ABCDEFGHIJKLMNOPQRSTUVWXYZ
1
Req IDCategoryDescriptionRequirementLocation
2
R-2329PrefieldworkPolicies & Procedures to Support Security PracticesPrefieldworkMain Office
3
R-2330PrefieldworkNetwork diagrams, data flow diagrams, system architecture documentsPrefieldworkMain Office
4
R-2331PrefieldworkDescription of the org's relationship with Controlled Unclassified Information (CUI), Federal Contract Information (FCI), Covered Defense Information (CDI). Locations of CUI/FCI/CDI. Types of CUI residing within the system.PrefieldworkMain Office
5
R-2332PrefieldworkList of IT/IS Managed Service Providers (MSPs), MSP contracts/SLAs/MSAs - if applicablePrefieldworkMain Office
6
R-2333ACAccess control lists, role-based access control (RBAC), Active Directory dump, security groups, remote access lists, asset inventory list, authorized device listAC.L2-3.1.1Main Office
7
R-2334ACWarning banner on [the information system] and [web application]AC.L2-3.1.9Main Office
8
R-2335ACConfiguration baselines for portable storage devices, encryption in use on portable storage devices and any other safeguards in use to protect portable storage devices, acceptable use policyAC.L2-3.1.21Main Office
9
R-2336ACprivileged/non-privileged user lists, info system monitoring tool(s) user lists, security groups, GPO dump, remote console access configurations, flow control policies, separation of duties, roles and responsibilities documentsAC.L2-3.1.2Main Office
10
R-2337ACAD users including privileged and non-privileged accounts, access control list, GPO dump, list of account types, birthright account privileges, privilege escalation proceduresAC.L2-3.1.5Main Office
11
R-2338ACAD users including privileged and non-privileged accounts, policy requiring the use of non-privilege accounts for non-security functions, tools monitoring privileged actionsAC.L2-3.1.6Main Office
12
R-2339ACGPO settings demonstrating invalid login attempt thresholds and account lockoutAC.L2-3.1.8Main Office
13
R-2340ACSession lock configuration and screen for [the information system] and [web application]AC.L2-3.1.10Main Office
14
R-2341ACWireless access policies and procedures; unless incorporated in the access control policies and proceduresAC.L2-3.1.16Main Office
15
R-2342ACEncryption services in use for wireless internet, procedures demonstrating how all types of users authenticate to wireless internet. WAN safeguards in place to prevent unauthorized access or man-in-the-middle attacksAC.L2-3.1.17Main Office
16
R-2343ACSeparation of Duties Matrix (SoD), information security roles and responsibilitiesAC.L2-3.1.4Main Office
17
R-2344ACList of privileged functions to be audited via [SIEM tool]. GPO dump for non-privileged users, RBACAC.L2-3.1.7,SC.L2-3.13.2Main Office
18
R-2345ACGPO settings demonstrating account timeout, screenshot of session timeout, conditions resulting in session terminationAC.L2-3.1.11Main Office
19
R-2346ACMobile Device Management configuration settings, MDM device list, MDM conditional access policies, user access agreements for mobile devices, demonstration of how mobile devices are configured for usersAC.L2-3.1.18Main Office
20
R-2347ACSettings/audit logs/evidence demonstrating how remote access is provisioned, monitored, and controlled. Evidence may include tickets, emails, and forms relevant to granting access to remote resources.AC.L2-3.1.12Main Office
21
R-2348ACFirewalls rules, proxies, system configuration for encryption level of remote access technology (VPN, SSH, RDP, etc.)AC.L2-3.1.13Main Office
22
R-2349ACList of all managed network access control points, network diagram displaying all network access control pointsAC.L2-3.1.14Main Office
23
R-2350ACRemote access authorizations, security-relevant information to be accessed remotely, functions to be conducted remotelyAC.L2-3.1.15Main Office
24
R-2351ACList of external system connections and authorizations, external system connection specifications, flow control policies, system architecture documents, network diagrams, firewall rules, system interconnection agreementsAC.L2-3.1.20Main Office
25
R-2352ACDemo how publicly accessible content is managed including list of users authorized. Evidence that info posted on publicly accessible websites reviewed. Inappropriate info posted to publicly accessible websites reviewed.AC.L2-3.1.22Main Office
26
R-2353ACAccess control lists, firewall rules, flow control policies, external connection authorizations, CUI access authorizations, system interconnection agreementsAC.L2-3.1.3Main Office
27
R-2354ACMobile Device Management configuration settings, encryption settings, MDM conditional access policiesAC.L2-3.1.19Main Office
28
R-2355AUAuditing/accountability for unique user, AD users privilege/non-privileged accounts, audit reports, role-based access control, list of authorized personnel that review/analyze info system audits, list of auditable eventsAU.L2-3.3.2Main Office
29
R-2356AUDocumentation demonstrating the auditable event review process, (e.g. tickets, emails notifying administrator to review defined auditable events, ticket documenting the administrator reviewing auditable events, unique loginsAU.L2-3.3.3Main Office
30
R-2357AUAlert sent from [SIEM tool] to [organization]-defined personnel, alert for audit log processing failureAU.L2-3.3.4Main Office
31
R-2358AUAudit policy and procedures including types of auditing events, monitoring, logging, SIEM correlation rulesAU.L2-3.3.1Main Office
32
R-2359AUNTP configuration demonstrating synchronization with external time source to NIST timeclock via primary domain controller, NTP configuration demonstrating how often time synchronization with external time source occursAU.L2-3.3.7Main Office
33
R-2360AUA walkthrough of demonstrating how audit log information are protectedAU.L2-3.3.8Main Office
34
R-2361AUList of privileged users with auditing capabilities, RBACAU.L2-3.3.9Main Office
35
R-2362AUSIEM tools, audit log correlation, dashboard of automated tools for auditing and monitoring, list of log input and output to SIEM tools, audit record retention configuration(s)AU.L2-3.3.5Main Office
36
R-2363AUSIEM tool report outputAU.L2-3.3.6Main Office
37
R-2364ATContent of security awareness and training program, acceptable use policy with employee signature, rules of behavior, CUI/CDI/FCI related trainingAT.L2-3.2.1Main Office
38
R-2365ATSecurity awareness and training program that includes insider threat, training recordsAT.L2-3.2.3Main Office
39
R-2366ATSecurity awareness and training records, rules of behavior acknowledgement, acceptable use policy, role-based security training, information security training for executivesAT.L2-3.2.2Main Office
40
R-2367CMScreenshots/evidence demonstrating how configuration baselines for all system components are managed (created, updated, deleted). Evidence may include items such as configuration baselines and asset inventory list.CM.L2-3.4.1Main Office
41
R-2368CMReview of unnecessary or insecure ports, protocols and services, CIS benchmark, SCAP scan reports, evidence that system components are configured according to the principle of least functionalityCM.L2-3.4.6Main Office
42
R-2369CMTool in place to monitor and prevent the install of software, GPO policiesCM.L2-3.4.9Main Office
43
R-2370CMSCAP and Nessus validated scans/reports, CIS benchmark, STIG scansCM.L2-3.4.2Main Office
44
R-2371CMChange Control Board meeting minutes, change requests (approvals and denials), change ticketsCM.L2-3.4.3Main Office
45
R-2372CMSecurity impact analysis and any related documentation (e.g. tickets, emails, forms, meeting minutes, scan output), change tickets/requests with analysisCM.L2-3.4.4Main Office
46
R-2373CMDocumented approval of changes that impacted logical or physical access restrictions, configuration management planCM.L2-3.4.5Main Office
47
R-2374CMSoftware program usage policies and restrictions, approved/denied software lists, CIS benchmark, SCAP scan resultsCM.L2-3.4.7Main Office
48
R-2375CMFirewall rules, whitelisting and blacklisting of software, evidence of reviews and updates of the list of authorized software programsCM.L2-3.4.8Main Office
49
R-2376IAWalkthrough how identifiers are created, updated, and deleted. Access control lists, role-based access control (RBAC), Active Directory user list, security groups.IA.L2-3.5.1Main Office
50
R-2377IAMultifactor authentication walkthrough, listing of types of authenticators (username, password, security token, hardware token, soft token, etc.)IA.L2-3.5.2Main Office
51
R-2378IAPassword policy and GPO password configurations, change of character requirementsIA.L2-3.5.7Main Office
52
R-2379IAPassword policy and GPO password configurations, password history configIA.L2-3.5.8Main Office
53
R-2380IATemporary password configurations, account activation email with temporary password, procedures for changing a temporary password upon first logonIA.L2-3.5.9Main Office
54
R-2381IAPassword hashing/encryption configurations, Windows SAM file and or /etc./shadowIA.L2-3.5.10Main Office
55
R-2382IAScreenshots of login masking and error messages that obscure passwordsIA.L2-3.5.11Main Office
56
R-2383IAListing of the types of access requiring MFA, multifactor authentication network access for privileged and non-privileged accounts, demonstrate the logon process using MFAIA.L2-3.5.3Main Office
57
R-2384IAConfiguration for replay resistant authentication (multifactor authentication via token) for network access to privileged accounts and non-privileged accountsIA.L2-3.5.4Main Office
58
R-2385IAGPO settings (min and max life configuration) for usernames, identifier reuse policy/descriptionIA.L2-3.5.5Main Office
59
R-2386IAWalkthrough demonstrating the disabling of inactive accounts after an organizationally-defined period. GPO settings (min and max life configuration) for usernames, GPO policy for identifiersIA.L2-3.5.6Main Office
60
R-2387IRIncident response plan/capabilities, IR policies and procedures, incident handling processIR.L2-3.6.1Main Office
61
R-2388IRIR tickets, IR notifications (internally and externally), contingency plan, coordination of incident handling with contingency planning team and security personnelIR.L2-3.6.2Main Office
62
R-2389IRIR training, tabletop exercises, lessons learnedIR.L2-3.6.3Main Office
63
R-2390MAOrganization's maintenance processMA.L2-3.7.1Main Office
64
R-2391MAMaintenance tickets, list of maintenance tools, list of authorized maintenance personnel, maintenance policy and proceduresMA.L2-3.7.2Main Office
65
R-2392MANon-local maintenance proceduresMA.L2-3.7.5Main Office
66
R-2393MAListing of external orgs that perform system maintenance, listing of individuals from external organizations that perform system maintenance, demo of external maintenance process, SLA, physical access logs, escort listMA.L2-3.7.6Main Office
67
R-2394MAOff-site maintenance process and procedures, vendor agreement with "keep your own hard drive" clause, sanitization processMA.L2-3.7.3Main Office
68
R-2395MAMaintain policy and procedures, sanitization of media process, anti-virus/malware scan reportsMA.L2-3.7.4Main Office
69
R-2396MPMedia marking, tracking, distribution limitationsMP.L2-3.8.4Main Office
70
R-2397MPAll safeguards in place for protecting paper/digital media containing Federal Contract Information (Passwords, authenticators, keys, encryption, spec manuals demonstrating how removable media is protected), media markingMP.L2-3.8.1Main Office
71
R-2398MPAccess control list, all safeguards in place for protecting system media (Passwords, authenticators, keys, encryption, spec manuals demonstrating how removable media is protected), access list of authorize CUI usersMP.L2-3.8.2Main Office
72
R-2399MPComprehensive listing of digital and non-digital media permitted for use on the system, demo of how media usage is restricted to specific personnel, and restriction of media usage to certain system componentsMP.L2-3.8.7Main Office
73
R-2400MPAccess policy and procedure for use of portable devices with no identifiable owner, acceptable use policyMP.L2-3.8.8Main Office
74
R-2401MPDestruction certificate from media destruction entity, receipt showing media destroyed, walkthrough of media destruction process, maintenance policy and proceduresMP.L2-3.8.3Main Office
75
R-2402MPEvidence demonstrating how media is transported; receipts showing an approved carrier was used; SLA.MP.L2-3.8.5Main Office
76
R-2403MPCryptographic ciphers/mechanisms/standards in use for when media is transported outside of controlled areas, maintenance policy and proceduresMP.L2-3.8.6Main Office
77
R-2404PSSample of employee background check and rescreening procedures, background check status reportPS.L2-3.9.1Main Office
78
R-2405PSEvidence / walkthrough demonstrating the employee transfer and termination process. Evidence may include employee transfer checklist, equipment retention forms, tickets and notification emails.PS.L2-3.9.2Main Office
79
R-2406PEComplete listing of personnel with authorized badge access generated via the physical access software, including access to communication equipment or closets, physical access logPE.L2-3.10.1Main Office
80
R-2407PEMSA, SLA, or contracts with any third party security contractors related to colocation services, visitor sign-in logsPE.L2-3.10.3Main Office
81
R-2408PESample of physical access audit logs, asset listing of all components managing physical access controlPE.L2-3.10.4Main Office
82
R-2409PEAsset listing of all components managing physical access controlPE.L2-3.10.5Main Office
83
R-2410PEEvidence demonstrating the phys facility/support infra are protected/monitored. Evidence includes confirmations for alarm software console, configs for monitoring software, logs of successful/unsuccessful access attempts.PE.L2-3.10.2Main Office
84
R-2411PEOrganization's alternate work site including security controls in place there (such as physical and logical access, physical security, WAN, and LAN). SLAs related to alternate work site.PE.L2-3.10.6Main Office
85
R-2412REBackup and data protection software configurations, backup proceduresMP.L2-3.8.9Main Office
86
R-2413RMEvidence of review and update of the risk assessment periodically and when there are changes to the information system, revision history table, emails, tickets, risk assessment policy and procedures, previous SARs, POAMRA.L2-3.11.1Main Office
87
R-2414RMEvidence demonstrating vuln scanning process (org systems and applications), scan results, evidence that privileged access authorization are implemented for vuln scanning activities, sec groups configured for vul scan adminsRA.L2-3.11.2Main Office
88
R-2415RMDemonstration of vuln remediation process & tickets, docs demonstrating Security Control Assessments being analyzed, POAM (open/closed items), vulnerability scan reports/output (for both the system and hosted applications)RA.L2-3.11.3Main Office
89
R-2416CASSP, system diagram, data flow diagramCA.L2-3.12.4Main Office
90
R-2417CAsecurity assessment policy and procedures, security assessment plan, previous security assessment reportsCA.L2-3.12.1Main Office
91
R-2418CAPOAM (open and close items)CA.L2-3.12.2Main Office
92
R-2419CAPOAM (open and close items), ConMon Plan, vulnerability scan reports, incident reportsCA.L2-3.12.3Main Office
93
R-2420SCList of networked collaborative computing devices (CCTV, Printer, Scanner, microphone) and evidence that they cannot be remotely activatedSC.L2-3.13.12Main Office
94
R-2421SCGPO forcing the use of FIPS-validated crypto, list of cryptography usedSC.L2-3.13.11Main Office
95
R-2423SCEvidence that [the information system] isolates management functionality from user functionality via subnetting, VLANs, access control and firewall configurations, remote access, RBACSC.L2-3.13.3Main Office
96
R-2424SCEvidence that shared systems remove information after session logout, session timeout configurations, tenant isolation, blocking FTP protocols, Residual Information Protection (RIP)SC.L2-3.13.4Main Office
97
R-2425SCFirewall configuration settings (deny-all, allow by exception)SC.L2-3.13.6Main Office
98
R-2426SCEvidence that split tunnel is disabled, remote access policy, VPN configurationsSC.L2-3.13.7Main Office
99
R-2427SCEvidence of employing protection for transmitted information via VPN, SSL/TLS and other methodologies, evidence of a hardened or alarmed carrier Protective Distribution System (PDS)SC.L2-3.13.8Main Office
100
R-2428SCEvidence of manual network disconnect at the termination of a session. Evidence of network disconnect due to inactive session. Evidence of employing a "logout" button.SC.L2-3.13.9Main Office