Federal Information and Information Systems, February 2004.

4. Federal Information Processing Standards Publication 200, Minimum Security

Requirements for Federal Information and Information Systems, March 2006.

5. Federal Information Security Management Act (P.L. 107-347, Title III), December 2002.

6. National Institute of Standards and Technology Special Publication 800-30, Guide for

Conducting Risk Assessments, September 2012.

7. National Institute of Standards and Technology Special Publication 800-37, Revision 1, Guide for Applying the Risk Management Framework to Federal Information Systems: A

Security Life Cycle Approach, February 2010.

8. National Institute of Standards and Technology Special Publication 800-39, Managing

Information Security Risk: Organization, Mission, and Information System View, March 2011.

9. National Institute of Standards and Technology Special Publication 800-53, Revision 4, Security and Privacy Controls for Federal Information Systems and Organizations, April 2013.

10. National Institute of Standards and Technology Special Publication 800-53A, Guide for Assessing the Security Controls in Federal Information Systems and Organizations:

Building Effective Security Assessment Plans, June 2010.

11. National Institute of Standards and Technology Special Publication 800-59, Guideline for Identifying an Information System as a National Security System, August 2003.

12. National Institute of Standards and Technology Special Publication 800-60, Revision 1, Volume I: Guide for Mapping Types of Information and Information Systems to Security

Categories, August 2008.

13. National Institute of Standards and Technology Special Publication 800-60, Revision 1, Volume II: Appendices to Guide for Mapping Types of Information and Information

Systems to Security Categories, August 2008

14. National Security Directive 42, National Policy for the Security of National Security

Telecommunications and Information Systems, July 1990.

9 Includes errata update as of 7 May 2013.

B-1

APPENDIX B

GLOSSARY

COMMON TERMS AND DEFINITIONS

The terms in this document are defined in the NIST JTF documents and CNSSI No. 4009, except for those listed below.

Initial Security Control Set The set of security controls resulting from the combination of a baseline and applicable overlays prior to system specific tailoring.

NSS baselines

The combination of NIST 800-53 baselines (represented by an “X”) and the additional NIST SP 800-53 security controls required for NSS (represented by a “+”) that are applicable to NSS.

Provisional security impact values

[NIST SP 800-60,

Adapted]

The initial or conditional impact determinations made until all considerations are fully reviewed, analyzed, and accepted in the subsequent categorization steps by appropriate officials.

Security Control Extension A statement, used in security control overlays, that extends the basic capability of a security control by specifying additional functionality, altering the strength mechanism, or adding or limiting implementation options.

C-1

APPENDIX C

ACRONYMS

COMMON ABBREVIATIONS

The acronyms and abbreviations used in this Instruction are included below. Control related acronyms included in the tables of appendices D and E are defined in NIST SP 800-53.

APT Advanced Persistent Threat

CNSS Committee on National Security Systems

CNSSI

Committee on National Security Systems Instruction

EO Executive Order

FIPS

Federal Information Processing Standards

FISMA Federal Information Security Management Act

HWM High Water Mark

JTF Joint Task Force Transformation Initiative Working Group

NIST National Institute of Standards and Technology

NSS National Security System

RMF Risk Management Framework

P.L. Public Law

SC Security Category

SDLC System Development Life Cycle

SP Special Publication

U.S. United States

U.S.C. United States Code

D-1

APPENDIX D

SECURITY CONTROL TABLES

D.1 NSS SECURITY CONTROL BASELINES

Table D-1 uses a 3-by-3 matrix to identify applicability of security controls in the NIST SP 800- 53, Revision 4 baselines for NSS. The matrix also identifies the additional security controls needed to protect NSS. This table represents the security controls applicable to NSS based on impact values.

The 3-by-3 matrix has nine columns showing three possible impact values (low, moderate, or high) for each of the three security objectives (confidentiality, integrity, or availability). The

"X"s in the table reflect the NIST specifications by impact value (i.e., low, moderate, and high).

The "+"s in the table reflect the additional CNSS specifications by impact value for all NSS. The association of security controls to security objectives is detailed in table D-2. A blank space in the table signifies the control was either not selected or not allocated to a particular security objective for the purposes of this Instruction. Controls that are designated as “withdrawn” indicate that they are no longer in the NIST SP 800-53 security control catalog

Table D-1: NSS Security Control Baselines

ID TITLE

Confidentiality Integrity Availability

L M H L M H L M H

AC-1 Access Control Policy and Procedures X X X X X X X X X

AC-2 Account Management X X X X X X

AC-2(1) Account Management | Automated System

Account Management X X X X

AC-2(2) Account Management | Removal of

Temporary / Emergency Accounts X X X X

AC-2(3) Account Management | Disable Inactive

Accounts X X X X

AC-2(4) Account Management | Automated Audit

Actions + X X + X X

AC-2(5) Account Management | Inactivity Logout + + X + + X + + X

AC-2(6) Account Management | Dynamic Privilege

Management

AC-2(7) Account Management | Role-Based Schemes + + + + + +

AC-2(8) Account Management | Dynamic Account

Creation

AC-2(9) Account Management | Restrictions on Use of

Shared Groups / Accounts + + + + + +

AC-2(10) Account Management | Shared / Group

Account Credential Termination + + + + + +

AC-2(11) Account Management | Usage Conditions X X

AC-2(12) Account Management | Account Monitoring / + + X + + X

10 Changes to the security control catalog are under the authority of NIST.

D-2

L M H L M H L M H

Atypical Usage

AC-2(13) Account Management | Disable Accounts For

High-Risk Individuals + + X + + X

AC-3 Access Enforcement X X X X X X

AC-3(1) Access Enforcement | Restricted Access to

Privileged Functions Withdrawn

AC-3(2) Access Enforcement | Dual Authorization

AC-3(3) Access Enforcement | Mandatory Access

Control

AC-3(4) Access Enforcement | Discretionary Access

AC-3(5) Access Enforcement | Security-Relevant

Information

AC-3(6) Access Enforcement | Protection of User and

System Information Withdrawn

AC-3(7) Access Enforcement | Role-Based Access

AC-3(8) Access Enforcement | Revocation of Access

Authorizations

AC-3(9) Access Enforcement | Controlled Release

AC-3(10) Access Enforcement | Audited Override of

Access Control Mechanisms

AC-4 Information Flow Enforcement X X X X

AC-4(1) Information Flow Enforcement | Object

Security Attributes

AC-4(2) Information Flow Enforcement | Processing

Domains

AC-4(3) Information Flow Enforcement | Dynamic

Information Flow Control

AC-4(4) Information Flow Enforcement | Content

Check Encrypted Information

AC-4(5) Information Flow Enforcement | Embedded

Data Types

AC-4(6) Information Flow Enforcement | Metadata

AC-4(7) Information Flow Enforcement | One-Way

Flow Mechanisms

AC-4(8) Information Flow Enforcement | Security

Policy Filters

AC-4(9) Information Flow Enforcement | Human

Reviews

AC-4(10) Information Flow Enforcement | Enable /

Disable Security Policy Filters

AC-4(11) Information Flow Enforcement |

Configuration of Security Policy Filters

AC-4(12) Information Flow Enforcement | Data Type

Identifiers

AC-4(13) Information Flow Enforcement |

Decomposition Into Policy-Relevant

D-3

L M H L M H L M H

Subcomponents

AC-4(14) Information Flow Enforcement | Security

Policy Filter Constraints

AC-4(15) Information Flow Enforcement | Detection of

Unsanctioned Information

AC-4(16) Information Flow Enforcement | Information

Transfers on Interconnected Systems Withdrawn

AC-4(17) Information Flow Enforcement | Domain

Authentication

AC-4(18) Information Flow Enforcement | Security

Attribute Binding

AC-4(19) Information Flow Enforcement | Validation of Metadata

AC-4(20) Information Flow Enforcement | Approved

Solutions

AC-4(21) Information Flow Enforcement | Physical /

Logical Separation of Information Flows

AC-4(22) Information Flow Enforcement | Access Only

AC-5 Separation of Duties + X X + X X

AC-6 Least Privilege + X X + X X

AC-6(1) Least Privilege | Authorize Access to Security

Functions + X X + X X

AC-6(2) Least Privilege | Non-Privileged Access For

Nonsecurity Functions + X X + X X

AC-6(3) Least Privilege | Network Access to

Privileged Commands X X

AC-6(4) Least Privilege | Separate Processing

Domains

AC-6(5) Least Privilege | Privileged Accounts + X X + X X

AC-6(6) Least Privilege | Privileged Access by Non-

Organizational Users

AC-6(7) Least Privilege | Review of User Privileges + + + + + +

AC-6(8) Least Privilege | Privilege Levels For Code

Execution

AC-6(9) Least Privilege | Auditing Use of Privileged

Functions + X X + X X

AC-6(10) Least Privilege | Prohibit Nonprivileged

Users from Executing Privileged Functions + X X + X X

AC-7 Unsuccessful Logon Attempts X X X X X X X X X

AC-7(1) Unsuccessful Logon Attempts | Automatic

Account Lock Withdrawn

AC-7(2) Unsuccessful Logon Attempts | Purge/Wipe

Mobile Device

AC-8 System Use Notification X X X X X X

AC-9 Previous Logon (Access) Notification

AC-9(1) Previous Logon Notification | Unsuccessful

D-4

L M H L M H L M H

Logons

AC-9(2) Previous Logon Notification | Successful /

Unsuccessful Logons

AC-9(3) Previous Logon Notification | Notification of

Account Changes

AC-9(4) Previous Logon Notification | Additional

Logon Information

AC-10 Concurrent Session Control + X + X + X

AC-11 Session Lock + X X + X X

AC-11(1) Session Lock | Pattern-Hiding Displays + X X

AC-12 Session Termination X X X X

AC-12(1) Session Termination | User-initiated Logouts

/ Message Displays + + + +

AC-13 Supervision and Review — Access Control Withdrawn

AC-14 Permitted Actions Without Identification or

Authentication X X X X X X

AC-14(1) Permitted Actions Without Identification or

Authentication | Necessary Uses Withdrawn

AC-15 Automated Marking Withdrawn

AC-16 Security Attributes + + + +

AC-16(1) Security Attributes | Dynamic Attribute

Association

AC-16(2) Security Attributes | Attribute Value Changes by Authorized Individuals

AC-16(3) Security Attributes | Maintenance of Attribute

Associations by Information System

AC-16(4) Security Attributes | Association of Attributes by Authorized Individuals

AC-16(5) Security Attributes | Attribute Displays For

Output Devices

AC-16(6) Security Attributes | Maintenance of Attribute

Association by Organization + + + +

AC-16(7) Security Attributes | Consistent Attribute

Interpretation

AC-16(8) Security Attributes | Association Techniques /

Technologies

AC-16(9) Security Attributes | Attribute Reassignment

AC-

16(10)

Security Attributes | Attribute Configuration by Authorized Individuals

AC-17 Remote Access X X X X X X

AC-17(1) Remote Access | Automated Monitoring /

Control + X X + X X

AC-17(2) Remote Access | Protection of Confidentiality

/ Integrity Using Encryption + X X + X X

AC-17(3) Remote Access | Managed Access Control

Points + X X + X X

D-5

L M H L M H L M H

AC-17(4) Remote Access | Privileged Commands /

Access + X X + X X

AC-17(5) Remote Access | Monitoring For

Unauthorized Connections Withdrawn

AC-17(6) Remote Access | Protection of Information + + +

AC-17(7) Remote Access | Additional Protection For

Security Function Access Withdrawn

AC-17(8) Remote Access | Disable Nonsecure Network

Protocols Withdrawn

AC-17(9) Remote Access | Disconnect / Disable Access + + + + + +

AC-18 Wireless Access X X X X X X

AC-18(1) Wireless Access | Authentication and

Encryption + X X + X X

AC-18(2) Wireless Access | Monitoring Unauthorized

Connections Withdrawn

AC-18(3) Wireless Access | Disable Wireless

Networking

AC-18(4) Wireless Access | Restrict Configurations by

Users + + X + + X

AC-18(5) Wireless Access | Antennas / Transmission

Power Levels X X

AC-19 Access Control For Mobile Devices X X X X X X

AC-19(1) Access Control For Mobile Devices | Use of

Writable / Portable Storage Devices Withdrawn

AC-19(2) Access Control For Mobile Devices | Use of

Personally Owned Portable Storage Devices Withdrawn

AC-19(3) Access Control For Mobile Devices | Use of

Portable Storage Devices with No

Identifiable Owner

Withdrawn

AC-19(4) Access Control For Mobile Devices |

Restrictions For Classified Information

AC-19(5) Access Control For Mobile Devices | Full

Device / Container-Based Encryption X X X X

AC-20 Use of External Information Systems X X X X X X

AC-20(1) Use of External Information Systems | Limits on Authorized Use + X X + X X

AC-20(2) Use of External Information Systems |

Portable Storage Devices + X X

AC-20(3) Use of External Information Systems | Non-

Organizationally Owned Systems / /

Components / Devices

AC-20(4) Use of External Information Systems |

Network Accessible Storage Devices

AC-21 Information Sharing X X

AC-21(1) Information Sharing | Automated Decision

Support

AC-21(2) Information Sharing | Information Search and

Retrieval

D-6

L M H L M H L M H

AC-22 Publicly Accessible Content X X X

AC-23 Data Mining Protection + +

AC-24 Access Control Decisions

AC-24(1) Access Control Decisions | Transmit Access

Authorization Information

AC-24(2) Access Control Decisions | No User or

Process Identity

AC-25 Reference Monitor

AT-1 Security Awareness and Training Policy and

Procedures X X X X X X X X X

AT-2 Security Awareness Training X X X X X X X X X

AT-2(1) Security Awareness | Practical Exercises

AT-2(2) Security Awareness | Insider Threat + X X + X X + X X

AT-3 Role-Based Security Training X X X X X X X X X

AT-3(1) Security Training | Environmental Controls

AT-3(2) Security Training | Physical Security Controls + + + + + + + + +

AT-3(3) Security Training | Practical Exercises

AT-3(4) Security Training | Suspicious

Communications and Anomalous System

Behavior

AT-4 Security Training Records X X X X X X X X X

AT-5 Contacts With Security Groups and

Associations Withdrawn

AU-1 Audit and Accountability Policy and

Procedures X X X X X X X X X

AU-2 Audit Events X X X X X X

AU-2(1) Audit Events | Compilation of Audit Records

From Multiple Sources Withdrawn

AU-2(2) Audit Events | Selection of Audit Events by

Component Withdrawn

AU-2(3) Audit Events | Reviews and Updates + X X + X X

AU-2(4) Audit Events | Privileged Functions Withdrawn

AU-3 Content of Audit Records X X X X X X

AU-3(1) Content of Audit Records | Additional Audit

Information + X X + X X

AU-3(2) Content of Audit Records | Centralized

Management of Planned Audit Record

Content

X X

AU-4 Audit Storage Capacity X X X

AU-4(1) Audit Storage Capacity | Transfer to Alternate

Storage

AU-5 Response to Audit Processing Failures X X X

AU-5(1) Response to Audit Processing Failures | Audit

Storage Capacity + + X

AU-5(2) Response to Audit Processing Failures | Real- X

D-7

L M H L M H L M H

Time Alerts

AU-5(3) Response to Audit Processing Failures |

Configurable Traffic Volume Thresholds

AU-5(4) Response to Audit Processing Failures |

Shutdown on Failure

AU-6 Audit Review, Analysis, and Reporting X X X X X X

AU-6(1) Audit Review, Analysis, and Reporting |

Process Integration + X X + X X

AU-6(2) Audit Review, Analysis, and Reporting |

Automated Security Alerts Withdrawn

AU-6(3) Audit Review, Analysis, and Reporting |

Correlate Audit Repositories + X X + X X

AU-6(4) Audit Review, Analysis, and Reporting |

Central Review and Analysis + + + + + +

AU-6(5) Audit Review, Analysis, and Reporting |

Integration / Scanning and Monitoring

Capabilities

X X

AU-6(6) Audit Review, Analysis, and Reporting |

Correlation With Physical Monitoring X X

AU-6(7) Audit Review, Analysis, and Reporting |

Permitted Actions

AU-6(8) Audit Review, Analysis, and Reporting | Full

Text Analysis of Privileged Commands

AU-6(9) Audit Review, Analysis, and Reporting |

Correlation with Information from

Nontechnical Sources

AU-6(10) Audit Review, Analysis, and Reporting |

Audit Level Adjustment + + + + + +

AU-7 Audit Reduction and Report Generation X X X X

AU-7(1) Audit Reduction and Report Generation |

Automatic Processing X X X X

AU-7(2) Audit Reduction and Report Generation |

Automatic Sort and Search

AU-8 Time Stamps X X X

AU-8(1) Time Stamps | Synchronization With

Authoritative Time Source + X X

AU-8(2) Time Stamps | Secondary Authoritative Time

Source

AU-9 Protection of Audit Information X X X X X X X X X

AU-9(1) Protection of Audit Information | Hardware

Write-Once Media

AU-9(2) Protection of Audit Information | Audit

Backup on Separate Physical Systems /

Components

X

AU-9(3) Protection of Audit Information |

Cryptographic Protection X

AU-9(4) Protection of Audit Information | Access by

Subset of Privileged Users + X X + X X

D-8

L M H L M H L M H

AU-9(5) Protection of Audit Information | Dual

Authorization

AU-9(6) Protection of Audit Information | Read Only

Access

AU-10 Non-Repudiation + X

AU-10(1) Non-Repudiation | Association of Identities

AU-10(2) Non-Repudiation | Validate Binding of

Information Producer Identity

AU-10(3) Non-Repudiation | Chain of Custody

AU-10(4) Non-Repudiation | Validate Binding of

Information Reviewer Identity

AU-10(5) Non-Repudiation | Digital Signatures Withdrawn

AU-11 Audit Record Retention X X X

AU-11(1) Audit Record Retention | Long-Term

Retrieval Capability

AU-12 Audit Generation X X X X X X

AU-12(1) Audit Generation | System-Wide / Time-

Correlated Audit Trail + + X

AU-12(2) Audit Generation | Standardized Formats

AU-12(3) Audit Generation | Changes by Authorized

Individuals + + X + + X

AU-13 Monitoring For Information Disclosure

AU-13(1) Monitoring For Information Disclosure | Use of Automated Tools

AU-13(2) Monitoring For Information Disclosure |

Review of Monitored Sites

AU-14 Session Audit + + + + + +

AU-14(1) Session Audit | System Start-Up + + + + + +

AU-14(2) Session Audit | Capture/Record and Log

Content

AU-14(3) Session Audit | Remote Viewing / Listening + + +

AU-15 Alternate Audit Capability

AU-16 Cross-Organizational Auditing

AU-16(1) Cross-Organizational Auditing | Identity

Preservation

AU-16(2) Cross-Organizational Auditing | Sharing of

Audit Information

CA-1 Security Assessment and Authorization

Policies and Procedures X X X X X X X X X

CA-2 Security Assessments X X X X X X X X X

CA-2(1) Security Assessments | Independent

Assessors + X X + X X + X X

CA-2(2) Security Assessments | Specialized

Assessments X X X

CA-2(3) Security Assessments | External

Organizations

D-9

L M H L M H L M H

CA-3 System Interconnections X X X X X X

CA-3(1) System Interconnections | Unclassified

National Security System Connections + + +

CA-3(2) System Interconnections | Classified National

Security System Connections

CA-3(3) System Interconnections | Unclassified Non-

National Security System Connections

CA-3(4) System Interconnections | Connections to

Public Networks

CA-3(5) System Interconnections | Restrictions on

External Network Connections + X X + X X

CA-4 Security Certification Withdrawn

CA-5 Plan of Action and Milestones X X X X X X X X X

CA-5(1) Plan of Action and Milestones | Automation

Support For Accuracy / Currency

CA-6 Security Authorization X X X X X X X X X

CA-7 Continuous Monitoring X X X X X X X X X

CA-7(1) Continuous Monitoring | Independent

Assessment X X X X X X

CA-7(2) Continuous Monitoring | Types of

Assessments Withdrawn

CA-7(3) Continuous Monitoring | Trend Analyses

CA-8 Penetration Testing X

CA-8(1) Penetration Testing | Independent Penetration

Agent or Team

CA-8(2) Penetration Testing | Red Team Exercises

CA-9 Internal System Connections X X X X X X

CA-9(1) Internal System Connections | Security

Compliance Checks

CM-1 Configuration Management Policy and

Procedures X X X X X X

CM-2 Baseline Configuration X X X

CM-2(1) Baseline Configuration | Reviews and

Updates + X X

CM-2(2) Baseline Configuration | Automation Support

For Accuracy / Currency X

CM-2(3) Baseline Configuration | Retention of

Previous Configurations X X

CM-2(4) Baseline Configuration | Unauthorized

Software Withdrawn

CM-2(5) Baseline Configuration | Authorized Software Withdrawn

CM-2(6) Baseline Configuration | Development and

Test Environments

CM-2(7) Baseline Configuration | Configure Systems, Components, or Devices for High-Risk Areas X X

CM-3 Configuration Change Control + X X

D-10

L M H L M H L M H

CM-3(1) Configuration Change Control | Automated

Document / Notification / Prohibition of

Changes

X

CM-3(2) Configuration Change Control | Test /

Validate / Document Changes X X

CM-3(3) Configuration Change Control | Automated

Change Implementation

CM-3(4) Configuration Change Control | Security

Representative

CM-3(5) Configuration Change Control | Automated

Security Response

CM-3(6) Configuration Change Control | Cryptography

Management

CM-4 Security Impact Analysis X X X

CM-4(1) Security Impact Analysis | Separate Test

Environments + X

CM-4(2) Security Impact Analysis | Verification of

Security Functions

CM-5 Access Restrictions For Change + X X

CM-5(1) Access Restrictions For Change | Automated

Access Enforcement / Auditing + X

CM-5(2) Access Restrictions For Change | Review

System Changes + X

CM-5(3) Access Restrictions For Change | Signed

Components X

CM-5(4) Access Restrictions For Change | Dual

CM-5(5) Access Restrictions For Change | Limit

Production / Operational Privileges + + +

CM-5(6) Access Restrictions For Change | Limit

Library Privileges

CM-5(7) Access Restrictions For Change | Automatic

Implementation of Security Safeguards Withdrawn

CM-6 Configuration Settings X X X

CM-6(1) Configuration Settings | Automated Central

Management / Application / Verification + X

CM-6(2) Configuration Settings | Respond to

Unauthorized Changes X

CM-6(3) Configuration Settings | Unauthorized

Change Detection Withdrawn

CM-6(4) Configuration Settings | Conformance

Demonstration Withdrawn

CM-7 Least Functionality X X X X X X

CM-7(1) Least Functionality | Periodic Review + X X + X X

CM-7(2) Least Functionality | Prevent Program

Execution + X X + X X

CM-7(3) Least Functionality | Registration Compliance + + + + + +

CM-7(4) Least Functionality | Unauthorized Software /

D-11

L M H L M H L M H

Blacklisting

CM-7(5) Least Functionality | Authorized Software /

Whitelisting + + X + + X

CM-8 Information System Component Inventory X X X

CM-8(1) Information System Component Inventory |

Updates During Installations / Removals X X

CM-8(2) Information System Component Inventory |

Automated Maintenance + + X

CM-8(3) Information System Component Inventory |

Automated Unauthorized Component

Detection

+ X X

CM-8(4) Information System Component Inventory |

Accountability Information X X

CM-8(5) Information System Component Inventory |

No Duplicate Accounting of Components X X

CM-8(6) Information System Component Inventory |

Assessed Configurations / Approved

Deviations

CM-8(7) Information System Component Inventory |

Centralized Repository

CM-8(8) Information System Component Inventory |

Automated Location Tracking

CM-8(9) Information System Component Inventory |

Assignment of Components to Systems

CM-9 Configuration Management Plan + X X

CM-9(1) Configuration Management Plan |

Assignment of Responsibility

CM-10 Software Usage Restrictions X X X

CM-10(1) Software Usage Restrictions | Open Source

Software

CM-11 User-Installed Software X X X X X X

CM-11(1) User-Installed Software | Alerts For

Unauthorized Installations

CM-11(2) User-Installed Software | Prohibit Installation without Privileged Status + + + + + +

CP-1 Contingency Planning Policy and Procedures X X X X X X X X X

CP-2 Contingency Plan X X X

CP-2(1) Contingency Plan | Coordinate With Related

Plans X X

CP-2(2) Contingency Plan | Capacity Planning X

CP-2(3) Contingency Plan | Resume Essential

Missions / Business Functions X X

CP-2(4) Contingency Plan | Resume All Missions /

Business Functions X

CP-2(5) Contingency Plan | Continue Essential

Missions / Business Functions X

CP-2(6) Contingency Plan | Alternate Processing /

D-12

L M H L M H L M H

Storage Site

CP-2(7) Contingency Plan | Coordinate With External

Service Providers

CP-2(8) Contingency Plan | Identify Critical Assets X X

CP-3 Contingency Training X X X

CP-3(1) Contingency Training | Simulated Events X

CP-3(2) Contingency Training | Automated Training

Environments

CP-4 Contingency Plan Testing X X X

CP-4(1) Contingency Plan Testing | Coordinate With

Related Plans X X

CP-4(2) Contingency Plan Testing | Alternate

Processing Site X

CP-4(3) Contingency Plan Testing | Automated

Testing

CP-4(4) Contingency Plan Testing | Full Recovery /

Reconstitution

CP-5 Contingency Plan Update Withdrawn

CP-6 Alternate Storage Site X X

CP-6(1) Alternate Storage Site | Separation From

Primary Site X X

CP-6(2) Alternate Storage Site | Recovery Time /

Point Objectives X

CP-6(3) Alternate Storage Site | Accessibility X X

CP-7 Alternate Processing Site X X X X X X

CP-7(1) Alternate Processing Site | Separation From

Primary Site X X

CP-7(2) Alternate Processing Site | Accessibility X X

CP-7(3) Alternate Processing Site | Priority of Service X X

CP-7(4) Alternate Processing Site | Preparation for

Use X

CP-7(5) Alternate Processing Site | Equivalent

Information Security Safeguards Withdrawn

CP-7(6) Alternate Processing Site | Inability to Return to Primary Site

CP-8 Telecommunications Services X X

CP-8(1) Telecommunications Services | Priority of

Service Provisions X X

CP-8(2) Telecommunications Services | Single Points of Failure X X

CP-8(3) Telecommunications Services | Separation of

Primary / Alternate Providers X

CP-8(4) Telecommunications Services | Provider

Contingency Plan X

CP-8(5) Telecommunications Services | Alternate

Telecommunication Service Testing +

CP-9 Information System Backup X X X X X X X X X

D-13

L M H L M H L M H

CP-9(1) Information System Backup | Testing For

Reliability / Integrity X X X X

CP-9(2) Information System Backup | Test

Restoration Using Sampling X

CP-9(3) Information System Backup | Separate

Storage for Critical Information X

CP-9(4) Information System Backup | Protection

From Unauthorized Modification Withdrawn

CP-9(5) Information System Backup | Transfer to

Alternate Storage Site + X

CP-9(6) Information System Backup | Redundant

Secondary System

CP-9(7) Information System Backup | Dual

CP-10 Information System Recovery and

Reconstitution X X X

CP-10(1) Information System Recovery and

Reconstitution | Contingency Plan Testing Withdrawn

CP-10(2) Information System Recovery and

Reconstitution | Transaction Recovery X X X X

CP-10(3) Information System Recovery and

Reconstitution | Compensating Security

Controls

Withdrawn

CP-10(4) Information System Recovery and

Reconstitution | Restore Within Time Period X X

CP-10(5) Information System Recovery and

Reconstitution | Failover Capability Withdrawn

CP-10(6) Information System Recovery and

Reconstitution | Component Protection

CP-11 Alternate Communications Protocols

CP-12 Safe Mode

CP-13 Alternative Security Mechanisms

IA-1 Identification and Authentication Policy and

Procedures X X X X X X

IA-2 Identification and Authentication

(Organizational Users) X X X X X X

IA-2(1) Identification and Authentication

(Organizational Users) | Network Access to

Privileged Accounts

X X X X X X

IA-2(2) Identification and Authentication

(Organizational Users) | Network Access to

Non-Privileged Accounts

+ X X + X X

IA-2(3) Identification and Authentication

(Organizational Users) | Local Access to

Privileged Accounts

X X X X

IA-2(4) Identification and Authentication

(Organizational Users) | Local Access to

Non-Privileged Accounts

+ X + X

D-14

L M H L M H L M H

IA-2(5) Identification and Authentication

(Organizational Users) | Group

Authentication

IA-2(6) Identification and Authentication

(Organizational Users) | Network Access to

Privileged Accounts - Separate Device

IA-2(7) Identification and Authentication

Non-Privileged Accounts - Separate Device

IA-2(8) Identification and Authentication

Privileged Accounts - Replay Resistant

+ X X + X X

IA-2(9) Identification and Authentication

(Organizational Users) | Network Access to

Non-Privileged Accounts - Replay Resistant

+ X + X

IA-2(10) Identification and Authentication

(Organizational Users) | Single Sign-On

IA-2(11) Identification and Authentication

(Organizational Users) | Remote Access -

Separate Device

+ X X + X X

IA-2(12) Identification and Authentication

(Organizational Users) | Acceptance of PIV

Credentials

X X X X X X

IA-2(13) Identification and Authentication | Out-of-

Band Authentication

IA-3 Device Identification and Authentication + X X + X X

IA-3(1) Device Identification and Authentication |

Cryptographic Bidirectional Authentication + + + +

IA-3(2) Device Identification and Authentication |

Cryptographic Bidirectional Network

Authentication

Withdrawn

IA-3(3) Device Identification and Authentication |

Dynamic Address Allocation

IA-3(4) Device Identification and Authentication |

Device Attestation

IA-4 Identifier Management X X X X X X

IA-4(1) Identifier Management | Prohibit Account

Identifiers As Public Identifiers

IA-4(2) Identifier Management | Supervisor

IA-4(3) Identifier Management | Multiple Forms of

Certification

IA-4(4) Identifier Management | Identify User Status + + + + + +

IA-4(5) Identifier Management | Dynamic

IA-4(6) Identifier Management | Cross-Organization

IA-4(7) Identifier Management | In Person

Registration

IA-5 Authenticator Management X X X X X X

D-15

L M H L M H L M H

IA-5(1) Authenticator Management | Password-Based

Authentication X X X X X X

IA-5(2) Authenticator Management | PKI-Based

Authentication X X X X

IA-5(3) Authenticator Management | In Person or

Trusted Third-Party Registration X X

IA-5(4) Authenticator Management | Automated

Support for Password Strength Determination + + + + + +

IA-5(5) Authenticator Management | Change

Authenticators Prior to Delivery

IA-5(6) Authenticator Management | Protection of

Authenticators

IA-5(7) Authenticator Management | No Embedded

Unencrypted Static Authenticators + + +

IA-5(8) Authenticator Management | Multiple

Information System Accounts + + + + + +

IA-5(9) Authenticator Management | Cross-

Organization Credential Management

IA-5(10) Authenticator Management | Dynamic

Credential Association

IA-5(11) Authenticator Management | Hardware

Token-Based Authentication X X X

IA-5(12) Authenticator Management | Biometric

Authentication

IA-5(13) Authenticator Management | Expiration of

Cached Authenticators + + + + + +

IA-5(14) Authenticator Management | Managing

Content of PKI Trust stores + + + + + +

IA-5(15) Authenticator Management | FICAM-

Approved Products and Services

IA-6 Authenticator Feedback X X X

IA-7 Cryptographic Module Authentication X X X X X X

IA-8 Identification and Authentication (Non-

Organizational Users) X X X X X X

IA-8(1) Identification and Authentication (Non-

Organizational Users) | Acceptance of PIV

Credentials from Other Agencies

X X X X X X

IA-8(2) Identification and Authentication (Non-

Organizational Users) | Acceptance of Third-

Party Credentials

X X X

IA-8(3) Identification and Authentication (Non-

Organizational Users) | Use of FICAM-

Approved Products

X X X

IA-8…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .