Appendix_J_-_NIST.SP.800-171_-_POAM_-_DRAFT.xlsx

XLSX spreadsheet 78 KB Posted

Attached to
Household Goods (HHG) Relocation Services Federal contract opportunity
Solicitation number
HTC711-19-R-R004
Issued by
Department of Defense United States Transportation Command

About this file

This document contains a Plan of Action and Milestones (POAM) for complying with the National Institute of Standards and Technology Special Publication 800-171 controls for protecting controlled unclassified information. The POAM identifies over 100 controls across 14 families, with the status of compliance for each, planned completion dates, and responsible parties. Key controls address access control, identification and authentication, incident response, configuration management, system and communications protection, and system integrity. The POAM provides a framework and timeline for implementing technical, operational, and managerial safeguards to protect federal contract information in accordance with NIST SP 800-171 requirements.

Appendix J - NIST.SP.800-171 - POAM - DRAFT

View the file

Other files for this federal contract opportunity

Other files attached to Household Goods (HHG) Relocation Services, newest first.
File Type Posted
Attachment_8_-_Small_Business_Subcontracting_Plan,_Amend_03.docx DOCX document
Attachment_1_-_Performance_Work_Statement,_Amend_03.pdf PDF
HTC711-19-R-R004,_GHC_Amend_02_SF30.pdf PDF
Attachment_1_-_Performance_Work_Statement,_Amend_02.pdf PDF
GHC_PreProposal_Conf_Slides.pdf PDF
HHG_Estimate.pdf PDF
GHC_Pre-Proposal_Conf_Save_the_Date.pdf PDF
Attachment_2a_-_Maps.pdf PDF
Appendix_I_-_CUI_Requirements_Table.pdf PDF
Attachment_5_-_Past_Performance_Questionnaire.docx DOCX document
Appendix_D_-_Non-Standard_Processes.pdf PDF
Appendix_A_-_Transition_Phase-In_Phase-Out.pdf PDF
Attachment_6_-_Financial_Information_Questionnaire.doc DOC document
Attachment_9_-_SB_Participation_Commitment_Document.docx DOCX document
Appendix_C_-_Transit_Times.pdf PDF
Attachment_2_-_Pricing_Rate_Table.xlsx XLSX spreadsheet
Attachment_1_-_Performance_Work_Statement.pdf PDF
Appendix_H__-_Form_Data_Elements.xlsx XLSX spreadsheet
Attachment_4_-_Award_Term_Plan.pdf PDF
Attachment_2b_-_Non-Standard_Rate_Areas_-_DRAFT.pdf PDF
Attachment_8_-_Small_Business_Subcontracting_Plan_-_DRAFT.docx DOCX document
HTC71119RR004_-_DRAFT.pdf PDF
Appendix_B_-_Required_Reports_-_DRAFT.pdf PDF
Appendix_I_-_CUI_Requirements_Table_-_DRAFT.pdf PDF
Appendix_E_-_Claims_and_Liability_Rules_-DRAFT.pdf PDF
DRAFT_RFP_Industry_Q&As.pdf PDF
Appendix_G_-_EPA_Schedule_-_DRAFT.pdf PDF
Appendix_C_-_Transit_Times.pdf PDF
Attachment_3_-_Wage_Determination.pdf PDF
Attachment_7_-_RFP_Offeror_Information_Sheet.pdf PDF
Appendix_C_-_Transit_Times.pdf PDF
HTC711-19-R-R004_GHC.pdf PDF
Appendix_D_-_Non-Standard_Processes.pdf PDF
Attachment_1_-_Global_HHG_Contract_(GHC)_PWS.pdf PDF
Appendix_B_-_Required_Reports.pdf PDF
Attachment_2_-_Pricing_Template.xlsx XLSX spreadsheet
Attachment_5_-_Past_Performance_Questionnaire.pdf PDF
Attachment_9_-_Small_Business_Participation_Commitment_Document.pdf PDF
Attachment_4_-_Award_Term_Plan.pdf PDF
2019.03.26_GHC_Industry_Day_General_Session_QA.pdf PDF
Industry_Day__2_1-on-1_Handout.pdf PDF
Industry_Day__2_General_Session_Slides.pptx PPTX presentation
DRAFT_PWS_Appendix_C_-_Report.pdf PDF
DRAFT_PWS.pdf PDF
DRAFT_PWS_Appendix_F_-_Transit_Times.pdf PDF
GHC_Industry_Day__2_Save_the_Date.DOCX DOCX document
2019.03.07_GHC_Industry_Day_General_Session_QA.pdf PDF
Global_HHG_Contract_(GHC)_PWS_(20190213)_-_Draft_for_Industry_Day.docx DOCX document
Lambert_to_Drury.ppt PPT presentation
HHG_RFI_20181128.pdf PDF
Show all 50

Household Goods (HHG) Relocation Services has more files on GovTribe.

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

POA&M

Date: 5/31/2017
Org Name, Cage Code: Street City State Zip (XXX) XXX-XXXX
Compliant (Yes/No)NIST 800-171 Control NumberControl FamilyControl TextControl TypeNon-Compliance Detection DateScheduled Completion DateActual Completion DateOriginal Impact LevelAdjusted Impact LevelAdjusted Impact Rationale (If Applicable)Supporting Documentation / System ControlsStatus / CommentsResponsible Party: IT Operations, Security Office, and/or Data CustodianISO 27002:2013 Mapping
3.1.1Access ControlLimit information system access to authorized users, processes acting on behalf of authorized users, or devices (including other information systems).BasicIT Operations, Data CustodianA.6.2.1, A.6.2.2, A.6.2.2, A.9.1.2, A.9.2.1, A.9.2.2, A.9.2.3, A.9.2.5, A.9.2.6, A.9.4.1, A.9.4.4, A.9.4.5, A.13.1.1, A.13.2.1, A.14.1.2, A.14.1.2, A.14.1.3, A.18.1.3
3.1.2Access ControlLimit information system access to the types of transactions and functions that authorized users are permitted to execute.DerivedIT Operations, Data CustodianA.6.2.1, A.6.2.2, A.6.2.2, A.9.1.2, A.9.2.1, A.9.2.2, A.9.2.3, A.9.2.5, A.9.2.6, A.9.4.1, A.9.4.4, A.9.4.5, A.13.1.1, A.13.2.1, A.14.1.2, A.14.1.2, A.14.1.3, A.18.1.3
3.1.3Access ControlControl the flow of CUI in accordance with approved authorizations.DerivedIT OperationsA.13.1.3, A.13.2.1, A.14.1.2, A.14.1.3
3.1.4Access ControlSeparate the duties of individuals to reduce the risk of malevolent activity without collusion.DerivedIT OperationsA.6.1.2
3.1.5Access ControlEmploy the principle of least privilege, including for specific security functions and privileged accounts.DerivedIT OperationsA.9.1.2, A.9.2.3, A.9.4.4, A.9.4.5
3.1.6Access ControlUse non-privileged accounts or roles when accessing nonsecurity functions.DerivedIT OperationsA.9.1.2, A.9.2.3, A.9.4.4, A.9.4.5
3.1.7Access ControlPrevent non-privileged users from executing privileged functions and audit the execution of such functions.DerivedIT OperationsA.9.1.2, A.9.2.3, A.9.4.4, A.9.4.5
3.1.8Access ControlLimit unsuccessful logon attempts.DerivedIT OperationsA.9.4.2
3.1.9Access ControlProvide privacy and security notices consistent with applicable CUI rules.DerivedIT OperationsA.9.4.2
3.1.10Access ControlUse session lock with pattern-hiding displays to prevent access/viewing of data after period of inactivity.BasicIT OperationsA.11.2.8, A.11.2.9
3.1.11Access ControlTerminate (automatically) a user session after a defined condition.DerivedIT OperationsNone
3.1.12Access ControlMonitor and control remote access sessions.DerivedIT OperationsA.6.2.1, A.6.2.2, A.13.1.1, A.13.2.1, A.14.1.2
3.1.13Access ControlEmploy cryptographic mechanisms to protect the confidentiality of remote access sessions.DerivedIT OperationsA.6.2.1, A.6.2.2, A.13.1.1, A.13.2.1, A.14.1.2
3.1.14Access ControlRoute remote access via managed access control points.DerivedIT OperationsA.6.2.1, A.6.2.2, A.13.1.1, A.13.2.1, A.14.1.2
3.1.15Access ControlAuthorize remote execution of privileged commands and remote access to security-relevant information.DerivedIT OperationsA.6.2.1, A.6.2.2, A.13.1.1, A.13.2.1, A.14.1.2
3.1.16Access ControlAuthorize wireless access prior to allowing such connections.DerivedSecurity Office, IT OperationsA.6.2.1, A.13.1.1, A.13.2.1
3.1.17Access ControlProtect wireless access using authentication and encryption.DerivedIT OperationsA.6.2.1, A.13.1.1, A.13.2.1
3.1.18Access ControlControl connection of mobile devices.DerivedSecurity Office, IT OperationsA.6.2.1, A.11.2.6, A.13.2.1
3.1.19Access ControlEncrypt CUI on mobile devices.DerivedIT OperationsA.6.2.1, A.11.2.6, A.13.2.1
3.1.20Access ControlVerify and control/limit connections to and use of external information systems.DerivedSecurity OfficeA.11.2.6, A.13.1.1, A.13.2.1
3.1.21Access ControlLimit use of organizational portable storage devices on external information systems.DerivedSecurity OfficeA.11.2.6, A.13.1.1, A.13.2.1
3.1.22Access ControlControl information posted or processed on publicly accessible information systems.DerivedSecurity Office, IT OperationsNone
3.2.1Awareness and TrainingEnsure that managers, systems administrators, and users of organizational information systems are made aware of the security risks associated with their activities and of the applicable policies, standards, and procedures related to the security of organizational information systems.BasicData Custodian, Security OfficeA.7.2.2, A.12.2.1
3.2.2Awareness and TrainingEnsure that organizational personnel are adequately trained to carry out their assigned information security-related duties and responsibilities.BasicData Custodian, Security OfficeA.7.2.2, A.12.2.1
3.2.3Awareness and TrainingProvide security awareness training on recognizing and reporting potential indicators of insider threat.DerivedData Custodian, Security OfficeA.7.2.2, A.12.2.1
3.3.1Audit and AccountabilityCreate, protect, and retain information system audit records to the extent needed to enable the monitoring, analysis, investigation, and reporting of unlawful, unauthorized, or inappropriate information system activity.BasicIT OperationsA.12.4.1, A.12.4.3, A.16.1.2, A.16.1.4
3.3.2Audit and AccountabilityEnsure that the actions of individual information system users can be uniquely traced to those users so they can be held accountable for their actions.BasicIT OperationsA.12.4.1, A.12.4.3, A.16.1.2, A.16.1.4
3.3.3Audit and AccountabilityReview and update audited events.DerivedIT OperationsNone
3.3.4Audit and AccountabilityAlert in the event of an audit process failure.DerivedIT OperationsNone
3.3.5Audit and AccountabilityUse automated mechanisms to integrate and correlate audit review, analysis, and reporting processes for investigation and response to indications of inappropriate, suspicious, or unusual activity.DerivedIT OperationsA.12.4.1, A.16.1.2, A.16.1.4
3.3.6Audit and AccountabilityProvide audit reduction and report generation to support on-demand analysis and reporting.DerivedIT OperationsNone
3.3.7Audit and AccountabilityProvide an information system capability that compares and synchronizes internal system clocks with an authoritative source to generate time stamps for audit records.DerivedIT OperationsA.12.4.4
3.3.8Audit and AccountabilityProtect audit information and audit tools from unauthorized access, modification, and deletion.DerivedIT OperationsA.12.4.2, A.12.4.3, A.18.1.3
3.3.9Audit and AccountabilityLimit management of audit functionality to a subset of privileged users.DerivedIT OperationsA.12.4.2, A.12.4.3, A.18.1.3
3.4.1Configuration ManagementEstablish and maintain baseline configurations and inventories of organizational information systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles.BasicIT OperationsA.8.1.1, A.8.1.2
3.4.2Configuration ManagementEstablish and enforce security configuration settings for information technology products employed in organizational information systems.BasicIT OperationsA.8.1.1, A.8.1.2
3.4.3Configuration ManagementTrack, review, approve/disapprove, and audit changes to information systems.DerivedIT OperationsA.12.1.2, A.14.2.2, A.14.2.3, A.14.2.4
3.4.4Configuration ManagementAnalyze the security impact of changes prior to implementation.DerivedIT OperationsA.14.2.3
3.4.5Configuration ManagementDefine, document, approve, and enforce physical and logical access restrictions associated with changes to the information system.DerivedSecurity OfficeA.9.2.3, A.9.4.5, A.12.1.2, A.12.1.4, A.12.5.1
3.4.6Configuration ManagementEmploy the principle of least functionality by configuring the information system to provide only essential capabilities.DerivedIT OperationsA.12.5.1 (ISO control doesn't completely match NIST 800-53)
3.4.7Configuration ManagementRestrict, disable, and prevent the use of nonessential programs, functions, ports, protocols, and services.DerivedIT OperationsA.12.5.1 (ISO control doesn't completely match NIST 800-53)
3.4.8Configuration ManagementApply deny-by-exception (blacklist) policy to prevent the use of unauthorized software or deny-all, permit-by-exception (whitelisting) policy to allow the execution of authorized software.DerivedIT OperationsA.12.5.1 (ISO control doesn't completely match NIST 800-53)
3.4.9Configuration ManagementControl and monitor user-installed software.DerivedIT OperationsA.12.5.1, A.12.6.2
3.5.1Identification and AuthenticationIdentify information system users, processes acting on behalf of users, or devices.BasicIT OperationsA.9.2.1, A.9.2.4, A.9.3.1, A.9.4.3
3.5.2Identification and AuthenticationAuthenticate (or verify) the identities of those users, processes, or devices, as a prerequisite to allowing access to organizational information systems.BasicIT Operations, Security Office, Data CustodianA.9.2.1, A.9.2.4, A.9.3.1, A.9.4.3
3.5.3Identification and AuthenticationUse multifactor authentication for local and network access to privileged accounts and for network access to non-privileged accounts.DerivedIT Operations, Security Office, Data CustodianA.9.2.1
3.5.4Identification and AuthenticationEmploy replay-resistant authentication mechanisms for network access to privileged and non-privileged accounts.DerivedIT Operations, Security Office, Data CustodianA.9.2.1
3.5.5Identification and AuthenticationPrevent reuse of identifiers for a defined period.DerivedIT OperationsA.9.2.1
3.5.6Identification and AuthenticationDisable identifiers after a defined period of inactivity.DerivedIT Operations, Security Office, Data CustodianA.9.2.1
3.5.7Identification and AuthenticationEnforce a minimum password complexity and change of characters when new passwords are created.DerivedIT OperationsA.9.2.1, A.9.2.4, A.9.3.1, A.9.4.3
3.5.8Identification and AuthenticationProhibit password reuse for a specified number of generations.DerivedIT OperationsA.9.2.1, A.9.2.4, A.9.3.1, A.9.4.3
3.5.9Identification and AuthenticationAllow temporary password use for system logons with an immediate change to a permanent password.DerivedIT OperationsA.9.2.1, A.9.2.4, A.9.3.1, A.9.4.3
3.5.10Identification and AuthenticationStore and transmit only encrypted representation of passwords.DerivedIT Operations, Security Office, Data CustodianA.9.2.1, A.9.2.4, A.9.3.1, A.9.4.3
3.5.11Identification and AuthenticationObscure feedback of authentication information.DerivedIT Operations, Security Office, Data CustodianA.9.2.1, A.9.2.4, A.9.3.1, A.9.4.3
3.6.1Incident ResponseEstablish an operational incident-handling capability for organizational information systems that includes adequate preparation, detection, analysis, containment, recovery, and user response activities.BasicSecurity OfficeA.6.1.3, A.7.2.2 (ISO Control doesn't completely match NIST 800-53), A.16.1.2, A.16.1.4, A.16.1.5, A.16.1.6
3.6.2Incident ResponseTrack, document, and report incidents to appropriate officials and/or authorities both internal and external to the organization.BasicSecurity OfficeNone
3.6.3Incident ResponseTest the organizational incident response capability.DerivedSecurity OfficeNone
3.7.1MaintenancePerform maintenance on organizational information systems.BasicIT OperationsA.11.2.4, A.11.2.5 (ISO Controls don't completely match NIST 800-53)
3.7.2MaintenanceProvide effective controls on the tools, techniques, mechanisms, and personnel used to conduct information system maintenance.BasicIT OperationsA.11.2.4, A.11.2.5 (ISO Controls don't completely match NIST 800-53)
3.7.3MaintenanceEnsure equipment removed for off-site maintenance is sanitized of any CUI.DerivedData CustodianA.11.2.4, A.11.2.5 (ISO Controls don't completely match NIST 800-53)
3.7.4MaintenanceCheck media containing diagnostic and test programs for malicious code before the media are used in the information system.DerivedData CustodianNone
3.7.5MaintenanceRequire multifactor authentication to establish nonlocal maintenance sessions via external network connections and terminate such connections when nonlocal maintenance is complete.DerivedData CustodianNone
3.7.6MaintenanceSupervise the maintenance activities of maintenance personnel without required access authorization.DerivedData CustodianNone
3.8.1Media ProtectionProtect (i.e., physically control and securely store) information system media containing CUI, both paper and digital.BasicData CustodianA.8.2.3, A.8.3.1, A.8.3.2, A.11.2.7, A.11.2.9
3.8.2Media ProtectionLimit access to CUI on information system media to authorized users.BasicData CustodianA.8.2.3, A.8.3.1, A.8.3.2, A.11.2.7, A.11.2.9
3.8.3Media ProtectionSanitize or destroy information system media containing CUI before disposal or release for reuse.BasicIT Operations, Security Office, Data CustodianA.8.2.3, A.8.3.1, A.8.3.2, A.11.2.7, A.11.2.9
3.8.4Media ProtectionMark media with necessary CUI markings and distribution limitations.DerivedData CustodianA.8.2.2
3.8.5Media ProtectionControl access to media containing CUI and maintain accountability for media during transport outside of controlled areas.DerivedData CustodianA.8.2.3, A.8.3.1, A.8.3.3, A.11.2.5, A.11.2.6
3.8.6Media ProtectionImplement cryptographic mechanisms to protect the confidentiality of CUI stored on digital media during transport unless otherwise protected by alternative physical safeguards.DerivedData CustodianA.8.2.3, A.8.3.1, A.8.3.3, A.11.2.5, A.11.2.6
3.8.7Media ProtectionControl the use of removable media on information system components.DerivedData CustodianA.8.2.3, A.8.3.1
3.8.8Media ProtectionProhibit the use of portable storage devices when such devices have no identifiable owner.DerivedData CustodianA.8.2.3, A.8.3.1
3.8.9Media ProtectionProtect the confidentiality of backup CUI at storage locations.DerivedData CustodianA.12.3.1, A.17.1.2, A.18.1.3
3.9.1Personnel SecurityScreen individuals prior to authorizing access to information systems containing CUI.BasicData CustodianA.7.1.1, A.7.3.1, A.8.1.4
3.9.2Personnel SecurityEnsure that CUI and information systems containing CUI are protected during and after personnel actions such as terminations and transfers.BasicData CustodianA.7.1.1, A.7.3.1, A.8.1.4
3.10.1Physical ProtectionLimit physical access to organizational information systems, equipment, and the respective operating environments to authorized individuals.BasicIT OperationsA.11.1.2, A.11.1.3
3.10.2Physical ProtectionProtect and monitor the physical facility and support infrastructure for those information systems.BasicIT OperationsA.11.1.2, A.11.1.3
3.10.3Physical ProtectionEscort visitors and monitor visitor activity.DerivedIT OperationsA.11.1.1, A.11.1.2, A.11.1.3
3.10.4Physical ProtectionMaintain audit logs of physical access.DerivedIT OperationsA.11.1.1, A.11.1.2, A.11.1.3
3.10.5Physical ProtectionControl and manage physical access devices.DerivedIT OperationsA.11.1.1, A.11.1.2, A.11.1.3
3.10.6Physical ProtectionEnforce safeguarding measures for CUI at alternate work sites (e.g., telework sites).DerivedIT OperationsA.6.2.2, A.11.2.6, A.13.2.1
3.11.1Risk AssessmentPeriodically assess the risk to organizational operations (including mission, functions, image, or reputation), organizational assets, and individuals, resulting from the operation of organizational information systems and the associated processing, storage, or transmission of CUI.BasicData Custodian, Security OfficeA.12.6.1 (ISO control doesn't completely match NIST 800-53)
3.11.2Risk AssessmentScan for vulnerabilities in the information system and applications periodically and when new vulnerabilities affecting the system are identified.DerivedSecurity OfficeA.12.6.1 (ISO control doesn't completely match NIST 800-53)
3.11.3Risk AssessmentRemediate vulnerabilities in accordance with assessments of risk.DerivedData Custodian, IT OperationsA.12.6.1 (ISO control doesn't completely match NIST 800-53)
3.12.1Security AssessmentPeriodically assess the security controls in organizational information systems to determine if the controls are effective in their application.BasicSecurity OfficeA.14.2.8, A.18.2.2, A.18.2.3 (for CA-2 only)
3.12.2Security AssessmentDevelop and implement plans of action designed to correct deficiencies and reduce or eliminate vulnerabilities in organizational information systems.BasicSecurity OfficeA.14.2.8, A.18.2.2, A.18.2.3 (for CA-2 only)
3.12.3Security AssessmentMonitor information system security controls on an ongoing basis to ensure the continued effectiveness of the controls.BasicSecurity OfficeA.14.2.8, A.18.2.2, A.18.2.3 (for CA-2 only)
3.13.1System and Communications ProtectionMonitor, control, and protect organizational communications (i.e., information transmitted or received by organizational information systems) at the external boundaries and key internal boundaries of the information systems.BasicIT OperationsA.8.2.3, A.13.1.1, A.13.1.3, A.13.2.1, A.13.2.3, A.14.1.2, A.14.1.3
3.13.2System and Communications ProtectionEmploy architectural designs, software development techniques, and systems engineering principles that promote effective information security within organizational information systems.BasicIT OperationsA.13.1.1, A.13.1.3, A.13.2.1, A.14.1.3, A.14.2.5
3.13.3System and Communications ProtectionSeparate user functionality from information system management functionality.DerivedIT OperationsNone
3.13.4System and Communications ProtectionPrevent unauthorized and unintended information transfer via shared system resources.DerivedIT OperationsNone
3.13.5System and Communications ProtectionImplement subnetworks for publicly accessible system components that are physically or logically separated from internal networks.DerivedIT OperationsA.13.1.1, A.13.1.3, A.13.2.1, A.14.1.3, A.14.2.5
3.13.6System and Communications ProtectionDeny network communications traffic by default and allow network communications traffic by exception (i.e., deny all, permit by exception).DerivedSecurity OfficeA.13.1.1, A.13.1.3, A.13.2.1, A.14.1.3
3.13.7System and Communications ProtectionPrevent remote devices from simultaneously establishing non-remote connections with the information system and communicating via some other connection to resources in external networks.DerivedIT OperationsA.13.1.1, A.13.1.3, A.13.2.1, A.14.1.3
3.13.8System and Communications ProtectionImplement cryptographic mechanisms to prevent unauthorized disclosure of CUI during transmission unless otherwise protected by alternative physical safeguards.DerivedIT OperationsA.8.2.3, A.13.1.1, A.13.2.1, A.13.2.3, A.14.1.2, A.14.1.3
3.13.9System and Communications ProtectionTerminate network connections associated with communications sessions at the end of the sessions or after a defined period of inactivity.DerivedIT OperationsA.13.1.1
3.13.10System and Communications ProtectionEstablish and manage cryptographic keys for cryptography employed in the information system;DerivedIT OperationsA.10.1.2
3.13.11System and Communications ProtectionEmploy FIPS-validated cryptography when used to protect the confidentiality of CUI.DerivedIT OperationsA.10.1.1, A.14.1.2, A.14.1.3, A.18.1.5
3.13.12System and Communications ProtectionProhibit remote activation of collaborative computing devices and provide indication of devices in use to users present at the device.DerivedIT OperationsA.13.2.1 (ISO control doesn't completely match NIST 800-53)
3.13.13System and Communications ProtectionControl and monitor the use of mobile code.DerivedIT OperationsNone
3.13.14System and Communications ProtectionControl and monitor the use of Voice over Internet Protocol (VoIP) technologies.DerivedIT OperationsNone
3.13.15System and Communications ProtectionProtect the authenticity of communications sessions.DerivedIT OperationsNone
3.13.16System and Communications ProtectionProtect the confidentiality of CUI at rest.DerivedIT OperationsA.8.2.3
3.14.1System and Information IntegrityIdentify, report, and correct information and information system flaws in a timely manner.BasicData CustodianA.6.1.4, A.12.2.1, A.12.6.1, A.14.2.2, A.14.2.3, A.16.1.3
3.14.2System and Information IntegrityProvide protection from malicious code at appropriate locations within organizational information systems.BasicData Custodian, Security OfficeA.6.1.4 (ISO control doesn't completely match NIST 800-53), A.12.2.1, A.12.6.1, A.14.2.2, A.14.2.3, A.16.1.3
3.14.3System and Information IntegrityMonitor information system security alerts and advisories and take appropriate actions in response.BasicData Custodian, Security OfficeA.6.1.4 (ISO control doesn't completely match NIST 800-53), A.12.2.1, A.12.6.1, A.14.2.2, A.14.2.3, A.16.1.3
3.14.4System and Information IntegrityUpdate malicious code protection mechanisms when new releases are available.DerivedData Custodian, Security OfficeA.12.2.1
3.14.5System and Information IntegrityPerform periodic scans of the information system and real-time scans of files from external sources as files are downloaded, opened, or executed.DerivedSecurity OfficeA.12.2.1
3.14.6System and Information IntegrityMonitor the information system including inbound and outbound communications traffic, to detect attacks and indicators of potential attacks.DerivedSecurity OfficeNone
3.14.7System and Information IntegrityIdentify unauthorized use of the information system.DerivedSecurity OfficeNone

HTC711-19-R-R004

App J - NIST.SP.800-171 - POAM

File details come from the government source that posted it. Updated .