ABCDEF
1
2
TitleDescriptionNIST 800-171NIST 800-171 Numerical ReferenceNIST 800-53 Numerical ReferenceNIST 800-53 Domain
3
Workstation LockoutInternal users' screensavers are configured to lock after a specified period of time of inactivity and require a password to unlock.Access Control, Access Control, Access Control, System and Communications Protection03.01.10.[a], 03.01.10.[b], 03.01.10.[c], 03.13.15.[]AC-11(), IA-11()ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION
4
Configuration StandardsA baseline security configuration is maintained by the information technology team and is deployed to all systems upon installation or upgrade. The configuration is reviewed at least annually or when there has been a significant change. The prior baseline configuration is also maintained for use in emergency rollback.Configuration Management, Configuration Management03.04.01.[a], 03.04.02.[a]CM-6(), SA-10(), CM-2(), SA-5()CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION, CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION
5
Restrict Software InstallThe ability to install applications on end-user machines is restricted per centralized device management settings.Configuration Management, Configuration Management03.04.08.[b], 03.04.08.[c]CM-5(), CM-7(), CM-11(), CM-14()CONFIGURATION MANAGEMENT, CONFIGURATION MANAGEMENT, CONFIGURATION MANAGEMENT, CONFIGURATION MANAGEMENT
6
Data Flow DiagramThe data flow diagram is maintained and highlights the systems that require logical access controls per data classification level. The data flow diagram is updated annually or as business needs require.Access Control, Configuration Management03.01.03.[], 03.04.11.[a]AC-4(), AC-17(), AC-18(), AC-19(), AC-20(), CM-13(), PE-17(), SC-7(), SC-8(), SC-15()ACCESS CONTROL, ACCESS CONTROL, ACCESS CONTROL, ACCESS CONTROL, ACCESS CONTROL, CONFIGURATION MANAGEMENT, PHYSICAL AND ENVIRONMENTAL PROTECTION, SYSTEM AND COMMUNICATIONS PROTECTION, SYSTEM AND COMMUNICATIONS PROTECTION, SYSTEM AND COMMUNICATIONS PROTECTION
7
Acceptable Use PolicyAll staff sign an Acceptable Use Policy, which outlines rules for the acceptable use of information associated with information and information processing, as well as, appropriate procedures for compliance with legislative, regulatory, and contractual requirements related to proprietary software services.Planning, Planning, Planning03.15.03.[a], 03.15.03.[c], 03.15.03.[d]PL-4()PLANNING
8
Policy ReviewIT security related policies are reviewed and approved annually or as business needs change. Procedure documents related to access control, change management, and incident management are updated as processes change.Planning03.15.01.[b]AU-1(), CA-2()AUDIT AND ACCOUNTABILITY, SECURITY ASSESSMENT AND AUTHORIZATION
9
Security TrainingEmployees and contractors complete security-related training, as relevant to their duties, upon hire and on an annual basis. The annual security training includes information on how to report security incidents and concerns. The training includes topics specific to different roles depending on participants' access to sensitive data.Awareness and Training, Awareness and Training, Incident Response, Incident Response03.02.01.[a], 03.02.01.[b], 03.06.04.[a], 03.06.04.[b]AT-2(), AT-3(), AT-4(), IR-2()AWARENESS AND TRAINING, AWARENESS AND TRAINING, AWARENESS AND TRAINING, INCIDENT RESPONSE
10
Asset InventoryAn inventory of information assets, including hardware and software, is maintained and updated at least annually. All assets have an assigned asset owner. All assets are classified based on the data classification convention. Configuration Management, Configuration Management, Configuration Management03.04.10.[a], 03.04.10.[b], 03.04.10.[c]CM-8(), PM-5()CONFIGURATION MANAGEMENT, PROGRAM MANAGEMENT
11
Vulnerability ScanVulnerability scans are performed quarterly to help identify security risks. Results are assessed and, where required, remediated.Risk Assessment, Risk Assessment, Risk Assessment03.11.02.[a], 03.11.02.[b], 03.11.02.[c]RA-5(), SI-2()RISK ASSESSMENT, SYSTEM AND INFORMATION INTEGRITY
12
Intrusion DetectionThreat detection tools are utilized to monitor and log possible or actual network breaches and other anomalous security events. Alerting occurs on threats and results are actioned as appropriate.System and Information Integrity03.14.06.[a]AC-3(), AC-17(), AC-18(), AC-20(), SC-7(), SC-8(), SC-10(), SI-4()ACCESS CONTROL, ACCESS CONTROL, ACCESS CONTROL, ACCESS CONTROL, SYSTEM AND COMMUNICATIONS PROTECTION, SYSTEM AND COMMUNICATIONS PROTECTION, SYSTEM AND COMMUNICATIONS PROTECTION, SYSTEM AND INFORMATION INTEGRITY
13
Logical Access PolicyLogical Access Policy and Procedures are in place which define the authorization, modification, removal of access, secure authentication requirements, and the principle of least privilege. The policy is reviewed annually.Access Control, Access Control, Access Control, Access Control, Configuration Management, Identification and Authentication, Identification and Authentication, Identification and Authentication03.01.01.[b], 03.01.05.[a], 03.01.05.[b], 03.01.11.[], 03.04.05.[], 03.05.02.[], 03.05.04.[], 03.05.11.[]AC-1(), AC-3(), IA-1(), IA-6(), PS-5()ACCESS CONTROL, ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, IDENTIFICATION AND AUTHENTICATION, PERSONNEL SECURITY
14
User AuthenticationUnique usernames and passwords are required to authenticate all users. Users must use non-privileged accounts or roles when accessing non-security functions, and any shared accounts must be approved by the head of IT.Access Control, Access Control, Identification and Authentication, Identification and Authentication, Identification and Authentication, Identification and Authentication03.01.01.[c], 03.01.06.[b], 03.05.01.[a], 03.05.01.[b], 03.05.02.[], 03.05.05.[d]IA-1(), IA-2()IDENTIFICATION AND AUTHENTICATION, IDENTIFICATION AND AUTHENTICATION
15
Privileged AccessOnly users assigned to a privileged role are able to manage the cloud service subscription and have root access.Access Control, Access Control03.01.06.[a], 03.01.07.[a]AC-6(), IA-2(), SC-2()ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION
16
Encryption Key ProtectionMaster passwords and encryption keys are restricted to authorized users [such as the Dev Ops team or specific job titles]; keys are securely stored.System and Communications Protection03.13.10.[]SC-12()SYSTEM AND COMMUNICATIONS PROTECTION
17
Termination of AccessA user's logical [and physical] access to IT systems is revoked within [# hours or business days] of termination or transfer and all assets are returned to the organization when employment ends or their contract terminates. Exceptions are documented in an offboarding checklist and/or offboarding ticket.Access Control, Personnel Security, Physical Protection03.01.01.[g], 03.09.02.[a], 03.10.01.[d]AC-2(), IA-2(), IA-4(), IA-5(), PS-4(), PS-5()ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, IDENTIFICATION AND AUTHENTICATION, IDENTIFICATION AND AUTHENTICATION, PERSONNEL SECURITY, PERSONNEL SECURITY
18
Review Privileged AccessAdministrative and privileged access, as defined by policy, is reviewed at least quarterly.Access Control, Access Control03.01.05.[c], 03.01.05.[d]AC-2(), AC-20(), CA-2()ACCESS CONTROL, ACCESS CONTROL, SECURITY ASSESSMENT AND AUTHORIZATION
19
Data Retention/DeletionProcedures are in place to remove data from production based on retention schedules, contract requirements, and deletion rules that are applied to specific forms of data; disposals are tracked; a data disposal process is in place. These procedures are reviewed, updated, and approved as needed.System and Information Integrity03.14.08.[]AC-3(), AU-9(), AU-11(), CP-9(), SI-21()ACCESS CONTROL, AUDIT AND ACCOUNTABILITY, AUDIT AND ACCOUNTABILITY, CONTINGENCY PLANNING, SYSTEM AND INFORMATION INTEGRITY
20
Password RequirementsAuthentication for the network, operating systems, databases, applications, cloud, and VPNs adheres to the company password setting requirements. These requirements are documented within the Logical Access [or Password] Policy.Identification and Authentication, Identification and Authentication, Identification and Authentication, Identification and Authentication03.05.07.[a], 03.05.07.[b], 03.05.07.[e], 03.05.07.[f]AC-24(), IA-2(), IA-5()ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, IDENTIFICATION AND AUTHENTICATION
21
MFA for Sensitive AccessAccess to cloud administration or other critical systems is restricted to authorized users [such as the Dev Ops team or specific job titles] through multi factor authentication.AC-24(), IA-2()ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION
22
Change Management PolicyA Change Management Policy and Procedures are in place to request, document, test, and approve changes. The head of IT is responsible for ensuring that changes to IT services are made in a manner appropriate to their impact on operations. All technology acquisition, development, and maintenance processes are governed by change management procedures. The policy is reviewed at least annually and re-distributed to staff, as needed.Access Control, Configuration Management, Configuration Management03.01.01.[g], 03.04.05.[], 03.04.11.[b]CM-3(), CM-4(), CM-5(), SA-11(), SI-2()CONFIGURATION MANAGEMENT, CONFIGURATION MANAGEMENT, CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION, SYSTEM AND INFORMATION INTEGRITY
23
Cloud Change MonitoringCloud logging is utilized to monitor cloud configuration changes. Logs are reviewed and inappropriate changes are investigated. Access to the logs are restricted.Configuration Management03.04.02.[a]AU-9(), AU-12(), CM-6()AUDIT AND ACCOUNTABILITY, AUDIT AND ACCOUNTABILITY, CONFIGURATION MANAGEMENT
24
Malware ScansInfrastructure malware scanning is configured and set to alert the technology team for review and/or action.System and Information Integrity03.14.02.[c]AT-2(), CM-6(), SI-3()AWARENESS AND TRAINING, CONFIGURATION MANAGEMENT, SYSTEM AND INFORMATION INTEGRITY
25
Encryption at RestAll data at rest is encrypted using industry standard algorithms.Media Protection03.08.09.[b]AC-3(), AC-4(), AC-17(), AC-18(), AC-19(), AC-20(), AU-9(), CP-9(), PE-17(), SC-7(), SC-8(), SC-13(), SC-15(), SC-28()ACCESS CONTROL, ACCESS CONTROL, ACCESS CONTROL, ACCESS CONTROL, ACCESS CONTROL, ACCESS CONTROL, AUDIT AND ACCOUNTABILITY, CONTINGENCY PLANNING, PHYSICAL AND ENVIRONMENTAL PROTECTION, SYSTEM AND COMMUNICATIONS PROTECTION, SYSTEM AND COMMUNICATIONS PROTECTION, SYSTEM AND COMMUNICATIONS PROTECTION, SYSTEM AND COMMUNICATIONS PROTECTION, SYSTEM AND COMMUNICATIONS PROTECTION
26
Encryption in TransitAny sensitive data that is transmitted over public networks, and data in transit is encrypted.System and Communications Protection03.13.08.[]AC-3(), AC-4(), AC-17(), AC-18(), AC-19(), AC-20(), PE-17(), SC-7(), SC-8(), SC-13(), SC-15()ACCESS CONTROL, ACCESS CONTROL, ACCESS CONTROL, ACCESS CONTROL, ACCESS CONTROL, ACCESS CONTROL, PHYSICAL AND ENVIRONMENTAL PROTECTION, SYSTEM AND COMMUNICATIONS PROTECTION, SYSTEM AND COMMUNICATIONS PROTECTION, SYSTEM AND COMMUNICATIONS PROTECTION, SYSTEM AND COMMUNICATIONS PROTECTION
27
Multi Factor AuthenticationProduction systems are configured to authenticate users through multi factor authentication methods, where available.Identification and Authentication, System and Communications Protection03.05.03.[], 03.13.15.[]AC-24()ACCESS CONTROL
28
Wireless NetworksControls are in place to avoid open access to the corporate wireless network. This can include a separate guest network, rotating passwords frequently, and/or a password expiration policy. Access Control03.01.16.[c]AC-4(), PE-4(), PE-5(), SC-7(), SC-40()ACCESS CONTROL, PHYSICAL AND ENVIRONMENTAL PROTECTION, PHYSICAL AND ENVIRONMENTAL PROTECTION, SYSTEM AND COMMUNICATIONS PROTECTION, SYSTEM AND COMMUNICATIONS PROTECTION
29
Backup ScheduleData is backed up following a set schedule and staff is notified of backup failures; access to backups is restricted to privileged users. Backup schedules and the timing for remediation of backup failures adhere to the Backup Policy.Media Protection03.08.09.[a]CP-9()CONTINGENCY PLANNING
30
Business ContinuityA Business Continuity Plan has been developed. The plan identifies a process, roles, and milestones for maintaining business continuity and restoring system functionality in the event of major disruption. The plan is reviewed and tested annually. Disaster recovery is included within the Business Continuity Plan.Physical Protection, Physical Protection03.10.06.[a], 03.10.06.[b]CP-8(), CP-9(), CP-10(), CP-11(), CP-13()CONTINGENCY PLANNING, CONTINGENCY PLANNING, CONTINGENCY PLANNING, CONTINGENCY PLANNING, CONTINGENCY PLANNING
31
Change Management: InfrastructureInfrastructure changes are tested, reviewed, and approved by authorized personnel prior to implementation.Configuration Management, Configuration Management, Configuration Management, Configuration Management03.04.03.[a], 03.04.03.[b], 03.04.03.[c], 03.04.03.[d]CM-3(), CM-4(), SA-10(), SA-11(), SI-2()CONFIGURATION MANAGEMENT, CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION, SYSTEM AND SERVICES ACQUISITION, SYSTEM AND INFORMATION INTEGRITY
32
Internal AuditAn internal audit function is in place to ensure internal controls are operating effectively and to ensure minimal disruptions to business processes. Audits are planned to minimize the impact on operating systems. Audits are completed and documented in an internal audit report at least annually.Security Assessment03.12.01.[]CA-2()SECURITY ASSESSMENT AND AUTHORIZATION
33
Distributed Denial of Service AlertingAn industry-standard service is utilized to protect and alert against the risk of a distributed denial of service attacks.System and Information Integrity03.14.06.[a]SC-5()SYSTEM AND COMMUNICATIONS PROTECTION
34
Visitor Sign-InA visitor log is maintained for visitors accessing the physical locations in scope. Physical Protection03.10.07.[b]PE-3(), PE-8()PHYSICAL AND ENVIRONMENTAL PROTECTION, PHYSICAL AND ENVIRONMENTAL PROTECTION
35
Software ConfigurationConfiguration templates are utilized to define software parameters which are rendered to the container scheduler from the secrets manager.Configuration Management03.04.02.[a]CM-6()CONFIGURATION MANAGEMENT
36
Software Install ScanUsers are allowed to install authorized software on issued devices. Devices are scanned for malicious and suspicious applications. A software inventory tool is utilized to automate the discovery and documentation of installed software. System and Information Integrity03.14.02.[c]CM-14()CONFIGURATION MANAGEMENT
37
Software UpdatesAn industry-standard tool is utilized to enforce the automatic installation of critical security updates for workstations as per the Patch Management Policy. The policy is reviewed at least annually and re-distributed to staff, as needed.System and Information Integrity03.14.01.[b]CM-14(), SI-2()CONFIGURATION MANAGEMENT, SYSTEM AND INFORMATION INTEGRITY
38
Virtual Private NetworkA virtual private network is logically enforced for remote connection to the company network.Access Control03.01.12.[c]AC-4(), AC-17(), AC-19(), AC-20(), MP-5(), PE-17(), SC-7()ACCESS CONTROL, ACCESS CONTROL, ACCESS CONTROL, ACCESS CONTROL, MEDIA PROTECTION, PHYSICAL AND ENVIRONMENTAL PROTECTION, SYSTEM AND COMMUNICATIONS PROTECTION
39
Virtual Private Network EncryptionRemote access virtual private network sessions are encrypted.System and Communications Protection03.13.15.[]AC-4(), AC-17(), IA-2(), SC-7()ACCESS CONTROL, ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION
40
Patch ManagementA formal process is followed in order to identify, review, install, and monitor patches for servers, workstations, and network devices. Server patching scans occur and patches are applied as needed. Management is notified of any down time to apply updates. Acceptance testing is documented for new information systems, upgrades, and new versions.System and Information Integrity03.14.01.[b]SI-2()SYSTEM AND INFORMATION INTEGRITY
41
Security TestingStatic Application Security Testing (SAST) and container scanning are run on all merge requests and actioned, as appropriate, by engineers. IT reviews source code management tool security dashboard for incidents and follows up, as needed.Configuration Management, Configuration Management03.04.04.[a], 03.04.04.[b]CA-2(), SA-11()SECURITY ASSESSMENT AND AUTHORIZATION, SYSTEM AND SERVICES ACQUISITION
42
Incident Response: Employee ResponsibilityA documented incident response plan is in place to guide employees in identifying, reporting, and acting on breaches and incidents. Incident Response, Incident Response03.06.05.[a], 03.06.05.[b]IR-1(), IR-8(), SI-2()INCIDENT RESPONSE, INCIDENT RESPONSE, SYSTEM AND INFORMATION INTEGRITY
43
Incident Response: ProcessThe incident response process includes documentation of containment steps performed, impact assessment, data capture for analysis, mitigations, stakeholder notification, steps to restore service. The organization performs a root cause analysis (RCA) for incidents and information disclosures that could impact security, confidentiality, or privacy. The plan is protected from unauthorized disclosure.Incident Response, Incident Response, Incident Response, Incident Response, Incident Response, Incident Response03.06.01.[], 03.06.02.[a], 03.06.02.[b], 03.06.02.[c], 03.06.05.[c], 03.06.05.[d]AU-6(), IR-4(), IR-5(), IR-6(), IR-7(), SC-47()AUDIT AND ACCOUNTABILITY, INCIDENT RESPONSE, INCIDENT RESPONSE, INCIDENT RESPONSE, INCIDENT RESPONSE, SYSTEM AND COMMUNICATIONS PROTECTION
44
Incident Response: ResponsibilityThe design, implementation, maintenance, execution, and periodic testing of the security incident response program and data breach response procedures are the responsibility of the [ROLE TITLE]. The Incident Response plan is reviewed, updated, and approved annually.Incident Response03.06.02.[d]IR-3()INCIDENT RESPONSE
45
Data Loss PreventionA data loss prevention software is configured to detect and prevent potential data breaches/data ex-filtration transmissions.AC-3(), AU-9(), CM-6(), CP-9()ACCESS CONTROL, AUDIT AND ACCOUNTABILITY, CONFIGURATION MANAGEMENT, CONTINGENCY PLANNING
46
Locked DoorsPhysical doors are locked according to policy.Physical Protection03.10.07.[a]PE-4(), PE-5()PHYSICAL AND ENVIRONMENTAL PROTECTION, PHYSICAL AND ENVIRONMENTAL PROTECTION
47
Audit Logs - AlertingApplication, database, network, operating system, source code, and VPN access logs are captured on a regular basis to help identify unauthorized or suspicious activities. Alerts are sent to the authorized administrators and investigated.Audit and Accountability, Audit and Accountability, Audit and Accountability, Audit and Accountability, Audit and Accountability, System and Information Integrity03.03.01.[b], 03.03.04.[a], 03.03.05.[a], 03.03.05.[b], 03.03.05.[c], 03.14.06.[c]AC-3(), AU-3(), AU-5(), AU-6(), AU-9(), AU-12(), CP-9(), IA-10()ACCESS CONTROL, AUDIT AND ACCOUNTABILITY, AUDIT AND ACCOUNTABILITY, AUDIT AND ACCOUNTABILITY, AUDIT AND ACCOUNTABILITY, AUDIT AND ACCOUNTABILITY, CONTINGENCY PLANNING, IDENTIFICATION AND AUTHENTICATION
48
Change Management: Separation of DutiesSeparation of duties exist during the infrastructure and application change process.Access Control, Access Control03.01.04.[a], 03.01.04.[b]CM-5()CONFIGURATION MANAGEMENT
49
Mobile Device PolicyA Mobile Device Policy is in place to outline the security measures that the organization has in place to protect information assets. The policy is reviewed at least annually and re-distributed to staff, as needed.Access Control03.01.18.[a]AC-17(), AC-18(), AC-19(), MP-7()ACCESS CONTROL, ACCESS CONTROL, ACCESS CONTROL, MEDIA PROTECTION
50
Risk Assessment PolicyThe Risk Management policy and procedures are in place and include how to identify risks, to evaluate risks, and how to address and mitigate those risks. The policy is reviewed at least annually and re-distributed to staff, as needed.Risk Assessment, Risk Assessment03.11.01.[a], 03.11.01.[b]RA-1(), RA-3()RISK ASSESSMENT, RISK ASSESSMENT
51
Organization Separation of DutiesConflicting duties and areas of responsibility are separated to reduce opportunities for unauthorized or unintentional modification or misuses of the organization’s assets.Access Control, Access Control03.01.04.[a], 03.01.04.[b]AC-5()ACCESS CONTROL
52
Physical Media TransferMedia containing information is protected against unauthorized access, misuse, or corruption during transportation.Media Protection, Media Protection, Media Protection, Media Protection, Media Protection03.08.01.[], 03.08.04.[], 03.08.05.[a], 03.08.05.[b], 03.08.05.[c]MP-5()MEDIA PROTECTION
53
Cryptographic Controls and Key Management PolicyA policy on the use of cryptographic controls for the protection of information, including key management, is in place. The policy is reviewed at least annually and re-distributed to staff, as needed.System and Communications Protection03.13.11.[]AC-4(), AC-17(), AC-18(), AC-19(), AC-20(), PE-17(), SC-7(), SC-8(), SC-12(), SC-13(), SC-15()ACCESS CONTROL, ACCESS CONTROL, ACCESS CONTROL, ACCESS CONTROL, ACCESS CONTROL, PHYSICAL AND ENVIRONMENTAL PROTECTION, SYSTEM AND COMMUNICATIONS PROTECTION, SYSTEM AND COMMUNICATIONS PROTECTION, SYSTEM AND COMMUNICATIONS PROTECTION, SYSTEM AND COMMUNICATIONS PROTECTION, SYSTEM AND COMMUNICATIONS PROTECTION
54
Cabling SecurityPower and telecommunications cabling carrying data or supporting information servers are protected from interception, interference, or damage.PE-9()PHYSICAL AND ENVIRONMENTAL PROTECTION
55
Clock SynchronizationAll system clocks are synchronized, based on an industry norm, to the same time source. Access to the clock synchronization is restricted.Audit and Accountability, Audit and Accountability03.03.07.[a], 03.03.07.[b]AU-8(), SC-45()AUDIT AND ACCOUNTABILITY, SYSTEM AND COMMUNICATIONS PROTECTION
56
Secure Engineering PrinciplesPrinciples for engineering secure systems are established, documented, maintained, and applied to any information system implementation efforts.SA-8()SYSTEM AND SERVICES ACQUISITION
57
Data Center Physical AccessPhysical access to the onsite server room/data center is restricted to authorized individuals. All changes to access are documented. New access requests and changes to access are appropriately approved. Physical Protection03.10.01.[a]CM-5(), PE-2(), PE-3(), PE-5()CONFIGURATION MANAGEMENT, PHYSICAL AND ENVIRONMENTAL PROTECTION, PHYSICAL AND ENVIRONMENTAL PROTECTION, PHYSICAL AND ENVIRONMENTAL PROTECTION
58
Physical Security MonitoringThe physical premises are continuously monitored for unauthorized physical access. Physical Protection, Physical Protection03.10.02.[a], 03.10.02.[b]PE-5(), PE-6()PHYSICAL AND ENVIRONMENTAL PROTECTION, PHYSICAL AND ENVIRONMENTAL PROTECTION
59
Hardening StandardsThe organization has documented key security, hardware, software, services, and network configuration in line with industry standards. Hardening configurations are periodically reviewed for compliance with relevant laws, regulations, and industry norms. Exceptions to standard configurations are documented and approved by Management.Configuration Management03.04.02.[b]CM-6()CONFIGURATION MANAGEMENT
60
Visitor EscortAll visitors are escorted when on the premises.Physical Protection03.10.07.[c]PE-3(), MA-5()PHYSICAL AND ENVIRONMENTAL PROTECTION, MAINTENANCE
61
Vendor Risk RegisterA register of all vendors and service providers is maintained. The register includes vendor risk level which is assessed prior to engaging with the vendor and re-assessed annually thereafter.Supply Chain Risk Management03.17.03.[b]SR-2(), SR-6()SUPPLY CHAIN RISK MANAGEMENT FAMILY, SUPPLY CHAIN RISK MANAGEMENT FAMILY
62
Visitor BadgesAll visitors are provided badges that visibly distinguish them from other personnel. Visitors are required to surrender their badge before leaving the facility or at the expiration date.Physical Protection03.10.07.[a]PE-3()PHYSICAL AND ENVIRONMENTAL PROTECTION
63
Wireless Access Point ListA list of all authorized wireless access points is maintained and includes documented justification. This list is reviewed quarterly or as business needs change.Access Control, Access Control03.01.16.[b], 03.01.16.[c]PE-4()PHYSICAL AND ENVIRONMENTAL PROTECTION
64
Internal Penetration TestInternal penetration testing is performed quarterly or as business needs require. Test results are addressed and rescans are repeated to verify corrections.CA-8()SECURITY ASSESSMENT AND AUTHORIZATION
65
Audit TrailAll events on applications and servers that are required to be logged have been defined. Logging has been enabled and the logs are reviewed weekly for anomalies. The logs record user, event type, date/time, origination of event, and an indication of success or failure of the event. Inappropriate events are addressed. Audit and Accountability, Audit and Accountability, Audit and Accountability, Audit and Accountability, System and Information Integrity03.03.01.[a], 03.03.02.[a], 03.03.02.[b], 03.03.03.[a], 03.14.06.[b]AU-4()AUDIT AND ACCOUNTABILITY
66
Audit Trail AccessAccess to audit logs, log backups, and logging settings are restricted. Read access to audit logs is restricted based on need to know. File integrity monitoring is in place to detect changes to logs and to alert the appropriate team for investigation.Audit and Accountability, Audit and Accountability03.03.08.[a], 03.03.08.[b]AU-9()AUDIT AND ACCOUNTABILITY
67
Remote Session InactivityRemote sessions are configured to end after a period of inactivity. Sessions are terminated at the end a session.Access Control, Access Control, Access Control, Access Control, Access Control03.01.01.[f], 03.01.01.[h], 03.01.10.[a], 03.01.10.[b], 03.01.10.[c]AC-12(), SC-10()ACCESS CONTROL, SYSTEM AND COMMUNICATIONS PROTECTION
68
System Maintenance PolicyThe organization has a documented system maintenance policy that governs the upkeep of organizational systems. The policy is reviewed at least annually and re-distributed to staff, as needed.Maintenance03.07.05.[a]MA-1()MAINTENANCE
69
Configuration Management PolicyThe organization has documented its configuration management policies.Configuration Management, System and Information Integrity03.04.05.[], 03.14.02.[b]CM-6(), CM-9(), SA-10(), SA-5()CONFIGURATION MANAGEMENT, CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION, SYSTEM AND SERVICES ACQUISITION
70
Authorized SoftwareWhitelisting is used to allow only approved program execution.Configuration Management, Configuration Management, Configuration Management03.04.08.[a], 03.04.08.[b], 03.04.08.[c]CM-7()CONFIGURATION MANAGEMENT
71
Audit and Accountability PolicyAudit logging activities are governed by the Audit and Accountability Policy. The policy is reviewed at least annually and re-distributed to staff, as needed.Audit and Accountability03.03.06.[a]AU-1(), AU-2(), AU-3(), AU-12()AUDIT AND ACCOUNTABILITY, AUDIT AND ACCOUNTABILITY, AUDIT AND ACCOUNTABILITY, AUDIT AND ACCOUNTABILITY
72
Remote Access PolicyThe Remote Access Policy and related procedures are documented and available to all personnel. The policy is reviewed at least annually and re-distributed to staff, as needed.Access Control03.01.12.[a]AC-17()ACCESS CONTROL
73
Logon Attempt RulesThe organization has defined and implemented rules for unsuccessful logon attempts.Access Control, Access Control03.01.08.[a], 03.01.08.[b]AC-7()ACCESS CONTROL
74
Session TerminationConditions for automatic user session termination are defined and enforced.Access Control, Maintenance03.01.11.[], 03.07.05.[c]AC-12()ACCESS CONTROL
75
Authorization of Mobile DevicesMobile devices may connect to the network when authorized. A list of approved devices is maintained. All mobile device connections are monitored and logged.Access Control03.01.18.[b]IA-3()IDENTIFICATION AND AUTHENTICATION
76
Use of External SystemsProcedures are in place to control and limit connections to external systems.Access Control, Access Control, System and Services Acquisition03.01.02.[], 03.01.20.[a], 03.16.03.[b]AC-4()ACCESS CONTROL
77
Publicly Accessible SystemsProcedures are in place for the control of CUI posted or processed on publicly available systems. A list of publicly accessible system components is maintained.Access Control, Access Control03.01.22.[a], 03.01.22.[b]AC-22()ACCESS CONTROL
78
System Media Protection PolicyProcedures are in place for the protection of system media. The policy is reviewed at least annually and re-distributed to staff, as needed.Media Protection, Media Protection, Media Protection03.08.01.[], 03.08.02.[], 03.08.04.[]MP-1(), MP-2()MEDIA PROTECTION, MEDIA PROTECTION
79
Collaborative Computing DevicesThe organization maintains an inventory of collaborative computing devices. Devices are not allowed to be activated remotely and include an indication to users of when they are in use.System and Communications Protection, System and Communications Protection03.13.12.[a], 03.13.12.[b]IA-3(), SC-20()IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION
80
Session ProtectionsCommunication protections are in place at the session level.SC-23()SYSTEM AND COMMUNICATIONS PROTECTION
81
Plan of Action (POAM)Plans of action and milestones (POAMs) are utilized to document unimplemented security requirements. POAMs are monitored for risk to the organization.Security Assessment, Security Assessment03.12.02.[a], 03.12.02.[b]CA-5()SECURITY ASSESSMENT AND AUTHORIZATION
82
File ScanningFiles that originate from external sources are automatically scanned for malicious code. The scan is performed prior to download or installation. System and Information Integrity, System and Information Integrity03.14.02.[a], 03.14.02.[c]AC-4()ACCESS CONTROL
83
Incident Response: TestingThe security incident response plan is tested on at least an annual basis. Incident Response, Incident Response03.06.03.[], 03.06.05.[c]IR-3()INCIDENT RESPONSE
84