Appendix 5a - USTRANSCOM NIST 800-171 POAM Amend 0002.xlsx

XLSX spreadsheet 203 KB Posted

Attached to
Domestic Charter Airlift Services Request for Proposal Federal contract opportunity
Solicitation number
HTC71118RCC01
Issued by
Department of Defense United States Transportation Command

About this file

This file provides details on a federal contract opportunity for domestic charter airlift services. The solicitation number is HTC71118RCC01 and seeks proposals for domestic passenger and/or cargo airlift services in support of the Department of Defense United States Transportation Command. Offerors are asked to submit proposals for Domestic Charter Airlift Services in response to Request for Proposal number HTC71118RCC01. The opportunity is for indefinite-delivery, indefinite-quantity airlift services within the continental United States to support Transportation Command missions.

View the file

Other files for this federal contract opportunity

Other files attached to Domestic Charter Airlift Services Request for Proposal, newest first.
File Type Posted
HTC71118RCC010004_SF30.pdf PDF
1 - RFP - HTC711-18-R-CC01 _0004.pdf PDF
2-Atch 1 - PWS - Dom 121 July 2022 Amend 0003.pdf PDF
1 - HTC711-18-R-CC01 Amend 0003.pdf PDF
3-Atch 2 - 1996-0460_Rev 42 Amend 0002.pdf PDF
Atch 2a Kerosene Waiver Amend 0001.pdf PDF
Atch 2-WD 1993-0200-40_1996-0460-29 Amend 0001.pdf PDF
Appendix 7 - Post Mission Report Amend 0001.xlsx XLSX spreadsheet
Atch 4 - Small Business Subcontracting Template Amend 0001.doc DOC document
1 - HTC711-18-R-CC01 Amend 0001.pdf PDF
Atch 1 - PWS Domestic Charter Airlift Services Feb 2019 Amend 0001.pdf PDF
2-0002-Atch 1-PWS-Dom 121 May 2022 Amend 0002.pdf PDF
3-Atch 2 - 1993-0200_Rev 53 Amend 0002.pdf PDF
1 - HTC711-18-R-CC01 Amend 0002.pdf PDF
Atch 2 - FPA Template Amend 0001.docx DOCX document
Domestic_Charters_Award_Details_-_FBO.xlsx XLSX spreadsheet
Final_Class_JA_LPL_Dom_Charter_Combi_Redacted.pdf PDF
RFP__Question_and_Answers_(1-5).docx DOCX document
Attachment_1_-_PWS_Domestic_Charter_Airlift_Services.pdf PDF
Appendix_7_-_Post_Mission_Report.xlsx XLSX spreadsheet
Attachment_4_-_Small_Business_Subcontracting_Template.doc DOC document
1_-_HTC711-18-R-CC01.pdf PDF
Attachment_3-WD_1993-0200_Revision_No_Jan_2018.doc.pdf PDF
Appendix_5-_Cyber_Security.xlsx XLSX spreadsheet
Attachment_2_-_FPA_Template.docx DOCX document
Attachment_2a_Kerosene_Waiver.pdf PDF
Attachment_1_-_DRAFT_PWS_Domestic_Airlift_Charter.pdf PDF
Domestic_Airlift_Charter_Services_-Pre_Solicitation_Notice_Synopsis.pdf PDF
Attachment_1_-_DRAFT_PWS_Domestic_Airlift_Charter.pdf PDF
Domestic_Airlift_Charter_Services_-Pre_Solicitation_Notice_Synopsis.pdf PDF
Minutes_-_Domestic_Airlift_Services_Industry_Day.pdf PDF
Show all 31

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Instructions for POAM

USTRANSCOM NIST 800-171 POAM
INSTRUCTIONS

Each tab across the bottom of this workbook contains a NIST 800-171 control family.

Note: Certain areas of each sheet are not editable. These include "control compliance", "control/objective number", "control family", "DIBCAC score", "control/objective text" and "control type" (columns A through F). These are all locked out.

Overarching control compliance status is controlled by the subobjectives under each control number. Example: 3.1.1 can only be compliant ("yes") if objectives 3.1.1[a] through [f] are all compliant ("yes"). A noncompliant ("no") in any subobjective will automatically render the objective as noncompliant ("no"). Thus, when all subobjectives are in compliance ("yes"), the objective automatically is compliant ("yes").

Noncompilance Detection Date: self explanatory

Scheduled Completion Date: please provide an estimated time the noncompliant control/objective will be corrected.

Actual Completion Date: please annotate the date the noncompliant control/objective was corrected.

Supporting Documentation/System Controls: briefly describe those technology controls and/or process documents that will be used to achieve compliance with the control/objective requirement. Include details of the implementation/deployment plans and associated milestones. Description should be complete enough so assessors can clearly see a pathway to compliance.

Status/Comments: additional amplifying information regarding the control, objective, documentation, and/or the POAM itself.

Carrier Info

Company name:
Contract number:
Cage code:
Date completed:
Submission Type (Annual contract requirement or interim update?)
Point of contact (POC):
POC phone number:
POC e-mail address:

Access Control

Compliant
(Yes/No)NIST 800-171
Control/Objective NumberControl FamilyDIBCAC ScoringControl/Objective TextControl TypeNon-Compliance Detection DateScheduled Completion DateActual Completion DateSupporting Documentation / System ControlsStatus / CommentsResponsible Party: IT Operations, Security Office, and/or Data CustodianISO 27002:2013 Mapping
Yes3.1.1Access Control5Limit information system access to authorized users, processes acting on behalf of authorized users, or devices (including other information systems).Basic
3.1.1[a]Access Controlauthorized users are identified.
3.1.1[b]Access Controlprocesses acting on behalf of authorized users are identified.
3.1.1[c]Access Controldevices (and other systems) authorized to connect to the system are identified.
3.1.1[d]Access Controlsystem access is limited to authorized users.
3.1.1[e]Access Controlsystem access is limited to processes acting on behalf of authorized users.
3.1.1[f]Access Controlsystem access is limited to authorized devices (including other systems).
Yes3.1.2Access Control5Limit information system access to the types of transactions and functions that authorized users are permitted to execute.Derived
3.1.2[a]Access Controlthe types of transactions and functions that authorized users are permitted to execute are defined.
3.1.2[b]Access Controlsystem access is limited to the defined types of transactions and functions for authorized users.
Yes3.1.3Access Control1Limit the flow of DoD information to organizations or individuals necessary for the performance of the operationally critical requirements of this contract.Derived
3.1.3[a]Access Controlinformation flow control policies are defined.
3.1.3[b]Access Controlmethods and enforcement mechanisms for controlling the flow of CUI are defined.
3.1.3[c]Access Controldesignated sources and destinations (e.g., networks, individuals, and devices) for CUI within the system and between interconnected systems are identified.
3.1.3[d]Access Controlauthorizations for controlling the flow of CUI are defined.
3.1.3[e]Access Controlapproved authorizations for controlling the flow of CUI are enforced.
Yes3.1.4Access Control1Separate the duties of individuals to reduce the risk of malevolent activity without collusion.Derived
3.1.4[a]Access Controlthe duties of individuals requiring separation are defined.
3.1.4[b]Access Controlresponsibilities for duties that require separation are assigned to separate individuals.
3.1.4[c]Access Controlaccess privileges that enable individuals to exercise the duties that require separation are granted to separate individuals.
Yes3.1.5Access Control3Employ the principle of least privilege, including for specific security functions and privileged accounts.Derived
3.1.5[a]Access Controlprivileged accounts are identified.
3.1.5[b]Access Controlaccess to privileged accounts is authorized in accordance with the principle of least privilege.
3.1.5[c]Access Controlsecurity functions are identified.
3.1.5[d]Access Controlaccess to security functions is authorized in accordance with the principle of least privilege.
Yes3.1.6Access Control1Use non-privileged accounts or roles when accessing nonsecurity functions.Derived
3.1.6[a]Access Controlnonsecurity functions are identified.
3.1.6[b]Access Controlusers are required to use non-privileged accounts or roles when accessing nonsecurity functions.
Yes3.1.7Access Control1Prevent non-privileged users from executing privileged functions and audit the execution of such functions.Derived
3.1.7[a]Access Controlprivileged functions are defined.
3.1.7[b]Access Controlnon-privileged users are defined.
3.1.7[c]Access Controlnon-privileged users are prevented from executing privileged functions.
3.1.7[d]Access Controlthe execution of privileged functions is captured in audit logs.
Yes3.1.8Access Control1Limit unsuccessful logon attempts.Derived
3.1.8[a]Access Controlthe means of limiting unsuccessful logon attempts is defined.
3.1.8[b]Access Controlthe defined means of limiting unsuccessful logon attempts is implemented.
Yes3.1.9Access Control1Provide privacy and security notices consistent with U.S. Government and/or local governmental regulations.Derived
3.1.9[a]Access Controlprivacy and security notices required by CUI-specified rules are identified, consistent, and associated with the specific CUI category.
3.1.9[b]Access Controlprivacy and security notices are displayed.
Yes3.1.10Access Control1Use session lock with pattern-hiding displays to prevent access/viewing of data after period of inactivity.Basic
3.1.10[a]Access Controlthe period of inactivity after which the system initiates a session lock is defined.
3.1.10[b]Access Controlaccess to the system and viewing of data is prevented by initiating a session lock after the defined period of inactivity.
3.1.10[c]Access Controlpreviously visible information is concealed via a pattern-hiding display after the defined period of inactivity.
Yes3.1.11Access Control1Terminate (automatically) a user session after a defined condition.Derived
3.1.11[a]Access Controlconditions requiring a user session to terminate are defined.
3.1.11[b]Access Controla user session is automatically terminated after any of the defined conditions occur.
Yes3.1.12Access Control5Monitor and control remote access sessions.Derived
3.1.12[a]Access Controlremote access sessions are permitted.
3.1.12[b]Access Controlthe types of permitted remote access are identified.
3.1.12[c]Access Controlremote access sessions are controlled.
3.1.12[d]Access Controlremote access sessions are monitored.
Yes3.1.13Access Control5Employ cryptographic mechanisms to protect the confidentiality of remote access sessions.Derived
3.1.13[a]Access Controlcryptographic mechanisms to protect the confidentiality of remote access sessions are identified.
3.1.13[b]Access Controlcryptographic mechanisms to protect the confidentiality of remote access sessions are implemented.
Yes3.1.14Access Control1Route remote access via managed access control points.Derived
3.1.14[a]Access Controlmanaged access control points are identified and implemented.
3.1.14[b]Access Controlremote access is routed through managed network access control points.
Yes3.1.15Access Control1Authorize remote execution of privileged commands and remote access to security-relevant information.Derived
3.1.15[a]Access Controlprivileged commands authorized for remote execution are identified.
3.1.15[b]Access Controlsecurity-relevant information authorized to be accessed remotely is identified.
3.1.15[c]Access Controlthe execution of the identified privileged commands via remote access is authorized.
3.1.15[d]Access Controlaccess to the identified security-relevant information via remote access is authorized.
Yes3.1.16Access Control5Authorize wireless access prior to allowing such connections.Derived
3.1.16[a]Access Controlwireless access points are identified.
3.1.16[b]Access Controlwireless access is authorized prior to allowing such connections.
Yes3.1.17Access Control5Protect wireless access using authentication and encryption.Derived
3.1.17[a]Access Controlwireless access to the system is protected using authentication.
3.1.17[b]Access Controlwireless access to the system is protected using encryption.
Yes3.1.18Access Control5Control connection of mobile devices.Derived
3.1.18[a]Access Controlmobile devices that process, store, or transmit CUI are identified.
3.1.18[b]Access Controlmobile device connections are authorized.
3.1.18[c]Access Controlmobile device connections are monitored and logged.
Yes3.1.19Access Control3Provide adequate technical protections on mobile devices and computing platforms that process and/or store contractual information.Derived
3.1.19[a]Access Controlmobile devices and mobile computing platforms that process, store, or transmit CUI are identified.
3.1.19[b]Access Controlencryption is employed to protect CUI on identified mobile devices and mobile computing platforms.
Yes3.1.20Access Control1Verify and control/limit connections to and use of external information systems.Derived
3.1.20[a]Access Controlconnections to external systems are identified.
3.1.20[b]Access Controlthe use of external systems is identified.
3.1.20[c]Access Controlconnections to external systems are verified.
3.1.20[d]Access Controlthe use of external systems is verified.
3.1.20[e]Access Controlconnections to external systems are controlled/limited.
3.1.20[f]Access Controlthe use of external systems is controlled/limited.
Yes3.1.21Access Control1Limit use of organizational portable storage devices on external information systems.Derived
3.1.21[a]Access Controlthe use of portable storage devices containing CUI on external systems is identified and documented.
3.1.21[b]Access Controllimits on the use of portable storage devices containing CUI on external systems are defined.
3.1.21[c]Access Controlthe use of portable storage devices containing CUI on external systems is limited as defined.
Yes3.1.22Access Control1Control DoD information posted or processed on publically accessible systems.Derived
3.1.22[a]Access Controlindividuals authorized to post or process information on publicly accessible systems are identified.
3.1.22[b]Access Controlprocedures to ensure CUI is not posted or processed on publicly accessible systems are identified.
3.1.22[c]Access Controla review process is in place prior to posting of any content to publicly accessible systems.
3.1.22[d]Access Controlcontent on publicly accessible systems is reviewed to ensure that it does not include CUI.
3.1.22[e]Access Controlmechanisms are in place to remove and address improper posting of CUI.

Awareness and Training

Compliant
(Yes/No)NIST 800-171
Control/Objective NumberControl FamilyDIBCAC ScoringControl/Objective TextControl TypeNon-Compliance Detection DateScheduled Completion DateActual Completion DateSupporting Documentation / System ControlsStatus / Comments
Yes3.2.1Awareness and Training5Ensure that managers, systems administrators, and users of organizational information systems are made aware of the security risks associated with their activities and of the applicable policies, standards, and procedures related to the security of organizational information systems.Basic5
3.2.1[a]Awareness and Trainingsecurity risks associated with organizational activities involving CUI are identified.
3.2.1[b]Awareness and Trainingpolicies, standards, and procedures related to the security of the system are identified.
3.2.1[c]Awareness and Trainingmanagers, systems administrators, and users of the system are made aware of the security risks associated with their activities.
3.2.1[d]Awareness and Trainingmanagers, systems administrators, and users of the system are made aware of the applicable policies, standards, and procedures related to the security of the system.
Yes3.2.2Awareness and Training5Ensure that organizational personnel are adequately trained to carry out their assigned information security-related duties and responsibilities.Basic5
3.2.2[a]Awareness and Traininginformation security-related duties, roles, and responsibilities are defined.
3.2.2[b]Awareness and Traininginformation security-related duties, roles, and responsibilities are assigned to designated personnel.
3.2.2[c]Awareness and Trainingpersonnel are adequately trained to carry out their assigned information security-related duties, roles, and responsibilities.
Yes3.2.3Awareness and Training1Provide security awareness training on recognizing and reporting potential indicators of insider threat.Derived1
3.2.3[a]Awareness and Trainingpotential indicators associated with insider threats are identified.
3.2.3[b]Awareness and Trainingsecurity awareness training on recognizing and reporting potential indicators of insider threat is provided to managers and employees.

Audit and Accountability

Compliant
(Yes/No)NIST 800-171
Control/Objective NumberControl FamilyDIBCAC ScoringControl/Objective TextControl TypeNon-Compliance Detection DateScheduled Completion DateActual Completion DateSupporting Documentation / System ControlsStatus / Comments
Yes3.3.1Audit and Accountability5Create, protect, and retain information system audit records to the extent needed to enable the monitoring, analysis, investigation, and reporting of unlawful, unauthorized, or inappropriate information system activity.Basic
3.3.1[a]Audit and Accountabilityaudit logs needed (i.e., event types to be logged) to enable the monitoring, analysis, investigation, and reporting of unlawful or unauthorized system activity are specified.
3.3.1[b]Audit and Accountabilitythe content of audit records needed to support monitoring, analysis, investigation, and reporting of unlawful or unauthorized system activity is defined.
3.3.1[c]Audit and Accountabilityaudit records are created (generated).
3.3.1[d]Audit and Accountabilityaudit records, once created, contain the defined content.
3.3.1[e]Audit and Accountabilityretention requirements for audit records are defined.
3.3.1[f]Audit and Accountabilityaudit records are retained as defined.
Yes3.3.2Audit and Accountability3Ensure that the actions of individual information system users can be uniquely traced to those users so they can be held accountable for their actions.Basic
3.3.2[a]Audit and Accountabilitythe content of the audit records needed to support the ability to uniquely trace users to their actions is defined.
3.3.2[b]Audit and Accountabilityaudit records, once created, contain the defined content.
Yes3.3.3Audit and Accountability1Review and update audited events.Derived
3.3.3[a]Audit and Accountabilitya process for determining when to review logged events is defined.
3.3.3[b]Audit and Accountabilityevent types being logged are reviewed in accordance with the defined review process.
3.3.3[c]Audit and Accountabilityevent types being logged are updated based on the review.
Yes3.3.4Audit and Accountability1Alert in the event of an audit process failure.Derived
3.3.4[a]Audit and Accountabilitypersonnel or roles to be alerted in the event of an audit logging process failure are identified.
3.3.4[b]Audit and Accountabilitytypes of audit logging process failures for which alert will be generated are defined.
3.3.4[c]Audit and Accountabilityidentified personnel or roles are alerted in the event of an audit logging process failure.
Yes3.3.5Audit and Accountability5Use automated mechanisms to integrate and correlate audit review, analysis, and reporting processes for investigation and response to indications of inappropriate, suspicious, or unusual activity.Derived
3.3.5[a]Audit and Accountabilityaudit record review, analysis, and reporting processes for investigation and response to indications of unlawful, unauthorized, suspicious, or unusual activity are defined.
3.3.5[b]Audit and Accountabilitydefined audit record review, analysis, and reporting processes are correlated.
Yes3.3.6Audit and Accountability1Provide audit reduction and report generation to support on-demand analysis and reporting.Derived
3.3.6[a]Audit and Accountabilityan audit record reduction capability that supports on-demand analysis is provided.
3.3.6[b]Audit and Accountabilitya report generation capability that supports on-demand reporting is provided.
Yes3.3.7Audit and Accountability1Provide an information system capability that compares and synchronizes internal system clocks with an authoritative source to generate time stamps for audit records.Derived
3.3.7[a]Audit and Accountabilityinternal system clocks are used to generate time stamps for audit records.
3.3.7[b]Audit and Accountabilityan authoritative source with which to compare and synchronize internal system clocks is specified.
3.3.7[c]Audit and Accountabilityinternal system clocks used to generate time stamps for audit records are compared to and synchronized with the specified authoritative time source.
Yes3.3.8Audit and Accountability1Protect audit information and audit tools from unauthorized access, modification, and deletion.Derived
3.3.8[a]Audit and Accountabilityaudit information is protected from unauthorized access.
3.3.8[b]Audit and Accountabilityaudit information is protected from unauthorized modification.
3.3.8[c]Audit and Accountabilityaudit information is protected from unauthorized deletion.
3.3.8[d]Audit and Accountabilityaudit logging tools are protected from unauthorized access.
3.3.8[e]Audit and Accountabilityaudit logging tools are protected from unauthorized modification.
3.3.8[f]Audit and Accountabilityaudit logging tools are protected from unauthorized deletion.
Yes3.3.9Audit and Accountability1Limit management of audit functionality to a subset of privileged users.Derived
3.3.9[a]Audit and Accountabilitya subset of privileged users granted access to manage audit logging functionality is defined.
3.3.9[b]Audit and Accountabilitymanagement of audit logging functionality is limited to the defined subset of privileged users.

Configuration Management

Compliant
(Yes/No)NIST 800-171
Control/Objective NumberControl FamilyDIBCAC ScoringControl/Objective TextControl TypeNon-Compliance Detection DateScheduled Completion DateActual Completion DateSupporting Documentation / System ControlsStatus / Comments
Yes3.4.1Configuration Management5Establish and maintain baseline configurations and inventories of organizational information systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles.Basic
3.4.1[a]Configuration Managementa baseline configuration is established.
3.4.1[b]Configuration Managementthe baseline configuration includes hardware, software, firmware, and documentation.
3.4.1[c]Configuration Managementthe baseline configuration is maintained (reviewed and updated) throughout the system development life cycle.
3.4.1[d]Configuration Managementa system inventory is established.
3.4.1[e]Configuration Managementthe system inventory includes hardware, software, firmware, and documentation.
3.4.1[f]Configuration Managementthe inventory is maintained (reviewed and updated) throughout the system development life cycle.
Yes3.4.2Configuration Management5Establish and enforce security configuration settings for information technology products employed in organizational information systems.Basic
3.4.2[a]Configuration Managementsecurity configuration settings for information technology products employed in the system are established and included in the baseline configuration.
3.4.2[b]Configuration Managementsecurity configuration settings for information technology products employed in the system are enforced.
Yes3.4.3Configuration Management1Track, review, approve/disapprove, and audit changes to information systems.Derived
3.4.3[a]Configuration Managementchanges to the system are tracked.
3.4.3[b]Configuration Managementchanges to the system are reviewed.
3.4.3[c]Configuration Managementchanges to the system are approved or disapproved.
3.4.3[d]Configuration Managementchanges to the system are logged.
3.4.4Configuration Management1Analyze the security impact of changes prior to implementation.Derived
Yes3.4.5Configuration Management5Define, document, approve, and enforce physical and logical access restrictions associated with changes to the information system.Derived
3.4.5[a]Configuration Managementphysical access restrictions associated with changes to the system are defined.
3.4.5[b]Configuration Managementphysical access restrictions associated with changes to the system are documented.
3.4.5[c]Configuration Managementphysical access restrictions associated with changes to the system are approved.
3.4.5[d]Configuration Managementphysical access restrictions associated with changes to the system are enforced.
3.4.5[e]Configuration Managementlogical access restrictions associated with changes to the system are defined.
3.4.5[f]Configuration Managementlogical access restrictions associated with changes to the system are documented.
3.4.5[g]Configuration Managementlogical access restrictions associated with changes to the system are approved.
3.4.5[h]Configuration Managementlogical access restrictions associated with changes to the system are enforced.
Yes3.4.6Configuration Management5Employ the principle of least functionality by configuring the information system to provide only essential capabilities.Derived
3.4.6[a]Configuration Managementessential system capabilities are defined based on the principle of least functionality.
3.4.6[b]Configuration Managementthe system is configured to provide only the defined essential capabilities.
Yes3.4.7Configuration Management5Restrict, disable, and prevent the use of nonessential programs, functions, ports, protocols, and services.Derived
3.4.7[a]Configuration Managementessential programs are defined.
3.4.7[b]Configuration Managementthe use of nonessential programs is defined.
3.4.7[c]Configuration Managementthe use of nonessential programs is restricted, disabled, or prevented as defined.
3.4.7[d]Configuration Managementessential functions are defined.
3.4.7[e]Configuration Managementthe use of nonessential functions is defined.
3.4.7[f]Configuration Managementthe use of nonessential functions is restricted, disabled, or prevented as defined.
3.4.7[g]Configuration Managementessential ports are defined.
3.4.7[h]Configuration Managementthe use of nonessential ports is defined.
3.4.7[i]Configuration Managementthe use of nonessential ports is restricted, disabled, or prevented as defined.
3.4.7[j]Configuration Managementessential protocols are defined.
3.4.7[k]Configuration Managementthe use of nonessential protocols is defined.
3.4.7[l]Configuration Managementthe use of nonessential protocols is restricted, disabled, or prevented as defined.
3.4.7[m]Configuration Managementessential services are defined.
3.4.7[n]Configuration Managementthe use of nonessential services is defined.
3.4.7[o]Configuration Managementthe use of nonessential services is restricted, disabled, or prevented as defined.
Yes3.4.8Configuration Management5Apply deny-by-exception (blacklist) policy to prevent the use of unauthorized software or deny-all, permit-by-exception (whitelisting) policy to allow the execution of authorized software.Derived
3.4.8[a]Configuration Managementa policy specifying whether whitelisting or blacklisting is to be implemented is specified.
3.4.8[b]Configuration Managementthe software allowed to execute under whitelisting or denied use under blacklisting is specified.
3.4.8[c]Configuration Managementwhitelisting to allow the execution of authorized software or blacklisting to prevent the use of unauthorized software is implemented as specified.
Yes3.4.9Configuration Management1Control and monitor user-installed software.Derived
3.4.9[a]Configuration Managementa policy for controlling the installation of software by users is established.
3.4.9[b]Configuration Managementinstallation of software by users is controlled based on the established policy.
3.4.9[c]Configuration Managementinstallation of software by users is monitored.

ID and Authentication

Compliant
(Yes/No)NIST 800-171
Control/Objective NumberControl FamilyDIBCAC ScoringControl/Objective TextControl TypeNon-Compliance Detection DateScheduled Completion DateActual Completion DateSupporting Documentation / System ControlsStatus / Comments
Yes3.5.1Identification and Authentication5Identify information system users, processes acting on behalf of users, or devices.Basic
3.5.1[a]Identification and Authenticationsystem users are identified.
3.5.1[b]Identification and Authenticationprocesses acting on behalf of users are identified.
3.5.1[c]Identification and Authenticationdevices accessing the system are identified.
Yes3.5.2Identification and Authentication5Authenticate (or verify) the identities of those users, processes, or devices, as a prerequisite to allowing access to organizational information systems.Basic
3.5.2[a]Identification and Authenticationthe identity of each user is authenticated or verified as a prerequisite to system access.
3.5.2[b]Identification and Authenticationthe identity of each process acting on behalf of a user is authenticated or verified as a prerequisite to system access.
3.5.2[c]Identification and Authenticationthe identity of each device accessing or connecting to the system is authenticated or verified as a prerequisite to system access.
Yes3.5.3Identification and Authentication5Use multifactor authentication for local and network access to privileged accounts and for network access to non-privileged accounts.Derived
3.5.3[a]Identification and Authenticationprivileged accounts are identified.
3.5.3[b]Identification and Authenticationmultifactor authentication is implemented for local access to privileged accounts.
3.5.3[c]Identification and Authenticationmultifactor authentication is implemented for network access to privileged accounts.
3.5.3[d]Identification and Authenticationmultifactor authentication is implemented for network access to non-privileged accounts.
3.5.4Identification and Authentication1Employ replay-resistant authentication mechanisms for network access to privileged and non-privileged accounts.Derived
Yes3.5.5Identification and Authentication1Prevent reuse of identifiers for a defined period.Derived
3.5.5[a]Identification and Authenticationa period within which identifiers cannot be reused is defined.
3.5.5[b]Identification and Authenticationreuse of identifiers is prevented within the defined period.
Yes3.5.6Identification and Authentication1Disable identifiers after a defined period of inactivity.Derived
3.5.6[a]Identification and Authenticationa period of inactivity after which an identifier is disabled is defined.
3.5.6[b]Identification and Authenticationidentifiers are disabled after the defined period of inactivity.
Yes3.5.7Identification and Authentication1Enforce a minimum password complexity and change of characters when new passwords are created.Derived
3.5.7[a]Identification and Authenticationpassword complexity requirements are defined.
3.5.7[b]Identification and Authenticationpassword change of character requirements are defined.
3.5.7[c]Identification and Authenticationminimum password complexity requirements as defined are enforced when new passwords are created.
3.5.7[d]Identification and Authenticationminimum password change of character requirements as defined are enforced when new passwords are created.
Yes3.5.8Identification and Authentication1Prohibit password reuse for a specified number of generations.Derived
3.5.8[a]Identification and Authenticationthe number of generations during which a password cannot be reused is specified.
3.5.8[b]Identification and Authenticationreuse of passwords is prohibited during the specified number of generations.
3.5.9Identification and Authentication1Allow temporary password use for system logons with an immediate change to a permanent password.Derived
Yes3.5.10Identification and Authentication5Store and transmit only encrypted representation of passwords.Derived
3.5.10[a]Identification and Authenticationpasswords are cryptographically protected in storage.
3.5.10[b]Identification and Authenticationpasswords are cryptographically protected in transit.
3.5.11Identification and Authentication1Obscure feedback of authentication information.Derived

Incident Response

Compliant
(Yes/No)NIST 800-171
Control/Objective NumberControl FamilyDIBCAC ScoringControl/Objective TextControl TypeNon-Compliance Detection DateScheduled Completion DateActual Completion DateSupporting Documentation / System ControlsStatus / Comments
Yes3.6.1Incident Response5Establish an operational incident-handling capability for organizational information systems that includes adequate preparation, detection, analysis, containment, recovery, and user response activities.Basic
3.6.1[a]Incident Responsean operational incident-handling capability is established.
3.6.1[b]Incident Responsethe operational incident-handling capability includes preparation.
3.6.1[c]Incident Responsethe operational incident-handling capability includes detection.
3.6.1[d]Incident Responsethe operational incident-handling capability includes analysis.
3.6.1[e]Incident Responsethe operational incident-handling capability includes containment.
3.6.1[f]Incident Responsethe operational incident-handling capability includes recovery.
3.6.1[g]Incident Responsethe operational incident-handling capability includes user response activities.
Yes3.6.2Incident Response5Track, document, and report incidents to appropriate officials and/or authorities both internal and external to the organization.Basic
3.6.2[a]Incident Responseincidents are tracked.
3.6.2[b]Incident Responseincidents are documented.
3.6.2[c]Incident Responseauthorities to whom incidents are to be reported are identified.
3.6.2[d]Incident Responseorganizational officials to whom incidents are to be reported are identified.
3.6.2[e]Incident Responseidentified authorities are notified of incidents.
3.6.2[f]Incident Responseidentified organizational officials are notified of incidents.
3.6.3Incident Response1Test the organizational incident response capability.Derived

Maintenance

Compliant
(Yes/No)NIST 800-171
Control/Objective NumberControl FamilyDIBCAC ScoringControl/Objective TextControl TypeNon-Compliance Detection DateScheduled Completion DateActual Completion DateSupporting Documentation / System ControlsStatus / Comments
3.7.1Maintenance3Perform maintenance on organizational information systems.Basic
Yes3.7.2Maintenance5Provide effective controls on the tools, techniques, mechanisms, and personnel used to conduct information system maintenance.Basic
3.7.2[a]Maintenancetools used to conduct system maintenance are controlled.
3.7.2[b]Maintenancetechniques used to conduct system maintenance are controlled.
3.7.2[c]Maintenancemechanisms used to conduct system maintenance are controlled.
3.7.2[d]Maintenancepersonnel used to conduct system maintenance are controlled.
3.7.3Maintenance1Ensure equipment removed for off-site maintenance is sanitized of DoD information.Derived
3.7.4Maintenance3Check media containing diagnostic and test programs for malicious code before the media are used in the information system.Derived
Yes3.7.5Maintenance5Require multifactor authentication to establish nonlocal maintenance sessions via external network connections and terminate such connections when nonlocal maintenance is complete.Derived
3.7.5[a]Maintenancemultifactor authentication is used to establish nonlocal maintenance sessions via external network connections.
3.7.5[b]Maintenancenonlocal maintenance sessions established via external network connections are terminated when nonlocal maintenance is complete.
3.7.6Maintenance1Supervise the maintenance activities of maintenance personnel without required access authorization.Derived

Media Protection

Compliant
(Yes/No)NIST 800-171
Control/Objective NumberControl FamilyDIBCAC ScoringControl/Objective TextControl TypeNon-Compliance Detection DateScheduled Completion DateActual Completion DateSupporting Documentation / System ControlsStatus / Comments
Yes3.8.1Media Protection3Protect (i.e., physically control and securely store) system media containing DoD information, both paper and digital.Basic
3.8.1[a]Media Protectionpaper media containing CUI is physically controlled.
3.8.1[b]Media Protectiondigital media containing CUI is physically controlled.
3.8.1[c]Media Protectionpaper media containing CUI is securely stored.
3.8.1[d]Media Protectiondigital media containing CUI is securely stored.
3.8.2Media Protection3Limit access to DoD information on system media to authorized users.Basic
Yes3.8.3Media Protection5Sanitize or destroy system media containing DoD information before disposal or release for reuse.Basic
3.8.3[a]Media Protectionsystem media containing CUI is sanitized or destroyed before disposal.
3.8.3[b]Media Protectionsystem media containing CUI is sanitized before it is released for reuse.
Yes3.8.4Media Protection1Mark media with privacy and security notices consistent with U.S. Government and/or local government regulations.Derived
3.8.4[a]Media Protectionmedia containing CUI is marked with applicable CUI markings.
3.8.4[b]Media Protectionmedia containing CUI is marked with distribution limitations.
Yes3.8.5Media Protection1Control access to and maintain accountability for media containing DoD information.Derived
3.8.5[a]Media Protectionaccess to media containing CUI is controlled.
3.8.5[b]Media Protectionaccountability for media containing CUI is maintained during transport outside of controlled areas.
3.8.6Media Protection1Implement cryptographic mechanisms to protect the confidentiality of CUI stored on digital media during transport unless otherwise protected by alternative physical safeguards.Derived
3.8.7Media Protection5Control the use of removable media on information system components.Derived
3.8.8Media Protection3Prohibit the use of portable storage devices when such devices have no identifiable owner.Derived
3.8.9Media Protection1Provide information backup procedures (frequency, timeframe for storage, etc.) for DoD data located on contractor systems. Protect the confidentiality of backup materials containing DoD information.Derived

Personnel Security

Compliant
(Yes/No)NIST 800-171
Control/Objective NumberControl FamilyDIBCAC ScoringControl/Objective TextControl TypeNon-Compliance Detection DateScheduled Completion DateActual Completion DateSupporting Documentation / System ControlsStatus / Comments
3.9.1Personnel Security3Screen individuals prior to authorizing access to organizational systems containing DoD information.Basic
Yes3.9.2Personnel Security5Ensure that DoD information and organizational systems containing DoD information are protected during and after personnel actions such as terminations and transfers.Basic
3.9.2[a]Personnel Securitya policy and/or process for terminating system access and any credentials coincident with personnel actions is established.
3.9.2[b]Personnel Securitysystem access and credentials are terminated consistent with personnel actions such as termination or transfer.
3.9.2[c]Personnel Securitythe system is protected during and after personnel transfer actions.

Physical Protection

Compliant
(Yes/No)NIST 800-171
Control/Objective NumberControl FamilyDIBCAC ScoringControl/Objective TextControl TypeNon-Compliance Detection DateScheduled Completion DateActual Completion DateSupporting Documentation / System ControlsStatus / Comments
Yes3.10.1Physical Protection5Limit physical access to organizational information systems, equipment, and the respective operating environments to authorized individuals.Basic
3.10.1[a]Physical Protectionauthorized individuals allowed physical access are identified.
3.10.1[b]Physical Protectionphysical access to organizational systems is limited to authorized individuals.
3.10.1[c]Physical Protectionphysical access to equipment is limited to authorized individuals.
3.10.1[d]Physical Protectionphysical access to operating environments is limited to authorized individuals.
Yes3.10.2Physical Protection5Protect and monitor the physical facility and support infrastructure for those information systems.Basic
3.10.2[a]Physical Protectionthe physical facility where organizational systems reside is protected.
3.10.2[b]Physical Protectionthe support infrastructure for organizational systems is protected.
3.10.2[c]Physical Protectionthe physical facility where organizational systems reside is monitored.
3.10.2[d]Physical Protectionthe support infrastructure for organizational systems is monitored.
Yes3.10.3Physical Protection1Escort visitors and monitor visitor activity.Derived
3.10.3[a]Physical Protectionvisitors are escorted.
3.10.3[b]Physical Protectionvisitor activity is monitored.
3.10.4Physical Protection1Maintain audit logs of physical access.Derived
Yes3.10.5Physical Protection1Control and manage physical access devices.Derived
3.10.5[a]Physical Protectionphysical access devices are identified.
3.10.5[b]Physical Protectionphysical access devices are controlled.
3.10.5[c]Physical Protectionphysical access devices are managed.
Yes3.10.6Physical Protection1Enforce safeguarding measures for DoD Information at alternate work sites (e.g., telework sites).Derived
3.10.6[a]Physical Protectionsafeguarding measures for CUI are defined for alternate work sites.
3.10.6[b]Physical Protectionsafeguarding measures for CUI are enforced for alternate work sites.

Risk Assessment

Compliant
(Yes/No)NIST 800-171
Control/Objective NumberControl FamilyDIBCAC ScoringControl/Objective TextControl TypeNon-Compliance Detection DateScheduled Completion DateActual Completion DateSupporting Documentation / System ControlsStatus / Comments
Yes3.11.1Risk Assessment3Periodically assess the risk to organizational operations (including mission, functions, image, or reputation), organizational assets, and individuals, resulting from the operation of organizational systems and the associated processing, storage, or transmission of DoD information.Basic
3.11.1[a]Risk Assessmentthe frequency to assess risk to organizational operations, organizational assets, and individuals is defined.
3.11.1[b]Risk Assessmentrisk to organizational operations, organizational assets, and individuals resulting from the operation of an organizational system that processes, stores, or transmits CUI is assessed with the defined frequency.
Yes3.11.2Risk Assessment5Scan for vulnerabilities in the information system and applications periodically and when new vulnerabilities affecting the system are identified.Derived
3.11.2[a]Risk Assessmentthe frequency to scan for vulnerabilities in organizational systems and applications is defined.
3.11.2[b]Risk Assessmentvulnerability scans are performed on organizational systems with the defined frequency.
3.11.2[c]Risk Assessmentvulnerability scans are performed on applications with the defined frequency.
3.11.2[d]Risk Assessmentvulnerability scans are performed on organizational systems when new vulnerabilities are identified.
3.11.2[e]Risk Assessmentvulnerability scans are performed on applications when new vulnerabilities are identified.
Yes3.11.3Risk Assessment1Remediate vulnerabilities in accordance with assessments of risk.Derived
3.11.3[a]Risk Assessmentvulnerabilities are identified.
3.11.3[b]Risk Assessmentvulnerabilities are remediated in accordance with risk assessments.

Security Assessment

Compliant
(Yes/No)NIST 800-171
Control/Objective NumberControl FamilyDIBCAC ScoringControl/Objective TextControl TypeNon-Compliance Detection DateScheduled Completion DateActual Completion DateSupporting Documentation / System ControlsStatus / Comments
Yes3.12.1Security Assessment5Periodically assess the security controls in organizational information systems to determine if the controls are effective in their application.Basic
3.12.1[a]Security Assessmentthe frequency of security control assessments is defined.
3.12.1[b]Security Assessmentsecurity controls are assessed with the defined frequency to determine if the controls are effective in their application.
Yes3.12.2Security Assessment3Develop and implement plans of action designed to correct deficiencies and reduce or eliminate vulnerabilities in organizational information systems.Basic
3.12.2[a]Security Assessmentdeficiencies and vulnerabilities to be addressed by the plan of action are identified.
3.12.2[b]Security Assessmenta plan of action is developed to correct identified deficiencies and reduce or eliminate identified vulnerabilities.
3.12.2[c]Security Assessmentthe plan of action is implemented to correct identified deficiencies and reduce or eliminate identified vulnerabilities.
3.12.3Security Assessment5Monitor information system security controls on an ongoing basis to ensure the continued effectiveness of the controls.Basic
Yes3.12.4Security AssessmentNADevelop, document, and periodically update system security plans that describe system boundaries, system environments of operation, how security requirements are implemented, and the relationships with or connections to other systems.Basic
3.12.4[a]Security Assessmenta system security plan is developed.
3.12.4[b]Security Assessmentthe system boundary is described and documented in the system security plan.
3.12.4[c]Security Assessmentthe system environment of operation is described and documented in the system security plan.
3.12.4[d]Security Assessmentthe security requirements identified and approved by the designated authority as non-applicable are identified.
3.12.4[e]Security Assessmentthe method of security requirement implementation is described and documented in the system security plan.
3.12.4[f]Security Assessmentthe relationship with or connection to other systems is described and documented in the system security plan.
3.12.4[g]Security Assessmentthe frequency to update the system security plan is defined.
3.12.4[h]Security Assessmentsystem security plan is updated with the defined frequency.

Sys and Comm Protection

Compliant
(Yes/No)NIST 800-171
Control/Objective NumberControl FamilyDIBCAC ScoringControl/Objective TextControl TypeNon-Compliance Detection DateScheduled Completion DateActual Completion DateSupporting Documentation / System ControlsStatus / Comments
Yes3.13.1System and Communications Protection5Monitor, control, and protect organizational communications (i.e., information transmitted or received by organizational information systems) at the external boundaries and key internal boundaries of the information systems.Basic
3.13.1[a]System and Communications Protectionthe external system boundary is defined.
3.13.1[b]System and Communications Protectionkey internal system boundaries are defined.
3.13.1[c]System and Communications Protectioncommunications are monitored at the external system boundary.
3.13.1[d]System and Communications Protectioncommunications are monitored at key internal boundaries.
3.13.1[e]System and Communications Protectioncommunications are controlled at the external system boundary.
3.13.1[f]System and Communications Protectioncommunications are controlled at key internal boundaries.
3.13.1[g]System and Communications Protectioncommunications are protected at the external system boundary.
3.13.1[h]System and Communications Protectioncommunications are protected at key internal boundaries.
Yes3.13.2System and Communications Protection5Employ architectural designs, software development techniques, and systems engineering principles that promote effective information security within organizational information systems.Basic
3.13.2[a]System and Communications Protectionarchitectural designs that promote effective information security are identified.
3.13.2[b]System and Communications Protectionsoftware development techniques that promote effective information security are identified.
3.13.2[c]System and Communications Protectionsystems engineering principles that promote effective information security are identified.
3.13.2[d]System and Communications Protectionidentified architectural designs that promote effective information security are employed.
3.13.2[e]System and Communications Protectionidentified software development techniques that promote effective information security are employed.
3.13.2[f]System and Communications Protectionidentified systems engineering principles that promote effective information security are employed.
Yes3.13.3System and Communications Protection1Separate user functionality from information system management functionality.Derived
3.13.3[a]System and Communications Protectionuser functionality is identified.
3.13.3[b]System and Communications Protectionsystem management functionality is identified.
3.13.3[c]System and Communications Protectionuser functionality is separated from system management functionality.
3.13.4System and Communications Protection1Prevent unauthorized and unintended information transfer via shared system resources.Derived
Yes3.13.5System and Communications Protection5Implement subnetworks for publicly accessible system components that are physically or logically separated from internal networks.Derived
3.13.5[a]System and Communications Protectionpublicly accessible system components are identified.
3.13.5[b]System and Communications Protectionsubnetworks for publicly accessible system components are physically or logically separated from internal networks.
Yes3.13.6System and Communications Protection5Deny network communications traffic by default and allow network communications traffic by exception (i.e., deny all, permit by exception).Derived
3.13.6[a]System and Communications Protectionnetwork communications traffic is denied by default.
3.13.6[b]System and Communications Protectionnetwork communications traffic is allowed by exception.

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .