| A | B | C | D | E | F | G | H | I | J | K | L | M | N | O | P | Q | R | S | T | U | V | W | X | Y | Z | |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
1 | Req ID | Category | Description | Requirement | Location | |||||||||||||||||||||
2 | R-2329 | Prefieldwork | Policies & Procedures to Support Security Practices | Prefieldwork | Main Office | |||||||||||||||||||||
3 | R-2330 | Prefieldwork | Network diagrams, data flow diagrams, system architecture documents | Prefieldwork | Main Office | |||||||||||||||||||||
4 | R-2331 | Prefieldwork | Description of the org's relationship with Controlled Unclassified Information (CUI), Federal Contract Information (FCI), Covered Defense Information (CDI). Locations of CUI/FCI/CDI. Types of CUI residing within the system. | Prefieldwork | Main Office | |||||||||||||||||||||
5 | R-2332 | Prefieldwork | List of IT/IS Managed Service Providers (MSPs), MSP contracts/SLAs/MSAs - if applicable | Prefieldwork | Main Office | |||||||||||||||||||||
6 | R-2333 | AC | Access control lists, role-based access control (RBAC), Active Directory dump, security groups, remote access lists, asset inventory list, authorized device list | AC.L2-3.1.1 | Main Office | |||||||||||||||||||||
7 | R-2334 | AC | Warning banner on [the information system] and [web application] | AC.L2-3.1.9 | Main Office | |||||||||||||||||||||
8 | R-2335 | AC | Configuration baselines for portable storage devices, encryption in use on portable storage devices and any other safeguards in use to protect portable storage devices, acceptable use policy | AC.L2-3.1.21 | Main Office | |||||||||||||||||||||
9 | R-2336 | AC | privileged/non-privileged user lists, info system monitoring tool(s) user lists, security groups, GPO dump, remote console access configurations, flow control policies, separation of duties, roles and responsibilities documents | AC.L2-3.1.2 | Main Office | |||||||||||||||||||||
10 | R-2337 | AC | AD users including privileged and non-privileged accounts, access control list, GPO dump, list of account types, birthright account privileges, privilege escalation procedures | AC.L2-3.1.5 | Main Office | |||||||||||||||||||||
11 | R-2338 | AC | AD users including privileged and non-privileged accounts, policy requiring the use of non-privilege accounts for non-security functions, tools monitoring privileged actions | AC.L2-3.1.6 | Main Office | |||||||||||||||||||||
12 | R-2339 | AC | GPO settings demonstrating invalid login attempt thresholds and account lockout | AC.L2-3.1.8 | Main Office | |||||||||||||||||||||
13 | R-2340 | AC | Session lock configuration and screen for [the information system] and [web application] | AC.L2-3.1.10 | Main Office | |||||||||||||||||||||
14 | R-2341 | AC | Wireless access policies and procedures; unless incorporated in the access control policies and procedures | AC.L2-3.1.16 | Main Office | |||||||||||||||||||||
15 | R-2342 | AC | Encryption services in use for wireless internet, procedures demonstrating how all types of users authenticate to wireless internet. WAN safeguards in place to prevent unauthorized access or man-in-the-middle attacks | AC.L2-3.1.17 | Main Office | |||||||||||||||||||||
16 | R-2343 | AC | Separation of Duties Matrix (SoD), information security roles and responsibilities | AC.L2-3.1.4 | Main Office | |||||||||||||||||||||
17 | R-2344 | AC | List of privileged functions to be audited via [SIEM tool]. GPO dump for non-privileged users, RBAC | AC.L2-3.1.7,SC.L2-3.13.2 | Main Office | |||||||||||||||||||||
18 | R-2345 | AC | GPO settings demonstrating account timeout, screenshot of session timeout, conditions resulting in session termination | AC.L2-3.1.11 | Main Office | |||||||||||||||||||||
19 | R-2346 | AC | Mobile Device Management configuration settings, MDM device list, MDM conditional access policies, user access agreements for mobile devices, demonstration of how mobile devices are configured for users | AC.L2-3.1.18 | Main Office | |||||||||||||||||||||
20 | R-2347 | AC | Settings/audit logs/evidence demonstrating how remote access is provisioned, monitored, and controlled. Evidence may include tickets, emails, and forms relevant to granting access to remote resources. | AC.L2-3.1.12 | Main Office | |||||||||||||||||||||
21 | R-2348 | AC | Firewalls rules, proxies, system configuration for encryption level of remote access technology (VPN, SSH, RDP, etc.) | AC.L2-3.1.13 | Main Office | |||||||||||||||||||||
22 | R-2349 | AC | List of all managed network access control points, network diagram displaying all network access control points | AC.L2-3.1.14 | Main Office | |||||||||||||||||||||
23 | R-2350 | AC | Remote access authorizations, security-relevant information to be accessed remotely, functions to be conducted remotely | AC.L2-3.1.15 | Main Office | |||||||||||||||||||||
24 | R-2351 | AC | List of external system connections and authorizations, external system connection specifications, flow control policies, system architecture documents, network diagrams, firewall rules, system interconnection agreements | AC.L2-3.1.20 | Main Office | |||||||||||||||||||||
25 | R-2352 | AC | Demo how publicly accessible content is managed including list of users authorized. Evidence that info posted on publicly accessible websites reviewed. Inappropriate info posted to publicly accessible websites reviewed. | AC.L2-3.1.22 | Main Office | |||||||||||||||||||||
26 | R-2353 | AC | Access control lists, firewall rules, flow control policies, external connection authorizations, CUI access authorizations, system interconnection agreements | AC.L2-3.1.3 | Main Office | |||||||||||||||||||||
27 | R-2354 | AC | Mobile Device Management configuration settings, encryption settings, MDM conditional access policies | AC.L2-3.1.19 | Main Office | |||||||||||||||||||||
28 | R-2355 | AU | Auditing/accountability for unique user, AD users privilege/non-privileged accounts, audit reports, role-based access control, list of authorized personnel that review/analyze info system audits, list of auditable events | AU.L2-3.3.2 | Main Office | |||||||||||||||||||||
29 | R-2356 | AU | Documentation demonstrating the auditable event review process, (e.g. tickets, emails notifying administrator to review defined auditable events, ticket documenting the administrator reviewing auditable events, unique logins | AU.L2-3.3.3 | Main Office | |||||||||||||||||||||
30 | R-2357 | AU | Alert sent from [SIEM tool] to [organization]-defined personnel, alert for audit log processing failure | AU.L2-3.3.4 | Main Office | |||||||||||||||||||||
31 | R-2358 | AU | Audit policy and procedures including types of auditing events, monitoring, logging, SIEM correlation rules | AU.L2-3.3.1 | Main Office | |||||||||||||||||||||
32 | R-2359 | AU | NTP configuration demonstrating synchronization with external time source to NIST timeclock via primary domain controller, NTP configuration demonstrating how often time synchronization with external time source occurs | AU.L2-3.3.7 | Main Office | |||||||||||||||||||||
33 | R-2360 | AU | A walkthrough of demonstrating how audit log information are protected | AU.L2-3.3.8 | Main Office | |||||||||||||||||||||
34 | R-2361 | AU | List of privileged users with auditing capabilities, RBAC | AU.L2-3.3.9 | Main Office | |||||||||||||||||||||
35 | R-2362 | AU | SIEM tools, audit log correlation, dashboard of automated tools for auditing and monitoring, list of log input and output to SIEM tools, audit record retention configuration(s) | AU.L2-3.3.5 | Main Office | |||||||||||||||||||||
36 | R-2363 | AU | SIEM tool report output | AU.L2-3.3.6 | Main Office | |||||||||||||||||||||
37 | R-2364 | AT | Content of security awareness and training program, acceptable use policy with employee signature, rules of behavior, CUI/CDI/FCI related training | AT.L2-3.2.1 | Main Office | |||||||||||||||||||||
38 | R-2365 | AT | Security awareness and training program that includes insider threat, training records | AT.L2-3.2.3 | Main Office | |||||||||||||||||||||
39 | R-2366 | AT | Security awareness and training records, rules of behavior acknowledgement, acceptable use policy, role-based security training, information security training for executives | AT.L2-3.2.2 | Main Office | |||||||||||||||||||||
40 | R-2367 | CM | Screenshots/evidence demonstrating how configuration baselines for all system components are managed (created, updated, deleted). Evidence may include items such as configuration baselines and asset inventory list. | CM.L2-3.4.1 | Main Office | |||||||||||||||||||||
41 | R-2368 | CM | Review of unnecessary or insecure ports, protocols and services, CIS benchmark, SCAP scan reports, evidence that system components are configured according to the principle of least functionality | CM.L2-3.4.6 | Main Office | |||||||||||||||||||||
42 | R-2369 | CM | Tool in place to monitor and prevent the install of software, GPO policies | CM.L2-3.4.9 | Main Office | |||||||||||||||||||||
43 | R-2370 | CM | SCAP and Nessus validated scans/reports, CIS benchmark, STIG scans | CM.L2-3.4.2 | Main Office | |||||||||||||||||||||
44 | R-2371 | CM | Change Control Board meeting minutes, change requests (approvals and denials), change tickets | CM.L2-3.4.3 | Main Office | |||||||||||||||||||||
45 | R-2372 | CM | Security impact analysis and any related documentation (e.g. tickets, emails, forms, meeting minutes, scan output), change tickets/requests with analysis | CM.L2-3.4.4 | Main Office | |||||||||||||||||||||
46 | R-2373 | CM | Documented approval of changes that impacted logical or physical access restrictions, configuration management plan | CM.L2-3.4.5 | Main Office | |||||||||||||||||||||
47 | R-2374 | CM | Software program usage policies and restrictions, approved/denied software lists, CIS benchmark, SCAP scan results | CM.L2-3.4.7 | Main Office | |||||||||||||||||||||
48 | R-2375 | CM | Firewall rules, whitelisting and blacklisting of software, evidence of reviews and updates of the list of authorized software programs | CM.L2-3.4.8 | Main Office | |||||||||||||||||||||
49 | R-2376 | IA | Walkthrough how identifiers are created, updated, and deleted. Access control lists, role-based access control (RBAC), Active Directory user list, security groups. | IA.L2-3.5.1 | Main Office | |||||||||||||||||||||
50 | R-2377 | IA | Multifactor authentication walkthrough, listing of types of authenticators (username, password, security token, hardware token, soft token, etc.) | IA.L2-3.5.2 | Main Office | |||||||||||||||||||||
51 | R-2378 | IA | Password policy and GPO password configurations, change of character requirements | IA.L2-3.5.7 | Main Office | |||||||||||||||||||||
52 | R-2379 | IA | Password policy and GPO password configurations, password history config | IA.L2-3.5.8 | Main Office | |||||||||||||||||||||
53 | R-2380 | IA | Temporary password configurations, account activation email with temporary password, procedures for changing a temporary password upon first logon | IA.L2-3.5.9 | Main Office | |||||||||||||||||||||
54 | R-2381 | IA | Password hashing/encryption configurations, Windows SAM file and or /etc./shadow | IA.L2-3.5.10 | Main Office | |||||||||||||||||||||
55 | R-2382 | IA | Screenshots of login masking and error messages that obscure passwords | IA.L2-3.5.11 | Main Office | |||||||||||||||||||||
56 | R-2383 | IA | Listing of the types of access requiring MFA, multifactor authentication network access for privileged and non-privileged accounts, demonstrate the logon process using MFA | IA.L2-3.5.3 | Main Office | |||||||||||||||||||||
57 | R-2384 | IA | Configuration for replay resistant authentication (multifactor authentication via token) for network access to privileged accounts and non-privileged accounts | IA.L2-3.5.4 | Main Office | |||||||||||||||||||||
58 | R-2385 | IA | GPO settings (min and max life configuration) for usernames, identifier reuse policy/description | IA.L2-3.5.5 | Main Office | |||||||||||||||||||||
59 | R-2386 | IA | Walkthrough demonstrating the disabling of inactive accounts after an organizationally-defined period. GPO settings (min and max life configuration) for usernames, GPO policy for identifiers | IA.L2-3.5.6 | Main Office | |||||||||||||||||||||
60 | R-2387 | IR | Incident response plan/capabilities, IR policies and procedures, incident handling process | IR.L2-3.6.1 | Main Office | |||||||||||||||||||||
61 | R-2388 | IR | IR tickets, IR notifications (internally and externally), contingency plan, coordination of incident handling with contingency planning team and security personnel | IR.L2-3.6.2 | Main Office | |||||||||||||||||||||
62 | R-2389 | IR | IR training, tabletop exercises, lessons learned | IR.L2-3.6.3 | Main Office | |||||||||||||||||||||
63 | R-2390 | MA | Organization's maintenance process | MA.L2-3.7.1 | Main Office | |||||||||||||||||||||
64 | R-2391 | MA | Maintenance tickets, list of maintenance tools, list of authorized maintenance personnel, maintenance policy and procedures | MA.L2-3.7.2 | Main Office | |||||||||||||||||||||
65 | R-2392 | MA | Non-local maintenance procedures | MA.L2-3.7.5 | Main Office | |||||||||||||||||||||
66 | R-2393 | MA | Listing of external orgs that perform system maintenance, listing of individuals from external organizations that perform system maintenance, demo of external maintenance process, SLA, physical access logs, escort list | MA.L2-3.7.6 | Main Office | |||||||||||||||||||||
67 | R-2394 | MA | Off-site maintenance process and procedures, vendor agreement with "keep your own hard drive" clause, sanitization process | MA.L2-3.7.3 | Main Office | |||||||||||||||||||||
68 | R-2395 | MA | Maintain policy and procedures, sanitization of media process, anti-virus/malware scan reports | MA.L2-3.7.4 | Main Office | |||||||||||||||||||||
69 | R-2396 | MP | Media marking, tracking, distribution limitations | MP.L2-3.8.4 | Main Office | |||||||||||||||||||||
70 | R-2397 | MP | All safeguards in place for protecting paper/digital media containing Federal Contract Information (Passwords, authenticators, keys, encryption, spec manuals demonstrating how removable media is protected), media marking | MP.L2-3.8.1 | Main Office | |||||||||||||||||||||
71 | R-2398 | MP | Access control list, all safeguards in place for protecting system media (Passwords, authenticators, keys, encryption, spec manuals demonstrating how removable media is protected), access list of authorize CUI users | MP.L2-3.8.2 | Main Office | |||||||||||||||||||||
72 | R-2399 | MP | Comprehensive listing of digital and non-digital media permitted for use on the system, demo of how media usage is restricted to specific personnel, and restriction of media usage to certain system components | MP.L2-3.8.7 | Main Office | |||||||||||||||||||||
73 | R-2400 | MP | Access policy and procedure for use of portable devices with no identifiable owner, acceptable use policy | MP.L2-3.8.8 | Main Office | |||||||||||||||||||||
74 | R-2401 | MP | Destruction certificate from media destruction entity, receipt showing media destroyed, walkthrough of media destruction process, maintenance policy and procedures | MP.L2-3.8.3 | Main Office | |||||||||||||||||||||
75 | R-2402 | MP | Evidence demonstrating how media is transported; receipts showing an approved carrier was used; SLA. | MP.L2-3.8.5 | Main Office | |||||||||||||||||||||
76 | R-2403 | MP | Cryptographic ciphers/mechanisms/standards in use for when media is transported outside of controlled areas, maintenance policy and procedures | MP.L2-3.8.6 | Main Office | |||||||||||||||||||||
77 | R-2404 | PS | Sample of employee background check and rescreening procedures, background check status report | PS.L2-3.9.1 | Main Office | |||||||||||||||||||||
78 | R-2405 | PS | Evidence / walkthrough demonstrating the employee transfer and termination process. Evidence may include employee transfer checklist, equipment retention forms, tickets and notification emails. | PS.L2-3.9.2 | Main Office | |||||||||||||||||||||
79 | R-2406 | PE | Complete listing of personnel with authorized badge access generated via the physical access software, including access to communication equipment or closets, physical access log | PE.L2-3.10.1 | Main Office | |||||||||||||||||||||
80 | R-2407 | PE | MSA, SLA, or contracts with any third party security contractors related to colocation services, visitor sign-in logs | PE.L2-3.10.3 | Main Office | |||||||||||||||||||||
81 | R-2408 | PE | Sample of physical access audit logs, asset listing of all components managing physical access control | PE.L2-3.10.4 | Main Office | |||||||||||||||||||||
82 | R-2409 | PE | Asset listing of all components managing physical access control | PE.L2-3.10.5 | Main Office | |||||||||||||||||||||
83 | R-2410 | PE | Evidence demonstrating the phys facility/support infra are protected/monitored. Evidence includes confirmations for alarm software console, configs for monitoring software, logs of successful/unsuccessful access attempts. | PE.L2-3.10.2 | Main Office | |||||||||||||||||||||
84 | R-2411 | PE | Organization's alternate work site including security controls in place there (such as physical and logical access, physical security, WAN, and LAN). SLAs related to alternate work site. | PE.L2-3.10.6 | Main Office | |||||||||||||||||||||
85 | R-2412 | RE | Backup and data protection software configurations, backup procedures | MP.L2-3.8.9 | Main Office | |||||||||||||||||||||
86 | R-2413 | RM | Evidence of review and update of the risk assessment periodically and when there are changes to the information system, revision history table, emails, tickets, risk assessment policy and procedures, previous SARs, POAM | RA.L2-3.11.1 | Main Office | |||||||||||||||||||||
87 | R-2414 | RM | Evidence demonstrating vuln scanning process (org systems and applications), scan results, evidence that privileged access authorization are implemented for vuln scanning activities, sec groups configured for vul scan admins | RA.L2-3.11.2 | Main Office | |||||||||||||||||||||
88 | R-2415 | RM | Demonstration of vuln remediation process & tickets, docs demonstrating Security Control Assessments being analyzed, POAM (open/closed items), vulnerability scan reports/output (for both the system and hosted applications) | RA.L2-3.11.3 | Main Office | |||||||||||||||||||||
89 | R-2416 | CA | SSP, system diagram, data flow diagram | CA.L2-3.12.4 | Main Office | |||||||||||||||||||||
90 | R-2417 | CA | security assessment policy and procedures, security assessment plan, previous security assessment reports | CA.L2-3.12.1 | Main Office | |||||||||||||||||||||
91 | R-2418 | CA | POAM (open and close items) | CA.L2-3.12.2 | Main Office | |||||||||||||||||||||
92 | R-2419 | CA | POAM (open and close items), ConMon Plan, vulnerability scan reports, incident reports | CA.L2-3.12.3 | Main Office | |||||||||||||||||||||
93 | R-2420 | SC | List of networked collaborative computing devices (CCTV, Printer, Scanner, microphone) and evidence that they cannot be remotely activated | SC.L2-3.13.12 | Main Office | |||||||||||||||||||||
94 | R-2421 | SC | GPO forcing the use of FIPS-validated crypto, list of cryptography used | SC.L2-3.13.11 | Main Office | |||||||||||||||||||||
95 | R-2423 | SC | Evidence that [the information system] isolates management functionality from user functionality via subnetting, VLANs, access control and firewall configurations, remote access, RBAC | SC.L2-3.13.3 | Main Office | |||||||||||||||||||||
96 | R-2424 | SC | Evidence that shared systems remove information after session logout, session timeout configurations, tenant isolation, blocking FTP protocols, Residual Information Protection (RIP) | SC.L2-3.13.4 | Main Office | |||||||||||||||||||||
97 | R-2425 | SC | Firewall configuration settings (deny-all, allow by exception) | SC.L2-3.13.6 | Main Office | |||||||||||||||||||||
98 | R-2426 | SC | Evidence that split tunnel is disabled, remote access policy, VPN configurations | SC.L2-3.13.7 | Main Office | |||||||||||||||||||||
99 | R-2427 | SC | Evidence of employing protection for transmitted information via VPN, SSL/TLS and other methodologies, evidence of a hardened or alarmed carrier Protective Distribution System (PDS) | SC.L2-3.13.8 | Main Office | |||||||||||||||||||||
100 | R-2428 | SC | Evidence of manual network disconnect at the termination of a session. Evidence of network disconnect due to inactive session. Evidence of employing a "logout" button. | SC.L2-3.13.9 | Main Office |