Section_C_PDGU_SOO_Appendix_C_SRTM_26Aug15.xlsx

XLSX spreadsheet 186 KB Posted

Attached to
Sustainment Upgrade for F-16 Programmable Display Generator Federal contract opportunity
Solicitation number
FA8232-16-R-3001
Issued by
Department of the Air Force Materiel Command Lifecycle Management Center Wright Patterson Air Force Base

About this file

PDGU SRTM File Embedded in Appendix C of the SOO (Reference Amendment 0001)

View the file

Other files for this federal contract opportunity

Other files attached to Sustainment Upgrade for F-16 Programmable Display Generator, newest first.
File Type Posted
Correction_to_Questions_15 _37 _ _144.pdf PDF
FA8232-16-R-3001_RFP_Q A_143 144_11Jan16.pdf PDF
Section_J_Attachment_Labor_Rate_Matrix0002.xlsx XLSX spreadsheet
Section_C_PDGU_SOO_7JAN16.pdf PDF
Exhibit_A_Admin_CDRLs_6Jan16.pdf PDF
Section_J_Attachment_Labor_Categories_Mapping_Worksheet0002.xlsx XLSX spreadsheet
FOUO_PDGU_TEP_Table_6Jan16.xlsx XLSX spreadsheet
FA823216R3001_______0002.pdf PDF
FA8232-16-R-3001_RFP_Q A_131_-_142_6_Jan_16.pdf PDF
FA8232-16-R-3001_RFP_Q A_13_-_118_18Dec15.pdf PDF
ppi_tool_4Dec15.accdb —
FA8232-16-R-3001_RFP_Q A_1_-_12_3Dec15.pdf PDF
Section_L_PDGU_1Dec15.pdf PDF
FA823216R3001_______0001_3Dec15.pdf PDF
Section_M_PDGU_3Dec15b.pdf PDF
Exhibit_B_TDP_CDRL.pdf PDF
Exhibit_A_Admin_CDRLs_19Nov15.pdf PDF
Section_C_PDGU_SOO_19_NOV.pdf PDF
Section_J_Attachment_Labor_Rate_Matrix_8_Oct.xlsx XLSX spreadsheet
Section_J_Attachment_Labor_Categories_Mapping_Worksheet.xlsx XLSX spreadsheet
Section_M_PDGU_26Oct15.pdf PDF
FA823216R3001_20Nov15.pdf PDF
Section_L_Attachment_Nine_Sample_BOE_Summary.xlsx XLSX spreadsheet
Section_L_Attachments_One_through_Seven_21Oct15.pdf PDF
FOUO_PDGU_TEP_Table_20Nov15.xlsx XLSX spreadsheet
PDGU_Draft_DD_254_4Nov15.pdf PDF
Section_L_PDGU_2Nov2015.pdf PDF
Section_L_Attachment_Eight_Email_Encryption_13Oct10.pdf PDF
Show all 28

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Aircraft Domain SRTM

NOTE: Once the compliance/non-compliance columns are populated: classify, store, mark and handle this document IAW the program security classification guide.
CtrlID2IDCONTROL NAME
Control Enhancement NameProgrammable Display Generator UpgradeAir Vehicle

: Air vehicle. This column address the actual aircraft Compliant : Y = Compliant N = Non-Compliant Ground Station Compliant : Y = Compliant N = Non-Compliant Tailoring Rationale / Comments Supplier Rationale / Comments Method of Verification : Refer to Control Assessment tab for general assessment guidance.

The program should identify in this column the detailed approach.Verification ResultsReference docs
1AC-1AC-1Access Control Policy and ProceduresThe AFLCMC/WW F16 System Program Office:

a. Develops, documents, and disseminates to [Assignment: organization-defined personnel or roles]:

1. An access control policy that addresses purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance; and

2. Procedures to facilitate the implementation of the access control policy and associated access controls; and

b. Reviews and updates the current:

1. Access control policy [Assignment: organization-defined frequency]; and

2. Access control procedures [Assignment: organization-defined frequency].XXGovernment
2AC-2AC-2Account ManagementThe organization:

a. Identifies and selects the following types of information system accounts to support organizational missions/business functions: [Assignment: organization-defined information system account types];

b. Assigns account managers for information system accounts;

c. Establishes conditions for group and role membership;

d. Specifies authorized users of the information system, group and role membership, and access authorizations (i.e., privileges) and other attributes (as required) for each account;

e. Requires approvals by [Assignment: organization-defined personnel or roles] for requests to create information system accounts;

f. Creates, enables, modifies, disables, and removes information system accounts in accordance with [Assignment: organization-defined procedures or conditions];

g. Monitors the use of information system accounts;

h. Notifies account managers:

1. When accounts are no longer required;

2. When users are terminated or transferred; and

3. When individual information system usage or need-to-know changes;

i. Authorizes access to the information system based on:

1. A valid access authorization;

2. Intended system usage; and

3. Other attributes as required by the organization or associated missions/business functions;

j. Reviews accounts for compliance with account management requirements [Assignment: organization-defined frequency]; and

k. Establishes a process for reissuing shared/group account credentials (if deployed) when individuals are removed from the group.X
3AC-2(1)AC-2(1)account management | automated system account managementThe organization employs automated mechanisms to support the management of information system accounts.
4AC-2(2)AC-2(2)account management | removal of temporary / emergency accountsThe information system automatically [Selection: removes; disables] temporary and emergency accounts after [Assignment: organization-defined time period for each type of account].
5AC-2(3)AC-2(3)account management | disable inactive accountsThe information system automatically disables inactive accounts after [Assignment: organization-defined time period].
6AC-2(4)AC-2(4)account management | automated audit actionsThe information system automatically audits account creation, modification, enabling, disabling, and removal actions, and notifies [Assignment: organization-defined personnel or roles].
7AC-2(5)AC-2(5)account management | inactivity logoutThe organization requires that users log out when [Assignment: organization-defined time-period of expected inactivity or description of when to log out].
8AC-2(6)AC-2(6)account management | dynamic privilege managementThe information system implements the following dynamic privilege management capabilities: [Assignment: organization-defined list of dynamic privilege management capabilities].
9AC-2(7)AC-2(7)account management | role-based schemesThe organization:

(a) Establishes and administers privileged user accounts in accordance with a role-based access scheme that organizes allowed information system access and privileges into roles;(b) Monitors privileged role assignments; and

(c) Takes [Assignment: organization-defined actions] when privileged role assignments are no longer appropriate.X
10AC-2(8)AC-2(8)account management | dynamic account creationThe information system creates [Assignment: organization-defined information system accounts] dynamically.
11AC-2(9)AC-2(9)account management | restrictions on use of shared groups / accountsThe organization only permits the use of shared/group accounts that meet [Assignment: organization-defined conditions for establishing shared/group accounts].X
12AC-2(10)AC-2(10)account management | shared / group account credential terminationThe information system terminates shared/group account credentials when members leave the group.
13AC-2(11)AC-2(11)account management | usage conditionsThe information system enforces [Assignment: organization-defined circumstances and/or usage conditions] for [Assignment: organization-defined information system accounts].X
14AC-2(12)AC-2(12)account management | account monitoring / atypical usageThe organization:

(a) Monitors information system accounts for [Assignment: organization-defined atypical use]; and

(b) Reports atypical usage of information system accounts to [Assignment: organization-defined personnel or roles].X
15AC-2(13)AC-2(13)account management | disable accounts for high-risk individualsThe organization disables accounts of users posing a significant risk within [Assignment: organization-defined time period] of discovery of the risk.X
16AC-3AC-3Access EnforcementThe information system enforces approved authorizations for logical access to information and system resources in accordance with applicable access control policies.XXSupplier/Government
17AC-3(1)AC-3(1)access enforcement | restricted access to privileged functions[Withdrawn: Incorporated into AC-6].
18AC-3(2)AC-3(2)access enforcement | dual authorizationThe information system enforces dual authorization for [Assignment: organization-defined privileged commands and/or other organization-defined actions].
19AC-3(3)AC-3(3)access enforcement | mandatory access controlThe information system enforces [Assignment: organization-defined mandatory access control policies] over all subjects and objects where the policy specifies that:

(a) The policy is uniformly enforced across all subjects and objects within the boundary of the information system;

(b) A subject that has been granted access to information is constrained from doing any of the following;

(1) Passing the information to unauthorized subjects or objects;

(2) Granting its privileges to other subjects;

(3) Changing one or more security attributes on subjects, objects, the information system, or information system components;

(4) Choosing the security attributes and attribute values to be associated with newly created or modified objects; or

(5) Changing the rules governing access control; and

(c) [Assignment: Organized-defined subjects] may explicitly be granted [Assignment: organization-defined privileges (i.e., they are trusted subjects)] such that they are not limited by some or all of the above constraints.

20 AC-3(4) AC-3(4) access enforcement | discretionary access control The information system enforces [Assignment: organization-defined discretionary access control policies] over defined subjects and objects where the policy specifies that a subject that has been granted access to information can do one or more of the following:

(a) Pass the information to any other subjects or objects;

(b) Grant its privileges to other subjects;

(c) Change security attributes on subjects, objects, the information system, or the information system’s components;

(d) Choose the security attributes to be associated with newly created or revised objects; or

(e) Change the rules governing access control.

21AC-3(5)AC-3(5)access enforcement | security-relevant informationThe information system prevents access to [Assignment: organization-defined security-relevant information] except during secure, non-operable system states.
22AC-3(6)AC-3(6)access enforcement | protection of user and system information[Withdrawn: Incorporated into MP-4 and SC-28].
23AC-3(7)AC-3(7)access enforcement | role-based access controlThe information system enforces a role-based access control policy over defined subjects and objects and controls access based upon [Assignment: organization-defined roles and users authorized to assume such roles].X
24AC-3(8)AC-3(8)access enforcement | revocation of access authorizationsThe information system enforces the revocation of access authorizations resulting from changes to the security attributes of subjects and objects based on [Assignment: organization-defined rules governing the timing of revocations of access authorizations].
25AC-3(9)AC-3(9)access enforcement | controlled releaseThe information system does not release information outside of the established system boundary unless:

(a) The receiving [Assignment: organization-defined information system or system component] provides [Assignment: organization-defined security safeguards]; and

(b) [Assignment: organization-defined security safeguards] are used to validate the appropriateness of the information designated for release.

26AC-3(10)AC-3(10)access enforcement | audited override of access control mechanismsThe organization employs an audited override of automated access control mechanisms under [Assignment: organization-defined conditions].
27AC-4AC-4Information Flow EnforcementThe information system enforces approved authorizations for controlling the flow of information within the system and between interconnected systems based on Root Trust and information flow control policies.XXSupplier/Government
28AC-4(1)AC-4(1)information flow enforcement | object security attributesThe information system uses [Assignment: organization-defined security attributes] associated with [Assignment: organization-defined information, source, and destination objects] to enforce [Assignment: organization-defined information flow control policies] as a basis for flow control decisions.
29AC-4(2)AC-4(2)information flow enforcement | processing domainsThe information system uses protected processing domains to enforce [Assignment: organization-defined information flow control policies] as a basis for flow control decisions.
30AC-4(3)AC-4(3)information flow enforcement | dynamic information flow controlThe information system enforces dynamic information flow control based on [Assignment: organization-defined policies].
31AC-4(4)AC-4(4)information flow enforcement | content check encrypted informationThe information system prevents encrypted information from bypassing content-checking mechanisms by [Selection (one or more): decrypting the information; blocking the flow of the encrypted information; terminating communications sessions attempting to pass encrypted information; [Assignment: organization-defined procedure or method]].
32AC-4(5)AC-4(5)information flow enforcement | embedded data typesThe information system enforces [Assignment: organization-defined limitations] on embedding data types within other data types.
33AC-4(6)AC-4(6)information flow enforcement | metadataThe information system enforces information flow control based on [Assignment: organization-defined metadata].
34AC-4(7)AC-4(7)information flow enforcement | one-way flow mechanismsThe information system enforces [Assignment: organization-defined one-way flows] using hardware mechanisms.X
35AC-4(8)AC-4(8)information flow enforcement | security policy filtersThe information system enforces information flow control using [Assignment: organization-defined security policy filters] as a basis for flow control decisions for [Assignment: organization-defined information flows].
36AC-4(9)AC-4(9)information flow enforcement | human reviewsThe information system enforces the use of human reviews for [Assignment: organization-defined information flows] under the following conditions: [Assignment: organization-defined conditions].
37AC-4(10)AC-4(10)information flow enforcement | enable / disable security policy filtersThe information system provides the capability for privileged administrators to enable/disable [Assignment: organization-defined security policy filters] under the following conditions: [Assignment: organization-defined conditions].
38AC-4(11)AC-4(11)information flow enforcement | configuration of security policy filtersThe information system provides the capability for privileged administrators to configure [Assignment: organization-defined security policy filters] to support different security policies.
39AC-4(12)AC-4(12)information flow enforcement | data type identifiersThe information system, when transferring information between different security domains, uses [Assignment: organization-defined data type identifiers] to validate data essential for information flow decisions.
40AC-4(13)AC-4(13)information flow enforcement | decomposition into policy-relevant subcomponentsThe information system, when transferring information between different security domains, decomposes information into [Assignment: organization-defined policy-relevant subcomponents] for submission to policy enforcement mechanisms.
41AC-4(14)AC-4(14)information flow enforcement | security policy filter constraintsThe information system, when transferring information between different security domains, implements [Assignment: organization-defined security policy filters] requiring fully enumerated formats that restrict data structure and content.
42AC-4(15)AC-4(15)information flow enforcement | detection of unsanctioned informationThe information system, when transferring information between different security domains, examines the information for the presence of [Assignment: organized-defined unsanctioned information] and prohibits the transfer of such information in accordance with the [Assignment: organization-defined security policy].
43AC-4(16)AC-4(16)information flow enforcement | information transfers on interconnected systems[Withdrawn: Incorporated into AC-4].
44AC-4(17)AC-4(17)information flow enforcement | domain authenticationThe information system uniquely identifies and authenticates source and destination points by [Selection (one or more): organization, system, application, individual] for information transfer.
45AC-4(18)AC-4(18)information flow enforcement | security attribute bindingThe information system binds security attributes to information using [Assignment: organization-defined binding techniques] to facilitate information flow policy enforcement.
46AC-4(19)AC-4(19)information flow enforcement | validation of metadataThe information system, when transferring information between different security domains, applies the same security policy filtering to metadata as it applies to data payloads.
47AC-4(20)AC-4(20)information flow enforcement | approved solutionsThe organization employs [Assignment: organization-defined solutions in approved configurations] to control the flow of [Assignment: organization-defined information] across security domains.
48AC-4(21)AC-4(21)information flow enforcement | physical / logical separation of information flowsThe information system separates information flows logically or physically using [Assignment: organization-defined mechanisms and/or techniques] to accomplish [Assignment: organization-defined required separations by types of information].
49AC-4(22)AC-4(22)information flow enforcement | access onlyThe information system provides access from a single device to computing platforms, applications, or data residing on multiple different security domains, while preventing any information flow between the different security domains.
50AC-5AC-5Separation of DutiesThe AFLCMC/WW F16 System Program Office:

a. Separates [Assignment: organization-defined duties of individuals];

b. Documents separation of duties of individuals; and

c. Defines information system access authorizations to support separation of duties.X
51AC-6AC-6Least PrivilegeThe F-16 SPO employs the principle of least privilege, allowing only authorized accesses for users (or processes acting on behalf of users) which are necessary to accomplish assigned tasks in accordance with organizational missions and business functions.XXGovernement
52AC-6(1)AC-6(1)least privilege | authorize access to security functionsThe F-16 SPO explicitly authorizes access to Critical Program Information (CPI), security functions and secret- collateral information based on key availability on the ADTC.XXGovernement
53AC-6(2)AC-6(2)least privilege | non-privileged access for no security functionsThe organization requires that users of information system accounts, or roles, with access to [Assignment: organization-defined security functions or security-relevant information], use non-privileged accounts or roles, when accessing nonsecurity functions.
54AC-6(3)AC-6(3)least privilege | network access to privileged commandsThe organization authorizes network access to [Assignment: organization-defined privileged commands] only for [Assignment: organization-defined compelling operational needs] and documents the rationale for such access in the security plan for the information system.X
55AC-6(4)AC-6(4)least privilege | separate processing domainsThe information system provides separate processing domains to enable finer-grained allocation of user privileges.
56AC-6(5)AC-6(5)least privilege | privileged accountsThe organization restricts privileged accounts on the information system to [Assignment: organization-defined personnel or roles].X
57AC-6(6)AC-6(6)least privilege | privileged access by non-organizational usersThe organization prohibits privileged access to the information system by non-organizational users.X
58AC-6(7)AC-6(7)least privilege | review of user privilegesThe AFLCMC/WW F16 System Program Office:

(a) Reviews [Assignment: organization-defined frequency] the privileges assigned to [Assignment: organization-defined roles or classes of users] to validate the need for such privileges; and

(b) Reassigns or removes privileges, if necessary, to correctly reflect organizational mission/business needs.X
59AC-6(8)AC-6(8)least privilege | privilege levels for code executionThe information system prevents [Assignment: organization-defined software] from executing at higher privilege levels than users executing the software.
60AC-6(9)AC-6(9)least privilege | auditing use of privileged functionsThe information system audits the execution of privileged functions.X
61AC-6(10)AC-6(10)least privilege | prohibit non-privileged users from executing privileged functionsThe information system prevents non-privileged users from executing privileged functions to include disabling, circumventing, or altering implemented security safeguards/countermeasures.X
62AC-7AC-7Unsuccessful Logon AttemptsThe information system:

a. Enforces a limit of [Assignment: organization-defined number] consecutive invalid logon attempts by a user during a [Assignment: organization-defined time period]; and

b. Automatically [Selection: locks the account/node for an [Assignment: organization-defined time period]; locks the account/node until released by an administrator; delays next logon prompt according to [Assignment: organization-defined delay algorithm]] when the maximum number of unsuccessful attempts is exceeded.

Supplemental Guidance: This control applies regardless of whether the logon occurs via a local or network connection. Due to the potential for denial of service, automatic lockouts initiated by information systems are usually temporary and automatically release after a predetermined time period established by organizations. If a delay algorithm is selected, organizations may choose to employ different algorithms for different information system components based on the capabilities of those components. Responses to unsuccessful logon attempts may be implemented at both the operating system and the application levels. Related controls: AC-2, AC-9, AC-14, IA-5.X
63AC-7(1)AC-7(1)unsuccessful logon attempts | automatic account lock[Withdrawn: Incorporated into AC-7].
64AC-7(2)AC-7(2)unsuccessful logon attempts | purge / wipe mobile deviceThe information system purges/wipes information from [Assignment: organization-defined mobile devices] based on [Assignment: organization-defined purging/wiping requirements/techniques] after [Assignment: organization-defined number] consecutive, unsuccessful device logon attempts.
65AC-8AC-8System Use NotificationThe information system:

a. Displays to users [Assignment: organization-defined system use notification message or banner] before granting access to the system that provides privacy and security notices consistent with applicable federal laws, Executive Orders, directives, policies, regulations, standards, and guidance and states that:

1. Users are accessing a U.S. Government information system;

2. Information system usage may be monitored, recorded, and subject to audit;

3. Unauthorized use of the information system is prohibited and subject to criminal and civil penalties; and

4. Use of the information system indicates consent to monitoring and recording;

b. Retains the notification message or banner on the screen until users acknowledge the usage conditions and take explicit actions to log on to or further access the information system; and

c. For publicly accessible systems:

1. Displays system use information [Assignment: organization-defined conditions], before granting further access;

2. Displays references, if any, to monitoring, recording, or auditing that are consistent with privacy accommodations for such systems that generally prohibit those activities; and

3. Includes a description of the authorized uses of the system.

66AC-9AC-9Previous Logon (Access) NotificationThe information system notifies the user, upon successful logon (access) to the system, of the date and time of the last logon (access).
67AC-9(1)AC-9(1)previous logon notification | unsuccessful logonsThe information system notifies the user, upon successful logon/access, of the number of unsuccessful logon/access attempts since the last successful logon/access.
68AC-9(2)AC-9(2)previous logon notification | successful / unsuccessful logonsThe information system notifies the user of the number of [Selection: successful logons/accesses; unsuccessful logon/access attempts; both] during [Assignment: organization-defined time period].
69AC-9(3)AC-9(3)previous logon notification | notification of account changesThe information system notifies the user of changes to [Assignment: organization-defined security-related characteristics/parameters of the user’s account] during [Assignment: organization-defined time period].
70AC-9(4)AC-9(4)previous logon notification | additional logon informationThe information system notifies the user, upon successful logon (access), of the following additional information: [Assignment: organization-defined information to be included in addition to the date and time of the last logon (access)].
71AC-10AC-10Concurrent Session ControlThe information system limits the number of concurrent sessions for each [Assignment: organization-defined account and/or account type] to [Assignment: organization-defined number].X
72AC-11AC-11Session LockThe information system:

a. Prevents further access to the system by initiating a session lock after [Assignment: organization-defined time period] of inactivity or upon receiving a request from a user; and

b. Retains the session lock until the user reestablishes access using established identification and authentication procedures.

73AC-11(1)AC-11(1)session lock | pattern-hiding displaysThe information system conceals, via the session lock, information previously visible on the display with a publicly viewable image.
74AC-12AC-12Session TerminationThe information system automatically terminates a user session after [Assignment: organization-defined conditions or trigger events requiring session disconnect].
75AC-12(1)AC-12(1)session termination | user-initiated logouts / message displaysThe information system:

(a) Provides a logout capability for user-initiated communications sessions whenever authentication is used to gain access to [Assignment: organization-defined information resources]; and

(b) Displays an explicit logout message to users indicating the reliable termination of authenticated communications sessions.

76AC-13AC-13Supervision and Review — Access Control[Withdrawn: Incorporated into AC-2 and AU-6].
77AC-14AC-14Permitted Actions without Identification or AuthenticationThe AFLCMC/WW F16 System Program Office:

a. Identifies [Assignment: organization-defined user actions] that can be performed on the information system without identification or authentication consistent with organizational missions/business functions; and

b. Documents and provides supporting rationale in the security plan for the information system, user actions not requiring identification or authentication.XXSupplier/Government
78AC-14(1)AC-14(1)permitted actions without identification or authentication | necessary uses[Withdrawn: Incorporated into AC-14].
79AC-15AC-15Automated Marking[Withdrawn: Incorporated into MP-3].
80AC-16AC-16Security AttributesThe organization:

a. Provides the means to associate [Assignment: organization-defined types of security attributes] having [Assignment: organization-defined security attribute values] with information in storage, in process, and/or in transmission;

b. Ensures that the security attribute associations are made and retained with the information;

c. Establishes the permitted [Assignment: organization-defined security attributes] for [Assignment: organization-defined information systems]; and

d. Determines the permitted [Assignment: organization-defined values or ranges] for each of the established security attributes.

81AC-16(1)AC-16(1)security attributes | dynamic attribute associationThe information system dynamically associates security attributes with [Assignment: organization-defined subjects and objects] in accordance with [Assignment: organization-defined security policies] as information is created and combined.
82AC-16(2)AC-16(2)security attributes | attribute value changes by authorized individualsThe information system provides authorized individuals (or processes acting on behalf of individuals) the capability to define or change the value of associated security attributes.
83AC-16(3)AC-16(3)security attributes | maintenance of attribute associations by information systemThe information system maintains the association and integrity of [Assignment: organization-defined security attributes] to [Assignment: organization-defined subjects and objects].
84AC-16(4)AC-16(4)security attributes | association of attributes by authorized individualsThe information system supports the association of [Assignment: organization-defined security attributes] with [Assignment: organization-defined subjects and objects] by authorized individuals (or processes acting on behalf of individuals).
85AC-16(5)AC-16(5)security attributes | attribute displays for output devicesThe information system displays security attributes in human-readable form on each object that the system transmits to output devices to identify [Assignment: organization-identified special dissemination, handling, or distribution instructions] using [Assignment: organization-identified human-readable, standard naming conventions].
86AC-16(6)AC-16(6)security attributes | maintenance of attribute association by organizationThe organization allows personnel to associate, and maintain the association of [Assignment: organization-defined security attributes] with [Assignment: organization-defined subjects and objects] in accordance with [Assignment: organization-defined security policies].
87AC-16(7)AC-16(7)security attributes | consistent attribute interpretationThe organization provides a consistent interpretation of security attributes transmitted between distributed information system components.
88AC-16(8)AC-16(8)security attributes | association techniques / technologiesThe information system implements [Assignment: organization-defined techniques or technologies] with [Assignment: organization-defined level of assurance] in associating security attributes to information.
89AC-16(9)AC-16(9)security attributes | attribute reassignmentThe organization ensures that security attributes associated with information are reassigned only via re-grading mechanisms validated using [Assignment: organization-defined techniques or procedures].
90AC-16(10)AC-16(10)security attributes | attribute configuration by authorized individualsThe information system provides authorized individuals the capability to define or change the type and value of security attributes available for association with subjects and objects.
91AC-17AC-17Remote AccessThe AFLCMC/WW F16 System Program Office:

a. Establishes and documents usage restrictions, configuration/connection requirements, and implementation guidance for each type of remote access allowed; and

b. Authorizes remote access to the information system prior to allowing such connections.X
92AC-17(1)AC-17(1)remote access | automated monitoring / controlThe information system monitors and controls remote access methods.
93AC-17(2)AC-17(2)remote access | protection of confidentiality / integrity using encryptionThe information system implements cryptographic mechanisms to protect the confidentiality and integrity of remote access sessions.
94AC-17(3)AC-17(3)remote access | managed access control pointsThe information system routes all remote accesses through [Assignment: organization-defined number] managed network access control points.
95AC-17(4)AC-17(4)remote access | privileged commands / accessThe organization:

(a) Authorizes the execution of privileged commands and access to security-relevant information via remote access only for [Assignment: organization-defined needs]; and

(b) Documents the rationale for such access in the security plan for the information system.

96AC-17(5)AC-17(5)remote access | monitoring for unauthorized connections[Withdrawn: Incorporated into SI-4].
97AC-17(6)AC-17(6)remote access | protection of informationThe organization ensures that users protect information about remote access mechanisms from unauthorized use and disclosure.
98AC-17(7)AC-17(7)remote access | additional protection for security function access[Withdrawn: Incorporated into AC-3 (10)].
99AC-17(8)AC-17(8)remote access | disable nonsecure network protocols[Withdrawn: Incorporated into CM-7].
100AC-17(9)AC-17(9)remote access | disconnect / disable accessThe organization provides the capability to expeditiously disconnect or disable remote access to the information system within [Assignment: organization-defined time period].X
101AC-18AC-18Wireless AccessThe AFLCMC/WW F16 System Program Office:

a. Establishes usage restrictions, configuration/connection requirements, and implementation guidance for wireless access; and

b. Authorizes wireless access to the information system prior to allowing such connections.X
102AC-18(1)AC-18(1)wireless access | authentication and encryptionThe information system protects wireless access to the system using authentication of [Selection (one or more): users; devices] and encryption.X
103AC-18(2)AC-18(2)wireless access | monitoring unauthorized connections[Withdrawn: Incorporated into SI-4].
104AC-18(3)AC-18(3)wireless access | disable wireless networkingThe organization disables, when not intended for use, wireless networking capabilities internally embedded within information system components prior to issuance and deployment.X
105AC-18(4)AC-18(4)wireless access | restrict configurations by usersThe organization identifies and explicitly authorizes users allowed to independently configure wireless networking capabilities.X
106AC-18(5)AC-18(5)wireless access | antennas / transmission power levelsThe organization selects radio antennas and calibrates transmission power levels to reduce the probability that usable signals can be received outside of organization-controlled boundaries.X
107AC-19AC-19Access Control for Mobile DevicesThe AFLCMC/WW F16 System Program Office:

a. Establishes usage restrictions, configuration requirements, connection requirements, and implementation guidance for organization-controlled mobile devices; and

b. Authorizes the connection of mobile devices to organizational information systems.X
108AC-19(1)AC-19(1)access control for mobile devices | use of writable / portable storage devices[Withdrawn: Incorporated into MP-7].
109AC-19(2)AC-19(2)access control for mobile devices | use of personally owned portable storage devices[Withdrawn: Incorporated into MP-7].
110AC-19(3)AC-19(3)access control for mobile devices | use of portable storage devices with no identifiable owner[Withdrawn: Incorporated into MP-7].
111AC-19(4)AC-19(4)access control for mobile devices | restrictions for classified informationThe AFLCMC/WW F16 System Program Office:

(a) Prohibits the use of unclassified mobile devices in facilities containing information systems processing, storing, or transmitting classified information unless specifically permitted by the authorizing official; and

(b) Enforces the following restrictions on individuals permitted by the authorizing official to use unclassified mobile devices in facilities containing information systems processing, storing, or transmitting classified information:

(1) Connection of unclassified mobile devices to classified information systems is prohibited;

(2) Connection of unclassified mobile devices to unclassified information systems requires approval from the authorizing official;

(3) Use of internal or external modems or wireless interfaces within the unclassified mobile devices is prohibited; and

(4) Unclassified mobile devices and the information stored on those devices are subject to random reviews and inspections by [Assignment: organization-defined security officials], and if classified information is found, the incident handling policy is followed.

(c) Restricts the connection of classified mobile devices to classified information systems in accordance with [Assignment: organization-defined security policies].X
112AC-19(5)AC-19(5)access control for mobile devices | full device / container-based encryptionThe F-16 SPO employs full-device encryption to protect the confidentiality and integrity of information at rest on the PDGU.XXGovernment
113AC-20AC-20Use of External Information SystemsThe organization establishes terms and conditions, consistent with any trust relationships established with other organizations owning, operating, and/or maintaining external information systems, allowing authorized individuals to:

a. Access the information system from external information systems; and

b. Process, store, or transmit organization-controlled information using external information systems.X
114AC-20(1)AC-20(1)use of external information systems | limits on authorized useThe organization permits authorized individuals to use an external information system to access the information system or to process, store, or transmit organization-controlled information only when The AFLCMC/WW F16 System Program Office:

(a) Verifies the implementation of required security controls on the external system as specified in the organization’s information security policy and security plan; or

(b) Retains approved information system connection or processing agreements with the organizational entity hosting the external information system.X
115AC-20(2)AC-20(2)use of external information systems | portable storage devicesThe F-16 SPO restrict access to the ADTC based on contents by authorized individuals.XXGovernment
116AC-20(3)AC-20(3)use of external information systems | non-organizationally owned systems / components / devicesThe organization [Selection: restricts; prohibits] the use of non-organizationally owned information systems, system components, or devices to process, store, or transmit organizational information.X
117AC-20(4)AC-20(4)use of external information systems | network accessible storage devicesThe organization prohibits the use of [Assignment: organization-defined network accessible storage devices] in external information systems.
118AC-21AC-21Information SharingThe AFLCMC/WW F16 System Program Office:

a. Facilitates information sharing by enabling authorized users to determine whether access authorizations assigned to the sharing partner match the access restrictions on the information for [Assignment: organization-defined information sharing circumstances where user discretion is required]; and

b. Employs [Assignment: organization-defined automated mechanisms or manual processes] to assist users in making information sharing/collaboration decisions.X
119AC-21(1)AC-21(1)information sharing | automated decision supportThe information system enforces information-sharing decisions by authorized users based on access authorizations of sharing partners and access restrictions on information to be shared.
120AC-21(2)AC-21(2)information sharing | information search and retrievalThe information system implements information search and retrieval services that enforce [Assignment: organization-defined information sharing restrictions].
121AC-22AC-22Publicly Accessible ContentThe AFLCMC/WW F16 System Program Office:

a. Designates individuals authorized to post information onto a publicly accessible information system;

b. Trains authorized individuals to ensure that publicly accessible information does not contain nonpublic information;

c. Reviews the proposed content of information prior to posting onto the publicly accessible information system to ensure that nonpublic information is not included; and

d. Reviews the content on the publicly accessible information system for nonpublic information [Assignment: organization-defined frequency] and removes such information, if discovered.X
122AC-23AC-23Data Mining ProtectionThe organization employs [Assignment: organization-defined data mining prevention and detection techniques] for [Assignment: organization-defined data storage objects] to adequately detect and protect against data mining.
123AC-24AC-24Access Control DecisionsThe organization establishes procedures to ensure [Assignment: organization-defined access control decisions] are applied to each access request prior to access enforcement.
124AC-24(1)AC-24(1)access control decisions | transmit access authorization informationThe information system transmits [Assignment: organization-defined access authorization information] using [Assignment: organization-defined security safeguards] to [Assignment: organization-defined information systems] that enforce access control decisions.
125AC-24(2)AC-24(2)access control decisions | no user or process identityThe information system enforces access control decisions based on [Assignment: organization-defined security attributes] that do not include the identity of the user or process acting on behalf of the user.
126AC-25AC-25Reference MonitorThe information system implements a reference monitor for [Assignment: organization-defined access control policies] that is tamperproof, always invoked, and small enough to be subject to analysis and testing, the completeness of which can be assured.
127AT-1AT-1Security Awareness and Training Policy and ProceduresThe AFLCMC/WW F16 System Program Office:

a. Develops, documents, and disseminates to [Assignment: organization-defined personnel or roles]:

1. A security awareness and training policy that addresses purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance; and

2. Procedures to facilitate the implementation of the security awareness and training policy and associated security awareness and training controls; and

b. Reviews and updates the current:

1. Security awareness and training policy [Assignment: organization-defined frequency]; and

2. Security awareness and training procedures [Assignment: organization-defined frequency].X
128AT-2AT-2Security Awareness TrainingThe organization provides basic security awareness training to information system users (including managers, senior executives, and contractors):

a. As part of initial training for new users;

b. When required by information system changes; and

c. [Assignment: organization-defined frequency] thereafter.X
129AT-2(1)AT-2(1)security awareness | practical exercisesThe organization includes practical exercises in security awareness training that simulate actual cyber attacks.
130AT-2(2)AT-2(2)security awareness | insider threatThe organization includes security awareness training on recognizing and reporting potential indicators of insider threat.X
131AT-3AT-3Role-Based Security TrainingThe organization provides role-based security training to personnel with assigned security roles and responsibilities:

a. Before authorizing access to the information system or performing assigned duties;

b. When required by information system changes; and

c. [Assignment: organization-defined frequency] thereafter.X
132AT-3(1)AT-3(1)security training | environmental controlsThe organization provides [Assignment: organization-defined personnel or roles] with initial and [Assignment: organization-defined frequency] training in the employment and operation of environmental controls.
133AT-3(2)AT-3(2)security training | physical security controlsThe organization provides [Assignment: organization-defined personnel or roles] with initial and [Assignment: organization-defined frequency] training in the employment and operation of physical security controls.X
134AT-3(3)AT-3(3)security training | practical exercisesThe organization includes practical exercises in security training that reinforce training objectives.
135AT-3(4)AT-3(4)security training | suspicious communications and anomalous system behaviorThe organization provides training to its personnel on [Assignment: organization-defined indicators of malicious code] to recognize suspicious communications and anomalous behavior in organizational information systems.X
136AT-4AT-4Security Training RecordsThe AFLCMC/WW F16 System Program Office:

a. Documents and monitors individual information system security training activities including basic security awareness training and specific information system security training; and

b. Retains individual training records for [Assignment: organization-defined time period].X
137AT-5AT-5Contacts with Security Groups and Associations[Withdrawn: Incorporated into PM-15].
138AU-1AU-1Audit and Accountability Policy and ProceduresThe AFLCMC/WW F16 System Program Office:

a. Develops, documents, and disseminates to [Assignment: organization-defined personnel or roles]:

1. An audit and accountability policy that addresses purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance; and

2. Procedures to facilitate the implementation of the audit and accountability policy and associated audit and accountability controls; and

b. Reviews and updates the current:

1. Audit and accountability policy [Assignment: organization-defined frequency]; and

2. Audit and accountability procedures [Assignment: organization-defined frequency].XXGovernment309th verify authentication
139AU-2AU-2Audit EventsThe AFLCMC/WW F16 System Program Office:

a. Determines that the information system is capable of auditing the following events: [Assignment: organization-defined auditable events];

b. Coordinates the security audit function with other organizational entities requiring audit-related information to enhance mutual support and to help guide the selection of auditable events;

c. Provides a rationale for why the auditable events are deemed to be adequate to support after-the-fact investigations of security incidents; and

d. Determines that the following events are to be audited within the information system: [Assignment: organization-defined audited events (the subset of the auditable events defined in AU-2 a.) along with the frequency of (or situation requiring) auditing for each identified event].XXGovernment309th verify authentication
140AU-2(1)AU-2(1)audit events | compilation of audit records from multiple sources[Withdrawn: Incorporated into AU-12].
141AU-2(2)AU-2(2)audit events | selection of audit events by component[Withdrawn: Incorporated into AU-12].
142AU-2(3)AU-2(3)audit events | reviews and updatesThe organization reviews and updates the audited events [Assignment: organization-defined frequency].X
143AU-2(4)AU-2(4)audit events | privileged functions[Withdrawn: Incorporated into AC-6 (9)].
144AU-3AU-3Content of Audit RecordsThe information system generates audit records containing information that establishes what type of event occurred, when the event occurred, where the event occurred, the source of the event, the outcome of the event, and the identity of any individuals or subjects associated with the event.XXSupplier/Government
145AU-3(1)AU-3(1)content of audit records | additional audit informationThe information system generates audit records containing the following additional information: [Assignment: organization-defined additional, more detailed information].X
146AU-3(2)AU-3(2)content of audit records | centralized management of planned audit record contentThe information system provides centralized management and configuration of the content to be captured in audit records generated by [Assignment: organization-defined information system components].
147AU-4AU-4Audit Storage CapacityThe organization allocates audit record storage capacity in accordance with [Assignment: organization-defined audit record storage requirements].X
148AU-4(1)AU-4(1)audit storage capacity | transfer to alternate storageThe information system off-loads audit records [Assignment: organization-defined frequency] onto a different system or media than the system being audited.
149AU-5AU-5Response to Audit Processing FailuresThe information system:

a. Alerts [Assignment: organization-defined personnel or roles] in the event of an audit processing failure; and

b. Takes the following additional actions: [Assignment: organization-defined actions to be taken (e.g., shut down information system, overwrite oldest audit records, stop generating audit records)].

150AU-5(1)AU-5(1)response to audit processing failures | audit storage capacityThe information system provides a warning to [Assignment: organization-defined personnel, roles, and/or locations] within [Assignment: organization-defined time period] when allocated audit record storage volume reaches [Assignment: organization-defined percentage] of repository maximum audit record storage capacity.
151AU-5(2)AU-5(2)response to audit processing failures | real-time alertsThe information system provides an alert in [Assignment: organization-defined real-time period] to [Assignment: organization-defined personnel, roles, and/or locations] when the following audit failure events occur: [Assignment: organization-defined audit failure events requiring real-time alerts].
152AU-5(3)AU-5(3)response to audit processing failures | configurable traffic volume thresholdsThe information system enforces configurable network communications traffic volume thresholds reflecting limits on auditing capacity and [Selection: rejects; delays] network traffic above those thresholds.
153AU-5(4)AU-5(4)response to audit processing failures | shutdown on failureThe information system invokes a [Selection: full system shutdown; partial system shutdown; degraded operational mode with limited mission/business functionality available] in the event of [Assignment: organization-defined audit failures], unless an alternate audit capability exists.
154AU-6AU-6Audit Review, Analysis, and ReportingThe AFLCMC/WW F16 System Program Office:

a. Reviews and analyzes information system audit records [Assignment: organization-defined frequency] for indications of [Assignment: organization-defined inappropriate or unusual activity]; and

b. Reports findings to [Assignment: organization-defined personnel or roles].X
155AU-6(1)AU-6(1)audit review, analysis, and reporting | process integrationThe organization employs automated mechanisms to integrate audit review, analysis, and reporting processes to support organizational processes for investigation and response to suspicious activities.X
156AU-6(2)AU-6(2)audit review, analysis, and reporting | automated security alerts[Withdrawn: Incorporated into SI-4].

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .