2016_06_21_HSFE60-16-R-0004_Attachment_G_DSA_Requirements_Traceability_M....pdf
PDF 590 KB Posted
- Attached to
- National Flood Insurance Program (NFIP) Direct Servicing Agent (DSA) Federal contract opportunity
- Solicitation number
- HSFE60-16-R-0004
About this file
HSFE60-16-R-0004 A00002 Attachment G DSA RTM
View the file
Other files for this federal contract opportunity
Show all 19
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
FOR OFFICIAL USE ONLY
Direct Servicing Agent
DSA
Requirements Traceability Matrix
(RTM)
Prepared for Department of Homeland Security
21 June 2016 i
1. Introduction
The Requirements Traceability Matrix (RTM) relates requirements from requirement source documents to the security certification process. It ensures that all security requirements are identified and investigated. Each row of the matrix identifies a specific requirement and provides the details of how it was tested or analyzed and the results.
The table is arranged to display the system security requirements from the applicable regulation documents, which are listed below:
• NIST 800-53 w/ DHS 4300A Rev 4 - Department of Homeland Security Sensitive Systems Policy Directive 4300A Version 10 (with 800-53 Rev 4)
The columns of the RTM are defined as follows:
Control Ref. Refers to the name (short title) of the source document and the ID or paragraph number of the listed control or requirement.
Security Req./ Control
Short title describing the security control or requirement (and the text of the control/requirement, which may be paraphrased for brevity).
Security Category
Category and class associated with the security control.
Control Type
Auto populated if the requirement is identified with two security control types: common and system-specific; i.e., a part of the requirement is identified as common type and another part of it is system-specific.
• Common. Auto populated if the requirement is designated to one or more information systems.
• Hybrid. Auto populated if the requirement is identified with two security control types:
common and system-specific; i.e., a part of the requirement is identified as common type and another part of it is system-specific.
• System-Specific. Auto populated if the requirement is assigned to a specific information system.
• Inherited. Auto populated if the requirement is inherited from another system.
• Not Specified. Auto populated if the requirement does not require any security control.
Planned Imp.
Auto populated if the requirement is identified with two security control types: common and system-specific; i.e., a part of the requirement is identified as common type and another part of it is system-specific.
• Common. Auto populated if the requirement is designated to one or more information systems.
• Hybrid. Auto populated if the requirement is identified with two security control types:
common and system-specific; i.e., a part of the requirement is identified as common type and another part of it is system-specific.
• System-Specific. Auto populated if the requirement is assigned to a specific information system.
• Inherited. Auto populated if the requirement is inherited from another system.
• Not Specified. Auto populated if the requirement does not require any security control.
Actual Imp. Identification whether the control is in place and how it has been implemented, or differences ii in how the control was implemented compared to what was planned.
• As Planned. Auto populated if Implemented control status is selected and Planned
Implementation column does not read Not Entered.
• Pending Implementation. Auto populated if Planned control status is selected and
Planned Implementation column does not read Not Entered.
• Partially Implemented. Auto populated if Partial control status is selected and
Planned Implementation column does not read Not Entered.
• Not Entered. Auto populated if the Planned Implementation column reads Not
Entered.
• Not Assigned. Auto populated if the Control Type and/or Control Status were not selected.
Test #(s) The ID number of the specific test procedure(s) that is used to validate the requirement or control.
• -. The control is not applicable.
Methods
The evaluation method (or methods) used to assess the requirement.
• I. Interview.
• E. Examine.
• T. Testing.
• -. The control is not applicable.
Tailored
The tailored control that modifies the control set.
• In. The control was tailored in.
• Out. The control was tailored out.
• - . The control was not affected from tailoring.
Overlays
The controls included or excluded from the controls already in the baseline.
• In. The control was added in to the controls in the baseline.
• Out. The control was removed from the controls in the baseline.
• - . The control was not affected from overlay(s).
Result
The summarized result for the test procedures that cover the requirement/control.
• Met - Requirement fully satisfied.
• Not Met - Requirement not satisfied.
• Not Applicable - Requirement not applicable.
Notes Identifies the factor, and the basis for; any tailoring of controls from the NIST 800-53 w/ DHS 4300A Rev 4 baseline or organizational overlay that was used for the system.
2. Requirements Traceability Matrix
Control Ref.
Security Req./
Control
Security Category
Control Type
Planned Imp.
Actual Imp.
Test #(s)
Methods Tailored Result Notes
I E T IN OUT
NIST 800-
53 w/ DHS 4300A Rev
4 AC-1
Access Control
Policy and Procedures
Access Control
Policy and Procedures
(T)
AC-1.1,
AC-1.2 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 AC-1
(DHS-
5.1.1.c)
Sharing of Personal
Passwords
Access Control
Policy and Procedures
(T)
AC-
1(DHS-
5.1.1.c)
X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 AC-2
Account Management
Account Management
(T) AC-2.1 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 AC-2 (1)
Automated System Account
Management
Account Management
(T) AC-2(1).1 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 AC-2 (2)
Removal Of Temporary / Emergency Accounts
Account Management
(T) AC-2(2).1 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 AC-2 (3)
Disable Inactive
Accounts
Account Management
(T) AC-2(3).1 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 AC-2 (4)
Automated Audit Actions
Account Management
AC-2(4).1 X X - - - Not Met None
Control Ref.
Security Req./
Category
Control Type
Planned Imp.
Actual Imp.
Test #(s) Methods Tailored Result Notes
NIST 800-
53 w/ DHS 4300A Rev
4 AC-3
Access Enforcement
Access Enforcement
(T) AC-3.1 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 AC-3
(DHS-
5.1.1.d)
Use of group passwords
Access Enforcement
3(DHS-
5.1.1.d)
X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 AC-4
Information Flow
Enforcement
Information Flow
Enforcement (T)
AC-4.1 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 AC-5
Separation of Duties
Separation of Duties (T) AC-5.1 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 AC-6
Least Privilege
Least Privilege (T) AC-6.1 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 AC-6 (1)
Authorize Access To Security
Functions
Least Privilege (T) AC-6(1).1 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 AC-6 (2)
Non- Privileged Access For Nonsecurity Functions
Least Privilege (T) AC-6(2).1 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 AC-6 (5)
Privileged Accounts
Least Privilege (T) AC-6(5).1 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
Auditing Use Of Privileged
Functions
Least Privilege (T) AC-6(9).1 X X - - - Not Met None
Control Ref.
Control Type
Planned Imp.
Actual Imp.
Test #(s) Methods Tailored Result Notes
4 AC-6 (9)
NIST 800-
53 w/ DHS 4300A Rev
4 AC-6
(10)
Prohibit Non- Privileged
Users From Executing Privileged Functions
Least Privilege (T) AC-
6(10).1 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 AC-7
Unsuccessful Logon
Attempts
Unsuccessful Logon
Attempts (T) AC-7.1 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 AC-8
System Use Notification
System Use Notification
(T)
AC-8.1,
AC-8.2 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 AC-8
(DHS-
4.8.5.d)
Governement Funded Office
Equipment
System Use Notification
8(DHS-
4.8.5.d)
X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 AC-11
Session Lock Session Lock
(T) AC-11.1 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 AC-11
(1)
Pattern- Hiding
Displays
Session Lock
(T) AC-
11(1).1 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 AC-12
Session Termination
Session Termination
(T) AC-12.1 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 AC-14
Permitted Actions without
Identification
Permitted Actions without
Identification
AC-14.1 X X - - - Not Met None
Control Ref.
Control Type
Planned Imp.
Actual Imp.
Test #(s) Methods Tailored Result Notes or Authenticatio n or Authenticatio n (T)
NIST 800-
53 w/ DHS 4300A Rev
4 AC-17
Remote Access
Remote Access (T) AC-17.1 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 AC-17
(1)
Automated Monitoring /
Control
Remote Access (T) AC-
17(1).1 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 AC-17
(2)
Protection Of Confidentialit y / Integrity
Using Encryption
Remote Access (T) AC-
17(2).1 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 AC-17
(3)
Managed Access Control Points
Remote Access (T) AC-
17(3).1 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 AC-17
(4)
Privileged Commands /
Access
Remote Access (T) AC-
17(4).1 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 AC-17
(DHS-
5.4.1.b)
Remote Access
Connection Management
Remote Access (T)
AC-
17(DHS-
5.4.1.b)
X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 AC-17
(DHS-
Remote Access of PII
Remote Access (T)
AC-
17(DHS-
5.4.1.c)
X X - - - Not Met None
Control Ref.
Control Type
Planned Imp.
Actual Imp.
Test #(s) Methods Tailored Result Notes
5.4.1.c)
NIST 800-
53 w/ DHS 4300A Rev
4 AC-18
Wireless Access
Wireless Access (T) AC-18.1 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 AC-18
(1)
Authenticatio n And
Encryption
Wireless Access (T) AC-
18(1).1 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 AC-19
Access Control for
Mobile Devices
Access Control for
Mobile Devices (T)
AC-19.1 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 AC-19
(5)
Full Device / Container-
Based Encryption
Access Control for
Mobile Devices (T)
AC-
19(5).1 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 AC-20
Use of External
Information Systems
Use of External
Information Systems (T)
AC-20.1 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 AC-20
(1)
Limits On Authorized
Use
Use of External
Information Systems (T)
AC-
20(1).1 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 AC-20
(2)
Portable Storage Devices
Use of External
Information Systems (T)
AC-
20(2).1 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 AC-21
Information Sharing
Information Sharing (T) AC-21.1 X X - - - Not Met None
NIST 800- Publicly Publicly AC-22.1 X X - - - Not Met None
Control Ref.
Control Type
Planned Imp.
Actual Imp.
Test #(s) Methods Tailored Result Notes
53 w/ DHS 4300A Rev
4 AC-22
Accessible Content
Accessible Content (T)
NIST 800-
53 w/ DHS 4300A Rev
4 AT-1
Security Awareness and Training Policy and Procedures
Security Awareness and Training Policy and Procedures
(O)
AT-1.1,
AT-1.2 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 AT-2
Security Awareness Training
Security Awareness
Training (O) AT-2.1 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 AT-2 (2)
Insider Threat Security
Awareness Training (O)
- - - - - Met None
NIST 800-
53 w/ DHS 4300A Rev
4 AT-3
Role-Based Security Training
Role-Based Security
Training (O) AT-3.1 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 AT-4
Security Training Records
Security Training
Records (O) AT-4.1 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 AU-1
Audit and Accountabilit y Policy and Procedures
Audit and Accountabilit y Policy and Procedures
(T)
AU-1.1,
AU-1.2 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 AU-2
Audit Events Audit Events
(T) AU-2.1 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 AU-2 (3)
Reviews And Updates
Audit Events
(T) AU-2(3).1 X X - - - Not Met None
Control Ref.
Control Type
Planned Imp.
Actual Imp.
Test #(s) Methods Tailored Result Notes
NIST 800-
53 w/ DHS 4300A Rev
4 AU-3
Content of Audit
Records
Content of Audit
Records (T) AU-3.1 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 AU-3 (1)
Additional Audit
Information
Content of Audit
Records (T) AU-3(1).1 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 AU-4
Audit Storage Capacity
Audit Storage Capacity (T) AU-4.1 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 AU-5
Response to Audit
Processing Failures
Response to Audit
Processing Failures (T)
AU-5.1 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 AU-6
Audit Review, Analysis, and Reporting
Audit Review, Analysis, and Reporting (T)
AU-6.1,
AU-6.2 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 AU-6 (1)
Process Integration
Audit Review, Analysis, and Reporting (T)
AU-6(1).1 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 AU-6 (3)
Correlate Audit
Repositories
Audit Review, Analysis, and Reporting (T)
AU-6(3).1 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 AU-6
(DHS-
5.3.b)
Audit Records for Financial
Systems and
PII
Audit Review, Analysis, and Reporting (T)
AU-
6(DHS-
5.3.b)
X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 AU-6
Mail Server Administratio n
Audit Review, Analysis, and Reporting (T)
AU-
5.4.6.f)
Control Ref.
Control Type
Planned Imp.
Actual Imp.
Test #(s) Methods Tailored Result Notes
(DHS-
5.4.6.f)
NIST 800-
53 w/ DHS 4300A Rev
4 AU-7
Audit Reduction and Report Generation
Audit Reduction and Report Generation
(T)
AU-7.1 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 AU-7 (1)
Automatic Processing
Audit Reduction and Report Generation
(T)
AU-7(1).1 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 AU-8
Time Stamps Time Stamps
(T) AU-8.1 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 AU-8 (1)
Synchronizati on With
Authoritative Time Source
Time Stamps
(T) AU-8(1).1 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 AU-9
Protection of Audit
Information
Protection of Audit
Information (T)
AU-9.1 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 AU-9 (4)
Access By Subset Of Privileged
Users
Protection of Audit
Information (T)
AU-9(4).1 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 AU-11
Audit Record Retention
Audit Record Retention (T) AU-11.1 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 AU-11
(DHS-
5.3.d)
Audit Log Retention
Audit Record Retention (T)
AU-
11(DHS-
5.3.d)
Control Ref.
Control Type
Planned Imp.
Actual Imp.
Test #(s) Methods Tailored Result Notes
NIST 800-
53 w/ DHS 4300A Rev
4 AU-12
Audit Generation
Audit Generation
(T) AU-12.1 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 CA-1
Security Assessment and Authorization Policies and Procedures
Security Assessment and Authorization Policies and Procedures
(M)
CA-1.1,
CA-1.2 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 CA-1
(DHS-
3.9.m)
Use of IACS for Security
Authorization
Security Assessment and Authorization Policies and
(M)
CA-
3.9.m)
X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 CA-1
(DHS-
3.18.c)
Cloud Environment
Usage
Security Assessment and Authorization Policies and
3.18.c)
X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 CA-1
(DHS-
3.18.d)
Usage of FedRAMP for Cloud Systems
Security Assessment and Authorization Policies and
3.18.d)
X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 CA-1
(DHS-
3.18.e)
Usage of Public Cloud
Service Provider
Security Assessment and Authorization Policies and
3.18.e)
Control Ref.
Control Type
Planned Imp.
Actual Imp.
Test #(s) Methods Tailored Result Notes
(M)
NIST 800-
53 w/ DHS 4300A Rev
4 CA-2
Security Assessments
Security Assessments
(M)
CA-2.1,
CA-2.2 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 CA-2 (1)
Independent Assessors
Security Assessments
(M) CA-2(1).1 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 CA-2
(DHS-
3.18.b)
Cloud Systems
Provided to External
Departments
Security Assessments
2(DHS-
3.18.b)
X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 CA-3
System Interconnecti ons
System Interconnecti ons (M) CA-3.1 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 CA-3 (5)
Restrictions On External
System Connections
System Interconnecti ons (M) CA-3(5).1 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 CA-3
(DHS-
5.4.3.b)
Interconnecti on
Establishmen t Procedures
System Interconnecti ons (M)
5.4.3.b)
X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 CA-3
(DHS-
5.4.3.c)
DHS OneNet Interconnecti ons
System
5.4.3.c)
X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
ISA
Reissuance
System
5.4.3.d)
Control Ref.
Control Type
Planned Imp.
Actual Imp.
Test #(s) Methods Tailored Result Notes
4 CA-3
(DHS-
5.4.3.d)
NIST 800-
53 w/ DHS 4300A Rev
4 CA-3
(DHS-
5.4.3.f)
Interconnecti on Security Agreements
System
5.4.3.f)
X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 CA-3
(DHS-
5.4.3.m)
Interconnecti on Security Agreements
System
5.4.3.m)
X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 CA-3
(DHS-
5.4.3.n)
DHS
Interconnecti ons
System
5.4.3.n)
X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 CA-5
Plan of Action and Milestones
Plan of Action and Milestones
(M)
CA-5.1 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 CA-5
(DHS-
2.2.8.d)
DHS
POA&M
Requirements
Plan of Action and Milestones
5(DHS-
2.2.8.d)
X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 CA-6
Security Authorization
Security Authorization
(M) CA-6.1 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
DHS Security Authorization
Security Authorization
3.9.h)
Control Ref.
Control Type
Planned Imp.
Actual Imp.
Test #(s) Methods Tailored Result Notes
4 CA-6
(DHS-
3.9.h)
NIST 800-
53 w/ DHS 4300A Rev
4 CA-7
Continuous Monitoring
Continuous Monitoring
(M) CA-7.1 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 CA-7 (1)
Independent Assessment
Continuous Monitoring
(M) CA-7(1).1 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 CA-7
(DHS-
4.6.3.a)
AO
Notification on Disabling
Security Features
Continuous Monitoring
7(DHS-
4.6.3.a)
X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 CA-9
Internal System
Connections
Internal System
Connections (M)
CA-9.1 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 CM-1
Configuration Management Policy and Procedures
Configuration Management Policy and Procedures
(O)
CM-1.1,
CM-1.2 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 CM-2
Baseline Configuration
Baseline Configuration
(O) CM-2.1 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 CM-2 (1)
Reviews And Updates
Baseline Configuration
(O) CM-2(1).1 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 CM-2 (3)
Retention Of Previous
Configuration s
Baseline Configuration
(O) CM-2(3).1 X X - - - Not Met None
Control Ref.
Control Type
Planned Imp.
Actual Imp.
Test #(s) Methods Tailored Result Notes
NIST 800-
53 w/ DHS 4300A Rev
4 CM-2 (7)
Configure Systems, Components, Or Devices For High- Risk Areas
Baseline Configuration
(O) CM-2(7).1 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 CM-2
(DHS-
3.9.b)
FIPS 199 and
FIPS 200
Usage
Baseline Configuration
CM-
3.9.b)
X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 CM-2
(DHS-
4.12.b)
Network Printers and Facsimile Machines
Baseline Configuration
4.12.b)
X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 CM-3
Configuration Change Control
Configuration Change
Control (O) CM-3.1 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 CM-3 (2)
Test / Validate / Document Changes
Configuration Change
Control (O) CM-3(2).1 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 CM-3
(DHS-
2.1.8.g)
Timely Response to
ICCB
Configuration Change
Control (O)
2.1.8.g)
X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 CM-3
(DHS-
5.4.3.l)
DHS Change Control Boards
(CCB)
Configuration Change
Control (O)
5.4.3.l)
Control Ref.
Control Type
Planned Imp.
Actual Imp.
Test #(s) Methods Tailored Result Notes
NIST 800-
53 w/ DHS 4300A Rev
4 CM-4
Security Impact
Analysis
Security Impact
Analysis (O) CM-4.1 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 CM-5
Access Restrictions for Change
Access Restrictions for Change
(O)
CM-5.1 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 CM-6
Configuration Settings
Configuration Settings (O) CM-6.1 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 CM-6
(DHS-
3.7.e)
USGCB
Requirements
Configuration Settings (O)
CM-
6(DHS-
3.7.e)
X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 CM-6
(DHS-
3.7.f)
USGCB
Compliance
Configuration Settings (O)
CM-
6(DHS-
3.7.f)
X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 CM-6
(DHS-
3.7.g)
Hardening and
Configuration Guidance
Configuration Settings (O)
CM-
6(DHS-
3.7.g)
X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 CM-6
(DHS-
4.5.2.b)
FAX Server Configuration
Configuration Settings (O)
CM-
6(DHS-
4.5.2.b)
X X - - - Not Met None
NIST 800-
53 w/ DHS
Hardening and
Configuration Settings (O) CM-
6(DHS- X X - - - Not Met None
Control Ref.
Control Type
Planned Imp.
Actual Imp.
Test #(s) Methods Tailored Result Notes
4300A Rev
4 CM-6
(DHS-
4.8.4.a)
Configuration Guidance
4.8.4.a)
NIST 800-
53 w/ DHS 4300A Rev
4 CM-6
(DHS-
4.12.f)
Network Printers, Copiers, and Facsimile
Administratio n
Configuration Settings (O)
CM-
6(DHS-
4.12.f)
X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 CM-6
(DHS-
4.12.j)
Multifunction Device
Configuration
Configuration Settings (O)
CM-
6(DHS-
4.12.j)
X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 CM-6
(DHS-
5.4.5.d)
Use of Telnet Configuration Settings (O)
CM-
6(DHS-
5.4.5.d)
X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 CM-6
(DHS-
5.4.5.e)
Use of File Transfer Protocol
(FTP)
Services
Configuration Settings (O)
CM-
6(DHS-
5.4.5.e)
X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 CM-6
(DHS-
5.4.6.a)
Email Operating
System Configuration
Guidance
Configuration Settings (O)
CM-
6(DHS-
5.4.6.a)
X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 CM-6
Email Server Configuration
Guidance
Configuration Settings (O)
CM-
6(DHS-
5.4.6.b)
Control Ref.
Control Type
Planned Imp.
Actual Imp.
Test #(s) Methods Tailored Result Notes
(DHS-
5.4.6.b)
NIST 800-
53 w/ DHS 4300A Rev
4 CM-6
(DHS-
5.4.6.c)
Email Content Filtering
Configuration Settings (O)
CM-
6(DHS-
5.4.6.c)
X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 CM-6
(DHS-
5.4.6.e)
Email Client Configuration
Configuration Settings (O)
CM-
6(DHS-
5.4.6.e)
X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 CM-7
Least Functionality
Least Functionality
(O) CM-7.1 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 CM-7 (1)
Periodic Review
Least Functionality
(O) CM-7(1).1 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 CM-7 (2)
Prevent Program
Execution
Least Functionality
(O) CM-7(2).1 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 CM-7 (4)
Unauthorized Software /
Blacklisting
Least Functionality
(O) CM-7(4).1 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 CM-7
(DHS-
4.8.6.a)
Wireless for Peripheral Equipment
Least Functionality
4.8.6.a)
X X - - - Not Met None
NIST 800-
53 w/ DHS
Network Printers, Least Functionality CM-
7(DHS- X X - - - Not Met None
Control Ref.
Control Type
Planned Imp.
Actual Imp.
Test #(s) Methods Tailored Result Notes
4300A Rev
4 CM-7
(DHS-
4.12.c)
Copiers, and Facsimile
Configuration
(O) 4.12.c)
NIST 800-
53 w/ DHS 4300A Rev
4 CM-7
(DHS-
5.4.5.f)
Remote Desktop
Connections
Least Functionality
5.4.5.f)
X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 CM-8
Information System
Component Inventory
Information System
Component Inventory (O)
CM-8.1 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 CM-8 (1)
Updates During
Installations / Removals
Information System
Component Inventory (O)
CM-8(1).1 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 CM-8 (3)
Automated Unauthorized Component Detection
Information System
Component Inventory (O)
CM-8(3).1 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 CM-8 (5)
No Duplicate Accounting
Of Components
Information System
Component Inventory (O)
CM-8(5).1 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 CM-9
Configuration Management
Plan
Configuration Management
Plan (O) CM-9.1 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 CM-10
Software Usage
Restrictions
SW Usage Restrictions
(O) CM-10.1 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 CM-11
User-Installed Software
User-Installed SW (O) CM-11.1 X X - - - Not Met None
Control Ref.
Control Type
Planned Imp.
Actual Imp.
Test #(s) Methods Tailored Result Notes
NIST 800-
53 w/ DHS 4300A Rev
4 CP-1
Contingency Planning
Policy and Procedures
Contingency Planning
Policy and Procedures
(O)
CP-1.1,
CP-1.2 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 CP-1
(DHS-
3.5.1.a)
Continuity of Operations Planning
Contingency Planning
Policy and
CP-
3.5.1.a)
X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 CP-1
(DHS-
3.5.2.d)
DHS
Contingency
Guidance
Contingency Planning
Policy and
3.5.2.d)
X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 CP-1
(DHS-
3.15.f)
DHS
Contingency Plan for CFO
Contingency Planning
Policy and
3.15.f)
X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 CP-2
Contingency Plan
Contingency Plan (O) CP-2.1, CP-2.2 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 CP-2 (1)
Coordinate With Related
Plans
Contingency Plan (O) CP-2(1).1 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 CP-2 (3)
Resume Essential
Missions / Business Functions
Contingency Plan (O) CP-2(3).1 X X - - - Not Met None
NIST 800-
53 w/ DHS
Identify Critical
Contingency Plan (O) CP-2(8).1 X X - - - Not Met None
Control Ref.
Control Type
Planned Imp.
Actual Imp.
Test #(s) Methods Tailored Result Notes
4300A Rev
4 CP-2 (8)
Assets
NIST 800-
53 w/ DHS 4300A Rev
4 CP-2
(DHS-
3.5.2.e)
DHS
Contingency
Plan
Contingency Plan (O)
CP-
2(DHS-
3.5.2.e)
X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 CP-3
Contingency Training
Contingency Training (O) CP-3.1 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 CP-4
Contingency Plan Testing
Contingency Plan Testing
(O) CP-4.1 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 CP-4 (1)
Coordinate With Related
Plans
Contingency Plan Testing
(O) CP-4(1).1 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 CP-4
(DHS-
3.5.2.f)
DHS
Contingency Plan Testing
Contingency Plan Testing
4(DHS-
3.5.2.f)
X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 CP-6
Alternate Storage Site
Alternate Storage Site
(O) CP-6.1 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 CP-6 (1)
Separation From Primary
Site
Alternate Storage Site
(O) CP-6(1).1 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 CP-6 (3)
Accessibility Alternate
Storage Site
CP-6(3).1 X X - - - Not Met None
Control Ref.
Control Type
Planned Imp.
Actual Imp.
Test #(s) Methods Tailored Result Notes
NIST 800-
53 w/ DHS 4300A Rev
4 CP-7
Alternate Processing
Site
Alternate Processing
Site (O) CP-7.1 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 CP-7 (1)
Separation From Primary
Site
Alternate Processing
Site (O) CP-7(1).1 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 CP-7 (2)
Accessibility Alternate
Processing Site (O)
CP-7(2).1 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 CP-7 (3)
Priority Of Service
Alternate Processing
Site (O) CP-7(3).1 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 CP-8
Telecommuni cations
Services
Telecommuni cations
Services (O) CP-8.1 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 CP-8 (1)
Priority Of Service
Provisions
Telecommuni cations
Services (O) CP-8(1).1 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 CP-8 (2)
Single Points Of Failure
Telecommuni cations
Services (O) CP-8(2).1 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 CP-9
Information System Backup
Information System
Backup (O)
CP-9.1,
CP-9.2 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 CP-9 (1)
Testing For Reliability /
Integrity
Information System
Backup (O) CP-9(1).1 X X - - - Not Met None
NIST 800-
53 w/ DHS
Information System
Information System CP-10.1 X X - - - Not Met None
Control Ref.
Control Type
Planned Imp.
Actual Imp.
Test #(s) Methods Tailored Result Notes
4300A Rev
4 CP-10
Recovery and Reconstitutio n
Recovery and Reconstitutio n (O)
NIST 800-
53 w/ DHS 4300A Rev
4 CP-10 (2)
Transaction Recovery
Information System
Recovery and Reconstitutio n (O)
CP-
10(2).1 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 CP-10
(DHS-
5.7.e)
Transaction Based
Systems
Information System
Recovery and Reconstitutio n (O)
10(DHS-
5.7.e)
X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 IA-1
Identification and
Authenticatio n Policy and Procedures
Identification and
Authenticatio n Policy and Procedures
(T)
IA-1.1,
IA-1.2 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 IA-1
(DHS-
1.6.d)
PIV
Credentials
Identification and
Authenticatio n Policy and
IA-
1.6.d)
X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 IA-1
(DHS-
3.14.7.a)
Online Transactions
Identification and
Authenticatio n Policy and
3.14.7.a)
X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 IA-1
(DHS-
3.14.7.c)
E- Authenticatio n
Identification and
Authenticatio n Policy and
3.14.7.c)
Control Ref.
Control Type
Planned Imp.
Actual Imp.
Test #(s) Methods Tailored Result Notes
NIST 800-
53 w/ DHS 4300A Rev
4 IA-1
(DHS-
3.14.7.f)
PIV
Credentials
Identification and
Authenticatio n Policy and
3.14.7.f)
X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 IA-1
(DHS-
5.4.6.j)
DHS Email Naming
Convention
Identification and
Authenticatio n Policy and
5.4.6.j)
X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 IA-2
Identification and
Authenticatio n
(Organization al Users)
Identification and
Authenticatio n
(Organization al Users) (T)
IA-2.1 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 IA-2 (1)
Network Access To Privileged Accounts
Identification and
Authenticatio n
(Organization al Users) (T)
IA-2(1).1 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 IA-2 (2)
Network Access To
Non- Privileged Accounts
Identification and
Authenticatio n
(Organization al Users) (T)
IA-2(2).1 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 IA-2 (3)
Local Access To Privileged
Accounts
Identification and
Authenticatio n
(Organization al Users) (T)
IA-2(3).1 X X - - - Not Met None
NIST 800-
53 w/ DHS
Network Access To
Identification and IA-2(8).1 X X - - - Not Met None
Control Ref.
Control Type
Planned Imp.
Actual Imp.
Test #(s) Methods Tailored Result Notes
4300A Rev
4 IA-2 (8)
Privileged Accounts -
Replay Resistant
Authenticatio n
(Organization al Users) (T)
NIST 800-
53 w/ DHS 4300A Rev
4 IA-2 (11)
Remote Access - Separate Device
Identification and
Authenticatio n
(Organization al Users) (T)
IA-2(11).1 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 IA-2 (12)
Acceptance Of PIV
Credentials
Identification and
Authenticatio n
(Organization al Users) (T)
IA-2(12).1 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 IA-2
(DHS-
5.1.d)
Usage of Identification or Authenticatio n Materials
Identification and
Authenticatio n
(Organization al Users) (T)
5.1.d)
X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 IA-3
Device Identification and Authenticatio n
Device Identification and Authenticatio n (T)
IA-3.1 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 IA-4
Identifier Management
Identifier Management
(T) IA-4.1 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 IA-5
Authenticator Management
Authenticator Management
(T) IA-5.1 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
Password- Based
Authenticatio
Authenticator Management
IA-5(1).1 X X - - - Not Met None
Control Ref.
Control Type
Planned Imp.
Actual Imp.
Test #(s) Methods Tailored Result Notes
4 IA-5 (1) n
NIST 800-
53 w/ DHS 4300A Rev
4 IA-5 (2)
PKI-Based Authenticatio n
Authenticator Management
(T) IA-5(2).1 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 IA-5 (3)
In-Person Or Trusted
Third-Party Registration
Authenticator Management
(T) IA-5(3).1 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 IA-5 (11)
Hardware Token-Based Authenticatio n
Authenticator Management
(T) IA-5(11).1 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 IA-5
(DHS-
5.1.e)
User Authenticatio n Materials
Authenticator Management
5.1.e)
X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 IA-6
Authenticator Feedback
Authenticator Feedback (T) IA-6.1 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 IA-7
Cryptographi c Module
Authenticatio n
Cryptographi c Module
Authenticatio n (T)
IA-7.1 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 IA-8
Identification and
Authenticatio n (Non-
Organizationa l Users)
Identification and
Authenticatio n (Non-
Organizationa l Users) (T)
IA-8.1 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 IA-8 (1)
Acceptance Of PIV
Credentials From Other Agencies
Identification and
Authenticatio n (Non-
Organizationa
IA-8(1).1 X X - - - Not Met None
Control Ref.
Control Type
Planned Imp.
Actual Imp.
Test #(s) Methods Tailored Result Notes l Users) (T)
NIST 800-
53 w/ DHS 4300A Rev
4 IA-8 (2)
Acceptance Of Third-
Party Credentials
Identification and
Authenticatio n (Non-
Organizationa l Users) (T)
IA-8(2).1 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 IA-8 (3)
Use Of
FICAM-
Approved Products
Identification and
Authenticatio n (Non-
Organizationa l Users) (T)
IA-8(3).1 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 IA-8 (4)
Use Of Ficam-Issued
Profiles
Identification and
Authenticatio n (Non-
Organizationa l Users) (T)
IA-8(4).1 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 IA-8
(DHS-
1.5.4.c)
Foreign Nationals
Identification and
Authenticatio n (Non-
Organizationa l Users) (T)
8(DHS-
1.5.4.c)
X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 IR-1
Incident Response Policy and Procedures
Incident Response Policy and Procedures
(O)
IR-1.1,
IR-1.2 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 IR-2
Incident Response Training
Incident Response
Training (O) IR-2.1 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 IR-3
Incident Response Testing
Incident Response
Testing (O) IR-3.1 X X - - - Not Met None
Control Ref.
Control Type
Planned Imp.
Actual Imp.
Test #(s) Methods Tailored Result Notes
NIST 800-
53 w/ DHS 4300A Rev
4 IR-3 (2)
Coordination With Related
Plans
Incident Response
Testing (O) IR-3(2).1 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 IR-4
Incident Handling
Incident Handling (O) IR-4.1 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 IR-4 (1)
Automated Incident Handling Processes
Incident Handling (O) IR-4(1).1 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 IR-5
Incident Monitoring
Incident Monitoring
(O) IR-5.1 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 IR-6
Incident Reporting
Incident Reporting (O) IR-6.1 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 IR-6 (1)
Automated Reporting
Incident Reporting (O) IR-6(1).1 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 IR-7
Incident Response Assistance
Incident Response Assistance
(O)
IR-7.1 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 IR-7 (1)
Automation Support For Availability
Of Information /
Support
Incident Response Assistance
(O)
IR-7(1).1 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 IR-8
Incident Response
Plan
Incident Response Plan (O)
IR-8.1,
IR-8.2 X X - - - Not Met None
Control Ref.
Control Type
Planned Imp.
Actual Imp.
Test #(s) Methods Tailored Result Notes
NIST 800-
53 w/ DHS 4300A Rev
4 MA-1
System Maintenance Policy and Procedures
System Maintenance Policy and Procedures
(O)
MA-1.1,
MA-1.2 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 MA-2
Controlled Maintenance
Controlled Maintenance
(O) MA-2.1 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 MA-3
Maintenance Tools
Maintenance Tools (O) MA-3.1 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 MA-3 (1)
Inspect Tools Maintenance Tools (O) MA-
3(1).1 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 MA-3 (2)
Inspect Media
Maintenance Tools (O) MA-
3(2).1 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 MA-4
Nonlocal Maintenance
Nonlocal Maintenance
(O) MA-4.1 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 MA-4 (2)
Document Nonlocal
Maintenance
Nonlocal Maintenance
(O)
MA-
4(2).1 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 MA-4 (6)
Cryptographi c Protection
Nonlocal Maintenance
(O)
MA-
4(6).1 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 MA-4
(DHS-
Remote Maintenance
Paths
Nonlocal Maintenance
MA-
5.4.4.c)
Control Ref.
Control Type
Planned Imp.
Actual Imp.
Test #(s) Methods Tailored Result Notes
5.4.4.c)
NIST 800-
53 w/ DHS 4300A Rev
4 MA-5
Maintenance Personnel
Maintenance Personnel (O) MA-5.1 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 MA-6
Timely Maintenance
Timely Maintenance
(O) MA-6.1 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 MP-1
Media Protection Policy and Procedures
Media Protection Policy and Procedures
(O)
MP-1.1,
MP-1.2 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 MP-1
(DHS-
3.14.5.b)
Removal of
PII
Media Protection Policy and
MP-
3.14.5.b)
X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 MP-1
(DHS-
4.3.1.g)
Protection of Printed Output
Media Protection Policy and
4.3.1.g)
X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 MP-1
(DHS-
5.4.1.d)
PII Remote Access
Media Protection Policy and
5.4.1.d)
X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 MP-1
(DHS-
5.6.c)
Media Scanning
Media Protection Policy and
5.6.c)
Control Ref.
Control Type
Planned Imp.
Actual Imp.
Test #(s) Methods Tailored Result Notes
NIST 800-
53 w/ DHS 4300A Rev
4 MP-2
Media Access Media Access
(O) MP-2.1 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 MP-3
Media Marking
Media Marking (O) MP-3.1 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 MP-4
Media Storage
Media Storage (O) MP-4.1 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 MP-4
(DHS-
3.14.5.f)
Rentention of Computer Readable Extracts (CREs)
Media Protection Policy and
3.14.5.f)
X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 MP-5
Media Transport
Media Transport (O) MP-5.1 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 MP-5 (4)
Cryptographi c Protection
Media Transport (O) MP-5(4).1 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 MP-5
(DHS-
4.11.f)
Backup Media
Shipping
Media Transport (O)
MP-
5(DHS-
4.11.f)
X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 MP-6
Media Sanitization
Media Sanitization
(O) MP-6.1 X X - - - Not Met None
NIST 800-
53 w/ DHS Media Use Media Use
(O) MP-7.1 X X - - - Not Met None
Control Ref.
Control Type
Planned Imp.
Actual Imp.
Test #(s) Methods Tailored Result Notes
4300A Rev
4 MP-7
NIST 800-
53 w/ DHS 4300A Rev
4 MP-7 (1)
Prohibit Use Without Owner
Media Use
(O) MP-7(1).1 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 MP-7
(DHS-
4.3.1.d)
USB Drive encryption
Media Use (O)
MP-
7(DHS-
4.3.1.d)
X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 MP-7
(DHS-
4.3.1.e)
DHS owned Removable
Media
Media Use (O)
MP-
7(DHS-
4.3.1.e)
X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 MP-7
(DHS-
4.3.1.f)
Protection of Sensitive Paper and Electronic Outputs
Media Use (O)
MP-
7(DHS-
4.3.1.f)
X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 PE-1
Physical and Environment al Protection Policy and Procedures
Physical and Environment al Protection Policy and Procedures
(O)
PE-1.1,
PE-1.2 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 PE-1
(DHS-
3.3.c)
Sensitive Information at Contractor
Sites
Physical and Environment al Protection Policy and
PE-
3.3.c)
X X - - - Not Met None
NIST 800-
53 w/ DHS
Voice Over Data
Physical and Environment PE-
1(DHS- X X - - - Not Met None
Control Ref.
Control Type
Planned Imp.
Actual Imp.
Test #(s) Methods Tailored Result Notes
4300A Rev
4 PE-1
(DHS-
4.5.4.b)
Networks al Protection Policy and Procedures
(O)
4.5.4.b)
NIST 800-
53 w/ DHS 4300A Rev
4 PE-1
(DHS-
4.6.2.3.b)
Video, IR, and RF Signals
Physical and Environment al Protection Policy and
4.6.2.3.b)
X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 PE-1
(DHS-
4.12.i)
Network Printers, Copiers, and Facsimile Locations
Physical and Environment al Protection Policy and
4.12.i)
X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 PE-2
Physical Access
Authorization s
Physical Access
Authorization s (O)
PE-2.1,
PE-2.2 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 PE-3
Physical Access Control
Physical Access
Control (O)
PE-3.1,
PE-3.2 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 PE-4
Access Control for
Transmission Medium
Access Control for
Transmission Medium (O)
PE-4.1 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 PE-5
Access Control for
Output Devices
Access Control for
Output Devices (O)
PE-5.1 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 PE-6
Monitoring Physical Access
Monitoring Physical
Access (O) PE-6.1 X X - - - Not Met None
NIST 800-
53 w/ DHS
Intrusion Alarms /
Physical PE-6(1).1 X X - - - Not Met None
Control Ref.
Control Type
Planned Imp.
Actual Imp.
Test #(s) Methods Tailored Result Notes
4300A Rev
4 PE-6 (1)
Surveillance Equipment
Access (O)
NIST 800-
53 w/ DHS 4300A Rev
4 PE-8
Visitor Access Records
Visitor Access
Records (O) PE-8.1 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 PE-9
Power Equipment and Cabling
Power Equipment and Cabling
(O)
PE-9.1 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 PE-10
Emergency Shutoff
Emergency Shutoff (O) PE-10.1 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 PE-11
Emergency Power
Emergency Power (O) PE-11.1 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 PE-12
Emergency Lighting
Emergency Lighting (O) PE-12.1 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 PE-13
Fire Protection
Fire Protection
(O) PE-13.1 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 PE-13 (3)
Automatic Fire
Suppression
Fire Protection
(O)
PE-
13(3).1 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 PE-14
Temperature and Humidity
Controls
Temperature and Humidity Controls (O)
PE-14.1 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 PE-15
Water Damage
Protection
Water Damage
Protection
PE-15.1 X X - - - Not Met None
Control Ref.
Control Type
Planned Imp.
Actual Imp.
Test #(s) Methods Tailored Result Notes
NIST 800-
53 w/ DHS 4300A Rev
4 PE-16
Delivery and Removal
Delivery and Removal (O) PE-16.1 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 PE-17
Alternate Work Site
Alternate Work Site
(O) PE-17.1 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 PL-1
Security Planning
Policy and Procedures
Security Planning
Policy and Procedures
(M)
PL-1.1,
PL-1.2 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 PL-1
(DHS-
3.14.5.c)
Sensitive PII
Security Planning
Policy and
PL-
3.14.5.c)
X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 PL-1
(DHS-
3.14.7.d)
E- Authenticatio n
Security Planning
Policy and
PL-
3.14.7.d)
X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 PL-2
System Security Plan
System Security Plan
(M) PL-2.1 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 PL-2 (3)
Plan / Coordinate With Other
Organizationa l Entities
System Security Plan
(M) PL-2(3).1 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 PL-4
Rules of Behavior
Rules of Behavior (M) PL-4.1 X X - - - Not Met None
Control Ref.
Control Type
Planned Imp.
Actual Imp.
Test #(s) Methods Tailored Result Notes
NIST 800-
53 w/ DHS 4300A Rev
4 PL-4 (1)
Social Media And
Networking Restrictions
Rules of Behavior (M) PL-4(1).1 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 PL-4
(DHS-
4.1.2.a)
DHS Rules of Behavior
Rules of Behavior (M)
PL-
4(DHS-
4.1.2.a)
X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 PL-4
(DHS-
4.8.2.a)
Laptop Encryption
Rules of Behavior (M)
PL-
4(DHS-
4.8.2.a)
X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 PL-4
(DHS-
4.8.2.b)
Laptop Power Down
Rules of Behavior (M)
PL-
4(DHS-
4.8.2.b)
X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 PL-4
(DHS-
4.8.3.a)
Personally Owned
Equipment
Rules of Behavior (M)
PL-
4(DHS-
4.8.3.a)
X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 PL-4
(DHS-
4.8.5.e)
Signed Rules of Behavior
Rules of Behavior (M)
PL-
4(DHS-
4.8.5.e)
X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 PL-8
Information Security
Architecture
Information Security
Architecture
PL-8.1 X X - - - Not Met None
Control Ref.
Control Type
Planned Imp.
Actual Imp.
Test #(s) Methods Tailored Result Notes
NIST 800-
53 w/ DHS 4300A Rev
4 PM-1
Information Security
Program Plan
Information Security
Program Plan (M)
PM-1.1 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 PM-2
Senior Information
Security Officer
Senior Information
Security Officer (M)
PM-2.1 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 PM-3
Information Security
Resources
Information Security
Resources (M)
PM-3.1 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 PM-4
Plan of Action and Milestones
Process
Plan of Action and Milestones Process (M)
PM-4.1 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 PM-5
Information System
Inventory
Information System
Inventory (M)
PM-5.1 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 PM-6
Information Security
Measures of Performance
Information Security
Measures of Performance
(M)
PM-6.1 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 PM-7
Enterprise Architecture
Enterprise Architecture
(M) PM-7.1 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 PM-8
Critical Infrastructure
Plan
Critical Infrastructure
Plan (M) PM-8.1 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 PM-9
Risk Management
Strategy
Risk Management Strategy (M)
PM-9.1 X X - - - Not Met None
NIST 800- Security Security PM-10.1 X X - - - Not Met None
Control Ref.
Control Type
Planned Imp.
Actual Imp.
Test #(s) Methods Tailored Result Notes
53 w/ DHS 4300A Rev
4 PM-10
Authorization Process
Authorization Process (M)
NIST 800-
53 w/ DHS 4300A Rev
4 PM-11
Mission/Busi ness Process Definition
Mission/Busi ness Process Definition
(M)
PM-11.1 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 PM-12
Insider Threat Program
Insider Threat Program (M) PM-12.1 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 PM-13
Information Security
Workforce
Information Security
Workforce (M)
PM-13.1 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 PM-14
Testing, Training, and Monitoring
Testing, Training, and Monitoring
(M)
PM-14.1 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 PM-15
Contacts with Security
Groups and Associations
Contacts with Security and Associations
(M)
PM-15.1 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 PM-16
Threat Awareness Program
Threat Awareness
Program (M) PM-16.1 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 PRIV-
AP-1
Authority to Collect
Authority to Collect () AP-1.1 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 PRIV-
AP-2
Purpose Specification
Purpose Specification
AP-2.1 X X - - - Not Met None
NIST 800- Governance Governance AR-1.1 X X - - - Not Met None
Control Ref.
Control Type
Planned Imp.
Actual Imp.
Test #(s) Methods Tailored Result Notes
53 w/ DHS 4300A Rev
4 PRIV-
AR-1
and Privacy Program and Privacy Program ()
NIST 800-
53 w/ DHS 4300A Rev
4 PRIV-
AR-2
Privacy Impact and
Risk Assessment
Privacy Impact and
Risk Assessment ()
AR-2.1 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 PRIV-
AR-3
Privacy Requirements for Contractors and Service Providers
Privacy Requirements for Contractors and Service Providers ()
AR-3.1 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 PRIV-
AR-4
Privacy Monitoring and Auditing
Privacy Monitoring and Auditing
AR-4.1 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 PRIV-
AR-5
Privacy Awareness and Training
Privacy Awareness and Training
AR-5.1 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 PRIV-
AR-6
Privacy Reporting
Privacy Reporting () AR-6.1 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 PRIV-
AR-7
Privacy- Enhanced
System Design and
Development
Privacy- Enhanced
System Design and
Development
AR-7.1 X X - - - Not Met None
NIST 800-
53 w/ DHS
Accounting of
Accounting of AR-8.1 X X - - - Not Met None
Control Ref.
Control Type
Planned Imp.
Actual Imp.
Test #(s) Methods Tailored Result Notes
4300A Rev
4 PRIV-
AR-8
Disclosures Disclosures ()
NIST 800-
53 w/ DHS 4300A Rev
4 PRIV-DI-
Data Quality Data Quality () DI-1.1 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 PRIV-DI-
Data Integrity and Data Integrity Board
Data Integrity and Data Integrity Board ()
DI-2.1 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 PRIV-
DM-1
Minimization of Personally Identifiable Information
Minimization of Personally Identifiable Information
DM-1.1 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 PRIV-
DM-2
Data Retention and
Disposal
Data Retention and
Disposal () DM-2.1 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 PRIV-
DM-3
Minimization of PII Used in
Testing, Training, and
Research
Minimization of PII Used in
Testing, Training, and Research ()
DM-3.1 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 PRIV-IP-
Consent Consent () IP-1.1 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 PRIV-IP-
Individual Access
Individual Access () IP-2.1 X X - - - Not Met None
Control Ref.
Control Type
Planned Imp.
Actual Imp.
Test #(s) Methods Tailored Result Notes
NIST 800-
53 w/ DHS 4300A Rev
4 PRIV-IP-
Redress Redress () IP-3.1 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 PRIV-IP-
Complaint Management
Complaint Management
IP-4.1 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 PRIV-
SE-1
Inventory of Personally Identifiable Information
Inventory of Personally Identifiable Information
SE-1.1 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 PRIV-
SE-2
Privacy Incident
Response
Privacy Incident
Response () SE-2.1 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 PRIV-
TR-1
Privacy Notice
Privacy Notice () TR-1.1 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 PRIV-
TR-2
System of Records
Notices and Privacy Act Statements
System of Records
Notices and Privacy Act
Statements ()
TR-2.1 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 PRIV-
TR-3
Disseminatio n of Privacy
Program Information
Disseminatio n of Privacy
Program Information
TR-3.1 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
Internal Use Internal Use () UL-1.1 X X - - - Not Met None
Control Ref.
Control Type
Planned Imp.
Actual Imp.
Test #(s) Methods Tailored Result Notes
4 PRIV-
UL-1
NIST 800-
53 w/ DHS 4300A Rev
4 PRIV-
UL-2
Information Sharing with Third Parties
Information Sharing with Third Parties
UL-2.1 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 PS-1
Personnel Security
Policy and Procedures
Personnel Security
Policy and Procedures
(O)
PS-1.1,
PS-1.2 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 PS-2
Position Risk Designation
Position Risk Designation
(O) PS-2.1 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 PS-3
Personnel Screening
Personnel Screening (O) PS-3.1 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 PS-4
Personnel Termination
Personnel Termination
(O) PS-4.1 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 PS-5
Personnel Transfer
Personnel Transfer (O) PS-5.1 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 PS-6
Access Agreements
Access Agreements
(O) PS-6.1 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 PS-7
Third-Party Personnel Security
Third-Party Personnel
Security (O) PS-7.1 X X - - - Not Met None
NIST 800-
53 w/ DHS
Personnel Sanctions
Personnel Sanctions (O) PS-8.1 X X - - - Not Met None
Control Ref.
Control Type
Planned Imp.
Actual Imp.
Test #(s) Methods Tailored Result Notes
4300A Rev
4 PS-8
NIST 800-
53 w/ DHS 4300A Rev
4 RA-1
Risk Assessment Policy and Procedures
Risk Assessment Policy and Procedures
(M)
RA-1.1,
RA-1.2 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 RA-2
Security Categorizatio n
Security Categorizatio n (M) RA-2.1 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 RA-2
(DHS-
3.9.a)
Security Objective
Impact Level
Security Categorizatio n (M)
RA-
3.9.a)
X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 RA-2
(DHS-
3.14.2.e)
Confidentialit y for Privacy
Systems
Security Categorizatio n (M)
RA-
3.14.2.e)
X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 RA-3
Risk Assessment
Risk Assessment
(M) RA-3.1 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 RA-5
Vulnerability Scanning
Vulnerability Scanning (M) RA-5.1, RA-5.2 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
4 RA-5 (1)
Update Tool Capability
Vulnerability Scanning (M) RA-5(1).1 X X - - - Not Met None
NIST 800-
53 w/ DHS 4300A Rev
Update By Frequency /
Prior To New
Vulnerability Scanning (M) RA-5(2).1 X X - - - Not Met None
Control Ref.
Control Type
Planned Imp.
Actual Imp.
Test #(s) Methods Tailored Result Notes
4 RA-5 (2) Scan / When Identified
NIST 800-
53 w/ DHS 4300A Rev
4 RA-5 (5)
Privileged Access
Vulnerability Scanning (M) RA-5(5).1 X X - - - Not Met…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .