| A | B | C | D | E | F | |
|---|---|---|---|---|---|---|
1 | ||||||
2 | Title | Description | NIST 800-171 | NIST 800-171 Numerical Reference | NIST 800-53 Numerical Reference | NIST 800-53 Domain |
3 | Workstation Lockout | Internal users' screensavers are configured to lock after a specified period of time of inactivity and require a password to unlock. | Access Control, Access Control, Access Control, System and Communications Protection | 03.01.10.[a], 03.01.10.[b], 03.01.10.[c], 03.13.15.[] | AC-11(), IA-11() | ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION |
4 | Configuration Standards | A baseline security configuration is maintained by the information technology team and is deployed to all systems upon installation or upgrade. The configuration is reviewed at least annually or when there has been a significant change. The prior baseline configuration is also maintained for use in emergency rollback. | Configuration Management, Configuration Management | 03.04.01.[a], 03.04.02.[a] | CM-6(), SA-10(), CM-2(), SA-5() | CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION, CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION |
5 | Restrict Software Install | The ability to install applications on end-user machines is restricted per centralized device management settings. | Configuration Management, Configuration Management | 03.04.08.[b], 03.04.08.[c] | CM-5(), CM-7(), CM-11(), CM-14() | CONFIGURATION MANAGEMENT, CONFIGURATION MANAGEMENT, CONFIGURATION MANAGEMENT, CONFIGURATION MANAGEMENT |
6 | Data Flow Diagram | The data flow diagram is maintained and highlights the systems that require logical access controls per data classification level. The data flow diagram is updated annually or as business needs require. | Access Control, Configuration Management | 03.01.03.[], 03.04.11.[a] | AC-4(), AC-17(), AC-18(), AC-19(), AC-20(), CM-13(), PE-17(), SC-7(), SC-8(), SC-15() | ACCESS CONTROL, ACCESS CONTROL, ACCESS CONTROL, ACCESS CONTROL, ACCESS CONTROL, CONFIGURATION MANAGEMENT, PHYSICAL AND ENVIRONMENTAL PROTECTION, SYSTEM AND COMMUNICATIONS PROTECTION, SYSTEM AND COMMUNICATIONS PROTECTION, SYSTEM AND COMMUNICATIONS PROTECTION |
7 | Acceptable Use Policy | All staff sign an Acceptable Use Policy, which outlines rules for the acceptable use of information associated with information and information processing, as well as, appropriate procedures for compliance with legislative, regulatory, and contractual requirements related to proprietary software services. | Planning, Planning, Planning | 03.15.03.[a], 03.15.03.[c], 03.15.03.[d] | PL-4() | PLANNING |
8 | Policy Review | IT security related policies are reviewed and approved annually or as business needs change. Procedure documents related to access control, change management, and incident management are updated as processes change. | Planning | 03.15.01.[b] | AU-1(), CA-2() | AUDIT AND ACCOUNTABILITY, SECURITY ASSESSMENT AND AUTHORIZATION |
9 | Security Training | Employees and contractors complete security-related training, as relevant to their duties, upon hire and on an annual basis. The annual security training includes information on how to report security incidents and concerns. The training includes topics specific to different roles depending on participants' access to sensitive data. | Awareness and Training, Awareness and Training, Incident Response, Incident Response | 03.02.01.[a], 03.02.01.[b], 03.06.04.[a], 03.06.04.[b] | AT-2(), AT-3(), AT-4(), IR-2() | AWARENESS AND TRAINING, AWARENESS AND TRAINING, AWARENESS AND TRAINING, INCIDENT RESPONSE |
10 | Asset Inventory | An inventory of information assets, including hardware and software, is maintained and updated at least annually. All assets have an assigned asset owner. All assets are classified based on the data classification convention. | Configuration Management, Configuration Management, Configuration Management | 03.04.10.[a], 03.04.10.[b], 03.04.10.[c] | CM-8(), PM-5() | CONFIGURATION MANAGEMENT, PROGRAM MANAGEMENT |
11 | Vulnerability Scan | Vulnerability scans are performed quarterly to help identify security risks. Results are assessed and, where required, remediated. | Risk Assessment, Risk Assessment, Risk Assessment | 03.11.02.[a], 03.11.02.[b], 03.11.02.[c] | RA-5(), SI-2() | RISK ASSESSMENT, SYSTEM AND INFORMATION INTEGRITY |
12 | Intrusion Detection | Threat detection tools are utilized to monitor and log possible or actual network breaches and other anomalous security events. Alerting occurs on threats and results are actioned as appropriate. | System and Information Integrity | 03.14.06.[a] | AC-3(), AC-17(), AC-18(), AC-20(), SC-7(), SC-8(), SC-10(), SI-4() | ACCESS CONTROL, ACCESS CONTROL, ACCESS CONTROL, ACCESS CONTROL, SYSTEM AND COMMUNICATIONS PROTECTION, SYSTEM AND COMMUNICATIONS PROTECTION, SYSTEM AND COMMUNICATIONS PROTECTION, SYSTEM AND INFORMATION INTEGRITY |
13 | Logical Access Policy | Logical Access Policy and Procedures are in place which define the authorization, modification, removal of access, secure authentication requirements, and the principle of least privilege. The policy is reviewed annually. | Access Control, Access Control, Access Control, Access Control, Configuration Management, Identification and Authentication, Identification and Authentication, Identification and Authentication | 03.01.01.[b], 03.01.05.[a], 03.01.05.[b], 03.01.11.[], 03.04.05.[], 03.05.02.[], 03.05.04.[], 03.05.11.[] | AC-1(), AC-3(), IA-1(), IA-6(), PS-5() | ACCESS CONTROL, ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, IDENTIFICATION AND AUTHENTICATION, PERSONNEL SECURITY |
14 | User Authentication | Unique usernames and passwords are required to authenticate all users. Users must use non-privileged accounts or roles when accessing non-security functions, and any shared accounts must be approved by the head of IT. | Access Control, Access Control, Identification and Authentication, Identification and Authentication, Identification and Authentication, Identification and Authentication | 03.01.01.[c], 03.01.06.[b], 03.05.01.[a], 03.05.01.[b], 03.05.02.[], 03.05.05.[d] | IA-1(), IA-2() | IDENTIFICATION AND AUTHENTICATION, IDENTIFICATION AND AUTHENTICATION |
15 | Privileged Access | Only users assigned to a privileged role are able to manage the cloud service subscription and have root access. | Access Control, Access Control | 03.01.06.[a], 03.01.07.[a] | AC-6(), IA-2(), SC-2() | ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION |
16 | Encryption Key Protection | Master passwords and encryption keys are restricted to authorized users [such as the Dev Ops team or specific job titles]; keys are securely stored. | System and Communications Protection | 03.13.10.[] | SC-12() | SYSTEM AND COMMUNICATIONS PROTECTION |
17 | Termination of Access | A user's logical [and physical] access to IT systems is revoked within [# hours or business days] of termination or transfer and all assets are returned to the organization when employment ends or their contract terminates. Exceptions are documented in an offboarding checklist and/or offboarding ticket. | Access Control, Personnel Security, Physical Protection | 03.01.01.[g], 03.09.02.[a], 03.10.01.[d] | AC-2(), IA-2(), IA-4(), IA-5(), PS-4(), PS-5() | ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, IDENTIFICATION AND AUTHENTICATION, IDENTIFICATION AND AUTHENTICATION, PERSONNEL SECURITY, PERSONNEL SECURITY |
18 | Review Privileged Access | Administrative and privileged access, as defined by policy, is reviewed at least quarterly. | Access Control, Access Control | 03.01.05.[c], 03.01.05.[d] | AC-2(), AC-20(), CA-2() | ACCESS CONTROL, ACCESS CONTROL, SECURITY ASSESSMENT AND AUTHORIZATION |
19 | Data Retention/Deletion | Procedures are in place to remove data from production based on retention schedules, contract requirements, and deletion rules that are applied to specific forms of data; disposals are tracked; a data disposal process is in place. These procedures are reviewed, updated, and approved as needed. | System and Information Integrity | 03.14.08.[] | AC-3(), AU-9(), AU-11(), CP-9(), SI-21() | ACCESS CONTROL, AUDIT AND ACCOUNTABILITY, AUDIT AND ACCOUNTABILITY, CONTINGENCY PLANNING, SYSTEM AND INFORMATION INTEGRITY |
20 | Password Requirements | Authentication for the network, operating systems, databases, applications, cloud, and VPNs adheres to the company password setting requirements. These requirements are documented within the Logical Access [or Password] Policy. | Identification and Authentication, Identification and Authentication, Identification and Authentication, Identification and Authentication | 03.05.07.[a], 03.05.07.[b], 03.05.07.[e], 03.05.07.[f] | AC-24(), IA-2(), IA-5() | ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, IDENTIFICATION AND AUTHENTICATION |
21 | MFA for Sensitive Access | Access to cloud administration or other critical systems is restricted to authorized users [such as the Dev Ops team or specific job titles] through multi factor authentication. | AC-24(), IA-2() | ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION | ||
22 | Change Management Policy | A Change Management Policy and Procedures are in place to request, document, test, and approve changes. The head of IT is responsible for ensuring that changes to IT services are made in a manner appropriate to their impact on operations. All technology acquisition, development, and maintenance processes are governed by change management procedures. The policy is reviewed at least annually and re-distributed to staff, as needed. | Access Control, Configuration Management, Configuration Management | 03.01.01.[g], 03.04.05.[], 03.04.11.[b] | CM-3(), CM-4(), CM-5(), SA-11(), SI-2() | CONFIGURATION MANAGEMENT, CONFIGURATION MANAGEMENT, CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION, SYSTEM AND INFORMATION INTEGRITY |
23 | Cloud Change Monitoring | Cloud logging is utilized to monitor cloud configuration changes. Logs are reviewed and inappropriate changes are investigated. Access to the logs are restricted. | Configuration Management | 03.04.02.[a] | AU-9(), AU-12(), CM-6() | AUDIT AND ACCOUNTABILITY, AUDIT AND ACCOUNTABILITY, CONFIGURATION MANAGEMENT |
24 | Malware Scans | Infrastructure malware scanning is configured and set to alert the technology team for review and/or action. | System and Information Integrity | 03.14.02.[c] | AT-2(), CM-6(), SI-3() | AWARENESS AND TRAINING, CONFIGURATION MANAGEMENT, SYSTEM AND INFORMATION INTEGRITY |
25 | Encryption at Rest | All data at rest is encrypted using industry standard algorithms. | Media Protection | 03.08.09.[b] | AC-3(), AC-4(), AC-17(), AC-18(), AC-19(), AC-20(), AU-9(), CP-9(), PE-17(), SC-7(), SC-8(), SC-13(), SC-15(), SC-28() | ACCESS CONTROL, ACCESS CONTROL, ACCESS CONTROL, ACCESS CONTROL, ACCESS CONTROL, ACCESS CONTROL, AUDIT AND ACCOUNTABILITY, CONTINGENCY PLANNING, PHYSICAL AND ENVIRONMENTAL PROTECTION, SYSTEM AND COMMUNICATIONS PROTECTION, SYSTEM AND COMMUNICATIONS PROTECTION, SYSTEM AND COMMUNICATIONS PROTECTION, SYSTEM AND COMMUNICATIONS PROTECTION, SYSTEM AND COMMUNICATIONS PROTECTION |
26 | Encryption in Transit | Any sensitive data that is transmitted over public networks, and data in transit is encrypted. | System and Communications Protection | 03.13.08.[] | AC-3(), AC-4(), AC-17(), AC-18(), AC-19(), AC-20(), PE-17(), SC-7(), SC-8(), SC-13(), SC-15() | ACCESS CONTROL, ACCESS CONTROL, ACCESS CONTROL, ACCESS CONTROL, ACCESS CONTROL, ACCESS CONTROL, PHYSICAL AND ENVIRONMENTAL PROTECTION, SYSTEM AND COMMUNICATIONS PROTECTION, SYSTEM AND COMMUNICATIONS PROTECTION, SYSTEM AND COMMUNICATIONS PROTECTION, SYSTEM AND COMMUNICATIONS PROTECTION |
27 | Multi Factor Authentication | Production systems are configured to authenticate users through multi factor authentication methods, where available. | Identification and Authentication, System and Communications Protection | 03.05.03.[], 03.13.15.[] | AC-24() | ACCESS CONTROL |
28 | Wireless Networks | Controls are in place to avoid open access to the corporate wireless network. This can include a separate guest network, rotating passwords frequently, and/or a password expiration policy. | Access Control | 03.01.16.[c] | AC-4(), PE-4(), PE-5(), SC-7(), SC-40() | ACCESS CONTROL, PHYSICAL AND ENVIRONMENTAL PROTECTION, PHYSICAL AND ENVIRONMENTAL PROTECTION, SYSTEM AND COMMUNICATIONS PROTECTION, SYSTEM AND COMMUNICATIONS PROTECTION |
29 | Backup Schedule | Data is backed up following a set schedule and staff is notified of backup failures; access to backups is restricted to privileged users. Backup schedules and the timing for remediation of backup failures adhere to the Backup Policy. | Media Protection | 03.08.09.[a] | CP-9() | CONTINGENCY PLANNING |
30 | Business Continuity | A Business Continuity Plan has been developed. The plan identifies a process, roles, and milestones for maintaining business continuity and restoring system functionality in the event of major disruption. The plan is reviewed and tested annually. Disaster recovery is included within the Business Continuity Plan. | Physical Protection, Physical Protection | 03.10.06.[a], 03.10.06.[b] | CP-8(), CP-9(), CP-10(), CP-11(), CP-13() | CONTINGENCY PLANNING, CONTINGENCY PLANNING, CONTINGENCY PLANNING, CONTINGENCY PLANNING, CONTINGENCY PLANNING |
31 | Change Management: Infrastructure | Infrastructure changes are tested, reviewed, and approved by authorized personnel prior to implementation. | Configuration Management, Configuration Management, Configuration Management, Configuration Management | 03.04.03.[a], 03.04.03.[b], 03.04.03.[c], 03.04.03.[d] | CM-3(), CM-4(), SA-10(), SA-11(), SI-2() | CONFIGURATION MANAGEMENT, CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION, SYSTEM AND SERVICES ACQUISITION, SYSTEM AND INFORMATION INTEGRITY |
32 | Internal Audit | An internal audit function is in place to ensure internal controls are operating effectively and to ensure minimal disruptions to business processes. Audits are planned to minimize the impact on operating systems. Audits are completed and documented in an internal audit report at least annually. | Security Assessment | 03.12.01.[] | CA-2() | SECURITY ASSESSMENT AND AUTHORIZATION |
33 | Distributed Denial of Service Alerting | An industry-standard service is utilized to protect and alert against the risk of a distributed denial of service attacks. | System and Information Integrity | 03.14.06.[a] | SC-5() | SYSTEM AND COMMUNICATIONS PROTECTION |
34 | Visitor Sign-In | A visitor log is maintained for visitors accessing the physical locations in scope. | Physical Protection | 03.10.07.[b] | PE-3(), PE-8() | PHYSICAL AND ENVIRONMENTAL PROTECTION, PHYSICAL AND ENVIRONMENTAL PROTECTION |
35 | Software Configuration | Configuration templates are utilized to define software parameters which are rendered to the container scheduler from the secrets manager. | Configuration Management | 03.04.02.[a] | CM-6() | CONFIGURATION MANAGEMENT |
36 | Software Install Scan | Users are allowed to install authorized software on issued devices. Devices are scanned for malicious and suspicious applications. A software inventory tool is utilized to automate the discovery and documentation of installed software. | System and Information Integrity | 03.14.02.[c] | CM-14() | CONFIGURATION MANAGEMENT |
37 | Software Updates | An industry-standard tool is utilized to enforce the automatic installation of critical security updates for workstations as per the Patch Management Policy. The policy is reviewed at least annually and re-distributed to staff, as needed. | System and Information Integrity | 03.14.01.[b] | CM-14(), SI-2() | CONFIGURATION MANAGEMENT, SYSTEM AND INFORMATION INTEGRITY |
38 | Virtual Private Network | A virtual private network is logically enforced for remote connection to the company network. | Access Control | 03.01.12.[c] | AC-4(), AC-17(), AC-19(), AC-20(), MP-5(), PE-17(), SC-7() | ACCESS CONTROL, ACCESS CONTROL, ACCESS CONTROL, ACCESS CONTROL, MEDIA PROTECTION, PHYSICAL AND ENVIRONMENTAL PROTECTION, SYSTEM AND COMMUNICATIONS PROTECTION |
39 | Virtual Private Network Encryption | Remote access virtual private network sessions are encrypted. | System and Communications Protection | 03.13.15.[] | AC-4(), AC-17(), IA-2(), SC-7() | ACCESS CONTROL, ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION |
40 | Patch Management | A formal process is followed in order to identify, review, install, and monitor patches for servers, workstations, and network devices. Server patching scans occur and patches are applied as needed. Management is notified of any down time to apply updates. Acceptance testing is documented for new information systems, upgrades, and new versions. | System and Information Integrity | 03.14.01.[b] | SI-2() | SYSTEM AND INFORMATION INTEGRITY |
41 | Security Testing | Static Application Security Testing (SAST) and container scanning are run on all merge requests and actioned, as appropriate, by engineers. IT reviews source code management tool security dashboard for incidents and follows up, as needed. | Configuration Management, Configuration Management | 03.04.04.[a], 03.04.04.[b] | CA-2(), SA-11() | SECURITY ASSESSMENT AND AUTHORIZATION, SYSTEM AND SERVICES ACQUISITION |
42 | Incident Response: Employee Responsibility | A documented incident response plan is in place to guide employees in identifying, reporting, and acting on breaches and incidents. | Incident Response, Incident Response | 03.06.05.[a], 03.06.05.[b] | IR-1(), IR-8(), SI-2() | INCIDENT RESPONSE, INCIDENT RESPONSE, SYSTEM AND INFORMATION INTEGRITY |
43 | Incident Response: Process | The incident response process includes documentation of containment steps performed, impact assessment, data capture for analysis, mitigations, stakeholder notification, steps to restore service. The organization performs a root cause analysis (RCA) for incidents and information disclosures that could impact security, confidentiality, or privacy. The plan is protected from unauthorized disclosure. | Incident Response, Incident Response, Incident Response, Incident Response, Incident Response, Incident Response | 03.06.01.[], 03.06.02.[a], 03.06.02.[b], 03.06.02.[c], 03.06.05.[c], 03.06.05.[d] | AU-6(), IR-4(), IR-5(), IR-6(), IR-7(), SC-47() | AUDIT AND ACCOUNTABILITY, INCIDENT RESPONSE, INCIDENT RESPONSE, INCIDENT RESPONSE, INCIDENT RESPONSE, SYSTEM AND COMMUNICATIONS PROTECTION |
44 | Incident Response: Responsibility | The design, implementation, maintenance, execution, and periodic testing of the security incident response program and data breach response procedures are the responsibility of the [ROLE TITLE]. The Incident Response plan is reviewed, updated, and approved annually. | Incident Response | 03.06.02.[d] | IR-3() | INCIDENT RESPONSE |
45 | Data Loss Prevention | A data loss prevention software is configured to detect and prevent potential data breaches/data ex-filtration transmissions. | AC-3(), AU-9(), CM-6(), CP-9() | ACCESS CONTROL, AUDIT AND ACCOUNTABILITY, CONFIGURATION MANAGEMENT, CONTINGENCY PLANNING | ||
46 | Locked Doors | Physical doors are locked according to policy. | Physical Protection | 03.10.07.[a] | PE-4(), PE-5() | PHYSICAL AND ENVIRONMENTAL PROTECTION, PHYSICAL AND ENVIRONMENTAL PROTECTION |
47 | Audit Logs - Alerting | Application, database, network, operating system, source code, and VPN access logs are captured on a regular basis to help identify unauthorized or suspicious activities. Alerts are sent to the authorized administrators and investigated. | Audit and Accountability, Audit and Accountability, Audit and Accountability, Audit and Accountability, Audit and Accountability, System and Information Integrity | 03.03.01.[b], 03.03.04.[a], 03.03.05.[a], 03.03.05.[b], 03.03.05.[c], 03.14.06.[c] | AC-3(), AU-3(), AU-5(), AU-6(), AU-9(), AU-12(), CP-9(), IA-10() | ACCESS CONTROL, AUDIT AND ACCOUNTABILITY, AUDIT AND ACCOUNTABILITY, AUDIT AND ACCOUNTABILITY, AUDIT AND ACCOUNTABILITY, AUDIT AND ACCOUNTABILITY, CONTINGENCY PLANNING, IDENTIFICATION AND AUTHENTICATION |
48 | Change Management: Separation of Duties | Separation of duties exist during the infrastructure and application change process. | Access Control, Access Control | 03.01.04.[a], 03.01.04.[b] | CM-5() | CONFIGURATION MANAGEMENT |
49 | Mobile Device Policy | A Mobile Device Policy is in place to outline the security measures that the organization has in place to protect information assets. The policy is reviewed at least annually and re-distributed to staff, as needed. | Access Control | 03.01.18.[a] | AC-17(), AC-18(), AC-19(), MP-7() | ACCESS CONTROL, ACCESS CONTROL, ACCESS CONTROL, MEDIA PROTECTION |
50 | Risk Assessment Policy | The Risk Management policy and procedures are in place and include how to identify risks, to evaluate risks, and how to address and mitigate those risks. The policy is reviewed at least annually and re-distributed to staff, as needed. | Risk Assessment, Risk Assessment | 03.11.01.[a], 03.11.01.[b] | RA-1(), RA-3() | RISK ASSESSMENT, RISK ASSESSMENT |
51 | Organization Separation of Duties | Conflicting duties and areas of responsibility are separated to reduce opportunities for unauthorized or unintentional modification or misuses of the organization’s assets. | Access Control, Access Control | 03.01.04.[a], 03.01.04.[b] | AC-5() | ACCESS CONTROL |
52 | Physical Media Transfer | Media containing information is protected against unauthorized access, misuse, or corruption during transportation. | Media Protection, Media Protection, Media Protection, Media Protection, Media Protection | 03.08.01.[], 03.08.04.[], 03.08.05.[a], 03.08.05.[b], 03.08.05.[c] | MP-5() | MEDIA PROTECTION |
53 | Cryptographic Controls and Key Management Policy | A policy on the use of cryptographic controls for the protection of information, including key management, is in place. The policy is reviewed at least annually and re-distributed to staff, as needed. | System and Communications Protection | 03.13.11.[] | AC-4(), AC-17(), AC-18(), AC-19(), AC-20(), PE-17(), SC-7(), SC-8(), SC-12(), SC-13(), SC-15() | ACCESS CONTROL, ACCESS CONTROL, ACCESS CONTROL, ACCESS CONTROL, ACCESS CONTROL, PHYSICAL AND ENVIRONMENTAL PROTECTION, SYSTEM AND COMMUNICATIONS PROTECTION, SYSTEM AND COMMUNICATIONS PROTECTION, SYSTEM AND COMMUNICATIONS PROTECTION, SYSTEM AND COMMUNICATIONS PROTECTION, SYSTEM AND COMMUNICATIONS PROTECTION |
54 | Cabling Security | Power and telecommunications cabling carrying data or supporting information servers are protected from interception, interference, or damage. | PE-9() | PHYSICAL AND ENVIRONMENTAL PROTECTION | ||
55 | Clock Synchronization | All system clocks are synchronized, based on an industry norm, to the same time source. Access to the clock synchronization is restricted. | Audit and Accountability, Audit and Accountability | 03.03.07.[a], 03.03.07.[b] | AU-8(), SC-45() | AUDIT AND ACCOUNTABILITY, SYSTEM AND COMMUNICATIONS PROTECTION |
56 | Secure Engineering Principles | Principles for engineering secure systems are established, documented, maintained, and applied to any information system implementation efforts. | SA-8() | SYSTEM AND SERVICES ACQUISITION | ||
57 | Data Center Physical Access | Physical access to the onsite server room/data center is restricted to authorized individuals. All changes to access are documented. New access requests and changes to access are appropriately approved. | Physical Protection | 03.10.01.[a] | CM-5(), PE-2(), PE-3(), PE-5() | CONFIGURATION MANAGEMENT, PHYSICAL AND ENVIRONMENTAL PROTECTION, PHYSICAL AND ENVIRONMENTAL PROTECTION, PHYSICAL AND ENVIRONMENTAL PROTECTION |
58 | Physical Security Monitoring | The physical premises are continuously monitored for unauthorized physical access. | Physical Protection, Physical Protection | 03.10.02.[a], 03.10.02.[b] | PE-5(), PE-6() | PHYSICAL AND ENVIRONMENTAL PROTECTION, PHYSICAL AND ENVIRONMENTAL PROTECTION |
59 | Hardening Standards | The organization has documented key security, hardware, software, services, and network configuration in line with industry standards. Hardening configurations are periodically reviewed for compliance with relevant laws, regulations, and industry norms. Exceptions to standard configurations are documented and approved by Management. | Configuration Management | 03.04.02.[b] | CM-6() | CONFIGURATION MANAGEMENT |
60 | Visitor Escort | All visitors are escorted when on the premises. | Physical Protection | 03.10.07.[c] | PE-3(), MA-5() | PHYSICAL AND ENVIRONMENTAL PROTECTION, MAINTENANCE |
61 | Vendor Risk Register | A register of all vendors and service providers is maintained. The register includes vendor risk level which is assessed prior to engaging with the vendor and re-assessed annually thereafter. | Supply Chain Risk Management | 03.17.03.[b] | SR-2(), SR-6() | SUPPLY CHAIN RISK MANAGEMENT FAMILY, SUPPLY CHAIN RISK MANAGEMENT FAMILY |
62 | Visitor Badges | All visitors are provided badges that visibly distinguish them from other personnel. Visitors are required to surrender their badge before leaving the facility or at the expiration date. | Physical Protection | 03.10.07.[a] | PE-3() | PHYSICAL AND ENVIRONMENTAL PROTECTION |
63 | Wireless Access Point List | A list of all authorized wireless access points is maintained and includes documented justification. This list is reviewed quarterly or as business needs change. | Access Control, Access Control | 03.01.16.[b], 03.01.16.[c] | PE-4() | PHYSICAL AND ENVIRONMENTAL PROTECTION |
64 | Internal Penetration Test | Internal penetration testing is performed quarterly or as business needs require. Test results are addressed and rescans are repeated to verify corrections. | CA-8() | SECURITY ASSESSMENT AND AUTHORIZATION | ||
65 | Audit Trail | All events on applications and servers that are required to be logged have been defined. Logging has been enabled and the logs are reviewed weekly for anomalies. The logs record user, event type, date/time, origination of event, and an indication of success or failure of the event. Inappropriate events are addressed. | Audit and Accountability, Audit and Accountability, Audit and Accountability, Audit and Accountability, System and Information Integrity | 03.03.01.[a], 03.03.02.[a], 03.03.02.[b], 03.03.03.[a], 03.14.06.[b] | AU-4() | AUDIT AND ACCOUNTABILITY |
66 | Audit Trail Access | Access to audit logs, log backups, and logging settings are restricted. Read access to audit logs is restricted based on need to know. File integrity monitoring is in place to detect changes to logs and to alert the appropriate team for investigation. | Audit and Accountability, Audit and Accountability | 03.03.08.[a], 03.03.08.[b] | AU-9() | AUDIT AND ACCOUNTABILITY |
67 | Remote Session Inactivity | Remote sessions are configured to end after a period of inactivity. Sessions are terminated at the end a session. | Access Control, Access Control, Access Control, Access Control, Access Control | 03.01.01.[f], 03.01.01.[h], 03.01.10.[a], 03.01.10.[b], 03.01.10.[c] | AC-12(), SC-10() | ACCESS CONTROL, SYSTEM AND COMMUNICATIONS PROTECTION |
68 | System Maintenance Policy | The organization has a documented system maintenance policy that governs the upkeep of organizational systems. The policy is reviewed at least annually and re-distributed to staff, as needed. | Maintenance | 03.07.05.[a] | MA-1() | MAINTENANCE |
69 | Configuration Management Policy | The organization has documented its configuration management policies. | Configuration Management, System and Information Integrity | 03.04.05.[], 03.14.02.[b] | CM-6(), CM-9(), SA-10(), SA-5() | CONFIGURATION MANAGEMENT, CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION, SYSTEM AND SERVICES ACQUISITION |
70 | Authorized Software | Whitelisting is used to allow only approved program execution. | Configuration Management, Configuration Management, Configuration Management | 03.04.08.[a], 03.04.08.[b], 03.04.08.[c] | CM-7() | CONFIGURATION MANAGEMENT |
71 | Audit and Accountability Policy | Audit logging activities are governed by the Audit and Accountability Policy. The policy is reviewed at least annually and re-distributed to staff, as needed. | Audit and Accountability | 03.03.06.[a] | AU-1(), AU-2(), AU-3(), AU-12() | AUDIT AND ACCOUNTABILITY, AUDIT AND ACCOUNTABILITY, AUDIT AND ACCOUNTABILITY, AUDIT AND ACCOUNTABILITY |
72 | Remote Access Policy | The Remote Access Policy and related procedures are documented and available to all personnel. The policy is reviewed at least annually and re-distributed to staff, as needed. | Access Control | 03.01.12.[a] | AC-17() | ACCESS CONTROL |
73 | Logon Attempt Rules | The organization has defined and implemented rules for unsuccessful logon attempts. | Access Control, Access Control | 03.01.08.[a], 03.01.08.[b] | AC-7() | ACCESS CONTROL |
74 | Session Termination | Conditions for automatic user session termination are defined and enforced. | Access Control, Maintenance | 03.01.11.[], 03.07.05.[c] | AC-12() | ACCESS CONTROL |
75 | Authorization of Mobile Devices | Mobile devices may connect to the network when authorized. A list of approved devices is maintained. All mobile device connections are monitored and logged. | Access Control | 03.01.18.[b] | IA-3() | IDENTIFICATION AND AUTHENTICATION |
76 | Use of External Systems | Procedures are in place to control and limit connections to external systems. | Access Control, Access Control, System and Services Acquisition | 03.01.02.[], 03.01.20.[a], 03.16.03.[b] | AC-4() | ACCESS CONTROL |
77 | Publicly Accessible Systems | Procedures are in place for the control of CUI posted or processed on publicly available systems. A list of publicly accessible system components is maintained. | Access Control, Access Control | 03.01.22.[a], 03.01.22.[b] | AC-22() | ACCESS CONTROL |
78 | System Media Protection Policy | Procedures are in place for the protection of system media. The policy is reviewed at least annually and re-distributed to staff, as needed. | Media Protection, Media Protection, Media Protection | 03.08.01.[], 03.08.02.[], 03.08.04.[] | MP-1(), MP-2() | MEDIA PROTECTION, MEDIA PROTECTION |
79 | Collaborative Computing Devices | The organization maintains an inventory of collaborative computing devices. Devices are not allowed to be activated remotely and include an indication to users of when they are in use. | System and Communications Protection, System and Communications Protection | 03.13.12.[a], 03.13.12.[b] | IA-3(), SC-20() | IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION |
80 | Session Protections | Communication protections are in place at the session level. | SC-23() | SYSTEM AND COMMUNICATIONS PROTECTION | ||
81 | Plan of Action (POAM) | Plans of action and milestones (POAMs) are utilized to document unimplemented security requirements. POAMs are monitored for risk to the organization. | Security Assessment, Security Assessment | 03.12.02.[a], 03.12.02.[b] | CA-5() | SECURITY ASSESSMENT AND AUTHORIZATION |
82 | File Scanning | Files that originate from external sources are automatically scanned for malicious code. The scan is performed prior to download or installation. | System and Information Integrity, System and Information Integrity | 03.14.02.[a], 03.14.02.[c] | AC-4() | ACCESS CONTROL |
83 | Incident Response: Testing | The security incident response plan is tested on at least an annual basis. | Incident Response, Incident Response | 03.06.03.[], 03.06.05.[c] | IR-3() | INCIDENT RESPONSE |
84 | ||||||