2016_06_21_HSFE60-16-R-0004_Attachment_G_DSA_Requirements_Traceability_M....pdf

PDF 590 KB Posted

Attached to
National Flood Insurance Program (NFIP) Direct Servicing Agent (DSA) Federal contract opportunity
Solicitation number
HSFE60-16-R-0004
Issued by
Federal Emergency Management Agency Recovery Section

About this file

HSFE60-16-R-0004 A00002 Attachment G DSA RTM

View the file

Other files for this federal contract opportunity

Show all 19

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

FOR OFFICIAL USE ONLY

Direct Servicing Agent

DSA

Requirements Traceability Matrix

(RTM)

Prepared for Department of Homeland Security

21 June 2016 i

1. Introduction

The Requirements Traceability Matrix (RTM) relates requirements from requirement source documents to the security certification process. It ensures that all security requirements are identified and investigated. Each row of the matrix identifies a specific requirement and provides the details of how it was tested or analyzed and the results.

The table is arranged to display the system security requirements from the applicable regulation documents, which are listed below:

• NIST 800-53 w/ DHS 4300A Rev 4 - Department of Homeland Security Sensitive Systems Policy Directive 4300A Version 10 (with 800-53 Rev 4)

The columns of the RTM are defined as follows:

Control Ref. Refers to the name (short title) of the source document and the ID or paragraph number of the listed control or requirement.

Security Req./ Control

Short title describing the security control or requirement (and the text of the control/requirement, which may be paraphrased for brevity).

Security Category

Category and class associated with the security control.

Control Type

Auto populated if the requirement is identified with two security control types: common and system-specific; i.e., a part of the requirement is identified as common type and another part of it is system-specific.

• Common. Auto populated if the requirement is designated to one or more information systems.

• Hybrid. Auto populated if the requirement is identified with two security control types:

common and system-specific; i.e., a part of the requirement is identified as common type and another part of it is system-specific.

• System-Specific. Auto populated if the requirement is assigned to a specific information system.

• Inherited. Auto populated if the requirement is inherited from another system.

• Not Specified. Auto populated if the requirement does not require any security control.

Planned Imp.

Auto populated if the requirement is identified with two security control types: common and system-specific; i.e., a part of the requirement is identified as common type and another part of it is system-specific.

• Common. Auto populated if the requirement is designated to one or more information systems.

• Hybrid. Auto populated if the requirement is identified with two security control types:

common and system-specific; i.e., a part of the requirement is identified as common type and another part of it is system-specific.

• System-Specific. Auto populated if the requirement is assigned to a specific information system.

• Inherited. Auto populated if the requirement is inherited from another system.

• Not Specified. Auto populated if the requirement does not require any security control.

Actual Imp. Identification whether the control is in place and how it has been implemented, or differences ii in how the control was implemented compared to what was planned.

• As Planned. Auto populated if Implemented control status is selected and Planned

Implementation column does not read Not Entered.

• Pending Implementation. Auto populated if Planned control status is selected and

Planned Implementation column does not read Not Entered.

• Partially Implemented. Auto populated if Partial control status is selected and

Planned Implementation column does not read Not Entered.

• Not Entered. Auto populated if the Planned Implementation column reads Not

Entered.

• Not Assigned. Auto populated if the Control Type and/or Control Status were not selected.

Test #(s) The ID number of the specific test procedure(s) that is used to validate the requirement or control.

• -. The control is not applicable.

Methods

The evaluation method (or methods) used to assess the requirement.

• I. Interview.

• E. Examine.

• T. Testing.

• -. The control is not applicable.

Tailored

The tailored control that modifies the control set.

• In. The control was tailored in.

• Out. The control was tailored out.

• - . The control was not affected from tailoring.

Overlays

The controls included or excluded from the controls already in the baseline.

• In. The control was added in to the controls in the baseline.

• Out. The control was removed from the controls in the baseline.

• - . The control was not affected from overlay(s).

Result

The summarized result for the test procedures that cover the requirement/control.

• Met - Requirement fully satisfied.

• Not Met - Requirement not satisfied.

• Not Applicable - Requirement not applicable.

Notes Identifies the factor, and the basis for; any tailoring of controls from the NIST 800-53 w/ DHS 4300A Rev 4 baseline or organizational overlay that was used for the system.

2. Requirements Traceability Matrix

Control Ref.

Security Req./

Control

Security Category

Control Type

Planned Imp.

Actual Imp.

Test #(s)

Methods Tailored Result Notes

I E T IN OUT

NIST 800-

53 w/ DHS 4300A Rev

4 AC-1

Access Control

Policy and Procedures

Access Control

Policy and Procedures

(T)

AC-1.1,

AC-1.2 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 AC-1

(DHS-

5.1.1.c)

Sharing of Personal

Passwords

Access Control

Policy and Procedures

(T)

AC-

1(DHS-

5.1.1.c)

X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 AC-2

Account Management

Account Management

(T) AC-2.1 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 AC-2 (1)

Automated System Account

Management

Account Management

(T) AC-2(1).1 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 AC-2 (2)

Removal Of Temporary / Emergency Accounts

Account Management

(T) AC-2(2).1 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 AC-2 (3)

Disable Inactive

Accounts

Account Management

(T) AC-2(3).1 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 AC-2 (4)

Automated Audit Actions

Account Management

AC-2(4).1 X X - - - Not Met None

Control Ref.

Security Req./

Category

Control Type

Planned Imp.

Actual Imp.

Test #(s) Methods Tailored Result Notes

NIST 800-

53 w/ DHS 4300A Rev

4 AC-3

Access Enforcement

Access Enforcement

(T) AC-3.1 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 AC-3

(DHS-

5.1.1.d)

Use of group passwords

Access Enforcement

3(DHS-

5.1.1.d)

X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 AC-4

Information Flow

Enforcement

Information Flow

Enforcement (T)

AC-4.1 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 AC-5

Separation of Duties

Separation of Duties (T) AC-5.1 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 AC-6

Least Privilege

Least Privilege (T) AC-6.1 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 AC-6 (1)

Authorize Access To Security

Functions

Least Privilege (T) AC-6(1).1 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 AC-6 (2)

Non- Privileged Access For Nonsecurity Functions

Least Privilege (T) AC-6(2).1 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 AC-6 (5)

Privileged Accounts

Least Privilege (T) AC-6(5).1 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

Auditing Use Of Privileged

Functions

Least Privilege (T) AC-6(9).1 X X - - - Not Met None

Control Ref.

Control Type

Planned Imp.

Actual Imp.

Test #(s) Methods Tailored Result Notes

4 AC-6 (9)

NIST 800-

53 w/ DHS 4300A Rev

4 AC-6

(10)

Prohibit Non- Privileged

Users From Executing Privileged Functions

Least Privilege (T) AC-

6(10).1 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 AC-7

Unsuccessful Logon

Attempts

Unsuccessful Logon

Attempts (T) AC-7.1 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 AC-8

System Use Notification

System Use Notification

(T)

AC-8.1,

AC-8.2 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 AC-8

(DHS-

4.8.5.d)

Governement Funded Office

Equipment

System Use Notification

8(DHS-

4.8.5.d)

X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 AC-11

Session Lock Session Lock

(T) AC-11.1 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 AC-11

(1)

Pattern- Hiding

Displays

Session Lock

(T) AC-

11(1).1 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 AC-12

Session Termination

Session Termination

(T) AC-12.1 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 AC-14

Permitted Actions without

Identification

Permitted Actions without

Identification

AC-14.1 X X - - - Not Met None

Control Ref.

Control Type

Planned Imp.

Actual Imp.

Test #(s) Methods Tailored Result Notes or Authenticatio n or Authenticatio n (T)

NIST 800-

53 w/ DHS 4300A Rev

4 AC-17

Remote Access

Remote Access (T) AC-17.1 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 AC-17

(1)

Automated Monitoring /

Control

Remote Access (T) AC-

17(1).1 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 AC-17

(2)

Protection Of Confidentialit y / Integrity

Using Encryption

Remote Access (T) AC-

17(2).1 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 AC-17

(3)

Managed Access Control Points

Remote Access (T) AC-

17(3).1 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 AC-17

(4)

Privileged Commands /

Access

Remote Access (T) AC-

17(4).1 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 AC-17

(DHS-

5.4.1.b)

Remote Access

Connection Management

Remote Access (T)

AC-

17(DHS-

5.4.1.b)

X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 AC-17

(DHS-

Remote Access of PII

Remote Access (T)

AC-

17(DHS-

5.4.1.c)

X X - - - Not Met None

Control Ref.

Control Type

Planned Imp.

Actual Imp.

Test #(s) Methods Tailored Result Notes

5.4.1.c)

NIST 800-

53 w/ DHS 4300A Rev

4 AC-18

Wireless Access

Wireless Access (T) AC-18.1 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 AC-18

(1)

Authenticatio n And

Encryption

Wireless Access (T) AC-

18(1).1 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 AC-19

Access Control for

Mobile Devices

Access Control for

Mobile Devices (T)

AC-19.1 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 AC-19

(5)

Full Device / Container-

Based Encryption

Access Control for

Mobile Devices (T)

AC-

19(5).1 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 AC-20

Use of External

Information Systems

Use of External

Information Systems (T)

AC-20.1 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 AC-20

(1)

Limits On Authorized

Use

Use of External

Information Systems (T)

AC-

20(1).1 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 AC-20

(2)

Portable Storage Devices

Use of External

Information Systems (T)

AC-

20(2).1 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 AC-21

Information Sharing

Information Sharing (T) AC-21.1 X X - - - Not Met None

NIST 800- Publicly Publicly AC-22.1 X X - - - Not Met None

Control Ref.

Control Type

Planned Imp.

Actual Imp.

Test #(s) Methods Tailored Result Notes

53 w/ DHS 4300A Rev

4 AC-22

Accessible Content

Accessible Content (T)

NIST 800-

53 w/ DHS 4300A Rev

4 AT-1

Security Awareness and Training Policy and Procedures

Security Awareness and Training Policy and Procedures

(O)

AT-1.1,

AT-1.2 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 AT-2

Security Awareness Training

Security Awareness

Training (O) AT-2.1 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 AT-2 (2)

Insider Threat Security

Awareness Training (O)

- - - - - Met None

NIST 800-

53 w/ DHS 4300A Rev

4 AT-3

Role-Based Security Training

Role-Based Security

Training (O) AT-3.1 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 AT-4

Security Training Records

Security Training

Records (O) AT-4.1 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 AU-1

Audit and Accountabilit y Policy and Procedures

Audit and Accountabilit y Policy and Procedures

(T)

AU-1.1,

AU-1.2 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 AU-2

Audit Events Audit Events

(T) AU-2.1 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 AU-2 (3)

Reviews And Updates

Audit Events

(T) AU-2(3).1 X X - - - Not Met None

Control Ref.

Control Type

Planned Imp.

Actual Imp.

Test #(s) Methods Tailored Result Notes

NIST 800-

53 w/ DHS 4300A Rev

4 AU-3

Content of Audit

Records

Content of Audit

Records (T) AU-3.1 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 AU-3 (1)

Additional Audit

Information

Content of Audit

Records (T) AU-3(1).1 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 AU-4

Audit Storage Capacity

Audit Storage Capacity (T) AU-4.1 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 AU-5

Response to Audit

Processing Failures

Response to Audit

Processing Failures (T)

AU-5.1 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 AU-6

Audit Review, Analysis, and Reporting

Audit Review, Analysis, and Reporting (T)

AU-6.1,

AU-6.2 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 AU-6 (1)

Process Integration

Audit Review, Analysis, and Reporting (T)

AU-6(1).1 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 AU-6 (3)

Correlate Audit

Repositories

Audit Review, Analysis, and Reporting (T)

AU-6(3).1 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 AU-6

(DHS-

5.3.b)

Audit Records for Financial

Systems and

PII

Audit Review, Analysis, and Reporting (T)

AU-

6(DHS-

5.3.b)

X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 AU-6

Mail Server Administratio n

Audit Review, Analysis, and Reporting (T)

AU-

5.4.6.f)

Control Ref.

Control Type

Planned Imp.

Actual Imp.

Test #(s) Methods Tailored Result Notes

(DHS-

5.4.6.f)

NIST 800-

53 w/ DHS 4300A Rev

4 AU-7

Audit Reduction and Report Generation

Audit Reduction and Report Generation

(T)

AU-7.1 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 AU-7 (1)

Automatic Processing

Audit Reduction and Report Generation

(T)

AU-7(1).1 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 AU-8

Time Stamps Time Stamps

(T) AU-8.1 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 AU-8 (1)

Synchronizati on With

Authoritative Time Source

Time Stamps

(T) AU-8(1).1 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 AU-9

Protection of Audit

Information

Protection of Audit

Information (T)

AU-9.1 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 AU-9 (4)

Access By Subset Of Privileged

Users

Protection of Audit

Information (T)

AU-9(4).1 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 AU-11

Audit Record Retention

Audit Record Retention (T) AU-11.1 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 AU-11

(DHS-

5.3.d)

Audit Log Retention

Audit Record Retention (T)

AU-

11(DHS-

5.3.d)

Control Ref.

Control Type

Planned Imp.

Actual Imp.

Test #(s) Methods Tailored Result Notes

NIST 800-

53 w/ DHS 4300A Rev

4 AU-12

Audit Generation

Audit Generation

(T) AU-12.1 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 CA-1

Security Assessment and Authorization Policies and Procedures

Security Assessment and Authorization Policies and Procedures

(M)

CA-1.1,

CA-1.2 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 CA-1

(DHS-

3.9.m)

Use of IACS for Security

Authorization

Security Assessment and Authorization Policies and

(M)

CA-

3.9.m)

X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 CA-1

(DHS-

3.18.c)

Cloud Environment

Usage

Security Assessment and Authorization Policies and

3.18.c)

X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 CA-1

(DHS-

3.18.d)

Usage of FedRAMP for Cloud Systems

Security Assessment and Authorization Policies and

3.18.d)

X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 CA-1

(DHS-

3.18.e)

Usage of Public Cloud

Service Provider

Security Assessment and Authorization Policies and

3.18.e)

Control Ref.

Control Type

Planned Imp.

Actual Imp.

Test #(s) Methods Tailored Result Notes

(M)

NIST 800-

53 w/ DHS 4300A Rev

4 CA-2

Security Assessments

Security Assessments

(M)

CA-2.1,

CA-2.2 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 CA-2 (1)

Independent Assessors

Security Assessments

(M) CA-2(1).1 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 CA-2

(DHS-

3.18.b)

Cloud Systems

Provided to External

Departments

Security Assessments

2(DHS-

3.18.b)

X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 CA-3

System Interconnecti ons

System Interconnecti ons (M) CA-3.1 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 CA-3 (5)

Restrictions On External

System Connections

System Interconnecti ons (M) CA-3(5).1 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 CA-3

(DHS-

5.4.3.b)

Interconnecti on

Establishmen t Procedures

System Interconnecti ons (M)

5.4.3.b)

X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 CA-3

(DHS-

5.4.3.c)

DHS OneNet Interconnecti ons

System

5.4.3.c)

X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

ISA

Reissuance

System

5.4.3.d)

Control Ref.

Control Type

Planned Imp.

Actual Imp.

Test #(s) Methods Tailored Result Notes

4 CA-3

(DHS-

5.4.3.d)

NIST 800-

53 w/ DHS 4300A Rev

4 CA-3

(DHS-

5.4.3.f)

Interconnecti on Security Agreements

System

5.4.3.f)

X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 CA-3

(DHS-

5.4.3.m)

Interconnecti on Security Agreements

System

5.4.3.m)

X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 CA-3

(DHS-

5.4.3.n)

DHS

Interconnecti ons

System

5.4.3.n)

X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 CA-5

Plan of Action and Milestones

Plan of Action and Milestones

(M)

CA-5.1 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 CA-5

(DHS-

2.2.8.d)

DHS

POA&M

Requirements

Plan of Action and Milestones

5(DHS-

2.2.8.d)

X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 CA-6

Security Authorization

Security Authorization

(M) CA-6.1 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

DHS Security Authorization

Security Authorization

3.9.h)

Control Ref.

Control Type

Planned Imp.

Actual Imp.

Test #(s) Methods Tailored Result Notes

4 CA-6

(DHS-

3.9.h)

NIST 800-

53 w/ DHS 4300A Rev

4 CA-7

Continuous Monitoring

Continuous Monitoring

(M) CA-7.1 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 CA-7 (1)

Independent Assessment

Continuous Monitoring

(M) CA-7(1).1 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 CA-7

(DHS-

4.6.3.a)

AO

Notification on Disabling

Security Features

Continuous Monitoring

7(DHS-

4.6.3.a)

X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 CA-9

Internal System

Connections

Internal System

Connections (M)

CA-9.1 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 CM-1

Configuration Management Policy and Procedures

Configuration Management Policy and Procedures

(O)

CM-1.1,

CM-1.2 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 CM-2

Baseline Configuration

Baseline Configuration

(O) CM-2.1 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 CM-2 (1)

Reviews And Updates

Baseline Configuration

(O) CM-2(1).1 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 CM-2 (3)

Retention Of Previous

Configuration s

Baseline Configuration

(O) CM-2(3).1 X X - - - Not Met None

Control Ref.

Control Type

Planned Imp.

Actual Imp.

Test #(s) Methods Tailored Result Notes

NIST 800-

53 w/ DHS 4300A Rev

4 CM-2 (7)

Configure Systems, Components, Or Devices For High- Risk Areas

Baseline Configuration

(O) CM-2(7).1 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 CM-2

(DHS-

3.9.b)

FIPS 199 and

FIPS 200

Usage

Baseline Configuration

CM-

3.9.b)

X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 CM-2

(DHS-

4.12.b)

Network Printers and Facsimile Machines

Baseline Configuration

4.12.b)

X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 CM-3

Configuration Change Control

Configuration Change

Control (O) CM-3.1 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 CM-3 (2)

Test / Validate / Document Changes

Configuration Change

Control (O) CM-3(2).1 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 CM-3

(DHS-

2.1.8.g)

Timely Response to

ICCB

Configuration Change

Control (O)

2.1.8.g)

X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 CM-3

(DHS-

5.4.3.l)

DHS Change Control Boards

(CCB)

Configuration Change

Control (O)

5.4.3.l)

Control Ref.

Control Type

Planned Imp.

Actual Imp.

Test #(s) Methods Tailored Result Notes

NIST 800-

53 w/ DHS 4300A Rev

4 CM-4

Security Impact

Analysis

Security Impact

Analysis (O) CM-4.1 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 CM-5

Access Restrictions for Change

Access Restrictions for Change

(O)

CM-5.1 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 CM-6

Configuration Settings

Configuration Settings (O) CM-6.1 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 CM-6

(DHS-

3.7.e)

USGCB

Requirements

Configuration Settings (O)

CM-

6(DHS-

3.7.e)

X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 CM-6

(DHS-

3.7.f)

USGCB

Compliance

Configuration Settings (O)

CM-

6(DHS-

3.7.f)

X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 CM-6

(DHS-

3.7.g)

Hardening and

Configuration Guidance

Configuration Settings (O)

CM-

6(DHS-

3.7.g)

X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 CM-6

(DHS-

4.5.2.b)

FAX Server Configuration

Configuration Settings (O)

CM-

6(DHS-

4.5.2.b)

X X - - - Not Met None

NIST 800-

53 w/ DHS

Hardening and

Configuration Settings (O) CM-

6(DHS- X X - - - Not Met None

Control Ref.

Control Type

Planned Imp.

Actual Imp.

Test #(s) Methods Tailored Result Notes

4300A Rev

4 CM-6

(DHS-

4.8.4.a)

Configuration Guidance

4.8.4.a)

NIST 800-

53 w/ DHS 4300A Rev

4 CM-6

(DHS-

4.12.f)

Network Printers, Copiers, and Facsimile

Administratio n

Configuration Settings (O)

CM-

6(DHS-

4.12.f)

X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 CM-6

(DHS-

4.12.j)

Multifunction Device

Configuration

Configuration Settings (O)

CM-

6(DHS-

4.12.j)

X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 CM-6

(DHS-

5.4.5.d)

Use of Telnet Configuration Settings (O)

CM-

6(DHS-

5.4.5.d)

X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 CM-6

(DHS-

5.4.5.e)

Use of File Transfer Protocol

(FTP)

Services

Configuration Settings (O)

CM-

6(DHS-

5.4.5.e)

X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 CM-6

(DHS-

5.4.6.a)

Email Operating

System Configuration

Guidance

Configuration Settings (O)

CM-

6(DHS-

5.4.6.a)

X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 CM-6

Email Server Configuration

Guidance

Configuration Settings (O)

CM-

6(DHS-

5.4.6.b)

Control Ref.

Control Type

Planned Imp.

Actual Imp.

Test #(s) Methods Tailored Result Notes

(DHS-

5.4.6.b)

NIST 800-

53 w/ DHS 4300A Rev

4 CM-6

(DHS-

5.4.6.c)

Email Content Filtering

Configuration Settings (O)

CM-

6(DHS-

5.4.6.c)

X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 CM-6

(DHS-

5.4.6.e)

Email Client Configuration

Configuration Settings (O)

CM-

6(DHS-

5.4.6.e)

X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 CM-7

Least Functionality

Least Functionality

(O) CM-7.1 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 CM-7 (1)

Periodic Review

Least Functionality

(O) CM-7(1).1 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 CM-7 (2)

Prevent Program

Execution

Least Functionality

(O) CM-7(2).1 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 CM-7 (4)

Unauthorized Software /

Blacklisting

Least Functionality

(O) CM-7(4).1 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 CM-7

(DHS-

4.8.6.a)

Wireless for Peripheral Equipment

Least Functionality

4.8.6.a)

X X - - - Not Met None

NIST 800-

53 w/ DHS

Network Printers, Least Functionality CM-

7(DHS- X X - - - Not Met None

Control Ref.

Control Type

Planned Imp.

Actual Imp.

Test #(s) Methods Tailored Result Notes

4300A Rev

4 CM-7

(DHS-

4.12.c)

Copiers, and Facsimile

Configuration

(O) 4.12.c)

NIST 800-

53 w/ DHS 4300A Rev

4 CM-7

(DHS-

5.4.5.f)

Remote Desktop

Connections

Least Functionality

5.4.5.f)

X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 CM-8

Information System

Component Inventory

Information System

Component Inventory (O)

CM-8.1 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 CM-8 (1)

Updates During

Installations / Removals

Information System

Component Inventory (O)

CM-8(1).1 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 CM-8 (3)

Automated Unauthorized Component Detection

Information System

Component Inventory (O)

CM-8(3).1 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 CM-8 (5)

No Duplicate Accounting

Of Components

Information System

Component Inventory (O)

CM-8(5).1 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 CM-9

Configuration Management

Plan

Configuration Management

Plan (O) CM-9.1 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 CM-10

Software Usage

Restrictions

SW Usage Restrictions

(O) CM-10.1 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 CM-11

User-Installed Software

User-Installed SW (O) CM-11.1 X X - - - Not Met None

Control Ref.

Control Type

Planned Imp.

Actual Imp.

Test #(s) Methods Tailored Result Notes

NIST 800-

53 w/ DHS 4300A Rev

4 CP-1

Contingency Planning

Policy and Procedures

Contingency Planning

Policy and Procedures

(O)

CP-1.1,

CP-1.2 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 CP-1

(DHS-

3.5.1.a)

Continuity of Operations Planning

Contingency Planning

Policy and

CP-

3.5.1.a)

X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 CP-1

(DHS-

3.5.2.d)

DHS

Contingency

Guidance

Contingency Planning

Policy and

3.5.2.d)

X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 CP-1

(DHS-

3.15.f)

DHS

Contingency Plan for CFO

Contingency Planning

Policy and

3.15.f)

X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 CP-2

Contingency Plan

Contingency Plan (O) CP-2.1, CP-2.2 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 CP-2 (1)

Coordinate With Related

Plans

Contingency Plan (O) CP-2(1).1 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 CP-2 (3)

Resume Essential

Missions / Business Functions

Contingency Plan (O) CP-2(3).1 X X - - - Not Met None

NIST 800-

53 w/ DHS

Identify Critical

Contingency Plan (O) CP-2(8).1 X X - - - Not Met None

Control Ref.

Control Type

Planned Imp.

Actual Imp.

Test #(s) Methods Tailored Result Notes

4300A Rev

4 CP-2 (8)

Assets

NIST 800-

53 w/ DHS 4300A Rev

4 CP-2

(DHS-

3.5.2.e)

DHS

Contingency

Plan

Contingency Plan (O)

CP-

2(DHS-

3.5.2.e)

X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 CP-3

Contingency Training

Contingency Training (O) CP-3.1 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 CP-4

Contingency Plan Testing

Contingency Plan Testing

(O) CP-4.1 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 CP-4 (1)

Coordinate With Related

Plans

Contingency Plan Testing

(O) CP-4(1).1 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 CP-4

(DHS-

3.5.2.f)

DHS

Contingency Plan Testing

Contingency Plan Testing

4(DHS-

3.5.2.f)

X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 CP-6

Alternate Storage Site

Alternate Storage Site

(O) CP-6.1 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 CP-6 (1)

Separation From Primary

Site

Alternate Storage Site

(O) CP-6(1).1 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 CP-6 (3)

Accessibility Alternate

Storage Site

CP-6(3).1 X X - - - Not Met None

Control Ref.

Control Type

Planned Imp.

Actual Imp.

Test #(s) Methods Tailored Result Notes

NIST 800-

53 w/ DHS 4300A Rev

4 CP-7

Alternate Processing

Site

Alternate Processing

Site (O) CP-7.1 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 CP-7 (1)

Separation From Primary

Site

Alternate Processing

Site (O) CP-7(1).1 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 CP-7 (2)

Accessibility Alternate

Processing Site (O)

CP-7(2).1 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 CP-7 (3)

Priority Of Service

Alternate Processing

Site (O) CP-7(3).1 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 CP-8

Telecommuni cations

Services

Telecommuni cations

Services (O) CP-8.1 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 CP-8 (1)

Priority Of Service

Provisions

Telecommuni cations

Services (O) CP-8(1).1 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 CP-8 (2)

Single Points Of Failure

Telecommuni cations

Services (O) CP-8(2).1 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 CP-9

Information System Backup

Information System

Backup (O)

CP-9.1,

CP-9.2 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 CP-9 (1)

Testing For Reliability /

Integrity

Information System

Backup (O) CP-9(1).1 X X - - - Not Met None

NIST 800-

53 w/ DHS

Information System

Information System CP-10.1 X X - - - Not Met None

Control Ref.

Control Type

Planned Imp.

Actual Imp.

Test #(s) Methods Tailored Result Notes

4300A Rev

4 CP-10

Recovery and Reconstitutio n

Recovery and Reconstitutio n (O)

NIST 800-

53 w/ DHS 4300A Rev

4 CP-10 (2)

Transaction Recovery

Information System

Recovery and Reconstitutio n (O)

CP-

10(2).1 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 CP-10

(DHS-

5.7.e)

Transaction Based

Systems

Information System

Recovery and Reconstitutio n (O)

10(DHS-

5.7.e)

X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 IA-1

Identification and

Authenticatio n Policy and Procedures

Identification and

Authenticatio n Policy and Procedures

(T)

IA-1.1,

IA-1.2 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 IA-1

(DHS-

1.6.d)

PIV

Credentials

Identification and

Authenticatio n Policy and

IA-

1.6.d)

X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 IA-1

(DHS-

3.14.7.a)

Online Transactions

Identification and

Authenticatio n Policy and

3.14.7.a)

X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 IA-1

(DHS-

3.14.7.c)

E- Authenticatio n

Identification and

Authenticatio n Policy and

3.14.7.c)

Control Ref.

Control Type

Planned Imp.

Actual Imp.

Test #(s) Methods Tailored Result Notes

NIST 800-

53 w/ DHS 4300A Rev

4 IA-1

(DHS-

3.14.7.f)

PIV

Credentials

Identification and

Authenticatio n Policy and

3.14.7.f)

X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 IA-1

(DHS-

5.4.6.j)

DHS Email Naming

Convention

Identification and

Authenticatio n Policy and

5.4.6.j)

X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 IA-2

Identification and

Authenticatio n

(Organization al Users)

Identification and

Authenticatio n

(Organization al Users) (T)

IA-2.1 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 IA-2 (1)

Network Access To Privileged Accounts

Identification and

Authenticatio n

(Organization al Users) (T)

IA-2(1).1 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 IA-2 (2)

Network Access To

Non- Privileged Accounts

Identification and

Authenticatio n

(Organization al Users) (T)

IA-2(2).1 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 IA-2 (3)

Local Access To Privileged

Accounts

Identification and

Authenticatio n

(Organization al Users) (T)

IA-2(3).1 X X - - - Not Met None

NIST 800-

53 w/ DHS

Network Access To

Identification and IA-2(8).1 X X - - - Not Met None

Control Ref.

Control Type

Planned Imp.

Actual Imp.

Test #(s) Methods Tailored Result Notes

4300A Rev

4 IA-2 (8)

Privileged Accounts -

Replay Resistant

Authenticatio n

(Organization al Users) (T)

NIST 800-

53 w/ DHS 4300A Rev

4 IA-2 (11)

Remote Access - Separate Device

Identification and

Authenticatio n

(Organization al Users) (T)

IA-2(11).1 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 IA-2 (12)

Acceptance Of PIV

Credentials

Identification and

Authenticatio n

(Organization al Users) (T)

IA-2(12).1 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 IA-2

(DHS-

5.1.d)

Usage of Identification or Authenticatio n Materials

Identification and

Authenticatio n

(Organization al Users) (T)

5.1.d)

X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 IA-3

Device Identification and Authenticatio n

Device Identification and Authenticatio n (T)

IA-3.1 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 IA-4

Identifier Management

Identifier Management

(T) IA-4.1 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 IA-5

Authenticator Management

Authenticator Management

(T) IA-5.1 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

Password- Based

Authenticatio

Authenticator Management

IA-5(1).1 X X - - - Not Met None

Control Ref.

Control Type

Planned Imp.

Actual Imp.

Test #(s) Methods Tailored Result Notes

4 IA-5 (1) n

NIST 800-

53 w/ DHS 4300A Rev

4 IA-5 (2)

PKI-Based Authenticatio n

Authenticator Management

(T) IA-5(2).1 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 IA-5 (3)

In-Person Or Trusted

Third-Party Registration

Authenticator Management

(T) IA-5(3).1 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 IA-5 (11)

Hardware Token-Based Authenticatio n

Authenticator Management

(T) IA-5(11).1 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 IA-5

(DHS-

5.1.e)

User Authenticatio n Materials

Authenticator Management

5.1.e)

X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 IA-6

Authenticator Feedback

Authenticator Feedback (T) IA-6.1 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 IA-7

Cryptographi c Module

Authenticatio n

Cryptographi c Module

Authenticatio n (T)

IA-7.1 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 IA-8

Identification and

Authenticatio n (Non-

Organizationa l Users)

Identification and

Authenticatio n (Non-

Organizationa l Users) (T)

IA-8.1 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 IA-8 (1)

Acceptance Of PIV

Credentials From Other Agencies

Identification and

Authenticatio n (Non-

Organizationa

IA-8(1).1 X X - - - Not Met None

Control Ref.

Control Type

Planned Imp.

Actual Imp.

Test #(s) Methods Tailored Result Notes l Users) (T)

NIST 800-

53 w/ DHS 4300A Rev

4 IA-8 (2)

Acceptance Of Third-

Party Credentials

Identification and

Authenticatio n (Non-

Organizationa l Users) (T)

IA-8(2).1 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 IA-8 (3)

Use Of

FICAM-

Approved Products

Identification and

Authenticatio n (Non-

Organizationa l Users) (T)

IA-8(3).1 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 IA-8 (4)

Use Of Ficam-Issued

Profiles

Identification and

Authenticatio n (Non-

Organizationa l Users) (T)

IA-8(4).1 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 IA-8

(DHS-

1.5.4.c)

Foreign Nationals

Identification and

Authenticatio n (Non-

Organizationa l Users) (T)

8(DHS-

1.5.4.c)

X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 IR-1

Incident Response Policy and Procedures

Incident Response Policy and Procedures

(O)

IR-1.1,

IR-1.2 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 IR-2

Incident Response Training

Incident Response

Training (O) IR-2.1 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 IR-3

Incident Response Testing

Incident Response

Testing (O) IR-3.1 X X - - - Not Met None

Control Ref.

Control Type

Planned Imp.

Actual Imp.

Test #(s) Methods Tailored Result Notes

NIST 800-

53 w/ DHS 4300A Rev

4 IR-3 (2)

Coordination With Related

Plans

Incident Response

Testing (O) IR-3(2).1 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 IR-4

Incident Handling

Incident Handling (O) IR-4.1 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 IR-4 (1)

Automated Incident Handling Processes

Incident Handling (O) IR-4(1).1 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 IR-5

Incident Monitoring

Incident Monitoring

(O) IR-5.1 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 IR-6

Incident Reporting

Incident Reporting (O) IR-6.1 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 IR-6 (1)

Automated Reporting

Incident Reporting (O) IR-6(1).1 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 IR-7

Incident Response Assistance

Incident Response Assistance

(O)

IR-7.1 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 IR-7 (1)

Automation Support For Availability

Of Information /

Support

Incident Response Assistance

(O)

IR-7(1).1 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 IR-8

Incident Response

Plan

Incident Response Plan (O)

IR-8.1,

IR-8.2 X X - - - Not Met None

Control Ref.

Control Type

Planned Imp.

Actual Imp.

Test #(s) Methods Tailored Result Notes

NIST 800-

53 w/ DHS 4300A Rev

4 MA-1

System Maintenance Policy and Procedures

System Maintenance Policy and Procedures

(O)

MA-1.1,

MA-1.2 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 MA-2

Controlled Maintenance

Controlled Maintenance

(O) MA-2.1 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 MA-3

Maintenance Tools

Maintenance Tools (O) MA-3.1 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 MA-3 (1)

Inspect Tools Maintenance Tools (O) MA-

3(1).1 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 MA-3 (2)

Inspect Media

Maintenance Tools (O) MA-

3(2).1 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 MA-4

Nonlocal Maintenance

Nonlocal Maintenance

(O) MA-4.1 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 MA-4 (2)

Document Nonlocal

Maintenance

Nonlocal Maintenance

(O)

MA-

4(2).1 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 MA-4 (6)

Cryptographi c Protection

Nonlocal Maintenance

(O)

MA-

4(6).1 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 MA-4

(DHS-

Remote Maintenance

Paths

Nonlocal Maintenance

MA-

5.4.4.c)

Control Ref.

Control Type

Planned Imp.

Actual Imp.

Test #(s) Methods Tailored Result Notes

5.4.4.c)

NIST 800-

53 w/ DHS 4300A Rev

4 MA-5

Maintenance Personnel

Maintenance Personnel (O) MA-5.1 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 MA-6

Timely Maintenance

Timely Maintenance

(O) MA-6.1 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 MP-1

Media Protection Policy and Procedures

Media Protection Policy and Procedures

(O)

MP-1.1,

MP-1.2 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 MP-1

(DHS-

3.14.5.b)

Removal of

PII

Media Protection Policy and

MP-

3.14.5.b)

X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 MP-1

(DHS-

4.3.1.g)

Protection of Printed Output

Media Protection Policy and

4.3.1.g)

X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 MP-1

(DHS-

5.4.1.d)

PII Remote Access

Media Protection Policy and

5.4.1.d)

X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 MP-1

(DHS-

5.6.c)

Media Scanning

Media Protection Policy and

5.6.c)

Control Ref.

Control Type

Planned Imp.

Actual Imp.

Test #(s) Methods Tailored Result Notes

NIST 800-

53 w/ DHS 4300A Rev

4 MP-2

Media Access Media Access

(O) MP-2.1 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 MP-3

Media Marking

Media Marking (O) MP-3.1 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 MP-4

Media Storage

Media Storage (O) MP-4.1 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 MP-4

(DHS-

3.14.5.f)

Rentention of Computer Readable Extracts (CREs)

Media Protection Policy and

3.14.5.f)

X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 MP-5

Media Transport

Media Transport (O) MP-5.1 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 MP-5 (4)

Cryptographi c Protection

Media Transport (O) MP-5(4).1 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 MP-5

(DHS-

4.11.f)

Backup Media

Shipping

Media Transport (O)

MP-

5(DHS-

4.11.f)

X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 MP-6

Media Sanitization

Media Sanitization

(O) MP-6.1 X X - - - Not Met None

NIST 800-

53 w/ DHS Media Use Media Use

(O) MP-7.1 X X - - - Not Met None

Control Ref.

Control Type

Planned Imp.

Actual Imp.

Test #(s) Methods Tailored Result Notes

4300A Rev

4 MP-7

NIST 800-

53 w/ DHS 4300A Rev

4 MP-7 (1)

Prohibit Use Without Owner

Media Use

(O) MP-7(1).1 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 MP-7

(DHS-

4.3.1.d)

USB Drive encryption

Media Use (O)

MP-

7(DHS-

4.3.1.d)

X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 MP-7

(DHS-

4.3.1.e)

DHS owned Removable

Media

Media Use (O)

MP-

7(DHS-

4.3.1.e)

X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 MP-7

(DHS-

4.3.1.f)

Protection of Sensitive Paper and Electronic Outputs

Media Use (O)

MP-

7(DHS-

4.3.1.f)

X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 PE-1

Physical and Environment al Protection Policy and Procedures

Physical and Environment al Protection Policy and Procedures

(O)

PE-1.1,

PE-1.2 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 PE-1

(DHS-

3.3.c)

Sensitive Information at Contractor

Sites

Physical and Environment al Protection Policy and

PE-

3.3.c)

X X - - - Not Met None

NIST 800-

53 w/ DHS

Voice Over Data

Physical and Environment PE-

1(DHS- X X - - - Not Met None

Control Ref.

Control Type

Planned Imp.

Actual Imp.

Test #(s) Methods Tailored Result Notes

4300A Rev

4 PE-1

(DHS-

4.5.4.b)

Networks al Protection Policy and Procedures

(O)

4.5.4.b)

NIST 800-

53 w/ DHS 4300A Rev

4 PE-1

(DHS-

4.6.2.3.b)

Video, IR, and RF Signals

Physical and Environment al Protection Policy and

4.6.2.3.b)

X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 PE-1

(DHS-

4.12.i)

Network Printers, Copiers, and Facsimile Locations

Physical and Environment al Protection Policy and

4.12.i)

X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 PE-2

Physical Access

Authorization s

Physical Access

Authorization s (O)

PE-2.1,

PE-2.2 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 PE-3

Physical Access Control

Physical Access

Control (O)

PE-3.1,

PE-3.2 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 PE-4

Access Control for

Transmission Medium

Access Control for

Transmission Medium (O)

PE-4.1 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 PE-5

Access Control for

Output Devices

Access Control for

Output Devices (O)

PE-5.1 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 PE-6

Monitoring Physical Access

Monitoring Physical

Access (O) PE-6.1 X X - - - Not Met None

NIST 800-

53 w/ DHS

Intrusion Alarms /

Physical PE-6(1).1 X X - - - Not Met None

Control Ref.

Control Type

Planned Imp.

Actual Imp.

Test #(s) Methods Tailored Result Notes

4300A Rev

4 PE-6 (1)

Surveillance Equipment

Access (O)

NIST 800-

53 w/ DHS 4300A Rev

4 PE-8

Visitor Access Records

Visitor Access

Records (O) PE-8.1 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 PE-9

Power Equipment and Cabling

Power Equipment and Cabling

(O)

PE-9.1 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 PE-10

Emergency Shutoff

Emergency Shutoff (O) PE-10.1 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 PE-11

Emergency Power

Emergency Power (O) PE-11.1 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 PE-12

Emergency Lighting

Emergency Lighting (O) PE-12.1 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 PE-13

Fire Protection

Fire Protection

(O) PE-13.1 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 PE-13 (3)

Automatic Fire

Suppression

Fire Protection

(O)

PE-

13(3).1 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 PE-14

Temperature and Humidity

Controls

Temperature and Humidity Controls (O)

PE-14.1 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 PE-15

Water Damage

Protection

Water Damage

Protection

PE-15.1 X X - - - Not Met None

Control Ref.

Control Type

Planned Imp.

Actual Imp.

Test #(s) Methods Tailored Result Notes

NIST 800-

53 w/ DHS 4300A Rev

4 PE-16

Delivery and Removal

Delivery and Removal (O) PE-16.1 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 PE-17

Alternate Work Site

Alternate Work Site

(O) PE-17.1 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 PL-1

Security Planning

Policy and Procedures

Security Planning

Policy and Procedures

(M)

PL-1.1,

PL-1.2 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 PL-1

(DHS-

3.14.5.c)

Sensitive PII

Security Planning

Policy and

PL-

3.14.5.c)

X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 PL-1

(DHS-

3.14.7.d)

E- Authenticatio n

Security Planning

Policy and

PL-

3.14.7.d)

X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 PL-2

System Security Plan

System Security Plan

(M) PL-2.1 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 PL-2 (3)

Plan / Coordinate With Other

Organizationa l Entities

System Security Plan

(M) PL-2(3).1 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 PL-4

Rules of Behavior

Rules of Behavior (M) PL-4.1 X X - - - Not Met None

Control Ref.

Control Type

Planned Imp.

Actual Imp.

Test #(s) Methods Tailored Result Notes

NIST 800-

53 w/ DHS 4300A Rev

4 PL-4 (1)

Social Media And

Networking Restrictions

Rules of Behavior (M) PL-4(1).1 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 PL-4

(DHS-

4.1.2.a)

DHS Rules of Behavior

Rules of Behavior (M)

PL-

4(DHS-

4.1.2.a)

X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 PL-4

(DHS-

4.8.2.a)

Laptop Encryption

Rules of Behavior (M)

PL-

4(DHS-

4.8.2.a)

X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 PL-4

(DHS-

4.8.2.b)

Laptop Power Down

Rules of Behavior (M)

PL-

4(DHS-

4.8.2.b)

X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 PL-4

(DHS-

4.8.3.a)

Personally Owned

Equipment

Rules of Behavior (M)

PL-

4(DHS-

4.8.3.a)

X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 PL-4

(DHS-

4.8.5.e)

Signed Rules of Behavior

Rules of Behavior (M)

PL-

4(DHS-

4.8.5.e)

X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 PL-8

Information Security

Architecture

Information Security

Architecture

PL-8.1 X X - - - Not Met None

Control Ref.

Control Type

Planned Imp.

Actual Imp.

Test #(s) Methods Tailored Result Notes

NIST 800-

53 w/ DHS 4300A Rev

4 PM-1

Information Security

Program Plan

Information Security

Program Plan (M)

PM-1.1 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 PM-2

Senior Information

Security Officer

Senior Information

Security Officer (M)

PM-2.1 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 PM-3

Information Security

Resources

Information Security

Resources (M)

PM-3.1 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 PM-4

Plan of Action and Milestones

Process

Plan of Action and Milestones Process (M)

PM-4.1 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 PM-5

Information System

Inventory

Information System

Inventory (M)

PM-5.1 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 PM-6

Information Security

Measures of Performance

Information Security

Measures of Performance

(M)

PM-6.1 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 PM-7

Enterprise Architecture

Enterprise Architecture

(M) PM-7.1 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 PM-8

Critical Infrastructure

Plan

Critical Infrastructure

Plan (M) PM-8.1 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 PM-9

Risk Management

Strategy

Risk Management Strategy (M)

PM-9.1 X X - - - Not Met None

NIST 800- Security Security PM-10.1 X X - - - Not Met None

Control Ref.

Control Type

Planned Imp.

Actual Imp.

Test #(s) Methods Tailored Result Notes

53 w/ DHS 4300A Rev

4 PM-10

Authorization Process

Authorization Process (M)

NIST 800-

53 w/ DHS 4300A Rev

4 PM-11

Mission/Busi ness Process Definition

Mission/Busi ness Process Definition

(M)

PM-11.1 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 PM-12

Insider Threat Program

Insider Threat Program (M) PM-12.1 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 PM-13

Information Security

Workforce

Information Security

Workforce (M)

PM-13.1 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 PM-14

Testing, Training, and Monitoring

Testing, Training, and Monitoring

(M)

PM-14.1 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 PM-15

Contacts with Security

Groups and Associations

Contacts with Security and Associations

(M)

PM-15.1 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 PM-16

Threat Awareness Program

Threat Awareness

Program (M) PM-16.1 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 PRIV-

AP-1

Authority to Collect

Authority to Collect () AP-1.1 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 PRIV-

AP-2

Purpose Specification

Purpose Specification

AP-2.1 X X - - - Not Met None

NIST 800- Governance Governance AR-1.1 X X - - - Not Met None

Control Ref.

Control Type

Planned Imp.

Actual Imp.

Test #(s) Methods Tailored Result Notes

53 w/ DHS 4300A Rev

4 PRIV-

AR-1

and Privacy Program and Privacy Program ()

NIST 800-

53 w/ DHS 4300A Rev

4 PRIV-

AR-2

Privacy Impact and

Risk Assessment

Privacy Impact and

Risk Assessment ()

AR-2.1 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 PRIV-

AR-3

Privacy Requirements for Contractors and Service Providers

Privacy Requirements for Contractors and Service Providers ()

AR-3.1 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 PRIV-

AR-4

Privacy Monitoring and Auditing

Privacy Monitoring and Auditing

AR-4.1 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 PRIV-

AR-5

Privacy Awareness and Training

Privacy Awareness and Training

AR-5.1 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 PRIV-

AR-6

Privacy Reporting

Privacy Reporting () AR-6.1 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 PRIV-

AR-7

Privacy- Enhanced

System Design and

Development

Privacy- Enhanced

System Design and

Development

AR-7.1 X X - - - Not Met None

NIST 800-

53 w/ DHS

Accounting of

Accounting of AR-8.1 X X - - - Not Met None

Control Ref.

Control Type

Planned Imp.

Actual Imp.

Test #(s) Methods Tailored Result Notes

4300A Rev

4 PRIV-

AR-8

Disclosures Disclosures ()

NIST 800-

53 w/ DHS 4300A Rev

4 PRIV-DI-

Data Quality Data Quality () DI-1.1 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 PRIV-DI-

Data Integrity and Data Integrity Board

Data Integrity and Data Integrity Board ()

DI-2.1 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 PRIV-

DM-1

Minimization of Personally Identifiable Information

Minimization of Personally Identifiable Information

DM-1.1 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 PRIV-

DM-2

Data Retention and

Disposal

Data Retention and

Disposal () DM-2.1 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 PRIV-

DM-3

Minimization of PII Used in

Testing, Training, and

Research

Minimization of PII Used in

Testing, Training, and Research ()

DM-3.1 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 PRIV-IP-

Consent Consent () IP-1.1 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 PRIV-IP-

Individual Access

Individual Access () IP-2.1 X X - - - Not Met None

Control Ref.

Control Type

Planned Imp.

Actual Imp.

Test #(s) Methods Tailored Result Notes

NIST 800-

53 w/ DHS 4300A Rev

4 PRIV-IP-

Redress Redress () IP-3.1 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 PRIV-IP-

Complaint Management

Complaint Management

IP-4.1 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 PRIV-

SE-1

Inventory of Personally Identifiable Information

Inventory of Personally Identifiable Information

SE-1.1 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 PRIV-

SE-2

Privacy Incident

Response

Privacy Incident

Response () SE-2.1 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 PRIV-

TR-1

Privacy Notice

Privacy Notice () TR-1.1 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 PRIV-

TR-2

System of Records

Notices and Privacy Act Statements

System of Records

Notices and Privacy Act

Statements ()

TR-2.1 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 PRIV-

TR-3

Disseminatio n of Privacy

Program Information

Disseminatio n of Privacy

Program Information

TR-3.1 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

Internal Use Internal Use () UL-1.1 X X - - - Not Met None

Control Ref.

Control Type

Planned Imp.

Actual Imp.

Test #(s) Methods Tailored Result Notes

4 PRIV-

UL-1

NIST 800-

53 w/ DHS 4300A Rev

4 PRIV-

UL-2

Information Sharing with Third Parties

Information Sharing with Third Parties

UL-2.1 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 PS-1

Personnel Security

Policy and Procedures

Personnel Security

Policy and Procedures

(O)

PS-1.1,

PS-1.2 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 PS-2

Position Risk Designation

Position Risk Designation

(O) PS-2.1 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 PS-3

Personnel Screening

Personnel Screening (O) PS-3.1 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 PS-4

Personnel Termination

Personnel Termination

(O) PS-4.1 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 PS-5

Personnel Transfer

Personnel Transfer (O) PS-5.1 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 PS-6

Access Agreements

Access Agreements

(O) PS-6.1 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 PS-7

Third-Party Personnel Security

Third-Party Personnel

Security (O) PS-7.1 X X - - - Not Met None

NIST 800-

53 w/ DHS

Personnel Sanctions

Personnel Sanctions (O) PS-8.1 X X - - - Not Met None

Control Ref.

Control Type

Planned Imp.

Actual Imp.

Test #(s) Methods Tailored Result Notes

4300A Rev

4 PS-8

NIST 800-

53 w/ DHS 4300A Rev

4 RA-1

Risk Assessment Policy and Procedures

Risk Assessment Policy and Procedures

(M)

RA-1.1,

RA-1.2 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 RA-2

Security Categorizatio n

Security Categorizatio n (M) RA-2.1 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 RA-2

(DHS-

3.9.a)

Security Objective

Impact Level

Security Categorizatio n (M)

RA-

3.9.a)

X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 RA-2

(DHS-

3.14.2.e)

Confidentialit y for Privacy

Systems

Security Categorizatio n (M)

RA-

3.14.2.e)

X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 RA-3

Risk Assessment

Risk Assessment

(M) RA-3.1 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 RA-5

Vulnerability Scanning

Vulnerability Scanning (M) RA-5.1, RA-5.2 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

4 RA-5 (1)

Update Tool Capability

Vulnerability Scanning (M) RA-5(1).1 X X - - - Not Met None

NIST 800-

53 w/ DHS 4300A Rev

Update By Frequency /

Prior To New

Vulnerability Scanning (M) RA-5(2).1 X X - - - Not Met None

Control Ref.

Control Type

Planned Imp.

Actual Imp.

Test #(s) Methods Tailored Result Notes

4 RA-5 (2) Scan / When Identified

NIST 800-

53 w/ DHS 4300A Rev

4 RA-5 (5)

Privileged Access

Vulnerability Scanning (M) RA-5(5).1 X X - - - Not Met…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .