Section_C_PDGU_SOO_Appendix_C_SRTM_26Aug15.xlsx
XLSX spreadsheet 186 KB Posted
- Attached to
- Sustainment Upgrade for F-16 Programmable Display Generator Federal contract opportunity
- Solicitation number
- FA8232-16-R-3001
About this file
PDGU SRTM File Embedded in Appendix C of the SOO (Reference Amendment 0001)
View the file
Other files for this federal contract opportunity
Show all 28
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Aircraft Domain SRTM
| NOTE: Once the compliance/non-compliance columns are populated: classify, store, mark and handle this document IAW the program security classification guide. | ||||
| Ctrl | ID2 | ID | CONTROL NAME | |
| Control Enhancement Name | Programmable Display Generator Upgrade | Air Vehicle |
: Air vehicle. This column address the actual aircraft Compliant : Y = Compliant N = Non-Compliant Ground Station Compliant : Y = Compliant N = Non-Compliant Tailoring Rationale / Comments Supplier Rationale / Comments Method of Verification : Refer to Control Assessment tab for general assessment guidance.
| The program should identify in this column the detailed approach. | Verification Results | Reference docs | |||
| 1 | AC-1 | AC-1 | Access Control Policy and Procedures | The AFLCMC/WW F16 System Program Office: |
a. Develops, documents, and disseminates to [Assignment: organization-defined personnel or roles]:
1. An access control policy that addresses purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance; and
2. Procedures to facilitate the implementation of the access control policy and associated access controls; and
b. Reviews and updates the current:
1. Access control policy [Assignment: organization-defined frequency]; and
| 2. Access control procedures [Assignment: organization-defined frequency]. | X | X | Government | ||
| 2 | AC-2 | AC-2 | Account Management | The organization: |
a. Identifies and selects the following types of information system accounts to support organizational missions/business functions: [Assignment: organization-defined information system account types];
b. Assigns account managers for information system accounts;
c. Establishes conditions for group and role membership;
d. Specifies authorized users of the information system, group and role membership, and access authorizations (i.e., privileges) and other attributes (as required) for each account;
e. Requires approvals by [Assignment: organization-defined personnel or roles] for requests to create information system accounts;
f. Creates, enables, modifies, disables, and removes information system accounts in accordance with [Assignment: organization-defined procedures or conditions];
g. Monitors the use of information system accounts;
h. Notifies account managers:
1. When accounts are no longer required;
2. When users are terminated or transferred; and
3. When individual information system usage or need-to-know changes;
i. Authorizes access to the information system based on:
1. A valid access authorization;
2. Intended system usage; and
3. Other attributes as required by the organization or associated missions/business functions;
j. Reviews accounts for compliance with account management requirements [Assignment: organization-defined frequency]; and
| k. Establishes a process for reissuing shared/group account credentials (if deployed) when individuals are removed from the group. | X | ||||
| 3 | AC-2(1) | AC-2(1) | account management | automated system account management | The organization employs automated mechanisms to support the management of information system accounts. | |
| 4 | AC-2(2) | AC-2(2) | account management | removal of temporary / emergency accounts | The information system automatically [Selection: removes; disables] temporary and emergency accounts after [Assignment: organization-defined time period for each type of account]. | |
| 5 | AC-2(3) | AC-2(3) | account management | disable inactive accounts | The information system automatically disables inactive accounts after [Assignment: organization-defined time period]. | |
| 6 | AC-2(4) | AC-2(4) | account management | automated audit actions | The information system automatically audits account creation, modification, enabling, disabling, and removal actions, and notifies [Assignment: organization-defined personnel or roles]. | |
| 7 | AC-2(5) | AC-2(5) | account management | inactivity logout | The organization requires that users log out when [Assignment: organization-defined time-period of expected inactivity or description of when to log out]. | |
| 8 | AC-2(6) | AC-2(6) | account management | dynamic privilege management | The information system implements the following dynamic privilege management capabilities: [Assignment: organization-defined list of dynamic privilege management capabilities]. | |
| 9 | AC-2(7) | AC-2(7) | account management | role-based schemes | The organization: |
(a) Establishes and administers privileged user accounts in accordance with a role-based access scheme that organizes allowed information system access and privileges into roles;(b) Monitors privileged role assignments; and
| (c) Takes [Assignment: organization-defined actions] when privileged role assignments are no longer appropriate. | X | |||||
| 10 | AC-2(8) | AC-2(8) | account management | dynamic account creation | The information system creates [Assignment: organization-defined information system accounts] dynamically. | ||
| 11 | AC-2(9) | AC-2(9) | account management | restrictions on use of shared groups / accounts | The organization only permits the use of shared/group accounts that meet [Assignment: organization-defined conditions for establishing shared/group accounts]. | X | |
| 12 | AC-2(10) | AC-2(10) | account management | shared / group account credential termination | The information system terminates shared/group account credentials when members leave the group. | ||
| 13 | AC-2(11) | AC-2(11) | account management | usage conditions | The information system enforces [Assignment: organization-defined circumstances and/or usage conditions] for [Assignment: organization-defined information system accounts]. | X | |
| 14 | AC-2(12) | AC-2(12) | account management | account monitoring / atypical usage | The organization: |
(a) Monitors information system accounts for [Assignment: organization-defined atypical use]; and
| (b) Reports atypical usage of information system accounts to [Assignment: organization-defined personnel or roles]. | X | |||||||
| 15 | AC-2(13) | AC-2(13) | account management | disable accounts for high-risk individuals | The organization disables accounts of users posing a significant risk within [Assignment: organization-defined time period] of discovery of the risk. | X | |||
| 16 | AC-3 | AC-3 | Access Enforcement | The information system enforces approved authorizations for logical access to information and system resources in accordance with applicable access control policies. | X | X | Supplier/Government | |
| 17 | AC-3(1) | AC-3(1) | access enforcement | restricted access to privileged functions | [Withdrawn: Incorporated into AC-6]. | ||||
| 18 | AC-3(2) | AC-3(2) | access enforcement | dual authorization | The information system enforces dual authorization for [Assignment: organization-defined privileged commands and/or other organization-defined actions]. | ||||
| 19 | AC-3(3) | AC-3(3) | access enforcement | mandatory access control | The information system enforces [Assignment: organization-defined mandatory access control policies] over all subjects and objects where the policy specifies that: |
(a) The policy is uniformly enforced across all subjects and objects within the boundary of the information system;
(b) A subject that has been granted access to information is constrained from doing any of the following;
(1) Passing the information to unauthorized subjects or objects;
(2) Granting its privileges to other subjects;
(3) Changing one or more security attributes on subjects, objects, the information system, or information system components;
(4) Choosing the security attributes and attribute values to be associated with newly created or modified objects; or
(5) Changing the rules governing access control; and
(c) [Assignment: Organized-defined subjects] may explicitly be granted [Assignment: organization-defined privileges (i.e., they are trusted subjects)] such that they are not limited by some or all of the above constraints.
20 AC-3(4) AC-3(4) access enforcement | discretionary access control The information system enforces [Assignment: organization-defined discretionary access control policies] over defined subjects and objects where the policy specifies that a subject that has been granted access to information can do one or more of the following:
(a) Pass the information to any other subjects or objects;
(b) Grant its privileges to other subjects;
(c) Change security attributes on subjects, objects, the information system, or the information system’s components;
(d) Choose the security attributes to be associated with newly created or revised objects; or
(e) Change the rules governing access control.
| 21 | AC-3(5) | AC-3(5) | access enforcement | security-relevant information | The information system prevents access to [Assignment: organization-defined security-relevant information] except during secure, non-operable system states. | |
| 22 | AC-3(6) | AC-3(6) | access enforcement | protection of user and system information | [Withdrawn: Incorporated into MP-4 and SC-28]. | |
| 23 | AC-3(7) | AC-3(7) | access enforcement | role-based access control | The information system enforces a role-based access control policy over defined subjects and objects and controls access based upon [Assignment: organization-defined roles and users authorized to assume such roles]. | X |
| 24 | AC-3(8) | AC-3(8) | access enforcement | revocation of access authorizations | The information system enforces the revocation of access authorizations resulting from changes to the security attributes of subjects and objects based on [Assignment: organization-defined rules governing the timing of revocations of access authorizations]. | |
| 25 | AC-3(9) | AC-3(9) | access enforcement | controlled release | The information system does not release information outside of the established system boundary unless: |
(a) The receiving [Assignment: organization-defined information system or system component] provides [Assignment: organization-defined security safeguards]; and
(b) [Assignment: organization-defined security safeguards] are used to validate the appropriateness of the information designated for release.
| 26 | AC-3(10) | AC-3(10) | access enforcement | audited override of access control mechanisms | The organization employs an audited override of automated access control mechanisms under [Assignment: organization-defined conditions]. | |||
| 27 | AC-4 | AC-4 | Information Flow Enforcement | The information system enforces approved authorizations for controlling the flow of information within the system and between interconnected systems based on Root Trust and information flow control policies. | X | X | Supplier/Government |
| 28 | AC-4(1) | AC-4(1) | information flow enforcement | object security attributes | The information system uses [Assignment: organization-defined security attributes] associated with [Assignment: organization-defined information, source, and destination objects] to enforce [Assignment: organization-defined information flow control policies] as a basis for flow control decisions. | |||
| 29 | AC-4(2) | AC-4(2) | information flow enforcement | processing domains | The information system uses protected processing domains to enforce [Assignment: organization-defined information flow control policies] as a basis for flow control decisions. | |||
| 30 | AC-4(3) | AC-4(3) | information flow enforcement | dynamic information flow control | The information system enforces dynamic information flow control based on [Assignment: organization-defined policies]. | |||
| 31 | AC-4(4) | AC-4(4) | information flow enforcement | content check encrypted information | The information system prevents encrypted information from bypassing content-checking mechanisms by [Selection (one or more): decrypting the information; blocking the flow of the encrypted information; terminating communications sessions attempting to pass encrypted information; [Assignment: organization-defined procedure or method]]. | |||
| 32 | AC-4(5) | AC-4(5) | information flow enforcement | embedded data types | The information system enforces [Assignment: organization-defined limitations] on embedding data types within other data types. | |||
| 33 | AC-4(6) | AC-4(6) | information flow enforcement | metadata | The information system enforces information flow control based on [Assignment: organization-defined metadata]. | |||
| 34 | AC-4(7) | AC-4(7) | information flow enforcement | one-way flow mechanisms | The information system enforces [Assignment: organization-defined one-way flows] using hardware mechanisms. | X | ||
| 35 | AC-4(8) | AC-4(8) | information flow enforcement | security policy filters | The information system enforces information flow control using [Assignment: organization-defined security policy filters] as a basis for flow control decisions for [Assignment: organization-defined information flows]. | |||
| 36 | AC-4(9) | AC-4(9) | information flow enforcement | human reviews | The information system enforces the use of human reviews for [Assignment: organization-defined information flows] under the following conditions: [Assignment: organization-defined conditions]. | |||
| 37 | AC-4(10) | AC-4(10) | information flow enforcement | enable / disable security policy filters | The information system provides the capability for privileged administrators to enable/disable [Assignment: organization-defined security policy filters] under the following conditions: [Assignment: organization-defined conditions]. | |||
| 38 | AC-4(11) | AC-4(11) | information flow enforcement | configuration of security policy filters | The information system provides the capability for privileged administrators to configure [Assignment: organization-defined security policy filters] to support different security policies. | |||
| 39 | AC-4(12) | AC-4(12) | information flow enforcement | data type identifiers | The information system, when transferring information between different security domains, uses [Assignment: organization-defined data type identifiers] to validate data essential for information flow decisions. | |||
| 40 | AC-4(13) | AC-4(13) | information flow enforcement | decomposition into policy-relevant subcomponents | The information system, when transferring information between different security domains, decomposes information into [Assignment: organization-defined policy-relevant subcomponents] for submission to policy enforcement mechanisms. | |||
| 41 | AC-4(14) | AC-4(14) | information flow enforcement | security policy filter constraints | The information system, when transferring information between different security domains, implements [Assignment: organization-defined security policy filters] requiring fully enumerated formats that restrict data structure and content. | |||
| 42 | AC-4(15) | AC-4(15) | information flow enforcement | detection of unsanctioned information | The information system, when transferring information between different security domains, examines the information for the presence of [Assignment: organized-defined unsanctioned information] and prohibits the transfer of such information in accordance with the [Assignment: organization-defined security policy]. | |||
| 43 | AC-4(16) | AC-4(16) | information flow enforcement | information transfers on interconnected systems | [Withdrawn: Incorporated into AC-4]. | |||
| 44 | AC-4(17) | AC-4(17) | information flow enforcement | domain authentication | The information system uniquely identifies and authenticates source and destination points by [Selection (one or more): organization, system, application, individual] for information transfer. | |||
| 45 | AC-4(18) | AC-4(18) | information flow enforcement | security attribute binding | The information system binds security attributes to information using [Assignment: organization-defined binding techniques] to facilitate information flow policy enforcement. | |||
| 46 | AC-4(19) | AC-4(19) | information flow enforcement | validation of metadata | The information system, when transferring information between different security domains, applies the same security policy filtering to metadata as it applies to data payloads. | |||
| 47 | AC-4(20) | AC-4(20) | information flow enforcement | approved solutions | The organization employs [Assignment: organization-defined solutions in approved configurations] to control the flow of [Assignment: organization-defined information] across security domains. | |||
| 48 | AC-4(21) | AC-4(21) | information flow enforcement | physical / logical separation of information flows | The information system separates information flows logically or physically using [Assignment: organization-defined mechanisms and/or techniques] to accomplish [Assignment: organization-defined required separations by types of information]. | |||
| 49 | AC-4(22) | AC-4(22) | information flow enforcement | access only | The information system provides access from a single device to computing platforms, applications, or data residing on multiple different security domains, while preventing any information flow between the different security domains. | |||
| 50 | AC-5 | AC-5 | Separation of Duties | The AFLCMC/WW F16 System Program Office: |
a. Separates [Assignment: organization-defined duties of individuals];
b. Documents separation of duties of individuals; and
| c. Defines information system access authorizations to support separation of duties. | X | |||||||
| 51 | AC-6 | AC-6 | Least Privilege | The F-16 SPO employs the principle of least privilege, allowing only authorized accesses for users (or processes acting on behalf of users) which are necessary to accomplish assigned tasks in accordance with organizational missions and business functions. | X | X | Governement | |
| 52 | AC-6(1) | AC-6(1) | least privilege | authorize access to security functions | The F-16 SPO explicitly authorizes access to Critical Program Information (CPI), security functions and secret- collateral information based on key availability on the ADTC. | X | X | Governement | |
| 53 | AC-6(2) | AC-6(2) | least privilege | non-privileged access for no security functions | The organization requires that users of information system accounts, or roles, with access to [Assignment: organization-defined security functions or security-relevant information], use non-privileged accounts or roles, when accessing nonsecurity functions. | ||||
| 54 | AC-6(3) | AC-6(3) | least privilege | network access to privileged commands | The organization authorizes network access to [Assignment: organization-defined privileged commands] only for [Assignment: organization-defined compelling operational needs] and documents the rationale for such access in the security plan for the information system. | X | |||
| 55 | AC-6(4) | AC-6(4) | least privilege | separate processing domains | The information system provides separate processing domains to enable finer-grained allocation of user privileges. | ||||
| 56 | AC-6(5) | AC-6(5) | least privilege | privileged accounts | The organization restricts privileged accounts on the information system to [Assignment: organization-defined personnel or roles]. | X | |||
| 57 | AC-6(6) | AC-6(6) | least privilege | privileged access by non-organizational users | The organization prohibits privileged access to the information system by non-organizational users. | X | |||
| 58 | AC-6(7) | AC-6(7) | least privilege | review of user privileges | The AFLCMC/WW F16 System Program Office: |
(a) Reviews [Assignment: organization-defined frequency] the privileges assigned to [Assignment: organization-defined roles or classes of users] to validate the need for such privileges; and
| (b) Reassigns or removes privileges, if necessary, to correctly reflect organizational mission/business needs. | X | |||||
| 59 | AC-6(8) | AC-6(8) | least privilege | privilege levels for code execution | The information system prevents [Assignment: organization-defined software] from executing at higher privilege levels than users executing the software. | ||
| 60 | AC-6(9) | AC-6(9) | least privilege | auditing use of privileged functions | The information system audits the execution of privileged functions. | X | |
| 61 | AC-6(10) | AC-6(10) | least privilege | prohibit non-privileged users from executing privileged functions | The information system prevents non-privileged users from executing privileged functions to include disabling, circumventing, or altering implemented security safeguards/countermeasures. | X | |
| 62 | AC-7 | AC-7 | Unsuccessful Logon Attempts | The information system: |
a. Enforces a limit of [Assignment: organization-defined number] consecutive invalid logon attempts by a user during a [Assignment: organization-defined time period]; and
b. Automatically [Selection: locks the account/node for an [Assignment: organization-defined time period]; locks the account/node until released by an administrator; delays next logon prompt according to [Assignment: organization-defined delay algorithm]] when the maximum number of unsuccessful attempts is exceeded.
| Supplemental Guidance: This control applies regardless of whether the logon occurs via a local or network connection. Due to the potential for denial of service, automatic lockouts initiated by information systems are usually temporary and automatically release after a predetermined time period established by organizations. If a delay algorithm is selected, organizations may choose to employ different algorithms for different information system components based on the capabilities of those components. Responses to unsuccessful logon attempts may be implemented at both the operating system and the application levels. Related controls: AC-2, AC-9, AC-14, IA-5. | X | ||||
| 63 | AC-7(1) | AC-7(1) | unsuccessful logon attempts | automatic account lock | [Withdrawn: Incorporated into AC-7]. | |
| 64 | AC-7(2) | AC-7(2) | unsuccessful logon attempts | purge / wipe mobile device | The information system purges/wipes information from [Assignment: organization-defined mobile devices] based on [Assignment: organization-defined purging/wiping requirements/techniques] after [Assignment: organization-defined number] consecutive, unsuccessful device logon attempts. | |
| 65 | AC-8 | AC-8 | System Use Notification | The information system: |
a. Displays to users [Assignment: organization-defined system use notification message or banner] before granting access to the system that provides privacy and security notices consistent with applicable federal laws, Executive Orders, directives, policies, regulations, standards, and guidance and states that:
1. Users are accessing a U.S. Government information system;
2. Information system usage may be monitored, recorded, and subject to audit;
3. Unauthorized use of the information system is prohibited and subject to criminal and civil penalties; and
4. Use of the information system indicates consent to monitoring and recording;
b. Retains the notification message or banner on the screen until users acknowledge the usage conditions and take explicit actions to log on to or further access the information system; and
c. For publicly accessible systems:
1. Displays system use information [Assignment: organization-defined conditions], before granting further access;
2. Displays references, if any, to monitoring, recording, or auditing that are consistent with privacy accommodations for such systems that generally prohibit those activities; and
3. Includes a description of the authorized uses of the system.
| 66 | AC-9 | AC-9 | Previous Logon (Access) Notification | The information system notifies the user, upon successful logon (access) to the system, of the date and time of the last logon (access). | |
| 67 | AC-9(1) | AC-9(1) | previous logon notification | unsuccessful logons | The information system notifies the user, upon successful logon/access, of the number of unsuccessful logon/access attempts since the last successful logon/access. | |
| 68 | AC-9(2) | AC-9(2) | previous logon notification | successful / unsuccessful logons | The information system notifies the user of the number of [Selection: successful logons/accesses; unsuccessful logon/access attempts; both] during [Assignment: organization-defined time period]. | |
| 69 | AC-9(3) | AC-9(3) | previous logon notification | notification of account changes | The information system notifies the user of changes to [Assignment: organization-defined security-related characteristics/parameters of the user’s account] during [Assignment: organization-defined time period]. | |
| 70 | AC-9(4) | AC-9(4) | previous logon notification | additional logon information | The information system notifies the user, upon successful logon (access), of the following additional information: [Assignment: organization-defined information to be included in addition to the date and time of the last logon (access)]. | |
| 71 | AC-10 | AC-10 | Concurrent Session Control | The information system limits the number of concurrent sessions for each [Assignment: organization-defined account and/or account type] to [Assignment: organization-defined number]. | X |
| 72 | AC-11 | AC-11 | Session Lock | The information system: |
a. Prevents further access to the system by initiating a session lock after [Assignment: organization-defined time period] of inactivity or upon receiving a request from a user; and
b. Retains the session lock until the user reestablishes access using established identification and authentication procedures.
| 73 | AC-11(1) | AC-11(1) | session lock | pattern-hiding displays | The information system conceals, via the session lock, information previously visible on the display with a publicly viewable image. |
| 74 | AC-12 | AC-12 | Session Termination | The information system automatically terminates a user session after [Assignment: organization-defined conditions or trigger events requiring session disconnect]. |
| 75 | AC-12(1) | AC-12(1) | session termination | user-initiated logouts / message displays | The information system: |
(a) Provides a logout capability for user-initiated communications sessions whenever authentication is used to gain access to [Assignment: organization-defined information resources]; and
(b) Displays an explicit logout message to users indicating the reliable termination of authenticated communications sessions.
| 76 | AC-13 | AC-13 | Supervision and Review — Access Control | [Withdrawn: Incorporated into AC-2 and AU-6]. |
| 77 | AC-14 | AC-14 | Permitted Actions without Identification or Authentication | The AFLCMC/WW F16 System Program Office: |
a. Identifies [Assignment: organization-defined user actions] that can be performed on the information system without identification or authentication consistent with organizational missions/business functions; and
| b. Documents and provides supporting rationale in the security plan for the information system, user actions not requiring identification or authentication. | X | X | Supplier/Government | ||
| 78 | AC-14(1) | AC-14(1) | permitted actions without identification or authentication | necessary uses | [Withdrawn: Incorporated into AC-14]. | |
| 79 | AC-15 | AC-15 | Automated Marking | [Withdrawn: Incorporated into MP-3]. | |
| 80 | AC-16 | AC-16 | Security Attributes | The organization: |
a. Provides the means to associate [Assignment: organization-defined types of security attributes] having [Assignment: organization-defined security attribute values] with information in storage, in process, and/or in transmission;
b. Ensures that the security attribute associations are made and retained with the information;
c. Establishes the permitted [Assignment: organization-defined security attributes] for [Assignment: organization-defined information systems]; and
d. Determines the permitted [Assignment: organization-defined values or ranges] for each of the established security attributes.
| 81 | AC-16(1) | AC-16(1) | security attributes | dynamic attribute association | The information system dynamically associates security attributes with [Assignment: organization-defined subjects and objects] in accordance with [Assignment: organization-defined security policies] as information is created and combined. |
| 82 | AC-16(2) | AC-16(2) | security attributes | attribute value changes by authorized individuals | The information system provides authorized individuals (or processes acting on behalf of individuals) the capability to define or change the value of associated security attributes. |
| 83 | AC-16(3) | AC-16(3) | security attributes | maintenance of attribute associations by information system | The information system maintains the association and integrity of [Assignment: organization-defined security attributes] to [Assignment: organization-defined subjects and objects]. |
| 84 | AC-16(4) | AC-16(4) | security attributes | association of attributes by authorized individuals | The information system supports the association of [Assignment: organization-defined security attributes] with [Assignment: organization-defined subjects and objects] by authorized individuals (or processes acting on behalf of individuals). |
| 85 | AC-16(5) | AC-16(5) | security attributes | attribute displays for output devices | The information system displays security attributes in human-readable form on each object that the system transmits to output devices to identify [Assignment: organization-identified special dissemination, handling, or distribution instructions] using [Assignment: organization-identified human-readable, standard naming conventions]. |
| 86 | AC-16(6) | AC-16(6) | security attributes | maintenance of attribute association by organization | The organization allows personnel to associate, and maintain the association of [Assignment: organization-defined security attributes] with [Assignment: organization-defined subjects and objects] in accordance with [Assignment: organization-defined security policies]. |
| 87 | AC-16(7) | AC-16(7) | security attributes | consistent attribute interpretation | The organization provides a consistent interpretation of security attributes transmitted between distributed information system components. |
| 88 | AC-16(8) | AC-16(8) | security attributes | association techniques / technologies | The information system implements [Assignment: organization-defined techniques or technologies] with [Assignment: organization-defined level of assurance] in associating security attributes to information. |
| 89 | AC-16(9) | AC-16(9) | security attributes | attribute reassignment | The organization ensures that security attributes associated with information are reassigned only via re-grading mechanisms validated using [Assignment: organization-defined techniques or procedures]. |
| 90 | AC-16(10) | AC-16(10) | security attributes | attribute configuration by authorized individuals | The information system provides authorized individuals the capability to define or change the type and value of security attributes available for association with subjects and objects. |
| 91 | AC-17 | AC-17 | Remote Access | The AFLCMC/WW F16 System Program Office: |
a. Establishes and documents usage restrictions, configuration/connection requirements, and implementation guidance for each type of remote access allowed; and
| b. Authorizes remote access to the information system prior to allowing such connections. | X | ||||
| 92 | AC-17(1) | AC-17(1) | remote access | automated monitoring / control | The information system monitors and controls remote access methods. | |
| 93 | AC-17(2) | AC-17(2) | remote access | protection of confidentiality / integrity using encryption | The information system implements cryptographic mechanisms to protect the confidentiality and integrity of remote access sessions. | |
| 94 | AC-17(3) | AC-17(3) | remote access | managed access control points | The information system routes all remote accesses through [Assignment: organization-defined number] managed network access control points. | |
| 95 | AC-17(4) | AC-17(4) | remote access | privileged commands / access | The organization: |
(a) Authorizes the execution of privileged commands and access to security-relevant information via remote access only for [Assignment: organization-defined needs]; and
(b) Documents the rationale for such access in the security plan for the information system.
| 96 | AC-17(5) | AC-17(5) | remote access | monitoring for unauthorized connections | [Withdrawn: Incorporated into SI-4]. | |
| 97 | AC-17(6) | AC-17(6) | remote access | protection of information | The organization ensures that users protect information about remote access mechanisms from unauthorized use and disclosure. | |
| 98 | AC-17(7) | AC-17(7) | remote access | additional protection for security function access | [Withdrawn: Incorporated into AC-3 (10)]. | |
| 99 | AC-17(8) | AC-17(8) | remote access | disable nonsecure network protocols | [Withdrawn: Incorporated into CM-7]. | |
| 100 | AC-17(9) | AC-17(9) | remote access | disconnect / disable access | The organization provides the capability to expeditiously disconnect or disable remote access to the information system within [Assignment: organization-defined time period]. | X |
| 101 | AC-18 | AC-18 | Wireless Access | The AFLCMC/WW F16 System Program Office: |
a. Establishes usage restrictions, configuration/connection requirements, and implementation guidance for wireless access; and
| b. Authorizes wireless access to the information system prior to allowing such connections. | X | |||||
| 102 | AC-18(1) | AC-18(1) | wireless access | authentication and encryption | The information system protects wireless access to the system using authentication of [Selection (one or more): users; devices] and encryption. | X | |
| 103 | AC-18(2) | AC-18(2) | wireless access | monitoring unauthorized connections | [Withdrawn: Incorporated into SI-4]. | ||
| 104 | AC-18(3) | AC-18(3) | wireless access | disable wireless networking | The organization disables, when not intended for use, wireless networking capabilities internally embedded within information system components prior to issuance and deployment. | X | |
| 105 | AC-18(4) | AC-18(4) | wireless access | restrict configurations by users | The organization identifies and explicitly authorizes users allowed to independently configure wireless networking capabilities. | X | |
| 106 | AC-18(5) | AC-18(5) | wireless access | antennas / transmission power levels | The organization selects radio antennas and calibrates transmission power levels to reduce the probability that usable signals can be received outside of organization-controlled boundaries. | X | |
| 107 | AC-19 | AC-19 | Access Control for Mobile Devices | The AFLCMC/WW F16 System Program Office: |
a. Establishes usage restrictions, configuration requirements, connection requirements, and implementation guidance for organization-controlled mobile devices; and
| b. Authorizes the connection of mobile devices to organizational information systems. | X | ||||
| 108 | AC-19(1) | AC-19(1) | access control for mobile devices | use of writable / portable storage devices | [Withdrawn: Incorporated into MP-7]. | |
| 109 | AC-19(2) | AC-19(2) | access control for mobile devices | use of personally owned portable storage devices | [Withdrawn: Incorporated into MP-7]. | |
| 110 | AC-19(3) | AC-19(3) | access control for mobile devices | use of portable storage devices with no identifiable owner | [Withdrawn: Incorporated into MP-7]. | |
| 111 | AC-19(4) | AC-19(4) | access control for mobile devices | restrictions for classified information | The AFLCMC/WW F16 System Program Office: |
(a) Prohibits the use of unclassified mobile devices in facilities containing information systems processing, storing, or transmitting classified information unless specifically permitted by the authorizing official; and
(b) Enforces the following restrictions on individuals permitted by the authorizing official to use unclassified mobile devices in facilities containing information systems processing, storing, or transmitting classified information:
(1) Connection of unclassified mobile devices to classified information systems is prohibited;
(2) Connection of unclassified mobile devices to unclassified information systems requires approval from the authorizing official;
(3) Use of internal or external modems or wireless interfaces within the unclassified mobile devices is prohibited; and
(4) Unclassified mobile devices and the information stored on those devices are subject to random reviews and inspections by [Assignment: organization-defined security officials], and if classified information is found, the incident handling policy is followed.
| (c) Restricts the connection of classified mobile devices to classified information systems in accordance with [Assignment: organization-defined security policies]. | X | |||||||
| 112 | AC-19(5) | AC-19(5) | access control for mobile devices | full device / container-based encryption | The F-16 SPO employs full-device encryption to protect the confidentiality and integrity of information at rest on the PDGU. | X | X | Government | |
| 113 | AC-20 | AC-20 | Use of External Information Systems | The organization establishes terms and conditions, consistent with any trust relationships established with other organizations owning, operating, and/or maintaining external information systems, allowing authorized individuals to: |
a. Access the information system from external information systems; and
| b. Process, store, or transmit organization-controlled information using external information systems. | X | ||||
| 114 | AC-20(1) | AC-20(1) | use of external information systems | limits on authorized use | The organization permits authorized individuals to use an external information system to access the information system or to process, store, or transmit organization-controlled information only when The AFLCMC/WW F16 System Program Office: |
(a) Verifies the implementation of required security controls on the external system as specified in the organization’s information security policy and security plan; or
| (b) Retains approved information system connection or processing agreements with the organizational entity hosting the external information system. | X | |||||||
| 115 | AC-20(2) | AC-20(2) | use of external information systems | portable storage devices | The F-16 SPO restrict access to the ADTC based on contents by authorized individuals. | X | X | Government | |
| 116 | AC-20(3) | AC-20(3) | use of external information systems | non-organizationally owned systems / components / devices | The organization [Selection: restricts; prohibits] the use of non-organizationally owned information systems, system components, or devices to process, store, or transmit organizational information. | X | |||
| 117 | AC-20(4) | AC-20(4) | use of external information systems | network accessible storage devices | The organization prohibits the use of [Assignment: organization-defined network accessible storage devices] in external information systems. | ||||
| 118 | AC-21 | AC-21 | Information Sharing | The AFLCMC/WW F16 System Program Office: |
a. Facilitates information sharing by enabling authorized users to determine whether access authorizations assigned to the sharing partner match the access restrictions on the information for [Assignment: organization-defined information sharing circumstances where user discretion is required]; and
| b. Employs [Assignment: organization-defined automated mechanisms or manual processes] to assist users in making information sharing/collaboration decisions. | X | ||||
| 119 | AC-21(1) | AC-21(1) | information sharing | automated decision support | The information system enforces information-sharing decisions by authorized users based on access authorizations of sharing partners and access restrictions on information to be shared. | |
| 120 | AC-21(2) | AC-21(2) | information sharing | information search and retrieval | The information system implements information search and retrieval services that enforce [Assignment: organization-defined information sharing restrictions]. | |
| 121 | AC-22 | AC-22 | Publicly Accessible Content | The AFLCMC/WW F16 System Program Office: |
a. Designates individuals authorized to post information onto a publicly accessible information system;
b. Trains authorized individuals to ensure that publicly accessible information does not contain nonpublic information;
c. Reviews the proposed content of information prior to posting onto the publicly accessible information system to ensure that nonpublic information is not included; and
| d. Reviews the content on the publicly accessible information system for nonpublic information [Assignment: organization-defined frequency] and removes such information, if discovered. | X | ||||
| 122 | AC-23 | AC-23 | Data Mining Protection | The organization employs [Assignment: organization-defined data mining prevention and detection techniques] for [Assignment: organization-defined data storage objects] to adequately detect and protect against data mining. | |
| 123 | AC-24 | AC-24 | Access Control Decisions | The organization establishes procedures to ensure [Assignment: organization-defined access control decisions] are applied to each access request prior to access enforcement. | |
| 124 | AC-24(1) | AC-24(1) | access control decisions | transmit access authorization information | The information system transmits [Assignment: organization-defined access authorization information] using [Assignment: organization-defined security safeguards] to [Assignment: organization-defined information systems] that enforce access control decisions. | |
| 125 | AC-24(2) | AC-24(2) | access control decisions | no user or process identity | The information system enforces access control decisions based on [Assignment: organization-defined security attributes] that do not include the identity of the user or process acting on behalf of the user. | |
| 126 | AC-25 | AC-25 | Reference Monitor | The information system implements a reference monitor for [Assignment: organization-defined access control policies] that is tamperproof, always invoked, and small enough to be subject to analysis and testing, the completeness of which can be assured. | |
| 127 | AT-1 | AT-1 | Security Awareness and Training Policy and Procedures | The AFLCMC/WW F16 System Program Office: |
a. Develops, documents, and disseminates to [Assignment: organization-defined personnel or roles]:
1. A security awareness and training policy that addresses purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance; and
2. Procedures to facilitate the implementation of the security awareness and training policy and associated security awareness and training controls; and
b. Reviews and updates the current:
1. Security awareness and training policy [Assignment: organization-defined frequency]; and
| 2. Security awareness and training procedures [Assignment: organization-defined frequency]. | X | ||||
| 128 | AT-2 | AT-2 | Security Awareness Training | The organization provides basic security awareness training to information system users (including managers, senior executives, and contractors): |
a. As part of initial training for new users;
b. When required by information system changes; and
| c. [Assignment: organization-defined frequency] thereafter. | X | |||||
| 129 | AT-2(1) | AT-2(1) | security awareness | practical exercises | The organization includes practical exercises in security awareness training that simulate actual cyber attacks. | ||
| 130 | AT-2(2) | AT-2(2) | security awareness | insider threat | The organization includes security awareness training on recognizing and reporting potential indicators of insider threat. | X | |
| 131 | AT-3 | AT-3 | Role-Based Security Training | The organization provides role-based security training to personnel with assigned security roles and responsibilities: |
a. Before authorizing access to the information system or performing assigned duties;
b. When required by information system changes; and
| c. [Assignment: organization-defined frequency] thereafter. | X | |||||
| 132 | AT-3(1) | AT-3(1) | security training | environmental controls | The organization provides [Assignment: organization-defined personnel or roles] with initial and [Assignment: organization-defined frequency] training in the employment and operation of environmental controls. | ||
| 133 | AT-3(2) | AT-3(2) | security training | physical security controls | The organization provides [Assignment: organization-defined personnel or roles] with initial and [Assignment: organization-defined frequency] training in the employment and operation of physical security controls. | X | |
| 134 | AT-3(3) | AT-3(3) | security training | practical exercises | The organization includes practical exercises in security training that reinforce training objectives. | ||
| 135 | AT-3(4) | AT-3(4) | security training | suspicious communications and anomalous system behavior | The organization provides training to its personnel on [Assignment: organization-defined indicators of malicious code] to recognize suspicious communications and anomalous behavior in organizational information systems. | X | |
| 136 | AT-4 | AT-4 | Security Training Records | The AFLCMC/WW F16 System Program Office: |
a. Documents and monitors individual information system security training activities including basic security awareness training and specific information system security training; and
| b. Retains individual training records for [Assignment: organization-defined time period]. | X | ||||
| 137 | AT-5 | AT-5 | Contacts with Security Groups and Associations | [Withdrawn: Incorporated into PM-15]. | |
| 138 | AU-1 | AU-1 | Audit and Accountability Policy and Procedures | The AFLCMC/WW F16 System Program Office: |
a. Develops, documents, and disseminates to [Assignment: organization-defined personnel or roles]:
1. An audit and accountability policy that addresses purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance; and
2. Procedures to facilitate the implementation of the audit and accountability policy and associated audit and accountability controls; and
b. Reviews and updates the current:
1. Audit and accountability policy [Assignment: organization-defined frequency]; and
| 2. Audit and accountability procedures [Assignment: organization-defined frequency]. | X | X | Government | 309th verify authentication | ||
| 139 | AU-2 | AU-2 | Audit Events | The AFLCMC/WW F16 System Program Office: |
a. Determines that the information system is capable of auditing the following events: [Assignment: organization-defined auditable events];
b. Coordinates the security audit function with other organizational entities requiring audit-related information to enhance mutual support and to help guide the selection of auditable events;
c. Provides a rationale for why the auditable events are deemed to be adequate to support after-the-fact investigations of security incidents; and
| d. Determines that the following events are to be audited within the information system: [Assignment: organization-defined audited events (the subset of the auditable events defined in AU-2 a.) along with the frequency of (or situation requiring) auditing for each identified event]. | X | X | Government | 309th verify authentication | |||||
| 140 | AU-2(1) | AU-2(1) | audit events | compilation of audit records from multiple sources | [Withdrawn: Incorporated into AU-12]. | |||||
| 141 | AU-2(2) | AU-2(2) | audit events | selection of audit events by component | [Withdrawn: Incorporated into AU-12]. | |||||
| 142 | AU-2(3) | AU-2(3) | audit events | reviews and updates | The organization reviews and updates the audited events [Assignment: organization-defined frequency]. | X | ||||
| 143 | AU-2(4) | AU-2(4) | audit events | privileged functions | [Withdrawn: Incorporated into AC-6 (9)]. | |||||
| 144 | AU-3 | AU-3 | Content of Audit Records | The information system generates audit records containing information that establishes what type of event occurred, when the event occurred, where the event occurred, the source of the event, the outcome of the event, and the identity of any individuals or subjects associated with the event. | X | X | Supplier/Government | ||
| 145 | AU-3(1) | AU-3(1) | content of audit records | additional audit information | The information system generates audit records containing the following additional information: [Assignment: organization-defined additional, more detailed information]. | X | ||||
| 146 | AU-3(2) | AU-3(2) | content of audit records | centralized management of planned audit record content | The information system provides centralized management and configuration of the content to be captured in audit records generated by [Assignment: organization-defined information system components]. | |||||
| 147 | AU-4 | AU-4 | Audit Storage Capacity | The organization allocates audit record storage capacity in accordance with [Assignment: organization-defined audit record storage requirements]. | X | ||||
| 148 | AU-4(1) | AU-4(1) | audit storage capacity | transfer to alternate storage | The information system off-loads audit records [Assignment: organization-defined frequency] onto a different system or media than the system being audited. | |||||
| 149 | AU-5 | AU-5 | Response to Audit Processing Failures | The information system: |
a. Alerts [Assignment: organization-defined personnel or roles] in the event of an audit processing failure; and
b. Takes the following additional actions: [Assignment: organization-defined actions to be taken (e.g., shut down information system, overwrite oldest audit records, stop generating audit records)].
| 150 | AU-5(1) | AU-5(1) | response to audit processing failures | audit storage capacity | The information system provides a warning to [Assignment: organization-defined personnel, roles, and/or locations] within [Assignment: organization-defined time period] when allocated audit record storage volume reaches [Assignment: organization-defined percentage] of repository maximum audit record storage capacity. |
| 151 | AU-5(2) | AU-5(2) | response to audit processing failures | real-time alerts | The information system provides an alert in [Assignment: organization-defined real-time period] to [Assignment: organization-defined personnel, roles, and/or locations] when the following audit failure events occur: [Assignment: organization-defined audit failure events requiring real-time alerts]. |
| 152 | AU-5(3) | AU-5(3) | response to audit processing failures | configurable traffic volume thresholds | The information system enforces configurable network communications traffic volume thresholds reflecting limits on auditing capacity and [Selection: rejects; delays] network traffic above those thresholds. |
| 153 | AU-5(4) | AU-5(4) | response to audit processing failures | shutdown on failure | The information system invokes a [Selection: full system shutdown; partial system shutdown; degraded operational mode with limited mission/business functionality available] in the event of [Assignment: organization-defined audit failures], unless an alternate audit capability exists. |
| 154 | AU-6 | AU-6 | Audit Review, Analysis, and Reporting | The AFLCMC/WW F16 System Program Office: |
a. Reviews and analyzes information system audit records [Assignment: organization-defined frequency] for indications of [Assignment: organization-defined inappropriate or unusual activity]; and
| b. Reports findings to [Assignment: organization-defined personnel or roles]. | X | |||||
| 155 | AU-6(1) | AU-6(1) | audit review, analysis, and reporting | process integration | The organization employs automated mechanisms to integrate audit review, analysis, and reporting processes to support organizational processes for investigation and response to suspicious activities. | X | |
| 156 | AU-6(2) | AU-6(2) | audit review, analysis, and reporting | automated security alerts | [Withdrawn: Incorporated into SI-4]. |
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .