<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://cmmcwiki.org/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=David</id>
	<title>CMMC Toolkit Wiki - User contributions [en]</title>
	<link rel="self" type="application/atom+xml" href="https://cmmcwiki.org/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=David"/>
	<link rel="alternate" type="text/html" href="https://cmmcwiki.org/index.php/Special:Contributions/David"/>
	<updated>2026-07-31T07:20:21Z</updated>
	<subtitle>User contributions</subtitle>
	<generator>MediaWiki 1.45.4</generator>
	<entry>
		<id>https://cmmcwiki.org/index.php?title=NIST_Cybersecurity_Framework&amp;diff=1644</id>
		<title>NIST Cybersecurity Framework</title>
		<link rel="alternate" type="text/html" href="https://cmmcwiki.org/index.php?title=NIST_Cybersecurity_Framework&amp;diff=1644"/>
		<updated>2026-07-30T16:28:28Z</updated>

		<summary type="html">&lt;p&gt;David: Created page with &amp;quot;&amp;#039;&amp;#039;&amp;#039; This page is currently under construction.&amp;quot;&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&#039;&#039;&#039; This page is currently under construction.&lt;/div&gt;</summary>
		<author><name>David</name></author>
	</entry>
	<entry>
		<id>https://cmmcwiki.org/index.php?title=NIST_SP_800-171A_R3&amp;diff=1643</id>
		<title>NIST SP 800-171A R3</title>
		<link rel="alternate" type="text/html" href="https://cmmcwiki.org/index.php?title=NIST_SP_800-171A_R3&amp;diff=1643"/>
		<updated>2026-07-30T16:28:17Z</updated>

		<summary type="html">&lt;p&gt;David: Replaced content with &amp;quot;&amp;#039;&amp;#039;&amp;#039; This page is currently under construction.&amp;quot;&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&#039;&#039;&#039; This page is currently under construction.&lt;/div&gt;</summary>
		<author><name>David</name></author>
	</entry>
	<entry>
		<id>https://cmmcwiki.org/index.php?title=NIST_SP_800-17_R3&amp;diff=1642</id>
		<title>NIST SP 800-17 R3</title>
		<link rel="alternate" type="text/html" href="https://cmmcwiki.org/index.php?title=NIST_SP_800-17_R3&amp;diff=1642"/>
		<updated>2026-07-30T16:28:05Z</updated>

		<summary type="html">&lt;p&gt;David: Replaced content with &amp;quot;&amp;#039;&amp;#039;&amp;#039; This page is currently under construction.&amp;quot;&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&#039;&#039;&#039; This page is currently under construction.&lt;/div&gt;</summary>
		<author><name>David</name></author>
	</entry>
	<entry>
		<id>https://cmmcwiki.org/index.php?title=NIST_SP_800-171A&amp;diff=1641</id>
		<title>NIST SP 800-171A</title>
		<link rel="alternate" type="text/html" href="https://cmmcwiki.org/index.php?title=NIST_SP_800-171A&amp;diff=1641"/>
		<updated>2026-07-30T16:27:52Z</updated>

		<summary type="html">&lt;p&gt;David: Replaced content with &amp;quot;&amp;#039;&amp;#039;&amp;#039; This page is currently under construction.&amp;quot;&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&#039;&#039;&#039; This page is currently under construction.&lt;/div&gt;</summary>
		<author><name>David</name></author>
	</entry>
	<entry>
		<id>https://cmmcwiki.org/index.php?title=NIST_SP_800-17_R2&amp;diff=1640</id>
		<title>NIST SP 800-17 R2</title>
		<link rel="alternate" type="text/html" href="https://cmmcwiki.org/index.php?title=NIST_SP_800-17_R2&amp;diff=1640"/>
		<updated>2026-07-30T16:27:05Z</updated>

		<summary type="html">&lt;p&gt;David: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&#039;&#039;&#039; This page is currently under construction.&lt;/div&gt;</summary>
		<author><name>David</name></author>
	</entry>
	<entry>
		<id>https://cmmcwiki.org/index.php?title=NIST_SP_800-17_R2&amp;diff=1639</id>
		<title>NIST SP 800-17 R2</title>
		<link rel="alternate" type="text/html" href="https://cmmcwiki.org/index.php?title=NIST_SP_800-17_R2&amp;diff=1639"/>
		<updated>2026-07-30T16:26:27Z</updated>

		<summary type="html">&lt;p&gt;David: Replaced content with &amp;quot;*** This page is currently under construction. ***&amp;quot;&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;*** This page is currently under construction. ***&lt;/div&gt;</summary>
		<author><name>David</name></author>
	</entry>
	<entry>
		<id>https://cmmcwiki.org/index.php?title=MediaWiki:Sidebar&amp;diff=1638</id>
		<title>MediaWiki:Sidebar</title>
		<link rel="alternate" type="text/html" href="https://cmmcwiki.org/index.php?title=MediaWiki:Sidebar&amp;diff=1638"/>
		<updated>2026-07-27T03:03:41Z</updated>

		<summary type="html">&lt;p&gt;David: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;* navigation&lt;br /&gt;
** mainpage | mainpage-description&lt;br /&gt;
* CMMC Model and Rule&lt;br /&gt;
** Model_Overview | Model Overview&lt;br /&gt;
** 32_CFR_Part_170 | 32 CFR Part 170&lt;br /&gt;
** 48_CFR_Parts_204_212_217_252 | 48 CFR Parts 204, 212, 217, and 252&lt;br /&gt;
* Scoping and Assessment Guides&lt;br /&gt;
** Level_1_Scoping_Guidance | Level 1 Scoping Guidance&lt;br /&gt;
** Level_1_Self-Assessment_Guide | Level 1 Self-Assessment Guide&lt;br /&gt;
** Level_2_Scoping_Guidance | Level 2 Scoping Guidance&lt;br /&gt;
** Level_2_Assessment_Guide | Level 2 Assessment Guide&lt;br /&gt;
** Level_3_Scoping_Guidance | Level 3 Scoping Guidance&lt;br /&gt;
** Level_3_Assessment_Guide | Level 3 Assessment Guide&lt;br /&gt;
* CMMC Guides and Tools&lt;br /&gt;
** CMMC_Hashing_Guide | CMMC Hashing Guide&lt;br /&gt;
** CMMC_Assessment_Process | CMMC Assessment Process (CAP) by CyberAB&lt;br /&gt;
** DoD_Assessment_Methodology | DoD Assessment Methodology&lt;br /&gt;
** Evidence_Collection_Approach | CMMC Evidence Collection Approach&lt;br /&gt;
** DoD Memo on ODPs for 800-171 Revision 3 | DoD Memo on Organization-Defined Parameters for NIST 800-171 Revision 3&lt;br /&gt;
* Other Publications and Tools&lt;br /&gt;
** NIST_SP_800-17_R2 | NIST SP 800-171 Rev. 2: Protecting CUI in Nonfederal Systems and Organizations&lt;br /&gt;
** NIST_SP_800-171A | NIST SP 800-171A: Assessing Security Requirements for CUI&lt;br /&gt;
** NIST_SP_800-17_R3 | NIST SP 800-171 Rev. 3: Protecting CUI in Nonfederal Systems and Organizations&lt;br /&gt;
** NIST_SP_800-171A_R3 | NIST SP 800-171A Rev. 3: Assessing Security Requirements for CUI&lt;br /&gt;
** NIST_Cybersecurity_Framework | NIST Cybersecurity Framework (CSF): NIST Cybersecurity Framework&lt;br /&gt;
** External_References | External References&lt;/div&gt;</summary>
		<author><name>David</name></author>
	</entry>
	<entry>
		<id>https://cmmcwiki.org/index.php?title=NIST_SP_800-171A_R3&amp;diff=1637</id>
		<title>NIST SP 800-171A R3</title>
		<link rel="alternate" type="text/html" href="https://cmmcwiki.org/index.php?title=NIST_SP_800-171A_R3&amp;diff=1637"/>
		<updated>2026-07-27T03:01:15Z</updated>

		<summary type="html">&lt;p&gt;David: Created page with &amp;quot;&amp;#039;&amp;#039;&amp;#039;NIST SP 800-171Ar3&amp;#039;&amp;#039;&amp;#039;  = Assessing Security Requirements for Controlled Unclassified Information =  Ron Ross  Computer Security Division, Information Technology Laboratory  Victoria Pillitteri  Computer Security Division, Information Technology Laboratory  This publication is available free of charge from:  https://doi.org/10.6028/NIST.SP.800-171Ar3  May 2024  ----  {{anchor|d30e53-FrontMatterH1}}== Abstract ==  The protection of Controlled Unclassified Information (C...&amp;quot;&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&#039;&#039;&#039;NIST SP 800-171Ar3&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
= Assessing Security Requirements for Controlled Unclassified Information =&lt;br /&gt;
&lt;br /&gt;
Ron Ross&lt;br /&gt;
&lt;br /&gt;
Computer Security Division, Information Technology Laboratory&lt;br /&gt;
&lt;br /&gt;
Victoria Pillitteri&lt;br /&gt;
&lt;br /&gt;
Computer Security Division, Information Technology Laboratory&lt;br /&gt;
&lt;br /&gt;
This publication is available free of charge from:&lt;br /&gt;
&lt;br /&gt;
https://doi.org/10.6028/NIST.SP.800-171Ar3&lt;br /&gt;
&lt;br /&gt;
May 2024&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
{{anchor|d30e53-FrontMatterH1}}== Abstract ==&lt;br /&gt;
&lt;br /&gt;
The protection of Controlled Unclassified Information (CUI) is of paramount importance to federal agencies and can directly impact the ability of the Federal Government to successfully conduct its essential missions and functions. This publication provides organizations with assessment procedures and a methodology that can be used to conduct assessments of the security requirements in NIST Special Publication 800-171, &#039;&#039;Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations&#039;&#039;. The assessment procedures are flexible and can be customized to the needs of organizations and assessors. Assessments can be conducted as independent, third-party assessments or as government-sponsored assessments. The assessments can be applied with various degrees of rigor based on customer-defined depth and coverage attributes.&lt;br /&gt;
&lt;br /&gt;
{{anchor|d30e60-Head1}}== Keywords ==&lt;br /&gt;
&lt;br /&gt;
assessment, assessment method, assessment object, assessment procedure, assurance, Controlled Unclassified Information, coverage, FISMA, NIST Special Publication 800-171, NIST Special Publication 800-53A, nonfederal organization, nonfederal system, security assessment, security requirement.&lt;br /&gt;
&lt;br /&gt;
{{anchor|d30e64-FrontMatterH1}}== Disclaimer ==&lt;br /&gt;
&lt;br /&gt;
Certain equipment, instruments, software, or materials, commercial or non-commercial, are identified in this paper in order to specify the experimental procedure adequately. Such identification does not imply recommendation or endorsement of any product or service by NIST, nor does it imply that the materials or equipment identified are necessarily the best available for the purpose.&lt;br /&gt;
&lt;br /&gt;
There may be references in this publication to other publications currently under development by NIST in accordance with its assigned statutory responsibilities. The information in this publication, including concepts and methodologies, may be used by federal agencies even before the completion of such companion publications. Thus, until each publication is completed, current requirements, guidelines, and procedures, where they exist, remain operative. For planning and transition purposes, federal agencies may wish to closely follow the development of these new publications by NIST.&lt;br /&gt;
&lt;br /&gt;
Organizations are encouraged to review all draft publications during public comment periods and provide feedback to NIST. Many NIST cybersecurity publications, other than the ones noted above, are available at https://csrc.nist.gov/publications.&lt;br /&gt;
&lt;br /&gt;
{{anchor|d30e76-FrontMatterH1}}== Authority ==&lt;br /&gt;
&lt;br /&gt;
This publication has been developed by NIST in accordance with its statutory responsibilities under the Federal Information Security Modernization Act (FISMA) of 2014, 44 U.S.C. § 3551 et seq., Public Law (P.L.) 113-283 &amp;amp;#91;[[#bibr-ref_1|&amp;lt;u&amp;gt;1&amp;lt;/u&amp;gt;]]&amp;amp;#93;. NIST is responsible for developing information security standards and guidelines, including minimum requirements for federal information systems, but such standards and guidelines shall not apply to national security systems without the express approval of appropriate federal officials exercising policy authority over such systems. This guideline is consistent with the requirements of the Office of Management and Budget (OMB) Circular A-130 &amp;amp;#91;[[#bibr-ref_2|&amp;lt;u&amp;gt;2&amp;lt;/u&amp;gt;]]&amp;amp;#93;.&lt;br /&gt;
&lt;br /&gt;
Nothing in this publication should be taken to contradict the standards and guidelines made mandatory and binding on federal agencies by the Secretary of Commerce under statutory authority. Nor should these guidelines be interpreted as altering or superseding the existing authorities of the Secretary of Commerce, Director of the OMB, or any other federal official. This publication may be used by nongovernmental organizations on a voluntary basis and is not subject to copyright in the United States. Attribution would, however, be appreciated by NIST.&lt;br /&gt;
&lt;br /&gt;
{{anchor|d30e91-FrontMatterH1}}== NIST Technical Series Policies ==&lt;br /&gt;
&lt;br /&gt;
[https://doi.org/10.6028/NIST-TECHPUBS.CROSSMARK-POLICY Copyright, Use, and Licensing Statements]&lt;br /&gt;
&lt;br /&gt;
[https://www.nist.gov/document/publication-identifier-syntax-nist-technical-series-publications NIST Technical Series Publication Identifier Syntax]&lt;br /&gt;
&lt;br /&gt;
{{anchor|d30e101-FrontMatterH1}}== Publication History ==&lt;br /&gt;
&lt;br /&gt;
Approved by the NIST Editorial Review Board on 2024-04-23&lt;br /&gt;
&lt;br /&gt;
Supersedes NIST Special Publication 800-171A (June 2018) https://doi.org/10.6028/NIST.SP.800-171A&lt;br /&gt;
&lt;br /&gt;
{{anchor|d30e110-FrontMatterH1}}== How to Cite this NIST Technical Series Publication ==&lt;br /&gt;
&lt;br /&gt;
Ross R, Pillitteri V (2024) Assessing Security Requirements for Controlled Unclassified Information and Organizations. (National Institute of Standards and Technology, Gaithersburg, MD), NIST Special Publication (SP) NIST SP 800-171Ar3. https://doi.org/10.6028/NIST.SP.800-171Ar3&lt;br /&gt;
&lt;br /&gt;
{{anchor|d30e117-FrontMatterH1}}== Author ORCID iDs ==&lt;br /&gt;
&lt;br /&gt;
Ron Ross: 0000-0002-1099-9757&lt;br /&gt;
&lt;br /&gt;
Victoria Pillitteri: 0000-0002-7446-7506&lt;br /&gt;
&lt;br /&gt;
{{anchor|d30e124-FrontMatterH1}}== Submit Comments ==&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;email protected&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
National Institute of Standards and Technology&lt;br /&gt;
&lt;br /&gt;
Attn: Computer Security Division, Information Technology Laboratory&lt;br /&gt;
&lt;br /&gt;
100 Bureau Drive (Mail Stop 8930) Gaithersburg, MD 20899-8930&lt;br /&gt;
&lt;br /&gt;
{{anchor|d30e134-FrontMatterH1}}== Additional Information ==&lt;br /&gt;
&lt;br /&gt;
Additional information about this publication is available at https://csrc.nist.gov/pubs/sp/800/171/a/r3/final, including related content, potential updates, and document history.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;All comments are subject to release under the Freedom of Information Act (FOIA).&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
{{anchor|d30e145-FrontMatterH1}}== Reports on Computer Systems Technology ==&lt;br /&gt;
&lt;br /&gt;
The Information Technology Laboratory (ITL) at the National Institute of Standards and Technology (NIST) promotes the U.S. economy and public welfare by providing technical leadership for the Nation’s measurement and standards infrastructure. ITL develops tests, test methods, reference data, proof of concept implementations, and technical analyses to advance the development and productive use of information technology. ITL’s responsibilities include the development of management, administrative, technical, and physical standards and guidelines for the cost-effective security and privacy of other than national security-related information in federal information systems. The Special Publication 800-series reports on ITL’s research, guidelines, and outreach efforts in information system security, and its collaborative activities with industry, government, and academic organizations.&lt;br /&gt;
&lt;br /&gt;
{{anchor|d30e149-FrontMatterH1}}== Audience ==&lt;br /&gt;
&lt;br /&gt;
This publication serves a diverse group of individuals and organizations in the public and private sectors, including individuals with:&lt;br /&gt;
&lt;br /&gt;
* System development life cycle responsibilities (e.g., program managers, mission/business owners, information owners/stewards, system designers and developers, system/security engineers, systems integrators)&lt;br /&gt;
* Acquisition or procurement responsibilities (e.g., contracting officers)&lt;br /&gt;
* System, security, or risk management and oversight responsibilities (e.g., authorizing officials, chief information officers, chief information security officers, system owners, information security managers)&lt;br /&gt;
* Security assessment and monitoring responsibilities (e.g., auditors, system evaluators, assessors, independent verifiers/validators, analysts)&lt;br /&gt;
&lt;br /&gt;
The above roles and responsibilities can be viewed from two perspectives:&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;Federal perspective&#039;&#039;: The entity establishing and conveying security assessment requirements in contractual vehicles or other types of agreements&lt;br /&gt;
* &#039;&#039;Nonfederal perspective&#039;&#039;: The entity responding to and complying with the security assessment requirements set forth in contracts or agreements&lt;br /&gt;
&lt;br /&gt;
{{anchor|d30e186-FrontMatterH1}}== Patent Disclosure Notice ==&lt;br /&gt;
&lt;br /&gt;
NOTICE: ITL has requested that holders of patent claims whose use may be required for compliance with the guidance or requirements of this publication disclose such patent claims to ITL. However, holders of patents are not obligated to respond to ITL calls for patents and ITL has not undertaken a patent search in order to identify which, if any, patents may apply to this publication.&lt;br /&gt;
&lt;br /&gt;
As of the date of publication and following call(s) for the identification of patent claims whose use may be required for compliance with the guidance or requirements of this publication, no such patent claims have been identified to ITL.&lt;br /&gt;
&lt;br /&gt;
No representation is made or implied by ITL that licenses are not required to avoid patent infringement in the use of this publication.&lt;br /&gt;
&lt;br /&gt;
{{anchor|d30e194-Acknowledgement_Head}}== Acknowledgments ==&lt;br /&gt;
&lt;br /&gt;
The authors gratefully acknowledge and appreciate the significant contributions from individuals and organizations in the public and private sectors whose constructive comments improved the overall quality, thoroughness, and usefulness of this publication. The authors also wish to thank the NIST technical editing and production staff – Jim Foti, Jeff Brewer, Eduardo Takamura, Isabel Van Wyk, Cristina Ritfeld, Derek Sappington, and Chris Enloe – for their outstanding support in preparing this document for publication.&lt;br /&gt;
&lt;br /&gt;
{{anchor|d30e198-FrontMatterH1}}== Historical Contributions ==&lt;br /&gt;
&lt;br /&gt;
The authors wish to acknowledge the following individuals for their historic contributions to this publication: Jon Boyens, Devin Casey, Ned Goren, Gary Guissanie, Jody Jacobs, Jeff Marron, Vicki Michetti, Mark Riddle, Mary Thomas, Gary Stoneburner, Patricia Toth, and Patrick Viscuso.&lt;br /&gt;
&lt;br /&gt;
{{anchor|d30e207-Head1}}{{anchor|sec-sec_1}}== 1 Introduction ==&lt;br /&gt;
&lt;br /&gt;
The security assessment process gathers information and produces evidence to determine the effectiveness of security requirements by:&lt;br /&gt;
&lt;br /&gt;
* Identifying potential problems or shortfalls in security and risk management programs&lt;br /&gt;
* Identifying security weaknesses and deficiencies in systems and the environments in which those systems operate&lt;br /&gt;
* Prioritizing risk mitigation decisions and activities&lt;br /&gt;
* Confirming that identified security weaknesses and deficiencies in the system and environment of operation have been addressed&lt;br /&gt;
* Supporting continuous monitoring activities and providing information security situational awareness&lt;br /&gt;
&lt;br /&gt;
{{anchor|d30e233-Head2}}{{anchor|sec-sec_1.1}}== 1.1 Purpose and Applicability ==&lt;br /&gt;
&lt;br /&gt;
The purpose of this publication is to provide procedures for assessing the security requirements in NIST Special Publication (SP) 800-171, &#039;&#039;Protecting Controlled Unclassified Information (CUI) in Nonfederal Systems and Organizations&#039;&#039; &amp;amp;#91;[[#bibr-ref_3|&amp;lt;u&amp;gt;3&amp;lt;/u&amp;gt;]]&amp;amp;#93;. Organizations can use the assessment procedures to generate evidence that the security requirements have been satisfied. The scope of the security assessments conducted using the procedures described in this publication is guided and informed by the system security plans for systems that process, store, or transmit CUI. The assessment procedures offer the flexibility to customize assessments based on organizational policies and requirements, known threat and vulnerability information, system and platform dependencies, operational considerations, and tolerance for risk.{{anchor|footnote-1-backlink}}[[#footnote-1|1]]&lt;br /&gt;
&lt;br /&gt;
{{anchor|d30e257-Head2}}{{anchor|sec-sec_1.2}}== 1.2 Organization of This Publication ==&lt;br /&gt;
&lt;br /&gt;
The remainder of this special publication is organized as follows:&lt;br /&gt;
&lt;br /&gt;
* [[#sec-sec_2|Section 2]] describes the fundamental concepts associated with assessments of security requirements, including assessment procedures, methods, objects, and assurance cases that can be created using the evidence produced during assessments.&lt;br /&gt;
* [[#sec-sec_3|Section 3]] provides assessment procedures for the security requirements in SP 800-171, including assessment objectives and potential assessment methods and objects for each procedure.&lt;br /&gt;
&lt;br /&gt;
The following sections provide additional information to support the protection of CUI:&lt;br /&gt;
&lt;br /&gt;
* References&lt;br /&gt;
* Appendix A: Acronyms&lt;br /&gt;
* Appendix B: Glossary&lt;br /&gt;
* Appendix C: Security Requirement Assessments&lt;br /&gt;
* Appendix D: Organization-Defined Parameters&lt;br /&gt;
* Appendix E: Change Log&lt;br /&gt;
&lt;br /&gt;
{{anchor|box_a}}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;blockquote&amp;gt;&lt;br /&gt;
The contents of this publication can be used for many different assessment-related purposes to determine organizational compliance with the security requirements. The broad range of potential assessment methods and objects listed in this publication does not necessarily reflect and should not be directly associated with actual compliance or noncompliance. Rather, the selection of specific assessment methods and objects from the list provided can help generate a picture of overall compliance with the security requirements. There is no expectation about the number of methods or objects needed to determine compliance with the security requirements. Moreover, the entire list of potential assessment objects should not be viewed as required artifacts needed to determine compliance. Organizations have the flexibility to determine the specific methods and objects sufficient to obtain the needed evidence to support any claims of compliance.&lt;br /&gt;
&amp;lt;/blockquote&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{{anchor|d30e306-Head1}}{{anchor|sec-sec_2}}== 2 The Fundamentals ==&lt;br /&gt;
&lt;br /&gt;
The process used by organizations and assessors to assess the security requirements in SP 800-171 &amp;amp;#91;[[#bibr-ref_3|3]]&amp;amp;#93; includes (1) preparing for the assessment, (2) developing a security assessment plan, (3) conducting the assessment, and (4) documenting, analyzing, and reporting the assessment results.{{anchor|footnote-2-backlink}}[[#footnote-2|2]] The remainder of this section describes the structure and content of the procedures used to assess the security requirements and the importance of assurance cases in providing the evidence necessary to determine compliance with the requirements.&lt;br /&gt;
&lt;br /&gt;
{{anchor|d30e324-Head2}}{{anchor|sec-sec_2.1}}== 2.1 Assessment Procedures ==&lt;br /&gt;
&lt;br /&gt;
The security requirements in SP 800-171 are organized into 17 families, as illustrated in [[#table-tab_1|Table 1]]. The assessment procedures in Sec. 3 are grouped by similar family designations to ensure the completeness and consistency of assessments. The procedures have been derived from the assessment procedures in SP 800-53A &amp;amp;#91;[[#bibr-ref_5|&amp;lt;u&amp;gt;5&amp;lt;/u&amp;gt;]]&amp;amp;#93;.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;{{anchor|d30e338}}Table 1. Security Requirement Families&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Access Control !! Maintenance !! Security Assessment and Monitoring&lt;br /&gt;
|-&lt;br /&gt;
| Awareness and Training || Media Protection || System and Communications Protection&lt;br /&gt;
|-&lt;br /&gt;
| Audit and Accountability || Personnel Security || System and Information Integrity&lt;br /&gt;
|-&lt;br /&gt;
| Configuration Management || Physical Protection || Planning&lt;br /&gt;
|-&lt;br /&gt;
| Identification and Authentication || Risk Assessment || System and Services Acquisition&lt;br /&gt;
|-&lt;br /&gt;
| Incident Response ||  || Supply Chain Risk Management&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
An assessment procedure consists of an assessment &#039;&#039;objective&#039;&#039; and a set of potential assessment &#039;&#039;methods&#039;&#039; and &#039;&#039;objects&#039;&#039; that can be used to conduct the assessment. Each potential assessment objective includes a determination statement related to the security requirement. If there is an organization-defined parameter (ODP) in the security requirement, then the assessment objective begins with a determination statement related to the definition of the ODP. The determination statements are linked to the content of the security requirements to help ensure traceability of the assessment results to the requirements.&lt;br /&gt;
&lt;br /&gt;
Assessment objects identify the specific items being assessed and can include specifications, mechanisms, activities, and individuals. Specifications are the documented artifacts{{anchor|footnote-3-backlink}}[[#footnote-3|3]] (e.g., plans, policies, procedures, requirements, functional and assurance specifications, design documentation, and architectures) associated with a system. Mechanisms are the hardware, software, and firmware safeguards implemented within a system. Activities are the protection-related actions supporting a system that involve people (e.g., conducting system backup operations, exercising an incident response plan, and monitoring network traffic). Individuals are the people applying the specifications, mechanisms, or activities described above.&lt;br /&gt;
&lt;br /&gt;
Assessment methods define the nature and extent of the assessor’s actions and are used to facilitate understanding, achieve clarification, or obtain evidence. The assessment methods include &#039;&#039;examine&#039;&#039;, &#039;&#039;interview&#039;&#039;, and &#039;&#039;test&#039;&#039;. The examine method is the process of reviewing, studying, inspecting, or analyzing assessment objects. The interview method is the process of holding discussions with individuals or groups about assessment objects. The test method is the process of exercising assessment objects (i.e., activities, mechanisms) under specified conditions to compare actual with expected behavior. Assessment methods include attributes of &#039;&#039;depth&#039;&#039; and &#039;&#039;coverage&#039;&#039;, which define the rigor, scope, and level of effort for the assessment as well as the degree of assurance that the security requirements have been satisfied. See SP 800-53A, [[#sec-sec_C|Appendix C]], &#039;&#039;Assessment Method Descriptions&#039;&#039; &amp;amp;#91;[[#bibr-ref_5|&amp;lt;u&amp;gt;5&amp;lt;/u&amp;gt;]]&amp;amp;#93;.&lt;br /&gt;
&lt;br /&gt;
The structure and content of an assessment procedure are provided in the example below:&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[Figure: Security Requirement Name]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;03.01.06 Least Privilege – Privileged Accounts&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;[Figure: Multi-Part Determination Statement and ODP for Security Requirement]&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;ASSESSMENT OBJECTIVE&#039;&#039;&#039;&lt;br /&gt;
* &#039;&#039;Determine if:&#039;&#039;&lt;br /&gt;
* &#039;&#039;&#039;A.03.01.06.ODP&amp;amp;#91;01&amp;amp;#93;: &#039;&#039;&#039;&amp;lt;nowiki/&amp;gt;&#039;&#039;&#039;&#039;&#039;personnel or roles to which privileged accounts on the system are to be restricted are defined&#039;&#039;&#039;&#039;&#039;&amp;lt;nowiki/&amp;gt;&#039;&#039;&#039;.&#039;&#039;&#039;&lt;br /&gt;
* &#039;&#039;&#039;A.03.01.06.a:&#039;&#039;&#039; privileged accounts on the system are restricted to &#039;&#039;&#039;&#039;&#039;&amp;lt;A.03.01.06.ODP&amp;amp;#91;01&amp;amp;#93;: personnel or roles&amp;gt;&#039;&#039;&#039;&#039;&#039;.&lt;br /&gt;
* &#039;&#039;&#039;A.03.01.06.b:&#039;&#039;&#039; users (or roles) with privileged accounts are required to use non-privileged accounts when accessing non-security functions or non-security information.&lt;br /&gt;
* &#039;&#039;&#039;ASSESSMENT METHODS AND OBJECTS&#039;&#039;&#039;&lt;br /&gt;
* &#039;&#039;&#039;Examine&#039;&#039;&#039;&lt;br /&gt;
* &amp;amp;#91;SELECT FROM: access control policy and procedures; procedures for least privilege; list of system-generated privileged accounts; list of system administration personnel; system audit records; system configuration settings; system security plan; list of system-generated security functions or security-relevant information assigned to system accounts or roles; other relevant documents or records&amp;amp;#93;&lt;br /&gt;
* &#039;&#039;&#039;Interview&#039;&#039;&#039;&lt;br /&gt;
* &amp;amp;#91;SELECT FROM: personnel with responsibilities for defining least privileges; personnel with information security responsibilities; system administrators&amp;amp;#93;&lt;br /&gt;
* &#039;&#039;&#039;Test&#039;&#039;&#039;&lt;br /&gt;
* &amp;amp;#91;SELECT FROM: mechanisms for implementing least privilege functions&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
==== REFERENCES ====&lt;br /&gt;
&lt;br /&gt;
Source Assessment Procedures: [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_A_5_1_1/home?element=AC-06 AC-06(02)], [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_A_5_1_1/home?element=AC-06 AC-06(05)]&lt;br /&gt;
&lt;br /&gt;
Determination statements have alphanumeric identifiers. Each determination statement begins with the letter “&#039;&#039;&#039;A&#039;&#039;&#039;” to indicate that it is part of an assessment procedure. The next sequence of numbers or letters (e.g., [[#A.03.01.01.e|03.01.01.e]] or [[#A.03.01.01.f.02|03.01.01.f.02]]) indicates the security requirement identifier from NIST SP 800-171 (and the specific control item if it is a multi-part requirement) that is the target of the assessment. Organization-defined parameters are indicated by the letters “&#039;&#039;&#039;ODP&#039;&#039;&#039;.” If there are multiple ODPs in the determination statement, the ODP number is indicated in a square bracket (e.g., [[#A.03.01.08.ODP[01]|A.03.01.08.ODP&amp;amp;#91;01&amp;amp;#93;]]). Square brackets are also used to denote when an assessment procedure further decomposes a requirement into more granular determination statements (e.g., [[#A.03.01.12.a[01]|A.03.01.12.a&amp;amp;#91;01&amp;amp;#93;]], [[#A.03.01.12.a[02]|A.03.01.12.a&amp;amp;#91;02&amp;amp;#93;]], [[#A.03.01.12.a[03]|A.03.01.12.a&amp;amp;#91;03&amp;amp;#93;]]).&lt;br /&gt;
&lt;br /&gt;
The application of an assessment procedure to a security requirement produces assessment results or &#039;&#039;findings&#039;&#039;. The findings are compiled and used as evidence to determine whether the security requirement has been &#039;&#039;satisfied&#039;&#039; or &#039;&#039;other than satisfied&#039;&#039;. A finding of satisfied indicates that the assessment objective has been met, producing a fully acceptable result. A finding of other than satisfied indicates that there are potential anomalies that may need to be addressed by the organization. A finding of other than satisfied may also indicate that the assessor was unable to obtain sufficient information to make the determination called for in the determination statement.&lt;br /&gt;
&lt;br /&gt;
{{anchor|d30e589-Head2}}{{anchor|sec-sec_2.2}}== 2.2 Assurance Cases ==&lt;br /&gt;
&lt;br /&gt;
Building an effective assurance case to determine compliance with security requirements involves compiling evidence from a variety of sources and conducting different types of activities during an assessment. An &#039;&#039;assurance case&#039;&#039; is a body of evidence organized into an argument demonstrating that some claim about a system is true. For security assessments conducted using the procedures in this publication, that claim is “compliance” with the security requirements in SP 800-171. Assessors obtain evidence during security assessments to allow designated officials{{anchor|footnote-4-backlink}}[[#footnote-4|4]] to make objective determinations about compliance with the security requirements. The evidence needed to make such determinations can be obtained from various sources, including independent, third-party assessments or other types of assessments, depending on the needs of the organization establishing the requirements and the organization conducting the assessments.&lt;br /&gt;
&lt;br /&gt;
For example, many technical security requirements are satisfied by security capabilities that are built into commercial information technology products and systems. Product assessments are typically conducted by independent, third-party testing organizations.{{anchor|footnote-5-backlink}}[[#footnote-5|5]] These assessments examine the security functions of products and established configuration settings. Assessments can also be conducted to demonstrate compliance with industry, national, or international security standards as well as developer and vendor claims. Since many information technology products are assessed by commercial testing organizations and then subsequently deployed in hundreds of thousands of systems, these types of assessments can be carried out at a greater level of depth and provide deeper insights into the security capabilities of the products.&lt;br /&gt;
&lt;br /&gt;
The evidence needed to determine compliance with the security requirements is obtained by assessing the implementation of the safeguards and countermeasures selected to satisfy the requirements. Assessors can build on previously developed materials that started with the specification of the information security needs of the organization and were further improved during the design, development, and implementation of the system. These materials provide the initial evidence for an assurance case.&lt;br /&gt;
&lt;br /&gt;
Assessments can be conducted by system developers, system integrators, auditors, system owners, or the security staffs of organizations. The assessors or assessment teams bring available information about the system together, such as the results of component product assessments. The assessors can conduct additional system-level assessments using the assessment methods and procedures contained in this publication and the implementation information provided by the nonfederal organization in its system security plan. Assessments can be used to compile and evaluate the evidence needed by organizations to help determine the effectiveness of the safeguards implemented to protect CUI, the actions needed to mitigate security risks to the organization, and compliance with the security requirements.&lt;br /&gt;
&lt;br /&gt;
{{anchor|box_b}}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;blockquote&amp;gt;&lt;br /&gt;
The assessment procedures in this publication are based on and sourced to the assessment procedures in SP 800-53A &amp;amp;#91;[[#bibr-ref_5|5]]&amp;amp;#93;. For additional information and guidance on preparing for security assessments, developing assessment plans, conducting assessments, and analyzing assessment report results, consult SP 800-53A &amp;amp;#91;[[#bibr-ref_5|5]]&amp;amp;#93;.&lt;br /&gt;
&amp;lt;/blockquote&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{{anchor|d30e634-Head1}}{{anchor|sec-sec_3}}== 3 The Procedures ==&lt;br /&gt;
&lt;br /&gt;
This section provides assessment procedures for the security requirements defined in NIST SP 800-171 &amp;amp;#91;[[#bibr-ref_3|3]]&amp;amp;#93;. Organizations that conduct security requirement assessments can develop their security assessment plans by using the information provided in the assessment procedures and selecting the specific assessment methods and objects that meet the organization’s needs. Organizations also have flexibility in defining the level of rigor and detail associated with the assessment based on the assurance requirements of the organization.&lt;br /&gt;
&lt;br /&gt;
{{anchor|d30e644-Head2}}{{anchor|sec-sec_3.1}}== 3.1 [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=AC Access Control] ==&lt;br /&gt;
&lt;br /&gt;
{{anchor|d30e649-Head3}}{{anchor|sec-sec_03.01.01}}=== 03.01.01 Account Management ===&lt;br /&gt;
&lt;br /&gt;
==== ASSESSMENT OBJECTIVE ====&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Determine if:&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.01.01.ODP[01]}}A.03.01.01.ODP&amp;amp;#91;01&amp;amp;#93;: &#039;&#039;&#039;&amp;lt;nowiki/&amp;gt;&#039;&#039;&#039;&#039;&#039;the time period for account inactivity before disabling is defined&#039;&#039;&#039;&#039;&#039;&amp;lt;nowiki/&amp;gt;&#039;&#039;&#039;.&#039;&#039;&#039;&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.01.01.ODP[02]}}A.03.01.01.ODP&amp;amp;#91;02&amp;amp;#93;: &#039;&#039;&#039;&amp;lt;nowiki/&amp;gt;&#039;&#039;&#039;&#039;&#039;the time period within which to notify account managers and designated personnel or roles when accounts are no longer required is defined&#039;&#039;&#039;&#039;&#039;&amp;lt;nowiki/&amp;gt;&#039;&#039;&#039;.&#039;&#039;&#039;&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.01.01.ODP[03]}}A.03.01.01.ODP&amp;amp;#91;03&amp;amp;#93;: &#039;&#039;&#039;&amp;lt;nowiki/&amp;gt;&#039;&#039;&#039;&#039;&#039;the time period within which to notify account managers and designated personnel or roles when users are terminated or transferred is defined&#039;&#039;&#039;&#039;&#039;&amp;lt;nowiki/&amp;gt;&#039;&#039;&#039;.&#039;&#039;&#039;&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.01.01.ODP[04]}}A.03.01.01.ODP&amp;amp;#91;04&amp;amp;#93;: &#039;&#039;&#039;&amp;lt;nowiki/&amp;gt;&#039;&#039;&#039;&#039;&#039;the time period within which to notify account managers and designated personnel or roles when system usage or the need-to-know changes for an individual is defined&#039;&#039;&#039;&#039;&#039;&amp;lt;nowiki/&amp;gt;&#039;&#039;&#039;.&#039;&#039;&#039;&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.01.01.ODP[05]}}A.03.01.01.ODP&amp;amp;#91;05&amp;amp;#93;: &#039;&#039;&#039;&amp;lt;nowiki/&amp;gt;&#039;&#039;&#039;&#039;&#039;the time period of expected inactivity requiring users to log out of the system is defined&#039;&#039;&#039;&#039;&#039;&amp;lt;nowiki/&amp;gt;&#039;&#039;&#039;.&#039;&#039;&#039;&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.01.01.ODP[06]}}A.03.01.01.ODP&amp;amp;#91;06&amp;amp;#93;: &#039;&#039;&#039;&amp;lt;nowiki/&amp;gt;&#039;&#039;&#039;&#039;&#039;circumstances requiring users to log out of the system are defined&#039;&#039;&#039;&#039;&#039;&amp;lt;nowiki/&amp;gt;&#039;&#039;&#039;.&#039;&#039;&#039;&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.01.01.a[01]}}A.03.01.01.a&amp;amp;#91;01&amp;amp;#93;:&#039;&#039;&#039; system account types allowed are defined.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.01.01.a[02]}}A.03.01.01.a&amp;amp;#91;02&amp;amp;#93;:&#039;&#039;&#039; system account types prohibited are defined.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.01.01.b[01]}}A.03.01.01.b&amp;amp;#91;01&amp;amp;#93;:&#039;&#039;&#039; system accounts are created in accordance with organizational policy, procedures, prerequisites, and criteria.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.01.01.b[02]}}A.03.01.01.b&amp;amp;#91;02&amp;amp;#93;:&#039;&#039;&#039; system accounts are enabled in accordance with organizational policy, procedures, prerequisites, and criteria.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.01.01.b[03]}}A.03.01.01.b&amp;amp;#91;03&amp;amp;#93;:&#039;&#039;&#039; system accounts are modified in accordance with organizational policy, procedures, prerequisites, and criteria.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.01.01.b[04]}}A.03.01.01.b&amp;amp;#91;04&amp;amp;#93;:&#039;&#039;&#039; system accounts are disabled in accordance with organizational policy, procedures, prerequisites, and criteria.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.01.01.b[05]}}A.03.01.01.b&amp;amp;#91;05&amp;amp;#93;:&#039;&#039;&#039; system accounts are removed in accordance with organizational policy, procedures, prerequisites, and criteria.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.01.01.c.01}}A.03.01.01.c.01:&#039;&#039;&#039; authorized users of the system are specified.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.01.01.c.02}}A.03.01.01.c.02:&#039;&#039;&#039; group and role memberships are specified.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.01.01.c.03}}A.03.01.01.c.03:&#039;&#039;&#039; access authorizations (i.e., privileges) for each account are specified.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.01.01.d.01}}A.03.01.01.d.01:&#039;&#039;&#039; access to the system is authorized based on a valid access authorization.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.01.01.d.02}}A.03.01.01.d.02:&#039;&#039;&#039; access to the system is authorized based on intended system usage.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.01.01.e}}A.03.01.01.e:&#039;&#039;&#039; the use of system accounts is monitored.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.01.01.f.01}}A.03.01.01.f.01:&#039;&#039;&#039; system accounts are disabled when the accounts have expired.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.01.01.f.02}}A.03.01.01.f.02:&#039;&#039;&#039; system accounts are disabled when the accounts have been inactive for &#039;&#039;&#039;&#039;&#039;&amp;lt;A.03.01.01.ODP&amp;amp;#91;01&amp;amp;#93;: time period&amp;gt;&#039;&#039;&#039;&#039;&#039;.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.01.01.f.03}}A.03.01.01.f.03:&#039;&#039;&#039; system accounts are disabled when the accounts are no longer associated with a user or individual.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.01.01.f.04}}A.03.01.01.f.04:&#039;&#039;&#039; system accounts are disabled when the accounts violate organizational policy.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.01.01.f.05}}A.03.01.01.f.05:&#039;&#039;&#039; system accounts are disabled when significant risks associated with individuals are discovered.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.01.01.g.01}}A.03.01.01.g.01:&#039;&#039;&#039; account managers and designated personnel or roles are notified within &#039;&#039;&#039;&#039;&#039;&amp;lt;A.03.01.01.ODP&amp;amp;#91;02&amp;amp;#93;: time period&amp;gt;&#039;&#039;&#039;&#039;&#039; when accounts are no longer required.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.01.01.g.02}}A.03.01.01.g.02:&#039;&#039;&#039; account managers and designated personnel or roles are notified within &#039;&#039;&#039;&#039;&#039;&amp;lt;A.03.01.01.ODP&amp;amp;#91;03&amp;amp;#93;: time period&amp;gt;&#039;&#039;&#039;&#039;&#039; when users are terminated or transferred.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.01.01.g.03}}A.03.01.01.g.03:&#039;&#039;&#039; account managers and designated personnel or roles are notified within &#039;&#039;&#039;&#039;&#039;&amp;lt;A.03.01.01.ODP&amp;amp;#91;04&amp;amp;#93;: time period&amp;gt;&#039;&#039;&#039;&#039;&#039; when system usage or the need-to-know changes for an individual.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.01.01.h}}A.03.01.01.h:&#039;&#039;&#039; users are required to log out of the system after &#039;&#039;&#039;&#039;&#039;&amp;lt;A.03.01.01.ODP&amp;amp;#91;05&amp;amp;#93;: time period&amp;gt;&#039;&#039;&#039;&#039;&#039; of expected inactivity or when the following circumstances occur: &#039;&#039;&#039;&#039;&#039;&amp;lt;A.03.01.01.ODP&amp;amp;#91;06&amp;amp;#93;: circumstances&amp;gt;&#039;&#039;&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
==== ASSESSMENT METHODS AND OBJECTS ====&lt;br /&gt;
&lt;br /&gt;
===== Examine =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: access control policy and procedures; personnel termination or transfer policies and procedures; procedures for account management; list of active system accounts and the name of the individual associated with each account; system design documentation; list of conditions for group and role membership; system configuration settings; notifications of recent transfers, separations, or terminations of employees; list of recently disabled system accounts and the name of the individual associated with each account; list of user activities that pose significant organizational risks; access authorization records; account management compliance reviews; system monitoring and audit records; system security plan; system-generated list of accounts removed; system-generated list of emergency accounts disabled; system-generated list of disabled accounts; other relevant documents and records&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
===== Interview =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: personnel with account management responsibilities; system administrators; personnel with information security responsibilities; system developers&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
===== Test =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: processes for account management on the system; mechanisms for implementing account management&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
==== REFERENCES ====&lt;br /&gt;
&lt;br /&gt;
Source Assessment Procedures: [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_A_5_1_1/home?element=AC-02 AC-02], [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_A_5_1_1/home?element=AC-02 AC-02(03)], [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=AC-02 AC-02(05)], [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_A_5_1_1/home?element=AC-02 AC-02(13)]&lt;br /&gt;
&lt;br /&gt;
{{anchor|d30e878-Head3}}{{anchor|sec-sec_03.01.02}}=== 03.01.02 Access Enforcement ===&lt;br /&gt;
&lt;br /&gt;
==== ASSESSMENT OBJECTIVE ====&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Determine if:&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;A.03.01.02&amp;amp;#91;01&amp;amp;#93;:&#039;&#039;&#039; approved authorizations for logical access to CUI are enforced in accordance with applicable access control policies.&lt;br /&gt;
* &#039;&#039;&#039;A.03.01.02&amp;amp;#91;02&amp;amp;#93;:&#039;&#039;&#039; approved authorizations for logical access to system resources are enforced in accordance with applicable access control policies.&lt;br /&gt;
&lt;br /&gt;
==== ASSESSMENT METHODS AND OBJECTS ====&lt;br /&gt;
&lt;br /&gt;
===== Examine =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: access control policy and procedures; procedures for access enforcement; system design documentation; system configuration settings; list of approved authorizations (i.e., user privileges); system audit records; system security plan; other relevant documents or records&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
===== Interview =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: personnel with access enforcement responsibilities; system administrators; personnel with information security responsibilities; system developers&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
===== Test =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: mechanisms for implementing the access control policy&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
==== REFERENCES ====&lt;br /&gt;
&lt;br /&gt;
Source Assessment Procedure: [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_A_5_1_1/home?element=AC-03 AC-03]&lt;br /&gt;
&lt;br /&gt;
{{anchor|d30e918-Head3}}{{anchor|sec-sec_03.01.03}}=== 03.01.03 Information Flow Enforcement ===&lt;br /&gt;
&lt;br /&gt;
==== ASSESSMENT OBJECTIVE ====&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Determine if:&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;A.03.01.03&amp;amp;#91;01&amp;amp;#93;:&#039;&#039;&#039; approved authorizations are enforced for controlling the flow of CUI within the system.&lt;br /&gt;
* &#039;&#039;&#039;A.03.01.03&amp;amp;#91;02&amp;amp;#93;:&#039;&#039;&#039; approved authorizations are enforced for controlling the flow of CUI between connected systems.&lt;br /&gt;
&lt;br /&gt;
==== ASSESSMENT METHODS AND OBJECTS ====&lt;br /&gt;
&lt;br /&gt;
===== Examine =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: access control policy and procedures; information flow control policies; procedures for information flow enforcement; security architecture and design documentation; system configuration settings; system baseline configuration; system audit records; list of information flow authorizations; system security plan; other relevant documents or records&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
===== Interview =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: system administrators; personnel with security architecture responsibilities; personnel with information security responsibilities; system developers&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
===== Test =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: mechanisms for implementing the information flow enforcement policy&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
==== REFERENCES ====&lt;br /&gt;
&lt;br /&gt;
Source Assessment Procedure: [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_A_5_1_1/home?element=AC-04 AC-04]&lt;br /&gt;
&lt;br /&gt;
{{anchor|d30e958-Head3}}{{anchor|sec-sec_03.01.04}}=== 03.01.04 Separation of Duties ===&lt;br /&gt;
&lt;br /&gt;
==== ASSESSMENT OBJECTIVE ====&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Determine if:&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.01.04.a}}A.03.01.04.a:&#039;&#039;&#039; duties of individuals requiring separation are identified.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.01.04.b}}A.03.01.04.b:&#039;&#039;&#039; system access authorizations to support separation of duties are defined.&lt;br /&gt;
&lt;br /&gt;
==== ASSESSMENT METHODS AND OBJECTS ====&lt;br /&gt;
&lt;br /&gt;
===== Examine =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: access control policy and procedures; procedures for the separation of duties and the division of responsibilities; system configuration settings; system audit records; system access authorizations; list of divisions of responsibility and separation of duties; system security plan; other relevant documents or records&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
===== Interview =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: personnel with responsibilities for defining the separation of duties and the division of responsibilities; personnel with information security responsibilities; system administrators&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
===== Test =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: mechanisms for implementing the separation of duties policy&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
==== REFERENCES ====&lt;br /&gt;
&lt;br /&gt;
Source Assessment Procedure: [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_A_5_1_1/home?element=AC-05 AC-05]&lt;br /&gt;
&lt;br /&gt;
{{anchor|d30e1000-Head3}}{{anchor|sec-sec_03.01.05}}=== 03.01.05 Least Privilege ===&lt;br /&gt;
&lt;br /&gt;
==== ASSESSMENT OBJECTIVE ====&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Determine if:&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.01.05.ODP[01]}}A.03.01.05.ODP&amp;amp;#91;01&amp;amp;#93;: &#039;&#039;&#039;&amp;lt;nowiki/&amp;gt;&#039;&#039;&#039;&#039;&#039;security functions for authorized access are defined.&#039;&#039;&#039;&#039;&#039;&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.01.05.ODP[02]}}A.03.01.05.ODP&amp;amp;#91;02&amp;amp;#93;: &#039;&#039;&#039;&amp;lt;nowiki/&amp;gt;&#039;&#039;&#039;&#039;&#039;security-relevant information for authorized access is defined.&#039;&#039;&#039;&#039;&#039;&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.01.05.ODP[03]}}A.03.01.05.ODP&amp;amp;#91;03&amp;amp;#93;: &#039;&#039;&#039;&amp;lt;nowiki/&amp;gt;&#039;&#039;&#039;&#039;&#039;the frequency at which to review the privileges assigned to roles or classes of users is defined.&#039;&#039;&#039;&#039;&#039;&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.01.05.a}}A.03.01.05.a:&#039;&#039;&#039; system access for users (or processes acting on behalf of users) is authorized only when necessary to accomplish assigned organizational tasks.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.01.05.b[01]}}A.03.01.05.b&amp;amp;#91;01&amp;amp;#93;:&#039;&#039;&#039; access to &#039;&#039;&#039;&#039;&#039;&amp;lt;A.03.01.05.ODP&amp;amp;#91;01&amp;amp;#93;: security functions&amp;gt;&#039;&#039;&#039;&#039;&#039; is authorized.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.01.05.b[02]}}A.03.01.05.b&amp;amp;#91;02&amp;amp;#93;:&#039;&#039;&#039; access to &#039;&#039;&#039;&#039;&#039;&amp;lt;A.03.01.05.ODP&amp;amp;#91;02&amp;amp;#93;: security-relevant information&amp;gt;&#039;&#039;&#039;&#039;&#039; is authorized.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.01.05.c}}A.03.01.05.c:&#039;&#039;&#039; the privileges assigned to roles or classes of users are reviewed &#039;&#039;&#039;&#039;&#039;&amp;lt;A.03.01.05.ODP&amp;amp;#91;03&amp;amp;#93;: frequency&amp;gt;&#039;&#039;&#039;&#039;&#039; to validate the need for such privileges.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.01.05.d}}A.03.01.05.d:&#039;&#039;&#039; privileges are reassigned or removed, as necessary.&lt;br /&gt;
&lt;br /&gt;
==== ASSESSMENT METHODS AND OBJECTS ====&lt;br /&gt;
&lt;br /&gt;
===== Examine =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: access control policy and procedures; procedures for least privilege; list of assigned access authorizations (i.e., privileges); system configuration settings; system audit records; list of security functions (implemented in hardware, software, and firmware); security-relevant information for which access must be explicitly authorized; list of system-generated roles or classes of users and assigned privileges; validation reviews of privileges assigned to roles or classes of users; records of privilege removals or reassignments for roles or classes of users; system security plan; system design documentation; other relevant documents or records&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
===== Interview =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: personnel with responsibilities for defining least privileges; personnel with information security responsibilities; system administrators&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
===== Test =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: mechanisms for implementing least privilege functions; mechanisms for implementing reviews of user privileges&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
==== REFERENCES ====&lt;br /&gt;
&lt;br /&gt;
Source Assessment Procedures: [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_A_5_1_1/home?element=AC-06 AC-06], [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_A_5_1_1/home?element=AC-06 AC-06(01)], [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_A_5_1_1/home?element=AC-06 AC-06(07)], [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_A_5_1_1/home?element=AU-09 AU-09(04)]&lt;br /&gt;
&lt;br /&gt;
{{anchor|d30e1100-Head3}}{{anchor|sec-sec_03.01.06}}=== 03.01.06 Least Privilege – Privileged Accounts ===&lt;br /&gt;
&lt;br /&gt;
==== ASSESSMENT OBJECTIVE ====&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Determine if:&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.01.06.ODP[01]}}A.03.01.06.ODP&amp;amp;#91;01&amp;amp;#93;: &#039;&#039;&#039;&amp;lt;nowiki/&amp;gt;&#039;&#039;&#039;&#039;&#039;personnel or roles to which privileged accounts on the system are to be restricted are defined.&#039;&#039;&#039;&#039;&#039;&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.01.06.a}}A.03.01.06.a:&#039;&#039;&#039; privileged accounts on the system are restricted to &#039;&#039;&#039;&#039;&#039;&amp;lt;A.03.01.06.ODP&amp;amp;#91;01&amp;amp;#93;: personnel or roles&amp;gt;&#039;&#039;&#039;&#039;&#039;.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.01.06.b}}A.03.01.06.b:&#039;&#039;&#039; users (or roles) with privileged accounts are required to use non-privileged accounts when accessing non-security functions or non-security information.&lt;br /&gt;
&lt;br /&gt;
==== ASSESSMENT METHODS AND OBJECTS ====&lt;br /&gt;
&lt;br /&gt;
===== Examine =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: access control policy and procedures; procedures for least privilege; list of system-generated privileged accounts; list of system administration personnel; system audit records; system configuration settings; system security plan; list of system-generated security functions or security-relevant information assigned to system accounts or roles; other relevant documents or records&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
===== Interview =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: personnel with responsibilities for defining least privileges; personnel with information security responsibilities; system administrators&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
===== Test =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: mechanisms for implementing least privilege functions&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
==== REFERENCES ====&lt;br /&gt;
&lt;br /&gt;
Source Assessment Procedures: [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_A_5_1_1/home?element=AC-06 AC-06(02)], [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_A_5_1_1/home?element=AC-06 AC-06(05)]&lt;br /&gt;
&lt;br /&gt;
{{anchor|d30e1157-Head3}}{{anchor|sec-sec_03.01.07}}=== 03.01.07 Least Privilege – Privileged Functions ===&lt;br /&gt;
&lt;br /&gt;
==== ASSESSMENT OBJECTIVE ====&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Determine if:&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.01.07.a}}A.03.01.07.a:&#039;&#039;&#039; non-privileged users are prevented from executing privileged functions.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.01.07.b}}A.03.01.07.b:&#039;&#039;&#039; the execution of privileged functions is logged.&lt;br /&gt;
&lt;br /&gt;
==== ASSESSMENT METHODS AND OBJECTS ====&lt;br /&gt;
&lt;br /&gt;
===== Examine =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: access control policy and procedures; procedures for least privilege; system design documentation; system configuration settings; system audit records; list of audited events; list of privileged functions to be audited and associated user account assignments; system security plan; other relevant documents or records&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
===== Interview =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: personnel with responsibilities for reviewing least privileges; personnel with information security responsibilities; system developers; system administrators&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
===== Test =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: mechanisms for auditing the execution of least privilege functions; mechanisms for implementing least privilege functions for non-privileged users&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
==== REFERENCES ====&lt;br /&gt;
&lt;br /&gt;
Source Assessment Procedures: [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_A_5_1_1/home?element=AC-06 AC-06(09)], [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_A_5_1_1/home?element=AC-06 AC-06(10)]&lt;br /&gt;
&lt;br /&gt;
{{anchor|d30e1203-Head3}}{{anchor|sec-sec_03.01.08}}=== 03.01.08 Unsuccessful Logon Attempts ===&lt;br /&gt;
&lt;br /&gt;
==== ASSESSMENT OBJECTIVE ====&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Determine if:&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.01.08.ODP[01]}}A.03.01.08.ODP&amp;amp;#91;01&amp;amp;#93;: &#039;&#039;&#039;&amp;lt;nowiki/&amp;gt;&#039;&#039;&#039;&#039;&#039;the number of consecutive invalid logon attempts by a user allowed during a time period is defined&#039;&#039;&#039;&#039;&#039;&amp;lt;nowiki/&amp;gt;&#039;&#039;&#039;.&#039;&#039;&#039;&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.01.08.ODP[02]}}A.03.01.08.ODP&amp;amp;#91;02&amp;amp;#93;: &#039;&#039;&#039;&amp;lt;nowiki/&amp;gt;&#039;&#039;&#039;&#039;&#039;the time period to which the number of consecutive invalid logon attempts by a user is limited is defined&#039;&#039;&#039;&#039;&#039;&amp;lt;nowiki/&amp;gt;&#039;&#039;&#039;.&#039;&#039;&#039;&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.01.08.ODP[03]}}A.03.01.08.ODP&amp;amp;#91;03&amp;amp;#93;: &#039;&#039;&#039;&amp;lt;nowiki/&amp;gt;&#039;&#039;&#039;&#039;&#039;one or more of the following PARAMETER VALUES are selected: &amp;amp;#123;the account or node is locked automatically for &amp;lt;A.03.01.08.ODP&amp;amp;#91;04&amp;amp;#93;: time period&amp;gt;; the account or node is locked automatically until released by an administrator; the next logon prompt is delayed automatically; the system administrator is notified automatically; other action is taken automatically&amp;amp;#125;.&#039;&#039;&#039;&#039;&#039;&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.01.08.ODP[04]}}A.03.01.08.ODP&amp;amp;#91;04&amp;amp;#93;: &#039;&#039;&#039;&amp;lt;nowiki/&amp;gt;&#039;&#039;&#039;&#039;&#039;the time period for an account or node to be locked is defined (if selected)&#039;&#039;&#039;&#039;&#039;&amp;lt;nowiki/&amp;gt;&#039;&#039;&#039;.&#039;&#039;&#039;&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.01.08.a}}A.03.01.08.a:&#039;&#039;&#039; a limit of &#039;&#039;&#039;&#039;&#039;&amp;lt;A.03.01.08.ODP&amp;amp;#91;01&amp;amp;#93;: number&amp;gt;&#039;&#039;&#039;&#039;&#039; consecutive invalid logon attempts by a user during &#039;&#039;&#039;&#039;&#039;&amp;lt;A.03.01.08.ODP&amp;amp;#91;02&amp;amp;#93;: time period&amp;gt;&#039;&#039;&#039;&#039;&#039; is enforced.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.01.08.b}}A.03.01.08.b: &#039;&#039;&#039;&amp;lt;nowiki/&amp;gt;&#039;&#039;&#039;&#039;&#039;&amp;lt;A.03.01.08.ODP&amp;amp;#91;03&amp;amp;#93;: SELECTED PARAMETER VALUES&amp;gt;&#039;&#039;&#039;&#039;&#039; when the maximum number of unsuccessful attempts is exceeded.&lt;br /&gt;
&lt;br /&gt;
==== ASSESSMENT METHODS AND OBJECTS ====&lt;br /&gt;
&lt;br /&gt;
===== Examine =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: access control policy and procedures; procedures for unsuccessful logon attempts; system design documentation; system audit records; system configuration settings; system security plan; other relevant documents or records&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
===== Interview =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: personnel with information security responsibilities; system developers; system administrators&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
===== Test =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: mechanisms for implementing the access control policy for unsuccessful logon attempts&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
==== REFERENCES ====&lt;br /&gt;
&lt;br /&gt;
Source Assessment Procedure: [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_A_5_1_1/home?element=AC-07 AC-07]&lt;br /&gt;
&lt;br /&gt;
{{anchor|d30e1289-Head3}}{{anchor|sec-sec_03.01.09}}=== 03.01.09 System Use Notification ===&lt;br /&gt;
&lt;br /&gt;
==== ASSESSMENT OBJECTIVE ====&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Determine if:&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;A.03.01.09:&#039;&#039;&#039; a system use notification message with privacy and security notices consistent with applicable CUI rules is displayed before granting access to the system.&lt;br /&gt;
&lt;br /&gt;
==== ASSESSMENT METHODS AND OBJECTS ====&lt;br /&gt;
&lt;br /&gt;
===== Examine =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: access control policy and procedures; privacy and security policies, procedures for system use notification; documented approval of system use notification messages; system audit records; user acknowledgements of system use notification messages; system design documentation; system configuration settings; system use notification messages; system security plan; other relevant documents or records&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
===== Interview =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: personnel with information security responsibilities; legal counsel; system developers; system administrators&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
===== Test =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: mechanisms for implementing system use notifications&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
==== REFERENCES ====&lt;br /&gt;
&lt;br /&gt;
Source Assessment Procedure: [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_A_5_1_1/home?element=AC-08 AC-08]&lt;br /&gt;
&lt;br /&gt;
{{anchor|d30e1325-Head3}}{{anchor|sec-sec_03.01.10}}=== 03.01.10 Device Lock ===&lt;br /&gt;
&lt;br /&gt;
==== ASSESSMENT OBJECTIVE ====&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Determine if:&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.01.10.ODP[01]}}A.03.01.10.ODP&amp;amp;#91;01&amp;amp;#93;: &#039;&#039;&#039;&amp;lt;nowiki/&amp;gt;&#039;&#039;&#039;&#039;&#039;one or more of the following PARAMETER VALUES are selected: &amp;amp;#123;a device lock is initiated after &amp;lt;A.03.01.10.ODP&amp;amp;#91;02&amp;amp;#93;: time period&amp;gt; of inactivity; the user is required to initiate a device lock before leaving the system unattended&amp;amp;#125;&#039;&#039;&#039;&#039;&#039;&amp;lt;nowiki/&amp;gt;&#039;&#039;&#039;.&#039;&#039;&#039;&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.01.10.ODP[02]}}A.03.01.10.ODP&amp;amp;#91;02&amp;amp;#93;: &#039;&#039;&#039;&amp;lt;nowiki/&amp;gt;&#039;&#039;&#039;&#039;&#039;the time period of inactivity after which a device lock is initiated is defined (if selected)&#039;&#039;&#039;&#039;&#039;&amp;lt;nowiki/&amp;gt;&#039;&#039;&#039;.&#039;&#039;&#039;&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.01.10.a}}A.03.01.10.a:&#039;&#039;&#039; access to the system is prevented by &#039;&#039;&#039;&#039;&#039;&amp;lt;A.03.01.10.ODP&amp;amp;#91;01&amp;amp;#93;: SELECTED PARAMETER VALUES&amp;gt;&#039;&#039;&#039;&#039;&#039;.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.01.10.b}}A.03.01.10.b:&#039;&#039;&#039; the device lock is retained until the user reestablishes access using established identification and authentication procedures.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.01.10.c}}A.03.01.10.c:&#039;&#039;&#039; information previously visible on the display is concealed via device lock with a publicly viewable image.&lt;br /&gt;
&lt;br /&gt;
==== ASSESSMENT METHODS AND OBJECTS ====&lt;br /&gt;
&lt;br /&gt;
===== Examine =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: access control policy and procedures; procedures for session lock and identification and authentication; system design documentation; system configuration settings; display screen with session lock activated; system security plan; other relevant documents or records&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
===== Interview =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: personnel with information security responsibilities; system developers; system administrators&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
===== Test =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: mechanisms for implementing the access control policy for session lock; session lock mechanisms&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
==== REFERENCES ====&lt;br /&gt;
&lt;br /&gt;
Source Assessment Procedures: [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_A_5_1_1/home?element=AC-11 AC-11], [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_A_5_1_1/home?element=AC-11 AC-11(01)]&lt;br /&gt;
&lt;br /&gt;
{{anchor|d30e1397-Head3}}{{anchor|sec-sec_03.01.11}}=== 03.01.11 Session Termination ===&lt;br /&gt;
&lt;br /&gt;
==== ASSESSMENT OBJECTIVE ====&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Determine if:&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.01.11.ODP[01]}}A.03.01.11.ODP&amp;amp;#91;01&amp;amp;#93;: &#039;&#039;&#039;&amp;lt;nowiki/&amp;gt;&#039;&#039;&#039;&#039;&#039;conditions or trigger events that require session disconnect are defined&#039;&#039;&#039;&#039;&#039;&amp;lt;nowiki/&amp;gt;&#039;&#039;&#039;.&#039;&#039;&#039;&lt;br /&gt;
* &#039;&#039;&#039;A.03.01.11:&#039;&#039;&#039; a user session is terminated automatically after &#039;&#039;&#039;&#039;&#039;&amp;lt;A.03.01.11.ODP&amp;amp;#91;01&amp;amp;#93;: conditions or trigger events&amp;gt;&#039;&#039;&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
==== ASSESSMENT METHODS AND OBJECTS ====&lt;br /&gt;
&lt;br /&gt;
===== Examine =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: access control policy and procedures; procedures for session termination; system design documentation; system configuration settings; list of conditions or trigger events requiring session disconnect; system audit records; system security plan; other relevant documents or records&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
===== Interview =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: personnel with information security responsibilities; system developers; system administrators&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
===== Test =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: automated mechanisms for implementing user session termination&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
==== REFERENCES ====&lt;br /&gt;
&lt;br /&gt;
Source Assessment Procedure: [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_A_5_1_1/home?element=AC-12 AC-12]&lt;br /&gt;
&lt;br /&gt;
{{anchor|d30e1446-Head3}}{{anchor|sec-sec_03.01.12}}=== 03.01.12 Remote Access ===&lt;br /&gt;
&lt;br /&gt;
==== ASSESSMENT OBJECTIVE ====&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Determine if:&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.01.12.a[01]}}A.03.01.12.a&amp;amp;#91;01&amp;amp;#93;:&#039;&#039;&#039; types of allowable remote system access are defined.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.01.12.a[02]}}A.03.01.12.a&amp;amp;#91;02&amp;amp;#93;:&#039;&#039;&#039; usage restrictions are established for each type of allowable remote system access.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.01.12.a[03]}}A.03.01.12.a&amp;amp;#91;03&amp;amp;#93;:&#039;&#039;&#039; configuration requirements are established for each type of allowable remote system access.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.01.12.a[04]}}A.03.01.12.a&amp;amp;#91;04&amp;amp;#93;:&#039;&#039;&#039; connection requirements are established for each type of allowable remote system access.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.01.12.b}}A.03.01.12.b:&#039;&#039;&#039; each type of remote system access is authorized prior to establishing such connections.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.01.12.c[01]}}A.03.01.12.c&amp;amp;#91;01&amp;amp;#93;:&#039;&#039;&#039; remote access to the system is routed through authorized access control points.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.01.12.c[02]}}A.03.01.12.c&amp;amp;#91;02&amp;amp;#93;:&#039;&#039;&#039; remote access to the system is routed through managed access control points.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.01.12.d[1]}}A.03.01.12.d&amp;amp;#91;1&amp;amp;#93;:&#039;&#039;&#039; remote execution of privileged commands is authorized.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.01.12.d[2]}}A.03.01.12.d&amp;amp;#91;2&amp;amp;#93;:&#039;&#039;&#039; remote access to security-relevant information is authorized.&lt;br /&gt;
&lt;br /&gt;
==== ASSESSMENT METHODS AND OBJECTS ====&lt;br /&gt;
&lt;br /&gt;
===== Examine =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: access control policy and procedures; procedures for remote system access; remote system access configuration and connection requirements; configuration management plan; system configuration settings; remote access authorizations; system audit records; system design documentation; procedures for remote access to the system; system monitoring records; list of managed network access control points; system security plan; other relevant documents or records&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
===== Interview =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: personnel with responsibilities for managing remote access connections; personnel with information security responsibilities; system administrators&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
===== Test =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: mechanisms for monitoring and controlling remote access methods; mechanisms for routing remote accesses through managed access control points; remote access management capability for the system&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
==== REFERENCES ====&lt;br /&gt;
&lt;br /&gt;
Source Assessment Procedures: [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_A_5_1_1/home?element=AC-17 AC-17], [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_A_5_1_1/home?element=AC-17 AC-17(03)], [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_A_5_1_1/home?element=AC-17 AC-17(04)]&lt;br /&gt;
&lt;br /&gt;
{{anchor|d30e1536-Head3}}{{anchor|sec-sec_03.01.13}}=== 03.01.13 Withdrawn ===&lt;br /&gt;
&lt;br /&gt;
Addressed by [[#sec-sec_03.13.08|03.13.08]].&lt;br /&gt;
&lt;br /&gt;
{{anchor|d30e1547-Head3}}{{anchor|sec-sec_03.01.14}}=== 03.01.14 Withdrawn ===&lt;br /&gt;
&lt;br /&gt;
Incorporated into [[#sec-sec_03.01.12|03.01.12]].&lt;br /&gt;
&lt;br /&gt;
{{anchor|d30e1557-Head3}}{{anchor|sec-sec_03.01.15}}=== 03.01.15 Withdrawn ===&lt;br /&gt;
&lt;br /&gt;
Incorporated into [[#sec-sec_03.01.12|03.01.12]].&lt;br /&gt;
&lt;br /&gt;
{{anchor|d30e1567-Head3}}{{anchor|sec-sec_03.01.16}}=== 03.01.16 Wireless Access ===&lt;br /&gt;
&lt;br /&gt;
==== ASSESSMENT OBJECTIVE ====&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Determine if:&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.01.16.a[01]}}A.03.01.16.a&amp;amp;#91;01&amp;amp;#93;:&#039;&#039;&#039; each type of wireless access to the system is defined.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.01.16.a[02]}}A.03.01.16.a&amp;amp;#91;02&amp;amp;#93;:&#039;&#039;&#039; usage restrictions are established for each type of wireless access to the system.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.01.16.a[03]}}A.03.01.16.a&amp;amp;#91;03&amp;amp;#93;:&#039;&#039;&#039; configuration requirements are established for each type of wireless access to the system.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.01.16.a[04]}}A.03.01.16.a&amp;amp;#91;04&amp;amp;#93;:&#039;&#039;&#039; connection requirements are established for each type of wireless access to the system.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.01.16.b}}A.03.01.16.b:&#039;&#039;&#039; each type of wireless access to the system is authorized prior to establishing such connections.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.01.16.c}}A.03.01.16.c:&#039;&#039;&#039; wireless networking capabilities not intended for use are disabled prior to issuance and deployment.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.01.16.d[01]}}A.03.01.16.d&amp;amp;#91;01&amp;amp;#93;:&#039;&#039;&#039; wireless access to the system is protected using authentication.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.01.16.d[02]}}A.03.01.16.d&amp;amp;#91;02&amp;amp;#93;:&#039;&#039;&#039; wireless access to the system is protected using encryption.&lt;br /&gt;
&lt;br /&gt;
==== ASSESSMENT METHODS AND OBJECTS ====&lt;br /&gt;
&lt;br /&gt;
===== Examine =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: access control policy and procedures; procedures for wireless system access; wireless system access configuration and connection requirements; configuration management plan; system configuration settings; wireless access authorizations; system audit records; system design documentation; system security plan; other relevant documents or records&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
===== Interview =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: personnel with responsibilities for managing wireless access connections; personnel with information security responsibilities; system developers; system administrators&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
===== Test =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: wireless access management capability for the system; mechanisms for implementing wireless access protections to the system; mechanisms for managing the disabling of wireless networking capabilities&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
==== REFERENCES ====&lt;br /&gt;
&lt;br /&gt;
Source Assessment Procedures: [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_A_5_1_1/home?element=AC-18 AC-18], [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=AC-18 AC-18(01)], [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_A_5_1_1/home?element=AC-18 AC-18(03)]&lt;br /&gt;
&lt;br /&gt;
{{anchor|d30e1653-Head3}}{{anchor|sec-sec_03.01.17}}=== 03.01.17 Withdrawn ===&lt;br /&gt;
&lt;br /&gt;
Incorporated into [[#sec-sec_03.01.16|&amp;lt;u&amp;gt;03.01.16&amp;lt;/u&amp;gt;]].&lt;br /&gt;
&lt;br /&gt;
{{anchor|d30e1664-Head3}}{{anchor|sec-sec_03.01.18}}=== 03.01.18 Access Control for Mobile Devices ===&lt;br /&gt;
&lt;br /&gt;
==== ASSESSMENT OBJECTIVE ====&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Determine if:&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.01.18.a[01]}}A.03.01.18.a&amp;amp;#91;01&amp;amp;#93;:&#039;&#039;&#039; usage restrictions are established for mobile devices.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.01.18.a[02]}}A.03.01.18.a&amp;amp;#91;02&amp;amp;#93;:&#039;&#039;&#039; configuration requirements are established for mobile devices.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.01.18.a[03]}}A.03.01.18.a&amp;amp;#91;03&amp;amp;#93;:&#039;&#039;&#039; connection requirements are established for mobile devices.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.01.18.b}}A.03.01.18.b:&#039;&#039;&#039; the connection of mobile devices to the system is authorized.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.01.18.c}}A.03.01.18.c:&#039;&#039;&#039; full-device or container-based encryption is implemented to protect the confidentiality of CUI on mobile devices.&lt;br /&gt;
&lt;br /&gt;
==== ASSESSMENT METHODS AND OBJECTS ====&lt;br /&gt;
&lt;br /&gt;
===== Examine =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: access control policy and procedures; procedures for mobile device access control; system design documentation; configuration management plan; system configuration settings; authorizations for mobile device connections to organizational systems; system audit records; encryption mechanisms and associated configuration documentation; system security plan; other relevant documents or records&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
===== Interview =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: personnel with access control responsibilities for mobile devices; personnel using mobile devices to access organizational systems; personnel with information security responsibilities; system administrators&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
===== Test =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: access control capability for mobile device connections to organizational systems; encryption mechanisms for protecting the confidentiality of CUI on mobile devices; configurations of mobile devices&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
==== REFERENCES ====&lt;br /&gt;
&lt;br /&gt;
Source Assessment Procedures: [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_A_5_1_1/home?element=AC-19 AC-19], [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_A_5_1_1/home?element=AC-19 AC-19(05)]&lt;br /&gt;
&lt;br /&gt;
{{anchor|d30e1731-Head3}}{{anchor|sec-sec_03.01.19}}=== 03.01.19 Withdrawn ===&lt;br /&gt;
&lt;br /&gt;
Incorporated into [[#sec-sec_03.01.18|03.01.18]].&lt;br /&gt;
&lt;br /&gt;
{{anchor|d30e1741-Head3}}{{anchor|sec-sec_03.01.20}}=== 03.01.20 Use of External Systems ===&lt;br /&gt;
&lt;br /&gt;
==== ASSESSMENT OBJECTIVE ====&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Determine if:&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.01.20.ODP[01]}}A.03.01.20.ODP&amp;amp;#91;01&amp;amp;#93;: &#039;&#039;&#039;&amp;lt;nowiki/&amp;gt;&#039;&#039;&#039;&#039;&#039;security requirements to be satisfied on external systems prior to allowing the use of or access to those systems by authorized individuals are defined&#039;&#039;&#039;&#039;&#039;&amp;lt;nowiki/&amp;gt;&#039;&#039;&#039;.&#039;&#039;&#039;&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.01.20.a}}A.03.01.20.a: the&#039;&#039;&#039; use of external systems is prohibited unless the systems are specifically authorized.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.01.20.b}}A.03.01.20.b:&#039;&#039;&#039; the following security requirements to be satisfied on external systems prior to allowing the use of or access to those systems by authorized individuals are established: &#039;&#039;&#039;&#039;&#039;&amp;lt;A.03.01.20.ODP&amp;amp;#91;01&amp;amp;#93;: security requirements&amp;gt;&#039;&#039;&#039;&#039;&#039;.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.01.20.c.01}}A.03.01.20.c.01:&#039;&#039;&#039; authorized individuals are permitted to use external systems to access the organizational system or to process, store, or transmit CUI only after verifying that the security requirements on the external systems as specified in the organization’s system security plans have been satisfied.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.01.20.c.02}}A.03.01.20.c.02:&#039;&#039;&#039; authorized individuals are permitted to use external systems to access the organizational system or to process, store, or transmit CUI only after retaining approved system connection or processing agreements with the organizational entity hosting the external systems.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.01.20.d}}A.03.01.20.d:&#039;&#039;&#039; the use of organization-controlled portable storage devices by authorized individuals on external systems is restricted.&lt;br /&gt;
&lt;br /&gt;
==== ASSESSMENT METHODS AND OBJECTS ====&lt;br /&gt;
&lt;br /&gt;
===== Examine =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: access control policy and procedures; procedures for the use of external systems; terms and conditions for the use of external systems; external systems security requirements; list of types of applications accessible from external systems; system configuration settings; system security plan; other relevant documents or records&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
===== Interview =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: personnel with responsibilities for defining terms, conditions, and security requirements for the use of external systems; personnel with information security responsibilities; system administrators&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
===== Test =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: mechanisms for implementing or enforcing terms, conditions, and security requirements for the use of external systems&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
==== REFERENCES ====&lt;br /&gt;
&lt;br /&gt;
Source Assessment Procedures: [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_A_5_1_1/home?element=AC-20 AC-20], [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_A_5_1_1/home?element=AC-20 AC-20(01)], [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_A_5_1_1/home?element=AC-20 AC-20(02)]&lt;br /&gt;
&lt;br /&gt;
{{anchor|d30e1823-Head3}}{{anchor|sec-sec_03.01.21}}=== 03.01.21 Withdrawn ===&lt;br /&gt;
&lt;br /&gt;
Incorporated into [[#sec-sec_03.01.20|03.01.20]].&lt;br /&gt;
&lt;br /&gt;
{{anchor|d30e1834-Head3}}{{anchor|sec-sec_03.01.22}}=== 03.01.22 Publicly Accessible Content ===&lt;br /&gt;
&lt;br /&gt;
==== ASSESSMENT OBJECTIVE ====&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Determine if:&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.01.22.a}}A.03.01.22.a:&#039;&#039;&#039; authorized individuals are trained to ensure that publicly accessible information does not contain CUI.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.01.22.b[01]}}A.03.01.22.b&amp;amp;#91;01&amp;amp;#93;:&#039;&#039;&#039; the content on publicly accessible systems is reviewed for CUI.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.01.22.b[02]}}A.03.01.22.b&amp;amp;#91;02&amp;amp;#93;:&#039;&#039;&#039; CUI is removed from publicly accessible systems, if discovered.&lt;br /&gt;
&lt;br /&gt;
==== ASSESSMENT METHODS AND OBJECTS ====&lt;br /&gt;
&lt;br /&gt;
===== Examine =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: access control policy and procedures; procedures for publicly accessible content; list of users authorized to post publicly accessible content on organizational systems; training materials or records; records of publicly accessible information reviews; records of response to CUI discovered on public websites; system audit logs; security awareness training records; system security plan; other relevant documents or records&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
===== Interview =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: personnel with responsibilities for managing publicly accessible information posted on organizational systems; personnel with information security responsibilities&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
===== Test =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: mechanisms for implementing the management of publicly accessible content&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
==== REFERENCES ====&lt;br /&gt;
&lt;br /&gt;
Source Assessment Procedure: [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_A_5_1_1/home?element=AC-22 AC-22]&lt;br /&gt;
&lt;br /&gt;
{{anchor|d30e1886-Head2}}{{anchor|sec-sec_3.2}}== 3.2 [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=AT Awareness and Training] ==&lt;br /&gt;
&lt;br /&gt;
{{anchor|d30e1891-Head3}}{{anchor|sec-sec_03.02.01}}=== 03.02.01 Literacy Training and Awareness ===&lt;br /&gt;
&lt;br /&gt;
==== ASSESSMENT OBJECTIVE ====&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Determine if:&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.02.01.ODP[01]}}A.03.02.01.ODP&amp;amp;#91;01&amp;amp;#93;: &#039;&#039;&#039;&amp;lt;nowiki/&amp;gt;&#039;&#039;&#039;&#039;&#039;the frequency at which to provide security literacy training to system users after initial training is defined&#039;&#039;&#039;&#039;&#039;&amp;lt;nowiki/&amp;gt;&#039;&#039;&#039;.&#039;&#039;&#039;&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.02.01.ODP[02]}}A.03.02.01.ODP&amp;amp;#91;02&amp;amp;#93;: &#039;&#039;&#039;&amp;lt;nowiki/&amp;gt;&#039;&#039;&#039;&#039;&#039;events that require security literacy training for system users are defined.&#039;&#039;&#039;&#039;&#039;&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.02.01.ODP[03]}}A.03.02.01.ODP&amp;amp;#91;03&amp;amp;#93;: &#039;&#039;&#039;&amp;lt;nowiki/&amp;gt;&#039;&#039;&#039;&#039;&#039;the frequency at which to update security literacy training content is defined.&#039;&#039;&#039;&#039;&#039;&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.02.01.ODP[04]}}A.03.02.01.ODP&amp;amp;#91;04&amp;amp;#93;: &#039;&#039;&#039;&amp;lt;nowiki/&amp;gt;&#039;&#039;&#039;&#039;&#039;events that require security literacy training content updates are defined.&#039;&#039;&#039;&#039;&#039;&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.02.01.a.01[01]}}A.03.02.01.a.01&amp;amp;#91;01&amp;amp;#93;:&#039;&#039;&#039; security literacy training is provided to system users as part of initial training for new users.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.02.01.a.01[02]}}A.03.02.01.a.01&amp;amp;#91;02&amp;amp;#93;:&#039;&#039;&#039; security literacy training is provided to system users &#039;&#039;&#039;&#039;&#039;&amp;lt;A.03.02.01.ODP&amp;amp;#91;01&amp;amp;#93;: frequency&amp;gt;&#039;&#039;&#039;&#039;&#039; after initial training.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.02.01.a.02}}A.03.02.01.a.02:&#039;&#039;&#039; security literacy training is provided to system users when required by system changes or following &#039;&#039;&#039;&#039;&#039;&amp;lt;A.03.02.01.ODP&amp;amp;#91;02&amp;amp;#93;: events&amp;gt;&#039;&#039;&#039;&#039;&#039;.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.02.01.a.03[01]}}A.03.02.01.a.03&amp;amp;#91;01&amp;amp;#93;:&#039;&#039;&#039; security literacy training is provided to system users on recognizing indicators of insider threat.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.02.01.a.03[02]}}A.03.02.01.a.03&amp;amp;#91;02&amp;amp;#93;:&#039;&#039;&#039; security literacy training is provided to system users on reporting indicators of insider threat.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.02.01.a.03[03]}}A.03.02.01.a.03&amp;amp;#91;03&amp;amp;#93;:&#039;&#039;&#039; security literacy training is provided to system users on recognizing indicators of social engineering.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.02.01.a.03[04]}}A.03.02.01.a.03&amp;amp;#91;04&amp;amp;#93;:&#039;&#039;&#039; security literacy training is provided to system users on reporting indicators of social engineering.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.02.01.a.03[05]}}A.03.02.01.a.03&amp;amp;#91;05&amp;amp;#93;:&#039;&#039;&#039; security literacy training is provided to system users on recognizing indicators of social mining.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.02.01.a.03[06]}}A.03.02.01.a.03&amp;amp;#91;06&amp;amp;#93;:&#039;&#039;&#039; security literacy training is provided to system users on reporting indicators of social mining.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.02.01.b[01]}}A.03.02.01.b&amp;amp;#91;01&amp;amp;#93;:&#039;&#039;&#039; security literacy training content is updated &#039;&#039;&#039;&#039;&#039;&amp;lt;A.03.02.01.ODP&amp;amp;#91;03&amp;amp;#93;: frequency&amp;gt;&#039;&#039;&#039;&#039;&#039;.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.02.01.b[02]}}A.03.02.01.b&amp;amp;#91;02&amp;amp;#93;:&#039;&#039;&#039; security literacy training content is updated following &#039;&#039;&#039;&#039;&#039;&amp;lt;A.03.02.01.ODP&amp;amp;#91;04&amp;amp;#93;: events&amp;gt;&#039;&#039;&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
==== ASSESSMENT METHODS AND OBJECTS ====&lt;br /&gt;
&lt;br /&gt;
===== Examine =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: security literacy training and awareness policy and procedures; procedures for security literacy training and awareness implementation; codes of federal regulations; security literacy and awareness training curriculum; security literacy and awareness training materials; training records; system security plan; other relevant documents or records&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
===== Interview =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: personnel with responsibilities for security literacy training and awareness; personnel comprising the general system user community; personnel with information security responsibilities&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
===== Test =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: mechanisms for managing information security literacy training and awareness&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
==== REFERENCES ====&lt;br /&gt;
&lt;br /&gt;
Source Assessment Procedures: [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_A_5_1_1/home?element=AT-02 AT-02], [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_A_5_1_1/home?element=AT-02 AT-02(02)], [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_A_5_1_1/home?element=AT-02 AT-02(03)]&lt;br /&gt;
&lt;br /&gt;
{{anchor|d30e2034-Head3}}{{anchor|sec-sec_03.02.02}}=== 03.02.02 Role-Based Training ===&lt;br /&gt;
&lt;br /&gt;
==== ASSESSMENT OBJECTIVE ====&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Determine if:&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.02.02.ODP[01]}}A.03.02.02.ODP&amp;amp;#91;01&amp;amp;#93;: &#039;&#039;&#039;&amp;lt;nowiki/&amp;gt;&#039;&#039;&#039;&#039;&#039;the frequency at which to provide role-based security training to assigned personnel after initial training is defined&#039;&#039;&#039;&#039;&#039;&amp;lt;nowiki/&amp;gt;&#039;&#039;&#039;.&#039;&#039;&#039;&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.02.02.ODP[02]}}A.03.02.02.ODP&amp;amp;#91;02&amp;amp;#93;: &#039;&#039;&#039;&amp;lt;nowiki/&amp;gt;&#039;&#039;&#039;&#039;&#039;events that require role-based security training are defined&#039;&#039;&#039;&#039;&#039;&amp;lt;nowiki/&amp;gt;&#039;&#039;&#039;.&#039;&#039;&#039;&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.02.02.ODP[03]}}A.03.02.02.ODP&amp;amp;#91;03&amp;amp;#93;: &#039;&#039;&#039;&amp;lt;nowiki/&amp;gt;&#039;&#039;&#039;&#039;&#039;the frequency at which to update role-based security training content is defined&#039;&#039;&#039;&#039;&#039;&amp;lt;nowiki/&amp;gt;&#039;&#039;&#039;.&#039;&#039;&#039;&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.02.02.ODP[04]}}A.03.02.02.ODP&amp;amp;#91;04&amp;amp;#93;: &#039;&#039;&#039;&amp;lt;nowiki/&amp;gt;&#039;&#039;&#039;&#039;&#039;events that require role-based security training content updates are defined&#039;&#039;&#039;&#039;&#039;&amp;lt;nowiki/&amp;gt;&#039;&#039;&#039;.&#039;&#039;&#039;&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.02.02.a.01[01]}}A.03.02.02.a.01&amp;amp;#91;01&amp;amp;#93;:&#039;&#039;&#039; role-based security training is provided to organizational personnel before authorizing access to the system or CUI.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.02.02.a.01[02]}}A.03.02.02.a.01&amp;amp;#91;02&amp;amp;#93;:&#039;&#039;&#039; role-based security training is provided to organizational personnel before performing assigned duties.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.02.02.a.01[03]}}A.03.02.02.a.01&amp;amp;#91;03&amp;amp;#93;:&#039;&#039;&#039; role-based security training is provided to organizational personnel &#039;&#039;&#039;&#039;&#039;&amp;lt;A.03.02.02.ODP&amp;amp;#91;01&amp;amp;#93;: frequency&amp;gt;&#039;&#039;&#039;&#039;&#039; after initial training.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.02.02.a.02}}A.03.02.02.a.02:&#039;&#039;&#039; role-based security training is provided to organizational personnel when required by system changes or following &#039;&#039;&#039;&#039;&#039;&amp;lt;A.03.02.02.ODP&amp;amp;#91;02&amp;amp;#93;: events&amp;gt;&#039;&#039;&#039;&#039;&#039;.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.02.02.b[01]}}A.03.02.02.b&amp;amp;#91;01&amp;amp;#93;:&#039;&#039;&#039; role-based security training content is updated &#039;&#039;&#039;&#039;&#039;&amp;lt;A.03.02.02.ODP&amp;amp;#91;03&amp;amp;#93;: frequency&amp;gt;&#039;&#039;&#039;&#039;&#039;.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.02.02.b[02]}}A.03.02.02.b&amp;amp;#91;02&amp;amp;#93;:&#039;&#039;&#039; role-based security training content is updated following &#039;&#039;&#039;&#039;&#039;&amp;lt;A.03.02.02.ODP&amp;amp;#91;04&amp;amp;#93;: events&amp;gt;&#039;&#039;&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
==== ASSESSMENT METHODS AND OBJECTS ====&lt;br /&gt;
&lt;br /&gt;
===== Examine =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: security awareness and training policy and procedures; procedures for security training implementation; codes of federal regulations; security training curriculum; security training materials; training records; system security plan; other relevant documents or records&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
===== Interview =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: personnel with responsibilities for role-based security training; personnel with assigned system security roles and responsibilities&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
===== Test =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: mechanisms for managing role-based security training and awareness&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
==== REFERENCES ====&lt;br /&gt;
&lt;br /&gt;
Source Assessment Procedure: [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_A_5_1_1/home?element=AT-03 AT-03]&lt;br /&gt;
&lt;br /&gt;
{{anchor|d30e2150-Head3}}{{anchor|sec-sec_03.02.03}}=== 03.02.03 Withdrawn ===&lt;br /&gt;
&lt;br /&gt;
Incorporated into [[#sec-sec_03.02.01|03.02.01]].&lt;br /&gt;
&lt;br /&gt;
{{anchor|d30e2161-Head2}}{{anchor|sec-sec_3.3}}== 3.3 [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=AU Audit and Accountability] ==&lt;br /&gt;
&lt;br /&gt;
{{anchor|d30e2166-Head3}}{{anchor|sec-sec_03.03.01}}=== 03.03.01 Event Logging ===&lt;br /&gt;
&lt;br /&gt;
==== ASSESSMENT OBJECTIVE ====&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Determine if:&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.03.01.ODP[01]}}A.03.03.01.ODP&amp;amp;#91;01&amp;amp;#93;: &#039;&#039;&#039;&amp;lt;nowiki/&amp;gt;&#039;&#039;&#039;&#039;&#039;event types selected for logging within the system are defined&#039;&#039;&#039;&#039;&#039;&amp;lt;nowiki/&amp;gt;&#039;&#039;&#039;.&#039;&#039;&#039;&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.03.01.ODP[02]}}A.03.03.01.ODP&amp;amp;#91;02&amp;amp;#93;: &#039;&#039;&#039;&amp;lt;nowiki/&amp;gt;&#039;&#039;&#039;&#039;&#039;the frequency of event types selected for logging are reviewed and updated.&#039;&#039;&#039;&#039;&#039;&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.03.01.a}}A.03.03.01.a:&#039;&#039;&#039; the following event types are specified for logging within the system: &#039;&#039;&#039;&#039;&#039;&amp;lt;A.03.03.01.ODP&amp;amp;#91;01&amp;amp;#93;: event types&amp;gt;&#039;&#039;&#039;&#039;&#039;.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.03.01.b[01]}}A.03.03.01.b&amp;amp;#91;01&amp;amp;#93;:&#039;&#039;&#039; the event types selected for logging are reviewed &#039;&#039;&#039;&#039;&#039;&amp;lt;A.03.03.01.ODP&amp;amp;#91;02&amp;amp;#93;: frequency&amp;gt;&#039;&#039;&#039;&#039;&#039;.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.03.01.b[02]}}A.03.03.01.b&amp;amp;#91;02&amp;amp;#93;:&#039;&#039;&#039; the event types selected for logging are updated &#039;&#039;&#039;&#039;&#039;&amp;lt;A.03.03.01.ODP&amp;amp;#91;02&amp;amp;#93;: frequency&amp;gt;&#039;&#039;&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
==== ASSESSMENT METHODS AND OBJECTS ====&lt;br /&gt;
&lt;br /&gt;
===== Examine =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: audit and accountability policy and procedures; procedures for auditable events; system design documentation; system configuration settings; system audit records; system auditable events; system security plan; other relevant documents or records&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
===== Interview =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: personnel with audit and accountability responsibilities; personnel with information security responsibilities; system administrators&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
===== Test =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: mechanisms for implementing system auditing&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
==== REFERENCES ====&lt;br /&gt;
&lt;br /&gt;
Source Assessment Procedure: [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_A_5_1_1/home?element=AU-02 AU-02]&lt;br /&gt;
&lt;br /&gt;
{{anchor|d30e2243-Head3}}{{anchor|sec-sec_03.03.02}}=== 03.03.02 Audit Record Content ===&lt;br /&gt;
&lt;br /&gt;
==== ASSESSMENT OBJECTIVE ====&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Determine if:&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.03.02.a.01}}A.03.03.02.a.01:&#039;&#039;&#039; audit records contain information that establishes what type of event occurred.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.03.02.a.02}}A.03.03.02.a.02:&#039;&#039;&#039; audit records contain information that establishes when the event occurred.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.03.02.a.03}}A.03.03.02.a.03:&#039;&#039;&#039; audit records contain information that establishes where the event occurred.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.03.02.a.04}}A.03.03.02.a.04:&#039;&#039;&#039; audit records contain information that establishes the source of the event.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.03.02.a.05}}A.03.03.02.a.05:&#039;&#039;&#039; audit records contain information that establishes the outcome of the event.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.03.02.a.06}}A.03.03.02.a.06:&#039;&#039;&#039; audit records contain information that establishes the identity of the individuals, subjects, objects, or entities associated with the event.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.03.02.b}}A.03.03.02.b:&#039;&#039;&#039; additional information for audit records is provided, as needed.&lt;br /&gt;
&lt;br /&gt;
==== ASSESSMENT METHODS AND OBJECTS ====&lt;br /&gt;
&lt;br /&gt;
===== Examine =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: audit and accountability policy and procedures; procedures for the content of audit records; list of organization-defined auditable events; system design documentation; system configuration settings; system audit records; system incident reports; system security plan; other relevant documents or records&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
===== Interview =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: personnel with audit and accountability responsibilities; personnel with information security responsibilities; system developers; system administrators&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
===== Test =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: mechanisms for implementing system auditing of auditable events; system audit capability&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
==== REFERENCES ====&lt;br /&gt;
&lt;br /&gt;
Source Assessment Procedures: [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_A_5_1_1/home?element=AU-03 AU-03], [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_A_5_1_1/home?element=AU-03 AU-03(01)]&lt;br /&gt;
&lt;br /&gt;
{{anchor|d30e2320-Head3}}{{anchor|sec-sec_03.03.03}}=== 03.03.03 Audit Record Generation ===&lt;br /&gt;
&lt;br /&gt;
==== ASSESSMENT OBJECTIVE ====&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Determine if:&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.03.03.a}}A.03.03.03.a:&#039;&#039;&#039; audit records for the selected event types and audit record content specified in [[#sec-sec_03.03.01|03.03.01]] and [[#sec-sec_03.03.02|03.03.02]] are generated.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.03.03.b}}A.03.03.03.b:&#039;&#039;&#039; audit records are retained for a time period consistent with the records retention policy.&lt;br /&gt;
&lt;br /&gt;
==== ASSESSMENT METHODS AND OBJECTS ====&lt;br /&gt;
&lt;br /&gt;
===== Examine =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: audit and accountability policy and procedures; procedures for audit record generation; system design documentation; list of auditable events; system audit records; audit record retention policy and procedures; organization-defined retention period for audit records; audit record archives; system configuration settings; system security plan; other relevant documents or records&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
===== Interview =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: personnel with audit record generation responsibilities; personnel with audit record retention responsibilities; personnel with information security responsibilities; system developers; system administrators&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
===== Test =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: mechanisms for implementing the audit record generation capability&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
==== REFERENCES ====&lt;br /&gt;
&lt;br /&gt;
Source Assessment Procedures: [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_A_5_1_1/home?element=AU-11 AU-11], [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_A_5_1_1/home?element=AU-12 AU-12]&lt;br /&gt;
&lt;br /&gt;
{{anchor|d30e2377-Head3}}{{anchor|sec-sec_03.03.04}}=== 03.03.04 Response to Audit Logging Process Failures ===&lt;br /&gt;
&lt;br /&gt;
==== ASSESSMENT OBJECTIVE ====&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Determine if:&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.03.04.ODP[01]}}A.03.03.04.ODP&amp;amp;#91;01&amp;amp;#93;: &#039;&#039;&#039;&amp;lt;nowiki/&amp;gt;&#039;&#039;&#039;&#039;&#039;the time period for organizational personnel or roles receiving audit logging process failure alerts is defined&#039;&#039;&#039;&#039;&#039;&amp;lt;nowiki/&amp;gt;&#039;&#039;&#039;.&#039;&#039;&#039;&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.03.04.ODP[02]}}A.03.03.04.ODP&amp;amp;#91;02&amp;amp;#93;: &#039;&#039;&#039;&amp;lt;nowiki/&amp;gt;&#039;&#039;&#039;&#039;&#039;additional actions to be taken in the event of an audit logging process failure are defined&#039;&#039;&#039;&#039;&#039;&amp;lt;nowiki/&amp;gt;&#039;&#039;&#039;.&#039;&#039;&#039;&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.03.04.a}}A.03.03.04.a:&#039;&#039;&#039; organizational personnel or roles are alerted in the event of an audit logging process failure within &#039;&#039;&#039;&#039;&#039;&amp;lt;A.03.03.04.ODP&amp;amp;#91;01&amp;amp;#93;: time period&amp;gt;&#039;&#039;&#039;&#039;&#039;.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.03.04.b}}A.03.03.04.b:&#039;&#039;&#039; the following additional actions are taken: &#039;&#039;&#039;&#039;&#039;&amp;lt;A.03.03.04.ODP&amp;amp;#91;02&amp;amp;#93;: additional actions&amp;gt;&#039;&#039;&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
==== ASSESSMENT METHODS AND OBJECTS ====&lt;br /&gt;
&lt;br /&gt;
===== Examine =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: audit and accountability policy and procedures; procedures for responding to audit processing failures; system design documentation; system configuration settings; list of personnel to be notified in case of an audit processing failure; system audit records; system security plan; other relevant documents or records&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
===== Interview =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: personnel with audit and accountability responsibilities; personnel with information security responsibilities; system developers; system administrators&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
===== Test =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: mechanisms for implementing system response to audit processing failures&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
==== REFERENCES ====&lt;br /&gt;
&lt;br /&gt;
Source Assessment Procedure: [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_A_5_1_1/home?element=AU-05 AU-05]&lt;br /&gt;
&lt;br /&gt;
{{anchor|d30e2449-Head3}}{{anchor|sec-sec_03.03.05}}=== 03.03.05 Audit Record Review, Analysis, and Reporting ===&lt;br /&gt;
&lt;br /&gt;
==== ASSESSMENT OBJECTIVE ====&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Determine if:&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.03.05.ODP[01]}}A.03.03.05.ODP&amp;amp;#91;01&amp;amp;#93;: &#039;&#039;&#039;&amp;lt;nowiki/&amp;gt;&#039;&#039;&#039;&#039;&#039;the frequency at which system audit records are reviewed and analyzed is defined&#039;&#039;&#039;&#039;&#039;&amp;lt;nowiki/&amp;gt;&#039;&#039;&#039;.&#039;&#039;&#039;&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.03.05.a}}A.03.03.05.a:&#039;&#039;&#039; system audit records are reviewed and analyzed &#039;&#039;&#039;&#039;&#039;&amp;lt;A.03.03.05.ODP&amp;amp;#91;01&amp;amp;#93;: frequency&amp;gt;&#039;&#039;&#039;&#039;&#039; for indications and the potential impact of inappropriate or unusual activity.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.03.05.b}}A.03.03.05.b:&#039;&#039;&#039; findings are reported to organizational personnel or roles.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.03.05.c[01]}}A.03.03.05.c&amp;amp;#91;01&amp;amp;#93;:&#039;&#039;&#039; audit records across different repositories are analyzed to gain organization-wide situational awareness.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.03.05.c[02]}}A.03.03.05.c&amp;amp;#91;02&amp;amp;#93;:&#039;&#039;&#039; audit records across different repositories are correlated to gain organization-wide situational awareness.&lt;br /&gt;
&lt;br /&gt;
==== ASSESSMENT METHODS AND OBJECTS ====&lt;br /&gt;
&lt;br /&gt;
===== Examine =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: audit and accountability policy and procedures; procedures for audit record review, analysis, and reporting; reports of audit record findings; records of actions taken in response to reviews and analyses of audit records; system design documentation; system audit records across different repositories; system security plan; system configuration settings; other relevant documents or records&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
===== Interview =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: personnel with audit record review, analysis, and reporting responsibilities; personnel with information security responsibilities&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
===== Test =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: mechanisms for supporting the analysis and correlation of audit records&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
==== REFERENCES ====&lt;br /&gt;
&lt;br /&gt;
Source Assessment Procedures: [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_A_5_1_1/home?element=AU-06 AU-06], [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_A_5_1_1/home?element=AU-06 AU-06(03)]&lt;br /&gt;
&lt;br /&gt;
{{anchor|d30e2522-Head3}}{{anchor|sec-sec_03.03.06}}=== 03.03.06 Audit Record Reduction and Report Generation ===&lt;br /&gt;
&lt;br /&gt;
==== ASSESSMENT OBJECTIVE ====&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Determine if:&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.03.06.a[01]}}A.03.03.06.a&amp;amp;#91;01&amp;amp;#93;:&#039;&#039;&#039; an audit record reduction and report generation capability that supports audit record review is implemented.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.03.06.a[02]}}A.03.03.06.a&amp;amp;#91;02&amp;amp;#93;:&#039;&#039;&#039; an audit record reduction and report generation capability that supports audit record analysis is implemented.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.03.06.a[03]}}A.03.03.06.a&amp;amp;#91;03&amp;amp;#93;:&#039;&#039;&#039; an audit record reduction and report generation capability that supports audit record reporting requirements is implemented.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.03.06.a[04]}}A.03.03.06.a&amp;amp;#91;04&amp;amp;#93;:&#039;&#039;&#039; an audit record reduction and report generation capability that supports after-the-fact investigations of incidents is implemented.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.03.06.b[01]}}A.03.03.06.b&amp;amp;#91;01&amp;amp;#93;:&#039;&#039;&#039; the original content of audit records is preserved.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.03.06.b[02]}}A.03.03.06.b&amp;amp;#91;02&amp;amp;#93;:&#039;&#039;&#039; the original time ordering of audit records is preserved.&lt;br /&gt;
&lt;br /&gt;
==== ASSESSMENT METHODS AND OBJECTS ====&lt;br /&gt;
&lt;br /&gt;
===== Examine =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: audit and accountability policy and procedures; procedures for audit record reduction and report generation; audit record reduction, review, analysis, and reporting tools; system audit records; system design documentation; system configuration settings; system security plan; other relevant documents or records&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
===== Interview =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: personnel with audit record reduction and report generation responsibilities; personnel with information security responsibilities&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
===== Test =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: mechanisms for supporting audit record reduction and report generation capability&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
==== REFERENCES ====&lt;br /&gt;
&lt;br /&gt;
Source Assessment Procedure: [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_A_5_1_1/home?element=AU-07 AU-07]&lt;br /&gt;
&lt;br /&gt;
{{anchor|d30e2590-Head3}}{{anchor|sec-sec_03.03.07}}=== 03.03.07 Time Stamps ===&lt;br /&gt;
&lt;br /&gt;
==== ASSESSMENT OBJECTIVE ====&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Determine if:&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.03.07.ODP[01]}}A.03.03.07.ODP&amp;amp;#91;01&amp;amp;#93;: &#039;&#039;&#039;&amp;lt;nowiki/&amp;gt;&#039;&#039;&#039;&#039;&#039;granularity of time measurement for audit record time stamps is defined&#039;&#039;&#039;&#039;&#039;&amp;lt;nowiki/&amp;gt;&#039;&#039;&#039;.&#039;&#039;&#039;&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.03.07.a}}A.03.03.07.a:&#039;&#039;&#039; internal system clocks are used to generate time stamps for audit records.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.03.07.b[01]}}A.03.03.07.b&amp;amp;#91;01&amp;amp;#93;:&#039;&#039;&#039; time stamps are recorded for audit records that meet &#039;&#039;&#039;&#039;&#039;&amp;lt;A.03.03.07.ODP&amp;amp;#91;01&amp;amp;#93;: granularity of time measurement&amp;gt;&#039;&#039;&#039;&#039;&#039;.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.03.07.b[02]}}A.03.03.07.b&amp;amp;#91;02&amp;amp;#93;:&#039;&#039;&#039; time stamps are recorded for audit records that use Coordinated Universal Time (UTC), have a fixed local time offset from UTC, or include the local time offset as part of the time stamp.&lt;br /&gt;
&lt;br /&gt;
==== ASSESSMENT METHODS AND OBJECTS ====&lt;br /&gt;
&lt;br /&gt;
===== Examine =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: audit and accountability policy and procedures; procedures for timestamp generation; system design documentation; system configuration settings; system audit records; system security plan; other relevant documents or records&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
===== Interview =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: personnel with information security responsibilities; system developers; system administrators&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
===== Test =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: mechanisms for implementing timestamp generation&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
==== REFERENCES ====&lt;br /&gt;
&lt;br /&gt;
Source Assessment Procedure: [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_A_5_1_1/home?element=AU-08 AU-08]&lt;br /&gt;
&lt;br /&gt;
{{anchor|d30e2654-Head3}}{{anchor|sec-sec_03.03.08}}=== 03.03.08 Protection of Audit Information ===&lt;br /&gt;
&lt;br /&gt;
==== ASSESSMENT OBJECTIVE ====&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Determine if:&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.03.08.a[01]}}A.03.03.08.a&amp;amp;#91;01&amp;amp;#93;:&#039;&#039;&#039; audit information is protected from unauthorized access, modification, and deletion.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.03.08.a[02]}}A.03.03.08.a&amp;amp;#91;02&amp;amp;#93;:&#039;&#039;&#039; audit logging tools are protected from unauthorized access, modification, and deletion.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.03.08.b}}A.03.03.08.b:&#039;&#039;&#039; access to management of audit logging functionality is authorized to only a subset of privileged users or roles.&lt;br /&gt;
&lt;br /&gt;
==== ASSESSMENT METHODS AND OBJECTS ====&lt;br /&gt;
&lt;br /&gt;
===== Examine =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: audit and accountability policy and procedures; access control policy and procedures; procedures for the protection of audit information; system configuration settings; system audit records; audit tools; system-generated list of privileged users with access to the management of audit functionality; access authorizations; access control list; system design documentation; system security plan; other relevant documents or records&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
===== Interview =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: personnel with audit and accountability responsibilities; personnel with information security responsibilities; system developers; system administrators&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
===== Test =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: mechanisms for implementing audit information protection; mechanisms for managing access to audit functionality&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
==== REFERENCES ====&lt;br /&gt;
&lt;br /&gt;
Source Assessment Procedures: [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_A_5_1_1/home?element=AU-09 AU-09], [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_A_5_1_1/home?element=AU-09 AU-09(04)]&lt;br /&gt;
&lt;br /&gt;
{{anchor|d30e2711-Head3}}{{anchor|sec-sec_03.03.09}}=== 03.03.09 Withdrawn ===&lt;br /&gt;
&lt;br /&gt;
Incorporated into [[#sec-sec_03.03.08|03.03.08]].&lt;br /&gt;
&lt;br /&gt;
{{anchor|d30e2721-Head2}}{{anchor|sec-sec_3.4}}== 3.4 [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=CM Configuration Management] ==&lt;br /&gt;
&lt;br /&gt;
{{anchor|d30e2726-Head3}}{{anchor|sec-sec_03.04.01}}=== 03.04.01 Baseline Configuration ===&lt;br /&gt;
&lt;br /&gt;
==== ASSESSMENT OBJECTIVE ====&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Determine if:&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.04.01.ODP[01]}}A.03.04.01.ODP&amp;amp;#91;01&amp;amp;#93;: &#039;&#039;&#039;&amp;lt;nowiki/&amp;gt;&#039;&#039;&#039;&#039;&#039;the frequency of baseline configuration review and update is defined&#039;&#039;&#039;&#039;&#039;&amp;lt;nowiki/&amp;gt;&#039;&#039;&#039;.&#039;&#039;&#039;&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.04.01.a[01]}}A.03.04.01.a&amp;amp;#91;01&amp;amp;#93;:&#039;&#039;&#039; a current baseline configuration of the system is developed.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.04.01.a[02]}}A.03.04.01.a&amp;amp;#91;02&amp;amp;#93;:&#039;&#039;&#039; a current baseline configuration of the system is maintained under configuration control.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.04.01.b[01]}}A.03.04.01.b&amp;amp;#91;01&amp;amp;#93;:&#039;&#039;&#039; the baseline configuration of the system is reviewed &#039;&#039;&#039;&#039;&#039;&amp;lt;A.03.04.01.ODP&amp;amp;#91;01&amp;amp;#93;: frequency&amp;gt;&#039;&#039;&#039;&#039;&#039;.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.04.01.b[02]}}A.03.04.01.b&amp;amp;#91;02&amp;amp;#93;:&#039;&#039;&#039; the baseline configuration of the system is updated &#039;&#039;&#039;&#039;&#039;&amp;lt;A.03.04.01.ODP&amp;amp;#91;01&amp;amp;#93;: frequency&amp;gt;&#039;&#039;&#039;&#039;&#039;.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.04.01.b[03]}}A.03.04.01.b&amp;amp;#91;03&amp;amp;#93;:&#039;&#039;&#039; the baseline configuration of the system is reviewed when system components are installed or modified.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.04.01.b[04]}}A.03.04.01.b&amp;amp;#91;04&amp;amp;#93;:&#039;&#039;&#039; the baseline configuration of the system is updated when system components are installed or modified.&lt;br /&gt;
&lt;br /&gt;
==== ASSESSMENT METHODS AND OBJECTS ====&lt;br /&gt;
&lt;br /&gt;
===== Examine =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: configuration management policy and procedures; procedures for the baseline system configuration; configuration management plan; enterprise architecture; system design documentation; system architecture; system configuration settings; system component inventory; change control records; system security plan; other relevant documents or records&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
===== Interview =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: personnel with configuration management responsibilities; personnel with information security responsibilities; system administrators&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
===== Test =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: processes for managing baseline configurations; mechanisms for supporting configuration control of the baseline configuration&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
==== REFERENCES ====&lt;br /&gt;
&lt;br /&gt;
Source Assessment Procedure: [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_A_5_1_1/home?element=CM-02 CM-02]&lt;br /&gt;
&lt;br /&gt;
{{anchor|d30e2809-Head3}}{{anchor|sec-sec_03.04.02}}=== 03.04.02 Configuration Settings ===&lt;br /&gt;
&lt;br /&gt;
==== ASSESSMENT OBJECTIVE ====&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Determine if:&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.04.02.ODP[01]}}A.03.04.02.ODP&amp;amp;#91;01&amp;amp;#93;: &#039;&#039;&#039;&amp;lt;nowiki/&amp;gt;&#039;&#039;&#039;&#039;&#039;configuration settings for the system that reflect the most restrictive mode consistent with operational requirements are defined&#039;&#039;&#039;&#039;&#039;&amp;lt;nowiki/&amp;gt;&#039;&#039;&#039;.&#039;&#039;&#039;&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.04.02.a[01]}}A.03.04.02.a&amp;amp;#91;01&amp;amp;#93;:&#039;&#039;&#039; the following configuration settings for the system that reflect the most restrictive mode consistent with operational requirements are established and documented: &#039;&#039;&#039;&#039;&#039;&amp;lt;A.03.04.02.ODP&amp;amp;#91;01&amp;amp;#93;: configuration settings&amp;gt;&#039;&#039;&#039;&#039;&#039;.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.04.02.a[02]}}A.03.04.02.a&amp;amp;#91;02&amp;amp;#93;:&#039;&#039;&#039; the following configuration settings for the system are implemented: &#039;&#039;&#039;&#039;&#039;&amp;lt;A.03.04.02.ODP&amp;amp;#91;01&amp;amp;#93;: configuration settings&amp;gt;&#039;&#039;&#039;&#039;&#039;.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.04.02.b[01]}}A.03.04.02.b&amp;amp;#91;01&amp;amp;#93;:&#039;&#039;&#039; any deviations from established configuration settings are identified and documented.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.04.02.b[02]}}A.03.04.02.b&amp;amp;#91;02&amp;amp;#93;:&#039;&#039;&#039; any deviations from established configuration settings are approved.&lt;br /&gt;
&lt;br /&gt;
==== ASSESSMENT METHODS AND OBJECTS ====&lt;br /&gt;
&lt;br /&gt;
===== Examine =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: configuration management policy and procedures; procedures for system configuration settings; configuration management plan; system design documentation; system configuration settings; common secure configuration checklists; system component inventory; evidence supporting approved deviations from established configuration settings; change control records; system data processing and retention permissions; system audit records; system security plan; other relevant documents or records&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
===== Interview =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: personnel with security configuration management responsibilities; personnel with information security responsibilities; system administrators&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
===== Test =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: processes for managing configuration settings; mechanisms that implement, monitor, or control system configuration settings; mechanisms that identify or document deviations from established configuration settings&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
==== REFERENCES ====&lt;br /&gt;
&lt;br /&gt;
Source Assessment Procedure: [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_A_5_1_1/home?element=CM-06 CM-06]&lt;br /&gt;
&lt;br /&gt;
{{anchor|d30e2881-Head3}}{{anchor|sec-sec_03.04.03}}=== 03.04.03 Configuration Change Control ===&lt;br /&gt;
&lt;br /&gt;
==== ASSESSMENT OBJECTIVE ====&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Determine if:&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.04.03.a}}A.03.04.03.a:&#039;&#039;&#039; the types of changes to the system that are configuration-controlled are defined.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.04.03.b[01]}}A.03.04.03.b&amp;amp;#91;01&amp;amp;#93;:&#039;&#039;&#039; proposed configuration-controlled changes to the system are reviewed with explicit consideration for security impacts.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.04.03.b[02]}}A.03.04.03.b&amp;amp;#91;02&amp;amp;#93;:&#039;&#039;&#039; proposed configuration-controlled changes to the system are approved or disapproved with explicit consideration for security impacts.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.04.03.c[01]}}A.03.04.03.c&amp;amp;#91;01&amp;amp;#93;:&#039;&#039;&#039; approved configuration-controlled changes to the system are implemented.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.04.03.c[02]}}A.03.04.03.c&amp;amp;#91;02&amp;amp;#93;:&#039;&#039;&#039; approved configuration-controlled changes to the system are documented.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.04.03.d[01]}}A.03.04.03.d&amp;amp;#91;01&amp;amp;#93;:&#039;&#039;&#039; activities associated with configuration-controlled changes to the system are monitored.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.04.03.d[02]}}A.03.04.03.d&amp;amp;#91;02&amp;amp;#93;:&#039;&#039;&#039; activities associated with configuration-controlled changes to the system are reviewed.&lt;br /&gt;
&lt;br /&gt;
==== ASSESSMENT METHODS AND OBJECTS ====&lt;br /&gt;
&lt;br /&gt;
===== Examine =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: configuration management policy and procedures; procedures for system configuration change control; configuration management plan; system architecture; configuration settings; change control records; system audit records; change control audit and review reports; agenda, minutes, and documentation from configuration change control oversight meetings; system security plan; other relevant documents or records&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
===== Interview =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: personnel with configuration change control responsibilities; personnel with information security responsibilities; members of change control board or similar; system administrators&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
===== Test =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: processes for configuration change control; mechanisms that implement configuration change control&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
==== REFERENCES ====&lt;br /&gt;
&lt;br /&gt;
Source Assessment Procedure: [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_A_5_1_1/home?element=CM-03 CM-03]&lt;br /&gt;
&lt;br /&gt;
{{anchor|d30e2954-Head3}}{{anchor|sec-sec_03.04.04}}=== 03.04.04 Impact Analyses ===&lt;br /&gt;
&lt;br /&gt;
==== ASSESSMENT OBJECTIVE ====&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Determine if:&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.04.04.a}}A.03.04.04.a:&#039;&#039;&#039; changes to the system are analyzed to determine potential security impacts prior to change implementation.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.04.04.b}}A.03.04.04.b:&#039;&#039;&#039; the security requirements for the system continue to be satisfied after the system changes have been implemented.&lt;br /&gt;
&lt;br /&gt;
==== ASSESSMENT METHODS AND OBJECTS ====&lt;br /&gt;
&lt;br /&gt;
===== Examine =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: configuration management policy and procedures; procedures for security impact analyses for system changes; configuration management plan; security impact analysis documentation; system design documentation; analysis tools and outputs; change control records; system audit records; system security plan; other relevant documents or records&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
===== Interview =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: personnel with security impact analysis responsibilities; personnel with information security responsibilities; members of change control board; system developers; system administrators&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
===== Test =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: processes for security impact analyses&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
==== REFERENCES ====&lt;br /&gt;
&lt;br /&gt;
Source Assessment Procedure: [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=CM-04 CM-04], [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=CM-04 CM-04(02)]&lt;br /&gt;
&lt;br /&gt;
{{anchor|d30e3005-Head3}}{{anchor|sec-sec_03.04.05}}=== 03.04.05 Access Restrictions for Change ===&lt;br /&gt;
&lt;br /&gt;
==== ASSESSMENT OBJECTIVE ====&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Determine if:&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;A.03.04.05&amp;amp;#91;01&amp;amp;#93;:&#039;&#039;&#039; physical access restrictions associated with changes to the system are defined and documented.&lt;br /&gt;
* &#039;&#039;&#039;A.03.04.05&amp;amp;#91;02&amp;amp;#93;:&#039;&#039;&#039; physical access restrictions associated with changes to the system are approved.&lt;br /&gt;
* &#039;&#039;&#039;A.03.04.05&amp;amp;#91;03&amp;amp;#93;:&#039;&#039;&#039; physical access restrictions associated with changes to the system are enforced.&lt;br /&gt;
* &#039;&#039;&#039;A.03.04.05&amp;amp;#91;04&amp;amp;#93;:&#039;&#039;&#039; logical access restrictions associated with changes to the system are defined and documented.&lt;br /&gt;
* &#039;&#039;&#039;A.03.04.05&amp;amp;#91;05&amp;amp;#93;:&#039;&#039;&#039; logical access restrictions associated with changes to the system are approved.&lt;br /&gt;
* &#039;&#039;&#039;A.03.04.05&amp;amp;#91;06&amp;amp;#93;:&#039;&#039;&#039; logical access restrictions associated with changes to the system are enforced.&lt;br /&gt;
&lt;br /&gt;
==== ASSESSMENT METHODS AND OBJECTS ====&lt;br /&gt;
&lt;br /&gt;
===== Examine =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: configuration management policy and procedures; procedures for access restrictions for system changes; configuration management plan; system design documentation; system architecture; system configuration settings; logical access approvals; physical access approvals; access credentials; change control records; system audit records; system security plan; other relevant documents or records&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
===== Interview =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: personnel with logical access control responsibilities; personnel with physical access control responsibilities; personnel with information security responsibilities; system administrators&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
===== Test =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: processes for managing access restrictions for system changes; mechanisms for supporting, implementing, or enforcing access restrictions associated with system changes&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
==== REFERENCES ====&lt;br /&gt;
&lt;br /&gt;
Source Assessment Procedure: [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_A_5_1_1/home?element=CM-05 CM-05]&lt;br /&gt;
&lt;br /&gt;
{{anchor|d30e3067-Head3}}{{anchor|sec-sec_03.04.06}}=== 03.04.06 Least Functionality ===&lt;br /&gt;
&lt;br /&gt;
==== ASSESSMENT OBJECTIVE ====&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Determine if:&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.04.06.ODP[01]}}A.03.04.06.ODP&amp;amp;#91;01&amp;amp;#93;: &#039;&#039;&#039;&amp;lt;nowiki/&amp;gt;&#039;&#039;&#039;&#039;&#039;functions to be prohibited or restricted are defined&#039;&#039;&#039;&#039;&#039;&amp;lt;nowiki/&amp;gt;&#039;&#039;&#039;.&#039;&#039;&#039;&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.04.06.ODP[02]}}A.03.04.06.ODP&amp;amp;#91;02&amp;amp;#93;: &#039;&#039;&#039;&amp;lt;nowiki/&amp;gt;&#039;&#039;&#039;&#039;&#039;ports to be prohibited or restricted are defined&#039;&#039;&#039;&#039;&#039;&amp;lt;nowiki/&amp;gt;&#039;&#039;&#039;.&#039;&#039;&#039;&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.04.06.ODP[03]}}A.03.04.06.ODP&amp;amp;#91;03&amp;amp;#93;: &#039;&#039;&#039;&amp;lt;nowiki/&amp;gt;&#039;&#039;&#039;&#039;&#039;protocols to be prohibited or restricted are defined&#039;&#039;&#039;&#039;&#039;&amp;lt;nowiki/&amp;gt;&#039;&#039;&#039;.&#039;&#039;&#039;&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.04.06.ODP[04]}}A.03.04.06.ODP&amp;amp;#91;04&amp;amp;#93;: &#039;&#039;&#039;&amp;lt;nowiki/&amp;gt;&#039;&#039;&#039;&#039;&#039;connections to be prohibited or restricted are defined&#039;&#039;&#039;&#039;&#039;&amp;lt;nowiki/&amp;gt;&#039;&#039;&#039;.&#039;&#039;&#039;&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.04.06.ODP[05]}}A.03.04.06.ODP&amp;amp;#91;05&amp;amp;#93;: &#039;&#039;&#039;&amp;lt;nowiki/&amp;gt;&#039;&#039;&#039;&#039;&#039;services to be prohibited or restricted are defined&#039;&#039;&#039;&#039;&#039;&amp;lt;nowiki/&amp;gt;&#039;&#039;&#039;.&#039;&#039;&#039;&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.04.06.ODP[06]}}A.03.04.06.ODP&amp;amp;#91;06&amp;amp;#93;: &#039;&#039;&#039;&amp;lt;nowiki/&amp;gt;&#039;&#039;&#039;&#039;&#039;the frequency at which to review the system to identify unnecessary or nonsecure functions, ports, protocols, connections, or services is defined&#039;&#039;&#039;&#039;&#039;&amp;lt;nowiki/&amp;gt;&#039;&#039;&#039;.&#039;&#039;&#039;&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.04.06.a}}A.03.04.06.a:&#039;&#039;&#039; the system is configured to provide only mission-essential capabilities.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.04.06.b[01]}}A.03.04.06.b&amp;amp;#91;01&amp;amp;#93;:&#039;&#039;&#039; the use of the following functions is prohibited or restricted: &#039;&#039;&#039;&#039;&#039;&amp;lt;A.03.04.06.ODP&amp;amp;#91;01&amp;amp;#93;: functions&amp;gt;&#039;&#039;&#039;&#039;&#039;.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.04.06.b[02]}}A.03.04.06.b&amp;amp;#91;02&amp;amp;#93;:&#039;&#039;&#039; the use of the following ports is prohibited or restricted: &#039;&#039;&#039;&#039;&#039;&amp;lt;A.03.04.06.ODP&amp;amp;#91;02&amp;amp;#93;: ports&amp;gt;&#039;&#039;&#039;&#039;&#039;.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.04.06.b[03]}}A.03.04.06.b&amp;amp;#91;03&amp;amp;#93;:&#039;&#039;&#039; the use of the following protocols is prohibited or restricted: &#039;&#039;&#039;&#039;&#039;&amp;lt;A.03.04.06.ODP&amp;amp;#91;03&amp;amp;#93;: protocols&amp;gt;&#039;&#039;&#039;&#039;&#039;.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.04.06.b[04]}}A.03.04.06.b&amp;amp;#91;04&amp;amp;#93;:&#039;&#039;&#039; the use of the following connections is prohibited or restricted: &#039;&#039;&#039;&#039;&#039;&amp;lt;A.03.04.06.ODP&amp;amp;#91;04&amp;amp;#93;: connections&amp;gt;&#039;&#039;&#039;&#039;&#039;.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.04.06.b[05]}}A.03.04.06.b&amp;amp;#91;05&amp;amp;#93;:&#039;&#039;&#039; the use of the following services is prohibited or restricted: &#039;&#039;&#039;&#039;&#039;&amp;lt;A.03.04.06.ODP&amp;amp;#91;05&amp;amp;#93;: services&amp;gt;&#039;&#039;&#039;&#039;&#039;.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.04.06.c}}A.03.04.06.c:&#039;&#039;&#039; the system is reviewed &#039;&#039;&#039;&#039;&#039;&amp;lt;A.03.04.06.ODP&amp;amp;#91;06&amp;amp;#93;: frequency&amp;gt;&#039;&#039;&#039;&#039;&#039; to identify unnecessary or nonsecure functions, ports, protocols, connections, and services.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.04.06.d}}A.03.04.06.d:&#039;&#039;&#039; unnecessary or nonsecure functions, ports, protocols, connections, and services are disabled or removed.&lt;br /&gt;
&lt;br /&gt;
==== ASSESSMENT METHODS AND OBJECTS ====&lt;br /&gt;
&lt;br /&gt;
===== Examine =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: configuration management policy and procedures; procedures for least functionality in the system; configuration management plan; system design documentation; system configuration settings; system component inventory; common secure configuration checklists; documented reviews of functions, ports, protocols, and services; change control records; system audit records; system security plan; other relevant documents or records&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
===== Interview =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: personnel with configuration management responsibilities; personnel with responsibilities for reviewing functions, ports, protocols, and services; personnel with information security responsibilities; system developers; system administrators&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
===== Test =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: processes for prohibiting or restricting functions, ports, protocols, and services; processes for reviewing or disabling functions, ports, protocols, and services; mechanisms for implementing the review and disabling of functions, ports, protocols, and services; mechanisms for implementing restrictions on or the prohibition of functions, ports, protocols, and services&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
==== REFERENCES ====&lt;br /&gt;
&lt;br /&gt;
Source Assessment Procedures: [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_A_5_1_1/home?element=CM-07 CM-07], [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_A_5_1_1/home?element=CM-07 CM-07(01)]&lt;br /&gt;
&lt;br /&gt;
{{anchor|d30e3221-Head3}}{{anchor|sec-sec_03.04.07}}=== 03.04.07 Withdrawn ===&lt;br /&gt;
&lt;br /&gt;
Incorporated into [[#sec-sec_03.04.06|03.04.06]] and [[#sec-sec_03.04.08|03.04.08]].&lt;br /&gt;
&lt;br /&gt;
{{anchor|d30e3234-Head3}}{{anchor|sec-sec_03.04.08}}=== 03.04.08 Authorized Software – Allow by Exception ===&lt;br /&gt;
&lt;br /&gt;
==== ASSESSMENT OBJECTIVE ====&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Determine if:&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.04.08.ODP[01]}}A.03.04.08.ODP&amp;amp;#91;01&amp;amp;#93;: &#039;&#039;&#039;&amp;lt;nowiki/&amp;gt;&#039;&#039;&#039;&#039;&#039;the frequency at which to review and update the list of authorized software programs is defined&#039;&#039;&#039;&#039;&#039;&amp;lt;nowiki/&amp;gt;&#039;&#039;&#039;.&#039;&#039;&#039;&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.04.08.a}}A.03.04.08.a:&#039;&#039;&#039; software programs authorized to execute on the system are identified.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.04.08.b}}A.03.04.08.b:&#039;&#039;&#039; a deny-all, allow-by-exception policy for the execution of authorized software programs on the system is implemented.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.04.08.c}}A.03.04.08.c:&#039;&#039;&#039; the list of authorized software programs is reviewed and updated &#039;&#039;&#039;&#039;&#039;&amp;lt;A.03.04.08.ODP&amp;amp;#91;01&amp;amp;#93;: frequency&amp;gt;&#039;&#039;&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
==== ASSESSMENT METHODS AND OBJECTS ====&lt;br /&gt;
&lt;br /&gt;
===== Examine =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: configuration management policy and procedures; procedures for least functionality in the system; configuration management plan; system design documentation; system configuration settings; list of software programs authorized to execute on the system; system component inventory; records associated with the review and update of the list of authorized software programs; common secure configuration checklists; change control records; system audit records; system security plan; other relevant documents or records&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
===== Interview =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: personnel with responsibilities for identifying software authorized to execute on the system; personnel with information security responsibilities; system administrators&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
===== Test =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: processes for identifying, reviewing, and updating programs authorized to execute on the system; processes for implementing authorized software policy; mechanisms for supporting or implementing authorized software policy&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
==== REFERENCES ====&lt;br /&gt;
&lt;br /&gt;
Source Assessment Procedure: [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_A_5_1_1/home?element=CM-07 CM-07(05)]&lt;br /&gt;
&lt;br /&gt;
{{anchor|d30e3299-Head3}}{{anchor|sec-sec_03.04.09}}=== 03.04.09 Withdrawn ===&lt;br /&gt;
&lt;br /&gt;
Addressed by [[#sec-sec_03.01.05|03.01.05]], [[#sec-sec_03.01.06|03.01.06]], [[#sec-sec_03.01.07|03.01.07]], [[#sec-sec_03.04.08|03.04.08]], and [[#sec-sec_03.12.03|03.12.03]].&lt;br /&gt;
&lt;br /&gt;
{{anchor|d30e3321-Head3}}{{anchor|sec-sec_03.04.10}}=== 03.04.10 System Component Inventory ===&lt;br /&gt;
&lt;br /&gt;
==== ASSESSMENT OBJECTIVE ====&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Determine if:&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.04.10.ODP[01]}}A.03.04.10.ODP&amp;amp;#91;01&amp;amp;#93;: &#039;&#039;&#039;&amp;lt;nowiki/&amp;gt;&#039;&#039;&#039;&#039;&#039;the frequency at which to review and update the system component inventory is defined&#039;&#039;&#039;&#039;&#039;&amp;lt;nowiki/&amp;gt;&#039;&#039;&#039;.&#039;&#039;&#039;&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.04.10.a}}A.03.04.10.a:&#039;&#039;&#039; an inventory of system components is developed and documented.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.04.10.b[01]}}A.03.04.10.b&amp;amp;#91;01&amp;amp;#93;:&#039;&#039;&#039; the system component inventory is reviewed &#039;&#039;&#039;&#039;&#039;&amp;lt;A.03.04.10.ODP&amp;amp;#91;01&amp;amp;#93;: frequency&amp;gt;&#039;&#039;&#039;&#039;&#039;.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.04.10.b[02]}}A.03.04.10.b&amp;amp;#91;02&amp;amp;#93;:&#039;&#039;&#039; the system component inventory is updated &#039;&#039;&#039;&#039;&#039;&amp;lt;A.03.04.10.ODP&amp;amp;#91;01&amp;amp;#93;: frequency&amp;gt;&#039;&#039;&#039;&#039;&#039;.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.04.10.c[01]}}A.03.04.10.c&amp;amp;#91;01&amp;amp;#93;:&#039;&#039;&#039; the system component inventory is updated as part of component installations.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.04.10.c[02]}}A.03.04.10.c&amp;amp;#91;02&amp;amp;#93;:&#039;&#039;&#039; the system component inventory is updated as part of component removals.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.04.10.c[03]}}A.03.04.10.c&amp;amp;#91;03&amp;amp;#93;:&#039;&#039;&#039; the system component inventory is updated as part of system updates.&lt;br /&gt;
&lt;br /&gt;
==== ASSESSMENT METHODS AND OBJECTS ====&lt;br /&gt;
&lt;br /&gt;
===== Examine =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: configuration management policy and procedures; procedures for system component inventory; configuration management plan; system design documentation; system component inventory; inventory reviews and update records; component installation records; change control records; component removal records; system change records; system security plan; other relevant documents or records&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
===== Interview =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: personnel with component inventory management responsibilities; personnel with information security responsibilities; system administrators&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
===== Test =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: processes for managing the system component inventory; mechanisms for supporting or implementing the system component inventory; processes for updating the system component inventory; mechanisms for supporting or implementing the system component inventory updates&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
==== REFERENCES ====&lt;br /&gt;
&lt;br /&gt;
Source Assessment Procedures: [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_A_5_1_1/home?element=CM-08 CM-08], [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_A_5_1_1/home?element=CM-08 CM-08(01)]&lt;br /&gt;
&lt;br /&gt;
{{anchor|d30e3408-Head3}}{{anchor|sec-sec_03.04.11}}=== 03.04.11 Information Location ===&lt;br /&gt;
&lt;br /&gt;
==== ASSESSMENT OBJECTIVE ====&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Determine if:&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.04.11.a[01]}}A.03.04.11.a&amp;amp;#91;01&amp;amp;#93;:&#039;&#039;&#039; the location of CUI is identified and documented.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.04.11.a[02]}}A.03.04.11.a&amp;amp;#91;02&amp;amp;#93;:&#039;&#039;&#039; the system components on which CUI is processed are identified and documented.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.04.11.a[03]}}A.03.04.11.a&amp;amp;#91;03&amp;amp;#93;:&#039;&#039;&#039; the system components on which CUI is stored are identified and documented.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.04.11.b[01]}}A.03.04.11.b&amp;amp;#91;01&amp;amp;#93;:&#039;&#039;&#039; changes to the system or system component location where CUI is processed are documented.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.04.11.b[02]}}A.03.04.11.b&amp;amp;#91;02&amp;amp;#93;:&#039;&#039;&#039; changes to the system or system component location where CUI is stored are documented.&lt;br /&gt;
&lt;br /&gt;
==== ASSESSMENT METHODS AND OBJECTS ====&lt;br /&gt;
&lt;br /&gt;
===== Examine =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: configuration management policy and procedures; configuration management plan; procedures for identification and documentation of information location; system audit records; architecture documentation; system design documentation; list of users with system and system component access; change control records; system component inventory; system security plan; other relevant documents or records&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
===== Interview =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: personnel with responsibilities for managing information location and user access; personnel with responsibilities for operating, using, or maintaining the system; personnel with information security responsibilities; system developers; system administrators&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
===== Test =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: processes governing information location; mechanisms for enforcing policies and methods for governing information location&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
==== REFERENCES ====&lt;br /&gt;
&lt;br /&gt;
Source Assessment Procedure: [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_A_5_1_1/home?element=CM-12 CM-12]&lt;br /&gt;
&lt;br /&gt;
{{anchor|d30e3470-Head3}}{{anchor|sec-sec_03.04.12}}=== 03.04.12 System and Component Configuration for High-Risk Areas ===&lt;br /&gt;
&lt;br /&gt;
==== ASSESSMENT OBJECTIVE ====&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Determine if:&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.04.12.ODP[01]}}A.03.04.12.ODP&amp;amp;#91;01&amp;amp;#93;: &#039;&#039;&#039;&amp;lt;nowiki/&amp;gt;&#039;&#039;&#039;&#039;&#039;configurations for systems or system components to be issued to individuals traveling to high-risk locations are defined&#039;&#039;&#039;&#039;&#039;&amp;lt;nowiki/&amp;gt;&#039;&#039;&#039;.&#039;&#039;&#039;&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.04.12.ODP[02]}}A.03.04.12.ODP&amp;amp;#91;02&amp;amp;#93;: &#039;&#039;&#039;&amp;lt;nowiki/&amp;gt;&#039;&#039;&#039;&#039;&#039;security requirements to be applied to the system or system components when individuals return from travel are defined&#039;&#039;&#039;&#039;&#039;&amp;lt;nowiki/&amp;gt;&#039;&#039;&#039;.&#039;&#039;&#039;&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.04.12.a}}A.03.04.12.a:&#039;&#039;&#039; systems or system components with the following configurations are issued to individuals traveling to high-risk locations: &#039;&#039;&#039;&#039;&#039;&amp;lt;A.03.04.12.ODP&amp;amp;#91;01&amp;amp;#93;: configurations&amp;gt;&#039;&#039;&#039;&#039;&#039;.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.04.12.b}}A.03.04.12.b:&#039;&#039;&#039; the following security requirements are applied to the system or system components when the individuals return from travel: &#039;&#039;&#039;&#039;&#039;&amp;lt;A.03.04.12.ODP&amp;amp;#91;02&amp;amp;#93;: security requirements&amp;gt;&#039;&#039;&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
==== ASSESSMENT METHODS AND OBJECTS ====&lt;br /&gt;
&lt;br /&gt;
===== Examine =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: configuration management policy and procedures; configuration management plan; procedures for the baseline configuration of the system; procedures for system component installations and upgrades; system component inventory; system component installations or upgrades and associated records; records of system baseline configuration reviews and updates; system configuration settings; system architecture; change control records; system security plan; other relevant documents or records&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
===== Interview =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: personnel with configuration management responsibilities; personnel with information security responsibilities; system administrators&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
===== Test =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: processes for managing baseline configurations&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
==== REFERENCES ====&lt;br /&gt;
&lt;br /&gt;
Source Assessment Procedure: [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_A_5_1_1/home?element=CM-02 CM-02(07)]&lt;br /&gt;
&lt;br /&gt;
{{anchor|d30e3542-Head2}}{{anchor|sec-sec_3.5}}== 3.5 [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=IA Identification and Authentication] ==&lt;br /&gt;
&lt;br /&gt;
{{anchor|d30e3547-Head3}}{{anchor|sec-sec_03.05.01}}=== 03.05.01 User Identification, Authentication, and Re-Authentication ===&lt;br /&gt;
&lt;br /&gt;
==== ASSESSMENT OBJECTIVE ====&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Determine if:&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.05.01.ODP[01]}}A.03.05.01.ODP&amp;amp;#91;01&amp;amp;#93;: &#039;&#039;&#039;&amp;lt;nowiki/&amp;gt;&#039;&#039;&#039;&#039;&#039;circumstances or situations that require re-authentication are defined&#039;&#039;&#039;&#039;&#039;&amp;lt;nowiki/&amp;gt;&#039;&#039;&#039;.&#039;&#039;&#039;&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.05.01.a[01]}}A.03.05.01.a&amp;amp;#91;01&amp;amp;#93;:&#039;&#039;&#039; system users are uniquely identified.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.05.01.a[02]}}A.03.05.01.a&amp;amp;#91;02&amp;amp;#93;:&#039;&#039;&#039; system users are authenticated.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.05.01.a[03]}}A.03.05.01.a&amp;amp;#91;03&amp;amp;#93;:&#039;&#039;&#039; processes acting on behalf of users are associated with uniquely identified and authenticated system users.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.05.01.b}}A.03.05.01.b:&#039;&#039;&#039; users are reauthenticated when &#039;&#039;&#039;&#039;&#039;&amp;lt;A.03.05.01.ODP&amp;amp;#91;01&amp;amp;#93;: circumstances or situations&amp;gt;&#039;&#039;&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
==== ASSESSMENT METHODS AND OBJECTS ====&lt;br /&gt;
&lt;br /&gt;
===== Examine =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: identification and authentication policy and procedures; list of circumstances or situations requiring re-authentication; system design documentation; system configuration settings; system audit records; list of system accounts; system security plan; other relevant documents or records&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
===== Interview =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: personnel with identification and authentication responsibilities; personnel with system operations responsibilities; personnel with account management responsibilities; system developers; personnel with information security responsibilities; system administrators&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
===== Test =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: processes for uniquely identifying and authenticating users; mechanisms for supporting or implementing identification and authentication capabilities&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
==== REFERENCES ====&lt;br /&gt;
&lt;br /&gt;
Source Assessment Procedures: [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_A_5_1_1/home?element=IA-02 IA-02], [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_A_5_1_1/home?element=IA-11 IA-11]&lt;br /&gt;
&lt;br /&gt;
{{anchor|d30e3620-Head3}}{{anchor|sec-sec_03.05.02}}=== 03.05.02 Device Identification and Authentication ===&lt;br /&gt;
&lt;br /&gt;
==== ASSESSMENT OBJECTIVE ====&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Determine if:&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.05.02.ODP[01]}}A.03.05.02.ODP&amp;amp;#91;01&amp;amp;#93;: &#039;&#039;&#039;&amp;lt;nowiki/&amp;gt;&#039;&#039;&#039;&#039;&#039;devices or types of devices to be uniquely identified and authenticated before establishing a connection are defined&#039;&#039;&#039;&#039;&#039;&amp;lt;nowiki/&amp;gt;&#039;&#039;&#039;.&#039;&#039;&#039;&lt;br /&gt;
* &#039;&#039;&#039;A.03.05.02&amp;amp;#91;01&amp;amp;#93;: &#039;&#039;&#039;&amp;lt;nowiki/&amp;gt;&#039;&#039;&#039;&#039;&#039;&amp;lt;A.03.05.02.ODP&amp;amp;#91;01&amp;amp;#93;: devices or types of devices&amp;gt;&#039;&#039;&#039;&#039;&#039; are uniquely identified before establishing a system connection.&lt;br /&gt;
* &#039;&#039;&#039;A.03.05.02&amp;amp;#91;02&amp;amp;#93;: &#039;&#039;&#039;&amp;lt;nowiki/&amp;gt;&#039;&#039;&#039;&#039;&#039;&amp;lt;A.03.05.02.ODP&amp;amp;#91;01&amp;amp;#93;: devices or types of devices&amp;gt;&#039;&#039;&#039;&#039;&#039; are authenticated before establishing a system connection.&lt;br /&gt;
&lt;br /&gt;
==== ASSESSMENT METHODS AND OBJECTS ====&lt;br /&gt;
&lt;br /&gt;
===== Examine =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: identification and authentication policy and procedures; procedures for device identification and authentication; system design documentation; list of devices requiring unique identification and authentication; device connection reports; system configuration settings; system security plan; other relevant documents or records&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
===== Interview =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: personnel with responsibilities for device identification and authentication; personnel with information security responsibilities; system developers; system administrators&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
===== Test =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: mechanisms for supporting or implementing device identification and authentication capabilities&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
==== REFERENCES ====&lt;br /&gt;
&lt;br /&gt;
Source Assessment Procedure: [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_A_5_1_1/home?element=IA-03 IA-03]&lt;br /&gt;
&lt;br /&gt;
{{anchor|d30e3681-Head3}}{{anchor|sec-sec_03.05.03}}=== 03.05.03 Multi-Factor Authentication ===&lt;br /&gt;
&lt;br /&gt;
==== ASSESSMENT OBJECTIVE ====&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Determine if:&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;A.03.05.03&amp;amp;#91;01&amp;amp;#93;:&#039;&#039;&#039; multi-factor authentication for access to privileged accounts is implemented.&lt;br /&gt;
* &#039;&#039;&#039;A.03.05.03&amp;amp;#91;02&amp;amp;#93;:&#039;&#039;&#039; multi-factor authentication for access to non-privileged accounts is implemented.&lt;br /&gt;
&lt;br /&gt;
==== ASSESSMENT METHODS AND OBJECTS ====&lt;br /&gt;
&lt;br /&gt;
===== Examine =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: identification and authentication policy and procedures; system design documentation; list of system accounts; system configuration settings; system audit records; system security plan; other relevant documents or records&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
===== Interview =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: personnel with system operations responsibilities; personnel with account management responsibilities; personnel with information security responsibilities; system developers; system administrators&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
===== Test =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: mechanisms for supporting or implementing a multi-factor authentication capability&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
==== REFERENCES ====&lt;br /&gt;
&lt;br /&gt;
Source Assessment Procedures: [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_A_5_1_1/home?element=IA-02 IA-02(01)], [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_A_5_1_1/home?element=IA-02 IA-02(02)]&lt;br /&gt;
&lt;br /&gt;
{{anchor|d30e3730-Head3}}{{anchor|sec-sec_03.05.04}}=== 03.05.04 Replay-Resistant Authentication ===&lt;br /&gt;
&lt;br /&gt;
==== ASSESSMENT OBJECTIVE ====&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Determine if:&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;A.03.05.04&amp;amp;#91;01&amp;amp;#93;:&#039;&#039;&#039; replay-resistant authentication mechanisms for access to privileged accounts are implemented.&lt;br /&gt;
* &#039;&#039;&#039;A.03.05.04&amp;amp;#91;02&amp;amp;#93;:&#039;&#039;&#039; replay-resistant authentication mechanisms for access to non-privileged accounts are implemented.&lt;br /&gt;
&lt;br /&gt;
==== ASSESSMENT METHODS AND OBJECTS ====&lt;br /&gt;
&lt;br /&gt;
===== Examine =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: identification and authentication policy and procedures; system design documentation; system audit records; system configuration settings; list of privileged system accounts; system security plan; other relevant documents or records&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
===== Interview =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: personnel with system operations responsibilities; personnel with account management responsibilities; personnel with information security responsibilities; system developers; system administrators&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
===== Test =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: mechanisms for supporting or implementing identification and authentication capabilities; mechanisms for supporting or implementing replay-resistance&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
==== REFERENCES ====&lt;br /&gt;
&lt;br /&gt;
Source Assessment Procedure: [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_A_5_1_1/home?element=IA-02 IA-02(08)]&lt;br /&gt;
&lt;br /&gt;
{{anchor|d30e3775-Head3}}{{anchor|sec-sec_03.05.05}}=== 03.05.05 Identifier Management ===&lt;br /&gt;
&lt;br /&gt;
==== ASSESSMENT OBJECTIVE ====&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Determine if:&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.05.05.ODP[01]}}A.03.05.05.ODP&amp;amp;#91;01&amp;amp;#93;: &#039;&#039;&#039;&amp;lt;nowiki/&amp;gt;&#039;&#039;&#039;&#039;&#039;the time period for preventing the reuse of identifiers is defined&#039;&#039;&#039;&#039;&#039;&amp;lt;nowiki/&amp;gt;&#039;&#039;&#039;.&#039;&#039;&#039;&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.05.05.ODP[02]}}A.03.05.05.ODP&amp;amp;#91;02&amp;amp;#93;: &#039;&#039;&#039;&amp;lt;nowiki/&amp;gt;&#039;&#039;&#039;&#039;&#039;characteristics used to identify individual status are defined&#039;&#039;&#039;&#039;&#039;&amp;lt;nowiki/&amp;gt;&#039;&#039;&#039;.&#039;&#039;&#039;&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.05.05.a}}A.03.05.05.a:&#039;&#039;&#039; authorization is received from organizational personnel or roles to assign an individual, group, role, service, or device identifier.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.05.05.b[01]}}A.03.05.05.b&amp;amp;#91;01&amp;amp;#93;:&#039;&#039;&#039; an identifier that identifies an individual, group, role, service, or device is selected.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.05.05.b[02]}}A.03.05.05.b&amp;amp;#91;02&amp;amp;#93;:&#039;&#039;&#039; an identifier that identifies an individual, group, role, service, or device is assigned.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.05.05.c}}A.03.05.05.c:&#039;&#039;&#039; the reuse of identifiers for &#039;&#039;&#039;&#039;&#039;&amp;lt;A.03.05.05.ODP&amp;amp;#91;01&amp;amp;#93;: time period&amp;gt;&#039;&#039;&#039;&#039;&#039; is prevented.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.05.05.d}}A.03.05.05.d:&#039;&#039;&#039; individual identifiers are managed by uniquely identifying each individual as &#039;&#039;&#039;&#039;&#039;&amp;lt;A.03.05.05.ODP&amp;amp;#91;02&amp;amp;#93;: characteristic&amp;gt;&#039;&#039;&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
==== ASSESSMENT METHODS AND OBJECTS ====&lt;br /&gt;
&lt;br /&gt;
===== Examine =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: identification and authentication policy and procedures; procedures for identifier management; procedures for account management; system design documentation; list of system accounts; list of characteristics identifying individual status; system configuration settings; list of identifiers generated from physical access control devices; system security plan; other relevant documents or records&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
===== Interview =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: personnel with identifier management responsibilities; personnel with information security responsibilities; system developers; system administrators&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
===== Test =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: mechanisms for supporting or implementing identifier management&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
==== REFERENCES ====&lt;br /&gt;
&lt;br /&gt;
Source Assessment Procedures: [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_A_5_1_1/home?element=IA-04 IA-04], [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_A_5_1_1/home?element=IA-04 IA-04(04)]&lt;br /&gt;
&lt;br /&gt;
{{anchor|d30e3866-Head3}}{{anchor|sec-sec_03.05.06}}=== 03.05.06 Withdrawn ===&lt;br /&gt;
&lt;br /&gt;
Consistency with SP 800-53 &amp;amp;#91;[[#bibr-ref_8|8]]&amp;amp;#93;.&lt;br /&gt;
&lt;br /&gt;
{{anchor|d30e3876-Head3}}{{anchor|sec-sec_03.05.07}}=== 03.05.07 Password Management ===&lt;br /&gt;
&lt;br /&gt;
==== ASSESSMENT OBJECTIVE ====&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Determine if:&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.05.07.ODP[01]}}A.03.05.07.ODP&amp;amp;#91;01&amp;amp;#93;: &#039;&#039;&#039;&amp;lt;nowiki/&amp;gt;&#039;&#039;&#039;&#039;&#039;the frequency at which to update the list of commonly used, expected, or compromised passwords is defined&#039;&#039;&#039;&#039;&#039;&amp;lt;nowiki/&amp;gt;&#039;&#039;&#039;.&#039;&#039;&#039;&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.05.07.ODP[02]}}A.03.05.07.ODP&amp;amp;#91;02&amp;amp;#93;: &#039;&#039;&#039;&amp;lt;nowiki/&amp;gt;&#039;&#039;&#039;&#039;&#039;password composition and complexity rules are defined&#039;&#039;&#039;&#039;&#039;&amp;lt;nowiki/&amp;gt;&#039;&#039;&#039;.&#039;&#039;&#039;&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.05.07.a[01]}}A.03.05.07.a&amp;amp;#91;01&amp;amp;#93;:&#039;&#039;&#039; a list of commonly used, expected, or compromised passwords is maintained.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.05.07.a[02]}}A.03.05.07.a&amp;amp;#91;02&amp;amp;#93;:&#039;&#039;&#039; a list of commonly used, expected, or compromised passwords is updated &#039;&#039;&#039;&#039;&#039;&amp;lt;A.03.05.07.ODP&amp;amp;#91;01&amp;amp;#93;: frequency&amp;gt;&#039;&#039;&#039;&#039;&#039;.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.05.07.a[03]}}A.03.05.07.a&amp;amp;#91;03&amp;amp;#93;:&#039;&#039;&#039; a list of commonly used, expected, or compromised passwords is updated when organizational passwords are suspected to have been compromised.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.05.07.b}}A.03.05.07.b:&#039;&#039;&#039; passwords are verified not to be found on the list of commonly used, expected, or compromised passwords when they are created or updated by users.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.05.07.c}}A.03.05.07.c:&#039;&#039;&#039; passwords are only transmitted over cryptographically protected channels.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.05.07.d}}A.03.05.07.d:&#039;&#039;&#039; passwords are stored in a cryptographically protected form.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.05.07.e}}A.03.05.07.e:&#039;&#039;&#039; a new password is selected upon first use after account recovery.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.05.07.f}}A.03.05.07.f:&#039;&#039;&#039; the following composition and complexity rules for passwords are enforced: &#039;&#039;&#039;&#039;&#039;&amp;lt;A.03.05.07.ODP&amp;amp;#91;02&amp;amp;#93;: rules&amp;gt;&#039;&#039;&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
==== ASSESSMENT METHODS AND OBJECTS ====&lt;br /&gt;
&lt;br /&gt;
===== Examine =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: identification and authentication policy and procedures; password policy; procedures for authenticator management; system design documentation; system configuration settings; password configurations; system security plan; other relevant documents or records&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
===== Interview =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: personnel with authenticator management responsibilities; personnel with information security responsibilities; system developers; system administrators&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
===== Test =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: mechanisms for supporting or implementing a password-based authenticator management capability&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
==== REFERENCES ====&lt;br /&gt;
&lt;br /&gt;
Source Assessment Procedure: [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_A_5_1_1/home?element=IA-05 IA-05(01)]&lt;br /&gt;
&lt;br /&gt;
{{anchor|d30e3978-Head3}}{{anchor|sec-sec_03.05.08}}=== 03.05.08 Withdrawn ===&lt;br /&gt;
&lt;br /&gt;
Consistency with SP 800-53 &amp;amp;#91;[[#bibr-ref_8|8]]&amp;amp;#93;.&lt;br /&gt;
&lt;br /&gt;
{{anchor|d30e3988-Head3}}{{anchor|sec-sec_03.05.09}}=== 03.05.09 Withdrawn ===&lt;br /&gt;
&lt;br /&gt;
Consistency with SP 800-53 &amp;amp;#91;[[#bibr-ref_8|8]]&amp;amp;#93;.&lt;br /&gt;
&lt;br /&gt;
{{anchor|d30e3999-Head3}}{{anchor|sec-sec_03.05.10}}=== 03.05.10 Withdrawn ===&lt;br /&gt;
&lt;br /&gt;
Incorporated into [[#sec-sec_03.05.07|03.05.07]].&lt;br /&gt;
&lt;br /&gt;
{{anchor|d30e4009-Head3}}{{anchor|sec-sec_03.05.11}}=== 03.05.11 Authentication Feedback ===&lt;br /&gt;
&lt;br /&gt;
==== ASSESSMENT OBJECTIVE ====&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Determine if:&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;A.03.05.11:&#039;&#039;&#039; feedback of authentication information during the authentication process is obscured.&lt;br /&gt;
&lt;br /&gt;
==== ASSESSMENT METHODS AND OBJECTS ====&lt;br /&gt;
&lt;br /&gt;
===== Examine =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: identification and authentication policy and procedures; procedures for authenticator feedback; system design documentation; system configuration settings; system audit records; system security plan; other relevant documents or records&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
===== Interview =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: personnel with information security responsibilities; system developers; system administrators&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
===== Test =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: mechanisms for supporting or implementing the obscuring of feedback of authentication information during authentication&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
==== REFERENCES ====&lt;br /&gt;
&lt;br /&gt;
Source Assessment Procedure: [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_A_5_1_1/home?element=IA-06 IA-06]&lt;br /&gt;
&lt;br /&gt;
{{anchor|d30e4050-Head3}}{{anchor|sec-sec_03.05.12}}=== 03.05.12 Authenticator Management ===&lt;br /&gt;
&lt;br /&gt;
==== ASSESSMENT OBJECTIVE ====&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Determine if:&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.05.12.ODP[01]}}A.03.05.12.ODP&amp;amp;#91;01&amp;amp;#93;: &#039;&#039;&#039;&amp;lt;nowiki/&amp;gt;&#039;&#039;&#039;&#039;&#039;the frequency for changing or refreshing authenticators is defined&#039;&#039;&#039;&#039;&#039;&amp;lt;nowiki/&amp;gt;&#039;&#039;&#039;.&#039;&#039;&#039;&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.05.12.ODP[02]}}A.03.05.12.ODP&amp;amp;#91;02&amp;amp;#93;: &#039;&#039;&#039;&amp;lt;nowiki/&amp;gt;&#039;&#039;&#039;&#039;&#039;events that trigger the change or refreshment of authenticators are defined&#039;&#039;&#039;&#039;&#039;&amp;lt;nowiki/&amp;gt;&#039;&#039;&#039;.&#039;&#039;&#039;&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.05.12.a}}A.03.05.12.a:&#039;&#039;&#039; the identity of the individual, group, role, service, or device receiving the authenticator as part of the initial authenticator distribution is verified.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.05.12.b}}A.03.05.12.b:&#039;&#039;&#039; initial authenticator content for any authenticators issued by the organization is established.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.05.12.c[01]}}A.03.05.12.c&amp;amp;#91;01&amp;amp;#93;:&#039;&#039;&#039; administrative procedures for initial authenticator distribution are established.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.05.12.c[02]}}A.03.05.12.c&amp;amp;#91;02&amp;amp;#93;:&#039;&#039;&#039; administrative procedures for lost, compromised, or damaged authenticators are established.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.05.12.c[03]}}A.03.05.12.c&amp;amp;#91;03&amp;amp;#93;:&#039;&#039;&#039; administrative procedures for revoking authenticators are established.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.05.12.c[04]}}A.03.05.12.c&amp;amp;#91;04&amp;amp;#93;:&#039;&#039;&#039; administrative procedures for initial authenticator distribution are implemented.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.05.12.c[05]}}A.03.05.12.c&amp;amp;#91;05&amp;amp;#93;:&#039;&#039;&#039; administrative procedures for lost, compromised, or damaged authenticators are implemented.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.05.12.c[06]}}A.03.05.12.c&amp;amp;#91;06&amp;amp;#93;:&#039;&#039;&#039; administrative procedures for revoking authenticators are implemented.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.05.12.d}}A.03.05.12.d:&#039;&#039;&#039; default authenticators are changed at first use.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.05.12.e}}A.03.05.12.e:&#039;&#039;&#039; authenticators are changed or refreshed &#039;&#039;&#039;&#039;&#039;&amp;lt;A.03.05.12.ODP&amp;amp;#91;01&amp;amp;#93;: frequency&amp;gt;&#039;&#039;&#039;&#039;&#039; or when the following events occur: &#039;&#039;&#039;&#039;&#039;&amp;lt;A.03.05.12.ODP&amp;amp;#91;02&amp;amp;#93;: events&amp;gt;&#039;&#039;&#039;&#039;&#039;.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.05.12.f[01]}}A.03.05.12.f&amp;amp;#91;01&amp;amp;#93;:&#039;&#039;&#039; authenticator content is protected from unauthorized disclosure.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.05.12.f[02]}}A.03.05.12.f&amp;amp;#91;02&amp;amp;#93;:&#039;&#039;&#039; authenticator content is protected from unauthorized modification.&lt;br /&gt;
&lt;br /&gt;
==== ASSESSMENT METHODS AND OBJECTS ====&lt;br /&gt;
&lt;br /&gt;
===== Examine =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: identification and authentication policy and procedures; procedures for authenticator management; system configuration settings; list of system authenticator types; system design documentation; system audit records; change control records associated with managing system authenticators; system security plan; other relevant documents or records&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
===== Interview =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: personnel with authenticator management responsibilities; personnel with information security responsibilities; system administrators&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
===== Test =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: mechanisms for supporting or implementing the authenticator management capability&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
==== REFERENCES ====&lt;br /&gt;
&lt;br /&gt;
Source Assessment Procedure: [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_A_5_1_1/home?element=IA-05 IA-05]&lt;br /&gt;
&lt;br /&gt;
{{anchor|d30e4172-Head2}}{{anchor|sec-sec_3.6}}== 3.6 [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=IR Incident Response] ==&lt;br /&gt;
&lt;br /&gt;
{{anchor|d30e4177-Head3}}{{anchor|sec-sec_03.06.01}}=== 03.06.01 Incident Handling ===&lt;br /&gt;
&lt;br /&gt;
==== ASSESSMENT OBJECTIVE ====&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Determine if:&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;A.03.06.01&amp;amp;#91;01&amp;amp;#93;:&#039;&#039;&#039; an incident-handling capability that is consistent with the incident response plan is implemented.&lt;br /&gt;
* &#039;&#039;&#039;A.03.06.01&amp;amp;#91;02&amp;amp;#93;:&#039;&#039;&#039; the incident handling capability includes preparation.&lt;br /&gt;
* &#039;&#039;&#039;A.03.06.01&amp;amp;#91;03&amp;amp;#93;:&#039;&#039;&#039; the incident handling capability includes detection and analysis.&lt;br /&gt;
* &#039;&#039;&#039;A.03.06.01&amp;amp;#91;04&amp;amp;#93;:&#039;&#039;&#039; the incident handling capability includes containment.&lt;br /&gt;
* &#039;&#039;&#039;A.03.06.01&amp;amp;#91;05&amp;amp;#93;:&#039;&#039;&#039; the incident handling capability includes eradication.&lt;br /&gt;
* &#039;&#039;&#039;A.03.06.01&amp;amp;#91;06&amp;amp;#93;:&#039;&#039;&#039; the incident handling capability includes recovery.&lt;br /&gt;
&lt;br /&gt;
==== ASSESSMENT METHODS AND OBJECTS ====&lt;br /&gt;
&lt;br /&gt;
===== Examine =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: incident response policy and procedures; contingency planning policy and procedures; procedures for incident handling; procedures for incident response planning; incident response plan; contingency plan; records of incident response plan reviews and approvals; system security plan; other relevant documents or records&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
===== Interview =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: personnel with incident handling responsibilities; personnel with incident response planning responsibilities; personnel with contingency planning responsibilities; personnel with information security responsibilities&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
===== Test =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: incident handling capability for the organization; incident response plan&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
==== REFERENCES ====&lt;br /&gt;
&lt;br /&gt;
Source Assessment Procedure: [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_A_5_1_1/home?element=IR-04 IR-04]&lt;br /&gt;
&lt;br /&gt;
{{anchor|d30e4239-Head3}}{{anchor|sec-sec_03.06.02}}=== 03.06.02 Incident Monitoring, Reporting, and Response Assistance ===&lt;br /&gt;
&lt;br /&gt;
==== ASSESSMENT OBJECTIVE ====&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Determine if:&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.06.02.ODP[01]}}A.03.06.02.ODP&amp;amp;#91;01&amp;amp;#93;: &#039;&#039;&#039;&amp;lt;nowiki/&amp;gt;&#039;&#039;&#039;&#039;&#039;the time period to report suspected incidents to the organizational incident response capability is defined&#039;&#039;&#039;&#039;&#039;&amp;lt;nowiki/&amp;gt;&#039;&#039;&#039;.&#039;&#039;&#039;&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.06.02.ODP[02]}}A.03.06.02.ODP&amp;amp;#91;02&amp;amp;#93;: &#039;&#039;&#039;&amp;lt;nowiki/&amp;gt;&#039;&#039;&#039;&#039;&#039;authorities to whom incident information is to be reported are defined&#039;&#039;&#039;&#039;&#039;&amp;lt;nowiki/&amp;gt;&#039;&#039;&#039;.&#039;&#039;&#039;&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.06.02.a[01]}}A.03.06.02.a&amp;amp;#91;01&amp;amp;#93;:&#039;&#039;&#039; system security incidents are tracked.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.06.02.a[02]}}A.03.06.02.a&amp;amp;#91;02&amp;amp;#93;:&#039;&#039;&#039; system security incidents are documented.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.06.02.b}}A.03.06.02.b:&#039;&#039;&#039; suspected incidents are reported to the organizational incident response capability within &#039;&#039;&#039;&#039;&#039;&amp;lt;A.03.06.02.ODP&amp;amp;#91;01&amp;amp;#93;: time period&amp;gt;&#039;&#039;&#039;&#039;&#039;.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.06.02.c}}A.03.06.02.c:&#039;&#039;&#039; incident information is reported to &#039;&#039;&#039;&#039;&#039;&amp;lt;A.03.06.02.ODP&amp;amp;#91;02&amp;amp;#93;: authorities&amp;gt;&#039;&#039;&#039;&#039;&#039;.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.06.02.d}}A.03.06.02.d:&#039;&#039;&#039; an incident response support resource that offers advice and assistance to system users on handling and reporting incidents is provided.&lt;br /&gt;
&lt;br /&gt;
==== ASSESSMENT METHODS AND OBJECTS ====&lt;br /&gt;
&lt;br /&gt;
===== Examine =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: incident response policy and procedures; procedures for incident monitoring; procedures for incident response assistance; incident response records and documentation; incident response plan; system security plan; other relevant documents or records&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
===== Interview =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: personnel with incident monitoring responsibilities; personnel with incident response assistance and support responsibilities; personnel with information security responsibilities&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
===== Test =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: processes for incident reporting; incident monitoring capability; mechanisms for supporting or implementing the tracking and documenting of system security incidents; mechanisms for supporting or implementing incident reporting; mechanisms for supporting or implementing incident response assistance; processes for incident response assistance&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
==== REFERENCES ====&lt;br /&gt;
&lt;br /&gt;
Source Assessment Procedures: [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_A_5_1_1/home?element=IR-05 IR-05], [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_A_5_1_1/home?element=IR-06 IR-06], [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_A_5_1_1/home?element=IR-07 IR-07]&lt;br /&gt;
&lt;br /&gt;
{{anchor|d30e4334-Head3}}{{anchor|sec-sec_03.06.03}}=== 03.06.03 Incident Response Testing ===&lt;br /&gt;
&lt;br /&gt;
==== ASSESSMENT OBJECTIVE ====&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Determine if:&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.06.03.ODP[01]}}A.03.06.03.ODP&amp;amp;#91;01&amp;amp;#93;: &#039;&#039;&#039;&amp;lt;nowiki/&amp;gt;&#039;&#039;&#039;&#039;&#039;the frequency at which to test the effectiveness of the incident response capability for the system is defined.&#039;&#039;&#039;&#039;&#039;&lt;br /&gt;
* &#039;&#039;&#039;A.03.06.03:&#039;&#039;&#039; the effectiveness of the incident response capability is tested &#039;&#039;&#039;&#039;&#039;&amp;lt;A.03.06.03.ODP&amp;amp;#91;01&amp;amp;#93;: frequency&amp;gt;&#039;&#039;&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
==== ASSESSMENT METHODS AND OBJECTS ====&lt;br /&gt;
&lt;br /&gt;
===== Examine =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: incident response policy and procedures; contingency planning policy and procedures; procedures for incident response testing; procedures for contingency plan testing; incident response testing material; incident response test results; incident response test plan; incident response plan; contingency plan; system security plan; other relevant documents or records&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
===== Interview =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: personnel with incident response testing responsibilities; personnel with information security responsibilities&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
==== REFERENCES ====&lt;br /&gt;
&lt;br /&gt;
Source Assessment Procedure: [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_A_5_1_1/home?element=IR-03 IR-03]&lt;br /&gt;
&lt;br /&gt;
{{anchor|d30e4380-Head3}}{{anchor|sec-sec_03.06.04}}=== 03.06.04 Incident Response Training ===&lt;br /&gt;
&lt;br /&gt;
==== ASSESSMENT OBJECTIVE ====&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Determine if:&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.06.04.ODP[01]}}A.03.06.04.ODP&amp;amp;#91;01&amp;amp;#93;: &#039;&#039;&#039;&amp;lt;nowiki/&amp;gt;&#039;&#039;&#039;&#039;&#039;the time period within which incident response training is to be provided to system users is defined&#039;&#039;&#039;&#039;&#039;&amp;lt;nowiki/&amp;gt;&#039;&#039;&#039;.&#039;&#039;&#039;&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.06.04.ODP[02]}}A.03.06.04.ODP&amp;amp;#91;02&amp;amp;#93;: &#039;&#039;&#039;&amp;lt;nowiki/&amp;gt;&#039;&#039;&#039;&#039;&#039;the frequency at which to provide incident response training to users after initial training is defined.&#039;&#039;&#039;&#039;&#039;&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.06.04.ODP[03]}}A.03.06.04.ODP&amp;amp;#91;03&amp;amp;#93;: &#039;&#039;&#039;&amp;lt;nowiki/&amp;gt;&#039;&#039;&#039;&#039;&#039;the frequency at which to review and update incident response training content is defined.&#039;&#039;&#039;&#039;&#039;&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.06.04.ODP[04]}}A.03.06.04.ODP&amp;amp;#91;04&amp;amp;#93;: &#039;&#039;&#039;&amp;lt;nowiki/&amp;gt;&#039;&#039;&#039;&#039;&#039;events that initiate a review of the incident response training content are defined&#039;&#039;&#039;&#039;&#039;&amp;lt;nowiki/&amp;gt;&#039;&#039;&#039;.&#039;&#039;&#039;&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.06.04.a.01}}A.03.06.04.a.01:&#039;&#039;&#039; incident response training for system users consistent with assigned roles and responsibilities is provided within &#039;&#039;&#039;&#039;&#039;&amp;lt;A.03.06.04.ODP&amp;amp;#91;01&amp;amp;#93;: time period&amp;gt;&#039;&#039;&#039;&#039;&#039; of assuming an incident response role or responsibility or acquiring system access.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.06.04.a.02}}A.03.06.04.a.02:&#039;&#039;&#039; incident response training for system users consistent with assigned roles and responsibilities is provided when required by system changes.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.06.04.a.03}}A.03.06.04.a.03:&#039;&#039;&#039; incident response training for system users consistent with assigned roles and responsibilities is provided &#039;&#039;&#039;&#039;&#039;&amp;lt;A.03.06.04.ODP&amp;amp;#91;02&amp;amp;#93;: frequency&amp;gt;&#039;&#039;&#039;&#039;&#039; thereafter.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.06.04.b[01]}}A.03.06.04.b&amp;amp;#91;01&amp;amp;#93;:&#039;&#039;&#039; incident response training content is reviewed &#039;&#039;&#039;&#039;&#039;&amp;lt;A.03.06.04.ODP&amp;amp;#91;03&amp;amp;#93;: frequency&amp;gt;&#039;&#039;&#039;&#039;&#039;.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.06.04.b[02]}}A.03.06.04.b&amp;amp;#91;02&amp;amp;#93;:&#039;&#039;&#039; incident response training content is updated &#039;&#039;&#039;&#039;&#039;&amp;lt;A.03.06.04.ODP&amp;amp;#91;03&amp;amp;#93;: frequency&amp;gt;&#039;&#039;&#039;&#039;&#039;.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.06.04.b[03]}}A.03.06.04.b&amp;amp;#91;03&amp;amp;#93;:&#039;&#039;&#039; incident response training content is reviewed following &#039;&#039;&#039;&#039;&#039;&amp;lt;A.03.06.04.ODP&amp;amp;#91;04&amp;amp;#93;: events&amp;gt;&#039;&#039;&#039;&#039;&#039;.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.06.04.b[04]}}A.03.06.04.b&amp;amp;#91;04&amp;amp;#93;:&#039;&#039;&#039; incident response training content is updated following &#039;&#039;&#039;&#039;&#039;&amp;lt;A.03.06.04.ODP&amp;amp;#91;04&amp;amp;#93;: events&amp;gt;&#039;&#039;&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
==== ASSESSMENT METHODS AND OBJECTS ====&lt;br /&gt;
&lt;br /&gt;
===== Examine =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: incident response policy and procedures; procedures for incident response training; incident response training curriculum; incident response training materials; incident response plan; incident response training records; system security plan; other relevant documents or records&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
===== Interview =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: personnel with incident response training and operational responsibilities; personnel with information security responsibilities&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
==== REFERENCES ====&lt;br /&gt;
&lt;br /&gt;
Source Assessment Procedure: [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_A_5_1_1/home?element=IR-02 IR-02]&lt;br /&gt;
&lt;br /&gt;
{{anchor|d30e4498-Head3}}{{anchor|sec-sec_03.06.05}}=== 03.06.05 Incident Response Plan ===&lt;br /&gt;
&lt;br /&gt;
==== ASSESSMENT OBJECTIVE ====&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Determine if:&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.06.05.a.01}}A.03.06.05.a.01:&#039;&#039;&#039; an incident response plan is developed that provides the organization with a roadmap for implementing its incident response capability.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.06.05.a.02}}A.03.06.05.a.02:&#039;&#039;&#039; an incident response plan is developed that describes the structure and organization of the incident response capability.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.06.05.a.03}}A.03.06.05.a.03:&#039;&#039;&#039; an incident response plan is developed that provides a high-level approach for how the incident response capability fits into the overall organization.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.06.05.a.04}}A.03.06.05.a.04:&#039;&#039;&#039; an incident response plan is developed that defines reportable incidents.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.06.05.a.05}}A.03.06.05.a.05:&#039;&#039;&#039; an incident response plan is developed that addresses the sharing of incident information.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.06.05.a.06}}A.03.06.05.a.06:&#039;&#039;&#039; an incident response plan is developed that designates responsibilities to organizational entities, personnel, or roles.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.06.05.b[01]}}A.03.06.05.b&amp;amp;#91;01&amp;amp;#93;:&#039;&#039;&#039; copies of the incident response plan are distributed to designated incident response personnel (identified by name or by role).&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.06.05.b[02]}}A.03.06.05.b&amp;amp;#91;02&amp;amp;#93;:&#039;&#039;&#039; copies of the incident response plan are distributed to organizational elements.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.06.05.c}}A.03.06.05.c:&#039;&#039;&#039; the incident response plan is updated to address system and organizational changes or problems encountered during plan implementation, execution, or testing.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.06.05.d}}A.03.06.05.d:&#039;&#039;&#039; the incident response plan is protected from unauthorized disclosure.&lt;br /&gt;
&lt;br /&gt;
==== ASSESSMENT METHODS AND OBJECTS ====&lt;br /&gt;
&lt;br /&gt;
===== Examine =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: incident response policy; procedures addressing incident response planning; incident response plan; system security plan; records of incident response plan reviews and approvals; other relevant documents or records&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
===== Interview =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: personnel with incident response planning responsibilities; personnel with information security responsibilities&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
===== Test =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: incident response plan and related processes&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
==== REFERENCES ====&lt;br /&gt;
&lt;br /&gt;
Source Assessment Procedure: [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_A_5_1_1/home?element=IR-08 IR-08]&lt;br /&gt;
&lt;br /&gt;
{{anchor|d30e4586-Head2}}{{anchor|sec-sec_3.7}}== 3.7 [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=MA Maintenance] ==&lt;br /&gt;
&lt;br /&gt;
{{anchor|d30e4591-Head3}}{{anchor|sec-sec_03.07.01}}=== 03.07.01 Withdrawn ===&lt;br /&gt;
&lt;br /&gt;
Recategorized as NCO.&lt;br /&gt;
&lt;br /&gt;
{{anchor|d30e4598-Head3}}{{anchor|sec-sec_03.07.02}}=== 03.07.02 Withdrawn ===&lt;br /&gt;
&lt;br /&gt;
Incorporated into [[#sec-sec_03.07.04|03.07.04]] and [[#sec-sec_03.07.06|03.07.06]].&lt;br /&gt;
&lt;br /&gt;
{{anchor|d30e4611-Head3}}{{anchor|sec-sec_03.07.03}}=== 03.07.03 Withdrawn ===&lt;br /&gt;
&lt;br /&gt;
Incorporated into [[#sec-sec_03.08.03|03.08.03]].&lt;br /&gt;
&lt;br /&gt;
{{anchor|d30e4621-Head3}}{{anchor|sec-sec_03.07.04}}=== 03.07.04 Maintenance Tools ===&lt;br /&gt;
&lt;br /&gt;
==== ASSESSMENT OBJECTIVE ====&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Determine if:&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.07.04.a[01]}}A.03.07.04.a&amp;amp;#91;01&amp;amp;#93;:&#039;&#039;&#039; the use of system maintenance tools is approved.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.07.04.a[02]}}A.03.07.04.a&amp;amp;#91;02&amp;amp;#93;:&#039;&#039;&#039; the use of system maintenance tools is controlled.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.07.04.a[03]}}A.03.07.04.a&amp;amp;#91;03&amp;amp;#93;:&#039;&#039;&#039; the use of system maintenance tools is monitored.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.07.04.b}}A.03.07.04.b:&#039;&#039;&#039; media with diagnostic and test programs are checked for malicious code before the media are used in the system.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.07.04.c}}A.03.07.04.c:&#039;&#039;&#039; the removal of system maintenance equipment containing CUI is prevented by verifying that there is no CUI on the equipment, sanitizing or destroying the equipment, or retaining the equipment within the facility.&lt;br /&gt;
&lt;br /&gt;
==== ASSESSMENT METHODS AND OBJECTS ====&lt;br /&gt;
&lt;br /&gt;
===== Examine =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: maintenance policy and procedures; procedures for system maintenance tools; system maintenance tools; maintenance tool inspection records; equipment sanitization records; media sanitization records; system security plan; other relevant documents or records&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
===== Interview =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: personnel with system maintenance responsibilities; personnel responsible for media sanitization; personnel with information security responsibilities&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
===== Test =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: processes for approving, controlling, and monitoring maintenance tools; mechanisms for supporting or implementing the approval, control, or monitoring of maintenance tools; processes for preventing the unauthorized removal of information; processes for inspecting media for malicious code; mechanisms for supporting media sanitization or the destruction of equipment; mechanisms for supporting the verification of media sanitization; processes for inspecting maintenance tools; mechanisms for supporting or implementing the inspection of maintenance tools; mechanisms for supporting or implementing the inspection of media used for maintenance&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
==== REFERENCES ====&lt;br /&gt;
&lt;br /&gt;
Source Assessment Procedures: [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_A_5_1_1/home?element=MA-03 MA-03], [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_A_5_1_1/home?element=MA-03 MA-03(01)], [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_A_5_1_1/home?element=MA-03 MA-03(02)], [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_A_5_1_1/home?element=MA-03 MA-03(03)]&lt;br /&gt;
&lt;br /&gt;
{{anchor|d30e4696-Head3}}{{anchor|sec-sec_03.07.05}}=== 03.07.05 Nonlocal Maintenance ===&lt;br /&gt;
&lt;br /&gt;
==== ASSESSMENT OBJECTIVE ====&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Determine if:&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.07.05.a[01]}}A.03.07.05.a&amp;amp;#91;01&amp;amp;#93;:&#039;&#039;&#039; nonlocal maintenance and diagnostic activities are approved.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.07.05.a[02]}}A.03.07.05.a&amp;amp;#91;02&amp;amp;#93;:&#039;&#039;&#039; nonlocal maintenance and diagnostic activities are monitored.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.07.05.b[01]}}A.03.07.05.b&amp;amp;#91;01&amp;amp;#93;:&#039;&#039;&#039; multi-factor authentication is implemented in the establishment of nonlocal maintenance and diagnostic sessions.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.07.05.b[02]}}A.03.07.05.b&amp;amp;#91;02&amp;amp;#93;:&#039;&#039;&#039; replay resistance is implemented in the establishment of nonlocal maintenance and diagnostic sessions.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.07.05.c[01]}}A.03.07.05.c&amp;amp;#91;01&amp;amp;#93;:&#039;&#039;&#039; session connections are terminated when nonlocal maintenance is completed.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.07.05.c[02]}}A.03.07.05.c&amp;amp;#91;02&amp;amp;#93;:&#039;&#039;&#039; network connections are terminated when nonlocal maintenance is completed.&lt;br /&gt;
&lt;br /&gt;
==== ASSESSMENT METHODS AND OBJECTS ====&lt;br /&gt;
&lt;br /&gt;
===== Examine =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: maintenance policy and procedures; remote access policy and procedures; procedures for nonlocal system maintenance; records of remote access; maintenance records; diagnostic records; system design documentation; system configuration settings; system security plan; other relevant documents or records&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
===== Interview =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: personnel with system maintenance responsibilities; personnel with information security responsibilities; system administrators&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
===== Test =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: processes for managing nonlocal maintenance; mechanisms for implementing, supporting, or managing nonlocal maintenance; mechanisms for implementing multi-factor authentication and replay resistance; mechanisms for terminating nonlocal maintenance sessions and network connections&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
==== REFERENCES ====&lt;br /&gt;
&lt;br /&gt;
Source Assessment Procedure: [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_A_5_1_1/home?element=MA-04 MA-04]&lt;br /&gt;
&lt;br /&gt;
{{anchor|d30e4764-Head3}}{{anchor|sec-sec_03.07.06}}=== 03.07.06 Maintenance Personnel ===&lt;br /&gt;
&lt;br /&gt;
==== ASSESSMENT OBJECTIVE ====&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Determine if:&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.07.06.a}}A.03.07.06.a:&#039;&#039;&#039; a process for maintenance personnel authorization is established.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.07.06.b}}A.03.07.06.b:&#039;&#039;&#039; a list of authorized maintenance organizations or personnel is maintained.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.07.06.c}}A.03.07.06.c:&#039;&#039;&#039; non-escorted personnel who perform maintenance on the system possess the required access authorizations.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.07.06.d[01]}}A.03.07.06.d&amp;amp;#91;01&amp;amp;#93;:&#039;&#039;&#039; organizational personnel with required access authorizations are designated to supervise the maintenance activities of personnel who do not possess the required access authorizations.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.07.06.d[02]}}A.03.07.06.d&amp;amp;#91;02&amp;amp;#93;:&#039;&#039;&#039; organizational personnel with required technical competence are designated to supervise the maintenance activities of personnel who do not possess the required access authorizations.&lt;br /&gt;
&lt;br /&gt;
==== ASSESSMENT METHODS AND OBJECTS ====&lt;br /&gt;
&lt;br /&gt;
===== Examine =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: maintenance policy and procedures; service provider contracts; service-level agreements; list of authorized personnel; maintenance records; access control records; system security plan; other relevant documents or records&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
===== Interview =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: personnel with system maintenance responsibilities; personnel with information security responsibilities&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
===== Test =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: processes for authorizing and managing maintenance personnel; mechanisms for supporting or implementing the authorization of maintenance personnel&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
==== REFERENCES ====&lt;br /&gt;
&lt;br /&gt;
Source Assessment Procedure: [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_A_5_1_1/home?element=MA-05 MA-05]&lt;br /&gt;
&lt;br /&gt;
{{anchor|d30e4826-Head2}}{{anchor|sec-sec_3.8}}== 3.8 [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=MP Media Protection] ==&lt;br /&gt;
&lt;br /&gt;
{{anchor|d30e4831-Head3}}{{anchor|sec-sec_03.08.01}}=== 03.08.01 Media Storage ===&lt;br /&gt;
&lt;br /&gt;
==== ASSESSMENT OBJECTIVE ====&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Determine if:&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;A.03.08.01&amp;amp;#91;01&amp;amp;#93;:&#039;&#039;&#039; system media that contain CUI are physically controlled.&lt;br /&gt;
* &#039;&#039;&#039;A.03.08.01&amp;amp;#91;02&amp;amp;#93;:&#039;&#039;&#039; system media that contain CUI are securely stored.&lt;br /&gt;
&lt;br /&gt;
==== ASSESSMENT METHODS AND OBJECTS ====&lt;br /&gt;
&lt;br /&gt;
===== Examine =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: physical protection policy and procedures; media protection policy and procedures; procedures for media storage; access control policy and procedures; system media; system security plan; other relevant documents or records&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
===== Interview =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: personnel with system media protection and storage responsibilities; personnel with information security responsibilities&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
===== Test =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: processes for storing information media; mechanisms for supporting or implementing secure media storage/media protection&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
==== REFERENCES ====&lt;br /&gt;
&lt;br /&gt;
Source Assessment Procedure: [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_A_5_1_1/home?element=MP-04 MP-04]&lt;br /&gt;
&lt;br /&gt;
{{anchor|d30e4877-Head3}}{{anchor|sec-sec_03.08.02}}=== 03.08.02 Media Access ===&lt;br /&gt;
&lt;br /&gt;
==== ASSESSMENT OBJECTIVE ====&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Determine if:&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;A.03.08.02:&#039;&#039;&#039; access to CUI on system media is restricted to authorized personnel or roles.&lt;br /&gt;
&lt;br /&gt;
==== ASSESSMENT METHODS AND OBJECTS ====&lt;br /&gt;
&lt;br /&gt;
===== Examine =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: physical protection policy and procedures; media protection policy and procedures; procedures for media access restrictions; access control policy and procedures; media storage facilities; access control records; system security plan; other relevant documents or records&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
===== Interview =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: personnel with system media protection responsibilities; personnel with information security responsibilities; system administrators&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
===== Test =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: processes for restricting information on media; mechanisms for supporting or implementing media access restrictions&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
==== REFERENCES ====&lt;br /&gt;
&lt;br /&gt;
Source Assessment Procedure: [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_A_5_1_1/home?element=MP-02 MP-02]&lt;br /&gt;
&lt;br /&gt;
{{anchor|d30e4918-Head3}}{{anchor|sec-sec_03.08.03}}=== 03.08.03 Media Sanitization ===&lt;br /&gt;
&lt;br /&gt;
==== ASSESSMENT OBJECTIVE ====&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Determine if:&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;A.03.08.03:&#039;&#039;&#039; system media that contain CUI are sanitized prior to disposal, release out of organizational control, or release for reuse.&lt;br /&gt;
&lt;br /&gt;
==== ASSESSMENT METHODS AND OBJECTS ====&lt;br /&gt;
&lt;br /&gt;
===== Examine =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: media protection policy and procedures; procedures for media sanitization and disposal; applicable standards and policies that address media sanitization policy; system audit records; media sanitization records; system design documentation; system configuration settings; records retention and disposition policy; records retention and disposition procedures; system security plan; other relevant documents or records&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
===== Interview =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: personnel with media sanitization responsibilities; personnel with records retention and disposition responsibilities; personnel with information security responsibilities; system administrators&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
===== Test =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: processes for media sanitization; mechanisms for supporting or implementing media sanitization&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
==== REFERENCES ====&lt;br /&gt;
&lt;br /&gt;
Source Assessment Procedure: [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_A_5_1_1/home?element=MP-06 MP-06]&lt;br /&gt;
&lt;br /&gt;
{{anchor|d30e4959-Head3}}{{anchor|sec-sec_03.08.04}}=== 03.08.04 Media Marking ===&lt;br /&gt;
&lt;br /&gt;
==== ASSESSMENT OBJECTIVE ====&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Determine if:&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;A.03.08.04&amp;amp;#91;01&amp;amp;#93;:&#039;&#039;&#039; system media that contain CUI are marked to indicate distribution limitations.&lt;br /&gt;
* &#039;&#039;&#039;A.03.08.04&amp;amp;#91;02&amp;amp;#93;:&#039;&#039;&#039; system media that contain CUI are marked to indicate handling caveats.&lt;br /&gt;
* &#039;&#039;&#039;A.03.08.04&amp;amp;#91;03&amp;amp;#93;:&#039;&#039;&#039; system media that contain CUI are marked to indicate applicable CUI markings.&lt;br /&gt;
&lt;br /&gt;
==== ASSESSMENT METHODS AND OBJECTS ====&lt;br /&gt;
&lt;br /&gt;
===== Examine =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: physical protection policy and procedures; media protection policy and procedures; procedures for media marking; list of system media marking security attributes; system security plan; other relevant documents or records&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
===== Interview =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: personnel with system media protection and marking responsibilities; personnel with information security responsibilities&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
===== Test =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: processes for marking information media; mechanisms for supporting or implementing media marking&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
==== REFERENCES ====&lt;br /&gt;
&lt;br /&gt;
Source Assessment Procedure: [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_A_5_1_1/home?element=MP-03 MP-03]&lt;br /&gt;
&lt;br /&gt;
{{anchor|d30e5008-Head3}}{{anchor|sec-sec_03.08.05}}=== 03.08.05 Media Transport ===&lt;br /&gt;
&lt;br /&gt;
==== ASSESSMENT OBJECTIVE ====&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Determine if:&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.08.05.a[01]}}A.03.08.05.a&amp;amp;#91;01&amp;amp;#93;:&#039;&#039;&#039; system media that contain CUI are protected during transport outside of controlled areas.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.08.05.a[02]}}A.03.08.05.a&amp;amp;#91;02&amp;amp;#93;:&#039;&#039;&#039; system media that contain CUI are controlled during transport outside of controlled areas.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.08.05.b}}A.03.08.05.b:&#039;&#039;&#039; accountability for system media that contain CUI is maintained during transport outside of controlled areas.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.08.05.c}}A.03.08.05.c:&#039;&#039;&#039; activities associated with the transport of system media that contain CUI are documented.&lt;br /&gt;
&lt;br /&gt;
==== ASSESSMENT METHODS AND OBJECTS ====&lt;br /&gt;
&lt;br /&gt;
===== Examine =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: physical protection policy and procedures; media protection policy and procedures; procedures for media storage; access control policy and procedures; authorized personnel list; system media; designated controlled areas; system and communications protection policy and procedures; cryptographic mechanisms and configuration documentation; procedures for the protection of information at rest; system design documentation; system configuration settings; list of information at rest requiring confidentiality protections; system audit records; system security plan; other relevant documents or records&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
===== Interview =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: personnel with system media protection and storage responsibilities; personnel with information security responsibilities; system developers; system administrators&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
===== Test =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: processes for storing information media; mechanisms for supporting or implementing media storage/media protection; mechanisms for supporting or implementing confidentiality protections for information at rest&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
==== REFERENCES ====&lt;br /&gt;
&lt;br /&gt;
Source Assessment Procedures: [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_A_5_1_1/home?element=MP-05 MP-05], [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_A_5_1_1/home?element=SC-28 SC-28]&lt;br /&gt;
&lt;br /&gt;
{{anchor|d30e5070-Head3}}{{anchor|sec-sec_03.08.06}}=== 03.08.06 Withdrawn ===&lt;br /&gt;
&lt;br /&gt;
Addressed by [[#sec-sec_03.13.08|03.13.08]].&lt;br /&gt;
&lt;br /&gt;
{{anchor|d30e5080-Head3}}{{anchor|sec-sec_03.08.07}}=== 03.08.07 Media Use ===&lt;br /&gt;
&lt;br /&gt;
==== ASSESSMENT OBJECTIVE ====&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Determine if:&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.08.07.ODP[01]}}A.03.08.07.ODP&amp;amp;#91;01&amp;amp;#93;: &#039;&#039;&#039;&amp;lt;nowiki/&amp;gt;&#039;&#039;&#039;&#039;&#039;types of system media with usage restrictions or that are prohibited from use are defined&#039;&#039;&#039;&#039;&#039;&amp;lt;nowiki/&amp;gt;&#039;&#039;&#039;.&#039;&#039;&#039;&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.08.07.a}}A.03.08.07.a:&#039;&#039;&#039; the use of the following types of system media is restricted or prohibited: &#039;&#039;&#039;&#039;&#039;&amp;lt;A.03.08.07.ODP&amp;amp;#91;01&amp;amp;#93;: types of system media&amp;gt;&#039;&#039;&#039;&#039;&#039;.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.08.07.b}}A.03.08.07.b:&#039;&#039;&#039; the use of removable system media without an identifiable owner is prohibited.&lt;br /&gt;
&lt;br /&gt;
==== ASSESSMENT METHODS AND OBJECTS ====&lt;br /&gt;
&lt;br /&gt;
===== Examine =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: system media protection policy and procedures; system use policy; procedures for media usage restrictions; rules of behavior; system audit records; system design documentation; system configuration settings; system security plan; other relevant documents or records&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
===== Interview =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: personnel with system media use responsibilities; personnel with information security responsibilities; system administrators&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
===== Test =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: processes for media use; mechanisms for restricting or prohibiting the use of system media on systems or system components&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
==== REFERENCES ====&lt;br /&gt;
&lt;br /&gt;
Source Assessment Procedure: [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_A_5_1_1/home?element=MP-07 MP-07]&lt;br /&gt;
&lt;br /&gt;
{{anchor|d30e5139-Head3}}{{anchor|sec-sec_03.08.08}}=== 03.08.08 Withdrawn ===&lt;br /&gt;
&lt;br /&gt;
Incorporated into [[#sec-sec_03.08.07|03.08.07]].&lt;br /&gt;
&lt;br /&gt;
{{anchor|d30e5149-Head3}}{{anchor|sec-sec_03.08.09}}=== 03.08.09 System Backup – Cryptographic Protection ===&lt;br /&gt;
&lt;br /&gt;
==== ASSESSMENT OBJECTIVE ====&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Determine if:&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.08.09.a}}A.03.08.09.a:&#039;&#039;&#039; the confidentiality of backup information is protected.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.08.09.b}}A.03.08.09.b:&#039;&#039;&#039; cryptographic mechanisms are implemented to prevent the unauthorized disclosure of CUI at backup storage locations.&lt;br /&gt;
&lt;br /&gt;
==== ASSESSMENT METHODS AND OBJECTS ====&lt;br /&gt;
&lt;br /&gt;
===== Examine =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: contingency planning policy and procedures; procedures for system backup; contingency plan; system design documentation; system configuration settings; system security plan; other relevant documents or records&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
===== Interview =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: personnel with system backup responsibilities; personnel with information security responsibilities&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
===== Test =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: mechanisms for supporting or implementing the cryptographic protection of backup information&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
==== REFERENCES ====&lt;br /&gt;
&lt;br /&gt;
Source Assessment Procedures: [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_A_5_1_1/home?element=CP-09 CP-09], [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_A_5_1_1/home?element=CP-09 CP-09(08)]&lt;br /&gt;
&lt;br /&gt;
{{anchor|d30e5201-Head2}}{{anchor|sec-sec_3.9}}== 3.9 [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=PS Personnel Security] ==&lt;br /&gt;
&lt;br /&gt;
{{anchor|d30e5206-Head3}}{{anchor|sec-sec_03.09.01}}=== 03.09.01 Personnel Screening ===&lt;br /&gt;
&lt;br /&gt;
==== ASSESSMENT OBJECTIVE ====&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Determine if:&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.09.01.ODP[01]}}A.03.09.01.ODP&amp;amp;#91;01&amp;amp;#93;: &#039;&#039;&#039;&amp;lt;nowiki/&amp;gt;&#039;&#039;&#039;&#039;&#039;conditions that require the rescreening of individuals are defined&#039;&#039;&#039;&#039;&#039;&amp;lt;nowiki/&amp;gt;&#039;&#039;&#039;.&#039;&#039;&#039;&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.09.01.a}}A.03.09.01.a:&#039;&#039;&#039; individuals are screened prior to authorizing access to the system.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.09.01.b}}A.03.09.01.b:&#039;&#039;&#039; individuals are rescreened in accordance with the following conditions: &#039;&#039;&#039;&#039;&#039;&amp;lt;A.03.09.01.ODP&amp;amp;#91;01&amp;amp;#93;: conditions&amp;gt;&#039;&#039;&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
==== ASSESSMENT METHODS AND OBJECTS ====&lt;br /&gt;
&lt;br /&gt;
===== Examine =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: personnel security policy and procedures; procedures for personnel screening and rescreening; records of screened personnel; system security plan; other relevant documents or records&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
===== Interview =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: personnel with personnel security responsibilities; personnel with information security responsibilities&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
===== Test =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: processes for personnel screening and rescreening&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
==== REFERENCES ====&lt;br /&gt;
&lt;br /&gt;
Source Assessment Procedure: [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_A_5_1_1/home?element=PS-03 PS-03]&lt;br /&gt;
&lt;br /&gt;
{{anchor|d30e5265-Head3}}{{anchor|sec-sec_03.09.02}}=== 03.09.02 Personnel Termination and Transfer ===&lt;br /&gt;
&lt;br /&gt;
==== ASSESSMENT OBJECTIVE ====&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Determine if:&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.09.02.ODP[01]}}A.03.09.02.ODP&amp;amp;#91;01&amp;amp;#93;: &#039;&#039;&#039;&amp;lt;nowiki/&amp;gt;&#039;&#039;&#039;&#039;&#039;the time period within which to disable system access is defined&#039;&#039;&#039;&#039;&#039;&amp;lt;nowiki/&amp;gt;&#039;&#039;&#039;.&#039;&#039;&#039;&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.09.02.a.01}}A.03.09.02.a.01:&#039;&#039;&#039; upon termination of individual employment, system access is disabled within &#039;&#039;&#039;&#039;&#039;&amp;lt;A.03.09.02.ODP&amp;amp;#91;01&amp;amp;#93;: time period&amp;gt;&#039;&#039;&#039;&#039;&#039;.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.09.02.a.02[01]}}A.03.09.02.a.02&amp;amp;#91;01&amp;amp;#93;:&#039;&#039;&#039; upon termination of individual employment, authenticators associated with the individual are terminated or revoked.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.09.02.a.02[02]}}A.03.09.02.a.02&amp;amp;#91;02&amp;amp;#93;:&#039;&#039;&#039; upon termination of individual employment, credentials associated with the individual are terminated or revoked.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.09.02.a.03}}A.03.09.02.a.03:&#039;&#039;&#039; upon termination of individual employment, security-related system property is retrieved.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.09.02.b.01[01]}}A.03.09.02.b.01&amp;amp;#91;01&amp;amp;#93;:&#039;&#039;&#039; upon individual reassignment or transfer to other positions in the organization, the ongoing operational need for current logical and physical access authorizations to the system and facility is reviewed.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.09.02.b.01[02]}}A.03.09.02.b.01&amp;amp;#91;02&amp;amp;#93;:&#039;&#039;&#039; upon individual reassignment or transfer to other positions in the organization, the ongoing operational need for current logical and physical access authorizations to the system and facility is confirmed.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.09.02.b.02}}A.03.09.02.b.02:&#039;&#039;&#039; upon individual reassignment or transfer to other positions in the organization, access authorization is modified to correspond with any changes in operational need.&lt;br /&gt;
&lt;br /&gt;
==== ASSESSMENT METHODS AND OBJECTS ====&lt;br /&gt;
&lt;br /&gt;
===== Examine =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: personnel security policy and procedures; procedures for personnel termination; records of personnel transfer actions; procedures for personnel transfer; list of system and facility access authorizations; records of personnel termination actions; records of terminated or revoked authenticators or credentials; list of system accounts; records of exit interviews; system security plan; other relevant documents or records&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
===== Interview =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: personnel with personnel security responsibilities; personnel with account management responsibilities; personnel with information security responsibilities; system administrators&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
===== Test =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: processes for personnel termination; processes for personnel transfer; mechanisms for supporting or implementing personnel transfer notifications; mechanisms for supporting or implementing personnel termination notifications; mechanisms for disabling system access and revoking authenticators&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
==== REFERENCES ====&lt;br /&gt;
&lt;br /&gt;
Source Assessment Procedures: [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_A_5_1_1/home?element=PS-04 PS-04], [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_A_5_1_1/home?element=PS-05 PS-05]&lt;br /&gt;
&lt;br /&gt;
{{anchor|d30e5354-Head2}}{{anchor|sec-sec_3.10}}== 3.10 [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=PE Physical Protection] ==&lt;br /&gt;
&lt;br /&gt;
{{anchor|d30e5359-Head3}}{{anchor|sec-sec_03.10.01}}=== 03.10.01 Physical Access Authorizations ===&lt;br /&gt;
&lt;br /&gt;
==== ASSESSMENT OBJECTIVE ====&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Determine if:&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.10.01.ODP[01]}}A.03.10.01.ODP&amp;amp;#91;01&amp;amp;#93;: &#039;&#039;&#039;&amp;lt;nowiki/&amp;gt;&#039;&#039;&#039;&#039;&#039;the frequency at which to review the access list detailing authorized facility access by individuals is defined.&#039;&#039;&#039;&#039;&#039;&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.10.01.a[01]}}A.03.10.01.a&amp;amp;#91;01&amp;amp;#93;:&#039;&#039;&#039; a list of individuals with authorized access to the facility where the system resides is developed.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.10.01.a[02]}}A.03.10.01.a&amp;amp;#91;02&amp;amp;#93;:&#039;&#039;&#039; a list of individuals with authorized access to the facility where the system resides is approved.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.10.01.a[03]}}A.03.10.01.a&amp;amp;#91;03&amp;amp;#93;:&#039;&#039;&#039; a list of individuals with authorized access to the facility where the system resides is maintained.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.10.01.b}}A.03.10.01.b:&#039;&#039;&#039; authorization credentials for facility access are issued.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.10.01.c}}A.03.10.01.c:&#039;&#039;&#039; the facility access list is reviewed &#039;&#039;&#039;&#039;&#039;&amp;lt;A.03.10.01.ODP&amp;amp;#91;01&amp;amp;#93;: frequency&amp;gt;&#039;&#039;&#039;&#039;&#039;.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.10.01.d}}A.03.10.01.d:&#039;&#039;&#039; individuals from the facility access list are removed when access is no longer required.&lt;br /&gt;
&lt;br /&gt;
==== ASSESSMENT METHODS AND OBJECTS ====&lt;br /&gt;
&lt;br /&gt;
===== Examine =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: physical protection policy and procedures; procedures for physical access authorizations; authorized personnel access list; physical access list reviews; physical access termination records; authorization credentials; system security plan; other relevant documents or records&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
===== Interview =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: personnel with physical access authorization responsibilities; personnel with physical access to the facility where the system resides; personnel with information security responsibilities&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
===== Test =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: processes for physical access authorizations; mechanisms for supporting or implementing physical access authorizations&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
==== REFERENCES ====&lt;br /&gt;
&lt;br /&gt;
Source Assessment Procedure: [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_A_5_1_1/home?element=PE-02 PE-02]&lt;br /&gt;
&lt;br /&gt;
{{anchor|d30e5437-Head3}}{{anchor|sec-sec_03.10.02}}=== 03.10.02 Monitoring Physical Access ===&lt;br /&gt;
&lt;br /&gt;
==== ASSESSMENT OBJECTIVE ====&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Determine if:&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.10.02.ODP[01]}}A.03.10.02.ODP&amp;amp;#91;01&amp;amp;#93;: &#039;&#039;&#039;&amp;lt;nowiki/&amp;gt;&#039;&#039;&#039;&#039;&#039;the frequency at which to review physical access logs is defined.&#039;&#039;&#039;&#039;&#039;&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.10.02.ODP[02]}}A.03.10.02.ODP&amp;amp;#91;02&amp;amp;#93;: &#039;&#039;&#039;&amp;lt;nowiki/&amp;gt;&#039;&#039;&#039;&#039;&#039;events or potential indications of events requiring physical access logs to be reviewed are defined.&#039;&#039;&#039;&#039;&#039;&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.10.02.a[01]}}A.03.10.02.a&amp;amp;#91;01&amp;amp;#93;:&#039;&#039;&#039; physical access to the facility where the system resides is monitored to detect physical security incidents.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.10.02.a[02]}}A.03.10.02.a&amp;amp;#91;02&amp;amp;#93;:&#039;&#039;&#039; physical security incidents are responded to.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.10.02.b[01]}}A.03.10.02.b&amp;amp;#91;01&amp;amp;#93;:&#039;&#039;&#039; physical access logs are reviewed &#039;&#039;&#039;&#039;&#039;&amp;lt;A.03.10.02.ODP&amp;amp;#91;01&amp;amp;#93;: frequency&amp;gt;&#039;&#039;&#039;&#039;&#039;.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.10.02.b[02]}}A.03.10.02.b&amp;amp;#91;02&amp;amp;#93;:&#039;&#039;&#039; physical access logs are reviewed upon occurrence of &#039;&#039;&#039;&#039;&#039;&amp;lt;A.03.10.02.ODP&amp;amp;#91;02&amp;amp;#93;: events or potential indications of events&amp;gt;&#039;&#039;&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
==== ASSESSMENT METHODS AND OBJECTS ====&lt;br /&gt;
&lt;br /&gt;
===== Examine =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: physical protection policy and procedures; procedures for physical access monitoring; physical access logs or records; physical access monitoring records; physical access log reviews; system security plan; other relevant documents or records&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
===== Interview =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: personnel with physical access monitoring responsibilities; personnel with incident response responsibilities; personnel with information security responsibilities&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
===== Test =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: processes for monitoring physical access; mechanisms for supporting or implementing physical access monitoring; mechanisms for supporting or implementing the review of physical access logs&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
==== REFERENCES ====&lt;br /&gt;
&lt;br /&gt;
Source Assessment Procedure: [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_A_5_1_1/home?element=PE-06 PE-06]&lt;br /&gt;
&lt;br /&gt;
{{anchor|d30e5514-Head3}}{{anchor|sec-sec_03.10.03}}=== 03.10.03 Withdrawn ===&lt;br /&gt;
&lt;br /&gt;
Incorporated into [[#sec-sec_03.10.07|03.10.07]].&lt;br /&gt;
&lt;br /&gt;
{{anchor|d30e5525-Head3}}{{anchor|sec-sec_03.10.04}}=== 03.10.04 Withdrawn ===&lt;br /&gt;
&lt;br /&gt;
Incorporated into [[#sec-sec_03.10.07|03.10.07]].&lt;br /&gt;
&lt;br /&gt;
{{anchor|d30e5535-Head3}}{{anchor|sec-sec_03.10.05}}=== 03.10.05 Withdrawn ===&lt;br /&gt;
&lt;br /&gt;
Incorporated into [[#sec-sec_03.10.07|03.10.07]].&lt;br /&gt;
&lt;br /&gt;
{{anchor|d30e5545-Head3}}{{anchor|sec-sec_03.10.06}}=== 03.10.06 Alternate Work Site ===&lt;br /&gt;
&lt;br /&gt;
==== ASSESSMENT OBJECTIVE ====&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Determine if:&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.10.06.ODP[01]}}A.03.10.06.ODP&amp;amp;#91;01&amp;amp;#93;: &#039;&#039;&#039;&amp;lt;nowiki/&amp;gt;&#039;&#039;&#039;&#039;&#039;security requirements to be employed at alternate work sites are defined&#039;&#039;&#039;&#039;&#039;&amp;lt;nowiki/&amp;gt;&#039;&#039;&#039;.&#039;&#039;&#039;&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.10.06.a}}A.03.10.06.a:&#039;&#039;&#039; alternate work sites allowed for use by employees are determined.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.10.06.b}}A.03.10.06.b:&#039;&#039;&#039; the following security requirements are employed at alternate work sites: &#039;&#039;&#039;&#039;&#039;&amp;lt;A.03.10.06.ODP&amp;amp;#91;01&amp;amp;#93;: security requirements&amp;gt;&#039;&#039;&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
==== ASSESSMENT METHODS AND OBJECTS ====&lt;br /&gt;
&lt;br /&gt;
===== Examine =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: physical protection policy and procedures; procedures for alternate work sites for personnel; list of security requirements for alternate work sites; assessments of security requirements at alternate work sites; system security plan; other relevant documents or records&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
===== Interview =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: personnel approving the use of alternate work sites; personnel using alternate work sites; personnel assessing security requirements at alternate work sites; personnel with information security responsibilities&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
===== Test =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: processes for security at alternate work sites; mechanisms for supporting alternate work sites; security requirements employed at alternate work sites; means of communication between personnel at alternate work sites and security personnel&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
==== REFERENCES ====&lt;br /&gt;
&lt;br /&gt;
Source Assessment Procedure: [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_A_5_1_1/home?element=PE-17 PE-17]&lt;br /&gt;
&lt;br /&gt;
{{anchor|d30e5604-Head3}}{{anchor|sec-sec_03.10.07}}=== 03.10.07 Physical Access Control ===&lt;br /&gt;
&lt;br /&gt;
==== ASSESSMENT OBJECTIVE ====&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Determine if:&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.10.07.a.01}}A.03.10.07.a.01:&#039;&#039;&#039; physical access authorizations are enforced at entry and exit points to the facility where the system resides by verifying individual physical access authorizations before granting access.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.10.07.a.02}}A.03.10.07.a.02:&#039;&#039;&#039; physical access authorizations are enforced at entry and exit points to the facility where the system resides by controlling ingress and egress with physical access control systems, devices, or guards.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.10.07.b}}A.03.10.07.b:&#039;&#039;&#039; physical access audit logs for entry or exit points are maintained.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.10.07.c[01]}}A.03.10.07.c&amp;amp;#91;01&amp;amp;#93;:&#039;&#039;&#039; visitors are escorted.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.10.07.c[02]}}A.03.10.07.c&amp;amp;#91;02&amp;amp;#93;:&#039;&#039;&#039; visitor activity is controlled.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.10.07.d}}A.03.10.07.d:&#039;&#039;&#039; keys, combinations, and other physical access devices are secured.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.10.07.e}}A.03.10.07.e:&#039;&#039;&#039; physical access to output devices is controlled to prevent unauthorized individuals from obtaining access to CUI.&lt;br /&gt;
&lt;br /&gt;
==== ASSESSMENT METHODS AND OBJECTS ====&lt;br /&gt;
&lt;br /&gt;
===== Examine =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: physical protection policy and procedures; procedures for physical access control; physical access control logs or records; inventory records of physical access control devices; system entry and exit points; records of key and lock combination changes; storage locations for physical access control devices; physical access control devices; list of security safeguards controlling access to designated publicly accessible areas within facility; system security plan; other relevant documents or records&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
===== Interview =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: personnel with physical access control responsibilities; personnel with information security responsibilities&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
===== Test =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: processes for physical access control; mechanisms for supporting or implementing physical access control; physical access control devices&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
==== REFERENCES ====&lt;br /&gt;
&lt;br /&gt;
Source Assessment Procedure: [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=PE-03 PE-03], [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=PE-05 PE-05]&lt;br /&gt;
&lt;br /&gt;
{{anchor|d30e5681-Head3}}{{anchor|sec-sec_03.10.08}}=== 03.10.08 Access Control for Transmission ===&lt;br /&gt;
&lt;br /&gt;
==== ASSESSMENT OBJECTIVE ====&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Determine if:&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;A.03.10.08:&#039;&#039;&#039; physical access to system distribution and transmission lines within organizational facilities is controlled.&lt;br /&gt;
&lt;br /&gt;
==== ASSESSMENT METHODS AND OBJECTS ====&lt;br /&gt;
&lt;br /&gt;
===== Examine =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: physical protection policy and procedures; procedures for access control for transmission mediums; system design documentation; facility communications and wiring diagrams; list of physical security safeguards applied to system distribution and transmission lines; procedures for access control for display medium; facility layout of system components; list of output devices and associated outputs that require physical access controls; actual displays from system components; physical access control logs or records for areas containing output devices and related outputs; system security plan; other relevant documents or records&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
===== Interview =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: personnel with physical access control responsibilities; personnel with information security responsibilities&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
===== Test =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: processes for access control for distribution and transmission lines; mechanisms for supporting or implementing access control for distribution and transmission lines; processes for access control to output devices; mechanisms for supporting or implementing access control for output devices&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
==== REFERENCES ====&lt;br /&gt;
&lt;br /&gt;
Source Assessment Procedure: [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_A_5_1_1/home?element=PE-04 PE-04]&lt;br /&gt;
&lt;br /&gt;
{{anchor|d30e5722-Head2}}{{anchor|sec-sec_3.11}}== 3.11 [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=RA Risk Assessment] ==&lt;br /&gt;
&lt;br /&gt;
{{anchor|d30e5727-Head3}}{{anchor|sec-sec_03.11.01}}=== 03.11.01 Risk Assessment ===&lt;br /&gt;
&lt;br /&gt;
==== ASSESSMENT OBJECTIVE ====&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Determine if:&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.11.01.ODP[01]}}A.03.11.01.ODP&amp;amp;#91;01&amp;amp;#93;: &#039;&#039;&#039;&amp;lt;nowiki/&amp;gt;&#039;&#039;&#039;&#039;&#039;the frequency at which to update the risk assessment is defined.&#039;&#039;&#039;&#039;&#039;&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.11.01.a}}A.03.11.01.a:&#039;&#039;&#039; the risk (including supply chain risk) of unauthorized disclosure resulting from the processing, storage, or transmission of CUI is assessed.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.11.01.b}}A.03.11.01.b:&#039;&#039;&#039; risk assessments are updated &#039;&#039;&#039;&#039;&#039;&amp;lt;A.03.11.01.ODP&amp;amp;#91;01&amp;amp;#93;: frequency&amp;gt;&#039;&#039;&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
==== ASSESSMENT METHODS AND OBJECTS ====&lt;br /&gt;
&lt;br /&gt;
===== Examine =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: risk assessment policy and procedures; security planning policy and procedures; procedures for organizational assessments of risk; risk assessment; risk assessment results; risk assessment reviews; risk assessment updates; SCRM policy and procedures; inventory of critical systems, system components, and system services; procedures for organizational assessments of supply chain risk; acquisition policy; SCRM plan; system security plan; other relevant documents or records&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
===== Interview =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: personnel with risk assessment responsibilities; personnel with SCRM responsibilities; personnel with security responsibilities&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
===== Test =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: processes for organizational risk assessments; mechanisms for supporting or conducting, documenting, reviewing, disseminating, and updating risk assessments; mechanisms for supporting or conducting, documenting, reviewing, disseminating, and updating supply chain risk assessments&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
==== REFERENCES ====&lt;br /&gt;
&lt;br /&gt;
Source Assessment Procedures: [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_A_5_1_1/home?element=RA-03 RA-03], [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_A_5_1_1/home?element=RA-03 RA-03(01)], [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_A_5_1_1/home?element=SR-06 SR-06]&lt;br /&gt;
&lt;br /&gt;
{{anchor|d30e5793-Head3}}{{anchor|sec-sec_03.11.02}}=== 03.11.02 Vulnerability Monitoring and Scanning ===&lt;br /&gt;
&lt;br /&gt;
==== ASSESSMENT OBJECTIVE ====&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Determine if:&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.11.02.ODP[01]}}A.03.11.02.ODP&amp;amp;#91;01&amp;amp;#93;: &#039;&#039;&#039;&amp;lt;nowiki/&amp;gt;&#039;&#039;&#039;&#039;&#039;the frequency at which the system is monitored for vulnerabilities is defined.&#039;&#039;&#039;&#039;&#039;&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.11.02.ODP[02]}}A.03.11.02.ODP&amp;amp;#91;02&amp;amp;#93;: &#039;&#039;&#039;&amp;lt;nowiki/&amp;gt;&#039;&#039;&#039;&#039;&#039;the frequency at which the system is scanned for vulnerabilities is defined.&#039;&#039;&#039;&#039;&#039;&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.11.02.ODP[03]}}A.03.11.02.ODP&amp;amp;#91;03&amp;amp;#93;: &#039;&#039;&#039;&amp;lt;nowiki/&amp;gt;&#039;&#039;&#039;&#039;&#039;response times to remediate system vulnerabilities are defined&#039;&#039;&#039;&#039;&#039;&amp;lt;nowiki/&amp;gt;&#039;&#039;&#039;.&#039;&#039;&#039;&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.11.02.ODP[04]}}A.03.11.02.ODP&amp;amp;#91;04&amp;amp;#93;: &#039;&#039;&#039;&amp;lt;nowiki/&amp;gt;&#039;&#039;&#039;&#039;&#039;the frequency at which to update system vulnerabilities to be scanned is defined.&#039;&#039;&#039;&#039;&#039;&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.11.02.a[01]}}A.03.11.02.a&amp;amp;#91;01&amp;amp;#93;:&#039;&#039;&#039; the system is monitored for vulnerabilities &#039;&#039;&#039;&#039;&#039;&amp;lt;A.03.11.02.ODP&amp;amp;#91;01&amp;amp;#93;: frequency&amp;gt;&#039;&#039;&#039;&#039;&#039;.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.11.02.a[02]}}A.03.11.02.a&amp;amp;#91;02&amp;amp;#93;:&#039;&#039;&#039; the system is scanned for vulnerabilities &#039;&#039;&#039;&#039;&#039;&amp;lt;A.03.11.02.ODP&amp;amp;#91;02&amp;amp;#93;: frequency&amp;gt;&#039;&#039;&#039;&#039;&#039;.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.11.02.a[03]}}A.03.11.02.a&amp;amp;#91;03&amp;amp;#93;:&#039;&#039;&#039; the system is monitored for vulnerabilities when new vulnerabilities that affect the system are identified.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.11.02.a[04]}}A.03.11.02.a&amp;amp;#91;04&amp;amp;#93;:&#039;&#039;&#039; the system is scanned for vulnerabilities when new vulnerabilities that affect the system are identified.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.11.02.b}}A.03.11.02.b:&#039;&#039;&#039; system vulnerabilities are remediated within &#039;&#039;&#039;&#039;&#039;&amp;lt;A.03.11.02.ODP&amp;amp;#91;03&amp;amp;#93;: response times&amp;gt;&#039;&#039;&#039;&#039;&#039;.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.11.02.c[01]}}A.03.11.02.c&amp;amp;#91;01&amp;amp;#93;:&#039;&#039;&#039; system vulnerabilities to be scanned are updated &#039;&#039;&#039;&#039;&#039;&amp;lt;A.03.11.02.ODP&amp;amp;#91;04&amp;amp;#93;: frequency&amp;gt;&#039;&#039;&#039;&#039;&#039;.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.11.02.c[02]}}A.03.11.02.c&amp;amp;#91;02&amp;amp;#93;:&#039;&#039;&#039; system vulnerabilities to be scanned are updated when new vulnerabilities are identified and reported.&lt;br /&gt;
&lt;br /&gt;
==== ASSESSMENT METHODS AND OBJECTS ====&lt;br /&gt;
&lt;br /&gt;
===== Examine =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: risk assessment policy and procedures; procedures for vulnerability scanning; patch and vulnerability management records; vulnerability scanning tools and configuration documentation; vulnerability scanning results; risk assessment; risk assessment report; system security plan; other relevant documents or records&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
===== Interview =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: personnel with risk assessment and vulnerability scanning responsibilities; personnel with vulnerability scan analysis responsibilities; personnel with vulnerability remediation responsibilities; personnel with information security responsibilities; system administrators&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
===== Test =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: processes for vulnerability monitoring, scanning, analysis, and remediation; mechanisms for supporting or implementing vulnerability monitoring, scanning, analysis, and remediation&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
==== REFERENCES ====&lt;br /&gt;
&lt;br /&gt;
Source Assessment Procedures: [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_A_5_1_1/home?element=RA-05 RA-05], [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_A_5_1_1/home?element=RA-05 RA-05(02)]&lt;br /&gt;
&lt;br /&gt;
{{anchor|d30e5912-Head3}}{{anchor|sec-sec_03.11.03}}=== 03.11.03 Withdrawn ===&lt;br /&gt;
&lt;br /&gt;
Incorporated into [[#sec-sec_03.11.02|03.11.02]].&lt;br /&gt;
&lt;br /&gt;
{{anchor|d30e5922-Head3}}{{anchor|sec-sec_03.11.04}}=== 03.11.04 Risk Response ===&lt;br /&gt;
&lt;br /&gt;
==== ASSESSMENT OBJECTIVE ====&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Determine if:&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;A.03.11.04&amp;amp;#91;01&amp;amp;#93;:&#039;&#039;&#039; findings from security assessments are responded to.&lt;br /&gt;
* &#039;&#039;&#039;A.03.11.04&amp;amp;#91;02&amp;amp;#93;:&#039;&#039;&#039; findings from security monitoring are responded to.&lt;br /&gt;
* &#039;&#039;&#039;A.03.11.04&amp;amp;#91;03&amp;amp;#93;:&#039;&#039;&#039; findings from security audits are responded to.&lt;br /&gt;
&lt;br /&gt;
==== ASSESSMENT METHODS AND OBJECTS ====&lt;br /&gt;
&lt;br /&gt;
===== Examine =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: risk assessment policy; assessment reports; system audit records; event logs; system security plan; other relevant documents or records&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
===== Interview =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: personnel with assessment and auditing responsibilities; system administrators; personnel with security responsibilities&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
===== Test =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: processes for assessments and audits; mechanisms and tools supporting or implementing assessments and auditing&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
==== REFERENCES ====&lt;br /&gt;
&lt;br /&gt;
Source Assessment Procedure: [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_A_5_1_1/home?element=RA-07 RA-07]&lt;br /&gt;
&lt;br /&gt;
{{anchor|d30e5971-Head2}}{{anchor|sec-sec_3.12}}== 3.12 [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=CA Security Assessment and Monitoring] ==&lt;br /&gt;
&lt;br /&gt;
{{anchor|d30e5976-Head3}}{{anchor|sec-sec_03.12.01}}=== 03.12.01 Security Assessment ===&lt;br /&gt;
&lt;br /&gt;
==== ASSESSMENT OBJECTIVE ====&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Determine if:&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.12.01.ODP[01]}}A.03.12.01.ODP&amp;amp;#91;01&amp;amp;#93;: &#039;&#039;&#039;&amp;lt;nowiki/&amp;gt;&#039;&#039;&#039;&#039;&#039;the frequency at which to assess the security requirements for the system and its environment of operation is defined.&#039;&#039;&#039;&#039;&#039;&lt;br /&gt;
* &#039;&#039;&#039;A.03.12.01:&#039;&#039;&#039; the security requirements for the system and its environment of operation are assessed &#039;&#039;&#039;&#039;&#039;&amp;lt;A.03.12.01.ODP&amp;amp;#91;01&amp;amp;#93;: frequency&amp;gt;&#039;&#039;&#039;&#039;&#039; to determine if the requirements have been satisfied.&lt;br /&gt;
&lt;br /&gt;
==== ASSESSMENT METHODS AND OBJECTS ====&lt;br /&gt;
&lt;br /&gt;
===== Examine =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: security assessment and monitoring policy and procedures; procedures for security assessment planning; security assessment plan; security assessment report; system security plan; other relevant documents or records&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
===== Interview =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: personnel with security assessment responsibilities; personnel with information security responsibilities&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
===== Test =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: mechanisms for supporting security assessments, processes for security assessment plan development, or security assessment reporting&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
==== REFERENCES ====&lt;br /&gt;
&lt;br /&gt;
Source Assessment Procedure: [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_A_5_1_1/home?element=CA-02 CA-02]&lt;br /&gt;
&lt;br /&gt;
{{anchor|d30e6028-Head3}}{{anchor|sec-sec_03.12.02}}=== 03.12.02 Plan of Action and Milestones ===&lt;br /&gt;
&lt;br /&gt;
==== ASSESSMENT OBJECTIVE ====&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Determine if:&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.12.02.a.01}}A.03.12.02.a.01:&#039;&#039;&#039; a plan of action and milestones for the system is developed to document the planned remediation actions for correcting weaknesses or deficiencies noted during security assessments.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.12.02.a.02}}A.03.12.02.a.02:&#039;&#039;&#039; a plan of action and milestones for the system is developed to reduce or eliminate known system vulnerabilities.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.12.02.b.01}}A.03.12.02.b.01:&#039;&#039;&#039; the existing plan of action and milestones is updated based on the findings from security assessments.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.12.02.b.02}}A.03.12.02.b.02:&#039;&#039;&#039; the existing plan of action and milestones is updated based on the findings from audits or reviews.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.12.02.b.03}}A.03.12.02.b.03:&#039;&#039;&#039; the existing plan of action and milestones is updated based on the findings from continuous monitoring activities.&lt;br /&gt;
&lt;br /&gt;
==== ASSESSMENT METHODS AND OBJECTS ====&lt;br /&gt;
&lt;br /&gt;
===== Examine =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: security assessment and monitoring policy and procedures; procedures for plans of action and milestones; security assessment plan; security assessment report; security assessment evidence; plan of action and milestones; system security plan; other relevant documents or records&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
===== Interview =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: personnel with plans of action and milestones development and implementation responsibilities; personnel with information security responsibilities&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
===== Test =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: mechanisms for developing, implementing, and maintaining plans of action and milestones&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
==== REFERENCES ====&lt;br /&gt;
&lt;br /&gt;
Source Assessment Procedure: [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_A_5_1_1/home?element=CA-05 CA-05]&lt;br /&gt;
&lt;br /&gt;
{{anchor|d30e6090-Head3}}{{anchor|sec-sec_03.12.03}}=== 03.12.03 Continuous Monitoring ===&lt;br /&gt;
&lt;br /&gt;
==== ASSESSMENT OBJECTIVE ====&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Determine if:&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;A.03.12.03&amp;amp;#91;01&amp;amp;#93;:&#039;&#039;&#039; a system-level continuous monitoring strategy is developed.&lt;br /&gt;
* &#039;&#039;&#039;A.03.12.03&amp;amp;#91;02&amp;amp;#93;:&#039;&#039;&#039; a system-level continuous monitoring strategy is implemented.&lt;br /&gt;
* &#039;&#039;&#039;A.03.12.03&amp;amp;#91;03&amp;amp;#93;:&#039;&#039;&#039; ongoing monitoring is included in the continuous monitoring strategy.&lt;br /&gt;
* &#039;&#039;&#039;A.03.12.03&amp;amp;#91;04&amp;amp;#93;:&#039;&#039;&#039; security assessments are included in the continuous monitoring strategy.&lt;br /&gt;
&lt;br /&gt;
==== ASSESSMENT METHODS AND OBJECTS ====&lt;br /&gt;
&lt;br /&gt;
===== Examine =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: security assessment and monitoring policy and procedures; organizational continuous monitoring strategy; system-level continuous monitoring strategy; procedures for continuous monitoring of the system; procedures for configuration management; security assessment report; plan of action and milestones; system monitoring records; configuration management records; impact analyses; status reports; system security plan; other relevant documents or records&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
===== Interview =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: personnel with continuous monitoring responsibilities; personnel with information security responsibilities; system administrators&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
===== Test =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: mechanisms for implementing continuous monitoring; mechanisms for supporting response actions for assessment and monitoring results; mechanisms for supporting security status reporting&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
==== REFERENCES ====&lt;br /&gt;
&lt;br /&gt;
Source Assessment Procedure: [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_A_5_1_1/home?element=CA-07 CA-07]&lt;br /&gt;
&lt;br /&gt;
{{anchor|d30e6144-Head3}}{{anchor|sec-sec_03.12.04}}=== 03.12.04 Withdrawn ===&lt;br /&gt;
&lt;br /&gt;
Incorporated into [[#sec-sec_03.15.02|03.15.02]].&lt;br /&gt;
&lt;br /&gt;
{{anchor|d30e6154-Head3}}{{anchor|sec-sec_03.12.05}}=== 03.12.05 Information Exchange ===&lt;br /&gt;
&lt;br /&gt;
==== ASSESSMENT OBJECTIVE ====&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Determine if:&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.12.05.ODP[01]}}A.03.12.05.ODP&amp;amp;#91;01&amp;amp;#93;: &#039;&#039;&#039;&amp;lt;nowiki/&amp;gt;&#039;&#039;&#039;&#039;&#039;one or more of the following PARAMETER VALUES are selected: &amp;amp;#123;interconnection security agreements; information exchange security agreements; memoranda of understanding or agreement; service-level agreements; user agreements; non-disclosure agreements&#039;&#039;&#039;&#039;&#039;; &#039;&#039;&#039;&#039;&#039;other types of agreements&amp;amp;#125;&#039;&#039;&#039;&#039;&#039;.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.12.05.ODP[02]}}A.03.12.05.ODP&amp;amp;#91;02&amp;amp;#93;: &#039;&#039;&#039;&amp;lt;nowiki/&amp;gt;&#039;&#039;&#039;&#039;&#039;the frequency at which to review and update agreements is defined.&#039;&#039;&#039;&#039;&#039;&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.12.05.a[01]}}A.03.12.05.a&amp;amp;#91;01&amp;amp;#93;:&#039;&#039;&#039; the exchange of CUI between the system and other systems is approved using &#039;&#039;&#039;&#039;&#039;&amp;lt;A.03.12.05.ODP&amp;amp;#91;01&amp;amp;#93;: SELECTED PARAMETER VALUES&amp;gt;&#039;&#039;&#039;&#039;&#039;.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.12.05.a[02]}}A.03.12.05.a&amp;amp;#91;02&amp;amp;#93;:&#039;&#039;&#039; the exchange of CUI between the system and other systems is managed using &#039;&#039;&#039;&#039;&#039;&amp;lt;A.03.12.05.ODP&amp;amp;#91;01&amp;amp;#93;: SELECTED PARAMETER VALUES&amp;gt;&#039;&#039;&#039;&#039;&#039;.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.12.05.b[01]}}A.03.12.05.b&amp;amp;#91;01&amp;amp;#93;:&#039;&#039;&#039; interface characteristics for each system are documented as part of the exchange agreements.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.12.05.b[02]}}A.03.12.05.b&amp;amp;#91;02&amp;amp;#93;:&#039;&#039;&#039; security requirements for each system are documented as part of the exchange agreements.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.12.05.b[03]}}A.03.12.05.b&amp;amp;#91;03&amp;amp;#93;:&#039;&#039;&#039; responsibilities for each system are documented as part of the exchange agreements.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.12.05.c[01]}}A.03.12.05.c&amp;amp;#91;01&amp;amp;#93;:&#039;&#039;&#039; exchange agreements are reviewed &#039;&#039;&#039;&#039;&#039;&amp;lt;A.03.12.05.ODP&amp;amp;#91;02&amp;amp;#93;: frequency&amp;gt;&#039;&#039;&#039;&#039;&#039;.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.12.05.c[02]}}A.03.12.05.c&amp;amp;#91;02&amp;amp;#93;:&#039;&#039;&#039; exchange agreements are updated &#039;&#039;&#039;&#039;&#039;&amp;lt;A.03.12.05.ODP&amp;amp;#91;02&amp;amp;#93;: frequency&amp;gt;&#039;&#039;&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
==== ASSESSMENT METHODS AND OBJECTS ====&lt;br /&gt;
&lt;br /&gt;
===== Examine =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: access control policy and procedures; procedures for system connections; system and communications protection policy and procedures; system interconnection security agreements; information exchange security agreements; service-level agreements; memoranda of understanding or agreements; non-disclosure agreements; system design documentation; enterprise architecture; security architecture; system configuration settings; system security plan; other relevant documents or records&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
===== Interview =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: personnel with development, implementation, and approval responsibilities for system interconnection agreements; personnel who manage systems to which the exchange agreements apply; personnel with information security responsibilities&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
==== REFERENCES ====&lt;br /&gt;
&lt;br /&gt;
Source Assessment Procedure: [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_A_5_1_1/home?element=CA-03 CA-03]&lt;br /&gt;
&lt;br /&gt;
{{anchor|d30e6252-Head2}}{{anchor|sec-sec_3.13}}== 3.13 [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=SC System and Communications Protection] ==&lt;br /&gt;
&lt;br /&gt;
{{anchor|d30e6257-Head3}}{{anchor|sec-sec_03.13.01}}=== 03.13.01 Boundary Protection ===&lt;br /&gt;
&lt;br /&gt;
==== ASSESSMENT OBJECTIVE ====&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Determine if:&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.13.01.a[01]}}A.03.13.01.a&amp;amp;#91;01&amp;amp;#93;:&#039;&#039;&#039; communications at external managed interfaces to the system are monitored.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.13.01.a[02]}}A.03.13.01.a&amp;amp;#91;02&amp;amp;#93;:&#039;&#039;&#039; communications at external managed interfaces to the system are controlled.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.13.01.a[03]}}A.03.13.01.a&amp;amp;#91;03&amp;amp;#93;:&#039;&#039;&#039; communications at key internal managed interfaces within the system are monitored.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.13.01.a[04]}}A.03.13.01.a&amp;amp;#91;04&amp;amp;#93;:&#039;&#039;&#039; communications at key internal managed interfaces within the system are controlled.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.13.01.b}}A.03.13.01.b:&#039;&#039;&#039; subnetworks are implemented for publicly accessible system components that are physically or logically separated from internal networks.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.13.01.c}}A.03.13.01.c:&#039;&#039;&#039; external system connections are only made through managed interfaces that consist of boundary protection devices arranged in accordance with an organizational security architecture.&lt;br /&gt;
&lt;br /&gt;
==== ASSESSMENT METHODS AND OBJECTS ====&lt;br /&gt;
&lt;br /&gt;
===== Examine =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: system and communications protection policy and procedures; procedures for boundary protection; list of key internal boundaries within the system; boundary protection hardware and software; system configuration settings; security architecture; system audit records; system design documentation; system security plan; other relevant documents or records&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
===== Interview =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: personnel with boundary protection responsibilities; personnel with information security responsibilities; system developers; system administrators&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
===== Test =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: mechanisms for implementing boundary protection capabilities&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
==== REFERENCES ====&lt;br /&gt;
&lt;br /&gt;
Source Assessment Procedure: [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_A_5_1_1/home?element=SC-07 SC-07]&lt;br /&gt;
&lt;br /&gt;
{{anchor|d30e6324-Head3}}{{anchor|sec-sec_03.13.02}}=== 03.13.02 Withdrawn ===&lt;br /&gt;
&lt;br /&gt;
Recategorized as NCO.&lt;br /&gt;
&lt;br /&gt;
{{anchor|d30e6332-Head3}}{{anchor|sec-sec_03.13.03}}=== 03.13.03 Withdrawn ===&lt;br /&gt;
&lt;br /&gt;
Addressed by [[#sec-sec_03.01.01|03.01.01]], [[#sec-sec_03.01.02|03.01.02]], [[#sec-sec_03.01.03|03.01.03]], [[#sec-sec_03.01.04|03.01.04]], [[#sec-sec_03.01.05|03.01.05]], [[#sec-sec_03.01.06|03.01.06]], and [[#sec-sec_03.01.07|03.01.07]].&lt;br /&gt;
&lt;br /&gt;
{{anchor|d30e6361-Head3}}{{anchor|sec-sec_03.13.04}}=== 03.13.04 Information in Shared System Resources ===&lt;br /&gt;
&lt;br /&gt;
==== ASSESSMENT OBJECTIVE ====&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Determine if:&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;A.03.13.04&amp;amp;#91;01&amp;amp;#93;:&#039;&#039;&#039; unauthorized information transfer via shared system resources is prevented.&lt;br /&gt;
* &#039;&#039;&#039;A.03.13.04&amp;amp;#91;02&amp;amp;#93;:&#039;&#039;&#039; unintended information transfer via shared system resources is prevented.&lt;br /&gt;
&lt;br /&gt;
==== ASSESSMENT METHODS AND OBJECTS ====&lt;br /&gt;
&lt;br /&gt;
===== Examine =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: system and communications protection policy and procedures; procedures for information protection in shared system resources; system configuration settings; system audit records; system design documentation; system security plan; other relevant documents or records&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
===== Interview =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: personnel with information security responsibilities; system developers; system administrators&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
===== Test =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: mechanisms for preventing the unauthorized and unintended transfer of information via shared system resources&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
==== REFERENCES ====&lt;br /&gt;
&lt;br /&gt;
Source Assessment Procedure: [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_A_5_1_1/home?element=SC-04 SC-04]&lt;br /&gt;
&lt;br /&gt;
{{anchor|d30e6406-Head3}}{{anchor|sec-sec_03.13.05}}=== 03.13.05 Withdrawn ===&lt;br /&gt;
&lt;br /&gt;
Incorporated into [[#sec-sec_03.13.01|03.13.01]].&lt;br /&gt;
&lt;br /&gt;
{{anchor|d30e6416-Head3}}{{anchor|sec-sec_03.13.06}}=== 03.13.06 Network Communications – Deny by Default – Allow by Exception ===&lt;br /&gt;
&lt;br /&gt;
==== ASSESSMENT OBJECTIVE ====&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Determine if:&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;A.03.13.06&amp;amp;#91;01&amp;amp;#93;:&#039;&#039;&#039; network communications traffic is denied by default.&lt;br /&gt;
* &#039;&#039;&#039;A.03.13.06&amp;amp;#91;02&amp;amp;#93;:&#039;&#039;&#039; network communications traffic is allowed by exception.&lt;br /&gt;
&lt;br /&gt;
==== ASSESSMENT METHODS AND OBJECTS ====&lt;br /&gt;
&lt;br /&gt;
===== Examine =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: system and communications protection policy and procedures; procedures for boundary protection; system design documentation; system configuration settings; system audit records; system security plan; other relevant documents or records&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
===== Interview =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: personnel with boundary protection responsibilities; personnel with information security responsibilities; system developers; system administrators&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
===== Test =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: mechanisms for implementing traffic management at managed interfaces&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
==== REFERENCES ====&lt;br /&gt;
&lt;br /&gt;
Source Assessment Procedure: [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_A_5_1_1/home?element=SC-07 SC-07(05)]&lt;br /&gt;
&lt;br /&gt;
{{anchor|d30e6461-Head3}}{{anchor|sec-sec_03.13.07}}=== 03.13.07 Withdrawn ===&lt;br /&gt;
&lt;br /&gt;
Addressed by [[#sec-sec_03.01.12|03.01.12]], [[#sec-sec_03.04.02|03.04.02]] and [[#sec-sec_03.04.06|03.04.06]].&lt;br /&gt;
&lt;br /&gt;
{{anchor|d30e6478-Head3}}{{anchor|sec-sec_03.13.08}}=== 03.13.08 Transmission and Storage Confidentiality ===&lt;br /&gt;
&lt;br /&gt;
==== ASSESSMENT OBJECTIVE ====&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Determine if:&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;A.03.13.08&amp;amp;#91;01&amp;amp;#93;:&#039;&#039;&#039; cryptographic mechanisms are implemented to prevent the unauthorized disclosure of CUI during transmission.&lt;br /&gt;
* &#039;&#039;&#039;A.03.13.08&amp;amp;#91;02&amp;amp;#93;:&#039;&#039;&#039; cryptographic mechanisms are implemented to prevent the unauthorized disclosure of CUI while in storage.&lt;br /&gt;
&lt;br /&gt;
==== ASSESSMENT METHODS AND OBJECTS ====&lt;br /&gt;
&lt;br /&gt;
===== Examine =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: system and communications protection policy and procedures; procedures for transmission confidentiality; procedures for the protection of information at rest; system design documentation; system configuration settings; cryptographic mechanisms and associated configuration documentation; information in storage requiring confidentiality protection; system audit records; system security plan; other relevant documents or records&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
===== Interview =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: personnel with information security responsibilities; system developers; system administrators&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
===== Test =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: mechanisms for supporting or implementing transmission confidentiality; cryptographic mechanisms for supporting or implementing transmission confidentiality; mechanisms for supporting or implementing confidentiality protection for information in storage; cryptographic mechanisms for implementing confidentiality protections for information in storage&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
==== REFERENCES ====&lt;br /&gt;
&lt;br /&gt;
Source Assessment Procedures: [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_A_5_1_1/home?element=SC-08 SC-08], [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_A_5_1_1/home?element=SC-08 SC-08(01)], [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_A_5_1_1/home?element=SC-28 SC-28], [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_A_5_1_1/home?element=SC-28 SC-28(01)]&lt;br /&gt;
&lt;br /&gt;
{{anchor|d30e6535-Head3}}{{anchor|sec-sec_03.13.09}}=== 03.13.09 Network Disconnect ===&lt;br /&gt;
&lt;br /&gt;
==== ASSESSMENT OBJECTIVE ====&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Determine if:&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.13.09.ODP[01]}}A.03.13.09.ODP&amp;amp;#91;01&amp;amp;#93;: &#039;&#039;&#039;&amp;lt;nowiki/&amp;gt;&#039;&#039;&#039;&#039;&#039;the time period of inactivity after which the system terminates a network connection associated with a communications session is defined.&#039;&#039;&#039;&#039;&#039;&lt;br /&gt;
* &#039;&#039;&#039;A.03.13.09:&#039;&#039;&#039; the network connection associated with a communications session is terminated at the end of the session or after &#039;&#039;&#039;&#039;&#039;&amp;lt;A.03.13.09.ODP&amp;amp;#91;01&amp;amp;#93;: time period&amp;gt;&#039;&#039;&#039;&#039;&#039; of inactivity.&lt;br /&gt;
&lt;br /&gt;
==== ASSESSMENT METHODS AND OBJECTS ====&lt;br /&gt;
&lt;br /&gt;
===== Examine =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: system and communications protection policy and procedures; procedures for network disconnect; system design documentation; system configuration settings; system audit records; system security plan; other relevant documents or records&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
===== Interview =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: personnel with information security responsibilities; system developers; system administrators&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
===== Test =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: mechanisms for supporting or implementing a network disconnect capability&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
==== REFERENCES ====&lt;br /&gt;
&lt;br /&gt;
Source Assessment Procedure: [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_A_5_1_1/home?element=SC-10 SC-10]&lt;br /&gt;
&lt;br /&gt;
{{anchor|d30e6586-Head3}}{{anchor|sec-sec_03.13.10}}=== 03.13.10 Cryptographic Key Establishment and Management ===&lt;br /&gt;
&lt;br /&gt;
==== ASSESSMENT OBJECTIVE ====&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Determine if:&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.13.10.ODP[01]}}A.03.13.10.ODP&amp;amp;#91;01&amp;amp;#93;: &#039;&#039;&#039;&amp;lt;nowiki/&amp;gt;&#039;&#039;&#039;&#039;&#039;requirements for key generation, distribution, storage, access, and destruction are defined.&#039;&#039;&#039;&#039;&#039;&lt;br /&gt;
* &#039;&#039;&#039;A.03.13.10&amp;amp;#91;01&amp;amp;#93;:&#039;&#039;&#039; cryptographic keys are established in the system in accordance with the following key management requirements: &#039;&#039;&#039;&#039;&#039;&amp;lt;A.03.13.10.ODP&amp;amp;#91;01&amp;amp;#93;: requirements&amp;gt;&#039;&#039;&#039;&#039;&#039;.&lt;br /&gt;
* &#039;&#039;&#039;A.03.13.10&amp;amp;#91;02&amp;amp;#93;:&#039;&#039;&#039; cryptographic keys are managed in the system in accordance with the following key management requirements: &#039;&#039;&#039;&#039;&#039;&amp;lt;A.03.13.10.ODP&amp;amp;#91;01&amp;amp;#93;: requirements&amp;gt;&#039;&#039;&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
==== ASSESSMENT METHODS AND OBJECTS ====&lt;br /&gt;
&lt;br /&gt;
===== Examine =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: system and communications protection policy and procedures; procedures for cryptographic key establishment and management; system design documentation; system configuration settings; cryptographic mechanisms; system audit records; system security plan; other relevant documents or records&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
===== Interview =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: personnel with responsibilities for cryptographic key establishment or management; personnel with information security responsibilities; system administrators&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
===== Test =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: mechanisms for supporting or implementing cryptographic key establishment and management&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
==== REFERENCES ====&lt;br /&gt;
&lt;br /&gt;
Source Assessment Procedure: [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_A_5_1_1/home?element=SC-12 SC-12]&lt;br /&gt;
&lt;br /&gt;
{{anchor|d30e6645-Head3}}{{anchor|sec-sec_03.13.11}}=== 03.13.11 Cryptographic Protection ===&lt;br /&gt;
&lt;br /&gt;
==== ASSESSMENT OBJECTIVE ====&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Determine if:&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.13.11.ODP[01]}}A.03.13.11.ODP&amp;amp;#91;01&amp;amp;#93;: &#039;&#039;&#039;&amp;lt;nowiki/&amp;gt;&#039;&#039;&#039;&#039;&#039;the types of cryptography for protecting the confidentiality of CUI are defined&#039;&#039;&#039;&#039;&#039;&amp;lt;nowiki/&amp;gt;&#039;&#039;&#039;.&#039;&#039;&#039;&lt;br /&gt;
* &#039;&#039;&#039;A.03.13.11:&#039;&#039;&#039; the following types of cryptography are implemented to protect the confidentiality of CUI: &#039;&#039;&#039;&#039;&#039;&amp;lt;A.03.13.11.ODP&amp;amp;#91;01&amp;amp;#93;: types of cryptography&amp;gt;&#039;&#039;&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
==== ASSESSMENT METHODS AND OBJECTS ====&lt;br /&gt;
&lt;br /&gt;
===== Examine =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: system and communications protection policy and procedures; procedures for cryptographic protection; system design documentation; system configuration settings; cryptographic module validation certificates; list of FIPS-validated cryptographic modules; system audit records; system security plan; other relevant documents or records&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
===== Interview =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: personnel with responsibilities for cryptographic protection; personnel with information security responsibilities; system developers; system administrators&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
===== Test =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: mechanisms for supporting or implementing cryptographic protection&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
==== REFERENCES ====&lt;br /&gt;
&lt;br /&gt;
Source Assessment Procedure: [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_A_5_1_1/home?element=SC-13 SC-13]&lt;br /&gt;
&lt;br /&gt;
{{anchor|d30e6698-Head3}}{{anchor|sec-sec_03.13.12}}=== 03.13.12 Collaborative Computing Devices and Applications ===&lt;br /&gt;
&lt;br /&gt;
==== ASSESSMENT OBJECTIVE ====&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Determine if:&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.13.12.ODP[01]}}A.03.13.12.ODP&amp;amp;#91;01&amp;amp;#93;: &#039;&#039;&#039;&amp;lt;nowiki/&amp;gt;&#039;&#039;&#039;&#039;&#039;exceptions where remote activation is to be allowed are defined.&#039;&#039;&#039;&#039;&#039;&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.13.12.a}}A.03.13.12.a:&#039;&#039;&#039; the remote activation of collaborative computing devices and applications is prohibited with the following exceptions: &#039;&#039;&#039;&#039;&#039;&amp;lt;A.03.13.12.ODP&amp;amp;#91;01&amp;amp;#93;: exceptions&amp;gt;&#039;&#039;&#039;&#039;&#039;.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.13.12.b}}A.03.13.12.b:&#039;&#039;&#039; an explicit indication of use is provided to users who are physically present at the devices.&lt;br /&gt;
&lt;br /&gt;
==== ASSESSMENT METHODS AND OBJECTS ====&lt;br /&gt;
&lt;br /&gt;
===== Examine =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: system and communications protection policy and procedures; procedures for collaborative computing; access control policy and procedures; system configuration settings; system design documentation; system audit records; system security plan; other relevant documents or records&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
===== Interview =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: personnel with responsibilities for managing collaborative computing devices; personnel with information security responsibilities; system developers; system administrators&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
===== Test =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: mechanisms for supporting or implementing the management of remote activation of collaborative computing devices; mechanisms for providing an indication of use of collaborative computing devices&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
==== REFERENCES ====&lt;br /&gt;
&lt;br /&gt;
Source Assessment Procedure: [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_A_5_1_1/home?element=SC-15 SC-15]&lt;br /&gt;
&lt;br /&gt;
{{anchor|d30e6755-Head3}}{{anchor|sec-sec_03.13.13}}=== 03.13.13 Mobile Code ===&lt;br /&gt;
&lt;br /&gt;
==== ASSESSMENT OBJECTIVE ====&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Determine if:&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.13.13.a[01]}}A.03.13.13.a&amp;amp;#91;01&amp;amp;#93;:&#039;&#039;&#039; acceptable mobile code is defined.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.13.13.a[02]}}A.03.13.13.a&amp;amp;#91;02&amp;amp;#93;:&#039;&#039;&#039; acceptable mobile code technologies are defined.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.13.13.b[01]}}A.03.13.13.b&amp;amp;#91;01&amp;amp;#93;:&#039;&#039;&#039; the use of mobile code is authorized.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.13.13.b[02]}}A.03.13.13.b&amp;amp;#91;02&amp;amp;#93;:&#039;&#039;&#039; the use of mobile code is monitored.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.13.13.b[03]}}A.03.13.13.b&amp;amp;#91;03&amp;amp;#93;:&#039;&#039;&#039; the use of mobile code is controlled.&lt;br /&gt;
&lt;br /&gt;
==== ASSESSMENT METHODS AND OBJECTS ====&lt;br /&gt;
&lt;br /&gt;
===== Examine =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: system and communications protection policy and procedures; procedures for mobile code; mobile code implementation policy and procedures; list of acceptable mobile code and mobile code technologies; authorization records; system monitoring records; system audit records; system security plan; other relevant documents or records&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
===== Interview =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: personnel with responsibilities for managing mobile code; personnel with information security responsibilities; system administrators&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
===== Test =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: processes for authorizing, monitoring, and controlling mobile code; mechanisms for supporting or implementing the management of mobile code; mechanisms for supporting or implementing mobile code monitoring&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
==== REFERENCES ====&lt;br /&gt;
&lt;br /&gt;
Source Assessment Procedure: [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_A_5_1_1/home?element=SC-18 SC-18]&lt;br /&gt;
&lt;br /&gt;
{{anchor|d30e6818-Head3}}{{anchor|sec-sec_03.13.14}}=== 03.13.14 Withdrawn ===&lt;br /&gt;
&lt;br /&gt;
Technology-specific.&lt;br /&gt;
&lt;br /&gt;
{{anchor|d30e6825-Head3}}{{anchor|sec-sec_03.13.15}}=== 03.13.15 Session Authenticity ===&lt;br /&gt;
&lt;br /&gt;
==== ASSESSMENT OBJECTIVE ====&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Determine if:&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;A.03.13.15:&#039;&#039;&#039; the authenticity of communications sessions is protected.&lt;br /&gt;
&lt;br /&gt;
==== ASSESSMENT METHODS AND OBJECTS ====&lt;br /&gt;
&lt;br /&gt;
===== Examine =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: system and communications protection policy and procedures; procedures for session authenticity; system design documentation; system configuration settings; system audit records; system security plan; other relevant documents or records&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
===== Interview =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: personnel with information security responsibilities; system administrators&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
===== Test =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: mechanisms for supporting or implementing session authenticity&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
==== REFERENCES ====&lt;br /&gt;
&lt;br /&gt;
Source Assessment Procedure: [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_A_5_1_1/home?element=SC-23 SC-23]&lt;br /&gt;
&lt;br /&gt;
{{anchor|d30e6866-Head3}}{{anchor|sec-sec_03.13.16}}=== 03.13.16 Withdrawn ===&lt;br /&gt;
&lt;br /&gt;
Incorporated into [[#sec-sec_03.13.08|03.13.08]].&lt;br /&gt;
&lt;br /&gt;
{{anchor|d30e6876-Head2}}{{anchor|sec-sec_3.14}}== 3.14 [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=SI System and Information Integrity] ==&lt;br /&gt;
&lt;br /&gt;
{{anchor|d30e6881-Head3}}{{anchor|sec-sec_03.14.01}}=== 03.14.01 Flaw Remediation ===&lt;br /&gt;
&lt;br /&gt;
==== ASSESSMENT OBJECTIVE ====&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Determine if:&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.14.01.ODP[01]}}A.03.14.01.ODP&amp;amp;#91;01&amp;amp;#93;: &#039;&#039;&#039;&amp;lt;nowiki/&amp;gt;&#039;&#039;&#039;&#039;&#039;the time period within which to install security-relevant software updates after the release of the updates is defined&#039;&#039;&#039;&#039;&#039;&amp;lt;nowiki/&amp;gt;&#039;&#039;&#039;.&#039;&#039;&#039;&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.14.01.ODP[02]}}A.03.14.01.ODP&amp;amp;#91;02&amp;amp;#93;: &#039;&#039;&#039;&amp;lt;nowiki/&amp;gt;&#039;&#039;&#039;&#039;&#039;the time period within which to install security-relevant firmware updates after the release of the updates is defined.&#039;&#039;&#039;&#039;&#039;&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.14.01.a[01]}}A.03.14.01.a&amp;amp;#91;01&amp;amp;#93;:&#039;&#039;&#039; system flaws are identified.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.14.01.a[02]}}A.03.14.01.a&amp;amp;#91;02&amp;amp;#93;:&#039;&#039;&#039; system flaws are reported.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.14.01.a[03]}}A.03.14.01.a&amp;amp;#91;03&amp;amp;#93;:&#039;&#039;&#039; system flaws are corrected.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.14.01.b[01]}}A.03.14.01.b&amp;amp;#91;01&amp;amp;#93;:&#039;&#039;&#039; security-relevant software updates are installed within &#039;&#039;&#039;&#039;&#039;&amp;lt;A.03.14.01.ODP&amp;amp;#91;01&amp;amp;#93;: time period&amp;gt;&#039;&#039;&#039;&#039;&#039; of the release of the updates.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.14.01.b[02]}}A.03.14.01.b&amp;amp;#91;02&amp;amp;#93;:&#039;&#039;&#039; security-relevant firmware updates are installed within &#039;&#039;&#039;&#039;&#039;&amp;lt;A.03.14.01.ODP&amp;amp;#91;02&amp;amp;#93;: time period&amp;gt;&#039;&#039;&#039;&#039;&#039; of the release of the updates.&lt;br /&gt;
&lt;br /&gt;
==== ASSESSMENT METHODS AND OBJECTS ====&lt;br /&gt;
&lt;br /&gt;
===== Examine =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: system and information integrity policy and procedures; procedures for flaw remediation; procedures for configuration management; list of recent security flaw remediation actions performed on the system; list of flaws and vulnerabilities that may potentially affect the system; test results from the installation of software and firmware updates to correct system flaws; installation and change control records for security-relevant software and firmware updates; system security plan; other relevant documents or records&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
===== Interview =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: personnel responsible for installing, configuring, or maintaining the system; personnel responsible for flaw remediation; personnel with configuration management responsibilities; personnel with information security responsibilities; system administrators&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
===== Test =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: processes for identifying, reporting, and correcting system flaws; processes for installing software and firmware updates; mechanisms for supporting or implementing the reporting and correction of system flaws; mechanisms for supporting or implementing the testing software and firmware updates&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
==== REFERENCES ====&lt;br /&gt;
&lt;br /&gt;
Source Assessment Procedure: [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_A_5_1_1/home?element=SI-02 SI-02]&lt;br /&gt;
&lt;br /&gt;
{{anchor|d30e6966-Head3}}{{anchor|sec-sec_03.14.02}}=== 03.14.02 Malicious Code Protection ===&lt;br /&gt;
&lt;br /&gt;
==== ASSESSMENT OBJECTIVE ====&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Determine if:&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.14.02.ODP[01]}}A.03.14.02.ODP&amp;amp;#91;01&amp;amp;#93;: &#039;&#039;&#039;&amp;lt;nowiki/&amp;gt;&#039;&#039;&#039;&#039;&#039;the frequency at which malicious code protection mechanisms perform scans is defined&#039;&#039;&#039;&#039;&#039;&amp;lt;nowiki/&amp;gt;&#039;&#039;&#039;.&#039;&#039;&#039;&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.14.02.a[01]}}A.03.14.02.a&amp;amp;#91;01&amp;amp;#93;:&#039;&#039;&#039; malicious code protection mechanisms are implemented at system entry and exit points to detect malicious code.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.14.02.a[02]}}A.03.14.02.a&amp;amp;#91;02&amp;amp;#93;:&#039;&#039;&#039; malicious code protection mechanisms are implemented at system entry and exit points to eradicate malicious code.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.14.02.b}}A.03.14.02.b:&#039;&#039;&#039; malicious code protection mechanisms are updated as new releases are available in accordance with configuration management policy and procedures.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.14.02.c.01[01]}}A.03.14.02.c.01&amp;amp;#91;01&amp;amp;#93;:&#039;&#039;&#039; malicious code protection mechanisms are configured to perform scans of the system &#039;&#039;&#039;&#039;&#039;&amp;lt;A.03.14.02.ODP&amp;amp;#91;01&amp;amp;#93;: frequency&amp;gt;&#039;&#039;&#039;&#039;&#039;.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.14.02.c.01[02]}}A.03.14.02.c.01&amp;amp;#91;02&amp;amp;#93;:&#039;&#039;&#039; malicious code protection mechanisms are configured to perform real-time scans of files from external sources at endpoints or system entry and exit points as the files are downloaded, opened, or executed.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.14.02.c.02}}A.03.14.02.c.02:&#039;&#039;&#039; malicious code protection mechanisms are configured to block malicious code, quarantine malicious code, or take other actions in response to malicious code detection.&lt;br /&gt;
&lt;br /&gt;
==== ASSESSMENT METHODS AND OBJECTS ====&lt;br /&gt;
&lt;br /&gt;
===== Examine =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: system and information integrity policy and procedures; configuration management policy and procedures; procedures for malicious code protection; records of malicious code protection updates; system design documentation; system configuration settings; scan results from malicious code protection mechanisms; record of actions initiated by malicious code protection mechanisms in response to malicious code detection; system audit records; system security plan; other relevant documents or records&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
===== Interview =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: personnel responsible for malicious code protection; personnel with system installation, configuration, or maintenance responsibilities; personnel with information security responsibilities; system administrators&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
===== Test =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: processes for employing, updating, and configuring malicious code protection mechanisms; processes for addressing the detection of false positives and resulting potential impacts; mechanisms for supporting or implementing, employing, updating, and configuring malicious code protection mechanisms; mechanisms for supporting or implementing malicious code scanning and the execution of subsequent actions&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
==== REFERENCES ====&lt;br /&gt;
&lt;br /&gt;
Source Assessment Procedure: [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_A_5_1_1/home?element=SI-03 SI-03]&lt;br /&gt;
&lt;br /&gt;
{{anchor|d30e7046-Head3}}{{anchor|sec-sec_03.14.03}}=== 03.14.03 Security Alerts, Advisories, and Directives ===&lt;br /&gt;
&lt;br /&gt;
==== ASSESSMENT OBJECTIVE ====&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Determine if:&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.14.03.a}}A.03.14.03.a:&#039;&#039;&#039; system security alerts, advisories, and directives from external organizations are received on an ongoing basis.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.14.03.b[01]}}A.03.14.03.b&amp;amp;#91;01&amp;amp;#93;:&#039;&#039;&#039; internal security alerts, advisories, and directives are generated, as necessary.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.14.03.b[02]}}A.03.14.03.b&amp;amp;#91;02&amp;amp;#93;:&#039;&#039;&#039; internal security alerts, advisories, and directives are disseminated, as necessary.&lt;br /&gt;
&lt;br /&gt;
==== ASSESSMENT METHODS AND OBJECTS ====&lt;br /&gt;
&lt;br /&gt;
===== Examine =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: system and information integrity policy and procedures; procedures for security alerts, advisories, and directives; records of security alerts and advisories; system security plan; other relevant documents or records&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
===== Interview =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: personnel with security alert and advisory responsibilities; personnel implementing, operating, maintaining, and using the system; personnel, organizational elements, or external organizations to whom alerts, advisories, and directives are to be disseminated; personnel with information security responsibilities; system administrators&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
===== Test =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: processes for defining, receiving, generating, disseminating, and complying with security alerts, advisories, and directives; mechanisms for supporting or implementing security directives; mechanisms for supporting or implementing the definition, receipt, generation, and dissemination of security alerts, advisories, and directives&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
==== REFERENCES ====&lt;br /&gt;
&lt;br /&gt;
Source Assessment Procedure: [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_A_5_1_1/home?element=SI-05 SI-05]&lt;br /&gt;
&lt;br /&gt;
{{anchor|d30e7098-Head3}}{{anchor|sec-sec_03.14.04}}=== 03.14.04 Withdrawn ===&lt;br /&gt;
&lt;br /&gt;
Incorporated into [[#sec-sec_03.14.02|03.14.02]].&lt;br /&gt;
&lt;br /&gt;
{{anchor|d30e7108-Head3}}{{anchor|sec-sec_03.14.05}}=== 03.14.05 Withdrawn ===&lt;br /&gt;
&lt;br /&gt;
Addressed by [[#sec-sec_03.14.02|03.14.02]].&lt;br /&gt;
&lt;br /&gt;
{{anchor|d30e7119-Head3}}{{anchor|sec-sec_03.14.06}}=== 03.14.06 System Monitoring ===&lt;br /&gt;
&lt;br /&gt;
==== ASSESSMENT OBJECTIVE ====&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Determine if:&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.14.06.a.01[01]}}A.03.14.06.a.01&amp;amp;#91;01&amp;amp;#93;:&#039;&#039;&#039; the system is monitored to detect attacks.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.14.06.a.01[02]}}A.03.14.06.a.01&amp;amp;#91;02&amp;amp;#93;:&#039;&#039;&#039; the system is monitored to detect indicators of potential attacks.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.14.06.a.02}}A.03.14.06.a.02:&#039;&#039;&#039; the system is monitored to detect unauthorized connections.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.14.06.b}}A.03.14.06.b:&#039;&#039;&#039; unauthorized use of the system is identified.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.14.06.c[01]}}A.03.14.06.c&amp;amp;#91;01&amp;amp;#93;:&#039;&#039;&#039; inbound communications traffic is monitored to detect unusual or unauthorized activities or conditions.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.14.06.c[02]}}A.03.14.06.c&amp;amp;#91;02&amp;amp;#93;:&#039;&#039;&#039; outbound communications traffic is monitored to detect unusual or unauthorized activities or conditions.&lt;br /&gt;
&lt;br /&gt;
==== ASSESSMENT METHODS AND OBJECTS ====&lt;br /&gt;
&lt;br /&gt;
===== Examine =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: system and information integrity policy and procedures; procedures for system monitoring tools and techniques; continuous monitoring strategy; facility diagram or layout; system design documentation; locations within the system where monitoring devices are deployed; system configuration settings; system protocols; system audit records; system security plan; other relevant documents or records&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
===== Interview =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: personnel with responsibilities for installing, configuring, or maintaining the system; personnel with system monitoring responsibilities; personnel with intrusion detection responsibilities; personnel with information security responsibilities; system administrators&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
===== Test =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: processes for intrusion detection and system monitoring; mechanisms for supporting or implementing system monitoring capabilities; mechanisms for supporting or implementing intrusion detection and system monitoring capabilities; mechanisms for supporting or implementing the monitoring of inbound and outbound communications traffic&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
==== REFERENCES ====&lt;br /&gt;
&lt;br /&gt;
Source Assessment Procedures: [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_A_5_1_1/home?element=SI-04 SI-04], [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_A_5_1_1/home?element=SI-04 SI-04(04)]&lt;br /&gt;
&lt;br /&gt;
{{anchor|d30e7190-Head3}}{{anchor|sec-sec_03.14.07}}=== 03.14.07 Withdrawn ===&lt;br /&gt;
&lt;br /&gt;
Incorporated into [[#sec-sec_03.14.06|03.14.06]].&lt;br /&gt;
&lt;br /&gt;
{{anchor|d30e7200-Head3}}{{anchor|sec-sec_03.14.08}}=== 03.14.08 Information Management and Retention ===&lt;br /&gt;
&lt;br /&gt;
==== ASSESSMENT OBJECTIVE ====&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Determine if:&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;A.03.14.08&amp;amp;#91;01&amp;amp;#93;:&#039;&#039;&#039; CUI within the system is managed in accordance with applicable laws, Executive Orders, directives, regulations, policies, standards, guidelines, and operational requirements.&lt;br /&gt;
* &#039;&#039;&#039;A.03.14.08&amp;amp;#91;02&amp;amp;#93;:&#039;&#039;&#039; CUI within the system is retained in accordance with applicable laws, Executive Orders, directives, regulations, policies, standards, guidelines, and operational requirements.&lt;br /&gt;
* &#039;&#039;&#039;A.03.14.08&amp;amp;#91;03&amp;amp;#93;:&#039;&#039;&#039; CUI output from the system is managed in accordance with applicable laws, Executive Orders, directives, regulations, policies, standards, guidelines, and operational requirements.&lt;br /&gt;
* &#039;&#039;&#039;A.03.14.08&amp;amp;#91;04&amp;amp;#93;:&#039;&#039;&#039; CUI output from the system is retained in accordance with applicable laws, Executive Orders, directives, regulations, policies, standards, guidelines, and operational requirements.&lt;br /&gt;
&lt;br /&gt;
==== ASSESSMENT METHODS AND OBJECTS ====&lt;br /&gt;
&lt;br /&gt;
===== Examine =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: system and information integrity policy and procedures; laws, Executive Orders, directives, policies, regulations, standards, and operational requirements applicable to information management and retention; records retention and disposition policy; records retention and disposition procedures; media protection policy; media protection procedures; audit findings; system security plan; other relevant documents or records&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
===== Interview =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: personnel with information and records management, retention, and disposition responsibilities; personnel with information security responsibilities; system administrators&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
===== Test =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: processes for information management, retention, and disposition; mechanisms for supporting or implementing information management, retention, and disposition&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
==== REFERENCES ====&lt;br /&gt;
&lt;br /&gt;
Source Assessment Procedure: [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_A_5_1_1/home?element=SI-12 SI-12]&lt;br /&gt;
&lt;br /&gt;
{{anchor|d30e7254-Head2}}{{anchor|sec-sec_3.15}}== 3.15 [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=PL Planning] ==&lt;br /&gt;
&lt;br /&gt;
{{anchor|d30e7259-Head3}}{{anchor|sec-sec_03.15.01}}=== 03.15.01 Policy and Procedures ===&lt;br /&gt;
&lt;br /&gt;
==== ASSESSMENT OBJECTIVE ====&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Determine if:&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.15.01.ODP[01]}}A.03.15.01.ODP&amp;amp;#91;01&amp;amp;#93;: &#039;&#039;&#039;&amp;lt;nowiki/&amp;gt;&#039;&#039;&#039;&#039;&#039;the frequency at which the policies and procedures for satisfying security requirements are reviewed and updated is defined.&#039;&#039;&#039;&#039;&#039;&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.15.01.a[01]}}A.03.15.01.a&amp;amp;#91;01&amp;amp;#93;:&#039;&#039;&#039; policies needed to satisfy the security requirements for the protection of CUI are developed and documented.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.15.01.a[02]}}A.03.15.01.a&amp;amp;#91;02&amp;amp;#93;:&#039;&#039;&#039; policies needed to satisfy the security requirements for the protection of CUI are disseminated to organizational personnel or roles.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.15.01.a[03]}}A.03.15.01.a&amp;amp;#91;03&amp;amp;#93;:&#039;&#039;&#039; procedures needed to satisfy the security requirements for the protection of CUI are developed and documented.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.15.01.a[04]}}A.03.15.01.a&amp;amp;#91;04&amp;amp;#93;:&#039;&#039;&#039; procedures needed to satisfy the security requirements for the protection of CUI are disseminated to organizational personnel or roles.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.15.01.b[01]}}A.03.15.01.b&amp;amp;#91;01&amp;amp;#93;:&#039;&#039;&#039; policies and procedures are reviewed &#039;&#039;&#039;&#039;&#039;&amp;lt;A.03.15.01.ODP&amp;amp;#91;01&amp;amp;#93;: frequency&amp;gt;&#039;&#039;&#039;&#039;&#039;.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.15.01.b[02]}}A.03.15.01.b&amp;amp;#91;02&amp;amp;#93;:&#039;&#039;&#039; policies and procedures are updated &#039;&#039;&#039;&#039;&#039;&amp;lt;A.03.15.01.ODP&amp;amp;#91;01&amp;amp;#93;: frequency&amp;gt;&#039;&#039;&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
==== ASSESSMENT METHODS AND OBJECTS ====&lt;br /&gt;
&lt;br /&gt;
===== Examine =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: security policies and procedures associated with the protection of CUI; audit findings; system security plan; other relevant documents or records&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
===== Interview =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: personnel with information security responsibilities&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
==== REFERENCES ====&lt;br /&gt;
&lt;br /&gt;
Source Assessment Procedures: [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_A_5_1_1/home?element=AC-01 AC-01], [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_A_5_1_1/home?element=AT-01 AT-01], [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_A_5_1_1/home?element=AU-01 AU-01], [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_A_5_1_1/home?element=CA-01 CA-01], [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_A_5_1_1/home?element=CM-01 CM-01], [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_A_5_1_1/home?element=IA-01 IA-01], [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_A_5_1_1/home?element=IR-01 IR-01], [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_A_5_1_1/home?element=MA-01 MA-01], [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_A_5_1_1/home?element=MP-01 MP-01], [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_A_5_1_1/home?element=PE-01 PE-01], [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_A_5_1_1/home?element=PL-01 PL-01], [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_A_5_1_1/home?element=PS-01 PS-01], [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_A_5_1_1/home?element=RA-01 RA-01], [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_A_5_1_1/home?element=SA-01 SA-01], [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_A_5_1_1/home?element=SC-01 SC-01], [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_A_5_1_1/home?element=SI-01 SI-01], [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_A_5_1_1/home?element=SR-01 SR-01]&lt;br /&gt;
&lt;br /&gt;
{{anchor|d30e7400-Head3}}{{anchor|sec-sec_03.15.02}}=== 03.15.02 System Security Plan ===&lt;br /&gt;
&lt;br /&gt;
==== ASSESSMENT OBJECTIVE ====&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Determine if:&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.15.02.ODP[01]}}A.03.15.02.ODP&amp;amp;#91;01&amp;amp;#93;: &#039;&#039;&#039;&amp;lt;nowiki/&amp;gt;&#039;&#039;&#039;&#039;&#039;the frequency at which the system security plan is reviewed and updated is defined.&#039;&#039;&#039;&#039;&#039;&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.15.02.a.01}}A.03.15.02.a.01:&#039;&#039;&#039; a system security plan that defines the constituent system components is developed.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.15.02.a.02}}A.03.15.02.a.02:&#039;&#039;&#039; a system security plan that identifies the information types processed, stored, and transmitted by the system is developed.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.15.02.a.03}}A.03.15.02.a.03:&#039;&#039;&#039; a system security plan that describes specific threats to the system that are of concern to the organization is developed.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.15.02.a.04}}A.03.15.02.a.04:&#039;&#039;&#039; a system security plan that describes the operational environment for the system and any dependencies on or connections to other systems or system components is developed.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.15.02.a.05}}A.03.15.02.a.05:&#039;&#039;&#039; a system security plan that provides an overview of the security requirements for the system is developed.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.15.02.a.06}}A.03.15.02.a.06:&#039;&#039;&#039; a system security plan that describes the safeguards in place or planned for meeting the security requirements is developed.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.15.02.a.07}}A.03.15.02.a.07:&#039;&#039;&#039; a system security plan that identifies individuals that fulfill system roles and responsibilities is developed.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.15.02.a.08}}A.03.15.02.a.08:&#039;&#039;&#039; a system security plan that includes other relevant information necessary for the protection of CUI is developed.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.15.02.b[01]}}A.03.15.02.b&amp;amp;#91;01&amp;amp;#93;:&#039;&#039;&#039; the system security plan is reviewed &#039;&#039;&#039;&#039;&#039;&amp;lt;A.03.15.02.ODP&amp;amp;#91;01&amp;amp;#93;: frequency&amp;gt;&#039;&#039;&#039;&#039;&#039;.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.15.02.b[02]}}A.03.15.02.b&amp;amp;#91;02&amp;amp;#93;:&#039;&#039;&#039; the system security plan is updated &#039;&#039;&#039;&#039;&#039;&amp;lt;A.03.15.02.ODP&amp;amp;#91;01&amp;amp;#93;: frequency&amp;gt;&#039;&#039;&#039;&#039;&#039;.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.15.02.c}}A.03.15.02.c:&#039;&#039;&#039; the system security plan is protected from unauthorized disclosure.&lt;br /&gt;
&lt;br /&gt;
==== ASSESSMENT METHODS AND OBJECTS ====&lt;br /&gt;
&lt;br /&gt;
===== Examine =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: security planning policy and procedures; procedures for system security plan development and implementation; procedures for system security plan reviews and updates; enterprise architecture; system security plan; records of system security plan reviews and updates; risk assessments; risk assessment results; security architecture and design documentation; other relevant documents or records&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
===== Interview =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: personnel with system security planning and plan implementation responsibilities; system developers; personnel with information security responsibilities&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
===== Test =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: processes for system security plan development, review, update, and approval&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
==== REFERENCES ====&lt;br /&gt;
&lt;br /&gt;
Source Assessment Procedure: [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_A_5_1_1/home?element=PL-02 PL-02]&lt;br /&gt;
&lt;br /&gt;
{{anchor|d30e7507-Head3}}{{anchor|sec-sec_03.15.03}}=== 03.15.03 Rules of Behavior ===&lt;br /&gt;
&lt;br /&gt;
==== ASSESSMENT OBJECTIVE ====&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Determine if:&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.15.03.ODP[01]}}A.03.15.03.ODP&amp;amp;#91;01&amp;amp;#93;: &#039;&#039;&#039;&amp;lt;nowiki/&amp;gt;&#039;&#039;&#039;&#039;&#039;the frequency at which the rules of behavior are reviewed and updated is defined.&#039;&#039;&#039;&#039;&#039;&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.15.03.a}}A.03.15.03.a:&#039;&#039;&#039; rules that describe responsibilities and expected behavior for system usage and protecting CUI are established.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.15.03.b}}A.03.15.03.b:&#039;&#039;&#039; rules are provided to individuals who require access to the system.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.15.03.c}}A.03.15.03.c:&#039;&#039;&#039; a documented acknowledgement from individuals indicating that they have read, understand, and agree to abide by the rules of behavior is received before authorizing access to CUI and the system.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.15.03.d[01]}}A.03.15.03.d&amp;amp;#91;01&amp;amp;#93;:&#039;&#039;&#039; the rules of behavior are reviewed &#039;&#039;&#039;&#039;&#039;&amp;lt;A.03.15.03.ODP&amp;amp;#91;01&amp;amp;#93;: frequency&amp;gt;&#039;&#039;&#039;&#039;&#039;.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.15.03.d[02]}}A.03.15.03.d&amp;amp;#91;02&amp;amp;#93;:&#039;&#039;&#039; the rules of behavior are updated &#039;&#039;&#039;&#039;&#039;&amp;lt;A.03.15.03.ODP&amp;amp;#91;01&amp;amp;#93;: frequency&amp;gt;&#039;&#039;&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
==== ASSESSMENT METHODS AND OBJECTS ====&lt;br /&gt;
&lt;br /&gt;
===== Examine =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: security planning policy and procedures; rules of behavior for system users; signed acknowledgements of rules of behavior; records for rules of behavior reviews and updates; system security plan; other relevant documents or records&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
===== Interview =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: personnel with rules of behavior establishment, review, and update responsibilities; personnel with literacy training and awareness responsibilities; personnel with role-based training responsibilities; authorized users of the system who have signed rules of behavior; personnel with information security responsibilities&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
===== Test =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: processes for establishing, reviewing, disseminating, and updating rules of behavior; mechanisms for supporting or implementing the establishment, dissemination, review, and update of rules of behavior&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
==== REFERENCES ====&lt;br /&gt;
&lt;br /&gt;
Source Assessment Procedure: [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_A_5_1_1/home?element=PL-04 PL-04]&lt;br /&gt;
&lt;br /&gt;
{{anchor|d30e7582-Head2}}{{anchor|sec-sec_3.16}}== 3.16 [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=SA System and Services Acquisition] ==&lt;br /&gt;
&lt;br /&gt;
{{anchor|d30e7587-Head3}}{{anchor|sec-sec_03.16.01}}=== 03.16.01 Systems Security Engineering Principles ===&lt;br /&gt;
&lt;br /&gt;
==== ASSESSMENT OBJECTIVE ====&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Determine if:&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.16.01.ODP[01]}}A.03.16.01.ODP&amp;amp;#91;01&amp;amp;#93;: &#039;&#039;&#039;&amp;lt;nowiki/&amp;gt;&#039;&#039;&#039;&#039;&#039;systems security engineering principles to be applied to the development or modification of the system and system components are defined.&#039;&#039;&#039;&#039;&#039;&lt;br /&gt;
* &#039;&#039;&#039;A.03.16.01: &#039;&#039;&#039;&amp;lt;nowiki/&amp;gt;&#039;&#039;&#039;&#039;&#039;&amp;lt;A.03.16.01.ODP&amp;amp;#91;01&amp;amp;#93;: systems security engineering principles&amp;gt;&#039;&#039;&#039;&#039;&#039; are applied to the development or modification of the system and system components.&lt;br /&gt;
&lt;br /&gt;
==== ASSESSMENT METHODS AND OBJECTS ====&lt;br /&gt;
&lt;br /&gt;
===== Examine =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: system and services acquisition policy; system and services&lt;br /&gt;
&lt;br /&gt;
acquisition procedures; procedures addressing security engineering principles used in the development and modification of the system; system design documentation; security requirements and specifications for the system; system security plan; other relevant documents or records&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
===== Interview =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: personnel with acquisition/contracting responsibilities; personnel with information security responsibilities; personnel with system development and modification responsibilities; system developers&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
===== Test =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: processes for applying security engineering principles in system development and modification; mechanisms supporting the application of security engineering principles in system development and modification&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
==== REFERENCES ====&lt;br /&gt;
&lt;br /&gt;
Source Assessment Procedure: [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_A_5_1_1/home?element=SA-08 SA-08]&lt;br /&gt;
&lt;br /&gt;
{{anchor|d30e7641-Head3}}{{anchor|sec-sec_03.16.02}}=== 03.16.02 Unsupported System Components ===&lt;br /&gt;
&lt;br /&gt;
==== ASSESSMENT OBJECTIVE ====&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Determine if:&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.16.02.a}}A.03.16.02.a:&#039;&#039;&#039; system components are replaced when support for the components is no longer available from the developer, vendor, or manufacturer.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.16.02.b}}A.03.16.02.b:&#039;&#039;&#039; options for risk mitigation or alternative sources for continued support for unsupported components that cannot be replaced are provided.&lt;br /&gt;
&lt;br /&gt;
==== ASSESSMENT METHODS AND OBJECTS ====&lt;br /&gt;
&lt;br /&gt;
===== Examine =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: system and services acquisition policy and procedures; procedures for the replacement or continued use of unsupported system components; documented evidence of replacing unsupported system components; documented approvals (including justification) for the continued use of unsupported system components; SCRM plan; system security plan; other relevant documents or records&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
===== Interview =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: personnel with system and service acquisition responsibilities; personnel responsible for component replacement; personnel with system development life cycle responsibilities; personnel with information security responsibilities&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
===== Test =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: processes for replacing unsupported system components; mechanisms for supporting or implementing the replacement of unsupported system components&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
==== REFERENCES ====&lt;br /&gt;
&lt;br /&gt;
Source Assessment Procedure: [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_A_5_1_1/home?element=SA-22 SA-22]&lt;br /&gt;
&lt;br /&gt;
{{anchor|d30e7688-Head3}}{{anchor|sec-sec_03.16.03}}=== 03.16.03 External System Services ===&lt;br /&gt;
&lt;br /&gt;
==== ASSESSMENT OBJECTIVE ====&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Determine if:&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.16.03.ODP[01]}}A.03.16.03.ODP&amp;amp;#91;01&amp;amp;#93;: &#039;&#039;&#039;&amp;lt;nowiki/&amp;gt;&#039;&#039;&#039;&#039;&#039;security requirements to be satisfied by external system service providers are defined&#039;&#039;&#039;&#039;&#039;&amp;lt;nowiki/&amp;gt;&#039;&#039;&#039;.&#039;&#039;&#039;&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.16.03.a}}A.03.16.03.a:&#039;&#039;&#039; the providers of external system services used for the processing, storage, or transmission of CUI comply with the following security requirements: &#039;&#039;&#039;&#039;&#039;&amp;lt;A.03.16.03.ODP&amp;amp;#91;01&amp;amp;#93;: security requirements&amp;gt;&#039;&#039;&#039;&#039;&#039;.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.16.03.b}}A.03.16.03.b:&#039;&#039;&#039; user roles and responsibilities with regard to external system services, including shared responsibilities with external service providers, are defined and documented.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.16.03.c}}A.03.16.03.c:&#039;&#039;&#039; processes, methods, and techniques to monitor security requirement compliance by external service providers on an ongoing basis are implemented.&lt;br /&gt;
&lt;br /&gt;
==== ASSESSMENT METHODS AND OBJECTS ====&lt;br /&gt;
&lt;br /&gt;
===== Examine =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: system and services acquisition policy and procedures; procedures for monitoring security requirement compliance by external service providers; acquisition documentation; contracts; service-level agreements; interagency agreements; licensing agreements; list of security requirements for external provider services; assessment results or reports from external service providers; SCRM plan; system security plan; other relevant documents or records&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
===== Interview =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: personnel with acquisition responsibilities; external providers of system services; personnel with SCRM responsibilities; personnel with information security responsibilities&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
===== Test =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: organizational processes for monitoring security and privacy control compliance by external service providers on an ongoing basis; mechanisms for monitoring security and privacy control compliance by external service providers on an ongoing basis&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
==== REFERENCES ====&lt;br /&gt;
&lt;br /&gt;
Source Assessment Procedure: [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_A_5_1_1/home?element=SA-09 SA-09]&lt;br /&gt;
&lt;br /&gt;
{{anchor|d30e7752-Head2}}{{anchor|sec-sec_3.17}}== 3.17 [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=SR Supply Chain Risk Management] ==&lt;br /&gt;
&lt;br /&gt;
{{anchor|d30e7758-Head3}}{{anchor|sec-sec_03.17.01}}=== 03.17.01 Supply Chain Risk Management Plan ===&lt;br /&gt;
&lt;br /&gt;
==== ASSESSMENT OBJECTIVE ====&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Determine if:&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.17.01.ODP[01]}}A.03.17.01.ODP&amp;amp;#91;01&amp;amp;#93;: &#039;&#039;&#039;&amp;lt;nowiki/&amp;gt;&#039;&#039;&#039;&#039;&#039;the frequency at which to review and update the supply chain risk management plan is defined.&#039;&#039;&#039;&#039;&#039;&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.17.01.a[01]}}A.03.17.01.a&amp;amp;#91;01&amp;amp;#93;:&#039;&#039;&#039; a plan for managing supply chain risks is developed.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.17.01.a[02]}}A.03.17.01.a&amp;amp;#91;02&amp;amp;#93;:&#039;&#039;&#039; the SCRM plan addresses risks associated with the research and development of the system, system components, or system services.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.17.01.a[03]}}A.03.17.01.a&amp;amp;#91;03&amp;amp;#93;:&#039;&#039;&#039; the SCRM plan addresses risks associated with the design of the system, system components, or system services.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.17.01.a[04]}}A.03.17.01.a&amp;amp;#91;04&amp;amp;#93;:&#039;&#039;&#039; the SCRM plan addresses risks associated with the manufacturing of the system, system components, or system services.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.17.01.a[05]}}A.03.17.01.a&amp;amp;#91;05&amp;amp;#93;:&#039;&#039;&#039; the SCRM plan addresses risks associated with the acquisition of the system, system components, or system services.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.17.01.a[06]}}A.03.17.01.a&amp;amp;#91;06&amp;amp;#93;:&#039;&#039;&#039; the SCRM plan addresses risks associated with the delivery of the system, system components, or system services.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.17.01.a[07]}}A.03.17.01.a&amp;amp;#91;07&amp;amp;#93;:&#039;&#039;&#039; the SCRM plan addresses risks associated with the integration of the system, system components, or system services.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.17.01.a[08]}}A.03.17.01.a&amp;amp;#91;08&amp;amp;#93;:&#039;&#039;&#039; the SCRM plan addresses risks associated with the operation of the system, system components, or system services.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.17.01.a[09]}}A.03.17.01.a&amp;amp;#91;09&amp;amp;#93;:&#039;&#039;&#039; the SCRM plan addresses risks associated with the maintenance of the system, system components, or system services.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.17.01.a}}A.03.17.01.a&amp;amp;#91;&#039;&#039;&#039;[[#bibr-ref_10|&#039;&#039;&#039;10&#039;&#039;&#039;]]&#039;&#039;&#039;&amp;amp;#93;:&#039;&#039;&#039; the SCRM plan addresses risks associated with the disposal of the system, system components, or system services.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.17.01.b[01]}}A.03.17.01.b&amp;amp;#91;01&amp;amp;#93;:&#039;&#039;&#039; the SCRM plan is reviewed &#039;&#039;&#039;&#039;&#039;&amp;lt;A.03.17.01.ODP&amp;amp;#91;01&amp;amp;#93;: frequency&amp;gt;&#039;&#039;&#039;&#039;&#039;.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.17.01.b[02]}}A.03.17.01.b&amp;amp;#91;02&amp;amp;#93;:&#039;&#039;&#039; the SCRM plan is updated &#039;&#039;&#039;&#039;&#039;&amp;lt;A.03.17.01.ODP&amp;amp;#91;01&amp;amp;#93;: frequency&amp;gt;&#039;&#039;&#039;&#039;&#039;.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.17.01.c}}A.03.17.01.c:&#039;&#039;&#039; the SCRM plan is protected from unauthorized disclosure.&lt;br /&gt;
&lt;br /&gt;
==== ASSESSMENT METHODS AND OBJECTS ====&lt;br /&gt;
&lt;br /&gt;
===== Examine =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: SCRM policy and procedures; SCRM plan; system and services acquisition policy and procedures; system and services acquisition procedures; procedures for supply chain protection; procedures for protecting the SCRM plan from unauthorized disclosure; system development life cycle procedures; procedures for the integration of information security requirements into the acquisition process; acquisition documentation; service-level agreements; acquisition contracts for the system, system components, or system services; list of supply chain threats; list of safeguards for supply chain threats; system life cycle documentation, including research and development, design, manufacturing, acquisition, delivery, integration, operations, maintenance, and disposal; inter-organizational agreements and procedures; system security plan; other relevant documents or records&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
===== Interview =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: personnel with acquisition responsibilities; personnel with SCRM responsibilities; personnel with information security responsibilities&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
===== Test =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: organizational processes for defining and documenting the system development life cycle (SDLC); organizational processes for identifying SDLC roles and responsibilities; organizational processes for integrating SCRM into the SDLC; mechanisms for supporting or implementing the SDLC&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
==== REFERENCES ====&lt;br /&gt;
&lt;br /&gt;
Source Assessment Procedure: [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_A_5_1_1/home?element=SR-02 SR-02]&lt;br /&gt;
&lt;br /&gt;
{{anchor|d30e7879-Head3}}{{anchor|sec-sec_03.17.02}}=== 03.17.02 Acquisition Strategies, Tools, and Methods ===&lt;br /&gt;
&lt;br /&gt;
==== ASSESSMENT OBJECTIVE ====&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Determine if:&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;A.03.17.02&amp;amp;#91;01&amp;amp;#93;:&#039;&#039;&#039; acquisition strategies, contract tools, and procurement methods are developed to identify supply chain risks.&lt;br /&gt;
* &#039;&#039;&#039;A.03.17.02&amp;amp;#91;02&amp;amp;#93;:&#039;&#039;&#039; acquisition strategies, contract tools, and procurement methods are developed to protect against supply chain risks.&lt;br /&gt;
* &#039;&#039;&#039;A.03.17.02&amp;amp;#91;03&amp;amp;#93;:&#039;&#039;&#039; acquisition strategies, contract tools, and procurement methods are developed to mitigate supply chain risks.&lt;br /&gt;
* &#039;&#039;&#039;A.03.17.02&amp;amp;#91;04&amp;amp;#93;:&#039;&#039;&#039; acquisition strategies, contract tools, and procurement methods are implemented to identify supply chain risks.&lt;br /&gt;
* &#039;&#039;&#039;A.03.17.02&amp;amp;#91;05&amp;amp;#93;:&#039;&#039;&#039; acquisition strategies, contract tools, and procurement methods are implemented to protect against supply chain risks.&lt;br /&gt;
* &#039;&#039;&#039;A.03.17.02&amp;amp;#91;06&amp;amp;#93;:&#039;&#039;&#039; acquisition strategies, contract tools, and procurement methods are implemented to mitigate supply chain risks.&lt;br /&gt;
&lt;br /&gt;
==== ASSESSMENT METHODS AND OBJECTS ====&lt;br /&gt;
&lt;br /&gt;
===== Examine =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: SCRM policy and procedures; SCRM plan; system and services acquisition policy and procedures; procedures for supply chain protection; procedures for the integration of information security requirements into the acquisition process; solicitation documentation; acquisition documentation (including purchase orders); service-level agreements; acquisition contracts for the system, system components, or services; documentation of identified supply chain risks; mitigation plans for supply chain risks; documentation of training, education, and awareness programs for personnel regarding supply chain risk; system security plan; other relevant documents or records&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
===== Interview =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: personnel with acquisition responsibilities; personnel with SCRM responsibilities; personnel with information security responsibilities&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
===== Test =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: processes for defining and employing tailored acquisition strategies, contract tools, and procurement methods; mechanisms for implementing tailored acquisition strategies, contract tools, and procurement methods&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
==== REFERENCES ====&lt;br /&gt;
&lt;br /&gt;
Source Assessment Procedure: [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_A_5_1_1/home?element=SR-05 SR-05]&lt;br /&gt;
&lt;br /&gt;
{{anchor|d30e7941-Head3}}{{anchor|sec-sec_03.17.03}}=== 03.17.03 Supply Chain Requirements and Processes ===&lt;br /&gt;
&lt;br /&gt;
==== ASSESSMENT OBJECTIVE ====&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Determine if:&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.17.03.ODP[01]}}A.03.17.03.ODP&amp;amp;#91;01&amp;amp;#93;: &#039;&#039;&#039;&amp;lt;nowiki/&amp;gt;&#039;&#039;&#039;&#039;&#039;security requirements to protect against supply chain risks to the system, system components, or system services and to limit the harm or consequences from supply chain-related events are defined&#039;&#039;&#039;&#039;&#039;&amp;lt;nowiki/&amp;gt;&#039;&#039;&#039;.&#039;&#039;&#039;&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.17.03.a[01]}}A.03.17.03.a&amp;amp;#91;01&amp;amp;#93;:&#039;&#039;&#039; a process for identifying weaknesses or deficiencies in the supply chain elements and processes is established.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.17.03.a[02]}}A.03.17.03.a&amp;amp;#91;02&amp;amp;#93;:&#039;&#039;&#039; a process for addressing weaknesses or deficiencies in the supply chain elements and processes is established.&lt;br /&gt;
* &#039;&#039;&#039;{{anchor|A.03.17.03.b}}A.03.17.03.b:&#039;&#039;&#039; the following security requirements are enforced to protect against supply chain risks to the system, system components, or system services and to limit the harm or consequences of supply chain-related events: &#039;&#039;&#039;&#039;&#039;&amp;lt;A.03.17.03.ODP&amp;amp;#91;01&amp;amp;#93;: security requirements&amp;gt;&#039;&#039;&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
==== ASSESSMENT METHODS AND OBJECTS ====&lt;br /&gt;
&lt;br /&gt;
===== Examine =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: SCRM policy and procedures; SCRM strategy; SCRM plan; systems and critical system components inventory documentation; system and services acquisition policy and procedures; procedures for the integration of security requirements into the acquisition process; solicitation documentation; acquisition documentation (including purchase orders); shipping and handling procedures; configuration management documentation and records; acquisition contracts for systems or services; service-level agreements; risk register documentation; system security plan; other relevant documents or records&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
===== Interview =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: personnel with acquisition responsibilities; personnel with information security responsibilities; personnel with SCRM responsibilities&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
===== Test =====&lt;br /&gt;
&lt;br /&gt;
&amp;amp;#91;SELECT FROM: processes for identifying and addressing supply chain element and process deficiencies&amp;amp;#93;&lt;br /&gt;
&lt;br /&gt;
==== REFERENCES ====&lt;br /&gt;
&lt;br /&gt;
Source Assessment Procedure: [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_A_5_1_1/home?element=SR-03 SR-03]&lt;br /&gt;
&lt;br /&gt;
{{anchor|d30e8005-BiblioHead}}References&lt;br /&gt;
&lt;br /&gt;
{{anchor|bibr-ref_1}}&amp;amp;#91;1&amp;amp;#93; Federal Information Security Modernization Act (P.L. 113-283), December 2014. Available at https://www.govinfo.gov/app/details/PLAW-113publ283&lt;br /&gt;
&lt;br /&gt;
{{anchor|bibr-ref_2}}&amp;amp;#91;2&amp;amp;#93; Office of Management and Budget Memorandum Circular A-130, Managing Information as a Strategic Resource, July 2016. Available at https://www.whitehouse.gov/wp-content/uploads/legacy_drupal_files/omb/circulars/A130/a130revised.pdf&lt;br /&gt;
&lt;br /&gt;
{{anchor|bibr-ref_3}}&amp;amp;#91;3&amp;amp;#93; Ross RS, Pillitteri VY, (2024) Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations. (National Institute of Standards and Technology, Gaithersburg, MD), NIST Special Publication (SP) NIST SP 800-171r3. https://doi.org/10.6028/NIST.SP.800-171r3&lt;br /&gt;
&lt;br /&gt;
{{anchor|bibr-ref_4}}&amp;amp;#91;4&amp;amp;#93; Joint Task Force Transformation Initiative (2011) Managing Information Security Risk: Organization, Mission, and Information System View. (National Institute of Standards and Technology, Gaithersburg, MD), NIST Special Publication ( SP) 800-39. https://doi.org/10.6028/NIST.SP.800-39&lt;br /&gt;
&lt;br /&gt;
{{anchor|bibr-ref_5}}&amp;amp;#91;5&amp;amp;#93; Joint Task Force (2022) Assessing Security and Privacy Controls in Information Systems and Organizations. (National Institute of Standards and Technology, Gaithersburg, MD), NIST Special Publication (SP) 800-53A, Rev. 5. https://doi.org/10.6028/NIST.SP.800-53Ar5&lt;br /&gt;
&lt;br /&gt;
{{anchor|bibr-ref_6}}&amp;amp;#91;6&amp;amp;#93; International Organization for Standardization/International Electrotechnical Commission 15408-3:2017, Information technology — Security techniques — Evaluation criteria for IT security — Part 3: Security assurance requirements, April 2017. https://www.commoncriteriaportal.org/files/ccfiles/CCPART3V3.1R5.pdf&lt;br /&gt;
&lt;br /&gt;
{{anchor|bibr-ref_7}}&amp;amp;#91;7&amp;amp;#93; National Institute of Standards and Technology (2019) Security Requirements for Cryptographic Modules. (U.S. Department of Commerce, Washington, D.C.), Federal Information Processing Standards Publication (FIPS) 140-3. https://doi.org/10.6028/NIST.FIPS.140-3&lt;br /&gt;
&lt;br /&gt;
{{anchor|bibr-ref_8}}&amp;amp;#91;8&amp;amp;#93; Joint Task Force (2020) Security and Privacy Controls for Information Systems and Organizations. (National Institute of Standards and Technology, Gaithersburg, MD), NIST Special Publication (SP) 800-53, Rev. 5, Includes updates as of December 10, 2020. https://doi.org/10.6028/NIST.SP.800-53r5&lt;br /&gt;
&lt;br /&gt;
{{anchor|bibr-ref_9}}&amp;amp;#91;9&amp;amp;#93; Committee on National Security Systems (2022) Committee on National Security Systems (CNSS) Glossary. (National Security Agency, Fort George G. Meade, MD), CNSS Instruction 4009. Available at https://www.cnss.gov/CNSS/issuances/Instructions.cfm&lt;br /&gt;
&lt;br /&gt;
{{anchor|bibr-ref_10}}&amp;amp;#91;10&amp;amp;#93; Executive Order 13556 (2010) Controlled Unclassified Information. (The White House, 2340 Washington, DC), DCPD-201000942, November 4, 2010. Available at https://www.govinfo.gov/app/details/DCPD-201000942&lt;br /&gt;
&lt;br /&gt;
{{anchor|d30e8109-Appendix_Title}}{{anchor|sec-sec_A}}== Appendix A : Acronyms ==&lt;br /&gt;
&lt;br /&gt;
; CNSS&lt;br /&gt;
: Committee on National Security Systems&lt;br /&gt;
; CUI&lt;br /&gt;
: Controlled Unclassified Information&lt;br /&gt;
; FIPS&lt;br /&gt;
: Federal Information Processing Standards&lt;br /&gt;
; FISMA&lt;br /&gt;
: Federal Information Security Modernization Act&lt;br /&gt;
; GRC&lt;br /&gt;
: Governance, Risk, and Compliance&lt;br /&gt;
; ODP&lt;br /&gt;
: Organization-Defined Parameter&lt;br /&gt;
; OSCAL&lt;br /&gt;
: Open Security Controls Assessment Language&lt;br /&gt;
; SCRM&lt;br /&gt;
: Supply Chain Risk Management&lt;br /&gt;
; SDLC&lt;br /&gt;
: System Development Life Cycle&lt;br /&gt;
&lt;br /&gt;
{{anchor|d30e8150-Appendix_Title}}{{anchor|sec-sec_B}}== Appendix B : Glossary ==&lt;br /&gt;
&lt;br /&gt;
[[#sec-sec_B|Appendix B]] provides definitions for the terminology used in SP 800-171A. The definitions are consistent with the definitions contained in the Committee on National Security Systems (CNSS) Glossary &amp;amp;#91;[[#bibr-ref_9|9]]&amp;amp;#93; unless otherwise noted.&lt;br /&gt;
&lt;br /&gt;
; agency&lt;br /&gt;
: Any executive agency or department, military department, Federal Government corporation, Federal Government-controlled corporation, or other establishment in the Executive Branch of the Federal Government, or any independent regulatory agency. &amp;amp;#91;[[#bibr-ref_2|&amp;lt;u&amp;gt;2&amp;lt;/u&amp;gt;]]&amp;amp;#93;&lt;br /&gt;
; assessment&lt;br /&gt;
: See &#039;&#039;security control assessment&#039;&#039;.&lt;br /&gt;
; assessor&lt;br /&gt;
: See &#039;&#039;security control assessor&#039;&#039;.&lt;br /&gt;
; controlled unclassified information&lt;br /&gt;
: Information that law, regulation, or governmentwide policy requires to have safeguarding or disseminating controls, excluding information that is classified under Executive Order 13526, Classified National Security Information, December 29, 2009, or any predecessor or successor order, or the Atomic Energy Act of 1954, as amended. &amp;amp;#91;[[#bibr-ref_10|&amp;lt;u&amp;gt;10&amp;lt;/u&amp;gt;]]&amp;amp;#93;&lt;br /&gt;
; information&lt;br /&gt;
: Any communication or representation of knowledge such as facts, data, or opinions in any medium or form, including textual, numerical, graphic, cartographic, narrative, electronic, or audiovisual forms. &amp;amp;#91;[[#bibr-ref_2|&amp;lt;u&amp;gt;2&amp;lt;/u&amp;gt;]]&amp;amp;#93;&lt;br /&gt;
; nonfederal organization&lt;br /&gt;
: An entity that owns, operates, or maintains a nonfederal system.&lt;br /&gt;
; nonfederal system&lt;br /&gt;
: A system that does not meet the criteria for a federal system.&lt;br /&gt;
; risk&lt;br /&gt;
: A measure of the extent to which an entity is threatened by a potential circumstance or event, and typically is a function of: (i) the adverse impact, or magnitude of harm, that would arise if the circumstance or event occurs; and (ii) the likelihood of occurrence. &amp;amp;#91;[[#bibr-ref_2|&amp;lt;u&amp;gt;2&amp;lt;/u&amp;gt;]]&amp;amp;#93;&lt;br /&gt;
; security&lt;br /&gt;
: A condition that results from the establishment and maintenance of protective measures that enable an organization to perform its mission or critical functions despite risks posed by threats to its use of systems. Protective measures may involve a combination of deterrence, avoidance, prevention, detection, recovery, and correction that should form part of the organization’s risk management approach. &amp;amp;#91;[[#bibr-ref_9|&amp;lt;u&amp;gt;9&amp;lt;/u&amp;gt;]]&amp;amp;#93;&lt;br /&gt;
; security assessment S&lt;br /&gt;
: ee &#039;&#039;security control assessment&#039;&#039;.&lt;br /&gt;
; security control&lt;br /&gt;
: The safeguards or countermeasures prescribed for an information system or an organization to protect the confidentiality, integrity, and availability of the system and its information. &amp;amp;#91;[[#bibr-ref_2|&amp;lt;u&amp;gt;2&amp;lt;/u&amp;gt;]]&amp;amp;#93;&lt;br /&gt;
; security control assessment&lt;br /&gt;
: The testing or evaluation of security controls to determine the extent to which the controls are implemented correctly, operating as intended, and producing the desired outcome with respect to meeting the security requirements for an information system or organization. &amp;amp;#91;[[#bibr-ref_2|&amp;lt;u&amp;gt;2&amp;lt;/u&amp;gt;]]&amp;amp;#93;&lt;br /&gt;
; system&lt;br /&gt;
: See &#039;&#039;information system&#039;&#039;.&lt;br /&gt;
; system security plan&lt;br /&gt;
: A document that describes how an organization meets or plans to meet the security requirements for a system. In particular, the system security plan describes the system boundary, the environment in which the system operates, how the security requirements are satisfied, and the relationships with or connections to other systems.&lt;br /&gt;
&lt;br /&gt;
{{anchor|d30e8258-Appendix_Title}}{{anchor|sec-sec_C}}== Appendix C : Security Requirement Assessment ==&lt;br /&gt;
&lt;br /&gt;
This appendix provides an overview of the process for assessing the security requirements in SP 800-171 &amp;amp;#91;[[#bibr-ref_3|3]]&amp;amp;#93;. The four-phase process is based on the methodology in SP 800-53A &amp;amp;#91;[[#bibr-ref_5|5]]&amp;amp;#93;{{anchor|footnote-6-backlink}}[[#footnote-6|6]] and includes:&lt;br /&gt;
&lt;br /&gt;
* Preparing for assessments&lt;br /&gt;
* Developing assessment plans&lt;br /&gt;
* Conducting assessments&lt;br /&gt;
* Analyzing, documenting, and reporting assessment results&lt;br /&gt;
&lt;br /&gt;
=== {{anchor|sec-sec_C.1}}C.1 Preparing for Assessments ===&lt;br /&gt;
&lt;br /&gt;
Thorough preparation by the organization and assessors is an important aspect of conducting an effective assessment. Preparatory activities address a range of issues relating to the cost, schedule, and conduct of the assessment. From an organizational perspective, preparing for an assessment includes the following activities:&lt;br /&gt;
&lt;br /&gt;
* Ensuring that appropriate policies that cover the assessment are in place and understood by affected organizational elements&lt;br /&gt;
* Establishing the objective and scope of the assessment (i.e., the purpose of the assessment and what is being assessed)&lt;br /&gt;
* Notifying appropriate organizational officials of the impending assessment and allocating the necessary resources to carry out the assessment&lt;br /&gt;
* Establishing appropriate communication channels among organizational officials with an interest in the assessment&lt;br /&gt;
* Establishing the time frame for completing the assessment and the key milestone decision points required by the organization&lt;br /&gt;
* Identifying and selecting the assessors who will be responsible for conducting the assessment and considering issues of assessor independence&lt;br /&gt;
* Providing artifacts to the assessors (e.g., policies, procedures, plans, specifications, designs, records, administrator/operator manuals, information exchange agreements, system documentation, previous assessment results, legal requirements)&lt;br /&gt;
* Establishing a mechanism between the organization and the assessors to minimize ambiguities or misunderstandings about the security requirements, implementation issues, and deficiencies identified during the assessment&lt;br /&gt;
&lt;br /&gt;
Assessors begin preparing for the assessment by:&lt;br /&gt;
&lt;br /&gt;
* Developing a general understanding of the organization’s operations and how the scope of the assessment supports those organizational operations&lt;br /&gt;
* Understanding the structure of the system (i.e., the system architecture) and the security requirements being assessed&lt;br /&gt;
* Meeting with organizational officials to ensure that there is a common understanding of the assessment objectives and the proposed rigor and scope of the assessment&lt;br /&gt;
* Obtaining the artifacts needed for the assessment (e.g., policies, procedures, plans, specifications, administrator/operator manuals, system documentation, information exchange agreements, designs, records, previous assessment results{{anchor|footnote-7-backlink}}[[#footnote-7|7]])&lt;br /&gt;
* Establishing organizational points of contact to carry out the assessment&lt;br /&gt;
&lt;br /&gt;
[[#table-tab_2|Table 2]] provides a summary of the purpose and expected outcomes of the &#039;&#039;assessment preparation phase&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;{{anchor|d30e8362}}Table 2. Summary of Assessment Preparation Phase&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! &#039;&#039;&#039;PURPOSE&#039;&#039;&#039; !! &#039;&#039;&#039;Address a range of issues pertaining to the cost, schedule, scope, and conduct of the assessment.&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;OUTCOMES&#039;&#039;&#039; || • The objective, scope, and time frame of the assessment are determined.&amp;lt;br/&amp;gt;• Key organizational stakeholders are notified, and the necessary resources are allocated.&amp;lt;br/&amp;gt;• Assessors are identified and selected.&amp;lt;br/&amp;gt;• Artifacts are collected and provided to assessors.&amp;lt;br/&amp;gt;• Mechanisms to minimize ambiguities and misunderstandings about the security requirements, implementation issues, and weaknesses/deficiencies identified during the assessment are established.&amp;lt;br/&amp;gt;• The organization’s operations, structure, objective, scope, and time frame of assessment are understood by assessors.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== {{anchor|sec-sec_C.2}}C.2 Developing Assessment Plans ===&lt;br /&gt;
&lt;br /&gt;
The assessment plan establishes the objectives for the security requirement assessment and a detailed roadmap of how to conduct the assessment based on the system security plan. The following steps are considered by assessors when developing an assessment plan:&lt;br /&gt;
&lt;br /&gt;
* Determine which security requirements are to be included in the assessment based on the contents of the system security plan and the purpose and scope of the assessment.&lt;br /&gt;
* Select the appropriate assessment procedures.&lt;br /&gt;
* Tailor the selected assessment procedures (e.g., select appropriate assessment methods and objects, and assign depth and coverage attribute values).{{anchor|footnote-8-backlink}}[[#footnote-8|8]]&lt;br /&gt;
* Optimize the assessment procedures to reduce the duplication of effort (e.g., sequence and consolidate assessment procedures) and provide a cost-effective assessment solution.&lt;br /&gt;
* Finalize the assessment plan, and obtain the necessary approvals to execute the plan.&lt;br /&gt;
&lt;br /&gt;
[[#table-tab_3|Table 3]] provides a summary of the purpose and expected outcomes of the &#039;&#039;assessment plan development phase&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;{{anchor|d30e8446}}Table 3. Summary of Assessment Plan Development Phase&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! &#039;&#039;&#039;PURPOSE&#039;&#039;&#039; !! &#039;&#039;&#039;Establish the objectives for the security requirement assessment and a detailed roadmap of how to conduct the assessment based on the system security plan.&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;OUTCOMES&#039;&#039;&#039; || • Security requirements to be included in the assessment are determined.&amp;lt;br/&amp;gt;• Assessment procedures are selected and tailored.&amp;lt;br/&amp;gt;• Assessment procedures are optimized to reduce the duplication of effort.&amp;lt;br/&amp;gt;• The assessment plan is finalized, and organizational approvals are obtained.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== {{anchor|sec-sec_C.3}}C.3 Conducting Assessments ===&lt;br /&gt;
&lt;br /&gt;
After the assessment plan is approved by the organization, the assessors execute the plan in accordance with the agreed-upon schedule. Assessment objectives are achieved by applying the designated assessment methods to selected assessment objects and compiling or producing the evidence necessary to make the determination associated with each assessment objective. Each determination statement contained within an assessment procedure executed by an assessor produces one of the following findings:&lt;br /&gt;
&lt;br /&gt;
* Satisfied or&lt;br /&gt;
* Other than satisfied.&lt;br /&gt;
&lt;br /&gt;
A finding of &#039;&#039;satisfied&#039;&#039; indicates that the assessment objective for the security requirement (or subset of the requirement) addressed by the determination statement has been met and produced an acceptable result. A finding of &#039;&#039;other than satisfied&#039;&#039; indicates that the assessment objective for the requirement has not been met and has produced an unacceptable result. A finding of &#039;&#039;other than satisfied&#039;&#039; may also indicate that the assessor was unable to obtain sufficient information to make the determination called for in the determination statement.&lt;br /&gt;
&lt;br /&gt;
[[#table-tab_4|Table 4]] provides a summary of the purpose and expected outcomes of the &#039;&#039;assessment execution phase&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;{{anchor|d30e8523}}Table 4. Summary of Assessment Execution Phase&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! &#039;&#039;&#039;PURPOSE&#039;&#039;&#039; !! &#039;&#039;&#039;Conduct the assessment in accordance with the assessment plan, and document the results in an assessment report.&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;OUTCOMES&#039;&#039;&#039; || • Security requirements are assessed in accordance with the assessment plan.&amp;lt;br/&amp;gt;• An assessment report that documents whether the security requirements have been satisfied is produced.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== {{anchor|sec-sec_C.4}}C.4 Analyzing, Documenting, and Reporting Assessment Results ===&lt;br /&gt;
&lt;br /&gt;
The assessment report includes information from assessors (in the form of findings) that is necessary to determine whether the security requirements in SP 800-171 have been satisfied.{{anchor|footnote-9-backlink}}[[#footnote-9|9]] The report conveys the results of the assessment to designated organizational officials. The report can also provide recommendations for correcting any deficiencies discovered during the assessment. Depending on the organization’s objective for the assessment, the assessment results can trigger a variety of risk response actions, including risk acceptance, risk mitigation, risk rejection, risk transfer, or risk sharing. The assessment results can also influence changes to the system security plan and plan of action and milestones.&lt;br /&gt;
&lt;br /&gt;
[[#table-tab_5|Table 5]] provides a summary of the purpose and expected outcomes of the &#039;&#039;assessment analysis, documentation, and reporting phase&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;{{anchor|d30e8581}}Table 5. Summary of Assessment Analysis, Documentation, and Reporting Phase&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! &#039;&#039;&#039;PURPOSE&#039;&#039;&#039; !! &#039;&#039;&#039;Analyze the risks that result from the weaknesses and deficiencies identified during the assessment, and determine an approach to respond to those risks in accordance with organizational priorities.&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;OUTCOMES&#039;&#039;&#039; || • Assessment findings are reviewed and analyzed.&amp;lt;br/&amp;gt;• Subsequent risk responses are initiated to manage risks.&amp;lt;br/&amp;gt;• The system security plan and plan of action and milestones are updated to reflect the results of the assessment and any subsequent risk response actions.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
{{anchor|d30e8621-Appendix_Title}}{{anchor|sec-sec_D}}== Appendix D : Organization-Defined Parameters ==&lt;br /&gt;
&lt;br /&gt;
This appendix lists the organization-defined parameters (ODPs) that are included in the assessment procedures in Sec. 3. The ODPs are listed sequentially by requirement family, beginning with the first requirement containing an ODP in the Access Control (AC) family and ending with the last requirement containing an ODP in the Supply Chain Risk Management (SR) family.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;{{anchor|d30e8626}}Table 6. Organization-Defined Parameters&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! &#039;&#039;&#039;SECURITY REQUIREMENT&#039;&#039;&#039; !! colspan=&amp;quot;2&amp;quot; | &#039;&#039;&#039;ORGANIZATION-DEFINED PARAMETER&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [[#sec-sec_03.01.01|03.01.01]] || [[#A.03.01.01.ODP[01]|A.03.01.01.ODP&amp;amp;#91;01&amp;amp;#93;]] || &#039;&#039;the time period for account inactivity before disabling is defined.&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [[#sec-sec_03.01.01|03.01.01]] || [[#A.03.01.01.ODP[02]|A.03.01.01.ODP&amp;amp;#91;02&amp;amp;#93;]] || &#039;&#039;the time period within which to notify account managers and designated personnel or roles when accounts are no longer required is defined.&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [[#sec-sec_03.01.01|03.01.01]] || [[#A.03.01.01.ODP[03]|A.03.01.01.ODP&amp;amp;#91;03&amp;amp;#93;]] || &#039;&#039;the time period within which to notify account managers and designated personnel or roles when users are terminated or transferred is defined.&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [[#sec-sec_03.01.01|03.01.01]] || [[#A.03.01.01.ODP[04]|A.03.01.01.ODP&amp;amp;#91;04&amp;amp;#93;]] || &#039;&#039;the time period within which to notify account managers and designated personnel or roles when system usage or the need-to-know changes for an individual is defined.&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [[#sec-sec_03.01.01|03.01.01]] || [[#A.03.01.01.ODP[05]|A.03.01.01.ODP&amp;amp;#91;05&amp;amp;#93;]] || &#039;&#039;the time period of expected inactivity requiring users to log out of the system is defined.&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [[#sec-sec_03.01.01|03.01.01]] || [[#A.03.01.01.ODP[06]|A.03.01.01.ODP&amp;amp;#91;06&amp;amp;#93;]] || &#039;&#039;circumstances requiring users to log out of the system are defined.&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [[#sec-sec_03.01.05|03.01.05]] || [[#A.03.01.05.ODP[01]|A.03.01.05.ODP&amp;amp;#91;01&amp;amp;#93;]] || &#039;&#039;security functions for authorized access are defined.&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [[#sec-sec_03.01.05|03.01.05]] || [[#A.03.01.05.ODP[02]|A.03.01.05.ODP&amp;amp;#91;02&amp;amp;#93;]] || &#039;&#039;security-relevant information for authorized access is defined.&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [[#sec-sec_03.01.05|03.01.05]] || [[#A.03.01.05.ODP[03]|A.03.01.05.ODP&amp;amp;#91;03&amp;amp;#93;]] || &#039;&#039;the frequency at which to review the privileges assigned to roles or classes of users is defined.&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [[#sec-sec_03.01.06|03.01.06]] || [[#A.03.01.06.ODP[01]|A.03.01.06.ODP&amp;amp;#91;01&amp;amp;#93;]] || &#039;&#039;personnel or roles to which privileged accounts on the system are to be restricted are defined.&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [[#sec-sec_03.01.08|03.01.08]] || [[#A.03.01.08.ODP[01]|A.03.01.08.ODP&amp;amp;#91;01&amp;amp;#93;]] || &#039;&#039;the number of consecutive invalid logon attempts by a user allowed during a time period is defined.&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [[#sec-sec_03.01.08|03.01.08]] || [[#A.03.01.08.ODP[02]|A.03.01.08.ODP&amp;amp;#91;02&amp;amp;#93;]] || &#039;&#039;the time period to which the number of consecutive invalid logon attempts by a user is limited is defined.&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [[#sec-sec_03.01.08|03.01.08]] || [[#A.03.01.08.ODP[03]|A.03.01.08.ODP&amp;amp;#91;03&amp;amp;#93;]] || &#039;&#039;one or more of the following PARAMETER VALUES are selected: &amp;amp;#123;the account or node is locked automatically for &amp;lt;A.03.01.08.ODP&amp;amp;#91;04&amp;amp;#93;: time period&amp;gt;; the account or node is locked automatically until released by an administrator; the next logon prompt is delayed automatically; the system administrator is notified automatically; other action is taken automatically&amp;amp;#125;.&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [[#sec-sec_03.01.08|03.01.08]] || [[#A.03.01.08.ODP[04]|A.03.01.08.ODP&amp;amp;#91;04&amp;amp;#93;]] || &#039;&#039;the time period for an account or node to be locked is defined (if selected).&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [[#sec-sec_03.01.10|03.01.10]] || [[#A.03.01.10.ODP[01]|A.03.01.10.ODP&amp;amp;#91;01&amp;amp;#93;]] || &#039;&#039;one or more of the following PARAMETER VALUES are selected: &amp;amp;#123;a device lock is initiated after &amp;lt;A.03.01.10.ODP&amp;amp;#91;02&amp;amp;#93;: time period&amp;gt; of inactivity; the user is required to initiate a device lock before leaving the system unattended&amp;amp;#125;.&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [[#sec-sec_03.01.10|03.01.10]] || [[#A.03.01.10.ODP[02]|A.03.01.10.ODP&amp;amp;#91;02&amp;amp;#93;]] || &#039;&#039;the time period of inactivity after which a device lock is initiated is defined (if selected).&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [[#sec-sec_03.01.11|03.01.11]] || [[#A.03.01.11.ODP[01]|A.03.01.11.ODP&amp;amp;#91;01&amp;amp;#93;]] || &#039;&#039;conditions or trigger events that require session disconnect are defined.&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [[#sec-sec_03.01.20|03.01.20]] || [[#A.03.01.20.ODP[01]|A.03.01.20.ODP&amp;amp;#91;01&amp;amp;#93;]] || &#039;&#039;security requirements to be satisfied on external systems prior to allowing the use of or access to those systems by authorized individuals are defined.&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [[#sec-sec_03.02.01|03.02.01]] || [[#A.03.02.01.ODP[01]|A.03.02.01.ODP&amp;amp;#91;01&amp;amp;#93;]] || &#039;&#039;the frequency at which to provide security literacy training to system users after initial training is defined.&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [[#sec-sec_03.02.01|03.02.01]] || [[#A.03.02.01.ODP[02]|A.03.02.01.ODP&amp;amp;#91;02&amp;amp;#93;]] || &#039;&#039;events that require security literacy training for system users are defined.&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [[#sec-sec_03.02.01|03.02.01]] || [[#A.03.02.01.ODP[03]|A.03.02.01.ODP&amp;amp;#91;03&amp;amp;#93;]] || &#039;&#039;the frequency at which to update security literacy training content is defined.&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [[#sec-sec_03.02.01|03.02.01]] || [[#A.03.02.01.ODP[04]|A.03.02.01.ODP&amp;amp;#91;04&amp;amp;#93;]] || &#039;&#039;events that require security literacy training content updates are defined.&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [[#sec-sec_03.02.02|03.02.02]] || [[#A.03.02.02.ODP[01]|A.03.02.02.ODP&amp;amp;#91;01&amp;amp;#93;]] || &#039;&#039;the frequency at which to provide role-based security training to assigned personnel after initial training is defined.&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [[#sec-sec_03.02.02|03.02.02]] || [[#A.03.02.02.ODP[02]|A.03.02.02.ODP&amp;amp;#91;02&amp;amp;#93;]] || &#039;&#039;events that require role-based security training are defined.&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [[#sec-sec_03.02.02|03.02.02]] || [[#A.03.02.02.ODP[03]|A.03.02.02.ODP&amp;amp;#91;03&amp;amp;#93;]] || &#039;&#039;the frequency at which to update role-based security training content is defined.&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [[#sec-sec_03.02.02|03.02.02]] || [[#A.03.02.02.ODP[04]|A.03.02.02.ODP&amp;amp;#91;04&amp;amp;#93;]] || &#039;&#039;events that require role-based security training content updates are defined.&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [[#sec-sec_03.03.01|03.03.01]] || [[#A.03.03.01.ODP[01]|A.03.03.01.ODP&amp;amp;#91;01&amp;amp;#93;]] || &#039;&#039;event types selected for logging within the system are defined.&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [[#sec-sec_03.03.01|03.03.01]] || [[#A.03.03.01.ODP[02]|A.03.03.01.ODP&amp;amp;#91;02&amp;amp;#93;]] || &#039;&#039;the frequency of event types selected for logging are reviewed and updated.&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [[#sec-sec_03.03.04|03.03.04]] || [[#A.03.03.04.ODP[01]|A.03.03.04.ODP&amp;amp;#91;01&amp;amp;#93;]] || &#039;&#039;the time period for organizational personnel or roles receiving audit logging process failure alerts is defined.&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [[#sec-sec_03.03.04|03.03.04]] || [[#A.03.03.04.ODP[02]|A.03.03.04.ODP&amp;amp;#91;02&amp;amp;#93;]] || &#039;&#039;additional actions to be taken in the event of an audit logging process failure are defined.&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [[#sec-sec_03.03.05|03.03.05]] || [[#A.03.03.05.ODP[01]|A.03.03.05.ODP&amp;amp;#91;01&amp;amp;#93;]] || &#039;&#039;the frequency at which system audit records are reviewed and analyzed is defined.&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [[#sec-sec_03.03.07|03.03.07]] || [[#A.03.03.07.ODP[01]|A.03.03.07.ODP&amp;amp;#91;01&amp;amp;#93;]] || &#039;&#039;granularity of time measurement for audit record time stamps is defined.&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [[#sec-sec_03.04.01|03.04.01]] || [[#A.03.04.01.ODP[01]|A.03.04.01.ODP&amp;amp;#91;01&amp;amp;#93;]] || &#039;&#039;the frequency of baseline configuration review and update is defined.&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [[#sec-sec_03.04.02|03.04.02]] || [[#A.03.04.02.ODP[01]|A.03.04.02.ODP&amp;amp;#91;01&amp;amp;#93;]] || &#039;&#039;configuration settings for the system that reflect the most restrictive mode consistent with operational requirements are defined.&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [[#sec-sec_03.04.06|03.04.06]] || [[#A.03.04.06.ODP[01]|A.03.04.06.ODP&amp;amp;#91;01&amp;amp;#93;]] || &#039;&#039;functions to be prohibited or restricted are defined.&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [[#sec-sec_03.04.06|03.04.06]] || [[#A.03.04.06.ODP[02]|A.03.04.06.ODP&amp;amp;#91;02&amp;amp;#93;]] || &#039;&#039;ports to be prohibited or restricted are defined.&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [[#sec-sec_03.04.06|03.04.06]] || [[#A.03.04.06.ODP[03]|A.03.04.06.ODP&amp;amp;#91;03&amp;amp;#93;]] || &#039;&#039;protocols to be prohibited or restricted are defined.&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [[#sec-sec_03.04.06|03.04.06]] || [[#A.03.04.06.ODP[04]|A.03.04.06.ODP&amp;amp;#91;04&amp;amp;#93;]] || &#039;&#039;connections to be prohibited or restricted are defined.&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [[#sec-sec_03.04.06|03.04.06]] || [[#A.03.04.06.ODP[05]|A.03.04.06.ODP&amp;amp;#91;05&amp;amp;#93;]] || &#039;&#039;services to be prohibited or restricted are defined.&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [[#sec-sec_03.04.06|03.04.06]] || [[#A.03.04.06.ODP[06]|A.03.04.06.ODP&amp;amp;#91;06&amp;amp;#93;]] || &#039;&#039;the frequency at which to review the system to identify unnecessary or nonsecure functions, ports, protocols, connections, or services is defined. &#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [[#sec-sec_03.04.08|03.04.08]] || [[#A.03.04.08.ODP[01]|A.03.04.08.ODP&amp;amp;#91;01&amp;amp;#93;]] || &#039;&#039;the frequency at which to review and update the list of authorized software programs is defined.&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [[#sec-sec_03.04.10|03.04.10]] || [[#A.03.04.10.ODP[01]|A.03.04.10.ODP&amp;amp;#91;01&amp;amp;#93;]] || &#039;&#039;the frequency at which to review and update the system component inventory is defined.&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [[#sec-sec_03.04.12|03.04.12]] || [[#A.03.04.12.ODP[01]|A.03.04.12.ODP&amp;amp;#91;01&amp;amp;#93;]] || &#039;&#039;configurations for systems or system components to be issued to individuals traveling to high-risk locations are defined.&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [[#sec-sec_03.04.12|03.04.12]] || [[#A.03.04.12.ODP[02]|A.03.04.12.ODP&amp;amp;#91;02&amp;amp;#93;]] || &#039;&#039;security requirements to be applied to the system or system components when individuals return from travel are defined.&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [[#sec-sec_03.05.01|03.05.01]] || [[#A.03.05.01.ODP[01]|A.03.05.01.ODP&amp;amp;#91;01&amp;amp;#93;]] || &#039;&#039;circumstances or situations that require re-authentication are defined.&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [[#sec-sec_03.05.02|03.05.02]] || [[#A.03.05.02.ODP[01]|A.03.05.02.ODP&amp;amp;#91;01&amp;amp;#93;]] || &#039;&#039;devices or types of devices to be uniquely identified and authenticated before establishing a connection are defined.&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [[#sec-sec_03.05.05|03.05.05]] || [[#A.03.05.05.ODP[01]|A.03.05.05.ODP&amp;amp;#91;01&amp;amp;#93;]] || &#039;&#039;the time period for preventing the reuse of identifiers is defined.&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [[#sec-sec_03.05.05|03.05.05]] || [[#A.03.05.05.ODP[02]|A.03.05.05.ODP&amp;amp;#91;02&amp;amp;#93;]] || &#039;&#039;characteristics used to identify individual status are defined.&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [[#sec-sec_03.05.07|03.05.07]] || [[#A.03.05.07.ODP[01]|A.03.05.07.ODP&amp;amp;#91;01&amp;amp;#93;]] || &#039;&#039;the frequency at which to update the list of commonly used, expected, or compromised passwords is defined.&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [[#sec-sec_03.05.07|03.05.07]] || [[#A.03.05.07.ODP[02]|A.03.05.07.ODP&amp;amp;#91;02&amp;amp;#93;]] || &#039;&#039;password composition and complexity rules are defined.&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [[#sec-sec_03.05.12|03.05.12]] || [[#A.03.05.12.ODP[01]|A.03.05.12.ODP&amp;amp;#91;01&amp;amp;#93;]] || &#039;&#039;the frequency for changing or refreshing authenticators is defined.&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [[#sec-sec_03.05.12|03.05.12]] || [[#A.03.05.12.ODP[02]|A.03.05.12.ODP&amp;amp;#91;02&amp;amp;#93;]] || &#039;&#039;events that trigger the change or refreshment of authenticators are defined.&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [[#sec-sec_03.06.02|03.06.02]] || [[#A.03.06.02.ODP[01]|A.03.06.02.ODP&amp;amp;#91;01&amp;amp;#93;]] || &#039;&#039;the time period to report suspected incidents to the organizational incident response capability is defined.&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [[#sec-sec_03.06.02|03.06.02]] || [[#A.03.06.02.ODP[02]|A.03.06.02.ODP&amp;amp;#91;02&amp;amp;#93;]] || &#039;&#039;authorities to whom incident information is to be reported are defined.&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [[#sec-sec_03.06.03|03.06.03]] || [[#A.03.06.03.ODP[01]|A.03.06.03.ODP&amp;amp;#91;01&amp;amp;#93;]] || &#039;&#039;the frequency at which to test the effectiveness of the incident response capability for the system is defined.&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [[#sec-sec_03.06.04|03.06.04]] || [[#A.03.06.04.ODP[01]|A.03.06.04.ODP&amp;amp;#91;01&amp;amp;#93;]] || &#039;&#039;the time period within which incident response training is to be provided to system users is defined.&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [[#sec-sec_03.06.04|03.06.04]] || [[#A.03.06.04.ODP[02]|A.03.06.04.ODP&amp;amp;#91;02&amp;amp;#93;]] || &#039;&#039;the frequency at which to provide incident response training to users is defined.&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [[#sec-sec_03.06.04|03.06.04]] || [[#A.03.06.04.ODP[03]|A.03.06.04.ODP&amp;amp;#91;03&amp;amp;#93;]] || &#039;&#039;the frequency at which to review and update incident response training content is defined.&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [[#sec-sec_03.06.04|03.06.04]] || [[#A.03.06.04.ODP[04]|A.03.06.04.ODP&amp;amp;#91;04&amp;amp;#93;]] || &#039;&#039;events that initiate a review of the incident response training content are defined.&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [[#sec-sec_03.08.07|03.08.07]] || [[#A.03.08.07.ODP[01]|A.03.08.07.ODP&amp;amp;#91;01&amp;amp;#93;]] || &#039;&#039;types of system media with usage restrictions or that are prohibited from use are defined.&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [[#sec-sec_03.09.01|03.09.01]] || [[#A.03.09.01.ODP[01]|A.03.09.01.ODP&amp;amp;#91;01&amp;amp;#93;]] || &#039;&#039;conditions that require the rescreening of individuals are defined.&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [[#sec-sec_03.09.02|03.09.02]] || [[#A.03.09.02.ODP[01]|A.03.09.02.ODP&amp;amp;#91;01&amp;amp;#93;]] || &#039;&#039;the time period within which to disable system access is defined.&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [[#sec-sec_03.10.01|03.10.01]] || [[#A.03.10.01.ODP[01]|A.03.10.01.ODP&amp;amp;#91;01&amp;amp;#93;]] || &#039;&#039;the frequency at which to review the access list detailing authorized facility access by individuals is defined.&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [[#sec-sec_03.10.02|03.10.02]] || [[#A.03.10.02.ODP[01]|A.03.10.02.ODP&amp;amp;#91;01&amp;amp;#93;]] || &#039;&#039;the frequency at which to review physical access logs is defined.&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [[#sec-sec_03.10.02|03.10.02]] || [[#A.03.10.02.ODP[02]|A.03.10.02.ODP&amp;amp;#91;02&amp;amp;#93;]] || &#039;&#039;events or potential indications of events requiring physical access logs to be reviewed are defined.&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [[#sec-sec_03.10.06|03.10.06]] || [[#A.03.10.06.ODP[01]|A.03.10.06.ODP&amp;amp;#91;01&amp;amp;#93;]] || &#039;&#039;security requirements to be employed at alternate work sites are defined.&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [[#sec-sec_03.11.01|03.11.01]] || [[#A.03.11.01.ODP[01]|A.03.11.01.ODP&amp;amp;#91;01&amp;amp;#93;]] || &#039;&#039;the frequency at which to update the risk assessment is defined.&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [[#sec-sec_03.11.02|03.11.02]] || [[#A.03.11.02.ODP[01]|A.03.11.02.ODP&amp;amp;#91;01&amp;amp;#93;]] || &#039;&#039;the frequency at which the system is monitored and scanned for vulnerabilities is defined.&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [[#sec-sec_03.11.02|03.11.02]] || [[#A.03.11.02.ODP[02]|A.03.11.02.ODP&amp;amp;#91;02&amp;amp;#93;]] || &#039;&#039;response times to remediate system vulnerabilities are defined.&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [[#sec-sec_03.11.02|03.11.02]] || [[#A.03.11.02.ODP[03]|A.03.11.02.ODP&amp;amp;#91;03&amp;amp;#93;]] || &#039;&#039;the frequency at which to update system vulnerabilities to be scanned is defined.&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [[#sec-sec_03.12.01|03.12.01]] || [[#A.03.12.01.ODP[01]|A.03.12.01.ODP&amp;amp;#91;01&amp;amp;#93;]] || &#039;&#039;the frequency at which to assess the security requirements for the system and its environment of operation is defined.&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [[#sec-sec_03.12.05|03.12.05]] || [[#A.03.12.05.ODP[01]|A.03.12.05.ODP&amp;amp;#91;01&amp;amp;#93;]] || &#039;&#039;one or more of the following PARAMETER VALUES are selected: &amp;amp;#123;interconnection security agreements; information exchange security agreements; memoranda of understanding or agreement; service-level agreements; user agreements; non-disclosure agreements; other types of agreements&amp;amp;#125;.&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [[#sec-sec_03.12.05|03.12.05]] || [[#A.03.12.05.ODP[02]|A.03.12.05.ODP&amp;amp;#91;02&amp;amp;#93;]] || &#039;&#039;the frequency at which to review and update agreements is defined.&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [[#sec-sec_03.13.09|03.13.09]] || [[#A.03.13.09.ODP[01]|A.03.13.09.ODP&amp;amp;#91;01&amp;amp;#93;]] || &#039;&#039;the time period of inactivity after which the system terminates a network connection associated with a communications session is defined.&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [[#sec-sec_03.13.10|03.13.10]] || [[#A.03.13.10.ODP[01]|A.03.13.10.ODP&amp;amp;#91;01&amp;amp;#93;]] || &#039;&#039;requirements for key generation, distribution, storage, access, and destruction are defined.&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [[#sec-sec_03.13.11|03.13.11]] || [[#A.03.13.11.ODP[01]|A.03.13.11.ODP&amp;amp;#91;01&amp;amp;#93;]] || &#039;&#039;the types of cryptography for protecting the confidentiality of CUI are defined.&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [[#sec-sec_03.13.12|03.13.12]] || [[#A.03.13.12.ODP[01]|A.03.13.12.ODP&amp;amp;#91;01&amp;amp;#93;]] || &#039;&#039;exceptions where remote activation is to be allowed are defined.&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [[#sec-sec_03.14.01|03.14.01]] || [[#A.03.14.01.ODP[01]|A.03.14.01.ODP&amp;amp;#91;01&amp;amp;#93;]] || &#039;&#039;the time period within which to install security-relevant software updates after the release of the updates is defined.&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [[#sec-sec_03.14.01|03.14.01]] || [[#A.03.14.01.ODP[02]|A.03.14.01.ODP&amp;amp;#91;02&amp;amp;#93;]] || &#039;&#039;the time period within which to install security-relevant firmware updates after the release of the updates is defined.&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [[#sec-sec_03.14.02|03.14.02]] || [[#A.03.14.02.ODP[01]|A.03.14.02.ODP&amp;amp;#91;01&amp;amp;#93;]] || &#039;&#039;the frequency at which malicious code protection mechanisms perform scans is defined.&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [[#sec-sec_03.15.01|03.15.01]] || [[#A.03.15.01.ODP[01]|A.03.15.01.ODP&amp;amp;#91;01&amp;amp;#93;]] || &#039;&#039;the frequency at which the policies and procedures for implementing security requirements are reviewed and updated is defined.&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [[#sec-sec_03.15.02|03.15.02]] || [[#A.03.15.02.ODP[01]|A.03.15.02.ODP&amp;amp;#91;01&amp;amp;#93;]] || &#039;&#039;the frequency at which the system security plan is reviewed and updated is defined.&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [[#sec-sec_03.15.03|03.15.03]] || [[#A.03.15.03.ODP[01]|A.03.15.03.ODP&amp;amp;#91;01&amp;amp;#93;]] || &#039;&#039;the frequency at which the rules of behavior are reviewed and updated is defined.&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [[#sec-sec_03.16.01|03.16.01]] || [[#A.03.16.01.ODP[01]|A.03.16.01.ODP&amp;amp;#91;01&amp;amp;#93;]] || &#039;&#039;systems security engineering principles to be applied to the development or modification of the system and system components are defined.&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [[#sec-sec_03.16.03|03.16.03]] || [[#A.03.16.03.ODP[01]|A.03.16.03.ODP&amp;amp;#91;01&amp;amp;#93;]] || &#039;&#039;security requirements to be satisfied by external system service providers are defined.&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [[#sec-sec_03.17.01|03.17.01]] || [[#A.03.17.01.ODP[01]|A.03.17.01.ODP&amp;amp;#91;01&amp;amp;#93;]] || &#039;&#039;the frequency at which to review and update the supply chain risk management plan is defined.&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [[#sec-sec_03.17.03|03.17.03]] || [[#A.03.17.03.ODP[01]|A.03.17.03.ODP&amp;amp;#91;01&amp;amp;#93;]] || &#039;&#039;security requirements to protect against supply chain risks to the system, system components, or system services and to limit the harm or consequences from supply chain-related events are defined.&#039;&#039;&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
{{anchor|d30e10309-Appendix_Title}}{{anchor|sec-sec_E}}== Appendix E : Change Log ==&lt;br /&gt;
&lt;br /&gt;
This publication incorporates the following changes from the original edition (June 2018):&lt;br /&gt;
&lt;br /&gt;
* Assessment procedures have been updated to be consistent with SP 800-171r3 (Revision 3) &amp;amp;#91;[[#bibr-ref_3|3]]&amp;amp;#93;.&lt;br /&gt;
* Organization-defined parameters (ODPs) have been added to determination statements.&lt;br /&gt;
* A references section has been added to each assessment procedure to provide a hyperlink to the source assessment procedure in SP 800-53A &amp;amp;#91;[[#bibr-ref_5|5]]&amp;amp;#93;.&lt;br /&gt;
&lt;br /&gt;
[[#table-tab_7|Table 7]] shows the changes incorporated into this publication. Errata updates can include corrections, clarifications, or other minor changes in the publication that are either &#039;&#039;editorial&#039;&#039; or &#039;&#039;substantive&#039;&#039; in nature. Any potential updates to this document that are not yet published in an errata update or a formal revision, including additional issues and potential corrections, will be posted as they are identified. See the [https://csrc.nist.gov/pubs/sp/800/171/a/r3/final publication details] for this report. The current release of this publication does not include any errata updates.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;{{anchor|d30e10348}}Table 7. Change Log&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;Publication ID&#039;&#039;&#039; || &#039;&#039;&#039;Date&#039;&#039;&#039; || &#039;&#039;&#039;Type of Edit&#039;&#039;&#039; || &#039;&#039;&#039;Change&#039;&#039;&#039; || &#039;&#039;&#039;Location&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|  ||  ||  ||  || &lt;br /&gt;
|-&lt;br /&gt;
|  ||  ||  ||  || &lt;br /&gt;
|-&lt;br /&gt;
|  ||  ||  ||  || &lt;br /&gt;
|-&lt;br /&gt;
|  ||  ||  ||  || &lt;br /&gt;
|-&lt;br /&gt;
|  ||  ||  ||  || &lt;br /&gt;
|-&lt;br /&gt;
|  ||  ||  ||  || &lt;br /&gt;
|-&lt;br /&gt;
|  ||  ||  ||  || &lt;br /&gt;
|-&lt;br /&gt;
|  ||  ||  ||  || &lt;br /&gt;
|-&lt;br /&gt;
|  ||  ||  ||  || &lt;br /&gt;
|-&lt;br /&gt;
|  ||  ||  ||  || &lt;br /&gt;
|-&lt;br /&gt;
|  ||  ||  ||  || &lt;br /&gt;
|-&lt;br /&gt;
|  ||  ||  ||  || &lt;br /&gt;
|-&lt;br /&gt;
|  ||  ||  ||  || &lt;br /&gt;
|-&lt;br /&gt;
|  ||  ||  ||  || &lt;br /&gt;
|-&lt;br /&gt;
|  ||  ||  ||  || &lt;br /&gt;
|-&lt;br /&gt;
|  ||  ||  ||  || &lt;br /&gt;
|-&lt;br /&gt;
|  ||  ||  ||  || &lt;br /&gt;
|-&lt;br /&gt;
|  ||  ||  ||  || &lt;br /&gt;
|-&lt;br /&gt;
|  ||  ||  ||  || &lt;br /&gt;
|-&lt;br /&gt;
|  ||  ||  ||  || &lt;br /&gt;
|-&lt;br /&gt;
|  ||  ||  ||  || &lt;br /&gt;
|-&lt;br /&gt;
|  ||  ||  ||  || &lt;br /&gt;
|-&lt;br /&gt;
|  ||  ||  ||  || &lt;br /&gt;
|-&lt;br /&gt;
|  ||  ||  ||  || &lt;br /&gt;
|-&lt;br /&gt;
|  ||  ||  ||  || &lt;br /&gt;
|-&lt;br /&gt;
|  ||  ||  ||  || &lt;br /&gt;
|-&lt;br /&gt;
|  ||  ||  ||  || &lt;br /&gt;
|-&lt;br /&gt;
|  ||  ||  ||  || &lt;br /&gt;
|-&lt;br /&gt;
|  ||  ||  ||  || &lt;br /&gt;
|-&lt;br /&gt;
|  ||  ||  ||  || &lt;br /&gt;
|-&lt;br /&gt;
|  ||  ||  ||  || &lt;br /&gt;
|-&lt;br /&gt;
|  ||  ||  ||  || &lt;br /&gt;
|-&lt;br /&gt;
|  ||  ||  ||  || &lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Footnotes ==&lt;br /&gt;
&lt;br /&gt;
{{anchor|footnote-1}}[[#footnote-1-backlink|1]] The term &#039;&#039;risk&#039;&#039; refers to risks to organizational operations (i.e., mission, functions, image, and reputation), organizational assets, individuals, other organizations, and the Nation. See SP 800-39 &amp;amp;#91;[[#bibr-ref_4|4]]&amp;amp;#93; for additional information on organizational risk management and risk tolerance.&lt;br /&gt;
&lt;br /&gt;
{{anchor|footnote-2}}[[#footnote-2-backlink|2]] SP 800-53A &amp;amp;#91;[[#bibr-ref_5|5]]&amp;amp;#93; provides additional information on the assessment process and the individuals steps listed above.&lt;br /&gt;
&lt;br /&gt;
{{anchor|footnote-3}}[[#footnote-3-backlink|3]] Artifacts may be in formats other than documents (e.g., databases, Governance, Risk, and Compliance &amp;amp;#91;GRC&amp;amp;#93; tools, or Open Security Controls Assessment Language &amp;amp;#91;OSCAL&amp;amp;#93;).&lt;br /&gt;
&lt;br /&gt;
{{anchor|footnote-4}}[[#footnote-4-backlink|4]] A &#039;&#039;designated official&#039;&#039; is an official, either internal or external to a nonfederal organization, with the responsibility to determine organizational compliance with the security requirements.&lt;br /&gt;
&lt;br /&gt;
{{anchor|footnote-5}}[[#footnote-5-backlink|5]] Examples of third-party testing organizations include Common Criteria Testing Laboratories that evaluate IT products in accordance with ISO/IEC 15408 &amp;amp;#91;[[#bibr-ref_6|6]]&amp;amp;#93; and Cryptographic Module Validation Program Testing Laboratories that evaluate cryptographic modules in accordance with Federal Information Processing Standard (FIPS) 140 &amp;amp;#91;[[#bibr-ref_7|7]]&amp;amp;#93;.&lt;br /&gt;
&lt;br /&gt;
{{anchor|footnote-6}}[[#footnote-6-backlink|6]] For additional detail and guidance, see SP 800-53A, Section 3.&lt;br /&gt;
&lt;br /&gt;
{{anchor|footnote-7}}[[#footnote-7-backlink|7]] Previous assessment results that may be reused for the current assessment include Inspector General reports, audits, vulnerability scans, physical security inspections, developmental testing and evaluation, vendor flaw remediation activities, and ISO 15408 &amp;amp;#91;[[#bibr-ref_6|6]]&amp;amp;#93; evaluations.&lt;br /&gt;
&lt;br /&gt;
{{anchor|footnote-8}}[[#footnote-8-backlink|8]] In addition to selecting assessment methods and objects, each assessment method (i.e., examine, interview, and test) is associated with depth and coverage attributes. The attribute values identify the rigor (depth) and scope (coverage) of the assessment procedures executed by the assessor. The depth and coverage attribute values are associated with the assurance requirements specified by the organization. SP 800-53A, Appendix C provides additional guidance on depth and coverage attributes.&lt;br /&gt;
&lt;br /&gt;
{{anchor|footnote-9}}[[#footnote-9-backlink|9]] SP 800-53A, Appendix E provides additional guidance on security assessment reports.&lt;/div&gt;</summary>
		<author><name>David</name></author>
	</entry>
	<entry>
		<id>https://cmmcwiki.org/index.php?title=NIST_SP_800-17_R3&amp;diff=1636</id>
		<title>NIST SP 800-17 R3</title>
		<link rel="alternate" type="text/html" href="https://cmmcwiki.org/index.php?title=NIST_SP_800-17_R3&amp;diff=1636"/>
		<updated>2026-07-27T03:00:10Z</updated>

		<summary type="html">&lt;p&gt;David: Created page with &amp;quot;&amp;#039;&amp;#039;&amp;#039;NIST SP 800-171r3&amp;#039;&amp;#039;&amp;#039;  == Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations ==  Ron Ross  Victoria Pillitteri  &amp;#039;&amp;#039;Computer Security Division, Information Technology Laboratory&amp;#039;&amp;#039;  &amp;#039;&amp;#039;Computer Security Division, Information Technology Laboratory&amp;#039;&amp;#039;  [https://doi.org/10.6028/NIST.SP.800-171r3]  May 2024  &amp;lt;span id=&amp;quot;d30e57-FrontMatterH1&amp;quot;&amp;gt;&amp;lt;/span&amp;gt; == Abstract ==  The protection of Controlled Unclassified Information (CUI) is of paramount impo...&amp;quot;&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&#039;&#039;&#039;NIST SP 800-171r3&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
== Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations ==&lt;br /&gt;
&lt;br /&gt;
Ron Ross&lt;br /&gt;
&lt;br /&gt;
Victoria Pillitteri&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Computer Security Division, Information Technology Laboratory&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Computer Security Division, Information Technology Laboratory&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
[https://doi.org/10.6028/NIST.SP.800-171r3]&lt;br /&gt;
&lt;br /&gt;
May 2024&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;d30e57-FrontMatterH1&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&lt;br /&gt;
== Abstract ==&lt;br /&gt;
&lt;br /&gt;
The protection of Controlled Unclassified Information (CUI) is of paramount importance to federal agencies and can directly impact the ability of the Federal Government to successfully conduct its essential missions and functions. This publication provides federal agencies with recommended security requirements for protecting the confidentiality of CUI when the information is resident in nonfederal systems and organizations. The requirements apply to components of nonfederal systems that process, store, or transmit CUI &#039;&#039;or&#039;&#039; that provide protection for such components. The security requirements are intended for use by federal agencies in contractual vehicles or other agreements established between those agencies and nonfederal organizations. This publication can be used in conjunction with its companion publication, NIST Special Publication 800-171A, which provides a comprehensive set of procedures to assess the security requirements.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;d30e137-FrontMatterH1&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&lt;br /&gt;
== Keywords ==&lt;br /&gt;
&lt;br /&gt;
Controlled Unclassified Information, Executive Order 13556, FIPS Publication 199, FIPS Publication 200, FISMA, NIST Special Publication 800-53, nonfederal organizations, nonfederal systems, organization-defined parameter, security assessment, security control, security requirement.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;d30e64-FrontMatterH1&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&lt;br /&gt;
== Disclaimer ==&lt;br /&gt;
&lt;br /&gt;
Certain equipment, instruments, software, or materials, commercial or non-commercial, are identified in this paper in order to specify the experimental procedure adequately. Such identification does not imply recommendation or endorsement of any product or service by NIST, nor does it imply that the materials or equipment identified are necessarily the best available for the purpose.&lt;br /&gt;
&lt;br /&gt;
There may be references in this publication to other publications currently under development by NIST in accordance with its assigned statutory responsibilities. The information in this publication, including concepts and methodologies, may be used by federal agencies even before the completion of such companion publications. Thus, until each publication is completed, current requirements, guidelines, and procedures, where they exist, remain operative. For planning and transition purposes, federal agencies may wish to closely follow the development of these new publications by NIST.&lt;br /&gt;
&lt;br /&gt;
Organizations are encouraged to review all draft publications during public comment periods and provide feedback to NIST. Many NIST cybersecurity publications, other than the ones noted above, are available at [https://csrc.nist.gov/publications].&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;d30e76-FrontMatterH1&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&lt;br /&gt;
== Authority ==&lt;br /&gt;
&lt;br /&gt;
This publication has been developed by NIST in accordance with its statutory responsibilities under the Federal Information Security Modernization Act (FISMA) of 2014, 44 U.S.C. § 3551 et seq., Public Law (P.L.) 113-283. NIST is responsible for developing information security standards and guidelines, including minimum requirements for federal information systems, but such standards and guidelines shall not apply to national security systems without the express approval of appropriate federal officials exercising policy authority over such systems. This guideline is consistent with the requirements of the Office of Management and Budget (OMB) Circular A-130.&lt;br /&gt;
&lt;br /&gt;
Nothing in this publication should be taken to contradict the standards and guidelines made mandatory and binding on federal agencies by the Secretary of Commerce under statutory authority. Nor should these guidelines be interpreted as altering or superseding the existing authorities of the Secretary of Commerce, Director of the OMB, or any other federal official. This publication may be used by nongovernmental organizations on a voluntary basis and is not subject to copyright in the United States. Attribution would, however, be appreciated by NIST.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;d30e82-FrontMatterH1&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&lt;br /&gt;
== NIST Technical Series Policies ==&lt;br /&gt;
&lt;br /&gt;
[https://doi.org/10.6028/NIST-TECHPUBS.CROSSMARK-POLICY Copyright, Use, and Licensing Statements]&lt;br /&gt;
&lt;br /&gt;
[https://www.nist.gov/document/publication-identifier-syntax-nist-technical-series-publications NIST Technical Series Publication Identifier Syntax]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;d30e93-FrontMatterH1&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&lt;br /&gt;
== Publication History ==&lt;br /&gt;
&lt;br /&gt;
Approved by the NIST Editorial Review Board on 2024-04-23&lt;br /&gt;
&lt;br /&gt;
Supersedes NIST Special Publication 800-171r2 (February 2020; Includes updates as of 01-28-2021) [https://doi.org/10.6028/NIST.SP.800-171r2]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;d30e102-FrontMatterH1&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&lt;br /&gt;
== How to Cite this NIST Technical Series Publication: ==&lt;br /&gt;
&lt;br /&gt;
Ross R, Pillitteri V (2024) Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations. (National Institute of Standards and Technology, Gaithersburg, MD), NIST Special Publication (SP) NIST SP 800-171r3. [https://doi.org/10.6028/NIST.SP.800-171r3]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;d30e109-FrontMatterH1&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&lt;br /&gt;
== Author ORCID iDs ==&lt;br /&gt;
&lt;br /&gt;
Ron Ross: 0000-0002-1099-9757&lt;br /&gt;
&lt;br /&gt;
Victoria Pillitteri: 0000-0002-7446-7506&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;d30e115-FrontMatterH1&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&lt;br /&gt;
== Submit Comments ==&lt;br /&gt;
&lt;br /&gt;
800-171comments@list.nist.gov&lt;br /&gt;
&lt;br /&gt;
National Institute of Standards and Technology&lt;br /&gt;
&lt;br /&gt;
Attn: Computer Security Division, Information Technology Laboratory&lt;br /&gt;
&lt;br /&gt;
100 Bureau Drive (Mail Stop 8930) Gaithersburg, MD 20899-8930&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;d30e126-FrontMatterH1&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&lt;br /&gt;
== Additional Information ==&lt;br /&gt;
&lt;br /&gt;
Additional information about this publication is available at [https://csrc.nist.gov/pubs/sp/800/171/r3/final], including related content, potential updates, and document history.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;All comments are subject to release under the Freedom of Information Act (FOIA).&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;d30e139-FrontMatterH1&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&lt;br /&gt;
== Reports on Computer Systems Technology ==&lt;br /&gt;
&lt;br /&gt;
The Information Technology Laboratory (ITL) at the National Institute of Standards and Technology (NIST) promotes the U.S. economy and public welfare by providing technical leadership for the Nation’s measurement and standards infrastructure. ITL develops tests, test methods, reference data, proof of concept implementations, and technical analyses to advance the development and productive use of information technology. ITL’s responsibilities include the development of management, administrative, technical, and physical standards and guidelines for the cost-effective security and privacy of other than national security-related information in federal information systems. The Special Publication 800-series reports on ITL’s research, guidelines, and outreach efforts in information system security, and its collaborative activities with industry, government, and academic organizations.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;d30e143-FrontMatterH1&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&lt;br /&gt;
== Audience ==&lt;br /&gt;
&lt;br /&gt;
This publication serves a diverse group of individuals and organizations in the public and private sectors, including:&lt;br /&gt;
&lt;br /&gt;
* Federal agencies responsible for managing and protecting CUI&lt;br /&gt;
* Nonfederal organizations responsible for protecting CUI&lt;br /&gt;
* Individuals with system development life cycle responsibilities (e.g., program managers, mission/business owners, information owners/stewards, system designers and developers, system/security engineers, systems integrators)&lt;br /&gt;
* Individuals with acquisition or procurement responsibilities (e.g., contracting officers)&lt;br /&gt;
* Individuals with system, security, or risk management and oversight responsibilities (e.g., authorizing officials, chief information officers, chief information security officers, system owners, information security managers)&lt;br /&gt;
* Individuals with security assessment and monitoring responsibilities (e.g., auditors, system evaluators, assessors, analysts, independent verifiers and validators)&lt;br /&gt;
&lt;br /&gt;
The above roles and responsibilities can be viewed from two perspectives:&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;Federal perspective&#039;&#039;: The entity establishing and conveying the security requirements in contractual vehicles or other types of agreements&lt;br /&gt;
* &#039;&#039;Nonfederal perspective&#039;&#039;: The entity responding to and complying with the security requirements set forth in contracts or agreements&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;d30e186-FrontMatterH1&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&lt;br /&gt;
== Patent Disclosure Notice ==&lt;br /&gt;
&lt;br /&gt;
NOTICE: ITL has requested that holders of patent claims whose use may be required for compliance with the guidance or requirements of this publication disclose such patent claims to ITL. However, holders of patents are not obligated to respond to ITL calls for patents and ITL has not undertaken a patent search in order to identify which, if any, patents may apply to this publication.&lt;br /&gt;
&lt;br /&gt;
As of the date of publication and following call(s) for the identification of patent claims whose use may be required for compliance with the guidance or requirements of this publication, no such patent claims have been identified to ITL.&lt;br /&gt;
&lt;br /&gt;
No representation is made or implied by ITL that licenses are not required to avoid patent infringement in the use of this publication.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;d30e212-Acknowledgement_Head&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&lt;br /&gt;
== Acknowledgments ==&lt;br /&gt;
&lt;br /&gt;
The authors gratefully acknowledge and appreciate the significant contributions from individuals and organizations in the public and private sectors whose constructive comments improved the overall quality, thoroughness, and usefulness of this publication. The authors also wish to thank the NIST technical editing and production staff – Jim Foti, Jeff Brewer, Eduardo Takamura, Isabel Van Wyk, Cristina Ritfeld, Derek Sappington, and Carolyn Schmidt – for their outstanding support in preparing this document for publication. Finally, a special note of thanks goes out to Kelley Dempsey for the initial research and development of the content used in the prototype CUI overlay.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;d30e194-FrontMatterH1&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&lt;br /&gt;
==== Historical Contributions ====&lt;br /&gt;
&lt;br /&gt;
The authors also wish to acknowledge the following organizations and individuals for their historic contributions to this publication:&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;Organizations:&#039;&#039; National Archives and Records Administration, Department of Defense&lt;br /&gt;
* &#039;&#039;Individuals:&#039;&#039; Carol Bales, Matthew Barrett, Jon Boyens, Devin Casey, Christian Enloe, Gary Guissanie, Peggy Himes, Robert Glenn, Elizabeth Lennon, Vicki Michetti, Dorian Pappas, Karen Quigg, Mark Riddle, Matthew Scholl, Mary Thomas, Murugiah Souppaya, Patricia Toth, and Patrick Viscuso&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;d30e223-Head1&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&amp;lt;span id=&amp;quot;sec-sec_1&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&lt;br /&gt;
== 1 Introduction ==&lt;br /&gt;
&lt;br /&gt;
Executive Order (EO) 13556 [[#bibr-ref_1|&amp;lt;u&amp;gt;1&amp;lt;/u&amp;gt;]] established a government-wide program to standardize the way the executive branch handles Controlled Unclassified Information (CUI).&amp;lt;span id=&amp;quot;footnote-1-backlink&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;[[#footnote-1|1]] EO 13556 required that the CUI program emphasize openness, transparency, and uniformity of government-wide practices and that the program implementation take place in a manner consistent with Office of Management and Budget (OMB) policies and National Institute of Standards and Technology (NIST) standards and guidelines. As the CUI program Executive Agent, the National Archives and Records Administration (NARA) provides information, guidance, policy, and requirements on handling CUI [[#bibr-ref_4|&amp;lt;u&amp;gt;4&amp;lt;/u&amp;gt;]]. This includes approved CUI categories and descriptions, the basis for safeguarding and dissemination controls, and procedures for the use of CUI.&amp;lt;span id=&amp;quot;footnote-2-backlink&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;[[#footnote-2|2]] The CUI federal regulation [[#bibr-ref_5|&amp;lt;u&amp;gt;5&amp;lt;/u&amp;gt;]] provides guidance to federal agencies on the designation, safeguarding, marking, dissemination, decontrolling, and disposition of CUI; establishes self-inspection and oversight requirements; and delineates other facets of the program.&lt;br /&gt;
&lt;br /&gt;
The CUI regulation requires federal agencies that use federal information systems&amp;lt;span id=&amp;quot;footnote-3-backlink&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;[[#footnote-3|3]] to process, store, or transmit CUI to comply with NIST standards and guidelines. The responsibility of federal agencies to protect CUI does not change when such information is shared with nonfederal organizations.&amp;lt;span id=&amp;quot;footnote-4-backlink&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;[[#footnote-4|4]] Therefore, a similar level of protection is needed when CUI is processed, stored, or transmitted by nonfederal organizations using nonfederal systems.&amp;lt;span id=&amp;quot;footnote-5-backlink&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;[[#footnote-5|5]] To maintain a consistent level of protection, the security requirements for safeguarding CUI in nonfederal systems and organizations must comply with Federal Information Processing Standards (FIPS 199) publication [[#bibr-ref_6|&amp;lt;u&amp;gt;6&amp;lt;/u&amp;gt;]] and FIPS 200 [[#bibr-ref_7|&amp;lt;u&amp;gt;7&amp;lt;/u&amp;gt;]]. The requirements are derived from the controls in NIST Special Publication (SP) 800-53 [[#bibr-ref_8|&amp;lt;u&amp;gt;8&amp;lt;/u&amp;gt;]].&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;d30e302-Head2&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&amp;lt;span id=&amp;quot;sec-sec_1.1&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&lt;br /&gt;
=== 1.1 Purpose and Applicability ===&lt;br /&gt;
&lt;br /&gt;
This publication provides federal agencies with recommended security requirements&amp;lt;span id=&amp;quot;footnote-6-backlink&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;[[#footnote-6|6]] for protecting the &#039;&#039;confidentiality&#039;&#039; of CUI&amp;lt;span id=&amp;quot;footnote-7-backlink&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;[[#footnote-7|7]] when such information is resident in nonfederal systems and organizations and where there are no specific safeguarding requirements prescribed by the authorizing law, regulation, or government-wide policy for the CUI category listed in the CUI registry [[#bibr-ref_4|4]]. The requirements do not apply to nonfederal organizations that are collecting or maintaining information on behalf of a federal agency or using or operating a system on behalf of an agency.&amp;lt;span id=&amp;quot;footnote-8-backlink&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;[[#footnote-8|8]]&lt;br /&gt;
&lt;br /&gt;
The security requirements in this publication are &#039;&#039;only&#039;&#039; applicable to components of nonfederal systems that process, store, or transmit CUI &#039;&#039;or&#039;&#039; that provide protection for such components.&amp;lt;span id=&amp;quot;footnote-9-backlink&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;[[#footnote-9|9]] The requirements are intended for use by federal agencies in contractual vehicles or other agreements that are established between those agencies and nonfederal organizations.&lt;br /&gt;
&lt;br /&gt;
Appropriately scoping requirements is an important factor in determining protection-related investment decisions and managing security risks for nonfederal organizations. If nonfederal organizations designate system components for the processing, storage, or transmission of CUI, those organizations may limit the scope of the security requirements by isolating the system components in a separate security domain. Isolation can be achieved by applying architectural and design concepts (e.g., implementing subnetworks with firewalls or other boundary protection devices and using information flow control mechanisms). Security domains may employ physical separation, logical separation, or a combination of both. This approach can provide adequate security for CUI and avoid increasing the organization’s security posture beyond what it requires for protecting its missions, operations, and assets.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;d30e365-Head2&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&amp;lt;span id=&amp;quot;sec-sec_1.2&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&lt;br /&gt;
=== 1.2 Organization of This Publication ===&lt;br /&gt;
&lt;br /&gt;
The remainder of this special publication is organized as follows:&lt;br /&gt;
&lt;br /&gt;
• [[#sec-sec_2|Section 2]] describes the assumptions and methodology used to develop the security requirements for protecting the confidentiality of CUI, the format of the requirements, and the tailoring criteria applied to the NIST guidelines to obtain the requirements.&lt;br /&gt;
&lt;br /&gt;
• [[#sec-sec_3|Section 3]] lists the security requirements for protecting the confidentiality of CUI in nonfederal systems and organizations.&lt;br /&gt;
&lt;br /&gt;
The following sections provide additional information to support the protection of CUI:&lt;br /&gt;
&lt;br /&gt;
* References&lt;br /&gt;
* Appendix A: Acronyms&lt;br /&gt;
* Appendix B: Glossary&lt;br /&gt;
* Appendix C: Tailoring Criteria&lt;br /&gt;
* Appendix D: Organization-Defined Parameters&lt;br /&gt;
* Appendix E: Change Log&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;d30e407-Head1&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&amp;lt;span id=&amp;quot;sec-sec_2&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&lt;br /&gt;
== 2 The Fundamentals ==&lt;br /&gt;
&lt;br /&gt;
This section describes the assumptions and methodology used to develop the requirements to protect the confidentiality of CUI in nonfederal systems and organizations. It also includes the tailoring&amp;lt;span id=&amp;quot;footnote-10-backlink&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;[[#footnote-10|10]] criteria applied to the controls in SP 800-53 [[#bibr-ref_8|&amp;lt;u&amp;gt;8&amp;lt;/u&amp;gt;]].&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;d30e429-Head2&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&amp;lt;span id=&amp;quot;sec-sec_2.1&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&lt;br /&gt;
=== 2.1 Security Requirement Assumptions ===&lt;br /&gt;
&lt;br /&gt;
The security requirements in this publication are based on the following assumptions:&lt;br /&gt;
&lt;br /&gt;
* Federal information designated as CUI has the same value, whether such information resides in a federal or nonfederal system or organization.&lt;br /&gt;
* Statutory and regulatory requirements for the protection of CUI are consistent in federal and nonfederal systems and organizations.&lt;br /&gt;
* Safeguards implemented to protect CUI are consistent in federal and nonfederal systems and organizations.&lt;br /&gt;
* The confidentiality impact value for CUI is no less than &#039;&#039;moderate&#039;&#039;.&amp;lt;span id=&amp;quot;footnote-11-backlink&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;[[#footnote-11|11]]&lt;br /&gt;
* Nonfederal organizations can directly implement a variety of potential security solutions or use external service providers to satisfy security requirements.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;d30e470-Head2&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&amp;lt;span id=&amp;quot;sec-sec_2.2&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&lt;br /&gt;
=== 2.2 Security Requirement Development Methodology ===&lt;br /&gt;
&lt;br /&gt;
Starting with the SP 800-53 controls in the SP 800-53B [[#bibr-ref_12|&amp;lt;u&amp;gt;12&amp;lt;/u&amp;gt;]] moderate baseline, the controls are &#039;&#039;tailored&#039;&#039; to eliminate selected controls or parts of controls that are:&lt;br /&gt;
&lt;br /&gt;
* Primarily the responsibility of the Federal Government,&lt;br /&gt;
* Not directly related to protecting the confidentiality of CUI,&lt;br /&gt;
* Adequately addressed by other related controls,&amp;lt;span id=&amp;quot;footnote-12-backlink&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;[[#footnote-12|12]] or&lt;br /&gt;
* Not applicable.&lt;br /&gt;
&lt;br /&gt;
SP 800-171 security requirements represent a subset of the controls that are necessary to protect the confidentiality of CUI. The security requirements are organized into 17 families, as illustrated in [[#table-tab_1|Table 1]]. Each family contains the requirements related to the general security topic of the family. Certain families from SP 800-53 are not included due to the tailoring criteria. For example, the PII Processing and Transparency (PT) family is not included because personally identifiable information (PII) is a category of CUI, and therefore, no additional requirements are specified for confidentiality protection. The Program Management (PM) family is not included because it is not associated with any control baseline. Finally, the Contingency Planning (CP) family is not included because it addresses availability.&amp;lt;span id=&amp;quot;footnote-13-backlink&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;[[#footnote-13|13]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;d30e520&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;Table 1. Security Requirement Families&lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| Access Control&lt;br /&gt;
| Maintenance&lt;br /&gt;
| Security Assessment and Monitoring&lt;br /&gt;
|-&lt;br /&gt;
| Awareness and Training&lt;br /&gt;
| Media Protection&lt;br /&gt;
| System and Communications Protection&lt;br /&gt;
|-&lt;br /&gt;
| Audit and Accountability&lt;br /&gt;
| Personnel Security&lt;br /&gt;
| System and Information Integrity&lt;br /&gt;
|-&lt;br /&gt;
| Configuration Management&lt;br /&gt;
| Physical Protection&lt;br /&gt;
| Planning&lt;br /&gt;
|-&lt;br /&gt;
| Identification and Authentication&lt;br /&gt;
| Risk Assessment&lt;br /&gt;
| System and Services Acquisition&lt;br /&gt;
|-&lt;br /&gt;
| Incident Response&lt;br /&gt;
| &lt;br /&gt;
| Supply Chain Risk Management&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Organization-defined parameters&#039;&#039; (ODPs) are included in certain security requirements. ODPs provide flexibility through the use of &#039;&#039;assignment&#039;&#039; and &#039;&#039;selection&#039;&#039; operations to allow federal agencies and nonfederal organizations to specify values for the designated parameters in the requirements.&amp;lt;span id=&amp;quot;footnote-14-backlink&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;[[#footnote-14|14]] Assignment and selection operations provide the capability to customize the security requirements based on specific protection needs. The determination of ODP values can be guided and informed by laws, Executive Orders, directives, regulations, policies, standards, guidance, or mission and business needs. Once specified, the values for the organization-defined parameters become part of the requirement.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;box_a&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;ORGANIZATION-DEFINED PARAMETERS&lt;br /&gt;
&lt;br /&gt;
Organization-defined parameters are an important part of a security requirement specification. ODPs provide both the flexibility and specificity needed by organizations to clearly define their CUI security requirements, given the diverse nature of their missions, business functions, operational environments, and risk tolerance. In addition, ODPs support consistent security assessments in determining whether specified security requirements have been satisfied. If a federal agency or a consortium of agencies do not specify a particular value or range of values for an ODP, nonfederal organizations must assign the value or values to complete the security requirement.&lt;br /&gt;
&lt;br /&gt;
A discussion section is included with each requirement. It is derived from the control discussion sections in SP 800-53 and provides additional information to facilitate the implementation and assessment of the requirements. The discussion section is informative, not normative. It is not intended to extend the scope of a requirement or influence the solutions that organizations may use to satisfy a requirement. The use of examples is notional, not exhaustive, and does not reflect the potential options available to organizations. A &#039;&#039;references&#039;&#039; section provides the source controls&amp;lt;span id=&amp;quot;footnote-15-backlink&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;[[#footnote-15|15]] from SP 800-53 and a list of NIST Special Publications with additional information on the topic described in the security requirement. The structure and content of a typical security requirement is provided in the example below.&lt;br /&gt;
&lt;br /&gt;
03.13.11 Cryptographic Protection&lt;br /&gt;
&lt;br /&gt;
Implement the following types of cryptography when used to protect the confidentiality of CUI: [&#039;&#039;Assignment: organization-defined types of cryptography&#039;&#039;].&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;DISCUSSION&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
Cryptography is implemented in accordance with applicable laws, Executive Orders, directives, policies, regulations, standards, and guidelines. FIPS-validated cryptography is recommended for the protection of CUI.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;REFERENCES&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
Source Control: [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=SC-13 SC-13]&lt;br /&gt;
&lt;br /&gt;
Supporting Publications: FIPS 140-3 [[#bibr-ref_38|&amp;lt;u&amp;gt;38&amp;lt;/u&amp;gt;]]&lt;br /&gt;
&lt;br /&gt;
The term &#039;&#039;organization&#039;&#039; is used in many security requirements, and its meaning depends on context. For example, in a security requirement with an ODP, an organization can refer to either the federal agency or the nonfederal organization establishing the parameter values for the requirement.&lt;br /&gt;
&lt;br /&gt;
[[#sec-sec_C|Appendix C]] describes the security control tailoring criteria used to develop the security requirements and the results of the tailoring process. The appendix provides a list of controls from SP 800-53 that support the requirements and the controls that have been eliminated from the moderate baseline in accordance with the tailoring criteria.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;box_b&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;ASSESSING SECURITY REQUIREMENTS&lt;br /&gt;
&lt;br /&gt;
SP 800-171A [[#bibr-ref_84|84]] provides a set of procedures to assess the security requirements described in this publication. The assessment procedures are based on the procedures described in SP 800-53A [[#bibr-ref_57|57]].&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;d30e700-Head1&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&amp;lt;span id=&amp;quot;sec-sec_3&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&lt;br /&gt;
== 3 The Security Requirements ==&lt;br /&gt;
&lt;br /&gt;
This section describes 17 families of security requirements for protecting the confidentiality of CUI in nonfederal systems and organizations. When used in the context of the requirements in Sec. 3, the term &#039;&#039;system&#039;&#039; is defined to be nonfederal systems or system components that process, store, or transmit CUI or that provide protection for such systems or components. Not all security requirements mention CUI explicitly. However, the requirements are included because they directly affect the protection of CUI during processing, while in storage, and when in transmission between different locations.&lt;br /&gt;
&lt;br /&gt;
Some systems, including specialized systems (e.g., industrial/process control systems, medical devices, computer numerical control machines), may have limitations on the application of certain security requirements. To accommodate such issues, the system security plan — as reflected in requirement [[#sec-sec_03.15.02|03.15.02]] — is used to describe any &#039;&#039;enduring exceptions&#039;&#039; to the security requirements. Individual, isolated, or temporary deficiencies are managed though plans of action and milestones, as reflected in requirement [[#sec-sec_03.12.02|03.12.02]].&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;box_c&amp;quot;&amp;gt;&amp;lt;/span&amp;gt; SCOPE AND APPLICABILITY OF SECURITY REQUIREMENTS&lt;br /&gt;
&lt;br /&gt;
The security requirements in this section are only applicable to components of nonfederal systems that process, store, or transmit CUI &#039;&#039;or&#039;&#039; that provide protection for such components.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;d30e729-Head2&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&amp;lt;span id=&amp;quot;sec-sec_3.1&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&lt;br /&gt;
=== 3.1 Access Control ===&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;d30e734-Head3&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&amp;lt;span id=&amp;quot;sec-sec_03.01.01&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&lt;br /&gt;
==== 03.01.01 Account Management ====&lt;br /&gt;
&lt;br /&gt;
# Define the types of system accounts allowed and prohibited.&lt;br /&gt;
# Create, enable, modify, disable, and remove system accounts in accordance with policy, procedures, prerequisites, and criteria.&lt;br /&gt;
# Specify:&lt;br /&gt;
## Authorized users of the system,&lt;br /&gt;
## Group and role membership, and&lt;br /&gt;
## Access authorizations (i.e., privileges) for each account.&lt;br /&gt;
# Authorize access to the system based on:&lt;br /&gt;
## A valid access authorization and&lt;br /&gt;
## Intended system usage.&lt;br /&gt;
# Monitor the use of system accounts.&lt;br /&gt;
# Disable system accounts when:&lt;br /&gt;
## The accounts have expired,&lt;br /&gt;
## The accounts have been inactive for [&#039;&#039;Assignment: organization-defined time period&#039;&#039;],&lt;br /&gt;
## The accounts are no longer associated with a user or individual,&lt;br /&gt;
## The accounts are in violation of organizational policy, or&lt;br /&gt;
## Significant risks associated with individuals are discovered.&lt;br /&gt;
# Notify account managers and designated personnel or roles within:&lt;br /&gt;
## [&#039;&#039;Assignment: organization-defined time period&#039;&#039;] when accounts are no longer required.&lt;br /&gt;
## [&#039;&#039;Assignment: organization-defined time period&#039;&#039;] when users are terminated or transferred.&lt;br /&gt;
## [&#039;&#039;Assignment: organization-defined time period&#039;&#039;] when system usage or the need-to-know changes for an individual.&lt;br /&gt;
# Require that users log out of the system after [&#039;&#039;Assignment: organization-defined time period&#039;&#039;] of expected inactivity or when [&#039;&#039;Assignment: organization-defined circumstances&#039;&#039;].&lt;br /&gt;
&lt;br /&gt;
===== DISCUSSION =====&lt;br /&gt;
&lt;br /&gt;
This requirement focuses on account management for systems and applications. The definition and enforcement of access authorizations other than those determined by account type (e.g., privileged access, non-privileged access) are addressed in [[#sec-sec_03.01.02|03.01.02]]. System account types include individual, group, temporary, system, guest, anonymous, emergency, developer, and service. Users who require administrative privileges on system accounts receive additional scrutiny by personnel responsible for approving such accounts and privileged access. Types of accounts that organizations may prohibit due to increased risk include group, emergency, guest, anonymous, and temporary.&lt;br /&gt;
&lt;br /&gt;
Organizations may choose to define access privileges or other attributes by account, type of account, or a combination of both. Other attributes required for authorizing access include restrictions on the time of day, day of the week, and point of origin. When defining other system account attributes, organizations consider system requirements (e.g., system upgrades, scheduled maintenance) and mission and business requirements (e.g., time zone differences, remote access to facilitate travel requirements).&lt;br /&gt;
&lt;br /&gt;
Users who pose a significant security risk include individuals for whom reliable evidence indicates either the intention to use authorized access to the system to cause harm or that adversaries will cause harm through them. Close coordination among mission and business owners, system administrators, human resource managers, and legal staff is essential when disabling system accounts for high-risk individuals. Time periods for the notification of organizational personnel or roles may vary.&lt;br /&gt;
&lt;br /&gt;
Inactivity logout is behavior- or policy-based and requires users to take physical action to log out when they are expecting inactivity longer than the defined period. Automatic enforcement of inactivity logout is addressed by [[#sec-sec_03.01.10|03.01.10]].&lt;br /&gt;
&lt;br /&gt;
===== REFERENCES =====&lt;br /&gt;
&lt;br /&gt;
Source Controls: [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=AC-02 AC-02], [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=AC-02 AC-02(03)], [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=AC-02 AC-02(05)], [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=AC-02 AC-02(13)]&lt;br /&gt;
&lt;br /&gt;
Supporting Publications: SP 800-46 [[#bibr-ref_14|14]], SP 800-57-1 [[#bibr-ref_15|15]], SP 800-57-2 [[#bibr-ref_16|16]], SP 800-57-3 [[#bibr-ref_17|17]], SP 800-77 [[#bibr-ref_18|18]], SP 800-113 [[#bibr-ref_19|19]], SP 800-114 [[#bibr-ref_20|20]], SP 800-121 [[#bibr-ref_21|21]], SP 800-162 [[#bibr-ref_22|22]], SP 800-178 [[#bibr-ref_23|23]], SP 800-192 [[#bibr-ref_24|24]], IR 7874 [[#bibr-ref_25|25]], IR 7966 [[#bibr-ref_26|26]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;d30e924-Head3&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&amp;lt;span id=&amp;quot;sec-sec_03.01.02&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&lt;br /&gt;
==== 03.01.02 Access Enforcement ====&lt;br /&gt;
&lt;br /&gt;
Enforce approved authorizations for logical access to CUI and system resources in accordance with applicable access control policies.&lt;br /&gt;
&lt;br /&gt;
===== DISCUSSION =====&lt;br /&gt;
&lt;br /&gt;
Access control policies control access between active entities or subjects (i.e., users or system processes acting on behalf of users) and passive entities or objects (i.e., devices, files, records, domains) in organizational systems. Types of system access include remote access and access to systems that communicate through external networks, such as the internet. Access enforcement mechanisms can also be employed at the application and service levels to provide increased protection for CUI. This recognizes that the system can host many applications and services in support of mission and business functions. Access control policies are defined in [[#sec-sec_03.15.01|03.15.01]].&lt;br /&gt;
&lt;br /&gt;
===== REFERENCES =====&lt;br /&gt;
&lt;br /&gt;
Source Control: [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=AC-03 AC-03]&lt;br /&gt;
&lt;br /&gt;
Supporting Publications: SP 800-46 [[#bibr-ref_14|14]], SP 800-57-1 [[#bibr-ref_15|15]], SP 800-57-2 [[#bibr-ref_16|16]], SP 800-57-3 [[#bibr-ref_17|17]], SP 800-77 [[#bibr-ref_18|18]], SP 800-113 [[#bibr-ref_19|19]], SP 800-114 [[#bibr-ref_20|20]], SP 800-121 [[#bibr-ref_21|21]], SP 800-162 [[#bibr-ref_22|22]], SP 800-178 [[#bibr-ref_23|23]], SP 800-192 [[#bibr-ref_24|24]], IR 7874 [[#bibr-ref_25|25]], IR 7966 [[#bibr-ref_26|26]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;d30e988-Head3&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&amp;lt;span id=&amp;quot;sec-sec_03.01.03&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&lt;br /&gt;
==== 03.01.03 Information Flow Enforcement ====&lt;br /&gt;
&lt;br /&gt;
Enforce approved authorizations for controlling the flow of CUI within the system and between connected systems.&lt;br /&gt;
&lt;br /&gt;
===== DISCUSSION =====&lt;br /&gt;
&lt;br /&gt;
Information flow control regulates where CUI can transit within a system and between systems (in contrast to who is allowed to access the information) and without regard to subsequent accesses to that information. Flow control restrictions include keeping CUI from being transmitted in the clear to the internet, blocking external communications traffic that claims to be sourced from within the organization, restricting requests to the internet that are not from the internal web proxy server, and limiting CUI transfers between organizations based on data structures and content.&lt;br /&gt;
&lt;br /&gt;
Transferring CUI between organizations may require an agreement that specifies how the information flow is enforced (see [[#sec-sec_03.12.05|03.12.05]]). Transferring CUI between systems that represent different security domains with different security policies introduces the risk that such transfers violate one or more domain security policies. In such situations, information owners or stewards provide guidance at designated policy enforcement points between interconnected systems. Organizations consider mandating specific architectural solutions when required to enforce specific security policies. Enforcement includes prohibiting CUI transfers between interconnected systems (i.e., allowing information access only), employing hardware mechanisms to enforce one-way information flows, and implementing trustworthy regrading mechanisms to reassign security attributes and security labels.&lt;br /&gt;
&lt;br /&gt;
Organizations commonly use information flow control policies and enforcement mechanisms to control the flow of CUI between designated sources and destinations (e.g., networks, individuals, and devices) within systems and between interconnected systems. Flow control is based on characteristics of the information or the information path. Enforcement occurs in boundary protection devices (e.g., encrypted tunnels, routers, gateways, and firewalls) that use rule sets or establish configuration settings that restrict system services, provide a packet-filtering capability based on header information, or provide a message-filtering capability based on message content (e.g., implementing key word searches or using document characteristics). Organizations also consider the trustworthiness of filtering and inspection mechanisms (i.e., hardware, firmware, and software components) that are critical to information flow enforcement.&lt;br /&gt;
&lt;br /&gt;
===== REFERENCES =====&lt;br /&gt;
&lt;br /&gt;
Source Control: [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=AC-04 AC-04]&lt;br /&gt;
&lt;br /&gt;
Supporting Publications: SP 800-160-1 [[#bibr-ref_11|11]], SP 800-162 [[#bibr-ref_22|22]], SP 800-178 [[#bibr-ref_23|23]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;d30e1025-Head3&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&amp;lt;span id=&amp;quot;sec-sec_03.01.04&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&lt;br /&gt;
==== 03.01.04 Separation of Duties ====&lt;br /&gt;
&lt;br /&gt;
# Identify the duties of individuals requiring separation.&lt;br /&gt;
# Define system access authorizations to support separation of duties.&lt;br /&gt;
&lt;br /&gt;
===== DISCUSSION =====&lt;br /&gt;
&lt;br /&gt;
Separation of duties addresses the potential for abuse of authorized privileges and reduces the risk of malevolent activity without collusion. Separation of duties includes dividing mission functions and support functions among different individuals or roles, conducting system support functions with different individuals or roles (e.g., quality assurance, configuration management, network security, system management, assessments, and programming), and ensuring that personnel who administer access control functions do not also administer audit functions. Because separation of duty violations can span systems and application domains, organizations consider the entirety of their systems and system components when developing policies on separation of duties. This requirement is enforced by [[#sec-sec_03.01.02|03.01.02]].&lt;br /&gt;
&lt;br /&gt;
===== REFERENCES =====&lt;br /&gt;
&lt;br /&gt;
Source Control: [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=AC-05 AC-05]&lt;br /&gt;
&lt;br /&gt;
Supporting Publications: SP 800-162 [[#bibr-ref_22|22]], SP 800-178 [[#bibr-ref_23|23]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;d30e1064-Head3&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&amp;lt;span id=&amp;quot;sec-sec_03.01.05&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&lt;br /&gt;
==== 03.01.05 Least Privilege ====&lt;br /&gt;
&lt;br /&gt;
# Allow only authorized system access for users (or processes acting on behalf of users) that is necessary to accomplish assigned organizational tasks.&lt;br /&gt;
# Authorize access to [&#039;&#039;Assignment: organization-defined security functions&#039;&#039;] and [&#039;&#039;Assignment: organization-defined security-relevant information&#039;&#039;].&lt;br /&gt;
# Review the privileges assigned to roles or classes of users [&#039;&#039;Assignment: organization-defined frequency&#039;&#039;] to validate the need for such privileges.&lt;br /&gt;
# Reassign or remove privileges, as necessary.&lt;br /&gt;
&lt;br /&gt;
===== DISCUSSION =====&lt;br /&gt;
&lt;br /&gt;
Organizations employ the principle of least privilege for specific duties and authorized access for users and system processes. Least privilege is applied to the development, implementation, and operation of the system. Organizations consider creating additional processes, roles, and system accounts to achieve least privilege. Security functions include establishing system accounts and assigning privileges, installing software, configuring access authorizations, configuring settings for events to be audited, establishing vulnerability scanning parameters, establishing intrusion detection parameters, and managing audit information. Security-relevant information includes threat and vulnerability information, filtering rules for routers or firewalls, configuration parameters for security services, security architecture, cryptographic key management information, access control lists, and audit information.&lt;br /&gt;
&lt;br /&gt;
===== REFERENCES =====&lt;br /&gt;
&lt;br /&gt;
Source Controls: [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=AC-06 AC-06], [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=AC-06 AC-06(01)], [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=AC-06 AC-06(07)], [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=AU-09 AU-09(04)]&lt;br /&gt;
&lt;br /&gt;
Supporting Publications: None&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;d30e1120-Head3&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&amp;lt;span id=&amp;quot;sec-sec_03.01.06&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&lt;br /&gt;
==== 03.01.06 Least Privilege – Privileged Accounts ====&lt;br /&gt;
&lt;br /&gt;
# Restrict privileged accounts on the system to [&#039;&#039;Assignment: organization-defined personnel or roles&#039;&#039;].&lt;br /&gt;
# Require that users (or roles) with privileged accounts use non-privileged accounts when accessing non-security functions or non-security information.&lt;br /&gt;
&lt;br /&gt;
===== DISCUSSION =====&lt;br /&gt;
&lt;br /&gt;
Privileged accounts refer to accounts that are granted elevated privileges to access resources (including security functions or security-relevant information) that are otherwise restricted for non-privileged accounts. These accounts are typically described as system administrator or super user accounts. For example, a privileged account is often required in order to perform privileged functions such as executing commands that could modify system behavior. Restricting privileged accounts to specific personnel or roles ensures that only those authorized users can access and manipulate security functions or security-relevant information. Requiring the use of non-privileged accounts when such access is not needed can limit unauthorized access to and manipulation of security functions or security-relevant information.&lt;br /&gt;
&lt;br /&gt;
===== REFERENCES =====&lt;br /&gt;
&lt;br /&gt;
Source Controls: [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=AC-06 AC-06(02)], [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=AC-06 AC-06(05)]&lt;br /&gt;
&lt;br /&gt;
Supporting Publications: None&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;d30e1157-Head3&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&amp;lt;span id=&amp;quot;sec-sec_03.01.07&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&lt;br /&gt;
==== 03.01.07 Least Privilege – Privileged Functions ====&lt;br /&gt;
&lt;br /&gt;
# Prevent non-privileged users from executing privileged functions.&lt;br /&gt;
# Log the execution of privileged functions.&lt;br /&gt;
&lt;br /&gt;
===== DISCUSSION =====&lt;br /&gt;
&lt;br /&gt;
Privileged functions include establishing system accounts, performing system integrity checks, conducting patching operations, changing system configuration settings, or administering cryptographic key management activities. Non-privileged users do not possess the authorizations to execute privileged functions. Bypassing intrusion detection and prevention mechanisms or malicious code protection mechanisms are examples of privileged functions that require protection from non-privileged users. This requirement represents a condition achieved by the definition of authorized privileges in [[#sec-sec_03.01.01|03.01.01]] and privilege enforcement in [[#sec-sec_03.01.02|03.01.02]].&lt;br /&gt;
&lt;br /&gt;
The misuse of privileged functions — whether intentionally or unintentionally by authorized users or by unauthorized external entities that have compromised system accounts — is a serious and ongoing concern that can have significant adverse impacts on organizations. Logging the use of privileged functions is one way to detect such misuse and mitigate risks from advanced persistent threats and insider threats.&lt;br /&gt;
&lt;br /&gt;
===== REFERENCES =====&lt;br /&gt;
&lt;br /&gt;
Source Controls: [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=AC-06 AC-06(09)], [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=AC-06 AC-06(10)]&lt;br /&gt;
&lt;br /&gt;
Supporting Publications: None&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;d30e1199-Head3&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&amp;lt;span id=&amp;quot;sec-sec_03.01.08&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&lt;br /&gt;
==== 03.01.08 Unsuccessful Logon Attempts ====&lt;br /&gt;
&lt;br /&gt;
# Enforce a limit of [&#039;&#039;Assignment: organization-defined number&#039;&#039;] consecutive invalid logon attempts by a user during a [&#039;&#039;Assignment: organization-defined time period&#039;&#039;].&lt;br /&gt;
# Automatically [&#039;&#039;Selection (one or more): lock the account or node for an&#039;&#039; [&#039;&#039;Assignment: organization-defined time period&#039;&#039;]&#039;&#039;; lock the account or node until released by an administrator; delay next logon prompt; notify system administrator; take other action&#039;&#039;] when the maximum number of unsuccessful attempts is exceeded.&lt;br /&gt;
&lt;br /&gt;
===== DISCUSSION =====&lt;br /&gt;
&lt;br /&gt;
Due to the potential for denial of service, automatic system lockouts are in most cases, temporary and automatically release after a predetermined time period established by the organization (i.e., using a delay algorithm). Organizations may employ different delay algorithms for different system components based on the capabilities of the respective components. Responses to unsuccessful system logon attempts may be implemented at the system and application levels.&lt;br /&gt;
&lt;br /&gt;
Organization-defined actions that may be taken include prompting the user to answer a secret question in addition to the username and password, invoking a lockdown mode with limited user capabilities (instead of a full lockout), allowing users to only logon from specified Internet Protocol (IP) addresses, requiring a CAPTCHA to prevent automated attacks, or applying user profiles, such as location, time of day, IP address, device, or Media Access Control (MAC) address.&lt;br /&gt;
&lt;br /&gt;
===== REFERENCES =====&lt;br /&gt;
&lt;br /&gt;
Source Control: [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=AC-07 AC-07]&lt;br /&gt;
&lt;br /&gt;
Supporting Publications: SP 800-63-3 [[#bibr-ref_27|27]], SP 800-124 [[#bibr-ref_28|28]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;d30e1251-Head3&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&amp;lt;span id=&amp;quot;sec-sec_03.01.09&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&lt;br /&gt;
==== 03.01.09 System Use Notification ====&lt;br /&gt;
&lt;br /&gt;
Display a system use notification message with privacy and security notices consistent with applicable CUI rules before granting access to the system.&lt;br /&gt;
&lt;br /&gt;
===== DISCUSSION =====&lt;br /&gt;
&lt;br /&gt;
System use notifications can be implemented using messages or warning banners. The messages or warning banners are displayed before individuals log in to a system that processes, stores, or transmits CUI. System use notifications are used for access via logon interfaces with human users and are not required when human interfaces do not exist. Organizations consider whether a secondary use notification is needed to access applications or other system resources after the initial network logon. Posters or other printed materials may be used in lieu of an automated system message. This requirement is related to [[#sec-sec_03.15.03|03.15.03]].&lt;br /&gt;
&lt;br /&gt;
===== REFERENCES =====&lt;br /&gt;
&lt;br /&gt;
Source Control: [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=AC-08 AC-08]&lt;br /&gt;
&lt;br /&gt;
Supporting Publications: None&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;d30e1275-Head3&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&amp;lt;span id=&amp;quot;sec-sec_03.01.10&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&lt;br /&gt;
==== 03.01.10 Device Lock ====&lt;br /&gt;
&lt;br /&gt;
# Prevent access to the system by [&#039;&#039;Selection (one or more): initiating a device lock after&#039;&#039; [&#039;&#039;Assignment: organization-defined time period&#039;&#039;] &#039;&#039;of inactivity; requiring the user to initiate a device lock before leaving the system unattended&#039;&#039;].&lt;br /&gt;
# Retain the device lock until the user reestablishes access using established identification and authentication procedures.&lt;br /&gt;
# Conceal, via the device lock, information previously visible on the display with a publicly viewable image.&lt;br /&gt;
&lt;br /&gt;
===== DISCUSSION =====&lt;br /&gt;
&lt;br /&gt;
Device locks are temporary actions taken to prevent access to the system when users depart from the immediate vicinity of the system but do not want to log out due to the temporary nature of their absences. Device locks can be implemented at the operating system level or application level. User-initiated device locking is behavior- or policy-based and requires users to take physical action to initiate the device lock. Device locks are not an acceptable substitute for logging out of the system (e.g., when organizations require users to log out at the end of workdays). Publicly viewable images can include static or dynamic images, such as patterns used with screen savers, solid colors, photographic images, a clock, a battery life indicator, or a blank screen with the caveat that controlled unclassified information is not displayed.&lt;br /&gt;
&lt;br /&gt;
===== REFERENCES =====&lt;br /&gt;
&lt;br /&gt;
Source Controls: [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=AC-11 AC-11], [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=AC-11 AC-11(01)]&lt;br /&gt;
&lt;br /&gt;
Supporting Publications: None&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;d30e1321-Head3&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&amp;lt;span id=&amp;quot;sec-sec_03.01.11&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&lt;br /&gt;
==== 03.01.11 Session Termination ====&lt;br /&gt;
&lt;br /&gt;
Terminate a user session automatically after [&#039;&#039;Assignment: organization-defined conditions or trigger events requiring session disconnect&#039;&#039;].&lt;br /&gt;
&lt;br /&gt;
===== DISCUSSION =====&lt;br /&gt;
&lt;br /&gt;
This requirement addresses the termination of user-initiated logical sessions in contrast to the termination of network connections that are associated with communications sessions (i.e., disconnecting from the network) in [[#sec-sec_03.13.09|03.13.09]]. A logical session is initiated whenever a user (or processes acting on behalf of a user) accesses a system. Logical sessions can be terminated (and thus terminate user access) without terminating network sessions. Session termination ends all system processes associated with a user’s logical session except those processes that are created by the user (i.e., session owner) to continue after the session is terminated. Conditions or trigger events that require automatic session termination can include organization-defined periods of user inactivity, time-of-day restrictions on system use, and targeted responses to certain types of incidents.&lt;br /&gt;
&lt;br /&gt;
===== REFERENCES =====&lt;br /&gt;
&lt;br /&gt;
Source Control: [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=AC-12 AC-12]&lt;br /&gt;
&lt;br /&gt;
Supporting Publications: None&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;d30e1347-Head3&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&amp;lt;span id=&amp;quot;sec-sec_03.01.12&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&lt;br /&gt;
==== 03.01.12 Remote Access ====&lt;br /&gt;
&lt;br /&gt;
# Establish usage restrictions, configuration requirements, and connection requirements for each type of allowable remote system access.&lt;br /&gt;
# Authorize each type of remote system access prior to establishing such connections.&lt;br /&gt;
# Route remote access to the system through authorized and managed access control points.&lt;br /&gt;
# Authorize the remote execution of privileged commands and remote access to security-relevant information.&lt;br /&gt;
&lt;br /&gt;
===== DISCUSSION =====&lt;br /&gt;
&lt;br /&gt;
Remote access is access to systems (or processes acting on behalf of users) that communicate through external networks, such as the internet. Monitoring and controlling remote access methods allows organizations to detect attacks and ensure compliance with remote access policies. Routing remote access through managed access control points enhances explicit control over such connections and reduces susceptibility to unauthorized access to the system, which could result in the unauthorized disclosure of CUI.&lt;br /&gt;
&lt;br /&gt;
Remote access to the system represents a significant potential vulnerability that can be exploited by adversaries. Restricting the execution of privileged commands and access to security-relevant information via remote access reduces the exposure of the organization and its susceptibility to threats by adversaries. A privileged command is a human-initiated command executed on a system that involves the control, monitoring, or administration of the system, including security functions and security-relevant information. Security-relevant information is information that can potentially impact the operation of security functions or the provision of security services in a manner that could result in failure to enforce the system security policy or maintain isolation of code and data. Privileged commands give individuals the ability to execute sensitive, security-critical, or security-relevant system functions.&lt;br /&gt;
&lt;br /&gt;
===== REFERENCES =====&lt;br /&gt;
&lt;br /&gt;
Source Controls: [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=AC-17 AC-17], [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=AC-17 AC-17(03)], [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=AC-17 AC-17(04)]&lt;br /&gt;
&lt;br /&gt;
Supporting Publications: SP 800-46 [[#bibr-ref_14|14]], SP 800-77 [[#bibr-ref_18|18]], SP 800-113 [[#bibr-ref_19|19]], SP 800-114 [[#bibr-ref_20|20]], SP 800-121 [[#bibr-ref_21|21]], IR 7966 [[#bibr-ref_26|26]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;d30e1412-Head3&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&amp;lt;span id=&amp;quot;sec-sec_03.01.13&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&lt;br /&gt;
==== 03.01.13 Withdrawn ====&lt;br /&gt;
&lt;br /&gt;
Addressed by [[#sec-sec_03.13.08|03.13.08]].&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;d30e1422-Head3&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&amp;lt;span id=&amp;quot;sec-sec_03.01.14&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&lt;br /&gt;
==== 03.01.14 Withdrawn ====&lt;br /&gt;
&lt;br /&gt;
Incorporated into [[#sec-sec_03.01.12|03.01.12]].&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;d30e1432-Head3&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&amp;lt;span id=&amp;quot;sec-sec_03.01.15&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&lt;br /&gt;
==== 03.01.15 Withdrawn ====&lt;br /&gt;
&lt;br /&gt;
Incorporated into [[#sec-sec_03.01.12|03.01.12]].&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;d30e1443-Head3&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&amp;lt;span id=&amp;quot;sec-sec_03.01.16&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&lt;br /&gt;
==== 03.01.16 Wireless Access ====&lt;br /&gt;
&lt;br /&gt;
# Establish usage restrictions, configuration requirements, and connection requirements for each type of wireless access to the system.&lt;br /&gt;
# Authorize each type of wireless access to the system prior to establishing such connections.&lt;br /&gt;
# Disable, when not intended for use, wireless networking capabilities prior to issuance and deployment.&lt;br /&gt;
# Protect wireless access to the system using authentication and encryption.&lt;br /&gt;
&lt;br /&gt;
===== DISCUSSION =====&lt;br /&gt;
&lt;br /&gt;
Wireless networking capabilities represent a significant potential vulnerability that can be exploited by adversaries. Establishing usage restrictions, configuration requirements, and connection requirements for wireless access to the system provides criteria to support access authorization decisions. These restrictions and requirements reduce susceptibility to unauthorized system access through wireless technologies. Wireless networks use authentication protocols that provide credential protection and mutual authentication. Organizations authenticate individuals and devices to protect wireless access to the system. Special attention is given to the variety of devices with potential wireless access to the system, including small form factor mobile devices (e.g., smart phones, tablets, smart watches). Wireless networking capabilities that are embedded within system components represent a potential vulnerability that can be exploited by adversaries. Strong authentication of users and devices, strong encryption, and disabling wireless capabilities that are not needed for essential mission or business functions can reduce susceptibility to threats by adversaries involving wireless technologies.&lt;br /&gt;
&lt;br /&gt;
===== REFERENCES =====&lt;br /&gt;
&lt;br /&gt;
Source Controls: [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=AC-18 AC-18], [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=AC-18 AC-18(01)], [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=AC-18 AC-18(03)]&lt;br /&gt;
&lt;br /&gt;
Supporting Publications: SP 800-94 [[#bibr-ref_29|29]], SP 800-97 [[#bibr-ref_30|30]], SP 800-124 [[#bibr-ref_28|28]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;d30e1495-Head3&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&amp;lt;span id=&amp;quot;sec-sec_03.01.17&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&lt;br /&gt;
==== 03.01.17 Withdrawn ====&lt;br /&gt;
&lt;br /&gt;
Incorporated into [[#sec-sec_03.01.16|03.01.16]].&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;d30e1505-Head3&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&amp;lt;span id=&amp;quot;sec-sec_03.01.18&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&lt;br /&gt;
==== 03.01.18 Access Control for Mobile Devices ====&lt;br /&gt;
&lt;br /&gt;
# Establish usage restrictions, configuration requirements, and connection requirements for mobile devices.&lt;br /&gt;
# Authorize the connection of mobile devices to the system.&lt;br /&gt;
# Implement full-device or container-based encryption to protect the confidentiality of CUI on mobile devices.&lt;br /&gt;
&lt;br /&gt;
===== DISCUSSION =====&lt;br /&gt;
&lt;br /&gt;
A mobile device is a computing device with a small form factor such that it can be carried by a single individual; is designed to operate without a physical connection; possesses local, non-removable, or removable data storage; and includes a self-contained power source. Mobile device functionality may include on-board sensors that allow the device to capture information, voice communication capabilities, and/or built-in features for synchronizing local data with remote locations. Examples include smart phones, smart watches, and tablets. Mobile devices are typically associated with a single individual. The processing, storage, and transmission capabilities of mobile devices may be comparable to or a subset of notebook or desktop systems, depending on the nature and intended purpose of the device. Some organizations may consider notebook computers to be mobile devices. The protection and control of mobile devices are behavior- or policy-based and require users to take physical action to protect and control such devices when outside of controlled areas. Controlled areas are spaces for which the organization provides physical or procedural controls to meet the requirements established for protecting CUI.&lt;br /&gt;
&lt;br /&gt;
Due to the large variety of mobile devices with different characteristics and capabilities, organizational restrictions may vary for the different classes or types of such devices. Usage restrictions, configuration requirements, and connection requirements for mobile devices include configuration management, device identification and authentication, implementing mandatory protective software, scanning devices for malicious code, updating virus protection software, scanning for critical software updates and patches, conducting operating system and possibly other software integrity checks, and disabling unnecessary hardware. On mobile devices, secure containers provide software-based data isolation designed to segment enterprise applications and information from personal apps and data. Containers may present multiple user interfaces, one of the most common being a mobile application that acts as a portal to a suite of business productivity apps, such as email, contacts, and calendar. Organizations can employ full-device encryption or container-based encryption to protect the confidentiality of CUI on mobile devices.&lt;br /&gt;
&lt;br /&gt;
===== REFERENCES =====&lt;br /&gt;
&lt;br /&gt;
Source Controls: [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=AC-19 AC-19], [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=AC-19 AC-19(05)]&lt;br /&gt;
&lt;br /&gt;
Supporting Publications: SP 800-46 [[#bibr-ref_14|14]], SP 800-114 [[#bibr-ref_31|31]], SP 800-124 [[#bibr-ref_28|28]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;d30e1553-Head3&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&amp;lt;span id=&amp;quot;sec-sec_03.01.19&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&lt;br /&gt;
==== 03.01.19 Withdrawn ====&lt;br /&gt;
&lt;br /&gt;
Incorporated into [[#sec-sec_03.01.18|03.01.18]].&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;d30e1563-Head3&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&amp;lt;span id=&amp;quot;sec-sec_03.01.20&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&lt;br /&gt;
==== 03.01.20 Use of External Systems ====&lt;br /&gt;
&lt;br /&gt;
# Prohibit the use of external systems unless the systems are specifically authorized.&lt;br /&gt;
# Establish the following security requirements to be satisfied on external systems prior to allowing use of or access to those systems by authorized individuals: [&#039;&#039;Assignment: organization-defined security requirements&#039;&#039;].&lt;br /&gt;
# Permit authorized individuals to use external systems to access the organizational system or to process, store, or transmit CUI only after:&lt;br /&gt;
## Verifying that the security requirements on the external systems as specified in the organization’s system security plans have been satisfied and&lt;br /&gt;
## Retaining approved system connection or processing agreements with the organizational entities hosting the external systems.&lt;br /&gt;
# Restrict the use of organization-controlled portable storage devices by authorized individuals on external systems.&lt;br /&gt;
&lt;br /&gt;
===== DISCUSSION =====&lt;br /&gt;
&lt;br /&gt;
External systems are systems that are used by but are not part of the organization. These systems include personally owned systems, system components, or devices; privately owned computing and communication devices in commercial or public facilities; systems owned or controlled by nonfederal organizations; and systems managed by contractors. Organizations have the option to prohibit the use of any type of external system or specified types of external systems (e.g., prohibit the use of external systems that are not organizationally owned). Terms and conditions are consistent with the trust relationships established with the entities that own, operate, or maintain external systems and include descriptions of shared responsibilities.&lt;br /&gt;
&lt;br /&gt;
Authorized individuals include organizational personnel, contractors, or other individuals with authorized access to the organizational system and over whom organizations have the authority to impose specific rules of behavior regarding system access. Restrictions that organizations impose on authorized individuals may vary depending on the trust relationships between organizations. Organizations need assurance that external systems satisfy the necessary security requirements so as not to compromise, damage, or harm the system. This requirement is related to [[#sec-sec_03.16.03|03.16.03]].&lt;br /&gt;
&lt;br /&gt;
===== REFERENCES =====&lt;br /&gt;
&lt;br /&gt;
Source Controls: [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=AC-20 AC-20], [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=AC-20 AC-20(01)], [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=AC-20 AC-20(02)]&lt;br /&gt;
&lt;br /&gt;
Supporting Publications: None&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;d30e1626-Head3&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&amp;lt;span id=&amp;quot;sec-sec_03.01.21&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&lt;br /&gt;
==== 03.01.21 Withdrawn ====&lt;br /&gt;
&lt;br /&gt;
Incorporated into [[#sec-sec_03.01.20|03.01.20]].&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;d30e1636-Head3&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&amp;lt;span id=&amp;quot;sec-sec_03.01.22&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&lt;br /&gt;
==== 03.01.22 Publicly Accessible Content ====&lt;br /&gt;
&lt;br /&gt;
# Train authorized individuals to ensure that publicly accessible information does not contain CUI.&lt;br /&gt;
# Review the content on publicly accessible systems for CUI and remove such information, if discovered.&lt;br /&gt;
&lt;br /&gt;
===== DISCUSSION =====&lt;br /&gt;
&lt;br /&gt;
In accordance with applicable laws, Executive Orders, directives, policies, regulations, standards, and guidelines, the public is not authorized to have access to nonpublic information, including CUI.&lt;br /&gt;
&lt;br /&gt;
===== REFERENCES =====&lt;br /&gt;
&lt;br /&gt;
Source Control: [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=AC-22 AC-22]&lt;br /&gt;
&lt;br /&gt;
Supporting Publications: None&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;d30e1666-Head2&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&amp;lt;span id=&amp;quot;sec-sec_3.2&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&lt;br /&gt;
=== 3.2 Awareness and Training ===&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;d30e1671-Head3&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&amp;lt;span id=&amp;quot;sec-sec_03.02.01&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&lt;br /&gt;
==== 03.02.01 Literacy Training and Awareness ====&lt;br /&gt;
&lt;br /&gt;
# Provide security literacy training to system users:&lt;br /&gt;
## As part of initial training for new users and [&#039;&#039;Assignment: organization-defined frequency&#039;&#039;] thereafter,&lt;br /&gt;
## When required by system changes or following [&#039;&#039;Assignment: organization-defined events&#039;&#039;], and&lt;br /&gt;
## On recognizing and reporting indicators of insider threat, social engineering, and social mining.&lt;br /&gt;
# Update security literacy training content [&#039;&#039;Assignment: organization-defined frequency&#039;&#039;] and following [&#039;&#039;Assignment: organization-defined events&#039;&#039;].&lt;br /&gt;
&lt;br /&gt;
===== DISCUSSION =====&lt;br /&gt;
&lt;br /&gt;
Organizations provide basic and advanced levels of security literacy training to system users (including managers, senior executives, system administrators, and contractors) and measures to test the knowledge level of users. Organizations determine the content of literacy training based on specific organizational requirements, the systems to which personnel have authorized access, and work environments (e.g., telework). The content includes an understanding of the need for security and the actions required of users to maintain security and respond to incidents. The content also addresses the need for operations security and the handling of CUI.&lt;br /&gt;
&lt;br /&gt;
Security awareness techniques include displaying posters, offering supplies inscribed with security reminders, generating email advisories or notices from organizational officials, displaying logon screen messages, and conducting awareness events using podcasts, videos, and webinars. Security literacy training is conducted at a frequency consistent with applicable laws, directives, regulations, and policies. Updating literacy training content on a regular basis ensures that the content remains relevant. Events that may precipitate an update to literacy training content include assessment or audit findings, security incidents or breaches, or changes in applicable laws, Executive Orders, directives, regulations, policies, standards, and guidelines.&lt;br /&gt;
&lt;br /&gt;
Potential indicators and possible precursors of insider threats include behaviors such as inordinate, long-term job dissatisfaction; attempts to gain access to information that is not required for job performance; unexplained access to financial resources; sexual harassment or bullying of fellow employees; workplace violence; and other serious violations of the policies, procedures, rules, directives, or practices of organizations. Organizations may consider tailoring insider threat awareness topics to roles (e.g., training for managers may be focused on specific changes in the behavior of team members, while training for employees may be focused on more general observations).&lt;br /&gt;
&lt;br /&gt;
Social engineering is an attempt to deceive an individual into revealing information or taking an action that can be used to breach, compromise, or otherwise adversely impact a system. Social engineering includes phishing, pretexting, impersonation, baiting, quid pro quo, threadjacking, social media exploitation, and tailgating. Social mining is an attempt to gather information about the organization that may be used to support future attacks. Security literacy training includes how to communicate employee and management concerns regarding potential indicators of insider threat and potential and actual instances of social engineering and data mining through appropriate organizational channels in accordance with established policies and procedures.&lt;br /&gt;
&lt;br /&gt;
===== REFERENCES =====&lt;br /&gt;
&lt;br /&gt;
Source Controls: [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=AT-02 AT-02], [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=AT-02 AT-02(02)], [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=AT-02 AT-02(03)]&lt;br /&gt;
&lt;br /&gt;
Supporting Publications: SP 800-50 [[#bibr-ref_32|32]], SP 800-160-2 [[#bibr-ref_10|10]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;d30e1747-Head3&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&amp;lt;span id=&amp;quot;sec-sec_03.02.02&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&lt;br /&gt;
==== 03.02.02 Role-Based Training ====&lt;br /&gt;
&lt;br /&gt;
# Provide role-based security training to organizational personnel:&lt;br /&gt;
## Before authorizing access to the system or CUI, before performing assigned duties, and [&#039;&#039;Assignment: organization-defined frequency&#039;&#039;] thereafter&lt;br /&gt;
## When required by system changes or following [&#039;&#039;Assignment: organization-defined events&#039;&#039;].&lt;br /&gt;
# Update role-based training content [&#039;&#039;Assignment: organization-defined frequency&#039;&#039;] and following [&#039;&#039;Assignment: organization-defined events&#039;&#039;].&lt;br /&gt;
&lt;br /&gt;
===== DISCUSSION =====&lt;br /&gt;
&lt;br /&gt;
Organizations determine the content and frequency of security training based on the assigned duties, roles, and responsibilities of individuals and the security requirements of the systems to which personnel have authorized access. In addition, organizations provide system developers, enterprise architects, security architects, software developers, systems integrators, acquisition/procurement officials, system and network administrators, personnel conducting configuration management and auditing activities, personnel performing independent verification and validation, security assessors, and personnel with access to system-level software with security-related technical training specifically tailored for their assigned duties.&lt;br /&gt;
&lt;br /&gt;
Comprehensive role-based training addresses management, operational, and technical roles and responsibilities that cover physical, personnel, and technical controls. Such training can include policies, procedures, tools, and artifacts for the security roles defined. Organizations also provide the training necessary for individuals to carry out their responsibilities related to operations and supply chain security within the context of organizational information security programs.&lt;br /&gt;
&lt;br /&gt;
===== REFERENCES =====&lt;br /&gt;
&lt;br /&gt;
Source Control: [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=AT-03 AT-03]&lt;br /&gt;
&lt;br /&gt;
Supporting Publications: SP 800-161 [[#bibr-ref_33|33]], SP 800-181 [[#bibr-ref_34|34]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;d30e1808-Head3&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&amp;lt;span id=&amp;quot;sec-sec_03.02.03&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&lt;br /&gt;
==== 03.02.03 Withdrawn ====&lt;br /&gt;
&lt;br /&gt;
Incorporated into [[#sec-sec_03.02.01|03.02.01]].&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;d30e1818-Head2&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&amp;lt;span id=&amp;quot;sec-sec_3.3&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&lt;br /&gt;
=== 3.3 Audit and Accountability ===&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;d30e1823-Head3&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&amp;lt;span id=&amp;quot;sec-sec_03.03.01&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&lt;br /&gt;
==== 03.03.01 Event Logging ====&lt;br /&gt;
&lt;br /&gt;
# Specify the following event types selected for logging within the system: [&#039;&#039;Assignment: organization-defined event types&#039;&#039;].&lt;br /&gt;
# Review and update the event types selected for logging [&#039;&#039;Assignment: organization-defined frequency&#039;&#039;].&lt;br /&gt;
&lt;br /&gt;
===== DISCUSSION =====&lt;br /&gt;
&lt;br /&gt;
An event is any observable occurrence in a system, including unlawful or unauthorized system activity. Organizations identify event types for which a logging functionality is needed. This includes events that are relevant to the security of systems and the environments in which those systems operate to meet specific and ongoing auditing needs. Event types can include password changes, the execution of privileged functions, failed logons or accesses related to systems, administrative privilege usage, or third-party credential usage. In determining event types that require logging, organizations consider the system monitoring and auditing that are appropriate for each of the security requirements. When defining event types, organizations consider the logging necessary to cover related events, such as the steps in distributed, transaction-based processes (e.g., processes that are distributed across multiple organizations) and actions that occur in service-oriented or cloud-based architectures.&lt;br /&gt;
&lt;br /&gt;
Monitoring and auditing requirements can be balanced with other system needs. For example, organizations may determine that systems must have the capability to log every file access — both successful and unsuccessful — but only activate that capability under specific circumstances due to the potential burden on system performance. The event types that are logged by organizations may change over time. Reviewing and updating the set of logged event types are necessary to ensure that the current set of event types remains relevant.&lt;br /&gt;
&lt;br /&gt;
===== REFERENCES =====&lt;br /&gt;
&lt;br /&gt;
Source Control: [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=AU-02 AU-02]&lt;br /&gt;
&lt;br /&gt;
Supporting Publications: SP 800-92 [[#bibr-ref_35|35]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;d30e1864-Head3&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&amp;lt;span id=&amp;quot;sec-sec_03.03.02&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&lt;br /&gt;
==== 03.03.02 Audit Record Content ====&lt;br /&gt;
&lt;br /&gt;
# Include the following content in audit records:&lt;br /&gt;
## What type of event occurred&lt;br /&gt;
## When the event occurred&lt;br /&gt;
## Where the event occurred&lt;br /&gt;
## Source of the event&lt;br /&gt;
## Outcome of the event&lt;br /&gt;
## Identity of the individuals, subjects, objects, or entities associated with the event&lt;br /&gt;
# Provide additional information for audit records as needed.&lt;br /&gt;
&lt;br /&gt;
===== DISCUSSION =====&lt;br /&gt;
&lt;br /&gt;
Audit record content that may be necessary to support the auditing function includes time stamps, source and destination addresses, user or process identifiers, event descriptions, file names, and the access control or flow control rules that are invoked. Event outcomes can include indicators of event success or failure and event-specific results (e.g., the security state of the system after the event occurred). Detailed information that organizations consider in audit records may include a full text recording of privileged commands or the individual identities of group account users.&lt;br /&gt;
&lt;br /&gt;
===== REFERENCES =====&lt;br /&gt;
&lt;br /&gt;
Source Controls: [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=AU-03 AU-03], [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=AU-03 AU-03(01)]&lt;br /&gt;
&lt;br /&gt;
Supporting Publications: None&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;d30e1920-Head3&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&amp;lt;span id=&amp;quot;sec-sec_03.03.03&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&lt;br /&gt;
==== 03.03.03 Audit Record Generation ====&lt;br /&gt;
&lt;br /&gt;
# Generate audit records for the selected event types and audit record content specified in [[#sec-sec_03.03.01|03.03.01]] and [[#sec-sec_03.03.02|03.03.02]].&lt;br /&gt;
# Retain audit records for a time period consistent with the records retention policy.&lt;br /&gt;
&lt;br /&gt;
===== DISCUSSION =====&lt;br /&gt;
&lt;br /&gt;
Audit records can be generated at various levels of abstraction, including at the packet level as information traverses the network. Selecting the appropriate level of abstraction is a critical aspect of an audit logging capability and can facilitate the identification of root causes to problems. The ability to add information generated in audit records is dependent on system functionality to configure the audit record content. Organizations may consider additional information in audit records, including the access control or flow control rules invoked and the individual identities of group account users. Organizations may also consider limiting additional audit record information to only information that is explicitly needed for audit requirements.&lt;br /&gt;
&lt;br /&gt;
===== REFERENCES =====&lt;br /&gt;
&lt;br /&gt;
Source Controls: [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=AU-11 AU-11], [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=AU-12 AU-12]&lt;br /&gt;
&lt;br /&gt;
Supporting Publications: SP 800-92 [[#bibr-ref_35|35]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;d30e1963-Head3&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&amp;lt;span id=&amp;quot;sec-sec_03.03.04&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&lt;br /&gt;
==== 03.03.04 Response to Audit Logging Process Failures ====&lt;br /&gt;
&lt;br /&gt;
# Alert organizational personnel or roles within [&#039;&#039;Assignment: organization-defined time period&#039;&#039;] in the event of an audit logging process failure.&lt;br /&gt;
# Take the following additional actions: [&#039;&#039;Assignment: organization-defined additional actions&#039;&#039;].&lt;br /&gt;
&lt;br /&gt;
===== DISCUSSION =====&lt;br /&gt;
&lt;br /&gt;
Audit logging process failures include software and hardware errors, failures in audit log capturing mechanisms, and reaching or exceeding audit log storage capacity. Response actions include overwriting the oldest audit records, shutting down the system, and stopping the generation of audit records. Organizations may choose to define additional actions for audit logging process failures based on the type of failure, the location of the failure, the severity of the failure, or a combination of such factors. When the audit logging process failure is related to storage, the response is carried out for the audit log storage repository (i.e., the distinct system component where the audit logs are stored), the system on which the audit logs reside, the total audit log storage capacity of the organization (i.e., all audit log storage repositories combined), or all three. Organizations may decide to take no additional actions after alerting designated roles or personnel.&lt;br /&gt;
&lt;br /&gt;
===== REFERENCES =====&lt;br /&gt;
&lt;br /&gt;
Source Control: [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=AU-05 AU-05]&lt;br /&gt;
&lt;br /&gt;
Supporting Publications: None&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;d30e1998-Head3&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&amp;lt;span id=&amp;quot;sec-sec_03.03.05&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&lt;br /&gt;
==== 03.03.05 Audit Record Review, Analysis, and Reporting ====&lt;br /&gt;
&lt;br /&gt;
# Review and analyze system audit records [&#039;&#039;Assignment: organization-defined frequency&#039;&#039;] for indications and the potential impact of inappropriate or unusual activity.&lt;br /&gt;
# Report findings to organizational personnel or roles.&lt;br /&gt;
# Analyze and correlate audit records across different repositories to gain organization-wide situational awareness.&lt;br /&gt;
&lt;br /&gt;
===== DISCUSSION =====&lt;br /&gt;
&lt;br /&gt;
Audit record review, analysis, and reporting cover information security logging performed by organizations and can include logging that results from the monitoring of account usage, remote access, wireless connectivity, configuration settings, the use of maintenance tools and nonlocal maintenance, system component inventory, mobile device connection, equipment delivery and removal, physical access, temperature and humidity, communications at system interfaces, and the use of mobile code. Findings can be reported to organizational entities, such as the incident response team, help desk, and security or privacy offices. If organizations are prohibited from reviewing and analyzing audit records or unable to conduct such activities, the review or analysis may be carried out by other organizations granted such authority. The scope, frequency, and/or depth of the audit record review, analysis, and reporting may be adjusted to meet organizational needs based on new information received. Correlating audit record review, analysis, and reporting processes helps to ensure that audit records collectively create a more complete view of events.&lt;br /&gt;
&lt;br /&gt;
===== REFERENCES =====&lt;br /&gt;
&lt;br /&gt;
Source Controls: [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=AU-06 AU-06], [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=AU-06 AU-06(03)]&lt;br /&gt;
&lt;br /&gt;
Supporting Publications: SP 800-86 [[#bibr-ref_36|36]], SP 800-101 [[#bibr-ref_37|37]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;d30e2044-Head3&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&amp;lt;span id=&amp;quot;sec-sec_03.03.06&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&lt;br /&gt;
==== 03.03.06 Audit Record Reduction and Report Generation ====&lt;br /&gt;
&lt;br /&gt;
# Implement an audit record reduction and report generation capability that supports audit record review, analysis, reporting requirements, and after-the-fact investigations of incidents.&lt;br /&gt;
# Preserve the original content and time ordering of audit records.&lt;br /&gt;
&lt;br /&gt;
===== DISCUSSION =====&lt;br /&gt;
&lt;br /&gt;
Audit records are generated in [[#sec-sec_03.03.03|03.03.03]]. Audit record reduction and report generation occur after audit record generation. Audit record reduction is a process that manipulates collected audit information and organizes it in a summary format that is more meaningful to analysts. Audit record reduction and report generation capabilities do not always come from the same system or organizational entities that conduct auditing activities. An audit record reduction capability can include, for example, modern data mining techniques with advanced data filters to identify anomalous behavior in audit records. The report generation capability provided by the system can help generate customizable reports. The time ordering of audit records can be a significant issue if the granularity of the time stamp in the record is insufficient.&lt;br /&gt;
&lt;br /&gt;
===== REFERENCES =====&lt;br /&gt;
&lt;br /&gt;
Source Control: [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=AU-07 AU-07]&lt;br /&gt;
&lt;br /&gt;
Supporting Publications: None&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;d30e2077-Head3&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&amp;lt;span id=&amp;quot;sec-sec_03.03.07&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&lt;br /&gt;
==== 03.03.07 Time Stamps ====&lt;br /&gt;
&lt;br /&gt;
# Use internal system clocks to generate time stamps for audit records.&lt;br /&gt;
# Record time stamps for audit records that meet [&#039;&#039;Assignment: organization-defined granularity of time measurement&#039;&#039;] and that use Coordinated Universal Time (UTC), have a fixed local time offset from UTC, or include the local time offset as part of the time stamp.&lt;br /&gt;
&lt;br /&gt;
===== DISCUSSION =====&lt;br /&gt;
&lt;br /&gt;
Time stamps generated by the system include the date and time. Time is often expressed in Coordinated Universal Time (UTC) — a modern continuation of Greenwich Mean Time (GMT) — or local time with an offset from UTC. The granularity of time measurements refers to the degree of synchronization between system clocks and reference clocks (e.g., clocks synchronizing within hundreds or tens of milliseconds). Organizations may define different time granularities for system components. Time service can be critical to other security capabilities (e.g., access control and identification and authentication), depending on the nature of the mechanisms used to support those capabilities.&lt;br /&gt;
&lt;br /&gt;
===== REFERENCES =====&lt;br /&gt;
&lt;br /&gt;
Source Control: [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=AU-08 AU-08]&lt;br /&gt;
&lt;br /&gt;
Supporting Publications: None&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;d30e2109-Head3&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&amp;lt;span id=&amp;quot;sec-sec_03.03.08&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&lt;br /&gt;
==== 03.03.08 Protection of Audit Information ====&lt;br /&gt;
&lt;br /&gt;
# Protect audit information and audit logging tools from unauthorized access, modification, and deletion.&lt;br /&gt;
# Authorize access to management of audit logging functionality to only a subset of privileged users or roles.&lt;br /&gt;
&lt;br /&gt;
===== DISCUSSION =====&lt;br /&gt;
&lt;br /&gt;
Audit information includes the information needed to successfully audit system activity, such as audit records, audit log settings, audit reports, and personally identifiable information. Audit logging tools are programs and devices used to conduct audit and logging activities. The protection of audit information focuses on technical protection and limits the ability to access and execute audit logging tools to authorized individuals. The physical protection of audit information is addressed by media and physical protection requirements.&lt;br /&gt;
&lt;br /&gt;
Individuals or roles with privileged access to a system and who are also the subject of an audit by that system may affect the reliability of the audit information by inhibiting audit activities or modifying audit records. Requiring privileged access to be further defined between audit-related privileges and other privileges limits the number of users or roles with audit-related privileges.&lt;br /&gt;
&lt;br /&gt;
===== REFERENCES =====&lt;br /&gt;
&lt;br /&gt;
Source Controls: [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=AU-09 AU-09], [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=AU-09 AU-09(04)]&lt;br /&gt;
&lt;br /&gt;
Supporting Publications: None&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;d30e2145-Head3&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&amp;lt;span id=&amp;quot;sec-sec_03.03.09&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&lt;br /&gt;
==== 03.03.09 Withdrawn ====&lt;br /&gt;
&lt;br /&gt;
Incorporated into [[#sec-sec_03.03.08|03.03.08]].&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;d30e2155-Head2&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&amp;lt;span id=&amp;quot;sec-sec_3.4&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&lt;br /&gt;
=== 3.4 Configuration Management ===&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;d30e2160-Head3&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&amp;lt;span id=&amp;quot;sec-sec_03.04.01&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&lt;br /&gt;
==== 03.04.01 Baseline Configuration ====&lt;br /&gt;
&lt;br /&gt;
# Develop and maintain under configuration control, a current baseline configuration of the system.&lt;br /&gt;
# Review and update the baseline configuration of the system [&#039;&#039;Assignment: organization-defined frequency&#039;&#039;] and when system components are installed or modified.&lt;br /&gt;
&lt;br /&gt;
===== DISCUSSION =====&lt;br /&gt;
&lt;br /&gt;
Baseline configurations for the system and system components include aspects of connectivity, operation, and communications. Baseline configurations are documented, formally reviewed, and agreed-upon specifications for the system or configuration items within the system. Baseline configurations serve as a basis for future builds, releases, or changes to the system and include information about system components, operational procedures, network topology, and the placement of components in the system architecture. Maintaining baseline configurations requires creating new baselines as the system changes over time. Baseline configurations of the system reflect the current enterprise architecture.&lt;br /&gt;
&lt;br /&gt;
===== REFERENCES =====&lt;br /&gt;
&lt;br /&gt;
Source Control: [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=CM-02 CM-02]&lt;br /&gt;
&lt;br /&gt;
Supporting Publications: SP 800-124 [[#bibr-ref_28|28]], SP 800-128 [[#bibr-ref_41|41]], IR 8011-2 [[#bibr-ref_42|42]], IR 8011-3 [[#bibr-ref_43|43]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;d30e2205-Head3&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&amp;lt;span id=&amp;quot;sec-sec_03.04.02&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&lt;br /&gt;
==== 03.04.02 Configuration Settings ====&lt;br /&gt;
&lt;br /&gt;
# Establish, document, and implement the following configuration settings for the system that reflect the most restrictive mode consistent with operational requirements: [&#039;&#039;Assignment: organization-defined configuration settings&#039;&#039;].&lt;br /&gt;
# Identify, document, and approve any deviations from established configuration settings.&lt;br /&gt;
&lt;br /&gt;
===== DISCUSSION =====&lt;br /&gt;
&lt;br /&gt;
Configuration settings are the set of parameters that can be changed in hardware, software, or firmware components of the system and that affect the security posture or functionality of the system. Security-related configuration settings can be defined for systems (e.g., servers, workstations), input and output devices (e.g., scanners, copiers, printers), network components (e.g., firewalls, routers, gateways, voice and data switches, wireless access points, network appliances, sensors), operating systems, middleware, and applications.&lt;br /&gt;
&lt;br /&gt;
Security parameters are those parameters that impact the security state of the system, including the parameters required to satisfy other security requirements. Security parameters include registry settings; account, file, and directory permission settings (i.e., privileges); and settings for functions, ports, protocols, and remote connections. Organizations establish organization-wide configuration settings and subsequently derive specific configuration settings for the system. The established settings become part of the system’s configuration baseline.&lt;br /&gt;
&lt;br /&gt;
Common secure configurations (also referred to as security configuration checklists, lockdown and hardening guides, security reference guides, and security technical implementation guides) provide recognized, standardized, and established benchmarks that stipulate secure configuration settings for specific information technology platforms/products and instructions for configuring those system components to meet operational requirements. Common secure configurations can be developed by a variety of organizations, including information technology product developers, manufacturers, vendors, consortia, academia, industry, federal agencies, and other organizations in the public and private sectors.&lt;br /&gt;
&lt;br /&gt;
===== REFERENCES =====&lt;br /&gt;
&lt;br /&gt;
Source Control: [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=CM-06 CM-06]&lt;br /&gt;
&lt;br /&gt;
Supporting Publications: SP 800-70 [[#bibr-ref_44|44]], SP 800-126 [[#bibr-ref_45|45]], SP 800-128 [[#bibr-ref_41|41]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;d30e2251-Head3&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&amp;lt;span id=&amp;quot;sec-sec_03.04.03&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&lt;br /&gt;
==== 03.04.03 Configuration Change Control ====&lt;br /&gt;
&lt;br /&gt;
# Define the types of changes to the system that are configuration-controlled.&lt;br /&gt;
# Review proposed configuration-controlled changes to the system, and approve or disapprove such changes with explicit consideration for security impacts.&lt;br /&gt;
# Implement and document approved configuration-controlled changes to the system.&lt;br /&gt;
# Monitor and review activities associated with configuration-controlled changes to the system.&lt;br /&gt;
&lt;br /&gt;
===== DISCUSSION =====&lt;br /&gt;
&lt;br /&gt;
Configuration change control refers to tracking, reviewing, approving or disapproving, and logging changes to the system. Specifically, it involves the systematic proposal, justification, implementation, testing, review, and disposition of changes to the system, including system upgrades and modifications. Configuration change control includes changes to baseline configurations for system components (e.g., operating systems, applications, firewalls, routers, mobile devices) and configuration items of the system, changes to configuration settings, unscheduled and unauthorized changes, and changes to remediate vulnerabilities. This requirement is related to [[#sec-sec_03.04.04|03.04.04]].&lt;br /&gt;
&lt;br /&gt;
===== REFERENCES =====&lt;br /&gt;
&lt;br /&gt;
Source Control: [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=CM-03 CM-03]&lt;br /&gt;
&lt;br /&gt;
Supporting Publications: SP 800-124 [[#bibr-ref_28|28]], SP 800-128 [[#bibr-ref_41|41]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;d30e2295-Head3&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&amp;lt;span id=&amp;quot;sec-sec_03.04.04&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&lt;br /&gt;
==== 03.04.04 Impact Analyses ====&lt;br /&gt;
&lt;br /&gt;
# Analyze changes to the system to determine potential security impacts prior to change implementation.&lt;br /&gt;
# Verify that the security requirements for the system continue to be satisfied after the system changes have been implemented.&lt;br /&gt;
&lt;br /&gt;
===== DISCUSSION =====&lt;br /&gt;
&lt;br /&gt;
Organizational personnel with security responsibilities conduct impact analyses that include reviewing system security plans, policies, and procedures to understand security requirements; reviewing system design documentation and operational procedures to understand how system changes might affect the security state of the system; reviewing the impacts of system changes on supply chain partners with stakeholders; and determining how potential changes to a system create new risks and the ability to mitigate those risks. Impact analyses also include risk assessments to understand the impacts of changes and determine whether additional security requirements are needed. Changes to the system may affect the safeguards and countermeasures previously implemented. This requirement is related to [[#sec-sec_03.04.03|03.04.03]]. Not all changes to the system are configuration controlled.&lt;br /&gt;
&lt;br /&gt;
===== REFERENCES =====&lt;br /&gt;
&lt;br /&gt;
Source Controls: [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=CM-04 CM-04], [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=CM-04 CM-04(02)]&lt;br /&gt;
&lt;br /&gt;
Supporting Publications: SP 800-128 [[#bibr-ref_41|41]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;d30e2335-Head3&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&amp;lt;span id=&amp;quot;sec-sec_03.04.05&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&lt;br /&gt;
==== 03.04.05 Access Restrictions for Change ====&lt;br /&gt;
&lt;br /&gt;
Define, document, approve, and enforce physical and logical access restrictions associated with changes to the system.&lt;br /&gt;
&lt;br /&gt;
===== DISCUSSION =====&lt;br /&gt;
&lt;br /&gt;
Changes to the hardware, software, or firmware components of the system or the operational procedures related to the system can have potentially significant effects on the security of the system. Therefore, organizations permit only qualified and authorized individuals to access the system for the purpose of initiating changes. Access restrictions include physical and logical access controls, software libraries, workflow automation, media libraries, abstract layers (i.e., changes implemented into external interfaces rather than directly into the system), and change windows (i.e., changes occur only during specified times).&lt;br /&gt;
&lt;br /&gt;
===== REFERENCES =====&lt;br /&gt;
&lt;br /&gt;
Source Control: [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=CM-05 CM-05]&lt;br /&gt;
&lt;br /&gt;
Supporting Publications: FIPS 140-3 [[#bibr-ref_38|38]], FIPS 180-4 [[#bibr-ref_39|39]], SP 800-128 [[#bibr-ref_41|41]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;d30e2365-Head3&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&amp;lt;span id=&amp;quot;sec-sec_03.04.06&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&lt;br /&gt;
==== 03.04.06 Least Functionality ====&lt;br /&gt;
&lt;br /&gt;
# Configure the system to provide only mission-essential capabilities.&lt;br /&gt;
# Prohibit or restrict use of the following functions, ports, protocols, connections, and services: [&#039;&#039;Assignment: organization-defined functions, ports, protocols, connections, and services&#039;&#039;].&lt;br /&gt;
# Review the system [&#039;&#039;Assignment: organization-defined frequency&#039;&#039;] to identify unnecessary or nonsecure functions, ports, protocols, connections, and services.&lt;br /&gt;
# Disable or remove functions, ports, protocols, connections, and services that are unnecessary or nonsecure.&lt;br /&gt;
&lt;br /&gt;
===== DISCUSSION =====&lt;br /&gt;
&lt;br /&gt;
Systems can provide a variety of functions and services. Some functions and services that are routinely provided by default may not be necessary to support essential organizational missions, functions, or operations. It may be convenient to provide multiple services from single system components. However, doing so increases risk over limiting the services provided by any one component. Where feasible, organizations limit functionality to a single function per component.&lt;br /&gt;
&lt;br /&gt;
Organizations review the functions and services provided by the system or system components to determine which functions and services are candidates for elimination. Organizations disable unused or unnecessary physical and logical ports and protocols to prevent the unauthorized connection of devices, the transfer of information, and tunneling. Organizations can employ network scanning tools, intrusion detection and prevention systems, and endpoint protection systems (e.g., firewalls and host-based intrusion detection systems) to identify and prevent the use of prohibited functions, ports, protocols, system connections, and services. Bluetooth, File Transfer Protocol (FTP), and peer-to-peer networking are examples of the types of protocols that organizations consider eliminating, restricting, or disabling.&lt;br /&gt;
&lt;br /&gt;
===== REFERENCES =====&lt;br /&gt;
&lt;br /&gt;
Source Controls: [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=CM-07 CM-07], [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=CM-07 CM-07(01)]&lt;br /&gt;
&lt;br /&gt;
Supporting Publications: SP 800-160-1 [[#bibr-ref_11|11]], SP 800-167 [[#bibr-ref_46|46]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;d30e2418-Head3&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&amp;lt;span id=&amp;quot;sec-sec_03.04.07&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&lt;br /&gt;
==== 03.04.07 Withdrawn ====&lt;br /&gt;
&lt;br /&gt;
Incorporated into [[#sec-sec_03.04.06|03.04.06]] and [[#sec-sec_03.04.08|03.04.08]].&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;d30e2432-Head3&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&amp;lt;span id=&amp;quot;sec-sec_03.04.08&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&lt;br /&gt;
==== 03.04.08 Authorized Software – Allow by Exception ====&lt;br /&gt;
&lt;br /&gt;
# Identify software programs authorized to execute on the system.&lt;br /&gt;
# Implement a deny-all, allow-by-exception policy for the execution of authorized software programs on the system.&lt;br /&gt;
# Review and update the list of authorized software programs [&#039;&#039;Assignment: organization-defined frequency&#039;&#039;].&lt;br /&gt;
&lt;br /&gt;
===== DISCUSSION =====&lt;br /&gt;
&lt;br /&gt;
If provided with the necessary privileges, users can install software in organizational systems. To maintain control over the software installed, organizations identify permitted and prohibited actions regarding software installation. Permitted software installations include updates and security patches to existing software and downloading new applications from organization-approved “app stores.” The policies selected for governing user-installed software are organization-developed or provided by some external entity. Policy enforcement methods can include procedural methods and automated methods.&lt;br /&gt;
&lt;br /&gt;
Authorized software programs can be limited to specific versions or come from specific sources. To facilitate a comprehensive authorized software process and increase the strength of protection against attacks that bypass application-level authorized software, software programs may be decomposed into and monitored at different levels of detail. These levels include applications, application programming interfaces, application modules, scripts, system processes, system services, kernel functions, registries, drivers, and dynamic link libraries.&lt;br /&gt;
&lt;br /&gt;
===== REFERENCES =====&lt;br /&gt;
&lt;br /&gt;
Source Control: [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=CM-07 CM-07(05)]&lt;br /&gt;
&lt;br /&gt;
Supporting Publications: SP 800-160-1 [[#bibr-ref_11|11]], SP 800-167 [[#bibr-ref_46|46]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;d30e2475-Head3&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&amp;lt;span id=&amp;quot;sec-sec_03.04.09&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&lt;br /&gt;
==== 03.04.09 Withdrawn ====&lt;br /&gt;
&lt;br /&gt;
Addressed by [[#sec-sec_03.01.05|03.01.05]], [[#sec-sec_03.04.08|03.04.08]], and [[#sec-sec_03.12.03|03.12.03]].&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;d30e2492-Head3&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&amp;lt;span id=&amp;quot;sec-sec_03.04.10&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&lt;br /&gt;
==== 03.04.10 System Component Inventory ====&lt;br /&gt;
&lt;br /&gt;
# Develop and document an inventory of system components.&lt;br /&gt;
# Review and update the system component inventory [&#039;&#039;Assignment: organization-defined frequency&#039;&#039;].&lt;br /&gt;
# Update the system component inventory as part of installations, removals, and system updates.&lt;br /&gt;
&lt;br /&gt;
===== DISCUSSION =====&lt;br /&gt;
&lt;br /&gt;
System components are discrete, identifiable assets (i.e., hardware, software, and firmware elements) that compose a system. Organizations may implement centralized system component inventories that include components from all systems. In such situations, organizations ensure that the inventories include the system-specific information required for component accountability. The information necessary for effective accountability of system components includes the system name, software owners, software version numbers, software license information, hardware inventory specifications, and — for networked components — the machine names and network addresses for all implemented protocols (e.g., IPv4, IPv6). Inventory specifications include component type, physical location, date of receipt, manufacturer, cost, model, serial number, and supplier information.&lt;br /&gt;
&lt;br /&gt;
===== REFERENCES =====&lt;br /&gt;
&lt;br /&gt;
Source Controls: [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=CM-08 CM-08], [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=CM-08 CM-08(01)]&lt;br /&gt;
&lt;br /&gt;
Supporting Publications: SP 800-124 [[#bibr-ref_28|28]], SP 800-128 [[#bibr-ref_41|41]], IR 8011-2 [[#bibr-ref_42|42]], IR 8011-3 [[#bibr-ref_43|43]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;d30e2543-Head3&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&amp;lt;span id=&amp;quot;sec-sec_03.04.11&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&lt;br /&gt;
==== 03.04.11 Information Location ====&lt;br /&gt;
&lt;br /&gt;
# Identify and document the location of CUI and the system components on which the information is processed and stored.&lt;br /&gt;
# Document changes to the system or system component location where CUI is processed and stored.&lt;br /&gt;
&lt;br /&gt;
===== DISCUSSION =====&lt;br /&gt;
&lt;br /&gt;
Information location addresses the need to understand the specific system components where CUI is being processed and stored and the users who have access to CUI so that appropriate protection mechanisms can be provided, including information flow controls, access controls, and information management.&lt;br /&gt;
&lt;br /&gt;
===== REFERENCES =====&lt;br /&gt;
&lt;br /&gt;
Source Control: [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=CM-12 CM-12]&lt;br /&gt;
&lt;br /&gt;
Supporting Publications: None&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;d30e2573-Head3&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&amp;lt;span id=&amp;quot;sec-sec_03.04.12&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&lt;br /&gt;
==== 03.04.12 System and Component Configuration for High-Risk Areas ====&lt;br /&gt;
&lt;br /&gt;
# Issue systems or system components with the following configurations to individuals traveling to high-risk locations: [&#039;&#039;Assignment: organization-defined system configurations&#039;&#039;].&lt;br /&gt;
# Apply the following security requirements to the systems or components when the individuals return from travel: [&#039;&#039;Assignment: organization-defined security requirements&#039;&#039;].&lt;br /&gt;
&lt;br /&gt;
===== DISCUSSION =====&lt;br /&gt;
&lt;br /&gt;
When it is known that a system or a system component will be in a high-risk area, additional security requirements may be needed to counter the increased threat. Organizations can implement protective measures on the systems or system components used by individuals departing on and returning from travel. Actions include determining whether the locations are of concern, defining the required configurations for the components, ensuring that the components are configured as intended before travel is initiated, and taking additional actions after travel is completed. For example, systems going into high-risk areas can be configured with sanitized hard drives, limited applications, and more stringent configuration settings. Actions applied to mobile devices upon return from travel include examining the device for signs of physical tampering and purging and reimaging the device storage.&lt;br /&gt;
&lt;br /&gt;
===== REFERENCES =====&lt;br /&gt;
&lt;br /&gt;
Source Control: [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=CM-02 CM-02(07)]&lt;br /&gt;
&lt;br /&gt;
Supporting Publications: SP 800-124 [[#bibr-ref_28|28]], SP 800-128 [[#bibr-ref_41|41]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;d30e2614-Head2&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&amp;lt;span id=&amp;quot;sec-sec_3.5&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&lt;br /&gt;
=== 3.5 Identification and Authentication ===&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;d30e2620-Head3&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&amp;lt;span id=&amp;quot;sec-sec_03.05.01&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&lt;br /&gt;
==== 03.05.01 User Identification and Authentication ====&lt;br /&gt;
&lt;br /&gt;
# Uniquely identify and authenticate system users, and associate that unique identification with processes acting on behalf of those users.&lt;br /&gt;
# Re-authenticate users when [&#039;&#039;Assignment: organization-defined circumstances or situations requiring re-authentication&#039;&#039;].&lt;br /&gt;
&lt;br /&gt;
===== DISCUSSION =====&lt;br /&gt;
&lt;br /&gt;
System users include individuals (or system processes acting on behalf of individuals) who are authorized to access a system. Typically, individual identifiers are the usernames associated with the system accounts assigned to those individuals. Since system processes execute on behalf of groups and roles, organizations may require the unique identification of individuals in group accounts or the accountability of individual activity. The unique identification and authentication of users apply to all system accesses. Organizations use passwords, physical authenticators, biometrics, or some combination thereof to authenticate user identities. Organizations may re-authenticate individuals in certain situations, including when roles, authenticators, or credentials change; when the execution of privileged functions occurs; after a fixed time period; or periodically.&lt;br /&gt;
&lt;br /&gt;
===== REFERENCES =====&lt;br /&gt;
&lt;br /&gt;
Source Controls: [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=IA-02 IA-02], [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=IA-11 IA-11]&lt;br /&gt;
&lt;br /&gt;
Supporting Publications: SP 800-63-3 [[#bibr-ref_27|27]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;d30e2659-Head3&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&amp;lt;span id=&amp;quot;sec-sec_03.05.02&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&lt;br /&gt;
==== 03.05.02 Device Identification and Authentication ====&lt;br /&gt;
&lt;br /&gt;
Uniquely identify and authenticate [&#039;&#039;Assignment: organization-defined devices or types of devices&#039;&#039;] before establishing a system connection.&lt;br /&gt;
&lt;br /&gt;
===== DISCUSSION =====&lt;br /&gt;
&lt;br /&gt;
Devices that require unique device-to-device identification and authentication are defined by type, device, or a combination of type and device. Organization-defined device types include devices that are not owned by the organization. Systems use shared known information (e.g., Media Access Control [MAC], Transmission Control Protocol/Internet Protocol [TCP/IP] addresses) for device identification or organizational authentication solutions (e.g., Institute of Electrical and Electronics Engineers [IEEE] 802.1x and Extensible Authentication Protocol [EAP], RADIUS server with EAP-Transport Layer Security [TLS] authentication, Kerberos) to identify and authenticate devices on local and wide area networks. Public Key Infrastructure (PKI) and certificate revocation checking for the certificates exchanged can be included as part of device authentication.&lt;br /&gt;
&lt;br /&gt;
===== REFERENCES =====&lt;br /&gt;
&lt;br /&gt;
Source Control: [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=IA-03 IA-03]&lt;br /&gt;
&lt;br /&gt;
Supporting Publications: SP 800-63-3 [[#bibr-ref_27|27]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;d30e2686-Head3&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&amp;lt;span id=&amp;quot;sec-sec_03.05.03&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&lt;br /&gt;
==== 03.05.03 Multi-Factor Authentication ====&lt;br /&gt;
&lt;br /&gt;
Implement multi-factor authentication for access to privileged and non-privileged accounts.&lt;br /&gt;
&lt;br /&gt;
===== DISCUSSION =====&lt;br /&gt;
&lt;br /&gt;
This requirement applies to user accounts. Multi-factor authentication requires the use of two or more different factors to achieve authentication. The authentication factors are defined as follows: something you know (e.g., a personal identification number [PIN]), something you have (e.g., a physical authenticator, such as a cryptographic private key), or something you are (e.g., a biometric). Multi-factor authentication solutions that feature physical authenticators include hardware authenticators that provide time-based or challenge-response outputs and smart cards. In addition to authenticating users at the system level, organizations may also employ authentication mechanisms at the application level to provide increased information security.&lt;br /&gt;
&lt;br /&gt;
===== REFERENCES =====&lt;br /&gt;
&lt;br /&gt;
Source Controls: [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=IA-02 IA-02(01)], [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=IA-02 IA-02(02)]&lt;br /&gt;
&lt;br /&gt;
Supporting Publications: SP 800-63-3 [[#bibr-ref_27|27]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;d30e2713-Head3&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&amp;lt;span id=&amp;quot;sec-sec_03.05.04&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&lt;br /&gt;
==== 03.05.04 Replay-Resistant Authentication ====&lt;br /&gt;
&lt;br /&gt;
Implement replay-resistant authentication mechanisms for access to privileged and non-privileged accounts.&lt;br /&gt;
&lt;br /&gt;
===== DISCUSSION =====&lt;br /&gt;
&lt;br /&gt;
Authentication processes resist replay attacks if it is impractical to successfully authenticate by recording or replaying previous authentication messages. Replay-resistant techniques include protocols that use nonces or challenges, such as time synchronous or challenge-response one-time authenticators.&lt;br /&gt;
&lt;br /&gt;
===== REFERENCES =====&lt;br /&gt;
&lt;br /&gt;
Source Control: [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=IA-02 IA-02(08)]&lt;br /&gt;
&lt;br /&gt;
Supporting Publications: SP 800-63-3 [[#bibr-ref_27|27]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;d30e2737-Head3&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&amp;lt;span id=&amp;quot;sec-sec_03.05.05&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&lt;br /&gt;
==== 03.05.05 Identifier Management ====&lt;br /&gt;
&lt;br /&gt;
# Receive authorization from organizational personnel or roles to assign an individual, group, role, service, or device identifier.&lt;br /&gt;
# Select and assign an identifier that identifies an individual, group, role, service, or device.&lt;br /&gt;
# Prevent the reuse of identifiers for [&#039;&#039;Assignment: organization-defined time period&#039;&#039;].&lt;br /&gt;
# Manage individual identifiers by uniquely identifying each individual as [&#039;&#039;Assignment: organization-defined characteristic identifying individual status&#039;&#039;].&lt;br /&gt;
&lt;br /&gt;
===== DISCUSSION =====&lt;br /&gt;
&lt;br /&gt;
Identifiers are provided for users, processes acting on behalf of users, and devices. Prohibiting the reuse of identifiers prevents the assignment of previously used individual, group, role, service, or device identifiers to different individuals, groups, roles, services, or devices.&lt;br /&gt;
&lt;br /&gt;
Characteristics that identify the status of individuals include contractors, foreign nationals, and non-organizational users. Identifying the status of individuals by these characteristics provides information about the people with whom organizational personnel are communicating. For example, it is useful for an employee to know that one of the individuals on an email message is a contractor.&lt;br /&gt;
&lt;br /&gt;
===== REFERENCES =====&lt;br /&gt;
&lt;br /&gt;
Source Controls: [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=IA-04 IA-04], [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=IA-04 IA-04(04)]&lt;br /&gt;
&lt;br /&gt;
Supporting Publications: SP 800-63-3 [[#bibr-ref_27|27]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;d30e2788-Head3&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&amp;lt;span id=&amp;quot;sec-sec_03.05.06&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&lt;br /&gt;
==== 03.05.06 Withdrawn ====&lt;br /&gt;
&lt;br /&gt;
Consistency with SP 800-53 [[#bibr-ref_8|8]].&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;d30e2798-Head3&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&amp;lt;span id=&amp;quot;sec-sec_03.05.07&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&lt;br /&gt;
==== 03.05.07 Password Management ====&lt;br /&gt;
&lt;br /&gt;
# Maintain a list of commonly-used, expected, or compromised passwords, and update the list [&#039;&#039;Assignment: organization-defined frequency&#039;&#039;] and when organizational passwords are suspected to have been compromised.&lt;br /&gt;
# Verify that passwords are not found on the list of commonly used, expected, or compromised passwords when users create or update passwords.&lt;br /&gt;
# Transmit passwords only over cryptographically protected channels.&lt;br /&gt;
# Store passwords in a cryptographically protected form.&lt;br /&gt;
# Select a new password upon first use after account recovery.&lt;br /&gt;
# Enforce the following composition and complexity rules for passwords: [&#039;&#039;Assignment: organization-defined composition and complexity rules&#039;&#039;].&lt;br /&gt;
&lt;br /&gt;
===== DISCUSSION =====&lt;br /&gt;
&lt;br /&gt;
Password-based authentication applies to passwords used in single-factor or multi-factor authentication. Long passwords or passphrases are preferable to shorter passwords. Enforced composition rules provide marginal security benefits while decreasing usability. However, organizations may choose to establish and enforce certain rules for password generation (e.g., minimum character length) under certain circumstances. For example, account recovery can occur when a password is forgotten. Cryptographically protected passwords include salted one-way cryptographic hashes of passwords. The list of commonly used, compromised, or expected passwords includes passwords obtained from previous breach corpuses, dictionary words, and repetitive or sequential characters. The list includes context-specific words, such as the name of the service, username, and derivatives thereof. Changing temporary passwords to permanent passwords immediately after system logon ensures that the necessary strength of the authentication mechanism is implemented at the earliest opportunity and reduces susceptibility to authenticator compromises. Long passwords and passphrases can be used to increase the complexity of passwords.&lt;br /&gt;
&lt;br /&gt;
===== REFERENCES =====&lt;br /&gt;
&lt;br /&gt;
Source Control: [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=IA-05 IA-05(01)]&lt;br /&gt;
&lt;br /&gt;
Supporting Publications: SP 800-63-3 [[#bibr-ref_27|27]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;d30e2849-Head3&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&amp;lt;span id=&amp;quot;sec-sec_03.05.08&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&lt;br /&gt;
==== 03.05.08 Withdrawn ====&lt;br /&gt;
&lt;br /&gt;
Consistency with SP 800-53 [[#bibr-ref_8|8]].&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;d30e2859-Head3&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&amp;lt;span id=&amp;quot;sec-sec_03.05.09&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&lt;br /&gt;
==== 03.05.09 Withdrawn ====&lt;br /&gt;
&lt;br /&gt;
Consistency with SP 800-53 [[#bibr-ref_8|8]].&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;d30e2869-Head3&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&amp;lt;span id=&amp;quot;sec-sec_03.05.10&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&lt;br /&gt;
==== 03.05.10 Withdrawn ====&lt;br /&gt;
&lt;br /&gt;
Incorporated into [[#sec-sec_03.05.07|03.05.07]].&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;d30e2879-Head3&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&amp;lt;span id=&amp;quot;sec-sec_03.05.11&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&lt;br /&gt;
==== 03.05.11 Authentication Feedback ====&lt;br /&gt;
&lt;br /&gt;
Obscure feedback of authentication information during the authentication process.&lt;br /&gt;
&lt;br /&gt;
===== DISCUSSION =====&lt;br /&gt;
&lt;br /&gt;
Authentication feedback does not provide information that would allow unauthorized individuals to compromise authentication mechanisms. For example, for desktop or notebook systems with relatively large monitors, the threat may be significant (commonly referred to as shoulder surfing). For mobile devices with small displays, this threat may be less significant and is balanced against the increased likelihood of input errors due to small keyboards. Therefore, the means of obscuring authenticator feedback is selected accordingly. Obscuring feedback includes displaying asterisks when users type passwords into input devices or displaying feedback for a limited time before fully obscuring it.&lt;br /&gt;
&lt;br /&gt;
===== REFERENCES =====&lt;br /&gt;
&lt;br /&gt;
Source Control: [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=IA-06 IA-06]&lt;br /&gt;
&lt;br /&gt;
Supporting Publications: None&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;d30e2900-Head3&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&amp;lt;span id=&amp;quot;sec-sec_03.05.12&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&lt;br /&gt;
==== 03.05.12 Authenticator Management ====&lt;br /&gt;
&lt;br /&gt;
# Verify the identity of the individual, group, role, service, or device receiving the authenticator as part of the initial authenticator distribution.&lt;br /&gt;
# Establish initial authenticator content for any authenticators issued by the organization.&lt;br /&gt;
# Establish and implement administrative procedures for initial authenticator distribution; for lost, compromised, or damaged authenticators; and for revoking authenticators.&lt;br /&gt;
# Change default authenticators at first use.&lt;br /&gt;
# Change or refresh authenticators [&#039;&#039;Assignment: organization-defined frequency&#039;&#039;] or when the following events occur: [&#039;&#039;Assignment: organization-defined events&#039;&#039;].&lt;br /&gt;
# Protect authenticator content from unauthorized disclosure and modification.&lt;br /&gt;
&lt;br /&gt;
===== DISCUSSION =====&lt;br /&gt;
&lt;br /&gt;
Authenticators include passwords, cryptographic devices, biometrics, certificates, one-time password devices, and ID badges. The initial authenticator content is the actual content of the authenticator (e.g., the initial password). In contrast, requirements for authenticator content contain specific characteristics. Authenticator management is supported by organization-defined settings and restrictions for various authenticator characteristics (e.g., password complexity and composition rules, validation time window for time synchronous one-time tokens, and the number of allowed rejections during the verification stage of biometric authentication).&lt;br /&gt;
&lt;br /&gt;
The requirement to protect individual authenticators may be implemented by [[#sec-sec_03.15.03|03.15.03]] for authenticators in the possession of individuals and by [[#sec-sec_03.01.01|03.01.01]], [[#sec-sec_03.01.02|03.01.02]], [[#sec-sec_03.01.05|03.01.05]], and [[#sec-sec_03.13.08|03.13.08]] for authenticators stored in organizational systems. This includes passwords stored in hashed or encrypted formats or files that contain hashed or encrypted passwords that are accessible with administrator privileges. Actions can be taken to protect authenticators, including maintaining possession of authenticators, not sharing authenticators with others, and immediately reporting lost, stolen, or compromised authenticators.&lt;br /&gt;
&lt;br /&gt;
Developers may deliver system components with factory default authentication credentials to allow for initial installation and configuration. Default authentication credentials are often well-known, easily discoverable, and present a significant risk. Authenticator management includes issuing and revoking authenticators for temporary access when they are no longer needed. The use of long passwords or passphrases may obviate the need to periodically change authenticators.&lt;br /&gt;
&lt;br /&gt;
===== REFERENCES =====&lt;br /&gt;
&lt;br /&gt;
Source Control: [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=IA-05 IA-05]&lt;br /&gt;
&lt;br /&gt;
Supporting Publications: SP 800-63-3 [[#bibr-ref_27|27]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;d30e2970-Head2&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&amp;lt;span id=&amp;quot;sec-sec_3.6&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&lt;br /&gt;
=== 3.6 Incident Response ===&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;d30e2975-Head3&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&amp;lt;span id=&amp;quot;sec-sec_03.06.01&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&lt;br /&gt;
==== 03.06.01 Incident Handling ====&lt;br /&gt;
&lt;br /&gt;
Implement an incident-handling capability that is consistent with the incident response plan and includes preparation, detection and analysis, containment, eradication, and recovery.&lt;br /&gt;
&lt;br /&gt;
===== DISCUSSION =====&lt;br /&gt;
&lt;br /&gt;
Incident-related information can be obtained from a variety of sources, including audit monitoring, network monitoring, physical access monitoring, user and administrator reports, and reported supply chain events. An effective incident handling capability involves coordination among many organizational entities, including mission and business owners, system owners, human resources offices, physical and personnel security offices, legal departments, operations personnel, and procurement offices.&lt;br /&gt;
&lt;br /&gt;
===== REFERENCES =====&lt;br /&gt;
&lt;br /&gt;
Source Controls: [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=IR-04 IR-04]&lt;br /&gt;
&lt;br /&gt;
Supporting Publications: SP 800-50 [[#bibr-ref_32|32]], SP 800-61 [[#bibr-ref_47|47]], SP 800-161 [[#bibr-ref_33|33]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;d30e3004-Head3&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&amp;lt;span id=&amp;quot;sec-sec_03.06.02&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&lt;br /&gt;
==== 03.06.02 Incident Monitoring, Reporting, and Response Assistance ====&lt;br /&gt;
&lt;br /&gt;
# Track and document system security incidents.&lt;br /&gt;
# [&#039;&#039;Assignment: organization-defined time period&#039;&#039;].&lt;br /&gt;
# Report incident information to [&#039;&#039;Assignment: organization-defined authorities&#039;&#039;].&lt;br /&gt;
# Provide an incident response support resource that offers advice and assistance to system users on handling and reporting incidents.&lt;br /&gt;
&lt;br /&gt;
===== DISCUSSION =====&lt;br /&gt;
&lt;br /&gt;
Documenting incidents includes maintaining records about each incident, the status of the incident, and other pertinent information necessary for forensics as well as evaluating incident details, trends, and handling. Incident information can be obtained from many sources, including network monitoring, incident reports, incident response teams, user complaints, supply chain partners, audit monitoring, physical access monitoring, and user and administrator reports. [[#sec-sec_03.06.01|03.06.01]] provides information on the types of incidents that are appropriate for monitoring. The types of incidents reported, the content and timeliness of the reports, and the reporting authorities reflect applicable laws, Executive Orders, directives, regulations, policies, standards, and guidelines. Incident information informs risk assessments, the effectiveness of security assessments, the security requirements for acquisitions, and the selection criteria for technology products. Incident response support resources provided by organizations include help desks, assistance groups, automated ticketing systems to open and track incident response tickets, and access to forensic services or consumer redress services, when required.&lt;br /&gt;
&lt;br /&gt;
===== REFERENCES =====&lt;br /&gt;
&lt;br /&gt;
Source Controls: [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=IR-05 IR-05], [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=IR-06 IR-06], [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=IR-07 IR-07]&lt;br /&gt;
&lt;br /&gt;
Supporting Publications: SP 800-61 [[#bibr-ref_47|47]], SP 800-86 [[#bibr-ref_36|36]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;d30e3063-Head3&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&amp;lt;span id=&amp;quot;sec-sec_03.06.03&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&lt;br /&gt;
==== 03.06.03 Incident Response Testing ====&lt;br /&gt;
&lt;br /&gt;
Test the effectiveness of the incident response capability [&#039;&#039;Assignment: organization-defined frequency&#039;&#039;].&lt;br /&gt;
&lt;br /&gt;
===== DISCUSSION =====&lt;br /&gt;
&lt;br /&gt;
Organizations test incident response capabilities to determine their effectiveness and identify potential weaknesses or deficiencies. Incident response testing includes the use of checklists, walk-through or tabletop exercises, and simulations. Incident response testing can include a determination of the effects of incident response on organizational operations, organizational assets, and individuals. Qualitative and quantitative data can help determine the effectiveness of incident response processes.&lt;br /&gt;
&lt;br /&gt;
===== REFERENCES =====&lt;br /&gt;
&lt;br /&gt;
Source Control: [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=IR-03 IR-03]&lt;br /&gt;
&lt;br /&gt;
Supporting Publications: SP 800-84 [[#bibr-ref_48|48]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;d30e3090-Head3&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&amp;lt;span id=&amp;quot;sec-sec_03.06.04&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&lt;br /&gt;
==== 03.06.04 Incident Response Training ====&lt;br /&gt;
&lt;br /&gt;
# Provide incident response training to system users consistent with assigned roles and responsibilities:&lt;br /&gt;
## Within [&#039;&#039;Assignment: organization-defined time period&#039;&#039;] of assuming an incident response role or responsibility or acquiring system access,&lt;br /&gt;
## When required by system changes, and&lt;br /&gt;
## [&#039;&#039;Assignment: organization-defined frequency&#039;&#039;] thereafter.&lt;br /&gt;
# Review and update incident response training content [&#039;&#039;Assignment: organization-defined frequency&#039;&#039;] and following [&#039;&#039;Assignment: organization-defined events&#039;&#039;].&lt;br /&gt;
&lt;br /&gt;
===== DISCUSSION =====&lt;br /&gt;
&lt;br /&gt;
Incident response training is associated with the assigned roles and responsibilities of organizational personnel to ensure that the appropriate content and level of detail are included in such training. For example, users may only need to know how to recognize an incident or whom to call; system administrators may require additional training on how to handle incidents; and incident responders may receive specific training on data collection techniques, forensics, reporting, system recovery, and system restoration. Incident response training includes user training in identifying and reporting suspicious activities from external and internal sources. Incident response training for users may be provided as part of [[#sec-sec_03.02.02|03.02.02]]. Events that may cause an update to incident response training content include incident response plan testing, response to an actual incident, audit or assessment findings, or changes in applicable laws, Executive Orders, policies, directives, regulations, standards, and guidelines.&lt;br /&gt;
&lt;br /&gt;
===== REFERENCES =====&lt;br /&gt;
&lt;br /&gt;
Source Control: [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=IR-02 IR-02]&lt;br /&gt;
&lt;br /&gt;
Supporting Publications: SP 800-86 [[#bibr-ref_36|36]], SP 800-137 [[#bibr-ref_49|49]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;d30e3154-Head3&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&amp;lt;span id=&amp;quot;sec-sec_03.06.05&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&lt;br /&gt;
==== 03.06.05 Incident Response Plan ====&lt;br /&gt;
&lt;br /&gt;
# Develop an incident response plan that:&lt;br /&gt;
## Provides the organization with a roadmap for implementing its incident response capability,&lt;br /&gt;
## Describes the structure and organization of the incident response capability,&lt;br /&gt;
## Provides a high-level approach for how the incident response capability fits into the overall organization,&lt;br /&gt;
## Defines reportable incidents,&lt;br /&gt;
## Addresses the sharing of incident information, and&lt;br /&gt;
## Designates responsibilities to organizational entities, personnel, or roles.&lt;br /&gt;
# Distribute copies of the incident response plan to designated incident response personnel (identified by name and/or by role) and organizational elements.&lt;br /&gt;
# Update the incident response plan to address system and organizational changes or problems encountered during plan implementation, execution, or testing.&lt;br /&gt;
# Protect the incident response plan from unauthorized disclosure.&lt;br /&gt;
&lt;br /&gt;
===== DISCUSSION =====&lt;br /&gt;
&lt;br /&gt;
It is important that organizations develop and implement a coordinated approach to incident response. Organizational mission and business functions determine the structure of incident response capabilities. As part of the incident response capabilities, organizations consider the coordination and sharing of information with external organizations, including external service providers and other organizations involved in the supply chain.&lt;br /&gt;
&lt;br /&gt;
===== REFERENCES =====&lt;br /&gt;
&lt;br /&gt;
Source Control: [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=IR-08 IR-08]&lt;br /&gt;
&lt;br /&gt;
Supporting Publications: SP 800-86 [[#bibr-ref_36|36]], SP 800-137 [[#bibr-ref_49|49]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;d30e3219-Head2&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&amp;lt;span id=&amp;quot;sec-sec_3.7&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&lt;br /&gt;
=== 3.7 Maintenance ===&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;d30e3224-Head3&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&amp;lt;span id=&amp;quot;sec-sec_03.07.01&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&lt;br /&gt;
==== 03.07.01 Withdrawn ====&lt;br /&gt;
&lt;br /&gt;
Recategorized as NCO.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;d30e3231-Head3&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&amp;lt;span id=&amp;quot;sec-sec_03.07.02&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&lt;br /&gt;
==== 03.07.02 Withdrawn ====&lt;br /&gt;
&lt;br /&gt;
Incorporated into [[#sec-sec_03.07.04|03.07.04]] and [[#sec-sec_03.07.06|03.07.06]].&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;d30e3244-Head3&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&amp;lt;span id=&amp;quot;sec-sec_03.07.03&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&lt;br /&gt;
==== 03.07.03 Withdrawn ====&lt;br /&gt;
&lt;br /&gt;
Incorporated into [[#sec-sec_03.08.03|03.08.03]].&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;d30e3255-Head3&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&amp;lt;span id=&amp;quot;sec-sec_03.07.04&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&lt;br /&gt;
==== 03.07.04 Maintenance Tools ====&lt;br /&gt;
&lt;br /&gt;
# Approve, control, and monitor the use of system maintenance tools.&lt;br /&gt;
# Check media with diagnostic and test programs for malicious code before it is used in the system.&lt;br /&gt;
&lt;br /&gt;
Prevent the removal of system maintenance equipment containing CUI by verifying that there is no CUI on the equipment, sanitizing or destroying the equipment, or retaining the equipment within the facility.&lt;br /&gt;
&lt;br /&gt;
===== DISCUSSION =====&lt;br /&gt;
&lt;br /&gt;
Approving, controlling, monitoring, and reviewing maintenance tools address security-related issues associated with the tools that are used for diagnostic and repair actions on the system. Maintenance tools can include hardware and software diagnostic and test equipment as well as packet sniffers. The tools may be pre-installed, brought in with maintenance personnel on media, cloud-based, or downloaded from a website. Diagnostic and test programs are potential vehicles for transporting malicious code into the system, either intentionally or unintentionally. Examples of media inspection include checking the cryptographic hash or digital signatures of diagnostic and test programs and media.&lt;br /&gt;
&lt;br /&gt;
If organizations inspect media that contain diagnostic and test programs and determine that the media also contain malicious code, the incident is handled consistent with incident handling policies and procedures. A periodic review of system maintenance tools can result in the withdrawal of approval for outdated, unsupported, irrelevant, or no-longer-used tools. Maintenance tools do not address the hardware and software components that support maintenance and are considered a part of the system.&lt;br /&gt;
&lt;br /&gt;
===== REFERENCES =====&lt;br /&gt;
&lt;br /&gt;
Source Controls: [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=MA-03 MA-03], [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=MA-03 MA-03(01)], [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=MA-03 MA-03(02)], [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=MA-03 MA-03(03)]&lt;br /&gt;
&lt;br /&gt;
Supporting Publications: SP 800-88 [[#bibr-ref_50|50]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;d30e3303-Head3&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&amp;lt;span id=&amp;quot;sec-sec_03.07.05&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&lt;br /&gt;
==== 03.07.05 Nonlocal Maintenance ====&lt;br /&gt;
&lt;br /&gt;
# Approve and monitor nonlocal maintenance and diagnostic activities.&lt;br /&gt;
# Implement multi-factor authentication and replay resistance in the establishment of nonlocal maintenance and diagnostic sessions.&lt;br /&gt;
# Terminate session and network connections when nonlocal maintenance is completed.&lt;br /&gt;
&lt;br /&gt;
===== DISCUSSION =====&lt;br /&gt;
&lt;br /&gt;
Nonlocal maintenance and diagnostic activities are conducted by individuals who communicate through an external or internal network. Local maintenance and diagnostic activities are carried out by individuals who are physically present at the location of the system and not communicating across a network connection. Authentication techniques used to establish nonlocal maintenance and diagnostic sessions reflect the requirements in [[#sec-sec_03.05.01|03.05.01]].&lt;br /&gt;
&lt;br /&gt;
===== REFERENCES =====&lt;br /&gt;
&lt;br /&gt;
Source Control: [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=MA-04 MA-04]&lt;br /&gt;
&lt;br /&gt;
Supporting Publications: SP 800-63-3 [[#bibr-ref_27|27]], SP 800-88 [[#bibr-ref_50|50]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;d30e3347-Head3&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&amp;lt;span id=&amp;quot;sec-sec_03.07.06&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&lt;br /&gt;
==== 03.07.06 Maintenance Personnel ====&lt;br /&gt;
&lt;br /&gt;
# Establish a process for maintenance personnel authorization.&lt;br /&gt;
# Maintain a list of authorized maintenance organizations or personnel.&lt;br /&gt;
# Verify that non-escorted personnel who perform maintenance on the system possess the required access authorizations.&lt;br /&gt;
# Designate organizational personnel with required access authorizations and technical competence to supervise the maintenance activities of personnel who do not possess the required access authorizations.&lt;br /&gt;
&lt;br /&gt;
===== DISCUSSION =====&lt;br /&gt;
&lt;br /&gt;
Maintenance personnel refers to individuals who perform hardware or software maintenance on the system, while [[#sec-sec_03.10.01|03.10.01]] addresses physical access for individuals whose maintenance duties place them within the physical protection perimeter of the system. The technical competence of supervising individuals relates to the maintenance performed on the system, while having required access authorizations refers to maintenance on and near the system. Individuals who have not been previously identified as authorized maintenance personnel (e.g., manufacturers, consultants, systems integrators, and vendors) may require privileged access to the system, such as when they are required to conduct maintenance with little or no notice. Organizations may choose to issue temporary credentials to these individuals based on their risk assessments. Temporary credentials may be for one-time use or for very limited time periods.&lt;br /&gt;
&lt;br /&gt;
===== REFERENCES =====&lt;br /&gt;
&lt;br /&gt;
Source Control: [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=MA-05 MA-05]&lt;br /&gt;
&lt;br /&gt;
Supporting Publications: None&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;d30e3388-Head2&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&amp;lt;span id=&amp;quot;sec-sec_3.8&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&lt;br /&gt;
=== 3.8 Media Protection ===&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;d30e3393-Head3&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&amp;lt;span id=&amp;quot;sec-sec_03.08.01&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&lt;br /&gt;
==== 03.08.01 Media Storage ====&lt;br /&gt;
&lt;br /&gt;
Physically control and securely store system media that contain CUI.&lt;br /&gt;
&lt;br /&gt;
===== DISCUSSION =====&lt;br /&gt;
&lt;br /&gt;
System media include digital and non-digital media. Digital media include diskettes, flash drives, magnetic tapes, external or removable solid state or magnetic drives, compact discs, and digital versatile discs. Non-digital media include paper and microfilm. Physically controlling stored media includes conducting inventories, establishing procedures to allow individuals to check out and return media to libraries, and maintaining accountability for stored media. Secure storage includes a locked drawer, desk, or cabinet or a controlled media library. Controlled areas provide physical and procedural controls to meet the requirements established for protecting information and systems. Sanitization techniques (e.g., destroying, cryptographically erasing, clearing, and purging) prevent the disclosure of CUI to unauthorized individuals. The sanitization process removes CUI from media such that the information cannot be retrieved or reconstructed.&lt;br /&gt;
&lt;br /&gt;
===== REFERENCES =====&lt;br /&gt;
&lt;br /&gt;
Source Control: [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=MP-04 MP-04]&lt;br /&gt;
&lt;br /&gt;
Supporting Publications: SP 800-88 [[#bibr-ref_50|50]], SP 800-111 [[#bibr-ref_51|51]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;d30e3421-Head3&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&amp;lt;span id=&amp;quot;sec-sec_03.08.02&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&lt;br /&gt;
==== 03.08.02 Media Access ====&lt;br /&gt;
&lt;br /&gt;
Restrict access to CUI on system media to authorized personnel or roles.&lt;br /&gt;
&lt;br /&gt;
===== DISCUSSION =====&lt;br /&gt;
&lt;br /&gt;
System media include digital and non-digital media. Access to CUI on system media can be restricted by physically controlling such media. This includes conducting inventories, ensuring that procedures are in place to allow individuals to check out and return media to the media library, and maintaining accountability for stored media. For digital media, access to CUI can be restricted by using cryptographic means. Encrypting data in storage or at rest is addressed in [[#sec-sec_03.13.08|03.13.08]].&lt;br /&gt;
&lt;br /&gt;
===== REFERENCES =====&lt;br /&gt;
&lt;br /&gt;
Source Control: [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=MP-02 MP-02]&lt;br /&gt;
&lt;br /&gt;
Supporting Publications: SP 800-111 [[#bibr-ref_51|51]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;d30e3451-Head3&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&amp;lt;span id=&amp;quot;sec-sec_03.08.03&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&lt;br /&gt;
==== 03.08.03 Media Sanitization ====&lt;br /&gt;
&lt;br /&gt;
Sanitize system media that contain CUI prior to disposal, release out of organizational control, or release for reuse.&lt;br /&gt;
&lt;br /&gt;
===== DISCUSSION =====&lt;br /&gt;
&lt;br /&gt;
Media sanitization applies to digital and non-digital media that are subject to disposal or reuse, whether or not the media are considered removable. Examples include digital media in scanners, copiers, printers, notebook computers, mobile devices, workstations, network components, and non-digital media. The sanitization process removes CUI from media such that the information cannot be retrieved or reconstructed. Sanitization techniques (e.g., cryptographically erasing, clearing, purging, and destroying) prevent the disclosure of CUI to unauthorized individuals when such media are reused or released for disposal. NARA policies control the sanitization process for media that contain CUI and may require destruction when other methods cannot be applied to the media.&lt;br /&gt;
&lt;br /&gt;
===== REFERENCES =====&lt;br /&gt;
&lt;br /&gt;
Source Control: [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=MP-06 MP-06]&lt;br /&gt;
&lt;br /&gt;
Supporting Publications: SP 800-88 [[#bibr-ref_50|50]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;d30e3477-Head3&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&amp;lt;span id=&amp;quot;sec-sec_03.08.04&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&lt;br /&gt;
==== 03.08.04 Media Marking ====&lt;br /&gt;
&lt;br /&gt;
Mark system media that contain CUI to indicate distribution limitations, handling caveats, and applicable CUI markings.&lt;br /&gt;
&lt;br /&gt;
===== DISCUSSION =====&lt;br /&gt;
&lt;br /&gt;
System media include digital and non-digital media. Marking refers to the use or application of human-readable security attributes. Labeling refers to the use of security attributes for internal system data structures. Digital media include diskettes, magnetic tapes, external or removable solid state or magnetic drives, flash drives, compact discs, and digital versatile discs. Non-digital media include paper and microfilm. CUI is defined by NARA along with marking, safeguarding, and dissemination requirements for such information.&lt;br /&gt;
&lt;br /&gt;
===== REFERENCES =====&lt;br /&gt;
&lt;br /&gt;
Source Control: [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=MP-03 MP-03]&lt;br /&gt;
&lt;br /&gt;
Supporting Publications: None&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;d30e3497-Head3&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&amp;lt;span id=&amp;quot;sec-sec_03.08.05&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&lt;br /&gt;
==== 03.08.05 Media Transport ====&lt;br /&gt;
&lt;br /&gt;
# Protect and control system media that contain CUI during transport outside of controlled areas.&lt;br /&gt;
# Maintain accountability of system media that contain CUI during transport outside of controlled areas.&lt;br /&gt;
# Document activities associated with the transport of system media that contain CUI.&lt;br /&gt;
&lt;br /&gt;
===== DISCUSSION =====&lt;br /&gt;
&lt;br /&gt;
System media include digital and non-digital media. Digital media include flash drives, diskettes, magnetic tapes, external or removable solid state or magnetic drives, compact discs, and digital versatile discs. Non-digital media include microfilm and paper. Controlled areas are spaces for which organizations provide physical or procedural measures to meet the requirements established for protecting CUI and systems. Media protection during transport can include cryptography and/or locked containers. Activities associated with media transport include releasing media for transport, ensuring that media enter the appropriate transport processes, and the actual transport. Authorized transport and courier personnel may include individuals external to the organization. Maintaining accountability of media during transport includes restricting transport activities to authorized personnel and tracking or obtaining the records of transport activities as the media move through the transportation system to prevent and detect loss, destruction, or tampering. This requirement is related to [[#sec-sec_03.13.08|03.13.08]] and [[#sec-sec_03.13.11|03.13.11]].&lt;br /&gt;
&lt;br /&gt;
===== REFERENCES =====&lt;br /&gt;
&lt;br /&gt;
Source Controls: [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=MP-05 MP-05], [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=SC-28 SC-28]&lt;br /&gt;
&lt;br /&gt;
Supporting Publications: SP 800-111 [[#bibr-ref_51|51]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;d30e3545-Head3&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&amp;lt;span id=&amp;quot;sec-sec_03.08.06&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&lt;br /&gt;
==== 03.08.06 Withdrawn ====&lt;br /&gt;
&lt;br /&gt;
Addressed by [[#sec-sec_03.13.08|03.13.08]].&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;d30e3555-Head3&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&amp;lt;span id=&amp;quot;sec-sec_03.08.07&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&lt;br /&gt;
==== 03.08.07 Media Use ====&lt;br /&gt;
&lt;br /&gt;
# Restrict or prohibit the use of [&#039;&#039;Assignment: organization-defined types of system media&#039;&#039;].&lt;br /&gt;
# Prohibit the use of removable system media without an identifiable owner.&lt;br /&gt;
&lt;br /&gt;
===== DISCUSSION =====&lt;br /&gt;
&lt;br /&gt;
In contrast to requirement [[#sec-sec_03.08.01|03.08.01]], which restricts user access to media, this requirement restricts or prohibits the use of certain types of media, such as external hard drives, flash drives, or smart displays. Organizations can use technical and non-technical measures (e.g., policies, procedures, and rules of behavior) to control the use of system media. For example, organizations may control the use of portable storage devices by using physical cages on workstations to prohibit access to external ports or disabling or removing the ability to insert, read, or write to devices.&lt;br /&gt;
&lt;br /&gt;
Organizations may limit the use of portable storage devices to only approved devices, including devices provided by the organization, devices provided by other approved organizations, and devices that are not personally owned. Organizations may also control the use of portable storage devices based on the type of device — prohibiting the use of writeable, portable devices — and implement this restriction by disabling or removing the capability to write to such devices. Limits on the use of organization-controlled system media in external systems include restrictions on how the media may be used and under what conditions. Requiring identifiable owners (e.g., individuals, organizations, or projects) for removable system media reduces the risk of using such technologies by allowing organizations to assign responsibility and accountability for addressing known vulnerabilities in the media (e.g., insertion of malicious code).&lt;br /&gt;
&lt;br /&gt;
===== REFERENCES =====&lt;br /&gt;
&lt;br /&gt;
Source Control: [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=MP-07 MP-07]&lt;br /&gt;
&lt;br /&gt;
Supporting Publications: SP 800-111 [[#bibr-ref_51|51]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;d30e3595-Head3&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&amp;lt;span id=&amp;quot;sec-sec_03.08.08&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&lt;br /&gt;
==== 03.08.08 Withdrawn ====&lt;br /&gt;
&lt;br /&gt;
Incorporated into [[#sec-sec_03.08.07|03.08.07]].&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;d30e3605-Head3&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&amp;lt;span id=&amp;quot;sec-sec_03.08.09&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&lt;br /&gt;
==== 03.08.09 System Backup – Cryptographic Protection ====&lt;br /&gt;
&lt;br /&gt;
# Protect the confidentiality of backup information.&lt;br /&gt;
# Implement cryptographic mechanisms to prevent the unauthorized disclosure of CUI at backup storage locations.&lt;br /&gt;
&lt;br /&gt;
===== DISCUSSION =====&lt;br /&gt;
&lt;br /&gt;
The selection of cryptographic mechanisms is based on the need to protect the confidentiality of backup information. Hardware security module (HSM) devices safeguard and manage cryptographic keys and provide cryptographic processing. Cryptographic operations (e.g., encryption, decryption, and signature generation and verification) are typically hosted on the HSM device, and many implementations provide hardware-accelerated mechanisms for cryptographic operations. This requirement is related to [[#sec-sec_03.13.11|03.13.11]].&lt;br /&gt;
&lt;br /&gt;
===== REFERENCES =====&lt;br /&gt;
&lt;br /&gt;
Source Controls: [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=CP-09 CP-09], [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=CP-09 CP-09(08)]&lt;br /&gt;
&lt;br /&gt;
Supporting Publications: SP 800-34 [[#bibr-ref_52|52]], SP 800-130 [[#bibr-ref_53|53]], SP 800-152 [[#bibr-ref_54|54]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;d30e3647-Head2&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&amp;lt;span id=&amp;quot;sec-sec_3.9&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&lt;br /&gt;
=== 3.9 Personnel Security ===&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;d30e3652-Head3&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&amp;lt;span id=&amp;quot;sec-sec_03.09.01&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&lt;br /&gt;
==== 03.09.01 Personnel Screening ====&lt;br /&gt;
&lt;br /&gt;
# Screen individuals prior to authorizing access to the system.&lt;br /&gt;
# Rescreen individuals in accordance with [&#039;&#039;Assignment: organization-defined conditions requiring rescreening&#039;&#039;].&lt;br /&gt;
&lt;br /&gt;
===== DISCUSSION =====&lt;br /&gt;
&lt;br /&gt;
Personnel security screening activities involve the assessment of the conduct, integrity, judgment, loyalty, reliability, and stability of an individual (i.e., the individual’s trustworthiness) prior to authorizing access to the system or when elevating system access. The screening and rescreening activities reflect applicable federal laws, Executive Orders, directives, policies, regulations, and criteria established for the level of access required for the assigned position.&lt;br /&gt;
&lt;br /&gt;
===== REFERENCES =====&lt;br /&gt;
&lt;br /&gt;
Source Control: [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=PS-03 PS-03]&lt;br /&gt;
&lt;br /&gt;
Supporting Publications: SP 800-181 [[#bibr-ref_34|34]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;d30e3689-Head3&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&amp;lt;span id=&amp;quot;sec-sec_03.09.02&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&lt;br /&gt;
==== 03.09.02 Personnel Termination and Transfer ====&lt;br /&gt;
&lt;br /&gt;
# When individual employment is terminated:&lt;br /&gt;
## Disable system access within [&#039;&#039;Assignment: organization-defined time period&#039;&#039;],&lt;br /&gt;
## Terminate or revoke authenticators and credentials associated with the individual, and&lt;br /&gt;
## Retrieve security-related system property.&lt;br /&gt;
# When individuals are reassigned or transferred to other positions in the organization:&lt;br /&gt;
## Review and confirm the ongoing operational need for current logical and physical access authorizations to the system and facility, and&lt;br /&gt;
## Modify access authorization to correspond with any changes in operational need.&lt;br /&gt;
&lt;br /&gt;
===== DISCUSSION =====&lt;br /&gt;
&lt;br /&gt;
Security-related system property includes hardware authentication tokens, system administration technical manuals, keys, identification cards, and building passes. Exit interviews ensure that terminated individuals understand the security constraints imposed by being former employees and that accountability is achieved for the organizational property. Security topics at exit interviews include reminding individuals of potential limitations on future employment and non-disclosure agreements. Exit interviews may not always be possible for some individuals, including in cases related to the unavailability of supervisors, illnesses, or job abandonment.&lt;br /&gt;
&lt;br /&gt;
The timely execution of termination actions is essential for individuals who have been terminated for cause. Organizations may consider disabling the accounts of individuals who are being terminated prior to the individuals being notified. This requirement applies to the reassignment or transfer of individuals when the personnel action is permanent or of such extended duration as to require protection. Protections that may be required for transfers or reassignments to other positions within organizations include returning old and issuing new identification cards, keys, and building passes; changing system access authorizations (i.e., privileges); closing system accounts and establishing new accounts; and providing access to official records to which individuals had access at previous work locations in previous system accounts.&lt;br /&gt;
&lt;br /&gt;
===== REFERENCES =====&lt;br /&gt;
&lt;br /&gt;
Source Controls: [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=PS-04 PS-04], [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=PS-05 PS-05]&lt;br /&gt;
&lt;br /&gt;
Supporting Publications: None&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;d30e3752-Head2&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&amp;lt;span id=&amp;quot;sec-sec_3.10&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&lt;br /&gt;
=== 3.10 Physical Protection ===&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;d30e3757-Head3&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&amp;lt;span id=&amp;quot;sec-sec_03.10.01&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&lt;br /&gt;
==== 03.10.01 Physical Access Authorizations ====&lt;br /&gt;
&lt;br /&gt;
# Develop, approve, and maintain a list of individuals with authorized access to the facility where the system resides.&lt;br /&gt;
# Issue authorization credentials for facility access.&lt;br /&gt;
# Review the facility access list [&#039;&#039;Assignment: organization-defined frequency&#039;&#039;].&lt;br /&gt;
# Remove individuals from the facility access list when access is no longer required.&lt;br /&gt;
&lt;br /&gt;
===== DISCUSSION =====&lt;br /&gt;
&lt;br /&gt;
A facility can include one or more physical locations containing systems or system components that process, store, or transmit CUI. Physical access authorizations apply to employees and visitors. Individuals with permanent physical access authorization credentials are not considered visitors. Authorization credentials include identification badges, identification cards, and smart cards. Organizations determine the strength of the authorization credentials consistent with applicable laws, Executive Orders, directives, regulations, policies, standards, and guidelines. Physical access authorizations may not be necessary to access certain areas within facilities that are designated as publicly accessible.&lt;br /&gt;
&lt;br /&gt;
===== REFERENCES =====&lt;br /&gt;
&lt;br /&gt;
Source Control: [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=PE-02 PE-02]&lt;br /&gt;
&lt;br /&gt;
Supporting Publications: None&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;d30e3798-Head3&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&amp;lt;span id=&amp;quot;sec-sec_03.10.02&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&lt;br /&gt;
==== 03.10.02 Monitoring Physical Access ====&lt;br /&gt;
&lt;br /&gt;
# Monitor physical access to the facility where the system resides to detect and respond to physical security incidents.&lt;br /&gt;
# Review physical access logs [&#039;&#039;Assignment: organization-defined frequency&#039;&#039;] and upon occurrence of [&#039;&#039;Assignment: organization-defined events or potential indications of events&#039;&#039;].&lt;br /&gt;
&lt;br /&gt;
===== DISCUSSION =====&lt;br /&gt;
&lt;br /&gt;
A facility can include one or more physical locations containing systems or system components that process, store, or transmit CUI. Physical access monitoring includes publicly accessible areas within organizational facilities. Examples of physical access monitoring include guards, video surveillance equipment (i.e., cameras), and sensor devices. Reviewing physical access logs can help to identify suspicious activities, anomalous events, or potential threats. The reviews can be supported by audit logging controls if the access logs are part of an automated system. Incident response capabilities include investigations of physical security incidents and responses to those incidents. Incidents include security violations or suspicious physical access activities, such as access outside of normal work hours, repeated access to areas not normally accessed, access for unusual lengths of time, and out-of-sequence access.&lt;br /&gt;
&lt;br /&gt;
===== REFERENCES =====&lt;br /&gt;
&lt;br /&gt;
Source Control: [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=PE-06 PE-06]&lt;br /&gt;
&lt;br /&gt;
Supporting Publications: None&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;d30e3836-Head3&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&amp;lt;span id=&amp;quot;sec-sec_03.10.03&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&lt;br /&gt;
==== 03.10.03 Withdrawn ====&lt;br /&gt;
&lt;br /&gt;
Incorporated into [[#sec-sec_03.10.07|03.10.07]].&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;d30e3846-Head3&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&amp;lt;span id=&amp;quot;sec-sec_03.10.04&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&lt;br /&gt;
==== 03.10.04 Withdrawn ====&lt;br /&gt;
&lt;br /&gt;
Incorporated into [[#sec-sec_03.10.07|03.10.07]].&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;d30e3856-Head3&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&amp;lt;span id=&amp;quot;sec-sec_03.10.05&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&lt;br /&gt;
==== 03.10.05 Withdrawn ====&lt;br /&gt;
&lt;br /&gt;
Incorporated into [[#sec-sec_03.10.07|03.10.07]].&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;d30e3866-Head3&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&amp;lt;span id=&amp;quot;sec-sec_03.10.06&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&lt;br /&gt;
==== 03.10.06 Alternate Work Site ====&lt;br /&gt;
&lt;br /&gt;
# Determine alternate work sites allowed for use by employees.&lt;br /&gt;
# Employ the following security requirements at alternate work sites: [&#039;&#039;Assignment: organization-defined security requirements&#039;&#039;].&lt;br /&gt;
&lt;br /&gt;
===== DISCUSSION =====&lt;br /&gt;
&lt;br /&gt;
Alternate work sites include the private residences of employees or other facilities designated by the organization. Alternate work sites can provide readily available alternate locations during contingency operations. Organizations can define different security requirements for specific alternate work sites or types of sites, depending on the work-related activities conducted at the sites. Assessing the effectiveness of the requirements and providing a means to communicate incidents at alternate work sites supports the contingency planning activities of organizations.&lt;br /&gt;
&lt;br /&gt;
===== REFERENCES =====&lt;br /&gt;
&lt;br /&gt;
Source Control: [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=PE-17 PE-17]&lt;br /&gt;
&lt;br /&gt;
Supporting Publications: SP 800-46 [[#bibr-ref_14|14]], SP 800-114 [[#bibr-ref_20|20]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;d30e3907-Head3&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&amp;lt;span id=&amp;quot;sec-sec_03.10.07&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&lt;br /&gt;
==== 03.10.07 Physical Access Control ====&lt;br /&gt;
&lt;br /&gt;
# Enforce physical access authorizations at entry and exit points to the facility where the system resides by:&lt;br /&gt;
## Verifying individual physical access authorizations before granting access to the facility and&lt;br /&gt;
## Controlling ingress and egress with physical access control systems, devices, or guards.&lt;br /&gt;
# Maintain physical access audit logs for entry or exit points.&lt;br /&gt;
# Escort visitors, and control visitor activity.&lt;br /&gt;
# Secure keys, combinations, and other physical access devices.&lt;br /&gt;
# Control physical access to output devices to prevent unauthorized individuals from obtaining access to CUI.&lt;br /&gt;
&lt;br /&gt;
===== DISCUSSION =====&lt;br /&gt;
&lt;br /&gt;
This requirement addresses physical locations containing systems or system components that process, store, or transmit CUI. Organizations determine the types of guards needed, including professional security staff or administrative staff. Physical access devices include keys, locks, combinations, biometric readers, and card readers. Physical access control systems comply with applicable laws, Executive Orders, directives, policies, regulations, standards, and guidelines. Organizations have flexibility in the types of audit logs employed. Audit logs can be procedural, automated, or some combination thereof. Physical access points can include exterior access points, interior access points to systems that require supplemental access controls, or both. Physical access control applies to employees and visitors. Individuals with permanent physical access authorizations are not considered visitors.&lt;br /&gt;
&lt;br /&gt;
Controlling physical access to output devices includes placing output devices in locked rooms or other secured areas with keypad or card reader access controls and only allowing access to authorized individuals, placing output devices in locations that can be monitored by personnel, installing monitor or screen filters, and using headphones. Examples of output devices include monitors, printers, scanners, facsimile machines, audio devices, and copiers.&lt;br /&gt;
&lt;br /&gt;
===== REFERENCES =====&lt;br /&gt;
&lt;br /&gt;
Source Controls: [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=PE-03 PE-03], [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=PE-05 PE-05]&lt;br /&gt;
&lt;br /&gt;
Supporting Publications: None&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;d30e3964-Head3&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&amp;lt;span id=&amp;quot;sec-sec_03.10.08&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&lt;br /&gt;
==== 03.10.08 Access Control for Transmission ====&lt;br /&gt;
&lt;br /&gt;
Control physical access to system distribution and transmission lines within organizational facilities.&lt;br /&gt;
&lt;br /&gt;
===== DISCUSSION =====&lt;br /&gt;
&lt;br /&gt;
Safeguarding measures applied to system distribution and transmission lines prevent accidental damage, disruption, and physical tampering. Such measures may also be necessary to prevent eavesdropping or the modification of unencrypted transmissions. Safeguarding measures used to control physical access to system distribution and transmission lines include disconnected or locked spare jacks, locked wiring closets, cabling protection with conduit or cable trays, and wiretapping sensors.&lt;br /&gt;
&lt;br /&gt;
===== REFERENCES =====&lt;br /&gt;
&lt;br /&gt;
Source Control: [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=PE-04 PE-04]&lt;br /&gt;
&lt;br /&gt;
Supporting Publications: None&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;d30e3987-Head2&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&amp;lt;span id=&amp;quot;sec-sec_3.11&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&lt;br /&gt;
=== 3.11 Risk Assessment ===&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;d30e3992-Head3&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&amp;lt;span id=&amp;quot;sec-sec_03.11.01&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&lt;br /&gt;
==== 03.11.01 Risk Assessment ====&lt;br /&gt;
&lt;br /&gt;
# Assess the risk (including supply chain risk) of unauthorized disclosure resulting from the processing, storage, or transmission of CUI.&lt;br /&gt;
# Update risk assessments [&#039;&#039;Assignment: organization-defined frequency&#039;&#039;].&lt;br /&gt;
&lt;br /&gt;
===== DISCUSSION =====&lt;br /&gt;
&lt;br /&gt;
Establishing the system boundary is a prerequisite to assessing the risk of the unauthorized disclosure of CUI. Risk assessments consider threats, vulnerabilities, likelihood, and adverse impacts to organizational operations and assets based on the operation and use of the system and the unauthorized disclosure of CUI. Risk assessments also consider risks from external parties (e.g., contractors operating systems on behalf of the organization, service providers, individuals accessing systems, and outsourcing entities). Risk assessments can be conducted at the organization level, the mission or business process level, or the system level and at any phase in the system development life cycle. Risk assessments include supply chain-related risks associated with suppliers or contractors and the system, system component, or system service that they provide.&lt;br /&gt;
&lt;br /&gt;
===== REFERENCES =====&lt;br /&gt;
&lt;br /&gt;
Source Controls: [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=RA-03 RA-03], [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=RA-03 RA-03(01)], [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=SR-06 SR-06]&lt;br /&gt;
&lt;br /&gt;
Supporting Publications: SP 800-30 [[#bibr-ref_55|55]], SP 800-161 [[#bibr-ref_33|33]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;d30e4041-Head3&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&amp;lt;span id=&amp;quot;sec-sec_03.11.02&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&lt;br /&gt;
==== 03.11.02 Vulnerability Monitoring and Scanning ====&lt;br /&gt;
&lt;br /&gt;
# Monitor and scan the system for vulnerabilities [&#039;&#039;Assignment: organization-defined frequency&#039;&#039;] and when new vulnerabilities affecting the system are identified.&lt;br /&gt;
# Remediate system vulnerabilities within [&#039;&#039;Assignment: organization-defined response times&#039;&#039;].&lt;br /&gt;
# Update system vulnerabilities to be scanned [&#039;&#039;Assignment: organization-defined frequency&#039;&#039;] and when new vulnerabilities are identified and reported.&lt;br /&gt;
&lt;br /&gt;
===== DISCUSSION =====&lt;br /&gt;
&lt;br /&gt;
Organizations determine the required vulnerability scanning for system components and ensure that potential sources of vulnerabilities (e.g., networked printers, scanners, and copiers) are not overlooked. Vulnerability analyses for custom software may require additional approaches, such as static analysis, dynamic analysis, or binary analysis. Organizations can use these approaches in source code reviews and tools (e.g., static analysis tools, web-based application scanners, binary analyzers). Vulnerability scanning includes scanning for patch levels; scanning for functions, ports, protocols, and services that should not be accessible to users or devices; and scanning for improperly configured or incorrectly operating flow control mechanisms.&lt;br /&gt;
&lt;br /&gt;
To facilitate interoperability, organizations consider using scanning tools that express vulnerabilities in the Common Vulnerabilities and Exposures (CVE) naming convention. Sources for vulnerability information also include the Common Weakness Enumeration (CWE) listing, the National Vulnerability Database (NVD), and the Common Vulnerability Scoring System (CVSS).&lt;br /&gt;
&lt;br /&gt;
===== REFERENCES =====&lt;br /&gt;
&lt;br /&gt;
Source Controls: [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=RA-05 RA-05], [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=RA-05 RA-05(02)]&lt;br /&gt;
&lt;br /&gt;
Supporting Publications: SP 800-40 [[#bibr-ref_56|56]], SP 800-53A [[#bibr-ref_57|57]], SP 800-70 [[#bibr-ref_44|44]], SP 800-115 [[#bibr-ref_58|58]], SP 800-126 [[#bibr-ref_45|45]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;d30e4106-Head3&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&amp;lt;span id=&amp;quot;sec-sec_03.11.03&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&lt;br /&gt;
==== 03.11.03 Withdrawn ====&lt;br /&gt;
&lt;br /&gt;
Incorporated into [[#sec-sec_03.11.02|03.11.02]].&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;d30e4116-Head3&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&amp;lt;span id=&amp;quot;sec-sec_03.11.04&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&lt;br /&gt;
==== 03.11.04 Risk Response ====&lt;br /&gt;
&lt;br /&gt;
Respond to findings from security assessments, monitoring, and audits.&lt;br /&gt;
&lt;br /&gt;
===== DISCUSSION =====&lt;br /&gt;
&lt;br /&gt;
This requirement addresses the need to determine an appropriate response to risk before generating a plan of action and milestones (POAM) entry. It may be possible to mitigate the risk immediately so that a POAM entry is not needed. However, a POAM entry is generated if the risk response is to mitigate the identified risk and the mitigation cannot be completed immediately.&lt;br /&gt;
&lt;br /&gt;
===== REFERENCES =====&lt;br /&gt;
&lt;br /&gt;
Source Control: [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=RA-07 RA-07]&lt;br /&gt;
&lt;br /&gt;
Supporting Publications: SP 800-30 [[#bibr-ref_55|55]], SP 800-37 [[#bibr-ref_59|59]], SP 800-39 [[#bibr-ref_60|60]], SP 800-160-1 [[#bibr-ref_11|11]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;d30e4150-Head2&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&amp;lt;span id=&amp;quot;sec-sec_3.12&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&lt;br /&gt;
=== 3.12 Security Assessment and Monitoring ===&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;d30e4155-Head3&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&amp;lt;span id=&amp;quot;sec-sec_03.12.01&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&lt;br /&gt;
==== 03.12.01 Security Assessment ====&lt;br /&gt;
&lt;br /&gt;
Assess the security requirements for the system and its environment of operation [&#039;&#039;Assignment: organization-defined frequency&#039;&#039;] to determine if the requirements have been satisfied.&lt;br /&gt;
&lt;br /&gt;
===== DISCUSSION =====&lt;br /&gt;
&lt;br /&gt;
By assessing the security requirements, organizations determine whether the necessary safeguards and countermeasures are implemented correctly, operating as intended, and producing the desired outcome. Security assessments identify weaknesses in the system and provide the essential information needed to make risk-based decisions. Security assessment reports document assessment results in sufficient detail as deemed necessary by the organization to determine the accuracy and completeness of the reports. Security assessment results are provided to the individuals or roles appropriate for the types of assessments being conducted.&lt;br /&gt;
&lt;br /&gt;
===== REFERENCES =====&lt;br /&gt;
&lt;br /&gt;
Source Control: [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=CA-02 CA-02]&lt;br /&gt;
&lt;br /&gt;
Supporting Publications: SP 800-53 [[#bibr-ref_8|8]], SP 800-53A [[#bibr-ref_57|57]], SP 800-37 [[#bibr-ref_59|59]], SP 800-115 [[#bibr-ref_58|58]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;d30e4193-Head3&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&amp;lt;span id=&amp;quot;sec-sec_03.12.02&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&lt;br /&gt;
==== 03.12.02 Plan of Action and Milestones ====&lt;br /&gt;
&lt;br /&gt;
# Develop a plan of action and milestones for the system:&lt;br /&gt;
## To document the planned remediation actions to correct weaknesses or deficiencies noted during security assessments and&lt;br /&gt;
## To reduce or eliminate known system vulnerabilities.&lt;br /&gt;
# Update the existing plan of action and milestones based on the findings from:&lt;br /&gt;
## Security assessments,&lt;br /&gt;
## Audits or reviews, and&lt;br /&gt;
## Continuous monitoring activities.&lt;br /&gt;
&lt;br /&gt;
===== DISCUSSION =====&lt;br /&gt;
&lt;br /&gt;
Plans of action and milestones (POAMs) are important documents in organizational security programs. Organizations use POAMs to describe how unsatisfied security requirements will be met and how planned mitigations will be implemented. Organizations can document system security plans and POAMs as separate or combined documents in any format. Federal agencies may consider system security plans and POAMs as inputs to risk-based decisions on whether to process, store, or transmit CUI on a system hosted by a nonfederal organization.&lt;br /&gt;
&lt;br /&gt;
===== REFERENCES =====&lt;br /&gt;
&lt;br /&gt;
Source Control: [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=CA-05 CA-05]&lt;br /&gt;
&lt;br /&gt;
Supporting Publications: SP 800-37 [[#bibr-ref_59|59]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;d30e4253-Head3&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&amp;lt;span id=&amp;quot;sec-sec_03.12.03&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&lt;br /&gt;
==== 03.12.03 Continuous Monitoring ====&lt;br /&gt;
&lt;br /&gt;
Develop and implement a system-level continuous monitoring strategy that includes ongoing monitoring and security assessments.&lt;br /&gt;
&lt;br /&gt;
===== DISCUSSION =====&lt;br /&gt;
&lt;br /&gt;
Continuous monitoring at the system level facilitates ongoing awareness of the system security posture to support risk management decisions. The terms &#039;&#039;continuous&#039;&#039; and &#039;&#039;ongoing&#039;&#039; imply that organizations assess and monitor their systems at a frequency that is sufficient to support risk-based decisions. Different types of security requirements may require different monitoring frequencies.&lt;br /&gt;
&lt;br /&gt;
===== REFERENCES =====&lt;br /&gt;
&lt;br /&gt;
Source Control: [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=CA-07 CA-07]&lt;br /&gt;
&lt;br /&gt;
Supporting Publications: SP 800-37 [[#bibr-ref_59|59]], SP 800-39 [[#bibr-ref_60|60]], SP 800-53A [[#bibr-ref_57|57]], SP 800-115 [[#bibr-ref_58|58]], SP 800-137 [[#bibr-ref_49|49]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;d30e4296-Head3&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&amp;lt;span id=&amp;quot;sec-sec_03.12.04&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&lt;br /&gt;
==== 03.12.04 Withdrawn ====&lt;br /&gt;
&lt;br /&gt;
Incorporated into [[#sec-sec_03.15.02|03.15.02]].&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;d30e4307-Head3&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&amp;lt;span id=&amp;quot;sec-sec_03.12.05&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&lt;br /&gt;
==== 03.12.05 Information Exchange ====&lt;br /&gt;
&lt;br /&gt;
# Approve and manage the exchange of CUI between the system and other systems using [&#039;&#039;Selection (one or more): interconnection security agreements; information exchange security agreements; memoranda of understanding or agreement; service-level agreements; user agreements; non-disclosure agreements; other types of agreements&#039;&#039;].&lt;br /&gt;
# Document interface characteristics, security requirements, and responsibilities for each system as part of the exchange agreements.&lt;br /&gt;
# Review and update the exchange agreements [&#039;&#039;Assignment: organization-defined frequency&#039;&#039;].&lt;br /&gt;
&lt;br /&gt;
===== DISCUSSION =====&lt;br /&gt;
&lt;br /&gt;
Information exchange applies to information exchanges between two or more systems, both internal and external to the organization. Organizations consider the risks related to new or increased threats that may be introduced when systems exchange information with other systems that may have different security requirements or policies. The types of agreements selected are based on factors such as the relationship between the organizations exchanging information (e.g., government to government, business to business, government to business, government or business, or government or business to individual) and the level of access to the organizational system by users of the other system. The types of agreements can include information exchange security agreements, interconnection security agreements, memoranda of understanding or agreement, service-level agreements, or other types of agreements.&lt;br /&gt;
&lt;br /&gt;
Organizations may incorporate agreement information into formal contracts, especially for information exchanges established between federal agencies and nonfederal organizations (e.g., service providers, contractors, system developers, and system integrators). The types of information contained in exchange agreements include the interface characteristics, security requirements, controls, and responsibilities for each system.&lt;br /&gt;
&lt;br /&gt;
===== REFERENCES =====&lt;br /&gt;
&lt;br /&gt;
Source Control: [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=CA-03 CA-03]&lt;br /&gt;
&lt;br /&gt;
Supporting Publications: SP 800-47 [[#bibr-ref_83|83]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;d30e4352-Head2&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&amp;lt;span id=&amp;quot;sec-sec_3.13&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&lt;br /&gt;
=== 3.13 System and Communications Protection ===&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;d30e4357-Head3&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&amp;lt;span id=&amp;quot;sec-sec_03.13.01&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&lt;br /&gt;
==== 03.13.01 Boundary Protection ====&lt;br /&gt;
&lt;br /&gt;
# Monitor and control communications at external managed interfaces to the system and key internal managed interfaces within the system.&lt;br /&gt;
# Implement subnetworks for publicly accessible system components that are physically or logically separated from internal networks.&lt;br /&gt;
# Connect to external systems only through managed interfaces that consist of boundary protection devices arranged in accordance with an organizational security architecture.&lt;br /&gt;
&lt;br /&gt;
===== DISCUSSION =====&lt;br /&gt;
&lt;br /&gt;
Managed interfaces include gateways, routers, firewalls, network-based malicious code analysis, virtualization systems, and encrypted tunnels implemented within a security architecture. Subnetworks that are either physically or logically separated from internal networks are referred to as demilitarized zones or DMZs. Restricting or prohibiting interfaces within organizational systems includes restricting external web traffic to designated web servers within managed interfaces, prohibiting external traffic that appears to be spoofing internal addresses, and prohibiting internal traffic that appears to be spoofing external addresses.&lt;br /&gt;
&lt;br /&gt;
===== REFERENCES =====&lt;br /&gt;
&lt;br /&gt;
Source Control: [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=SC-07 SC-07]&lt;br /&gt;
&lt;br /&gt;
Supporting Publications: SP 800-41 [[#bibr-ref_64|64]], SP 800-125B [[#bibr-ref_65|65]], SP 800-160-1 [[#bibr-ref_11|11]], SP 800-189 [[#bibr-ref_67|67]], SP 800-207 [[#bibr-ref_66|66]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;d30e4407-Head3&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&amp;lt;span id=&amp;quot;sec-sec_03.13.02&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&lt;br /&gt;
==== 03.13.02 Withdrawn ====&lt;br /&gt;
&lt;br /&gt;
Recategorized as NCO.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;d30e4414-Head3&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&amp;lt;span id=&amp;quot;sec-sec_03.13.03&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&lt;br /&gt;
==== 03.13.03 Withdrawn ====&lt;br /&gt;
&lt;br /&gt;
Addressed by [[#sec-sec_03.01.01|03.01.01]], [[#sec-sec_03.01.02|03.01.02]], [[#sec-sec_03.01.03|03.01.03]], [[#sec-sec_03.01.04|03.01.04]], [[#sec-sec_03.01.05|03.01.05]], [[#sec-sec_03.01.06|03.01.06]], and [[#sec-sec_03.01.07|03.01.07]].&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;d30e4443-Head3&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&amp;lt;span id=&amp;quot;sec-sec_03.13.04&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&lt;br /&gt;
==== 03.13.04 Information in Shared System Resources ====&lt;br /&gt;
&lt;br /&gt;
Prevent unauthorized and unintended information transfer via shared system resources.&lt;br /&gt;
&lt;br /&gt;
===== DISCUSSION =====&lt;br /&gt;
&lt;br /&gt;
Preventing unauthorized and unintended information transfer via shared system resources stops information produced by the actions of prior users or roles (or actions of processes acting on behalf of prior users or roles) from being available to current users or roles (or current processes acting on behalf of current users or roles) that obtain access to shared system resources after those resources have been released back to the system. Information in shared system resources also applies to encrypted representations of information. In other contexts, the control of information in shared system resources is referred to as object reuse and residual information protection. Information in shared system resources does not address information remanence, which refers to the residual representation of data that has been nominally deleted, covert channels (including storage and timing channels) in which shared system resources are manipulated to violate information flow restrictions, or components within systems for which there are only single users or roles.&lt;br /&gt;
&lt;br /&gt;
===== REFERENCES =====&lt;br /&gt;
&lt;br /&gt;
Source Control: [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=SC-04 SC-04]&lt;br /&gt;
&lt;br /&gt;
Supporting Publications: None&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;d30e4466-Head3&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&amp;lt;span id=&amp;quot;sec-sec_03.13.05&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&lt;br /&gt;
==== 03.13.05 Withdrawn ====&lt;br /&gt;
&lt;br /&gt;
Incorporated into [[#sec-sec_03.13.01|03.13.01]].&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;d30e4476-Head3&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&amp;lt;span id=&amp;quot;sec-sec_03.13.06&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&lt;br /&gt;
==== 03.13.06 Network Communications – Deny by Default – Allow by Exception ====&lt;br /&gt;
&lt;br /&gt;
Deny network communications traffic by default, and allow network communications traffic by exception.&lt;br /&gt;
&lt;br /&gt;
===== DISCUSSION =====&lt;br /&gt;
&lt;br /&gt;
This requirement applies to inbound and outbound network communications traffic at the system boundary and at identified points within the system. A deny-all, allow-by-exception network communications traffic policy ensures that only essential and approved connections are allowed.&lt;br /&gt;
&lt;br /&gt;
===== REFERENCES =====&lt;br /&gt;
&lt;br /&gt;
Source Control: [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=SC-07 SC-07(05)]&lt;br /&gt;
&lt;br /&gt;
Supporting Publications: SP 800-41 [[#bibr-ref_64|64]], SP 800-77 [[#bibr-ref_18|18]], SP 800-189 [[#bibr-ref_67|67]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;d30e4508-Head3&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&amp;lt;span id=&amp;quot;sec-sec_03.13.07&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&lt;br /&gt;
==== 03.13.07 Withdrawn ====&lt;br /&gt;
&lt;br /&gt;
Addressed by [[#sec-sec_03.01.12|03.01.12]], [[#sec-sec_03.04.02|03.04.02]] and [[#sec-sec_03.04.06|03.04.06]].&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;d30e4524-Head3&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&amp;lt;span id=&amp;quot;sec-sec_03.13.08&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&lt;br /&gt;
==== 03.13.08 Transmission and Storage Confidentiality ====&lt;br /&gt;
&lt;br /&gt;
Implement cryptographic mechanisms to prevent the unauthorized disclosure of CUI during transmission and while in storage.&lt;br /&gt;
&lt;br /&gt;
===== DISCUSSION =====&lt;br /&gt;
&lt;br /&gt;
This requirement applies to internal and external networks and any system components that can transmit CUI, including servers, notebook computers, desktop computers, mobile devices, printers, copiers, scanners, facsimile machines, and radios. Unprotected communication paths are susceptible to interception and modification. Encryption protects CUI from unauthorized disclosure during transmission and while in storage. Cryptographic mechanisms that protect the confidentiality of CUI during transmission include TLS and IPsec. Information in storage (i.e., information at rest) refers to the state of CUI when it is not in process or in transit and resides on internal or external storage devices, storage area network devices, and databases. Protecting CUI in storage does not focus on the type of storage device or the frequency of access to that device but rather on the state of the information. This requirement relates to [[#sec-sec_03.13.11|03.13.11]].&lt;br /&gt;
&lt;br /&gt;
===== REFERENCES =====&lt;br /&gt;
&lt;br /&gt;
Source Controls: [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=SC-08 SC-08], [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=SC-08 SC-08(01)], [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=SC-28 SC-28], [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=SC-28 SC-28(01)]&lt;br /&gt;
&lt;br /&gt;
Supporting Publications: FIPS 140-3 [[#bibr-ref_38|38]], FIPS 197 [[#bibr-ref_68|68]], SP 800-46 [[#bibr-ref_14|14]], SP 800-52 [[#bibr-ref_69|69]], SP 800-56A [[#bibr-ref_73|73]], SP 800-56B [[#bibr-ref_74|74]], SP 800-56C [[#bibr-ref_75|75]], SP 800-57-1 [[#bibr-ref_15|15]], SP 800-57-2 [[#bibr-ref_16|16]], SP 800-57-3 [[#bibr-ref_17|17]], SP 800-77 [[#bibr-ref_18|18]], SP 800-111 [[#bibr-ref_51|51]], SP 800-113 [[#bibr-ref_19|19]], SP 800-114 [[#bibr-ref_20|20]], SP 800-121 [[#bibr-ref_21|21]], SP 800-124 [[#bibr-ref_28|28]], SP 800-177 [[#bibr-ref_70|70]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;d30e4615-Head3&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&amp;lt;span id=&amp;quot;sec-sec_03.13.09&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&lt;br /&gt;
==== 03.13.09 Network Disconnect ====&lt;br /&gt;
&lt;br /&gt;
Terminate the network connection associated with a communications session at the end of the session or after [&#039;&#039;Assignment: organization-defined time period&#039;&#039;] of inactivity.&lt;br /&gt;
&lt;br /&gt;
===== DISCUSSION =====&lt;br /&gt;
&lt;br /&gt;
This requirement applies to internal and external networks. Terminating network connections associated with communications sessions includes deallocating TCP/IP addresses or port pairs at the operating system level or deallocating networking assignments at the application level if multiple application sessions are using a single network connection. Time periods of inactivity may be established by organizations and include time periods by type of network access or for specific network accesses.&lt;br /&gt;
&lt;br /&gt;
===== REFERENCES =====&lt;br /&gt;
&lt;br /&gt;
Source Control: [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=SC-10 SC-10]&lt;br /&gt;
&lt;br /&gt;
Supporting Publications: None&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;d30e4640-Head3&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&amp;lt;span id=&amp;quot;sec-sec_03.13.10&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&lt;br /&gt;
==== 03.13.10 Cryptographic Key Establishment and Management ====&lt;br /&gt;
&lt;br /&gt;
Establish and manage cryptographic keys in the system in accordance with the following key management requirements: [&#039;&#039;Assignment: organization-defined requirements for key generation, distribution, storage, access, and destruction&#039;&#039;].&lt;br /&gt;
&lt;br /&gt;
===== DISCUSSION =====&lt;br /&gt;
&lt;br /&gt;
Cryptographic keys can be established and managed using either manual procedures or automated mechanisms supported by manual procedures. Organizations satisfy key establishment and management requirements in accordance with applicable federal laws, Executive Orders, policies, directives, regulations, and standards that specify appropriate options, levels, and parameters. This requirement is related to [[#sec-sec_03.13.11|03.13.11]].&lt;br /&gt;
&lt;br /&gt;
===== REFERENCES =====&lt;br /&gt;
&lt;br /&gt;
Source Control: [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=SC-12 SC-12]&lt;br /&gt;
&lt;br /&gt;
Supporting Publications: FIPS 140-3 [[#bibr-ref_38|38]], SP 800-56A [[#bibr-ref_73|73]], SP 800-56B [[#bibr-ref_74|74]], SP 800-56C [[#bibr-ref_75|75]], SP 800-57-1 [[#bibr-ref_15|15]], SP 800-57-2 [[#bibr-ref_16|16]], SP 800-57-3 [[#bibr-ref_17|17]], SP 800-63-3 [[#bibr-ref_27|27]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;d30e4694-Head3&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&amp;lt;span id=&amp;quot;sec-sec_03.13.11&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&lt;br /&gt;
==== 03.13.11 Cryptographic Protection ====&lt;br /&gt;
&lt;br /&gt;
Implement the following types of cryptography to protect the confidentiality of CUI: [&#039;&#039;Assignment: organization-defined types of cryptography&#039;&#039;].&lt;br /&gt;
&lt;br /&gt;
===== DISCUSSION =====&lt;br /&gt;
&lt;br /&gt;
Cryptography is implemented in accordance with applicable laws, Executive Orders, directives, regulations, policies, standards, and guidelines. FIPS-validated cryptography is recommended for the protection of CUI.&lt;br /&gt;
&lt;br /&gt;
===== REFERENCES =====&lt;br /&gt;
&lt;br /&gt;
Source Control: [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=SC-13 SC-13]&lt;br /&gt;
&lt;br /&gt;
Supporting Publications: FIPS 140-3 [[#bibr-ref_38|38]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;d30e4723-Head3&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&amp;lt;span id=&amp;quot;sec-sec_03.13.12&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&lt;br /&gt;
==== 03.13.12 Collaborative Computing Devices and Applications ====&lt;br /&gt;
&lt;br /&gt;
# Prohibit the remote activation of collaborative computing devices and applications with the following exceptions: [&#039;&#039;Assignment: organization-defined exceptions where remote activation is to be allowed&#039;&#039;].&lt;br /&gt;
# Provide an explicit indication of use to users physically present at the devices.&lt;br /&gt;
&lt;br /&gt;
===== DISCUSSION =====&lt;br /&gt;
&lt;br /&gt;
Collaborative computing devices include white boards, microphones, and cameras. Notebook computers, smartphones, display monitors, and tablets containing cameras and microphones are considered part of collaborative computing devices when conferencing software is in use. Indication of use includes notifying users (e.g., a pop-up menu stating that recording is in progress or that the microphone has been turned on) when collaborative computing devices are activated. Dedicated video conferencing systems, which typically rely on one of the participants calling or connecting to the other party to activate the video conference, are excluded. Solutions to prevent device usage include webcam covers and buttons to disable microphones.&lt;br /&gt;
&lt;br /&gt;
===== REFERENCES =====&lt;br /&gt;
&lt;br /&gt;
Source Control: [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=SC-15 SC-15]&lt;br /&gt;
&lt;br /&gt;
Supporting Publications: None&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;d30e4757-Head3&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&amp;lt;span id=&amp;quot;sec-sec_03.13.13&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&lt;br /&gt;
==== 03.13.13 Mobile Code ====&lt;br /&gt;
&lt;br /&gt;
# Define acceptable mobile code and mobile code technologies.&lt;br /&gt;
# Authorize, monitor, and control the use of mobile code.&lt;br /&gt;
&lt;br /&gt;
===== DISCUSSION =====&lt;br /&gt;
&lt;br /&gt;
Mobile code includes software programs or parts of programs that are obtained from remote systems, transmitted across a network, and executed on a local system without explicit installation or execution by the recipient. Decisions regarding the use of mobile code are based on the potential for the code to cause damage to the system if used maliciously. Mobile code technologies include Java applets, JavaScript, HTML5, VBScript, and WebGL. Usage restrictions and implementation guidelines apply to the selection and use of mobile code installed on servers and downloaded and executed on individual workstations and devices, including notebook computers, smart phones, and smart devices. Mobile code policies and procedures address the actions taken to prevent the development, acquisition, and use of unacceptable mobile code within the system, including requiring mobile code to be digitally signed by a trusted source.&lt;br /&gt;
&lt;br /&gt;
===== REFERENCES =====&lt;br /&gt;
&lt;br /&gt;
Source Control: [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=SC-18 SC-18]&lt;br /&gt;
&lt;br /&gt;
Supporting Publications: SP 800-28 [[#bibr-ref_71|71]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;d30e4792-Head3&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&amp;lt;span id=&amp;quot;sec-sec_03.13.14&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&lt;br /&gt;
==== 03.13.14 Withdrawn ====&lt;br /&gt;
&lt;br /&gt;
Technology-specific.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;d30e4799-Head3&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&amp;lt;span id=&amp;quot;sec-sec_03.13.15&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&lt;br /&gt;
==== 03.13.15 Session Authenticity ====&lt;br /&gt;
&lt;br /&gt;
Protect the authenticity of communications sessions.&lt;br /&gt;
&lt;br /&gt;
===== DISCUSSION =====&lt;br /&gt;
&lt;br /&gt;
Protecting session authenticity addresses communications protection at the session level, not at the packet level. Such protection establishes grounds for confidence at both ends of the communications sessions in the ongoing identities of other parties and the validity of the transmitted information. Authenticity protection includes protecting against adversary-in-the-middle attacks, session hijacking, and the insertion of false information into sessions.&lt;br /&gt;
&lt;br /&gt;
===== REFERENCES =====&lt;br /&gt;
&lt;br /&gt;
Source Control: [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=SC-23 SC-23]&lt;br /&gt;
&lt;br /&gt;
Supporting Publications: SP 800-52 [[#bibr-ref_69|69]], SP 800-77 [[#bibr-ref_18|18]], SP 800-95 [[#bibr-ref_72|72]], SP 800-113 [[#bibr-ref_19|19]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;d30e4834-Head3&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&amp;lt;span id=&amp;quot;sec-sec_03.13.16&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&lt;br /&gt;
==== 03.13.16 Withdrawn ====&lt;br /&gt;
&lt;br /&gt;
Incorporated into [[#sec-sec_03.13.08|03.13.08]].&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;d30e4844-Head2&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&amp;lt;span id=&amp;quot;sec-sec_3.14&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&lt;br /&gt;
=== 3.14 System and Information Integrity ===&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;d30e4849-Head3&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&amp;lt;span id=&amp;quot;sec-sec_03.14.01&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&lt;br /&gt;
==== 03.14.01 Flaw Remediation ====&lt;br /&gt;
&lt;br /&gt;
# Identify, report, and correct system flaws.&lt;br /&gt;
# Install security-relevant software and firmware updates within [&#039;&#039;Assignment: organization-defined time period&#039;&#039;] of the release of the updates.&lt;br /&gt;
&lt;br /&gt;
===== DISCUSSION =====&lt;br /&gt;
&lt;br /&gt;
Organizations identify systems that are affected by announced software and firmware flaws, including potential vulnerabilities that result from those flaws, and report this information to designated personnel with information security responsibilities. Security-relevant updates include patches, service packs, hot fixes, and anti-virus signatures. Organizations address the flaws discovered during security assessments, continuous monitoring, incident response activities, and system error handling. Organizations can take advantage of available resources (e.g., CWE or CVE databases) when remediating system flaws. Organization-defined time periods for updating security-relevant software and firmware may vary based on a variety of factors, including the criticality of the update (i.e., severity of the vulnerability related to the discovered flaw). Some types of flaw remediation may require more testing than other types.&lt;br /&gt;
&lt;br /&gt;
===== REFERENCES =====&lt;br /&gt;
&lt;br /&gt;
Source Control: [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=SI-02 SI-02]&lt;br /&gt;
&lt;br /&gt;
Supporting Publications: SP 800-39 [[#bibr-ref_60|60]], SP 800-40 [[#bibr-ref_56|56]], SP 800-128 [[#bibr-ref_41|41]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;d30e4893-Head3&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&amp;lt;span id=&amp;quot;sec-sec_03.14.02&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&lt;br /&gt;
==== 03.14.02 Malicious Code Protection ====&lt;br /&gt;
&lt;br /&gt;
# Implement malicious code protection mechanisms at system entry and exit points to detect and eradicate malicious code.&lt;br /&gt;
# Update malicious code protection mechanisms as new releases are available in accordance with configuration management policies and procedures.&lt;br /&gt;
# Configure malicious code protection mechanisms to:&lt;br /&gt;
## Perform scans of the system [&#039;&#039;Assignment: organization-defined frequency&#039;&#039;] and real-time scans of files from external sources at endpoints or system entry and exit points as the files are downloaded, opened, or executed; and&lt;br /&gt;
## Block malicious code, quarantine malicious code, or take other mitigation actions in response to malicious code detection.&lt;br /&gt;
&lt;br /&gt;
===== DISCUSSION =====&lt;br /&gt;
&lt;br /&gt;
Malicious code insertions occur through the exploitation of system vulnerabilities. Malicious code can be inserted into the system in a variety of ways, including email, the internet, and portable storage devices. Malicious code includes viruses, worms, Trojan horses, and spyware. Malicious code can be encoded in various formats, contained in compressed or hidden files, or hidden in files using techniques such as steganography. Malicious code may be present in commercial off-the-shelf software and custom-built software and could include logic bombs, backdoors, and other types of attacks that could affect organizational mission and business functions. Periodic scans of the system and real-time scans of files from external sources as files are downloaded, opened, or executed can detect malicious code. Malicious code protection mechanisms can also monitor systems for anomalous or unexpected behaviors and take appropriate actions.&lt;br /&gt;
&lt;br /&gt;
Malicious code protection mechanisms include signature- and non-signature-based technologies. Non-signature-based detection mechanisms include artificial intelligence techniques that use heuristics to detect, analyze, and describe the characteristics or behavior of malicious code and to provide controls against such code for which signatures do not yet exist or for which existing signatures may not be effective. Malicious code for which active signatures do not yet exist or may be ineffective includes polymorphic malicious code (i.e., code that changes signatures when it replicates). Non-signature-based mechanisms include reputation-based technologies. Pervasive configuration management, anti-exploitation software, and software integrity controls may also be effective in preventing unauthorized code execution.&lt;br /&gt;
&lt;br /&gt;
If malicious code cannot be detected by detection methods or technologies, organizations can rely on secure coding practices, configuration management and control, trusted procurement processes, and monitoring practices to help ensure that the software only performs intended functions. Organizations may determine that different actions are warranted in response to the detection of malicious code. For example, organizations can define actions to be taken in response to the detection of malicious code during scans, malicious downloads, or malicious activity when attempting to open or execute files.&lt;br /&gt;
&lt;br /&gt;
===== REFERENCES =====&lt;br /&gt;
&lt;br /&gt;
Source Control: [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=SI-03 SI-03]&lt;br /&gt;
&lt;br /&gt;
Supporting Publications: SP 800-83 [[#bibr-ref_76|76]], SP 800-125B [[#bibr-ref_65|65]], SP 800-177 [[#bibr-ref_70|70]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;d30e4954-Head3&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&amp;lt;span id=&amp;quot;sec-sec_03.14.03&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&lt;br /&gt;
==== 03.14.03 Security Alerts, Advisories, and Directives ====&lt;br /&gt;
&lt;br /&gt;
# Receive system security alerts, advisories, and directives from external organizations on an ongoing basis.&lt;br /&gt;
# Generate and disseminate internal system security alerts, advisories, and directives, as necessary.&lt;br /&gt;
&lt;br /&gt;
===== DISCUSSION =====&lt;br /&gt;
&lt;br /&gt;
There are many publicly available sources of system security alerts and advisories. The Department of Homeland Security’s Cybersecurity and Infrastructure Security Agency (CISA), the National Security Agency (NSA), and the Federal Bureau of Investigation (FBI) generate security alerts and advisories to maintain situational awareness across the Federal Government and in nonfederal organizations. Software vendors, subscription services, and industry Information Sharing and Analysis Centers (ISACs) may also provide security alerts and advisories. Compliance with security directives is essential due to the critical nature of many of these directives and the potential immediate adverse effects on organizational operations and assets, individuals, other organizations, and the Nation should the directives not be implemented in a timely manner.&lt;br /&gt;
&lt;br /&gt;
===== REFERENCES =====&lt;br /&gt;
&lt;br /&gt;
Source Control: [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=SI-05 SI-05]&lt;br /&gt;
&lt;br /&gt;
Supporting Publications: SP 800-161 [[#bibr-ref_33|33]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;d30e4989-Head3&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&amp;lt;span id=&amp;quot;sec-sec_03.14.04&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&lt;br /&gt;
==== 03.14.04 Withdrawn ====&lt;br /&gt;
&lt;br /&gt;
Incorporated into [[#sec-sec_03.14.02|03.14.02]].&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;d30e4999-Head3&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&amp;lt;span id=&amp;quot;sec-sec_03.14.05&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&lt;br /&gt;
==== 03.14.05 Withdrawn ====&lt;br /&gt;
&lt;br /&gt;
Addressed by [[#sec-sec_03.14.02|03.14.02]].&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;d30e5009-Head3&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&amp;lt;span id=&amp;quot;sec-sec_03.14.06&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&lt;br /&gt;
==== 03.14.06 System Monitoring ====&lt;br /&gt;
&lt;br /&gt;
# Monitor the system to detect:&lt;br /&gt;
# Attacks and indicators of potential attacks and&lt;br /&gt;
# Unauthorized connections.&lt;br /&gt;
# Identify unauthorized use of the system.&lt;br /&gt;
# Monitor inbound and outbound communications traffic to detect unusual or unauthorized activities or conditions.&lt;br /&gt;
&lt;br /&gt;
===== DISCUSSION =====&lt;br /&gt;
&lt;br /&gt;
System monitoring involves external and internal monitoring. Internal monitoring includes the observation of events that occur within the system. External monitoring includes the observation of events that occur at the system boundary. Organizations can monitor the system by observing audit record activities in real time or by observing other system aspects, such as access patterns, characteristics of access, and other actions. The monitoring objectives may guide determination of the events.&lt;br /&gt;
&lt;br /&gt;
A system monitoring capability is achieved through a variety of tools and techniques (e.g., audit record monitoring software, intrusion detection systems, intrusion prevention systems, malicious code protection software, scanning tools, network monitoring software). Strategic locations for monitoring devices include selected perimeter locations and near server farms that support critical applications with such devices being employed at managed system interfaces. The granularity of monitoring the information collected is based on organizational monitoring objectives and the capability of the system to support such objectives.&lt;br /&gt;
&lt;br /&gt;
Systems connections can be network, remote, or local. A network connection is any connection with a device that communicates through a network (e.g., local area network, the internet). A remote connection is any connection with a device that communicates through an external network (e.g., the internet). Network, remote, and local connections can be either wired or wireless.&lt;br /&gt;
&lt;br /&gt;
Unusual or unauthorized activities or conditions related to inbound and outbound communications traffic include internal traffic that indicates the presence of malicious code in the system or propagating among system components, the unauthorized export of information, or signaling to external systems. Evidence of malicious code is used to identify a potentially compromised system. System monitoring requirements, including the need for types of system monitoring, may be referenced in other requirements.&lt;br /&gt;
&lt;br /&gt;
===== REFERENCES =====&lt;br /&gt;
&lt;br /&gt;
Source Controls: [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=SI-04 SI-04], [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=SI-04 SI-04(04)]&lt;br /&gt;
&lt;br /&gt;
Supporting Publications: SP 800-61 [[#bibr-ref_47|47]], SP 800-83 [[#bibr-ref_76|76]], SP 800-92 [[#bibr-ref_35|35]], SP 800-94 [[#bibr-ref_29|29]], SP 800-137 [[#bibr-ref_49|49]], SP 800-177 [[#bibr-ref_70|70]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;d30e5078-Head3&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&amp;lt;span id=&amp;quot;sec-sec_03.14.07&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&lt;br /&gt;
==== 03.14.07 Withdrawn ====&lt;br /&gt;
&lt;br /&gt;
Incorporated into [[#sec-sec_03.14.06|03.14.06]].&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;d30e5088-Head3&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&amp;lt;span id=&amp;quot;sec-sec_03.14.08&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&lt;br /&gt;
==== 03.14.08 Information Management and Retention ====&lt;br /&gt;
&lt;br /&gt;
Manage and retain CUI within the system and CUI output from the system in accordance with applicable laws, Executive Orders, directives, regulations, policies, standards, guidelines, and operational requirements.&lt;br /&gt;
&lt;br /&gt;
===== DISCUSSION =====&lt;br /&gt;
&lt;br /&gt;
Federal agencies consider data retention requirements for nonfederal organizations. Retaining CUI on nonfederal systems after contracts or agreements have concluded increases the attack surface for those systems and the risk of the information being compromised. NARA provides federal policy and guidance on records retention and schedules.&lt;br /&gt;
&lt;br /&gt;
===== REFERENCES =====&lt;br /&gt;
&lt;br /&gt;
Source Control: [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=SI-12 SI-12]&lt;br /&gt;
&lt;br /&gt;
Supporting Publications: None&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;d30e5111-Head2&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&amp;lt;span id=&amp;quot;sec-sec_3.15&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&lt;br /&gt;
=== 3.15 Planning ===&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;d30e5116-Head3&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&amp;lt;span id=&amp;quot;sec-sec_03.15.01&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&lt;br /&gt;
==== 03.15.01 Policy and Procedures ====&lt;br /&gt;
&lt;br /&gt;
# Develop, document, and disseminate to organizational personnel or roles the policies and procedures needed to satisfy the security requirements for the protection of CUI.&lt;br /&gt;
# Review and update policies and procedures [&#039;&#039;Assignment: organization-defined frequency&#039;&#039;].&lt;br /&gt;
&lt;br /&gt;
===== DISCUSSION =====&lt;br /&gt;
&lt;br /&gt;
This requirement addresses policies and procedures for the protection of CUI. Policies and procedures contribute to security assurance and should address each family of the CUI security requirements. Policies can be included as part of the organizational security policy or be represented by separate policies that address each family of security requirements. Procedures describe how policies are implemented and can be directed at the individual or role that is the object of the procedure. Procedures can be documented in system security plans or in one or more separate documents.&lt;br /&gt;
&lt;br /&gt;
===== REFERENCES =====&lt;br /&gt;
&lt;br /&gt;
Source Controls: [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=AC-01 AC-01], [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=AT-01 AT-01], [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=AU-01 AU-01], [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=CA-01 CA-01], [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=CM-01 CM-01], [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=IA-01 IA-01], [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=IR-01 IR-01], [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=MA-01 MA-01], [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=MP-01 MP-01], [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=PE-01 PE-01], [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=PL-01 PL-01], [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=PS-01 PS-01], [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=RA-01 RA-01], [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=SA-01 SA-01], [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=SC-01 SC-01], [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=SI-01 SI-01], [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=SR-01 SR-01]&lt;br /&gt;
&lt;br /&gt;
Supporting Publications: SP 800-12 [[#bibr-ref_61|61]], SP 800-100 [[#bibr-ref_62|62]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;d30e5223-Head3&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&amp;lt;span id=&amp;quot;sec-sec_03.15.02&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&lt;br /&gt;
==== 03.15.02 System Security Plan ====&lt;br /&gt;
&lt;br /&gt;
# Develop a system security plan that:&lt;br /&gt;
## Defines the constituent system components;&lt;br /&gt;
## Identifies the information types processed, stored, and transmitted by the system;&lt;br /&gt;
## Describes specific threats to the system that are of concern to the organization;&lt;br /&gt;
## Describes the operational environment for the system and any dependencies on or connections to other systems or system components;&lt;br /&gt;
## Provides an overview of the security requirements for the system;&lt;br /&gt;
## Describes the safeguards in place or planned for meeting the security requirements;&lt;br /&gt;
## Identifies individuals that fulfill system roles and responsibilities; and&lt;br /&gt;
## Includes other relevant information necessary for the protection of CUI.&lt;br /&gt;
# Review and update the system security plan [&#039;&#039;Assignment: organization-defined frequency&#039;&#039;].&lt;br /&gt;
# Protect the system security plan from unauthorized disclosure.&lt;br /&gt;
&lt;br /&gt;
===== DISCUSSION =====&lt;br /&gt;
&lt;br /&gt;
System security plans provide key characteristics of the system that is processing, storing, and transmitting CUI and how the system and information are protected. System security plans contain sufficient information to enable a design and implementation that are unambiguously compliant with the intent of the plans and the subsequent determinations of risk if the plan is implemented as intended. System security plans can be a collection of documents, including documents that already exist. Effective system security plans reference policies, procedures, and documents (e.g., design specifications) that provide additional detailed information. This reduces the documentation requirements associated with security programs and maintains security information in other established management or operational areas related to enterprise architecture, the system development life cycle, systems engineering, and acquisition.&lt;br /&gt;
&lt;br /&gt;
===== REFERENCES =====&lt;br /&gt;
&lt;br /&gt;
Source Control: [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=PL-02 PL-02]&lt;br /&gt;
&lt;br /&gt;
Supporting Publications: SP 800-18 [[#bibr-ref_63|63]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;d30e5292-Head3&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&amp;lt;span id=&amp;quot;sec-sec_03.15.03&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&lt;br /&gt;
==== 03.15.03 Rules of Behavior ====&lt;br /&gt;
&lt;br /&gt;
# Establish rules that describe the responsibilities and expected behavior for system usage and protecting CUI.&lt;br /&gt;
# Provide rules to individuals who require access to the system.&lt;br /&gt;
# Receive a documented acknowledgement from individuals indicating that they have read, understand, and agree to abide by the rules of behavior before authorizing access to CUI and the system.&lt;br /&gt;
# Review and update the rules of behavior [&#039;&#039;Assignment: organization-defined frequency&#039;&#039;].&lt;br /&gt;
&lt;br /&gt;
===== DISCUSSION =====&lt;br /&gt;
&lt;br /&gt;
Rules of behavior represent a type of access agreement for system users. Organizations consider rules of behavior for the handling of CUI based on individual user roles and responsibilities and differentiate between rules that apply to privileged users and rules that apply to general users.&lt;br /&gt;
&lt;br /&gt;
===== REFERENCES =====&lt;br /&gt;
&lt;br /&gt;
Source Control: [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=PL-04 PL-04]&lt;br /&gt;
&lt;br /&gt;
Supporting Publications: SP 800-18 [[#bibr-ref_63|63]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;d30e5336-Head2&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&amp;lt;span id=&amp;quot;sec-sec_3.16&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&lt;br /&gt;
=== 3.16 System and Services Acquisition ===&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;d30e5341-Head3&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&amp;lt;span id=&amp;quot;sec-sec_03.16.01&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&lt;br /&gt;
==== 03.16.01 Security Engineering Principles ====&lt;br /&gt;
&lt;br /&gt;
Apply the following systems security engineering principles to the development or modification of the system and system components: [&#039;&#039;Assignment: organization-defined systems security engineering principles&#039;&#039;].&lt;br /&gt;
&lt;br /&gt;
===== DISCUSSION =====&lt;br /&gt;
&lt;br /&gt;
Organizations apply systems security engineering principles to new development systems. For legacy systems, organizations apply systems security engineering principles to system modifications to the extent feasible, given the current state of hardware, software, and firmware components. The application of systems security engineering principles helps to develop trustworthy, secure, and resilient systems and reduce the susceptibility of organizations to disruptions, hazards, and threats. Examples include developing layered protections; establishing security policies, architectures, and controls as the foundation for system design; incorporating security requirements into the system development life cycle; delineating physical and logical security boundaries; ensuring that developers are trained on how to build trustworthy secure software; and performing threat modeling to identify use cases, threat agents, attack vectors and patterns, design patterns, and compensating controls needed to mitigate risk. Organizations that apply security engineering principles can facilitate the development of trustworthy, secure systems, system components, and system services; reduce risks to acceptable levels; and make informed risk-management decisions.&lt;br /&gt;
&lt;br /&gt;
===== REFERENCES =====&lt;br /&gt;
&lt;br /&gt;
Source Control: [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=SA-08 SA-08]&lt;br /&gt;
&lt;br /&gt;
Supporting Publications: SP 800-160-1 [[#bibr-ref_11|11]], SP 800-160-2 [[#bibr-ref_10|10]], SP 800-207 [[#bibr-ref_66|66]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;d30e5376-Head3&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&amp;lt;span id=&amp;quot;sec-sec_03.16.02&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&lt;br /&gt;
==== 03.16.02 Unsupported System Components ====&lt;br /&gt;
&lt;br /&gt;
# Replace system components when support for the components is no longer available from the developer, vendor, or manufacturer.&lt;br /&gt;
# Provide options for risk mitigation or alternative sources for continued support for unsupported components that cannot be replaced.&lt;br /&gt;
&lt;br /&gt;
===== DISCUSSION =====&lt;br /&gt;
&lt;br /&gt;
Support for system components includes software patches, firmware updates, replacement parts, and maintenance contracts. An example of unsupported components includes when vendors no longer provide critical software patches or product updates, which can result in opportunities for adversaries to exploit weaknesses or deficiencies in the installed components. Exceptions to replacing unsupported system components include systems that provide critical mission or business capabilities when newer technologies are unavailable or when the systems are so isolated that installing replacement components is not an option.&lt;br /&gt;
&lt;br /&gt;
Alternative sources of support address the need to provide continued support for system components that are no longer supported by the original manufacturers, developers, or vendors when such components remain essential to organizational missions and business functions. If necessary, organizations can establish in-house support by developing customized patches for critical software components or obtain the services of external service providers who provide ongoing support for unsupported components through contractual relationships. Such contractual relationships can include open-source software value-added vendors. The increased risk of using unsupported system components can be mitigated by prohibiting the connection of such components to public or uncontrolled networks or implementing other forms of isolation.&lt;br /&gt;
&lt;br /&gt;
===== REFERENCES =====&lt;br /&gt;
&lt;br /&gt;
Source Control: [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=SA-22 SA-22]&lt;br /&gt;
&lt;br /&gt;
Supporting Publications: None&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;d30e5410-Head3&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&amp;lt;span id=&amp;quot;sec-sec_03.16.03&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&lt;br /&gt;
==== 03.16.03 External System Services ====&lt;br /&gt;
&lt;br /&gt;
# Require the providers of external system services used for the processing, storage, or transmission of CUI to comply with the following security requirements: [&#039;&#039;Assignment: organization-defined security requirements&#039;&#039;].&lt;br /&gt;
# Define and document user roles and responsibilities with regard to external system services, including shared responsibilities with external service providers.&lt;br /&gt;
# Implement processes, methods, and techniques to monitor security requirement compliance by external service providers on an ongoing basis.&lt;br /&gt;
&lt;br /&gt;
===== DISCUSSION =====&lt;br /&gt;
&lt;br /&gt;
External system services are provided by external service providers. Organizations establish relationships with external service providers in a variety of ways, including through business partnerships, contracts, interagency agreements, lines of business arrangements, licensing agreements, joint ventures, and supply chain exchanges. The responsibility for managing risks from the use of external system services remains with the organization charged with protecting CUI. Service-level agreements define expectations of performance, describe measurable outcomes, and identify remedies, mitigations, and response requirements for instances of noncompliance. Information from external service providers regarding the specific functions, ports, protocols, and services used in the provision of such services can be useful when there is a need to understand the trade-offs involved in restricting certain functions and services or blocking certain ports and protocols. This requirement is related to [[#sec-sec_03.01.20|03.01.20]].&lt;br /&gt;
&lt;br /&gt;
===== REFERENCES =====&lt;br /&gt;
&lt;br /&gt;
Source Control: [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=SA-09 SA-09]&lt;br /&gt;
&lt;br /&gt;
Supporting Publications: SP 800-160-1 [[#bibr-ref_11|11]], SP 800-161 [[#bibr-ref_33|33]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;d30e5456-Head2&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&amp;lt;span id=&amp;quot;sec-sec_3.17&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&lt;br /&gt;
=== 3.17 Supply Chain Risk Management ===&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;d30e5461-Head3&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&amp;lt;span id=&amp;quot;sec-sec_03.17.01&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&lt;br /&gt;
==== 03.17.01 Supply Chain Risk Management Plan ====&lt;br /&gt;
&lt;br /&gt;
# Develop a plan for managing supply chain risks associated with the research and development, design, manufacturing, acquisition, delivery, integration, operations, maintenance, and disposal of the system, system components, or system services.&lt;br /&gt;
# Review and update the supply chain risk management plan [&#039;&#039;Assignment: organization-defined frequency&#039;&#039;].&lt;br /&gt;
# Protect the supply chain risk management plan from unauthorized disclosure.&lt;br /&gt;
&lt;br /&gt;
===== DISCUSSION =====&lt;br /&gt;
&lt;br /&gt;
Dependence on the products, systems, and services of external providers and the nature of the relationships with those providers present an increasing level of risk to an organization. Threat actions that may increase security risks include unauthorized production, the insertion or use of counterfeits, tampering, poor manufacturing and development practices in the supply chain, theft, and the insertion of malicious software, firmware, and hardware. Supply chain risks can be endemic or systemic within a system, component, or service. Managing supply chain risks is a complex, multifaceted undertaking that requires a coordinated effort across an organization to build trust relationships and communicate with internal and external stakeholders.&lt;br /&gt;
&lt;br /&gt;
Supply chain risk management (SCRM) activities include identifying and assessing risks, determining appropriate risk response actions, developing SCRM plans to document response actions, and monitoring performance against the plans. The system-level SCRM plan is implementation-specific and provides constraints, policy implementation, requirements, and implications. It can either be stand-alone or incorporated into system security plans. The SCRM plan addresses the management, implementation, and monitoring of SCRM requirements and the development or sustainment of systems across the system development life cycle to support mission and business functions. Because supply chains can differ significantly across and within organizations, SCRM plans are tailored to individual program, organizational, and operational contexts.&lt;br /&gt;
&lt;br /&gt;
===== REFERENCES =====&lt;br /&gt;
&lt;br /&gt;
Source Control: [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=SR-02 SR-02]&lt;br /&gt;
&lt;br /&gt;
Supporting Publications: SP 800-30 [[#bibr-ref_55|55]], SP 800-39 [[#bibr-ref_60|60]], SP 800-161 [[#bibr-ref_33|33]], SP 800-181 [[#bibr-ref_34|34]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;d30e5512-Head3&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&amp;lt;span id=&amp;quot;sec-sec_03.17.02&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&lt;br /&gt;
==== 03.17.02 Acquisition Strategies, Tools, and Methods ====&lt;br /&gt;
&lt;br /&gt;
Develop and implement acquisition strategies, contract tools, and procurement methods to identify, protect against, and mitigate supply chain risks.&lt;br /&gt;
&lt;br /&gt;
===== DISCUSSION =====&lt;br /&gt;
&lt;br /&gt;
The acquisition process provides an important vehicle for protecting the supply chain. There are many useful tools and techniques available, including obscuring the end use of a system or system component, using blind purchases, requiring tamper-evident packaging, or using trusted or controlled distribution. The results from a supply chain risk assessment can inform the strategies, tools, and methods that are most applicable to the situation. Tools and techniques may provide protections against unauthorized production, theft, tampering, the insertion of counterfeits, the insertion of malicious software or backdoors, and poor development practices throughout the system life cycle.&lt;br /&gt;
&lt;br /&gt;
Organizations also consider providing incentives for suppliers to implement safeguards, promote transparency in their processes and security practices, provide contract language that addresses the prohibition of tainted or counterfeit components, and restrict purchases from untrustworthy suppliers. Organizations consider providing training, education, and awareness programs for personnel regarding supply chain risks, available mitigation strategies, and when the programs should be employed. Methods for reviewing and protecting development plans, documentation, and evidence are commensurate with the security requirements of the organization. Contracts may specify documentation protection requirements.&lt;br /&gt;
&lt;br /&gt;
===== REFERENCES =====&lt;br /&gt;
&lt;br /&gt;
Source Control: [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=SR-05 SR-05]&lt;br /&gt;
&lt;br /&gt;
Supporting Publications: SP 800-30 [[#bibr-ref_55|55]], SP 800-161 [[#bibr-ref_33|33]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;d30e5543-Head3&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&amp;lt;span id=&amp;quot;sec-sec_03.17.03&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&lt;br /&gt;
==== 03.17.03 Supply Chain Requirements and Processes ====&lt;br /&gt;
&lt;br /&gt;
# Establish a process for identifying and addressing weaknesses or deficiencies in the supply chain elements and processes.&lt;br /&gt;
# Enforce the following security requirements to protect against supply chain risks to the system, system components, or system services and to limit the harm or consequences from supply chain-related events: [&#039;&#039;Assignment: organization-defined security requirements&#039;&#039;].&lt;br /&gt;
&lt;br /&gt;
===== DISCUSSION =====&lt;br /&gt;
&lt;br /&gt;
Supply chain elements include organizations, entities, or tools that are employed for the research, development, design, manufacturing, acquisition, delivery, integration, operations, maintenance, and disposal of systems and system components. Supply chain processes include hardware, software, firmware, and systems development processes; shipping and handling procedures; physical security programs; personnel security programs; configuration management tools, techniques, and measures to maintain provenance; or other programs, processes, or procedures associated with the development, acquisition, maintenance, and disposal of systems and system components. Supply chain elements and processes are provided by organizations, system integrators, or external service providers. Weaknesses or deficiencies in supply chain elements or processes represent potential vulnerabilities that can be exploited by adversaries to harm the organization and affect its ability to carry out its core missions or business functions.&lt;br /&gt;
&lt;br /&gt;
===== REFERENCES =====&lt;br /&gt;
&lt;br /&gt;
Source Control: [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=SR-03 SR-03]&lt;br /&gt;
&lt;br /&gt;
Supporting Publications: SP 800-30 [[#bibr-ref_55|55]], SP 800-161 [[#bibr-ref_33|33]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;d30e5583-BiblioHead&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;References&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;bibr-ref_1&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;[1] Executive Order 13556 (2010) Controlled Unclassified Information. (The White House, Washington, DC), DCPD-201000942, November 4, 2010. Available at [https://www.govinfo.gov/app/details/DCPD-201000942]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;bibr-ref_2&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;[2] Executive Order 13526 (2009) Classified National Security Information. (The White House, Washington, DC), DCPD-200901022, December 29, 2009. Available at [https://www.govinfo.gov/app/details/DCPD-200901022]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;bibr-ref_3&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;[3] Atomic Energy Act (P.L. 83-703), August 1954. Available at [https://www.govinfo.gov/app/details/STATUTE-68/STATUTE-68-Pg919]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;bibr-ref_4&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;[4] National Archives and Records Administration (2019) Controlled Unclassified Information (CUI) Registry. Available at [https://www.archives.gov/cui]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;bibr-ref_5&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;[5] 32 CFR Part 2002 (2016), Controlled Unclassified Information (CUI), September 2016. Available at [https://www.govinfo.gov/content/pkg/CFR-2018-title32-vol6/pdf/CFR-2018-title32-vol6-part2002.pdf]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;bibr-ref_6&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;[6] National Institute of Standards and Technology (2004) Standards for Security Categorization of Federal Information and Information Systems. (U.S. Department of Commerce, Washington, DC), Federal Information Processing Standards Publication (FIPS) 199. [https://doi.org/10.6028/NIST.FIPS.199]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;bibr-ref_7&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;[7] National Institute of Standards and Technology (2006) Minimum Security Requirements for Federal Information and Information Systems. (U.S. Department of Commerce, Washington, DC), Federal Information Processing Standards Publication (FIPS) 200. [https://doi.org/10.6028/NIST.FIPS.200]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;bibr-ref_8&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;[8] Joint Task Force (2020) Security and Privacy Controls for Information Systems and Organizations. (National Institute of Standards and Technology, Gaithersburg, MD), NIST Special Publication (SP) 800-53, Rev. 5, Includes updates as of December 10, 2020. [https://doi.org/10.6028/NIST.SP.800-53r5]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;bibr-ref_9&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;[9] Federal Information Security Modernization Act (P.L. 113-283), December 2014. Available at [https://www.govinfo.gov/app/details/PLAW-113publ283]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;bibr-ref_10&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;[10] Ross RS, Pillitteri VY, Graubart R, Bodeau D, McQuaid R, (2021) Developing Cyber-Resilient Systems: A Systems Security Engineering Approach. (National Institute of Standards and Technology, Gaithersburg, MD), NIST Special Publication (SP) 800-160, Vol. 2, Rev. 1. [https://doi.org/10.6028/NIST.SP.800-160v2r1]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;bibr-ref_11&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;[11] Ross R, Winstead M, McEvilley M, (2022) Engineering Trustworthy Secure Systems. (National Institute of Standards and Technology, Gaithersburg, MD), NIST Special Publication (SP) 800-160, Vol. 1, Rev. 1. [https://doi.org/10.6028/NIST.SP.800-160v1r1]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;bibr-ref_12&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;[12] Joint Task Force (2020) Control Baselines for Systems and Organizations. (National Institute of Standards and Technology, Gaithersburg, MD), NIST Special Publication (SP) 800-53B, Includes updates as of December 10, 2020. [https://doi.org/10.6028/NIST.SP.800-53B]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;bibr-ref_13&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;[13] Office of Management and Budget Circular A-130, Managing Information as a Strategic Resource, July 2016. Available at [https://www.whitehouse.gov/wp-content/uploads/legacy_drupal_files/omb/circulars/A130/a130revised.pdf]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;bibr-ref_14&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;[14] Souppaya MP, Scarfone KA, (2016) Guide to Enterprise Telework, Remote Access, and Bring Your Own Device (BYOD) Security. (National Institute of Standards and Technology, Gaithersburg, MD), NIST Special Publication (SP) 800-46, Rev. 2. [https://doi.org/10.6028/NIST.SP.800-46r2]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;bibr-ref_15&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;[15] Barker EB, (2020) Recommendation for Key Management: Part 1 – General. (National Institute of Standards and Technology, Gaithersburg, MD), NIST Special Publication (SP) 800-57 Part 1, Rev. 5. [https://doi.org/10.6028/NIST.SP.800-57pt1r5]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;bibr-ref_16&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;[16] Barker EB, Barker WC, (2019) Recommendation for Key Management: Part 2 – Best Practices for Key Management Organizations. (National Institute of Standards and Technology, Gaithersburg, MD), NIST Special Publication (SP) 800-57 Part 2, Rev. 1. [https://doi.org/10.6028/NIST.SP.800-57pt2r1]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;bibr-ref_17&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;[17] Barker EB, Dang QH, (2015) Recommendation for Key Management, Part 3: Application-Specific Key Management Guidance. (National Institute of Standards and Technology, Gaithersburg, MD), NIST Special Publication (SP) 800-57 Part 3, Rev. 1. [https://doi.org/10.6028/NIST.SP.800-57pt3r1]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;bibr-ref_18&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;[18] Barker EB, Dang QH, Frankel SE, Scarfone KA, Wouters P, (2020) Guide to IPsec VPNs. (National Institute of Standards and Technology, Gaithersburg, MD), NIST Special Publication (SP) 800-77, Rev. 1. [https://doi.org/10.6028/NIST.SP.800-77r1]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;bibr-ref_19&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;[19] Frankel SE, Hoffman P, Orebaugh AD, Park R, (2008) Guide to SSL VPNs. (National Institute of Standards and Technology, Gaithersburg, MD), NIST Special Publication ( SP) 800-113. [https://doi.org/10.6028/NIST.SP.800-113]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;bibr-ref_20&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;[20] Souppaya MP, Scarfone KA, (2016) User’s Guide to Telework and Bring Your Own Device (BYOD) Security. (National Institute of Standards and Technology, Gaithersburg, MD), NIST Special Publication (SP) 800-114, Rev. 1. [https://doi.org/10.6028/NIST.SP.800-114r1]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;bibr-ref_21&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;[21] Padgette J, Bahr J, Holtmann M, Batra M, Chen L, Smithbey R, Scarfone KA, (2017) Guide to Bluetooth Security. (National Institute of Standards and Technology, Gaithersburg, MD), NIST Special Publication (SP) 800-121, Rev. 2, Includes updates as of January 19, 2022. [https://doi.org/10.6028/NIST.SP.800-121r2-upd1]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;bibr-ref_22&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;[22] Hu VC, Ferraiolo DF, Kuhn R, Schnitzer A, Sandlin K, Miller R, Scarfone KA, (2014) Guide to Attribute Based Access Control (ABAC) Definition and Considerations. (National Institute of Standards and Technology, Gaithersburg, MD), NIST Special Publication (SP) 800-162, Includes updates as of August 2, 2019. [https://doi.org/10.6028/NIST.SP.800-162]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;bibr-ref_23&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;[23] Ferraiolo DF, Hu VC, Kuhn R, Chandramouli R, (2016) A Comparison of Attribute Based Access Control (ABAC) Standards for Data Service Applications: Extensible Access Control Markup Language (XACML) and Next Generation Access Control (NGAC). (National Institute of Standards and Technology, Gaithersburg, MD), NIST Special Publication ( SP) 800-178. [https://doi.org/10.6028/NIST.SP.800-178]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;bibr-ref_24&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;[24] Yaga DJ, Kuhn R, Hu VC, (2017) Verification and Test Methods for Access Control Policies/Models. (National Institute of Standards and Technology, Gaithersburg, MD), NIST Special Publication ( SP) 800-192. [https://doi.org/10.6028/NIST.SP.800-192]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;bibr-ref_25&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;[25] Hu VC, Scarfone KA, (2012) Guidelines for Access Control System Evaluation Metrics. (National Institute of Standards and Technology, Gaithersburg, MD), NIST Interagency or Internal Report (IR) 7874. [https://doi.org/10.6028/NIST.IR.7874]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;bibr-ref_26&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;[26] Ylonen T, Turner P, Scarfone KA, Souppaya MP, (2015) Security of Interactive and Automated Access Management Using Secure Shell (SSH). (National Institute of Standards and Technology, Gaithersburg, MD), NIST Interagency or Internal Report (IR) 7966. [https://doi.org/10.6028/NIST.IR.7966]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;bibr-ref_27&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;[27] Grassi PA, Garcia ME, Fenton JL, (2017) Digital Identity Guidelines. (National Institute of Standards and Technology, Gaithersburg, MD), NIST Special Publication (SP) 800-63-3, Includes updates as of March 2, 2020. [https://doi.org/10.6028/NIST.SP.800-63-3]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;bibr-ref_28&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;[28] Howell G, Franklin JM, Sritapan V, Souppaya M, Scarfone K, (2023) Guidelines for Managing the Security of Mobile Devices in the Enterprise. (National Institute of Standards and Technology, Gaithersburg, MD), NIST Special Publication (SP) 800-124, Rev. 2. [https://doi.org/10.6028/NIST.SP.800-124r2]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;bibr-ref_29&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;[29] Scarfone KA, Mell PM, (2007) Guide to Intrusion Detection and Prevention Systems (IDPS). (National Institute of Standards and Technology, Gaithersburg, MD), NIST Special Publication ( SP) 800-94. [https://doi.org/10.6028/NIST.SP.800-94]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;bibr-ref_30&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;[30] Frankel SE, Eydt B, Owens L, Scarfone KA, (2007) Establishing Wireless Robust Security Networks: A Guide to IEEE 802.11i. (National Institute of Standards and Technology, Gaithersburg, MD), NIST Special Publication ( SP) 800-97. [https://doi.org/10.6028/NIST.SP.800-97]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;bibr-ref_31&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;[31] Souppaya MP, Scarfone KA, (2016) User’s Guide to Telework and Bring Your Own Device (BYOD) Security. (National Institute of Standards and Technology, Gaithersburg, MD), NIST Special Publication (SP) 800-114, Rev. 1. [https://doi.org/10.6028/NIST.SP.800-114r1]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;bibr-ref_32&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;[32] Wilson M, Hash J, (2003) Building an Information Technology Security Awareness and Training Program. (National Institute of Standards and Technology, Gaithersburg, MD), NIST Special Publication ( SP) 800-50. [https://doi.org/10.6028/NIST.SP.800-50]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;bibr-ref_33&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;[33] Boyens JM, Smith A, Bartol N, Winkler K, Holbrook A, Fallon M, (2022) Cybersecurity Supply Chain Risk Management Practices for Systems and Organizations. (National Institute of Standards and Technology, Gaithersburg, MD), NIST Special Publication (SP) 800-161, Rev. 1. [https://doi.org/10.6028/NIST.SP.800-161r1]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;bibr-ref_34&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;[34] Petersen R, Santos D, Smith MC, Wetzel KA, Witte G, (2020) Workforce Framework for Cybersecurity (NICE Framework). (National Institute of Standards and Technology, Gaithersburg, MD), NIST Special Publication (SP) 800-181, Rev. 1. [https://doi.org/10.6028/NIST.SP.800-181r1]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;bibr-ref_35&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;[35] Kent K, Souppaya MP, (2006) Guide to Computer Security Log Management. (National Institute of Standards and Technology, Gaithersburg, MD), NIST Special Publication ( SP) 800-92. [https://doi.org/10.6028/NIST.SP.800-92]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;bibr-ref_36&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;[36] Kent K, Chevalier S, Grance T, Dang H, (2006) Guide to Integrating Forensic Techniques into Incident Response. (National Institute of Standards and Technology, Gaithersburg, MD), NIST Special Publication ( SP) 800-86. [https://doi.org/10.6028/NIST.SP.800-86]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;bibr-ref_37&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;[37] Ayers RP, Brothers S, Jansen W, (2014) Guidelines on Mobile Device Forensics. (National Institute of Standards and Technology, Gaithersburg, MD), NIST Special Publication (SP) 800-101, Rev. 1. [https://doi.org/10.6028/NIST.SP.800-101r1]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;bibr-ref_38&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;[38] National Institute of Standards and Technology (2019) Security Requirements for Cryptographic Modules. (U.S. Department of Commerce, Washington, D.C.), Federal Information Processing Standards Publication (FIPS) 140-3. [https://doi.org/10.6028/NIST.FIPS.140-3]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;bibr-ref_39&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;[39] National Institute of Standards and Technology (2015) Secure Hash Standard (SHS). (U.S. Department of Commerce, Washington, D.C.), Federal Information Processing Standards Publication (FIPS) 180-4. [https://doi.org/10.6028/NIST.FIPS.180-4]&lt;br /&gt;
&lt;br /&gt;
[40] National Institute of Standards and Technology (2015) SHA-3 Standard: Permutation-Based Hash and Extendable-Output Functions. (U.S. Department of Commerce, Washington, D.C.), Federal Information Processing Standards Publication (FIPS) 202. [https://doi.org/10.6028/NIST.FIPS.202]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;bibr-ref_41&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;[41] Johnson LA, Dempsey KL, Ross RS, Gupta S, Bailey D, (2011) Guide for Security-Focused Configuration Management of Information Systems. (National Institute of Standards and Technology, Gaithersburg, MD), NIST Special Publication (SP) 800-128, Includes updates as of October 10, 2019. [https://doi.org/10.6028/NIST.SP.800-128]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;bibr-ref_42&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;[42] Dempsey KL, Eavy P, Moore G, (2017) Automation Support for Security Control Assessments: Volume 2: Hardware Asset Management. (National Institute of Standards and Technology, Gaithersburg, MD), NIST Interagency or Internal Report (IR) 8011, Volume 2. [https://doi.org/10.6028/NIST.IR.8011-2]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;bibr-ref_43&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;[43] Dempsey KL, Eavy P, Goren N, Moore G, (2018) Automation Support for Security Control Assessments: Volume 3: Software Asset Management. (National Institute of Standards and Technology, Gaithersburg, MD), NIST Interagency or Internal Report (IR) 8011, Volume 3. [https://doi.org/10.6028/NIST.IR.8011-3]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;bibr-ref_44&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;[44] Quinn SD, Souppaya MP, Cook MR, Scarfone KA, (2018) National Checklist Program for IT Products: Guidelines for Checklist Users and Developers. (National Institute of Standards and Technology, Gaithersburg, MD), NIST Special Publication (SP) 800-70, Rev. 4. [https://doi.org/10.6028/NIST.SP.800-70r4]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;bibr-ref_45&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;[45] Waltermire DA, Quinn SD, Booth H, Scarfone KA, Prisaca D, (2018) The Technical Specification for the Security Content Automation Protocol (SCAP): SCAP Version 1.3. (National Institute of Standards and Technology, Gaithersburg, MD), NIST Special Publication (SP) 800-126, Rev. 3. [https://doi.org/10.6028/NIST.SP.800-126r3]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;bibr-ref_46&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;[46] Sedgewick A, Souppaya MP, Scarfone KA, (2015) Guide to Application Whitelisting. (National Institute of Standards and Technology, Gaithersburg, MD), NIST Special Publication ( SP) 800-167. [https://doi.org/10.6028/NIST.SP.800-167]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;bibr-ref_47&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;[47] Cichonski PR, Millar T, Grance T, Scarfone KA, (2012) Computer Security Incident Handling Guide. (National Institute of Standards and Technology, Gaithersburg, MD), NIST Special Publication (SP) 800-61, Rev. 2. [https://doi.org/10.6028/NIST.SP.800-61r2]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;bibr-ref_48&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;[48] Grance T, Nolan T, Burke K, Dudley R, White G, Good T, (2006) Guide to Test, Training, and Exercise Programs for IT Plans and Capabilities. (National Institute of Standards and Technology, Gaithersburg, MD), NIST Special Publication ( SP) 800-84. [https://doi.org/10.6028/NIST.SP.800-84]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;bibr-ref_49&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;[49] Dempsey KL, Chawla NS, Johnson LA, Johnston R, Jones AC, Orebaugh AD, Scholl MA, Stine KM, (2011) Information Security Continuous Monitoring (ISCM) for Federal Information Systems and Organizations. (National Institute of Standards and Technology, Gaithersburg, MD), NIST Special Publication ( SP) 800-137. [https://doi.org/10.6028/NIST.SP.800-137]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;bibr-ref_50&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;[50] Kissel RL, Regenscheid AR, Scholl MA, Stine KM, (2014) Guidelines for Media Sanitization. (National Institute of Standards and Technology, Gaithersburg, MD), NIST Special Publication (SP) 800-88, Rev. 1. [https://doi.org/10.6028/NIST.SP.800-88r1]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;bibr-ref_51&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;[51] Scarfone KA, Souppaya MP, Sexton M, (2007) Guide to Storage Encryption Technologies for End User Devices. (National Institute of Standards and Technology, Gaithersburg, MD), NIST Special Publication ( SP) 800-111. [https://doi.org/10.6028/NIST.SP.800-111]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;bibr-ref_52&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;[52] Swanson MA, Bowen P, Phillips AW, Gallup D, Lynes D, (2010) Contingency Planning Guide for Federal Information Systems. (National Institute of Standards and Technology, Gaithersburg, MD), NIST Special Publication (SP) 800-34, Rev. 1, Includes updates as of November 11, 2010. [https://doi.org/10.6028/NIST.SP.800-34r1]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;bibr-ref_53&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;[53] Barker EB, Smid ME, Branstad DK, Chokhani S, (2013) A Framework for Designing Cryptographic Key Management Systems. (National Institute of Standards and Technology, Gaithersburg, MD), NIST Special Publication ( SP) 800-130. [https://doi.org/10.6028/NIST.SP.800-130]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;bibr-ref_54&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;[54] Barker EB, Branstad DK, Smid ME, (2015) A Profile for U.S. Federal Cryptographic Key Management Systems (CKMS). (National Institute of Standards and Technology, Gaithersburg, MD), NIST Special Publication ( SP) 800-152. [https://doi.org/10.6028/NIST.SP.800-152]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;bibr-ref_55&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;[55] Joint Task Force Transformation Initiative (2012) Guide for Conducting Risk Assessments. (National Institute of Standards and Technology, Gaithersburg, MD), NIST Special Publication (SP) 800-30, Rev. 1. [https://doi.org/10.6028/NIST.SP.800-30r1]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;bibr-ref_56&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;[56] Souppaya MP, Scarfone KA, (2022) Guide to Enterprise Patch Management Planning: Preventive Maintenance for Technology. (National Institute of Standards and Technology, Gaithersburg, MD), NIST Special Publication (SP) 800-40, Rev. 4. [https://doi.org/10.6028/NIST.SP.800-40r4]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;bibr-ref_57&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;[57] Joint Task Force Transformation Initiative (2022) Assessing Security and Privacy Controls in Information Systems and Organizations. (National Institute of Standards and Technology, Gaithersburg, MD), NIST Special Publication (SP) 800-53A, Rev. 5. [https://doi.org/10.6028/NIST.SP.800-53Ar5]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;bibr-ref_58&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;[58] Scarfone KA, Souppaya MP, Cody A, Orebaugh AD, (2008) Technical Guide to Information Security Testing and Assessment. (National Institute of Standards and Technology, Gaithersburg, MD), NIST Special Publication ( SP) 800-115. [https://doi.org/10.6028/NIST.SP.800-115]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;bibr-ref_59&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;[59] Joint Task Force (2018) Risk Management Framework for Information Systems and Organizations: A System Life Cycle Approach for Security and Privacy. (National Institute of Standards and Technology, Gaithersburg, MD), NIST Special Publication (SP) 800-37, Rev. 2. [https://doi.org/10.6028/NIST.SP.800-37r2]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;bibr-ref_60&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;[60] Joint Task Force Transformation Initiative (2011) Managing Information Security Risk: Organization, Mission, and Information System View. (National Institute of Standards and Technology, Gaithersburg, MD), NIST Special Publication ( SP) 800-39. [https://doi.org/10.6028/NIST.SP.800-39]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;bibr-ref_61&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;[61] Nieles M, Pillitteri VY, Dempsey KL, (2017) An Introduction to Information Security. (National Institute of Standards and Technology, Gaithersburg, MD), NIST Special Publication (SP) 800-12, Rev. 1. [https://doi.org/10.6028/NIST.SP.800-12r1]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;bibr-ref_62&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;[62] Bowen P, Hash J, Wilson M, (2006) Information Security Handbook: A Guide for Managers. (National Institute of Standards and Technology, Gaithersburg, MD), NIST Special Publication (SP) 800-100, Includes updates as of March 7, 2007. [https://doi.org/10.6028/NIST.SP.800-100]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;bibr-ref_63&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;[63] Swanson MA, Hash J, Bowen P, (2006) Guide for Developing Security Plans for Federal Information Systems. (National Institute of Standards and Technology, Gaithersburg, MD), NIST Special Publication (SP) 800-18, Rev. 1. [https://doi.org/10.6028/NIST.SP.800-18r1]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;bibr-ref_64&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;[64] Scarfone KA, Hoffman P, (2009) Guidelines on Firewalls and Firewall Policy. (National Institute of Standards and Technology, Gaithersburg, MD), NIST Special Publication (SP) 800-41, Rev. 1. [https://doi.org/10.6028/NIST.SP.800-41r1]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;bibr-ref_65&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;[65] Chandramouli R, (2016) Secure Virtual Network Configuration for Virtual Machine (VM) Protection. (National Institute of Standards and Technology, Gaithersburg, MD), NIST Special Publication ( SP) 800-125B. [https://doi.org/10.6028/NIST.SP.800-125B]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;bibr-ref_66&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;[66] Rose S, Borchert O, Mitchell S, Connelly S, (2017) Zero Trust Architecture. (National Institute of Standards and Technology, Gaithersburg, MD), NIST Special Publication ( SP) 800-207. [https://doi.org/10.6028/NIST.SP.800-207]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;bibr-ref_67&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;[67] Sriram K, Montgomery D, (2019) Resilient Interdomain Traffic Exchange: BGP Security and DDoS Mitigation. (National Institute of Standards and Technology, Gaithersburg, MD), NIST Special Publication ( SP) 800-189. [https://doi.org/10.6028/NIST.SP.800-189]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;bibr-ref_68&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;[68] National Institute of Standards and Technology (2001) Advanced Encryption Standard (AES). (U.S. Department of Commerce, Washington, D.C.), Federal Information Processing Standards Publication (FIPS) 197, updated May 9, 2023. [https://doi.org/10.6028/NIST.FIPS.197-upd1]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;bibr-ref_69&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;[69] McKay KA, Cooper DA, (2019) Guidelines for the Selection, Configuration, and Use of Transport Layer Security (TLS) Implementations. (National Institute of Standards and Technology, Gaithersburg, MD), NIST Special Publication (SP) 800-52, Rev. 2. [https://doi.org/10.6028/NIST.SP.800-52r2]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;bibr-ref_70&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;[70] Rose SW, Nightingale S, Garfinkel SL, Chandramouli R, (2019) Trustworthy Email. (National Institute of Standards and Technology, Gaithersburg, MD), NIST Special Publication (SP) 800-177, Rev. 1. [https://doi.org/10.6028/NIST.SP.800-177r1]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;bibr-ref_71&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;[71] Jansen W, Winograd T, Scarfone KA, (2008) Guidelines on Active Content and Mobile Code. (National Institute of Standards and Technology, Gaithersburg, MD), NIST Special Publication (SP) 800-28, Version 2. [https://doi.org/10.6028/NIST.SP.800-28ver2]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;bibr-ref_72&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;[72] Singhal A, Winograd T, Scarfone KA, (2007) Guide to Secure Web Services. (National Institute of Standards and Technology, Gaithersburg, MD), NIST Special Publication ( SP) 800-95. [https://doi.org/10.6028/NIST.SP.800-95]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;bibr-ref_73&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;[73] Barker EB, Chen L, Roginsky A, Vassilev A, Davis R, (2018) Recommendation for Pair-Wise Key-Establishment Schemes Using Discrete Logarithm Cryptography. (National Institute of Standards and Technology, Gaithersburg, MD), NIST Special Publication (SP) 800-56A, Rev. 3. [https://doi.org/10.6028/NIST.SP.800-56Ar3]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;bibr-ref_74&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;[74] Barker EB, Chen L, Roginsky A, Vassilev A, Davis R, Simon S, (2019) Recommendation for Pair-Wise Key-Establishment Using Integer Factorization Cryptography. (National Institute of Standards and Technology, Gaithersburg, MD), NIST Special Publication (SP) 800-56B, Rev. 2. [https://doi.org/10.6028/NIST.SP.800-56Br2]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;bibr-ref_75&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;[75] Barker EB, Chen L, Davis R, (2020) Recommendation for Key-Derivation Methods in Key-Establishment Schemes. (National Institute of Standards and Technology, Gaithersburg, MD), NIST Special Publication (SP) 800-56C, Rev. 2. [https://doi.org/10.6028/NIST.SP.800-56Cr2]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;bibr-ref_76&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;[76] Souppaya MP, Scarfone KA, (2013) Guide to Malware Incident Prevention and Handling for Desktops and Laptops. (National Institute of Standards and Technology, Gaithersburg, MD), NIST Special Publication (SP) 800-83, Rev. 1. [https://doi.org/10.6028/NIST.SP.800-83r1]&lt;br /&gt;
&lt;br /&gt;
[77] Tracy MC, Jansen W, Scarfone KA, Butterfield J, (2007) Guidelines on Electronic Mail Security. (National Institute of Standards and Technology, Gaithersburg, MD), NIST Special Publication (SP) 800-45, Version 2. [https://doi.org/10.6028/NIST.SP.800-45ver2]&lt;br /&gt;
&lt;br /&gt;
[78] Committee on National Security Systems (2022) Committee on National Security Systems (CNSS) Glossary. (National Security Agency, Fort George G. Meade, MD), CNSS Instruction 4009. Available at [https://www.cnss.gov/CNSS/issuances/Instructions.cfm]&lt;br /&gt;
&lt;br /&gt;
[79] Title 44 U.S. Code, Sec. 3552, Definitions. 2017 ed. Available at [https://www.govinfo.gov/app/details/USCODE-2017-title44/USCODE-2017-title44-chap35-subchapII-sec3552]&lt;br /&gt;
&lt;br /&gt;
[80] Title 40 U.S. Code, Sec. 11331, Responsibilities for Federal information systems standards. 2017 ed. Available at [https://www.govinfo.gov/app/details/USCODE-2017-title40/USCODE-2017-title40-subtitleIII-chap113-subchapIII-sec11331]&lt;br /&gt;
&lt;br /&gt;
[81] Title 44 U.S. Code, Sec. 3502, Definitions. 2017 ed. Available at [https://www.govinfo.gov/app/details/USCODE-2021-title44/USCODE-2021-title44-chap35-subchapI-sec3502]&lt;br /&gt;
&lt;br /&gt;
[82] Chandramouli R, Rose SW, (2013) Secure Domain Name System (DNS) Deployment Guide. (National Institute of Standards and Technology, Gaithersburg, MD), NIST Special Publication (SP) 800-81-2. [https://doi.org/10.6028/NIST.SP.800-81-2]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;bibr-ref_83&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;[83] Dempsey K, Pillitteri V, Regenscheid A, (2021) Managing the Security of Information Exchanges. (National Institute of Standards and Technology, Gaithersburg, MD), NIST Special Publication (SP) 800-47, Rev. 1. [https://doi.org/10.6028/NIST.SP.800-47r1]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;bibr-ref_84&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;[84] Ross R, Pillitteri V, (2024) Assessing Security Requirements for Controlled Unclassified Information. (National Institute of Standards and Technology, Gaithersburg, MD), NIST Special Publication (SP) 800-171A, Rev. 3. [https://doi.org/10.6028/NIST.SP.800-171Ar3]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;d30e6922-Appendix_Title&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&amp;lt;span id=&amp;quot;sec-sec_A&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&lt;br /&gt;
== Appendix A : Acronyms ==&lt;br /&gt;
&lt;br /&gt;
;CFR&lt;br /&gt;
:Code of Federal Regulations&lt;br /&gt;
;CISA&lt;br /&gt;
:Cybersecurity and Infrastructure Security Agency&lt;br /&gt;
;CUI&lt;br /&gt;
:Controlled Unclassified Information&lt;br /&gt;
;CVE&lt;br /&gt;
:Common Vulnerabilities and Exposures&lt;br /&gt;
;CVSS&lt;br /&gt;
:Common Vulnerability Scoring System&lt;br /&gt;
;CWE&lt;br /&gt;
:Common Weakness Enumeration&lt;br /&gt;
;DMZ&lt;br /&gt;
:Demilitarized Zone&lt;br /&gt;
;EAP&lt;br /&gt;
:Extensible Authentication Protocol&lt;br /&gt;
;FIPS&lt;br /&gt;
:Federal Information Processing Standards&lt;br /&gt;
;FISMA&lt;br /&gt;
:Federal Information Security Modernization Act&lt;br /&gt;
;FTP&lt;br /&gt;
:File Transfer Protocol&lt;br /&gt;
;GMT&lt;br /&gt;
:Greenwich Mean Time&lt;br /&gt;
;HSM&lt;br /&gt;
:Hardware Security Module&lt;br /&gt;
;IEEE&lt;br /&gt;
:Institute of Electrical and Electronics Engineers&lt;br /&gt;
;IIoT&lt;br /&gt;
:Industrial Internet of Things&lt;br /&gt;
;IoT&lt;br /&gt;
:Internet of Things&lt;br /&gt;
;ISOO&lt;br /&gt;
:Information Security Oversight Office&lt;br /&gt;
;IT&lt;br /&gt;
:Information Technology&lt;br /&gt;
;LSI&lt;br /&gt;
:Large-Scale Integration&lt;br /&gt;
;MAC&lt;br /&gt;
:Media Access Control&lt;br /&gt;
;NARA&lt;br /&gt;
:National Archives and Records Administration&lt;br /&gt;
;NVD&lt;br /&gt;
:National Vulnerability Database&lt;br /&gt;
;ODP&lt;br /&gt;
:Organization-Defined Parameter&lt;br /&gt;
;OT&lt;br /&gt;
:Operational Technology&lt;br /&gt;
;PII&lt;br /&gt;
:Personally Identifiable Information&lt;br /&gt;
;PIN&lt;br /&gt;
:Personal Identification Number&lt;br /&gt;
;PROM&lt;br /&gt;
:Programmable Read-Only Memory&lt;br /&gt;
;ROM&lt;br /&gt;
:Read-Only Memory&lt;br /&gt;
;SCAP&lt;br /&gt;
:Security Content Automation Protocol&lt;br /&gt;
;SCRM&lt;br /&gt;
:Supply Chain Risk Management&lt;br /&gt;
;TCP/IP&lt;br /&gt;
:Transmission Control Protocol/Internet Protocol&lt;br /&gt;
;TLS&lt;br /&gt;
:Transport Layer Security&lt;br /&gt;
;UTC&lt;br /&gt;
:Coordinated Universal Time&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;d30e7063-Appendix_Title&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&amp;lt;span id=&amp;quot;sec-sec_B&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&lt;br /&gt;
== Appendix B : Glossary ==&lt;br /&gt;
&lt;br /&gt;
[[#sec-sec_B|Appendix B]] provides definitions for the terminology used in SP 800-171r3. The definitions are consistent with the definitions contained in the National Information Assurance Glossary [[#bibr-ref_78|&amp;lt;u&amp;gt;78&amp;lt;/u&amp;gt;]] unless otherwise noted.&lt;br /&gt;
&lt;br /&gt;
;agency&lt;br /&gt;
:Any executive agency or department, military department, Federal Government corporation, Federal Government-controlled corporation, or other establishment in the Executive Branch of the Federal Government, or any independent regulatory agency. [[#bibr-ref_13|&amp;lt;u&amp;gt;13&amp;lt;/u&amp;gt;]]&lt;br /&gt;
;assessment&lt;br /&gt;
:See &#039;&#039;security control assessment&#039;&#039;.&lt;br /&gt;
;assessor&lt;br /&gt;
:See &#039;&#039;security control assessor&#039;&#039;.&lt;br /&gt;
;audit log&lt;br /&gt;
:A chronological record of system activities, including records of system accesses and operations performed in a given period.&lt;br /&gt;
;audit record&lt;br /&gt;
:An individual entry in an audit log related to an audited event.&lt;br /&gt;
;authentication&lt;br /&gt;
:Verifying the identity of a user, process, or device, often as a prerequisite to allowing access to resources in a system. [[#bibr-ref_7|&amp;lt;u&amp;gt;7, adapted&amp;lt;/u&amp;gt;]].&lt;br /&gt;
;availability&lt;br /&gt;
:Ensuring timely and reliable access to and use of information. [[#bibr-ref_79|&amp;lt;u&amp;gt;79&amp;lt;/u&amp;gt;]]&lt;br /&gt;
;advanced persistent threat&lt;br /&gt;
:An adversary that possesses sophisticated levels of expertise and significant resources which allow it to create opportunities to achieve its objectives by using multiple attack vectors including, for example, cyber, physical, and deception. These objectives typically include establishing and extending footholds within the IT infrastructure of the targeted organizations for purposes of exfiltrating information, undermining or impeding critical aspects of a mission, program, or organization; or positioning itself to carry out these objectives in the future. The advanced persistent threat pursues its objectives repeatedly over an extended period; adapts to defenders’ efforts to resist it; and is determined to maintain the level of interaction needed to execute its objectives. [[#bibr-ref_60|&amp;lt;u&amp;gt;60&amp;lt;/u&amp;gt;]]&lt;br /&gt;
;authenticator&lt;br /&gt;
:Something the claimant possesses and controls (typically a cryptographic module or password) that is used to authenticate the claimant’s identity. This was previously referred to as a token.&lt;br /&gt;
;baseline configuration&lt;br /&gt;
:A documented set of specifications for a system or a configuration item within a system that has been formally reviewed and agreed upon at a given point in time, and that can only be changed through change control procedures.&lt;br /&gt;
;common secure configuration&lt;br /&gt;
:Recognized, standardized, and established benchmarks that stipulate secure configuration settings for specific information technology platforms/products and instructions for configuring those system components to meet operational requirements. These benchmarks are also referred to as security configuration checklists, lockdown and hardening guides, security reference guides, and security technical implementation guides.&lt;br /&gt;
;confidentiality&lt;br /&gt;
:Preserving authorized restrictions on information access and disclosure, including means for protecting personal privacy and proprietary information. [[#bibr-ref_79|&amp;lt;u&amp;gt;79&amp;lt;/u&amp;gt;]]&lt;br /&gt;
;configuration management&lt;br /&gt;
:A collection of activities focused on establishing and maintaining the integrity of information technology products and systems through the control of processes for initializing, changing, and monitoring the configurations of those products and systems throughout the system development life cycle.&lt;br /&gt;
;configuration settings&lt;br /&gt;
:The set of parameters that can be changed in hardware, software, or firmware that affect the security posture and/or functionality of the system.&lt;br /&gt;
;controlled area&lt;br /&gt;
:Any area or space for which the organization has confidence that the physical and procedural protections provided are sufficient to meet the requirements established for protecting the information or system.&lt;br /&gt;
;controlled unclassified information&lt;br /&gt;
:Information that law, regulation, or governmentwide policy requires to have safeguarding or disseminating controls, excluding information that is classified under Executive Order 13526, Classified National Security Information, December 29, 2009, or any predecessor or successor order, or the Atomic Energy Act of 1954, as amended. [[#bibr-ref_1|&amp;lt;u&amp;gt;1&amp;lt;/u&amp;gt;]]&lt;br /&gt;
;CUI Executive Agent&lt;br /&gt;
:The National Archives and Records Administration (NARA), which implements the executive branch-wide CUI Program and oversees federal agency actions to comply with Executive Order 13556. NARA has delegated this authority to the Director of the Information Security Oversight Office (ISOO). [[#bibr-ref_5|&amp;lt;u&amp;gt;5&amp;lt;/u&amp;gt;]]&lt;br /&gt;
;CUI program&lt;br /&gt;
:The executive branch-wide program to standardize CUI handling by all federal agencies. The program includes the rules, organization, and procedures for CUI, established by Executive Order 13556, 32 CFR Part 2002, and the CUI Registry. [[#bibr-ref_5|&amp;lt;u&amp;gt;5&amp;lt;/u&amp;gt;]]&lt;br /&gt;
;CUI registry&lt;br /&gt;
:The online repository for all information, guidance, policy, and requirements on handling CUI, including everything issued by the CUI Executive Agent other than 32 CFR Part 2002. Among other information, the CUI Registry identifies all approved CUI categories, provides general descriptions for each, identifies the basis for controls, establishes markings, and includes guidance on handling procedures. [[#bibr-ref_5|&amp;lt;u&amp;gt;5&amp;lt;/u&amp;gt;]]&lt;br /&gt;
;cyber-physical systems&lt;br /&gt;
:Interacting digital, analog, physical, and human components engineered for function through integrated physics and logic.&lt;br /&gt;
;executive agency&lt;br /&gt;
:An executive department specified in 5 U.S.C. Sec. 101; a military department specified in 5 U.S.C. Sec. 102; an independent establishment as defined in 5 U.S.C. Sec. 104(1); and a wholly owned Government corporation fully subject to the provisions of 31 U.S.C. Chapter 91.&lt;br /&gt;
;external network&lt;br /&gt;
:A network not controlled by the organization.&lt;br /&gt;
;external service provider&lt;br /&gt;
:See &#039;&#039;external system service provider&#039;&#039;.&lt;br /&gt;
;external system (or component)&lt;br /&gt;
:A system or component of a system that is outside of the authorization boundary established by the organization and for which the organization typically has no direct control over the application of required security controls or the assessment of security control effectiveness.&lt;br /&gt;
;external system service&lt;br /&gt;
:A system service that is implemented outside of the authorization boundary of the organizational system (i.e., a service that is used by but not a part of the organizational system) and for which the organization typically has no direct control over the application of required security controls or the assessment of security control effectiveness.&lt;br /&gt;
;external system service provider&lt;br /&gt;
:A provider of external system services to an organization through a variety of consumer-producer relationships, including joint ventures, business partnerships, outsourcing arrangements (i.e., through contracts, interagency agreements, lines of business arrangements), licensing agreements, and/or supply chain exchanges. [[#bibr-ref_8|8]]&lt;br /&gt;
;facility&lt;br /&gt;
:One or more physical locations containing systems or system components that process, store, or transmit information.&lt;br /&gt;
;federal agency&lt;br /&gt;
:See &#039;&#039;executive agency&#039;&#039;.&lt;br /&gt;
;federal information system&lt;br /&gt;
:An information system used or operated by an executive agency, by a contractor of an executive agency, or by another organization on behalf of an executive agency. [[#bibr-ref_80|&amp;lt;u&amp;gt;80&amp;lt;/u&amp;gt;]]&lt;br /&gt;
;FIPS-validated cryptography&lt;br /&gt;
:A cryptographic module validated by the Cryptographic Module Validation Program (CMVP) to meet the requirements specified in FIPS Publication 140-3 (as amended). As a prerequisite to CMVP validation, the cryptographic module is required to employ a cryptographic algorithm implementation that has successfully passed validation testing by the Cryptographic Algorithm Validation Program (CAVP). See &#039;&#039;NSA-approved cryptography&#039;&#039;.&lt;br /&gt;
;firmware&lt;br /&gt;
:Computer programs and data stored in hardware – typically in read-only memory (ROM) or programmable read-only memory (PROM) – such that the programs and data cannot be dynamically written or modified during execution of the programs. See &#039;&#039;hardware&#039;&#039; and &#039;&#039;software&#039;&#039;. [[#bibr-ref_78|&amp;lt;u&amp;gt;78&amp;lt;/u&amp;gt;]]&lt;br /&gt;
;hardware&lt;br /&gt;
:The material physical components of a system. See &#039;&#039;software&#039;&#039; and &#039;&#039;firmware&#039;&#039;. [[#bibr-ref_78|&amp;lt;u&amp;gt;78&amp;lt;/u&amp;gt;]]&lt;br /&gt;
;identifier&lt;br /&gt;
:Unique data used to represent a person’s identity and associated attributes. A name or a card number are examples of identifiers.&lt;br /&gt;
:A unique label used by a system to indicate a specific entity, object, or group.&lt;br /&gt;
;impact&lt;br /&gt;
:With respect to security, the effect on organizational operations, organizational assets, individuals, other organizations, or the Nation (including the national security interests of the United States) of a loss of confidentiality, integrity, or availability of information or a system. With respect to privacy, the adverse effects that individuals could experience when an information system processes their PII.&lt;br /&gt;
;impact value&lt;br /&gt;
:The assessed worst-case potential impact that could result from a compromise of the confidentiality, integrity, or availability of information expressed as a value of low, moderate, or high. [[#bibr-ref_6|&amp;lt;u&amp;gt;6&amp;lt;/u&amp;gt;]]&lt;br /&gt;
;incident&lt;br /&gt;
:An occurrence that actually or imminently jeopardizes, without lawful authority, the confidentiality, integrity, or availability of information or an information system; or constitutes a violation or imminent threat of violation of law, security policies, security procedures, or acceptable use policies. [[#bibr-ref_79|&amp;lt;u&amp;gt;79&amp;lt;/u&amp;gt;]]&lt;br /&gt;
;information&lt;br /&gt;
:Any communication or representation of knowledge such as facts, data, or opinions in any medium or form, including textual, numerical, graphic, cartographic, narrative, electronic, or audiovisual forms. [[#bibr-ref_13|&amp;lt;u&amp;gt;13&amp;lt;/u&amp;gt;]]&lt;br /&gt;
;information flow control&lt;br /&gt;
:Procedure to ensure that information transfers within a system do not violate the security policy.&lt;br /&gt;
;information resources&lt;br /&gt;
:Information and related resources, such as personnel, equipment, funds, and information technology. [[#bibr-ref_81|&amp;lt;u&amp;gt;81&amp;lt;/u&amp;gt;]]&lt;br /&gt;
;information security&lt;br /&gt;
:The protection of information and systems from unauthorized access, use, disclosure, disruption, modification, or destruction in order to provide confidentiality, integrity, and availability. [[#bibr-ref_79|&amp;lt;u&amp;gt;79&amp;lt;/u&amp;gt;]]&lt;br /&gt;
;information system&lt;br /&gt;
:A discrete set of information resources organized for the collection, processing, maintenance, use, sharing, dissemination, or disposition of information. [[#bibr-ref_81|&amp;lt;u&amp;gt;81&amp;lt;/u&amp;gt;]]&lt;br /&gt;
;information technology&lt;br /&gt;
:Any services, equipment, or interconnected system(s) or subsystem(s) of equipment, that are used in the automatic acquisition, storage, analysis, evaluation, manipulation, management, movement, control, display, switching, interchange, transmission, or reception of data or information by the agency. For purposes of this definition, such services or equipment if used by the agency directly or is used by a contractor under a contract with the agency that requires its use; or to a significant extent, its use in the performance of a service or the furnishing of a product. Information technology includes computers, ancillary equipment (including imaging peripherals, input, output, and storage devices necessary for security and surveillance), peripheral equipment designed to be controlled by the central processing unit of a computer, software, firmware and similar procedures, services (including cloud computing and help-desk services or other professional services which support any point of the life cycle of the equipment or service), and related resources. Information technology does not include any equipment that is acquired by a contractor incidental to a contract which does not require its use. [[#bibr-ref_13|&amp;lt;u&amp;gt;13&amp;lt;/u&amp;gt;]]&lt;br /&gt;
;insider threat&lt;br /&gt;
:The threat that an insider will use her/his authorized access, wittingly or unwittingly, to do harm to the security of the United States. This threat can include damage to the United States through espionage, terrorism, unauthorized disclosure, or through the loss or degradation of departmental resources or capabilities.&lt;br /&gt;
;integrity&lt;br /&gt;
:Guarding against improper information modification or destruction and includes ensuring information non-repudiation and authenticity. [[#bibr-ref_79|&amp;lt;u&amp;gt;79&amp;lt;/u&amp;gt;]]&lt;br /&gt;
;internal network&lt;br /&gt;
:A network in which the establishment, maintenance, and provisioning of security controls are under the direct control of organizational employees or contractors or in which the cryptographic encapsulation or similar security technology implemented between organization-controlled endpoints provides the same effect (with regard to confidentiality and integrity). An internal network is typically organization-owned yet may be organization-controlled while not being organization-owned.&lt;br /&gt;
;least privilege&lt;br /&gt;
:The principle that a security architecture is designed so that each entity is granted the minimum system authorizations and resources needed to perform its function.&lt;br /&gt;
;malicious code&lt;br /&gt;
:Software or firmware intended to perform an unauthorized process that will have an adverse impact on the confidentiality, integrity, or availability of a system. Examples of malicious code include viruses, worms, Trojan horses, spyware, some forms of adware, or other code-based entities that infect a host.&lt;br /&gt;
;media&lt;br /&gt;
:Physical devices or writing surfaces including, but not limited to, magnetic tapes, optical disks, magnetic disks, Large-Scale Integration (LSI) memory chips, and printouts (but not including display media) onto which information is recorded, stored, or printed within a system. [[#bibr-ref_7|&amp;lt;u&amp;gt;7&amp;lt;/u&amp;gt;]]&lt;br /&gt;
;mobile code&lt;br /&gt;
:Software programs or parts of programs obtained from remote systems, transmitted across a network, and executed on a local system without explicit installation or execution by the recipient.&lt;br /&gt;
;mobile device&lt;br /&gt;
:A portable computing device that has a small form factor such that it can easily be carried by a single individual; is designed to operate without a physical connection (e.g., wirelessly transmit or receive information); possesses local, non-removable, or removable data storage; and includes a self-contained power source. Mobile devices may also include voice communication capabilities, on-board sensors that allow the devices to capture information, or built-in features that synchronize local data with remote locations. Examples include smartphones, tablets, and e-readers.&lt;br /&gt;
;multi-factor authentication&lt;br /&gt;
:Authentication using two or more different factors to achieve authentication. Factors include something you know (e.g., PIN, password), something you have (e.g., cryptographic identification device, token), or something you are (e.g., biometric). See &#039;&#039;authenticator&#039;&#039;.&lt;br /&gt;
;network&lt;br /&gt;
:A system implemented with a collection of interconnected components. Such components may include routers, hubs, cabling, telecommunications controllers, key distribution centers, and technical control devices.&lt;br /&gt;
;network access&lt;br /&gt;
:Access to a system by a user (or a process acting on behalf of a user) communicating through a network (e.g., local area network, wide area network, the internet).&lt;br /&gt;
;nonfederal organization&lt;br /&gt;
:An entity that owns, operates, or maintains a nonfederal system.&lt;br /&gt;
;nonfederal system&lt;br /&gt;
:A system that does not meet the criteria for a federal system.&lt;br /&gt;
;nonlocal maintenance&lt;br /&gt;
:Maintenance activities conducted by individuals communicating through an external network (e.g., the internet) or an internal network.&lt;br /&gt;
;NSA-approved cryptography&lt;br /&gt;
:Cryptography that consists of an approved algorithm, an implementation that has been approved for the protection of classified information and/or controlled unclassified information in a specific environment, and a supporting key management infrastructure. [[#bibr-ref_8|&amp;lt;u&amp;gt;8&amp;lt;/u&amp;gt;]]&lt;br /&gt;
;on behalf of (an agency)&lt;br /&gt;
:A situation that occurs when: (i) a non-executive branch entity uses or operates an information system or maintains or collects information for the purpose of processing, storing, or transmitting Federal information; and (ii) those activities are not incidental to providing a service or product to the government. [[#bibr-ref_5|&amp;lt;u&amp;gt;5&amp;lt;/u&amp;gt;]]&lt;br /&gt;
;organization&lt;br /&gt;
:An entity of any size, complexity, or positioning within an organizational structure. [[#bibr-ref_7|&amp;lt;u&amp;gt;7, adapted&amp;lt;/u&amp;gt;]]&lt;br /&gt;
;organization-defined parameter&lt;br /&gt;
:The variable part of a security requirement that is instantiated by an organization during the tailoring process by assigning an organization-defined value as part of the requirement. [[#bibr-ref_8|&amp;lt;u&amp;gt;8, adapted&amp;lt;/u&amp;gt;]]&lt;br /&gt;
;overlay&lt;br /&gt;
:A specification of security or privacy controls, control enhancements, supplemental guidance, and other supporting information employed during the tailoring process, that is intended to complement (and further refine) security control baselines. The overlay specification may be more stringent or less stringent than the original security control baseline specification and can be applied to multiple information systems. [[#bibr-ref_13|&amp;lt;u&amp;gt;13&amp;lt;/u&amp;gt;]]&lt;br /&gt;
;personnel security&lt;br /&gt;
:The discipline of assessing the conduct, integrity, judgment, loyalty, reliability, and stability of individuals for duties and responsibilities requiring trustworthiness. [[#bibr-ref_8|&amp;lt;u&amp;gt;8&amp;lt;/u&amp;gt;]]&lt;br /&gt;
;portable storage device&lt;br /&gt;
:A system component that can be inserted into and removed from a system and that is used to store information or data (e.g., text, video, audio, and/or image data). Such components are typically implemented on magnetic, optical, or solid-state devices (e.g., compact/digital video disks, flash/thumb drives, external solid-state drives, external hard disk drives, flash memory cards/drives that contain nonvolatile memory).&lt;br /&gt;
;potential impact&lt;br /&gt;
:The loss of confidentiality, integrity, or availability could be expected to have: (i) a limited adverse effect (FIPS Publication 199 low); (ii) a serious adverse effect (FIPS Publication 199 moderate); or (iii) a severe or catastrophic adverse effect (FIPS Publication 199 high) on organizational operations, organizational assets, or individuals. [[#bibr-ref_6|6]]&lt;br /&gt;
;privileged account&lt;br /&gt;
:A system account with the authorizations of a privileged user.&lt;br /&gt;
;privileged user&lt;br /&gt;
:A user who is authorized (and therefore, trusted) to perform security-relevant functions that ordinary users are not authorized to perform.&lt;br /&gt;
;records&lt;br /&gt;
:The recordings (automated and/or manual) of evidence of activities performed or results achieved (e.g., forms, reports, test results) that serve as a basis for verifying that the organization and the system are performing as intended. Also used to refer to units of related data fields (i.e., groups of data fields that can be accessed by a program and that contain a complete set of information on particular items).&lt;br /&gt;
;remote access&lt;br /&gt;
:Access to an organizational system by a user (or a process acting on behalf of a user) communicating through an external network (e.g., the internet). Remote access methods include dial-up, broadband, and wireless.&lt;br /&gt;
;remote maintenance&lt;br /&gt;
:Maintenance activities conducted by individuals communicating through an external network (e.g., the internet).&lt;br /&gt;
;replay resistance&lt;br /&gt;
:Protection against the capture of transmitted authentication or access control information and its subsequent retransmission with the intent of producing an unauthorized effect or gaining unauthorized access.&lt;br /&gt;
;risk&lt;br /&gt;
:A measure of the extent to which an entity is threatened by a potential circumstance or event, and typically is a function of: (i) the adverse impact, or magnitude of harm, that would arise if the circumstance or event occurs; and (ii) the likelihood of occurrence. [[#bibr-ref_13|&amp;lt;u&amp;gt;13&amp;lt;/u&amp;gt;]]&lt;br /&gt;
;risk assessment&lt;br /&gt;
:The process of identifying risks to organizational operations (including mission, functions, image, reputation), organizational assets, individuals, other organizations, and the Nation, resulting from the operation of a system. [[#bibr-ref_55|&amp;lt;u&amp;gt;55&amp;lt;/u&amp;gt;]]&lt;br /&gt;
;sanitization&lt;br /&gt;
:Actions taken to render data written on media unrecoverable by ordinary and — for some forms of sanitization — extraordinary means.&lt;br /&gt;
:A process to remove information from media such that data recovery is not possible, including the removal of all classified labels, markings, and activity logs.&lt;br /&gt;
;security&lt;br /&gt;
:A condition that results from the establishment and maintenance of protective measures that enable an organization to perform its mission or critical functions despite risks posed by threats to its use of systems. Protective measures may involve a combination of deterrence, avoidance, prevention, detection, recovery, and correction that should form part of the organization’s risk management approach. [[#bibr-ref_78|&amp;lt;u&amp;gt;78&amp;lt;/u&amp;gt;]]&lt;br /&gt;
;security assessment&lt;br /&gt;
:See &#039;&#039;security control assessment&#039;&#039;.&lt;br /&gt;
;security control&lt;br /&gt;
:The safeguards or countermeasures prescribed for an information system or an organization to protect the confidentiality, integrity, and availability of the system and its information. [[#bibr-ref_13|&amp;lt;u&amp;gt;13&amp;lt;/u&amp;gt;]]&lt;br /&gt;
;security control assessment&lt;br /&gt;
:The testing or evaluation of security controls to determine the extent to which the controls are implemented correctly, operating as intended, and producing the desired outcome with respect to meeting the security requirements for an information system or organization. [[#bibr-ref_13|&amp;lt;u&amp;gt;13&amp;lt;/u&amp;gt;]]&lt;br /&gt;
;security domain&lt;br /&gt;
:A domain that implements a security policy and is administered by a single authority. [[#bibr-ref_78|&amp;lt;u&amp;gt;78, adapted&amp;lt;/u&amp;gt;]]&lt;br /&gt;
;security functions&lt;br /&gt;
:The hardware, software, or firmware of the system responsible for enforcing the system security policy and supporting the isolation of code and data on which the protection is based.&lt;br /&gt;
;security requirement&lt;br /&gt;
:A requirement levied on a system or an organization that is derived from applicable laws, Executive Orders, directives, regulations, policies, standards, procedures, or mission/business needs to ensure the confidentiality, integrity, and availability of information that is being processed, stored, or transmitted. [[#bibr-ref_7|&amp;lt;u&amp;gt;7, adapted&amp;lt;/u&amp;gt;]] [[#bibr-ref_8|&amp;lt;u&amp;gt;8, adapted&amp;lt;/u&amp;gt;]]&lt;br /&gt;
;system&lt;br /&gt;
:See &#039;&#039;information system&#039;&#039;.&lt;br /&gt;
;system component&lt;br /&gt;
:A discrete identifiable information technology asset that represents a building block of a system and may include hardware, software, and firmware. [[#bibr-ref_41|&amp;lt;u&amp;gt;41&amp;lt;/u&amp;gt;]]&lt;br /&gt;
;system security plan&lt;br /&gt;
:A document that describes how an organization meets or plans to meet the security requirements for a system. In particular, the system security plan describes the system boundary, the environment in which the system operates, how the security requirements are satisfied, and the relationships with or connections to other systems.&lt;br /&gt;
;system service&lt;br /&gt;
:A capability provided by a system that facilitates information processing, storage, or transmission.&lt;br /&gt;
;threat&lt;br /&gt;
:Any circumstance or event with the potential to adversely impact organizational operations, organizational assets, individuals, other organizations, or the Nation through a system via unauthorized access, destruction, disclosure, modification of information, and/or denial of service. [[#bibr-ref_55|&amp;lt;u&amp;gt;55&amp;lt;/u&amp;gt;]]&lt;br /&gt;
;system user&lt;br /&gt;
:An individual or (system) process acting on behalf of an individual that is authorized to access a system.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;d30e7632-Appendix_Title&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&amp;lt;span id=&amp;quot;sec-sec_C&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&lt;br /&gt;
== Appendix C : Tailoring Criteria ==&lt;br /&gt;
&lt;br /&gt;
This appendix describes the security control tailoring criteria used to develop the CUI security requirements. [[#table-tab_2|Table 2]] lists the available tailoring options and the shorthand tailoring symbols. [[#table-tab_3|Table 3]] through [[#table-tab_22|Table 22]] specify the tailoring actions applied to the controls in the SP 800-53 moderate baseline [[#bibr-ref_12|12]] to obtain the security requirements in Sec. 3. The controls and control enhancements are hyperlinked to the NIST [https://csrc.nist.gov/projects/cprt/catalog#/cprt/home Cybersecurity and Privacy Reference Tool], which provides online access to the specific control language and supplemental materials in SP 800-53.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;d30e7654&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;Table 2. Security Control Tailoring Criteria&lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
! &#039;&#039;&#039;TAILORING&#039;&#039;&#039;&amp;lt;br&amp;gt;&lt;br /&gt;
&#039;&#039;&#039;SYMBOL&#039;&#039;&#039;&lt;br /&gt;
! &#039;&#039;&#039;TAILORING CRITERIA&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| NCO&lt;br /&gt;
| The control is not directly related to protecting the confidentiality of CUI.&lt;br /&gt;
|-&lt;br /&gt;
| FED&lt;br /&gt;
| The control is primarily the responsibility of the Federal Government.&lt;br /&gt;
|-&lt;br /&gt;
| ORC&lt;br /&gt;
| The outcome of the control related to protecting the confidentiality of CUI is adequately covered by other related controls.&amp;lt;span id=&amp;quot;footnote-16-backlink&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;[[#footnote-16|16]]&amp;lt;br&amp;gt;&lt;br /&gt;
The security controls in SP 800-53 provide a comprehensive set of security capabilities needed to protect organizational systems and support the concept of defense in depth. Some of the security controls may address similar or overlapping security topics that are covered by other related controls. These controls have been designated as ORC in the tailoring criteria.&lt;br /&gt;
|-&lt;br /&gt;
| N/A&lt;br /&gt;
| The control is not applicable.&lt;br /&gt;
|-&lt;br /&gt;
| CUI&lt;br /&gt;
| The control is directly related to protecting the confidentiality of CUI.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;d30e7740&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;Table 3. [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=AC Access Control (AC)]&lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
! colspan=&amp;quot;2&amp;quot; | &#039;&#039;&#039;NIST SP 800-53 CONTROLS MODERATE BASELINE&#039;&#039;&#039;&lt;br /&gt;
! &#039;&#039;&#039;TAILORING&#039;&#039;&#039;&amp;lt;br&amp;gt;&lt;br /&gt;
&#039;&#039;&#039;CRITERIA&#039;&#039;&#039;&lt;br /&gt;
! &#039;&#039;&#039;SECURITY&#039;&#039;&#039;&amp;lt;br&amp;gt;&lt;br /&gt;
&#039;&#039;&#039;REQUIREMENT&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=AC-01 AC-01]&lt;br /&gt;
| Policy and Procedures&lt;br /&gt;
| CUI&lt;br /&gt;
| [[#sec-sec_03.15.01|03.15.01]]&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=AC-02 AC-02]&lt;br /&gt;
| Account Management&lt;br /&gt;
| CUI&lt;br /&gt;
| [[#sec-sec_03.01.01|03.01.01]]&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=AC-02 AC-02(01)]&lt;br /&gt;
| Account Management | Automated System Account Management&lt;br /&gt;
| NCO&lt;br /&gt;
| —&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=AC-02 AC-02(02)]&lt;br /&gt;
| Account Management | Automated Temporary and Emergency Account Management&lt;br /&gt;
| NCO&lt;br /&gt;
| —&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=AC-02 AC-02(03)]&lt;br /&gt;
| Account Management | Disable Accounts&lt;br /&gt;
| CUI&lt;br /&gt;
| [[#sec-sec_03.01.01|03.01.01]]&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=AC-02 AC-02(04)]&lt;br /&gt;
| Account Management | Automated Audit Actions&lt;br /&gt;
| NCO&lt;br /&gt;
| —&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=AC-02 AC-02(05)]&lt;br /&gt;
| Account Management | Inactivity Logout&lt;br /&gt;
| CUI&lt;br /&gt;
| [[#sec-sec_03.01.01|03.01.01]]&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=AC-02 AC-02(13)]&lt;br /&gt;
| Account Management | Disable Accounts for High-Risk Individuals&lt;br /&gt;
| CUI&lt;br /&gt;
| [[#sec-sec_03.01.01|03.01.01]]&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=AC-03 AC-03]&lt;br /&gt;
| Access Enforcement&lt;br /&gt;
| CUI&lt;br /&gt;
| [[#sec-sec_03.01.02|03.01.02]]&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=AC-04 AC-04]&lt;br /&gt;
| Information Flow Enforcement&lt;br /&gt;
| CUI&lt;br /&gt;
| [[#sec-sec_03.01.03|03.01.03]]&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=AC-05 AC-05]&lt;br /&gt;
| Separation of Duties&lt;br /&gt;
| CUI&lt;br /&gt;
| [[#sec-sec_03.01.04|03.01.04]]&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=AC-06 AC-06]&lt;br /&gt;
| Least Privilege&lt;br /&gt;
| CUI&lt;br /&gt;
| [[#sec-sec_03.01.05|03.01.05]]&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=AC-06 AC-06(01)]&lt;br /&gt;
| Least Privilege | Authorize Access to Security Functions&lt;br /&gt;
| CUI&lt;br /&gt;
| [[#sec-sec_03.01.05|03.01.05]]&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=AC-06 AC-06(02)]&lt;br /&gt;
| Least Privilege | Non-Privileged Access for Non-Security Functions&lt;br /&gt;
| CUI&lt;br /&gt;
| [[#sec-sec_03.01.06|03.01.06]]&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=AC-06 AC-06(05)]&lt;br /&gt;
| Least Privilege | Privileged Accounts&lt;br /&gt;
| CUI&lt;br /&gt;
| [[#sec-sec_03.01.06|03.01.06]]&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=AC-06 AC-06(07)]&lt;br /&gt;
| Least Privilege | Review of User Privileges&lt;br /&gt;
| CUI&lt;br /&gt;
| [[#sec-sec_03.01.05|03.01.05]]&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=AC-06 AC-06(09)]&lt;br /&gt;
| Least Privilege | Log Use of Privileged Functions&lt;br /&gt;
| CUI&lt;br /&gt;
| [[#sec-sec_03.01.07|03.01.07]]&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=AC-06 AC-06(10)]&lt;br /&gt;
| Least Privilege | Prohibit Non-Privileged Users From Executing Privileged Functions&lt;br /&gt;
| CUI&lt;br /&gt;
| [[#sec-sec_03.01.07|03.01.07]]&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=AC-07 AC-07]&lt;br /&gt;
| Unsuccessful Logon Attempts&lt;br /&gt;
| CUI&lt;br /&gt;
| [[#sec-sec_03.01.08|03.01.08]]&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=AC-08 AC-08]&lt;br /&gt;
| System Use Notification&lt;br /&gt;
| CUI&lt;br /&gt;
| [[#sec-sec_03.01.09|03.01.09]]&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=AC-11 AC-11]&lt;br /&gt;
| Device Lock&lt;br /&gt;
| CUI&lt;br /&gt;
| [[#sec-sec_03.01.10|03.01.10]]&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=AC-11 AC-11(01)]&lt;br /&gt;
| Device Lock | Pattern-Hiding Displays&lt;br /&gt;
| CUI&lt;br /&gt;
| [[#sec-sec_03.01.10|03.01.10]]&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=AC-12 AC-12]&lt;br /&gt;
| Session Termination&lt;br /&gt;
| CUI&lt;br /&gt;
| [[#sec-sec_03.01.11|03.01.11]]&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=AC-12 AC-14]&lt;br /&gt;
| Permitted Actions Without Identification or Authentication&lt;br /&gt;
| FED&lt;br /&gt;
| —&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=AC-17 AC-17]&lt;br /&gt;
| Remote Access&lt;br /&gt;
| CUI&lt;br /&gt;
| [[#sec-sec_03.01.02|03.01.02]]&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=AC-17 AC-17(01)]&lt;br /&gt;
| Remote Access | Monitoring and Control&lt;br /&gt;
| NCO&lt;br /&gt;
| —&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=AC-17 AC-17(02)]&lt;br /&gt;
| Remote Access | Protection of Confidentiality and Integrity Using Encryption&lt;br /&gt;
| CUI&lt;br /&gt;
| [[#sec-sec_03.13.08|03.13.08]]&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=AC-17 AC-17(03)]&lt;br /&gt;
| Remote Access | Managed Access Control Points&lt;br /&gt;
| CUI&lt;br /&gt;
| [[#sec-sec_03.01.12|03.01.12]]&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=AC-17 AC-17(04)]&lt;br /&gt;
| Remote Access | Privileged Commands and Access&lt;br /&gt;
| CUI&lt;br /&gt;
| [[#sec-sec_03.01.12|03.01.12]]&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=AC-18 AC-18]&lt;br /&gt;
| Wireless Access&lt;br /&gt;
| CUI&lt;br /&gt;
| [[#sec-sec_03.01.16|03.01.16]]&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=AC-18 AC-18(01)]&lt;br /&gt;
| Wireless Access | Authentication and Encryption&lt;br /&gt;
| CUI&lt;br /&gt;
| [[#sec-sec_03.01.16|03.01.16]]&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=AC-18 AC-18(03)]&lt;br /&gt;
| Wireless Access | Disable Wireless Networking&lt;br /&gt;
| CUI&lt;br /&gt;
| [[#sec-sec_03.01.16|03.01.16]]&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=AC-19 AC-19]&lt;br /&gt;
| Access Control for Mobile Devices&lt;br /&gt;
| CUI&lt;br /&gt;
| [[#sec-sec_03.01.18|03.01.18]]&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=AC-19 AC-19(05)]&lt;br /&gt;
| Access Control for Mobile Devices | Full Device or Container-Based Encryption&lt;br /&gt;
| CUI&lt;br /&gt;
| [[#sec-sec_03.01.18|03.01.18]]&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=AC-20 AC-20]&lt;br /&gt;
| Use of External Systems&lt;br /&gt;
| CUI&lt;br /&gt;
| [[#sec-sec_03.01.20|03.01.20]]&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=AC-20 AC-20(01)]&lt;br /&gt;
| Use of External Systems | Limits on Authorized Use&lt;br /&gt;
| CUI&lt;br /&gt;
| [[#sec-sec_03.01.20|03.01.20]]&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=AC-20 AC-20(02)]&lt;br /&gt;
| Use of External Systems | Portable Storage Devices – Restricted Use&lt;br /&gt;
| CUI&lt;br /&gt;
| [[#sec-sec_03.01.20|03.01.20]]&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=AC-21 AC-21]&lt;br /&gt;
| Information Sharing&lt;br /&gt;
| FED&lt;br /&gt;
| —&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=AC-22 AC-22]&lt;br /&gt;
| Publicly Accessible Content&lt;br /&gt;
| CUI&lt;br /&gt;
| [[#sec-sec_03.01.22|03.01.22]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;d30e8712&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;Table 4. [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=AT Awareness and Training (AT)]&lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
! colspan=&amp;quot;2&amp;quot; | &#039;&#039;&#039;NIST SP 800-53 CONTROLS MODERATE BASELINE&#039;&#039;&#039;&lt;br /&gt;
! &#039;&#039;&#039;TAILORING&#039;&#039;&#039;&amp;lt;br&amp;gt;&lt;br /&gt;
&#039;&#039;&#039;CRITERIA&#039;&#039;&#039;&lt;br /&gt;
! &#039;&#039;&#039;SECURITY&#039;&#039;&#039;&amp;lt;br&amp;gt;&lt;br /&gt;
&#039;&#039;&#039;REQUIREMENT&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=AT-01 AT-01]&lt;br /&gt;
| Policy and Procedures&lt;br /&gt;
| CUI&lt;br /&gt;
| [[#sec-sec_03.15.01|03.15.01]]&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=AT-02 AT-02]&lt;br /&gt;
| Literacy Training and Awareness&lt;br /&gt;
| CUI&lt;br /&gt;
| [[#sec-sec_03.02.01|03.02.01]]&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=AT-02 AT-02(02)]&lt;br /&gt;
| Literacy Training and Awareness | Insider Threat&lt;br /&gt;
| CUI&lt;br /&gt;
| [[#sec-sec_03.02.01|03.02.01]]&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=AT-02 AT-02(03)]&lt;br /&gt;
| Literacy Training and Awareness | Social Engineering and Mining&lt;br /&gt;
| CUI&lt;br /&gt;
| [[#sec-sec_03.02.01|03.02.01]]&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=AT-03 AT-03]&lt;br /&gt;
| Role-Based Training&lt;br /&gt;
| CUI&lt;br /&gt;
| [[#sec-sec_03.02.02|03.02.02]]&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=AT-04 AT-04]&lt;br /&gt;
| Training Records&lt;br /&gt;
| NCO&lt;br /&gt;
| —&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;d30e8893&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;Table 5. [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=AU Audit and Accountability (AU)]&lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
! colspan=&amp;quot;2&amp;quot; | &#039;&#039;&#039;NIST SP 800-53 CONTROLS MODERATE BASELINE&#039;&#039;&#039;&lt;br /&gt;
! &#039;&#039;&#039;TAILORING&#039;&#039;&#039;&amp;lt;br&amp;gt;&lt;br /&gt;
&#039;&#039;&#039;CRITERIA&#039;&#039;&#039;&lt;br /&gt;
! &#039;&#039;&#039;SECURITY&#039;&#039;&#039;&amp;lt;br&amp;gt;&lt;br /&gt;
&#039;&#039;&#039;REQUIREMENT&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=AU-01 AU-01]&lt;br /&gt;
| Policy and Procedures&lt;br /&gt;
| CUI&lt;br /&gt;
| [[#sec-sec_03.15.01|03.15.01]]&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=AU-02 AU-02]&lt;br /&gt;
| Event Logging&lt;br /&gt;
| CUI&lt;br /&gt;
| [[#sec-sec_03.03.01|03.03.01]]&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=AU-03 AU-03]&lt;br /&gt;
| Content of Audit Records&lt;br /&gt;
| CUI&lt;br /&gt;
| [[#sec-sec_03.03.02|03.03.02]]&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=AU-03 AU-03(01)]&lt;br /&gt;
| Additional Audit Information&lt;br /&gt;
| CUI&lt;br /&gt;
| [[#sec-sec_03.03.02|03.03.02]]&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=AU-04 AU-04]&lt;br /&gt;
| Audit Log Storage Capacity&lt;br /&gt;
| NCO&lt;br /&gt;
| —&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=AU-05 AU-05]&lt;br /&gt;
| Response to Audit Logging Process Failures&lt;br /&gt;
| CUI&lt;br /&gt;
| [[#sec-sec_03.03.04|03.03.04]]&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=AU-06 AU-06]&lt;br /&gt;
| Audit Record Review, Analysis, and Reporting&lt;br /&gt;
| CUI&lt;br /&gt;
| [[#sec-sec_03.03.05|03.03.05]]&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=AU-06 AU-06(01)]&lt;br /&gt;
| Audit Record Review, Analysis, and Reporting | Automated Process Integration&lt;br /&gt;
| NCO&lt;br /&gt;
| —&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=AU-06 AU-06(03)]&lt;br /&gt;
| Audit Record Review, Analysis, and Reporting | Correlate Audit Record Repositories&lt;br /&gt;
| CUI&lt;br /&gt;
| [[#sec-sec_03.03.05|03.03.05]]&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=AU-07 AU-07]&lt;br /&gt;
| Audit Record Reduction and Report Generation&lt;br /&gt;
| CUI&lt;br /&gt;
| [[#sec-sec_03.03.06|03.03.06]]&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=AU-07 AU-07(01)]&lt;br /&gt;
| Audit Record Reduction and Report Generation | Automatic Processing&lt;br /&gt;
| NCO&lt;br /&gt;
| —&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=AU-08 AU-08]&lt;br /&gt;
| Time Stamps&lt;br /&gt;
| CUI&lt;br /&gt;
| [[#sec-sec_03.03.07|03.03.07]]&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=AU-09 AU-09]&lt;br /&gt;
| Protection of Audit Information&lt;br /&gt;
| CUI&lt;br /&gt;
| [[#sec-sec_03.03.08|03.03.08]]&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=AU-09 AU-09(04)]&lt;br /&gt;
| Protection of Audit Information | Access by Subset of Privileged Users&lt;br /&gt;
| CUI&lt;br /&gt;
| [[#sec-sec_03.03.08|03.03.08]]&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=AU-11 AU-11]&lt;br /&gt;
| Audit Record Retention&lt;br /&gt;
| CUI&lt;br /&gt;
| [[#sec-sec_03.03.03|03.03.03]]&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=AU-12 AU-12]&lt;br /&gt;
| Audit Record Generation&lt;br /&gt;
| CUI&lt;br /&gt;
| [[#sec-sec_03.03.03|03.03.03]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;d30e9313&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;Table 6. [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=CA Assessment, Authorization, and Monitoring (CA)]&lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
! colspan=&amp;quot;2&amp;quot; | &#039;&#039;&#039;NIST SP 800-53 CONTROLS MODERATE BASELINE&#039;&#039;&#039;&lt;br /&gt;
! &#039;&#039;&#039;TAILORING&#039;&#039;&#039;&amp;lt;br&amp;gt;&lt;br /&gt;
&#039;&#039;&#039;CRITERIA&#039;&#039;&#039;&lt;br /&gt;
! &#039;&#039;&#039;SECURITY&#039;&#039;&#039;&amp;lt;br&amp;gt;&lt;br /&gt;
&#039;&#039;&#039;REQUIREMENT&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=CA-01 CA-01]&lt;br /&gt;
| Policy and Procedures&lt;br /&gt;
| CUI&lt;br /&gt;
| [[#sec-sec_03.15.01|03.15.01]]&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=CA-02 CA-02]&lt;br /&gt;
| Control Assessments&lt;br /&gt;
| CUI&lt;br /&gt;
| [[#sec-sec_03.12.01|03.12.01]]&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=CA-02 CA-02(01)]&lt;br /&gt;
| Control Assessments | Independent Assessors&lt;br /&gt;
| NCO&lt;br /&gt;
| —&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=CA-03 CA-03]&lt;br /&gt;
| Information Exchange&lt;br /&gt;
| CUI&lt;br /&gt;
| [[#sec-sec_03.12.05|03.12.05]]&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=CA-05 CA-05]&lt;br /&gt;
| Plan of Action and Milestones&lt;br /&gt;
| CUI&lt;br /&gt;
| [[#sec-sec_03.12.02|03.12.02]]&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=CA-06 CA-06]&lt;br /&gt;
| Authorization&lt;br /&gt;
| FED&lt;br /&gt;
| —&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=CA-07 CA-07]&lt;br /&gt;
| Continuous Monitoring&lt;br /&gt;
| CUI&lt;br /&gt;
| [[#sec-sec_03.12.03|03.12.03]]&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=CA-07 CA-07(01)]&lt;br /&gt;
| Continuous Monitoring | Independent Assessment&lt;br /&gt;
| NCO&lt;br /&gt;
| —&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=CA-07 CA-07(04)]&lt;br /&gt;
| Continuous Monitoring | Risk Monitoring&lt;br /&gt;
| NCO&lt;br /&gt;
| —&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=CA-09 CA-09]&lt;br /&gt;
| Internal System Connections&lt;br /&gt;
| NCO&lt;br /&gt;
| —&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;d30e9586&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;Table 7. [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=CM Configuration Management (CM)]&lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
! colspan=&amp;quot;2&amp;quot; | &#039;&#039;&#039;NIST SP 800-53 CONTROLS MODERATE BASELINE&#039;&#039;&#039;&lt;br /&gt;
! &#039;&#039;&#039;TAILORING&#039;&#039;&#039;&amp;lt;br&amp;gt;&lt;br /&gt;
&#039;&#039;&#039;CRITERIA&#039;&#039;&#039;&lt;br /&gt;
! &#039;&#039;&#039;SECURITY&#039;&#039;&#039;&amp;lt;br&amp;gt;&lt;br /&gt;
&#039;&#039;&#039;REQUIREMENT&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=CM-01 CM-01]&lt;br /&gt;
| Policy and Procedures&lt;br /&gt;
| CUI&lt;br /&gt;
| [[#sec-sec_03.15.01|03.15.01]]&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=CM-02 CM-02]&lt;br /&gt;
| Baseline Configuration&lt;br /&gt;
| CUI&lt;br /&gt;
| [[#sec-sec_03.04.01|03.04.01]]&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=CM-02 CM-02(02)]&lt;br /&gt;
| Baseline Configuration | Automation Support for Accuracy and Currency&lt;br /&gt;
| NCO&lt;br /&gt;
| —&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=CM-02 CM-02(03)]&lt;br /&gt;
| Baseline Configuration | Retention of Previous Configurations&lt;br /&gt;
| NCO&lt;br /&gt;
| —&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=CM-02 CM-02(07)]&lt;br /&gt;
| Baseline Configuration | Configure Systems and Components for High-Risk Areas&lt;br /&gt;
| CUI&lt;br /&gt;
| [[#sec-sec_03.04.12|03.04.12]]&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=CM-03 CM-03]&lt;br /&gt;
| Configuration Change Control&lt;br /&gt;
| CUI&lt;br /&gt;
| [[#sec-sec_03.04.03|03.04.03]]&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=CM-03 CM-03(02)]&lt;br /&gt;
| Configuration Change Control | Testing, Validation, and Documentation of Changes&lt;br /&gt;
| NCO&lt;br /&gt;
| —&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=CM-03 CM-03(04)]&lt;br /&gt;
| Configuration Change Control | Security and Privacy Representatives&lt;br /&gt;
| NCO&lt;br /&gt;
| —&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=CM-04 CM-04]&lt;br /&gt;
| Impact Analyses&lt;br /&gt;
| CUI&lt;br /&gt;
| [[#sec-sec_03.04.04|03.04.04]]&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=CM-04 CM-04(02)]&lt;br /&gt;
| Impact Analyses | Verification of Controls&lt;br /&gt;
| CUI&lt;br /&gt;
| [[#sec-sec_03.04.04|03.04.04]]&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=CM-05 CM-05]&lt;br /&gt;
| Access Restrictions for Change&lt;br /&gt;
| CUI&lt;br /&gt;
| [[#sec-sec_03.04.05|03.04.05]]&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=CM-06 CM-06]&lt;br /&gt;
| Configuration Settings&lt;br /&gt;
| CUI&lt;br /&gt;
| [[#sec-sec_03.04.02|03.04.02]]&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=CM-07 CM-07]&lt;br /&gt;
| Least Functionality&lt;br /&gt;
| CUI&lt;br /&gt;
| [[#sec-sec_03.04.06|03.04.06]]&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=CM-07 CM-07(01)]&lt;br /&gt;
| Least Functionality | Periodic Review&lt;br /&gt;
| CUI&lt;br /&gt;
| [[#sec-sec_03.04.06|03.04.06]]&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=CM-07 CM-07(02)]&lt;br /&gt;
| Least Functionality | Prevent Program Execution&lt;br /&gt;
| ORC&lt;br /&gt;
| —&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=CM-07 CM-07(05)]&lt;br /&gt;
| Least Functionality | Authorized Software – Allow by Exception&lt;br /&gt;
| CUI&lt;br /&gt;
| [[#sec-sec_03.04.08|03.04.08]]&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=CM-08 CM-08]&lt;br /&gt;
| System Component Inventory&lt;br /&gt;
| CUI&lt;br /&gt;
| [[#sec-sec_03.04.10|03.04.10]]&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=CM-08 CM-08(01)]&lt;br /&gt;
| System Component Inventory | Updates During Installation and Removal&lt;br /&gt;
| CUI&lt;br /&gt;
| [[#sec-sec_03.04.10|03.04.10]]&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=CM-08 CM-08(03)]&lt;br /&gt;
| System Component Inventory | Automated Unauthorized Component Detection&lt;br /&gt;
| NCO&lt;br /&gt;
| —&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=CM-09 CM-09]&lt;br /&gt;
| Configuration Management Plan&lt;br /&gt;
| NCO&lt;br /&gt;
| —&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=CM-10 CM-10]&lt;br /&gt;
| Software Usage Restrictions&lt;br /&gt;
| NCO&lt;br /&gt;
| —&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=CM-11 CM-11]&lt;br /&gt;
| User-Installed Software&lt;br /&gt;
| ORC&lt;br /&gt;
| —&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=CM-12 CM-12]&lt;br /&gt;
| Information Location&lt;br /&gt;
| CUI&lt;br /&gt;
| [[#sec-sec_03.04.11|03.04.11]]&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=CM-12 CM-12(01)]&lt;br /&gt;
| Information Location | Automated Tools to Support Information Location&lt;br /&gt;
| NCO&lt;br /&gt;
| —&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;d30e10193&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;Table 8. [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=CP Contingency Planning (CP)]&lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
! colspan=&amp;quot;2&amp;quot; | &#039;&#039;&#039;NIST SP 800-53 CONTROLS MODERATE BASELINE&#039;&#039;&#039;&lt;br /&gt;
! &#039;&#039;&#039;TAILORING&#039;&#039;&#039;&amp;lt;br&amp;gt;&lt;br /&gt;
&#039;&#039;&#039;CRITERIA&#039;&#039;&#039;&lt;br /&gt;
! &#039;&#039;&#039;SECURITY&#039;&#039;&#039;&amp;lt;br&amp;gt;&lt;br /&gt;
&#039;&#039;&#039;REQUIREMENT&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=CP-01 CP-01]&lt;br /&gt;
| Policy and Procedures&lt;br /&gt;
| NCO&lt;br /&gt;
| —&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=CP-02 CP-02]&lt;br /&gt;
| Contingency Plan&lt;br /&gt;
| NCO&lt;br /&gt;
| —&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=CP-02 CP-02(01)]&lt;br /&gt;
| Contingency Plan | Coordinate With Related Plans&lt;br /&gt;
| NCO&lt;br /&gt;
| —&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=CP-02 CP-02(03)]&lt;br /&gt;
| Contingency Plan | Resume Mission and Business Functions&lt;br /&gt;
| NCO&lt;br /&gt;
| —&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=CP-02 CP-02(08)]&lt;br /&gt;
| Contingency Plan | Identify Critical Assets&lt;br /&gt;
| NCO&lt;br /&gt;
| —&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=CP-03 CP-03]&lt;br /&gt;
| Contingency Training&lt;br /&gt;
| NCO&lt;br /&gt;
| —&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=CP-04 CP-04]&lt;br /&gt;
| Contingency Plan Testing&lt;br /&gt;
| NCO&lt;br /&gt;
| —&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=CP-04 CP-04(01)]&lt;br /&gt;
| Contingency Plan Testing | Coordinate Related Plans&lt;br /&gt;
| NCO&lt;br /&gt;
| —&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=CP-06 CP-06]&lt;br /&gt;
| Alternate Storage Site&lt;br /&gt;
| NCO&lt;br /&gt;
| —&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=CP-06 CP-06(01)]&lt;br /&gt;
| Alternate Storage Site | Separation of Primary Site&lt;br /&gt;
| NCO&lt;br /&gt;
| —&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=CP-06 CP-06(03)]&lt;br /&gt;
| Alternate Storage Site | Accessibility&lt;br /&gt;
| NCO&lt;br /&gt;
| —&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=CP-07 CP-07]&lt;br /&gt;
| Alternate Processing Site&lt;br /&gt;
| NCO&lt;br /&gt;
| —&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=CP-07 CP-07(01)]&lt;br /&gt;
| Alternate Processing Site | Separation of Primary Site&lt;br /&gt;
| NCO&lt;br /&gt;
| —&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=CP-07 CP-07(02)]&lt;br /&gt;
| Alternate Processing Site | Accessibility&lt;br /&gt;
| NCO&lt;br /&gt;
| —&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=CP-07 CP-07(03)]&lt;br /&gt;
| Alternate Processing Site | Priority of Service&lt;br /&gt;
| NCO&lt;br /&gt;
| —&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=CP-08 CP-08]&lt;br /&gt;
| Telecommunications Services&lt;br /&gt;
| NCO&lt;br /&gt;
| —&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=CP-08 CP-08(01)]&lt;br /&gt;
| Telecommunications Services | Priority of Service Provisions&lt;br /&gt;
| NCO&lt;br /&gt;
| —&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=CP-08 CP-08(02)]&lt;br /&gt;
| Telecommunications Services | Single Points of Failure&lt;br /&gt;
| NCO&lt;br /&gt;
| —&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=CP-09 CP-09]&lt;br /&gt;
| System Backup&lt;br /&gt;
| CUI&lt;br /&gt;
| [[#sec-sec_03.08.09|03.08.09]]&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=CP-09 CP-09(01)]&lt;br /&gt;
| System Backup | Testing for Reliability and Integrity&lt;br /&gt;
| NCO&lt;br /&gt;
| —&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=CP-09 CP-09(08)]&lt;br /&gt;
| System Backup | Cryptographic Protection&lt;br /&gt;
| CUI&lt;br /&gt;
| [[#sec-sec_03.08.09|03.08.09]]&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=CP-10 CP-10]&lt;br /&gt;
| System Recovery and Reconstitution&lt;br /&gt;
| NCO&lt;br /&gt;
| —&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=CP-10 CP-10(02)]&lt;br /&gt;
| System Recovery and Reconstitution | Transaction Recovery&lt;br /&gt;
| NCO&lt;br /&gt;
| —&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;d30e10764&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;Table 9. [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=IA Identification and Authentication (IA)]&lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
! colspan=&amp;quot;2&amp;quot; | &#039;&#039;&#039;NIST SP 800-53 CONTROLS MODERATE BASELINE&#039;&#039;&#039;&lt;br /&gt;
! &#039;&#039;&#039;TAILORING&#039;&#039;&#039;&amp;lt;br&amp;gt;&lt;br /&gt;
&#039;&#039;&#039;CRITERIA&#039;&#039;&#039;&lt;br /&gt;
! &#039;&#039;&#039;SECURITY&#039;&#039;&#039;&amp;lt;br&amp;gt;&lt;br /&gt;
&#039;&#039;&#039;REQUIREMENT&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=IA-01 IA-01]&lt;br /&gt;
| Policy and Procedures&lt;br /&gt;
| CUI&lt;br /&gt;
| [[#sec-sec_03.15.01|03.15.01]]&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=IA-02 IA-02]&lt;br /&gt;
| Identification and Authentication (Organizational Users)&lt;br /&gt;
| CUI&lt;br /&gt;
| [[#sec-sec_03.05.01|03.05.01]]&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=IA-02 IA-02(01)]&lt;br /&gt;
| Identification and Authentication (Organizational Users) | Multi-Factor Authentication to Privileged Accounts&lt;br /&gt;
| CUI&lt;br /&gt;
| [[#sec-sec_03.05.03|03.05.03]]&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=IA-02 IA-02(02)]&lt;br /&gt;
| Identification and Authentication (Organizational Users) | Multi-Factor Authentication to Non-Privileged Accounts&lt;br /&gt;
| CUI&lt;br /&gt;
| [[#sec-sec_03.05.03|03.05.03]]&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=IA-02 IA-02(08)]&lt;br /&gt;
| Identification and Authentication (Organizational Users) | Access to Accounts – Replay Resistant&lt;br /&gt;
| CUI&lt;br /&gt;
| [[#sec-sec_03.05.04|03.05.04]]&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=IA-02 IA-02(12)]&lt;br /&gt;
| Identification and Authentication (Organizational Users) | Acceptance of PIV Credentials&lt;br /&gt;
| FED&lt;br /&gt;
| —&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=IA-03 IA-03]&lt;br /&gt;
| Device Identification and Authentication&lt;br /&gt;
| CUI&lt;br /&gt;
| [[#sec-sec_03.05.02|03.05.02]]&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=IA-04 IA-04]&lt;br /&gt;
| Identifier Management&lt;br /&gt;
| CUI&lt;br /&gt;
| [[#sec-sec_03.05.05|03.05.05]]&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=IA-04 IA-04(04)]&lt;br /&gt;
| Identifier Management | Identify User Status&lt;br /&gt;
| CUI&lt;br /&gt;
| [[#sec-sec_03.05.05|03.05.05]]&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=IA-05 IA-05]&lt;br /&gt;
| Authenticator Management&lt;br /&gt;
| CUI&lt;br /&gt;
| [[#sec-sec_03.05.12|03.05.12]]&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=IA-05 IA-05(01)]&lt;br /&gt;
| Authenticator Management | Password-Based Authentication&lt;br /&gt;
| CUI&lt;br /&gt;
| [[#sec-sec_03.05.07|03.05.07]]&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=IA-05 IA-05(02)]&lt;br /&gt;
| Authenticator Management | Public Key-Based Authentication&lt;br /&gt;
| FED&lt;br /&gt;
| —&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=IA-05 IA-05(06)]&lt;br /&gt;
| Authenticator Management | Protection of Authenticators&lt;br /&gt;
| FED&lt;br /&gt;
| —&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=IA-06 IA-06]&lt;br /&gt;
| Authentication Feedback&lt;br /&gt;
| CUI&lt;br /&gt;
| [[#sec-sec_03.05.11|03.05.11]]&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=IA-07 IA-07]&lt;br /&gt;
| Cryptographic Module Authentication&lt;br /&gt;
| FED&lt;br /&gt;
| —&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=IA-08 IA-08]&lt;br /&gt;
| Identification and Authentication (Non-Organizational Users)&lt;br /&gt;
| FED&lt;br /&gt;
| —&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=IA-08 IA-08(01)]&lt;br /&gt;
| Identification and Authentication (Non-Organizational Users) | Acceptance of PIV Credentials From Other Agencies&lt;br /&gt;
| FED&lt;br /&gt;
| —&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=IA-08 IA-08(02)]&lt;br /&gt;
| Identification and Authentication (Non-Organizational Users) | Acceptance of External Authenticators&lt;br /&gt;
| FED&lt;br /&gt;
| —&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=IA-08 IA-08(04)]&lt;br /&gt;
| Identification and Authentication (Non-Organizational Users) | Use of Defined Profiles&lt;br /&gt;
| FED&lt;br /&gt;
| —&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=IA-11 IA-11]&lt;br /&gt;
| Re-Authentication&lt;br /&gt;
| CUI&lt;br /&gt;
| [[#sec-sec_03.05.01|03.05.01]]&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=IA-12 IA-12]&lt;br /&gt;
| Identity Proofing&lt;br /&gt;
| FED&lt;br /&gt;
| —&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=IA-12 IA-12(02)]&lt;br /&gt;
| Identity Proofing | Identity Evidence&lt;br /&gt;
| FED&lt;br /&gt;
| —&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=IA-12 IA-12(03)]&lt;br /&gt;
| Identity Proofing | Identity Evidence Validation and Verification&lt;br /&gt;
| FED&lt;br /&gt;
| —&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=IA-12 IA-12(05)]&lt;br /&gt;
| Identity Proofing | Address Confirmation&lt;br /&gt;
| FED&lt;br /&gt;
| —&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;d30e11368&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;Table 10. [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=IR Incident Response (IR)]&lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
! colspan=&amp;quot;2&amp;quot; | &#039;&#039;&#039;NIST SP 800-53 CONTROLS MODERATE BASELINE&#039;&#039;&#039;&lt;br /&gt;
! &#039;&#039;&#039;TAILORING&#039;&#039;&#039;&amp;lt;br&amp;gt;&lt;br /&gt;
&#039;&#039;&#039;CRITERIA&#039;&#039;&#039;&lt;br /&gt;
! &#039;&#039;&#039;SECURITY&#039;&#039;&#039;&amp;lt;br&amp;gt;&lt;br /&gt;
&#039;&#039;&#039;REQUIREMENT&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=IR-01 IR-01]&lt;br /&gt;
| Policy and Procedures&lt;br /&gt;
| CUI&lt;br /&gt;
| [[#sec-sec_03.15.01|03.15.01]]&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=IR-02 IR-02]&lt;br /&gt;
| Incident Response Training&lt;br /&gt;
| CUI&lt;br /&gt;
| [[#sec-sec_03.06.04|03.06.04]]&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=IR-03 IR-03]&lt;br /&gt;
| Incident Response Testing&lt;br /&gt;
| CUI&lt;br /&gt;
| [[#sec-sec_03.06.03|03.06.03]]&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=IR-03 IR-03(02)]&lt;br /&gt;
| Incident Response Testing | Coordinate With Related Plans&lt;br /&gt;
| NCO&lt;br /&gt;
| —&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=IR-04 IR-04]&lt;br /&gt;
| Incident Handling&lt;br /&gt;
| CUI&lt;br /&gt;
| [[#sec-sec_03.06.01|03.06.01]]&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=IR-04 IR-04(01)]&lt;br /&gt;
| Incident Handling | Automated Incident Handling Processes&lt;br /&gt;
| NCO&lt;br /&gt;
| —&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=IR-05 IR-05]&lt;br /&gt;
| Incident Monitoring&lt;br /&gt;
| CUI&lt;br /&gt;
| [[#sec-sec_03.06.02|03.06.02]]&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=IR-06 IR-06]&lt;br /&gt;
| Incident Reporting&lt;br /&gt;
| CUI&lt;br /&gt;
| [[#sec-sec_03.06.02|03.06.02]]&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=IR-06 IR-06(01)]&lt;br /&gt;
| Incident Reporting | Automated Reporting&lt;br /&gt;
| NCO&lt;br /&gt;
| —&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=IR-06 IR-06(03)]&lt;br /&gt;
| Incident Reporting | Supply Chain Coordination&lt;br /&gt;
| NCO&lt;br /&gt;
| —&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=IR-07 IR-07]&lt;br /&gt;
| Incident Response Assistance&lt;br /&gt;
| CUI&lt;br /&gt;
| [[#sec-sec_03.06.02|03.06.02]]&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=IR-07 IR-07(01)]&lt;br /&gt;
| Incident Response Assistance | Automation Support for Availability of Information and Support&lt;br /&gt;
| NCO&lt;br /&gt;
| —&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=IR-08 IR-08]&lt;br /&gt;
| Incident Response Plan&lt;br /&gt;
| CUI&lt;br /&gt;
| [[#sec-sec_03.06.05|03.06.05]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;d30e11714&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;Table 11. [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=MA Maintenance (MA)]&lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
! colspan=&amp;quot;2&amp;quot; | &#039;&#039;&#039;NIST SP 800-53 CONTROLS MODERATE BASELINE&#039;&#039;&#039;&lt;br /&gt;
! &#039;&#039;&#039;TAILORING&#039;&#039;&#039;&amp;lt;br&amp;gt;&lt;br /&gt;
&#039;&#039;&#039;CRITERIA&#039;&#039;&#039;&lt;br /&gt;
! &#039;&#039;&#039;SECURITY&#039;&#039;&#039;&amp;lt;br&amp;gt;&lt;br /&gt;
&#039;&#039;&#039;REQUIREMENT&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=MA-01 MA-01]&lt;br /&gt;
| System Maintenance Policy and Procedures&lt;br /&gt;
| CUI&lt;br /&gt;
| [[#sec-sec_03.15.01|03.15.01]]&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=MA-02 MA-02]&lt;br /&gt;
| Controlled Maintenance&lt;br /&gt;
| NCO&lt;br /&gt;
| —&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=MA-03 MA-03]&lt;br /&gt;
| Maintenance Tools&lt;br /&gt;
| CUI&lt;br /&gt;
| [[#sec-sec_03.07.04|03.07.04]]&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=MA-03 MA-03(01)]&lt;br /&gt;
| Maintenance Tools | Inspect Tools&lt;br /&gt;
| CUI&lt;br /&gt;
| [[#sec-sec_03.07.04|03.07.04]]&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=MA-03 MA-03(02)]&lt;br /&gt;
| Maintenance Tools | Inspect Media&lt;br /&gt;
| CUI&lt;br /&gt;
| [[#sec-sec_03.07.04|03.07.04]]&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=MA-03 MA-03(03)]&lt;br /&gt;
| Maintenance Tools | Prevent Unauthorized Removal&lt;br /&gt;
| CUI&lt;br /&gt;
| [[#sec-sec_03.07.04|03.07.04]]&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=MA-04 MA-04]&lt;br /&gt;
| Nonlocal Maintenance&lt;br /&gt;
| CUI&lt;br /&gt;
| [[#sec-sec_03.07.05|03.07.05]]&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=MA-05 MA-05]&lt;br /&gt;
| Maintenance Personnel&lt;br /&gt;
| CUI&lt;br /&gt;
| [[#sec-sec_03.07.06|03.07.06]]&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=MA-06 MA-06]&lt;br /&gt;
| Timely Maintenance&lt;br /&gt;
| NCO&lt;br /&gt;
| —&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;d30e11966&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;Table 12. [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=MP Media Protection (MP)]&lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
! colspan=&amp;quot;2&amp;quot; | &#039;&#039;&#039;NIST SP 800-53 CONTROLS MODERATE BASELINE&#039;&#039;&#039;&lt;br /&gt;
! &#039;&#039;&#039;TAILORING&#039;&#039;&#039;&amp;lt;br&amp;gt;&lt;br /&gt;
&#039;&#039;&#039;CRITERIA&#039;&#039;&#039;&lt;br /&gt;
! &#039;&#039;&#039;SECURITY&#039;&#039;&#039;&amp;lt;br&amp;gt;&lt;br /&gt;
&#039;&#039;&#039;REQUIREMENT&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=MP-01 MP-01]&lt;br /&gt;
| Policy and Procedures&lt;br /&gt;
| CUI&lt;br /&gt;
| [[#sec-sec_03.15.01|03.15.01]]&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=MP-02 MP-02]&lt;br /&gt;
| Media Access&lt;br /&gt;
| CUI&lt;br /&gt;
| [[#sec-sec_03.08.02|03.08.02]]&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=MP-03 MP-03]&lt;br /&gt;
| Media Marking&lt;br /&gt;
| CUI&lt;br /&gt;
| [[#sec-sec_03.08.04|03.08.04]]&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=MP-04 MP-04]&lt;br /&gt;
| Media Storage&lt;br /&gt;
| CUI&lt;br /&gt;
| [[#sec-sec_03.08.01|03.08.01]]&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=MP-05 MP-05]&lt;br /&gt;
| Media Transport&lt;br /&gt;
| CUI&lt;br /&gt;
| [[#sec-sec_03.08.05|03.08.05]]&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=MP-06 MP-06]&lt;br /&gt;
| Media Sanitization&lt;br /&gt;
| CUI&lt;br /&gt;
| [[#sec-sec_03.08.03|03.08.03]]&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=MP-07 MP-07]&lt;br /&gt;
| Media Use&lt;br /&gt;
| CUI&lt;br /&gt;
| [[#sec-sec_03.08.07|03.08.07]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;d30e12173&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;Table 13. [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=PE Physical and Environmental Protection (PE)]&lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
! colspan=&amp;quot;2&amp;quot; | &#039;&#039;&#039;NIST SP 800-53 CONTROLS MODERATE BASELINE&#039;&#039;&#039;&lt;br /&gt;
! &#039;&#039;&#039;TAILORING&#039;&#039;&#039;&amp;lt;br&amp;gt;&lt;br /&gt;
&#039;&#039;&#039;CRITERIA&#039;&#039;&#039;&lt;br /&gt;
! &#039;&#039;&#039;SECURITY&#039;&#039;&#039;&amp;lt;br&amp;gt;&lt;br /&gt;
&#039;&#039;&#039;REQUIREMENT&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=PE-01 PE-01]&lt;br /&gt;
| Policy and Procedures&lt;br /&gt;
| CUI&lt;br /&gt;
| [[#sec-sec_03.15.01|03.15.01]]&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=PE-02 PE-02]&lt;br /&gt;
| Physical Access Authorizations&lt;br /&gt;
| CUI&lt;br /&gt;
| [[#sec-sec_03.10.01|03.10.01]]&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=PE-03 PE-03]&lt;br /&gt;
| Physical Access Control&lt;br /&gt;
| CUI&lt;br /&gt;
| [[#sec-sec_03.10.07|03.10.07]]&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=PE-04 PE-04]&lt;br /&gt;
| Access Control for Transmission&lt;br /&gt;
| CUI&lt;br /&gt;
| [[#sec-sec_03.10.08|03.10.08]]&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=PE-05 PE-05]&lt;br /&gt;
| Access Control for Output Devices&lt;br /&gt;
| CUI&lt;br /&gt;
| [[#sec-sec_03.10.07|03.10.07]]&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=PE-06 PE-06]&lt;br /&gt;
| Monitoring Physical Access&lt;br /&gt;
| CUI&lt;br /&gt;
| [[#sec-sec_03.10.02|03.10.02]]&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=PE-06 PE-06(01)]&lt;br /&gt;
| Monitoring Physical Access | Intrusion Alarms and Surveillance Equipment&lt;br /&gt;
| NCO&lt;br /&gt;
| —&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=PE-08 PE-08]&lt;br /&gt;
| Visitor Access Records&lt;br /&gt;
| NCO&lt;br /&gt;
| —&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=PE-09 PE-09]&lt;br /&gt;
| Power Equipment and Cabling&lt;br /&gt;
| NCO&lt;br /&gt;
| —&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=PE-10 PE-10]&lt;br /&gt;
| Emergency Shutoff&lt;br /&gt;
| NCO&lt;br /&gt;
| —&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=PE-11 PE-11]&lt;br /&gt;
| Emergency Power&lt;br /&gt;
| NCO&lt;br /&gt;
| —&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=PE-12 PE-12]&lt;br /&gt;
| Emergency Lighting&lt;br /&gt;
| NCO&lt;br /&gt;
| —&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=PE-13 PE-13]&lt;br /&gt;
| Fire Protection&lt;br /&gt;
| NCO&lt;br /&gt;
| —&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=PE-13 PE-13(01)]&lt;br /&gt;
| Fire Protection | Detection Systems – Automatic Activation and Notification&lt;br /&gt;
| NCO&lt;br /&gt;
| —&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=PE-14 PE-14]&lt;br /&gt;
| Environmental Controls&lt;br /&gt;
| NCO&lt;br /&gt;
| —&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=PE-15 PE-15]&lt;br /&gt;
| Water Damage Protection&lt;br /&gt;
| NCO&lt;br /&gt;
| —&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=PE-16 PE-16]&lt;br /&gt;
| Delivery and Removal&lt;br /&gt;
| NCO&lt;br /&gt;
| —&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=PE-17 PE-17]&lt;br /&gt;
| Alternate Work Site&lt;br /&gt;
| CUI&lt;br /&gt;
| [[#sec-sec_03.10.06|03.10.06]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;d30e12633&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;Table 14. [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=PL Planning (PL)]&lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
! colspan=&amp;quot;2&amp;quot; | &#039;&#039;&#039;NIST SP 800-53 CONTROLS MODERATE BASELINE&#039;&#039;&#039;&lt;br /&gt;
! &#039;&#039;&#039;TAILORING&#039;&#039;&#039;&amp;lt;br&amp;gt;&lt;br /&gt;
&#039;&#039;&#039;CRITERIA&#039;&#039;&#039;&lt;br /&gt;
! &#039;&#039;&#039;SECURITY&#039;&#039;&#039;&amp;lt;br&amp;gt;&lt;br /&gt;
&#039;&#039;&#039;REQUIREMENT&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=PL-01 PL-01]&lt;br /&gt;
| Policy and Procedures&lt;br /&gt;
| CUI&lt;br /&gt;
| [[#sec-sec_03.15.01|03.15.01]]&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=PL-02 PL-02]&lt;br /&gt;
| System Security and Privacy Plans&lt;br /&gt;
| CUI&lt;br /&gt;
| [[#sec-sec_03.15.02|03.15.02]]&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=PL-04 PL-04]&lt;br /&gt;
| Rules of Behavior&lt;br /&gt;
| CUI&lt;br /&gt;
| [[#sec-sec_03.15.03|03.15.03]]&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=PL-04 PL-04(01)]&lt;br /&gt;
| Rules of Behavior | Social Media and External Site/Application Usage Restrictions&lt;br /&gt;
| NCO&lt;br /&gt;
| —&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=PL-08 PL-08]&lt;br /&gt;
| Security and Privacy Architectures&lt;br /&gt;
| NCO&lt;br /&gt;
| —&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=PL-10 PL-10]&lt;br /&gt;
| Baseline Selection&lt;br /&gt;
| FED&lt;br /&gt;
| —&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=PL-11 PL-11]&lt;br /&gt;
| Baseline Tailoring&lt;br /&gt;
| FED&lt;br /&gt;
| —&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;d30e12835&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;Table 15. [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=PM Program Management (PM)]&lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
! colspan=&amp;quot;2&amp;quot; | &#039;&#039;&#039;NIST SP 800-53 CONTROLS MODERATE BASELINE&#039;&#039;&#039;&lt;br /&gt;
! &#039;&#039;&#039;TAILORING&#039;&#039;&#039;&amp;lt;br&amp;gt;&lt;br /&gt;
&#039;&#039;&#039;CRITERIA&#039;&#039;&#039;&lt;br /&gt;
! &#039;&#039;&#039;SECURITY&#039;&#039;&#039;&amp;lt;br&amp;gt;&lt;br /&gt;
&#039;&#039;&#039;REQUIREMENT&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=PM-01 PM-01]&lt;br /&gt;
| Information Security Program Plan&lt;br /&gt;
| N/A&lt;br /&gt;
| —&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=PM-02 PM-02]&lt;br /&gt;
| Information Security Program Leadership Role&lt;br /&gt;
| N/A&lt;br /&gt;
| —&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=PM-03 PM-03]&lt;br /&gt;
| Information Security and Privacy Resources&lt;br /&gt;
| N/A&lt;br /&gt;
| —&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=PM-04 PM-04]&lt;br /&gt;
| Plan of Action and Milestones Process&lt;br /&gt;
| N/A&lt;br /&gt;
| —&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=PM-05 PM-05]&lt;br /&gt;
| System Inventory&lt;br /&gt;
| N/A&lt;br /&gt;
| —&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=PM-05 PM-05(01)]&lt;br /&gt;
| System Inventory | Inventory of Personally Identifiable Information&lt;br /&gt;
| N/A&lt;br /&gt;
| —&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=PM-06 PM-06]&lt;br /&gt;
| Measures of Performance&lt;br /&gt;
| N/A&lt;br /&gt;
| —&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=PM-07 PM-07]&lt;br /&gt;
| Enterprise Architecture&lt;br /&gt;
| N/A&lt;br /&gt;
| —&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=PM-07 PM-07(01)]&lt;br /&gt;
| Enterprise Architecture | Offloading&lt;br /&gt;
| N/A&lt;br /&gt;
| —&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=PM-08 PM-08]&lt;br /&gt;
| Critical Infrastructure Plan&lt;br /&gt;
| N/A&lt;br /&gt;
| —&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=PM-09 PM-09]&lt;br /&gt;
| Risk Management Strategy&lt;br /&gt;
| N/A&lt;br /&gt;
| —&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=PM-10 PM-10]&lt;br /&gt;
| Authorization Process&lt;br /&gt;
| N/A&lt;br /&gt;
| —&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=PM-11 PM-11]&lt;br /&gt;
| Mission and Business Process Definition&lt;br /&gt;
| N/A&lt;br /&gt;
| —&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=PM-12 PM-12]&lt;br /&gt;
| Insider Threat Program&lt;br /&gt;
| N/A&lt;br /&gt;
| —&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=PM-13 PM-13]&lt;br /&gt;
| Security and Privacy Workforce&lt;br /&gt;
| N/A&lt;br /&gt;
| —&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=PM-14 PM-14]&lt;br /&gt;
| Testing, Training, and Monitoring&lt;br /&gt;
| N/A&lt;br /&gt;
| —&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=PM-15 PM-15]&lt;br /&gt;
| Security and Privacy Groups and Associations&lt;br /&gt;
| N/A&lt;br /&gt;
| —&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=PM-16 PM-16]&lt;br /&gt;
| Threat Awareness Program&lt;br /&gt;
| N/A&lt;br /&gt;
| —&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=PM-16 PM-16(01)]&lt;br /&gt;
| Threat Awareness Program | Automated Means for Sharing Threat Intelligence&lt;br /&gt;
| N/A&lt;br /&gt;
| —&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=PM-17 PM-17]&lt;br /&gt;
| Protecting Controlled Unclassified Information on External Systems&lt;br /&gt;
| N/A&lt;br /&gt;
| —&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=PM-18 PM-18]&lt;br /&gt;
| Privacy Program Plan&lt;br /&gt;
| N/A&lt;br /&gt;
| —&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=PM-19 PM-19]&lt;br /&gt;
| Privacy Program Leadership Role&lt;br /&gt;
| N/A&lt;br /&gt;
| —&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=PM-20 PM-20]&lt;br /&gt;
| Dissemination of Privacy Program Information&lt;br /&gt;
| N/A&lt;br /&gt;
| —&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=PM-20 PM-20(01)]&lt;br /&gt;
| Dissemination of Privacy Program Information | Privacy Policies on Websites, Applications, and Digital Services&lt;br /&gt;
| N/A&lt;br /&gt;
| —&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=PM-21 PM-21]&lt;br /&gt;
| Accounting of Disclosures&lt;br /&gt;
| N/A&lt;br /&gt;
| —&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=PM-22 PM-22]&lt;br /&gt;
| Personally Identifiable Information Quality Management&lt;br /&gt;
| N/A&lt;br /&gt;
| —&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=PM-23 PM-23]&lt;br /&gt;
| Data Governance Body&lt;br /&gt;
| N/A&lt;br /&gt;
| —&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=PM-24 PM-24]&lt;br /&gt;
| Data Integrity Board&lt;br /&gt;
| N/A&lt;br /&gt;
| —&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=PM-25 PM-25]&lt;br /&gt;
| Minimization of PII Used in Testing, Training, and Research&lt;br /&gt;
| N/A&lt;br /&gt;
| —&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=PM-26 PM-26]&lt;br /&gt;
| Complaint Management&lt;br /&gt;
| N/A&lt;br /&gt;
| —&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=PM-27 PM-27]&lt;br /&gt;
| Privacy Reporting&lt;br /&gt;
| N/A&lt;br /&gt;
| —&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=PM-28 PM-28]&lt;br /&gt;
| Risk Framing&lt;br /&gt;
| N/A&lt;br /&gt;
| —&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=PM-29 PM-29]&lt;br /&gt;
| Risk Management Program Leadership Roles&lt;br /&gt;
| N/A&lt;br /&gt;
| —&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=PM-30 PM-30]&lt;br /&gt;
| Supply Chain Risk Management Strategy&lt;br /&gt;
| N/A&lt;br /&gt;
| —&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=PM-30 PM-30(01)]&lt;br /&gt;
| Supply Chain Risk Management Strategy | Suppliers of Critical or Mission-Essential Items&lt;br /&gt;
| N/A&lt;br /&gt;
| —&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=PM-31 PM-31]&lt;br /&gt;
| Continuous Monitoring Strategy&lt;br /&gt;
| N/A&lt;br /&gt;
| —&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=PM-32 PM-32]&lt;br /&gt;
| Purposing&lt;br /&gt;
| N/A&lt;br /&gt;
| —&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;d30e13727&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;Table 16. [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=PS Personnel Security (PS)]&lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
! colspan=&amp;quot;2&amp;quot; | &#039;&#039;&#039;NIST SP 800-53 CONTROLS MODERATE BASELINE&#039;&#039;&#039;&lt;br /&gt;
! &#039;&#039;&#039;TAILORING&#039;&#039;&#039;&amp;lt;br&amp;gt;&lt;br /&gt;
&#039;&#039;&#039;CRITERIA&#039;&#039;&#039;&lt;br /&gt;
! &#039;&#039;&#039;SECURITY&#039;&#039;&#039;&amp;lt;br&amp;gt;&lt;br /&gt;
&#039;&#039;&#039;REQUIREMENT&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=PS-01 PS-01]&lt;br /&gt;
| Policy and Procedures&lt;br /&gt;
| CUI&lt;br /&gt;
| [[#sec-sec_03.15.01|03.15.01]]&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=PS-02 PS-02]&lt;br /&gt;
| Position Risk Designation&lt;br /&gt;
| FED&lt;br /&gt;
| —&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=PS-03 PS-03]&lt;br /&gt;
| Personnel Screening&lt;br /&gt;
| CUI&lt;br /&gt;
| [[#sec-sec_03.09.01|03.09.01]]&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=PS-04 PS-04]&lt;br /&gt;
| Personnel Termination&lt;br /&gt;
| CUI&lt;br /&gt;
| [[#sec-sec_03.09.02|03.09.02]]&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=PS-05 PS-05]&lt;br /&gt;
| Personnel Transfer&lt;br /&gt;
| CUI&lt;br /&gt;
| [[#sec-sec_03.09.02|03.09.02]]&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=PS-06 PS-06]&lt;br /&gt;
| Access Agreements&lt;br /&gt;
| NCO&lt;br /&gt;
| —&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=PS-07 PS-07]&lt;br /&gt;
| External Personnel Security&lt;br /&gt;
| NCO&lt;br /&gt;
| —&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=PS-08 PS-08]&lt;br /&gt;
| Personnel Sanctions&lt;br /&gt;
| NCO&lt;br /&gt;
| —&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=PS-09 PS-09]&lt;br /&gt;
| Position Descriptions&lt;br /&gt;
| FED&lt;br /&gt;
| —&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;d30e13976&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;Table 17. [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=PT PII Processing and Transparency (PT)]&lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
! colspan=&amp;quot;2&amp;quot; | &#039;&#039;&#039;NIST SP 800-53 CONTROLS MODERATE BASELINE&#039;&#039;&#039;&lt;br /&gt;
! &#039;&#039;&#039;TAILORING&#039;&#039;&#039;&amp;lt;br&amp;gt;&lt;br /&gt;
&#039;&#039;&#039;CRITERIA&#039;&#039;&#039;&lt;br /&gt;
! &#039;&#039;&#039;SECURITY&#039;&#039;&#039;&amp;lt;br&amp;gt;&lt;br /&gt;
&#039;&#039;&#039;REQUIREMENT&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=PT-01 PT-01]&lt;br /&gt;
| Policy and Procedures&lt;br /&gt;
| N/A&lt;br /&gt;
| —&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=PT-02 PT-02]&lt;br /&gt;
| Authority to Process Personally Identifiable Information&lt;br /&gt;
| N/A&lt;br /&gt;
| —&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=PT-02 PT-02(01)]&lt;br /&gt;
| Authority to Process Personally Identifiable Information | Data Tagging&lt;br /&gt;
| N/A&lt;br /&gt;
| —&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=PT-02 PT-02(02)]&lt;br /&gt;
| Authority to Process Personally Identifiable Information | Automation&lt;br /&gt;
| N/A&lt;br /&gt;
| —&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=PT-03 PT-03]&lt;br /&gt;
| Personally Identifiable Information Processing Purposes&lt;br /&gt;
| N/A&lt;br /&gt;
| —&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=PT-03 PT-03(01)]&lt;br /&gt;
| Personally Identifiable Information Processing Purposes | Data Tagging&lt;br /&gt;
| N/A&lt;br /&gt;
| —&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=PT-03 PT-03(02)]&lt;br /&gt;
| Personally Identifiable Information Processing Purposes | Automation&lt;br /&gt;
| N/A&lt;br /&gt;
| —&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=PT-04 PT-04]&lt;br /&gt;
| Consent&lt;br /&gt;
| N/A&lt;br /&gt;
| —&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=PT-04 PT-04(01)]&lt;br /&gt;
| Consent | Tailored Consent&lt;br /&gt;
| N/A&lt;br /&gt;
| —&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=PT-04 PT-04(02)]&lt;br /&gt;
| Consent | Just-in-Time Consent&lt;br /&gt;
| N/A&lt;br /&gt;
| —&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=PT-04 PT-04(03)]&lt;br /&gt;
| Consent | Revocation&lt;br /&gt;
| N/A&lt;br /&gt;
| —&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=PT-05 PT-05]&lt;br /&gt;
| Privacy Notice&lt;br /&gt;
| N/A&lt;br /&gt;
| —&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=PT-05 PT-05(01)]&lt;br /&gt;
| Privacy Notice | Just-in-Time Notice&lt;br /&gt;
| N/A&lt;br /&gt;
| —&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=PT-05 PT-05(02)]&lt;br /&gt;
| Privacy Notice | Privacy Act Statements&lt;br /&gt;
| N/A&lt;br /&gt;
| —&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=PT-06 PT-06]&lt;br /&gt;
| System of Records Notice&lt;br /&gt;
| N/A&lt;br /&gt;
| —&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=PT-06 PT-06(01)]&lt;br /&gt;
| System of Records Notice | Routine Uses&lt;br /&gt;
| N/A&lt;br /&gt;
| —&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=PT-06 PT-06(02)]&lt;br /&gt;
| System of Records Notice | Exemption Rules&lt;br /&gt;
| N/A&lt;br /&gt;
| —&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=PT-07 PT-07]&lt;br /&gt;
| Specific Categories of Personally Identifiable Information&lt;br /&gt;
| N/A&lt;br /&gt;
| —&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=PT-07 PT-07(01)]&lt;br /&gt;
| Specific Categories of Personally Identifiable Information | Social Security Numbers&lt;br /&gt;
| N/A&lt;br /&gt;
| —&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=PT-07 PT-07(02)]&lt;br /&gt;
| Specific Categories of Personally Identifiable Information | First Amendment Information&lt;br /&gt;
| N/A&lt;br /&gt;
| —&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=PT-08 PT-08]&lt;br /&gt;
| Computer Matching Requirements&lt;br /&gt;
| N/A&lt;br /&gt;
| —&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;d30e14498&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;Table 18. [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=RA Risk Assessment (RA)]&lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
! colspan=&amp;quot;2&amp;quot; | &#039;&#039;&#039;NIST SP 800-53 CONTROLS MODERATE BASELINE&#039;&#039;&#039;&lt;br /&gt;
! &#039;&#039;&#039;TAILORING&#039;&#039;&#039;&amp;lt;br&amp;gt;&lt;br /&gt;
&#039;&#039;&#039;CRITERIA&#039;&#039;&#039;&lt;br /&gt;
! &#039;&#039;&#039;SECURITY&#039;&#039;&#039;&amp;lt;br&amp;gt;&lt;br /&gt;
&#039;&#039;&#039;REQUIREMENT&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=RA-01 RA-01]&lt;br /&gt;
| Policy and Procedures&lt;br /&gt;
| CUI&lt;br /&gt;
| [[#sec-sec_03.15.01|03.15.01]]&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=RA-02 RA-02]&lt;br /&gt;
| Security Categorization&lt;br /&gt;
| FED&lt;br /&gt;
| —&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=RA-03 RA-03]&lt;br /&gt;
| Risk Assessment&lt;br /&gt;
| CUI&lt;br /&gt;
| [[#sec-sec_03.11.01|03.11.01]]&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=RA-03 RA-03(01)]&lt;br /&gt;
| Risk Assessment | Supply Chain Risk Assessment&lt;br /&gt;
| CUI&lt;br /&gt;
| [[#sec-sec_03.11.01|03.11.01]]&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=RA-05 RA-05]&lt;br /&gt;
| Vulnerability Monitoring and Scanning&lt;br /&gt;
| CUI&lt;br /&gt;
| [[#sec-sec_03.11.02|03.11.02]]&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=RA-05 RA-05(02)]&lt;br /&gt;
| Vulnerability Monitoring and Scanning | Update Vulnerabilities to be Scanned&lt;br /&gt;
| CUI&lt;br /&gt;
| [[#sec-sec_03.11.02|03.11.02]]&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=RA-05 RA-05(05)]&lt;br /&gt;
| Vulnerability Monitoring and Scanning | Privileged Access&lt;br /&gt;
| ORC&lt;br /&gt;
| —&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=RA-05 RA-05(11)]&lt;br /&gt;
| Vulnerability Monitoring and Scanning | Public Disclosure Program&lt;br /&gt;
| NCO&lt;br /&gt;
| —&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=RA-07 RA-07]&lt;br /&gt;
| Risk Response&lt;br /&gt;
| CUI&lt;br /&gt;
| [[#sec-sec_03.11.04|03.11.04]]&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=RA-09 RA-09]&lt;br /&gt;
| Criticality Analysis&lt;br /&gt;
| NCO&lt;br /&gt;
| —&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;d30e14773&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;Table 19. [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=SA System and Services Acquisition (SA)]&lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
! colspan=&amp;quot;2&amp;quot; | &#039;&#039;&#039;NIST SP 800-53 CONTROLS MODERATE BASELINE&#039;&#039;&#039;&lt;br /&gt;
! &#039;&#039;&#039;TAILORING&#039;&#039;&#039;&amp;lt;br&amp;gt;&lt;br /&gt;
&#039;&#039;&#039;CRITERIA&#039;&#039;&#039;&lt;br /&gt;
! &#039;&#039;&#039;SECURITY&#039;&#039;&#039;&amp;lt;br&amp;gt;&lt;br /&gt;
&#039;&#039;&#039;REQUIREMENT&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=SA-01 SA-01]&lt;br /&gt;
| Policy and Procedures&lt;br /&gt;
| CUI&lt;br /&gt;
| [[#sec-sec_03.15.01|03.15.01]]&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=SA-02 SA-02]&lt;br /&gt;
| Allocation of Resources&lt;br /&gt;
| NCO&lt;br /&gt;
| —&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=SA-03 SA-03]&lt;br /&gt;
| System Development Life Cycle&lt;br /&gt;
| NCO&lt;br /&gt;
| —&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=SA-04 SA-04]&lt;br /&gt;
| Acquisition Process&lt;br /&gt;
| NCO&lt;br /&gt;
| —&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=SA-04 SA-04(01)]&lt;br /&gt;
| Acquisition Process | Functional Properties of Controls&lt;br /&gt;
| NCO&lt;br /&gt;
| —&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=SA-04 SA-04(02)]&lt;br /&gt;
| Acquisition Process | Design and Implementation Information for Controls&lt;br /&gt;
| NCO&lt;br /&gt;
| —&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=SA-04 SA-04(09)]&lt;br /&gt;
| Acquisition Process | Functions, Ports, Protocols, and Services in Use&lt;br /&gt;
| NCO&lt;br /&gt;
| —&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=SA-04 SA-04(10)]&lt;br /&gt;
| Acquisition Process | Use of Approved PIV Products&lt;br /&gt;
| FED&lt;br /&gt;
| —&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=SA-05 SA-05]&lt;br /&gt;
| System Documentation&lt;br /&gt;
| NCO&lt;br /&gt;
| —&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=SA-08 SA-08]&lt;br /&gt;
| Security and Privacy Engineering Principles&lt;br /&gt;
| CUI&lt;br /&gt;
| [[#sec-sec_03.16.01|03.16.01]]&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=SA-09 SA-09]&lt;br /&gt;
| External System Services&lt;br /&gt;
| CUI&lt;br /&gt;
| [[#sec-sec_03.16.03|03.16.03]]&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=SA-09 SA-09(02)]&lt;br /&gt;
| External System Services | Identification of Functions, Ports, Protocols, and Services&lt;br /&gt;
| ORC&lt;br /&gt;
| —&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=SA-10 SA-10]&lt;br /&gt;
| Developer Configuration Management&lt;br /&gt;
| NCO&lt;br /&gt;
| —&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=SA-11 SA-11]&lt;br /&gt;
| Developer Testing and Evaluation&lt;br /&gt;
| NCO&lt;br /&gt;
| —&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=SA-15 SA-15]&lt;br /&gt;
| Development Process, Standards, and Tools&lt;br /&gt;
| NCO&lt;br /&gt;
| —&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=SA-15 SA-15(03)]&lt;br /&gt;
| Development Process, Standards, and Tools | Criticality Analysis&lt;br /&gt;
| NCO&lt;br /&gt;
| —&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=SA-22 SA-22]&lt;br /&gt;
| Unsupported System Components&lt;br /&gt;
| CUI&lt;br /&gt;
| [[#sec-sec_03.16.02|03.16.02]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;d30e15207&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;Table 20. [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=SC System and Communications Protection (SC)]&lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
! colspan=&amp;quot;2&amp;quot; | &#039;&#039;&#039;NIST SP 800-53 CONTROLS MODERATE BASELINE&#039;&#039;&#039;&lt;br /&gt;
! &#039;&#039;&#039;TAILORING&#039;&#039;&#039;&amp;lt;br&amp;gt;&lt;br /&gt;
&#039;&#039;&#039;CRITERIA&#039;&#039;&#039;&lt;br /&gt;
! &#039;&#039;&#039;SECURITY&#039;&#039;&#039;&amp;lt;br&amp;gt;&lt;br /&gt;
&#039;&#039;&#039;REQUIREMENT&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=SC-01 SC-01]&lt;br /&gt;
| Policy and Procedures&lt;br /&gt;
| CUI&lt;br /&gt;
| [[#sec-sec_03.15.01|03.15.01]]&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=SC-02 SC-02]&lt;br /&gt;
| Separation of System and User Functionality&lt;br /&gt;
| ORC&lt;br /&gt;
| —&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=SC-04 SC-04]&lt;br /&gt;
| Information in Shared System Resources&lt;br /&gt;
| CUI&lt;br /&gt;
| [[#sec-sec_03.13.04|03.13.04]]&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=SC-05 SC-05]&lt;br /&gt;
| Denial-of-Service Protection&lt;br /&gt;
| NCO&lt;br /&gt;
| —&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=SC-07 SC-07]&lt;br /&gt;
| Boundary Protection&lt;br /&gt;
| CUI&lt;br /&gt;
| [[#sec-sec_03.13.01|03.13.01]]&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=SC-07 SC-07(03)]&lt;br /&gt;
| Boundary Protection | Access Points&lt;br /&gt;
| ORC&lt;br /&gt;
| —&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=SC-07 SC-07(04)]&lt;br /&gt;
| Boundary Protection | External Telecommunications Services&lt;br /&gt;
| ORC&lt;br /&gt;
| —&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=SC-07 SC-07(05)]&lt;br /&gt;
| Boundary Protection | Deny by Default – Allow by Exception&lt;br /&gt;
| CUI&lt;br /&gt;
| [[#sec-sec_03.13.06|03.13.06]]&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=SC-07 SC-07(07)]&lt;br /&gt;
| Boundary Protection | Split Tunneling for Remote Devices&lt;br /&gt;
| ORC&lt;br /&gt;
| —&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=SC-07 SC-07(08)]&lt;br /&gt;
| Boundary Protection | Route Traffic to Authenticated Proxy Servers&lt;br /&gt;
| ORC&lt;br /&gt;
| —&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=SC-08 SC-08]&lt;br /&gt;
| Transmission Confidentiality and Integrity&lt;br /&gt;
| CUI&lt;br /&gt;
| [[#sec-sec_03.13.08|03.13.08]]&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=SC-08 SC-08(01)]&lt;br /&gt;
| Transmission Confidentiality and Integrity | Cryptographic Protection&lt;br /&gt;
| CUI&lt;br /&gt;
| [[#sec-sec_03.13.08|03.13.08]]&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=SC-10 SC-10]&lt;br /&gt;
| Network Disconnect&lt;br /&gt;
| CUI&lt;br /&gt;
| [[#sec-sec_03.13.09|03.13.09]]&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=SC-12 SC-12]&lt;br /&gt;
| Cryptographic Key Establishment and Management&lt;br /&gt;
| CUI&lt;br /&gt;
| [[#sec-sec_03.13.10|03.13.10]]&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=SC-13 SC-13]&lt;br /&gt;
| Cryptographic Protection&lt;br /&gt;
| CUI&lt;br /&gt;
| [[#sec-sec_03.13.11|03.13.11]]&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=SC-15 SC-15]&lt;br /&gt;
| Collaborative Computing Devices and Applications&lt;br /&gt;
| CUI&lt;br /&gt;
| [[#sec-sec_03.13.12|03.13.12]]&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=SC-17 SC-17]&lt;br /&gt;
| Public Key Infrastructure Certificates&lt;br /&gt;
| FED&lt;br /&gt;
| —&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=SC-18 SC-18]&lt;br /&gt;
| Mobile Code&lt;br /&gt;
| CUI&lt;br /&gt;
| [[#sec-sec_03.13.13|03.13.13]]&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=SC-20 SC-20]&lt;br /&gt;
| Secure Name/Address Resolution Service (Authoritative Source)&lt;br /&gt;
| NCO&lt;br /&gt;
| —&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=SC-21 SC-21]&lt;br /&gt;
| Secure Name/Address Resolution Service (Recursive or Caching Resolver)&lt;br /&gt;
| NCO&lt;br /&gt;
| —&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=SC-22 SC-22]&lt;br /&gt;
| Architecture and Provisioning for Name/Address Resolution Service&lt;br /&gt;
| NCO&lt;br /&gt;
| —&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=SC-23 SC-23]&lt;br /&gt;
| Session Authenticity&lt;br /&gt;
| CUI&lt;br /&gt;
| [[#sec-sec_03.13.15|03.13.15]]&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=SC-28 SC-28]&lt;br /&gt;
| Protection of Information at Rest&lt;br /&gt;
| CUI&lt;br /&gt;
| [[#sec-sec_03.13.08|03.13.08]]&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=SC-28 SC-28(01)]&lt;br /&gt;
| Protection of Information at Rest | Cryptographic Protection&lt;br /&gt;
| CUI&lt;br /&gt;
| [[#sec-sec_03.13.08|03.13.08]]&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=SC-39 SC-39]&lt;br /&gt;
| Process Isolation&lt;br /&gt;
| NCO&lt;br /&gt;
| —&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;d30e15836&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;Table 21. [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=SI System and Information Integrity (SI)]&lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
! colspan=&amp;quot;2&amp;quot; | &#039;&#039;&#039;NIST SP 800-53 CONTROLS MODERATE BASELINE&#039;&#039;&#039;&lt;br /&gt;
! &#039;&#039;&#039;TAILORING&#039;&#039;&#039;&amp;lt;br&amp;gt;&lt;br /&gt;
&#039;&#039;&#039;CRITERIA&#039;&#039;&#039;&lt;br /&gt;
! &#039;&#039;&#039;SECURITY&#039;&#039;&#039;&amp;lt;br&amp;gt;&lt;br /&gt;
&#039;&#039;&#039;REQUIREMENT&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=SI-01 SI-01]&lt;br /&gt;
| Policy and Procedures&lt;br /&gt;
| CUI&lt;br /&gt;
| [[#sec-sec_03.15.01|03.15.01]]&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=SI-02 SI-02]&lt;br /&gt;
| Flaw Remediation&lt;br /&gt;
| CUI&lt;br /&gt;
| [[#sec-sec_03.14.01|03.14.01]]&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=SI-02 SI-02(02)]&lt;br /&gt;
| Flaw Remediation | Automated Flaw Remediation Status&lt;br /&gt;
| NCO&lt;br /&gt;
| —&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=SI-03 SI-03]&lt;br /&gt;
| Malicious Code Protection&lt;br /&gt;
| CUI&lt;br /&gt;
| [[#sec-sec_03.14.02|03.14.02]]&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=SI-04 SI-04]&lt;br /&gt;
| System Monitoring&lt;br /&gt;
| CUI&lt;br /&gt;
| [[#sec-sec_03.14.06|03.14.06]]&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=SI-04 SI-04(02)]&lt;br /&gt;
| System Monitoring | Automated Tools and Mechanisms for Real-Time Analysis&lt;br /&gt;
| NCO&lt;br /&gt;
| —&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=SI-04 SI-04(04)]&lt;br /&gt;
| System Monitoring | Inbound and Outbound Communications Traffic&lt;br /&gt;
| CUI&lt;br /&gt;
| [[#sec-sec_03.14.06|03.14.06]]&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=SI-04 SI-04(05)]&lt;br /&gt;
| System Monitoring | System-Generated Alerts&lt;br /&gt;
| NCO&lt;br /&gt;
| —&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=SI-05 SI-05]&lt;br /&gt;
| Security Alerts, Advisories, and Directives&lt;br /&gt;
| CUI&lt;br /&gt;
| [[#sec-sec_03.14.03|03.14.03]]&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=SI-07 SI-07]&lt;br /&gt;
| Software, Firmware, and Information Integrity&lt;br /&gt;
| NCO&lt;br /&gt;
| —&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=SI-07 SI-07(01)]&lt;br /&gt;
| Software, Firmware, and Information Integrity | Integrity Checks&lt;br /&gt;
| NCO&lt;br /&gt;
| —&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=SI-07 SI-07(07)]&lt;br /&gt;
| Software, Firmware, and Information Integrity | Integration of Detection and Response&lt;br /&gt;
| NCO&lt;br /&gt;
| —&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=SI-08 SI-08]&lt;br /&gt;
| Spam Protection&lt;br /&gt;
| ORC&lt;br /&gt;
| —&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=SI-08 SI-08(02)]&lt;br /&gt;
| Spam Protection | Automatic Updates&lt;br /&gt;
| NCO&lt;br /&gt;
| —&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=SI-10 SI-10]&lt;br /&gt;
| Information Input Validation&lt;br /&gt;
| NCO&lt;br /&gt;
| —&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=SI-11 SI-11]&lt;br /&gt;
| Error Handling&lt;br /&gt;
| NCO&lt;br /&gt;
| —&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=SI-12 SI-12]&lt;br /&gt;
| Information Management and Retention&lt;br /&gt;
| CUI&lt;br /&gt;
| [[#sec-sec_03.14.08|03.14.08]]&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=SI-16 SI-16]&lt;br /&gt;
| Memory Protection&lt;br /&gt;
| NCO&lt;br /&gt;
| —&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;d30e16296&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;Table 22. [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=SR Supply Chain Risk Management (SR)]&lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
! colspan=&amp;quot;2&amp;quot; | &#039;&#039;&#039;NIST SP 800-53 CONTROLS MODERATE BASELINE&#039;&#039;&#039;&lt;br /&gt;
! &#039;&#039;&#039;TAILORING&#039;&#039;&#039;&amp;lt;br&amp;gt;&lt;br /&gt;
&#039;&#039;&#039;CRITERIA&#039;&#039;&#039;&lt;br /&gt;
! &#039;&#039;&#039;SECURITY&#039;&#039;&#039;&amp;lt;br&amp;gt;&lt;br /&gt;
&#039;&#039;&#039;REQUIREMENT&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=SR-01 SR-01]&lt;br /&gt;
| Policy and Procedures&lt;br /&gt;
| CUI&lt;br /&gt;
| [[#sec-sec_03.15.01|03.15.01]]&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=SR-02 SR-02]&lt;br /&gt;
| Supply Chain Risk Management Plan&lt;br /&gt;
| CUI&lt;br /&gt;
| [[#sec-sec_03.17.01|03.17.01]]&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=SR-02 SR-02(01)]&lt;br /&gt;
| Supply Chain Risk Management Plan | Establish SCRM Team&lt;br /&gt;
| NCO&lt;br /&gt;
| —&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=SR-03 SR-03]&lt;br /&gt;
| Supply Chain Controls and Processes&lt;br /&gt;
| CUI&lt;br /&gt;
| [[#sec-sec_03.17.03|03.17.03]]&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=SR-05 SR-05]&lt;br /&gt;
| Acquisition Strategies, Tools, and Methods&lt;br /&gt;
| CUI&lt;br /&gt;
| [[#sec-sec_03.17.02|03.17.02]]&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=SR-06 SR-06]&lt;br /&gt;
| Supplier Assessments and Reviews&lt;br /&gt;
| CUI&lt;br /&gt;
| [[#sec-sec_03.11.01|03.11.01]]&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=SR-08 SR-08]&lt;br /&gt;
| Notification Agreements&lt;br /&gt;
| NCO&lt;br /&gt;
| —&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=SR-10 SR-10]&lt;br /&gt;
| Inspection of Systems or Components&lt;br /&gt;
| NCO&lt;br /&gt;
| —&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=SR-11 SR-11]&lt;br /&gt;
| Component Authenticity&lt;br /&gt;
| NCO&lt;br /&gt;
| —&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=SR-11 SR-11(01)]&lt;br /&gt;
| Component Authenticity | Anti-Counterfeit Training&lt;br /&gt;
| NCO&lt;br /&gt;
| —&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=SR-11 SR-11(02)]&lt;br /&gt;
| Component Authenticity | Configuration Control for Component Service and Repair&lt;br /&gt;
| NCO&lt;br /&gt;
| —&lt;br /&gt;
|-&lt;br /&gt;
| [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=SR-12 SR-12]&lt;br /&gt;
| Component Disposal&lt;br /&gt;
| ORC&lt;br /&gt;
| —&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;d30e16617-Appendix_Title&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&amp;lt;span id=&amp;quot;sec-sec_D&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&lt;br /&gt;
== Appendix D : Organization-Defined Parameters ==&lt;br /&gt;
&lt;br /&gt;
This appendix lists the organization-defined parameters (ODPs) that are included in the security requirements in Sec. 3. The ODPs are listed sequentially by requirement family, beginning with the first requirement containing an ODP in the Access Control (AC) family and ending with the last requirement containing an ODP in the Supply Chain Risk Management (SR) family.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;d30e16623&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;Table 23. Organization-Defined Parameters&lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
! &#039;&#039;&#039;SECURITY&#039;&#039;&#039;&amp;lt;br&amp;gt;&lt;br /&gt;
&#039;&#039;&#039;REQUIREMENT&#039;&#039;&#039;&lt;br /&gt;
! colspan=&amp;quot;2&amp;quot; | &#039;&#039;&#039;ORGANIZATION-DEFINED PARAMETER&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [[#sec-sec_03.01.01|03.01.01]]&lt;br /&gt;
| [[#list_03.01.01.f.02|03.01.01.f.02]]&lt;br /&gt;
| [&#039;&#039;Assignment: organization-defined time period&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
| [[#sec-sec_03.01.01|03.01.01]]&lt;br /&gt;
| [[#list_03.01.01.g.01|03.01.01.g.01]]&lt;br /&gt;
| [&#039;&#039;Assignment: organization-defined time period&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
| [[#sec-sec_03.01.01|03.01.01]]&lt;br /&gt;
| [[#list_03.01.01.g.02|03.01.01.g.02]]&lt;br /&gt;
| [&#039;&#039;Assignment: organization-defined time period&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
| [[#sec-sec_03.01.01|03.01.01]]&lt;br /&gt;
| [[#list_03.01.01.g.03|03.01.01.g.03]]&lt;br /&gt;
| [&#039;&#039;Assignment: organization-defined time period&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
| [[#sec-sec_03.01.01|03.01.01]]&lt;br /&gt;
| [[#list_03.01.01.h|03.01.01.h]]&lt;br /&gt;
| [&#039;&#039;Assignment: organization-defined time period&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
| [[#sec-sec_03.01.01|03.01.01]]&lt;br /&gt;
| [[#list_03.01.01.h|03.01.01.h]]&lt;br /&gt;
| [&#039;&#039;Assignment: organization-defined circumstances&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
| [[#sec-sec_03.01.05|03.01.05]]&lt;br /&gt;
| [[#list_03.01.05.b|03.01.05.b]]&lt;br /&gt;
| [&#039;&#039;Assignment: organization-defined security functions&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
| [[#sec-sec_03.01.05|03.01.05]]&lt;br /&gt;
| [[#list_03.01.05.b|03.01.05.b]]&lt;br /&gt;
| [&#039;&#039;Assignment: organization-defined security-relevant information&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
| [[#sec-sec_03.01.05|03.01.05]]&lt;br /&gt;
| [[#list_03.01.05.c|03.01.05.c]]&lt;br /&gt;
| [&#039;&#039;Assignment: organization-defined frequency&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
| [[#sec-sec_03.01.06|03.01.06]]&lt;br /&gt;
| [[#list_03.01.06.a|03.01.06.a]]&lt;br /&gt;
| [&#039;&#039;Assignment: organization-defined personnel or roles&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
| [[#sec-sec_03.01.08|03.01.08]]&lt;br /&gt;
| [[#list_03.01.08.a|03.01.08.a]]&lt;br /&gt;
| [&#039;&#039;Assignment: organization-defined number&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
| [[#sec-sec_03.01.08|03.01.08]]&lt;br /&gt;
| [[#list_03.01.08.a|03.01.08.a]]&lt;br /&gt;
| [&#039;&#039;Assignment: organization-defined time period&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
| [[#sec-sec_03.01.08|03.01.08]]&lt;br /&gt;
| [[#list_03.01.08.b|03.01.08.b]]&lt;br /&gt;
| [&#039;&#039;Selection (one or more): lock the account or node for an&#039;&#039; [&#039;&#039;Assignment: organization-defined time period&#039;&#039;]&#039;&#039;; lock the account or node until released by an administrator; delay next logon prompt; notify system administrator; take other action&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
| [[#sec-sec_03.01.10|03.01.10]]&lt;br /&gt;
| [[#list_03.01.10.a|03.01.10.a]]&lt;br /&gt;
| [&#039;&#039;Selection (one or more): initiating a device lock after &#039;&#039;[&#039;&#039;Assignment: organization-defined time period&#039;&#039;]&#039;&#039; of inactivity; requiring the user to initiate a device lock before leaving the system unattended&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
| [[#sec-sec_03.01.11|03.01.11]]&lt;br /&gt;
| [[#sec-sec_03.01.11|03.01.11]]&lt;br /&gt;
| [&#039;&#039;Assignment: organization-defined conditions or trigger events requiring session disconnect&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
| [[#sec-sec_03.01.20|03.01.20]]&lt;br /&gt;
| [[#list_03.01.20.b|03.01.20.b]]&lt;br /&gt;
| [&#039;&#039;Assignment: organization-defined security requirements&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
| [[#sec-sec_03.02.01|03.02.01]]&lt;br /&gt;
| [[#list_03.02.01.a.01|03.02.01.a.01]]&lt;br /&gt;
| [&#039;&#039;Assignment: organization-defined frequency&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
| [[#sec-sec_03.02.01|03.02.01]]&lt;br /&gt;
| [[#list_03.02.01.a.02|03.02.01.a.02]]&lt;br /&gt;
| [&#039;&#039;Assignment: organization-defined events&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
| [[#sec-sec_03.02.01|03.02.01]]&lt;br /&gt;
| [[#list_03.02.01.b|03.02.01.b]]&lt;br /&gt;
| [&#039;&#039;Assignment: organization-defined frequency&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
| [[#sec-sec_03.02.01|03.02.01]]&lt;br /&gt;
| [[#list_03.02.01.b|03.02.01.b]]&lt;br /&gt;
| [&#039;&#039;Assignment: organization-defined events&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
| [[#sec-sec_03.02.02|03.02.02]]&lt;br /&gt;
| [[#list_03.02.02.a.01|03.02.02.a.01]]&lt;br /&gt;
| [&#039;&#039;Assignment: organization-defined frequency&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
| [[#sec-sec_03.02.02|03.02.02]]&lt;br /&gt;
| [[#list_03.02.02.a.02|03.02.02.a.02]]&lt;br /&gt;
| [&#039;&#039;Assignment: organization-defined events&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
| [[#sec-sec_03.02.02|03.02.02]]&lt;br /&gt;
| [[#list_03.02.02.b|03.02.02.b]]&lt;br /&gt;
| [&#039;&#039;Assignment: organization-defined frequency&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
| [[#sec-sec_03.02.02|03.02.02]]&lt;br /&gt;
| [[#list_03.02.02.b|03.02.02.b]]&lt;br /&gt;
| [&#039;&#039;Assignment: organization-defined events&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
| [[#sec-sec_03.03.01|03.03.01]]&lt;br /&gt;
| [[#list_03.03.01.a|03.03.01.a]]&lt;br /&gt;
| [&#039;&#039;Assignment: organization-defined event types&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
| [[#sec-sec_03.03.01|03.03.01]]&lt;br /&gt;
| [[#list_03.03.01.b|03.03.01.b]]&lt;br /&gt;
| [&#039;&#039;Assignment: organization-defined frequency&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
| [[#sec-sec_03.03.04|03.03.04]]&lt;br /&gt;
| [[#list_03.03.04.a|03.03.04.a]]&lt;br /&gt;
| [&#039;&#039;Assignment: organization-defined time period&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
| [[#sec-sec_03.03.04|03.03.04]]&lt;br /&gt;
| [[#list_03.03.04.b|03.03.04.b]]&lt;br /&gt;
| [&#039;&#039;Assignment: organization-defined additional actions&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
| [[#sec-sec_03.03.05|03.03.05]]&lt;br /&gt;
| [[#list_03.03.05.a|03.03.05.a]]&lt;br /&gt;
| [&#039;&#039;Assignment: organization-defined frequency&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
| [[#sec-sec_03.03.07|03.03.07]]&lt;br /&gt;
| [[#list_03.03.07.b|03.03.07.b]]&lt;br /&gt;
| [&#039;&#039;Assignment: organization-defined granularity of time measurement&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
| [[#sec-sec_03.04.01|03.04.01]]&lt;br /&gt;
| [[#list_03.04.01.b|03.04.01.b]]&lt;br /&gt;
| [&#039;&#039;Assignment: organization-defined frequency&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
| [[#sec-sec_03.04.02|03.04.02]]&lt;br /&gt;
| [[#list_03.04.02.a|03.04.02.a]]&lt;br /&gt;
| [&#039;&#039;Assignment: organization-defined configuration settings&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
| [[#sec-sec_03.04.06|03.04.06]]&lt;br /&gt;
| [[#list_03.04.06.b|03.04.06.b]]&lt;br /&gt;
| [&#039;&#039;Assignment: organization-defined functions, ports, protocols, connections, and/or services&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
| [[#sec-sec_03.04.06|03.04.06]]&lt;br /&gt;
| [[#list_03.04.06.c|03.04.06.c]]&lt;br /&gt;
| [&#039;&#039;Assignment: organization-defined frequency&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
| [[#sec-sec_03.04.08|03.04.08]]&lt;br /&gt;
| [[#list_03.04.08.c|03.04.08.c]]&lt;br /&gt;
| [&#039;&#039;Assignment: organization-defined frequency&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
| [[#sec-sec_03.04.10|03.04.10]]&lt;br /&gt;
| [[#list_03.04.10.b|03.04.10.b]]&lt;br /&gt;
| [&#039;&#039;Assignment: organization-defined frequency&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
| [[#sec-sec_03.04.12|03.04.12]]&lt;br /&gt;
| [[#list_03.04.12.a|03.04.12.a]]&lt;br /&gt;
| [&#039;&#039;Assignment: organization-defined system configurations&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
| [[#sec-sec_03.04.12|03.04.12]]&lt;br /&gt;
| [[#list_03.04.12.b|03.04.12.b]]&lt;br /&gt;
| [&#039;&#039;Assignment: organization-defined security requirements&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
| [[#sec-sec_03.05.01|03.05.01]]&lt;br /&gt;
| [[#list_03.05.01.b|03.05.01.b]]&lt;br /&gt;
| [&#039;&#039;Assignment: organization-defined circumstances or situations requiring re-authentication&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
| [[#sec-sec_03.05.02|03.05.02]]&lt;br /&gt;
| [[#sec-sec_03.05.02|03.05.02]]&lt;br /&gt;
| [&#039;&#039;Assignment: organization-defined devices or types of devices&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
| [[#sec-sec_03.05.05|03.05.05]]&lt;br /&gt;
| [[#list_03.05.05.c|03.05.05.c]]&lt;br /&gt;
| [&#039;&#039;Assignment: organization-defined time period&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
| [[#sec-sec_03.05.05|03.05.05]]&lt;br /&gt;
| [[#list_03.05.05.d|03.05.05.d]]&lt;br /&gt;
| [&#039;&#039;Assignment: organization-defined characteristic identifying individual status&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
| [[#sec-sec_03.05.07|03.05.07]]&lt;br /&gt;
| [[#list_03.05.07.a|03.05.07.a]]&lt;br /&gt;
| [&#039;&#039;Assignment: organization-defined frequency&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
| [[#sec-sec_03.05.07|03.05.07]]&lt;br /&gt;
| [[#list_03.05.07.f|03.05.07.f]]&lt;br /&gt;
| [&#039;&#039;Assignment: organization-defined composition and complexity rules&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
| [[#sec-sec_03.05.12|03.05.12]]&lt;br /&gt;
| [[#list_03.05.12.e|03.05.12.e]]&lt;br /&gt;
| [&#039;&#039;Assignment: organization-defined frequency&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
| [[#sec-sec_03.05.12|03.05.12]]&lt;br /&gt;
| [[#list_03.05.12.e|03.05.12.e]]&lt;br /&gt;
| [&#039;&#039;Assignment: organization-defined events&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
| [[#sec-sec_03.06.02|03.06.02]]&lt;br /&gt;
| [[#list_03.06.02.b|03.06.02.b]]&lt;br /&gt;
| [&#039;&#039;Assignment: organization-defined time period&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
| [[#sec-sec_03.06.02|03.06.02]]&lt;br /&gt;
| [[#list_03.06.02.c|03.06.02.c]]&lt;br /&gt;
| [&#039;&#039;Assignment: organization-defined authorities&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
| [[#sec-sec_03.06.03|03.06.03]]&lt;br /&gt;
| [[#sec-sec_03.06.03|03.06.03]]&lt;br /&gt;
| [&#039;&#039;Assignment: organization-defined frequency&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
| [[#sec-sec_03.06.04|03.06.04]]&lt;br /&gt;
| [[#list_03.06.04.a.01|03.06.04.a.01]]&lt;br /&gt;
| [&#039;&#039;Assignment: organization-defined time period&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
| [[#sec-sec_03.06.04|03.06.04]]&lt;br /&gt;
| [[#list_03.06.04.a.03|03.06.04.a.03]]&lt;br /&gt;
| [&#039;&#039;Assignment: organization-defined frequency&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
| [[#sec-sec_03.06.04|03.06.04]]&lt;br /&gt;
| [[#list_03.06.04.b|03.06.04.b]]&lt;br /&gt;
| [&#039;&#039;Assignment: organization-defined frequency&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
| [[#sec-sec_03.06.04|03.06.04]]&lt;br /&gt;
| [[#list_03.06.04.b|03.06.04.b]]&lt;br /&gt;
| [&#039;&#039;Assignment: organization-defined events&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
| [[#sec-sec_03.08.07|03.08.07]]&lt;br /&gt;
| [[#list_03.08.07.a|03.08.07.a]]&lt;br /&gt;
| [&#039;&#039;Assignment: organization-defined types of system media&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
| [[#sec-sec_03.09.01|03.09.01]]&lt;br /&gt;
| [[#list_03.09.01.b|03.09.01.b]]&lt;br /&gt;
| [&#039;&#039;Assignment: organization-defined conditions requiring rescreening&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
| [[#sec-sec_03.09.02|03.09.02]]&lt;br /&gt;
| [[#list_03.09.02.a.01|03.09.02.a.01]]&lt;br /&gt;
| [&#039;&#039;Assignment: organization-defined time period&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
| [[#sec-sec_03.10.01|03.10.01]]&lt;br /&gt;
| [[#list_03.10.01.c|03.10.01.c]]&lt;br /&gt;
| [&#039;&#039;Assignment: organization-defined frequency&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
| [[#sec-sec_03.10.02|03.10.02]]&lt;br /&gt;
| [[#list_03.10.02.b|03.10.02.b]]&lt;br /&gt;
| [&#039;&#039;Assignment: organization-defined frequency&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
| [[#sec-sec_03.10.02|03.10.02]]&lt;br /&gt;
| [[#list_03.10.02.b|03.10.02.b]]&lt;br /&gt;
| [&#039;&#039;Assignment: organization-defined events or potential indications of events&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
| [[#sec-sec_03.10.06|03.10.06]]&lt;br /&gt;
| [[#list_03.10.06.b|03.10.06.b]]&lt;br /&gt;
| [&#039;&#039;Assignment: organization-defined security requirements&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
| [[#sec-sec_03.11.01|03.11.01]]&lt;br /&gt;
| [[#list_03.11.01.b|03.11.01.b]]&lt;br /&gt;
| [&#039;&#039;Assignment: organization-defined frequency&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
| [[#sec-sec_03.11.02|03.11.02]]&lt;br /&gt;
| [[#list_03.11.02.a|03.11.02.a]]&lt;br /&gt;
| [&#039;&#039;Assignment: organization-defined frequency&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
| [[#sec-sec_03.11.02|03.11.02]]&lt;br /&gt;
| [[#list_03.11.02.b|03.11.02.b]]&lt;br /&gt;
| [&#039;&#039;Assignment: organization-defined response times&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
| [[#sec-sec_03.11.02|03.11.02]]&lt;br /&gt;
| [[#list_03.11.02.c|03.11.02.c]]&lt;br /&gt;
| [&#039;&#039;Assignment: organization-defined frequency&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
| [[#sec-sec_03.12.01|03.12.01]]&lt;br /&gt;
| [[#sec-sec_03.12.01|03.12.01]]&lt;br /&gt;
| [&#039;&#039;Assignment: organization-defined frequency&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
| [[#sec-sec_03.12.05|03.12.05]]&lt;br /&gt;
| [[#list_03.12.05.a|03.12.05.a]]&lt;br /&gt;
| [&#039;&#039;Selection (one or more): interconnection security agreements; information exchange security agreements; memoranda of understanding or agreement; service-level agreements; user agreements; nondisclosure agreements; other types of agreements&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
| [[#sec-sec_03.12.05|03.12.05]]&lt;br /&gt;
| [[#list_03.12.05.c|03.12.05.c]]&lt;br /&gt;
| [&#039;&#039;Assignment: organization-defined frequency&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
| [[#sec-sec_03.13.09|03.13.09]]&lt;br /&gt;
| [[#sec-sec_03.13.09|03.13.09]]&lt;br /&gt;
| [&#039;&#039;Assignment: organization-defined time period&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
| [[#sec-sec_03.13.10|03.13.10]]&lt;br /&gt;
| [[#sec-sec_03.13.10|03.13.10]]&lt;br /&gt;
| [&#039;&#039;Assignment: organization-defined requirements for key establishment and management&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
| [[#sec-sec_03.13.11|03.13.11]]&lt;br /&gt;
| [[#sec-sec_03.13.11|03.13.11]]&lt;br /&gt;
| [&#039;&#039;Assignment: organization-defined types of cryptography&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
| [[#sec-sec_03.13.12|03.13.12]]&lt;br /&gt;
| [[#list_03.13.12.a|03.13.12.a]]&lt;br /&gt;
| [&#039;&#039;Assignment: organization-defined exceptions where remote activation is to be allowed&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
| [[#sec-sec_03.14.01|03.14.01]]&lt;br /&gt;
| [[#list_03.14.01.b|03.14.01.b]]&lt;br /&gt;
| [&#039;&#039;Assignment: organization-defined time period&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
| [[#sec-sec_03.14.02|03.14.02]]&lt;br /&gt;
| [[#list_03.14.02.c.01|03.14.02.c.01]]&lt;br /&gt;
| [&#039;&#039;Assignment: organization-defined frequency&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
| [[#sec-sec_03.15.01|03.15.01]]&lt;br /&gt;
| [[#list_03.15.01.b|03.15.01.b]]&lt;br /&gt;
| [&#039;&#039;Assignment: organization-defined frequency&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
| [[#sec-sec_03.15.02|03.15.02]]&lt;br /&gt;
| [[#list_03.15.02.b|03.15.02.b]]&lt;br /&gt;
| [&#039;&#039;Assignment: organization-defined frequency&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
| [[#sec-sec_03.15.03|03.15.03]]&lt;br /&gt;
| [[#list_03.15.03.d|03.15.03.d]]&lt;br /&gt;
| [&#039;&#039;Assignment: organization-defined frequency&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
| [[#sec-sec_03.16.01|03.16.01]]&lt;br /&gt;
| [[#sec-sec_03.16.01|03.16.01]]&lt;br /&gt;
| [&#039;&#039;Assignment: organization-defined systems security engineering principles&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
| [[#sec-sec_03.16.03|03.16.03]]&lt;br /&gt;
| [[#list_03.16.03.a|03.16.03.a]]&lt;br /&gt;
| [&#039;&#039;Assignment: organization-defined security requirements&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
| [[#sec-sec_03.17.01|03.17.01]]&lt;br /&gt;
| [[#list_03.17.01.b|03.17.01.b]]&lt;br /&gt;
| [&#039;&#039;Assignment: organization-defined frequency&#039;&#039;]&lt;br /&gt;
|-&lt;br /&gt;
| [[#sec-sec_03.17.03|03.17.03]]&lt;br /&gt;
| [[#list_03.17.03.b|03.17.03.b]]&lt;br /&gt;
| [&#039;&#039;Assignment: organization-defined security requirements&#039;&#039;]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;d30e18280-Appendix_Title&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&amp;lt;span id=&amp;quot;sec-sec_E&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&lt;br /&gt;
== Appendix E : Change Log ==&lt;br /&gt;
&lt;br /&gt;
This publication incorporates the following changes from the original edition (February 2020; updated January 28, 2021):&lt;br /&gt;
&lt;br /&gt;
* Streamlined introductory information in Sec. 1 and Sec. 2 to improve clarity and understanding&lt;br /&gt;
* Modified the security requirements and families in Sec. 3 to reflect the security controls in the SP 800-53B [[#bibr-ref_12|12]] moderate baseline and the tailoring actions in [[#sec-sec_C|Appendix C]]&lt;br /&gt;
* Eliminated the distinction between basic and derived security requirements&lt;br /&gt;
* Increased the specificity of security requirements to remove ambiguity, improve the effectiveness of implementation, and clarify the scope of assessments&lt;br /&gt;
* Introduced organization-defined parameters (ODPs) in selected security requirements to increase flexibility and help organizations better manage risk&lt;br /&gt;
* Grouped security requirements, where possible, to improve understanding and the efficiency of implementations and assessments&lt;br /&gt;
* Removed outdated and redundant security requirements&lt;br /&gt;
* Added new security requirements&lt;br /&gt;
* Added titles to the security requirements&lt;br /&gt;
* Restructured and streamlined the security requirement discussion sections&lt;br /&gt;
* Added new tailoring categories: Other Related Controls (ORC) and Not Applicable (N/A)&lt;br /&gt;
* Recategorized selected controls in the SP 800-53B moderate baseline using the tailoring criteria in [[#sec-sec_C|Appendix C]]&lt;br /&gt;
* Revised the security requirements for consistency with the security control language in SP 800-53&lt;br /&gt;
* Revised the structure of the References, Acronyms, and Glossary sections for greater clarity and ease of use&lt;br /&gt;
* Revised the tailoring tables in [[#sec-sec_C|Appendix C]] to be consistent with the changes to the security requirements&lt;br /&gt;
* Added new appendix listing organization-defined parameters for security requirements&lt;br /&gt;
&lt;br /&gt;
[[#table-tab_24|Table 24]] shows the changes incorporated into this publication. Errata updates can include corrections, clarifications, or other minor changes in the publication that are either &#039;&#039;editorial&#039;&#039; or &#039;&#039;substantive&#039;&#039; in nature. Any potential updates to this document that are not yet published in an errata update or a formal revision, including additional issues and potential corrections, will be posted as they are identified. See the [https://csrc.nist.gov/pubs/sp/800/171/r3/final publication details] for this report. The current release of this publication does not include any errata updates.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;d30e18362&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;Table 24. Change Log&lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;PUBLICATION ID&#039;&#039;&#039;&lt;br /&gt;
| &#039;&#039;&#039;DATE&#039;&#039;&#039;&lt;br /&gt;
| &#039;&#039;&#039;TYPE OF EDIT&#039;&#039;&#039;&lt;br /&gt;
| &#039;&#039;&#039;CHANGE&#039;&#039;&#039;&lt;br /&gt;
| &#039;&#039;&#039;LOCATION&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Footnotes ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;footnote-1&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;[[#footnote-1-backlink|1]] CUI is any information that a law, regulation, or government-wide policy requires to have safeguarding or disseminating controls, excluding information that is classified under EO 13526 [[#bibr-ref_2|&amp;lt;u&amp;gt;2&amp;lt;/u&amp;gt;]], any predecessor or successor order, or the Atomic Energy Act [[#bibr-ref_3|&amp;lt;u&amp;gt;3&amp;lt;/u&amp;gt;]] as amended.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;footnote-2&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;[[#footnote-2-backlink|2]] Procedures for the use of CUI include marking, safeguarding, transporting, disseminating, reusing, and disposing of the information.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;footnote-3&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;[[#footnote-3-backlink|3]] A &#039;&#039;federal information system&#039;&#039; is a system that is used or operated by an executive agency, by a contractor of an executive agency, or by another organization on behalf of an executive agency. The term &#039;&#039;system&#039;&#039; is used in this publication to represent people, processes, and technologies involved in the processing, storage, or transmission of CUI. Systems can include operational technology (OT), information technology (IT), Internet of Things (IoT) devices, Industrial IoT (IIoT) devices, specialized systems, cyber-physical systems, embedded systems, and sensors.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;footnote-4&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;[[#footnote-4-backlink|4]] A &#039;&#039;nonfederal organization&#039;&#039; is any entity that owns, operates, or maintains a nonfederal system.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;footnote-5&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;[[#footnote-5-backlink|5]] A &#039;&#039;nonfederal system&#039;&#039; is any system that does not meet the criteria for a federal information system.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;footnote-6&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;[[#footnote-6-backlink|6]] The term &#039;&#039;security requirement&#039;&#039; refers to the protection needs for a system or organization. Security requirements may be derived from laws, Executive Orders, directives, regulations, policies, standards, mission and business needs, or risk assessments.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;footnote-7&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;[[#footnote-7-backlink|7]] In accordance with EO 13526 [[#bibr-ref_2|&amp;lt;u&amp;gt;2&amp;lt;/u&amp;gt;]] and 32 CFR 2002 [[#bibr-ref_5|&amp;lt;u&amp;gt;5&amp;lt;/u&amp;gt;]], the scope of CUI protection is primarily focused on &#039;&#039;confidentiality&#039;&#039;. However, the security objectives of confidentiality and integrity are closely related since many of the underlying security mechanisms support both objectives. Therefore, the security requirements in this publication address the protection of CUI from unauthorized disclosure and modification.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;footnote-8&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;[[#footnote-8-backlink|8]] Nonfederal organizations that collect or maintain information on behalf of a federal agency or that use or operate a system on behalf of an agency must comply with the requirements in FISMA [[#bibr-ref_9|&amp;lt;u&amp;gt;9&amp;lt;/u&amp;gt;]].&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;footnote-9&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;[[#footnote-9-backlink|9]] System &#039;&#039;components&#039;&#039; include workstations, servers, notebook computers, smartphones, tablets, input and output devices, network components, operating systems, virtual machines, database management systems, and applications.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&amp;lt;span id=&amp;quot;footnote-10&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;[[#footnote-10-backlink|10]]Tailoring&#039;&#039; is the process by which control baselines are modified to achieve certain organizational goals and objectives [[#bibr-ref_13|&amp;lt;u&amp;gt;13&amp;lt;/u&amp;gt;]].&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;footnote-11&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;[[#footnote-11-backlink|11]] In accordance with 32 CFR 2002 [[#bibr-ref_5|&amp;lt;u&amp;gt;5&amp;lt;/u&amp;gt;]], CUI is categorized at no less than the FIPS 199 [[#bibr-ref_6|&amp;lt;u&amp;gt;6&amp;lt;/u&amp;gt;]] moderate confidentiality impact value. However, when federal law, regulation, or government-wide policy establishing the control of CUI specifies controls that differ from those of the moderate control baseline, then the applicable law, regulation, or government-wide policy is followed.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;footnote-12&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;[[#footnote-12-backlink|12]] “Adequately addressed by other related controls” means that the protection capability offered by the control is provided by another control in the same or different control family. Using this tailoring option helps to eliminate potential redundancy in requirements without affecting the protection of CUI in nonfederal systems and organizations.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;u&amp;gt;&amp;lt;span id=&amp;quot;footnote-13&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;[[#footnote-13-backlink|13]] [https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=CP-09 CP-09]&amp;lt;/u&amp;gt; and &amp;lt;u&amp;gt;[https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_1_1/home?element=CP-09 CP-09(08)]&amp;lt;/u&amp;gt; are included by exception to ensure the confidentiality of backup information is projected.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;footnote-14&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;[[#footnote-14-backlink|14]] NIST does not establish or assign values for ODPs. If ODP values for selected security requirements are not formally established or assigned by a federal agency or a consortium of federal agencies, nonfederal organizations must assign those values to complete the requirements.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;footnote-15&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;[[#footnote-15-backlink|15]] With few exceptions, the security controls in SP 800-53 are policy-, technology-, and sector-neutral, meaning that the controls focus on the fundamental measures necessary to protect information across the information life cycle.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span id=&amp;quot;footnote-16&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;[[#footnote-16-backlink|16]] The security controls in SP 800-53 provide a comprehensive set of security capabilities needed to protect organizational systems and support the concept of defense in depth. Some of the security controls may address similar or overlapping security topics that are covered by other related controls. These controls have been designated as ORC in the tailoring criteria.&lt;/div&gt;</summary>
		<author><name>David</name></author>
	</entry>
	<entry>
		<id>https://cmmcwiki.org/index.php?title=NIST_SP_800-171A&amp;diff=1635</id>
		<title>NIST SP 800-171A</title>
		<link rel="alternate" type="text/html" href="https://cmmcwiki.org/index.php?title=NIST_SP_800-171A&amp;diff=1635"/>
		<updated>2026-07-27T02:58:59Z</updated>

		<summary type="html">&lt;p&gt;David: Created page with &amp;quot;{{Infobox document | title           = NIST Special Publication 800-171A | subtitle        = Assessing Security Requirements for Controlled Unclassified Information | authors         = Ron Ross, Kelley Dempsey, Victoria Pillitteri | publisher       = Computer Security Division, National Institute of Standards and Technology | pub_date        = June 2018 | pages           = 92 | coden           = NSPUE2 | doi             = https://doi.org/10.6028/NIST.SP.800-171A }}  {{No...&amp;quot;&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Infobox document&lt;br /&gt;
| title           = NIST Special Publication 800-171A&lt;br /&gt;
| subtitle        = Assessing Security Requirements for Controlled Unclassified Information&lt;br /&gt;
| authors         = Ron Ross, Kelley Dempsey, Victoria Pillitteri&lt;br /&gt;
| publisher       = Computer Security Division, National Institute of Standards and Technology&lt;br /&gt;
| pub_date        = June 2018&lt;br /&gt;
| pages           = 92&lt;br /&gt;
| coden           = NSPUE2&lt;br /&gt;
| doi             = https://doi.org/10.6028/NIST.SP.800-171A&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
{{Notice|type=warning|&#039;&#039;&#039;WITHDRAWN NIST TECHNICAL SERIES PUBLICATION&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
The attached publication has been withdrawn (archived), and is provided solely for historical purposes. It may have been superseded by another publication (indicated below).&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Series/Number || NIST SP 800-171A&lt;br /&gt;
|-&lt;br /&gt;
! Title || Assessing Security Requirements for Controlled Unclassified Information&lt;br /&gt;
|-&lt;br /&gt;
! Publication Date(s) || June 2018&lt;br /&gt;
|-&lt;br /&gt;
! Withdrawal Date || May 14, 2024&lt;br /&gt;
|-&lt;br /&gt;
! Withdrawal Note || NIST SP 800-171A is withdrawn and superseded in its entirety by NIST SP 800-171Ar3.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Superseding Publication&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Series/Number || NIST SP 800-171Ar3&lt;br /&gt;
|-&lt;br /&gt;
! Title || Assessing Security Requirements for Controlled Unclassified Information&lt;br /&gt;
|-&lt;br /&gt;
! Author(s) || Ron Ross; Victoria Pillitteri&lt;br /&gt;
|-&lt;br /&gt;
! Publication Date(s) || May 2024&lt;br /&gt;
|-&lt;br /&gt;
! URL/DOI || https://doi.org/10.6028/NIST.SP.800-171Ar3&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Additional Information&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Contact || Computer Security Division (Information Technology Laboratory)&lt;br /&gt;
|-&lt;br /&gt;
! Related Information || https://csrc.nist.gov/pubs/sp/800/171/a/final&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
Date updated: May 14, 2024&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
== Front Matter ==&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;National Institute of Standards and Technology Special Publication 800-171A&#039;&#039;&#039;&amp;lt;br&amp;gt;&lt;br /&gt;
Natl. Inst. Stand. Technol. Spec. Publ. 800-171A, &#039;&#039;&#039;92 pages&#039;&#039;&#039; (June 2018)&lt;br /&gt;
&lt;br /&gt;
CODEN: NSPUE2&lt;br /&gt;
&lt;br /&gt;
This publication is available free of charge from: https://doi.org/10.6028/NIST.SP.800-171A&lt;br /&gt;
&lt;br /&gt;
{{Notice|type=note|Certain commercial entities, equipment, or materials may be identified in this document to describe an experimental procedure or concept adequately. Such identification is not intended to imply recommendation or endorsement by NIST, nor is it intended to imply that the entities, materials, or equipment are necessarily the best available for the purpose.&lt;br /&gt;
&lt;br /&gt;
There may be references in this publication to other publications currently under development by NIST in accordance with its assigned statutory responsibilities. The information in this publication, including concepts, practices, and methodologies, may be used by federal agencies even before the completion of such companion publications. Thus, until each publication is completed, current requirements, guidelines, and procedures, where they exist, remain operative. For planning and transition purposes, federal agencies may wish to closely follow the development of these new publications by NIST.&lt;br /&gt;
&lt;br /&gt;
Organizations are encouraged to review draft publications during the designated public comment periods and provide feedback to NIST. Many NIST cybersecurity publications, other than the ones noted above, are available at https://csrc.nist.gov/publications.}}&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Comments on this publication may be submitted to:&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
National Institute of Standards and Technology&amp;lt;br&amp;gt;&lt;br /&gt;
Attn: Computer Security Division, Information Technology Laboratory&amp;lt;br&amp;gt;&lt;br /&gt;
100 Bureau Drive (Mail Stop 8930) Gaithersburg, MD 20899-8930&amp;lt;br&amp;gt;&lt;br /&gt;
Email: sec-cert@nist.gov&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;All comments are subject to release under the Freedom of Information Act (FOIA).&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
=== Authority ===&lt;br /&gt;
&lt;br /&gt;
This publication has been developed by the National Institute of Standards and Technology to further its statutory responsibilities under the Federal Information Security Modernization Act (FISMA) of 2014, 44 U.S.C. § 3551 &#039;&#039;et seq.&#039;&#039;, Public Law (P.L.) 113-283. NIST is responsible for developing information security standards and guidelines, including minimum requirements for federal information systems, but such standards and guidelines shall not apply to national security systems without the express approval of appropriate federal officials exercising policy authority over such systems. This guideline is consistent with requirements of the Office of Management and Budget (OMB) Circular A-130.&lt;br /&gt;
&lt;br /&gt;
Nothing in this publication should be taken to contradict the standards and guidelines made mandatory and binding on federal agencies by the Secretary of Commerce under statutory authority. Nor should these guidelines be interpreted as altering or superseding the existing authorities of the Secretary of Commerce, Director of OMB, or any other federal official. This publication may be used by nongovernmental organizations on a voluntary basis and is not subject to copyright in the United States. Attribution would, however, be appreciated by NIST.&lt;br /&gt;
&lt;br /&gt;
=== Reports on Computer Systems Technology ===&lt;br /&gt;
&lt;br /&gt;
The NIST Information Technology Laboratory (ITL) promotes the United States economy and public welfare by providing technical leadership for the Nation&#039;s measurement and standards infrastructure. ITL develops tests, test methods, reference data, proof of concept implementations, and technical analyses to advance the development and productive use of information technology.&lt;br /&gt;
&lt;br /&gt;
ITL&#039;s responsibilities include the development of management, administrative, technical, and physical standards and guidelines for the cost-effective security of other than national security-related information and protection of individuals&#039; privacy in federal information systems. The Special Publication 800-series reports on ITL&#039;s research, guidelines, and outreach efforts in information systems security and its collaborative activities with industry, government, and academic organizations.&lt;br /&gt;
&lt;br /&gt;
=== Abstract ===&lt;br /&gt;
&lt;br /&gt;
The protection of Controlled Unclassified Information (CUI) resident in nonfederal systems and organizations is of paramount importance to federal agencies and can directly impact the ability of the federal government to successfully conduct its assigned missions and business operations. This publication provides federal and nonfederal organizations with assessment procedures and a methodology that can be employed to conduct assessments of the CUI security requirements in [[NIST Special Publication 800-171]], &#039;&#039;Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations&#039;&#039;. The assessment procedures are flexible and can be customized to the needs of the organizations and the assessors conducting the assessments. Security assessments can be conducted as self-assessments; independent, third-party assessments; or government-sponsored assessments and can be applied with various degrees of rigor, based on customer-defined depth and coverage attributes. The findings and evidence produced during the security assessments can facilitate risk-based decisions by organizations related to the CUI requirements.&lt;br /&gt;
&lt;br /&gt;
=== Keywords ===&lt;br /&gt;
&lt;br /&gt;
Assessment; Assessment Method; Assessment Object; Assessment Procedure; Assurance; Basic Security Requirement; Controlled Unclassified Information; Coverage; CUI Registry; Depth; Derived Security Requirement; Executive Order 13556; FISMA; NIST Special Publication 800-53; NIST Special Publication 800-53A; Nonfederal Organization; Nonfederal System; Security Assessment; Security Control.&lt;br /&gt;
&lt;br /&gt;
=== Acknowledgements ===&lt;br /&gt;
&lt;br /&gt;
The authors gratefully acknowledge and appreciate the contributions from Jon Boyens, Devin Casey, Chris Enloe, Ned Goren, Gary Guissanie, Jody Jacobs, Jeff Marron, Vicki Michetti, Mark Riddle, Mary Thomas, Matt Scholl, Gary Stoneburner, Patricia Toth, and Patrick Viscuso whose thoughtful and constructive comments improved the quality, thoroughness, and usefulness of this publication. A special note of thanks goes to Jim Foti and Elizabeth Lennon for their superb administrative and technical editing support.&lt;br /&gt;
&lt;br /&gt;
{{Notice|type=note|&#039;&#039;&#039;CAUTIONARY NOTE&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
The generalized assessment procedures described in this publication provide a framework and a starting point for developing specific procedures to assess the CUI security requirements in [[NIST Special Publication 800-171]]. The assessment procedures can be used to generate relevant evidence to determine if the security safeguards employed by organizations are implemented correctly, are operating as intended, and satisfy the CUI security requirements. Organizations have the flexibility to specialize the assessment procedures by selecting the specific assessment methods and the set of assessment objects to achieve the assessment objectives. There is no expectation that all assessment methods and all objects will be used for every assessment. There is also significant flexibility on the scope of the assessment and the degree of rigor applied during the assessment process. The assessment procedures and methods can be applied across a continuum of approaches—including self-assessments; independent, third-party assessments; and assessments conducted by sponsoring organizations (e.g., government agencies). Such approaches may be specified in contracts or in agreements by participating parties.}}&lt;br /&gt;
&lt;br /&gt;
{{Notice|type=note|&#039;&#039;&#039;DEFINITION AND USAGE OF THE TERM INFORMATION SYSTEM&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
Unless otherwise specified by legislation, regulation, or governmentwide policy, the use of the term &#039;&#039;information system&#039;&#039; in this publication is replaced by the term &#039;&#039;system&#039;&#039;. This change reflects a more broad-based and holistic definition of information systems that includes, for example: general purpose information systems; industrial and process control systems; cyber-physical systems; and individual devices that are part of the Internet of Things. As computing platforms and information technologies are increasingly deployed ubiquitously worldwide and systems and components are connected through wired and wireless networks, the susceptibility of Controlled Unclassified Information to loss or compromise grows—as does the potential for adverse consequences resulting from such occurrences.}}&lt;br /&gt;
&lt;br /&gt;
{{Notice|type=note|&#039;&#039;&#039;OTHER RESOURCES TO SUPPORT ASSESSMENTS&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
NIST Special Publication 800-171A is a companion publication developed to support assessments of the CUI security requirements in [[NIST Special Publication 800-171]]. As such, it is the primary and authoritative source of guidance for organizations conducting such assessments. However, since it is recognized that the communities of interest affected by the CUI security requirements are broad and diverse, other supporting assessment guidance may be developed for those communities. For example, the NIST Manufacturing Extension Partnership (MEP) developed Handbook 162, &#039;&#039;NIST MEP Cybersecurity Self-Assessment Handbook for Assessing NIST SP 800-171 Security Requirements in Response to DFARS Cybersecurity Requirements&#039;&#039;. This resource, along with other assessment resources that may be developed in the future, can complement the assessment procedures in NIST Special Publication 800-171A, thus helping sector-specific organizations generate the evidence needed to determine if the CUI security requirements have been satisfied.}}&lt;br /&gt;
&lt;br /&gt;
== Table of Contents ==&lt;br /&gt;
__TOC__&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;CHAPTER ONE&#039;&#039;&#039; Introduction ..... 1&lt;br /&gt;
** 1.1 Purpose and Applicability ..... 1&lt;br /&gt;
** 1.2 Target Audience ..... 2&lt;br /&gt;
** 1.3 Organization of this Special Publication ..... 2&lt;br /&gt;
* &#039;&#039;&#039;CHAPTER TWO&#039;&#039;&#039; The Fundamentals ..... 4&lt;br /&gt;
** 2.1 Assessment Procedures ..... 4&lt;br /&gt;
** 2.2 Assurance Cases ..... 6&lt;br /&gt;
* &#039;&#039;&#039;CHAPTER THREE&#039;&#039;&#039; The Procedures ..... 8&lt;br /&gt;
** 3.1 Access Control ..... 9&lt;br /&gt;
** 3.2 Awareness and Training ..... 19&lt;br /&gt;
** 3.3 Audit and Accountability ..... 21&lt;br /&gt;
** 3.4 Configuration Management ..... 26&lt;br /&gt;
** 3.5 Identification and Authentication ..... 31&lt;br /&gt;
** 3.6 Incident Response ..... 36&lt;br /&gt;
** 3.7 Maintenance ..... 38&lt;br /&gt;
** 3.8 Media Protection ..... 41&lt;br /&gt;
** 3.9 Personnel Security ..... 45&lt;br /&gt;
** 3.10 Physical Protection ..... 46&lt;br /&gt;
** 3.11 Risk Assessment ..... 49&lt;br /&gt;
** 3.12 Security Assessment ..... 51&lt;br /&gt;
** 3.13 System and Communications Protection ..... 53&lt;br /&gt;
** 3.14 System and Information Integrity ..... 61&lt;br /&gt;
* &#039;&#039;&#039;APPENDIX A&#039;&#039;&#039; References ..... 65&lt;br /&gt;
* &#039;&#039;&#039;APPENDIX B&#039;&#039;&#039; Glossary ..... 67&lt;br /&gt;
* &#039;&#039;&#039;APPENDIX C&#039;&#039;&#039; Acronyms ..... 75&lt;br /&gt;
* &#039;&#039;&#039;APPENDIX D&#039;&#039;&#039; Assessment Methods ..... 76&lt;br /&gt;
&lt;br /&gt;
== Errata ==&lt;br /&gt;
&lt;br /&gt;
This table contains changes that have been incorporated into Special Publication 800-171A. Errata updates can include corrections, clarifications, or other minor changes in the publication that are either &#039;&#039;editorial&#039;&#039; or &#039;&#039;substantive&#039;&#039; in nature.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! Date !! Type !! Revision !! Page&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;4&amp;quot; | (No errata entries listed in source document)&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Chapter One: Introduction ==&lt;br /&gt;
&#039;&#039;The need to assess CUI security requirements&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
The protection of unclassified federal information in nonfederal systems and organizations is dependent on the federal government providing a process for identifying the different types of information that are used by federal agencies. Executive Order 13556 established a governmentwide Controlled Unclassified Information (CUI)&amp;lt;ref&amp;gt;&#039;&#039;Controlled Unclassified Information&#039;&#039; is information the Government creates or possesses, or that an entity creates or possesses for or on behalf of the Government, that a law, regulation, or governmentwide policy requires or permits an agency to handle using safeguarding or dissemination controls, excluding information that is classified under Executive Order 13526, &#039;&#039;Classified National Security Information&#039;&#039;, December 29, 2009, or any predecessor or successor order, or the Atomic Energy Act of 1954, as amended.&amp;lt;/ref&amp;gt; Program to standardize the way the executive branch handles unclassified information that requires protection. The implementing regulation for the CUI Program is 32 CFR part 2002, &#039;&#039;Controlled Unclassified Information&#039;&#039;. Only federal information that requires safeguarding or dissemination controls pursuant to federal law, regulation, or governmentwide policy may be designated as CUI.&amp;lt;ref&amp;gt;The CUI Registry is the online repository for information, guidance, policy, and requirements on handling CUI.&amp;lt;/ref&amp;gt; NIST Special Publication 800-171, &#039;&#039;Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations&#039;&#039;, specifies the security requirements to ensure the confidentiality of CUI.&lt;br /&gt;
&lt;br /&gt;
=== 1.1 Purpose and Applicability ===&lt;br /&gt;
&lt;br /&gt;
The purpose of this publication is to provide procedures for assessing the CUI requirements in NIST Special Publication 800-171. Compliance with the security requirements is addressed in CUI guidance and the CUI Federal Acquisition Regulation (FAR)&amp;lt;ref&amp;gt;The CUI Executive Agent is actively engaged in the process of developing a FAR clause that will apply the requirements of the federal CUI regulation and NIST Special Publication 800-171 to contractors.&amp;lt;/ref&amp;gt; or as supplemented by federal agencies (e.g., Department of Defense Federal Acquisition Regulation). Organizations can use the assessment procedures to generate evidence to support the assertion that the security requirements have been satisfied.&lt;br /&gt;
&lt;br /&gt;
The assessment process is an information-gathering and evidence-producing activity to determine the effectiveness of the safeguards intended to meet the set of security requirements specified in NIST Special Publication 800-171. In this context, the information gathered and the evidence produced can be used by an organization to:&lt;br /&gt;
&lt;br /&gt;
* Identify potential problems or shortfalls in the organization&#039;s security and risk management programs;&lt;br /&gt;
* Identify security weaknesses and deficiencies in its systems and in the environments in which those systems operate;&lt;br /&gt;
* Prioritize risk mitigation decisions and activities;&lt;br /&gt;
* Confirm that identified security weaknesses and deficiencies in the system and in the environment of operation have been addressed; and&lt;br /&gt;
* Support continuous monitoring activities and provide information security situational awareness.&lt;br /&gt;
&lt;br /&gt;
The assessment procedures in this publication offer the flexibility to customize assessments based on organizational policies and requirements, known threat and vulnerability information, system and platform dependencies, operational considerations, and tolerance for risk.&amp;lt;ref&amp;gt;The term &#039;&#039;risk&#039;&#039; is used to mean risk to organizational operations (i.e., mission, functions, image, and reputation), organizational assets, individuals, other organizations, and the Nation. See NIST Special Publication 800-39 for additional information on organizational risk management and risk tolerance.&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{{Notice|type=note|&#039;&#039;&#039;THE SCOPE OF CUI SECURITY REQUIREMENT ASSESSMENTS&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
For the CUI security requirements in NIST Special Publication 800-171, nonfederal organizations describe in a &#039;&#039;system security plan&#039;&#039;, how the specified requirements are met or how organizations plan to meet the requirements. The plan describes the system boundary; the environment in which the system operates; how the requirements are implemented; and the relationships with or connections to other systems. The scope of the assessments conducted using the procedures described in this publication are guided and informed by the individual system security plans for the organizational systems processing, storing, or transmitting CUI. The assessments focus on the implementation and effectiveness of the safeguards intended to meet a fixed set of security requirements as defined in NIST Special Publication 800-171.}}&lt;br /&gt;
&lt;br /&gt;
=== 1.2 Target Audience ===&lt;br /&gt;
&lt;br /&gt;
This publication serves system, information security, and privacy&amp;lt;ref&amp;gt;References to privacy in this publication are made &#039;&#039;only&#039;&#039; in the context of where security and privacy considerations overlap—that is, in the security objective of &#039;&#039;confidentiality&#039;&#039;, which generally supports privacy and the protection of personally identifiable information from unauthorized disclosure. NIST Internal Report 8062 provides additional information on the overlapping and complementary nature of security and privacy disciplines.&amp;lt;/ref&amp;gt; professionals including individuals with:&lt;br /&gt;
&lt;br /&gt;
* System development responsibilities (e.g., program managers, system developers, system owners, systems integrators, system security engineers);&lt;br /&gt;
* Information security assessment and monitoring responsibilities (e.g., system evaluators, assessors, independent verifiers/validators, auditors, analysts, system owners);&lt;br /&gt;
* Information security, privacy, risk management, governance, and oversight responsibilities (e.g., authorizing officials, chief information officers, chief privacy officers, chief information security officers, system managers, information security managers); and&lt;br /&gt;
* Information security implementation and operational responsibilities (e.g., system owners, information owners/stewards, mission and business owners, systems administrators, system security officers).&lt;br /&gt;
&lt;br /&gt;
=== 1.3 Organization of this Special Publication ===&lt;br /&gt;
&lt;br /&gt;
The remainder of this special publication is organized as follows:&lt;br /&gt;
&lt;br /&gt;
* [[#Chapter Two: The Fundamentals|Chapter Two]] describes the fundamental concepts associated with assessments of CUI security requirements including assessment procedures, methods, objects, and assurance cases that can be created using evidence produced during assessments.&lt;br /&gt;
* [[#Chapter Three: The Procedures|Chapter Three]] provides a catalog of assessment procedures for the fourteen families of CUI security requirements in NIST Special Publication 800-171, including assessment objectives and potential assessment methods and objects for each procedure.&lt;br /&gt;
* Supporting appendices provide additional assessment-related information including general references; definitions and terms; acronyms; and a description of the assessment methods used in assessment procedures.&lt;br /&gt;
&lt;br /&gt;
== Chapter Two: The Fundamentals ==&lt;br /&gt;
&#039;&#039;Basic concepts for assessments of CUI security requirements&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
The CUI security requirements in NIST Special Publication 800-171 are organized into fourteen families. Each family contains the requirements related to the general security topic of the family. Table 1 lists the CUI security requirement families addressed in this publication. The assessment procedures in [[#Chapter Three: The Procedures|Chapter Three]] are grouped by family designations to help ensure completeness and consistency of assessments.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;TABLE 1: CUI SECURITY REQUIREMENT FAMILIES&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! Family !! Family&lt;br /&gt;
|-&lt;br /&gt;
| Access Control || Media Protection&lt;br /&gt;
|-&lt;br /&gt;
| Awareness and Training || Personnel Security&lt;br /&gt;
|-&lt;br /&gt;
| Audit and Accountability || Physical Protection&lt;br /&gt;
|-&lt;br /&gt;
| Configuration Management || Risk Assessment&lt;br /&gt;
|-&lt;br /&gt;
| Identification and Authentication || Security Assessment&lt;br /&gt;
|-&lt;br /&gt;
| Incident Response || System and Communications Protection&lt;br /&gt;
|-&lt;br /&gt;
| Maintenance || System and Information Integrity&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== 2.1 Assessment Procedures ===&lt;br /&gt;
&lt;br /&gt;
An assessment procedure consists of an assessment &#039;&#039;objective&#039;&#039; and a set of potential assessment &#039;&#039;methods&#039;&#039; and assessment &#039;&#039;objects&#039;&#039; that can be used to conduct the assessment. Each assessment objective includes a determination statement related to the CUI security requirement that is the subject of the assessment. The determination statements are linked to the content of the CUI security requirements to ensure traceability of the assessment results to the requirements. The application of an assessment procedure to a security requirement produces assessment &#039;&#039;findings&#039;&#039;. These findings reflect, or are subsequently used, to help determine if the security requirement has been satisfied.&lt;br /&gt;
&lt;br /&gt;
Assessment objects identify the specific items being assessed and can include specifications, mechanisms, activities, and individuals. Specifications are the document-based artifacts (e.g., policies, procedures, security plans, security requirements, functional specifications, architectural designs) associated with a system. Mechanisms are the specific hardware, software, or firmware safeguards employed within a system. Activities are the protection-related actions supporting a system that involve people (e.g., conducting system backup operations, exercising a contingency plan, and monitoring network traffic). Individuals, or groups of individuals, are people applying the specifications, mechanisms, or activities described above.&lt;br /&gt;
&lt;br /&gt;
The assessment methods define the nature and the extent of the assessor&#039;s actions. The methods include &#039;&#039;examine&#039;&#039;, &#039;&#039;interview&#039;&#039;, and &#039;&#039;test&#039;&#039;. The examine method is the process of reviewing, inspecting, observing, studying, or analyzing assessment objects (i.e., specifications, mechanisms, activities). The purpose of the examine method is to facilitate understanding, achieve clarification, or obtain evidence. The interview method is the process of holding discussions with individuals or groups of individuals to facilitate understanding, achieve clarification, or obtain evidence. And finally, the test method is the process of exercising assessment objects (i.e., activities, mechanisms) under specified conditions to compare actual with expected behavior. In all three assessment methods, the results are used in making specific determinations called for in the determination statements and thereby achieving the objectives for the assessment procedure.&lt;br /&gt;
&lt;br /&gt;
The assessment methods described above have associated attributes of &#039;&#039;depth&#039;&#039; and &#039;&#039;coverage&#039;&#039;, which define the level of effort for the assessment. These attributes provide a means to define the rigor and scope of the assessment for the increased assurance of security requirements. A description of assessment methods and objects is provided in [[#Appendix D: Assessment Methods|Appendix D]].&amp;lt;ref&amp;gt;Additional information on assessment methods and objects and the attributes of depth and coverage is provided in NIST Special Publication 800-53A.&amp;lt;/ref&amp;gt; Figure 1 illustrates an example of an assessment procedure for CUI security requirement 3.1.3 from NIST Special Publication 800-171.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;FIGURE 1: ASSESSMENT PROCEDURE FOR CUI SECURITY REQUIREMENT&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
{{Requirement&lt;br /&gt;
|id=3.1.3&lt;br /&gt;
|title=Control the flow of CUI in accordance with approved authorizations.&lt;br /&gt;
|objectives=&lt;br /&gt;
* 3.1.3[a] information flow control policies are defined.&lt;br /&gt;
* 3.1.3[b] methods and enforcement mechanisms for controlling the flow of CUI are defined.&lt;br /&gt;
* 3.1.3[c] designated sources and destinations (e.g., networks, individuals, and devices) for CUI within the system and between interconnected systems are identified.&lt;br /&gt;
* 3.1.3[d] authorizations for controlling the flow of CUI are defined.&lt;br /&gt;
* 3.1.3[e] approved authorizations for controlling the flow of CUI are enforced.&lt;br /&gt;
|examine=Access control policy; information flow control policies; procedures addressing information flow enforcement; system security plan; system design documentation; system configuration settings and associated documentation; list of information flow authorizations; system baseline configuration; system audit logs and records; other relevant documents or records.&lt;br /&gt;
|interview=System or network administrators; personnel with information security responsibilities; system developers.&lt;br /&gt;
|test=Mechanisms implementing information flow enforcement policy.&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
Organizations are not expected to employ &#039;&#039;all&#039;&#039; assessment methods and objects contained within the assessment procedures identified in this publication. Rather, organizations have the flexibility to determine the level of effort needed and the assurance required for an assessment (e.g., which assessment methods and assessment objects are deemed to be the most useful in obtaining the desired results). This determination is made based on how the organization can accomplish the assessment objectives in the most cost-effective manner and with sufficient confidence to support the determination that the CUI requirements have been satisfied.&lt;br /&gt;
&lt;br /&gt;
=== 2.2 Assurance Cases ===&lt;br /&gt;
&lt;br /&gt;
Building an effective assurance case for determining compliance to CUI security requirements is a process that involves compiling evidence from a variety of sources and conducting different types of activities during an assessment. An assurance case is a body of evidence organized into an argument demonstrating that some claim about a system is true. For assessments conducted using the procedures in this publication, that claim is &#039;&#039;compliance&#039;&#039; with the security requirements specified in NIST Special Publication 800-171. Assessors gather evidence during the assessment process to allow designated officials&amp;lt;ref&amp;gt;A &#039;&#039;designated official&#039;&#039; is an official, either internal or external to the nonfederal organization, with the responsibility to determine organizational compliance to CUI security requirements.&amp;lt;/ref&amp;gt; to make objective determinations about compliance to the CUI security requirements. The evidence needed to make such determinations can be obtained from various sources including self-assessments, independent third-party assessments, or other types of assessments, depending on the needs of the organization establishing the requirements and the organization conducting the assessments.&lt;br /&gt;
&lt;br /&gt;
For example, many technical security requirements are satisfied by security capabilities that are built in to commercial information technology products and systems. Product assessments are typically conducted by independent, third-party testing organizations.&amp;lt;ref&amp;gt;Examples include Common Criteria Testing Laboratories evaluating commercial IT products in accordance with ISO/IEC 15408 and Cryptographic Module Validation Program Testing Laboratories evaluating cryptographic modules in accordance with Federal Information Processing Standard (FIPS) 140.&amp;lt;/ref&amp;gt; These assessments examine the security functions of products and established configuration settings. Assessments can also be conducted to demonstrate compliance to industry, national, or international security standards as well as developer and vendor claims. Since many information technology products are assessed by commercial testing organizations and then subsequently deployed in hundreds of thousands of systems, these types of assessments can be carried out at a greater level of depth and provide deeper insights into the security capabilities of the products.&lt;br /&gt;
&lt;br /&gt;
Ultimately, evidence needed to determine compliance comes from the implementation of the selected safeguards to satisfy the CUI security requirements and from the assessments of that implementation. Assessors can build on previously developed materials that started with the specification of the organization&#039;s information security needs and is further developed during the design, development, and implementation of the system and system components. These materials, developed while implementing security throughout the life cycle of the system, provide the initial evidence for an assurance case.&lt;br /&gt;
&lt;br /&gt;
Assessments can be conducted by systems developers, systems integrators, auditors, system owners, or the security staffs of organizations. The assessors or assessment teams bring together available information about the system such as the results from individual component product assessments. The assessors can conduct additional system-level assessments using the procedures and methods contained in this publication and based on the implementation information provided by the nonfederal organization in its system security plan. System assessments can be used to compile and evaluate the evidence needed by organizations to help determine the effectiveness of the safeguards implemented to protect CUI; the actions needed to mitigate security-related risks to the organization; and compliance to the CUI security requirements.&lt;br /&gt;
&lt;br /&gt;
{{Notice|type=note|&#039;&#039;&#039;APPLICABLE CUI SECURITY REQUIREMENTS&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
The system security plan is used to describe how the organization meets or plans to meet the CUI security requirements. Any security requirements that are deemed &#039;&#039;non-applicable&#039;&#039; by the organization (e.g., no wireless capability in the system or the system component processing, storing, or transmitting CUI), are documented as such in the system security plan. Once the system security plan is completed, a security assessment plan can be developed using the assessment procedures described in Chapter Three and tailoring those procedures as needed. An assessment procedure is developed for every CUI security requirement that is applicable to the system, system component, or the organization. Conversely, security requirements that are deemed non-applicable in the system security plan are &#039;&#039;not&#039;&#039; assessed.}}&lt;br /&gt;
&lt;br /&gt;
== Chapter Three: The Procedures ==&lt;br /&gt;
&#039;&#039;Assessment procedures, methods, and objects for CUI security requirements&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
This chapter provides assessment procedures for all CUI security requirements defined in NIST Special Publication 800-171. The assessment procedures are organized into fourteen families. Organizations conducting CUI security requirement assessments can build their assessment plans using the information provided in the generic assessment procedures—selecting the specific assessment methods and objects that meet the organization&#039;s needs. Organizations also have flexibility in defining the level of rigor and detail associated with the assessment based on the assurance requirements of the organization. [[#Appendix D: Assessment Methods|Appendix D]] provides additional information on the different levels of rigor and detail for assessments.&lt;br /&gt;
&lt;br /&gt;
The assessment objective defined for each assessment procedure is achieved by applying the designated assessment methods to the selected assessment objects and compiling/producing the evidence necessary to make the determination associated with each assessment objective. Each determination statement contained within an assessment procedure produces one of the following findings: &#039;&#039;satisfied&#039;&#039; or &#039;&#039;other than satisfied&#039;&#039;. A finding of &amp;quot;satisfied&amp;quot; indicates that for the security requirement addressed by the determination statement, the assessment information obtained (i.e., the evidence collected) indicates that the assessment objective has been met producing a fully acceptable result. A finding of &amp;quot;other than satisfied&amp;quot; indicates that for the security requirement addressed by the determination statement, the assessment findings obtained indicate potential anomalies that may need to be addressed by the organization. A finding of &amp;quot;other than satisfied&amp;quot; may also indicate that for reasons specified in the assessment report, the assessor was unable to obtain sufficient information to make the determination called for in the determination statement.&lt;br /&gt;
&lt;br /&gt;
For assessment findings that are other than satisfied, organizations may define subcategories of findings indicating the severity or criticality of the weaknesses or deficiencies discovered and the potential adverse effects of those weaknesses or deficiencies on organizational missions and/or business functions. Defining such subcategories can help to establish priorities for needed risk mitigation actions.&lt;br /&gt;
&lt;br /&gt;
{{Notice|type=note|&#039;&#039;&#039;CAUTIONARY NOTE&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
The content in this publication can be used for many different assessment-related purposes in determining organizational compliance to the CUI security requirements. The broad range of potential assessment methods and objects listed in this publication do not necessarily reflect, and should not be directly associated with, actual compliance or noncompliance. Rather, the selection of specific assessment methods and objects from the list provided, can help generate a picture of overall compliance with the CUI security requirements. There is no expectation about the number of methods or objects needed to determine compliance to the CUI security requirements. Moreover, the entire list of potential assessment objects should not be viewed as required artifacts needed to determine compliance to the requirements. Organizations have the flexibility to determine the specific methods and objects sufficient to obtain the needed evidence to support claims of compliance.}}&lt;br /&gt;
&lt;br /&gt;
=== 3.1 Access Control ===&lt;br /&gt;
&lt;br /&gt;
{{Requirement&lt;br /&gt;
|id=3.1.1&lt;br /&gt;
|title=Limit system access to authorized users, processes acting on behalf of authorized users, and devices (including other systems).&lt;br /&gt;
|objectives=&lt;br /&gt;
* 3.1.1[a] authorized users are identified.&lt;br /&gt;
* 3.1.1[b] processes acting on behalf of authorized users are identified.&lt;br /&gt;
* 3.1.1[c] devices (and other systems) authorized to connect to the system are identified.&lt;br /&gt;
* 3.1.1[d] system access is limited to authorized users.&lt;br /&gt;
* 3.1.1[e] system access is limited to processes acting on behalf of authorized users.&lt;br /&gt;
* 3.1.1[f] system access is limited to authorized devices (including other systems).&lt;br /&gt;
|examine=Access control policy; procedures addressing account management; system security plan; system design documentation; system configuration settings and associated documentation; list of active system accounts and the name of the individual associated with each account; notifications or records of recently transferred, separated, or terminated employees; list of conditions for group and role membership; list of recently disabled system accounts along with the name of the individual associated with each account; access authorization records; account management compliance reviews; system monitoring records; system audit logs and records; list of devices and systems authorized to connect to organizational systems; other relevant documents or records.&lt;br /&gt;
|interview=Personnel with account management responsibilities; system or network administrators; personnel with information security responsibilities.&lt;br /&gt;
|test=Organizational processes for managing system accounts; mechanisms for implementing account management.&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
{{Requirement&lt;br /&gt;
|id=3.1.2&lt;br /&gt;
|title=Limit system access to the types of transactions and functions that authorized users are permitted to execute.&lt;br /&gt;
|objectives=&lt;br /&gt;
* 3.1.2[a] the types of transactions and functions that authorized users are permitted to execute are defined.&lt;br /&gt;
* 3.1.2[b] system access is limited to the defined types of transactions and functions for authorized users.&lt;br /&gt;
|examine=Access control policy; procedures addressing access enforcement; system security plan; system design documentation; list of approved authorizations including remote access authorizations; system audit logs and records; system configuration settings and associated documentation; other relevant documents or records.&lt;br /&gt;
|interview=Personnel with access enforcement responsibilities; system or network administrators; personnel with information security responsibilities; system developers.&lt;br /&gt;
|test=Mechanisms implementing access control policy.&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
{{Requirement&lt;br /&gt;
|id=3.1.3&lt;br /&gt;
|title=Control the flow of CUI in accordance with approved authorizations.&lt;br /&gt;
|objectives=&lt;br /&gt;
* 3.1.3[a] information flow control policies are defined.&lt;br /&gt;
* 3.1.3[b] methods and enforcement mechanisms for controlling the flow of CUI are defined.&lt;br /&gt;
* 3.1.3[c] designated sources and destinations (e.g., networks, individuals, and devices) for CUI within the system and between interconnected systems are identified.&lt;br /&gt;
* 3.1.3[d] authorizations for controlling the flow of CUI are defined.&lt;br /&gt;
* 3.1.3[e] approved authorizations for controlling the flow of CUI are enforced.&lt;br /&gt;
|examine=Access control policy; information flow control policies; procedures addressing information flow enforcement; system security plan; system design documentation; system configuration settings and associated documentation; list of information flow authorizations; system baseline configuration; system audit logs and records; other relevant documents or records.&lt;br /&gt;
|interview=System or network administrators; personnel with information security responsibilities; system developers.&lt;br /&gt;
|test=Mechanisms implementing information flow enforcement policy.&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
{{Requirement&lt;br /&gt;
|id=3.1.4&lt;br /&gt;
|title=Separate the duties of individuals to reduce the risk of malevolent activity without collusion.&lt;br /&gt;
|objectives=&lt;br /&gt;
* 3.1.4[a] the duties of individuals requiring separation are defined.&lt;br /&gt;
* 3.1.4[b] responsibilities for duties that require separation are assigned to separate individuals.&lt;br /&gt;
* 3.1.4[c] access privileges that enable individuals to exercise the duties that require separation are granted to separate individuals.&lt;br /&gt;
|examine=Access control policy; procedures addressing divisions of responsibility and separation of duties; system security plan; system configuration settings and associated documentation; list of divisions of responsibility and separation of duties; system access authorizations; system audit logs and records; other relevant documents or records.&lt;br /&gt;
|interview=Personnel with responsibilities for defining divisions of responsibility and separation of duties; personnel with information security responsibilities; system or network administrators.&lt;br /&gt;
|test=Mechanisms implementing separation of duties policy.&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
{{Requirement&lt;br /&gt;
|id=3.1.5&lt;br /&gt;
|title=Employ the principle of least privilege, including for specific security functions and privileged accounts.&lt;br /&gt;
|objectives=&lt;br /&gt;
* 3.1.5[a] privileged accounts are identified.&lt;br /&gt;
* 3.1.5[b] access to privileged accounts is authorized in accordance with the principle of least privilege.&lt;br /&gt;
* 3.1.5[c] security functions are identified.&lt;br /&gt;
* 3.1.5[d] access to security functions is authorized in accordance with the principle of least privilege.&lt;br /&gt;
|examine=Access control policy; procedures addressing account management; system security plan; system design documentation; system configuration settings and associated documentation; list of active system accounts and the name of the individual associated with each account; list of conditions for group and role membership; notifications or records of recently transferred, separated, or terminated employees; list of recently disabled system accounts along with the name of the individual associated with each account; access authorization records; account management compliance reviews; system monitoring/audit records; procedures addressing least privilege; list of security functions (deployed in hardware, software, and firmware) and security-relevant information for which access is to be explicitly authorized; list of system-generated privileged accounts; list of system administration personnel; other relevant documents or records.&lt;br /&gt;
|interview=Personnel with account management responsibilities; system or network administrators; personnel with information security responsibilities; personnel with responsibilities for defining least privileges necessary to accomplish specified tasks.&lt;br /&gt;
|test=Organizational processes for managing system accounts; mechanisms for implementing account management; mechanisms implementing least privilege functions; mechanisms prohibiting privileged access to the system.&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
{{Requirement&lt;br /&gt;
|id=3.1.6&lt;br /&gt;
|title=Use non-privileged accounts or roles when accessing nonsecurity functions.&lt;br /&gt;
|objectives=&lt;br /&gt;
* 3.1.6[a] nonsecurity functions are identified.&lt;br /&gt;
* 3.1.6[b] users are required to use non-privileged accounts or roles when accessing nonsecurity functions.&lt;br /&gt;
|examine=Access control policy; procedures addressing least privilege; system security plan; list of system-generated security functions assigned to system accounts or roles; system configuration settings and associated documentation; system audit logs and records; other relevant documents or records.&lt;br /&gt;
|interview=Personnel with responsibilities for defining least privileges necessary to accomplish specified organizational tasks; personnel with information security responsibilities; system or network administrators.&lt;br /&gt;
|test=Mechanisms implementing least privilege functions.&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
{{Requirement&lt;br /&gt;
|id=3.1.7&lt;br /&gt;
|title=Prevent non-privileged users from executing privileged functions and capture the execution of such functions in audit logs.&lt;br /&gt;
|objectives=&lt;br /&gt;
* 3.1.7[a] privileged functions are defined.&lt;br /&gt;
* 3.1.7[b] non-privileged users are defined.&lt;br /&gt;
* 3.1.7[c] non-privileged users are prevented from executing privileged functions.&lt;br /&gt;
* 3.1.7[d] the execution of privileged functions is captured in audit logs.&lt;br /&gt;
|examine=Access control policy; procedures addressing least privilege; system security plan; system design documentation; list of privileged functions and associated user account assignments; system configuration settings and associated documentation; system audit logs and records; other relevant documents or records.&lt;br /&gt;
|interview=Personnel with responsibilities for defining least privileges necessary to accomplish specified tasks; personnel with information security responsibilities; system developers.&lt;br /&gt;
|test=Mechanisms implementing least privilege functions for non-privileged users; mechanisms auditing the execution of privileged functions.&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
{{Requirement&lt;br /&gt;
|id=3.1.8&lt;br /&gt;
|title=Limit unsuccessful logon attempts.&lt;br /&gt;
|objectives=&lt;br /&gt;
* 3.1.8[a] the means of limiting unsuccessful logon attempts is defined.&lt;br /&gt;
* 3.1.8[b] the defined means of limiting unsuccessful logon attempts is implemented.&lt;br /&gt;
|examine=Access control policy; procedures addressing unsuccessful logon attempts; system security plan; system design documentation; system configuration settings and associated documentation; system audit logs and records; other relevant documents or records.&lt;br /&gt;
|interview=Personnel with information security responsibilities; system developers; system or network administrators.&lt;br /&gt;
|test=Mechanisms implementing access control policy for unsuccessful logon attempts.&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
{{Requirement&lt;br /&gt;
|id=3.1.9&lt;br /&gt;
|title=Provide privacy and security notices consistent with applicable CUI rules.&lt;br /&gt;
|objectives=&lt;br /&gt;
* 3.1.9[a] privacy and security notices required by CUI-specified rules are identified, consistent, and associated with the specific CUI category.&lt;br /&gt;
* 3.1.9[b] privacy and security notices are displayed.&lt;br /&gt;
|examine=Privacy and security policies, procedures addressing system use notification; documented approval of system use notification messages or banners; system audit logs and records; system design documentation; user acknowledgements of notification message or banner; system security plan; system use notification messages; system configuration settings and associated documentation; other relevant documents or records.&lt;br /&gt;
|interview=System or network administrators; personnel with information security responsibilities; personnel with responsibility for providing legal advice; system developers.&lt;br /&gt;
|test=Mechanisms implementing system use notification.&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
{{Requirement&lt;br /&gt;
|id=3.1.10&lt;br /&gt;
|title=Use session lock with pattern-hiding displays to prevent access and viewing of data after a period of inactivity.&lt;br /&gt;
|objectives=&lt;br /&gt;
* 3.1.10[a] the period of inactivity after which the system initiates a session lock is defined.&lt;br /&gt;
* 3.1.10[b] access to the system and viewing of data is prevented by initiating a session lock after the defined period of inactivity.&lt;br /&gt;
* 3.1.10[c] previously visible information is concealed via a pattern-hiding display after the defined period of inactivity.&lt;br /&gt;
|examine=Access control policy; procedures addressing session lock; procedures addressing identification and authentication; system design documentation; system configuration settings and associated documentation; system security plan; other relevant documents or records.&lt;br /&gt;
|interview=System or network administrators; personnel with information security responsibilities; system developers.&lt;br /&gt;
|test=Mechanisms implementing access control policy for session lock.&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
{{Requirement&lt;br /&gt;
|id=3.1.11&lt;br /&gt;
|title=Terminate (automatically) a user session after a defined condition.&lt;br /&gt;
|objectives=&lt;br /&gt;
* 3.1.11[a] conditions requiring a user session to terminate are defined.&lt;br /&gt;
* 3.1.11[b] a user session is automatically terminated after any of the defined conditions occur.&lt;br /&gt;
|examine=Access control policy; procedures addressing session termination; system design documentation; system security plan; system configuration settings and associated documentation; list of conditions or trigger events requiring session disconnect; system audit logs and records; other relevant documents or records.&lt;br /&gt;
|interview=System or network administrators; personnel with information security responsibilities; system developers.&lt;br /&gt;
|test=Mechanisms implementing user session termination.&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
{{Requirement&lt;br /&gt;
|id=3.1.12&lt;br /&gt;
|title=Monitor and control remote access sessions.&lt;br /&gt;
|objectives=&lt;br /&gt;
* 3.1.12[a] remote access sessions are permitted.&lt;br /&gt;
* 3.1.12[b] the types of permitted remote access are identified.&lt;br /&gt;
* 3.1.12[c] remote access sessions are controlled.&lt;br /&gt;
* 3.1.12[d] remote access sessions are monitored.&lt;br /&gt;
|examine=Access control policy; procedures addressing remote access implementation and usage (including restrictions); configuration management plan; system security plan; system design documentation; system configuration settings and associated documentation; remote access authorizations; system audit logs and records; other relevant documents or records.&lt;br /&gt;
|interview=Personnel with responsibilities for managing remote access connections; system or network administrators; personnel with information security responsibilities.&lt;br /&gt;
|test=Remote access management capability for the system.&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
{{Requirement&lt;br /&gt;
|id=3.1.13&lt;br /&gt;
|title=Employ cryptographic mechanisms to protect the confidentiality of remote access sessions.&lt;br /&gt;
|objectives=&lt;br /&gt;
* 3.1.13[a] cryptographic mechanisms to protect the confidentiality of remote access sessions are identified.&lt;br /&gt;
* 3.1.13[b] cryptographic mechanisms to protect the confidentiality of remote access sessions are implemented.&lt;br /&gt;
|examine=Access control policy; procedures addressing remote access to the system; system security plan; system design documentation; system configuration settings and associated documentation; cryptographic mechanisms and associated configuration documentation; system audit logs and records; other relevant documents or records.&lt;br /&gt;
|interview=System or network administrators; personnel with information security responsibilities; system developers.&lt;br /&gt;
|test=Cryptographic mechanisms protecting remote access sessions.&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
{{Requirement&lt;br /&gt;
|id=3.1.14&lt;br /&gt;
|title=Route remote access via managed access control points.&lt;br /&gt;
|objectives=&lt;br /&gt;
* 3.1.14[a] managed access control points are identified and implemented.&lt;br /&gt;
* 3.1.14[b] remote access is routed through managed network access control points.&lt;br /&gt;
|examine=Access control policy; procedures addressing remote access to the system; system security plan; system design documentation; list of all managed network access control points; system configuration settings and associated documentation; system audit logs and records; other relevant documents or records.&lt;br /&gt;
|interview=System or network administrators; personnel with information security responsibilities.&lt;br /&gt;
|test=Mechanisms routing all remote accesses through managed network access control points.&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
{{Requirement&lt;br /&gt;
|id=3.1.15&lt;br /&gt;
|title=Authorize remote execution of privileged commands and remote access to security-relevant information.&lt;br /&gt;
|objectives=&lt;br /&gt;
* 3.1.15[a] privileged commands authorized for remote execution are identified.&lt;br /&gt;
* 3.1.15[b] security-relevant information authorized to be accessed remotely is identified.&lt;br /&gt;
* 3.1.15[c] the execution of the identified privileged commands via remote access is authorized.&lt;br /&gt;
* 3.1.15[d] access to the identified security-relevant information via remote access is authorized.&lt;br /&gt;
|examine=Access control policy; procedures addressing remote access to the system; system configuration settings and associated documentation; system security plan; system audit logs and records; other relevant documents or records.&lt;br /&gt;
|interview=System or network administrators; personnel with information security responsibilities.&lt;br /&gt;
|test=Mechanisms implementing remote access management.&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
{{Requirement&lt;br /&gt;
|id=3.1.16&lt;br /&gt;
|title=Authorize wireless access prior to allowing such connections.&lt;br /&gt;
|objectives=&lt;br /&gt;
* 3.1.16[a] wireless access points are identified.&lt;br /&gt;
* 3.1.16[b] wireless access is authorized prior to allowing such connections.&lt;br /&gt;
|examine=Access control policy; configuration management plan; procedures addressing wireless access implementation and usage (including restrictions); system security plan; system design documentation; system configuration settings and associated documentation; wireless access authorizations; system audit logs and records; other relevant documents or records.&lt;br /&gt;
|interview=Personnel with responsibilities for managing wireless access connections; personnel with information security responsibilities.&lt;br /&gt;
|test=Wireless access management capability for the system.&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
{{Requirement&lt;br /&gt;
|id=3.1.17&lt;br /&gt;
|title=Protect wireless access using authentication and encryption.&lt;br /&gt;
|objectives=&lt;br /&gt;
* 3.1.17[a] wireless access to the system is protected using authentication.&lt;br /&gt;
* 3.1.17[b] wireless access to the system is protected using encryption.&lt;br /&gt;
|examine=Access control policy; system design documentation; procedures addressing wireless implementation and usage (including restrictions); system security plan; system configuration settings and associated documentation; system audit logs and records; other relevant documents or records.&lt;br /&gt;
|interview=System or network administrators; personnel with information security responsibilities; system developers.&lt;br /&gt;
|test=Mechanisms implementing wireless access protections to the system.&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
{{Requirement&lt;br /&gt;
|id=3.1.18&lt;br /&gt;
|title=Control connection of mobile devices.&lt;br /&gt;
|objectives=&lt;br /&gt;
* 3.1.18[a] mobile devices that process, store, or transmit CUI are identified.&lt;br /&gt;
* 3.1.18[b] mobile device connections are authorized.&lt;br /&gt;
* 3.1.18[c] mobile device connections are monitored and logged.&lt;br /&gt;
|examine=Access control policy; authorizations for mobile device connections to organizational systems; procedures addressing access control for mobile device usage (including restrictions); system design documentation; configuration management plan; system security plan; system audit logs and records; system configuration settings and associated documentation; other relevant documents or records.&lt;br /&gt;
|interview=Personnel using mobile devices to access organizational systems; system or network administrators; personnel with information security responsibilities.&lt;br /&gt;
|test=Access control capability authorizing mobile device connections to organizational systems.&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
{{Requirement&lt;br /&gt;
|id=3.1.19&lt;br /&gt;
|title=Encrypt CUI on mobile devices and mobile computing platforms.&lt;br /&gt;
|objectives=&lt;br /&gt;
* 3.1.19[a] mobile devices and mobile computing platforms that process, store, or transmit CUI are identified.&lt;br /&gt;
* 3.1.19[b] encryption is employed to protect CUI on identified mobile devices and mobile computing platforms.&lt;br /&gt;
|examine=Access control policy; procedures addressing access control for mobile devices; system design documentation; system configuration settings and associated documentation; encryption mechanisms and associated configuration documentation; system security plan; system audit logs and records; other relevant documents or records.&lt;br /&gt;
|interview=Personnel with access control responsibilities for mobile devices; system or network administrators; personnel with information security responsibilities.&lt;br /&gt;
|test=Encryption mechanisms protecting confidentiality of information on mobile devices.&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
{{Requirement&lt;br /&gt;
|id=3.1.20&lt;br /&gt;
|title=Verify and control/limit connections to and use of external systems.&lt;br /&gt;
|objectives=&lt;br /&gt;
* 3.1.20[a] connections to external systems are identified.&lt;br /&gt;
* 3.1.20[b] the use of external systems is identified.&lt;br /&gt;
* 3.1.20[c] connections to external systems are verified.&lt;br /&gt;
* 3.1.20[d] the use of external systems is verified.&lt;br /&gt;
* 3.1.20[e] connections to external systems are controlled/limited.&lt;br /&gt;
* 3.1.20[f] the use of external systems is controlled/limited.&lt;br /&gt;
|examine=Access control policy; procedures addressing the use of external systems; terms and conditions for external systems; system security plan; list of applications accessible from external systems; system configuration settings and associated documentation; system connection or processing agreements; account management documents; other relevant documents or records.&lt;br /&gt;
|interview=Personnel with responsibilities for defining terms and conditions for use of external systems to access organizational systems; system or network administrators; personnel with information security responsibilities.&lt;br /&gt;
|test=Mechanisms implementing terms and conditions on use of external systems.&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
{{Requirement&lt;br /&gt;
|id=3.1.21&lt;br /&gt;
|title=Limit use of portable storage devices on external systems.&lt;br /&gt;
|objectives=&lt;br /&gt;
* 3.1.21[a] the use of portable storage devices containing CUI on external systems is identified and documented.&lt;br /&gt;
* 3.1.21[b] limits on the use of portable storage devices containing CUI on external systems are defined.&lt;br /&gt;
* 3.1.21[c] the use of portable storage devices containing CUI on external systems is limited as defined.&lt;br /&gt;
|examine=Access control policy; procedures addressing the use of external systems; system security plan; system configuration settings and associated documentation; system connection or processing agreements; account management documents; other relevant documents or records.&lt;br /&gt;
|interview=Personnel with responsibilities for restricting or prohibiting use of organization-controlled storage devices on external systems; system or network administrators; personnel with information security responsibilities.&lt;br /&gt;
|test=Mechanisms implementing restrictions on use of portable storage devices.&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
{{Requirement&lt;br /&gt;
|id=3.1.22&lt;br /&gt;
|title=Control CUI posted or processed on publicly accessible systems.&lt;br /&gt;
|objectives=&lt;br /&gt;
* 3.1.22[a] individuals authorized to post or process information on publicly accessible systems are identified.&lt;br /&gt;
* 3.1.22[b] procedures to ensure CUI is not posted or processed on publicly accessible systems are identified.&lt;br /&gt;
* 3.1.22[c] a review process is in place prior to posting of any content to publicly accessible systems.&lt;br /&gt;
* 3.1.22[d] content on publicly accessible systems is reviewed to ensure that it does not include CUI.&lt;br /&gt;
* 3.1.22[e] mechanisms are in place to remove and address improper posting of CUI.&lt;br /&gt;
|examine=Access control policy; procedures addressing publicly accessible content; system security plan; list of users authorized to post publicly accessible content on organizational systems; training materials and/or records; records of publicly accessible information reviews; records of response to nonpublic information on public websites; system audit logs and records; security awareness training records; other relevant documents or records.&lt;br /&gt;
|interview=Personnel with responsibilities for managing publicly accessible information posted on organizational systems; personnel with information security responsibilities.&lt;br /&gt;
|test=Mechanisms implementing management of publicly accessible content.&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
=== 3.2 Awareness and Training ===&lt;br /&gt;
&lt;br /&gt;
{{Requirement&lt;br /&gt;
|id=3.2.1&lt;br /&gt;
|title=Ensure that managers, systems administrators, and users of organizational systems are made aware of the security risks associated with their activities and of the applicable policies, standards, and procedures related to the security of those systems.&lt;br /&gt;
|objectives=&lt;br /&gt;
* 3.2.1[a] security risks associated with organizational activities involving CUI are identified.&lt;br /&gt;
* 3.2.1[b] policies, standards, and procedures related to the security of the system are identified.&lt;br /&gt;
* 3.2.1[c] managers, systems administrators, and users of the system are made aware of the security risks associated with their activities.&lt;br /&gt;
* 3.2.1[d] managers, systems administrators, and users of the system are made aware of the applicable policies, standards, and procedures related to the security of the system.&lt;br /&gt;
|examine=Security awareness and training policy; procedures addressing security awareness training implementation; relevant codes of federal regulations; security awareness training curriculum; security awareness training materials; system security plan; training records; other relevant documents or records.&lt;br /&gt;
|interview=Personnel with responsibilities for security awareness training; personnel with information security responsibilities; personnel composing the general system user community; personnel with responsibilities for role-based awareness training.&lt;br /&gt;
|test=Mechanisms managing security awareness training; mechanisms managing role-based security training.&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
{{Requirement&lt;br /&gt;
|id=3.2.2&lt;br /&gt;
|title=Ensure that personnel are trained to carry out their assigned information security-related duties and responsibilities.&lt;br /&gt;
|objectives=&lt;br /&gt;
* 3.2.2[a] information security-related duties, roles, and responsibilities are defined.&lt;br /&gt;
* 3.2.2[b] information security-related duties, roles, and responsibilities are assigned to designated personnel.&lt;br /&gt;
* 3.2.2[c] personnel are adequately trained to carry out their assigned information security-related duties, roles, and responsibilities.&lt;br /&gt;
|examine=Security awareness and training policy; procedures addressing security training implementation; codes of federal regulations; security training curriculum; security training materials; system security plan; training records; other relevant documents or records.&lt;br /&gt;
|interview=Personnel with responsibilities for role-based security training; personnel with assigned system security roles and responsibilities; personnel with responsibilities for security awareness training; personnel with information security responsibilities; personnel representing the general system user community.&lt;br /&gt;
|test=Mechanisms managing role-based security training; mechanisms managing security awareness training.&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
{{Requirement&lt;br /&gt;
|id=3.2.3&lt;br /&gt;
|title=Provide security awareness training on recognizing and reporting potential indicators of insider threat.&lt;br /&gt;
|objectives=&lt;br /&gt;
* 3.2.3[a] potential indicators associated with insider threats are identified.&lt;br /&gt;
* 3.2.3[b] security awareness training on recognizing and reporting potential indicators of insider threat is provided to managers and employees.&lt;br /&gt;
|examine=Security awareness and training policy; procedures addressing security awareness training implementation; security awareness training curriculum; security awareness training materials; insider threat policy and procedures; system security plan; other relevant documents or records.&lt;br /&gt;
|interview=Personnel that participate in security awareness training; personnel with responsibilities for basic security awareness training; personnel with information security responsibilities.&lt;br /&gt;
|test=Mechanisms managing insider threat training.&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
=== 3.3 Audit and Accountability ===&lt;br /&gt;
&lt;br /&gt;
{{Requirement&lt;br /&gt;
|id=3.3.1&lt;br /&gt;
|title=Create and retain system audit logs and records to the extent needed to enable the monitoring, analysis, investigation, and reporting of unlawful or unauthorized system activity.&lt;br /&gt;
|objectives=&lt;br /&gt;
* 3.3.1[a] audit logs needed (i.e., event types to be logged) to enable the monitoring, analysis, investigation, and reporting of unlawful or unauthorized system activity are specified.&lt;br /&gt;
* 3.3.1[b] the content of audit records needed to support monitoring, analysis, investigation, and reporting of unlawful or unauthorized system activity is defined.&lt;br /&gt;
* 3.3.1[c] audit records are created (generated).&lt;br /&gt;
* 3.3.1[d] audit records, once created, contain the defined content.&lt;br /&gt;
* 3.3.1[e] retention requirements for audit records are defined.&lt;br /&gt;
* 3.3.1[f] audit records are retained as defined.&lt;br /&gt;
|examine=Audit and accountability policy; procedures addressing auditable events; system security plan; system design documentation; system configuration settings and associated documentation; procedures addressing control of audit records; procedures addressing audit record generation; system audit logs and records; system auditable events; system incident reports; other relevant documents or records.&lt;br /&gt;
|interview=Personnel with audit and accountability responsibilities; personnel with information security responsibilities; personnel with audit review, analysis and reporting responsibilities; system or network administrators.&lt;br /&gt;
|test=Mechanisms implementing system audit logging.&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
{{Requirement&lt;br /&gt;
|id=3.3.2&lt;br /&gt;
|title=Ensure that the actions of individual system users can be uniquely traced to those users so they can be held accountable for their actions.&lt;br /&gt;
|objectives=&lt;br /&gt;
* 3.3.2[a] the content of the audit records needed to support the ability to uniquely trace users to their actions is defined.&lt;br /&gt;
* 3.3.2[b] audit records, once created, contain the defined content.&lt;br /&gt;
|examine=Audit and accountability policy; procedures addressing audit records and event types; system security plan; system design documentation; system configuration settings and associated documentation; procedures addressing audit record generation; procedures addressing audit review, analysis, and reporting; reports of audit findings; system audit logs and records; system events; system incident reports; other relevant documents or records.&lt;br /&gt;
|interview=Personnel with audit and accountability responsibilities; personnel with information security responsibilities; system or network administrators.&lt;br /&gt;
|test=Mechanisms implementing system audit logging.&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
{{Requirement&lt;br /&gt;
|id=3.3.3&lt;br /&gt;
|title=Review and update logged events.&lt;br /&gt;
|objectives=&lt;br /&gt;
* 3.3.3[a] a process for determining when to review logged events is defined.&lt;br /&gt;
* 3.3.3[b] event types being logged are reviewed in accordance with the defined review process.&lt;br /&gt;
* 3.3.3[c] event types being logged are updated based on the review.&lt;br /&gt;
|examine=Audit and accountability policy; procedures addressing audit records and event types; system security plan; list of organization-defined event types to be logged; reviewed and updated records of logged event types; system audit logs and records; system incident reports; other relevant documents or records.&lt;br /&gt;
|interview=Personnel with audit and accountability responsibilities; personnel with information security responsibilities.&lt;br /&gt;
|test=Mechanisms supporting review and update of logged event types.&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
{{Requirement&lt;br /&gt;
|id=3.3.4&lt;br /&gt;
|title=Alert in the event of an audit logging process failure.&lt;br /&gt;
|objectives=&lt;br /&gt;
* 3.3.4[a] personnel or roles to be alerted in the event of an audit logging process failure are identified.&lt;br /&gt;
* 3.3.4[b] types of audit logging process failures for which alert will be generated are defined.&lt;br /&gt;
* 3.3.4[c] identified personnel or roles are alerted in the event of an audit logging process failure.&lt;br /&gt;
|examine=Audit and accountability policy; procedures addressing response to audit logging processing failures; system design documentation; system security plan; system configuration settings and associated documentation; list of personnel to be notified in case of an audit logging processing failure; system incident reports; system audit logs and records; other relevant documents or records.&lt;br /&gt;
|interview=Personnel with audit and accountability responsibilities; personnel with information security responsibilities; system or network administrators; system developers.&lt;br /&gt;
|test=Mechanisms implementing system response to audit logging processing failures.&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
{{Requirement&lt;br /&gt;
|id=3.3.5&lt;br /&gt;
|title=Correlate audit record review, analysis, and reporting processes for investigation and response to indications of unlawful, unauthorized, suspicious, or unusual activity.&lt;br /&gt;
|objectives=&lt;br /&gt;
* 3.3.5[a] audit record review, analysis, and reporting processes for investigation and response to indications of unlawful, unauthorized, suspicious, or unusual activity are defined.&lt;br /&gt;
* 3.3.5[b] defined audit record review, analysis, and reporting processes are correlated.&lt;br /&gt;
|examine=Audit and accountability policy; procedures addressing audit record review, analysis, and reporting; system security plan; system design documentation; system configuration settings and associated documentation; procedures addressing investigation of and response to suspicious activities; system audit logs and records across different repositories; other relevant documents or records.&lt;br /&gt;
|interview=Personnel with audit record review, analysis, and reporting responsibilities; personnel with information security responsibilities.&lt;br /&gt;
|test=Mechanisms supporting analysis and correlation of audit records; mechanisms integrating audit review, analysis and reporting.&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
{{Requirement&lt;br /&gt;
|id=3.3.6&lt;br /&gt;
|title=Provide audit record reduction and report generation to support on-demand analysis and reporting.&lt;br /&gt;
|objectives=&lt;br /&gt;
* 3.3.6[a] an audit record reduction capability that supports on-demand analysis is provided.&lt;br /&gt;
* 3.3.6[b] a report generation capability that supports on-demand reporting is provided.&lt;br /&gt;
|examine=Audit and accountability policy; procedures addressing audit record reduction and report generation; system design documentation; system security plan; system configuration settings and associated documentation; audit record reduction, review, analysis, and reporting tools; system audit logs and records; other relevant documents or records.&lt;br /&gt;
|interview=Personnel with audit record reduction and report generation responsibilities; personnel with information security responsibilities.&lt;br /&gt;
|test=Audit record reduction and report generation capability.&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
{{Requirement&lt;br /&gt;
|id=3.3.7&lt;br /&gt;
|title=Provide a system capability that compares and synchronizes internal system clocks with an authoritative source to generate time stamps for audit records.&lt;br /&gt;
|objectives=&lt;br /&gt;
* 3.3.7[a] internal system clocks are used to generate time stamps for audit records.&lt;br /&gt;
* 3.3.7[b] an authoritative source with which to compare and synchronize internal system clocks is specified.&lt;br /&gt;
* 3.3.7[c] internal system clocks used to generate time stamps for audit records are compared to and synchronized with the specified authoritative time source.&lt;br /&gt;
|examine=Audit and accountability policy; procedures addressing time stamp generation; system design documentation; system security plan; system configuration settings and associated documentation; system audit logs and records; other relevant documents or records.&lt;br /&gt;
|interview=Personnel with information security responsibilities; system or network administrators; system developers.&lt;br /&gt;
|test=Mechanisms implementing time stamp generation; mechanisms implementing internal information system clock synchronization.&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
{{Requirement&lt;br /&gt;
|id=3.3.8&lt;br /&gt;
|title=Protect audit information and audit logging tools from unauthorized access, modification, and deletion.&lt;br /&gt;
|objectives=&lt;br /&gt;
* 3.3.8[a] audit information is protected from unauthorized access.&lt;br /&gt;
* 3.3.8[b] audit information is protected from unauthorized modification.&lt;br /&gt;
* 3.3.8[c] audit information is protected from unauthorized deletion.&lt;br /&gt;
* 3.3.8[d] audit logging tools are protected from unauthorized access.&lt;br /&gt;
* 3.3.8[e] audit logging tools are protected from unauthorized modification.&lt;br /&gt;
* 3.3.8[f] audit logging tools are protected from unauthorized deletion.&lt;br /&gt;
|examine=Audit and accountability policy; access control policy and procedures; procedures addressing protection of audit information; system security plan; system design documentation; system configuration settings and associated documentation, system audit logs and records; audit logging tools; other relevant documents or records.&lt;br /&gt;
|interview=Personnel with audit and accountability responsibilities; personnel with information security responsibilities; system or network administrators; system developers.&lt;br /&gt;
|test=Mechanisms implementing audit information protection.&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
{{Requirement&lt;br /&gt;
|id=3.3.9&lt;br /&gt;
|title=Limit management of audit logging functionality to a subset of privileged users.&lt;br /&gt;
|objectives=&lt;br /&gt;
* 3.3.9[a] a subset of privileged users granted access to manage audit logging functionality is defined.&lt;br /&gt;
* 3.3.9[b] management of audit logging functionality is limited to the defined subset of privileged users.&lt;br /&gt;
|examine=Audit and accountability policy; access control policy and procedures; procedures addressing protection of audit information; system security plan; system design documentation; system configuration settings and associated documentation; access authorizations; system-generated list of privileged users with access to management of audit logging functionality; access control list; system audit logs and records; other relevant documents or records.&lt;br /&gt;
|interview=Personnel with audit and accountability responsibilities; personnel with information security responsibilities; system or network administrators; system developers.&lt;br /&gt;
|test=Mechanisms managing access to audit logging functionality.&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
=== 3.4 Configuration Management ===&lt;br /&gt;
&lt;br /&gt;
{{Requirement&lt;br /&gt;
|id=3.4.1&lt;br /&gt;
|title=Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles.&lt;br /&gt;
|objectives=&lt;br /&gt;
* 3.4.1[a] a baseline configuration is established.&lt;br /&gt;
* 3.4.1[b] the baseline configuration includes hardware, software, firmware, and documentation.&lt;br /&gt;
* 3.4.1[c] the baseline configuration is maintained (reviewed and updated) throughout the system development life cycle.&lt;br /&gt;
* 3.4.1[d] a system inventory is established.&lt;br /&gt;
* 3.4.1[e] the system inventory includes hardware, software, firmware, and documentation.&lt;br /&gt;
* 3.4.1[f] the inventory is maintained (reviewed and updated) throughout the system development life cycle.&lt;br /&gt;
|examine=Configuration management policy; procedures addressing the baseline configuration of the system; procedures addressing system inventory; system security plan; configuration management plan; system inventory records; inventory review and update records; enterprise architecture documentation; system design documentation; system architecture and configuration documentation; system configuration settings and associated documentation; change control records; system component installation records; system component removal records; other relevant documents or records.&lt;br /&gt;
|interview=Personnel with configuration management responsibilities; personnel with responsibilities for establishing the system inventory; personnel with responsibilities for updating the system inventory; personnel with information security responsibilities; system or network administrators.&lt;br /&gt;
|test=Organizational processes for managing baseline configurations; mechanisms supporting configuration control of the baseline configuration; organizational processes for developing and documenting an inventory of system components; organizational processes for updating inventory of system components; mechanisms supporting or implementing the system inventory; mechanisms implementing updating of the system inventory.&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
{{Requirement&lt;br /&gt;
|id=3.4.2&lt;br /&gt;
|title=Establish and enforce security configuration settings for information technology products employed in organizational systems.&lt;br /&gt;
|objectives=&lt;br /&gt;
* 3.4.2[a] security configuration settings for information technology products employed in the system are established and included in the baseline configuration.&lt;br /&gt;
* 3.4.2[b] security configuration settings for information technology products employed in the system are enforced.&lt;br /&gt;
|examine=Configuration management policy; baseline configuration; procedures addressing configuration settings for the system; configuration management plan; system security plan; system design documentation; system configuration settings and associated documentation; security configuration checklists; evidence supporting approved deviations from established configuration settings; change control records; system audit logs and records; other relevant documents or records.&lt;br /&gt;
|interview=Personnel with security configuration management responsibilities; personnel with information security responsibilities; system or network administrators.&lt;br /&gt;
|test=Organizational processes for managing configuration settings; mechanisms that implement, monitor, and/or control system configuration settings; mechanisms that identify and/or document deviations from established configuration settings; processes for managing baseline configurations; mechanisms supporting configuration control of baseline configurations.&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
{{Requirement&lt;br /&gt;
|id=3.4.3&lt;br /&gt;
|title=Track, review, approve or disapprove, and log changes to organizational systems.&lt;br /&gt;
|objectives=&lt;br /&gt;
* 3.4.3[a] changes to the system are tracked.&lt;br /&gt;
* 3.4.3[b] changes to the system are reviewed.&lt;br /&gt;
* 3.4.3[c] changes to the system are approved or disapproved.&lt;br /&gt;
* 3.4.3[d] changes to the system are logged.&lt;br /&gt;
|examine=Configuration management policy; procedures addressing system configuration change control; configuration management plan; system architecture and configuration documentation; system security plan; change control records; system audit logs and records; change control audit and review reports; agenda/minutes from configuration change control oversight meetings; other relevant documents or records.&lt;br /&gt;
|interview=Personnel with configuration change control responsibilities; personnel with information security responsibilities; system or network administrators; members of change control board or similar.&lt;br /&gt;
|test=Organizational processes for configuration change control; mechanisms that implement configuration change control.&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
{{Requirement&lt;br /&gt;
|id=3.4.4&lt;br /&gt;
|title=Analyze the security impact of changes prior to implementation.&lt;br /&gt;
|objectives=Determine if the security impact of changes to the system is analyzed prior to implementation.&lt;br /&gt;
|examine=Configuration management policy; procedures addressing security impact analysis for system changes; configuration management plan; security impact analysis documentation; system security plan; analysis tools and associated outputs; change control records; system audit logs and records; other relevant documents or records.&lt;br /&gt;
|interview=Personnel with responsibility for conducting security impact analysis; personnel with information security responsibilities; system or network administrators.&lt;br /&gt;
|test=Organizational processes for security impact analysis.&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
{{Requirement&lt;br /&gt;
|id=3.4.5&lt;br /&gt;
|title=Define, document, approve, and enforce physical and logical access restrictions associated with changes to organizational systems.&lt;br /&gt;
|objectives=&lt;br /&gt;
* 3.4.5[a] physical access restrictions associated with changes to the system are defined.&lt;br /&gt;
* 3.4.5[b] physical access restrictions associated with changes to the system are documented.&lt;br /&gt;
* 3.4.5[c] physical access restrictions associated with changes to the system are approved.&lt;br /&gt;
* 3.4.5[d] physical access restrictions associated with changes to the system are enforced.&lt;br /&gt;
* 3.4.5[e] logical access restrictions associated with changes to the system are defined.&lt;br /&gt;
* 3.4.5[f] logical access restrictions associated with changes to the system are documented.&lt;br /&gt;
* 3.4.5[g] logical access restrictions associated with changes to the system are approved.&lt;br /&gt;
* 3.4.5[h] logical access restrictions associated with changes to the system are enforced.&lt;br /&gt;
|examine=Configuration management policy; procedures addressing access restrictions for changes to the system; system security plan; configuration management plan; system design documentation; system architecture and configuration documentation; system configuration settings and associated documentation; logical access approvals; physical access approvals; access credentials; change control records; system audit logs and records; other relevant documents or records.&lt;br /&gt;
|interview=Personnel with logical access control responsibilities; personnel with physical access control responsibilities; personnel with information security responsibilities; system or network administrators.&lt;br /&gt;
|test=Organizational processes for managing access restrictions associated with changes to the system; mechanisms supporting, implementing, and enforcing access restrictions associated with changes to the system.&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
{{Requirement&lt;br /&gt;
|id=3.4.6&lt;br /&gt;
|title=Employ the principle of least functionality by configuring organizational systems to provide only essential capabilities.&lt;br /&gt;
|objectives=&lt;br /&gt;
* 3.4.6[a] essential system capabilities are defined based on the principle of least functionality.&lt;br /&gt;
* 3.4.6[b] the system is configured to provide only the defined essential capabilities.&lt;br /&gt;
|examine=Configuration management policy; configuration management plan; procedures addressing least functionality in the system; system security plan; system design documentation; system configuration settings and associated documentation; security configuration checklists; other relevant documents or records.&lt;br /&gt;
|interview=Personnel with security configuration management responsibilities; personnel with information security responsibilities; system or network administrators.&lt;br /&gt;
|test=Organizational processes prohibiting or restricting functions, ports, protocols, or services; mechanisms implementing restrictions or prohibition of functions, ports, protocols, or services.&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
{{Requirement&lt;br /&gt;
|id=3.4.7&lt;br /&gt;
|title=Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services.&lt;br /&gt;
|objectives=&lt;br /&gt;
* 3.4.7[a] essential programs are defined.&lt;br /&gt;
* 3.4.7[b] the use of nonessential programs is defined.&lt;br /&gt;
* 3.4.7[c] the use of nonessential programs is restricted, disabled, or prevented as defined.&lt;br /&gt;
* 3.4.7[d] essential functions are defined.&lt;br /&gt;
* 3.4.7[e] the use of nonessential functions is defined.&lt;br /&gt;
* 3.4.7[f] the use of nonessential functions is restricted, disabled, or prevented as defined.&lt;br /&gt;
* 3.4.7[g] essential ports are defined.&lt;br /&gt;
* 3.4.7[h] the use of nonessential ports is defined.&lt;br /&gt;
* 3.4.7[i] the use of nonessential ports is restricted, disabled, or prevented as defined.&lt;br /&gt;
* 3.4.7[j] essential protocols are defined.&lt;br /&gt;
* 3.4.7[k] the use of nonessential protocols is defined.&lt;br /&gt;
* 3.4.7[l] the use of nonessential protocols is restricted, disabled, or prevented as defined.&lt;br /&gt;
* 3.4.7[m] essential services are defined.&lt;br /&gt;
* 3.4.7[n] the use of nonessential services is defined.&lt;br /&gt;
* 3.4.7[o] the use of nonessential services is restricted, disabled, or prevented as defined.&lt;br /&gt;
|examine=Configuration management policy; procedures addressing least functionality in the system; configuration management plan; system security plan; system design documentation; security configuration checklists; system configuration settings and associated documentation; specifications for preventing software program execution; documented reviews of programs, functions, ports, protocols, and/or services; change control records; system audit logs and records; other relevant documents or records.&lt;br /&gt;
|interview=Personnel with responsibilities for reviewing programs, functions, ports, protocols, and services on the system; personnel with information security responsibilities; system or network administrators; system developers.&lt;br /&gt;
|test=Organizational processes for reviewing and disabling nonessential programs, functions, ports, protocols, or services; mechanisms implementing review and handling of nonessential programs, functions, ports, protocols, or services; organizational processes preventing program execution on the system; organizational processes for software program usage and restrictions; mechanisms supporting or implementing software program usage and restrictions; mechanisms preventing program execution on the system.&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
{{Requirement&lt;br /&gt;
|id=3.4.8&lt;br /&gt;
|title=Apply deny-by-exception (blacklisting) policy to prevent the use of unauthorized software or deny-all, permit-by-exception (whitelisting) policy to allow the execution of authorized software.&lt;br /&gt;
|objectives=&lt;br /&gt;
* 3.4.8[a] a policy specifying whether whitelisting or blacklisting is to be implemented is specified.&lt;br /&gt;
* 3.4.8[b] the software allowed to execute under whitelisting or denied use under blacklisting is specified.&lt;br /&gt;
* 3.4.8[c] whitelisting to allow the execution of authorized software or blacklisting to prevent the use of unauthorized software is implemented as specified.&lt;br /&gt;
|examine=Configuration management policy; procedures addressing least functionality in the system; system security plan; configuration management plan; system design documentation; system configuration settings and associated documentation; list of software programs not authorized to execute on the system; list of software programs authorized to execute on the system; security configuration checklists; review and update records associated with list of authorized or unauthorized software programs; change control records; system audit logs and records; other relevant documents or records.&lt;br /&gt;
|interview=Personnel with responsibilities for identifying software authorized or not authorized to execute on the system; personnel with information security responsibilities; system or network administrators.&lt;br /&gt;
|test=Organizational process for identifying, reviewing, and updating programs authorized or not authorized to execute on the system; process for implementing blacklisting or whitelisting; mechanisms supporting or implementing blacklisting or whitelisting.&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
{{Requirement&lt;br /&gt;
|id=3.4.9&lt;br /&gt;
|title=Control and monitor user-installed software.&lt;br /&gt;
|objectives=&lt;br /&gt;
* 3.4.9[a] a policy for controlling the installation of software by users is established.&lt;br /&gt;
* 3.4.9[b] installation of software by users is controlled based on the established policy.&lt;br /&gt;
* 3.4.9[c] installation of software by users is monitored.&lt;br /&gt;
|examine=Configuration management policy; procedures addressing user installed software; configuration management plan; system security plan; system design documentation; system configuration settings and associated documentation; list of rules governing user-installed software; system monitoring records; system audit logs and records; continuous monitoring strategy; other relevant documents or records.&lt;br /&gt;
|interview=Personnel with responsibilities for governing user-installed software; personnel operating, using, or maintaining the system; personnel monitoring compliance with user-installed software policy; personnel with information security responsibilities; system or network administrators.&lt;br /&gt;
|test=Organizational processes governing user-installed software on the system; mechanisms enforcing rules or methods for governing the installation of software by users; mechanisms monitoring policy compliance.&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
=== 3.5 Identification and Authentication ===&lt;br /&gt;
&lt;br /&gt;
{{Requirement&lt;br /&gt;
|id=3.5.1&lt;br /&gt;
|title=Identify system users, processes acting on behalf of users, and devices.&lt;br /&gt;
|objectives=&lt;br /&gt;
* 3.5.1[a] system users are identified.&lt;br /&gt;
* 3.5.1[b] processes acting on behalf of users are identified.&lt;br /&gt;
* 3.5.1[c] devices accessing the system are identified.&lt;br /&gt;
|examine=Identification and authentication policy; procedures addressing user identification and authentication; system security plan, system design documentation; system configuration settings and associated documentation; system audit logs and records; list of system accounts; other relevant documents or records.&lt;br /&gt;
|interview=Personnel with system operations responsibilities; personnel with information security responsibilities; system or network administrators; personnel with account management responsibilities; system developers.&lt;br /&gt;
|test=Organizational processes for uniquely identifying and authenticating users; mechanisms supporting or implementing identification and authentication capability.&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
{{Requirement&lt;br /&gt;
|id=3.5.2&lt;br /&gt;
|title=Authenticate (or verify) the identities of users, processes, or devices, as a prerequisite to allowing access to organizational systems.&lt;br /&gt;
|objectives=&lt;br /&gt;
* 3.5.2[a] the identity of each user is authenticated or verified as a prerequisite to system access.&lt;br /&gt;
* 3.5.2[b] the identity of each process acting on behalf of a user is authenticated or verified as a prerequisite to system access.&lt;br /&gt;
* 3.5.2[c] the identity of each device accessing or connecting to the system is authenticated or verified as a prerequisite to system access.&lt;br /&gt;
|examine=Identification and authentication policy; system security plan; procedures addressing authenticator management; procedures addressing user identification and authentication; system design documentation; list of system authenticator types; system configuration settings and associated documentation; change control records associated with managing system authenticators; system audit logs and records; other relevant documents or records.&lt;br /&gt;
|interview=Personnel with authenticator management responsibilities; personnel with information security responsibilities; system or network administrators.&lt;br /&gt;
|test=Mechanisms supporting or implementing authenticator management capability.&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
{{Requirement&lt;br /&gt;
|id=3.5.3&lt;br /&gt;
|title=Use multifactor authentication for local and network access to privileged accounts and for network access to non-privileged accounts.&lt;br /&gt;
|objectives=&lt;br /&gt;
* 3.5.3[a] privileged accounts are identified.&lt;br /&gt;
* 3.5.3[b] multifactor authentication is implemented for local access to privileged accounts.&lt;br /&gt;
* 3.5.3[c] multifactor authentication is implemented for network access to privileged accounts.&lt;br /&gt;
* 3.5.3[d] multifactor authentication is implemented for network access to non-privileged accounts.&lt;br /&gt;
|examine=Identification and authentication policy; procedures addressing user identification and authentication; system security plan; system design documentation; system configuration settings and associated documentation; system audit logs and records; list of system accounts; other relevant documents or records.&lt;br /&gt;
|interview=Personnel with system operations responsibilities; personnel with account management responsibilities; personnel with information security responsibilities; system or network administrators; system developers.&lt;br /&gt;
|test=Mechanisms supporting or implementing multifactor authentication capability.&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
{{Requirement&lt;br /&gt;
|id=3.5.4&lt;br /&gt;
|title=Employ replay-resistant authentication mechanisms for network access to privileged and non-privileged accounts.&lt;br /&gt;
|objectives=Determine if replay-resistant authentication mechanisms are implemented for network account access to privileged and non-privileged accounts.&lt;br /&gt;
|examine=Identification and authentication policy; procedures addressing user identification and authentication; system security plan; system design documentation; system configuration settings and associated documentation; system audit logs and records; list of privileged system accounts; other relevant documents or records.&lt;br /&gt;
|interview=Personnel with system operations responsibilities; personnel with account management responsibilities; personnel with information security responsibilities; system or network administrators; system developers.&lt;br /&gt;
|test=Mechanisms supporting or implementing identification and authentication capability or replay resistant authentication mechanisms.&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
{{Requirement&lt;br /&gt;
|id=3.5.5&lt;br /&gt;
|title=Prevent reuse of identifiers for a defined period.&lt;br /&gt;
|objectives=&lt;br /&gt;
* 3.5.5[a] a period within which identifiers cannot be reused is defined.&lt;br /&gt;
* 3.5.5[b] reuse of identifiers is prevented within the defined period.&lt;br /&gt;
|examine=Identification and authentication policy; procedures addressing identifier management; procedures addressing account management; system security plan; system design documentation; system configuration settings and associated documentation; list of system accounts; list of identifiers generated from physical access control devices; other relevant documents or records.&lt;br /&gt;
|interview=Personnel with identifier management responsibilities; personnel with information security responsibilities; system or network administrators; system developers.&lt;br /&gt;
|test=Mechanisms supporting or implementing identifier management.&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
{{Requirement&lt;br /&gt;
|id=3.5.6&lt;br /&gt;
|title=Disable identifiers after a defined period of inactivity.&lt;br /&gt;
|objectives=&lt;br /&gt;
* 3.5.6[a] a period of inactivity after which an identifier is disabled is defined.&lt;br /&gt;
* 3.5.6[b] identifiers are disabled after the defined period of inactivity.&lt;br /&gt;
|examine=Identification and authentication policy; procedures addressing identifier management; procedures addressing account management; system security plan; system design documentation; system configuration settings and associated documentation; list of system accounts; list of identifiers generated from physical access control devices; other relevant documents or records.&lt;br /&gt;
|interview=Personnel with identifier management responsibilities; personnel with information security responsibilities; system or network administrators; system developers.&lt;br /&gt;
|test=Mechanisms supporting or implementing identifier management.&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
{{Requirement&lt;br /&gt;
|id=3.5.7&lt;br /&gt;
|title=Enforce a minimum password complexity and change of characters when new passwords are created.&lt;br /&gt;
|objectives=&lt;br /&gt;
* 3.5.7[a] password complexity requirements are defined.&lt;br /&gt;
* 3.5.7[b] password change of character requirements are defined.&lt;br /&gt;
* 3.5.7[c] minimum password complexity requirements as defined are enforced when new passwords are created.&lt;br /&gt;
* 3.5.7[d] minimum password change of character requirements as defined are enforced when new passwords are created.&lt;br /&gt;
|examine=Identification and authentication policy; password policy; procedures addressing authenticator management; system security plan; system configuration settings and associated documentation; system design documentation; password configurations and associated documentation; other relevant documents or records.&lt;br /&gt;
|interview=Personnel with authenticator management responsibilities; personnel with information security responsibilities; system or network administrators; system developers.&lt;br /&gt;
|test=Mechanisms supporting or implementing password-based authenticator management capability.&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
{{Requirement&lt;br /&gt;
|id=3.5.8&lt;br /&gt;
|title=Prohibit password reuse for a specified number of generations.&lt;br /&gt;
|objectives=&lt;br /&gt;
* 3.5.8[a] the number of generations during which a password cannot be reused is specified.&lt;br /&gt;
* 3.5.8[b] reuse of passwords is prohibited during the specified number of generations.&lt;br /&gt;
|examine=Identification and authentication policy; password policy; procedures addressing authenticator management; system security plan; system design documentation; system configuration settings and associated documentation; password configurations and associated documentation; other relevant documents or records.&lt;br /&gt;
|interview=Personnel with authenticator management responsibilities; personnel with information security responsibilities; system or network administrators; system developers.&lt;br /&gt;
|test=Mechanisms supporting or implementing password-based authenticator management capability.&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
{{Requirement&lt;br /&gt;
|id=3.5.9&lt;br /&gt;
|title=Allow temporary password use for system logons with an immediate change to a permanent password.&lt;br /&gt;
|objectives=Determine if an immediate change to a permanent password is required when a temporary password is used for system logon.&lt;br /&gt;
|examine=Identification and authentication policy; password policy; procedures addressing authenticator management; system security plan; system configuration settings and associated documentation; system design documentation; password configurations and associated documentation; other relevant documents or records.&lt;br /&gt;
|interview=Personnel with authenticator management responsibilities; personnel with information security responsibilities; system or network administrators; system developers.&lt;br /&gt;
|test=Mechanisms supporting or implementing password-based authenticator management capability.&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
{{Requirement&lt;br /&gt;
|id=3.5.10&lt;br /&gt;
|title=Store and transmit only cryptographically-protected passwords.&lt;br /&gt;
|objectives=&lt;br /&gt;
* 3.5.10[a] passwords are cryptographically protected in storage.&lt;br /&gt;
* 3.5.10[b] passwords are cryptographically protected in transit.&lt;br /&gt;
|examine=Identification and authentication policy; password policy; procedures addressing authenticator management; system security plan; system configuration settings and associated documentation; system design documentation; password configurations and associated documentation; other relevant documents or records.&lt;br /&gt;
|interview=Personnel with authenticator management responsibilities; personnel with information security responsibilities; system or network administrators; system developers.&lt;br /&gt;
|test=Mechanisms supporting or implementing password-based authenticator management capability.&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
{{Requirement&lt;br /&gt;
|id=3.5.11&lt;br /&gt;
|title=Obscure feedback of authentication information.&lt;br /&gt;
|objectives=Determine if authentication information is obscured during the authentication process.&lt;br /&gt;
|examine=Identification and authentication policy; procedures addressing authenticator feedback; system security plan; system design documentation; system configuration settings and associated documentation; system audit logs and records; other relevant documents or records.&lt;br /&gt;
|interview=Personnel with information security responsibilities; system or network administrators; system developers.&lt;br /&gt;
|test=Mechanisms supporting or implementing the obscuring of feedback of authentication information during authentication.&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
=== 3.6 Incident Response ===&lt;br /&gt;
&lt;br /&gt;
{{Requirement&lt;br /&gt;
|id=3.6.1&lt;br /&gt;
|title=Establish an operational incident-handling capability for organizational systems that includes preparation, detection, analysis, containment, recovery, and user response activities.&lt;br /&gt;
|objectives=&lt;br /&gt;
* 3.6.1[a] an operational incident-handling capability is established.&lt;br /&gt;
* 3.6.1[b] the operational incident-handling capability includes preparation.&lt;br /&gt;
* 3.6.1[c] the operational incident-handling capability includes detection.&lt;br /&gt;
* 3.6.1[d] the operational incident-handling capability includes analysis.&lt;br /&gt;
* 3.6.1[e] the operational incident-handling capability includes containment.&lt;br /&gt;
* 3.6.1[f] the operational incident-handling capability includes recovery.&lt;br /&gt;
* 3.6.1[g] the operational incident-handling capability includes user response activities.&lt;br /&gt;
|examine=Incident response policy; contingency planning policy; procedures addressing incident handling; procedures addressing incident response assistance; incident response plan; contingency plan; system security plan; procedures addressing incident response training; incident response training curriculum; incident response training materials; incident response training records; other relevant documents or records.&lt;br /&gt;
|interview=Personnel with incident handling responsibilities; personnel with contingency planning responsibilities; personnel with incident response training and operational responsibilities; personnel with incident response assistance and support responsibilities; personnel with access to incident response support and assistance capability; personnel with information security responsibilities.&lt;br /&gt;
|test=Incident-handling capability for the organization; organizational processes for incident response assistance; mechanisms supporting or implementing incident response assistance.&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
{{Requirement&lt;br /&gt;
|id=3.6.2&lt;br /&gt;
|title=Track, document, and report incidents to designated officials and/or authorities both internal and external to the organization.&lt;br /&gt;
|objectives=&lt;br /&gt;
* 3.6.2[a] incidents are tracked.&lt;br /&gt;
* 3.6.2[b] incidents are documented.&lt;br /&gt;
* 3.6.2[c] authorities to whom incidents are to be reported are identified.&lt;br /&gt;
* 3.6.2[d] organizational officials to whom incidents are to be reported are identified.&lt;br /&gt;
* 3.6.2[e] identified authorities are notified of incidents.&lt;br /&gt;
* 3.6.2[f] identified organizational officials are notified of incidents.&lt;br /&gt;
|examine=Incident response policy; procedures addressing incident monitoring; incident response records and documentation; procedures addressing incident reporting; incident reporting records and documentation; incident response plan; system security plan; other relevant documents or records.&lt;br /&gt;
|interview=Personnel with incident monitoring responsibilities; personnel with incident reporting responsibilities; personnel who have or should have reported incidents; personnel (authorities) to whom incident information is to be reported; personnel with information security responsibilities.&lt;br /&gt;
|test=Incident monitoring capability for the organization; mechanisms supporting or implementing tracking and documenting of system security incidents; organizational processes for incident reporting; mechanisms supporting or implementing incident reporting.&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
{{Requirement&lt;br /&gt;
|id=3.6.3&lt;br /&gt;
|title=Test the organizational incident response capability.&lt;br /&gt;
|objectives=Determine if the incident response capability is tested.&lt;br /&gt;
|examine=Incident response policy; contingency planning policy; procedures addressing incident response testing; procedures addressing contingency plan testing; incident response testing material; incident response test results; incident response test plan; incident response plan; contingency plan; system security plan; other relevant documents or records.&lt;br /&gt;
|interview=Personnel with incident response testing responsibilities; personnel with information security responsibilities; personnel with responsibilities for testing plans related to incident response.&lt;br /&gt;
|test=Mechanisms and processes for incident response.&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
=== 3.7 Maintenance ===&lt;br /&gt;
&lt;br /&gt;
{{Requirement&lt;br /&gt;
|id=3.7.1&lt;br /&gt;
|title=Perform maintenance on organizational systems.&lt;br /&gt;
|objectives=Determine if system maintenance is performed.&lt;br /&gt;
|examine=System maintenance policy; procedures addressing controlled system maintenance; maintenance records; manufacturer or vendor maintenance specifications; equipment sanitization records; media sanitization records; system security plan; other relevant documents or records.&lt;br /&gt;
|interview=Personnel with system maintenance responsibilities; personnel with information security responsibilities; personnel responsible for media sanitization; system or network administrators.&lt;br /&gt;
|test=Organizational processes for scheduling, performing, documenting, reviewing, approving, and monitoring maintenance and repairs for systems; organizational processes for sanitizing system components; mechanisms supporting or implementing controlled maintenance; mechanisms implementing sanitization of system components.&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
{{Requirement&lt;br /&gt;
|id=3.7.2&lt;br /&gt;
|title=Provide controls on the tools, techniques, mechanisms, and personnel used to conduct system maintenance.&lt;br /&gt;
|objectives=&lt;br /&gt;
* 3.7.2[a] tools used to conduct system maintenance are controlled.&lt;br /&gt;
* 3.7.2[b] techniques used to conduct system maintenance are controlled.&lt;br /&gt;
* 3.7.2[c] mechanisms used to conduct system maintenance are controlled.&lt;br /&gt;
* 3.7.2[d] personnel used to conduct system maintenance are controlled.&lt;br /&gt;
|examine=System maintenance policy; procedures addressing system maintenance tools and media; maintenance records; system maintenance tools and associated documentation; maintenance tool inspection records; system security plan; other relevant documents or records.&lt;br /&gt;
|interview=Personnel with system maintenance responsibilities; personnel with information security responsibilities.&lt;br /&gt;
|test=Organizational processes for approving, controlling, and monitoring maintenance tools; mechanisms supporting or implementing approval, control, and monitoring of maintenance tools; organizational processes for inspecting maintenance tools; mechanisms supporting or implementing inspection of maintenance tools; organizational process for inspecting media for malicious code; mechanisms supporting or implementing inspection of media used for maintenance.&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
{{Requirement&lt;br /&gt;
|id=3.7.3&lt;br /&gt;
|title=Ensure equipment removed for off-site maintenance is sanitized of any CUI.&lt;br /&gt;
|objectives=Determine if equipment to be removed from organizational spaces for off-site maintenance is sanitized of any CUI.&lt;br /&gt;
|examine=System maintenance policy; procedures addressing controlled system maintenance; maintenance records; manufacturer or vendor maintenance specifications; equipment sanitization records; media sanitization records; system security plan; other relevant documents or records.&lt;br /&gt;
|interview=Personnel with system maintenance responsibilities; personnel with information security responsibilities; personnel responsible for media sanitization; system or network administrators.&lt;br /&gt;
|test=Organizational processes for scheduling, performing, documenting, reviewing, approving, and monitoring maintenance and repairs for systems; organizational processes for sanitizing system components; mechanisms supporting or implementing controlled maintenance; mechanisms implementing sanitization of system components.&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
{{Requirement&lt;br /&gt;
|id=3.7.4&lt;br /&gt;
|title=Check media containing diagnostic and test programs for malicious code before the media are used in organizational systems.&lt;br /&gt;
|objectives=Determine if media containing diagnostic and test programs are checked for malicious code before being used in organizational systems that process, store, or transmit CUI.&lt;br /&gt;
|examine=System maintenance policy; procedures addressing system maintenance tools; system maintenance tools and associated documentation; maintenance records; system security plan; other relevant documents or records.&lt;br /&gt;
|interview=Personnel with system maintenance responsibilities; personnel with information security responsibilities.&lt;br /&gt;
|test=Organizational process for inspecting media for malicious code; mechanisms supporting or implementing inspection of media used for maintenance.&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
{{Requirement&lt;br /&gt;
|id=3.7.5&lt;br /&gt;
|title=Require multifactor authentication to establish nonlocal maintenance sessions via external network connections and terminate such connections when nonlocal maintenance is complete.&lt;br /&gt;
|objectives=&lt;br /&gt;
* 3.7.5[a] multifactor authentication is used to establish nonlocal maintenance sessions via external network connections.&lt;br /&gt;
* 3.7.5[b] nonlocal maintenance sessions established via external network connections are terminated when nonlocal maintenance is complete.&lt;br /&gt;
|examine=System maintenance policy; procedures addressing nonlocal system maintenance; system security plan; system design documentation; system configuration settings and associated documentation; maintenance records; diagnostic records; other relevant documents or records.&lt;br /&gt;
|interview=Personnel with system maintenance responsibilities; personnel with information security responsibilities; system or network administrators.&lt;br /&gt;
|test=Organizational processes for managing nonlocal maintenance; mechanisms implementing, supporting, and managing nonlocal maintenance; mechanisms for strong authentication of nonlocal maintenance diagnostic sessions; mechanisms for terminating nonlocal maintenance sessions and network connections.&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
{{Requirement&lt;br /&gt;
|id=3.7.6&lt;br /&gt;
|title=Supervise the maintenance activities of maintenance personnel without required access authorization.&lt;br /&gt;
|objectives=Determine if maintenance personnel without required access authorization are supervised during maintenance activities.&lt;br /&gt;
|examine=System maintenance policy; procedures addressing maintenance personnel; service provider contracts; service-level agreements; list of authorized personnel; maintenance records; access control records; system security plan; other relevant documents or records.&lt;br /&gt;
|interview=Personnel with system maintenance responsibilities; personnel with information security responsibilities.&lt;br /&gt;
|test=Organizational processes for authorizing and managing maintenance personnel; mechanisms supporting or implementing authorization of maintenance personnel.&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
=== 3.8 Media Protection ===&lt;br /&gt;
&lt;br /&gt;
{{Requirement&lt;br /&gt;
|id=3.8.1&lt;br /&gt;
|title=Protect (i.e., physically control and securely store) system media containing CUI, both paper and digital.&lt;br /&gt;
|objectives=&lt;br /&gt;
* 3.8.1[a] paper media containing CUI is physically controlled.&lt;br /&gt;
* 3.8.1[b] digital media containing CUI is physically controlled.&lt;br /&gt;
* 3.8.1[c] paper media containing CUI is securely stored.&lt;br /&gt;
* 3.8.1[d] digital media containing CUI is securely stored.&lt;br /&gt;
|examine=System media protection policy; procedures addressing media storage; procedures addressing media access restrictions; access control policy and procedures; physical and environmental protection policy and procedures; system security plan; media storage facilities; access control records; other relevant documents or records.&lt;br /&gt;
|interview=Personnel with system media protection responsibilities; personnel with information security responsibilities; system or network administrators.&lt;br /&gt;
|test=Organizational processes for restricting information media; mechanisms supporting or implementing media access restrictions.&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
{{Requirement&lt;br /&gt;
|id=3.8.2&lt;br /&gt;
|title=Limit access to CUI on system media to authorized users.&lt;br /&gt;
|objectives=Determine if access to CUI on system media is limited to authorized users.&lt;br /&gt;
|examine=System media protection policy; procedures addressing media storage; physical and environmental protection policy and procedures; access control policy and procedures; system security plan; system media; designated controlled areas; other relevant documents or records.&lt;br /&gt;
|interview=Personnel with system media protection and storage responsibilities; personnel with information security responsibilities.&lt;br /&gt;
|test=Organizational processes for storing media; mechanisms supporting or implementing secure media storage and media protection.&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
{{Requirement&lt;br /&gt;
|id=3.8.3&lt;br /&gt;
|title=Sanitize or destroy system media containing CUI before disposal or release for reuse.&lt;br /&gt;
|objectives=&lt;br /&gt;
* 3.8.3[a] system media containing CUI is sanitized or destroyed before disposal.&lt;br /&gt;
* 3.8.3[b] system media containing CUI is sanitized before it is released for reuse.&lt;br /&gt;
|examine=System media protection policy; procedures addressing media sanitization and disposal; applicable standards and policies addressing media sanitization; system security plan; media sanitization records; system audit logs and records; system design documentation; system configuration settings and associated documentation; other relevant documents or records.&lt;br /&gt;
|interview=Personnel with media sanitization responsibilities; personnel with information security responsibilities; system or network administrators.&lt;br /&gt;
|test=Organizational processes for media sanitization; mechanisms supporting or implementing media sanitization.&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
{{Requirement&lt;br /&gt;
|id=3.8.4&lt;br /&gt;
|title=Mark media with necessary CUI markings and distribution limitations.&lt;br /&gt;
|objectives=&lt;br /&gt;
* 3.8.4[a] media containing CUI is marked with applicable CUI markings.&lt;br /&gt;
* 3.8.4[b] media containing CUI is marked with distribution limitations.&lt;br /&gt;
|examine=System media protection policy; procedures addressing media marking; physical and environmental protection policy and procedures; system security plan; list of system media marking security attributes; designated controlled areas; other relevant documents or records.&lt;br /&gt;
|interview=Personnel with system media protection and marking responsibilities; personnel with information security responsibilities.&lt;br /&gt;
|test=Organizational processes for marking information media; mechanisms supporting or implementing media marking.&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
{{Requirement&lt;br /&gt;
|id=3.8.5&lt;br /&gt;
|title=Control access to media containing CUI and maintain accountability for media during transport outside of controlled areas.&lt;br /&gt;
|objectives=&lt;br /&gt;
* 3.8.5[a] access to media containing CUI is controlled.&lt;br /&gt;
* 3.8.5[b] accountability for media containing CUI is maintained during transport outside of controlled areas.&lt;br /&gt;
|examine=System media protection policy; procedures addressing media storage; physical and environmental protection policy and procedures; access control policy and procedures; system security plan; system media; designated controlled areas; other relevant documents or records.&lt;br /&gt;
|interview=Personnel with system media protection and storage responsibilities; personnel with information security responsibilities; system or network administrators.&lt;br /&gt;
|test=Organizational processes for storing media; mechanisms supporting or implementing media storage and media protection.&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
{{Requirement&lt;br /&gt;
|id=3.8.6&lt;br /&gt;
|title=Implement cryptographic mechanisms to protect the confidentiality of CUI stored on digital media during transport unless otherwise protected by alternative physical safeguards.&lt;br /&gt;
|objectives=Determine if the confidentiality of CUI stored on digital media is protected during transport using cryptographic mechanisms or alternative physical safeguards.&lt;br /&gt;
|examine=System media protection policy; procedures addressing media transport; system design documentation; system security plan; system configuration settings and associated documentation; system media transport records; system audit logs and records; other relevant documents or records.&lt;br /&gt;
|interview=Personnel with system media transport responsibilities; personnel with information security responsibilities.&lt;br /&gt;
|test=Cryptographic mechanisms protecting information on digital media during transportation outside controlled areas.&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
{{Requirement&lt;br /&gt;
|id=3.8.7&lt;br /&gt;
|title=Control the use of removable media on system components.&lt;br /&gt;
|objectives=Determine if the use of removable media on system components is controlled.&lt;br /&gt;
|examine=System media protection policy; system use policy; procedures addressing media usage restrictions; system security plan; rules of behavior; system design documentation; system configuration settings and associated documentation; system audit logs and records; other relevant documents or records.&lt;br /&gt;
|interview=Personnel with system media use responsibilities; personnel with information security responsibilities; system or network administrators.&lt;br /&gt;
|test=Organizational processes for media use; mechanisms restricting or prohibiting use of system media on systems or system components.&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
{{Requirement&lt;br /&gt;
|id=3.8.8&lt;br /&gt;
|title=Prohibit the use of portable storage devices when such devices have no identifiable owner.&lt;br /&gt;
|objectives=Determine if the use of portable storage devices is prohibited when such devices have no identifiable owner.&lt;br /&gt;
|examine=System media protection policy; system use policy; procedures addressing media usage restrictions; system security plan; rules of behavior; system configuration settings and associated documentation; system design documentation; system audit logs and records; other relevant documents or records.&lt;br /&gt;
|interview=Personnel with system media use responsibilities; personnel with information security responsibilities; system or network administrators.&lt;br /&gt;
|test=Organizational processes for media use; mechanisms prohibiting use of media on systems or system components.&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
{{Requirement&lt;br /&gt;
|id=3.8.9&lt;br /&gt;
|title=Protect the confidentiality of backup CUI at storage locations.&lt;br /&gt;
|objectives=Determine if the confidentiality of backup CUI is protected at storage locations.&lt;br /&gt;
|examine=Procedures addressing system backup; system configuration settings and associated documentation; security plan; backup storage locations; system backup logs or records; other relevant documents or records.&lt;br /&gt;
|interview=Personnel with system backup responsibilities; personnel with information security responsibilities.&lt;br /&gt;
|test=Organizational processes for conducting system backups; mechanisms supporting or implementing system backups.&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
=== 3.9 Personnel Security ===&lt;br /&gt;
&lt;br /&gt;
{{Requirement&lt;br /&gt;
|id=3.9.1&lt;br /&gt;
|title=Screen individuals prior to authorizing access to organizational systems containing CUI.&lt;br /&gt;
|objectives=Determine if individuals are screened prior to authorizing access to organizational systems containing CUI.&lt;br /&gt;
|examine=Personnel security policy; procedures addressing personnel screening; records of screened personnel; system security plan; other relevant documents or records.&lt;br /&gt;
|interview=Personnel with personnel security responsibilities; personnel with information security responsibilities.&lt;br /&gt;
|test=Organizational processes for personnel screening.&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
{{Requirement&lt;br /&gt;
|id=3.9.2&lt;br /&gt;
|title=Ensure that organizational systems containing CUI are protected during and after personnel actions such as terminations and transfers.&lt;br /&gt;
|objectives=&lt;br /&gt;
* 3.9.2[a] a policy and/or process for terminating system access and any credentials coincident with personnel actions is established.&lt;br /&gt;
* 3.9.2[b] system access and credentials are terminated consistent with personnel actions such as termination or transfer.&lt;br /&gt;
* 3.9.2[c] the system is protected during and after personnel transfer actions.&lt;br /&gt;
|examine=Personnel security policy; procedures addressing personnel transfer and termination; records of personnel transfer and termination actions; list of system accounts; records of terminated or revoked authenticators and credentials; records of exit interviews; other relevant documents or records.&lt;br /&gt;
|interview=Personnel with personnel security responsibilities; personnel with account management responsibilities; system or network administrators; personnel with information security responsibilities.&lt;br /&gt;
|test=Organizational processes for personnel transfer and termination; mechanisms supporting or implementing personnel transfer and termination notifications; mechanisms for disabling system access and revoking authenticators.&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
=== 3.10 Physical Protection ===&lt;br /&gt;
&lt;br /&gt;
{{Requirement&lt;br /&gt;
|id=3.10.1&lt;br /&gt;
|title=Limit physical access to organizational systems, equipment, and the respective operating environments to authorized individuals.&lt;br /&gt;
|objectives=&lt;br /&gt;
* 3.10.1[a] authorized individuals allowed physical access are identified.&lt;br /&gt;
* 3.10.1[b] physical access to organizational systems is limited to authorized individuals.&lt;br /&gt;
* 3.10.1[c] physical access to equipment is limited to authorized individuals.&lt;br /&gt;
* 3.10.1[d] physical access to operating environments is limited to authorized individuals.&lt;br /&gt;
|examine=Physical and environmental protection policy; procedures addressing physical access authorizations; system security plan; authorized personnel access list; authorization credentials; physical access list reviews; physical access termination records and associated documentation; other relevant documents or records.&lt;br /&gt;
|interview=Personnel with physical access authorization responsibilities; personnel with physical access to system facility; personnel with information security responsibilities.&lt;br /&gt;
|test=Organizational processes for physical access authorizations; mechanisms supporting or implementing physical access authorizations.&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
{{Requirement&lt;br /&gt;
|id=3.10.2&lt;br /&gt;
|title=Protect and monitor the physical facility and support infrastructure for organizational systems.&lt;br /&gt;
|objectives=&lt;br /&gt;
* 3.10.2[a] the physical facility where organizational systems reside is protected.&lt;br /&gt;
* 3.10.2[b] the support infrastructure for organizational systems is protected.&lt;br /&gt;
* 3.10.2[c] the physical facility where organizational systems reside is monitored.&lt;br /&gt;
* 3.10.2[d] the support infrastructure for organizational systems is monitored.&lt;br /&gt;
|examine=Physical and environmental protection policy; procedures addressing physical access monitoring; system security plan; physical access logs or records; physical access monitoring records; physical access log reviews; other relevant documents or records.&lt;br /&gt;
|interview=Personnel with physical access monitoring responsibilities; personnel with incident response responsibilities; personnel with information security responsibilities.&lt;br /&gt;
|test=Organizational processes for monitoring physical access; mechanisms supporting or implementing physical access monitoring; mechanisms supporting or implementing the review of physical access logs.&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
{{Requirement&lt;br /&gt;
|id=3.10.3&lt;br /&gt;
|title=Escort visitors and monitor visitor activity.&lt;br /&gt;
|objectives=&lt;br /&gt;
* 3.10.3[a] visitors are escorted.&lt;br /&gt;
* 3.10.3[b] visitor activity is monitored.&lt;br /&gt;
|examine=Physical and environmental protection policy; procedures addressing physical access control; system security plan; physical access control logs or records; inventory records of physical access control devices; system entry and exit points; records of key and lock combination changes; storage locations for physical access control devices; physical access control devices; list of security safeguards controlling access to designated publicly accessible areas within facility; other relevant documents or records.&lt;br /&gt;
|interview=Personnel with physical access control responsibilities; personnel with information security responsibilities.&lt;br /&gt;
|test=Organizational processes for physical access control; mechanisms supporting or implementing physical access control; physical access control devices.&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
{{Requirement&lt;br /&gt;
|id=3.10.4&lt;br /&gt;
|title=Maintain audit logs of physical access.&lt;br /&gt;
|objectives=Determine if audit logs of physical access are maintained.&lt;br /&gt;
|examine=Physical and environmental protection policy; procedures addressing physical access control; system security plan; physical access control logs or records; inventory records of physical access control devices; system entry and exit points; records of key and lock combination changes; storage locations for physical access control devices; physical access control devices; list of security safeguards controlling access to designated publicly accessible areas within facility; other relevant documents or records.&lt;br /&gt;
|interview=Personnel with physical access control responsibilities; personnel with information security responsibilities.&lt;br /&gt;
|test=Organizational processes for physical access control; mechanisms supporting or implementing physical access control; physical access control devices.&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
{{Requirement&lt;br /&gt;
|id=3.10.5&lt;br /&gt;
|title=Control and manage physical access devices.&lt;br /&gt;
|objectives=&lt;br /&gt;
* 3.10.5[a] physical access devices are identified.&lt;br /&gt;
* 3.10.5[b] physical access devices are controlled.&lt;br /&gt;
* 3.10.5[c] physical access devices are managed.&lt;br /&gt;
|examine=Physical and environmental protection policy; procedures addressing physical access control; system security plan; physical access control logs or records; inventory records of physical access control devices; system entry and exit points; records of key and lock combination changes; storage locations for physical access control devices; physical access control devices; list of security safeguards controlling access to designated publicly accessible areas within facility; other relevant documents or records.&lt;br /&gt;
|interview=Personnel with physical access control responsibilities; personnel with information security responsibilities.&lt;br /&gt;
|test=Organizational processes for physical access control; mechanisms supporting or implementing physical access control; physical access control devices.&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
{{Requirement&lt;br /&gt;
|id=3.10.6&lt;br /&gt;
|title=Enforce safeguarding measures for CUI at alternate work sites.&lt;br /&gt;
|objectives=&lt;br /&gt;
* 3.10.6[a] safeguarding measures for CUI are defined for alternate work sites.&lt;br /&gt;
* 3.10.6[b] safeguarding measures for CUI are enforced for alternate work sites.&lt;br /&gt;
|examine=Physical and environmental protection policy; procedures addressing alternate work sites for personnel; system security plan; list of safeguards required for alternate work sites; assessments of safeguards at alternate work sites; other relevant documents or records.&lt;br /&gt;
|interview=Personnel approving use of alternate work sites; personnel using alternate work sites; personnel assessing controls at alternate work sites; personnel with information security responsibilities.&lt;br /&gt;
|test=Organizational processes for security at alternate work sites; mechanisms supporting alternate work sites; safeguards employed at alternate work sites; means of communications between personnel at alternate work sites and security personnel.&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
=== 3.11 Risk Assessment ===&lt;br /&gt;
&lt;br /&gt;
{{Requirement&lt;br /&gt;
|id=3.11.1&lt;br /&gt;
|title=Periodically assess the risk to organizational operations (including mission, functions, image, or reputation), organizational assets, and individuals, resulting from the operation of organizational systems and the associated processing, storage, or transmission of CUI.&lt;br /&gt;
|objectives=&lt;br /&gt;
* 3.11.1[a] the frequency to assess risk to organizational operations, organizational assets, and individuals is defined.&lt;br /&gt;
* 3.11.1[b] risk to organizational operations, organizational assets, and individuals resulting from the operation of an organizational system that processes, stores, or transmits CUI is assessed with the defined frequency.&lt;br /&gt;
|examine=Risk assessment policy; security planning policy and procedures; procedures addressing organizational risk assessments; system security plan; risk assessment; risk assessment results; risk assessment reviews; risk assessment updates; other relevant documents or records.&lt;br /&gt;
|interview=Personnel with risk assessment responsibilities; personnel with information security responsibilities.&lt;br /&gt;
|test=Organizational processes for risk assessment; mechanisms supporting or for conducting, documenting, reviewing, disseminating, and updating the risk assessment.&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
{{Requirement&lt;br /&gt;
|id=3.11.2&lt;br /&gt;
|title=Scan for vulnerabilities in organizational systems and applications periodically and when new vulnerabilities affecting those systems and applications are identified.&lt;br /&gt;
|objectives=&lt;br /&gt;
* 3.11.2[a] the frequency to scan for vulnerabilities in organizational systems and applications is defined.&lt;br /&gt;
* 3.11.2[b] vulnerability scans are performed on organizational systems with the defined frequency.&lt;br /&gt;
* 3.11.2[c] vulnerability scans are performed on applications with the defined frequency.&lt;br /&gt;
* 3.11.2[d] vulnerability scans are performed on organizational systems when new vulnerabilities are identified.&lt;br /&gt;
* 3.11.2[e] vulnerability scans are performed on applications when new vulnerabilities are identified.&lt;br /&gt;
|examine=Risk assessment policy; procedures addressing vulnerability scanning; risk assessment; system security plan; security assessment report; vulnerability scanning tools and associated configuration documentation; vulnerability scanning results; patch and vulnerability management records; other relevant documents or records.&lt;br /&gt;
|interview=Personnel with risk assessment, security assessment and vulnerability scanning responsibilities; personnel with vulnerability scan analysis and remediation responsibilities; personnel with information security responsibilities; system or network administrators.&lt;br /&gt;
|test=Organizational processes for vulnerability scanning, analysis, remediation, and information sharing; mechanisms supporting or implementing vulnerability scanning, analysis, remediation, and information sharing.&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
{{Requirement&lt;br /&gt;
|id=3.11.3&lt;br /&gt;
|title=Remediate vulnerabilities in accordance with risk assessments.&lt;br /&gt;
|objectives=&lt;br /&gt;
* 3.11.3[a] vulnerabilities are identified.&lt;br /&gt;
* 3.11.3[b] vulnerabilities are remediated in accordance with risk assessments.&lt;br /&gt;
|examine=Risk assessment policy; procedures addressing vulnerability scanning; risk assessment; system security plan; security assessment report; vulnerability scanning tools and associated configuration documentation; vulnerability scanning results; patch and vulnerability management records; other relevant documents or records.&lt;br /&gt;
|interview=Personnel with risk assessment, security assessment and vulnerability scanning responsibilities; personnel with vulnerability scan analysis responsibilities; personnel with vulnerability remediation responsibilities; personnel with information security responsibilities; system or network administrators.&lt;br /&gt;
|test=Organizational processes for vulnerability scanning, analysis, remediation, and information sharing; mechanisms supporting or implementing vulnerability scanning, analysis, remediation, and information sharing.&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
=== 3.12 Security Assessment ===&lt;br /&gt;
&lt;br /&gt;
{{Requirement&lt;br /&gt;
|id=3.12.1&lt;br /&gt;
|title=Periodically assess the security controls in organizational systems to determine if the controls are effective in their application.&lt;br /&gt;
|objectives=&lt;br /&gt;
* 3.12.1[a] the frequency of security control assessments is defined.&lt;br /&gt;
* 3.12.1[b] security controls are assessed with the defined frequency to determine if the controls are effective in their application.&lt;br /&gt;
|examine=Security assessment and authorization policy; procedures addressing security assessment planning; procedures addressing security assessments; security assessment plan; system security plan; other relevant documents or records.&lt;br /&gt;
|interview=Personnel with security assessment responsibilities; personnel with information security responsibilities.&lt;br /&gt;
|test=Mechanisms supporting security assessment, security assessment plan development, and security assessment reporting.&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
{{Requirement&lt;br /&gt;
|id=3.12.2&lt;br /&gt;
|title=Develop and implement plans of action designed to correct deficiencies and reduce or eliminate vulnerabilities in organizational systems.&lt;br /&gt;
|objectives=&lt;br /&gt;
* 3.12.2[a] deficiencies and vulnerabilities to be addressed by the plan of action are identified.&lt;br /&gt;
* 3.12.2[b] a plan of action is developed to correct identified deficiencies and reduce or eliminate identified vulnerabilities.&lt;br /&gt;
* 3.12.2[c] the plan of action is implemented to correct identified deficiencies and reduce or eliminate identified vulnerabilities.&lt;br /&gt;
|examine=Security assessment and authorization policy; procedures addressing plan of action; system security plan; security assessment plan; security assessment report; security assessment evidence; plan of action; other relevant documents or records.&lt;br /&gt;
|interview=Personnel with plan of action development and implementation responsibilities; personnel with information security responsibilities.&lt;br /&gt;
|test=Mechanisms for developing, implementing, and maintaining plan of action.&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
{{Requirement&lt;br /&gt;
|id=3.12.3&lt;br /&gt;
|title=Monitor security controls on an ongoing basis to ensure the continued effectiveness of the controls.&lt;br /&gt;
|objectives=Determine if security controls are monitored on an ongoing basis to ensure the continued effectiveness of those controls.&lt;br /&gt;
|examine=Security planning policy; organizational procedures addressing system security plan development and implementation; procedures addressing system security plan reviews and updates; enterprise architecture documentation; system security plan; records of system security plan reviews and updates; other relevant documents or records.&lt;br /&gt;
|interview=Personnel with security planning and system security plan implementation responsibilities; personnel with information security responsibilities.&lt;br /&gt;
|test=Organizational processes for system security plan development, review, update, and approval; mechanisms supporting the system security plan.&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
{{Requirement&lt;br /&gt;
|id=3.12.4&lt;br /&gt;
|title=Develop, document, and periodically update system security plans that describe system boundaries, system environments of operation, how security requirements are implemented, and the relationships with or connections to other systems.&lt;br /&gt;
|objectives=&lt;br /&gt;
* 3.12.4[a] a system security plan is developed.&lt;br /&gt;
* 3.12.4[b] the system boundary is described and documented in the system security plan.&lt;br /&gt;
* 3.12.4[c] the system environment of operation is described and documented in the system security plan.&lt;br /&gt;
* 3.12.4[d] the security requirements identified and approved by the designated authority as non-applicable are identified.&lt;br /&gt;
* 3.12.4[e] the method of security requirement implementation is described and documented in the system security plan.&lt;br /&gt;
* 3.12.4[f] the relationship with or connection to other systems is described and documented in the system security plan.&lt;br /&gt;
* 3.12.4[g] the frequency to update the system security plan is defined.&lt;br /&gt;
* 3.12.4[h] system security plan is updated with the defined frequency.&lt;br /&gt;
|examine=Security planning policy; procedures addressing system security plan development and implementation; procedures addressing system security plan reviews and updates; enterprise architecture documentation; system security plan; records of system security plan reviews and updates; other relevant documents or records.&lt;br /&gt;
|interview=Personnel with security planning and system security plan implementation responsibilities; personnel with information security responsibilities.&lt;br /&gt;
|test=Organizational processes for system security plan development, review, update, and approval; mechanisms supporting the system security plan.&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
=== 3.13 System and Communications Protection ===&lt;br /&gt;
&lt;br /&gt;
{{Requirement&lt;br /&gt;
|id=3.13.1&lt;br /&gt;
|title=Monitor, control, and protect communications (i.e., information transmitted or received by organizational systems) at the external boundaries and key internal boundaries of organizational systems.&lt;br /&gt;
|objectives=&lt;br /&gt;
* 3.13.1[a] the external system boundary is defined.&lt;br /&gt;
* 3.13.1[b] key internal system boundaries are defined.&lt;br /&gt;
* 3.13.1[c] communications are monitored at the external system boundary.&lt;br /&gt;
* 3.13.1[d] communications are monitored at key internal boundaries.&lt;br /&gt;
* 3.13.1[e] communications are controlled at the external system boundary.&lt;br /&gt;
* 3.13.1[f] communications are controlled at key internal boundaries.&lt;br /&gt;
* 3.13.1[g] communications are protected at the external system boundary.&lt;br /&gt;
* 3.13.1[h] communications are protected at key internal boundaries.&lt;br /&gt;
|examine=System and communications protection policy; procedures addressing boundary protection; system security plan; list of key internal boundaries of the system; system design documentation; boundary protection hardware and software; enterprise security architecture documentation; system audit logs and records; system configuration settings and associated documentation; other relevant documents or records.&lt;br /&gt;
|interview=System or network administrators; personnel with information security responsibilities; system developer; personnel with boundary protection responsibilities.&lt;br /&gt;
|test=Mechanisms implementing boundary protection capability.&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
{{Requirement&lt;br /&gt;
|id=3.13.2&lt;br /&gt;
|title=Employ architectural designs, software development techniques, and systems engineering principles that promote effective information security within organizational systems.&lt;br /&gt;
|objectives=&lt;br /&gt;
* 3.13.2[a] architectural designs that promote effective information security are identified.&lt;br /&gt;
* 3.13.2[b] software development techniques that promote effective information security are identified.&lt;br /&gt;
* 3.13.2[c] systems engineering principles that promote effective information security are identified.&lt;br /&gt;
* 3.13.2[d] identified architectural designs that promote effective information security are employed.&lt;br /&gt;
* 3.13.2[e] identified software development techniques that promote effective information security are employed.&lt;br /&gt;
* 3.13.2[f] identified systems engineering principles that promote effective information security are employed.&lt;br /&gt;
|examine=Security planning policy; procedures addressing system security plan development and implementation; procedures addressing system security plan reviews and updates; enterprise architecture documentation; system security plan; records of system security plan reviews and updates; system and communications protection policy; procedures addressing security engineering principles used in the specification, design, development, implementation, and modification of the system; security architecture documentation; security requirements and specifications for the system; system design documentation; system configuration settings and associated documentation; other relevant documents or records.&lt;br /&gt;
|interview=Personnel with responsibility for determining information system security requirements; personnel with information system design, development, implementation, and modification responsibilities; personnel with security planning and system security plan implementation responsibilities; personnel with information security responsibilities.&lt;br /&gt;
|test=Organizational processes for system security plan development, review, update, and approval; mechanisms supporting the system security plan; processes for applying security engineering principles in system specification, design, development, implementation, and modification; automated mechanisms supporting the application of security engineering principles in information system specification, design, development, implementation, and modification.&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
{{Requirement&lt;br /&gt;
|id=3.13.3&lt;br /&gt;
|title=Separate user functionality from system management functionality.&lt;br /&gt;
|objectives=&lt;br /&gt;
* 3.13.3[a] user functionality is identified.&lt;br /&gt;
* 3.13.3[b] system management functionality is identified.&lt;br /&gt;
* 3.13.3[c] user functionality is separated from system management functionality.&lt;br /&gt;
|examine=System and communications protection policy; procedures addressing application partitioning; system design documentation; system configuration settings and associated documentation; system security plan; system audit logs and records; other relevant documents or records.&lt;br /&gt;
|interview=System or network administrators; personnel with information security responsibilities; system developer.&lt;br /&gt;
|test=Separation of user functionality from system management functionality.&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
{{Requirement&lt;br /&gt;
|id=3.13.4&lt;br /&gt;
|title=Prevent unauthorized and unintended information transfer via shared system resources.&lt;br /&gt;
|objectives=Determine if unauthorized and unintended information transfer via shared system resources is prevented.&lt;br /&gt;
|examine=System and communications protection policy; procedures addressing application partitioning; system security plan; system design documentation; system configuration settings and associated documentation; system audit logs and records; other relevant documents or records.&lt;br /&gt;
|interview=System or network administrators; personnel with information security responsibilities; system developer.&lt;br /&gt;
|test=Separation of user functionality from system management functionality.&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
{{Requirement&lt;br /&gt;
|id=3.13.5&lt;br /&gt;
|title=Implement subnetworks for publicly accessible system components that are physically or logically separated from internal networks.&lt;br /&gt;
|objectives=&lt;br /&gt;
* 3.13.5[a] publicly accessible system components are identified.&lt;br /&gt;
* 3.13.5[b] subnetworks for publicly accessible system components are physically or logically separated from internal networks.&lt;br /&gt;
|examine=System and communications protection policy; procedures addressing boundary protection; system security plan; list of key internal boundaries of the system; system design documentation; boundary protection hardware and software; system configuration settings and associated documentation; enterprise security architecture documentation; system audit logs and records; other relevant documents or records.&lt;br /&gt;
|interview=System or network administrators; personnel with information security responsibilities; system developer; personnel with boundary protection responsibilities.&lt;br /&gt;
|test=Mechanisms implementing boundary protection capability.&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
{{Requirement&lt;br /&gt;
|id=3.13.6&lt;br /&gt;
|title=Deny network communications traffic by default and allow network communications traffic by exception (i.e., deny all, permit by exception).&lt;br /&gt;
|objectives=&lt;br /&gt;
* 3.13.6[a] network communications traffic is denied by default.&lt;br /&gt;
* 3.13.6[b] network communications traffic is allowed by exception.&lt;br /&gt;
|examine=System and communications protection policy; procedures addressing boundary protection; system security plan; system design documentation; system configuration settings and associated documentation; system audit logs and records; other relevant documents or records.&lt;br /&gt;
|interview=System or network administrators; personnel with information security responsibilities; system developer; personnel with boundary protection responsibilities.&lt;br /&gt;
|test=Mechanisms implementing traffic management at managed interfaces.&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
{{Requirement&lt;br /&gt;
|id=3.13.7&lt;br /&gt;
|title=Prevent remote devices from simultaneously establishing non-remote connections with organizational systems and communicating via some other connection to resources in external networks (i.e., split tunneling).&lt;br /&gt;
|objectives=Determine if remote devices are prevented from simultaneously establishing non-remote connections with the system and communicating via some other connection to resources in external networks (i.e., split tunneling).&lt;br /&gt;
|examine=System and communications protection policy; procedures addressing boundary protection; system security plan; system design documentation; system hardware and software; system architecture; system configuration settings and associated documentation; system audit logs and records; other relevant documents or records.&lt;br /&gt;
|interview=System or network administrators; personnel with information security responsibilities; system developer; personnel with boundary protection responsibilities.&lt;br /&gt;
|test=Mechanisms implementing boundary protection capability; mechanisms supporting or restricting non-remote connections.&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
{{Requirement&lt;br /&gt;
|id=3.13.8&lt;br /&gt;
|title=Implement cryptographic mechanisms to prevent unauthorized disclosure of CUI during transmission unless otherwise protected by alternative physical safeguards.&lt;br /&gt;
|objectives=&lt;br /&gt;
* 3.13.8[a] cryptographic mechanisms intended to prevent unauthorized disclosure of CUI are identified.&lt;br /&gt;
* 3.13.8[b] alternative physical safeguards intended to prevent unauthorized disclosure of CUI are identified.&lt;br /&gt;
* 3.13.8[c] either cryptographic mechanisms or alternative physical safeguards are implemented to prevent unauthorized disclosure of CUI during transmission.&lt;br /&gt;
|examine=System and communications protection policy; procedures addressing transmission confidentiality and integrity; system security plan; system design documentation; system configuration settings and associated documentation; system audit logs and records; other relevant documents or records.&lt;br /&gt;
|interview=System or network administrators; personnel with information security responsibilities; system developer.&lt;br /&gt;
|test=Cryptographic mechanisms or mechanisms supporting or implementing transmission confidentiality; organizational processes for defining and implementing alternative physical safeguards.&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
{{Requirement&lt;br /&gt;
|id=3.13.9&lt;br /&gt;
|title=Terminate network connections associated with communications sessions at the end of the sessions or after a defined period of inactivity.&lt;br /&gt;
|objectives=&lt;br /&gt;
* 3.13.9[a] a period of inactivity to terminate network connections associated with communications sessions is defined.&lt;br /&gt;
* 3.13.9[b] network connections associated with communications sessions are terminated at the end of the sessions.&lt;br /&gt;
* 3.13.9[c] network connections associated with communications sessions are terminated after the defined period of inactivity.&lt;br /&gt;
|examine=System and communications protection policy; procedures addressing network disconnect; system design documentation; system security plan; system configuration settings and associated documentation; system audit logs and records; other relevant documents or records.&lt;br /&gt;
|interview=System or network administrators; personnel with information security responsibilities; system developer.&lt;br /&gt;
|test=Mechanisms supporting or implementing network disconnect capability.&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
{{Requirement&lt;br /&gt;
|id=3.13.10&lt;br /&gt;
|title=Establish and manage cryptographic keys for cryptography employed in organizational systems.&lt;br /&gt;
|objectives=&lt;br /&gt;
* 3.13.10[a] cryptographic keys are established whenever cryptography is employed.&lt;br /&gt;
* 3.13.10[b] cryptographic keys are managed whenever cryptography is employed.&lt;br /&gt;
|examine=System and communications protection policy; procedures addressing cryptographic key establishment and management; system security plan; system design documentation; cryptographic mechanisms; system configuration settings and associated documentation; system audit logs and records; other relevant documents or records.&lt;br /&gt;
|interview=System or network administrators; personnel with information security responsibilities; personnel with responsibilities for cryptographic key establishment and management.&lt;br /&gt;
|test=Mechanisms supporting or implementing cryptographic key establishment and management.&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
{{Requirement&lt;br /&gt;
|id=3.13.11&lt;br /&gt;
|title=Employ FIPS-validated cryptography when used to protect the confidentiality of CUI.&lt;br /&gt;
|objectives=Determine if FIPS-validated cryptography is employed to protect the confidentiality of CUI.&lt;br /&gt;
|examine=System and communications protection policy; procedures addressing cryptographic protection; system security plan; system design documentation; system configuration settings and associated documentation; cryptographic module validation certificates; list of FIPS-validated cryptographic modules; system audit logs and records; other relevant documents or records.&lt;br /&gt;
|interview=System or network administrators; personnel with information security responsibilities; system developer; personnel with responsibilities for cryptographic protection.&lt;br /&gt;
|test=Mechanisms supporting or implementing cryptographic protection.&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
{{Requirement&lt;br /&gt;
|id=3.13.12&lt;br /&gt;
|title=Prohibit remote activation of collaborative computing devices and provide indication of devices in use to users present at the device.&lt;br /&gt;
|objectives=&lt;br /&gt;
* 3.13.12[a] collaborative computing devices are identified.&lt;br /&gt;
* 3.13.12[b] collaborative computing devices provide indication to users of devices in use.&lt;br /&gt;
* 3.13.12[c] remote activation of collaborative computing devices is prohibited.&lt;br /&gt;
|examine=System and communications protection policy; procedures addressing collaborative computing; access control policy and procedures; system security plan; system design documentation; system audit logs and records; system configuration settings and associated documentation; other relevant documents or records.&lt;br /&gt;
|interview=System or network administrators; personnel with information security responsibilities; system developer; personnel with responsibilities for managing collaborative computing devices.&lt;br /&gt;
|test=Mechanisms supporting or implementing management of remote activation of collaborative computing devices; mechanisms providing an indication of use of collaborative computing devices.&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
{{Requirement&lt;br /&gt;
|id=3.13.13&lt;br /&gt;
|title=Control and monitor the use of mobile code.&lt;br /&gt;
|objectives=&lt;br /&gt;
* 3.13.13[a] use of mobile code is controlled.&lt;br /&gt;
* 3.13.13[b] use of mobile code is monitored.&lt;br /&gt;
|examine=System and communications protection policy; procedures addressing mobile code; mobile code usage restrictions, mobile code implementation policy and procedures; system audit logs and records; system security plan; list of acceptable mobile code and mobile code technologies; list of unacceptable mobile code and mobile technologies; authorization records; system monitoring records; system audit logs and records; other relevant documents or records.&lt;br /&gt;
|interview=System or network administrators; personnel with information security responsibilities; personnel with responsibilities for managing mobile code.&lt;br /&gt;
|test=Organizational process for controlling, authorizing, monitoring, and restricting mobile code; mechanisms supporting or implementing the management of mobile code; mechanisms supporting or implementing the monitoring of mobile code.&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
{{Requirement&lt;br /&gt;
|id=3.13.14&lt;br /&gt;
|title=Control and monitor the use of Voice over Internet Protocol (VoIP) technologies.&lt;br /&gt;
|objectives=&lt;br /&gt;
* 3.13.14[a] use of Voice over Internet Protocol (VoIP) technologies is controlled.&lt;br /&gt;
* 3.13.14[b] use of Voice over Internet Protocol (VoIP) technologies is monitored.&lt;br /&gt;
|examine=System and communications protection policy; procedures addressing VoIP; VoIP usage restrictions; VoIP implementation guidance; system security plan; system design documentation; system audit logs and records; system configuration settings and associated documentation; system monitoring records; other relevant documents or records.&lt;br /&gt;
|interview=System or network administrators; personnel with information security responsibilities; personnel with responsibilities for managing VoIP.&lt;br /&gt;
|test=Organizational process for authorizing, monitoring, and controlling VoIP; mechanisms supporting or implementing authorizing, monitoring, and controlling VoIP.&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
{{Requirement&lt;br /&gt;
|id=3.13.15&lt;br /&gt;
|title=Protect the authenticity of communications sessions.&lt;br /&gt;
|objectives=Determine if the authenticity of communications sessions is protected.&lt;br /&gt;
|examine=System and communications protection policy; procedures addressing session authenticity; system security plan; system design documentation; system configuration settings and associated documentation; system audit logs and records; other relevant documents or records.&lt;br /&gt;
|interview=System or network administrators; personnel with information security responsibilities.&lt;br /&gt;
|test=Mechanisms supporting or implementing session authenticity.&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
{{Requirement&lt;br /&gt;
|id=3.13.16&lt;br /&gt;
|title=Protect the confidentiality of CUI at rest.&lt;br /&gt;
|objectives=Determine if the confidentiality of CUI at rest is protected.&lt;br /&gt;
|examine=System and communications protection policy; procedures addressing protection of information at rest; system security plan; system design documentation; list of information at rest requiring confidentiality protections; system configuration settings and associated documentation; cryptographic mechanisms and associated configuration documentation; other relevant documents or records.&lt;br /&gt;
|interview=System or network administrators; personnel with information security responsibilities; system developer.&lt;br /&gt;
|test=Mechanisms supporting or implementing confidentiality protections for information at rest.&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
=== 3.14 System and Information Integrity ===&lt;br /&gt;
&lt;br /&gt;
{{Requirement&lt;br /&gt;
|id=3.14.1&lt;br /&gt;
|title=Identify, report, and correct system flaws in a timely manner.&lt;br /&gt;
|objectives=&lt;br /&gt;
* 3.14.1[a] the time within which to identify system flaws is specified.&lt;br /&gt;
* 3.14.1[b] system flaws are identified within the specified time frame.&lt;br /&gt;
* 3.14.1[c] the time within which to report system flaws is specified.&lt;br /&gt;
* 3.14.1[d] system flaws are reported within the specified time frame.&lt;br /&gt;
* 3.14.1[e] the time within which to correct system flaws is specified.&lt;br /&gt;
* 3.14.1[f] system flaws are corrected within the specified time frame.&lt;br /&gt;
|examine=System and information integrity policy; procedures addressing flaw remediation; procedures addressing configuration management; system security plan; list of flaws and vulnerabilities potentially affecting the system; list of recent security flaw remediation actions performed on the system (e.g., list of installed patches, service packs, hot fixes, and other software updates to correct system flaws); test results from the installation of software and firmware updates to correct system flaws; installation/change control records for security-relevant software and firmware updates; other relevant documents or records.&lt;br /&gt;
|interview=System or network administrators; personnel with information security responsibilities; personnel installing, configuring, and maintaining the system; personnel with responsibility for flaw remediation; personnel with configuration management responsibility.&lt;br /&gt;
|test=Organizational processes for identifying, reporting, and correcting system flaws; organizational process for installing software and firmware updates; mechanisms supporting or implementing reporting, and correcting system flaws; mechanisms supporting or implementing testing software and firmware updates.&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
{{Requirement&lt;br /&gt;
|id=3.14.2&lt;br /&gt;
|title=Provide protection from malicious code at designated locations within organizational systems.&lt;br /&gt;
|objectives=&lt;br /&gt;
* 3.14.2[a] designated locations for malicious code protection are identified.&lt;br /&gt;
* 3.14.2[b] protection from malicious code at designated locations is provided.&lt;br /&gt;
|examine=System and information integrity policy; configuration management policy and procedures; procedures addressing malicious code protection; records of malicious code protection updates; malicious code protection mechanisms; system security plan; system configuration settings and associated documentation; record of actions initiated by malicious code protection mechanisms in response to malicious code detection; scan results from malicious code protection mechanisms; system design documentation; system audit logs and records; other relevant documents or records.&lt;br /&gt;
|interview=System or network administrators; personnel with information security responsibilities; personnel installing, configuring, and maintaining the system; personnel with responsibility for malicious code protection; personnel with configuration management responsibility.&lt;br /&gt;
|test=Organizational processes for employing, updating, and configuring malicious code protection mechanisms; organizational process for addressing false positives and resulting potential impact; mechanisms supporting or implementing employing, updating, and configuring malicious code protection mechanisms; mechanisms supporting or implementing malicious code scanning and subsequent actions.&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
{{Requirement&lt;br /&gt;
|id=3.14.3&lt;br /&gt;
|title=Monitor system security alerts and advisories and take action in response.&lt;br /&gt;
|objectives=&lt;br /&gt;
* 3.14.3[a] response actions to system security alerts and advisories are identified.&lt;br /&gt;
* 3.14.3[b] system security alerts and advisories are monitored.&lt;br /&gt;
* 3.14.3[c] actions in response to system security alerts and advisories are taken.&lt;br /&gt;
|examine=System and information integrity policy; procedures addressing security alerts, advisories, and directives; system security plan; records of security alerts and advisories; other relevant documents or records.&lt;br /&gt;
|interview=Personnel with security alert and advisory responsibilities; personnel implementing, operating, maintaining, and using the system; personnel, organizational elements, and external organizations to whom alerts, advisories, and directives are to be disseminated; system or network administrators; personnel with information security responsibilities.&lt;br /&gt;
|test=Organizational processes for defining, receiving, generating, disseminating, and complying with security alerts, advisories, and directives; mechanisms supporting or implementing definition, receipt, generation, and dissemination of security alerts, advisories, and directives; mechanisms supporting or implementing security directives.&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
{{Requirement&lt;br /&gt;
|id=3.14.4&lt;br /&gt;
|title=Update malicious code protection mechanisms when new releases are available.&lt;br /&gt;
|objectives=Determine if malicious code protection mechanisms are updated when new releases are available.&lt;br /&gt;
|examine=System and information integrity policy; configuration management policy and procedures; procedures addressing malicious code protection; malicious code protection mechanisms; records of malicious code protection updates; system security plan; system design documentation; system configuration settings and associated documentation; scan results from malicious code protection mechanisms; record of actions initiated by malicious code protection mechanisms in response to malicious code detection; system audit logs and records; other relevant documents or records.&lt;br /&gt;
|interview=System or network administrators; personnel with information security responsibilities; personnel installing, configuring, and maintaining the system; personnel with responsibility for malicious code protection; personnel with configuration management responsibility.&lt;br /&gt;
|test=Organizational processes for employing, updating, and configuring malicious code protection mechanisms; organizational process for addressing false positives and resulting potential impact; mechanisms supporting or implementing malicious code protection mechanisms (including updates and configurations); mechanisms supporting or implementing malicious code scanning and subsequent actions.&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
{{Requirement&lt;br /&gt;
|id=3.14.5&lt;br /&gt;
|title=Perform periodic scans of organizational systems and real-time scans of files from external sources as files are downloaded, opened, or executed.&lt;br /&gt;
|objectives=&lt;br /&gt;
* 3.14.5[a] the frequency for malicious code scans is defined.&lt;br /&gt;
* 3.14.5[b] malicious code scans are performed with the defined frequency.&lt;br /&gt;
* 3.14.5[c] real-time malicious code scans of files from external sources as files are downloaded, opened, or executed are performed.&lt;br /&gt;
|examine=System and information integrity policy; configuration management policy and procedures; procedures addressing malicious code protection; malicious code protection mechanisms; records of malicious code protection updates; system security plan; system design documentation; system configuration settings and associated documentation; scan results from malicious code protection mechanisms; record of actions initiated by malicious code protection mechanisms in response to malicious code detection; system audit logs and records; other relevant documents or records.&lt;br /&gt;
|interview=System or network administrators; personnel with information security responsibilities; personnel installing, configuring, and maintaining the system; personnel with responsibility for malicious code protection; personnel with configuration management responsibility.&lt;br /&gt;
|test=Organizational processes for employing, updating, and configuring malicious code protection mechanisms; organizational process for addressing false positives and resulting potential impact; mechanisms supporting or implementing malicious code protection mechanisms (including updates and configurations); mechanisms supporting or implementing malicious code scanning and subsequent actions.&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
{{Requirement&lt;br /&gt;
|id=3.14.6&lt;br /&gt;
|title=Monitor organizational systems, including inbound and outbound communications traffic, to detect attacks and indicators of potential attacks.&lt;br /&gt;
|objectives=&lt;br /&gt;
* 3.14.6[a] the system is monitored to detect attacks and indicators of potential attacks.&lt;br /&gt;
* 3.14.6[b] inbound communications traffic is monitored to detect attacks and indicators of potential attacks.&lt;br /&gt;
* 3.14.6[c] outbound communications traffic is monitored to detect attacks and indicators of potential attacks.&lt;br /&gt;
|examine=System and information integrity policy; procedures addressing system monitoring tools and techniques; continuous monitoring strategy; facility diagram or layout; system security plan; system monitoring tools and techniques documentation; system design documentation; locations within system where monitoring devices are deployed; system protocols; system configuration settings and associated documentation; system audit logs and records; other relevant documents or records.&lt;br /&gt;
|interview=System or network administrators; personnel with information security responsibilities; personnel installing, configuring, and maintaining the system; personnel with responsibility monitoring the system; personnel with responsibility for the intrusion detection system.&lt;br /&gt;
|test=Organizational processes for system monitoring; mechanisms supporting or implementing intrusion detection capability and system monitoring; mechanisms supporting or implementing system monitoring capability; organizational processes for intrusion detection and system monitoring; mechanisms supporting or implementing the monitoring of inbound and outbound communications traffic.&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
{{Requirement&lt;br /&gt;
|id=3.14.7&lt;br /&gt;
|title=Identify unauthorized use of organizational systems.&lt;br /&gt;
|objectives=&lt;br /&gt;
* 3.14.7[a] authorized use of the system is defined.&lt;br /&gt;
* 3.14.7[b] unauthorized use of the system is identified.&lt;br /&gt;
|examine=Continuous monitoring strategy; system and information integrity policy; procedures addressing system monitoring tools and techniques; facility diagram/layout; system security plan; system design documentation; system monitoring tools and techniques documentation; locations within system where monitoring devices are deployed; system configuration settings and associated documentation; other relevant documents or records.&lt;br /&gt;
|interview=System or network administrators; personnel with information security responsibilities; personnel installing, configuring, and maintaining the system; personnel with responsibility for monitoring the system.&lt;br /&gt;
|test=Organizational processes for system monitoring; mechanisms supporting or implementing system monitoring capability.&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
== Appendix A: References ==&lt;br /&gt;
&#039;&#039;Laws, Executive Orders, Regulations, Instructions, Standards, and Guidelines&#039;&#039;&amp;lt;ref&amp;gt;References in this section without specific publication dates or revision numbers are assumed to refer to the most recent updates to those publications.&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Legislation, Executive Orders, and Regulations ===&lt;br /&gt;
&lt;br /&gt;
# Federal Information Security Modernization Act of 2014 (P.L. 113-283), December 2014. https://www.gpo.gov/fdsys/pkg/PLAW-113publ283/pdf/PLAW-113publ283.pdf&lt;br /&gt;
# Executive Order 13526, &#039;&#039;Classified National Security Information&#039;&#039;, December 2009. https://www.archives.gov/isoo/policy-documents/cnsi-eo.html&lt;br /&gt;
# Executive Order 13556, &#039;&#039;Controlled Unclassified Information&#039;&#039;, November 2010. https://www.gpo.gov/fdsys/pkg/FR-2010-11-09/pdf/2010-28360.pdf&lt;br /&gt;
# Executive Order 13636, &#039;&#039;Improving Critical Infrastructure Cybersecurity&#039;&#039;, February 2013. https://www.gpo.gov/fdsys/pkg/FR-2013-02-19/pdf/2013-03915.pdf&lt;br /&gt;
# 32 CFR Part 2002, &#039;&#039;Controlled Unclassified Information&#039;&#039;, September 2016. https://www.gpo.gov/fdsys/pkg/CFR-2017-title32-vol6/pdf/CFR-2017-title32-vol6-part2002.pdf&lt;br /&gt;
&lt;br /&gt;
=== Standards, Guidelines, Interagency Reports, and Instructions ===&lt;br /&gt;
&lt;br /&gt;
# National Institute of Standards and Technology Federal Information Processing Standards Publication 199, &#039;&#039;Standards for Security Categorization of Federal Information and Information Systems&#039;&#039;, February 2004. https://doi.org/10.6028/NIST.FIPS.199&lt;br /&gt;
# National Institute of Standards and Technology Federal Information Processing Standards Publication 200, &#039;&#039;Minimum Security Requirements for Federal Information and Information Systems&#039;&#039;, March 2006. https://doi.org/10.6028/NIST.FIPS.200&lt;br /&gt;
# National Institute of Standards and Technology Special Publication 800-39, &#039;&#039;Managing Information Security Risk: Organization, Mission, and Information System View&#039;&#039;, March 2011. https://doi.org/10.6028/NIST.SP.800-39&lt;br /&gt;
# National Institute of Standards and Technology Special Publication 800-53, Revision 4, &#039;&#039;Security and Privacy Controls for Federal Information Systems and Organizations&#039;&#039;, April 2013. https://doi.org/10.6028/NIST.SP.800-53r4&lt;br /&gt;
# National Institute of Standards and Technology Special Publication 800-53A, Revision 4, &#039;&#039;Assessing Security and Privacy Controls in Federal Information Systems and Organizations: Building Effective Security Assessment Plans&#039;&#039;, December 2014. https://doi.org/10.6028/NIST.SP.800-53Ar4&lt;br /&gt;
# National Institute of Standards and Technology Special Publication 171, Revision 1, &#039;&#039;Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations&#039;&#039;, December 2016. https://doi.org/10.6028/NIST.SP.800-171r1&lt;br /&gt;
# National Institute of Standards and Technology Special Publication 128, &#039;&#039;Guide for Security-Focused Configuration Management of Information Systems&#039;&#039;, August 2011. https://doi.org/10.6028/NIST.SP.800-128&lt;br /&gt;
# International Organization for Standardization/International Electrotechnical Commission (ISO/IEC) 27001:2013, &#039;&#039;Information technology -- Security techniques -- Information security management systems -- Requirements&#039;&#039;, September 2013.&lt;br /&gt;
# International Organization for Standardization/International Electrotechnical Commission (ISO/IEC) 27002:2013, &#039;&#039;Information technology -- Security techniques -- Code of practice for information security controls&#039;&#039;, September 2013.&lt;br /&gt;
# Committee on National Security Systems Instruction 4009, &#039;&#039;National Information Assurance Glossary&#039;&#039;, April 2015. https://www.cnss.gov&lt;br /&gt;
# National Institute of Standards and Technology Internal Report 8062, &#039;&#039;An Introduction to Privacy Engineering and Risk Management in Federal Systems&#039;&#039;, January 2017. https://doi.org/10.6028/NIST.IR.8062&lt;br /&gt;
&lt;br /&gt;
=== Other Resources ===&lt;br /&gt;
&lt;br /&gt;
# National Archives and Records Administration, &#039;&#039;Controlled Unclassified Information Registry&#039;&#039;. https://www.archives.gov/cui/registry/category-list&lt;br /&gt;
# National Institute of Standards and Technology Handbook 162, &#039;&#039;NIST MEP Cybersecurity Self-Assessment Handbook for Assessing NIST SP 800-171 Security Requirements in Response to DFARS Cybersecurity Requirements&#039;&#039;, November 2017. https://doi.org/10.6028/NIST.HB.162&lt;br /&gt;
&lt;br /&gt;
== Appendix B: Glossary ==&lt;br /&gt;
&#039;&#039;Common terms and definitions&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
Appendix B provides definitions for security terminology used within Special Publication 800-171. Unless specifically defined in this glossary, all terms used in this publication are consistent with the definitions contained in CNSS Instruction 4009, &#039;&#039;National Information Assurance Glossary&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Term !! Definition&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;agency&#039;&#039;&#039; || See &#039;&#039;executive agency&#039;&#039;.&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;assessment&#039;&#039;&#039; || See &#039;&#039;Security Control Assessment&#039;&#039;.&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;assessor&#039;&#039;&#039; || See &#039;&#039;Security Control Assessor&#039;&#039;.&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;audit log&#039;&#039;&#039; || A chronological record of system activities, including records of system accesses and operations performed in a given period.&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;audit record&#039;&#039;&#039; || An individual entry in an audit log related to an audited event.&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;authentication&#039;&#039;&#039; &amp;lt;small&amp;gt;[FIPS 200, Adapted]&amp;lt;/small&amp;gt; || Verifying the identity of a user, process, or device, often as a prerequisite to allowing access to resources in a system.&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;availability&#039;&#039;&#039; &amp;lt;small&amp;gt;[44 U.S.C., Sec. 3542]&amp;lt;/small&amp;gt; || Ensuring timely and reliable access to and use of information.&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;baseline configuration&#039;&#039;&#039; || A documented set of specifications for a system, or a configuration item within a system, that has been formally reviewed and agreed on at a given point in time, and which can be changed only through change control procedures.&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;blacklisting&#039;&#039;&#039; || A process used to identify software programs that are not authorized to execute on a system or prohibited Universal Resource Locators (URL)/websites.&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;confidentiality&#039;&#039;&#039; &amp;lt;small&amp;gt;[44 U.S.C., Sec. 3542]&amp;lt;/small&amp;gt; || Preserving authorized restrictions on information access and disclosure, including means for protecting personal privacy and proprietary information.&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;configuration management&#039;&#039;&#039; || A collection of activities focused on establishing and maintaining the integrity of information technology products and systems, through control of processes for initializing, changing, and monitoring the configurations of those products and systems throughout the system development life cycle.&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;configuration settings&#039;&#039;&#039; || The set of parameters that can be changed in hardware, software, or firmware that affect the security posture and/or functionality of the system.&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;controlled area&#039;&#039;&#039; || Any area or space for which the organization has confidence that the physical and procedural protections provided are sufficient to meet the requirements established for protecting the information or system.&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;controlled unclassified information&#039;&#039;&#039; &amp;lt;small&amp;gt;[E.O. 13556]&amp;lt;/small&amp;gt; || Information that law, regulation, or governmentwide policy requires to have safeguarding or disseminating controls, excluding information that is classified under Executive Order 13526, &#039;&#039;Classified National Security Information&#039;&#039;, December 29, 2009, or any predecessor or successor order, or the Atomic Energy Act of 1954, as amended.&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;CUI categories or subcategories&#039;&#039;&#039; &amp;lt;small&amp;gt;[Title 32 CFR, Part 2002]&amp;lt;/small&amp;gt; || Those types of information for which laws, regulations, or governmentwide policies require or permit agencies to exercise safeguarding or dissemination controls, and which the CUI Executive Agent has approved and listed in the CUI Registry.&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;CUI Executive Agent&#039;&#039;&#039; &amp;lt;small&amp;gt;[Title 32 CFR, Part 2002]&amp;lt;/small&amp;gt; || The National Archives and Records Administration (NARA), which implements the executive branch-wide CUI Program and oversees federal agency actions to comply with Executive Order 13556. NARA has delegated this authority to the Director of the Information Security Oversight Office (ISOO).&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;CUI program&#039;&#039;&#039; &amp;lt;small&amp;gt;[Title 32 CFR, Part 2002]&amp;lt;/small&amp;gt; || The executive branch-wide program to standardize CUI handling by all federal agencies. The program includes the rules, organization, and procedures for CUI, established by Executive Order 13556, 32 CFR Part 2002, and the CUI Registry.&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;CUI registry&#039;&#039;&#039; &amp;lt;small&amp;gt;[Title 32 CFR, Part 2002]&amp;lt;/small&amp;gt; || The online repository for all information, guidance, policy, and requirements on handling CUI, including everything issued by the CUI Executive Agent other than 32 CFR Part 2002. Among other information, the CUI Registry identifies all approved CUI categories and subcategories, provides general descriptions for each, identifies the basis for controls, establishes markings, and includes guidance on handling procedures.&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;environment of operation&#039;&#039;&#039; &amp;lt;small&amp;gt;[NIST SP 800-37, Adapted]&amp;lt;/small&amp;gt; || The physical surroundings in which a system processes, stores, and transmits information.&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;executive agency&#039;&#039;&#039; &amp;lt;small&amp;gt;[41 U.S.C., Sec. 403]&amp;lt;/small&amp;gt; || An executive department specified in 5 U.S.C., Sec. 105; a military department specified in 5 U.S.C., Sec. 102; an independent establishment as defined in 5 U.S.C., Sec. 104(1); and a wholly owned Government corporation fully subject to the provisions of 31 U.S.C., Chapter 91.&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;external system (or component)&#039;&#039;&#039; || A system or component of a system that is outside of the authorization boundary established by the organization and for which the organization typically has no direct control over the application of required security controls or the assessment of security control effectiveness.&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;external system service&#039;&#039;&#039; || A system service that is implemented outside of the authorization boundary of the organizational system (i.e., a service that is used by, but not a part of, the organizational system) and for which the organization typically has no direct control over the application of required security controls or the assessment of security control effectiveness.&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;external system service provider&#039;&#039;&#039; || A provider of external system services to an organization through a variety of consumer-producer relationships including but not limited to: joint ventures; business partnerships; outsourcing arrangements (i.e., through contracts, interagency agreements, lines of business arrangements); licensing agreements; and/or supply chain exchanges.&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;external network&#039;&#039;&#039; || A network not controlled by the organization.&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;federal agency&#039;&#039;&#039; || See &#039;&#039;executive agency&#039;&#039;.&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;federal information system&#039;&#039;&#039; &amp;lt;small&amp;gt;[40 U.S.C., Sec. 11331]&amp;lt;/small&amp;gt; || An information system used or operated by an executive agency, by a contractor of an executive agency, or by another organization on behalf of an executive agency. See &#039;&#039;on behalf of (an agency)&#039;&#039; for additional information.&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;FIPS-validated cryptography&#039;&#039;&#039; || A cryptographic module validated by the Cryptographic Module Validation Program (CMVP) to meet requirements specified in FIPS Publication 140-2 (as amended). As a prerequisite to CMVP validation, the cryptographic module is required to employ a cryptographic algorithm implementation that has successfully passed validation testing by the Cryptographic Algorithm Validation Program (CAVP). See &#039;&#039;NSA-Approved Cryptography&#039;&#039;.&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;firmware&#039;&#039;&#039; || Computer programs and data stored in hardware - typically in read-only memory (ROM) or programmable read-only memory (PROM) - such that the programs and data cannot be dynamically written or modified during execution of the programs.&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;hardware&#039;&#039;&#039; || The physical components of a system. See &#039;&#039;Software&#039;&#039; and &#039;&#039;Firmware&#039;&#039;.&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;identifier&#039;&#039;&#039; || Unique data used to represent a person&#039;s identity and associated attributes. A name or a card number are examples of identifiers. A unique label used by a system to indicate a specific entity, object, or group.&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;impact&#039;&#039;&#039; || The effect on organizational operations, organizational assets, individuals, other organizations, or the Nation (including the national security interests of the United States) of a loss of confidentiality, integrity, or availability of information or a system.&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;impact value&#039;&#039;&#039; || The assessed potential impact resulting from a compromise of the confidentiality of information (e.g., CUI) expressed as a value of low, moderate, or high.&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;incident&#039;&#039;&#039; &amp;lt;small&amp;gt;[FIPS 200, Adapted]&amp;lt;/small&amp;gt; || An occurrence that actually or potentially jeopardizes the confidentiality, integrity, or availability of a system or the information the system processes, stores, or transmits or that constitutes a violation or imminent threat of violation of security policies, security procedures, or acceptable use policies.&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;information&#039;&#039;&#039; || Any communication or representation of knowledge such as facts, data, or opinions in any medium or form, including textual, numerical, graphic, cartographic, narrative, or audiovisual.&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;information flow control&#039;&#039;&#039; || Procedure to ensure that information transfers within a system are not made in violation of the security policy.&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;information resources&#039;&#039;&#039; &amp;lt;small&amp;gt;[44 U.S.C., Sec. 3502]&amp;lt;/small&amp;gt; || Information and related resources, such as personnel, equipment, funds, and information technology.&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;information security&#039;&#039;&#039; &amp;lt;small&amp;gt;[44 U.S.C., Sec. 3542]&amp;lt;/small&amp;gt; || The protection of information and information systems from unauthorized access, use, disclosure, disruption, modification, or destruction in order to provide confidentiality, integrity, and availability.&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;information system&#039;&#039;&#039; &amp;lt;small&amp;gt;[44 U.S.C., Sec. 3502]&amp;lt;/small&amp;gt; || A discrete set of information resources organized for the collection, processing, maintenance, use, sharing, dissemination, or disposition of information.&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;information technology&#039;&#039;&#039; &amp;lt;small&amp;gt;[40 U.S.C., Sec. 1401]&amp;lt;/small&amp;gt; || Any equipment or interconnected system or subsystem of equipment that is used in the automatic acquisition, storage, manipulation, management, movement, control, display, switching, interchange, transmission, or reception of data or information by the executive agency. For purposes of the preceding sentence, equipment is used by an executive agency if the equipment is used by the executive agency directly or is used by a contractor under a contract with the executive agency which: (i) requires the use of such equipment; or (ii) requires the use, to a significant extent, of such equipment in the performance of a service or the furnishing of a product. The term &#039;&#039;information technology&#039;&#039; includes computers, ancillary equipment, software, firmware, and similar procedures, services (including support services), and related resources.&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;insider threat&#039;&#039;&#039; || The threat that an insider will use her/his authorized access, wittingly or unwittingly, to do harm to the security of the United States. This threat can include damage to the United States through espionage, terrorism, unauthorized disclosure, or through the loss or degradation of departmental resources or capabilities.&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;integrity&#039;&#039;&#039; &amp;lt;small&amp;gt;[44 U.S.C., Sec. 3542]&amp;lt;/small&amp;gt; || Guarding against improper information modification or destruction, and includes ensuring information non-repudiation and authenticity.&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;internal network&#039;&#039;&#039; || A network where establishment, maintenance, and provisioning of security controls are under the direct control of organizational employees or contractors; or the cryptographic encapsulation or similar security technology implemented between organization-controlled endpoints, provides the same effect (with regard to confidentiality and integrity). An internal network is typically organization-owned, yet may be organization-controlled while not being organization-owned.&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;least privilege&#039;&#039;&#039; || The principle that a system security architecture is designed so that each entity is granted the minimum system resources and authorizations that the entity needs to perform its function.&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;local access&#039;&#039;&#039; || Access to an organizational system by a user (or process acting on behalf of a user) communicating through a direct connection without the use of a network.&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;malicious code&#039;&#039;&#039; || Software or firmware intended to perform an unauthorized process that will have adverse impact on the confidentiality, integrity, or availability of a system. A virus, worm, Trojan horse, or other code-based entity that infects a host. Spyware and some forms of adware are also examples of malicious code.&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;media&#039;&#039;&#039; &amp;lt;small&amp;gt;[FIPS 200]&amp;lt;/small&amp;gt; || Physical devices or writing surfaces including, but not limited to, magnetic tapes, optical disks, magnetic disks, Large-Scale Integration (LSI) memory chips, and printouts (but not including display media) onto which information is recorded, stored, or printed within a system.&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;mobile code&#039;&#039;&#039; || Software programs or parts of programs obtained from remote systems, transmitted across a network, and executed on a local system without explicit installation or execution by the recipient.&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;mobile device&#039;&#039;&#039; || A portable computing device that has a small form factor such that it can easily be carried by a single individual; is designed to operate without a physical connection (e.g., wirelessly transmit or receive information); possesses local, non-removable/removable data storage; and includes a self-contained power source. Mobile devices may also include voice communication capabilities, on-board sensors that allow the devices to capture information, or built-in features that synchronize local data with remote locations. Examples include smartphones, tablets, and E-readers.&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;multifactor authentication&#039;&#039;&#039; || Authentication using two or more different factors to achieve authentication. Factors include something you know (e.g., PIN, password); something you have (e.g., cryptographic identification device, token); or something you are (e.g., biometric). See also &#039;&#039;Authenticator&#039;&#039;.&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;nonfederal organization&#039;&#039;&#039; || An entity that owns, operates, or maintains a nonfederal system.&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;nonfederal system&#039;&#039;&#039; || A system that does not meet the criteria for a federal system.&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;network&#039;&#039;&#039; || A system implemented with a collection of interconnected components. Such components may include routers, hubs, cabling, telecommunications controllers, key distribution centers, and technical control devices.&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;network access&#039;&#039;&#039; || Access to a system by a user (or a process acting on behalf of a user) communicating through a network (e.g., local area network, wide area network, Internet).&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;nonlocal maintenance&#039;&#039;&#039; || Maintenance activities conducted by individuals communicating through a network, either an external network (e.g., the Internet) or an internal network.&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;on behalf of (an agency)&#039;&#039;&#039; &amp;lt;small&amp;gt;[32 CFR Part 2002]&amp;lt;/small&amp;gt; || A situation that occurs when: (i) a non-executive branch entity uses or operates an information system or maintains or collects information for the purpose of processing, storing, or transmitting Federal information; and (ii) those activities are not incidental to providing a service or product to the government.&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;organization&#039;&#039;&#039; &amp;lt;small&amp;gt;[FIPS 200, Adapted]&amp;lt;/small&amp;gt; || An entity of any size, complexity, or positioning within an organizational structure.&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;portable storage device&#039;&#039;&#039; || A system component that can be inserted into and removed from a system, and that is used to store data or information (e.g., text, video, audio, and/or image data). Such components are typically implemented on magnetic, optical, or solid-state devices (e.g., floppy disks, compact/digital video disks, flash/thumb drives, external hard disk drives, and flash memory cards/drives that contain nonvolatile memory).&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;potential impact&#039;&#039;&#039; &amp;lt;small&amp;gt;[FIPS 199]&amp;lt;/small&amp;gt; || The loss of confidentiality, integrity, or availability could be expected to have: (i) a &#039;&#039;limited&#039;&#039; adverse effect (FIPS Publication 199 low); (ii) a &#039;&#039;serious&#039;&#039; adverse effect (FIPS Publication 199 moderate); or (iii) a &#039;&#039;severe&#039;&#039; or &#039;&#039;catastrophic&#039;&#039; adverse effect (FIPS Publication 199 high) on organizational operations, organizational assets, or individuals.&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;privileged account&#039;&#039;&#039; || A system account with authorizations of a privileged user.&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;privileged user&#039;&#039;&#039; || A user that is authorized (and therefore, trusted) to perform security-relevant functions that ordinary users are not authorized to perform.&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;records&#039;&#039;&#039; || The recordings (automated and/or manual) of evidence of activities performed or results achieved (e.g., forms, reports, test results), which serve as a basis for verifying that the organization and the system are performing as intended. Also used to refer to units of related data fields (i.e., groups of data fields that can be accessed by a program and that contain the complete set of information on particular items).&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;remote access&#039;&#039;&#039; || Access to an organizational system by a user (or a process acting on behalf of a user) communicating through an external network (e.g., the Internet).&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;remote maintenance&#039;&#039;&#039; || Maintenance activities conducted by individuals communicating through an external network (e.g., the Internet).&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;replay resistance&#039;&#039;&#039; || Protection against the capture of transmitted authentication or access control information and its subsequent retransmission with the intent of producing an unauthorized effect or gaining unauthorized access.&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;risk&#039;&#039;&#039; &amp;lt;small&amp;gt;[FIPS 200, Adapted]&amp;lt;/small&amp;gt; || A measure of the extent to which an entity is threatened by a potential circumstance or event, and typically a function of: (i) the adverse impacts that would arise if the circumstance or event occurs; and (ii) the likelihood of occurrence. System-related security risks are those risks that arise from the loss of confidentiality, integrity, or availability of information or systems. Such risks reflect the potential adverse impacts to organizational operations, organizational assets, individuals, other organizations, and the Nation.&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;risk assessment&#039;&#039;&#039; || The process of identifying risks to organizational operations (including mission, functions, image, reputation), organizational assets, individuals, other organizations, and the Nation, resulting from the operation of a system. Part of risk management, incorporates threat and vulnerability analyses, and considers mitigations provided by security controls planned or in place. Synonymous with risk analysis.&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;sanitization&#039;&#039;&#039; || Actions taken to render data written on media unrecoverable by both ordinary and, for some forms of sanitization, extraordinary means. Process to remove information from media such that data recovery is not possible. It includes removing all classified labels, markings, and activity logs.&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;security&#039;&#039;&#039; || A condition that results from the establishment and maintenance of protective measures that enable an enterprise to perform its mission or critical functions despite risks posed by threats to its use of systems. Protective measures may involve a combination of deterrence, avoidance, prevention, detection, recovery, and correction that form part of the enterprise&#039;s risk management approach.&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;security assessment&#039;&#039;&#039; || See &#039;&#039;Security Control Assessment&#039;&#039;.&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;security control&#039;&#039;&#039; &amp;lt;small&amp;gt;[FIPS 199, Adapted]&amp;lt;/small&amp;gt; || A safeguard or countermeasure prescribed for a system or an organization designed to protect the confidentiality, integrity, and availability of its information and to meet a set of defined security requirements.&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;security control assessment&#039;&#039;&#039; &amp;lt;small&amp;gt;[CNSSI 4009, Adapted]&amp;lt;/small&amp;gt; || The testing or evaluation of security controls to determine the extent to which the controls are implemented correctly, operating as intended, and producing the desired outcome with respect to meeting the security requirements for a system or organization.&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;security functionality&#039;&#039;&#039; || The security-related features, functions, mechanisms, services, procedures, and architectures implemented within organizational systems or the environments in which those systems operate.&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;security functions&#039;&#039;&#039; || The hardware, software, or firmware of the system responsible for enforcing the system security policy and supporting the isolation of code and data on which the protection is based.&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;security relevance&#039;&#039;&#039; || Functions or mechanisms that are relied upon, directly or indirectly, to enforce a security policy that governs confidentiality, integrity, and availability protections.&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;situational awareness&#039;&#039;&#039; &amp;lt;small&amp;gt;[CNSSI 4009]&amp;lt;/small&amp;gt; || Within a volume of time and space, the perception of an enterprise&#039;s security posture and its threat environment; the comprehension/meaning of both taken together (risk); and the projection of their status into the near future.&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;split tunneling&#039;&#039;&#039; || The process of allowing a remote user or device to establish a non-remote connection with a system and simultaneously communicate via some other connection to a resource in an external network. This method of network access enables a user to access remote devices (e.g., a networked printer) at the same time as accessing uncontrolled networks.&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;supplemental guidance&#039;&#039;&#039; || Statements used to provide additional explanatory information for security controls or security control enhancements.&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;system&#039;&#039;&#039; || See &#039;&#039;Information System&#039;&#039;.&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;system component&#039;&#039;&#039; &amp;lt;small&amp;gt;[NIST SP 800-128, Adapted]&amp;lt;/small&amp;gt; || A discrete, identifiable information technology asset (hardware, software, firmware) that represents a building block of a system. System components include commercial information technology products.&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;system security plan&#039;&#039;&#039; || A document that describes how an organization meets the security requirements for a system or how an organization plans to meet the requirements. The system security plan describes the system boundary; the environment in which the system operates; the relationships with or connections to other systems; and how the security requirements are implemented.&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;system service&#039;&#039;&#039; || A capability provided by a system that facilitates information processing, storage, or transmission.&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;threat&#039;&#039;&#039; &amp;lt;small&amp;gt;[CNSSI 4009, Adapted]&amp;lt;/small&amp;gt; || Any circumstance or event with the potential to adversely impact organizational operations, organizational assets, individuals, other organizations, or the Nation through a system via unauthorized access, destruction, disclosure, modification of information, and/or denial of service.&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;user&#039;&#039;&#039; &amp;lt;small&amp;gt;[CNSSI 4009, Adapted]&amp;lt;/small&amp;gt; || Individual, or (system) process acting on behalf of an individual, authorized to access a system.&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;whitelisting&#039;&#039;&#039; || A process used to identify software programs that are authorized to execute on a system or authorized Universal Resource Locators (URL)/websites.&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;wireless technology&#039;&#039;&#039; || Technology that permits the transfer of information between separated points without physical connection.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Appendix C: Acronyms ==&lt;br /&gt;
&#039;&#039;Common abbreviations&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Acronym !! Meaning&lt;br /&gt;
|-&lt;br /&gt;
| CFR || Code of Federal Regulations&lt;br /&gt;
|-&lt;br /&gt;
| CIO || Chief Information Officer&lt;br /&gt;
|-&lt;br /&gt;
| CNSS || Committee on National Security Systems&lt;br /&gt;
|-&lt;br /&gt;
| CUI || Controlled Unclassified Information&lt;br /&gt;
|-&lt;br /&gt;
| FIPS || Federal Information Processing Standards&lt;br /&gt;
|-&lt;br /&gt;
| FISMA || Federal Information Security Modernization Act&lt;br /&gt;
|-&lt;br /&gt;
| ISO/IEC || International Organization for Standardization/International Electrotechnical Commission&lt;br /&gt;
|-&lt;br /&gt;
| ISOO || Information Security Oversight Office&lt;br /&gt;
|-&lt;br /&gt;
| ITL || Information Technology Laboratory&lt;br /&gt;
|-&lt;br /&gt;
| NARA || National Archives and Records Administration&lt;br /&gt;
|-&lt;br /&gt;
| NFO || Nonfederal Organization&lt;br /&gt;
|-&lt;br /&gt;
| NIST || National Institute of Standards and Technology&lt;br /&gt;
|-&lt;br /&gt;
| OMB || Office of Management and Budget&lt;br /&gt;
|-&lt;br /&gt;
| SP || Special Publication&lt;br /&gt;
|-&lt;br /&gt;
| SSP || System Security Plan&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Appendix D: Assessment Methods ==&lt;br /&gt;
&#039;&#039;Assessment method definitions, applicable objects, and attributes&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
This appendix defines three assessment methods that can be used to assess the CUI security requirements in NIST Special Publication 800-171: &#039;&#039;examine&#039;&#039;, &#039;&#039;interview&#039;&#039;, and &#039;&#039;test&#039;&#039;. Included in the definition of each assessment method are types of objects to which the method can be applied. The application of each method is described in terms of the attributes of &#039;&#039;depth&#039;&#039; and &#039;&#039;coverage&#039;&#039;, progressing from &#039;&#039;basic&#039;&#039; to &#039;&#039;focused&#039;&#039; to &#039;&#039;comprehensive&#039;&#039;. The attribute values correlate to the assurance requirements specified by the organization.&lt;br /&gt;
&lt;br /&gt;
The depth attribute addresses the rigor and level of detail of the assessment. For the depth attribute, the &#039;&#039;focused&#039;&#039; attribute value includes and builds upon the assessment rigor and level of detail defined for the &#039;&#039;basic&#039;&#039; attribute value; the &#039;&#039;comprehensive&#039;&#039; attribute value includes and builds upon the assessment rigor and level of detail defined for the &#039;&#039;focused&#039;&#039; attribute value.&lt;br /&gt;
&lt;br /&gt;
The coverage attribute addresses the scope or breadth of the assessment. For the coverage attribute, the &#039;&#039;focused&#039;&#039; attribute value includes and builds upon the number and type of assessment objects defined for the &#039;&#039;basic&#039;&#039; attribute value; the &#039;&#039;comprehensive&#039;&#039; attribute value includes and builds upon the number and type of assessment objects defined for the &#039;&#039;focused&#039;&#039; attribute value.&lt;br /&gt;
&lt;br /&gt;
Tables D-1 through D-3 provide complete descriptions of the examine, interview, and test assessment methods. The use of &#039;&#039;&#039;bolded text&#039;&#039;&#039; in the assessment method description indicates the content that was added to and appears for the first time, in the description indicating greater rigor and level of detail for the attribute value.&lt;br /&gt;
&lt;br /&gt;
=== Table D-1: Examine Assessment Method ===&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! colspan=&amp;quot;2&amp;quot; | Method: EXAMINE&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;2&amp;quot; | The process of checking, inspecting, reviewing, observing, studying, or analyzing one or more assessment objects to facilitate understanding, achieve clarification, or obtain evidence. The results are used to support the determination of security safeguard existence, functionality, correctness, completeness, and potential for improvement over time.&lt;br /&gt;
|-&lt;br /&gt;
! Objects !! Description&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;Specifications&#039;&#039; || Examples: policies, plans, procedures, system requirements, designs.&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;Mechanisms&#039;&#039; || Examples: functionality implemented in hardware, software, firmware.&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;Activities&#039;&#039; || Examples: system operations, administration, management, exercises.&lt;br /&gt;
|-&lt;br /&gt;
! Attribute: Depth !! Description&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;Basic&#039;&#039;&#039; || Examination that consists of high-level reviews, checks, observations, or inspections of the assessment object. This type of examination is conducted using a limited body of evidence or documentation. Examples include: functional-level descriptions for mechanisms; high-level process descriptions for activities; and documents for specifications. Basic examinations provide a level of understanding of the security safeguards necessary for determining whether the safeguards are implemented and free of obvious errors.&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;Focused&#039;&#039;&#039; || Examination that consists of high-level reviews, checks, observations, or inspections &#039;&#039;&#039;and more in-depth studies and analyses&#039;&#039;&#039; of the assessment object. This type of examination is conducted using a &#039;&#039;&#039;substantial&#039;&#039;&#039; body of evidence or documentation. Examples include: functional-level descriptions &#039;&#039;&#039;and where appropriate and available, high-level design information&#039;&#039;&#039; for mechanisms; high-level process descriptions &#039;&#039;&#039;and implementation procedures&#039;&#039;&#039; for activities; and documents &#039;&#039;&#039;and related documents&#039;&#039;&#039; for specifications. Focused examinations provide a level of understanding of the security safeguards necessary for determining whether the safeguards are implemented and free of obvious errors &#039;&#039;&#039;and whether there are increased grounds for confidence that the safeguards are implemented correctly and operating as intended&#039;&#039;&#039;.&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;Comprehensive&#039;&#039;&#039; || Examination that consists of high-level reviews, checks, observations, or inspections and more in-depth, &#039;&#039;&#039;detailed, and thorough&#039;&#039;&#039; studies and analyses of the assessment object. This type of examination is conducted using an &#039;&#039;&#039;extensive&#039;&#039;&#039; body of evidence or documentation. Examples include: functional-level descriptions and where appropriate and available, high-level design information, &#039;&#039;&#039;low-level design information, and implementation information&#039;&#039;&#039; for mechanisms; high-level process descriptions and &#039;&#039;&#039;detailed&#039;&#039;&#039; implementation procedures for activities; and documents and related documents for specifications.&amp;lt;ref&amp;gt;While additional documentation is likely for mechanisms when moving from basic to focused to comprehensive examinations, the documentation associated with specifications and activities may be the same or similar for focused and comprehensive examinations, with the rigor of the examinations of these documents being increased at the comprehensive level.&amp;lt;/ref&amp;gt; &#039;&#039;&#039;Comprehensive&#039;&#039;&#039; examinations provide a level of understanding of the security safeguards necessary for determining whether the safeguards are implemented and free of obvious errors and whether there are &#039;&#039;&#039;further&#039;&#039;&#039; increased grounds for confidence that the safeguards are implemented correctly and operating as intended &#039;&#039;&#039;on an ongoing and consistent basis, and that there is support for continuous improvement in the effectiveness of the safeguards&#039;&#039;&#039;.&lt;br /&gt;
|-&lt;br /&gt;
! Attribute: Coverage !! Description&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;2&amp;quot; | Addresses the scope or breadth of the examination process and includes the types of assessment objects to be examined; the number of objects to be examined by type; and specific objects to be examined.&amp;lt;ref&amp;gt;The organization, considering a variety of factors (e.g., available resources, importance of the assessment, the organization&#039;s overall assessment goals and objectives), confers with assessors and provides direction on the type, number, and specific objects to be examined for the attribute value described.&amp;lt;/ref&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;Basic&#039;&#039;&#039; || Examination that uses a representative sample of assessment objects (by type and number within type) to provide a level of coverage necessary for determining whether the security safeguards are implemented and free of obvious errors.&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;Focused&#039;&#039;&#039; || Examination that uses a representative sample of assessment objects (by type and number within type) &#039;&#039;&#039;and other specific assessment objects deemed particularly important to achieving the assessment objective&#039;&#039;&#039; to provide a level of coverage necessary for determining whether the security safeguards are implemented and free of obvious errors &#039;&#039;&#039;and whether there are increased grounds for confidence that the safeguards are implemented correctly and operating as intended&#039;&#039;&#039;.&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;Comprehensive&#039;&#039;&#039; || Examination that uses a &#039;&#039;&#039;sufficiently large&#039;&#039;&#039; sample of assessment objects (by type and number within type) and other specific assessment objects deemed particularly important to achieving the assessment objective to provide a level of coverage necessary for determining whether the security safeguards are implemented and free of obvious errors and whether there are &#039;&#039;&#039;further&#039;&#039;&#039; increased grounds for confidence that the safeguards are implemented correctly and operating as intended &#039;&#039;&#039;on an ongoing and consistent basis, and that there is support for continuous improvement in the effectiveness of the safeguards&#039;&#039;&#039;.&lt;br /&gt;
|-&lt;br /&gt;
! colspan=&amp;quot;2&amp;quot; | Discussion&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;2&amp;quot; | Typical assessor actions may include, for example: reviewing information security policies, plans, and procedures; analyzing system design documentation and interface specifications; observing system backup operations; reviewing training records; reviewing audit records; observing incident response activities; studying technical manuals and user/administrator guides; checking, studying, or observing the operation of an information technology mechanism in the system hardware or software; or checking, studying, or observing physical security measures related to the operation of a system.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== Table D-2: Interview Assessment Method ===&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! colspan=&amp;quot;2&amp;quot; | Method: INTERVIEW&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;2&amp;quot; | The process of conducting discussions with individuals or groups of individuals in an organization to facilitate understanding, achieve clarification, or lead to the location of evidence. The results are used to support the determination of security safeguard existence, functionality, correctness, completeness, and potential for improvement over time.&lt;br /&gt;
|-&lt;br /&gt;
! Objects !! Description&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;Individuals or Groups&#039;&#039; || Examples: Personnel with risk assessment responsibilities; personnel with information security responsibilities; system or network administrators; personnel with account management responsibilities.&lt;br /&gt;
|-&lt;br /&gt;
! Attribute: Depth !! Description&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;Basic&#039;&#039;&#039; || Interview that consists of broad-based, high-level discussions with individuals or groups of individuals. This type of interview is conducted using a set of generalized, high-level questions. Basic interviews provide a level of understanding of the security safeguards necessary for determining whether the safeguards are implemented and free of obvious errors.&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;Focused&#039;&#039;&#039; || Interview that consists of broad-based, high-level discussions &#039;&#039;&#039;and more in-depth discussions in specific areas&#039;&#039;&#039; with individuals or groups of individuals. This type of interview is conducted using a set of generalized, high-level questions &#039;&#039;&#039;and more in-depth questions in specific areas where responses indicate a need for more in-depth investigation&#039;&#039;&#039;. Focused interviews provide a level of understanding of the security safeguards necessary for determining whether the safeguards are implemented and free of obvious errors &#039;&#039;&#039;and whether there are increased grounds for confidence that the safeguards are implemented correctly and operating as intended&#039;&#039;&#039;.&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;Comprehensive&#039;&#039;&#039; || Interview that consists of broad-based, high-level discussions and more in-depth, &#039;&#039;&#039;probing&#039;&#039;&#039; discussions in specific areas with individuals or groups of individuals. This type of interview is conducted using a set of generalized, high-level questions and more in-depth, &#039;&#039;&#039;probing&#039;&#039;&#039; questions in specific areas where responses indicate a need for more in-depth investigation. &#039;&#039;&#039;Comprehensive&#039;&#039;&#039; interviews provide a level of understanding of the security safeguards necessary for determining whether the safeguards are implemented and free of obvious errors and whether there are &#039;&#039;&#039;further&#039;&#039;&#039; increased grounds for confidence that the safeguards are implemented correctly and operating as intended &#039;&#039;&#039;on an ongoing and consistent basis, and that there is support for continuous improvement in the effectiveness of the safeguards&#039;&#039;&#039;.&lt;br /&gt;
|-&lt;br /&gt;
! Attribute: Coverage !! Description&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;2&amp;quot; | Addresses the scope or breadth of the interview process and includes the types of individuals to be interviewed by role and responsibility; the number of individuals to be interviewed by type; and specific individuals to be interviewed.&amp;lt;ref&amp;gt;The organization, considering a variety of factors (e.g., available resources, importance of the assessment, the organization&#039;s overall assessment goals and objectives), confers with assessors and provides direction on the type, number, and specific individuals to be interviewed for the attribute value described.&amp;lt;/ref&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;Basic&#039;&#039;&#039; || Interview that uses a representative sample of individuals in organizational roles to provide a level of coverage necessary for determining whether the security safeguards are implemented and free of obvious errors.&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;Focused&#039;&#039;&#039; || Interview that uses a representative sample of individuals in organizational roles &#039;&#039;&#039;and other specific individuals deemed particularly important to achieving the assessment objective&#039;&#039;&#039; to provide a level of coverage necessary for determining whether the security safeguards are implemented and free of obvious errors &#039;&#039;&#039;and whether there are increased grounds for confidence that the safeguards are implemented correctly and operating as intended&#039;&#039;&#039;.&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;Comprehensive&#039;&#039;&#039; || Interview that uses a &#039;&#039;&#039;sufficiently large&#039;&#039;&#039; sample of individuals in organizational roles and other specific individuals deemed particularly important to achieving the assessment objective to provide a level of coverage necessary for determining whether the security safeguards are implemented and free of obvious errors and whether there are &#039;&#039;&#039;further&#039;&#039;&#039; increased grounds for confidence that the safeguards are implemented correctly and operating as intended &#039;&#039;&#039;on an ongoing and consistent basis, and that there is support for continuous improvement in the effectiveness of the safeguards&#039;&#039;&#039;.&lt;br /&gt;
|-&lt;br /&gt;
! colspan=&amp;quot;2&amp;quot; | Discussion&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;2&amp;quot; | Typical assessor actions may include, for example, interviewing chief executive officers, chief information officers, senior information security officers, information owners, system and mission owners, system security officers, system security managers, personnel officers, human resource managers, network and system administrators, facilities managers, training officers, physical security officers, system operators, site managers, and users.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== Table D-3: Test Assessment Method ===&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! colspan=&amp;quot;2&amp;quot; | Method: TEST&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;2&amp;quot; | The process of exercising one or more assessment objects under specified conditions to compare actual with expected behavior. The results are used to support the determination of security safeguard existence, functionality, correctness, completeness, and potential for improvement over time.&amp;lt;ref&amp;gt;Testing is typically used to determine if mechanisms or activities meet a set of predefined specifications. Testing can also be performed to determine characteristics of a security or privacy control that are not commonly associated with predefined specifications, with an example of such testing being penetration testing.&amp;lt;/ref&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
! Objects !! Description&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;Mechanisms&#039;&#039; || Examples: hardware, software, firmware.&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;Activities&#039;&#039; || Examples: system operations, administration, management; exercises.&lt;br /&gt;
|-&lt;br /&gt;
! Attribute: Depth !! Description&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;Basic&#039;&#039;&#039; || Test methodology (also known as &#039;&#039;black box&#039;&#039; testing) that assumes no knowledge of the internal structure and implementation detail of the assessment object. This type of testing is conducted using a functional specification for mechanisms and a high-level process description for activities. Basic testing provides a level of understanding of the security safeguards necessary for determining whether the safeguards are implemented and free of obvious errors.&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;Focused&#039;&#039;&#039; || Test methodology (also known as &#039;&#039;gray box&#039;&#039; testing) that assumes &#039;&#039;&#039;some&#039;&#039;&#039; knowledge of the internal structure and implementation detail of the assessment object. This type of testing is conducted using a functional specification &#039;&#039;&#039;and limited system architectural information (e.g., high-level design)&#039;&#039;&#039; for mechanisms and a high-level process description &#039;&#039;&#039;and high-level description of integration into the operational environment&#039;&#039;&#039; for activities. Focused testing provides a level of understanding of the security safeguards necessary for determining whether the safeguards are implemented and free of obvious errors &#039;&#039;&#039;and whether there are increased grounds for confidence that the safeguards are implemented correctly and operating as intended&#039;&#039;&#039;.&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;Comprehensive&#039;&#039;&#039; || Test methodology (also known as &#039;&#039;white box&#039;&#039; testing) that assumes &#039;&#039;&#039;explicit and substantial&#039;&#039;&#039; knowledge of the internal structure and implementation detail of the assessment object. This type of testing is conducted using a functional specification, &#039;&#039;&#039;extensive&#039;&#039;&#039; system architectural information (e.g., high-level design, &#039;&#039;&#039;low-level design&#039;&#039;&#039;) and &#039;&#039;&#039;implementation representation (e.g., source code, schematics)&#039;&#039;&#039; for mechanisms and a high-level process description and &#039;&#039;&#039;detailed&#039;&#039;&#039; description of integration into the operational environment for activities. Comprehensive testing provides a level of understanding of the security safeguards necessary for determining whether the safeguards are implemented and free of obvious errors and whether there are &#039;&#039;&#039;further&#039;&#039;&#039; increased grounds for confidence that the safeguards are implemented correctly and operating as intended &#039;&#039;&#039;on an ongoing and consistent basis, and that there is support for continuous improvement in the effectiveness of the safeguards&#039;&#039;&#039;.&lt;br /&gt;
|-&lt;br /&gt;
! Attribute: Coverage !! Description&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;2&amp;quot; | Addresses the scope or breadth of the testing process and includes the types of assessment objects to be tested; the number of objects to be tested by type; and specific objects to be tested.&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;Basic&#039;&#039;&#039; || Testing that uses a representative sample of assessment objects by type and number within type, to provide a level of coverage necessary for determining whether the security safeguards are implemented and free of obvious errors.&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;Focused&#039;&#039;&#039; || Testing that uses a representative sample of assessment objects by type and number within type, &#039;&#039;&#039;and other specific assessment objects deemed particularly important to achieving the assessment objective&#039;&#039;&#039; to provide a level of coverage necessary for determining whether the security safeguards are implemented and free of obvious errors &#039;&#039;&#039;and whether there are increased grounds for confidence that the safeguards are implemented correctly and operating as intended&#039;&#039;&#039;.&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;Comprehensive&#039;&#039;&#039; || Testing that uses a &#039;&#039;&#039;sufficiently large&#039;&#039;&#039; sample of assessment objects by type and number within type, and other specific assessment objects deemed particularly important to achieving the assessment objective to provide a level of coverage necessary for determining whether the security safeguards are implemented and free of obvious errors and whether there are &#039;&#039;&#039;further&#039;&#039;&#039; increased grounds for confidence that the safeguards are implemented correctly and operating as intended &#039;&#039;&#039;on an ongoing and consistent basis, and that there is support for continuous improvement in the effectiveness of the safeguards&#039;&#039;&#039;.&lt;br /&gt;
|-&lt;br /&gt;
! colspan=&amp;quot;2&amp;quot; | Discussion&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;2&amp;quot; | Typical assessor actions may include, for example: testing access control, identification and authentication, and audit mechanisms; testing security configuration settings; testing physical access control devices; conducting penetration testing of key system components; testing system backup operations; testing incident response capability; and exercising vulnerability scanning capability.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Notes ==&lt;br /&gt;
&amp;lt;references/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[[Category:NIST Special Publications]]&lt;br /&gt;
[[Category:Cybersecurity standards]]&lt;br /&gt;
[[Category:Controlled Unclassified Information]]&lt;/div&gt;</summary>
		<author><name>David</name></author>
	</entry>
	<entry>
		<id>https://cmmcwiki.org/index.php?title=NIST_SP_800-17_R2&amp;diff=1634</id>
		<title>NIST SP 800-17 R2</title>
		<link rel="alternate" type="text/html" href="https://cmmcwiki.org/index.php?title=NIST_SP_800-17_R2&amp;diff=1634"/>
		<updated>2026-07-27T02:57:21Z</updated>

		<summary type="html">&lt;p&gt;David: Created page with &amp;quot;{{DISPLAYTITLE:NIST Special Publication 800-171, Revision 2}} &amp;#039;&amp;#039;&amp;#039;NIST Special Publication 800-171, Revision 2&amp;#039;&amp;#039;&amp;#039; — &amp;#039;&amp;#039;Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations&amp;#039;&amp;#039; — is a National Institute of Standards and Technology (NIST) publication that provides federal agencies with recommended security requirements for protecting the confidentiality of Controlled Unclassified Information (CUI) when that information resides in n...&amp;quot;&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{DISPLAYTITLE:NIST Special Publication 800-171, Revision 2}}&lt;br /&gt;
&#039;&#039;&#039;NIST Special Publication 800-171, Revision 2&#039;&#039;&#039; — &#039;&#039;Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations&#039;&#039; — is a [[National Institute of Standards and Technology]] (NIST) publication that provides federal agencies with recommended security requirements for protecting the confidentiality of [[Controlled Unclassified Information]] (CUI) when that information resides in nonfederal systems and organizations.&lt;br /&gt;
&lt;br /&gt;
{{Infobox publication&lt;br /&gt;
| title           = Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations&lt;br /&gt;
| series          = NIST Special Publication 800-171&lt;br /&gt;
| revision        = Revision 2&lt;br /&gt;
| authors         = Ron Ross, Victoria Pillitteri, Kelley Dempsey, Mark Riddle, Gary Guissanie&lt;br /&gt;
| publisher       = National Institute of Standards and Technology, U.S. Department of Commerce&lt;br /&gt;
| publication_date = February 2020 (includes updates as of January 28, 2021)&lt;br /&gt;
| doi             = 10.6028/NIST.SP.800-171r2&lt;br /&gt;
| pages           = 113&lt;br /&gt;
| status          = Withdrawn May 14, 2024; superseded by NIST SP 800-171 Revision 3&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
== Withdrawal notice ==&lt;br /&gt;
{{Ambox&lt;br /&gt;
| type = notice&lt;br /&gt;
| text = This publication has been &#039;&#039;&#039;withdrawn (archived)&#039;&#039;&#039; and is provided solely for historical purposes.&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Withdrawn publication !! Detail&lt;br /&gt;
|-&lt;br /&gt;
| Series/Number || NIST SP 800-171r2&lt;br /&gt;
|-&lt;br /&gt;
| Title || Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations&lt;br /&gt;
|-&lt;br /&gt;
| Publication date(s) || February 2020 (includes updates as of January 28, 2021)&lt;br /&gt;
|-&lt;br /&gt;
| Withdrawal date || May 14, 2024&lt;br /&gt;
|-&lt;br /&gt;
| Withdrawal note || NIST SP 800-171r2 is withdrawn and superseded in its entirety by NIST SP 800-171r3&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Superseding publication !! Detail&lt;br /&gt;
|-&lt;br /&gt;
| Series/Number || NIST SP 800-171r3&lt;br /&gt;
|-&lt;br /&gt;
| Title || Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations&lt;br /&gt;
|-&lt;br /&gt;
| Author(s) || Ron Ross; Victoria Pillitteri&lt;br /&gt;
|-&lt;br /&gt;
| Publication date(s) || May 2024&lt;br /&gt;
|-&lt;br /&gt;
| URL/DOI || {{URL|https://doi.org/10.6028/NIST.SP.800-171r3}}&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
Contact: Computer Security Division (Information Technology Laboratory). Related information: {{URL|https://csrc.nist.gov/pubs/sp/800/171/r2/upd1/final}}. Date updated: May 14, 2024.&lt;br /&gt;
&lt;br /&gt;
== Front matter ==&lt;br /&gt;
&lt;br /&gt;
=== Authority ===&lt;br /&gt;
This publication was developed by NIST to further its statutory responsibilities under the [[Federal Information Security Modernization Act]] (FISMA), 44 U.S.C. § 3551 &#039;&#039;et seq.&#039;&#039;, Public Law (P.L.) 113-283. NIST is responsible for developing information security standards and guidelines, including minimum requirements for federal information systems. Such information security standards and guidelines do not apply to national security systems without the express approval of the appropriate federal officials exercising policy authority over such systems. This guideline is consistent with the requirements of [[Office of Management and Budget]] (OMB) Circular A-130.&lt;br /&gt;
&lt;br /&gt;
Nothing in the publication should be taken to contradict the standards and guidelines made mandatory and binding on federal agencies by the Secretary of Commerce under statutory authority, nor should the guidelines be interpreted as altering or superseding the existing authorities of the Secretary of Commerce, the OMB Director, or any other federal official. The publication may be used by nongovernmental organizations on a voluntary basis and is not subject to copyright in the United States, although attribution is appreciated by NIST.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;National Institute of Standards and Technology Special Publication 800-171, Revision 2&#039;&#039;&#039;&amp;lt;br&amp;gt;&lt;br /&gt;
Natl. Inst. Stand. Technol. Spec. Publ. 800-171, Revision 2, 113 pages (February 2020)&amp;lt;br&amp;gt;&lt;br /&gt;
CODEN: NSPUE2&amp;lt;br&amp;gt;&lt;br /&gt;
{{URL|https://doi.org/10.6028/NIST.SP.800-171r2}}&lt;br /&gt;
&lt;br /&gt;
=== Reports on Computer Systems Technology ===&lt;br /&gt;
The National Institute of Standards and Technology (NIST) Information Technology Laboratory (ITL) promotes the U.S. economy and public welfare by providing technical leadership for the nation&#039;s measurement and standards infrastructure. ITL develops tests, test methods, reference data, proof-of-concept implementations, and technical analyses to advance the development and productive use of information technology. ITL&#039;s responsibilities include developing management, administrative, technical, and physical standards and guidelines for the cost-effective security of other than national-security-related information in federal information systems. The Special Publication 800-series reports on ITL&#039;s research, guidelines, and outreach efforts in information systems security and privacy and its collaborative activities with industry, government, and academic organizations.&lt;br /&gt;
&lt;br /&gt;
=== Abstract ===&lt;br /&gt;
The protection of Controlled Unclassified Information (CUI) resident in nonfederal systems and organizations is of paramount importance to federal agencies and can directly impact the ability of the federal government to successfully conduct its essential missions and functions. This publication provides agencies with recommended security requirements for protecting the confidentiality of CUI when the information is resident in nonfederal systems and organizations; when the nonfederal organization is not collecting or maintaining information on behalf of a federal agency or using or operating a system on behalf of an agency; and where there are no specific safeguarding requirements for protecting the confidentiality of CUI prescribed by the authorizing law, regulation, or governmentwide policy for the CUI category listed in the CUI Registry. The requirements apply to all components of nonfederal systems and organizations that process, store, and/or transmit CUI, or that provide protection for such components. The security requirements are intended for use by federal agencies in contractual vehicles or other agreements established between those agencies and nonfederal organizations.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Keywords:&#039;&#039;&#039; Basic Security Requirement; Contractor Systems; Controlled Unclassified Information; CUI Registry; Derived Security Requirement; Executive Order 13556; FIPS Publication 199; FIPS Publication 200; FISMA; NIST Special Publication 800-53; Nonfederal Organizations; Nonfederal Systems; Security Assessment; Security Control; Security Requirement.&lt;br /&gt;
&lt;br /&gt;
=== Acknowledgements ===&lt;br /&gt;
The authors wish to recognize the scientists, engineers, and research staff from the Computer Security Division and Applied Cybersecurity Division for their exceptional contributions in helping to improve the content of the publication, and thank Pat O&#039;Reilly, Jim Foti, and Jeff Brewer of the NIST web team for their administrative support. The authors also acknowledge the contributions from individuals and organizations in the public and private sectors, nationally and internationally, whose comments improved the overall quality, thoroughness, and usefulness of the publication.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Historical contributions&#039;&#039;&#039; to previous versions of Special Publication 800-171, since its inception in June 2015, were made by Carol Bales, Matthew Barrett, Jon Boyens, Devin Casey, Christian Enloe, Peggy Himes, Robert Glenn, Elizabeth Lennon, Vicki Michetti, Dorian Pappas, Karen Quigg, Mary Thomas, Matthew Scholl, Murugiah Souppaya, Patricia Toth, and Patrick Viscuso.&lt;br /&gt;
&lt;br /&gt;
=== Patent disclosure notice ===&lt;br /&gt;
The Information Technology Laboratory (ITL) requested that holders of patent claims whose use may be required for compliance with the guidance or requirements of this publication disclose such patent claims to ITL. Holders of patents are not obligated to respond to ITL&#039;s calls for patents, and ITL has not undertaken a patent search to identify which, if any, patents may apply to the publication. As of the date of publication and following the call(s) for identification of patent claims, no such patent claims had been identified to ITL. No representation is made or implied by ITL that licenses are not required to avoid patent infringement in the use of the publication.&lt;br /&gt;
&lt;br /&gt;
=== Cautionary note ===&lt;br /&gt;
FISMA of 2014 requires federal agencies to identify and provide information security protections commensurate with the risk resulting from the unauthorized access, use, disclosure, disruption, modification, or destruction of information collected or maintained by or on behalf of an agency, or of information systems used or operated by an agency, a contractor of an agency, or another organization on behalf of an agency. This publication focuses on protecting the confidentiality of CUI in nonfederal systems and organizations and recommends specific security requirements to achieve that objective. It does not change the requirements set forth in FISMA, nor does it alter the responsibility of federal agencies to comply with the full provisions of the statute, OMB policy, and supporting NIST standards and guidelines.&lt;br /&gt;
&lt;br /&gt;
The requirements recommended in the publication are derived from [[FIPS 200]] and the moderate security control baseline in [[NIST Special Publication 800-53|SP 800-53]], and are based on the CUI regulation (32 CFR 2002). These requirements and controls have, over time, been determined to provide the necessary protection for federal information and systems covered under FISMA. The tailoring criteria applied to the FIPS 200 requirements and SP 800-53 controls are not an endorsement of eliminating those requirements and controls; rather, the tailoring focuses on protecting CUI from unauthorized disclosure in nonfederal systems and organizations. Because the security requirements are derived from the NIST publications listed above, organizations should not assume that satisfying these particular requirements will automatically satisfy the requirements and controls in FIPS 200 and SP 800-53.&lt;br /&gt;
&lt;br /&gt;
In addition to confidentiality, the objectives of integrity and availability remain a high priority for organizations concerned with establishing and maintaining a comprehensive information security program. While the primary purpose of this publication is to define requirements to protect the confidentiality of CUI, confidentiality and integrity are closely related since many underlying security mechanisms at the system level support both objectives; the basic and derived security requirements therefore provide protection from both unauthorized disclosure and unauthorized modification of CUI. Organizations that must comply with the recommendations in this publication are strongly advised to review the complete listing of controls in the moderate baseline in Appendix E to ensure their security plans and control deployments provide the necessary and sufficient protection against cyber and kinetic threats to organizational missions and business operations.&lt;br /&gt;
&lt;br /&gt;
=== CUI security requirements ===&lt;br /&gt;
The recommended security requirements contained in this publication are only applicable to a nonfederal system or organization when mandated by a federal agency in a contract, grant, or other agreement. The security requirements apply to the components of nonfederal systems that process, store, or transmit CUI, or that provide security protection for such components.&lt;br /&gt;
&lt;br /&gt;
=== Framework for Improving Critical Infrastructure Cybersecurity ===&lt;br /&gt;
Organizations that have implemented, or plan to implement, the NIST [[Framework for Improving Critical Infrastructure Cybersecurity]] (Cybersecurity Framework) can find in Appendix D a direct mapping of the CUI security requirements to the security controls in SP 800-53 and [[ISO/IEC 27001]]. These controls are also mapped to the categories and subcategories associated with the Cybersecurity Framework&#039;s core functions: Identify, Protect, Detect, Respond, and Recover. The mappings can be useful to organizations that wish to demonstrate compliance with the security requirements in the context of an established information security program built around the NIST or ISO/IEC security controls.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Additional resources:&#039;&#039;&#039;&lt;br /&gt;
* Mapping security controls to the Cybersecurity Framework: {{URL|https://csrc.nist.gov/publications/detail/nistir/8170/draft}}&lt;br /&gt;
* Mapping CUI security requirements to the Cybersecurity Framework: {{URL|https://csrc.nist.gov/projects/cybersecurity-framework/informative-reference-catalog/details/1}}&lt;br /&gt;
&lt;br /&gt;
=== Errata ===&lt;br /&gt;
This table contains changes that have been incorporated into the publication since its original February 2020 release. Errata updates can include corrections, clarifications, or other minor changes that are either editorial or substantive in nature. All entries below are dated January 28, 2021.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Location !! Type !! Change&lt;br /&gt;
|-&lt;br /&gt;
| Front matter (Cautionary note) || Editorial || Changed &amp;quot;The requirements apply only&amp;quot; to &amp;quot;The security requirements apply&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| Chapter One, §1.1, paragraph 1 || Editorial || Deleted the sentence &amp;quot;The requirements apply only to components of nonfederal systems that process, store, or transmit CUI, or that provide security protection for such components.&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| Chapter One, §1.1, paragraph 2 || Editorial || Added a passage on the scope of applicability and on isolating designated system components into a separate CUI security domain&lt;br /&gt;
|-&lt;br /&gt;
| Chapter One, §1.1, paragraph 3 || Editorial || Changed &amp;quot;The requirements are&amp;quot; to &amp;quot;The recommended security requirements in this publication are&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| Chapter One, §1.1, paragraph 6 || Editorial || Deleted a passage on isolating CUI into its own security domain (superseded by the paragraph 2 addition above)&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Table of contents ==&lt;br /&gt;
* [[#Chapter One: Introduction|Chapter One: Introduction]]&lt;br /&gt;
** 1.1 Purpose and Applicability&lt;br /&gt;
** 1.2 Target Audience&lt;br /&gt;
** 1.3 Organization of this Special Publication&lt;br /&gt;
* [[#Chapter Two: The Fundamentals|Chapter Two: The Fundamentals]]&lt;br /&gt;
** 2.1 Basic Assumptions&lt;br /&gt;
** 2.2 Development of Security Requirements&lt;br /&gt;
* [[#Chapter Three: The Requirements|Chapter Three: The Requirements]]&lt;br /&gt;
** 3.1 Access Control&lt;br /&gt;
** 3.2 Awareness and Training&lt;br /&gt;
** 3.3 Audit and Accountability&lt;br /&gt;
** 3.4 Configuration Management&lt;br /&gt;
** 3.5 Identification and Authentication&lt;br /&gt;
** 3.6 Incident Response&lt;br /&gt;
** 3.7 Maintenance&lt;br /&gt;
** 3.8 Media Protection&lt;br /&gt;
** 3.9 Personnel Security&lt;br /&gt;
** 3.10 Physical Protection&lt;br /&gt;
** 3.11 Risk Assessment&lt;br /&gt;
** 3.12 Security Assessment&lt;br /&gt;
** 3.13 System and Communications Protection&lt;br /&gt;
** 3.14 System and Information Integrity&lt;br /&gt;
* [[#Appendix A: References|Appendix A: References]]&lt;br /&gt;
* [[#Appendix B: Glossary|Appendix B: Glossary]]&lt;br /&gt;
* [[#Appendix C: Acronyms|Appendix C: Acronyms]]&lt;br /&gt;
* [[#Appendix D: Mapping Tables|Appendix D: Mapping Tables]]&lt;br /&gt;
* [[#Appendix E: Tailoring Criteria|Appendix E: Tailoring Criteria]]&lt;br /&gt;
&lt;br /&gt;
== Chapter One: Introduction ==&lt;br /&gt;
&#039;&#039;The need to protect Controlled Unclassified Information&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
Today, more than at any time in history, the federal government relies on external service providers to help carry out a wide range of federal missions and business functions using information systems.&amp;lt;ref&amp;gt;An information system is a discrete set of information resources organized expressly for the collection, processing, maintenance, use, sharing, dissemination, or disposition of information. Information systems also include specialized systems, for example: industrial/process control systems, cyber-physical systems, embedded systems, and devices. The term &#039;&#039;system&#039;&#039; is used throughout this publication to represent all types of computing platforms that can process, store, or transmit CUI.&amp;lt;/ref&amp;gt; Many federal contractors process, store, and transmit sensitive federal information to support the delivery of essential products and services to federal agencies (e.g., providing financial services; providing web and electronic mail services; processing security clearances or healthcare data; providing cloud services; and developing communications, satellite, and weapons systems). Federal information is frequently provided to or shared with entities such as state and local governments, colleges and universities, and independent research organizations. The protection of sensitive federal information while residing in nonfederal systems&amp;lt;ref&amp;gt;A federal information system is a system that is used or operated by an executive agency, by a contractor of an executive agency, or by another organization on behalf of an executive agency. A system that does not meet such criteria is a nonfederal system.&amp;lt;/ref&amp;gt; and organizations is of paramount importance to federal agencies, and can directly impact the ability of the federal government to carry out its designated missions and business operations.&lt;br /&gt;
&lt;br /&gt;
The protection of unclassified federal information in nonfederal systems and organizations is dependent on the federal government providing a process for identifying the different types of information that are used by federal agencies. Executive Order 13556 established a governmentwide Controlled Unclassified Information (CUI)&amp;lt;ref&amp;gt;Controlled Unclassified Information is any information that law, regulation, or governmentwide policy requires to have safeguarding or disseminating controls, excluding information that is classified under Executive Order 13526 or any predecessor or successor order, or the Atomic Energy Act of 1954, as amended.&amp;lt;/ref&amp;gt; Program to standardize the way the executive branch handles unclassified information that requires protection.&amp;lt;ref&amp;gt;Executive Order 13556 designated the National Archives and Records Administration (NARA) as the Executive Agent to implement the CUI Program.&amp;lt;/ref&amp;gt; Only information that requires safeguarding or dissemination controls pursuant to federal law, regulation, or governmentwide policy may be designated as CUI. The CUI Program is designed to address several deficiencies in managing and protecting unclassified information, including inconsistent markings, inadequate safeguarding, and needless restrictions, both by standardizing procedures and by providing common definitions through a CUI Registry maintained by NARA. The CUI Registry is the online repository for information, guidance, policy, and requirements on handling CUI, including issuances by the CUI Executive Agent. It identifies approved CUI categories, provides general descriptions for each, identifies the basis for controls, and sets out procedures for the use of CUI, including marking, safeguarding, transporting, disseminating, reusing, and disposing of the information.&lt;br /&gt;
&lt;br /&gt;
Executive Order 13556 also required that the CUI Program emphasize openness, transparency, and uniformity of governmentwide practices, and that implementation take place consistent with applicable OMB policies and federal standards and guidelines issued by NIST. The federal CUI regulation,&amp;lt;ref&amp;gt;32 CFR 2002 was issued on September 14, 2016, and became effective on November 14, 2016.&amp;lt;/ref&amp;gt; developed by the CUI Executive Agent, provides guidance to federal agencies on the designation, safeguarding, dissemination, marking, decontrolling, and disposition of CUI, establishes self-inspection and oversight requirements, and delineates other facets of the program.&lt;br /&gt;
&lt;br /&gt;
=== 1.1 Purpose and Applicability ===&lt;br /&gt;
The purpose of this publication is to provide federal agencies with recommended security requirements&amp;lt;ref&amp;gt;The term &#039;&#039;requirements&#039;&#039; can be used in different contexts. In federal information security and privacy policy, it generally refers to information security and privacy obligations imposed on organizations — for example, OMB Circular A-130 imposes a series of such requirements with which federal agencies must comply. The term is also used in this guideline in a broader sense to refer to an expression of the set of stakeholder protection needs for a particular system or organization, which may be derived from many sources (e.g., laws, executive orders, directives, regulations, policies, standards, mission and business needs, or risk assessments). As used in this guideline, the term includes both legal and policy requirements as well as the broader set of stakeholder protection needs.&amp;lt;/ref&amp;gt; for protecting the confidentiality of CUI: (1) when the CUI is resident in a nonfederal system and organization; (2) when the nonfederal organization is not collecting or maintaining information on behalf of a federal agency or using or operating a system on behalf of an agency;&amp;lt;ref&amp;gt;Nonfederal organizations that collect or maintain information on behalf of a federal agency, or that use or operate a system on behalf of an agency, must comply with the requirements in FISMA, including the requirements in FIPS 200 and the security controls in SP 800-53 (see 44 U.S.C. § 3554(a)(1)(A)).&amp;lt;/ref&amp;gt; and (3) where there are no specific safeguarding requirements for protecting the confidentiality of CUI prescribed by the authorizing law, regulation, or governmentwide policy for the CUI category listed in the CUI Registry.&amp;lt;ref&amp;gt;The requirements in this publication can be used to comply with the FISMA requirement for senior agency officials to provide information security for the information that supports the operations and assets under their control, including CUI resident in nonfederal systems and organizations (see 44 U.S.C. § 3554(a)(1)(A) and (a)(2)).&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The requirements apply to components of nonfederal systems that process, store, or transmit CUI, or that provide security protection for such components.&amp;lt;ref&amp;gt;System components include, for example: mainframes, workstations, servers; input and output devices; network components; operating systems; virtual machines; and applications.&amp;lt;/ref&amp;gt; If nonfederal organizations designate specific system components for the processing, storage, or transmission of CUI, those organizations may limit the scope of the security requirements by isolating the designated system components in a separate CUI security domain. Isolation can be achieved by applying architectural and design concepts (e.g., implementing subnetworks with firewalls or other boundary protection devices and using information flow control mechanisms). Security domains may employ physical separation, logical separation, or a combination of both. This approach can provide adequate security for the CUI and avoid increasing the organization&#039;s security posture to a level beyond that which it requires for protecting its missions, operations, and assets.&lt;br /&gt;
&lt;br /&gt;
The recommended security requirements in this publication are intended for use by federal agencies in appropriate contractual vehicles or other agreements established between those agencies and nonfederal organizations. In CUI guidance and the CUI Federal Acquisition Regulation (FAR),&amp;lt;ref&amp;gt;NARA, as the CUI Executive Agent, plans to sponsor a single FAR clause that will apply the requirements of the federal CUI regulation and NIST Special Publication 800-171 to contractors. Until the FAR clause is in place, the requirements in NIST Special Publication 800-171 may be referenced in federal contracts consistent with federal law and regulatory requirements.&amp;lt;/ref&amp;gt; the CUI Executive Agent will address determining compliance with security requirements.&amp;lt;ref&amp;gt;NIST Special Publication 800-171A provides assessment procedures to determine compliance with the CUI security requirements.&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
In accordance with the federal CUI regulation, federal agencies using federal systems to process, store, or transmit CUI must, at a minimum, comply with:&lt;br /&gt;
* Federal Information Processing Standards (FIPS) Publication 199, &#039;&#039;Standards for Security Categorization of Federal Information and Information Systems&#039;&#039; (moderate confidentiality);&amp;lt;ref&amp;gt;FIPS 199 defines three values of potential impact (i.e., low, moderate, high) on organizations, assets, or individuals in the event of a breach of security (e.g., a loss of confidentiality).&amp;lt;/ref&amp;gt;&lt;br /&gt;
* Federal Information Processing Standards (FIPS) Publication 200, &#039;&#039;Minimum Security Requirements for Federal Information and Information Systems&#039;&#039;;&lt;br /&gt;
* NIST Special Publication 800-53, &#039;&#039;Security and Privacy Controls for Federal Information Systems and Organizations&#039;&#039;; and&lt;br /&gt;
* NIST Special Publication 800-60, &#039;&#039;Guide for Mapping Types of Information and Information Systems to Security Categories&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
The responsibility of federal agencies to protect CUI does not change when such information is shared with nonfederal partners. Therefore, a similar level of protection is needed when CUI is processed, stored, or transmitted by nonfederal organizations using nonfederal systems.&amp;lt;ref&amp;gt;A nonfederal organization is any entity that owns, operates, or maintains a nonfederal system. Examples include: state, local, and tribal governments; colleges and universities; and contractors.&amp;lt;/ref&amp;gt; The recommended requirements for safeguarding CUI in nonfederal systems and organizations are derived from the above authoritative federal standards and guidelines to maintain a consistent level of protection. However, recognizing that the scope of the safeguarding requirements in the federal CUI regulation is limited to the security objective of confidentiality (i.e., not directly addressing integrity and availability), and that some of the security requirements expressed in the NIST standards and guidelines are uniquely federal, the requirements in this publication have been tailored for nonfederal entities.&lt;br /&gt;
&lt;br /&gt;
The tailoring criteria described in Chapter Two are not intended to reduce or minimize the federal requirements for safeguarding CUI as expressed in the federal CUI regulation. Rather, the intent is to express the requirements in a manner that allows for and facilitates equivalent safeguarding measures within nonfederal systems and organizations and does not diminish the level of protection of CUI required for moderate confidentiality. Additional or differing requirements, other than those described in this publication, may be applied only when based on law, regulation, or governmentwide policy and when indicated in the CUI Registry as CUI-specified, or when an agreement establishes requirements to protect CUI Basic&amp;lt;ref&amp;gt;CUI Basic is defined in the CUI Registry.&amp;lt;/ref&amp;gt; at higher than moderate confidentiality. The provision of safeguarding requirements for CUI in a specified category will be addressed by NARA in its CUI guidance and in the CUI FAR, and reflected as specific requirements in contracts or other agreements. Nonfederal organizations may use the same CUI infrastructure for multiple government contracts or agreements, if that infrastructure meets the safeguarding requirements for the organization&#039;s CUI-related contracts and/or agreements, including any specific safeguarding required or permitted by the authorizing law, regulation, or governmentwide policy.&lt;br /&gt;
&lt;br /&gt;
=== 1.2 Target Audience ===&lt;br /&gt;
This publication serves a diverse group of individuals and organizations in both the public and private sectors, including, but not limited to, individuals with:&lt;br /&gt;
* System development life cycle responsibilities (e.g., program managers, mission/business owners, information owners/stewards, system designers and developers, system/security engineers, systems integrators);&lt;br /&gt;
* Acquisition or procurement responsibilities (e.g., contracting officers);&lt;br /&gt;
* System, security, or risk management and oversight responsibilities (e.g., authorizing officials, chief information officers, chief information security officers, system owners, information security managers); and&lt;br /&gt;
* Security assessment and monitoring responsibilities (e.g., auditors, system evaluators, assessors, independent verifiers/validators, analysts).&lt;br /&gt;
&lt;br /&gt;
These roles and responsibilities can be viewed from two distinct perspectives: the federal perspective, as the entity establishing and conveying the security requirements in contractual vehicles or other inter-organizational agreements; and the nonfederal perspective, as the entity responding to and complying with the security requirements set forth in contracts or agreements.&lt;br /&gt;
&lt;br /&gt;
=== 1.3 Organization of this Special Publication ===&lt;br /&gt;
The remainder of this special publication is organized as follows:&lt;br /&gt;
* Chapter Two describes the fundamental assumptions and methodology used to develop the security requirements for protecting the confidentiality of CUI; the format and structure of the requirements; and the tailoring criteria applied to the NIST standards and guidelines to obtain the requirements.&lt;br /&gt;
* Chapter Three describes the fourteen families of security requirements for protecting the confidentiality of CUI in nonfederal systems and organizations.&lt;br /&gt;
* Supporting appendices provide additional information related to the protection of CUI in nonfederal systems and organizations, including general references; definitions and terms; acronyms; mapping tables relating security requirements to the security controls in SP 800-53 and ISO/IEC 27001; and tailoring actions applied to the moderate security control baseline.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;references/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Chapter Two: The Fundamentals ==&lt;br /&gt;
&#039;&#039;Assumptions and methodology for developing security requirements&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
This chapter describes the assumptions and the methodology used to develop the recommended security requirements to protect CUI in nonfederal systems and organizations; the structure of the basic and derived security requirements; and the tailoring criteria applied to the federal information security requirements and controls.&lt;br /&gt;
&lt;br /&gt;
=== 2.1 Basic Assumptions ===&lt;br /&gt;
The recommended security requirements described in this publication have been developed based on three fundamental assumptions:&lt;br /&gt;
* Statutory and regulatory requirements for the protection of CUI are consistent, whether such information resides in federal systems or nonfederal systems, including the environments in which those systems operate;&lt;br /&gt;
* Safeguards implemented to protect CUI are consistent in both federal and nonfederal systems and organizations; and&lt;br /&gt;
* The confidentiality impact value for CUI is no less than FIPS 199 moderate.&amp;lt;ref&amp;gt;The moderate impact value defined in FIPS 199 may become part of a moderate-impact system in FIPS 200, which requires the use of the moderate baseline in SP 800-53 as the starting point for tailoring actions.&amp;lt;/ref&amp;gt;&amp;lt;ref&amp;gt;In accordance with 32 CFR 2002, CUI is categorized at no less than the moderate confidentiality impact value. However, when federal law, regulation, or governmentwide policy establishing control of the CUI specifies controls that differ from those of the moderate confidentiality baseline, those will be followed.&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
These assumptions reinforce the concept that federal information designated as CUI has the same intrinsic value and potential adverse impact if compromised — whether the information resides in a federal or a nonfederal organization. Thus, protecting the confidentiality of CUI is critical to the mission and business success of federal agencies and to the economic and national security interests of the nation. Additional assumptions affecting the development of the security requirements, and the expectation of federal agencies working with nonfederal entities, include:&lt;br /&gt;
* Nonfederal organizations have information technology infrastructures in place, and are not necessarily developing or acquiring systems specifically for processing, storing, or transmitting CUI;&lt;br /&gt;
* Nonfederal organizations have specific safeguarding measures in place to protect their information, which may also be sufficient to satisfy the security requirements;&lt;br /&gt;
* Nonfederal organizations may not have the necessary organizational structure or resources to satisfy every security requirement and may implement alternative, but equally effective, security measures to compensate for the inability to satisfy a requirement; and&lt;br /&gt;
* Nonfederal organizations can implement a variety of potential security solutions directly, or using external service providers (e.g., managed services), to satisfy security requirements.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Implementing a single, state security solution for CUI:&#039;&#039;&#039; Controlled Unclassified Information has the same value whether it is resident in a federal system that is part of a federal agency or a nonfederal system that is part of a nonfederal organization. Accordingly, the recommended security requirements in this publication are consistent with, and complementary to, the standards and guidelines used by federal agencies to protect CUI.&lt;br /&gt;
&lt;br /&gt;
=== 2.2 Development of Security Requirements ===&lt;br /&gt;
The security requirements for protecting the confidentiality of CUI in nonfederal systems and organizations have a well-defined structure consisting of a basic security requirements section and a derived security requirements section. The basic security requirements are obtained from FIPS 200, which provides the high-level and fundamental security requirements for federal information and systems. The derived security requirements, which supplement the basic security requirements, are taken from the security controls in SP 800-53. Starting with the security requirements and controls in the moderate baseline (i.e., the minimum level of protection required for CUI in federal systems and organizations), the requirements and controls are tailored to eliminate requirements, controls, or parts of controls that are:&lt;br /&gt;
* Uniquely federal (i.e., primarily the responsibility of the federal government);&lt;br /&gt;
* Not directly related to protecting the confidentiality of CUI; or&lt;br /&gt;
* Expected to be routinely satisfied by nonfederal organizations without specification.&amp;lt;ref&amp;gt;The security requirements developed from the tailored FIPS 200 security requirements and the SP 800-53 moderate security control baseline represent a subset of the safeguarding measures necessary for a comprehensive information security program. The strength and quality of such programs in nonfederal organizations depend on the degree to which the organizations implement the security requirements and controls expected to be routinely satisfied without specification by the federal government, including security policies, procedures, and practices that support an effective risk-based information security program. Nonfederal organizations are encouraged to refer to Appendix E and SP 800-53 for a complete listing of security controls in the moderate baseline deemed out of scope for the security requirements in Chapter Three.&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Appendix E provides a complete listing of security controls that support the CUI derived security requirements, and those controls that have been eliminated from the moderate baseline based on the CUI tailoring criteria described above.&lt;br /&gt;
&lt;br /&gt;
The combination of the basic and derived security requirements captures the intent of FIPS 200 and SP 800-53 with respect to protecting the confidentiality of CUI in nonfederal systems and organizations. Appendix D provides informal mappings of the security requirements to the relevant security controls in SP 800-53 and ISO/IEC 27001. The mappings promote a better understanding of the CUI security requirements and are not intended to impose additional requirements on nonfederal organizations.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Example — structure of a CUI requirement (Media Protection family):&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Basic Security Requirements&#039;&#039;&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! # !! Requirement&lt;br /&gt;
|-&lt;br /&gt;
| 3.8.1 || Protect (i.e., physically control and securely store) system media containing CUI, both paper and digital.&lt;br /&gt;
|-&lt;br /&gt;
| 3.8.2 || Limit access to CUI on system media to authorized users.&lt;br /&gt;
|-&lt;br /&gt;
| 3.8.3 || Sanitize or destroy system media containing CUI before disposal or release for reuse.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Derived Security Requirements&#039;&#039;&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! # !! Requirement&lt;br /&gt;
|-&lt;br /&gt;
| 3.8.4 || Mark media with necessary CUI markings and distribution limitations.&lt;br /&gt;
|-&lt;br /&gt;
| 3.8.5 || Control access to media containing CUI and maintain accountability for media during transport outside of controlled areas.&lt;br /&gt;
|-&lt;br /&gt;
| 3.8.6 || Implement cryptographic mechanisms to protect the confidentiality of CUI stored on digital media during transport unless otherwise protected by alternative physical safeguards.&lt;br /&gt;
|-&lt;br /&gt;
| 3.8.7 || Control the use of removable media on system components.&lt;br /&gt;
|-&lt;br /&gt;
| 3.8.8 || Prohibit the use of portable storage devices when such devices have no identifiable owner.&lt;br /&gt;
|-&lt;br /&gt;
| 3.8.9 || Protect the confidentiality of backup CUI at storage locations.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
For ease of use, the security requirements are organized into fourteen families. Each family contains the requirements related to the general security topic of the family. The families are closely aligned with the minimum security requirements for federal information and systems described in FIPS 200. The contingency planning, system and services acquisition, and planning requirements are not included within the scope of this publication due to the tailoring criteria.&amp;lt;ref&amp;gt;Three exceptions include: a requirement to protect the confidentiality of system backups (derived from CP-9) from the contingency planning family; a requirement to develop and implement a system security plan (derived from PL-2) from the planning family; and a requirement to implement system security engineering principles (derived from SA-8) from the system and services acquisition family. These requirements are included in the CUI media protection, security assessment, and system and communications protection requirements families, respectively.&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Table 1: Security requirement families&#039;&#039;&#039;&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Family !! Family&lt;br /&gt;
|-&lt;br /&gt;
| Access Control || Media Protection&lt;br /&gt;
|-&lt;br /&gt;
| Awareness and Training || Personnel Security&lt;br /&gt;
|-&lt;br /&gt;
| Audit and Accountability || Physical Protection&lt;br /&gt;
|-&lt;br /&gt;
| Configuration Management || Risk Assessment&lt;br /&gt;
|-&lt;br /&gt;
| Identification and Authentication || Security Assessment&lt;br /&gt;
|-&lt;br /&gt;
| Incident Response || System and Communications Protection&lt;br /&gt;
|-&lt;br /&gt;
| Maintenance || System and Information Integrity&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
A discussion section follows each CUI security requirement, providing additional information to facilitate implementation and assessment of the requirement. This information is derived primarily from the security control discussion sections in SP 800-53 and is provided to give organizations a better understanding of the mechanisms and procedures used to implement the controls that protect CUI. The discussion section is informative, not normative: it is not intended to extend the scope of a requirement or to influence the solutions organizations may use to satisfy it. The use of examples is notional, not exhaustive, and not reflective of the potential options available to organizations. The example below illustrates basic security requirement 3.8.3 with its supporting discussion section.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! 3.8.3&lt;br /&gt;
| Sanitize or destroy system media containing CUI before disposal or release for reuse.&lt;br /&gt;
|-&lt;br /&gt;
! DISCUSSION&lt;br /&gt;
| This requirement applies to all system media, digital and non-digital, subject to disposal or reuse. Examples include: digital media found in workstations, network components, scanners, copiers, printers, notebook computers, and mobile devices; and non-digital media such as paper and microfilm. The sanitization process removes information from the media such that the information cannot be retrieved or reconstructed. Sanitization techniques, including clearing, purging, cryptographic erase, and destruction, prevent the disclosure of information to unauthorized individuals when such media is released for reuse or disposal.&lt;br /&gt;
&lt;br /&gt;
Organizations determine the appropriate sanitization methods, recognizing that destruction may be necessary when other methods cannot be applied to the media requiring sanitization. Organizations use discretion in employing sanitization techniques and procedures for media containing information that is in the public domain, is publicly releasable, or is deemed to have no adverse impact on organizations or individuals if released for reuse or disposal. Sanitization of non-digital media includes destruction, removing CUI from documents, or redacting selected sections or words from a document by obscuring the redacted sections or words in a manner equivalent in effectiveness to removing the words or sections from the document. NARA policy and guidance control sanitization processes for controlled unclassified information.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;(SP 800-88 provides guidance on media sanitization.)&#039;&#039;&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;references/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Chapter Three: The Requirements ==&lt;br /&gt;
&#039;&#039;Security requirements for protecting the confidentiality of CUI&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
This chapter describes fourteen families of recommended security requirements for protecting the confidentiality of CUI in nonfederal systems and organizations.&amp;lt;ref&amp;gt;The security objectives of confidentiality and integrity are closely related since many of the underlying security mechanisms at the system level support both objectives. Therefore, the basic and derived security requirements in this publication provide protection from unauthorized disclosure and unauthorized modification of CUI.&amp;lt;/ref&amp;gt; The security controls from SP 800-53 associated with the basic and derived requirements are listed in Appendix D.&amp;lt;ref&amp;gt;The security control references in Appendix D are included to promote a better understanding of the recommended security requirements and do not expand the scope of the requirements.&amp;lt;/ref&amp;gt; Organizations can use the NIST publication to obtain additional, non-prescriptive information related to the recommended security requirements (e.g., explanatory information in the discussion section for each of the referenced security controls, mapping tables to ISO/IEC 27001 security controls, and a catalog of optional controls that can be used to specify additional security requirements, if needed). This information can help clarify or interpret the requirements in the context of mission and business requirements, operational environments, or assessments of risk. Nonfederal organizations can implement a variety of potential security solutions, either directly or using managed services, to satisfy the security requirements, and may implement alternative, but equally effective, security measures to compensate for the inability to satisfy a requirement.&amp;lt;ref&amp;gt;To promote consistency, transparency, and comparability, the compensatory security measures selected by organizations are based on or derived from existing and recognized security standards and control sets, including, for example, ISO/IEC 27001 or SP 800-53.&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Discussion section:&#039;&#039;&#039; The discussion section associated with each CUI requirement is informative, not normative. It is not intended to extend the scope of a requirement or to influence the solutions organizations may use to satisfy a requirement. In addition, the use of examples is notional, not exhaustive, and not reflective of potential options available to organizations.&lt;br /&gt;
&lt;br /&gt;
Nonfederal organizations describe, in a system security plan, how the security requirements are met or how organizations plan to meet the requirements and address known and anticipated threats. The system security plan describes: the system boundary; operational environment; how security requirements are implemented; and the relationships with or connections to other systems. Nonfederal organizations develop plans of action that describe how unimplemented security requirements will be met and how any planned mitigations will be implemented. Organizations can document the system security plan and the plan of action as separate or combined documents and in any chosen format.&amp;lt;ref&amp;gt;NIST&#039;s CUI project provides supplemental material for Special Publication 800-171, including templates for system security plans and plans of action.&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
When requested, the system security plan (or extracts thereof) and the associated plans of action for any planned implementations or mitigations are submitted to the responsible federal agency/contracting office to demonstrate the nonfederal organization&#039;s implementation or planned implementation of the security requirements. Federal agencies may consider the submitted system security plans and plans of action as critical inputs to a risk management decision to process, store, or transmit CUI on a system hosted by a nonfederal organization, and whether it is advisable to pursue an agreement or contract with the nonfederal organization.&lt;br /&gt;
&lt;br /&gt;
The recommended security requirements in this publication apply only to the components of nonfederal systems that process, store, or transmit CUI or that provide protection for such components. Some systems, including specialized systems (e.g., industrial/process control systems, medical devices, computer numerical control machines), may have limitations on the application of certain security requirements. To accommodate such issues, the system security plan, as reflected in requirement 3.12.4, is used to describe any enduring exceptions to the security requirements. Individual, isolated, or temporary deficiencies are managed through plans of action, as reflected in requirement 3.12.2.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;The meaning of &#039;&#039;organizational systems&#039;&#039;:&#039;&#039;&#039; The term &#039;&#039;organizational system&#039;&#039; is used in many of the recommended CUI security requirements in this publication. This term has a specific meaning regarding the scope of applicability for the security requirements: the requirements apply only to the components of nonfederal systems that process, store, or transmit CUI, or that provide protection for the system components. The appropriate scoping for the CUI security requirements is an important factor in determining protection-related investment decisions and managing security risk for nonfederal organizations that have the responsibility of safeguarding CUI.&lt;br /&gt;
&lt;br /&gt;
=== 3.1 Access Control ===&lt;br /&gt;
==== Basic Security Requirements ====&lt;br /&gt;
;3.1.1: Limit system access to authorized users, processes acting on behalf of authorized users, and devices (including other systems).&lt;br /&gt;
:&#039;&#039;&#039;Discussion:&#039;&#039;&#039; Access control policies (e.g., identity- or role-based policies, control matrices, and cryptography) control access between active entities or subjects (i.e., users or processes acting on behalf of users) and passive entities or objects (e.g., devices, files, records, and domains) in systems. Access enforcement mechanisms can be employed at the application and service level to provide increased information security. Other systems include systems internal and external to the organization. This requirement focuses on account management for systems and applications. The definition of and enforcement of access authorizations, other than those determined by account type (e.g., privileged versus non-privileged), are addressed in requirement 3.1.2.&lt;br /&gt;
&lt;br /&gt;
;3.1.2: Limit system access to the types of transactions and functions that authorized users are permitted to execute.&lt;br /&gt;
:&#039;&#039;&#039;Discussion:&#039;&#039;&#039; Organizations may choose to define access privileges or other attributes by account, by type of account, or a combination of both. System account types include individual, shared, group, system, anonymous, guest, emergency, developer, manufacturer, vendor, and temporary. Other attributes required for authorizing access include restrictions on time-of-day, day-of-week, and point-of-origin. In defining other account attributes, organizations consider system-related requirements (e.g., scheduled system upgrades and maintenance) and mission or business requirements (e.g., time zone differences, customer requirements, remote access to support travel requirements).&lt;br /&gt;
&lt;br /&gt;
==== Derived Security Requirements ====&lt;br /&gt;
;3.1.3: Control the flow of CUI in accordance with approved authorizations.&lt;br /&gt;
:&#039;&#039;&#039;Discussion:&#039;&#039;&#039; Information flow control regulates where information can travel within a system and between systems (versus who can access the information), without explicit regard to subsequent accesses to that information. Flow control restrictions include: keeping export-controlled information from being transmitted in the clear to the Internet; blocking outside traffic that claims to be from within the organization; restricting requests to the Internet that are not from the internal web proxy server; and limiting information transfers between organizations based on data structures and content.&lt;br /&gt;
&lt;br /&gt;
Organizations commonly use information flow control policies and enforcement mechanisms to control the flow of information between designated sources and destinations (e.g., networks, individuals, and devices) within systems and between interconnected systems. Flow control is based on characteristics of the information or the information path. Enforcement occurs in boundary protection devices (e.g., gateways, routers, guards, encrypted tunnels, firewalls) that employ rule sets or configuration settings that restrict system services, provide packet-filtering based on header information, or message-filtering based on message content. Organizations also consider the trustworthiness of filtering and inspection mechanisms critical to information flow enforcement.&lt;br /&gt;
&lt;br /&gt;
Transferring information between systems representing different security domains with different security policies introduces the risk that such transfers violate one or more domain security policies. In such situations, information owners or stewards provide guidance at designated policy enforcement points between interconnected systems. Enforcement includes prohibiting information transfers between interconnected systems (i.e., allowing access only), employing hardware mechanisms to enforce one-way information flows, and implementing trustworthy regrading mechanisms to reassign security attributes and labels.&lt;br /&gt;
&lt;br /&gt;
;3.1.4: Separate the duties of individuals to reduce the risk of malevolent activity without collusion.&lt;br /&gt;
:&#039;&#039;&#039;Discussion:&#039;&#039;&#039; Separation of duties addresses the potential for abuse of authorized privileges and helps reduce the risk of malevolent activity without collusion. It includes dividing mission functions and system support functions among different individuals or roles; conducting system support functions with different individuals (e.g., configuration management, quality assurance and testing, system management, programming, and network security); and ensuring that security personnel administering access control functions do not also administer audit functions. Because separation-of-duty violations can span systems and application domains, organizations consider the entirety of organizational systems and components when developing policy on separation of duties.&lt;br /&gt;
&lt;br /&gt;
;3.1.5: Employ the principle of least privilege, including for specific security functions and privileged accounts.&lt;br /&gt;
:&#039;&#039;&#039;Discussion:&#039;&#039;&#039; Organizations employ the principle of least privilege for specific duties and authorized accesses for users and processes, with the goal of authorized privileges no higher than necessary to accomplish required missions or business functions. Organizations consider creating additional processes, roles, and system accounts as necessary to achieve least privilege, and also apply least privilege to the development, implementation, and operation of organizational systems. Security functions include establishing system accounts, setting logged events, setting intrusion detection parameters, and configuring access authorizations.&lt;br /&gt;
&lt;br /&gt;
Privileged accounts, including super user accounts, are typically described as system administrator accounts for various commercial off-the-shelf operating systems. Restricting privileged accounts to specific personnel or roles prevents day-to-day users from having access to privileged information or functions. Organizations may differentiate application of this requirement between local and domain accounts, provided they retain the ability to control system configurations for key security parameters and otherwise sufficiently mitigate risk.&lt;br /&gt;
&lt;br /&gt;
;3.1.6: Use non-privileged accounts or roles when accessing nonsecurity functions.&lt;br /&gt;
:&#039;&#039;&#039;Discussion:&#039;&#039;&#039; This requirement limits exposure when operating from within privileged accounts or roles. The inclusion of roles addresses situations where organizations implement access control policies such as role-based access control, and where a change of role provides the same degree of assurance in the change of access authorizations for the user and all processes acting on the user&#039;s behalf as would be provided by a change between a privileged and non-privileged account.&lt;br /&gt;
&lt;br /&gt;
;3.1.7: Prevent non-privileged users from executing privileged functions and capture the execution of such functions in audit logs.&lt;br /&gt;
:&#039;&#039;&#039;Discussion:&#039;&#039;&#039; Privileged functions include establishing system accounts, performing system integrity checks, conducting patching operations, or administering cryptographic key management activities. Non-privileged users are individuals who do not possess appropriate authorizations. Circumventing intrusion detection and prevention mechanisms or malicious code protection mechanisms are examples of privileged functions requiring protection from non-privileged users. This requirement represents a condition to be achieved by the definition of authorized privileges in 3.1.2.&lt;br /&gt;
&lt;br /&gt;
Misuse of privileged functions, whether intentional or unintentional by authorized users, or by unauthorized external entities that have compromised system accounts, is a serious and ongoing concern with potentially significant adverse impacts. Logging the use of privileged functions is one way to detect such misuse and help mitigate the risk from insider threats and the advanced persistent threat.&lt;br /&gt;
&lt;br /&gt;
;3.1.8: Limit unsuccessful logon attempts.&lt;br /&gt;
:&#039;&#039;&#039;Discussion:&#039;&#039;&#039; This requirement applies regardless of whether the logon occurs via a local or network connection. Due to the potential for denial of service, automatic lockouts initiated by systems are, in most cases, temporary and automatically release after a predetermined period established by the organization (i.e., a delay algorithm). Organizations may employ different delay algorithms for different system components based on their capabilities. Responses to unsuccessful logon attempts may be implemented at the operating system and application levels.&lt;br /&gt;
&lt;br /&gt;
;3.1.9: Provide privacy and security notices consistent with applicable CUI rules.&lt;br /&gt;
:&#039;&#039;&#039;Discussion:&#039;&#039;&#039; System use notifications can be implemented using messages or warning banners displayed before individuals log in to organizational systems. System use notifications are used only for access via logon interfaces with human users and are not required when such human interfaces do not exist. Based on a risk assessment, organizations consider whether a secondary system use notification is needed to access applications or other system resources after the initial network logon. Where necessary, posters or other printed materials may be used in lieu of an automated system banner. Organizations consult with the Office of General Counsel for legal review and approval of warning banner content.&lt;br /&gt;
&lt;br /&gt;
;3.1.10: Use session lock with pattern-hiding displays to prevent access and viewing of data after a period of inactivity.&lt;br /&gt;
:&#039;&#039;&#039;Discussion:&#039;&#039;&#039; Session locks are temporary actions taken when users stop work and move away from the immediate vicinity of the system but do not want to log out because of the temporary nature of their absence. Session locks are implemented where session activities can be determined, typically at the operating system level, but can also be at the application level. Session locks are not an acceptable substitute for logging out of the system, for example, if organizations require users to log out at the end of the workday.&lt;br /&gt;
&lt;br /&gt;
Pattern-hiding displays can include static or dynamic images, such as screen-saver patterns, photographic images, solid colors, a clock, a battery-life indicator, or a blank screen, with the additional caveat that none of the images convey controlled unclassified information.&lt;br /&gt;
&lt;br /&gt;
;3.1.11: Terminate (automatically) a user session after a defined condition.&lt;br /&gt;
:&#039;&#039;&#039;Discussion:&#039;&#039;&#039; This requirement addresses the termination of user-initiated logical sessions, in contrast to the termination of network connections associated with communications sessions (i.e., disconnecting from the network). A logical session (for local, network, and remote access) is initiated whenever a user (or process acting on a user&#039;s behalf) accesses an organizational system. Such user sessions can be terminated (and thus terminate user access) without terminating network sessions. Session termination terminates all processes associated with a user&#039;s logical session except those specifically created by the user (i.e., session owner) to continue after the session is terminated. Conditions or trigger events requiring automatic session termination can include organization-defined periods of user inactivity, targeted responses to certain types of incidents, and time-of-day restrictions on system use.&lt;br /&gt;
&lt;br /&gt;
;3.1.12: Monitor and control remote access sessions.&lt;br /&gt;
:&#039;&#039;&#039;Discussion:&#039;&#039;&#039; Remote access is access to organizational systems by users (or processes acting on their behalf) communicating through external networks (e.g., the Internet). Remote access methods include dial-up, broadband, and wireless. Organizations often employ encrypted virtual private networks (VPNs) to enhance confidentiality over remote connections; the use of encrypted VPNs does not make the access non-remote, but when adequately provisioned with appropriate controls, may provide sufficient assurance that the organization can effectively treat such connections as internal networks. VPNs with encrypted tunnels can affect the capability to adequately monitor network communications traffic for malicious code.&lt;br /&gt;
&lt;br /&gt;
Automated monitoring and control of remote access sessions allows organizations to detect cyberattacks and help ensure ongoing compliance with remote access policies by auditing connection activities of remote users on a variety of system components (e.g., servers, workstations, notebook computers, smart phones, and tablets). NIST Special Publications 800-46, 800-77, and 800-113 provide guidance on secure remote access and virtual private networks.&lt;br /&gt;
&lt;br /&gt;
;3.1.13: Employ cryptographic mechanisms to protect the confidentiality of remote access sessions.&lt;br /&gt;
:&#039;&#039;&#039;Discussion:&#039;&#039;&#039; Cryptographic standards include FIPS-validated cryptography and NSA-approved cryptography.&lt;br /&gt;
&lt;br /&gt;
;3.1.14: Route remote access via managed access control points.&lt;br /&gt;
:&#039;&#039;&#039;Discussion:&#039;&#039;&#039; Routing remote access through managed access control points enhances explicit, organizational control over such connections, reducing susceptibility to unauthorized access to organizational systems resulting in the unauthorized disclosure of CUI.&lt;br /&gt;
&lt;br /&gt;
;3.1.15: Authorize remote execution of privileged commands and remote access to security-relevant information.&lt;br /&gt;
:&#039;&#039;&#039;Discussion:&#039;&#039;&#039; A privileged command is a human-initiated (interactively or via a process operating on the human&#039;s behalf) command executed on a system involving the control, monitoring, or administration of the system, including security functions and associated security-relevant information. Security-relevant information is any information within the system that can potentially impact the operation of security functions or the provision of security services in a manner that could result in failure to enforce the system security policy or maintain isolation of code and data. Privileged commands give individuals the ability to execute sensitive, security-critical, or security-relevant system functions. Controlling such access from remote locations helps ensure that unauthorized individuals cannot freely execute such commands with the potential to do serious or catastrophic damage to organizational systems. The ability to affect the integrity of the system is considered security-relevant, as it could enable a means to bypass security functions, even without directly impacting the function itself.&lt;br /&gt;
&lt;br /&gt;
;3.1.16: Authorize wireless access prior to allowing such connections.&lt;br /&gt;
:&#039;&#039;&#039;Discussion:&#039;&#039;&#039; Establishing usage restrictions and configuration/connection requirements for wireless access to the system provides criteria for organizations to support wireless access authorization decisions, reducing the susceptibility to unauthorized access to the system through wireless technologies. Wireless networks use authentication protocols that provide credential protection and mutual authentication. NIST Special Publication 800-97 provides guidance on secure wireless networks.&lt;br /&gt;
&lt;br /&gt;
;3.1.17: Protect wireless access using authentication and encryption.&lt;br /&gt;
:&#039;&#039;&#039;Discussion:&#039;&#039;&#039; Organizations authenticate individuals and devices to help protect wireless access to the system. Special attention is given to the wide variety of devices that are part of the Internet of Things, which may have wireless access to organizational systems.&lt;br /&gt;
&lt;br /&gt;
;3.1.18: Control connection of mobile devices.&lt;br /&gt;
:&#039;&#039;&#039;Discussion:&#039;&#039;&#039; A mobile device is a computing device with a small form factor that can easily be carried by a single individual; is designed to operate without a physical connection (e.g., wirelessly transmitting or receiving information); possesses local, non-removable or removable data storage; and includes a self-contained power source. Mobile devices may also include voice communication capabilities, on-board sensors allowing the device to capture information, or built-in features for synchronizing local data with remote locations. Examples include smart phones, e-readers, and tablets.&lt;br /&gt;
&lt;br /&gt;
Due to the large variety of mobile devices with different technical characteristics and capabilities, organizational restrictions may vary for different device types. Usage restrictions and implementation guidance for mobile devices include: device identification and authentication; configuration management; implementation of mandatory protective software (e.g., malicious code detection, firewall); scanning devices for malicious code; updating virus protection software; scanning for critical software updates and patches; conducting operating system integrity checks; and disabling unnecessary hardware (e.g., wireless, infrared). Many controls for mobile devices are reflected in other CUI security requirements. NIST Special Publication 800-124 provides guidance on mobile device security.&lt;br /&gt;
&lt;br /&gt;
;3.1.19: Encrypt CUI on mobile devices and mobile computing platforms.&amp;lt;ref&amp;gt;Mobile devices and computing platforms include, for example, smartphones and tablets.&amp;lt;/ref&amp;gt;&lt;br /&gt;
:&#039;&#039;&#039;Discussion:&#039;&#039;&#039; Organizations can employ full-device encryption or container-based encryption to protect the confidentiality of CUI on mobile devices and computing platforms. Container-based encryption provides a more fine-grained approach, including encrypting selected data structures such as files, records, or fields.&lt;br /&gt;
&lt;br /&gt;
;3.1.20: Verify and control/limit connections to and use of external systems.&lt;br /&gt;
:&#039;&#039;&#039;Discussion:&#039;&#039;&#039; External systems are systems or components for which organizations typically have no direct supervision and authority over the application of security requirements and controls, or the determination of the effectiveness of implemented controls. External systems include personally owned systems, components, or devices, and privately owned computing and communications devices resident in commercial or public facilities. This requirement also addresses the use of external systems for the processing, storage, or transmission of CUI, including accessing cloud services (e.g., infrastructure as a service, platform as a service, or software as a service) from organizational systems.&lt;br /&gt;
&lt;br /&gt;
Organizations establish terms and conditions for the use of external systems in accordance with organizational security policies and procedures, addressing at a minimum the types of applications that can be accessed on organizational systems from external systems. If terms and conditions with the owners of external systems cannot be established, organizations may impose restrictions on organizational personnel using those external systems.&lt;br /&gt;
&lt;br /&gt;
This requirement recognizes that there are circumstances where individuals using external systems (e.g., contractors, coalition partners) need to access organizational systems. In those situations, organizations need confidence that the external systems contain the necessary controls so as not to compromise, damage, or otherwise harm organizational systems. Verification that the required controls have been effectively implemented can be achieved through third-party independent assessments, attestations, or other means, depending on the assurance or confidence level required.&lt;br /&gt;
&lt;br /&gt;
Note that while &amp;quot;external&amp;quot; typically refers to outside of the organization&#039;s direct supervision and authority, that is not always the case: an organization may have systems that process CUI and others that do not, and among the systems that process CUI there are likely access restrictions that apply between systems. Therefore, from the perspective of a given system, other systems within the organization may be considered &amp;quot;external&amp;quot; to that system.&lt;br /&gt;
&lt;br /&gt;
;3.1.21: Limit use of portable storage devices on external systems.&lt;br /&gt;
:&#039;&#039;&#039;Discussion:&#039;&#039;&#039; Limits on the use of organization-controlled portable storage devices in external systems include complete prohibition of use, or restrictions on how and under what conditions the devices may be used. As with 3.1.20, &amp;quot;external&amp;quot; does not always mean outside the organization; from the perspective of a given system, other systems within the organization may be considered &amp;quot;external&amp;quot; to that system.&lt;br /&gt;
&lt;br /&gt;
;3.1.22: Control CUI posted or processed on publicly accessible systems.&lt;br /&gt;
:&#039;&#039;&#039;Discussion:&#039;&#039;&#039; In accordance with laws, executive orders, directives, policies, regulations, or standards, the public is not authorized access to nonpublic information (e.g., information protected under the Privacy Act, CUI, and proprietary information). This requirement addresses systems that are controlled by the organization and accessible to the public, typically without identification or authentication. Individuals authorized to post CUI onto publicly accessible systems are designated, and the content of information is reviewed prior to posting to ensure that nonpublic information is not included.&lt;br /&gt;
&lt;br /&gt;
=== 3.2 Awareness and Training ===&lt;br /&gt;
==== Basic Security Requirements ====&lt;br /&gt;
;3.2.1: Ensure that managers, systems administrators, and users of organizational systems are made aware of the security risks associated with their activities and of the applicable policies, standards, and procedures related to the security of those systems.&lt;br /&gt;
:&#039;&#039;&#039;Discussion:&#039;&#039;&#039; Organizations determine the content and frequency of security awareness training and techniques based on specific organizational requirements and the systems to which personnel have authorized access. Content includes a basic understanding of the need for information security and user actions to maintain security and respond to suspected security incidents, as well as awareness of the need for operations security. Techniques include formal training, supplies inscribed with security reminders, email advisories, logon screen messages, security awareness posters, and information security awareness events. NIST Special Publication 800-50 provides guidance on security awareness and training programs.&lt;br /&gt;
&lt;br /&gt;
;3.2.2: Ensure that personnel are trained to carry out their assigned information security-related duties and responsibilities.&lt;br /&gt;
:&#039;&#039;&#039;Discussion:&#039;&#039;&#039; Organizations determine the content and frequency of security training based on assigned duties, roles, and responsibilities, and the security requirements of organizations and the systems to which personnel have authorized access. Organizations provide system developers, architects, acquisition/procurement officials, system/network administrators, configuration management and auditing personnel, independent verification and validation personnel, security assessors, and others with system-level access, security-related technical training tailored to their assigned duties. Comprehensive role-based training addresses management, operational, and technical roles and responsibilities covering physical, personnel, and technical controls, and can include policies, procedures, tools, and artifacts for the defined security roles. Organizations also provide training for responsibilities related to operations and supply chain security. NIST Special Publication 800-181 provides guidance on role-based information security training; NIST Special Publication 800-161 provides guidance on supply chain risk management.&lt;br /&gt;
&lt;br /&gt;
==== Derived Security Requirements ====&lt;br /&gt;
;3.2.3: Provide security awareness training on recognizing and reporting potential indicators of insider threat.&lt;br /&gt;
:&#039;&#039;&#039;Discussion:&#039;&#039;&#039; Potential indicators and possible precursors of insider threat include behaviors such as: inordinate, long-term job dissatisfaction; attempts to gain access to information not required for job performance; unexplained access to financial resources; bullying or sexual harassment of fellow employees; workplace violence; and other serious violations of organizational policies, procedures, directives, rules, or practices. Security awareness training includes how to communicate employee and management concerns about potential indicators of insider threat through appropriate organizational channels. Organizations may consider tailoring insider threat awareness topics to the role (e.g., training for managers focused on changes in team members&#039; behavior, training for employees focused on more general observations).&lt;br /&gt;
&lt;br /&gt;
=== 3.3 Audit and Accountability ===&lt;br /&gt;
==== Basic Security Requirements ====&lt;br /&gt;
;3.3.1: Create and retain system audit logs and records to the extent needed to enable the monitoring, analysis, investigation, and reporting of unlawful or unauthorized system activity.&lt;br /&gt;
:&#039;&#039;&#039;Discussion:&#039;&#039;&#039; An event is any observable occurrence in a system, including unlawful or unauthorized system activity. Organizations identify event types for which a logging functionality is needed as those significant and relevant to the security of systems and their operating environments. Event types can include password changes, failed logons or accesses, administrative privilege usage, or third-party credential usage. Organizations consider the monitoring and auditing appropriate for each CUI security requirement, balanced with other system needs; for example, systems may have the capability to log every file access but not activate that capability except in specific circumstances due to the potential burden on performance.&lt;br /&gt;
&lt;br /&gt;
Audit records can be generated at various levels of abstraction, including at the packet level. Selecting the appropriate level of abstraction is a critical aspect of audit logging and can facilitate identifying root causes of problems. Organizations consider the logging necessary to cover related events, such as steps in distributed, transaction-based processes and actions occurring in service-oriented or cloud-based architectures.&lt;br /&gt;
&lt;br /&gt;
Audit record content that may be necessary includes time stamps, source and destination addresses, user or process identifiers, event descriptions, success or failure indications, filenames involved, and access control or flow control rules invoked. Organizations consider limiting additional audit log information to only what is explicitly needed, to avoid misleading information or making it harder to locate information of interest. Audit logs are reviewed and analyzed as often as needed to facilitate risk-based decision making. NIST Special Publication 800-92 provides guidance on security log management.&lt;br /&gt;
&lt;br /&gt;
;3.3.2: Ensure that the actions of individual system users can be uniquely traced to those users, so they can be held accountable for their actions.&lt;br /&gt;
:&#039;&#039;&#039;Discussion:&#039;&#039;&#039; This requirement ensures that audit record content includes the information needed to link an audit event to the actions of an individual, to the extent feasible. Organizations consider logging for traceability including account usage, remote access, wireless connectivity, mobile device connection, boundary communications, configuration settings, physical access, nonlocal maintenance, use of maintenance tools, temperature and humidity, equipment delivery and removal, system component inventory, use of mobile code, and use of Voice over Internet Protocol (VoIP).&lt;br /&gt;
&lt;br /&gt;
==== Derived Security Requirements ====&lt;br /&gt;
;3.3.3: Review and update logged events.&lt;br /&gt;
:&#039;&#039;&#039;Discussion:&#039;&#039;&#039; The intent of this requirement is to periodically re-evaluate which logged events will continue to be included in the list of events to be logged. Event types logged by organizations may change over time; periodic review and updating ensures that the current set remains necessary and sufficient.&lt;br /&gt;
&lt;br /&gt;
;3.3.4: Alert in the event of an audit logging process failure.&lt;br /&gt;
:&#039;&#039;&#039;Discussion:&#039;&#039;&#039; Audit logging process failures include software and hardware errors, failures in audit record capturing mechanisms, and audit record storage capacity being reached or exceeded. This requirement applies to each audit record data storage repository, the total audit record storage capacity of organizations, or both.&lt;br /&gt;
&lt;br /&gt;
;3.3.5: Correlate audit record review, analysis, and reporting processes for investigation and response to indications of unlawful, unauthorized, suspicious, or unusual activity.&lt;br /&gt;
:&#039;&#039;&#039;Discussion:&#039;&#039;&#039; Correlating audit record review, analysis, and reporting processes helps ensure they operate collectively rather than independently. The requirement is agnostic as to whether correlation is applied at the system level or the organization level across all systems.&lt;br /&gt;
&lt;br /&gt;
;3.3.6: Provide audit record reduction and report generation to support on-demand analysis and reporting.&lt;br /&gt;
:&#039;&#039;&#039;Discussion:&#039;&#039;&#039; Audit record reduction manipulates collected audit information and organizes it into a summary format more meaningful to analysts. Reduction and report generation capabilities do not always come from the same system or organizational entity conducting auditing activities, and can include modern data mining techniques with advanced data filters to identify anomalous behavior. Time ordering of audit records can be a significant issue if time stamp granularity in the record is insufficient.&lt;br /&gt;
&lt;br /&gt;
;3.3.7: Provide a system capability that compares and synchronizes internal system clocks with an authoritative source to generate time stamps for audit records.&lt;br /&gt;
:&#039;&#039;&#039;Discussion:&#039;&#039;&#039; Internal system clocks generate time stamps, expressed in Coordinated Universal Time (UTC), a modern continuation of Greenwich Mean Time (GMT), or local time with an offset from UTC. Granularity of time measurements refers to the degree of synchronization between system clocks and reference clocks (e.g., within hundreds or tens of milliseconds); organizations may define different granularities for different components. Time service can also be critical to other security capabilities such as access control and identification and authentication. This requirement provides uniformity of time stamps for systems with multiple clocks and systems connected over a network.&lt;br /&gt;
&lt;br /&gt;
;3.3.8: Protect audit information and audit logging tools from unauthorized access, modification, and deletion.&lt;br /&gt;
:&#039;&#039;&#039;Discussion:&#039;&#039;&#039; Audit information includes all information (e.g., audit records, audit log settings, and audit reports) needed to successfully audit system activity. Audit logging tools are the programs and devices used to conduct audit and logging activities. This requirement focuses on the technical protection of audit information and limits the ability to access and execute audit logging tools to authorized individuals; physical protection of audit information is addressed by media protection and physical/environmental protection requirements.&lt;br /&gt;
&lt;br /&gt;
;3.3.9: Limit management of audit logging functionality to a subset of privileged users.&lt;br /&gt;
:&#039;&#039;&#039;Discussion:&#039;&#039;&#039; Individuals with privileged access to a system who are also subject to audit by that system may affect the reliability of audit information by inhibiting audit logging activities or modifying audit records. This requirement specifies that privileged access be further defined between audit-related privileges and other privileges, limiting the users who have audit-related privileges.&lt;br /&gt;
&lt;br /&gt;
=== 3.4 Configuration Management ===&lt;br /&gt;
==== Basic Security Requirements ====&lt;br /&gt;
;3.4.1: Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles.&lt;br /&gt;
:&#039;&#039;&#039;Discussion:&#039;&#039;&#039; Baseline configurations are documented, formally reviewed, and agreed-upon specifications for systems or configuration items within them, serving as a basis for future builds, releases, and changes. Baseline configurations include information about system components (e.g., standard software packages installed on workstations, notebook computers, servers, network components, or mobile devices; current version, update, and patch information for operating systems and applications; and configuration settings and parameters), network topology, and the logical placement of components within the system architecture. Maintaining effective baseline configurations requires creating new baselines as systems change over time, including reviewing and updating the baseline when changes are made based on security risks and deviations from the established configuration.&lt;br /&gt;
&lt;br /&gt;
Organizations can implement centralized system component inventories spanning multiple organizational systems, ensuring the inventories include system-specific information required for proper component accountability (e.g., system association, system owner). Information for effective accountability includes hardware inventory specifications, software license information, software version numbers, component owners, and, for networked components, machine names and network addresses. NIST Special Publication 800-128 provides guidance on security-focused configuration management.&lt;br /&gt;
&lt;br /&gt;
;3.4.2: Establish and enforce security configuration settings for information technology products employed in organizational systems.&lt;br /&gt;
:&#039;&#039;&#039;Discussion:&#039;&#039;&#039; Configuration settings are the parameters that can be changed in hardware, software, or firmware components that affect the security posture or functionality of the system. Products for which security-related settings can be defined include mainframe computers, servers, workstations, input/output devices, network components, operating systems, middleware, and applications.&lt;br /&gt;
&lt;br /&gt;
Security parameters are those impacting the security state of systems, including parameters required to satisfy other security requirements, such as registry settings, account/file/directory permission settings, and settings for functions, ports, protocols, and remote connections. Organizations establish organization-wide configuration settings and derive specific settings for systems, which become part of the systems&#039; configuration baseline. Common secure configurations (also called security configuration checklists, lockdown and hardening guides, security reference guides, or security technical implementation guides) provide recognized, standardized benchmarks for secure configuration of specific IT platforms/products. NIST Special Publications 800-70 and 800-128 provide guidance on security configuration settings.&lt;br /&gt;
&lt;br /&gt;
==== Derived Security Requirements ====&lt;br /&gt;
;3.4.3: Track, review, approve or disapprove, and log changes to organizational systems.&lt;br /&gt;
:&#039;&#039;&#039;Discussion:&#039;&#039;&#039; Tracking, reviewing, approving/disapproving, and logging changes is called configuration change control, which involves the systematic proposal, justification, implementation, testing, review, and disposition of changes to systems, including upgrades and modifications. It includes changes to baseline configurations, changes to configuration settings for IT products, unscheduled and unauthorized changes, and changes to remediate vulnerabilities. Processes for managing configuration changes include Configuration Control Boards or Change Advisory Boards that review and approve proposed changes. NIST Special Publication 800-128 provides guidance on configuration change control.&lt;br /&gt;
&lt;br /&gt;
;3.4.4: Analyze the security impact of changes prior to implementation.&lt;br /&gt;
:&#039;&#039;&#039;Discussion:&#039;&#039;&#039; Personnel with information security responsibilities (e.g., system administrators, security officers, security managers, security engineers) conduct security impact analyses, possessing the necessary skills and technical expertise to analyze changes and their security ramifications. This may include reviewing security plans and system design documentation to understand controls and how changes might affect them, and may include risk assessments to understand impact and determine if additional controls are required. NIST Special Publication 800-128 provides related guidance.&lt;br /&gt;
&lt;br /&gt;
;3.4.5: Define, document, approve, and enforce physical and logical access restrictions associated with changes to organizational systems.&lt;br /&gt;
:&#039;&#039;&#039;Discussion:&#039;&#039;&#039; Any changes to hardware, software, or firmware components can potentially have significant effects on overall system security. Organizations therefore permit only qualified and authorized individuals to access systems to initiate changes, including upgrades and modifications; access restrictions for change also include software libraries. Restrictions include physical and logical access control requirements, workflow automation, media libraries, abstract layers, and change windows. NIST Special Publication 800-128 provides related guidance.&lt;br /&gt;
&lt;br /&gt;
;3.4.6: Employ the principle of least functionality by configuring organizational systems to provide only essential capabilities.&lt;br /&gt;
:&#039;&#039;&#039;Discussion:&#039;&#039;&#039; Systems can provide a wide variety of functions and services, some of which, though provided by default, may not be necessary to support essential organizational missions or operations. Providing multiple services from a single system component increases risk relative to limiting the services provided by any one component; where feasible, organizations limit component functionality to a single function per component. Organizations review functions and services to determine candidates for elimination, disable unused or unnecessary physical and logical ports and protocols, and can use network scanning tools, intrusion detection and prevention systems, and end-point protections to identify and prevent the use of prohibited functions, ports, protocols, and services.&lt;br /&gt;
&lt;br /&gt;
;3.4.7: Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services.&lt;br /&gt;
:&#039;&#039;&#039;Discussion:&#039;&#039;&#039; Restricting nonessential software includes restricting the roles allowed to approve program execution, prohibiting auto-execute, program blacklisting and whitelisting, or restricting the number of program instances executed simultaneously. Organizations make a security-based determination of which functions, ports, protocols, and services are restricted. Bluetooth, File Transfer Protocol (FTP), and peer-to-peer networking are examples of protocols organizations consider preventing, restricting, or disabling.&lt;br /&gt;
&lt;br /&gt;
;3.4.8: Apply deny-by-exception (blacklisting) policy to prevent the use of unauthorized software or deny-all, permit-by-exception (whitelisting) policy to allow the execution of authorized software.&lt;br /&gt;
:&#039;&#039;&#039;Discussion:&#039;&#039;&#039; The process used to identify software programs not authorized to execute is commonly called blacklisting; the process used to identify programs that are authorized to execute is commonly called whitelisting. Whitelisting is the stronger of the two policies. Organizations also consider verifying the integrity of whitelisted software using, for example, cryptographic checksums, digital signatures, or hash functions, either prior to execution or at system startup. NIST Special Publication 800-167 provides guidance on application whitelisting.&lt;br /&gt;
&lt;br /&gt;
;3.4.9: Control and monitor user-installed software.&lt;br /&gt;
:&#039;&#039;&#039;Discussion:&#039;&#039;&#039; Users can install software in organizational systems if given the necessary privileges. To maintain control, organizations identify permitted and prohibited actions regarding software installation through policy. Permitted installations may include updates and security patches from organization-approved &amp;quot;app stores&amp;quot;; prohibited installations may include software with unknown or suspect pedigrees or software considered potentially malicious. Policy enforcement methods include procedural methods, automated methods, or both.&lt;br /&gt;
&lt;br /&gt;
=== 3.5 Identification and Authentication ===&lt;br /&gt;
==== Basic Security Requirements ====&lt;br /&gt;
;3.5.1: Identify system users, processes acting on behalf of users, and devices.&lt;br /&gt;
:&#039;&#039;&#039;Discussion:&#039;&#039;&#039; Common device identifiers include Media Access Control (MAC) addresses, Internet Protocol (IP) addresses, or device-unique token identifiers. Management of individual identifiers does not apply to shared system accounts; typically, individual identifiers are the user names associated with system accounts assigned to individuals. Organizations may require unique identification of individuals in group accounts, and this requirement also addresses individual identifiers not necessarily associated with system accounts. Organizational devices requiring identification may be defined by type, by device, or by a combination of both. NIST Special Publication 800-63-3 provides guidance on digital identities.&lt;br /&gt;
&lt;br /&gt;
;3.5.2: Authenticate (or verify) the identities of users, processes, or devices, as a prerequisite to allowing access to organizational systems.&lt;br /&gt;
:&#039;&#039;&#039;Discussion:&#039;&#039;&#039; Individual authenticators include passwords, key cards, cryptographic devices, and one-time password devices. Developers ship system components with factory default authentication credentials to allow for initial installation and configuration; default credentials are often well known, easily discoverable, and present a significant security risk. Systems support authenticator management through organization-defined settings and restrictions for authenticator characteristics, including minimum password length, validation time windows for time-synchronous one-time tokens, and the number of allowed rejections during biometric verification. Authenticator management includes issuing and revoking authenticators for temporary access, such as for remote maintenance. Device authenticators include certificates and passwords. NIST Special Publication 800-63-3 provides guidance on digital identities.&lt;br /&gt;
&lt;br /&gt;
==== Derived Security Requirements ====&lt;br /&gt;
;3.5.3: Use multifactor authentication for local and network access to privileged accounts and for network access to non-privileged accounts.&amp;lt;ref&amp;gt;Multifactor authentication requires two or more different factors to achieve authentication: something you know (e.g., password/PIN); something you have (e.g., cryptographic identification device, token); or something you are (e.g., biometric). This requirement should not be interpreted as requiring federal Personal Identity Verification (PIV) card or Department of Defense Common Access Card (CAC)-like solutions. A variety of multifactor solutions (including those with replay resistance) using tokens and biometrics are commercially available, and may employ hard tokens (e.g., smartcards, key fobs, dongles) or soft tokens to store user credentials.&amp;lt;/ref&amp;gt;&amp;lt;ref&amp;gt;Local access is any access to a system by a user (or process acting on a user&#039;s behalf) communicating through a direct connection without the use of a network. Network access is any access to a system by a user (or process) communicating through a network (e.g., local area network, wide area network, Internet).&amp;lt;/ref&amp;gt;&lt;br /&gt;
:&#039;&#039;&#039;Discussion:&#039;&#039;&#039; Multifactor authentication requires two or more different factors: something you know (e.g., password, PIN); something you have (e.g., cryptographic identification device, token); or something you are (e.g., biometric). Solutions featuring physical authenticators include hardware authenticators providing time-based or challenge-response authentication and smart cards. Organizations may also employ authentication mechanisms at the application level, when necessary.&lt;br /&gt;
&lt;br /&gt;
Access to organizational systems is defined as local access or network access. Local access is any access obtained by direct connection without the use of networks; network access is access obtained through network connections. Remote access is a type of network access involving communication through external networks. Encrypted virtual private networks connecting organization-controlled and non-organization-controlled endpoints may be treated as internal networks with regard to confidentiality protection. NIST Special Publication 800-63-3 provides guidance on digital identities.&lt;br /&gt;
&lt;br /&gt;
;3.5.4: Employ replay-resistant authentication mechanisms for network access to privileged and non-privileged accounts.&lt;br /&gt;
:&#039;&#039;&#039;Discussion:&#039;&#039;&#039; Authentication processes resist replay attacks if it is impractical to successfully authenticate by recording or replaying previous authentication messages. Replay-resistant techniques include protocols using nonces or challenges, such as time-synchronous or challenge-response one-time authenticators. NIST Special Publication 800-63-3 provides guidance on digital identities.&lt;br /&gt;
&lt;br /&gt;
;3.5.5: Prevent reuse of identifiers for a defined period.&lt;br /&gt;
:&#039;&#039;&#039;Discussion:&#039;&#039;&#039; Identifiers are provided for users, processes acting on their behalf, or devices (see 3.5.1). Preventing reuse implies preventing the assignment of previously used individual, group, role, or device identifiers to different individuals, groups, roles, or devices.&lt;br /&gt;
&lt;br /&gt;
;3.5.6: Disable identifiers after a defined period of inactivity.&lt;br /&gt;
:&#039;&#039;&#039;Discussion:&#039;&#039;&#039; Inactive identifiers pose a risk because attackers may exploit them to gain undetected access to organizational devices; owners of inactive accounts may not notice if unauthorized access has occurred.&lt;br /&gt;
&lt;br /&gt;
;3.5.7: Enforce a minimum password complexity and change of characters when new passwords are created.&lt;br /&gt;
:&#039;&#039;&#039;Discussion:&#039;&#039;&#039; This requirement applies to single-factor authentication of individuals using passwords as individual or group authenticators, and similarly when passwords are used as part of multifactor authenticators. The number of changed characters refers to the number of changes required relative to the total number of positions in the current password. Organizations may also consider salting passwords to mitigate certain brute-force attacks.&lt;br /&gt;
&lt;br /&gt;
;3.5.8: Prohibit password reuse for a specified number of generations.&lt;br /&gt;
:&#039;&#039;&#039;Discussion:&#039;&#039;&#039; Password lifetime restrictions do not apply to temporary passwords.&lt;br /&gt;
&lt;br /&gt;
;3.5.9: Allow temporary password use for system logons with an immediate change to a permanent password.&lt;br /&gt;
:&#039;&#039;&#039;Discussion:&#039;&#039;&#039; Changing temporary passwords to permanent passwords immediately after system logon ensures the necessary strength of the authentication mechanism is implemented at the earliest opportunity, reducing susceptibility to authenticator compromise.&lt;br /&gt;
&lt;br /&gt;
;3.5.10: Store and transmit only cryptographically-protected passwords.&lt;br /&gt;
:&#039;&#039;&#039;Discussion:&#039;&#039;&#039; Cryptographically protected passwords use salted one-way cryptographic hashes of passwords.&lt;br /&gt;
&lt;br /&gt;
;3.5.11: Obscure feedback of authentication information.&lt;br /&gt;
:&#039;&#039;&#039;Discussion:&#039;&#039;&#039; System feedback does not provide information that would allow unauthorized individuals to compromise authentication mechanisms. For systems with relatively large monitors (e.g., desktop or notebook computers), the threat of &amp;quot;shoulder surfing&amp;quot; may be significant; for systems with small displays (e.g., mobile devices) this threat may be less significant but is balanced against the increased likelihood of typographic input errors from small keyboards. The means for obscuring feedback — such as displaying asterisks when users type passwords, or showing feedback briefly before fully obscuring it — is selected accordingly.&lt;br /&gt;
&lt;br /&gt;
=== 3.6 Incident Response ===&lt;br /&gt;
==== Basic Security Requirements ====&lt;br /&gt;
;3.6.1: Establish an operational incident-handling capability for organizational systems that includes preparation, detection, analysis, containment, recovery, and user response activities.&lt;br /&gt;
:&#039;&#039;&#039;Discussion:&#039;&#039;&#039; Incident-handling capability depends on the capabilities of organizational systems and the mission/business processes they support; organizations consider incident handling as part of the definition, design, and development of those processes and systems. Incident-related information can come from audit monitoring, network monitoring, physical access monitoring, user and administrator reports, and reported supply chain events. Effective incident-handling capability includes coordination among many organizational entities, including mission/business owners, system owners, authorizing officials, human resources, physical and personnel security offices, legal departments, operations personnel, procurement offices, and the risk executive.&lt;br /&gt;
&lt;br /&gt;
As part of user response activities, incident response training is linked to assigned roles and responsibilities: regular users may only need to know who to call or how to recognize an incident, system administrators may need additional training on handling or remediating incidents, and incident responders may receive more specific training on forensics, reporting, and system recovery and restoration. Training includes identifying and reporting suspicious activities from external and internal sources; user response activities also include help desk support, assistance groups, and access to forensics or consumer redress services when required. NIST Special Publication 800-61 provides guidance on incident handling; NIST Special Publications 800-86 and 800-101 provide guidance on integrating forensic techniques into incident response; NIST Special Publication 800-161 provides guidance on supply chain risk management.&lt;br /&gt;
&lt;br /&gt;
;3.6.2: Track, document, and report incidents to designated officials and/or authorities both internal and external to the organization.&lt;br /&gt;
:&#039;&#039;&#039;Discussion:&#039;&#039;&#039; Tracking and documenting incidents includes maintaining records about each incident, its status, and other pertinent information necessary for forensics and for evaluating incident details, trends, and handling. Incident information can be obtained from incident reports, incident response teams, audit monitoring, network monitoring, physical access monitoring, and user/administrator reports.&lt;br /&gt;
&lt;br /&gt;
Reporting incidents addresses specific internal reporting requirements as well as formal reporting requirements applicable to the organization. Suspected security incidents may also be reported, including the receipt of suspicious email communications that could contain malicious code. The types of incidents reported, the content and timeliness of reports, and the designated reporting authorities reflect applicable laws, executive orders, directives, regulations, and policies. NIST Special Publication 800-61 provides guidance on incident handling.&lt;br /&gt;
&lt;br /&gt;
==== Derived Security Requirements ====&lt;br /&gt;
;3.6.3: Test the organizational incident response capability.&lt;br /&gt;
:&#039;&#039;&#039;Discussion:&#039;&#039;&#039; Organizations test incident response capabilities to determine their effectiveness and identify potential weaknesses or deficiencies. Testing includes checklists, walk-through or tabletop exercises, simulations (parallel and full interrupt), and comprehensive exercises, and can include determining the effects of incident response on organizational operations, assets, and individuals. NIST Special Publication 800-84 provides guidance on testing programs for information technology capabilities.&lt;br /&gt;
&lt;br /&gt;
=== 3.7 Maintenance ===&lt;br /&gt;
==== Basic Security Requirements ====&lt;br /&gt;
;3.7.1: Perform maintenance on organizational systems.&amp;lt;ref&amp;gt;In general, system maintenance requirements tend to support the security objective of availability. However, improper system maintenance or a failure to perform maintenance can result in the unauthorized disclosure of CUI, thus compromising confidentiality of that information.&amp;lt;/ref&amp;gt;&lt;br /&gt;
:&#039;&#039;&#039;Discussion:&#039;&#039;&#039; This requirement addresses the information security aspects of the system maintenance program and applies to all types of maintenance on any system component (including hardware, firmware, applications) conducted by any local or nonlocal entity. System maintenance also includes components not directly associated with information processing or data retention, such as scanners, copiers, and printers.&lt;br /&gt;
&lt;br /&gt;
;3.7.2: Provide controls on the tools, techniques, mechanisms, and personnel used to conduct system maintenance.&lt;br /&gt;
:&#039;&#039;&#039;Discussion:&#039;&#039;&#039; This requirement addresses security issues with maintenance tools that are outside the organizational system boundaries that process, store, or transmit CUI, but are used specifically for diagnostic and repair actions on those systems. Organizations have flexibility in determining controls for maintenance tools, which can include approving, controlling, and monitoring their use. Maintenance tools are potential vehicles for transporting malicious code into a facility and into organizational systems, and can include hardware, software, and firmware items such as diagnostic test equipment and packet sniffers.&lt;br /&gt;
&lt;br /&gt;
==== Derived Security Requirements ====&lt;br /&gt;
;3.7.3: Ensure equipment removed for off-site maintenance is sanitized of any CUI.&lt;br /&gt;
:&#039;&#039;&#039;Discussion:&#039;&#039;&#039; This requirement addresses the information security aspects of system maintenance performed off-site and applies to all types of maintenance conducted by a local or nonlocal entity (e.g., in-contract, warranty, in-house, software maintenance agreement). NIST Special Publication 800-88 provides guidance on media sanitization.&lt;br /&gt;
&lt;br /&gt;
;3.7.4: Check media containing diagnostic and test programs for malicious code before the media are used in organizational systems.&lt;br /&gt;
:&#039;&#039;&#039;Discussion:&#039;&#039;&#039; If, upon inspection, organizations determine that media containing maintenance diagnostic and test programs contain malicious code, the incident is handled consistent with incident handling policies and procedures.&lt;br /&gt;
&lt;br /&gt;
;3.7.5: Require multifactor authentication to establish nonlocal maintenance sessions via external network connections and terminate such connections when nonlocal maintenance is complete.&lt;br /&gt;
:&#039;&#039;&#039;Discussion:&#039;&#039;&#039; Nonlocal maintenance and diagnostic activities are conducted by individuals communicating through an external network. The authentication techniques employed for these sessions reflect the network access requirements in 3.5.3.&lt;br /&gt;
&lt;br /&gt;
;3.7.6: Supervise the maintenance activities of maintenance personnel without required access authorization.&lt;br /&gt;
:&#039;&#039;&#039;Discussion:&#039;&#039;&#039; This requirement applies to individuals performing hardware or software maintenance on organizational systems, while 3.10.1 addresses physical access for individuals whose maintenance duties place them within the physical protection perimeter of the systems (e.g., custodial staff, physical plant maintenance personnel). Individuals not previously identified as authorized maintenance personnel — such as IT manufacturers, vendors, consultants, and systems integrators — may require privileged access, for example when conducting maintenance with little or no notice. Organizations may choose to issue temporary credentials to such individuals based on risk assessments; these may be for one-time use or very limited time periods.&lt;br /&gt;
&lt;br /&gt;
=== 3.8 Media Protection ===&lt;br /&gt;
==== Basic Security Requirements ====&lt;br /&gt;
;3.8.1: Protect (i.e., physically control and securely store) system media containing CUI, both paper and digital.&lt;br /&gt;
:&#039;&#039;&#039;Discussion:&#039;&#039;&#039; System media includes digital media (e.g., diskettes, magnetic tapes, external and removable hard disk drives, flash drives, compact disks, digital video disks) and non-digital media (e.g., paper, microfilm). Physically controlling system media includes conducting inventories, maintaining accountability for stored media, and ensuring procedures allow individuals to check out and return media to the media library. Secure storage includes a locked drawer, desk, or cabinet, or a controlled media library. NIST Special Publication 800-111 provides guidance on storage encryption technologies for end-user devices.&lt;br /&gt;
&lt;br /&gt;
;3.8.2: Limit access to CUI on system media to authorized users.&lt;br /&gt;
:&#039;&#039;&#039;Discussion:&#039;&#039;&#039; Access can be limited by physically controlling system media and secure storage areas, including conducting inventories, ensuring procedures allow individuals to check out and return media to the media library, and maintaining accountability for all stored media.&lt;br /&gt;
&lt;br /&gt;
;3.8.3: Sanitize or destroy system media containing CUI before disposal or release for reuse.&lt;br /&gt;
:&#039;&#039;&#039;Discussion:&#039;&#039;&#039; This requirement applies to all system media, digital and non-digital, subject to disposal or reuse. Examples include digital media found in workstations, network components, scanners, copiers, printers, notebook computers, and mobile devices, and non-digital media such as paper and microfilm. Sanitization removes information such that it cannot be retrieved or reconstructed; techniques include clearing, purging, cryptographic erase, and destruction. Organizations determine appropriate sanitization methods, recognizing destruction may be necessary when other methods cannot be applied, and use discretion for media containing information that is public, publicly releasable, or deemed to have no adverse impact if released. Sanitization of non-digital media includes destruction, removing CUI from documents, or redacting sections or words in a manner equivalent to removal. NARA policy and guidance control sanitization processes for CUI. NIST Special Publication 800-88 provides guidance on media sanitization.&lt;br /&gt;
&lt;br /&gt;
==== Derived Security Requirements ====&lt;br /&gt;
;3.8.4: Mark media with necessary CUI markings and distribution limitations.&amp;lt;ref&amp;gt;Implementation of this requirement follows the marking guidance in 32 CFR 2002 and NARA&#039;s CUI guidance. Standard Form (SF) 902 and SF 903 can be used on media containing CUI such as hard drives or USB devices; both forms are available from GSA Advantage.&amp;lt;/ref&amp;gt;&lt;br /&gt;
:&#039;&#039;&#039;Discussion:&#039;&#039;&#039; The term &#039;&#039;security marking&#039;&#039; refers to the application or use of human-readable security attributes. Marking of system media (digital and non-digital) reflects applicable federal laws, executive orders, directives, policies, and regulations.&lt;br /&gt;
&lt;br /&gt;
;3.8.5: Control access to media containing CUI and maintain accountability for media during transport outside of controlled areas.&lt;br /&gt;
:&#039;&#039;&#039;Discussion:&#039;&#039;&#039; Controlled areas are areas or spaces for which organizations provide physical or procedural controls to meet requirements for protecting systems and information. Controls to maintain accountability for media during transport include locked containers and cryptography, which can provide confidentiality and integrity protections depending on the mechanisms used. Activities associated with transport include the transport itself as well as releasing media for transport and ensuring media enters the appropriate transport processes; authorized transport and courier personnel may include individuals external to the organization. Maintaining accountability includes restricting transport activities to authorized personnel and tracking and obtaining explicit records of transport activities to prevent and detect loss, destruction, or tampering.&lt;br /&gt;
&lt;br /&gt;
;3.8.6: Implement cryptographic mechanisms to protect the confidentiality of CUI stored on digital media during transport unless otherwise protected by alternative physical safeguards.&lt;br /&gt;
:&#039;&#039;&#039;Discussion:&#039;&#039;&#039; This requirement applies to portable storage devices (e.g., USB memory sticks, digital video disks, compact disks, external or removable hard disk drives). NIST Special Publication 800-111 provides guidance on storage encryption technologies for end-user devices.&lt;br /&gt;
&lt;br /&gt;
;3.8.7: Control the use of removable media on system components.&lt;br /&gt;
:&#039;&#039;&#039;Discussion:&#039;&#039;&#039; In contrast to requirement 3.8.1, which restricts user access to media, this requirement restricts the use of certain types of media on systems, for example restricting or prohibiting flash drives or external hard disk drives. Organizations can employ technical and nontechnical controls (e.g., policies, procedures, rules of behavior), such as physical cages on workstations to prohibit access to certain external ports, or disabling the ability to insert, read, or write to such devices. Organizations may also limit use to approved devices only, or prohibit writeable portable devices by disabling or removing write capability.&lt;br /&gt;
&lt;br /&gt;
;3.8.8: Prohibit the use of portable storage devices when such devices have no identifiable owner.&lt;br /&gt;
:&#039;&#039;&#039;Discussion:&#039;&#039;&#039; Requiring identifiable owners (individuals, organizations, or projects) for portable storage devices reduces overall risk by allowing organizations to assign responsibility and accountability for addressing known vulnerabilities in the devices (e.g., insertion of malicious code).&lt;br /&gt;
&lt;br /&gt;
;3.8.9: Protect the confidentiality of backup CUI at storage locations.&lt;br /&gt;
:&#039;&#039;&#039;Discussion:&#039;&#039;&#039; Organizations can employ cryptographic mechanisms or alternative physical controls to protect the confidentiality of backup information at designated storage locations. Backed-up information containing CUI may include system-level information (system-state information, operating system software, application software, licenses) and user-level information (information other than system-level information).&lt;br /&gt;
&lt;br /&gt;
=== 3.9 Personnel Security ===&lt;br /&gt;
==== Basic Security Requirements ====&lt;br /&gt;
;3.9.1: Screen individuals prior to authorizing access to organizational systems containing CUI.&lt;br /&gt;
:&#039;&#039;&#039;Discussion:&#039;&#039;&#039; Personnel security screening (vetting) activities involve evaluating an individual&#039;s conduct, integrity, judgment, loyalty, reliability, and stability (i.e., trustworthiness) prior to authorizing access to organizational systems containing CUI. Screening activities reflect applicable federal laws, executive orders, directives, policies, regulations, and criteria established for the level of access required for assigned positions.&lt;br /&gt;
&lt;br /&gt;
;3.9.2: Ensure that organizational systems containing CUI are protected during and after personnel actions such as terminations and transfers.&lt;br /&gt;
:&#039;&#039;&#039;Discussion:&#039;&#039;&#039; Protecting CUI during and after personnel actions may include returning system-related property (e.g., hardware authentication tokens, identification cards, technical manuals, keys, building passes) and conducting exit interviews, which can address nondisclosure agreements and potential limitations on future employment. Exit interviews may not be possible for some terminated individuals (e.g., job abandonment, illness, non-availability of supervisors); for cause terminations, timely execution is essential, and organizations may consider disabling accounts prior to notifying the individual.&lt;br /&gt;
&lt;br /&gt;
This requirement applies to reassignments or transfers when the personnel action is permanent or of such extended duration as to require protection. Organizations define appropriate protections, which may include returning old and issuing new keys, identification cards, and building passes; changing system access authorizations; closing old accounts and establishing new ones; and providing access to official records the individual had access to at previous work locations and accounts.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;(This family has no Derived Security Requirements.)&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
=== 3.10 Physical Protection ===&lt;br /&gt;
==== Basic Security Requirements ====&lt;br /&gt;
;3.10.1: Limit physical access to organizational systems, equipment, and the respective operating environments to authorized individuals.&lt;br /&gt;
:&#039;&#039;&#039;Discussion:&#039;&#039;&#039; This requirement applies to employees, individuals with permanent physical access authorization credentials, and visitors. Authorized individuals have credentials that include badges, identification cards, and smart cards; organizations determine the necessary strength of credentials consistent with applicable laws, policies, and standards. The requirement applies only to areas within facilities not designated as publicly accessible. Limiting physical access to equipment may include placing equipment in locked rooms or secured areas accessible only to authorized individuals, and in locations that can be monitored by organizational personnel. Examples of equipment include computing devices, external disk drives, networking devices, monitors, printers, copiers, scanners, facsimile machines, and audio devices.&lt;br /&gt;
&lt;br /&gt;
;3.10.2: Protect and monitor the physical facility and support infrastructure for organizational systems.&lt;br /&gt;
:&#039;&#039;&#039;Discussion:&#039;&#039;&#039; Monitoring of physical access includes publicly accessible areas within organizational facilities, accomplished for example through guards, sensor devices, or video surveillance. Examples of support infrastructure include system distribution, transmission, and power lines; security controls applied to support infrastructure prevent accidental damage, disruption, and physical tampering, and may also prevent eavesdropping or modification of unencrypted transmissions. Physical access controls for support infrastructure include locked wiring closets, disconnected or locked spare jacks, protection of cabling by conduit or cable trays, and wiretapping sensors.&lt;br /&gt;
&lt;br /&gt;
==== Derived Security Requirements ====&lt;br /&gt;
;3.10.3: Escort visitors and monitor visitor activity.&lt;br /&gt;
:&#039;&#039;&#039;Discussion:&#039;&#039;&#039; Individuals with permanent physical access authorization credentials are not considered visitors. Audit logs can be used to monitor visitor activity.&lt;br /&gt;
&lt;br /&gt;
;3.10.4: Maintain audit logs of physical access.&lt;br /&gt;
:&#039;&#039;&#039;Discussion:&#039;&#039;&#039; Organizations have flexibility in the types of audit logs employed, which can be procedural (e.g., a written log), automated (e.g., capturing ID from a PIV card), or a combination. Physical access points can include facility access points, interior access points to systems or components requiring supplemental access controls, or both.&lt;br /&gt;
&lt;br /&gt;
;3.10.5: Control and manage physical access devices.&lt;br /&gt;
:&#039;&#039;&#039;Discussion:&#039;&#039;&#039; Physical access devices include keys, locks, combinations, and card readers.&lt;br /&gt;
&lt;br /&gt;
;3.10.6: Enforce safeguarding measures for CUI at alternate work sites.&lt;br /&gt;
:&#039;&#039;&#039;Discussion:&#039;&#039;&#039; Alternate work sites may include government facilities or the private residences of employees. Organizations may define different security requirements for specific alternate work sites or types of sites depending on the work-related activities conducted there. NIST Special Publications 800-46 and 800-114 provide guidance on enterprise and user security when teleworking.&lt;br /&gt;
&lt;br /&gt;
=== 3.11 Risk Assessment ===&lt;br /&gt;
==== Basic Security Requirements ====&lt;br /&gt;
;3.11.1: Periodically assess the risk to organizational operations (including mission, functions, image, or reputation), organizational assets, and individuals, resulting from the operation of organizational systems and the associated processing, storage, or transmission of CUI.&lt;br /&gt;
:&#039;&#039;&#039;Discussion:&#039;&#039;&#039; Clearly defined system boundaries are a prerequisite for effective risk assessments, which consider threats, vulnerabilities, likelihood, and impact based on the operation and use of organizational systems, as well as risk from external parties (e.g., service providers, contractors, individuals accessing organizational systems, outsourcing entities). Risk assessments, formal or informal, can be conducted at the organization, mission/business process, or system level, and at any phase of the system development life cycle. NIST Special Publication 800-30 provides guidance on conducting risk assessments.&lt;br /&gt;
&lt;br /&gt;
==== Derived Security Requirements ====&lt;br /&gt;
;3.11.2: Scan for vulnerabilities in organizational systems and applications periodically and when new vulnerabilities affecting those systems and applications are identified.&lt;br /&gt;
:&#039;&#039;&#039;Discussion:&#039;&#039;&#039; Organizations determine required vulnerability scanning for all system components, ensuring potential sources such as networked printers, scanners, and copiers are not overlooked, and update the vulnerabilities scanned for as new ones are discovered. Vulnerability analyses for custom software applications may require static analysis, dynamic analysis, binary analysis, or a hybrid approach. Scanning includes patch levels, functions/ports/protocols/services that should not be accessible, and improperly configured information flow control mechanisms. Organizations consider using SCAP-validated products, tools that use the CVE naming convention and OVAL, and sources such as the Common Weakness Enumeration (CWE) and the National Vulnerability Database (NVD).&lt;br /&gt;
&lt;br /&gt;
Security assessments such as red team exercises provide additional sources of potential vulnerabilities to scan for; organizations also consider tools that express impact using the Common Vulnerability Scoring System (CVSS). Privileged access authorization to selected components facilitates thorough scanning and protects the sensitive nature of such scanning. NIST Special Publication 800-40 provides guidance on vulnerability management.&lt;br /&gt;
&lt;br /&gt;
;3.11.3: Remediate vulnerabilities in accordance with risk assessments.&lt;br /&gt;
:&#039;&#039;&#039;Discussion:&#039;&#039;&#039; Vulnerabilities discovered, for example via the scanning conducted per 3.11.2, are remediated with consideration given to the related assessment of risk, which influences the prioritization of remediation efforts and the level of effort expended for specific vulnerabilities.&lt;br /&gt;
&lt;br /&gt;
=== 3.12 Security Assessment ===&lt;br /&gt;
==== Basic Security Requirements ====&lt;br /&gt;
;3.12.1: Periodically assess the security controls in organizational systems to determine if the controls are effective in their application.&lt;br /&gt;
:&#039;&#039;&#039;Discussion:&#039;&#039;&#039; Organizations assess security controls in organizational systems and their operating environments as part of the system development life cycle. Security controls are the safeguards or countermeasures implemented to satisfy security requirements; assessing them determines whether they are in place and operating as intended. Assessments ensure information security is built into organizational systems, identify weaknesses and deficiencies early, provide information for risk-based decisions, and ensure compliance with vulnerability mitigation procedures. Assessment reports document results in sufficient detail to determine accuracy, completeness, and whether controls are implemented correctly and producing the desired outcome, and results are provided to appropriate individuals or roles.&lt;br /&gt;
&lt;br /&gt;
Organizations ensure assessment results are current, relevant, and obtained with appropriate assessor independence, and can use other activities such as vulnerability scanning and system monitoring to maintain security posture throughout the system life cycle. NIST Special Publication 800-53 provides guidance on security and privacy controls; NIST Special Publication 800-53A provides guidance on developing assessment plans and conducting assessments.&lt;br /&gt;
&lt;br /&gt;
;3.12.2: Develop and implement plans of action designed to correct deficiencies and reduce or eliminate vulnerabilities in organizational systems.&lt;br /&gt;
:&#039;&#039;&#039;Discussion:&#039;&#039;&#039; The plan of action is a key document in the information security program, describing how unimplemented security requirements will be met and how planned mitigations will be implemented. Organizations can document the system security plan and plan of action as separate or combined documents in any chosen format. Federal agencies may consider submitted system security plans and plans of action as critical inputs to risk management decisions about hosting CUI on a nonfederal system.&lt;br /&gt;
&lt;br /&gt;
;3.12.3: Monitor security controls on an ongoing basis to ensure the continued effectiveness of the controls.&lt;br /&gt;
:&#039;&#039;&#039;Discussion:&#039;&#039;&#039; Continuous monitoring programs facilitate ongoing awareness of threats, vulnerabilities, and information security to support risk management decisions. &amp;quot;Continuous&amp;quot; and &amp;quot;ongoing&amp;quot; imply that organizations assess and analyze security controls and risks at a frequency sufficient to support risk-based decisions; results generate appropriate risk response actions. Providing access to security information through reports or dashboards gives officials the capability to make effective, timely decisions; automation supports more frequent inventory updates. Effectiveness is enhanced when monitoring outputs are specific, measurable, actionable, relevant, and timely. NIST Special Publication 800-137 provides guidance on continuous monitoring.&lt;br /&gt;
&lt;br /&gt;
;3.12.4: Develop, document, and periodically update system security plans that describe system boundaries, system environments of operation, how security requirements are implemented, and the relationships with or connections to other systems.&amp;lt;ref&amp;gt;There is no prescribed format or specified level of detail for system security plans; however, organizations ensure the required information is conveyed in those plans.&amp;lt;/ref&amp;gt;&lt;br /&gt;
:&#039;&#039;&#039;Discussion:&#039;&#039;&#039; System security plans relate security requirements to a set of security controls and describe, at a high level, how the controls meet those requirements, without providing detailed technical descriptions of design or implementation. Plans contain sufficient information to enable a design and implementation unambiguously compliant with the plan&#039;s intent, and need not be single documents — they can be a collection of various documents, including ones that already exist, making extensive use of references to policies, procedures, and additional documents. This reduces documentation requirements and keeps security-related information within established management/operational areas related to enterprise architecture, system development life cycle, systems engineering, and acquisition.&lt;br /&gt;
&lt;br /&gt;
Federal agencies may consider submitted system security plans and plans of action as critical inputs to risk management decisions about hosting CUI on a nonfederal system. NIST Special Publication 800-18 provides guidance on developing security plans.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;(This family has no additional Derived Security Requirements.)&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
=== 3.13 System and Communications Protection ===&lt;br /&gt;
==== Basic Security Requirements ====&lt;br /&gt;
;3.13.1: Monitor, control, and protect communications (i.e., information transmitted or received by organizational systems) at the external boundaries and key internal boundaries of organizational systems.&lt;br /&gt;
:&#039;&#039;&#039;Discussion:&#039;&#039;&#039; Communications can be monitored, controlled, and protected at boundary components and by restricting or prohibiting interfaces in organizational systems. Boundary components include gateways, routers, firewalls, guards, network-based malicious code analysis and virtualization systems, or encrypted tunnels implemented within a system security architecture. Restricting or prohibiting interfaces includes restricting external web communications traffic to designated web servers within managed interfaces and prohibiting external traffic that appears to be spoofing internal addresses.&lt;br /&gt;
&lt;br /&gt;
Organizations consider the shared nature of commercial telecommunications services when implementing security requirements, since such services are commonly based on network components and consolidated management systems shared by all attached commercial customers, which may represent sources of increased risk despite contract security provisions. NIST Special Publication 800-41 provides guidance on firewalls and firewall policy; NIST Special Publication 800-125B provides guidance on security for virtualization technologies.&lt;br /&gt;
&lt;br /&gt;
;3.13.2: Employ architectural designs, software development techniques, and systems engineering principles that promote effective information security within organizational systems.&lt;br /&gt;
:&#039;&#039;&#039;Discussion:&#039;&#039;&#039; Organizations apply systems security engineering principles to new development systems or systems undergoing major upgrades, and, to the extent feasible, to legacy system upgrades and modifications. Applying these concepts and principles helps develop trustworthy, secure, and resilient systems and reduces susceptibility to disruptions, hazards, and threats. Examples include developing layered protections; establishing security policies, architecture, and controls as the foundation for design; incorporating security requirements into the system development life cycle; delineating physical and logical security boundaries; training developers to build secure software; and performing threat modeling to identify use cases, threat agents, attack vectors and patterns, design patterns, and compensating controls needed to mitigate risk. NIST Special Publication 800-160, Volume 1 provides guidance on systems security engineering.&lt;br /&gt;
&lt;br /&gt;
==== Derived Security Requirements ====&lt;br /&gt;
;3.13.3: Separate user functionality from system management functionality.&lt;br /&gt;
:&#039;&#039;&#039;Discussion:&#039;&#039;&#039; System management functionality includes functions necessary to administer databases, network components, workstations, or servers, and typically requires privileged user access. Separation of user functionality from system management functionality is physical or logical, and can be implemented using different computers, different central processing units, different operating system instances, different network addresses, virtualization techniques, or combinations thereof. This includes web administrative interfaces using separate authentication methods from other system resources, and may include isolating administrative interfaces on different domains with additional access controls.&lt;br /&gt;
&lt;br /&gt;
;3.13.4: Prevent unauthorized and unintended information transfer via shared system resources.&lt;br /&gt;
:&#039;&#039;&#039;Discussion:&#039;&#039;&#039; Control of information in shared system resources (e.g., registers, cache memory, main memory, hard disks) is also commonly referred to as object reuse and residual information protection. This requirement prevents information produced by prior users or roles from being available to current users or roles that obtain access to shared system resources after those resources have been released back to the system, and also applies to encrypted representations of information. It does not address information remanence, covert channels, or components with only single users or roles.&lt;br /&gt;
&lt;br /&gt;
;3.13.5: Implement subnetworks for publicly accessible system components that are physically or logically separated from internal networks.&lt;br /&gt;
:&#039;&#039;&#039;Discussion:&#039;&#039;&#039; Subnetworks physically or logically separated from internal networks are referred to as demilitarized zones (DMZs), typically implemented with boundary control devices and techniques including routers, gateways, firewalls, virtualization, or cloud-based technologies. NIST Special Publications 800-41 and 800-125B provide related guidance.&lt;br /&gt;
&lt;br /&gt;
;3.13.6: Deny network communications traffic by default and allow network communications traffic by exception (i.e., deny all, permit by exception).&lt;br /&gt;
:&#039;&#039;&#039;Discussion:&#039;&#039;&#039; This requirement applies to inbound and outbound network communications traffic at the system boundary and at identified points within the system. A deny-all, permit-by-exception policy ensures that only essential and approved connections are allowed.&lt;br /&gt;
&lt;br /&gt;
;3.13.7: Prevent remote devices from simultaneously establishing non-remote connections with organizational systems and communicating via some other connection to resources in external networks (i.e., split tunneling).&lt;br /&gt;
:&#039;&#039;&#039;Discussion:&#039;&#039;&#039; Split tunneling might be desirable for remote users to communicate with local system resources such as printers or file servers, but it allows unauthorized external connections, making the system more vulnerable to attack and exfiltration. This requirement is implemented in remote devices through configuration settings that disable split tunneling and prevent users from readily reconfiguring them, and in the system by detecting split tunneling on the remote device and prohibiting the connection if detected.&lt;br /&gt;
&lt;br /&gt;
;3.13.8: Implement cryptographic mechanisms to prevent unauthorized disclosure of CUI during transmission unless otherwise protected by alternative physical safeguards.&lt;br /&gt;
:&#039;&#039;&#039;Discussion:&#039;&#039;&#039; This requirement applies to internal and external networks and any system components that can transmit information, including servers, notebook and desktop computers, mobile devices, printers, copiers, scanners, and facsimile machines. Communication paths outside the physical protection of controlled boundaries are susceptible to interception and modification. Organizations relying on commercial providers offering transmission as a commodity service rather than a dedicated service may find it difficult to obtain the necessary assurances, and in such cases implement compensating safeguards or explicitly accept the additional risk. An example of an alternative physical safeguard is a protected distribution system (PDS), where the distribution medium is protected against electronic or physical intercept.&lt;br /&gt;
&lt;br /&gt;
;3.13.9: Terminate network connections associated with communications sessions at the end of the sessions or after a defined period of inactivity.&lt;br /&gt;
:&#039;&#039;&#039;Discussion:&#039;&#039;&#039; This requirement applies to internal and external networks. Terminating network connections includes de-allocating associated TCP/IP address or port pairs at the operating system level, or de-allocating networking assignments at the application level if multiple application sessions share a single operating-system-level network connection. Organizations may establish time periods of inactivity by type of network access or for specific network accesses.&lt;br /&gt;
&lt;br /&gt;
;3.13.10: Establish and manage cryptographic keys for cryptography employed in organizational systems.&lt;br /&gt;
:&#039;&#039;&#039;Discussion:&#039;&#039;&#039; Cryptographic key management and establishment can be performed using manual procedures or mechanisms supported by manual procedures. Organizations define key management requirements in accordance with applicable federal laws, executive orders, policies, directives, regulations, and standards. NIST Special Publications 800-56A and 800-57 Part 1 provide guidance on cryptographic key management and establishment.&lt;br /&gt;
&lt;br /&gt;
;3.13.11: Employ FIPS-validated cryptography when used to protect the confidentiality of CUI.&lt;br /&gt;
:&#039;&#039;&#039;Discussion:&#039;&#039;&#039; Cryptography can support many security solutions, including protecting CUI, providing digital signatures, enforcing information separation, and supporting random number and hash generation. Cryptographic standards include FIPS-validated cryptography and/or NSA-approved cryptography.&lt;br /&gt;
&lt;br /&gt;
;3.13.12: Prohibit remote activation of collaborative computing devices and provide indication of devices in use to users present at the device.&amp;lt;ref&amp;gt;Dedicated video conferencing systems, which rely on one of the participants calling or connecting to the other party to activate the video conference, are excluded.&amp;lt;/ref&amp;gt;&lt;br /&gt;
:&#039;&#039;&#039;Discussion:&#039;&#039;&#039; Collaborative computing devices include networked white boards, cameras, and microphones. Indication of use includes signals to users when such devices are activated.&lt;br /&gt;
&lt;br /&gt;
;3.13.13: Control and monitor the use of mobile code.&lt;br /&gt;
:&#039;&#039;&#039;Discussion:&#039;&#039;&#039; Mobile code technologies include Java, JavaScript, ActiveX, Postscript, PDF, Flash animations, and VBScript. Decisions on the use of mobile code are based on its potential to cause damage if used maliciously; usage restrictions apply both to mobile code installed on servers and to code downloaded and executed on individual workstations, notebook computers, and devices. Mobile code policy and procedures address controlling or preventing the development, acquisition, or introduction of unacceptable mobile code, including requiring mobile code to be digitally signed by a trusted source. NIST Special Publication 800-28 provides guidance on mobile code.&lt;br /&gt;
&lt;br /&gt;
;3.13.14: Control and monitor the use of Voice over Internet Protocol (VoIP) technologies.&lt;br /&gt;
:&#039;&#039;&#039;Discussion:&#039;&#039;&#039; VoIP has different requirements, features, functionality, availability, and service limitations compared with plain old telephone service (POTS). To address VoIP-related threats — which are similar to those inherent in any Internet-based application — usage restrictions and implementation guidelines are based on the technology&#039;s potential to cause damage if used maliciously. NIST Special Publication 800-58 provides guidance on VoIP systems.&lt;br /&gt;
&lt;br /&gt;
;3.13.15: Protect the authenticity of communications sessions.&lt;br /&gt;
:&#039;&#039;&#039;Discussion:&#039;&#039;&#039; Authenticity protection includes protecting against man-in-the-middle attacks, session hijacking, and the insertion of false information into communications sessions. This requirement addresses communications protection at the session level (as opposed to the packet level) and establishes confidence at both ends of a session in the ongoing identity of the other party and the validity of information transmitted. NIST Special Publications 800-77, 800-95, and 800-113 provide guidance on secure communications sessions.&lt;br /&gt;
&lt;br /&gt;
;3.13.16: Protect the confidentiality of CUI at rest.&lt;br /&gt;
:&#039;&#039;&#039;Discussion:&#039;&#039;&#039; Information at rest refers to the state of information when it is not in process or in transit and is located on storage devices as specific components of systems. Protection focuses on the state of the information rather than the type of storage device or frequency of access. Organizations can use mechanisms such as cryptography and file share scanning to achieve confidentiality protection, and may also use secure off-line storage or continuous monitoring to identify malicious code at rest.&lt;br /&gt;
&lt;br /&gt;
=== 3.14 System and Information Integrity ===&lt;br /&gt;
==== Basic Security Requirements ====&lt;br /&gt;
;3.14.1: Identify, report, and correct system flaws in a timely manner.&lt;br /&gt;
:&#039;&#039;&#039;Discussion:&#039;&#039;&#039; Organizations identify systems affected by announced software and firmware flaws, including potential vulnerabilities resulting from those flaws, and report this information to designated personnel with information security responsibilities. Security-relevant updates include patches, service packs, hot fixes, and anti-virus signatures. Organizations address flaws discovered during security assessments, continuous monitoring, incident response activities, and system error handling, and can take advantage of resources such as the Common Weakness Enumeration (CWE) and Common Vulnerabilities and Exposures (CVE) databases. Organization-defined time periods for updating security-relevant software and firmware may vary based on factors such as the criticality of the update, and some remediation may require more testing than others. NIST Special Publication 800-40 provides guidance on patch management technologies.&lt;br /&gt;
&lt;br /&gt;
;3.14.2: Provide protection from malicious code at designated locations within organizational systems.&lt;br /&gt;
:&#039;&#039;&#039;Discussion:&#039;&#039;&#039; Designated locations include system entry and exit points, which may include firewalls, remote-access servers, workstations, electronic mail servers, web servers, proxy servers, notebook computers, and mobile devices. Malicious code includes viruses, worms, Trojan horses, and spyware, and can be encoded in various formats, contained within compressed or hidden files, or hidden using techniques such as steganography; it can be inserted via web accesses, email and attachments, and portable storage devices, typically through the exploitation of system vulnerabilities.&lt;br /&gt;
&lt;br /&gt;
Malicious code protection mechanisms include anti-virus signature definitions and reputation-based technologies. Pervasive configuration management and comprehensive software integrity controls may be effective in preventing execution of unauthorized code. Malicious code may also be present in custom-built software (e.g., logic bombs, back doors), which traditional protection mechanisms cannot always detect; in these situations organizations rely on secure coding practices, configuration management and control, trusted procurement processes, and monitoring practices. NIST Special Publication 800-83 provides guidance on malware incident prevention.&lt;br /&gt;
&lt;br /&gt;
;3.14.3: Monitor system security alerts and advisories and take action in response.&lt;br /&gt;
:&#039;&#039;&#039;Discussion:&#039;&#039;&#039; There are many publicly available sources of system security alerts and advisories, for example the Department of Homeland Security&#039;s Cybersecurity and Infrastructure Security Agency (CISA), which generates alerts and advisories to maintain situational awareness across the federal government and nonfederal organizations. Software vendors, subscription services, and industry information sharing and analysis centers (ISACs) may also provide alerts and advisories. Response actions can include notifying relevant external organizations, such as mission/business partners, supply chain partners, external service providers, and peer or supporting organizations. NIST Special Publication 800-161 provides guidance on supply chain risk management.&lt;br /&gt;
&lt;br /&gt;
==== Derived Security Requirements ====&lt;br /&gt;
;3.14.4: Update malicious code protection mechanisms when new releases are available.&lt;br /&gt;
:&#039;&#039;&#039;Discussion:&#039;&#039;&#039; Malicious code protection mechanisms include anti-virus signature definitions and reputation-based technologies. As with 3.14.2, pervasive configuration management and comprehensive software integrity controls help prevent execution of unauthorized code, including custom-built malicious code that traditional mechanisms cannot always detect, in which case organizations rely on secure coding practices, configuration management, trusted procurement, and monitoring.&lt;br /&gt;
&lt;br /&gt;
;3.14.5: Perform periodic scans of organizational systems and real-time scans of files from external sources as files are downloaded, opened, or executed.&lt;br /&gt;
:&#039;&#039;&#039;Discussion:&#039;&#039;&#039; Periodic and real-time scans can detect malicious code, which can be encoded in various formats, contained within compressed or hidden files, or hidden using techniques such as steganography, and inserted through web accesses, email and attachments, or portable storage devices via the exploitation of system vulnerabilities.&lt;br /&gt;
&lt;br /&gt;
;3.14.6: Monitor organizational systems, including inbound and outbound communications traffic, to detect attacks and indicators of potential attacks.&lt;br /&gt;
:&#039;&#039;&#039;Discussion:&#039;&#039;&#039; System monitoring includes external monitoring (observation of events at the system boundary, part of perimeter defense and boundary protection) and internal monitoring (observation of events within the system). Organizations can monitor systems by observing audit record activities in real time or by observing access patterns and other actions, using tools such as intrusion detection and prevention systems, malicious code protection software, scanning tools, audit record monitoring software, and network monitoring software. Strategic locations for monitoring devices include selected perimeter locations and near server farms supporting critical applications.&lt;br /&gt;
&lt;br /&gt;
System monitoring is an integral part of continuous monitoring and incident response programs. Unusual or unauthorized activities or conditions related to inbound/outbound communications traffic include internal traffic indicating the presence of malicious code, unauthorized exporting of information, or signaling to external systems; evidence of malicious code is used to identify potentially compromised systems or components. NIST Special Publication 800-94 provides guidance on intrusion detection and prevention systems.&lt;br /&gt;
&lt;br /&gt;
;3.14.7: Identify unauthorized use of organizational systems.&lt;br /&gt;
:&#039;&#039;&#039;Discussion:&#039;&#039;&#039; System monitoring, comprising external and internal monitoring, can detect unauthorized use of organizational systems and is an integral part of continuous monitoring and incident response programs, achieved through tools such as intrusion detection and prevention systems, malicious code protection software, scanning tools, audit record monitoring software, and network monitoring software. Unusual/unauthorized activities or conditions related to communications traffic include internal traffic indicating malicious code, unauthorized exporting of information, or signaling to external systems. NIST Special Publication 800-94 provides guidance on intrusion detection and prevention systems.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;references/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Appendix A: References ==&lt;br /&gt;
&#039;&#039;Laws, executive orders, regulations, instructions, standards, and guidelines. References in this section without specific publication dates or revision numbers are assumed to refer to the most recent updates to those publications.&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
=== Laws And Executive Orders ===&lt;br /&gt;
; [ATOM54]&lt;br /&gt;
: Atomic Energy Act (P.L. 83-703), August 1954.&lt;br /&gt;
&lt;br /&gt;
; [FOIA96]&lt;br /&gt;
: Freedom of Information Act (FOIA), 5 U.S.C. § 552, As Amended By Public Law No. 104-231, 110 Stat. 3048, Electronic Freedom of Information Act Amendments of 1996. https://www.govinfo.gov/app/details/STATUTE-68/STATUTE-68-Pg919 https://www.govinfo.gov/app/details/PLAW-104publ231&lt;br /&gt;
&lt;br /&gt;
; [FISMA]&lt;br /&gt;
: Federal Information Security Modernization Act (P.L. 113-283), December 2014. https://www.govinfo.gov/app/details/PLAW-113publ283&lt;br /&gt;
&lt;br /&gt;
; [40 USC 11331]&lt;br /&gt;
: Title 40 U.S. Code, Sec. 11331, Responsibilities for Federal information systems standards. 2017 ed. https://www.govinfo.gov/app/details/USCODE-2017-title40/USCODE-2017-title40subtitleIII-chap113-subchapIII-sec11331&lt;br /&gt;
&lt;br /&gt;
; [44 USC 3502]&lt;br /&gt;
: Title 44 U.S. Code, Sec. 3502, Definitions. 2017 ed.&lt;br /&gt;
&lt;br /&gt;
; [44 USC 3552]&lt;br /&gt;
: Title 44 U.S. Code, Sec. 3552, Definitions. 2017 ed.&lt;br /&gt;
&lt;br /&gt;
; [44 USC 3554]&lt;br /&gt;
: Title 44 U.S. Code, Sec. 3554, Federal agency responsibilities. 2017 ed.&lt;br /&gt;
&lt;br /&gt;
; [EO 13526]&lt;br /&gt;
: Executive Order 13526 (2009) Classified National Security Information. (The White House, Washington, DC), DCPD-200901022, December 29, 2009. https://www.govinfo.gov/app/details/USCODE-2017-title44/USCODE-2017-title44chap35-subchapI-sec3502 https://www.govinfo.gov/app/details/USCODE-2017-title44/USCODE-2017-title44chap35-subchapII-sec3552 https://www.govinfo.gov/app/details/USCODE-2017-title44/USCODE-2017-title44chap35-subchapII-sec3554 https://www.govinfo.gov/app/details/DCPD-200901022&lt;br /&gt;
&lt;br /&gt;
; [EO 13556]&lt;br /&gt;
: Executive Order 13556 (2010) Controlled Unclassified Information. (The White House, Washington, DC), DCPD-201000942, November 4, 2010. https://www.govinfo.gov/app/details/DCPD-201000942&lt;br /&gt;
&lt;br /&gt;
=== Policies, Regulations, Directives, And Instructions ===&lt;br /&gt;
; [32 CFR 2002]&lt;br /&gt;
: 32 CFR Part 2002, Controlled Unclassified Information, September 2016. https://www.govinfo.gov/app/details/CFR-2017-title32-vol6/CFR-2017-title32vol6-part2002/summary&lt;br /&gt;
&lt;br /&gt;
; [OMB A-130]&lt;br /&gt;
: Office of Management and Budget (2016) Managing Information as a Strategic Resource. (The White House, Washington, DC), OMB Circular A130, July 2016. https://www.whitehouse.gov/sites/whitehouse.gov/files/omb/circulars/A130/a130revised.pdf&lt;br /&gt;
&lt;br /&gt;
; [CNSSI 4009]&lt;br /&gt;
: Committee on National Security Systems (2015) Committee on National Security Systems (CNSS) Glossary. (National Security Agency, Fort George G. Meade, MD), CNSS Instruction 4009. https://www.cnss.gov/CNSS/issuances/Instructions.cfm&lt;br /&gt;
&lt;br /&gt;
=== Standards, Guidelines, And Reports ===&lt;br /&gt;
; [ISO 27001]&lt;br /&gt;
: International Organization for Standardization/International Electrotechnical Commission (2013) Information Technology—Security techniques— Information security management systems—Requirements. (International Organization for Standardization, Geneva, Switzerland), ISO/IEC 27001:2013. https://www.iso.org/standard/54534.html&lt;br /&gt;
&lt;br /&gt;
; [FIPS 199]&lt;br /&gt;
: National Institute of Standards and Technology (2004) Standards for Security Categorization of Federal Information and Information Systems. (U.S. Department of Commerce, Washington, DC), Federal Information Processing Standards Publication (FIPS) 199. https://doi.org/10.6028/NIST.FIPS.199&lt;br /&gt;
&lt;br /&gt;
; [FIPS 200]&lt;br /&gt;
: National Institute of Standards and Technology (2006) Minimum Security Requirements for Federal Information and Information Systems. (U.S. Department of Commerce, Washington, DC), Federal Information Processing Standards Publication (FIPS) 200. https://doi.org/10.6028/NIST.FIPS.200&lt;br /&gt;
&lt;br /&gt;
; [SP 800-18]&lt;br /&gt;
: Swanson MA, Hash J, Bowen P (2006) Guide for Developing Security Plans for Federal Information Systems. (National Institute of Standards and Technology, Gaithersburg, MD), NIST Special Publication (SP) 800-18, Rev. 1. https://doi.org/10.6028/NIST.SP.800-18r1&lt;br /&gt;
&lt;br /&gt;
; [SP 800-28]&lt;br /&gt;
: Jansen W, Winograd T, Scarfone KA (2008) Guidelines on Active Content and Mobile Code. (National Institute of Standards and Technology, Gaithersburg, MD), NIST Special Publication (SP) 800-28, Version 2. https://doi.org/10.6028/NIST.SP.800-28ver2&lt;br /&gt;
&lt;br /&gt;
; [SP 800-30]&lt;br /&gt;
: Joint Task Force Transformation Initiative (2012) Guide for Conducting Risk Assessments. (National Institute of Standards and Technology, Gaithersburg, MD), NIST Special Publication (SP) 800-30, Rev. 1. https://doi.org/10.6028/NIST.SP.800-30r1&lt;br /&gt;
&lt;br /&gt;
; [SP 800-39]&lt;br /&gt;
: Joint Task Force Transformation Initiative (2011) Managing Information Security Risk: Organization, Mission, and Information System View. (National Institute of Standards and Technology, Gaithersburg, MD), NIST Special Publication (SP) 800-39. https://doi.org/10.6028/NIST.SP.800-39&lt;br /&gt;
&lt;br /&gt;
; [SP 800-40]&lt;br /&gt;
: Souppaya MP, Scarfone KA (2013) Guide to Enterprise Patch Management Technologies. (National Institute of Standards and Technology, Gaithersburg, MD), NIST Special Publication (SP) 800-40, Rev. 3. https://doi.org/10.6028/NIST.SP.800-40r3&lt;br /&gt;
&lt;br /&gt;
; [SP 800-41]&lt;br /&gt;
: Scarfone KA, Hoffman P (2009) Guidelines on Firewalls and Firewall Policy. (National Institute of Standards and Technology, Gaithersburg, MD), NIST Special Publication (SP) 800-41, Rev. 1. https://doi.org/10.6028/NIST.SP.800-41r1&lt;br /&gt;
&lt;br /&gt;
; [SP 800-46]&lt;br /&gt;
: Souppaya MP, Scarfone KA (2016) Guide to Enterprise Telework, Remote Access, and Bring Your Own Device (BYOD) Security. (National Institute of Standards and Technology, Gaithersburg, MD), NIST Special Publication (SP) 800-46, Rev. 2. https://doi.org/10.6028/NIST.SP.800-46r2&lt;br /&gt;
&lt;br /&gt;
; [SP 800-50]&lt;br /&gt;
: Wilson M, Hash J (2003) Building an Information Technology Security Awareness and Training Program. (National Institute of Standards and Technology, Gaithersburg, MD), NIST Special Publication (SP) 800-50. https://doi.org/10.6028/NIST.SP.800-50&lt;br /&gt;
&lt;br /&gt;
; [SP 800-53]&lt;br /&gt;
: Joint Task Force Transformation Initiative (2013) Security and Privacy Controls for Federal Information Systems and Organizations. (National Institute of Standards and Technology, Gaithersburg, MD), NIST Special Publication (SP) 800-53, Rev. 4, Includes updates as of January 22, 2015. https://doi.org/10.6028/NIST.SP.800-53r4&lt;br /&gt;
&lt;br /&gt;
; [SP 800-53A]&lt;br /&gt;
: Joint Task Force Transformation Initiative (2014) Assessing Security and Privacy Controls in Federal Information Systems and Organizations: Building Effective Assessment Plans. (National Institute of Standards and Technology, Gaithersburg, MD), NIST Special Publication (SP) 800-53A, Rev. 4, Includes updates as of December 18, 2014. https://doi.org/10.6028/NIST.SP.800-53Ar4&lt;br /&gt;
&lt;br /&gt;
; [SP 800-53B]&lt;br /&gt;
: Control Baselines and Tailoring Guidance for Federal Information Systems and Organizations. (National Institute of Standards and Technology, Gaithersburg, MD), Draft NIST Special Publication (SP) 800-53B. [Forthcoming].&lt;br /&gt;
&lt;br /&gt;
; [SP 800-56A]&lt;br /&gt;
: Barker EB, Chen L, Roginsky A, Vassilev A, Davis R (2018) Recommendation for Pair-Wise Key-Establishment Schemes Using Discrete Logarithm Cryptography. (National Institute of Standards and Technology, Gaithersburg, MD), NIST Special Publication (SP) 800-56A, Rev. 3. https://doi.org/10.6028/NIST.SP.800-56Ar3&lt;br /&gt;
&lt;br /&gt;
; [SP 800-57-1]&lt;br /&gt;
: Barker EB (2016) Recommendation for Key Management, Part 1: General. (National Institute of Standards and Technology, Gaithersburg, MD), NIST Special Publication (SP) 800-57 Part 1, Rev. 4. https://doi.org/10.6028/NIST.SP.800-57pt1r4&lt;br /&gt;
&lt;br /&gt;
; [SP 800-58]&lt;br /&gt;
: Kuhn R, Walsh TJ, Fries S (2005) Security Considerations for Voice Over IP Systems. (National Institute of Standards and Technology, Gaithersburg, MD), NIST Special Publication (SP) 800-58. https://doi.org/10.6028/NIST.SP.800-58&lt;br /&gt;
&lt;br /&gt;
; [SP 800-60-1]&lt;br /&gt;
: Stine KM, Kissel RL, Barker WC, Fahlsing J, Gulick J (2008) Guide for Mapping Types of Information and Information Systems to Security Categories. (National Institute of Standards and Technology, Gaithersburg, MD), NIST Special Publication (SP) 800-60, Vol. 1, Rev. 1. https://doi.org/10.6028/NIST.SP.800-60v1r1&lt;br /&gt;
&lt;br /&gt;
; [SP 800-60-2]&lt;br /&gt;
: Stine KM, Kissel RL, Barker WC, Lee A, Fahlsing J (2008) Guide for Mapping Types of Information and Information Systems to Security Categories: Appendices. (National Institute of Standards and Technology, Gaithersburg, MD), NIST Special Publication (SP) 800-60, Vol. 2, Rev. 1. https://doi.org/10.6028/NIST.SP.800-60v2r1&lt;br /&gt;
&lt;br /&gt;
; [SP 800-61]&lt;br /&gt;
: Cichonski PR, Millar T, Grance T, Scarfone KA (2012) Computer Security Incident Handling Guide. (National Institute of Standards and Technology, Gaithersburg, MD), NIST Special Publication (SP) 800-61, Rev. 2. https://doi.org/10.6028/NIST.SP.800-61r2&lt;br /&gt;
&lt;br /&gt;
; [SP 800-63-3]&lt;br /&gt;
: Grassi PA, Garcia ME, Fenton JL (2017) Digital Identity Guidelines. (National Institute of Standards and Technology, Gaithersburg, MD), NIST Special Publication (SP) 800-63-3, Includes updates as of December 1, 2017. https://doi.org/10.6028/NIST.SP.800-63-3&lt;br /&gt;
&lt;br /&gt;
; [SP 800-70]&lt;br /&gt;
: Quinn SD, Souppaya MP, Cook MR, Scarfone KA (2018) National Checklist Program for IT Products: Guidelines for Checklist Users and Developers. (National Institute of Standards and Technology, Gaithersburg, MD), NIST Special Publication (SP) 800-70, Rev. 4. https://doi.org/10.6028/NIST.SP.800-70r4&lt;br /&gt;
&lt;br /&gt;
; [SP 800-77]&lt;br /&gt;
: Frankel SE, Kent K, Lewkowski R, Orebaugh AD, Ritchey RW, Sharma SR (2005) Guide to IPsec VPNs. (National Institute of Standards and Technology, Gaithersburg, MD), NIST Special Publication (SP) 800-77. https://doi.org/10.6028/NIST.SP.800-77&lt;br /&gt;
&lt;br /&gt;
; [SP 800-83]&lt;br /&gt;
: Souppaya MP, Scarfone KA (2013) Guide to Malware Incident Prevention and Handling for Desktops and Laptops. (National Institute of Standards and Technology, Gaithersburg, MD), NIST Special Publication (SP) 800-83, Rev. 1. https://doi.org/10.6028/NIST.SP.800-83r1&lt;br /&gt;
&lt;br /&gt;
; [SP 800-84]&lt;br /&gt;
: Grance T, Nolan T, Burke K, Dudley R, White G, Good T (2006) Guide to Test, Training, and Exercise Programs for IT Plans and Capabilities. (National Institute of Standards and Technology, Gaithersburg, MD), NIST Special Publication (SP) 800-84. https://doi.org/10.6028/NIST.SP.800-84&lt;br /&gt;
&lt;br /&gt;
; [SP 800-86]&lt;br /&gt;
: Kent K, Chevalier S, Grance T, Dang H (2006) Guide to Integrating Forensic Techniques into Incident Response. (National Institute of Standards and Technology, Gaithersburg, MD), NIST Special Publication (SP) 800-86. https://doi.org/10.6028/NIST.SP.800-86&lt;br /&gt;
&lt;br /&gt;
; [SP 800-88]&lt;br /&gt;
: Kissel RL, Regenscheid AR, Scholl MA, Stine KM (2014) Guidelines for Media Sanitization. (National Institute of Standards and Technology, Gaithersburg, MD), NIST Special Publication (SP) 800-88, Rev. 1. https://doi.org/10.6028/NIST.SP.800-88r1&lt;br /&gt;
&lt;br /&gt;
; [SP 800-92]&lt;br /&gt;
: Kent K, Souppaya MP (2006) Guide to Computer Security Log Management. (National Institute of Standards and Technology, Gaithersburg, MD), NIST Special Publication (SP) 800-92. https://doi.org/10.6028/NIST.SP.800-92&lt;br /&gt;
&lt;br /&gt;
; [SP 800-94]&lt;br /&gt;
: Scarfone KA, Mell PM (2007) Guide to Intrusion Detection and Prevention Systems (IDPS). (National Institute of Standards and Technology, Gaithersburg, MD), NIST Special Publication (SP) 800-94. https://doi.org/10.6028/NIST.SP.800-94&lt;br /&gt;
&lt;br /&gt;
; [SP 800-95]&lt;br /&gt;
: Singhal A, Winograd T, Scarfone KA (2007) Guide to Secure Web Services. (National Institute of Standards and Technology, Gaithersburg, MD), NIST Special Publication (SP) 800-95. https://doi.org/10.6028/NIST.SP.800-95&lt;br /&gt;
&lt;br /&gt;
; [SP 800-97]&lt;br /&gt;
: Frankel SE, Eydt B, Owens L, Scarfone KA (2007) Establishing Wireless Robust Security Networks: A Guide to IEEE 802.11i. (National Institute of Standards and Technology, Gaithersburg, MD), NIST Special Publication (SP) 800-97. https://doi.org/10.6028/NIST.SP.800-97&lt;br /&gt;
&lt;br /&gt;
; [SP 800-101]&lt;br /&gt;
: Ayers RP, Brothers S, Jansen W (2014) Guidelines on Mobile Device Forensics. (National Institute of Standards and Technology, Gaithersburg, MD), NIST Special Publication (SP) 800-101, Rev. 1. https://doi.org/10.6028/NIST.SP.800-101r1&lt;br /&gt;
&lt;br /&gt;
; [SP 800-111]&lt;br /&gt;
: Scarfone KA, Souppaya MP, Sexton M (2007) Guide to Storage Encryption Technologies for End User Devices. (National Institute of Standards and Technology, Gaithersburg, MD), NIST Special Publication (SP) 800-111. https://doi.org/10.6028/NIST.SP.800-111&lt;br /&gt;
&lt;br /&gt;
; [SP 800-113]&lt;br /&gt;
: Frankel SE, Hoffman P, Orebaugh AD, Park R (2008) Guide to SSL VPNs. (National Institute of Standards and Technology, Gaithersburg, MD), NIST Special Publication (SP) 800-113. https://doi.org/10.6028/NIST.SP.800-113&lt;br /&gt;
&lt;br /&gt;
; [SP 800-114]&lt;br /&gt;
: Souppaya MP, Scarfone KA (2016) User&#039;s Guide to Telework and Bring Your Own Device (BYOD) Security. (National Institute of Standards and Technology, Gaithersburg, MD), NIST Special Publication (SP) 800-114, Rev. 1. https://doi.org/10.6028/NIST.SP.800-114r1&lt;br /&gt;
&lt;br /&gt;
; [SP 800-124]&lt;br /&gt;
: Souppaya MP, Scarfone KA (2013) Guidelines for Managing the Security of Mobile Devices in the Enterprise. (National Institute of Standards and Technology, Gaithersburg, MD), NIST Special Publication (SP) 800-124, Rev. 1. https://doi.org/10.6028/NIST.SP.800-124r1&lt;br /&gt;
&lt;br /&gt;
; [SP 800-125B]&lt;br /&gt;
: Chandramouli R (2016) Secure Virtual Network Configuration for Virtual Machine (VM) Protection. (National Institute of Standards and Technology, Gaithersburg, MD), NIST Special Publication (SP) 800-125B. https://doi.org/10.6028/NIST.SP.800-125B&lt;br /&gt;
&lt;br /&gt;
; [SP 800-128]&lt;br /&gt;
: Johnson LA, Dempsey KL, Ross RS, Gupta S, Bailey D (2011) Guide for Security-Focused Configuration Management of Information Systems. (National Institute of Standards and Technology, Gaithersburg, MD), NIST Special Publication (SP) 800-128. https://doi.org/10.6028/NIST.SP.800-128&lt;br /&gt;
&lt;br /&gt;
; [SP 800-137]&lt;br /&gt;
: Dempsey KL, Chawla NS, Johnson LA, Johnston R, Jones AC, Orebaugh AD, Scholl MA, Stine KM (2011) Information Security Continuous Monitoring (ISCM) for Federal Information Systems and Organizations. (National Institute of Standards and Technology, Gaithersburg, MD), NIST Special Publication (SP) 800-137. https://doi.org/10.6028/NIST.SP.800-137&lt;br /&gt;
&lt;br /&gt;
; [SP 800-160-1]&lt;br /&gt;
: Ross RS, Oren JC, McEvilley M (2016) Systems Security Engineering: Considerations for a Multidisciplinary Approach in the Engineering of Trustworthy Secure Systems. (National Institute of Standards and Technology, Gaithersburg, MD), NIST Special Publication (SP) 800-160, Vol. 1, Includes updates as of March 21, 2018. https://doi.org/10.6028/NIST.SP.800-160v1&lt;br /&gt;
&lt;br /&gt;
; [SP 800-161]&lt;br /&gt;
: Boyens JM, Paulsen C, Moorthy R, Bartol N (2015) Supply Chain Risk Management Practices for Federal Information Systems and Organizations. (National Institute of Standards and Technology, Gaithersburg, MD), NIST Special Publication (SP) 800-161. https://doi.org/10.6028/NIST.SP.800-161&lt;br /&gt;
&lt;br /&gt;
; [SP 800-167]&lt;br /&gt;
: Sedgewick A, Souppaya MP, Scarfone KA (2015) Guide to Application Whitelisting. (National Institute of Standards and Technology, Gaithersburg, MD), NIST Special Publication (SP) 800-167. https://doi.org/10.6028/NIST.SP.800-167&lt;br /&gt;
&lt;br /&gt;
; [SP 800-171A]&lt;br /&gt;
: Ross RS, Dempsey KL, Pillitteri VY (2018) Assessing Security Requirements for Controlled Unclassified Information. (National Institute of Standards and Technology, Gaithersburg, MD), NIST Special Publication (SP) 800-171A. https://doi.org/10.6028/NIST.SP.800-171A&lt;br /&gt;
&lt;br /&gt;
; [SP 800-181]&lt;br /&gt;
: Newhouse WD, Witte GA, Scribner B, Keith S (2017) National Initiative for Cybersecurity Education (NICE) Cybersecurity Workforce Framework. (National Institute of Standards and Technology, Gaithersburg, MD), NIST Special Publication (SP) 800-181. https://doi.org/10.6028/NIST.SP.800-181&lt;br /&gt;
&lt;br /&gt;
=== Miscellaneous Publications And Websites ===&lt;br /&gt;
; [IETF 5905]&lt;br /&gt;
: Mills D, Martin J (ed.), Burbank J, Kasch W (2010) Network Time Protocol Version 4: Protocol and Algorithms Specification. (Internet Engineering Task Force), IETF Request for Comments (RFC) 5905. https://doi.org/10.17487/RFC5905&lt;br /&gt;
&lt;br /&gt;
; [NARA CUI]&lt;br /&gt;
: National Archives and Records Administration (2019) Controlled Unclassified Information (CUI) Registry. https://www.archives.gov/cui&lt;br /&gt;
&lt;br /&gt;
; [NARA MARK]&lt;br /&gt;
: National Archives and Records Administration (2016) Marking Controlled Unclassified Information, Version 1.1. (National Archives, Washington, DC). https://www.archives.gov/files/cui/20161206-cui-marking-handbook-v1-1.pdf CUI Notice 2019-01, Controlled Unclassified Information Coversheets and Labels. https://www.archives.gov/files/cui/documents/20190222-cui-notice-2019-01coversheet-label.pdf&lt;br /&gt;
&lt;br /&gt;
; [NIST CAVP]&lt;br /&gt;
: National Institute of Standards and Technology (2019) Cryptographic Algorithm Validation Program. https://csrc.nist.gov/projects/cavp&lt;br /&gt;
&lt;br /&gt;
; [NIST CMVP]&lt;br /&gt;
: National Institute of Standards and Technology (2019) Cryptographic Module Validation Program. https://csrc.nist.gov/projects/cmvp&lt;br /&gt;
&lt;br /&gt;
; [NIST CRYPTO]&lt;br /&gt;
: National Institute of Standards and Technology (2019) Cryptographic Standards and Guidelines. https://csrc.nist.gov/projects/cryptographic-standards-and-guidelines&lt;br /&gt;
&lt;br /&gt;
; [NIST CSF]&lt;br /&gt;
: National Institute of Standards and Technology (2018) Framework for Improving Critical Infrastructure Cybersecurity, Version 1.1. (National Institute of Standards and Technology, Gaithersburg, MD). https://doi.org/10.6028/NIST.CSWP.04162018&lt;br /&gt;
&lt;br /&gt;
; [NIST CUI]&lt;br /&gt;
: National Institute of Standards and Technology (2019) Special Publication 800-171 Publication and Supporting Resources. https://csrc.nist.gov/publications/detail/sp/800-171/rev-1/final&lt;br /&gt;
&lt;br /&gt;
== Appendix B: Glossary ==&lt;br /&gt;
&#039;&#039;Common terms and definitions used within this publication. Unless specifically defined in this glossary, all terms are consistent with the definitions in CNSSI 4009, the &#039;&#039;National Information Assurance Glossary&#039;&#039;.&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
; advanced persistent threat&lt;br /&gt;
: An adversary that possesses sophisticated levels of expertise and significant resources which allow it to create opportunities to achieve its objectives by using multiple attack vectors including, for example, cyber, physical, and deception. These objectives typically include establishing and extending footholds within the IT infrastructure of the targeted organizations for purposes of exfiltrating information, undermining or impeding critical aspects of a mission, program, or organization; or positioning itself to carry out these objectives in the future. The advanced persistent threat pursues its objectives repeatedly over an extended period; adapts to defenders’ efforts to resist it; and is determined to maintain the level of interaction needed to execute its objectives.&lt;br /&gt;
&lt;br /&gt;
; agency&lt;br /&gt;
: Any executive agency or department, military department, Federal Government corporation, Federal Government-controlled corporation, or other establishment in the Executive Branch of the Federal Government, or any independent regulatory agency.&lt;br /&gt;
&lt;br /&gt;
; assessment&lt;br /&gt;
: See security control assessment.&lt;br /&gt;
&lt;br /&gt;
; assessor&lt;br /&gt;
: See security control assessor.&lt;br /&gt;
&lt;br /&gt;
; audit log&lt;br /&gt;
: A chronological record of system activities, including records of system accesses and operations performed in a given period.&lt;br /&gt;
&lt;br /&gt;
; audit record&lt;br /&gt;
: An individual entry in an audit log related to an audited event.&lt;br /&gt;
&lt;br /&gt;
; authentication&lt;br /&gt;
: Verifying the identity of a user, process, or device, often as a prerequisite to allowing access to resources in a system. [FIPS 200, Adapted]&lt;br /&gt;
&lt;br /&gt;
; availability&lt;br /&gt;
: Ensuring timely and reliable access to and use of information.&lt;br /&gt;
&lt;br /&gt;
; baseline configuration&lt;br /&gt;
: A documented set of specifications for a system, or a configuration item within a system, that has been formally reviewed and agreed on at a given point in time, and which can be changed only through change control procedures. [OMB A-130] [44 USC 3552] [SP 800-39]&lt;br /&gt;
&lt;br /&gt;
; bidirectional authentication&lt;br /&gt;
: Two parties authenticating each other at the same time. Also known as mutual authentication or two-way authentication.&lt;br /&gt;
&lt;br /&gt;
; blacklisting&lt;br /&gt;
: A process used to identify software programs that are not authorized to execute on a system or prohibited Universal Resource Locators (URL)/websites.&lt;br /&gt;
&lt;br /&gt;
; confidentiality&lt;br /&gt;
: Preserving authorized restrictions on information access and disclosure, including means for protecting personal privacy and proprietary information.&lt;br /&gt;
&lt;br /&gt;
; configuration management&lt;br /&gt;
: A collection of activities focused on establishing and maintaining the integrity of information technology products and systems, through control of processes for initializing, changing, and monitoring the configurations of those products and systems throughout the system development life cycle.&lt;br /&gt;
&lt;br /&gt;
; configuration settings&lt;br /&gt;
: The set of parameters that can be changed in hardware, software, or firmware that affect the security posture and/or functionality of the system.&lt;br /&gt;
&lt;br /&gt;
; controlled area&lt;br /&gt;
: Any area or space for which the organization has confidence that the physical and procedural protections provided are sufficient to meet the requirements established for protecting the information or system.&lt;br /&gt;
&lt;br /&gt;
; controlled unclassified information&lt;br /&gt;
: Information that law, regulation, or governmentwide policy requires to have safeguarding or disseminating controls, excluding information that is classified under Executive Order 13526, Classified National Security Information, December 29, 2009, or any predecessor or successor order, or the Atomic Energy Act of 1954, as amended.&lt;br /&gt;
&lt;br /&gt;
; CUI categories&lt;br /&gt;
: Those types of information for which laws, regulations, or governmentwide policies require or permit agencies to exercise safeguarding or dissemination controls, and which the CUI Executive Agent has approved and listed in the CUI Registry.&lt;br /&gt;
&lt;br /&gt;
; CUI Executive Agent&lt;br /&gt;
: The National Archives and Records Administration (NARA), which implements the executive branch-wide CUI Program and oversees federal agency actions to comply with Executive Order 13556. NARA has delegated this authority to the Director of the Information Security Oversight Office (ISOO).&lt;br /&gt;
&lt;br /&gt;
; CUI program&lt;br /&gt;
: The executive branch-wide program to standardize CUI handling by all federal agencies. The program includes the rules, organization, and procedures for CUI, established by Executive Order 13556, 32 CFR Part 2002, and the CUI Registry. [44 USC 3552] [EO 13556] [32 CFR 2002]&lt;br /&gt;
&lt;br /&gt;
; CUI registry&lt;br /&gt;
: The online repository for all information, guidance, policy, and requirements on handling CUI, including everything issued by the CUI Executive Agent other than 32 CFR Part 2002. Among other information, the CUI Registry identifies all approved CUI categories, provides general descriptions for each, identifies the basis for controls, establishes markings, and includes guidance on handling procedures.&lt;br /&gt;
&lt;br /&gt;
; cyber-physical systems&lt;br /&gt;
: Interacting digital, analog, physical, and human components engineered for function through integrated physics and logic.&lt;br /&gt;
&lt;br /&gt;
; dual authorization&lt;br /&gt;
: The system of storage and handling designed to prohibit individual access to certain resources by requiring the presence and actions of at least two authorized persons, each capable of detecting incorrect or unauthorized security procedures with respect to the task being performed.&lt;br /&gt;
&lt;br /&gt;
; executive agency&lt;br /&gt;
: An executive department specified in 5 U.S.C. Sec. 101; a military department specified in 5 U.S.C. Sec. 102; an independent establishment as defined in 5 U.S.C. Sec. 104(1); and a wholly owned Government corporation fully subject to the provisions of 31 U.S.C. Chapter 91.&lt;br /&gt;
&lt;br /&gt;
; external network&lt;br /&gt;
: A network not controlled by the organization.&lt;br /&gt;
&lt;br /&gt;
; external system (or component)&lt;br /&gt;
: A system or component of a system that is outside of the authorization boundary established by the organization and for which the organization typically has no direct control over the application of required security controls or the assessment of security control effectiveness.&lt;br /&gt;
&lt;br /&gt;
; external system service&lt;br /&gt;
: A system service that is implemented outside of the authorization boundary of the organizational system (i.e., a service that is used by, but not a part of, the organizational system) and for which the organization typically has no direct control over the application of required security controls or the assessment of security control effectiveness.&lt;br /&gt;
&lt;br /&gt;
; external system service provider&lt;br /&gt;
: A provider of external system services to an organization through a variety of consumer-producer relationships including, but not limited to: joint ventures; business partnerships; outsourcing arrangements (i.e., through contracts, interagency agreements, lines of business arrangements); licensing agreements; and/or supply chain exchanges.&lt;br /&gt;
&lt;br /&gt;
; federal agency&lt;br /&gt;
: See executive agency.&lt;br /&gt;
&lt;br /&gt;
; federal information system&lt;br /&gt;
: An information system used or operated by an executive agency, by a contractor of an executive agency, or by another organization on behalf of an executive agency. [32 CFR 2002] [CNSSI 4009, Adapted] [OMB A-130] [40 USC 11331]&lt;br /&gt;
&lt;br /&gt;
; FIPS-validated cryptography&lt;br /&gt;
: A cryptographic module validated by the Cryptographic Module Validation Program (CMVP) to meet requirements specified in FIPS Publication 140-2 (as amended). As a prerequisite to CMVP validation, the cryptographic module is required to employ a cryptographic algorithm implementation that has successfully passed validation testing by the Cryptographic Algorithm Validation Program (CAVP). See NSA-approved cryptography.&lt;br /&gt;
&lt;br /&gt;
; firmware&lt;br /&gt;
: Computer programs and data stored in hardware - typically in read-only memory (ROM) or programmable read-only memory (PROM) - such that the programs and data cannot be dynamically written or modified during execution of the programs. See hardware and software.&lt;br /&gt;
&lt;br /&gt;
; hardware&lt;br /&gt;
: The material physical components of a system. See software and firmware.&lt;br /&gt;
&lt;br /&gt;
; identifier&lt;br /&gt;
: Unique data used to represent a person’s identity and associated attributes. A name or a card number are examples of identifiers. A unique label used by a system to indicate a specific entity, object, or group.&lt;br /&gt;
&lt;br /&gt;
; impact&lt;br /&gt;
: With respect to security, the effect on organizational operations, organizational assets, individuals, other organizations, or the Nation (including the national security interests of the United States) of a loss of confidentiality, integrity, or availability of information or a system. With respect to privacy, the adverse effects that individuals could experience when an information system processes their PII.&lt;br /&gt;
&lt;br /&gt;
; impact value&lt;br /&gt;
: The assessed worst-case potential impact that could result from a compromise of the confidentiality, integrity, or availability of information expressed as a value of low, moderate or high.&lt;br /&gt;
&lt;br /&gt;
; incident&lt;br /&gt;
: An occurrence that actually or imminently jeopardizes, without lawful authority, the confidentiality, integrity, or availability of information or an information system; or constitutes a violation or imminent threat of violation of law, security policies, security procedures, or acceptable use policies.&lt;br /&gt;
&lt;br /&gt;
; information&lt;br /&gt;
: Any communication or representation of knowledge such as facts, data, or opinions in any medium or form, including textual, numerical, graphic, cartographic, narrative, electronic, or audiovisual forms.&lt;br /&gt;
&lt;br /&gt;
; information flow control&lt;br /&gt;
: Procedure to ensure that information transfers within a system are not made in violation of the security policy.&lt;br /&gt;
&lt;br /&gt;
; information resources&lt;br /&gt;
: Information and related resources, such as personnel, equipment, funds, and information technology. [CNSSI 4009] [FIPS 199] [44 USC 3552] [OMB A-130] [44 USC 3502]&lt;br /&gt;
&lt;br /&gt;
; information security&lt;br /&gt;
: The protection of information and systems from unauthorized access, use, disclosure, disruption, modification, or destruction in order to provide confidentiality, integrity, and availability.&lt;br /&gt;
&lt;br /&gt;
; information system&lt;br /&gt;
: A discrete set of information resources organized for the collection, processing, maintenance, use, sharing, dissemination, or disposition of information.&lt;br /&gt;
&lt;br /&gt;
; information technology&lt;br /&gt;
: Any services, equipment, or interconnected system(s) or subsystem(s) of equipment, that are used in the automatic acquisition, storage, analysis, evaluation, manipulation, management, movement, control, display, switching, interchange, transmission, or reception of data or information by the agency. For purposes of this definition, such services or equipment if used by the agency directly or is used by a contractor under a contract with the agency that requires its use; or to a significant extent, its use in the performance of a service or the furnishing of a product. Information technology includes computers, ancillary equipment (including imaging peripherals, input, output, and storage devices necessary for security and surveillance), peripheral equipment designed to be controlled by the central processing unit of a computer, software, firmware and similar procedures, services (including cloud computing and help-desk services or other professional services which support any point of the life cycle of the equipment or service), and related resources. Information technology does not include any equipment that is acquired by a contractor incidental to a contract which does not require its use.&lt;br /&gt;
&lt;br /&gt;
; insider threat&lt;br /&gt;
: The threat that an insider will use her/his authorized access, wittingly or unwittingly, to do harm to the security of the United States. This threat can include damage to the United States through espionage, terrorism, unauthorized disclosure, or through the loss or degradation of departmental resources or capabilities.&lt;br /&gt;
&lt;br /&gt;
; integrity&lt;br /&gt;
: Guarding against improper information modification or destruction, and includes ensuring information non-repudiation and authenticity.&lt;br /&gt;
&lt;br /&gt;
; internal network&lt;br /&gt;
: A network where establishment, maintenance, and provisioning of security controls are under the direct control of organizational employees or contractors; or the cryptographic encapsulation or similar security technology implemented between organizationcontrolled endpoints, provides the same effect (with regard to confidentiality and integrity). An internal network is typically organization-owned, yet may be organization-controlled while not being organization-owned. [44 USC 3552] [44 USC 3502] [OMB A-130]&lt;br /&gt;
&lt;br /&gt;
; least privilege&lt;br /&gt;
: The principle that a security architecture is designed so that each entity is granted the minimum system authorizations and resources that the entity needs to perform its function.&lt;br /&gt;
&lt;br /&gt;
; local access&lt;br /&gt;
: Access to an organizational system by a user (or process acting on behalf of a user) communicating through a direct connection without the use of a network.&lt;br /&gt;
&lt;br /&gt;
; malicious code&lt;br /&gt;
: Software or firmware intended to perform an unauthorized process that will have adverse impact on the confidentiality, integrity, or availability of a system. A virus, worm, Trojan horse, or other code-based entity that infects a host. Spyware and some forms of adware are also examples of malicious code.&lt;br /&gt;
&lt;br /&gt;
; media&lt;br /&gt;
: Physical devices or writing surfaces including, but not limited to, magnetic tapes, optical disks, magnetic disks, Large-Scale Integration (LSI) memory chips, and printouts (but not including display media) onto which information is recorded, stored, or printed within a system.&lt;br /&gt;
&lt;br /&gt;
; mobile code&lt;br /&gt;
: Software programs or parts of programs obtained from remote systems, transmitted across a network, and executed on a local system without explicit installation or execution by the recipient.&lt;br /&gt;
&lt;br /&gt;
; mobile device&lt;br /&gt;
: A portable computing device that has a small form factor such that it can easily be carried by a single individual; is designed to operate without a physical connection (e.g., wirelessly transmit or receive information); possesses local, nonremovable/removable data storage; and includes a selfcontained power source. Mobile devices may also include voice communication capabilities, on-board sensors that allow the devices to capture information, or built-in features that synchronize local data with remote locations. Examples include smartphones, tablets, and E-readers.&lt;br /&gt;
&lt;br /&gt;
; multifactor authentication&lt;br /&gt;
: Authentication using two or more different factors to achieve authentication. Factors include something you know (e.g., PIN, password); something you have (e.g., cryptographic identification device, token); or something you are (e.g., biometric). See authenticator.&lt;br /&gt;
&lt;br /&gt;
; mutual authentication [CNSSI 4009]&lt;br /&gt;
: The process of both entities involved in a transaction verifying each other. See bidirectional authentication.&lt;br /&gt;
&lt;br /&gt;
; network&lt;br /&gt;
: A system implemented with a collection of interconnected components. Such components may include routers, hubs, cabling, telecommunications controllers, key distribution centers, and technical control devices. [FIPS 200]&lt;br /&gt;
&lt;br /&gt;
; network access&lt;br /&gt;
: Access to a system by a user (or a process acting on behalf of a user) communicating through a network (e.g., local area network, wide area network, Internet).&lt;br /&gt;
&lt;br /&gt;
; nonfederal organization&lt;br /&gt;
: An entity that owns, operates, or maintains a nonfederal system.&lt;br /&gt;
&lt;br /&gt;
; nonfederal system&lt;br /&gt;
: A system that does not meet the criteria for a federal system.&lt;br /&gt;
&lt;br /&gt;
; nonlocal maintenance&lt;br /&gt;
: Maintenance activities conducted by individuals communicating through a network, either an external network (e.g., the Internet) or an internal network.&lt;br /&gt;
&lt;br /&gt;
; on behalf of (an agency)&lt;br /&gt;
: A situation that occurs when: (i) a non-executive branch entity uses or operates an information system or maintains or collects information for the purpose of processing, storing, or transmitting Federal information; and (ii) those activities are not incidental to providing a service or product to the government.&lt;br /&gt;
&lt;br /&gt;
; organization&lt;br /&gt;
: An entity of any size, complexity, or positioning within an organizational structure.&lt;br /&gt;
&lt;br /&gt;
; personnel security&lt;br /&gt;
: The discipline of assessing the conduct, integrity, judgment, loyalty, reliability, and stability of individuals for duties and responsibilities requiring trustworthiness.&lt;br /&gt;
&lt;br /&gt;
; portable storage device&lt;br /&gt;
: A system component that can be inserted into and removed from a system, and that is used to store data or information (e.g., text, video, audio, and/or image data). Such components are typically implemented on magnetic, optical, or solid-state devices (e.g., floppy disks, compact/digital video disks, flash/thumb drives, external hard disk drives, and flash memory cards/drives that contain nonvolatile memory).&lt;br /&gt;
&lt;br /&gt;
; potential impact&lt;br /&gt;
: The loss of confidentiality, integrity, or availability could be expected to have: (i) a limited adverse effect (FIPS Publication 199 low); (ii) a serious adverse effect (FIPS Publication 199 moderate); or (iii) a severe or catastrophic adverse effect (FIPS Publication 199 high) on organizational operations, organizational assets, or individuals.&lt;br /&gt;
&lt;br /&gt;
; privileged account&lt;br /&gt;
: A system account with authorizations of a privileged user.&lt;br /&gt;
&lt;br /&gt;
; privileged user&lt;br /&gt;
: A user that is authorized (and therefore, trusted) to perform security-relevant functions that ordinary users are not authorized to perform.&lt;br /&gt;
&lt;br /&gt;
; records&lt;br /&gt;
: The recordings (automated and/or manual) of evidence of activities performed or results achieved (e.g., forms, reports, test results), which serve as a basis for verifying that the organization and the system are performing as intended. Also used to refer to units of related data fields (i.e., groups of data fields that can be accessed by a program and that contain the complete set of information on particular items).&lt;br /&gt;
&lt;br /&gt;
; remote access&lt;br /&gt;
: Access to an organizational system by a user (or a process acting on behalf of a user) communicating through an external network (e.g., the Internet). [32 CFR 2002] [FIPS 200, Adapted] [SP 800-53] [FIPS 199]&lt;br /&gt;
&lt;br /&gt;
; remote maintenance&lt;br /&gt;
: Maintenance activities conducted by individuals communicating through an external network (e.g., the Internet).&lt;br /&gt;
&lt;br /&gt;
; replay resistance&lt;br /&gt;
: Protection against the capture of transmitted authentication or access control information and its subsequent retransmission with the intent of producing an unauthorized effect or gaining unauthorized access.&lt;br /&gt;
&lt;br /&gt;
; risk&lt;br /&gt;
: A measure of the extent to which an entity is threatened by a potential circumstance or event, and typically is a function of: (i) the adverse impact, or magnitude of harm, that would arise if the circumstance or event occurs; and (ii) the likelihood of occurrence.&lt;br /&gt;
&lt;br /&gt;
; risk assessment&lt;br /&gt;
: The process of identifying risks to organizational operations (including mission, functions, image, reputation), organizational assets, individuals, other organizations, and the Nation, resulting from the operation of a system.&lt;br /&gt;
&lt;br /&gt;
; sanitization&lt;br /&gt;
: Actions taken to render data written on media unrecoverable by both ordinary and, for some forms of sanitization, extraordinary means. Process to remove information from media such that data recovery is not possible. It includes removing all classified labels, markings, and activity logs.&lt;br /&gt;
&lt;br /&gt;
; security&lt;br /&gt;
: A condition that results from the establishment and maintenance of protective measures that enable an organization to perform its mission or critical functions despite risks posed by threats to its use of systems. Protective measures may involve a combination of deterrence, avoidance, prevention, detection, recovery, and correction that should form part of the organization’s risk management approach.&lt;br /&gt;
&lt;br /&gt;
; security assessment&lt;br /&gt;
: See security control assessment.&lt;br /&gt;
&lt;br /&gt;
; security control&lt;br /&gt;
: The safeguards or countermeasures prescribed for an information system or an organization to protect the confidentiality, integrity, and availability of the system and its information.&lt;br /&gt;
&lt;br /&gt;
; security control assessment&lt;br /&gt;
: The testing or evaluation of security controls to determine the extent to which the controls are implemented correctly, operating as intended, and producing the desired outcome with respect to meeting the security requirements for an information system or organization.&lt;br /&gt;
&lt;br /&gt;
; security domain&lt;br /&gt;
: A domain that implements a security policy and is administered by a single authority.&lt;br /&gt;
&lt;br /&gt;
; security functions&lt;br /&gt;
: The hardware, software, or firmware of the system responsible for enforcing the system security policy and supporting the isolation of code and data on which the protection is based. [OMB A-130] [SP 800-30] [CNSSI 4009] [CNSSI 4009, Adapted]&lt;br /&gt;
&lt;br /&gt;
; split tunneling&lt;br /&gt;
: The process of allowing a remote user or device to establish a non-remote connection with a system and simultaneously communicate via some other connection to a resource in an external network. This method of network access enables a user to access remote devices (e.g., a networked printer) at the same time as accessing uncontrolled networks.&lt;br /&gt;
&lt;br /&gt;
; system&lt;br /&gt;
: See information system.&lt;br /&gt;
&lt;br /&gt;
; system component&lt;br /&gt;
: A discrete identifiable information technology asset that represents a building block of a system and may include hardware, software, and firmware.&lt;br /&gt;
&lt;br /&gt;
; system security plan&lt;br /&gt;
: A document that describes how an organization meets the security requirements for a system or how an organization plans to meet the requirements. In particular, the system security plan describes the system boundary; the environment in which the system operates; how the security requirements are implemented; and the relationships with or connections to other systems.&lt;br /&gt;
&lt;br /&gt;
; system service&lt;br /&gt;
: A capability provided by a system that facilitates information processing, storage, or transmission.&lt;br /&gt;
&lt;br /&gt;
; system user&lt;br /&gt;
: Individual, or (system) process acting on behalf of an individual, authorized to access a system.&lt;br /&gt;
&lt;br /&gt;
; threat&lt;br /&gt;
: Any circumstance or event with the potential to adversely impact organizational operations, organizational assets, individuals, other organizations, or the Nation through a system via unauthorized access, destruction, disclosure, modification of information, and/or denial of service.&lt;br /&gt;
&lt;br /&gt;
; whitelisting&lt;br /&gt;
: A process used to identify software programs that are authorized to execute on a system or authorized Universal Resource Locators (URL)/websites.&lt;br /&gt;
&lt;br /&gt;
; wireless technology&lt;br /&gt;
: Technology that permits the transfer of information between separated points without physical connection. Wireless technologies include microwave, packet radio (ultra-high frequency or very high frequency), 802.11x, and Bluetooth. [SP 800-128] [SP 800-30]&lt;br /&gt;
&lt;br /&gt;
== Appendix C: Acronyms ==&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Acronym !! Meaning&lt;br /&gt;
|-&lt;br /&gt;
| CFR || Code of Federal Regulations&lt;br /&gt;
|-&lt;br /&gt;
| CNSS || Committee on National Security Systems&lt;br /&gt;
|-&lt;br /&gt;
| CUI || Controlled Unclassified Information&lt;br /&gt;
|-&lt;br /&gt;
| CISA || Cybersecurity and Infrastructure Security Agency&lt;br /&gt;
|-&lt;br /&gt;
| DMZ || Demilitarized Zone&lt;br /&gt;
|-&lt;br /&gt;
| FAR || Federal Acquisition Regulation&lt;br /&gt;
|-&lt;br /&gt;
| FIPS || Federal Information Processing Standards&lt;br /&gt;
|-&lt;br /&gt;
| FISMA || Federal Information Security Modernization Act&lt;br /&gt;
|-&lt;br /&gt;
| IoT || Internet of Things&lt;br /&gt;
|-&lt;br /&gt;
| IP || Internet Protocol&lt;br /&gt;
|-&lt;br /&gt;
| ISO/IEC || International Organization for Standardization/International Electrotechnical Commission&lt;br /&gt;
|-&lt;br /&gt;
| ISOO || Information Security Oversight Office&lt;br /&gt;
|-&lt;br /&gt;
| IT || Information Technology&lt;br /&gt;
|-&lt;br /&gt;
| ITL || Information Technology Laboratory&lt;br /&gt;
|-&lt;br /&gt;
| NARA || National Archives and Records Administration&lt;br /&gt;
|-&lt;br /&gt;
| NFO || Nonfederal Organization&lt;br /&gt;
|-&lt;br /&gt;
| NIST || National Institute of Standards and Technology&lt;br /&gt;
|-&lt;br /&gt;
| OMB || Office of Management and Budget&lt;br /&gt;
|-&lt;br /&gt;
| SP || Special Publication&lt;br /&gt;
|-&lt;br /&gt;
| VoIP || Voice over Internet Protocol&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Appendix D: Mapping Tables ==&lt;br /&gt;
Appendix D provides informal mappings between the CUI security requirements in Chapter Three and the relevant security controls in NIST Special Publication 800-53, Revision 4 (the moderate security control baseline).&amp;lt;ref&amp;gt;The security controls in Tables D-1 through D-14 are taken from NIST Special Publication 800-53, Revision 4. These tables were to be updated upon publication of the draft NIST Special Publication 800-53B, which would provide an update to the moderate security control baseline consistent with NIST Special Publication 800-53, Revision 5. Changes to the moderate baseline affect future updates to the basic and derived security requirements in Chapter Three.&amp;lt;/ref&amp;gt; The original publication also cross-references each requirement to the relevant control(s) in ISO/IEC 27001:2013, Annex A; because that cross-reference spans a complex, multi-column table, it is summarized narratively below rather than reproduced cell-by-cell. Organizations that have implemented or plan to implement the NIST Framework for Improving Critical Infrastructure Cybersecurity can use the mapping of security requirements to SP 800-53 and ISO/IEC 27001 controls to locate the equivalent controls in the Categories and Subcategories associated with the Cybersecurity Framework&#039;s core functions: Identify, Protect, Detect, Respond, and Recover.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Note: this summary lists the primary NIST SP 800-53, Revision 4 control(s) associated with each requirement. Consult the original publication for the full, detailed ISO/IEC 27001 sub-control cross-references, which are organized in a multi-column table not fully reproduced here.&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
=== 3.1 Access Control ===&lt;br /&gt;
&#039;&#039;&#039;Table D-1: Mapping Access Control Requirements to Controls&#039;&#039;&#039;&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Security Requirement !! NIST SP 800-53 Relevant Security Control(s)&lt;br /&gt;
|-&lt;br /&gt;
| 3.1.1 || AC-2&lt;br /&gt;
|-&lt;br /&gt;
| 3.1.2 || AC-3&lt;br /&gt;
|-&lt;br /&gt;
| 3.1.3 || AC-4&lt;br /&gt;
|-&lt;br /&gt;
| 3.1.4 || AC-5&lt;br /&gt;
|-&lt;br /&gt;
| 3.1.5 || AC-6&lt;br /&gt;
|-&lt;br /&gt;
| 3.1.6 || AC-6(2)&lt;br /&gt;
|-&lt;br /&gt;
| 3.1.7 || AC-6(9), AC-6(10)&lt;br /&gt;
|-&lt;br /&gt;
| 3.1.8 || AC-7&lt;br /&gt;
|-&lt;br /&gt;
| 3.1.9 || AC-8&lt;br /&gt;
|-&lt;br /&gt;
| 3.1.10 || AC-11, AC-11(1)&lt;br /&gt;
|-&lt;br /&gt;
| 3.1.11 || AC-12&lt;br /&gt;
|-&lt;br /&gt;
| 3.1.12 || AC-17(1)&lt;br /&gt;
|-&lt;br /&gt;
| 3.1.13 || AC-17(2)&lt;br /&gt;
|-&lt;br /&gt;
| 3.1.14 || AC-17(3)&lt;br /&gt;
|-&lt;br /&gt;
| 3.1.15 || AC-17(4)&lt;br /&gt;
|-&lt;br /&gt;
| 3.1.16 || AC-18&lt;br /&gt;
|-&lt;br /&gt;
| 3.1.17 || AC-18(1)&lt;br /&gt;
|-&lt;br /&gt;
| 3.1.18 || AC-19&lt;br /&gt;
|-&lt;br /&gt;
| 3.1.19 || AC-19(5)&lt;br /&gt;
|-&lt;br /&gt;
| 3.1.20 || AC-20, AC-20(1)&lt;br /&gt;
|-&lt;br /&gt;
| 3.1.21 || AC-20(2)&lt;br /&gt;
|-&lt;br /&gt;
| 3.1.22 || AC-22&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== 3.2 Awareness and Training ===&lt;br /&gt;
&#039;&#039;&#039;Table D-2: Mapping Awareness and Training Requirements to Controls&#039;&#039;&#039;&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Security Requirement !! NIST SP 800-53 Relevant Security Control(s)&lt;br /&gt;
|-&lt;br /&gt;
| 3.2.1 || AT-2&lt;br /&gt;
|-&lt;br /&gt;
| 3.2.2 || AT-3&lt;br /&gt;
|-&lt;br /&gt;
| 3.2.3 || AT-2(2)&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== 3.3 Audit and Accountability ===&lt;br /&gt;
&#039;&#039;&#039;Table D-3: Mapping Audit and Accountability Requirements to Controls&#039;&#039;&#039;&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Security Requirement !! NIST SP 800-53 Relevant Security Control(s)&lt;br /&gt;
|-&lt;br /&gt;
| 3.3.1 || AU-2, AU-3, AU-12&lt;br /&gt;
|-&lt;br /&gt;
| 3.3.2 || AU-6, AU-12&lt;br /&gt;
|-&lt;br /&gt;
| 3.3.3 || AU-2&lt;br /&gt;
|-&lt;br /&gt;
| 3.3.4 || AU-5&lt;br /&gt;
|-&lt;br /&gt;
| 3.3.5 || AU-6&lt;br /&gt;
|-&lt;br /&gt;
| 3.3.6 || AU-7&lt;br /&gt;
|-&lt;br /&gt;
| 3.3.7 || AU-8&lt;br /&gt;
|-&lt;br /&gt;
| 3.3.8 || AU-9&lt;br /&gt;
|-&lt;br /&gt;
| 3.3.9 || AU-9(4)&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== 3.4 Configuration Management ===&lt;br /&gt;
&#039;&#039;&#039;Table D-4: Mapping Configuration Management Requirements to Controls&#039;&#039;&#039;&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Security Requirement !! NIST SP 800-53 Relevant Security Control(s)&lt;br /&gt;
|-&lt;br /&gt;
| 3.4.1 || CM-2, CM-8&lt;br /&gt;
|-&lt;br /&gt;
| 3.4.2 || CM-6&lt;br /&gt;
|-&lt;br /&gt;
| 3.4.3 || CM-3&lt;br /&gt;
|-&lt;br /&gt;
| 3.4.4 || CM-4&lt;br /&gt;
|-&lt;br /&gt;
| 3.4.5 || CM-5&lt;br /&gt;
|-&lt;br /&gt;
| 3.4.6 || CM-7&lt;br /&gt;
|-&lt;br /&gt;
| 3.4.7 || CM-7(1)&lt;br /&gt;
|-&lt;br /&gt;
| 3.4.8 || CM-7(2), CM-7(5)&lt;br /&gt;
|-&lt;br /&gt;
| 3.4.9 || CM-11&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== 3.5 Identification and Authentication ===&lt;br /&gt;
&#039;&#039;&#039;Table D-5: Mapping Identification and Authentication Requirements to Controls&#039;&#039;&#039;&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Security Requirement !! NIST SP 800-53 Relevant Security Control(s)&lt;br /&gt;
|-&lt;br /&gt;
| 3.5.1 || IA-2, IA-4, IA-5, IA-8&lt;br /&gt;
|-&lt;br /&gt;
| 3.5.2 || IA-2, IA-8&lt;br /&gt;
|-&lt;br /&gt;
| 3.5.3 || IA-2(1), IA-2(2), IA-2(3), IA-2(4)&lt;br /&gt;
|-&lt;br /&gt;
| 3.5.4 || IA-2(8), IA-2(9)&lt;br /&gt;
|-&lt;br /&gt;
| 3.5.5 || IA-4&lt;br /&gt;
|-&lt;br /&gt;
| 3.5.6 || IA-4&lt;br /&gt;
|-&lt;br /&gt;
| 3.5.7 || IA-5(1)&lt;br /&gt;
|-&lt;br /&gt;
| 3.5.8 || IA-5(1)&lt;br /&gt;
|-&lt;br /&gt;
| 3.5.9 || IA-5(1)&lt;br /&gt;
|-&lt;br /&gt;
| 3.5.10 || IA-5(1)&lt;br /&gt;
|-&lt;br /&gt;
| 3.5.11 || IA-6&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== 3.6 Incident Response ===&lt;br /&gt;
&#039;&#039;&#039;Table D-6: Mapping Incident Response Requirements to Controls&#039;&#039;&#039;&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Security Requirement !! NIST SP 800-53 Relevant Security Control(s)&lt;br /&gt;
|-&lt;br /&gt;
| 3.6.1 || IR-2, IR-4, IR-5, IR-6, IR-7&lt;br /&gt;
|-&lt;br /&gt;
| 3.6.2 || IR-6&lt;br /&gt;
|-&lt;br /&gt;
| 3.6.3 || IR-3&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== 3.7 Maintenance ===&lt;br /&gt;
&#039;&#039;&#039;Table D-7: Mapping Maintenance Requirements to Controls&#039;&#039;&#039;&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Security Requirement !! NIST SP 800-53 Relevant Security Control(s)&lt;br /&gt;
|-&lt;br /&gt;
| 3.7.1 || MA-2&lt;br /&gt;
|-&lt;br /&gt;
| 3.7.2 || MA-3&lt;br /&gt;
|-&lt;br /&gt;
| 3.7.3 || MA-2, MA-3(3)&lt;br /&gt;
|-&lt;br /&gt;
| 3.7.4 || MA-3(2)&lt;br /&gt;
|-&lt;br /&gt;
| 3.7.5 || MA-4&lt;br /&gt;
|-&lt;br /&gt;
| 3.7.6 || MA-5&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== 3.8 Media Protection ===&lt;br /&gt;
&#039;&#039;&#039;Table D-8: Mapping Media Protection Requirements to Controls&#039;&#039;&#039;&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Security Requirement !! NIST SP 800-53 Relevant Security Control(s)&lt;br /&gt;
|-&lt;br /&gt;
| 3.8.1 || MP-2, MP-4&lt;br /&gt;
|-&lt;br /&gt;
| 3.8.2 || MP-2&lt;br /&gt;
|-&lt;br /&gt;
| 3.8.3 || MP-6&lt;br /&gt;
|-&lt;br /&gt;
| 3.8.4 || MP-3&lt;br /&gt;
|-&lt;br /&gt;
| 3.8.5 || MP-5&lt;br /&gt;
|-&lt;br /&gt;
| 3.8.6 || MP-5(4)&lt;br /&gt;
|-&lt;br /&gt;
| 3.8.7 || MP-7&lt;br /&gt;
|-&lt;br /&gt;
| 3.8.8 || MP-7(1)&lt;br /&gt;
|-&lt;br /&gt;
| 3.8.9 || CP-9&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== 3.9 Personnel Security ===&lt;br /&gt;
&#039;&#039;&#039;Table D-9: Mapping Personnel Security Requirements to Controls&#039;&#039;&#039;&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Security Requirement !! NIST SP 800-53 Relevant Security Control(s)&lt;br /&gt;
|-&lt;br /&gt;
| 3.9.1 || PS-3&lt;br /&gt;
|-&lt;br /&gt;
| 3.9.2 || PS-4, PS-5&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== 3.10 Physical Protection ===&lt;br /&gt;
&#039;&#039;&#039;Table D-10: Mapping Physical Protection Requirements to Controls&#039;&#039;&#039;&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Security Requirement !! NIST SP 800-53 Relevant Security Control(s)&lt;br /&gt;
|-&lt;br /&gt;
| 3.10.1 || PE-2, PE-3, PE-5, PE-6&lt;br /&gt;
|-&lt;br /&gt;
| 3.10.2 || PE-6, PE-20&lt;br /&gt;
|-&lt;br /&gt;
| 3.10.3 || PE-3&lt;br /&gt;
|-&lt;br /&gt;
| 3.10.4 || PE-6, PE-8&lt;br /&gt;
|-&lt;br /&gt;
| 3.10.5 || PE-3&lt;br /&gt;
|-&lt;br /&gt;
| 3.10.6 || PE-17&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== 3.11 Risk Assessment ===&lt;br /&gt;
&#039;&#039;&#039;Table D-11: Mapping Risk Assessment Requirements to Controls&#039;&#039;&#039;&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Security Requirement !! NIST SP 800-53 Relevant Security Control(s)&lt;br /&gt;
|-&lt;br /&gt;
| 3.11.1 || RA-3&lt;br /&gt;
|-&lt;br /&gt;
| 3.11.2 || RA-5&lt;br /&gt;
|-&lt;br /&gt;
| 3.11.3 || RA-5&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== 3.12 Security Assessment ===&lt;br /&gt;
&#039;&#039;&#039;Table D-12: Mapping Security Assessment Requirements to Controls&#039;&#039;&#039;&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Security Requirement !! NIST SP 800-53 Relevant Security Control(s)&lt;br /&gt;
|-&lt;br /&gt;
| 3.12.1 || CA-2&lt;br /&gt;
|-&lt;br /&gt;
| 3.12.2 || CA-5&lt;br /&gt;
|-&lt;br /&gt;
| 3.12.3 || CA-7&lt;br /&gt;
|-&lt;br /&gt;
| 3.12.4 || PL-2&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== 3.13 System and Communications Protection ===&lt;br /&gt;
&#039;&#039;&#039;Table D-13: Mapping System and Communications Protection Requirements to Controls&#039;&#039;&#039;&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Security Requirement !! NIST SP 800-53 Relevant Security Control(s)&lt;br /&gt;
|-&lt;br /&gt;
| 3.13.1 || SC-7&lt;br /&gt;
|-&lt;br /&gt;
| 3.13.2 || SA-8&lt;br /&gt;
|-&lt;br /&gt;
| 3.13.3 || SC-2&lt;br /&gt;
|-&lt;br /&gt;
| 3.13.4 || SC-4&lt;br /&gt;
|-&lt;br /&gt;
| 3.13.5 || SC-7(3)&lt;br /&gt;
|-&lt;br /&gt;
| 3.13.6 || SC-7(5)&lt;br /&gt;
|-&lt;br /&gt;
| 3.13.7 || SC-7(7)&lt;br /&gt;
|-&lt;br /&gt;
| 3.13.8 || SC-8, SC-8(1)&lt;br /&gt;
|-&lt;br /&gt;
| 3.13.9 || SC-10&lt;br /&gt;
|-&lt;br /&gt;
| 3.13.10 || SC-12&lt;br /&gt;
|-&lt;br /&gt;
| 3.13.11 || SC-13&lt;br /&gt;
|-&lt;br /&gt;
| 3.13.12 || SC-15&lt;br /&gt;
|-&lt;br /&gt;
| 3.13.13 || SC-18&lt;br /&gt;
|-&lt;br /&gt;
| 3.13.14 || SC-19&lt;br /&gt;
|-&lt;br /&gt;
| 3.13.15 || SC-23&lt;br /&gt;
|-&lt;br /&gt;
| 3.13.16 || SC-28&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== 3.14 System and Information Integrity ===&lt;br /&gt;
&#039;&#039;&#039;Table D-14: Mapping System and Information Integrity Requirements to Controls&#039;&#039;&#039;&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Security Requirement !! NIST SP 800-53 Relevant Security Control(s)&lt;br /&gt;
|-&lt;br /&gt;
| 3.14.1 || SI-2&lt;br /&gt;
|-&lt;br /&gt;
| 3.14.2 || SI-3&lt;br /&gt;
|-&lt;br /&gt;
| 3.14.3 || SI-5&lt;br /&gt;
|-&lt;br /&gt;
| 3.14.4 || SI-3&lt;br /&gt;
|-&lt;br /&gt;
| 3.14.5 || SI-3(2)&lt;br /&gt;
|-&lt;br /&gt;
| 3.14.6 || SI-4&lt;br /&gt;
|-&lt;br /&gt;
| 3.14.7 || SI-4(24)&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;references/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Appendix E: Tailoring Criteria ==&lt;br /&gt;
This appendix lists the security controls in the SP 800-53 moderate baseline — one of the sources, along with FIPS 200, used to develop the CUI security requirements in Chapter Three — together with the tailoring action applied to each. Tables E-1 through E-17 contain the specific tailoring actions carried out on the controls in accordance with the tailoring criteria established by NIST and NARA, which facilitated development of the CUI derived security requirements that supplement the basic security requirements.&amp;lt;ref&amp;gt;The same tailoring criteria were applied to the security requirements in FIPS 200, resulting in the CUI basic security requirements described in Chapter Three.&amp;lt;/ref&amp;gt; There are three primary criteria for eliminating a security control or control enhancement from the moderate baseline:&lt;br /&gt;
* The control or control enhancement is uniquely federal (i.e., primarily the responsibility of the federal government);&lt;br /&gt;
* The control or control enhancement is not directly related to protecting the confidentiality of CUI;&amp;lt;ref&amp;gt;While the primary purpose of this publication is to define requirements to protect the confidentiality of CUI, there is a close relationship between the security objectives of confidentiality and integrity. Therefore, the security controls in the SP 800-53 moderate baseline that support protection against unauthorized disclosure also support protection against unauthorized modification.&amp;lt;/ref&amp;gt; or&lt;br /&gt;
* The control or control enhancement is expected to be routinely satisfied by nonfederal organizations without specification.&amp;lt;ref&amp;gt;The security controls tailored out of the moderate baseline (i.e., controls marked NCO or NFO) are often included as part of an organization&#039;s comprehensive security program.&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Table E: Tailoring action symbols&#039;&#039;&#039;&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Symbol !! Tailoring criteria&lt;br /&gt;
|-&lt;br /&gt;
| NCO || Not directly related to protecting the confidentiality of CUI&lt;br /&gt;
|-&lt;br /&gt;
| FED || Uniquely federal, primarily the responsibility of the federal government&lt;br /&gt;
|-&lt;br /&gt;
| NFO || Expected to be routinely satisfied by nonfederal organizations without specification&lt;br /&gt;
|-&lt;br /&gt;
| CUI || The CUI basic or derived security requirement is reflected in, and is traceable to, the security control, control enhancement, or specific elements of the control/enhancement&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Note: the security controls in these tables are taken from NIST Special Publication 800-53, Revision 4.&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
=== Table E-1: Tailoring Actions For Access Controls ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! NIST SP 800-53 Moderate Baseline Security Control !! Tailoring Action&lt;br /&gt;
|-&lt;br /&gt;
| AC-1 — Access Control Policy and Procedures || NFO&lt;br /&gt;
|-&lt;br /&gt;
| AC-2 — Account Management || CUI&lt;br /&gt;
|-&lt;br /&gt;
| AC-2(1) — Account management | Automated system account management || NCO&lt;br /&gt;
|-&lt;br /&gt;
| AC-2(2) — Account management | Removal of temporary / emergency accounts || NCO&lt;br /&gt;
|-&lt;br /&gt;
| AC-2(3) — Account management | Disable inactive accounts || NCO&lt;br /&gt;
|-&lt;br /&gt;
| AC-2(4) — Account management | Automated audit actions || NCO&lt;br /&gt;
|-&lt;br /&gt;
| AC-3 — Access Enforcement || CUI&lt;br /&gt;
|-&lt;br /&gt;
| AC-4 — Information Flow Enforcement || CUI&lt;br /&gt;
|-&lt;br /&gt;
| AC-5 — Separation of Duties || CUI&lt;br /&gt;
|-&lt;br /&gt;
| AC-6 — Least Privilege || CUI&lt;br /&gt;
|-&lt;br /&gt;
| AC-6(1) — Least privilege | Authorize access to security functions || CUI&lt;br /&gt;
|-&lt;br /&gt;
| AC-6(2) — Least privilege | Non-privileged access for nonsecurity functions || CUI&lt;br /&gt;
|-&lt;br /&gt;
| AC-6(5) — Least privilege | Privileged accounts || CUI&lt;br /&gt;
|-&lt;br /&gt;
| AC-6(9) — Least privilege | Auditing use of privileged functions || CUI&lt;br /&gt;
|-&lt;br /&gt;
| AC-6(10) — Least privilege | Prohibit non-privileged users from executing privileged functions || CUI&lt;br /&gt;
|-&lt;br /&gt;
| AC-7 — Unsuccessful Logon Attempts || CUI&lt;br /&gt;
|-&lt;br /&gt;
| AC-8 — System Use Notification || CUI&lt;br /&gt;
|-&lt;br /&gt;
| AC-11 — Session Lock || CUI&lt;br /&gt;
|-&lt;br /&gt;
| AC-11(1) — Session lock | Pattern-hiding displays || CUI&lt;br /&gt;
|-&lt;br /&gt;
| AC-12 — Session Termination || CUI&lt;br /&gt;
|-&lt;br /&gt;
| AC-14 — Permitted Actions without Identification or Authentication || FED&lt;br /&gt;
|-&lt;br /&gt;
| AC-17 — Remote Access || CUI&lt;br /&gt;
|-&lt;br /&gt;
| AC-17(1) — Remote access | Automated monitoring / control || CUI&lt;br /&gt;
|-&lt;br /&gt;
| AC-17(2) — Remote access | Protection of confidentiality / integrity using encryption || CUI&lt;br /&gt;
|-&lt;br /&gt;
| AC-17(3) — Remote access | Managed access control points || CUI&lt;br /&gt;
|-&lt;br /&gt;
| AC-17(4) — Remote access | Privileged commands / access || CUI&lt;br /&gt;
|-&lt;br /&gt;
| AC-18 — Wireless Access || CUI&lt;br /&gt;
|-&lt;br /&gt;
| AC-18(1) — Wireless access | Authentication and encryption || CUI&lt;br /&gt;
|-&lt;br /&gt;
| AC-19 — Access Control for Mobile Devices || CUI&lt;br /&gt;
|-&lt;br /&gt;
| AC-19(5) — Access control for mobile devices | Full device / container-based encryption || CUI&lt;br /&gt;
|-&lt;br /&gt;
| AC-20 — Use of External Systems || CUI&lt;br /&gt;
|-&lt;br /&gt;
| AC-20(1) — Use of external systems | Limits on authorized use || CUI&lt;br /&gt;
|-&lt;br /&gt;
| AC-20(2) — Use of external systems | Portable storage devices || CUI&lt;br /&gt;
|-&lt;br /&gt;
| AC-21 — Information Sharing || FED&lt;br /&gt;
|-&lt;br /&gt;
| AC-22 — Publicly Accessible Content || CUI&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== Table E-2: Tailoring Actions For Awareness And Training Controls ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! NIST SP 800-53 Moderate Baseline Security Control !! Tailoring Action&lt;br /&gt;
|-&lt;br /&gt;
| AT-1 — Security Awareness and Training Policy and Procedures || NFO&lt;br /&gt;
|-&lt;br /&gt;
| AT-2 — Security Awareness Training || CUI&lt;br /&gt;
|-&lt;br /&gt;
| AT-2(2) — Security awareness | Insider threat || CUI&lt;br /&gt;
|-&lt;br /&gt;
| AT-3 — Role-Based Security Training || CUI&lt;br /&gt;
|-&lt;br /&gt;
| AT-4 — Security Training Records || NFO&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== Table E-3: Tailoring Actions For Audit And Accountability Controls ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! NIST SP 800-53 Moderate Baseline Security Control !! Tailoring Action&lt;br /&gt;
|-&lt;br /&gt;
| AU-1 — Audit and Accountability Policy and Procedures || NFO&lt;br /&gt;
|-&lt;br /&gt;
| AU-2 — Audit Events || CUI&lt;br /&gt;
|-&lt;br /&gt;
| AU-2(3) — Audit events | Reviews and updates || CUI&lt;br /&gt;
|-&lt;br /&gt;
| AU-3 — Content of Audit Records || CUI&lt;br /&gt;
|-&lt;br /&gt;
| AU-3(1) — Content of audit records | Additional audit information || CUI&lt;br /&gt;
|-&lt;br /&gt;
| AU-4 — Audit Storage Capacity || NCO&lt;br /&gt;
|-&lt;br /&gt;
| AU-5 — Response to Audit Logging Process Failures || CUI&lt;br /&gt;
|-&lt;br /&gt;
| AU-6 — Audit Review, Analysis, and Reporting || CUI&lt;br /&gt;
|-&lt;br /&gt;
| AU-6(1) — Audit review, analysis, and reporting | Process integration || NCO&lt;br /&gt;
|-&lt;br /&gt;
| AU-6(3) — Audit review, analysis, and reporting | Correlate audit repositories || CUI&lt;br /&gt;
|-&lt;br /&gt;
| AU-7 — Audit Reduction and Report Generation || CUI&lt;br /&gt;
|-&lt;br /&gt;
| AU-7(1) — Audit reduction and report generation | Automatic processing || NCO&lt;br /&gt;
|-&lt;br /&gt;
| AU-8 — Time Stamps || CUI&lt;br /&gt;
|-&lt;br /&gt;
| AU-8(1) — Time stamps | Synchronization with authoritative time source || CUI&lt;br /&gt;
|-&lt;br /&gt;
| AU-9 — Protection of Audit Information || CUI&lt;br /&gt;
|-&lt;br /&gt;
| AU-9(4) — Protection of audit information | Access by subset of privileged users || CUI&lt;br /&gt;
|-&lt;br /&gt;
| AU-11 — Audit Record Retention || NCO&lt;br /&gt;
|-&lt;br /&gt;
| AU-12 — Audit Generation || CUI&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== Table E-4: Tailoring Actions For Security Assessment And Authorization Controls ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! NIST SP 800-53 Moderate Baseline Security Control !! Tailoring Action&lt;br /&gt;
|-&lt;br /&gt;
| CA-1 — Security Assessment and Authorization Policies and Procedures || NFO&lt;br /&gt;
|-&lt;br /&gt;
| CA-2 — Security Assessments || CUI&lt;br /&gt;
|-&lt;br /&gt;
| CA-2(1) — Security assessments | Independent assessors || NFO&lt;br /&gt;
|-&lt;br /&gt;
| CA-3 — System Interconnections || NFO&lt;br /&gt;
|-&lt;br /&gt;
| CA-3(5) — System interconnections | Restrictions on external system connections || NFO&lt;br /&gt;
|-&lt;br /&gt;
| CA-5 — Plan of Action and Milestones || CUI&lt;br /&gt;
|-&lt;br /&gt;
| CA-6 — Security Authorization || FED&lt;br /&gt;
|-&lt;br /&gt;
| CA-7 — Continuous Monitoring || CUI&lt;br /&gt;
|-&lt;br /&gt;
| CA-7(1) — Continuous monitoring | Independent assessment || NFO&lt;br /&gt;
|-&lt;br /&gt;
| CA-9 — Internal System Connections || NFO&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== Table E-5: Tailoring Actions For Configuration Management Controls ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! NIST SP 800-53 Moderate Baseline Security Control !! Tailoring Action&lt;br /&gt;
|-&lt;br /&gt;
| CM-1 — Configuration Management Policy and Procedures || NFO&lt;br /&gt;
|-&lt;br /&gt;
| CM-2 — Baseline Configuration || CUI&lt;br /&gt;
|-&lt;br /&gt;
| CM-2(1) — Baseline configuration | Reviews and updates || NFO&lt;br /&gt;
|-&lt;br /&gt;
| CM-2(3) — Baseline configuration | Retention of previous configurations || NCO&lt;br /&gt;
|-&lt;br /&gt;
| CM-2(7) — Baseline configuration | Configure systems, components, or devices for high-risk areas || NFO&lt;br /&gt;
|-&lt;br /&gt;
| CM-3 — Configuration Change Control || CUI&lt;br /&gt;
|-&lt;br /&gt;
| CM-3(2) — Configuration change control | Test / validate / document changes || NFO&lt;br /&gt;
|-&lt;br /&gt;
| CM-4 — Security Impact Analysis || CUI&lt;br /&gt;
|-&lt;br /&gt;
| CM-5 — Access Restrictions for Change || CUI&lt;br /&gt;
|-&lt;br /&gt;
| CM-6 — Configuration Settings || CUI&lt;br /&gt;
|-&lt;br /&gt;
| CM-7 — Least Functionality || CUI&lt;br /&gt;
|-&lt;br /&gt;
| CM-7(1) — Least functionality | Periodic review || CUI&lt;br /&gt;
|-&lt;br /&gt;
| CM-7(2) — Least functionality | Prevent program execution || CUI&lt;br /&gt;
|-&lt;br /&gt;
| CM-8 — System Component Inventory || CUI&lt;br /&gt;
|-&lt;br /&gt;
| CM-8(1) — System component inventory | Updates during installations / removals || CUI&lt;br /&gt;
|-&lt;br /&gt;
| CM-8(3) — System component inventory | Automated unauthorized component detection || NCO&lt;br /&gt;
|-&lt;br /&gt;
| CM-8(5) — System component inventory | No duplicate accounting of components || NFO&lt;br /&gt;
|-&lt;br /&gt;
| CM-9 — Configuration Management Plan || NFO&lt;br /&gt;
|-&lt;br /&gt;
| CM-10 — Software Usage Restrictions || NCO&lt;br /&gt;
|-&lt;br /&gt;
| CM-11 — User-Installed Software || CUI&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== Table E-6: Tailoring Actions For Contingency Planning Controls ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! NIST SP 800-53 Moderate Baseline Security Control !! Tailoring Action&lt;br /&gt;
|-&lt;br /&gt;
| CP-1 — Contingency Planning Policy and Procedures || NCO&lt;br /&gt;
|-&lt;br /&gt;
| CP-2 — Contingency Plan || NCO&lt;br /&gt;
|-&lt;br /&gt;
| CP-2(1) — Contingency plan | Coordinate with related plans || NCO&lt;br /&gt;
|-&lt;br /&gt;
| CP-2(3) — Contingency plan | Resume essential missions / business functions || NCO&lt;br /&gt;
|-&lt;br /&gt;
| CP-2(8) — Contingency plan | Identify critical assets || NCO&lt;br /&gt;
|-&lt;br /&gt;
| CP-3 — Contingency Training || NCO&lt;br /&gt;
|-&lt;br /&gt;
| CP-4 — Contingency Plan Testing || NCO&lt;br /&gt;
|-&lt;br /&gt;
| CP-4(1) — Contingency plan testing | Coordinate with related plans || NCO&lt;br /&gt;
|-&lt;br /&gt;
| CP-6 — Alternate Storage Site || NCO&lt;br /&gt;
|-&lt;br /&gt;
| CP-6(1) — Alternate storage site | Separation from primary site || NCO&lt;br /&gt;
|-&lt;br /&gt;
| CP-6(3) — Alternate storage site | Accessibility || NCO&lt;br /&gt;
|-&lt;br /&gt;
| CP-7 — Alternate Processing Site || NCO&lt;br /&gt;
|-&lt;br /&gt;
| CP-7(1) — Alternate processing site | Separation from primary site || NCO&lt;br /&gt;
|-&lt;br /&gt;
| CP-7(2) — Alternate processing site | Accessibility || NCO&lt;br /&gt;
|-&lt;br /&gt;
| CP-7(3) — Alternate processing site | Priority of service || NCO&lt;br /&gt;
|-&lt;br /&gt;
| CP-8 — Telecommunications Services || NCO&lt;br /&gt;
|-&lt;br /&gt;
| CP-8(1) — Telecommunications services | Priority of service provisions || NCO&lt;br /&gt;
|-&lt;br /&gt;
| CP-8(2) — Telecommunications services | Single points of failure || NCO&lt;br /&gt;
|-&lt;br /&gt;
| CP-9 — System Backup || CUI&lt;br /&gt;
|-&lt;br /&gt;
| CP-9(1) — System backup | Testing for reliability / integrity || NCO&lt;br /&gt;
|-&lt;br /&gt;
| CP-10 — System Recovery and Reconstitution || NCO&lt;br /&gt;
|-&lt;br /&gt;
| CP-10(2) — System recovery and reconstitution | Transaction recovery || NCO&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== Table E-7: Tailoring Actions For Identification And Authentication Controls ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! NIST SP 800-53 Moderate Baseline Security Control !! Tailoring Action&lt;br /&gt;
|-&lt;br /&gt;
| IA-1 — Identification and Authentication Policy and Procedures || NFO&lt;br /&gt;
|-&lt;br /&gt;
| IA-2 — Identification and Authentication (Organizational Users) || CUI&lt;br /&gt;
|-&lt;br /&gt;
| IA-2(1) — Identification and authentication (organizational users) | Network access to privileged || CUI&lt;br /&gt;
|-&lt;br /&gt;
| IA-2(2) — Identification and authentication (organizational users) | Network access to non-privileged || CUI&lt;br /&gt;
|-&lt;br /&gt;
| IA-2(3) — Identification and authentication (organizational users) | Local access to privileged || CUI&lt;br /&gt;
|-&lt;br /&gt;
| IA-2(8) — Identification and authentication (organizational users) | Network access to privileged || CUI&lt;br /&gt;
|-&lt;br /&gt;
| IA-2(9) — Identification and authentication (organizational users) | Network access to non-privileged || CUI&lt;br /&gt;
|-&lt;br /&gt;
| IA-2(11) — Identification and authentication (organizational users) | Remote access - separate device || FED&lt;br /&gt;
|-&lt;br /&gt;
| IA-2(12) — Identification and authentication (organizational users) | Acceptance of piv credentials || FED&lt;br /&gt;
|-&lt;br /&gt;
| IA-3 — Device Identification and Authentication || CUI&lt;br /&gt;
|-&lt;br /&gt;
| IA-4 — Identifier Management || CUI&lt;br /&gt;
|-&lt;br /&gt;
| IA-5 — Authenticator Management || CUI&lt;br /&gt;
|-&lt;br /&gt;
| IA-5(1) — Authenticator management | Password-based authentication || CUI&lt;br /&gt;
|-&lt;br /&gt;
| IA-5(2) — Authenticator management | Pki-based authentication || FED&lt;br /&gt;
|-&lt;br /&gt;
| IA-5(3) — Authenticator management | In-person or trusted third-party registration || FED&lt;br /&gt;
|-&lt;br /&gt;
| IA-5(11) — Authenticator management | Hardware token-based authentication || FED&lt;br /&gt;
|-&lt;br /&gt;
| IA-6 — Authenticator Feedback || CUI&lt;br /&gt;
|-&lt;br /&gt;
| IA-7 — Cryptographic Module Authentication || FED&lt;br /&gt;
|-&lt;br /&gt;
| IA-8 — Identification and Authentication (Non-Organizational Users) || FED&lt;br /&gt;
|-&lt;br /&gt;
| IA-8(1) — Identification and authentication (non-organizational users) | Acceptance of piv credentials || FED&lt;br /&gt;
|-&lt;br /&gt;
| IA-8(2) — Identification and authentication (non-organizational users) | Acceptance of third-party || FED&lt;br /&gt;
|-&lt;br /&gt;
| IA-8(3) — Identification and authentication (non-organizational users) | Use of ficam-approved || FED&lt;br /&gt;
|-&lt;br /&gt;
| IA-8(4) — Appendix e identification and authentication (non-organizational users) | Use of ficam-issued profiles || FED&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== Table E-8: Tailoring Actions For Incident Response Controls ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! NIST SP 800-53 Moderate Baseline Security Control !! Tailoring Action&lt;br /&gt;
|-&lt;br /&gt;
| IR-1 — Incident Response Policy and Procedures || NFO&lt;br /&gt;
|-&lt;br /&gt;
| IR-2 — Incident Response Training || CUI&lt;br /&gt;
|-&lt;br /&gt;
| IR-3 — Incident Response Testing || CUI&lt;br /&gt;
|-&lt;br /&gt;
| IR-3(2) — Incident response testing | Coordination with related plans || NCO&lt;br /&gt;
|-&lt;br /&gt;
| IR-4 — Incident Handling || CUI&lt;br /&gt;
|-&lt;br /&gt;
| IR-4(1) — Incident handling | Automated incident handling processes || NCO&lt;br /&gt;
|-&lt;br /&gt;
| IR-5 — Incident Monitoring || CUI&lt;br /&gt;
|-&lt;br /&gt;
| IR-6 — Incident Reporting || CUI&lt;br /&gt;
|-&lt;br /&gt;
| IR-6(1) — Incident reporting | Automated reporting || NCO&lt;br /&gt;
|-&lt;br /&gt;
| IR-7 — Incident Response Assistance || CUI&lt;br /&gt;
|-&lt;br /&gt;
| IR-7(1) — Incident response assistance | Automation support for availability of information / support || NCO&lt;br /&gt;
|-&lt;br /&gt;
| IR-8 — Incident Response Plan || NFO&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== Table E-9: Tailoring Actions For Maintenance Controls ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! NIST SP 800-53 Moderate Baseline Security Control !! Tailoring Action&lt;br /&gt;
|-&lt;br /&gt;
| MA-1 — System Maintenance Policy and Procedures || NFO&lt;br /&gt;
|-&lt;br /&gt;
| MA-2 — Controlled Maintenance || CUI&lt;br /&gt;
|-&lt;br /&gt;
| MA-3 — Maintenance Tools || CUI&lt;br /&gt;
|-&lt;br /&gt;
| MA-3(1) — Maintenance tools | Inspect tools || CUI&lt;br /&gt;
|-&lt;br /&gt;
| MA-3(2) — Maintenance tools | Inspect media || CUI&lt;br /&gt;
|-&lt;br /&gt;
| MA-4 — Nonlocal Maintenance || CUI&lt;br /&gt;
|-&lt;br /&gt;
| MA-4(2) — Nonlocal maintenance | Document nonlocal maintenance || NFO&lt;br /&gt;
|-&lt;br /&gt;
| MA-5 — Maintenance Personnel || CUI&lt;br /&gt;
|-&lt;br /&gt;
| MA-6 — Timely Maintenance || NCO&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== Table E-10: Tailoring Actions For Media Protection Controls ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! NIST SP 800-53 Moderate Baseline Security Control !! Tailoring Action&lt;br /&gt;
|-&lt;br /&gt;
| MP-1 — Media Protection Policy and Procedures || NFO&lt;br /&gt;
|-&lt;br /&gt;
| MP-2 — Media Access || CUI&lt;br /&gt;
|-&lt;br /&gt;
| MP-3 — Media Marking || CUI&lt;br /&gt;
|-&lt;br /&gt;
| MP-4 — Media Storage || CUI&lt;br /&gt;
|-&lt;br /&gt;
| MP-5 — Media Transport || CUI&lt;br /&gt;
|-&lt;br /&gt;
| MP-5(4) — Media transport | Cryptographic protection || CUI&lt;br /&gt;
|-&lt;br /&gt;
| MP-6 — Media Sanitization || CUI&lt;br /&gt;
|-&lt;br /&gt;
| MP-7 — Media Use || CUI&lt;br /&gt;
|-&lt;br /&gt;
| MP-7(1) — Media use | Prohibit use without owner || CUI&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== Table E-11: Tailoring Actions For Physical And Environmental Protection Controls ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! NIST SP 800-53 Moderate Baseline Security Control !! Tailoring Action&lt;br /&gt;
|-&lt;br /&gt;
| PE-1 — Physical and Environmental Protection Policy and Procedures || NFO&lt;br /&gt;
|-&lt;br /&gt;
| PE-2 — Physical Access Authorizations || CUI&lt;br /&gt;
|-&lt;br /&gt;
| PE-3 — Physical Access Control || CUI&lt;br /&gt;
|-&lt;br /&gt;
| PE-4 — Access Control for Transmission Medium || CUI&lt;br /&gt;
|-&lt;br /&gt;
| PE-5 — Access Control for Output Devices || CUI&lt;br /&gt;
|-&lt;br /&gt;
| PE-6 — Monitoring Physical Access || CUI&lt;br /&gt;
|-&lt;br /&gt;
| PE-6(1) — Monitoring physical access | Intrusion alarms / surveillance equipment || NFO&lt;br /&gt;
|-&lt;br /&gt;
| PE-8 — Visitor Access Records || NFO&lt;br /&gt;
|-&lt;br /&gt;
| PE-9 — Power Equipment and Cabling || NCO&lt;br /&gt;
|-&lt;br /&gt;
| PE-10 — Emergency Shutoff || NCO&lt;br /&gt;
|-&lt;br /&gt;
| PE-11 — Emergency Power || NCO&lt;br /&gt;
|-&lt;br /&gt;
| PE-12 — Emergency Lighting || NCO&lt;br /&gt;
|-&lt;br /&gt;
| PE-13 — Fire Protection || NCO&lt;br /&gt;
|-&lt;br /&gt;
| PE-13(3) — Fire protection | Automatic fire suppression || NCO&lt;br /&gt;
|-&lt;br /&gt;
| PE-14 — Temperature and Humidity Controls || NCO&lt;br /&gt;
|-&lt;br /&gt;
| PE-15 — Water Damage Protection || NCO&lt;br /&gt;
|-&lt;br /&gt;
| PE-16 — Delivery and Removal || NFO&lt;br /&gt;
|-&lt;br /&gt;
| PE-17 — Alternate Work Site || CUI&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== Table E-12: Tailoring Actions For Planning Controls ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! NIST SP 800-53 Moderate Baseline Security Control !! Tailoring Action&lt;br /&gt;
|-&lt;br /&gt;
| PL-1 — Security Planning Policy and Procedures || NFO&lt;br /&gt;
|-&lt;br /&gt;
| PL-2 — System Security Plan || CUI&lt;br /&gt;
|-&lt;br /&gt;
| PL-2(3) — System security plan | Plan / coordinate with other organizational entities || NFO&lt;br /&gt;
|-&lt;br /&gt;
| PL-4 — Rules of Behavior || NFO&lt;br /&gt;
|-&lt;br /&gt;
| PL-4(1) — Rules of behavior | Social media and networking restrictions || NFO&lt;br /&gt;
|-&lt;br /&gt;
| PL-8 — Information Security Architecture || NFO&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== Table E-13: Tailoring Actions For Personnel Security Controls ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! NIST SP 800-53 Moderate Baseline Security Control !! Tailoring Action&lt;br /&gt;
|-&lt;br /&gt;
| PS-1 — Personnel Security Policy and Procedures || NFO&lt;br /&gt;
|-&lt;br /&gt;
| PS-2 — Position Risk Designation || FED&lt;br /&gt;
|-&lt;br /&gt;
| PS-3 — Personnel Screening || CUI&lt;br /&gt;
|-&lt;br /&gt;
| PS-4 — Personnel Termination || CUI&lt;br /&gt;
|-&lt;br /&gt;
| PS-5 — Personnel Transfer || CUI&lt;br /&gt;
|-&lt;br /&gt;
| PS-6 — Access Agreements || NFO&lt;br /&gt;
|-&lt;br /&gt;
| PS-7 — Third-Party Personnel Security || NFO&lt;br /&gt;
|-&lt;br /&gt;
| PS-8 — Personnel Sanctions || NFO&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== Table E-14: Tailoring Actions For Risk Assessment Controls ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! NIST SP 800-53 Moderate Baseline Security Control !! Tailoring Action&lt;br /&gt;
|-&lt;br /&gt;
| RA-1 — Risk Assessment Policy and Procedures || NFO&lt;br /&gt;
|-&lt;br /&gt;
| RA-2 — Security Categorization || FED&lt;br /&gt;
|-&lt;br /&gt;
| RA-3 — Risk Assessment || CUI&lt;br /&gt;
|-&lt;br /&gt;
| RA-5 — Vulnerability Scanning || CUI&lt;br /&gt;
|-&lt;br /&gt;
| RA-5(1) — Vulnerability scanning | Update tool capability || NFO&lt;br /&gt;
|-&lt;br /&gt;
| RA-5(2) — Vulnerability scanning | Update by frequency / prior to new scan / when identified || NFO&lt;br /&gt;
|-&lt;br /&gt;
| RA-5(5) — Vulnerability scanning | Privileged access || CUI&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== Table E-15: Tailoring Actions For System And Services Acquisition Controls ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! NIST SP 800-53 Moderate Baseline Security Control !! Tailoring Action&lt;br /&gt;
|-&lt;br /&gt;
| SA-1 — System and Services Acquisition Policy and Procedures || NFO&lt;br /&gt;
|-&lt;br /&gt;
| SA-2 — Allocation of Resources || NFO&lt;br /&gt;
|-&lt;br /&gt;
| SA-3 — System Development Life Cycle || NFO&lt;br /&gt;
|-&lt;br /&gt;
| SA-4 — Acquisition Process || NFO&lt;br /&gt;
|-&lt;br /&gt;
| SA-4(1) — Acquisition process | Functional properties of security controls || NFO&lt;br /&gt;
|-&lt;br /&gt;
| SA-4(2) — Acquisition process | Design / implementation information for security controls || NFO&lt;br /&gt;
|-&lt;br /&gt;
| SA-4(9) — Acquisition process | Functions / ports / protocols / services in use || NFO&lt;br /&gt;
|-&lt;br /&gt;
| SA-4(10) — Acquisition process | Use of approved piv products || NFO&lt;br /&gt;
|-&lt;br /&gt;
| SA-5 — System Documentation || NFO&lt;br /&gt;
|-&lt;br /&gt;
| SA-8 — Security Engineering Principles || CUI&lt;br /&gt;
|-&lt;br /&gt;
| SA-9 — External System Services || NFO&lt;br /&gt;
|-&lt;br /&gt;
| SA-9(2) — External systems | Identification of functions / ports / protocols / services || NFO&lt;br /&gt;
|-&lt;br /&gt;
| SA-10 — Developer Configuration Management || NFO&lt;br /&gt;
|-&lt;br /&gt;
| SA-11 — Developer Security Testing and Evaluation || NFO&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== Table E-16: Tailoring Actions For System And Communications Protection Controls ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! NIST SP 800-53 Moderate Baseline Security Control !! Tailoring Action&lt;br /&gt;
|-&lt;br /&gt;
| SC-1 — System and Communications Protection Policy and Procedures || NFO&lt;br /&gt;
|-&lt;br /&gt;
| SC-2 — Application Partitioning || CUI&lt;br /&gt;
|-&lt;br /&gt;
| SC-4 — Information in Shared Resources || CUI&lt;br /&gt;
|-&lt;br /&gt;
| SC-5 — Denial of Service Protection || NCO&lt;br /&gt;
|-&lt;br /&gt;
| SC-7 — Boundary Protection || CUI&lt;br /&gt;
|-&lt;br /&gt;
| SC-7(3) — Boundary protection | Access points || NFO&lt;br /&gt;
|-&lt;br /&gt;
| SC-7(4) — Boundary protection | External telecommunications services || NFO&lt;br /&gt;
|-&lt;br /&gt;
| SC-7(5) — Boundary protection | Deny by default / allow by exception || CUI&lt;br /&gt;
|-&lt;br /&gt;
| SC-7(7) — Boundary protection | Prevent split tunneling for remote devices || CUI&lt;br /&gt;
|-&lt;br /&gt;
| SC-8 — Transmission Confidentiality and Integrity || CUI&lt;br /&gt;
|-&lt;br /&gt;
| SC-8(1) — Transmission confidentiality and integrity | Cryptographic or alternate physical protection || CUI&lt;br /&gt;
|-&lt;br /&gt;
| SC-10 — Network Disconnect || CUI&lt;br /&gt;
|-&lt;br /&gt;
| SC-12 — Cryptographic Key Establishment and Management || CUI&lt;br /&gt;
|-&lt;br /&gt;
| SC-13 — Cryptographic Protection || CUI&lt;br /&gt;
|-&lt;br /&gt;
| SC-15 — Collaborative Computing Devices || CUI&lt;br /&gt;
|-&lt;br /&gt;
| SC-17 — Public Key Infrastructure Certificates || FED&lt;br /&gt;
|-&lt;br /&gt;
| SC-18 — Mobile Code || CUI&lt;br /&gt;
|-&lt;br /&gt;
| SC-19 — Voice over Internet Protocol || CUI&lt;br /&gt;
|-&lt;br /&gt;
| SC-20 — Secure Name /Address Resolution Service (Authoritative Source) || NFO&lt;br /&gt;
|-&lt;br /&gt;
| SC-21 — Secure Name /Address Resolution Service (Recursive or Caching Resolver) || NFO&lt;br /&gt;
|-&lt;br /&gt;
| SC-22 — Architecture and Provisioning for Name/Address Resolution Service || NFO&lt;br /&gt;
|-&lt;br /&gt;
| SC-23 — Session Authenticity || CUI&lt;br /&gt;
|-&lt;br /&gt;
| SC-28 — Protection of Information at Rest || CUI&lt;br /&gt;
|-&lt;br /&gt;
| SC-39 — Process Isolation || NFO&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== Table E-17: Tailoring Actions For System And Information Integrity Controls ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! NIST SP 800-53 Moderate Baseline Security Control !! Tailoring Action&lt;br /&gt;
|-&lt;br /&gt;
| SI-1 — System and Information Integrity Policy and Procedures || NFO&lt;br /&gt;
|-&lt;br /&gt;
| SI-2 — Flaw Remediation || CUI&lt;br /&gt;
|-&lt;br /&gt;
| SI-2(2) — Flaw remediation | Automated flaw remediation status || NCO&lt;br /&gt;
|-&lt;br /&gt;
| SI-3 — Malicious Code Protection || CUI&lt;br /&gt;
|-&lt;br /&gt;
| SI-3(1) — Malicious code protection | Central management || NCO&lt;br /&gt;
|-&lt;br /&gt;
| SI-3(2) — Malicious code protection | Automatic updates || NCO&lt;br /&gt;
|-&lt;br /&gt;
| SI-4 — System Monitoring || CUI&lt;br /&gt;
|-&lt;br /&gt;
| SI-4(2) — System monitoring | Automated tools for real-time analysis || NCO&lt;br /&gt;
|-&lt;br /&gt;
| SI-4(4) — System monitoring | Inbound and outbound communications traffic || CUI&lt;br /&gt;
|-&lt;br /&gt;
| SI-4(5) — System monitoring | System-generated alerts || NFO&lt;br /&gt;
|-&lt;br /&gt;
| SI-5 — Security Alerts, Advisories, and Directives || CUI&lt;br /&gt;
|-&lt;br /&gt;
| SI-7 — Software, Firmware, and Information Integrity || NCO&lt;br /&gt;
|-&lt;br /&gt;
| SI-7(1) — Software, firmware, and information integrity | Integrity checks || NCO&lt;br /&gt;
|-&lt;br /&gt;
| SI-7(7) — Software, firmware, and information integrity | Integration of detection and response || NCO&lt;br /&gt;
|-&lt;br /&gt;
| SI-8 — Spam Protection || NCO&lt;br /&gt;
|-&lt;br /&gt;
| SI-8(1) — Spam protection | Central management || NCO&lt;br /&gt;
|-&lt;br /&gt;
| SI-8(2) — Spam protection | Automatic updates || NCO&lt;br /&gt;
|-&lt;br /&gt;
| SI-10 — Information Input Validation || NCO&lt;br /&gt;
|-&lt;br /&gt;
| SI-11 — Error Handling || NCO&lt;br /&gt;
|-&lt;br /&gt;
| SI-12 — Information Handling and Retention || FED&lt;br /&gt;
|-&lt;br /&gt;
| SI-16 — Memory Protection || NFO&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;references/&amp;gt;&lt;/div&gt;</summary>
		<author><name>David</name></author>
	</entry>
	<entry>
		<id>https://cmmcwiki.org/index.php?title=MediaWiki:Sidebar&amp;diff=1633</id>
		<title>MediaWiki:Sidebar</title>
		<link rel="alternate" type="text/html" href="https://cmmcwiki.org/index.php?title=MediaWiki:Sidebar&amp;diff=1633"/>
		<updated>2026-07-26T01:33:03Z</updated>

		<summary type="html">&lt;p&gt;David: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;* navigation&lt;br /&gt;
** mainpage | mainpage-description&lt;br /&gt;
* CMMC Model and Rule&lt;br /&gt;
** Model_Overview | Model Overview&lt;br /&gt;
** 32_CFR_Part_170 | 32 CFR Part 170&lt;br /&gt;
** 48_CFR_Parts_204_212_217_252 | 48 CFR Parts 204, 212, 217, and 252&lt;br /&gt;
* Scoping and Assessment Guides&lt;br /&gt;
** Level_1_Scoping_Guidance | Level 1 Scoping Guidance&lt;br /&gt;
** Level_1_Self-Assessment_Guide | Level 1 Self-Assessment Guide&lt;br /&gt;
** Level_2_Scoping_Guidance | Level 2 Scoping Guidance&lt;br /&gt;
** Level_2_Assessment_Guide | Level 2 Assessment Guide&lt;br /&gt;
** Level_3_Scoping_Guidance | Level 3 Scoping Guidance&lt;br /&gt;
** Level_3_Assessment_Guide | Level 3 Assessment Guide&lt;br /&gt;
* CMMC Guides and Tools&lt;br /&gt;
** CMMC_Hashing_Guide | CMMC Hashing Guide&lt;br /&gt;
** CMMC_Assessment_Process | CMMC Assessment Process (CAP) by CyberAB&lt;br /&gt;
** DoD_Assessment_Methodology | DoD Assessment Methodology&lt;br /&gt;
** Evidence_Collection_Approach | CMMC Evidence Collection Approach&lt;br /&gt;
** DoD Memo on ODPs for 800-171 Revision 3 | DoD Memo on Organization-Defined Parameters for NIST 800-171 Revision 3&lt;br /&gt;
* Other Publications and Tools&lt;br /&gt;
** NIST_Cybersecurity_Framework | NIST Cybersecurity Framework (CSF): NIST Cybersecurity Framework&lt;br /&gt;
** NIST_SP_800-17_R2 | NIST SP 800-171 Rev. 2: Protecting CUI in Nonfederal Systems and Organizations&lt;br /&gt;
** NIST_SP_800-171A | NIST SP 800-171A: Assessing Security Requirements for CUI&lt;br /&gt;
** NIST_SP_800-17_R3 | NIST SP 800-171 Rev. 3: Protecting CUI in Nonfederal Systems and Organizations&lt;br /&gt;
** NIST_SP_800-171A_R3 | NIST SP 800-171A Rev. 3: Assessing Security Requirements for CUI&lt;br /&gt;
** NIST_SP_800-53 | NIST SP 800-53: Security and Privacy Controls for Information Systems and Organizations&lt;br /&gt;
** External_References | External References&lt;/div&gt;</summary>
		<author><name>David</name></author>
	</entry>
	<entry>
		<id>https://cmmcwiki.org/index.php?title=MediaWiki:Sidebar&amp;diff=1632</id>
		<title>MediaWiki:Sidebar</title>
		<link rel="alternate" type="text/html" href="https://cmmcwiki.org/index.php?title=MediaWiki:Sidebar&amp;diff=1632"/>
		<updated>2026-07-26T01:32:13Z</updated>

		<summary type="html">&lt;p&gt;David: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;* navigation&lt;br /&gt;
** mainpage | mainpage-description&lt;br /&gt;
* CMMC Model and Rule&lt;br /&gt;
** Model_Overview | Model Overview&lt;br /&gt;
** 32_CFR_Part_170 | 32 CFR Part 170&lt;br /&gt;
** 48_CFR_Parts_204_212_217_252 | 48 CFR Parts 204, 212, 217, and 252&lt;br /&gt;
* Scoping and Assessment Guides&lt;br /&gt;
** Level_1_Scoping_Guidance | Level 1 Scoping Guidance&lt;br /&gt;
** Level_1_Self-Assessment_Guide | Level 1 Self-Assessment Guide&lt;br /&gt;
** Level_2_Scoping_Guidance | Level 2 Scoping Guidance&lt;br /&gt;
** Level_2_Assessment_Guide | Level 2 Assessment Guide&lt;br /&gt;
** Level_3_Scoping_Guidance | Level 3 Scoping Guidance&lt;br /&gt;
** Level_3_Assessment_Guide | Level 3 Assessment Guide&lt;br /&gt;
* CMMC Guides and Tools&lt;br /&gt;
** CMMC_Hashing_Guide | CMMC Hashing Guide&lt;br /&gt;
** CMMC_Assessment_Process | CMMC Assessment Process (CAP) by CyberAB&lt;br /&gt;
** DoD_Assessment_Methodology | DoD Assessment Methodology&lt;br /&gt;
** Evidence_Collection_Approach | CMMC Evidence Collection Approach&lt;br /&gt;
** DoD Memo on ODPs for 800-171 Revision 3 | DoD Memo on Organization-Defined Parameters for NIST 800-171 Revision 3&lt;br /&gt;
* Other Publications and Tools&lt;br /&gt;
** NIST_Cybersecurity_Framework | NIST Cybersecurity Framework (CSF): NIST Cybersecurity Framework&lt;br /&gt;
** NIST_SP_800-17_R2 | NIST SP 800-171 Rev. 2: Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations&lt;br /&gt;
** NIST_SP_800-171A | NIST SP 800-171A: Assessing Security Requirements for Controlled Unclassified Information&lt;br /&gt;
** NIST_SP_800-17_R3 | NIST SP 800-171 Rev. 3: Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations&lt;br /&gt;
** NIST_SP_800-171A_R3 | NIST SP 800-171A Rev. 3: Assessing Security Requirements for Controlled Unclassified Information&lt;br /&gt;
** NIST_SP_800-53 | NIST SP 800-53: Security and Privacy Controls for Information Systems and Organizations&lt;br /&gt;
** External_References | External References&lt;/div&gt;</summary>
		<author><name>David</name></author>
	</entry>
	<entry>
		<id>https://cmmcwiki.org/index.php?title=48_CFR_Parts_204_212_217_252&amp;diff=1631</id>
		<title>48 CFR Parts 204 212 217 252</title>
		<link rel="alternate" type="text/html" href="https://cmmcwiki.org/index.php?title=48_CFR_Parts_204_212_217_252&amp;diff=1631"/>
		<updated>2026-07-26T01:21:57Z</updated>

		<summary type="html">&lt;p&gt;David: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{DISPLAYTITLE:Defense Federal Acquisition Regulation Supplement: Assessing Contractor Implementation of Cybersecurity Requirements (DFARS Case 2019–D041)}}&lt;br /&gt;
&#039;&#039;&#039;Source of Reference: The official [https://www.federalregister.gov/documents/2025/09/10/2025-17359/defense-federal-acquisition-regulation-supplement-assessing-contractor-implementation-of Defense Federal Acquisition Regulation Supplement: Assessing Contractor Implementation of Cybersecurity Requirements (DFARS Case 2019-D041)] final rule.&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
For inquiries and reporting errors on this wiki, please [mailto:support@cmmcwiki.org contact us]. Thank you.&lt;br /&gt;
&lt;br /&gt;
== Agency Information ==&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Field !! Value&lt;br /&gt;
|-&lt;br /&gt;
| Agency || Defense Acquisition Regulations System, Department of Defense (DoD)&lt;br /&gt;
|-&lt;br /&gt;
| Action || Final rule&lt;br /&gt;
|-&lt;br /&gt;
| Docket || DARS–2020–0034&lt;br /&gt;
|-&lt;br /&gt;
| RIN || 0750–AK81&lt;br /&gt;
|-&lt;br /&gt;
| Effective Date || November 10, 2025&lt;br /&gt;
|-&lt;br /&gt;
| Contact || Ms. Heather Kitchens, telephone 571–296–7152&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Summary ==&lt;br /&gt;
&lt;br /&gt;
DoD is issuing a final rule amending the Defense Federal Acquisition Regulation Supplement (DFARS) to incorporate contractual requirements related to the final Cybersecurity Maturity Model Certification (CMMC) program rule. This final DFARS rule also partially implements a section of the National Defense Authorization Act for Fiscal Year 2020 that directed the Secretary of Defense to develop a consistent, comprehensive framework to enhance cybersecurity for the U.S. defense industrial base.&lt;br /&gt;
&lt;br /&gt;
== I. Background ==&lt;br /&gt;
&lt;br /&gt;
* DoD published an interim rule in the Federal Register at 85 FR 61505 on September 29, 2020, to assess contractor implementation of cybersecurity requirements and enhance the protection of unclassified information within the DoD supply chain.&lt;br /&gt;
* DoD subsequently published a proposed rule at 89 FR 66327 on August 15, 2024, to implement the contractual requirements related to CMMC. Ninety-seven respondents submitted public comments in response to the proposed rule.&lt;br /&gt;
* Separately, a proposed rule to establish the CMMC program at 32 CFR part 170 was published at 88 FR 89058 on December 26, 2023. A final rule was published at 89 FR 83092 on October 15, 2024, and became effective on December 16, 2024.&lt;br /&gt;
&lt;br /&gt;
== II. Discussion and Analysis ==&lt;br /&gt;
&lt;br /&gt;
=== A. Summary of Significant Changes From the Proposed Rule ===&lt;br /&gt;
&lt;br /&gt;
==== 1. Definitions ====&lt;br /&gt;
&lt;br /&gt;
The final rule adds and modifies certain definitions at DFARS 204.7501, Definitions.&lt;br /&gt;
&lt;br /&gt;
* The definition of &amp;quot;current&amp;quot; was changed to clarify that it is related to having no changes in compliance with the requirements at 32 CFR part 170, and to clarify what &amp;quot;current&amp;quot; means when referring to &amp;quot;Conditional CMMC Status,&amp;quot; &amp;quot;Final CMMC Status,&amp;quot; and &amp;quot;affirmation of continuous compliance.&amp;quot;&lt;br /&gt;
* The term &amp;quot;DoD unique identifier&amp;quot; was updated to &amp;quot;CMMC unique identifier&amp;quot; to match the naming convention in the Supplier Performance Risk System (SPRS). The CMMC UID means ten alpha-numeric characters assigned to each contractor CMMC assessment and reflected in SPRS for each contractor information system.&lt;br /&gt;
* The final rule adds the definition of &amp;quot;Federal contract information&amp;quot; based on the definition from the clause at FAR 52.204–21.&lt;br /&gt;
* The final rule adds a definition of &amp;quot;plan of action and milestones&amp;quot; (POA&amp;amp;M) based on the definition codified at 32 CFR part 170.&lt;br /&gt;
* The final rule adds the term &amp;quot;CMMC status&amp;quot; and a definition for the term.&lt;br /&gt;
&lt;br /&gt;
==== 2. Policy ====&lt;br /&gt;
&lt;br /&gt;
DFARS 204.7502, Policy, includes language to add clarity by stating that for CMMC levels 2 and 3 only, a conditional CMMC status is permitted for a period not to exceed 180 days from the conditional CMMC date, in accordance with 32 CFR 170.21, and an award can occur with a CMMC conditional status. The language also clarifies that a final CMMC is achieved upon successful closeout of a valid POA&amp;amp;M.&lt;br /&gt;
&lt;br /&gt;
==== 3. Procedures ====&lt;br /&gt;
&lt;br /&gt;
* Language at DFARS 204.7503 was updated to add paragraph headings.&lt;br /&gt;
* Language clarifies that contracting officers are required to check SPRS and not award a contract, task order, or delivery order to an offeror that does not have a current CMMC status posted in SPRS at the CMMC level required by the solicitation, or higher, for each CMMC UID provided by the offeror.&lt;br /&gt;
* Paragraph (d) clarifies that all offerors are required to provide the CMMC UIDs applicable to each contractor information system that processes, stores, or transmits FCI or CUI and that will be used in performance of the contract.&lt;br /&gt;
&lt;br /&gt;
==== 4. Clause Prescription ====&lt;br /&gt;
&lt;br /&gt;
At DFARS 204.7504, the prescription for the contract clause has been updated to clarify the phased implementation approach:&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;Until three years after the effective date of the rule&#039;&#039;&#039;: the clause will be prescribed for use if program managers and requiring activities make a determination to apply a CMMC requirement to contracts, excluding awards solely for the acquisition of commercially available off-the-shelf (COTS) items (unless the requirements at 32 CFR 170.5(d) are met).&lt;br /&gt;
* &#039;&#039;&#039;Beginning three years and one day after the effective date of the rule&#039;&#039;&#039;: the clause will be prescribed for use if program managers and requiring activities determine that the contractor will be required to use contractor information systems in the performance of the contract to process, store, or transmit FCI or CUI, excluding awards solely for the acquisition of COTS items.&lt;br /&gt;
&lt;br /&gt;
==== 5. Solicitation Provision and Contract Clause ====&lt;br /&gt;
&lt;br /&gt;
* The contract clause has been updated to include a fill-in for the contracting officer to identify the CMMC level required by the contract.&lt;br /&gt;
* The subcontract flowdown language has been updated to identify that subcontractors also must submit affirmations of continuous compliance and the results of self-assessments in SPRS.&lt;br /&gt;
* The clause has been updated to include the term &amp;quot;affirming official&amp;quot; in place of &amp;quot;senior company official&amp;quot; to match 32 CFR part 170.&lt;br /&gt;
* The solicitation provision and contract clause include the terminology needed for entering the CMMC level: &#039;&#039;&#039;CMMC Level 1 (Self)&#039;&#039;&#039;; &#039;&#039;&#039;CMMC Level 2 (Self)&#039;&#039;&#039;; &#039;&#039;&#039;CMMC Level 2 (C3PAO)&#039;&#039;&#039;; or &#039;&#039;&#039;CMMC Level 3 (DIBCAC)&#039;&#039;&#039;.&lt;br /&gt;
* The solicitation provision clarifies that offerors will not be eligible for award if the offeror does not have a current CMMC status entered in SPRS at the required level and a current affirmation of continuous compliance for each applicable contractor information system.&lt;br /&gt;
&lt;br /&gt;
=== B. Analysis of Public Comments ===&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Note: Technical and programmatic comments on CMMC, and comments related to the CMMC cost analysis, were addressed in the CMMC program rule that codified 32 CFR part 170. This DFARS rule addresses the nontechnical and nonprogrammatic comments.&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
==== 1. Clarification of &amp;quot;Changes&amp;quot; ====&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Comment:&#039;&#039;&#039; Several respondents asked for more clarity regarding what &amp;quot;changes&amp;quot; means in the proposed rule.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Response:&#039;&#039;&#039; Based on public comment, the final DFARS rule adds the sentence: &amp;quot;Submit to the Contracting Officer . . . any changes in the CMMC UIDs generated in SPRS throughout the life of the contract, task order, or delivery order, if applicable.&amp;quot; The notification requirement to report lapses in information security or changes in compliance with 32 CFR part 170 was removed, since the reporting requirement at DFARS 252.204–7012 paragraph (c) already provides sufficient notification of relevant information security incidents.&lt;br /&gt;
&lt;br /&gt;
==== 2. Clarification of &amp;quot;Lapses in Information Security&amp;quot; ====&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Comment:&#039;&#039;&#039; Several respondents asked for clarity on &amp;quot;lapses in information security&amp;quot; in proposed paragraph (b)(4) at DFARS 252.204–7021; several recommended it be removed.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Response:&#039;&#039;&#039; The requirement to notify the contracting officer of lapses in information security or changes in CMMC status has been removed from the final rule.&lt;br /&gt;
&lt;br /&gt;
==== 3. Editorial Changes ====&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Comment:&#039;&#039;&#039; Respondents identified typos and recommended using &amp;quot;and/or&amp;quot; instead of &amp;quot;or&amp;quot; for CMMC UIDs.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Response:&#039;&#039;&#039; Editorial comments were noted; most were mooted by other final-rule changes. The &amp;quot;and/or&amp;quot; recommendation was &#039;&#039;&#039;not&#039;&#039;&#039; implemented because it could narrow the scope of the requirement beyond what was intended.&lt;br /&gt;
&lt;br /&gt;
==== 4. CMMC Level Notification and Compliance ====&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Comment:&#039;&#039;&#039; Respondents asked how the required CMMC level will be communicated and determined, and requested clarity on phase-in exemptions for small businesses.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Response:&#039;&#039;&#039; The CMMC level determination is made in accordance with 32 CFR 170.19 (CMMC scoping) by the program office/requiring activity (for the prime contract) or the prime/next higher-tier subcontractor (for subcontracts). CMMC levels are: CMMC Level 1 (Self); CMMC Level 2 (Self); CMMC Level 2 (C3PAO); and CMMC Level 3 (DIBCAC) (see 32 CFR 170.14). DoD did not incorporate the recommendation to limit CMMC inclusion in existing contracts, as contracting officers already have discretion to bilaterally modify existing contracts.&lt;br /&gt;
&lt;br /&gt;
==== 5. COTS Item Exclusion ====&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Comment:&#039;&#039;&#039; Respondents requested clarification on the scope of the COTS exclusion.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Response:&#039;&#039;&#039; The rule does not apply to awards that are exclusively for COTS items, as defined at FAR 2.101. Any award exclusively for items meeting the FAR definition is considered an &amp;quot;exclusively COTS&amp;quot; award.&lt;br /&gt;
&lt;br /&gt;
==== 6. Extending the Certification Time for New Bidders ====&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Comment:&#039;&#039;&#039; A respondent requested an extension of certification time for new bidders.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Response:&#039;&#039;&#039; Per 32 CFR part 170, contractors must have a CMMC self-assessment or certification at time of award; there is no delayed implementation for new bidders, though 32 CFR 170.21 allows a POA&amp;amp;M in certain instances.&lt;br /&gt;
&lt;br /&gt;
==== 7. Flowdown Requirements When Subcontractors Use Prime Contractor Information System ====&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Comment:&#039;&#039;&#039; Respondents asked about flowdown when subcontractors use the prime&#039;s information system rather than their own.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Response:&#039;&#039;&#039; A subcontractor that does not process, store, or transmit FCI or CUI on its own systems has no CMMC assessment requirement. DoD does not have an automated tool giving primes visibility into subcontractor certification status in SPRS, but subcontractors may voluntarily share scores/certificates.&lt;br /&gt;
&lt;br /&gt;
==== 8. Definitions ====&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;a. CUI&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Comment:&#039;&#039;&#039; Respondents asked to define CUI and streamline it with &amp;quot;covered defense information.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Response:&#039;&#039;&#039; The definition of CUI incorporates the definition codified at 32 CFR part 170; modifying it further is outside the scope of this rule.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;b. FCI&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Comment:&#039;&#039;&#039; A respondent requested clarification of &amp;quot;not intended for public release&amp;quot; and &amp;quot;simple transactional information,&amp;quot; and whether FOIA-subject information is still FCI.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Response:&#039;&#039;&#039; A definition of FCI was added, based on FAR 52.204–21, with &amp;quot;information necessary to process payments&amp;quot; as an example of simple transactional information. Marking/FOIA comments are outside scope.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;c. Current&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Comment:&#039;&#039;&#039; Clarify whether &amp;quot;current&amp;quot; refers to date of assessment or date of certification.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Response:&#039;&#039;&#039; The final rule changes the definition of &amp;quot;current&amp;quot; to address this; the underlying requirements were established in 32 CFR part 170, and DoD cannot make changes beyond that in this DFARS rule.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;d. Data&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Comment:&#039;&#039;&#039; Respondents asked that &amp;quot;data&amp;quot; be replaced with &amp;quot;FCI and/or CUI&amp;quot; to narrow scope.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Response:&#039;&#039;&#039; Based on public comments, the rule was revised to remove the term &amp;quot;data.&amp;quot; The rule applies to information that is FCI and CUI only.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;e. Contractor Information Systems&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Comment:&#039;&#039;&#039; Respondents asked that &amp;quot;contractor information systems&amp;quot; be limited/defined more narrowly, similar to &amp;quot;covered contractor information systems.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Response:&#039;&#039;&#039; The rule clarifies that &amp;quot;contractor information systems&amp;quot; throughout the rule means systems &amp;quot;that process, store, or transmit FCI or CUI in performance of the contract.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
==== 9. Regulatory Impact Analysis (RIA) Estimate ====&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Comment:&#039;&#039;&#039; Several respondents said the RIA cost estimate was too low and should include all offerors and a revised estimate of average information systems per contractor.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Response:&#039;&#039;&#039; The RIA only covers costs of contractual requirements to upload self-assessments and complete affirmations in SPRS (technical/programmatic CMMC costs are addressed under 32 CFR part 170). The RIA was revised to expand the estimated impacted entities to include, in year four and beyond, all entities in the Federal Procurement Data System awarded DoD contracts FY2022–FY2024. The estimate of five information systems per contractor remains a DoD subject-matter-expert estimate.&lt;br /&gt;
&lt;br /&gt;
==== 10. Application to Fundamental Research ====&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Comment:&#039;&#039;&#039; Respondents raised concerns about applying CMMC to fundamental research that could become CUI.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Response:&#039;&#039;&#039; Fundamental research (per NSDD 189) is published and broadly shared and cannot be safeguarded as FCI or CUI; however, if it has the potential to become CUI, it would be subject to CMMC once it becomes CUI.&lt;br /&gt;
&lt;br /&gt;
==== 11. Applicability ====&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Comment:&#039;&#039;&#039; Respondents raised numerous applicability questions: FCI-only Level 1 self-assessment carve-outs, program manager documentation of rationale, existing vs. new contracts, micro-purchase threshold subcontracts, and scope of paragraph (b)(3).&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Response:&#039;&#039;&#039; The clause will be included in solicitations issued on/after the effective date and in resulting contracts; contracting officers may also bilaterally incorporate the clause into existing contracts (see FAR 1.108(d)). Until three years after the effective date, CMMC applies only where program managers/requiring activities determine to apply it (excluding COTS-only awards); afterward, it applies wherever contractor information systems will process, store, or transmit FCI or CUI. 32 CFR part 170 does not allow spot checks and requires the CMMC requirement be met at time of award.&lt;br /&gt;
&lt;br /&gt;
==== 12. Flowdown ====&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Comment:&#039;&#039;&#039; Respondents requested clarification on flowdown scope, CUI dissemination limits, and lower-tier CMMC level determination.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Response:&#039;&#039;&#039; See 32 CFR 170.23 for flowdown guidance. Clause paragraph (d)(1) was revised to clarify flowdown applies only where the subcontract requires a CMMC level, and to no longer exclude paragraph (b)(3) (affirmation of continuous compliance) from subcontractor flowdown. The rule was &#039;&#039;&#039;not&#039;&#039;&#039; revised regarding which subcontractors must receive CUI — that determination remains with the prime contractor.&lt;br /&gt;
&lt;br /&gt;
==== 13. CMMC as an Evaluation Factor ====&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Comment:&#039;&#039;&#039; Is CMMC a competition evaluation factor or set-aside requirement?&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Response:&#039;&#039;&#039; No. CMMC is not an evaluation factor or set-aside requirement; DFARS 204.7503 requires contracting officers not to award to an offeror that fails to meet the CMMC requirements in the solicitation, and if included in the solicitation, it becomes a contract requirement.&lt;br /&gt;
&lt;br /&gt;
==== 14. Program Office Requirements ====&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Comment:&#039;&#039;&#039; Require the program office to review contractor-provided information.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Response:&#039;&#039;&#039; The rule was revised to require the contracting officer to work with the program office/requiring activity to review the offeror&#039;s CMMC status and affirmation information.&lt;br /&gt;
&lt;br /&gt;
==== 15. Clarifying When FCI Applies ====&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Comment:&#039;&#039;&#039; Clarify that systems processing FCI (not CUI) need only CMMC Level 1.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Response:&#039;&#039;&#039; Not included in the final rule; contracting officers do not determine the required CMMC level.&lt;br /&gt;
&lt;br /&gt;
==== 16. International Applicability ====&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Comment:&#039;&#039;&#039; Respondents raised questions about C3PAO assessments outside the U.S., international harmonization, and foreign verification bodies (e.g., Taiwan&#039;s TAF).&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Response:&#039;&#039;&#039; Contracts subject to NIST SP 800–171 compliance (e.g., via DFARS 252.204–7012) require foreign or domestic contractors to secure their systems. See 32 CFR 179 regarding foreign C3PAO accreditation; DoD permits an equivalent process for personnel ineligible for a Tier 3 background investigation, for CMMC Program purposes only.&lt;br /&gt;
&lt;br /&gt;
==== 17. POA&amp;amp;M ====&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Comment:&#039;&#039;&#039; Respondents sought clarity on POA&amp;amp;M closeout, conditional certification for subcontract award, and continued reliance on POA&amp;amp;Ms for newly discovered risks.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Response:&#039;&#039;&#039; The rule was revised to clarify (via the &amp;quot;current&amp;quot; definition) that for CMMC Levels 2 and 3 only, conditional CMMC status is permitted for up to 180 days from the conditional CMMC status date, and that final CMMC status is achieved upon successful POA&amp;amp;M closeout. 32 CFR part 170 does not allow additional POA&amp;amp;Ms beyond established scoping, other than for scenarios appropriate for an &amp;quot;operational plan of action&amp;quot; (32 CFR 170.4).&lt;br /&gt;
&lt;br /&gt;
==== 18. Subcontractor Compliance ====&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Comment:&#039;&#039;&#039; Respondents asked how primes monitor/verify subcontractor CMMC adherence, requested an automated SPRS visibility tool, and asked when subcontractors must be compliant.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Response:&#039;&#039;&#039; Contractors can only access their own CMMC information in SPRS; DoD has no tool for automatic sharing with primes. Subcontractors may screenshot/print their own SPRS status to share voluntarily. Prior to awarding a subcontract, the prime must ensure the subcontractor has a current CMMC status at the appropriate level. 32 CFR part 170 does not allow limiting enforcement to direct suppliers only.&lt;br /&gt;
&lt;br /&gt;
==== 19. Senior Company Official ====&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Comment:&#039;&#039;&#039; Respondents noted the proposed rule&#039;s &amp;quot;senior company official&amp;quot; term does not match 32 CFR part 170&#039;s &amp;quot;affirming official,&amp;quot; and asked for a clear definition.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Response:&#039;&#039;&#039; The final rule updates terminology to &amp;quot;affirming official&amp;quot; to align with 32 CFR part 170 (the proposed DFARS rule used the older term due to timing of the two rulemakings).&lt;br /&gt;
&lt;br /&gt;
==== 20. Task Orders and Delivery Orders ====&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Comment:&#039;&#039;&#039; Will existing IDIQ contracts&#039; task/delivery orders issued after the rule contain a CMMC requirement?&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Response:&#039;&#039;&#039; Task orders or delivery orders issued after the rule&#039;s effective date may include a CMMC requirement under the prescribed clause/provision.&lt;br /&gt;
&lt;br /&gt;
==== 21. Relationship Between &amp;quot;Covered Contractor Information Systems&amp;quot; and &amp;quot;Contractor Information Systems&amp;quot; ====&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Comment:&#039;&#039;&#039; Clarify the relationship between the two terms and possible over-broad scope.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Response:&#039;&#039;&#039; The rule clarifies that &amp;quot;contractor information systems&amp;quot; are limited to those &amp;quot;that process, store, or transmit FCI or CUI during performance of the contract.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
==== 22. CMMC Unique Identifiers ====&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Comment:&#039;&#039;&#039; Respondents sought clarification on CMMC UIDs vs. CAGE codes, mandatory vs. optional UID submission, and prime vs. subcontractor UID reporting obligations.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Response:&#039;&#039;&#039; A CMMC UID is assigned per CMMC Assessment Scope as defined by the Organization Seeking Assessment (OSA) (see 32 CFR 170.19). SPRS/eMASS assigns the UID upon submission of assessment results. OSAs must obtain a CAGE code (via sam.gov) or NCAGE code (for non-U.S. businesses, via NSPA) and a PIEE account. Only prime contractors with a CMMC requirement must submit CMMC UIDs to the contracting officer (which may include subcontractors&#039; UIDs); subcontractors themselves do not submit UIDs to the contracting officer. A new UID is generated whenever a new SPRS score is entered (e.g., at reassessment or 3-year renewal).&lt;br /&gt;
&lt;br /&gt;
==== 23. Creation of Exception ====&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Comment:&#039;&#039;&#039; Requests for exceptional-circumstance relief and small-business exemptions for second-tier suppliers.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Response:&#039;&#039;&#039; 32 CFR part 170 does not include an exemption for exceptional circumstances, and this DFARS rule cannot create one. DoD does not require flowdown to subcontractors that do not receive FCI or CUI.&lt;br /&gt;
&lt;br /&gt;
==== 24. Period of Performance ====&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Comment:&#039;&#039;&#039; Should contracting officers validate CMMC compliance before extending a period of performance?&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Response:&#039;&#039;&#039; Yes — 32 CFR part 170 requires CMMC statuses to be maintained for the life of the contract, so contracting officers must validate compliance before extending performance periods or exercising options.&lt;br /&gt;
&lt;br /&gt;
==== 25. Prime Contractor Protection From Subcontractor Noncompliance ====&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Comment:&#039;&#039;&#039; Clarify that primes won&#039;t be rendered ineligible due to subcontractor noncompliance.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Response:&#039;&#039;&#039; The Government does not establish the prime/subcontractor relationship and does not indemnify the prime from its subcontractors, as it lacks privity of contract with subcontractors.&lt;br /&gt;
&lt;br /&gt;
==== 26. Application of CMMC to FAR Part 16 Contract Types ====&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Comment:&#039;&#039;&#039; Require CMMC Program Office/USD(A&amp;amp;S) approval before applying CMMC to FAR part 16 contract types during phase-in.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Response:&#039;&#039;&#039; 32 CFR part 170 does not include such an approval process, and this rule cannot create one.&lt;br /&gt;
&lt;br /&gt;
==== 27. Acquiring Entities Without CMMC Certification ====&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Comment:&#039;&#039;&#039; How are newly acquired entities or new sites added to an existing certification?&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Response:&#039;&#039;&#039; Per DFARS 252.204–7021(c)(1), contractors must report changes to UIDs to the contracting officer. Adding new users to an existing system does not necessarily change the CMMC assessment scope (see 32 CFR 170.19).&lt;br /&gt;
&lt;br /&gt;
==== 28. Applicability to Civilian Agencies ====&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Comment:&#039;&#039;&#039; Does CMMC apply to CUI from non-DoD agencies?&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Response:&#039;&#039;&#039; This rule amends the DFARS and applies only to DoD or DoD-funded acquisitions.&lt;br /&gt;
&lt;br /&gt;
==== 29. Provision and Clause Clarifications ====&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Comment:&#039;&#039;&#039; Questions on subcontractor UID updates and the &amp;quot;unless electronically posted&amp;quot; language.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Response:&#039;&#039;&#039; The clause was updated to require subcontractors to enter self-assessment results in SPRS and complete annual affirmations, which they may share via screenshot. &amp;quot;Unless electronically posted&amp;quot; language was removed. Paragraph (c)(1) is excluded from subcontractor flowdown because the Government lacks privity of contract with subcontractors, though primes are encouraged to flow down similar language voluntarily.&lt;br /&gt;
&lt;br /&gt;
==== 30. Outside the Scope of the Rule ====&lt;br /&gt;
&lt;br /&gt;
DoD received numerous comments outside the scope of this rule, including topics related to: the DFARS Case 2022–D017 timeline; CUI marking and definitions; the CMMC Program&#039;s underlying policy at 32 CFR part 170 (permissible changes, exemptions for MWR/NAF procurements, ISO/IEC 27001 relationship, phase-in timeline, spot checks, FedRAMP, waivers, eMASS training, and more); cost impacts; and various sector-specific applicability questions (medical devices, furniture manufacturers, common carriers, etc.).&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Response (selected points):&#039;&#039;&#039;&lt;br /&gt;
* CMMC level selection is made by the program office/requiring activity per DoD policy and 32 CFR 170.5; contracting officers do not determine the level.&lt;br /&gt;
* All CUI categories require at least a self-assessment; DoD Organizational Index group CUI categories generally require a C3PAO assessment at minimum.&lt;br /&gt;
* MWR/NAF procurements requiring NIST SP 800–171 implementation are subject to the CMMC requirement.&lt;br /&gt;
* Waivers are established at 32 CFR 170.5 and are at the discretion of the program office/requiring activity, prior to contracting officer involvement.&lt;br /&gt;
* Contractors do not have access to CMMC eMASS (used only for certification assessments); all CMMC assessments are reflected in SPRS.&lt;br /&gt;
* Enclave scoping is determined by the contractor per 32 CFR 170.19.&lt;br /&gt;
* Reassessments are expected to be infrequent and DoD-conducted, per updates to 32 CFR part 170.&lt;br /&gt;
* Flowdown requirements are at 32 CFR 170.23.&lt;br /&gt;
&lt;br /&gt;
=== C. Other Changes ===&lt;br /&gt;
&lt;br /&gt;
* DFARS 204.7500 was updated to remove a web address and replace it with a reference to 32 CFR part 170.&lt;br /&gt;
* Clarified throughout that a higher CMMC level than required is also permissible.&lt;br /&gt;
* The term &amp;quot;CMMC status&amp;quot; was added throughout, clarifying that contracts may be awarded with a current Final Level 1 (Self), Conditional Level 2 (Self), Final Level 2 (Self), Conditional Level 2 (C3PAO), or Final Level 2 (C3PAO) CMMC status. A definition of &amp;quot;CMMC status&amp;quot; was added to DFARS subpart 204.75, clause 252.204–7021, and provision 252.204–7025.&lt;br /&gt;
&lt;br /&gt;
== III. Applicability to Contracts at or Below the SAT, Commercial Products, and Commercial Services ==&lt;br /&gt;
&lt;br /&gt;
The clause at DFARS 252.204–7021 is prescribed at DFARS 204.7504 for use:&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;Until November 9, 2028&#039;&#039;&#039; (three years after the effective date): in solicitations and contracts, task orders, or delivery orders — including FAR part 12 commercial product/service acquisitions, except those solely for COTS items — if the program office or requiring activity determines the contractor is required to have a specific CMMC level (unless 32 CFR 170.5(d) requirements are met).&lt;br /&gt;
* &#039;&#039;&#039;On or after November 10, 2028&#039;&#039;&#039;: in solicitations and contracts, task orders, or delivery orders — including FAR part 12 acquisitions, except those solely for COTS items — if the program office or requiring activity determines the contractor must use contractor information systems to process, store, or transmit FCI or CUI.&lt;br /&gt;
&lt;br /&gt;
The provision at DFARS 252.204–7025 is prescribed at DFARS 204.7504(b) for use in solicitations that include the clause at DFARS 252.204–7021.&lt;br /&gt;
&lt;br /&gt;
Consistent with DoD&#039;s analysis of section 1648 of the NDAA for FY 2020, DoD applies the statute (as implemented in these clause/provision) to contracts at or below the Simplified Acquisition Threshold (SAT), to commercial products (excluding COTS items), and to commercial services as defined at FAR 2.101.&lt;br /&gt;
&lt;br /&gt;
== IV. Expected Impact of the Rule ==&lt;br /&gt;
&lt;br /&gt;
=== A. Background ===&lt;br /&gt;
&lt;br /&gt;
DoD is amending the DFARS to implement contractual requirements tied to the CMMC policy (32 CFR part 170, 89 FR 83092, October 15, 2024). New solicitation/contractual requirements include:&lt;br /&gt;
&lt;br /&gt;
* Offeror/contractor requirement to post CMMC Level 1 or Level 2 self-assessment results to SPRS prior to award, option exercise, or period-of-performance extension, if not already posted.&lt;br /&gt;
* Contractor requirement to maintain the required CMMC status for the life of the contract.&lt;br /&gt;
* Contractor requirement for an affirming official to complete an annual affirmation of continuous compliance in SPRS for each applicable CMMC UID.&lt;br /&gt;
* Offeror/contractor requirement to identify contractor information systems used to process, store, or transmit FCI or CUI, by providing CMMC UIDs generated by SPRS.&lt;br /&gt;
&lt;br /&gt;
=== B. Summary of Impact ===&lt;br /&gt;
&lt;br /&gt;
The rule will be implemented over a phased, three-year period, after which it applies to all contracts where the contractor processes, stores, or transmits FCI or CUI on contractor information systems (except COTS-only contracts).&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Estimated impacted entities (Year 4 and beyond):&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Metric !! Value&lt;br /&gt;
|-&lt;br /&gt;
| Average unique entities awarded DoD contracts above micro-purchase threshold (FY2022–FY2024) || 32,756&lt;br /&gt;
|-&lt;br /&gt;
| Unique entities awarded using only commercial procedures || 18,370&lt;br /&gt;
|-&lt;br /&gt;
| Estimated COTS-only awardees (25% of 18,370) || 4,592&lt;br /&gt;
|-&lt;br /&gt;
| Unique entities after removing COTS-only awardees || 28,164&lt;br /&gt;
|-&lt;br /&gt;
| Assumed offerors per solicitation || 2&lt;br /&gt;
|-&lt;br /&gt;
| Total prime offerors (28,164 × 2) || 56,328&lt;br /&gt;
|-&lt;br /&gt;
| Assumed subcontractors per prime offer || 5&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;Total estimated impacted entities&#039;&#039;&#039; (primes + subcontractors) || &#039;&#039;&#039;337,968&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| Of which, small entities (68%) || 229,818&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Estimated time burden per contractor information system:&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
* Offerors/contractors: ~5 minutes to post CMMC self-assessment results in SPRS; ~5 minutes to complete the required affirmation; ~5 minutes to retrieve and submit CMMC UIDs.&lt;br /&gt;
* Government: ~5 minutes to validate CMMC level/currency prior to award, option exercise, or performance extension; ~5 minutes to validate affirmation currency; ~5 minutes to validate CMMC status/affirmation when UIDs change during performance.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Benefits:&#039;&#039;&#039; Verification of DIB contractors&#039; implementation of system security requirements, protection of CUI/FCI and intellectual property, and reduced exposure to malicious cyber activity. The Council of Economic Advisers estimated malicious cyber activity cost the U.S. economy $57–109 billion in 2016 (a 10-year burden of an estimated $400–765 billion at a 7% discount rate, or $486–929 billion at a 3% discount rate). GAO cited Treasury reporting that ransomware-related incidents reached $886 million in 2021.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Estimated public and Government costs over a 10-year period:&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Summary (3% discount rate) !! Public !! Government !! Total&lt;br /&gt;
|-&lt;br /&gt;
| Present Value || $329,097,922 || $15,812,069 || $344,909,991&lt;br /&gt;
|-&lt;br /&gt;
| Annualized Costs || $38,580,316 || $1,760,303 || $40,340,619&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Summary (7% discount rate) !! Public !! Government !! Total&lt;br /&gt;
|-&lt;br /&gt;
| Present Value || $254,756,766 || $11,533,649 || $266,290,415&lt;br /&gt;
|-&lt;br /&gt;
| Annualized Costs || $36,271,632 || $1,642,132 || $37,913,764&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== V. Executive Orders 12866 and 13563 ==&lt;br /&gt;
&lt;br /&gt;
This is a significant regulatory action, subject to review under section 6(b) of E.O. 12866, Regulatory Planning and Review, as amended.&lt;br /&gt;
&lt;br /&gt;
== VI. Executive Order 14192 ==&lt;br /&gt;
&lt;br /&gt;
This rule is &#039;&#039;&#039;not&#039;&#039;&#039; subject to E.O. 14192, because it is issued with respect to a national security function of the United States. Implementation of CMMC Program requirements is urgently needed to strengthen protection of DoD information, protect critical defense technologies from exfiltration, and protect the DIB&#039;s intellectual property and the broader U.S. economy from malicious cyber actors.&lt;br /&gt;
&lt;br /&gt;
== VII. Congressional Review Act ==&lt;br /&gt;
&lt;br /&gt;
DoD will submit the rule to the U.S. Senate, House of Representatives, and Comptroller General as required by the Congressional Review Act (5 U.S.C. 801–808). The Office of Information and Regulatory Affairs has determined this rule is &#039;&#039;&#039;not&#039;&#039;&#039; a major rule as defined by 5 U.S.C. 804(2).&lt;br /&gt;
&lt;br /&gt;
== VIII. Regulatory Flexibility Act ==&lt;br /&gt;
&lt;br /&gt;
A final regulatory flexibility analysis was prepared under 5 U.S.C. 601 &#039;&#039;et seq.&#039;&#039; Key points:&lt;br /&gt;
&lt;br /&gt;
* This rule responds to threats posed by malicious cyber activity targeting U.S. intellectual property and DoD CUI.&lt;br /&gt;
* Requirements apply to all offerors/contractors under a CMMC-requirement solicitation/contract: (1) post current CMMC status in SPRS; (2) maintain CMMC status for contract life; (3) provide CMMC UIDs to the contracting officer, with updates; (4) maintain a current affirmation of continuous compliance.&lt;br /&gt;
* These requirements do &#039;&#039;&#039;not&#039;&#039;&#039; apply to awards not involving FCI or CUI.&lt;br /&gt;
* No public comments were submitted in response to the initial regulatory flexibility analysis.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Estimated small entities impacted, phased rollout:&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Year !! Estimated Small Entities&lt;br /&gt;
|-&lt;br /&gt;
| Year 1 || 1,104&lt;br /&gt;
|-&lt;br /&gt;
| Year 2 || 5,565&lt;br /&gt;
|-&lt;br /&gt;
| Year 3 || 18,554&lt;br /&gt;
|-&lt;br /&gt;
| Year 4+ || 229,818&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Anticipated mix of CMMC statuses starting Year 4:&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! CMMC Level !! Percentage !! Small Entities !! Large Entities !! Total Entities&lt;br /&gt;
|-&lt;br /&gt;
| Level 1 Self-assessment || 62% || 142,487 || 67,053 || 209,540&lt;br /&gt;
|-&lt;br /&gt;
| Level 2 Self-assessment || 2% || 4,596 || 2,163 || 6,759&lt;br /&gt;
|-&lt;br /&gt;
| Level 2 Certificate || 35% || 80,436 || 37,853 || 118,289&lt;br /&gt;
|-&lt;br /&gt;
| Level 3 Certificate || 1% || 2,298 || 1,082 || 3,380&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;Total&#039;&#039;&#039; || &#039;&#039;&#039;100%&#039;&#039;&#039; || &#039;&#039;&#039;229,818&#039;&#039;&#039; || &#039;&#039;&#039;108,150&#039;&#039;&#039; || &#039;&#039;&#039;337,968&#039;&#039;&#039;&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;New reporting/recordkeeping requirements for small entities:&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
# Post current CMMC status (not covered by C3PAO/DIBCAC assessment) to SPRS for each applicable CMMC UID.&lt;br /&gt;
# Provide CMMC UIDs prior to award and upon any changes.&lt;br /&gt;
# Affirming official completes and maintains, annually (or upon compliance status change), the affirmation of continuous compliance in SPRS.&lt;br /&gt;
&lt;br /&gt;
DoD identified no alternatives that would accomplish the statutory objectives while further reducing small-entity burden; the phased rollout and COTS exemption are intended to minimize economic impact.&lt;br /&gt;
&lt;br /&gt;
== IX. Paperwork Reduction Act ==&lt;br /&gt;
&lt;br /&gt;
This final rule&#039;s information collection requirements have been approved by OMB under the Paperwork Reduction Act (44 U.S.C. chapter 35), OMB Control Number &#039;&#039;&#039;0750–0008&#039;&#039;&#039;, DFARS Part 204, Contractor Implementation of Cybersecurity Requirements.&lt;br /&gt;
&lt;br /&gt;
== List of Subjects in 48 CFR Parts 204, 212, 217, and 252 ==&lt;br /&gt;
&lt;br /&gt;
Government procurement.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Signed:&#039;&#039; Kimberly R. Ziegler, Editor/Publisher, Defense Acquisition Regulations System.&lt;br /&gt;
&lt;br /&gt;
The interim rule amending 48 CFR parts 204, 212, 217, and 252 (published at 85 FR 61505 on September 29, 2020) is adopted as final with the following changes.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Authority citation for parts 204, 212, 217, and 252:&#039;&#039;&#039; 41 U.S.C. 1303 and 48 CFR chapter 1.&lt;br /&gt;
&lt;br /&gt;
== PART 204—Administrative and Information Matters ==&lt;br /&gt;
&lt;br /&gt;
=== Subpart 204.75—Cybersecurity Maturity Model Certification ===&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Contents:&#039;&#039;&#039;&lt;br /&gt;
* 204.7500 Scope of subpart.&lt;br /&gt;
* 204.7501 Definitions.&lt;br /&gt;
* 204.7502 Policy.&lt;br /&gt;
* 204.7503 Procedures.&lt;br /&gt;
* 204.7504 Solicitation provision and contract clause.&lt;br /&gt;
&lt;br /&gt;
==== 204.7500 Scope of subpart ====&lt;br /&gt;
&lt;br /&gt;
(a) This subpart prescribes policies and procedures for including the Cybersecurity Maturity Model Certification (CMMC) level requirements in DoD contracts. CMMC is a framework (see 32 CFR part 170) for assessing a contractor&#039;s information security protections.&lt;br /&gt;
&lt;br /&gt;
(b) This subpart does not abrogate any other requirements regarding contractor physical, personnel, information, technical, or general administrative security operations governing the protection of unclassified information, nor does it affect requirements of the National Industrial Security Program.&lt;br /&gt;
&lt;br /&gt;
(c) This subpart applies to unclassified contractor information systems.&lt;br /&gt;
&lt;br /&gt;
==== 204.7501 Definitions ====&lt;br /&gt;
&lt;br /&gt;
As used in this subpart—&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Controlled unclassified information&#039;&#039;&#039; means information the Government creates or possesses, or information an entity creates or possesses for or on behalf of the Government, that a law, regulation, or Governmentwide policy requires or permits an agency to handle using safeguarding or dissemination controls (32 CFR 2002.4(h)).&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Current&#039;&#039;&#039; means—&lt;br /&gt;
&lt;br /&gt;
(1) With regard to Conditional Cybersecurity Maturity Model Certification (CMMC) Status—&lt;br /&gt;
&lt;br /&gt;
:(i) Not older than 180 days for Conditional Level 2 (Self) assessments and Conditional Level 2 (certified third-party assessment organization (C3PAO)) assessments, with—&lt;br /&gt;
::(A) No changes in compliance with the requirements at 32 CFR part 170 since the Conditional CMMC Status date (see 32 CFR 170.16 and 170.17); and&lt;br /&gt;
::(B) A corresponding affirmation of continuous compliance by an affirming official (see 32 CFR 170.4); and&lt;br /&gt;
&lt;br /&gt;
:(ii) Not older than 180 days for Conditional Level 3 (Defense Industrial Base Cybersecurity Assessment Center (DIBCAC)) assessments, with—&lt;br /&gt;
::(A) No changes in compliance with the requirements at 32 CFR part 170 since the Conditional CMMC Status date (see 32 CFR 170.18); and&lt;br /&gt;
::(B) A corresponding affirmation of continuous compliance by an affirming official;&lt;br /&gt;
&lt;br /&gt;
(2) With regard to Final CMMC Status—&lt;br /&gt;
&lt;br /&gt;
:(i) Not older than 1 year for Final Level 1 (Self), with—&lt;br /&gt;
::(A) No changes in compliance with the requirements at 32 CFR part 170 since the Final CMMC Status date (see 32 CFR 170.15); and&lt;br /&gt;
::(B) A corresponding affirmation of continuous compliance, not older than 1 year, by an affirming official;&lt;br /&gt;
&lt;br /&gt;
:(ii) Not older than 3 years for Final Level 2 (Self) assessments and Final Level 2 (C3PAO) assessments, with—&lt;br /&gt;
::(A) No changes in compliance with the requirements at 32 CFR part 170 since the Final CMMC Status date (see 32 CFR 170.16 and 170.17); and&lt;br /&gt;
::(B) A corresponding affirmation of continuous compliance, not older than 1 year, by an affirming official; and&lt;br /&gt;
&lt;br /&gt;
:(iii) Not older than 3 years for Final Level 3 (DIBCAC) assessments, with—&lt;br /&gt;
::(A) No changes in compliance with the requirements at 32 CFR part 170 since the Final CMMC Status date (see 32 CFR 170.18); and&lt;br /&gt;
::(B) A corresponding affirmation of continuous compliance, not older than 1 year, by an affirming official; and&lt;br /&gt;
&lt;br /&gt;
(3) With regard to affirmation of continuous compliance (32 CFR 170.22), not older than 1 year with no changes in compliance with the requirements at 32 CFR part 170.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Cybersecurity Maturity Model Certification (CMMC) status&#039;&#039;&#039; means the result of meeting or exceeding the minimum required score for the corresponding assessment. The potential statuses are as follows:&lt;br /&gt;
&lt;br /&gt;
# Final Level 1 (Self).&lt;br /&gt;
# Conditional Level 2 (Self).&lt;br /&gt;
# Final Level 2 (Self).&lt;br /&gt;
# Conditional Level 2 (C3PAO).&lt;br /&gt;
# Final Level 2 (C3PAO).&lt;br /&gt;
# Conditional Level 3 (DIBCAC).&lt;br /&gt;
# Final Level 3 (DIBCAC).&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Cybersecurity Maturity Model Certification unique identifier (CMMC UID)&#039;&#039;&#039; means 10 alpha-numeric characters assigned to each CMMC assessment and reflected in the Supplier Performance Risk System (SPRS) for each contractor information system.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Federal contract information (FCI)&#039;&#039;&#039; means information, not intended for public release, that is provided by or generated for the Government under a contract to develop or deliver a product or service to the Government. It does not include information provided by the Government to the public, such as on public websites, or simple transactional information, such as information necessary to process payments.&lt;br /&gt;
&lt;br /&gt;
==== 204.7502 Policy ====&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;(a) Award eligibility.&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
(1) The contracting officer shall include in the solicitation the required CMMC level, if provided by the program office or the requiring activity.&lt;br /&gt;
&lt;br /&gt;
(2) Contracting officers shall not award a contract, task order, or delivery order to an offeror that does not have a current CMMC status at the CMMC level required by the solicitation.&lt;br /&gt;
&lt;br /&gt;
(3) Contractors are required to achieve, at time of award, a CMMC status at the CMMC level specified in the solicitation, or higher, for all information systems used in the performance of the contract, task order, or delivery order that will process, store, or transmit FCI or CUI. Contractors are required to maintain a current CMMC status at the specified CMMC level or higher, if required by the contract, task order, or delivery order, throughout the life of the contract, task order, or delivery order.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;(b) CMMC status.&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
(1) Contracting officers may award a contract, task order, delivery order, or modification to exercise an option or extend a period of performance, if the offeror&#039;s or contractor&#039;s CMMC status is—&lt;br /&gt;
&lt;br /&gt;
:(i) Listed in the definition of &amp;quot;CMMC status&amp;quot;; and&lt;br /&gt;
:(ii) Equal to or higher than the CMMC level required by the solicitation or contract, task order, or delivery order.&lt;br /&gt;
&lt;br /&gt;
(2) CMMC levels 2 and 3 can be in a conditional level for a period not to exceed 180 days from the CMMC status date (32 CFR 170.21), and award can occur with a conditional CMMC level. CMMC level 1 requires a final CMMC level for award.&lt;br /&gt;
&lt;br /&gt;
==== 204.7503 Procedures ====&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;(a) CMMC level.&#039;&#039;&#039; The contracting officer shall include the CMMC level (see 32 CFR 170.19) required by the program office or requiring activity in the solicitation provision and contract clause prescribed at 204.7504.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;(b) Award.&#039;&#039;&#039; Contracting officers shall check SPRS and not award a contract, task order, or delivery order to an offeror that does not have a current CMMC status posted in SPRS at the CMMC level (see 32 CFR 170.15 through 170.18) required by the solicitation, or higher, for each CMMC UID provided by the offeror. The CMMC UIDs are applicable to each of the contractor information systems that will process, store, or transmit FCI or CUI and that will be used in performance of the contract.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;(c) Option exercise or period of performance extension.&#039;&#039;&#039; Contracting officers shall check SPRS and not exercise an option or extend the period of performance on a contract, task order, or delivery order, unless the contractor has a current CMMC status posted in SPRS at the CMMC level (see 32 CFR 170.15 through 170.18) required by the contract, task order, or delivery order, or higher, for each CMMC UID provided by the contractor. The contractor&#039;s CMMC UIDs are applicable to each of the contractor information systems that process, store, or transmit FCI or CUI and that are or will be used in performance of the contract.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;(d) CMMC UIDs.&#039;&#039;&#039; If the contractor provides new CMMC UIDs during performance of the contract, task order, or delivery order, the contracting officer shall check in SPRS, using the CMMC UIDs assigned by SPRS, that the contractor has a current CMMC status at the required CMMC level, or higher, for each of the contractor information systems identified that will process, store, or transmit FCI or CUI during contract performance.&lt;br /&gt;
&lt;br /&gt;
==== 204.7504 Solicitation provision and contract clause ====&lt;br /&gt;
&lt;br /&gt;
(a) Unless the requirements at 32 CFR 170.5(d) are met, use the clause at 252.204–7021, &#039;&#039;Contractor Compliance with the Cybersecurity Maturity Model Certification Level Requirements&#039;&#039;, as follows:&lt;br /&gt;
&lt;br /&gt;
(1) &#039;&#039;&#039;Until November 9, 2028&#039;&#039;&#039;, in solicitations and contracts, task orders, or delivery orders, including those using FAR part 12 procedures for the acquisition of commercial products and commercial services, except for those solely for the acquisition of commercially available off-the-shelf (COTS) items, if the program office or requiring activity determines that the contractor is required to have a specific CMMC level.&lt;br /&gt;
&lt;br /&gt;
(2) &#039;&#039;&#039;On or after November 10, 2028&#039;&#039;&#039;, in solicitations and contracts, task orders, or delivery orders, including those using FAR part 12 procedures for the acquisition of commercial products and commercial services, except for those solely for the acquisition of COTS items, if the program office or requiring activity determines that the contractor is required to use contractor information systems in the performance of the contract, task order, or delivery order to process, store, or transmit FCI or CUI.&lt;br /&gt;
&lt;br /&gt;
(b) Use the provision at 252.204–7025, &#039;&#039;Notice of Cybersecurity Maturity Model Certification Level Requirements&#039;&#039;, in solicitations that include the clause at 252.204–7021.&lt;br /&gt;
&lt;br /&gt;
== PART 212—Acquisition of Commercial Products and Commercial Services ==&lt;br /&gt;
&lt;br /&gt;
=== 212.301 Solicitation provisions and contract clauses for the acquisition of commercial products and commercial services ===&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Amendment:&#039;&#039;&#039;&lt;br /&gt;
* In paragraph (f)(ii)(L), remove &amp;quot;204.7503 (a) and (b)&amp;quot; and add &amp;quot;204.7504(a)&amp;quot; in its place.&lt;br /&gt;
* Add paragraph (f)(ii)(P):&lt;br /&gt;
&lt;br /&gt;
:(P) Use the provision at 252.204–7025, Notice of Cybersecurity Maturity Model Certification Level Requirements, as prescribed in 204.7504(b).&lt;br /&gt;
&lt;br /&gt;
== PART 217—Special Contracting Methods ==&lt;br /&gt;
&lt;br /&gt;
=== 217.207 Exercise of options ===&lt;br /&gt;
&lt;br /&gt;
(c) In addition to the requirements at FAR 17.207(c), exercise an option only after—&lt;br /&gt;
&lt;br /&gt;
(1) Determining that the contractor&#039;s record in the System for Award Management database is active and the contractor&#039;s unique entity identifier number, Commercial and Government Entity (CAGE) code, name, and physical address are accurately reflected in the contract document. (See PGI 217.207 for the requirement to perform cost or price analysis of spare parts prior to exercising any option for firm-fixed-price contracts containing spare parts.); and&lt;br /&gt;
&lt;br /&gt;
(2) Working with the program office or requiring activity to verify in the Supplier Performance Risk System (https://piee.eb.mil) that—&lt;br /&gt;
&lt;br /&gt;
:(i) The summary level score of a current NIST SP 800–171 DoD Assessment (i.e., not more than 3 years old, unless a lesser time is specified in the solicitation) for each covered contractor information system that is relevant to an offer, contract, task order, or delivery order are posted (see 204.7303); and&lt;br /&gt;
&lt;br /&gt;
:(ii) If there is a requirement for the contractor to have a Cybersecurity Maturity Model Certification (CMMC) status at a specific CMMC level, the contractor has a current CMMC status at the CMMC level required by the contract, or higher, for each of the CMMC unique identifiers applicable to each of the contractor information systems that process, store, or transmit Federal contract information or controlled unclassified information (see 204.7503(c)).&lt;br /&gt;
&lt;br /&gt;
== PART 252—Solicitation Provisions and Contract Clauses ==&lt;br /&gt;
&lt;br /&gt;
=== 252.204–7021 Contractor Compliance With the Cybersecurity Maturity Model Certification Level Requirements ===&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;As prescribed in 204.7504(a), use the following clause:&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;CONTRACTOR COMPLIANCE WITH THE CYBERSECURITY MATURITY MODEL CERTIFICATION LEVEL REQUIREMENTS (NOV 2025)&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;(a) Definitions.&#039;&#039;&#039; As used in this clause—&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Controlled unclassified information&#039;&#039;&#039; means information the Government creates or possesses, or information an entity creates or possesses for or on behalf of the Government, that a law, regulation, or Governmentwide policy requires or permits an agency to handle using safeguarding or dissemination controls (32 CFR 2002.4(h)).&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Current&#039;&#039;&#039; means— &#039;&#039;(see definition under DFARS 204.7501 above, which is incorporated identically into this clause)&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Cybersecurity Maturity Model Certification (CMMC) status&#039;&#039;&#039; means the result of meeting or exceeding the minimum required score for the corresponding assessment. The potential statuses are as follows:&lt;br /&gt;
&lt;br /&gt;
# Final Level 1 (Self).&lt;br /&gt;
# Conditional Level 2 (Self).&lt;br /&gt;
# Final Level 2 (Self).&lt;br /&gt;
# Conditional Level 2 (C3PAO).&lt;br /&gt;
# Final Level 2 (C3PAO).&lt;br /&gt;
# Conditional Level 3 (DIBCAC).&lt;br /&gt;
# Final Level 3 (DIBCAC).&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Cybersecurity Maturity Model Certification unique identifier (CMMC UID)&#039;&#039;&#039; means 10 alpha-numeric characters assigned to each CMMC assessment and reflected in the Supplier Performance Risk System (SPRS) for each contractor information system.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Federal contract information (FCI)&#039;&#039;&#039; means information, not intended for public release, that is provided by or generated for the Government under a contract to develop or deliver a product or service to the Government. It does not include information provided by the Government to the public, such as on public websites, or simple transactional information, such as information necessary to process payments.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Plan of action and milestones&#039;&#039;&#039; means a document that identifies tasks to be accomplished. It details resources required to accomplish the elements of the plan, any milestones in meeting the tasks, and scheduled completion dates for the milestones, as defined in National Institute of Standards and Technology Special Publication 800–115 (32 CFR 170.21).&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;(b) Framework.&#039;&#039;&#039; The Cybersecurity Maturity Model Certification (CMMC) is a framework for assessing a contractor&#039;s compliance with applicable information security protections (see 32 CFR part 170).&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;(c) Duplication.&#039;&#039;&#039; The CMMC assessments will not duplicate efforts from any other comparable DoD assessment, except for rare circumstances when a reassessment may be necessary, for example, when there are indications of issues with cybersecurity and/or compliance with CMMC requirements.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;(d) Requirements.&#039;&#039;&#039; The Contractor shall—&lt;br /&gt;
&lt;br /&gt;
(1)(i) Have and maintain for the duration of the contract a current CMMC status at the following CMMC level, or higher: _____ [Contracting Officer insert: CMMC Level 1 (Self); CMMC Level 2 (Self); CMMC Level 2 (C3PAO); or CMMC Level 3 (DIBCAC)] for all information systems used in performance of the contract, task order, or delivery order that process, store, or transmit FCI or CUI; and&lt;br /&gt;
&lt;br /&gt;
:(ii) Consult 32 CFR 170.23 related to the flowdown of the CMMC requirements, and flow down the correct CMMC level to subcontracts and other contractual instruments;&lt;br /&gt;
&lt;br /&gt;
(2) Only process, store, or transmit FCI or CUI on contractor information systems that have a CMMC status at the CMMC level required in paragraph (d)(1) of this clause, or higher;&lt;br /&gt;
&lt;br /&gt;
(3) Complete on an annual basis, and maintain as current, an affirmation, by the affirming official (see 32 CFR 170.4), of continuous compliance with the requirements associated with the CMMC level required in paragraph (d)(1) of this clause in the Supplier Performance Risk System (SPRS) (https://piee.eb.mil) for each CMMC UID applicable to each of the contractor information systems that process, store, or transmit FCI or CUI and that are used in performance of the contract;&lt;br /&gt;
&lt;br /&gt;
(4) Ensure all subcontractors and suppliers complete prior to subcontract award, and maintain on an annual basis, an affirmation, by the affirming official (see 32 CFR 170.4), of continuous compliance with the requirements associated with the CMMC level required for the subcontract or other contractual instrument for each of the subcontractor information systems that process, store, or transmit FCI or CUI and that are used in performance of the subcontract; and&lt;br /&gt;
&lt;br /&gt;
(5) If the Contractor has a CMMC Status of Conditional, successfully close out a valid plan of action and milestones (32 CFR 170.21) to achieve a CMMC Status of Final.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;(e) Reporting.&#039;&#039;&#039; The Contractor shall—&lt;br /&gt;
&lt;br /&gt;
(1) Submit to the Contracting Officer—&lt;br /&gt;
&lt;br /&gt;
:(i) The CMMC UID(s) issued by SPRS for contractor information systems that will process, store, or transmit FCI or CUI during performance of the contract; and&lt;br /&gt;
&lt;br /&gt;
:(ii) Any changes in the CMMC UIDs generated in SPRS throughout the life of the contract, task order, or delivery order, if applicable;&lt;br /&gt;
&lt;br /&gt;
(2) Enter into SPRS the results of a current self-assessment for each CMMC UID, not covered by a C3PAO assessment or DIBCAC assessment, applicable to each of the contractor information systems that process, store, or transmit FCI or CUI and that are used in performance of the contract; and&lt;br /&gt;
&lt;br /&gt;
(3) Complete in SPRS on an annual basis and maintain as current an affirmation of continuous compliance by the affirming official (see 32 CFR 170.4) for each self-assessment, C3PAO assessment, or DIBCAC assessment required under the contract in SPRS.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;(f) Subcontracts.&#039;&#039;&#039; The Contractor shall—&lt;br /&gt;
&lt;br /&gt;
(1) Insert the substance of this clause, including this paragraph (f) and excluding paragraph (e)(1), in subcontracts and other contractual instruments, including those for the acquisition of commercial products and commercial services, excluding commercially available off-the-shelf items, if the subcontract or other contractual instrument will contain a requirement to process, store, or transmit FCI or CUI; and&lt;br /&gt;
&lt;br /&gt;
(2) Prior to awarding a subcontract or other contractual instrument, ensure that the subcontractor has a current CMMC certificate or current CMMC status at the CMMC level that is appropriate for the information that is being flowed down to the subcontractor based on the requirements at 32 CFR 170.23.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;(End of clause)&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
=== 252.204–7025 Notice of Cybersecurity Maturity Model Certification Level Requirements ===&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;As prescribed in 204.7504(b), use the following provision:&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;NOTICE OF CYBERSECURITY MATURITY MODEL CERTIFICATION LEVEL REQUIREMENTS (NOV 2025)&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;(a) Definitions.&#039;&#039;&#039; As used in this provision, &#039;&#039;controlled unclassified information (CUI)&#039;&#039;, &#039;&#039;current&#039;&#039;, &#039;&#039;Cybersecurity Maturity Model Certification (CMMC) status&#039;&#039;, &#039;&#039;Cybersecurity Maturity Model Certification unique identifier (CMMC UID)&#039;&#039;, &#039;&#039;Federal contract information (FCI)&#039;&#039;, and &#039;&#039;Plan of action and milestones&#039;&#039; have the meaning given in the Defense Federal Acquisition Regulation Supplement 252.204–7021, &#039;&#039;Contractor Compliance With the Cybersecurity Maturity Model Certification Level Requirements&#039;&#039;, clause of this solicitation.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;(b)(1) Cybersecurity Maturity Model Certification (CMMC) level.&#039;&#039;&#039; The CMMC level required by this solicitation is: _____ [Contracting Officer insert: CMMC Level 1 (Self); CMMC Level 2 (Self); CMMC Level 2 (C3PAO); or CMMC Level 3 (DIBCAC)]. This CMMC level, or higher (see 32 CFR part 170), is required prior to award for each contractor information system that will process, store, or transmit Federal contract information (FCI) or controlled unclassified information (CUI) during performance of the contract.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;(2)&#039;&#039;&#039; The Offeror will not be eligible for award of a contract, task order, or delivery order resulting from this solicitation if the Offeror does not have, for each of the contractor information systems that will process, store, or transmit FCI or CUI and that will be used in performance of a contract resulting from this solicitation—&lt;br /&gt;
&lt;br /&gt;
:(i) The current CMMC status entered in the Supplier Performance Risk System (SPRS) (https://piee.eb.mil) at the CMMC level required by paragraph (b)(1) of this provision; and&lt;br /&gt;
&lt;br /&gt;
:(ii) A current affirmation of continuous compliance with the security requirements identified at 32 CFR part 170 in SPRS.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;(c) Plan of action and milestones.&#039;&#039;&#039; If the Offeror has a CMMC Status of Conditional, the Offeror shall successfully close out a valid plan of action and milestones (32 CFR 170.21) to achieve a CMMC Status of Final.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;(d) CMMC unique identifiers.&#039;&#039;&#039; The Offeror shall provide, in the proposal, the CMMC unique identifier(s) (CMMC UIDs) issued by SPRS for each contractor information system that will process, store, or transmit FCI or CUI during performance of a contract, task order, or delivery order resulting from this solicitation. The Offeror also shall update the list when new CMMC UIDs are generated in SPRS. The CMMC UIDs are provided in SPRS after the Offeror enters the results of self-assessment(s) for each such information system.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;(End of provision)&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;[FR Doc. 2025–17359 Filed 9–9–25; 8:45 am]&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;BILLING CODE 6001–FR–P&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
[[Category:Federal Register]]&lt;br /&gt;
[[Category:DFARS]]&lt;br /&gt;
[[Category:Cybersecurity Maturity Model Certification]]&lt;br /&gt;
[[Category:Defense Acquisition Regulations]]&lt;/div&gt;</summary>
		<author><name>David</name></author>
	</entry>
	<entry>
		<id>https://cmmcwiki.org/index.php?title=48_CFR_Parts_204_212_217_252&amp;diff=1630</id>
		<title>48 CFR Parts 204 212 217 252</title>
		<link rel="alternate" type="text/html" href="https://cmmcwiki.org/index.php?title=48_CFR_Parts_204_212_217_252&amp;diff=1630"/>
		<updated>2026-07-26T01:21:12Z</updated>

		<summary type="html">&lt;p&gt;David: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{DISPLAYTITLE:Defense Federal Acquisition Regulation Supplement: Assessing Contractor Implementation of Cybersecurity Requirements (DFARS Case 2019–D041)}}&lt;br /&gt;
&#039;&#039;&#039;Source of Reference: The official [https://www.federalregister.gov/documents/2025/09/10/2025-17359/defense-federal-acquisition-regulation-supplement-assessing-contractor-implementation-of Defense Federal Acquisition Regulation Supplement: Assessing Contractor Implementation of Cybersecurity Requirements (DFARS Case 2019-D041)] final rule.&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
For inquiries and reporting errors on this wiki, please [mailto:support@cmmcwiki.org contact us]. Thank you.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Federal Register&#039;&#039;&#039; / Vol. 90, No. 173 / Wednesday, September 10, 2025 / Rules and Regulations&lt;br /&gt;
&lt;br /&gt;
== Agency Information ==&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Field !! Value&lt;br /&gt;
|-&lt;br /&gt;
| Agency || Defense Acquisition Regulations System, Department of Defense (DoD)&lt;br /&gt;
|-&lt;br /&gt;
| Action || Final rule&lt;br /&gt;
|-&lt;br /&gt;
| Docket || DARS–2020–0034&lt;br /&gt;
|-&lt;br /&gt;
| RIN || 0750–AK81&lt;br /&gt;
|-&lt;br /&gt;
| Effective Date || November 10, 2025&lt;br /&gt;
|-&lt;br /&gt;
| Contact || Ms. Heather Kitchens, telephone 571–296–7152&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Summary ==&lt;br /&gt;
&lt;br /&gt;
DoD is issuing a final rule amending the Defense Federal Acquisition Regulation Supplement (DFARS) to incorporate contractual requirements related to the final Cybersecurity Maturity Model Certification (CMMC) program rule. This final DFARS rule also partially implements a section of the National Defense Authorization Act for Fiscal Year 2020 that directed the Secretary of Defense to develop a consistent, comprehensive framework to enhance cybersecurity for the U.S. defense industrial base.&lt;br /&gt;
&lt;br /&gt;
== I. Background ==&lt;br /&gt;
&lt;br /&gt;
* DoD published an interim rule in the Federal Register at 85 FR 61505 on September 29, 2020, to assess contractor implementation of cybersecurity requirements and enhance the protection of unclassified information within the DoD supply chain.&lt;br /&gt;
* DoD subsequently published a proposed rule at 89 FR 66327 on August 15, 2024, to implement the contractual requirements related to CMMC. Ninety-seven respondents submitted public comments in response to the proposed rule.&lt;br /&gt;
* Separately, a proposed rule to establish the CMMC program at 32 CFR part 170 was published at 88 FR 89058 on December 26, 2023. A final rule was published at 89 FR 83092 on October 15, 2024, and became effective on December 16, 2024.&lt;br /&gt;
&lt;br /&gt;
== II. Discussion and Analysis ==&lt;br /&gt;
&lt;br /&gt;
=== A. Summary of Significant Changes From the Proposed Rule ===&lt;br /&gt;
&lt;br /&gt;
==== 1. Definitions ====&lt;br /&gt;
&lt;br /&gt;
The final rule adds and modifies certain definitions at DFARS 204.7501, Definitions.&lt;br /&gt;
&lt;br /&gt;
* The definition of &amp;quot;current&amp;quot; was changed to clarify that it is related to having no changes in compliance with the requirements at 32 CFR part 170, and to clarify what &amp;quot;current&amp;quot; means when referring to &amp;quot;Conditional CMMC Status,&amp;quot; &amp;quot;Final CMMC Status,&amp;quot; and &amp;quot;affirmation of continuous compliance.&amp;quot;&lt;br /&gt;
* The term &amp;quot;DoD unique identifier&amp;quot; was updated to &amp;quot;CMMC unique identifier&amp;quot; to match the naming convention in the Supplier Performance Risk System (SPRS). The CMMC UID means ten alpha-numeric characters assigned to each contractor CMMC assessment and reflected in SPRS for each contractor information system.&lt;br /&gt;
* The final rule adds the definition of &amp;quot;Federal contract information&amp;quot; based on the definition from the clause at FAR 52.204–21.&lt;br /&gt;
* The final rule adds a definition of &amp;quot;plan of action and milestones&amp;quot; (POA&amp;amp;M) based on the definition codified at 32 CFR part 170.&lt;br /&gt;
* The final rule adds the term &amp;quot;CMMC status&amp;quot; and a definition for the term.&lt;br /&gt;
&lt;br /&gt;
==== 2. Policy ====&lt;br /&gt;
&lt;br /&gt;
DFARS 204.7502, Policy, includes language to add clarity by stating that for CMMC levels 2 and 3 only, a conditional CMMC status is permitted for a period not to exceed 180 days from the conditional CMMC date, in accordance with 32 CFR 170.21, and an award can occur with a CMMC conditional status. The language also clarifies that a final CMMC is achieved upon successful closeout of a valid POA&amp;amp;M.&lt;br /&gt;
&lt;br /&gt;
==== 3. Procedures ====&lt;br /&gt;
&lt;br /&gt;
* Language at DFARS 204.7503 was updated to add paragraph headings.&lt;br /&gt;
* Language clarifies that contracting officers are required to check SPRS and not award a contract, task order, or delivery order to an offeror that does not have a current CMMC status posted in SPRS at the CMMC level required by the solicitation, or higher, for each CMMC UID provided by the offeror.&lt;br /&gt;
* Paragraph (d) clarifies that all offerors are required to provide the CMMC UIDs applicable to each contractor information system that processes, stores, or transmits FCI or CUI and that will be used in performance of the contract.&lt;br /&gt;
&lt;br /&gt;
==== 4. Clause Prescription ====&lt;br /&gt;
&lt;br /&gt;
At DFARS 204.7504, the prescription for the contract clause has been updated to clarify the phased implementation approach:&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;Until three years after the effective date of the rule&#039;&#039;&#039;: the clause will be prescribed for use if program managers and requiring activities make a determination to apply a CMMC requirement to contracts, excluding awards solely for the acquisition of commercially available off-the-shelf (COTS) items (unless the requirements at 32 CFR 170.5(d) are met).&lt;br /&gt;
* &#039;&#039;&#039;Beginning three years and one day after the effective date of the rule&#039;&#039;&#039;: the clause will be prescribed for use if program managers and requiring activities determine that the contractor will be required to use contractor information systems in the performance of the contract to process, store, or transmit FCI or CUI, excluding awards solely for the acquisition of COTS items.&lt;br /&gt;
&lt;br /&gt;
==== 5. Solicitation Provision and Contract Clause ====&lt;br /&gt;
&lt;br /&gt;
* The contract clause has been updated to include a fill-in for the contracting officer to identify the CMMC level required by the contract.&lt;br /&gt;
* The subcontract flowdown language has been updated to identify that subcontractors also must submit affirmations of continuous compliance and the results of self-assessments in SPRS.&lt;br /&gt;
* The clause has been updated to include the term &amp;quot;affirming official&amp;quot; in place of &amp;quot;senior company official&amp;quot; to match 32 CFR part 170.&lt;br /&gt;
* The solicitation provision and contract clause include the terminology needed for entering the CMMC level: &#039;&#039;&#039;CMMC Level 1 (Self)&#039;&#039;&#039;; &#039;&#039;&#039;CMMC Level 2 (Self)&#039;&#039;&#039;; &#039;&#039;&#039;CMMC Level 2 (C3PAO)&#039;&#039;&#039;; or &#039;&#039;&#039;CMMC Level 3 (DIBCAC)&#039;&#039;&#039;.&lt;br /&gt;
* The solicitation provision clarifies that offerors will not be eligible for award if the offeror does not have a current CMMC status entered in SPRS at the required level and a current affirmation of continuous compliance for each applicable contractor information system.&lt;br /&gt;
&lt;br /&gt;
=== B. Analysis of Public Comments ===&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Note: Technical and programmatic comments on CMMC, and comments related to the CMMC cost analysis, were addressed in the CMMC program rule that codified 32 CFR part 170. This DFARS rule addresses the nontechnical and nonprogrammatic comments.&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
==== 1. Clarification of &amp;quot;Changes&amp;quot; ====&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Comment:&#039;&#039;&#039; Several respondents asked for more clarity regarding what &amp;quot;changes&amp;quot; means in the proposed rule.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Response:&#039;&#039;&#039; Based on public comment, the final DFARS rule adds the sentence: &amp;quot;Submit to the Contracting Officer . . . any changes in the CMMC UIDs generated in SPRS throughout the life of the contract, task order, or delivery order, if applicable.&amp;quot; The notification requirement to report lapses in information security or changes in compliance with 32 CFR part 170 was removed, since the reporting requirement at DFARS 252.204–7012 paragraph (c) already provides sufficient notification of relevant information security incidents.&lt;br /&gt;
&lt;br /&gt;
==== 2. Clarification of &amp;quot;Lapses in Information Security&amp;quot; ====&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Comment:&#039;&#039;&#039; Several respondents asked for clarity on &amp;quot;lapses in information security&amp;quot; in proposed paragraph (b)(4) at DFARS 252.204–7021; several recommended it be removed.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Response:&#039;&#039;&#039; The requirement to notify the contracting officer of lapses in information security or changes in CMMC status has been removed from the final rule.&lt;br /&gt;
&lt;br /&gt;
==== 3. Editorial Changes ====&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Comment:&#039;&#039;&#039; Respondents identified typos and recommended using &amp;quot;and/or&amp;quot; instead of &amp;quot;or&amp;quot; for CMMC UIDs.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Response:&#039;&#039;&#039; Editorial comments were noted; most were mooted by other final-rule changes. The &amp;quot;and/or&amp;quot; recommendation was &#039;&#039;&#039;not&#039;&#039;&#039; implemented because it could narrow the scope of the requirement beyond what was intended.&lt;br /&gt;
&lt;br /&gt;
==== 4. CMMC Level Notification and Compliance ====&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Comment:&#039;&#039;&#039; Respondents asked how the required CMMC level will be communicated and determined, and requested clarity on phase-in exemptions for small businesses.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Response:&#039;&#039;&#039; The CMMC level determination is made in accordance with 32 CFR 170.19 (CMMC scoping) by the program office/requiring activity (for the prime contract) or the prime/next higher-tier subcontractor (for subcontracts). CMMC levels are: CMMC Level 1 (Self); CMMC Level 2 (Self); CMMC Level 2 (C3PAO); and CMMC Level 3 (DIBCAC) (see 32 CFR 170.14). DoD did not incorporate the recommendation to limit CMMC inclusion in existing contracts, as contracting officers already have discretion to bilaterally modify existing contracts.&lt;br /&gt;
&lt;br /&gt;
==== 5. COTS Item Exclusion ====&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Comment:&#039;&#039;&#039; Respondents requested clarification on the scope of the COTS exclusion.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Response:&#039;&#039;&#039; The rule does not apply to awards that are exclusively for COTS items, as defined at FAR 2.101. Any award exclusively for items meeting the FAR definition is considered an &amp;quot;exclusively COTS&amp;quot; award.&lt;br /&gt;
&lt;br /&gt;
==== 6. Extending the Certification Time for New Bidders ====&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Comment:&#039;&#039;&#039; A respondent requested an extension of certification time for new bidders.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Response:&#039;&#039;&#039; Per 32 CFR part 170, contractors must have a CMMC self-assessment or certification at time of award; there is no delayed implementation for new bidders, though 32 CFR 170.21 allows a POA&amp;amp;M in certain instances.&lt;br /&gt;
&lt;br /&gt;
==== 7. Flowdown Requirements When Subcontractors Use Prime Contractor Information System ====&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Comment:&#039;&#039;&#039; Respondents asked about flowdown when subcontractors use the prime&#039;s information system rather than their own.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Response:&#039;&#039;&#039; A subcontractor that does not process, store, or transmit FCI or CUI on its own systems has no CMMC assessment requirement. DoD does not have an automated tool giving primes visibility into subcontractor certification status in SPRS, but subcontractors may voluntarily share scores/certificates.&lt;br /&gt;
&lt;br /&gt;
==== 8. Definitions ====&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;a. CUI&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Comment:&#039;&#039;&#039; Respondents asked to define CUI and streamline it with &amp;quot;covered defense information.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Response:&#039;&#039;&#039; The definition of CUI incorporates the definition codified at 32 CFR part 170; modifying it further is outside the scope of this rule.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;b. FCI&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Comment:&#039;&#039;&#039; A respondent requested clarification of &amp;quot;not intended for public release&amp;quot; and &amp;quot;simple transactional information,&amp;quot; and whether FOIA-subject information is still FCI.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Response:&#039;&#039;&#039; A definition of FCI was added, based on FAR 52.204–21, with &amp;quot;information necessary to process payments&amp;quot; as an example of simple transactional information. Marking/FOIA comments are outside scope.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;c. Current&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Comment:&#039;&#039;&#039; Clarify whether &amp;quot;current&amp;quot; refers to date of assessment or date of certification.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Response:&#039;&#039;&#039; The final rule changes the definition of &amp;quot;current&amp;quot; to address this; the underlying requirements were established in 32 CFR part 170, and DoD cannot make changes beyond that in this DFARS rule.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;d. Data&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Comment:&#039;&#039;&#039; Respondents asked that &amp;quot;data&amp;quot; be replaced with &amp;quot;FCI and/or CUI&amp;quot; to narrow scope.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Response:&#039;&#039;&#039; Based on public comments, the rule was revised to remove the term &amp;quot;data.&amp;quot; The rule applies to information that is FCI and CUI only.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;e. Contractor Information Systems&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Comment:&#039;&#039;&#039; Respondents asked that &amp;quot;contractor information systems&amp;quot; be limited/defined more narrowly, similar to &amp;quot;covered contractor information systems.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Response:&#039;&#039;&#039; The rule clarifies that &amp;quot;contractor information systems&amp;quot; throughout the rule means systems &amp;quot;that process, store, or transmit FCI or CUI in performance of the contract.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
==== 9. Regulatory Impact Analysis (RIA) Estimate ====&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Comment:&#039;&#039;&#039; Several respondents said the RIA cost estimate was too low and should include all offerors and a revised estimate of average information systems per contractor.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Response:&#039;&#039;&#039; The RIA only covers costs of contractual requirements to upload self-assessments and complete affirmations in SPRS (technical/programmatic CMMC costs are addressed under 32 CFR part 170). The RIA was revised to expand the estimated impacted entities to include, in year four and beyond, all entities in the Federal Procurement Data System awarded DoD contracts FY2022–FY2024. The estimate of five information systems per contractor remains a DoD subject-matter-expert estimate.&lt;br /&gt;
&lt;br /&gt;
==== 10. Application to Fundamental Research ====&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Comment:&#039;&#039;&#039; Respondents raised concerns about applying CMMC to fundamental research that could become CUI.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Response:&#039;&#039;&#039; Fundamental research (per NSDD 189) is published and broadly shared and cannot be safeguarded as FCI or CUI; however, if it has the potential to become CUI, it would be subject to CMMC once it becomes CUI.&lt;br /&gt;
&lt;br /&gt;
==== 11. Applicability ====&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Comment:&#039;&#039;&#039; Respondents raised numerous applicability questions: FCI-only Level 1 self-assessment carve-outs, program manager documentation of rationale, existing vs. new contracts, micro-purchase threshold subcontracts, and scope of paragraph (b)(3).&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Response:&#039;&#039;&#039; The clause will be included in solicitations issued on/after the effective date and in resulting contracts; contracting officers may also bilaterally incorporate the clause into existing contracts (see FAR 1.108(d)). Until three years after the effective date, CMMC applies only where program managers/requiring activities determine to apply it (excluding COTS-only awards); afterward, it applies wherever contractor information systems will process, store, or transmit FCI or CUI. 32 CFR part 170 does not allow spot checks and requires the CMMC requirement be met at time of award.&lt;br /&gt;
&lt;br /&gt;
==== 12. Flowdown ====&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Comment:&#039;&#039;&#039; Respondents requested clarification on flowdown scope, CUI dissemination limits, and lower-tier CMMC level determination.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Response:&#039;&#039;&#039; See 32 CFR 170.23 for flowdown guidance. Clause paragraph (d)(1) was revised to clarify flowdown applies only where the subcontract requires a CMMC level, and to no longer exclude paragraph (b)(3) (affirmation of continuous compliance) from subcontractor flowdown. The rule was &#039;&#039;&#039;not&#039;&#039;&#039; revised regarding which subcontractors must receive CUI — that determination remains with the prime contractor.&lt;br /&gt;
&lt;br /&gt;
==== 13. CMMC as an Evaluation Factor ====&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Comment:&#039;&#039;&#039; Is CMMC a competition evaluation factor or set-aside requirement?&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Response:&#039;&#039;&#039; No. CMMC is not an evaluation factor or set-aside requirement; DFARS 204.7503 requires contracting officers not to award to an offeror that fails to meet the CMMC requirements in the solicitation, and if included in the solicitation, it becomes a contract requirement.&lt;br /&gt;
&lt;br /&gt;
==== 14. Program Office Requirements ====&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Comment:&#039;&#039;&#039; Require the program office to review contractor-provided information.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Response:&#039;&#039;&#039; The rule was revised to require the contracting officer to work with the program office/requiring activity to review the offeror&#039;s CMMC status and affirmation information.&lt;br /&gt;
&lt;br /&gt;
==== 15. Clarifying When FCI Applies ====&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Comment:&#039;&#039;&#039; Clarify that systems processing FCI (not CUI) need only CMMC Level 1.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Response:&#039;&#039;&#039; Not included in the final rule; contracting officers do not determine the required CMMC level.&lt;br /&gt;
&lt;br /&gt;
==== 16. International Applicability ====&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Comment:&#039;&#039;&#039; Respondents raised questions about C3PAO assessments outside the U.S., international harmonization, and foreign verification bodies (e.g., Taiwan&#039;s TAF).&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Response:&#039;&#039;&#039; Contracts subject to NIST SP 800–171 compliance (e.g., via DFARS 252.204–7012) require foreign or domestic contractors to secure their systems. See 32 CFR 179 regarding foreign C3PAO accreditation; DoD permits an equivalent process for personnel ineligible for a Tier 3 background investigation, for CMMC Program purposes only.&lt;br /&gt;
&lt;br /&gt;
==== 17. POA&amp;amp;M ====&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Comment:&#039;&#039;&#039; Respondents sought clarity on POA&amp;amp;M closeout, conditional certification for subcontract award, and continued reliance on POA&amp;amp;Ms for newly discovered risks.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Response:&#039;&#039;&#039; The rule was revised to clarify (via the &amp;quot;current&amp;quot; definition) that for CMMC Levels 2 and 3 only, conditional CMMC status is permitted for up to 180 days from the conditional CMMC status date, and that final CMMC status is achieved upon successful POA&amp;amp;M closeout. 32 CFR part 170 does not allow additional POA&amp;amp;Ms beyond established scoping, other than for scenarios appropriate for an &amp;quot;operational plan of action&amp;quot; (32 CFR 170.4).&lt;br /&gt;
&lt;br /&gt;
==== 18. Subcontractor Compliance ====&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Comment:&#039;&#039;&#039; Respondents asked how primes monitor/verify subcontractor CMMC adherence, requested an automated SPRS visibility tool, and asked when subcontractors must be compliant.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Response:&#039;&#039;&#039; Contractors can only access their own CMMC information in SPRS; DoD has no tool for automatic sharing with primes. Subcontractors may screenshot/print their own SPRS status to share voluntarily. Prior to awarding a subcontract, the prime must ensure the subcontractor has a current CMMC status at the appropriate level. 32 CFR part 170 does not allow limiting enforcement to direct suppliers only.&lt;br /&gt;
&lt;br /&gt;
==== 19. Senior Company Official ====&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Comment:&#039;&#039;&#039; Respondents noted the proposed rule&#039;s &amp;quot;senior company official&amp;quot; term does not match 32 CFR part 170&#039;s &amp;quot;affirming official,&amp;quot; and asked for a clear definition.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Response:&#039;&#039;&#039; The final rule updates terminology to &amp;quot;affirming official&amp;quot; to align with 32 CFR part 170 (the proposed DFARS rule used the older term due to timing of the two rulemakings).&lt;br /&gt;
&lt;br /&gt;
==== 20. Task Orders and Delivery Orders ====&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Comment:&#039;&#039;&#039; Will existing IDIQ contracts&#039; task/delivery orders issued after the rule contain a CMMC requirement?&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Response:&#039;&#039;&#039; Task orders or delivery orders issued after the rule&#039;s effective date may include a CMMC requirement under the prescribed clause/provision.&lt;br /&gt;
&lt;br /&gt;
==== 21. Relationship Between &amp;quot;Covered Contractor Information Systems&amp;quot; and &amp;quot;Contractor Information Systems&amp;quot; ====&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Comment:&#039;&#039;&#039; Clarify the relationship between the two terms and possible over-broad scope.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Response:&#039;&#039;&#039; The rule clarifies that &amp;quot;contractor information systems&amp;quot; are limited to those &amp;quot;that process, store, or transmit FCI or CUI during performance of the contract.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
==== 22. CMMC Unique Identifiers ====&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Comment:&#039;&#039;&#039; Respondents sought clarification on CMMC UIDs vs. CAGE codes, mandatory vs. optional UID submission, and prime vs. subcontractor UID reporting obligations.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Response:&#039;&#039;&#039; A CMMC UID is assigned per CMMC Assessment Scope as defined by the Organization Seeking Assessment (OSA) (see 32 CFR 170.19). SPRS/eMASS assigns the UID upon submission of assessment results. OSAs must obtain a CAGE code (via sam.gov) or NCAGE code (for non-U.S. businesses, via NSPA) and a PIEE account. Only prime contractors with a CMMC requirement must submit CMMC UIDs to the contracting officer (which may include subcontractors&#039; UIDs); subcontractors themselves do not submit UIDs to the contracting officer. A new UID is generated whenever a new SPRS score is entered (e.g., at reassessment or 3-year renewal).&lt;br /&gt;
&lt;br /&gt;
==== 23. Creation of Exception ====&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Comment:&#039;&#039;&#039; Requests for exceptional-circumstance relief and small-business exemptions for second-tier suppliers.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Response:&#039;&#039;&#039; 32 CFR part 170 does not include an exemption for exceptional circumstances, and this DFARS rule cannot create one. DoD does not require flowdown to subcontractors that do not receive FCI or CUI.&lt;br /&gt;
&lt;br /&gt;
==== 24. Period of Performance ====&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Comment:&#039;&#039;&#039; Should contracting officers validate CMMC compliance before extending a period of performance?&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Response:&#039;&#039;&#039; Yes — 32 CFR part 170 requires CMMC statuses to be maintained for the life of the contract, so contracting officers must validate compliance before extending performance periods or exercising options.&lt;br /&gt;
&lt;br /&gt;
==== 25. Prime Contractor Protection From Subcontractor Noncompliance ====&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Comment:&#039;&#039;&#039; Clarify that primes won&#039;t be rendered ineligible due to subcontractor noncompliance.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Response:&#039;&#039;&#039; The Government does not establish the prime/subcontractor relationship and does not indemnify the prime from its subcontractors, as it lacks privity of contract with subcontractors.&lt;br /&gt;
&lt;br /&gt;
==== 26. Application of CMMC to FAR Part 16 Contract Types ====&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Comment:&#039;&#039;&#039; Require CMMC Program Office/USD(A&amp;amp;S) approval before applying CMMC to FAR part 16 contract types during phase-in.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Response:&#039;&#039;&#039; 32 CFR part 170 does not include such an approval process, and this rule cannot create one.&lt;br /&gt;
&lt;br /&gt;
==== 27. Acquiring Entities Without CMMC Certification ====&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Comment:&#039;&#039;&#039; How are newly acquired entities or new sites added to an existing certification?&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Response:&#039;&#039;&#039; Per DFARS 252.204–7021(c)(1), contractors must report changes to UIDs to the contracting officer. Adding new users to an existing system does not necessarily change the CMMC assessment scope (see 32 CFR 170.19).&lt;br /&gt;
&lt;br /&gt;
==== 28. Applicability to Civilian Agencies ====&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Comment:&#039;&#039;&#039; Does CMMC apply to CUI from non-DoD agencies?&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Response:&#039;&#039;&#039; This rule amends the DFARS and applies only to DoD or DoD-funded acquisitions.&lt;br /&gt;
&lt;br /&gt;
==== 29. Provision and Clause Clarifications ====&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Comment:&#039;&#039;&#039; Questions on subcontractor UID updates and the &amp;quot;unless electronically posted&amp;quot; language.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Response:&#039;&#039;&#039; The clause was updated to require subcontractors to enter self-assessment results in SPRS and complete annual affirmations, which they may share via screenshot. &amp;quot;Unless electronically posted&amp;quot; language was removed. Paragraph (c)(1) is excluded from subcontractor flowdown because the Government lacks privity of contract with subcontractors, though primes are encouraged to flow down similar language voluntarily.&lt;br /&gt;
&lt;br /&gt;
==== 30. Outside the Scope of the Rule ====&lt;br /&gt;
&lt;br /&gt;
DoD received numerous comments outside the scope of this rule, including topics related to: the DFARS Case 2022–D017 timeline; CUI marking and definitions; the CMMC Program&#039;s underlying policy at 32 CFR part 170 (permissible changes, exemptions for MWR/NAF procurements, ISO/IEC 27001 relationship, phase-in timeline, spot checks, FedRAMP, waivers, eMASS training, and more); cost impacts; and various sector-specific applicability questions (medical devices, furniture manufacturers, common carriers, etc.).&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Response (selected points):&#039;&#039;&#039;&lt;br /&gt;
* CMMC level selection is made by the program office/requiring activity per DoD policy and 32 CFR 170.5; contracting officers do not determine the level.&lt;br /&gt;
* All CUI categories require at least a self-assessment; DoD Organizational Index group CUI categories generally require a C3PAO assessment at minimum.&lt;br /&gt;
* MWR/NAF procurements requiring NIST SP 800–171 implementation are subject to the CMMC requirement.&lt;br /&gt;
* Waivers are established at 32 CFR 170.5 and are at the discretion of the program office/requiring activity, prior to contracting officer involvement.&lt;br /&gt;
* Contractors do not have access to CMMC eMASS (used only for certification assessments); all CMMC assessments are reflected in SPRS.&lt;br /&gt;
* Enclave scoping is determined by the contractor per 32 CFR 170.19.&lt;br /&gt;
* Reassessments are expected to be infrequent and DoD-conducted, per updates to 32 CFR part 170.&lt;br /&gt;
* Flowdown requirements are at 32 CFR 170.23.&lt;br /&gt;
&lt;br /&gt;
=== C. Other Changes ===&lt;br /&gt;
&lt;br /&gt;
* DFARS 204.7500 was updated to remove a web address and replace it with a reference to 32 CFR part 170.&lt;br /&gt;
* Clarified throughout that a higher CMMC level than required is also permissible.&lt;br /&gt;
* The term &amp;quot;CMMC status&amp;quot; was added throughout, clarifying that contracts may be awarded with a current Final Level 1 (Self), Conditional Level 2 (Self), Final Level 2 (Self), Conditional Level 2 (C3PAO), or Final Level 2 (C3PAO) CMMC status. A definition of &amp;quot;CMMC status&amp;quot; was added to DFARS subpart 204.75, clause 252.204–7021, and provision 252.204–7025.&lt;br /&gt;
&lt;br /&gt;
== III. Applicability to Contracts at or Below the SAT, Commercial Products, and Commercial Services ==&lt;br /&gt;
&lt;br /&gt;
The clause at DFARS 252.204–7021 is prescribed at DFARS 204.7504 for use:&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;Until November 9, 2028&#039;&#039;&#039; (three years after the effective date): in solicitations and contracts, task orders, or delivery orders — including FAR part 12 commercial product/service acquisitions, except those solely for COTS items — if the program office or requiring activity determines the contractor is required to have a specific CMMC level (unless 32 CFR 170.5(d) requirements are met).&lt;br /&gt;
* &#039;&#039;&#039;On or after November 10, 2028&#039;&#039;&#039;: in solicitations and contracts, task orders, or delivery orders — including FAR part 12 acquisitions, except those solely for COTS items — if the program office or requiring activity determines the contractor must use contractor information systems to process, store, or transmit FCI or CUI.&lt;br /&gt;
&lt;br /&gt;
The provision at DFARS 252.204–7025 is prescribed at DFARS 204.7504(b) for use in solicitations that include the clause at DFARS 252.204–7021.&lt;br /&gt;
&lt;br /&gt;
Consistent with DoD&#039;s analysis of section 1648 of the NDAA for FY 2020, DoD applies the statute (as implemented in these clause/provision) to contracts at or below the Simplified Acquisition Threshold (SAT), to commercial products (excluding COTS items), and to commercial services as defined at FAR 2.101.&lt;br /&gt;
&lt;br /&gt;
== IV. Expected Impact of the Rule ==&lt;br /&gt;
&lt;br /&gt;
=== A. Background ===&lt;br /&gt;
&lt;br /&gt;
DoD is amending the DFARS to implement contractual requirements tied to the CMMC policy (32 CFR part 170, 89 FR 83092, October 15, 2024). New solicitation/contractual requirements include:&lt;br /&gt;
&lt;br /&gt;
* Offeror/contractor requirement to post CMMC Level 1 or Level 2 self-assessment results to SPRS prior to award, option exercise, or period-of-performance extension, if not already posted.&lt;br /&gt;
* Contractor requirement to maintain the required CMMC status for the life of the contract.&lt;br /&gt;
* Contractor requirement for an affirming official to complete an annual affirmation of continuous compliance in SPRS for each applicable CMMC UID.&lt;br /&gt;
* Offeror/contractor requirement to identify contractor information systems used to process, store, or transmit FCI or CUI, by providing CMMC UIDs generated by SPRS.&lt;br /&gt;
&lt;br /&gt;
=== B. Summary of Impact ===&lt;br /&gt;
&lt;br /&gt;
The rule will be implemented over a phased, three-year period, after which it applies to all contracts where the contractor processes, stores, or transmits FCI or CUI on contractor information systems (except COTS-only contracts).&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Estimated impacted entities (Year 4 and beyond):&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Metric !! Value&lt;br /&gt;
|-&lt;br /&gt;
| Average unique entities awarded DoD contracts above micro-purchase threshold (FY2022–FY2024) || 32,756&lt;br /&gt;
|-&lt;br /&gt;
| Unique entities awarded using only commercial procedures || 18,370&lt;br /&gt;
|-&lt;br /&gt;
| Estimated COTS-only awardees (25% of 18,370) || 4,592&lt;br /&gt;
|-&lt;br /&gt;
| Unique entities after removing COTS-only awardees || 28,164&lt;br /&gt;
|-&lt;br /&gt;
| Assumed offerors per solicitation || 2&lt;br /&gt;
|-&lt;br /&gt;
| Total prime offerors (28,164 × 2) || 56,328&lt;br /&gt;
|-&lt;br /&gt;
| Assumed subcontractors per prime offer || 5&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;Total estimated impacted entities&#039;&#039;&#039; (primes + subcontractors) || &#039;&#039;&#039;337,968&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| Of which, small entities (68%) || 229,818&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Estimated time burden per contractor information system:&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
* Offerors/contractors: ~5 minutes to post CMMC self-assessment results in SPRS; ~5 minutes to complete the required affirmation; ~5 minutes to retrieve and submit CMMC UIDs.&lt;br /&gt;
* Government: ~5 minutes to validate CMMC level/currency prior to award, option exercise, or performance extension; ~5 minutes to validate affirmation currency; ~5 minutes to validate CMMC status/affirmation when UIDs change during performance.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Benefits:&#039;&#039;&#039; Verification of DIB contractors&#039; implementation of system security requirements, protection of CUI/FCI and intellectual property, and reduced exposure to malicious cyber activity. The Council of Economic Advisers estimated malicious cyber activity cost the U.S. economy $57–109 billion in 2016 (a 10-year burden of an estimated $400–765 billion at a 7% discount rate, or $486–929 billion at a 3% discount rate). GAO cited Treasury reporting that ransomware-related incidents reached $886 million in 2021.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Estimated public and Government costs over a 10-year period:&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Summary (3% discount rate) !! Public !! Government !! Total&lt;br /&gt;
|-&lt;br /&gt;
| Present Value || $329,097,922 || $15,812,069 || $344,909,991&lt;br /&gt;
|-&lt;br /&gt;
| Annualized Costs || $38,580,316 || $1,760,303 || $40,340,619&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Summary (7% discount rate) !! Public !! Government !! Total&lt;br /&gt;
|-&lt;br /&gt;
| Present Value || $254,756,766 || $11,533,649 || $266,290,415&lt;br /&gt;
|-&lt;br /&gt;
| Annualized Costs || $36,271,632 || $1,642,132 || $37,913,764&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== V. Executive Orders 12866 and 13563 ==&lt;br /&gt;
&lt;br /&gt;
This is a significant regulatory action, subject to review under section 6(b) of E.O. 12866, Regulatory Planning and Review, as amended.&lt;br /&gt;
&lt;br /&gt;
== VI. Executive Order 14192 ==&lt;br /&gt;
&lt;br /&gt;
This rule is &#039;&#039;&#039;not&#039;&#039;&#039; subject to E.O. 14192, because it is issued with respect to a national security function of the United States. Implementation of CMMC Program requirements is urgently needed to strengthen protection of DoD information, protect critical defense technologies from exfiltration, and protect the DIB&#039;s intellectual property and the broader U.S. economy from malicious cyber actors.&lt;br /&gt;
&lt;br /&gt;
== VII. Congressional Review Act ==&lt;br /&gt;
&lt;br /&gt;
DoD will submit the rule to the U.S. Senate, House of Representatives, and Comptroller General as required by the Congressional Review Act (5 U.S.C. 801–808). The Office of Information and Regulatory Affairs has determined this rule is &#039;&#039;&#039;not&#039;&#039;&#039; a major rule as defined by 5 U.S.C. 804(2).&lt;br /&gt;
&lt;br /&gt;
== VIII. Regulatory Flexibility Act ==&lt;br /&gt;
&lt;br /&gt;
A final regulatory flexibility analysis was prepared under 5 U.S.C. 601 &#039;&#039;et seq.&#039;&#039; Key points:&lt;br /&gt;
&lt;br /&gt;
* This rule responds to threats posed by malicious cyber activity targeting U.S. intellectual property and DoD CUI.&lt;br /&gt;
* Requirements apply to all offerors/contractors under a CMMC-requirement solicitation/contract: (1) post current CMMC status in SPRS; (2) maintain CMMC status for contract life; (3) provide CMMC UIDs to the contracting officer, with updates; (4) maintain a current affirmation of continuous compliance.&lt;br /&gt;
* These requirements do &#039;&#039;&#039;not&#039;&#039;&#039; apply to awards not involving FCI or CUI.&lt;br /&gt;
* No public comments were submitted in response to the initial regulatory flexibility analysis.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Estimated small entities impacted, phased rollout:&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Year !! Estimated Small Entities&lt;br /&gt;
|-&lt;br /&gt;
| Year 1 || 1,104&lt;br /&gt;
|-&lt;br /&gt;
| Year 2 || 5,565&lt;br /&gt;
|-&lt;br /&gt;
| Year 3 || 18,554&lt;br /&gt;
|-&lt;br /&gt;
| Year 4+ || 229,818&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Anticipated mix of CMMC statuses starting Year 4:&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! CMMC Level !! Percentage !! Small Entities !! Large Entities !! Total Entities&lt;br /&gt;
|-&lt;br /&gt;
| Level 1 Self-assessment || 62% || 142,487 || 67,053 || 209,540&lt;br /&gt;
|-&lt;br /&gt;
| Level 2 Self-assessment || 2% || 4,596 || 2,163 || 6,759&lt;br /&gt;
|-&lt;br /&gt;
| Level 2 Certificate || 35% || 80,436 || 37,853 || 118,289&lt;br /&gt;
|-&lt;br /&gt;
| Level 3 Certificate || 1% || 2,298 || 1,082 || 3,380&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;Total&#039;&#039;&#039; || &#039;&#039;&#039;100%&#039;&#039;&#039; || &#039;&#039;&#039;229,818&#039;&#039;&#039; || &#039;&#039;&#039;108,150&#039;&#039;&#039; || &#039;&#039;&#039;337,968&#039;&#039;&#039;&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;New reporting/recordkeeping requirements for small entities:&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
# Post current CMMC status (not covered by C3PAO/DIBCAC assessment) to SPRS for each applicable CMMC UID.&lt;br /&gt;
# Provide CMMC UIDs prior to award and upon any changes.&lt;br /&gt;
# Affirming official completes and maintains, annually (or upon compliance status change), the affirmation of continuous compliance in SPRS.&lt;br /&gt;
&lt;br /&gt;
DoD identified no alternatives that would accomplish the statutory objectives while further reducing small-entity burden; the phased rollout and COTS exemption are intended to minimize economic impact.&lt;br /&gt;
&lt;br /&gt;
== IX. Paperwork Reduction Act ==&lt;br /&gt;
&lt;br /&gt;
This final rule&#039;s information collection requirements have been approved by OMB under the Paperwork Reduction Act (44 U.S.C. chapter 35), OMB Control Number &#039;&#039;&#039;0750–0008&#039;&#039;&#039;, DFARS Part 204, Contractor Implementation of Cybersecurity Requirements.&lt;br /&gt;
&lt;br /&gt;
== List of Subjects in 48 CFR Parts 204, 212, 217, and 252 ==&lt;br /&gt;
&lt;br /&gt;
Government procurement.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Signed:&#039;&#039; Kimberly R. Ziegler, Editor/Publisher, Defense Acquisition Regulations System.&lt;br /&gt;
&lt;br /&gt;
The interim rule amending 48 CFR parts 204, 212, 217, and 252 (published at 85 FR 61505 on September 29, 2020) is adopted as final with the following changes.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Authority citation for parts 204, 212, 217, and 252:&#039;&#039;&#039; 41 U.S.C. 1303 and 48 CFR chapter 1.&lt;br /&gt;
&lt;br /&gt;
== PART 204—Administrative and Information Matters ==&lt;br /&gt;
&lt;br /&gt;
=== Subpart 204.75—Cybersecurity Maturity Model Certification ===&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Contents:&#039;&#039;&#039;&lt;br /&gt;
* 204.7500 Scope of subpart.&lt;br /&gt;
* 204.7501 Definitions.&lt;br /&gt;
* 204.7502 Policy.&lt;br /&gt;
* 204.7503 Procedures.&lt;br /&gt;
* 204.7504 Solicitation provision and contract clause.&lt;br /&gt;
&lt;br /&gt;
==== 204.7500 Scope of subpart ====&lt;br /&gt;
&lt;br /&gt;
(a) This subpart prescribes policies and procedures for including the Cybersecurity Maturity Model Certification (CMMC) level requirements in DoD contracts. CMMC is a framework (see 32 CFR part 170) for assessing a contractor&#039;s information security protections.&lt;br /&gt;
&lt;br /&gt;
(b) This subpart does not abrogate any other requirements regarding contractor physical, personnel, information, technical, or general administrative security operations governing the protection of unclassified information, nor does it affect requirements of the National Industrial Security Program.&lt;br /&gt;
&lt;br /&gt;
(c) This subpart applies to unclassified contractor information systems.&lt;br /&gt;
&lt;br /&gt;
==== 204.7501 Definitions ====&lt;br /&gt;
&lt;br /&gt;
As used in this subpart—&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Controlled unclassified information&#039;&#039;&#039; means information the Government creates or possesses, or information an entity creates or possesses for or on behalf of the Government, that a law, regulation, or Governmentwide policy requires or permits an agency to handle using safeguarding or dissemination controls (32 CFR 2002.4(h)).&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Current&#039;&#039;&#039; means—&lt;br /&gt;
&lt;br /&gt;
(1) With regard to Conditional Cybersecurity Maturity Model Certification (CMMC) Status—&lt;br /&gt;
&lt;br /&gt;
:(i) Not older than 180 days for Conditional Level 2 (Self) assessments and Conditional Level 2 (certified third-party assessment organization (C3PAO)) assessments, with—&lt;br /&gt;
::(A) No changes in compliance with the requirements at 32 CFR part 170 since the Conditional CMMC Status date (see 32 CFR 170.16 and 170.17); and&lt;br /&gt;
::(B) A corresponding affirmation of continuous compliance by an affirming official (see 32 CFR 170.4); and&lt;br /&gt;
&lt;br /&gt;
:(ii) Not older than 180 days for Conditional Level 3 (Defense Industrial Base Cybersecurity Assessment Center (DIBCAC)) assessments, with—&lt;br /&gt;
::(A) No changes in compliance with the requirements at 32 CFR part 170 since the Conditional CMMC Status date (see 32 CFR 170.18); and&lt;br /&gt;
::(B) A corresponding affirmation of continuous compliance by an affirming official;&lt;br /&gt;
&lt;br /&gt;
(2) With regard to Final CMMC Status—&lt;br /&gt;
&lt;br /&gt;
:(i) Not older than 1 year for Final Level 1 (Self), with—&lt;br /&gt;
::(A) No changes in compliance with the requirements at 32 CFR part 170 since the Final CMMC Status date (see 32 CFR 170.15); and&lt;br /&gt;
::(B) A corresponding affirmation of continuous compliance, not older than 1 year, by an affirming official;&lt;br /&gt;
&lt;br /&gt;
:(ii) Not older than 3 years for Final Level 2 (Self) assessments and Final Level 2 (C3PAO) assessments, with—&lt;br /&gt;
::(A) No changes in compliance with the requirements at 32 CFR part 170 since the Final CMMC Status date (see 32 CFR 170.16 and 170.17); and&lt;br /&gt;
::(B) A corresponding affirmation of continuous compliance, not older than 1 year, by an affirming official; and&lt;br /&gt;
&lt;br /&gt;
:(iii) Not older than 3 years for Final Level 3 (DIBCAC) assessments, with—&lt;br /&gt;
::(A) No changes in compliance with the requirements at 32 CFR part 170 since the Final CMMC Status date (see 32 CFR 170.18); and&lt;br /&gt;
::(B) A corresponding affirmation of continuous compliance, not older than 1 year, by an affirming official; and&lt;br /&gt;
&lt;br /&gt;
(3) With regard to affirmation of continuous compliance (32 CFR 170.22), not older than 1 year with no changes in compliance with the requirements at 32 CFR part 170.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Cybersecurity Maturity Model Certification (CMMC) status&#039;&#039;&#039; means the result of meeting or exceeding the minimum required score for the corresponding assessment. The potential statuses are as follows:&lt;br /&gt;
&lt;br /&gt;
# Final Level 1 (Self).&lt;br /&gt;
# Conditional Level 2 (Self).&lt;br /&gt;
# Final Level 2 (Self).&lt;br /&gt;
# Conditional Level 2 (C3PAO).&lt;br /&gt;
# Final Level 2 (C3PAO).&lt;br /&gt;
# Conditional Level 3 (DIBCAC).&lt;br /&gt;
# Final Level 3 (DIBCAC).&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Cybersecurity Maturity Model Certification unique identifier (CMMC UID)&#039;&#039;&#039; means 10 alpha-numeric characters assigned to each CMMC assessment and reflected in the Supplier Performance Risk System (SPRS) for each contractor information system.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Federal contract information (FCI)&#039;&#039;&#039; means information, not intended for public release, that is provided by or generated for the Government under a contract to develop or deliver a product or service to the Government. It does not include information provided by the Government to the public, such as on public websites, or simple transactional information, such as information necessary to process payments.&lt;br /&gt;
&lt;br /&gt;
==== 204.7502 Policy ====&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;(a) Award eligibility.&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
(1) The contracting officer shall include in the solicitation the required CMMC level, if provided by the program office or the requiring activity.&lt;br /&gt;
&lt;br /&gt;
(2) Contracting officers shall not award a contract, task order, or delivery order to an offeror that does not have a current CMMC status at the CMMC level required by the solicitation.&lt;br /&gt;
&lt;br /&gt;
(3) Contractors are required to achieve, at time of award, a CMMC status at the CMMC level specified in the solicitation, or higher, for all information systems used in the performance of the contract, task order, or delivery order that will process, store, or transmit FCI or CUI. Contractors are required to maintain a current CMMC status at the specified CMMC level or higher, if required by the contract, task order, or delivery order, throughout the life of the contract, task order, or delivery order.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;(b) CMMC status.&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
(1) Contracting officers may award a contract, task order, delivery order, or modification to exercise an option or extend a period of performance, if the offeror&#039;s or contractor&#039;s CMMC status is—&lt;br /&gt;
&lt;br /&gt;
:(i) Listed in the definition of &amp;quot;CMMC status&amp;quot;; and&lt;br /&gt;
:(ii) Equal to or higher than the CMMC level required by the solicitation or contract, task order, or delivery order.&lt;br /&gt;
&lt;br /&gt;
(2) CMMC levels 2 and 3 can be in a conditional level for a period not to exceed 180 days from the CMMC status date (32 CFR 170.21), and award can occur with a conditional CMMC level. CMMC level 1 requires a final CMMC level for award.&lt;br /&gt;
&lt;br /&gt;
==== 204.7503 Procedures ====&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;(a) CMMC level.&#039;&#039;&#039; The contracting officer shall include the CMMC level (see 32 CFR 170.19) required by the program office or requiring activity in the solicitation provision and contract clause prescribed at 204.7504.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;(b) Award.&#039;&#039;&#039; Contracting officers shall check SPRS and not award a contract, task order, or delivery order to an offeror that does not have a current CMMC status posted in SPRS at the CMMC level (see 32 CFR 170.15 through 170.18) required by the solicitation, or higher, for each CMMC UID provided by the offeror. The CMMC UIDs are applicable to each of the contractor information systems that will process, store, or transmit FCI or CUI and that will be used in performance of the contract.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;(c) Option exercise or period of performance extension.&#039;&#039;&#039; Contracting officers shall check SPRS and not exercise an option or extend the period of performance on a contract, task order, or delivery order, unless the contractor has a current CMMC status posted in SPRS at the CMMC level (see 32 CFR 170.15 through 170.18) required by the contract, task order, or delivery order, or higher, for each CMMC UID provided by the contractor. The contractor&#039;s CMMC UIDs are applicable to each of the contractor information systems that process, store, or transmit FCI or CUI and that are or will be used in performance of the contract.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;(d) CMMC UIDs.&#039;&#039;&#039; If the contractor provides new CMMC UIDs during performance of the contract, task order, or delivery order, the contracting officer shall check in SPRS, using the CMMC UIDs assigned by SPRS, that the contractor has a current CMMC status at the required CMMC level, or higher, for each of the contractor information systems identified that will process, store, or transmit FCI or CUI during contract performance.&lt;br /&gt;
&lt;br /&gt;
==== 204.7504 Solicitation provision and contract clause ====&lt;br /&gt;
&lt;br /&gt;
(a) Unless the requirements at 32 CFR 170.5(d) are met, use the clause at 252.204–7021, &#039;&#039;Contractor Compliance with the Cybersecurity Maturity Model Certification Level Requirements&#039;&#039;, as follows:&lt;br /&gt;
&lt;br /&gt;
(1) &#039;&#039;&#039;Until November 9, 2028&#039;&#039;&#039;, in solicitations and contracts, task orders, or delivery orders, including those using FAR part 12 procedures for the acquisition of commercial products and commercial services, except for those solely for the acquisition of commercially available off-the-shelf (COTS) items, if the program office or requiring activity determines that the contractor is required to have a specific CMMC level.&lt;br /&gt;
&lt;br /&gt;
(2) &#039;&#039;&#039;On or after November 10, 2028&#039;&#039;&#039;, in solicitations and contracts, task orders, or delivery orders, including those using FAR part 12 procedures for the acquisition of commercial products and commercial services, except for those solely for the acquisition of COTS items, if the program office or requiring activity determines that the contractor is required to use contractor information systems in the performance of the contract, task order, or delivery order to process, store, or transmit FCI or CUI.&lt;br /&gt;
&lt;br /&gt;
(b) Use the provision at 252.204–7025, &#039;&#039;Notice of Cybersecurity Maturity Model Certification Level Requirements&#039;&#039;, in solicitations that include the clause at 252.204–7021.&lt;br /&gt;
&lt;br /&gt;
== PART 212—Acquisition of Commercial Products and Commercial Services ==&lt;br /&gt;
&lt;br /&gt;
=== 212.301 Solicitation provisions and contract clauses for the acquisition of commercial products and commercial services ===&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Amendment:&#039;&#039;&#039;&lt;br /&gt;
* In paragraph (f)(ii)(L), remove &amp;quot;204.7503 (a) and (b)&amp;quot; and add &amp;quot;204.7504(a)&amp;quot; in its place.&lt;br /&gt;
* Add paragraph (f)(ii)(P):&lt;br /&gt;
&lt;br /&gt;
:(P) Use the provision at 252.204–7025, Notice of Cybersecurity Maturity Model Certification Level Requirements, as prescribed in 204.7504(b).&lt;br /&gt;
&lt;br /&gt;
== PART 217—Special Contracting Methods ==&lt;br /&gt;
&lt;br /&gt;
=== 217.207 Exercise of options ===&lt;br /&gt;
&lt;br /&gt;
(c) In addition to the requirements at FAR 17.207(c), exercise an option only after—&lt;br /&gt;
&lt;br /&gt;
(1) Determining that the contractor&#039;s record in the System for Award Management database is active and the contractor&#039;s unique entity identifier number, Commercial and Government Entity (CAGE) code, name, and physical address are accurately reflected in the contract document. (See PGI 217.207 for the requirement to perform cost or price analysis of spare parts prior to exercising any option for firm-fixed-price contracts containing spare parts.); and&lt;br /&gt;
&lt;br /&gt;
(2) Working with the program office or requiring activity to verify in the Supplier Performance Risk System (https://piee.eb.mil) that—&lt;br /&gt;
&lt;br /&gt;
:(i) The summary level score of a current NIST SP 800–171 DoD Assessment (i.e., not more than 3 years old, unless a lesser time is specified in the solicitation) for each covered contractor information system that is relevant to an offer, contract, task order, or delivery order are posted (see 204.7303); and&lt;br /&gt;
&lt;br /&gt;
:(ii) If there is a requirement for the contractor to have a Cybersecurity Maturity Model Certification (CMMC) status at a specific CMMC level, the contractor has a current CMMC status at the CMMC level required by the contract, or higher, for each of the CMMC unique identifiers applicable to each of the contractor information systems that process, store, or transmit Federal contract information or controlled unclassified information (see 204.7503(c)).&lt;br /&gt;
&lt;br /&gt;
== PART 252—Solicitation Provisions and Contract Clauses ==&lt;br /&gt;
&lt;br /&gt;
=== 252.204–7021 Contractor Compliance With the Cybersecurity Maturity Model Certification Level Requirements ===&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;As prescribed in 204.7504(a), use the following clause:&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;CONTRACTOR COMPLIANCE WITH THE CYBERSECURITY MATURITY MODEL CERTIFICATION LEVEL REQUIREMENTS (NOV 2025)&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;(a) Definitions.&#039;&#039;&#039; As used in this clause—&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Controlled unclassified information&#039;&#039;&#039; means information the Government creates or possesses, or information an entity creates or possesses for or on behalf of the Government, that a law, regulation, or Governmentwide policy requires or permits an agency to handle using safeguarding or dissemination controls (32 CFR 2002.4(h)).&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Current&#039;&#039;&#039; means— &#039;&#039;(see definition under DFARS 204.7501 above, which is incorporated identically into this clause)&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Cybersecurity Maturity Model Certification (CMMC) status&#039;&#039;&#039; means the result of meeting or exceeding the minimum required score for the corresponding assessment. The potential statuses are as follows:&lt;br /&gt;
&lt;br /&gt;
# Final Level 1 (Self).&lt;br /&gt;
# Conditional Level 2 (Self).&lt;br /&gt;
# Final Level 2 (Self).&lt;br /&gt;
# Conditional Level 2 (C3PAO).&lt;br /&gt;
# Final Level 2 (C3PAO).&lt;br /&gt;
# Conditional Level 3 (DIBCAC).&lt;br /&gt;
# Final Level 3 (DIBCAC).&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Cybersecurity Maturity Model Certification unique identifier (CMMC UID)&#039;&#039;&#039; means 10 alpha-numeric characters assigned to each CMMC assessment and reflected in the Supplier Performance Risk System (SPRS) for each contractor information system.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Federal contract information (FCI)&#039;&#039;&#039; means information, not intended for public release, that is provided by or generated for the Government under a contract to develop or deliver a product or service to the Government. It does not include information provided by the Government to the public, such as on public websites, or simple transactional information, such as information necessary to process payments.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Plan of action and milestones&#039;&#039;&#039; means a document that identifies tasks to be accomplished. It details resources required to accomplish the elements of the plan, any milestones in meeting the tasks, and scheduled completion dates for the milestones, as defined in National Institute of Standards and Technology Special Publication 800–115 (32 CFR 170.21).&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;(b) Framework.&#039;&#039;&#039; The Cybersecurity Maturity Model Certification (CMMC) is a framework for assessing a contractor&#039;s compliance with applicable information security protections (see 32 CFR part 170).&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;(c) Duplication.&#039;&#039;&#039; The CMMC assessments will not duplicate efforts from any other comparable DoD assessment, except for rare circumstances when a reassessment may be necessary, for example, when there are indications of issues with cybersecurity and/or compliance with CMMC requirements.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;(d) Requirements.&#039;&#039;&#039; The Contractor shall—&lt;br /&gt;
&lt;br /&gt;
(1)(i) Have and maintain for the duration of the contract a current CMMC status at the following CMMC level, or higher: _____ [Contracting Officer insert: CMMC Level 1 (Self); CMMC Level 2 (Self); CMMC Level 2 (C3PAO); or CMMC Level 3 (DIBCAC)] for all information systems used in performance of the contract, task order, or delivery order that process, store, or transmit FCI or CUI; and&lt;br /&gt;
&lt;br /&gt;
:(ii) Consult 32 CFR 170.23 related to the flowdown of the CMMC requirements, and flow down the correct CMMC level to subcontracts and other contractual instruments;&lt;br /&gt;
&lt;br /&gt;
(2) Only process, store, or transmit FCI or CUI on contractor information systems that have a CMMC status at the CMMC level required in paragraph (d)(1) of this clause, or higher;&lt;br /&gt;
&lt;br /&gt;
(3) Complete on an annual basis, and maintain as current, an affirmation, by the affirming official (see 32 CFR 170.4), of continuous compliance with the requirements associated with the CMMC level required in paragraph (d)(1) of this clause in the Supplier Performance Risk System (SPRS) (https://piee.eb.mil) for each CMMC UID applicable to each of the contractor information systems that process, store, or transmit FCI or CUI and that are used in performance of the contract;&lt;br /&gt;
&lt;br /&gt;
(4) Ensure all subcontractors and suppliers complete prior to subcontract award, and maintain on an annual basis, an affirmation, by the affirming official (see 32 CFR 170.4), of continuous compliance with the requirements associated with the CMMC level required for the subcontract or other contractual instrument for each of the subcontractor information systems that process, store, or transmit FCI or CUI and that are used in performance of the subcontract; and&lt;br /&gt;
&lt;br /&gt;
(5) If the Contractor has a CMMC Status of Conditional, successfully close out a valid plan of action and milestones (32 CFR 170.21) to achieve a CMMC Status of Final.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;(e) Reporting.&#039;&#039;&#039; The Contractor shall—&lt;br /&gt;
&lt;br /&gt;
(1) Submit to the Contracting Officer—&lt;br /&gt;
&lt;br /&gt;
:(i) The CMMC UID(s) issued by SPRS for contractor information systems that will process, store, or transmit FCI or CUI during performance of the contract; and&lt;br /&gt;
&lt;br /&gt;
:(ii) Any changes in the CMMC UIDs generated in SPRS throughout the life of the contract, task order, or delivery order, if applicable;&lt;br /&gt;
&lt;br /&gt;
(2) Enter into SPRS the results of a current self-assessment for each CMMC UID, not covered by a C3PAO assessment or DIBCAC assessment, applicable to each of the contractor information systems that process, store, or transmit FCI or CUI and that are used in performance of the contract; and&lt;br /&gt;
&lt;br /&gt;
(3) Complete in SPRS on an annual basis and maintain as current an affirmation of continuous compliance by the affirming official (see 32 CFR 170.4) for each self-assessment, C3PAO assessment, or DIBCAC assessment required under the contract in SPRS.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;(f) Subcontracts.&#039;&#039;&#039; The Contractor shall—&lt;br /&gt;
&lt;br /&gt;
(1) Insert the substance of this clause, including this paragraph (f) and excluding paragraph (e)(1), in subcontracts and other contractual instruments, including those for the acquisition of commercial products and commercial services, excluding commercially available off-the-shelf items, if the subcontract or other contractual instrument will contain a requirement to process, store, or transmit FCI or CUI; and&lt;br /&gt;
&lt;br /&gt;
(2) Prior to awarding a subcontract or other contractual instrument, ensure that the subcontractor has a current CMMC certificate or current CMMC status at the CMMC level that is appropriate for the information that is being flowed down to the subcontractor based on the requirements at 32 CFR 170.23.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;(End of clause)&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
=== 252.204–7025 Notice of Cybersecurity Maturity Model Certification Level Requirements ===&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;As prescribed in 204.7504(b), use the following provision:&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;NOTICE OF CYBERSECURITY MATURITY MODEL CERTIFICATION LEVEL REQUIREMENTS (NOV 2025)&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;(a) Definitions.&#039;&#039;&#039; As used in this provision, &#039;&#039;controlled unclassified information (CUI)&#039;&#039;, &#039;&#039;current&#039;&#039;, &#039;&#039;Cybersecurity Maturity Model Certification (CMMC) status&#039;&#039;, &#039;&#039;Cybersecurity Maturity Model Certification unique identifier (CMMC UID)&#039;&#039;, &#039;&#039;Federal contract information (FCI)&#039;&#039;, and &#039;&#039;Plan of action and milestones&#039;&#039; have the meaning given in the Defense Federal Acquisition Regulation Supplement 252.204–7021, &#039;&#039;Contractor Compliance With the Cybersecurity Maturity Model Certification Level Requirements&#039;&#039;, clause of this solicitation.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;(b)(1) Cybersecurity Maturity Model Certification (CMMC) level.&#039;&#039;&#039; The CMMC level required by this solicitation is: _____ [Contracting Officer insert: CMMC Level 1 (Self); CMMC Level 2 (Self); CMMC Level 2 (C3PAO); or CMMC Level 3 (DIBCAC)]. This CMMC level, or higher (see 32 CFR part 170), is required prior to award for each contractor information system that will process, store, or transmit Federal contract information (FCI) or controlled unclassified information (CUI) during performance of the contract.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;(2)&#039;&#039;&#039; The Offeror will not be eligible for award of a contract, task order, or delivery order resulting from this solicitation if the Offeror does not have, for each of the contractor information systems that will process, store, or transmit FCI or CUI and that will be used in performance of a contract resulting from this solicitation—&lt;br /&gt;
&lt;br /&gt;
:(i) The current CMMC status entered in the Supplier Performance Risk System (SPRS) (https://piee.eb.mil) at the CMMC level required by paragraph (b)(1) of this provision; and&lt;br /&gt;
&lt;br /&gt;
:(ii) A current affirmation of continuous compliance with the security requirements identified at 32 CFR part 170 in SPRS.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;(c) Plan of action and milestones.&#039;&#039;&#039; If the Offeror has a CMMC Status of Conditional, the Offeror shall successfully close out a valid plan of action and milestones (32 CFR 170.21) to achieve a CMMC Status of Final.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;(d) CMMC unique identifiers.&#039;&#039;&#039; The Offeror shall provide, in the proposal, the CMMC unique identifier(s) (CMMC UIDs) issued by SPRS for each contractor information system that will process, store, or transmit FCI or CUI during performance of a contract, task order, or delivery order resulting from this solicitation. The Offeror also shall update the list when new CMMC UIDs are generated in SPRS. The CMMC UIDs are provided in SPRS after the Offeror enters the results of self-assessment(s) for each such information system.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;(End of provision)&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;[FR Doc. 2025–17359 Filed 9–9–25; 8:45 am]&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;BILLING CODE 6001–FR–P&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
[[Category:Federal Register]]&lt;br /&gt;
[[Category:DFARS]]&lt;br /&gt;
[[Category:Cybersecurity Maturity Model Certification]]&lt;br /&gt;
[[Category:Defense Acquisition Regulations]]&lt;/div&gt;</summary>
		<author><name>David</name></author>
	</entry>
	<entry>
		<id>https://cmmcwiki.org/index.php?title=MediaWiki:Sidebar&amp;diff=1629</id>
		<title>MediaWiki:Sidebar</title>
		<link rel="alternate" type="text/html" href="https://cmmcwiki.org/index.php?title=MediaWiki:Sidebar&amp;diff=1629"/>
		<updated>2026-07-20T01:54:50Z</updated>

		<summary type="html">&lt;p&gt;David: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;* navigation&lt;br /&gt;
** mainpage | mainpage-description&lt;br /&gt;
* CMMC Model and Rule&lt;br /&gt;
** Model_Overview | Model Overview&lt;br /&gt;
** 32_CFR_Part_170 | 32 CFR Part 170&lt;br /&gt;
** 48_CFR_Parts_204_212_217_252 | 48 CFR Parts 204, 212, 217, and 252&lt;br /&gt;
* Scoping and Assessment Guides&lt;br /&gt;
** Level_1_Scoping_Guidance | Level 1 Scoping Guidance&lt;br /&gt;
** Level_1_Self-Assessment_Guide | Level 1 Self-Assessment Guide&lt;br /&gt;
** Level_2_Scoping_Guidance | Level 2 Scoping Guidance&lt;br /&gt;
** Level_2_Assessment_Guide | Level 2 Assessment Guide&lt;br /&gt;
** Level_3_Scoping_Guidance | Level 3 Scoping Guidance&lt;br /&gt;
** Level_3_Assessment_Guide | Level 3 Assessment Guide&lt;br /&gt;
* CMMC Guides and Tools&lt;br /&gt;
** CMMC_Hashing_Guide | CMMC Hashing Guide&lt;br /&gt;
** CMMC_Assessment_Process | CMMC Assessment Process (CAP) by CyberAB&lt;br /&gt;
** DoD_Assessment_Methodology | DoD Assessment Methodology&lt;br /&gt;
** Evidence_Collection_Approach | CMMC Evidence Collection Approach&lt;br /&gt;
** DoD Memo on ODPs for 800-171 Revision 3 | DoD Memo on Organization-Defined Parameters for NIST 800-171 Revision 3&lt;br /&gt;
** External_References | External References&lt;/div&gt;</summary>
		<author><name>David</name></author>
	</entry>
	<entry>
		<id>https://cmmcwiki.org/index.php?title=Evidence_Collection_Approach&amp;diff=1628</id>
		<title>Evidence Collection Approach</title>
		<link rel="alternate" type="text/html" href="https://cmmcwiki.org/index.php?title=Evidence_Collection_Approach&amp;diff=1628"/>
		<updated>2026-07-20T01:49:51Z</updated>

		<summary type="html">&lt;p&gt;David: /* SC.L2-3.13.12 – Collaborative Device Control */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;CMMC assessments and certification require substantial evidence and documentation. The following tables outline general guidelines for collecting evidence to assess control requirements and objectives. While these guidelines provide a structured approach, they are not the only means of conducting an accurate assessment. Assessors should exercise professional judgment and may employ alternative methods appropriate to the specific organizational context and circumstances.&lt;br /&gt;
&lt;br /&gt;
Evidence collection approaches are defined as:&lt;br /&gt;
* &#039;&#039;&#039;Documentation&#039;&#039;&#039;: Tangible materials containing information over which an organization has authority, including all types of written records and their copies.&lt;br /&gt;
* &#039;&#039;&#039;Artifacts&#039;&#039;&#039;: Tangible, reviewable records directly resulting from a practice or process being performed by a system or by personnel executing their role within that practice, control, or process.&lt;br /&gt;
* &#039;&#039;&#039;Physical Review&#039;&#039;&#039;: Direct on-site observation and examination of evidence.&lt;br /&gt;
* &#039;&#039;&#039;Screen Share&#039;&#039;&#039;: Real-time remote observation of a user demonstrating a task or process via shared computer screen, sometimes called &amp;quot;over-the-shoulder&amp;quot; review.&lt;br /&gt;
&lt;br /&gt;
DISCLAIMER: Evidence requirements vary significantly across assessment types. &#039;&#039;&#039;The examples provided are illustrative only and should be tailored to meet the specific adequacy and sufficiency standards of your particular assessment context.&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
For inquiries and reporting errors on this wiki, please [mailto:support@cmmctoolkit.org contact us]. Thank you.&lt;br /&gt;
&lt;br /&gt;
== Access Control (AC) ==&lt;br /&gt;
=== AC.L2-3.1.1 – Authorized Access Control [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.1_Details|&#039;&#039;&#039;AC.L2-3.1.1&#039;&#039;&#039;]] Limit information system access to authorized users, processes acting on behalf of authorized users, or devices (including other information systems).&lt;br /&gt;
|-&lt;br /&gt;
| [a] authorized users are identified. || Document || Document defining account request, approval, provisioning.&lt;br /&gt;
|-&lt;br /&gt;
| [b] processes acting on behalf of authorized users are identified. || Document || Document defining account request, approval, provisioning.&lt;br /&gt;
|-&lt;br /&gt;
| [c] devices (and other systems) authorized to connect to the system are identified. || Document || Document defining account request, approval, provisioning.&lt;br /&gt;
|-&lt;br /&gt;
| [d] system access is limited to authorized users. || Screen Share || Screen share showing login requirements are enforced. Example of an unauthorized user denied (unauthorized username entered at login).&lt;br /&gt;
|-&lt;br /&gt;
| [e] system access is limited to processes acting on behalf of authorized users. || Screen Share || Screenshot showing that service accounts are assigned to authorized users only; no rogue accounts without an authorized user are active.&lt;br /&gt;
|-&lt;br /&gt;
| [f] system access is limited to authorized devices (including other systems). || Screen Share || Screen share showing that all devices running are authorized; no rogue devices on the network.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.2 – Transaction &amp;amp; Function Control [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.2_Details|&#039;&#039;&#039;AC.L2-3.1.2&#039;&#039;&#039;]] Limit information system access to the types of transactions and functions that authorized users are permitted to execute.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the types of transactions and functions that authorized users are permitted to execute are defined. || Document || SSP, AUP, or IAM document that defines what authorized users can execute.&lt;br /&gt;
|-&lt;br /&gt;
| [b] system access is limited to the defined types of transactions and functions for authorized users. || Screen Share || Screenshot of security roles in AD or IAM or other directory-based identity-related services tool that shows transactions are as defined in the SSP or IAM document; privileged and non-privileged accounts need to be defined and identified in the artifact; screenshot of a non-privileged user trying to execute a privileged function.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.3 – Control CUI Flow ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.3_Details|&#039;&#039;&#039;AC.L2-3.1.3&#039;&#039;&#039;]] Control the flow of CUI in accordance with approved authorizations.&lt;br /&gt;
|-&lt;br /&gt;
| [a] information flow control policies are defined. || Document || SSP or other document describing the control of CUI on the network.&lt;br /&gt;
|-&lt;br /&gt;
| [b] methods and enforcement mechanisms for controlling the flow of CUI are defined. || Document || Document that defines the networking devices that are on the CUI network and answers what measures are in place to control the flow. List of firewalls, border and internal layer 3 devices, IDS/IPS, DLP, that process CUI.&lt;br /&gt;
|-&lt;br /&gt;
| [c] designated sources and destinations (e.g., networks, individuals, and devices) for CUI within the system and between interconnected systems are identified. || Artifact || Network diagram, data flow diagram, external system connection diagrams, document describing the policies for CUI on the network; listing of VLANs and subnets where CUI is authorized; document must describe source and authorized destinations.&lt;br /&gt;
|-&lt;br /&gt;
| [d] authorizations for controlling the flow of CUI are defined. || Document || Document that defines how CUI is to be controlled, such as an InfoSec plan, and/or network management plan.&lt;br /&gt;
|-&lt;br /&gt;
| [e] approved authorizations for controlling the flow of CUI are enforced. || Screen Share || Screenshots of firewall rules, ACLs, etc.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.4 – Separation of Duties ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.4_Details|&#039;&#039;&#039;AC.L2-3.1.4&#039;&#039;&#039;]] Separate the duties of individuals to reduce the risk of malevolent activity without collusion.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the duties of individuals requiring separation are defined. || Document || Document, SSP, account management policy, defining separation of duties by person or role.&lt;br /&gt;
|-&lt;br /&gt;
| [b] responsibilities for duties that require separation are assigned to separate individuals. || Screen Share || Screenshot showing that separation of duties is enforced by showing admin accounts are assigned to different people based on role.&lt;br /&gt;
|-&lt;br /&gt;
| [c] access privileges that enable individuals to exercise the duties that require separation are granted to separate individuals. || Screen Share || Screen shot showing an example such as a security manager can not log into a network device and change ACLs, or network admins can not access security logs in the SIEM tool.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.5 – Least Privilege ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.5_Details|&#039;&#039;&#039;AC.L2-3.1.5&#039;&#039;&#039;]] Employ the principle of least privilege, including for specific security functions and privileged accounts.&lt;br /&gt;
|-&lt;br /&gt;
| [a] privileged accounts are identified. || Document || &amp;quot;SSP or policy (documentation) identify what is considered a privileged account.&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| [b] access to privileged accounts is authorized in accordance with the principle of least privilege. || Artifact || An artifact that identifies the least amount of permissions associated with different types of privileged accounts are approved.&lt;br /&gt;
|-&lt;br /&gt;
| [c] security functions are identified. || Document || &amp;quot;SSP or policy (documentation) identifies what is considered a security account.&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| [d] access to security functions is authorized in accordance with the principle of least privilege. || Artifact || Artifact(s) that identify the least amount of permissions associated with different types of security accounts are approved.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.6 – Non-Privileged Account Use ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.6_Details|&#039;&#039;&#039;AC.L2-3.1.6&#039;&#039;&#039;]] Use non-privileged accounts or roles when accessing nonsecurity functions.&lt;br /&gt;
|-&lt;br /&gt;
| [a] nonsecurity functions are identified. || Document || SSP or account management document, AUP, that defines non-security functions.&lt;br /&gt;
|-&lt;br /&gt;
| [b] users are required to use non-privileged accounts or roles when accessing nonsecurity functions. || Screen Share || Screenshot showing that a privileged user tried to use their admin account to access a non-security function, such as a browser or email (whatever is defined in their policy) and was blocked.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.7 – Privileged Functions ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.7_Details|&#039;&#039;&#039;AC.L2-3.1.7&#039;&#039;&#039;]] Prevent non-privileged users from executing privileged functions and capture the execution of such functions in audit logs.&lt;br /&gt;
|-&lt;br /&gt;
| [a] privileged functions are defined. || Document || SSP or policy (documentation) that defines privileged functions.&lt;br /&gt;
|-&lt;br /&gt;
| [b] non-privileged users are defined. || Document || SSP or policy (documentation) that defines non-privileged users.&lt;br /&gt;
|-&lt;br /&gt;
| [c] non-privileged users are prevented from executing privileged functions. || Screen Share || Screen share that shows that a non-privileged user is not allowed to complete a privileged function (installing software).&lt;br /&gt;
|-&lt;br /&gt;
| [d] the execution of privileged functions is captured in audit logs. || Screen Share || Screen share that shows logs being captured of the execution of privileged functions.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.8 – Unsuccessful Logon Attempts ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.8_Details|&#039;&#039;&#039;AC.L2-3.1.8&#039;&#039;&#039;]] Limit unsuccessful logon attempts.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the means of limiting unsuccessful logon attempts is defined. || Document || SSP or policy (documentation) showing unsuccessful logon attempts settings and or policy.&lt;br /&gt;
|-&lt;br /&gt;
| [b] the defined means of limiting unsuccessful logon attempts is implemented. || Artifact || Artifact showing GPO / Policy for limiting logon attempts.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.9 – Privacy &amp;amp; Security Notices ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.9_Details|&#039;&#039;&#039;AC.L2-3.1.9&#039;&#039;&#039;]] Provide privacy and security notices consistent with applicable CUI rules.&lt;br /&gt;
|-&lt;br /&gt;
| [a] privacy and security notices required by CUI-specified rules are identified, consistent, and associated with the specific CUI category. || Document || SSP or policy (documentation) showing CUI-specified rules are identified, consistent, and associated with the specific CUI category.&lt;br /&gt;
|-&lt;br /&gt;
| [b] privacy and security notices are displayed. || Artifact || Artifact that shows a consent banner or screen that a user sees as they log in to the system.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.10 – Session Lock ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.10_Details|&#039;&#039;&#039;AC.L2-3.1.10&#039;&#039;&#039;]] Use session lock with pattern-hiding displays to prevent access and viewing of data after a period of inactivity.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the period of inactivity after which the system initiates a session lock is defined. || Document || SSP or policy (documentation) that defines the period of inactivity and when a session lock is defined.&lt;br /&gt;
|-&lt;br /&gt;
| [b] access to the system and viewing of data is prevented by initiating a session lock after the defined period of inactivity. || Artifact || Artifact that shows the setting of session lock (GPO or system policy or similar solution addressing the controls supporting centralized management and configuration of operating systems, applications, and users&#039; settings for the working environment of user accounts and computer accounts).&lt;br /&gt;
|-&lt;br /&gt;
| [c] previously visible information is concealed via a pattern-hiding display after the defined period of inactivity. || Document || Screenshot of GPO setting and configuration settings, or similar solution addressing the controls supporting centralized management and configuration of operating systems, applications, and users&#039; settings for the working environment of user accounts and computer accounts.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.11 – Session Termination ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.11_Details|&#039;&#039;&#039;AC.L2-3.1.11&#039;&#039;&#039;]] Terminate (automatically) a user session after a defined condition.&lt;br /&gt;
|-&lt;br /&gt;
| [a] conditions requiring a user session to terminate are defined. || Document || SSP or policy (documentation) that defines the conditions requiring a user session to be terminated.&lt;br /&gt;
|-&lt;br /&gt;
| [b] a user session is automatically terminated after any of the defined conditions. || Screen Share || Screen share showing GPO / VPN Settings that show when a session would be terminated (Idle time, max connection time).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.12 – Control Remote Access ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.12_Details|&#039;&#039;&#039;AC.L2-3.1.12&#039;&#039;&#039;]] Monitor and control remote access sessions.&lt;br /&gt;
|-&lt;br /&gt;
| [a] remote access sessions are permitted. || Document || SSP or policy (documentation) that defines remote access sessions.&lt;br /&gt;
|-&lt;br /&gt;
| [b] the types of permitted remote access are identified. || Document || SSP or policy (documentation) that defines remote access is permitted.&lt;br /&gt;
|-&lt;br /&gt;
| [c] remote access sessions are controlled. || Screen Share || Screen share that shows how the remote access is controlled (access session, and or groups).&lt;br /&gt;
|-&lt;br /&gt;
| [d] remote access sessions are monitored. || Screen Share || Screen share that shows how remote sessions are monitored (logs).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.13 – Remote Access Confidentiality ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.13_Details|&#039;&#039;&#039;AC.L2-3.1.13&#039;&#039;&#039;]] Employ cryptographic mechanisms to protect the confidentiality of remote access sessions.&lt;br /&gt;
|-&lt;br /&gt;
| [a] cryptographic mechanisms to protect the confidentiality of remote access sessions are identified. || Document || SSP or policy (documentation) that discusses the CUI rules, consistent, and associated with the specific CUI category; FIPS Cert # of appliance or application.&lt;br /&gt;
|-&lt;br /&gt;
| [b] cryptographic mechanisms to protect the confidentiality of remote access sessions are implemented. || Screen Share || Screenshot of VPN concentration that shows encryption is on and enabled (point-to-point, etc.).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.14 – Remote Access Routing ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.14_Details|&#039;&#039;&#039;AC.L2-3.1.14&#039;&#039;&#039;]] Route remote access via managed access control points.&lt;br /&gt;
|-&lt;br /&gt;
| [a] managed access control points are identified and implemented. || Screen Share || Screen share that shows access control points (groups and/or users).&lt;br /&gt;
|-&lt;br /&gt;
| [b] remote access is routed through managed network access control points. || Screen Share || Screen share that shows access control points and how they are managed.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.15 – Privileged Remote Access ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.15_Details|&#039;&#039;&#039;AC.L2-3.1.15&#039;&#039;&#039;]] Authorize remote execution of privileged commands and remote access to security-relevant information.&lt;br /&gt;
|-&lt;br /&gt;
| [a] privileged commands authorized for remote execution are identified. || Document || SSP or policy (documentation) that defines what is authorized to be executed remotely and how that is handled.&lt;br /&gt;
|-&lt;br /&gt;
| [b] security-relevant information authorized to be accessed remotely is identified. || Document || SSP or policy (documentation) that defines what can be accessed remotely and what procedures are implemented to allow this (RDP, jump box).&lt;br /&gt;
|-&lt;br /&gt;
| [c] the execution of the identified privileged commands via remote access is authorized. || Artifact || Screen share that shows who has access to perform privileged commands a remotely (access groups for privileged accounts).&lt;br /&gt;
|-&lt;br /&gt;
| [d] access to the identified security-relevant information via remote access is authorized. || Artifact || Screen share that shows the routing of remote access and how it is monitored and how many locations (Firewall, VPN Concentrator).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.16 – Wireless Access Authorization ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.16_Details|&#039;&#039;&#039;AC.L2-3.1.16&#039;&#039;&#039;]] Authorize wireless access prior to allowing such connections.&lt;br /&gt;
|-&lt;br /&gt;
| [a] wireless access points are identified. || Document || SSP, network administration document.&lt;br /&gt;
|-&lt;br /&gt;
| [b] wireless access is authorized prior to allowing such connections. || Screen Share || Authorization profile(s) in Wireless Access Controller or Identity Manager (i.e. Cisco ISE).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.17 – Wireless Access Protection ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.17_Details|&#039;&#039;&#039;AC.L2-3.1.17&#039;&#039;&#039;]] Protect wireless access using authentication and encryption.&lt;br /&gt;
|-&lt;br /&gt;
| [a] wireless access to the system is protected using authentication. || Screen Share || Security page (or similar) of a Wireless Access Controller.&lt;br /&gt;
|-&lt;br /&gt;
| [b] wireless access to the system is protected using encryption. || Screen Share || Security page (or similar) of a Wireless Access Controller.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.18 – Mobile Device Connection ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.18_Details|&#039;&#039;&#039;AC.L2-3.1.18&#039;&#039;&#039;]] Control connection of mobile devices.&lt;br /&gt;
|-&lt;br /&gt;
| [a] mobile devices that process, store, or transmit CUI are identified. || Document || SSP, Mobile Device Policy.&lt;br /&gt;
|-&lt;br /&gt;
| [b] mobile device connections are authorized. || Artifact || Authorization profile(s) in Wireless Access Controller or Identity Manager (i.e. Cisco ISE).&lt;br /&gt;
|-&lt;br /&gt;
| [c] mobile device connections are monitored and logged. || Screen Share || Mobile device logs within the MDM, log intake (sources) configuration (within SIEM) showing MDM is feeding logs to the SIEM.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.19 – Encrypt CUI on Mobile ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.19_Details|&#039;&#039;&#039;AC.L2-3.1.19&#039;&#039;&#039;]] Encrypt CUI on mobile devices and mobile computing platforms.&lt;br /&gt;
|-&lt;br /&gt;
| [a] mobile devices and mobile computing platforms that process, store, or transmit CUI are identified. || Document || SSP, Mobile Device Policy.&lt;br /&gt;
|-&lt;br /&gt;
| [b] encryption is employed to protect CUI on identified mobile devices and mobile computing platforms. || Screen Share || Security policy page in MDM showing how encryption are enforced on mobile device. If no MDM or MDM doesn&#039;t enforce encryption, then validate if the devices used are on the list of devices with native FIPS approved validation.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.20 – External Connections [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.20_Details|&#039;&#039;&#039;AC.L2-3.1.20&#039;&#039;&#039;]] Verify and control/limit connections to and use of external information systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] connections to external systems are identified. || Document || SSP, Systems Interconnection Agreements, SLA.&lt;br /&gt;
|-&lt;br /&gt;
| [b] the use of external systems is identified. || Document || SSP, Systems Interconnection Agreements, SLA.&lt;br /&gt;
|-&lt;br /&gt;
| [c] connections to external systems are verified. || Artifact || SLA for external systems, memorandum for interconnection, information to prove that any cloud solution is at FedRAMP impact level of moderate or higher (i.e. license information, screenshot of AWS cloud dashboard, purchase order document).&lt;br /&gt;
|-&lt;br /&gt;
| [d] the use of external systems is verified. || Artifact || SLA for external systems, memorandum for interconnection, information to prove that any cloud solution is at FedRAMP impact level of moderate or higher (i.e. license information, screenshot of AWS cloud dashboard, purchase order document).&lt;br /&gt;
|-&lt;br /&gt;
| [e] connections to external systems are controlled/limited. || Screen Share || Firewall ruleset for controlling access to cloud service or external system.&lt;br /&gt;
|-&lt;br /&gt;
| [f] the use of external systems is controlled/limited. || Screen Share || Firewall ruleset for controlling access to cloud service or external system.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.21 – Portable Storage Use ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.21_Details|&#039;&#039;&#039;AC.L2-3.1.21&#039;&#039;&#039;]] Limit use of portable storage devices on external systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the use of portable storage devices containing CUI on external systems is identified and documented. || Document || SSP, Removable Media Policy, Acceptable Use Policy (with emphasis on portable media use).&lt;br /&gt;
|-&lt;br /&gt;
| [b] limits on the use of portable storage devices containing CUI on external systems are defined. || Document || SSP, Removable Media Policy, Acceptable Use Policy (with emphasis on portable media use).&lt;br /&gt;
|-&lt;br /&gt;
| [c] the use of portable storage devices containing CUI on external systems is limited as defined. || Document || SSP, Removable Media Policy, Acceptable Use Policy (with emphasis on portable media use).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.22 – Control Public Information [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.22_Details|&#039;&#039;&#039;AC.L2-3.1.22&#039;&#039;&#039;]] Control information posted or processed on publicly accessible information systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] individuals authorized to post or process information on publicly accessible systems are identified. || Document || SSP, Website Governance Plan, Information Release Document.&lt;br /&gt;
|-&lt;br /&gt;
| [b] procedures to ensure CUI is not posted or processed on publicly accessible systems are identified. || Document || SSP, Website Governance Plan, Information Release Document.&lt;br /&gt;
|-&lt;br /&gt;
| [c] a review process is in place prior to posting of any content to publicly accessible systems. || Artifact || &amp;quot;Information release approval process, i.e. chain of email communication from originator, approver, and final decision (may or may not include individual authorized to post); &lt;br /&gt;
SharePoint/electronic or paper form/ ticket system showing information flow between requestor and approver (may or may not include  individual authorized to post).&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| [d] content on publicly accessible systems is reviewed to ensure that it does not include CUI. || Artifact || Incident response process, web design/update/modification SOP etc.&lt;br /&gt;
|-&lt;br /&gt;
| [e] mechanisms are in place to remove and address improper posting of CUI. || Artifact || Incident response process, web design/update/modification SOP etc.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Awareness and Training (AT) ==&lt;br /&gt;
=== AT.L2-3.2.1 – Role-Based Risk Awareness ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AT.L2-3.2.1_Details|&#039;&#039;&#039;AT.L2-3.2.1&#039;&#039;&#039;]] Ensure that managers, systems administrators, and users of organizational systems are made aware of the security risks associated with their activities and of the applicable policies, standards, and procedures related to the security of those systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] security risks associated with organizational activities involving CUI are identified. || Document || Policy of Security Awareness Training; Security Awareness Training Briefing.&lt;br /&gt;
|-&lt;br /&gt;
| [b] policies, standards, and procedures related to the security of the system are identified. || Document || Acceptable Use Policy, Policy/Procedures/Instruction related to the security of the system.&lt;br /&gt;
|-&lt;br /&gt;
| [c] managers, systems administrators, and users of the system are made aware of the security risks associated with their activities. || Artifact || Security Training Brief, training records.&lt;br /&gt;
|-&lt;br /&gt;
| [d] managers, systems administrators, and users of the system are made aware of the applicable policies, standards, and procedures related to the security of the system. || Artifact || Policies, standards and procedures for employees within training (completed training report).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AT.L2-3.2.2 – Role-Based Training ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AT.L2-3.2.2_Details|&#039;&#039;&#039;AT.L2-3.2.2&#039;&#039;&#039;]] Ensure that personnel are trained to carry out their assigned information security-related duties and responsibilities.|-&lt;br /&gt;
|-&lt;br /&gt;
| [a] information security-related duties, roles, and responsibilities are defined. || Document || Policy/Procedures/Instruction, Job Role Matrix, Position Descriptions, User Roles.&lt;br /&gt;
|-&lt;br /&gt;
| [b] information security-related duties, roles, and responsibilities are assigned to designated personnel. || Artifact || Screenshot of breakout of different roles/permissions assigned to individuals (i.e. ActiveDirectory); Privilege Access Agreement.&lt;br /&gt;
|-&lt;br /&gt;
| [c] personnel are adequately trained to carry out their assigned information security-related duties, roles, and responsibilities. || Artifact || Screenshot of tool and/or training specifying security specific roles, duties and responsibilities; Screenshot of required certifications (i.e. Sec+, CISSP).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AT.L2-3.2.3 – Insider Threat Awareness ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AT.L2-3.2.3_Details|&#039;&#039;&#039;AT.L2-3.2.3&#039;&#039;&#039;]] Provide security awareness training on recognizing and reporting potential indicators of insider threat.&lt;br /&gt;
|-&lt;br /&gt;
| [a] potential indicators associated with insider threats are identified. || Document || Insidert Threat Policy/Procedures/Instruction; Insider Threat Training/Briefing.&lt;br /&gt;
|-&lt;br /&gt;
| [b] security awareness training on recognizing and reporting potential indicators of insider threat is provided to managers and employees. || Artifact || Screenshot of training records showing completion of Insider Threat training, emails showing completion of Insider Threat training, Screenshot of certificate showing completion with individual&#039;s name.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Audit and Accountability (AU) ==&lt;br /&gt;
=== AU.L2-3.3.1 – System Auditing ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AU.L2-3.3.1_Details|&#039;&#039;&#039;AU.L2-3.3.1&#039;&#039;&#039;]] Create and retain system audit logs and records to the extent needed to enable the monitoring, analysis, investigation, and reporting of unlawful or unauthorized system activity.&lt;br /&gt;
|-&lt;br /&gt;
| [a] audit logs needed (i.e., event types to be logged) to enable the monitoring, analysis, investigation, and reporting of unlawful or unauthorized system activity are specified. || Document || SSP, policy, or auditing and logging process that defines specific types of events to be logged.&lt;br /&gt;
|-&lt;br /&gt;
| [b] the content of audit records needed to support monitoring, analysis, investigation, and reporting of unlawful or unauthorized system activity is defined. || Document || SSP, policy, or auditing and logging process that defines specific content of audit records/files.&lt;br /&gt;
|-&lt;br /&gt;
| [c] audit records are created (generated). || Screen Share || Screen share of tool that shows logs are generated for all systems.&lt;br /&gt;
|-&lt;br /&gt;
| [d] audit records, once created, contain the defined content. || Screen Share || Screen share of tool that shows logs contain defined content as defined in SSP, policy, or procedures.&lt;br /&gt;
|-&lt;br /&gt;
| [e] retention requirements for audit records are defined. || Document || SSP, Polocy, or Auditing and logging process that describes how long records are kept.&lt;br /&gt;
|-&lt;br /&gt;
| [f] audit records are retained as defined. || Screen Share || Screen share of tool that shows records and audit content retained at a minimum as defined.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AU.L2-3.3.2 – User Accountability ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AU.L2-3.3.2_Details|&#039;&#039;&#039;AU.L2-3.3.2&#039;&#039;&#039;]] Ensure that the actions of individual system users can be uniquely traced to those users so they can be held accountable for their actions.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the content of the audit records needed to support the ability to uniquely trace users to their actions is defined. || Document || SSP, policy, or process that defines actions traced back to individuals.&lt;br /&gt;
|-&lt;br /&gt;
| [b] audit records, once created, contain the defined content. || Screen Share || Screen share of tool that shows audit records traced to specific users/roles.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AU.L2-3.3.3 – Event Review ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AU.L2-3.3.3_Details|&#039;&#039;&#039;AU.L2-3.3.3&#039;&#039;&#039;]] Review and update logged events.&lt;br /&gt;
|-&lt;br /&gt;
| [a] a process for determining when to review logged events is defined. || Document || SSP, policy, or documented process that shows frequency of when to review types of logged events.&lt;br /&gt;
|-&lt;br /&gt;
| [b] event types being logged are reviewed in accordance with the defined review process. || Artifact || Evidence through a documented method such as meeting minutes, CAB minutes, etc. of log sources and log events being logged at the defined frequency.&lt;br /&gt;
|-&lt;br /&gt;
| [c] event types being logged are updated based on the review. || Artifact || Evidence of implementation based on the results of the review of logged events/sources through a ticket, meeting minutes, or screen share of the tool that shows changes implemented (finetuning).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AU.L2-3.3.4 – Audit Failure Alerting ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AU.L2-3.3.4_Details|&#039;&#039;&#039;AU.L2-3.3.4&#039;&#039;&#039;]] Alert in the event of an audit logging process failure.&lt;br /&gt;
|-&lt;br /&gt;
| [a] personnel or roles to be alerted in the event of an audit logging process failure are identified. || Document || SSP, policy, or procedure that shows who needs to be notified in case of an audit failure.&lt;br /&gt;
|-&lt;br /&gt;
| [b] types of audit logging process failures for which alert will be generated are defined. || Document || SSP, policy, or procedure that shows what types of failure will generate notifications.&lt;br /&gt;
|-&lt;br /&gt;
| [c] identified personnel or roles are alerted in the event of an audit logging process failure. || Artifact || Artifact such as email or ticket that shows the identified personnel were alerted of any audit/logging process failure as defined.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AU.L2-3.3.5 – Audit Correlation ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AU.L2-3.3.5_Details|&#039;&#039;&#039;AU.L2-3.3.5&#039;&#039;&#039;]] Correlate audit record review, analysis, and reporting processes for investigation and response to indications of unlawful, unauthorized, suspicious, or unusual activity.&lt;br /&gt;
|-&lt;br /&gt;
| [a] audit record review, analysis, and reporting processes for investigation and response to indications of unlawful, unauthorized, suspicious, or unusual activity are defined. || Document || SSP, policy, or procedure covering audit logging, monitoring, and reporting.&lt;br /&gt;
|-&lt;br /&gt;
| [b] defined audit record review, analysis, and reporting processes are correlated. || Artifact || Artifact showing an audit event and the resultant corrective action or actions to the event; this can be a Help Desk ticket, meeting notes, or a change control board items showing the event and any corrective action taken.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AU.L2-3.3.6 – Reduction &amp;amp; Reporting ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AU.L2-3.3.6_Details|&#039;&#039;&#039;AU.L2-3.3.6&#039;&#039;&#039;]] Provide audit record reduction and report generation to support on-demand analysis and reporting.&lt;br /&gt;
|-&lt;br /&gt;
| [a] an audit record reduction capability that supports on-demand analysis is provided. || Screen Share || Screen share of the logging environment where an event can be selected and traced back to a specific device, or dashboard showing realtime event analysis.&lt;br /&gt;
|-&lt;br /&gt;
| [b] a report generation capability that supports on-demand reporting is provided. || Screen Share || Screen share showing the generation of an on demand report.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AU.L2-3.3.7 – Authoritative Time Source ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AU.L2-3.3.7_Details|&#039;&#039;&#039;AU.L2-3.3.7&#039;&#039;&#039;]] Provide a system capability that compares and synchronizes internal system clocks with an authoritative source to generate time stamps for audit records.&lt;br /&gt;
|-&lt;br /&gt;
| [a] internal system clocks are used to generate time stamps for audit records. || Screen Share || Screen share showing the NTP settings of a windows, Unix, Linux device; a screen share showing the NTP settings of network appliances.&lt;br /&gt;
|-&lt;br /&gt;
| [b] an authoritative source with which to compare and synchronize internal system clocks is specified. || Document || SSP or policy indicating that devices need to be synched to a local authoritative time device that is synched with an authoritative time service.&lt;br /&gt;
|-&lt;br /&gt;
| [c] internal system clocks used to generate time stamps for audit records are compared to and synchronized with the specified authoritative time source. || Screen Share || Screen share showing device logging appliance time is point to the appropriate authoritative time server.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AU.L2-3.3.8 – Audit Protection ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AU.L2-3.3.8_Details|&#039;&#039;&#039;AU.L2-3.3.8&#039;&#039;&#039;]] Protect audit information and audit logging tools from unauthorized access, modification, and deletion.&lt;br /&gt;
|-&lt;br /&gt;
| [a] audit information is protected from unauthorized access. || Screen Share || Screen share showing operating system permissions on the audit folders being restricted to appropriate users.&lt;br /&gt;
|-&lt;br /&gt;
| [b] audit information is protected from unauthorized modification. || Screen Share || Screen share showing operating system permissions on the audit folders being restricted to appropriate users.&lt;br /&gt;
|-&lt;br /&gt;
| [c] audit information is protected from unauthorized deletion. || Screen Share || Screen share showing operating system permissions on the audit folders being restricted to appropriate users.&lt;br /&gt;
|-&lt;br /&gt;
| [d] audit logging tools are protected from unauthorized access. || Screen Share || Artifact showing access permissions in the SIEM tool.&lt;br /&gt;
|-&lt;br /&gt;
| [e] audit logging tools are protected from unauthorized modification. || Screen Share || Artifact showing update permissions in the SIEM tool.&lt;br /&gt;
|-&lt;br /&gt;
| [f] audit logging tools are protected from unauthorized deletion. || Screen Share || Artifact showing delete permissions in the SIEM tool.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AU.L2-3.3.9 – Audit Management ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AU.L2-3.3.9_Details|&#039;&#039;&#039;AU.L2-3.3.9&#039;&#039;&#039;]] Limit management of audit logging functionality to a subset of privileged users.&lt;br /&gt;
|-&lt;br /&gt;
| [a] a subset of privileged users granted access to manage audit logging functionality is defined. || Document || SSP or policy indicating which users or groups have access to audit logs.&lt;br /&gt;
|-&lt;br /&gt;
| [b] management of audit logging functionality is limited to the defined subset of privileged users. || Screen Share || Artifact showing SIEM or OS folder permissions (this should be limited to the assigned users or groups); artifact showing an ACL setting in SIEM tool in regards to logs.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Configuration Management (CM) ==&lt;br /&gt;
=== CM.L2-3.4.1 – System Baselining ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_CM.L2-3.4.1_Details|&#039;&#039;&#039;CM.L2-3.4.1&#039;&#039;&#039;]] Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles.&lt;br /&gt;
|-&lt;br /&gt;
| [a] a baseline configuration is established. || Document || Documentation showing or explaining standard imaging process (how standard images are deployed and where  they are stored).&lt;br /&gt;
|-&lt;br /&gt;
| [b] the baseline configuration includes hardware, software, firmware, and documentation. || Artifact || Screenshot of repository of where images are maintained and information relating to hardware, software, and firmware.&lt;br /&gt;
|-&lt;br /&gt;
| [c] the baseline configuration is maintained (reviewed and updated) throughout the system development life cycle. || Artifact || Screenshot/evidence displaying management of baseline configurations (how often they are being managed as stated).&lt;br /&gt;
|-&lt;br /&gt;
| [d] a system inventory is established. || Document || Screenshot/evidence displaying inventory listing of approved products for use.&lt;br /&gt;
|-&lt;br /&gt;
| [e] the system inventory includes hardware, software, firmware, and documentation. || Artifact || Screeenshot/evidence displaying inventory listing of approved products and versions permitted for use.&lt;br /&gt;
|-&lt;br /&gt;
| [f] the inventory is maintained (reviewed and updated) throughout the system development life cycle. || Artifact || Screeenshot/evidence displaying management of baseline configurations (How often and are they being managed as stated.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== CM.L2-3.4.2 – Security Configuration Enforcement ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_CM.L2-3.4.2_Details|&#039;&#039;&#039;CM.L2-3.4.2&#039;&#039;&#039;]] Establish and enforce security configuration settings for information technology products employed in organizational systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] security configuration settings for information technology products employed in the system are established and included in the baseline configuration. || Document || Documentation explaining methodology used by organization to create secure baselines (STIGs, benchmarks).&lt;br /&gt;
|-&lt;br /&gt;
| [b] security configuration settings for information technology products employed in the system are enforced. || Artifact || Evidence of tool/s used to enforce security configurations to ensure images used are free from modification unless authorized.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== CM.L2-3.4.3 – System Change Management ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_CM.L2-3.4.3_Details|&#039;&#039;&#039;CM.L2-3.4.3&#039;&#039;&#039;]] Track, review, approve or disapprove, and log changes to organizational systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] changes to the system are tracked. || Artifact || Evidence of IT Service Management tool / process used to track system changes.&lt;br /&gt;
|-&lt;br /&gt;
| [b] changes to the system are reviewed. || Artifact || Evidence of IT Service Management tool / process used to review system changes.&lt;br /&gt;
|-&lt;br /&gt;
| [c] changes to the system are approved or disapproved. || Artifact || Evidence of IT Service Management tool / process used to approve/disapprove system changes.&lt;br /&gt;
|-&lt;br /&gt;
| [d] changes to the system are logged. || Artifact || Evidence of IT Service Management tool / process used to log system changes.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== CM.L2-3.4.4 – Security Impact Analysis ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_CM.L2-3.4.4_Details|&#039;&#039;&#039;CM.L2-3.4.4&#039;&#039;&#039;]] Analyze the security impact of changes prior to implementation.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the security impact of changes to the system is analyzed prior to implementation. || Artifact || Document explaining that security impact analysis of proposed changes to a system is conducted prior to implementation.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== CM.L2-3.4.5 – Access Restrictions for Change ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_CM.L2-3.4.5_Details|&#039;&#039;&#039;CM.L2-3.4.5&#039;&#039;&#039;]] Define, document, approve, and enforce physical and logical access restrictions associated with changes to organizational systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] physical access restrictions associated with changes to the system are defined. || Document || Document explaining the process of how physical access restrictions are defined for an individuals ability to make system changes.&lt;br /&gt;
|-&lt;br /&gt;
| [b] physical access restrictions associated with changes to the system are documented. || Document || Document explaining the process of how physical access restrictions are defined for an individuals ability to make system changes are documented; access request process.&lt;br /&gt;
|-&lt;br /&gt;
| [c] physical access restrictions associated with changes to the system are approved. || Artifact || Evidence of process of how physical access to systems are granted (i.e. physical access request sample).&lt;br /&gt;
|-&lt;br /&gt;
| [d] physical access restrictions associated with changes to the system are enforced. || Physical Review || Evidence of process of how physical access to systems are enforced (physical access system).&lt;br /&gt;
|-&lt;br /&gt;
| [e] logical access restrictions associated with changes to the system are defined. || Document || Document explaining the process of how logical access restrictions are defined for an individual&#039;s ability to make system changes.&lt;br /&gt;
|-&lt;br /&gt;
| [f] logical access restrictions associated with changes to the system are documented. || Document || Document explaining the process of how logical access restrictions are defined for an individual&#039;s ability to make system changes are documented.&lt;br /&gt;
|-&lt;br /&gt;
| [g] logical access restrictions associated with changes to the system are approved. || Artifact || Evidence of process of how logical access to systems are granted.&lt;br /&gt;
|-&lt;br /&gt;
| [h] logical access restrictions associated with changes to the system are enforced. || Artifact || Evidence of process of how logical access to systems are enforced.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== CM.L2-3.4.6 – Least Functionality ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_CM.L2-3.4.6_Details|&#039;&#039;&#039;CM.L2-3.4.6&#039;&#039;&#039;]] Employ the principle of least functionality by configuring organizational systems to provide only essential capabilities.&lt;br /&gt;
|-&lt;br /&gt;
| [a] essential system capabilities are defined based on the principle of least functionality. || Document || Documentation explaining how systems are configured to utilize the principle of least functionality for designated users.&lt;br /&gt;
|-&lt;br /&gt;
| [b] the system is configured to provide only the defined essential capabilities. || Screen Share || Evidence displaying how systems are configured to utilize the principle of least functionality for designated users; disabled service settings, accepted standards for hardening (CIS benchmarks, etc.).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== CM.L2-3.4.7 – Nonessential Functionality ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_CM.L2-3.4.7_Details|&#039;&#039;&#039;CM.L2-3.4.7&#039;&#039;&#039;]] Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services.&lt;br /&gt;
|-&lt;br /&gt;
| [a] essential programs are defined. || Document || Documented essential programs specified; build documents; software center; SSP.&lt;br /&gt;
|-&lt;br /&gt;
| [b] the use of nonessential programs is defined. || Document || Documented listing of nonessential programs (whatever is NOT specified in [a]); AUP/User Agreement may identify nonessential use/programs.&lt;br /&gt;
|-&lt;br /&gt;
| [c] the use of nonessential programs is restricted, disabled, or prevented as defined. || Screen Share || Tool used to restrict nonessential programs displays restrictions as defined (McAfee ePO settings, Carbon Black rules, etc.).&lt;br /&gt;
|-&lt;br /&gt;
| [d] essential functions are defined. || Document || Documented essential functions are specified.&lt;br /&gt;
|-&lt;br /&gt;
| [e] the use of nonessential functions is defined. || Document || Documented nonessential functions are specified.&lt;br /&gt;
|-&lt;br /&gt;
| [f] the use of nonessential functions is restricted, disabled, or prevented as defined. || Screen Share || Tool used to restrict essential/nonessential functions displays restrictions as defined.&lt;br /&gt;
|-&lt;br /&gt;
| [g] essential ports are defined. || Document || Documented essential ports are specified.&lt;br /&gt;
|-&lt;br /&gt;
| [h] the use of nonessential ports is defined. || Document || Documented nonessential ports functions are specified.&lt;br /&gt;
|-&lt;br /&gt;
| [i] the use of nonessential ports is restricted, disabled, or prevented as defined. || Screen Share || Tool used to restrict essential/nonessential ports displays restrictions as defined (FW rules; McAfee; GPO, etc.).&lt;br /&gt;
|-&lt;br /&gt;
| [j] essential protocols are defined. || Document || Documented essential protocols are specified.&lt;br /&gt;
|-&lt;br /&gt;
| [k] the use of nonessential protocols is defined. || Document || Documented nonessential protocols functions are specified.&lt;br /&gt;
|-&lt;br /&gt;
| [l] the use of nonessential protocols is restricted, disabled, or prevented as defined. || Screen Share || Tool used to restrict essential/nonessential protocols displays restrictions as defined (FW rules; GPO, etc.).&lt;br /&gt;
|-&lt;br /&gt;
| [m] essential services are defined. || Document || Documented essential services specified.&lt;br /&gt;
|-&lt;br /&gt;
| [n] the use of nonessential services is defined. || Document || Documented nonessential services functions are specified.&lt;br /&gt;
|-&lt;br /&gt;
| [o] the use of nonessential services is restricted, disabled, or prevented as defined. || Screen Share || Tool used to restrict essential/nonessential services displays restrictions as defined.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== CM.L2-3.4.8 – Application Execution Policy ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_CM.L2-3.4.8_Details|&#039;&#039;&#039;CM.L2-3.4.8&#039;&#039;&#039;]] Apply deny-by-exception (blacklisting) policy to prevent the use of unauthorized software or deny-all, permit-by-exception (whitelisting) policy to allow the execution of authorized software.&lt;br /&gt;
|-&lt;br /&gt;
| [a] a policy specifying whether whitelisting or blacklisting is to be implemented is specified. || Document || Documentation explaining whitelisting or blacklisting process.&lt;br /&gt;
|-&lt;br /&gt;
| [b] the software allowed to execute under whitelisting or denied use under blacklisting is specified. || Document || Documentation explaining whitelisting or blacklisting process for software.&lt;br /&gt;
|-&lt;br /&gt;
| [c] whitelisting to allow the execution of authorized software or blacklisting to prevent the use of unauthorized software is implemented as specified. || Screen Share || Tool used for whitelisting or blacklisting for software shows capability of restricting/authorizing software (Carbon Black dashboard, &amp;quot;SW Store&amp;quot;, web proxies, DNS Blackhole, etc.).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== CM.L2-3.4.9 – User-Installed Software ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_CM.L2-3.4.9_Details|&#039;&#039;&#039;CM.L2-3.4.9&#039;&#039;&#039;]] Control and monitor user-installed software.&lt;br /&gt;
|-&lt;br /&gt;
| [a] a policy for controlling the installation of software by users is established. || Document || Documented software authorization process or methodology for approval.&lt;br /&gt;
|-&lt;br /&gt;
| [b] installation of software by users is controlled based on the established policy. || Screen Share || Evidence that approval/restriction in installation of software by authorized personnel is implemented as specified (AUP, GPO, etc.).&lt;br /&gt;
|-&lt;br /&gt;
| [c] installation of software by users is monitored. || Screen Share || Evidence that installation of software by authorized personnel is monitored (SCCM groups, SW Center, etc.).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Identification and Authentication (IA) ==&lt;br /&gt;
=== IA.L2-3.5.1 – Identification [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IA.L2-3.5.1_Details|&#039;&#039;&#039;IA.L2-3.5.1&#039;&#039;&#039;]] Identify information system users, processes acting on behalf of users, or devices.&lt;br /&gt;
|-&lt;br /&gt;
| [a] system users are identified. || Document || Based on what is defined in their documentation (SSP, AUP, Policy, SOP), request to see a sample of non-privileged/privileged users in AD OU group (overlaps with 3.1.1 and 3.1.5).&lt;br /&gt;
|-&lt;br /&gt;
| [b] processes acting on behalf of users are identified. || Document || Based on what is defined in their documentation (SSP, AUP, Policy, SOP), request to see a sample of service accounts in AD OU group (overlaps with 3.1.1 and 3.1.5).&lt;br /&gt;
|-&lt;br /&gt;
| [c] devices accessing the system are identified. || Document || Based on what is defined in their documentation (SSP, AUP, Policy, SOP), request to see a sample of domain-joined workstation &amp;amp; servers in AD OU group (overlaps with 3.1.1 and 3.1.5).  For network devices, request screen share/artifact to show how they are identified on the enterprise network.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IA.L2-3.5.2 – Authentication [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IA.L2-3.5.2_Details|&#039;&#039;&#039;IA.L2-3.5.2&#039;&#039;&#039;]] Authenticate (or verify) the identities of those users, processes, or devices, as a prerequisite to allowing access to organizational information systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the identity of each user is authenticated or verified as a prerequisite to system access. || Screen Share || If the user logs in with non-privileged account during other demoes and then a privileged account, then this should be satisfied.  If screen share is unavailable, request logs to show successful and unsuccessful login by privileged and non-privilged users.&lt;br /&gt;
|-&lt;br /&gt;
| [b] the identity of each process acting on behalf of a user is authenticated or verified as a prerequisite to system access. || Screen Share || Request a log that shows successful/unsuccessful service account trying to log on to company&#039;s asset.&lt;br /&gt;
|-&lt;br /&gt;
| [c] the identity of each device accessing or connecting to the system is authenticated or verified as a prerequisite to system access. || Screen Share || Request a log that shows domain-joined workstation/server authenticating to AD (focus on the MAC/IP address/hostname).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IA.L2-3.5.3 – Multifactor Authentication ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IA.L2-3.5.3_Details|&#039;&#039;&#039;IA.L2-3.5.3&#039;&#039;&#039;]] Use multifactor authentication for local and network access to privileged accounts and for network access to non-privileged accounts.&lt;br /&gt;
|-&lt;br /&gt;
| [a] privileged accounts are identified. || Document || Based on what is defined in their documentation, request to see a sample of privileged users in AD OU group.  Overlaps with 3.1.5.  Screenshot/screen share to show implementation is enforced.&lt;br /&gt;
|-&lt;br /&gt;
| [b] multifactor authentication is implemented for local access to privileged accounts. || Screen Share || SSP, AUP, Policy, SOP that defines that MFA is needed for privileged local access.&lt;br /&gt;
|-&lt;br /&gt;
| [c] multifactor authentication is implemented for network access to privileged accounts. || Screen Share || Within the MFA implementation mechanism, show that privileged users are forced to use MFA;  Screenshot/Screen share to show implementation is enforced.&lt;br /&gt;
|-&lt;br /&gt;
| [d] multifactor authentication is implemented for network access to non-privileged accounts. || Screen Share || Within the MFA implementation mechanism, show that non-privileged users are forced to use MFA; Screenshot/Screen share to show implementation is enforced.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IA.L2-3.5.4 – Replay-Resistant Authentication ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IA.L2-3.5.4_Details|&#039;&#039;&#039;IA.L2-3.5.4&#039;&#039;&#039;]] Employ replay-resistant authentication mechanisms for network access to privileged and non-privileged accounts.&lt;br /&gt;
|-&lt;br /&gt;
| [a] replay-resistant authentication mechanisms are implemented for network account access to privileged and non-privileged accounts. || Screen Share || Show the GPO setting that enforces Kerberos within AD.  If MFA is used, show the implementation to enforce replay resistant techniques.  For non-windows, show the technical solution to enforce replay resistant attacks.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IA.L2-3.5.5 – Identifier Reuse ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IA.L2-3.5.5_Details|&#039;&#039;&#039;IA.L2-3.5.5&#039;&#039;&#039;]] Prevent reuse of identifiers for a defined period.&lt;br /&gt;
|-&lt;br /&gt;
| [a] a period within which identifiers cannot be reused is defined. || Document || SSP, policies, or SOP that defines identifier reuse.&lt;br /&gt;
|-&lt;br /&gt;
| [b] reuse of identifiers is prevented within the defined period. || Artifact || Show the GPO setting/technical solution that enforces what is defined in policy/documentation (this can be automated or manual process; screen share/artifacts can be presented to satisfy this requirement.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IA.L2-3.5.6 – Identifier Handling ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IA.L2-3.5.6_Details|&#039;&#039;&#039;IA.L2-3.5.6&#039;&#039;&#039;]] Disable identifiers after a defined period of inactivity.&lt;br /&gt;
|-&lt;br /&gt;
| [a] a period of inactivity after which an identifier is disabled is defined. || Document || SSP, policy that defines the period of inactivity after which an identifier is disabled.&lt;br /&gt;
|-&lt;br /&gt;
| [b] identifiers are disabled after the defined period of inactivity. || Artifact || Screen share AD or similar tool supporting directory-based identity-related services for disabled accounts (can be done by hand or script).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IA.L2-3.5.7 – Password Complexity ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IA.L2-3.5.7_Details|&#039;&#039;&#039;IA.L2-3.5.7&#039;&#039;&#039;]] Enforce a minimum password complexity and change of characters when new passwords are created.&lt;br /&gt;
|-&lt;br /&gt;
| [a] password complexity requirements are defined. || Document || SSP, policy that defines password complexity requirements.&lt;br /&gt;
|-&lt;br /&gt;
| [b] password change of character requirements are defined. || Document || SSP, policy that defines change of character requirements are defined.&lt;br /&gt;
|-&lt;br /&gt;
| [c] minimum password complexity requirements as defined are enforced when new passwords are created. || Screen Share || Screen share of AD or similar directory-based identity-related service tool to show complexity requirements.&lt;br /&gt;
|-&lt;br /&gt;
| [d] minimum password change of character requirements as defined are enforced when new passwords are created. || Screen Share || Screen share of Group Policy configuration or similar tool providing centralized management and configuration of operating systems, applications, and users&#039; settings to show that characters must be changed.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IA.L2-3.5.8 – Password Reuse ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IA.L2-3.5.8_Details|&#039;&#039;&#039;IA.L2-3.5.8&#039;&#039;&#039;]] Prohibit password reuse for a specified number of generations.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the number of generations during which a password cannot be reused is specified. || Document || SSP, policy that specifies the number of generations during which a password cannot be reused is specified.&lt;br /&gt;
|-&lt;br /&gt;
| [b] reuse of passwords is prohibited during the specified number of generations. || Screen Share || Screen share Group Policy or similar tool providing centralized management and configuration of operating systems, applications, and users&#039; settings in a directory-based identity-related service tool&#039;s configuration to show reuse of passwords is prohibited.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IA.L2-3.5.9 – Temporary Passwords ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IA.L2-3.5.9_Details|&#039;&#039;&#039;IA.L2-3.5.9&#039;&#039;&#039;]] Allow temporary password use for system logons with an immediate change to a permanent password.&lt;br /&gt;
|-&lt;br /&gt;
| [a] an immediate change to a permanent password is required when a temporary password is used for system logon. || Screen Share || Screen share of Group Policy or similar tool providing centralized management and configuration of operating systems, applications, and users&#039; settings in a directory-based identity-related service tool&#039;s configuration to show &amp;quot;change password at first logon.&amp;quot;&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IA.L2-3.5.10 – Cryptographically-Protected Passwords ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IA.L2-3.5.1_Details|&#039;&#039;&#039;IA.L2-3.5.1&#039;&#039;&#039;]] Store and transmit only cryptographically-protected passwords.&lt;br /&gt;
|-&lt;br /&gt;
| [a] passwords are cryptographically protected in storage. || Screen Share || Screen share Group Policy or similar tool providing centralized management and configuration of operating systems, applications, and users&#039; settings in a directory-based identity-related service tool&#039;s configuration that Kerberos, or a similar network authentication protocol that works on the basis of tickets to allow nodes communicating over a non-secure network to prove their identity to one another in a secure manner, is enabled.&lt;br /&gt;
|-&lt;br /&gt;
| [b] passwords are cryptographically protected in transit. || Screen Share || Screen share Group Policy or similar tool providing centralized management and configuration of operating systems, applications, and users&#039; settings in a directory-based identity-related service tool&#039;s configuration that Kerberos, or a similar network authentication protocol that works on the basis of tickets to allow nodes communicating over a non-secure network to prove their identity to one another in a secure manner, is enabled.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IA.L2-3.5.11 – Obscure Feedback ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IA.L2-3.5.10_Details|&#039;&#039;&#039;IA.L2-3.5.10&#039;&#039;&#039;]] Obscure feedback of authentication information.&lt;br /&gt;
|-&lt;br /&gt;
| [a] authentication information is obscured during the authentication process. || Screen Share || Screen share of Group Policy or similar tool providing centralized management and configuration of operating systems, applications, and users&#039; settings in a directory-based identity-related service tool&#039;s configuration to show that passwords are obscured.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Incident Response (IR) ==&lt;br /&gt;
=== IR.L2-3.6.1 – Incident Handling ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IR.L2-3.6.1_Details|&#039;&#039;&#039;IR.L2-3.6.1&#039;&#039;&#039;]] Establish an operational incident-handling capability for organizational systems that includes preparation, detection, analysis, containment, recovery, and user response activities.&lt;br /&gt;
|-&lt;br /&gt;
| [a] an operational incident-handling capability is established. || Document || Incident Response SOP/Plan.&lt;br /&gt;
|-&lt;br /&gt;
| [b] the operational incident-handling capability includes preparation. || Document || Incident Response SOP/Plan, prior incident report, training, COOP plan.&lt;br /&gt;
|-&lt;br /&gt;
| [c] the operational incident-handling capability includes detection. || Document || Incident Response SOP/Plan; definition of tools used to detect; artifacts showing tools used; prior incident report.&lt;br /&gt;
|-&lt;br /&gt;
| [d] the operational incident-handling capability includes analysis. || Document || Incident Response SOP/Plan; Definition of tools used to analyze potential incidents; artifacts showing tools used for analysis; prior incident report.&lt;br /&gt;
|-&lt;br /&gt;
| [e] the operational incident-handling capability includes containment. || Document || Incident Response SOP/Plan; isolation/quarantine process; user training.&lt;br /&gt;
|-&lt;br /&gt;
| [f] the operational incident-handling capability includes recovery. || Document || Incident Response SOP/Plan; COOP Plan; prior incident reports, re-baselining impacted devices.&lt;br /&gt;
|-&lt;br /&gt;
| [g] the operational incident-handling capability includes user response. || Document || Incident Response SOP/Plan; user awareness training; Help Desk process.&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IR.L2-3.6.2 – Incident Reporting ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IR.L2-3.6.2_Details|&#039;&#039;&#039;IR.L2-3.6.2&#039;&#039;&#039;]] Track, document, and report incidents to designated officials and/or authorities both internal and external to the organization.&lt;br /&gt;
|-&lt;br /&gt;
| [a] incidents are tracked. || Artifact || Incident Response SOP/Plan; ITSM artifact; technical implementation for incident tracking.&lt;br /&gt;
|-&lt;br /&gt;
| [b] incidents are documented. || Artifact || Incident Response SOP/Plan; ITSM artifact; technical implementation for incident tracking.&lt;br /&gt;
|-&lt;br /&gt;
| [c] authorities to whom incidents are to be reported are identified. || Document || Incident Response SOP/Plan.&lt;br /&gt;
|-&lt;br /&gt;
| [d] organizational officials to whom incidents are to be reported are identified. || Document || Incident Response SOP/Plan.&lt;br /&gt;
|-&lt;br /&gt;
| [e] identified authorities are notified of incidents. || Screen Share || Prior incident report; DIBNET login; prior email notifications.&lt;br /&gt;
|-&lt;br /&gt;
| [f] identified organizational officials are notified of incidents. || Artifact || Prior incident report; prior email notifications; tabletop exercises.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IR.L2-3.6.3 – Incident Response Testing ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IR.L2-3.6.3_Details|&#039;&#039;&#039;IR.L2-3.6.3&#039;&#039;&#039;]] Test the organizational incident response capability.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the incident response capability is tested. || Artifact || Incident response table top/scheduled or unscheduled test or penetration test.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Maintenance (MA) ==&lt;br /&gt;
=== MA.L2-3.7.1 – Perform Maintenance ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MA.L2-3.7.1_Details|&#039;&#039;&#039;MA.L2-3.7.1&#039;&#039;&#039;]] Perform maintenance on organizational systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] system maintenance is performed. || Artifact || Establish typical maintenance activities (HVAC, UPS, power distribution, generators, copier maintenance) that are performed; maintenance agreements or contracts detailing these types of activities are acceptable; interview responses should be considered.  This requirement should not be confused with 3.14.1 - report, remediate, and correct system flaws in a timely manner (patch management).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MA.L2-3.7.2 – System Maintenance Control ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MA.L2-3.7.2_Details|&#039;&#039;&#039;MA.L2-3.7.2&#039;&#039;&#039;]] Provide controls on the tools, techniques, mechanisms, and personnel used to conduct system maintenance.&lt;br /&gt;
|-&lt;br /&gt;
| [a] tools used to conduct system maintenance are controlled. || Artifact || Tools may largely depend on the assessed environment; discussion examples include network diagnostic and monitoring tools (including hardware and software); artifacts could demonstrate secured locations/areas for these tools (photos) or checkout sheets/rosters (documents) depicting responsible personnel and the dates/times of checkout.&lt;br /&gt;
|-&lt;br /&gt;
| [b] techniques used to conduct system maintenance are controlled. || Artifact || Processes for scheduling, performing, documenting, reviewing, approving, and monitoring maintenance and repairs for the information system.&lt;br /&gt;
|-&lt;br /&gt;
| [c] mechanisms used to conduct system maintenance are controlled. || Artifact || Processes for scheduling, performing, documenting, reviewing, approving, and monitoring maintenance and repairs for the information system.&lt;br /&gt;
|-&lt;br /&gt;
| [d] personnel used to conduct system maintenance are controlled. || Physical Review || Screenshot of who is authorized to conduct maintenance; maintenance personnel training program.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MA.L2-3.7.3 – Equipment Sanitization ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MA.L2-3.7.3_Details|&#039;&#039;&#039;MA.L2-3.7.3&#039;&#039;&#039;]] Ensure equipment removed for off-site maintenance is sanitized of any CUI.&lt;br /&gt;
|-&lt;br /&gt;
| [a] equipment to be removed from organizational spaces for off-site maintenance is sanitized of any CUI. || Artifact || Document or artifact; record if equipment sanitized; categories of sanitization/destruction defined; sanitization procedural document.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MA.L2-3.7.4 – Media Inspection ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MA.L2-3.7.4_Details|&#039;&#039;&#039;MA.L2-3.7.4&#039;&#039;&#039;]] Check media containing diagnostic and test programs for malicious code before the media are used in organizational systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] media containing diagnostic and test programs are checked for malicious code before being used in organizational systems that process, store, or transmit CUI. || Artifact || Screenshot of diagnostic/test program being used (such as Symantec and McAfee on access scans…).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MA.L2-3.7.5 – Nonlocal Maintenance ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MA.L2-3.7.5_Details|&#039;&#039;&#039;MA.L2-3.7.5&#039;&#039;&#039;]] Require multifactor authentication to establish nonlocal maintenance sessions via external network connections and terminate such connections when nonlocal maintenance is complete.&lt;br /&gt;
|-&lt;br /&gt;
| [a] multifactor authentication is used to establish nonlocal maintenance sessions via external network connections. || Screen Share || Describe MFA used to remote from external service to organizational systems for maintenance and screenshot of MFA (3.5.3)(points associated with admin).&lt;br /&gt;
|-&lt;br /&gt;
| [b] nonlocal maintenance sessions established via external network connections are terminated when nonlocal maintenance is complete. || Screen Share || Screenshot VPN session timeout.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MA.L2-3.7.6 – Maintenance Personnel ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MA.L2-3.7.6_Details|&#039;&#039;&#039;MA.L2-3.7.6&#039;&#039;&#039;]] Supervise the maintenance activities of maintenance personnel without required access authorization.&lt;br /&gt;
|-&lt;br /&gt;
| [a] maintenance personnel without required access authorization are supervised during maintenance activities. || Document || System maintenance policy; list of authorized personnel; maintenance records or, contracts/SLAs; WebEx.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Media Protection (MP) ==&lt;br /&gt;
=== MP.L2-3.8.1 – Media Protection ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MP.L2-3.8.1_Details|&#039;&#039;&#039;MP.L2-3.8.1&#039;&#039;&#039;]] Protect (i.e., physically control and securely store) system media containing CUI, both paper and digital.&lt;br /&gt;
|-&lt;br /&gt;
| [a] paper media containing CUI is physically controlled. || Document || Policy showing CUI paper media is controlled; artifact showing who has access; artifacts/records of  inventories conducted; media check out procedures (i.e. file cabinets, encryption, password protection).&lt;br /&gt;
|-&lt;br /&gt;
| [b] digital media containing CUI is physically controlled. || Document || Policy showing CUI digital media is controlled; artifact showing who has access; artifacts/records of inventories conducted; media check out procedures (i.e. file cabinets, external drives, USBs, encryption, password protection).&lt;br /&gt;
|-&lt;br /&gt;
| [c] paper media containing CUI is securely stored. || Physical Review || Check out/sign out sheets; possible photo of storage container/video walk through of storage area; badge reader logs or access lists for keys for secured areas; interview response considered (i.e. file cabinets,  encryption, password protection).&lt;br /&gt;
|-&lt;br /&gt;
| [d] digital media containing CUI is securely stored. || Physical Review || Check out/sign out sheets; possible photo of storage container/video walk through of storage area; badge reader logs or access lists for keys for secured areas; interview response considered (i.e. file cabinets, external drives, USBs, encryption, password protection).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MP.L2-3.8.2 – Media Access ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MP.L2-3.8.2_Details|&#039;&#039;&#039;MP.L2-3.8.2&#039;&#039;&#039;]] Limit access to CUI on system media to authorized users.&lt;br /&gt;
|-&lt;br /&gt;
| [a] access to CUI on system media is limited to authorized users. || Artifact || Document describing how CUI is limited AND artifact showing principle of least access is implemented.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MP.L2-3.8.3 – Media Disposal [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MP.L2-3.8.3_Details|&#039;&#039;&#039;MP.L2-3.8.3&#039;&#039;&#039;]] Sanitize or destroy information system media containing Federal Contract Information before disposal or release for reuse.&lt;br /&gt;
|-&lt;br /&gt;
| [a] system media containing CUI is sanitized or destroyed before disposal. || Document || Policy or artifact of media destruction logs; certificates of destruction; SLAs or contracts.&lt;br /&gt;
|-&lt;br /&gt;
| [b] system media containing CUI is sanitized before it is released for reuse. || Document || Policy or artifact describing method to sanitize, software used (i.e. DoD Wipe, ShredIT and Iron Mountain; Blancco; GDisk, DBAN).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MP.L2-3.8.4 – Media Markings ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MP.L2-3.8.4_Details|&#039;&#039;&#039;MP.L2-3.8.4&#039;&#039;&#039;]] Mark media with necessary CUI markings and distribution limitations.&lt;br /&gt;
|-&lt;br /&gt;
| [a] media containing CUI is marked with applicable CUI markings. || Physical Review || Document or artifact showing CUI markings (i.e. labeling standards ).&lt;br /&gt;
|-&lt;br /&gt;
| [b] media containing CUI is marked with distribution limitations. || Physical Review || Document or artifact showing distro limitations (i.e. labeling standards ).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MP.L2-3.8.5 – Media Accountability ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MP.L2-3.8.5_Details|&#039;&#039;&#039;MP.L2-3.8.5&#039;&#039;&#039;]] Control access to media containing CUI and maintain accountability for media during transport outside of controlled areas.&lt;br /&gt;
|-&lt;br /&gt;
| [a] access to media containing CUI is controlled. || Document || Policy, artifact of audit logs showing tracking, Access Control Lists, records of transport activities (i.e. USB drives, CDs, chain of custody.&lt;br /&gt;
|-&lt;br /&gt;
| [b] accountability for media containing CUI is maintained during transport outside of controlled areas. || Artifact || Artifact of audit logs showing tracking, Access Control Lists, records of transport activities (i.e. USB drives, CDs; chain of custody.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MP.L2-3.8.6 – Portable Storage Encryption ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MP.L2-3.8.6_Details|&#039;&#039;&#039;MP.L2-3.8.6&#039;&#039;&#039;]] Implement cryptographic mechanisms to protect the confidentiality of CUI stored on digital media during transport unless otherwise protected by alternative physical safeguards.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the confidentiality of CUI stored on digital media is protected during transport using cryptographic mechanisms or alternative physical safeguards. || Artifact || Artifact showing crypto mechanisms used to protect (are they FIPS 140-2 [13.11]); artifact showing what alternative physical safeguards are in place (i.e. encryption; BitLocker; McAfee ).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MP.L2-3.8.7 – Removable Media ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MP.L2-3.8.7_Details|&#039;&#039;&#039;MP.L2-3.8.7&#039;&#039;&#039;]] Control the use of removable media on system components.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the use of removable media on system components is controlled. || Artifact || Policy showing if removable media is allowed; writable removable media is restricted; tracking artifacts; what tools are used (i.e. Carbon Black, Crowd Strike, GPO, Zoho Desktop Central); procedure/process describing what happens if it is lost; what mechanisms are in place to control/restrict removable media (i.e. Active Directory Groups and Group Policy artifact showing restriction).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MP.L2-3.8.8 – Shared Media ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MP.L2-3.8.8_Details|&#039;&#039;&#039;MP.L2-3.8.8&#039;&#039;&#039;]] Prohibit the use of portable storage devices when such devices have no identifiable owner.ASSESSMENT OBJECTIVES&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [a] the use of portable storage devices is prohibited when such devices have no identifiable owner. || Artifact || Policy and/or artifact showing company stance on portable storage devices if there is no owner (are personal USB devices allowed or are they company-issued; artifact showing alerts if device is connected to network (i.e. external HDD, Carbon Black, Crowd Strike, GPO, Zoho Desktop Central.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MP.L2-3.8.9 – Protect Backups ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MP.L2-3.8.9_Details|&#039;&#039;&#039;MP.L2-3.8.9&#039;&#039;&#039;]] Protect the confidentiality of backup CUI at storage locations.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the confidentiality of backup CUI is protected at storage locations. || Artifact || Policy on system backups; artifact showing media labeling; artifact showing encyption (is it FIPS 140-2 [13.11]); Access Control List artifact (i.e. backup tapes, Tivoli Storage Manager).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Personnel Security (PS) ==&lt;br /&gt;
=== PS.L2-3.9.1 – Screen Individuals ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_PS.L2-3.9.1_Details|&#039;&#039;&#039;PS.L2-3.9.1&#039;&#039;&#039;]] Screen individuals prior to authorizing access to organizational systems containing CUI.&lt;br /&gt;
|-&lt;br /&gt;
| [a] individuals are screened prior to authorizing access to organizational systems containing CUI. || Artifact || Screenshot of records of screened personnel/background checks.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== PS.L2-3.9.2 – Personnel Actions ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_PS.L2-3.9.2_Details|&#039;&#039;&#039;PS.L2-3.9.2&#039;&#039;&#039;]] Ensure that organizational systems containing CUI are protected during and after personnel actions such as terminations and transfers.&lt;br /&gt;
|-&lt;br /&gt;
| [a] a policy and/or process for terminating system access and any credentials coincident with personnel actions is established. || Document || Personnel security policy/procedures/instruction; Access control policy/procedure/instruction.&lt;br /&gt;
|-&lt;br /&gt;
| [b] system access and credentials are terminated consistent with personnel actions such as termination or transfer. || Artifact || Screenshot of records of personnel transfer and termination actions.&lt;br /&gt;
|-&lt;br /&gt;
| [c] the system is protected during and after personnel transfer actions. || Artifact || Completed outprocessing checklist.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Physical Protection (PE) ==&lt;br /&gt;
=== PE.L2-3.10.1 – Limit Physical Access [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_PE.L2-3.10.1_Details|&#039;&#039;&#039;PE.L2-3.10.1&#039;&#039;&#039;]] Limit physical access to organizational information systems, equipment, and the respective operating environments to authorized individuals.&lt;br /&gt;
|-&lt;br /&gt;
| [a] authorized individuals allowed physical access are identified. || Artifact || Authorized personnel (names) access list.&lt;br /&gt;
|-&lt;br /&gt;
| [b] physical access to organizational systems is limited to authorized individuals. || Physical Review || Badge reader logs, audit logs, and/or card swipe test.&lt;br /&gt;
|-&lt;br /&gt;
| [c] physical access to equipment is limited to authorized individuals. || Physical Review || Badge reader logs, audit logs, and/or card swipe test.&lt;br /&gt;
|-&lt;br /&gt;
| [d] physical access to operating environments is limited to authorized. || Physical Review || Badge reader logs, audit logs, and/or card swipe test.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== PE.L2-3.10.2 – Monitor Facility ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_PE.L2-3.10.2_Details|&#039;&#039;&#039;PE.L2-3.10.2&#039;&#039;&#039;]] Protect and monitor the physical facility and support infrastructure for organizational systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the physical facility where organizational systems reside is protected. || Physical Review || Physical security measures and barriers into the physical facility (cameras/locks/gates/guards, etc.).&lt;br /&gt;
|-&lt;br /&gt;
| [b] the support infrastructure for organizational systems is protected. || Physical Review || Physical barriers to entries into computer spaces, server rooms, etc.&lt;br /&gt;
|-&lt;br /&gt;
| [c] the physical facility where organizational systems reside is monitored. || Physical Review || Audit logs/how the physical facility is being monitored (cameras/access system/guards, etc.).&lt;br /&gt;
|-&lt;br /&gt;
| [d] the support infrastructure for organizational systems is monitored. || Physical Review || Audit logs/how the physical facility is being monitored (cameras/access system/guards, etc.).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== PE.L2-3.10.3 – Escort Visitors [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_PE.L2-3.10.3_Details|&#039;&#039;&#039;PE.L2-3.10.3&#039;&#039;&#039;]] Escort visitors and monitor visitor activity.&lt;br /&gt;
|-&lt;br /&gt;
| [a] visitors are escorted. || Physical Review || Policy/procedures/instruction on methodology for handling non-authorized personnel (entry to exit).&lt;br /&gt;
|-&lt;br /&gt;
| [b] visitor activity is monitored. || Physical Review || Policy/procedures/instructio on methodology for handling non-authorized personnel (entry to exit).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== PE.L2-3.10.4 – Physical Access Logs [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_PE.L2-3.10.4_Details|&#039;&#039;&#039;PE.L2-3.10.4&#039;&#039;&#039;]] Maintain audit logs of physical access.&lt;br /&gt;
|-&lt;br /&gt;
| [a] audit logs of physical access are maintained. || Artifact || Log or report from badging system.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== PE.L2-3.10.5 – Manage Physical Access [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_PE.L2-3.10.5_Details|&#039;&#039;&#039;PE.L2-3.10.5&#039;&#039;&#039;]] Control and manage physical access devices.&lt;br /&gt;
|-&lt;br /&gt;
| [a] physical access devices are identified. || Document || Physical access control systems description, guard force contract/policy, key locks, logical systems specifications, etc.&lt;br /&gt;
|-&lt;br /&gt;
| [b] physical access devices are controlled. || Physical Review || Inventory records of physical access control devices (e.g. keys, locks, card readers, locks, etc.).&lt;br /&gt;
|-&lt;br /&gt;
| [c] physical access devices are managed. || Physical Review || List of security safeguards controlling access to the facility (e.g. cameras, monitoring by guards, isolation of IT systems equiment and or system components).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== PE.L2-3.10.6 – Alternative Work Sites ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_PE.L2-3.10.6_Details|&#039;&#039;&#039;PE.L2-3.10.6&#039;&#039;&#039;]] Enforce safeguarding measures for CUI at alternate work sites.&lt;br /&gt;
|-&lt;br /&gt;
| [a] safeguarding measures for CUI are defined for alternate work sites. || Document || Telework agreement, Acceptable Use Policy and SOP for alternate work locations; user security training validation which includes physical/logical/technical protections of system at alternate work sites.&lt;br /&gt;
|-&lt;br /&gt;
| [b] safeguarding measures for CUI are enforced for alternate work sites. || Artifact || Monitoring/audit log of user activity and logical/physical/technical mechanisms in place to preclude unauthorized activity (telework agreement , AUP?).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Risk Assessment (RA) ==&lt;br /&gt;
=== RA.L2-3.11.1 – Risk Assessments ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_RA.L2-3.11.1_Details|&#039;&#039;&#039;RA.L2-3.11.1&#039;&#039;&#039;]] Periodically assess the risk to organizational operations (including mission, functions, image, or reputation), organizational assets, and individuals, resulting from the operation of organizational systems and the associated processing, storage, or transmission of CUI.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the frequency to assess risk to organizational operations, organizational assets, and individuals is defined. || Document || Risk assessment policy.&lt;br /&gt;
|-&lt;br /&gt;
| [b] risk to organizational operations, organizational assets, and individuals resulting from the operation of an organizational system that processes, stores, or transmits CUI is assessed with the defined frequency. || Artifact || Copy of last risk assessment done within defined frequency.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== RA.L2-3.11.2 – Vulnerability Scan ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_RA.L2-3.11.2_Details|&#039;&#039;&#039;RA.L2-3.11.2&#039;&#039;&#039;]] Scan for vulnerabilities in organizational systems and applications periodically and when new vulnerabilities affecting those systems and applications are identified.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the frequency to scan for vulnerabilities in organizational systems and applications is defined. || Document || Policy/procedures/instruction addressing vulnerability scanning records.&lt;br /&gt;
|-&lt;br /&gt;
| [b] vulnerability scans are performed on organizational systems with the defined frequency. || Screen Share || System configuration settings of vulnerability scanning scheduling and vulnerability scan results of systems within defined frequency.&lt;br /&gt;
|-&lt;br /&gt;
| [c] vulnerability scans are performed on applications with the defined frequency. || Screen Share || System configuration settings of vulnerability scanning scheduling and vulnerability scan results of applications within defined frequency.&lt;br /&gt;
|-&lt;br /&gt;
| [d] vulnerability scans are performed on organizational systems when new vulnerabilities are identified. || Screen Share || View signatures in scanning tool/ad hoc scan performed as a result.&lt;br /&gt;
|-&lt;br /&gt;
| [e] vulnerability scans are performed on applications when new vulnerabilities are identified. || Screen Share || View signatures in scanning tool/ad hoc scan performed as a result.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== RA.L2-3.11.3 – Vulnerability Remediation ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_RA.L2-3.11.3_Details|&#039;&#039;&#039;RA.L2-3.11.3&#039;&#039;&#039;]] Remediate vulnerabilities in accordance with risk assessments.&lt;br /&gt;
|-&lt;br /&gt;
| [a] vulnerabilities are identified. || Artifact || Scan results showing vulnerabilities identified.&lt;br /&gt;
|-&lt;br /&gt;
| [b] vulnerabilities are remediated in accordance with risk assessments. || Artifact || Screenshot/document of scan results of remediated vulnerabilities in accordance to risk assessments.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Security Assessment (CA) ==&lt;br /&gt;
=== CA.L2-3.12.1 – Security Control Assessment ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_CA.L2-3.12.1_Details|&#039;&#039;&#039;CA.L2-3.12.1&#039;&#039;&#039;]] Periodically assess the security controls in organizational systems to determine if the controls are effective in their application.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the frequency of security control assessments is defined. || Document || SSP.&lt;br /&gt;
|-&lt;br /&gt;
| [b] security controls are assessed with the defined frequency to determine if the controls are effective in their application. || Artifact || Copy of last security control assessment done within defined frequency.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== CA.L2-3.12.2 – Operational Plan of Action ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_CA.L2-3.12.2_Details|&#039;&#039;&#039;CA.L2-3.12.2&#039;&#039;&#039;]] Develop and implement plans of action designed to correct deficiencies and reduce or eliminate vulnerabilities in organizational systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] deficiencies and vulnerabilities to be addressed by the plan of action are identified. || Artifact || Plan of Action (POA).&lt;br /&gt;
|-&lt;br /&gt;
| [b] a plan of action is developed to correct identified deficiencies and reduce or eliminate identified vulnerabilities. || Artifact || Plan of Action (POA).&lt;br /&gt;
|-&lt;br /&gt;
| [c] the plan of action is implemented to correct identified deficiencies and reduce or eliminate identified vulnerabilities. || Artifact || Plan of Action (POA)/previously completed POAs.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== CA.L2-3.12.3 – Security Control Monitoring ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_CA.L2-3.12.3_Details|&#039;&#039;&#039;CA.L2-3.12.3&#039;&#039;&#039;]] Monitor security controls on an ongoing basis to ensure the continued effectiveness of the controls.&lt;br /&gt;
|-&lt;br /&gt;
| [a] security controls are monitored on an ongoing basis to ensure the continued effectiveness of those controls. || Artifact || Collection of risk assessment results, internal or third-party audits/security assessments and/or continuous monitoring reports/alerts (SIEM tool, etc.).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== CA.L2-3.12.4 – System Security Plan ====&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_CA.L2-3.12.4_Details|&#039;&#039;&#039;CA.L2-3.12.4&#039;&#039;&#039;]] Develop, document, and periodically update system security plans that describe system boundaries, system environments of operation, how security requirements are implemented, and the relationships with or connections to other systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] a system security plan is developed. || Document || SSP.&lt;br /&gt;
|-&lt;br /&gt;
| [b] the system boundary is described and documented in the system security plan. || Document || SSP and any supporting documentation.&lt;br /&gt;
|-&lt;br /&gt;
| [c] the system environment of operation is described and documented in the system security plan. || Document || SSP and any supporting documentation.&lt;br /&gt;
|-&lt;br /&gt;
| [d] the security requirements identified and approved by the designated authority as non-applicable are identified. || Document || SSP and required adjudication from DoD CIO.&lt;br /&gt;
|-&lt;br /&gt;
| [e] the method of security requirement implementation is described and documented in the system security plan. || Document || SSP and any supporting documentation.&lt;br /&gt;
|-&lt;br /&gt;
| [f] the relationship with or connection to other systems is described and documented in the system security plan. || Document || SSP and any supporting documentation.&lt;br /&gt;
|-&lt;br /&gt;
| [g] the frequency to update the system security plan is defined. || Document || SSP.&lt;br /&gt;
|-&lt;br /&gt;
| [h] system security plan is updated with the defined frequency. || Document || SSP/any previous versions.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== System and Communications Protection (SC) ==&lt;br /&gt;
=== SC.L2-3.13.1 – Boundary Protection [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.1_Details|&#039;&#039;&#039;SC.L2-3.13.1&#039;&#039;&#039;]] Monitor, control, and protect organizational communications (i.e., information transmitted or received by organizational information systems) at the external boundaries and key internal boundaries of the information systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the external system boundary is defined. || Document || SSP, network diagrams, CUI flow, cloud provider FedRAMP Moderate.&lt;br /&gt;
|-&lt;br /&gt;
| [b] key internal system boundaries are defined. || Document || SSP, network diagrams, CUI flow.&lt;br /&gt;
|-&lt;br /&gt;
| [c] communications are monitored at the external system boundary. || Screen Share || SSP, logging server, boundary device configurations, monitoring policy.&lt;br /&gt;
|-&lt;br /&gt;
| [d] communications are monitored at key internal boundaries. || Screen Share || SSP, logging server, boundary device configurations, monitoring policy.&lt;br /&gt;
|-&lt;br /&gt;
| [e] communications are controlled at the external system boundary. || Screen Share || SSP, boundary device configurations, ACL, subnets, DMZ.&lt;br /&gt;
|-&lt;br /&gt;
| [f] communications are controlled at key internal boundaries. || Screen Share || SSP, boundary device configurations, ACL, subnets.&lt;br /&gt;
|-&lt;br /&gt;
| [g] communications are protected at the external system boundary. || Screen Share || Configurations for IPS/IDS, email gateway, VLAN, proxy, firewall, malware protection, DNS, TSL.&lt;br /&gt;
|-&lt;br /&gt;
| [h] communications are protected at key internal boundaries. || Screen Share || Configurations for IPS/IDS, VLAN, firewall, malware protection, SSL.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.2 – Security Engineering ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.2_Details|&#039;&#039;&#039;SC.L2-3.13.2&#039;&#039;&#039;]] Employ architectural designs, software development techniques, and systems engineering principles that promote effective information security within organizational systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] architectural designs that promote effective information security are identified. || Document || SSP, config management policy, network diagram, CCB minutes, enterprise architecture process.&lt;br /&gt;
|-&lt;br /&gt;
| [b] software development techniques that promote effective information security are identified. || Document || SSP, config management policy, SDLC, CCB minutes.&lt;br /&gt;
|-&lt;br /&gt;
| [c] systems engineering principles that promote effective information security are identified. || Document || SSP, config management policy, CCB minutes, security architecture engineering.&lt;br /&gt;
|-&lt;br /&gt;
| [d] identified architectural designs that promote effective information security are employed. || Artifact || CCB minutes, Network diagrams and configurations, Project Plans.&lt;br /&gt;
|-&lt;br /&gt;
| [e] identified software development techniques that promote effective information security are employed. || Artifact || CCB minutes, SDLC, code scanner results, code management tracking.&lt;br /&gt;
|-&lt;br /&gt;
| [f] identified systems engineering principles that promote effective information security are employed. || Artifact || CCB minutes, configuration management, ITSM, patch management, lifecycle replacement processes.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.3 – Role Separation ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.3_Details|&#039;&#039;&#039;SC.L2-3.13.3&#039;&#039;&#039;]] Separate user functionality from system management functionality.&lt;br /&gt;
|-&lt;br /&gt;
| [a] user functionality is identified. || Document || SSP, AUP.&lt;br /&gt;
|-&lt;br /&gt;
| [b] system management functionality is identified. || Document || SSP, Privileged Account Agreement.&lt;br /&gt;
|-&lt;br /&gt;
| [c] user functionality is separated from system management functionality. || Screen Share || Active Directory, Jump Boxes, GPO, VM, RDP.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.4 – Shared Resource Control ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.4_Details|&#039;&#039;&#039;SC.L2-3.13.4&#039;&#039;&#039;]] Prevent unauthorized and unintended information transfer via shared system resources.&lt;br /&gt;
|-&lt;br /&gt;
| [a] unauthorized and unintended information transfer via shared system resources is prevented. || Screen Share || SSP, OS configurations, Linux containers, system/media reuse policies, certificate management policies, media destruction policies, printer configs, VDI configuration.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
===  SC.L2-3.13.5 – Public-Access System Separation [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.5_Details|&#039;&#039;&#039;SC.L2-3.13.5&#039;&#039;&#039;]] Implement subnetworks for publicly accessible system components that are physically or logically separated from internal networks.&lt;br /&gt;
|-&lt;br /&gt;
| [a] publicly accessible system components are identified. || Document || SSP, network diagram, DMZ inventory/roles.&lt;br /&gt;
|-&lt;br /&gt;
| [b] subnetworks for publicly accessible system components are physically or logically separated from internal networks. || Artifact || Network diagram, IPAM, VLAN, DHCP, DMZ.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.6 – Network Communication by Exception ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.6_Details|&#039;&#039;&#039;SC.L2-3.13.6&#039;&#039;&#039;]] Deny network communications traffic by default and allow network communications traffic by exception (i.e., deny all, permit by exception).&lt;br /&gt;
|-&lt;br /&gt;
| [a] network communications traffic is denied by default. || Screen Share || Host and network firewall rules, SIEM logs, hit counts.&lt;br /&gt;
|-&lt;br /&gt;
| [b] network communications traffic is allowed by exception. || Screen Share || Host and network firewall rules, SIEM logs, hit counts.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.7 – Split Tunneling ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.7_Details|&#039;&#039;&#039;SC.L2-3.13.7&#039;&#039;&#039;]] Prevent remote devices from simultaneously establishing non-remote connections with organizational systems and communicating via some other connection to resources in external networks (i.e., split tunneling).&lt;br /&gt;
|-&lt;br /&gt;
| [a] remote devices are prevented from simultaneously establishing non-remote connections with the system and communicating via some other connection to resources in external networks (i.e., split tunneling). || Screen Share || VPN appliance/server configuration, endpoint VPN software configuration.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.8 – Data in Transit ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.8_Details|&#039;&#039;&#039;SC.L2-3.13.8&#039;&#039;&#039;]] Implement cryptographic mechanisms to prevent unauthorized disclosure of CUI during transmission unless otherwise protected by alternative physical safeguards.&lt;br /&gt;
|-&lt;br /&gt;
| [a] cryptographic mechanisms intended to prevent unauthorized disclosure of CUI are identified. || Document || SSP, PKI policies, configuration processes, config management, email attachment encryption policy, removable media policy, data at rest policy.&lt;br /&gt;
|-&lt;br /&gt;
| [b] alternative physical safeguards intended to prevent unauthorized disclosure of CUI are identified. || Document || SSP, physical security policy.&lt;br /&gt;
|-&lt;br /&gt;
| [c] either cryptographic mechanisms or alternative physical safeguards are implemented to prevent unauthorized disclosure of CUI during transmission. || Artifact || TLS settings, SSL settings, VPN/Wireless Access Points/Mobile Devices cryptographic settings, ODBC connector settings, SAN configuration, IPSec/MPLS, backup configuration, physical security.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.9 – Connections Termination ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.9_Details|&#039;&#039;&#039;SC.L2-3.13.9&#039;&#039;&#039;]] Terminate network connections associated with communications sessions at the end of the sessions or after a defined period of inactivity.&lt;br /&gt;
|-&lt;br /&gt;
| [a] a period of inactivity to terminate network connections associated with communications sessions is defined. || Document || SSP, network communications policy.&lt;br /&gt;
|-&lt;br /&gt;
| [b] network connections associated with communications sessions are terminated at the end of the sessions. || Screen Share || VPN appliance/server logs, VPN configurations, web server configurations, firewall connection settings.&lt;br /&gt;
|-&lt;br /&gt;
| [c] network connections associated with communications sessions are terminated after the defined period of inactivity. || Screen Share || VPN appliance/server logs, VPN configurations, web server configurations, frewall connection settings.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.10 – Key Management ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.10_Details|&#039;&#039;&#039;SC.L2-3.13.10&#039;&#039;&#039;]] Establish and manage cryptographic keys for cryptography employed in organizational systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] cryptographic keys are established whenever cryptography is employed. || Artifact || SSP, PKI/certificate management policy, configuration management.&lt;br /&gt;
|-&lt;br /&gt;
| [b] cryptographic keys are managed whenever cryptography is employed. || Artifact || SSP, PKI/certificate management policy, configuration management, access control policy.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.11 – CUI Encryption ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.11_Details|&#039;&#039;&#039;SC.L2-3.13.11&#039;&#039;&#039;]] Employ FIPS-validated cryptography when used to protect the confidentiality of CUI.&lt;br /&gt;
|-&lt;br /&gt;
| [a] FIPS-validated cryptography is employed to protect the confidentiality of CUI. || Screen Share || VPN, wireless, mobile devices, client certificates, server certificates, disk encryption, Outlook plugin, external mail, backup media, ePO server, removable storage, SAN, file compression; look for FIPS mode enabled on appliances.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.12 – Collaborative Device Control ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.12_Details|&#039;&#039;&#039;SC.L2-3.13.12&#039;&#039;&#039;]] Prohibit remote activation of collaborative computing devices and provide indication of devices in use to users present at the device.&lt;br /&gt;
|-&lt;br /&gt;
| [a] collaborative computing devices are identified. || Document || SSP, network diagrams.&lt;br /&gt;
|-&lt;br /&gt;
| [b] collaborative computing devices provide indication to users of devices in use. || Physical Review || Physical inspection of device.&lt;br /&gt;
|-&lt;br /&gt;
| [c] remote activation of collaborative computing devices is prohibited. || Artifact || Collaboration device configuration/console.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.13 – Mobile Code ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.13_Details|&#039;&#039;&#039;SC.L2-3.13.13&#039;&#039;&#039;]] Control and monitor the use of mobile code.&lt;br /&gt;
|-&lt;br /&gt;
| [a] use of mobile code is controlled. || Screen Share || GPO settings, malware protection, software agent configurations, software development policies, code scanners, MDM configuration, firewall/secure web gateway/proxy config.&lt;br /&gt;
|-&lt;br /&gt;
| [b] use of mobile code is monitored. || Screen Share || SIEM/console monitoring.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.14 – Voice over Internet Protocol ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.14_Details|&#039;&#039;&#039;SC.L2-3.13.14&#039;&#039;&#039;]] Control and monitor the use of Voice over Internet Protocol (VoIP) technologies.&lt;br /&gt;
|-&lt;br /&gt;
| [a] use of Voice over Internet Protocol (VoIP) technologies is controlled. || Artifact || VLAN, ACL, firewall config, VoIP gateway/condenser configuration.&lt;br /&gt;
|-&lt;br /&gt;
| [b] use of Voice over Internet Protocol (VoIP) technologies is monitored. || Artifact || SIEM/VoIP console monitoring, session border controller.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.15 – Communications Authenticity ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.15_Details|&#039;&#039;&#039;SC.L2-3.13.15&#039;&#039;&#039;]] Protect the authenticity of communications sessions.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the authenticity of communications sessions is protected. || Screen Share || SSL, TLS, SMB3, SFTP, IPSec, SSH, Kerberos configs, MPLS, Network Access Control.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.16 – Data at Rest ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.16_Details|&#039;&#039;&#039;SC.L2-3.13.16&#039;&#039;&#039;]] Protect the confidentiality of CUI at rest.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the confidentiality of CUI at rest is protected. || Artifact || Full disk encryption, removable media encryption, SAN encryption, digital backups, mobile device encryption, third party offsite backup storage, cloud virtualization encryption, physical media storage policies.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== System and Information Integrity (SI) ==&lt;br /&gt;
=== SI.L2-3.14.1 – Flaw Remediation [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SI.L2-3.14.1_Details|&#039;&#039;&#039;SI.L2-3.14.1&#039;&#039;&#039;]] Identify, report, and correct information and information system flaws in a timely manner.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the time within which to identify system flaws is specified. || Document || SSP, patch management policy.&lt;br /&gt;
|-&lt;br /&gt;
| [b] system flaws are identified within the specified time frame. || Screen Share || Vulnerability management scanner output and scan policy configuration.&lt;br /&gt;
|-&lt;br /&gt;
| [c] the time within which to report system flaws is specified. || Document || SSP, patch management policy.&lt;br /&gt;
|-&lt;br /&gt;
| [d] system flaws are reported within the specified time frame. || Screen Share || ITSM/trouble tickets, vulnerability management scanner output.&lt;br /&gt;
|-&lt;br /&gt;
| [e] the time within which to correct system flaws is specified. || Document || SSP, patch management policy.&lt;br /&gt;
|-&lt;br /&gt;
| [f] system flaws are corrected within the specified time frame. || Screen Share || Vulnerability management scanner output and scan policy configuration.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SI.L2-3.14.2 – Malicious Code ProTection [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SI.L2-3.14.2_Details|&#039;&#039;&#039;SI.L2-3.14.2&#039;&#039;&#039;]] Provide protection from malicious code at appropriate locations within organizational information systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] designated locations for malicious code protection are identified. || Document || SSP, system protection policy, network diagrams, security architecture documents.&lt;br /&gt;
|-&lt;br /&gt;
| [b] protection from malicious code at designated locations is provided. || Screen Share || Endpoint security settings, email/web proxy gateways, firewall, IPS sensor, MDM configuration, Network Access Control.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SI.L2-3.14.3 – Security Alerts &amp;amp; Advisories ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SI.L2-3.14.3_Details|&#039;&#039;&#039;SI.L2-3.14.3&#039;&#039;&#039;]] Monitor system security alerts and advisories and take action in response.&lt;br /&gt;
|-&lt;br /&gt;
| [a] response actions to system security alerts and advisories are identified. || Document || SSP, vulnerability management policy, Incident Response Plan.&lt;br /&gt;
|-&lt;br /&gt;
| [b] system security alerts and advisories are monitored. || Artifact || Threat intelligence subscriptions, email advisories.&lt;br /&gt;
|-&lt;br /&gt;
| [c] actions in response to system security alerts and advisories are taken. || Artifact || ITSM/trouble tickets, user notifications, updates to firewall/IPS, etc.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SI.L2-3.14.4 – Update Malicious Code Protection [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SI.L2-3.14.4_Details|&#039;&#039;&#039;SI.L2-3.14.4&#039;&#039;&#039;]] Update malicious code protection mechanisms when new releases are available.&lt;br /&gt;
|-&lt;br /&gt;
| [a] malicious code protection mechanisms are updated when new releases are available. || Screen Share || Antivirus console dashboard, firewall AV, Email gateway signatures,proxy, IPS updates.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SI.L2-3.14.5 – System &amp;amp; File Scanning [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SI.L2-3.14.5_Details|&#039;&#039;&#039;SI.L2-3.14.5&#039;&#039;&#039;]] Perform periodic scans of the information system and real-time scans of files from external sources as files are downloaded, opened, or executed.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the frequency for malicious code scans is defined. || Document || SSP, vulnerability management policy.&lt;br /&gt;
|-&lt;br /&gt;
| [b] malicious code scans are performed with the defined frequency. || Screen Share || Consoles for AV (endpoints, servers, and file shares), firewall, email gateway, proxy, IPS, MDM configurations.&lt;br /&gt;
|-&lt;br /&gt;
| [c] real-time malicious code scans of files from external sources as files are downloaded, opened, or executed are performed. || Screen Share || Consoles for AV (endpoints, servers, and file shares), firewall, email gateway, proxy, IPS, MDM configurations.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SI.L2-3.14.6 – Monitor Communications for Attacks ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SI.L2-3.14.6_Details|&#039;&#039;&#039;SI.L2-3.14.6&#039;&#039;&#039;]] Monitor organizational systems, including inbound and outbound communications traffic, to detect attacks and indicators of potential attacks.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the system is monitored to detect attacks and indicators of potential attacks. || Screen Share || Firewall, IPS, endpoint protection, SIEM alerts and reports.&lt;br /&gt;
|-&lt;br /&gt;
| [b] inbound communications traffic is monitored to detect attacks and indicators of potential attacks. || Screen Share || Firewall, IPS, endpoint protection, SIEM alerts and reports.&lt;br /&gt;
|-&lt;br /&gt;
| [c] outbound communications traffic is monitored to detect attacks and indicators of potential attacks. || Screen Share || Firewall, IPS, endpoint protection, SIEM alerts and reports.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SI.L2-3.14.7 – Identify Unauthorized Use ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SI.L2-3.14.7_Details|&#039;&#039;&#039;SI.L2-3.14.7&#039;&#039;&#039;]] Identify unauthorized use of organizational systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] authorized use of the system is defined. || Document || AUP, SSP.&lt;br /&gt;
|-&lt;br /&gt;
| [b] unauthorized use of the system is identified. || Artifact || SIEM logs, endpoint protection console, IPS, Firewall.&lt;br /&gt;
|}&lt;/div&gt;</summary>
		<author><name>David</name></author>
	</entry>
	<entry>
		<id>https://cmmcwiki.org/index.php?title=Evidence_Collection_Approach&amp;diff=1627</id>
		<title>Evidence Collection Approach</title>
		<link rel="alternate" type="text/html" href="https://cmmcwiki.org/index.php?title=Evidence_Collection_Approach&amp;diff=1627"/>
		<updated>2026-07-20T01:49:19Z</updated>

		<summary type="html">&lt;p&gt;David: /* SC.L2-3.13.9 – Connections Termination */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;CMMC assessments and certification require substantial evidence and documentation. The following tables outline general guidelines for collecting evidence to assess control requirements and objectives. While these guidelines provide a structured approach, they are not the only means of conducting an accurate assessment. Assessors should exercise professional judgment and may employ alternative methods appropriate to the specific organizational context and circumstances.&lt;br /&gt;
&lt;br /&gt;
Evidence collection approaches are defined as:&lt;br /&gt;
* &#039;&#039;&#039;Documentation&#039;&#039;&#039;: Tangible materials containing information over which an organization has authority, including all types of written records and their copies.&lt;br /&gt;
* &#039;&#039;&#039;Artifacts&#039;&#039;&#039;: Tangible, reviewable records directly resulting from a practice or process being performed by a system or by personnel executing their role within that practice, control, or process.&lt;br /&gt;
* &#039;&#039;&#039;Physical Review&#039;&#039;&#039;: Direct on-site observation and examination of evidence.&lt;br /&gt;
* &#039;&#039;&#039;Screen Share&#039;&#039;&#039;: Real-time remote observation of a user demonstrating a task or process via shared computer screen, sometimes called &amp;quot;over-the-shoulder&amp;quot; review.&lt;br /&gt;
&lt;br /&gt;
DISCLAIMER: Evidence requirements vary significantly across assessment types. &#039;&#039;&#039;The examples provided are illustrative only and should be tailored to meet the specific adequacy and sufficiency standards of your particular assessment context.&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
For inquiries and reporting errors on this wiki, please [mailto:support@cmmctoolkit.org contact us]. Thank you.&lt;br /&gt;
&lt;br /&gt;
== Access Control (AC) ==&lt;br /&gt;
=== AC.L2-3.1.1 – Authorized Access Control [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.1_Details|&#039;&#039;&#039;AC.L2-3.1.1&#039;&#039;&#039;]] Limit information system access to authorized users, processes acting on behalf of authorized users, or devices (including other information systems).&lt;br /&gt;
|-&lt;br /&gt;
| [a] authorized users are identified. || Document || Document defining account request, approval, provisioning.&lt;br /&gt;
|-&lt;br /&gt;
| [b] processes acting on behalf of authorized users are identified. || Document || Document defining account request, approval, provisioning.&lt;br /&gt;
|-&lt;br /&gt;
| [c] devices (and other systems) authorized to connect to the system are identified. || Document || Document defining account request, approval, provisioning.&lt;br /&gt;
|-&lt;br /&gt;
| [d] system access is limited to authorized users. || Screen Share || Screen share showing login requirements are enforced. Example of an unauthorized user denied (unauthorized username entered at login).&lt;br /&gt;
|-&lt;br /&gt;
| [e] system access is limited to processes acting on behalf of authorized users. || Screen Share || Screenshot showing that service accounts are assigned to authorized users only; no rogue accounts without an authorized user are active.&lt;br /&gt;
|-&lt;br /&gt;
| [f] system access is limited to authorized devices (including other systems). || Screen Share || Screen share showing that all devices running are authorized; no rogue devices on the network.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.2 – Transaction &amp;amp; Function Control [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.2_Details|&#039;&#039;&#039;AC.L2-3.1.2&#039;&#039;&#039;]] Limit information system access to the types of transactions and functions that authorized users are permitted to execute.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the types of transactions and functions that authorized users are permitted to execute are defined. || Document || SSP, AUP, or IAM document that defines what authorized users can execute.&lt;br /&gt;
|-&lt;br /&gt;
| [b] system access is limited to the defined types of transactions and functions for authorized users. || Screen Share || Screenshot of security roles in AD or IAM or other directory-based identity-related services tool that shows transactions are as defined in the SSP or IAM document; privileged and non-privileged accounts need to be defined and identified in the artifact; screenshot of a non-privileged user trying to execute a privileged function.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.3 – Control CUI Flow ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.3_Details|&#039;&#039;&#039;AC.L2-3.1.3&#039;&#039;&#039;]] Control the flow of CUI in accordance with approved authorizations.&lt;br /&gt;
|-&lt;br /&gt;
| [a] information flow control policies are defined. || Document || SSP or other document describing the control of CUI on the network.&lt;br /&gt;
|-&lt;br /&gt;
| [b] methods and enforcement mechanisms for controlling the flow of CUI are defined. || Document || Document that defines the networking devices that are on the CUI network and answers what measures are in place to control the flow. List of firewalls, border and internal layer 3 devices, IDS/IPS, DLP, that process CUI.&lt;br /&gt;
|-&lt;br /&gt;
| [c] designated sources and destinations (e.g., networks, individuals, and devices) for CUI within the system and between interconnected systems are identified. || Artifact || Network diagram, data flow diagram, external system connection diagrams, document describing the policies for CUI on the network; listing of VLANs and subnets where CUI is authorized; document must describe source and authorized destinations.&lt;br /&gt;
|-&lt;br /&gt;
| [d] authorizations for controlling the flow of CUI are defined. || Document || Document that defines how CUI is to be controlled, such as an InfoSec plan, and/or network management plan.&lt;br /&gt;
|-&lt;br /&gt;
| [e] approved authorizations for controlling the flow of CUI are enforced. || Screen Share || Screenshots of firewall rules, ACLs, etc.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.4 – Separation of Duties ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.4_Details|&#039;&#039;&#039;AC.L2-3.1.4&#039;&#039;&#039;]] Separate the duties of individuals to reduce the risk of malevolent activity without collusion.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the duties of individuals requiring separation are defined. || Document || Document, SSP, account management policy, defining separation of duties by person or role.&lt;br /&gt;
|-&lt;br /&gt;
| [b] responsibilities for duties that require separation are assigned to separate individuals. || Screen Share || Screenshot showing that separation of duties is enforced by showing admin accounts are assigned to different people based on role.&lt;br /&gt;
|-&lt;br /&gt;
| [c] access privileges that enable individuals to exercise the duties that require separation are granted to separate individuals. || Screen Share || Screen shot showing an example such as a security manager can not log into a network device and change ACLs, or network admins can not access security logs in the SIEM tool.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.5 – Least Privilege ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.5_Details|&#039;&#039;&#039;AC.L2-3.1.5&#039;&#039;&#039;]] Employ the principle of least privilege, including for specific security functions and privileged accounts.&lt;br /&gt;
|-&lt;br /&gt;
| [a] privileged accounts are identified. || Document || &amp;quot;SSP or policy (documentation) identify what is considered a privileged account.&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| [b] access to privileged accounts is authorized in accordance with the principle of least privilege. || Artifact || An artifact that identifies the least amount of permissions associated with different types of privileged accounts are approved.&lt;br /&gt;
|-&lt;br /&gt;
| [c] security functions are identified. || Document || &amp;quot;SSP or policy (documentation) identifies what is considered a security account.&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| [d] access to security functions is authorized in accordance with the principle of least privilege. || Artifact || Artifact(s) that identify the least amount of permissions associated with different types of security accounts are approved.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.6 – Non-Privileged Account Use ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.6_Details|&#039;&#039;&#039;AC.L2-3.1.6&#039;&#039;&#039;]] Use non-privileged accounts or roles when accessing nonsecurity functions.&lt;br /&gt;
|-&lt;br /&gt;
| [a] nonsecurity functions are identified. || Document || SSP or account management document, AUP, that defines non-security functions.&lt;br /&gt;
|-&lt;br /&gt;
| [b] users are required to use non-privileged accounts or roles when accessing nonsecurity functions. || Screen Share || Screenshot showing that a privileged user tried to use their admin account to access a non-security function, such as a browser or email (whatever is defined in their policy) and was blocked.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.7 – Privileged Functions ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.7_Details|&#039;&#039;&#039;AC.L2-3.1.7&#039;&#039;&#039;]] Prevent non-privileged users from executing privileged functions and capture the execution of such functions in audit logs.&lt;br /&gt;
|-&lt;br /&gt;
| [a] privileged functions are defined. || Document || SSP or policy (documentation) that defines privileged functions.&lt;br /&gt;
|-&lt;br /&gt;
| [b] non-privileged users are defined. || Document || SSP or policy (documentation) that defines non-privileged users.&lt;br /&gt;
|-&lt;br /&gt;
| [c] non-privileged users are prevented from executing privileged functions. || Screen Share || Screen share that shows that a non-privileged user is not allowed to complete a privileged function (installing software).&lt;br /&gt;
|-&lt;br /&gt;
| [d] the execution of privileged functions is captured in audit logs. || Screen Share || Screen share that shows logs being captured of the execution of privileged functions.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.8 – Unsuccessful Logon Attempts ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.8_Details|&#039;&#039;&#039;AC.L2-3.1.8&#039;&#039;&#039;]] Limit unsuccessful logon attempts.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the means of limiting unsuccessful logon attempts is defined. || Document || SSP or policy (documentation) showing unsuccessful logon attempts settings and or policy.&lt;br /&gt;
|-&lt;br /&gt;
| [b] the defined means of limiting unsuccessful logon attempts is implemented. || Artifact || Artifact showing GPO / Policy for limiting logon attempts.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.9 – Privacy &amp;amp; Security Notices ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.9_Details|&#039;&#039;&#039;AC.L2-3.1.9&#039;&#039;&#039;]] Provide privacy and security notices consistent with applicable CUI rules.&lt;br /&gt;
|-&lt;br /&gt;
| [a] privacy and security notices required by CUI-specified rules are identified, consistent, and associated with the specific CUI category. || Document || SSP or policy (documentation) showing CUI-specified rules are identified, consistent, and associated with the specific CUI category.&lt;br /&gt;
|-&lt;br /&gt;
| [b] privacy and security notices are displayed. || Artifact || Artifact that shows a consent banner or screen that a user sees as they log in to the system.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.10 – Session Lock ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.10_Details|&#039;&#039;&#039;AC.L2-3.1.10&#039;&#039;&#039;]] Use session lock with pattern-hiding displays to prevent access and viewing of data after a period of inactivity.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the period of inactivity after which the system initiates a session lock is defined. || Document || SSP or policy (documentation) that defines the period of inactivity and when a session lock is defined.&lt;br /&gt;
|-&lt;br /&gt;
| [b] access to the system and viewing of data is prevented by initiating a session lock after the defined period of inactivity. || Artifact || Artifact that shows the setting of session lock (GPO or system policy or similar solution addressing the controls supporting centralized management and configuration of operating systems, applications, and users&#039; settings for the working environment of user accounts and computer accounts).&lt;br /&gt;
|-&lt;br /&gt;
| [c] previously visible information is concealed via a pattern-hiding display after the defined period of inactivity. || Document || Screenshot of GPO setting and configuration settings, or similar solution addressing the controls supporting centralized management and configuration of operating systems, applications, and users&#039; settings for the working environment of user accounts and computer accounts.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.11 – Session Termination ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.11_Details|&#039;&#039;&#039;AC.L2-3.1.11&#039;&#039;&#039;]] Terminate (automatically) a user session after a defined condition.&lt;br /&gt;
|-&lt;br /&gt;
| [a] conditions requiring a user session to terminate are defined. || Document || SSP or policy (documentation) that defines the conditions requiring a user session to be terminated.&lt;br /&gt;
|-&lt;br /&gt;
| [b] a user session is automatically terminated after any of the defined conditions. || Screen Share || Screen share showing GPO / VPN Settings that show when a session would be terminated (Idle time, max connection time).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.12 – Control Remote Access ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.12_Details|&#039;&#039;&#039;AC.L2-3.1.12&#039;&#039;&#039;]] Monitor and control remote access sessions.&lt;br /&gt;
|-&lt;br /&gt;
| [a] remote access sessions are permitted. || Document || SSP or policy (documentation) that defines remote access sessions.&lt;br /&gt;
|-&lt;br /&gt;
| [b] the types of permitted remote access are identified. || Document || SSP or policy (documentation) that defines remote access is permitted.&lt;br /&gt;
|-&lt;br /&gt;
| [c] remote access sessions are controlled. || Screen Share || Screen share that shows how the remote access is controlled (access session, and or groups).&lt;br /&gt;
|-&lt;br /&gt;
| [d] remote access sessions are monitored. || Screen Share || Screen share that shows how remote sessions are monitored (logs).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.13 – Remote Access Confidentiality ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.13_Details|&#039;&#039;&#039;AC.L2-3.1.13&#039;&#039;&#039;]] Employ cryptographic mechanisms to protect the confidentiality of remote access sessions.&lt;br /&gt;
|-&lt;br /&gt;
| [a] cryptographic mechanisms to protect the confidentiality of remote access sessions are identified. || Document || SSP or policy (documentation) that discusses the CUI rules, consistent, and associated with the specific CUI category; FIPS Cert # of appliance or application.&lt;br /&gt;
|-&lt;br /&gt;
| [b] cryptographic mechanisms to protect the confidentiality of remote access sessions are implemented. || Screen Share || Screenshot of VPN concentration that shows encryption is on and enabled (point-to-point, etc.).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.14 – Remote Access Routing ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.14_Details|&#039;&#039;&#039;AC.L2-3.1.14&#039;&#039;&#039;]] Route remote access via managed access control points.&lt;br /&gt;
|-&lt;br /&gt;
| [a] managed access control points are identified and implemented. || Screen Share || Screen share that shows access control points (groups and/or users).&lt;br /&gt;
|-&lt;br /&gt;
| [b] remote access is routed through managed network access control points. || Screen Share || Screen share that shows access control points and how they are managed.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.15 – Privileged Remote Access ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.15_Details|&#039;&#039;&#039;AC.L2-3.1.15&#039;&#039;&#039;]] Authorize remote execution of privileged commands and remote access to security-relevant information.&lt;br /&gt;
|-&lt;br /&gt;
| [a] privileged commands authorized for remote execution are identified. || Document || SSP or policy (documentation) that defines what is authorized to be executed remotely and how that is handled.&lt;br /&gt;
|-&lt;br /&gt;
| [b] security-relevant information authorized to be accessed remotely is identified. || Document || SSP or policy (documentation) that defines what can be accessed remotely and what procedures are implemented to allow this (RDP, jump box).&lt;br /&gt;
|-&lt;br /&gt;
| [c] the execution of the identified privileged commands via remote access is authorized. || Artifact || Screen share that shows who has access to perform privileged commands a remotely (access groups for privileged accounts).&lt;br /&gt;
|-&lt;br /&gt;
| [d] access to the identified security-relevant information via remote access is authorized. || Artifact || Screen share that shows the routing of remote access and how it is monitored and how many locations (Firewall, VPN Concentrator).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.16 – Wireless Access Authorization ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.16_Details|&#039;&#039;&#039;AC.L2-3.1.16&#039;&#039;&#039;]] Authorize wireless access prior to allowing such connections.&lt;br /&gt;
|-&lt;br /&gt;
| [a] wireless access points are identified. || Document || SSP, network administration document.&lt;br /&gt;
|-&lt;br /&gt;
| [b] wireless access is authorized prior to allowing such connections. || Screen Share || Authorization profile(s) in Wireless Access Controller or Identity Manager (i.e. Cisco ISE).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.17 – Wireless Access Protection ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.17_Details|&#039;&#039;&#039;AC.L2-3.1.17&#039;&#039;&#039;]] Protect wireless access using authentication and encryption.&lt;br /&gt;
|-&lt;br /&gt;
| [a] wireless access to the system is protected using authentication. || Screen Share || Security page (or similar) of a Wireless Access Controller.&lt;br /&gt;
|-&lt;br /&gt;
| [b] wireless access to the system is protected using encryption. || Screen Share || Security page (or similar) of a Wireless Access Controller.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.18 – Mobile Device Connection ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.18_Details|&#039;&#039;&#039;AC.L2-3.1.18&#039;&#039;&#039;]] Control connection of mobile devices.&lt;br /&gt;
|-&lt;br /&gt;
| [a] mobile devices that process, store, or transmit CUI are identified. || Document || SSP, Mobile Device Policy.&lt;br /&gt;
|-&lt;br /&gt;
| [b] mobile device connections are authorized. || Artifact || Authorization profile(s) in Wireless Access Controller or Identity Manager (i.e. Cisco ISE).&lt;br /&gt;
|-&lt;br /&gt;
| [c] mobile device connections are monitored and logged. || Screen Share || Mobile device logs within the MDM, log intake (sources) configuration (within SIEM) showing MDM is feeding logs to the SIEM.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.19 – Encrypt CUI on Mobile ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.19_Details|&#039;&#039;&#039;AC.L2-3.1.19&#039;&#039;&#039;]] Encrypt CUI on mobile devices and mobile computing platforms.&lt;br /&gt;
|-&lt;br /&gt;
| [a] mobile devices and mobile computing platforms that process, store, or transmit CUI are identified. || Document || SSP, Mobile Device Policy.&lt;br /&gt;
|-&lt;br /&gt;
| [b] encryption is employed to protect CUI on identified mobile devices and mobile computing platforms. || Screen Share || Security policy page in MDM showing how encryption are enforced on mobile device. If no MDM or MDM doesn&#039;t enforce encryption, then validate if the devices used are on the list of devices with native FIPS approved validation.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.20 – External Connections [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.20_Details|&#039;&#039;&#039;AC.L2-3.1.20&#039;&#039;&#039;]] Verify and control/limit connections to and use of external information systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] connections to external systems are identified. || Document || SSP, Systems Interconnection Agreements, SLA.&lt;br /&gt;
|-&lt;br /&gt;
| [b] the use of external systems is identified. || Document || SSP, Systems Interconnection Agreements, SLA.&lt;br /&gt;
|-&lt;br /&gt;
| [c] connections to external systems are verified. || Artifact || SLA for external systems, memorandum for interconnection, information to prove that any cloud solution is at FedRAMP impact level of moderate or higher (i.e. license information, screenshot of AWS cloud dashboard, purchase order document).&lt;br /&gt;
|-&lt;br /&gt;
| [d] the use of external systems is verified. || Artifact || SLA for external systems, memorandum for interconnection, information to prove that any cloud solution is at FedRAMP impact level of moderate or higher (i.e. license information, screenshot of AWS cloud dashboard, purchase order document).&lt;br /&gt;
|-&lt;br /&gt;
| [e] connections to external systems are controlled/limited. || Screen Share || Firewall ruleset for controlling access to cloud service or external system.&lt;br /&gt;
|-&lt;br /&gt;
| [f] the use of external systems is controlled/limited. || Screen Share || Firewall ruleset for controlling access to cloud service or external system.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.21 – Portable Storage Use ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.21_Details|&#039;&#039;&#039;AC.L2-3.1.21&#039;&#039;&#039;]] Limit use of portable storage devices on external systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the use of portable storage devices containing CUI on external systems is identified and documented. || Document || SSP, Removable Media Policy, Acceptable Use Policy (with emphasis on portable media use).&lt;br /&gt;
|-&lt;br /&gt;
| [b] limits on the use of portable storage devices containing CUI on external systems are defined. || Document || SSP, Removable Media Policy, Acceptable Use Policy (with emphasis on portable media use).&lt;br /&gt;
|-&lt;br /&gt;
| [c] the use of portable storage devices containing CUI on external systems is limited as defined. || Document || SSP, Removable Media Policy, Acceptable Use Policy (with emphasis on portable media use).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.22 – Control Public Information [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.22_Details|&#039;&#039;&#039;AC.L2-3.1.22&#039;&#039;&#039;]] Control information posted or processed on publicly accessible information systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] individuals authorized to post or process information on publicly accessible systems are identified. || Document || SSP, Website Governance Plan, Information Release Document.&lt;br /&gt;
|-&lt;br /&gt;
| [b] procedures to ensure CUI is not posted or processed on publicly accessible systems are identified. || Document || SSP, Website Governance Plan, Information Release Document.&lt;br /&gt;
|-&lt;br /&gt;
| [c] a review process is in place prior to posting of any content to publicly accessible systems. || Artifact || &amp;quot;Information release approval process, i.e. chain of email communication from originator, approver, and final decision (may or may not include individual authorized to post); &lt;br /&gt;
SharePoint/electronic or paper form/ ticket system showing information flow between requestor and approver (may or may not include  individual authorized to post).&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| [d] content on publicly accessible systems is reviewed to ensure that it does not include CUI. || Artifact || Incident response process, web design/update/modification SOP etc.&lt;br /&gt;
|-&lt;br /&gt;
| [e] mechanisms are in place to remove and address improper posting of CUI. || Artifact || Incident response process, web design/update/modification SOP etc.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Awareness and Training (AT) ==&lt;br /&gt;
=== AT.L2-3.2.1 – Role-Based Risk Awareness ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AT.L2-3.2.1_Details|&#039;&#039;&#039;AT.L2-3.2.1&#039;&#039;&#039;]] Ensure that managers, systems administrators, and users of organizational systems are made aware of the security risks associated with their activities and of the applicable policies, standards, and procedures related to the security of those systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] security risks associated with organizational activities involving CUI are identified. || Document || Policy of Security Awareness Training; Security Awareness Training Briefing.&lt;br /&gt;
|-&lt;br /&gt;
| [b] policies, standards, and procedures related to the security of the system are identified. || Document || Acceptable Use Policy, Policy/Procedures/Instruction related to the security of the system.&lt;br /&gt;
|-&lt;br /&gt;
| [c] managers, systems administrators, and users of the system are made aware of the security risks associated with their activities. || Artifact || Security Training Brief, training records.&lt;br /&gt;
|-&lt;br /&gt;
| [d] managers, systems administrators, and users of the system are made aware of the applicable policies, standards, and procedures related to the security of the system. || Artifact || Policies, standards and procedures for employees within training (completed training report).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AT.L2-3.2.2 – Role-Based Training ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AT.L2-3.2.2_Details|&#039;&#039;&#039;AT.L2-3.2.2&#039;&#039;&#039;]] Ensure that personnel are trained to carry out their assigned information security-related duties and responsibilities.|-&lt;br /&gt;
|-&lt;br /&gt;
| [a] information security-related duties, roles, and responsibilities are defined. || Document || Policy/Procedures/Instruction, Job Role Matrix, Position Descriptions, User Roles.&lt;br /&gt;
|-&lt;br /&gt;
| [b] information security-related duties, roles, and responsibilities are assigned to designated personnel. || Artifact || Screenshot of breakout of different roles/permissions assigned to individuals (i.e. ActiveDirectory); Privilege Access Agreement.&lt;br /&gt;
|-&lt;br /&gt;
| [c] personnel are adequately trained to carry out their assigned information security-related duties, roles, and responsibilities. || Artifact || Screenshot of tool and/or training specifying security specific roles, duties and responsibilities; Screenshot of required certifications (i.e. Sec+, CISSP).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AT.L2-3.2.3 – Insider Threat Awareness ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AT.L2-3.2.3_Details|&#039;&#039;&#039;AT.L2-3.2.3&#039;&#039;&#039;]] Provide security awareness training on recognizing and reporting potential indicators of insider threat.&lt;br /&gt;
|-&lt;br /&gt;
| [a] potential indicators associated with insider threats are identified. || Document || Insidert Threat Policy/Procedures/Instruction; Insider Threat Training/Briefing.&lt;br /&gt;
|-&lt;br /&gt;
| [b] security awareness training on recognizing and reporting potential indicators of insider threat is provided to managers and employees. || Artifact || Screenshot of training records showing completion of Insider Threat training, emails showing completion of Insider Threat training, Screenshot of certificate showing completion with individual&#039;s name.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Audit and Accountability (AU) ==&lt;br /&gt;
=== AU.L2-3.3.1 – System Auditing ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AU.L2-3.3.1_Details|&#039;&#039;&#039;AU.L2-3.3.1&#039;&#039;&#039;]] Create and retain system audit logs and records to the extent needed to enable the monitoring, analysis, investigation, and reporting of unlawful or unauthorized system activity.&lt;br /&gt;
|-&lt;br /&gt;
| [a] audit logs needed (i.e., event types to be logged) to enable the monitoring, analysis, investigation, and reporting of unlawful or unauthorized system activity are specified. || Document || SSP, policy, or auditing and logging process that defines specific types of events to be logged.&lt;br /&gt;
|-&lt;br /&gt;
| [b] the content of audit records needed to support monitoring, analysis, investigation, and reporting of unlawful or unauthorized system activity is defined. || Document || SSP, policy, or auditing and logging process that defines specific content of audit records/files.&lt;br /&gt;
|-&lt;br /&gt;
| [c] audit records are created (generated). || Screen Share || Screen share of tool that shows logs are generated for all systems.&lt;br /&gt;
|-&lt;br /&gt;
| [d] audit records, once created, contain the defined content. || Screen Share || Screen share of tool that shows logs contain defined content as defined in SSP, policy, or procedures.&lt;br /&gt;
|-&lt;br /&gt;
| [e] retention requirements for audit records are defined. || Document || SSP, Polocy, or Auditing and logging process that describes how long records are kept.&lt;br /&gt;
|-&lt;br /&gt;
| [f] audit records are retained as defined. || Screen Share || Screen share of tool that shows records and audit content retained at a minimum as defined.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AU.L2-3.3.2 – User Accountability ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AU.L2-3.3.2_Details|&#039;&#039;&#039;AU.L2-3.3.2&#039;&#039;&#039;]] Ensure that the actions of individual system users can be uniquely traced to those users so they can be held accountable for their actions.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the content of the audit records needed to support the ability to uniquely trace users to their actions is defined. || Document || SSP, policy, or process that defines actions traced back to individuals.&lt;br /&gt;
|-&lt;br /&gt;
| [b] audit records, once created, contain the defined content. || Screen Share || Screen share of tool that shows audit records traced to specific users/roles.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AU.L2-3.3.3 – Event Review ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AU.L2-3.3.3_Details|&#039;&#039;&#039;AU.L2-3.3.3&#039;&#039;&#039;]] Review and update logged events.&lt;br /&gt;
|-&lt;br /&gt;
| [a] a process for determining when to review logged events is defined. || Document || SSP, policy, or documented process that shows frequency of when to review types of logged events.&lt;br /&gt;
|-&lt;br /&gt;
| [b] event types being logged are reviewed in accordance with the defined review process. || Artifact || Evidence through a documented method such as meeting minutes, CAB minutes, etc. of log sources and log events being logged at the defined frequency.&lt;br /&gt;
|-&lt;br /&gt;
| [c] event types being logged are updated based on the review. || Artifact || Evidence of implementation based on the results of the review of logged events/sources through a ticket, meeting minutes, or screen share of the tool that shows changes implemented (finetuning).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AU.L2-3.3.4 – Audit Failure Alerting ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AU.L2-3.3.4_Details|&#039;&#039;&#039;AU.L2-3.3.4&#039;&#039;&#039;]] Alert in the event of an audit logging process failure.&lt;br /&gt;
|-&lt;br /&gt;
| [a] personnel or roles to be alerted in the event of an audit logging process failure are identified. || Document || SSP, policy, or procedure that shows who needs to be notified in case of an audit failure.&lt;br /&gt;
|-&lt;br /&gt;
| [b] types of audit logging process failures for which alert will be generated are defined. || Document || SSP, policy, or procedure that shows what types of failure will generate notifications.&lt;br /&gt;
|-&lt;br /&gt;
| [c] identified personnel or roles are alerted in the event of an audit logging process failure. || Artifact || Artifact such as email or ticket that shows the identified personnel were alerted of any audit/logging process failure as defined.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AU.L2-3.3.5 – Audit Correlation ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AU.L2-3.3.5_Details|&#039;&#039;&#039;AU.L2-3.3.5&#039;&#039;&#039;]] Correlate audit record review, analysis, and reporting processes for investigation and response to indications of unlawful, unauthorized, suspicious, or unusual activity.&lt;br /&gt;
|-&lt;br /&gt;
| [a] audit record review, analysis, and reporting processes for investigation and response to indications of unlawful, unauthorized, suspicious, or unusual activity are defined. || Document || SSP, policy, or procedure covering audit logging, monitoring, and reporting.&lt;br /&gt;
|-&lt;br /&gt;
| [b] defined audit record review, analysis, and reporting processes are correlated. || Artifact || Artifact showing an audit event and the resultant corrective action or actions to the event; this can be a Help Desk ticket, meeting notes, or a change control board items showing the event and any corrective action taken.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AU.L2-3.3.6 – Reduction &amp;amp; Reporting ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AU.L2-3.3.6_Details|&#039;&#039;&#039;AU.L2-3.3.6&#039;&#039;&#039;]] Provide audit record reduction and report generation to support on-demand analysis and reporting.&lt;br /&gt;
|-&lt;br /&gt;
| [a] an audit record reduction capability that supports on-demand analysis is provided. || Screen Share || Screen share of the logging environment where an event can be selected and traced back to a specific device, or dashboard showing realtime event analysis.&lt;br /&gt;
|-&lt;br /&gt;
| [b] a report generation capability that supports on-demand reporting is provided. || Screen Share || Screen share showing the generation of an on demand report.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AU.L2-3.3.7 – Authoritative Time Source ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AU.L2-3.3.7_Details|&#039;&#039;&#039;AU.L2-3.3.7&#039;&#039;&#039;]] Provide a system capability that compares and synchronizes internal system clocks with an authoritative source to generate time stamps for audit records.&lt;br /&gt;
|-&lt;br /&gt;
| [a] internal system clocks are used to generate time stamps for audit records. || Screen Share || Screen share showing the NTP settings of a windows, Unix, Linux device; a screen share showing the NTP settings of network appliances.&lt;br /&gt;
|-&lt;br /&gt;
| [b] an authoritative source with which to compare and synchronize internal system clocks is specified. || Document || SSP or policy indicating that devices need to be synched to a local authoritative time device that is synched with an authoritative time service.&lt;br /&gt;
|-&lt;br /&gt;
| [c] internal system clocks used to generate time stamps for audit records are compared to and synchronized with the specified authoritative time source. || Screen Share || Screen share showing device logging appliance time is point to the appropriate authoritative time server.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AU.L2-3.3.8 – Audit Protection ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AU.L2-3.3.8_Details|&#039;&#039;&#039;AU.L2-3.3.8&#039;&#039;&#039;]] Protect audit information and audit logging tools from unauthorized access, modification, and deletion.&lt;br /&gt;
|-&lt;br /&gt;
| [a] audit information is protected from unauthorized access. || Screen Share || Screen share showing operating system permissions on the audit folders being restricted to appropriate users.&lt;br /&gt;
|-&lt;br /&gt;
| [b] audit information is protected from unauthorized modification. || Screen Share || Screen share showing operating system permissions on the audit folders being restricted to appropriate users.&lt;br /&gt;
|-&lt;br /&gt;
| [c] audit information is protected from unauthorized deletion. || Screen Share || Screen share showing operating system permissions on the audit folders being restricted to appropriate users.&lt;br /&gt;
|-&lt;br /&gt;
| [d] audit logging tools are protected from unauthorized access. || Screen Share || Artifact showing access permissions in the SIEM tool.&lt;br /&gt;
|-&lt;br /&gt;
| [e] audit logging tools are protected from unauthorized modification. || Screen Share || Artifact showing update permissions in the SIEM tool.&lt;br /&gt;
|-&lt;br /&gt;
| [f] audit logging tools are protected from unauthorized deletion. || Screen Share || Artifact showing delete permissions in the SIEM tool.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AU.L2-3.3.9 – Audit Management ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AU.L2-3.3.9_Details|&#039;&#039;&#039;AU.L2-3.3.9&#039;&#039;&#039;]] Limit management of audit logging functionality to a subset of privileged users.&lt;br /&gt;
|-&lt;br /&gt;
| [a] a subset of privileged users granted access to manage audit logging functionality is defined. || Document || SSP or policy indicating which users or groups have access to audit logs.&lt;br /&gt;
|-&lt;br /&gt;
| [b] management of audit logging functionality is limited to the defined subset of privileged users. || Screen Share || Artifact showing SIEM or OS folder permissions (this should be limited to the assigned users or groups); artifact showing an ACL setting in SIEM tool in regards to logs.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Configuration Management (CM) ==&lt;br /&gt;
=== CM.L2-3.4.1 – System Baselining ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_CM.L2-3.4.1_Details|&#039;&#039;&#039;CM.L2-3.4.1&#039;&#039;&#039;]] Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles.&lt;br /&gt;
|-&lt;br /&gt;
| [a] a baseline configuration is established. || Document || Documentation showing or explaining standard imaging process (how standard images are deployed and where  they are stored).&lt;br /&gt;
|-&lt;br /&gt;
| [b] the baseline configuration includes hardware, software, firmware, and documentation. || Artifact || Screenshot of repository of where images are maintained and information relating to hardware, software, and firmware.&lt;br /&gt;
|-&lt;br /&gt;
| [c] the baseline configuration is maintained (reviewed and updated) throughout the system development life cycle. || Artifact || Screenshot/evidence displaying management of baseline configurations (how often they are being managed as stated).&lt;br /&gt;
|-&lt;br /&gt;
| [d] a system inventory is established. || Document || Screenshot/evidence displaying inventory listing of approved products for use.&lt;br /&gt;
|-&lt;br /&gt;
| [e] the system inventory includes hardware, software, firmware, and documentation. || Artifact || Screeenshot/evidence displaying inventory listing of approved products and versions permitted for use.&lt;br /&gt;
|-&lt;br /&gt;
| [f] the inventory is maintained (reviewed and updated) throughout the system development life cycle. || Artifact || Screeenshot/evidence displaying management of baseline configurations (How often and are they being managed as stated.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== CM.L2-3.4.2 – Security Configuration Enforcement ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_CM.L2-3.4.2_Details|&#039;&#039;&#039;CM.L2-3.4.2&#039;&#039;&#039;]] Establish and enforce security configuration settings for information technology products employed in organizational systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] security configuration settings for information technology products employed in the system are established and included in the baseline configuration. || Document || Documentation explaining methodology used by organization to create secure baselines (STIGs, benchmarks).&lt;br /&gt;
|-&lt;br /&gt;
| [b] security configuration settings for information technology products employed in the system are enforced. || Artifact || Evidence of tool/s used to enforce security configurations to ensure images used are free from modification unless authorized.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== CM.L2-3.4.3 – System Change Management ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_CM.L2-3.4.3_Details|&#039;&#039;&#039;CM.L2-3.4.3&#039;&#039;&#039;]] Track, review, approve or disapprove, and log changes to organizational systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] changes to the system are tracked. || Artifact || Evidence of IT Service Management tool / process used to track system changes.&lt;br /&gt;
|-&lt;br /&gt;
| [b] changes to the system are reviewed. || Artifact || Evidence of IT Service Management tool / process used to review system changes.&lt;br /&gt;
|-&lt;br /&gt;
| [c] changes to the system are approved or disapproved. || Artifact || Evidence of IT Service Management tool / process used to approve/disapprove system changes.&lt;br /&gt;
|-&lt;br /&gt;
| [d] changes to the system are logged. || Artifact || Evidence of IT Service Management tool / process used to log system changes.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== CM.L2-3.4.4 – Security Impact Analysis ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_CM.L2-3.4.4_Details|&#039;&#039;&#039;CM.L2-3.4.4&#039;&#039;&#039;]] Analyze the security impact of changes prior to implementation.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the security impact of changes to the system is analyzed prior to implementation. || Artifact || Document explaining that security impact analysis of proposed changes to a system is conducted prior to implementation.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== CM.L2-3.4.5 – Access Restrictions for Change ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_CM.L2-3.4.5_Details|&#039;&#039;&#039;CM.L2-3.4.5&#039;&#039;&#039;]] Define, document, approve, and enforce physical and logical access restrictions associated with changes to organizational systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] physical access restrictions associated with changes to the system are defined. || Document || Document explaining the process of how physical access restrictions are defined for an individuals ability to make system changes.&lt;br /&gt;
|-&lt;br /&gt;
| [b] physical access restrictions associated with changes to the system are documented. || Document || Document explaining the process of how physical access restrictions are defined for an individuals ability to make system changes are documented; access request process.&lt;br /&gt;
|-&lt;br /&gt;
| [c] physical access restrictions associated with changes to the system are approved. || Artifact || Evidence of process of how physical access to systems are granted (i.e. physical access request sample).&lt;br /&gt;
|-&lt;br /&gt;
| [d] physical access restrictions associated with changes to the system are enforced. || Physical Review || Evidence of process of how physical access to systems are enforced (physical access system).&lt;br /&gt;
|-&lt;br /&gt;
| [e] logical access restrictions associated with changes to the system are defined. || Document || Document explaining the process of how logical access restrictions are defined for an individual&#039;s ability to make system changes.&lt;br /&gt;
|-&lt;br /&gt;
| [f] logical access restrictions associated with changes to the system are documented. || Document || Document explaining the process of how logical access restrictions are defined for an individual&#039;s ability to make system changes are documented.&lt;br /&gt;
|-&lt;br /&gt;
| [g] logical access restrictions associated with changes to the system are approved. || Artifact || Evidence of process of how logical access to systems are granted.&lt;br /&gt;
|-&lt;br /&gt;
| [h] logical access restrictions associated with changes to the system are enforced. || Artifact || Evidence of process of how logical access to systems are enforced.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== CM.L2-3.4.6 – Least Functionality ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_CM.L2-3.4.6_Details|&#039;&#039;&#039;CM.L2-3.4.6&#039;&#039;&#039;]] Employ the principle of least functionality by configuring organizational systems to provide only essential capabilities.&lt;br /&gt;
|-&lt;br /&gt;
| [a] essential system capabilities are defined based on the principle of least functionality. || Document || Documentation explaining how systems are configured to utilize the principle of least functionality for designated users.&lt;br /&gt;
|-&lt;br /&gt;
| [b] the system is configured to provide only the defined essential capabilities. || Screen Share || Evidence displaying how systems are configured to utilize the principle of least functionality for designated users; disabled service settings, accepted standards for hardening (CIS benchmarks, etc.).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== CM.L2-3.4.7 – Nonessential Functionality ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_CM.L2-3.4.7_Details|&#039;&#039;&#039;CM.L2-3.4.7&#039;&#039;&#039;]] Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services.&lt;br /&gt;
|-&lt;br /&gt;
| [a] essential programs are defined. || Document || Documented essential programs specified; build documents; software center; SSP.&lt;br /&gt;
|-&lt;br /&gt;
| [b] the use of nonessential programs is defined. || Document || Documented listing of nonessential programs (whatever is NOT specified in [a]); AUP/User Agreement may identify nonessential use/programs.&lt;br /&gt;
|-&lt;br /&gt;
| [c] the use of nonessential programs is restricted, disabled, or prevented as defined. || Screen Share || Tool used to restrict nonessential programs displays restrictions as defined (McAfee ePO settings, Carbon Black rules, etc.).&lt;br /&gt;
|-&lt;br /&gt;
| [d] essential functions are defined. || Document || Documented essential functions are specified.&lt;br /&gt;
|-&lt;br /&gt;
| [e] the use of nonessential functions is defined. || Document || Documented nonessential functions are specified.&lt;br /&gt;
|-&lt;br /&gt;
| [f] the use of nonessential functions is restricted, disabled, or prevented as defined. || Screen Share || Tool used to restrict essential/nonessential functions displays restrictions as defined.&lt;br /&gt;
|-&lt;br /&gt;
| [g] essential ports are defined. || Document || Documented essential ports are specified.&lt;br /&gt;
|-&lt;br /&gt;
| [h] the use of nonessential ports is defined. || Document || Documented nonessential ports functions are specified.&lt;br /&gt;
|-&lt;br /&gt;
| [i] the use of nonessential ports is restricted, disabled, or prevented as defined. || Screen Share || Tool used to restrict essential/nonessential ports displays restrictions as defined (FW rules; McAfee; GPO, etc.).&lt;br /&gt;
|-&lt;br /&gt;
| [j] essential protocols are defined. || Document || Documented essential protocols are specified.&lt;br /&gt;
|-&lt;br /&gt;
| [k] the use of nonessential protocols is defined. || Document || Documented nonessential protocols functions are specified.&lt;br /&gt;
|-&lt;br /&gt;
| [l] the use of nonessential protocols is restricted, disabled, or prevented as defined. || Screen Share || Tool used to restrict essential/nonessential protocols displays restrictions as defined (FW rules; GPO, etc.).&lt;br /&gt;
|-&lt;br /&gt;
| [m] essential services are defined. || Document || Documented essential services specified.&lt;br /&gt;
|-&lt;br /&gt;
| [n] the use of nonessential services is defined. || Document || Documented nonessential services functions are specified.&lt;br /&gt;
|-&lt;br /&gt;
| [o] the use of nonessential services is restricted, disabled, or prevented as defined. || Screen Share || Tool used to restrict essential/nonessential services displays restrictions as defined.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== CM.L2-3.4.8 – Application Execution Policy ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_CM.L2-3.4.8_Details|&#039;&#039;&#039;CM.L2-3.4.8&#039;&#039;&#039;]] Apply deny-by-exception (blacklisting) policy to prevent the use of unauthorized software or deny-all, permit-by-exception (whitelisting) policy to allow the execution of authorized software.&lt;br /&gt;
|-&lt;br /&gt;
| [a] a policy specifying whether whitelisting or blacklisting is to be implemented is specified. || Document || Documentation explaining whitelisting or blacklisting process.&lt;br /&gt;
|-&lt;br /&gt;
| [b] the software allowed to execute under whitelisting or denied use under blacklisting is specified. || Document || Documentation explaining whitelisting or blacklisting process for software.&lt;br /&gt;
|-&lt;br /&gt;
| [c] whitelisting to allow the execution of authorized software or blacklisting to prevent the use of unauthorized software is implemented as specified. || Screen Share || Tool used for whitelisting or blacklisting for software shows capability of restricting/authorizing software (Carbon Black dashboard, &amp;quot;SW Store&amp;quot;, web proxies, DNS Blackhole, etc.).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== CM.L2-3.4.9 – User-Installed Software ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_CM.L2-3.4.9_Details|&#039;&#039;&#039;CM.L2-3.4.9&#039;&#039;&#039;]] Control and monitor user-installed software.&lt;br /&gt;
|-&lt;br /&gt;
| [a] a policy for controlling the installation of software by users is established. || Document || Documented software authorization process or methodology for approval.&lt;br /&gt;
|-&lt;br /&gt;
| [b] installation of software by users is controlled based on the established policy. || Screen Share || Evidence that approval/restriction in installation of software by authorized personnel is implemented as specified (AUP, GPO, etc.).&lt;br /&gt;
|-&lt;br /&gt;
| [c] installation of software by users is monitored. || Screen Share || Evidence that installation of software by authorized personnel is monitored (SCCM groups, SW Center, etc.).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Identification and Authentication (IA) ==&lt;br /&gt;
=== IA.L2-3.5.1 – Identification [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IA.L2-3.5.1_Details|&#039;&#039;&#039;IA.L2-3.5.1&#039;&#039;&#039;]] Identify information system users, processes acting on behalf of users, or devices.&lt;br /&gt;
|-&lt;br /&gt;
| [a] system users are identified. || Document || Based on what is defined in their documentation (SSP, AUP, Policy, SOP), request to see a sample of non-privileged/privileged users in AD OU group (overlaps with 3.1.1 and 3.1.5).&lt;br /&gt;
|-&lt;br /&gt;
| [b] processes acting on behalf of users are identified. || Document || Based on what is defined in their documentation (SSP, AUP, Policy, SOP), request to see a sample of service accounts in AD OU group (overlaps with 3.1.1 and 3.1.5).&lt;br /&gt;
|-&lt;br /&gt;
| [c] devices accessing the system are identified. || Document || Based on what is defined in their documentation (SSP, AUP, Policy, SOP), request to see a sample of domain-joined workstation &amp;amp; servers in AD OU group (overlaps with 3.1.1 and 3.1.5).  For network devices, request screen share/artifact to show how they are identified on the enterprise network.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IA.L2-3.5.2 – Authentication [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IA.L2-3.5.2_Details|&#039;&#039;&#039;IA.L2-3.5.2&#039;&#039;&#039;]] Authenticate (or verify) the identities of those users, processes, or devices, as a prerequisite to allowing access to organizational information systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the identity of each user is authenticated or verified as a prerequisite to system access. || Screen Share || If the user logs in with non-privileged account during other demoes and then a privileged account, then this should be satisfied.  If screen share is unavailable, request logs to show successful and unsuccessful login by privileged and non-privilged users.&lt;br /&gt;
|-&lt;br /&gt;
| [b] the identity of each process acting on behalf of a user is authenticated or verified as a prerequisite to system access. || Screen Share || Request a log that shows successful/unsuccessful service account trying to log on to company&#039;s asset.&lt;br /&gt;
|-&lt;br /&gt;
| [c] the identity of each device accessing or connecting to the system is authenticated or verified as a prerequisite to system access. || Screen Share || Request a log that shows domain-joined workstation/server authenticating to AD (focus on the MAC/IP address/hostname).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IA.L2-3.5.3 – Multifactor Authentication ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IA.L2-3.5.3_Details|&#039;&#039;&#039;IA.L2-3.5.3&#039;&#039;&#039;]] Use multifactor authentication for local and network access to privileged accounts and for network access to non-privileged accounts.&lt;br /&gt;
|-&lt;br /&gt;
| [a] privileged accounts are identified. || Document || Based on what is defined in their documentation, request to see a sample of privileged users in AD OU group.  Overlaps with 3.1.5.  Screenshot/screen share to show implementation is enforced.&lt;br /&gt;
|-&lt;br /&gt;
| [b] multifactor authentication is implemented for local access to privileged accounts. || Screen Share || SSP, AUP, Policy, SOP that defines that MFA is needed for privileged local access.&lt;br /&gt;
|-&lt;br /&gt;
| [c] multifactor authentication is implemented for network access to privileged accounts. || Screen Share || Within the MFA implementation mechanism, show that privileged users are forced to use MFA;  Screenshot/Screen share to show implementation is enforced.&lt;br /&gt;
|-&lt;br /&gt;
| [d] multifactor authentication is implemented for network access to non-privileged accounts. || Screen Share || Within the MFA implementation mechanism, show that non-privileged users are forced to use MFA; Screenshot/Screen share to show implementation is enforced.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IA.L2-3.5.4 – Replay-Resistant Authentication ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IA.L2-3.5.4_Details|&#039;&#039;&#039;IA.L2-3.5.4&#039;&#039;&#039;]] Employ replay-resistant authentication mechanisms for network access to privileged and non-privileged accounts.&lt;br /&gt;
|-&lt;br /&gt;
| [a] replay-resistant authentication mechanisms are implemented for network account access to privileged and non-privileged accounts. || Screen Share || Show the GPO setting that enforces Kerberos within AD.  If MFA is used, show the implementation to enforce replay resistant techniques.  For non-windows, show the technical solution to enforce replay resistant attacks.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IA.L2-3.5.5 – Identifier Reuse ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IA.L2-3.5.5_Details|&#039;&#039;&#039;IA.L2-3.5.5&#039;&#039;&#039;]] Prevent reuse of identifiers for a defined period.&lt;br /&gt;
|-&lt;br /&gt;
| [a] a period within which identifiers cannot be reused is defined. || Document || SSP, policies, or SOP that defines identifier reuse.&lt;br /&gt;
|-&lt;br /&gt;
| [b] reuse of identifiers is prevented within the defined period. || Artifact || Show the GPO setting/technical solution that enforces what is defined in policy/documentation (this can be automated or manual process; screen share/artifacts can be presented to satisfy this requirement.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IA.L2-3.5.6 – Identifier Handling ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IA.L2-3.5.6_Details|&#039;&#039;&#039;IA.L2-3.5.6&#039;&#039;&#039;]] Disable identifiers after a defined period of inactivity.&lt;br /&gt;
|-&lt;br /&gt;
| [a] a period of inactivity after which an identifier is disabled is defined. || Document || SSP, policy that defines the period of inactivity after which an identifier is disabled.&lt;br /&gt;
|-&lt;br /&gt;
| [b] identifiers are disabled after the defined period of inactivity. || Artifact || Screen share AD or similar tool supporting directory-based identity-related services for disabled accounts (can be done by hand or script).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IA.L2-3.5.7 – Password Complexity ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IA.L2-3.5.7_Details|&#039;&#039;&#039;IA.L2-3.5.7&#039;&#039;&#039;]] Enforce a minimum password complexity and change of characters when new passwords are created.&lt;br /&gt;
|-&lt;br /&gt;
| [a] password complexity requirements are defined. || Document || SSP, policy that defines password complexity requirements.&lt;br /&gt;
|-&lt;br /&gt;
| [b] password change of character requirements are defined. || Document || SSP, policy that defines change of character requirements are defined.&lt;br /&gt;
|-&lt;br /&gt;
| [c] minimum password complexity requirements as defined are enforced when new passwords are created. || Screen Share || Screen share of AD or similar directory-based identity-related service tool to show complexity requirements.&lt;br /&gt;
|-&lt;br /&gt;
| [d] minimum password change of character requirements as defined are enforced when new passwords are created. || Screen Share || Screen share of Group Policy configuration or similar tool providing centralized management and configuration of operating systems, applications, and users&#039; settings to show that characters must be changed.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IA.L2-3.5.8 – Password Reuse ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IA.L2-3.5.8_Details|&#039;&#039;&#039;IA.L2-3.5.8&#039;&#039;&#039;]] Prohibit password reuse for a specified number of generations.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the number of generations during which a password cannot be reused is specified. || Document || SSP, policy that specifies the number of generations during which a password cannot be reused is specified.&lt;br /&gt;
|-&lt;br /&gt;
| [b] reuse of passwords is prohibited during the specified number of generations. || Screen Share || Screen share Group Policy or similar tool providing centralized management and configuration of operating systems, applications, and users&#039; settings in a directory-based identity-related service tool&#039;s configuration to show reuse of passwords is prohibited.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IA.L2-3.5.9 – Temporary Passwords ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IA.L2-3.5.9_Details|&#039;&#039;&#039;IA.L2-3.5.9&#039;&#039;&#039;]] Allow temporary password use for system logons with an immediate change to a permanent password.&lt;br /&gt;
|-&lt;br /&gt;
| [a] an immediate change to a permanent password is required when a temporary password is used for system logon. || Screen Share || Screen share of Group Policy or similar tool providing centralized management and configuration of operating systems, applications, and users&#039; settings in a directory-based identity-related service tool&#039;s configuration to show &amp;quot;change password at first logon.&amp;quot;&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IA.L2-3.5.10 – Cryptographically-Protected Passwords ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IA.L2-3.5.1_Details|&#039;&#039;&#039;IA.L2-3.5.1&#039;&#039;&#039;]] Store and transmit only cryptographically-protected passwords.&lt;br /&gt;
|-&lt;br /&gt;
| [a] passwords are cryptographically protected in storage. || Screen Share || Screen share Group Policy or similar tool providing centralized management and configuration of operating systems, applications, and users&#039; settings in a directory-based identity-related service tool&#039;s configuration that Kerberos, or a similar network authentication protocol that works on the basis of tickets to allow nodes communicating over a non-secure network to prove their identity to one another in a secure manner, is enabled.&lt;br /&gt;
|-&lt;br /&gt;
| [b] passwords are cryptographically protected in transit. || Screen Share || Screen share Group Policy or similar tool providing centralized management and configuration of operating systems, applications, and users&#039; settings in a directory-based identity-related service tool&#039;s configuration that Kerberos, or a similar network authentication protocol that works on the basis of tickets to allow nodes communicating over a non-secure network to prove their identity to one another in a secure manner, is enabled.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IA.L2-3.5.11 – Obscure Feedback ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IA.L2-3.5.10_Details|&#039;&#039;&#039;IA.L2-3.5.10&#039;&#039;&#039;]] Obscure feedback of authentication information.&lt;br /&gt;
|-&lt;br /&gt;
| [a] authentication information is obscured during the authentication process. || Screen Share || Screen share of Group Policy or similar tool providing centralized management and configuration of operating systems, applications, and users&#039; settings in a directory-based identity-related service tool&#039;s configuration to show that passwords are obscured.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Incident Response (IR) ==&lt;br /&gt;
=== IR.L2-3.6.1 – Incident Handling ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IR.L2-3.6.1_Details|&#039;&#039;&#039;IR.L2-3.6.1&#039;&#039;&#039;]] Establish an operational incident-handling capability for organizational systems that includes preparation, detection, analysis, containment, recovery, and user response activities.&lt;br /&gt;
|-&lt;br /&gt;
| [a] an operational incident-handling capability is established. || Document || Incident Response SOP/Plan.&lt;br /&gt;
|-&lt;br /&gt;
| [b] the operational incident-handling capability includes preparation. || Document || Incident Response SOP/Plan, prior incident report, training, COOP plan.&lt;br /&gt;
|-&lt;br /&gt;
| [c] the operational incident-handling capability includes detection. || Document || Incident Response SOP/Plan; definition of tools used to detect; artifacts showing tools used; prior incident report.&lt;br /&gt;
|-&lt;br /&gt;
| [d] the operational incident-handling capability includes analysis. || Document || Incident Response SOP/Plan; Definition of tools used to analyze potential incidents; artifacts showing tools used for analysis; prior incident report.&lt;br /&gt;
|-&lt;br /&gt;
| [e] the operational incident-handling capability includes containment. || Document || Incident Response SOP/Plan; isolation/quarantine process; user training.&lt;br /&gt;
|-&lt;br /&gt;
| [f] the operational incident-handling capability includes recovery. || Document || Incident Response SOP/Plan; COOP Plan; prior incident reports, re-baselining impacted devices.&lt;br /&gt;
|-&lt;br /&gt;
| [g] the operational incident-handling capability includes user response. || Document || Incident Response SOP/Plan; user awareness training; Help Desk process.&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IR.L2-3.6.2 – Incident Reporting ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IR.L2-3.6.2_Details|&#039;&#039;&#039;IR.L2-3.6.2&#039;&#039;&#039;]] Track, document, and report incidents to designated officials and/or authorities both internal and external to the organization.&lt;br /&gt;
|-&lt;br /&gt;
| [a] incidents are tracked. || Artifact || Incident Response SOP/Plan; ITSM artifact; technical implementation for incident tracking.&lt;br /&gt;
|-&lt;br /&gt;
| [b] incidents are documented. || Artifact || Incident Response SOP/Plan; ITSM artifact; technical implementation for incident tracking.&lt;br /&gt;
|-&lt;br /&gt;
| [c] authorities to whom incidents are to be reported are identified. || Document || Incident Response SOP/Plan.&lt;br /&gt;
|-&lt;br /&gt;
| [d] organizational officials to whom incidents are to be reported are identified. || Document || Incident Response SOP/Plan.&lt;br /&gt;
|-&lt;br /&gt;
| [e] identified authorities are notified of incidents. || Screen Share || Prior incident report; DIBNET login; prior email notifications.&lt;br /&gt;
|-&lt;br /&gt;
| [f] identified organizational officials are notified of incidents. || Artifact || Prior incident report; prior email notifications; tabletop exercises.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IR.L2-3.6.3 – Incident Response Testing ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IR.L2-3.6.3_Details|&#039;&#039;&#039;IR.L2-3.6.3&#039;&#039;&#039;]] Test the organizational incident response capability.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the incident response capability is tested. || Artifact || Incident response table top/scheduled or unscheduled test or penetration test.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Maintenance (MA) ==&lt;br /&gt;
=== MA.L2-3.7.1 – Perform Maintenance ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MA.L2-3.7.1_Details|&#039;&#039;&#039;MA.L2-3.7.1&#039;&#039;&#039;]] Perform maintenance on organizational systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] system maintenance is performed. || Artifact || Establish typical maintenance activities (HVAC, UPS, power distribution, generators, copier maintenance) that are performed; maintenance agreements or contracts detailing these types of activities are acceptable; interview responses should be considered.  This requirement should not be confused with 3.14.1 - report, remediate, and correct system flaws in a timely manner (patch management).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MA.L2-3.7.2 – System Maintenance Control ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MA.L2-3.7.2_Details|&#039;&#039;&#039;MA.L2-3.7.2&#039;&#039;&#039;]] Provide controls on the tools, techniques, mechanisms, and personnel used to conduct system maintenance.&lt;br /&gt;
|-&lt;br /&gt;
| [a] tools used to conduct system maintenance are controlled. || Artifact || Tools may largely depend on the assessed environment; discussion examples include network diagnostic and monitoring tools (including hardware and software); artifacts could demonstrate secured locations/areas for these tools (photos) or checkout sheets/rosters (documents) depicting responsible personnel and the dates/times of checkout.&lt;br /&gt;
|-&lt;br /&gt;
| [b] techniques used to conduct system maintenance are controlled. || Artifact || Processes for scheduling, performing, documenting, reviewing, approving, and monitoring maintenance and repairs for the information system.&lt;br /&gt;
|-&lt;br /&gt;
| [c] mechanisms used to conduct system maintenance are controlled. || Artifact || Processes for scheduling, performing, documenting, reviewing, approving, and monitoring maintenance and repairs for the information system.&lt;br /&gt;
|-&lt;br /&gt;
| [d] personnel used to conduct system maintenance are controlled. || Physical Review || Screenshot of who is authorized to conduct maintenance; maintenance personnel training program.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MA.L2-3.7.3 – Equipment Sanitization ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MA.L2-3.7.3_Details|&#039;&#039;&#039;MA.L2-3.7.3&#039;&#039;&#039;]] Ensure equipment removed for off-site maintenance is sanitized of any CUI.&lt;br /&gt;
|-&lt;br /&gt;
| [a] equipment to be removed from organizational spaces for off-site maintenance is sanitized of any CUI. || Artifact || Document or artifact; record if equipment sanitized; categories of sanitization/destruction defined; sanitization procedural document.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MA.L2-3.7.4 – Media Inspection ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MA.L2-3.7.4_Details|&#039;&#039;&#039;MA.L2-3.7.4&#039;&#039;&#039;]] Check media containing diagnostic and test programs for malicious code before the media are used in organizational systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] media containing diagnostic and test programs are checked for malicious code before being used in organizational systems that process, store, or transmit CUI. || Artifact || Screenshot of diagnostic/test program being used (such as Symantec and McAfee on access scans…).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MA.L2-3.7.5 – Nonlocal Maintenance ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MA.L2-3.7.5_Details|&#039;&#039;&#039;MA.L2-3.7.5&#039;&#039;&#039;]] Require multifactor authentication to establish nonlocal maintenance sessions via external network connections and terminate such connections when nonlocal maintenance is complete.&lt;br /&gt;
|-&lt;br /&gt;
| [a] multifactor authentication is used to establish nonlocal maintenance sessions via external network connections. || Screen Share || Describe MFA used to remote from external service to organizational systems for maintenance and screenshot of MFA (3.5.3)(points associated with admin).&lt;br /&gt;
|-&lt;br /&gt;
| [b] nonlocal maintenance sessions established via external network connections are terminated when nonlocal maintenance is complete. || Screen Share || Screenshot VPN session timeout.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MA.L2-3.7.6 – Maintenance Personnel ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MA.L2-3.7.6_Details|&#039;&#039;&#039;MA.L2-3.7.6&#039;&#039;&#039;]] Supervise the maintenance activities of maintenance personnel without required access authorization.&lt;br /&gt;
|-&lt;br /&gt;
| [a] maintenance personnel without required access authorization are supervised during maintenance activities. || Document || System maintenance policy; list of authorized personnel; maintenance records or, contracts/SLAs; WebEx.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Media Protection (MP) ==&lt;br /&gt;
=== MP.L2-3.8.1 – Media Protection ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MP.L2-3.8.1_Details|&#039;&#039;&#039;MP.L2-3.8.1&#039;&#039;&#039;]] Protect (i.e., physically control and securely store) system media containing CUI, both paper and digital.&lt;br /&gt;
|-&lt;br /&gt;
| [a] paper media containing CUI is physically controlled. || Document || Policy showing CUI paper media is controlled; artifact showing who has access; artifacts/records of  inventories conducted; media check out procedures (i.e. file cabinets, encryption, password protection).&lt;br /&gt;
|-&lt;br /&gt;
| [b] digital media containing CUI is physically controlled. || Document || Policy showing CUI digital media is controlled; artifact showing who has access; artifacts/records of inventories conducted; media check out procedures (i.e. file cabinets, external drives, USBs, encryption, password protection).&lt;br /&gt;
|-&lt;br /&gt;
| [c] paper media containing CUI is securely stored. || Physical Review || Check out/sign out sheets; possible photo of storage container/video walk through of storage area; badge reader logs or access lists for keys for secured areas; interview response considered (i.e. file cabinets,  encryption, password protection).&lt;br /&gt;
|-&lt;br /&gt;
| [d] digital media containing CUI is securely stored. || Physical Review || Check out/sign out sheets; possible photo of storage container/video walk through of storage area; badge reader logs or access lists for keys for secured areas; interview response considered (i.e. file cabinets, external drives, USBs, encryption, password protection).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MP.L2-3.8.2 – Media Access ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MP.L2-3.8.2_Details|&#039;&#039;&#039;MP.L2-3.8.2&#039;&#039;&#039;]] Limit access to CUI on system media to authorized users.&lt;br /&gt;
|-&lt;br /&gt;
| [a] access to CUI on system media is limited to authorized users. || Artifact || Document describing how CUI is limited AND artifact showing principle of least access is implemented.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MP.L2-3.8.3 – Media Disposal [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MP.L2-3.8.3_Details|&#039;&#039;&#039;MP.L2-3.8.3&#039;&#039;&#039;]] Sanitize or destroy information system media containing Federal Contract Information before disposal or release for reuse.&lt;br /&gt;
|-&lt;br /&gt;
| [a] system media containing CUI is sanitized or destroyed before disposal. || Document || Policy or artifact of media destruction logs; certificates of destruction; SLAs or contracts.&lt;br /&gt;
|-&lt;br /&gt;
| [b] system media containing CUI is sanitized before it is released for reuse. || Document || Policy or artifact describing method to sanitize, software used (i.e. DoD Wipe, ShredIT and Iron Mountain; Blancco; GDisk, DBAN).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MP.L2-3.8.4 – Media Markings ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MP.L2-3.8.4_Details|&#039;&#039;&#039;MP.L2-3.8.4&#039;&#039;&#039;]] Mark media with necessary CUI markings and distribution limitations.&lt;br /&gt;
|-&lt;br /&gt;
| [a] media containing CUI is marked with applicable CUI markings. || Physical Review || Document or artifact showing CUI markings (i.e. labeling standards ).&lt;br /&gt;
|-&lt;br /&gt;
| [b] media containing CUI is marked with distribution limitations. || Physical Review || Document or artifact showing distro limitations (i.e. labeling standards ).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MP.L2-3.8.5 – Media Accountability ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MP.L2-3.8.5_Details|&#039;&#039;&#039;MP.L2-3.8.5&#039;&#039;&#039;]] Control access to media containing CUI and maintain accountability for media during transport outside of controlled areas.&lt;br /&gt;
|-&lt;br /&gt;
| [a] access to media containing CUI is controlled. || Document || Policy, artifact of audit logs showing tracking, Access Control Lists, records of transport activities (i.e. USB drives, CDs, chain of custody.&lt;br /&gt;
|-&lt;br /&gt;
| [b] accountability for media containing CUI is maintained during transport outside of controlled areas. || Artifact || Artifact of audit logs showing tracking, Access Control Lists, records of transport activities (i.e. USB drives, CDs; chain of custody.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MP.L2-3.8.6 – Portable Storage Encryption ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MP.L2-3.8.6_Details|&#039;&#039;&#039;MP.L2-3.8.6&#039;&#039;&#039;]] Implement cryptographic mechanisms to protect the confidentiality of CUI stored on digital media during transport unless otherwise protected by alternative physical safeguards.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the confidentiality of CUI stored on digital media is protected during transport using cryptographic mechanisms or alternative physical safeguards. || Artifact || Artifact showing crypto mechanisms used to protect (are they FIPS 140-2 [13.11]); artifact showing what alternative physical safeguards are in place (i.e. encryption; BitLocker; McAfee ).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MP.L2-3.8.7 – Removable Media ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MP.L2-3.8.7_Details|&#039;&#039;&#039;MP.L2-3.8.7&#039;&#039;&#039;]] Control the use of removable media on system components.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the use of removable media on system components is controlled. || Artifact || Policy showing if removable media is allowed; writable removable media is restricted; tracking artifacts; what tools are used (i.e. Carbon Black, Crowd Strike, GPO, Zoho Desktop Central); procedure/process describing what happens if it is lost; what mechanisms are in place to control/restrict removable media (i.e. Active Directory Groups and Group Policy artifact showing restriction).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MP.L2-3.8.8 – Shared Media ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MP.L2-3.8.8_Details|&#039;&#039;&#039;MP.L2-3.8.8&#039;&#039;&#039;]] Prohibit the use of portable storage devices when such devices have no identifiable owner.ASSESSMENT OBJECTIVES&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [a] the use of portable storage devices is prohibited when such devices have no identifiable owner. || Artifact || Policy and/or artifact showing company stance on portable storage devices if there is no owner (are personal USB devices allowed or are they company-issued; artifact showing alerts if device is connected to network (i.e. external HDD, Carbon Black, Crowd Strike, GPO, Zoho Desktop Central.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MP.L2-3.8.9 – Protect Backups ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MP.L2-3.8.9_Details|&#039;&#039;&#039;MP.L2-3.8.9&#039;&#039;&#039;]] Protect the confidentiality of backup CUI at storage locations.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the confidentiality of backup CUI is protected at storage locations. || Artifact || Policy on system backups; artifact showing media labeling; artifact showing encyption (is it FIPS 140-2 [13.11]); Access Control List artifact (i.e. backup tapes, Tivoli Storage Manager).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Personnel Security (PS) ==&lt;br /&gt;
=== PS.L2-3.9.1 – Screen Individuals ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_PS.L2-3.9.1_Details|&#039;&#039;&#039;PS.L2-3.9.1&#039;&#039;&#039;]] Screen individuals prior to authorizing access to organizational systems containing CUI.&lt;br /&gt;
|-&lt;br /&gt;
| [a] individuals are screened prior to authorizing access to organizational systems containing CUI. || Artifact || Screenshot of records of screened personnel/background checks.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== PS.L2-3.9.2 – Personnel Actions ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_PS.L2-3.9.2_Details|&#039;&#039;&#039;PS.L2-3.9.2&#039;&#039;&#039;]] Ensure that organizational systems containing CUI are protected during and after personnel actions such as terminations and transfers.&lt;br /&gt;
|-&lt;br /&gt;
| [a] a policy and/or process for terminating system access and any credentials coincident with personnel actions is established. || Document || Personnel security policy/procedures/instruction; Access control policy/procedure/instruction.&lt;br /&gt;
|-&lt;br /&gt;
| [b] system access and credentials are terminated consistent with personnel actions such as termination or transfer. || Artifact || Screenshot of records of personnel transfer and termination actions.&lt;br /&gt;
|-&lt;br /&gt;
| [c] the system is protected during and after personnel transfer actions. || Artifact || Completed outprocessing checklist.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Physical Protection (PE) ==&lt;br /&gt;
=== PE.L2-3.10.1 – Limit Physical Access [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_PE.L2-3.10.1_Details|&#039;&#039;&#039;PE.L2-3.10.1&#039;&#039;&#039;]] Limit physical access to organizational information systems, equipment, and the respective operating environments to authorized individuals.&lt;br /&gt;
|-&lt;br /&gt;
| [a] authorized individuals allowed physical access are identified. || Artifact || Authorized personnel (names) access list.&lt;br /&gt;
|-&lt;br /&gt;
| [b] physical access to organizational systems is limited to authorized individuals. || Physical Review || Badge reader logs, audit logs, and/or card swipe test.&lt;br /&gt;
|-&lt;br /&gt;
| [c] physical access to equipment is limited to authorized individuals. || Physical Review || Badge reader logs, audit logs, and/or card swipe test.&lt;br /&gt;
|-&lt;br /&gt;
| [d] physical access to operating environments is limited to authorized. || Physical Review || Badge reader logs, audit logs, and/or card swipe test.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== PE.L2-3.10.2 – Monitor Facility ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_PE.L2-3.10.2_Details|&#039;&#039;&#039;PE.L2-3.10.2&#039;&#039;&#039;]] Protect and monitor the physical facility and support infrastructure for organizational systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the physical facility where organizational systems reside is protected. || Physical Review || Physical security measures and barriers into the physical facility (cameras/locks/gates/guards, etc.).&lt;br /&gt;
|-&lt;br /&gt;
| [b] the support infrastructure for organizational systems is protected. || Physical Review || Physical barriers to entries into computer spaces, server rooms, etc.&lt;br /&gt;
|-&lt;br /&gt;
| [c] the physical facility where organizational systems reside is monitored. || Physical Review || Audit logs/how the physical facility is being monitored (cameras/access system/guards, etc.).&lt;br /&gt;
|-&lt;br /&gt;
| [d] the support infrastructure for organizational systems is monitored. || Physical Review || Audit logs/how the physical facility is being monitored (cameras/access system/guards, etc.).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== PE.L2-3.10.3 – Escort Visitors [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_PE.L2-3.10.3_Details|&#039;&#039;&#039;PE.L2-3.10.3&#039;&#039;&#039;]] Escort visitors and monitor visitor activity.&lt;br /&gt;
|-&lt;br /&gt;
| [a] visitors are escorted. || Physical Review || Policy/procedures/instruction on methodology for handling non-authorized personnel (entry to exit).&lt;br /&gt;
|-&lt;br /&gt;
| [b] visitor activity is monitored. || Physical Review || Policy/procedures/instructio on methodology for handling non-authorized personnel (entry to exit).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== PE.L2-3.10.4 – Physical Access Logs [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_PE.L2-3.10.4_Details|&#039;&#039;&#039;PE.L2-3.10.4&#039;&#039;&#039;]] Maintain audit logs of physical access.&lt;br /&gt;
|-&lt;br /&gt;
| [a] audit logs of physical access are maintained. || Artifact || Log or report from badging system.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== PE.L2-3.10.5 – Manage Physical Access [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_PE.L2-3.10.5_Details|&#039;&#039;&#039;PE.L2-3.10.5&#039;&#039;&#039;]] Control and manage physical access devices.&lt;br /&gt;
|-&lt;br /&gt;
| [a] physical access devices are identified. || Document || Physical access control systems description, guard force contract/policy, key locks, logical systems specifications, etc.&lt;br /&gt;
|-&lt;br /&gt;
| [b] physical access devices are controlled. || Physical Review || Inventory records of physical access control devices (e.g. keys, locks, card readers, locks, etc.).&lt;br /&gt;
|-&lt;br /&gt;
| [c] physical access devices are managed. || Physical Review || List of security safeguards controlling access to the facility (e.g. cameras, monitoring by guards, isolation of IT systems equiment and or system components).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== PE.L2-3.10.6 – Alternative Work Sites ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_PE.L2-3.10.6_Details|&#039;&#039;&#039;PE.L2-3.10.6&#039;&#039;&#039;]] Enforce safeguarding measures for CUI at alternate work sites.&lt;br /&gt;
|-&lt;br /&gt;
| [a] safeguarding measures for CUI are defined for alternate work sites. || Document || Telework agreement, Acceptable Use Policy and SOP for alternate work locations; user security training validation which includes physical/logical/technical protections of system at alternate work sites.&lt;br /&gt;
|-&lt;br /&gt;
| [b] safeguarding measures for CUI are enforced for alternate work sites. || Artifact || Monitoring/audit log of user activity and logical/physical/technical mechanisms in place to preclude unauthorized activity (telework agreement , AUP?).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Risk Assessment (RA) ==&lt;br /&gt;
=== RA.L2-3.11.1 – Risk Assessments ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_RA.L2-3.11.1_Details|&#039;&#039;&#039;RA.L2-3.11.1&#039;&#039;&#039;]] Periodically assess the risk to organizational operations (including mission, functions, image, or reputation), organizational assets, and individuals, resulting from the operation of organizational systems and the associated processing, storage, or transmission of CUI.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the frequency to assess risk to organizational operations, organizational assets, and individuals is defined. || Document || Risk assessment policy.&lt;br /&gt;
|-&lt;br /&gt;
| [b] risk to organizational operations, organizational assets, and individuals resulting from the operation of an organizational system that processes, stores, or transmits CUI is assessed with the defined frequency. || Artifact || Copy of last risk assessment done within defined frequency.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== RA.L2-3.11.2 – Vulnerability Scan ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_RA.L2-3.11.2_Details|&#039;&#039;&#039;RA.L2-3.11.2&#039;&#039;&#039;]] Scan for vulnerabilities in organizational systems and applications periodically and when new vulnerabilities affecting those systems and applications are identified.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the frequency to scan for vulnerabilities in organizational systems and applications is defined. || Document || Policy/procedures/instruction addressing vulnerability scanning records.&lt;br /&gt;
|-&lt;br /&gt;
| [b] vulnerability scans are performed on organizational systems with the defined frequency. || Screen Share || System configuration settings of vulnerability scanning scheduling and vulnerability scan results of systems within defined frequency.&lt;br /&gt;
|-&lt;br /&gt;
| [c] vulnerability scans are performed on applications with the defined frequency. || Screen Share || System configuration settings of vulnerability scanning scheduling and vulnerability scan results of applications within defined frequency.&lt;br /&gt;
|-&lt;br /&gt;
| [d] vulnerability scans are performed on organizational systems when new vulnerabilities are identified. || Screen Share || View signatures in scanning tool/ad hoc scan performed as a result.&lt;br /&gt;
|-&lt;br /&gt;
| [e] vulnerability scans are performed on applications when new vulnerabilities are identified. || Screen Share || View signatures in scanning tool/ad hoc scan performed as a result.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== RA.L2-3.11.3 – Vulnerability Remediation ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_RA.L2-3.11.3_Details|&#039;&#039;&#039;RA.L2-3.11.3&#039;&#039;&#039;]] Remediate vulnerabilities in accordance with risk assessments.&lt;br /&gt;
|-&lt;br /&gt;
| [a] vulnerabilities are identified. || Artifact || Scan results showing vulnerabilities identified.&lt;br /&gt;
|-&lt;br /&gt;
| [b] vulnerabilities are remediated in accordance with risk assessments. || Artifact || Screenshot/document of scan results of remediated vulnerabilities in accordance to risk assessments.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Security Assessment (CA) ==&lt;br /&gt;
=== CA.L2-3.12.1 – Security Control Assessment ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_CA.L2-3.12.1_Details|&#039;&#039;&#039;CA.L2-3.12.1&#039;&#039;&#039;]] Periodically assess the security controls in organizational systems to determine if the controls are effective in their application.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the frequency of security control assessments is defined. || Document || SSP.&lt;br /&gt;
|-&lt;br /&gt;
| [b] security controls are assessed with the defined frequency to determine if the controls are effective in their application. || Artifact || Copy of last security control assessment done within defined frequency.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== CA.L2-3.12.2 – Operational Plan of Action ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_CA.L2-3.12.2_Details|&#039;&#039;&#039;CA.L2-3.12.2&#039;&#039;&#039;]] Develop and implement plans of action designed to correct deficiencies and reduce or eliminate vulnerabilities in organizational systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] deficiencies and vulnerabilities to be addressed by the plan of action are identified. || Artifact || Plan of Action (POA).&lt;br /&gt;
|-&lt;br /&gt;
| [b] a plan of action is developed to correct identified deficiencies and reduce or eliminate identified vulnerabilities. || Artifact || Plan of Action (POA).&lt;br /&gt;
|-&lt;br /&gt;
| [c] the plan of action is implemented to correct identified deficiencies and reduce or eliminate identified vulnerabilities. || Artifact || Plan of Action (POA)/previously completed POAs.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== CA.L2-3.12.3 – Security Control Monitoring ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_CA.L2-3.12.3_Details|&#039;&#039;&#039;CA.L2-3.12.3&#039;&#039;&#039;]] Monitor security controls on an ongoing basis to ensure the continued effectiveness of the controls.&lt;br /&gt;
|-&lt;br /&gt;
| [a] security controls are monitored on an ongoing basis to ensure the continued effectiveness of those controls. || Artifact || Collection of risk assessment results, internal or third-party audits/security assessments and/or continuous monitoring reports/alerts (SIEM tool, etc.).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== CA.L2-3.12.4 – System Security Plan ====&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_CA.L2-3.12.4_Details|&#039;&#039;&#039;CA.L2-3.12.4&#039;&#039;&#039;]] Develop, document, and periodically update system security plans that describe system boundaries, system environments of operation, how security requirements are implemented, and the relationships with or connections to other systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] a system security plan is developed. || Document || SSP.&lt;br /&gt;
|-&lt;br /&gt;
| [b] the system boundary is described and documented in the system security plan. || Document || SSP and any supporting documentation.&lt;br /&gt;
|-&lt;br /&gt;
| [c] the system environment of operation is described and documented in the system security plan. || Document || SSP and any supporting documentation.&lt;br /&gt;
|-&lt;br /&gt;
| [d] the security requirements identified and approved by the designated authority as non-applicable are identified. || Document || SSP and required adjudication from DoD CIO.&lt;br /&gt;
|-&lt;br /&gt;
| [e] the method of security requirement implementation is described and documented in the system security plan. || Document || SSP and any supporting documentation.&lt;br /&gt;
|-&lt;br /&gt;
| [f] the relationship with or connection to other systems is described and documented in the system security plan. || Document || SSP and any supporting documentation.&lt;br /&gt;
|-&lt;br /&gt;
| [g] the frequency to update the system security plan is defined. || Document || SSP.&lt;br /&gt;
|-&lt;br /&gt;
| [h] system security plan is updated with the defined frequency. || Document || SSP/any previous versions.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== System and Communications Protection (SC) ==&lt;br /&gt;
=== SC.L2-3.13.1 – Boundary Protection [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.1_Details|&#039;&#039;&#039;SC.L2-3.13.1&#039;&#039;&#039;]] Monitor, control, and protect organizational communications (i.e., information transmitted or received by organizational information systems) at the external boundaries and key internal boundaries of the information systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the external system boundary is defined. || Document || SSP, network diagrams, CUI flow, cloud provider FedRAMP Moderate.&lt;br /&gt;
|-&lt;br /&gt;
| [b] key internal system boundaries are defined. || Document || SSP, network diagrams, CUI flow.&lt;br /&gt;
|-&lt;br /&gt;
| [c] communications are monitored at the external system boundary. || Screen Share || SSP, logging server, boundary device configurations, monitoring policy.&lt;br /&gt;
|-&lt;br /&gt;
| [d] communications are monitored at key internal boundaries. || Screen Share || SSP, logging server, boundary device configurations, monitoring policy.&lt;br /&gt;
|-&lt;br /&gt;
| [e] communications are controlled at the external system boundary. || Screen Share || SSP, boundary device configurations, ACL, subnets, DMZ.&lt;br /&gt;
|-&lt;br /&gt;
| [f] communications are controlled at key internal boundaries. || Screen Share || SSP, boundary device configurations, ACL, subnets.&lt;br /&gt;
|-&lt;br /&gt;
| [g] communications are protected at the external system boundary. || Screen Share || Configurations for IPS/IDS, email gateway, VLAN, proxy, firewall, malware protection, DNS, TSL.&lt;br /&gt;
|-&lt;br /&gt;
| [h] communications are protected at key internal boundaries. || Screen Share || Configurations for IPS/IDS, VLAN, firewall, malware protection, SSL.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.2 – Security Engineering ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.2_Details|&#039;&#039;&#039;SC.L2-3.13.2&#039;&#039;&#039;]] Employ architectural designs, software development techniques, and systems engineering principles that promote effective information security within organizational systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] architectural designs that promote effective information security are identified. || Document || SSP, config management policy, network diagram, CCB minutes, enterprise architecture process.&lt;br /&gt;
|-&lt;br /&gt;
| [b] software development techniques that promote effective information security are identified. || Document || SSP, config management policy, SDLC, CCB minutes.&lt;br /&gt;
|-&lt;br /&gt;
| [c] systems engineering principles that promote effective information security are identified. || Document || SSP, config management policy, CCB minutes, security architecture engineering.&lt;br /&gt;
|-&lt;br /&gt;
| [d] identified architectural designs that promote effective information security are employed. || Artifact || CCB minutes, Network diagrams and configurations, Project Plans.&lt;br /&gt;
|-&lt;br /&gt;
| [e] identified software development techniques that promote effective information security are employed. || Artifact || CCB minutes, SDLC, code scanner results, code management tracking.&lt;br /&gt;
|-&lt;br /&gt;
| [f] identified systems engineering principles that promote effective information security are employed. || Artifact || CCB minutes, configuration management, ITSM, patch management, lifecycle replacement processes.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.3 – Role Separation ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.3_Details|&#039;&#039;&#039;SC.L2-3.13.3&#039;&#039;&#039;]] Separate user functionality from system management functionality.&lt;br /&gt;
|-&lt;br /&gt;
| [a] user functionality is identified. || Document || SSP, AUP.&lt;br /&gt;
|-&lt;br /&gt;
| [b] system management functionality is identified. || Document || SSP, Privileged Account Agreement.&lt;br /&gt;
|-&lt;br /&gt;
| [c] user functionality is separated from system management functionality. || Screen Share || Active Directory, Jump Boxes, GPO, VM, RDP.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.4 – Shared Resource Control ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.4_Details|&#039;&#039;&#039;SC.L2-3.13.4&#039;&#039;&#039;]] Prevent unauthorized and unintended information transfer via shared system resources.&lt;br /&gt;
|-&lt;br /&gt;
| [a] unauthorized and unintended information transfer via shared system resources is prevented. || Screen Share || SSP, OS configurations, Linux containers, system/media reuse policies, certificate management policies, media destruction policies, printer configs, VDI configuration.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
===  SC.L2-3.13.5 – Public-Access System Separation [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.5_Details|&#039;&#039;&#039;SC.L2-3.13.5&#039;&#039;&#039;]] Implement subnetworks for publicly accessible system components that are physically or logically separated from internal networks.&lt;br /&gt;
|-&lt;br /&gt;
| [a] publicly accessible system components are identified. || Document || SSP, network diagram, DMZ inventory/roles.&lt;br /&gt;
|-&lt;br /&gt;
| [b] subnetworks for publicly accessible system components are physically or logically separated from internal networks. || Artifact || Network diagram, IPAM, VLAN, DHCP, DMZ.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.6 – Network Communication by Exception ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.6_Details|&#039;&#039;&#039;SC.L2-3.13.6&#039;&#039;&#039;]] Deny network communications traffic by default and allow network communications traffic by exception (i.e., deny all, permit by exception).&lt;br /&gt;
|-&lt;br /&gt;
| [a] network communications traffic is denied by default. || Screen Share || Host and network firewall rules, SIEM logs, hit counts.&lt;br /&gt;
|-&lt;br /&gt;
| [b] network communications traffic is allowed by exception. || Screen Share || Host and network firewall rules, SIEM logs, hit counts.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.7 – Split Tunneling ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.7_Details|&#039;&#039;&#039;SC.L2-3.13.7&#039;&#039;&#039;]] Prevent remote devices from simultaneously establishing non-remote connections with organizational systems and communicating via some other connection to resources in external networks (i.e., split tunneling).&lt;br /&gt;
|-&lt;br /&gt;
| [a] remote devices are prevented from simultaneously establishing non-remote connections with the system and communicating via some other connection to resources in external networks (i.e., split tunneling). || Screen Share || VPN appliance/server configuration, endpoint VPN software configuration.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.8 – Data in Transit ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.8_Details|&#039;&#039;&#039;SC.L2-3.13.8&#039;&#039;&#039;]] Implement cryptographic mechanisms to prevent unauthorized disclosure of CUI during transmission unless otherwise protected by alternative physical safeguards.&lt;br /&gt;
|-&lt;br /&gt;
| [a] cryptographic mechanisms intended to prevent unauthorized disclosure of CUI are identified. || Document || SSP, PKI policies, configuration processes, config management, email attachment encryption policy, removable media policy, data at rest policy.&lt;br /&gt;
|-&lt;br /&gt;
| [b] alternative physical safeguards intended to prevent unauthorized disclosure of CUI are identified. || Document || SSP, physical security policy.&lt;br /&gt;
|-&lt;br /&gt;
| [c] either cryptographic mechanisms or alternative physical safeguards are implemented to prevent unauthorized disclosure of CUI during transmission. || Artifact || TLS settings, SSL settings, VPN/Wireless Access Points/Mobile Devices cryptographic settings, ODBC connector settings, SAN configuration, IPSec/MPLS, backup configuration, physical security.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.9 – Connections Termination ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.9_Details|&#039;&#039;&#039;SC.L2-3.13.9&#039;&#039;&#039;]] Terminate network connections associated with communications sessions at the end of the sessions or after a defined period of inactivity.&lt;br /&gt;
|-&lt;br /&gt;
| [a] a period of inactivity to terminate network connections associated with communications sessions is defined. || Document || SSP, network communications policy.&lt;br /&gt;
|-&lt;br /&gt;
| [b] network connections associated with communications sessions are terminated at the end of the sessions. || Screen Share || VPN appliance/server logs, VPN configurations, web server configurations, firewall connection settings.&lt;br /&gt;
|-&lt;br /&gt;
| [c] network connections associated with communications sessions are terminated after the defined period of inactivity. || Screen Share || VPN appliance/server logs, VPN configurations, web server configurations, frewall connection settings.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.10 – Key Management ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.10_Details|&#039;&#039;&#039;SC.L2-3.13.10&#039;&#039;&#039;]] Establish and manage cryptographic keys for cryptography employed in organizational systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] cryptographic keys are established whenever cryptography is employed. || Artifact || SSP, PKI/certificate management policy, configuration management.&lt;br /&gt;
|-&lt;br /&gt;
| [b] cryptographic keys are managed whenever cryptography is employed. || Artifact || SSP, PKI/certificate management policy, configuration management, access control policy.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.11 – CUI Encryption ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.11_Details|&#039;&#039;&#039;SC.L2-3.13.11&#039;&#039;&#039;]] Employ FIPS-validated cryptography when used to protect the confidentiality of CUI.&lt;br /&gt;
|-&lt;br /&gt;
| [a] FIPS-validated cryptography is employed to protect the confidentiality of CUI. || Screen Share || VPN, wireless, mobile devices, client certificates, server certificates, disk encryption, Outlook plugin, external mail, backup media, ePO server, removable storage, SAN, file compression; look for FIPS mode enabled on appliances.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.12 – Collaborative Device Control ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.12_Details|&#039;&#039;&#039;SC.L2-3.13.12&#039;&#039;&#039;]] Prohibit remote activation of collaborative computing devices and provide indication of devices in use to users present at the device.&lt;br /&gt;
|-&lt;br /&gt;
| [a] collaborative computing devices are identified. || Document || SSP, network diagrams.&lt;br /&gt;
|-&lt;br /&gt;
| [b] collaborative computing devices provide indication to users of devices in use. || Physical Review || Physical inspection of device.&lt;br /&gt;
|-&lt;br /&gt;
| [c] remote activation of collaborative computing devices is prohibited. || Screen Share || Collaboration device configuration/console.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.13 – Mobile Code ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.13_Details|&#039;&#039;&#039;SC.L2-3.13.13&#039;&#039;&#039;]] Control and monitor the use of mobile code.&lt;br /&gt;
|-&lt;br /&gt;
| [a] use of mobile code is controlled. || Screen Share || GPO settings, malware protection, software agent configurations, software development policies, code scanners, MDM configuration, firewall/secure web gateway/proxy config.&lt;br /&gt;
|-&lt;br /&gt;
| [b] use of mobile code is monitored. || Screen Share || SIEM/console monitoring.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.14 – Voice over Internet Protocol ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.14_Details|&#039;&#039;&#039;SC.L2-3.13.14&#039;&#039;&#039;]] Control and monitor the use of Voice over Internet Protocol (VoIP) technologies.&lt;br /&gt;
|-&lt;br /&gt;
| [a] use of Voice over Internet Protocol (VoIP) technologies is controlled. || Artifact || VLAN, ACL, firewall config, VoIP gateway/condenser configuration.&lt;br /&gt;
|-&lt;br /&gt;
| [b] use of Voice over Internet Protocol (VoIP) technologies is monitored. || Artifact || SIEM/VoIP console monitoring, session border controller.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.15 – Communications Authenticity ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.15_Details|&#039;&#039;&#039;SC.L2-3.13.15&#039;&#039;&#039;]] Protect the authenticity of communications sessions.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the authenticity of communications sessions is protected. || Screen Share || SSL, TLS, SMB3, SFTP, IPSec, SSH, Kerberos configs, MPLS, Network Access Control.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.16 – Data at Rest ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.16_Details|&#039;&#039;&#039;SC.L2-3.13.16&#039;&#039;&#039;]] Protect the confidentiality of CUI at rest.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the confidentiality of CUI at rest is protected. || Artifact || Full disk encryption, removable media encryption, SAN encryption, digital backups, mobile device encryption, third party offsite backup storage, cloud virtualization encryption, physical media storage policies.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== System and Information Integrity (SI) ==&lt;br /&gt;
=== SI.L2-3.14.1 – Flaw Remediation [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SI.L2-3.14.1_Details|&#039;&#039;&#039;SI.L2-3.14.1&#039;&#039;&#039;]] Identify, report, and correct information and information system flaws in a timely manner.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the time within which to identify system flaws is specified. || Document || SSP, patch management policy.&lt;br /&gt;
|-&lt;br /&gt;
| [b] system flaws are identified within the specified time frame. || Screen Share || Vulnerability management scanner output and scan policy configuration.&lt;br /&gt;
|-&lt;br /&gt;
| [c] the time within which to report system flaws is specified. || Document || SSP, patch management policy.&lt;br /&gt;
|-&lt;br /&gt;
| [d] system flaws are reported within the specified time frame. || Screen Share || ITSM/trouble tickets, vulnerability management scanner output.&lt;br /&gt;
|-&lt;br /&gt;
| [e] the time within which to correct system flaws is specified. || Document || SSP, patch management policy.&lt;br /&gt;
|-&lt;br /&gt;
| [f] system flaws are corrected within the specified time frame. || Screen Share || Vulnerability management scanner output and scan policy configuration.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SI.L2-3.14.2 – Malicious Code ProTection [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SI.L2-3.14.2_Details|&#039;&#039;&#039;SI.L2-3.14.2&#039;&#039;&#039;]] Provide protection from malicious code at appropriate locations within organizational information systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] designated locations for malicious code protection are identified. || Document || SSP, system protection policy, network diagrams, security architecture documents.&lt;br /&gt;
|-&lt;br /&gt;
| [b] protection from malicious code at designated locations is provided. || Screen Share || Endpoint security settings, email/web proxy gateways, firewall, IPS sensor, MDM configuration, Network Access Control.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SI.L2-3.14.3 – Security Alerts &amp;amp; Advisories ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SI.L2-3.14.3_Details|&#039;&#039;&#039;SI.L2-3.14.3&#039;&#039;&#039;]] Monitor system security alerts and advisories and take action in response.&lt;br /&gt;
|-&lt;br /&gt;
| [a] response actions to system security alerts and advisories are identified. || Document || SSP, vulnerability management policy, Incident Response Plan.&lt;br /&gt;
|-&lt;br /&gt;
| [b] system security alerts and advisories are monitored. || Artifact || Threat intelligence subscriptions, email advisories.&lt;br /&gt;
|-&lt;br /&gt;
| [c] actions in response to system security alerts and advisories are taken. || Artifact || ITSM/trouble tickets, user notifications, updates to firewall/IPS, etc.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SI.L2-3.14.4 – Update Malicious Code Protection [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SI.L2-3.14.4_Details|&#039;&#039;&#039;SI.L2-3.14.4&#039;&#039;&#039;]] Update malicious code protection mechanisms when new releases are available.&lt;br /&gt;
|-&lt;br /&gt;
| [a] malicious code protection mechanisms are updated when new releases are available. || Screen Share || Antivirus console dashboard, firewall AV, Email gateway signatures,proxy, IPS updates.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SI.L2-3.14.5 – System &amp;amp; File Scanning [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SI.L2-3.14.5_Details|&#039;&#039;&#039;SI.L2-3.14.5&#039;&#039;&#039;]] Perform periodic scans of the information system and real-time scans of files from external sources as files are downloaded, opened, or executed.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the frequency for malicious code scans is defined. || Document || SSP, vulnerability management policy.&lt;br /&gt;
|-&lt;br /&gt;
| [b] malicious code scans are performed with the defined frequency. || Screen Share || Consoles for AV (endpoints, servers, and file shares), firewall, email gateway, proxy, IPS, MDM configurations.&lt;br /&gt;
|-&lt;br /&gt;
| [c] real-time malicious code scans of files from external sources as files are downloaded, opened, or executed are performed. || Screen Share || Consoles for AV (endpoints, servers, and file shares), firewall, email gateway, proxy, IPS, MDM configurations.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SI.L2-3.14.6 – Monitor Communications for Attacks ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SI.L2-3.14.6_Details|&#039;&#039;&#039;SI.L2-3.14.6&#039;&#039;&#039;]] Monitor organizational systems, including inbound and outbound communications traffic, to detect attacks and indicators of potential attacks.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the system is monitored to detect attacks and indicators of potential attacks. || Screen Share || Firewall, IPS, endpoint protection, SIEM alerts and reports.&lt;br /&gt;
|-&lt;br /&gt;
| [b] inbound communications traffic is monitored to detect attacks and indicators of potential attacks. || Screen Share || Firewall, IPS, endpoint protection, SIEM alerts and reports.&lt;br /&gt;
|-&lt;br /&gt;
| [c] outbound communications traffic is monitored to detect attacks and indicators of potential attacks. || Screen Share || Firewall, IPS, endpoint protection, SIEM alerts and reports.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SI.L2-3.14.7 – Identify Unauthorized Use ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SI.L2-3.14.7_Details|&#039;&#039;&#039;SI.L2-3.14.7&#039;&#039;&#039;]] Identify unauthorized use of organizational systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] authorized use of the system is defined. || Document || AUP, SSP.&lt;br /&gt;
|-&lt;br /&gt;
| [b] unauthorized use of the system is identified. || Artifact || SIEM logs, endpoint protection console, IPS, Firewall.&lt;br /&gt;
|}&lt;/div&gt;</summary>
		<author><name>David</name></author>
	</entry>
	<entry>
		<id>https://cmmcwiki.org/index.php?title=Evidence_Collection_Approach&amp;diff=1626</id>
		<title>Evidence Collection Approach</title>
		<link rel="alternate" type="text/html" href="https://cmmcwiki.org/index.php?title=Evidence_Collection_Approach&amp;diff=1626"/>
		<updated>2026-07-20T01:49:09Z</updated>

		<summary type="html">&lt;p&gt;David: /* SC.L2-3.13.8 – Data in Transit */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;CMMC assessments and certification require substantial evidence and documentation. The following tables outline general guidelines for collecting evidence to assess control requirements and objectives. While these guidelines provide a structured approach, they are not the only means of conducting an accurate assessment. Assessors should exercise professional judgment and may employ alternative methods appropriate to the specific organizational context and circumstances.&lt;br /&gt;
&lt;br /&gt;
Evidence collection approaches are defined as:&lt;br /&gt;
* &#039;&#039;&#039;Documentation&#039;&#039;&#039;: Tangible materials containing information over which an organization has authority, including all types of written records and their copies.&lt;br /&gt;
* &#039;&#039;&#039;Artifacts&#039;&#039;&#039;: Tangible, reviewable records directly resulting from a practice or process being performed by a system or by personnel executing their role within that practice, control, or process.&lt;br /&gt;
* &#039;&#039;&#039;Physical Review&#039;&#039;&#039;: Direct on-site observation and examination of evidence.&lt;br /&gt;
* &#039;&#039;&#039;Screen Share&#039;&#039;&#039;: Real-time remote observation of a user demonstrating a task or process via shared computer screen, sometimes called &amp;quot;over-the-shoulder&amp;quot; review.&lt;br /&gt;
&lt;br /&gt;
DISCLAIMER: Evidence requirements vary significantly across assessment types. &#039;&#039;&#039;The examples provided are illustrative only and should be tailored to meet the specific adequacy and sufficiency standards of your particular assessment context.&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
For inquiries and reporting errors on this wiki, please [mailto:support@cmmctoolkit.org contact us]. Thank you.&lt;br /&gt;
&lt;br /&gt;
== Access Control (AC) ==&lt;br /&gt;
=== AC.L2-3.1.1 – Authorized Access Control [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.1_Details|&#039;&#039;&#039;AC.L2-3.1.1&#039;&#039;&#039;]] Limit information system access to authorized users, processes acting on behalf of authorized users, or devices (including other information systems).&lt;br /&gt;
|-&lt;br /&gt;
| [a] authorized users are identified. || Document || Document defining account request, approval, provisioning.&lt;br /&gt;
|-&lt;br /&gt;
| [b] processes acting on behalf of authorized users are identified. || Document || Document defining account request, approval, provisioning.&lt;br /&gt;
|-&lt;br /&gt;
| [c] devices (and other systems) authorized to connect to the system are identified. || Document || Document defining account request, approval, provisioning.&lt;br /&gt;
|-&lt;br /&gt;
| [d] system access is limited to authorized users. || Screen Share || Screen share showing login requirements are enforced. Example of an unauthorized user denied (unauthorized username entered at login).&lt;br /&gt;
|-&lt;br /&gt;
| [e] system access is limited to processes acting on behalf of authorized users. || Screen Share || Screenshot showing that service accounts are assigned to authorized users only; no rogue accounts without an authorized user are active.&lt;br /&gt;
|-&lt;br /&gt;
| [f] system access is limited to authorized devices (including other systems). || Screen Share || Screen share showing that all devices running are authorized; no rogue devices on the network.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.2 – Transaction &amp;amp; Function Control [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.2_Details|&#039;&#039;&#039;AC.L2-3.1.2&#039;&#039;&#039;]] Limit information system access to the types of transactions and functions that authorized users are permitted to execute.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the types of transactions and functions that authorized users are permitted to execute are defined. || Document || SSP, AUP, or IAM document that defines what authorized users can execute.&lt;br /&gt;
|-&lt;br /&gt;
| [b] system access is limited to the defined types of transactions and functions for authorized users. || Screen Share || Screenshot of security roles in AD or IAM or other directory-based identity-related services tool that shows transactions are as defined in the SSP or IAM document; privileged and non-privileged accounts need to be defined and identified in the artifact; screenshot of a non-privileged user trying to execute a privileged function.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.3 – Control CUI Flow ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.3_Details|&#039;&#039;&#039;AC.L2-3.1.3&#039;&#039;&#039;]] Control the flow of CUI in accordance with approved authorizations.&lt;br /&gt;
|-&lt;br /&gt;
| [a] information flow control policies are defined. || Document || SSP or other document describing the control of CUI on the network.&lt;br /&gt;
|-&lt;br /&gt;
| [b] methods and enforcement mechanisms for controlling the flow of CUI are defined. || Document || Document that defines the networking devices that are on the CUI network and answers what measures are in place to control the flow. List of firewalls, border and internal layer 3 devices, IDS/IPS, DLP, that process CUI.&lt;br /&gt;
|-&lt;br /&gt;
| [c] designated sources and destinations (e.g., networks, individuals, and devices) for CUI within the system and between interconnected systems are identified. || Artifact || Network diagram, data flow diagram, external system connection diagrams, document describing the policies for CUI on the network; listing of VLANs and subnets where CUI is authorized; document must describe source and authorized destinations.&lt;br /&gt;
|-&lt;br /&gt;
| [d] authorizations for controlling the flow of CUI are defined. || Document || Document that defines how CUI is to be controlled, such as an InfoSec plan, and/or network management plan.&lt;br /&gt;
|-&lt;br /&gt;
| [e] approved authorizations for controlling the flow of CUI are enforced. || Screen Share || Screenshots of firewall rules, ACLs, etc.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.4 – Separation of Duties ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.4_Details|&#039;&#039;&#039;AC.L2-3.1.4&#039;&#039;&#039;]] Separate the duties of individuals to reduce the risk of malevolent activity without collusion.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the duties of individuals requiring separation are defined. || Document || Document, SSP, account management policy, defining separation of duties by person or role.&lt;br /&gt;
|-&lt;br /&gt;
| [b] responsibilities for duties that require separation are assigned to separate individuals. || Screen Share || Screenshot showing that separation of duties is enforced by showing admin accounts are assigned to different people based on role.&lt;br /&gt;
|-&lt;br /&gt;
| [c] access privileges that enable individuals to exercise the duties that require separation are granted to separate individuals. || Screen Share || Screen shot showing an example such as a security manager can not log into a network device and change ACLs, or network admins can not access security logs in the SIEM tool.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.5 – Least Privilege ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.5_Details|&#039;&#039;&#039;AC.L2-3.1.5&#039;&#039;&#039;]] Employ the principle of least privilege, including for specific security functions and privileged accounts.&lt;br /&gt;
|-&lt;br /&gt;
| [a] privileged accounts are identified. || Document || &amp;quot;SSP or policy (documentation) identify what is considered a privileged account.&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| [b] access to privileged accounts is authorized in accordance with the principle of least privilege. || Artifact || An artifact that identifies the least amount of permissions associated with different types of privileged accounts are approved.&lt;br /&gt;
|-&lt;br /&gt;
| [c] security functions are identified. || Document || &amp;quot;SSP or policy (documentation) identifies what is considered a security account.&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| [d] access to security functions is authorized in accordance with the principle of least privilege. || Artifact || Artifact(s) that identify the least amount of permissions associated with different types of security accounts are approved.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.6 – Non-Privileged Account Use ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.6_Details|&#039;&#039;&#039;AC.L2-3.1.6&#039;&#039;&#039;]] Use non-privileged accounts or roles when accessing nonsecurity functions.&lt;br /&gt;
|-&lt;br /&gt;
| [a] nonsecurity functions are identified. || Document || SSP or account management document, AUP, that defines non-security functions.&lt;br /&gt;
|-&lt;br /&gt;
| [b] users are required to use non-privileged accounts or roles when accessing nonsecurity functions. || Screen Share || Screenshot showing that a privileged user tried to use their admin account to access a non-security function, such as a browser or email (whatever is defined in their policy) and was blocked.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.7 – Privileged Functions ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.7_Details|&#039;&#039;&#039;AC.L2-3.1.7&#039;&#039;&#039;]] Prevent non-privileged users from executing privileged functions and capture the execution of such functions in audit logs.&lt;br /&gt;
|-&lt;br /&gt;
| [a] privileged functions are defined. || Document || SSP or policy (documentation) that defines privileged functions.&lt;br /&gt;
|-&lt;br /&gt;
| [b] non-privileged users are defined. || Document || SSP or policy (documentation) that defines non-privileged users.&lt;br /&gt;
|-&lt;br /&gt;
| [c] non-privileged users are prevented from executing privileged functions. || Screen Share || Screen share that shows that a non-privileged user is not allowed to complete a privileged function (installing software).&lt;br /&gt;
|-&lt;br /&gt;
| [d] the execution of privileged functions is captured in audit logs. || Screen Share || Screen share that shows logs being captured of the execution of privileged functions.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.8 – Unsuccessful Logon Attempts ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.8_Details|&#039;&#039;&#039;AC.L2-3.1.8&#039;&#039;&#039;]] Limit unsuccessful logon attempts.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the means of limiting unsuccessful logon attempts is defined. || Document || SSP or policy (documentation) showing unsuccessful logon attempts settings and or policy.&lt;br /&gt;
|-&lt;br /&gt;
| [b] the defined means of limiting unsuccessful logon attempts is implemented. || Artifact || Artifact showing GPO / Policy for limiting logon attempts.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.9 – Privacy &amp;amp; Security Notices ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.9_Details|&#039;&#039;&#039;AC.L2-3.1.9&#039;&#039;&#039;]] Provide privacy and security notices consistent with applicable CUI rules.&lt;br /&gt;
|-&lt;br /&gt;
| [a] privacy and security notices required by CUI-specified rules are identified, consistent, and associated with the specific CUI category. || Document || SSP or policy (documentation) showing CUI-specified rules are identified, consistent, and associated with the specific CUI category.&lt;br /&gt;
|-&lt;br /&gt;
| [b] privacy and security notices are displayed. || Artifact || Artifact that shows a consent banner or screen that a user sees as they log in to the system.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.10 – Session Lock ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.10_Details|&#039;&#039;&#039;AC.L2-3.1.10&#039;&#039;&#039;]] Use session lock with pattern-hiding displays to prevent access and viewing of data after a period of inactivity.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the period of inactivity after which the system initiates a session lock is defined. || Document || SSP or policy (documentation) that defines the period of inactivity and when a session lock is defined.&lt;br /&gt;
|-&lt;br /&gt;
| [b] access to the system and viewing of data is prevented by initiating a session lock after the defined period of inactivity. || Artifact || Artifact that shows the setting of session lock (GPO or system policy or similar solution addressing the controls supporting centralized management and configuration of operating systems, applications, and users&#039; settings for the working environment of user accounts and computer accounts).&lt;br /&gt;
|-&lt;br /&gt;
| [c] previously visible information is concealed via a pattern-hiding display after the defined period of inactivity. || Document || Screenshot of GPO setting and configuration settings, or similar solution addressing the controls supporting centralized management and configuration of operating systems, applications, and users&#039; settings for the working environment of user accounts and computer accounts.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.11 – Session Termination ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.11_Details|&#039;&#039;&#039;AC.L2-3.1.11&#039;&#039;&#039;]] Terminate (automatically) a user session after a defined condition.&lt;br /&gt;
|-&lt;br /&gt;
| [a] conditions requiring a user session to terminate are defined. || Document || SSP or policy (documentation) that defines the conditions requiring a user session to be terminated.&lt;br /&gt;
|-&lt;br /&gt;
| [b] a user session is automatically terminated after any of the defined conditions. || Screen Share || Screen share showing GPO / VPN Settings that show when a session would be terminated (Idle time, max connection time).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.12 – Control Remote Access ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.12_Details|&#039;&#039;&#039;AC.L2-3.1.12&#039;&#039;&#039;]] Monitor and control remote access sessions.&lt;br /&gt;
|-&lt;br /&gt;
| [a] remote access sessions are permitted. || Document || SSP or policy (documentation) that defines remote access sessions.&lt;br /&gt;
|-&lt;br /&gt;
| [b] the types of permitted remote access are identified. || Document || SSP or policy (documentation) that defines remote access is permitted.&lt;br /&gt;
|-&lt;br /&gt;
| [c] remote access sessions are controlled. || Screen Share || Screen share that shows how the remote access is controlled (access session, and or groups).&lt;br /&gt;
|-&lt;br /&gt;
| [d] remote access sessions are monitored. || Screen Share || Screen share that shows how remote sessions are monitored (logs).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.13 – Remote Access Confidentiality ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.13_Details|&#039;&#039;&#039;AC.L2-3.1.13&#039;&#039;&#039;]] Employ cryptographic mechanisms to protect the confidentiality of remote access sessions.&lt;br /&gt;
|-&lt;br /&gt;
| [a] cryptographic mechanisms to protect the confidentiality of remote access sessions are identified. || Document || SSP or policy (documentation) that discusses the CUI rules, consistent, and associated with the specific CUI category; FIPS Cert # of appliance or application.&lt;br /&gt;
|-&lt;br /&gt;
| [b] cryptographic mechanisms to protect the confidentiality of remote access sessions are implemented. || Screen Share || Screenshot of VPN concentration that shows encryption is on and enabled (point-to-point, etc.).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.14 – Remote Access Routing ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.14_Details|&#039;&#039;&#039;AC.L2-3.1.14&#039;&#039;&#039;]] Route remote access via managed access control points.&lt;br /&gt;
|-&lt;br /&gt;
| [a] managed access control points are identified and implemented. || Screen Share || Screen share that shows access control points (groups and/or users).&lt;br /&gt;
|-&lt;br /&gt;
| [b] remote access is routed through managed network access control points. || Screen Share || Screen share that shows access control points and how they are managed.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.15 – Privileged Remote Access ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.15_Details|&#039;&#039;&#039;AC.L2-3.1.15&#039;&#039;&#039;]] Authorize remote execution of privileged commands and remote access to security-relevant information.&lt;br /&gt;
|-&lt;br /&gt;
| [a] privileged commands authorized for remote execution are identified. || Document || SSP or policy (documentation) that defines what is authorized to be executed remotely and how that is handled.&lt;br /&gt;
|-&lt;br /&gt;
| [b] security-relevant information authorized to be accessed remotely is identified. || Document || SSP or policy (documentation) that defines what can be accessed remotely and what procedures are implemented to allow this (RDP, jump box).&lt;br /&gt;
|-&lt;br /&gt;
| [c] the execution of the identified privileged commands via remote access is authorized. || Artifact || Screen share that shows who has access to perform privileged commands a remotely (access groups for privileged accounts).&lt;br /&gt;
|-&lt;br /&gt;
| [d] access to the identified security-relevant information via remote access is authorized. || Artifact || Screen share that shows the routing of remote access and how it is monitored and how many locations (Firewall, VPN Concentrator).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.16 – Wireless Access Authorization ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.16_Details|&#039;&#039;&#039;AC.L2-3.1.16&#039;&#039;&#039;]] Authorize wireless access prior to allowing such connections.&lt;br /&gt;
|-&lt;br /&gt;
| [a] wireless access points are identified. || Document || SSP, network administration document.&lt;br /&gt;
|-&lt;br /&gt;
| [b] wireless access is authorized prior to allowing such connections. || Screen Share || Authorization profile(s) in Wireless Access Controller or Identity Manager (i.e. Cisco ISE).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.17 – Wireless Access Protection ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.17_Details|&#039;&#039;&#039;AC.L2-3.1.17&#039;&#039;&#039;]] Protect wireless access using authentication and encryption.&lt;br /&gt;
|-&lt;br /&gt;
| [a] wireless access to the system is protected using authentication. || Screen Share || Security page (or similar) of a Wireless Access Controller.&lt;br /&gt;
|-&lt;br /&gt;
| [b] wireless access to the system is protected using encryption. || Screen Share || Security page (or similar) of a Wireless Access Controller.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.18 – Mobile Device Connection ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.18_Details|&#039;&#039;&#039;AC.L2-3.1.18&#039;&#039;&#039;]] Control connection of mobile devices.&lt;br /&gt;
|-&lt;br /&gt;
| [a] mobile devices that process, store, or transmit CUI are identified. || Document || SSP, Mobile Device Policy.&lt;br /&gt;
|-&lt;br /&gt;
| [b] mobile device connections are authorized. || Artifact || Authorization profile(s) in Wireless Access Controller or Identity Manager (i.e. Cisco ISE).&lt;br /&gt;
|-&lt;br /&gt;
| [c] mobile device connections are monitored and logged. || Screen Share || Mobile device logs within the MDM, log intake (sources) configuration (within SIEM) showing MDM is feeding logs to the SIEM.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.19 – Encrypt CUI on Mobile ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.19_Details|&#039;&#039;&#039;AC.L2-3.1.19&#039;&#039;&#039;]] Encrypt CUI on mobile devices and mobile computing platforms.&lt;br /&gt;
|-&lt;br /&gt;
| [a] mobile devices and mobile computing platforms that process, store, or transmit CUI are identified. || Document || SSP, Mobile Device Policy.&lt;br /&gt;
|-&lt;br /&gt;
| [b] encryption is employed to protect CUI on identified mobile devices and mobile computing platforms. || Screen Share || Security policy page in MDM showing how encryption are enforced on mobile device. If no MDM or MDM doesn&#039;t enforce encryption, then validate if the devices used are on the list of devices with native FIPS approved validation.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.20 – External Connections [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.20_Details|&#039;&#039;&#039;AC.L2-3.1.20&#039;&#039;&#039;]] Verify and control/limit connections to and use of external information systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] connections to external systems are identified. || Document || SSP, Systems Interconnection Agreements, SLA.&lt;br /&gt;
|-&lt;br /&gt;
| [b] the use of external systems is identified. || Document || SSP, Systems Interconnection Agreements, SLA.&lt;br /&gt;
|-&lt;br /&gt;
| [c] connections to external systems are verified. || Artifact || SLA for external systems, memorandum for interconnection, information to prove that any cloud solution is at FedRAMP impact level of moderate or higher (i.e. license information, screenshot of AWS cloud dashboard, purchase order document).&lt;br /&gt;
|-&lt;br /&gt;
| [d] the use of external systems is verified. || Artifact || SLA for external systems, memorandum for interconnection, information to prove that any cloud solution is at FedRAMP impact level of moderate or higher (i.e. license information, screenshot of AWS cloud dashboard, purchase order document).&lt;br /&gt;
|-&lt;br /&gt;
| [e] connections to external systems are controlled/limited. || Screen Share || Firewall ruleset for controlling access to cloud service or external system.&lt;br /&gt;
|-&lt;br /&gt;
| [f] the use of external systems is controlled/limited. || Screen Share || Firewall ruleset for controlling access to cloud service or external system.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.21 – Portable Storage Use ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.21_Details|&#039;&#039;&#039;AC.L2-3.1.21&#039;&#039;&#039;]] Limit use of portable storage devices on external systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the use of portable storage devices containing CUI on external systems is identified and documented. || Document || SSP, Removable Media Policy, Acceptable Use Policy (with emphasis on portable media use).&lt;br /&gt;
|-&lt;br /&gt;
| [b] limits on the use of portable storage devices containing CUI on external systems are defined. || Document || SSP, Removable Media Policy, Acceptable Use Policy (with emphasis on portable media use).&lt;br /&gt;
|-&lt;br /&gt;
| [c] the use of portable storage devices containing CUI on external systems is limited as defined. || Document || SSP, Removable Media Policy, Acceptable Use Policy (with emphasis on portable media use).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.22 – Control Public Information [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.22_Details|&#039;&#039;&#039;AC.L2-3.1.22&#039;&#039;&#039;]] Control information posted or processed on publicly accessible information systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] individuals authorized to post or process information on publicly accessible systems are identified. || Document || SSP, Website Governance Plan, Information Release Document.&lt;br /&gt;
|-&lt;br /&gt;
| [b] procedures to ensure CUI is not posted or processed on publicly accessible systems are identified. || Document || SSP, Website Governance Plan, Information Release Document.&lt;br /&gt;
|-&lt;br /&gt;
| [c] a review process is in place prior to posting of any content to publicly accessible systems. || Artifact || &amp;quot;Information release approval process, i.e. chain of email communication from originator, approver, and final decision (may or may not include individual authorized to post); &lt;br /&gt;
SharePoint/electronic or paper form/ ticket system showing information flow between requestor and approver (may or may not include  individual authorized to post).&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| [d] content on publicly accessible systems is reviewed to ensure that it does not include CUI. || Artifact || Incident response process, web design/update/modification SOP etc.&lt;br /&gt;
|-&lt;br /&gt;
| [e] mechanisms are in place to remove and address improper posting of CUI. || Artifact || Incident response process, web design/update/modification SOP etc.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Awareness and Training (AT) ==&lt;br /&gt;
=== AT.L2-3.2.1 – Role-Based Risk Awareness ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AT.L2-3.2.1_Details|&#039;&#039;&#039;AT.L2-3.2.1&#039;&#039;&#039;]] Ensure that managers, systems administrators, and users of organizational systems are made aware of the security risks associated with their activities and of the applicable policies, standards, and procedures related to the security of those systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] security risks associated with organizational activities involving CUI are identified. || Document || Policy of Security Awareness Training; Security Awareness Training Briefing.&lt;br /&gt;
|-&lt;br /&gt;
| [b] policies, standards, and procedures related to the security of the system are identified. || Document || Acceptable Use Policy, Policy/Procedures/Instruction related to the security of the system.&lt;br /&gt;
|-&lt;br /&gt;
| [c] managers, systems administrators, and users of the system are made aware of the security risks associated with their activities. || Artifact || Security Training Brief, training records.&lt;br /&gt;
|-&lt;br /&gt;
| [d] managers, systems administrators, and users of the system are made aware of the applicable policies, standards, and procedures related to the security of the system. || Artifact || Policies, standards and procedures for employees within training (completed training report).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AT.L2-3.2.2 – Role-Based Training ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AT.L2-3.2.2_Details|&#039;&#039;&#039;AT.L2-3.2.2&#039;&#039;&#039;]] Ensure that personnel are trained to carry out their assigned information security-related duties and responsibilities.|-&lt;br /&gt;
|-&lt;br /&gt;
| [a] information security-related duties, roles, and responsibilities are defined. || Document || Policy/Procedures/Instruction, Job Role Matrix, Position Descriptions, User Roles.&lt;br /&gt;
|-&lt;br /&gt;
| [b] information security-related duties, roles, and responsibilities are assigned to designated personnel. || Artifact || Screenshot of breakout of different roles/permissions assigned to individuals (i.e. ActiveDirectory); Privilege Access Agreement.&lt;br /&gt;
|-&lt;br /&gt;
| [c] personnel are adequately trained to carry out their assigned information security-related duties, roles, and responsibilities. || Artifact || Screenshot of tool and/or training specifying security specific roles, duties and responsibilities; Screenshot of required certifications (i.e. Sec+, CISSP).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AT.L2-3.2.3 – Insider Threat Awareness ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AT.L2-3.2.3_Details|&#039;&#039;&#039;AT.L2-3.2.3&#039;&#039;&#039;]] Provide security awareness training on recognizing and reporting potential indicators of insider threat.&lt;br /&gt;
|-&lt;br /&gt;
| [a] potential indicators associated with insider threats are identified. || Document || Insidert Threat Policy/Procedures/Instruction; Insider Threat Training/Briefing.&lt;br /&gt;
|-&lt;br /&gt;
| [b] security awareness training on recognizing and reporting potential indicators of insider threat is provided to managers and employees. || Artifact || Screenshot of training records showing completion of Insider Threat training, emails showing completion of Insider Threat training, Screenshot of certificate showing completion with individual&#039;s name.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Audit and Accountability (AU) ==&lt;br /&gt;
=== AU.L2-3.3.1 – System Auditing ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AU.L2-3.3.1_Details|&#039;&#039;&#039;AU.L2-3.3.1&#039;&#039;&#039;]] Create and retain system audit logs and records to the extent needed to enable the monitoring, analysis, investigation, and reporting of unlawful or unauthorized system activity.&lt;br /&gt;
|-&lt;br /&gt;
| [a] audit logs needed (i.e., event types to be logged) to enable the monitoring, analysis, investigation, and reporting of unlawful or unauthorized system activity are specified. || Document || SSP, policy, or auditing and logging process that defines specific types of events to be logged.&lt;br /&gt;
|-&lt;br /&gt;
| [b] the content of audit records needed to support monitoring, analysis, investigation, and reporting of unlawful or unauthorized system activity is defined. || Document || SSP, policy, or auditing and logging process that defines specific content of audit records/files.&lt;br /&gt;
|-&lt;br /&gt;
| [c] audit records are created (generated). || Screen Share || Screen share of tool that shows logs are generated for all systems.&lt;br /&gt;
|-&lt;br /&gt;
| [d] audit records, once created, contain the defined content. || Screen Share || Screen share of tool that shows logs contain defined content as defined in SSP, policy, or procedures.&lt;br /&gt;
|-&lt;br /&gt;
| [e] retention requirements for audit records are defined. || Document || SSP, Polocy, or Auditing and logging process that describes how long records are kept.&lt;br /&gt;
|-&lt;br /&gt;
| [f] audit records are retained as defined. || Screen Share || Screen share of tool that shows records and audit content retained at a minimum as defined.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AU.L2-3.3.2 – User Accountability ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AU.L2-3.3.2_Details|&#039;&#039;&#039;AU.L2-3.3.2&#039;&#039;&#039;]] Ensure that the actions of individual system users can be uniquely traced to those users so they can be held accountable for their actions.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the content of the audit records needed to support the ability to uniquely trace users to their actions is defined. || Document || SSP, policy, or process that defines actions traced back to individuals.&lt;br /&gt;
|-&lt;br /&gt;
| [b] audit records, once created, contain the defined content. || Screen Share || Screen share of tool that shows audit records traced to specific users/roles.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AU.L2-3.3.3 – Event Review ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AU.L2-3.3.3_Details|&#039;&#039;&#039;AU.L2-3.3.3&#039;&#039;&#039;]] Review and update logged events.&lt;br /&gt;
|-&lt;br /&gt;
| [a] a process for determining when to review logged events is defined. || Document || SSP, policy, or documented process that shows frequency of when to review types of logged events.&lt;br /&gt;
|-&lt;br /&gt;
| [b] event types being logged are reviewed in accordance with the defined review process. || Artifact || Evidence through a documented method such as meeting minutes, CAB minutes, etc. of log sources and log events being logged at the defined frequency.&lt;br /&gt;
|-&lt;br /&gt;
| [c] event types being logged are updated based on the review. || Artifact || Evidence of implementation based on the results of the review of logged events/sources through a ticket, meeting minutes, or screen share of the tool that shows changes implemented (finetuning).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AU.L2-3.3.4 – Audit Failure Alerting ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AU.L2-3.3.4_Details|&#039;&#039;&#039;AU.L2-3.3.4&#039;&#039;&#039;]] Alert in the event of an audit logging process failure.&lt;br /&gt;
|-&lt;br /&gt;
| [a] personnel or roles to be alerted in the event of an audit logging process failure are identified. || Document || SSP, policy, or procedure that shows who needs to be notified in case of an audit failure.&lt;br /&gt;
|-&lt;br /&gt;
| [b] types of audit logging process failures for which alert will be generated are defined. || Document || SSP, policy, or procedure that shows what types of failure will generate notifications.&lt;br /&gt;
|-&lt;br /&gt;
| [c] identified personnel or roles are alerted in the event of an audit logging process failure. || Artifact || Artifact such as email or ticket that shows the identified personnel were alerted of any audit/logging process failure as defined.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AU.L2-3.3.5 – Audit Correlation ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AU.L2-3.3.5_Details|&#039;&#039;&#039;AU.L2-3.3.5&#039;&#039;&#039;]] Correlate audit record review, analysis, and reporting processes for investigation and response to indications of unlawful, unauthorized, suspicious, or unusual activity.&lt;br /&gt;
|-&lt;br /&gt;
| [a] audit record review, analysis, and reporting processes for investigation and response to indications of unlawful, unauthorized, suspicious, or unusual activity are defined. || Document || SSP, policy, or procedure covering audit logging, monitoring, and reporting.&lt;br /&gt;
|-&lt;br /&gt;
| [b] defined audit record review, analysis, and reporting processes are correlated. || Artifact || Artifact showing an audit event and the resultant corrective action or actions to the event; this can be a Help Desk ticket, meeting notes, or a change control board items showing the event and any corrective action taken.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AU.L2-3.3.6 – Reduction &amp;amp; Reporting ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AU.L2-3.3.6_Details|&#039;&#039;&#039;AU.L2-3.3.6&#039;&#039;&#039;]] Provide audit record reduction and report generation to support on-demand analysis and reporting.&lt;br /&gt;
|-&lt;br /&gt;
| [a] an audit record reduction capability that supports on-demand analysis is provided. || Screen Share || Screen share of the logging environment where an event can be selected and traced back to a specific device, or dashboard showing realtime event analysis.&lt;br /&gt;
|-&lt;br /&gt;
| [b] a report generation capability that supports on-demand reporting is provided. || Screen Share || Screen share showing the generation of an on demand report.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AU.L2-3.3.7 – Authoritative Time Source ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AU.L2-3.3.7_Details|&#039;&#039;&#039;AU.L2-3.3.7&#039;&#039;&#039;]] Provide a system capability that compares and synchronizes internal system clocks with an authoritative source to generate time stamps for audit records.&lt;br /&gt;
|-&lt;br /&gt;
| [a] internal system clocks are used to generate time stamps for audit records. || Screen Share || Screen share showing the NTP settings of a windows, Unix, Linux device; a screen share showing the NTP settings of network appliances.&lt;br /&gt;
|-&lt;br /&gt;
| [b] an authoritative source with which to compare and synchronize internal system clocks is specified. || Document || SSP or policy indicating that devices need to be synched to a local authoritative time device that is synched with an authoritative time service.&lt;br /&gt;
|-&lt;br /&gt;
| [c] internal system clocks used to generate time stamps for audit records are compared to and synchronized with the specified authoritative time source. || Screen Share || Screen share showing device logging appliance time is point to the appropriate authoritative time server.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AU.L2-3.3.8 – Audit Protection ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AU.L2-3.3.8_Details|&#039;&#039;&#039;AU.L2-3.3.8&#039;&#039;&#039;]] Protect audit information and audit logging tools from unauthorized access, modification, and deletion.&lt;br /&gt;
|-&lt;br /&gt;
| [a] audit information is protected from unauthorized access. || Screen Share || Screen share showing operating system permissions on the audit folders being restricted to appropriate users.&lt;br /&gt;
|-&lt;br /&gt;
| [b] audit information is protected from unauthorized modification. || Screen Share || Screen share showing operating system permissions on the audit folders being restricted to appropriate users.&lt;br /&gt;
|-&lt;br /&gt;
| [c] audit information is protected from unauthorized deletion. || Screen Share || Screen share showing operating system permissions on the audit folders being restricted to appropriate users.&lt;br /&gt;
|-&lt;br /&gt;
| [d] audit logging tools are protected from unauthorized access. || Screen Share || Artifact showing access permissions in the SIEM tool.&lt;br /&gt;
|-&lt;br /&gt;
| [e] audit logging tools are protected from unauthorized modification. || Screen Share || Artifact showing update permissions in the SIEM tool.&lt;br /&gt;
|-&lt;br /&gt;
| [f] audit logging tools are protected from unauthorized deletion. || Screen Share || Artifact showing delete permissions in the SIEM tool.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AU.L2-3.3.9 – Audit Management ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AU.L2-3.3.9_Details|&#039;&#039;&#039;AU.L2-3.3.9&#039;&#039;&#039;]] Limit management of audit logging functionality to a subset of privileged users.&lt;br /&gt;
|-&lt;br /&gt;
| [a] a subset of privileged users granted access to manage audit logging functionality is defined. || Document || SSP or policy indicating which users or groups have access to audit logs.&lt;br /&gt;
|-&lt;br /&gt;
| [b] management of audit logging functionality is limited to the defined subset of privileged users. || Screen Share || Artifact showing SIEM or OS folder permissions (this should be limited to the assigned users or groups); artifact showing an ACL setting in SIEM tool in regards to logs.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Configuration Management (CM) ==&lt;br /&gt;
=== CM.L2-3.4.1 – System Baselining ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_CM.L2-3.4.1_Details|&#039;&#039;&#039;CM.L2-3.4.1&#039;&#039;&#039;]] Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles.&lt;br /&gt;
|-&lt;br /&gt;
| [a] a baseline configuration is established. || Document || Documentation showing or explaining standard imaging process (how standard images are deployed and where  they are stored).&lt;br /&gt;
|-&lt;br /&gt;
| [b] the baseline configuration includes hardware, software, firmware, and documentation. || Artifact || Screenshot of repository of where images are maintained and information relating to hardware, software, and firmware.&lt;br /&gt;
|-&lt;br /&gt;
| [c] the baseline configuration is maintained (reviewed and updated) throughout the system development life cycle. || Artifact || Screenshot/evidence displaying management of baseline configurations (how often they are being managed as stated).&lt;br /&gt;
|-&lt;br /&gt;
| [d] a system inventory is established. || Document || Screenshot/evidence displaying inventory listing of approved products for use.&lt;br /&gt;
|-&lt;br /&gt;
| [e] the system inventory includes hardware, software, firmware, and documentation. || Artifact || Screeenshot/evidence displaying inventory listing of approved products and versions permitted for use.&lt;br /&gt;
|-&lt;br /&gt;
| [f] the inventory is maintained (reviewed and updated) throughout the system development life cycle. || Artifact || Screeenshot/evidence displaying management of baseline configurations (How often and are they being managed as stated.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== CM.L2-3.4.2 – Security Configuration Enforcement ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_CM.L2-3.4.2_Details|&#039;&#039;&#039;CM.L2-3.4.2&#039;&#039;&#039;]] Establish and enforce security configuration settings for information technology products employed in organizational systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] security configuration settings for information technology products employed in the system are established and included in the baseline configuration. || Document || Documentation explaining methodology used by organization to create secure baselines (STIGs, benchmarks).&lt;br /&gt;
|-&lt;br /&gt;
| [b] security configuration settings for information technology products employed in the system are enforced. || Artifact || Evidence of tool/s used to enforce security configurations to ensure images used are free from modification unless authorized.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== CM.L2-3.4.3 – System Change Management ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_CM.L2-3.4.3_Details|&#039;&#039;&#039;CM.L2-3.4.3&#039;&#039;&#039;]] Track, review, approve or disapprove, and log changes to organizational systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] changes to the system are tracked. || Artifact || Evidence of IT Service Management tool / process used to track system changes.&lt;br /&gt;
|-&lt;br /&gt;
| [b] changes to the system are reviewed. || Artifact || Evidence of IT Service Management tool / process used to review system changes.&lt;br /&gt;
|-&lt;br /&gt;
| [c] changes to the system are approved or disapproved. || Artifact || Evidence of IT Service Management tool / process used to approve/disapprove system changes.&lt;br /&gt;
|-&lt;br /&gt;
| [d] changes to the system are logged. || Artifact || Evidence of IT Service Management tool / process used to log system changes.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== CM.L2-3.4.4 – Security Impact Analysis ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_CM.L2-3.4.4_Details|&#039;&#039;&#039;CM.L2-3.4.4&#039;&#039;&#039;]] Analyze the security impact of changes prior to implementation.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the security impact of changes to the system is analyzed prior to implementation. || Artifact || Document explaining that security impact analysis of proposed changes to a system is conducted prior to implementation.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== CM.L2-3.4.5 – Access Restrictions for Change ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_CM.L2-3.4.5_Details|&#039;&#039;&#039;CM.L2-3.4.5&#039;&#039;&#039;]] Define, document, approve, and enforce physical and logical access restrictions associated with changes to organizational systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] physical access restrictions associated with changes to the system are defined. || Document || Document explaining the process of how physical access restrictions are defined for an individuals ability to make system changes.&lt;br /&gt;
|-&lt;br /&gt;
| [b] physical access restrictions associated with changes to the system are documented. || Document || Document explaining the process of how physical access restrictions are defined for an individuals ability to make system changes are documented; access request process.&lt;br /&gt;
|-&lt;br /&gt;
| [c] physical access restrictions associated with changes to the system are approved. || Artifact || Evidence of process of how physical access to systems are granted (i.e. physical access request sample).&lt;br /&gt;
|-&lt;br /&gt;
| [d] physical access restrictions associated with changes to the system are enforced. || Physical Review || Evidence of process of how physical access to systems are enforced (physical access system).&lt;br /&gt;
|-&lt;br /&gt;
| [e] logical access restrictions associated with changes to the system are defined. || Document || Document explaining the process of how logical access restrictions are defined for an individual&#039;s ability to make system changes.&lt;br /&gt;
|-&lt;br /&gt;
| [f] logical access restrictions associated with changes to the system are documented. || Document || Document explaining the process of how logical access restrictions are defined for an individual&#039;s ability to make system changes are documented.&lt;br /&gt;
|-&lt;br /&gt;
| [g] logical access restrictions associated with changes to the system are approved. || Artifact || Evidence of process of how logical access to systems are granted.&lt;br /&gt;
|-&lt;br /&gt;
| [h] logical access restrictions associated with changes to the system are enforced. || Artifact || Evidence of process of how logical access to systems are enforced.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== CM.L2-3.4.6 – Least Functionality ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_CM.L2-3.4.6_Details|&#039;&#039;&#039;CM.L2-3.4.6&#039;&#039;&#039;]] Employ the principle of least functionality by configuring organizational systems to provide only essential capabilities.&lt;br /&gt;
|-&lt;br /&gt;
| [a] essential system capabilities are defined based on the principle of least functionality. || Document || Documentation explaining how systems are configured to utilize the principle of least functionality for designated users.&lt;br /&gt;
|-&lt;br /&gt;
| [b] the system is configured to provide only the defined essential capabilities. || Screen Share || Evidence displaying how systems are configured to utilize the principle of least functionality for designated users; disabled service settings, accepted standards for hardening (CIS benchmarks, etc.).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== CM.L2-3.4.7 – Nonessential Functionality ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_CM.L2-3.4.7_Details|&#039;&#039;&#039;CM.L2-3.4.7&#039;&#039;&#039;]] Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services.&lt;br /&gt;
|-&lt;br /&gt;
| [a] essential programs are defined. || Document || Documented essential programs specified; build documents; software center; SSP.&lt;br /&gt;
|-&lt;br /&gt;
| [b] the use of nonessential programs is defined. || Document || Documented listing of nonessential programs (whatever is NOT specified in [a]); AUP/User Agreement may identify nonessential use/programs.&lt;br /&gt;
|-&lt;br /&gt;
| [c] the use of nonessential programs is restricted, disabled, or prevented as defined. || Screen Share || Tool used to restrict nonessential programs displays restrictions as defined (McAfee ePO settings, Carbon Black rules, etc.).&lt;br /&gt;
|-&lt;br /&gt;
| [d] essential functions are defined. || Document || Documented essential functions are specified.&lt;br /&gt;
|-&lt;br /&gt;
| [e] the use of nonessential functions is defined. || Document || Documented nonessential functions are specified.&lt;br /&gt;
|-&lt;br /&gt;
| [f] the use of nonessential functions is restricted, disabled, or prevented as defined. || Screen Share || Tool used to restrict essential/nonessential functions displays restrictions as defined.&lt;br /&gt;
|-&lt;br /&gt;
| [g] essential ports are defined. || Document || Documented essential ports are specified.&lt;br /&gt;
|-&lt;br /&gt;
| [h] the use of nonessential ports is defined. || Document || Documented nonessential ports functions are specified.&lt;br /&gt;
|-&lt;br /&gt;
| [i] the use of nonessential ports is restricted, disabled, or prevented as defined. || Screen Share || Tool used to restrict essential/nonessential ports displays restrictions as defined (FW rules; McAfee; GPO, etc.).&lt;br /&gt;
|-&lt;br /&gt;
| [j] essential protocols are defined. || Document || Documented essential protocols are specified.&lt;br /&gt;
|-&lt;br /&gt;
| [k] the use of nonessential protocols is defined. || Document || Documented nonessential protocols functions are specified.&lt;br /&gt;
|-&lt;br /&gt;
| [l] the use of nonessential protocols is restricted, disabled, or prevented as defined. || Screen Share || Tool used to restrict essential/nonessential protocols displays restrictions as defined (FW rules; GPO, etc.).&lt;br /&gt;
|-&lt;br /&gt;
| [m] essential services are defined. || Document || Documented essential services specified.&lt;br /&gt;
|-&lt;br /&gt;
| [n] the use of nonessential services is defined. || Document || Documented nonessential services functions are specified.&lt;br /&gt;
|-&lt;br /&gt;
| [o] the use of nonessential services is restricted, disabled, or prevented as defined. || Screen Share || Tool used to restrict essential/nonessential services displays restrictions as defined.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== CM.L2-3.4.8 – Application Execution Policy ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_CM.L2-3.4.8_Details|&#039;&#039;&#039;CM.L2-3.4.8&#039;&#039;&#039;]] Apply deny-by-exception (blacklisting) policy to prevent the use of unauthorized software or deny-all, permit-by-exception (whitelisting) policy to allow the execution of authorized software.&lt;br /&gt;
|-&lt;br /&gt;
| [a] a policy specifying whether whitelisting or blacklisting is to be implemented is specified. || Document || Documentation explaining whitelisting or blacklisting process.&lt;br /&gt;
|-&lt;br /&gt;
| [b] the software allowed to execute under whitelisting or denied use under blacklisting is specified. || Document || Documentation explaining whitelisting or blacklisting process for software.&lt;br /&gt;
|-&lt;br /&gt;
| [c] whitelisting to allow the execution of authorized software or blacklisting to prevent the use of unauthorized software is implemented as specified. || Screen Share || Tool used for whitelisting or blacklisting for software shows capability of restricting/authorizing software (Carbon Black dashboard, &amp;quot;SW Store&amp;quot;, web proxies, DNS Blackhole, etc.).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== CM.L2-3.4.9 – User-Installed Software ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_CM.L2-3.4.9_Details|&#039;&#039;&#039;CM.L2-3.4.9&#039;&#039;&#039;]] Control and monitor user-installed software.&lt;br /&gt;
|-&lt;br /&gt;
| [a] a policy for controlling the installation of software by users is established. || Document || Documented software authorization process or methodology for approval.&lt;br /&gt;
|-&lt;br /&gt;
| [b] installation of software by users is controlled based on the established policy. || Screen Share || Evidence that approval/restriction in installation of software by authorized personnel is implemented as specified (AUP, GPO, etc.).&lt;br /&gt;
|-&lt;br /&gt;
| [c] installation of software by users is monitored. || Screen Share || Evidence that installation of software by authorized personnel is monitored (SCCM groups, SW Center, etc.).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Identification and Authentication (IA) ==&lt;br /&gt;
=== IA.L2-3.5.1 – Identification [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IA.L2-3.5.1_Details|&#039;&#039;&#039;IA.L2-3.5.1&#039;&#039;&#039;]] Identify information system users, processes acting on behalf of users, or devices.&lt;br /&gt;
|-&lt;br /&gt;
| [a] system users are identified. || Document || Based on what is defined in their documentation (SSP, AUP, Policy, SOP), request to see a sample of non-privileged/privileged users in AD OU group (overlaps with 3.1.1 and 3.1.5).&lt;br /&gt;
|-&lt;br /&gt;
| [b] processes acting on behalf of users are identified. || Document || Based on what is defined in their documentation (SSP, AUP, Policy, SOP), request to see a sample of service accounts in AD OU group (overlaps with 3.1.1 and 3.1.5).&lt;br /&gt;
|-&lt;br /&gt;
| [c] devices accessing the system are identified. || Document || Based on what is defined in their documentation (SSP, AUP, Policy, SOP), request to see a sample of domain-joined workstation &amp;amp; servers in AD OU group (overlaps with 3.1.1 and 3.1.5).  For network devices, request screen share/artifact to show how they are identified on the enterprise network.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IA.L2-3.5.2 – Authentication [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IA.L2-3.5.2_Details|&#039;&#039;&#039;IA.L2-3.5.2&#039;&#039;&#039;]] Authenticate (or verify) the identities of those users, processes, or devices, as a prerequisite to allowing access to organizational information systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the identity of each user is authenticated or verified as a prerequisite to system access. || Screen Share || If the user logs in with non-privileged account during other demoes and then a privileged account, then this should be satisfied.  If screen share is unavailable, request logs to show successful and unsuccessful login by privileged and non-privilged users.&lt;br /&gt;
|-&lt;br /&gt;
| [b] the identity of each process acting on behalf of a user is authenticated or verified as a prerequisite to system access. || Screen Share || Request a log that shows successful/unsuccessful service account trying to log on to company&#039;s asset.&lt;br /&gt;
|-&lt;br /&gt;
| [c] the identity of each device accessing or connecting to the system is authenticated or verified as a prerequisite to system access. || Screen Share || Request a log that shows domain-joined workstation/server authenticating to AD (focus on the MAC/IP address/hostname).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IA.L2-3.5.3 – Multifactor Authentication ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IA.L2-3.5.3_Details|&#039;&#039;&#039;IA.L2-3.5.3&#039;&#039;&#039;]] Use multifactor authentication for local and network access to privileged accounts and for network access to non-privileged accounts.&lt;br /&gt;
|-&lt;br /&gt;
| [a] privileged accounts are identified. || Document || Based on what is defined in their documentation, request to see a sample of privileged users in AD OU group.  Overlaps with 3.1.5.  Screenshot/screen share to show implementation is enforced.&lt;br /&gt;
|-&lt;br /&gt;
| [b] multifactor authentication is implemented for local access to privileged accounts. || Screen Share || SSP, AUP, Policy, SOP that defines that MFA is needed for privileged local access.&lt;br /&gt;
|-&lt;br /&gt;
| [c] multifactor authentication is implemented for network access to privileged accounts. || Screen Share || Within the MFA implementation mechanism, show that privileged users are forced to use MFA;  Screenshot/Screen share to show implementation is enforced.&lt;br /&gt;
|-&lt;br /&gt;
| [d] multifactor authentication is implemented for network access to non-privileged accounts. || Screen Share || Within the MFA implementation mechanism, show that non-privileged users are forced to use MFA; Screenshot/Screen share to show implementation is enforced.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IA.L2-3.5.4 – Replay-Resistant Authentication ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IA.L2-3.5.4_Details|&#039;&#039;&#039;IA.L2-3.5.4&#039;&#039;&#039;]] Employ replay-resistant authentication mechanisms for network access to privileged and non-privileged accounts.&lt;br /&gt;
|-&lt;br /&gt;
| [a] replay-resistant authentication mechanisms are implemented for network account access to privileged and non-privileged accounts. || Screen Share || Show the GPO setting that enforces Kerberos within AD.  If MFA is used, show the implementation to enforce replay resistant techniques.  For non-windows, show the technical solution to enforce replay resistant attacks.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IA.L2-3.5.5 – Identifier Reuse ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IA.L2-3.5.5_Details|&#039;&#039;&#039;IA.L2-3.5.5&#039;&#039;&#039;]] Prevent reuse of identifiers for a defined period.&lt;br /&gt;
|-&lt;br /&gt;
| [a] a period within which identifiers cannot be reused is defined. || Document || SSP, policies, or SOP that defines identifier reuse.&lt;br /&gt;
|-&lt;br /&gt;
| [b] reuse of identifiers is prevented within the defined period. || Artifact || Show the GPO setting/technical solution that enforces what is defined in policy/documentation (this can be automated or manual process; screen share/artifacts can be presented to satisfy this requirement.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IA.L2-3.5.6 – Identifier Handling ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IA.L2-3.5.6_Details|&#039;&#039;&#039;IA.L2-3.5.6&#039;&#039;&#039;]] Disable identifiers after a defined period of inactivity.&lt;br /&gt;
|-&lt;br /&gt;
| [a] a period of inactivity after which an identifier is disabled is defined. || Document || SSP, policy that defines the period of inactivity after which an identifier is disabled.&lt;br /&gt;
|-&lt;br /&gt;
| [b] identifiers are disabled after the defined period of inactivity. || Artifact || Screen share AD or similar tool supporting directory-based identity-related services for disabled accounts (can be done by hand or script).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IA.L2-3.5.7 – Password Complexity ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IA.L2-3.5.7_Details|&#039;&#039;&#039;IA.L2-3.5.7&#039;&#039;&#039;]] Enforce a minimum password complexity and change of characters when new passwords are created.&lt;br /&gt;
|-&lt;br /&gt;
| [a] password complexity requirements are defined. || Document || SSP, policy that defines password complexity requirements.&lt;br /&gt;
|-&lt;br /&gt;
| [b] password change of character requirements are defined. || Document || SSP, policy that defines change of character requirements are defined.&lt;br /&gt;
|-&lt;br /&gt;
| [c] minimum password complexity requirements as defined are enforced when new passwords are created. || Screen Share || Screen share of AD or similar directory-based identity-related service tool to show complexity requirements.&lt;br /&gt;
|-&lt;br /&gt;
| [d] minimum password change of character requirements as defined are enforced when new passwords are created. || Screen Share || Screen share of Group Policy configuration or similar tool providing centralized management and configuration of operating systems, applications, and users&#039; settings to show that characters must be changed.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IA.L2-3.5.8 – Password Reuse ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IA.L2-3.5.8_Details|&#039;&#039;&#039;IA.L2-3.5.8&#039;&#039;&#039;]] Prohibit password reuse for a specified number of generations.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the number of generations during which a password cannot be reused is specified. || Document || SSP, policy that specifies the number of generations during which a password cannot be reused is specified.&lt;br /&gt;
|-&lt;br /&gt;
| [b] reuse of passwords is prohibited during the specified number of generations. || Screen Share || Screen share Group Policy or similar tool providing centralized management and configuration of operating systems, applications, and users&#039; settings in a directory-based identity-related service tool&#039;s configuration to show reuse of passwords is prohibited.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IA.L2-3.5.9 – Temporary Passwords ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IA.L2-3.5.9_Details|&#039;&#039;&#039;IA.L2-3.5.9&#039;&#039;&#039;]] Allow temporary password use for system logons with an immediate change to a permanent password.&lt;br /&gt;
|-&lt;br /&gt;
| [a] an immediate change to a permanent password is required when a temporary password is used for system logon. || Screen Share || Screen share of Group Policy or similar tool providing centralized management and configuration of operating systems, applications, and users&#039; settings in a directory-based identity-related service tool&#039;s configuration to show &amp;quot;change password at first logon.&amp;quot;&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IA.L2-3.5.10 – Cryptographically-Protected Passwords ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IA.L2-3.5.1_Details|&#039;&#039;&#039;IA.L2-3.5.1&#039;&#039;&#039;]] Store and transmit only cryptographically-protected passwords.&lt;br /&gt;
|-&lt;br /&gt;
| [a] passwords are cryptographically protected in storage. || Screen Share || Screen share Group Policy or similar tool providing centralized management and configuration of operating systems, applications, and users&#039; settings in a directory-based identity-related service tool&#039;s configuration that Kerberos, or a similar network authentication protocol that works on the basis of tickets to allow nodes communicating over a non-secure network to prove their identity to one another in a secure manner, is enabled.&lt;br /&gt;
|-&lt;br /&gt;
| [b] passwords are cryptographically protected in transit. || Screen Share || Screen share Group Policy or similar tool providing centralized management and configuration of operating systems, applications, and users&#039; settings in a directory-based identity-related service tool&#039;s configuration that Kerberos, or a similar network authentication protocol that works on the basis of tickets to allow nodes communicating over a non-secure network to prove their identity to one another in a secure manner, is enabled.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IA.L2-3.5.11 – Obscure Feedback ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IA.L2-3.5.10_Details|&#039;&#039;&#039;IA.L2-3.5.10&#039;&#039;&#039;]] Obscure feedback of authentication information.&lt;br /&gt;
|-&lt;br /&gt;
| [a] authentication information is obscured during the authentication process. || Screen Share || Screen share of Group Policy or similar tool providing centralized management and configuration of operating systems, applications, and users&#039; settings in a directory-based identity-related service tool&#039;s configuration to show that passwords are obscured.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Incident Response (IR) ==&lt;br /&gt;
=== IR.L2-3.6.1 – Incident Handling ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IR.L2-3.6.1_Details|&#039;&#039;&#039;IR.L2-3.6.1&#039;&#039;&#039;]] Establish an operational incident-handling capability for organizational systems that includes preparation, detection, analysis, containment, recovery, and user response activities.&lt;br /&gt;
|-&lt;br /&gt;
| [a] an operational incident-handling capability is established. || Document || Incident Response SOP/Plan.&lt;br /&gt;
|-&lt;br /&gt;
| [b] the operational incident-handling capability includes preparation. || Document || Incident Response SOP/Plan, prior incident report, training, COOP plan.&lt;br /&gt;
|-&lt;br /&gt;
| [c] the operational incident-handling capability includes detection. || Document || Incident Response SOP/Plan; definition of tools used to detect; artifacts showing tools used; prior incident report.&lt;br /&gt;
|-&lt;br /&gt;
| [d] the operational incident-handling capability includes analysis. || Document || Incident Response SOP/Plan; Definition of tools used to analyze potential incidents; artifacts showing tools used for analysis; prior incident report.&lt;br /&gt;
|-&lt;br /&gt;
| [e] the operational incident-handling capability includes containment. || Document || Incident Response SOP/Plan; isolation/quarantine process; user training.&lt;br /&gt;
|-&lt;br /&gt;
| [f] the operational incident-handling capability includes recovery. || Document || Incident Response SOP/Plan; COOP Plan; prior incident reports, re-baselining impacted devices.&lt;br /&gt;
|-&lt;br /&gt;
| [g] the operational incident-handling capability includes user response. || Document || Incident Response SOP/Plan; user awareness training; Help Desk process.&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IR.L2-3.6.2 – Incident Reporting ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IR.L2-3.6.2_Details|&#039;&#039;&#039;IR.L2-3.6.2&#039;&#039;&#039;]] Track, document, and report incidents to designated officials and/or authorities both internal and external to the organization.&lt;br /&gt;
|-&lt;br /&gt;
| [a] incidents are tracked. || Artifact || Incident Response SOP/Plan; ITSM artifact; technical implementation for incident tracking.&lt;br /&gt;
|-&lt;br /&gt;
| [b] incidents are documented. || Artifact || Incident Response SOP/Plan; ITSM artifact; technical implementation for incident tracking.&lt;br /&gt;
|-&lt;br /&gt;
| [c] authorities to whom incidents are to be reported are identified. || Document || Incident Response SOP/Plan.&lt;br /&gt;
|-&lt;br /&gt;
| [d] organizational officials to whom incidents are to be reported are identified. || Document || Incident Response SOP/Plan.&lt;br /&gt;
|-&lt;br /&gt;
| [e] identified authorities are notified of incidents. || Screen Share || Prior incident report; DIBNET login; prior email notifications.&lt;br /&gt;
|-&lt;br /&gt;
| [f] identified organizational officials are notified of incidents. || Artifact || Prior incident report; prior email notifications; tabletop exercises.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IR.L2-3.6.3 – Incident Response Testing ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IR.L2-3.6.3_Details|&#039;&#039;&#039;IR.L2-3.6.3&#039;&#039;&#039;]] Test the organizational incident response capability.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the incident response capability is tested. || Artifact || Incident response table top/scheduled or unscheduled test or penetration test.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Maintenance (MA) ==&lt;br /&gt;
=== MA.L2-3.7.1 – Perform Maintenance ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MA.L2-3.7.1_Details|&#039;&#039;&#039;MA.L2-3.7.1&#039;&#039;&#039;]] Perform maintenance on organizational systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] system maintenance is performed. || Artifact || Establish typical maintenance activities (HVAC, UPS, power distribution, generators, copier maintenance) that are performed; maintenance agreements or contracts detailing these types of activities are acceptable; interview responses should be considered.  This requirement should not be confused with 3.14.1 - report, remediate, and correct system flaws in a timely manner (patch management).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MA.L2-3.7.2 – System Maintenance Control ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MA.L2-3.7.2_Details|&#039;&#039;&#039;MA.L2-3.7.2&#039;&#039;&#039;]] Provide controls on the tools, techniques, mechanisms, and personnel used to conduct system maintenance.&lt;br /&gt;
|-&lt;br /&gt;
| [a] tools used to conduct system maintenance are controlled. || Artifact || Tools may largely depend on the assessed environment; discussion examples include network diagnostic and monitoring tools (including hardware and software); artifacts could demonstrate secured locations/areas for these tools (photos) or checkout sheets/rosters (documents) depicting responsible personnel and the dates/times of checkout.&lt;br /&gt;
|-&lt;br /&gt;
| [b] techniques used to conduct system maintenance are controlled. || Artifact || Processes for scheduling, performing, documenting, reviewing, approving, and monitoring maintenance and repairs for the information system.&lt;br /&gt;
|-&lt;br /&gt;
| [c] mechanisms used to conduct system maintenance are controlled. || Artifact || Processes for scheduling, performing, documenting, reviewing, approving, and monitoring maintenance and repairs for the information system.&lt;br /&gt;
|-&lt;br /&gt;
| [d] personnel used to conduct system maintenance are controlled. || Physical Review || Screenshot of who is authorized to conduct maintenance; maintenance personnel training program.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MA.L2-3.7.3 – Equipment Sanitization ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MA.L2-3.7.3_Details|&#039;&#039;&#039;MA.L2-3.7.3&#039;&#039;&#039;]] Ensure equipment removed for off-site maintenance is sanitized of any CUI.&lt;br /&gt;
|-&lt;br /&gt;
| [a] equipment to be removed from organizational spaces for off-site maintenance is sanitized of any CUI. || Artifact || Document or artifact; record if equipment sanitized; categories of sanitization/destruction defined; sanitization procedural document.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MA.L2-3.7.4 – Media Inspection ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MA.L2-3.7.4_Details|&#039;&#039;&#039;MA.L2-3.7.4&#039;&#039;&#039;]] Check media containing diagnostic and test programs for malicious code before the media are used in organizational systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] media containing diagnostic and test programs are checked for malicious code before being used in organizational systems that process, store, or transmit CUI. || Artifact || Screenshot of diagnostic/test program being used (such as Symantec and McAfee on access scans…).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MA.L2-3.7.5 – Nonlocal Maintenance ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MA.L2-3.7.5_Details|&#039;&#039;&#039;MA.L2-3.7.5&#039;&#039;&#039;]] Require multifactor authentication to establish nonlocal maintenance sessions via external network connections and terminate such connections when nonlocal maintenance is complete.&lt;br /&gt;
|-&lt;br /&gt;
| [a] multifactor authentication is used to establish nonlocal maintenance sessions via external network connections. || Screen Share || Describe MFA used to remote from external service to organizational systems for maintenance and screenshot of MFA (3.5.3)(points associated with admin).&lt;br /&gt;
|-&lt;br /&gt;
| [b] nonlocal maintenance sessions established via external network connections are terminated when nonlocal maintenance is complete. || Screen Share || Screenshot VPN session timeout.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MA.L2-3.7.6 – Maintenance Personnel ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MA.L2-3.7.6_Details|&#039;&#039;&#039;MA.L2-3.7.6&#039;&#039;&#039;]] Supervise the maintenance activities of maintenance personnel without required access authorization.&lt;br /&gt;
|-&lt;br /&gt;
| [a] maintenance personnel without required access authorization are supervised during maintenance activities. || Document || System maintenance policy; list of authorized personnel; maintenance records or, contracts/SLAs; WebEx.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Media Protection (MP) ==&lt;br /&gt;
=== MP.L2-3.8.1 – Media Protection ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MP.L2-3.8.1_Details|&#039;&#039;&#039;MP.L2-3.8.1&#039;&#039;&#039;]] Protect (i.e., physically control and securely store) system media containing CUI, both paper and digital.&lt;br /&gt;
|-&lt;br /&gt;
| [a] paper media containing CUI is physically controlled. || Document || Policy showing CUI paper media is controlled; artifact showing who has access; artifacts/records of  inventories conducted; media check out procedures (i.e. file cabinets, encryption, password protection).&lt;br /&gt;
|-&lt;br /&gt;
| [b] digital media containing CUI is physically controlled. || Document || Policy showing CUI digital media is controlled; artifact showing who has access; artifacts/records of inventories conducted; media check out procedures (i.e. file cabinets, external drives, USBs, encryption, password protection).&lt;br /&gt;
|-&lt;br /&gt;
| [c] paper media containing CUI is securely stored. || Physical Review || Check out/sign out sheets; possible photo of storage container/video walk through of storage area; badge reader logs or access lists for keys for secured areas; interview response considered (i.e. file cabinets,  encryption, password protection).&lt;br /&gt;
|-&lt;br /&gt;
| [d] digital media containing CUI is securely stored. || Physical Review || Check out/sign out sheets; possible photo of storage container/video walk through of storage area; badge reader logs or access lists for keys for secured areas; interview response considered (i.e. file cabinets, external drives, USBs, encryption, password protection).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MP.L2-3.8.2 – Media Access ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MP.L2-3.8.2_Details|&#039;&#039;&#039;MP.L2-3.8.2&#039;&#039;&#039;]] Limit access to CUI on system media to authorized users.&lt;br /&gt;
|-&lt;br /&gt;
| [a] access to CUI on system media is limited to authorized users. || Artifact || Document describing how CUI is limited AND artifact showing principle of least access is implemented.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MP.L2-3.8.3 – Media Disposal [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MP.L2-3.8.3_Details|&#039;&#039;&#039;MP.L2-3.8.3&#039;&#039;&#039;]] Sanitize or destroy information system media containing Federal Contract Information before disposal or release for reuse.&lt;br /&gt;
|-&lt;br /&gt;
| [a] system media containing CUI is sanitized or destroyed before disposal. || Document || Policy or artifact of media destruction logs; certificates of destruction; SLAs or contracts.&lt;br /&gt;
|-&lt;br /&gt;
| [b] system media containing CUI is sanitized before it is released for reuse. || Document || Policy or artifact describing method to sanitize, software used (i.e. DoD Wipe, ShredIT and Iron Mountain; Blancco; GDisk, DBAN).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MP.L2-3.8.4 – Media Markings ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MP.L2-3.8.4_Details|&#039;&#039;&#039;MP.L2-3.8.4&#039;&#039;&#039;]] Mark media with necessary CUI markings and distribution limitations.&lt;br /&gt;
|-&lt;br /&gt;
| [a] media containing CUI is marked with applicable CUI markings. || Physical Review || Document or artifact showing CUI markings (i.e. labeling standards ).&lt;br /&gt;
|-&lt;br /&gt;
| [b] media containing CUI is marked with distribution limitations. || Physical Review || Document or artifact showing distro limitations (i.e. labeling standards ).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MP.L2-3.8.5 – Media Accountability ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MP.L2-3.8.5_Details|&#039;&#039;&#039;MP.L2-3.8.5&#039;&#039;&#039;]] Control access to media containing CUI and maintain accountability for media during transport outside of controlled areas.&lt;br /&gt;
|-&lt;br /&gt;
| [a] access to media containing CUI is controlled. || Document || Policy, artifact of audit logs showing tracking, Access Control Lists, records of transport activities (i.e. USB drives, CDs, chain of custody.&lt;br /&gt;
|-&lt;br /&gt;
| [b] accountability for media containing CUI is maintained during transport outside of controlled areas. || Artifact || Artifact of audit logs showing tracking, Access Control Lists, records of transport activities (i.e. USB drives, CDs; chain of custody.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MP.L2-3.8.6 – Portable Storage Encryption ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MP.L2-3.8.6_Details|&#039;&#039;&#039;MP.L2-3.8.6&#039;&#039;&#039;]] Implement cryptographic mechanisms to protect the confidentiality of CUI stored on digital media during transport unless otherwise protected by alternative physical safeguards.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the confidentiality of CUI stored on digital media is protected during transport using cryptographic mechanisms or alternative physical safeguards. || Artifact || Artifact showing crypto mechanisms used to protect (are they FIPS 140-2 [13.11]); artifact showing what alternative physical safeguards are in place (i.e. encryption; BitLocker; McAfee ).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MP.L2-3.8.7 – Removable Media ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MP.L2-3.8.7_Details|&#039;&#039;&#039;MP.L2-3.8.7&#039;&#039;&#039;]] Control the use of removable media on system components.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the use of removable media on system components is controlled. || Artifact || Policy showing if removable media is allowed; writable removable media is restricted; tracking artifacts; what tools are used (i.e. Carbon Black, Crowd Strike, GPO, Zoho Desktop Central); procedure/process describing what happens if it is lost; what mechanisms are in place to control/restrict removable media (i.e. Active Directory Groups and Group Policy artifact showing restriction).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MP.L2-3.8.8 – Shared Media ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MP.L2-3.8.8_Details|&#039;&#039;&#039;MP.L2-3.8.8&#039;&#039;&#039;]] Prohibit the use of portable storage devices when such devices have no identifiable owner.ASSESSMENT OBJECTIVES&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [a] the use of portable storage devices is prohibited when such devices have no identifiable owner. || Artifact || Policy and/or artifact showing company stance on portable storage devices if there is no owner (are personal USB devices allowed or are they company-issued; artifact showing alerts if device is connected to network (i.e. external HDD, Carbon Black, Crowd Strike, GPO, Zoho Desktop Central.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MP.L2-3.8.9 – Protect Backups ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MP.L2-3.8.9_Details|&#039;&#039;&#039;MP.L2-3.8.9&#039;&#039;&#039;]] Protect the confidentiality of backup CUI at storage locations.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the confidentiality of backup CUI is protected at storage locations. || Artifact || Policy on system backups; artifact showing media labeling; artifact showing encyption (is it FIPS 140-2 [13.11]); Access Control List artifact (i.e. backup tapes, Tivoli Storage Manager).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Personnel Security (PS) ==&lt;br /&gt;
=== PS.L2-3.9.1 – Screen Individuals ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_PS.L2-3.9.1_Details|&#039;&#039;&#039;PS.L2-3.9.1&#039;&#039;&#039;]] Screen individuals prior to authorizing access to organizational systems containing CUI.&lt;br /&gt;
|-&lt;br /&gt;
| [a] individuals are screened prior to authorizing access to organizational systems containing CUI. || Artifact || Screenshot of records of screened personnel/background checks.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== PS.L2-3.9.2 – Personnel Actions ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_PS.L2-3.9.2_Details|&#039;&#039;&#039;PS.L2-3.9.2&#039;&#039;&#039;]] Ensure that organizational systems containing CUI are protected during and after personnel actions such as terminations and transfers.&lt;br /&gt;
|-&lt;br /&gt;
| [a] a policy and/or process for terminating system access and any credentials coincident with personnel actions is established. || Document || Personnel security policy/procedures/instruction; Access control policy/procedure/instruction.&lt;br /&gt;
|-&lt;br /&gt;
| [b] system access and credentials are terminated consistent with personnel actions such as termination or transfer. || Artifact || Screenshot of records of personnel transfer and termination actions.&lt;br /&gt;
|-&lt;br /&gt;
| [c] the system is protected during and after personnel transfer actions. || Artifact || Completed outprocessing checklist.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Physical Protection (PE) ==&lt;br /&gt;
=== PE.L2-3.10.1 – Limit Physical Access [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_PE.L2-3.10.1_Details|&#039;&#039;&#039;PE.L2-3.10.1&#039;&#039;&#039;]] Limit physical access to organizational information systems, equipment, and the respective operating environments to authorized individuals.&lt;br /&gt;
|-&lt;br /&gt;
| [a] authorized individuals allowed physical access are identified. || Artifact || Authorized personnel (names) access list.&lt;br /&gt;
|-&lt;br /&gt;
| [b] physical access to organizational systems is limited to authorized individuals. || Physical Review || Badge reader logs, audit logs, and/or card swipe test.&lt;br /&gt;
|-&lt;br /&gt;
| [c] physical access to equipment is limited to authorized individuals. || Physical Review || Badge reader logs, audit logs, and/or card swipe test.&lt;br /&gt;
|-&lt;br /&gt;
| [d] physical access to operating environments is limited to authorized. || Physical Review || Badge reader logs, audit logs, and/or card swipe test.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== PE.L2-3.10.2 – Monitor Facility ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_PE.L2-3.10.2_Details|&#039;&#039;&#039;PE.L2-3.10.2&#039;&#039;&#039;]] Protect and monitor the physical facility and support infrastructure for organizational systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the physical facility where organizational systems reside is protected. || Physical Review || Physical security measures and barriers into the physical facility (cameras/locks/gates/guards, etc.).&lt;br /&gt;
|-&lt;br /&gt;
| [b] the support infrastructure for organizational systems is protected. || Physical Review || Physical barriers to entries into computer spaces, server rooms, etc.&lt;br /&gt;
|-&lt;br /&gt;
| [c] the physical facility where organizational systems reside is monitored. || Physical Review || Audit logs/how the physical facility is being monitored (cameras/access system/guards, etc.).&lt;br /&gt;
|-&lt;br /&gt;
| [d] the support infrastructure for organizational systems is monitored. || Physical Review || Audit logs/how the physical facility is being monitored (cameras/access system/guards, etc.).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== PE.L2-3.10.3 – Escort Visitors [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_PE.L2-3.10.3_Details|&#039;&#039;&#039;PE.L2-3.10.3&#039;&#039;&#039;]] Escort visitors and monitor visitor activity.&lt;br /&gt;
|-&lt;br /&gt;
| [a] visitors are escorted. || Physical Review || Policy/procedures/instruction on methodology for handling non-authorized personnel (entry to exit).&lt;br /&gt;
|-&lt;br /&gt;
| [b] visitor activity is monitored. || Physical Review || Policy/procedures/instructio on methodology for handling non-authorized personnel (entry to exit).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== PE.L2-3.10.4 – Physical Access Logs [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_PE.L2-3.10.4_Details|&#039;&#039;&#039;PE.L2-3.10.4&#039;&#039;&#039;]] Maintain audit logs of physical access.&lt;br /&gt;
|-&lt;br /&gt;
| [a] audit logs of physical access are maintained. || Artifact || Log or report from badging system.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== PE.L2-3.10.5 – Manage Physical Access [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_PE.L2-3.10.5_Details|&#039;&#039;&#039;PE.L2-3.10.5&#039;&#039;&#039;]] Control and manage physical access devices.&lt;br /&gt;
|-&lt;br /&gt;
| [a] physical access devices are identified. || Document || Physical access control systems description, guard force contract/policy, key locks, logical systems specifications, etc.&lt;br /&gt;
|-&lt;br /&gt;
| [b] physical access devices are controlled. || Physical Review || Inventory records of physical access control devices (e.g. keys, locks, card readers, locks, etc.).&lt;br /&gt;
|-&lt;br /&gt;
| [c] physical access devices are managed. || Physical Review || List of security safeguards controlling access to the facility (e.g. cameras, monitoring by guards, isolation of IT systems equiment and or system components).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== PE.L2-3.10.6 – Alternative Work Sites ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_PE.L2-3.10.6_Details|&#039;&#039;&#039;PE.L2-3.10.6&#039;&#039;&#039;]] Enforce safeguarding measures for CUI at alternate work sites.&lt;br /&gt;
|-&lt;br /&gt;
| [a] safeguarding measures for CUI are defined for alternate work sites. || Document || Telework agreement, Acceptable Use Policy and SOP for alternate work locations; user security training validation which includes physical/logical/technical protections of system at alternate work sites.&lt;br /&gt;
|-&lt;br /&gt;
| [b] safeguarding measures for CUI are enforced for alternate work sites. || Artifact || Monitoring/audit log of user activity and logical/physical/technical mechanisms in place to preclude unauthorized activity (telework agreement , AUP?).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Risk Assessment (RA) ==&lt;br /&gt;
=== RA.L2-3.11.1 – Risk Assessments ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_RA.L2-3.11.1_Details|&#039;&#039;&#039;RA.L2-3.11.1&#039;&#039;&#039;]] Periodically assess the risk to organizational operations (including mission, functions, image, or reputation), organizational assets, and individuals, resulting from the operation of organizational systems and the associated processing, storage, or transmission of CUI.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the frequency to assess risk to organizational operations, organizational assets, and individuals is defined. || Document || Risk assessment policy.&lt;br /&gt;
|-&lt;br /&gt;
| [b] risk to organizational operations, organizational assets, and individuals resulting from the operation of an organizational system that processes, stores, or transmits CUI is assessed with the defined frequency. || Artifact || Copy of last risk assessment done within defined frequency.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== RA.L2-3.11.2 – Vulnerability Scan ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_RA.L2-3.11.2_Details|&#039;&#039;&#039;RA.L2-3.11.2&#039;&#039;&#039;]] Scan for vulnerabilities in organizational systems and applications periodically and when new vulnerabilities affecting those systems and applications are identified.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the frequency to scan for vulnerabilities in organizational systems and applications is defined. || Document || Policy/procedures/instruction addressing vulnerability scanning records.&lt;br /&gt;
|-&lt;br /&gt;
| [b] vulnerability scans are performed on organizational systems with the defined frequency. || Screen Share || System configuration settings of vulnerability scanning scheduling and vulnerability scan results of systems within defined frequency.&lt;br /&gt;
|-&lt;br /&gt;
| [c] vulnerability scans are performed on applications with the defined frequency. || Screen Share || System configuration settings of vulnerability scanning scheduling and vulnerability scan results of applications within defined frequency.&lt;br /&gt;
|-&lt;br /&gt;
| [d] vulnerability scans are performed on organizational systems when new vulnerabilities are identified. || Screen Share || View signatures in scanning tool/ad hoc scan performed as a result.&lt;br /&gt;
|-&lt;br /&gt;
| [e] vulnerability scans are performed on applications when new vulnerabilities are identified. || Screen Share || View signatures in scanning tool/ad hoc scan performed as a result.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== RA.L2-3.11.3 – Vulnerability Remediation ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_RA.L2-3.11.3_Details|&#039;&#039;&#039;RA.L2-3.11.3&#039;&#039;&#039;]] Remediate vulnerabilities in accordance with risk assessments.&lt;br /&gt;
|-&lt;br /&gt;
| [a] vulnerabilities are identified. || Artifact || Scan results showing vulnerabilities identified.&lt;br /&gt;
|-&lt;br /&gt;
| [b] vulnerabilities are remediated in accordance with risk assessments. || Artifact || Screenshot/document of scan results of remediated vulnerabilities in accordance to risk assessments.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Security Assessment (CA) ==&lt;br /&gt;
=== CA.L2-3.12.1 – Security Control Assessment ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_CA.L2-3.12.1_Details|&#039;&#039;&#039;CA.L2-3.12.1&#039;&#039;&#039;]] Periodically assess the security controls in organizational systems to determine if the controls are effective in their application.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the frequency of security control assessments is defined. || Document || SSP.&lt;br /&gt;
|-&lt;br /&gt;
| [b] security controls are assessed with the defined frequency to determine if the controls are effective in their application. || Artifact || Copy of last security control assessment done within defined frequency.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== CA.L2-3.12.2 – Operational Plan of Action ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_CA.L2-3.12.2_Details|&#039;&#039;&#039;CA.L2-3.12.2&#039;&#039;&#039;]] Develop and implement plans of action designed to correct deficiencies and reduce or eliminate vulnerabilities in organizational systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] deficiencies and vulnerabilities to be addressed by the plan of action are identified. || Artifact || Plan of Action (POA).&lt;br /&gt;
|-&lt;br /&gt;
| [b] a plan of action is developed to correct identified deficiencies and reduce or eliminate identified vulnerabilities. || Artifact || Plan of Action (POA).&lt;br /&gt;
|-&lt;br /&gt;
| [c] the plan of action is implemented to correct identified deficiencies and reduce or eliminate identified vulnerabilities. || Artifact || Plan of Action (POA)/previously completed POAs.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== CA.L2-3.12.3 – Security Control Monitoring ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_CA.L2-3.12.3_Details|&#039;&#039;&#039;CA.L2-3.12.3&#039;&#039;&#039;]] Monitor security controls on an ongoing basis to ensure the continued effectiveness of the controls.&lt;br /&gt;
|-&lt;br /&gt;
| [a] security controls are monitored on an ongoing basis to ensure the continued effectiveness of those controls. || Artifact || Collection of risk assessment results, internal or third-party audits/security assessments and/or continuous monitoring reports/alerts (SIEM tool, etc.).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== CA.L2-3.12.4 – System Security Plan ====&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_CA.L2-3.12.4_Details|&#039;&#039;&#039;CA.L2-3.12.4&#039;&#039;&#039;]] Develop, document, and periodically update system security plans that describe system boundaries, system environments of operation, how security requirements are implemented, and the relationships with or connections to other systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] a system security plan is developed. || Document || SSP.&lt;br /&gt;
|-&lt;br /&gt;
| [b] the system boundary is described and documented in the system security plan. || Document || SSP and any supporting documentation.&lt;br /&gt;
|-&lt;br /&gt;
| [c] the system environment of operation is described and documented in the system security plan. || Document || SSP and any supporting documentation.&lt;br /&gt;
|-&lt;br /&gt;
| [d] the security requirements identified and approved by the designated authority as non-applicable are identified. || Document || SSP and required adjudication from DoD CIO.&lt;br /&gt;
|-&lt;br /&gt;
| [e] the method of security requirement implementation is described and documented in the system security plan. || Document || SSP and any supporting documentation.&lt;br /&gt;
|-&lt;br /&gt;
| [f] the relationship with or connection to other systems is described and documented in the system security plan. || Document || SSP and any supporting documentation.&lt;br /&gt;
|-&lt;br /&gt;
| [g] the frequency to update the system security plan is defined. || Document || SSP.&lt;br /&gt;
|-&lt;br /&gt;
| [h] system security plan is updated with the defined frequency. || Document || SSP/any previous versions.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== System and Communications Protection (SC) ==&lt;br /&gt;
=== SC.L2-3.13.1 – Boundary Protection [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.1_Details|&#039;&#039;&#039;SC.L2-3.13.1&#039;&#039;&#039;]] Monitor, control, and protect organizational communications (i.e., information transmitted or received by organizational information systems) at the external boundaries and key internal boundaries of the information systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the external system boundary is defined. || Document || SSP, network diagrams, CUI flow, cloud provider FedRAMP Moderate.&lt;br /&gt;
|-&lt;br /&gt;
| [b] key internal system boundaries are defined. || Document || SSP, network diagrams, CUI flow.&lt;br /&gt;
|-&lt;br /&gt;
| [c] communications are monitored at the external system boundary. || Screen Share || SSP, logging server, boundary device configurations, monitoring policy.&lt;br /&gt;
|-&lt;br /&gt;
| [d] communications are monitored at key internal boundaries. || Screen Share || SSP, logging server, boundary device configurations, monitoring policy.&lt;br /&gt;
|-&lt;br /&gt;
| [e] communications are controlled at the external system boundary. || Screen Share || SSP, boundary device configurations, ACL, subnets, DMZ.&lt;br /&gt;
|-&lt;br /&gt;
| [f] communications are controlled at key internal boundaries. || Screen Share || SSP, boundary device configurations, ACL, subnets.&lt;br /&gt;
|-&lt;br /&gt;
| [g] communications are protected at the external system boundary. || Screen Share || Configurations for IPS/IDS, email gateway, VLAN, proxy, firewall, malware protection, DNS, TSL.&lt;br /&gt;
|-&lt;br /&gt;
| [h] communications are protected at key internal boundaries. || Screen Share || Configurations for IPS/IDS, VLAN, firewall, malware protection, SSL.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.2 – Security Engineering ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.2_Details|&#039;&#039;&#039;SC.L2-3.13.2&#039;&#039;&#039;]] Employ architectural designs, software development techniques, and systems engineering principles that promote effective information security within organizational systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] architectural designs that promote effective information security are identified. || Document || SSP, config management policy, network diagram, CCB minutes, enterprise architecture process.&lt;br /&gt;
|-&lt;br /&gt;
| [b] software development techniques that promote effective information security are identified. || Document || SSP, config management policy, SDLC, CCB minutes.&lt;br /&gt;
|-&lt;br /&gt;
| [c] systems engineering principles that promote effective information security are identified. || Document || SSP, config management policy, CCB minutes, security architecture engineering.&lt;br /&gt;
|-&lt;br /&gt;
| [d] identified architectural designs that promote effective information security are employed. || Artifact || CCB minutes, Network diagrams and configurations, Project Plans.&lt;br /&gt;
|-&lt;br /&gt;
| [e] identified software development techniques that promote effective information security are employed. || Artifact || CCB minutes, SDLC, code scanner results, code management tracking.&lt;br /&gt;
|-&lt;br /&gt;
| [f] identified systems engineering principles that promote effective information security are employed. || Artifact || CCB minutes, configuration management, ITSM, patch management, lifecycle replacement processes.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.3 – Role Separation ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.3_Details|&#039;&#039;&#039;SC.L2-3.13.3&#039;&#039;&#039;]] Separate user functionality from system management functionality.&lt;br /&gt;
|-&lt;br /&gt;
| [a] user functionality is identified. || Document || SSP, AUP.&lt;br /&gt;
|-&lt;br /&gt;
| [b] system management functionality is identified. || Document || SSP, Privileged Account Agreement.&lt;br /&gt;
|-&lt;br /&gt;
| [c] user functionality is separated from system management functionality. || Screen Share || Active Directory, Jump Boxes, GPO, VM, RDP.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.4 – Shared Resource Control ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.4_Details|&#039;&#039;&#039;SC.L2-3.13.4&#039;&#039;&#039;]] Prevent unauthorized and unintended information transfer via shared system resources.&lt;br /&gt;
|-&lt;br /&gt;
| [a] unauthorized and unintended information transfer via shared system resources is prevented. || Screen Share || SSP, OS configurations, Linux containers, system/media reuse policies, certificate management policies, media destruction policies, printer configs, VDI configuration.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
===  SC.L2-3.13.5 – Public-Access System Separation [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.5_Details|&#039;&#039;&#039;SC.L2-3.13.5&#039;&#039;&#039;]] Implement subnetworks for publicly accessible system components that are physically or logically separated from internal networks.&lt;br /&gt;
|-&lt;br /&gt;
| [a] publicly accessible system components are identified. || Document || SSP, network diagram, DMZ inventory/roles.&lt;br /&gt;
|-&lt;br /&gt;
| [b] subnetworks for publicly accessible system components are physically or logically separated from internal networks. || Artifact || Network diagram, IPAM, VLAN, DHCP, DMZ.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.6 – Network Communication by Exception ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.6_Details|&#039;&#039;&#039;SC.L2-3.13.6&#039;&#039;&#039;]] Deny network communications traffic by default and allow network communications traffic by exception (i.e., deny all, permit by exception).&lt;br /&gt;
|-&lt;br /&gt;
| [a] network communications traffic is denied by default. || Screen Share || Host and network firewall rules, SIEM logs, hit counts.&lt;br /&gt;
|-&lt;br /&gt;
| [b] network communications traffic is allowed by exception. || Screen Share || Host and network firewall rules, SIEM logs, hit counts.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.7 – Split Tunneling ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.7_Details|&#039;&#039;&#039;SC.L2-3.13.7&#039;&#039;&#039;]] Prevent remote devices from simultaneously establishing non-remote connections with organizational systems and communicating via some other connection to resources in external networks (i.e., split tunneling).&lt;br /&gt;
|-&lt;br /&gt;
| [a] remote devices are prevented from simultaneously establishing non-remote connections with the system and communicating via some other connection to resources in external networks (i.e., split tunneling). || Screen Share || VPN appliance/server configuration, endpoint VPN software configuration.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.8 – Data in Transit ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.8_Details|&#039;&#039;&#039;SC.L2-3.13.8&#039;&#039;&#039;]] Implement cryptographic mechanisms to prevent unauthorized disclosure of CUI during transmission unless otherwise protected by alternative physical safeguards.&lt;br /&gt;
|-&lt;br /&gt;
| [a] cryptographic mechanisms intended to prevent unauthorized disclosure of CUI are identified. || Document || SSP, PKI policies, configuration processes, config management, email attachment encryption policy, removable media policy, data at rest policy.&lt;br /&gt;
|-&lt;br /&gt;
| [b] alternative physical safeguards intended to prevent unauthorized disclosure of CUI are identified. || Document || SSP, physical security policy.&lt;br /&gt;
|-&lt;br /&gt;
| [c] either cryptographic mechanisms or alternative physical safeguards are implemented to prevent unauthorized disclosure of CUI during transmission. || Artifact || TLS settings, SSL settings, VPN/Wireless Access Points/Mobile Devices cryptographic settings, ODBC connector settings, SAN configuration, IPSec/MPLS, backup configuration, physical security.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.9 – Connections Termination ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.9_Details|&#039;&#039;&#039;SC.L2-3.13.9&#039;&#039;&#039;]] Terminate network connections associated with communications sessions at the end of the sessions or after a defined period of inactivity.&lt;br /&gt;
|-&lt;br /&gt;
| [a] a period of inactivity to terminate network connections associated with communications sessions is defined. || Document || SSP, network communications policy.&lt;br /&gt;
|-&lt;br /&gt;
| [b] network connections associated with communications sessions are terminated at the end of the sessions. || Screen Share || VPN appliance/server logs, VPN configurations, web server configurations, firewall connection settings.&lt;br /&gt;
|-&lt;br /&gt;
| [c] network connections associated with communications sessions are terminated after the defined period of inactivity. || Artifact || VPN appliance/server logs, VPN configurations, web server configurations, frewall connection settings.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.10 – Key Management ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.10_Details|&#039;&#039;&#039;SC.L2-3.13.10&#039;&#039;&#039;]] Establish and manage cryptographic keys for cryptography employed in organizational systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] cryptographic keys are established whenever cryptography is employed. || Artifact || SSP, PKI/certificate management policy, configuration management.&lt;br /&gt;
|-&lt;br /&gt;
| [b] cryptographic keys are managed whenever cryptography is employed. || Artifact || SSP, PKI/certificate management policy, configuration management, access control policy.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.11 – CUI Encryption ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.11_Details|&#039;&#039;&#039;SC.L2-3.13.11&#039;&#039;&#039;]] Employ FIPS-validated cryptography when used to protect the confidentiality of CUI.&lt;br /&gt;
|-&lt;br /&gt;
| [a] FIPS-validated cryptography is employed to protect the confidentiality of CUI. || Screen Share || VPN, wireless, mobile devices, client certificates, server certificates, disk encryption, Outlook plugin, external mail, backup media, ePO server, removable storage, SAN, file compression; look for FIPS mode enabled on appliances.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.12 – Collaborative Device Control ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.12_Details|&#039;&#039;&#039;SC.L2-3.13.12&#039;&#039;&#039;]] Prohibit remote activation of collaborative computing devices and provide indication of devices in use to users present at the device.&lt;br /&gt;
|-&lt;br /&gt;
| [a] collaborative computing devices are identified. || Document || SSP, network diagrams.&lt;br /&gt;
|-&lt;br /&gt;
| [b] collaborative computing devices provide indication to users of devices in use. || Physical Review || Physical inspection of device.&lt;br /&gt;
|-&lt;br /&gt;
| [c] remote activation of collaborative computing devices is prohibited. || Screen Share || Collaboration device configuration/console.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.13 – Mobile Code ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.13_Details|&#039;&#039;&#039;SC.L2-3.13.13&#039;&#039;&#039;]] Control and monitor the use of mobile code.&lt;br /&gt;
|-&lt;br /&gt;
| [a] use of mobile code is controlled. || Screen Share || GPO settings, malware protection, software agent configurations, software development policies, code scanners, MDM configuration, firewall/secure web gateway/proxy config.&lt;br /&gt;
|-&lt;br /&gt;
| [b] use of mobile code is monitored. || Screen Share || SIEM/console monitoring.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.14 – Voice over Internet Protocol ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.14_Details|&#039;&#039;&#039;SC.L2-3.13.14&#039;&#039;&#039;]] Control and monitor the use of Voice over Internet Protocol (VoIP) technologies.&lt;br /&gt;
|-&lt;br /&gt;
| [a] use of Voice over Internet Protocol (VoIP) technologies is controlled. || Artifact || VLAN, ACL, firewall config, VoIP gateway/condenser configuration.&lt;br /&gt;
|-&lt;br /&gt;
| [b] use of Voice over Internet Protocol (VoIP) technologies is monitored. || Artifact || SIEM/VoIP console monitoring, session border controller.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.15 – Communications Authenticity ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.15_Details|&#039;&#039;&#039;SC.L2-3.13.15&#039;&#039;&#039;]] Protect the authenticity of communications sessions.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the authenticity of communications sessions is protected. || Screen Share || SSL, TLS, SMB3, SFTP, IPSec, SSH, Kerberos configs, MPLS, Network Access Control.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.16 – Data at Rest ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.16_Details|&#039;&#039;&#039;SC.L2-3.13.16&#039;&#039;&#039;]] Protect the confidentiality of CUI at rest.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the confidentiality of CUI at rest is protected. || Artifact || Full disk encryption, removable media encryption, SAN encryption, digital backups, mobile device encryption, third party offsite backup storage, cloud virtualization encryption, physical media storage policies.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== System and Information Integrity (SI) ==&lt;br /&gt;
=== SI.L2-3.14.1 – Flaw Remediation [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SI.L2-3.14.1_Details|&#039;&#039;&#039;SI.L2-3.14.1&#039;&#039;&#039;]] Identify, report, and correct information and information system flaws in a timely manner.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the time within which to identify system flaws is specified. || Document || SSP, patch management policy.&lt;br /&gt;
|-&lt;br /&gt;
| [b] system flaws are identified within the specified time frame. || Screen Share || Vulnerability management scanner output and scan policy configuration.&lt;br /&gt;
|-&lt;br /&gt;
| [c] the time within which to report system flaws is specified. || Document || SSP, patch management policy.&lt;br /&gt;
|-&lt;br /&gt;
| [d] system flaws are reported within the specified time frame. || Screen Share || ITSM/trouble tickets, vulnerability management scanner output.&lt;br /&gt;
|-&lt;br /&gt;
| [e] the time within which to correct system flaws is specified. || Document || SSP, patch management policy.&lt;br /&gt;
|-&lt;br /&gt;
| [f] system flaws are corrected within the specified time frame. || Screen Share || Vulnerability management scanner output and scan policy configuration.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SI.L2-3.14.2 – Malicious Code ProTection [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SI.L2-3.14.2_Details|&#039;&#039;&#039;SI.L2-3.14.2&#039;&#039;&#039;]] Provide protection from malicious code at appropriate locations within organizational information systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] designated locations for malicious code protection are identified. || Document || SSP, system protection policy, network diagrams, security architecture documents.&lt;br /&gt;
|-&lt;br /&gt;
| [b] protection from malicious code at designated locations is provided. || Screen Share || Endpoint security settings, email/web proxy gateways, firewall, IPS sensor, MDM configuration, Network Access Control.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SI.L2-3.14.3 – Security Alerts &amp;amp; Advisories ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SI.L2-3.14.3_Details|&#039;&#039;&#039;SI.L2-3.14.3&#039;&#039;&#039;]] Monitor system security alerts and advisories and take action in response.&lt;br /&gt;
|-&lt;br /&gt;
| [a] response actions to system security alerts and advisories are identified. || Document || SSP, vulnerability management policy, Incident Response Plan.&lt;br /&gt;
|-&lt;br /&gt;
| [b] system security alerts and advisories are monitored. || Artifact || Threat intelligence subscriptions, email advisories.&lt;br /&gt;
|-&lt;br /&gt;
| [c] actions in response to system security alerts and advisories are taken. || Artifact || ITSM/trouble tickets, user notifications, updates to firewall/IPS, etc.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SI.L2-3.14.4 – Update Malicious Code Protection [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SI.L2-3.14.4_Details|&#039;&#039;&#039;SI.L2-3.14.4&#039;&#039;&#039;]] Update malicious code protection mechanisms when new releases are available.&lt;br /&gt;
|-&lt;br /&gt;
| [a] malicious code protection mechanisms are updated when new releases are available. || Screen Share || Antivirus console dashboard, firewall AV, Email gateway signatures,proxy, IPS updates.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SI.L2-3.14.5 – System &amp;amp; File Scanning [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SI.L2-3.14.5_Details|&#039;&#039;&#039;SI.L2-3.14.5&#039;&#039;&#039;]] Perform periodic scans of the information system and real-time scans of files from external sources as files are downloaded, opened, or executed.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the frequency for malicious code scans is defined. || Document || SSP, vulnerability management policy.&lt;br /&gt;
|-&lt;br /&gt;
| [b] malicious code scans are performed with the defined frequency. || Screen Share || Consoles for AV (endpoints, servers, and file shares), firewall, email gateway, proxy, IPS, MDM configurations.&lt;br /&gt;
|-&lt;br /&gt;
| [c] real-time malicious code scans of files from external sources as files are downloaded, opened, or executed are performed. || Screen Share || Consoles for AV (endpoints, servers, and file shares), firewall, email gateway, proxy, IPS, MDM configurations.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SI.L2-3.14.6 – Monitor Communications for Attacks ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SI.L2-3.14.6_Details|&#039;&#039;&#039;SI.L2-3.14.6&#039;&#039;&#039;]] Monitor organizational systems, including inbound and outbound communications traffic, to detect attacks and indicators of potential attacks.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the system is monitored to detect attacks and indicators of potential attacks. || Screen Share || Firewall, IPS, endpoint protection, SIEM alerts and reports.&lt;br /&gt;
|-&lt;br /&gt;
| [b] inbound communications traffic is monitored to detect attacks and indicators of potential attacks. || Screen Share || Firewall, IPS, endpoint protection, SIEM alerts and reports.&lt;br /&gt;
|-&lt;br /&gt;
| [c] outbound communications traffic is monitored to detect attacks and indicators of potential attacks. || Screen Share || Firewall, IPS, endpoint protection, SIEM alerts and reports.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SI.L2-3.14.7 – Identify Unauthorized Use ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SI.L2-3.14.7_Details|&#039;&#039;&#039;SI.L2-3.14.7&#039;&#039;&#039;]] Identify unauthorized use of organizational systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] authorized use of the system is defined. || Document || AUP, SSP.&lt;br /&gt;
|-&lt;br /&gt;
| [b] unauthorized use of the system is identified. || Artifact || SIEM logs, endpoint protection console, IPS, Firewall.&lt;br /&gt;
|}&lt;/div&gt;</summary>
		<author><name>David</name></author>
	</entry>
	<entry>
		<id>https://cmmcwiki.org/index.php?title=Evidence_Collection_Approach&amp;diff=1625</id>
		<title>Evidence Collection Approach</title>
		<link rel="alternate" type="text/html" href="https://cmmcwiki.org/index.php?title=Evidence_Collection_Approach&amp;diff=1625"/>
		<updated>2026-07-20T01:48:42Z</updated>

		<summary type="html">&lt;p&gt;David: /* SC.L2-3.13.9 – Connections Termination */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;CMMC assessments and certification require substantial evidence and documentation. The following tables outline general guidelines for collecting evidence to assess control requirements and objectives. While these guidelines provide a structured approach, they are not the only means of conducting an accurate assessment. Assessors should exercise professional judgment and may employ alternative methods appropriate to the specific organizational context and circumstances.&lt;br /&gt;
&lt;br /&gt;
Evidence collection approaches are defined as:&lt;br /&gt;
* &#039;&#039;&#039;Documentation&#039;&#039;&#039;: Tangible materials containing information over which an organization has authority, including all types of written records and their copies.&lt;br /&gt;
* &#039;&#039;&#039;Artifacts&#039;&#039;&#039;: Tangible, reviewable records directly resulting from a practice or process being performed by a system or by personnel executing their role within that practice, control, or process.&lt;br /&gt;
* &#039;&#039;&#039;Physical Review&#039;&#039;&#039;: Direct on-site observation and examination of evidence.&lt;br /&gt;
* &#039;&#039;&#039;Screen Share&#039;&#039;&#039;: Real-time remote observation of a user demonstrating a task or process via shared computer screen, sometimes called &amp;quot;over-the-shoulder&amp;quot; review.&lt;br /&gt;
&lt;br /&gt;
DISCLAIMER: Evidence requirements vary significantly across assessment types. &#039;&#039;&#039;The examples provided are illustrative only and should be tailored to meet the specific adequacy and sufficiency standards of your particular assessment context.&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
For inquiries and reporting errors on this wiki, please [mailto:support@cmmctoolkit.org contact us]. Thank you.&lt;br /&gt;
&lt;br /&gt;
== Access Control (AC) ==&lt;br /&gt;
=== AC.L2-3.1.1 – Authorized Access Control [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.1_Details|&#039;&#039;&#039;AC.L2-3.1.1&#039;&#039;&#039;]] Limit information system access to authorized users, processes acting on behalf of authorized users, or devices (including other information systems).&lt;br /&gt;
|-&lt;br /&gt;
| [a] authorized users are identified. || Document || Document defining account request, approval, provisioning.&lt;br /&gt;
|-&lt;br /&gt;
| [b] processes acting on behalf of authorized users are identified. || Document || Document defining account request, approval, provisioning.&lt;br /&gt;
|-&lt;br /&gt;
| [c] devices (and other systems) authorized to connect to the system are identified. || Document || Document defining account request, approval, provisioning.&lt;br /&gt;
|-&lt;br /&gt;
| [d] system access is limited to authorized users. || Screen Share || Screen share showing login requirements are enforced. Example of an unauthorized user denied (unauthorized username entered at login).&lt;br /&gt;
|-&lt;br /&gt;
| [e] system access is limited to processes acting on behalf of authorized users. || Screen Share || Screenshot showing that service accounts are assigned to authorized users only; no rogue accounts without an authorized user are active.&lt;br /&gt;
|-&lt;br /&gt;
| [f] system access is limited to authorized devices (including other systems). || Screen Share || Screen share showing that all devices running are authorized; no rogue devices on the network.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.2 – Transaction &amp;amp; Function Control [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.2_Details|&#039;&#039;&#039;AC.L2-3.1.2&#039;&#039;&#039;]] Limit information system access to the types of transactions and functions that authorized users are permitted to execute.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the types of transactions and functions that authorized users are permitted to execute are defined. || Document || SSP, AUP, or IAM document that defines what authorized users can execute.&lt;br /&gt;
|-&lt;br /&gt;
| [b] system access is limited to the defined types of transactions and functions for authorized users. || Screen Share || Screenshot of security roles in AD or IAM or other directory-based identity-related services tool that shows transactions are as defined in the SSP or IAM document; privileged and non-privileged accounts need to be defined and identified in the artifact; screenshot of a non-privileged user trying to execute a privileged function.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.3 – Control CUI Flow ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.3_Details|&#039;&#039;&#039;AC.L2-3.1.3&#039;&#039;&#039;]] Control the flow of CUI in accordance with approved authorizations.&lt;br /&gt;
|-&lt;br /&gt;
| [a] information flow control policies are defined. || Document || SSP or other document describing the control of CUI on the network.&lt;br /&gt;
|-&lt;br /&gt;
| [b] methods and enforcement mechanisms for controlling the flow of CUI are defined. || Document || Document that defines the networking devices that are on the CUI network and answers what measures are in place to control the flow. List of firewalls, border and internal layer 3 devices, IDS/IPS, DLP, that process CUI.&lt;br /&gt;
|-&lt;br /&gt;
| [c] designated sources and destinations (e.g., networks, individuals, and devices) for CUI within the system and between interconnected systems are identified. || Artifact || Network diagram, data flow diagram, external system connection diagrams, document describing the policies for CUI on the network; listing of VLANs and subnets where CUI is authorized; document must describe source and authorized destinations.&lt;br /&gt;
|-&lt;br /&gt;
| [d] authorizations for controlling the flow of CUI are defined. || Document || Document that defines how CUI is to be controlled, such as an InfoSec plan, and/or network management plan.&lt;br /&gt;
|-&lt;br /&gt;
| [e] approved authorizations for controlling the flow of CUI are enforced. || Screen Share || Screenshots of firewall rules, ACLs, etc.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.4 – Separation of Duties ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.4_Details|&#039;&#039;&#039;AC.L2-3.1.4&#039;&#039;&#039;]] Separate the duties of individuals to reduce the risk of malevolent activity without collusion.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the duties of individuals requiring separation are defined. || Document || Document, SSP, account management policy, defining separation of duties by person or role.&lt;br /&gt;
|-&lt;br /&gt;
| [b] responsibilities for duties that require separation are assigned to separate individuals. || Screen Share || Screenshot showing that separation of duties is enforced by showing admin accounts are assigned to different people based on role.&lt;br /&gt;
|-&lt;br /&gt;
| [c] access privileges that enable individuals to exercise the duties that require separation are granted to separate individuals. || Screen Share || Screen shot showing an example such as a security manager can not log into a network device and change ACLs, or network admins can not access security logs in the SIEM tool.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.5 – Least Privilege ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.5_Details|&#039;&#039;&#039;AC.L2-3.1.5&#039;&#039;&#039;]] Employ the principle of least privilege, including for specific security functions and privileged accounts.&lt;br /&gt;
|-&lt;br /&gt;
| [a] privileged accounts are identified. || Document || &amp;quot;SSP or policy (documentation) identify what is considered a privileged account.&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| [b] access to privileged accounts is authorized in accordance with the principle of least privilege. || Artifact || An artifact that identifies the least amount of permissions associated with different types of privileged accounts are approved.&lt;br /&gt;
|-&lt;br /&gt;
| [c] security functions are identified. || Document || &amp;quot;SSP or policy (documentation) identifies what is considered a security account.&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| [d] access to security functions is authorized in accordance with the principle of least privilege. || Artifact || Artifact(s) that identify the least amount of permissions associated with different types of security accounts are approved.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.6 – Non-Privileged Account Use ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.6_Details|&#039;&#039;&#039;AC.L2-3.1.6&#039;&#039;&#039;]] Use non-privileged accounts or roles when accessing nonsecurity functions.&lt;br /&gt;
|-&lt;br /&gt;
| [a] nonsecurity functions are identified. || Document || SSP or account management document, AUP, that defines non-security functions.&lt;br /&gt;
|-&lt;br /&gt;
| [b] users are required to use non-privileged accounts or roles when accessing nonsecurity functions. || Screen Share || Screenshot showing that a privileged user tried to use their admin account to access a non-security function, such as a browser or email (whatever is defined in their policy) and was blocked.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.7 – Privileged Functions ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.7_Details|&#039;&#039;&#039;AC.L2-3.1.7&#039;&#039;&#039;]] Prevent non-privileged users from executing privileged functions and capture the execution of such functions in audit logs.&lt;br /&gt;
|-&lt;br /&gt;
| [a] privileged functions are defined. || Document || SSP or policy (documentation) that defines privileged functions.&lt;br /&gt;
|-&lt;br /&gt;
| [b] non-privileged users are defined. || Document || SSP or policy (documentation) that defines non-privileged users.&lt;br /&gt;
|-&lt;br /&gt;
| [c] non-privileged users are prevented from executing privileged functions. || Screen Share || Screen share that shows that a non-privileged user is not allowed to complete a privileged function (installing software).&lt;br /&gt;
|-&lt;br /&gt;
| [d] the execution of privileged functions is captured in audit logs. || Screen Share || Screen share that shows logs being captured of the execution of privileged functions.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.8 – Unsuccessful Logon Attempts ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.8_Details|&#039;&#039;&#039;AC.L2-3.1.8&#039;&#039;&#039;]] Limit unsuccessful logon attempts.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the means of limiting unsuccessful logon attempts is defined. || Document || SSP or policy (documentation) showing unsuccessful logon attempts settings and or policy.&lt;br /&gt;
|-&lt;br /&gt;
| [b] the defined means of limiting unsuccessful logon attempts is implemented. || Artifact || Artifact showing GPO / Policy for limiting logon attempts.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.9 – Privacy &amp;amp; Security Notices ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.9_Details|&#039;&#039;&#039;AC.L2-3.1.9&#039;&#039;&#039;]] Provide privacy and security notices consistent with applicable CUI rules.&lt;br /&gt;
|-&lt;br /&gt;
| [a] privacy and security notices required by CUI-specified rules are identified, consistent, and associated with the specific CUI category. || Document || SSP or policy (documentation) showing CUI-specified rules are identified, consistent, and associated with the specific CUI category.&lt;br /&gt;
|-&lt;br /&gt;
| [b] privacy and security notices are displayed. || Artifact || Artifact that shows a consent banner or screen that a user sees as they log in to the system.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.10 – Session Lock ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.10_Details|&#039;&#039;&#039;AC.L2-3.1.10&#039;&#039;&#039;]] Use session lock with pattern-hiding displays to prevent access and viewing of data after a period of inactivity.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the period of inactivity after which the system initiates a session lock is defined. || Document || SSP or policy (documentation) that defines the period of inactivity and when a session lock is defined.&lt;br /&gt;
|-&lt;br /&gt;
| [b] access to the system and viewing of data is prevented by initiating a session lock after the defined period of inactivity. || Artifact || Artifact that shows the setting of session lock (GPO or system policy or similar solution addressing the controls supporting centralized management and configuration of operating systems, applications, and users&#039; settings for the working environment of user accounts and computer accounts).&lt;br /&gt;
|-&lt;br /&gt;
| [c] previously visible information is concealed via a pattern-hiding display after the defined period of inactivity. || Document || Screenshot of GPO setting and configuration settings, or similar solution addressing the controls supporting centralized management and configuration of operating systems, applications, and users&#039; settings for the working environment of user accounts and computer accounts.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.11 – Session Termination ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.11_Details|&#039;&#039;&#039;AC.L2-3.1.11&#039;&#039;&#039;]] Terminate (automatically) a user session after a defined condition.&lt;br /&gt;
|-&lt;br /&gt;
| [a] conditions requiring a user session to terminate are defined. || Document || SSP or policy (documentation) that defines the conditions requiring a user session to be terminated.&lt;br /&gt;
|-&lt;br /&gt;
| [b] a user session is automatically terminated after any of the defined conditions. || Screen Share || Screen share showing GPO / VPN Settings that show when a session would be terminated (Idle time, max connection time).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.12 – Control Remote Access ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.12_Details|&#039;&#039;&#039;AC.L2-3.1.12&#039;&#039;&#039;]] Monitor and control remote access sessions.&lt;br /&gt;
|-&lt;br /&gt;
| [a] remote access sessions are permitted. || Document || SSP or policy (documentation) that defines remote access sessions.&lt;br /&gt;
|-&lt;br /&gt;
| [b] the types of permitted remote access are identified. || Document || SSP or policy (documentation) that defines remote access is permitted.&lt;br /&gt;
|-&lt;br /&gt;
| [c] remote access sessions are controlled. || Screen Share || Screen share that shows how the remote access is controlled (access session, and or groups).&lt;br /&gt;
|-&lt;br /&gt;
| [d] remote access sessions are monitored. || Screen Share || Screen share that shows how remote sessions are monitored (logs).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.13 – Remote Access Confidentiality ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.13_Details|&#039;&#039;&#039;AC.L2-3.1.13&#039;&#039;&#039;]] Employ cryptographic mechanisms to protect the confidentiality of remote access sessions.&lt;br /&gt;
|-&lt;br /&gt;
| [a] cryptographic mechanisms to protect the confidentiality of remote access sessions are identified. || Document || SSP or policy (documentation) that discusses the CUI rules, consistent, and associated with the specific CUI category; FIPS Cert # of appliance or application.&lt;br /&gt;
|-&lt;br /&gt;
| [b] cryptographic mechanisms to protect the confidentiality of remote access sessions are implemented. || Screen Share || Screenshot of VPN concentration that shows encryption is on and enabled (point-to-point, etc.).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.14 – Remote Access Routing ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.14_Details|&#039;&#039;&#039;AC.L2-3.1.14&#039;&#039;&#039;]] Route remote access via managed access control points.&lt;br /&gt;
|-&lt;br /&gt;
| [a] managed access control points are identified and implemented. || Screen Share || Screen share that shows access control points (groups and/or users).&lt;br /&gt;
|-&lt;br /&gt;
| [b] remote access is routed through managed network access control points. || Screen Share || Screen share that shows access control points and how they are managed.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.15 – Privileged Remote Access ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.15_Details|&#039;&#039;&#039;AC.L2-3.1.15&#039;&#039;&#039;]] Authorize remote execution of privileged commands and remote access to security-relevant information.&lt;br /&gt;
|-&lt;br /&gt;
| [a] privileged commands authorized for remote execution are identified. || Document || SSP or policy (documentation) that defines what is authorized to be executed remotely and how that is handled.&lt;br /&gt;
|-&lt;br /&gt;
| [b] security-relevant information authorized to be accessed remotely is identified. || Document || SSP or policy (documentation) that defines what can be accessed remotely and what procedures are implemented to allow this (RDP, jump box).&lt;br /&gt;
|-&lt;br /&gt;
| [c] the execution of the identified privileged commands via remote access is authorized. || Artifact || Screen share that shows who has access to perform privileged commands a remotely (access groups for privileged accounts).&lt;br /&gt;
|-&lt;br /&gt;
| [d] access to the identified security-relevant information via remote access is authorized. || Artifact || Screen share that shows the routing of remote access and how it is monitored and how many locations (Firewall, VPN Concentrator).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.16 – Wireless Access Authorization ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.16_Details|&#039;&#039;&#039;AC.L2-3.1.16&#039;&#039;&#039;]] Authorize wireless access prior to allowing such connections.&lt;br /&gt;
|-&lt;br /&gt;
| [a] wireless access points are identified. || Document || SSP, network administration document.&lt;br /&gt;
|-&lt;br /&gt;
| [b] wireless access is authorized prior to allowing such connections. || Screen Share || Authorization profile(s) in Wireless Access Controller or Identity Manager (i.e. Cisco ISE).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.17 – Wireless Access Protection ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.17_Details|&#039;&#039;&#039;AC.L2-3.1.17&#039;&#039;&#039;]] Protect wireless access using authentication and encryption.&lt;br /&gt;
|-&lt;br /&gt;
| [a] wireless access to the system is protected using authentication. || Screen Share || Security page (or similar) of a Wireless Access Controller.&lt;br /&gt;
|-&lt;br /&gt;
| [b] wireless access to the system is protected using encryption. || Screen Share || Security page (or similar) of a Wireless Access Controller.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.18 – Mobile Device Connection ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.18_Details|&#039;&#039;&#039;AC.L2-3.1.18&#039;&#039;&#039;]] Control connection of mobile devices.&lt;br /&gt;
|-&lt;br /&gt;
| [a] mobile devices that process, store, or transmit CUI are identified. || Document || SSP, Mobile Device Policy.&lt;br /&gt;
|-&lt;br /&gt;
| [b] mobile device connections are authorized. || Artifact || Authorization profile(s) in Wireless Access Controller or Identity Manager (i.e. Cisco ISE).&lt;br /&gt;
|-&lt;br /&gt;
| [c] mobile device connections are monitored and logged. || Screen Share || Mobile device logs within the MDM, log intake (sources) configuration (within SIEM) showing MDM is feeding logs to the SIEM.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.19 – Encrypt CUI on Mobile ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.19_Details|&#039;&#039;&#039;AC.L2-3.1.19&#039;&#039;&#039;]] Encrypt CUI on mobile devices and mobile computing platforms.&lt;br /&gt;
|-&lt;br /&gt;
| [a] mobile devices and mobile computing platforms that process, store, or transmit CUI are identified. || Document || SSP, Mobile Device Policy.&lt;br /&gt;
|-&lt;br /&gt;
| [b] encryption is employed to protect CUI on identified mobile devices and mobile computing platforms. || Screen Share || Security policy page in MDM showing how encryption are enforced on mobile device. If no MDM or MDM doesn&#039;t enforce encryption, then validate if the devices used are on the list of devices with native FIPS approved validation.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.20 – External Connections [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.20_Details|&#039;&#039;&#039;AC.L2-3.1.20&#039;&#039;&#039;]] Verify and control/limit connections to and use of external information systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] connections to external systems are identified. || Document || SSP, Systems Interconnection Agreements, SLA.&lt;br /&gt;
|-&lt;br /&gt;
| [b] the use of external systems is identified. || Document || SSP, Systems Interconnection Agreements, SLA.&lt;br /&gt;
|-&lt;br /&gt;
| [c] connections to external systems are verified. || Artifact || SLA for external systems, memorandum for interconnection, information to prove that any cloud solution is at FedRAMP impact level of moderate or higher (i.e. license information, screenshot of AWS cloud dashboard, purchase order document).&lt;br /&gt;
|-&lt;br /&gt;
| [d] the use of external systems is verified. || Artifact || SLA for external systems, memorandum for interconnection, information to prove that any cloud solution is at FedRAMP impact level of moderate or higher (i.e. license information, screenshot of AWS cloud dashboard, purchase order document).&lt;br /&gt;
|-&lt;br /&gt;
| [e] connections to external systems are controlled/limited. || Screen Share || Firewall ruleset for controlling access to cloud service or external system.&lt;br /&gt;
|-&lt;br /&gt;
| [f] the use of external systems is controlled/limited. || Screen Share || Firewall ruleset for controlling access to cloud service or external system.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.21 – Portable Storage Use ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.21_Details|&#039;&#039;&#039;AC.L2-3.1.21&#039;&#039;&#039;]] Limit use of portable storage devices on external systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the use of portable storage devices containing CUI on external systems is identified and documented. || Document || SSP, Removable Media Policy, Acceptable Use Policy (with emphasis on portable media use).&lt;br /&gt;
|-&lt;br /&gt;
| [b] limits on the use of portable storage devices containing CUI on external systems are defined. || Document || SSP, Removable Media Policy, Acceptable Use Policy (with emphasis on portable media use).&lt;br /&gt;
|-&lt;br /&gt;
| [c] the use of portable storage devices containing CUI on external systems is limited as defined. || Document || SSP, Removable Media Policy, Acceptable Use Policy (with emphasis on portable media use).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.22 – Control Public Information [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.22_Details|&#039;&#039;&#039;AC.L2-3.1.22&#039;&#039;&#039;]] Control information posted or processed on publicly accessible information systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] individuals authorized to post or process information on publicly accessible systems are identified. || Document || SSP, Website Governance Plan, Information Release Document.&lt;br /&gt;
|-&lt;br /&gt;
| [b] procedures to ensure CUI is not posted or processed on publicly accessible systems are identified. || Document || SSP, Website Governance Plan, Information Release Document.&lt;br /&gt;
|-&lt;br /&gt;
| [c] a review process is in place prior to posting of any content to publicly accessible systems. || Artifact || &amp;quot;Information release approval process, i.e. chain of email communication from originator, approver, and final decision (may or may not include individual authorized to post); &lt;br /&gt;
SharePoint/electronic or paper form/ ticket system showing information flow between requestor and approver (may or may not include  individual authorized to post).&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| [d] content on publicly accessible systems is reviewed to ensure that it does not include CUI. || Artifact || Incident response process, web design/update/modification SOP etc.&lt;br /&gt;
|-&lt;br /&gt;
| [e] mechanisms are in place to remove and address improper posting of CUI. || Artifact || Incident response process, web design/update/modification SOP etc.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Awareness and Training (AT) ==&lt;br /&gt;
=== AT.L2-3.2.1 – Role-Based Risk Awareness ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AT.L2-3.2.1_Details|&#039;&#039;&#039;AT.L2-3.2.1&#039;&#039;&#039;]] Ensure that managers, systems administrators, and users of organizational systems are made aware of the security risks associated with their activities and of the applicable policies, standards, and procedures related to the security of those systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] security risks associated with organizational activities involving CUI are identified. || Document || Policy of Security Awareness Training; Security Awareness Training Briefing.&lt;br /&gt;
|-&lt;br /&gt;
| [b] policies, standards, and procedures related to the security of the system are identified. || Document || Acceptable Use Policy, Policy/Procedures/Instruction related to the security of the system.&lt;br /&gt;
|-&lt;br /&gt;
| [c] managers, systems administrators, and users of the system are made aware of the security risks associated with their activities. || Artifact || Security Training Brief, training records.&lt;br /&gt;
|-&lt;br /&gt;
| [d] managers, systems administrators, and users of the system are made aware of the applicable policies, standards, and procedures related to the security of the system. || Artifact || Policies, standards and procedures for employees within training (completed training report).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AT.L2-3.2.2 – Role-Based Training ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AT.L2-3.2.2_Details|&#039;&#039;&#039;AT.L2-3.2.2&#039;&#039;&#039;]] Ensure that personnel are trained to carry out their assigned information security-related duties and responsibilities.|-&lt;br /&gt;
|-&lt;br /&gt;
| [a] information security-related duties, roles, and responsibilities are defined. || Document || Policy/Procedures/Instruction, Job Role Matrix, Position Descriptions, User Roles.&lt;br /&gt;
|-&lt;br /&gt;
| [b] information security-related duties, roles, and responsibilities are assigned to designated personnel. || Artifact || Screenshot of breakout of different roles/permissions assigned to individuals (i.e. ActiveDirectory); Privilege Access Agreement.&lt;br /&gt;
|-&lt;br /&gt;
| [c] personnel are adequately trained to carry out their assigned information security-related duties, roles, and responsibilities. || Artifact || Screenshot of tool and/or training specifying security specific roles, duties and responsibilities; Screenshot of required certifications (i.e. Sec+, CISSP).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AT.L2-3.2.3 – Insider Threat Awareness ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AT.L2-3.2.3_Details|&#039;&#039;&#039;AT.L2-3.2.3&#039;&#039;&#039;]] Provide security awareness training on recognizing and reporting potential indicators of insider threat.&lt;br /&gt;
|-&lt;br /&gt;
| [a] potential indicators associated with insider threats are identified. || Document || Insidert Threat Policy/Procedures/Instruction; Insider Threat Training/Briefing.&lt;br /&gt;
|-&lt;br /&gt;
| [b] security awareness training on recognizing and reporting potential indicators of insider threat is provided to managers and employees. || Artifact || Screenshot of training records showing completion of Insider Threat training, emails showing completion of Insider Threat training, Screenshot of certificate showing completion with individual&#039;s name.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Audit and Accountability (AU) ==&lt;br /&gt;
=== AU.L2-3.3.1 – System Auditing ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AU.L2-3.3.1_Details|&#039;&#039;&#039;AU.L2-3.3.1&#039;&#039;&#039;]] Create and retain system audit logs and records to the extent needed to enable the monitoring, analysis, investigation, and reporting of unlawful or unauthorized system activity.&lt;br /&gt;
|-&lt;br /&gt;
| [a] audit logs needed (i.e., event types to be logged) to enable the monitoring, analysis, investigation, and reporting of unlawful or unauthorized system activity are specified. || Document || SSP, policy, or auditing and logging process that defines specific types of events to be logged.&lt;br /&gt;
|-&lt;br /&gt;
| [b] the content of audit records needed to support monitoring, analysis, investigation, and reporting of unlawful or unauthorized system activity is defined. || Document || SSP, policy, or auditing and logging process that defines specific content of audit records/files.&lt;br /&gt;
|-&lt;br /&gt;
| [c] audit records are created (generated). || Screen Share || Screen share of tool that shows logs are generated for all systems.&lt;br /&gt;
|-&lt;br /&gt;
| [d] audit records, once created, contain the defined content. || Screen Share || Screen share of tool that shows logs contain defined content as defined in SSP, policy, or procedures.&lt;br /&gt;
|-&lt;br /&gt;
| [e] retention requirements for audit records are defined. || Document || SSP, Polocy, or Auditing and logging process that describes how long records are kept.&lt;br /&gt;
|-&lt;br /&gt;
| [f] audit records are retained as defined. || Screen Share || Screen share of tool that shows records and audit content retained at a minimum as defined.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AU.L2-3.3.2 – User Accountability ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AU.L2-3.3.2_Details|&#039;&#039;&#039;AU.L2-3.3.2&#039;&#039;&#039;]] Ensure that the actions of individual system users can be uniquely traced to those users so they can be held accountable for their actions.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the content of the audit records needed to support the ability to uniquely trace users to their actions is defined. || Document || SSP, policy, or process that defines actions traced back to individuals.&lt;br /&gt;
|-&lt;br /&gt;
| [b] audit records, once created, contain the defined content. || Screen Share || Screen share of tool that shows audit records traced to specific users/roles.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AU.L2-3.3.3 – Event Review ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AU.L2-3.3.3_Details|&#039;&#039;&#039;AU.L2-3.3.3&#039;&#039;&#039;]] Review and update logged events.&lt;br /&gt;
|-&lt;br /&gt;
| [a] a process for determining when to review logged events is defined. || Document || SSP, policy, or documented process that shows frequency of when to review types of logged events.&lt;br /&gt;
|-&lt;br /&gt;
| [b] event types being logged are reviewed in accordance with the defined review process. || Artifact || Evidence through a documented method such as meeting minutes, CAB minutes, etc. of log sources and log events being logged at the defined frequency.&lt;br /&gt;
|-&lt;br /&gt;
| [c] event types being logged are updated based on the review. || Artifact || Evidence of implementation based on the results of the review of logged events/sources through a ticket, meeting minutes, or screen share of the tool that shows changes implemented (finetuning).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AU.L2-3.3.4 – Audit Failure Alerting ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AU.L2-3.3.4_Details|&#039;&#039;&#039;AU.L2-3.3.4&#039;&#039;&#039;]] Alert in the event of an audit logging process failure.&lt;br /&gt;
|-&lt;br /&gt;
| [a] personnel or roles to be alerted in the event of an audit logging process failure are identified. || Document || SSP, policy, or procedure that shows who needs to be notified in case of an audit failure.&lt;br /&gt;
|-&lt;br /&gt;
| [b] types of audit logging process failures for which alert will be generated are defined. || Document || SSP, policy, or procedure that shows what types of failure will generate notifications.&lt;br /&gt;
|-&lt;br /&gt;
| [c] identified personnel or roles are alerted in the event of an audit logging process failure. || Artifact || Artifact such as email or ticket that shows the identified personnel were alerted of any audit/logging process failure as defined.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AU.L2-3.3.5 – Audit Correlation ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AU.L2-3.3.5_Details|&#039;&#039;&#039;AU.L2-3.3.5&#039;&#039;&#039;]] Correlate audit record review, analysis, and reporting processes for investigation and response to indications of unlawful, unauthorized, suspicious, or unusual activity.&lt;br /&gt;
|-&lt;br /&gt;
| [a] audit record review, analysis, and reporting processes for investigation and response to indications of unlawful, unauthorized, suspicious, or unusual activity are defined. || Document || SSP, policy, or procedure covering audit logging, monitoring, and reporting.&lt;br /&gt;
|-&lt;br /&gt;
| [b] defined audit record review, analysis, and reporting processes are correlated. || Artifact || Artifact showing an audit event and the resultant corrective action or actions to the event; this can be a Help Desk ticket, meeting notes, or a change control board items showing the event and any corrective action taken.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AU.L2-3.3.6 – Reduction &amp;amp; Reporting ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AU.L2-3.3.6_Details|&#039;&#039;&#039;AU.L2-3.3.6&#039;&#039;&#039;]] Provide audit record reduction and report generation to support on-demand analysis and reporting.&lt;br /&gt;
|-&lt;br /&gt;
| [a] an audit record reduction capability that supports on-demand analysis is provided. || Screen Share || Screen share of the logging environment where an event can be selected and traced back to a specific device, or dashboard showing realtime event analysis.&lt;br /&gt;
|-&lt;br /&gt;
| [b] a report generation capability that supports on-demand reporting is provided. || Screen Share || Screen share showing the generation of an on demand report.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AU.L2-3.3.7 – Authoritative Time Source ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AU.L2-3.3.7_Details|&#039;&#039;&#039;AU.L2-3.3.7&#039;&#039;&#039;]] Provide a system capability that compares and synchronizes internal system clocks with an authoritative source to generate time stamps for audit records.&lt;br /&gt;
|-&lt;br /&gt;
| [a] internal system clocks are used to generate time stamps for audit records. || Screen Share || Screen share showing the NTP settings of a windows, Unix, Linux device; a screen share showing the NTP settings of network appliances.&lt;br /&gt;
|-&lt;br /&gt;
| [b] an authoritative source with which to compare and synchronize internal system clocks is specified. || Document || SSP or policy indicating that devices need to be synched to a local authoritative time device that is synched with an authoritative time service.&lt;br /&gt;
|-&lt;br /&gt;
| [c] internal system clocks used to generate time stamps for audit records are compared to and synchronized with the specified authoritative time source. || Screen Share || Screen share showing device logging appliance time is point to the appropriate authoritative time server.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AU.L2-3.3.8 – Audit Protection ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AU.L2-3.3.8_Details|&#039;&#039;&#039;AU.L2-3.3.8&#039;&#039;&#039;]] Protect audit information and audit logging tools from unauthorized access, modification, and deletion.&lt;br /&gt;
|-&lt;br /&gt;
| [a] audit information is protected from unauthorized access. || Screen Share || Screen share showing operating system permissions on the audit folders being restricted to appropriate users.&lt;br /&gt;
|-&lt;br /&gt;
| [b] audit information is protected from unauthorized modification. || Screen Share || Screen share showing operating system permissions on the audit folders being restricted to appropriate users.&lt;br /&gt;
|-&lt;br /&gt;
| [c] audit information is protected from unauthorized deletion. || Screen Share || Screen share showing operating system permissions on the audit folders being restricted to appropriate users.&lt;br /&gt;
|-&lt;br /&gt;
| [d] audit logging tools are protected from unauthorized access. || Screen Share || Artifact showing access permissions in the SIEM tool.&lt;br /&gt;
|-&lt;br /&gt;
| [e] audit logging tools are protected from unauthorized modification. || Screen Share || Artifact showing update permissions in the SIEM tool.&lt;br /&gt;
|-&lt;br /&gt;
| [f] audit logging tools are protected from unauthorized deletion. || Screen Share || Artifact showing delete permissions in the SIEM tool.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AU.L2-3.3.9 – Audit Management ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AU.L2-3.3.9_Details|&#039;&#039;&#039;AU.L2-3.3.9&#039;&#039;&#039;]] Limit management of audit logging functionality to a subset of privileged users.&lt;br /&gt;
|-&lt;br /&gt;
| [a] a subset of privileged users granted access to manage audit logging functionality is defined. || Document || SSP or policy indicating which users or groups have access to audit logs.&lt;br /&gt;
|-&lt;br /&gt;
| [b] management of audit logging functionality is limited to the defined subset of privileged users. || Screen Share || Artifact showing SIEM or OS folder permissions (this should be limited to the assigned users or groups); artifact showing an ACL setting in SIEM tool in regards to logs.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Configuration Management (CM) ==&lt;br /&gt;
=== CM.L2-3.4.1 – System Baselining ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_CM.L2-3.4.1_Details|&#039;&#039;&#039;CM.L2-3.4.1&#039;&#039;&#039;]] Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles.&lt;br /&gt;
|-&lt;br /&gt;
| [a] a baseline configuration is established. || Document || Documentation showing or explaining standard imaging process (how standard images are deployed and where  they are stored).&lt;br /&gt;
|-&lt;br /&gt;
| [b] the baseline configuration includes hardware, software, firmware, and documentation. || Artifact || Screenshot of repository of where images are maintained and information relating to hardware, software, and firmware.&lt;br /&gt;
|-&lt;br /&gt;
| [c] the baseline configuration is maintained (reviewed and updated) throughout the system development life cycle. || Artifact || Screenshot/evidence displaying management of baseline configurations (how often they are being managed as stated).&lt;br /&gt;
|-&lt;br /&gt;
| [d] a system inventory is established. || Document || Screenshot/evidence displaying inventory listing of approved products for use.&lt;br /&gt;
|-&lt;br /&gt;
| [e] the system inventory includes hardware, software, firmware, and documentation. || Artifact || Screeenshot/evidence displaying inventory listing of approved products and versions permitted for use.&lt;br /&gt;
|-&lt;br /&gt;
| [f] the inventory is maintained (reviewed and updated) throughout the system development life cycle. || Artifact || Screeenshot/evidence displaying management of baseline configurations (How often and are they being managed as stated.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== CM.L2-3.4.2 – Security Configuration Enforcement ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_CM.L2-3.4.2_Details|&#039;&#039;&#039;CM.L2-3.4.2&#039;&#039;&#039;]] Establish and enforce security configuration settings for information technology products employed in organizational systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] security configuration settings for information technology products employed in the system are established and included in the baseline configuration. || Document || Documentation explaining methodology used by organization to create secure baselines (STIGs, benchmarks).&lt;br /&gt;
|-&lt;br /&gt;
| [b] security configuration settings for information technology products employed in the system are enforced. || Artifact || Evidence of tool/s used to enforce security configurations to ensure images used are free from modification unless authorized.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== CM.L2-3.4.3 – System Change Management ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_CM.L2-3.4.3_Details|&#039;&#039;&#039;CM.L2-3.4.3&#039;&#039;&#039;]] Track, review, approve or disapprove, and log changes to organizational systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] changes to the system are tracked. || Artifact || Evidence of IT Service Management tool / process used to track system changes.&lt;br /&gt;
|-&lt;br /&gt;
| [b] changes to the system are reviewed. || Artifact || Evidence of IT Service Management tool / process used to review system changes.&lt;br /&gt;
|-&lt;br /&gt;
| [c] changes to the system are approved or disapproved. || Artifact || Evidence of IT Service Management tool / process used to approve/disapprove system changes.&lt;br /&gt;
|-&lt;br /&gt;
| [d] changes to the system are logged. || Artifact || Evidence of IT Service Management tool / process used to log system changes.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== CM.L2-3.4.4 – Security Impact Analysis ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_CM.L2-3.4.4_Details|&#039;&#039;&#039;CM.L2-3.4.4&#039;&#039;&#039;]] Analyze the security impact of changes prior to implementation.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the security impact of changes to the system is analyzed prior to implementation. || Artifact || Document explaining that security impact analysis of proposed changes to a system is conducted prior to implementation.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== CM.L2-3.4.5 – Access Restrictions for Change ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_CM.L2-3.4.5_Details|&#039;&#039;&#039;CM.L2-3.4.5&#039;&#039;&#039;]] Define, document, approve, and enforce physical and logical access restrictions associated with changes to organizational systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] physical access restrictions associated with changes to the system are defined. || Document || Document explaining the process of how physical access restrictions are defined for an individuals ability to make system changes.&lt;br /&gt;
|-&lt;br /&gt;
| [b] physical access restrictions associated with changes to the system are documented. || Document || Document explaining the process of how physical access restrictions are defined for an individuals ability to make system changes are documented; access request process.&lt;br /&gt;
|-&lt;br /&gt;
| [c] physical access restrictions associated with changes to the system are approved. || Artifact || Evidence of process of how physical access to systems are granted (i.e. physical access request sample).&lt;br /&gt;
|-&lt;br /&gt;
| [d] physical access restrictions associated with changes to the system are enforced. || Physical Review || Evidence of process of how physical access to systems are enforced (physical access system).&lt;br /&gt;
|-&lt;br /&gt;
| [e] logical access restrictions associated with changes to the system are defined. || Document || Document explaining the process of how logical access restrictions are defined for an individual&#039;s ability to make system changes.&lt;br /&gt;
|-&lt;br /&gt;
| [f] logical access restrictions associated with changes to the system are documented. || Document || Document explaining the process of how logical access restrictions are defined for an individual&#039;s ability to make system changes are documented.&lt;br /&gt;
|-&lt;br /&gt;
| [g] logical access restrictions associated with changes to the system are approved. || Artifact || Evidence of process of how logical access to systems are granted.&lt;br /&gt;
|-&lt;br /&gt;
| [h] logical access restrictions associated with changes to the system are enforced. || Artifact || Evidence of process of how logical access to systems are enforced.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== CM.L2-3.4.6 – Least Functionality ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_CM.L2-3.4.6_Details|&#039;&#039;&#039;CM.L2-3.4.6&#039;&#039;&#039;]] Employ the principle of least functionality by configuring organizational systems to provide only essential capabilities.&lt;br /&gt;
|-&lt;br /&gt;
| [a] essential system capabilities are defined based on the principle of least functionality. || Document || Documentation explaining how systems are configured to utilize the principle of least functionality for designated users.&lt;br /&gt;
|-&lt;br /&gt;
| [b] the system is configured to provide only the defined essential capabilities. || Screen Share || Evidence displaying how systems are configured to utilize the principle of least functionality for designated users; disabled service settings, accepted standards for hardening (CIS benchmarks, etc.).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== CM.L2-3.4.7 – Nonessential Functionality ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_CM.L2-3.4.7_Details|&#039;&#039;&#039;CM.L2-3.4.7&#039;&#039;&#039;]] Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services.&lt;br /&gt;
|-&lt;br /&gt;
| [a] essential programs are defined. || Document || Documented essential programs specified; build documents; software center; SSP.&lt;br /&gt;
|-&lt;br /&gt;
| [b] the use of nonessential programs is defined. || Document || Documented listing of nonessential programs (whatever is NOT specified in [a]); AUP/User Agreement may identify nonessential use/programs.&lt;br /&gt;
|-&lt;br /&gt;
| [c] the use of nonessential programs is restricted, disabled, or prevented as defined. || Screen Share || Tool used to restrict nonessential programs displays restrictions as defined (McAfee ePO settings, Carbon Black rules, etc.).&lt;br /&gt;
|-&lt;br /&gt;
| [d] essential functions are defined. || Document || Documented essential functions are specified.&lt;br /&gt;
|-&lt;br /&gt;
| [e] the use of nonessential functions is defined. || Document || Documented nonessential functions are specified.&lt;br /&gt;
|-&lt;br /&gt;
| [f] the use of nonessential functions is restricted, disabled, or prevented as defined. || Screen Share || Tool used to restrict essential/nonessential functions displays restrictions as defined.&lt;br /&gt;
|-&lt;br /&gt;
| [g] essential ports are defined. || Document || Documented essential ports are specified.&lt;br /&gt;
|-&lt;br /&gt;
| [h] the use of nonessential ports is defined. || Document || Documented nonessential ports functions are specified.&lt;br /&gt;
|-&lt;br /&gt;
| [i] the use of nonessential ports is restricted, disabled, or prevented as defined. || Screen Share || Tool used to restrict essential/nonessential ports displays restrictions as defined (FW rules; McAfee; GPO, etc.).&lt;br /&gt;
|-&lt;br /&gt;
| [j] essential protocols are defined. || Document || Documented essential protocols are specified.&lt;br /&gt;
|-&lt;br /&gt;
| [k] the use of nonessential protocols is defined. || Document || Documented nonessential protocols functions are specified.&lt;br /&gt;
|-&lt;br /&gt;
| [l] the use of nonessential protocols is restricted, disabled, or prevented as defined. || Screen Share || Tool used to restrict essential/nonessential protocols displays restrictions as defined (FW rules; GPO, etc.).&lt;br /&gt;
|-&lt;br /&gt;
| [m] essential services are defined. || Document || Documented essential services specified.&lt;br /&gt;
|-&lt;br /&gt;
| [n] the use of nonessential services is defined. || Document || Documented nonessential services functions are specified.&lt;br /&gt;
|-&lt;br /&gt;
| [o] the use of nonessential services is restricted, disabled, or prevented as defined. || Screen Share || Tool used to restrict essential/nonessential services displays restrictions as defined.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== CM.L2-3.4.8 – Application Execution Policy ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_CM.L2-3.4.8_Details|&#039;&#039;&#039;CM.L2-3.4.8&#039;&#039;&#039;]] Apply deny-by-exception (blacklisting) policy to prevent the use of unauthorized software or deny-all, permit-by-exception (whitelisting) policy to allow the execution of authorized software.&lt;br /&gt;
|-&lt;br /&gt;
| [a] a policy specifying whether whitelisting or blacklisting is to be implemented is specified. || Document || Documentation explaining whitelisting or blacklisting process.&lt;br /&gt;
|-&lt;br /&gt;
| [b] the software allowed to execute under whitelisting or denied use under blacklisting is specified. || Document || Documentation explaining whitelisting or blacklisting process for software.&lt;br /&gt;
|-&lt;br /&gt;
| [c] whitelisting to allow the execution of authorized software or blacklisting to prevent the use of unauthorized software is implemented as specified. || Screen Share || Tool used for whitelisting or blacklisting for software shows capability of restricting/authorizing software (Carbon Black dashboard, &amp;quot;SW Store&amp;quot;, web proxies, DNS Blackhole, etc.).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== CM.L2-3.4.9 – User-Installed Software ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_CM.L2-3.4.9_Details|&#039;&#039;&#039;CM.L2-3.4.9&#039;&#039;&#039;]] Control and monitor user-installed software.&lt;br /&gt;
|-&lt;br /&gt;
| [a] a policy for controlling the installation of software by users is established. || Document || Documented software authorization process or methodology for approval.&lt;br /&gt;
|-&lt;br /&gt;
| [b] installation of software by users is controlled based on the established policy. || Screen Share || Evidence that approval/restriction in installation of software by authorized personnel is implemented as specified (AUP, GPO, etc.).&lt;br /&gt;
|-&lt;br /&gt;
| [c] installation of software by users is monitored. || Screen Share || Evidence that installation of software by authorized personnel is monitored (SCCM groups, SW Center, etc.).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Identification and Authentication (IA) ==&lt;br /&gt;
=== IA.L2-3.5.1 – Identification [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IA.L2-3.5.1_Details|&#039;&#039;&#039;IA.L2-3.5.1&#039;&#039;&#039;]] Identify information system users, processes acting on behalf of users, or devices.&lt;br /&gt;
|-&lt;br /&gt;
| [a] system users are identified. || Document || Based on what is defined in their documentation (SSP, AUP, Policy, SOP), request to see a sample of non-privileged/privileged users in AD OU group (overlaps with 3.1.1 and 3.1.5).&lt;br /&gt;
|-&lt;br /&gt;
| [b] processes acting on behalf of users are identified. || Document || Based on what is defined in their documentation (SSP, AUP, Policy, SOP), request to see a sample of service accounts in AD OU group (overlaps with 3.1.1 and 3.1.5).&lt;br /&gt;
|-&lt;br /&gt;
| [c] devices accessing the system are identified. || Document || Based on what is defined in their documentation (SSP, AUP, Policy, SOP), request to see a sample of domain-joined workstation &amp;amp; servers in AD OU group (overlaps with 3.1.1 and 3.1.5).  For network devices, request screen share/artifact to show how they are identified on the enterprise network.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IA.L2-3.5.2 – Authentication [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IA.L2-3.5.2_Details|&#039;&#039;&#039;IA.L2-3.5.2&#039;&#039;&#039;]] Authenticate (or verify) the identities of those users, processes, or devices, as a prerequisite to allowing access to organizational information systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the identity of each user is authenticated or verified as a prerequisite to system access. || Screen Share || If the user logs in with non-privileged account during other demoes and then a privileged account, then this should be satisfied.  If screen share is unavailable, request logs to show successful and unsuccessful login by privileged and non-privilged users.&lt;br /&gt;
|-&lt;br /&gt;
| [b] the identity of each process acting on behalf of a user is authenticated or verified as a prerequisite to system access. || Screen Share || Request a log that shows successful/unsuccessful service account trying to log on to company&#039;s asset.&lt;br /&gt;
|-&lt;br /&gt;
| [c] the identity of each device accessing or connecting to the system is authenticated or verified as a prerequisite to system access. || Screen Share || Request a log that shows domain-joined workstation/server authenticating to AD (focus on the MAC/IP address/hostname).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IA.L2-3.5.3 – Multifactor Authentication ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IA.L2-3.5.3_Details|&#039;&#039;&#039;IA.L2-3.5.3&#039;&#039;&#039;]] Use multifactor authentication for local and network access to privileged accounts and for network access to non-privileged accounts.&lt;br /&gt;
|-&lt;br /&gt;
| [a] privileged accounts are identified. || Document || Based on what is defined in their documentation, request to see a sample of privileged users in AD OU group.  Overlaps with 3.1.5.  Screenshot/screen share to show implementation is enforced.&lt;br /&gt;
|-&lt;br /&gt;
| [b] multifactor authentication is implemented for local access to privileged accounts. || Screen Share || SSP, AUP, Policy, SOP that defines that MFA is needed for privileged local access.&lt;br /&gt;
|-&lt;br /&gt;
| [c] multifactor authentication is implemented for network access to privileged accounts. || Screen Share || Within the MFA implementation mechanism, show that privileged users are forced to use MFA;  Screenshot/Screen share to show implementation is enforced.&lt;br /&gt;
|-&lt;br /&gt;
| [d] multifactor authentication is implemented for network access to non-privileged accounts. || Screen Share || Within the MFA implementation mechanism, show that non-privileged users are forced to use MFA; Screenshot/Screen share to show implementation is enforced.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IA.L2-3.5.4 – Replay-Resistant Authentication ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IA.L2-3.5.4_Details|&#039;&#039;&#039;IA.L2-3.5.4&#039;&#039;&#039;]] Employ replay-resistant authentication mechanisms for network access to privileged and non-privileged accounts.&lt;br /&gt;
|-&lt;br /&gt;
| [a] replay-resistant authentication mechanisms are implemented for network account access to privileged and non-privileged accounts. || Screen Share || Show the GPO setting that enforces Kerberos within AD.  If MFA is used, show the implementation to enforce replay resistant techniques.  For non-windows, show the technical solution to enforce replay resistant attacks.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IA.L2-3.5.5 – Identifier Reuse ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IA.L2-3.5.5_Details|&#039;&#039;&#039;IA.L2-3.5.5&#039;&#039;&#039;]] Prevent reuse of identifiers for a defined period.&lt;br /&gt;
|-&lt;br /&gt;
| [a] a period within which identifiers cannot be reused is defined. || Document || SSP, policies, or SOP that defines identifier reuse.&lt;br /&gt;
|-&lt;br /&gt;
| [b] reuse of identifiers is prevented within the defined period. || Artifact || Show the GPO setting/technical solution that enforces what is defined in policy/documentation (this can be automated or manual process; screen share/artifacts can be presented to satisfy this requirement.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IA.L2-3.5.6 – Identifier Handling ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IA.L2-3.5.6_Details|&#039;&#039;&#039;IA.L2-3.5.6&#039;&#039;&#039;]] Disable identifiers after a defined period of inactivity.&lt;br /&gt;
|-&lt;br /&gt;
| [a] a period of inactivity after which an identifier is disabled is defined. || Document || SSP, policy that defines the period of inactivity after which an identifier is disabled.&lt;br /&gt;
|-&lt;br /&gt;
| [b] identifiers are disabled after the defined period of inactivity. || Artifact || Screen share AD or similar tool supporting directory-based identity-related services for disabled accounts (can be done by hand or script).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IA.L2-3.5.7 – Password Complexity ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IA.L2-3.5.7_Details|&#039;&#039;&#039;IA.L2-3.5.7&#039;&#039;&#039;]] Enforce a minimum password complexity and change of characters when new passwords are created.&lt;br /&gt;
|-&lt;br /&gt;
| [a] password complexity requirements are defined. || Document || SSP, policy that defines password complexity requirements.&lt;br /&gt;
|-&lt;br /&gt;
| [b] password change of character requirements are defined. || Document || SSP, policy that defines change of character requirements are defined.&lt;br /&gt;
|-&lt;br /&gt;
| [c] minimum password complexity requirements as defined are enforced when new passwords are created. || Screen Share || Screen share of AD or similar directory-based identity-related service tool to show complexity requirements.&lt;br /&gt;
|-&lt;br /&gt;
| [d] minimum password change of character requirements as defined are enforced when new passwords are created. || Screen Share || Screen share of Group Policy configuration or similar tool providing centralized management and configuration of operating systems, applications, and users&#039; settings to show that characters must be changed.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IA.L2-3.5.8 – Password Reuse ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IA.L2-3.5.8_Details|&#039;&#039;&#039;IA.L2-3.5.8&#039;&#039;&#039;]] Prohibit password reuse for a specified number of generations.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the number of generations during which a password cannot be reused is specified. || Document || SSP, policy that specifies the number of generations during which a password cannot be reused is specified.&lt;br /&gt;
|-&lt;br /&gt;
| [b] reuse of passwords is prohibited during the specified number of generations. || Screen Share || Screen share Group Policy or similar tool providing centralized management and configuration of operating systems, applications, and users&#039; settings in a directory-based identity-related service tool&#039;s configuration to show reuse of passwords is prohibited.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IA.L2-3.5.9 – Temporary Passwords ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IA.L2-3.5.9_Details|&#039;&#039;&#039;IA.L2-3.5.9&#039;&#039;&#039;]] Allow temporary password use for system logons with an immediate change to a permanent password.&lt;br /&gt;
|-&lt;br /&gt;
| [a] an immediate change to a permanent password is required when a temporary password is used for system logon. || Screen Share || Screen share of Group Policy or similar tool providing centralized management and configuration of operating systems, applications, and users&#039; settings in a directory-based identity-related service tool&#039;s configuration to show &amp;quot;change password at first logon.&amp;quot;&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IA.L2-3.5.10 – Cryptographically-Protected Passwords ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IA.L2-3.5.1_Details|&#039;&#039;&#039;IA.L2-3.5.1&#039;&#039;&#039;]] Store and transmit only cryptographically-protected passwords.&lt;br /&gt;
|-&lt;br /&gt;
| [a] passwords are cryptographically protected in storage. || Screen Share || Screen share Group Policy or similar tool providing centralized management and configuration of operating systems, applications, and users&#039; settings in a directory-based identity-related service tool&#039;s configuration that Kerberos, or a similar network authentication protocol that works on the basis of tickets to allow nodes communicating over a non-secure network to prove their identity to one another in a secure manner, is enabled.&lt;br /&gt;
|-&lt;br /&gt;
| [b] passwords are cryptographically protected in transit. || Screen Share || Screen share Group Policy or similar tool providing centralized management and configuration of operating systems, applications, and users&#039; settings in a directory-based identity-related service tool&#039;s configuration that Kerberos, or a similar network authentication protocol that works on the basis of tickets to allow nodes communicating over a non-secure network to prove their identity to one another in a secure manner, is enabled.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IA.L2-3.5.11 – Obscure Feedback ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IA.L2-3.5.10_Details|&#039;&#039;&#039;IA.L2-3.5.10&#039;&#039;&#039;]] Obscure feedback of authentication information.&lt;br /&gt;
|-&lt;br /&gt;
| [a] authentication information is obscured during the authentication process. || Screen Share || Screen share of Group Policy or similar tool providing centralized management and configuration of operating systems, applications, and users&#039; settings in a directory-based identity-related service tool&#039;s configuration to show that passwords are obscured.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Incident Response (IR) ==&lt;br /&gt;
=== IR.L2-3.6.1 – Incident Handling ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IR.L2-3.6.1_Details|&#039;&#039;&#039;IR.L2-3.6.1&#039;&#039;&#039;]] Establish an operational incident-handling capability for organizational systems that includes preparation, detection, analysis, containment, recovery, and user response activities.&lt;br /&gt;
|-&lt;br /&gt;
| [a] an operational incident-handling capability is established. || Document || Incident Response SOP/Plan.&lt;br /&gt;
|-&lt;br /&gt;
| [b] the operational incident-handling capability includes preparation. || Document || Incident Response SOP/Plan, prior incident report, training, COOP plan.&lt;br /&gt;
|-&lt;br /&gt;
| [c] the operational incident-handling capability includes detection. || Document || Incident Response SOP/Plan; definition of tools used to detect; artifacts showing tools used; prior incident report.&lt;br /&gt;
|-&lt;br /&gt;
| [d] the operational incident-handling capability includes analysis. || Document || Incident Response SOP/Plan; Definition of tools used to analyze potential incidents; artifacts showing tools used for analysis; prior incident report.&lt;br /&gt;
|-&lt;br /&gt;
| [e] the operational incident-handling capability includes containment. || Document || Incident Response SOP/Plan; isolation/quarantine process; user training.&lt;br /&gt;
|-&lt;br /&gt;
| [f] the operational incident-handling capability includes recovery. || Document || Incident Response SOP/Plan; COOP Plan; prior incident reports, re-baselining impacted devices.&lt;br /&gt;
|-&lt;br /&gt;
| [g] the operational incident-handling capability includes user response. || Document || Incident Response SOP/Plan; user awareness training; Help Desk process.&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IR.L2-3.6.2 – Incident Reporting ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IR.L2-3.6.2_Details|&#039;&#039;&#039;IR.L2-3.6.2&#039;&#039;&#039;]] Track, document, and report incidents to designated officials and/or authorities both internal and external to the organization.&lt;br /&gt;
|-&lt;br /&gt;
| [a] incidents are tracked. || Artifact || Incident Response SOP/Plan; ITSM artifact; technical implementation for incident tracking.&lt;br /&gt;
|-&lt;br /&gt;
| [b] incidents are documented. || Artifact || Incident Response SOP/Plan; ITSM artifact; technical implementation for incident tracking.&lt;br /&gt;
|-&lt;br /&gt;
| [c] authorities to whom incidents are to be reported are identified. || Document || Incident Response SOP/Plan.&lt;br /&gt;
|-&lt;br /&gt;
| [d] organizational officials to whom incidents are to be reported are identified. || Document || Incident Response SOP/Plan.&lt;br /&gt;
|-&lt;br /&gt;
| [e] identified authorities are notified of incidents. || Screen Share || Prior incident report; DIBNET login; prior email notifications.&lt;br /&gt;
|-&lt;br /&gt;
| [f] identified organizational officials are notified of incidents. || Artifact || Prior incident report; prior email notifications; tabletop exercises.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IR.L2-3.6.3 – Incident Response Testing ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IR.L2-3.6.3_Details|&#039;&#039;&#039;IR.L2-3.6.3&#039;&#039;&#039;]] Test the organizational incident response capability.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the incident response capability is tested. || Artifact || Incident response table top/scheduled or unscheduled test or penetration test.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Maintenance (MA) ==&lt;br /&gt;
=== MA.L2-3.7.1 – Perform Maintenance ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MA.L2-3.7.1_Details|&#039;&#039;&#039;MA.L2-3.7.1&#039;&#039;&#039;]] Perform maintenance on organizational systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] system maintenance is performed. || Artifact || Establish typical maintenance activities (HVAC, UPS, power distribution, generators, copier maintenance) that are performed; maintenance agreements or contracts detailing these types of activities are acceptable; interview responses should be considered.  This requirement should not be confused with 3.14.1 - report, remediate, and correct system flaws in a timely manner (patch management).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MA.L2-3.7.2 – System Maintenance Control ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MA.L2-3.7.2_Details|&#039;&#039;&#039;MA.L2-3.7.2&#039;&#039;&#039;]] Provide controls on the tools, techniques, mechanisms, and personnel used to conduct system maintenance.&lt;br /&gt;
|-&lt;br /&gt;
| [a] tools used to conduct system maintenance are controlled. || Artifact || Tools may largely depend on the assessed environment; discussion examples include network diagnostic and monitoring tools (including hardware and software); artifacts could demonstrate secured locations/areas for these tools (photos) or checkout sheets/rosters (documents) depicting responsible personnel and the dates/times of checkout.&lt;br /&gt;
|-&lt;br /&gt;
| [b] techniques used to conduct system maintenance are controlled. || Artifact || Processes for scheduling, performing, documenting, reviewing, approving, and monitoring maintenance and repairs for the information system.&lt;br /&gt;
|-&lt;br /&gt;
| [c] mechanisms used to conduct system maintenance are controlled. || Artifact || Processes for scheduling, performing, documenting, reviewing, approving, and monitoring maintenance and repairs for the information system.&lt;br /&gt;
|-&lt;br /&gt;
| [d] personnel used to conduct system maintenance are controlled. || Physical Review || Screenshot of who is authorized to conduct maintenance; maintenance personnel training program.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MA.L2-3.7.3 – Equipment Sanitization ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MA.L2-3.7.3_Details|&#039;&#039;&#039;MA.L2-3.7.3&#039;&#039;&#039;]] Ensure equipment removed for off-site maintenance is sanitized of any CUI.&lt;br /&gt;
|-&lt;br /&gt;
| [a] equipment to be removed from organizational spaces for off-site maintenance is sanitized of any CUI. || Artifact || Document or artifact; record if equipment sanitized; categories of sanitization/destruction defined; sanitization procedural document.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MA.L2-3.7.4 – Media Inspection ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MA.L2-3.7.4_Details|&#039;&#039;&#039;MA.L2-3.7.4&#039;&#039;&#039;]] Check media containing diagnostic and test programs for malicious code before the media are used in organizational systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] media containing diagnostic and test programs are checked for malicious code before being used in organizational systems that process, store, or transmit CUI. || Artifact || Screenshot of diagnostic/test program being used (such as Symantec and McAfee on access scans…).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MA.L2-3.7.5 – Nonlocal Maintenance ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MA.L2-3.7.5_Details|&#039;&#039;&#039;MA.L2-3.7.5&#039;&#039;&#039;]] Require multifactor authentication to establish nonlocal maintenance sessions via external network connections and terminate such connections when nonlocal maintenance is complete.&lt;br /&gt;
|-&lt;br /&gt;
| [a] multifactor authentication is used to establish nonlocal maintenance sessions via external network connections. || Screen Share || Describe MFA used to remote from external service to organizational systems for maintenance and screenshot of MFA (3.5.3)(points associated with admin).&lt;br /&gt;
|-&lt;br /&gt;
| [b] nonlocal maintenance sessions established via external network connections are terminated when nonlocal maintenance is complete. || Screen Share || Screenshot VPN session timeout.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MA.L2-3.7.6 – Maintenance Personnel ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MA.L2-3.7.6_Details|&#039;&#039;&#039;MA.L2-3.7.6&#039;&#039;&#039;]] Supervise the maintenance activities of maintenance personnel without required access authorization.&lt;br /&gt;
|-&lt;br /&gt;
| [a] maintenance personnel without required access authorization are supervised during maintenance activities. || Document || System maintenance policy; list of authorized personnel; maintenance records or, contracts/SLAs; WebEx.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Media Protection (MP) ==&lt;br /&gt;
=== MP.L2-3.8.1 – Media Protection ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MP.L2-3.8.1_Details|&#039;&#039;&#039;MP.L2-3.8.1&#039;&#039;&#039;]] Protect (i.e., physically control and securely store) system media containing CUI, both paper and digital.&lt;br /&gt;
|-&lt;br /&gt;
| [a] paper media containing CUI is physically controlled. || Document || Policy showing CUI paper media is controlled; artifact showing who has access; artifacts/records of  inventories conducted; media check out procedures (i.e. file cabinets, encryption, password protection).&lt;br /&gt;
|-&lt;br /&gt;
| [b] digital media containing CUI is physically controlled. || Document || Policy showing CUI digital media is controlled; artifact showing who has access; artifacts/records of inventories conducted; media check out procedures (i.e. file cabinets, external drives, USBs, encryption, password protection).&lt;br /&gt;
|-&lt;br /&gt;
| [c] paper media containing CUI is securely stored. || Physical Review || Check out/sign out sheets; possible photo of storage container/video walk through of storage area; badge reader logs or access lists for keys for secured areas; interview response considered (i.e. file cabinets,  encryption, password protection).&lt;br /&gt;
|-&lt;br /&gt;
| [d] digital media containing CUI is securely stored. || Physical Review || Check out/sign out sheets; possible photo of storage container/video walk through of storage area; badge reader logs or access lists for keys for secured areas; interview response considered (i.e. file cabinets, external drives, USBs, encryption, password protection).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MP.L2-3.8.2 – Media Access ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MP.L2-3.8.2_Details|&#039;&#039;&#039;MP.L2-3.8.2&#039;&#039;&#039;]] Limit access to CUI on system media to authorized users.&lt;br /&gt;
|-&lt;br /&gt;
| [a] access to CUI on system media is limited to authorized users. || Artifact || Document describing how CUI is limited AND artifact showing principle of least access is implemented.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MP.L2-3.8.3 – Media Disposal [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MP.L2-3.8.3_Details|&#039;&#039;&#039;MP.L2-3.8.3&#039;&#039;&#039;]] Sanitize or destroy information system media containing Federal Contract Information before disposal or release for reuse.&lt;br /&gt;
|-&lt;br /&gt;
| [a] system media containing CUI is sanitized or destroyed before disposal. || Document || Policy or artifact of media destruction logs; certificates of destruction; SLAs or contracts.&lt;br /&gt;
|-&lt;br /&gt;
| [b] system media containing CUI is sanitized before it is released for reuse. || Document || Policy or artifact describing method to sanitize, software used (i.e. DoD Wipe, ShredIT and Iron Mountain; Blancco; GDisk, DBAN).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MP.L2-3.8.4 – Media Markings ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MP.L2-3.8.4_Details|&#039;&#039;&#039;MP.L2-3.8.4&#039;&#039;&#039;]] Mark media with necessary CUI markings and distribution limitations.&lt;br /&gt;
|-&lt;br /&gt;
| [a] media containing CUI is marked with applicable CUI markings. || Physical Review || Document or artifact showing CUI markings (i.e. labeling standards ).&lt;br /&gt;
|-&lt;br /&gt;
| [b] media containing CUI is marked with distribution limitations. || Physical Review || Document or artifact showing distro limitations (i.e. labeling standards ).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MP.L2-3.8.5 – Media Accountability ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MP.L2-3.8.5_Details|&#039;&#039;&#039;MP.L2-3.8.5&#039;&#039;&#039;]] Control access to media containing CUI and maintain accountability for media during transport outside of controlled areas.&lt;br /&gt;
|-&lt;br /&gt;
| [a] access to media containing CUI is controlled. || Document || Policy, artifact of audit logs showing tracking, Access Control Lists, records of transport activities (i.e. USB drives, CDs, chain of custody.&lt;br /&gt;
|-&lt;br /&gt;
| [b] accountability for media containing CUI is maintained during transport outside of controlled areas. || Artifact || Artifact of audit logs showing tracking, Access Control Lists, records of transport activities (i.e. USB drives, CDs; chain of custody.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MP.L2-3.8.6 – Portable Storage Encryption ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MP.L2-3.8.6_Details|&#039;&#039;&#039;MP.L2-3.8.6&#039;&#039;&#039;]] Implement cryptographic mechanisms to protect the confidentiality of CUI stored on digital media during transport unless otherwise protected by alternative physical safeguards.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the confidentiality of CUI stored on digital media is protected during transport using cryptographic mechanisms or alternative physical safeguards. || Artifact || Artifact showing crypto mechanisms used to protect (are they FIPS 140-2 [13.11]); artifact showing what alternative physical safeguards are in place (i.e. encryption; BitLocker; McAfee ).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MP.L2-3.8.7 – Removable Media ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MP.L2-3.8.7_Details|&#039;&#039;&#039;MP.L2-3.8.7&#039;&#039;&#039;]] Control the use of removable media on system components.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the use of removable media on system components is controlled. || Artifact || Policy showing if removable media is allowed; writable removable media is restricted; tracking artifacts; what tools are used (i.e. Carbon Black, Crowd Strike, GPO, Zoho Desktop Central); procedure/process describing what happens if it is lost; what mechanisms are in place to control/restrict removable media (i.e. Active Directory Groups and Group Policy artifact showing restriction).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MP.L2-3.8.8 – Shared Media ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MP.L2-3.8.8_Details|&#039;&#039;&#039;MP.L2-3.8.8&#039;&#039;&#039;]] Prohibit the use of portable storage devices when such devices have no identifiable owner.ASSESSMENT OBJECTIVES&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [a] the use of portable storage devices is prohibited when such devices have no identifiable owner. || Artifact || Policy and/or artifact showing company stance on portable storage devices if there is no owner (are personal USB devices allowed or are they company-issued; artifact showing alerts if device is connected to network (i.e. external HDD, Carbon Black, Crowd Strike, GPO, Zoho Desktop Central.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MP.L2-3.8.9 – Protect Backups ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MP.L2-3.8.9_Details|&#039;&#039;&#039;MP.L2-3.8.9&#039;&#039;&#039;]] Protect the confidentiality of backup CUI at storage locations.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the confidentiality of backup CUI is protected at storage locations. || Artifact || Policy on system backups; artifact showing media labeling; artifact showing encyption (is it FIPS 140-2 [13.11]); Access Control List artifact (i.e. backup tapes, Tivoli Storage Manager).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Personnel Security (PS) ==&lt;br /&gt;
=== PS.L2-3.9.1 – Screen Individuals ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_PS.L2-3.9.1_Details|&#039;&#039;&#039;PS.L2-3.9.1&#039;&#039;&#039;]] Screen individuals prior to authorizing access to organizational systems containing CUI.&lt;br /&gt;
|-&lt;br /&gt;
| [a] individuals are screened prior to authorizing access to organizational systems containing CUI. || Artifact || Screenshot of records of screened personnel/background checks.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== PS.L2-3.9.2 – Personnel Actions ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_PS.L2-3.9.2_Details|&#039;&#039;&#039;PS.L2-3.9.2&#039;&#039;&#039;]] Ensure that organizational systems containing CUI are protected during and after personnel actions such as terminations and transfers.&lt;br /&gt;
|-&lt;br /&gt;
| [a] a policy and/or process for terminating system access and any credentials coincident with personnel actions is established. || Document || Personnel security policy/procedures/instruction; Access control policy/procedure/instruction.&lt;br /&gt;
|-&lt;br /&gt;
| [b] system access and credentials are terminated consistent with personnel actions such as termination or transfer. || Artifact || Screenshot of records of personnel transfer and termination actions.&lt;br /&gt;
|-&lt;br /&gt;
| [c] the system is protected during and after personnel transfer actions. || Artifact || Completed outprocessing checklist.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Physical Protection (PE) ==&lt;br /&gt;
=== PE.L2-3.10.1 – Limit Physical Access [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_PE.L2-3.10.1_Details|&#039;&#039;&#039;PE.L2-3.10.1&#039;&#039;&#039;]] Limit physical access to organizational information systems, equipment, and the respective operating environments to authorized individuals.&lt;br /&gt;
|-&lt;br /&gt;
| [a] authorized individuals allowed physical access are identified. || Artifact || Authorized personnel (names) access list.&lt;br /&gt;
|-&lt;br /&gt;
| [b] physical access to organizational systems is limited to authorized individuals. || Physical Review || Badge reader logs, audit logs, and/or card swipe test.&lt;br /&gt;
|-&lt;br /&gt;
| [c] physical access to equipment is limited to authorized individuals. || Physical Review || Badge reader logs, audit logs, and/or card swipe test.&lt;br /&gt;
|-&lt;br /&gt;
| [d] physical access to operating environments is limited to authorized. || Physical Review || Badge reader logs, audit logs, and/or card swipe test.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== PE.L2-3.10.2 – Monitor Facility ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_PE.L2-3.10.2_Details|&#039;&#039;&#039;PE.L2-3.10.2&#039;&#039;&#039;]] Protect and monitor the physical facility and support infrastructure for organizational systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the physical facility where organizational systems reside is protected. || Physical Review || Physical security measures and barriers into the physical facility (cameras/locks/gates/guards, etc.).&lt;br /&gt;
|-&lt;br /&gt;
| [b] the support infrastructure for organizational systems is protected. || Physical Review || Physical barriers to entries into computer spaces, server rooms, etc.&lt;br /&gt;
|-&lt;br /&gt;
| [c] the physical facility where organizational systems reside is monitored. || Physical Review || Audit logs/how the physical facility is being monitored (cameras/access system/guards, etc.).&lt;br /&gt;
|-&lt;br /&gt;
| [d] the support infrastructure for organizational systems is monitored. || Physical Review || Audit logs/how the physical facility is being monitored (cameras/access system/guards, etc.).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== PE.L2-3.10.3 – Escort Visitors [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_PE.L2-3.10.3_Details|&#039;&#039;&#039;PE.L2-3.10.3&#039;&#039;&#039;]] Escort visitors and monitor visitor activity.&lt;br /&gt;
|-&lt;br /&gt;
| [a] visitors are escorted. || Physical Review || Policy/procedures/instruction on methodology for handling non-authorized personnel (entry to exit).&lt;br /&gt;
|-&lt;br /&gt;
| [b] visitor activity is monitored. || Physical Review || Policy/procedures/instructio on methodology for handling non-authorized personnel (entry to exit).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== PE.L2-3.10.4 – Physical Access Logs [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_PE.L2-3.10.4_Details|&#039;&#039;&#039;PE.L2-3.10.4&#039;&#039;&#039;]] Maintain audit logs of physical access.&lt;br /&gt;
|-&lt;br /&gt;
| [a] audit logs of physical access are maintained. || Artifact || Log or report from badging system.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== PE.L2-3.10.5 – Manage Physical Access [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_PE.L2-3.10.5_Details|&#039;&#039;&#039;PE.L2-3.10.5&#039;&#039;&#039;]] Control and manage physical access devices.&lt;br /&gt;
|-&lt;br /&gt;
| [a] physical access devices are identified. || Document || Physical access control systems description, guard force contract/policy, key locks, logical systems specifications, etc.&lt;br /&gt;
|-&lt;br /&gt;
| [b] physical access devices are controlled. || Physical Review || Inventory records of physical access control devices (e.g. keys, locks, card readers, locks, etc.).&lt;br /&gt;
|-&lt;br /&gt;
| [c] physical access devices are managed. || Physical Review || List of security safeguards controlling access to the facility (e.g. cameras, monitoring by guards, isolation of IT systems equiment and or system components).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== PE.L2-3.10.6 – Alternative Work Sites ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_PE.L2-3.10.6_Details|&#039;&#039;&#039;PE.L2-3.10.6&#039;&#039;&#039;]] Enforce safeguarding measures for CUI at alternate work sites.&lt;br /&gt;
|-&lt;br /&gt;
| [a] safeguarding measures for CUI are defined for alternate work sites. || Document || Telework agreement, Acceptable Use Policy and SOP for alternate work locations; user security training validation which includes physical/logical/technical protections of system at alternate work sites.&lt;br /&gt;
|-&lt;br /&gt;
| [b] safeguarding measures for CUI are enforced for alternate work sites. || Artifact || Monitoring/audit log of user activity and logical/physical/technical mechanisms in place to preclude unauthorized activity (telework agreement , AUP?).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Risk Assessment (RA) ==&lt;br /&gt;
=== RA.L2-3.11.1 – Risk Assessments ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_RA.L2-3.11.1_Details|&#039;&#039;&#039;RA.L2-3.11.1&#039;&#039;&#039;]] Periodically assess the risk to organizational operations (including mission, functions, image, or reputation), organizational assets, and individuals, resulting from the operation of organizational systems and the associated processing, storage, or transmission of CUI.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the frequency to assess risk to organizational operations, organizational assets, and individuals is defined. || Document || Risk assessment policy.&lt;br /&gt;
|-&lt;br /&gt;
| [b] risk to organizational operations, organizational assets, and individuals resulting from the operation of an organizational system that processes, stores, or transmits CUI is assessed with the defined frequency. || Artifact || Copy of last risk assessment done within defined frequency.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== RA.L2-3.11.2 – Vulnerability Scan ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_RA.L2-3.11.2_Details|&#039;&#039;&#039;RA.L2-3.11.2&#039;&#039;&#039;]] Scan for vulnerabilities in organizational systems and applications periodically and when new vulnerabilities affecting those systems and applications are identified.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the frequency to scan for vulnerabilities in organizational systems and applications is defined. || Document || Policy/procedures/instruction addressing vulnerability scanning records.&lt;br /&gt;
|-&lt;br /&gt;
| [b] vulnerability scans are performed on organizational systems with the defined frequency. || Screen Share || System configuration settings of vulnerability scanning scheduling and vulnerability scan results of systems within defined frequency.&lt;br /&gt;
|-&lt;br /&gt;
| [c] vulnerability scans are performed on applications with the defined frequency. || Screen Share || System configuration settings of vulnerability scanning scheduling and vulnerability scan results of applications within defined frequency.&lt;br /&gt;
|-&lt;br /&gt;
| [d] vulnerability scans are performed on organizational systems when new vulnerabilities are identified. || Screen Share || View signatures in scanning tool/ad hoc scan performed as a result.&lt;br /&gt;
|-&lt;br /&gt;
| [e] vulnerability scans are performed on applications when new vulnerabilities are identified. || Screen Share || View signatures in scanning tool/ad hoc scan performed as a result.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== RA.L2-3.11.3 – Vulnerability Remediation ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_RA.L2-3.11.3_Details|&#039;&#039;&#039;RA.L2-3.11.3&#039;&#039;&#039;]] Remediate vulnerabilities in accordance with risk assessments.&lt;br /&gt;
|-&lt;br /&gt;
| [a] vulnerabilities are identified. || Artifact || Scan results showing vulnerabilities identified.&lt;br /&gt;
|-&lt;br /&gt;
| [b] vulnerabilities are remediated in accordance with risk assessments. || Artifact || Screenshot/document of scan results of remediated vulnerabilities in accordance to risk assessments.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Security Assessment (CA) ==&lt;br /&gt;
=== CA.L2-3.12.1 – Security Control Assessment ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_CA.L2-3.12.1_Details|&#039;&#039;&#039;CA.L2-3.12.1&#039;&#039;&#039;]] Periodically assess the security controls in organizational systems to determine if the controls are effective in their application.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the frequency of security control assessments is defined. || Document || SSP.&lt;br /&gt;
|-&lt;br /&gt;
| [b] security controls are assessed with the defined frequency to determine if the controls are effective in their application. || Artifact || Copy of last security control assessment done within defined frequency.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== CA.L2-3.12.2 – Operational Plan of Action ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_CA.L2-3.12.2_Details|&#039;&#039;&#039;CA.L2-3.12.2&#039;&#039;&#039;]] Develop and implement plans of action designed to correct deficiencies and reduce or eliminate vulnerabilities in organizational systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] deficiencies and vulnerabilities to be addressed by the plan of action are identified. || Artifact || Plan of Action (POA).&lt;br /&gt;
|-&lt;br /&gt;
| [b] a plan of action is developed to correct identified deficiencies and reduce or eliminate identified vulnerabilities. || Artifact || Plan of Action (POA).&lt;br /&gt;
|-&lt;br /&gt;
| [c] the plan of action is implemented to correct identified deficiencies and reduce or eliminate identified vulnerabilities. || Artifact || Plan of Action (POA)/previously completed POAs.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== CA.L2-3.12.3 – Security Control Monitoring ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_CA.L2-3.12.3_Details|&#039;&#039;&#039;CA.L2-3.12.3&#039;&#039;&#039;]] Monitor security controls on an ongoing basis to ensure the continued effectiveness of the controls.&lt;br /&gt;
|-&lt;br /&gt;
| [a] security controls are monitored on an ongoing basis to ensure the continued effectiveness of those controls. || Artifact || Collection of risk assessment results, internal or third-party audits/security assessments and/or continuous monitoring reports/alerts (SIEM tool, etc.).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== CA.L2-3.12.4 – System Security Plan ====&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_CA.L2-3.12.4_Details|&#039;&#039;&#039;CA.L2-3.12.4&#039;&#039;&#039;]] Develop, document, and periodically update system security plans that describe system boundaries, system environments of operation, how security requirements are implemented, and the relationships with or connections to other systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] a system security plan is developed. || Document || SSP.&lt;br /&gt;
|-&lt;br /&gt;
| [b] the system boundary is described and documented in the system security plan. || Document || SSP and any supporting documentation.&lt;br /&gt;
|-&lt;br /&gt;
| [c] the system environment of operation is described and documented in the system security plan. || Document || SSP and any supporting documentation.&lt;br /&gt;
|-&lt;br /&gt;
| [d] the security requirements identified and approved by the designated authority as non-applicable are identified. || Document || SSP and required adjudication from DoD CIO.&lt;br /&gt;
|-&lt;br /&gt;
| [e] the method of security requirement implementation is described and documented in the system security plan. || Document || SSP and any supporting documentation.&lt;br /&gt;
|-&lt;br /&gt;
| [f] the relationship with or connection to other systems is described and documented in the system security plan. || Document || SSP and any supporting documentation.&lt;br /&gt;
|-&lt;br /&gt;
| [g] the frequency to update the system security plan is defined. || Document || SSP.&lt;br /&gt;
|-&lt;br /&gt;
| [h] system security plan is updated with the defined frequency. || Document || SSP/any previous versions.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== System and Communications Protection (SC) ==&lt;br /&gt;
=== SC.L2-3.13.1 – Boundary Protection [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.1_Details|&#039;&#039;&#039;SC.L2-3.13.1&#039;&#039;&#039;]] Monitor, control, and protect organizational communications (i.e., information transmitted or received by organizational information systems) at the external boundaries and key internal boundaries of the information systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the external system boundary is defined. || Document || SSP, network diagrams, CUI flow, cloud provider FedRAMP Moderate.&lt;br /&gt;
|-&lt;br /&gt;
| [b] key internal system boundaries are defined. || Document || SSP, network diagrams, CUI flow.&lt;br /&gt;
|-&lt;br /&gt;
| [c] communications are monitored at the external system boundary. || Screen Share || SSP, logging server, boundary device configurations, monitoring policy.&lt;br /&gt;
|-&lt;br /&gt;
| [d] communications are monitored at key internal boundaries. || Screen Share || SSP, logging server, boundary device configurations, monitoring policy.&lt;br /&gt;
|-&lt;br /&gt;
| [e] communications are controlled at the external system boundary. || Screen Share || SSP, boundary device configurations, ACL, subnets, DMZ.&lt;br /&gt;
|-&lt;br /&gt;
| [f] communications are controlled at key internal boundaries. || Screen Share || SSP, boundary device configurations, ACL, subnets.&lt;br /&gt;
|-&lt;br /&gt;
| [g] communications are protected at the external system boundary. || Screen Share || Configurations for IPS/IDS, email gateway, VLAN, proxy, firewall, malware protection, DNS, TSL.&lt;br /&gt;
|-&lt;br /&gt;
| [h] communications are protected at key internal boundaries. || Screen Share || Configurations for IPS/IDS, VLAN, firewall, malware protection, SSL.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.2 – Security Engineering ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.2_Details|&#039;&#039;&#039;SC.L2-3.13.2&#039;&#039;&#039;]] Employ architectural designs, software development techniques, and systems engineering principles that promote effective information security within organizational systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] architectural designs that promote effective information security are identified. || Document || SSP, config management policy, network diagram, CCB minutes, enterprise architecture process.&lt;br /&gt;
|-&lt;br /&gt;
| [b] software development techniques that promote effective information security are identified. || Document || SSP, config management policy, SDLC, CCB minutes.&lt;br /&gt;
|-&lt;br /&gt;
| [c] systems engineering principles that promote effective information security are identified. || Document || SSP, config management policy, CCB minutes, security architecture engineering.&lt;br /&gt;
|-&lt;br /&gt;
| [d] identified architectural designs that promote effective information security are employed. || Artifact || CCB minutes, Network diagrams and configurations, Project Plans.&lt;br /&gt;
|-&lt;br /&gt;
| [e] identified software development techniques that promote effective information security are employed. || Artifact || CCB minutes, SDLC, code scanner results, code management tracking.&lt;br /&gt;
|-&lt;br /&gt;
| [f] identified systems engineering principles that promote effective information security are employed. || Artifact || CCB minutes, configuration management, ITSM, patch management, lifecycle replacement processes.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.3 – Role Separation ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.3_Details|&#039;&#039;&#039;SC.L2-3.13.3&#039;&#039;&#039;]] Separate user functionality from system management functionality.&lt;br /&gt;
|-&lt;br /&gt;
| [a] user functionality is identified. || Document || SSP, AUP.&lt;br /&gt;
|-&lt;br /&gt;
| [b] system management functionality is identified. || Document || SSP, Privileged Account Agreement.&lt;br /&gt;
|-&lt;br /&gt;
| [c] user functionality is separated from system management functionality. || Screen Share || Active Directory, Jump Boxes, GPO, VM, RDP.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.4 – Shared Resource Control ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.4_Details|&#039;&#039;&#039;SC.L2-3.13.4&#039;&#039;&#039;]] Prevent unauthorized and unintended information transfer via shared system resources.&lt;br /&gt;
|-&lt;br /&gt;
| [a] unauthorized and unintended information transfer via shared system resources is prevented. || Screen Share || SSP, OS configurations, Linux containers, system/media reuse policies, certificate management policies, media destruction policies, printer configs, VDI configuration.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
===  SC.L2-3.13.5 – Public-Access System Separation [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.5_Details|&#039;&#039;&#039;SC.L2-3.13.5&#039;&#039;&#039;]] Implement subnetworks for publicly accessible system components that are physically or logically separated from internal networks.&lt;br /&gt;
|-&lt;br /&gt;
| [a] publicly accessible system components are identified. || Document || SSP, network diagram, DMZ inventory/roles.&lt;br /&gt;
|-&lt;br /&gt;
| [b] subnetworks for publicly accessible system components are physically or logically separated from internal networks. || Artifact || Network diagram, IPAM, VLAN, DHCP, DMZ.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.6 – Network Communication by Exception ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.6_Details|&#039;&#039;&#039;SC.L2-3.13.6&#039;&#039;&#039;]] Deny network communications traffic by default and allow network communications traffic by exception (i.e., deny all, permit by exception).&lt;br /&gt;
|-&lt;br /&gt;
| [a] network communications traffic is denied by default. || Screen Share || Host and network firewall rules, SIEM logs, hit counts.&lt;br /&gt;
|-&lt;br /&gt;
| [b] network communications traffic is allowed by exception. || Screen Share || Host and network firewall rules, SIEM logs, hit counts.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.7 – Split Tunneling ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.7_Details|&#039;&#039;&#039;SC.L2-3.13.7&#039;&#039;&#039;]] Prevent remote devices from simultaneously establishing non-remote connections with organizational systems and communicating via some other connection to resources in external networks (i.e., split tunneling).&lt;br /&gt;
|-&lt;br /&gt;
| [a] remote devices are prevented from simultaneously establishing non-remote connections with the system and communicating via some other connection to resources in external networks (i.e., split tunneling). || Screen Share || VPN appliance/server configuration, endpoint VPN software configuration.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.8 – Data in Transit ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.8_Details|&#039;&#039;&#039;SC.L2-3.13.8&#039;&#039;&#039;]] Implement cryptographic mechanisms to prevent unauthorized disclosure of CUI during transmission unless otherwise protected by alternative physical safeguards.&lt;br /&gt;
|-&lt;br /&gt;
| [a] cryptographic mechanisms intended to prevent unauthorized disclosure of CUI are identified. || Document || SSP, PKI policies, configuration processes, config management, email attachment encryption policy, removable media policy, data at rest policy.&lt;br /&gt;
|-&lt;br /&gt;
| [b] alternative physical safeguards intended to prevent unauthorized disclosure of CUI are identified. || Document || SSP, physical security policy.&lt;br /&gt;
|-&lt;br /&gt;
| [c] either cryptographic mechanisms or alternative physical safeguards are implemented to prevent unauthorized disclosure of CUI during transmission. || Screen Share || TLS settings, SSL settings, VPN/Wireless Access Points/Mobile Devices cryptographic settings, ODBC connector settings, SAN configuration, IPSec/MPLS, backup configuration, physical security.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.9 – Connections Termination ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.9_Details|&#039;&#039;&#039;SC.L2-3.13.9&#039;&#039;&#039;]] Terminate network connections associated with communications sessions at the end of the sessions or after a defined period of inactivity.&lt;br /&gt;
|-&lt;br /&gt;
| [a] a period of inactivity to terminate network connections associated with communications sessions is defined. || Document || SSP, network communications policy.&lt;br /&gt;
|-&lt;br /&gt;
| [b] network connections associated with communications sessions are terminated at the end of the sessions. || Screen Share || VPN appliance/server logs, VPN configurations, web server configurations, firewall connection settings.&lt;br /&gt;
|-&lt;br /&gt;
| [c] network connections associated with communications sessions are terminated after the defined period of inactivity. || Artifact || VPN appliance/server logs, VPN configurations, web server configurations, frewall connection settings.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.10 – Key Management ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.10_Details|&#039;&#039;&#039;SC.L2-3.13.10&#039;&#039;&#039;]] Establish and manage cryptographic keys for cryptography employed in organizational systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] cryptographic keys are established whenever cryptography is employed. || Artifact || SSP, PKI/certificate management policy, configuration management.&lt;br /&gt;
|-&lt;br /&gt;
| [b] cryptographic keys are managed whenever cryptography is employed. || Artifact || SSP, PKI/certificate management policy, configuration management, access control policy.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.11 – CUI Encryption ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.11_Details|&#039;&#039;&#039;SC.L2-3.13.11&#039;&#039;&#039;]] Employ FIPS-validated cryptography when used to protect the confidentiality of CUI.&lt;br /&gt;
|-&lt;br /&gt;
| [a] FIPS-validated cryptography is employed to protect the confidentiality of CUI. || Screen Share || VPN, wireless, mobile devices, client certificates, server certificates, disk encryption, Outlook plugin, external mail, backup media, ePO server, removable storage, SAN, file compression; look for FIPS mode enabled on appliances.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.12 – Collaborative Device Control ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.12_Details|&#039;&#039;&#039;SC.L2-3.13.12&#039;&#039;&#039;]] Prohibit remote activation of collaborative computing devices and provide indication of devices in use to users present at the device.&lt;br /&gt;
|-&lt;br /&gt;
| [a] collaborative computing devices are identified. || Document || SSP, network diagrams.&lt;br /&gt;
|-&lt;br /&gt;
| [b] collaborative computing devices provide indication to users of devices in use. || Physical Review || Physical inspection of device.&lt;br /&gt;
|-&lt;br /&gt;
| [c] remote activation of collaborative computing devices is prohibited. || Screen Share || Collaboration device configuration/console.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.13 – Mobile Code ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.13_Details|&#039;&#039;&#039;SC.L2-3.13.13&#039;&#039;&#039;]] Control and monitor the use of mobile code.&lt;br /&gt;
|-&lt;br /&gt;
| [a] use of mobile code is controlled. || Screen Share || GPO settings, malware protection, software agent configurations, software development policies, code scanners, MDM configuration, firewall/secure web gateway/proxy config.&lt;br /&gt;
|-&lt;br /&gt;
| [b] use of mobile code is monitored. || Screen Share || SIEM/console monitoring.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.14 – Voice over Internet Protocol ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.14_Details|&#039;&#039;&#039;SC.L2-3.13.14&#039;&#039;&#039;]] Control and monitor the use of Voice over Internet Protocol (VoIP) technologies.&lt;br /&gt;
|-&lt;br /&gt;
| [a] use of Voice over Internet Protocol (VoIP) technologies is controlled. || Artifact || VLAN, ACL, firewall config, VoIP gateway/condenser configuration.&lt;br /&gt;
|-&lt;br /&gt;
| [b] use of Voice over Internet Protocol (VoIP) technologies is monitored. || Artifact || SIEM/VoIP console monitoring, session border controller.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.15 – Communications Authenticity ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.15_Details|&#039;&#039;&#039;SC.L2-3.13.15&#039;&#039;&#039;]] Protect the authenticity of communications sessions.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the authenticity of communications sessions is protected. || Screen Share || SSL, TLS, SMB3, SFTP, IPSec, SSH, Kerberos configs, MPLS, Network Access Control.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.16 – Data at Rest ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.16_Details|&#039;&#039;&#039;SC.L2-3.13.16&#039;&#039;&#039;]] Protect the confidentiality of CUI at rest.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the confidentiality of CUI at rest is protected. || Artifact || Full disk encryption, removable media encryption, SAN encryption, digital backups, mobile device encryption, third party offsite backup storage, cloud virtualization encryption, physical media storage policies.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== System and Information Integrity (SI) ==&lt;br /&gt;
=== SI.L2-3.14.1 – Flaw Remediation [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SI.L2-3.14.1_Details|&#039;&#039;&#039;SI.L2-3.14.1&#039;&#039;&#039;]] Identify, report, and correct information and information system flaws in a timely manner.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the time within which to identify system flaws is specified. || Document || SSP, patch management policy.&lt;br /&gt;
|-&lt;br /&gt;
| [b] system flaws are identified within the specified time frame. || Screen Share || Vulnerability management scanner output and scan policy configuration.&lt;br /&gt;
|-&lt;br /&gt;
| [c] the time within which to report system flaws is specified. || Document || SSP, patch management policy.&lt;br /&gt;
|-&lt;br /&gt;
| [d] system flaws are reported within the specified time frame. || Screen Share || ITSM/trouble tickets, vulnerability management scanner output.&lt;br /&gt;
|-&lt;br /&gt;
| [e] the time within which to correct system flaws is specified. || Document || SSP, patch management policy.&lt;br /&gt;
|-&lt;br /&gt;
| [f] system flaws are corrected within the specified time frame. || Screen Share || Vulnerability management scanner output and scan policy configuration.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SI.L2-3.14.2 – Malicious Code ProTection [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SI.L2-3.14.2_Details|&#039;&#039;&#039;SI.L2-3.14.2&#039;&#039;&#039;]] Provide protection from malicious code at appropriate locations within organizational information systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] designated locations for malicious code protection are identified. || Document || SSP, system protection policy, network diagrams, security architecture documents.&lt;br /&gt;
|-&lt;br /&gt;
| [b] protection from malicious code at designated locations is provided. || Screen Share || Endpoint security settings, email/web proxy gateways, firewall, IPS sensor, MDM configuration, Network Access Control.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SI.L2-3.14.3 – Security Alerts &amp;amp; Advisories ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SI.L2-3.14.3_Details|&#039;&#039;&#039;SI.L2-3.14.3&#039;&#039;&#039;]] Monitor system security alerts and advisories and take action in response.&lt;br /&gt;
|-&lt;br /&gt;
| [a] response actions to system security alerts and advisories are identified. || Document || SSP, vulnerability management policy, Incident Response Plan.&lt;br /&gt;
|-&lt;br /&gt;
| [b] system security alerts and advisories are monitored. || Artifact || Threat intelligence subscriptions, email advisories.&lt;br /&gt;
|-&lt;br /&gt;
| [c] actions in response to system security alerts and advisories are taken. || Artifact || ITSM/trouble tickets, user notifications, updates to firewall/IPS, etc.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SI.L2-3.14.4 – Update Malicious Code Protection [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SI.L2-3.14.4_Details|&#039;&#039;&#039;SI.L2-3.14.4&#039;&#039;&#039;]] Update malicious code protection mechanisms when new releases are available.&lt;br /&gt;
|-&lt;br /&gt;
| [a] malicious code protection mechanisms are updated when new releases are available. || Screen Share || Antivirus console dashboard, firewall AV, Email gateway signatures,proxy, IPS updates.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SI.L2-3.14.5 – System &amp;amp; File Scanning [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SI.L2-3.14.5_Details|&#039;&#039;&#039;SI.L2-3.14.5&#039;&#039;&#039;]] Perform periodic scans of the information system and real-time scans of files from external sources as files are downloaded, opened, or executed.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the frequency for malicious code scans is defined. || Document || SSP, vulnerability management policy.&lt;br /&gt;
|-&lt;br /&gt;
| [b] malicious code scans are performed with the defined frequency. || Screen Share || Consoles for AV (endpoints, servers, and file shares), firewall, email gateway, proxy, IPS, MDM configurations.&lt;br /&gt;
|-&lt;br /&gt;
| [c] real-time malicious code scans of files from external sources as files are downloaded, opened, or executed are performed. || Screen Share || Consoles for AV (endpoints, servers, and file shares), firewall, email gateway, proxy, IPS, MDM configurations.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SI.L2-3.14.6 – Monitor Communications for Attacks ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SI.L2-3.14.6_Details|&#039;&#039;&#039;SI.L2-3.14.6&#039;&#039;&#039;]] Monitor organizational systems, including inbound and outbound communications traffic, to detect attacks and indicators of potential attacks.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the system is monitored to detect attacks and indicators of potential attacks. || Screen Share || Firewall, IPS, endpoint protection, SIEM alerts and reports.&lt;br /&gt;
|-&lt;br /&gt;
| [b] inbound communications traffic is monitored to detect attacks and indicators of potential attacks. || Screen Share || Firewall, IPS, endpoint protection, SIEM alerts and reports.&lt;br /&gt;
|-&lt;br /&gt;
| [c] outbound communications traffic is monitored to detect attacks and indicators of potential attacks. || Screen Share || Firewall, IPS, endpoint protection, SIEM alerts and reports.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SI.L2-3.14.7 – Identify Unauthorized Use ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SI.L2-3.14.7_Details|&#039;&#039;&#039;SI.L2-3.14.7&#039;&#039;&#039;]] Identify unauthorized use of organizational systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] authorized use of the system is defined. || Document || AUP, SSP.&lt;br /&gt;
|-&lt;br /&gt;
| [b] unauthorized use of the system is identified. || Artifact || SIEM logs, endpoint protection console, IPS, Firewall.&lt;br /&gt;
|}&lt;/div&gt;</summary>
		<author><name>David</name></author>
	</entry>
	<entry>
		<id>https://cmmcwiki.org/index.php?title=Evidence_Collection_Approach&amp;diff=1624</id>
		<title>Evidence Collection Approach</title>
		<link rel="alternate" type="text/html" href="https://cmmcwiki.org/index.php?title=Evidence_Collection_Approach&amp;diff=1624"/>
		<updated>2026-07-20T01:42:47Z</updated>

		<summary type="html">&lt;p&gt;David: /* IA.L2-3.5.6 – Identifier Handling */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;CMMC assessments and certification require substantial evidence and documentation. The following tables outline general guidelines for collecting evidence to assess control requirements and objectives. While these guidelines provide a structured approach, they are not the only means of conducting an accurate assessment. Assessors should exercise professional judgment and may employ alternative methods appropriate to the specific organizational context and circumstances.&lt;br /&gt;
&lt;br /&gt;
Evidence collection approaches are defined as:&lt;br /&gt;
* &#039;&#039;&#039;Documentation&#039;&#039;&#039;: Tangible materials containing information over which an organization has authority, including all types of written records and their copies.&lt;br /&gt;
* &#039;&#039;&#039;Artifacts&#039;&#039;&#039;: Tangible, reviewable records directly resulting from a practice or process being performed by a system or by personnel executing their role within that practice, control, or process.&lt;br /&gt;
* &#039;&#039;&#039;Physical Review&#039;&#039;&#039;: Direct on-site observation and examination of evidence.&lt;br /&gt;
* &#039;&#039;&#039;Screen Share&#039;&#039;&#039;: Real-time remote observation of a user demonstrating a task or process via shared computer screen, sometimes called &amp;quot;over-the-shoulder&amp;quot; review.&lt;br /&gt;
&lt;br /&gt;
DISCLAIMER: Evidence requirements vary significantly across assessment types. &#039;&#039;&#039;The examples provided are illustrative only and should be tailored to meet the specific adequacy and sufficiency standards of your particular assessment context.&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
For inquiries and reporting errors on this wiki, please [mailto:support@cmmctoolkit.org contact us]. Thank you.&lt;br /&gt;
&lt;br /&gt;
== Access Control (AC) ==&lt;br /&gt;
=== AC.L2-3.1.1 – Authorized Access Control [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.1_Details|&#039;&#039;&#039;AC.L2-3.1.1&#039;&#039;&#039;]] Limit information system access to authorized users, processes acting on behalf of authorized users, or devices (including other information systems).&lt;br /&gt;
|-&lt;br /&gt;
| [a] authorized users are identified. || Document || Document defining account request, approval, provisioning.&lt;br /&gt;
|-&lt;br /&gt;
| [b] processes acting on behalf of authorized users are identified. || Document || Document defining account request, approval, provisioning.&lt;br /&gt;
|-&lt;br /&gt;
| [c] devices (and other systems) authorized to connect to the system are identified. || Document || Document defining account request, approval, provisioning.&lt;br /&gt;
|-&lt;br /&gt;
| [d] system access is limited to authorized users. || Screen Share || Screen share showing login requirements are enforced. Example of an unauthorized user denied (unauthorized username entered at login).&lt;br /&gt;
|-&lt;br /&gt;
| [e] system access is limited to processes acting on behalf of authorized users. || Screen Share || Screenshot showing that service accounts are assigned to authorized users only; no rogue accounts without an authorized user are active.&lt;br /&gt;
|-&lt;br /&gt;
| [f] system access is limited to authorized devices (including other systems). || Screen Share || Screen share showing that all devices running are authorized; no rogue devices on the network.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.2 – Transaction &amp;amp; Function Control [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.2_Details|&#039;&#039;&#039;AC.L2-3.1.2&#039;&#039;&#039;]] Limit information system access to the types of transactions and functions that authorized users are permitted to execute.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the types of transactions and functions that authorized users are permitted to execute are defined. || Document || SSP, AUP, or IAM document that defines what authorized users can execute.&lt;br /&gt;
|-&lt;br /&gt;
| [b] system access is limited to the defined types of transactions and functions for authorized users. || Screen Share || Screenshot of security roles in AD or IAM or other directory-based identity-related services tool that shows transactions are as defined in the SSP or IAM document; privileged and non-privileged accounts need to be defined and identified in the artifact; screenshot of a non-privileged user trying to execute a privileged function.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.3 – Control CUI Flow ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.3_Details|&#039;&#039;&#039;AC.L2-3.1.3&#039;&#039;&#039;]] Control the flow of CUI in accordance with approved authorizations.&lt;br /&gt;
|-&lt;br /&gt;
| [a] information flow control policies are defined. || Document || SSP or other document describing the control of CUI on the network.&lt;br /&gt;
|-&lt;br /&gt;
| [b] methods and enforcement mechanisms for controlling the flow of CUI are defined. || Document || Document that defines the networking devices that are on the CUI network and answers what measures are in place to control the flow. List of firewalls, border and internal layer 3 devices, IDS/IPS, DLP, that process CUI.&lt;br /&gt;
|-&lt;br /&gt;
| [c] designated sources and destinations (e.g., networks, individuals, and devices) for CUI within the system and between interconnected systems are identified. || Artifact || Network diagram, data flow diagram, external system connection diagrams, document describing the policies for CUI on the network; listing of VLANs and subnets where CUI is authorized; document must describe source and authorized destinations.&lt;br /&gt;
|-&lt;br /&gt;
| [d] authorizations for controlling the flow of CUI are defined. || Document || Document that defines how CUI is to be controlled, such as an InfoSec plan, and/or network management plan.&lt;br /&gt;
|-&lt;br /&gt;
| [e] approved authorizations for controlling the flow of CUI are enforced. || Screen Share || Screenshots of firewall rules, ACLs, etc.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.4 – Separation of Duties ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.4_Details|&#039;&#039;&#039;AC.L2-3.1.4&#039;&#039;&#039;]] Separate the duties of individuals to reduce the risk of malevolent activity without collusion.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the duties of individuals requiring separation are defined. || Document || Document, SSP, account management policy, defining separation of duties by person or role.&lt;br /&gt;
|-&lt;br /&gt;
| [b] responsibilities for duties that require separation are assigned to separate individuals. || Screen Share || Screenshot showing that separation of duties is enforced by showing admin accounts are assigned to different people based on role.&lt;br /&gt;
|-&lt;br /&gt;
| [c] access privileges that enable individuals to exercise the duties that require separation are granted to separate individuals. || Screen Share || Screen shot showing an example such as a security manager can not log into a network device and change ACLs, or network admins can not access security logs in the SIEM tool.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.5 – Least Privilege ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.5_Details|&#039;&#039;&#039;AC.L2-3.1.5&#039;&#039;&#039;]] Employ the principle of least privilege, including for specific security functions and privileged accounts.&lt;br /&gt;
|-&lt;br /&gt;
| [a] privileged accounts are identified. || Document || &amp;quot;SSP or policy (documentation) identify what is considered a privileged account.&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| [b] access to privileged accounts is authorized in accordance with the principle of least privilege. || Artifact || An artifact that identifies the least amount of permissions associated with different types of privileged accounts are approved.&lt;br /&gt;
|-&lt;br /&gt;
| [c] security functions are identified. || Document || &amp;quot;SSP or policy (documentation) identifies what is considered a security account.&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| [d] access to security functions is authorized in accordance with the principle of least privilege. || Artifact || Artifact(s) that identify the least amount of permissions associated with different types of security accounts are approved.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.6 – Non-Privileged Account Use ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.6_Details|&#039;&#039;&#039;AC.L2-3.1.6&#039;&#039;&#039;]] Use non-privileged accounts or roles when accessing nonsecurity functions.&lt;br /&gt;
|-&lt;br /&gt;
| [a] nonsecurity functions are identified. || Document || SSP or account management document, AUP, that defines non-security functions.&lt;br /&gt;
|-&lt;br /&gt;
| [b] users are required to use non-privileged accounts or roles when accessing nonsecurity functions. || Screen Share || Screenshot showing that a privileged user tried to use their admin account to access a non-security function, such as a browser or email (whatever is defined in their policy) and was blocked.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.7 – Privileged Functions ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.7_Details|&#039;&#039;&#039;AC.L2-3.1.7&#039;&#039;&#039;]] Prevent non-privileged users from executing privileged functions and capture the execution of such functions in audit logs.&lt;br /&gt;
|-&lt;br /&gt;
| [a] privileged functions are defined. || Document || SSP or policy (documentation) that defines privileged functions.&lt;br /&gt;
|-&lt;br /&gt;
| [b] non-privileged users are defined. || Document || SSP or policy (documentation) that defines non-privileged users.&lt;br /&gt;
|-&lt;br /&gt;
| [c] non-privileged users are prevented from executing privileged functions. || Screen Share || Screen share that shows that a non-privileged user is not allowed to complete a privileged function (installing software).&lt;br /&gt;
|-&lt;br /&gt;
| [d] the execution of privileged functions is captured in audit logs. || Screen Share || Screen share that shows logs being captured of the execution of privileged functions.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.8 – Unsuccessful Logon Attempts ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.8_Details|&#039;&#039;&#039;AC.L2-3.1.8&#039;&#039;&#039;]] Limit unsuccessful logon attempts.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the means of limiting unsuccessful logon attempts is defined. || Document || SSP or policy (documentation) showing unsuccessful logon attempts settings and or policy.&lt;br /&gt;
|-&lt;br /&gt;
| [b] the defined means of limiting unsuccessful logon attempts is implemented. || Artifact || Artifact showing GPO / Policy for limiting logon attempts.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.9 – Privacy &amp;amp; Security Notices ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.9_Details|&#039;&#039;&#039;AC.L2-3.1.9&#039;&#039;&#039;]] Provide privacy and security notices consistent with applicable CUI rules.&lt;br /&gt;
|-&lt;br /&gt;
| [a] privacy and security notices required by CUI-specified rules are identified, consistent, and associated with the specific CUI category. || Document || SSP or policy (documentation) showing CUI-specified rules are identified, consistent, and associated with the specific CUI category.&lt;br /&gt;
|-&lt;br /&gt;
| [b] privacy and security notices are displayed. || Artifact || Artifact that shows a consent banner or screen that a user sees as they log in to the system.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.10 – Session Lock ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.10_Details|&#039;&#039;&#039;AC.L2-3.1.10&#039;&#039;&#039;]] Use session lock with pattern-hiding displays to prevent access and viewing of data after a period of inactivity.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the period of inactivity after which the system initiates a session lock is defined. || Document || SSP or policy (documentation) that defines the period of inactivity and when a session lock is defined.&lt;br /&gt;
|-&lt;br /&gt;
| [b] access to the system and viewing of data is prevented by initiating a session lock after the defined period of inactivity. || Artifact || Artifact that shows the setting of session lock (GPO or system policy or similar solution addressing the controls supporting centralized management and configuration of operating systems, applications, and users&#039; settings for the working environment of user accounts and computer accounts).&lt;br /&gt;
|-&lt;br /&gt;
| [c] previously visible information is concealed via a pattern-hiding display after the defined period of inactivity. || Document || Screenshot of GPO setting and configuration settings, or similar solution addressing the controls supporting centralized management and configuration of operating systems, applications, and users&#039; settings for the working environment of user accounts and computer accounts.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.11 – Session Termination ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.11_Details|&#039;&#039;&#039;AC.L2-3.1.11&#039;&#039;&#039;]] Terminate (automatically) a user session after a defined condition.&lt;br /&gt;
|-&lt;br /&gt;
| [a] conditions requiring a user session to terminate are defined. || Document || SSP or policy (documentation) that defines the conditions requiring a user session to be terminated.&lt;br /&gt;
|-&lt;br /&gt;
| [b] a user session is automatically terminated after any of the defined conditions. || Screen Share || Screen share showing GPO / VPN Settings that show when a session would be terminated (Idle time, max connection time).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.12 – Control Remote Access ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.12_Details|&#039;&#039;&#039;AC.L2-3.1.12&#039;&#039;&#039;]] Monitor and control remote access sessions.&lt;br /&gt;
|-&lt;br /&gt;
| [a] remote access sessions are permitted. || Document || SSP or policy (documentation) that defines remote access sessions.&lt;br /&gt;
|-&lt;br /&gt;
| [b] the types of permitted remote access are identified. || Document || SSP or policy (documentation) that defines remote access is permitted.&lt;br /&gt;
|-&lt;br /&gt;
| [c] remote access sessions are controlled. || Screen Share || Screen share that shows how the remote access is controlled (access session, and or groups).&lt;br /&gt;
|-&lt;br /&gt;
| [d] remote access sessions are monitored. || Screen Share || Screen share that shows how remote sessions are monitored (logs).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.13 – Remote Access Confidentiality ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.13_Details|&#039;&#039;&#039;AC.L2-3.1.13&#039;&#039;&#039;]] Employ cryptographic mechanisms to protect the confidentiality of remote access sessions.&lt;br /&gt;
|-&lt;br /&gt;
| [a] cryptographic mechanisms to protect the confidentiality of remote access sessions are identified. || Document || SSP or policy (documentation) that discusses the CUI rules, consistent, and associated with the specific CUI category; FIPS Cert # of appliance or application.&lt;br /&gt;
|-&lt;br /&gt;
| [b] cryptographic mechanisms to protect the confidentiality of remote access sessions are implemented. || Screen Share || Screenshot of VPN concentration that shows encryption is on and enabled (point-to-point, etc.).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.14 – Remote Access Routing ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.14_Details|&#039;&#039;&#039;AC.L2-3.1.14&#039;&#039;&#039;]] Route remote access via managed access control points.&lt;br /&gt;
|-&lt;br /&gt;
| [a] managed access control points are identified and implemented. || Screen Share || Screen share that shows access control points (groups and/or users).&lt;br /&gt;
|-&lt;br /&gt;
| [b] remote access is routed through managed network access control points. || Screen Share || Screen share that shows access control points and how they are managed.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.15 – Privileged Remote Access ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.15_Details|&#039;&#039;&#039;AC.L2-3.1.15&#039;&#039;&#039;]] Authorize remote execution of privileged commands and remote access to security-relevant information.&lt;br /&gt;
|-&lt;br /&gt;
| [a] privileged commands authorized for remote execution are identified. || Document || SSP or policy (documentation) that defines what is authorized to be executed remotely and how that is handled.&lt;br /&gt;
|-&lt;br /&gt;
| [b] security-relevant information authorized to be accessed remotely is identified. || Document || SSP or policy (documentation) that defines what can be accessed remotely and what procedures are implemented to allow this (RDP, jump box).&lt;br /&gt;
|-&lt;br /&gt;
| [c] the execution of the identified privileged commands via remote access is authorized. || Artifact || Screen share that shows who has access to perform privileged commands a remotely (access groups for privileged accounts).&lt;br /&gt;
|-&lt;br /&gt;
| [d] access to the identified security-relevant information via remote access is authorized. || Artifact || Screen share that shows the routing of remote access and how it is monitored and how many locations (Firewall, VPN Concentrator).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.16 – Wireless Access Authorization ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.16_Details|&#039;&#039;&#039;AC.L2-3.1.16&#039;&#039;&#039;]] Authorize wireless access prior to allowing such connections.&lt;br /&gt;
|-&lt;br /&gt;
| [a] wireless access points are identified. || Document || SSP, network administration document.&lt;br /&gt;
|-&lt;br /&gt;
| [b] wireless access is authorized prior to allowing such connections. || Screen Share || Authorization profile(s) in Wireless Access Controller or Identity Manager (i.e. Cisco ISE).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.17 – Wireless Access Protection ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.17_Details|&#039;&#039;&#039;AC.L2-3.1.17&#039;&#039;&#039;]] Protect wireless access using authentication and encryption.&lt;br /&gt;
|-&lt;br /&gt;
| [a] wireless access to the system is protected using authentication. || Screen Share || Security page (or similar) of a Wireless Access Controller.&lt;br /&gt;
|-&lt;br /&gt;
| [b] wireless access to the system is protected using encryption. || Screen Share || Security page (or similar) of a Wireless Access Controller.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.18 – Mobile Device Connection ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.18_Details|&#039;&#039;&#039;AC.L2-3.1.18&#039;&#039;&#039;]] Control connection of mobile devices.&lt;br /&gt;
|-&lt;br /&gt;
| [a] mobile devices that process, store, or transmit CUI are identified. || Document || SSP, Mobile Device Policy.&lt;br /&gt;
|-&lt;br /&gt;
| [b] mobile device connections are authorized. || Artifact || Authorization profile(s) in Wireless Access Controller or Identity Manager (i.e. Cisco ISE).&lt;br /&gt;
|-&lt;br /&gt;
| [c] mobile device connections are monitored and logged. || Screen Share || Mobile device logs within the MDM, log intake (sources) configuration (within SIEM) showing MDM is feeding logs to the SIEM.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.19 – Encrypt CUI on Mobile ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.19_Details|&#039;&#039;&#039;AC.L2-3.1.19&#039;&#039;&#039;]] Encrypt CUI on mobile devices and mobile computing platforms.&lt;br /&gt;
|-&lt;br /&gt;
| [a] mobile devices and mobile computing platforms that process, store, or transmit CUI are identified. || Document || SSP, Mobile Device Policy.&lt;br /&gt;
|-&lt;br /&gt;
| [b] encryption is employed to protect CUI on identified mobile devices and mobile computing platforms. || Screen Share || Security policy page in MDM showing how encryption are enforced on mobile device. If no MDM or MDM doesn&#039;t enforce encryption, then validate if the devices used are on the list of devices with native FIPS approved validation.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.20 – External Connections [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.20_Details|&#039;&#039;&#039;AC.L2-3.1.20&#039;&#039;&#039;]] Verify and control/limit connections to and use of external information systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] connections to external systems are identified. || Document || SSP, Systems Interconnection Agreements, SLA.&lt;br /&gt;
|-&lt;br /&gt;
| [b] the use of external systems is identified. || Document || SSP, Systems Interconnection Agreements, SLA.&lt;br /&gt;
|-&lt;br /&gt;
| [c] connections to external systems are verified. || Artifact || SLA for external systems, memorandum for interconnection, information to prove that any cloud solution is at FedRAMP impact level of moderate or higher (i.e. license information, screenshot of AWS cloud dashboard, purchase order document).&lt;br /&gt;
|-&lt;br /&gt;
| [d] the use of external systems is verified. || Artifact || SLA for external systems, memorandum for interconnection, information to prove that any cloud solution is at FedRAMP impact level of moderate or higher (i.e. license information, screenshot of AWS cloud dashboard, purchase order document).&lt;br /&gt;
|-&lt;br /&gt;
| [e] connections to external systems are controlled/limited. || Screen Share || Firewall ruleset for controlling access to cloud service or external system.&lt;br /&gt;
|-&lt;br /&gt;
| [f] the use of external systems is controlled/limited. || Screen Share || Firewall ruleset for controlling access to cloud service or external system.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.21 – Portable Storage Use ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.21_Details|&#039;&#039;&#039;AC.L2-3.1.21&#039;&#039;&#039;]] Limit use of portable storage devices on external systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the use of portable storage devices containing CUI on external systems is identified and documented. || Document || SSP, Removable Media Policy, Acceptable Use Policy (with emphasis on portable media use).&lt;br /&gt;
|-&lt;br /&gt;
| [b] limits on the use of portable storage devices containing CUI on external systems are defined. || Document || SSP, Removable Media Policy, Acceptable Use Policy (with emphasis on portable media use).&lt;br /&gt;
|-&lt;br /&gt;
| [c] the use of portable storage devices containing CUI on external systems is limited as defined. || Document || SSP, Removable Media Policy, Acceptable Use Policy (with emphasis on portable media use).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.22 – Control Public Information [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.22_Details|&#039;&#039;&#039;AC.L2-3.1.22&#039;&#039;&#039;]] Control information posted or processed on publicly accessible information systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] individuals authorized to post or process information on publicly accessible systems are identified. || Document || SSP, Website Governance Plan, Information Release Document.&lt;br /&gt;
|-&lt;br /&gt;
| [b] procedures to ensure CUI is not posted or processed on publicly accessible systems are identified. || Document || SSP, Website Governance Plan, Information Release Document.&lt;br /&gt;
|-&lt;br /&gt;
| [c] a review process is in place prior to posting of any content to publicly accessible systems. || Artifact || &amp;quot;Information release approval process, i.e. chain of email communication from originator, approver, and final decision (may or may not include individual authorized to post); &lt;br /&gt;
SharePoint/electronic or paper form/ ticket system showing information flow between requestor and approver (may or may not include  individual authorized to post).&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| [d] content on publicly accessible systems is reviewed to ensure that it does not include CUI. || Artifact || Incident response process, web design/update/modification SOP etc.&lt;br /&gt;
|-&lt;br /&gt;
| [e] mechanisms are in place to remove and address improper posting of CUI. || Artifact || Incident response process, web design/update/modification SOP etc.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Awareness and Training (AT) ==&lt;br /&gt;
=== AT.L2-3.2.1 – Role-Based Risk Awareness ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AT.L2-3.2.1_Details|&#039;&#039;&#039;AT.L2-3.2.1&#039;&#039;&#039;]] Ensure that managers, systems administrators, and users of organizational systems are made aware of the security risks associated with their activities and of the applicable policies, standards, and procedures related to the security of those systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] security risks associated with organizational activities involving CUI are identified. || Document || Policy of Security Awareness Training; Security Awareness Training Briefing.&lt;br /&gt;
|-&lt;br /&gt;
| [b] policies, standards, and procedures related to the security of the system are identified. || Document || Acceptable Use Policy, Policy/Procedures/Instruction related to the security of the system.&lt;br /&gt;
|-&lt;br /&gt;
| [c] managers, systems administrators, and users of the system are made aware of the security risks associated with their activities. || Artifact || Security Training Brief, training records.&lt;br /&gt;
|-&lt;br /&gt;
| [d] managers, systems administrators, and users of the system are made aware of the applicable policies, standards, and procedures related to the security of the system. || Artifact || Policies, standards and procedures for employees within training (completed training report).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AT.L2-3.2.2 – Role-Based Training ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AT.L2-3.2.2_Details|&#039;&#039;&#039;AT.L2-3.2.2&#039;&#039;&#039;]] Ensure that personnel are trained to carry out their assigned information security-related duties and responsibilities.|-&lt;br /&gt;
|-&lt;br /&gt;
| [a] information security-related duties, roles, and responsibilities are defined. || Document || Policy/Procedures/Instruction, Job Role Matrix, Position Descriptions, User Roles.&lt;br /&gt;
|-&lt;br /&gt;
| [b] information security-related duties, roles, and responsibilities are assigned to designated personnel. || Artifact || Screenshot of breakout of different roles/permissions assigned to individuals (i.e. ActiveDirectory); Privilege Access Agreement.&lt;br /&gt;
|-&lt;br /&gt;
| [c] personnel are adequately trained to carry out their assigned information security-related duties, roles, and responsibilities. || Artifact || Screenshot of tool and/or training specifying security specific roles, duties and responsibilities; Screenshot of required certifications (i.e. Sec+, CISSP).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AT.L2-3.2.3 – Insider Threat Awareness ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AT.L2-3.2.3_Details|&#039;&#039;&#039;AT.L2-3.2.3&#039;&#039;&#039;]] Provide security awareness training on recognizing and reporting potential indicators of insider threat.&lt;br /&gt;
|-&lt;br /&gt;
| [a] potential indicators associated with insider threats are identified. || Document || Insidert Threat Policy/Procedures/Instruction; Insider Threat Training/Briefing.&lt;br /&gt;
|-&lt;br /&gt;
| [b] security awareness training on recognizing and reporting potential indicators of insider threat is provided to managers and employees. || Artifact || Screenshot of training records showing completion of Insider Threat training, emails showing completion of Insider Threat training, Screenshot of certificate showing completion with individual&#039;s name.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Audit and Accountability (AU) ==&lt;br /&gt;
=== AU.L2-3.3.1 – System Auditing ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AU.L2-3.3.1_Details|&#039;&#039;&#039;AU.L2-3.3.1&#039;&#039;&#039;]] Create and retain system audit logs and records to the extent needed to enable the monitoring, analysis, investigation, and reporting of unlawful or unauthorized system activity.&lt;br /&gt;
|-&lt;br /&gt;
| [a] audit logs needed (i.e., event types to be logged) to enable the monitoring, analysis, investigation, and reporting of unlawful or unauthorized system activity are specified. || Document || SSP, policy, or auditing and logging process that defines specific types of events to be logged.&lt;br /&gt;
|-&lt;br /&gt;
| [b] the content of audit records needed to support monitoring, analysis, investigation, and reporting of unlawful or unauthorized system activity is defined. || Document || SSP, policy, or auditing and logging process that defines specific content of audit records/files.&lt;br /&gt;
|-&lt;br /&gt;
| [c] audit records are created (generated). || Screen Share || Screen share of tool that shows logs are generated for all systems.&lt;br /&gt;
|-&lt;br /&gt;
| [d] audit records, once created, contain the defined content. || Screen Share || Screen share of tool that shows logs contain defined content as defined in SSP, policy, or procedures.&lt;br /&gt;
|-&lt;br /&gt;
| [e] retention requirements for audit records are defined. || Document || SSP, Polocy, or Auditing and logging process that describes how long records are kept.&lt;br /&gt;
|-&lt;br /&gt;
| [f] audit records are retained as defined. || Screen Share || Screen share of tool that shows records and audit content retained at a minimum as defined.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AU.L2-3.3.2 – User Accountability ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AU.L2-3.3.2_Details|&#039;&#039;&#039;AU.L2-3.3.2&#039;&#039;&#039;]] Ensure that the actions of individual system users can be uniquely traced to those users so they can be held accountable for their actions.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the content of the audit records needed to support the ability to uniquely trace users to their actions is defined. || Document || SSP, policy, or process that defines actions traced back to individuals.&lt;br /&gt;
|-&lt;br /&gt;
| [b] audit records, once created, contain the defined content. || Screen Share || Screen share of tool that shows audit records traced to specific users/roles.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AU.L2-3.3.3 – Event Review ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AU.L2-3.3.3_Details|&#039;&#039;&#039;AU.L2-3.3.3&#039;&#039;&#039;]] Review and update logged events.&lt;br /&gt;
|-&lt;br /&gt;
| [a] a process for determining when to review logged events is defined. || Document || SSP, policy, or documented process that shows frequency of when to review types of logged events.&lt;br /&gt;
|-&lt;br /&gt;
| [b] event types being logged are reviewed in accordance with the defined review process. || Artifact || Evidence through a documented method such as meeting minutes, CAB minutes, etc. of log sources and log events being logged at the defined frequency.&lt;br /&gt;
|-&lt;br /&gt;
| [c] event types being logged are updated based on the review. || Artifact || Evidence of implementation based on the results of the review of logged events/sources through a ticket, meeting minutes, or screen share of the tool that shows changes implemented (finetuning).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AU.L2-3.3.4 – Audit Failure Alerting ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AU.L2-3.3.4_Details|&#039;&#039;&#039;AU.L2-3.3.4&#039;&#039;&#039;]] Alert in the event of an audit logging process failure.&lt;br /&gt;
|-&lt;br /&gt;
| [a] personnel or roles to be alerted in the event of an audit logging process failure are identified. || Document || SSP, policy, or procedure that shows who needs to be notified in case of an audit failure.&lt;br /&gt;
|-&lt;br /&gt;
| [b] types of audit logging process failures for which alert will be generated are defined. || Document || SSP, policy, or procedure that shows what types of failure will generate notifications.&lt;br /&gt;
|-&lt;br /&gt;
| [c] identified personnel or roles are alerted in the event of an audit logging process failure. || Artifact || Artifact such as email or ticket that shows the identified personnel were alerted of any audit/logging process failure as defined.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AU.L2-3.3.5 – Audit Correlation ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AU.L2-3.3.5_Details|&#039;&#039;&#039;AU.L2-3.3.5&#039;&#039;&#039;]] Correlate audit record review, analysis, and reporting processes for investigation and response to indications of unlawful, unauthorized, suspicious, or unusual activity.&lt;br /&gt;
|-&lt;br /&gt;
| [a] audit record review, analysis, and reporting processes for investigation and response to indications of unlawful, unauthorized, suspicious, or unusual activity are defined. || Document || SSP, policy, or procedure covering audit logging, monitoring, and reporting.&lt;br /&gt;
|-&lt;br /&gt;
| [b] defined audit record review, analysis, and reporting processes are correlated. || Artifact || Artifact showing an audit event and the resultant corrective action or actions to the event; this can be a Help Desk ticket, meeting notes, or a change control board items showing the event and any corrective action taken.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AU.L2-3.3.6 – Reduction &amp;amp; Reporting ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AU.L2-3.3.6_Details|&#039;&#039;&#039;AU.L2-3.3.6&#039;&#039;&#039;]] Provide audit record reduction and report generation to support on-demand analysis and reporting.&lt;br /&gt;
|-&lt;br /&gt;
| [a] an audit record reduction capability that supports on-demand analysis is provided. || Screen Share || Screen share of the logging environment where an event can be selected and traced back to a specific device, or dashboard showing realtime event analysis.&lt;br /&gt;
|-&lt;br /&gt;
| [b] a report generation capability that supports on-demand reporting is provided. || Screen Share || Screen share showing the generation of an on demand report.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AU.L2-3.3.7 – Authoritative Time Source ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AU.L2-3.3.7_Details|&#039;&#039;&#039;AU.L2-3.3.7&#039;&#039;&#039;]] Provide a system capability that compares and synchronizes internal system clocks with an authoritative source to generate time stamps for audit records.&lt;br /&gt;
|-&lt;br /&gt;
| [a] internal system clocks are used to generate time stamps for audit records. || Screen Share || Screen share showing the NTP settings of a windows, Unix, Linux device; a screen share showing the NTP settings of network appliances.&lt;br /&gt;
|-&lt;br /&gt;
| [b] an authoritative source with which to compare and synchronize internal system clocks is specified. || Document || SSP or policy indicating that devices need to be synched to a local authoritative time device that is synched with an authoritative time service.&lt;br /&gt;
|-&lt;br /&gt;
| [c] internal system clocks used to generate time stamps for audit records are compared to and synchronized with the specified authoritative time source. || Screen Share || Screen share showing device logging appliance time is point to the appropriate authoritative time server.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AU.L2-3.3.8 – Audit Protection ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AU.L2-3.3.8_Details|&#039;&#039;&#039;AU.L2-3.3.8&#039;&#039;&#039;]] Protect audit information and audit logging tools from unauthorized access, modification, and deletion.&lt;br /&gt;
|-&lt;br /&gt;
| [a] audit information is protected from unauthorized access. || Screen Share || Screen share showing operating system permissions on the audit folders being restricted to appropriate users.&lt;br /&gt;
|-&lt;br /&gt;
| [b] audit information is protected from unauthorized modification. || Screen Share || Screen share showing operating system permissions on the audit folders being restricted to appropriate users.&lt;br /&gt;
|-&lt;br /&gt;
| [c] audit information is protected from unauthorized deletion. || Screen Share || Screen share showing operating system permissions on the audit folders being restricted to appropriate users.&lt;br /&gt;
|-&lt;br /&gt;
| [d] audit logging tools are protected from unauthorized access. || Screen Share || Artifact showing access permissions in the SIEM tool.&lt;br /&gt;
|-&lt;br /&gt;
| [e] audit logging tools are protected from unauthorized modification. || Screen Share || Artifact showing update permissions in the SIEM tool.&lt;br /&gt;
|-&lt;br /&gt;
| [f] audit logging tools are protected from unauthorized deletion. || Screen Share || Artifact showing delete permissions in the SIEM tool.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AU.L2-3.3.9 – Audit Management ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AU.L2-3.3.9_Details|&#039;&#039;&#039;AU.L2-3.3.9&#039;&#039;&#039;]] Limit management of audit logging functionality to a subset of privileged users.&lt;br /&gt;
|-&lt;br /&gt;
| [a] a subset of privileged users granted access to manage audit logging functionality is defined. || Document || SSP or policy indicating which users or groups have access to audit logs.&lt;br /&gt;
|-&lt;br /&gt;
| [b] management of audit logging functionality is limited to the defined subset of privileged users. || Screen Share || Artifact showing SIEM or OS folder permissions (this should be limited to the assigned users or groups); artifact showing an ACL setting in SIEM tool in regards to logs.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Configuration Management (CM) ==&lt;br /&gt;
=== CM.L2-3.4.1 – System Baselining ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_CM.L2-3.4.1_Details|&#039;&#039;&#039;CM.L2-3.4.1&#039;&#039;&#039;]] Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles.&lt;br /&gt;
|-&lt;br /&gt;
| [a] a baseline configuration is established. || Document || Documentation showing or explaining standard imaging process (how standard images are deployed and where  they are stored).&lt;br /&gt;
|-&lt;br /&gt;
| [b] the baseline configuration includes hardware, software, firmware, and documentation. || Artifact || Screenshot of repository of where images are maintained and information relating to hardware, software, and firmware.&lt;br /&gt;
|-&lt;br /&gt;
| [c] the baseline configuration is maintained (reviewed and updated) throughout the system development life cycle. || Artifact || Screenshot/evidence displaying management of baseline configurations (how often they are being managed as stated).&lt;br /&gt;
|-&lt;br /&gt;
| [d] a system inventory is established. || Document || Screenshot/evidence displaying inventory listing of approved products for use.&lt;br /&gt;
|-&lt;br /&gt;
| [e] the system inventory includes hardware, software, firmware, and documentation. || Artifact || Screeenshot/evidence displaying inventory listing of approved products and versions permitted for use.&lt;br /&gt;
|-&lt;br /&gt;
| [f] the inventory is maintained (reviewed and updated) throughout the system development life cycle. || Artifact || Screeenshot/evidence displaying management of baseline configurations (How often and are they being managed as stated.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== CM.L2-3.4.2 – Security Configuration Enforcement ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_CM.L2-3.4.2_Details|&#039;&#039;&#039;CM.L2-3.4.2&#039;&#039;&#039;]] Establish and enforce security configuration settings for information technology products employed in organizational systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] security configuration settings for information technology products employed in the system are established and included in the baseline configuration. || Document || Documentation explaining methodology used by organization to create secure baselines (STIGs, benchmarks).&lt;br /&gt;
|-&lt;br /&gt;
| [b] security configuration settings for information technology products employed in the system are enforced. || Artifact || Evidence of tool/s used to enforce security configurations to ensure images used are free from modification unless authorized.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== CM.L2-3.4.3 – System Change Management ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_CM.L2-3.4.3_Details|&#039;&#039;&#039;CM.L2-3.4.3&#039;&#039;&#039;]] Track, review, approve or disapprove, and log changes to organizational systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] changes to the system are tracked. || Artifact || Evidence of IT Service Management tool / process used to track system changes.&lt;br /&gt;
|-&lt;br /&gt;
| [b] changes to the system are reviewed. || Artifact || Evidence of IT Service Management tool / process used to review system changes.&lt;br /&gt;
|-&lt;br /&gt;
| [c] changes to the system are approved or disapproved. || Artifact || Evidence of IT Service Management tool / process used to approve/disapprove system changes.&lt;br /&gt;
|-&lt;br /&gt;
| [d] changes to the system are logged. || Artifact || Evidence of IT Service Management tool / process used to log system changes.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== CM.L2-3.4.4 – Security Impact Analysis ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_CM.L2-3.4.4_Details|&#039;&#039;&#039;CM.L2-3.4.4&#039;&#039;&#039;]] Analyze the security impact of changes prior to implementation.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the security impact of changes to the system is analyzed prior to implementation. || Artifact || Document explaining that security impact analysis of proposed changes to a system is conducted prior to implementation.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== CM.L2-3.4.5 – Access Restrictions for Change ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_CM.L2-3.4.5_Details|&#039;&#039;&#039;CM.L2-3.4.5&#039;&#039;&#039;]] Define, document, approve, and enforce physical and logical access restrictions associated with changes to organizational systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] physical access restrictions associated with changes to the system are defined. || Document || Document explaining the process of how physical access restrictions are defined for an individuals ability to make system changes.&lt;br /&gt;
|-&lt;br /&gt;
| [b] physical access restrictions associated with changes to the system are documented. || Document || Document explaining the process of how physical access restrictions are defined for an individuals ability to make system changes are documented; access request process.&lt;br /&gt;
|-&lt;br /&gt;
| [c] physical access restrictions associated with changes to the system are approved. || Artifact || Evidence of process of how physical access to systems are granted (i.e. physical access request sample).&lt;br /&gt;
|-&lt;br /&gt;
| [d] physical access restrictions associated with changes to the system are enforced. || Physical Review || Evidence of process of how physical access to systems are enforced (physical access system).&lt;br /&gt;
|-&lt;br /&gt;
| [e] logical access restrictions associated with changes to the system are defined. || Document || Document explaining the process of how logical access restrictions are defined for an individual&#039;s ability to make system changes.&lt;br /&gt;
|-&lt;br /&gt;
| [f] logical access restrictions associated with changes to the system are documented. || Document || Document explaining the process of how logical access restrictions are defined for an individual&#039;s ability to make system changes are documented.&lt;br /&gt;
|-&lt;br /&gt;
| [g] logical access restrictions associated with changes to the system are approved. || Artifact || Evidence of process of how logical access to systems are granted.&lt;br /&gt;
|-&lt;br /&gt;
| [h] logical access restrictions associated with changes to the system are enforced. || Artifact || Evidence of process of how logical access to systems are enforced.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== CM.L2-3.4.6 – Least Functionality ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_CM.L2-3.4.6_Details|&#039;&#039;&#039;CM.L2-3.4.6&#039;&#039;&#039;]] Employ the principle of least functionality by configuring organizational systems to provide only essential capabilities.&lt;br /&gt;
|-&lt;br /&gt;
| [a] essential system capabilities are defined based on the principle of least functionality. || Document || Documentation explaining how systems are configured to utilize the principle of least functionality for designated users.&lt;br /&gt;
|-&lt;br /&gt;
| [b] the system is configured to provide only the defined essential capabilities. || Screen Share || Evidence displaying how systems are configured to utilize the principle of least functionality for designated users; disabled service settings, accepted standards for hardening (CIS benchmarks, etc.).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== CM.L2-3.4.7 – Nonessential Functionality ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_CM.L2-3.4.7_Details|&#039;&#039;&#039;CM.L2-3.4.7&#039;&#039;&#039;]] Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services.&lt;br /&gt;
|-&lt;br /&gt;
| [a] essential programs are defined. || Document || Documented essential programs specified; build documents; software center; SSP.&lt;br /&gt;
|-&lt;br /&gt;
| [b] the use of nonessential programs is defined. || Document || Documented listing of nonessential programs (whatever is NOT specified in [a]); AUP/User Agreement may identify nonessential use/programs.&lt;br /&gt;
|-&lt;br /&gt;
| [c] the use of nonessential programs is restricted, disabled, or prevented as defined. || Screen Share || Tool used to restrict nonessential programs displays restrictions as defined (McAfee ePO settings, Carbon Black rules, etc.).&lt;br /&gt;
|-&lt;br /&gt;
| [d] essential functions are defined. || Document || Documented essential functions are specified.&lt;br /&gt;
|-&lt;br /&gt;
| [e] the use of nonessential functions is defined. || Document || Documented nonessential functions are specified.&lt;br /&gt;
|-&lt;br /&gt;
| [f] the use of nonessential functions is restricted, disabled, or prevented as defined. || Screen Share || Tool used to restrict essential/nonessential functions displays restrictions as defined.&lt;br /&gt;
|-&lt;br /&gt;
| [g] essential ports are defined. || Document || Documented essential ports are specified.&lt;br /&gt;
|-&lt;br /&gt;
| [h] the use of nonessential ports is defined. || Document || Documented nonessential ports functions are specified.&lt;br /&gt;
|-&lt;br /&gt;
| [i] the use of nonessential ports is restricted, disabled, or prevented as defined. || Screen Share || Tool used to restrict essential/nonessential ports displays restrictions as defined (FW rules; McAfee; GPO, etc.).&lt;br /&gt;
|-&lt;br /&gt;
| [j] essential protocols are defined. || Document || Documented essential protocols are specified.&lt;br /&gt;
|-&lt;br /&gt;
| [k] the use of nonessential protocols is defined. || Document || Documented nonessential protocols functions are specified.&lt;br /&gt;
|-&lt;br /&gt;
| [l] the use of nonessential protocols is restricted, disabled, or prevented as defined. || Screen Share || Tool used to restrict essential/nonessential protocols displays restrictions as defined (FW rules; GPO, etc.).&lt;br /&gt;
|-&lt;br /&gt;
| [m] essential services are defined. || Document || Documented essential services specified.&lt;br /&gt;
|-&lt;br /&gt;
| [n] the use of nonessential services is defined. || Document || Documented nonessential services functions are specified.&lt;br /&gt;
|-&lt;br /&gt;
| [o] the use of nonessential services is restricted, disabled, or prevented as defined. || Screen Share || Tool used to restrict essential/nonessential services displays restrictions as defined.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== CM.L2-3.4.8 – Application Execution Policy ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_CM.L2-3.4.8_Details|&#039;&#039;&#039;CM.L2-3.4.8&#039;&#039;&#039;]] Apply deny-by-exception (blacklisting) policy to prevent the use of unauthorized software or deny-all, permit-by-exception (whitelisting) policy to allow the execution of authorized software.&lt;br /&gt;
|-&lt;br /&gt;
| [a] a policy specifying whether whitelisting or blacklisting is to be implemented is specified. || Document || Documentation explaining whitelisting or blacklisting process.&lt;br /&gt;
|-&lt;br /&gt;
| [b] the software allowed to execute under whitelisting or denied use under blacklisting is specified. || Document || Documentation explaining whitelisting or blacklisting process for software.&lt;br /&gt;
|-&lt;br /&gt;
| [c] whitelisting to allow the execution of authorized software or blacklisting to prevent the use of unauthorized software is implemented as specified. || Screen Share || Tool used for whitelisting or blacklisting for software shows capability of restricting/authorizing software (Carbon Black dashboard, &amp;quot;SW Store&amp;quot;, web proxies, DNS Blackhole, etc.).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== CM.L2-3.4.9 – User-Installed Software ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_CM.L2-3.4.9_Details|&#039;&#039;&#039;CM.L2-3.4.9&#039;&#039;&#039;]] Control and monitor user-installed software.&lt;br /&gt;
|-&lt;br /&gt;
| [a] a policy for controlling the installation of software by users is established. || Document || Documented software authorization process or methodology for approval.&lt;br /&gt;
|-&lt;br /&gt;
| [b] installation of software by users is controlled based on the established policy. || Screen Share || Evidence that approval/restriction in installation of software by authorized personnel is implemented as specified (AUP, GPO, etc.).&lt;br /&gt;
|-&lt;br /&gt;
| [c] installation of software by users is monitored. || Screen Share || Evidence that installation of software by authorized personnel is monitored (SCCM groups, SW Center, etc.).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Identification and Authentication (IA) ==&lt;br /&gt;
=== IA.L2-3.5.1 – Identification [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IA.L2-3.5.1_Details|&#039;&#039;&#039;IA.L2-3.5.1&#039;&#039;&#039;]] Identify information system users, processes acting on behalf of users, or devices.&lt;br /&gt;
|-&lt;br /&gt;
| [a] system users are identified. || Document || Based on what is defined in their documentation (SSP, AUP, Policy, SOP), request to see a sample of non-privileged/privileged users in AD OU group (overlaps with 3.1.1 and 3.1.5).&lt;br /&gt;
|-&lt;br /&gt;
| [b] processes acting on behalf of users are identified. || Document || Based on what is defined in their documentation (SSP, AUP, Policy, SOP), request to see a sample of service accounts in AD OU group (overlaps with 3.1.1 and 3.1.5).&lt;br /&gt;
|-&lt;br /&gt;
| [c] devices accessing the system are identified. || Document || Based on what is defined in their documentation (SSP, AUP, Policy, SOP), request to see a sample of domain-joined workstation &amp;amp; servers in AD OU group (overlaps with 3.1.1 and 3.1.5).  For network devices, request screen share/artifact to show how they are identified on the enterprise network.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IA.L2-3.5.2 – Authentication [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IA.L2-3.5.2_Details|&#039;&#039;&#039;IA.L2-3.5.2&#039;&#039;&#039;]] Authenticate (or verify) the identities of those users, processes, or devices, as a prerequisite to allowing access to organizational information systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the identity of each user is authenticated or verified as a prerequisite to system access. || Screen Share || If the user logs in with non-privileged account during other demoes and then a privileged account, then this should be satisfied.  If screen share is unavailable, request logs to show successful and unsuccessful login by privileged and non-privilged users.&lt;br /&gt;
|-&lt;br /&gt;
| [b] the identity of each process acting on behalf of a user is authenticated or verified as a prerequisite to system access. || Screen Share || Request a log that shows successful/unsuccessful service account trying to log on to company&#039;s asset.&lt;br /&gt;
|-&lt;br /&gt;
| [c] the identity of each device accessing or connecting to the system is authenticated or verified as a prerequisite to system access. || Screen Share || Request a log that shows domain-joined workstation/server authenticating to AD (focus on the MAC/IP address/hostname).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IA.L2-3.5.3 – Multifactor Authentication ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IA.L2-3.5.3_Details|&#039;&#039;&#039;IA.L2-3.5.3&#039;&#039;&#039;]] Use multifactor authentication for local and network access to privileged accounts and for network access to non-privileged accounts.&lt;br /&gt;
|-&lt;br /&gt;
| [a] privileged accounts are identified. || Document || Based on what is defined in their documentation, request to see a sample of privileged users in AD OU group.  Overlaps with 3.1.5.  Screenshot/screen share to show implementation is enforced.&lt;br /&gt;
|-&lt;br /&gt;
| [b] multifactor authentication is implemented for local access to privileged accounts. || Screen Share || SSP, AUP, Policy, SOP that defines that MFA is needed for privileged local access.&lt;br /&gt;
|-&lt;br /&gt;
| [c] multifactor authentication is implemented for network access to privileged accounts. || Screen Share || Within the MFA implementation mechanism, show that privileged users are forced to use MFA;  Screenshot/Screen share to show implementation is enforced.&lt;br /&gt;
|-&lt;br /&gt;
| [d] multifactor authentication is implemented for network access to non-privileged accounts. || Screen Share || Within the MFA implementation mechanism, show that non-privileged users are forced to use MFA; Screenshot/Screen share to show implementation is enforced.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IA.L2-3.5.4 – Replay-Resistant Authentication ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IA.L2-3.5.4_Details|&#039;&#039;&#039;IA.L2-3.5.4&#039;&#039;&#039;]] Employ replay-resistant authentication mechanisms for network access to privileged and non-privileged accounts.&lt;br /&gt;
|-&lt;br /&gt;
| [a] replay-resistant authentication mechanisms are implemented for network account access to privileged and non-privileged accounts. || Screen Share || Show the GPO setting that enforces Kerberos within AD.  If MFA is used, show the implementation to enforce replay resistant techniques.  For non-windows, show the technical solution to enforce replay resistant attacks.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IA.L2-3.5.5 – Identifier Reuse ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IA.L2-3.5.5_Details|&#039;&#039;&#039;IA.L2-3.5.5&#039;&#039;&#039;]] Prevent reuse of identifiers for a defined period.&lt;br /&gt;
|-&lt;br /&gt;
| [a] a period within which identifiers cannot be reused is defined. || Document || SSP, policies, or SOP that defines identifier reuse.&lt;br /&gt;
|-&lt;br /&gt;
| [b] reuse of identifiers is prevented within the defined period. || Artifact || Show the GPO setting/technical solution that enforces what is defined in policy/documentation (this can be automated or manual process; screen share/artifacts can be presented to satisfy this requirement.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IA.L2-3.5.6 – Identifier Handling ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IA.L2-3.5.6_Details|&#039;&#039;&#039;IA.L2-3.5.6&#039;&#039;&#039;]] Disable identifiers after a defined period of inactivity.&lt;br /&gt;
|-&lt;br /&gt;
| [a] a period of inactivity after which an identifier is disabled is defined. || Document || SSP, policy that defines the period of inactivity after which an identifier is disabled.&lt;br /&gt;
|-&lt;br /&gt;
| [b] identifiers are disabled after the defined period of inactivity. || Artifact || Screen share AD or similar tool supporting directory-based identity-related services for disabled accounts (can be done by hand or script).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IA.L2-3.5.7 – Password Complexity ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IA.L2-3.5.7_Details|&#039;&#039;&#039;IA.L2-3.5.7&#039;&#039;&#039;]] Enforce a minimum password complexity and change of characters when new passwords are created.&lt;br /&gt;
|-&lt;br /&gt;
| [a] password complexity requirements are defined. || Document || SSP, policy that defines password complexity requirements.&lt;br /&gt;
|-&lt;br /&gt;
| [b] password change of character requirements are defined. || Document || SSP, policy that defines change of character requirements are defined.&lt;br /&gt;
|-&lt;br /&gt;
| [c] minimum password complexity requirements as defined are enforced when new passwords are created. || Screen Share || Screen share of AD or similar directory-based identity-related service tool to show complexity requirements.&lt;br /&gt;
|-&lt;br /&gt;
| [d] minimum password change of character requirements as defined are enforced when new passwords are created. || Screen Share || Screen share of Group Policy configuration or similar tool providing centralized management and configuration of operating systems, applications, and users&#039; settings to show that characters must be changed.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IA.L2-3.5.8 – Password Reuse ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IA.L2-3.5.8_Details|&#039;&#039;&#039;IA.L2-3.5.8&#039;&#039;&#039;]] Prohibit password reuse for a specified number of generations.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the number of generations during which a password cannot be reused is specified. || Document || SSP, policy that specifies the number of generations during which a password cannot be reused is specified.&lt;br /&gt;
|-&lt;br /&gt;
| [b] reuse of passwords is prohibited during the specified number of generations. || Screen Share || Screen share Group Policy or similar tool providing centralized management and configuration of operating systems, applications, and users&#039; settings in a directory-based identity-related service tool&#039;s configuration to show reuse of passwords is prohibited.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IA.L2-3.5.9 – Temporary Passwords ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IA.L2-3.5.9_Details|&#039;&#039;&#039;IA.L2-3.5.9&#039;&#039;&#039;]] Allow temporary password use for system logons with an immediate change to a permanent password.&lt;br /&gt;
|-&lt;br /&gt;
| [a] an immediate change to a permanent password is required when a temporary password is used for system logon. || Screen Share || Screen share of Group Policy or similar tool providing centralized management and configuration of operating systems, applications, and users&#039; settings in a directory-based identity-related service tool&#039;s configuration to show &amp;quot;change password at first logon.&amp;quot;&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IA.L2-3.5.10 – Cryptographically-Protected Passwords ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IA.L2-3.5.1_Details|&#039;&#039;&#039;IA.L2-3.5.1&#039;&#039;&#039;]] Store and transmit only cryptographically-protected passwords.&lt;br /&gt;
|-&lt;br /&gt;
| [a] passwords are cryptographically protected in storage. || Screen Share || Screen share Group Policy or similar tool providing centralized management and configuration of operating systems, applications, and users&#039; settings in a directory-based identity-related service tool&#039;s configuration that Kerberos, or a similar network authentication protocol that works on the basis of tickets to allow nodes communicating over a non-secure network to prove their identity to one another in a secure manner, is enabled.&lt;br /&gt;
|-&lt;br /&gt;
| [b] passwords are cryptographically protected in transit. || Screen Share || Screen share Group Policy or similar tool providing centralized management and configuration of operating systems, applications, and users&#039; settings in a directory-based identity-related service tool&#039;s configuration that Kerberos, or a similar network authentication protocol that works on the basis of tickets to allow nodes communicating over a non-secure network to prove their identity to one another in a secure manner, is enabled.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IA.L2-3.5.11 – Obscure Feedback ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IA.L2-3.5.10_Details|&#039;&#039;&#039;IA.L2-3.5.10&#039;&#039;&#039;]] Obscure feedback of authentication information.&lt;br /&gt;
|-&lt;br /&gt;
| [a] authentication information is obscured during the authentication process. || Screen Share || Screen share of Group Policy or similar tool providing centralized management and configuration of operating systems, applications, and users&#039; settings in a directory-based identity-related service tool&#039;s configuration to show that passwords are obscured.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Incident Response (IR) ==&lt;br /&gt;
=== IR.L2-3.6.1 – Incident Handling ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IR.L2-3.6.1_Details|&#039;&#039;&#039;IR.L2-3.6.1&#039;&#039;&#039;]] Establish an operational incident-handling capability for organizational systems that includes preparation, detection, analysis, containment, recovery, and user response activities.&lt;br /&gt;
|-&lt;br /&gt;
| [a] an operational incident-handling capability is established. || Document || Incident Response SOP/Plan.&lt;br /&gt;
|-&lt;br /&gt;
| [b] the operational incident-handling capability includes preparation. || Document || Incident Response SOP/Plan, prior incident report, training, COOP plan.&lt;br /&gt;
|-&lt;br /&gt;
| [c] the operational incident-handling capability includes detection. || Document || Incident Response SOP/Plan; definition of tools used to detect; artifacts showing tools used; prior incident report.&lt;br /&gt;
|-&lt;br /&gt;
| [d] the operational incident-handling capability includes analysis. || Document || Incident Response SOP/Plan; Definition of tools used to analyze potential incidents; artifacts showing tools used for analysis; prior incident report.&lt;br /&gt;
|-&lt;br /&gt;
| [e] the operational incident-handling capability includes containment. || Document || Incident Response SOP/Plan; isolation/quarantine process; user training.&lt;br /&gt;
|-&lt;br /&gt;
| [f] the operational incident-handling capability includes recovery. || Document || Incident Response SOP/Plan; COOP Plan; prior incident reports, re-baselining impacted devices.&lt;br /&gt;
|-&lt;br /&gt;
| [g] the operational incident-handling capability includes user response. || Document || Incident Response SOP/Plan; user awareness training; Help Desk process.&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IR.L2-3.6.2 – Incident Reporting ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IR.L2-3.6.2_Details|&#039;&#039;&#039;IR.L2-3.6.2&#039;&#039;&#039;]] Track, document, and report incidents to designated officials and/or authorities both internal and external to the organization.&lt;br /&gt;
|-&lt;br /&gt;
| [a] incidents are tracked. || Artifact || Incident Response SOP/Plan; ITSM artifact; technical implementation for incident tracking.&lt;br /&gt;
|-&lt;br /&gt;
| [b] incidents are documented. || Artifact || Incident Response SOP/Plan; ITSM artifact; technical implementation for incident tracking.&lt;br /&gt;
|-&lt;br /&gt;
| [c] authorities to whom incidents are to be reported are identified. || Document || Incident Response SOP/Plan.&lt;br /&gt;
|-&lt;br /&gt;
| [d] organizational officials to whom incidents are to be reported are identified. || Document || Incident Response SOP/Plan.&lt;br /&gt;
|-&lt;br /&gt;
| [e] identified authorities are notified of incidents. || Screen Share || Prior incident report; DIBNET login; prior email notifications.&lt;br /&gt;
|-&lt;br /&gt;
| [f] identified organizational officials are notified of incidents. || Artifact || Prior incident report; prior email notifications; tabletop exercises.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IR.L2-3.6.3 – Incident Response Testing ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IR.L2-3.6.3_Details|&#039;&#039;&#039;IR.L2-3.6.3&#039;&#039;&#039;]] Test the organizational incident response capability.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the incident response capability is tested. || Artifact || Incident response table top/scheduled or unscheduled test or penetration test.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Maintenance (MA) ==&lt;br /&gt;
=== MA.L2-3.7.1 – Perform Maintenance ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MA.L2-3.7.1_Details|&#039;&#039;&#039;MA.L2-3.7.1&#039;&#039;&#039;]] Perform maintenance on organizational systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] system maintenance is performed. || Artifact || Establish typical maintenance activities (HVAC, UPS, power distribution, generators, copier maintenance) that are performed; maintenance agreements or contracts detailing these types of activities are acceptable; interview responses should be considered.  This requirement should not be confused with 3.14.1 - report, remediate, and correct system flaws in a timely manner (patch management).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MA.L2-3.7.2 – System Maintenance Control ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MA.L2-3.7.2_Details|&#039;&#039;&#039;MA.L2-3.7.2&#039;&#039;&#039;]] Provide controls on the tools, techniques, mechanisms, and personnel used to conduct system maintenance.&lt;br /&gt;
|-&lt;br /&gt;
| [a] tools used to conduct system maintenance are controlled. || Artifact || Tools may largely depend on the assessed environment; discussion examples include network diagnostic and monitoring tools (including hardware and software); artifacts could demonstrate secured locations/areas for these tools (photos) or checkout sheets/rosters (documents) depicting responsible personnel and the dates/times of checkout.&lt;br /&gt;
|-&lt;br /&gt;
| [b] techniques used to conduct system maintenance are controlled. || Artifact || Processes for scheduling, performing, documenting, reviewing, approving, and monitoring maintenance and repairs for the information system.&lt;br /&gt;
|-&lt;br /&gt;
| [c] mechanisms used to conduct system maintenance are controlled. || Artifact || Processes for scheduling, performing, documenting, reviewing, approving, and monitoring maintenance and repairs for the information system.&lt;br /&gt;
|-&lt;br /&gt;
| [d] personnel used to conduct system maintenance are controlled. || Physical Review || Screenshot of who is authorized to conduct maintenance; maintenance personnel training program.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MA.L2-3.7.3 – Equipment Sanitization ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MA.L2-3.7.3_Details|&#039;&#039;&#039;MA.L2-3.7.3&#039;&#039;&#039;]] Ensure equipment removed for off-site maintenance is sanitized of any CUI.&lt;br /&gt;
|-&lt;br /&gt;
| [a] equipment to be removed from organizational spaces for off-site maintenance is sanitized of any CUI. || Artifact || Document or artifact; record if equipment sanitized; categories of sanitization/destruction defined; sanitization procedural document.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MA.L2-3.7.4 – Media Inspection ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MA.L2-3.7.4_Details|&#039;&#039;&#039;MA.L2-3.7.4&#039;&#039;&#039;]] Check media containing diagnostic and test programs for malicious code before the media are used in organizational systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] media containing diagnostic and test programs are checked for malicious code before being used in organizational systems that process, store, or transmit CUI. || Artifact || Screenshot of diagnostic/test program being used (such as Symantec and McAfee on access scans…).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MA.L2-3.7.5 – Nonlocal Maintenance ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MA.L2-3.7.5_Details|&#039;&#039;&#039;MA.L2-3.7.5&#039;&#039;&#039;]] Require multifactor authentication to establish nonlocal maintenance sessions via external network connections and terminate such connections when nonlocal maintenance is complete.&lt;br /&gt;
|-&lt;br /&gt;
| [a] multifactor authentication is used to establish nonlocal maintenance sessions via external network connections. || Screen Share || Describe MFA used to remote from external service to organizational systems for maintenance and screenshot of MFA (3.5.3)(points associated with admin).&lt;br /&gt;
|-&lt;br /&gt;
| [b] nonlocal maintenance sessions established via external network connections are terminated when nonlocal maintenance is complete. || Screen Share || Screenshot VPN session timeout.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MA.L2-3.7.6 – Maintenance Personnel ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MA.L2-3.7.6_Details|&#039;&#039;&#039;MA.L2-3.7.6&#039;&#039;&#039;]] Supervise the maintenance activities of maintenance personnel without required access authorization.&lt;br /&gt;
|-&lt;br /&gt;
| [a] maintenance personnel without required access authorization are supervised during maintenance activities. || Document || System maintenance policy; list of authorized personnel; maintenance records or, contracts/SLAs; WebEx.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Media Protection (MP) ==&lt;br /&gt;
=== MP.L2-3.8.1 – Media Protection ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MP.L2-3.8.1_Details|&#039;&#039;&#039;MP.L2-3.8.1&#039;&#039;&#039;]] Protect (i.e., physically control and securely store) system media containing CUI, both paper and digital.&lt;br /&gt;
|-&lt;br /&gt;
| [a] paper media containing CUI is physically controlled. || Document || Policy showing CUI paper media is controlled; artifact showing who has access; artifacts/records of  inventories conducted; media check out procedures (i.e. file cabinets, encryption, password protection).&lt;br /&gt;
|-&lt;br /&gt;
| [b] digital media containing CUI is physically controlled. || Document || Policy showing CUI digital media is controlled; artifact showing who has access; artifacts/records of inventories conducted; media check out procedures (i.e. file cabinets, external drives, USBs, encryption, password protection).&lt;br /&gt;
|-&lt;br /&gt;
| [c] paper media containing CUI is securely stored. || Physical Review || Check out/sign out sheets; possible photo of storage container/video walk through of storage area; badge reader logs or access lists for keys for secured areas; interview response considered (i.e. file cabinets,  encryption, password protection).&lt;br /&gt;
|-&lt;br /&gt;
| [d] digital media containing CUI is securely stored. || Physical Review || Check out/sign out sheets; possible photo of storage container/video walk through of storage area; badge reader logs or access lists for keys for secured areas; interview response considered (i.e. file cabinets, external drives, USBs, encryption, password protection).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MP.L2-3.8.2 – Media Access ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MP.L2-3.8.2_Details|&#039;&#039;&#039;MP.L2-3.8.2&#039;&#039;&#039;]] Limit access to CUI on system media to authorized users.&lt;br /&gt;
|-&lt;br /&gt;
| [a] access to CUI on system media is limited to authorized users. || Artifact || Document describing how CUI is limited AND artifact showing principle of least access is implemented.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MP.L2-3.8.3 – Media Disposal [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MP.L2-3.8.3_Details|&#039;&#039;&#039;MP.L2-3.8.3&#039;&#039;&#039;]] Sanitize or destroy information system media containing Federal Contract Information before disposal or release for reuse.&lt;br /&gt;
|-&lt;br /&gt;
| [a] system media containing CUI is sanitized or destroyed before disposal. || Document || Policy or artifact of media destruction logs; certificates of destruction; SLAs or contracts.&lt;br /&gt;
|-&lt;br /&gt;
| [b] system media containing CUI is sanitized before it is released for reuse. || Document || Policy or artifact describing method to sanitize, software used (i.e. DoD Wipe, ShredIT and Iron Mountain; Blancco; GDisk, DBAN).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MP.L2-3.8.4 – Media Markings ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MP.L2-3.8.4_Details|&#039;&#039;&#039;MP.L2-3.8.4&#039;&#039;&#039;]] Mark media with necessary CUI markings and distribution limitations.&lt;br /&gt;
|-&lt;br /&gt;
| [a] media containing CUI is marked with applicable CUI markings. || Physical Review || Document or artifact showing CUI markings (i.e. labeling standards ).&lt;br /&gt;
|-&lt;br /&gt;
| [b] media containing CUI is marked with distribution limitations. || Physical Review || Document or artifact showing distro limitations (i.e. labeling standards ).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MP.L2-3.8.5 – Media Accountability ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MP.L2-3.8.5_Details|&#039;&#039;&#039;MP.L2-3.8.5&#039;&#039;&#039;]] Control access to media containing CUI and maintain accountability for media during transport outside of controlled areas.&lt;br /&gt;
|-&lt;br /&gt;
| [a] access to media containing CUI is controlled. || Document || Policy, artifact of audit logs showing tracking, Access Control Lists, records of transport activities (i.e. USB drives, CDs, chain of custody.&lt;br /&gt;
|-&lt;br /&gt;
| [b] accountability for media containing CUI is maintained during transport outside of controlled areas. || Artifact || Artifact of audit logs showing tracking, Access Control Lists, records of transport activities (i.e. USB drives, CDs; chain of custody.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MP.L2-3.8.6 – Portable Storage Encryption ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MP.L2-3.8.6_Details|&#039;&#039;&#039;MP.L2-3.8.6&#039;&#039;&#039;]] Implement cryptographic mechanisms to protect the confidentiality of CUI stored on digital media during transport unless otherwise protected by alternative physical safeguards.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the confidentiality of CUI stored on digital media is protected during transport using cryptographic mechanisms or alternative physical safeguards. || Artifact || Artifact showing crypto mechanisms used to protect (are they FIPS 140-2 [13.11]); artifact showing what alternative physical safeguards are in place (i.e. encryption; BitLocker; McAfee ).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MP.L2-3.8.7 – Removable Media ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MP.L2-3.8.7_Details|&#039;&#039;&#039;MP.L2-3.8.7&#039;&#039;&#039;]] Control the use of removable media on system components.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the use of removable media on system components is controlled. || Artifact || Policy showing if removable media is allowed; writable removable media is restricted; tracking artifacts; what tools are used (i.e. Carbon Black, Crowd Strike, GPO, Zoho Desktop Central); procedure/process describing what happens if it is lost; what mechanisms are in place to control/restrict removable media (i.e. Active Directory Groups and Group Policy artifact showing restriction).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MP.L2-3.8.8 – Shared Media ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MP.L2-3.8.8_Details|&#039;&#039;&#039;MP.L2-3.8.8&#039;&#039;&#039;]] Prohibit the use of portable storage devices when such devices have no identifiable owner.ASSESSMENT OBJECTIVES&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [a] the use of portable storage devices is prohibited when such devices have no identifiable owner. || Artifact || Policy and/or artifact showing company stance on portable storage devices if there is no owner (are personal USB devices allowed or are they company-issued; artifact showing alerts if device is connected to network (i.e. external HDD, Carbon Black, Crowd Strike, GPO, Zoho Desktop Central.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MP.L2-3.8.9 – Protect Backups ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MP.L2-3.8.9_Details|&#039;&#039;&#039;MP.L2-3.8.9&#039;&#039;&#039;]] Protect the confidentiality of backup CUI at storage locations.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the confidentiality of backup CUI is protected at storage locations. || Artifact || Policy on system backups; artifact showing media labeling; artifact showing encyption (is it FIPS 140-2 [13.11]); Access Control List artifact (i.e. backup tapes, Tivoli Storage Manager).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Personnel Security (PS) ==&lt;br /&gt;
=== PS.L2-3.9.1 – Screen Individuals ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_PS.L2-3.9.1_Details|&#039;&#039;&#039;PS.L2-3.9.1&#039;&#039;&#039;]] Screen individuals prior to authorizing access to organizational systems containing CUI.&lt;br /&gt;
|-&lt;br /&gt;
| [a] individuals are screened prior to authorizing access to organizational systems containing CUI. || Artifact || Screenshot of records of screened personnel/background checks.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== PS.L2-3.9.2 – Personnel Actions ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_PS.L2-3.9.2_Details|&#039;&#039;&#039;PS.L2-3.9.2&#039;&#039;&#039;]] Ensure that organizational systems containing CUI are protected during and after personnel actions such as terminations and transfers.&lt;br /&gt;
|-&lt;br /&gt;
| [a] a policy and/or process for terminating system access and any credentials coincident with personnel actions is established. || Document || Personnel security policy/procedures/instruction; Access control policy/procedure/instruction.&lt;br /&gt;
|-&lt;br /&gt;
| [b] system access and credentials are terminated consistent with personnel actions such as termination or transfer. || Artifact || Screenshot of records of personnel transfer and termination actions.&lt;br /&gt;
|-&lt;br /&gt;
| [c] the system is protected during and after personnel transfer actions. || Artifact || Completed outprocessing checklist.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Physical Protection (PE) ==&lt;br /&gt;
=== PE.L2-3.10.1 – Limit Physical Access [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_PE.L2-3.10.1_Details|&#039;&#039;&#039;PE.L2-3.10.1&#039;&#039;&#039;]] Limit physical access to organizational information systems, equipment, and the respective operating environments to authorized individuals.&lt;br /&gt;
|-&lt;br /&gt;
| [a] authorized individuals allowed physical access are identified. || Artifact || Authorized personnel (names) access list.&lt;br /&gt;
|-&lt;br /&gt;
| [b] physical access to organizational systems is limited to authorized individuals. || Physical Review || Badge reader logs, audit logs, and/or card swipe test.&lt;br /&gt;
|-&lt;br /&gt;
| [c] physical access to equipment is limited to authorized individuals. || Physical Review || Badge reader logs, audit logs, and/or card swipe test.&lt;br /&gt;
|-&lt;br /&gt;
| [d] physical access to operating environments is limited to authorized. || Physical Review || Badge reader logs, audit logs, and/or card swipe test.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== PE.L2-3.10.2 – Monitor Facility ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_PE.L2-3.10.2_Details|&#039;&#039;&#039;PE.L2-3.10.2&#039;&#039;&#039;]] Protect and monitor the physical facility and support infrastructure for organizational systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the physical facility where organizational systems reside is protected. || Physical Review || Physical security measures and barriers into the physical facility (cameras/locks/gates/guards, etc.).&lt;br /&gt;
|-&lt;br /&gt;
| [b] the support infrastructure for organizational systems is protected. || Physical Review || Physical barriers to entries into computer spaces, server rooms, etc.&lt;br /&gt;
|-&lt;br /&gt;
| [c] the physical facility where organizational systems reside is monitored. || Physical Review || Audit logs/how the physical facility is being monitored (cameras/access system/guards, etc.).&lt;br /&gt;
|-&lt;br /&gt;
| [d] the support infrastructure for organizational systems is monitored. || Physical Review || Audit logs/how the physical facility is being monitored (cameras/access system/guards, etc.).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== PE.L2-3.10.3 – Escort Visitors [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_PE.L2-3.10.3_Details|&#039;&#039;&#039;PE.L2-3.10.3&#039;&#039;&#039;]] Escort visitors and monitor visitor activity.&lt;br /&gt;
|-&lt;br /&gt;
| [a] visitors are escorted. || Physical Review || Policy/procedures/instruction on methodology for handling non-authorized personnel (entry to exit).&lt;br /&gt;
|-&lt;br /&gt;
| [b] visitor activity is monitored. || Physical Review || Policy/procedures/instructio on methodology for handling non-authorized personnel (entry to exit).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== PE.L2-3.10.4 – Physical Access Logs [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_PE.L2-3.10.4_Details|&#039;&#039;&#039;PE.L2-3.10.4&#039;&#039;&#039;]] Maintain audit logs of physical access.&lt;br /&gt;
|-&lt;br /&gt;
| [a] audit logs of physical access are maintained. || Artifact || Log or report from badging system.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== PE.L2-3.10.5 – Manage Physical Access [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_PE.L2-3.10.5_Details|&#039;&#039;&#039;PE.L2-3.10.5&#039;&#039;&#039;]] Control and manage physical access devices.&lt;br /&gt;
|-&lt;br /&gt;
| [a] physical access devices are identified. || Document || Physical access control systems description, guard force contract/policy, key locks, logical systems specifications, etc.&lt;br /&gt;
|-&lt;br /&gt;
| [b] physical access devices are controlled. || Physical Review || Inventory records of physical access control devices (e.g. keys, locks, card readers, locks, etc.).&lt;br /&gt;
|-&lt;br /&gt;
| [c] physical access devices are managed. || Physical Review || List of security safeguards controlling access to the facility (e.g. cameras, monitoring by guards, isolation of IT systems equiment and or system components).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== PE.L2-3.10.6 – Alternative Work Sites ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_PE.L2-3.10.6_Details|&#039;&#039;&#039;PE.L2-3.10.6&#039;&#039;&#039;]] Enforce safeguarding measures for CUI at alternate work sites.&lt;br /&gt;
|-&lt;br /&gt;
| [a] safeguarding measures for CUI are defined for alternate work sites. || Document || Telework agreement, Acceptable Use Policy and SOP for alternate work locations; user security training validation which includes physical/logical/technical protections of system at alternate work sites.&lt;br /&gt;
|-&lt;br /&gt;
| [b] safeguarding measures for CUI are enforced for alternate work sites. || Artifact || Monitoring/audit log of user activity and logical/physical/technical mechanisms in place to preclude unauthorized activity (telework agreement , AUP?).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Risk Assessment (RA) ==&lt;br /&gt;
=== RA.L2-3.11.1 – Risk Assessments ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_RA.L2-3.11.1_Details|&#039;&#039;&#039;RA.L2-3.11.1&#039;&#039;&#039;]] Periodically assess the risk to organizational operations (including mission, functions, image, or reputation), organizational assets, and individuals, resulting from the operation of organizational systems and the associated processing, storage, or transmission of CUI.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the frequency to assess risk to organizational operations, organizational assets, and individuals is defined. || Document || Risk assessment policy.&lt;br /&gt;
|-&lt;br /&gt;
| [b] risk to organizational operations, organizational assets, and individuals resulting from the operation of an organizational system that processes, stores, or transmits CUI is assessed with the defined frequency. || Artifact || Copy of last risk assessment done within defined frequency.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== RA.L2-3.11.2 – Vulnerability Scan ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_RA.L2-3.11.2_Details|&#039;&#039;&#039;RA.L2-3.11.2&#039;&#039;&#039;]] Scan for vulnerabilities in organizational systems and applications periodically and when new vulnerabilities affecting those systems and applications are identified.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the frequency to scan for vulnerabilities in organizational systems and applications is defined. || Document || Policy/procedures/instruction addressing vulnerability scanning records.&lt;br /&gt;
|-&lt;br /&gt;
| [b] vulnerability scans are performed on organizational systems with the defined frequency. || Screen Share || System configuration settings of vulnerability scanning scheduling and vulnerability scan results of systems within defined frequency.&lt;br /&gt;
|-&lt;br /&gt;
| [c] vulnerability scans are performed on applications with the defined frequency. || Screen Share || System configuration settings of vulnerability scanning scheduling and vulnerability scan results of applications within defined frequency.&lt;br /&gt;
|-&lt;br /&gt;
| [d] vulnerability scans are performed on organizational systems when new vulnerabilities are identified. || Screen Share || View signatures in scanning tool/ad hoc scan performed as a result.&lt;br /&gt;
|-&lt;br /&gt;
| [e] vulnerability scans are performed on applications when new vulnerabilities are identified. || Screen Share || View signatures in scanning tool/ad hoc scan performed as a result.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== RA.L2-3.11.3 – Vulnerability Remediation ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_RA.L2-3.11.3_Details|&#039;&#039;&#039;RA.L2-3.11.3&#039;&#039;&#039;]] Remediate vulnerabilities in accordance with risk assessments.&lt;br /&gt;
|-&lt;br /&gt;
| [a] vulnerabilities are identified. || Artifact || Scan results showing vulnerabilities identified.&lt;br /&gt;
|-&lt;br /&gt;
| [b] vulnerabilities are remediated in accordance with risk assessments. || Artifact || Screenshot/document of scan results of remediated vulnerabilities in accordance to risk assessments.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Security Assessment (CA) ==&lt;br /&gt;
=== CA.L2-3.12.1 – Security Control Assessment ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_CA.L2-3.12.1_Details|&#039;&#039;&#039;CA.L2-3.12.1&#039;&#039;&#039;]] Periodically assess the security controls in organizational systems to determine if the controls are effective in their application.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the frequency of security control assessments is defined. || Document || SSP.&lt;br /&gt;
|-&lt;br /&gt;
| [b] security controls are assessed with the defined frequency to determine if the controls are effective in their application. || Artifact || Copy of last security control assessment done within defined frequency.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== CA.L2-3.12.2 – Operational Plan of Action ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_CA.L2-3.12.2_Details|&#039;&#039;&#039;CA.L2-3.12.2&#039;&#039;&#039;]] Develop and implement plans of action designed to correct deficiencies and reduce or eliminate vulnerabilities in organizational systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] deficiencies and vulnerabilities to be addressed by the plan of action are identified. || Artifact || Plan of Action (POA).&lt;br /&gt;
|-&lt;br /&gt;
| [b] a plan of action is developed to correct identified deficiencies and reduce or eliminate identified vulnerabilities. || Artifact || Plan of Action (POA).&lt;br /&gt;
|-&lt;br /&gt;
| [c] the plan of action is implemented to correct identified deficiencies and reduce or eliminate identified vulnerabilities. || Artifact || Plan of Action (POA)/previously completed POAs.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== CA.L2-3.12.3 – Security Control Monitoring ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_CA.L2-3.12.3_Details|&#039;&#039;&#039;CA.L2-3.12.3&#039;&#039;&#039;]] Monitor security controls on an ongoing basis to ensure the continued effectiveness of the controls.&lt;br /&gt;
|-&lt;br /&gt;
| [a] security controls are monitored on an ongoing basis to ensure the continued effectiveness of those controls. || Artifact || Collection of risk assessment results, internal or third-party audits/security assessments and/or continuous monitoring reports/alerts (SIEM tool, etc.).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== CA.L2-3.12.4 – System Security Plan ====&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_CA.L2-3.12.4_Details|&#039;&#039;&#039;CA.L2-3.12.4&#039;&#039;&#039;]] Develop, document, and periodically update system security plans that describe system boundaries, system environments of operation, how security requirements are implemented, and the relationships with or connections to other systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] a system security plan is developed. || Document || SSP.&lt;br /&gt;
|-&lt;br /&gt;
| [b] the system boundary is described and documented in the system security plan. || Document || SSP and any supporting documentation.&lt;br /&gt;
|-&lt;br /&gt;
| [c] the system environment of operation is described and documented in the system security plan. || Document || SSP and any supporting documentation.&lt;br /&gt;
|-&lt;br /&gt;
| [d] the security requirements identified and approved by the designated authority as non-applicable are identified. || Document || SSP and required adjudication from DoD CIO.&lt;br /&gt;
|-&lt;br /&gt;
| [e] the method of security requirement implementation is described and documented in the system security plan. || Document || SSP and any supporting documentation.&lt;br /&gt;
|-&lt;br /&gt;
| [f] the relationship with or connection to other systems is described and documented in the system security plan. || Document || SSP and any supporting documentation.&lt;br /&gt;
|-&lt;br /&gt;
| [g] the frequency to update the system security plan is defined. || Document || SSP.&lt;br /&gt;
|-&lt;br /&gt;
| [h] system security plan is updated with the defined frequency. || Document || SSP/any previous versions.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== System and Communications Protection (SC) ==&lt;br /&gt;
=== SC.L2-3.13.1 – Boundary Protection [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.1_Details|&#039;&#039;&#039;SC.L2-3.13.1&#039;&#039;&#039;]] Monitor, control, and protect organizational communications (i.e., information transmitted or received by organizational information systems) at the external boundaries and key internal boundaries of the information systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the external system boundary is defined. || Document || SSP, network diagrams, CUI flow, cloud provider FedRAMP Moderate.&lt;br /&gt;
|-&lt;br /&gt;
| [b] key internal system boundaries are defined. || Document || SSP, network diagrams, CUI flow.&lt;br /&gt;
|-&lt;br /&gt;
| [c] communications are monitored at the external system boundary. || Screen Share || SSP, logging server, boundary device configurations, monitoring policy.&lt;br /&gt;
|-&lt;br /&gt;
| [d] communications are monitored at key internal boundaries. || Screen Share || SSP, logging server, boundary device configurations, monitoring policy.&lt;br /&gt;
|-&lt;br /&gt;
| [e] communications are controlled at the external system boundary. || Screen Share || SSP, boundary device configurations, ACL, subnets, DMZ.&lt;br /&gt;
|-&lt;br /&gt;
| [f] communications are controlled at key internal boundaries. || Screen Share || SSP, boundary device configurations, ACL, subnets.&lt;br /&gt;
|-&lt;br /&gt;
| [g] communications are protected at the external system boundary. || Screen Share || Configurations for IPS/IDS, email gateway, VLAN, proxy, firewall, malware protection, DNS, TSL.&lt;br /&gt;
|-&lt;br /&gt;
| [h] communications are protected at key internal boundaries. || Screen Share || Configurations for IPS/IDS, VLAN, firewall, malware protection, SSL.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.2 – Security Engineering ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.2_Details|&#039;&#039;&#039;SC.L2-3.13.2&#039;&#039;&#039;]] Employ architectural designs, software development techniques, and systems engineering principles that promote effective information security within organizational systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] architectural designs that promote effective information security are identified. || Document || SSP, config management policy, network diagram, CCB minutes, enterprise architecture process.&lt;br /&gt;
|-&lt;br /&gt;
| [b] software development techniques that promote effective information security are identified. || Document || SSP, config management policy, SDLC, CCB minutes.&lt;br /&gt;
|-&lt;br /&gt;
| [c] systems engineering principles that promote effective information security are identified. || Document || SSP, config management policy, CCB minutes, security architecture engineering.&lt;br /&gt;
|-&lt;br /&gt;
| [d] identified architectural designs that promote effective information security are employed. || Artifact || CCB minutes, Network diagrams and configurations, Project Plans.&lt;br /&gt;
|-&lt;br /&gt;
| [e] identified software development techniques that promote effective information security are employed. || Artifact || CCB minutes, SDLC, code scanner results, code management tracking.&lt;br /&gt;
|-&lt;br /&gt;
| [f] identified systems engineering principles that promote effective information security are employed. || Artifact || CCB minutes, configuration management, ITSM, patch management, lifecycle replacement processes.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.3 – Role Separation ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.3_Details|&#039;&#039;&#039;SC.L2-3.13.3&#039;&#039;&#039;]] Separate user functionality from system management functionality.&lt;br /&gt;
|-&lt;br /&gt;
| [a] user functionality is identified. || Document || SSP, AUP.&lt;br /&gt;
|-&lt;br /&gt;
| [b] system management functionality is identified. || Document || SSP, Privileged Account Agreement.&lt;br /&gt;
|-&lt;br /&gt;
| [c] user functionality is separated from system management functionality. || Screen Share || Active Directory, Jump Boxes, GPO, VM, RDP.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.4 – Shared Resource Control ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.4_Details|&#039;&#039;&#039;SC.L2-3.13.4&#039;&#039;&#039;]] Prevent unauthorized and unintended information transfer via shared system resources.&lt;br /&gt;
|-&lt;br /&gt;
| [a] unauthorized and unintended information transfer via shared system resources is prevented. || Screen Share || SSP, OS configurations, Linux containers, system/media reuse policies, certificate management policies, media destruction policies, printer configs, VDI configuration.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
===  SC.L2-3.13.5 – Public-Access System Separation [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.5_Details|&#039;&#039;&#039;SC.L2-3.13.5&#039;&#039;&#039;]] Implement subnetworks for publicly accessible system components that are physically or logically separated from internal networks.&lt;br /&gt;
|-&lt;br /&gt;
| [a] publicly accessible system components are identified. || Document || SSP, network diagram, DMZ inventory/roles.&lt;br /&gt;
|-&lt;br /&gt;
| [b] subnetworks for publicly accessible system components are physically or logically separated from internal networks. || Artifact || Network diagram, IPAM, VLAN, DHCP, DMZ.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.6 – Network Communication by Exception ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.6_Details|&#039;&#039;&#039;SC.L2-3.13.6&#039;&#039;&#039;]] Deny network communications traffic by default and allow network communications traffic by exception (i.e., deny all, permit by exception).&lt;br /&gt;
|-&lt;br /&gt;
| [a] network communications traffic is denied by default. || Screen Share || Host and network firewall rules, SIEM logs, hit counts.&lt;br /&gt;
|-&lt;br /&gt;
| [b] network communications traffic is allowed by exception. || Screen Share || Host and network firewall rules, SIEM logs, hit counts.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.7 – Split Tunneling ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.7_Details|&#039;&#039;&#039;SC.L2-3.13.7&#039;&#039;&#039;]] Prevent remote devices from simultaneously establishing non-remote connections with organizational systems and communicating via some other connection to resources in external networks (i.e., split tunneling).&lt;br /&gt;
|-&lt;br /&gt;
| [a] remote devices are prevented from simultaneously establishing non-remote connections with the system and communicating via some other connection to resources in external networks (i.e., split tunneling). || Screen Share || VPN appliance/server configuration, endpoint VPN software configuration.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.8 – Data in Transit ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.8_Details|&#039;&#039;&#039;SC.L2-3.13.8&#039;&#039;&#039;]] Implement cryptographic mechanisms to prevent unauthorized disclosure of CUI during transmission unless otherwise protected by alternative physical safeguards.&lt;br /&gt;
|-&lt;br /&gt;
| [a] cryptographic mechanisms intended to prevent unauthorized disclosure of CUI are identified. || Document || SSP, PKI policies, configuration processes, config management, email attachment encryption policy, removable media policy, data at rest policy.&lt;br /&gt;
|-&lt;br /&gt;
| [b] alternative physical safeguards intended to prevent unauthorized disclosure of CUI are identified. || Document || SSP, physical security policy.&lt;br /&gt;
|-&lt;br /&gt;
| [c] either cryptographic mechanisms or alternative physical safeguards are implemented to prevent unauthorized disclosure of CUI during transmission. || Screen Share || TLS settings, SSL settings, VPN/Wireless Access Points/Mobile Devices cryptographic settings, ODBC connector settings, SAN configuration, IPSec/MPLS, backup configuration, physical security.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.9 – Connections Termination ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.9_Details|&#039;&#039;&#039;SC.L2-3.13.9&#039;&#039;&#039;]] Terminate network connections associated with communications sessions at the end of the sessions or after a defined period of inactivity.&lt;br /&gt;
|-&lt;br /&gt;
| [a] a period of inactivity to terminate network connections associated with communications sessions is defined. || Document || SSP, network communications policy.&lt;br /&gt;
|-&lt;br /&gt;
| [b] network connections associated with communications sessions are terminated at the end of the sessions. || Screen Share || VPN appliance/server logs, VPN configurations, web server configurations, firewall connection settings.&lt;br /&gt;
|-&lt;br /&gt;
| [c] network connections associated with communications sessions are terminated after the defined period of inactivity. || Screen Share || VPN appliance/server logs, VPN configurations, web server configurations, frewall connection settings.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.10 – Key Management ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.10_Details|&#039;&#039;&#039;SC.L2-3.13.10&#039;&#039;&#039;]] Establish and manage cryptographic keys for cryptography employed in organizational systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] cryptographic keys are established whenever cryptography is employed. || Artifact || SSP, PKI/certificate management policy, configuration management.&lt;br /&gt;
|-&lt;br /&gt;
| [b] cryptographic keys are managed whenever cryptography is employed. || Artifact || SSP, PKI/certificate management policy, configuration management, access control policy.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.11 – CUI Encryption ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.11_Details|&#039;&#039;&#039;SC.L2-3.13.11&#039;&#039;&#039;]] Employ FIPS-validated cryptography when used to protect the confidentiality of CUI.&lt;br /&gt;
|-&lt;br /&gt;
| [a] FIPS-validated cryptography is employed to protect the confidentiality of CUI. || Screen Share || VPN, wireless, mobile devices, client certificates, server certificates, disk encryption, Outlook plugin, external mail, backup media, ePO server, removable storage, SAN, file compression; look for FIPS mode enabled on appliances.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.12 – Collaborative Device Control ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.12_Details|&#039;&#039;&#039;SC.L2-3.13.12&#039;&#039;&#039;]] Prohibit remote activation of collaborative computing devices and provide indication of devices in use to users present at the device.&lt;br /&gt;
|-&lt;br /&gt;
| [a] collaborative computing devices are identified. || Document || SSP, network diagrams.&lt;br /&gt;
|-&lt;br /&gt;
| [b] collaborative computing devices provide indication to users of devices in use. || Physical Review || Physical inspection of device.&lt;br /&gt;
|-&lt;br /&gt;
| [c] remote activation of collaborative computing devices is prohibited. || Screen Share || Collaboration device configuration/console.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.13 – Mobile Code ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.13_Details|&#039;&#039;&#039;SC.L2-3.13.13&#039;&#039;&#039;]] Control and monitor the use of mobile code.&lt;br /&gt;
|-&lt;br /&gt;
| [a] use of mobile code is controlled. || Screen Share || GPO settings, malware protection, software agent configurations, software development policies, code scanners, MDM configuration, firewall/secure web gateway/proxy config.&lt;br /&gt;
|-&lt;br /&gt;
| [b] use of mobile code is monitored. || Screen Share || SIEM/console monitoring.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.14 – Voice over Internet Protocol ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.14_Details|&#039;&#039;&#039;SC.L2-3.13.14&#039;&#039;&#039;]] Control and monitor the use of Voice over Internet Protocol (VoIP) technologies.&lt;br /&gt;
|-&lt;br /&gt;
| [a] use of Voice over Internet Protocol (VoIP) technologies is controlled. || Artifact || VLAN, ACL, firewall config, VoIP gateway/condenser configuration.&lt;br /&gt;
|-&lt;br /&gt;
| [b] use of Voice over Internet Protocol (VoIP) technologies is monitored. || Artifact || SIEM/VoIP console monitoring, session border controller.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.15 – Communications Authenticity ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.15_Details|&#039;&#039;&#039;SC.L2-3.13.15&#039;&#039;&#039;]] Protect the authenticity of communications sessions.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the authenticity of communications sessions is protected. || Screen Share || SSL, TLS, SMB3, SFTP, IPSec, SSH, Kerberos configs, MPLS, Network Access Control.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.16 – Data at Rest ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.16_Details|&#039;&#039;&#039;SC.L2-3.13.16&#039;&#039;&#039;]] Protect the confidentiality of CUI at rest.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the confidentiality of CUI at rest is protected. || Artifact || Full disk encryption, removable media encryption, SAN encryption, digital backups, mobile device encryption, third party offsite backup storage, cloud virtualization encryption, physical media storage policies.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== System and Information Integrity (SI) ==&lt;br /&gt;
=== SI.L2-3.14.1 – Flaw Remediation [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SI.L2-3.14.1_Details|&#039;&#039;&#039;SI.L2-3.14.1&#039;&#039;&#039;]] Identify, report, and correct information and information system flaws in a timely manner.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the time within which to identify system flaws is specified. || Document || SSP, patch management policy.&lt;br /&gt;
|-&lt;br /&gt;
| [b] system flaws are identified within the specified time frame. || Screen Share || Vulnerability management scanner output and scan policy configuration.&lt;br /&gt;
|-&lt;br /&gt;
| [c] the time within which to report system flaws is specified. || Document || SSP, patch management policy.&lt;br /&gt;
|-&lt;br /&gt;
| [d] system flaws are reported within the specified time frame. || Screen Share || ITSM/trouble tickets, vulnerability management scanner output.&lt;br /&gt;
|-&lt;br /&gt;
| [e] the time within which to correct system flaws is specified. || Document || SSP, patch management policy.&lt;br /&gt;
|-&lt;br /&gt;
| [f] system flaws are corrected within the specified time frame. || Screen Share || Vulnerability management scanner output and scan policy configuration.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SI.L2-3.14.2 – Malicious Code ProTection [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SI.L2-3.14.2_Details|&#039;&#039;&#039;SI.L2-3.14.2&#039;&#039;&#039;]] Provide protection from malicious code at appropriate locations within organizational information systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] designated locations for malicious code protection are identified. || Document || SSP, system protection policy, network diagrams, security architecture documents.&lt;br /&gt;
|-&lt;br /&gt;
| [b] protection from malicious code at designated locations is provided. || Screen Share || Endpoint security settings, email/web proxy gateways, firewall, IPS sensor, MDM configuration, Network Access Control.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SI.L2-3.14.3 – Security Alerts &amp;amp; Advisories ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SI.L2-3.14.3_Details|&#039;&#039;&#039;SI.L2-3.14.3&#039;&#039;&#039;]] Monitor system security alerts and advisories and take action in response.&lt;br /&gt;
|-&lt;br /&gt;
| [a] response actions to system security alerts and advisories are identified. || Document || SSP, vulnerability management policy, Incident Response Plan.&lt;br /&gt;
|-&lt;br /&gt;
| [b] system security alerts and advisories are monitored. || Artifact || Threat intelligence subscriptions, email advisories.&lt;br /&gt;
|-&lt;br /&gt;
| [c] actions in response to system security alerts and advisories are taken. || Artifact || ITSM/trouble tickets, user notifications, updates to firewall/IPS, etc.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SI.L2-3.14.4 – Update Malicious Code Protection [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SI.L2-3.14.4_Details|&#039;&#039;&#039;SI.L2-3.14.4&#039;&#039;&#039;]] Update malicious code protection mechanisms when new releases are available.&lt;br /&gt;
|-&lt;br /&gt;
| [a] malicious code protection mechanisms are updated when new releases are available. || Screen Share || Antivirus console dashboard, firewall AV, Email gateway signatures,proxy, IPS updates.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SI.L2-3.14.5 – System &amp;amp; File Scanning [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SI.L2-3.14.5_Details|&#039;&#039;&#039;SI.L2-3.14.5&#039;&#039;&#039;]] Perform periodic scans of the information system and real-time scans of files from external sources as files are downloaded, opened, or executed.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the frequency for malicious code scans is defined. || Document || SSP, vulnerability management policy.&lt;br /&gt;
|-&lt;br /&gt;
| [b] malicious code scans are performed with the defined frequency. || Screen Share || Consoles for AV (endpoints, servers, and file shares), firewall, email gateway, proxy, IPS, MDM configurations.&lt;br /&gt;
|-&lt;br /&gt;
| [c] real-time malicious code scans of files from external sources as files are downloaded, opened, or executed are performed. || Screen Share || Consoles for AV (endpoints, servers, and file shares), firewall, email gateway, proxy, IPS, MDM configurations.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SI.L2-3.14.6 – Monitor Communications for Attacks ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SI.L2-3.14.6_Details|&#039;&#039;&#039;SI.L2-3.14.6&#039;&#039;&#039;]] Monitor organizational systems, including inbound and outbound communications traffic, to detect attacks and indicators of potential attacks.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the system is monitored to detect attacks and indicators of potential attacks. || Screen Share || Firewall, IPS, endpoint protection, SIEM alerts and reports.&lt;br /&gt;
|-&lt;br /&gt;
| [b] inbound communications traffic is monitored to detect attacks and indicators of potential attacks. || Screen Share || Firewall, IPS, endpoint protection, SIEM alerts and reports.&lt;br /&gt;
|-&lt;br /&gt;
| [c] outbound communications traffic is monitored to detect attacks and indicators of potential attacks. || Screen Share || Firewall, IPS, endpoint protection, SIEM alerts and reports.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SI.L2-3.14.7 – Identify Unauthorized Use ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SI.L2-3.14.7_Details|&#039;&#039;&#039;SI.L2-3.14.7&#039;&#039;&#039;]] Identify unauthorized use of organizational systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] authorized use of the system is defined. || Document || AUP, SSP.&lt;br /&gt;
|-&lt;br /&gt;
| [b] unauthorized use of the system is identified. || Artifact || SIEM logs, endpoint protection console, IPS, Firewall.&lt;br /&gt;
|}&lt;/div&gt;</summary>
		<author><name>David</name></author>
	</entry>
	<entry>
		<id>https://cmmcwiki.org/index.php?title=Evidence_Collection_Approach&amp;diff=1623</id>
		<title>Evidence Collection Approach</title>
		<link rel="alternate" type="text/html" href="https://cmmcwiki.org/index.php?title=Evidence_Collection_Approach&amp;diff=1623"/>
		<updated>2026-07-20T01:42:37Z</updated>

		<summary type="html">&lt;p&gt;David: /* IA.L2-3.5.5 – Identifier Reuse */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;CMMC assessments and certification require substantial evidence and documentation. The following tables outline general guidelines for collecting evidence to assess control requirements and objectives. While these guidelines provide a structured approach, they are not the only means of conducting an accurate assessment. Assessors should exercise professional judgment and may employ alternative methods appropriate to the specific organizational context and circumstances.&lt;br /&gt;
&lt;br /&gt;
Evidence collection approaches are defined as:&lt;br /&gt;
* &#039;&#039;&#039;Documentation&#039;&#039;&#039;: Tangible materials containing information over which an organization has authority, including all types of written records and their copies.&lt;br /&gt;
* &#039;&#039;&#039;Artifacts&#039;&#039;&#039;: Tangible, reviewable records directly resulting from a practice or process being performed by a system or by personnel executing their role within that practice, control, or process.&lt;br /&gt;
* &#039;&#039;&#039;Physical Review&#039;&#039;&#039;: Direct on-site observation and examination of evidence.&lt;br /&gt;
* &#039;&#039;&#039;Screen Share&#039;&#039;&#039;: Real-time remote observation of a user demonstrating a task or process via shared computer screen, sometimes called &amp;quot;over-the-shoulder&amp;quot; review.&lt;br /&gt;
&lt;br /&gt;
DISCLAIMER: Evidence requirements vary significantly across assessment types. &#039;&#039;&#039;The examples provided are illustrative only and should be tailored to meet the specific adequacy and sufficiency standards of your particular assessment context.&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
For inquiries and reporting errors on this wiki, please [mailto:support@cmmctoolkit.org contact us]. Thank you.&lt;br /&gt;
&lt;br /&gt;
== Access Control (AC) ==&lt;br /&gt;
=== AC.L2-3.1.1 – Authorized Access Control [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.1_Details|&#039;&#039;&#039;AC.L2-3.1.1&#039;&#039;&#039;]] Limit information system access to authorized users, processes acting on behalf of authorized users, or devices (including other information systems).&lt;br /&gt;
|-&lt;br /&gt;
| [a] authorized users are identified. || Document || Document defining account request, approval, provisioning.&lt;br /&gt;
|-&lt;br /&gt;
| [b] processes acting on behalf of authorized users are identified. || Document || Document defining account request, approval, provisioning.&lt;br /&gt;
|-&lt;br /&gt;
| [c] devices (and other systems) authorized to connect to the system are identified. || Document || Document defining account request, approval, provisioning.&lt;br /&gt;
|-&lt;br /&gt;
| [d] system access is limited to authorized users. || Screen Share || Screen share showing login requirements are enforced. Example of an unauthorized user denied (unauthorized username entered at login).&lt;br /&gt;
|-&lt;br /&gt;
| [e] system access is limited to processes acting on behalf of authorized users. || Screen Share || Screenshot showing that service accounts are assigned to authorized users only; no rogue accounts without an authorized user are active.&lt;br /&gt;
|-&lt;br /&gt;
| [f] system access is limited to authorized devices (including other systems). || Screen Share || Screen share showing that all devices running are authorized; no rogue devices on the network.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.2 – Transaction &amp;amp; Function Control [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.2_Details|&#039;&#039;&#039;AC.L2-3.1.2&#039;&#039;&#039;]] Limit information system access to the types of transactions and functions that authorized users are permitted to execute.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the types of transactions and functions that authorized users are permitted to execute are defined. || Document || SSP, AUP, or IAM document that defines what authorized users can execute.&lt;br /&gt;
|-&lt;br /&gt;
| [b] system access is limited to the defined types of transactions and functions for authorized users. || Screen Share || Screenshot of security roles in AD or IAM or other directory-based identity-related services tool that shows transactions are as defined in the SSP or IAM document; privileged and non-privileged accounts need to be defined and identified in the artifact; screenshot of a non-privileged user trying to execute a privileged function.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.3 – Control CUI Flow ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.3_Details|&#039;&#039;&#039;AC.L2-3.1.3&#039;&#039;&#039;]] Control the flow of CUI in accordance with approved authorizations.&lt;br /&gt;
|-&lt;br /&gt;
| [a] information flow control policies are defined. || Document || SSP or other document describing the control of CUI on the network.&lt;br /&gt;
|-&lt;br /&gt;
| [b] methods and enforcement mechanisms for controlling the flow of CUI are defined. || Document || Document that defines the networking devices that are on the CUI network and answers what measures are in place to control the flow. List of firewalls, border and internal layer 3 devices, IDS/IPS, DLP, that process CUI.&lt;br /&gt;
|-&lt;br /&gt;
| [c] designated sources and destinations (e.g., networks, individuals, and devices) for CUI within the system and between interconnected systems are identified. || Artifact || Network diagram, data flow diagram, external system connection diagrams, document describing the policies for CUI on the network; listing of VLANs and subnets where CUI is authorized; document must describe source and authorized destinations.&lt;br /&gt;
|-&lt;br /&gt;
| [d] authorizations for controlling the flow of CUI are defined. || Document || Document that defines how CUI is to be controlled, such as an InfoSec plan, and/or network management plan.&lt;br /&gt;
|-&lt;br /&gt;
| [e] approved authorizations for controlling the flow of CUI are enforced. || Screen Share || Screenshots of firewall rules, ACLs, etc.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.4 – Separation of Duties ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.4_Details|&#039;&#039;&#039;AC.L2-3.1.4&#039;&#039;&#039;]] Separate the duties of individuals to reduce the risk of malevolent activity without collusion.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the duties of individuals requiring separation are defined. || Document || Document, SSP, account management policy, defining separation of duties by person or role.&lt;br /&gt;
|-&lt;br /&gt;
| [b] responsibilities for duties that require separation are assigned to separate individuals. || Screen Share || Screenshot showing that separation of duties is enforced by showing admin accounts are assigned to different people based on role.&lt;br /&gt;
|-&lt;br /&gt;
| [c] access privileges that enable individuals to exercise the duties that require separation are granted to separate individuals. || Screen Share || Screen shot showing an example such as a security manager can not log into a network device and change ACLs, or network admins can not access security logs in the SIEM tool.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.5 – Least Privilege ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.5_Details|&#039;&#039;&#039;AC.L2-3.1.5&#039;&#039;&#039;]] Employ the principle of least privilege, including for specific security functions and privileged accounts.&lt;br /&gt;
|-&lt;br /&gt;
| [a] privileged accounts are identified. || Document || &amp;quot;SSP or policy (documentation) identify what is considered a privileged account.&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| [b] access to privileged accounts is authorized in accordance with the principle of least privilege. || Artifact || An artifact that identifies the least amount of permissions associated with different types of privileged accounts are approved.&lt;br /&gt;
|-&lt;br /&gt;
| [c] security functions are identified. || Document || &amp;quot;SSP or policy (documentation) identifies what is considered a security account.&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| [d] access to security functions is authorized in accordance with the principle of least privilege. || Artifact || Artifact(s) that identify the least amount of permissions associated with different types of security accounts are approved.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.6 – Non-Privileged Account Use ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.6_Details|&#039;&#039;&#039;AC.L2-3.1.6&#039;&#039;&#039;]] Use non-privileged accounts or roles when accessing nonsecurity functions.&lt;br /&gt;
|-&lt;br /&gt;
| [a] nonsecurity functions are identified. || Document || SSP or account management document, AUP, that defines non-security functions.&lt;br /&gt;
|-&lt;br /&gt;
| [b] users are required to use non-privileged accounts or roles when accessing nonsecurity functions. || Screen Share || Screenshot showing that a privileged user tried to use their admin account to access a non-security function, such as a browser or email (whatever is defined in their policy) and was blocked.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.7 – Privileged Functions ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.7_Details|&#039;&#039;&#039;AC.L2-3.1.7&#039;&#039;&#039;]] Prevent non-privileged users from executing privileged functions and capture the execution of such functions in audit logs.&lt;br /&gt;
|-&lt;br /&gt;
| [a] privileged functions are defined. || Document || SSP or policy (documentation) that defines privileged functions.&lt;br /&gt;
|-&lt;br /&gt;
| [b] non-privileged users are defined. || Document || SSP or policy (documentation) that defines non-privileged users.&lt;br /&gt;
|-&lt;br /&gt;
| [c] non-privileged users are prevented from executing privileged functions. || Screen Share || Screen share that shows that a non-privileged user is not allowed to complete a privileged function (installing software).&lt;br /&gt;
|-&lt;br /&gt;
| [d] the execution of privileged functions is captured in audit logs. || Screen Share || Screen share that shows logs being captured of the execution of privileged functions.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.8 – Unsuccessful Logon Attempts ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.8_Details|&#039;&#039;&#039;AC.L2-3.1.8&#039;&#039;&#039;]] Limit unsuccessful logon attempts.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the means of limiting unsuccessful logon attempts is defined. || Document || SSP or policy (documentation) showing unsuccessful logon attempts settings and or policy.&lt;br /&gt;
|-&lt;br /&gt;
| [b] the defined means of limiting unsuccessful logon attempts is implemented. || Artifact || Artifact showing GPO / Policy for limiting logon attempts.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.9 – Privacy &amp;amp; Security Notices ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.9_Details|&#039;&#039;&#039;AC.L2-3.1.9&#039;&#039;&#039;]] Provide privacy and security notices consistent with applicable CUI rules.&lt;br /&gt;
|-&lt;br /&gt;
| [a] privacy and security notices required by CUI-specified rules are identified, consistent, and associated with the specific CUI category. || Document || SSP or policy (documentation) showing CUI-specified rules are identified, consistent, and associated with the specific CUI category.&lt;br /&gt;
|-&lt;br /&gt;
| [b] privacy and security notices are displayed. || Artifact || Artifact that shows a consent banner or screen that a user sees as they log in to the system.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.10 – Session Lock ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.10_Details|&#039;&#039;&#039;AC.L2-3.1.10&#039;&#039;&#039;]] Use session lock with pattern-hiding displays to prevent access and viewing of data after a period of inactivity.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the period of inactivity after which the system initiates a session lock is defined. || Document || SSP or policy (documentation) that defines the period of inactivity and when a session lock is defined.&lt;br /&gt;
|-&lt;br /&gt;
| [b] access to the system and viewing of data is prevented by initiating a session lock after the defined period of inactivity. || Artifact || Artifact that shows the setting of session lock (GPO or system policy or similar solution addressing the controls supporting centralized management and configuration of operating systems, applications, and users&#039; settings for the working environment of user accounts and computer accounts).&lt;br /&gt;
|-&lt;br /&gt;
| [c] previously visible information is concealed via a pattern-hiding display after the defined period of inactivity. || Document || Screenshot of GPO setting and configuration settings, or similar solution addressing the controls supporting centralized management and configuration of operating systems, applications, and users&#039; settings for the working environment of user accounts and computer accounts.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.11 – Session Termination ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.11_Details|&#039;&#039;&#039;AC.L2-3.1.11&#039;&#039;&#039;]] Terminate (automatically) a user session after a defined condition.&lt;br /&gt;
|-&lt;br /&gt;
| [a] conditions requiring a user session to terminate are defined. || Document || SSP or policy (documentation) that defines the conditions requiring a user session to be terminated.&lt;br /&gt;
|-&lt;br /&gt;
| [b] a user session is automatically terminated after any of the defined conditions. || Screen Share || Screen share showing GPO / VPN Settings that show when a session would be terminated (Idle time, max connection time).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.12 – Control Remote Access ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.12_Details|&#039;&#039;&#039;AC.L2-3.1.12&#039;&#039;&#039;]] Monitor and control remote access sessions.&lt;br /&gt;
|-&lt;br /&gt;
| [a] remote access sessions are permitted. || Document || SSP or policy (documentation) that defines remote access sessions.&lt;br /&gt;
|-&lt;br /&gt;
| [b] the types of permitted remote access are identified. || Document || SSP or policy (documentation) that defines remote access is permitted.&lt;br /&gt;
|-&lt;br /&gt;
| [c] remote access sessions are controlled. || Screen Share || Screen share that shows how the remote access is controlled (access session, and or groups).&lt;br /&gt;
|-&lt;br /&gt;
| [d] remote access sessions are monitored. || Screen Share || Screen share that shows how remote sessions are monitored (logs).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.13 – Remote Access Confidentiality ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.13_Details|&#039;&#039;&#039;AC.L2-3.1.13&#039;&#039;&#039;]] Employ cryptographic mechanisms to protect the confidentiality of remote access sessions.&lt;br /&gt;
|-&lt;br /&gt;
| [a] cryptographic mechanisms to protect the confidentiality of remote access sessions are identified. || Document || SSP or policy (documentation) that discusses the CUI rules, consistent, and associated with the specific CUI category; FIPS Cert # of appliance or application.&lt;br /&gt;
|-&lt;br /&gt;
| [b] cryptographic mechanisms to protect the confidentiality of remote access sessions are implemented. || Screen Share || Screenshot of VPN concentration that shows encryption is on and enabled (point-to-point, etc.).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.14 – Remote Access Routing ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.14_Details|&#039;&#039;&#039;AC.L2-3.1.14&#039;&#039;&#039;]] Route remote access via managed access control points.&lt;br /&gt;
|-&lt;br /&gt;
| [a] managed access control points are identified and implemented. || Screen Share || Screen share that shows access control points (groups and/or users).&lt;br /&gt;
|-&lt;br /&gt;
| [b] remote access is routed through managed network access control points. || Screen Share || Screen share that shows access control points and how they are managed.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.15 – Privileged Remote Access ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.15_Details|&#039;&#039;&#039;AC.L2-3.1.15&#039;&#039;&#039;]] Authorize remote execution of privileged commands and remote access to security-relevant information.&lt;br /&gt;
|-&lt;br /&gt;
| [a] privileged commands authorized for remote execution are identified. || Document || SSP or policy (documentation) that defines what is authorized to be executed remotely and how that is handled.&lt;br /&gt;
|-&lt;br /&gt;
| [b] security-relevant information authorized to be accessed remotely is identified. || Document || SSP or policy (documentation) that defines what can be accessed remotely and what procedures are implemented to allow this (RDP, jump box).&lt;br /&gt;
|-&lt;br /&gt;
| [c] the execution of the identified privileged commands via remote access is authorized. || Artifact || Screen share that shows who has access to perform privileged commands a remotely (access groups for privileged accounts).&lt;br /&gt;
|-&lt;br /&gt;
| [d] access to the identified security-relevant information via remote access is authorized. || Artifact || Screen share that shows the routing of remote access and how it is monitored and how many locations (Firewall, VPN Concentrator).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.16 – Wireless Access Authorization ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.16_Details|&#039;&#039;&#039;AC.L2-3.1.16&#039;&#039;&#039;]] Authorize wireless access prior to allowing such connections.&lt;br /&gt;
|-&lt;br /&gt;
| [a] wireless access points are identified. || Document || SSP, network administration document.&lt;br /&gt;
|-&lt;br /&gt;
| [b] wireless access is authorized prior to allowing such connections. || Screen Share || Authorization profile(s) in Wireless Access Controller or Identity Manager (i.e. Cisco ISE).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.17 – Wireless Access Protection ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.17_Details|&#039;&#039;&#039;AC.L2-3.1.17&#039;&#039;&#039;]] Protect wireless access using authentication and encryption.&lt;br /&gt;
|-&lt;br /&gt;
| [a] wireless access to the system is protected using authentication. || Screen Share || Security page (or similar) of a Wireless Access Controller.&lt;br /&gt;
|-&lt;br /&gt;
| [b] wireless access to the system is protected using encryption. || Screen Share || Security page (or similar) of a Wireless Access Controller.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.18 – Mobile Device Connection ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.18_Details|&#039;&#039;&#039;AC.L2-3.1.18&#039;&#039;&#039;]] Control connection of mobile devices.&lt;br /&gt;
|-&lt;br /&gt;
| [a] mobile devices that process, store, or transmit CUI are identified. || Document || SSP, Mobile Device Policy.&lt;br /&gt;
|-&lt;br /&gt;
| [b] mobile device connections are authorized. || Artifact || Authorization profile(s) in Wireless Access Controller or Identity Manager (i.e. Cisco ISE).&lt;br /&gt;
|-&lt;br /&gt;
| [c] mobile device connections are monitored and logged. || Screen Share || Mobile device logs within the MDM, log intake (sources) configuration (within SIEM) showing MDM is feeding logs to the SIEM.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.19 – Encrypt CUI on Mobile ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.19_Details|&#039;&#039;&#039;AC.L2-3.1.19&#039;&#039;&#039;]] Encrypt CUI on mobile devices and mobile computing platforms.&lt;br /&gt;
|-&lt;br /&gt;
| [a] mobile devices and mobile computing platforms that process, store, or transmit CUI are identified. || Document || SSP, Mobile Device Policy.&lt;br /&gt;
|-&lt;br /&gt;
| [b] encryption is employed to protect CUI on identified mobile devices and mobile computing platforms. || Screen Share || Security policy page in MDM showing how encryption are enforced on mobile device. If no MDM or MDM doesn&#039;t enforce encryption, then validate if the devices used are on the list of devices with native FIPS approved validation.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.20 – External Connections [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.20_Details|&#039;&#039;&#039;AC.L2-3.1.20&#039;&#039;&#039;]] Verify and control/limit connections to and use of external information systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] connections to external systems are identified. || Document || SSP, Systems Interconnection Agreements, SLA.&lt;br /&gt;
|-&lt;br /&gt;
| [b] the use of external systems is identified. || Document || SSP, Systems Interconnection Agreements, SLA.&lt;br /&gt;
|-&lt;br /&gt;
| [c] connections to external systems are verified. || Artifact || SLA for external systems, memorandum for interconnection, information to prove that any cloud solution is at FedRAMP impact level of moderate or higher (i.e. license information, screenshot of AWS cloud dashboard, purchase order document).&lt;br /&gt;
|-&lt;br /&gt;
| [d] the use of external systems is verified. || Artifact || SLA for external systems, memorandum for interconnection, information to prove that any cloud solution is at FedRAMP impact level of moderate or higher (i.e. license information, screenshot of AWS cloud dashboard, purchase order document).&lt;br /&gt;
|-&lt;br /&gt;
| [e] connections to external systems are controlled/limited. || Screen Share || Firewall ruleset for controlling access to cloud service or external system.&lt;br /&gt;
|-&lt;br /&gt;
| [f] the use of external systems is controlled/limited. || Screen Share || Firewall ruleset for controlling access to cloud service or external system.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.21 – Portable Storage Use ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.21_Details|&#039;&#039;&#039;AC.L2-3.1.21&#039;&#039;&#039;]] Limit use of portable storage devices on external systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the use of portable storage devices containing CUI on external systems is identified and documented. || Document || SSP, Removable Media Policy, Acceptable Use Policy (with emphasis on portable media use).&lt;br /&gt;
|-&lt;br /&gt;
| [b] limits on the use of portable storage devices containing CUI on external systems are defined. || Document || SSP, Removable Media Policy, Acceptable Use Policy (with emphasis on portable media use).&lt;br /&gt;
|-&lt;br /&gt;
| [c] the use of portable storage devices containing CUI on external systems is limited as defined. || Document || SSP, Removable Media Policy, Acceptable Use Policy (with emphasis on portable media use).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.22 – Control Public Information [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.22_Details|&#039;&#039;&#039;AC.L2-3.1.22&#039;&#039;&#039;]] Control information posted or processed on publicly accessible information systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] individuals authorized to post or process information on publicly accessible systems are identified. || Document || SSP, Website Governance Plan, Information Release Document.&lt;br /&gt;
|-&lt;br /&gt;
| [b] procedures to ensure CUI is not posted or processed on publicly accessible systems are identified. || Document || SSP, Website Governance Plan, Information Release Document.&lt;br /&gt;
|-&lt;br /&gt;
| [c] a review process is in place prior to posting of any content to publicly accessible systems. || Artifact || &amp;quot;Information release approval process, i.e. chain of email communication from originator, approver, and final decision (may or may not include individual authorized to post); &lt;br /&gt;
SharePoint/electronic or paper form/ ticket system showing information flow between requestor and approver (may or may not include  individual authorized to post).&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| [d] content on publicly accessible systems is reviewed to ensure that it does not include CUI. || Artifact || Incident response process, web design/update/modification SOP etc.&lt;br /&gt;
|-&lt;br /&gt;
| [e] mechanisms are in place to remove and address improper posting of CUI. || Artifact || Incident response process, web design/update/modification SOP etc.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Awareness and Training (AT) ==&lt;br /&gt;
=== AT.L2-3.2.1 – Role-Based Risk Awareness ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AT.L2-3.2.1_Details|&#039;&#039;&#039;AT.L2-3.2.1&#039;&#039;&#039;]] Ensure that managers, systems administrators, and users of organizational systems are made aware of the security risks associated with their activities and of the applicable policies, standards, and procedures related to the security of those systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] security risks associated with organizational activities involving CUI are identified. || Document || Policy of Security Awareness Training; Security Awareness Training Briefing.&lt;br /&gt;
|-&lt;br /&gt;
| [b] policies, standards, and procedures related to the security of the system are identified. || Document || Acceptable Use Policy, Policy/Procedures/Instruction related to the security of the system.&lt;br /&gt;
|-&lt;br /&gt;
| [c] managers, systems administrators, and users of the system are made aware of the security risks associated with their activities. || Artifact || Security Training Brief, training records.&lt;br /&gt;
|-&lt;br /&gt;
| [d] managers, systems administrators, and users of the system are made aware of the applicable policies, standards, and procedures related to the security of the system. || Artifact || Policies, standards and procedures for employees within training (completed training report).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AT.L2-3.2.2 – Role-Based Training ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AT.L2-3.2.2_Details|&#039;&#039;&#039;AT.L2-3.2.2&#039;&#039;&#039;]] Ensure that personnel are trained to carry out their assigned information security-related duties and responsibilities.|-&lt;br /&gt;
|-&lt;br /&gt;
| [a] information security-related duties, roles, and responsibilities are defined. || Document || Policy/Procedures/Instruction, Job Role Matrix, Position Descriptions, User Roles.&lt;br /&gt;
|-&lt;br /&gt;
| [b] information security-related duties, roles, and responsibilities are assigned to designated personnel. || Artifact || Screenshot of breakout of different roles/permissions assigned to individuals (i.e. ActiveDirectory); Privilege Access Agreement.&lt;br /&gt;
|-&lt;br /&gt;
| [c] personnel are adequately trained to carry out their assigned information security-related duties, roles, and responsibilities. || Artifact || Screenshot of tool and/or training specifying security specific roles, duties and responsibilities; Screenshot of required certifications (i.e. Sec+, CISSP).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AT.L2-3.2.3 – Insider Threat Awareness ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AT.L2-3.2.3_Details|&#039;&#039;&#039;AT.L2-3.2.3&#039;&#039;&#039;]] Provide security awareness training on recognizing and reporting potential indicators of insider threat.&lt;br /&gt;
|-&lt;br /&gt;
| [a] potential indicators associated with insider threats are identified. || Document || Insidert Threat Policy/Procedures/Instruction; Insider Threat Training/Briefing.&lt;br /&gt;
|-&lt;br /&gt;
| [b] security awareness training on recognizing and reporting potential indicators of insider threat is provided to managers and employees. || Artifact || Screenshot of training records showing completion of Insider Threat training, emails showing completion of Insider Threat training, Screenshot of certificate showing completion with individual&#039;s name.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Audit and Accountability (AU) ==&lt;br /&gt;
=== AU.L2-3.3.1 – System Auditing ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AU.L2-3.3.1_Details|&#039;&#039;&#039;AU.L2-3.3.1&#039;&#039;&#039;]] Create and retain system audit logs and records to the extent needed to enable the monitoring, analysis, investigation, and reporting of unlawful or unauthorized system activity.&lt;br /&gt;
|-&lt;br /&gt;
| [a] audit logs needed (i.e., event types to be logged) to enable the monitoring, analysis, investigation, and reporting of unlawful or unauthorized system activity are specified. || Document || SSP, policy, or auditing and logging process that defines specific types of events to be logged.&lt;br /&gt;
|-&lt;br /&gt;
| [b] the content of audit records needed to support monitoring, analysis, investigation, and reporting of unlawful or unauthorized system activity is defined. || Document || SSP, policy, or auditing and logging process that defines specific content of audit records/files.&lt;br /&gt;
|-&lt;br /&gt;
| [c] audit records are created (generated). || Screen Share || Screen share of tool that shows logs are generated for all systems.&lt;br /&gt;
|-&lt;br /&gt;
| [d] audit records, once created, contain the defined content. || Screen Share || Screen share of tool that shows logs contain defined content as defined in SSP, policy, or procedures.&lt;br /&gt;
|-&lt;br /&gt;
| [e] retention requirements for audit records are defined. || Document || SSP, Polocy, or Auditing and logging process that describes how long records are kept.&lt;br /&gt;
|-&lt;br /&gt;
| [f] audit records are retained as defined. || Screen Share || Screen share of tool that shows records and audit content retained at a minimum as defined.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AU.L2-3.3.2 – User Accountability ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AU.L2-3.3.2_Details|&#039;&#039;&#039;AU.L2-3.3.2&#039;&#039;&#039;]] Ensure that the actions of individual system users can be uniquely traced to those users so they can be held accountable for their actions.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the content of the audit records needed to support the ability to uniquely trace users to their actions is defined. || Document || SSP, policy, or process that defines actions traced back to individuals.&lt;br /&gt;
|-&lt;br /&gt;
| [b] audit records, once created, contain the defined content. || Screen Share || Screen share of tool that shows audit records traced to specific users/roles.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AU.L2-3.3.3 – Event Review ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AU.L2-3.3.3_Details|&#039;&#039;&#039;AU.L2-3.3.3&#039;&#039;&#039;]] Review and update logged events.&lt;br /&gt;
|-&lt;br /&gt;
| [a] a process for determining when to review logged events is defined. || Document || SSP, policy, or documented process that shows frequency of when to review types of logged events.&lt;br /&gt;
|-&lt;br /&gt;
| [b] event types being logged are reviewed in accordance with the defined review process. || Artifact || Evidence through a documented method such as meeting minutes, CAB minutes, etc. of log sources and log events being logged at the defined frequency.&lt;br /&gt;
|-&lt;br /&gt;
| [c] event types being logged are updated based on the review. || Artifact || Evidence of implementation based on the results of the review of logged events/sources through a ticket, meeting minutes, or screen share of the tool that shows changes implemented (finetuning).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AU.L2-3.3.4 – Audit Failure Alerting ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AU.L2-3.3.4_Details|&#039;&#039;&#039;AU.L2-3.3.4&#039;&#039;&#039;]] Alert in the event of an audit logging process failure.&lt;br /&gt;
|-&lt;br /&gt;
| [a] personnel or roles to be alerted in the event of an audit logging process failure are identified. || Document || SSP, policy, or procedure that shows who needs to be notified in case of an audit failure.&lt;br /&gt;
|-&lt;br /&gt;
| [b] types of audit logging process failures for which alert will be generated are defined. || Document || SSP, policy, or procedure that shows what types of failure will generate notifications.&lt;br /&gt;
|-&lt;br /&gt;
| [c] identified personnel or roles are alerted in the event of an audit logging process failure. || Artifact || Artifact such as email or ticket that shows the identified personnel were alerted of any audit/logging process failure as defined.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AU.L2-3.3.5 – Audit Correlation ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AU.L2-3.3.5_Details|&#039;&#039;&#039;AU.L2-3.3.5&#039;&#039;&#039;]] Correlate audit record review, analysis, and reporting processes for investigation and response to indications of unlawful, unauthorized, suspicious, or unusual activity.&lt;br /&gt;
|-&lt;br /&gt;
| [a] audit record review, analysis, and reporting processes for investigation and response to indications of unlawful, unauthorized, suspicious, or unusual activity are defined. || Document || SSP, policy, or procedure covering audit logging, monitoring, and reporting.&lt;br /&gt;
|-&lt;br /&gt;
| [b] defined audit record review, analysis, and reporting processes are correlated. || Artifact || Artifact showing an audit event and the resultant corrective action or actions to the event; this can be a Help Desk ticket, meeting notes, or a change control board items showing the event and any corrective action taken.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AU.L2-3.3.6 – Reduction &amp;amp; Reporting ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AU.L2-3.3.6_Details|&#039;&#039;&#039;AU.L2-3.3.6&#039;&#039;&#039;]] Provide audit record reduction and report generation to support on-demand analysis and reporting.&lt;br /&gt;
|-&lt;br /&gt;
| [a] an audit record reduction capability that supports on-demand analysis is provided. || Screen Share || Screen share of the logging environment where an event can be selected and traced back to a specific device, or dashboard showing realtime event analysis.&lt;br /&gt;
|-&lt;br /&gt;
| [b] a report generation capability that supports on-demand reporting is provided. || Screen Share || Screen share showing the generation of an on demand report.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AU.L2-3.3.7 – Authoritative Time Source ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AU.L2-3.3.7_Details|&#039;&#039;&#039;AU.L2-3.3.7&#039;&#039;&#039;]] Provide a system capability that compares and synchronizes internal system clocks with an authoritative source to generate time stamps for audit records.&lt;br /&gt;
|-&lt;br /&gt;
| [a] internal system clocks are used to generate time stamps for audit records. || Screen Share || Screen share showing the NTP settings of a windows, Unix, Linux device; a screen share showing the NTP settings of network appliances.&lt;br /&gt;
|-&lt;br /&gt;
| [b] an authoritative source with which to compare and synchronize internal system clocks is specified. || Document || SSP or policy indicating that devices need to be synched to a local authoritative time device that is synched with an authoritative time service.&lt;br /&gt;
|-&lt;br /&gt;
| [c] internal system clocks used to generate time stamps for audit records are compared to and synchronized with the specified authoritative time source. || Screen Share || Screen share showing device logging appliance time is point to the appropriate authoritative time server.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AU.L2-3.3.8 – Audit Protection ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AU.L2-3.3.8_Details|&#039;&#039;&#039;AU.L2-3.3.8&#039;&#039;&#039;]] Protect audit information and audit logging tools from unauthorized access, modification, and deletion.&lt;br /&gt;
|-&lt;br /&gt;
| [a] audit information is protected from unauthorized access. || Screen Share || Screen share showing operating system permissions on the audit folders being restricted to appropriate users.&lt;br /&gt;
|-&lt;br /&gt;
| [b] audit information is protected from unauthorized modification. || Screen Share || Screen share showing operating system permissions on the audit folders being restricted to appropriate users.&lt;br /&gt;
|-&lt;br /&gt;
| [c] audit information is protected from unauthorized deletion. || Screen Share || Screen share showing operating system permissions on the audit folders being restricted to appropriate users.&lt;br /&gt;
|-&lt;br /&gt;
| [d] audit logging tools are protected from unauthorized access. || Screen Share || Artifact showing access permissions in the SIEM tool.&lt;br /&gt;
|-&lt;br /&gt;
| [e] audit logging tools are protected from unauthorized modification. || Screen Share || Artifact showing update permissions in the SIEM tool.&lt;br /&gt;
|-&lt;br /&gt;
| [f] audit logging tools are protected from unauthorized deletion. || Screen Share || Artifact showing delete permissions in the SIEM tool.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AU.L2-3.3.9 – Audit Management ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AU.L2-3.3.9_Details|&#039;&#039;&#039;AU.L2-3.3.9&#039;&#039;&#039;]] Limit management of audit logging functionality to a subset of privileged users.&lt;br /&gt;
|-&lt;br /&gt;
| [a] a subset of privileged users granted access to manage audit logging functionality is defined. || Document || SSP or policy indicating which users or groups have access to audit logs.&lt;br /&gt;
|-&lt;br /&gt;
| [b] management of audit logging functionality is limited to the defined subset of privileged users. || Screen Share || Artifact showing SIEM or OS folder permissions (this should be limited to the assigned users or groups); artifact showing an ACL setting in SIEM tool in regards to logs.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Configuration Management (CM) ==&lt;br /&gt;
=== CM.L2-3.4.1 – System Baselining ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_CM.L2-3.4.1_Details|&#039;&#039;&#039;CM.L2-3.4.1&#039;&#039;&#039;]] Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles.&lt;br /&gt;
|-&lt;br /&gt;
| [a] a baseline configuration is established. || Document || Documentation showing or explaining standard imaging process (how standard images are deployed and where  they are stored).&lt;br /&gt;
|-&lt;br /&gt;
| [b] the baseline configuration includes hardware, software, firmware, and documentation. || Artifact || Screenshot of repository of where images are maintained and information relating to hardware, software, and firmware.&lt;br /&gt;
|-&lt;br /&gt;
| [c] the baseline configuration is maintained (reviewed and updated) throughout the system development life cycle. || Artifact || Screenshot/evidence displaying management of baseline configurations (how often they are being managed as stated).&lt;br /&gt;
|-&lt;br /&gt;
| [d] a system inventory is established. || Document || Screenshot/evidence displaying inventory listing of approved products for use.&lt;br /&gt;
|-&lt;br /&gt;
| [e] the system inventory includes hardware, software, firmware, and documentation. || Artifact || Screeenshot/evidence displaying inventory listing of approved products and versions permitted for use.&lt;br /&gt;
|-&lt;br /&gt;
| [f] the inventory is maintained (reviewed and updated) throughout the system development life cycle. || Artifact || Screeenshot/evidence displaying management of baseline configurations (How often and are they being managed as stated.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== CM.L2-3.4.2 – Security Configuration Enforcement ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_CM.L2-3.4.2_Details|&#039;&#039;&#039;CM.L2-3.4.2&#039;&#039;&#039;]] Establish and enforce security configuration settings for information technology products employed in organizational systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] security configuration settings for information technology products employed in the system are established and included in the baseline configuration. || Document || Documentation explaining methodology used by organization to create secure baselines (STIGs, benchmarks).&lt;br /&gt;
|-&lt;br /&gt;
| [b] security configuration settings for information technology products employed in the system are enforced. || Artifact || Evidence of tool/s used to enforce security configurations to ensure images used are free from modification unless authorized.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== CM.L2-3.4.3 – System Change Management ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_CM.L2-3.4.3_Details|&#039;&#039;&#039;CM.L2-3.4.3&#039;&#039;&#039;]] Track, review, approve or disapprove, and log changes to organizational systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] changes to the system are tracked. || Artifact || Evidence of IT Service Management tool / process used to track system changes.&lt;br /&gt;
|-&lt;br /&gt;
| [b] changes to the system are reviewed. || Artifact || Evidence of IT Service Management tool / process used to review system changes.&lt;br /&gt;
|-&lt;br /&gt;
| [c] changes to the system are approved or disapproved. || Artifact || Evidence of IT Service Management tool / process used to approve/disapprove system changes.&lt;br /&gt;
|-&lt;br /&gt;
| [d] changes to the system are logged. || Artifact || Evidence of IT Service Management tool / process used to log system changes.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== CM.L2-3.4.4 – Security Impact Analysis ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_CM.L2-3.4.4_Details|&#039;&#039;&#039;CM.L2-3.4.4&#039;&#039;&#039;]] Analyze the security impact of changes prior to implementation.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the security impact of changes to the system is analyzed prior to implementation. || Artifact || Document explaining that security impact analysis of proposed changes to a system is conducted prior to implementation.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== CM.L2-3.4.5 – Access Restrictions for Change ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_CM.L2-3.4.5_Details|&#039;&#039;&#039;CM.L2-3.4.5&#039;&#039;&#039;]] Define, document, approve, and enforce physical and logical access restrictions associated with changes to organizational systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] physical access restrictions associated with changes to the system are defined. || Document || Document explaining the process of how physical access restrictions are defined for an individuals ability to make system changes.&lt;br /&gt;
|-&lt;br /&gt;
| [b] physical access restrictions associated with changes to the system are documented. || Document || Document explaining the process of how physical access restrictions are defined for an individuals ability to make system changes are documented; access request process.&lt;br /&gt;
|-&lt;br /&gt;
| [c] physical access restrictions associated with changes to the system are approved. || Artifact || Evidence of process of how physical access to systems are granted (i.e. physical access request sample).&lt;br /&gt;
|-&lt;br /&gt;
| [d] physical access restrictions associated with changes to the system are enforced. || Physical Review || Evidence of process of how physical access to systems are enforced (physical access system).&lt;br /&gt;
|-&lt;br /&gt;
| [e] logical access restrictions associated with changes to the system are defined. || Document || Document explaining the process of how logical access restrictions are defined for an individual&#039;s ability to make system changes.&lt;br /&gt;
|-&lt;br /&gt;
| [f] logical access restrictions associated with changes to the system are documented. || Document || Document explaining the process of how logical access restrictions are defined for an individual&#039;s ability to make system changes are documented.&lt;br /&gt;
|-&lt;br /&gt;
| [g] logical access restrictions associated with changes to the system are approved. || Artifact || Evidence of process of how logical access to systems are granted.&lt;br /&gt;
|-&lt;br /&gt;
| [h] logical access restrictions associated with changes to the system are enforced. || Artifact || Evidence of process of how logical access to systems are enforced.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== CM.L2-3.4.6 – Least Functionality ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_CM.L2-3.4.6_Details|&#039;&#039;&#039;CM.L2-3.4.6&#039;&#039;&#039;]] Employ the principle of least functionality by configuring organizational systems to provide only essential capabilities.&lt;br /&gt;
|-&lt;br /&gt;
| [a] essential system capabilities are defined based on the principle of least functionality. || Document || Documentation explaining how systems are configured to utilize the principle of least functionality for designated users.&lt;br /&gt;
|-&lt;br /&gt;
| [b] the system is configured to provide only the defined essential capabilities. || Screen Share || Evidence displaying how systems are configured to utilize the principle of least functionality for designated users; disabled service settings, accepted standards for hardening (CIS benchmarks, etc.).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== CM.L2-3.4.7 – Nonessential Functionality ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_CM.L2-3.4.7_Details|&#039;&#039;&#039;CM.L2-3.4.7&#039;&#039;&#039;]] Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services.&lt;br /&gt;
|-&lt;br /&gt;
| [a] essential programs are defined. || Document || Documented essential programs specified; build documents; software center; SSP.&lt;br /&gt;
|-&lt;br /&gt;
| [b] the use of nonessential programs is defined. || Document || Documented listing of nonessential programs (whatever is NOT specified in [a]); AUP/User Agreement may identify nonessential use/programs.&lt;br /&gt;
|-&lt;br /&gt;
| [c] the use of nonessential programs is restricted, disabled, or prevented as defined. || Screen Share || Tool used to restrict nonessential programs displays restrictions as defined (McAfee ePO settings, Carbon Black rules, etc.).&lt;br /&gt;
|-&lt;br /&gt;
| [d] essential functions are defined. || Document || Documented essential functions are specified.&lt;br /&gt;
|-&lt;br /&gt;
| [e] the use of nonessential functions is defined. || Document || Documented nonessential functions are specified.&lt;br /&gt;
|-&lt;br /&gt;
| [f] the use of nonessential functions is restricted, disabled, or prevented as defined. || Screen Share || Tool used to restrict essential/nonessential functions displays restrictions as defined.&lt;br /&gt;
|-&lt;br /&gt;
| [g] essential ports are defined. || Document || Documented essential ports are specified.&lt;br /&gt;
|-&lt;br /&gt;
| [h] the use of nonessential ports is defined. || Document || Documented nonessential ports functions are specified.&lt;br /&gt;
|-&lt;br /&gt;
| [i] the use of nonessential ports is restricted, disabled, or prevented as defined. || Screen Share || Tool used to restrict essential/nonessential ports displays restrictions as defined (FW rules; McAfee; GPO, etc.).&lt;br /&gt;
|-&lt;br /&gt;
| [j] essential protocols are defined. || Document || Documented essential protocols are specified.&lt;br /&gt;
|-&lt;br /&gt;
| [k] the use of nonessential protocols is defined. || Document || Documented nonessential protocols functions are specified.&lt;br /&gt;
|-&lt;br /&gt;
| [l] the use of nonessential protocols is restricted, disabled, or prevented as defined. || Screen Share || Tool used to restrict essential/nonessential protocols displays restrictions as defined (FW rules; GPO, etc.).&lt;br /&gt;
|-&lt;br /&gt;
| [m] essential services are defined. || Document || Documented essential services specified.&lt;br /&gt;
|-&lt;br /&gt;
| [n] the use of nonessential services is defined. || Document || Documented nonessential services functions are specified.&lt;br /&gt;
|-&lt;br /&gt;
| [o] the use of nonessential services is restricted, disabled, or prevented as defined. || Screen Share || Tool used to restrict essential/nonessential services displays restrictions as defined.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== CM.L2-3.4.8 – Application Execution Policy ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_CM.L2-3.4.8_Details|&#039;&#039;&#039;CM.L2-3.4.8&#039;&#039;&#039;]] Apply deny-by-exception (blacklisting) policy to prevent the use of unauthorized software or deny-all, permit-by-exception (whitelisting) policy to allow the execution of authorized software.&lt;br /&gt;
|-&lt;br /&gt;
| [a] a policy specifying whether whitelisting or blacklisting is to be implemented is specified. || Document || Documentation explaining whitelisting or blacklisting process.&lt;br /&gt;
|-&lt;br /&gt;
| [b] the software allowed to execute under whitelisting or denied use under blacklisting is specified. || Document || Documentation explaining whitelisting or blacklisting process for software.&lt;br /&gt;
|-&lt;br /&gt;
| [c] whitelisting to allow the execution of authorized software or blacklisting to prevent the use of unauthorized software is implemented as specified. || Screen Share || Tool used for whitelisting or blacklisting for software shows capability of restricting/authorizing software (Carbon Black dashboard, &amp;quot;SW Store&amp;quot;, web proxies, DNS Blackhole, etc.).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== CM.L2-3.4.9 – User-Installed Software ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_CM.L2-3.4.9_Details|&#039;&#039;&#039;CM.L2-3.4.9&#039;&#039;&#039;]] Control and monitor user-installed software.&lt;br /&gt;
|-&lt;br /&gt;
| [a] a policy for controlling the installation of software by users is established. || Document || Documented software authorization process or methodology for approval.&lt;br /&gt;
|-&lt;br /&gt;
| [b] installation of software by users is controlled based on the established policy. || Screen Share || Evidence that approval/restriction in installation of software by authorized personnel is implemented as specified (AUP, GPO, etc.).&lt;br /&gt;
|-&lt;br /&gt;
| [c] installation of software by users is monitored. || Screen Share || Evidence that installation of software by authorized personnel is monitored (SCCM groups, SW Center, etc.).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Identification and Authentication (IA) ==&lt;br /&gt;
=== IA.L2-3.5.1 – Identification [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IA.L2-3.5.1_Details|&#039;&#039;&#039;IA.L2-3.5.1&#039;&#039;&#039;]] Identify information system users, processes acting on behalf of users, or devices.&lt;br /&gt;
|-&lt;br /&gt;
| [a] system users are identified. || Document || Based on what is defined in their documentation (SSP, AUP, Policy, SOP), request to see a sample of non-privileged/privileged users in AD OU group (overlaps with 3.1.1 and 3.1.5).&lt;br /&gt;
|-&lt;br /&gt;
| [b] processes acting on behalf of users are identified. || Document || Based on what is defined in their documentation (SSP, AUP, Policy, SOP), request to see a sample of service accounts in AD OU group (overlaps with 3.1.1 and 3.1.5).&lt;br /&gt;
|-&lt;br /&gt;
| [c] devices accessing the system are identified. || Document || Based on what is defined in their documentation (SSP, AUP, Policy, SOP), request to see a sample of domain-joined workstation &amp;amp; servers in AD OU group (overlaps with 3.1.1 and 3.1.5).  For network devices, request screen share/artifact to show how they are identified on the enterprise network.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IA.L2-3.5.2 – Authentication [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IA.L2-3.5.2_Details|&#039;&#039;&#039;IA.L2-3.5.2&#039;&#039;&#039;]] Authenticate (or verify) the identities of those users, processes, or devices, as a prerequisite to allowing access to organizational information systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the identity of each user is authenticated or verified as a prerequisite to system access. || Screen Share || If the user logs in with non-privileged account during other demoes and then a privileged account, then this should be satisfied.  If screen share is unavailable, request logs to show successful and unsuccessful login by privileged and non-privilged users.&lt;br /&gt;
|-&lt;br /&gt;
| [b] the identity of each process acting on behalf of a user is authenticated or verified as a prerequisite to system access. || Screen Share || Request a log that shows successful/unsuccessful service account trying to log on to company&#039;s asset.&lt;br /&gt;
|-&lt;br /&gt;
| [c] the identity of each device accessing or connecting to the system is authenticated or verified as a prerequisite to system access. || Screen Share || Request a log that shows domain-joined workstation/server authenticating to AD (focus on the MAC/IP address/hostname).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IA.L2-3.5.3 – Multifactor Authentication ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IA.L2-3.5.3_Details|&#039;&#039;&#039;IA.L2-3.5.3&#039;&#039;&#039;]] Use multifactor authentication for local and network access to privileged accounts and for network access to non-privileged accounts.&lt;br /&gt;
|-&lt;br /&gt;
| [a] privileged accounts are identified. || Document || Based on what is defined in their documentation, request to see a sample of privileged users in AD OU group.  Overlaps with 3.1.5.  Screenshot/screen share to show implementation is enforced.&lt;br /&gt;
|-&lt;br /&gt;
| [b] multifactor authentication is implemented for local access to privileged accounts. || Screen Share || SSP, AUP, Policy, SOP that defines that MFA is needed for privileged local access.&lt;br /&gt;
|-&lt;br /&gt;
| [c] multifactor authentication is implemented for network access to privileged accounts. || Screen Share || Within the MFA implementation mechanism, show that privileged users are forced to use MFA;  Screenshot/Screen share to show implementation is enforced.&lt;br /&gt;
|-&lt;br /&gt;
| [d] multifactor authentication is implemented for network access to non-privileged accounts. || Screen Share || Within the MFA implementation mechanism, show that non-privileged users are forced to use MFA; Screenshot/Screen share to show implementation is enforced.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IA.L2-3.5.4 – Replay-Resistant Authentication ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IA.L2-3.5.4_Details|&#039;&#039;&#039;IA.L2-3.5.4&#039;&#039;&#039;]] Employ replay-resistant authentication mechanisms for network access to privileged and non-privileged accounts.&lt;br /&gt;
|-&lt;br /&gt;
| [a] replay-resistant authentication mechanisms are implemented for network account access to privileged and non-privileged accounts. || Screen Share || Show the GPO setting that enforces Kerberos within AD.  If MFA is used, show the implementation to enforce replay resistant techniques.  For non-windows, show the technical solution to enforce replay resistant attacks.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IA.L2-3.5.5 – Identifier Reuse ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IA.L2-3.5.5_Details|&#039;&#039;&#039;IA.L2-3.5.5&#039;&#039;&#039;]] Prevent reuse of identifiers for a defined period.&lt;br /&gt;
|-&lt;br /&gt;
| [a] a period within which identifiers cannot be reused is defined. || Document || SSP, policies, or SOP that defines identifier reuse.&lt;br /&gt;
|-&lt;br /&gt;
| [b] reuse of identifiers is prevented within the defined period. || Artifact || Show the GPO setting/technical solution that enforces what is defined in policy/documentation (this can be automated or manual process; screen share/artifacts can be presented to satisfy this requirement.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IA.L2-3.5.6 – Identifier Handling ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IA.L2-3.5.6_Details|&#039;&#039;&#039;IA.L2-3.5.6&#039;&#039;&#039;]] Disable identifiers after a defined period of inactivity.&lt;br /&gt;
|-&lt;br /&gt;
| [a] a period of inactivity after which an identifier is disabled is defined. || Document || SSP, policy that defines the period of inactivity after which an identifier is disabled.&lt;br /&gt;
|-&lt;br /&gt;
| [b] identifiers are disabled after the defined period of inactivity. || Screen Share || Screen share AD or similar tool supporting directory-based identity-related services for disabled accounts (can be done by hand or script).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IA.L2-3.5.7 – Password Complexity ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IA.L2-3.5.7_Details|&#039;&#039;&#039;IA.L2-3.5.7&#039;&#039;&#039;]] Enforce a minimum password complexity and change of characters when new passwords are created.&lt;br /&gt;
|-&lt;br /&gt;
| [a] password complexity requirements are defined. || Document || SSP, policy that defines password complexity requirements.&lt;br /&gt;
|-&lt;br /&gt;
| [b] password change of character requirements are defined. || Document || SSP, policy that defines change of character requirements are defined.&lt;br /&gt;
|-&lt;br /&gt;
| [c] minimum password complexity requirements as defined are enforced when new passwords are created. || Screen Share || Screen share of AD or similar directory-based identity-related service tool to show complexity requirements.&lt;br /&gt;
|-&lt;br /&gt;
| [d] minimum password change of character requirements as defined are enforced when new passwords are created. || Screen Share || Screen share of Group Policy configuration or similar tool providing centralized management and configuration of operating systems, applications, and users&#039; settings to show that characters must be changed.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IA.L2-3.5.8 – Password Reuse ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IA.L2-3.5.8_Details|&#039;&#039;&#039;IA.L2-3.5.8&#039;&#039;&#039;]] Prohibit password reuse for a specified number of generations.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the number of generations during which a password cannot be reused is specified. || Document || SSP, policy that specifies the number of generations during which a password cannot be reused is specified.&lt;br /&gt;
|-&lt;br /&gt;
| [b] reuse of passwords is prohibited during the specified number of generations. || Screen Share || Screen share Group Policy or similar tool providing centralized management and configuration of operating systems, applications, and users&#039; settings in a directory-based identity-related service tool&#039;s configuration to show reuse of passwords is prohibited.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IA.L2-3.5.9 – Temporary Passwords ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IA.L2-3.5.9_Details|&#039;&#039;&#039;IA.L2-3.5.9&#039;&#039;&#039;]] Allow temporary password use for system logons with an immediate change to a permanent password.&lt;br /&gt;
|-&lt;br /&gt;
| [a] an immediate change to a permanent password is required when a temporary password is used for system logon. || Screen Share || Screen share of Group Policy or similar tool providing centralized management and configuration of operating systems, applications, and users&#039; settings in a directory-based identity-related service tool&#039;s configuration to show &amp;quot;change password at first logon.&amp;quot;&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IA.L2-3.5.10 – Cryptographically-Protected Passwords ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IA.L2-3.5.1_Details|&#039;&#039;&#039;IA.L2-3.5.1&#039;&#039;&#039;]] Store and transmit only cryptographically-protected passwords.&lt;br /&gt;
|-&lt;br /&gt;
| [a] passwords are cryptographically protected in storage. || Screen Share || Screen share Group Policy or similar tool providing centralized management and configuration of operating systems, applications, and users&#039; settings in a directory-based identity-related service tool&#039;s configuration that Kerberos, or a similar network authentication protocol that works on the basis of tickets to allow nodes communicating over a non-secure network to prove their identity to one another in a secure manner, is enabled.&lt;br /&gt;
|-&lt;br /&gt;
| [b] passwords are cryptographically protected in transit. || Screen Share || Screen share Group Policy or similar tool providing centralized management and configuration of operating systems, applications, and users&#039; settings in a directory-based identity-related service tool&#039;s configuration that Kerberos, or a similar network authentication protocol that works on the basis of tickets to allow nodes communicating over a non-secure network to prove their identity to one another in a secure manner, is enabled.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IA.L2-3.5.11 – Obscure Feedback ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IA.L2-3.5.10_Details|&#039;&#039;&#039;IA.L2-3.5.10&#039;&#039;&#039;]] Obscure feedback of authentication information.&lt;br /&gt;
|-&lt;br /&gt;
| [a] authentication information is obscured during the authentication process. || Screen Share || Screen share of Group Policy or similar tool providing centralized management and configuration of operating systems, applications, and users&#039; settings in a directory-based identity-related service tool&#039;s configuration to show that passwords are obscured.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Incident Response (IR) ==&lt;br /&gt;
=== IR.L2-3.6.1 – Incident Handling ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IR.L2-3.6.1_Details|&#039;&#039;&#039;IR.L2-3.6.1&#039;&#039;&#039;]] Establish an operational incident-handling capability for organizational systems that includes preparation, detection, analysis, containment, recovery, and user response activities.&lt;br /&gt;
|-&lt;br /&gt;
| [a] an operational incident-handling capability is established. || Document || Incident Response SOP/Plan.&lt;br /&gt;
|-&lt;br /&gt;
| [b] the operational incident-handling capability includes preparation. || Document || Incident Response SOP/Plan, prior incident report, training, COOP plan.&lt;br /&gt;
|-&lt;br /&gt;
| [c] the operational incident-handling capability includes detection. || Document || Incident Response SOP/Plan; definition of tools used to detect; artifacts showing tools used; prior incident report.&lt;br /&gt;
|-&lt;br /&gt;
| [d] the operational incident-handling capability includes analysis. || Document || Incident Response SOP/Plan; Definition of tools used to analyze potential incidents; artifacts showing tools used for analysis; prior incident report.&lt;br /&gt;
|-&lt;br /&gt;
| [e] the operational incident-handling capability includes containment. || Document || Incident Response SOP/Plan; isolation/quarantine process; user training.&lt;br /&gt;
|-&lt;br /&gt;
| [f] the operational incident-handling capability includes recovery. || Document || Incident Response SOP/Plan; COOP Plan; prior incident reports, re-baselining impacted devices.&lt;br /&gt;
|-&lt;br /&gt;
| [g] the operational incident-handling capability includes user response. || Document || Incident Response SOP/Plan; user awareness training; Help Desk process.&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IR.L2-3.6.2 – Incident Reporting ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IR.L2-3.6.2_Details|&#039;&#039;&#039;IR.L2-3.6.2&#039;&#039;&#039;]] Track, document, and report incidents to designated officials and/or authorities both internal and external to the organization.&lt;br /&gt;
|-&lt;br /&gt;
| [a] incidents are tracked. || Artifact || Incident Response SOP/Plan; ITSM artifact; technical implementation for incident tracking.&lt;br /&gt;
|-&lt;br /&gt;
| [b] incidents are documented. || Artifact || Incident Response SOP/Plan; ITSM artifact; technical implementation for incident tracking.&lt;br /&gt;
|-&lt;br /&gt;
| [c] authorities to whom incidents are to be reported are identified. || Document || Incident Response SOP/Plan.&lt;br /&gt;
|-&lt;br /&gt;
| [d] organizational officials to whom incidents are to be reported are identified. || Document || Incident Response SOP/Plan.&lt;br /&gt;
|-&lt;br /&gt;
| [e] identified authorities are notified of incidents. || Screen Share || Prior incident report; DIBNET login; prior email notifications.&lt;br /&gt;
|-&lt;br /&gt;
| [f] identified organizational officials are notified of incidents. || Artifact || Prior incident report; prior email notifications; tabletop exercises.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IR.L2-3.6.3 – Incident Response Testing ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IR.L2-3.6.3_Details|&#039;&#039;&#039;IR.L2-3.6.3&#039;&#039;&#039;]] Test the organizational incident response capability.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the incident response capability is tested. || Artifact || Incident response table top/scheduled or unscheduled test or penetration test.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Maintenance (MA) ==&lt;br /&gt;
=== MA.L2-3.7.1 – Perform Maintenance ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MA.L2-3.7.1_Details|&#039;&#039;&#039;MA.L2-3.7.1&#039;&#039;&#039;]] Perform maintenance on organizational systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] system maintenance is performed. || Artifact || Establish typical maintenance activities (HVAC, UPS, power distribution, generators, copier maintenance) that are performed; maintenance agreements or contracts detailing these types of activities are acceptable; interview responses should be considered.  This requirement should not be confused with 3.14.1 - report, remediate, and correct system flaws in a timely manner (patch management).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MA.L2-3.7.2 – System Maintenance Control ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MA.L2-3.7.2_Details|&#039;&#039;&#039;MA.L2-3.7.2&#039;&#039;&#039;]] Provide controls on the tools, techniques, mechanisms, and personnel used to conduct system maintenance.&lt;br /&gt;
|-&lt;br /&gt;
| [a] tools used to conduct system maintenance are controlled. || Artifact || Tools may largely depend on the assessed environment; discussion examples include network diagnostic and monitoring tools (including hardware and software); artifacts could demonstrate secured locations/areas for these tools (photos) or checkout sheets/rosters (documents) depicting responsible personnel and the dates/times of checkout.&lt;br /&gt;
|-&lt;br /&gt;
| [b] techniques used to conduct system maintenance are controlled. || Artifact || Processes for scheduling, performing, documenting, reviewing, approving, and monitoring maintenance and repairs for the information system.&lt;br /&gt;
|-&lt;br /&gt;
| [c] mechanisms used to conduct system maintenance are controlled. || Artifact || Processes for scheduling, performing, documenting, reviewing, approving, and monitoring maintenance and repairs for the information system.&lt;br /&gt;
|-&lt;br /&gt;
| [d] personnel used to conduct system maintenance are controlled. || Physical Review || Screenshot of who is authorized to conduct maintenance; maintenance personnel training program.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MA.L2-3.7.3 – Equipment Sanitization ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MA.L2-3.7.3_Details|&#039;&#039;&#039;MA.L2-3.7.3&#039;&#039;&#039;]] Ensure equipment removed for off-site maintenance is sanitized of any CUI.&lt;br /&gt;
|-&lt;br /&gt;
| [a] equipment to be removed from organizational spaces for off-site maintenance is sanitized of any CUI. || Artifact || Document or artifact; record if equipment sanitized; categories of sanitization/destruction defined; sanitization procedural document.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MA.L2-3.7.4 – Media Inspection ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MA.L2-3.7.4_Details|&#039;&#039;&#039;MA.L2-3.7.4&#039;&#039;&#039;]] Check media containing diagnostic and test programs for malicious code before the media are used in organizational systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] media containing diagnostic and test programs are checked for malicious code before being used in organizational systems that process, store, or transmit CUI. || Artifact || Screenshot of diagnostic/test program being used (such as Symantec and McAfee on access scans…).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MA.L2-3.7.5 – Nonlocal Maintenance ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MA.L2-3.7.5_Details|&#039;&#039;&#039;MA.L2-3.7.5&#039;&#039;&#039;]] Require multifactor authentication to establish nonlocal maintenance sessions via external network connections and terminate such connections when nonlocal maintenance is complete.&lt;br /&gt;
|-&lt;br /&gt;
| [a] multifactor authentication is used to establish nonlocal maintenance sessions via external network connections. || Screen Share || Describe MFA used to remote from external service to organizational systems for maintenance and screenshot of MFA (3.5.3)(points associated with admin).&lt;br /&gt;
|-&lt;br /&gt;
| [b] nonlocal maintenance sessions established via external network connections are terminated when nonlocal maintenance is complete. || Screen Share || Screenshot VPN session timeout.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MA.L2-3.7.6 – Maintenance Personnel ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MA.L2-3.7.6_Details|&#039;&#039;&#039;MA.L2-3.7.6&#039;&#039;&#039;]] Supervise the maintenance activities of maintenance personnel without required access authorization.&lt;br /&gt;
|-&lt;br /&gt;
| [a] maintenance personnel without required access authorization are supervised during maintenance activities. || Document || System maintenance policy; list of authorized personnel; maintenance records or, contracts/SLAs; WebEx.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Media Protection (MP) ==&lt;br /&gt;
=== MP.L2-3.8.1 – Media Protection ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MP.L2-3.8.1_Details|&#039;&#039;&#039;MP.L2-3.8.1&#039;&#039;&#039;]] Protect (i.e., physically control and securely store) system media containing CUI, both paper and digital.&lt;br /&gt;
|-&lt;br /&gt;
| [a] paper media containing CUI is physically controlled. || Document || Policy showing CUI paper media is controlled; artifact showing who has access; artifacts/records of  inventories conducted; media check out procedures (i.e. file cabinets, encryption, password protection).&lt;br /&gt;
|-&lt;br /&gt;
| [b] digital media containing CUI is physically controlled. || Document || Policy showing CUI digital media is controlled; artifact showing who has access; artifacts/records of inventories conducted; media check out procedures (i.e. file cabinets, external drives, USBs, encryption, password protection).&lt;br /&gt;
|-&lt;br /&gt;
| [c] paper media containing CUI is securely stored. || Physical Review || Check out/sign out sheets; possible photo of storage container/video walk through of storage area; badge reader logs or access lists for keys for secured areas; interview response considered (i.e. file cabinets,  encryption, password protection).&lt;br /&gt;
|-&lt;br /&gt;
| [d] digital media containing CUI is securely stored. || Physical Review || Check out/sign out sheets; possible photo of storage container/video walk through of storage area; badge reader logs or access lists for keys for secured areas; interview response considered (i.e. file cabinets, external drives, USBs, encryption, password protection).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MP.L2-3.8.2 – Media Access ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MP.L2-3.8.2_Details|&#039;&#039;&#039;MP.L2-3.8.2&#039;&#039;&#039;]] Limit access to CUI on system media to authorized users.&lt;br /&gt;
|-&lt;br /&gt;
| [a] access to CUI on system media is limited to authorized users. || Artifact || Document describing how CUI is limited AND artifact showing principle of least access is implemented.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MP.L2-3.8.3 – Media Disposal [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MP.L2-3.8.3_Details|&#039;&#039;&#039;MP.L2-3.8.3&#039;&#039;&#039;]] Sanitize or destroy information system media containing Federal Contract Information before disposal or release for reuse.&lt;br /&gt;
|-&lt;br /&gt;
| [a] system media containing CUI is sanitized or destroyed before disposal. || Document || Policy or artifact of media destruction logs; certificates of destruction; SLAs or contracts.&lt;br /&gt;
|-&lt;br /&gt;
| [b] system media containing CUI is sanitized before it is released for reuse. || Document || Policy or artifact describing method to sanitize, software used (i.e. DoD Wipe, ShredIT and Iron Mountain; Blancco; GDisk, DBAN).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MP.L2-3.8.4 – Media Markings ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MP.L2-3.8.4_Details|&#039;&#039;&#039;MP.L2-3.8.4&#039;&#039;&#039;]] Mark media with necessary CUI markings and distribution limitations.&lt;br /&gt;
|-&lt;br /&gt;
| [a] media containing CUI is marked with applicable CUI markings. || Physical Review || Document or artifact showing CUI markings (i.e. labeling standards ).&lt;br /&gt;
|-&lt;br /&gt;
| [b] media containing CUI is marked with distribution limitations. || Physical Review || Document or artifact showing distro limitations (i.e. labeling standards ).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MP.L2-3.8.5 – Media Accountability ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MP.L2-3.8.5_Details|&#039;&#039;&#039;MP.L2-3.8.5&#039;&#039;&#039;]] Control access to media containing CUI and maintain accountability for media during transport outside of controlled areas.&lt;br /&gt;
|-&lt;br /&gt;
| [a] access to media containing CUI is controlled. || Document || Policy, artifact of audit logs showing tracking, Access Control Lists, records of transport activities (i.e. USB drives, CDs, chain of custody.&lt;br /&gt;
|-&lt;br /&gt;
| [b] accountability for media containing CUI is maintained during transport outside of controlled areas. || Artifact || Artifact of audit logs showing tracking, Access Control Lists, records of transport activities (i.e. USB drives, CDs; chain of custody.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MP.L2-3.8.6 – Portable Storage Encryption ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MP.L2-3.8.6_Details|&#039;&#039;&#039;MP.L2-3.8.6&#039;&#039;&#039;]] Implement cryptographic mechanisms to protect the confidentiality of CUI stored on digital media during transport unless otherwise protected by alternative physical safeguards.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the confidentiality of CUI stored on digital media is protected during transport using cryptographic mechanisms or alternative physical safeguards. || Artifact || Artifact showing crypto mechanisms used to protect (are they FIPS 140-2 [13.11]); artifact showing what alternative physical safeguards are in place (i.e. encryption; BitLocker; McAfee ).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MP.L2-3.8.7 – Removable Media ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MP.L2-3.8.7_Details|&#039;&#039;&#039;MP.L2-3.8.7&#039;&#039;&#039;]] Control the use of removable media on system components.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the use of removable media on system components is controlled. || Artifact || Policy showing if removable media is allowed; writable removable media is restricted; tracking artifacts; what tools are used (i.e. Carbon Black, Crowd Strike, GPO, Zoho Desktop Central); procedure/process describing what happens if it is lost; what mechanisms are in place to control/restrict removable media (i.e. Active Directory Groups and Group Policy artifact showing restriction).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MP.L2-3.8.8 – Shared Media ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MP.L2-3.8.8_Details|&#039;&#039;&#039;MP.L2-3.8.8&#039;&#039;&#039;]] Prohibit the use of portable storage devices when such devices have no identifiable owner.ASSESSMENT OBJECTIVES&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [a] the use of portable storage devices is prohibited when such devices have no identifiable owner. || Artifact || Policy and/or artifact showing company stance on portable storage devices if there is no owner (are personal USB devices allowed or are they company-issued; artifact showing alerts if device is connected to network (i.e. external HDD, Carbon Black, Crowd Strike, GPO, Zoho Desktop Central.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MP.L2-3.8.9 – Protect Backups ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MP.L2-3.8.9_Details|&#039;&#039;&#039;MP.L2-3.8.9&#039;&#039;&#039;]] Protect the confidentiality of backup CUI at storage locations.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the confidentiality of backup CUI is protected at storage locations. || Artifact || Policy on system backups; artifact showing media labeling; artifact showing encyption (is it FIPS 140-2 [13.11]); Access Control List artifact (i.e. backup tapes, Tivoli Storage Manager).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Personnel Security (PS) ==&lt;br /&gt;
=== PS.L2-3.9.1 – Screen Individuals ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_PS.L2-3.9.1_Details|&#039;&#039;&#039;PS.L2-3.9.1&#039;&#039;&#039;]] Screen individuals prior to authorizing access to organizational systems containing CUI.&lt;br /&gt;
|-&lt;br /&gt;
| [a] individuals are screened prior to authorizing access to organizational systems containing CUI. || Artifact || Screenshot of records of screened personnel/background checks.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== PS.L2-3.9.2 – Personnel Actions ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_PS.L2-3.9.2_Details|&#039;&#039;&#039;PS.L2-3.9.2&#039;&#039;&#039;]] Ensure that organizational systems containing CUI are protected during and after personnel actions such as terminations and transfers.&lt;br /&gt;
|-&lt;br /&gt;
| [a] a policy and/or process for terminating system access and any credentials coincident with personnel actions is established. || Document || Personnel security policy/procedures/instruction; Access control policy/procedure/instruction.&lt;br /&gt;
|-&lt;br /&gt;
| [b] system access and credentials are terminated consistent with personnel actions such as termination or transfer. || Artifact || Screenshot of records of personnel transfer and termination actions.&lt;br /&gt;
|-&lt;br /&gt;
| [c] the system is protected during and after personnel transfer actions. || Artifact || Completed outprocessing checklist.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Physical Protection (PE) ==&lt;br /&gt;
=== PE.L2-3.10.1 – Limit Physical Access [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_PE.L2-3.10.1_Details|&#039;&#039;&#039;PE.L2-3.10.1&#039;&#039;&#039;]] Limit physical access to organizational information systems, equipment, and the respective operating environments to authorized individuals.&lt;br /&gt;
|-&lt;br /&gt;
| [a] authorized individuals allowed physical access are identified. || Artifact || Authorized personnel (names) access list.&lt;br /&gt;
|-&lt;br /&gt;
| [b] physical access to organizational systems is limited to authorized individuals. || Physical Review || Badge reader logs, audit logs, and/or card swipe test.&lt;br /&gt;
|-&lt;br /&gt;
| [c] physical access to equipment is limited to authorized individuals. || Physical Review || Badge reader logs, audit logs, and/or card swipe test.&lt;br /&gt;
|-&lt;br /&gt;
| [d] physical access to operating environments is limited to authorized. || Physical Review || Badge reader logs, audit logs, and/or card swipe test.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== PE.L2-3.10.2 – Monitor Facility ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_PE.L2-3.10.2_Details|&#039;&#039;&#039;PE.L2-3.10.2&#039;&#039;&#039;]] Protect and monitor the physical facility and support infrastructure for organizational systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the physical facility where organizational systems reside is protected. || Physical Review || Physical security measures and barriers into the physical facility (cameras/locks/gates/guards, etc.).&lt;br /&gt;
|-&lt;br /&gt;
| [b] the support infrastructure for organizational systems is protected. || Physical Review || Physical barriers to entries into computer spaces, server rooms, etc.&lt;br /&gt;
|-&lt;br /&gt;
| [c] the physical facility where organizational systems reside is monitored. || Physical Review || Audit logs/how the physical facility is being monitored (cameras/access system/guards, etc.).&lt;br /&gt;
|-&lt;br /&gt;
| [d] the support infrastructure for organizational systems is monitored. || Physical Review || Audit logs/how the physical facility is being monitored (cameras/access system/guards, etc.).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== PE.L2-3.10.3 – Escort Visitors [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_PE.L2-3.10.3_Details|&#039;&#039;&#039;PE.L2-3.10.3&#039;&#039;&#039;]] Escort visitors and monitor visitor activity.&lt;br /&gt;
|-&lt;br /&gt;
| [a] visitors are escorted. || Physical Review || Policy/procedures/instruction on methodology for handling non-authorized personnel (entry to exit).&lt;br /&gt;
|-&lt;br /&gt;
| [b] visitor activity is monitored. || Physical Review || Policy/procedures/instructio on methodology for handling non-authorized personnel (entry to exit).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== PE.L2-3.10.4 – Physical Access Logs [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_PE.L2-3.10.4_Details|&#039;&#039;&#039;PE.L2-3.10.4&#039;&#039;&#039;]] Maintain audit logs of physical access.&lt;br /&gt;
|-&lt;br /&gt;
| [a] audit logs of physical access are maintained. || Artifact || Log or report from badging system.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== PE.L2-3.10.5 – Manage Physical Access [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_PE.L2-3.10.5_Details|&#039;&#039;&#039;PE.L2-3.10.5&#039;&#039;&#039;]] Control and manage physical access devices.&lt;br /&gt;
|-&lt;br /&gt;
| [a] physical access devices are identified. || Document || Physical access control systems description, guard force contract/policy, key locks, logical systems specifications, etc.&lt;br /&gt;
|-&lt;br /&gt;
| [b] physical access devices are controlled. || Physical Review || Inventory records of physical access control devices (e.g. keys, locks, card readers, locks, etc.).&lt;br /&gt;
|-&lt;br /&gt;
| [c] physical access devices are managed. || Physical Review || List of security safeguards controlling access to the facility (e.g. cameras, monitoring by guards, isolation of IT systems equiment and or system components).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== PE.L2-3.10.6 – Alternative Work Sites ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_PE.L2-3.10.6_Details|&#039;&#039;&#039;PE.L2-3.10.6&#039;&#039;&#039;]] Enforce safeguarding measures for CUI at alternate work sites.&lt;br /&gt;
|-&lt;br /&gt;
| [a] safeguarding measures for CUI are defined for alternate work sites. || Document || Telework agreement, Acceptable Use Policy and SOP for alternate work locations; user security training validation which includes physical/logical/technical protections of system at alternate work sites.&lt;br /&gt;
|-&lt;br /&gt;
| [b] safeguarding measures for CUI are enforced for alternate work sites. || Artifact || Monitoring/audit log of user activity and logical/physical/technical mechanisms in place to preclude unauthorized activity (telework agreement , AUP?).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Risk Assessment (RA) ==&lt;br /&gt;
=== RA.L2-3.11.1 – Risk Assessments ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_RA.L2-3.11.1_Details|&#039;&#039;&#039;RA.L2-3.11.1&#039;&#039;&#039;]] Periodically assess the risk to organizational operations (including mission, functions, image, or reputation), organizational assets, and individuals, resulting from the operation of organizational systems and the associated processing, storage, or transmission of CUI.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the frequency to assess risk to organizational operations, organizational assets, and individuals is defined. || Document || Risk assessment policy.&lt;br /&gt;
|-&lt;br /&gt;
| [b] risk to organizational operations, organizational assets, and individuals resulting from the operation of an organizational system that processes, stores, or transmits CUI is assessed with the defined frequency. || Artifact || Copy of last risk assessment done within defined frequency.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== RA.L2-3.11.2 – Vulnerability Scan ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_RA.L2-3.11.2_Details|&#039;&#039;&#039;RA.L2-3.11.2&#039;&#039;&#039;]] Scan for vulnerabilities in organizational systems and applications periodically and when new vulnerabilities affecting those systems and applications are identified.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the frequency to scan for vulnerabilities in organizational systems and applications is defined. || Document || Policy/procedures/instruction addressing vulnerability scanning records.&lt;br /&gt;
|-&lt;br /&gt;
| [b] vulnerability scans are performed on organizational systems with the defined frequency. || Screen Share || System configuration settings of vulnerability scanning scheduling and vulnerability scan results of systems within defined frequency.&lt;br /&gt;
|-&lt;br /&gt;
| [c] vulnerability scans are performed on applications with the defined frequency. || Screen Share || System configuration settings of vulnerability scanning scheduling and vulnerability scan results of applications within defined frequency.&lt;br /&gt;
|-&lt;br /&gt;
| [d] vulnerability scans are performed on organizational systems when new vulnerabilities are identified. || Screen Share || View signatures in scanning tool/ad hoc scan performed as a result.&lt;br /&gt;
|-&lt;br /&gt;
| [e] vulnerability scans are performed on applications when new vulnerabilities are identified. || Screen Share || View signatures in scanning tool/ad hoc scan performed as a result.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== RA.L2-3.11.3 – Vulnerability Remediation ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_RA.L2-3.11.3_Details|&#039;&#039;&#039;RA.L2-3.11.3&#039;&#039;&#039;]] Remediate vulnerabilities in accordance with risk assessments.&lt;br /&gt;
|-&lt;br /&gt;
| [a] vulnerabilities are identified. || Artifact || Scan results showing vulnerabilities identified.&lt;br /&gt;
|-&lt;br /&gt;
| [b] vulnerabilities are remediated in accordance with risk assessments. || Artifact || Screenshot/document of scan results of remediated vulnerabilities in accordance to risk assessments.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Security Assessment (CA) ==&lt;br /&gt;
=== CA.L2-3.12.1 – Security Control Assessment ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_CA.L2-3.12.1_Details|&#039;&#039;&#039;CA.L2-3.12.1&#039;&#039;&#039;]] Periodically assess the security controls in organizational systems to determine if the controls are effective in their application.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the frequency of security control assessments is defined. || Document || SSP.&lt;br /&gt;
|-&lt;br /&gt;
| [b] security controls are assessed with the defined frequency to determine if the controls are effective in their application. || Artifact || Copy of last security control assessment done within defined frequency.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== CA.L2-3.12.2 – Operational Plan of Action ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_CA.L2-3.12.2_Details|&#039;&#039;&#039;CA.L2-3.12.2&#039;&#039;&#039;]] Develop and implement plans of action designed to correct deficiencies and reduce or eliminate vulnerabilities in organizational systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] deficiencies and vulnerabilities to be addressed by the plan of action are identified. || Artifact || Plan of Action (POA).&lt;br /&gt;
|-&lt;br /&gt;
| [b] a plan of action is developed to correct identified deficiencies and reduce or eliminate identified vulnerabilities. || Artifact || Plan of Action (POA).&lt;br /&gt;
|-&lt;br /&gt;
| [c] the plan of action is implemented to correct identified deficiencies and reduce or eliminate identified vulnerabilities. || Artifact || Plan of Action (POA)/previously completed POAs.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== CA.L2-3.12.3 – Security Control Monitoring ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_CA.L2-3.12.3_Details|&#039;&#039;&#039;CA.L2-3.12.3&#039;&#039;&#039;]] Monitor security controls on an ongoing basis to ensure the continued effectiveness of the controls.&lt;br /&gt;
|-&lt;br /&gt;
| [a] security controls are monitored on an ongoing basis to ensure the continued effectiveness of those controls. || Artifact || Collection of risk assessment results, internal or third-party audits/security assessments and/or continuous monitoring reports/alerts (SIEM tool, etc.).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== CA.L2-3.12.4 – System Security Plan ====&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_CA.L2-3.12.4_Details|&#039;&#039;&#039;CA.L2-3.12.4&#039;&#039;&#039;]] Develop, document, and periodically update system security plans that describe system boundaries, system environments of operation, how security requirements are implemented, and the relationships with or connections to other systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] a system security plan is developed. || Document || SSP.&lt;br /&gt;
|-&lt;br /&gt;
| [b] the system boundary is described and documented in the system security plan. || Document || SSP and any supporting documentation.&lt;br /&gt;
|-&lt;br /&gt;
| [c] the system environment of operation is described and documented in the system security plan. || Document || SSP and any supporting documentation.&lt;br /&gt;
|-&lt;br /&gt;
| [d] the security requirements identified and approved by the designated authority as non-applicable are identified. || Document || SSP and required adjudication from DoD CIO.&lt;br /&gt;
|-&lt;br /&gt;
| [e] the method of security requirement implementation is described and documented in the system security plan. || Document || SSP and any supporting documentation.&lt;br /&gt;
|-&lt;br /&gt;
| [f] the relationship with or connection to other systems is described and documented in the system security plan. || Document || SSP and any supporting documentation.&lt;br /&gt;
|-&lt;br /&gt;
| [g] the frequency to update the system security plan is defined. || Document || SSP.&lt;br /&gt;
|-&lt;br /&gt;
| [h] system security plan is updated with the defined frequency. || Document || SSP/any previous versions.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== System and Communications Protection (SC) ==&lt;br /&gt;
=== SC.L2-3.13.1 – Boundary Protection [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.1_Details|&#039;&#039;&#039;SC.L2-3.13.1&#039;&#039;&#039;]] Monitor, control, and protect organizational communications (i.e., information transmitted or received by organizational information systems) at the external boundaries and key internal boundaries of the information systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the external system boundary is defined. || Document || SSP, network diagrams, CUI flow, cloud provider FedRAMP Moderate.&lt;br /&gt;
|-&lt;br /&gt;
| [b] key internal system boundaries are defined. || Document || SSP, network diagrams, CUI flow.&lt;br /&gt;
|-&lt;br /&gt;
| [c] communications are monitored at the external system boundary. || Screen Share || SSP, logging server, boundary device configurations, monitoring policy.&lt;br /&gt;
|-&lt;br /&gt;
| [d] communications are monitored at key internal boundaries. || Screen Share || SSP, logging server, boundary device configurations, monitoring policy.&lt;br /&gt;
|-&lt;br /&gt;
| [e] communications are controlled at the external system boundary. || Screen Share || SSP, boundary device configurations, ACL, subnets, DMZ.&lt;br /&gt;
|-&lt;br /&gt;
| [f] communications are controlled at key internal boundaries. || Screen Share || SSP, boundary device configurations, ACL, subnets.&lt;br /&gt;
|-&lt;br /&gt;
| [g] communications are protected at the external system boundary. || Screen Share || Configurations for IPS/IDS, email gateway, VLAN, proxy, firewall, malware protection, DNS, TSL.&lt;br /&gt;
|-&lt;br /&gt;
| [h] communications are protected at key internal boundaries. || Screen Share || Configurations for IPS/IDS, VLAN, firewall, malware protection, SSL.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.2 – Security Engineering ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.2_Details|&#039;&#039;&#039;SC.L2-3.13.2&#039;&#039;&#039;]] Employ architectural designs, software development techniques, and systems engineering principles that promote effective information security within organizational systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] architectural designs that promote effective information security are identified. || Document || SSP, config management policy, network diagram, CCB minutes, enterprise architecture process.&lt;br /&gt;
|-&lt;br /&gt;
| [b] software development techniques that promote effective information security are identified. || Document || SSP, config management policy, SDLC, CCB minutes.&lt;br /&gt;
|-&lt;br /&gt;
| [c] systems engineering principles that promote effective information security are identified. || Document || SSP, config management policy, CCB minutes, security architecture engineering.&lt;br /&gt;
|-&lt;br /&gt;
| [d] identified architectural designs that promote effective information security are employed. || Artifact || CCB minutes, Network diagrams and configurations, Project Plans.&lt;br /&gt;
|-&lt;br /&gt;
| [e] identified software development techniques that promote effective information security are employed. || Artifact || CCB minutes, SDLC, code scanner results, code management tracking.&lt;br /&gt;
|-&lt;br /&gt;
| [f] identified systems engineering principles that promote effective information security are employed. || Artifact || CCB minutes, configuration management, ITSM, patch management, lifecycle replacement processes.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.3 – Role Separation ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.3_Details|&#039;&#039;&#039;SC.L2-3.13.3&#039;&#039;&#039;]] Separate user functionality from system management functionality.&lt;br /&gt;
|-&lt;br /&gt;
| [a] user functionality is identified. || Document || SSP, AUP.&lt;br /&gt;
|-&lt;br /&gt;
| [b] system management functionality is identified. || Document || SSP, Privileged Account Agreement.&lt;br /&gt;
|-&lt;br /&gt;
| [c] user functionality is separated from system management functionality. || Screen Share || Active Directory, Jump Boxes, GPO, VM, RDP.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.4 – Shared Resource Control ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.4_Details|&#039;&#039;&#039;SC.L2-3.13.4&#039;&#039;&#039;]] Prevent unauthorized and unintended information transfer via shared system resources.&lt;br /&gt;
|-&lt;br /&gt;
| [a] unauthorized and unintended information transfer via shared system resources is prevented. || Screen Share || SSP, OS configurations, Linux containers, system/media reuse policies, certificate management policies, media destruction policies, printer configs, VDI configuration.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
===  SC.L2-3.13.5 – Public-Access System Separation [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.5_Details|&#039;&#039;&#039;SC.L2-3.13.5&#039;&#039;&#039;]] Implement subnetworks for publicly accessible system components that are physically or logically separated from internal networks.&lt;br /&gt;
|-&lt;br /&gt;
| [a] publicly accessible system components are identified. || Document || SSP, network diagram, DMZ inventory/roles.&lt;br /&gt;
|-&lt;br /&gt;
| [b] subnetworks for publicly accessible system components are physically or logically separated from internal networks. || Artifact || Network diagram, IPAM, VLAN, DHCP, DMZ.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.6 – Network Communication by Exception ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.6_Details|&#039;&#039;&#039;SC.L2-3.13.6&#039;&#039;&#039;]] Deny network communications traffic by default and allow network communications traffic by exception (i.e., deny all, permit by exception).&lt;br /&gt;
|-&lt;br /&gt;
| [a] network communications traffic is denied by default. || Screen Share || Host and network firewall rules, SIEM logs, hit counts.&lt;br /&gt;
|-&lt;br /&gt;
| [b] network communications traffic is allowed by exception. || Screen Share || Host and network firewall rules, SIEM logs, hit counts.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.7 – Split Tunneling ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.7_Details|&#039;&#039;&#039;SC.L2-3.13.7&#039;&#039;&#039;]] Prevent remote devices from simultaneously establishing non-remote connections with organizational systems and communicating via some other connection to resources in external networks (i.e., split tunneling).&lt;br /&gt;
|-&lt;br /&gt;
| [a] remote devices are prevented from simultaneously establishing non-remote connections with the system and communicating via some other connection to resources in external networks (i.e., split tunneling). || Screen Share || VPN appliance/server configuration, endpoint VPN software configuration.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.8 – Data in Transit ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.8_Details|&#039;&#039;&#039;SC.L2-3.13.8&#039;&#039;&#039;]] Implement cryptographic mechanisms to prevent unauthorized disclosure of CUI during transmission unless otherwise protected by alternative physical safeguards.&lt;br /&gt;
|-&lt;br /&gt;
| [a] cryptographic mechanisms intended to prevent unauthorized disclosure of CUI are identified. || Document || SSP, PKI policies, configuration processes, config management, email attachment encryption policy, removable media policy, data at rest policy.&lt;br /&gt;
|-&lt;br /&gt;
| [b] alternative physical safeguards intended to prevent unauthorized disclosure of CUI are identified. || Document || SSP, physical security policy.&lt;br /&gt;
|-&lt;br /&gt;
| [c] either cryptographic mechanisms or alternative physical safeguards are implemented to prevent unauthorized disclosure of CUI during transmission. || Screen Share || TLS settings, SSL settings, VPN/Wireless Access Points/Mobile Devices cryptographic settings, ODBC connector settings, SAN configuration, IPSec/MPLS, backup configuration, physical security.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.9 – Connections Termination ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.9_Details|&#039;&#039;&#039;SC.L2-3.13.9&#039;&#039;&#039;]] Terminate network connections associated with communications sessions at the end of the sessions or after a defined period of inactivity.&lt;br /&gt;
|-&lt;br /&gt;
| [a] a period of inactivity to terminate network connections associated with communications sessions is defined. || Document || SSP, network communications policy.&lt;br /&gt;
|-&lt;br /&gt;
| [b] network connections associated with communications sessions are terminated at the end of the sessions. || Screen Share || VPN appliance/server logs, VPN configurations, web server configurations, firewall connection settings.&lt;br /&gt;
|-&lt;br /&gt;
| [c] network connections associated with communications sessions are terminated after the defined period of inactivity. || Screen Share || VPN appliance/server logs, VPN configurations, web server configurations, frewall connection settings.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.10 – Key Management ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.10_Details|&#039;&#039;&#039;SC.L2-3.13.10&#039;&#039;&#039;]] Establish and manage cryptographic keys for cryptography employed in organizational systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] cryptographic keys are established whenever cryptography is employed. || Artifact || SSP, PKI/certificate management policy, configuration management.&lt;br /&gt;
|-&lt;br /&gt;
| [b] cryptographic keys are managed whenever cryptography is employed. || Artifact || SSP, PKI/certificate management policy, configuration management, access control policy.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.11 – CUI Encryption ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.11_Details|&#039;&#039;&#039;SC.L2-3.13.11&#039;&#039;&#039;]] Employ FIPS-validated cryptography when used to protect the confidentiality of CUI.&lt;br /&gt;
|-&lt;br /&gt;
| [a] FIPS-validated cryptography is employed to protect the confidentiality of CUI. || Screen Share || VPN, wireless, mobile devices, client certificates, server certificates, disk encryption, Outlook plugin, external mail, backup media, ePO server, removable storage, SAN, file compression; look for FIPS mode enabled on appliances.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.12 – Collaborative Device Control ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.12_Details|&#039;&#039;&#039;SC.L2-3.13.12&#039;&#039;&#039;]] Prohibit remote activation of collaborative computing devices and provide indication of devices in use to users present at the device.&lt;br /&gt;
|-&lt;br /&gt;
| [a] collaborative computing devices are identified. || Document || SSP, network diagrams.&lt;br /&gt;
|-&lt;br /&gt;
| [b] collaborative computing devices provide indication to users of devices in use. || Physical Review || Physical inspection of device.&lt;br /&gt;
|-&lt;br /&gt;
| [c] remote activation of collaborative computing devices is prohibited. || Screen Share || Collaboration device configuration/console.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.13 – Mobile Code ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.13_Details|&#039;&#039;&#039;SC.L2-3.13.13&#039;&#039;&#039;]] Control and monitor the use of mobile code.&lt;br /&gt;
|-&lt;br /&gt;
| [a] use of mobile code is controlled. || Screen Share || GPO settings, malware protection, software agent configurations, software development policies, code scanners, MDM configuration, firewall/secure web gateway/proxy config.&lt;br /&gt;
|-&lt;br /&gt;
| [b] use of mobile code is monitored. || Screen Share || SIEM/console monitoring.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.14 – Voice over Internet Protocol ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.14_Details|&#039;&#039;&#039;SC.L2-3.13.14&#039;&#039;&#039;]] Control and monitor the use of Voice over Internet Protocol (VoIP) technologies.&lt;br /&gt;
|-&lt;br /&gt;
| [a] use of Voice over Internet Protocol (VoIP) technologies is controlled. || Artifact || VLAN, ACL, firewall config, VoIP gateway/condenser configuration.&lt;br /&gt;
|-&lt;br /&gt;
| [b] use of Voice over Internet Protocol (VoIP) technologies is monitored. || Artifact || SIEM/VoIP console monitoring, session border controller.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.15 – Communications Authenticity ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.15_Details|&#039;&#039;&#039;SC.L2-3.13.15&#039;&#039;&#039;]] Protect the authenticity of communications sessions.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the authenticity of communications sessions is protected. || Screen Share || SSL, TLS, SMB3, SFTP, IPSec, SSH, Kerberos configs, MPLS, Network Access Control.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.16 – Data at Rest ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.16_Details|&#039;&#039;&#039;SC.L2-3.13.16&#039;&#039;&#039;]] Protect the confidentiality of CUI at rest.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the confidentiality of CUI at rest is protected. || Artifact || Full disk encryption, removable media encryption, SAN encryption, digital backups, mobile device encryption, third party offsite backup storage, cloud virtualization encryption, physical media storage policies.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== System and Information Integrity (SI) ==&lt;br /&gt;
=== SI.L2-3.14.1 – Flaw Remediation [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SI.L2-3.14.1_Details|&#039;&#039;&#039;SI.L2-3.14.1&#039;&#039;&#039;]] Identify, report, and correct information and information system flaws in a timely manner.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the time within which to identify system flaws is specified. || Document || SSP, patch management policy.&lt;br /&gt;
|-&lt;br /&gt;
| [b] system flaws are identified within the specified time frame. || Screen Share || Vulnerability management scanner output and scan policy configuration.&lt;br /&gt;
|-&lt;br /&gt;
| [c] the time within which to report system flaws is specified. || Document || SSP, patch management policy.&lt;br /&gt;
|-&lt;br /&gt;
| [d] system flaws are reported within the specified time frame. || Screen Share || ITSM/trouble tickets, vulnerability management scanner output.&lt;br /&gt;
|-&lt;br /&gt;
| [e] the time within which to correct system flaws is specified. || Document || SSP, patch management policy.&lt;br /&gt;
|-&lt;br /&gt;
| [f] system flaws are corrected within the specified time frame. || Screen Share || Vulnerability management scanner output and scan policy configuration.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SI.L2-3.14.2 – Malicious Code ProTection [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SI.L2-3.14.2_Details|&#039;&#039;&#039;SI.L2-3.14.2&#039;&#039;&#039;]] Provide protection from malicious code at appropriate locations within organizational information systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] designated locations for malicious code protection are identified. || Document || SSP, system protection policy, network diagrams, security architecture documents.&lt;br /&gt;
|-&lt;br /&gt;
| [b] protection from malicious code at designated locations is provided. || Screen Share || Endpoint security settings, email/web proxy gateways, firewall, IPS sensor, MDM configuration, Network Access Control.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SI.L2-3.14.3 – Security Alerts &amp;amp; Advisories ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SI.L2-3.14.3_Details|&#039;&#039;&#039;SI.L2-3.14.3&#039;&#039;&#039;]] Monitor system security alerts and advisories and take action in response.&lt;br /&gt;
|-&lt;br /&gt;
| [a] response actions to system security alerts and advisories are identified. || Document || SSP, vulnerability management policy, Incident Response Plan.&lt;br /&gt;
|-&lt;br /&gt;
| [b] system security alerts and advisories are monitored. || Artifact || Threat intelligence subscriptions, email advisories.&lt;br /&gt;
|-&lt;br /&gt;
| [c] actions in response to system security alerts and advisories are taken. || Artifact || ITSM/trouble tickets, user notifications, updates to firewall/IPS, etc.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SI.L2-3.14.4 – Update Malicious Code Protection [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SI.L2-3.14.4_Details|&#039;&#039;&#039;SI.L2-3.14.4&#039;&#039;&#039;]] Update malicious code protection mechanisms when new releases are available.&lt;br /&gt;
|-&lt;br /&gt;
| [a] malicious code protection mechanisms are updated when new releases are available. || Screen Share || Antivirus console dashboard, firewall AV, Email gateway signatures,proxy, IPS updates.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SI.L2-3.14.5 – System &amp;amp; File Scanning [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SI.L2-3.14.5_Details|&#039;&#039;&#039;SI.L2-3.14.5&#039;&#039;&#039;]] Perform periodic scans of the information system and real-time scans of files from external sources as files are downloaded, opened, or executed.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the frequency for malicious code scans is defined. || Document || SSP, vulnerability management policy.&lt;br /&gt;
|-&lt;br /&gt;
| [b] malicious code scans are performed with the defined frequency. || Screen Share || Consoles for AV (endpoints, servers, and file shares), firewall, email gateway, proxy, IPS, MDM configurations.&lt;br /&gt;
|-&lt;br /&gt;
| [c] real-time malicious code scans of files from external sources as files are downloaded, opened, or executed are performed. || Screen Share || Consoles for AV (endpoints, servers, and file shares), firewall, email gateway, proxy, IPS, MDM configurations.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SI.L2-3.14.6 – Monitor Communications for Attacks ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SI.L2-3.14.6_Details|&#039;&#039;&#039;SI.L2-3.14.6&#039;&#039;&#039;]] Monitor organizational systems, including inbound and outbound communications traffic, to detect attacks and indicators of potential attacks.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the system is monitored to detect attacks and indicators of potential attacks. || Screen Share || Firewall, IPS, endpoint protection, SIEM alerts and reports.&lt;br /&gt;
|-&lt;br /&gt;
| [b] inbound communications traffic is monitored to detect attacks and indicators of potential attacks. || Screen Share || Firewall, IPS, endpoint protection, SIEM alerts and reports.&lt;br /&gt;
|-&lt;br /&gt;
| [c] outbound communications traffic is monitored to detect attacks and indicators of potential attacks. || Screen Share || Firewall, IPS, endpoint protection, SIEM alerts and reports.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SI.L2-3.14.7 – Identify Unauthorized Use ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SI.L2-3.14.7_Details|&#039;&#039;&#039;SI.L2-3.14.7&#039;&#039;&#039;]] Identify unauthorized use of organizational systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] authorized use of the system is defined. || Document || AUP, SSP.&lt;br /&gt;
|-&lt;br /&gt;
| [b] unauthorized use of the system is identified. || Artifact || SIEM logs, endpoint protection console, IPS, Firewall.&lt;br /&gt;
|}&lt;/div&gt;</summary>
		<author><name>David</name></author>
	</entry>
	<entry>
		<id>https://cmmcwiki.org/index.php?title=Evidence_Collection_Approach&amp;diff=1622</id>
		<title>Evidence Collection Approach</title>
		<link rel="alternate" type="text/html" href="https://cmmcwiki.org/index.php?title=Evidence_Collection_Approach&amp;diff=1622"/>
		<updated>2026-07-20T01:42:06Z</updated>

		<summary type="html">&lt;p&gt;David: /* IA.L2-3.5.3 – Multifactor Authentication */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;CMMC assessments and certification require substantial evidence and documentation. The following tables outline general guidelines for collecting evidence to assess control requirements and objectives. While these guidelines provide a structured approach, they are not the only means of conducting an accurate assessment. Assessors should exercise professional judgment and may employ alternative methods appropriate to the specific organizational context and circumstances.&lt;br /&gt;
&lt;br /&gt;
Evidence collection approaches are defined as:&lt;br /&gt;
* &#039;&#039;&#039;Documentation&#039;&#039;&#039;: Tangible materials containing information over which an organization has authority, including all types of written records and their copies.&lt;br /&gt;
* &#039;&#039;&#039;Artifacts&#039;&#039;&#039;: Tangible, reviewable records directly resulting from a practice or process being performed by a system or by personnel executing their role within that practice, control, or process.&lt;br /&gt;
* &#039;&#039;&#039;Physical Review&#039;&#039;&#039;: Direct on-site observation and examination of evidence.&lt;br /&gt;
* &#039;&#039;&#039;Screen Share&#039;&#039;&#039;: Real-time remote observation of a user demonstrating a task or process via shared computer screen, sometimes called &amp;quot;over-the-shoulder&amp;quot; review.&lt;br /&gt;
&lt;br /&gt;
DISCLAIMER: Evidence requirements vary significantly across assessment types. &#039;&#039;&#039;The examples provided are illustrative only and should be tailored to meet the specific adequacy and sufficiency standards of your particular assessment context.&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
For inquiries and reporting errors on this wiki, please [mailto:support@cmmctoolkit.org contact us]. Thank you.&lt;br /&gt;
&lt;br /&gt;
== Access Control (AC) ==&lt;br /&gt;
=== AC.L2-3.1.1 – Authorized Access Control [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.1_Details|&#039;&#039;&#039;AC.L2-3.1.1&#039;&#039;&#039;]] Limit information system access to authorized users, processes acting on behalf of authorized users, or devices (including other information systems).&lt;br /&gt;
|-&lt;br /&gt;
| [a] authorized users are identified. || Document || Document defining account request, approval, provisioning.&lt;br /&gt;
|-&lt;br /&gt;
| [b] processes acting on behalf of authorized users are identified. || Document || Document defining account request, approval, provisioning.&lt;br /&gt;
|-&lt;br /&gt;
| [c] devices (and other systems) authorized to connect to the system are identified. || Document || Document defining account request, approval, provisioning.&lt;br /&gt;
|-&lt;br /&gt;
| [d] system access is limited to authorized users. || Screen Share || Screen share showing login requirements are enforced. Example of an unauthorized user denied (unauthorized username entered at login).&lt;br /&gt;
|-&lt;br /&gt;
| [e] system access is limited to processes acting on behalf of authorized users. || Screen Share || Screenshot showing that service accounts are assigned to authorized users only; no rogue accounts without an authorized user are active.&lt;br /&gt;
|-&lt;br /&gt;
| [f] system access is limited to authorized devices (including other systems). || Screen Share || Screen share showing that all devices running are authorized; no rogue devices on the network.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.2 – Transaction &amp;amp; Function Control [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.2_Details|&#039;&#039;&#039;AC.L2-3.1.2&#039;&#039;&#039;]] Limit information system access to the types of transactions and functions that authorized users are permitted to execute.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the types of transactions and functions that authorized users are permitted to execute are defined. || Document || SSP, AUP, or IAM document that defines what authorized users can execute.&lt;br /&gt;
|-&lt;br /&gt;
| [b] system access is limited to the defined types of transactions and functions for authorized users. || Screen Share || Screenshot of security roles in AD or IAM or other directory-based identity-related services tool that shows transactions are as defined in the SSP or IAM document; privileged and non-privileged accounts need to be defined and identified in the artifact; screenshot of a non-privileged user trying to execute a privileged function.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.3 – Control CUI Flow ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.3_Details|&#039;&#039;&#039;AC.L2-3.1.3&#039;&#039;&#039;]] Control the flow of CUI in accordance with approved authorizations.&lt;br /&gt;
|-&lt;br /&gt;
| [a] information flow control policies are defined. || Document || SSP or other document describing the control of CUI on the network.&lt;br /&gt;
|-&lt;br /&gt;
| [b] methods and enforcement mechanisms for controlling the flow of CUI are defined. || Document || Document that defines the networking devices that are on the CUI network and answers what measures are in place to control the flow. List of firewalls, border and internal layer 3 devices, IDS/IPS, DLP, that process CUI.&lt;br /&gt;
|-&lt;br /&gt;
| [c] designated sources and destinations (e.g., networks, individuals, and devices) for CUI within the system and between interconnected systems are identified. || Artifact || Network diagram, data flow diagram, external system connection diagrams, document describing the policies for CUI on the network; listing of VLANs and subnets where CUI is authorized; document must describe source and authorized destinations.&lt;br /&gt;
|-&lt;br /&gt;
| [d] authorizations for controlling the flow of CUI are defined. || Document || Document that defines how CUI is to be controlled, such as an InfoSec plan, and/or network management plan.&lt;br /&gt;
|-&lt;br /&gt;
| [e] approved authorizations for controlling the flow of CUI are enforced. || Screen Share || Screenshots of firewall rules, ACLs, etc.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.4 – Separation of Duties ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.4_Details|&#039;&#039;&#039;AC.L2-3.1.4&#039;&#039;&#039;]] Separate the duties of individuals to reduce the risk of malevolent activity without collusion.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the duties of individuals requiring separation are defined. || Document || Document, SSP, account management policy, defining separation of duties by person or role.&lt;br /&gt;
|-&lt;br /&gt;
| [b] responsibilities for duties that require separation are assigned to separate individuals. || Screen Share || Screenshot showing that separation of duties is enforced by showing admin accounts are assigned to different people based on role.&lt;br /&gt;
|-&lt;br /&gt;
| [c] access privileges that enable individuals to exercise the duties that require separation are granted to separate individuals. || Screen Share || Screen shot showing an example such as a security manager can not log into a network device and change ACLs, or network admins can not access security logs in the SIEM tool.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.5 – Least Privilege ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.5_Details|&#039;&#039;&#039;AC.L2-3.1.5&#039;&#039;&#039;]] Employ the principle of least privilege, including for specific security functions and privileged accounts.&lt;br /&gt;
|-&lt;br /&gt;
| [a] privileged accounts are identified. || Document || &amp;quot;SSP or policy (documentation) identify what is considered a privileged account.&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| [b] access to privileged accounts is authorized in accordance with the principle of least privilege. || Artifact || An artifact that identifies the least amount of permissions associated with different types of privileged accounts are approved.&lt;br /&gt;
|-&lt;br /&gt;
| [c] security functions are identified. || Document || &amp;quot;SSP or policy (documentation) identifies what is considered a security account.&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| [d] access to security functions is authorized in accordance with the principle of least privilege. || Artifact || Artifact(s) that identify the least amount of permissions associated with different types of security accounts are approved.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.6 – Non-Privileged Account Use ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.6_Details|&#039;&#039;&#039;AC.L2-3.1.6&#039;&#039;&#039;]] Use non-privileged accounts or roles when accessing nonsecurity functions.&lt;br /&gt;
|-&lt;br /&gt;
| [a] nonsecurity functions are identified. || Document || SSP or account management document, AUP, that defines non-security functions.&lt;br /&gt;
|-&lt;br /&gt;
| [b] users are required to use non-privileged accounts or roles when accessing nonsecurity functions. || Screen Share || Screenshot showing that a privileged user tried to use their admin account to access a non-security function, such as a browser or email (whatever is defined in their policy) and was blocked.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.7 – Privileged Functions ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.7_Details|&#039;&#039;&#039;AC.L2-3.1.7&#039;&#039;&#039;]] Prevent non-privileged users from executing privileged functions and capture the execution of such functions in audit logs.&lt;br /&gt;
|-&lt;br /&gt;
| [a] privileged functions are defined. || Document || SSP or policy (documentation) that defines privileged functions.&lt;br /&gt;
|-&lt;br /&gt;
| [b] non-privileged users are defined. || Document || SSP or policy (documentation) that defines non-privileged users.&lt;br /&gt;
|-&lt;br /&gt;
| [c] non-privileged users are prevented from executing privileged functions. || Screen Share || Screen share that shows that a non-privileged user is not allowed to complete a privileged function (installing software).&lt;br /&gt;
|-&lt;br /&gt;
| [d] the execution of privileged functions is captured in audit logs. || Screen Share || Screen share that shows logs being captured of the execution of privileged functions.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.8 – Unsuccessful Logon Attempts ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.8_Details|&#039;&#039;&#039;AC.L2-3.1.8&#039;&#039;&#039;]] Limit unsuccessful logon attempts.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the means of limiting unsuccessful logon attempts is defined. || Document || SSP or policy (documentation) showing unsuccessful logon attempts settings and or policy.&lt;br /&gt;
|-&lt;br /&gt;
| [b] the defined means of limiting unsuccessful logon attempts is implemented. || Artifact || Artifact showing GPO / Policy for limiting logon attempts.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.9 – Privacy &amp;amp; Security Notices ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.9_Details|&#039;&#039;&#039;AC.L2-3.1.9&#039;&#039;&#039;]] Provide privacy and security notices consistent with applicable CUI rules.&lt;br /&gt;
|-&lt;br /&gt;
| [a] privacy and security notices required by CUI-specified rules are identified, consistent, and associated with the specific CUI category. || Document || SSP or policy (documentation) showing CUI-specified rules are identified, consistent, and associated with the specific CUI category.&lt;br /&gt;
|-&lt;br /&gt;
| [b] privacy and security notices are displayed. || Artifact || Artifact that shows a consent banner or screen that a user sees as they log in to the system.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.10 – Session Lock ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.10_Details|&#039;&#039;&#039;AC.L2-3.1.10&#039;&#039;&#039;]] Use session lock with pattern-hiding displays to prevent access and viewing of data after a period of inactivity.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the period of inactivity after which the system initiates a session lock is defined. || Document || SSP or policy (documentation) that defines the period of inactivity and when a session lock is defined.&lt;br /&gt;
|-&lt;br /&gt;
| [b] access to the system and viewing of data is prevented by initiating a session lock after the defined period of inactivity. || Artifact || Artifact that shows the setting of session lock (GPO or system policy or similar solution addressing the controls supporting centralized management and configuration of operating systems, applications, and users&#039; settings for the working environment of user accounts and computer accounts).&lt;br /&gt;
|-&lt;br /&gt;
| [c] previously visible information is concealed via a pattern-hiding display after the defined period of inactivity. || Document || Screenshot of GPO setting and configuration settings, or similar solution addressing the controls supporting centralized management and configuration of operating systems, applications, and users&#039; settings for the working environment of user accounts and computer accounts.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.11 – Session Termination ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.11_Details|&#039;&#039;&#039;AC.L2-3.1.11&#039;&#039;&#039;]] Terminate (automatically) a user session after a defined condition.&lt;br /&gt;
|-&lt;br /&gt;
| [a] conditions requiring a user session to terminate are defined. || Document || SSP or policy (documentation) that defines the conditions requiring a user session to be terminated.&lt;br /&gt;
|-&lt;br /&gt;
| [b] a user session is automatically terminated after any of the defined conditions. || Screen Share || Screen share showing GPO / VPN Settings that show when a session would be terminated (Idle time, max connection time).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.12 – Control Remote Access ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.12_Details|&#039;&#039;&#039;AC.L2-3.1.12&#039;&#039;&#039;]] Monitor and control remote access sessions.&lt;br /&gt;
|-&lt;br /&gt;
| [a] remote access sessions are permitted. || Document || SSP or policy (documentation) that defines remote access sessions.&lt;br /&gt;
|-&lt;br /&gt;
| [b] the types of permitted remote access are identified. || Document || SSP or policy (documentation) that defines remote access is permitted.&lt;br /&gt;
|-&lt;br /&gt;
| [c] remote access sessions are controlled. || Screen Share || Screen share that shows how the remote access is controlled (access session, and or groups).&lt;br /&gt;
|-&lt;br /&gt;
| [d] remote access sessions are monitored. || Screen Share || Screen share that shows how remote sessions are monitored (logs).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.13 – Remote Access Confidentiality ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.13_Details|&#039;&#039;&#039;AC.L2-3.1.13&#039;&#039;&#039;]] Employ cryptographic mechanisms to protect the confidentiality of remote access sessions.&lt;br /&gt;
|-&lt;br /&gt;
| [a] cryptographic mechanisms to protect the confidentiality of remote access sessions are identified. || Document || SSP or policy (documentation) that discusses the CUI rules, consistent, and associated with the specific CUI category; FIPS Cert # of appliance or application.&lt;br /&gt;
|-&lt;br /&gt;
| [b] cryptographic mechanisms to protect the confidentiality of remote access sessions are implemented. || Screen Share || Screenshot of VPN concentration that shows encryption is on and enabled (point-to-point, etc.).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.14 – Remote Access Routing ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.14_Details|&#039;&#039;&#039;AC.L2-3.1.14&#039;&#039;&#039;]] Route remote access via managed access control points.&lt;br /&gt;
|-&lt;br /&gt;
| [a] managed access control points are identified and implemented. || Screen Share || Screen share that shows access control points (groups and/or users).&lt;br /&gt;
|-&lt;br /&gt;
| [b] remote access is routed through managed network access control points. || Screen Share || Screen share that shows access control points and how they are managed.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.15 – Privileged Remote Access ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.15_Details|&#039;&#039;&#039;AC.L2-3.1.15&#039;&#039;&#039;]] Authorize remote execution of privileged commands and remote access to security-relevant information.&lt;br /&gt;
|-&lt;br /&gt;
| [a] privileged commands authorized for remote execution are identified. || Document || SSP or policy (documentation) that defines what is authorized to be executed remotely and how that is handled.&lt;br /&gt;
|-&lt;br /&gt;
| [b] security-relevant information authorized to be accessed remotely is identified. || Document || SSP or policy (documentation) that defines what can be accessed remotely and what procedures are implemented to allow this (RDP, jump box).&lt;br /&gt;
|-&lt;br /&gt;
| [c] the execution of the identified privileged commands via remote access is authorized. || Artifact || Screen share that shows who has access to perform privileged commands a remotely (access groups for privileged accounts).&lt;br /&gt;
|-&lt;br /&gt;
| [d] access to the identified security-relevant information via remote access is authorized. || Artifact || Screen share that shows the routing of remote access and how it is monitored and how many locations (Firewall, VPN Concentrator).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.16 – Wireless Access Authorization ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.16_Details|&#039;&#039;&#039;AC.L2-3.1.16&#039;&#039;&#039;]] Authorize wireless access prior to allowing such connections.&lt;br /&gt;
|-&lt;br /&gt;
| [a] wireless access points are identified. || Document || SSP, network administration document.&lt;br /&gt;
|-&lt;br /&gt;
| [b] wireless access is authorized prior to allowing such connections. || Screen Share || Authorization profile(s) in Wireless Access Controller or Identity Manager (i.e. Cisco ISE).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.17 – Wireless Access Protection ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.17_Details|&#039;&#039;&#039;AC.L2-3.1.17&#039;&#039;&#039;]] Protect wireless access using authentication and encryption.&lt;br /&gt;
|-&lt;br /&gt;
| [a] wireless access to the system is protected using authentication. || Screen Share || Security page (or similar) of a Wireless Access Controller.&lt;br /&gt;
|-&lt;br /&gt;
| [b] wireless access to the system is protected using encryption. || Screen Share || Security page (or similar) of a Wireless Access Controller.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.18 – Mobile Device Connection ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.18_Details|&#039;&#039;&#039;AC.L2-3.1.18&#039;&#039;&#039;]] Control connection of mobile devices.&lt;br /&gt;
|-&lt;br /&gt;
| [a] mobile devices that process, store, or transmit CUI are identified. || Document || SSP, Mobile Device Policy.&lt;br /&gt;
|-&lt;br /&gt;
| [b] mobile device connections are authorized. || Artifact || Authorization profile(s) in Wireless Access Controller or Identity Manager (i.e. Cisco ISE).&lt;br /&gt;
|-&lt;br /&gt;
| [c] mobile device connections are monitored and logged. || Screen Share || Mobile device logs within the MDM, log intake (sources) configuration (within SIEM) showing MDM is feeding logs to the SIEM.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.19 – Encrypt CUI on Mobile ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.19_Details|&#039;&#039;&#039;AC.L2-3.1.19&#039;&#039;&#039;]] Encrypt CUI on mobile devices and mobile computing platforms.&lt;br /&gt;
|-&lt;br /&gt;
| [a] mobile devices and mobile computing platforms that process, store, or transmit CUI are identified. || Document || SSP, Mobile Device Policy.&lt;br /&gt;
|-&lt;br /&gt;
| [b] encryption is employed to protect CUI on identified mobile devices and mobile computing platforms. || Screen Share || Security policy page in MDM showing how encryption are enforced on mobile device. If no MDM or MDM doesn&#039;t enforce encryption, then validate if the devices used are on the list of devices with native FIPS approved validation.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.20 – External Connections [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.20_Details|&#039;&#039;&#039;AC.L2-3.1.20&#039;&#039;&#039;]] Verify and control/limit connections to and use of external information systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] connections to external systems are identified. || Document || SSP, Systems Interconnection Agreements, SLA.&lt;br /&gt;
|-&lt;br /&gt;
| [b] the use of external systems is identified. || Document || SSP, Systems Interconnection Agreements, SLA.&lt;br /&gt;
|-&lt;br /&gt;
| [c] connections to external systems are verified. || Artifact || SLA for external systems, memorandum for interconnection, information to prove that any cloud solution is at FedRAMP impact level of moderate or higher (i.e. license information, screenshot of AWS cloud dashboard, purchase order document).&lt;br /&gt;
|-&lt;br /&gt;
| [d] the use of external systems is verified. || Artifact || SLA for external systems, memorandum for interconnection, information to prove that any cloud solution is at FedRAMP impact level of moderate or higher (i.e. license information, screenshot of AWS cloud dashboard, purchase order document).&lt;br /&gt;
|-&lt;br /&gt;
| [e] connections to external systems are controlled/limited. || Screen Share || Firewall ruleset for controlling access to cloud service or external system.&lt;br /&gt;
|-&lt;br /&gt;
| [f] the use of external systems is controlled/limited. || Screen Share || Firewall ruleset for controlling access to cloud service or external system.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.21 – Portable Storage Use ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.21_Details|&#039;&#039;&#039;AC.L2-3.1.21&#039;&#039;&#039;]] Limit use of portable storage devices on external systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the use of portable storage devices containing CUI on external systems is identified and documented. || Document || SSP, Removable Media Policy, Acceptable Use Policy (with emphasis on portable media use).&lt;br /&gt;
|-&lt;br /&gt;
| [b] limits on the use of portable storage devices containing CUI on external systems are defined. || Document || SSP, Removable Media Policy, Acceptable Use Policy (with emphasis on portable media use).&lt;br /&gt;
|-&lt;br /&gt;
| [c] the use of portable storage devices containing CUI on external systems is limited as defined. || Document || SSP, Removable Media Policy, Acceptable Use Policy (with emphasis on portable media use).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.22 – Control Public Information [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.22_Details|&#039;&#039;&#039;AC.L2-3.1.22&#039;&#039;&#039;]] Control information posted or processed on publicly accessible information systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] individuals authorized to post or process information on publicly accessible systems are identified. || Document || SSP, Website Governance Plan, Information Release Document.&lt;br /&gt;
|-&lt;br /&gt;
| [b] procedures to ensure CUI is not posted or processed on publicly accessible systems are identified. || Document || SSP, Website Governance Plan, Information Release Document.&lt;br /&gt;
|-&lt;br /&gt;
| [c] a review process is in place prior to posting of any content to publicly accessible systems. || Artifact || &amp;quot;Information release approval process, i.e. chain of email communication from originator, approver, and final decision (may or may not include individual authorized to post); &lt;br /&gt;
SharePoint/electronic or paper form/ ticket system showing information flow between requestor and approver (may or may not include  individual authorized to post).&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| [d] content on publicly accessible systems is reviewed to ensure that it does not include CUI. || Artifact || Incident response process, web design/update/modification SOP etc.&lt;br /&gt;
|-&lt;br /&gt;
| [e] mechanisms are in place to remove and address improper posting of CUI. || Artifact || Incident response process, web design/update/modification SOP etc.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Awareness and Training (AT) ==&lt;br /&gt;
=== AT.L2-3.2.1 – Role-Based Risk Awareness ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AT.L2-3.2.1_Details|&#039;&#039;&#039;AT.L2-3.2.1&#039;&#039;&#039;]] Ensure that managers, systems administrators, and users of organizational systems are made aware of the security risks associated with their activities and of the applicable policies, standards, and procedures related to the security of those systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] security risks associated with organizational activities involving CUI are identified. || Document || Policy of Security Awareness Training; Security Awareness Training Briefing.&lt;br /&gt;
|-&lt;br /&gt;
| [b] policies, standards, and procedures related to the security of the system are identified. || Document || Acceptable Use Policy, Policy/Procedures/Instruction related to the security of the system.&lt;br /&gt;
|-&lt;br /&gt;
| [c] managers, systems administrators, and users of the system are made aware of the security risks associated with their activities. || Artifact || Security Training Brief, training records.&lt;br /&gt;
|-&lt;br /&gt;
| [d] managers, systems administrators, and users of the system are made aware of the applicable policies, standards, and procedures related to the security of the system. || Artifact || Policies, standards and procedures for employees within training (completed training report).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AT.L2-3.2.2 – Role-Based Training ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AT.L2-3.2.2_Details|&#039;&#039;&#039;AT.L2-3.2.2&#039;&#039;&#039;]] Ensure that personnel are trained to carry out their assigned information security-related duties and responsibilities.|-&lt;br /&gt;
|-&lt;br /&gt;
| [a] information security-related duties, roles, and responsibilities are defined. || Document || Policy/Procedures/Instruction, Job Role Matrix, Position Descriptions, User Roles.&lt;br /&gt;
|-&lt;br /&gt;
| [b] information security-related duties, roles, and responsibilities are assigned to designated personnel. || Artifact || Screenshot of breakout of different roles/permissions assigned to individuals (i.e. ActiveDirectory); Privilege Access Agreement.&lt;br /&gt;
|-&lt;br /&gt;
| [c] personnel are adequately trained to carry out their assigned information security-related duties, roles, and responsibilities. || Artifact || Screenshot of tool and/or training specifying security specific roles, duties and responsibilities; Screenshot of required certifications (i.e. Sec+, CISSP).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AT.L2-3.2.3 – Insider Threat Awareness ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AT.L2-3.2.3_Details|&#039;&#039;&#039;AT.L2-3.2.3&#039;&#039;&#039;]] Provide security awareness training on recognizing and reporting potential indicators of insider threat.&lt;br /&gt;
|-&lt;br /&gt;
| [a] potential indicators associated with insider threats are identified. || Document || Insidert Threat Policy/Procedures/Instruction; Insider Threat Training/Briefing.&lt;br /&gt;
|-&lt;br /&gt;
| [b] security awareness training on recognizing and reporting potential indicators of insider threat is provided to managers and employees. || Artifact || Screenshot of training records showing completion of Insider Threat training, emails showing completion of Insider Threat training, Screenshot of certificate showing completion with individual&#039;s name.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Audit and Accountability (AU) ==&lt;br /&gt;
=== AU.L2-3.3.1 – System Auditing ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AU.L2-3.3.1_Details|&#039;&#039;&#039;AU.L2-3.3.1&#039;&#039;&#039;]] Create and retain system audit logs and records to the extent needed to enable the monitoring, analysis, investigation, and reporting of unlawful or unauthorized system activity.&lt;br /&gt;
|-&lt;br /&gt;
| [a] audit logs needed (i.e., event types to be logged) to enable the monitoring, analysis, investigation, and reporting of unlawful or unauthorized system activity are specified. || Document || SSP, policy, or auditing and logging process that defines specific types of events to be logged.&lt;br /&gt;
|-&lt;br /&gt;
| [b] the content of audit records needed to support monitoring, analysis, investigation, and reporting of unlawful or unauthorized system activity is defined. || Document || SSP, policy, or auditing and logging process that defines specific content of audit records/files.&lt;br /&gt;
|-&lt;br /&gt;
| [c] audit records are created (generated). || Screen Share || Screen share of tool that shows logs are generated for all systems.&lt;br /&gt;
|-&lt;br /&gt;
| [d] audit records, once created, contain the defined content. || Screen Share || Screen share of tool that shows logs contain defined content as defined in SSP, policy, or procedures.&lt;br /&gt;
|-&lt;br /&gt;
| [e] retention requirements for audit records are defined. || Document || SSP, Polocy, or Auditing and logging process that describes how long records are kept.&lt;br /&gt;
|-&lt;br /&gt;
| [f] audit records are retained as defined. || Screen Share || Screen share of tool that shows records and audit content retained at a minimum as defined.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AU.L2-3.3.2 – User Accountability ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AU.L2-3.3.2_Details|&#039;&#039;&#039;AU.L2-3.3.2&#039;&#039;&#039;]] Ensure that the actions of individual system users can be uniquely traced to those users so they can be held accountable for their actions.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the content of the audit records needed to support the ability to uniquely trace users to their actions is defined. || Document || SSP, policy, or process that defines actions traced back to individuals.&lt;br /&gt;
|-&lt;br /&gt;
| [b] audit records, once created, contain the defined content. || Screen Share || Screen share of tool that shows audit records traced to specific users/roles.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AU.L2-3.3.3 – Event Review ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AU.L2-3.3.3_Details|&#039;&#039;&#039;AU.L2-3.3.3&#039;&#039;&#039;]] Review and update logged events.&lt;br /&gt;
|-&lt;br /&gt;
| [a] a process for determining when to review logged events is defined. || Document || SSP, policy, or documented process that shows frequency of when to review types of logged events.&lt;br /&gt;
|-&lt;br /&gt;
| [b] event types being logged are reviewed in accordance with the defined review process. || Artifact || Evidence through a documented method such as meeting minutes, CAB minutes, etc. of log sources and log events being logged at the defined frequency.&lt;br /&gt;
|-&lt;br /&gt;
| [c] event types being logged are updated based on the review. || Artifact || Evidence of implementation based on the results of the review of logged events/sources through a ticket, meeting minutes, or screen share of the tool that shows changes implemented (finetuning).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AU.L2-3.3.4 – Audit Failure Alerting ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AU.L2-3.3.4_Details|&#039;&#039;&#039;AU.L2-3.3.4&#039;&#039;&#039;]] Alert in the event of an audit logging process failure.&lt;br /&gt;
|-&lt;br /&gt;
| [a] personnel or roles to be alerted in the event of an audit logging process failure are identified. || Document || SSP, policy, or procedure that shows who needs to be notified in case of an audit failure.&lt;br /&gt;
|-&lt;br /&gt;
| [b] types of audit logging process failures for which alert will be generated are defined. || Document || SSP, policy, or procedure that shows what types of failure will generate notifications.&lt;br /&gt;
|-&lt;br /&gt;
| [c] identified personnel or roles are alerted in the event of an audit logging process failure. || Artifact || Artifact such as email or ticket that shows the identified personnel were alerted of any audit/logging process failure as defined.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AU.L2-3.3.5 – Audit Correlation ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AU.L2-3.3.5_Details|&#039;&#039;&#039;AU.L2-3.3.5&#039;&#039;&#039;]] Correlate audit record review, analysis, and reporting processes for investigation and response to indications of unlawful, unauthorized, suspicious, or unusual activity.&lt;br /&gt;
|-&lt;br /&gt;
| [a] audit record review, analysis, and reporting processes for investigation and response to indications of unlawful, unauthorized, suspicious, or unusual activity are defined. || Document || SSP, policy, or procedure covering audit logging, monitoring, and reporting.&lt;br /&gt;
|-&lt;br /&gt;
| [b] defined audit record review, analysis, and reporting processes are correlated. || Artifact || Artifact showing an audit event and the resultant corrective action or actions to the event; this can be a Help Desk ticket, meeting notes, or a change control board items showing the event and any corrective action taken.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AU.L2-3.3.6 – Reduction &amp;amp; Reporting ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AU.L2-3.3.6_Details|&#039;&#039;&#039;AU.L2-3.3.6&#039;&#039;&#039;]] Provide audit record reduction and report generation to support on-demand analysis and reporting.&lt;br /&gt;
|-&lt;br /&gt;
| [a] an audit record reduction capability that supports on-demand analysis is provided. || Screen Share || Screen share of the logging environment where an event can be selected and traced back to a specific device, or dashboard showing realtime event analysis.&lt;br /&gt;
|-&lt;br /&gt;
| [b] a report generation capability that supports on-demand reporting is provided. || Screen Share || Screen share showing the generation of an on demand report.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AU.L2-3.3.7 – Authoritative Time Source ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AU.L2-3.3.7_Details|&#039;&#039;&#039;AU.L2-3.3.7&#039;&#039;&#039;]] Provide a system capability that compares and synchronizes internal system clocks with an authoritative source to generate time stamps for audit records.&lt;br /&gt;
|-&lt;br /&gt;
| [a] internal system clocks are used to generate time stamps for audit records. || Screen Share || Screen share showing the NTP settings of a windows, Unix, Linux device; a screen share showing the NTP settings of network appliances.&lt;br /&gt;
|-&lt;br /&gt;
| [b] an authoritative source with which to compare and synchronize internal system clocks is specified. || Document || SSP or policy indicating that devices need to be synched to a local authoritative time device that is synched with an authoritative time service.&lt;br /&gt;
|-&lt;br /&gt;
| [c] internal system clocks used to generate time stamps for audit records are compared to and synchronized with the specified authoritative time source. || Screen Share || Screen share showing device logging appliance time is point to the appropriate authoritative time server.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AU.L2-3.3.8 – Audit Protection ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AU.L2-3.3.8_Details|&#039;&#039;&#039;AU.L2-3.3.8&#039;&#039;&#039;]] Protect audit information and audit logging tools from unauthorized access, modification, and deletion.&lt;br /&gt;
|-&lt;br /&gt;
| [a] audit information is protected from unauthorized access. || Screen Share || Screen share showing operating system permissions on the audit folders being restricted to appropriate users.&lt;br /&gt;
|-&lt;br /&gt;
| [b] audit information is protected from unauthorized modification. || Screen Share || Screen share showing operating system permissions on the audit folders being restricted to appropriate users.&lt;br /&gt;
|-&lt;br /&gt;
| [c] audit information is protected from unauthorized deletion. || Screen Share || Screen share showing operating system permissions on the audit folders being restricted to appropriate users.&lt;br /&gt;
|-&lt;br /&gt;
| [d] audit logging tools are protected from unauthorized access. || Screen Share || Artifact showing access permissions in the SIEM tool.&lt;br /&gt;
|-&lt;br /&gt;
| [e] audit logging tools are protected from unauthorized modification. || Screen Share || Artifact showing update permissions in the SIEM tool.&lt;br /&gt;
|-&lt;br /&gt;
| [f] audit logging tools are protected from unauthorized deletion. || Screen Share || Artifact showing delete permissions in the SIEM tool.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AU.L2-3.3.9 – Audit Management ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AU.L2-3.3.9_Details|&#039;&#039;&#039;AU.L2-3.3.9&#039;&#039;&#039;]] Limit management of audit logging functionality to a subset of privileged users.&lt;br /&gt;
|-&lt;br /&gt;
| [a] a subset of privileged users granted access to manage audit logging functionality is defined. || Document || SSP or policy indicating which users or groups have access to audit logs.&lt;br /&gt;
|-&lt;br /&gt;
| [b] management of audit logging functionality is limited to the defined subset of privileged users. || Screen Share || Artifact showing SIEM or OS folder permissions (this should be limited to the assigned users or groups); artifact showing an ACL setting in SIEM tool in regards to logs.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Configuration Management (CM) ==&lt;br /&gt;
=== CM.L2-3.4.1 – System Baselining ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_CM.L2-3.4.1_Details|&#039;&#039;&#039;CM.L2-3.4.1&#039;&#039;&#039;]] Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles.&lt;br /&gt;
|-&lt;br /&gt;
| [a] a baseline configuration is established. || Document || Documentation showing or explaining standard imaging process (how standard images are deployed and where  they are stored).&lt;br /&gt;
|-&lt;br /&gt;
| [b] the baseline configuration includes hardware, software, firmware, and documentation. || Artifact || Screenshot of repository of where images are maintained and information relating to hardware, software, and firmware.&lt;br /&gt;
|-&lt;br /&gt;
| [c] the baseline configuration is maintained (reviewed and updated) throughout the system development life cycle. || Artifact || Screenshot/evidence displaying management of baseline configurations (how often they are being managed as stated).&lt;br /&gt;
|-&lt;br /&gt;
| [d] a system inventory is established. || Document || Screenshot/evidence displaying inventory listing of approved products for use.&lt;br /&gt;
|-&lt;br /&gt;
| [e] the system inventory includes hardware, software, firmware, and documentation. || Artifact || Screeenshot/evidence displaying inventory listing of approved products and versions permitted for use.&lt;br /&gt;
|-&lt;br /&gt;
| [f] the inventory is maintained (reviewed and updated) throughout the system development life cycle. || Artifact || Screeenshot/evidence displaying management of baseline configurations (How often and are they being managed as stated.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== CM.L2-3.4.2 – Security Configuration Enforcement ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_CM.L2-3.4.2_Details|&#039;&#039;&#039;CM.L2-3.4.2&#039;&#039;&#039;]] Establish and enforce security configuration settings for information technology products employed in organizational systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] security configuration settings for information technology products employed in the system are established and included in the baseline configuration. || Document || Documentation explaining methodology used by organization to create secure baselines (STIGs, benchmarks).&lt;br /&gt;
|-&lt;br /&gt;
| [b] security configuration settings for information technology products employed in the system are enforced. || Artifact || Evidence of tool/s used to enforce security configurations to ensure images used are free from modification unless authorized.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== CM.L2-3.4.3 – System Change Management ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_CM.L2-3.4.3_Details|&#039;&#039;&#039;CM.L2-3.4.3&#039;&#039;&#039;]] Track, review, approve or disapprove, and log changes to organizational systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] changes to the system are tracked. || Artifact || Evidence of IT Service Management tool / process used to track system changes.&lt;br /&gt;
|-&lt;br /&gt;
| [b] changes to the system are reviewed. || Artifact || Evidence of IT Service Management tool / process used to review system changes.&lt;br /&gt;
|-&lt;br /&gt;
| [c] changes to the system are approved or disapproved. || Artifact || Evidence of IT Service Management tool / process used to approve/disapprove system changes.&lt;br /&gt;
|-&lt;br /&gt;
| [d] changes to the system are logged. || Artifact || Evidence of IT Service Management tool / process used to log system changes.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== CM.L2-3.4.4 – Security Impact Analysis ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_CM.L2-3.4.4_Details|&#039;&#039;&#039;CM.L2-3.4.4&#039;&#039;&#039;]] Analyze the security impact of changes prior to implementation.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the security impact of changes to the system is analyzed prior to implementation. || Artifact || Document explaining that security impact analysis of proposed changes to a system is conducted prior to implementation.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== CM.L2-3.4.5 – Access Restrictions for Change ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_CM.L2-3.4.5_Details|&#039;&#039;&#039;CM.L2-3.4.5&#039;&#039;&#039;]] Define, document, approve, and enforce physical and logical access restrictions associated with changes to organizational systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] physical access restrictions associated with changes to the system are defined. || Document || Document explaining the process of how physical access restrictions are defined for an individuals ability to make system changes.&lt;br /&gt;
|-&lt;br /&gt;
| [b] physical access restrictions associated with changes to the system are documented. || Document || Document explaining the process of how physical access restrictions are defined for an individuals ability to make system changes are documented; access request process.&lt;br /&gt;
|-&lt;br /&gt;
| [c] physical access restrictions associated with changes to the system are approved. || Artifact || Evidence of process of how physical access to systems are granted (i.e. physical access request sample).&lt;br /&gt;
|-&lt;br /&gt;
| [d] physical access restrictions associated with changes to the system are enforced. || Physical Review || Evidence of process of how physical access to systems are enforced (physical access system).&lt;br /&gt;
|-&lt;br /&gt;
| [e] logical access restrictions associated with changes to the system are defined. || Document || Document explaining the process of how logical access restrictions are defined for an individual&#039;s ability to make system changes.&lt;br /&gt;
|-&lt;br /&gt;
| [f] logical access restrictions associated with changes to the system are documented. || Document || Document explaining the process of how logical access restrictions are defined for an individual&#039;s ability to make system changes are documented.&lt;br /&gt;
|-&lt;br /&gt;
| [g] logical access restrictions associated with changes to the system are approved. || Artifact || Evidence of process of how logical access to systems are granted.&lt;br /&gt;
|-&lt;br /&gt;
| [h] logical access restrictions associated with changes to the system are enforced. || Artifact || Evidence of process of how logical access to systems are enforced.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== CM.L2-3.4.6 – Least Functionality ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_CM.L2-3.4.6_Details|&#039;&#039;&#039;CM.L2-3.4.6&#039;&#039;&#039;]] Employ the principle of least functionality by configuring organizational systems to provide only essential capabilities.&lt;br /&gt;
|-&lt;br /&gt;
| [a] essential system capabilities are defined based on the principle of least functionality. || Document || Documentation explaining how systems are configured to utilize the principle of least functionality for designated users.&lt;br /&gt;
|-&lt;br /&gt;
| [b] the system is configured to provide only the defined essential capabilities. || Screen Share || Evidence displaying how systems are configured to utilize the principle of least functionality for designated users; disabled service settings, accepted standards for hardening (CIS benchmarks, etc.).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== CM.L2-3.4.7 – Nonessential Functionality ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_CM.L2-3.4.7_Details|&#039;&#039;&#039;CM.L2-3.4.7&#039;&#039;&#039;]] Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services.&lt;br /&gt;
|-&lt;br /&gt;
| [a] essential programs are defined. || Document || Documented essential programs specified; build documents; software center; SSP.&lt;br /&gt;
|-&lt;br /&gt;
| [b] the use of nonessential programs is defined. || Document || Documented listing of nonessential programs (whatever is NOT specified in [a]); AUP/User Agreement may identify nonessential use/programs.&lt;br /&gt;
|-&lt;br /&gt;
| [c] the use of nonessential programs is restricted, disabled, or prevented as defined. || Screen Share || Tool used to restrict nonessential programs displays restrictions as defined (McAfee ePO settings, Carbon Black rules, etc.).&lt;br /&gt;
|-&lt;br /&gt;
| [d] essential functions are defined. || Document || Documented essential functions are specified.&lt;br /&gt;
|-&lt;br /&gt;
| [e] the use of nonessential functions is defined. || Document || Documented nonessential functions are specified.&lt;br /&gt;
|-&lt;br /&gt;
| [f] the use of nonessential functions is restricted, disabled, or prevented as defined. || Screen Share || Tool used to restrict essential/nonessential functions displays restrictions as defined.&lt;br /&gt;
|-&lt;br /&gt;
| [g] essential ports are defined. || Document || Documented essential ports are specified.&lt;br /&gt;
|-&lt;br /&gt;
| [h] the use of nonessential ports is defined. || Document || Documented nonessential ports functions are specified.&lt;br /&gt;
|-&lt;br /&gt;
| [i] the use of nonessential ports is restricted, disabled, or prevented as defined. || Screen Share || Tool used to restrict essential/nonessential ports displays restrictions as defined (FW rules; McAfee; GPO, etc.).&lt;br /&gt;
|-&lt;br /&gt;
| [j] essential protocols are defined. || Document || Documented essential protocols are specified.&lt;br /&gt;
|-&lt;br /&gt;
| [k] the use of nonessential protocols is defined. || Document || Documented nonessential protocols functions are specified.&lt;br /&gt;
|-&lt;br /&gt;
| [l] the use of nonessential protocols is restricted, disabled, or prevented as defined. || Screen Share || Tool used to restrict essential/nonessential protocols displays restrictions as defined (FW rules; GPO, etc.).&lt;br /&gt;
|-&lt;br /&gt;
| [m] essential services are defined. || Document || Documented essential services specified.&lt;br /&gt;
|-&lt;br /&gt;
| [n] the use of nonessential services is defined. || Document || Documented nonessential services functions are specified.&lt;br /&gt;
|-&lt;br /&gt;
| [o] the use of nonessential services is restricted, disabled, or prevented as defined. || Screen Share || Tool used to restrict essential/nonessential services displays restrictions as defined.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== CM.L2-3.4.8 – Application Execution Policy ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_CM.L2-3.4.8_Details|&#039;&#039;&#039;CM.L2-3.4.8&#039;&#039;&#039;]] Apply deny-by-exception (blacklisting) policy to prevent the use of unauthorized software or deny-all, permit-by-exception (whitelisting) policy to allow the execution of authorized software.&lt;br /&gt;
|-&lt;br /&gt;
| [a] a policy specifying whether whitelisting or blacklisting is to be implemented is specified. || Document || Documentation explaining whitelisting or blacklisting process.&lt;br /&gt;
|-&lt;br /&gt;
| [b] the software allowed to execute under whitelisting or denied use under blacklisting is specified. || Document || Documentation explaining whitelisting or blacklisting process for software.&lt;br /&gt;
|-&lt;br /&gt;
| [c] whitelisting to allow the execution of authorized software or blacklisting to prevent the use of unauthorized software is implemented as specified. || Screen Share || Tool used for whitelisting or blacklisting for software shows capability of restricting/authorizing software (Carbon Black dashboard, &amp;quot;SW Store&amp;quot;, web proxies, DNS Blackhole, etc.).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== CM.L2-3.4.9 – User-Installed Software ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_CM.L2-3.4.9_Details|&#039;&#039;&#039;CM.L2-3.4.9&#039;&#039;&#039;]] Control and monitor user-installed software.&lt;br /&gt;
|-&lt;br /&gt;
| [a] a policy for controlling the installation of software by users is established. || Document || Documented software authorization process or methodology for approval.&lt;br /&gt;
|-&lt;br /&gt;
| [b] installation of software by users is controlled based on the established policy. || Screen Share || Evidence that approval/restriction in installation of software by authorized personnel is implemented as specified (AUP, GPO, etc.).&lt;br /&gt;
|-&lt;br /&gt;
| [c] installation of software by users is monitored. || Screen Share || Evidence that installation of software by authorized personnel is monitored (SCCM groups, SW Center, etc.).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Identification and Authentication (IA) ==&lt;br /&gt;
=== IA.L2-3.5.1 – Identification [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IA.L2-3.5.1_Details|&#039;&#039;&#039;IA.L2-3.5.1&#039;&#039;&#039;]] Identify information system users, processes acting on behalf of users, or devices.&lt;br /&gt;
|-&lt;br /&gt;
| [a] system users are identified. || Document || Based on what is defined in their documentation (SSP, AUP, Policy, SOP), request to see a sample of non-privileged/privileged users in AD OU group (overlaps with 3.1.1 and 3.1.5).&lt;br /&gt;
|-&lt;br /&gt;
| [b] processes acting on behalf of users are identified. || Document || Based on what is defined in their documentation (SSP, AUP, Policy, SOP), request to see a sample of service accounts in AD OU group (overlaps with 3.1.1 and 3.1.5).&lt;br /&gt;
|-&lt;br /&gt;
| [c] devices accessing the system are identified. || Document || Based on what is defined in their documentation (SSP, AUP, Policy, SOP), request to see a sample of domain-joined workstation &amp;amp; servers in AD OU group (overlaps with 3.1.1 and 3.1.5).  For network devices, request screen share/artifact to show how they are identified on the enterprise network.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IA.L2-3.5.2 – Authentication [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IA.L2-3.5.2_Details|&#039;&#039;&#039;IA.L2-3.5.2&#039;&#039;&#039;]] Authenticate (or verify) the identities of those users, processes, or devices, as a prerequisite to allowing access to organizational information systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the identity of each user is authenticated or verified as a prerequisite to system access. || Screen Share || If the user logs in with non-privileged account during other demoes and then a privileged account, then this should be satisfied.  If screen share is unavailable, request logs to show successful and unsuccessful login by privileged and non-privilged users.&lt;br /&gt;
|-&lt;br /&gt;
| [b] the identity of each process acting on behalf of a user is authenticated or verified as a prerequisite to system access. || Screen Share || Request a log that shows successful/unsuccessful service account trying to log on to company&#039;s asset.&lt;br /&gt;
|-&lt;br /&gt;
| [c] the identity of each device accessing or connecting to the system is authenticated or verified as a prerequisite to system access. || Screen Share || Request a log that shows domain-joined workstation/server authenticating to AD (focus on the MAC/IP address/hostname).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IA.L2-3.5.3 – Multifactor Authentication ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IA.L2-3.5.3_Details|&#039;&#039;&#039;IA.L2-3.5.3&#039;&#039;&#039;]] Use multifactor authentication for local and network access to privileged accounts and for network access to non-privileged accounts.&lt;br /&gt;
|-&lt;br /&gt;
| [a] privileged accounts are identified. || Document || Based on what is defined in their documentation, request to see a sample of privileged users in AD OU group.  Overlaps with 3.1.5.  Screenshot/screen share to show implementation is enforced.&lt;br /&gt;
|-&lt;br /&gt;
| [b] multifactor authentication is implemented for local access to privileged accounts. || Screen Share || SSP, AUP, Policy, SOP that defines that MFA is needed for privileged local access.&lt;br /&gt;
|-&lt;br /&gt;
| [c] multifactor authentication is implemented for network access to privileged accounts. || Screen Share || Within the MFA implementation mechanism, show that privileged users are forced to use MFA;  Screenshot/Screen share to show implementation is enforced.&lt;br /&gt;
|-&lt;br /&gt;
| [d] multifactor authentication is implemented for network access to non-privileged accounts. || Screen Share || Within the MFA implementation mechanism, show that non-privileged users are forced to use MFA; Screenshot/Screen share to show implementation is enforced.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IA.L2-3.5.4 – Replay-Resistant Authentication ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IA.L2-3.5.4_Details|&#039;&#039;&#039;IA.L2-3.5.4&#039;&#039;&#039;]] Employ replay-resistant authentication mechanisms for network access to privileged and non-privileged accounts.&lt;br /&gt;
|-&lt;br /&gt;
| [a] replay-resistant authentication mechanisms are implemented for network account access to privileged and non-privileged accounts. || Screen Share || Show the GPO setting that enforces Kerberos within AD.  If MFA is used, show the implementation to enforce replay resistant techniques.  For non-windows, show the technical solution to enforce replay resistant attacks.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IA.L2-3.5.5 – Identifier Reuse ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IA.L2-3.5.5_Details|&#039;&#039;&#039;IA.L2-3.5.5&#039;&#039;&#039;]] Prevent reuse of identifiers for a defined period.&lt;br /&gt;
|-&lt;br /&gt;
| [a] a period within which identifiers cannot be reused is defined. || Document || SSP, policies, or SOP that defines identifier reuse.&lt;br /&gt;
|-&lt;br /&gt;
| [b] reuse of identifiers is prevented within the defined period. || Screen Share || Show the GPO setting/technical solution that enforces what is defined in policy/documentation (this can be automated or manual process; screen share/artifacts can be presented to satisfy this requirement.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IA.L2-3.5.6 – Identifier Handling ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IA.L2-3.5.6_Details|&#039;&#039;&#039;IA.L2-3.5.6&#039;&#039;&#039;]] Disable identifiers after a defined period of inactivity.&lt;br /&gt;
|-&lt;br /&gt;
| [a] a period of inactivity after which an identifier is disabled is defined. || Document || SSP, policy that defines the period of inactivity after which an identifier is disabled.&lt;br /&gt;
|-&lt;br /&gt;
| [b] identifiers are disabled after the defined period of inactivity. || Screen Share || Screen share AD or similar tool supporting directory-based identity-related services for disabled accounts (can be done by hand or script).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IA.L2-3.5.7 – Password Complexity ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IA.L2-3.5.7_Details|&#039;&#039;&#039;IA.L2-3.5.7&#039;&#039;&#039;]] Enforce a minimum password complexity and change of characters when new passwords are created.&lt;br /&gt;
|-&lt;br /&gt;
| [a] password complexity requirements are defined. || Document || SSP, policy that defines password complexity requirements.&lt;br /&gt;
|-&lt;br /&gt;
| [b] password change of character requirements are defined. || Document || SSP, policy that defines change of character requirements are defined.&lt;br /&gt;
|-&lt;br /&gt;
| [c] minimum password complexity requirements as defined are enforced when new passwords are created. || Screen Share || Screen share of AD or similar directory-based identity-related service tool to show complexity requirements.&lt;br /&gt;
|-&lt;br /&gt;
| [d] minimum password change of character requirements as defined are enforced when new passwords are created. || Screen Share || Screen share of Group Policy configuration or similar tool providing centralized management and configuration of operating systems, applications, and users&#039; settings to show that characters must be changed.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IA.L2-3.5.8 – Password Reuse ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IA.L2-3.5.8_Details|&#039;&#039;&#039;IA.L2-3.5.8&#039;&#039;&#039;]] Prohibit password reuse for a specified number of generations.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the number of generations during which a password cannot be reused is specified. || Document || SSP, policy that specifies the number of generations during which a password cannot be reused is specified.&lt;br /&gt;
|-&lt;br /&gt;
| [b] reuse of passwords is prohibited during the specified number of generations. || Screen Share || Screen share Group Policy or similar tool providing centralized management and configuration of operating systems, applications, and users&#039; settings in a directory-based identity-related service tool&#039;s configuration to show reuse of passwords is prohibited.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IA.L2-3.5.9 – Temporary Passwords ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IA.L2-3.5.9_Details|&#039;&#039;&#039;IA.L2-3.5.9&#039;&#039;&#039;]] Allow temporary password use for system logons with an immediate change to a permanent password.&lt;br /&gt;
|-&lt;br /&gt;
| [a] an immediate change to a permanent password is required when a temporary password is used for system logon. || Screen Share || Screen share of Group Policy or similar tool providing centralized management and configuration of operating systems, applications, and users&#039; settings in a directory-based identity-related service tool&#039;s configuration to show &amp;quot;change password at first logon.&amp;quot;&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IA.L2-3.5.10 – Cryptographically-Protected Passwords ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IA.L2-3.5.1_Details|&#039;&#039;&#039;IA.L2-3.5.1&#039;&#039;&#039;]] Store and transmit only cryptographically-protected passwords.&lt;br /&gt;
|-&lt;br /&gt;
| [a] passwords are cryptographically protected in storage. || Screen Share || Screen share Group Policy or similar tool providing centralized management and configuration of operating systems, applications, and users&#039; settings in a directory-based identity-related service tool&#039;s configuration that Kerberos, or a similar network authentication protocol that works on the basis of tickets to allow nodes communicating over a non-secure network to prove their identity to one another in a secure manner, is enabled.&lt;br /&gt;
|-&lt;br /&gt;
| [b] passwords are cryptographically protected in transit. || Screen Share || Screen share Group Policy or similar tool providing centralized management and configuration of operating systems, applications, and users&#039; settings in a directory-based identity-related service tool&#039;s configuration that Kerberos, or a similar network authentication protocol that works on the basis of tickets to allow nodes communicating over a non-secure network to prove their identity to one another in a secure manner, is enabled.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IA.L2-3.5.11 – Obscure Feedback ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IA.L2-3.5.10_Details|&#039;&#039;&#039;IA.L2-3.5.10&#039;&#039;&#039;]] Obscure feedback of authentication information.&lt;br /&gt;
|-&lt;br /&gt;
| [a] authentication information is obscured during the authentication process. || Screen Share || Screen share of Group Policy or similar tool providing centralized management and configuration of operating systems, applications, and users&#039; settings in a directory-based identity-related service tool&#039;s configuration to show that passwords are obscured.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Incident Response (IR) ==&lt;br /&gt;
=== IR.L2-3.6.1 – Incident Handling ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IR.L2-3.6.1_Details|&#039;&#039;&#039;IR.L2-3.6.1&#039;&#039;&#039;]] Establish an operational incident-handling capability for organizational systems that includes preparation, detection, analysis, containment, recovery, and user response activities.&lt;br /&gt;
|-&lt;br /&gt;
| [a] an operational incident-handling capability is established. || Document || Incident Response SOP/Plan.&lt;br /&gt;
|-&lt;br /&gt;
| [b] the operational incident-handling capability includes preparation. || Document || Incident Response SOP/Plan, prior incident report, training, COOP plan.&lt;br /&gt;
|-&lt;br /&gt;
| [c] the operational incident-handling capability includes detection. || Document || Incident Response SOP/Plan; definition of tools used to detect; artifacts showing tools used; prior incident report.&lt;br /&gt;
|-&lt;br /&gt;
| [d] the operational incident-handling capability includes analysis. || Document || Incident Response SOP/Plan; Definition of tools used to analyze potential incidents; artifacts showing tools used for analysis; prior incident report.&lt;br /&gt;
|-&lt;br /&gt;
| [e] the operational incident-handling capability includes containment. || Document || Incident Response SOP/Plan; isolation/quarantine process; user training.&lt;br /&gt;
|-&lt;br /&gt;
| [f] the operational incident-handling capability includes recovery. || Document || Incident Response SOP/Plan; COOP Plan; prior incident reports, re-baselining impacted devices.&lt;br /&gt;
|-&lt;br /&gt;
| [g] the operational incident-handling capability includes user response. || Document || Incident Response SOP/Plan; user awareness training; Help Desk process.&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IR.L2-3.6.2 – Incident Reporting ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IR.L2-3.6.2_Details|&#039;&#039;&#039;IR.L2-3.6.2&#039;&#039;&#039;]] Track, document, and report incidents to designated officials and/or authorities both internal and external to the organization.&lt;br /&gt;
|-&lt;br /&gt;
| [a] incidents are tracked. || Artifact || Incident Response SOP/Plan; ITSM artifact; technical implementation for incident tracking.&lt;br /&gt;
|-&lt;br /&gt;
| [b] incidents are documented. || Artifact || Incident Response SOP/Plan; ITSM artifact; technical implementation for incident tracking.&lt;br /&gt;
|-&lt;br /&gt;
| [c] authorities to whom incidents are to be reported are identified. || Document || Incident Response SOP/Plan.&lt;br /&gt;
|-&lt;br /&gt;
| [d] organizational officials to whom incidents are to be reported are identified. || Document || Incident Response SOP/Plan.&lt;br /&gt;
|-&lt;br /&gt;
| [e] identified authorities are notified of incidents. || Screen Share || Prior incident report; DIBNET login; prior email notifications.&lt;br /&gt;
|-&lt;br /&gt;
| [f] identified organizational officials are notified of incidents. || Artifact || Prior incident report; prior email notifications; tabletop exercises.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IR.L2-3.6.3 – Incident Response Testing ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IR.L2-3.6.3_Details|&#039;&#039;&#039;IR.L2-3.6.3&#039;&#039;&#039;]] Test the organizational incident response capability.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the incident response capability is tested. || Artifact || Incident response table top/scheduled or unscheduled test or penetration test.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Maintenance (MA) ==&lt;br /&gt;
=== MA.L2-3.7.1 – Perform Maintenance ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MA.L2-3.7.1_Details|&#039;&#039;&#039;MA.L2-3.7.1&#039;&#039;&#039;]] Perform maintenance on organizational systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] system maintenance is performed. || Artifact || Establish typical maintenance activities (HVAC, UPS, power distribution, generators, copier maintenance) that are performed; maintenance agreements or contracts detailing these types of activities are acceptable; interview responses should be considered.  This requirement should not be confused with 3.14.1 - report, remediate, and correct system flaws in a timely manner (patch management).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MA.L2-3.7.2 – System Maintenance Control ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MA.L2-3.7.2_Details|&#039;&#039;&#039;MA.L2-3.7.2&#039;&#039;&#039;]] Provide controls on the tools, techniques, mechanisms, and personnel used to conduct system maintenance.&lt;br /&gt;
|-&lt;br /&gt;
| [a] tools used to conduct system maintenance are controlled. || Artifact || Tools may largely depend on the assessed environment; discussion examples include network diagnostic and monitoring tools (including hardware and software); artifacts could demonstrate secured locations/areas for these tools (photos) or checkout sheets/rosters (documents) depicting responsible personnel and the dates/times of checkout.&lt;br /&gt;
|-&lt;br /&gt;
| [b] techniques used to conduct system maintenance are controlled. || Artifact || Processes for scheduling, performing, documenting, reviewing, approving, and monitoring maintenance and repairs for the information system.&lt;br /&gt;
|-&lt;br /&gt;
| [c] mechanisms used to conduct system maintenance are controlled. || Artifact || Processes for scheduling, performing, documenting, reviewing, approving, and monitoring maintenance and repairs for the information system.&lt;br /&gt;
|-&lt;br /&gt;
| [d] personnel used to conduct system maintenance are controlled. || Physical Review || Screenshot of who is authorized to conduct maintenance; maintenance personnel training program.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MA.L2-3.7.3 – Equipment Sanitization ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MA.L2-3.7.3_Details|&#039;&#039;&#039;MA.L2-3.7.3&#039;&#039;&#039;]] Ensure equipment removed for off-site maintenance is sanitized of any CUI.&lt;br /&gt;
|-&lt;br /&gt;
| [a] equipment to be removed from organizational spaces for off-site maintenance is sanitized of any CUI. || Artifact || Document or artifact; record if equipment sanitized; categories of sanitization/destruction defined; sanitization procedural document.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MA.L2-3.7.4 – Media Inspection ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MA.L2-3.7.4_Details|&#039;&#039;&#039;MA.L2-3.7.4&#039;&#039;&#039;]] Check media containing diagnostic and test programs for malicious code before the media are used in organizational systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] media containing diagnostic and test programs are checked for malicious code before being used in organizational systems that process, store, or transmit CUI. || Artifact || Screenshot of diagnostic/test program being used (such as Symantec and McAfee on access scans…).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MA.L2-3.7.5 – Nonlocal Maintenance ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MA.L2-3.7.5_Details|&#039;&#039;&#039;MA.L2-3.7.5&#039;&#039;&#039;]] Require multifactor authentication to establish nonlocal maintenance sessions via external network connections and terminate such connections when nonlocal maintenance is complete.&lt;br /&gt;
|-&lt;br /&gt;
| [a] multifactor authentication is used to establish nonlocal maintenance sessions via external network connections. || Screen Share || Describe MFA used to remote from external service to organizational systems for maintenance and screenshot of MFA (3.5.3)(points associated with admin).&lt;br /&gt;
|-&lt;br /&gt;
| [b] nonlocal maintenance sessions established via external network connections are terminated when nonlocal maintenance is complete. || Screen Share || Screenshot VPN session timeout.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MA.L2-3.7.6 – Maintenance Personnel ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MA.L2-3.7.6_Details|&#039;&#039;&#039;MA.L2-3.7.6&#039;&#039;&#039;]] Supervise the maintenance activities of maintenance personnel without required access authorization.&lt;br /&gt;
|-&lt;br /&gt;
| [a] maintenance personnel without required access authorization are supervised during maintenance activities. || Document || System maintenance policy; list of authorized personnel; maintenance records or, contracts/SLAs; WebEx.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Media Protection (MP) ==&lt;br /&gt;
=== MP.L2-3.8.1 – Media Protection ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MP.L2-3.8.1_Details|&#039;&#039;&#039;MP.L2-3.8.1&#039;&#039;&#039;]] Protect (i.e., physically control and securely store) system media containing CUI, both paper and digital.&lt;br /&gt;
|-&lt;br /&gt;
| [a] paper media containing CUI is physically controlled. || Document || Policy showing CUI paper media is controlled; artifact showing who has access; artifacts/records of  inventories conducted; media check out procedures (i.e. file cabinets, encryption, password protection).&lt;br /&gt;
|-&lt;br /&gt;
| [b] digital media containing CUI is physically controlled. || Document || Policy showing CUI digital media is controlled; artifact showing who has access; artifacts/records of inventories conducted; media check out procedures (i.e. file cabinets, external drives, USBs, encryption, password protection).&lt;br /&gt;
|-&lt;br /&gt;
| [c] paper media containing CUI is securely stored. || Physical Review || Check out/sign out sheets; possible photo of storage container/video walk through of storage area; badge reader logs or access lists for keys for secured areas; interview response considered (i.e. file cabinets,  encryption, password protection).&lt;br /&gt;
|-&lt;br /&gt;
| [d] digital media containing CUI is securely stored. || Physical Review || Check out/sign out sheets; possible photo of storage container/video walk through of storage area; badge reader logs or access lists for keys for secured areas; interview response considered (i.e. file cabinets, external drives, USBs, encryption, password protection).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MP.L2-3.8.2 – Media Access ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MP.L2-3.8.2_Details|&#039;&#039;&#039;MP.L2-3.8.2&#039;&#039;&#039;]] Limit access to CUI on system media to authorized users.&lt;br /&gt;
|-&lt;br /&gt;
| [a] access to CUI on system media is limited to authorized users. || Artifact || Document describing how CUI is limited AND artifact showing principle of least access is implemented.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MP.L2-3.8.3 – Media Disposal [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MP.L2-3.8.3_Details|&#039;&#039;&#039;MP.L2-3.8.3&#039;&#039;&#039;]] Sanitize or destroy information system media containing Federal Contract Information before disposal or release for reuse.&lt;br /&gt;
|-&lt;br /&gt;
| [a] system media containing CUI is sanitized or destroyed before disposal. || Document || Policy or artifact of media destruction logs; certificates of destruction; SLAs or contracts.&lt;br /&gt;
|-&lt;br /&gt;
| [b] system media containing CUI is sanitized before it is released for reuse. || Document || Policy or artifact describing method to sanitize, software used (i.e. DoD Wipe, ShredIT and Iron Mountain; Blancco; GDisk, DBAN).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MP.L2-3.8.4 – Media Markings ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MP.L2-3.8.4_Details|&#039;&#039;&#039;MP.L2-3.8.4&#039;&#039;&#039;]] Mark media with necessary CUI markings and distribution limitations.&lt;br /&gt;
|-&lt;br /&gt;
| [a] media containing CUI is marked with applicable CUI markings. || Physical Review || Document or artifact showing CUI markings (i.e. labeling standards ).&lt;br /&gt;
|-&lt;br /&gt;
| [b] media containing CUI is marked with distribution limitations. || Physical Review || Document or artifact showing distro limitations (i.e. labeling standards ).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MP.L2-3.8.5 – Media Accountability ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MP.L2-3.8.5_Details|&#039;&#039;&#039;MP.L2-3.8.5&#039;&#039;&#039;]] Control access to media containing CUI and maintain accountability for media during transport outside of controlled areas.&lt;br /&gt;
|-&lt;br /&gt;
| [a] access to media containing CUI is controlled. || Document || Policy, artifact of audit logs showing tracking, Access Control Lists, records of transport activities (i.e. USB drives, CDs, chain of custody.&lt;br /&gt;
|-&lt;br /&gt;
| [b] accountability for media containing CUI is maintained during transport outside of controlled areas. || Artifact || Artifact of audit logs showing tracking, Access Control Lists, records of transport activities (i.e. USB drives, CDs; chain of custody.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MP.L2-3.8.6 – Portable Storage Encryption ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MP.L2-3.8.6_Details|&#039;&#039;&#039;MP.L2-3.8.6&#039;&#039;&#039;]] Implement cryptographic mechanisms to protect the confidentiality of CUI stored on digital media during transport unless otherwise protected by alternative physical safeguards.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the confidentiality of CUI stored on digital media is protected during transport using cryptographic mechanisms or alternative physical safeguards. || Artifact || Artifact showing crypto mechanisms used to protect (are they FIPS 140-2 [13.11]); artifact showing what alternative physical safeguards are in place (i.e. encryption; BitLocker; McAfee ).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MP.L2-3.8.7 – Removable Media ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MP.L2-3.8.7_Details|&#039;&#039;&#039;MP.L2-3.8.7&#039;&#039;&#039;]] Control the use of removable media on system components.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the use of removable media on system components is controlled. || Artifact || Policy showing if removable media is allowed; writable removable media is restricted; tracking artifacts; what tools are used (i.e. Carbon Black, Crowd Strike, GPO, Zoho Desktop Central); procedure/process describing what happens if it is lost; what mechanisms are in place to control/restrict removable media (i.e. Active Directory Groups and Group Policy artifact showing restriction).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MP.L2-3.8.8 – Shared Media ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MP.L2-3.8.8_Details|&#039;&#039;&#039;MP.L2-3.8.8&#039;&#039;&#039;]] Prohibit the use of portable storage devices when such devices have no identifiable owner.ASSESSMENT OBJECTIVES&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [a] the use of portable storage devices is prohibited when such devices have no identifiable owner. || Artifact || Policy and/or artifact showing company stance on portable storage devices if there is no owner (are personal USB devices allowed or are they company-issued; artifact showing alerts if device is connected to network (i.e. external HDD, Carbon Black, Crowd Strike, GPO, Zoho Desktop Central.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MP.L2-3.8.9 – Protect Backups ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MP.L2-3.8.9_Details|&#039;&#039;&#039;MP.L2-3.8.9&#039;&#039;&#039;]] Protect the confidentiality of backup CUI at storage locations.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the confidentiality of backup CUI is protected at storage locations. || Artifact || Policy on system backups; artifact showing media labeling; artifact showing encyption (is it FIPS 140-2 [13.11]); Access Control List artifact (i.e. backup tapes, Tivoli Storage Manager).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Personnel Security (PS) ==&lt;br /&gt;
=== PS.L2-3.9.1 – Screen Individuals ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_PS.L2-3.9.1_Details|&#039;&#039;&#039;PS.L2-3.9.1&#039;&#039;&#039;]] Screen individuals prior to authorizing access to organizational systems containing CUI.&lt;br /&gt;
|-&lt;br /&gt;
| [a] individuals are screened prior to authorizing access to organizational systems containing CUI. || Artifact || Screenshot of records of screened personnel/background checks.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== PS.L2-3.9.2 – Personnel Actions ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_PS.L2-3.9.2_Details|&#039;&#039;&#039;PS.L2-3.9.2&#039;&#039;&#039;]] Ensure that organizational systems containing CUI are protected during and after personnel actions such as terminations and transfers.&lt;br /&gt;
|-&lt;br /&gt;
| [a] a policy and/or process for terminating system access and any credentials coincident with personnel actions is established. || Document || Personnel security policy/procedures/instruction; Access control policy/procedure/instruction.&lt;br /&gt;
|-&lt;br /&gt;
| [b] system access and credentials are terminated consistent with personnel actions such as termination or transfer. || Artifact || Screenshot of records of personnel transfer and termination actions.&lt;br /&gt;
|-&lt;br /&gt;
| [c] the system is protected during and after personnel transfer actions. || Artifact || Completed outprocessing checklist.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Physical Protection (PE) ==&lt;br /&gt;
=== PE.L2-3.10.1 – Limit Physical Access [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_PE.L2-3.10.1_Details|&#039;&#039;&#039;PE.L2-3.10.1&#039;&#039;&#039;]] Limit physical access to organizational information systems, equipment, and the respective operating environments to authorized individuals.&lt;br /&gt;
|-&lt;br /&gt;
| [a] authorized individuals allowed physical access are identified. || Artifact || Authorized personnel (names) access list.&lt;br /&gt;
|-&lt;br /&gt;
| [b] physical access to organizational systems is limited to authorized individuals. || Physical Review || Badge reader logs, audit logs, and/or card swipe test.&lt;br /&gt;
|-&lt;br /&gt;
| [c] physical access to equipment is limited to authorized individuals. || Physical Review || Badge reader logs, audit logs, and/or card swipe test.&lt;br /&gt;
|-&lt;br /&gt;
| [d] physical access to operating environments is limited to authorized. || Physical Review || Badge reader logs, audit logs, and/or card swipe test.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== PE.L2-3.10.2 – Monitor Facility ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_PE.L2-3.10.2_Details|&#039;&#039;&#039;PE.L2-3.10.2&#039;&#039;&#039;]] Protect and monitor the physical facility and support infrastructure for organizational systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the physical facility where organizational systems reside is protected. || Physical Review || Physical security measures and barriers into the physical facility (cameras/locks/gates/guards, etc.).&lt;br /&gt;
|-&lt;br /&gt;
| [b] the support infrastructure for organizational systems is protected. || Physical Review || Physical barriers to entries into computer spaces, server rooms, etc.&lt;br /&gt;
|-&lt;br /&gt;
| [c] the physical facility where organizational systems reside is monitored. || Physical Review || Audit logs/how the physical facility is being monitored (cameras/access system/guards, etc.).&lt;br /&gt;
|-&lt;br /&gt;
| [d] the support infrastructure for organizational systems is monitored. || Physical Review || Audit logs/how the physical facility is being monitored (cameras/access system/guards, etc.).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== PE.L2-3.10.3 – Escort Visitors [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_PE.L2-3.10.3_Details|&#039;&#039;&#039;PE.L2-3.10.3&#039;&#039;&#039;]] Escort visitors and monitor visitor activity.&lt;br /&gt;
|-&lt;br /&gt;
| [a] visitors are escorted. || Physical Review || Policy/procedures/instruction on methodology for handling non-authorized personnel (entry to exit).&lt;br /&gt;
|-&lt;br /&gt;
| [b] visitor activity is monitored. || Physical Review || Policy/procedures/instructio on methodology for handling non-authorized personnel (entry to exit).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== PE.L2-3.10.4 – Physical Access Logs [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_PE.L2-3.10.4_Details|&#039;&#039;&#039;PE.L2-3.10.4&#039;&#039;&#039;]] Maintain audit logs of physical access.&lt;br /&gt;
|-&lt;br /&gt;
| [a] audit logs of physical access are maintained. || Artifact || Log or report from badging system.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== PE.L2-3.10.5 – Manage Physical Access [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_PE.L2-3.10.5_Details|&#039;&#039;&#039;PE.L2-3.10.5&#039;&#039;&#039;]] Control and manage physical access devices.&lt;br /&gt;
|-&lt;br /&gt;
| [a] physical access devices are identified. || Document || Physical access control systems description, guard force contract/policy, key locks, logical systems specifications, etc.&lt;br /&gt;
|-&lt;br /&gt;
| [b] physical access devices are controlled. || Physical Review || Inventory records of physical access control devices (e.g. keys, locks, card readers, locks, etc.).&lt;br /&gt;
|-&lt;br /&gt;
| [c] physical access devices are managed. || Physical Review || List of security safeguards controlling access to the facility (e.g. cameras, monitoring by guards, isolation of IT systems equiment and or system components).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== PE.L2-3.10.6 – Alternative Work Sites ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_PE.L2-3.10.6_Details|&#039;&#039;&#039;PE.L2-3.10.6&#039;&#039;&#039;]] Enforce safeguarding measures for CUI at alternate work sites.&lt;br /&gt;
|-&lt;br /&gt;
| [a] safeguarding measures for CUI are defined for alternate work sites. || Document || Telework agreement, Acceptable Use Policy and SOP for alternate work locations; user security training validation which includes physical/logical/technical protections of system at alternate work sites.&lt;br /&gt;
|-&lt;br /&gt;
| [b] safeguarding measures for CUI are enforced for alternate work sites. || Artifact || Monitoring/audit log of user activity and logical/physical/technical mechanisms in place to preclude unauthorized activity (telework agreement , AUP?).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Risk Assessment (RA) ==&lt;br /&gt;
=== RA.L2-3.11.1 – Risk Assessments ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_RA.L2-3.11.1_Details|&#039;&#039;&#039;RA.L2-3.11.1&#039;&#039;&#039;]] Periodically assess the risk to organizational operations (including mission, functions, image, or reputation), organizational assets, and individuals, resulting from the operation of organizational systems and the associated processing, storage, or transmission of CUI.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the frequency to assess risk to organizational operations, organizational assets, and individuals is defined. || Document || Risk assessment policy.&lt;br /&gt;
|-&lt;br /&gt;
| [b] risk to organizational operations, organizational assets, and individuals resulting from the operation of an organizational system that processes, stores, or transmits CUI is assessed with the defined frequency. || Artifact || Copy of last risk assessment done within defined frequency.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== RA.L2-3.11.2 – Vulnerability Scan ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_RA.L2-3.11.2_Details|&#039;&#039;&#039;RA.L2-3.11.2&#039;&#039;&#039;]] Scan for vulnerabilities in organizational systems and applications periodically and when new vulnerabilities affecting those systems and applications are identified.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the frequency to scan for vulnerabilities in organizational systems and applications is defined. || Document || Policy/procedures/instruction addressing vulnerability scanning records.&lt;br /&gt;
|-&lt;br /&gt;
| [b] vulnerability scans are performed on organizational systems with the defined frequency. || Screen Share || System configuration settings of vulnerability scanning scheduling and vulnerability scan results of systems within defined frequency.&lt;br /&gt;
|-&lt;br /&gt;
| [c] vulnerability scans are performed on applications with the defined frequency. || Screen Share || System configuration settings of vulnerability scanning scheduling and vulnerability scan results of applications within defined frequency.&lt;br /&gt;
|-&lt;br /&gt;
| [d] vulnerability scans are performed on organizational systems when new vulnerabilities are identified. || Screen Share || View signatures in scanning tool/ad hoc scan performed as a result.&lt;br /&gt;
|-&lt;br /&gt;
| [e] vulnerability scans are performed on applications when new vulnerabilities are identified. || Screen Share || View signatures in scanning tool/ad hoc scan performed as a result.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== RA.L2-3.11.3 – Vulnerability Remediation ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_RA.L2-3.11.3_Details|&#039;&#039;&#039;RA.L2-3.11.3&#039;&#039;&#039;]] Remediate vulnerabilities in accordance with risk assessments.&lt;br /&gt;
|-&lt;br /&gt;
| [a] vulnerabilities are identified. || Artifact || Scan results showing vulnerabilities identified.&lt;br /&gt;
|-&lt;br /&gt;
| [b] vulnerabilities are remediated in accordance with risk assessments. || Artifact || Screenshot/document of scan results of remediated vulnerabilities in accordance to risk assessments.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Security Assessment (CA) ==&lt;br /&gt;
=== CA.L2-3.12.1 – Security Control Assessment ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_CA.L2-3.12.1_Details|&#039;&#039;&#039;CA.L2-3.12.1&#039;&#039;&#039;]] Periodically assess the security controls in organizational systems to determine if the controls are effective in their application.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the frequency of security control assessments is defined. || Document || SSP.&lt;br /&gt;
|-&lt;br /&gt;
| [b] security controls are assessed with the defined frequency to determine if the controls are effective in their application. || Artifact || Copy of last security control assessment done within defined frequency.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== CA.L2-3.12.2 – Operational Plan of Action ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_CA.L2-3.12.2_Details|&#039;&#039;&#039;CA.L2-3.12.2&#039;&#039;&#039;]] Develop and implement plans of action designed to correct deficiencies and reduce or eliminate vulnerabilities in organizational systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] deficiencies and vulnerabilities to be addressed by the plan of action are identified. || Artifact || Plan of Action (POA).&lt;br /&gt;
|-&lt;br /&gt;
| [b] a plan of action is developed to correct identified deficiencies and reduce or eliminate identified vulnerabilities. || Artifact || Plan of Action (POA).&lt;br /&gt;
|-&lt;br /&gt;
| [c] the plan of action is implemented to correct identified deficiencies and reduce or eliminate identified vulnerabilities. || Artifact || Plan of Action (POA)/previously completed POAs.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== CA.L2-3.12.3 – Security Control Monitoring ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_CA.L2-3.12.3_Details|&#039;&#039;&#039;CA.L2-3.12.3&#039;&#039;&#039;]] Monitor security controls on an ongoing basis to ensure the continued effectiveness of the controls.&lt;br /&gt;
|-&lt;br /&gt;
| [a] security controls are monitored on an ongoing basis to ensure the continued effectiveness of those controls. || Artifact || Collection of risk assessment results, internal or third-party audits/security assessments and/or continuous monitoring reports/alerts (SIEM tool, etc.).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== CA.L2-3.12.4 – System Security Plan ====&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_CA.L2-3.12.4_Details|&#039;&#039;&#039;CA.L2-3.12.4&#039;&#039;&#039;]] Develop, document, and periodically update system security plans that describe system boundaries, system environments of operation, how security requirements are implemented, and the relationships with or connections to other systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] a system security plan is developed. || Document || SSP.&lt;br /&gt;
|-&lt;br /&gt;
| [b] the system boundary is described and documented in the system security plan. || Document || SSP and any supporting documentation.&lt;br /&gt;
|-&lt;br /&gt;
| [c] the system environment of operation is described and documented in the system security plan. || Document || SSP and any supporting documentation.&lt;br /&gt;
|-&lt;br /&gt;
| [d] the security requirements identified and approved by the designated authority as non-applicable are identified. || Document || SSP and required adjudication from DoD CIO.&lt;br /&gt;
|-&lt;br /&gt;
| [e] the method of security requirement implementation is described and documented in the system security plan. || Document || SSP and any supporting documentation.&lt;br /&gt;
|-&lt;br /&gt;
| [f] the relationship with or connection to other systems is described and documented in the system security plan. || Document || SSP and any supporting documentation.&lt;br /&gt;
|-&lt;br /&gt;
| [g] the frequency to update the system security plan is defined. || Document || SSP.&lt;br /&gt;
|-&lt;br /&gt;
| [h] system security plan is updated with the defined frequency. || Document || SSP/any previous versions.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== System and Communications Protection (SC) ==&lt;br /&gt;
=== SC.L2-3.13.1 – Boundary Protection [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.1_Details|&#039;&#039;&#039;SC.L2-3.13.1&#039;&#039;&#039;]] Monitor, control, and protect organizational communications (i.e., information transmitted or received by organizational information systems) at the external boundaries and key internal boundaries of the information systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the external system boundary is defined. || Document || SSP, network diagrams, CUI flow, cloud provider FedRAMP Moderate.&lt;br /&gt;
|-&lt;br /&gt;
| [b] key internal system boundaries are defined. || Document || SSP, network diagrams, CUI flow.&lt;br /&gt;
|-&lt;br /&gt;
| [c] communications are monitored at the external system boundary. || Screen Share || SSP, logging server, boundary device configurations, monitoring policy.&lt;br /&gt;
|-&lt;br /&gt;
| [d] communications are monitored at key internal boundaries. || Screen Share || SSP, logging server, boundary device configurations, monitoring policy.&lt;br /&gt;
|-&lt;br /&gt;
| [e] communications are controlled at the external system boundary. || Screen Share || SSP, boundary device configurations, ACL, subnets, DMZ.&lt;br /&gt;
|-&lt;br /&gt;
| [f] communications are controlled at key internal boundaries. || Screen Share || SSP, boundary device configurations, ACL, subnets.&lt;br /&gt;
|-&lt;br /&gt;
| [g] communications are protected at the external system boundary. || Screen Share || Configurations for IPS/IDS, email gateway, VLAN, proxy, firewall, malware protection, DNS, TSL.&lt;br /&gt;
|-&lt;br /&gt;
| [h] communications are protected at key internal boundaries. || Screen Share || Configurations for IPS/IDS, VLAN, firewall, malware protection, SSL.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.2 – Security Engineering ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.2_Details|&#039;&#039;&#039;SC.L2-3.13.2&#039;&#039;&#039;]] Employ architectural designs, software development techniques, and systems engineering principles that promote effective information security within organizational systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] architectural designs that promote effective information security are identified. || Document || SSP, config management policy, network diagram, CCB minutes, enterprise architecture process.&lt;br /&gt;
|-&lt;br /&gt;
| [b] software development techniques that promote effective information security are identified. || Document || SSP, config management policy, SDLC, CCB minutes.&lt;br /&gt;
|-&lt;br /&gt;
| [c] systems engineering principles that promote effective information security are identified. || Document || SSP, config management policy, CCB minutes, security architecture engineering.&lt;br /&gt;
|-&lt;br /&gt;
| [d] identified architectural designs that promote effective information security are employed. || Artifact || CCB minutes, Network diagrams and configurations, Project Plans.&lt;br /&gt;
|-&lt;br /&gt;
| [e] identified software development techniques that promote effective information security are employed. || Artifact || CCB minutes, SDLC, code scanner results, code management tracking.&lt;br /&gt;
|-&lt;br /&gt;
| [f] identified systems engineering principles that promote effective information security are employed. || Artifact || CCB minutes, configuration management, ITSM, patch management, lifecycle replacement processes.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.3 – Role Separation ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.3_Details|&#039;&#039;&#039;SC.L2-3.13.3&#039;&#039;&#039;]] Separate user functionality from system management functionality.&lt;br /&gt;
|-&lt;br /&gt;
| [a] user functionality is identified. || Document || SSP, AUP.&lt;br /&gt;
|-&lt;br /&gt;
| [b] system management functionality is identified. || Document || SSP, Privileged Account Agreement.&lt;br /&gt;
|-&lt;br /&gt;
| [c] user functionality is separated from system management functionality. || Screen Share || Active Directory, Jump Boxes, GPO, VM, RDP.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.4 – Shared Resource Control ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.4_Details|&#039;&#039;&#039;SC.L2-3.13.4&#039;&#039;&#039;]] Prevent unauthorized and unintended information transfer via shared system resources.&lt;br /&gt;
|-&lt;br /&gt;
| [a] unauthorized and unintended information transfer via shared system resources is prevented. || Screen Share || SSP, OS configurations, Linux containers, system/media reuse policies, certificate management policies, media destruction policies, printer configs, VDI configuration.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
===  SC.L2-3.13.5 – Public-Access System Separation [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.5_Details|&#039;&#039;&#039;SC.L2-3.13.5&#039;&#039;&#039;]] Implement subnetworks for publicly accessible system components that are physically or logically separated from internal networks.&lt;br /&gt;
|-&lt;br /&gt;
| [a] publicly accessible system components are identified. || Document || SSP, network diagram, DMZ inventory/roles.&lt;br /&gt;
|-&lt;br /&gt;
| [b] subnetworks for publicly accessible system components are physically or logically separated from internal networks. || Artifact || Network diagram, IPAM, VLAN, DHCP, DMZ.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.6 – Network Communication by Exception ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.6_Details|&#039;&#039;&#039;SC.L2-3.13.6&#039;&#039;&#039;]] Deny network communications traffic by default and allow network communications traffic by exception (i.e., deny all, permit by exception).&lt;br /&gt;
|-&lt;br /&gt;
| [a] network communications traffic is denied by default. || Screen Share || Host and network firewall rules, SIEM logs, hit counts.&lt;br /&gt;
|-&lt;br /&gt;
| [b] network communications traffic is allowed by exception. || Screen Share || Host and network firewall rules, SIEM logs, hit counts.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.7 – Split Tunneling ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.7_Details|&#039;&#039;&#039;SC.L2-3.13.7&#039;&#039;&#039;]] Prevent remote devices from simultaneously establishing non-remote connections with organizational systems and communicating via some other connection to resources in external networks (i.e., split tunneling).&lt;br /&gt;
|-&lt;br /&gt;
| [a] remote devices are prevented from simultaneously establishing non-remote connections with the system and communicating via some other connection to resources in external networks (i.e., split tunneling). || Screen Share || VPN appliance/server configuration, endpoint VPN software configuration.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.8 – Data in Transit ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.8_Details|&#039;&#039;&#039;SC.L2-3.13.8&#039;&#039;&#039;]] Implement cryptographic mechanisms to prevent unauthorized disclosure of CUI during transmission unless otherwise protected by alternative physical safeguards.&lt;br /&gt;
|-&lt;br /&gt;
| [a] cryptographic mechanisms intended to prevent unauthorized disclosure of CUI are identified. || Document || SSP, PKI policies, configuration processes, config management, email attachment encryption policy, removable media policy, data at rest policy.&lt;br /&gt;
|-&lt;br /&gt;
| [b] alternative physical safeguards intended to prevent unauthorized disclosure of CUI are identified. || Document || SSP, physical security policy.&lt;br /&gt;
|-&lt;br /&gt;
| [c] either cryptographic mechanisms or alternative physical safeguards are implemented to prevent unauthorized disclosure of CUI during transmission. || Screen Share || TLS settings, SSL settings, VPN/Wireless Access Points/Mobile Devices cryptographic settings, ODBC connector settings, SAN configuration, IPSec/MPLS, backup configuration, physical security.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.9 – Connections Termination ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.9_Details|&#039;&#039;&#039;SC.L2-3.13.9&#039;&#039;&#039;]] Terminate network connections associated with communications sessions at the end of the sessions or after a defined period of inactivity.&lt;br /&gt;
|-&lt;br /&gt;
| [a] a period of inactivity to terminate network connections associated with communications sessions is defined. || Document || SSP, network communications policy.&lt;br /&gt;
|-&lt;br /&gt;
| [b] network connections associated with communications sessions are terminated at the end of the sessions. || Screen Share || VPN appliance/server logs, VPN configurations, web server configurations, firewall connection settings.&lt;br /&gt;
|-&lt;br /&gt;
| [c] network connections associated with communications sessions are terminated after the defined period of inactivity. || Screen Share || VPN appliance/server logs, VPN configurations, web server configurations, frewall connection settings.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.10 – Key Management ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.10_Details|&#039;&#039;&#039;SC.L2-3.13.10&#039;&#039;&#039;]] Establish and manage cryptographic keys for cryptography employed in organizational systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] cryptographic keys are established whenever cryptography is employed. || Artifact || SSP, PKI/certificate management policy, configuration management.&lt;br /&gt;
|-&lt;br /&gt;
| [b] cryptographic keys are managed whenever cryptography is employed. || Artifact || SSP, PKI/certificate management policy, configuration management, access control policy.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.11 – CUI Encryption ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.11_Details|&#039;&#039;&#039;SC.L2-3.13.11&#039;&#039;&#039;]] Employ FIPS-validated cryptography when used to protect the confidentiality of CUI.&lt;br /&gt;
|-&lt;br /&gt;
| [a] FIPS-validated cryptography is employed to protect the confidentiality of CUI. || Screen Share || VPN, wireless, mobile devices, client certificates, server certificates, disk encryption, Outlook plugin, external mail, backup media, ePO server, removable storage, SAN, file compression; look for FIPS mode enabled on appliances.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.12 – Collaborative Device Control ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.12_Details|&#039;&#039;&#039;SC.L2-3.13.12&#039;&#039;&#039;]] Prohibit remote activation of collaborative computing devices and provide indication of devices in use to users present at the device.&lt;br /&gt;
|-&lt;br /&gt;
| [a] collaborative computing devices are identified. || Document || SSP, network diagrams.&lt;br /&gt;
|-&lt;br /&gt;
| [b] collaborative computing devices provide indication to users of devices in use. || Physical Review || Physical inspection of device.&lt;br /&gt;
|-&lt;br /&gt;
| [c] remote activation of collaborative computing devices is prohibited. || Screen Share || Collaboration device configuration/console.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.13 – Mobile Code ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.13_Details|&#039;&#039;&#039;SC.L2-3.13.13&#039;&#039;&#039;]] Control and monitor the use of mobile code.&lt;br /&gt;
|-&lt;br /&gt;
| [a] use of mobile code is controlled. || Screen Share || GPO settings, malware protection, software agent configurations, software development policies, code scanners, MDM configuration, firewall/secure web gateway/proxy config.&lt;br /&gt;
|-&lt;br /&gt;
| [b] use of mobile code is monitored. || Screen Share || SIEM/console monitoring.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.14 – Voice over Internet Protocol ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.14_Details|&#039;&#039;&#039;SC.L2-3.13.14&#039;&#039;&#039;]] Control and monitor the use of Voice over Internet Protocol (VoIP) technologies.&lt;br /&gt;
|-&lt;br /&gt;
| [a] use of Voice over Internet Protocol (VoIP) technologies is controlled. || Artifact || VLAN, ACL, firewall config, VoIP gateway/condenser configuration.&lt;br /&gt;
|-&lt;br /&gt;
| [b] use of Voice over Internet Protocol (VoIP) technologies is monitored. || Artifact || SIEM/VoIP console monitoring, session border controller.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.15 – Communications Authenticity ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.15_Details|&#039;&#039;&#039;SC.L2-3.13.15&#039;&#039;&#039;]] Protect the authenticity of communications sessions.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the authenticity of communications sessions is protected. || Screen Share || SSL, TLS, SMB3, SFTP, IPSec, SSH, Kerberos configs, MPLS, Network Access Control.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.16 – Data at Rest ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.16_Details|&#039;&#039;&#039;SC.L2-3.13.16&#039;&#039;&#039;]] Protect the confidentiality of CUI at rest.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the confidentiality of CUI at rest is protected. || Artifact || Full disk encryption, removable media encryption, SAN encryption, digital backups, mobile device encryption, third party offsite backup storage, cloud virtualization encryption, physical media storage policies.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== System and Information Integrity (SI) ==&lt;br /&gt;
=== SI.L2-3.14.1 – Flaw Remediation [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SI.L2-3.14.1_Details|&#039;&#039;&#039;SI.L2-3.14.1&#039;&#039;&#039;]] Identify, report, and correct information and information system flaws in a timely manner.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the time within which to identify system flaws is specified. || Document || SSP, patch management policy.&lt;br /&gt;
|-&lt;br /&gt;
| [b] system flaws are identified within the specified time frame. || Screen Share || Vulnerability management scanner output and scan policy configuration.&lt;br /&gt;
|-&lt;br /&gt;
| [c] the time within which to report system flaws is specified. || Document || SSP, patch management policy.&lt;br /&gt;
|-&lt;br /&gt;
| [d] system flaws are reported within the specified time frame. || Screen Share || ITSM/trouble tickets, vulnerability management scanner output.&lt;br /&gt;
|-&lt;br /&gt;
| [e] the time within which to correct system flaws is specified. || Document || SSP, patch management policy.&lt;br /&gt;
|-&lt;br /&gt;
| [f] system flaws are corrected within the specified time frame. || Screen Share || Vulnerability management scanner output and scan policy configuration.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SI.L2-3.14.2 – Malicious Code ProTection [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SI.L2-3.14.2_Details|&#039;&#039;&#039;SI.L2-3.14.2&#039;&#039;&#039;]] Provide protection from malicious code at appropriate locations within organizational information systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] designated locations for malicious code protection are identified. || Document || SSP, system protection policy, network diagrams, security architecture documents.&lt;br /&gt;
|-&lt;br /&gt;
| [b] protection from malicious code at designated locations is provided. || Screen Share || Endpoint security settings, email/web proxy gateways, firewall, IPS sensor, MDM configuration, Network Access Control.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SI.L2-3.14.3 – Security Alerts &amp;amp; Advisories ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SI.L2-3.14.3_Details|&#039;&#039;&#039;SI.L2-3.14.3&#039;&#039;&#039;]] Monitor system security alerts and advisories and take action in response.&lt;br /&gt;
|-&lt;br /&gt;
| [a] response actions to system security alerts and advisories are identified. || Document || SSP, vulnerability management policy, Incident Response Plan.&lt;br /&gt;
|-&lt;br /&gt;
| [b] system security alerts and advisories are monitored. || Artifact || Threat intelligence subscriptions, email advisories.&lt;br /&gt;
|-&lt;br /&gt;
| [c] actions in response to system security alerts and advisories are taken. || Artifact || ITSM/trouble tickets, user notifications, updates to firewall/IPS, etc.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SI.L2-3.14.4 – Update Malicious Code Protection [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SI.L2-3.14.4_Details|&#039;&#039;&#039;SI.L2-3.14.4&#039;&#039;&#039;]] Update malicious code protection mechanisms when new releases are available.&lt;br /&gt;
|-&lt;br /&gt;
| [a] malicious code protection mechanisms are updated when new releases are available. || Screen Share || Antivirus console dashboard, firewall AV, Email gateway signatures,proxy, IPS updates.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SI.L2-3.14.5 – System &amp;amp; File Scanning [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SI.L2-3.14.5_Details|&#039;&#039;&#039;SI.L2-3.14.5&#039;&#039;&#039;]] Perform periodic scans of the information system and real-time scans of files from external sources as files are downloaded, opened, or executed.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the frequency for malicious code scans is defined. || Document || SSP, vulnerability management policy.&lt;br /&gt;
|-&lt;br /&gt;
| [b] malicious code scans are performed with the defined frequency. || Screen Share || Consoles for AV (endpoints, servers, and file shares), firewall, email gateway, proxy, IPS, MDM configurations.&lt;br /&gt;
|-&lt;br /&gt;
| [c] real-time malicious code scans of files from external sources as files are downloaded, opened, or executed are performed. || Screen Share || Consoles for AV (endpoints, servers, and file shares), firewall, email gateway, proxy, IPS, MDM configurations.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SI.L2-3.14.6 – Monitor Communications for Attacks ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SI.L2-3.14.6_Details|&#039;&#039;&#039;SI.L2-3.14.6&#039;&#039;&#039;]] Monitor organizational systems, including inbound and outbound communications traffic, to detect attacks and indicators of potential attacks.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the system is monitored to detect attacks and indicators of potential attacks. || Screen Share || Firewall, IPS, endpoint protection, SIEM alerts and reports.&lt;br /&gt;
|-&lt;br /&gt;
| [b] inbound communications traffic is monitored to detect attacks and indicators of potential attacks. || Screen Share || Firewall, IPS, endpoint protection, SIEM alerts and reports.&lt;br /&gt;
|-&lt;br /&gt;
| [c] outbound communications traffic is monitored to detect attacks and indicators of potential attacks. || Screen Share || Firewall, IPS, endpoint protection, SIEM alerts and reports.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SI.L2-3.14.7 – Identify Unauthorized Use ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SI.L2-3.14.7_Details|&#039;&#039;&#039;SI.L2-3.14.7&#039;&#039;&#039;]] Identify unauthorized use of organizational systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] authorized use of the system is defined. || Document || AUP, SSP.&lt;br /&gt;
|-&lt;br /&gt;
| [b] unauthorized use of the system is identified. || Artifact || SIEM logs, endpoint protection console, IPS, Firewall.&lt;br /&gt;
|}&lt;/div&gt;</summary>
		<author><name>David</name></author>
	</entry>
	<entry>
		<id>https://cmmcwiki.org/index.php?title=Evidence_Collection_Approach&amp;diff=1621</id>
		<title>Evidence Collection Approach</title>
		<link rel="alternate" type="text/html" href="https://cmmcwiki.org/index.php?title=Evidence_Collection_Approach&amp;diff=1621"/>
		<updated>2026-07-20T01:41:36Z</updated>

		<summary type="html">&lt;p&gt;David: /* IA.L2-3.5.1 – Identification [CUI Data] */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;CMMC assessments and certification require substantial evidence and documentation. The following tables outline general guidelines for collecting evidence to assess control requirements and objectives. While these guidelines provide a structured approach, they are not the only means of conducting an accurate assessment. Assessors should exercise professional judgment and may employ alternative methods appropriate to the specific organizational context and circumstances.&lt;br /&gt;
&lt;br /&gt;
Evidence collection approaches are defined as:&lt;br /&gt;
* &#039;&#039;&#039;Documentation&#039;&#039;&#039;: Tangible materials containing information over which an organization has authority, including all types of written records and their copies.&lt;br /&gt;
* &#039;&#039;&#039;Artifacts&#039;&#039;&#039;: Tangible, reviewable records directly resulting from a practice or process being performed by a system or by personnel executing their role within that practice, control, or process.&lt;br /&gt;
* &#039;&#039;&#039;Physical Review&#039;&#039;&#039;: Direct on-site observation and examination of evidence.&lt;br /&gt;
* &#039;&#039;&#039;Screen Share&#039;&#039;&#039;: Real-time remote observation of a user demonstrating a task or process via shared computer screen, sometimes called &amp;quot;over-the-shoulder&amp;quot; review.&lt;br /&gt;
&lt;br /&gt;
DISCLAIMER: Evidence requirements vary significantly across assessment types. &#039;&#039;&#039;The examples provided are illustrative only and should be tailored to meet the specific adequacy and sufficiency standards of your particular assessment context.&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
For inquiries and reporting errors on this wiki, please [mailto:support@cmmctoolkit.org contact us]. Thank you.&lt;br /&gt;
&lt;br /&gt;
== Access Control (AC) ==&lt;br /&gt;
=== AC.L2-3.1.1 – Authorized Access Control [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.1_Details|&#039;&#039;&#039;AC.L2-3.1.1&#039;&#039;&#039;]] Limit information system access to authorized users, processes acting on behalf of authorized users, or devices (including other information systems).&lt;br /&gt;
|-&lt;br /&gt;
| [a] authorized users are identified. || Document || Document defining account request, approval, provisioning.&lt;br /&gt;
|-&lt;br /&gt;
| [b] processes acting on behalf of authorized users are identified. || Document || Document defining account request, approval, provisioning.&lt;br /&gt;
|-&lt;br /&gt;
| [c] devices (and other systems) authorized to connect to the system are identified. || Document || Document defining account request, approval, provisioning.&lt;br /&gt;
|-&lt;br /&gt;
| [d] system access is limited to authorized users. || Screen Share || Screen share showing login requirements are enforced. Example of an unauthorized user denied (unauthorized username entered at login).&lt;br /&gt;
|-&lt;br /&gt;
| [e] system access is limited to processes acting on behalf of authorized users. || Screen Share || Screenshot showing that service accounts are assigned to authorized users only; no rogue accounts without an authorized user are active.&lt;br /&gt;
|-&lt;br /&gt;
| [f] system access is limited to authorized devices (including other systems). || Screen Share || Screen share showing that all devices running are authorized; no rogue devices on the network.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.2 – Transaction &amp;amp; Function Control [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.2_Details|&#039;&#039;&#039;AC.L2-3.1.2&#039;&#039;&#039;]] Limit information system access to the types of transactions and functions that authorized users are permitted to execute.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the types of transactions and functions that authorized users are permitted to execute are defined. || Document || SSP, AUP, or IAM document that defines what authorized users can execute.&lt;br /&gt;
|-&lt;br /&gt;
| [b] system access is limited to the defined types of transactions and functions for authorized users. || Screen Share || Screenshot of security roles in AD or IAM or other directory-based identity-related services tool that shows transactions are as defined in the SSP or IAM document; privileged and non-privileged accounts need to be defined and identified in the artifact; screenshot of a non-privileged user trying to execute a privileged function.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.3 – Control CUI Flow ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.3_Details|&#039;&#039;&#039;AC.L2-3.1.3&#039;&#039;&#039;]] Control the flow of CUI in accordance with approved authorizations.&lt;br /&gt;
|-&lt;br /&gt;
| [a] information flow control policies are defined. || Document || SSP or other document describing the control of CUI on the network.&lt;br /&gt;
|-&lt;br /&gt;
| [b] methods and enforcement mechanisms for controlling the flow of CUI are defined. || Document || Document that defines the networking devices that are on the CUI network and answers what measures are in place to control the flow. List of firewalls, border and internal layer 3 devices, IDS/IPS, DLP, that process CUI.&lt;br /&gt;
|-&lt;br /&gt;
| [c] designated sources and destinations (e.g., networks, individuals, and devices) for CUI within the system and between interconnected systems are identified. || Artifact || Network diagram, data flow diagram, external system connection diagrams, document describing the policies for CUI on the network; listing of VLANs and subnets where CUI is authorized; document must describe source and authorized destinations.&lt;br /&gt;
|-&lt;br /&gt;
| [d] authorizations for controlling the flow of CUI are defined. || Document || Document that defines how CUI is to be controlled, such as an InfoSec plan, and/or network management plan.&lt;br /&gt;
|-&lt;br /&gt;
| [e] approved authorizations for controlling the flow of CUI are enforced. || Screen Share || Screenshots of firewall rules, ACLs, etc.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.4 – Separation of Duties ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.4_Details|&#039;&#039;&#039;AC.L2-3.1.4&#039;&#039;&#039;]] Separate the duties of individuals to reduce the risk of malevolent activity without collusion.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the duties of individuals requiring separation are defined. || Document || Document, SSP, account management policy, defining separation of duties by person or role.&lt;br /&gt;
|-&lt;br /&gt;
| [b] responsibilities for duties that require separation are assigned to separate individuals. || Screen Share || Screenshot showing that separation of duties is enforced by showing admin accounts are assigned to different people based on role.&lt;br /&gt;
|-&lt;br /&gt;
| [c] access privileges that enable individuals to exercise the duties that require separation are granted to separate individuals. || Screen Share || Screen shot showing an example such as a security manager can not log into a network device and change ACLs, or network admins can not access security logs in the SIEM tool.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.5 – Least Privilege ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.5_Details|&#039;&#039;&#039;AC.L2-3.1.5&#039;&#039;&#039;]] Employ the principle of least privilege, including for specific security functions and privileged accounts.&lt;br /&gt;
|-&lt;br /&gt;
| [a] privileged accounts are identified. || Document || &amp;quot;SSP or policy (documentation) identify what is considered a privileged account.&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| [b] access to privileged accounts is authorized in accordance with the principle of least privilege. || Artifact || An artifact that identifies the least amount of permissions associated with different types of privileged accounts are approved.&lt;br /&gt;
|-&lt;br /&gt;
| [c] security functions are identified. || Document || &amp;quot;SSP or policy (documentation) identifies what is considered a security account.&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| [d] access to security functions is authorized in accordance with the principle of least privilege. || Artifact || Artifact(s) that identify the least amount of permissions associated with different types of security accounts are approved.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.6 – Non-Privileged Account Use ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.6_Details|&#039;&#039;&#039;AC.L2-3.1.6&#039;&#039;&#039;]] Use non-privileged accounts or roles when accessing nonsecurity functions.&lt;br /&gt;
|-&lt;br /&gt;
| [a] nonsecurity functions are identified. || Document || SSP or account management document, AUP, that defines non-security functions.&lt;br /&gt;
|-&lt;br /&gt;
| [b] users are required to use non-privileged accounts or roles when accessing nonsecurity functions. || Screen Share || Screenshot showing that a privileged user tried to use their admin account to access a non-security function, such as a browser or email (whatever is defined in their policy) and was blocked.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.7 – Privileged Functions ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.7_Details|&#039;&#039;&#039;AC.L2-3.1.7&#039;&#039;&#039;]] Prevent non-privileged users from executing privileged functions and capture the execution of such functions in audit logs.&lt;br /&gt;
|-&lt;br /&gt;
| [a] privileged functions are defined. || Document || SSP or policy (documentation) that defines privileged functions.&lt;br /&gt;
|-&lt;br /&gt;
| [b] non-privileged users are defined. || Document || SSP or policy (documentation) that defines non-privileged users.&lt;br /&gt;
|-&lt;br /&gt;
| [c] non-privileged users are prevented from executing privileged functions. || Screen Share || Screen share that shows that a non-privileged user is not allowed to complete a privileged function (installing software).&lt;br /&gt;
|-&lt;br /&gt;
| [d] the execution of privileged functions is captured in audit logs. || Screen Share || Screen share that shows logs being captured of the execution of privileged functions.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.8 – Unsuccessful Logon Attempts ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.8_Details|&#039;&#039;&#039;AC.L2-3.1.8&#039;&#039;&#039;]] Limit unsuccessful logon attempts.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the means of limiting unsuccessful logon attempts is defined. || Document || SSP or policy (documentation) showing unsuccessful logon attempts settings and or policy.&lt;br /&gt;
|-&lt;br /&gt;
| [b] the defined means of limiting unsuccessful logon attempts is implemented. || Artifact || Artifact showing GPO / Policy for limiting logon attempts.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.9 – Privacy &amp;amp; Security Notices ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.9_Details|&#039;&#039;&#039;AC.L2-3.1.9&#039;&#039;&#039;]] Provide privacy and security notices consistent with applicable CUI rules.&lt;br /&gt;
|-&lt;br /&gt;
| [a] privacy and security notices required by CUI-specified rules are identified, consistent, and associated with the specific CUI category. || Document || SSP or policy (documentation) showing CUI-specified rules are identified, consistent, and associated with the specific CUI category.&lt;br /&gt;
|-&lt;br /&gt;
| [b] privacy and security notices are displayed. || Artifact || Artifact that shows a consent banner or screen that a user sees as they log in to the system.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.10 – Session Lock ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.10_Details|&#039;&#039;&#039;AC.L2-3.1.10&#039;&#039;&#039;]] Use session lock with pattern-hiding displays to prevent access and viewing of data after a period of inactivity.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the period of inactivity after which the system initiates a session lock is defined. || Document || SSP or policy (documentation) that defines the period of inactivity and when a session lock is defined.&lt;br /&gt;
|-&lt;br /&gt;
| [b] access to the system and viewing of data is prevented by initiating a session lock after the defined period of inactivity. || Artifact || Artifact that shows the setting of session lock (GPO or system policy or similar solution addressing the controls supporting centralized management and configuration of operating systems, applications, and users&#039; settings for the working environment of user accounts and computer accounts).&lt;br /&gt;
|-&lt;br /&gt;
| [c] previously visible information is concealed via a pattern-hiding display after the defined period of inactivity. || Document || Screenshot of GPO setting and configuration settings, or similar solution addressing the controls supporting centralized management and configuration of operating systems, applications, and users&#039; settings for the working environment of user accounts and computer accounts.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.11 – Session Termination ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.11_Details|&#039;&#039;&#039;AC.L2-3.1.11&#039;&#039;&#039;]] Terminate (automatically) a user session after a defined condition.&lt;br /&gt;
|-&lt;br /&gt;
| [a] conditions requiring a user session to terminate are defined. || Document || SSP or policy (documentation) that defines the conditions requiring a user session to be terminated.&lt;br /&gt;
|-&lt;br /&gt;
| [b] a user session is automatically terminated after any of the defined conditions. || Screen Share || Screen share showing GPO / VPN Settings that show when a session would be terminated (Idle time, max connection time).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.12 – Control Remote Access ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.12_Details|&#039;&#039;&#039;AC.L2-3.1.12&#039;&#039;&#039;]] Monitor and control remote access sessions.&lt;br /&gt;
|-&lt;br /&gt;
| [a] remote access sessions are permitted. || Document || SSP or policy (documentation) that defines remote access sessions.&lt;br /&gt;
|-&lt;br /&gt;
| [b] the types of permitted remote access are identified. || Document || SSP or policy (documentation) that defines remote access is permitted.&lt;br /&gt;
|-&lt;br /&gt;
| [c] remote access sessions are controlled. || Screen Share || Screen share that shows how the remote access is controlled (access session, and or groups).&lt;br /&gt;
|-&lt;br /&gt;
| [d] remote access sessions are monitored. || Screen Share || Screen share that shows how remote sessions are monitored (logs).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.13 – Remote Access Confidentiality ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.13_Details|&#039;&#039;&#039;AC.L2-3.1.13&#039;&#039;&#039;]] Employ cryptographic mechanisms to protect the confidentiality of remote access sessions.&lt;br /&gt;
|-&lt;br /&gt;
| [a] cryptographic mechanisms to protect the confidentiality of remote access sessions are identified. || Document || SSP or policy (documentation) that discusses the CUI rules, consistent, and associated with the specific CUI category; FIPS Cert # of appliance or application.&lt;br /&gt;
|-&lt;br /&gt;
| [b] cryptographic mechanisms to protect the confidentiality of remote access sessions are implemented. || Screen Share || Screenshot of VPN concentration that shows encryption is on and enabled (point-to-point, etc.).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.14 – Remote Access Routing ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.14_Details|&#039;&#039;&#039;AC.L2-3.1.14&#039;&#039;&#039;]] Route remote access via managed access control points.&lt;br /&gt;
|-&lt;br /&gt;
| [a] managed access control points are identified and implemented. || Screen Share || Screen share that shows access control points (groups and/or users).&lt;br /&gt;
|-&lt;br /&gt;
| [b] remote access is routed through managed network access control points. || Screen Share || Screen share that shows access control points and how they are managed.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.15 – Privileged Remote Access ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.15_Details|&#039;&#039;&#039;AC.L2-3.1.15&#039;&#039;&#039;]] Authorize remote execution of privileged commands and remote access to security-relevant information.&lt;br /&gt;
|-&lt;br /&gt;
| [a] privileged commands authorized for remote execution are identified. || Document || SSP or policy (documentation) that defines what is authorized to be executed remotely and how that is handled.&lt;br /&gt;
|-&lt;br /&gt;
| [b] security-relevant information authorized to be accessed remotely is identified. || Document || SSP or policy (documentation) that defines what can be accessed remotely and what procedures are implemented to allow this (RDP, jump box).&lt;br /&gt;
|-&lt;br /&gt;
| [c] the execution of the identified privileged commands via remote access is authorized. || Artifact || Screen share that shows who has access to perform privileged commands a remotely (access groups for privileged accounts).&lt;br /&gt;
|-&lt;br /&gt;
| [d] access to the identified security-relevant information via remote access is authorized. || Artifact || Screen share that shows the routing of remote access and how it is monitored and how many locations (Firewall, VPN Concentrator).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.16 – Wireless Access Authorization ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.16_Details|&#039;&#039;&#039;AC.L2-3.1.16&#039;&#039;&#039;]] Authorize wireless access prior to allowing such connections.&lt;br /&gt;
|-&lt;br /&gt;
| [a] wireless access points are identified. || Document || SSP, network administration document.&lt;br /&gt;
|-&lt;br /&gt;
| [b] wireless access is authorized prior to allowing such connections. || Screen Share || Authorization profile(s) in Wireless Access Controller or Identity Manager (i.e. Cisco ISE).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.17 – Wireless Access Protection ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.17_Details|&#039;&#039;&#039;AC.L2-3.1.17&#039;&#039;&#039;]] Protect wireless access using authentication and encryption.&lt;br /&gt;
|-&lt;br /&gt;
| [a] wireless access to the system is protected using authentication. || Screen Share || Security page (or similar) of a Wireless Access Controller.&lt;br /&gt;
|-&lt;br /&gt;
| [b] wireless access to the system is protected using encryption. || Screen Share || Security page (or similar) of a Wireless Access Controller.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.18 – Mobile Device Connection ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.18_Details|&#039;&#039;&#039;AC.L2-3.1.18&#039;&#039;&#039;]] Control connection of mobile devices.&lt;br /&gt;
|-&lt;br /&gt;
| [a] mobile devices that process, store, or transmit CUI are identified. || Document || SSP, Mobile Device Policy.&lt;br /&gt;
|-&lt;br /&gt;
| [b] mobile device connections are authorized. || Artifact || Authorization profile(s) in Wireless Access Controller or Identity Manager (i.e. Cisco ISE).&lt;br /&gt;
|-&lt;br /&gt;
| [c] mobile device connections are monitored and logged. || Screen Share || Mobile device logs within the MDM, log intake (sources) configuration (within SIEM) showing MDM is feeding logs to the SIEM.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.19 – Encrypt CUI on Mobile ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.19_Details|&#039;&#039;&#039;AC.L2-3.1.19&#039;&#039;&#039;]] Encrypt CUI on mobile devices and mobile computing platforms.&lt;br /&gt;
|-&lt;br /&gt;
| [a] mobile devices and mobile computing platforms that process, store, or transmit CUI are identified. || Document || SSP, Mobile Device Policy.&lt;br /&gt;
|-&lt;br /&gt;
| [b] encryption is employed to protect CUI on identified mobile devices and mobile computing platforms. || Screen Share || Security policy page in MDM showing how encryption are enforced on mobile device. If no MDM or MDM doesn&#039;t enforce encryption, then validate if the devices used are on the list of devices with native FIPS approved validation.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.20 – External Connections [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.20_Details|&#039;&#039;&#039;AC.L2-3.1.20&#039;&#039;&#039;]] Verify and control/limit connections to and use of external information systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] connections to external systems are identified. || Document || SSP, Systems Interconnection Agreements, SLA.&lt;br /&gt;
|-&lt;br /&gt;
| [b] the use of external systems is identified. || Document || SSP, Systems Interconnection Agreements, SLA.&lt;br /&gt;
|-&lt;br /&gt;
| [c] connections to external systems are verified. || Artifact || SLA for external systems, memorandum for interconnection, information to prove that any cloud solution is at FedRAMP impact level of moderate or higher (i.e. license information, screenshot of AWS cloud dashboard, purchase order document).&lt;br /&gt;
|-&lt;br /&gt;
| [d] the use of external systems is verified. || Artifact || SLA for external systems, memorandum for interconnection, information to prove that any cloud solution is at FedRAMP impact level of moderate or higher (i.e. license information, screenshot of AWS cloud dashboard, purchase order document).&lt;br /&gt;
|-&lt;br /&gt;
| [e] connections to external systems are controlled/limited. || Screen Share || Firewall ruleset for controlling access to cloud service or external system.&lt;br /&gt;
|-&lt;br /&gt;
| [f] the use of external systems is controlled/limited. || Screen Share || Firewall ruleset for controlling access to cloud service or external system.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.21 – Portable Storage Use ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.21_Details|&#039;&#039;&#039;AC.L2-3.1.21&#039;&#039;&#039;]] Limit use of portable storage devices on external systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the use of portable storage devices containing CUI on external systems is identified and documented. || Document || SSP, Removable Media Policy, Acceptable Use Policy (with emphasis on portable media use).&lt;br /&gt;
|-&lt;br /&gt;
| [b] limits on the use of portable storage devices containing CUI on external systems are defined. || Document || SSP, Removable Media Policy, Acceptable Use Policy (with emphasis on portable media use).&lt;br /&gt;
|-&lt;br /&gt;
| [c] the use of portable storage devices containing CUI on external systems is limited as defined. || Document || SSP, Removable Media Policy, Acceptable Use Policy (with emphasis on portable media use).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.22 – Control Public Information [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.22_Details|&#039;&#039;&#039;AC.L2-3.1.22&#039;&#039;&#039;]] Control information posted or processed on publicly accessible information systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] individuals authorized to post or process information on publicly accessible systems are identified. || Document || SSP, Website Governance Plan, Information Release Document.&lt;br /&gt;
|-&lt;br /&gt;
| [b] procedures to ensure CUI is not posted or processed on publicly accessible systems are identified. || Document || SSP, Website Governance Plan, Information Release Document.&lt;br /&gt;
|-&lt;br /&gt;
| [c] a review process is in place prior to posting of any content to publicly accessible systems. || Artifact || &amp;quot;Information release approval process, i.e. chain of email communication from originator, approver, and final decision (may or may not include individual authorized to post); &lt;br /&gt;
SharePoint/electronic or paper form/ ticket system showing information flow between requestor and approver (may or may not include  individual authorized to post).&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| [d] content on publicly accessible systems is reviewed to ensure that it does not include CUI. || Artifact || Incident response process, web design/update/modification SOP etc.&lt;br /&gt;
|-&lt;br /&gt;
| [e] mechanisms are in place to remove and address improper posting of CUI. || Artifact || Incident response process, web design/update/modification SOP etc.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Awareness and Training (AT) ==&lt;br /&gt;
=== AT.L2-3.2.1 – Role-Based Risk Awareness ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AT.L2-3.2.1_Details|&#039;&#039;&#039;AT.L2-3.2.1&#039;&#039;&#039;]] Ensure that managers, systems administrators, and users of organizational systems are made aware of the security risks associated with their activities and of the applicable policies, standards, and procedures related to the security of those systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] security risks associated with organizational activities involving CUI are identified. || Document || Policy of Security Awareness Training; Security Awareness Training Briefing.&lt;br /&gt;
|-&lt;br /&gt;
| [b] policies, standards, and procedures related to the security of the system are identified. || Document || Acceptable Use Policy, Policy/Procedures/Instruction related to the security of the system.&lt;br /&gt;
|-&lt;br /&gt;
| [c] managers, systems administrators, and users of the system are made aware of the security risks associated with their activities. || Artifact || Security Training Brief, training records.&lt;br /&gt;
|-&lt;br /&gt;
| [d] managers, systems administrators, and users of the system are made aware of the applicable policies, standards, and procedures related to the security of the system. || Artifact || Policies, standards and procedures for employees within training (completed training report).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AT.L2-3.2.2 – Role-Based Training ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AT.L2-3.2.2_Details|&#039;&#039;&#039;AT.L2-3.2.2&#039;&#039;&#039;]] Ensure that personnel are trained to carry out their assigned information security-related duties and responsibilities.|-&lt;br /&gt;
|-&lt;br /&gt;
| [a] information security-related duties, roles, and responsibilities are defined. || Document || Policy/Procedures/Instruction, Job Role Matrix, Position Descriptions, User Roles.&lt;br /&gt;
|-&lt;br /&gt;
| [b] information security-related duties, roles, and responsibilities are assigned to designated personnel. || Artifact || Screenshot of breakout of different roles/permissions assigned to individuals (i.e. ActiveDirectory); Privilege Access Agreement.&lt;br /&gt;
|-&lt;br /&gt;
| [c] personnel are adequately trained to carry out their assigned information security-related duties, roles, and responsibilities. || Artifact || Screenshot of tool and/or training specifying security specific roles, duties and responsibilities; Screenshot of required certifications (i.e. Sec+, CISSP).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AT.L2-3.2.3 – Insider Threat Awareness ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AT.L2-3.2.3_Details|&#039;&#039;&#039;AT.L2-3.2.3&#039;&#039;&#039;]] Provide security awareness training on recognizing and reporting potential indicators of insider threat.&lt;br /&gt;
|-&lt;br /&gt;
| [a] potential indicators associated with insider threats are identified. || Document || Insidert Threat Policy/Procedures/Instruction; Insider Threat Training/Briefing.&lt;br /&gt;
|-&lt;br /&gt;
| [b] security awareness training on recognizing and reporting potential indicators of insider threat is provided to managers and employees. || Artifact || Screenshot of training records showing completion of Insider Threat training, emails showing completion of Insider Threat training, Screenshot of certificate showing completion with individual&#039;s name.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Audit and Accountability (AU) ==&lt;br /&gt;
=== AU.L2-3.3.1 – System Auditing ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AU.L2-3.3.1_Details|&#039;&#039;&#039;AU.L2-3.3.1&#039;&#039;&#039;]] Create and retain system audit logs and records to the extent needed to enable the monitoring, analysis, investigation, and reporting of unlawful or unauthorized system activity.&lt;br /&gt;
|-&lt;br /&gt;
| [a] audit logs needed (i.e., event types to be logged) to enable the monitoring, analysis, investigation, and reporting of unlawful or unauthorized system activity are specified. || Document || SSP, policy, or auditing and logging process that defines specific types of events to be logged.&lt;br /&gt;
|-&lt;br /&gt;
| [b] the content of audit records needed to support monitoring, analysis, investigation, and reporting of unlawful or unauthorized system activity is defined. || Document || SSP, policy, or auditing and logging process that defines specific content of audit records/files.&lt;br /&gt;
|-&lt;br /&gt;
| [c] audit records are created (generated). || Screen Share || Screen share of tool that shows logs are generated for all systems.&lt;br /&gt;
|-&lt;br /&gt;
| [d] audit records, once created, contain the defined content. || Screen Share || Screen share of tool that shows logs contain defined content as defined in SSP, policy, or procedures.&lt;br /&gt;
|-&lt;br /&gt;
| [e] retention requirements for audit records are defined. || Document || SSP, Polocy, or Auditing and logging process that describes how long records are kept.&lt;br /&gt;
|-&lt;br /&gt;
| [f] audit records are retained as defined. || Screen Share || Screen share of tool that shows records and audit content retained at a minimum as defined.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AU.L2-3.3.2 – User Accountability ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AU.L2-3.3.2_Details|&#039;&#039;&#039;AU.L2-3.3.2&#039;&#039;&#039;]] Ensure that the actions of individual system users can be uniquely traced to those users so they can be held accountable for their actions.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the content of the audit records needed to support the ability to uniquely trace users to their actions is defined. || Document || SSP, policy, or process that defines actions traced back to individuals.&lt;br /&gt;
|-&lt;br /&gt;
| [b] audit records, once created, contain the defined content. || Screen Share || Screen share of tool that shows audit records traced to specific users/roles.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AU.L2-3.3.3 – Event Review ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AU.L2-3.3.3_Details|&#039;&#039;&#039;AU.L2-3.3.3&#039;&#039;&#039;]] Review and update logged events.&lt;br /&gt;
|-&lt;br /&gt;
| [a] a process for determining when to review logged events is defined. || Document || SSP, policy, or documented process that shows frequency of when to review types of logged events.&lt;br /&gt;
|-&lt;br /&gt;
| [b] event types being logged are reviewed in accordance with the defined review process. || Artifact || Evidence through a documented method such as meeting minutes, CAB minutes, etc. of log sources and log events being logged at the defined frequency.&lt;br /&gt;
|-&lt;br /&gt;
| [c] event types being logged are updated based on the review. || Artifact || Evidence of implementation based on the results of the review of logged events/sources through a ticket, meeting minutes, or screen share of the tool that shows changes implemented (finetuning).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AU.L2-3.3.4 – Audit Failure Alerting ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AU.L2-3.3.4_Details|&#039;&#039;&#039;AU.L2-3.3.4&#039;&#039;&#039;]] Alert in the event of an audit logging process failure.&lt;br /&gt;
|-&lt;br /&gt;
| [a] personnel or roles to be alerted in the event of an audit logging process failure are identified. || Document || SSP, policy, or procedure that shows who needs to be notified in case of an audit failure.&lt;br /&gt;
|-&lt;br /&gt;
| [b] types of audit logging process failures for which alert will be generated are defined. || Document || SSP, policy, or procedure that shows what types of failure will generate notifications.&lt;br /&gt;
|-&lt;br /&gt;
| [c] identified personnel or roles are alerted in the event of an audit logging process failure. || Artifact || Artifact such as email or ticket that shows the identified personnel were alerted of any audit/logging process failure as defined.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AU.L2-3.3.5 – Audit Correlation ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AU.L2-3.3.5_Details|&#039;&#039;&#039;AU.L2-3.3.5&#039;&#039;&#039;]] Correlate audit record review, analysis, and reporting processes for investigation and response to indications of unlawful, unauthorized, suspicious, or unusual activity.&lt;br /&gt;
|-&lt;br /&gt;
| [a] audit record review, analysis, and reporting processes for investigation and response to indications of unlawful, unauthorized, suspicious, or unusual activity are defined. || Document || SSP, policy, or procedure covering audit logging, monitoring, and reporting.&lt;br /&gt;
|-&lt;br /&gt;
| [b] defined audit record review, analysis, and reporting processes are correlated. || Artifact || Artifact showing an audit event and the resultant corrective action or actions to the event; this can be a Help Desk ticket, meeting notes, or a change control board items showing the event and any corrective action taken.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AU.L2-3.3.6 – Reduction &amp;amp; Reporting ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AU.L2-3.3.6_Details|&#039;&#039;&#039;AU.L2-3.3.6&#039;&#039;&#039;]] Provide audit record reduction and report generation to support on-demand analysis and reporting.&lt;br /&gt;
|-&lt;br /&gt;
| [a] an audit record reduction capability that supports on-demand analysis is provided. || Screen Share || Screen share of the logging environment where an event can be selected and traced back to a specific device, or dashboard showing realtime event analysis.&lt;br /&gt;
|-&lt;br /&gt;
| [b] a report generation capability that supports on-demand reporting is provided. || Screen Share || Screen share showing the generation of an on demand report.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AU.L2-3.3.7 – Authoritative Time Source ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AU.L2-3.3.7_Details|&#039;&#039;&#039;AU.L2-3.3.7&#039;&#039;&#039;]] Provide a system capability that compares and synchronizes internal system clocks with an authoritative source to generate time stamps for audit records.&lt;br /&gt;
|-&lt;br /&gt;
| [a] internal system clocks are used to generate time stamps for audit records. || Screen Share || Screen share showing the NTP settings of a windows, Unix, Linux device; a screen share showing the NTP settings of network appliances.&lt;br /&gt;
|-&lt;br /&gt;
| [b] an authoritative source with which to compare and synchronize internal system clocks is specified. || Document || SSP or policy indicating that devices need to be synched to a local authoritative time device that is synched with an authoritative time service.&lt;br /&gt;
|-&lt;br /&gt;
| [c] internal system clocks used to generate time stamps for audit records are compared to and synchronized with the specified authoritative time source. || Screen Share || Screen share showing device logging appliance time is point to the appropriate authoritative time server.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AU.L2-3.3.8 – Audit Protection ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AU.L2-3.3.8_Details|&#039;&#039;&#039;AU.L2-3.3.8&#039;&#039;&#039;]] Protect audit information and audit logging tools from unauthorized access, modification, and deletion.&lt;br /&gt;
|-&lt;br /&gt;
| [a] audit information is protected from unauthorized access. || Screen Share || Screen share showing operating system permissions on the audit folders being restricted to appropriate users.&lt;br /&gt;
|-&lt;br /&gt;
| [b] audit information is protected from unauthorized modification. || Screen Share || Screen share showing operating system permissions on the audit folders being restricted to appropriate users.&lt;br /&gt;
|-&lt;br /&gt;
| [c] audit information is protected from unauthorized deletion. || Screen Share || Screen share showing operating system permissions on the audit folders being restricted to appropriate users.&lt;br /&gt;
|-&lt;br /&gt;
| [d] audit logging tools are protected from unauthorized access. || Screen Share || Artifact showing access permissions in the SIEM tool.&lt;br /&gt;
|-&lt;br /&gt;
| [e] audit logging tools are protected from unauthorized modification. || Screen Share || Artifact showing update permissions in the SIEM tool.&lt;br /&gt;
|-&lt;br /&gt;
| [f] audit logging tools are protected from unauthorized deletion. || Screen Share || Artifact showing delete permissions in the SIEM tool.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AU.L2-3.3.9 – Audit Management ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AU.L2-3.3.9_Details|&#039;&#039;&#039;AU.L2-3.3.9&#039;&#039;&#039;]] Limit management of audit logging functionality to a subset of privileged users.&lt;br /&gt;
|-&lt;br /&gt;
| [a] a subset of privileged users granted access to manage audit logging functionality is defined. || Document || SSP or policy indicating which users or groups have access to audit logs.&lt;br /&gt;
|-&lt;br /&gt;
| [b] management of audit logging functionality is limited to the defined subset of privileged users. || Screen Share || Artifact showing SIEM or OS folder permissions (this should be limited to the assigned users or groups); artifact showing an ACL setting in SIEM tool in regards to logs.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Configuration Management (CM) ==&lt;br /&gt;
=== CM.L2-3.4.1 – System Baselining ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_CM.L2-3.4.1_Details|&#039;&#039;&#039;CM.L2-3.4.1&#039;&#039;&#039;]] Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles.&lt;br /&gt;
|-&lt;br /&gt;
| [a] a baseline configuration is established. || Document || Documentation showing or explaining standard imaging process (how standard images are deployed and where  they are stored).&lt;br /&gt;
|-&lt;br /&gt;
| [b] the baseline configuration includes hardware, software, firmware, and documentation. || Artifact || Screenshot of repository of where images are maintained and information relating to hardware, software, and firmware.&lt;br /&gt;
|-&lt;br /&gt;
| [c] the baseline configuration is maintained (reviewed and updated) throughout the system development life cycle. || Artifact || Screenshot/evidence displaying management of baseline configurations (how often they are being managed as stated).&lt;br /&gt;
|-&lt;br /&gt;
| [d] a system inventory is established. || Document || Screenshot/evidence displaying inventory listing of approved products for use.&lt;br /&gt;
|-&lt;br /&gt;
| [e] the system inventory includes hardware, software, firmware, and documentation. || Artifact || Screeenshot/evidence displaying inventory listing of approved products and versions permitted for use.&lt;br /&gt;
|-&lt;br /&gt;
| [f] the inventory is maintained (reviewed and updated) throughout the system development life cycle. || Artifact || Screeenshot/evidence displaying management of baseline configurations (How often and are they being managed as stated.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== CM.L2-3.4.2 – Security Configuration Enforcement ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_CM.L2-3.4.2_Details|&#039;&#039;&#039;CM.L2-3.4.2&#039;&#039;&#039;]] Establish and enforce security configuration settings for information technology products employed in organizational systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] security configuration settings for information technology products employed in the system are established and included in the baseline configuration. || Document || Documentation explaining methodology used by organization to create secure baselines (STIGs, benchmarks).&lt;br /&gt;
|-&lt;br /&gt;
| [b] security configuration settings for information technology products employed in the system are enforced. || Artifact || Evidence of tool/s used to enforce security configurations to ensure images used are free from modification unless authorized.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== CM.L2-3.4.3 – System Change Management ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_CM.L2-3.4.3_Details|&#039;&#039;&#039;CM.L2-3.4.3&#039;&#039;&#039;]] Track, review, approve or disapprove, and log changes to organizational systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] changes to the system are tracked. || Artifact || Evidence of IT Service Management tool / process used to track system changes.&lt;br /&gt;
|-&lt;br /&gt;
| [b] changes to the system are reviewed. || Artifact || Evidence of IT Service Management tool / process used to review system changes.&lt;br /&gt;
|-&lt;br /&gt;
| [c] changes to the system are approved or disapproved. || Artifact || Evidence of IT Service Management tool / process used to approve/disapprove system changes.&lt;br /&gt;
|-&lt;br /&gt;
| [d] changes to the system are logged. || Artifact || Evidence of IT Service Management tool / process used to log system changes.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== CM.L2-3.4.4 – Security Impact Analysis ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_CM.L2-3.4.4_Details|&#039;&#039;&#039;CM.L2-3.4.4&#039;&#039;&#039;]] Analyze the security impact of changes prior to implementation.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the security impact of changes to the system is analyzed prior to implementation. || Artifact || Document explaining that security impact analysis of proposed changes to a system is conducted prior to implementation.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== CM.L2-3.4.5 – Access Restrictions for Change ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_CM.L2-3.4.5_Details|&#039;&#039;&#039;CM.L2-3.4.5&#039;&#039;&#039;]] Define, document, approve, and enforce physical and logical access restrictions associated with changes to organizational systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] physical access restrictions associated with changes to the system are defined. || Document || Document explaining the process of how physical access restrictions are defined for an individuals ability to make system changes.&lt;br /&gt;
|-&lt;br /&gt;
| [b] physical access restrictions associated with changes to the system are documented. || Document || Document explaining the process of how physical access restrictions are defined for an individuals ability to make system changes are documented; access request process.&lt;br /&gt;
|-&lt;br /&gt;
| [c] physical access restrictions associated with changes to the system are approved. || Artifact || Evidence of process of how physical access to systems are granted (i.e. physical access request sample).&lt;br /&gt;
|-&lt;br /&gt;
| [d] physical access restrictions associated with changes to the system are enforced. || Physical Review || Evidence of process of how physical access to systems are enforced (physical access system).&lt;br /&gt;
|-&lt;br /&gt;
| [e] logical access restrictions associated with changes to the system are defined. || Document || Document explaining the process of how logical access restrictions are defined for an individual&#039;s ability to make system changes.&lt;br /&gt;
|-&lt;br /&gt;
| [f] logical access restrictions associated with changes to the system are documented. || Document || Document explaining the process of how logical access restrictions are defined for an individual&#039;s ability to make system changes are documented.&lt;br /&gt;
|-&lt;br /&gt;
| [g] logical access restrictions associated with changes to the system are approved. || Artifact || Evidence of process of how logical access to systems are granted.&lt;br /&gt;
|-&lt;br /&gt;
| [h] logical access restrictions associated with changes to the system are enforced. || Artifact || Evidence of process of how logical access to systems are enforced.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== CM.L2-3.4.6 – Least Functionality ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_CM.L2-3.4.6_Details|&#039;&#039;&#039;CM.L2-3.4.6&#039;&#039;&#039;]] Employ the principle of least functionality by configuring organizational systems to provide only essential capabilities.&lt;br /&gt;
|-&lt;br /&gt;
| [a] essential system capabilities are defined based on the principle of least functionality. || Document || Documentation explaining how systems are configured to utilize the principle of least functionality for designated users.&lt;br /&gt;
|-&lt;br /&gt;
| [b] the system is configured to provide only the defined essential capabilities. || Screen Share || Evidence displaying how systems are configured to utilize the principle of least functionality for designated users; disabled service settings, accepted standards for hardening (CIS benchmarks, etc.).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== CM.L2-3.4.7 – Nonessential Functionality ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_CM.L2-3.4.7_Details|&#039;&#039;&#039;CM.L2-3.4.7&#039;&#039;&#039;]] Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services.&lt;br /&gt;
|-&lt;br /&gt;
| [a] essential programs are defined. || Document || Documented essential programs specified; build documents; software center; SSP.&lt;br /&gt;
|-&lt;br /&gt;
| [b] the use of nonessential programs is defined. || Document || Documented listing of nonessential programs (whatever is NOT specified in [a]); AUP/User Agreement may identify nonessential use/programs.&lt;br /&gt;
|-&lt;br /&gt;
| [c] the use of nonessential programs is restricted, disabled, or prevented as defined. || Screen Share || Tool used to restrict nonessential programs displays restrictions as defined (McAfee ePO settings, Carbon Black rules, etc.).&lt;br /&gt;
|-&lt;br /&gt;
| [d] essential functions are defined. || Document || Documented essential functions are specified.&lt;br /&gt;
|-&lt;br /&gt;
| [e] the use of nonessential functions is defined. || Document || Documented nonessential functions are specified.&lt;br /&gt;
|-&lt;br /&gt;
| [f] the use of nonessential functions is restricted, disabled, or prevented as defined. || Screen Share || Tool used to restrict essential/nonessential functions displays restrictions as defined.&lt;br /&gt;
|-&lt;br /&gt;
| [g] essential ports are defined. || Document || Documented essential ports are specified.&lt;br /&gt;
|-&lt;br /&gt;
| [h] the use of nonessential ports is defined. || Document || Documented nonessential ports functions are specified.&lt;br /&gt;
|-&lt;br /&gt;
| [i] the use of nonessential ports is restricted, disabled, or prevented as defined. || Screen Share || Tool used to restrict essential/nonessential ports displays restrictions as defined (FW rules; McAfee; GPO, etc.).&lt;br /&gt;
|-&lt;br /&gt;
| [j] essential protocols are defined. || Document || Documented essential protocols are specified.&lt;br /&gt;
|-&lt;br /&gt;
| [k] the use of nonessential protocols is defined. || Document || Documented nonessential protocols functions are specified.&lt;br /&gt;
|-&lt;br /&gt;
| [l] the use of nonessential protocols is restricted, disabled, or prevented as defined. || Screen Share || Tool used to restrict essential/nonessential protocols displays restrictions as defined (FW rules; GPO, etc.).&lt;br /&gt;
|-&lt;br /&gt;
| [m] essential services are defined. || Document || Documented essential services specified.&lt;br /&gt;
|-&lt;br /&gt;
| [n] the use of nonessential services is defined. || Document || Documented nonessential services functions are specified.&lt;br /&gt;
|-&lt;br /&gt;
| [o] the use of nonessential services is restricted, disabled, or prevented as defined. || Screen Share || Tool used to restrict essential/nonessential services displays restrictions as defined.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== CM.L2-3.4.8 – Application Execution Policy ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_CM.L2-3.4.8_Details|&#039;&#039;&#039;CM.L2-3.4.8&#039;&#039;&#039;]] Apply deny-by-exception (blacklisting) policy to prevent the use of unauthorized software or deny-all, permit-by-exception (whitelisting) policy to allow the execution of authorized software.&lt;br /&gt;
|-&lt;br /&gt;
| [a] a policy specifying whether whitelisting or blacklisting is to be implemented is specified. || Document || Documentation explaining whitelisting or blacklisting process.&lt;br /&gt;
|-&lt;br /&gt;
| [b] the software allowed to execute under whitelisting or denied use under blacklisting is specified. || Document || Documentation explaining whitelisting or blacklisting process for software.&lt;br /&gt;
|-&lt;br /&gt;
| [c] whitelisting to allow the execution of authorized software or blacklisting to prevent the use of unauthorized software is implemented as specified. || Screen Share || Tool used for whitelisting or blacklisting for software shows capability of restricting/authorizing software (Carbon Black dashboard, &amp;quot;SW Store&amp;quot;, web proxies, DNS Blackhole, etc.).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== CM.L2-3.4.9 – User-Installed Software ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_CM.L2-3.4.9_Details|&#039;&#039;&#039;CM.L2-3.4.9&#039;&#039;&#039;]] Control and monitor user-installed software.&lt;br /&gt;
|-&lt;br /&gt;
| [a] a policy for controlling the installation of software by users is established. || Document || Documented software authorization process or methodology for approval.&lt;br /&gt;
|-&lt;br /&gt;
| [b] installation of software by users is controlled based on the established policy. || Screen Share || Evidence that approval/restriction in installation of software by authorized personnel is implemented as specified (AUP, GPO, etc.).&lt;br /&gt;
|-&lt;br /&gt;
| [c] installation of software by users is monitored. || Screen Share || Evidence that installation of software by authorized personnel is monitored (SCCM groups, SW Center, etc.).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Identification and Authentication (IA) ==&lt;br /&gt;
=== IA.L2-3.5.1 – Identification [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IA.L2-3.5.1_Details|&#039;&#039;&#039;IA.L2-3.5.1&#039;&#039;&#039;]] Identify information system users, processes acting on behalf of users, or devices.&lt;br /&gt;
|-&lt;br /&gt;
| [a] system users are identified. || Document || Based on what is defined in their documentation (SSP, AUP, Policy, SOP), request to see a sample of non-privileged/privileged users in AD OU group (overlaps with 3.1.1 and 3.1.5).&lt;br /&gt;
|-&lt;br /&gt;
| [b] processes acting on behalf of users are identified. || Document || Based on what is defined in their documentation (SSP, AUP, Policy, SOP), request to see a sample of service accounts in AD OU group (overlaps with 3.1.1 and 3.1.5).&lt;br /&gt;
|-&lt;br /&gt;
| [c] devices accessing the system are identified. || Document || Based on what is defined in their documentation (SSP, AUP, Policy, SOP), request to see a sample of domain-joined workstation &amp;amp; servers in AD OU group (overlaps with 3.1.1 and 3.1.5).  For network devices, request screen share/artifact to show how they are identified on the enterprise network.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IA.L2-3.5.2 – Authentication [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IA.L2-3.5.2_Details|&#039;&#039;&#039;IA.L2-3.5.2&#039;&#039;&#039;]] Authenticate (or verify) the identities of those users, processes, or devices, as a prerequisite to allowing access to organizational information systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the identity of each user is authenticated or verified as a prerequisite to system access. || Screen Share || If the user logs in with non-privileged account during other demoes and then a privileged account, then this should be satisfied.  If screen share is unavailable, request logs to show successful and unsuccessful login by privileged and non-privilged users.&lt;br /&gt;
|-&lt;br /&gt;
| [b] the identity of each process acting on behalf of a user is authenticated or verified as a prerequisite to system access. || Screen Share || Request a log that shows successful/unsuccessful service account trying to log on to company&#039;s asset.&lt;br /&gt;
|-&lt;br /&gt;
| [c] the identity of each device accessing or connecting to the system is authenticated or verified as a prerequisite to system access. || Screen Share || Request a log that shows domain-joined workstation/server authenticating to AD (focus on the MAC/IP address/hostname).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IA.L2-3.5.3 – Multifactor Authentication ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IA.L2-3.5.3_Details|&#039;&#039;&#039;IA.L2-3.5.3&#039;&#039;&#039;]] Use multifactor authentication for local and network access to privileged accounts and for network access to non-privileged accounts.&lt;br /&gt;
|-&lt;br /&gt;
| [a] privileged accounts are identified. || Screen Share|| Based on what is defined in their documentation, request to see a sample of privileged users in AD OU group.  Overlaps with 3.1.5.  Screenshot/screen share to show implementation is enforced.&lt;br /&gt;
|-&lt;br /&gt;
| [b] multifactor authentication is implemented for local access to privileged accounts. || Document || SSP, AUP, Policy, SOP that defines that MFA is needed for privileged local access.&lt;br /&gt;
|-&lt;br /&gt;
| [c] multifactor authentication is implemented for network access to privileged accounts. || Screen Share || Within the MFA implementation mechanism, show that privileged users are forced to use MFA;  Screenshot/Screen share to show implementation is enforced.&lt;br /&gt;
|-&lt;br /&gt;
| [d] multifactor authentication is implemented for network access to non-privileged accounts. || Screen Share || Within the MFA implementation mechanism, show that non-privileged users are forced to use MFA; Screenshot/Screen share to show implementation is enforced.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IA.L2-3.5.4 – Replay-Resistant Authentication ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IA.L2-3.5.4_Details|&#039;&#039;&#039;IA.L2-3.5.4&#039;&#039;&#039;]] Employ replay-resistant authentication mechanisms for network access to privileged and non-privileged accounts.&lt;br /&gt;
|-&lt;br /&gt;
| [a] replay-resistant authentication mechanisms are implemented for network account access to privileged and non-privileged accounts. || Screen Share || Show the GPO setting that enforces Kerberos within AD.  If MFA is used, show the implementation to enforce replay resistant techniques.  For non-windows, show the technical solution to enforce replay resistant attacks.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IA.L2-3.5.5 – Identifier Reuse ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IA.L2-3.5.5_Details|&#039;&#039;&#039;IA.L2-3.5.5&#039;&#039;&#039;]] Prevent reuse of identifiers for a defined period.&lt;br /&gt;
|-&lt;br /&gt;
| [a] a period within which identifiers cannot be reused is defined. || Document || SSP, policies, or SOP that defines identifier reuse.&lt;br /&gt;
|-&lt;br /&gt;
| [b] reuse of identifiers is prevented within the defined period. || Screen Share || Show the GPO setting/technical solution that enforces what is defined in policy/documentation (this can be automated or manual process; screen share/artifacts can be presented to satisfy this requirement.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IA.L2-3.5.6 – Identifier Handling ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IA.L2-3.5.6_Details|&#039;&#039;&#039;IA.L2-3.5.6&#039;&#039;&#039;]] Disable identifiers after a defined period of inactivity.&lt;br /&gt;
|-&lt;br /&gt;
| [a] a period of inactivity after which an identifier is disabled is defined. || Document || SSP, policy that defines the period of inactivity after which an identifier is disabled.&lt;br /&gt;
|-&lt;br /&gt;
| [b] identifiers are disabled after the defined period of inactivity. || Screen Share || Screen share AD or similar tool supporting directory-based identity-related services for disabled accounts (can be done by hand or script).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IA.L2-3.5.7 – Password Complexity ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IA.L2-3.5.7_Details|&#039;&#039;&#039;IA.L2-3.5.7&#039;&#039;&#039;]] Enforce a minimum password complexity and change of characters when new passwords are created.&lt;br /&gt;
|-&lt;br /&gt;
| [a] password complexity requirements are defined. || Document || SSP, policy that defines password complexity requirements.&lt;br /&gt;
|-&lt;br /&gt;
| [b] password change of character requirements are defined. || Document || SSP, policy that defines change of character requirements are defined.&lt;br /&gt;
|-&lt;br /&gt;
| [c] minimum password complexity requirements as defined are enforced when new passwords are created. || Screen Share || Screen share of AD or similar directory-based identity-related service tool to show complexity requirements.&lt;br /&gt;
|-&lt;br /&gt;
| [d] minimum password change of character requirements as defined are enforced when new passwords are created. || Screen Share || Screen share of Group Policy configuration or similar tool providing centralized management and configuration of operating systems, applications, and users&#039; settings to show that characters must be changed.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IA.L2-3.5.8 – Password Reuse ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IA.L2-3.5.8_Details|&#039;&#039;&#039;IA.L2-3.5.8&#039;&#039;&#039;]] Prohibit password reuse for a specified number of generations.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the number of generations during which a password cannot be reused is specified. || Document || SSP, policy that specifies the number of generations during which a password cannot be reused is specified.&lt;br /&gt;
|-&lt;br /&gt;
| [b] reuse of passwords is prohibited during the specified number of generations. || Screen Share || Screen share Group Policy or similar tool providing centralized management and configuration of operating systems, applications, and users&#039; settings in a directory-based identity-related service tool&#039;s configuration to show reuse of passwords is prohibited.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IA.L2-3.5.9 – Temporary Passwords ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IA.L2-3.5.9_Details|&#039;&#039;&#039;IA.L2-3.5.9&#039;&#039;&#039;]] Allow temporary password use for system logons with an immediate change to a permanent password.&lt;br /&gt;
|-&lt;br /&gt;
| [a] an immediate change to a permanent password is required when a temporary password is used for system logon. || Screen Share || Screen share of Group Policy or similar tool providing centralized management and configuration of operating systems, applications, and users&#039; settings in a directory-based identity-related service tool&#039;s configuration to show &amp;quot;change password at first logon.&amp;quot;&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IA.L2-3.5.10 – Cryptographically-Protected Passwords ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IA.L2-3.5.1_Details|&#039;&#039;&#039;IA.L2-3.5.1&#039;&#039;&#039;]] Store and transmit only cryptographically-protected passwords.&lt;br /&gt;
|-&lt;br /&gt;
| [a] passwords are cryptographically protected in storage. || Screen Share || Screen share Group Policy or similar tool providing centralized management and configuration of operating systems, applications, and users&#039; settings in a directory-based identity-related service tool&#039;s configuration that Kerberos, or a similar network authentication protocol that works on the basis of tickets to allow nodes communicating over a non-secure network to prove their identity to one another in a secure manner, is enabled.&lt;br /&gt;
|-&lt;br /&gt;
| [b] passwords are cryptographically protected in transit. || Screen Share || Screen share Group Policy or similar tool providing centralized management and configuration of operating systems, applications, and users&#039; settings in a directory-based identity-related service tool&#039;s configuration that Kerberos, or a similar network authentication protocol that works on the basis of tickets to allow nodes communicating over a non-secure network to prove their identity to one another in a secure manner, is enabled.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IA.L2-3.5.11 – Obscure Feedback ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IA.L2-3.5.10_Details|&#039;&#039;&#039;IA.L2-3.5.10&#039;&#039;&#039;]] Obscure feedback of authentication information.&lt;br /&gt;
|-&lt;br /&gt;
| [a] authentication information is obscured during the authentication process. || Screen Share || Screen share of Group Policy or similar tool providing centralized management and configuration of operating systems, applications, and users&#039; settings in a directory-based identity-related service tool&#039;s configuration to show that passwords are obscured.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Incident Response (IR) ==&lt;br /&gt;
=== IR.L2-3.6.1 – Incident Handling ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IR.L2-3.6.1_Details|&#039;&#039;&#039;IR.L2-3.6.1&#039;&#039;&#039;]] Establish an operational incident-handling capability for organizational systems that includes preparation, detection, analysis, containment, recovery, and user response activities.&lt;br /&gt;
|-&lt;br /&gt;
| [a] an operational incident-handling capability is established. || Document || Incident Response SOP/Plan.&lt;br /&gt;
|-&lt;br /&gt;
| [b] the operational incident-handling capability includes preparation. || Document || Incident Response SOP/Plan, prior incident report, training, COOP plan.&lt;br /&gt;
|-&lt;br /&gt;
| [c] the operational incident-handling capability includes detection. || Document || Incident Response SOP/Plan; definition of tools used to detect; artifacts showing tools used; prior incident report.&lt;br /&gt;
|-&lt;br /&gt;
| [d] the operational incident-handling capability includes analysis. || Document || Incident Response SOP/Plan; Definition of tools used to analyze potential incidents; artifacts showing tools used for analysis; prior incident report.&lt;br /&gt;
|-&lt;br /&gt;
| [e] the operational incident-handling capability includes containment. || Document || Incident Response SOP/Plan; isolation/quarantine process; user training.&lt;br /&gt;
|-&lt;br /&gt;
| [f] the operational incident-handling capability includes recovery. || Document || Incident Response SOP/Plan; COOP Plan; prior incident reports, re-baselining impacted devices.&lt;br /&gt;
|-&lt;br /&gt;
| [g] the operational incident-handling capability includes user response. || Document || Incident Response SOP/Plan; user awareness training; Help Desk process.&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IR.L2-3.6.2 – Incident Reporting ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IR.L2-3.6.2_Details|&#039;&#039;&#039;IR.L2-3.6.2&#039;&#039;&#039;]] Track, document, and report incidents to designated officials and/or authorities both internal and external to the organization.&lt;br /&gt;
|-&lt;br /&gt;
| [a] incidents are tracked. || Artifact || Incident Response SOP/Plan; ITSM artifact; technical implementation for incident tracking.&lt;br /&gt;
|-&lt;br /&gt;
| [b] incidents are documented. || Artifact || Incident Response SOP/Plan; ITSM artifact; technical implementation for incident tracking.&lt;br /&gt;
|-&lt;br /&gt;
| [c] authorities to whom incidents are to be reported are identified. || Document || Incident Response SOP/Plan.&lt;br /&gt;
|-&lt;br /&gt;
| [d] organizational officials to whom incidents are to be reported are identified. || Document || Incident Response SOP/Plan.&lt;br /&gt;
|-&lt;br /&gt;
| [e] identified authorities are notified of incidents. || Screen Share || Prior incident report; DIBNET login; prior email notifications.&lt;br /&gt;
|-&lt;br /&gt;
| [f] identified organizational officials are notified of incidents. || Artifact || Prior incident report; prior email notifications; tabletop exercises.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IR.L2-3.6.3 – Incident Response Testing ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IR.L2-3.6.3_Details|&#039;&#039;&#039;IR.L2-3.6.3&#039;&#039;&#039;]] Test the organizational incident response capability.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the incident response capability is tested. || Artifact || Incident response table top/scheduled or unscheduled test or penetration test.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Maintenance (MA) ==&lt;br /&gt;
=== MA.L2-3.7.1 – Perform Maintenance ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MA.L2-3.7.1_Details|&#039;&#039;&#039;MA.L2-3.7.1&#039;&#039;&#039;]] Perform maintenance on organizational systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] system maintenance is performed. || Artifact || Establish typical maintenance activities (HVAC, UPS, power distribution, generators, copier maintenance) that are performed; maintenance agreements or contracts detailing these types of activities are acceptable; interview responses should be considered.  This requirement should not be confused with 3.14.1 - report, remediate, and correct system flaws in a timely manner (patch management).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MA.L2-3.7.2 – System Maintenance Control ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MA.L2-3.7.2_Details|&#039;&#039;&#039;MA.L2-3.7.2&#039;&#039;&#039;]] Provide controls on the tools, techniques, mechanisms, and personnel used to conduct system maintenance.&lt;br /&gt;
|-&lt;br /&gt;
| [a] tools used to conduct system maintenance are controlled. || Artifact || Tools may largely depend on the assessed environment; discussion examples include network diagnostic and monitoring tools (including hardware and software); artifacts could demonstrate secured locations/areas for these tools (photos) or checkout sheets/rosters (documents) depicting responsible personnel and the dates/times of checkout.&lt;br /&gt;
|-&lt;br /&gt;
| [b] techniques used to conduct system maintenance are controlled. || Artifact || Processes for scheduling, performing, documenting, reviewing, approving, and monitoring maintenance and repairs for the information system.&lt;br /&gt;
|-&lt;br /&gt;
| [c] mechanisms used to conduct system maintenance are controlled. || Artifact || Processes for scheduling, performing, documenting, reviewing, approving, and monitoring maintenance and repairs for the information system.&lt;br /&gt;
|-&lt;br /&gt;
| [d] personnel used to conduct system maintenance are controlled. || Physical Review || Screenshot of who is authorized to conduct maintenance; maintenance personnel training program.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MA.L2-3.7.3 – Equipment Sanitization ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MA.L2-3.7.3_Details|&#039;&#039;&#039;MA.L2-3.7.3&#039;&#039;&#039;]] Ensure equipment removed for off-site maintenance is sanitized of any CUI.&lt;br /&gt;
|-&lt;br /&gt;
| [a] equipment to be removed from organizational spaces for off-site maintenance is sanitized of any CUI. || Artifact || Document or artifact; record if equipment sanitized; categories of sanitization/destruction defined; sanitization procedural document.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MA.L2-3.7.4 – Media Inspection ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MA.L2-3.7.4_Details|&#039;&#039;&#039;MA.L2-3.7.4&#039;&#039;&#039;]] Check media containing diagnostic and test programs for malicious code before the media are used in organizational systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] media containing diagnostic and test programs are checked for malicious code before being used in organizational systems that process, store, or transmit CUI. || Artifact || Screenshot of diagnostic/test program being used (such as Symantec and McAfee on access scans…).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MA.L2-3.7.5 – Nonlocal Maintenance ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MA.L2-3.7.5_Details|&#039;&#039;&#039;MA.L2-3.7.5&#039;&#039;&#039;]] Require multifactor authentication to establish nonlocal maintenance sessions via external network connections and terminate such connections when nonlocal maintenance is complete.&lt;br /&gt;
|-&lt;br /&gt;
| [a] multifactor authentication is used to establish nonlocal maintenance sessions via external network connections. || Screen Share || Describe MFA used to remote from external service to organizational systems for maintenance and screenshot of MFA (3.5.3)(points associated with admin).&lt;br /&gt;
|-&lt;br /&gt;
| [b] nonlocal maintenance sessions established via external network connections are terminated when nonlocal maintenance is complete. || Screen Share || Screenshot VPN session timeout.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MA.L2-3.7.6 – Maintenance Personnel ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MA.L2-3.7.6_Details|&#039;&#039;&#039;MA.L2-3.7.6&#039;&#039;&#039;]] Supervise the maintenance activities of maintenance personnel without required access authorization.&lt;br /&gt;
|-&lt;br /&gt;
| [a] maintenance personnel without required access authorization are supervised during maintenance activities. || Document || System maintenance policy; list of authorized personnel; maintenance records or, contracts/SLAs; WebEx.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Media Protection (MP) ==&lt;br /&gt;
=== MP.L2-3.8.1 – Media Protection ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MP.L2-3.8.1_Details|&#039;&#039;&#039;MP.L2-3.8.1&#039;&#039;&#039;]] Protect (i.e., physically control and securely store) system media containing CUI, both paper and digital.&lt;br /&gt;
|-&lt;br /&gt;
| [a] paper media containing CUI is physically controlled. || Document || Policy showing CUI paper media is controlled; artifact showing who has access; artifacts/records of  inventories conducted; media check out procedures (i.e. file cabinets, encryption, password protection).&lt;br /&gt;
|-&lt;br /&gt;
| [b] digital media containing CUI is physically controlled. || Document || Policy showing CUI digital media is controlled; artifact showing who has access; artifacts/records of inventories conducted; media check out procedures (i.e. file cabinets, external drives, USBs, encryption, password protection).&lt;br /&gt;
|-&lt;br /&gt;
| [c] paper media containing CUI is securely stored. || Physical Review || Check out/sign out sheets; possible photo of storage container/video walk through of storage area; badge reader logs or access lists for keys for secured areas; interview response considered (i.e. file cabinets,  encryption, password protection).&lt;br /&gt;
|-&lt;br /&gt;
| [d] digital media containing CUI is securely stored. || Physical Review || Check out/sign out sheets; possible photo of storage container/video walk through of storage area; badge reader logs or access lists for keys for secured areas; interview response considered (i.e. file cabinets, external drives, USBs, encryption, password protection).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MP.L2-3.8.2 – Media Access ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MP.L2-3.8.2_Details|&#039;&#039;&#039;MP.L2-3.8.2&#039;&#039;&#039;]] Limit access to CUI on system media to authorized users.&lt;br /&gt;
|-&lt;br /&gt;
| [a] access to CUI on system media is limited to authorized users. || Artifact || Document describing how CUI is limited AND artifact showing principle of least access is implemented.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MP.L2-3.8.3 – Media Disposal [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MP.L2-3.8.3_Details|&#039;&#039;&#039;MP.L2-3.8.3&#039;&#039;&#039;]] Sanitize or destroy information system media containing Federal Contract Information before disposal or release for reuse.&lt;br /&gt;
|-&lt;br /&gt;
| [a] system media containing CUI is sanitized or destroyed before disposal. || Document || Policy or artifact of media destruction logs; certificates of destruction; SLAs or contracts.&lt;br /&gt;
|-&lt;br /&gt;
| [b] system media containing CUI is sanitized before it is released for reuse. || Document || Policy or artifact describing method to sanitize, software used (i.e. DoD Wipe, ShredIT and Iron Mountain; Blancco; GDisk, DBAN).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MP.L2-3.8.4 – Media Markings ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MP.L2-3.8.4_Details|&#039;&#039;&#039;MP.L2-3.8.4&#039;&#039;&#039;]] Mark media with necessary CUI markings and distribution limitations.&lt;br /&gt;
|-&lt;br /&gt;
| [a] media containing CUI is marked with applicable CUI markings. || Physical Review || Document or artifact showing CUI markings (i.e. labeling standards ).&lt;br /&gt;
|-&lt;br /&gt;
| [b] media containing CUI is marked with distribution limitations. || Physical Review || Document or artifact showing distro limitations (i.e. labeling standards ).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MP.L2-3.8.5 – Media Accountability ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MP.L2-3.8.5_Details|&#039;&#039;&#039;MP.L2-3.8.5&#039;&#039;&#039;]] Control access to media containing CUI and maintain accountability for media during transport outside of controlled areas.&lt;br /&gt;
|-&lt;br /&gt;
| [a] access to media containing CUI is controlled. || Document || Policy, artifact of audit logs showing tracking, Access Control Lists, records of transport activities (i.e. USB drives, CDs, chain of custody.&lt;br /&gt;
|-&lt;br /&gt;
| [b] accountability for media containing CUI is maintained during transport outside of controlled areas. || Artifact || Artifact of audit logs showing tracking, Access Control Lists, records of transport activities (i.e. USB drives, CDs; chain of custody.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MP.L2-3.8.6 – Portable Storage Encryption ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MP.L2-3.8.6_Details|&#039;&#039;&#039;MP.L2-3.8.6&#039;&#039;&#039;]] Implement cryptographic mechanisms to protect the confidentiality of CUI stored on digital media during transport unless otherwise protected by alternative physical safeguards.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the confidentiality of CUI stored on digital media is protected during transport using cryptographic mechanisms or alternative physical safeguards. || Artifact || Artifact showing crypto mechanisms used to protect (are they FIPS 140-2 [13.11]); artifact showing what alternative physical safeguards are in place (i.e. encryption; BitLocker; McAfee ).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MP.L2-3.8.7 – Removable Media ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MP.L2-3.8.7_Details|&#039;&#039;&#039;MP.L2-3.8.7&#039;&#039;&#039;]] Control the use of removable media on system components.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the use of removable media on system components is controlled. || Artifact || Policy showing if removable media is allowed; writable removable media is restricted; tracking artifacts; what tools are used (i.e. Carbon Black, Crowd Strike, GPO, Zoho Desktop Central); procedure/process describing what happens if it is lost; what mechanisms are in place to control/restrict removable media (i.e. Active Directory Groups and Group Policy artifact showing restriction).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MP.L2-3.8.8 – Shared Media ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MP.L2-3.8.8_Details|&#039;&#039;&#039;MP.L2-3.8.8&#039;&#039;&#039;]] Prohibit the use of portable storage devices when such devices have no identifiable owner.ASSESSMENT OBJECTIVES&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [a] the use of portable storage devices is prohibited when such devices have no identifiable owner. || Artifact || Policy and/or artifact showing company stance on portable storage devices if there is no owner (are personal USB devices allowed or are they company-issued; artifact showing alerts if device is connected to network (i.e. external HDD, Carbon Black, Crowd Strike, GPO, Zoho Desktop Central.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MP.L2-3.8.9 – Protect Backups ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MP.L2-3.8.9_Details|&#039;&#039;&#039;MP.L2-3.8.9&#039;&#039;&#039;]] Protect the confidentiality of backup CUI at storage locations.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the confidentiality of backup CUI is protected at storage locations. || Artifact || Policy on system backups; artifact showing media labeling; artifact showing encyption (is it FIPS 140-2 [13.11]); Access Control List artifact (i.e. backup tapes, Tivoli Storage Manager).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Personnel Security (PS) ==&lt;br /&gt;
=== PS.L2-3.9.1 – Screen Individuals ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_PS.L2-3.9.1_Details|&#039;&#039;&#039;PS.L2-3.9.1&#039;&#039;&#039;]] Screen individuals prior to authorizing access to organizational systems containing CUI.&lt;br /&gt;
|-&lt;br /&gt;
| [a] individuals are screened prior to authorizing access to organizational systems containing CUI. || Artifact || Screenshot of records of screened personnel/background checks.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== PS.L2-3.9.2 – Personnel Actions ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_PS.L2-3.9.2_Details|&#039;&#039;&#039;PS.L2-3.9.2&#039;&#039;&#039;]] Ensure that organizational systems containing CUI are protected during and after personnel actions such as terminations and transfers.&lt;br /&gt;
|-&lt;br /&gt;
| [a] a policy and/or process for terminating system access and any credentials coincident with personnel actions is established. || Document || Personnel security policy/procedures/instruction; Access control policy/procedure/instruction.&lt;br /&gt;
|-&lt;br /&gt;
| [b] system access and credentials are terminated consistent with personnel actions such as termination or transfer. || Artifact || Screenshot of records of personnel transfer and termination actions.&lt;br /&gt;
|-&lt;br /&gt;
| [c] the system is protected during and after personnel transfer actions. || Artifact || Completed outprocessing checklist.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Physical Protection (PE) ==&lt;br /&gt;
=== PE.L2-3.10.1 – Limit Physical Access [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_PE.L2-3.10.1_Details|&#039;&#039;&#039;PE.L2-3.10.1&#039;&#039;&#039;]] Limit physical access to organizational information systems, equipment, and the respective operating environments to authorized individuals.&lt;br /&gt;
|-&lt;br /&gt;
| [a] authorized individuals allowed physical access are identified. || Artifact || Authorized personnel (names) access list.&lt;br /&gt;
|-&lt;br /&gt;
| [b] physical access to organizational systems is limited to authorized individuals. || Physical Review || Badge reader logs, audit logs, and/or card swipe test.&lt;br /&gt;
|-&lt;br /&gt;
| [c] physical access to equipment is limited to authorized individuals. || Physical Review || Badge reader logs, audit logs, and/or card swipe test.&lt;br /&gt;
|-&lt;br /&gt;
| [d] physical access to operating environments is limited to authorized. || Physical Review || Badge reader logs, audit logs, and/or card swipe test.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== PE.L2-3.10.2 – Monitor Facility ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_PE.L2-3.10.2_Details|&#039;&#039;&#039;PE.L2-3.10.2&#039;&#039;&#039;]] Protect and monitor the physical facility and support infrastructure for organizational systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the physical facility where organizational systems reside is protected. || Physical Review || Physical security measures and barriers into the physical facility (cameras/locks/gates/guards, etc.).&lt;br /&gt;
|-&lt;br /&gt;
| [b] the support infrastructure for organizational systems is protected. || Physical Review || Physical barriers to entries into computer spaces, server rooms, etc.&lt;br /&gt;
|-&lt;br /&gt;
| [c] the physical facility where organizational systems reside is monitored. || Physical Review || Audit logs/how the physical facility is being monitored (cameras/access system/guards, etc.).&lt;br /&gt;
|-&lt;br /&gt;
| [d] the support infrastructure for organizational systems is monitored. || Physical Review || Audit logs/how the physical facility is being monitored (cameras/access system/guards, etc.).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== PE.L2-3.10.3 – Escort Visitors [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_PE.L2-3.10.3_Details|&#039;&#039;&#039;PE.L2-3.10.3&#039;&#039;&#039;]] Escort visitors and monitor visitor activity.&lt;br /&gt;
|-&lt;br /&gt;
| [a] visitors are escorted. || Physical Review || Policy/procedures/instruction on methodology for handling non-authorized personnel (entry to exit).&lt;br /&gt;
|-&lt;br /&gt;
| [b] visitor activity is monitored. || Physical Review || Policy/procedures/instructio on methodology for handling non-authorized personnel (entry to exit).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== PE.L2-3.10.4 – Physical Access Logs [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_PE.L2-3.10.4_Details|&#039;&#039;&#039;PE.L2-3.10.4&#039;&#039;&#039;]] Maintain audit logs of physical access.&lt;br /&gt;
|-&lt;br /&gt;
| [a] audit logs of physical access are maintained. || Artifact || Log or report from badging system.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== PE.L2-3.10.5 – Manage Physical Access [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_PE.L2-3.10.5_Details|&#039;&#039;&#039;PE.L2-3.10.5&#039;&#039;&#039;]] Control and manage physical access devices.&lt;br /&gt;
|-&lt;br /&gt;
| [a] physical access devices are identified. || Document || Physical access control systems description, guard force contract/policy, key locks, logical systems specifications, etc.&lt;br /&gt;
|-&lt;br /&gt;
| [b] physical access devices are controlled. || Physical Review || Inventory records of physical access control devices (e.g. keys, locks, card readers, locks, etc.).&lt;br /&gt;
|-&lt;br /&gt;
| [c] physical access devices are managed. || Physical Review || List of security safeguards controlling access to the facility (e.g. cameras, monitoring by guards, isolation of IT systems equiment and or system components).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== PE.L2-3.10.6 – Alternative Work Sites ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_PE.L2-3.10.6_Details|&#039;&#039;&#039;PE.L2-3.10.6&#039;&#039;&#039;]] Enforce safeguarding measures for CUI at alternate work sites.&lt;br /&gt;
|-&lt;br /&gt;
| [a] safeguarding measures for CUI are defined for alternate work sites. || Document || Telework agreement, Acceptable Use Policy and SOP for alternate work locations; user security training validation which includes physical/logical/technical protections of system at alternate work sites.&lt;br /&gt;
|-&lt;br /&gt;
| [b] safeguarding measures for CUI are enforced for alternate work sites. || Artifact || Monitoring/audit log of user activity and logical/physical/technical mechanisms in place to preclude unauthorized activity (telework agreement , AUP?).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Risk Assessment (RA) ==&lt;br /&gt;
=== RA.L2-3.11.1 – Risk Assessments ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_RA.L2-3.11.1_Details|&#039;&#039;&#039;RA.L2-3.11.1&#039;&#039;&#039;]] Periodically assess the risk to organizational operations (including mission, functions, image, or reputation), organizational assets, and individuals, resulting from the operation of organizational systems and the associated processing, storage, or transmission of CUI.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the frequency to assess risk to organizational operations, organizational assets, and individuals is defined. || Document || Risk assessment policy.&lt;br /&gt;
|-&lt;br /&gt;
| [b] risk to organizational operations, organizational assets, and individuals resulting from the operation of an organizational system that processes, stores, or transmits CUI is assessed with the defined frequency. || Artifact || Copy of last risk assessment done within defined frequency.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== RA.L2-3.11.2 – Vulnerability Scan ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_RA.L2-3.11.2_Details|&#039;&#039;&#039;RA.L2-3.11.2&#039;&#039;&#039;]] Scan for vulnerabilities in organizational systems and applications periodically and when new vulnerabilities affecting those systems and applications are identified.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the frequency to scan for vulnerabilities in organizational systems and applications is defined. || Document || Policy/procedures/instruction addressing vulnerability scanning records.&lt;br /&gt;
|-&lt;br /&gt;
| [b] vulnerability scans are performed on organizational systems with the defined frequency. || Screen Share || System configuration settings of vulnerability scanning scheduling and vulnerability scan results of systems within defined frequency.&lt;br /&gt;
|-&lt;br /&gt;
| [c] vulnerability scans are performed on applications with the defined frequency. || Screen Share || System configuration settings of vulnerability scanning scheduling and vulnerability scan results of applications within defined frequency.&lt;br /&gt;
|-&lt;br /&gt;
| [d] vulnerability scans are performed on organizational systems when new vulnerabilities are identified. || Screen Share || View signatures in scanning tool/ad hoc scan performed as a result.&lt;br /&gt;
|-&lt;br /&gt;
| [e] vulnerability scans are performed on applications when new vulnerabilities are identified. || Screen Share || View signatures in scanning tool/ad hoc scan performed as a result.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== RA.L2-3.11.3 – Vulnerability Remediation ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_RA.L2-3.11.3_Details|&#039;&#039;&#039;RA.L2-3.11.3&#039;&#039;&#039;]] Remediate vulnerabilities in accordance with risk assessments.&lt;br /&gt;
|-&lt;br /&gt;
| [a] vulnerabilities are identified. || Artifact || Scan results showing vulnerabilities identified.&lt;br /&gt;
|-&lt;br /&gt;
| [b] vulnerabilities are remediated in accordance with risk assessments. || Artifact || Screenshot/document of scan results of remediated vulnerabilities in accordance to risk assessments.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Security Assessment (CA) ==&lt;br /&gt;
=== CA.L2-3.12.1 – Security Control Assessment ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_CA.L2-3.12.1_Details|&#039;&#039;&#039;CA.L2-3.12.1&#039;&#039;&#039;]] Periodically assess the security controls in organizational systems to determine if the controls are effective in their application.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the frequency of security control assessments is defined. || Document || SSP.&lt;br /&gt;
|-&lt;br /&gt;
| [b] security controls are assessed with the defined frequency to determine if the controls are effective in their application. || Artifact || Copy of last security control assessment done within defined frequency.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== CA.L2-3.12.2 – Operational Plan of Action ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_CA.L2-3.12.2_Details|&#039;&#039;&#039;CA.L2-3.12.2&#039;&#039;&#039;]] Develop and implement plans of action designed to correct deficiencies and reduce or eliminate vulnerabilities in organizational systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] deficiencies and vulnerabilities to be addressed by the plan of action are identified. || Artifact || Plan of Action (POA).&lt;br /&gt;
|-&lt;br /&gt;
| [b] a plan of action is developed to correct identified deficiencies and reduce or eliminate identified vulnerabilities. || Artifact || Plan of Action (POA).&lt;br /&gt;
|-&lt;br /&gt;
| [c] the plan of action is implemented to correct identified deficiencies and reduce or eliminate identified vulnerabilities. || Artifact || Plan of Action (POA)/previously completed POAs.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== CA.L2-3.12.3 – Security Control Monitoring ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_CA.L2-3.12.3_Details|&#039;&#039;&#039;CA.L2-3.12.3&#039;&#039;&#039;]] Monitor security controls on an ongoing basis to ensure the continued effectiveness of the controls.&lt;br /&gt;
|-&lt;br /&gt;
| [a] security controls are monitored on an ongoing basis to ensure the continued effectiveness of those controls. || Artifact || Collection of risk assessment results, internal or third-party audits/security assessments and/or continuous monitoring reports/alerts (SIEM tool, etc.).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== CA.L2-3.12.4 – System Security Plan ====&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_CA.L2-3.12.4_Details|&#039;&#039;&#039;CA.L2-3.12.4&#039;&#039;&#039;]] Develop, document, and periodically update system security plans that describe system boundaries, system environments of operation, how security requirements are implemented, and the relationships with or connections to other systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] a system security plan is developed. || Document || SSP.&lt;br /&gt;
|-&lt;br /&gt;
| [b] the system boundary is described and documented in the system security plan. || Document || SSP and any supporting documentation.&lt;br /&gt;
|-&lt;br /&gt;
| [c] the system environment of operation is described and documented in the system security plan. || Document || SSP and any supporting documentation.&lt;br /&gt;
|-&lt;br /&gt;
| [d] the security requirements identified and approved by the designated authority as non-applicable are identified. || Document || SSP and required adjudication from DoD CIO.&lt;br /&gt;
|-&lt;br /&gt;
| [e] the method of security requirement implementation is described and documented in the system security plan. || Document || SSP and any supporting documentation.&lt;br /&gt;
|-&lt;br /&gt;
| [f] the relationship with or connection to other systems is described and documented in the system security plan. || Document || SSP and any supporting documentation.&lt;br /&gt;
|-&lt;br /&gt;
| [g] the frequency to update the system security plan is defined. || Document || SSP.&lt;br /&gt;
|-&lt;br /&gt;
| [h] system security plan is updated with the defined frequency. || Document || SSP/any previous versions.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== System and Communications Protection (SC) ==&lt;br /&gt;
=== SC.L2-3.13.1 – Boundary Protection [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.1_Details|&#039;&#039;&#039;SC.L2-3.13.1&#039;&#039;&#039;]] Monitor, control, and protect organizational communications (i.e., information transmitted or received by organizational information systems) at the external boundaries and key internal boundaries of the information systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the external system boundary is defined. || Document || SSP, network diagrams, CUI flow, cloud provider FedRAMP Moderate.&lt;br /&gt;
|-&lt;br /&gt;
| [b] key internal system boundaries are defined. || Document || SSP, network diagrams, CUI flow.&lt;br /&gt;
|-&lt;br /&gt;
| [c] communications are monitored at the external system boundary. || Screen Share || SSP, logging server, boundary device configurations, monitoring policy.&lt;br /&gt;
|-&lt;br /&gt;
| [d] communications are monitored at key internal boundaries. || Screen Share || SSP, logging server, boundary device configurations, monitoring policy.&lt;br /&gt;
|-&lt;br /&gt;
| [e] communications are controlled at the external system boundary. || Screen Share || SSP, boundary device configurations, ACL, subnets, DMZ.&lt;br /&gt;
|-&lt;br /&gt;
| [f] communications are controlled at key internal boundaries. || Screen Share || SSP, boundary device configurations, ACL, subnets.&lt;br /&gt;
|-&lt;br /&gt;
| [g] communications are protected at the external system boundary. || Screen Share || Configurations for IPS/IDS, email gateway, VLAN, proxy, firewall, malware protection, DNS, TSL.&lt;br /&gt;
|-&lt;br /&gt;
| [h] communications are protected at key internal boundaries. || Screen Share || Configurations for IPS/IDS, VLAN, firewall, malware protection, SSL.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.2 – Security Engineering ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.2_Details|&#039;&#039;&#039;SC.L2-3.13.2&#039;&#039;&#039;]] Employ architectural designs, software development techniques, and systems engineering principles that promote effective information security within organizational systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] architectural designs that promote effective information security are identified. || Document || SSP, config management policy, network diagram, CCB minutes, enterprise architecture process.&lt;br /&gt;
|-&lt;br /&gt;
| [b] software development techniques that promote effective information security are identified. || Document || SSP, config management policy, SDLC, CCB minutes.&lt;br /&gt;
|-&lt;br /&gt;
| [c] systems engineering principles that promote effective information security are identified. || Document || SSP, config management policy, CCB minutes, security architecture engineering.&lt;br /&gt;
|-&lt;br /&gt;
| [d] identified architectural designs that promote effective information security are employed. || Artifact || CCB minutes, Network diagrams and configurations, Project Plans.&lt;br /&gt;
|-&lt;br /&gt;
| [e] identified software development techniques that promote effective information security are employed. || Artifact || CCB minutes, SDLC, code scanner results, code management tracking.&lt;br /&gt;
|-&lt;br /&gt;
| [f] identified systems engineering principles that promote effective information security are employed. || Artifact || CCB minutes, configuration management, ITSM, patch management, lifecycle replacement processes.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.3 – Role Separation ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.3_Details|&#039;&#039;&#039;SC.L2-3.13.3&#039;&#039;&#039;]] Separate user functionality from system management functionality.&lt;br /&gt;
|-&lt;br /&gt;
| [a] user functionality is identified. || Document || SSP, AUP.&lt;br /&gt;
|-&lt;br /&gt;
| [b] system management functionality is identified. || Document || SSP, Privileged Account Agreement.&lt;br /&gt;
|-&lt;br /&gt;
| [c] user functionality is separated from system management functionality. || Screen Share || Active Directory, Jump Boxes, GPO, VM, RDP.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.4 – Shared Resource Control ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.4_Details|&#039;&#039;&#039;SC.L2-3.13.4&#039;&#039;&#039;]] Prevent unauthorized and unintended information transfer via shared system resources.&lt;br /&gt;
|-&lt;br /&gt;
| [a] unauthorized and unintended information transfer via shared system resources is prevented. || Screen Share || SSP, OS configurations, Linux containers, system/media reuse policies, certificate management policies, media destruction policies, printer configs, VDI configuration.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
===  SC.L2-3.13.5 – Public-Access System Separation [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.5_Details|&#039;&#039;&#039;SC.L2-3.13.5&#039;&#039;&#039;]] Implement subnetworks for publicly accessible system components that are physically or logically separated from internal networks.&lt;br /&gt;
|-&lt;br /&gt;
| [a] publicly accessible system components are identified. || Document || SSP, network diagram, DMZ inventory/roles.&lt;br /&gt;
|-&lt;br /&gt;
| [b] subnetworks for publicly accessible system components are physically or logically separated from internal networks. || Artifact || Network diagram, IPAM, VLAN, DHCP, DMZ.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.6 – Network Communication by Exception ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.6_Details|&#039;&#039;&#039;SC.L2-3.13.6&#039;&#039;&#039;]] Deny network communications traffic by default and allow network communications traffic by exception (i.e., deny all, permit by exception).&lt;br /&gt;
|-&lt;br /&gt;
| [a] network communications traffic is denied by default. || Screen Share || Host and network firewall rules, SIEM logs, hit counts.&lt;br /&gt;
|-&lt;br /&gt;
| [b] network communications traffic is allowed by exception. || Screen Share || Host and network firewall rules, SIEM logs, hit counts.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.7 – Split Tunneling ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.7_Details|&#039;&#039;&#039;SC.L2-3.13.7&#039;&#039;&#039;]] Prevent remote devices from simultaneously establishing non-remote connections with organizational systems and communicating via some other connection to resources in external networks (i.e., split tunneling).&lt;br /&gt;
|-&lt;br /&gt;
| [a] remote devices are prevented from simultaneously establishing non-remote connections with the system and communicating via some other connection to resources in external networks (i.e., split tunneling). || Screen Share || VPN appliance/server configuration, endpoint VPN software configuration.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.8 – Data in Transit ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.8_Details|&#039;&#039;&#039;SC.L2-3.13.8&#039;&#039;&#039;]] Implement cryptographic mechanisms to prevent unauthorized disclosure of CUI during transmission unless otherwise protected by alternative physical safeguards.&lt;br /&gt;
|-&lt;br /&gt;
| [a] cryptographic mechanisms intended to prevent unauthorized disclosure of CUI are identified. || Document || SSP, PKI policies, configuration processes, config management, email attachment encryption policy, removable media policy, data at rest policy.&lt;br /&gt;
|-&lt;br /&gt;
| [b] alternative physical safeguards intended to prevent unauthorized disclosure of CUI are identified. || Document || SSP, physical security policy.&lt;br /&gt;
|-&lt;br /&gt;
| [c] either cryptographic mechanisms or alternative physical safeguards are implemented to prevent unauthorized disclosure of CUI during transmission. || Screen Share || TLS settings, SSL settings, VPN/Wireless Access Points/Mobile Devices cryptographic settings, ODBC connector settings, SAN configuration, IPSec/MPLS, backup configuration, physical security.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.9 – Connections Termination ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.9_Details|&#039;&#039;&#039;SC.L2-3.13.9&#039;&#039;&#039;]] Terminate network connections associated with communications sessions at the end of the sessions or after a defined period of inactivity.&lt;br /&gt;
|-&lt;br /&gt;
| [a] a period of inactivity to terminate network connections associated with communications sessions is defined. || Document || SSP, network communications policy.&lt;br /&gt;
|-&lt;br /&gt;
| [b] network connections associated with communications sessions are terminated at the end of the sessions. || Screen Share || VPN appliance/server logs, VPN configurations, web server configurations, firewall connection settings.&lt;br /&gt;
|-&lt;br /&gt;
| [c] network connections associated with communications sessions are terminated after the defined period of inactivity. || Screen Share || VPN appliance/server logs, VPN configurations, web server configurations, frewall connection settings.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.10 – Key Management ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.10_Details|&#039;&#039;&#039;SC.L2-3.13.10&#039;&#039;&#039;]] Establish and manage cryptographic keys for cryptography employed in organizational systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] cryptographic keys are established whenever cryptography is employed. || Artifact || SSP, PKI/certificate management policy, configuration management.&lt;br /&gt;
|-&lt;br /&gt;
| [b] cryptographic keys are managed whenever cryptography is employed. || Artifact || SSP, PKI/certificate management policy, configuration management, access control policy.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.11 – CUI Encryption ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.11_Details|&#039;&#039;&#039;SC.L2-3.13.11&#039;&#039;&#039;]] Employ FIPS-validated cryptography when used to protect the confidentiality of CUI.&lt;br /&gt;
|-&lt;br /&gt;
| [a] FIPS-validated cryptography is employed to protect the confidentiality of CUI. || Screen Share || VPN, wireless, mobile devices, client certificates, server certificates, disk encryption, Outlook plugin, external mail, backup media, ePO server, removable storage, SAN, file compression; look for FIPS mode enabled on appliances.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.12 – Collaborative Device Control ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.12_Details|&#039;&#039;&#039;SC.L2-3.13.12&#039;&#039;&#039;]] Prohibit remote activation of collaborative computing devices and provide indication of devices in use to users present at the device.&lt;br /&gt;
|-&lt;br /&gt;
| [a] collaborative computing devices are identified. || Document || SSP, network diagrams.&lt;br /&gt;
|-&lt;br /&gt;
| [b] collaborative computing devices provide indication to users of devices in use. || Physical Review || Physical inspection of device.&lt;br /&gt;
|-&lt;br /&gt;
| [c] remote activation of collaborative computing devices is prohibited. || Screen Share || Collaboration device configuration/console.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.13 – Mobile Code ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.13_Details|&#039;&#039;&#039;SC.L2-3.13.13&#039;&#039;&#039;]] Control and monitor the use of mobile code.&lt;br /&gt;
|-&lt;br /&gt;
| [a] use of mobile code is controlled. || Screen Share || GPO settings, malware protection, software agent configurations, software development policies, code scanners, MDM configuration, firewall/secure web gateway/proxy config.&lt;br /&gt;
|-&lt;br /&gt;
| [b] use of mobile code is monitored. || Screen Share || SIEM/console monitoring.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.14 – Voice over Internet Protocol ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.14_Details|&#039;&#039;&#039;SC.L2-3.13.14&#039;&#039;&#039;]] Control and monitor the use of Voice over Internet Protocol (VoIP) technologies.&lt;br /&gt;
|-&lt;br /&gt;
| [a] use of Voice over Internet Protocol (VoIP) technologies is controlled. || Artifact || VLAN, ACL, firewall config, VoIP gateway/condenser configuration.&lt;br /&gt;
|-&lt;br /&gt;
| [b] use of Voice over Internet Protocol (VoIP) technologies is monitored. || Artifact || SIEM/VoIP console monitoring, session border controller.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.15 – Communications Authenticity ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.15_Details|&#039;&#039;&#039;SC.L2-3.13.15&#039;&#039;&#039;]] Protect the authenticity of communications sessions.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the authenticity of communications sessions is protected. || Screen Share || SSL, TLS, SMB3, SFTP, IPSec, SSH, Kerberos configs, MPLS, Network Access Control.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.16 – Data at Rest ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.16_Details|&#039;&#039;&#039;SC.L2-3.13.16&#039;&#039;&#039;]] Protect the confidentiality of CUI at rest.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the confidentiality of CUI at rest is protected. || Artifact || Full disk encryption, removable media encryption, SAN encryption, digital backups, mobile device encryption, third party offsite backup storage, cloud virtualization encryption, physical media storage policies.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== System and Information Integrity (SI) ==&lt;br /&gt;
=== SI.L2-3.14.1 – Flaw Remediation [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SI.L2-3.14.1_Details|&#039;&#039;&#039;SI.L2-3.14.1&#039;&#039;&#039;]] Identify, report, and correct information and information system flaws in a timely manner.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the time within which to identify system flaws is specified. || Document || SSP, patch management policy.&lt;br /&gt;
|-&lt;br /&gt;
| [b] system flaws are identified within the specified time frame. || Screen Share || Vulnerability management scanner output and scan policy configuration.&lt;br /&gt;
|-&lt;br /&gt;
| [c] the time within which to report system flaws is specified. || Document || SSP, patch management policy.&lt;br /&gt;
|-&lt;br /&gt;
| [d] system flaws are reported within the specified time frame. || Screen Share || ITSM/trouble tickets, vulnerability management scanner output.&lt;br /&gt;
|-&lt;br /&gt;
| [e] the time within which to correct system flaws is specified. || Document || SSP, patch management policy.&lt;br /&gt;
|-&lt;br /&gt;
| [f] system flaws are corrected within the specified time frame. || Screen Share || Vulnerability management scanner output and scan policy configuration.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SI.L2-3.14.2 – Malicious Code ProTection [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SI.L2-3.14.2_Details|&#039;&#039;&#039;SI.L2-3.14.2&#039;&#039;&#039;]] Provide protection from malicious code at appropriate locations within organizational information systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] designated locations for malicious code protection are identified. || Document || SSP, system protection policy, network diagrams, security architecture documents.&lt;br /&gt;
|-&lt;br /&gt;
| [b] protection from malicious code at designated locations is provided. || Screen Share || Endpoint security settings, email/web proxy gateways, firewall, IPS sensor, MDM configuration, Network Access Control.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SI.L2-3.14.3 – Security Alerts &amp;amp; Advisories ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SI.L2-3.14.3_Details|&#039;&#039;&#039;SI.L2-3.14.3&#039;&#039;&#039;]] Monitor system security alerts and advisories and take action in response.&lt;br /&gt;
|-&lt;br /&gt;
| [a] response actions to system security alerts and advisories are identified. || Document || SSP, vulnerability management policy, Incident Response Plan.&lt;br /&gt;
|-&lt;br /&gt;
| [b] system security alerts and advisories are monitored. || Artifact || Threat intelligence subscriptions, email advisories.&lt;br /&gt;
|-&lt;br /&gt;
| [c] actions in response to system security alerts and advisories are taken. || Artifact || ITSM/trouble tickets, user notifications, updates to firewall/IPS, etc.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SI.L2-3.14.4 – Update Malicious Code Protection [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SI.L2-3.14.4_Details|&#039;&#039;&#039;SI.L2-3.14.4&#039;&#039;&#039;]] Update malicious code protection mechanisms when new releases are available.&lt;br /&gt;
|-&lt;br /&gt;
| [a] malicious code protection mechanisms are updated when new releases are available. || Screen Share || Antivirus console dashboard, firewall AV, Email gateway signatures,proxy, IPS updates.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SI.L2-3.14.5 – System &amp;amp; File Scanning [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SI.L2-3.14.5_Details|&#039;&#039;&#039;SI.L2-3.14.5&#039;&#039;&#039;]] Perform periodic scans of the information system and real-time scans of files from external sources as files are downloaded, opened, or executed.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the frequency for malicious code scans is defined. || Document || SSP, vulnerability management policy.&lt;br /&gt;
|-&lt;br /&gt;
| [b] malicious code scans are performed with the defined frequency. || Screen Share || Consoles for AV (endpoints, servers, and file shares), firewall, email gateway, proxy, IPS, MDM configurations.&lt;br /&gt;
|-&lt;br /&gt;
| [c] real-time malicious code scans of files from external sources as files are downloaded, opened, or executed are performed. || Screen Share || Consoles for AV (endpoints, servers, and file shares), firewall, email gateway, proxy, IPS, MDM configurations.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SI.L2-3.14.6 – Monitor Communications for Attacks ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SI.L2-3.14.6_Details|&#039;&#039;&#039;SI.L2-3.14.6&#039;&#039;&#039;]] Monitor organizational systems, including inbound and outbound communications traffic, to detect attacks and indicators of potential attacks.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the system is monitored to detect attacks and indicators of potential attacks. || Screen Share || Firewall, IPS, endpoint protection, SIEM alerts and reports.&lt;br /&gt;
|-&lt;br /&gt;
| [b] inbound communications traffic is monitored to detect attacks and indicators of potential attacks. || Screen Share || Firewall, IPS, endpoint protection, SIEM alerts and reports.&lt;br /&gt;
|-&lt;br /&gt;
| [c] outbound communications traffic is monitored to detect attacks and indicators of potential attacks. || Screen Share || Firewall, IPS, endpoint protection, SIEM alerts and reports.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SI.L2-3.14.7 – Identify Unauthorized Use ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SI.L2-3.14.7_Details|&#039;&#039;&#039;SI.L2-3.14.7&#039;&#039;&#039;]] Identify unauthorized use of organizational systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] authorized use of the system is defined. || Document || AUP, SSP.&lt;br /&gt;
|-&lt;br /&gt;
| [b] unauthorized use of the system is identified. || Artifact || SIEM logs, endpoint protection console, IPS, Firewall.&lt;br /&gt;
|}&lt;/div&gt;</summary>
		<author><name>David</name></author>
	</entry>
	<entry>
		<id>https://cmmcwiki.org/index.php?title=Evidence_Collection_Approach&amp;diff=1620</id>
		<title>Evidence Collection Approach</title>
		<link rel="alternate" type="text/html" href="https://cmmcwiki.org/index.php?title=Evidence_Collection_Approach&amp;diff=1620"/>
		<updated>2026-07-20T01:39:30Z</updated>

		<summary type="html">&lt;p&gt;David: /* AU.L2-3.3.3 – Event Review */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;CMMC assessments and certification require substantial evidence and documentation. The following tables outline general guidelines for collecting evidence to assess control requirements and objectives. While these guidelines provide a structured approach, they are not the only means of conducting an accurate assessment. Assessors should exercise professional judgment and may employ alternative methods appropriate to the specific organizational context and circumstances.&lt;br /&gt;
&lt;br /&gt;
Evidence collection approaches are defined as:&lt;br /&gt;
* &#039;&#039;&#039;Documentation&#039;&#039;&#039;: Tangible materials containing information over which an organization has authority, including all types of written records and their copies.&lt;br /&gt;
* &#039;&#039;&#039;Artifacts&#039;&#039;&#039;: Tangible, reviewable records directly resulting from a practice or process being performed by a system or by personnel executing their role within that practice, control, or process.&lt;br /&gt;
* &#039;&#039;&#039;Physical Review&#039;&#039;&#039;: Direct on-site observation and examination of evidence.&lt;br /&gt;
* &#039;&#039;&#039;Screen Share&#039;&#039;&#039;: Real-time remote observation of a user demonstrating a task or process via shared computer screen, sometimes called &amp;quot;over-the-shoulder&amp;quot; review.&lt;br /&gt;
&lt;br /&gt;
DISCLAIMER: Evidence requirements vary significantly across assessment types. &#039;&#039;&#039;The examples provided are illustrative only and should be tailored to meet the specific adequacy and sufficiency standards of your particular assessment context.&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
For inquiries and reporting errors on this wiki, please [mailto:support@cmmctoolkit.org contact us]. Thank you.&lt;br /&gt;
&lt;br /&gt;
== Access Control (AC) ==&lt;br /&gt;
=== AC.L2-3.1.1 – Authorized Access Control [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.1_Details|&#039;&#039;&#039;AC.L2-3.1.1&#039;&#039;&#039;]] Limit information system access to authorized users, processes acting on behalf of authorized users, or devices (including other information systems).&lt;br /&gt;
|-&lt;br /&gt;
| [a] authorized users are identified. || Document || Document defining account request, approval, provisioning.&lt;br /&gt;
|-&lt;br /&gt;
| [b] processes acting on behalf of authorized users are identified. || Document || Document defining account request, approval, provisioning.&lt;br /&gt;
|-&lt;br /&gt;
| [c] devices (and other systems) authorized to connect to the system are identified. || Document || Document defining account request, approval, provisioning.&lt;br /&gt;
|-&lt;br /&gt;
| [d] system access is limited to authorized users. || Screen Share || Screen share showing login requirements are enforced. Example of an unauthorized user denied (unauthorized username entered at login).&lt;br /&gt;
|-&lt;br /&gt;
| [e] system access is limited to processes acting on behalf of authorized users. || Screen Share || Screenshot showing that service accounts are assigned to authorized users only; no rogue accounts without an authorized user are active.&lt;br /&gt;
|-&lt;br /&gt;
| [f] system access is limited to authorized devices (including other systems). || Screen Share || Screen share showing that all devices running are authorized; no rogue devices on the network.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.2 – Transaction &amp;amp; Function Control [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.2_Details|&#039;&#039;&#039;AC.L2-3.1.2&#039;&#039;&#039;]] Limit information system access to the types of transactions and functions that authorized users are permitted to execute.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the types of transactions and functions that authorized users are permitted to execute are defined. || Document || SSP, AUP, or IAM document that defines what authorized users can execute.&lt;br /&gt;
|-&lt;br /&gt;
| [b] system access is limited to the defined types of transactions and functions for authorized users. || Screen Share || Screenshot of security roles in AD or IAM or other directory-based identity-related services tool that shows transactions are as defined in the SSP or IAM document; privileged and non-privileged accounts need to be defined and identified in the artifact; screenshot of a non-privileged user trying to execute a privileged function.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.3 – Control CUI Flow ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.3_Details|&#039;&#039;&#039;AC.L2-3.1.3&#039;&#039;&#039;]] Control the flow of CUI in accordance with approved authorizations.&lt;br /&gt;
|-&lt;br /&gt;
| [a] information flow control policies are defined. || Document || SSP or other document describing the control of CUI on the network.&lt;br /&gt;
|-&lt;br /&gt;
| [b] methods and enforcement mechanisms for controlling the flow of CUI are defined. || Document || Document that defines the networking devices that are on the CUI network and answers what measures are in place to control the flow. List of firewalls, border and internal layer 3 devices, IDS/IPS, DLP, that process CUI.&lt;br /&gt;
|-&lt;br /&gt;
| [c] designated sources and destinations (e.g., networks, individuals, and devices) for CUI within the system and between interconnected systems are identified. || Artifact || Network diagram, data flow diagram, external system connection diagrams, document describing the policies for CUI on the network; listing of VLANs and subnets where CUI is authorized; document must describe source and authorized destinations.&lt;br /&gt;
|-&lt;br /&gt;
| [d] authorizations for controlling the flow of CUI are defined. || Document || Document that defines how CUI is to be controlled, such as an InfoSec plan, and/or network management plan.&lt;br /&gt;
|-&lt;br /&gt;
| [e] approved authorizations for controlling the flow of CUI are enforced. || Screen Share || Screenshots of firewall rules, ACLs, etc.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.4 – Separation of Duties ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.4_Details|&#039;&#039;&#039;AC.L2-3.1.4&#039;&#039;&#039;]] Separate the duties of individuals to reduce the risk of malevolent activity without collusion.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the duties of individuals requiring separation are defined. || Document || Document, SSP, account management policy, defining separation of duties by person or role.&lt;br /&gt;
|-&lt;br /&gt;
| [b] responsibilities for duties that require separation are assigned to separate individuals. || Screen Share || Screenshot showing that separation of duties is enforced by showing admin accounts are assigned to different people based on role.&lt;br /&gt;
|-&lt;br /&gt;
| [c] access privileges that enable individuals to exercise the duties that require separation are granted to separate individuals. || Screen Share || Screen shot showing an example such as a security manager can not log into a network device and change ACLs, or network admins can not access security logs in the SIEM tool.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.5 – Least Privilege ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.5_Details|&#039;&#039;&#039;AC.L2-3.1.5&#039;&#039;&#039;]] Employ the principle of least privilege, including for specific security functions and privileged accounts.&lt;br /&gt;
|-&lt;br /&gt;
| [a] privileged accounts are identified. || Document || &amp;quot;SSP or policy (documentation) identify what is considered a privileged account.&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| [b] access to privileged accounts is authorized in accordance with the principle of least privilege. || Artifact || An artifact that identifies the least amount of permissions associated with different types of privileged accounts are approved.&lt;br /&gt;
|-&lt;br /&gt;
| [c] security functions are identified. || Document || &amp;quot;SSP or policy (documentation) identifies what is considered a security account.&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| [d] access to security functions is authorized in accordance with the principle of least privilege. || Artifact || Artifact(s) that identify the least amount of permissions associated with different types of security accounts are approved.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.6 – Non-Privileged Account Use ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.6_Details|&#039;&#039;&#039;AC.L2-3.1.6&#039;&#039;&#039;]] Use non-privileged accounts or roles when accessing nonsecurity functions.&lt;br /&gt;
|-&lt;br /&gt;
| [a] nonsecurity functions are identified. || Document || SSP or account management document, AUP, that defines non-security functions.&lt;br /&gt;
|-&lt;br /&gt;
| [b] users are required to use non-privileged accounts or roles when accessing nonsecurity functions. || Screen Share || Screenshot showing that a privileged user tried to use their admin account to access a non-security function, such as a browser or email (whatever is defined in their policy) and was blocked.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.7 – Privileged Functions ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.7_Details|&#039;&#039;&#039;AC.L2-3.1.7&#039;&#039;&#039;]] Prevent non-privileged users from executing privileged functions and capture the execution of such functions in audit logs.&lt;br /&gt;
|-&lt;br /&gt;
| [a] privileged functions are defined. || Document || SSP or policy (documentation) that defines privileged functions.&lt;br /&gt;
|-&lt;br /&gt;
| [b] non-privileged users are defined. || Document || SSP or policy (documentation) that defines non-privileged users.&lt;br /&gt;
|-&lt;br /&gt;
| [c] non-privileged users are prevented from executing privileged functions. || Screen Share || Screen share that shows that a non-privileged user is not allowed to complete a privileged function (installing software).&lt;br /&gt;
|-&lt;br /&gt;
| [d] the execution of privileged functions is captured in audit logs. || Screen Share || Screen share that shows logs being captured of the execution of privileged functions.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.8 – Unsuccessful Logon Attempts ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.8_Details|&#039;&#039;&#039;AC.L2-3.1.8&#039;&#039;&#039;]] Limit unsuccessful logon attempts.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the means of limiting unsuccessful logon attempts is defined. || Document || SSP or policy (documentation) showing unsuccessful logon attempts settings and or policy.&lt;br /&gt;
|-&lt;br /&gt;
| [b] the defined means of limiting unsuccessful logon attempts is implemented. || Artifact || Artifact showing GPO / Policy for limiting logon attempts.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.9 – Privacy &amp;amp; Security Notices ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.9_Details|&#039;&#039;&#039;AC.L2-3.1.9&#039;&#039;&#039;]] Provide privacy and security notices consistent with applicable CUI rules.&lt;br /&gt;
|-&lt;br /&gt;
| [a] privacy and security notices required by CUI-specified rules are identified, consistent, and associated with the specific CUI category. || Document || SSP or policy (documentation) showing CUI-specified rules are identified, consistent, and associated with the specific CUI category.&lt;br /&gt;
|-&lt;br /&gt;
| [b] privacy and security notices are displayed. || Artifact || Artifact that shows a consent banner or screen that a user sees as they log in to the system.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.10 – Session Lock ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.10_Details|&#039;&#039;&#039;AC.L2-3.1.10&#039;&#039;&#039;]] Use session lock with pattern-hiding displays to prevent access and viewing of data after a period of inactivity.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the period of inactivity after which the system initiates a session lock is defined. || Document || SSP or policy (documentation) that defines the period of inactivity and when a session lock is defined.&lt;br /&gt;
|-&lt;br /&gt;
| [b] access to the system and viewing of data is prevented by initiating a session lock after the defined period of inactivity. || Artifact || Artifact that shows the setting of session lock (GPO or system policy or similar solution addressing the controls supporting centralized management and configuration of operating systems, applications, and users&#039; settings for the working environment of user accounts and computer accounts).&lt;br /&gt;
|-&lt;br /&gt;
| [c] previously visible information is concealed via a pattern-hiding display after the defined period of inactivity. || Document || Screenshot of GPO setting and configuration settings, or similar solution addressing the controls supporting centralized management and configuration of operating systems, applications, and users&#039; settings for the working environment of user accounts and computer accounts.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.11 – Session Termination ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.11_Details|&#039;&#039;&#039;AC.L2-3.1.11&#039;&#039;&#039;]] Terminate (automatically) a user session after a defined condition.&lt;br /&gt;
|-&lt;br /&gt;
| [a] conditions requiring a user session to terminate are defined. || Document || SSP or policy (documentation) that defines the conditions requiring a user session to be terminated.&lt;br /&gt;
|-&lt;br /&gt;
| [b] a user session is automatically terminated after any of the defined conditions. || Screen Share || Screen share showing GPO / VPN Settings that show when a session would be terminated (Idle time, max connection time).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.12 – Control Remote Access ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.12_Details|&#039;&#039;&#039;AC.L2-3.1.12&#039;&#039;&#039;]] Monitor and control remote access sessions.&lt;br /&gt;
|-&lt;br /&gt;
| [a] remote access sessions are permitted. || Document || SSP or policy (documentation) that defines remote access sessions.&lt;br /&gt;
|-&lt;br /&gt;
| [b] the types of permitted remote access are identified. || Document || SSP or policy (documentation) that defines remote access is permitted.&lt;br /&gt;
|-&lt;br /&gt;
| [c] remote access sessions are controlled. || Screen Share || Screen share that shows how the remote access is controlled (access session, and or groups).&lt;br /&gt;
|-&lt;br /&gt;
| [d] remote access sessions are monitored. || Screen Share || Screen share that shows how remote sessions are monitored (logs).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.13 – Remote Access Confidentiality ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.13_Details|&#039;&#039;&#039;AC.L2-3.1.13&#039;&#039;&#039;]] Employ cryptographic mechanisms to protect the confidentiality of remote access sessions.&lt;br /&gt;
|-&lt;br /&gt;
| [a] cryptographic mechanisms to protect the confidentiality of remote access sessions are identified. || Document || SSP or policy (documentation) that discusses the CUI rules, consistent, and associated with the specific CUI category; FIPS Cert # of appliance or application.&lt;br /&gt;
|-&lt;br /&gt;
| [b] cryptographic mechanisms to protect the confidentiality of remote access sessions are implemented. || Screen Share || Screenshot of VPN concentration that shows encryption is on and enabled (point-to-point, etc.).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.14 – Remote Access Routing ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.14_Details|&#039;&#039;&#039;AC.L2-3.1.14&#039;&#039;&#039;]] Route remote access via managed access control points.&lt;br /&gt;
|-&lt;br /&gt;
| [a] managed access control points are identified and implemented. || Screen Share || Screen share that shows access control points (groups and/or users).&lt;br /&gt;
|-&lt;br /&gt;
| [b] remote access is routed through managed network access control points. || Screen Share || Screen share that shows access control points and how they are managed.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.15 – Privileged Remote Access ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.15_Details|&#039;&#039;&#039;AC.L2-3.1.15&#039;&#039;&#039;]] Authorize remote execution of privileged commands and remote access to security-relevant information.&lt;br /&gt;
|-&lt;br /&gt;
| [a] privileged commands authorized for remote execution are identified. || Document || SSP or policy (documentation) that defines what is authorized to be executed remotely and how that is handled.&lt;br /&gt;
|-&lt;br /&gt;
| [b] security-relevant information authorized to be accessed remotely is identified. || Document || SSP or policy (documentation) that defines what can be accessed remotely and what procedures are implemented to allow this (RDP, jump box).&lt;br /&gt;
|-&lt;br /&gt;
| [c] the execution of the identified privileged commands via remote access is authorized. || Artifact || Screen share that shows who has access to perform privileged commands a remotely (access groups for privileged accounts).&lt;br /&gt;
|-&lt;br /&gt;
| [d] access to the identified security-relevant information via remote access is authorized. || Artifact || Screen share that shows the routing of remote access and how it is monitored and how many locations (Firewall, VPN Concentrator).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.16 – Wireless Access Authorization ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.16_Details|&#039;&#039;&#039;AC.L2-3.1.16&#039;&#039;&#039;]] Authorize wireless access prior to allowing such connections.&lt;br /&gt;
|-&lt;br /&gt;
| [a] wireless access points are identified. || Document || SSP, network administration document.&lt;br /&gt;
|-&lt;br /&gt;
| [b] wireless access is authorized prior to allowing such connections. || Screen Share || Authorization profile(s) in Wireless Access Controller or Identity Manager (i.e. Cisco ISE).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.17 – Wireless Access Protection ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.17_Details|&#039;&#039;&#039;AC.L2-3.1.17&#039;&#039;&#039;]] Protect wireless access using authentication and encryption.&lt;br /&gt;
|-&lt;br /&gt;
| [a] wireless access to the system is protected using authentication. || Screen Share || Security page (or similar) of a Wireless Access Controller.&lt;br /&gt;
|-&lt;br /&gt;
| [b] wireless access to the system is protected using encryption. || Screen Share || Security page (or similar) of a Wireless Access Controller.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.18 – Mobile Device Connection ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.18_Details|&#039;&#039;&#039;AC.L2-3.1.18&#039;&#039;&#039;]] Control connection of mobile devices.&lt;br /&gt;
|-&lt;br /&gt;
| [a] mobile devices that process, store, or transmit CUI are identified. || Document || SSP, Mobile Device Policy.&lt;br /&gt;
|-&lt;br /&gt;
| [b] mobile device connections are authorized. || Artifact || Authorization profile(s) in Wireless Access Controller or Identity Manager (i.e. Cisco ISE).&lt;br /&gt;
|-&lt;br /&gt;
| [c] mobile device connections are monitored and logged. || Screen Share || Mobile device logs within the MDM, log intake (sources) configuration (within SIEM) showing MDM is feeding logs to the SIEM.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.19 – Encrypt CUI on Mobile ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.19_Details|&#039;&#039;&#039;AC.L2-3.1.19&#039;&#039;&#039;]] Encrypt CUI on mobile devices and mobile computing platforms.&lt;br /&gt;
|-&lt;br /&gt;
| [a] mobile devices and mobile computing platforms that process, store, or transmit CUI are identified. || Document || SSP, Mobile Device Policy.&lt;br /&gt;
|-&lt;br /&gt;
| [b] encryption is employed to protect CUI on identified mobile devices and mobile computing platforms. || Screen Share || Security policy page in MDM showing how encryption are enforced on mobile device. If no MDM or MDM doesn&#039;t enforce encryption, then validate if the devices used are on the list of devices with native FIPS approved validation.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.20 – External Connections [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.20_Details|&#039;&#039;&#039;AC.L2-3.1.20&#039;&#039;&#039;]] Verify and control/limit connections to and use of external information systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] connections to external systems are identified. || Document || SSP, Systems Interconnection Agreements, SLA.&lt;br /&gt;
|-&lt;br /&gt;
| [b] the use of external systems is identified. || Document || SSP, Systems Interconnection Agreements, SLA.&lt;br /&gt;
|-&lt;br /&gt;
| [c] connections to external systems are verified. || Artifact || SLA for external systems, memorandum for interconnection, information to prove that any cloud solution is at FedRAMP impact level of moderate or higher (i.e. license information, screenshot of AWS cloud dashboard, purchase order document).&lt;br /&gt;
|-&lt;br /&gt;
| [d] the use of external systems is verified. || Artifact || SLA for external systems, memorandum for interconnection, information to prove that any cloud solution is at FedRAMP impact level of moderate or higher (i.e. license information, screenshot of AWS cloud dashboard, purchase order document).&lt;br /&gt;
|-&lt;br /&gt;
| [e] connections to external systems are controlled/limited. || Screen Share || Firewall ruleset for controlling access to cloud service or external system.&lt;br /&gt;
|-&lt;br /&gt;
| [f] the use of external systems is controlled/limited. || Screen Share || Firewall ruleset for controlling access to cloud service or external system.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.21 – Portable Storage Use ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.21_Details|&#039;&#039;&#039;AC.L2-3.1.21&#039;&#039;&#039;]] Limit use of portable storage devices on external systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the use of portable storage devices containing CUI on external systems is identified and documented. || Document || SSP, Removable Media Policy, Acceptable Use Policy (with emphasis on portable media use).&lt;br /&gt;
|-&lt;br /&gt;
| [b] limits on the use of portable storage devices containing CUI on external systems are defined. || Document || SSP, Removable Media Policy, Acceptable Use Policy (with emphasis on portable media use).&lt;br /&gt;
|-&lt;br /&gt;
| [c] the use of portable storage devices containing CUI on external systems is limited as defined. || Document || SSP, Removable Media Policy, Acceptable Use Policy (with emphasis on portable media use).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.22 – Control Public Information [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.22_Details|&#039;&#039;&#039;AC.L2-3.1.22&#039;&#039;&#039;]] Control information posted or processed on publicly accessible information systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] individuals authorized to post or process information on publicly accessible systems are identified. || Document || SSP, Website Governance Plan, Information Release Document.&lt;br /&gt;
|-&lt;br /&gt;
| [b] procedures to ensure CUI is not posted or processed on publicly accessible systems are identified. || Document || SSP, Website Governance Plan, Information Release Document.&lt;br /&gt;
|-&lt;br /&gt;
| [c] a review process is in place prior to posting of any content to publicly accessible systems. || Artifact || &amp;quot;Information release approval process, i.e. chain of email communication from originator, approver, and final decision (may or may not include individual authorized to post); &lt;br /&gt;
SharePoint/electronic or paper form/ ticket system showing information flow between requestor and approver (may or may not include  individual authorized to post).&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| [d] content on publicly accessible systems is reviewed to ensure that it does not include CUI. || Artifact || Incident response process, web design/update/modification SOP etc.&lt;br /&gt;
|-&lt;br /&gt;
| [e] mechanisms are in place to remove and address improper posting of CUI. || Artifact || Incident response process, web design/update/modification SOP etc.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Awareness and Training (AT) ==&lt;br /&gt;
=== AT.L2-3.2.1 – Role-Based Risk Awareness ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AT.L2-3.2.1_Details|&#039;&#039;&#039;AT.L2-3.2.1&#039;&#039;&#039;]] Ensure that managers, systems administrators, and users of organizational systems are made aware of the security risks associated with their activities and of the applicable policies, standards, and procedures related to the security of those systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] security risks associated with organizational activities involving CUI are identified. || Document || Policy of Security Awareness Training; Security Awareness Training Briefing.&lt;br /&gt;
|-&lt;br /&gt;
| [b] policies, standards, and procedures related to the security of the system are identified. || Document || Acceptable Use Policy, Policy/Procedures/Instruction related to the security of the system.&lt;br /&gt;
|-&lt;br /&gt;
| [c] managers, systems administrators, and users of the system are made aware of the security risks associated with their activities. || Artifact || Security Training Brief, training records.&lt;br /&gt;
|-&lt;br /&gt;
| [d] managers, systems administrators, and users of the system are made aware of the applicable policies, standards, and procedures related to the security of the system. || Artifact || Policies, standards and procedures for employees within training (completed training report).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AT.L2-3.2.2 – Role-Based Training ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AT.L2-3.2.2_Details|&#039;&#039;&#039;AT.L2-3.2.2&#039;&#039;&#039;]] Ensure that personnel are trained to carry out their assigned information security-related duties and responsibilities.|-&lt;br /&gt;
|-&lt;br /&gt;
| [a] information security-related duties, roles, and responsibilities are defined. || Document || Policy/Procedures/Instruction, Job Role Matrix, Position Descriptions, User Roles.&lt;br /&gt;
|-&lt;br /&gt;
| [b] information security-related duties, roles, and responsibilities are assigned to designated personnel. || Artifact || Screenshot of breakout of different roles/permissions assigned to individuals (i.e. ActiveDirectory); Privilege Access Agreement.&lt;br /&gt;
|-&lt;br /&gt;
| [c] personnel are adequately trained to carry out their assigned information security-related duties, roles, and responsibilities. || Artifact || Screenshot of tool and/or training specifying security specific roles, duties and responsibilities; Screenshot of required certifications (i.e. Sec+, CISSP).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AT.L2-3.2.3 – Insider Threat Awareness ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AT.L2-3.2.3_Details|&#039;&#039;&#039;AT.L2-3.2.3&#039;&#039;&#039;]] Provide security awareness training on recognizing and reporting potential indicators of insider threat.&lt;br /&gt;
|-&lt;br /&gt;
| [a] potential indicators associated with insider threats are identified. || Document || Insidert Threat Policy/Procedures/Instruction; Insider Threat Training/Briefing.&lt;br /&gt;
|-&lt;br /&gt;
| [b] security awareness training on recognizing and reporting potential indicators of insider threat is provided to managers and employees. || Artifact || Screenshot of training records showing completion of Insider Threat training, emails showing completion of Insider Threat training, Screenshot of certificate showing completion with individual&#039;s name.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Audit and Accountability (AU) ==&lt;br /&gt;
=== AU.L2-3.3.1 – System Auditing ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AU.L2-3.3.1_Details|&#039;&#039;&#039;AU.L2-3.3.1&#039;&#039;&#039;]] Create and retain system audit logs and records to the extent needed to enable the monitoring, analysis, investigation, and reporting of unlawful or unauthorized system activity.&lt;br /&gt;
|-&lt;br /&gt;
| [a] audit logs needed (i.e., event types to be logged) to enable the monitoring, analysis, investigation, and reporting of unlawful or unauthorized system activity are specified. || Document || SSP, policy, or auditing and logging process that defines specific types of events to be logged.&lt;br /&gt;
|-&lt;br /&gt;
| [b] the content of audit records needed to support monitoring, analysis, investigation, and reporting of unlawful or unauthorized system activity is defined. || Document || SSP, policy, or auditing and logging process that defines specific content of audit records/files.&lt;br /&gt;
|-&lt;br /&gt;
| [c] audit records are created (generated). || Screen Share || Screen share of tool that shows logs are generated for all systems.&lt;br /&gt;
|-&lt;br /&gt;
| [d] audit records, once created, contain the defined content. || Screen Share || Screen share of tool that shows logs contain defined content as defined in SSP, policy, or procedures.&lt;br /&gt;
|-&lt;br /&gt;
| [e] retention requirements for audit records are defined. || Document || SSP, Polocy, or Auditing and logging process that describes how long records are kept.&lt;br /&gt;
|-&lt;br /&gt;
| [f] audit records are retained as defined. || Screen Share || Screen share of tool that shows records and audit content retained at a minimum as defined.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AU.L2-3.3.2 – User Accountability ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AU.L2-3.3.2_Details|&#039;&#039;&#039;AU.L2-3.3.2&#039;&#039;&#039;]] Ensure that the actions of individual system users can be uniquely traced to those users so they can be held accountable for their actions.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the content of the audit records needed to support the ability to uniquely trace users to their actions is defined. || Document || SSP, policy, or process that defines actions traced back to individuals.&lt;br /&gt;
|-&lt;br /&gt;
| [b] audit records, once created, contain the defined content. || Screen Share || Screen share of tool that shows audit records traced to specific users/roles.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AU.L2-3.3.3 – Event Review ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AU.L2-3.3.3_Details|&#039;&#039;&#039;AU.L2-3.3.3&#039;&#039;&#039;]] Review and update logged events.&lt;br /&gt;
|-&lt;br /&gt;
| [a] a process for determining when to review logged events is defined. || Document || SSP, policy, or documented process that shows frequency of when to review types of logged events.&lt;br /&gt;
|-&lt;br /&gt;
| [b] event types being logged are reviewed in accordance with the defined review process. || Artifact || Evidence through a documented method such as meeting minutes, CAB minutes, etc. of log sources and log events being logged at the defined frequency.&lt;br /&gt;
|-&lt;br /&gt;
| [c] event types being logged are updated based on the review. || Artifact || Evidence of implementation based on the results of the review of logged events/sources through a ticket, meeting minutes, or screen share of the tool that shows changes implemented (finetuning).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AU.L2-3.3.4 – Audit Failure Alerting ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AU.L2-3.3.4_Details|&#039;&#039;&#039;AU.L2-3.3.4&#039;&#039;&#039;]] Alert in the event of an audit logging process failure.&lt;br /&gt;
|-&lt;br /&gt;
| [a] personnel or roles to be alerted in the event of an audit logging process failure are identified. || Document || SSP, policy, or procedure that shows who needs to be notified in case of an audit failure.&lt;br /&gt;
|-&lt;br /&gt;
| [b] types of audit logging process failures for which alert will be generated are defined. || Document || SSP, policy, or procedure that shows what types of failure will generate notifications.&lt;br /&gt;
|-&lt;br /&gt;
| [c] identified personnel or roles are alerted in the event of an audit logging process failure. || Artifact || Artifact such as email or ticket that shows the identified personnel were alerted of any audit/logging process failure as defined.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AU.L2-3.3.5 – Audit Correlation ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AU.L2-3.3.5_Details|&#039;&#039;&#039;AU.L2-3.3.5&#039;&#039;&#039;]] Correlate audit record review, analysis, and reporting processes for investigation and response to indications of unlawful, unauthorized, suspicious, or unusual activity.&lt;br /&gt;
|-&lt;br /&gt;
| [a] audit record review, analysis, and reporting processes for investigation and response to indications of unlawful, unauthorized, suspicious, or unusual activity are defined. || Document || SSP, policy, or procedure covering audit logging, monitoring, and reporting.&lt;br /&gt;
|-&lt;br /&gt;
| [b] defined audit record review, analysis, and reporting processes are correlated. || Artifact || Artifact showing an audit event and the resultant corrective action or actions to the event; this can be a Help Desk ticket, meeting notes, or a change control board items showing the event and any corrective action taken.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AU.L2-3.3.6 – Reduction &amp;amp; Reporting ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AU.L2-3.3.6_Details|&#039;&#039;&#039;AU.L2-3.3.6&#039;&#039;&#039;]] Provide audit record reduction and report generation to support on-demand analysis and reporting.&lt;br /&gt;
|-&lt;br /&gt;
| [a] an audit record reduction capability that supports on-demand analysis is provided. || Screen Share || Screen share of the logging environment where an event can be selected and traced back to a specific device, or dashboard showing realtime event analysis.&lt;br /&gt;
|-&lt;br /&gt;
| [b] a report generation capability that supports on-demand reporting is provided. || Screen Share || Screen share showing the generation of an on demand report.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AU.L2-3.3.7 – Authoritative Time Source ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AU.L2-3.3.7_Details|&#039;&#039;&#039;AU.L2-3.3.7&#039;&#039;&#039;]] Provide a system capability that compares and synchronizes internal system clocks with an authoritative source to generate time stamps for audit records.&lt;br /&gt;
|-&lt;br /&gt;
| [a] internal system clocks are used to generate time stamps for audit records. || Screen Share || Screen share showing the NTP settings of a windows, Unix, Linux device; a screen share showing the NTP settings of network appliances.&lt;br /&gt;
|-&lt;br /&gt;
| [b] an authoritative source with which to compare and synchronize internal system clocks is specified. || Document || SSP or policy indicating that devices need to be synched to a local authoritative time device that is synched with an authoritative time service.&lt;br /&gt;
|-&lt;br /&gt;
| [c] internal system clocks used to generate time stamps for audit records are compared to and synchronized with the specified authoritative time source. || Screen Share || Screen share showing device logging appliance time is point to the appropriate authoritative time server.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AU.L2-3.3.8 – Audit Protection ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AU.L2-3.3.8_Details|&#039;&#039;&#039;AU.L2-3.3.8&#039;&#039;&#039;]] Protect audit information and audit logging tools from unauthorized access, modification, and deletion.&lt;br /&gt;
|-&lt;br /&gt;
| [a] audit information is protected from unauthorized access. || Screen Share || Screen share showing operating system permissions on the audit folders being restricted to appropriate users.&lt;br /&gt;
|-&lt;br /&gt;
| [b] audit information is protected from unauthorized modification. || Screen Share || Screen share showing operating system permissions on the audit folders being restricted to appropriate users.&lt;br /&gt;
|-&lt;br /&gt;
| [c] audit information is protected from unauthorized deletion. || Screen Share || Screen share showing operating system permissions on the audit folders being restricted to appropriate users.&lt;br /&gt;
|-&lt;br /&gt;
| [d] audit logging tools are protected from unauthorized access. || Screen Share || Artifact showing access permissions in the SIEM tool.&lt;br /&gt;
|-&lt;br /&gt;
| [e] audit logging tools are protected from unauthorized modification. || Screen Share || Artifact showing update permissions in the SIEM tool.&lt;br /&gt;
|-&lt;br /&gt;
| [f] audit logging tools are protected from unauthorized deletion. || Screen Share || Artifact showing delete permissions in the SIEM tool.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AU.L2-3.3.9 – Audit Management ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AU.L2-3.3.9_Details|&#039;&#039;&#039;AU.L2-3.3.9&#039;&#039;&#039;]] Limit management of audit logging functionality to a subset of privileged users.&lt;br /&gt;
|-&lt;br /&gt;
| [a] a subset of privileged users granted access to manage audit logging functionality is defined. || Document || SSP or policy indicating which users or groups have access to audit logs.&lt;br /&gt;
|-&lt;br /&gt;
| [b] management of audit logging functionality is limited to the defined subset of privileged users. || Screen Share || Artifact showing SIEM or OS folder permissions (this should be limited to the assigned users or groups); artifact showing an ACL setting in SIEM tool in regards to logs.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Configuration Management (CM) ==&lt;br /&gt;
=== CM.L2-3.4.1 – System Baselining ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_CM.L2-3.4.1_Details|&#039;&#039;&#039;CM.L2-3.4.1&#039;&#039;&#039;]] Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles.&lt;br /&gt;
|-&lt;br /&gt;
| [a] a baseline configuration is established. || Document || Documentation showing or explaining standard imaging process (how standard images are deployed and where  they are stored).&lt;br /&gt;
|-&lt;br /&gt;
| [b] the baseline configuration includes hardware, software, firmware, and documentation. || Artifact || Screenshot of repository of where images are maintained and information relating to hardware, software, and firmware.&lt;br /&gt;
|-&lt;br /&gt;
| [c] the baseline configuration is maintained (reviewed and updated) throughout the system development life cycle. || Artifact || Screenshot/evidence displaying management of baseline configurations (how often they are being managed as stated).&lt;br /&gt;
|-&lt;br /&gt;
| [d] a system inventory is established. || Document || Screenshot/evidence displaying inventory listing of approved products for use.&lt;br /&gt;
|-&lt;br /&gt;
| [e] the system inventory includes hardware, software, firmware, and documentation. || Artifact || Screeenshot/evidence displaying inventory listing of approved products and versions permitted for use.&lt;br /&gt;
|-&lt;br /&gt;
| [f] the inventory is maintained (reviewed and updated) throughout the system development life cycle. || Artifact || Screeenshot/evidence displaying management of baseline configurations (How often and are they being managed as stated.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== CM.L2-3.4.2 – Security Configuration Enforcement ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_CM.L2-3.4.2_Details|&#039;&#039;&#039;CM.L2-3.4.2&#039;&#039;&#039;]] Establish and enforce security configuration settings for information technology products employed in organizational systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] security configuration settings for information technology products employed in the system are established and included in the baseline configuration. || Document || Documentation explaining methodology used by organization to create secure baselines (STIGs, benchmarks).&lt;br /&gt;
|-&lt;br /&gt;
| [b] security configuration settings for information technology products employed in the system are enforced. || Artifact || Evidence of tool/s used to enforce security configurations to ensure images used are free from modification unless authorized.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== CM.L2-3.4.3 – System Change Management ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_CM.L2-3.4.3_Details|&#039;&#039;&#039;CM.L2-3.4.3&#039;&#039;&#039;]] Track, review, approve or disapprove, and log changes to organizational systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] changes to the system are tracked. || Artifact || Evidence of IT Service Management tool / process used to track system changes.&lt;br /&gt;
|-&lt;br /&gt;
| [b] changes to the system are reviewed. || Artifact || Evidence of IT Service Management tool / process used to review system changes.&lt;br /&gt;
|-&lt;br /&gt;
| [c] changes to the system are approved or disapproved. || Artifact || Evidence of IT Service Management tool / process used to approve/disapprove system changes.&lt;br /&gt;
|-&lt;br /&gt;
| [d] changes to the system are logged. || Artifact || Evidence of IT Service Management tool / process used to log system changes.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== CM.L2-3.4.4 – Security Impact Analysis ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_CM.L2-3.4.4_Details|&#039;&#039;&#039;CM.L2-3.4.4&#039;&#039;&#039;]] Analyze the security impact of changes prior to implementation.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the security impact of changes to the system is analyzed prior to implementation. || Artifact || Document explaining that security impact analysis of proposed changes to a system is conducted prior to implementation.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== CM.L2-3.4.5 – Access Restrictions for Change ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_CM.L2-3.4.5_Details|&#039;&#039;&#039;CM.L2-3.4.5&#039;&#039;&#039;]] Define, document, approve, and enforce physical and logical access restrictions associated with changes to organizational systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] physical access restrictions associated with changes to the system are defined. || Document || Document explaining the process of how physical access restrictions are defined for an individuals ability to make system changes.&lt;br /&gt;
|-&lt;br /&gt;
| [b] physical access restrictions associated with changes to the system are documented. || Document || Document explaining the process of how physical access restrictions are defined for an individuals ability to make system changes are documented; access request process.&lt;br /&gt;
|-&lt;br /&gt;
| [c] physical access restrictions associated with changes to the system are approved. || Artifact || Evidence of process of how physical access to systems are granted (i.e. physical access request sample).&lt;br /&gt;
|-&lt;br /&gt;
| [d] physical access restrictions associated with changes to the system are enforced. || Physical Review || Evidence of process of how physical access to systems are enforced (physical access system).&lt;br /&gt;
|-&lt;br /&gt;
| [e] logical access restrictions associated with changes to the system are defined. || Document || Document explaining the process of how logical access restrictions are defined for an individual&#039;s ability to make system changes.&lt;br /&gt;
|-&lt;br /&gt;
| [f] logical access restrictions associated with changes to the system are documented. || Document || Document explaining the process of how logical access restrictions are defined for an individual&#039;s ability to make system changes are documented.&lt;br /&gt;
|-&lt;br /&gt;
| [g] logical access restrictions associated with changes to the system are approved. || Artifact || Evidence of process of how logical access to systems are granted.&lt;br /&gt;
|-&lt;br /&gt;
| [h] logical access restrictions associated with changes to the system are enforced. || Artifact || Evidence of process of how logical access to systems are enforced.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== CM.L2-3.4.6 – Least Functionality ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_CM.L2-3.4.6_Details|&#039;&#039;&#039;CM.L2-3.4.6&#039;&#039;&#039;]] Employ the principle of least functionality by configuring organizational systems to provide only essential capabilities.&lt;br /&gt;
|-&lt;br /&gt;
| [a] essential system capabilities are defined based on the principle of least functionality. || Document || Documentation explaining how systems are configured to utilize the principle of least functionality for designated users.&lt;br /&gt;
|-&lt;br /&gt;
| [b] the system is configured to provide only the defined essential capabilities. || Screen Share || Evidence displaying how systems are configured to utilize the principle of least functionality for designated users; disabled service settings, accepted standards for hardening (CIS benchmarks, etc.).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== CM.L2-3.4.7 – Nonessential Functionality ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_CM.L2-3.4.7_Details|&#039;&#039;&#039;CM.L2-3.4.7&#039;&#039;&#039;]] Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services.&lt;br /&gt;
|-&lt;br /&gt;
| [a] essential programs are defined. || Document || Documented essential programs specified; build documents; software center; SSP.&lt;br /&gt;
|-&lt;br /&gt;
| [b] the use of nonessential programs is defined. || Document || Documented listing of nonessential programs (whatever is NOT specified in [a]); AUP/User Agreement may identify nonessential use/programs.&lt;br /&gt;
|-&lt;br /&gt;
| [c] the use of nonessential programs is restricted, disabled, or prevented as defined. || Screen Share || Tool used to restrict nonessential programs displays restrictions as defined (McAfee ePO settings, Carbon Black rules, etc.).&lt;br /&gt;
|-&lt;br /&gt;
| [d] essential functions are defined. || Document || Documented essential functions are specified.&lt;br /&gt;
|-&lt;br /&gt;
| [e] the use of nonessential functions is defined. || Document || Documented nonessential functions are specified.&lt;br /&gt;
|-&lt;br /&gt;
| [f] the use of nonessential functions is restricted, disabled, or prevented as defined. || Screen Share || Tool used to restrict essential/nonessential functions displays restrictions as defined.&lt;br /&gt;
|-&lt;br /&gt;
| [g] essential ports are defined. || Document || Documented essential ports are specified.&lt;br /&gt;
|-&lt;br /&gt;
| [h] the use of nonessential ports is defined. || Document || Documented nonessential ports functions are specified.&lt;br /&gt;
|-&lt;br /&gt;
| [i] the use of nonessential ports is restricted, disabled, or prevented as defined. || Screen Share || Tool used to restrict essential/nonessential ports displays restrictions as defined (FW rules; McAfee; GPO, etc.).&lt;br /&gt;
|-&lt;br /&gt;
| [j] essential protocols are defined. || Document || Documented essential protocols are specified.&lt;br /&gt;
|-&lt;br /&gt;
| [k] the use of nonessential protocols is defined. || Document || Documented nonessential protocols functions are specified.&lt;br /&gt;
|-&lt;br /&gt;
| [l] the use of nonessential protocols is restricted, disabled, or prevented as defined. || Screen Share || Tool used to restrict essential/nonessential protocols displays restrictions as defined (FW rules; GPO, etc.).&lt;br /&gt;
|-&lt;br /&gt;
| [m] essential services are defined. || Document || Documented essential services specified.&lt;br /&gt;
|-&lt;br /&gt;
| [n] the use of nonessential services is defined. || Document || Documented nonessential services functions are specified.&lt;br /&gt;
|-&lt;br /&gt;
| [o] the use of nonessential services is restricted, disabled, or prevented as defined. || Screen Share || Tool used to restrict essential/nonessential services displays restrictions as defined.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== CM.L2-3.4.8 – Application Execution Policy ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_CM.L2-3.4.8_Details|&#039;&#039;&#039;CM.L2-3.4.8&#039;&#039;&#039;]] Apply deny-by-exception (blacklisting) policy to prevent the use of unauthorized software or deny-all, permit-by-exception (whitelisting) policy to allow the execution of authorized software.&lt;br /&gt;
|-&lt;br /&gt;
| [a] a policy specifying whether whitelisting or blacklisting is to be implemented is specified. || Document || Documentation explaining whitelisting or blacklisting process.&lt;br /&gt;
|-&lt;br /&gt;
| [b] the software allowed to execute under whitelisting or denied use under blacklisting is specified. || Document || Documentation explaining whitelisting or blacklisting process for software.&lt;br /&gt;
|-&lt;br /&gt;
| [c] whitelisting to allow the execution of authorized software or blacklisting to prevent the use of unauthorized software is implemented as specified. || Screen Share || Tool used for whitelisting or blacklisting for software shows capability of restricting/authorizing software (Carbon Black dashboard, &amp;quot;SW Store&amp;quot;, web proxies, DNS Blackhole, etc.).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== CM.L2-3.4.9 – User-Installed Software ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_CM.L2-3.4.9_Details|&#039;&#039;&#039;CM.L2-3.4.9&#039;&#039;&#039;]] Control and monitor user-installed software.&lt;br /&gt;
|-&lt;br /&gt;
| [a] a policy for controlling the installation of software by users is established. || Document || Documented software authorization process or methodology for approval.&lt;br /&gt;
|-&lt;br /&gt;
| [b] installation of software by users is controlled based on the established policy. || Screen Share || Evidence that approval/restriction in installation of software by authorized personnel is implemented as specified (AUP, GPO, etc.).&lt;br /&gt;
|-&lt;br /&gt;
| [c] installation of software by users is monitored. || Screen Share || Evidence that installation of software by authorized personnel is monitored (SCCM groups, SW Center, etc.).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Identification and Authentication (IA) ==&lt;br /&gt;
=== IA.L2-3.5.1 – Identification [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IA.L2-3.5.1_Details|&#039;&#039;&#039;IA.L2-3.5.1&#039;&#039;&#039;]] Identify information system users, processes acting on behalf of users, or devices.&lt;br /&gt;
|-&lt;br /&gt;
| [a] system users are identified. || Document || Based on what is defined in their documentation (SSP, AUP, Policy, SOP), request to see a sample of non-privileged/privileged users in AD OU group (overlaps with 3.1.1 and 3.1.5).&lt;br /&gt;
|-&lt;br /&gt;
| [b] processes acting on behalf of users are identified. || Screen Share || Based on what is defined in their documentation (SSP, AUP, Policy, SOP), request to see a sample of service accounts in AD OU group (overlaps with 3.1.1 and 3.1.5).&lt;br /&gt;
|-&lt;br /&gt;
| [c] devices accessing the system are identified. || Screen Share || Based on what is defined in their documentation (SSP, AUP, Policy, SOP), request to see a sample of domain-joined workstation &amp;amp; servers in AD OU group (overlaps with 3.1.1 and 3.1.5).  For network devices, request screen share/artifact to show how they are identified on the enterprise network.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IA.L2-3.5.2 – Authentication [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IA.L2-3.5.2_Details|&#039;&#039;&#039;IA.L2-3.5.2&#039;&#039;&#039;]] Authenticate (or verify) the identities of those users, processes, or devices, as a prerequisite to allowing access to organizational information systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the identity of each user is authenticated or verified as a prerequisite to system access. || Screen Share || If the user logs in with non-privileged account during other demoes and then a privileged account, then this should be satisfied.  If screen share is unavailable, request logs to show successful and unsuccessful login by privileged and non-privilged users.&lt;br /&gt;
|-&lt;br /&gt;
| [b] the identity of each process acting on behalf of a user is authenticated or verified as a prerequisite to system access. || Screen Share || Request a log that shows successful/unsuccessful service account trying to log on to company&#039;s asset.&lt;br /&gt;
|-&lt;br /&gt;
| [c] the identity of each device accessing or connecting to the system is authenticated or verified as a prerequisite to system access. || Screen Share || Request a log that shows domain-joined workstation/server authenticating to AD (focus on the MAC/IP address/hostname).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IA.L2-3.5.3 – Multifactor Authentication ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IA.L2-3.5.3_Details|&#039;&#039;&#039;IA.L2-3.5.3&#039;&#039;&#039;]] Use multifactor authentication for local and network access to privileged accounts and for network access to non-privileged accounts.&lt;br /&gt;
|-&lt;br /&gt;
| [a] privileged accounts are identified. || Screen Share|| Based on what is defined in their documentation, request to see a sample of privileged users in AD OU group.  Overlaps with 3.1.5.  Screenshot/screen share to show implementation is enforced.&lt;br /&gt;
|-&lt;br /&gt;
| [b] multifactor authentication is implemented for local access to privileged accounts. || Document || SSP, AUP, Policy, SOP that defines that MFA is needed for privileged local access.&lt;br /&gt;
|-&lt;br /&gt;
| [c] multifactor authentication is implemented for network access to privileged accounts. || Screen Share || Within the MFA implementation mechanism, show that privileged users are forced to use MFA;  Screenshot/Screen share to show implementation is enforced.&lt;br /&gt;
|-&lt;br /&gt;
| [d] multifactor authentication is implemented for network access to non-privileged accounts. || Screen Share || Within the MFA implementation mechanism, show that non-privileged users are forced to use MFA; Screenshot/Screen share to show implementation is enforced.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IA.L2-3.5.4 – Replay-Resistant Authentication ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IA.L2-3.5.4_Details|&#039;&#039;&#039;IA.L2-3.5.4&#039;&#039;&#039;]] Employ replay-resistant authentication mechanisms for network access to privileged and non-privileged accounts.&lt;br /&gt;
|-&lt;br /&gt;
| [a] replay-resistant authentication mechanisms are implemented for network account access to privileged and non-privileged accounts. || Screen Share || Show the GPO setting that enforces Kerberos within AD.  If MFA is used, show the implementation to enforce replay resistant techniques.  For non-windows, show the technical solution to enforce replay resistant attacks.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IA.L2-3.5.5 – Identifier Reuse ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IA.L2-3.5.5_Details|&#039;&#039;&#039;IA.L2-3.5.5&#039;&#039;&#039;]] Prevent reuse of identifiers for a defined period.&lt;br /&gt;
|-&lt;br /&gt;
| [a] a period within which identifiers cannot be reused is defined. || Document || SSP, policies, or SOP that defines identifier reuse.&lt;br /&gt;
|-&lt;br /&gt;
| [b] reuse of identifiers is prevented within the defined period. || Screen Share || Show the GPO setting/technical solution that enforces what is defined in policy/documentation (this can be automated or manual process; screen share/artifacts can be presented to satisfy this requirement.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IA.L2-3.5.6 – Identifier Handling ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IA.L2-3.5.6_Details|&#039;&#039;&#039;IA.L2-3.5.6&#039;&#039;&#039;]] Disable identifiers after a defined period of inactivity.&lt;br /&gt;
|-&lt;br /&gt;
| [a] a period of inactivity after which an identifier is disabled is defined. || Document || SSP, policy that defines the period of inactivity after which an identifier is disabled.&lt;br /&gt;
|-&lt;br /&gt;
| [b] identifiers are disabled after the defined period of inactivity. || Screen Share || Screen share AD or similar tool supporting directory-based identity-related services for disabled accounts (can be done by hand or script).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IA.L2-3.5.7 – Password Complexity ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IA.L2-3.5.7_Details|&#039;&#039;&#039;IA.L2-3.5.7&#039;&#039;&#039;]] Enforce a minimum password complexity and change of characters when new passwords are created.&lt;br /&gt;
|-&lt;br /&gt;
| [a] password complexity requirements are defined. || Document || SSP, policy that defines password complexity requirements.&lt;br /&gt;
|-&lt;br /&gt;
| [b] password change of character requirements are defined. || Document || SSP, policy that defines change of character requirements are defined.&lt;br /&gt;
|-&lt;br /&gt;
| [c] minimum password complexity requirements as defined are enforced when new passwords are created. || Screen Share || Screen share of AD or similar directory-based identity-related service tool to show complexity requirements.&lt;br /&gt;
|-&lt;br /&gt;
| [d] minimum password change of character requirements as defined are enforced when new passwords are created. || Screen Share || Screen share of Group Policy configuration or similar tool providing centralized management and configuration of operating systems, applications, and users&#039; settings to show that characters must be changed.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IA.L2-3.5.8 – Password Reuse ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IA.L2-3.5.8_Details|&#039;&#039;&#039;IA.L2-3.5.8&#039;&#039;&#039;]] Prohibit password reuse for a specified number of generations.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the number of generations during which a password cannot be reused is specified. || Document || SSP, policy that specifies the number of generations during which a password cannot be reused is specified.&lt;br /&gt;
|-&lt;br /&gt;
| [b] reuse of passwords is prohibited during the specified number of generations. || Screen Share || Screen share Group Policy or similar tool providing centralized management and configuration of operating systems, applications, and users&#039; settings in a directory-based identity-related service tool&#039;s configuration to show reuse of passwords is prohibited.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IA.L2-3.5.9 – Temporary Passwords ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IA.L2-3.5.9_Details|&#039;&#039;&#039;IA.L2-3.5.9&#039;&#039;&#039;]] Allow temporary password use for system logons with an immediate change to a permanent password.&lt;br /&gt;
|-&lt;br /&gt;
| [a] an immediate change to a permanent password is required when a temporary password is used for system logon. || Screen Share || Screen share of Group Policy or similar tool providing centralized management and configuration of operating systems, applications, and users&#039; settings in a directory-based identity-related service tool&#039;s configuration to show &amp;quot;change password at first logon.&amp;quot;&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IA.L2-3.5.10 – Cryptographically-Protected Passwords ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IA.L2-3.5.1_Details|&#039;&#039;&#039;IA.L2-3.5.1&#039;&#039;&#039;]] Store and transmit only cryptographically-protected passwords.&lt;br /&gt;
|-&lt;br /&gt;
| [a] passwords are cryptographically protected in storage. || Screen Share || Screen share Group Policy or similar tool providing centralized management and configuration of operating systems, applications, and users&#039; settings in a directory-based identity-related service tool&#039;s configuration that Kerberos, or a similar network authentication protocol that works on the basis of tickets to allow nodes communicating over a non-secure network to prove their identity to one another in a secure manner, is enabled.&lt;br /&gt;
|-&lt;br /&gt;
| [b] passwords are cryptographically protected in transit. || Screen Share || Screen share Group Policy or similar tool providing centralized management and configuration of operating systems, applications, and users&#039; settings in a directory-based identity-related service tool&#039;s configuration that Kerberos, or a similar network authentication protocol that works on the basis of tickets to allow nodes communicating over a non-secure network to prove their identity to one another in a secure manner, is enabled.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IA.L2-3.5.11 – Obscure Feedback ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IA.L2-3.5.10_Details|&#039;&#039;&#039;IA.L2-3.5.10&#039;&#039;&#039;]] Obscure feedback of authentication information.&lt;br /&gt;
|-&lt;br /&gt;
| [a] authentication information is obscured during the authentication process. || Screen Share || Screen share of Group Policy or similar tool providing centralized management and configuration of operating systems, applications, and users&#039; settings in a directory-based identity-related service tool&#039;s configuration to show that passwords are obscured.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Incident Response (IR) ==&lt;br /&gt;
=== IR.L2-3.6.1 – Incident Handling ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IR.L2-3.6.1_Details|&#039;&#039;&#039;IR.L2-3.6.1&#039;&#039;&#039;]] Establish an operational incident-handling capability for organizational systems that includes preparation, detection, analysis, containment, recovery, and user response activities.&lt;br /&gt;
|-&lt;br /&gt;
| [a] an operational incident-handling capability is established. || Document || Incident Response SOP/Plan.&lt;br /&gt;
|-&lt;br /&gt;
| [b] the operational incident-handling capability includes preparation. || Document || Incident Response SOP/Plan, prior incident report, training, COOP plan.&lt;br /&gt;
|-&lt;br /&gt;
| [c] the operational incident-handling capability includes detection. || Document || Incident Response SOP/Plan; definition of tools used to detect; artifacts showing tools used; prior incident report.&lt;br /&gt;
|-&lt;br /&gt;
| [d] the operational incident-handling capability includes analysis. || Document || Incident Response SOP/Plan; Definition of tools used to analyze potential incidents; artifacts showing tools used for analysis; prior incident report.&lt;br /&gt;
|-&lt;br /&gt;
| [e] the operational incident-handling capability includes containment. || Document || Incident Response SOP/Plan; isolation/quarantine process; user training.&lt;br /&gt;
|-&lt;br /&gt;
| [f] the operational incident-handling capability includes recovery. || Document || Incident Response SOP/Plan; COOP Plan; prior incident reports, re-baselining impacted devices.&lt;br /&gt;
|-&lt;br /&gt;
| [g] the operational incident-handling capability includes user response. || Document || Incident Response SOP/Plan; user awareness training; Help Desk process.&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IR.L2-3.6.2 – Incident Reporting ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IR.L2-3.6.2_Details|&#039;&#039;&#039;IR.L2-3.6.2&#039;&#039;&#039;]] Track, document, and report incidents to designated officials and/or authorities both internal and external to the organization.&lt;br /&gt;
|-&lt;br /&gt;
| [a] incidents are tracked. || Artifact || Incident Response SOP/Plan; ITSM artifact; technical implementation for incident tracking.&lt;br /&gt;
|-&lt;br /&gt;
| [b] incidents are documented. || Artifact || Incident Response SOP/Plan; ITSM artifact; technical implementation for incident tracking.&lt;br /&gt;
|-&lt;br /&gt;
| [c] authorities to whom incidents are to be reported are identified. || Document || Incident Response SOP/Plan.&lt;br /&gt;
|-&lt;br /&gt;
| [d] organizational officials to whom incidents are to be reported are identified. || Document || Incident Response SOP/Plan.&lt;br /&gt;
|-&lt;br /&gt;
| [e] identified authorities are notified of incidents. || Screen Share || Prior incident report; DIBNET login; prior email notifications.&lt;br /&gt;
|-&lt;br /&gt;
| [f] identified organizational officials are notified of incidents. || Artifact || Prior incident report; prior email notifications; tabletop exercises.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IR.L2-3.6.3 – Incident Response Testing ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IR.L2-3.6.3_Details|&#039;&#039;&#039;IR.L2-3.6.3&#039;&#039;&#039;]] Test the organizational incident response capability.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the incident response capability is tested. || Artifact || Incident response table top/scheduled or unscheduled test or penetration test.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Maintenance (MA) ==&lt;br /&gt;
=== MA.L2-3.7.1 – Perform Maintenance ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MA.L2-3.7.1_Details|&#039;&#039;&#039;MA.L2-3.7.1&#039;&#039;&#039;]] Perform maintenance on organizational systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] system maintenance is performed. || Artifact || Establish typical maintenance activities (HVAC, UPS, power distribution, generators, copier maintenance) that are performed; maintenance agreements or contracts detailing these types of activities are acceptable; interview responses should be considered.  This requirement should not be confused with 3.14.1 - report, remediate, and correct system flaws in a timely manner (patch management).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MA.L2-3.7.2 – System Maintenance Control ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MA.L2-3.7.2_Details|&#039;&#039;&#039;MA.L2-3.7.2&#039;&#039;&#039;]] Provide controls on the tools, techniques, mechanisms, and personnel used to conduct system maintenance.&lt;br /&gt;
|-&lt;br /&gt;
| [a] tools used to conduct system maintenance are controlled. || Artifact || Tools may largely depend on the assessed environment; discussion examples include network diagnostic and monitoring tools (including hardware and software); artifacts could demonstrate secured locations/areas for these tools (photos) or checkout sheets/rosters (documents) depicting responsible personnel and the dates/times of checkout.&lt;br /&gt;
|-&lt;br /&gt;
| [b] techniques used to conduct system maintenance are controlled. || Artifact || Processes for scheduling, performing, documenting, reviewing, approving, and monitoring maintenance and repairs for the information system.&lt;br /&gt;
|-&lt;br /&gt;
| [c] mechanisms used to conduct system maintenance are controlled. || Artifact || Processes for scheduling, performing, documenting, reviewing, approving, and monitoring maintenance and repairs for the information system.&lt;br /&gt;
|-&lt;br /&gt;
| [d] personnel used to conduct system maintenance are controlled. || Physical Review || Screenshot of who is authorized to conduct maintenance; maintenance personnel training program.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MA.L2-3.7.3 – Equipment Sanitization ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MA.L2-3.7.3_Details|&#039;&#039;&#039;MA.L2-3.7.3&#039;&#039;&#039;]] Ensure equipment removed for off-site maintenance is sanitized of any CUI.&lt;br /&gt;
|-&lt;br /&gt;
| [a] equipment to be removed from organizational spaces for off-site maintenance is sanitized of any CUI. || Artifact || Document or artifact; record if equipment sanitized; categories of sanitization/destruction defined; sanitization procedural document.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MA.L2-3.7.4 – Media Inspection ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MA.L2-3.7.4_Details|&#039;&#039;&#039;MA.L2-3.7.4&#039;&#039;&#039;]] Check media containing diagnostic and test programs for malicious code before the media are used in organizational systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] media containing diagnostic and test programs are checked for malicious code before being used in organizational systems that process, store, or transmit CUI. || Artifact || Screenshot of diagnostic/test program being used (such as Symantec and McAfee on access scans…).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MA.L2-3.7.5 – Nonlocal Maintenance ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MA.L2-3.7.5_Details|&#039;&#039;&#039;MA.L2-3.7.5&#039;&#039;&#039;]] Require multifactor authentication to establish nonlocal maintenance sessions via external network connections and terminate such connections when nonlocal maintenance is complete.&lt;br /&gt;
|-&lt;br /&gt;
| [a] multifactor authentication is used to establish nonlocal maintenance sessions via external network connections. || Screen Share || Describe MFA used to remote from external service to organizational systems for maintenance and screenshot of MFA (3.5.3)(points associated with admin).&lt;br /&gt;
|-&lt;br /&gt;
| [b] nonlocal maintenance sessions established via external network connections are terminated when nonlocal maintenance is complete. || Screen Share || Screenshot VPN session timeout.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MA.L2-3.7.6 – Maintenance Personnel ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MA.L2-3.7.6_Details|&#039;&#039;&#039;MA.L2-3.7.6&#039;&#039;&#039;]] Supervise the maintenance activities of maintenance personnel without required access authorization.&lt;br /&gt;
|-&lt;br /&gt;
| [a] maintenance personnel without required access authorization are supervised during maintenance activities. || Document || System maintenance policy; list of authorized personnel; maintenance records or, contracts/SLAs; WebEx.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Media Protection (MP) ==&lt;br /&gt;
=== MP.L2-3.8.1 – Media Protection ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MP.L2-3.8.1_Details|&#039;&#039;&#039;MP.L2-3.8.1&#039;&#039;&#039;]] Protect (i.e., physically control and securely store) system media containing CUI, both paper and digital.&lt;br /&gt;
|-&lt;br /&gt;
| [a] paper media containing CUI is physically controlled. || Document || Policy showing CUI paper media is controlled; artifact showing who has access; artifacts/records of  inventories conducted; media check out procedures (i.e. file cabinets, encryption, password protection).&lt;br /&gt;
|-&lt;br /&gt;
| [b] digital media containing CUI is physically controlled. || Document || Policy showing CUI digital media is controlled; artifact showing who has access; artifacts/records of inventories conducted; media check out procedures (i.e. file cabinets, external drives, USBs, encryption, password protection).&lt;br /&gt;
|-&lt;br /&gt;
| [c] paper media containing CUI is securely stored. || Physical Review || Check out/sign out sheets; possible photo of storage container/video walk through of storage area; badge reader logs or access lists for keys for secured areas; interview response considered (i.e. file cabinets,  encryption, password protection).&lt;br /&gt;
|-&lt;br /&gt;
| [d] digital media containing CUI is securely stored. || Physical Review || Check out/sign out sheets; possible photo of storage container/video walk through of storage area; badge reader logs or access lists for keys for secured areas; interview response considered (i.e. file cabinets, external drives, USBs, encryption, password protection).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MP.L2-3.8.2 – Media Access ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MP.L2-3.8.2_Details|&#039;&#039;&#039;MP.L2-3.8.2&#039;&#039;&#039;]] Limit access to CUI on system media to authorized users.&lt;br /&gt;
|-&lt;br /&gt;
| [a] access to CUI on system media is limited to authorized users. || Artifact || Document describing how CUI is limited AND artifact showing principle of least access is implemented.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MP.L2-3.8.3 – Media Disposal [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MP.L2-3.8.3_Details|&#039;&#039;&#039;MP.L2-3.8.3&#039;&#039;&#039;]] Sanitize or destroy information system media containing Federal Contract Information before disposal or release for reuse.&lt;br /&gt;
|-&lt;br /&gt;
| [a] system media containing CUI is sanitized or destroyed before disposal. || Document || Policy or artifact of media destruction logs; certificates of destruction; SLAs or contracts.&lt;br /&gt;
|-&lt;br /&gt;
| [b] system media containing CUI is sanitized before it is released for reuse. || Document || Policy or artifact describing method to sanitize, software used (i.e. DoD Wipe, ShredIT and Iron Mountain; Blancco; GDisk, DBAN).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MP.L2-3.8.4 – Media Markings ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MP.L2-3.8.4_Details|&#039;&#039;&#039;MP.L2-3.8.4&#039;&#039;&#039;]] Mark media with necessary CUI markings and distribution limitations.&lt;br /&gt;
|-&lt;br /&gt;
| [a] media containing CUI is marked with applicable CUI markings. || Physical Review || Document or artifact showing CUI markings (i.e. labeling standards ).&lt;br /&gt;
|-&lt;br /&gt;
| [b] media containing CUI is marked with distribution limitations. || Physical Review || Document or artifact showing distro limitations (i.e. labeling standards ).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MP.L2-3.8.5 – Media Accountability ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MP.L2-3.8.5_Details|&#039;&#039;&#039;MP.L2-3.8.5&#039;&#039;&#039;]] Control access to media containing CUI and maintain accountability for media during transport outside of controlled areas.&lt;br /&gt;
|-&lt;br /&gt;
| [a] access to media containing CUI is controlled. || Document || Policy, artifact of audit logs showing tracking, Access Control Lists, records of transport activities (i.e. USB drives, CDs, chain of custody.&lt;br /&gt;
|-&lt;br /&gt;
| [b] accountability for media containing CUI is maintained during transport outside of controlled areas. || Artifact || Artifact of audit logs showing tracking, Access Control Lists, records of transport activities (i.e. USB drives, CDs; chain of custody.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MP.L2-3.8.6 – Portable Storage Encryption ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MP.L2-3.8.6_Details|&#039;&#039;&#039;MP.L2-3.8.6&#039;&#039;&#039;]] Implement cryptographic mechanisms to protect the confidentiality of CUI stored on digital media during transport unless otherwise protected by alternative physical safeguards.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the confidentiality of CUI stored on digital media is protected during transport using cryptographic mechanisms or alternative physical safeguards. || Artifact || Artifact showing crypto mechanisms used to protect (are they FIPS 140-2 [13.11]); artifact showing what alternative physical safeguards are in place (i.e. encryption; BitLocker; McAfee ).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MP.L2-3.8.7 – Removable Media ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MP.L2-3.8.7_Details|&#039;&#039;&#039;MP.L2-3.8.7&#039;&#039;&#039;]] Control the use of removable media on system components.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the use of removable media on system components is controlled. || Artifact || Policy showing if removable media is allowed; writable removable media is restricted; tracking artifacts; what tools are used (i.e. Carbon Black, Crowd Strike, GPO, Zoho Desktop Central); procedure/process describing what happens if it is lost; what mechanisms are in place to control/restrict removable media (i.e. Active Directory Groups and Group Policy artifact showing restriction).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MP.L2-3.8.8 – Shared Media ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MP.L2-3.8.8_Details|&#039;&#039;&#039;MP.L2-3.8.8&#039;&#039;&#039;]] Prohibit the use of portable storage devices when such devices have no identifiable owner.ASSESSMENT OBJECTIVES&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [a] the use of portable storage devices is prohibited when such devices have no identifiable owner. || Artifact || Policy and/or artifact showing company stance on portable storage devices if there is no owner (are personal USB devices allowed or are they company-issued; artifact showing alerts if device is connected to network (i.e. external HDD, Carbon Black, Crowd Strike, GPO, Zoho Desktop Central.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MP.L2-3.8.9 – Protect Backups ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MP.L2-3.8.9_Details|&#039;&#039;&#039;MP.L2-3.8.9&#039;&#039;&#039;]] Protect the confidentiality of backup CUI at storage locations.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the confidentiality of backup CUI is protected at storage locations. || Artifact || Policy on system backups; artifact showing media labeling; artifact showing encyption (is it FIPS 140-2 [13.11]); Access Control List artifact (i.e. backup tapes, Tivoli Storage Manager).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Personnel Security (PS) ==&lt;br /&gt;
=== PS.L2-3.9.1 – Screen Individuals ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_PS.L2-3.9.1_Details|&#039;&#039;&#039;PS.L2-3.9.1&#039;&#039;&#039;]] Screen individuals prior to authorizing access to organizational systems containing CUI.&lt;br /&gt;
|-&lt;br /&gt;
| [a] individuals are screened prior to authorizing access to organizational systems containing CUI. || Artifact || Screenshot of records of screened personnel/background checks.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== PS.L2-3.9.2 – Personnel Actions ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_PS.L2-3.9.2_Details|&#039;&#039;&#039;PS.L2-3.9.2&#039;&#039;&#039;]] Ensure that organizational systems containing CUI are protected during and after personnel actions such as terminations and transfers.&lt;br /&gt;
|-&lt;br /&gt;
| [a] a policy and/or process for terminating system access and any credentials coincident with personnel actions is established. || Document || Personnel security policy/procedures/instruction; Access control policy/procedure/instruction.&lt;br /&gt;
|-&lt;br /&gt;
| [b] system access and credentials are terminated consistent with personnel actions such as termination or transfer. || Artifact || Screenshot of records of personnel transfer and termination actions.&lt;br /&gt;
|-&lt;br /&gt;
| [c] the system is protected during and after personnel transfer actions. || Artifact || Completed outprocessing checklist.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Physical Protection (PE) ==&lt;br /&gt;
=== PE.L2-3.10.1 – Limit Physical Access [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_PE.L2-3.10.1_Details|&#039;&#039;&#039;PE.L2-3.10.1&#039;&#039;&#039;]] Limit physical access to organizational information systems, equipment, and the respective operating environments to authorized individuals.&lt;br /&gt;
|-&lt;br /&gt;
| [a] authorized individuals allowed physical access are identified. || Artifact || Authorized personnel (names) access list.&lt;br /&gt;
|-&lt;br /&gt;
| [b] physical access to organizational systems is limited to authorized individuals. || Physical Review || Badge reader logs, audit logs, and/or card swipe test.&lt;br /&gt;
|-&lt;br /&gt;
| [c] physical access to equipment is limited to authorized individuals. || Physical Review || Badge reader logs, audit logs, and/or card swipe test.&lt;br /&gt;
|-&lt;br /&gt;
| [d] physical access to operating environments is limited to authorized. || Physical Review || Badge reader logs, audit logs, and/or card swipe test.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== PE.L2-3.10.2 – Monitor Facility ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_PE.L2-3.10.2_Details|&#039;&#039;&#039;PE.L2-3.10.2&#039;&#039;&#039;]] Protect and monitor the physical facility and support infrastructure for organizational systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the physical facility where organizational systems reside is protected. || Physical Review || Physical security measures and barriers into the physical facility (cameras/locks/gates/guards, etc.).&lt;br /&gt;
|-&lt;br /&gt;
| [b] the support infrastructure for organizational systems is protected. || Physical Review || Physical barriers to entries into computer spaces, server rooms, etc.&lt;br /&gt;
|-&lt;br /&gt;
| [c] the physical facility where organizational systems reside is monitored. || Physical Review || Audit logs/how the physical facility is being monitored (cameras/access system/guards, etc.).&lt;br /&gt;
|-&lt;br /&gt;
| [d] the support infrastructure for organizational systems is monitored. || Physical Review || Audit logs/how the physical facility is being monitored (cameras/access system/guards, etc.).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== PE.L2-3.10.3 – Escort Visitors [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_PE.L2-3.10.3_Details|&#039;&#039;&#039;PE.L2-3.10.3&#039;&#039;&#039;]] Escort visitors and monitor visitor activity.&lt;br /&gt;
|-&lt;br /&gt;
| [a] visitors are escorted. || Physical Review || Policy/procedures/instruction on methodology for handling non-authorized personnel (entry to exit).&lt;br /&gt;
|-&lt;br /&gt;
| [b] visitor activity is monitored. || Physical Review || Policy/procedures/instructio on methodology for handling non-authorized personnel (entry to exit).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== PE.L2-3.10.4 – Physical Access Logs [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_PE.L2-3.10.4_Details|&#039;&#039;&#039;PE.L2-3.10.4&#039;&#039;&#039;]] Maintain audit logs of physical access.&lt;br /&gt;
|-&lt;br /&gt;
| [a] audit logs of physical access are maintained. || Artifact || Log or report from badging system.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== PE.L2-3.10.5 – Manage Physical Access [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_PE.L2-3.10.5_Details|&#039;&#039;&#039;PE.L2-3.10.5&#039;&#039;&#039;]] Control and manage physical access devices.&lt;br /&gt;
|-&lt;br /&gt;
| [a] physical access devices are identified. || Document || Physical access control systems description, guard force contract/policy, key locks, logical systems specifications, etc.&lt;br /&gt;
|-&lt;br /&gt;
| [b] physical access devices are controlled. || Physical Review || Inventory records of physical access control devices (e.g. keys, locks, card readers, locks, etc.).&lt;br /&gt;
|-&lt;br /&gt;
| [c] physical access devices are managed. || Physical Review || List of security safeguards controlling access to the facility (e.g. cameras, monitoring by guards, isolation of IT systems equiment and or system components).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== PE.L2-3.10.6 – Alternative Work Sites ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_PE.L2-3.10.6_Details|&#039;&#039;&#039;PE.L2-3.10.6&#039;&#039;&#039;]] Enforce safeguarding measures for CUI at alternate work sites.&lt;br /&gt;
|-&lt;br /&gt;
| [a] safeguarding measures for CUI are defined for alternate work sites. || Document || Telework agreement, Acceptable Use Policy and SOP for alternate work locations; user security training validation which includes physical/logical/technical protections of system at alternate work sites.&lt;br /&gt;
|-&lt;br /&gt;
| [b] safeguarding measures for CUI are enforced for alternate work sites. || Artifact || Monitoring/audit log of user activity and logical/physical/technical mechanisms in place to preclude unauthorized activity (telework agreement , AUP?).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Risk Assessment (RA) ==&lt;br /&gt;
=== RA.L2-3.11.1 – Risk Assessments ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_RA.L2-3.11.1_Details|&#039;&#039;&#039;RA.L2-3.11.1&#039;&#039;&#039;]] Periodically assess the risk to organizational operations (including mission, functions, image, or reputation), organizational assets, and individuals, resulting from the operation of organizational systems and the associated processing, storage, or transmission of CUI.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the frequency to assess risk to organizational operations, organizational assets, and individuals is defined. || Document || Risk assessment policy.&lt;br /&gt;
|-&lt;br /&gt;
| [b] risk to organizational operations, organizational assets, and individuals resulting from the operation of an organizational system that processes, stores, or transmits CUI is assessed with the defined frequency. || Artifact || Copy of last risk assessment done within defined frequency.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== RA.L2-3.11.2 – Vulnerability Scan ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_RA.L2-3.11.2_Details|&#039;&#039;&#039;RA.L2-3.11.2&#039;&#039;&#039;]] Scan for vulnerabilities in organizational systems and applications periodically and when new vulnerabilities affecting those systems and applications are identified.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the frequency to scan for vulnerabilities in organizational systems and applications is defined. || Document || Policy/procedures/instruction addressing vulnerability scanning records.&lt;br /&gt;
|-&lt;br /&gt;
| [b] vulnerability scans are performed on organizational systems with the defined frequency. || Screen Share || System configuration settings of vulnerability scanning scheduling and vulnerability scan results of systems within defined frequency.&lt;br /&gt;
|-&lt;br /&gt;
| [c] vulnerability scans are performed on applications with the defined frequency. || Screen Share || System configuration settings of vulnerability scanning scheduling and vulnerability scan results of applications within defined frequency.&lt;br /&gt;
|-&lt;br /&gt;
| [d] vulnerability scans are performed on organizational systems when new vulnerabilities are identified. || Screen Share || View signatures in scanning tool/ad hoc scan performed as a result.&lt;br /&gt;
|-&lt;br /&gt;
| [e] vulnerability scans are performed on applications when new vulnerabilities are identified. || Screen Share || View signatures in scanning tool/ad hoc scan performed as a result.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== RA.L2-3.11.3 – Vulnerability Remediation ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_RA.L2-3.11.3_Details|&#039;&#039;&#039;RA.L2-3.11.3&#039;&#039;&#039;]] Remediate vulnerabilities in accordance with risk assessments.&lt;br /&gt;
|-&lt;br /&gt;
| [a] vulnerabilities are identified. || Artifact || Scan results showing vulnerabilities identified.&lt;br /&gt;
|-&lt;br /&gt;
| [b] vulnerabilities are remediated in accordance with risk assessments. || Artifact || Screenshot/document of scan results of remediated vulnerabilities in accordance to risk assessments.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Security Assessment (CA) ==&lt;br /&gt;
=== CA.L2-3.12.1 – Security Control Assessment ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_CA.L2-3.12.1_Details|&#039;&#039;&#039;CA.L2-3.12.1&#039;&#039;&#039;]] Periodically assess the security controls in organizational systems to determine if the controls are effective in their application.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the frequency of security control assessments is defined. || Document || SSP.&lt;br /&gt;
|-&lt;br /&gt;
| [b] security controls are assessed with the defined frequency to determine if the controls are effective in their application. || Artifact || Copy of last security control assessment done within defined frequency.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== CA.L2-3.12.2 – Operational Plan of Action ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_CA.L2-3.12.2_Details|&#039;&#039;&#039;CA.L2-3.12.2&#039;&#039;&#039;]] Develop and implement plans of action designed to correct deficiencies and reduce or eliminate vulnerabilities in organizational systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] deficiencies and vulnerabilities to be addressed by the plan of action are identified. || Artifact || Plan of Action (POA).&lt;br /&gt;
|-&lt;br /&gt;
| [b] a plan of action is developed to correct identified deficiencies and reduce or eliminate identified vulnerabilities. || Artifact || Plan of Action (POA).&lt;br /&gt;
|-&lt;br /&gt;
| [c] the plan of action is implemented to correct identified deficiencies and reduce or eliminate identified vulnerabilities. || Artifact || Plan of Action (POA)/previously completed POAs.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== CA.L2-3.12.3 – Security Control Monitoring ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_CA.L2-3.12.3_Details|&#039;&#039;&#039;CA.L2-3.12.3&#039;&#039;&#039;]] Monitor security controls on an ongoing basis to ensure the continued effectiveness of the controls.&lt;br /&gt;
|-&lt;br /&gt;
| [a] security controls are monitored on an ongoing basis to ensure the continued effectiveness of those controls. || Artifact || Collection of risk assessment results, internal or third-party audits/security assessments and/or continuous monitoring reports/alerts (SIEM tool, etc.).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== CA.L2-3.12.4 – System Security Plan ====&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_CA.L2-3.12.4_Details|&#039;&#039;&#039;CA.L2-3.12.4&#039;&#039;&#039;]] Develop, document, and periodically update system security plans that describe system boundaries, system environments of operation, how security requirements are implemented, and the relationships with or connections to other systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] a system security plan is developed. || Document || SSP.&lt;br /&gt;
|-&lt;br /&gt;
| [b] the system boundary is described and documented in the system security plan. || Document || SSP and any supporting documentation.&lt;br /&gt;
|-&lt;br /&gt;
| [c] the system environment of operation is described and documented in the system security plan. || Document || SSP and any supporting documentation.&lt;br /&gt;
|-&lt;br /&gt;
| [d] the security requirements identified and approved by the designated authority as non-applicable are identified. || Document || SSP and required adjudication from DoD CIO.&lt;br /&gt;
|-&lt;br /&gt;
| [e] the method of security requirement implementation is described and documented in the system security plan. || Document || SSP and any supporting documentation.&lt;br /&gt;
|-&lt;br /&gt;
| [f] the relationship with or connection to other systems is described and documented in the system security plan. || Document || SSP and any supporting documentation.&lt;br /&gt;
|-&lt;br /&gt;
| [g] the frequency to update the system security plan is defined. || Document || SSP.&lt;br /&gt;
|-&lt;br /&gt;
| [h] system security plan is updated with the defined frequency. || Document || SSP/any previous versions.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== System and Communications Protection (SC) ==&lt;br /&gt;
=== SC.L2-3.13.1 – Boundary Protection [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.1_Details|&#039;&#039;&#039;SC.L2-3.13.1&#039;&#039;&#039;]] Monitor, control, and protect organizational communications (i.e., information transmitted or received by organizational information systems) at the external boundaries and key internal boundaries of the information systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the external system boundary is defined. || Document || SSP, network diagrams, CUI flow, cloud provider FedRAMP Moderate.&lt;br /&gt;
|-&lt;br /&gt;
| [b] key internal system boundaries are defined. || Document || SSP, network diagrams, CUI flow.&lt;br /&gt;
|-&lt;br /&gt;
| [c] communications are monitored at the external system boundary. || Screen Share || SSP, logging server, boundary device configurations, monitoring policy.&lt;br /&gt;
|-&lt;br /&gt;
| [d] communications are monitored at key internal boundaries. || Screen Share || SSP, logging server, boundary device configurations, monitoring policy.&lt;br /&gt;
|-&lt;br /&gt;
| [e] communications are controlled at the external system boundary. || Screen Share || SSP, boundary device configurations, ACL, subnets, DMZ.&lt;br /&gt;
|-&lt;br /&gt;
| [f] communications are controlled at key internal boundaries. || Screen Share || SSP, boundary device configurations, ACL, subnets.&lt;br /&gt;
|-&lt;br /&gt;
| [g] communications are protected at the external system boundary. || Screen Share || Configurations for IPS/IDS, email gateway, VLAN, proxy, firewall, malware protection, DNS, TSL.&lt;br /&gt;
|-&lt;br /&gt;
| [h] communications are protected at key internal boundaries. || Screen Share || Configurations for IPS/IDS, VLAN, firewall, malware protection, SSL.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.2 – Security Engineering ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.2_Details|&#039;&#039;&#039;SC.L2-3.13.2&#039;&#039;&#039;]] Employ architectural designs, software development techniques, and systems engineering principles that promote effective information security within organizational systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] architectural designs that promote effective information security are identified. || Document || SSP, config management policy, network diagram, CCB minutes, enterprise architecture process.&lt;br /&gt;
|-&lt;br /&gt;
| [b] software development techniques that promote effective information security are identified. || Document || SSP, config management policy, SDLC, CCB minutes.&lt;br /&gt;
|-&lt;br /&gt;
| [c] systems engineering principles that promote effective information security are identified. || Document || SSP, config management policy, CCB minutes, security architecture engineering.&lt;br /&gt;
|-&lt;br /&gt;
| [d] identified architectural designs that promote effective information security are employed. || Artifact || CCB minutes, Network diagrams and configurations, Project Plans.&lt;br /&gt;
|-&lt;br /&gt;
| [e] identified software development techniques that promote effective information security are employed. || Artifact || CCB minutes, SDLC, code scanner results, code management tracking.&lt;br /&gt;
|-&lt;br /&gt;
| [f] identified systems engineering principles that promote effective information security are employed. || Artifact || CCB minutes, configuration management, ITSM, patch management, lifecycle replacement processes.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.3 – Role Separation ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.3_Details|&#039;&#039;&#039;SC.L2-3.13.3&#039;&#039;&#039;]] Separate user functionality from system management functionality.&lt;br /&gt;
|-&lt;br /&gt;
| [a] user functionality is identified. || Document || SSP, AUP.&lt;br /&gt;
|-&lt;br /&gt;
| [b] system management functionality is identified. || Document || SSP, Privileged Account Agreement.&lt;br /&gt;
|-&lt;br /&gt;
| [c] user functionality is separated from system management functionality. || Screen Share || Active Directory, Jump Boxes, GPO, VM, RDP.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.4 – Shared Resource Control ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.4_Details|&#039;&#039;&#039;SC.L2-3.13.4&#039;&#039;&#039;]] Prevent unauthorized and unintended information transfer via shared system resources.&lt;br /&gt;
|-&lt;br /&gt;
| [a] unauthorized and unintended information transfer via shared system resources is prevented. || Screen Share || SSP, OS configurations, Linux containers, system/media reuse policies, certificate management policies, media destruction policies, printer configs, VDI configuration.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
===  SC.L2-3.13.5 – Public-Access System Separation [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.5_Details|&#039;&#039;&#039;SC.L2-3.13.5&#039;&#039;&#039;]] Implement subnetworks for publicly accessible system components that are physically or logically separated from internal networks.&lt;br /&gt;
|-&lt;br /&gt;
| [a] publicly accessible system components are identified. || Document || SSP, network diagram, DMZ inventory/roles.&lt;br /&gt;
|-&lt;br /&gt;
| [b] subnetworks for publicly accessible system components are physically or logically separated from internal networks. || Artifact || Network diagram, IPAM, VLAN, DHCP, DMZ.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.6 – Network Communication by Exception ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.6_Details|&#039;&#039;&#039;SC.L2-3.13.6&#039;&#039;&#039;]] Deny network communications traffic by default and allow network communications traffic by exception (i.e., deny all, permit by exception).&lt;br /&gt;
|-&lt;br /&gt;
| [a] network communications traffic is denied by default. || Screen Share || Host and network firewall rules, SIEM logs, hit counts.&lt;br /&gt;
|-&lt;br /&gt;
| [b] network communications traffic is allowed by exception. || Screen Share || Host and network firewall rules, SIEM logs, hit counts.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.7 – Split Tunneling ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.7_Details|&#039;&#039;&#039;SC.L2-3.13.7&#039;&#039;&#039;]] Prevent remote devices from simultaneously establishing non-remote connections with organizational systems and communicating via some other connection to resources in external networks (i.e., split tunneling).&lt;br /&gt;
|-&lt;br /&gt;
| [a] remote devices are prevented from simultaneously establishing non-remote connections with the system and communicating via some other connection to resources in external networks (i.e., split tunneling). || Screen Share || VPN appliance/server configuration, endpoint VPN software configuration.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.8 – Data in Transit ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.8_Details|&#039;&#039;&#039;SC.L2-3.13.8&#039;&#039;&#039;]] Implement cryptographic mechanisms to prevent unauthorized disclosure of CUI during transmission unless otherwise protected by alternative physical safeguards.&lt;br /&gt;
|-&lt;br /&gt;
| [a] cryptographic mechanisms intended to prevent unauthorized disclosure of CUI are identified. || Document || SSP, PKI policies, configuration processes, config management, email attachment encryption policy, removable media policy, data at rest policy.&lt;br /&gt;
|-&lt;br /&gt;
| [b] alternative physical safeguards intended to prevent unauthorized disclosure of CUI are identified. || Document || SSP, physical security policy.&lt;br /&gt;
|-&lt;br /&gt;
| [c] either cryptographic mechanisms or alternative physical safeguards are implemented to prevent unauthorized disclosure of CUI during transmission. || Screen Share || TLS settings, SSL settings, VPN/Wireless Access Points/Mobile Devices cryptographic settings, ODBC connector settings, SAN configuration, IPSec/MPLS, backup configuration, physical security.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.9 – Connections Termination ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.9_Details|&#039;&#039;&#039;SC.L2-3.13.9&#039;&#039;&#039;]] Terminate network connections associated with communications sessions at the end of the sessions or after a defined period of inactivity.&lt;br /&gt;
|-&lt;br /&gt;
| [a] a period of inactivity to terminate network connections associated with communications sessions is defined. || Document || SSP, network communications policy.&lt;br /&gt;
|-&lt;br /&gt;
| [b] network connections associated with communications sessions are terminated at the end of the sessions. || Screen Share || VPN appliance/server logs, VPN configurations, web server configurations, firewall connection settings.&lt;br /&gt;
|-&lt;br /&gt;
| [c] network connections associated with communications sessions are terminated after the defined period of inactivity. || Screen Share || VPN appliance/server logs, VPN configurations, web server configurations, frewall connection settings.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.10 – Key Management ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.10_Details|&#039;&#039;&#039;SC.L2-3.13.10&#039;&#039;&#039;]] Establish and manage cryptographic keys for cryptography employed in organizational systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] cryptographic keys are established whenever cryptography is employed. || Artifact || SSP, PKI/certificate management policy, configuration management.&lt;br /&gt;
|-&lt;br /&gt;
| [b] cryptographic keys are managed whenever cryptography is employed. || Artifact || SSP, PKI/certificate management policy, configuration management, access control policy.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.11 – CUI Encryption ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.11_Details|&#039;&#039;&#039;SC.L2-3.13.11&#039;&#039;&#039;]] Employ FIPS-validated cryptography when used to protect the confidentiality of CUI.&lt;br /&gt;
|-&lt;br /&gt;
| [a] FIPS-validated cryptography is employed to protect the confidentiality of CUI. || Screen Share || VPN, wireless, mobile devices, client certificates, server certificates, disk encryption, Outlook plugin, external mail, backup media, ePO server, removable storage, SAN, file compression; look for FIPS mode enabled on appliances.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.12 – Collaborative Device Control ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.12_Details|&#039;&#039;&#039;SC.L2-3.13.12&#039;&#039;&#039;]] Prohibit remote activation of collaborative computing devices and provide indication of devices in use to users present at the device.&lt;br /&gt;
|-&lt;br /&gt;
| [a] collaborative computing devices are identified. || Document || SSP, network diagrams.&lt;br /&gt;
|-&lt;br /&gt;
| [b] collaborative computing devices provide indication to users of devices in use. || Physical Review || Physical inspection of device.&lt;br /&gt;
|-&lt;br /&gt;
| [c] remote activation of collaborative computing devices is prohibited. || Screen Share || Collaboration device configuration/console.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.13 – Mobile Code ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.13_Details|&#039;&#039;&#039;SC.L2-3.13.13&#039;&#039;&#039;]] Control and monitor the use of mobile code.&lt;br /&gt;
|-&lt;br /&gt;
| [a] use of mobile code is controlled. || Screen Share || GPO settings, malware protection, software agent configurations, software development policies, code scanners, MDM configuration, firewall/secure web gateway/proxy config.&lt;br /&gt;
|-&lt;br /&gt;
| [b] use of mobile code is monitored. || Screen Share || SIEM/console monitoring.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.14 – Voice over Internet Protocol ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.14_Details|&#039;&#039;&#039;SC.L2-3.13.14&#039;&#039;&#039;]] Control and monitor the use of Voice over Internet Protocol (VoIP) technologies.&lt;br /&gt;
|-&lt;br /&gt;
| [a] use of Voice over Internet Protocol (VoIP) technologies is controlled. || Artifact || VLAN, ACL, firewall config, VoIP gateway/condenser configuration.&lt;br /&gt;
|-&lt;br /&gt;
| [b] use of Voice over Internet Protocol (VoIP) technologies is monitored. || Artifact || SIEM/VoIP console monitoring, session border controller.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.15 – Communications Authenticity ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.15_Details|&#039;&#039;&#039;SC.L2-3.13.15&#039;&#039;&#039;]] Protect the authenticity of communications sessions.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the authenticity of communications sessions is protected. || Screen Share || SSL, TLS, SMB3, SFTP, IPSec, SSH, Kerberos configs, MPLS, Network Access Control.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.16 – Data at Rest ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.16_Details|&#039;&#039;&#039;SC.L2-3.13.16&#039;&#039;&#039;]] Protect the confidentiality of CUI at rest.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the confidentiality of CUI at rest is protected. || Artifact || Full disk encryption, removable media encryption, SAN encryption, digital backups, mobile device encryption, third party offsite backup storage, cloud virtualization encryption, physical media storage policies.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== System and Information Integrity (SI) ==&lt;br /&gt;
=== SI.L2-3.14.1 – Flaw Remediation [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SI.L2-3.14.1_Details|&#039;&#039;&#039;SI.L2-3.14.1&#039;&#039;&#039;]] Identify, report, and correct information and information system flaws in a timely manner.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the time within which to identify system flaws is specified. || Document || SSP, patch management policy.&lt;br /&gt;
|-&lt;br /&gt;
| [b] system flaws are identified within the specified time frame. || Screen Share || Vulnerability management scanner output and scan policy configuration.&lt;br /&gt;
|-&lt;br /&gt;
| [c] the time within which to report system flaws is specified. || Document || SSP, patch management policy.&lt;br /&gt;
|-&lt;br /&gt;
| [d] system flaws are reported within the specified time frame. || Screen Share || ITSM/trouble tickets, vulnerability management scanner output.&lt;br /&gt;
|-&lt;br /&gt;
| [e] the time within which to correct system flaws is specified. || Document || SSP, patch management policy.&lt;br /&gt;
|-&lt;br /&gt;
| [f] system flaws are corrected within the specified time frame. || Screen Share || Vulnerability management scanner output and scan policy configuration.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SI.L2-3.14.2 – Malicious Code ProTection [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SI.L2-3.14.2_Details|&#039;&#039;&#039;SI.L2-3.14.2&#039;&#039;&#039;]] Provide protection from malicious code at appropriate locations within organizational information systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] designated locations for malicious code protection are identified. || Document || SSP, system protection policy, network diagrams, security architecture documents.&lt;br /&gt;
|-&lt;br /&gt;
| [b] protection from malicious code at designated locations is provided. || Screen Share || Endpoint security settings, email/web proxy gateways, firewall, IPS sensor, MDM configuration, Network Access Control.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SI.L2-3.14.3 – Security Alerts &amp;amp; Advisories ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SI.L2-3.14.3_Details|&#039;&#039;&#039;SI.L2-3.14.3&#039;&#039;&#039;]] Monitor system security alerts and advisories and take action in response.&lt;br /&gt;
|-&lt;br /&gt;
| [a] response actions to system security alerts and advisories are identified. || Document || SSP, vulnerability management policy, Incident Response Plan.&lt;br /&gt;
|-&lt;br /&gt;
| [b] system security alerts and advisories are monitored. || Artifact || Threat intelligence subscriptions, email advisories.&lt;br /&gt;
|-&lt;br /&gt;
| [c] actions in response to system security alerts and advisories are taken. || Artifact || ITSM/trouble tickets, user notifications, updates to firewall/IPS, etc.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SI.L2-3.14.4 – Update Malicious Code Protection [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SI.L2-3.14.4_Details|&#039;&#039;&#039;SI.L2-3.14.4&#039;&#039;&#039;]] Update malicious code protection mechanisms when new releases are available.&lt;br /&gt;
|-&lt;br /&gt;
| [a] malicious code protection mechanisms are updated when new releases are available. || Screen Share || Antivirus console dashboard, firewall AV, Email gateway signatures,proxy, IPS updates.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SI.L2-3.14.5 – System &amp;amp; File Scanning [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SI.L2-3.14.5_Details|&#039;&#039;&#039;SI.L2-3.14.5&#039;&#039;&#039;]] Perform periodic scans of the information system and real-time scans of files from external sources as files are downloaded, opened, or executed.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the frequency for malicious code scans is defined. || Document || SSP, vulnerability management policy.&lt;br /&gt;
|-&lt;br /&gt;
| [b] malicious code scans are performed with the defined frequency. || Screen Share || Consoles for AV (endpoints, servers, and file shares), firewall, email gateway, proxy, IPS, MDM configurations.&lt;br /&gt;
|-&lt;br /&gt;
| [c] real-time malicious code scans of files from external sources as files are downloaded, opened, or executed are performed. || Screen Share || Consoles for AV (endpoints, servers, and file shares), firewall, email gateway, proxy, IPS, MDM configurations.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SI.L2-3.14.6 – Monitor Communications for Attacks ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SI.L2-3.14.6_Details|&#039;&#039;&#039;SI.L2-3.14.6&#039;&#039;&#039;]] Monitor organizational systems, including inbound and outbound communications traffic, to detect attacks and indicators of potential attacks.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the system is monitored to detect attacks and indicators of potential attacks. || Screen Share || Firewall, IPS, endpoint protection, SIEM alerts and reports.&lt;br /&gt;
|-&lt;br /&gt;
| [b] inbound communications traffic is monitored to detect attacks and indicators of potential attacks. || Screen Share || Firewall, IPS, endpoint protection, SIEM alerts and reports.&lt;br /&gt;
|-&lt;br /&gt;
| [c] outbound communications traffic is monitored to detect attacks and indicators of potential attacks. || Screen Share || Firewall, IPS, endpoint protection, SIEM alerts and reports.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SI.L2-3.14.7 – Identify Unauthorized Use ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SI.L2-3.14.7_Details|&#039;&#039;&#039;SI.L2-3.14.7&#039;&#039;&#039;]] Identify unauthorized use of organizational systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] authorized use of the system is defined. || Document || AUP, SSP.&lt;br /&gt;
|-&lt;br /&gt;
| [b] unauthorized use of the system is identified. || Artifact || SIEM logs, endpoint protection console, IPS, Firewall.&lt;br /&gt;
|}&lt;/div&gt;</summary>
		<author><name>David</name></author>
	</entry>
	<entry>
		<id>https://cmmcwiki.org/index.php?title=Evidence_Collection_Approach&amp;diff=1619</id>
		<title>Evidence Collection Approach</title>
		<link rel="alternate" type="text/html" href="https://cmmcwiki.org/index.php?title=Evidence_Collection_Approach&amp;diff=1619"/>
		<updated>2026-07-20T01:39:11Z</updated>

		<summary type="html">&lt;p&gt;David: /* AU.L2-3.3.3 – Event Review */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;CMMC assessments and certification require substantial evidence and documentation. The following tables outline general guidelines for collecting evidence to assess control requirements and objectives. While these guidelines provide a structured approach, they are not the only means of conducting an accurate assessment. Assessors should exercise professional judgment and may employ alternative methods appropriate to the specific organizational context and circumstances.&lt;br /&gt;
&lt;br /&gt;
Evidence collection approaches are defined as:&lt;br /&gt;
* &#039;&#039;&#039;Documentation&#039;&#039;&#039;: Tangible materials containing information over which an organization has authority, including all types of written records and their copies.&lt;br /&gt;
* &#039;&#039;&#039;Artifacts&#039;&#039;&#039;: Tangible, reviewable records directly resulting from a practice or process being performed by a system or by personnel executing their role within that practice, control, or process.&lt;br /&gt;
* &#039;&#039;&#039;Physical Review&#039;&#039;&#039;: Direct on-site observation and examination of evidence.&lt;br /&gt;
* &#039;&#039;&#039;Screen Share&#039;&#039;&#039;: Real-time remote observation of a user demonstrating a task or process via shared computer screen, sometimes called &amp;quot;over-the-shoulder&amp;quot; review.&lt;br /&gt;
&lt;br /&gt;
DISCLAIMER: Evidence requirements vary significantly across assessment types. &#039;&#039;&#039;The examples provided are illustrative only and should be tailored to meet the specific adequacy and sufficiency standards of your particular assessment context.&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
For inquiries and reporting errors on this wiki, please [mailto:support@cmmctoolkit.org contact us]. Thank you.&lt;br /&gt;
&lt;br /&gt;
== Access Control (AC) ==&lt;br /&gt;
=== AC.L2-3.1.1 – Authorized Access Control [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.1_Details|&#039;&#039;&#039;AC.L2-3.1.1&#039;&#039;&#039;]] Limit information system access to authorized users, processes acting on behalf of authorized users, or devices (including other information systems).&lt;br /&gt;
|-&lt;br /&gt;
| [a] authorized users are identified. || Document || Document defining account request, approval, provisioning.&lt;br /&gt;
|-&lt;br /&gt;
| [b] processes acting on behalf of authorized users are identified. || Document || Document defining account request, approval, provisioning.&lt;br /&gt;
|-&lt;br /&gt;
| [c] devices (and other systems) authorized to connect to the system are identified. || Document || Document defining account request, approval, provisioning.&lt;br /&gt;
|-&lt;br /&gt;
| [d] system access is limited to authorized users. || Screen Share || Screen share showing login requirements are enforced. Example of an unauthorized user denied (unauthorized username entered at login).&lt;br /&gt;
|-&lt;br /&gt;
| [e] system access is limited to processes acting on behalf of authorized users. || Screen Share || Screenshot showing that service accounts are assigned to authorized users only; no rogue accounts without an authorized user are active.&lt;br /&gt;
|-&lt;br /&gt;
| [f] system access is limited to authorized devices (including other systems). || Screen Share || Screen share showing that all devices running are authorized; no rogue devices on the network.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.2 – Transaction &amp;amp; Function Control [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.2_Details|&#039;&#039;&#039;AC.L2-3.1.2&#039;&#039;&#039;]] Limit information system access to the types of transactions and functions that authorized users are permitted to execute.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the types of transactions and functions that authorized users are permitted to execute are defined. || Document || SSP, AUP, or IAM document that defines what authorized users can execute.&lt;br /&gt;
|-&lt;br /&gt;
| [b] system access is limited to the defined types of transactions and functions for authorized users. || Screen Share || Screenshot of security roles in AD or IAM or other directory-based identity-related services tool that shows transactions are as defined in the SSP or IAM document; privileged and non-privileged accounts need to be defined and identified in the artifact; screenshot of a non-privileged user trying to execute a privileged function.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.3 – Control CUI Flow ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.3_Details|&#039;&#039;&#039;AC.L2-3.1.3&#039;&#039;&#039;]] Control the flow of CUI in accordance with approved authorizations.&lt;br /&gt;
|-&lt;br /&gt;
| [a] information flow control policies are defined. || Document || SSP or other document describing the control of CUI on the network.&lt;br /&gt;
|-&lt;br /&gt;
| [b] methods and enforcement mechanisms for controlling the flow of CUI are defined. || Document || Document that defines the networking devices that are on the CUI network and answers what measures are in place to control the flow. List of firewalls, border and internal layer 3 devices, IDS/IPS, DLP, that process CUI.&lt;br /&gt;
|-&lt;br /&gt;
| [c] designated sources and destinations (e.g., networks, individuals, and devices) for CUI within the system and between interconnected systems are identified. || Artifact || Network diagram, data flow diagram, external system connection diagrams, document describing the policies for CUI on the network; listing of VLANs and subnets where CUI is authorized; document must describe source and authorized destinations.&lt;br /&gt;
|-&lt;br /&gt;
| [d] authorizations for controlling the flow of CUI are defined. || Document || Document that defines how CUI is to be controlled, such as an InfoSec plan, and/or network management plan.&lt;br /&gt;
|-&lt;br /&gt;
| [e] approved authorizations for controlling the flow of CUI are enforced. || Screen Share || Screenshots of firewall rules, ACLs, etc.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.4 – Separation of Duties ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.4_Details|&#039;&#039;&#039;AC.L2-3.1.4&#039;&#039;&#039;]] Separate the duties of individuals to reduce the risk of malevolent activity without collusion.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the duties of individuals requiring separation are defined. || Document || Document, SSP, account management policy, defining separation of duties by person or role.&lt;br /&gt;
|-&lt;br /&gt;
| [b] responsibilities for duties that require separation are assigned to separate individuals. || Screen Share || Screenshot showing that separation of duties is enforced by showing admin accounts are assigned to different people based on role.&lt;br /&gt;
|-&lt;br /&gt;
| [c] access privileges that enable individuals to exercise the duties that require separation are granted to separate individuals. || Screen Share || Screen shot showing an example such as a security manager can not log into a network device and change ACLs, or network admins can not access security logs in the SIEM tool.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.5 – Least Privilege ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.5_Details|&#039;&#039;&#039;AC.L2-3.1.5&#039;&#039;&#039;]] Employ the principle of least privilege, including for specific security functions and privileged accounts.&lt;br /&gt;
|-&lt;br /&gt;
| [a] privileged accounts are identified. || Document || &amp;quot;SSP or policy (documentation) identify what is considered a privileged account.&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| [b] access to privileged accounts is authorized in accordance with the principle of least privilege. || Artifact || An artifact that identifies the least amount of permissions associated with different types of privileged accounts are approved.&lt;br /&gt;
|-&lt;br /&gt;
| [c] security functions are identified. || Document || &amp;quot;SSP or policy (documentation) identifies what is considered a security account.&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| [d] access to security functions is authorized in accordance with the principle of least privilege. || Artifact || Artifact(s) that identify the least amount of permissions associated with different types of security accounts are approved.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.6 – Non-Privileged Account Use ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.6_Details|&#039;&#039;&#039;AC.L2-3.1.6&#039;&#039;&#039;]] Use non-privileged accounts or roles when accessing nonsecurity functions.&lt;br /&gt;
|-&lt;br /&gt;
| [a] nonsecurity functions are identified. || Document || SSP or account management document, AUP, that defines non-security functions.&lt;br /&gt;
|-&lt;br /&gt;
| [b] users are required to use non-privileged accounts or roles when accessing nonsecurity functions. || Screen Share || Screenshot showing that a privileged user tried to use their admin account to access a non-security function, such as a browser or email (whatever is defined in their policy) and was blocked.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.7 – Privileged Functions ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.7_Details|&#039;&#039;&#039;AC.L2-3.1.7&#039;&#039;&#039;]] Prevent non-privileged users from executing privileged functions and capture the execution of such functions in audit logs.&lt;br /&gt;
|-&lt;br /&gt;
| [a] privileged functions are defined. || Document || SSP or policy (documentation) that defines privileged functions.&lt;br /&gt;
|-&lt;br /&gt;
| [b] non-privileged users are defined. || Document || SSP or policy (documentation) that defines non-privileged users.&lt;br /&gt;
|-&lt;br /&gt;
| [c] non-privileged users are prevented from executing privileged functions. || Screen Share || Screen share that shows that a non-privileged user is not allowed to complete a privileged function (installing software).&lt;br /&gt;
|-&lt;br /&gt;
| [d] the execution of privileged functions is captured in audit logs. || Screen Share || Screen share that shows logs being captured of the execution of privileged functions.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.8 – Unsuccessful Logon Attempts ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.8_Details|&#039;&#039;&#039;AC.L2-3.1.8&#039;&#039;&#039;]] Limit unsuccessful logon attempts.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the means of limiting unsuccessful logon attempts is defined. || Document || SSP or policy (documentation) showing unsuccessful logon attempts settings and or policy.&lt;br /&gt;
|-&lt;br /&gt;
| [b] the defined means of limiting unsuccessful logon attempts is implemented. || Artifact || Artifact showing GPO / Policy for limiting logon attempts.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.9 – Privacy &amp;amp; Security Notices ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.9_Details|&#039;&#039;&#039;AC.L2-3.1.9&#039;&#039;&#039;]] Provide privacy and security notices consistent with applicable CUI rules.&lt;br /&gt;
|-&lt;br /&gt;
| [a] privacy and security notices required by CUI-specified rules are identified, consistent, and associated with the specific CUI category. || Document || SSP or policy (documentation) showing CUI-specified rules are identified, consistent, and associated with the specific CUI category.&lt;br /&gt;
|-&lt;br /&gt;
| [b] privacy and security notices are displayed. || Artifact || Artifact that shows a consent banner or screen that a user sees as they log in to the system.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.10 – Session Lock ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.10_Details|&#039;&#039;&#039;AC.L2-3.1.10&#039;&#039;&#039;]] Use session lock with pattern-hiding displays to prevent access and viewing of data after a period of inactivity.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the period of inactivity after which the system initiates a session lock is defined. || Document || SSP or policy (documentation) that defines the period of inactivity and when a session lock is defined.&lt;br /&gt;
|-&lt;br /&gt;
| [b] access to the system and viewing of data is prevented by initiating a session lock after the defined period of inactivity. || Artifact || Artifact that shows the setting of session lock (GPO or system policy or similar solution addressing the controls supporting centralized management and configuration of operating systems, applications, and users&#039; settings for the working environment of user accounts and computer accounts).&lt;br /&gt;
|-&lt;br /&gt;
| [c] previously visible information is concealed via a pattern-hiding display after the defined period of inactivity. || Document || Screenshot of GPO setting and configuration settings, or similar solution addressing the controls supporting centralized management and configuration of operating systems, applications, and users&#039; settings for the working environment of user accounts and computer accounts.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.11 – Session Termination ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.11_Details|&#039;&#039;&#039;AC.L2-3.1.11&#039;&#039;&#039;]] Terminate (automatically) a user session after a defined condition.&lt;br /&gt;
|-&lt;br /&gt;
| [a] conditions requiring a user session to terminate are defined. || Document || SSP or policy (documentation) that defines the conditions requiring a user session to be terminated.&lt;br /&gt;
|-&lt;br /&gt;
| [b] a user session is automatically terminated after any of the defined conditions. || Screen Share || Screen share showing GPO / VPN Settings that show when a session would be terminated (Idle time, max connection time).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.12 – Control Remote Access ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.12_Details|&#039;&#039;&#039;AC.L2-3.1.12&#039;&#039;&#039;]] Monitor and control remote access sessions.&lt;br /&gt;
|-&lt;br /&gt;
| [a] remote access sessions are permitted. || Document || SSP or policy (documentation) that defines remote access sessions.&lt;br /&gt;
|-&lt;br /&gt;
| [b] the types of permitted remote access are identified. || Document || SSP or policy (documentation) that defines remote access is permitted.&lt;br /&gt;
|-&lt;br /&gt;
| [c] remote access sessions are controlled. || Screen Share || Screen share that shows how the remote access is controlled (access session, and or groups).&lt;br /&gt;
|-&lt;br /&gt;
| [d] remote access sessions are monitored. || Screen Share || Screen share that shows how remote sessions are monitored (logs).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.13 – Remote Access Confidentiality ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.13_Details|&#039;&#039;&#039;AC.L2-3.1.13&#039;&#039;&#039;]] Employ cryptographic mechanisms to protect the confidentiality of remote access sessions.&lt;br /&gt;
|-&lt;br /&gt;
| [a] cryptographic mechanisms to protect the confidentiality of remote access sessions are identified. || Document || SSP or policy (documentation) that discusses the CUI rules, consistent, and associated with the specific CUI category; FIPS Cert # of appliance or application.&lt;br /&gt;
|-&lt;br /&gt;
| [b] cryptographic mechanisms to protect the confidentiality of remote access sessions are implemented. || Screen Share || Screenshot of VPN concentration that shows encryption is on and enabled (point-to-point, etc.).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.14 – Remote Access Routing ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.14_Details|&#039;&#039;&#039;AC.L2-3.1.14&#039;&#039;&#039;]] Route remote access via managed access control points.&lt;br /&gt;
|-&lt;br /&gt;
| [a] managed access control points are identified and implemented. || Screen Share || Screen share that shows access control points (groups and/or users).&lt;br /&gt;
|-&lt;br /&gt;
| [b] remote access is routed through managed network access control points. || Screen Share || Screen share that shows access control points and how they are managed.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.15 – Privileged Remote Access ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.15_Details|&#039;&#039;&#039;AC.L2-3.1.15&#039;&#039;&#039;]] Authorize remote execution of privileged commands and remote access to security-relevant information.&lt;br /&gt;
|-&lt;br /&gt;
| [a] privileged commands authorized for remote execution are identified. || Document || SSP or policy (documentation) that defines what is authorized to be executed remotely and how that is handled.&lt;br /&gt;
|-&lt;br /&gt;
| [b] security-relevant information authorized to be accessed remotely is identified. || Document || SSP or policy (documentation) that defines what can be accessed remotely and what procedures are implemented to allow this (RDP, jump box).&lt;br /&gt;
|-&lt;br /&gt;
| [c] the execution of the identified privileged commands via remote access is authorized. || Artifact || Screen share that shows who has access to perform privileged commands a remotely (access groups for privileged accounts).&lt;br /&gt;
|-&lt;br /&gt;
| [d] access to the identified security-relevant information via remote access is authorized. || Artifact || Screen share that shows the routing of remote access and how it is monitored and how many locations (Firewall, VPN Concentrator).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.16 – Wireless Access Authorization ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.16_Details|&#039;&#039;&#039;AC.L2-3.1.16&#039;&#039;&#039;]] Authorize wireless access prior to allowing such connections.&lt;br /&gt;
|-&lt;br /&gt;
| [a] wireless access points are identified. || Document || SSP, network administration document.&lt;br /&gt;
|-&lt;br /&gt;
| [b] wireless access is authorized prior to allowing such connections. || Screen Share || Authorization profile(s) in Wireless Access Controller or Identity Manager (i.e. Cisco ISE).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.17 – Wireless Access Protection ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.17_Details|&#039;&#039;&#039;AC.L2-3.1.17&#039;&#039;&#039;]] Protect wireless access using authentication and encryption.&lt;br /&gt;
|-&lt;br /&gt;
| [a] wireless access to the system is protected using authentication. || Screen Share || Security page (or similar) of a Wireless Access Controller.&lt;br /&gt;
|-&lt;br /&gt;
| [b] wireless access to the system is protected using encryption. || Screen Share || Security page (or similar) of a Wireless Access Controller.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.18 – Mobile Device Connection ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.18_Details|&#039;&#039;&#039;AC.L2-3.1.18&#039;&#039;&#039;]] Control connection of mobile devices.&lt;br /&gt;
|-&lt;br /&gt;
| [a] mobile devices that process, store, or transmit CUI are identified. || Document || SSP, Mobile Device Policy.&lt;br /&gt;
|-&lt;br /&gt;
| [b] mobile device connections are authorized. || Artifact || Authorization profile(s) in Wireless Access Controller or Identity Manager (i.e. Cisco ISE).&lt;br /&gt;
|-&lt;br /&gt;
| [c] mobile device connections are monitored and logged. || Screen Share || Mobile device logs within the MDM, log intake (sources) configuration (within SIEM) showing MDM is feeding logs to the SIEM.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.19 – Encrypt CUI on Mobile ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.19_Details|&#039;&#039;&#039;AC.L2-3.1.19&#039;&#039;&#039;]] Encrypt CUI on mobile devices and mobile computing platforms.&lt;br /&gt;
|-&lt;br /&gt;
| [a] mobile devices and mobile computing platforms that process, store, or transmit CUI are identified. || Document || SSP, Mobile Device Policy.&lt;br /&gt;
|-&lt;br /&gt;
| [b] encryption is employed to protect CUI on identified mobile devices and mobile computing platforms. || Screen Share || Security policy page in MDM showing how encryption are enforced on mobile device. If no MDM or MDM doesn&#039;t enforce encryption, then validate if the devices used are on the list of devices with native FIPS approved validation.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.20 – External Connections [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.20_Details|&#039;&#039;&#039;AC.L2-3.1.20&#039;&#039;&#039;]] Verify and control/limit connections to and use of external information systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] connections to external systems are identified. || Document || SSP, Systems Interconnection Agreements, SLA.&lt;br /&gt;
|-&lt;br /&gt;
| [b] the use of external systems is identified. || Document || SSP, Systems Interconnection Agreements, SLA.&lt;br /&gt;
|-&lt;br /&gt;
| [c] connections to external systems are verified. || Artifact || SLA for external systems, memorandum for interconnection, information to prove that any cloud solution is at FedRAMP impact level of moderate or higher (i.e. license information, screenshot of AWS cloud dashboard, purchase order document).&lt;br /&gt;
|-&lt;br /&gt;
| [d] the use of external systems is verified. || Artifact || SLA for external systems, memorandum for interconnection, information to prove that any cloud solution is at FedRAMP impact level of moderate or higher (i.e. license information, screenshot of AWS cloud dashboard, purchase order document).&lt;br /&gt;
|-&lt;br /&gt;
| [e] connections to external systems are controlled/limited. || Screen Share || Firewall ruleset for controlling access to cloud service or external system.&lt;br /&gt;
|-&lt;br /&gt;
| [f] the use of external systems is controlled/limited. || Screen Share || Firewall ruleset for controlling access to cloud service or external system.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.21 – Portable Storage Use ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.21_Details|&#039;&#039;&#039;AC.L2-3.1.21&#039;&#039;&#039;]] Limit use of portable storage devices on external systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the use of portable storage devices containing CUI on external systems is identified and documented. || Document || SSP, Removable Media Policy, Acceptable Use Policy (with emphasis on portable media use).&lt;br /&gt;
|-&lt;br /&gt;
| [b] limits on the use of portable storage devices containing CUI on external systems are defined. || Document || SSP, Removable Media Policy, Acceptable Use Policy (with emphasis on portable media use).&lt;br /&gt;
|-&lt;br /&gt;
| [c] the use of portable storage devices containing CUI on external systems is limited as defined. || Document || SSP, Removable Media Policy, Acceptable Use Policy (with emphasis on portable media use).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.22 – Control Public Information [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.22_Details|&#039;&#039;&#039;AC.L2-3.1.22&#039;&#039;&#039;]] Control information posted or processed on publicly accessible information systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] individuals authorized to post or process information on publicly accessible systems are identified. || Document || SSP, Website Governance Plan, Information Release Document.&lt;br /&gt;
|-&lt;br /&gt;
| [b] procedures to ensure CUI is not posted or processed on publicly accessible systems are identified. || Document || SSP, Website Governance Plan, Information Release Document.&lt;br /&gt;
|-&lt;br /&gt;
| [c] a review process is in place prior to posting of any content to publicly accessible systems. || Artifact || &amp;quot;Information release approval process, i.e. chain of email communication from originator, approver, and final decision (may or may not include individual authorized to post); &lt;br /&gt;
SharePoint/electronic or paper form/ ticket system showing information flow between requestor and approver (may or may not include  individual authorized to post).&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| [d] content on publicly accessible systems is reviewed to ensure that it does not include CUI. || Artifact || Incident response process, web design/update/modification SOP etc.&lt;br /&gt;
|-&lt;br /&gt;
| [e] mechanisms are in place to remove and address improper posting of CUI. || Artifact || Incident response process, web design/update/modification SOP etc.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Awareness and Training (AT) ==&lt;br /&gt;
=== AT.L2-3.2.1 – Role-Based Risk Awareness ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AT.L2-3.2.1_Details|&#039;&#039;&#039;AT.L2-3.2.1&#039;&#039;&#039;]] Ensure that managers, systems administrators, and users of organizational systems are made aware of the security risks associated with their activities and of the applicable policies, standards, and procedures related to the security of those systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] security risks associated with organizational activities involving CUI are identified. || Document || Policy of Security Awareness Training; Security Awareness Training Briefing.&lt;br /&gt;
|-&lt;br /&gt;
| [b] policies, standards, and procedures related to the security of the system are identified. || Document || Acceptable Use Policy, Policy/Procedures/Instruction related to the security of the system.&lt;br /&gt;
|-&lt;br /&gt;
| [c] managers, systems administrators, and users of the system are made aware of the security risks associated with their activities. || Artifact || Security Training Brief, training records.&lt;br /&gt;
|-&lt;br /&gt;
| [d] managers, systems administrators, and users of the system are made aware of the applicable policies, standards, and procedures related to the security of the system. || Artifact || Policies, standards and procedures for employees within training (completed training report).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AT.L2-3.2.2 – Role-Based Training ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AT.L2-3.2.2_Details|&#039;&#039;&#039;AT.L2-3.2.2&#039;&#039;&#039;]] Ensure that personnel are trained to carry out their assigned information security-related duties and responsibilities.|-&lt;br /&gt;
|-&lt;br /&gt;
| [a] information security-related duties, roles, and responsibilities are defined. || Document || Policy/Procedures/Instruction, Job Role Matrix, Position Descriptions, User Roles.&lt;br /&gt;
|-&lt;br /&gt;
| [b] information security-related duties, roles, and responsibilities are assigned to designated personnel. || Artifact || Screenshot of breakout of different roles/permissions assigned to individuals (i.e. ActiveDirectory); Privilege Access Agreement.&lt;br /&gt;
|-&lt;br /&gt;
| [c] personnel are adequately trained to carry out their assigned information security-related duties, roles, and responsibilities. || Artifact || Screenshot of tool and/or training specifying security specific roles, duties and responsibilities; Screenshot of required certifications (i.e. Sec+, CISSP).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AT.L2-3.2.3 – Insider Threat Awareness ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AT.L2-3.2.3_Details|&#039;&#039;&#039;AT.L2-3.2.3&#039;&#039;&#039;]] Provide security awareness training on recognizing and reporting potential indicators of insider threat.&lt;br /&gt;
|-&lt;br /&gt;
| [a] potential indicators associated with insider threats are identified. || Document || Insidert Threat Policy/Procedures/Instruction; Insider Threat Training/Briefing.&lt;br /&gt;
|-&lt;br /&gt;
| [b] security awareness training on recognizing and reporting potential indicators of insider threat is provided to managers and employees. || Artifact || Screenshot of training records showing completion of Insider Threat training, emails showing completion of Insider Threat training, Screenshot of certificate showing completion with individual&#039;s name.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Audit and Accountability (AU) ==&lt;br /&gt;
=== AU.L2-3.3.1 – System Auditing ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AU.L2-3.3.1_Details|&#039;&#039;&#039;AU.L2-3.3.1&#039;&#039;&#039;]] Create and retain system audit logs and records to the extent needed to enable the monitoring, analysis, investigation, and reporting of unlawful or unauthorized system activity.&lt;br /&gt;
|-&lt;br /&gt;
| [a] audit logs needed (i.e., event types to be logged) to enable the monitoring, analysis, investigation, and reporting of unlawful or unauthorized system activity are specified. || Document || SSP, policy, or auditing and logging process that defines specific types of events to be logged.&lt;br /&gt;
|-&lt;br /&gt;
| [b] the content of audit records needed to support monitoring, analysis, investigation, and reporting of unlawful or unauthorized system activity is defined. || Document || SSP, policy, or auditing and logging process that defines specific content of audit records/files.&lt;br /&gt;
|-&lt;br /&gt;
| [c] audit records are created (generated). || Screen Share || Screen share of tool that shows logs are generated for all systems.&lt;br /&gt;
|-&lt;br /&gt;
| [d] audit records, once created, contain the defined content. || Screen Share || Screen share of tool that shows logs contain defined content as defined in SSP, policy, or procedures.&lt;br /&gt;
|-&lt;br /&gt;
| [e] retention requirements for audit records are defined. || Document || SSP, Polocy, or Auditing and logging process that describes how long records are kept.&lt;br /&gt;
|-&lt;br /&gt;
| [f] audit records are retained as defined. || Screen Share || Screen share of tool that shows records and audit content retained at a minimum as defined.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AU.L2-3.3.2 – User Accountability ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AU.L2-3.3.2_Details|&#039;&#039;&#039;AU.L2-3.3.2&#039;&#039;&#039;]] Ensure that the actions of individual system users can be uniquely traced to those users so they can be held accountable for their actions.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the content of the audit records needed to support the ability to uniquely trace users to their actions is defined. || Document || SSP, policy, or process that defines actions traced back to individuals.&lt;br /&gt;
|-&lt;br /&gt;
| [b] audit records, once created, contain the defined content. || Screen Share || Screen share of tool that shows audit records traced to specific users/roles.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AU.L2-3.3.3 – Event Review ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AU.L2-3.3.3_Details|&#039;&#039;&#039;AU.L2-3.3.3&#039;&#039;&#039;]] Review and update logged events.&lt;br /&gt;
|-&lt;br /&gt;
| [a] a process for determining when to review logged events is defined. || Document || SSP, policy, or documented process that shows frequency of when to review types of logged events.&lt;br /&gt;
|-&lt;br /&gt;
| [b] event types being logged are reviewed in accordance with the defined review process. || Document || Evidence through a documented method such as meeting minutes, CAB minutes, etc. of log sources and log events being logged at the defined frequency.&lt;br /&gt;
|-&lt;br /&gt;
| [c] event types being logged are updated based on the review. || Artifact || Evidence of implementation based on the results of the review of logged events/sources through a ticket, meeting minutes, or screen share of the tool that shows changes implemented (finetuning).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AU.L2-3.3.4 – Audit Failure Alerting ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AU.L2-3.3.4_Details|&#039;&#039;&#039;AU.L2-3.3.4&#039;&#039;&#039;]] Alert in the event of an audit logging process failure.&lt;br /&gt;
|-&lt;br /&gt;
| [a] personnel or roles to be alerted in the event of an audit logging process failure are identified. || Document || SSP, policy, or procedure that shows who needs to be notified in case of an audit failure.&lt;br /&gt;
|-&lt;br /&gt;
| [b] types of audit logging process failures for which alert will be generated are defined. || Document || SSP, policy, or procedure that shows what types of failure will generate notifications.&lt;br /&gt;
|-&lt;br /&gt;
| [c] identified personnel or roles are alerted in the event of an audit logging process failure. || Artifact || Artifact such as email or ticket that shows the identified personnel were alerted of any audit/logging process failure as defined.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AU.L2-3.3.5 – Audit Correlation ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AU.L2-3.3.5_Details|&#039;&#039;&#039;AU.L2-3.3.5&#039;&#039;&#039;]] Correlate audit record review, analysis, and reporting processes for investigation and response to indications of unlawful, unauthorized, suspicious, or unusual activity.&lt;br /&gt;
|-&lt;br /&gt;
| [a] audit record review, analysis, and reporting processes for investigation and response to indications of unlawful, unauthorized, suspicious, or unusual activity are defined. || Document || SSP, policy, or procedure covering audit logging, monitoring, and reporting.&lt;br /&gt;
|-&lt;br /&gt;
| [b] defined audit record review, analysis, and reporting processes are correlated. || Artifact || Artifact showing an audit event and the resultant corrective action or actions to the event; this can be a Help Desk ticket, meeting notes, or a change control board items showing the event and any corrective action taken.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AU.L2-3.3.6 – Reduction &amp;amp; Reporting ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AU.L2-3.3.6_Details|&#039;&#039;&#039;AU.L2-3.3.6&#039;&#039;&#039;]] Provide audit record reduction and report generation to support on-demand analysis and reporting.&lt;br /&gt;
|-&lt;br /&gt;
| [a] an audit record reduction capability that supports on-demand analysis is provided. || Screen Share || Screen share of the logging environment where an event can be selected and traced back to a specific device, or dashboard showing realtime event analysis.&lt;br /&gt;
|-&lt;br /&gt;
| [b] a report generation capability that supports on-demand reporting is provided. || Screen Share || Screen share showing the generation of an on demand report.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AU.L2-3.3.7 – Authoritative Time Source ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AU.L2-3.3.7_Details|&#039;&#039;&#039;AU.L2-3.3.7&#039;&#039;&#039;]] Provide a system capability that compares and synchronizes internal system clocks with an authoritative source to generate time stamps for audit records.&lt;br /&gt;
|-&lt;br /&gt;
| [a] internal system clocks are used to generate time stamps for audit records. || Screen Share || Screen share showing the NTP settings of a windows, Unix, Linux device; a screen share showing the NTP settings of network appliances.&lt;br /&gt;
|-&lt;br /&gt;
| [b] an authoritative source with which to compare and synchronize internal system clocks is specified. || Document || SSP or policy indicating that devices need to be synched to a local authoritative time device that is synched with an authoritative time service.&lt;br /&gt;
|-&lt;br /&gt;
| [c] internal system clocks used to generate time stamps for audit records are compared to and synchronized with the specified authoritative time source. || Screen Share || Screen share showing device logging appliance time is point to the appropriate authoritative time server.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AU.L2-3.3.8 – Audit Protection ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AU.L2-3.3.8_Details|&#039;&#039;&#039;AU.L2-3.3.8&#039;&#039;&#039;]] Protect audit information and audit logging tools from unauthorized access, modification, and deletion.&lt;br /&gt;
|-&lt;br /&gt;
| [a] audit information is protected from unauthorized access. || Screen Share || Screen share showing operating system permissions on the audit folders being restricted to appropriate users.&lt;br /&gt;
|-&lt;br /&gt;
| [b] audit information is protected from unauthorized modification. || Screen Share || Screen share showing operating system permissions on the audit folders being restricted to appropriate users.&lt;br /&gt;
|-&lt;br /&gt;
| [c] audit information is protected from unauthorized deletion. || Screen Share || Screen share showing operating system permissions on the audit folders being restricted to appropriate users.&lt;br /&gt;
|-&lt;br /&gt;
| [d] audit logging tools are protected from unauthorized access. || Screen Share || Artifact showing access permissions in the SIEM tool.&lt;br /&gt;
|-&lt;br /&gt;
| [e] audit logging tools are protected from unauthorized modification. || Screen Share || Artifact showing update permissions in the SIEM tool.&lt;br /&gt;
|-&lt;br /&gt;
| [f] audit logging tools are protected from unauthorized deletion. || Screen Share || Artifact showing delete permissions in the SIEM tool.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AU.L2-3.3.9 – Audit Management ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AU.L2-3.3.9_Details|&#039;&#039;&#039;AU.L2-3.3.9&#039;&#039;&#039;]] Limit management of audit logging functionality to a subset of privileged users.&lt;br /&gt;
|-&lt;br /&gt;
| [a] a subset of privileged users granted access to manage audit logging functionality is defined. || Document || SSP or policy indicating which users or groups have access to audit logs.&lt;br /&gt;
|-&lt;br /&gt;
| [b] management of audit logging functionality is limited to the defined subset of privileged users. || Screen Share || Artifact showing SIEM or OS folder permissions (this should be limited to the assigned users or groups); artifact showing an ACL setting in SIEM tool in regards to logs.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Configuration Management (CM) ==&lt;br /&gt;
=== CM.L2-3.4.1 – System Baselining ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_CM.L2-3.4.1_Details|&#039;&#039;&#039;CM.L2-3.4.1&#039;&#039;&#039;]] Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles.&lt;br /&gt;
|-&lt;br /&gt;
| [a] a baseline configuration is established. || Document || Documentation showing or explaining standard imaging process (how standard images are deployed and where  they are stored).&lt;br /&gt;
|-&lt;br /&gt;
| [b] the baseline configuration includes hardware, software, firmware, and documentation. || Artifact || Screenshot of repository of where images are maintained and information relating to hardware, software, and firmware.&lt;br /&gt;
|-&lt;br /&gt;
| [c] the baseline configuration is maintained (reviewed and updated) throughout the system development life cycle. || Artifact || Screenshot/evidence displaying management of baseline configurations (how often they are being managed as stated).&lt;br /&gt;
|-&lt;br /&gt;
| [d] a system inventory is established. || Document || Screenshot/evidence displaying inventory listing of approved products for use.&lt;br /&gt;
|-&lt;br /&gt;
| [e] the system inventory includes hardware, software, firmware, and documentation. || Artifact || Screeenshot/evidence displaying inventory listing of approved products and versions permitted for use.&lt;br /&gt;
|-&lt;br /&gt;
| [f] the inventory is maintained (reviewed and updated) throughout the system development life cycle. || Artifact || Screeenshot/evidence displaying management of baseline configurations (How often and are they being managed as stated.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== CM.L2-3.4.2 – Security Configuration Enforcement ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_CM.L2-3.4.2_Details|&#039;&#039;&#039;CM.L2-3.4.2&#039;&#039;&#039;]] Establish and enforce security configuration settings for information technology products employed in organizational systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] security configuration settings for information technology products employed in the system are established and included in the baseline configuration. || Document || Documentation explaining methodology used by organization to create secure baselines (STIGs, benchmarks).&lt;br /&gt;
|-&lt;br /&gt;
| [b] security configuration settings for information technology products employed in the system are enforced. || Artifact || Evidence of tool/s used to enforce security configurations to ensure images used are free from modification unless authorized.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== CM.L2-3.4.3 – System Change Management ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_CM.L2-3.4.3_Details|&#039;&#039;&#039;CM.L2-3.4.3&#039;&#039;&#039;]] Track, review, approve or disapprove, and log changes to organizational systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] changes to the system are tracked. || Artifact || Evidence of IT Service Management tool / process used to track system changes.&lt;br /&gt;
|-&lt;br /&gt;
| [b] changes to the system are reviewed. || Artifact || Evidence of IT Service Management tool / process used to review system changes.&lt;br /&gt;
|-&lt;br /&gt;
| [c] changes to the system are approved or disapproved. || Artifact || Evidence of IT Service Management tool / process used to approve/disapprove system changes.&lt;br /&gt;
|-&lt;br /&gt;
| [d] changes to the system are logged. || Artifact || Evidence of IT Service Management tool / process used to log system changes.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== CM.L2-3.4.4 – Security Impact Analysis ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_CM.L2-3.4.4_Details|&#039;&#039;&#039;CM.L2-3.4.4&#039;&#039;&#039;]] Analyze the security impact of changes prior to implementation.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the security impact of changes to the system is analyzed prior to implementation. || Artifact || Document explaining that security impact analysis of proposed changes to a system is conducted prior to implementation.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== CM.L2-3.4.5 – Access Restrictions for Change ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_CM.L2-3.4.5_Details|&#039;&#039;&#039;CM.L2-3.4.5&#039;&#039;&#039;]] Define, document, approve, and enforce physical and logical access restrictions associated with changes to organizational systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] physical access restrictions associated with changes to the system are defined. || Document || Document explaining the process of how physical access restrictions are defined for an individuals ability to make system changes.&lt;br /&gt;
|-&lt;br /&gt;
| [b] physical access restrictions associated with changes to the system are documented. || Document || Document explaining the process of how physical access restrictions are defined for an individuals ability to make system changes are documented; access request process.&lt;br /&gt;
|-&lt;br /&gt;
| [c] physical access restrictions associated with changes to the system are approved. || Artifact || Evidence of process of how physical access to systems are granted (i.e. physical access request sample).&lt;br /&gt;
|-&lt;br /&gt;
| [d] physical access restrictions associated with changes to the system are enforced. || Physical Review || Evidence of process of how physical access to systems are enforced (physical access system).&lt;br /&gt;
|-&lt;br /&gt;
| [e] logical access restrictions associated with changes to the system are defined. || Document || Document explaining the process of how logical access restrictions are defined for an individual&#039;s ability to make system changes.&lt;br /&gt;
|-&lt;br /&gt;
| [f] logical access restrictions associated with changes to the system are documented. || Document || Document explaining the process of how logical access restrictions are defined for an individual&#039;s ability to make system changes are documented.&lt;br /&gt;
|-&lt;br /&gt;
| [g] logical access restrictions associated with changes to the system are approved. || Artifact || Evidence of process of how logical access to systems are granted.&lt;br /&gt;
|-&lt;br /&gt;
| [h] logical access restrictions associated with changes to the system are enforced. || Artifact || Evidence of process of how logical access to systems are enforced.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== CM.L2-3.4.6 – Least Functionality ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_CM.L2-3.4.6_Details|&#039;&#039;&#039;CM.L2-3.4.6&#039;&#039;&#039;]] Employ the principle of least functionality by configuring organizational systems to provide only essential capabilities.&lt;br /&gt;
|-&lt;br /&gt;
| [a] essential system capabilities are defined based on the principle of least functionality. || Document || Documentation explaining how systems are configured to utilize the principle of least functionality for designated users.&lt;br /&gt;
|-&lt;br /&gt;
| [b] the system is configured to provide only the defined essential capabilities. || Screen Share || Evidence displaying how systems are configured to utilize the principle of least functionality for designated users; disabled service settings, accepted standards for hardening (CIS benchmarks, etc.).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== CM.L2-3.4.7 – Nonessential Functionality ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_CM.L2-3.4.7_Details|&#039;&#039;&#039;CM.L2-3.4.7&#039;&#039;&#039;]] Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services.&lt;br /&gt;
|-&lt;br /&gt;
| [a] essential programs are defined. || Document || Documented essential programs specified; build documents; software center; SSP.&lt;br /&gt;
|-&lt;br /&gt;
| [b] the use of nonessential programs is defined. || Document || Documented listing of nonessential programs (whatever is NOT specified in [a]); AUP/User Agreement may identify nonessential use/programs.&lt;br /&gt;
|-&lt;br /&gt;
| [c] the use of nonessential programs is restricted, disabled, or prevented as defined. || Screen Share || Tool used to restrict nonessential programs displays restrictions as defined (McAfee ePO settings, Carbon Black rules, etc.).&lt;br /&gt;
|-&lt;br /&gt;
| [d] essential functions are defined. || Document || Documented essential functions are specified.&lt;br /&gt;
|-&lt;br /&gt;
| [e] the use of nonessential functions is defined. || Document || Documented nonessential functions are specified.&lt;br /&gt;
|-&lt;br /&gt;
| [f] the use of nonessential functions is restricted, disabled, or prevented as defined. || Screen Share || Tool used to restrict essential/nonessential functions displays restrictions as defined.&lt;br /&gt;
|-&lt;br /&gt;
| [g] essential ports are defined. || Document || Documented essential ports are specified.&lt;br /&gt;
|-&lt;br /&gt;
| [h] the use of nonessential ports is defined. || Document || Documented nonessential ports functions are specified.&lt;br /&gt;
|-&lt;br /&gt;
| [i] the use of nonessential ports is restricted, disabled, or prevented as defined. || Screen Share || Tool used to restrict essential/nonessential ports displays restrictions as defined (FW rules; McAfee; GPO, etc.).&lt;br /&gt;
|-&lt;br /&gt;
| [j] essential protocols are defined. || Document || Documented essential protocols are specified.&lt;br /&gt;
|-&lt;br /&gt;
| [k] the use of nonessential protocols is defined. || Document || Documented nonessential protocols functions are specified.&lt;br /&gt;
|-&lt;br /&gt;
| [l] the use of nonessential protocols is restricted, disabled, or prevented as defined. || Screen Share || Tool used to restrict essential/nonessential protocols displays restrictions as defined (FW rules; GPO, etc.).&lt;br /&gt;
|-&lt;br /&gt;
| [m] essential services are defined. || Document || Documented essential services specified.&lt;br /&gt;
|-&lt;br /&gt;
| [n] the use of nonessential services is defined. || Document || Documented nonessential services functions are specified.&lt;br /&gt;
|-&lt;br /&gt;
| [o] the use of nonessential services is restricted, disabled, or prevented as defined. || Screen Share || Tool used to restrict essential/nonessential services displays restrictions as defined.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== CM.L2-3.4.8 – Application Execution Policy ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_CM.L2-3.4.8_Details|&#039;&#039;&#039;CM.L2-3.4.8&#039;&#039;&#039;]] Apply deny-by-exception (blacklisting) policy to prevent the use of unauthorized software or deny-all, permit-by-exception (whitelisting) policy to allow the execution of authorized software.&lt;br /&gt;
|-&lt;br /&gt;
| [a] a policy specifying whether whitelisting or blacklisting is to be implemented is specified. || Document || Documentation explaining whitelisting or blacklisting process.&lt;br /&gt;
|-&lt;br /&gt;
| [b] the software allowed to execute under whitelisting or denied use under blacklisting is specified. || Document || Documentation explaining whitelisting or blacklisting process for software.&lt;br /&gt;
|-&lt;br /&gt;
| [c] whitelisting to allow the execution of authorized software or blacklisting to prevent the use of unauthorized software is implemented as specified. || Screen Share || Tool used for whitelisting or blacklisting for software shows capability of restricting/authorizing software (Carbon Black dashboard, &amp;quot;SW Store&amp;quot;, web proxies, DNS Blackhole, etc.).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== CM.L2-3.4.9 – User-Installed Software ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_CM.L2-3.4.9_Details|&#039;&#039;&#039;CM.L2-3.4.9&#039;&#039;&#039;]] Control and monitor user-installed software.&lt;br /&gt;
|-&lt;br /&gt;
| [a] a policy for controlling the installation of software by users is established. || Document || Documented software authorization process or methodology for approval.&lt;br /&gt;
|-&lt;br /&gt;
| [b] installation of software by users is controlled based on the established policy. || Screen Share || Evidence that approval/restriction in installation of software by authorized personnel is implemented as specified (AUP, GPO, etc.).&lt;br /&gt;
|-&lt;br /&gt;
| [c] installation of software by users is monitored. || Screen Share || Evidence that installation of software by authorized personnel is monitored (SCCM groups, SW Center, etc.).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Identification and Authentication (IA) ==&lt;br /&gt;
=== IA.L2-3.5.1 – Identification [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IA.L2-3.5.1_Details|&#039;&#039;&#039;IA.L2-3.5.1&#039;&#039;&#039;]] Identify information system users, processes acting on behalf of users, or devices.&lt;br /&gt;
|-&lt;br /&gt;
| [a] system users are identified. || Document || Based on what is defined in their documentation (SSP, AUP, Policy, SOP), request to see a sample of non-privileged/privileged users in AD OU group (overlaps with 3.1.1 and 3.1.5).&lt;br /&gt;
|-&lt;br /&gt;
| [b] processes acting on behalf of users are identified. || Screen Share || Based on what is defined in their documentation (SSP, AUP, Policy, SOP), request to see a sample of service accounts in AD OU group (overlaps with 3.1.1 and 3.1.5).&lt;br /&gt;
|-&lt;br /&gt;
| [c] devices accessing the system are identified. || Screen Share || Based on what is defined in their documentation (SSP, AUP, Policy, SOP), request to see a sample of domain-joined workstation &amp;amp; servers in AD OU group (overlaps with 3.1.1 and 3.1.5).  For network devices, request screen share/artifact to show how they are identified on the enterprise network.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IA.L2-3.5.2 – Authentication [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IA.L2-3.5.2_Details|&#039;&#039;&#039;IA.L2-3.5.2&#039;&#039;&#039;]] Authenticate (or verify) the identities of those users, processes, or devices, as a prerequisite to allowing access to organizational information systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the identity of each user is authenticated or verified as a prerequisite to system access. || Screen Share || If the user logs in with non-privileged account during other demoes and then a privileged account, then this should be satisfied.  If screen share is unavailable, request logs to show successful and unsuccessful login by privileged and non-privilged users.&lt;br /&gt;
|-&lt;br /&gt;
| [b] the identity of each process acting on behalf of a user is authenticated or verified as a prerequisite to system access. || Screen Share || Request a log that shows successful/unsuccessful service account trying to log on to company&#039;s asset.&lt;br /&gt;
|-&lt;br /&gt;
| [c] the identity of each device accessing or connecting to the system is authenticated or verified as a prerequisite to system access. || Screen Share || Request a log that shows domain-joined workstation/server authenticating to AD (focus on the MAC/IP address/hostname).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IA.L2-3.5.3 – Multifactor Authentication ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IA.L2-3.5.3_Details|&#039;&#039;&#039;IA.L2-3.5.3&#039;&#039;&#039;]] Use multifactor authentication for local and network access to privileged accounts and for network access to non-privileged accounts.&lt;br /&gt;
|-&lt;br /&gt;
| [a] privileged accounts are identified. || Screen Share|| Based on what is defined in their documentation, request to see a sample of privileged users in AD OU group.  Overlaps with 3.1.5.  Screenshot/screen share to show implementation is enforced.&lt;br /&gt;
|-&lt;br /&gt;
| [b] multifactor authentication is implemented for local access to privileged accounts. || Document || SSP, AUP, Policy, SOP that defines that MFA is needed for privileged local access.&lt;br /&gt;
|-&lt;br /&gt;
| [c] multifactor authentication is implemented for network access to privileged accounts. || Screen Share || Within the MFA implementation mechanism, show that privileged users are forced to use MFA;  Screenshot/Screen share to show implementation is enforced.&lt;br /&gt;
|-&lt;br /&gt;
| [d] multifactor authentication is implemented for network access to non-privileged accounts. || Screen Share || Within the MFA implementation mechanism, show that non-privileged users are forced to use MFA; Screenshot/Screen share to show implementation is enforced.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IA.L2-3.5.4 – Replay-Resistant Authentication ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IA.L2-3.5.4_Details|&#039;&#039;&#039;IA.L2-3.5.4&#039;&#039;&#039;]] Employ replay-resistant authentication mechanisms for network access to privileged and non-privileged accounts.&lt;br /&gt;
|-&lt;br /&gt;
| [a] replay-resistant authentication mechanisms are implemented for network account access to privileged and non-privileged accounts. || Screen Share || Show the GPO setting that enforces Kerberos within AD.  If MFA is used, show the implementation to enforce replay resistant techniques.  For non-windows, show the technical solution to enforce replay resistant attacks.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IA.L2-3.5.5 – Identifier Reuse ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IA.L2-3.5.5_Details|&#039;&#039;&#039;IA.L2-3.5.5&#039;&#039;&#039;]] Prevent reuse of identifiers for a defined period.&lt;br /&gt;
|-&lt;br /&gt;
| [a] a period within which identifiers cannot be reused is defined. || Document || SSP, policies, or SOP that defines identifier reuse.&lt;br /&gt;
|-&lt;br /&gt;
| [b] reuse of identifiers is prevented within the defined period. || Screen Share || Show the GPO setting/technical solution that enforces what is defined in policy/documentation (this can be automated or manual process; screen share/artifacts can be presented to satisfy this requirement.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IA.L2-3.5.6 – Identifier Handling ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IA.L2-3.5.6_Details|&#039;&#039;&#039;IA.L2-3.5.6&#039;&#039;&#039;]] Disable identifiers after a defined period of inactivity.&lt;br /&gt;
|-&lt;br /&gt;
| [a] a period of inactivity after which an identifier is disabled is defined. || Document || SSP, policy that defines the period of inactivity after which an identifier is disabled.&lt;br /&gt;
|-&lt;br /&gt;
| [b] identifiers are disabled after the defined period of inactivity. || Screen Share || Screen share AD or similar tool supporting directory-based identity-related services for disabled accounts (can be done by hand or script).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IA.L2-3.5.7 – Password Complexity ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IA.L2-3.5.7_Details|&#039;&#039;&#039;IA.L2-3.5.7&#039;&#039;&#039;]] Enforce a minimum password complexity and change of characters when new passwords are created.&lt;br /&gt;
|-&lt;br /&gt;
| [a] password complexity requirements are defined. || Document || SSP, policy that defines password complexity requirements.&lt;br /&gt;
|-&lt;br /&gt;
| [b] password change of character requirements are defined. || Document || SSP, policy that defines change of character requirements are defined.&lt;br /&gt;
|-&lt;br /&gt;
| [c] minimum password complexity requirements as defined are enforced when new passwords are created. || Screen Share || Screen share of AD or similar directory-based identity-related service tool to show complexity requirements.&lt;br /&gt;
|-&lt;br /&gt;
| [d] minimum password change of character requirements as defined are enforced when new passwords are created. || Screen Share || Screen share of Group Policy configuration or similar tool providing centralized management and configuration of operating systems, applications, and users&#039; settings to show that characters must be changed.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IA.L2-3.5.8 – Password Reuse ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IA.L2-3.5.8_Details|&#039;&#039;&#039;IA.L2-3.5.8&#039;&#039;&#039;]] Prohibit password reuse for a specified number of generations.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the number of generations during which a password cannot be reused is specified. || Document || SSP, policy that specifies the number of generations during which a password cannot be reused is specified.&lt;br /&gt;
|-&lt;br /&gt;
| [b] reuse of passwords is prohibited during the specified number of generations. || Screen Share || Screen share Group Policy or similar tool providing centralized management and configuration of operating systems, applications, and users&#039; settings in a directory-based identity-related service tool&#039;s configuration to show reuse of passwords is prohibited.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IA.L2-3.5.9 – Temporary Passwords ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IA.L2-3.5.9_Details|&#039;&#039;&#039;IA.L2-3.5.9&#039;&#039;&#039;]] Allow temporary password use for system logons with an immediate change to a permanent password.&lt;br /&gt;
|-&lt;br /&gt;
| [a] an immediate change to a permanent password is required when a temporary password is used for system logon. || Screen Share || Screen share of Group Policy or similar tool providing centralized management and configuration of operating systems, applications, and users&#039; settings in a directory-based identity-related service tool&#039;s configuration to show &amp;quot;change password at first logon.&amp;quot;&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IA.L2-3.5.10 – Cryptographically-Protected Passwords ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IA.L2-3.5.1_Details|&#039;&#039;&#039;IA.L2-3.5.1&#039;&#039;&#039;]] Store and transmit only cryptographically-protected passwords.&lt;br /&gt;
|-&lt;br /&gt;
| [a] passwords are cryptographically protected in storage. || Screen Share || Screen share Group Policy or similar tool providing centralized management and configuration of operating systems, applications, and users&#039; settings in a directory-based identity-related service tool&#039;s configuration that Kerberos, or a similar network authentication protocol that works on the basis of tickets to allow nodes communicating over a non-secure network to prove their identity to one another in a secure manner, is enabled.&lt;br /&gt;
|-&lt;br /&gt;
| [b] passwords are cryptographically protected in transit. || Screen Share || Screen share Group Policy or similar tool providing centralized management and configuration of operating systems, applications, and users&#039; settings in a directory-based identity-related service tool&#039;s configuration that Kerberos, or a similar network authentication protocol that works on the basis of tickets to allow nodes communicating over a non-secure network to prove their identity to one another in a secure manner, is enabled.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IA.L2-3.5.11 – Obscure Feedback ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IA.L2-3.5.10_Details|&#039;&#039;&#039;IA.L2-3.5.10&#039;&#039;&#039;]] Obscure feedback of authentication information.&lt;br /&gt;
|-&lt;br /&gt;
| [a] authentication information is obscured during the authentication process. || Screen Share || Screen share of Group Policy or similar tool providing centralized management and configuration of operating systems, applications, and users&#039; settings in a directory-based identity-related service tool&#039;s configuration to show that passwords are obscured.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Incident Response (IR) ==&lt;br /&gt;
=== IR.L2-3.6.1 – Incident Handling ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IR.L2-3.6.1_Details|&#039;&#039;&#039;IR.L2-3.6.1&#039;&#039;&#039;]] Establish an operational incident-handling capability for organizational systems that includes preparation, detection, analysis, containment, recovery, and user response activities.&lt;br /&gt;
|-&lt;br /&gt;
| [a] an operational incident-handling capability is established. || Document || Incident Response SOP/Plan.&lt;br /&gt;
|-&lt;br /&gt;
| [b] the operational incident-handling capability includes preparation. || Document || Incident Response SOP/Plan, prior incident report, training, COOP plan.&lt;br /&gt;
|-&lt;br /&gt;
| [c] the operational incident-handling capability includes detection. || Document || Incident Response SOP/Plan; definition of tools used to detect; artifacts showing tools used; prior incident report.&lt;br /&gt;
|-&lt;br /&gt;
| [d] the operational incident-handling capability includes analysis. || Document || Incident Response SOP/Plan; Definition of tools used to analyze potential incidents; artifacts showing tools used for analysis; prior incident report.&lt;br /&gt;
|-&lt;br /&gt;
| [e] the operational incident-handling capability includes containment. || Document || Incident Response SOP/Plan; isolation/quarantine process; user training.&lt;br /&gt;
|-&lt;br /&gt;
| [f] the operational incident-handling capability includes recovery. || Document || Incident Response SOP/Plan; COOP Plan; prior incident reports, re-baselining impacted devices.&lt;br /&gt;
|-&lt;br /&gt;
| [g] the operational incident-handling capability includes user response. || Document || Incident Response SOP/Plan; user awareness training; Help Desk process.&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IR.L2-3.6.2 – Incident Reporting ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IR.L2-3.6.2_Details|&#039;&#039;&#039;IR.L2-3.6.2&#039;&#039;&#039;]] Track, document, and report incidents to designated officials and/or authorities both internal and external to the organization.&lt;br /&gt;
|-&lt;br /&gt;
| [a] incidents are tracked. || Artifact || Incident Response SOP/Plan; ITSM artifact; technical implementation for incident tracking.&lt;br /&gt;
|-&lt;br /&gt;
| [b] incidents are documented. || Artifact || Incident Response SOP/Plan; ITSM artifact; technical implementation for incident tracking.&lt;br /&gt;
|-&lt;br /&gt;
| [c] authorities to whom incidents are to be reported are identified. || Document || Incident Response SOP/Plan.&lt;br /&gt;
|-&lt;br /&gt;
| [d] organizational officials to whom incidents are to be reported are identified. || Document || Incident Response SOP/Plan.&lt;br /&gt;
|-&lt;br /&gt;
| [e] identified authorities are notified of incidents. || Screen Share || Prior incident report; DIBNET login; prior email notifications.&lt;br /&gt;
|-&lt;br /&gt;
| [f] identified organizational officials are notified of incidents. || Artifact || Prior incident report; prior email notifications; tabletop exercises.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IR.L2-3.6.3 – Incident Response Testing ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IR.L2-3.6.3_Details|&#039;&#039;&#039;IR.L2-3.6.3&#039;&#039;&#039;]] Test the organizational incident response capability.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the incident response capability is tested. || Artifact || Incident response table top/scheduled or unscheduled test or penetration test.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Maintenance (MA) ==&lt;br /&gt;
=== MA.L2-3.7.1 – Perform Maintenance ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MA.L2-3.7.1_Details|&#039;&#039;&#039;MA.L2-3.7.1&#039;&#039;&#039;]] Perform maintenance on organizational systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] system maintenance is performed. || Artifact || Establish typical maintenance activities (HVAC, UPS, power distribution, generators, copier maintenance) that are performed; maintenance agreements or contracts detailing these types of activities are acceptable; interview responses should be considered.  This requirement should not be confused with 3.14.1 - report, remediate, and correct system flaws in a timely manner (patch management).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MA.L2-3.7.2 – System Maintenance Control ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MA.L2-3.7.2_Details|&#039;&#039;&#039;MA.L2-3.7.2&#039;&#039;&#039;]] Provide controls on the tools, techniques, mechanisms, and personnel used to conduct system maintenance.&lt;br /&gt;
|-&lt;br /&gt;
| [a] tools used to conduct system maintenance are controlled. || Artifact || Tools may largely depend on the assessed environment; discussion examples include network diagnostic and monitoring tools (including hardware and software); artifacts could demonstrate secured locations/areas for these tools (photos) or checkout sheets/rosters (documents) depicting responsible personnel and the dates/times of checkout.&lt;br /&gt;
|-&lt;br /&gt;
| [b] techniques used to conduct system maintenance are controlled. || Artifact || Processes for scheduling, performing, documenting, reviewing, approving, and monitoring maintenance and repairs for the information system.&lt;br /&gt;
|-&lt;br /&gt;
| [c] mechanisms used to conduct system maintenance are controlled. || Artifact || Processes for scheduling, performing, documenting, reviewing, approving, and monitoring maintenance and repairs for the information system.&lt;br /&gt;
|-&lt;br /&gt;
| [d] personnel used to conduct system maintenance are controlled. || Physical Review || Screenshot of who is authorized to conduct maintenance; maintenance personnel training program.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MA.L2-3.7.3 – Equipment Sanitization ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MA.L2-3.7.3_Details|&#039;&#039;&#039;MA.L2-3.7.3&#039;&#039;&#039;]] Ensure equipment removed for off-site maintenance is sanitized of any CUI.&lt;br /&gt;
|-&lt;br /&gt;
| [a] equipment to be removed from organizational spaces for off-site maintenance is sanitized of any CUI. || Artifact || Document or artifact; record if equipment sanitized; categories of sanitization/destruction defined; sanitization procedural document.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MA.L2-3.7.4 – Media Inspection ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MA.L2-3.7.4_Details|&#039;&#039;&#039;MA.L2-3.7.4&#039;&#039;&#039;]] Check media containing diagnostic and test programs for malicious code before the media are used in organizational systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] media containing diagnostic and test programs are checked for malicious code before being used in organizational systems that process, store, or transmit CUI. || Artifact || Screenshot of diagnostic/test program being used (such as Symantec and McAfee on access scans…).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MA.L2-3.7.5 – Nonlocal Maintenance ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MA.L2-3.7.5_Details|&#039;&#039;&#039;MA.L2-3.7.5&#039;&#039;&#039;]] Require multifactor authentication to establish nonlocal maintenance sessions via external network connections and terminate such connections when nonlocal maintenance is complete.&lt;br /&gt;
|-&lt;br /&gt;
| [a] multifactor authentication is used to establish nonlocal maintenance sessions via external network connections. || Screen Share || Describe MFA used to remote from external service to organizational systems for maintenance and screenshot of MFA (3.5.3)(points associated with admin).&lt;br /&gt;
|-&lt;br /&gt;
| [b] nonlocal maintenance sessions established via external network connections are terminated when nonlocal maintenance is complete. || Screen Share || Screenshot VPN session timeout.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MA.L2-3.7.6 – Maintenance Personnel ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MA.L2-3.7.6_Details|&#039;&#039;&#039;MA.L2-3.7.6&#039;&#039;&#039;]] Supervise the maintenance activities of maintenance personnel without required access authorization.&lt;br /&gt;
|-&lt;br /&gt;
| [a] maintenance personnel without required access authorization are supervised during maintenance activities. || Document || System maintenance policy; list of authorized personnel; maintenance records or, contracts/SLAs; WebEx.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Media Protection (MP) ==&lt;br /&gt;
=== MP.L2-3.8.1 – Media Protection ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MP.L2-3.8.1_Details|&#039;&#039;&#039;MP.L2-3.8.1&#039;&#039;&#039;]] Protect (i.e., physically control and securely store) system media containing CUI, both paper and digital.&lt;br /&gt;
|-&lt;br /&gt;
| [a] paper media containing CUI is physically controlled. || Document || Policy showing CUI paper media is controlled; artifact showing who has access; artifacts/records of  inventories conducted; media check out procedures (i.e. file cabinets, encryption, password protection).&lt;br /&gt;
|-&lt;br /&gt;
| [b] digital media containing CUI is physically controlled. || Document || Policy showing CUI digital media is controlled; artifact showing who has access; artifacts/records of inventories conducted; media check out procedures (i.e. file cabinets, external drives, USBs, encryption, password protection).&lt;br /&gt;
|-&lt;br /&gt;
| [c] paper media containing CUI is securely stored. || Physical Review || Check out/sign out sheets; possible photo of storage container/video walk through of storage area; badge reader logs or access lists for keys for secured areas; interview response considered (i.e. file cabinets,  encryption, password protection).&lt;br /&gt;
|-&lt;br /&gt;
| [d] digital media containing CUI is securely stored. || Physical Review || Check out/sign out sheets; possible photo of storage container/video walk through of storage area; badge reader logs or access lists for keys for secured areas; interview response considered (i.e. file cabinets, external drives, USBs, encryption, password protection).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MP.L2-3.8.2 – Media Access ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MP.L2-3.8.2_Details|&#039;&#039;&#039;MP.L2-3.8.2&#039;&#039;&#039;]] Limit access to CUI on system media to authorized users.&lt;br /&gt;
|-&lt;br /&gt;
| [a] access to CUI on system media is limited to authorized users. || Artifact || Document describing how CUI is limited AND artifact showing principle of least access is implemented.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MP.L2-3.8.3 – Media Disposal [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MP.L2-3.8.3_Details|&#039;&#039;&#039;MP.L2-3.8.3&#039;&#039;&#039;]] Sanitize or destroy information system media containing Federal Contract Information before disposal or release for reuse.&lt;br /&gt;
|-&lt;br /&gt;
| [a] system media containing CUI is sanitized or destroyed before disposal. || Document || Policy or artifact of media destruction logs; certificates of destruction; SLAs or contracts.&lt;br /&gt;
|-&lt;br /&gt;
| [b] system media containing CUI is sanitized before it is released for reuse. || Document || Policy or artifact describing method to sanitize, software used (i.e. DoD Wipe, ShredIT and Iron Mountain; Blancco; GDisk, DBAN).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MP.L2-3.8.4 – Media Markings ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MP.L2-3.8.4_Details|&#039;&#039;&#039;MP.L2-3.8.4&#039;&#039;&#039;]] Mark media with necessary CUI markings and distribution limitations.&lt;br /&gt;
|-&lt;br /&gt;
| [a] media containing CUI is marked with applicable CUI markings. || Physical Review || Document or artifact showing CUI markings (i.e. labeling standards ).&lt;br /&gt;
|-&lt;br /&gt;
| [b] media containing CUI is marked with distribution limitations. || Physical Review || Document or artifact showing distro limitations (i.e. labeling standards ).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MP.L2-3.8.5 – Media Accountability ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MP.L2-3.8.5_Details|&#039;&#039;&#039;MP.L2-3.8.5&#039;&#039;&#039;]] Control access to media containing CUI and maintain accountability for media during transport outside of controlled areas.&lt;br /&gt;
|-&lt;br /&gt;
| [a] access to media containing CUI is controlled. || Document || Policy, artifact of audit logs showing tracking, Access Control Lists, records of transport activities (i.e. USB drives, CDs, chain of custody.&lt;br /&gt;
|-&lt;br /&gt;
| [b] accountability for media containing CUI is maintained during transport outside of controlled areas. || Artifact || Artifact of audit logs showing tracking, Access Control Lists, records of transport activities (i.e. USB drives, CDs; chain of custody.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MP.L2-3.8.6 – Portable Storage Encryption ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MP.L2-3.8.6_Details|&#039;&#039;&#039;MP.L2-3.8.6&#039;&#039;&#039;]] Implement cryptographic mechanisms to protect the confidentiality of CUI stored on digital media during transport unless otherwise protected by alternative physical safeguards.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the confidentiality of CUI stored on digital media is protected during transport using cryptographic mechanisms or alternative physical safeguards. || Artifact || Artifact showing crypto mechanisms used to protect (are they FIPS 140-2 [13.11]); artifact showing what alternative physical safeguards are in place (i.e. encryption; BitLocker; McAfee ).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MP.L2-3.8.7 – Removable Media ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MP.L2-3.8.7_Details|&#039;&#039;&#039;MP.L2-3.8.7&#039;&#039;&#039;]] Control the use of removable media on system components.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the use of removable media on system components is controlled. || Artifact || Policy showing if removable media is allowed; writable removable media is restricted; tracking artifacts; what tools are used (i.e. Carbon Black, Crowd Strike, GPO, Zoho Desktop Central); procedure/process describing what happens if it is lost; what mechanisms are in place to control/restrict removable media (i.e. Active Directory Groups and Group Policy artifact showing restriction).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MP.L2-3.8.8 – Shared Media ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MP.L2-3.8.8_Details|&#039;&#039;&#039;MP.L2-3.8.8&#039;&#039;&#039;]] Prohibit the use of portable storage devices when such devices have no identifiable owner.ASSESSMENT OBJECTIVES&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [a] the use of portable storage devices is prohibited when such devices have no identifiable owner. || Artifact || Policy and/or artifact showing company stance on portable storage devices if there is no owner (are personal USB devices allowed or are they company-issued; artifact showing alerts if device is connected to network (i.e. external HDD, Carbon Black, Crowd Strike, GPO, Zoho Desktop Central.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MP.L2-3.8.9 – Protect Backups ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MP.L2-3.8.9_Details|&#039;&#039;&#039;MP.L2-3.8.9&#039;&#039;&#039;]] Protect the confidentiality of backup CUI at storage locations.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the confidentiality of backup CUI is protected at storage locations. || Artifact || Policy on system backups; artifact showing media labeling; artifact showing encyption (is it FIPS 140-2 [13.11]); Access Control List artifact (i.e. backup tapes, Tivoli Storage Manager).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Personnel Security (PS) ==&lt;br /&gt;
=== PS.L2-3.9.1 – Screen Individuals ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_PS.L2-3.9.1_Details|&#039;&#039;&#039;PS.L2-3.9.1&#039;&#039;&#039;]] Screen individuals prior to authorizing access to organizational systems containing CUI.&lt;br /&gt;
|-&lt;br /&gt;
| [a] individuals are screened prior to authorizing access to organizational systems containing CUI. || Artifact || Screenshot of records of screened personnel/background checks.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== PS.L2-3.9.2 – Personnel Actions ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_PS.L2-3.9.2_Details|&#039;&#039;&#039;PS.L2-3.9.2&#039;&#039;&#039;]] Ensure that organizational systems containing CUI are protected during and after personnel actions such as terminations and transfers.&lt;br /&gt;
|-&lt;br /&gt;
| [a] a policy and/or process for terminating system access and any credentials coincident with personnel actions is established. || Document || Personnel security policy/procedures/instruction; Access control policy/procedure/instruction.&lt;br /&gt;
|-&lt;br /&gt;
| [b] system access and credentials are terminated consistent with personnel actions such as termination or transfer. || Artifact || Screenshot of records of personnel transfer and termination actions.&lt;br /&gt;
|-&lt;br /&gt;
| [c] the system is protected during and after personnel transfer actions. || Artifact || Completed outprocessing checklist.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Physical Protection (PE) ==&lt;br /&gt;
=== PE.L2-3.10.1 – Limit Physical Access [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_PE.L2-3.10.1_Details|&#039;&#039;&#039;PE.L2-3.10.1&#039;&#039;&#039;]] Limit physical access to organizational information systems, equipment, and the respective operating environments to authorized individuals.&lt;br /&gt;
|-&lt;br /&gt;
| [a] authorized individuals allowed physical access are identified. || Artifact || Authorized personnel (names) access list.&lt;br /&gt;
|-&lt;br /&gt;
| [b] physical access to organizational systems is limited to authorized individuals. || Physical Review || Badge reader logs, audit logs, and/or card swipe test.&lt;br /&gt;
|-&lt;br /&gt;
| [c] physical access to equipment is limited to authorized individuals. || Physical Review || Badge reader logs, audit logs, and/or card swipe test.&lt;br /&gt;
|-&lt;br /&gt;
| [d] physical access to operating environments is limited to authorized. || Physical Review || Badge reader logs, audit logs, and/or card swipe test.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== PE.L2-3.10.2 – Monitor Facility ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_PE.L2-3.10.2_Details|&#039;&#039;&#039;PE.L2-3.10.2&#039;&#039;&#039;]] Protect and monitor the physical facility and support infrastructure for organizational systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the physical facility where organizational systems reside is protected. || Physical Review || Physical security measures and barriers into the physical facility (cameras/locks/gates/guards, etc.).&lt;br /&gt;
|-&lt;br /&gt;
| [b] the support infrastructure for organizational systems is protected. || Physical Review || Physical barriers to entries into computer spaces, server rooms, etc.&lt;br /&gt;
|-&lt;br /&gt;
| [c] the physical facility where organizational systems reside is monitored. || Physical Review || Audit logs/how the physical facility is being monitored (cameras/access system/guards, etc.).&lt;br /&gt;
|-&lt;br /&gt;
| [d] the support infrastructure for organizational systems is monitored. || Physical Review || Audit logs/how the physical facility is being monitored (cameras/access system/guards, etc.).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== PE.L2-3.10.3 – Escort Visitors [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_PE.L2-3.10.3_Details|&#039;&#039;&#039;PE.L2-3.10.3&#039;&#039;&#039;]] Escort visitors and monitor visitor activity.&lt;br /&gt;
|-&lt;br /&gt;
| [a] visitors are escorted. || Physical Review || Policy/procedures/instruction on methodology for handling non-authorized personnel (entry to exit).&lt;br /&gt;
|-&lt;br /&gt;
| [b] visitor activity is monitored. || Physical Review || Policy/procedures/instructio on methodology for handling non-authorized personnel (entry to exit).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== PE.L2-3.10.4 – Physical Access Logs [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_PE.L2-3.10.4_Details|&#039;&#039;&#039;PE.L2-3.10.4&#039;&#039;&#039;]] Maintain audit logs of physical access.&lt;br /&gt;
|-&lt;br /&gt;
| [a] audit logs of physical access are maintained. || Artifact || Log or report from badging system.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== PE.L2-3.10.5 – Manage Physical Access [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_PE.L2-3.10.5_Details|&#039;&#039;&#039;PE.L2-3.10.5&#039;&#039;&#039;]] Control and manage physical access devices.&lt;br /&gt;
|-&lt;br /&gt;
| [a] physical access devices are identified. || Document || Physical access control systems description, guard force contract/policy, key locks, logical systems specifications, etc.&lt;br /&gt;
|-&lt;br /&gt;
| [b] physical access devices are controlled. || Physical Review || Inventory records of physical access control devices (e.g. keys, locks, card readers, locks, etc.).&lt;br /&gt;
|-&lt;br /&gt;
| [c] physical access devices are managed. || Physical Review || List of security safeguards controlling access to the facility (e.g. cameras, monitoring by guards, isolation of IT systems equiment and or system components).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== PE.L2-3.10.6 – Alternative Work Sites ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_PE.L2-3.10.6_Details|&#039;&#039;&#039;PE.L2-3.10.6&#039;&#039;&#039;]] Enforce safeguarding measures for CUI at alternate work sites.&lt;br /&gt;
|-&lt;br /&gt;
| [a] safeguarding measures for CUI are defined for alternate work sites. || Document || Telework agreement, Acceptable Use Policy and SOP for alternate work locations; user security training validation which includes physical/logical/technical protections of system at alternate work sites.&lt;br /&gt;
|-&lt;br /&gt;
| [b] safeguarding measures for CUI are enforced for alternate work sites. || Artifact || Monitoring/audit log of user activity and logical/physical/technical mechanisms in place to preclude unauthorized activity (telework agreement , AUP?).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Risk Assessment (RA) ==&lt;br /&gt;
=== RA.L2-3.11.1 – Risk Assessments ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_RA.L2-3.11.1_Details|&#039;&#039;&#039;RA.L2-3.11.1&#039;&#039;&#039;]] Periodically assess the risk to organizational operations (including mission, functions, image, or reputation), organizational assets, and individuals, resulting from the operation of organizational systems and the associated processing, storage, or transmission of CUI.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the frequency to assess risk to organizational operations, organizational assets, and individuals is defined. || Document || Risk assessment policy.&lt;br /&gt;
|-&lt;br /&gt;
| [b] risk to organizational operations, organizational assets, and individuals resulting from the operation of an organizational system that processes, stores, or transmits CUI is assessed with the defined frequency. || Artifact || Copy of last risk assessment done within defined frequency.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== RA.L2-3.11.2 – Vulnerability Scan ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_RA.L2-3.11.2_Details|&#039;&#039;&#039;RA.L2-3.11.2&#039;&#039;&#039;]] Scan for vulnerabilities in organizational systems and applications periodically and when new vulnerabilities affecting those systems and applications are identified.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the frequency to scan for vulnerabilities in organizational systems and applications is defined. || Document || Policy/procedures/instruction addressing vulnerability scanning records.&lt;br /&gt;
|-&lt;br /&gt;
| [b] vulnerability scans are performed on organizational systems with the defined frequency. || Screen Share || System configuration settings of vulnerability scanning scheduling and vulnerability scan results of systems within defined frequency.&lt;br /&gt;
|-&lt;br /&gt;
| [c] vulnerability scans are performed on applications with the defined frequency. || Screen Share || System configuration settings of vulnerability scanning scheduling and vulnerability scan results of applications within defined frequency.&lt;br /&gt;
|-&lt;br /&gt;
| [d] vulnerability scans are performed on organizational systems when new vulnerabilities are identified. || Screen Share || View signatures in scanning tool/ad hoc scan performed as a result.&lt;br /&gt;
|-&lt;br /&gt;
| [e] vulnerability scans are performed on applications when new vulnerabilities are identified. || Screen Share || View signatures in scanning tool/ad hoc scan performed as a result.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== RA.L2-3.11.3 – Vulnerability Remediation ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_RA.L2-3.11.3_Details|&#039;&#039;&#039;RA.L2-3.11.3&#039;&#039;&#039;]] Remediate vulnerabilities in accordance with risk assessments.&lt;br /&gt;
|-&lt;br /&gt;
| [a] vulnerabilities are identified. || Artifact || Scan results showing vulnerabilities identified.&lt;br /&gt;
|-&lt;br /&gt;
| [b] vulnerabilities are remediated in accordance with risk assessments. || Artifact || Screenshot/document of scan results of remediated vulnerabilities in accordance to risk assessments.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Security Assessment (CA) ==&lt;br /&gt;
=== CA.L2-3.12.1 – Security Control Assessment ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_CA.L2-3.12.1_Details|&#039;&#039;&#039;CA.L2-3.12.1&#039;&#039;&#039;]] Periodically assess the security controls in organizational systems to determine if the controls are effective in their application.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the frequency of security control assessments is defined. || Document || SSP.&lt;br /&gt;
|-&lt;br /&gt;
| [b] security controls are assessed with the defined frequency to determine if the controls are effective in their application. || Artifact || Copy of last security control assessment done within defined frequency.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== CA.L2-3.12.2 – Operational Plan of Action ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_CA.L2-3.12.2_Details|&#039;&#039;&#039;CA.L2-3.12.2&#039;&#039;&#039;]] Develop and implement plans of action designed to correct deficiencies and reduce or eliminate vulnerabilities in organizational systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] deficiencies and vulnerabilities to be addressed by the plan of action are identified. || Artifact || Plan of Action (POA).&lt;br /&gt;
|-&lt;br /&gt;
| [b] a plan of action is developed to correct identified deficiencies and reduce or eliminate identified vulnerabilities. || Artifact || Plan of Action (POA).&lt;br /&gt;
|-&lt;br /&gt;
| [c] the plan of action is implemented to correct identified deficiencies and reduce or eliminate identified vulnerabilities. || Artifact || Plan of Action (POA)/previously completed POAs.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== CA.L2-3.12.3 – Security Control Monitoring ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_CA.L2-3.12.3_Details|&#039;&#039;&#039;CA.L2-3.12.3&#039;&#039;&#039;]] Monitor security controls on an ongoing basis to ensure the continued effectiveness of the controls.&lt;br /&gt;
|-&lt;br /&gt;
| [a] security controls are monitored on an ongoing basis to ensure the continued effectiveness of those controls. || Artifact || Collection of risk assessment results, internal or third-party audits/security assessments and/or continuous monitoring reports/alerts (SIEM tool, etc.).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== CA.L2-3.12.4 – System Security Plan ====&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_CA.L2-3.12.4_Details|&#039;&#039;&#039;CA.L2-3.12.4&#039;&#039;&#039;]] Develop, document, and periodically update system security plans that describe system boundaries, system environments of operation, how security requirements are implemented, and the relationships with or connections to other systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] a system security plan is developed. || Document || SSP.&lt;br /&gt;
|-&lt;br /&gt;
| [b] the system boundary is described and documented in the system security plan. || Document || SSP and any supporting documentation.&lt;br /&gt;
|-&lt;br /&gt;
| [c] the system environment of operation is described and documented in the system security plan. || Document || SSP and any supporting documentation.&lt;br /&gt;
|-&lt;br /&gt;
| [d] the security requirements identified and approved by the designated authority as non-applicable are identified. || Document || SSP and required adjudication from DoD CIO.&lt;br /&gt;
|-&lt;br /&gt;
| [e] the method of security requirement implementation is described and documented in the system security plan. || Document || SSP and any supporting documentation.&lt;br /&gt;
|-&lt;br /&gt;
| [f] the relationship with or connection to other systems is described and documented in the system security plan. || Document || SSP and any supporting documentation.&lt;br /&gt;
|-&lt;br /&gt;
| [g] the frequency to update the system security plan is defined. || Document || SSP.&lt;br /&gt;
|-&lt;br /&gt;
| [h] system security plan is updated with the defined frequency. || Document || SSP/any previous versions.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== System and Communications Protection (SC) ==&lt;br /&gt;
=== SC.L2-3.13.1 – Boundary Protection [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.1_Details|&#039;&#039;&#039;SC.L2-3.13.1&#039;&#039;&#039;]] Monitor, control, and protect organizational communications (i.e., information transmitted or received by organizational information systems) at the external boundaries and key internal boundaries of the information systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the external system boundary is defined. || Document || SSP, network diagrams, CUI flow, cloud provider FedRAMP Moderate.&lt;br /&gt;
|-&lt;br /&gt;
| [b] key internal system boundaries are defined. || Document || SSP, network diagrams, CUI flow.&lt;br /&gt;
|-&lt;br /&gt;
| [c] communications are monitored at the external system boundary. || Screen Share || SSP, logging server, boundary device configurations, monitoring policy.&lt;br /&gt;
|-&lt;br /&gt;
| [d] communications are monitored at key internal boundaries. || Screen Share || SSP, logging server, boundary device configurations, monitoring policy.&lt;br /&gt;
|-&lt;br /&gt;
| [e] communications are controlled at the external system boundary. || Screen Share || SSP, boundary device configurations, ACL, subnets, DMZ.&lt;br /&gt;
|-&lt;br /&gt;
| [f] communications are controlled at key internal boundaries. || Screen Share || SSP, boundary device configurations, ACL, subnets.&lt;br /&gt;
|-&lt;br /&gt;
| [g] communications are protected at the external system boundary. || Screen Share || Configurations for IPS/IDS, email gateway, VLAN, proxy, firewall, malware protection, DNS, TSL.&lt;br /&gt;
|-&lt;br /&gt;
| [h] communications are protected at key internal boundaries. || Screen Share || Configurations for IPS/IDS, VLAN, firewall, malware protection, SSL.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.2 – Security Engineering ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.2_Details|&#039;&#039;&#039;SC.L2-3.13.2&#039;&#039;&#039;]] Employ architectural designs, software development techniques, and systems engineering principles that promote effective information security within organizational systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] architectural designs that promote effective information security are identified. || Document || SSP, config management policy, network diagram, CCB minutes, enterprise architecture process.&lt;br /&gt;
|-&lt;br /&gt;
| [b] software development techniques that promote effective information security are identified. || Document || SSP, config management policy, SDLC, CCB minutes.&lt;br /&gt;
|-&lt;br /&gt;
| [c] systems engineering principles that promote effective information security are identified. || Document || SSP, config management policy, CCB minutes, security architecture engineering.&lt;br /&gt;
|-&lt;br /&gt;
| [d] identified architectural designs that promote effective information security are employed. || Artifact || CCB minutes, Network diagrams and configurations, Project Plans.&lt;br /&gt;
|-&lt;br /&gt;
| [e] identified software development techniques that promote effective information security are employed. || Artifact || CCB minutes, SDLC, code scanner results, code management tracking.&lt;br /&gt;
|-&lt;br /&gt;
| [f] identified systems engineering principles that promote effective information security are employed. || Artifact || CCB minutes, configuration management, ITSM, patch management, lifecycle replacement processes.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.3 – Role Separation ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.3_Details|&#039;&#039;&#039;SC.L2-3.13.3&#039;&#039;&#039;]] Separate user functionality from system management functionality.&lt;br /&gt;
|-&lt;br /&gt;
| [a] user functionality is identified. || Document || SSP, AUP.&lt;br /&gt;
|-&lt;br /&gt;
| [b] system management functionality is identified. || Document || SSP, Privileged Account Agreement.&lt;br /&gt;
|-&lt;br /&gt;
| [c] user functionality is separated from system management functionality. || Screen Share || Active Directory, Jump Boxes, GPO, VM, RDP.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.4 – Shared Resource Control ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.4_Details|&#039;&#039;&#039;SC.L2-3.13.4&#039;&#039;&#039;]] Prevent unauthorized and unintended information transfer via shared system resources.&lt;br /&gt;
|-&lt;br /&gt;
| [a] unauthorized and unintended information transfer via shared system resources is prevented. || Screen Share || SSP, OS configurations, Linux containers, system/media reuse policies, certificate management policies, media destruction policies, printer configs, VDI configuration.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
===  SC.L2-3.13.5 – Public-Access System Separation [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.5_Details|&#039;&#039;&#039;SC.L2-3.13.5&#039;&#039;&#039;]] Implement subnetworks for publicly accessible system components that are physically or logically separated from internal networks.&lt;br /&gt;
|-&lt;br /&gt;
| [a] publicly accessible system components are identified. || Document || SSP, network diagram, DMZ inventory/roles.&lt;br /&gt;
|-&lt;br /&gt;
| [b] subnetworks for publicly accessible system components are physically or logically separated from internal networks. || Artifact || Network diagram, IPAM, VLAN, DHCP, DMZ.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.6 – Network Communication by Exception ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.6_Details|&#039;&#039;&#039;SC.L2-3.13.6&#039;&#039;&#039;]] Deny network communications traffic by default and allow network communications traffic by exception (i.e., deny all, permit by exception).&lt;br /&gt;
|-&lt;br /&gt;
| [a] network communications traffic is denied by default. || Screen Share || Host and network firewall rules, SIEM logs, hit counts.&lt;br /&gt;
|-&lt;br /&gt;
| [b] network communications traffic is allowed by exception. || Screen Share || Host and network firewall rules, SIEM logs, hit counts.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.7 – Split Tunneling ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.7_Details|&#039;&#039;&#039;SC.L2-3.13.7&#039;&#039;&#039;]] Prevent remote devices from simultaneously establishing non-remote connections with organizational systems and communicating via some other connection to resources in external networks (i.e., split tunneling).&lt;br /&gt;
|-&lt;br /&gt;
| [a] remote devices are prevented from simultaneously establishing non-remote connections with the system and communicating via some other connection to resources in external networks (i.e., split tunneling). || Screen Share || VPN appliance/server configuration, endpoint VPN software configuration.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.8 – Data in Transit ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.8_Details|&#039;&#039;&#039;SC.L2-3.13.8&#039;&#039;&#039;]] Implement cryptographic mechanisms to prevent unauthorized disclosure of CUI during transmission unless otherwise protected by alternative physical safeguards.&lt;br /&gt;
|-&lt;br /&gt;
| [a] cryptographic mechanisms intended to prevent unauthorized disclosure of CUI are identified. || Document || SSP, PKI policies, configuration processes, config management, email attachment encryption policy, removable media policy, data at rest policy.&lt;br /&gt;
|-&lt;br /&gt;
| [b] alternative physical safeguards intended to prevent unauthorized disclosure of CUI are identified. || Document || SSP, physical security policy.&lt;br /&gt;
|-&lt;br /&gt;
| [c] either cryptographic mechanisms or alternative physical safeguards are implemented to prevent unauthorized disclosure of CUI during transmission. || Screen Share || TLS settings, SSL settings, VPN/Wireless Access Points/Mobile Devices cryptographic settings, ODBC connector settings, SAN configuration, IPSec/MPLS, backup configuration, physical security.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.9 – Connections Termination ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.9_Details|&#039;&#039;&#039;SC.L2-3.13.9&#039;&#039;&#039;]] Terminate network connections associated with communications sessions at the end of the sessions or after a defined period of inactivity.&lt;br /&gt;
|-&lt;br /&gt;
| [a] a period of inactivity to terminate network connections associated with communications sessions is defined. || Document || SSP, network communications policy.&lt;br /&gt;
|-&lt;br /&gt;
| [b] network connections associated with communications sessions are terminated at the end of the sessions. || Screen Share || VPN appliance/server logs, VPN configurations, web server configurations, firewall connection settings.&lt;br /&gt;
|-&lt;br /&gt;
| [c] network connections associated with communications sessions are terminated after the defined period of inactivity. || Screen Share || VPN appliance/server logs, VPN configurations, web server configurations, frewall connection settings.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.10 – Key Management ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.10_Details|&#039;&#039;&#039;SC.L2-3.13.10&#039;&#039;&#039;]] Establish and manage cryptographic keys for cryptography employed in organizational systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] cryptographic keys are established whenever cryptography is employed. || Artifact || SSP, PKI/certificate management policy, configuration management.&lt;br /&gt;
|-&lt;br /&gt;
| [b] cryptographic keys are managed whenever cryptography is employed. || Artifact || SSP, PKI/certificate management policy, configuration management, access control policy.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.11 – CUI Encryption ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.11_Details|&#039;&#039;&#039;SC.L2-3.13.11&#039;&#039;&#039;]] Employ FIPS-validated cryptography when used to protect the confidentiality of CUI.&lt;br /&gt;
|-&lt;br /&gt;
| [a] FIPS-validated cryptography is employed to protect the confidentiality of CUI. || Screen Share || VPN, wireless, mobile devices, client certificates, server certificates, disk encryption, Outlook plugin, external mail, backup media, ePO server, removable storage, SAN, file compression; look for FIPS mode enabled on appliances.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.12 – Collaborative Device Control ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.12_Details|&#039;&#039;&#039;SC.L2-3.13.12&#039;&#039;&#039;]] Prohibit remote activation of collaborative computing devices and provide indication of devices in use to users present at the device.&lt;br /&gt;
|-&lt;br /&gt;
| [a] collaborative computing devices are identified. || Document || SSP, network diagrams.&lt;br /&gt;
|-&lt;br /&gt;
| [b] collaborative computing devices provide indication to users of devices in use. || Physical Review || Physical inspection of device.&lt;br /&gt;
|-&lt;br /&gt;
| [c] remote activation of collaborative computing devices is prohibited. || Screen Share || Collaboration device configuration/console.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.13 – Mobile Code ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.13_Details|&#039;&#039;&#039;SC.L2-3.13.13&#039;&#039;&#039;]] Control and monitor the use of mobile code.&lt;br /&gt;
|-&lt;br /&gt;
| [a] use of mobile code is controlled. || Screen Share || GPO settings, malware protection, software agent configurations, software development policies, code scanners, MDM configuration, firewall/secure web gateway/proxy config.&lt;br /&gt;
|-&lt;br /&gt;
| [b] use of mobile code is monitored. || Screen Share || SIEM/console monitoring.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.14 – Voice over Internet Protocol ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.14_Details|&#039;&#039;&#039;SC.L2-3.13.14&#039;&#039;&#039;]] Control and monitor the use of Voice over Internet Protocol (VoIP) technologies.&lt;br /&gt;
|-&lt;br /&gt;
| [a] use of Voice over Internet Protocol (VoIP) technologies is controlled. || Artifact || VLAN, ACL, firewall config, VoIP gateway/condenser configuration.&lt;br /&gt;
|-&lt;br /&gt;
| [b] use of Voice over Internet Protocol (VoIP) technologies is monitored. || Artifact || SIEM/VoIP console monitoring, session border controller.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.15 – Communications Authenticity ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.15_Details|&#039;&#039;&#039;SC.L2-3.13.15&#039;&#039;&#039;]] Protect the authenticity of communications sessions.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the authenticity of communications sessions is protected. || Screen Share || SSL, TLS, SMB3, SFTP, IPSec, SSH, Kerberos configs, MPLS, Network Access Control.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.16 – Data at Rest ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.16_Details|&#039;&#039;&#039;SC.L2-3.13.16&#039;&#039;&#039;]] Protect the confidentiality of CUI at rest.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the confidentiality of CUI at rest is protected. || Artifact || Full disk encryption, removable media encryption, SAN encryption, digital backups, mobile device encryption, third party offsite backup storage, cloud virtualization encryption, physical media storage policies.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== System and Information Integrity (SI) ==&lt;br /&gt;
=== SI.L2-3.14.1 – Flaw Remediation [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SI.L2-3.14.1_Details|&#039;&#039;&#039;SI.L2-3.14.1&#039;&#039;&#039;]] Identify, report, and correct information and information system flaws in a timely manner.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the time within which to identify system flaws is specified. || Document || SSP, patch management policy.&lt;br /&gt;
|-&lt;br /&gt;
| [b] system flaws are identified within the specified time frame. || Screen Share || Vulnerability management scanner output and scan policy configuration.&lt;br /&gt;
|-&lt;br /&gt;
| [c] the time within which to report system flaws is specified. || Document || SSP, patch management policy.&lt;br /&gt;
|-&lt;br /&gt;
| [d] system flaws are reported within the specified time frame. || Screen Share || ITSM/trouble tickets, vulnerability management scanner output.&lt;br /&gt;
|-&lt;br /&gt;
| [e] the time within which to correct system flaws is specified. || Document || SSP, patch management policy.&lt;br /&gt;
|-&lt;br /&gt;
| [f] system flaws are corrected within the specified time frame. || Screen Share || Vulnerability management scanner output and scan policy configuration.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SI.L2-3.14.2 – Malicious Code ProTection [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SI.L2-3.14.2_Details|&#039;&#039;&#039;SI.L2-3.14.2&#039;&#039;&#039;]] Provide protection from malicious code at appropriate locations within organizational information systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] designated locations for malicious code protection are identified. || Document || SSP, system protection policy, network diagrams, security architecture documents.&lt;br /&gt;
|-&lt;br /&gt;
| [b] protection from malicious code at designated locations is provided. || Screen Share || Endpoint security settings, email/web proxy gateways, firewall, IPS sensor, MDM configuration, Network Access Control.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SI.L2-3.14.3 – Security Alerts &amp;amp; Advisories ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SI.L2-3.14.3_Details|&#039;&#039;&#039;SI.L2-3.14.3&#039;&#039;&#039;]] Monitor system security alerts and advisories and take action in response.&lt;br /&gt;
|-&lt;br /&gt;
| [a] response actions to system security alerts and advisories are identified. || Document || SSP, vulnerability management policy, Incident Response Plan.&lt;br /&gt;
|-&lt;br /&gt;
| [b] system security alerts and advisories are monitored. || Artifact || Threat intelligence subscriptions, email advisories.&lt;br /&gt;
|-&lt;br /&gt;
| [c] actions in response to system security alerts and advisories are taken. || Artifact || ITSM/trouble tickets, user notifications, updates to firewall/IPS, etc.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SI.L2-3.14.4 – Update Malicious Code Protection [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SI.L2-3.14.4_Details|&#039;&#039;&#039;SI.L2-3.14.4&#039;&#039;&#039;]] Update malicious code protection mechanisms when new releases are available.&lt;br /&gt;
|-&lt;br /&gt;
| [a] malicious code protection mechanisms are updated when new releases are available. || Screen Share || Antivirus console dashboard, firewall AV, Email gateway signatures,proxy, IPS updates.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SI.L2-3.14.5 – System &amp;amp; File Scanning [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SI.L2-3.14.5_Details|&#039;&#039;&#039;SI.L2-3.14.5&#039;&#039;&#039;]] Perform periodic scans of the information system and real-time scans of files from external sources as files are downloaded, opened, or executed.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the frequency for malicious code scans is defined. || Document || SSP, vulnerability management policy.&lt;br /&gt;
|-&lt;br /&gt;
| [b] malicious code scans are performed with the defined frequency. || Screen Share || Consoles for AV (endpoints, servers, and file shares), firewall, email gateway, proxy, IPS, MDM configurations.&lt;br /&gt;
|-&lt;br /&gt;
| [c] real-time malicious code scans of files from external sources as files are downloaded, opened, or executed are performed. || Screen Share || Consoles for AV (endpoints, servers, and file shares), firewall, email gateway, proxy, IPS, MDM configurations.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SI.L2-3.14.6 – Monitor Communications for Attacks ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SI.L2-3.14.6_Details|&#039;&#039;&#039;SI.L2-3.14.6&#039;&#039;&#039;]] Monitor organizational systems, including inbound and outbound communications traffic, to detect attacks and indicators of potential attacks.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the system is monitored to detect attacks and indicators of potential attacks. || Screen Share || Firewall, IPS, endpoint protection, SIEM alerts and reports.&lt;br /&gt;
|-&lt;br /&gt;
| [b] inbound communications traffic is monitored to detect attacks and indicators of potential attacks. || Screen Share || Firewall, IPS, endpoint protection, SIEM alerts and reports.&lt;br /&gt;
|-&lt;br /&gt;
| [c] outbound communications traffic is monitored to detect attacks and indicators of potential attacks. || Screen Share || Firewall, IPS, endpoint protection, SIEM alerts and reports.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SI.L2-3.14.7 – Identify Unauthorized Use ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SI.L2-3.14.7_Details|&#039;&#039;&#039;SI.L2-3.14.7&#039;&#039;&#039;]] Identify unauthorized use of organizational systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] authorized use of the system is defined. || Document || AUP, SSP.&lt;br /&gt;
|-&lt;br /&gt;
| [b] unauthorized use of the system is identified. || Artifact || SIEM logs, endpoint protection console, IPS, Firewall.&lt;br /&gt;
|}&lt;/div&gt;</summary>
		<author><name>David</name></author>
	</entry>
	<entry>
		<id>https://cmmcwiki.org/index.php?title=Evidence_Collection_Approach&amp;diff=1618</id>
		<title>Evidence Collection Approach</title>
		<link rel="alternate" type="text/html" href="https://cmmcwiki.org/index.php?title=Evidence_Collection_Approach&amp;diff=1618"/>
		<updated>2026-07-20T01:38:05Z</updated>

		<summary type="html">&lt;p&gt;David: /* AC.L2-3.1.18 – Mobile Device Connection */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;CMMC assessments and certification require substantial evidence and documentation. The following tables outline general guidelines for collecting evidence to assess control requirements and objectives. While these guidelines provide a structured approach, they are not the only means of conducting an accurate assessment. Assessors should exercise professional judgment and may employ alternative methods appropriate to the specific organizational context and circumstances.&lt;br /&gt;
&lt;br /&gt;
Evidence collection approaches are defined as:&lt;br /&gt;
* &#039;&#039;&#039;Documentation&#039;&#039;&#039;: Tangible materials containing information over which an organization has authority, including all types of written records and their copies.&lt;br /&gt;
* &#039;&#039;&#039;Artifacts&#039;&#039;&#039;: Tangible, reviewable records directly resulting from a practice or process being performed by a system or by personnel executing their role within that practice, control, or process.&lt;br /&gt;
* &#039;&#039;&#039;Physical Review&#039;&#039;&#039;: Direct on-site observation and examination of evidence.&lt;br /&gt;
* &#039;&#039;&#039;Screen Share&#039;&#039;&#039;: Real-time remote observation of a user demonstrating a task or process via shared computer screen, sometimes called &amp;quot;over-the-shoulder&amp;quot; review.&lt;br /&gt;
&lt;br /&gt;
DISCLAIMER: Evidence requirements vary significantly across assessment types. &#039;&#039;&#039;The examples provided are illustrative only and should be tailored to meet the specific adequacy and sufficiency standards of your particular assessment context.&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
For inquiries and reporting errors on this wiki, please [mailto:support@cmmctoolkit.org contact us]. Thank you.&lt;br /&gt;
&lt;br /&gt;
== Access Control (AC) ==&lt;br /&gt;
=== AC.L2-3.1.1 – Authorized Access Control [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.1_Details|&#039;&#039;&#039;AC.L2-3.1.1&#039;&#039;&#039;]] Limit information system access to authorized users, processes acting on behalf of authorized users, or devices (including other information systems).&lt;br /&gt;
|-&lt;br /&gt;
| [a] authorized users are identified. || Document || Document defining account request, approval, provisioning.&lt;br /&gt;
|-&lt;br /&gt;
| [b] processes acting on behalf of authorized users are identified. || Document || Document defining account request, approval, provisioning.&lt;br /&gt;
|-&lt;br /&gt;
| [c] devices (and other systems) authorized to connect to the system are identified. || Document || Document defining account request, approval, provisioning.&lt;br /&gt;
|-&lt;br /&gt;
| [d] system access is limited to authorized users. || Screen Share || Screen share showing login requirements are enforced. Example of an unauthorized user denied (unauthorized username entered at login).&lt;br /&gt;
|-&lt;br /&gt;
| [e] system access is limited to processes acting on behalf of authorized users. || Screen Share || Screenshot showing that service accounts are assigned to authorized users only; no rogue accounts without an authorized user are active.&lt;br /&gt;
|-&lt;br /&gt;
| [f] system access is limited to authorized devices (including other systems). || Screen Share || Screen share showing that all devices running are authorized; no rogue devices on the network.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.2 – Transaction &amp;amp; Function Control [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.2_Details|&#039;&#039;&#039;AC.L2-3.1.2&#039;&#039;&#039;]] Limit information system access to the types of transactions and functions that authorized users are permitted to execute.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the types of transactions and functions that authorized users are permitted to execute are defined. || Document || SSP, AUP, or IAM document that defines what authorized users can execute.&lt;br /&gt;
|-&lt;br /&gt;
| [b] system access is limited to the defined types of transactions and functions for authorized users. || Screen Share || Screenshot of security roles in AD or IAM or other directory-based identity-related services tool that shows transactions are as defined in the SSP or IAM document; privileged and non-privileged accounts need to be defined and identified in the artifact; screenshot of a non-privileged user trying to execute a privileged function.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.3 – Control CUI Flow ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.3_Details|&#039;&#039;&#039;AC.L2-3.1.3&#039;&#039;&#039;]] Control the flow of CUI in accordance with approved authorizations.&lt;br /&gt;
|-&lt;br /&gt;
| [a] information flow control policies are defined. || Document || SSP or other document describing the control of CUI on the network.&lt;br /&gt;
|-&lt;br /&gt;
| [b] methods and enforcement mechanisms for controlling the flow of CUI are defined. || Document || Document that defines the networking devices that are on the CUI network and answers what measures are in place to control the flow. List of firewalls, border and internal layer 3 devices, IDS/IPS, DLP, that process CUI.&lt;br /&gt;
|-&lt;br /&gt;
| [c] designated sources and destinations (e.g., networks, individuals, and devices) for CUI within the system and between interconnected systems are identified. || Artifact || Network diagram, data flow diagram, external system connection diagrams, document describing the policies for CUI on the network; listing of VLANs and subnets where CUI is authorized; document must describe source and authorized destinations.&lt;br /&gt;
|-&lt;br /&gt;
| [d] authorizations for controlling the flow of CUI are defined. || Document || Document that defines how CUI is to be controlled, such as an InfoSec plan, and/or network management plan.&lt;br /&gt;
|-&lt;br /&gt;
| [e] approved authorizations for controlling the flow of CUI are enforced. || Screen Share || Screenshots of firewall rules, ACLs, etc.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.4 – Separation of Duties ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.4_Details|&#039;&#039;&#039;AC.L2-3.1.4&#039;&#039;&#039;]] Separate the duties of individuals to reduce the risk of malevolent activity without collusion.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the duties of individuals requiring separation are defined. || Document || Document, SSP, account management policy, defining separation of duties by person or role.&lt;br /&gt;
|-&lt;br /&gt;
| [b] responsibilities for duties that require separation are assigned to separate individuals. || Screen Share || Screenshot showing that separation of duties is enforced by showing admin accounts are assigned to different people based on role.&lt;br /&gt;
|-&lt;br /&gt;
| [c] access privileges that enable individuals to exercise the duties that require separation are granted to separate individuals. || Screen Share || Screen shot showing an example such as a security manager can not log into a network device and change ACLs, or network admins can not access security logs in the SIEM tool.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.5 – Least Privilege ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.5_Details|&#039;&#039;&#039;AC.L2-3.1.5&#039;&#039;&#039;]] Employ the principle of least privilege, including for specific security functions and privileged accounts.&lt;br /&gt;
|-&lt;br /&gt;
| [a] privileged accounts are identified. || Document || &amp;quot;SSP or policy (documentation) identify what is considered a privileged account.&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| [b] access to privileged accounts is authorized in accordance with the principle of least privilege. || Artifact || An artifact that identifies the least amount of permissions associated with different types of privileged accounts are approved.&lt;br /&gt;
|-&lt;br /&gt;
| [c] security functions are identified. || Document || &amp;quot;SSP or policy (documentation) identifies what is considered a security account.&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| [d] access to security functions is authorized in accordance with the principle of least privilege. || Artifact || Artifact(s) that identify the least amount of permissions associated with different types of security accounts are approved.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.6 – Non-Privileged Account Use ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.6_Details|&#039;&#039;&#039;AC.L2-3.1.6&#039;&#039;&#039;]] Use non-privileged accounts or roles when accessing nonsecurity functions.&lt;br /&gt;
|-&lt;br /&gt;
| [a] nonsecurity functions are identified. || Document || SSP or account management document, AUP, that defines non-security functions.&lt;br /&gt;
|-&lt;br /&gt;
| [b] users are required to use non-privileged accounts or roles when accessing nonsecurity functions. || Screen Share || Screenshot showing that a privileged user tried to use their admin account to access a non-security function, such as a browser or email (whatever is defined in their policy) and was blocked.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.7 – Privileged Functions ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.7_Details|&#039;&#039;&#039;AC.L2-3.1.7&#039;&#039;&#039;]] Prevent non-privileged users from executing privileged functions and capture the execution of such functions in audit logs.&lt;br /&gt;
|-&lt;br /&gt;
| [a] privileged functions are defined. || Document || SSP or policy (documentation) that defines privileged functions.&lt;br /&gt;
|-&lt;br /&gt;
| [b] non-privileged users are defined. || Document || SSP or policy (documentation) that defines non-privileged users.&lt;br /&gt;
|-&lt;br /&gt;
| [c] non-privileged users are prevented from executing privileged functions. || Screen Share || Screen share that shows that a non-privileged user is not allowed to complete a privileged function (installing software).&lt;br /&gt;
|-&lt;br /&gt;
| [d] the execution of privileged functions is captured in audit logs. || Screen Share || Screen share that shows logs being captured of the execution of privileged functions.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.8 – Unsuccessful Logon Attempts ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.8_Details|&#039;&#039;&#039;AC.L2-3.1.8&#039;&#039;&#039;]] Limit unsuccessful logon attempts.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the means of limiting unsuccessful logon attempts is defined. || Document || SSP or policy (documentation) showing unsuccessful logon attempts settings and or policy.&lt;br /&gt;
|-&lt;br /&gt;
| [b] the defined means of limiting unsuccessful logon attempts is implemented. || Artifact || Artifact showing GPO / Policy for limiting logon attempts.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.9 – Privacy &amp;amp; Security Notices ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.9_Details|&#039;&#039;&#039;AC.L2-3.1.9&#039;&#039;&#039;]] Provide privacy and security notices consistent with applicable CUI rules.&lt;br /&gt;
|-&lt;br /&gt;
| [a] privacy and security notices required by CUI-specified rules are identified, consistent, and associated with the specific CUI category. || Document || SSP or policy (documentation) showing CUI-specified rules are identified, consistent, and associated with the specific CUI category.&lt;br /&gt;
|-&lt;br /&gt;
| [b] privacy and security notices are displayed. || Artifact || Artifact that shows a consent banner or screen that a user sees as they log in to the system.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.10 – Session Lock ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.10_Details|&#039;&#039;&#039;AC.L2-3.1.10&#039;&#039;&#039;]] Use session lock with pattern-hiding displays to prevent access and viewing of data after a period of inactivity.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the period of inactivity after which the system initiates a session lock is defined. || Document || SSP or policy (documentation) that defines the period of inactivity and when a session lock is defined.&lt;br /&gt;
|-&lt;br /&gt;
| [b] access to the system and viewing of data is prevented by initiating a session lock after the defined period of inactivity. || Artifact || Artifact that shows the setting of session lock (GPO or system policy or similar solution addressing the controls supporting centralized management and configuration of operating systems, applications, and users&#039; settings for the working environment of user accounts and computer accounts).&lt;br /&gt;
|-&lt;br /&gt;
| [c] previously visible information is concealed via a pattern-hiding display after the defined period of inactivity. || Document || Screenshot of GPO setting and configuration settings, or similar solution addressing the controls supporting centralized management and configuration of operating systems, applications, and users&#039; settings for the working environment of user accounts and computer accounts.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.11 – Session Termination ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.11_Details|&#039;&#039;&#039;AC.L2-3.1.11&#039;&#039;&#039;]] Terminate (automatically) a user session after a defined condition.&lt;br /&gt;
|-&lt;br /&gt;
| [a] conditions requiring a user session to terminate are defined. || Document || SSP or policy (documentation) that defines the conditions requiring a user session to be terminated.&lt;br /&gt;
|-&lt;br /&gt;
| [b] a user session is automatically terminated after any of the defined conditions. || Screen Share || Screen share showing GPO / VPN Settings that show when a session would be terminated (Idle time, max connection time).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.12 – Control Remote Access ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.12_Details|&#039;&#039;&#039;AC.L2-3.1.12&#039;&#039;&#039;]] Monitor and control remote access sessions.&lt;br /&gt;
|-&lt;br /&gt;
| [a] remote access sessions are permitted. || Document || SSP or policy (documentation) that defines remote access sessions.&lt;br /&gt;
|-&lt;br /&gt;
| [b] the types of permitted remote access are identified. || Document || SSP or policy (documentation) that defines remote access is permitted.&lt;br /&gt;
|-&lt;br /&gt;
| [c] remote access sessions are controlled. || Screen Share || Screen share that shows how the remote access is controlled (access session, and or groups).&lt;br /&gt;
|-&lt;br /&gt;
| [d] remote access sessions are monitored. || Screen Share || Screen share that shows how remote sessions are monitored (logs).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.13 – Remote Access Confidentiality ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.13_Details|&#039;&#039;&#039;AC.L2-3.1.13&#039;&#039;&#039;]] Employ cryptographic mechanisms to protect the confidentiality of remote access sessions.&lt;br /&gt;
|-&lt;br /&gt;
| [a] cryptographic mechanisms to protect the confidentiality of remote access sessions are identified. || Document || SSP or policy (documentation) that discusses the CUI rules, consistent, and associated with the specific CUI category; FIPS Cert # of appliance or application.&lt;br /&gt;
|-&lt;br /&gt;
| [b] cryptographic mechanisms to protect the confidentiality of remote access sessions are implemented. || Screen Share || Screenshot of VPN concentration that shows encryption is on and enabled (point-to-point, etc.).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.14 – Remote Access Routing ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.14_Details|&#039;&#039;&#039;AC.L2-3.1.14&#039;&#039;&#039;]] Route remote access via managed access control points.&lt;br /&gt;
|-&lt;br /&gt;
| [a] managed access control points are identified and implemented. || Screen Share || Screen share that shows access control points (groups and/or users).&lt;br /&gt;
|-&lt;br /&gt;
| [b] remote access is routed through managed network access control points. || Screen Share || Screen share that shows access control points and how they are managed.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.15 – Privileged Remote Access ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.15_Details|&#039;&#039;&#039;AC.L2-3.1.15&#039;&#039;&#039;]] Authorize remote execution of privileged commands and remote access to security-relevant information.&lt;br /&gt;
|-&lt;br /&gt;
| [a] privileged commands authorized for remote execution are identified. || Document || SSP or policy (documentation) that defines what is authorized to be executed remotely and how that is handled.&lt;br /&gt;
|-&lt;br /&gt;
| [b] security-relevant information authorized to be accessed remotely is identified. || Document || SSP or policy (documentation) that defines what can be accessed remotely and what procedures are implemented to allow this (RDP, jump box).&lt;br /&gt;
|-&lt;br /&gt;
| [c] the execution of the identified privileged commands via remote access is authorized. || Artifact || Screen share that shows who has access to perform privileged commands a remotely (access groups for privileged accounts).&lt;br /&gt;
|-&lt;br /&gt;
| [d] access to the identified security-relevant information via remote access is authorized. || Artifact || Screen share that shows the routing of remote access and how it is monitored and how many locations (Firewall, VPN Concentrator).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.16 – Wireless Access Authorization ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.16_Details|&#039;&#039;&#039;AC.L2-3.1.16&#039;&#039;&#039;]] Authorize wireless access prior to allowing such connections.&lt;br /&gt;
|-&lt;br /&gt;
| [a] wireless access points are identified. || Document || SSP, network administration document.&lt;br /&gt;
|-&lt;br /&gt;
| [b] wireless access is authorized prior to allowing such connections. || Screen Share || Authorization profile(s) in Wireless Access Controller or Identity Manager (i.e. Cisco ISE).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.17 – Wireless Access Protection ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.17_Details|&#039;&#039;&#039;AC.L2-3.1.17&#039;&#039;&#039;]] Protect wireless access using authentication and encryption.&lt;br /&gt;
|-&lt;br /&gt;
| [a] wireless access to the system is protected using authentication. || Screen Share || Security page (or similar) of a Wireless Access Controller.&lt;br /&gt;
|-&lt;br /&gt;
| [b] wireless access to the system is protected using encryption. || Screen Share || Security page (or similar) of a Wireless Access Controller.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.18 – Mobile Device Connection ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.18_Details|&#039;&#039;&#039;AC.L2-3.1.18&#039;&#039;&#039;]] Control connection of mobile devices.&lt;br /&gt;
|-&lt;br /&gt;
| [a] mobile devices that process, store, or transmit CUI are identified. || Document || SSP, Mobile Device Policy.&lt;br /&gt;
|-&lt;br /&gt;
| [b] mobile device connections are authorized. || Artifact || Authorization profile(s) in Wireless Access Controller or Identity Manager (i.e. Cisco ISE).&lt;br /&gt;
|-&lt;br /&gt;
| [c] mobile device connections are monitored and logged. || Screen Share || Mobile device logs within the MDM, log intake (sources) configuration (within SIEM) showing MDM is feeding logs to the SIEM.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.19 – Encrypt CUI on Mobile ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.19_Details|&#039;&#039;&#039;AC.L2-3.1.19&#039;&#039;&#039;]] Encrypt CUI on mobile devices and mobile computing platforms.&lt;br /&gt;
|-&lt;br /&gt;
| [a] mobile devices and mobile computing platforms that process, store, or transmit CUI are identified. || Document || SSP, Mobile Device Policy.&lt;br /&gt;
|-&lt;br /&gt;
| [b] encryption is employed to protect CUI on identified mobile devices and mobile computing platforms. || Screen Share || Security policy page in MDM showing how encryption are enforced on mobile device. If no MDM or MDM doesn&#039;t enforce encryption, then validate if the devices used are on the list of devices with native FIPS approved validation.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.20 – External Connections [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.20_Details|&#039;&#039;&#039;AC.L2-3.1.20&#039;&#039;&#039;]] Verify and control/limit connections to and use of external information systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] connections to external systems are identified. || Document || SSP, Systems Interconnection Agreements, SLA.&lt;br /&gt;
|-&lt;br /&gt;
| [b] the use of external systems is identified. || Document || SSP, Systems Interconnection Agreements, SLA.&lt;br /&gt;
|-&lt;br /&gt;
| [c] connections to external systems are verified. || Artifact || SLA for external systems, memorandum for interconnection, information to prove that any cloud solution is at FedRAMP impact level of moderate or higher (i.e. license information, screenshot of AWS cloud dashboard, purchase order document).&lt;br /&gt;
|-&lt;br /&gt;
| [d] the use of external systems is verified. || Artifact || SLA for external systems, memorandum for interconnection, information to prove that any cloud solution is at FedRAMP impact level of moderate or higher (i.e. license information, screenshot of AWS cloud dashboard, purchase order document).&lt;br /&gt;
|-&lt;br /&gt;
| [e] connections to external systems are controlled/limited. || Screen Share || Firewall ruleset for controlling access to cloud service or external system.&lt;br /&gt;
|-&lt;br /&gt;
| [f] the use of external systems is controlled/limited. || Screen Share || Firewall ruleset for controlling access to cloud service or external system.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.21 – Portable Storage Use ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.21_Details|&#039;&#039;&#039;AC.L2-3.1.21&#039;&#039;&#039;]] Limit use of portable storage devices on external systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the use of portable storage devices containing CUI on external systems is identified and documented. || Document || SSP, Removable Media Policy, Acceptable Use Policy (with emphasis on portable media use).&lt;br /&gt;
|-&lt;br /&gt;
| [b] limits on the use of portable storage devices containing CUI on external systems are defined. || Document || SSP, Removable Media Policy, Acceptable Use Policy (with emphasis on portable media use).&lt;br /&gt;
|-&lt;br /&gt;
| [c] the use of portable storage devices containing CUI on external systems is limited as defined. || Document || SSP, Removable Media Policy, Acceptable Use Policy (with emphasis on portable media use).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.22 – Control Public Information [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.22_Details|&#039;&#039;&#039;AC.L2-3.1.22&#039;&#039;&#039;]] Control information posted or processed on publicly accessible information systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] individuals authorized to post or process information on publicly accessible systems are identified. || Document || SSP, Website Governance Plan, Information Release Document.&lt;br /&gt;
|-&lt;br /&gt;
| [b] procedures to ensure CUI is not posted or processed on publicly accessible systems are identified. || Document || SSP, Website Governance Plan, Information Release Document.&lt;br /&gt;
|-&lt;br /&gt;
| [c] a review process is in place prior to posting of any content to publicly accessible systems. || Artifact || &amp;quot;Information release approval process, i.e. chain of email communication from originator, approver, and final decision (may or may not include individual authorized to post); &lt;br /&gt;
SharePoint/electronic or paper form/ ticket system showing information flow between requestor and approver (may or may not include  individual authorized to post).&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| [d] content on publicly accessible systems is reviewed to ensure that it does not include CUI. || Artifact || Incident response process, web design/update/modification SOP etc.&lt;br /&gt;
|-&lt;br /&gt;
| [e] mechanisms are in place to remove and address improper posting of CUI. || Artifact || Incident response process, web design/update/modification SOP etc.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Awareness and Training (AT) ==&lt;br /&gt;
=== AT.L2-3.2.1 – Role-Based Risk Awareness ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AT.L2-3.2.1_Details|&#039;&#039;&#039;AT.L2-3.2.1&#039;&#039;&#039;]] Ensure that managers, systems administrators, and users of organizational systems are made aware of the security risks associated with their activities and of the applicable policies, standards, and procedures related to the security of those systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] security risks associated with organizational activities involving CUI are identified. || Document || Policy of Security Awareness Training; Security Awareness Training Briefing.&lt;br /&gt;
|-&lt;br /&gt;
| [b] policies, standards, and procedures related to the security of the system are identified. || Document || Acceptable Use Policy, Policy/Procedures/Instruction related to the security of the system.&lt;br /&gt;
|-&lt;br /&gt;
| [c] managers, systems administrators, and users of the system are made aware of the security risks associated with their activities. || Artifact || Security Training Brief, training records.&lt;br /&gt;
|-&lt;br /&gt;
| [d] managers, systems administrators, and users of the system are made aware of the applicable policies, standards, and procedures related to the security of the system. || Artifact || Policies, standards and procedures for employees within training (completed training report).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AT.L2-3.2.2 – Role-Based Training ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AT.L2-3.2.2_Details|&#039;&#039;&#039;AT.L2-3.2.2&#039;&#039;&#039;]] Ensure that personnel are trained to carry out their assigned information security-related duties and responsibilities.|-&lt;br /&gt;
|-&lt;br /&gt;
| [a] information security-related duties, roles, and responsibilities are defined. || Document || Policy/Procedures/Instruction, Job Role Matrix, Position Descriptions, User Roles.&lt;br /&gt;
|-&lt;br /&gt;
| [b] information security-related duties, roles, and responsibilities are assigned to designated personnel. || Artifact || Screenshot of breakout of different roles/permissions assigned to individuals (i.e. ActiveDirectory); Privilege Access Agreement.&lt;br /&gt;
|-&lt;br /&gt;
| [c] personnel are adequately trained to carry out their assigned information security-related duties, roles, and responsibilities. || Artifact || Screenshot of tool and/or training specifying security specific roles, duties and responsibilities; Screenshot of required certifications (i.e. Sec+, CISSP).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AT.L2-3.2.3 – Insider Threat Awareness ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AT.L2-3.2.3_Details|&#039;&#039;&#039;AT.L2-3.2.3&#039;&#039;&#039;]] Provide security awareness training on recognizing and reporting potential indicators of insider threat.&lt;br /&gt;
|-&lt;br /&gt;
| [a] potential indicators associated with insider threats are identified. || Document || Insidert Threat Policy/Procedures/Instruction; Insider Threat Training/Briefing.&lt;br /&gt;
|-&lt;br /&gt;
| [b] security awareness training on recognizing and reporting potential indicators of insider threat is provided to managers and employees. || Artifact || Screenshot of training records showing completion of Insider Threat training, emails showing completion of Insider Threat training, Screenshot of certificate showing completion with individual&#039;s name.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Audit and Accountability (AU) ==&lt;br /&gt;
=== AU.L2-3.3.1 – System Auditing ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AU.L2-3.3.1_Details|&#039;&#039;&#039;AU.L2-3.3.1&#039;&#039;&#039;]] Create and retain system audit logs and records to the extent needed to enable the monitoring, analysis, investigation, and reporting of unlawful or unauthorized system activity.&lt;br /&gt;
|-&lt;br /&gt;
| [a] audit logs needed (i.e., event types to be logged) to enable the monitoring, analysis, investigation, and reporting of unlawful or unauthorized system activity are specified. || Document || SSP, policy, or auditing and logging process that defines specific types of events to be logged.&lt;br /&gt;
|-&lt;br /&gt;
| [b] the content of audit records needed to support monitoring, analysis, investigation, and reporting of unlawful or unauthorized system activity is defined. || Document || SSP, policy, or auditing and logging process that defines specific content of audit records/files.&lt;br /&gt;
|-&lt;br /&gt;
| [c] audit records are created (generated). || Screen Share || Screen share of tool that shows logs are generated for all systems.&lt;br /&gt;
|-&lt;br /&gt;
| [d] audit records, once created, contain the defined content. || Screen Share || Screen share of tool that shows logs contain defined content as defined in SSP, policy, or procedures.&lt;br /&gt;
|-&lt;br /&gt;
| [e] retention requirements for audit records are defined. || Document || SSP, Polocy, or Auditing and logging process that describes how long records are kept.&lt;br /&gt;
|-&lt;br /&gt;
| [f] audit records are retained as defined. || Screen Share || Screen share of tool that shows records and audit content retained at a minimum as defined.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AU.L2-3.3.2 – User Accountability ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AU.L2-3.3.2_Details|&#039;&#039;&#039;AU.L2-3.3.2&#039;&#039;&#039;]] Ensure that the actions of individual system users can be uniquely traced to those users so they can be held accountable for their actions.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the content of the audit records needed to support the ability to uniquely trace users to their actions is defined. || Document || SSP, policy, or process that defines actions traced back to individuals.&lt;br /&gt;
|-&lt;br /&gt;
| [b] audit records, once created, contain the defined content. || Screen Share || Screen share of tool that shows audit records traced to specific users/roles.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AU.L2-3.3.3 – Event Review ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AU.L2-3.3.3_Details|&#039;&#039;&#039;AU.L2-3.3.3&#039;&#039;&#039;]] Review and update logged events.&lt;br /&gt;
|-&lt;br /&gt;
| [a] a process for determining when to review logged events is defined. || Document || SSP, policy, or documented process that shows frequency of when to review types of logged events.&lt;br /&gt;
|-&lt;br /&gt;
| [b] event types being logged are reviewed in accordance with the defined review process. || Artifact || Evidence through a documented method such as meeting minutes, CAB minutes, etc. of log sources and log events being logged at the defined frequency.&lt;br /&gt;
|-&lt;br /&gt;
| [c] event types being logged are updated based on the review. || Artifact || Evidence of implementation based on the results of the review of logged events/sources through a ticket, meeting minutes, or screen share of the tool that shows changes implemented (finetuning).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AU.L2-3.3.4 – Audit Failure Alerting ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AU.L2-3.3.4_Details|&#039;&#039;&#039;AU.L2-3.3.4&#039;&#039;&#039;]] Alert in the event of an audit logging process failure.&lt;br /&gt;
|-&lt;br /&gt;
| [a] personnel or roles to be alerted in the event of an audit logging process failure are identified. || Document || SSP, policy, or procedure that shows who needs to be notified in case of an audit failure.&lt;br /&gt;
|-&lt;br /&gt;
| [b] types of audit logging process failures for which alert will be generated are defined. || Document || SSP, policy, or procedure that shows what types of failure will generate notifications.&lt;br /&gt;
|-&lt;br /&gt;
| [c] identified personnel or roles are alerted in the event of an audit logging process failure. || Artifact || Artifact such as email or ticket that shows the identified personnel were alerted of any audit/logging process failure as defined.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AU.L2-3.3.5 – Audit Correlation ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AU.L2-3.3.5_Details|&#039;&#039;&#039;AU.L2-3.3.5&#039;&#039;&#039;]] Correlate audit record review, analysis, and reporting processes for investigation and response to indications of unlawful, unauthorized, suspicious, or unusual activity.&lt;br /&gt;
|-&lt;br /&gt;
| [a] audit record review, analysis, and reporting processes for investigation and response to indications of unlawful, unauthorized, suspicious, or unusual activity are defined. || Document || SSP, policy, or procedure covering audit logging, monitoring, and reporting.&lt;br /&gt;
|-&lt;br /&gt;
| [b] defined audit record review, analysis, and reporting processes are correlated. || Artifact || Artifact showing an audit event and the resultant corrective action or actions to the event; this can be a Help Desk ticket, meeting notes, or a change control board items showing the event and any corrective action taken.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AU.L2-3.3.6 – Reduction &amp;amp; Reporting ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AU.L2-3.3.6_Details|&#039;&#039;&#039;AU.L2-3.3.6&#039;&#039;&#039;]] Provide audit record reduction and report generation to support on-demand analysis and reporting.&lt;br /&gt;
|-&lt;br /&gt;
| [a] an audit record reduction capability that supports on-demand analysis is provided. || Screen Share || Screen share of the logging environment where an event can be selected and traced back to a specific device, or dashboard showing realtime event analysis.&lt;br /&gt;
|-&lt;br /&gt;
| [b] a report generation capability that supports on-demand reporting is provided. || Screen Share || Screen share showing the generation of an on demand report.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AU.L2-3.3.7 – Authoritative Time Source ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AU.L2-3.3.7_Details|&#039;&#039;&#039;AU.L2-3.3.7&#039;&#039;&#039;]] Provide a system capability that compares and synchronizes internal system clocks with an authoritative source to generate time stamps for audit records.&lt;br /&gt;
|-&lt;br /&gt;
| [a] internal system clocks are used to generate time stamps for audit records. || Screen Share || Screen share showing the NTP settings of a windows, Unix, Linux device; a screen share showing the NTP settings of network appliances.&lt;br /&gt;
|-&lt;br /&gt;
| [b] an authoritative source with which to compare and synchronize internal system clocks is specified. || Document || SSP or policy indicating that devices need to be synched to a local authoritative time device that is synched with an authoritative time service.&lt;br /&gt;
|-&lt;br /&gt;
| [c] internal system clocks used to generate time stamps for audit records are compared to and synchronized with the specified authoritative time source. || Screen Share || Screen share showing device logging appliance time is point to the appropriate authoritative time server.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AU.L2-3.3.8 – Audit Protection ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AU.L2-3.3.8_Details|&#039;&#039;&#039;AU.L2-3.3.8&#039;&#039;&#039;]] Protect audit information and audit logging tools from unauthorized access, modification, and deletion.&lt;br /&gt;
|-&lt;br /&gt;
| [a] audit information is protected from unauthorized access. || Screen Share || Screen share showing operating system permissions on the audit folders being restricted to appropriate users.&lt;br /&gt;
|-&lt;br /&gt;
| [b] audit information is protected from unauthorized modification. || Screen Share || Screen share showing operating system permissions on the audit folders being restricted to appropriate users.&lt;br /&gt;
|-&lt;br /&gt;
| [c] audit information is protected from unauthorized deletion. || Screen Share || Screen share showing operating system permissions on the audit folders being restricted to appropriate users.&lt;br /&gt;
|-&lt;br /&gt;
| [d] audit logging tools are protected from unauthorized access. || Screen Share || Artifact showing access permissions in the SIEM tool.&lt;br /&gt;
|-&lt;br /&gt;
| [e] audit logging tools are protected from unauthorized modification. || Screen Share || Artifact showing update permissions in the SIEM tool.&lt;br /&gt;
|-&lt;br /&gt;
| [f] audit logging tools are protected from unauthorized deletion. || Screen Share || Artifact showing delete permissions in the SIEM tool.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AU.L2-3.3.9 – Audit Management ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AU.L2-3.3.9_Details|&#039;&#039;&#039;AU.L2-3.3.9&#039;&#039;&#039;]] Limit management of audit logging functionality to a subset of privileged users.&lt;br /&gt;
|-&lt;br /&gt;
| [a] a subset of privileged users granted access to manage audit logging functionality is defined. || Document || SSP or policy indicating which users or groups have access to audit logs.&lt;br /&gt;
|-&lt;br /&gt;
| [b] management of audit logging functionality is limited to the defined subset of privileged users. || Screen Share || Artifact showing SIEM or OS folder permissions (this should be limited to the assigned users or groups); artifact showing an ACL setting in SIEM tool in regards to logs.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Configuration Management (CM) ==&lt;br /&gt;
=== CM.L2-3.4.1 – System Baselining ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_CM.L2-3.4.1_Details|&#039;&#039;&#039;CM.L2-3.4.1&#039;&#039;&#039;]] Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles.&lt;br /&gt;
|-&lt;br /&gt;
| [a] a baseline configuration is established. || Document || Documentation showing or explaining standard imaging process (how standard images are deployed and where  they are stored).&lt;br /&gt;
|-&lt;br /&gt;
| [b] the baseline configuration includes hardware, software, firmware, and documentation. || Artifact || Screenshot of repository of where images are maintained and information relating to hardware, software, and firmware.&lt;br /&gt;
|-&lt;br /&gt;
| [c] the baseline configuration is maintained (reviewed and updated) throughout the system development life cycle. || Artifact || Screenshot/evidence displaying management of baseline configurations (how often they are being managed as stated).&lt;br /&gt;
|-&lt;br /&gt;
| [d] a system inventory is established. || Document || Screenshot/evidence displaying inventory listing of approved products for use.&lt;br /&gt;
|-&lt;br /&gt;
| [e] the system inventory includes hardware, software, firmware, and documentation. || Artifact || Screeenshot/evidence displaying inventory listing of approved products and versions permitted for use.&lt;br /&gt;
|-&lt;br /&gt;
| [f] the inventory is maintained (reviewed and updated) throughout the system development life cycle. || Artifact || Screeenshot/evidence displaying management of baseline configurations (How often and are they being managed as stated.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== CM.L2-3.4.2 – Security Configuration Enforcement ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_CM.L2-3.4.2_Details|&#039;&#039;&#039;CM.L2-3.4.2&#039;&#039;&#039;]] Establish and enforce security configuration settings for information technology products employed in organizational systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] security configuration settings for information technology products employed in the system are established and included in the baseline configuration. || Document || Documentation explaining methodology used by organization to create secure baselines (STIGs, benchmarks).&lt;br /&gt;
|-&lt;br /&gt;
| [b] security configuration settings for information technology products employed in the system are enforced. || Artifact || Evidence of tool/s used to enforce security configurations to ensure images used are free from modification unless authorized.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== CM.L2-3.4.3 – System Change Management ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_CM.L2-3.4.3_Details|&#039;&#039;&#039;CM.L2-3.4.3&#039;&#039;&#039;]] Track, review, approve or disapprove, and log changes to organizational systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] changes to the system are tracked. || Artifact || Evidence of IT Service Management tool / process used to track system changes.&lt;br /&gt;
|-&lt;br /&gt;
| [b] changes to the system are reviewed. || Artifact || Evidence of IT Service Management tool / process used to review system changes.&lt;br /&gt;
|-&lt;br /&gt;
| [c] changes to the system are approved or disapproved. || Artifact || Evidence of IT Service Management tool / process used to approve/disapprove system changes.&lt;br /&gt;
|-&lt;br /&gt;
| [d] changes to the system are logged. || Artifact || Evidence of IT Service Management tool / process used to log system changes.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== CM.L2-3.4.4 – Security Impact Analysis ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_CM.L2-3.4.4_Details|&#039;&#039;&#039;CM.L2-3.4.4&#039;&#039;&#039;]] Analyze the security impact of changes prior to implementation.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the security impact of changes to the system is analyzed prior to implementation. || Artifact || Document explaining that security impact analysis of proposed changes to a system is conducted prior to implementation.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== CM.L2-3.4.5 – Access Restrictions for Change ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_CM.L2-3.4.5_Details|&#039;&#039;&#039;CM.L2-3.4.5&#039;&#039;&#039;]] Define, document, approve, and enforce physical and logical access restrictions associated with changes to organizational systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] physical access restrictions associated with changes to the system are defined. || Document || Document explaining the process of how physical access restrictions are defined for an individuals ability to make system changes.&lt;br /&gt;
|-&lt;br /&gt;
| [b] physical access restrictions associated with changes to the system are documented. || Document || Document explaining the process of how physical access restrictions are defined for an individuals ability to make system changes are documented; access request process.&lt;br /&gt;
|-&lt;br /&gt;
| [c] physical access restrictions associated with changes to the system are approved. || Artifact || Evidence of process of how physical access to systems are granted (i.e. physical access request sample).&lt;br /&gt;
|-&lt;br /&gt;
| [d] physical access restrictions associated with changes to the system are enforced. || Physical Review || Evidence of process of how physical access to systems are enforced (physical access system).&lt;br /&gt;
|-&lt;br /&gt;
| [e] logical access restrictions associated with changes to the system are defined. || Document || Document explaining the process of how logical access restrictions are defined for an individual&#039;s ability to make system changes.&lt;br /&gt;
|-&lt;br /&gt;
| [f] logical access restrictions associated with changes to the system are documented. || Document || Document explaining the process of how logical access restrictions are defined for an individual&#039;s ability to make system changes are documented.&lt;br /&gt;
|-&lt;br /&gt;
| [g] logical access restrictions associated with changes to the system are approved. || Artifact || Evidence of process of how logical access to systems are granted.&lt;br /&gt;
|-&lt;br /&gt;
| [h] logical access restrictions associated with changes to the system are enforced. || Artifact || Evidence of process of how logical access to systems are enforced.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== CM.L2-3.4.6 – Least Functionality ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_CM.L2-3.4.6_Details|&#039;&#039;&#039;CM.L2-3.4.6&#039;&#039;&#039;]] Employ the principle of least functionality by configuring organizational systems to provide only essential capabilities.&lt;br /&gt;
|-&lt;br /&gt;
| [a] essential system capabilities are defined based on the principle of least functionality. || Document || Documentation explaining how systems are configured to utilize the principle of least functionality for designated users.&lt;br /&gt;
|-&lt;br /&gt;
| [b] the system is configured to provide only the defined essential capabilities. || Screen Share || Evidence displaying how systems are configured to utilize the principle of least functionality for designated users; disabled service settings, accepted standards for hardening (CIS benchmarks, etc.).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== CM.L2-3.4.7 – Nonessential Functionality ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_CM.L2-3.4.7_Details|&#039;&#039;&#039;CM.L2-3.4.7&#039;&#039;&#039;]] Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services.&lt;br /&gt;
|-&lt;br /&gt;
| [a] essential programs are defined. || Document || Documented essential programs specified; build documents; software center; SSP.&lt;br /&gt;
|-&lt;br /&gt;
| [b] the use of nonessential programs is defined. || Document || Documented listing of nonessential programs (whatever is NOT specified in [a]); AUP/User Agreement may identify nonessential use/programs.&lt;br /&gt;
|-&lt;br /&gt;
| [c] the use of nonessential programs is restricted, disabled, or prevented as defined. || Screen Share || Tool used to restrict nonessential programs displays restrictions as defined (McAfee ePO settings, Carbon Black rules, etc.).&lt;br /&gt;
|-&lt;br /&gt;
| [d] essential functions are defined. || Document || Documented essential functions are specified.&lt;br /&gt;
|-&lt;br /&gt;
| [e] the use of nonessential functions is defined. || Document || Documented nonessential functions are specified.&lt;br /&gt;
|-&lt;br /&gt;
| [f] the use of nonessential functions is restricted, disabled, or prevented as defined. || Screen Share || Tool used to restrict essential/nonessential functions displays restrictions as defined.&lt;br /&gt;
|-&lt;br /&gt;
| [g] essential ports are defined. || Document || Documented essential ports are specified.&lt;br /&gt;
|-&lt;br /&gt;
| [h] the use of nonessential ports is defined. || Document || Documented nonessential ports functions are specified.&lt;br /&gt;
|-&lt;br /&gt;
| [i] the use of nonessential ports is restricted, disabled, or prevented as defined. || Screen Share || Tool used to restrict essential/nonessential ports displays restrictions as defined (FW rules; McAfee; GPO, etc.).&lt;br /&gt;
|-&lt;br /&gt;
| [j] essential protocols are defined. || Document || Documented essential protocols are specified.&lt;br /&gt;
|-&lt;br /&gt;
| [k] the use of nonessential protocols is defined. || Document || Documented nonessential protocols functions are specified.&lt;br /&gt;
|-&lt;br /&gt;
| [l] the use of nonessential protocols is restricted, disabled, or prevented as defined. || Screen Share || Tool used to restrict essential/nonessential protocols displays restrictions as defined (FW rules; GPO, etc.).&lt;br /&gt;
|-&lt;br /&gt;
| [m] essential services are defined. || Document || Documented essential services specified.&lt;br /&gt;
|-&lt;br /&gt;
| [n] the use of nonessential services is defined. || Document || Documented nonessential services functions are specified.&lt;br /&gt;
|-&lt;br /&gt;
| [o] the use of nonessential services is restricted, disabled, or prevented as defined. || Screen Share || Tool used to restrict essential/nonessential services displays restrictions as defined.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== CM.L2-3.4.8 – Application Execution Policy ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_CM.L2-3.4.8_Details|&#039;&#039;&#039;CM.L2-3.4.8&#039;&#039;&#039;]] Apply deny-by-exception (blacklisting) policy to prevent the use of unauthorized software or deny-all, permit-by-exception (whitelisting) policy to allow the execution of authorized software.&lt;br /&gt;
|-&lt;br /&gt;
| [a] a policy specifying whether whitelisting or blacklisting is to be implemented is specified. || Document || Documentation explaining whitelisting or blacklisting process.&lt;br /&gt;
|-&lt;br /&gt;
| [b] the software allowed to execute under whitelisting or denied use under blacklisting is specified. || Document || Documentation explaining whitelisting or blacklisting process for software.&lt;br /&gt;
|-&lt;br /&gt;
| [c] whitelisting to allow the execution of authorized software or blacklisting to prevent the use of unauthorized software is implemented as specified. || Screen Share || Tool used for whitelisting or blacklisting for software shows capability of restricting/authorizing software (Carbon Black dashboard, &amp;quot;SW Store&amp;quot;, web proxies, DNS Blackhole, etc.).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== CM.L2-3.4.9 – User-Installed Software ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_CM.L2-3.4.9_Details|&#039;&#039;&#039;CM.L2-3.4.9&#039;&#039;&#039;]] Control and monitor user-installed software.&lt;br /&gt;
|-&lt;br /&gt;
| [a] a policy for controlling the installation of software by users is established. || Document || Documented software authorization process or methodology for approval.&lt;br /&gt;
|-&lt;br /&gt;
| [b] installation of software by users is controlled based on the established policy. || Screen Share || Evidence that approval/restriction in installation of software by authorized personnel is implemented as specified (AUP, GPO, etc.).&lt;br /&gt;
|-&lt;br /&gt;
| [c] installation of software by users is monitored. || Screen Share || Evidence that installation of software by authorized personnel is monitored (SCCM groups, SW Center, etc.).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Identification and Authentication (IA) ==&lt;br /&gt;
=== IA.L2-3.5.1 – Identification [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IA.L2-3.5.1_Details|&#039;&#039;&#039;IA.L2-3.5.1&#039;&#039;&#039;]] Identify information system users, processes acting on behalf of users, or devices.&lt;br /&gt;
|-&lt;br /&gt;
| [a] system users are identified. || Document || Based on what is defined in their documentation (SSP, AUP, Policy, SOP), request to see a sample of non-privileged/privileged users in AD OU group (overlaps with 3.1.1 and 3.1.5).&lt;br /&gt;
|-&lt;br /&gt;
| [b] processes acting on behalf of users are identified. || Screen Share || Based on what is defined in their documentation (SSP, AUP, Policy, SOP), request to see a sample of service accounts in AD OU group (overlaps with 3.1.1 and 3.1.5).&lt;br /&gt;
|-&lt;br /&gt;
| [c] devices accessing the system are identified. || Screen Share || Based on what is defined in their documentation (SSP, AUP, Policy, SOP), request to see a sample of domain-joined workstation &amp;amp; servers in AD OU group (overlaps with 3.1.1 and 3.1.5).  For network devices, request screen share/artifact to show how they are identified on the enterprise network.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IA.L2-3.5.2 – Authentication [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IA.L2-3.5.2_Details|&#039;&#039;&#039;IA.L2-3.5.2&#039;&#039;&#039;]] Authenticate (or verify) the identities of those users, processes, or devices, as a prerequisite to allowing access to organizational information systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the identity of each user is authenticated or verified as a prerequisite to system access. || Screen Share || If the user logs in with non-privileged account during other demoes and then a privileged account, then this should be satisfied.  If screen share is unavailable, request logs to show successful and unsuccessful login by privileged and non-privilged users.&lt;br /&gt;
|-&lt;br /&gt;
| [b] the identity of each process acting on behalf of a user is authenticated or verified as a prerequisite to system access. || Screen Share || Request a log that shows successful/unsuccessful service account trying to log on to company&#039;s asset.&lt;br /&gt;
|-&lt;br /&gt;
| [c] the identity of each device accessing or connecting to the system is authenticated or verified as a prerequisite to system access. || Screen Share || Request a log that shows domain-joined workstation/server authenticating to AD (focus on the MAC/IP address/hostname).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IA.L2-3.5.3 – Multifactor Authentication ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IA.L2-3.5.3_Details|&#039;&#039;&#039;IA.L2-3.5.3&#039;&#039;&#039;]] Use multifactor authentication for local and network access to privileged accounts and for network access to non-privileged accounts.&lt;br /&gt;
|-&lt;br /&gt;
| [a] privileged accounts are identified. || Screen Share|| Based on what is defined in their documentation, request to see a sample of privileged users in AD OU group.  Overlaps with 3.1.5.  Screenshot/screen share to show implementation is enforced.&lt;br /&gt;
|-&lt;br /&gt;
| [b] multifactor authentication is implemented for local access to privileged accounts. || Document || SSP, AUP, Policy, SOP that defines that MFA is needed for privileged local access.&lt;br /&gt;
|-&lt;br /&gt;
| [c] multifactor authentication is implemented for network access to privileged accounts. || Screen Share || Within the MFA implementation mechanism, show that privileged users are forced to use MFA;  Screenshot/Screen share to show implementation is enforced.&lt;br /&gt;
|-&lt;br /&gt;
| [d] multifactor authentication is implemented for network access to non-privileged accounts. || Screen Share || Within the MFA implementation mechanism, show that non-privileged users are forced to use MFA; Screenshot/Screen share to show implementation is enforced.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IA.L2-3.5.4 – Replay-Resistant Authentication ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IA.L2-3.5.4_Details|&#039;&#039;&#039;IA.L2-3.5.4&#039;&#039;&#039;]] Employ replay-resistant authentication mechanisms for network access to privileged and non-privileged accounts.&lt;br /&gt;
|-&lt;br /&gt;
| [a] replay-resistant authentication mechanisms are implemented for network account access to privileged and non-privileged accounts. || Screen Share || Show the GPO setting that enforces Kerberos within AD.  If MFA is used, show the implementation to enforce replay resistant techniques.  For non-windows, show the technical solution to enforce replay resistant attacks.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IA.L2-3.5.5 – Identifier Reuse ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IA.L2-3.5.5_Details|&#039;&#039;&#039;IA.L2-3.5.5&#039;&#039;&#039;]] Prevent reuse of identifiers for a defined period.&lt;br /&gt;
|-&lt;br /&gt;
| [a] a period within which identifiers cannot be reused is defined. || Document || SSP, policies, or SOP that defines identifier reuse.&lt;br /&gt;
|-&lt;br /&gt;
| [b] reuse of identifiers is prevented within the defined period. || Screen Share || Show the GPO setting/technical solution that enforces what is defined in policy/documentation (this can be automated or manual process; screen share/artifacts can be presented to satisfy this requirement.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IA.L2-3.5.6 – Identifier Handling ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IA.L2-3.5.6_Details|&#039;&#039;&#039;IA.L2-3.5.6&#039;&#039;&#039;]] Disable identifiers after a defined period of inactivity.&lt;br /&gt;
|-&lt;br /&gt;
| [a] a period of inactivity after which an identifier is disabled is defined. || Document || SSP, policy that defines the period of inactivity after which an identifier is disabled.&lt;br /&gt;
|-&lt;br /&gt;
| [b] identifiers are disabled after the defined period of inactivity. || Screen Share || Screen share AD or similar tool supporting directory-based identity-related services for disabled accounts (can be done by hand or script).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IA.L2-3.5.7 – Password Complexity ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IA.L2-3.5.7_Details|&#039;&#039;&#039;IA.L2-3.5.7&#039;&#039;&#039;]] Enforce a minimum password complexity and change of characters when new passwords are created.&lt;br /&gt;
|-&lt;br /&gt;
| [a] password complexity requirements are defined. || Document || SSP, policy that defines password complexity requirements.&lt;br /&gt;
|-&lt;br /&gt;
| [b] password change of character requirements are defined. || Document || SSP, policy that defines change of character requirements are defined.&lt;br /&gt;
|-&lt;br /&gt;
| [c] minimum password complexity requirements as defined are enforced when new passwords are created. || Screen Share || Screen share of AD or similar directory-based identity-related service tool to show complexity requirements.&lt;br /&gt;
|-&lt;br /&gt;
| [d] minimum password change of character requirements as defined are enforced when new passwords are created. || Screen Share || Screen share of Group Policy configuration or similar tool providing centralized management and configuration of operating systems, applications, and users&#039; settings to show that characters must be changed.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IA.L2-3.5.8 – Password Reuse ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IA.L2-3.5.8_Details|&#039;&#039;&#039;IA.L2-3.5.8&#039;&#039;&#039;]] Prohibit password reuse for a specified number of generations.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the number of generations during which a password cannot be reused is specified. || Document || SSP, policy that specifies the number of generations during which a password cannot be reused is specified.&lt;br /&gt;
|-&lt;br /&gt;
| [b] reuse of passwords is prohibited during the specified number of generations. || Screen Share || Screen share Group Policy or similar tool providing centralized management and configuration of operating systems, applications, and users&#039; settings in a directory-based identity-related service tool&#039;s configuration to show reuse of passwords is prohibited.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IA.L2-3.5.9 – Temporary Passwords ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IA.L2-3.5.9_Details|&#039;&#039;&#039;IA.L2-3.5.9&#039;&#039;&#039;]] Allow temporary password use for system logons with an immediate change to a permanent password.&lt;br /&gt;
|-&lt;br /&gt;
| [a] an immediate change to a permanent password is required when a temporary password is used for system logon. || Screen Share || Screen share of Group Policy or similar tool providing centralized management and configuration of operating systems, applications, and users&#039; settings in a directory-based identity-related service tool&#039;s configuration to show &amp;quot;change password at first logon.&amp;quot;&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IA.L2-3.5.10 – Cryptographically-Protected Passwords ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IA.L2-3.5.1_Details|&#039;&#039;&#039;IA.L2-3.5.1&#039;&#039;&#039;]] Store and transmit only cryptographically-protected passwords.&lt;br /&gt;
|-&lt;br /&gt;
| [a] passwords are cryptographically protected in storage. || Screen Share || Screen share Group Policy or similar tool providing centralized management and configuration of operating systems, applications, and users&#039; settings in a directory-based identity-related service tool&#039;s configuration that Kerberos, or a similar network authentication protocol that works on the basis of tickets to allow nodes communicating over a non-secure network to prove their identity to one another in a secure manner, is enabled.&lt;br /&gt;
|-&lt;br /&gt;
| [b] passwords are cryptographically protected in transit. || Screen Share || Screen share Group Policy or similar tool providing centralized management and configuration of operating systems, applications, and users&#039; settings in a directory-based identity-related service tool&#039;s configuration that Kerberos, or a similar network authentication protocol that works on the basis of tickets to allow nodes communicating over a non-secure network to prove their identity to one another in a secure manner, is enabled.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IA.L2-3.5.11 – Obscure Feedback ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IA.L2-3.5.10_Details|&#039;&#039;&#039;IA.L2-3.5.10&#039;&#039;&#039;]] Obscure feedback of authentication information.&lt;br /&gt;
|-&lt;br /&gt;
| [a] authentication information is obscured during the authentication process. || Screen Share || Screen share of Group Policy or similar tool providing centralized management and configuration of operating systems, applications, and users&#039; settings in a directory-based identity-related service tool&#039;s configuration to show that passwords are obscured.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Incident Response (IR) ==&lt;br /&gt;
=== IR.L2-3.6.1 – Incident Handling ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IR.L2-3.6.1_Details|&#039;&#039;&#039;IR.L2-3.6.1&#039;&#039;&#039;]] Establish an operational incident-handling capability for organizational systems that includes preparation, detection, analysis, containment, recovery, and user response activities.&lt;br /&gt;
|-&lt;br /&gt;
| [a] an operational incident-handling capability is established. || Document || Incident Response SOP/Plan.&lt;br /&gt;
|-&lt;br /&gt;
| [b] the operational incident-handling capability includes preparation. || Document || Incident Response SOP/Plan, prior incident report, training, COOP plan.&lt;br /&gt;
|-&lt;br /&gt;
| [c] the operational incident-handling capability includes detection. || Document || Incident Response SOP/Plan; definition of tools used to detect; artifacts showing tools used; prior incident report.&lt;br /&gt;
|-&lt;br /&gt;
| [d] the operational incident-handling capability includes analysis. || Document || Incident Response SOP/Plan; Definition of tools used to analyze potential incidents; artifacts showing tools used for analysis; prior incident report.&lt;br /&gt;
|-&lt;br /&gt;
| [e] the operational incident-handling capability includes containment. || Document || Incident Response SOP/Plan; isolation/quarantine process; user training.&lt;br /&gt;
|-&lt;br /&gt;
| [f] the operational incident-handling capability includes recovery. || Document || Incident Response SOP/Plan; COOP Plan; prior incident reports, re-baselining impacted devices.&lt;br /&gt;
|-&lt;br /&gt;
| [g] the operational incident-handling capability includes user response. || Document || Incident Response SOP/Plan; user awareness training; Help Desk process.&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IR.L2-3.6.2 – Incident Reporting ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IR.L2-3.6.2_Details|&#039;&#039;&#039;IR.L2-3.6.2&#039;&#039;&#039;]] Track, document, and report incidents to designated officials and/or authorities both internal and external to the organization.&lt;br /&gt;
|-&lt;br /&gt;
| [a] incidents are tracked. || Artifact || Incident Response SOP/Plan; ITSM artifact; technical implementation for incident tracking.&lt;br /&gt;
|-&lt;br /&gt;
| [b] incidents are documented. || Artifact || Incident Response SOP/Plan; ITSM artifact; technical implementation for incident tracking.&lt;br /&gt;
|-&lt;br /&gt;
| [c] authorities to whom incidents are to be reported are identified. || Document || Incident Response SOP/Plan.&lt;br /&gt;
|-&lt;br /&gt;
| [d] organizational officials to whom incidents are to be reported are identified. || Document || Incident Response SOP/Plan.&lt;br /&gt;
|-&lt;br /&gt;
| [e] identified authorities are notified of incidents. || Screen Share || Prior incident report; DIBNET login; prior email notifications.&lt;br /&gt;
|-&lt;br /&gt;
| [f] identified organizational officials are notified of incidents. || Artifact || Prior incident report; prior email notifications; tabletop exercises.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IR.L2-3.6.3 – Incident Response Testing ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IR.L2-3.6.3_Details|&#039;&#039;&#039;IR.L2-3.6.3&#039;&#039;&#039;]] Test the organizational incident response capability.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the incident response capability is tested. || Artifact || Incident response table top/scheduled or unscheduled test or penetration test.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Maintenance (MA) ==&lt;br /&gt;
=== MA.L2-3.7.1 – Perform Maintenance ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MA.L2-3.7.1_Details|&#039;&#039;&#039;MA.L2-3.7.1&#039;&#039;&#039;]] Perform maintenance on organizational systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] system maintenance is performed. || Artifact || Establish typical maintenance activities (HVAC, UPS, power distribution, generators, copier maintenance) that are performed; maintenance agreements or contracts detailing these types of activities are acceptable; interview responses should be considered.  This requirement should not be confused with 3.14.1 - report, remediate, and correct system flaws in a timely manner (patch management).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MA.L2-3.7.2 – System Maintenance Control ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MA.L2-3.7.2_Details|&#039;&#039;&#039;MA.L2-3.7.2&#039;&#039;&#039;]] Provide controls on the tools, techniques, mechanisms, and personnel used to conduct system maintenance.&lt;br /&gt;
|-&lt;br /&gt;
| [a] tools used to conduct system maintenance are controlled. || Artifact || Tools may largely depend on the assessed environment; discussion examples include network diagnostic and monitoring tools (including hardware and software); artifacts could demonstrate secured locations/areas for these tools (photos) or checkout sheets/rosters (documents) depicting responsible personnel and the dates/times of checkout.&lt;br /&gt;
|-&lt;br /&gt;
| [b] techniques used to conduct system maintenance are controlled. || Artifact || Processes for scheduling, performing, documenting, reviewing, approving, and monitoring maintenance and repairs for the information system.&lt;br /&gt;
|-&lt;br /&gt;
| [c] mechanisms used to conduct system maintenance are controlled. || Artifact || Processes for scheduling, performing, documenting, reviewing, approving, and monitoring maintenance and repairs for the information system.&lt;br /&gt;
|-&lt;br /&gt;
| [d] personnel used to conduct system maintenance are controlled. || Physical Review || Screenshot of who is authorized to conduct maintenance; maintenance personnel training program.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MA.L2-3.7.3 – Equipment Sanitization ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MA.L2-3.7.3_Details|&#039;&#039;&#039;MA.L2-3.7.3&#039;&#039;&#039;]] Ensure equipment removed for off-site maintenance is sanitized of any CUI.&lt;br /&gt;
|-&lt;br /&gt;
| [a] equipment to be removed from organizational spaces for off-site maintenance is sanitized of any CUI. || Artifact || Document or artifact; record if equipment sanitized; categories of sanitization/destruction defined; sanitization procedural document.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MA.L2-3.7.4 – Media Inspection ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MA.L2-3.7.4_Details|&#039;&#039;&#039;MA.L2-3.7.4&#039;&#039;&#039;]] Check media containing diagnostic and test programs for malicious code before the media are used in organizational systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] media containing diagnostic and test programs are checked for malicious code before being used in organizational systems that process, store, or transmit CUI. || Artifact || Screenshot of diagnostic/test program being used (such as Symantec and McAfee on access scans…).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MA.L2-3.7.5 – Nonlocal Maintenance ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MA.L2-3.7.5_Details|&#039;&#039;&#039;MA.L2-3.7.5&#039;&#039;&#039;]] Require multifactor authentication to establish nonlocal maintenance sessions via external network connections and terminate such connections when nonlocal maintenance is complete.&lt;br /&gt;
|-&lt;br /&gt;
| [a] multifactor authentication is used to establish nonlocal maintenance sessions via external network connections. || Screen Share || Describe MFA used to remote from external service to organizational systems for maintenance and screenshot of MFA (3.5.3)(points associated with admin).&lt;br /&gt;
|-&lt;br /&gt;
| [b] nonlocal maintenance sessions established via external network connections are terminated when nonlocal maintenance is complete. || Screen Share || Screenshot VPN session timeout.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MA.L2-3.7.6 – Maintenance Personnel ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MA.L2-3.7.6_Details|&#039;&#039;&#039;MA.L2-3.7.6&#039;&#039;&#039;]] Supervise the maintenance activities of maintenance personnel without required access authorization.&lt;br /&gt;
|-&lt;br /&gt;
| [a] maintenance personnel without required access authorization are supervised during maintenance activities. || Document || System maintenance policy; list of authorized personnel; maintenance records or, contracts/SLAs; WebEx.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Media Protection (MP) ==&lt;br /&gt;
=== MP.L2-3.8.1 – Media Protection ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MP.L2-3.8.1_Details|&#039;&#039;&#039;MP.L2-3.8.1&#039;&#039;&#039;]] Protect (i.e., physically control and securely store) system media containing CUI, both paper and digital.&lt;br /&gt;
|-&lt;br /&gt;
| [a] paper media containing CUI is physically controlled. || Document || Policy showing CUI paper media is controlled; artifact showing who has access; artifacts/records of  inventories conducted; media check out procedures (i.e. file cabinets, encryption, password protection).&lt;br /&gt;
|-&lt;br /&gt;
| [b] digital media containing CUI is physically controlled. || Document || Policy showing CUI digital media is controlled; artifact showing who has access; artifacts/records of inventories conducted; media check out procedures (i.e. file cabinets, external drives, USBs, encryption, password protection).&lt;br /&gt;
|-&lt;br /&gt;
| [c] paper media containing CUI is securely stored. || Physical Review || Check out/sign out sheets; possible photo of storage container/video walk through of storage area; badge reader logs or access lists for keys for secured areas; interview response considered (i.e. file cabinets,  encryption, password protection).&lt;br /&gt;
|-&lt;br /&gt;
| [d] digital media containing CUI is securely stored. || Physical Review || Check out/sign out sheets; possible photo of storage container/video walk through of storage area; badge reader logs or access lists for keys for secured areas; interview response considered (i.e. file cabinets, external drives, USBs, encryption, password protection).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MP.L2-3.8.2 – Media Access ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MP.L2-3.8.2_Details|&#039;&#039;&#039;MP.L2-3.8.2&#039;&#039;&#039;]] Limit access to CUI on system media to authorized users.&lt;br /&gt;
|-&lt;br /&gt;
| [a] access to CUI on system media is limited to authorized users. || Artifact || Document describing how CUI is limited AND artifact showing principle of least access is implemented.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MP.L2-3.8.3 – Media Disposal [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MP.L2-3.8.3_Details|&#039;&#039;&#039;MP.L2-3.8.3&#039;&#039;&#039;]] Sanitize or destroy information system media containing Federal Contract Information before disposal or release for reuse.&lt;br /&gt;
|-&lt;br /&gt;
| [a] system media containing CUI is sanitized or destroyed before disposal. || Document || Policy or artifact of media destruction logs; certificates of destruction; SLAs or contracts.&lt;br /&gt;
|-&lt;br /&gt;
| [b] system media containing CUI is sanitized before it is released for reuse. || Document || Policy or artifact describing method to sanitize, software used (i.e. DoD Wipe, ShredIT and Iron Mountain; Blancco; GDisk, DBAN).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MP.L2-3.8.4 – Media Markings ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MP.L2-3.8.4_Details|&#039;&#039;&#039;MP.L2-3.8.4&#039;&#039;&#039;]] Mark media with necessary CUI markings and distribution limitations.&lt;br /&gt;
|-&lt;br /&gt;
| [a] media containing CUI is marked with applicable CUI markings. || Physical Review || Document or artifact showing CUI markings (i.e. labeling standards ).&lt;br /&gt;
|-&lt;br /&gt;
| [b] media containing CUI is marked with distribution limitations. || Physical Review || Document or artifact showing distro limitations (i.e. labeling standards ).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MP.L2-3.8.5 – Media Accountability ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MP.L2-3.8.5_Details|&#039;&#039;&#039;MP.L2-3.8.5&#039;&#039;&#039;]] Control access to media containing CUI and maintain accountability for media during transport outside of controlled areas.&lt;br /&gt;
|-&lt;br /&gt;
| [a] access to media containing CUI is controlled. || Document || Policy, artifact of audit logs showing tracking, Access Control Lists, records of transport activities (i.e. USB drives, CDs, chain of custody.&lt;br /&gt;
|-&lt;br /&gt;
| [b] accountability for media containing CUI is maintained during transport outside of controlled areas. || Artifact || Artifact of audit logs showing tracking, Access Control Lists, records of transport activities (i.e. USB drives, CDs; chain of custody.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MP.L2-3.8.6 – Portable Storage Encryption ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MP.L2-3.8.6_Details|&#039;&#039;&#039;MP.L2-3.8.6&#039;&#039;&#039;]] Implement cryptographic mechanisms to protect the confidentiality of CUI stored on digital media during transport unless otherwise protected by alternative physical safeguards.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the confidentiality of CUI stored on digital media is protected during transport using cryptographic mechanisms or alternative physical safeguards. || Artifact || Artifact showing crypto mechanisms used to protect (are they FIPS 140-2 [13.11]); artifact showing what alternative physical safeguards are in place (i.e. encryption; BitLocker; McAfee ).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MP.L2-3.8.7 – Removable Media ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MP.L2-3.8.7_Details|&#039;&#039;&#039;MP.L2-3.8.7&#039;&#039;&#039;]] Control the use of removable media on system components.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the use of removable media on system components is controlled. || Artifact || Policy showing if removable media is allowed; writable removable media is restricted; tracking artifacts; what tools are used (i.e. Carbon Black, Crowd Strike, GPO, Zoho Desktop Central); procedure/process describing what happens if it is lost; what mechanisms are in place to control/restrict removable media (i.e. Active Directory Groups and Group Policy artifact showing restriction).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MP.L2-3.8.8 – Shared Media ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MP.L2-3.8.8_Details|&#039;&#039;&#039;MP.L2-3.8.8&#039;&#039;&#039;]] Prohibit the use of portable storage devices when such devices have no identifiable owner.ASSESSMENT OBJECTIVES&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [a] the use of portable storage devices is prohibited when such devices have no identifiable owner. || Artifact || Policy and/or artifact showing company stance on portable storage devices if there is no owner (are personal USB devices allowed or are they company-issued; artifact showing alerts if device is connected to network (i.e. external HDD, Carbon Black, Crowd Strike, GPO, Zoho Desktop Central.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MP.L2-3.8.9 – Protect Backups ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MP.L2-3.8.9_Details|&#039;&#039;&#039;MP.L2-3.8.9&#039;&#039;&#039;]] Protect the confidentiality of backup CUI at storage locations.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the confidentiality of backup CUI is protected at storage locations. || Artifact || Policy on system backups; artifact showing media labeling; artifact showing encyption (is it FIPS 140-2 [13.11]); Access Control List artifact (i.e. backup tapes, Tivoli Storage Manager).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Personnel Security (PS) ==&lt;br /&gt;
=== PS.L2-3.9.1 – Screen Individuals ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_PS.L2-3.9.1_Details|&#039;&#039;&#039;PS.L2-3.9.1&#039;&#039;&#039;]] Screen individuals prior to authorizing access to organizational systems containing CUI.&lt;br /&gt;
|-&lt;br /&gt;
| [a] individuals are screened prior to authorizing access to organizational systems containing CUI. || Artifact || Screenshot of records of screened personnel/background checks.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== PS.L2-3.9.2 – Personnel Actions ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_PS.L2-3.9.2_Details|&#039;&#039;&#039;PS.L2-3.9.2&#039;&#039;&#039;]] Ensure that organizational systems containing CUI are protected during and after personnel actions such as terminations and transfers.&lt;br /&gt;
|-&lt;br /&gt;
| [a] a policy and/or process for terminating system access and any credentials coincident with personnel actions is established. || Document || Personnel security policy/procedures/instruction; Access control policy/procedure/instruction.&lt;br /&gt;
|-&lt;br /&gt;
| [b] system access and credentials are terminated consistent with personnel actions such as termination or transfer. || Artifact || Screenshot of records of personnel transfer and termination actions.&lt;br /&gt;
|-&lt;br /&gt;
| [c] the system is protected during and after personnel transfer actions. || Artifact || Completed outprocessing checklist.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Physical Protection (PE) ==&lt;br /&gt;
=== PE.L2-3.10.1 – Limit Physical Access [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_PE.L2-3.10.1_Details|&#039;&#039;&#039;PE.L2-3.10.1&#039;&#039;&#039;]] Limit physical access to organizational information systems, equipment, and the respective operating environments to authorized individuals.&lt;br /&gt;
|-&lt;br /&gt;
| [a] authorized individuals allowed physical access are identified. || Artifact || Authorized personnel (names) access list.&lt;br /&gt;
|-&lt;br /&gt;
| [b] physical access to organizational systems is limited to authorized individuals. || Physical Review || Badge reader logs, audit logs, and/or card swipe test.&lt;br /&gt;
|-&lt;br /&gt;
| [c] physical access to equipment is limited to authorized individuals. || Physical Review || Badge reader logs, audit logs, and/or card swipe test.&lt;br /&gt;
|-&lt;br /&gt;
| [d] physical access to operating environments is limited to authorized. || Physical Review || Badge reader logs, audit logs, and/or card swipe test.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== PE.L2-3.10.2 – Monitor Facility ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_PE.L2-3.10.2_Details|&#039;&#039;&#039;PE.L2-3.10.2&#039;&#039;&#039;]] Protect and monitor the physical facility and support infrastructure for organizational systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the physical facility where organizational systems reside is protected. || Physical Review || Physical security measures and barriers into the physical facility (cameras/locks/gates/guards, etc.).&lt;br /&gt;
|-&lt;br /&gt;
| [b] the support infrastructure for organizational systems is protected. || Physical Review || Physical barriers to entries into computer spaces, server rooms, etc.&lt;br /&gt;
|-&lt;br /&gt;
| [c] the physical facility where organizational systems reside is monitored. || Physical Review || Audit logs/how the physical facility is being monitored (cameras/access system/guards, etc.).&lt;br /&gt;
|-&lt;br /&gt;
| [d] the support infrastructure for organizational systems is monitored. || Physical Review || Audit logs/how the physical facility is being monitored (cameras/access system/guards, etc.).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== PE.L2-3.10.3 – Escort Visitors [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_PE.L2-3.10.3_Details|&#039;&#039;&#039;PE.L2-3.10.3&#039;&#039;&#039;]] Escort visitors and monitor visitor activity.&lt;br /&gt;
|-&lt;br /&gt;
| [a] visitors are escorted. || Physical Review || Policy/procedures/instruction on methodology for handling non-authorized personnel (entry to exit).&lt;br /&gt;
|-&lt;br /&gt;
| [b] visitor activity is monitored. || Physical Review || Policy/procedures/instructio on methodology for handling non-authorized personnel (entry to exit).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== PE.L2-3.10.4 – Physical Access Logs [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_PE.L2-3.10.4_Details|&#039;&#039;&#039;PE.L2-3.10.4&#039;&#039;&#039;]] Maintain audit logs of physical access.&lt;br /&gt;
|-&lt;br /&gt;
| [a] audit logs of physical access are maintained. || Artifact || Log or report from badging system.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== PE.L2-3.10.5 – Manage Physical Access [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_PE.L2-3.10.5_Details|&#039;&#039;&#039;PE.L2-3.10.5&#039;&#039;&#039;]] Control and manage physical access devices.&lt;br /&gt;
|-&lt;br /&gt;
| [a] physical access devices are identified. || Document || Physical access control systems description, guard force contract/policy, key locks, logical systems specifications, etc.&lt;br /&gt;
|-&lt;br /&gt;
| [b] physical access devices are controlled. || Physical Review || Inventory records of physical access control devices (e.g. keys, locks, card readers, locks, etc.).&lt;br /&gt;
|-&lt;br /&gt;
| [c] physical access devices are managed. || Physical Review || List of security safeguards controlling access to the facility (e.g. cameras, monitoring by guards, isolation of IT systems equiment and or system components).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== PE.L2-3.10.6 – Alternative Work Sites ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_PE.L2-3.10.6_Details|&#039;&#039;&#039;PE.L2-3.10.6&#039;&#039;&#039;]] Enforce safeguarding measures for CUI at alternate work sites.&lt;br /&gt;
|-&lt;br /&gt;
| [a] safeguarding measures for CUI are defined for alternate work sites. || Document || Telework agreement, Acceptable Use Policy and SOP for alternate work locations; user security training validation which includes physical/logical/technical protections of system at alternate work sites.&lt;br /&gt;
|-&lt;br /&gt;
| [b] safeguarding measures for CUI are enforced for alternate work sites. || Artifact || Monitoring/audit log of user activity and logical/physical/technical mechanisms in place to preclude unauthorized activity (telework agreement , AUP?).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Risk Assessment (RA) ==&lt;br /&gt;
=== RA.L2-3.11.1 – Risk Assessments ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_RA.L2-3.11.1_Details|&#039;&#039;&#039;RA.L2-3.11.1&#039;&#039;&#039;]] Periodically assess the risk to organizational operations (including mission, functions, image, or reputation), organizational assets, and individuals, resulting from the operation of organizational systems and the associated processing, storage, or transmission of CUI.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the frequency to assess risk to organizational operations, organizational assets, and individuals is defined. || Document || Risk assessment policy.&lt;br /&gt;
|-&lt;br /&gt;
| [b] risk to organizational operations, organizational assets, and individuals resulting from the operation of an organizational system that processes, stores, or transmits CUI is assessed with the defined frequency. || Artifact || Copy of last risk assessment done within defined frequency.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== RA.L2-3.11.2 – Vulnerability Scan ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_RA.L2-3.11.2_Details|&#039;&#039;&#039;RA.L2-3.11.2&#039;&#039;&#039;]] Scan for vulnerabilities in organizational systems and applications periodically and when new vulnerabilities affecting those systems and applications are identified.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the frequency to scan for vulnerabilities in organizational systems and applications is defined. || Document || Policy/procedures/instruction addressing vulnerability scanning records.&lt;br /&gt;
|-&lt;br /&gt;
| [b] vulnerability scans are performed on organizational systems with the defined frequency. || Screen Share || System configuration settings of vulnerability scanning scheduling and vulnerability scan results of systems within defined frequency.&lt;br /&gt;
|-&lt;br /&gt;
| [c] vulnerability scans are performed on applications with the defined frequency. || Screen Share || System configuration settings of vulnerability scanning scheduling and vulnerability scan results of applications within defined frequency.&lt;br /&gt;
|-&lt;br /&gt;
| [d] vulnerability scans are performed on organizational systems when new vulnerabilities are identified. || Screen Share || View signatures in scanning tool/ad hoc scan performed as a result.&lt;br /&gt;
|-&lt;br /&gt;
| [e] vulnerability scans are performed on applications when new vulnerabilities are identified. || Screen Share || View signatures in scanning tool/ad hoc scan performed as a result.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== RA.L2-3.11.3 – Vulnerability Remediation ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_RA.L2-3.11.3_Details|&#039;&#039;&#039;RA.L2-3.11.3&#039;&#039;&#039;]] Remediate vulnerabilities in accordance with risk assessments.&lt;br /&gt;
|-&lt;br /&gt;
| [a] vulnerabilities are identified. || Artifact || Scan results showing vulnerabilities identified.&lt;br /&gt;
|-&lt;br /&gt;
| [b] vulnerabilities are remediated in accordance with risk assessments. || Artifact || Screenshot/document of scan results of remediated vulnerabilities in accordance to risk assessments.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Security Assessment (CA) ==&lt;br /&gt;
=== CA.L2-3.12.1 – Security Control Assessment ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_CA.L2-3.12.1_Details|&#039;&#039;&#039;CA.L2-3.12.1&#039;&#039;&#039;]] Periodically assess the security controls in organizational systems to determine if the controls are effective in their application.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the frequency of security control assessments is defined. || Document || SSP.&lt;br /&gt;
|-&lt;br /&gt;
| [b] security controls are assessed with the defined frequency to determine if the controls are effective in their application. || Artifact || Copy of last security control assessment done within defined frequency.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== CA.L2-3.12.2 – Operational Plan of Action ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_CA.L2-3.12.2_Details|&#039;&#039;&#039;CA.L2-3.12.2&#039;&#039;&#039;]] Develop and implement plans of action designed to correct deficiencies and reduce or eliminate vulnerabilities in organizational systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] deficiencies and vulnerabilities to be addressed by the plan of action are identified. || Artifact || Plan of Action (POA).&lt;br /&gt;
|-&lt;br /&gt;
| [b] a plan of action is developed to correct identified deficiencies and reduce or eliminate identified vulnerabilities. || Artifact || Plan of Action (POA).&lt;br /&gt;
|-&lt;br /&gt;
| [c] the plan of action is implemented to correct identified deficiencies and reduce or eliminate identified vulnerabilities. || Artifact || Plan of Action (POA)/previously completed POAs.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== CA.L2-3.12.3 – Security Control Monitoring ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_CA.L2-3.12.3_Details|&#039;&#039;&#039;CA.L2-3.12.3&#039;&#039;&#039;]] Monitor security controls on an ongoing basis to ensure the continued effectiveness of the controls.&lt;br /&gt;
|-&lt;br /&gt;
| [a] security controls are monitored on an ongoing basis to ensure the continued effectiveness of those controls. || Artifact || Collection of risk assessment results, internal or third-party audits/security assessments and/or continuous monitoring reports/alerts (SIEM tool, etc.).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== CA.L2-3.12.4 – System Security Plan ====&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_CA.L2-3.12.4_Details|&#039;&#039;&#039;CA.L2-3.12.4&#039;&#039;&#039;]] Develop, document, and periodically update system security plans that describe system boundaries, system environments of operation, how security requirements are implemented, and the relationships with or connections to other systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] a system security plan is developed. || Document || SSP.&lt;br /&gt;
|-&lt;br /&gt;
| [b] the system boundary is described and documented in the system security plan. || Document || SSP and any supporting documentation.&lt;br /&gt;
|-&lt;br /&gt;
| [c] the system environment of operation is described and documented in the system security plan. || Document || SSP and any supporting documentation.&lt;br /&gt;
|-&lt;br /&gt;
| [d] the security requirements identified and approved by the designated authority as non-applicable are identified. || Document || SSP and required adjudication from DoD CIO.&lt;br /&gt;
|-&lt;br /&gt;
| [e] the method of security requirement implementation is described and documented in the system security plan. || Document || SSP and any supporting documentation.&lt;br /&gt;
|-&lt;br /&gt;
| [f] the relationship with or connection to other systems is described and documented in the system security plan. || Document || SSP and any supporting documentation.&lt;br /&gt;
|-&lt;br /&gt;
| [g] the frequency to update the system security plan is defined. || Document || SSP.&lt;br /&gt;
|-&lt;br /&gt;
| [h] system security plan is updated with the defined frequency. || Document || SSP/any previous versions.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== System and Communications Protection (SC) ==&lt;br /&gt;
=== SC.L2-3.13.1 – Boundary Protection [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.1_Details|&#039;&#039;&#039;SC.L2-3.13.1&#039;&#039;&#039;]] Monitor, control, and protect organizational communications (i.e., information transmitted or received by organizational information systems) at the external boundaries and key internal boundaries of the information systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the external system boundary is defined. || Document || SSP, network diagrams, CUI flow, cloud provider FedRAMP Moderate.&lt;br /&gt;
|-&lt;br /&gt;
| [b] key internal system boundaries are defined. || Document || SSP, network diagrams, CUI flow.&lt;br /&gt;
|-&lt;br /&gt;
| [c] communications are monitored at the external system boundary. || Screen Share || SSP, logging server, boundary device configurations, monitoring policy.&lt;br /&gt;
|-&lt;br /&gt;
| [d] communications are monitored at key internal boundaries. || Screen Share || SSP, logging server, boundary device configurations, monitoring policy.&lt;br /&gt;
|-&lt;br /&gt;
| [e] communications are controlled at the external system boundary. || Screen Share || SSP, boundary device configurations, ACL, subnets, DMZ.&lt;br /&gt;
|-&lt;br /&gt;
| [f] communications are controlled at key internal boundaries. || Screen Share || SSP, boundary device configurations, ACL, subnets.&lt;br /&gt;
|-&lt;br /&gt;
| [g] communications are protected at the external system boundary. || Screen Share || Configurations for IPS/IDS, email gateway, VLAN, proxy, firewall, malware protection, DNS, TSL.&lt;br /&gt;
|-&lt;br /&gt;
| [h] communications are protected at key internal boundaries. || Screen Share || Configurations for IPS/IDS, VLAN, firewall, malware protection, SSL.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.2 – Security Engineering ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.2_Details|&#039;&#039;&#039;SC.L2-3.13.2&#039;&#039;&#039;]] Employ architectural designs, software development techniques, and systems engineering principles that promote effective information security within organizational systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] architectural designs that promote effective information security are identified. || Document || SSP, config management policy, network diagram, CCB minutes, enterprise architecture process.&lt;br /&gt;
|-&lt;br /&gt;
| [b] software development techniques that promote effective information security are identified. || Document || SSP, config management policy, SDLC, CCB minutes.&lt;br /&gt;
|-&lt;br /&gt;
| [c] systems engineering principles that promote effective information security are identified. || Document || SSP, config management policy, CCB minutes, security architecture engineering.&lt;br /&gt;
|-&lt;br /&gt;
| [d] identified architectural designs that promote effective information security are employed. || Artifact || CCB minutes, Network diagrams and configurations, Project Plans.&lt;br /&gt;
|-&lt;br /&gt;
| [e] identified software development techniques that promote effective information security are employed. || Artifact || CCB minutes, SDLC, code scanner results, code management tracking.&lt;br /&gt;
|-&lt;br /&gt;
| [f] identified systems engineering principles that promote effective information security are employed. || Artifact || CCB minutes, configuration management, ITSM, patch management, lifecycle replacement processes.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.3 – Role Separation ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.3_Details|&#039;&#039;&#039;SC.L2-3.13.3&#039;&#039;&#039;]] Separate user functionality from system management functionality.&lt;br /&gt;
|-&lt;br /&gt;
| [a] user functionality is identified. || Document || SSP, AUP.&lt;br /&gt;
|-&lt;br /&gt;
| [b] system management functionality is identified. || Document || SSP, Privileged Account Agreement.&lt;br /&gt;
|-&lt;br /&gt;
| [c] user functionality is separated from system management functionality. || Screen Share || Active Directory, Jump Boxes, GPO, VM, RDP.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.4 – Shared Resource Control ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.4_Details|&#039;&#039;&#039;SC.L2-3.13.4&#039;&#039;&#039;]] Prevent unauthorized and unintended information transfer via shared system resources.&lt;br /&gt;
|-&lt;br /&gt;
| [a] unauthorized and unintended information transfer via shared system resources is prevented. || Screen Share || SSP, OS configurations, Linux containers, system/media reuse policies, certificate management policies, media destruction policies, printer configs, VDI configuration.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
===  SC.L2-3.13.5 – Public-Access System Separation [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.5_Details|&#039;&#039;&#039;SC.L2-3.13.5&#039;&#039;&#039;]] Implement subnetworks for publicly accessible system components that are physically or logically separated from internal networks.&lt;br /&gt;
|-&lt;br /&gt;
| [a] publicly accessible system components are identified. || Document || SSP, network diagram, DMZ inventory/roles.&lt;br /&gt;
|-&lt;br /&gt;
| [b] subnetworks for publicly accessible system components are physically or logically separated from internal networks. || Artifact || Network diagram, IPAM, VLAN, DHCP, DMZ.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.6 – Network Communication by Exception ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.6_Details|&#039;&#039;&#039;SC.L2-3.13.6&#039;&#039;&#039;]] Deny network communications traffic by default and allow network communications traffic by exception (i.e., deny all, permit by exception).&lt;br /&gt;
|-&lt;br /&gt;
| [a] network communications traffic is denied by default. || Screen Share || Host and network firewall rules, SIEM logs, hit counts.&lt;br /&gt;
|-&lt;br /&gt;
| [b] network communications traffic is allowed by exception. || Screen Share || Host and network firewall rules, SIEM logs, hit counts.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.7 – Split Tunneling ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.7_Details|&#039;&#039;&#039;SC.L2-3.13.7&#039;&#039;&#039;]] Prevent remote devices from simultaneously establishing non-remote connections with organizational systems and communicating via some other connection to resources in external networks (i.e., split tunneling).&lt;br /&gt;
|-&lt;br /&gt;
| [a] remote devices are prevented from simultaneously establishing non-remote connections with the system and communicating via some other connection to resources in external networks (i.e., split tunneling). || Screen Share || VPN appliance/server configuration, endpoint VPN software configuration.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.8 – Data in Transit ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.8_Details|&#039;&#039;&#039;SC.L2-3.13.8&#039;&#039;&#039;]] Implement cryptographic mechanisms to prevent unauthorized disclosure of CUI during transmission unless otherwise protected by alternative physical safeguards.&lt;br /&gt;
|-&lt;br /&gt;
| [a] cryptographic mechanisms intended to prevent unauthorized disclosure of CUI are identified. || Document || SSP, PKI policies, configuration processes, config management, email attachment encryption policy, removable media policy, data at rest policy.&lt;br /&gt;
|-&lt;br /&gt;
| [b] alternative physical safeguards intended to prevent unauthorized disclosure of CUI are identified. || Document || SSP, physical security policy.&lt;br /&gt;
|-&lt;br /&gt;
| [c] either cryptographic mechanisms or alternative physical safeguards are implemented to prevent unauthorized disclosure of CUI during transmission. || Screen Share || TLS settings, SSL settings, VPN/Wireless Access Points/Mobile Devices cryptographic settings, ODBC connector settings, SAN configuration, IPSec/MPLS, backup configuration, physical security.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.9 – Connections Termination ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.9_Details|&#039;&#039;&#039;SC.L2-3.13.9&#039;&#039;&#039;]] Terminate network connections associated with communications sessions at the end of the sessions or after a defined period of inactivity.&lt;br /&gt;
|-&lt;br /&gt;
| [a] a period of inactivity to terminate network connections associated with communications sessions is defined. || Document || SSP, network communications policy.&lt;br /&gt;
|-&lt;br /&gt;
| [b] network connections associated with communications sessions are terminated at the end of the sessions. || Screen Share || VPN appliance/server logs, VPN configurations, web server configurations, firewall connection settings.&lt;br /&gt;
|-&lt;br /&gt;
| [c] network connections associated with communications sessions are terminated after the defined period of inactivity. || Screen Share || VPN appliance/server logs, VPN configurations, web server configurations, frewall connection settings.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.10 – Key Management ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.10_Details|&#039;&#039;&#039;SC.L2-3.13.10&#039;&#039;&#039;]] Establish and manage cryptographic keys for cryptography employed in organizational systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] cryptographic keys are established whenever cryptography is employed. || Artifact || SSP, PKI/certificate management policy, configuration management.&lt;br /&gt;
|-&lt;br /&gt;
| [b] cryptographic keys are managed whenever cryptography is employed. || Artifact || SSP, PKI/certificate management policy, configuration management, access control policy.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.11 – CUI Encryption ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.11_Details|&#039;&#039;&#039;SC.L2-3.13.11&#039;&#039;&#039;]] Employ FIPS-validated cryptography when used to protect the confidentiality of CUI.&lt;br /&gt;
|-&lt;br /&gt;
| [a] FIPS-validated cryptography is employed to protect the confidentiality of CUI. || Screen Share || VPN, wireless, mobile devices, client certificates, server certificates, disk encryption, Outlook plugin, external mail, backup media, ePO server, removable storage, SAN, file compression; look for FIPS mode enabled on appliances.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.12 – Collaborative Device Control ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.12_Details|&#039;&#039;&#039;SC.L2-3.13.12&#039;&#039;&#039;]] Prohibit remote activation of collaborative computing devices and provide indication of devices in use to users present at the device.&lt;br /&gt;
|-&lt;br /&gt;
| [a] collaborative computing devices are identified. || Document || SSP, network diagrams.&lt;br /&gt;
|-&lt;br /&gt;
| [b] collaborative computing devices provide indication to users of devices in use. || Physical Review || Physical inspection of device.&lt;br /&gt;
|-&lt;br /&gt;
| [c] remote activation of collaborative computing devices is prohibited. || Screen Share || Collaboration device configuration/console.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.13 – Mobile Code ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.13_Details|&#039;&#039;&#039;SC.L2-3.13.13&#039;&#039;&#039;]] Control and monitor the use of mobile code.&lt;br /&gt;
|-&lt;br /&gt;
| [a] use of mobile code is controlled. || Screen Share || GPO settings, malware protection, software agent configurations, software development policies, code scanners, MDM configuration, firewall/secure web gateway/proxy config.&lt;br /&gt;
|-&lt;br /&gt;
| [b] use of mobile code is monitored. || Screen Share || SIEM/console monitoring.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.14 – Voice over Internet Protocol ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.14_Details|&#039;&#039;&#039;SC.L2-3.13.14&#039;&#039;&#039;]] Control and monitor the use of Voice over Internet Protocol (VoIP) technologies.&lt;br /&gt;
|-&lt;br /&gt;
| [a] use of Voice over Internet Protocol (VoIP) technologies is controlled. || Artifact || VLAN, ACL, firewall config, VoIP gateway/condenser configuration.&lt;br /&gt;
|-&lt;br /&gt;
| [b] use of Voice over Internet Protocol (VoIP) technologies is monitored. || Artifact || SIEM/VoIP console monitoring, session border controller.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.15 – Communications Authenticity ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.15_Details|&#039;&#039;&#039;SC.L2-3.13.15&#039;&#039;&#039;]] Protect the authenticity of communications sessions.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the authenticity of communications sessions is protected. || Screen Share || SSL, TLS, SMB3, SFTP, IPSec, SSH, Kerberos configs, MPLS, Network Access Control.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.16 – Data at Rest ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.16_Details|&#039;&#039;&#039;SC.L2-3.13.16&#039;&#039;&#039;]] Protect the confidentiality of CUI at rest.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the confidentiality of CUI at rest is protected. || Artifact || Full disk encryption, removable media encryption, SAN encryption, digital backups, mobile device encryption, third party offsite backup storage, cloud virtualization encryption, physical media storage policies.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== System and Information Integrity (SI) ==&lt;br /&gt;
=== SI.L2-3.14.1 – Flaw Remediation [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SI.L2-3.14.1_Details|&#039;&#039;&#039;SI.L2-3.14.1&#039;&#039;&#039;]] Identify, report, and correct information and information system flaws in a timely manner.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the time within which to identify system flaws is specified. || Document || SSP, patch management policy.&lt;br /&gt;
|-&lt;br /&gt;
| [b] system flaws are identified within the specified time frame. || Screen Share || Vulnerability management scanner output and scan policy configuration.&lt;br /&gt;
|-&lt;br /&gt;
| [c] the time within which to report system flaws is specified. || Document || SSP, patch management policy.&lt;br /&gt;
|-&lt;br /&gt;
| [d] system flaws are reported within the specified time frame. || Screen Share || ITSM/trouble tickets, vulnerability management scanner output.&lt;br /&gt;
|-&lt;br /&gt;
| [e] the time within which to correct system flaws is specified. || Document || SSP, patch management policy.&lt;br /&gt;
|-&lt;br /&gt;
| [f] system flaws are corrected within the specified time frame. || Screen Share || Vulnerability management scanner output and scan policy configuration.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SI.L2-3.14.2 – Malicious Code ProTection [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SI.L2-3.14.2_Details|&#039;&#039;&#039;SI.L2-3.14.2&#039;&#039;&#039;]] Provide protection from malicious code at appropriate locations within organizational information systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] designated locations for malicious code protection are identified. || Document || SSP, system protection policy, network diagrams, security architecture documents.&lt;br /&gt;
|-&lt;br /&gt;
| [b] protection from malicious code at designated locations is provided. || Screen Share || Endpoint security settings, email/web proxy gateways, firewall, IPS sensor, MDM configuration, Network Access Control.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SI.L2-3.14.3 – Security Alerts &amp;amp; Advisories ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SI.L2-3.14.3_Details|&#039;&#039;&#039;SI.L2-3.14.3&#039;&#039;&#039;]] Monitor system security alerts and advisories and take action in response.&lt;br /&gt;
|-&lt;br /&gt;
| [a] response actions to system security alerts and advisories are identified. || Document || SSP, vulnerability management policy, Incident Response Plan.&lt;br /&gt;
|-&lt;br /&gt;
| [b] system security alerts and advisories are monitored. || Artifact || Threat intelligence subscriptions, email advisories.&lt;br /&gt;
|-&lt;br /&gt;
| [c] actions in response to system security alerts and advisories are taken. || Artifact || ITSM/trouble tickets, user notifications, updates to firewall/IPS, etc.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SI.L2-3.14.4 – Update Malicious Code Protection [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SI.L2-3.14.4_Details|&#039;&#039;&#039;SI.L2-3.14.4&#039;&#039;&#039;]] Update malicious code protection mechanisms when new releases are available.&lt;br /&gt;
|-&lt;br /&gt;
| [a] malicious code protection mechanisms are updated when new releases are available. || Screen Share || Antivirus console dashboard, firewall AV, Email gateway signatures,proxy, IPS updates.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SI.L2-3.14.5 – System &amp;amp; File Scanning [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SI.L2-3.14.5_Details|&#039;&#039;&#039;SI.L2-3.14.5&#039;&#039;&#039;]] Perform periodic scans of the information system and real-time scans of files from external sources as files are downloaded, opened, or executed.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the frequency for malicious code scans is defined. || Document || SSP, vulnerability management policy.&lt;br /&gt;
|-&lt;br /&gt;
| [b] malicious code scans are performed with the defined frequency. || Screen Share || Consoles for AV (endpoints, servers, and file shares), firewall, email gateway, proxy, IPS, MDM configurations.&lt;br /&gt;
|-&lt;br /&gt;
| [c] real-time malicious code scans of files from external sources as files are downloaded, opened, or executed are performed. || Screen Share || Consoles for AV (endpoints, servers, and file shares), firewall, email gateway, proxy, IPS, MDM configurations.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SI.L2-3.14.6 – Monitor Communications for Attacks ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SI.L2-3.14.6_Details|&#039;&#039;&#039;SI.L2-3.14.6&#039;&#039;&#039;]] Monitor organizational systems, including inbound and outbound communications traffic, to detect attacks and indicators of potential attacks.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the system is monitored to detect attacks and indicators of potential attacks. || Screen Share || Firewall, IPS, endpoint protection, SIEM alerts and reports.&lt;br /&gt;
|-&lt;br /&gt;
| [b] inbound communications traffic is monitored to detect attacks and indicators of potential attacks. || Screen Share || Firewall, IPS, endpoint protection, SIEM alerts and reports.&lt;br /&gt;
|-&lt;br /&gt;
| [c] outbound communications traffic is monitored to detect attacks and indicators of potential attacks. || Screen Share || Firewall, IPS, endpoint protection, SIEM alerts and reports.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SI.L2-3.14.7 – Identify Unauthorized Use ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SI.L2-3.14.7_Details|&#039;&#039;&#039;SI.L2-3.14.7&#039;&#039;&#039;]] Identify unauthorized use of organizational systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] authorized use of the system is defined. || Document || AUP, SSP.&lt;br /&gt;
|-&lt;br /&gt;
| [b] unauthorized use of the system is identified. || Artifact || SIEM logs, endpoint protection console, IPS, Firewall.&lt;br /&gt;
|}&lt;/div&gt;</summary>
		<author><name>David</name></author>
	</entry>
	<entry>
		<id>https://cmmcwiki.org/index.php?title=Evidence_Collection_Approach&amp;diff=1617</id>
		<title>Evidence Collection Approach</title>
		<link rel="alternate" type="text/html" href="https://cmmcwiki.org/index.php?title=Evidence_Collection_Approach&amp;diff=1617"/>
		<updated>2026-07-20T01:37:39Z</updated>

		<summary type="html">&lt;p&gt;David: /* AC.L2-3.1.15 – Privileged Remote Access */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;CMMC assessments and certification require substantial evidence and documentation. The following tables outline general guidelines for collecting evidence to assess control requirements and objectives. While these guidelines provide a structured approach, they are not the only means of conducting an accurate assessment. Assessors should exercise professional judgment and may employ alternative methods appropriate to the specific organizational context and circumstances.&lt;br /&gt;
&lt;br /&gt;
Evidence collection approaches are defined as:&lt;br /&gt;
* &#039;&#039;&#039;Documentation&#039;&#039;&#039;: Tangible materials containing information over which an organization has authority, including all types of written records and their copies.&lt;br /&gt;
* &#039;&#039;&#039;Artifacts&#039;&#039;&#039;: Tangible, reviewable records directly resulting from a practice or process being performed by a system or by personnel executing their role within that practice, control, or process.&lt;br /&gt;
* &#039;&#039;&#039;Physical Review&#039;&#039;&#039;: Direct on-site observation and examination of evidence.&lt;br /&gt;
* &#039;&#039;&#039;Screen Share&#039;&#039;&#039;: Real-time remote observation of a user demonstrating a task or process via shared computer screen, sometimes called &amp;quot;over-the-shoulder&amp;quot; review.&lt;br /&gt;
&lt;br /&gt;
DISCLAIMER: Evidence requirements vary significantly across assessment types. &#039;&#039;&#039;The examples provided are illustrative only and should be tailored to meet the specific adequacy and sufficiency standards of your particular assessment context.&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
For inquiries and reporting errors on this wiki, please [mailto:support@cmmctoolkit.org contact us]. Thank you.&lt;br /&gt;
&lt;br /&gt;
== Access Control (AC) ==&lt;br /&gt;
=== AC.L2-3.1.1 – Authorized Access Control [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.1_Details|&#039;&#039;&#039;AC.L2-3.1.1&#039;&#039;&#039;]] Limit information system access to authorized users, processes acting on behalf of authorized users, or devices (including other information systems).&lt;br /&gt;
|-&lt;br /&gt;
| [a] authorized users are identified. || Document || Document defining account request, approval, provisioning.&lt;br /&gt;
|-&lt;br /&gt;
| [b] processes acting on behalf of authorized users are identified. || Document || Document defining account request, approval, provisioning.&lt;br /&gt;
|-&lt;br /&gt;
| [c] devices (and other systems) authorized to connect to the system are identified. || Document || Document defining account request, approval, provisioning.&lt;br /&gt;
|-&lt;br /&gt;
| [d] system access is limited to authorized users. || Screen Share || Screen share showing login requirements are enforced. Example of an unauthorized user denied (unauthorized username entered at login).&lt;br /&gt;
|-&lt;br /&gt;
| [e] system access is limited to processes acting on behalf of authorized users. || Screen Share || Screenshot showing that service accounts are assigned to authorized users only; no rogue accounts without an authorized user are active.&lt;br /&gt;
|-&lt;br /&gt;
| [f] system access is limited to authorized devices (including other systems). || Screen Share || Screen share showing that all devices running are authorized; no rogue devices on the network.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.2 – Transaction &amp;amp; Function Control [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.2_Details|&#039;&#039;&#039;AC.L2-3.1.2&#039;&#039;&#039;]] Limit information system access to the types of transactions and functions that authorized users are permitted to execute.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the types of transactions and functions that authorized users are permitted to execute are defined. || Document || SSP, AUP, or IAM document that defines what authorized users can execute.&lt;br /&gt;
|-&lt;br /&gt;
| [b] system access is limited to the defined types of transactions and functions for authorized users. || Screen Share || Screenshot of security roles in AD or IAM or other directory-based identity-related services tool that shows transactions are as defined in the SSP or IAM document; privileged and non-privileged accounts need to be defined and identified in the artifact; screenshot of a non-privileged user trying to execute a privileged function.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.3 – Control CUI Flow ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.3_Details|&#039;&#039;&#039;AC.L2-3.1.3&#039;&#039;&#039;]] Control the flow of CUI in accordance with approved authorizations.&lt;br /&gt;
|-&lt;br /&gt;
| [a] information flow control policies are defined. || Document || SSP or other document describing the control of CUI on the network.&lt;br /&gt;
|-&lt;br /&gt;
| [b] methods and enforcement mechanisms for controlling the flow of CUI are defined. || Document || Document that defines the networking devices that are on the CUI network and answers what measures are in place to control the flow. List of firewalls, border and internal layer 3 devices, IDS/IPS, DLP, that process CUI.&lt;br /&gt;
|-&lt;br /&gt;
| [c] designated sources and destinations (e.g., networks, individuals, and devices) for CUI within the system and between interconnected systems are identified. || Artifact || Network diagram, data flow diagram, external system connection diagrams, document describing the policies for CUI on the network; listing of VLANs and subnets where CUI is authorized; document must describe source and authorized destinations.&lt;br /&gt;
|-&lt;br /&gt;
| [d] authorizations for controlling the flow of CUI are defined. || Document || Document that defines how CUI is to be controlled, such as an InfoSec plan, and/or network management plan.&lt;br /&gt;
|-&lt;br /&gt;
| [e] approved authorizations for controlling the flow of CUI are enforced. || Screen Share || Screenshots of firewall rules, ACLs, etc.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.4 – Separation of Duties ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.4_Details|&#039;&#039;&#039;AC.L2-3.1.4&#039;&#039;&#039;]] Separate the duties of individuals to reduce the risk of malevolent activity without collusion.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the duties of individuals requiring separation are defined. || Document || Document, SSP, account management policy, defining separation of duties by person or role.&lt;br /&gt;
|-&lt;br /&gt;
| [b] responsibilities for duties that require separation are assigned to separate individuals. || Screen Share || Screenshot showing that separation of duties is enforced by showing admin accounts are assigned to different people based on role.&lt;br /&gt;
|-&lt;br /&gt;
| [c] access privileges that enable individuals to exercise the duties that require separation are granted to separate individuals. || Screen Share || Screen shot showing an example such as a security manager can not log into a network device and change ACLs, or network admins can not access security logs in the SIEM tool.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.5 – Least Privilege ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.5_Details|&#039;&#039;&#039;AC.L2-3.1.5&#039;&#039;&#039;]] Employ the principle of least privilege, including for specific security functions and privileged accounts.&lt;br /&gt;
|-&lt;br /&gt;
| [a] privileged accounts are identified. || Document || &amp;quot;SSP or policy (documentation) identify what is considered a privileged account.&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| [b] access to privileged accounts is authorized in accordance with the principle of least privilege. || Artifact || An artifact that identifies the least amount of permissions associated with different types of privileged accounts are approved.&lt;br /&gt;
|-&lt;br /&gt;
| [c] security functions are identified. || Document || &amp;quot;SSP or policy (documentation) identifies what is considered a security account.&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| [d] access to security functions is authorized in accordance with the principle of least privilege. || Artifact || Artifact(s) that identify the least amount of permissions associated with different types of security accounts are approved.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.6 – Non-Privileged Account Use ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.6_Details|&#039;&#039;&#039;AC.L2-3.1.6&#039;&#039;&#039;]] Use non-privileged accounts or roles when accessing nonsecurity functions.&lt;br /&gt;
|-&lt;br /&gt;
| [a] nonsecurity functions are identified. || Document || SSP or account management document, AUP, that defines non-security functions.&lt;br /&gt;
|-&lt;br /&gt;
| [b] users are required to use non-privileged accounts or roles when accessing nonsecurity functions. || Screen Share || Screenshot showing that a privileged user tried to use their admin account to access a non-security function, such as a browser or email (whatever is defined in their policy) and was blocked.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.7 – Privileged Functions ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.7_Details|&#039;&#039;&#039;AC.L2-3.1.7&#039;&#039;&#039;]] Prevent non-privileged users from executing privileged functions and capture the execution of such functions in audit logs.&lt;br /&gt;
|-&lt;br /&gt;
| [a] privileged functions are defined. || Document || SSP or policy (documentation) that defines privileged functions.&lt;br /&gt;
|-&lt;br /&gt;
| [b] non-privileged users are defined. || Document || SSP or policy (documentation) that defines non-privileged users.&lt;br /&gt;
|-&lt;br /&gt;
| [c] non-privileged users are prevented from executing privileged functions. || Screen Share || Screen share that shows that a non-privileged user is not allowed to complete a privileged function (installing software).&lt;br /&gt;
|-&lt;br /&gt;
| [d] the execution of privileged functions is captured in audit logs. || Screen Share || Screen share that shows logs being captured of the execution of privileged functions.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.8 – Unsuccessful Logon Attempts ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.8_Details|&#039;&#039;&#039;AC.L2-3.1.8&#039;&#039;&#039;]] Limit unsuccessful logon attempts.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the means of limiting unsuccessful logon attempts is defined. || Document || SSP or policy (documentation) showing unsuccessful logon attempts settings and or policy.&lt;br /&gt;
|-&lt;br /&gt;
| [b] the defined means of limiting unsuccessful logon attempts is implemented. || Artifact || Artifact showing GPO / Policy for limiting logon attempts.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.9 – Privacy &amp;amp; Security Notices ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.9_Details|&#039;&#039;&#039;AC.L2-3.1.9&#039;&#039;&#039;]] Provide privacy and security notices consistent with applicable CUI rules.&lt;br /&gt;
|-&lt;br /&gt;
| [a] privacy and security notices required by CUI-specified rules are identified, consistent, and associated with the specific CUI category. || Document || SSP or policy (documentation) showing CUI-specified rules are identified, consistent, and associated with the specific CUI category.&lt;br /&gt;
|-&lt;br /&gt;
| [b] privacy and security notices are displayed. || Artifact || Artifact that shows a consent banner or screen that a user sees as they log in to the system.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.10 – Session Lock ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.10_Details|&#039;&#039;&#039;AC.L2-3.1.10&#039;&#039;&#039;]] Use session lock with pattern-hiding displays to prevent access and viewing of data after a period of inactivity.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the period of inactivity after which the system initiates a session lock is defined. || Document || SSP or policy (documentation) that defines the period of inactivity and when a session lock is defined.&lt;br /&gt;
|-&lt;br /&gt;
| [b] access to the system and viewing of data is prevented by initiating a session lock after the defined period of inactivity. || Artifact || Artifact that shows the setting of session lock (GPO or system policy or similar solution addressing the controls supporting centralized management and configuration of operating systems, applications, and users&#039; settings for the working environment of user accounts and computer accounts).&lt;br /&gt;
|-&lt;br /&gt;
| [c] previously visible information is concealed via a pattern-hiding display after the defined period of inactivity. || Document || Screenshot of GPO setting and configuration settings, or similar solution addressing the controls supporting centralized management and configuration of operating systems, applications, and users&#039; settings for the working environment of user accounts and computer accounts.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.11 – Session Termination ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.11_Details|&#039;&#039;&#039;AC.L2-3.1.11&#039;&#039;&#039;]] Terminate (automatically) a user session after a defined condition.&lt;br /&gt;
|-&lt;br /&gt;
| [a] conditions requiring a user session to terminate are defined. || Document || SSP or policy (documentation) that defines the conditions requiring a user session to be terminated.&lt;br /&gt;
|-&lt;br /&gt;
| [b] a user session is automatically terminated after any of the defined conditions. || Screen Share || Screen share showing GPO / VPN Settings that show when a session would be terminated (Idle time, max connection time).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.12 – Control Remote Access ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.12_Details|&#039;&#039;&#039;AC.L2-3.1.12&#039;&#039;&#039;]] Monitor and control remote access sessions.&lt;br /&gt;
|-&lt;br /&gt;
| [a] remote access sessions are permitted. || Document || SSP or policy (documentation) that defines remote access sessions.&lt;br /&gt;
|-&lt;br /&gt;
| [b] the types of permitted remote access are identified. || Document || SSP or policy (documentation) that defines remote access is permitted.&lt;br /&gt;
|-&lt;br /&gt;
| [c] remote access sessions are controlled. || Screen Share || Screen share that shows how the remote access is controlled (access session, and or groups).&lt;br /&gt;
|-&lt;br /&gt;
| [d] remote access sessions are monitored. || Screen Share || Screen share that shows how remote sessions are monitored (logs).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.13 – Remote Access Confidentiality ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.13_Details|&#039;&#039;&#039;AC.L2-3.1.13&#039;&#039;&#039;]] Employ cryptographic mechanisms to protect the confidentiality of remote access sessions.&lt;br /&gt;
|-&lt;br /&gt;
| [a] cryptographic mechanisms to protect the confidentiality of remote access sessions are identified. || Document || SSP or policy (documentation) that discusses the CUI rules, consistent, and associated with the specific CUI category; FIPS Cert # of appliance or application.&lt;br /&gt;
|-&lt;br /&gt;
| [b] cryptographic mechanisms to protect the confidentiality of remote access sessions are implemented. || Screen Share || Screenshot of VPN concentration that shows encryption is on and enabled (point-to-point, etc.).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.14 – Remote Access Routing ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.14_Details|&#039;&#039;&#039;AC.L2-3.1.14&#039;&#039;&#039;]] Route remote access via managed access control points.&lt;br /&gt;
|-&lt;br /&gt;
| [a] managed access control points are identified and implemented. || Screen Share || Screen share that shows access control points (groups and/or users).&lt;br /&gt;
|-&lt;br /&gt;
| [b] remote access is routed through managed network access control points. || Screen Share || Screen share that shows access control points and how they are managed.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.15 – Privileged Remote Access ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.15_Details|&#039;&#039;&#039;AC.L2-3.1.15&#039;&#039;&#039;]] Authorize remote execution of privileged commands and remote access to security-relevant information.&lt;br /&gt;
|-&lt;br /&gt;
| [a] privileged commands authorized for remote execution are identified. || Document || SSP or policy (documentation) that defines what is authorized to be executed remotely and how that is handled.&lt;br /&gt;
|-&lt;br /&gt;
| [b] security-relevant information authorized to be accessed remotely is identified. || Document || SSP or policy (documentation) that defines what can be accessed remotely and what procedures are implemented to allow this (RDP, jump box).&lt;br /&gt;
|-&lt;br /&gt;
| [c] the execution of the identified privileged commands via remote access is authorized. || Artifact || Screen share that shows who has access to perform privileged commands a remotely (access groups for privileged accounts).&lt;br /&gt;
|-&lt;br /&gt;
| [d] access to the identified security-relevant information via remote access is authorized. || Artifact || Screen share that shows the routing of remote access and how it is monitored and how many locations (Firewall, VPN Concentrator).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.16 – Wireless Access Authorization ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.16_Details|&#039;&#039;&#039;AC.L2-3.1.16&#039;&#039;&#039;]] Authorize wireless access prior to allowing such connections.&lt;br /&gt;
|-&lt;br /&gt;
| [a] wireless access points are identified. || Document || SSP, network administration document.&lt;br /&gt;
|-&lt;br /&gt;
| [b] wireless access is authorized prior to allowing such connections. || Screen Share || Authorization profile(s) in Wireless Access Controller or Identity Manager (i.e. Cisco ISE).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.17 – Wireless Access Protection ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.17_Details|&#039;&#039;&#039;AC.L2-3.1.17&#039;&#039;&#039;]] Protect wireless access using authentication and encryption.&lt;br /&gt;
|-&lt;br /&gt;
| [a] wireless access to the system is protected using authentication. || Screen Share || Security page (or similar) of a Wireless Access Controller.&lt;br /&gt;
|-&lt;br /&gt;
| [b] wireless access to the system is protected using encryption. || Screen Share || Security page (or similar) of a Wireless Access Controller.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.18 – Mobile Device Connection ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.18_Details|&#039;&#039;&#039;AC.L2-3.1.18&#039;&#039;&#039;]] Control connection of mobile devices.&lt;br /&gt;
|-&lt;br /&gt;
| [a] mobile devices that process, store, or transmit CUI are identified. || Document || SSP, Mobile Device Policy.&lt;br /&gt;
|-&lt;br /&gt;
| [b] mobile device connections are authorized. || Screen Share || Authorization profile(s) in Wireless Access Controller or Identity Manager (i.e. Cisco ISE).&lt;br /&gt;
|-&lt;br /&gt;
| [c] mobile device connections are monitored and logged. || Screen Share || Mobile device logs within the MDM, log intake (sources) configuration (within SIEM) showing MDM is feeding logs to the SIEM.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.19 – Encrypt CUI on Mobile ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.19_Details|&#039;&#039;&#039;AC.L2-3.1.19&#039;&#039;&#039;]] Encrypt CUI on mobile devices and mobile computing platforms.&lt;br /&gt;
|-&lt;br /&gt;
| [a] mobile devices and mobile computing platforms that process, store, or transmit CUI are identified. || Document || SSP, Mobile Device Policy.&lt;br /&gt;
|-&lt;br /&gt;
| [b] encryption is employed to protect CUI on identified mobile devices and mobile computing platforms. || Screen Share || Security policy page in MDM showing how encryption are enforced on mobile device. If no MDM or MDM doesn&#039;t enforce encryption, then validate if the devices used are on the list of devices with native FIPS approved validation.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.20 – External Connections [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.20_Details|&#039;&#039;&#039;AC.L2-3.1.20&#039;&#039;&#039;]] Verify and control/limit connections to and use of external information systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] connections to external systems are identified. || Document || SSP, Systems Interconnection Agreements, SLA.&lt;br /&gt;
|-&lt;br /&gt;
| [b] the use of external systems is identified. || Document || SSP, Systems Interconnection Agreements, SLA.&lt;br /&gt;
|-&lt;br /&gt;
| [c] connections to external systems are verified. || Artifact || SLA for external systems, memorandum for interconnection, information to prove that any cloud solution is at FedRAMP impact level of moderate or higher (i.e. license information, screenshot of AWS cloud dashboard, purchase order document).&lt;br /&gt;
|-&lt;br /&gt;
| [d] the use of external systems is verified. || Artifact || SLA for external systems, memorandum for interconnection, information to prove that any cloud solution is at FedRAMP impact level of moderate or higher (i.e. license information, screenshot of AWS cloud dashboard, purchase order document).&lt;br /&gt;
|-&lt;br /&gt;
| [e] connections to external systems are controlled/limited. || Screen Share || Firewall ruleset for controlling access to cloud service or external system.&lt;br /&gt;
|-&lt;br /&gt;
| [f] the use of external systems is controlled/limited. || Screen Share || Firewall ruleset for controlling access to cloud service or external system.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.21 – Portable Storage Use ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.21_Details|&#039;&#039;&#039;AC.L2-3.1.21&#039;&#039;&#039;]] Limit use of portable storage devices on external systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the use of portable storage devices containing CUI on external systems is identified and documented. || Document || SSP, Removable Media Policy, Acceptable Use Policy (with emphasis on portable media use).&lt;br /&gt;
|-&lt;br /&gt;
| [b] limits on the use of portable storage devices containing CUI on external systems are defined. || Document || SSP, Removable Media Policy, Acceptable Use Policy (with emphasis on portable media use).&lt;br /&gt;
|-&lt;br /&gt;
| [c] the use of portable storage devices containing CUI on external systems is limited as defined. || Document || SSP, Removable Media Policy, Acceptable Use Policy (with emphasis on portable media use).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.22 – Control Public Information [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.22_Details|&#039;&#039;&#039;AC.L2-3.1.22&#039;&#039;&#039;]] Control information posted or processed on publicly accessible information systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] individuals authorized to post or process information on publicly accessible systems are identified. || Document || SSP, Website Governance Plan, Information Release Document.&lt;br /&gt;
|-&lt;br /&gt;
| [b] procedures to ensure CUI is not posted or processed on publicly accessible systems are identified. || Document || SSP, Website Governance Plan, Information Release Document.&lt;br /&gt;
|-&lt;br /&gt;
| [c] a review process is in place prior to posting of any content to publicly accessible systems. || Artifact || &amp;quot;Information release approval process, i.e. chain of email communication from originator, approver, and final decision (may or may not include individual authorized to post); &lt;br /&gt;
SharePoint/electronic or paper form/ ticket system showing information flow between requestor and approver (may or may not include  individual authorized to post).&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| [d] content on publicly accessible systems is reviewed to ensure that it does not include CUI. || Artifact || Incident response process, web design/update/modification SOP etc.&lt;br /&gt;
|-&lt;br /&gt;
| [e] mechanisms are in place to remove and address improper posting of CUI. || Artifact || Incident response process, web design/update/modification SOP etc.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Awareness and Training (AT) ==&lt;br /&gt;
=== AT.L2-3.2.1 – Role-Based Risk Awareness ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AT.L2-3.2.1_Details|&#039;&#039;&#039;AT.L2-3.2.1&#039;&#039;&#039;]] Ensure that managers, systems administrators, and users of organizational systems are made aware of the security risks associated with their activities and of the applicable policies, standards, and procedures related to the security of those systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] security risks associated with organizational activities involving CUI are identified. || Document || Policy of Security Awareness Training; Security Awareness Training Briefing.&lt;br /&gt;
|-&lt;br /&gt;
| [b] policies, standards, and procedures related to the security of the system are identified. || Document || Acceptable Use Policy, Policy/Procedures/Instruction related to the security of the system.&lt;br /&gt;
|-&lt;br /&gt;
| [c] managers, systems administrators, and users of the system are made aware of the security risks associated with their activities. || Artifact || Security Training Brief, training records.&lt;br /&gt;
|-&lt;br /&gt;
| [d] managers, systems administrators, and users of the system are made aware of the applicable policies, standards, and procedures related to the security of the system. || Artifact || Policies, standards and procedures for employees within training (completed training report).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AT.L2-3.2.2 – Role-Based Training ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AT.L2-3.2.2_Details|&#039;&#039;&#039;AT.L2-3.2.2&#039;&#039;&#039;]] Ensure that personnel are trained to carry out their assigned information security-related duties and responsibilities.|-&lt;br /&gt;
|-&lt;br /&gt;
| [a] information security-related duties, roles, and responsibilities are defined. || Document || Policy/Procedures/Instruction, Job Role Matrix, Position Descriptions, User Roles.&lt;br /&gt;
|-&lt;br /&gt;
| [b] information security-related duties, roles, and responsibilities are assigned to designated personnel. || Artifact || Screenshot of breakout of different roles/permissions assigned to individuals (i.e. ActiveDirectory); Privilege Access Agreement.&lt;br /&gt;
|-&lt;br /&gt;
| [c] personnel are adequately trained to carry out their assigned information security-related duties, roles, and responsibilities. || Artifact || Screenshot of tool and/or training specifying security specific roles, duties and responsibilities; Screenshot of required certifications (i.e. Sec+, CISSP).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AT.L2-3.2.3 – Insider Threat Awareness ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AT.L2-3.2.3_Details|&#039;&#039;&#039;AT.L2-3.2.3&#039;&#039;&#039;]] Provide security awareness training on recognizing and reporting potential indicators of insider threat.&lt;br /&gt;
|-&lt;br /&gt;
| [a] potential indicators associated with insider threats are identified. || Document || Insidert Threat Policy/Procedures/Instruction; Insider Threat Training/Briefing.&lt;br /&gt;
|-&lt;br /&gt;
| [b] security awareness training on recognizing and reporting potential indicators of insider threat is provided to managers and employees. || Artifact || Screenshot of training records showing completion of Insider Threat training, emails showing completion of Insider Threat training, Screenshot of certificate showing completion with individual&#039;s name.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Audit and Accountability (AU) ==&lt;br /&gt;
=== AU.L2-3.3.1 – System Auditing ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AU.L2-3.3.1_Details|&#039;&#039;&#039;AU.L2-3.3.1&#039;&#039;&#039;]] Create and retain system audit logs and records to the extent needed to enable the monitoring, analysis, investigation, and reporting of unlawful or unauthorized system activity.&lt;br /&gt;
|-&lt;br /&gt;
| [a] audit logs needed (i.e., event types to be logged) to enable the monitoring, analysis, investigation, and reporting of unlawful or unauthorized system activity are specified. || Document || SSP, policy, or auditing and logging process that defines specific types of events to be logged.&lt;br /&gt;
|-&lt;br /&gt;
| [b] the content of audit records needed to support monitoring, analysis, investigation, and reporting of unlawful or unauthorized system activity is defined. || Document || SSP, policy, or auditing and logging process that defines specific content of audit records/files.&lt;br /&gt;
|-&lt;br /&gt;
| [c] audit records are created (generated). || Screen Share || Screen share of tool that shows logs are generated for all systems.&lt;br /&gt;
|-&lt;br /&gt;
| [d] audit records, once created, contain the defined content. || Screen Share || Screen share of tool that shows logs contain defined content as defined in SSP, policy, or procedures.&lt;br /&gt;
|-&lt;br /&gt;
| [e] retention requirements for audit records are defined. || Document || SSP, Polocy, or Auditing and logging process that describes how long records are kept.&lt;br /&gt;
|-&lt;br /&gt;
| [f] audit records are retained as defined. || Screen Share || Screen share of tool that shows records and audit content retained at a minimum as defined.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AU.L2-3.3.2 – User Accountability ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AU.L2-3.3.2_Details|&#039;&#039;&#039;AU.L2-3.3.2&#039;&#039;&#039;]] Ensure that the actions of individual system users can be uniquely traced to those users so they can be held accountable for their actions.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the content of the audit records needed to support the ability to uniquely trace users to their actions is defined. || Document || SSP, policy, or process that defines actions traced back to individuals.&lt;br /&gt;
|-&lt;br /&gt;
| [b] audit records, once created, contain the defined content. || Screen Share || Screen share of tool that shows audit records traced to specific users/roles.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AU.L2-3.3.3 – Event Review ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AU.L2-3.3.3_Details|&#039;&#039;&#039;AU.L2-3.3.3&#039;&#039;&#039;]] Review and update logged events.&lt;br /&gt;
|-&lt;br /&gt;
| [a] a process for determining when to review logged events is defined. || Document || SSP, policy, or documented process that shows frequency of when to review types of logged events.&lt;br /&gt;
|-&lt;br /&gt;
| [b] event types being logged are reviewed in accordance with the defined review process. || Artifact || Evidence through a documented method such as meeting minutes, CAB minutes, etc. of log sources and log events being logged at the defined frequency.&lt;br /&gt;
|-&lt;br /&gt;
| [c] event types being logged are updated based on the review. || Artifact || Evidence of implementation based on the results of the review of logged events/sources through a ticket, meeting minutes, or screen share of the tool that shows changes implemented (finetuning).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AU.L2-3.3.4 – Audit Failure Alerting ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AU.L2-3.3.4_Details|&#039;&#039;&#039;AU.L2-3.3.4&#039;&#039;&#039;]] Alert in the event of an audit logging process failure.&lt;br /&gt;
|-&lt;br /&gt;
| [a] personnel or roles to be alerted in the event of an audit logging process failure are identified. || Document || SSP, policy, or procedure that shows who needs to be notified in case of an audit failure.&lt;br /&gt;
|-&lt;br /&gt;
| [b] types of audit logging process failures for which alert will be generated are defined. || Document || SSP, policy, or procedure that shows what types of failure will generate notifications.&lt;br /&gt;
|-&lt;br /&gt;
| [c] identified personnel or roles are alerted in the event of an audit logging process failure. || Artifact || Artifact such as email or ticket that shows the identified personnel were alerted of any audit/logging process failure as defined.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AU.L2-3.3.5 – Audit Correlation ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AU.L2-3.3.5_Details|&#039;&#039;&#039;AU.L2-3.3.5&#039;&#039;&#039;]] Correlate audit record review, analysis, and reporting processes for investigation and response to indications of unlawful, unauthorized, suspicious, or unusual activity.&lt;br /&gt;
|-&lt;br /&gt;
| [a] audit record review, analysis, and reporting processes for investigation and response to indications of unlawful, unauthorized, suspicious, or unusual activity are defined. || Document || SSP, policy, or procedure covering audit logging, monitoring, and reporting.&lt;br /&gt;
|-&lt;br /&gt;
| [b] defined audit record review, analysis, and reporting processes are correlated. || Artifact || Artifact showing an audit event and the resultant corrective action or actions to the event; this can be a Help Desk ticket, meeting notes, or a change control board items showing the event and any corrective action taken.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AU.L2-3.3.6 – Reduction &amp;amp; Reporting ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AU.L2-3.3.6_Details|&#039;&#039;&#039;AU.L2-3.3.6&#039;&#039;&#039;]] Provide audit record reduction and report generation to support on-demand analysis and reporting.&lt;br /&gt;
|-&lt;br /&gt;
| [a] an audit record reduction capability that supports on-demand analysis is provided. || Screen Share || Screen share of the logging environment where an event can be selected and traced back to a specific device, or dashboard showing realtime event analysis.&lt;br /&gt;
|-&lt;br /&gt;
| [b] a report generation capability that supports on-demand reporting is provided. || Screen Share || Screen share showing the generation of an on demand report.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AU.L2-3.3.7 – Authoritative Time Source ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AU.L2-3.3.7_Details|&#039;&#039;&#039;AU.L2-3.3.7&#039;&#039;&#039;]] Provide a system capability that compares and synchronizes internal system clocks with an authoritative source to generate time stamps for audit records.&lt;br /&gt;
|-&lt;br /&gt;
| [a] internal system clocks are used to generate time stamps for audit records. || Screen Share || Screen share showing the NTP settings of a windows, Unix, Linux device; a screen share showing the NTP settings of network appliances.&lt;br /&gt;
|-&lt;br /&gt;
| [b] an authoritative source with which to compare and synchronize internal system clocks is specified. || Document || SSP or policy indicating that devices need to be synched to a local authoritative time device that is synched with an authoritative time service.&lt;br /&gt;
|-&lt;br /&gt;
| [c] internal system clocks used to generate time stamps for audit records are compared to and synchronized with the specified authoritative time source. || Screen Share || Screen share showing device logging appliance time is point to the appropriate authoritative time server.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AU.L2-3.3.8 – Audit Protection ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AU.L2-3.3.8_Details|&#039;&#039;&#039;AU.L2-3.3.8&#039;&#039;&#039;]] Protect audit information and audit logging tools from unauthorized access, modification, and deletion.&lt;br /&gt;
|-&lt;br /&gt;
| [a] audit information is protected from unauthorized access. || Screen Share || Screen share showing operating system permissions on the audit folders being restricted to appropriate users.&lt;br /&gt;
|-&lt;br /&gt;
| [b] audit information is protected from unauthorized modification. || Screen Share || Screen share showing operating system permissions on the audit folders being restricted to appropriate users.&lt;br /&gt;
|-&lt;br /&gt;
| [c] audit information is protected from unauthorized deletion. || Screen Share || Screen share showing operating system permissions on the audit folders being restricted to appropriate users.&lt;br /&gt;
|-&lt;br /&gt;
| [d] audit logging tools are protected from unauthorized access. || Screen Share || Artifact showing access permissions in the SIEM tool.&lt;br /&gt;
|-&lt;br /&gt;
| [e] audit logging tools are protected from unauthorized modification. || Screen Share || Artifact showing update permissions in the SIEM tool.&lt;br /&gt;
|-&lt;br /&gt;
| [f] audit logging tools are protected from unauthorized deletion. || Screen Share || Artifact showing delete permissions in the SIEM tool.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AU.L2-3.3.9 – Audit Management ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AU.L2-3.3.9_Details|&#039;&#039;&#039;AU.L2-3.3.9&#039;&#039;&#039;]] Limit management of audit logging functionality to a subset of privileged users.&lt;br /&gt;
|-&lt;br /&gt;
| [a] a subset of privileged users granted access to manage audit logging functionality is defined. || Document || SSP or policy indicating which users or groups have access to audit logs.&lt;br /&gt;
|-&lt;br /&gt;
| [b] management of audit logging functionality is limited to the defined subset of privileged users. || Screen Share || Artifact showing SIEM or OS folder permissions (this should be limited to the assigned users or groups); artifact showing an ACL setting in SIEM tool in regards to logs.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Configuration Management (CM) ==&lt;br /&gt;
=== CM.L2-3.4.1 – System Baselining ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_CM.L2-3.4.1_Details|&#039;&#039;&#039;CM.L2-3.4.1&#039;&#039;&#039;]] Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles.&lt;br /&gt;
|-&lt;br /&gt;
| [a] a baseline configuration is established. || Document || Documentation showing or explaining standard imaging process (how standard images are deployed and where  they are stored).&lt;br /&gt;
|-&lt;br /&gt;
| [b] the baseline configuration includes hardware, software, firmware, and documentation. || Artifact || Screenshot of repository of where images are maintained and information relating to hardware, software, and firmware.&lt;br /&gt;
|-&lt;br /&gt;
| [c] the baseline configuration is maintained (reviewed and updated) throughout the system development life cycle. || Artifact || Screenshot/evidence displaying management of baseline configurations (how often they are being managed as stated).&lt;br /&gt;
|-&lt;br /&gt;
| [d] a system inventory is established. || Document || Screenshot/evidence displaying inventory listing of approved products for use.&lt;br /&gt;
|-&lt;br /&gt;
| [e] the system inventory includes hardware, software, firmware, and documentation. || Artifact || Screeenshot/evidence displaying inventory listing of approved products and versions permitted for use.&lt;br /&gt;
|-&lt;br /&gt;
| [f] the inventory is maintained (reviewed and updated) throughout the system development life cycle. || Artifact || Screeenshot/evidence displaying management of baseline configurations (How often and are they being managed as stated.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== CM.L2-3.4.2 – Security Configuration Enforcement ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_CM.L2-3.4.2_Details|&#039;&#039;&#039;CM.L2-3.4.2&#039;&#039;&#039;]] Establish and enforce security configuration settings for information technology products employed in organizational systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] security configuration settings for information technology products employed in the system are established and included in the baseline configuration. || Document || Documentation explaining methodology used by organization to create secure baselines (STIGs, benchmarks).&lt;br /&gt;
|-&lt;br /&gt;
| [b] security configuration settings for information technology products employed in the system are enforced. || Artifact || Evidence of tool/s used to enforce security configurations to ensure images used are free from modification unless authorized.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== CM.L2-3.4.3 – System Change Management ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_CM.L2-3.4.3_Details|&#039;&#039;&#039;CM.L2-3.4.3&#039;&#039;&#039;]] Track, review, approve or disapprove, and log changes to organizational systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] changes to the system are tracked. || Artifact || Evidence of IT Service Management tool / process used to track system changes.&lt;br /&gt;
|-&lt;br /&gt;
| [b] changes to the system are reviewed. || Artifact || Evidence of IT Service Management tool / process used to review system changes.&lt;br /&gt;
|-&lt;br /&gt;
| [c] changes to the system are approved or disapproved. || Artifact || Evidence of IT Service Management tool / process used to approve/disapprove system changes.&lt;br /&gt;
|-&lt;br /&gt;
| [d] changes to the system are logged. || Artifact || Evidence of IT Service Management tool / process used to log system changes.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== CM.L2-3.4.4 – Security Impact Analysis ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_CM.L2-3.4.4_Details|&#039;&#039;&#039;CM.L2-3.4.4&#039;&#039;&#039;]] Analyze the security impact of changes prior to implementation.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the security impact of changes to the system is analyzed prior to implementation. || Artifact || Document explaining that security impact analysis of proposed changes to a system is conducted prior to implementation.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== CM.L2-3.4.5 – Access Restrictions for Change ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_CM.L2-3.4.5_Details|&#039;&#039;&#039;CM.L2-3.4.5&#039;&#039;&#039;]] Define, document, approve, and enforce physical and logical access restrictions associated with changes to organizational systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] physical access restrictions associated with changes to the system are defined. || Document || Document explaining the process of how physical access restrictions are defined for an individuals ability to make system changes.&lt;br /&gt;
|-&lt;br /&gt;
| [b] physical access restrictions associated with changes to the system are documented. || Document || Document explaining the process of how physical access restrictions are defined for an individuals ability to make system changes are documented; access request process.&lt;br /&gt;
|-&lt;br /&gt;
| [c] physical access restrictions associated with changes to the system are approved. || Artifact || Evidence of process of how physical access to systems are granted (i.e. physical access request sample).&lt;br /&gt;
|-&lt;br /&gt;
| [d] physical access restrictions associated with changes to the system are enforced. || Physical Review || Evidence of process of how physical access to systems are enforced (physical access system).&lt;br /&gt;
|-&lt;br /&gt;
| [e] logical access restrictions associated with changes to the system are defined. || Document || Document explaining the process of how logical access restrictions are defined for an individual&#039;s ability to make system changes.&lt;br /&gt;
|-&lt;br /&gt;
| [f] logical access restrictions associated with changes to the system are documented. || Document || Document explaining the process of how logical access restrictions are defined for an individual&#039;s ability to make system changes are documented.&lt;br /&gt;
|-&lt;br /&gt;
| [g] logical access restrictions associated with changes to the system are approved. || Artifact || Evidence of process of how logical access to systems are granted.&lt;br /&gt;
|-&lt;br /&gt;
| [h] logical access restrictions associated with changes to the system are enforced. || Artifact || Evidence of process of how logical access to systems are enforced.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== CM.L2-3.4.6 – Least Functionality ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_CM.L2-3.4.6_Details|&#039;&#039;&#039;CM.L2-3.4.6&#039;&#039;&#039;]] Employ the principle of least functionality by configuring organizational systems to provide only essential capabilities.&lt;br /&gt;
|-&lt;br /&gt;
| [a] essential system capabilities are defined based on the principle of least functionality. || Document || Documentation explaining how systems are configured to utilize the principle of least functionality for designated users.&lt;br /&gt;
|-&lt;br /&gt;
| [b] the system is configured to provide only the defined essential capabilities. || Screen Share || Evidence displaying how systems are configured to utilize the principle of least functionality for designated users; disabled service settings, accepted standards for hardening (CIS benchmarks, etc.).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== CM.L2-3.4.7 – Nonessential Functionality ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_CM.L2-3.4.7_Details|&#039;&#039;&#039;CM.L2-3.4.7&#039;&#039;&#039;]] Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services.&lt;br /&gt;
|-&lt;br /&gt;
| [a] essential programs are defined. || Document || Documented essential programs specified; build documents; software center; SSP.&lt;br /&gt;
|-&lt;br /&gt;
| [b] the use of nonessential programs is defined. || Document || Documented listing of nonessential programs (whatever is NOT specified in [a]); AUP/User Agreement may identify nonessential use/programs.&lt;br /&gt;
|-&lt;br /&gt;
| [c] the use of nonessential programs is restricted, disabled, or prevented as defined. || Screen Share || Tool used to restrict nonessential programs displays restrictions as defined (McAfee ePO settings, Carbon Black rules, etc.).&lt;br /&gt;
|-&lt;br /&gt;
| [d] essential functions are defined. || Document || Documented essential functions are specified.&lt;br /&gt;
|-&lt;br /&gt;
| [e] the use of nonessential functions is defined. || Document || Documented nonessential functions are specified.&lt;br /&gt;
|-&lt;br /&gt;
| [f] the use of nonessential functions is restricted, disabled, or prevented as defined. || Screen Share || Tool used to restrict essential/nonessential functions displays restrictions as defined.&lt;br /&gt;
|-&lt;br /&gt;
| [g] essential ports are defined. || Document || Documented essential ports are specified.&lt;br /&gt;
|-&lt;br /&gt;
| [h] the use of nonessential ports is defined. || Document || Documented nonessential ports functions are specified.&lt;br /&gt;
|-&lt;br /&gt;
| [i] the use of nonessential ports is restricted, disabled, or prevented as defined. || Screen Share || Tool used to restrict essential/nonessential ports displays restrictions as defined (FW rules; McAfee; GPO, etc.).&lt;br /&gt;
|-&lt;br /&gt;
| [j] essential protocols are defined. || Document || Documented essential protocols are specified.&lt;br /&gt;
|-&lt;br /&gt;
| [k] the use of nonessential protocols is defined. || Document || Documented nonessential protocols functions are specified.&lt;br /&gt;
|-&lt;br /&gt;
| [l] the use of nonessential protocols is restricted, disabled, or prevented as defined. || Screen Share || Tool used to restrict essential/nonessential protocols displays restrictions as defined (FW rules; GPO, etc.).&lt;br /&gt;
|-&lt;br /&gt;
| [m] essential services are defined. || Document || Documented essential services specified.&lt;br /&gt;
|-&lt;br /&gt;
| [n] the use of nonessential services is defined. || Document || Documented nonessential services functions are specified.&lt;br /&gt;
|-&lt;br /&gt;
| [o] the use of nonessential services is restricted, disabled, or prevented as defined. || Screen Share || Tool used to restrict essential/nonessential services displays restrictions as defined.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== CM.L2-3.4.8 – Application Execution Policy ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_CM.L2-3.4.8_Details|&#039;&#039;&#039;CM.L2-3.4.8&#039;&#039;&#039;]] Apply deny-by-exception (blacklisting) policy to prevent the use of unauthorized software or deny-all, permit-by-exception (whitelisting) policy to allow the execution of authorized software.&lt;br /&gt;
|-&lt;br /&gt;
| [a] a policy specifying whether whitelisting or blacklisting is to be implemented is specified. || Document || Documentation explaining whitelisting or blacklisting process.&lt;br /&gt;
|-&lt;br /&gt;
| [b] the software allowed to execute under whitelisting or denied use under blacklisting is specified. || Document || Documentation explaining whitelisting or blacklisting process for software.&lt;br /&gt;
|-&lt;br /&gt;
| [c] whitelisting to allow the execution of authorized software or blacklisting to prevent the use of unauthorized software is implemented as specified. || Screen Share || Tool used for whitelisting or blacklisting for software shows capability of restricting/authorizing software (Carbon Black dashboard, &amp;quot;SW Store&amp;quot;, web proxies, DNS Blackhole, etc.).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== CM.L2-3.4.9 – User-Installed Software ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_CM.L2-3.4.9_Details|&#039;&#039;&#039;CM.L2-3.4.9&#039;&#039;&#039;]] Control and monitor user-installed software.&lt;br /&gt;
|-&lt;br /&gt;
| [a] a policy for controlling the installation of software by users is established. || Document || Documented software authorization process or methodology for approval.&lt;br /&gt;
|-&lt;br /&gt;
| [b] installation of software by users is controlled based on the established policy. || Screen Share || Evidence that approval/restriction in installation of software by authorized personnel is implemented as specified (AUP, GPO, etc.).&lt;br /&gt;
|-&lt;br /&gt;
| [c] installation of software by users is monitored. || Screen Share || Evidence that installation of software by authorized personnel is monitored (SCCM groups, SW Center, etc.).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Identification and Authentication (IA) ==&lt;br /&gt;
=== IA.L2-3.5.1 – Identification [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IA.L2-3.5.1_Details|&#039;&#039;&#039;IA.L2-3.5.1&#039;&#039;&#039;]] Identify information system users, processes acting on behalf of users, or devices.&lt;br /&gt;
|-&lt;br /&gt;
| [a] system users are identified. || Document || Based on what is defined in their documentation (SSP, AUP, Policy, SOP), request to see a sample of non-privileged/privileged users in AD OU group (overlaps with 3.1.1 and 3.1.5).&lt;br /&gt;
|-&lt;br /&gt;
| [b] processes acting on behalf of users are identified. || Screen Share || Based on what is defined in their documentation (SSP, AUP, Policy, SOP), request to see a sample of service accounts in AD OU group (overlaps with 3.1.1 and 3.1.5).&lt;br /&gt;
|-&lt;br /&gt;
| [c] devices accessing the system are identified. || Screen Share || Based on what is defined in their documentation (SSP, AUP, Policy, SOP), request to see a sample of domain-joined workstation &amp;amp; servers in AD OU group (overlaps with 3.1.1 and 3.1.5).  For network devices, request screen share/artifact to show how they are identified on the enterprise network.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IA.L2-3.5.2 – Authentication [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IA.L2-3.5.2_Details|&#039;&#039;&#039;IA.L2-3.5.2&#039;&#039;&#039;]] Authenticate (or verify) the identities of those users, processes, or devices, as a prerequisite to allowing access to organizational information systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the identity of each user is authenticated or verified as a prerequisite to system access. || Screen Share || If the user logs in with non-privileged account during other demoes and then a privileged account, then this should be satisfied.  If screen share is unavailable, request logs to show successful and unsuccessful login by privileged and non-privilged users.&lt;br /&gt;
|-&lt;br /&gt;
| [b] the identity of each process acting on behalf of a user is authenticated or verified as a prerequisite to system access. || Screen Share || Request a log that shows successful/unsuccessful service account trying to log on to company&#039;s asset.&lt;br /&gt;
|-&lt;br /&gt;
| [c] the identity of each device accessing or connecting to the system is authenticated or verified as a prerequisite to system access. || Screen Share || Request a log that shows domain-joined workstation/server authenticating to AD (focus on the MAC/IP address/hostname).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IA.L2-3.5.3 – Multifactor Authentication ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IA.L2-3.5.3_Details|&#039;&#039;&#039;IA.L2-3.5.3&#039;&#039;&#039;]] Use multifactor authentication for local and network access to privileged accounts and for network access to non-privileged accounts.&lt;br /&gt;
|-&lt;br /&gt;
| [a] privileged accounts are identified. || Screen Share|| Based on what is defined in their documentation, request to see a sample of privileged users in AD OU group.  Overlaps with 3.1.5.  Screenshot/screen share to show implementation is enforced.&lt;br /&gt;
|-&lt;br /&gt;
| [b] multifactor authentication is implemented for local access to privileged accounts. || Document || SSP, AUP, Policy, SOP that defines that MFA is needed for privileged local access.&lt;br /&gt;
|-&lt;br /&gt;
| [c] multifactor authentication is implemented for network access to privileged accounts. || Screen Share || Within the MFA implementation mechanism, show that privileged users are forced to use MFA;  Screenshot/Screen share to show implementation is enforced.&lt;br /&gt;
|-&lt;br /&gt;
| [d] multifactor authentication is implemented for network access to non-privileged accounts. || Screen Share || Within the MFA implementation mechanism, show that non-privileged users are forced to use MFA; Screenshot/Screen share to show implementation is enforced.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IA.L2-3.5.4 – Replay-Resistant Authentication ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IA.L2-3.5.4_Details|&#039;&#039;&#039;IA.L2-3.5.4&#039;&#039;&#039;]] Employ replay-resistant authentication mechanisms for network access to privileged and non-privileged accounts.&lt;br /&gt;
|-&lt;br /&gt;
| [a] replay-resistant authentication mechanisms are implemented for network account access to privileged and non-privileged accounts. || Screen Share || Show the GPO setting that enforces Kerberos within AD.  If MFA is used, show the implementation to enforce replay resistant techniques.  For non-windows, show the technical solution to enforce replay resistant attacks.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IA.L2-3.5.5 – Identifier Reuse ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IA.L2-3.5.5_Details|&#039;&#039;&#039;IA.L2-3.5.5&#039;&#039;&#039;]] Prevent reuse of identifiers for a defined period.&lt;br /&gt;
|-&lt;br /&gt;
| [a] a period within which identifiers cannot be reused is defined. || Document || SSP, policies, or SOP that defines identifier reuse.&lt;br /&gt;
|-&lt;br /&gt;
| [b] reuse of identifiers is prevented within the defined period. || Screen Share || Show the GPO setting/technical solution that enforces what is defined in policy/documentation (this can be automated or manual process; screen share/artifacts can be presented to satisfy this requirement.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IA.L2-3.5.6 – Identifier Handling ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IA.L2-3.5.6_Details|&#039;&#039;&#039;IA.L2-3.5.6&#039;&#039;&#039;]] Disable identifiers after a defined period of inactivity.&lt;br /&gt;
|-&lt;br /&gt;
| [a] a period of inactivity after which an identifier is disabled is defined. || Document || SSP, policy that defines the period of inactivity after which an identifier is disabled.&lt;br /&gt;
|-&lt;br /&gt;
| [b] identifiers are disabled after the defined period of inactivity. || Screen Share || Screen share AD or similar tool supporting directory-based identity-related services for disabled accounts (can be done by hand or script).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IA.L2-3.5.7 – Password Complexity ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IA.L2-3.5.7_Details|&#039;&#039;&#039;IA.L2-3.5.7&#039;&#039;&#039;]] Enforce a minimum password complexity and change of characters when new passwords are created.&lt;br /&gt;
|-&lt;br /&gt;
| [a] password complexity requirements are defined. || Document || SSP, policy that defines password complexity requirements.&lt;br /&gt;
|-&lt;br /&gt;
| [b] password change of character requirements are defined. || Document || SSP, policy that defines change of character requirements are defined.&lt;br /&gt;
|-&lt;br /&gt;
| [c] minimum password complexity requirements as defined are enforced when new passwords are created. || Screen Share || Screen share of AD or similar directory-based identity-related service tool to show complexity requirements.&lt;br /&gt;
|-&lt;br /&gt;
| [d] minimum password change of character requirements as defined are enforced when new passwords are created. || Screen Share || Screen share of Group Policy configuration or similar tool providing centralized management and configuration of operating systems, applications, and users&#039; settings to show that characters must be changed.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IA.L2-3.5.8 – Password Reuse ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IA.L2-3.5.8_Details|&#039;&#039;&#039;IA.L2-3.5.8&#039;&#039;&#039;]] Prohibit password reuse for a specified number of generations.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the number of generations during which a password cannot be reused is specified. || Document || SSP, policy that specifies the number of generations during which a password cannot be reused is specified.&lt;br /&gt;
|-&lt;br /&gt;
| [b] reuse of passwords is prohibited during the specified number of generations. || Screen Share || Screen share Group Policy or similar tool providing centralized management and configuration of operating systems, applications, and users&#039; settings in a directory-based identity-related service tool&#039;s configuration to show reuse of passwords is prohibited.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IA.L2-3.5.9 – Temporary Passwords ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IA.L2-3.5.9_Details|&#039;&#039;&#039;IA.L2-3.5.9&#039;&#039;&#039;]] Allow temporary password use for system logons with an immediate change to a permanent password.&lt;br /&gt;
|-&lt;br /&gt;
| [a] an immediate change to a permanent password is required when a temporary password is used for system logon. || Screen Share || Screen share of Group Policy or similar tool providing centralized management and configuration of operating systems, applications, and users&#039; settings in a directory-based identity-related service tool&#039;s configuration to show &amp;quot;change password at first logon.&amp;quot;&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IA.L2-3.5.10 – Cryptographically-Protected Passwords ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IA.L2-3.5.1_Details|&#039;&#039;&#039;IA.L2-3.5.1&#039;&#039;&#039;]] Store and transmit only cryptographically-protected passwords.&lt;br /&gt;
|-&lt;br /&gt;
| [a] passwords are cryptographically protected in storage. || Screen Share || Screen share Group Policy or similar tool providing centralized management and configuration of operating systems, applications, and users&#039; settings in a directory-based identity-related service tool&#039;s configuration that Kerberos, or a similar network authentication protocol that works on the basis of tickets to allow nodes communicating over a non-secure network to prove their identity to one another in a secure manner, is enabled.&lt;br /&gt;
|-&lt;br /&gt;
| [b] passwords are cryptographically protected in transit. || Screen Share || Screen share Group Policy or similar tool providing centralized management and configuration of operating systems, applications, and users&#039; settings in a directory-based identity-related service tool&#039;s configuration that Kerberos, or a similar network authentication protocol that works on the basis of tickets to allow nodes communicating over a non-secure network to prove their identity to one another in a secure manner, is enabled.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IA.L2-3.5.11 – Obscure Feedback ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IA.L2-3.5.10_Details|&#039;&#039;&#039;IA.L2-3.5.10&#039;&#039;&#039;]] Obscure feedback of authentication information.&lt;br /&gt;
|-&lt;br /&gt;
| [a] authentication information is obscured during the authentication process. || Screen Share || Screen share of Group Policy or similar tool providing centralized management and configuration of operating systems, applications, and users&#039; settings in a directory-based identity-related service tool&#039;s configuration to show that passwords are obscured.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Incident Response (IR) ==&lt;br /&gt;
=== IR.L2-3.6.1 – Incident Handling ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IR.L2-3.6.1_Details|&#039;&#039;&#039;IR.L2-3.6.1&#039;&#039;&#039;]] Establish an operational incident-handling capability for organizational systems that includes preparation, detection, analysis, containment, recovery, and user response activities.&lt;br /&gt;
|-&lt;br /&gt;
| [a] an operational incident-handling capability is established. || Document || Incident Response SOP/Plan.&lt;br /&gt;
|-&lt;br /&gt;
| [b] the operational incident-handling capability includes preparation. || Document || Incident Response SOP/Plan, prior incident report, training, COOP plan.&lt;br /&gt;
|-&lt;br /&gt;
| [c] the operational incident-handling capability includes detection. || Document || Incident Response SOP/Plan; definition of tools used to detect; artifacts showing tools used; prior incident report.&lt;br /&gt;
|-&lt;br /&gt;
| [d] the operational incident-handling capability includes analysis. || Document || Incident Response SOP/Plan; Definition of tools used to analyze potential incidents; artifacts showing tools used for analysis; prior incident report.&lt;br /&gt;
|-&lt;br /&gt;
| [e] the operational incident-handling capability includes containment. || Document || Incident Response SOP/Plan; isolation/quarantine process; user training.&lt;br /&gt;
|-&lt;br /&gt;
| [f] the operational incident-handling capability includes recovery. || Document || Incident Response SOP/Plan; COOP Plan; prior incident reports, re-baselining impacted devices.&lt;br /&gt;
|-&lt;br /&gt;
| [g] the operational incident-handling capability includes user response. || Document || Incident Response SOP/Plan; user awareness training; Help Desk process.&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IR.L2-3.6.2 – Incident Reporting ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IR.L2-3.6.2_Details|&#039;&#039;&#039;IR.L2-3.6.2&#039;&#039;&#039;]] Track, document, and report incidents to designated officials and/or authorities both internal and external to the organization.&lt;br /&gt;
|-&lt;br /&gt;
| [a] incidents are tracked. || Artifact || Incident Response SOP/Plan; ITSM artifact; technical implementation for incident tracking.&lt;br /&gt;
|-&lt;br /&gt;
| [b] incidents are documented. || Artifact || Incident Response SOP/Plan; ITSM artifact; technical implementation for incident tracking.&lt;br /&gt;
|-&lt;br /&gt;
| [c] authorities to whom incidents are to be reported are identified. || Document || Incident Response SOP/Plan.&lt;br /&gt;
|-&lt;br /&gt;
| [d] organizational officials to whom incidents are to be reported are identified. || Document || Incident Response SOP/Plan.&lt;br /&gt;
|-&lt;br /&gt;
| [e] identified authorities are notified of incidents. || Screen Share || Prior incident report; DIBNET login; prior email notifications.&lt;br /&gt;
|-&lt;br /&gt;
| [f] identified organizational officials are notified of incidents. || Artifact || Prior incident report; prior email notifications; tabletop exercises.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IR.L2-3.6.3 – Incident Response Testing ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IR.L2-3.6.3_Details|&#039;&#039;&#039;IR.L2-3.6.3&#039;&#039;&#039;]] Test the organizational incident response capability.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the incident response capability is tested. || Artifact || Incident response table top/scheduled or unscheduled test or penetration test.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Maintenance (MA) ==&lt;br /&gt;
=== MA.L2-3.7.1 – Perform Maintenance ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MA.L2-3.7.1_Details|&#039;&#039;&#039;MA.L2-3.7.1&#039;&#039;&#039;]] Perform maintenance on organizational systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] system maintenance is performed. || Artifact || Establish typical maintenance activities (HVAC, UPS, power distribution, generators, copier maintenance) that are performed; maintenance agreements or contracts detailing these types of activities are acceptable; interview responses should be considered.  This requirement should not be confused with 3.14.1 - report, remediate, and correct system flaws in a timely manner (patch management).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MA.L2-3.7.2 – System Maintenance Control ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MA.L2-3.7.2_Details|&#039;&#039;&#039;MA.L2-3.7.2&#039;&#039;&#039;]] Provide controls on the tools, techniques, mechanisms, and personnel used to conduct system maintenance.&lt;br /&gt;
|-&lt;br /&gt;
| [a] tools used to conduct system maintenance are controlled. || Artifact || Tools may largely depend on the assessed environment; discussion examples include network diagnostic and monitoring tools (including hardware and software); artifacts could demonstrate secured locations/areas for these tools (photos) or checkout sheets/rosters (documents) depicting responsible personnel and the dates/times of checkout.&lt;br /&gt;
|-&lt;br /&gt;
| [b] techniques used to conduct system maintenance are controlled. || Artifact || Processes for scheduling, performing, documenting, reviewing, approving, and monitoring maintenance and repairs for the information system.&lt;br /&gt;
|-&lt;br /&gt;
| [c] mechanisms used to conduct system maintenance are controlled. || Artifact || Processes for scheduling, performing, documenting, reviewing, approving, and monitoring maintenance and repairs for the information system.&lt;br /&gt;
|-&lt;br /&gt;
| [d] personnel used to conduct system maintenance are controlled. || Physical Review || Screenshot of who is authorized to conduct maintenance; maintenance personnel training program.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MA.L2-3.7.3 – Equipment Sanitization ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MA.L2-3.7.3_Details|&#039;&#039;&#039;MA.L2-3.7.3&#039;&#039;&#039;]] Ensure equipment removed for off-site maintenance is sanitized of any CUI.&lt;br /&gt;
|-&lt;br /&gt;
| [a] equipment to be removed from organizational spaces for off-site maintenance is sanitized of any CUI. || Artifact || Document or artifact; record if equipment sanitized; categories of sanitization/destruction defined; sanitization procedural document.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MA.L2-3.7.4 – Media Inspection ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MA.L2-3.7.4_Details|&#039;&#039;&#039;MA.L2-3.7.4&#039;&#039;&#039;]] Check media containing diagnostic and test programs for malicious code before the media are used in organizational systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] media containing diagnostic and test programs are checked for malicious code before being used in organizational systems that process, store, or transmit CUI. || Artifact || Screenshot of diagnostic/test program being used (such as Symantec and McAfee on access scans…).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MA.L2-3.7.5 – Nonlocal Maintenance ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MA.L2-3.7.5_Details|&#039;&#039;&#039;MA.L2-3.7.5&#039;&#039;&#039;]] Require multifactor authentication to establish nonlocal maintenance sessions via external network connections and terminate such connections when nonlocal maintenance is complete.&lt;br /&gt;
|-&lt;br /&gt;
| [a] multifactor authentication is used to establish nonlocal maintenance sessions via external network connections. || Screen Share || Describe MFA used to remote from external service to organizational systems for maintenance and screenshot of MFA (3.5.3)(points associated with admin).&lt;br /&gt;
|-&lt;br /&gt;
| [b] nonlocal maintenance sessions established via external network connections are terminated when nonlocal maintenance is complete. || Screen Share || Screenshot VPN session timeout.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MA.L2-3.7.6 – Maintenance Personnel ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MA.L2-3.7.6_Details|&#039;&#039;&#039;MA.L2-3.7.6&#039;&#039;&#039;]] Supervise the maintenance activities of maintenance personnel without required access authorization.&lt;br /&gt;
|-&lt;br /&gt;
| [a] maintenance personnel without required access authorization are supervised during maintenance activities. || Document || System maintenance policy; list of authorized personnel; maintenance records or, contracts/SLAs; WebEx.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Media Protection (MP) ==&lt;br /&gt;
=== MP.L2-3.8.1 – Media Protection ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MP.L2-3.8.1_Details|&#039;&#039;&#039;MP.L2-3.8.1&#039;&#039;&#039;]] Protect (i.e., physically control and securely store) system media containing CUI, both paper and digital.&lt;br /&gt;
|-&lt;br /&gt;
| [a] paper media containing CUI is physically controlled. || Document || Policy showing CUI paper media is controlled; artifact showing who has access; artifacts/records of  inventories conducted; media check out procedures (i.e. file cabinets, encryption, password protection).&lt;br /&gt;
|-&lt;br /&gt;
| [b] digital media containing CUI is physically controlled. || Document || Policy showing CUI digital media is controlled; artifact showing who has access; artifacts/records of inventories conducted; media check out procedures (i.e. file cabinets, external drives, USBs, encryption, password protection).&lt;br /&gt;
|-&lt;br /&gt;
| [c] paper media containing CUI is securely stored. || Physical Review || Check out/sign out sheets; possible photo of storage container/video walk through of storage area; badge reader logs or access lists for keys for secured areas; interview response considered (i.e. file cabinets,  encryption, password protection).&lt;br /&gt;
|-&lt;br /&gt;
| [d] digital media containing CUI is securely stored. || Physical Review || Check out/sign out sheets; possible photo of storage container/video walk through of storage area; badge reader logs or access lists for keys for secured areas; interview response considered (i.e. file cabinets, external drives, USBs, encryption, password protection).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MP.L2-3.8.2 – Media Access ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MP.L2-3.8.2_Details|&#039;&#039;&#039;MP.L2-3.8.2&#039;&#039;&#039;]] Limit access to CUI on system media to authorized users.&lt;br /&gt;
|-&lt;br /&gt;
| [a] access to CUI on system media is limited to authorized users. || Artifact || Document describing how CUI is limited AND artifact showing principle of least access is implemented.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MP.L2-3.8.3 – Media Disposal [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MP.L2-3.8.3_Details|&#039;&#039;&#039;MP.L2-3.8.3&#039;&#039;&#039;]] Sanitize or destroy information system media containing Federal Contract Information before disposal or release for reuse.&lt;br /&gt;
|-&lt;br /&gt;
| [a] system media containing CUI is sanitized or destroyed before disposal. || Document || Policy or artifact of media destruction logs; certificates of destruction; SLAs or contracts.&lt;br /&gt;
|-&lt;br /&gt;
| [b] system media containing CUI is sanitized before it is released for reuse. || Document || Policy or artifact describing method to sanitize, software used (i.e. DoD Wipe, ShredIT and Iron Mountain; Blancco; GDisk, DBAN).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MP.L2-3.8.4 – Media Markings ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MP.L2-3.8.4_Details|&#039;&#039;&#039;MP.L2-3.8.4&#039;&#039;&#039;]] Mark media with necessary CUI markings and distribution limitations.&lt;br /&gt;
|-&lt;br /&gt;
| [a] media containing CUI is marked with applicable CUI markings. || Physical Review || Document or artifact showing CUI markings (i.e. labeling standards ).&lt;br /&gt;
|-&lt;br /&gt;
| [b] media containing CUI is marked with distribution limitations. || Physical Review || Document or artifact showing distro limitations (i.e. labeling standards ).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MP.L2-3.8.5 – Media Accountability ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MP.L2-3.8.5_Details|&#039;&#039;&#039;MP.L2-3.8.5&#039;&#039;&#039;]] Control access to media containing CUI and maintain accountability for media during transport outside of controlled areas.&lt;br /&gt;
|-&lt;br /&gt;
| [a] access to media containing CUI is controlled. || Document || Policy, artifact of audit logs showing tracking, Access Control Lists, records of transport activities (i.e. USB drives, CDs, chain of custody.&lt;br /&gt;
|-&lt;br /&gt;
| [b] accountability for media containing CUI is maintained during transport outside of controlled areas. || Artifact || Artifact of audit logs showing tracking, Access Control Lists, records of transport activities (i.e. USB drives, CDs; chain of custody.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MP.L2-3.8.6 – Portable Storage Encryption ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MP.L2-3.8.6_Details|&#039;&#039;&#039;MP.L2-3.8.6&#039;&#039;&#039;]] Implement cryptographic mechanisms to protect the confidentiality of CUI stored on digital media during transport unless otherwise protected by alternative physical safeguards.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the confidentiality of CUI stored on digital media is protected during transport using cryptographic mechanisms or alternative physical safeguards. || Artifact || Artifact showing crypto mechanisms used to protect (are they FIPS 140-2 [13.11]); artifact showing what alternative physical safeguards are in place (i.e. encryption; BitLocker; McAfee ).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MP.L2-3.8.7 – Removable Media ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MP.L2-3.8.7_Details|&#039;&#039;&#039;MP.L2-3.8.7&#039;&#039;&#039;]] Control the use of removable media on system components.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the use of removable media on system components is controlled. || Artifact || Policy showing if removable media is allowed; writable removable media is restricted; tracking artifacts; what tools are used (i.e. Carbon Black, Crowd Strike, GPO, Zoho Desktop Central); procedure/process describing what happens if it is lost; what mechanisms are in place to control/restrict removable media (i.e. Active Directory Groups and Group Policy artifact showing restriction).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MP.L2-3.8.8 – Shared Media ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MP.L2-3.8.8_Details|&#039;&#039;&#039;MP.L2-3.8.8&#039;&#039;&#039;]] Prohibit the use of portable storage devices when such devices have no identifiable owner.ASSESSMENT OBJECTIVES&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [a] the use of portable storage devices is prohibited when such devices have no identifiable owner. || Artifact || Policy and/or artifact showing company stance on portable storage devices if there is no owner (are personal USB devices allowed or are they company-issued; artifact showing alerts if device is connected to network (i.e. external HDD, Carbon Black, Crowd Strike, GPO, Zoho Desktop Central.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MP.L2-3.8.9 – Protect Backups ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MP.L2-3.8.9_Details|&#039;&#039;&#039;MP.L2-3.8.9&#039;&#039;&#039;]] Protect the confidentiality of backup CUI at storage locations.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the confidentiality of backup CUI is protected at storage locations. || Artifact || Policy on system backups; artifact showing media labeling; artifact showing encyption (is it FIPS 140-2 [13.11]); Access Control List artifact (i.e. backup tapes, Tivoli Storage Manager).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Personnel Security (PS) ==&lt;br /&gt;
=== PS.L2-3.9.1 – Screen Individuals ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_PS.L2-3.9.1_Details|&#039;&#039;&#039;PS.L2-3.9.1&#039;&#039;&#039;]] Screen individuals prior to authorizing access to organizational systems containing CUI.&lt;br /&gt;
|-&lt;br /&gt;
| [a] individuals are screened prior to authorizing access to organizational systems containing CUI. || Artifact || Screenshot of records of screened personnel/background checks.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== PS.L2-3.9.2 – Personnel Actions ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_PS.L2-3.9.2_Details|&#039;&#039;&#039;PS.L2-3.9.2&#039;&#039;&#039;]] Ensure that organizational systems containing CUI are protected during and after personnel actions such as terminations and transfers.&lt;br /&gt;
|-&lt;br /&gt;
| [a] a policy and/or process for terminating system access and any credentials coincident with personnel actions is established. || Document || Personnel security policy/procedures/instruction; Access control policy/procedure/instruction.&lt;br /&gt;
|-&lt;br /&gt;
| [b] system access and credentials are terminated consistent with personnel actions such as termination or transfer. || Artifact || Screenshot of records of personnel transfer and termination actions.&lt;br /&gt;
|-&lt;br /&gt;
| [c] the system is protected during and after personnel transfer actions. || Artifact || Completed outprocessing checklist.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Physical Protection (PE) ==&lt;br /&gt;
=== PE.L2-3.10.1 – Limit Physical Access [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_PE.L2-3.10.1_Details|&#039;&#039;&#039;PE.L2-3.10.1&#039;&#039;&#039;]] Limit physical access to organizational information systems, equipment, and the respective operating environments to authorized individuals.&lt;br /&gt;
|-&lt;br /&gt;
| [a] authorized individuals allowed physical access are identified. || Artifact || Authorized personnel (names) access list.&lt;br /&gt;
|-&lt;br /&gt;
| [b] physical access to organizational systems is limited to authorized individuals. || Physical Review || Badge reader logs, audit logs, and/or card swipe test.&lt;br /&gt;
|-&lt;br /&gt;
| [c] physical access to equipment is limited to authorized individuals. || Physical Review || Badge reader logs, audit logs, and/or card swipe test.&lt;br /&gt;
|-&lt;br /&gt;
| [d] physical access to operating environments is limited to authorized. || Physical Review || Badge reader logs, audit logs, and/or card swipe test.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== PE.L2-3.10.2 – Monitor Facility ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_PE.L2-3.10.2_Details|&#039;&#039;&#039;PE.L2-3.10.2&#039;&#039;&#039;]] Protect and monitor the physical facility and support infrastructure for organizational systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the physical facility where organizational systems reside is protected. || Physical Review || Physical security measures and barriers into the physical facility (cameras/locks/gates/guards, etc.).&lt;br /&gt;
|-&lt;br /&gt;
| [b] the support infrastructure for organizational systems is protected. || Physical Review || Physical barriers to entries into computer spaces, server rooms, etc.&lt;br /&gt;
|-&lt;br /&gt;
| [c] the physical facility where organizational systems reside is monitored. || Physical Review || Audit logs/how the physical facility is being monitored (cameras/access system/guards, etc.).&lt;br /&gt;
|-&lt;br /&gt;
| [d] the support infrastructure for organizational systems is monitored. || Physical Review || Audit logs/how the physical facility is being monitored (cameras/access system/guards, etc.).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== PE.L2-3.10.3 – Escort Visitors [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_PE.L2-3.10.3_Details|&#039;&#039;&#039;PE.L2-3.10.3&#039;&#039;&#039;]] Escort visitors and monitor visitor activity.&lt;br /&gt;
|-&lt;br /&gt;
| [a] visitors are escorted. || Physical Review || Policy/procedures/instruction on methodology for handling non-authorized personnel (entry to exit).&lt;br /&gt;
|-&lt;br /&gt;
| [b] visitor activity is monitored. || Physical Review || Policy/procedures/instructio on methodology for handling non-authorized personnel (entry to exit).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== PE.L2-3.10.4 – Physical Access Logs [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_PE.L2-3.10.4_Details|&#039;&#039;&#039;PE.L2-3.10.4&#039;&#039;&#039;]] Maintain audit logs of physical access.&lt;br /&gt;
|-&lt;br /&gt;
| [a] audit logs of physical access are maintained. || Artifact || Log or report from badging system.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== PE.L2-3.10.5 – Manage Physical Access [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_PE.L2-3.10.5_Details|&#039;&#039;&#039;PE.L2-3.10.5&#039;&#039;&#039;]] Control and manage physical access devices.&lt;br /&gt;
|-&lt;br /&gt;
| [a] physical access devices are identified. || Document || Physical access control systems description, guard force contract/policy, key locks, logical systems specifications, etc.&lt;br /&gt;
|-&lt;br /&gt;
| [b] physical access devices are controlled. || Physical Review || Inventory records of physical access control devices (e.g. keys, locks, card readers, locks, etc.).&lt;br /&gt;
|-&lt;br /&gt;
| [c] physical access devices are managed. || Physical Review || List of security safeguards controlling access to the facility (e.g. cameras, monitoring by guards, isolation of IT systems equiment and or system components).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== PE.L2-3.10.6 – Alternative Work Sites ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_PE.L2-3.10.6_Details|&#039;&#039;&#039;PE.L2-3.10.6&#039;&#039;&#039;]] Enforce safeguarding measures for CUI at alternate work sites.&lt;br /&gt;
|-&lt;br /&gt;
| [a] safeguarding measures for CUI are defined for alternate work sites. || Document || Telework agreement, Acceptable Use Policy and SOP for alternate work locations; user security training validation which includes physical/logical/technical protections of system at alternate work sites.&lt;br /&gt;
|-&lt;br /&gt;
| [b] safeguarding measures for CUI are enforced for alternate work sites. || Artifact || Monitoring/audit log of user activity and logical/physical/technical mechanisms in place to preclude unauthorized activity (telework agreement , AUP?).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Risk Assessment (RA) ==&lt;br /&gt;
=== RA.L2-3.11.1 – Risk Assessments ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_RA.L2-3.11.1_Details|&#039;&#039;&#039;RA.L2-3.11.1&#039;&#039;&#039;]] Periodically assess the risk to organizational operations (including mission, functions, image, or reputation), organizational assets, and individuals, resulting from the operation of organizational systems and the associated processing, storage, or transmission of CUI.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the frequency to assess risk to organizational operations, organizational assets, and individuals is defined. || Document || Risk assessment policy.&lt;br /&gt;
|-&lt;br /&gt;
| [b] risk to organizational operations, organizational assets, and individuals resulting from the operation of an organizational system that processes, stores, or transmits CUI is assessed with the defined frequency. || Artifact || Copy of last risk assessment done within defined frequency.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== RA.L2-3.11.2 – Vulnerability Scan ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_RA.L2-3.11.2_Details|&#039;&#039;&#039;RA.L2-3.11.2&#039;&#039;&#039;]] Scan for vulnerabilities in organizational systems and applications periodically and when new vulnerabilities affecting those systems and applications are identified.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the frequency to scan for vulnerabilities in organizational systems and applications is defined. || Document || Policy/procedures/instruction addressing vulnerability scanning records.&lt;br /&gt;
|-&lt;br /&gt;
| [b] vulnerability scans are performed on organizational systems with the defined frequency. || Screen Share || System configuration settings of vulnerability scanning scheduling and vulnerability scan results of systems within defined frequency.&lt;br /&gt;
|-&lt;br /&gt;
| [c] vulnerability scans are performed on applications with the defined frequency. || Screen Share || System configuration settings of vulnerability scanning scheduling and vulnerability scan results of applications within defined frequency.&lt;br /&gt;
|-&lt;br /&gt;
| [d] vulnerability scans are performed on organizational systems when new vulnerabilities are identified. || Screen Share || View signatures in scanning tool/ad hoc scan performed as a result.&lt;br /&gt;
|-&lt;br /&gt;
| [e] vulnerability scans are performed on applications when new vulnerabilities are identified. || Screen Share || View signatures in scanning tool/ad hoc scan performed as a result.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== RA.L2-3.11.3 – Vulnerability Remediation ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_RA.L2-3.11.3_Details|&#039;&#039;&#039;RA.L2-3.11.3&#039;&#039;&#039;]] Remediate vulnerabilities in accordance with risk assessments.&lt;br /&gt;
|-&lt;br /&gt;
| [a] vulnerabilities are identified. || Artifact || Scan results showing vulnerabilities identified.&lt;br /&gt;
|-&lt;br /&gt;
| [b] vulnerabilities are remediated in accordance with risk assessments. || Artifact || Screenshot/document of scan results of remediated vulnerabilities in accordance to risk assessments.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Security Assessment (CA) ==&lt;br /&gt;
=== CA.L2-3.12.1 – Security Control Assessment ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_CA.L2-3.12.1_Details|&#039;&#039;&#039;CA.L2-3.12.1&#039;&#039;&#039;]] Periodically assess the security controls in organizational systems to determine if the controls are effective in their application.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the frequency of security control assessments is defined. || Document || SSP.&lt;br /&gt;
|-&lt;br /&gt;
| [b] security controls are assessed with the defined frequency to determine if the controls are effective in their application. || Artifact || Copy of last security control assessment done within defined frequency.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== CA.L2-3.12.2 – Operational Plan of Action ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_CA.L2-3.12.2_Details|&#039;&#039;&#039;CA.L2-3.12.2&#039;&#039;&#039;]] Develop and implement plans of action designed to correct deficiencies and reduce or eliminate vulnerabilities in organizational systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] deficiencies and vulnerabilities to be addressed by the plan of action are identified. || Artifact || Plan of Action (POA).&lt;br /&gt;
|-&lt;br /&gt;
| [b] a plan of action is developed to correct identified deficiencies and reduce or eliminate identified vulnerabilities. || Artifact || Plan of Action (POA).&lt;br /&gt;
|-&lt;br /&gt;
| [c] the plan of action is implemented to correct identified deficiencies and reduce or eliminate identified vulnerabilities. || Artifact || Plan of Action (POA)/previously completed POAs.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== CA.L2-3.12.3 – Security Control Monitoring ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_CA.L2-3.12.3_Details|&#039;&#039;&#039;CA.L2-3.12.3&#039;&#039;&#039;]] Monitor security controls on an ongoing basis to ensure the continued effectiveness of the controls.&lt;br /&gt;
|-&lt;br /&gt;
| [a] security controls are monitored on an ongoing basis to ensure the continued effectiveness of those controls. || Artifact || Collection of risk assessment results, internal or third-party audits/security assessments and/or continuous monitoring reports/alerts (SIEM tool, etc.).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== CA.L2-3.12.4 – System Security Plan ====&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_CA.L2-3.12.4_Details|&#039;&#039;&#039;CA.L2-3.12.4&#039;&#039;&#039;]] Develop, document, and periodically update system security plans that describe system boundaries, system environments of operation, how security requirements are implemented, and the relationships with or connections to other systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] a system security plan is developed. || Document || SSP.&lt;br /&gt;
|-&lt;br /&gt;
| [b] the system boundary is described and documented in the system security plan. || Document || SSP and any supporting documentation.&lt;br /&gt;
|-&lt;br /&gt;
| [c] the system environment of operation is described and documented in the system security plan. || Document || SSP and any supporting documentation.&lt;br /&gt;
|-&lt;br /&gt;
| [d] the security requirements identified and approved by the designated authority as non-applicable are identified. || Document || SSP and required adjudication from DoD CIO.&lt;br /&gt;
|-&lt;br /&gt;
| [e] the method of security requirement implementation is described and documented in the system security plan. || Document || SSP and any supporting documentation.&lt;br /&gt;
|-&lt;br /&gt;
| [f] the relationship with or connection to other systems is described and documented in the system security plan. || Document || SSP and any supporting documentation.&lt;br /&gt;
|-&lt;br /&gt;
| [g] the frequency to update the system security plan is defined. || Document || SSP.&lt;br /&gt;
|-&lt;br /&gt;
| [h] system security plan is updated with the defined frequency. || Document || SSP/any previous versions.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== System and Communications Protection (SC) ==&lt;br /&gt;
=== SC.L2-3.13.1 – Boundary Protection [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.1_Details|&#039;&#039;&#039;SC.L2-3.13.1&#039;&#039;&#039;]] Monitor, control, and protect organizational communications (i.e., information transmitted or received by organizational information systems) at the external boundaries and key internal boundaries of the information systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the external system boundary is defined. || Document || SSP, network diagrams, CUI flow, cloud provider FedRAMP Moderate.&lt;br /&gt;
|-&lt;br /&gt;
| [b] key internal system boundaries are defined. || Document || SSP, network diagrams, CUI flow.&lt;br /&gt;
|-&lt;br /&gt;
| [c] communications are monitored at the external system boundary. || Screen Share || SSP, logging server, boundary device configurations, monitoring policy.&lt;br /&gt;
|-&lt;br /&gt;
| [d] communications are monitored at key internal boundaries. || Screen Share || SSP, logging server, boundary device configurations, monitoring policy.&lt;br /&gt;
|-&lt;br /&gt;
| [e] communications are controlled at the external system boundary. || Screen Share || SSP, boundary device configurations, ACL, subnets, DMZ.&lt;br /&gt;
|-&lt;br /&gt;
| [f] communications are controlled at key internal boundaries. || Screen Share || SSP, boundary device configurations, ACL, subnets.&lt;br /&gt;
|-&lt;br /&gt;
| [g] communications are protected at the external system boundary. || Screen Share || Configurations for IPS/IDS, email gateway, VLAN, proxy, firewall, malware protection, DNS, TSL.&lt;br /&gt;
|-&lt;br /&gt;
| [h] communications are protected at key internal boundaries. || Screen Share || Configurations for IPS/IDS, VLAN, firewall, malware protection, SSL.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.2 – Security Engineering ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.2_Details|&#039;&#039;&#039;SC.L2-3.13.2&#039;&#039;&#039;]] Employ architectural designs, software development techniques, and systems engineering principles that promote effective information security within organizational systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] architectural designs that promote effective information security are identified. || Document || SSP, config management policy, network diagram, CCB minutes, enterprise architecture process.&lt;br /&gt;
|-&lt;br /&gt;
| [b] software development techniques that promote effective information security are identified. || Document || SSP, config management policy, SDLC, CCB minutes.&lt;br /&gt;
|-&lt;br /&gt;
| [c] systems engineering principles that promote effective information security are identified. || Document || SSP, config management policy, CCB minutes, security architecture engineering.&lt;br /&gt;
|-&lt;br /&gt;
| [d] identified architectural designs that promote effective information security are employed. || Artifact || CCB minutes, Network diagrams and configurations, Project Plans.&lt;br /&gt;
|-&lt;br /&gt;
| [e] identified software development techniques that promote effective information security are employed. || Artifact || CCB minutes, SDLC, code scanner results, code management tracking.&lt;br /&gt;
|-&lt;br /&gt;
| [f] identified systems engineering principles that promote effective information security are employed. || Artifact || CCB minutes, configuration management, ITSM, patch management, lifecycle replacement processes.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.3 – Role Separation ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.3_Details|&#039;&#039;&#039;SC.L2-3.13.3&#039;&#039;&#039;]] Separate user functionality from system management functionality.&lt;br /&gt;
|-&lt;br /&gt;
| [a] user functionality is identified. || Document || SSP, AUP.&lt;br /&gt;
|-&lt;br /&gt;
| [b] system management functionality is identified. || Document || SSP, Privileged Account Agreement.&lt;br /&gt;
|-&lt;br /&gt;
| [c] user functionality is separated from system management functionality. || Screen Share || Active Directory, Jump Boxes, GPO, VM, RDP.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.4 – Shared Resource Control ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.4_Details|&#039;&#039;&#039;SC.L2-3.13.4&#039;&#039;&#039;]] Prevent unauthorized and unintended information transfer via shared system resources.&lt;br /&gt;
|-&lt;br /&gt;
| [a] unauthorized and unintended information transfer via shared system resources is prevented. || Screen Share || SSP, OS configurations, Linux containers, system/media reuse policies, certificate management policies, media destruction policies, printer configs, VDI configuration.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
===  SC.L2-3.13.5 – Public-Access System Separation [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.5_Details|&#039;&#039;&#039;SC.L2-3.13.5&#039;&#039;&#039;]] Implement subnetworks for publicly accessible system components that are physically or logically separated from internal networks.&lt;br /&gt;
|-&lt;br /&gt;
| [a] publicly accessible system components are identified. || Document || SSP, network diagram, DMZ inventory/roles.&lt;br /&gt;
|-&lt;br /&gt;
| [b] subnetworks for publicly accessible system components are physically or logically separated from internal networks. || Artifact || Network diagram, IPAM, VLAN, DHCP, DMZ.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.6 – Network Communication by Exception ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.6_Details|&#039;&#039;&#039;SC.L2-3.13.6&#039;&#039;&#039;]] Deny network communications traffic by default and allow network communications traffic by exception (i.e., deny all, permit by exception).&lt;br /&gt;
|-&lt;br /&gt;
| [a] network communications traffic is denied by default. || Screen Share || Host and network firewall rules, SIEM logs, hit counts.&lt;br /&gt;
|-&lt;br /&gt;
| [b] network communications traffic is allowed by exception. || Screen Share || Host and network firewall rules, SIEM logs, hit counts.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.7 – Split Tunneling ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.7_Details|&#039;&#039;&#039;SC.L2-3.13.7&#039;&#039;&#039;]] Prevent remote devices from simultaneously establishing non-remote connections with organizational systems and communicating via some other connection to resources in external networks (i.e., split tunneling).&lt;br /&gt;
|-&lt;br /&gt;
| [a] remote devices are prevented from simultaneously establishing non-remote connections with the system and communicating via some other connection to resources in external networks (i.e., split tunneling). || Screen Share || VPN appliance/server configuration, endpoint VPN software configuration.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.8 – Data in Transit ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.8_Details|&#039;&#039;&#039;SC.L2-3.13.8&#039;&#039;&#039;]] Implement cryptographic mechanisms to prevent unauthorized disclosure of CUI during transmission unless otherwise protected by alternative physical safeguards.&lt;br /&gt;
|-&lt;br /&gt;
| [a] cryptographic mechanisms intended to prevent unauthorized disclosure of CUI are identified. || Document || SSP, PKI policies, configuration processes, config management, email attachment encryption policy, removable media policy, data at rest policy.&lt;br /&gt;
|-&lt;br /&gt;
| [b] alternative physical safeguards intended to prevent unauthorized disclosure of CUI are identified. || Document || SSP, physical security policy.&lt;br /&gt;
|-&lt;br /&gt;
| [c] either cryptographic mechanisms or alternative physical safeguards are implemented to prevent unauthorized disclosure of CUI during transmission. || Screen Share || TLS settings, SSL settings, VPN/Wireless Access Points/Mobile Devices cryptographic settings, ODBC connector settings, SAN configuration, IPSec/MPLS, backup configuration, physical security.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.9 – Connections Termination ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.9_Details|&#039;&#039;&#039;SC.L2-3.13.9&#039;&#039;&#039;]] Terminate network connections associated with communications sessions at the end of the sessions or after a defined period of inactivity.&lt;br /&gt;
|-&lt;br /&gt;
| [a] a period of inactivity to terminate network connections associated with communications sessions is defined. || Document || SSP, network communications policy.&lt;br /&gt;
|-&lt;br /&gt;
| [b] network connections associated with communications sessions are terminated at the end of the sessions. || Screen Share || VPN appliance/server logs, VPN configurations, web server configurations, firewall connection settings.&lt;br /&gt;
|-&lt;br /&gt;
| [c] network connections associated with communications sessions are terminated after the defined period of inactivity. || Screen Share || VPN appliance/server logs, VPN configurations, web server configurations, frewall connection settings.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.10 – Key Management ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.10_Details|&#039;&#039;&#039;SC.L2-3.13.10&#039;&#039;&#039;]] Establish and manage cryptographic keys for cryptography employed in organizational systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] cryptographic keys are established whenever cryptography is employed. || Artifact || SSP, PKI/certificate management policy, configuration management.&lt;br /&gt;
|-&lt;br /&gt;
| [b] cryptographic keys are managed whenever cryptography is employed. || Artifact || SSP, PKI/certificate management policy, configuration management, access control policy.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.11 – CUI Encryption ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.11_Details|&#039;&#039;&#039;SC.L2-3.13.11&#039;&#039;&#039;]] Employ FIPS-validated cryptography when used to protect the confidentiality of CUI.&lt;br /&gt;
|-&lt;br /&gt;
| [a] FIPS-validated cryptography is employed to protect the confidentiality of CUI. || Screen Share || VPN, wireless, mobile devices, client certificates, server certificates, disk encryption, Outlook plugin, external mail, backup media, ePO server, removable storage, SAN, file compression; look for FIPS mode enabled on appliances.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.12 – Collaborative Device Control ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.12_Details|&#039;&#039;&#039;SC.L2-3.13.12&#039;&#039;&#039;]] Prohibit remote activation of collaborative computing devices and provide indication of devices in use to users present at the device.&lt;br /&gt;
|-&lt;br /&gt;
| [a] collaborative computing devices are identified. || Document || SSP, network diagrams.&lt;br /&gt;
|-&lt;br /&gt;
| [b] collaborative computing devices provide indication to users of devices in use. || Physical Review || Physical inspection of device.&lt;br /&gt;
|-&lt;br /&gt;
| [c] remote activation of collaborative computing devices is prohibited. || Screen Share || Collaboration device configuration/console.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.13 – Mobile Code ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.13_Details|&#039;&#039;&#039;SC.L2-3.13.13&#039;&#039;&#039;]] Control and monitor the use of mobile code.&lt;br /&gt;
|-&lt;br /&gt;
| [a] use of mobile code is controlled. || Screen Share || GPO settings, malware protection, software agent configurations, software development policies, code scanners, MDM configuration, firewall/secure web gateway/proxy config.&lt;br /&gt;
|-&lt;br /&gt;
| [b] use of mobile code is monitored. || Screen Share || SIEM/console monitoring.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.14 – Voice over Internet Protocol ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.14_Details|&#039;&#039;&#039;SC.L2-3.13.14&#039;&#039;&#039;]] Control and monitor the use of Voice over Internet Protocol (VoIP) technologies.&lt;br /&gt;
|-&lt;br /&gt;
| [a] use of Voice over Internet Protocol (VoIP) technologies is controlled. || Artifact || VLAN, ACL, firewall config, VoIP gateway/condenser configuration.&lt;br /&gt;
|-&lt;br /&gt;
| [b] use of Voice over Internet Protocol (VoIP) technologies is monitored. || Artifact || SIEM/VoIP console monitoring, session border controller.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.15 – Communications Authenticity ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.15_Details|&#039;&#039;&#039;SC.L2-3.13.15&#039;&#039;&#039;]] Protect the authenticity of communications sessions.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the authenticity of communications sessions is protected. || Screen Share || SSL, TLS, SMB3, SFTP, IPSec, SSH, Kerberos configs, MPLS, Network Access Control.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.16 – Data at Rest ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.16_Details|&#039;&#039;&#039;SC.L2-3.13.16&#039;&#039;&#039;]] Protect the confidentiality of CUI at rest.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the confidentiality of CUI at rest is protected. || Artifact || Full disk encryption, removable media encryption, SAN encryption, digital backups, mobile device encryption, third party offsite backup storage, cloud virtualization encryption, physical media storage policies.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== System and Information Integrity (SI) ==&lt;br /&gt;
=== SI.L2-3.14.1 – Flaw Remediation [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SI.L2-3.14.1_Details|&#039;&#039;&#039;SI.L2-3.14.1&#039;&#039;&#039;]] Identify, report, and correct information and information system flaws in a timely manner.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the time within which to identify system flaws is specified. || Document || SSP, patch management policy.&lt;br /&gt;
|-&lt;br /&gt;
| [b] system flaws are identified within the specified time frame. || Screen Share || Vulnerability management scanner output and scan policy configuration.&lt;br /&gt;
|-&lt;br /&gt;
| [c] the time within which to report system flaws is specified. || Document || SSP, patch management policy.&lt;br /&gt;
|-&lt;br /&gt;
| [d] system flaws are reported within the specified time frame. || Screen Share || ITSM/trouble tickets, vulnerability management scanner output.&lt;br /&gt;
|-&lt;br /&gt;
| [e] the time within which to correct system flaws is specified. || Document || SSP, patch management policy.&lt;br /&gt;
|-&lt;br /&gt;
| [f] system flaws are corrected within the specified time frame. || Screen Share || Vulnerability management scanner output and scan policy configuration.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SI.L2-3.14.2 – Malicious Code ProTection [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SI.L2-3.14.2_Details|&#039;&#039;&#039;SI.L2-3.14.2&#039;&#039;&#039;]] Provide protection from malicious code at appropriate locations within organizational information systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] designated locations for malicious code protection are identified. || Document || SSP, system protection policy, network diagrams, security architecture documents.&lt;br /&gt;
|-&lt;br /&gt;
| [b] protection from malicious code at designated locations is provided. || Screen Share || Endpoint security settings, email/web proxy gateways, firewall, IPS sensor, MDM configuration, Network Access Control.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SI.L2-3.14.3 – Security Alerts &amp;amp; Advisories ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SI.L2-3.14.3_Details|&#039;&#039;&#039;SI.L2-3.14.3&#039;&#039;&#039;]] Monitor system security alerts and advisories and take action in response.&lt;br /&gt;
|-&lt;br /&gt;
| [a] response actions to system security alerts and advisories are identified. || Document || SSP, vulnerability management policy, Incident Response Plan.&lt;br /&gt;
|-&lt;br /&gt;
| [b] system security alerts and advisories are monitored. || Artifact || Threat intelligence subscriptions, email advisories.&lt;br /&gt;
|-&lt;br /&gt;
| [c] actions in response to system security alerts and advisories are taken. || Artifact || ITSM/trouble tickets, user notifications, updates to firewall/IPS, etc.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SI.L2-3.14.4 – Update Malicious Code Protection [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SI.L2-3.14.4_Details|&#039;&#039;&#039;SI.L2-3.14.4&#039;&#039;&#039;]] Update malicious code protection mechanisms when new releases are available.&lt;br /&gt;
|-&lt;br /&gt;
| [a] malicious code protection mechanisms are updated when new releases are available. || Screen Share || Antivirus console dashboard, firewall AV, Email gateway signatures,proxy, IPS updates.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SI.L2-3.14.5 – System &amp;amp; File Scanning [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SI.L2-3.14.5_Details|&#039;&#039;&#039;SI.L2-3.14.5&#039;&#039;&#039;]] Perform periodic scans of the information system and real-time scans of files from external sources as files are downloaded, opened, or executed.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the frequency for malicious code scans is defined. || Document || SSP, vulnerability management policy.&lt;br /&gt;
|-&lt;br /&gt;
| [b] malicious code scans are performed with the defined frequency. || Screen Share || Consoles for AV (endpoints, servers, and file shares), firewall, email gateway, proxy, IPS, MDM configurations.&lt;br /&gt;
|-&lt;br /&gt;
| [c] real-time malicious code scans of files from external sources as files are downloaded, opened, or executed are performed. || Screen Share || Consoles for AV (endpoints, servers, and file shares), firewall, email gateway, proxy, IPS, MDM configurations.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SI.L2-3.14.6 – Monitor Communications for Attacks ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SI.L2-3.14.6_Details|&#039;&#039;&#039;SI.L2-3.14.6&#039;&#039;&#039;]] Monitor organizational systems, including inbound and outbound communications traffic, to detect attacks and indicators of potential attacks.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the system is monitored to detect attacks and indicators of potential attacks. || Screen Share || Firewall, IPS, endpoint protection, SIEM alerts and reports.&lt;br /&gt;
|-&lt;br /&gt;
| [b] inbound communications traffic is monitored to detect attacks and indicators of potential attacks. || Screen Share || Firewall, IPS, endpoint protection, SIEM alerts and reports.&lt;br /&gt;
|-&lt;br /&gt;
| [c] outbound communications traffic is monitored to detect attacks and indicators of potential attacks. || Screen Share || Firewall, IPS, endpoint protection, SIEM alerts and reports.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SI.L2-3.14.7 – Identify Unauthorized Use ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SI.L2-3.14.7_Details|&#039;&#039;&#039;SI.L2-3.14.7&#039;&#039;&#039;]] Identify unauthorized use of organizational systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] authorized use of the system is defined. || Document || AUP, SSP.&lt;br /&gt;
|-&lt;br /&gt;
| [b] unauthorized use of the system is identified. || Artifact || SIEM logs, endpoint protection console, IPS, Firewall.&lt;br /&gt;
|}&lt;/div&gt;</summary>
		<author><name>David</name></author>
	</entry>
	<entry>
		<id>https://cmmcwiki.org/index.php?title=Evidence_Collection_Approach&amp;diff=1616</id>
		<title>Evidence Collection Approach</title>
		<link rel="alternate" type="text/html" href="https://cmmcwiki.org/index.php?title=Evidence_Collection_Approach&amp;diff=1616"/>
		<updated>2026-07-20T01:36:57Z</updated>

		<summary type="html">&lt;p&gt;David: /* AC.L2-3.1.10 – Session Lock */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;CMMC assessments and certification require substantial evidence and documentation. The following tables outline general guidelines for collecting evidence to assess control requirements and objectives. While these guidelines provide a structured approach, they are not the only means of conducting an accurate assessment. Assessors should exercise professional judgment and may employ alternative methods appropriate to the specific organizational context and circumstances.&lt;br /&gt;
&lt;br /&gt;
Evidence collection approaches are defined as:&lt;br /&gt;
* &#039;&#039;&#039;Documentation&#039;&#039;&#039;: Tangible materials containing information over which an organization has authority, including all types of written records and their copies.&lt;br /&gt;
* &#039;&#039;&#039;Artifacts&#039;&#039;&#039;: Tangible, reviewable records directly resulting from a practice or process being performed by a system or by personnel executing their role within that practice, control, or process.&lt;br /&gt;
* &#039;&#039;&#039;Physical Review&#039;&#039;&#039;: Direct on-site observation and examination of evidence.&lt;br /&gt;
* &#039;&#039;&#039;Screen Share&#039;&#039;&#039;: Real-time remote observation of a user demonstrating a task or process via shared computer screen, sometimes called &amp;quot;over-the-shoulder&amp;quot; review.&lt;br /&gt;
&lt;br /&gt;
DISCLAIMER: Evidence requirements vary significantly across assessment types. &#039;&#039;&#039;The examples provided are illustrative only and should be tailored to meet the specific adequacy and sufficiency standards of your particular assessment context.&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
For inquiries and reporting errors on this wiki, please [mailto:support@cmmctoolkit.org contact us]. Thank you.&lt;br /&gt;
&lt;br /&gt;
== Access Control (AC) ==&lt;br /&gt;
=== AC.L2-3.1.1 – Authorized Access Control [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.1_Details|&#039;&#039;&#039;AC.L2-3.1.1&#039;&#039;&#039;]] Limit information system access to authorized users, processes acting on behalf of authorized users, or devices (including other information systems).&lt;br /&gt;
|-&lt;br /&gt;
| [a] authorized users are identified. || Document || Document defining account request, approval, provisioning.&lt;br /&gt;
|-&lt;br /&gt;
| [b] processes acting on behalf of authorized users are identified. || Document || Document defining account request, approval, provisioning.&lt;br /&gt;
|-&lt;br /&gt;
| [c] devices (and other systems) authorized to connect to the system are identified. || Document || Document defining account request, approval, provisioning.&lt;br /&gt;
|-&lt;br /&gt;
| [d] system access is limited to authorized users. || Screen Share || Screen share showing login requirements are enforced. Example of an unauthorized user denied (unauthorized username entered at login).&lt;br /&gt;
|-&lt;br /&gt;
| [e] system access is limited to processes acting on behalf of authorized users. || Screen Share || Screenshot showing that service accounts are assigned to authorized users only; no rogue accounts without an authorized user are active.&lt;br /&gt;
|-&lt;br /&gt;
| [f] system access is limited to authorized devices (including other systems). || Screen Share || Screen share showing that all devices running are authorized; no rogue devices on the network.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.2 – Transaction &amp;amp; Function Control [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.2_Details|&#039;&#039;&#039;AC.L2-3.1.2&#039;&#039;&#039;]] Limit information system access to the types of transactions and functions that authorized users are permitted to execute.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the types of transactions and functions that authorized users are permitted to execute are defined. || Document || SSP, AUP, or IAM document that defines what authorized users can execute.&lt;br /&gt;
|-&lt;br /&gt;
| [b] system access is limited to the defined types of transactions and functions for authorized users. || Screen Share || Screenshot of security roles in AD or IAM or other directory-based identity-related services tool that shows transactions are as defined in the SSP or IAM document; privileged and non-privileged accounts need to be defined and identified in the artifact; screenshot of a non-privileged user trying to execute a privileged function.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.3 – Control CUI Flow ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.3_Details|&#039;&#039;&#039;AC.L2-3.1.3&#039;&#039;&#039;]] Control the flow of CUI in accordance with approved authorizations.&lt;br /&gt;
|-&lt;br /&gt;
| [a] information flow control policies are defined. || Document || SSP or other document describing the control of CUI on the network.&lt;br /&gt;
|-&lt;br /&gt;
| [b] methods and enforcement mechanisms for controlling the flow of CUI are defined. || Document || Document that defines the networking devices that are on the CUI network and answers what measures are in place to control the flow. List of firewalls, border and internal layer 3 devices, IDS/IPS, DLP, that process CUI.&lt;br /&gt;
|-&lt;br /&gt;
| [c] designated sources and destinations (e.g., networks, individuals, and devices) for CUI within the system and between interconnected systems are identified. || Artifact || Network diagram, data flow diagram, external system connection diagrams, document describing the policies for CUI on the network; listing of VLANs and subnets where CUI is authorized; document must describe source and authorized destinations.&lt;br /&gt;
|-&lt;br /&gt;
| [d] authorizations for controlling the flow of CUI are defined. || Document || Document that defines how CUI is to be controlled, such as an InfoSec plan, and/or network management plan.&lt;br /&gt;
|-&lt;br /&gt;
| [e] approved authorizations for controlling the flow of CUI are enforced. || Screen Share || Screenshots of firewall rules, ACLs, etc.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.4 – Separation of Duties ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.4_Details|&#039;&#039;&#039;AC.L2-3.1.4&#039;&#039;&#039;]] Separate the duties of individuals to reduce the risk of malevolent activity without collusion.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the duties of individuals requiring separation are defined. || Document || Document, SSP, account management policy, defining separation of duties by person or role.&lt;br /&gt;
|-&lt;br /&gt;
| [b] responsibilities for duties that require separation are assigned to separate individuals. || Screen Share || Screenshot showing that separation of duties is enforced by showing admin accounts are assigned to different people based on role.&lt;br /&gt;
|-&lt;br /&gt;
| [c] access privileges that enable individuals to exercise the duties that require separation are granted to separate individuals. || Screen Share || Screen shot showing an example such as a security manager can not log into a network device and change ACLs, or network admins can not access security logs in the SIEM tool.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.5 – Least Privilege ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.5_Details|&#039;&#039;&#039;AC.L2-3.1.5&#039;&#039;&#039;]] Employ the principle of least privilege, including for specific security functions and privileged accounts.&lt;br /&gt;
|-&lt;br /&gt;
| [a] privileged accounts are identified. || Document || &amp;quot;SSP or policy (documentation) identify what is considered a privileged account.&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| [b] access to privileged accounts is authorized in accordance with the principle of least privilege. || Artifact || An artifact that identifies the least amount of permissions associated with different types of privileged accounts are approved.&lt;br /&gt;
|-&lt;br /&gt;
| [c] security functions are identified. || Document || &amp;quot;SSP or policy (documentation) identifies what is considered a security account.&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| [d] access to security functions is authorized in accordance with the principle of least privilege. || Artifact || Artifact(s) that identify the least amount of permissions associated with different types of security accounts are approved.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.6 – Non-Privileged Account Use ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.6_Details|&#039;&#039;&#039;AC.L2-3.1.6&#039;&#039;&#039;]] Use non-privileged accounts or roles when accessing nonsecurity functions.&lt;br /&gt;
|-&lt;br /&gt;
| [a] nonsecurity functions are identified. || Document || SSP or account management document, AUP, that defines non-security functions.&lt;br /&gt;
|-&lt;br /&gt;
| [b] users are required to use non-privileged accounts or roles when accessing nonsecurity functions. || Screen Share || Screenshot showing that a privileged user tried to use their admin account to access a non-security function, such as a browser or email (whatever is defined in their policy) and was blocked.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.7 – Privileged Functions ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.7_Details|&#039;&#039;&#039;AC.L2-3.1.7&#039;&#039;&#039;]] Prevent non-privileged users from executing privileged functions and capture the execution of such functions in audit logs.&lt;br /&gt;
|-&lt;br /&gt;
| [a] privileged functions are defined. || Document || SSP or policy (documentation) that defines privileged functions.&lt;br /&gt;
|-&lt;br /&gt;
| [b] non-privileged users are defined. || Document || SSP or policy (documentation) that defines non-privileged users.&lt;br /&gt;
|-&lt;br /&gt;
| [c] non-privileged users are prevented from executing privileged functions. || Screen Share || Screen share that shows that a non-privileged user is not allowed to complete a privileged function (installing software).&lt;br /&gt;
|-&lt;br /&gt;
| [d] the execution of privileged functions is captured in audit logs. || Screen Share || Screen share that shows logs being captured of the execution of privileged functions.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.8 – Unsuccessful Logon Attempts ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.8_Details|&#039;&#039;&#039;AC.L2-3.1.8&#039;&#039;&#039;]] Limit unsuccessful logon attempts.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the means of limiting unsuccessful logon attempts is defined. || Document || SSP or policy (documentation) showing unsuccessful logon attempts settings and or policy.&lt;br /&gt;
|-&lt;br /&gt;
| [b] the defined means of limiting unsuccessful logon attempts is implemented. || Artifact || Artifact showing GPO / Policy for limiting logon attempts.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.9 – Privacy &amp;amp; Security Notices ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.9_Details|&#039;&#039;&#039;AC.L2-3.1.9&#039;&#039;&#039;]] Provide privacy and security notices consistent with applicable CUI rules.&lt;br /&gt;
|-&lt;br /&gt;
| [a] privacy and security notices required by CUI-specified rules are identified, consistent, and associated with the specific CUI category. || Document || SSP or policy (documentation) showing CUI-specified rules are identified, consistent, and associated with the specific CUI category.&lt;br /&gt;
|-&lt;br /&gt;
| [b] privacy and security notices are displayed. || Artifact || Artifact that shows a consent banner or screen that a user sees as they log in to the system.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.10 – Session Lock ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.10_Details|&#039;&#039;&#039;AC.L2-3.1.10&#039;&#039;&#039;]] Use session lock with pattern-hiding displays to prevent access and viewing of data after a period of inactivity.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the period of inactivity after which the system initiates a session lock is defined. || Document || SSP or policy (documentation) that defines the period of inactivity and when a session lock is defined.&lt;br /&gt;
|-&lt;br /&gt;
| [b] access to the system and viewing of data is prevented by initiating a session lock after the defined period of inactivity. || Artifact || Artifact that shows the setting of session lock (GPO or system policy or similar solution addressing the controls supporting centralized management and configuration of operating systems, applications, and users&#039; settings for the working environment of user accounts and computer accounts).&lt;br /&gt;
|-&lt;br /&gt;
| [c] previously visible information is concealed via a pattern-hiding display after the defined period of inactivity. || Document || Screenshot of GPO setting and configuration settings, or similar solution addressing the controls supporting centralized management and configuration of operating systems, applications, and users&#039; settings for the working environment of user accounts and computer accounts.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.11 – Session Termination ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.11_Details|&#039;&#039;&#039;AC.L2-3.1.11&#039;&#039;&#039;]] Terminate (automatically) a user session after a defined condition.&lt;br /&gt;
|-&lt;br /&gt;
| [a] conditions requiring a user session to terminate are defined. || Document || SSP or policy (documentation) that defines the conditions requiring a user session to be terminated.&lt;br /&gt;
|-&lt;br /&gt;
| [b] a user session is automatically terminated after any of the defined conditions. || Screen Share || Screen share showing GPO / VPN Settings that show when a session would be terminated (Idle time, max connection time).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.12 – Control Remote Access ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.12_Details|&#039;&#039;&#039;AC.L2-3.1.12&#039;&#039;&#039;]] Monitor and control remote access sessions.&lt;br /&gt;
|-&lt;br /&gt;
| [a] remote access sessions are permitted. || Document || SSP or policy (documentation) that defines remote access sessions.&lt;br /&gt;
|-&lt;br /&gt;
| [b] the types of permitted remote access are identified. || Document || SSP or policy (documentation) that defines remote access is permitted.&lt;br /&gt;
|-&lt;br /&gt;
| [c] remote access sessions are controlled. || Screen Share || Screen share that shows how the remote access is controlled (access session, and or groups).&lt;br /&gt;
|-&lt;br /&gt;
| [d] remote access sessions are monitored. || Screen Share || Screen share that shows how remote sessions are monitored (logs).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.13 – Remote Access Confidentiality ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.13_Details|&#039;&#039;&#039;AC.L2-3.1.13&#039;&#039;&#039;]] Employ cryptographic mechanisms to protect the confidentiality of remote access sessions.&lt;br /&gt;
|-&lt;br /&gt;
| [a] cryptographic mechanisms to protect the confidentiality of remote access sessions are identified. || Document || SSP or policy (documentation) that discusses the CUI rules, consistent, and associated with the specific CUI category; FIPS Cert # of appliance or application.&lt;br /&gt;
|-&lt;br /&gt;
| [b] cryptographic mechanisms to protect the confidentiality of remote access sessions are implemented. || Screen Share || Screenshot of VPN concentration that shows encryption is on and enabled (point-to-point, etc.).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.14 – Remote Access Routing ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.14_Details|&#039;&#039;&#039;AC.L2-3.1.14&#039;&#039;&#039;]] Route remote access via managed access control points.&lt;br /&gt;
|-&lt;br /&gt;
| [a] managed access control points are identified and implemented. || Screen Share || Screen share that shows access control points (groups and/or users).&lt;br /&gt;
|-&lt;br /&gt;
| [b] remote access is routed through managed network access control points. || Screen Share || Screen share that shows access control points and how they are managed.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.15 – Privileged Remote Access ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.15_Details|&#039;&#039;&#039;AC.L2-3.1.15&#039;&#039;&#039;]] Authorize remote execution of privileged commands and remote access to security-relevant information.&lt;br /&gt;
|-&lt;br /&gt;
| [a] privileged commands authorized for remote execution are identified. || Document || SSP or policy (documentation) that defines what is authorized to be executed remotely and how that is handled.&lt;br /&gt;
|-&lt;br /&gt;
| [b] security-relevant information authorized to be accessed remotely is identified. || Document || SSP or policy (documentation) that defines what can be accessed remotely and what procedures are implemented to allow this (RDP, jump box).&lt;br /&gt;
|-&lt;br /&gt;
| [c] the execution of the identified privileged commands via remote access is authorized. || Screen Share || Screen share that shows who has access to perform privileged commands a remotely (access groups for privileged accounts).&lt;br /&gt;
|-&lt;br /&gt;
| [d] access to the identified security-relevant information via remote access is authorized. || Screen Share || Screen share that shows the routing of remote access and how it is monitored and how many locations (Firewall, VPN Concentrator).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.16 – Wireless Access Authorization ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.16_Details|&#039;&#039;&#039;AC.L2-3.1.16&#039;&#039;&#039;]] Authorize wireless access prior to allowing such connections.&lt;br /&gt;
|-&lt;br /&gt;
| [a] wireless access points are identified. || Document || SSP, network administration document.&lt;br /&gt;
|-&lt;br /&gt;
| [b] wireless access is authorized prior to allowing such connections. || Screen Share || Authorization profile(s) in Wireless Access Controller or Identity Manager (i.e. Cisco ISE).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.17 – Wireless Access Protection ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.17_Details|&#039;&#039;&#039;AC.L2-3.1.17&#039;&#039;&#039;]] Protect wireless access using authentication and encryption.&lt;br /&gt;
|-&lt;br /&gt;
| [a] wireless access to the system is protected using authentication. || Screen Share || Security page (or similar) of a Wireless Access Controller.&lt;br /&gt;
|-&lt;br /&gt;
| [b] wireless access to the system is protected using encryption. || Screen Share || Security page (or similar) of a Wireless Access Controller.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.18 – Mobile Device Connection ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.18_Details|&#039;&#039;&#039;AC.L2-3.1.18&#039;&#039;&#039;]] Control connection of mobile devices.&lt;br /&gt;
|-&lt;br /&gt;
| [a] mobile devices that process, store, or transmit CUI are identified. || Document || SSP, Mobile Device Policy.&lt;br /&gt;
|-&lt;br /&gt;
| [b] mobile device connections are authorized. || Screen Share || Authorization profile(s) in Wireless Access Controller or Identity Manager (i.e. Cisco ISE).&lt;br /&gt;
|-&lt;br /&gt;
| [c] mobile device connections are monitored and logged. || Screen Share || Mobile device logs within the MDM, log intake (sources) configuration (within SIEM) showing MDM is feeding logs to the SIEM.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.19 – Encrypt CUI on Mobile ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.19_Details|&#039;&#039;&#039;AC.L2-3.1.19&#039;&#039;&#039;]] Encrypt CUI on mobile devices and mobile computing platforms.&lt;br /&gt;
|-&lt;br /&gt;
| [a] mobile devices and mobile computing platforms that process, store, or transmit CUI are identified. || Document || SSP, Mobile Device Policy.&lt;br /&gt;
|-&lt;br /&gt;
| [b] encryption is employed to protect CUI on identified mobile devices and mobile computing platforms. || Screen Share || Security policy page in MDM showing how encryption are enforced on mobile device. If no MDM or MDM doesn&#039;t enforce encryption, then validate if the devices used are on the list of devices with native FIPS approved validation.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.20 – External Connections [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.20_Details|&#039;&#039;&#039;AC.L2-3.1.20&#039;&#039;&#039;]] Verify and control/limit connections to and use of external information systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] connections to external systems are identified. || Document || SSP, Systems Interconnection Agreements, SLA.&lt;br /&gt;
|-&lt;br /&gt;
| [b] the use of external systems is identified. || Document || SSP, Systems Interconnection Agreements, SLA.&lt;br /&gt;
|-&lt;br /&gt;
| [c] connections to external systems are verified. || Artifact || SLA for external systems, memorandum for interconnection, information to prove that any cloud solution is at FedRAMP impact level of moderate or higher (i.e. license information, screenshot of AWS cloud dashboard, purchase order document).&lt;br /&gt;
|-&lt;br /&gt;
| [d] the use of external systems is verified. || Artifact || SLA for external systems, memorandum for interconnection, information to prove that any cloud solution is at FedRAMP impact level of moderate or higher (i.e. license information, screenshot of AWS cloud dashboard, purchase order document).&lt;br /&gt;
|-&lt;br /&gt;
| [e] connections to external systems are controlled/limited. || Screen Share || Firewall ruleset for controlling access to cloud service or external system.&lt;br /&gt;
|-&lt;br /&gt;
| [f] the use of external systems is controlled/limited. || Screen Share || Firewall ruleset for controlling access to cloud service or external system.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.21 – Portable Storage Use ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.21_Details|&#039;&#039;&#039;AC.L2-3.1.21&#039;&#039;&#039;]] Limit use of portable storage devices on external systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the use of portable storage devices containing CUI on external systems is identified and documented. || Document || SSP, Removable Media Policy, Acceptable Use Policy (with emphasis on portable media use).&lt;br /&gt;
|-&lt;br /&gt;
| [b] limits on the use of portable storage devices containing CUI on external systems are defined. || Document || SSP, Removable Media Policy, Acceptable Use Policy (with emphasis on portable media use).&lt;br /&gt;
|-&lt;br /&gt;
| [c] the use of portable storage devices containing CUI on external systems is limited as defined. || Document || SSP, Removable Media Policy, Acceptable Use Policy (with emphasis on portable media use).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.22 – Control Public Information [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.22_Details|&#039;&#039;&#039;AC.L2-3.1.22&#039;&#039;&#039;]] Control information posted or processed on publicly accessible information systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] individuals authorized to post or process information on publicly accessible systems are identified. || Document || SSP, Website Governance Plan, Information Release Document.&lt;br /&gt;
|-&lt;br /&gt;
| [b] procedures to ensure CUI is not posted or processed on publicly accessible systems are identified. || Document || SSP, Website Governance Plan, Information Release Document.&lt;br /&gt;
|-&lt;br /&gt;
| [c] a review process is in place prior to posting of any content to publicly accessible systems. || Artifact || &amp;quot;Information release approval process, i.e. chain of email communication from originator, approver, and final decision (may or may not include individual authorized to post); &lt;br /&gt;
SharePoint/electronic or paper form/ ticket system showing information flow between requestor and approver (may or may not include  individual authorized to post).&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| [d] content on publicly accessible systems is reviewed to ensure that it does not include CUI. || Artifact || Incident response process, web design/update/modification SOP etc.&lt;br /&gt;
|-&lt;br /&gt;
| [e] mechanisms are in place to remove and address improper posting of CUI. || Artifact || Incident response process, web design/update/modification SOP etc.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Awareness and Training (AT) ==&lt;br /&gt;
=== AT.L2-3.2.1 – Role-Based Risk Awareness ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AT.L2-3.2.1_Details|&#039;&#039;&#039;AT.L2-3.2.1&#039;&#039;&#039;]] Ensure that managers, systems administrators, and users of organizational systems are made aware of the security risks associated with their activities and of the applicable policies, standards, and procedures related to the security of those systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] security risks associated with organizational activities involving CUI are identified. || Document || Policy of Security Awareness Training; Security Awareness Training Briefing.&lt;br /&gt;
|-&lt;br /&gt;
| [b] policies, standards, and procedures related to the security of the system are identified. || Document || Acceptable Use Policy, Policy/Procedures/Instruction related to the security of the system.&lt;br /&gt;
|-&lt;br /&gt;
| [c] managers, systems administrators, and users of the system are made aware of the security risks associated with their activities. || Artifact || Security Training Brief, training records.&lt;br /&gt;
|-&lt;br /&gt;
| [d] managers, systems administrators, and users of the system are made aware of the applicable policies, standards, and procedures related to the security of the system. || Artifact || Policies, standards and procedures for employees within training (completed training report).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AT.L2-3.2.2 – Role-Based Training ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AT.L2-3.2.2_Details|&#039;&#039;&#039;AT.L2-3.2.2&#039;&#039;&#039;]] Ensure that personnel are trained to carry out their assigned information security-related duties and responsibilities.|-&lt;br /&gt;
|-&lt;br /&gt;
| [a] information security-related duties, roles, and responsibilities are defined. || Document || Policy/Procedures/Instruction, Job Role Matrix, Position Descriptions, User Roles.&lt;br /&gt;
|-&lt;br /&gt;
| [b] information security-related duties, roles, and responsibilities are assigned to designated personnel. || Artifact || Screenshot of breakout of different roles/permissions assigned to individuals (i.e. ActiveDirectory); Privilege Access Agreement.&lt;br /&gt;
|-&lt;br /&gt;
| [c] personnel are adequately trained to carry out their assigned information security-related duties, roles, and responsibilities. || Artifact || Screenshot of tool and/or training specifying security specific roles, duties and responsibilities; Screenshot of required certifications (i.e. Sec+, CISSP).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AT.L2-3.2.3 – Insider Threat Awareness ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AT.L2-3.2.3_Details|&#039;&#039;&#039;AT.L2-3.2.3&#039;&#039;&#039;]] Provide security awareness training on recognizing and reporting potential indicators of insider threat.&lt;br /&gt;
|-&lt;br /&gt;
| [a] potential indicators associated with insider threats are identified. || Document || Insidert Threat Policy/Procedures/Instruction; Insider Threat Training/Briefing.&lt;br /&gt;
|-&lt;br /&gt;
| [b] security awareness training on recognizing and reporting potential indicators of insider threat is provided to managers and employees. || Artifact || Screenshot of training records showing completion of Insider Threat training, emails showing completion of Insider Threat training, Screenshot of certificate showing completion with individual&#039;s name.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Audit and Accountability (AU) ==&lt;br /&gt;
=== AU.L2-3.3.1 – System Auditing ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AU.L2-3.3.1_Details|&#039;&#039;&#039;AU.L2-3.3.1&#039;&#039;&#039;]] Create and retain system audit logs and records to the extent needed to enable the monitoring, analysis, investigation, and reporting of unlawful or unauthorized system activity.&lt;br /&gt;
|-&lt;br /&gt;
| [a] audit logs needed (i.e., event types to be logged) to enable the monitoring, analysis, investigation, and reporting of unlawful or unauthorized system activity are specified. || Document || SSP, policy, or auditing and logging process that defines specific types of events to be logged.&lt;br /&gt;
|-&lt;br /&gt;
| [b] the content of audit records needed to support monitoring, analysis, investigation, and reporting of unlawful or unauthorized system activity is defined. || Document || SSP, policy, or auditing and logging process that defines specific content of audit records/files.&lt;br /&gt;
|-&lt;br /&gt;
| [c] audit records are created (generated). || Screen Share || Screen share of tool that shows logs are generated for all systems.&lt;br /&gt;
|-&lt;br /&gt;
| [d] audit records, once created, contain the defined content. || Screen Share || Screen share of tool that shows logs contain defined content as defined in SSP, policy, or procedures.&lt;br /&gt;
|-&lt;br /&gt;
| [e] retention requirements for audit records are defined. || Document || SSP, Polocy, or Auditing and logging process that describes how long records are kept.&lt;br /&gt;
|-&lt;br /&gt;
| [f] audit records are retained as defined. || Screen Share || Screen share of tool that shows records and audit content retained at a minimum as defined.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AU.L2-3.3.2 – User Accountability ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AU.L2-3.3.2_Details|&#039;&#039;&#039;AU.L2-3.3.2&#039;&#039;&#039;]] Ensure that the actions of individual system users can be uniquely traced to those users so they can be held accountable for their actions.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the content of the audit records needed to support the ability to uniquely trace users to their actions is defined. || Document || SSP, policy, or process that defines actions traced back to individuals.&lt;br /&gt;
|-&lt;br /&gt;
| [b] audit records, once created, contain the defined content. || Screen Share || Screen share of tool that shows audit records traced to specific users/roles.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AU.L2-3.3.3 – Event Review ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AU.L2-3.3.3_Details|&#039;&#039;&#039;AU.L2-3.3.3&#039;&#039;&#039;]] Review and update logged events.&lt;br /&gt;
|-&lt;br /&gt;
| [a] a process for determining when to review logged events is defined. || Document || SSP, policy, or documented process that shows frequency of when to review types of logged events.&lt;br /&gt;
|-&lt;br /&gt;
| [b] event types being logged are reviewed in accordance with the defined review process. || Artifact || Evidence through a documented method such as meeting minutes, CAB minutes, etc. of log sources and log events being logged at the defined frequency.&lt;br /&gt;
|-&lt;br /&gt;
| [c] event types being logged are updated based on the review. || Artifact || Evidence of implementation based on the results of the review of logged events/sources through a ticket, meeting minutes, or screen share of the tool that shows changes implemented (finetuning).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AU.L2-3.3.4 – Audit Failure Alerting ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AU.L2-3.3.4_Details|&#039;&#039;&#039;AU.L2-3.3.4&#039;&#039;&#039;]] Alert in the event of an audit logging process failure.&lt;br /&gt;
|-&lt;br /&gt;
| [a] personnel or roles to be alerted in the event of an audit logging process failure are identified. || Document || SSP, policy, or procedure that shows who needs to be notified in case of an audit failure.&lt;br /&gt;
|-&lt;br /&gt;
| [b] types of audit logging process failures for which alert will be generated are defined. || Document || SSP, policy, or procedure that shows what types of failure will generate notifications.&lt;br /&gt;
|-&lt;br /&gt;
| [c] identified personnel or roles are alerted in the event of an audit logging process failure. || Artifact || Artifact such as email or ticket that shows the identified personnel were alerted of any audit/logging process failure as defined.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AU.L2-3.3.5 – Audit Correlation ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AU.L2-3.3.5_Details|&#039;&#039;&#039;AU.L2-3.3.5&#039;&#039;&#039;]] Correlate audit record review, analysis, and reporting processes for investigation and response to indications of unlawful, unauthorized, suspicious, or unusual activity.&lt;br /&gt;
|-&lt;br /&gt;
| [a] audit record review, analysis, and reporting processes for investigation and response to indications of unlawful, unauthorized, suspicious, or unusual activity are defined. || Document || SSP, policy, or procedure covering audit logging, monitoring, and reporting.&lt;br /&gt;
|-&lt;br /&gt;
| [b] defined audit record review, analysis, and reporting processes are correlated. || Artifact || Artifact showing an audit event and the resultant corrective action or actions to the event; this can be a Help Desk ticket, meeting notes, or a change control board items showing the event and any corrective action taken.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AU.L2-3.3.6 – Reduction &amp;amp; Reporting ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AU.L2-3.3.6_Details|&#039;&#039;&#039;AU.L2-3.3.6&#039;&#039;&#039;]] Provide audit record reduction and report generation to support on-demand analysis and reporting.&lt;br /&gt;
|-&lt;br /&gt;
| [a] an audit record reduction capability that supports on-demand analysis is provided. || Screen Share || Screen share of the logging environment where an event can be selected and traced back to a specific device, or dashboard showing realtime event analysis.&lt;br /&gt;
|-&lt;br /&gt;
| [b] a report generation capability that supports on-demand reporting is provided. || Screen Share || Screen share showing the generation of an on demand report.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AU.L2-3.3.7 – Authoritative Time Source ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AU.L2-3.3.7_Details|&#039;&#039;&#039;AU.L2-3.3.7&#039;&#039;&#039;]] Provide a system capability that compares and synchronizes internal system clocks with an authoritative source to generate time stamps for audit records.&lt;br /&gt;
|-&lt;br /&gt;
| [a] internal system clocks are used to generate time stamps for audit records. || Screen Share || Screen share showing the NTP settings of a windows, Unix, Linux device; a screen share showing the NTP settings of network appliances.&lt;br /&gt;
|-&lt;br /&gt;
| [b] an authoritative source with which to compare and synchronize internal system clocks is specified. || Document || SSP or policy indicating that devices need to be synched to a local authoritative time device that is synched with an authoritative time service.&lt;br /&gt;
|-&lt;br /&gt;
| [c] internal system clocks used to generate time stamps for audit records are compared to and synchronized with the specified authoritative time source. || Screen Share || Screen share showing device logging appliance time is point to the appropriate authoritative time server.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AU.L2-3.3.8 – Audit Protection ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AU.L2-3.3.8_Details|&#039;&#039;&#039;AU.L2-3.3.8&#039;&#039;&#039;]] Protect audit information and audit logging tools from unauthorized access, modification, and deletion.&lt;br /&gt;
|-&lt;br /&gt;
| [a] audit information is protected from unauthorized access. || Screen Share || Screen share showing operating system permissions on the audit folders being restricted to appropriate users.&lt;br /&gt;
|-&lt;br /&gt;
| [b] audit information is protected from unauthorized modification. || Screen Share || Screen share showing operating system permissions on the audit folders being restricted to appropriate users.&lt;br /&gt;
|-&lt;br /&gt;
| [c] audit information is protected from unauthorized deletion. || Screen Share || Screen share showing operating system permissions on the audit folders being restricted to appropriate users.&lt;br /&gt;
|-&lt;br /&gt;
| [d] audit logging tools are protected from unauthorized access. || Screen Share || Artifact showing access permissions in the SIEM tool.&lt;br /&gt;
|-&lt;br /&gt;
| [e] audit logging tools are protected from unauthorized modification. || Screen Share || Artifact showing update permissions in the SIEM tool.&lt;br /&gt;
|-&lt;br /&gt;
| [f] audit logging tools are protected from unauthorized deletion. || Screen Share || Artifact showing delete permissions in the SIEM tool.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AU.L2-3.3.9 – Audit Management ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AU.L2-3.3.9_Details|&#039;&#039;&#039;AU.L2-3.3.9&#039;&#039;&#039;]] Limit management of audit logging functionality to a subset of privileged users.&lt;br /&gt;
|-&lt;br /&gt;
| [a] a subset of privileged users granted access to manage audit logging functionality is defined. || Document || SSP or policy indicating which users or groups have access to audit logs.&lt;br /&gt;
|-&lt;br /&gt;
| [b] management of audit logging functionality is limited to the defined subset of privileged users. || Screen Share || Artifact showing SIEM or OS folder permissions (this should be limited to the assigned users or groups); artifact showing an ACL setting in SIEM tool in regards to logs.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Configuration Management (CM) ==&lt;br /&gt;
=== CM.L2-3.4.1 – System Baselining ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_CM.L2-3.4.1_Details|&#039;&#039;&#039;CM.L2-3.4.1&#039;&#039;&#039;]] Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles.&lt;br /&gt;
|-&lt;br /&gt;
| [a] a baseline configuration is established. || Document || Documentation showing or explaining standard imaging process (how standard images are deployed and where  they are stored).&lt;br /&gt;
|-&lt;br /&gt;
| [b] the baseline configuration includes hardware, software, firmware, and documentation. || Artifact || Screenshot of repository of where images are maintained and information relating to hardware, software, and firmware.&lt;br /&gt;
|-&lt;br /&gt;
| [c] the baseline configuration is maintained (reviewed and updated) throughout the system development life cycle. || Artifact || Screenshot/evidence displaying management of baseline configurations (how often they are being managed as stated).&lt;br /&gt;
|-&lt;br /&gt;
| [d] a system inventory is established. || Document || Screenshot/evidence displaying inventory listing of approved products for use.&lt;br /&gt;
|-&lt;br /&gt;
| [e] the system inventory includes hardware, software, firmware, and documentation. || Artifact || Screeenshot/evidence displaying inventory listing of approved products and versions permitted for use.&lt;br /&gt;
|-&lt;br /&gt;
| [f] the inventory is maintained (reviewed and updated) throughout the system development life cycle. || Artifact || Screeenshot/evidence displaying management of baseline configurations (How often and are they being managed as stated.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== CM.L2-3.4.2 – Security Configuration Enforcement ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_CM.L2-3.4.2_Details|&#039;&#039;&#039;CM.L2-3.4.2&#039;&#039;&#039;]] Establish and enforce security configuration settings for information technology products employed in organizational systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] security configuration settings for information technology products employed in the system are established and included in the baseline configuration. || Document || Documentation explaining methodology used by organization to create secure baselines (STIGs, benchmarks).&lt;br /&gt;
|-&lt;br /&gt;
| [b] security configuration settings for information technology products employed in the system are enforced. || Artifact || Evidence of tool/s used to enforce security configurations to ensure images used are free from modification unless authorized.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== CM.L2-3.4.3 – System Change Management ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_CM.L2-3.4.3_Details|&#039;&#039;&#039;CM.L2-3.4.3&#039;&#039;&#039;]] Track, review, approve or disapprove, and log changes to organizational systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] changes to the system are tracked. || Artifact || Evidence of IT Service Management tool / process used to track system changes.&lt;br /&gt;
|-&lt;br /&gt;
| [b] changes to the system are reviewed. || Artifact || Evidence of IT Service Management tool / process used to review system changes.&lt;br /&gt;
|-&lt;br /&gt;
| [c] changes to the system are approved or disapproved. || Artifact || Evidence of IT Service Management tool / process used to approve/disapprove system changes.&lt;br /&gt;
|-&lt;br /&gt;
| [d] changes to the system are logged. || Artifact || Evidence of IT Service Management tool / process used to log system changes.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== CM.L2-3.4.4 – Security Impact Analysis ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_CM.L2-3.4.4_Details|&#039;&#039;&#039;CM.L2-3.4.4&#039;&#039;&#039;]] Analyze the security impact of changes prior to implementation.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the security impact of changes to the system is analyzed prior to implementation. || Artifact || Document explaining that security impact analysis of proposed changes to a system is conducted prior to implementation.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== CM.L2-3.4.5 – Access Restrictions for Change ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_CM.L2-3.4.5_Details|&#039;&#039;&#039;CM.L2-3.4.5&#039;&#039;&#039;]] Define, document, approve, and enforce physical and logical access restrictions associated with changes to organizational systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] physical access restrictions associated with changes to the system are defined. || Document || Document explaining the process of how physical access restrictions are defined for an individuals ability to make system changes.&lt;br /&gt;
|-&lt;br /&gt;
| [b] physical access restrictions associated with changes to the system are documented. || Document || Document explaining the process of how physical access restrictions are defined for an individuals ability to make system changes are documented; access request process.&lt;br /&gt;
|-&lt;br /&gt;
| [c] physical access restrictions associated with changes to the system are approved. || Artifact || Evidence of process of how physical access to systems are granted (i.e. physical access request sample).&lt;br /&gt;
|-&lt;br /&gt;
| [d] physical access restrictions associated with changes to the system are enforced. || Physical Review || Evidence of process of how physical access to systems are enforced (physical access system).&lt;br /&gt;
|-&lt;br /&gt;
| [e] logical access restrictions associated with changes to the system are defined. || Document || Document explaining the process of how logical access restrictions are defined for an individual&#039;s ability to make system changes.&lt;br /&gt;
|-&lt;br /&gt;
| [f] logical access restrictions associated with changes to the system are documented. || Document || Document explaining the process of how logical access restrictions are defined for an individual&#039;s ability to make system changes are documented.&lt;br /&gt;
|-&lt;br /&gt;
| [g] logical access restrictions associated with changes to the system are approved. || Artifact || Evidence of process of how logical access to systems are granted.&lt;br /&gt;
|-&lt;br /&gt;
| [h] logical access restrictions associated with changes to the system are enforced. || Artifact || Evidence of process of how logical access to systems are enforced.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== CM.L2-3.4.6 – Least Functionality ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_CM.L2-3.4.6_Details|&#039;&#039;&#039;CM.L2-3.4.6&#039;&#039;&#039;]] Employ the principle of least functionality by configuring organizational systems to provide only essential capabilities.&lt;br /&gt;
|-&lt;br /&gt;
| [a] essential system capabilities are defined based on the principle of least functionality. || Document || Documentation explaining how systems are configured to utilize the principle of least functionality for designated users.&lt;br /&gt;
|-&lt;br /&gt;
| [b] the system is configured to provide only the defined essential capabilities. || Screen Share || Evidence displaying how systems are configured to utilize the principle of least functionality for designated users; disabled service settings, accepted standards for hardening (CIS benchmarks, etc.).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== CM.L2-3.4.7 – Nonessential Functionality ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_CM.L2-3.4.7_Details|&#039;&#039;&#039;CM.L2-3.4.7&#039;&#039;&#039;]] Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services.&lt;br /&gt;
|-&lt;br /&gt;
| [a] essential programs are defined. || Document || Documented essential programs specified; build documents; software center; SSP.&lt;br /&gt;
|-&lt;br /&gt;
| [b] the use of nonessential programs is defined. || Document || Documented listing of nonessential programs (whatever is NOT specified in [a]); AUP/User Agreement may identify nonessential use/programs.&lt;br /&gt;
|-&lt;br /&gt;
| [c] the use of nonessential programs is restricted, disabled, or prevented as defined. || Screen Share || Tool used to restrict nonessential programs displays restrictions as defined (McAfee ePO settings, Carbon Black rules, etc.).&lt;br /&gt;
|-&lt;br /&gt;
| [d] essential functions are defined. || Document || Documented essential functions are specified.&lt;br /&gt;
|-&lt;br /&gt;
| [e] the use of nonessential functions is defined. || Document || Documented nonessential functions are specified.&lt;br /&gt;
|-&lt;br /&gt;
| [f] the use of nonessential functions is restricted, disabled, or prevented as defined. || Screen Share || Tool used to restrict essential/nonessential functions displays restrictions as defined.&lt;br /&gt;
|-&lt;br /&gt;
| [g] essential ports are defined. || Document || Documented essential ports are specified.&lt;br /&gt;
|-&lt;br /&gt;
| [h] the use of nonessential ports is defined. || Document || Documented nonessential ports functions are specified.&lt;br /&gt;
|-&lt;br /&gt;
| [i] the use of nonessential ports is restricted, disabled, or prevented as defined. || Screen Share || Tool used to restrict essential/nonessential ports displays restrictions as defined (FW rules; McAfee; GPO, etc.).&lt;br /&gt;
|-&lt;br /&gt;
| [j] essential protocols are defined. || Document || Documented essential protocols are specified.&lt;br /&gt;
|-&lt;br /&gt;
| [k] the use of nonessential protocols is defined. || Document || Documented nonessential protocols functions are specified.&lt;br /&gt;
|-&lt;br /&gt;
| [l] the use of nonessential protocols is restricted, disabled, or prevented as defined. || Screen Share || Tool used to restrict essential/nonessential protocols displays restrictions as defined (FW rules; GPO, etc.).&lt;br /&gt;
|-&lt;br /&gt;
| [m] essential services are defined. || Document || Documented essential services specified.&lt;br /&gt;
|-&lt;br /&gt;
| [n] the use of nonessential services is defined. || Document || Documented nonessential services functions are specified.&lt;br /&gt;
|-&lt;br /&gt;
| [o] the use of nonessential services is restricted, disabled, or prevented as defined. || Screen Share || Tool used to restrict essential/nonessential services displays restrictions as defined.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== CM.L2-3.4.8 – Application Execution Policy ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_CM.L2-3.4.8_Details|&#039;&#039;&#039;CM.L2-3.4.8&#039;&#039;&#039;]] Apply deny-by-exception (blacklisting) policy to prevent the use of unauthorized software or deny-all, permit-by-exception (whitelisting) policy to allow the execution of authorized software.&lt;br /&gt;
|-&lt;br /&gt;
| [a] a policy specifying whether whitelisting or blacklisting is to be implemented is specified. || Document || Documentation explaining whitelisting or blacklisting process.&lt;br /&gt;
|-&lt;br /&gt;
| [b] the software allowed to execute under whitelisting or denied use under blacklisting is specified. || Document || Documentation explaining whitelisting or blacklisting process for software.&lt;br /&gt;
|-&lt;br /&gt;
| [c] whitelisting to allow the execution of authorized software or blacklisting to prevent the use of unauthorized software is implemented as specified. || Screen Share || Tool used for whitelisting or blacklisting for software shows capability of restricting/authorizing software (Carbon Black dashboard, &amp;quot;SW Store&amp;quot;, web proxies, DNS Blackhole, etc.).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== CM.L2-3.4.9 – User-Installed Software ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_CM.L2-3.4.9_Details|&#039;&#039;&#039;CM.L2-3.4.9&#039;&#039;&#039;]] Control and monitor user-installed software.&lt;br /&gt;
|-&lt;br /&gt;
| [a] a policy for controlling the installation of software by users is established. || Document || Documented software authorization process or methodology for approval.&lt;br /&gt;
|-&lt;br /&gt;
| [b] installation of software by users is controlled based on the established policy. || Screen Share || Evidence that approval/restriction in installation of software by authorized personnel is implemented as specified (AUP, GPO, etc.).&lt;br /&gt;
|-&lt;br /&gt;
| [c] installation of software by users is monitored. || Screen Share || Evidence that installation of software by authorized personnel is monitored (SCCM groups, SW Center, etc.).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Identification and Authentication (IA) ==&lt;br /&gt;
=== IA.L2-3.5.1 – Identification [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IA.L2-3.5.1_Details|&#039;&#039;&#039;IA.L2-3.5.1&#039;&#039;&#039;]] Identify information system users, processes acting on behalf of users, or devices.&lt;br /&gt;
|-&lt;br /&gt;
| [a] system users are identified. || Document || Based on what is defined in their documentation (SSP, AUP, Policy, SOP), request to see a sample of non-privileged/privileged users in AD OU group (overlaps with 3.1.1 and 3.1.5).&lt;br /&gt;
|-&lt;br /&gt;
| [b] processes acting on behalf of users are identified. || Screen Share || Based on what is defined in their documentation (SSP, AUP, Policy, SOP), request to see a sample of service accounts in AD OU group (overlaps with 3.1.1 and 3.1.5).&lt;br /&gt;
|-&lt;br /&gt;
| [c] devices accessing the system are identified. || Screen Share || Based on what is defined in their documentation (SSP, AUP, Policy, SOP), request to see a sample of domain-joined workstation &amp;amp; servers in AD OU group (overlaps with 3.1.1 and 3.1.5).  For network devices, request screen share/artifact to show how they are identified on the enterprise network.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IA.L2-3.5.2 – Authentication [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IA.L2-3.5.2_Details|&#039;&#039;&#039;IA.L2-3.5.2&#039;&#039;&#039;]] Authenticate (or verify) the identities of those users, processes, or devices, as a prerequisite to allowing access to organizational information systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the identity of each user is authenticated or verified as a prerequisite to system access. || Screen Share || If the user logs in with non-privileged account during other demoes and then a privileged account, then this should be satisfied.  If screen share is unavailable, request logs to show successful and unsuccessful login by privileged and non-privilged users.&lt;br /&gt;
|-&lt;br /&gt;
| [b] the identity of each process acting on behalf of a user is authenticated or verified as a prerequisite to system access. || Screen Share || Request a log that shows successful/unsuccessful service account trying to log on to company&#039;s asset.&lt;br /&gt;
|-&lt;br /&gt;
| [c] the identity of each device accessing or connecting to the system is authenticated or verified as a prerequisite to system access. || Screen Share || Request a log that shows domain-joined workstation/server authenticating to AD (focus on the MAC/IP address/hostname).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IA.L2-3.5.3 – Multifactor Authentication ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IA.L2-3.5.3_Details|&#039;&#039;&#039;IA.L2-3.5.3&#039;&#039;&#039;]] Use multifactor authentication for local and network access to privileged accounts and for network access to non-privileged accounts.&lt;br /&gt;
|-&lt;br /&gt;
| [a] privileged accounts are identified. || Screen Share|| Based on what is defined in their documentation, request to see a sample of privileged users in AD OU group.  Overlaps with 3.1.5.  Screenshot/screen share to show implementation is enforced.&lt;br /&gt;
|-&lt;br /&gt;
| [b] multifactor authentication is implemented for local access to privileged accounts. || Document || SSP, AUP, Policy, SOP that defines that MFA is needed for privileged local access.&lt;br /&gt;
|-&lt;br /&gt;
| [c] multifactor authentication is implemented for network access to privileged accounts. || Screen Share || Within the MFA implementation mechanism, show that privileged users are forced to use MFA;  Screenshot/Screen share to show implementation is enforced.&lt;br /&gt;
|-&lt;br /&gt;
| [d] multifactor authentication is implemented for network access to non-privileged accounts. || Screen Share || Within the MFA implementation mechanism, show that non-privileged users are forced to use MFA; Screenshot/Screen share to show implementation is enforced.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IA.L2-3.5.4 – Replay-Resistant Authentication ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IA.L2-3.5.4_Details|&#039;&#039;&#039;IA.L2-3.5.4&#039;&#039;&#039;]] Employ replay-resistant authentication mechanisms for network access to privileged and non-privileged accounts.&lt;br /&gt;
|-&lt;br /&gt;
| [a] replay-resistant authentication mechanisms are implemented for network account access to privileged and non-privileged accounts. || Screen Share || Show the GPO setting that enforces Kerberos within AD.  If MFA is used, show the implementation to enforce replay resistant techniques.  For non-windows, show the technical solution to enforce replay resistant attacks.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IA.L2-3.5.5 – Identifier Reuse ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IA.L2-3.5.5_Details|&#039;&#039;&#039;IA.L2-3.5.5&#039;&#039;&#039;]] Prevent reuse of identifiers for a defined period.&lt;br /&gt;
|-&lt;br /&gt;
| [a] a period within which identifiers cannot be reused is defined. || Document || SSP, policies, or SOP that defines identifier reuse.&lt;br /&gt;
|-&lt;br /&gt;
| [b] reuse of identifiers is prevented within the defined period. || Screen Share || Show the GPO setting/technical solution that enforces what is defined in policy/documentation (this can be automated or manual process; screen share/artifacts can be presented to satisfy this requirement.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IA.L2-3.5.6 – Identifier Handling ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IA.L2-3.5.6_Details|&#039;&#039;&#039;IA.L2-3.5.6&#039;&#039;&#039;]] Disable identifiers after a defined period of inactivity.&lt;br /&gt;
|-&lt;br /&gt;
| [a] a period of inactivity after which an identifier is disabled is defined. || Document || SSP, policy that defines the period of inactivity after which an identifier is disabled.&lt;br /&gt;
|-&lt;br /&gt;
| [b] identifiers are disabled after the defined period of inactivity. || Screen Share || Screen share AD or similar tool supporting directory-based identity-related services for disabled accounts (can be done by hand or script).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IA.L2-3.5.7 – Password Complexity ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IA.L2-3.5.7_Details|&#039;&#039;&#039;IA.L2-3.5.7&#039;&#039;&#039;]] Enforce a minimum password complexity and change of characters when new passwords are created.&lt;br /&gt;
|-&lt;br /&gt;
| [a] password complexity requirements are defined. || Document || SSP, policy that defines password complexity requirements.&lt;br /&gt;
|-&lt;br /&gt;
| [b] password change of character requirements are defined. || Document || SSP, policy that defines change of character requirements are defined.&lt;br /&gt;
|-&lt;br /&gt;
| [c] minimum password complexity requirements as defined are enforced when new passwords are created. || Screen Share || Screen share of AD or similar directory-based identity-related service tool to show complexity requirements.&lt;br /&gt;
|-&lt;br /&gt;
| [d] minimum password change of character requirements as defined are enforced when new passwords are created. || Screen Share || Screen share of Group Policy configuration or similar tool providing centralized management and configuration of operating systems, applications, and users&#039; settings to show that characters must be changed.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IA.L2-3.5.8 – Password Reuse ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IA.L2-3.5.8_Details|&#039;&#039;&#039;IA.L2-3.5.8&#039;&#039;&#039;]] Prohibit password reuse for a specified number of generations.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the number of generations during which a password cannot be reused is specified. || Document || SSP, policy that specifies the number of generations during which a password cannot be reused is specified.&lt;br /&gt;
|-&lt;br /&gt;
| [b] reuse of passwords is prohibited during the specified number of generations. || Screen Share || Screen share Group Policy or similar tool providing centralized management and configuration of operating systems, applications, and users&#039; settings in a directory-based identity-related service tool&#039;s configuration to show reuse of passwords is prohibited.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IA.L2-3.5.9 – Temporary Passwords ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IA.L2-3.5.9_Details|&#039;&#039;&#039;IA.L2-3.5.9&#039;&#039;&#039;]] Allow temporary password use for system logons with an immediate change to a permanent password.&lt;br /&gt;
|-&lt;br /&gt;
| [a] an immediate change to a permanent password is required when a temporary password is used for system logon. || Screen Share || Screen share of Group Policy or similar tool providing centralized management and configuration of operating systems, applications, and users&#039; settings in a directory-based identity-related service tool&#039;s configuration to show &amp;quot;change password at first logon.&amp;quot;&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IA.L2-3.5.10 – Cryptographically-Protected Passwords ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IA.L2-3.5.1_Details|&#039;&#039;&#039;IA.L2-3.5.1&#039;&#039;&#039;]] Store and transmit only cryptographically-protected passwords.&lt;br /&gt;
|-&lt;br /&gt;
| [a] passwords are cryptographically protected in storage. || Screen Share || Screen share Group Policy or similar tool providing centralized management and configuration of operating systems, applications, and users&#039; settings in a directory-based identity-related service tool&#039;s configuration that Kerberos, or a similar network authentication protocol that works on the basis of tickets to allow nodes communicating over a non-secure network to prove their identity to one another in a secure manner, is enabled.&lt;br /&gt;
|-&lt;br /&gt;
| [b] passwords are cryptographically protected in transit. || Screen Share || Screen share Group Policy or similar tool providing centralized management and configuration of operating systems, applications, and users&#039; settings in a directory-based identity-related service tool&#039;s configuration that Kerberos, or a similar network authentication protocol that works on the basis of tickets to allow nodes communicating over a non-secure network to prove their identity to one another in a secure manner, is enabled.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IA.L2-3.5.11 – Obscure Feedback ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IA.L2-3.5.10_Details|&#039;&#039;&#039;IA.L2-3.5.10&#039;&#039;&#039;]] Obscure feedback of authentication information.&lt;br /&gt;
|-&lt;br /&gt;
| [a] authentication information is obscured during the authentication process. || Screen Share || Screen share of Group Policy or similar tool providing centralized management and configuration of operating systems, applications, and users&#039; settings in a directory-based identity-related service tool&#039;s configuration to show that passwords are obscured.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Incident Response (IR) ==&lt;br /&gt;
=== IR.L2-3.6.1 – Incident Handling ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IR.L2-3.6.1_Details|&#039;&#039;&#039;IR.L2-3.6.1&#039;&#039;&#039;]] Establish an operational incident-handling capability for organizational systems that includes preparation, detection, analysis, containment, recovery, and user response activities.&lt;br /&gt;
|-&lt;br /&gt;
| [a] an operational incident-handling capability is established. || Document || Incident Response SOP/Plan.&lt;br /&gt;
|-&lt;br /&gt;
| [b] the operational incident-handling capability includes preparation. || Document || Incident Response SOP/Plan, prior incident report, training, COOP plan.&lt;br /&gt;
|-&lt;br /&gt;
| [c] the operational incident-handling capability includes detection. || Document || Incident Response SOP/Plan; definition of tools used to detect; artifacts showing tools used; prior incident report.&lt;br /&gt;
|-&lt;br /&gt;
| [d] the operational incident-handling capability includes analysis. || Document || Incident Response SOP/Plan; Definition of tools used to analyze potential incidents; artifacts showing tools used for analysis; prior incident report.&lt;br /&gt;
|-&lt;br /&gt;
| [e] the operational incident-handling capability includes containment. || Document || Incident Response SOP/Plan; isolation/quarantine process; user training.&lt;br /&gt;
|-&lt;br /&gt;
| [f] the operational incident-handling capability includes recovery. || Document || Incident Response SOP/Plan; COOP Plan; prior incident reports, re-baselining impacted devices.&lt;br /&gt;
|-&lt;br /&gt;
| [g] the operational incident-handling capability includes user response. || Document || Incident Response SOP/Plan; user awareness training; Help Desk process.&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IR.L2-3.6.2 – Incident Reporting ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IR.L2-3.6.2_Details|&#039;&#039;&#039;IR.L2-3.6.2&#039;&#039;&#039;]] Track, document, and report incidents to designated officials and/or authorities both internal and external to the organization.&lt;br /&gt;
|-&lt;br /&gt;
| [a] incidents are tracked. || Artifact || Incident Response SOP/Plan; ITSM artifact; technical implementation for incident tracking.&lt;br /&gt;
|-&lt;br /&gt;
| [b] incidents are documented. || Artifact || Incident Response SOP/Plan; ITSM artifact; technical implementation for incident tracking.&lt;br /&gt;
|-&lt;br /&gt;
| [c] authorities to whom incidents are to be reported are identified. || Document || Incident Response SOP/Plan.&lt;br /&gt;
|-&lt;br /&gt;
| [d] organizational officials to whom incidents are to be reported are identified. || Document || Incident Response SOP/Plan.&lt;br /&gt;
|-&lt;br /&gt;
| [e] identified authorities are notified of incidents. || Screen Share || Prior incident report; DIBNET login; prior email notifications.&lt;br /&gt;
|-&lt;br /&gt;
| [f] identified organizational officials are notified of incidents. || Artifact || Prior incident report; prior email notifications; tabletop exercises.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IR.L2-3.6.3 – Incident Response Testing ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IR.L2-3.6.3_Details|&#039;&#039;&#039;IR.L2-3.6.3&#039;&#039;&#039;]] Test the organizational incident response capability.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the incident response capability is tested. || Artifact || Incident response table top/scheduled or unscheduled test or penetration test.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Maintenance (MA) ==&lt;br /&gt;
=== MA.L2-3.7.1 – Perform Maintenance ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MA.L2-3.7.1_Details|&#039;&#039;&#039;MA.L2-3.7.1&#039;&#039;&#039;]] Perform maintenance on organizational systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] system maintenance is performed. || Artifact || Establish typical maintenance activities (HVAC, UPS, power distribution, generators, copier maintenance) that are performed; maintenance agreements or contracts detailing these types of activities are acceptable; interview responses should be considered.  This requirement should not be confused with 3.14.1 - report, remediate, and correct system flaws in a timely manner (patch management).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MA.L2-3.7.2 – System Maintenance Control ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MA.L2-3.7.2_Details|&#039;&#039;&#039;MA.L2-3.7.2&#039;&#039;&#039;]] Provide controls on the tools, techniques, mechanisms, and personnel used to conduct system maintenance.&lt;br /&gt;
|-&lt;br /&gt;
| [a] tools used to conduct system maintenance are controlled. || Artifact || Tools may largely depend on the assessed environment; discussion examples include network diagnostic and monitoring tools (including hardware and software); artifacts could demonstrate secured locations/areas for these tools (photos) or checkout sheets/rosters (documents) depicting responsible personnel and the dates/times of checkout.&lt;br /&gt;
|-&lt;br /&gt;
| [b] techniques used to conduct system maintenance are controlled. || Artifact || Processes for scheduling, performing, documenting, reviewing, approving, and monitoring maintenance and repairs for the information system.&lt;br /&gt;
|-&lt;br /&gt;
| [c] mechanisms used to conduct system maintenance are controlled. || Artifact || Processes for scheduling, performing, documenting, reviewing, approving, and monitoring maintenance and repairs for the information system.&lt;br /&gt;
|-&lt;br /&gt;
| [d] personnel used to conduct system maintenance are controlled. || Physical Review || Screenshot of who is authorized to conduct maintenance; maintenance personnel training program.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MA.L2-3.7.3 – Equipment Sanitization ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MA.L2-3.7.3_Details|&#039;&#039;&#039;MA.L2-3.7.3&#039;&#039;&#039;]] Ensure equipment removed for off-site maintenance is sanitized of any CUI.&lt;br /&gt;
|-&lt;br /&gt;
| [a] equipment to be removed from organizational spaces for off-site maintenance is sanitized of any CUI. || Artifact || Document or artifact; record if equipment sanitized; categories of sanitization/destruction defined; sanitization procedural document.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MA.L2-3.7.4 – Media Inspection ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MA.L2-3.7.4_Details|&#039;&#039;&#039;MA.L2-3.7.4&#039;&#039;&#039;]] Check media containing diagnostic and test programs for malicious code before the media are used in organizational systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] media containing diagnostic and test programs are checked for malicious code before being used in organizational systems that process, store, or transmit CUI. || Artifact || Screenshot of diagnostic/test program being used (such as Symantec and McAfee on access scans…).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MA.L2-3.7.5 – Nonlocal Maintenance ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MA.L2-3.7.5_Details|&#039;&#039;&#039;MA.L2-3.7.5&#039;&#039;&#039;]] Require multifactor authentication to establish nonlocal maintenance sessions via external network connections and terminate such connections when nonlocal maintenance is complete.&lt;br /&gt;
|-&lt;br /&gt;
| [a] multifactor authentication is used to establish nonlocal maintenance sessions via external network connections. || Screen Share || Describe MFA used to remote from external service to organizational systems for maintenance and screenshot of MFA (3.5.3)(points associated with admin).&lt;br /&gt;
|-&lt;br /&gt;
| [b] nonlocal maintenance sessions established via external network connections are terminated when nonlocal maintenance is complete. || Screen Share || Screenshot VPN session timeout.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MA.L2-3.7.6 – Maintenance Personnel ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MA.L2-3.7.6_Details|&#039;&#039;&#039;MA.L2-3.7.6&#039;&#039;&#039;]] Supervise the maintenance activities of maintenance personnel without required access authorization.&lt;br /&gt;
|-&lt;br /&gt;
| [a] maintenance personnel without required access authorization are supervised during maintenance activities. || Document || System maintenance policy; list of authorized personnel; maintenance records or, contracts/SLAs; WebEx.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Media Protection (MP) ==&lt;br /&gt;
=== MP.L2-3.8.1 – Media Protection ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MP.L2-3.8.1_Details|&#039;&#039;&#039;MP.L2-3.8.1&#039;&#039;&#039;]] Protect (i.e., physically control and securely store) system media containing CUI, both paper and digital.&lt;br /&gt;
|-&lt;br /&gt;
| [a] paper media containing CUI is physically controlled. || Document || Policy showing CUI paper media is controlled; artifact showing who has access; artifacts/records of  inventories conducted; media check out procedures (i.e. file cabinets, encryption, password protection).&lt;br /&gt;
|-&lt;br /&gt;
| [b] digital media containing CUI is physically controlled. || Document || Policy showing CUI digital media is controlled; artifact showing who has access; artifacts/records of inventories conducted; media check out procedures (i.e. file cabinets, external drives, USBs, encryption, password protection).&lt;br /&gt;
|-&lt;br /&gt;
| [c] paper media containing CUI is securely stored. || Physical Review || Check out/sign out sheets; possible photo of storage container/video walk through of storage area; badge reader logs or access lists for keys for secured areas; interview response considered (i.e. file cabinets,  encryption, password protection).&lt;br /&gt;
|-&lt;br /&gt;
| [d] digital media containing CUI is securely stored. || Physical Review || Check out/sign out sheets; possible photo of storage container/video walk through of storage area; badge reader logs or access lists for keys for secured areas; interview response considered (i.e. file cabinets, external drives, USBs, encryption, password protection).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MP.L2-3.8.2 – Media Access ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MP.L2-3.8.2_Details|&#039;&#039;&#039;MP.L2-3.8.2&#039;&#039;&#039;]] Limit access to CUI on system media to authorized users.&lt;br /&gt;
|-&lt;br /&gt;
| [a] access to CUI on system media is limited to authorized users. || Artifact || Document describing how CUI is limited AND artifact showing principle of least access is implemented.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MP.L2-3.8.3 – Media Disposal [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MP.L2-3.8.3_Details|&#039;&#039;&#039;MP.L2-3.8.3&#039;&#039;&#039;]] Sanitize or destroy information system media containing Federal Contract Information before disposal or release for reuse.&lt;br /&gt;
|-&lt;br /&gt;
| [a] system media containing CUI is sanitized or destroyed before disposal. || Document || Policy or artifact of media destruction logs; certificates of destruction; SLAs or contracts.&lt;br /&gt;
|-&lt;br /&gt;
| [b] system media containing CUI is sanitized before it is released for reuse. || Document || Policy or artifact describing method to sanitize, software used (i.e. DoD Wipe, ShredIT and Iron Mountain; Blancco; GDisk, DBAN).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MP.L2-3.8.4 – Media Markings ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MP.L2-3.8.4_Details|&#039;&#039;&#039;MP.L2-3.8.4&#039;&#039;&#039;]] Mark media with necessary CUI markings and distribution limitations.&lt;br /&gt;
|-&lt;br /&gt;
| [a] media containing CUI is marked with applicable CUI markings. || Physical Review || Document or artifact showing CUI markings (i.e. labeling standards ).&lt;br /&gt;
|-&lt;br /&gt;
| [b] media containing CUI is marked with distribution limitations. || Physical Review || Document or artifact showing distro limitations (i.e. labeling standards ).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MP.L2-3.8.5 – Media Accountability ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MP.L2-3.8.5_Details|&#039;&#039;&#039;MP.L2-3.8.5&#039;&#039;&#039;]] Control access to media containing CUI and maintain accountability for media during transport outside of controlled areas.&lt;br /&gt;
|-&lt;br /&gt;
| [a] access to media containing CUI is controlled. || Document || Policy, artifact of audit logs showing tracking, Access Control Lists, records of transport activities (i.e. USB drives, CDs, chain of custody.&lt;br /&gt;
|-&lt;br /&gt;
| [b] accountability for media containing CUI is maintained during transport outside of controlled areas. || Artifact || Artifact of audit logs showing tracking, Access Control Lists, records of transport activities (i.e. USB drives, CDs; chain of custody.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MP.L2-3.8.6 – Portable Storage Encryption ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MP.L2-3.8.6_Details|&#039;&#039;&#039;MP.L2-3.8.6&#039;&#039;&#039;]] Implement cryptographic mechanisms to protect the confidentiality of CUI stored on digital media during transport unless otherwise protected by alternative physical safeguards.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the confidentiality of CUI stored on digital media is protected during transport using cryptographic mechanisms or alternative physical safeguards. || Artifact || Artifact showing crypto mechanisms used to protect (are they FIPS 140-2 [13.11]); artifact showing what alternative physical safeguards are in place (i.e. encryption; BitLocker; McAfee ).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MP.L2-3.8.7 – Removable Media ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MP.L2-3.8.7_Details|&#039;&#039;&#039;MP.L2-3.8.7&#039;&#039;&#039;]] Control the use of removable media on system components.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the use of removable media on system components is controlled. || Artifact || Policy showing if removable media is allowed; writable removable media is restricted; tracking artifacts; what tools are used (i.e. Carbon Black, Crowd Strike, GPO, Zoho Desktop Central); procedure/process describing what happens if it is lost; what mechanisms are in place to control/restrict removable media (i.e. Active Directory Groups and Group Policy artifact showing restriction).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MP.L2-3.8.8 – Shared Media ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MP.L2-3.8.8_Details|&#039;&#039;&#039;MP.L2-3.8.8&#039;&#039;&#039;]] Prohibit the use of portable storage devices when such devices have no identifiable owner.ASSESSMENT OBJECTIVES&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [a] the use of portable storage devices is prohibited when such devices have no identifiable owner. || Artifact || Policy and/or artifact showing company stance on portable storage devices if there is no owner (are personal USB devices allowed or are they company-issued; artifact showing alerts if device is connected to network (i.e. external HDD, Carbon Black, Crowd Strike, GPO, Zoho Desktop Central.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MP.L2-3.8.9 – Protect Backups ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MP.L2-3.8.9_Details|&#039;&#039;&#039;MP.L2-3.8.9&#039;&#039;&#039;]] Protect the confidentiality of backup CUI at storage locations.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the confidentiality of backup CUI is protected at storage locations. || Artifact || Policy on system backups; artifact showing media labeling; artifact showing encyption (is it FIPS 140-2 [13.11]); Access Control List artifact (i.e. backup tapes, Tivoli Storage Manager).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Personnel Security (PS) ==&lt;br /&gt;
=== PS.L2-3.9.1 – Screen Individuals ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_PS.L2-3.9.1_Details|&#039;&#039;&#039;PS.L2-3.9.1&#039;&#039;&#039;]] Screen individuals prior to authorizing access to organizational systems containing CUI.&lt;br /&gt;
|-&lt;br /&gt;
| [a] individuals are screened prior to authorizing access to organizational systems containing CUI. || Artifact || Screenshot of records of screened personnel/background checks.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== PS.L2-3.9.2 – Personnel Actions ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_PS.L2-3.9.2_Details|&#039;&#039;&#039;PS.L2-3.9.2&#039;&#039;&#039;]] Ensure that organizational systems containing CUI are protected during and after personnel actions such as terminations and transfers.&lt;br /&gt;
|-&lt;br /&gt;
| [a] a policy and/or process for terminating system access and any credentials coincident with personnel actions is established. || Document || Personnel security policy/procedures/instruction; Access control policy/procedure/instruction.&lt;br /&gt;
|-&lt;br /&gt;
| [b] system access and credentials are terminated consistent with personnel actions such as termination or transfer. || Artifact || Screenshot of records of personnel transfer and termination actions.&lt;br /&gt;
|-&lt;br /&gt;
| [c] the system is protected during and after personnel transfer actions. || Artifact || Completed outprocessing checklist.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Physical Protection (PE) ==&lt;br /&gt;
=== PE.L2-3.10.1 – Limit Physical Access [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_PE.L2-3.10.1_Details|&#039;&#039;&#039;PE.L2-3.10.1&#039;&#039;&#039;]] Limit physical access to organizational information systems, equipment, and the respective operating environments to authorized individuals.&lt;br /&gt;
|-&lt;br /&gt;
| [a] authorized individuals allowed physical access are identified. || Artifact || Authorized personnel (names) access list.&lt;br /&gt;
|-&lt;br /&gt;
| [b] physical access to organizational systems is limited to authorized individuals. || Physical Review || Badge reader logs, audit logs, and/or card swipe test.&lt;br /&gt;
|-&lt;br /&gt;
| [c] physical access to equipment is limited to authorized individuals. || Physical Review || Badge reader logs, audit logs, and/or card swipe test.&lt;br /&gt;
|-&lt;br /&gt;
| [d] physical access to operating environments is limited to authorized. || Physical Review || Badge reader logs, audit logs, and/or card swipe test.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== PE.L2-3.10.2 – Monitor Facility ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_PE.L2-3.10.2_Details|&#039;&#039;&#039;PE.L2-3.10.2&#039;&#039;&#039;]] Protect and monitor the physical facility and support infrastructure for organizational systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the physical facility where organizational systems reside is protected. || Physical Review || Physical security measures and barriers into the physical facility (cameras/locks/gates/guards, etc.).&lt;br /&gt;
|-&lt;br /&gt;
| [b] the support infrastructure for organizational systems is protected. || Physical Review || Physical barriers to entries into computer spaces, server rooms, etc.&lt;br /&gt;
|-&lt;br /&gt;
| [c] the physical facility where organizational systems reside is monitored. || Physical Review || Audit logs/how the physical facility is being monitored (cameras/access system/guards, etc.).&lt;br /&gt;
|-&lt;br /&gt;
| [d] the support infrastructure for organizational systems is monitored. || Physical Review || Audit logs/how the physical facility is being monitored (cameras/access system/guards, etc.).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== PE.L2-3.10.3 – Escort Visitors [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_PE.L2-3.10.3_Details|&#039;&#039;&#039;PE.L2-3.10.3&#039;&#039;&#039;]] Escort visitors and monitor visitor activity.&lt;br /&gt;
|-&lt;br /&gt;
| [a] visitors are escorted. || Physical Review || Policy/procedures/instruction on methodology for handling non-authorized personnel (entry to exit).&lt;br /&gt;
|-&lt;br /&gt;
| [b] visitor activity is monitored. || Physical Review || Policy/procedures/instructio on methodology for handling non-authorized personnel (entry to exit).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== PE.L2-3.10.4 – Physical Access Logs [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_PE.L2-3.10.4_Details|&#039;&#039;&#039;PE.L2-3.10.4&#039;&#039;&#039;]] Maintain audit logs of physical access.&lt;br /&gt;
|-&lt;br /&gt;
| [a] audit logs of physical access are maintained. || Artifact || Log or report from badging system.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== PE.L2-3.10.5 – Manage Physical Access [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_PE.L2-3.10.5_Details|&#039;&#039;&#039;PE.L2-3.10.5&#039;&#039;&#039;]] Control and manage physical access devices.&lt;br /&gt;
|-&lt;br /&gt;
| [a] physical access devices are identified. || Document || Physical access control systems description, guard force contract/policy, key locks, logical systems specifications, etc.&lt;br /&gt;
|-&lt;br /&gt;
| [b] physical access devices are controlled. || Physical Review || Inventory records of physical access control devices (e.g. keys, locks, card readers, locks, etc.).&lt;br /&gt;
|-&lt;br /&gt;
| [c] physical access devices are managed. || Physical Review || List of security safeguards controlling access to the facility (e.g. cameras, monitoring by guards, isolation of IT systems equiment and or system components).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== PE.L2-3.10.6 – Alternative Work Sites ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_PE.L2-3.10.6_Details|&#039;&#039;&#039;PE.L2-3.10.6&#039;&#039;&#039;]] Enforce safeguarding measures for CUI at alternate work sites.&lt;br /&gt;
|-&lt;br /&gt;
| [a] safeguarding measures for CUI are defined for alternate work sites. || Document || Telework agreement, Acceptable Use Policy and SOP for alternate work locations; user security training validation which includes physical/logical/technical protections of system at alternate work sites.&lt;br /&gt;
|-&lt;br /&gt;
| [b] safeguarding measures for CUI are enforced for alternate work sites. || Artifact || Monitoring/audit log of user activity and logical/physical/technical mechanisms in place to preclude unauthorized activity (telework agreement , AUP?).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Risk Assessment (RA) ==&lt;br /&gt;
=== RA.L2-3.11.1 – Risk Assessments ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_RA.L2-3.11.1_Details|&#039;&#039;&#039;RA.L2-3.11.1&#039;&#039;&#039;]] Periodically assess the risk to organizational operations (including mission, functions, image, or reputation), organizational assets, and individuals, resulting from the operation of organizational systems and the associated processing, storage, or transmission of CUI.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the frequency to assess risk to organizational operations, organizational assets, and individuals is defined. || Document || Risk assessment policy.&lt;br /&gt;
|-&lt;br /&gt;
| [b] risk to organizational operations, organizational assets, and individuals resulting from the operation of an organizational system that processes, stores, or transmits CUI is assessed with the defined frequency. || Artifact || Copy of last risk assessment done within defined frequency.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== RA.L2-3.11.2 – Vulnerability Scan ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_RA.L2-3.11.2_Details|&#039;&#039;&#039;RA.L2-3.11.2&#039;&#039;&#039;]] Scan for vulnerabilities in organizational systems and applications periodically and when new vulnerabilities affecting those systems and applications are identified.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the frequency to scan for vulnerabilities in organizational systems and applications is defined. || Document || Policy/procedures/instruction addressing vulnerability scanning records.&lt;br /&gt;
|-&lt;br /&gt;
| [b] vulnerability scans are performed on organizational systems with the defined frequency. || Screen Share || System configuration settings of vulnerability scanning scheduling and vulnerability scan results of systems within defined frequency.&lt;br /&gt;
|-&lt;br /&gt;
| [c] vulnerability scans are performed on applications with the defined frequency. || Screen Share || System configuration settings of vulnerability scanning scheduling and vulnerability scan results of applications within defined frequency.&lt;br /&gt;
|-&lt;br /&gt;
| [d] vulnerability scans are performed on organizational systems when new vulnerabilities are identified. || Screen Share || View signatures in scanning tool/ad hoc scan performed as a result.&lt;br /&gt;
|-&lt;br /&gt;
| [e] vulnerability scans are performed on applications when new vulnerabilities are identified. || Screen Share || View signatures in scanning tool/ad hoc scan performed as a result.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== RA.L2-3.11.3 – Vulnerability Remediation ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_RA.L2-3.11.3_Details|&#039;&#039;&#039;RA.L2-3.11.3&#039;&#039;&#039;]] Remediate vulnerabilities in accordance with risk assessments.&lt;br /&gt;
|-&lt;br /&gt;
| [a] vulnerabilities are identified. || Artifact || Scan results showing vulnerabilities identified.&lt;br /&gt;
|-&lt;br /&gt;
| [b] vulnerabilities are remediated in accordance with risk assessments. || Artifact || Screenshot/document of scan results of remediated vulnerabilities in accordance to risk assessments.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Security Assessment (CA) ==&lt;br /&gt;
=== CA.L2-3.12.1 – Security Control Assessment ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_CA.L2-3.12.1_Details|&#039;&#039;&#039;CA.L2-3.12.1&#039;&#039;&#039;]] Periodically assess the security controls in organizational systems to determine if the controls are effective in their application.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the frequency of security control assessments is defined. || Document || SSP.&lt;br /&gt;
|-&lt;br /&gt;
| [b] security controls are assessed with the defined frequency to determine if the controls are effective in their application. || Artifact || Copy of last security control assessment done within defined frequency.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== CA.L2-3.12.2 – Operational Plan of Action ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_CA.L2-3.12.2_Details|&#039;&#039;&#039;CA.L2-3.12.2&#039;&#039;&#039;]] Develop and implement plans of action designed to correct deficiencies and reduce or eliminate vulnerabilities in organizational systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] deficiencies and vulnerabilities to be addressed by the plan of action are identified. || Artifact || Plan of Action (POA).&lt;br /&gt;
|-&lt;br /&gt;
| [b] a plan of action is developed to correct identified deficiencies and reduce or eliminate identified vulnerabilities. || Artifact || Plan of Action (POA).&lt;br /&gt;
|-&lt;br /&gt;
| [c] the plan of action is implemented to correct identified deficiencies and reduce or eliminate identified vulnerabilities. || Artifact || Plan of Action (POA)/previously completed POAs.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== CA.L2-3.12.3 – Security Control Monitoring ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_CA.L2-3.12.3_Details|&#039;&#039;&#039;CA.L2-3.12.3&#039;&#039;&#039;]] Monitor security controls on an ongoing basis to ensure the continued effectiveness of the controls.&lt;br /&gt;
|-&lt;br /&gt;
| [a] security controls are monitored on an ongoing basis to ensure the continued effectiveness of those controls. || Artifact || Collection of risk assessment results, internal or third-party audits/security assessments and/or continuous monitoring reports/alerts (SIEM tool, etc.).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== CA.L2-3.12.4 – System Security Plan ====&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_CA.L2-3.12.4_Details|&#039;&#039;&#039;CA.L2-3.12.4&#039;&#039;&#039;]] Develop, document, and periodically update system security plans that describe system boundaries, system environments of operation, how security requirements are implemented, and the relationships with or connections to other systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] a system security plan is developed. || Document || SSP.&lt;br /&gt;
|-&lt;br /&gt;
| [b] the system boundary is described and documented in the system security plan. || Document || SSP and any supporting documentation.&lt;br /&gt;
|-&lt;br /&gt;
| [c] the system environment of operation is described and documented in the system security plan. || Document || SSP and any supporting documentation.&lt;br /&gt;
|-&lt;br /&gt;
| [d] the security requirements identified and approved by the designated authority as non-applicable are identified. || Document || SSP and required adjudication from DoD CIO.&lt;br /&gt;
|-&lt;br /&gt;
| [e] the method of security requirement implementation is described and documented in the system security plan. || Document || SSP and any supporting documentation.&lt;br /&gt;
|-&lt;br /&gt;
| [f] the relationship with or connection to other systems is described and documented in the system security plan. || Document || SSP and any supporting documentation.&lt;br /&gt;
|-&lt;br /&gt;
| [g] the frequency to update the system security plan is defined. || Document || SSP.&lt;br /&gt;
|-&lt;br /&gt;
| [h] system security plan is updated with the defined frequency. || Document || SSP/any previous versions.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== System and Communications Protection (SC) ==&lt;br /&gt;
=== SC.L2-3.13.1 – Boundary Protection [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.1_Details|&#039;&#039;&#039;SC.L2-3.13.1&#039;&#039;&#039;]] Monitor, control, and protect organizational communications (i.e., information transmitted or received by organizational information systems) at the external boundaries and key internal boundaries of the information systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the external system boundary is defined. || Document || SSP, network diagrams, CUI flow, cloud provider FedRAMP Moderate.&lt;br /&gt;
|-&lt;br /&gt;
| [b] key internal system boundaries are defined. || Document || SSP, network diagrams, CUI flow.&lt;br /&gt;
|-&lt;br /&gt;
| [c] communications are monitored at the external system boundary. || Screen Share || SSP, logging server, boundary device configurations, monitoring policy.&lt;br /&gt;
|-&lt;br /&gt;
| [d] communications are monitored at key internal boundaries. || Screen Share || SSP, logging server, boundary device configurations, monitoring policy.&lt;br /&gt;
|-&lt;br /&gt;
| [e] communications are controlled at the external system boundary. || Screen Share || SSP, boundary device configurations, ACL, subnets, DMZ.&lt;br /&gt;
|-&lt;br /&gt;
| [f] communications are controlled at key internal boundaries. || Screen Share || SSP, boundary device configurations, ACL, subnets.&lt;br /&gt;
|-&lt;br /&gt;
| [g] communications are protected at the external system boundary. || Screen Share || Configurations for IPS/IDS, email gateway, VLAN, proxy, firewall, malware protection, DNS, TSL.&lt;br /&gt;
|-&lt;br /&gt;
| [h] communications are protected at key internal boundaries. || Screen Share || Configurations for IPS/IDS, VLAN, firewall, malware protection, SSL.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.2 – Security Engineering ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.2_Details|&#039;&#039;&#039;SC.L2-3.13.2&#039;&#039;&#039;]] Employ architectural designs, software development techniques, and systems engineering principles that promote effective information security within organizational systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] architectural designs that promote effective information security are identified. || Document || SSP, config management policy, network diagram, CCB minutes, enterprise architecture process.&lt;br /&gt;
|-&lt;br /&gt;
| [b] software development techniques that promote effective information security are identified. || Document || SSP, config management policy, SDLC, CCB minutes.&lt;br /&gt;
|-&lt;br /&gt;
| [c] systems engineering principles that promote effective information security are identified. || Document || SSP, config management policy, CCB minutes, security architecture engineering.&lt;br /&gt;
|-&lt;br /&gt;
| [d] identified architectural designs that promote effective information security are employed. || Artifact || CCB minutes, Network diagrams and configurations, Project Plans.&lt;br /&gt;
|-&lt;br /&gt;
| [e] identified software development techniques that promote effective information security are employed. || Artifact || CCB minutes, SDLC, code scanner results, code management tracking.&lt;br /&gt;
|-&lt;br /&gt;
| [f] identified systems engineering principles that promote effective information security are employed. || Artifact || CCB minutes, configuration management, ITSM, patch management, lifecycle replacement processes.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.3 – Role Separation ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.3_Details|&#039;&#039;&#039;SC.L2-3.13.3&#039;&#039;&#039;]] Separate user functionality from system management functionality.&lt;br /&gt;
|-&lt;br /&gt;
| [a] user functionality is identified. || Document || SSP, AUP.&lt;br /&gt;
|-&lt;br /&gt;
| [b] system management functionality is identified. || Document || SSP, Privileged Account Agreement.&lt;br /&gt;
|-&lt;br /&gt;
| [c] user functionality is separated from system management functionality. || Screen Share || Active Directory, Jump Boxes, GPO, VM, RDP.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.4 – Shared Resource Control ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.4_Details|&#039;&#039;&#039;SC.L2-3.13.4&#039;&#039;&#039;]] Prevent unauthorized and unintended information transfer via shared system resources.&lt;br /&gt;
|-&lt;br /&gt;
| [a] unauthorized and unintended information transfer via shared system resources is prevented. || Screen Share || SSP, OS configurations, Linux containers, system/media reuse policies, certificate management policies, media destruction policies, printer configs, VDI configuration.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
===  SC.L2-3.13.5 – Public-Access System Separation [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.5_Details|&#039;&#039;&#039;SC.L2-3.13.5&#039;&#039;&#039;]] Implement subnetworks for publicly accessible system components that are physically or logically separated from internal networks.&lt;br /&gt;
|-&lt;br /&gt;
| [a] publicly accessible system components are identified. || Document || SSP, network diagram, DMZ inventory/roles.&lt;br /&gt;
|-&lt;br /&gt;
| [b] subnetworks for publicly accessible system components are physically or logically separated from internal networks. || Artifact || Network diagram, IPAM, VLAN, DHCP, DMZ.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.6 – Network Communication by Exception ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.6_Details|&#039;&#039;&#039;SC.L2-3.13.6&#039;&#039;&#039;]] Deny network communications traffic by default and allow network communications traffic by exception (i.e., deny all, permit by exception).&lt;br /&gt;
|-&lt;br /&gt;
| [a] network communications traffic is denied by default. || Screen Share || Host and network firewall rules, SIEM logs, hit counts.&lt;br /&gt;
|-&lt;br /&gt;
| [b] network communications traffic is allowed by exception. || Screen Share || Host and network firewall rules, SIEM logs, hit counts.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.7 – Split Tunneling ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.7_Details|&#039;&#039;&#039;SC.L2-3.13.7&#039;&#039;&#039;]] Prevent remote devices from simultaneously establishing non-remote connections with organizational systems and communicating via some other connection to resources in external networks (i.e., split tunneling).&lt;br /&gt;
|-&lt;br /&gt;
| [a] remote devices are prevented from simultaneously establishing non-remote connections with the system and communicating via some other connection to resources in external networks (i.e., split tunneling). || Screen Share || VPN appliance/server configuration, endpoint VPN software configuration.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.8 – Data in Transit ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.8_Details|&#039;&#039;&#039;SC.L2-3.13.8&#039;&#039;&#039;]] Implement cryptographic mechanisms to prevent unauthorized disclosure of CUI during transmission unless otherwise protected by alternative physical safeguards.&lt;br /&gt;
|-&lt;br /&gt;
| [a] cryptographic mechanisms intended to prevent unauthorized disclosure of CUI are identified. || Document || SSP, PKI policies, configuration processes, config management, email attachment encryption policy, removable media policy, data at rest policy.&lt;br /&gt;
|-&lt;br /&gt;
| [b] alternative physical safeguards intended to prevent unauthorized disclosure of CUI are identified. || Document || SSP, physical security policy.&lt;br /&gt;
|-&lt;br /&gt;
| [c] either cryptographic mechanisms or alternative physical safeguards are implemented to prevent unauthorized disclosure of CUI during transmission. || Screen Share || TLS settings, SSL settings, VPN/Wireless Access Points/Mobile Devices cryptographic settings, ODBC connector settings, SAN configuration, IPSec/MPLS, backup configuration, physical security.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.9 – Connections Termination ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.9_Details|&#039;&#039;&#039;SC.L2-3.13.9&#039;&#039;&#039;]] Terminate network connections associated with communications sessions at the end of the sessions or after a defined period of inactivity.&lt;br /&gt;
|-&lt;br /&gt;
| [a] a period of inactivity to terminate network connections associated with communications sessions is defined. || Document || SSP, network communications policy.&lt;br /&gt;
|-&lt;br /&gt;
| [b] network connections associated with communications sessions are terminated at the end of the sessions. || Screen Share || VPN appliance/server logs, VPN configurations, web server configurations, firewall connection settings.&lt;br /&gt;
|-&lt;br /&gt;
| [c] network connections associated with communications sessions are terminated after the defined period of inactivity. || Screen Share || VPN appliance/server logs, VPN configurations, web server configurations, frewall connection settings.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.10 – Key Management ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.10_Details|&#039;&#039;&#039;SC.L2-3.13.10&#039;&#039;&#039;]] Establish and manage cryptographic keys for cryptography employed in organizational systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] cryptographic keys are established whenever cryptography is employed. || Artifact || SSP, PKI/certificate management policy, configuration management.&lt;br /&gt;
|-&lt;br /&gt;
| [b] cryptographic keys are managed whenever cryptography is employed. || Artifact || SSP, PKI/certificate management policy, configuration management, access control policy.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.11 – CUI Encryption ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.11_Details|&#039;&#039;&#039;SC.L2-3.13.11&#039;&#039;&#039;]] Employ FIPS-validated cryptography when used to protect the confidentiality of CUI.&lt;br /&gt;
|-&lt;br /&gt;
| [a] FIPS-validated cryptography is employed to protect the confidentiality of CUI. || Screen Share || VPN, wireless, mobile devices, client certificates, server certificates, disk encryption, Outlook plugin, external mail, backup media, ePO server, removable storage, SAN, file compression; look for FIPS mode enabled on appliances.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.12 – Collaborative Device Control ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.12_Details|&#039;&#039;&#039;SC.L2-3.13.12&#039;&#039;&#039;]] Prohibit remote activation of collaborative computing devices and provide indication of devices in use to users present at the device.&lt;br /&gt;
|-&lt;br /&gt;
| [a] collaborative computing devices are identified. || Document || SSP, network diagrams.&lt;br /&gt;
|-&lt;br /&gt;
| [b] collaborative computing devices provide indication to users of devices in use. || Physical Review || Physical inspection of device.&lt;br /&gt;
|-&lt;br /&gt;
| [c] remote activation of collaborative computing devices is prohibited. || Screen Share || Collaboration device configuration/console.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.13 – Mobile Code ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.13_Details|&#039;&#039;&#039;SC.L2-3.13.13&#039;&#039;&#039;]] Control and monitor the use of mobile code.&lt;br /&gt;
|-&lt;br /&gt;
| [a] use of mobile code is controlled. || Screen Share || GPO settings, malware protection, software agent configurations, software development policies, code scanners, MDM configuration, firewall/secure web gateway/proxy config.&lt;br /&gt;
|-&lt;br /&gt;
| [b] use of mobile code is monitored. || Screen Share || SIEM/console monitoring.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.14 – Voice over Internet Protocol ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.14_Details|&#039;&#039;&#039;SC.L2-3.13.14&#039;&#039;&#039;]] Control and monitor the use of Voice over Internet Protocol (VoIP) technologies.&lt;br /&gt;
|-&lt;br /&gt;
| [a] use of Voice over Internet Protocol (VoIP) technologies is controlled. || Artifact || VLAN, ACL, firewall config, VoIP gateway/condenser configuration.&lt;br /&gt;
|-&lt;br /&gt;
| [b] use of Voice over Internet Protocol (VoIP) technologies is monitored. || Artifact || SIEM/VoIP console monitoring, session border controller.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.15 – Communications Authenticity ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.15_Details|&#039;&#039;&#039;SC.L2-3.13.15&#039;&#039;&#039;]] Protect the authenticity of communications sessions.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the authenticity of communications sessions is protected. || Screen Share || SSL, TLS, SMB3, SFTP, IPSec, SSH, Kerberos configs, MPLS, Network Access Control.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.16 – Data at Rest ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.16_Details|&#039;&#039;&#039;SC.L2-3.13.16&#039;&#039;&#039;]] Protect the confidentiality of CUI at rest.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the confidentiality of CUI at rest is protected. || Artifact || Full disk encryption, removable media encryption, SAN encryption, digital backups, mobile device encryption, third party offsite backup storage, cloud virtualization encryption, physical media storage policies.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== System and Information Integrity (SI) ==&lt;br /&gt;
=== SI.L2-3.14.1 – Flaw Remediation [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SI.L2-3.14.1_Details|&#039;&#039;&#039;SI.L2-3.14.1&#039;&#039;&#039;]] Identify, report, and correct information and information system flaws in a timely manner.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the time within which to identify system flaws is specified. || Document || SSP, patch management policy.&lt;br /&gt;
|-&lt;br /&gt;
| [b] system flaws are identified within the specified time frame. || Screen Share || Vulnerability management scanner output and scan policy configuration.&lt;br /&gt;
|-&lt;br /&gt;
| [c] the time within which to report system flaws is specified. || Document || SSP, patch management policy.&lt;br /&gt;
|-&lt;br /&gt;
| [d] system flaws are reported within the specified time frame. || Screen Share || ITSM/trouble tickets, vulnerability management scanner output.&lt;br /&gt;
|-&lt;br /&gt;
| [e] the time within which to correct system flaws is specified. || Document || SSP, patch management policy.&lt;br /&gt;
|-&lt;br /&gt;
| [f] system flaws are corrected within the specified time frame. || Screen Share || Vulnerability management scanner output and scan policy configuration.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SI.L2-3.14.2 – Malicious Code ProTection [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SI.L2-3.14.2_Details|&#039;&#039;&#039;SI.L2-3.14.2&#039;&#039;&#039;]] Provide protection from malicious code at appropriate locations within organizational information systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] designated locations for malicious code protection are identified. || Document || SSP, system protection policy, network diagrams, security architecture documents.&lt;br /&gt;
|-&lt;br /&gt;
| [b] protection from malicious code at designated locations is provided. || Screen Share || Endpoint security settings, email/web proxy gateways, firewall, IPS sensor, MDM configuration, Network Access Control.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SI.L2-3.14.3 – Security Alerts &amp;amp; Advisories ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SI.L2-3.14.3_Details|&#039;&#039;&#039;SI.L2-3.14.3&#039;&#039;&#039;]] Monitor system security alerts and advisories and take action in response.&lt;br /&gt;
|-&lt;br /&gt;
| [a] response actions to system security alerts and advisories are identified. || Document || SSP, vulnerability management policy, Incident Response Plan.&lt;br /&gt;
|-&lt;br /&gt;
| [b] system security alerts and advisories are monitored. || Artifact || Threat intelligence subscriptions, email advisories.&lt;br /&gt;
|-&lt;br /&gt;
| [c] actions in response to system security alerts and advisories are taken. || Artifact || ITSM/trouble tickets, user notifications, updates to firewall/IPS, etc.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SI.L2-3.14.4 – Update Malicious Code Protection [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SI.L2-3.14.4_Details|&#039;&#039;&#039;SI.L2-3.14.4&#039;&#039;&#039;]] Update malicious code protection mechanisms when new releases are available.&lt;br /&gt;
|-&lt;br /&gt;
| [a] malicious code protection mechanisms are updated when new releases are available. || Screen Share || Antivirus console dashboard, firewall AV, Email gateway signatures,proxy, IPS updates.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SI.L2-3.14.5 – System &amp;amp; File Scanning [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SI.L2-3.14.5_Details|&#039;&#039;&#039;SI.L2-3.14.5&#039;&#039;&#039;]] Perform periodic scans of the information system and real-time scans of files from external sources as files are downloaded, opened, or executed.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the frequency for malicious code scans is defined. || Document || SSP, vulnerability management policy.&lt;br /&gt;
|-&lt;br /&gt;
| [b] malicious code scans are performed with the defined frequency. || Screen Share || Consoles for AV (endpoints, servers, and file shares), firewall, email gateway, proxy, IPS, MDM configurations.&lt;br /&gt;
|-&lt;br /&gt;
| [c] real-time malicious code scans of files from external sources as files are downloaded, opened, or executed are performed. || Screen Share || Consoles for AV (endpoints, servers, and file shares), firewall, email gateway, proxy, IPS, MDM configurations.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SI.L2-3.14.6 – Monitor Communications for Attacks ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SI.L2-3.14.6_Details|&#039;&#039;&#039;SI.L2-3.14.6&#039;&#039;&#039;]] Monitor organizational systems, including inbound and outbound communications traffic, to detect attacks and indicators of potential attacks.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the system is monitored to detect attacks and indicators of potential attacks. || Screen Share || Firewall, IPS, endpoint protection, SIEM alerts and reports.&lt;br /&gt;
|-&lt;br /&gt;
| [b] inbound communications traffic is monitored to detect attacks and indicators of potential attacks. || Screen Share || Firewall, IPS, endpoint protection, SIEM alerts and reports.&lt;br /&gt;
|-&lt;br /&gt;
| [c] outbound communications traffic is monitored to detect attacks and indicators of potential attacks. || Screen Share || Firewall, IPS, endpoint protection, SIEM alerts and reports.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SI.L2-3.14.7 – Identify Unauthorized Use ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SI.L2-3.14.7_Details|&#039;&#039;&#039;SI.L2-3.14.7&#039;&#039;&#039;]] Identify unauthorized use of organizational systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] authorized use of the system is defined. || Document || AUP, SSP.&lt;br /&gt;
|-&lt;br /&gt;
| [b] unauthorized use of the system is identified. || Artifact || SIEM logs, endpoint protection console, IPS, Firewall.&lt;br /&gt;
|}&lt;/div&gt;</summary>
		<author><name>David</name></author>
	</entry>
	<entry>
		<id>https://cmmcwiki.org/index.php?title=Evidence_Collection_Approach&amp;diff=1615</id>
		<title>Evidence Collection Approach</title>
		<link rel="alternate" type="text/html" href="https://cmmcwiki.org/index.php?title=Evidence_Collection_Approach&amp;diff=1615"/>
		<updated>2026-07-20T01:35:45Z</updated>

		<summary type="html">&lt;p&gt;David: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;CMMC assessments and certification require substantial evidence and documentation. The following tables outline general guidelines for collecting evidence to assess control requirements and objectives. While these guidelines provide a structured approach, they are not the only means of conducting an accurate assessment. Assessors should exercise professional judgment and may employ alternative methods appropriate to the specific organizational context and circumstances.&lt;br /&gt;
&lt;br /&gt;
Evidence collection approaches are defined as:&lt;br /&gt;
* &#039;&#039;&#039;Documentation&#039;&#039;&#039;: Tangible materials containing information over which an organization has authority, including all types of written records and their copies.&lt;br /&gt;
* &#039;&#039;&#039;Artifacts&#039;&#039;&#039;: Tangible, reviewable records directly resulting from a practice or process being performed by a system or by personnel executing their role within that practice, control, or process.&lt;br /&gt;
* &#039;&#039;&#039;Physical Review&#039;&#039;&#039;: Direct on-site observation and examination of evidence.&lt;br /&gt;
* &#039;&#039;&#039;Screen Share&#039;&#039;&#039;: Real-time remote observation of a user demonstrating a task or process via shared computer screen, sometimes called &amp;quot;over-the-shoulder&amp;quot; review.&lt;br /&gt;
&lt;br /&gt;
DISCLAIMER: Evidence requirements vary significantly across assessment types. &#039;&#039;&#039;The examples provided are illustrative only and should be tailored to meet the specific adequacy and sufficiency standards of your particular assessment context.&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
For inquiries and reporting errors on this wiki, please [mailto:support@cmmctoolkit.org contact us]. Thank you.&lt;br /&gt;
&lt;br /&gt;
== Access Control (AC) ==&lt;br /&gt;
=== AC.L2-3.1.1 – Authorized Access Control [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.1_Details|&#039;&#039;&#039;AC.L2-3.1.1&#039;&#039;&#039;]] Limit information system access to authorized users, processes acting on behalf of authorized users, or devices (including other information systems).&lt;br /&gt;
|-&lt;br /&gt;
| [a] authorized users are identified. || Document || Document defining account request, approval, provisioning.&lt;br /&gt;
|-&lt;br /&gt;
| [b] processes acting on behalf of authorized users are identified. || Document || Document defining account request, approval, provisioning.&lt;br /&gt;
|-&lt;br /&gt;
| [c] devices (and other systems) authorized to connect to the system are identified. || Document || Document defining account request, approval, provisioning.&lt;br /&gt;
|-&lt;br /&gt;
| [d] system access is limited to authorized users. || Screen Share || Screen share showing login requirements are enforced. Example of an unauthorized user denied (unauthorized username entered at login).&lt;br /&gt;
|-&lt;br /&gt;
| [e] system access is limited to processes acting on behalf of authorized users. || Screen Share || Screenshot showing that service accounts are assigned to authorized users only; no rogue accounts without an authorized user are active.&lt;br /&gt;
|-&lt;br /&gt;
| [f] system access is limited to authorized devices (including other systems). || Screen Share || Screen share showing that all devices running are authorized; no rogue devices on the network.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.2 – Transaction &amp;amp; Function Control [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.2_Details|&#039;&#039;&#039;AC.L2-3.1.2&#039;&#039;&#039;]] Limit information system access to the types of transactions and functions that authorized users are permitted to execute.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the types of transactions and functions that authorized users are permitted to execute are defined. || Document || SSP, AUP, or IAM document that defines what authorized users can execute.&lt;br /&gt;
|-&lt;br /&gt;
| [b] system access is limited to the defined types of transactions and functions for authorized users. || Screen Share || Screenshot of security roles in AD or IAM or other directory-based identity-related services tool that shows transactions are as defined in the SSP or IAM document; privileged and non-privileged accounts need to be defined and identified in the artifact; screenshot of a non-privileged user trying to execute a privileged function.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.3 – Control CUI Flow ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.3_Details|&#039;&#039;&#039;AC.L2-3.1.3&#039;&#039;&#039;]] Control the flow of CUI in accordance with approved authorizations.&lt;br /&gt;
|-&lt;br /&gt;
| [a] information flow control policies are defined. || Document || SSP or other document describing the control of CUI on the network.&lt;br /&gt;
|-&lt;br /&gt;
| [b] methods and enforcement mechanisms for controlling the flow of CUI are defined. || Document || Document that defines the networking devices that are on the CUI network and answers what measures are in place to control the flow. List of firewalls, border and internal layer 3 devices, IDS/IPS, DLP, that process CUI.&lt;br /&gt;
|-&lt;br /&gt;
| [c] designated sources and destinations (e.g., networks, individuals, and devices) for CUI within the system and between interconnected systems are identified. || Artifact || Network diagram, data flow diagram, external system connection diagrams, document describing the policies for CUI on the network; listing of VLANs and subnets where CUI is authorized; document must describe source and authorized destinations.&lt;br /&gt;
|-&lt;br /&gt;
| [d] authorizations for controlling the flow of CUI are defined. || Document || Document that defines how CUI is to be controlled, such as an InfoSec plan, and/or network management plan.&lt;br /&gt;
|-&lt;br /&gt;
| [e] approved authorizations for controlling the flow of CUI are enforced. || Screen Share || Screenshots of firewall rules, ACLs, etc.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.4 – Separation of Duties ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.4_Details|&#039;&#039;&#039;AC.L2-3.1.4&#039;&#039;&#039;]] Separate the duties of individuals to reduce the risk of malevolent activity without collusion.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the duties of individuals requiring separation are defined. || Document || Document, SSP, account management policy, defining separation of duties by person or role.&lt;br /&gt;
|-&lt;br /&gt;
| [b] responsibilities for duties that require separation are assigned to separate individuals. || Screen Share || Screenshot showing that separation of duties is enforced by showing admin accounts are assigned to different people based on role.&lt;br /&gt;
|-&lt;br /&gt;
| [c] access privileges that enable individuals to exercise the duties that require separation are granted to separate individuals. || Screen Share || Screen shot showing an example such as a security manager can not log into a network device and change ACLs, or network admins can not access security logs in the SIEM tool.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.5 – Least Privilege ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.5_Details|&#039;&#039;&#039;AC.L2-3.1.5&#039;&#039;&#039;]] Employ the principle of least privilege, including for specific security functions and privileged accounts.&lt;br /&gt;
|-&lt;br /&gt;
| [a] privileged accounts are identified. || Document || &amp;quot;SSP or policy (documentation) identify what is considered a privileged account.&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| [b] access to privileged accounts is authorized in accordance with the principle of least privilege. || Artifact || An artifact that identifies the least amount of permissions associated with different types of privileged accounts are approved.&lt;br /&gt;
|-&lt;br /&gt;
| [c] security functions are identified. || Document || &amp;quot;SSP or policy (documentation) identifies what is considered a security account.&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| [d] access to security functions is authorized in accordance with the principle of least privilege. || Artifact || Artifact(s) that identify the least amount of permissions associated with different types of security accounts are approved.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.6 – Non-Privileged Account Use ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.6_Details|&#039;&#039;&#039;AC.L2-3.1.6&#039;&#039;&#039;]] Use non-privileged accounts or roles when accessing nonsecurity functions.&lt;br /&gt;
|-&lt;br /&gt;
| [a] nonsecurity functions are identified. || Document || SSP or account management document, AUP, that defines non-security functions.&lt;br /&gt;
|-&lt;br /&gt;
| [b] users are required to use non-privileged accounts or roles when accessing nonsecurity functions. || Screen Share || Screenshot showing that a privileged user tried to use their admin account to access a non-security function, such as a browser or email (whatever is defined in their policy) and was blocked.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.7 – Privileged Functions ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.7_Details|&#039;&#039;&#039;AC.L2-3.1.7&#039;&#039;&#039;]] Prevent non-privileged users from executing privileged functions and capture the execution of such functions in audit logs.&lt;br /&gt;
|-&lt;br /&gt;
| [a] privileged functions are defined. || Document || SSP or policy (documentation) that defines privileged functions.&lt;br /&gt;
|-&lt;br /&gt;
| [b] non-privileged users are defined. || Document || SSP or policy (documentation) that defines non-privileged users.&lt;br /&gt;
|-&lt;br /&gt;
| [c] non-privileged users are prevented from executing privileged functions. || Screen Share || Screen share that shows that a non-privileged user is not allowed to complete a privileged function (installing software).&lt;br /&gt;
|-&lt;br /&gt;
| [d] the execution of privileged functions is captured in audit logs. || Screen Share || Screen share that shows logs being captured of the execution of privileged functions.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.8 – Unsuccessful Logon Attempts ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.8_Details|&#039;&#039;&#039;AC.L2-3.1.8&#039;&#039;&#039;]] Limit unsuccessful logon attempts.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the means of limiting unsuccessful logon attempts is defined. || Document || SSP or policy (documentation) showing unsuccessful logon attempts settings and or policy.&lt;br /&gt;
|-&lt;br /&gt;
| [b] the defined means of limiting unsuccessful logon attempts is implemented. || Artifact || Artifact showing GPO / Policy for limiting logon attempts.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.9 – Privacy &amp;amp; Security Notices ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.9_Details|&#039;&#039;&#039;AC.L2-3.1.9&#039;&#039;&#039;]] Provide privacy and security notices consistent with applicable CUI rules.&lt;br /&gt;
|-&lt;br /&gt;
| [a] privacy and security notices required by CUI-specified rules are identified, consistent, and associated with the specific CUI category. || Document || SSP or policy (documentation) showing CUI-specified rules are identified, consistent, and associated with the specific CUI category.&lt;br /&gt;
|-&lt;br /&gt;
| [b] privacy and security notices are displayed. || Artifact || Artifact that shows a consent banner or screen that a user sees as they log in to the system.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.10 – Session Lock ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.10_Details|&#039;&#039;&#039;AC.L2-3.1.10&#039;&#039;&#039;]] Use session lock with pattern-hiding displays to prevent access and viewing of data after a period of inactivity.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the period of inactivity after which the system initiates a session lock is defined. || Document || SSP or policy (documentation) that defines the period of inactivity and when a session lock is defined.&lt;br /&gt;
|-&lt;br /&gt;
| [b] access to the system and viewing of data is prevented by initiating a session lock after the defined period of inactivity. || Artifact || Artifact that shows the setting of session lock (GPO or system policy or similar solution addressing the controls supporting centralized management and configuration of operating systems, applications, and users&#039; settings for the working environment of user accounts and computer accounts).&lt;br /&gt;
|-&lt;br /&gt;
| [c] previously visible information is concealed via a pattern-hiding display after the defined period of inactivity. || Artifact || Screenshot of GPO setting and configuration settings, or similar solution addressing the controls supporting centralized management and configuration of operating systems, applications, and users&#039; settings for the working environment of user accounts and computer accounts.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.11 – Session Termination ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.11_Details|&#039;&#039;&#039;AC.L2-3.1.11&#039;&#039;&#039;]] Terminate (automatically) a user session after a defined condition.&lt;br /&gt;
|-&lt;br /&gt;
| [a] conditions requiring a user session to terminate are defined. || Document || SSP or policy (documentation) that defines the conditions requiring a user session to be terminated.&lt;br /&gt;
|-&lt;br /&gt;
| [b] a user session is automatically terminated after any of the defined conditions. || Screen Share || Screen share showing GPO / VPN Settings that show when a session would be terminated (Idle time, max connection time).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.12 – Control Remote Access ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.12_Details|&#039;&#039;&#039;AC.L2-3.1.12&#039;&#039;&#039;]] Monitor and control remote access sessions.&lt;br /&gt;
|-&lt;br /&gt;
| [a] remote access sessions are permitted. || Document || SSP or policy (documentation) that defines remote access sessions.&lt;br /&gt;
|-&lt;br /&gt;
| [b] the types of permitted remote access are identified. || Document || SSP or policy (documentation) that defines remote access is permitted.&lt;br /&gt;
|-&lt;br /&gt;
| [c] remote access sessions are controlled. || Screen Share || Screen share that shows how the remote access is controlled (access session, and or groups).&lt;br /&gt;
|-&lt;br /&gt;
| [d] remote access sessions are monitored. || Screen Share || Screen share that shows how remote sessions are monitored (logs).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.13 – Remote Access Confidentiality ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.13_Details|&#039;&#039;&#039;AC.L2-3.1.13&#039;&#039;&#039;]] Employ cryptographic mechanisms to protect the confidentiality of remote access sessions.&lt;br /&gt;
|-&lt;br /&gt;
| [a] cryptographic mechanisms to protect the confidentiality of remote access sessions are identified. || Document || SSP or policy (documentation) that discusses the CUI rules, consistent, and associated with the specific CUI category; FIPS Cert # of appliance or application.&lt;br /&gt;
|-&lt;br /&gt;
| [b] cryptographic mechanisms to protect the confidentiality of remote access sessions are implemented. || Screen Share || Screenshot of VPN concentration that shows encryption is on and enabled (point-to-point, etc.).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.14 – Remote Access Routing ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.14_Details|&#039;&#039;&#039;AC.L2-3.1.14&#039;&#039;&#039;]] Route remote access via managed access control points.&lt;br /&gt;
|-&lt;br /&gt;
| [a] managed access control points are identified and implemented. || Screen Share || Screen share that shows access control points (groups and/or users).&lt;br /&gt;
|-&lt;br /&gt;
| [b] remote access is routed through managed network access control points. || Screen Share || Screen share that shows access control points and how they are managed.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.15 – Privileged Remote Access ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.15_Details|&#039;&#039;&#039;AC.L2-3.1.15&#039;&#039;&#039;]] Authorize remote execution of privileged commands and remote access to security-relevant information.&lt;br /&gt;
|-&lt;br /&gt;
| [a] privileged commands authorized for remote execution are identified. || Document || SSP or policy (documentation) that defines what is authorized to be executed remotely and how that is handled.&lt;br /&gt;
|-&lt;br /&gt;
| [b] security-relevant information authorized to be accessed remotely is identified. || Document || SSP or policy (documentation) that defines what can be accessed remotely and what procedures are implemented to allow this (RDP, jump box).&lt;br /&gt;
|-&lt;br /&gt;
| [c] the execution of the identified privileged commands via remote access is authorized. || Screen Share || Screen share that shows who has access to perform privileged commands a remotely (access groups for privileged accounts).&lt;br /&gt;
|-&lt;br /&gt;
| [d] access to the identified security-relevant information via remote access is authorized. || Screen Share || Screen share that shows the routing of remote access and how it is monitored and how many locations (Firewall, VPN Concentrator).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.16 – Wireless Access Authorization ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.16_Details|&#039;&#039;&#039;AC.L2-3.1.16&#039;&#039;&#039;]] Authorize wireless access prior to allowing such connections.&lt;br /&gt;
|-&lt;br /&gt;
| [a] wireless access points are identified. || Document || SSP, network administration document.&lt;br /&gt;
|-&lt;br /&gt;
| [b] wireless access is authorized prior to allowing such connections. || Screen Share || Authorization profile(s) in Wireless Access Controller or Identity Manager (i.e. Cisco ISE).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.17 – Wireless Access Protection ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.17_Details|&#039;&#039;&#039;AC.L2-3.1.17&#039;&#039;&#039;]] Protect wireless access using authentication and encryption.&lt;br /&gt;
|-&lt;br /&gt;
| [a] wireless access to the system is protected using authentication. || Screen Share || Security page (or similar) of a Wireless Access Controller.&lt;br /&gt;
|-&lt;br /&gt;
| [b] wireless access to the system is protected using encryption. || Screen Share || Security page (or similar) of a Wireless Access Controller.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.18 – Mobile Device Connection ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.18_Details|&#039;&#039;&#039;AC.L2-3.1.18&#039;&#039;&#039;]] Control connection of mobile devices.&lt;br /&gt;
|-&lt;br /&gt;
| [a] mobile devices that process, store, or transmit CUI are identified. || Document || SSP, Mobile Device Policy.&lt;br /&gt;
|-&lt;br /&gt;
| [b] mobile device connections are authorized. || Screen Share || Authorization profile(s) in Wireless Access Controller or Identity Manager (i.e. Cisco ISE).&lt;br /&gt;
|-&lt;br /&gt;
| [c] mobile device connections are monitored and logged. || Screen Share || Mobile device logs within the MDM, log intake (sources) configuration (within SIEM) showing MDM is feeding logs to the SIEM.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.19 – Encrypt CUI on Mobile ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.19_Details|&#039;&#039;&#039;AC.L2-3.1.19&#039;&#039;&#039;]] Encrypt CUI on mobile devices and mobile computing platforms.&lt;br /&gt;
|-&lt;br /&gt;
| [a] mobile devices and mobile computing platforms that process, store, or transmit CUI are identified. || Document || SSP, Mobile Device Policy.&lt;br /&gt;
|-&lt;br /&gt;
| [b] encryption is employed to protect CUI on identified mobile devices and mobile computing platforms. || Screen Share || Security policy page in MDM showing how encryption are enforced on mobile device. If no MDM or MDM doesn&#039;t enforce encryption, then validate if the devices used are on the list of devices with native FIPS approved validation.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.20 – External Connections [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.20_Details|&#039;&#039;&#039;AC.L2-3.1.20&#039;&#039;&#039;]] Verify and control/limit connections to and use of external information systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] connections to external systems are identified. || Document || SSP, Systems Interconnection Agreements, SLA.&lt;br /&gt;
|-&lt;br /&gt;
| [b] the use of external systems is identified. || Document || SSP, Systems Interconnection Agreements, SLA.&lt;br /&gt;
|-&lt;br /&gt;
| [c] connections to external systems are verified. || Artifact || SLA for external systems, memorandum for interconnection, information to prove that any cloud solution is at FedRAMP impact level of moderate or higher (i.e. license information, screenshot of AWS cloud dashboard, purchase order document).&lt;br /&gt;
|-&lt;br /&gt;
| [d] the use of external systems is verified. || Artifact || SLA for external systems, memorandum for interconnection, information to prove that any cloud solution is at FedRAMP impact level of moderate or higher (i.e. license information, screenshot of AWS cloud dashboard, purchase order document).&lt;br /&gt;
|-&lt;br /&gt;
| [e] connections to external systems are controlled/limited. || Screen Share || Firewall ruleset for controlling access to cloud service or external system.&lt;br /&gt;
|-&lt;br /&gt;
| [f] the use of external systems is controlled/limited. || Screen Share || Firewall ruleset for controlling access to cloud service or external system.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.21 – Portable Storage Use ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.21_Details|&#039;&#039;&#039;AC.L2-3.1.21&#039;&#039;&#039;]] Limit use of portable storage devices on external systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the use of portable storage devices containing CUI on external systems is identified and documented. || Document || SSP, Removable Media Policy, Acceptable Use Policy (with emphasis on portable media use).&lt;br /&gt;
|-&lt;br /&gt;
| [b] limits on the use of portable storage devices containing CUI on external systems are defined. || Document || SSP, Removable Media Policy, Acceptable Use Policy (with emphasis on portable media use).&lt;br /&gt;
|-&lt;br /&gt;
| [c] the use of portable storage devices containing CUI on external systems is limited as defined. || Document || SSP, Removable Media Policy, Acceptable Use Policy (with emphasis on portable media use).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.22 – Control Public Information [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.22_Details|&#039;&#039;&#039;AC.L2-3.1.22&#039;&#039;&#039;]] Control information posted or processed on publicly accessible information systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] individuals authorized to post or process information on publicly accessible systems are identified. || Document || SSP, Website Governance Plan, Information Release Document.&lt;br /&gt;
|-&lt;br /&gt;
| [b] procedures to ensure CUI is not posted or processed on publicly accessible systems are identified. || Document || SSP, Website Governance Plan, Information Release Document.&lt;br /&gt;
|-&lt;br /&gt;
| [c] a review process is in place prior to posting of any content to publicly accessible systems. || Artifact || &amp;quot;Information release approval process, i.e. chain of email communication from originator, approver, and final decision (may or may not include individual authorized to post); &lt;br /&gt;
SharePoint/electronic or paper form/ ticket system showing information flow between requestor and approver (may or may not include  individual authorized to post).&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| [d] content on publicly accessible systems is reviewed to ensure that it does not include CUI. || Artifact || Incident response process, web design/update/modification SOP etc.&lt;br /&gt;
|-&lt;br /&gt;
| [e] mechanisms are in place to remove and address improper posting of CUI. || Artifact || Incident response process, web design/update/modification SOP etc.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Awareness and Training (AT) ==&lt;br /&gt;
=== AT.L2-3.2.1 – Role-Based Risk Awareness ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AT.L2-3.2.1_Details|&#039;&#039;&#039;AT.L2-3.2.1&#039;&#039;&#039;]] Ensure that managers, systems administrators, and users of organizational systems are made aware of the security risks associated with their activities and of the applicable policies, standards, and procedures related to the security of those systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] security risks associated with organizational activities involving CUI are identified. || Document || Policy of Security Awareness Training; Security Awareness Training Briefing.&lt;br /&gt;
|-&lt;br /&gt;
| [b] policies, standards, and procedures related to the security of the system are identified. || Document || Acceptable Use Policy, Policy/Procedures/Instruction related to the security of the system.&lt;br /&gt;
|-&lt;br /&gt;
| [c] managers, systems administrators, and users of the system are made aware of the security risks associated with their activities. || Artifact || Security Training Brief, training records.&lt;br /&gt;
|-&lt;br /&gt;
| [d] managers, systems administrators, and users of the system are made aware of the applicable policies, standards, and procedures related to the security of the system. || Artifact || Policies, standards and procedures for employees within training (completed training report).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AT.L2-3.2.2 – Role-Based Training ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AT.L2-3.2.2_Details|&#039;&#039;&#039;AT.L2-3.2.2&#039;&#039;&#039;]] Ensure that personnel are trained to carry out their assigned information security-related duties and responsibilities.|-&lt;br /&gt;
|-&lt;br /&gt;
| [a] information security-related duties, roles, and responsibilities are defined. || Document || Policy/Procedures/Instruction, Job Role Matrix, Position Descriptions, User Roles.&lt;br /&gt;
|-&lt;br /&gt;
| [b] information security-related duties, roles, and responsibilities are assigned to designated personnel. || Artifact || Screenshot of breakout of different roles/permissions assigned to individuals (i.e. ActiveDirectory); Privilege Access Agreement.&lt;br /&gt;
|-&lt;br /&gt;
| [c] personnel are adequately trained to carry out their assigned information security-related duties, roles, and responsibilities. || Artifact || Screenshot of tool and/or training specifying security specific roles, duties and responsibilities; Screenshot of required certifications (i.e. Sec+, CISSP).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AT.L2-3.2.3 – Insider Threat Awareness ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AT.L2-3.2.3_Details|&#039;&#039;&#039;AT.L2-3.2.3&#039;&#039;&#039;]] Provide security awareness training on recognizing and reporting potential indicators of insider threat.&lt;br /&gt;
|-&lt;br /&gt;
| [a] potential indicators associated with insider threats are identified. || Document || Insidert Threat Policy/Procedures/Instruction; Insider Threat Training/Briefing.&lt;br /&gt;
|-&lt;br /&gt;
| [b] security awareness training on recognizing and reporting potential indicators of insider threat is provided to managers and employees. || Artifact || Screenshot of training records showing completion of Insider Threat training, emails showing completion of Insider Threat training, Screenshot of certificate showing completion with individual&#039;s name.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Audit and Accountability (AU) ==&lt;br /&gt;
=== AU.L2-3.3.1 – System Auditing ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AU.L2-3.3.1_Details|&#039;&#039;&#039;AU.L2-3.3.1&#039;&#039;&#039;]] Create and retain system audit logs and records to the extent needed to enable the monitoring, analysis, investigation, and reporting of unlawful or unauthorized system activity.&lt;br /&gt;
|-&lt;br /&gt;
| [a] audit logs needed (i.e., event types to be logged) to enable the monitoring, analysis, investigation, and reporting of unlawful or unauthorized system activity are specified. || Document || SSP, policy, or auditing and logging process that defines specific types of events to be logged.&lt;br /&gt;
|-&lt;br /&gt;
| [b] the content of audit records needed to support monitoring, analysis, investigation, and reporting of unlawful or unauthorized system activity is defined. || Document || SSP, policy, or auditing and logging process that defines specific content of audit records/files.&lt;br /&gt;
|-&lt;br /&gt;
| [c] audit records are created (generated). || Screen Share || Screen share of tool that shows logs are generated for all systems.&lt;br /&gt;
|-&lt;br /&gt;
| [d] audit records, once created, contain the defined content. || Screen Share || Screen share of tool that shows logs contain defined content as defined in SSP, policy, or procedures.&lt;br /&gt;
|-&lt;br /&gt;
| [e] retention requirements for audit records are defined. || Document || SSP, Polocy, or Auditing and logging process that describes how long records are kept.&lt;br /&gt;
|-&lt;br /&gt;
| [f] audit records are retained as defined. || Screen Share || Screen share of tool that shows records and audit content retained at a minimum as defined.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AU.L2-3.3.2 – User Accountability ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AU.L2-3.3.2_Details|&#039;&#039;&#039;AU.L2-3.3.2&#039;&#039;&#039;]] Ensure that the actions of individual system users can be uniquely traced to those users so they can be held accountable for their actions.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the content of the audit records needed to support the ability to uniquely trace users to their actions is defined. || Document || SSP, policy, or process that defines actions traced back to individuals.&lt;br /&gt;
|-&lt;br /&gt;
| [b] audit records, once created, contain the defined content. || Screen Share || Screen share of tool that shows audit records traced to specific users/roles.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AU.L2-3.3.3 – Event Review ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AU.L2-3.3.3_Details|&#039;&#039;&#039;AU.L2-3.3.3&#039;&#039;&#039;]] Review and update logged events.&lt;br /&gt;
|-&lt;br /&gt;
| [a] a process for determining when to review logged events is defined. || Document || SSP, policy, or documented process that shows frequency of when to review types of logged events.&lt;br /&gt;
|-&lt;br /&gt;
| [b] event types being logged are reviewed in accordance with the defined review process. || Artifact || Evidence through a documented method such as meeting minutes, CAB minutes, etc. of log sources and log events being logged at the defined frequency.&lt;br /&gt;
|-&lt;br /&gt;
| [c] event types being logged are updated based on the review. || Artifact || Evidence of implementation based on the results of the review of logged events/sources through a ticket, meeting minutes, or screen share of the tool that shows changes implemented (finetuning).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AU.L2-3.3.4 – Audit Failure Alerting ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AU.L2-3.3.4_Details|&#039;&#039;&#039;AU.L2-3.3.4&#039;&#039;&#039;]] Alert in the event of an audit logging process failure.&lt;br /&gt;
|-&lt;br /&gt;
| [a] personnel or roles to be alerted in the event of an audit logging process failure are identified. || Document || SSP, policy, or procedure that shows who needs to be notified in case of an audit failure.&lt;br /&gt;
|-&lt;br /&gt;
| [b] types of audit logging process failures for which alert will be generated are defined. || Document || SSP, policy, or procedure that shows what types of failure will generate notifications.&lt;br /&gt;
|-&lt;br /&gt;
| [c] identified personnel or roles are alerted in the event of an audit logging process failure. || Artifact || Artifact such as email or ticket that shows the identified personnel were alerted of any audit/logging process failure as defined.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AU.L2-3.3.5 – Audit Correlation ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AU.L2-3.3.5_Details|&#039;&#039;&#039;AU.L2-3.3.5&#039;&#039;&#039;]] Correlate audit record review, analysis, and reporting processes for investigation and response to indications of unlawful, unauthorized, suspicious, or unusual activity.&lt;br /&gt;
|-&lt;br /&gt;
| [a] audit record review, analysis, and reporting processes for investigation and response to indications of unlawful, unauthorized, suspicious, or unusual activity are defined. || Document || SSP, policy, or procedure covering audit logging, monitoring, and reporting.&lt;br /&gt;
|-&lt;br /&gt;
| [b] defined audit record review, analysis, and reporting processes are correlated. || Artifact || Artifact showing an audit event and the resultant corrective action or actions to the event; this can be a Help Desk ticket, meeting notes, or a change control board items showing the event and any corrective action taken.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AU.L2-3.3.6 – Reduction &amp;amp; Reporting ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AU.L2-3.3.6_Details|&#039;&#039;&#039;AU.L2-3.3.6&#039;&#039;&#039;]] Provide audit record reduction and report generation to support on-demand analysis and reporting.&lt;br /&gt;
|-&lt;br /&gt;
| [a] an audit record reduction capability that supports on-demand analysis is provided. || Screen Share || Screen share of the logging environment where an event can be selected and traced back to a specific device, or dashboard showing realtime event analysis.&lt;br /&gt;
|-&lt;br /&gt;
| [b] a report generation capability that supports on-demand reporting is provided. || Screen Share || Screen share showing the generation of an on demand report.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AU.L2-3.3.7 – Authoritative Time Source ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AU.L2-3.3.7_Details|&#039;&#039;&#039;AU.L2-3.3.7&#039;&#039;&#039;]] Provide a system capability that compares and synchronizes internal system clocks with an authoritative source to generate time stamps for audit records.&lt;br /&gt;
|-&lt;br /&gt;
| [a] internal system clocks are used to generate time stamps for audit records. || Screen Share || Screen share showing the NTP settings of a windows, Unix, Linux device; a screen share showing the NTP settings of network appliances.&lt;br /&gt;
|-&lt;br /&gt;
| [b] an authoritative source with which to compare and synchronize internal system clocks is specified. || Document || SSP or policy indicating that devices need to be synched to a local authoritative time device that is synched with an authoritative time service.&lt;br /&gt;
|-&lt;br /&gt;
| [c] internal system clocks used to generate time stamps for audit records are compared to and synchronized with the specified authoritative time source. || Screen Share || Screen share showing device logging appliance time is point to the appropriate authoritative time server.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AU.L2-3.3.8 – Audit Protection ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AU.L2-3.3.8_Details|&#039;&#039;&#039;AU.L2-3.3.8&#039;&#039;&#039;]] Protect audit information and audit logging tools from unauthorized access, modification, and deletion.&lt;br /&gt;
|-&lt;br /&gt;
| [a] audit information is protected from unauthorized access. || Screen Share || Screen share showing operating system permissions on the audit folders being restricted to appropriate users.&lt;br /&gt;
|-&lt;br /&gt;
| [b] audit information is protected from unauthorized modification. || Screen Share || Screen share showing operating system permissions on the audit folders being restricted to appropriate users.&lt;br /&gt;
|-&lt;br /&gt;
| [c] audit information is protected from unauthorized deletion. || Screen Share || Screen share showing operating system permissions on the audit folders being restricted to appropriate users.&lt;br /&gt;
|-&lt;br /&gt;
| [d] audit logging tools are protected from unauthorized access. || Screen Share || Artifact showing access permissions in the SIEM tool.&lt;br /&gt;
|-&lt;br /&gt;
| [e] audit logging tools are protected from unauthorized modification. || Screen Share || Artifact showing update permissions in the SIEM tool.&lt;br /&gt;
|-&lt;br /&gt;
| [f] audit logging tools are protected from unauthorized deletion. || Screen Share || Artifact showing delete permissions in the SIEM tool.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AU.L2-3.3.9 – Audit Management ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AU.L2-3.3.9_Details|&#039;&#039;&#039;AU.L2-3.3.9&#039;&#039;&#039;]] Limit management of audit logging functionality to a subset of privileged users.&lt;br /&gt;
|-&lt;br /&gt;
| [a] a subset of privileged users granted access to manage audit logging functionality is defined. || Document || SSP or policy indicating which users or groups have access to audit logs.&lt;br /&gt;
|-&lt;br /&gt;
| [b] management of audit logging functionality is limited to the defined subset of privileged users. || Screen Share || Artifact showing SIEM or OS folder permissions (this should be limited to the assigned users or groups); artifact showing an ACL setting in SIEM tool in regards to logs.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Configuration Management (CM) ==&lt;br /&gt;
=== CM.L2-3.4.1 – System Baselining ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_CM.L2-3.4.1_Details|&#039;&#039;&#039;CM.L2-3.4.1&#039;&#039;&#039;]] Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles.&lt;br /&gt;
|-&lt;br /&gt;
| [a] a baseline configuration is established. || Document || Documentation showing or explaining standard imaging process (how standard images are deployed and where  they are stored).&lt;br /&gt;
|-&lt;br /&gt;
| [b] the baseline configuration includes hardware, software, firmware, and documentation. || Artifact || Screenshot of repository of where images are maintained and information relating to hardware, software, and firmware.&lt;br /&gt;
|-&lt;br /&gt;
| [c] the baseline configuration is maintained (reviewed and updated) throughout the system development life cycle. || Artifact || Screenshot/evidence displaying management of baseline configurations (how often they are being managed as stated).&lt;br /&gt;
|-&lt;br /&gt;
| [d] a system inventory is established. || Document || Screenshot/evidence displaying inventory listing of approved products for use.&lt;br /&gt;
|-&lt;br /&gt;
| [e] the system inventory includes hardware, software, firmware, and documentation. || Artifact || Screeenshot/evidence displaying inventory listing of approved products and versions permitted for use.&lt;br /&gt;
|-&lt;br /&gt;
| [f] the inventory is maintained (reviewed and updated) throughout the system development life cycle. || Artifact || Screeenshot/evidence displaying management of baseline configurations (How often and are they being managed as stated.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== CM.L2-3.4.2 – Security Configuration Enforcement ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_CM.L2-3.4.2_Details|&#039;&#039;&#039;CM.L2-3.4.2&#039;&#039;&#039;]] Establish and enforce security configuration settings for information technology products employed in organizational systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] security configuration settings for information technology products employed in the system are established and included in the baseline configuration. || Document || Documentation explaining methodology used by organization to create secure baselines (STIGs, benchmarks).&lt;br /&gt;
|-&lt;br /&gt;
| [b] security configuration settings for information technology products employed in the system are enforced. || Artifact || Evidence of tool/s used to enforce security configurations to ensure images used are free from modification unless authorized.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== CM.L2-3.4.3 – System Change Management ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_CM.L2-3.4.3_Details|&#039;&#039;&#039;CM.L2-3.4.3&#039;&#039;&#039;]] Track, review, approve or disapprove, and log changes to organizational systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] changes to the system are tracked. || Artifact || Evidence of IT Service Management tool / process used to track system changes.&lt;br /&gt;
|-&lt;br /&gt;
| [b] changes to the system are reviewed. || Artifact || Evidence of IT Service Management tool / process used to review system changes.&lt;br /&gt;
|-&lt;br /&gt;
| [c] changes to the system are approved or disapproved. || Artifact || Evidence of IT Service Management tool / process used to approve/disapprove system changes.&lt;br /&gt;
|-&lt;br /&gt;
| [d] changes to the system are logged. || Artifact || Evidence of IT Service Management tool / process used to log system changes.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== CM.L2-3.4.4 – Security Impact Analysis ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_CM.L2-3.4.4_Details|&#039;&#039;&#039;CM.L2-3.4.4&#039;&#039;&#039;]] Analyze the security impact of changes prior to implementation.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the security impact of changes to the system is analyzed prior to implementation. || Artifact || Document explaining that security impact analysis of proposed changes to a system is conducted prior to implementation.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== CM.L2-3.4.5 – Access Restrictions for Change ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_CM.L2-3.4.5_Details|&#039;&#039;&#039;CM.L2-3.4.5&#039;&#039;&#039;]] Define, document, approve, and enforce physical and logical access restrictions associated with changes to organizational systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] physical access restrictions associated with changes to the system are defined. || Document || Document explaining the process of how physical access restrictions are defined for an individuals ability to make system changes.&lt;br /&gt;
|-&lt;br /&gt;
| [b] physical access restrictions associated with changes to the system are documented. || Document || Document explaining the process of how physical access restrictions are defined for an individuals ability to make system changes are documented; access request process.&lt;br /&gt;
|-&lt;br /&gt;
| [c] physical access restrictions associated with changes to the system are approved. || Artifact || Evidence of process of how physical access to systems are granted (i.e. physical access request sample).&lt;br /&gt;
|-&lt;br /&gt;
| [d] physical access restrictions associated with changes to the system are enforced. || Physical Review || Evidence of process of how physical access to systems are enforced (physical access system).&lt;br /&gt;
|-&lt;br /&gt;
| [e] logical access restrictions associated with changes to the system are defined. || Document || Document explaining the process of how logical access restrictions are defined for an individual&#039;s ability to make system changes.&lt;br /&gt;
|-&lt;br /&gt;
| [f] logical access restrictions associated with changes to the system are documented. || Document || Document explaining the process of how logical access restrictions are defined for an individual&#039;s ability to make system changes are documented.&lt;br /&gt;
|-&lt;br /&gt;
| [g] logical access restrictions associated with changes to the system are approved. || Artifact || Evidence of process of how logical access to systems are granted.&lt;br /&gt;
|-&lt;br /&gt;
| [h] logical access restrictions associated with changes to the system are enforced. || Artifact || Evidence of process of how logical access to systems are enforced.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== CM.L2-3.4.6 – Least Functionality ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_CM.L2-3.4.6_Details|&#039;&#039;&#039;CM.L2-3.4.6&#039;&#039;&#039;]] Employ the principle of least functionality by configuring organizational systems to provide only essential capabilities.&lt;br /&gt;
|-&lt;br /&gt;
| [a] essential system capabilities are defined based on the principle of least functionality. || Document || Documentation explaining how systems are configured to utilize the principle of least functionality for designated users.&lt;br /&gt;
|-&lt;br /&gt;
| [b] the system is configured to provide only the defined essential capabilities. || Screen Share || Evidence displaying how systems are configured to utilize the principle of least functionality for designated users; disabled service settings, accepted standards for hardening (CIS benchmarks, etc.).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== CM.L2-3.4.7 – Nonessential Functionality ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_CM.L2-3.4.7_Details|&#039;&#039;&#039;CM.L2-3.4.7&#039;&#039;&#039;]] Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services.&lt;br /&gt;
|-&lt;br /&gt;
| [a] essential programs are defined. || Document || Documented essential programs specified; build documents; software center; SSP.&lt;br /&gt;
|-&lt;br /&gt;
| [b] the use of nonessential programs is defined. || Document || Documented listing of nonessential programs (whatever is NOT specified in [a]); AUP/User Agreement may identify nonessential use/programs.&lt;br /&gt;
|-&lt;br /&gt;
| [c] the use of nonessential programs is restricted, disabled, or prevented as defined. || Screen Share || Tool used to restrict nonessential programs displays restrictions as defined (McAfee ePO settings, Carbon Black rules, etc.).&lt;br /&gt;
|-&lt;br /&gt;
| [d] essential functions are defined. || Document || Documented essential functions are specified.&lt;br /&gt;
|-&lt;br /&gt;
| [e] the use of nonessential functions is defined. || Document || Documented nonessential functions are specified.&lt;br /&gt;
|-&lt;br /&gt;
| [f] the use of nonessential functions is restricted, disabled, or prevented as defined. || Screen Share || Tool used to restrict essential/nonessential functions displays restrictions as defined.&lt;br /&gt;
|-&lt;br /&gt;
| [g] essential ports are defined. || Document || Documented essential ports are specified.&lt;br /&gt;
|-&lt;br /&gt;
| [h] the use of nonessential ports is defined. || Document || Documented nonessential ports functions are specified.&lt;br /&gt;
|-&lt;br /&gt;
| [i] the use of nonessential ports is restricted, disabled, or prevented as defined. || Screen Share || Tool used to restrict essential/nonessential ports displays restrictions as defined (FW rules; McAfee; GPO, etc.).&lt;br /&gt;
|-&lt;br /&gt;
| [j] essential protocols are defined. || Document || Documented essential protocols are specified.&lt;br /&gt;
|-&lt;br /&gt;
| [k] the use of nonessential protocols is defined. || Document || Documented nonessential protocols functions are specified.&lt;br /&gt;
|-&lt;br /&gt;
| [l] the use of nonessential protocols is restricted, disabled, or prevented as defined. || Screen Share || Tool used to restrict essential/nonessential protocols displays restrictions as defined (FW rules; GPO, etc.).&lt;br /&gt;
|-&lt;br /&gt;
| [m] essential services are defined. || Document || Documented essential services specified.&lt;br /&gt;
|-&lt;br /&gt;
| [n] the use of nonessential services is defined. || Document || Documented nonessential services functions are specified.&lt;br /&gt;
|-&lt;br /&gt;
| [o] the use of nonessential services is restricted, disabled, or prevented as defined. || Screen Share || Tool used to restrict essential/nonessential services displays restrictions as defined.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== CM.L2-3.4.8 – Application Execution Policy ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_CM.L2-3.4.8_Details|&#039;&#039;&#039;CM.L2-3.4.8&#039;&#039;&#039;]] Apply deny-by-exception (blacklisting) policy to prevent the use of unauthorized software or deny-all, permit-by-exception (whitelisting) policy to allow the execution of authorized software.&lt;br /&gt;
|-&lt;br /&gt;
| [a] a policy specifying whether whitelisting or blacklisting is to be implemented is specified. || Document || Documentation explaining whitelisting or blacklisting process.&lt;br /&gt;
|-&lt;br /&gt;
| [b] the software allowed to execute under whitelisting or denied use under blacklisting is specified. || Document || Documentation explaining whitelisting or blacklisting process for software.&lt;br /&gt;
|-&lt;br /&gt;
| [c] whitelisting to allow the execution of authorized software or blacklisting to prevent the use of unauthorized software is implemented as specified. || Screen Share || Tool used for whitelisting or blacklisting for software shows capability of restricting/authorizing software (Carbon Black dashboard, &amp;quot;SW Store&amp;quot;, web proxies, DNS Blackhole, etc.).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== CM.L2-3.4.9 – User-Installed Software ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_CM.L2-3.4.9_Details|&#039;&#039;&#039;CM.L2-3.4.9&#039;&#039;&#039;]] Control and monitor user-installed software.&lt;br /&gt;
|-&lt;br /&gt;
| [a] a policy for controlling the installation of software by users is established. || Document || Documented software authorization process or methodology for approval.&lt;br /&gt;
|-&lt;br /&gt;
| [b] installation of software by users is controlled based on the established policy. || Screen Share || Evidence that approval/restriction in installation of software by authorized personnel is implemented as specified (AUP, GPO, etc.).&lt;br /&gt;
|-&lt;br /&gt;
| [c] installation of software by users is monitored. || Screen Share || Evidence that installation of software by authorized personnel is monitored (SCCM groups, SW Center, etc.).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Identification and Authentication (IA) ==&lt;br /&gt;
=== IA.L2-3.5.1 – Identification [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IA.L2-3.5.1_Details|&#039;&#039;&#039;IA.L2-3.5.1&#039;&#039;&#039;]] Identify information system users, processes acting on behalf of users, or devices.&lt;br /&gt;
|-&lt;br /&gt;
| [a] system users are identified. || Document || Based on what is defined in their documentation (SSP, AUP, Policy, SOP), request to see a sample of non-privileged/privileged users in AD OU group (overlaps with 3.1.1 and 3.1.5).&lt;br /&gt;
|-&lt;br /&gt;
| [b] processes acting on behalf of users are identified. || Screen Share || Based on what is defined in their documentation (SSP, AUP, Policy, SOP), request to see a sample of service accounts in AD OU group (overlaps with 3.1.1 and 3.1.5).&lt;br /&gt;
|-&lt;br /&gt;
| [c] devices accessing the system are identified. || Screen Share || Based on what is defined in their documentation (SSP, AUP, Policy, SOP), request to see a sample of domain-joined workstation &amp;amp; servers in AD OU group (overlaps with 3.1.1 and 3.1.5).  For network devices, request screen share/artifact to show how they are identified on the enterprise network.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IA.L2-3.5.2 – Authentication [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IA.L2-3.5.2_Details|&#039;&#039;&#039;IA.L2-3.5.2&#039;&#039;&#039;]] Authenticate (or verify) the identities of those users, processes, or devices, as a prerequisite to allowing access to organizational information systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the identity of each user is authenticated or verified as a prerequisite to system access. || Screen Share || If the user logs in with non-privileged account during other demoes and then a privileged account, then this should be satisfied.  If screen share is unavailable, request logs to show successful and unsuccessful login by privileged and non-privilged users.&lt;br /&gt;
|-&lt;br /&gt;
| [b] the identity of each process acting on behalf of a user is authenticated or verified as a prerequisite to system access. || Screen Share || Request a log that shows successful/unsuccessful service account trying to log on to company&#039;s asset.&lt;br /&gt;
|-&lt;br /&gt;
| [c] the identity of each device accessing or connecting to the system is authenticated or verified as a prerequisite to system access. || Screen Share || Request a log that shows domain-joined workstation/server authenticating to AD (focus on the MAC/IP address/hostname).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IA.L2-3.5.3 – Multifactor Authentication ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IA.L2-3.5.3_Details|&#039;&#039;&#039;IA.L2-3.5.3&#039;&#039;&#039;]] Use multifactor authentication for local and network access to privileged accounts and for network access to non-privileged accounts.&lt;br /&gt;
|-&lt;br /&gt;
| [a] privileged accounts are identified. || Screen Share|| Based on what is defined in their documentation, request to see a sample of privileged users in AD OU group.  Overlaps with 3.1.5.  Screenshot/screen share to show implementation is enforced.&lt;br /&gt;
|-&lt;br /&gt;
| [b] multifactor authentication is implemented for local access to privileged accounts. || Document || SSP, AUP, Policy, SOP that defines that MFA is needed for privileged local access.&lt;br /&gt;
|-&lt;br /&gt;
| [c] multifactor authentication is implemented for network access to privileged accounts. || Screen Share || Within the MFA implementation mechanism, show that privileged users are forced to use MFA;  Screenshot/Screen share to show implementation is enforced.&lt;br /&gt;
|-&lt;br /&gt;
| [d] multifactor authentication is implemented for network access to non-privileged accounts. || Screen Share || Within the MFA implementation mechanism, show that non-privileged users are forced to use MFA; Screenshot/Screen share to show implementation is enforced.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IA.L2-3.5.4 – Replay-Resistant Authentication ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IA.L2-3.5.4_Details|&#039;&#039;&#039;IA.L2-3.5.4&#039;&#039;&#039;]] Employ replay-resistant authentication mechanisms for network access to privileged and non-privileged accounts.&lt;br /&gt;
|-&lt;br /&gt;
| [a] replay-resistant authentication mechanisms are implemented for network account access to privileged and non-privileged accounts. || Screen Share || Show the GPO setting that enforces Kerberos within AD.  If MFA is used, show the implementation to enforce replay resistant techniques.  For non-windows, show the technical solution to enforce replay resistant attacks.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IA.L2-3.5.5 – Identifier Reuse ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IA.L2-3.5.5_Details|&#039;&#039;&#039;IA.L2-3.5.5&#039;&#039;&#039;]] Prevent reuse of identifiers for a defined period.&lt;br /&gt;
|-&lt;br /&gt;
| [a] a period within which identifiers cannot be reused is defined. || Document || SSP, policies, or SOP that defines identifier reuse.&lt;br /&gt;
|-&lt;br /&gt;
| [b] reuse of identifiers is prevented within the defined period. || Screen Share || Show the GPO setting/technical solution that enforces what is defined in policy/documentation (this can be automated or manual process; screen share/artifacts can be presented to satisfy this requirement.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IA.L2-3.5.6 – Identifier Handling ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IA.L2-3.5.6_Details|&#039;&#039;&#039;IA.L2-3.5.6&#039;&#039;&#039;]] Disable identifiers after a defined period of inactivity.&lt;br /&gt;
|-&lt;br /&gt;
| [a] a period of inactivity after which an identifier is disabled is defined. || Document || SSP, policy that defines the period of inactivity after which an identifier is disabled.&lt;br /&gt;
|-&lt;br /&gt;
| [b] identifiers are disabled after the defined period of inactivity. || Screen Share || Screen share AD or similar tool supporting directory-based identity-related services for disabled accounts (can be done by hand or script).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IA.L2-3.5.7 – Password Complexity ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IA.L2-3.5.7_Details|&#039;&#039;&#039;IA.L2-3.5.7&#039;&#039;&#039;]] Enforce a minimum password complexity and change of characters when new passwords are created.&lt;br /&gt;
|-&lt;br /&gt;
| [a] password complexity requirements are defined. || Document || SSP, policy that defines password complexity requirements.&lt;br /&gt;
|-&lt;br /&gt;
| [b] password change of character requirements are defined. || Document || SSP, policy that defines change of character requirements are defined.&lt;br /&gt;
|-&lt;br /&gt;
| [c] minimum password complexity requirements as defined are enforced when new passwords are created. || Screen Share || Screen share of AD or similar directory-based identity-related service tool to show complexity requirements.&lt;br /&gt;
|-&lt;br /&gt;
| [d] minimum password change of character requirements as defined are enforced when new passwords are created. || Screen Share || Screen share of Group Policy configuration or similar tool providing centralized management and configuration of operating systems, applications, and users&#039; settings to show that characters must be changed.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IA.L2-3.5.8 – Password Reuse ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IA.L2-3.5.8_Details|&#039;&#039;&#039;IA.L2-3.5.8&#039;&#039;&#039;]] Prohibit password reuse for a specified number of generations.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the number of generations during which a password cannot be reused is specified. || Document || SSP, policy that specifies the number of generations during which a password cannot be reused is specified.&lt;br /&gt;
|-&lt;br /&gt;
| [b] reuse of passwords is prohibited during the specified number of generations. || Screen Share || Screen share Group Policy or similar tool providing centralized management and configuration of operating systems, applications, and users&#039; settings in a directory-based identity-related service tool&#039;s configuration to show reuse of passwords is prohibited.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IA.L2-3.5.9 – Temporary Passwords ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IA.L2-3.5.9_Details|&#039;&#039;&#039;IA.L2-3.5.9&#039;&#039;&#039;]] Allow temporary password use for system logons with an immediate change to a permanent password.&lt;br /&gt;
|-&lt;br /&gt;
| [a] an immediate change to a permanent password is required when a temporary password is used for system logon. || Screen Share || Screen share of Group Policy or similar tool providing centralized management and configuration of operating systems, applications, and users&#039; settings in a directory-based identity-related service tool&#039;s configuration to show &amp;quot;change password at first logon.&amp;quot;&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IA.L2-3.5.10 – Cryptographically-Protected Passwords ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IA.L2-3.5.1_Details|&#039;&#039;&#039;IA.L2-3.5.1&#039;&#039;&#039;]] Store and transmit only cryptographically-protected passwords.&lt;br /&gt;
|-&lt;br /&gt;
| [a] passwords are cryptographically protected in storage. || Screen Share || Screen share Group Policy or similar tool providing centralized management and configuration of operating systems, applications, and users&#039; settings in a directory-based identity-related service tool&#039;s configuration that Kerberos, or a similar network authentication protocol that works on the basis of tickets to allow nodes communicating over a non-secure network to prove their identity to one another in a secure manner, is enabled.&lt;br /&gt;
|-&lt;br /&gt;
| [b] passwords are cryptographically protected in transit. || Screen Share || Screen share Group Policy or similar tool providing centralized management and configuration of operating systems, applications, and users&#039; settings in a directory-based identity-related service tool&#039;s configuration that Kerberos, or a similar network authentication protocol that works on the basis of tickets to allow nodes communicating over a non-secure network to prove their identity to one another in a secure manner, is enabled.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IA.L2-3.5.11 – Obscure Feedback ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IA.L2-3.5.10_Details|&#039;&#039;&#039;IA.L2-3.5.10&#039;&#039;&#039;]] Obscure feedback of authentication information.&lt;br /&gt;
|-&lt;br /&gt;
| [a] authentication information is obscured during the authentication process. || Screen Share || Screen share of Group Policy or similar tool providing centralized management and configuration of operating systems, applications, and users&#039; settings in a directory-based identity-related service tool&#039;s configuration to show that passwords are obscured.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Incident Response (IR) ==&lt;br /&gt;
=== IR.L2-3.6.1 – Incident Handling ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IR.L2-3.6.1_Details|&#039;&#039;&#039;IR.L2-3.6.1&#039;&#039;&#039;]] Establish an operational incident-handling capability for organizational systems that includes preparation, detection, analysis, containment, recovery, and user response activities.&lt;br /&gt;
|-&lt;br /&gt;
| [a] an operational incident-handling capability is established. || Document || Incident Response SOP/Plan.&lt;br /&gt;
|-&lt;br /&gt;
| [b] the operational incident-handling capability includes preparation. || Document || Incident Response SOP/Plan, prior incident report, training, COOP plan.&lt;br /&gt;
|-&lt;br /&gt;
| [c] the operational incident-handling capability includes detection. || Document || Incident Response SOP/Plan; definition of tools used to detect; artifacts showing tools used; prior incident report.&lt;br /&gt;
|-&lt;br /&gt;
| [d] the operational incident-handling capability includes analysis. || Document || Incident Response SOP/Plan; Definition of tools used to analyze potential incidents; artifacts showing tools used for analysis; prior incident report.&lt;br /&gt;
|-&lt;br /&gt;
| [e] the operational incident-handling capability includes containment. || Document || Incident Response SOP/Plan; isolation/quarantine process; user training.&lt;br /&gt;
|-&lt;br /&gt;
| [f] the operational incident-handling capability includes recovery. || Document || Incident Response SOP/Plan; COOP Plan; prior incident reports, re-baselining impacted devices.&lt;br /&gt;
|-&lt;br /&gt;
| [g] the operational incident-handling capability includes user response. || Document || Incident Response SOP/Plan; user awareness training; Help Desk process.&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IR.L2-3.6.2 – Incident Reporting ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IR.L2-3.6.2_Details|&#039;&#039;&#039;IR.L2-3.6.2&#039;&#039;&#039;]] Track, document, and report incidents to designated officials and/or authorities both internal and external to the organization.&lt;br /&gt;
|-&lt;br /&gt;
| [a] incidents are tracked. || Artifact || Incident Response SOP/Plan; ITSM artifact; technical implementation for incident tracking.&lt;br /&gt;
|-&lt;br /&gt;
| [b] incidents are documented. || Artifact || Incident Response SOP/Plan; ITSM artifact; technical implementation for incident tracking.&lt;br /&gt;
|-&lt;br /&gt;
| [c] authorities to whom incidents are to be reported are identified. || Document || Incident Response SOP/Plan.&lt;br /&gt;
|-&lt;br /&gt;
| [d] organizational officials to whom incidents are to be reported are identified. || Document || Incident Response SOP/Plan.&lt;br /&gt;
|-&lt;br /&gt;
| [e] identified authorities are notified of incidents. || Screen Share || Prior incident report; DIBNET login; prior email notifications.&lt;br /&gt;
|-&lt;br /&gt;
| [f] identified organizational officials are notified of incidents. || Artifact || Prior incident report; prior email notifications; tabletop exercises.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IR.L2-3.6.3 – Incident Response Testing ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IR.L2-3.6.3_Details|&#039;&#039;&#039;IR.L2-3.6.3&#039;&#039;&#039;]] Test the organizational incident response capability.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the incident response capability is tested. || Artifact || Incident response table top/scheduled or unscheduled test or penetration test.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Maintenance (MA) ==&lt;br /&gt;
=== MA.L2-3.7.1 – Perform Maintenance ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MA.L2-3.7.1_Details|&#039;&#039;&#039;MA.L2-3.7.1&#039;&#039;&#039;]] Perform maintenance on organizational systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] system maintenance is performed. || Artifact || Establish typical maintenance activities (HVAC, UPS, power distribution, generators, copier maintenance) that are performed; maintenance agreements or contracts detailing these types of activities are acceptable; interview responses should be considered.  This requirement should not be confused with 3.14.1 - report, remediate, and correct system flaws in a timely manner (patch management).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MA.L2-3.7.2 – System Maintenance Control ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MA.L2-3.7.2_Details|&#039;&#039;&#039;MA.L2-3.7.2&#039;&#039;&#039;]] Provide controls on the tools, techniques, mechanisms, and personnel used to conduct system maintenance.&lt;br /&gt;
|-&lt;br /&gt;
| [a] tools used to conduct system maintenance are controlled. || Artifact || Tools may largely depend on the assessed environment; discussion examples include network diagnostic and monitoring tools (including hardware and software); artifacts could demonstrate secured locations/areas for these tools (photos) or checkout sheets/rosters (documents) depicting responsible personnel and the dates/times of checkout.&lt;br /&gt;
|-&lt;br /&gt;
| [b] techniques used to conduct system maintenance are controlled. || Artifact || Processes for scheduling, performing, documenting, reviewing, approving, and monitoring maintenance and repairs for the information system.&lt;br /&gt;
|-&lt;br /&gt;
| [c] mechanisms used to conduct system maintenance are controlled. || Artifact || Processes for scheduling, performing, documenting, reviewing, approving, and monitoring maintenance and repairs for the information system.&lt;br /&gt;
|-&lt;br /&gt;
| [d] personnel used to conduct system maintenance are controlled. || Physical Review || Screenshot of who is authorized to conduct maintenance; maintenance personnel training program.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MA.L2-3.7.3 – Equipment Sanitization ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MA.L2-3.7.3_Details|&#039;&#039;&#039;MA.L2-3.7.3&#039;&#039;&#039;]] Ensure equipment removed for off-site maintenance is sanitized of any CUI.&lt;br /&gt;
|-&lt;br /&gt;
| [a] equipment to be removed from organizational spaces for off-site maintenance is sanitized of any CUI. || Artifact || Document or artifact; record if equipment sanitized; categories of sanitization/destruction defined; sanitization procedural document.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MA.L2-3.7.4 – Media Inspection ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MA.L2-3.7.4_Details|&#039;&#039;&#039;MA.L2-3.7.4&#039;&#039;&#039;]] Check media containing diagnostic and test programs for malicious code before the media are used in organizational systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] media containing diagnostic and test programs are checked for malicious code before being used in organizational systems that process, store, or transmit CUI. || Artifact || Screenshot of diagnostic/test program being used (such as Symantec and McAfee on access scans…).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MA.L2-3.7.5 – Nonlocal Maintenance ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MA.L2-3.7.5_Details|&#039;&#039;&#039;MA.L2-3.7.5&#039;&#039;&#039;]] Require multifactor authentication to establish nonlocal maintenance sessions via external network connections and terminate such connections when nonlocal maintenance is complete.&lt;br /&gt;
|-&lt;br /&gt;
| [a] multifactor authentication is used to establish nonlocal maintenance sessions via external network connections. || Screen Share || Describe MFA used to remote from external service to organizational systems for maintenance and screenshot of MFA (3.5.3)(points associated with admin).&lt;br /&gt;
|-&lt;br /&gt;
| [b] nonlocal maintenance sessions established via external network connections are terminated when nonlocal maintenance is complete. || Screen Share || Screenshot VPN session timeout.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MA.L2-3.7.6 – Maintenance Personnel ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MA.L2-3.7.6_Details|&#039;&#039;&#039;MA.L2-3.7.6&#039;&#039;&#039;]] Supervise the maintenance activities of maintenance personnel without required access authorization.&lt;br /&gt;
|-&lt;br /&gt;
| [a] maintenance personnel without required access authorization are supervised during maintenance activities. || Document || System maintenance policy; list of authorized personnel; maintenance records or, contracts/SLAs; WebEx.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Media Protection (MP) ==&lt;br /&gt;
=== MP.L2-3.8.1 – Media Protection ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MP.L2-3.8.1_Details|&#039;&#039;&#039;MP.L2-3.8.1&#039;&#039;&#039;]] Protect (i.e., physically control and securely store) system media containing CUI, both paper and digital.&lt;br /&gt;
|-&lt;br /&gt;
| [a] paper media containing CUI is physically controlled. || Document || Policy showing CUI paper media is controlled; artifact showing who has access; artifacts/records of  inventories conducted; media check out procedures (i.e. file cabinets, encryption, password protection).&lt;br /&gt;
|-&lt;br /&gt;
| [b] digital media containing CUI is physically controlled. || Document || Policy showing CUI digital media is controlled; artifact showing who has access; artifacts/records of inventories conducted; media check out procedures (i.e. file cabinets, external drives, USBs, encryption, password protection).&lt;br /&gt;
|-&lt;br /&gt;
| [c] paper media containing CUI is securely stored. || Physical Review || Check out/sign out sheets; possible photo of storage container/video walk through of storage area; badge reader logs or access lists for keys for secured areas; interview response considered (i.e. file cabinets,  encryption, password protection).&lt;br /&gt;
|-&lt;br /&gt;
| [d] digital media containing CUI is securely stored. || Physical Review || Check out/sign out sheets; possible photo of storage container/video walk through of storage area; badge reader logs or access lists for keys for secured areas; interview response considered (i.e. file cabinets, external drives, USBs, encryption, password protection).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MP.L2-3.8.2 – Media Access ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MP.L2-3.8.2_Details|&#039;&#039;&#039;MP.L2-3.8.2&#039;&#039;&#039;]] Limit access to CUI on system media to authorized users.&lt;br /&gt;
|-&lt;br /&gt;
| [a] access to CUI on system media is limited to authorized users. || Artifact || Document describing how CUI is limited AND artifact showing principle of least access is implemented.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MP.L2-3.8.3 – Media Disposal [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MP.L2-3.8.3_Details|&#039;&#039;&#039;MP.L2-3.8.3&#039;&#039;&#039;]] Sanitize or destroy information system media containing Federal Contract Information before disposal or release for reuse.&lt;br /&gt;
|-&lt;br /&gt;
| [a] system media containing CUI is sanitized or destroyed before disposal. || Document || Policy or artifact of media destruction logs; certificates of destruction; SLAs or contracts.&lt;br /&gt;
|-&lt;br /&gt;
| [b] system media containing CUI is sanitized before it is released for reuse. || Document || Policy or artifact describing method to sanitize, software used (i.e. DoD Wipe, ShredIT and Iron Mountain; Blancco; GDisk, DBAN).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MP.L2-3.8.4 – Media Markings ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MP.L2-3.8.4_Details|&#039;&#039;&#039;MP.L2-3.8.4&#039;&#039;&#039;]] Mark media with necessary CUI markings and distribution limitations.&lt;br /&gt;
|-&lt;br /&gt;
| [a] media containing CUI is marked with applicable CUI markings. || Physical Review || Document or artifact showing CUI markings (i.e. labeling standards ).&lt;br /&gt;
|-&lt;br /&gt;
| [b] media containing CUI is marked with distribution limitations. || Physical Review || Document or artifact showing distro limitations (i.e. labeling standards ).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MP.L2-3.8.5 – Media Accountability ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MP.L2-3.8.5_Details|&#039;&#039;&#039;MP.L2-3.8.5&#039;&#039;&#039;]] Control access to media containing CUI and maintain accountability for media during transport outside of controlled areas.&lt;br /&gt;
|-&lt;br /&gt;
| [a] access to media containing CUI is controlled. || Document || Policy, artifact of audit logs showing tracking, Access Control Lists, records of transport activities (i.e. USB drives, CDs, chain of custody.&lt;br /&gt;
|-&lt;br /&gt;
| [b] accountability for media containing CUI is maintained during transport outside of controlled areas. || Artifact || Artifact of audit logs showing tracking, Access Control Lists, records of transport activities (i.e. USB drives, CDs; chain of custody.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MP.L2-3.8.6 – Portable Storage Encryption ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MP.L2-3.8.6_Details|&#039;&#039;&#039;MP.L2-3.8.6&#039;&#039;&#039;]] Implement cryptographic mechanisms to protect the confidentiality of CUI stored on digital media during transport unless otherwise protected by alternative physical safeguards.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the confidentiality of CUI stored on digital media is protected during transport using cryptographic mechanisms or alternative physical safeguards. || Artifact || Artifact showing crypto mechanisms used to protect (are they FIPS 140-2 [13.11]); artifact showing what alternative physical safeguards are in place (i.e. encryption; BitLocker; McAfee ).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MP.L2-3.8.7 – Removable Media ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MP.L2-3.8.7_Details|&#039;&#039;&#039;MP.L2-3.8.7&#039;&#039;&#039;]] Control the use of removable media on system components.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the use of removable media on system components is controlled. || Artifact || Policy showing if removable media is allowed; writable removable media is restricted; tracking artifacts; what tools are used (i.e. Carbon Black, Crowd Strike, GPO, Zoho Desktop Central); procedure/process describing what happens if it is lost; what mechanisms are in place to control/restrict removable media (i.e. Active Directory Groups and Group Policy artifact showing restriction).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MP.L2-3.8.8 – Shared Media ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MP.L2-3.8.8_Details|&#039;&#039;&#039;MP.L2-3.8.8&#039;&#039;&#039;]] Prohibit the use of portable storage devices when such devices have no identifiable owner.ASSESSMENT OBJECTIVES&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [a] the use of portable storage devices is prohibited when such devices have no identifiable owner. || Artifact || Policy and/or artifact showing company stance on portable storage devices if there is no owner (are personal USB devices allowed or are they company-issued; artifact showing alerts if device is connected to network (i.e. external HDD, Carbon Black, Crowd Strike, GPO, Zoho Desktop Central.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MP.L2-3.8.9 – Protect Backups ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MP.L2-3.8.9_Details|&#039;&#039;&#039;MP.L2-3.8.9&#039;&#039;&#039;]] Protect the confidentiality of backup CUI at storage locations.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the confidentiality of backup CUI is protected at storage locations. || Artifact || Policy on system backups; artifact showing media labeling; artifact showing encyption (is it FIPS 140-2 [13.11]); Access Control List artifact (i.e. backup tapes, Tivoli Storage Manager).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Personnel Security (PS) ==&lt;br /&gt;
=== PS.L2-3.9.1 – Screen Individuals ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_PS.L2-3.9.1_Details|&#039;&#039;&#039;PS.L2-3.9.1&#039;&#039;&#039;]] Screen individuals prior to authorizing access to organizational systems containing CUI.&lt;br /&gt;
|-&lt;br /&gt;
| [a] individuals are screened prior to authorizing access to organizational systems containing CUI. || Artifact || Screenshot of records of screened personnel/background checks.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== PS.L2-3.9.2 – Personnel Actions ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_PS.L2-3.9.2_Details|&#039;&#039;&#039;PS.L2-3.9.2&#039;&#039;&#039;]] Ensure that organizational systems containing CUI are protected during and after personnel actions such as terminations and transfers.&lt;br /&gt;
|-&lt;br /&gt;
| [a] a policy and/or process for terminating system access and any credentials coincident with personnel actions is established. || Document || Personnel security policy/procedures/instruction; Access control policy/procedure/instruction.&lt;br /&gt;
|-&lt;br /&gt;
| [b] system access and credentials are terminated consistent with personnel actions such as termination or transfer. || Artifact || Screenshot of records of personnel transfer and termination actions.&lt;br /&gt;
|-&lt;br /&gt;
| [c] the system is protected during and after personnel transfer actions. || Artifact || Completed outprocessing checklist.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Physical Protection (PE) ==&lt;br /&gt;
=== PE.L2-3.10.1 – Limit Physical Access [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_PE.L2-3.10.1_Details|&#039;&#039;&#039;PE.L2-3.10.1&#039;&#039;&#039;]] Limit physical access to organizational information systems, equipment, and the respective operating environments to authorized individuals.&lt;br /&gt;
|-&lt;br /&gt;
| [a] authorized individuals allowed physical access are identified. || Artifact || Authorized personnel (names) access list.&lt;br /&gt;
|-&lt;br /&gt;
| [b] physical access to organizational systems is limited to authorized individuals. || Physical Review || Badge reader logs, audit logs, and/or card swipe test.&lt;br /&gt;
|-&lt;br /&gt;
| [c] physical access to equipment is limited to authorized individuals. || Physical Review || Badge reader logs, audit logs, and/or card swipe test.&lt;br /&gt;
|-&lt;br /&gt;
| [d] physical access to operating environments is limited to authorized. || Physical Review || Badge reader logs, audit logs, and/or card swipe test.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== PE.L2-3.10.2 – Monitor Facility ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_PE.L2-3.10.2_Details|&#039;&#039;&#039;PE.L2-3.10.2&#039;&#039;&#039;]] Protect and monitor the physical facility and support infrastructure for organizational systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the physical facility where organizational systems reside is protected. || Physical Review || Physical security measures and barriers into the physical facility (cameras/locks/gates/guards, etc.).&lt;br /&gt;
|-&lt;br /&gt;
| [b] the support infrastructure for organizational systems is protected. || Physical Review || Physical barriers to entries into computer spaces, server rooms, etc.&lt;br /&gt;
|-&lt;br /&gt;
| [c] the physical facility where organizational systems reside is monitored. || Physical Review || Audit logs/how the physical facility is being monitored (cameras/access system/guards, etc.).&lt;br /&gt;
|-&lt;br /&gt;
| [d] the support infrastructure for organizational systems is monitored. || Physical Review || Audit logs/how the physical facility is being monitored (cameras/access system/guards, etc.).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== PE.L2-3.10.3 – Escort Visitors [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_PE.L2-3.10.3_Details|&#039;&#039;&#039;PE.L2-3.10.3&#039;&#039;&#039;]] Escort visitors and monitor visitor activity.&lt;br /&gt;
|-&lt;br /&gt;
| [a] visitors are escorted. || Physical Review || Policy/procedures/instruction on methodology for handling non-authorized personnel (entry to exit).&lt;br /&gt;
|-&lt;br /&gt;
| [b] visitor activity is monitored. || Physical Review || Policy/procedures/instructio on methodology for handling non-authorized personnel (entry to exit).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== PE.L2-3.10.4 – Physical Access Logs [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_PE.L2-3.10.4_Details|&#039;&#039;&#039;PE.L2-3.10.4&#039;&#039;&#039;]] Maintain audit logs of physical access.&lt;br /&gt;
|-&lt;br /&gt;
| [a] audit logs of physical access are maintained. || Artifact || Log or report from badging system.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== PE.L2-3.10.5 – Manage Physical Access [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_PE.L2-3.10.5_Details|&#039;&#039;&#039;PE.L2-3.10.5&#039;&#039;&#039;]] Control and manage physical access devices.&lt;br /&gt;
|-&lt;br /&gt;
| [a] physical access devices are identified. || Document || Physical access control systems description, guard force contract/policy, key locks, logical systems specifications, etc.&lt;br /&gt;
|-&lt;br /&gt;
| [b] physical access devices are controlled. || Physical Review || Inventory records of physical access control devices (e.g. keys, locks, card readers, locks, etc.).&lt;br /&gt;
|-&lt;br /&gt;
| [c] physical access devices are managed. || Physical Review || List of security safeguards controlling access to the facility (e.g. cameras, monitoring by guards, isolation of IT systems equiment and or system components).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== PE.L2-3.10.6 – Alternative Work Sites ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_PE.L2-3.10.6_Details|&#039;&#039;&#039;PE.L2-3.10.6&#039;&#039;&#039;]] Enforce safeguarding measures for CUI at alternate work sites.&lt;br /&gt;
|-&lt;br /&gt;
| [a] safeguarding measures for CUI are defined for alternate work sites. || Document || Telework agreement, Acceptable Use Policy and SOP for alternate work locations; user security training validation which includes physical/logical/technical protections of system at alternate work sites.&lt;br /&gt;
|-&lt;br /&gt;
| [b] safeguarding measures for CUI are enforced for alternate work sites. || Artifact || Monitoring/audit log of user activity and logical/physical/technical mechanisms in place to preclude unauthorized activity (telework agreement , AUP?).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Risk Assessment (RA) ==&lt;br /&gt;
=== RA.L2-3.11.1 – Risk Assessments ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_RA.L2-3.11.1_Details|&#039;&#039;&#039;RA.L2-3.11.1&#039;&#039;&#039;]] Periodically assess the risk to organizational operations (including mission, functions, image, or reputation), organizational assets, and individuals, resulting from the operation of organizational systems and the associated processing, storage, or transmission of CUI.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the frequency to assess risk to organizational operations, organizational assets, and individuals is defined. || Document || Risk assessment policy.&lt;br /&gt;
|-&lt;br /&gt;
| [b] risk to organizational operations, organizational assets, and individuals resulting from the operation of an organizational system that processes, stores, or transmits CUI is assessed with the defined frequency. || Artifact || Copy of last risk assessment done within defined frequency.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== RA.L2-3.11.2 – Vulnerability Scan ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_RA.L2-3.11.2_Details|&#039;&#039;&#039;RA.L2-3.11.2&#039;&#039;&#039;]] Scan for vulnerabilities in organizational systems and applications periodically and when new vulnerabilities affecting those systems and applications are identified.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the frequency to scan for vulnerabilities in organizational systems and applications is defined. || Document || Policy/procedures/instruction addressing vulnerability scanning records.&lt;br /&gt;
|-&lt;br /&gt;
| [b] vulnerability scans are performed on organizational systems with the defined frequency. || Screen Share || System configuration settings of vulnerability scanning scheduling and vulnerability scan results of systems within defined frequency.&lt;br /&gt;
|-&lt;br /&gt;
| [c] vulnerability scans are performed on applications with the defined frequency. || Screen Share || System configuration settings of vulnerability scanning scheduling and vulnerability scan results of applications within defined frequency.&lt;br /&gt;
|-&lt;br /&gt;
| [d] vulnerability scans are performed on organizational systems when new vulnerabilities are identified. || Screen Share || View signatures in scanning tool/ad hoc scan performed as a result.&lt;br /&gt;
|-&lt;br /&gt;
| [e] vulnerability scans are performed on applications when new vulnerabilities are identified. || Screen Share || View signatures in scanning tool/ad hoc scan performed as a result.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== RA.L2-3.11.3 – Vulnerability Remediation ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_RA.L2-3.11.3_Details|&#039;&#039;&#039;RA.L2-3.11.3&#039;&#039;&#039;]] Remediate vulnerabilities in accordance with risk assessments.&lt;br /&gt;
|-&lt;br /&gt;
| [a] vulnerabilities are identified. || Artifact || Scan results showing vulnerabilities identified.&lt;br /&gt;
|-&lt;br /&gt;
| [b] vulnerabilities are remediated in accordance with risk assessments. || Artifact || Screenshot/document of scan results of remediated vulnerabilities in accordance to risk assessments.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Security Assessment (CA) ==&lt;br /&gt;
=== CA.L2-3.12.1 – Security Control Assessment ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_CA.L2-3.12.1_Details|&#039;&#039;&#039;CA.L2-3.12.1&#039;&#039;&#039;]] Periodically assess the security controls in organizational systems to determine if the controls are effective in their application.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the frequency of security control assessments is defined. || Document || SSP.&lt;br /&gt;
|-&lt;br /&gt;
| [b] security controls are assessed with the defined frequency to determine if the controls are effective in their application. || Artifact || Copy of last security control assessment done within defined frequency.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== CA.L2-3.12.2 – Operational Plan of Action ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_CA.L2-3.12.2_Details|&#039;&#039;&#039;CA.L2-3.12.2&#039;&#039;&#039;]] Develop and implement plans of action designed to correct deficiencies and reduce or eliminate vulnerabilities in organizational systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] deficiencies and vulnerabilities to be addressed by the plan of action are identified. || Artifact || Plan of Action (POA).&lt;br /&gt;
|-&lt;br /&gt;
| [b] a plan of action is developed to correct identified deficiencies and reduce or eliminate identified vulnerabilities. || Artifact || Plan of Action (POA).&lt;br /&gt;
|-&lt;br /&gt;
| [c] the plan of action is implemented to correct identified deficiencies and reduce or eliminate identified vulnerabilities. || Artifact || Plan of Action (POA)/previously completed POAs.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== CA.L2-3.12.3 – Security Control Monitoring ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_CA.L2-3.12.3_Details|&#039;&#039;&#039;CA.L2-3.12.3&#039;&#039;&#039;]] Monitor security controls on an ongoing basis to ensure the continued effectiveness of the controls.&lt;br /&gt;
|-&lt;br /&gt;
| [a] security controls are monitored on an ongoing basis to ensure the continued effectiveness of those controls. || Artifact || Collection of risk assessment results, internal or third-party audits/security assessments and/or continuous monitoring reports/alerts (SIEM tool, etc.).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== CA.L2-3.12.4 – System Security Plan ====&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_CA.L2-3.12.4_Details|&#039;&#039;&#039;CA.L2-3.12.4&#039;&#039;&#039;]] Develop, document, and periodically update system security plans that describe system boundaries, system environments of operation, how security requirements are implemented, and the relationships with or connections to other systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] a system security plan is developed. || Document || SSP.&lt;br /&gt;
|-&lt;br /&gt;
| [b] the system boundary is described and documented in the system security plan. || Document || SSP and any supporting documentation.&lt;br /&gt;
|-&lt;br /&gt;
| [c] the system environment of operation is described and documented in the system security plan. || Document || SSP and any supporting documentation.&lt;br /&gt;
|-&lt;br /&gt;
| [d] the security requirements identified and approved by the designated authority as non-applicable are identified. || Document || SSP and required adjudication from DoD CIO.&lt;br /&gt;
|-&lt;br /&gt;
| [e] the method of security requirement implementation is described and documented in the system security plan. || Document || SSP and any supporting documentation.&lt;br /&gt;
|-&lt;br /&gt;
| [f] the relationship with or connection to other systems is described and documented in the system security plan. || Document || SSP and any supporting documentation.&lt;br /&gt;
|-&lt;br /&gt;
| [g] the frequency to update the system security plan is defined. || Document || SSP.&lt;br /&gt;
|-&lt;br /&gt;
| [h] system security plan is updated with the defined frequency. || Document || SSP/any previous versions.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== System and Communications Protection (SC) ==&lt;br /&gt;
=== SC.L2-3.13.1 – Boundary Protection [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.1_Details|&#039;&#039;&#039;SC.L2-3.13.1&#039;&#039;&#039;]] Monitor, control, and protect organizational communications (i.e., information transmitted or received by organizational information systems) at the external boundaries and key internal boundaries of the information systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the external system boundary is defined. || Document || SSP, network diagrams, CUI flow, cloud provider FedRAMP Moderate.&lt;br /&gt;
|-&lt;br /&gt;
| [b] key internal system boundaries are defined. || Document || SSP, network diagrams, CUI flow.&lt;br /&gt;
|-&lt;br /&gt;
| [c] communications are monitored at the external system boundary. || Screen Share || SSP, logging server, boundary device configurations, monitoring policy.&lt;br /&gt;
|-&lt;br /&gt;
| [d] communications are monitored at key internal boundaries. || Screen Share || SSP, logging server, boundary device configurations, monitoring policy.&lt;br /&gt;
|-&lt;br /&gt;
| [e] communications are controlled at the external system boundary. || Screen Share || SSP, boundary device configurations, ACL, subnets, DMZ.&lt;br /&gt;
|-&lt;br /&gt;
| [f] communications are controlled at key internal boundaries. || Screen Share || SSP, boundary device configurations, ACL, subnets.&lt;br /&gt;
|-&lt;br /&gt;
| [g] communications are protected at the external system boundary. || Screen Share || Configurations for IPS/IDS, email gateway, VLAN, proxy, firewall, malware protection, DNS, TSL.&lt;br /&gt;
|-&lt;br /&gt;
| [h] communications are protected at key internal boundaries. || Screen Share || Configurations for IPS/IDS, VLAN, firewall, malware protection, SSL.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.2 – Security Engineering ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.2_Details|&#039;&#039;&#039;SC.L2-3.13.2&#039;&#039;&#039;]] Employ architectural designs, software development techniques, and systems engineering principles that promote effective information security within organizational systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] architectural designs that promote effective information security are identified. || Document || SSP, config management policy, network diagram, CCB minutes, enterprise architecture process.&lt;br /&gt;
|-&lt;br /&gt;
| [b] software development techniques that promote effective information security are identified. || Document || SSP, config management policy, SDLC, CCB minutes.&lt;br /&gt;
|-&lt;br /&gt;
| [c] systems engineering principles that promote effective information security are identified. || Document || SSP, config management policy, CCB minutes, security architecture engineering.&lt;br /&gt;
|-&lt;br /&gt;
| [d] identified architectural designs that promote effective information security are employed. || Artifact || CCB minutes, Network diagrams and configurations, Project Plans.&lt;br /&gt;
|-&lt;br /&gt;
| [e] identified software development techniques that promote effective information security are employed. || Artifact || CCB minutes, SDLC, code scanner results, code management tracking.&lt;br /&gt;
|-&lt;br /&gt;
| [f] identified systems engineering principles that promote effective information security are employed. || Artifact || CCB minutes, configuration management, ITSM, patch management, lifecycle replacement processes.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.3 – Role Separation ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.3_Details|&#039;&#039;&#039;SC.L2-3.13.3&#039;&#039;&#039;]] Separate user functionality from system management functionality.&lt;br /&gt;
|-&lt;br /&gt;
| [a] user functionality is identified. || Document || SSP, AUP.&lt;br /&gt;
|-&lt;br /&gt;
| [b] system management functionality is identified. || Document || SSP, Privileged Account Agreement.&lt;br /&gt;
|-&lt;br /&gt;
| [c] user functionality is separated from system management functionality. || Screen Share || Active Directory, Jump Boxes, GPO, VM, RDP.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.4 – Shared Resource Control ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.4_Details|&#039;&#039;&#039;SC.L2-3.13.4&#039;&#039;&#039;]] Prevent unauthorized and unintended information transfer via shared system resources.&lt;br /&gt;
|-&lt;br /&gt;
| [a] unauthorized and unintended information transfer via shared system resources is prevented. || Screen Share || SSP, OS configurations, Linux containers, system/media reuse policies, certificate management policies, media destruction policies, printer configs, VDI configuration.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
===  SC.L2-3.13.5 – Public-Access System Separation [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.5_Details|&#039;&#039;&#039;SC.L2-3.13.5&#039;&#039;&#039;]] Implement subnetworks for publicly accessible system components that are physically or logically separated from internal networks.&lt;br /&gt;
|-&lt;br /&gt;
| [a] publicly accessible system components are identified. || Document || SSP, network diagram, DMZ inventory/roles.&lt;br /&gt;
|-&lt;br /&gt;
| [b] subnetworks for publicly accessible system components are physically or logically separated from internal networks. || Artifact || Network diagram, IPAM, VLAN, DHCP, DMZ.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.6 – Network Communication by Exception ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.6_Details|&#039;&#039;&#039;SC.L2-3.13.6&#039;&#039;&#039;]] Deny network communications traffic by default and allow network communications traffic by exception (i.e., deny all, permit by exception).&lt;br /&gt;
|-&lt;br /&gt;
| [a] network communications traffic is denied by default. || Screen Share || Host and network firewall rules, SIEM logs, hit counts.&lt;br /&gt;
|-&lt;br /&gt;
| [b] network communications traffic is allowed by exception. || Screen Share || Host and network firewall rules, SIEM logs, hit counts.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.7 – Split Tunneling ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.7_Details|&#039;&#039;&#039;SC.L2-3.13.7&#039;&#039;&#039;]] Prevent remote devices from simultaneously establishing non-remote connections with organizational systems and communicating via some other connection to resources in external networks (i.e., split tunneling).&lt;br /&gt;
|-&lt;br /&gt;
| [a] remote devices are prevented from simultaneously establishing non-remote connections with the system and communicating via some other connection to resources in external networks (i.e., split tunneling). || Screen Share || VPN appliance/server configuration, endpoint VPN software configuration.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.8 – Data in Transit ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.8_Details|&#039;&#039;&#039;SC.L2-3.13.8&#039;&#039;&#039;]] Implement cryptographic mechanisms to prevent unauthorized disclosure of CUI during transmission unless otherwise protected by alternative physical safeguards.&lt;br /&gt;
|-&lt;br /&gt;
| [a] cryptographic mechanisms intended to prevent unauthorized disclosure of CUI are identified. || Document || SSP, PKI policies, configuration processes, config management, email attachment encryption policy, removable media policy, data at rest policy.&lt;br /&gt;
|-&lt;br /&gt;
| [b] alternative physical safeguards intended to prevent unauthorized disclosure of CUI are identified. || Document || SSP, physical security policy.&lt;br /&gt;
|-&lt;br /&gt;
| [c] either cryptographic mechanisms or alternative physical safeguards are implemented to prevent unauthorized disclosure of CUI during transmission. || Screen Share || TLS settings, SSL settings, VPN/Wireless Access Points/Mobile Devices cryptographic settings, ODBC connector settings, SAN configuration, IPSec/MPLS, backup configuration, physical security.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.9 – Connections Termination ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.9_Details|&#039;&#039;&#039;SC.L2-3.13.9&#039;&#039;&#039;]] Terminate network connections associated with communications sessions at the end of the sessions or after a defined period of inactivity.&lt;br /&gt;
|-&lt;br /&gt;
| [a] a period of inactivity to terminate network connections associated with communications sessions is defined. || Document || SSP, network communications policy.&lt;br /&gt;
|-&lt;br /&gt;
| [b] network connections associated with communications sessions are terminated at the end of the sessions. || Screen Share || VPN appliance/server logs, VPN configurations, web server configurations, firewall connection settings.&lt;br /&gt;
|-&lt;br /&gt;
| [c] network connections associated with communications sessions are terminated after the defined period of inactivity. || Screen Share || VPN appliance/server logs, VPN configurations, web server configurations, frewall connection settings.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.10 – Key Management ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.10_Details|&#039;&#039;&#039;SC.L2-3.13.10&#039;&#039;&#039;]] Establish and manage cryptographic keys for cryptography employed in organizational systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] cryptographic keys are established whenever cryptography is employed. || Artifact || SSP, PKI/certificate management policy, configuration management.&lt;br /&gt;
|-&lt;br /&gt;
| [b] cryptographic keys are managed whenever cryptography is employed. || Artifact || SSP, PKI/certificate management policy, configuration management, access control policy.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.11 – CUI Encryption ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.11_Details|&#039;&#039;&#039;SC.L2-3.13.11&#039;&#039;&#039;]] Employ FIPS-validated cryptography when used to protect the confidentiality of CUI.&lt;br /&gt;
|-&lt;br /&gt;
| [a] FIPS-validated cryptography is employed to protect the confidentiality of CUI. || Screen Share || VPN, wireless, mobile devices, client certificates, server certificates, disk encryption, Outlook plugin, external mail, backup media, ePO server, removable storage, SAN, file compression; look for FIPS mode enabled on appliances.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.12 – Collaborative Device Control ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.12_Details|&#039;&#039;&#039;SC.L2-3.13.12&#039;&#039;&#039;]] Prohibit remote activation of collaborative computing devices and provide indication of devices in use to users present at the device.&lt;br /&gt;
|-&lt;br /&gt;
| [a] collaborative computing devices are identified. || Document || SSP, network diagrams.&lt;br /&gt;
|-&lt;br /&gt;
| [b] collaborative computing devices provide indication to users of devices in use. || Physical Review || Physical inspection of device.&lt;br /&gt;
|-&lt;br /&gt;
| [c] remote activation of collaborative computing devices is prohibited. || Screen Share || Collaboration device configuration/console.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.13 – Mobile Code ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.13_Details|&#039;&#039;&#039;SC.L2-3.13.13&#039;&#039;&#039;]] Control and monitor the use of mobile code.&lt;br /&gt;
|-&lt;br /&gt;
| [a] use of mobile code is controlled. || Screen Share || GPO settings, malware protection, software agent configurations, software development policies, code scanners, MDM configuration, firewall/secure web gateway/proxy config.&lt;br /&gt;
|-&lt;br /&gt;
| [b] use of mobile code is monitored. || Screen Share || SIEM/console monitoring.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.14 – Voice over Internet Protocol ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.14_Details|&#039;&#039;&#039;SC.L2-3.13.14&#039;&#039;&#039;]] Control and monitor the use of Voice over Internet Protocol (VoIP) technologies.&lt;br /&gt;
|-&lt;br /&gt;
| [a] use of Voice over Internet Protocol (VoIP) technologies is controlled. || Artifact || VLAN, ACL, firewall config, VoIP gateway/condenser configuration.&lt;br /&gt;
|-&lt;br /&gt;
| [b] use of Voice over Internet Protocol (VoIP) technologies is monitored. || Artifact || SIEM/VoIP console monitoring, session border controller.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.15 – Communications Authenticity ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.15_Details|&#039;&#039;&#039;SC.L2-3.13.15&#039;&#039;&#039;]] Protect the authenticity of communications sessions.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the authenticity of communications sessions is protected. || Screen Share || SSL, TLS, SMB3, SFTP, IPSec, SSH, Kerberos configs, MPLS, Network Access Control.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.16 – Data at Rest ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.16_Details|&#039;&#039;&#039;SC.L2-3.13.16&#039;&#039;&#039;]] Protect the confidentiality of CUI at rest.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the confidentiality of CUI at rest is protected. || Artifact || Full disk encryption, removable media encryption, SAN encryption, digital backups, mobile device encryption, third party offsite backup storage, cloud virtualization encryption, physical media storage policies.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== System and Information Integrity (SI) ==&lt;br /&gt;
=== SI.L2-3.14.1 – Flaw Remediation [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SI.L2-3.14.1_Details|&#039;&#039;&#039;SI.L2-3.14.1&#039;&#039;&#039;]] Identify, report, and correct information and information system flaws in a timely manner.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the time within which to identify system flaws is specified. || Document || SSP, patch management policy.&lt;br /&gt;
|-&lt;br /&gt;
| [b] system flaws are identified within the specified time frame. || Screen Share || Vulnerability management scanner output and scan policy configuration.&lt;br /&gt;
|-&lt;br /&gt;
| [c] the time within which to report system flaws is specified. || Document || SSP, patch management policy.&lt;br /&gt;
|-&lt;br /&gt;
| [d] system flaws are reported within the specified time frame. || Screen Share || ITSM/trouble tickets, vulnerability management scanner output.&lt;br /&gt;
|-&lt;br /&gt;
| [e] the time within which to correct system flaws is specified. || Document || SSP, patch management policy.&lt;br /&gt;
|-&lt;br /&gt;
| [f] system flaws are corrected within the specified time frame. || Screen Share || Vulnerability management scanner output and scan policy configuration.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SI.L2-3.14.2 – Malicious Code ProTection [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SI.L2-3.14.2_Details|&#039;&#039;&#039;SI.L2-3.14.2&#039;&#039;&#039;]] Provide protection from malicious code at appropriate locations within organizational information systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] designated locations for malicious code protection are identified. || Document || SSP, system protection policy, network diagrams, security architecture documents.&lt;br /&gt;
|-&lt;br /&gt;
| [b] protection from malicious code at designated locations is provided. || Screen Share || Endpoint security settings, email/web proxy gateways, firewall, IPS sensor, MDM configuration, Network Access Control.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SI.L2-3.14.3 – Security Alerts &amp;amp; Advisories ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SI.L2-3.14.3_Details|&#039;&#039;&#039;SI.L2-3.14.3&#039;&#039;&#039;]] Monitor system security alerts and advisories and take action in response.&lt;br /&gt;
|-&lt;br /&gt;
| [a] response actions to system security alerts and advisories are identified. || Document || SSP, vulnerability management policy, Incident Response Plan.&lt;br /&gt;
|-&lt;br /&gt;
| [b] system security alerts and advisories are monitored. || Artifact || Threat intelligence subscriptions, email advisories.&lt;br /&gt;
|-&lt;br /&gt;
| [c] actions in response to system security alerts and advisories are taken. || Artifact || ITSM/trouble tickets, user notifications, updates to firewall/IPS, etc.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SI.L2-3.14.4 – Update Malicious Code Protection [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SI.L2-3.14.4_Details|&#039;&#039;&#039;SI.L2-3.14.4&#039;&#039;&#039;]] Update malicious code protection mechanisms when new releases are available.&lt;br /&gt;
|-&lt;br /&gt;
| [a] malicious code protection mechanisms are updated when new releases are available. || Screen Share || Antivirus console dashboard, firewall AV, Email gateway signatures,proxy, IPS updates.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SI.L2-3.14.5 – System &amp;amp; File Scanning [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SI.L2-3.14.5_Details|&#039;&#039;&#039;SI.L2-3.14.5&#039;&#039;&#039;]] Perform periodic scans of the information system and real-time scans of files from external sources as files are downloaded, opened, or executed.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the frequency for malicious code scans is defined. || Document || SSP, vulnerability management policy.&lt;br /&gt;
|-&lt;br /&gt;
| [b] malicious code scans are performed with the defined frequency. || Screen Share || Consoles for AV (endpoints, servers, and file shares), firewall, email gateway, proxy, IPS, MDM configurations.&lt;br /&gt;
|-&lt;br /&gt;
| [c] real-time malicious code scans of files from external sources as files are downloaded, opened, or executed are performed. || Screen Share || Consoles for AV (endpoints, servers, and file shares), firewall, email gateway, proxy, IPS, MDM configurations.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SI.L2-3.14.6 – Monitor Communications for Attacks ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SI.L2-3.14.6_Details|&#039;&#039;&#039;SI.L2-3.14.6&#039;&#039;&#039;]] Monitor organizational systems, including inbound and outbound communications traffic, to detect attacks and indicators of potential attacks.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the system is monitored to detect attacks and indicators of potential attacks. || Screen Share || Firewall, IPS, endpoint protection, SIEM alerts and reports.&lt;br /&gt;
|-&lt;br /&gt;
| [b] inbound communications traffic is monitored to detect attacks and indicators of potential attacks. || Screen Share || Firewall, IPS, endpoint protection, SIEM alerts and reports.&lt;br /&gt;
|-&lt;br /&gt;
| [c] outbound communications traffic is monitored to detect attacks and indicators of potential attacks. || Screen Share || Firewall, IPS, endpoint protection, SIEM alerts and reports.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SI.L2-3.14.7 – Identify Unauthorized Use ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SI.L2-3.14.7_Details|&#039;&#039;&#039;SI.L2-3.14.7&#039;&#039;&#039;]] Identify unauthorized use of organizational systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] authorized use of the system is defined. || Document || AUP, SSP.&lt;br /&gt;
|-&lt;br /&gt;
| [b] unauthorized use of the system is identified. || Artifact || SIEM logs, endpoint protection console, IPS, Firewall.&lt;br /&gt;
|}&lt;/div&gt;</summary>
		<author><name>David</name></author>
	</entry>
	<entry>
		<id>https://cmmcwiki.org/index.php?title=Evidence_Collection_Approach&amp;diff=1614</id>
		<title>Evidence Collection Approach</title>
		<link rel="alternate" type="text/html" href="https://cmmcwiki.org/index.php?title=Evidence_Collection_Approach&amp;diff=1614"/>
		<updated>2026-07-20T01:33:54Z</updated>

		<summary type="html">&lt;p&gt;David: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;CMMC assessments and certification require substantial evidence and documentation. The following tables outline general guidelines for collecting evidence to assess control requirements and objectives. While these guidelines provide a structured approach, they are not the only means of conducting an accurate assessment. Assessors should exercise professional judgment and may employ alternative methods appropriate to the specific organizational context and circumstances.&lt;br /&gt;
&lt;br /&gt;
Evidence collection approaches are defined as:&lt;br /&gt;
* &#039;&#039;&#039;Documentation&#039;&#039;&#039;: Tangible materials containing information over which an organization has authority, including all types of written records and their copies.&lt;br /&gt;
* &#039;&#039;&#039;Artifacts&#039;&#039;&#039;: Tangible, reviewable records directly resulting from a practice or process being performed by a system or by personnel executing their role within that practice, control, or process.&lt;br /&gt;
* &#039;&#039;&#039;Physical Review&#039;&#039;&#039;: Direct on-site observation and examination of evidence.&lt;br /&gt;
* &#039;&#039;&#039;Screen Share&#039;&#039;&#039;: Real-time remote observation of a user demonstrating a task or process via shared computer screen, sometimes called &amp;quot;over-the-shoulder&amp;quot; review.&lt;br /&gt;
&lt;br /&gt;
DISCLAIMER: Evidence requirements vary significantly across assessment types. &#039;&#039;&#039;The examples provided are illustrative only and should be tailored to meet the specific adequacy and sufficiency standards of your particular assessment context.&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
For inquiries and reporting errors on this wiki, please [mailto:support@cmmctoolkit.org contact us]. Thank you.&lt;br /&gt;
&lt;br /&gt;
== Access Control (AC) ==&lt;br /&gt;
=== AC.L2-3.1.1 – Authorized Access Control [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;width: 85%;&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.1_Details|&#039;&#039;&#039;AC.L2-3.1.1&#039;&#039;&#039;]] Limit information system access to authorized users, processes acting on behalf of authorized users, or devices (including other information systems).&lt;br /&gt;
|-&lt;br /&gt;
| [a] authorized users are identified. || Document || Document defining account request, approval, provisioning.&lt;br /&gt;
|-&lt;br /&gt;
| [b] processes acting on behalf of authorized users are identified. || Document || Document defining account request, approval, provisioning.&lt;br /&gt;
|-&lt;br /&gt;
| [c] devices (and other systems) authorized to connect to the system are identified. || Document || Document defining account request, approval, provisioning.&lt;br /&gt;
|-&lt;br /&gt;
| [d] system access is limited to authorized users. || Screen Share || Screen share showing login requirements are enforced. Example of an unauthorized user denied (unauthorized username entered at login).&lt;br /&gt;
|-&lt;br /&gt;
| [e] system access is limited to processes acting on behalf of authorized users. || Screen Share || Screenshot showing that service accounts are assigned to authorized users only; no rogue accounts without an authorized user are active.&lt;br /&gt;
|-&lt;br /&gt;
| [f] system access is limited to authorized devices (including other systems). || Screen Share || Screen share showing that all devices running are authorized; no rogue devices on the network.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.2 – Transaction &amp;amp; Function Control [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;width: 85%;&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.2_Details|&#039;&#039;&#039;AC.L2-3.1.2&#039;&#039;&#039;]] Limit information system access to the types of transactions and functions that authorized users are permitted to execute.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the types of transactions and functions that authorized users are permitted to execute are defined. || Document || SSP, AUP, or IAM document that defines what authorized users can execute.&lt;br /&gt;
|-&lt;br /&gt;
| [b] system access is limited to the defined types of transactions and functions for authorized users. || Screen Share || Screenshot of security roles in AD or IAM or other directory-based identity-related services tool that shows transactions are as defined in the SSP or IAM document; privileged and non-privileged accounts need to be defined and identified in the artifact; screenshot of a non-privileged user trying to execute a privileged function.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.3 – Control CUI Flow ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;width: 85%;&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.3_Details|&#039;&#039;&#039;AC.L2-3.1.3&#039;&#039;&#039;]] Control the flow of CUI in accordance with approved authorizations.&lt;br /&gt;
|-&lt;br /&gt;
| [a] information flow control policies are defined. || Document || SSP or other document describing the control of CUI on the network.&lt;br /&gt;
|-&lt;br /&gt;
| [b] methods and enforcement mechanisms for controlling the flow of CUI are defined. || Document || Document that defines the networking devices that are on the CUI network and answers what measures are in place to control the flow. List of firewalls, border and internal layer 3 devices, IDS/IPS, DLP, that process CUI.&lt;br /&gt;
|-&lt;br /&gt;
| [c] designated sources and destinations (e.g., networks, individuals, and devices) for CUI within the system and between interconnected systems are identified. || Artifact || Network diagram, data flow diagram, external system connection diagrams, document describing the policies for CUI on the network; listing of VLANs and subnets where CUI is authorized; document must describe source and authorized destinations.&lt;br /&gt;
|-&lt;br /&gt;
| [d] authorizations for controlling the flow of CUI are defined. || Document || Document that defines how CUI is to be controlled, such as an InfoSec plan, and/or network management plan.&lt;br /&gt;
|-&lt;br /&gt;
| [e] approved authorizations for controlling the flow of CUI are enforced. || Screen Share || Screenshots of firewall rules, ACLs, etc.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.4 – Separation of Duties ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;width: 85%;&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.4_Details|&#039;&#039;&#039;AC.L2-3.1.4&#039;&#039;&#039;]] Separate the duties of individuals to reduce the risk of malevolent activity without collusion.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the duties of individuals requiring separation are defined. || Document || Document, SSP, account management policy, defining separation of duties by person or role.&lt;br /&gt;
|-&lt;br /&gt;
| [b] responsibilities for duties that require separation are assigned to separate individuals. || Screen Share || Screenshot showing that separation of duties is enforced by showing admin accounts are assigned to different people based on role.&lt;br /&gt;
|-&lt;br /&gt;
| [c] access privileges that enable individuals to exercise the duties that require separation are granted to separate individuals. || Screen Share || Screen shot showing an example such as a security manager can not log into a network device and change ACLs, or network admins can not access security logs in the SIEM tool.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.5 – Least Privilege ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;width: 85%;&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.5_Details|&#039;&#039;&#039;AC.L2-3.1.5&#039;&#039;&#039;]] Employ the principle of least privilege, including for specific security functions and privileged accounts.&lt;br /&gt;
|-&lt;br /&gt;
| [a] privileged accounts are identified. || Document || &amp;quot;SSP or policy (documentation) identify what is considered a privileged account.&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| [b] access to privileged accounts is authorized in accordance with the principle of least privilege. || Artifact || An artifact that identifies the least amount of permissions associated with different types of privileged accounts are approved.&lt;br /&gt;
|-&lt;br /&gt;
| [c] security functions are identified. || Document || &amp;quot;SSP or policy (documentation) identifies what is considered a security account.&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| [d] access to security functions is authorized in accordance with the principle of least privilege. || Artifact || Artifact(s) that identify the least amount of permissions associated with different types of security accounts are approved.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.6 – Non-Privileged Account Use ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;width: 85%;&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.6_Details|&#039;&#039;&#039;AC.L2-3.1.6&#039;&#039;&#039;]] Use non-privileged accounts or roles when accessing nonsecurity functions.&lt;br /&gt;
|-&lt;br /&gt;
| [a] nonsecurity functions are identified. || Document || SSP or account management document, AUP, that defines non-security functions.&lt;br /&gt;
|-&lt;br /&gt;
| [b] users are required to use non-privileged accounts or roles when accessing nonsecurity functions. || Screen Share || Screenshot showing that a privileged user tried to use their admin account to access a non-security function, such as a browser or email (whatever is defined in their policy) and was blocked.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.7 – Privileged Functions ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;width: 85%;&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.7_Details|&#039;&#039;&#039;AC.L2-3.1.7&#039;&#039;&#039;]] Prevent non-privileged users from executing privileged functions and capture the execution of such functions in audit logs.&lt;br /&gt;
|-&lt;br /&gt;
| [a] privileged functions are defined. || Document || SSP or policy (documentation) that defines privileged functions.&lt;br /&gt;
|-&lt;br /&gt;
| [b] non-privileged users are defined. || Document || SSP or policy (documentation) that defines non-privileged users.&lt;br /&gt;
|-&lt;br /&gt;
| [c] non-privileged users are prevented from executing privileged functions. || Screen Share || Screen share that shows that a non-privileged user is not allowed to complete a privileged function (installing software).&lt;br /&gt;
|-&lt;br /&gt;
| [d] the execution of privileged functions is captured in audit logs. || Screen Share || Screen share that shows logs being captured of the execution of privileged functions.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.8 – Unsuccessful Logon Attempts ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;width: 85%;&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.8_Details|&#039;&#039;&#039;AC.L2-3.1.8&#039;&#039;&#039;]] Limit unsuccessful logon attempts.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the means of limiting unsuccessful logon attempts is defined. || Document || SSP or policy (documentation) showing unsuccessful logon attempts settings and or policy.&lt;br /&gt;
|-&lt;br /&gt;
| [b] the defined means of limiting unsuccessful logon attempts is implemented. || Artifact || Artifact showing GPO / Policy for limiting logon attempts.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.9 – Privacy &amp;amp; Security Notices ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;width: 85%;&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.9_Details|&#039;&#039;&#039;AC.L2-3.1.9&#039;&#039;&#039;]] Provide privacy and security notices consistent with applicable CUI rules.&lt;br /&gt;
|-&lt;br /&gt;
| [a] privacy and security notices required by CUI-specified rules are identified, consistent, and associated with the specific CUI category. || Document || SSP or policy (documentation) showing CUI-specified rules are identified, consistent, and associated with the specific CUI category.&lt;br /&gt;
|-&lt;br /&gt;
| [b] privacy and security notices are displayed. || Artifact || Artifact that shows a consent banner or screen that a user sees as they log in to the system.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.10 – Session Lock ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;width: 85%;&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.10_Details|&#039;&#039;&#039;AC.L2-3.1.10&#039;&#039;&#039;]] Use session lock with pattern-hiding displays to prevent access and viewing of data after a period of inactivity.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the period of inactivity after which the system initiates a session lock is defined. || Document || SSP or policy (documentation) that defines the period of inactivity and when a session lock is defined.&lt;br /&gt;
|-&lt;br /&gt;
| [b] access to the system and viewing of data is prevented by initiating a session lock after the defined period of inactivity. || Artifact || Artifact that shows the setting of session lock (GPO or system policy or similar solution addressing the controls supporting centralized management and configuration of operating systems, applications, and users&#039; settings for the working environment of user accounts and computer accounts).&lt;br /&gt;
|-&lt;br /&gt;
| [c] previously visible information is concealed via a pattern-hiding display after the defined period of inactivity. || Artifact || Screenshot of GPO setting and configuration settings, or similar solution addressing the controls supporting centralized management and configuration of operating systems, applications, and users&#039; settings for the working environment of user accounts and computer accounts.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.11 – Session Termination ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;width: 85%;&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.11_Details|&#039;&#039;&#039;AC.L2-3.1.11&#039;&#039;&#039;]] Terminate (automatically) a user session after a defined condition.&lt;br /&gt;
|-&lt;br /&gt;
| [a] conditions requiring a user session to terminate are defined. || Document || SSP or policy (documentation) that defines the conditions requiring a user session to be terminated.&lt;br /&gt;
|-&lt;br /&gt;
| [b] a user session is automatically terminated after any of the defined conditions. || Screen Share || Screen share showing GPO / VPN Settings that show when a session would be terminated (Idle time, max connection time).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.12 – Control Remote Access ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;width: 85%;&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.12_Details|&#039;&#039;&#039;AC.L2-3.1.12&#039;&#039;&#039;]] Monitor and control remote access sessions.&lt;br /&gt;
|-&lt;br /&gt;
| [a] remote access sessions are permitted. || Document || SSP or policy (documentation) that defines remote access sessions.&lt;br /&gt;
|-&lt;br /&gt;
| [b] the types of permitted remote access are identified. || Document || SSP or policy (documentation) that defines remote access is permitted.&lt;br /&gt;
|-&lt;br /&gt;
| [c] remote access sessions are controlled. || Screen Share || Screen share that shows how the remote access is controlled (access session, and or groups).&lt;br /&gt;
|-&lt;br /&gt;
| [d] remote access sessions are monitored. || Screen Share || Screen share that shows how remote sessions are monitored (logs).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.13 – Remote Access Confidentiality ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;width: 85%;&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.13_Details|&#039;&#039;&#039;AC.L2-3.1.13&#039;&#039;&#039;]] Employ cryptographic mechanisms to protect the confidentiality of remote access sessions.&lt;br /&gt;
|-&lt;br /&gt;
| [a] cryptographic mechanisms to protect the confidentiality of remote access sessions are identified. || Document || SSP or policy (documentation) that discusses the CUI rules, consistent, and associated with the specific CUI category; FIPS Cert # of appliance or application.&lt;br /&gt;
|-&lt;br /&gt;
| [b] cryptographic mechanisms to protect the confidentiality of remote access sessions are implemented. || Screen Share || Screenshot of VPN concentration that shows encryption is on and enabled (point-to-point, etc.).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.14 – Remote Access Routing ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;width: 85%;&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.14_Details|&#039;&#039;&#039;AC.L2-3.1.14&#039;&#039;&#039;]] Route remote access via managed access control points.&lt;br /&gt;
|-&lt;br /&gt;
| [a] managed access control points are identified and implemented. || Screen Share || Screen share that shows access control points (groups and/or users).&lt;br /&gt;
|-&lt;br /&gt;
| [b] remote access is routed through managed network access control points. || Screen Share || Screen share that shows access control points and how they are managed.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.15 – Privileged Remote Access ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;width: 85%;&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.15_Details|&#039;&#039;&#039;AC.L2-3.1.15&#039;&#039;&#039;]] Authorize remote execution of privileged commands and remote access to security-relevant information.&lt;br /&gt;
|-&lt;br /&gt;
| [a] privileged commands authorized for remote execution are identified. || Document || SSP or policy (documentation) that defines what is authorized to be executed remotely and how that is handled.&lt;br /&gt;
|-&lt;br /&gt;
| [b] security-relevant information authorized to be accessed remotely is identified. || Document || SSP or policy (documentation) that defines what can be accessed remotely and what procedures are implemented to allow this (RDP, jump box).&lt;br /&gt;
|-&lt;br /&gt;
| [c] the execution of the identified privileged commands via remote access is authorized. || Screen Share || Screen share that shows who has access to perform privileged commands a remotely (access groups for privileged accounts).&lt;br /&gt;
|-&lt;br /&gt;
| [d] access to the identified security-relevant information via remote access is authorized. || Screen Share || Screen share that shows the routing of remote access and how it is monitored and how many locations (Firewall, VPN Concentrator).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.16 – Wireless Access Authorization ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;width: 85%;&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.16_Details|&#039;&#039;&#039;AC.L2-3.1.16&#039;&#039;&#039;]] Authorize wireless access prior to allowing such connections.&lt;br /&gt;
|-&lt;br /&gt;
| [a] wireless access points are identified. || Document || SSP, network administration document.&lt;br /&gt;
|-&lt;br /&gt;
| [b] wireless access is authorized prior to allowing such connections. || Screen Share || Authorization profile(s) in Wireless Access Controller or Identity Manager (i.e. Cisco ISE).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.17 – Wireless Access Protection ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;width: 85%;&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.17_Details|&#039;&#039;&#039;AC.L2-3.1.17&#039;&#039;&#039;]] Protect wireless access using authentication and encryption.&lt;br /&gt;
|-&lt;br /&gt;
| [a] wireless access to the system is protected using authentication. || Screen Share || Security page (or similar) of a Wireless Access Controller.&lt;br /&gt;
|-&lt;br /&gt;
| [b] wireless access to the system is protected using encryption. || Screen Share || Security page (or similar) of a Wireless Access Controller.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.18 – Mobile Device Connection ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;width: 85%;&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.18_Details|&#039;&#039;&#039;AC.L2-3.1.18&#039;&#039;&#039;]] Control connection of mobile devices.&lt;br /&gt;
|-&lt;br /&gt;
| [a] mobile devices that process, store, or transmit CUI are identified. || Document || SSP, Mobile Device Policy.&lt;br /&gt;
|-&lt;br /&gt;
| [b] mobile device connections are authorized. || Screen Share || Authorization profile(s) in Wireless Access Controller or Identity Manager (i.e. Cisco ISE).&lt;br /&gt;
|-&lt;br /&gt;
| [c] mobile device connections are monitored and logged. || Screen Share || Mobile device logs within the MDM, log intake (sources) configuration (within SIEM) showing MDM is feeding logs to the SIEM.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.19 – Encrypt CUI on Mobile ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;width: 85%;&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.19_Details|&#039;&#039;&#039;AC.L2-3.1.19&#039;&#039;&#039;]] Encrypt CUI on mobile devices and mobile computing platforms.&lt;br /&gt;
|-&lt;br /&gt;
| [a] mobile devices and mobile computing platforms that process, store, or transmit CUI are identified. || Document || SSP, Mobile Device Policy.&lt;br /&gt;
|-&lt;br /&gt;
| [b] encryption is employed to protect CUI on identified mobile devices and mobile computing platforms. || Screen Share || Security policy page in MDM showing how encryption are enforced on mobile device. If no MDM or MDM doesn&#039;t enforce encryption, then validate if the devices used are on the list of devices with native FIPS approved validation.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.20 – External Connections [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;width: 85%;&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.20_Details|&#039;&#039;&#039;AC.L2-3.1.20&#039;&#039;&#039;]] Verify and control/limit connections to and use of external information systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] connections to external systems are identified. || Document || SSP, Systems Interconnection Agreements, SLA.&lt;br /&gt;
|-&lt;br /&gt;
| [b] the use of external systems is identified. || Document || SSP, Systems Interconnection Agreements, SLA.&lt;br /&gt;
|-&lt;br /&gt;
| [c] connections to external systems are verified. || Artifact || SLA for external systems, memorandum for interconnection, information to prove that any cloud solution is at FedRAMP impact level of moderate or higher (i.e. license information, screenshot of AWS cloud dashboard, purchase order document).&lt;br /&gt;
|-&lt;br /&gt;
| [d] the use of external systems is verified. || Artifact || SLA for external systems, memorandum for interconnection, information to prove that any cloud solution is at FedRAMP impact level of moderate or higher (i.e. license information, screenshot of AWS cloud dashboard, purchase order document).&lt;br /&gt;
|-&lt;br /&gt;
| [e] connections to external systems are controlled/limited. || Screen Share || Firewall ruleset for controlling access to cloud service or external system.&lt;br /&gt;
|-&lt;br /&gt;
| [f] the use of external systems is controlled/limited. || Screen Share || Firewall ruleset for controlling access to cloud service or external system.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.21 – Portable Storage Use ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;width: 85%;&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.21_Details|&#039;&#039;&#039;AC.L2-3.1.21&#039;&#039;&#039;]] Limit use of portable storage devices on external systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the use of portable storage devices containing CUI on external systems is identified and documented. || Document || SSP, Removable Media Policy, Acceptable Use Policy (with emphasis on portable media use).&lt;br /&gt;
|-&lt;br /&gt;
| [b] limits on the use of portable storage devices containing CUI on external systems are defined. || Document || SSP, Removable Media Policy, Acceptable Use Policy (with emphasis on portable media use).&lt;br /&gt;
|-&lt;br /&gt;
| [c] the use of portable storage devices containing CUI on external systems is limited as defined. || Document || SSP, Removable Media Policy, Acceptable Use Policy (with emphasis on portable media use).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.22 – Control Public Information [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;width: 85%;&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AC.L2-3.1.22_Details|&#039;&#039;&#039;AC.L2-3.1.22&#039;&#039;&#039;]] Control information posted or processed on publicly accessible information systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] individuals authorized to post or process information on publicly accessible systems are identified. || Document || SSP, Website Governance Plan, Information Release Document.&lt;br /&gt;
|-&lt;br /&gt;
| [b] procedures to ensure CUI is not posted or processed on publicly accessible systems are identified. || Document || SSP, Website Governance Plan, Information Release Document.&lt;br /&gt;
|-&lt;br /&gt;
| [c] a review process is in place prior to posting of any content to publicly accessible systems. || Artifact || &amp;quot;Information release approval process, i.e. chain of email communication from originator, approver, and final decision (may or may not include individual authorized to post); &lt;br /&gt;
SharePoint/electronic or paper form/ ticket system showing information flow between requestor and approver (may or may not include  individual authorized to post).&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| [d] content on publicly accessible systems is reviewed to ensure that it does not include CUI. || Artifact || Incident response process, web design/update/modification SOP etc.&lt;br /&gt;
|-&lt;br /&gt;
| [e] mechanisms are in place to remove and address improper posting of CUI. || Artifact || Incident response process, web design/update/modification SOP etc.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Awareness and Training (AT) ==&lt;br /&gt;
=== AT.L2-3.2.1 – Role-Based Risk Awareness ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;width: 85%;&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AT.L2-3.2.1_Details|&#039;&#039;&#039;AT.L2-3.2.1&#039;&#039;&#039;]] Ensure that managers, systems administrators, and users of organizational systems are made aware of the security risks associated with their activities and of the applicable policies, standards, and procedures related to the security of those systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] security risks associated with organizational activities involving CUI are identified. || Document || Policy of Security Awareness Training; Security Awareness Training Briefing.&lt;br /&gt;
|-&lt;br /&gt;
| [b] policies, standards, and procedures related to the security of the system are identified. || Document || Acceptable Use Policy, Policy/Procedures/Instruction related to the security of the system.&lt;br /&gt;
|-&lt;br /&gt;
| [c] managers, systems administrators, and users of the system are made aware of the security risks associated with their activities. || Artifact || Security Training Brief, training records.&lt;br /&gt;
|-&lt;br /&gt;
| [d] managers, systems administrators, and users of the system are made aware of the applicable policies, standards, and procedures related to the security of the system. || Artifact || Policies, standards and procedures for employees within training (completed training report).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AT.L2-3.2.2 – Role-Based Training ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;width: 85%;&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AT.L2-3.2.2_Details|&#039;&#039;&#039;AT.L2-3.2.2&#039;&#039;&#039;]] Ensure that personnel are trained to carry out their assigned information security-related duties and responsibilities.|-&lt;br /&gt;
|-&lt;br /&gt;
| [a] information security-related duties, roles, and responsibilities are defined. || Document || Policy/Procedures/Instruction, Job Role Matrix, Position Descriptions, User Roles.&lt;br /&gt;
|-&lt;br /&gt;
| [b] information security-related duties, roles, and responsibilities are assigned to designated personnel. || Artifact || Screenshot of breakout of different roles/permissions assigned to individuals (i.e. ActiveDirectory); Privilege Access Agreement.&lt;br /&gt;
|-&lt;br /&gt;
| [c] personnel are adequately trained to carry out their assigned information security-related duties, roles, and responsibilities. || Artifact || Screenshot of tool and/or training specifying security specific roles, duties and responsibilities; Screenshot of required certifications (i.e. Sec+, CISSP).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AT.L2-3.2.3 – Insider Threat Awareness ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;width: 85%;&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AT.L2-3.2.3_Details|&#039;&#039;&#039;AT.L2-3.2.3&#039;&#039;&#039;]] Provide security awareness training on recognizing and reporting potential indicators of insider threat.&lt;br /&gt;
|-&lt;br /&gt;
| [a] potential indicators associated with insider threats are identified. || Document || Insidert Threat Policy/Procedures/Instruction; Insider Threat Training/Briefing.&lt;br /&gt;
|-&lt;br /&gt;
| [b] security awareness training on recognizing and reporting potential indicators of insider threat is provided to managers and employees. || Artifact || Screenshot of training records showing completion of Insider Threat training, emails showing completion of Insider Threat training, Screenshot of certificate showing completion with individual&#039;s name.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Audit and Accountability (AU) ==&lt;br /&gt;
=== AU.L2-3.3.1 – System Auditing ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;width: 85%;&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AU.L2-3.3.1_Details|&#039;&#039;&#039;AU.L2-3.3.1&#039;&#039;&#039;]] Create and retain system audit logs and records to the extent needed to enable the monitoring, analysis, investigation, and reporting of unlawful or unauthorized system activity.&lt;br /&gt;
|-&lt;br /&gt;
| [a] audit logs needed (i.e., event types to be logged) to enable the monitoring, analysis, investigation, and reporting of unlawful or unauthorized system activity are specified. || Document || SSP, policy, or auditing and logging process that defines specific types of events to be logged.&lt;br /&gt;
|-&lt;br /&gt;
| [b] the content of audit records needed to support monitoring, analysis, investigation, and reporting of unlawful or unauthorized system activity is defined. || Document || SSP, policy, or auditing and logging process that defines specific content of audit records/files.&lt;br /&gt;
|-&lt;br /&gt;
| [c] audit records are created (generated). || Screen Share || Screen share of tool that shows logs are generated for all systems.&lt;br /&gt;
|-&lt;br /&gt;
| [d] audit records, once created, contain the defined content. || Screen Share || Screen share of tool that shows logs contain defined content as defined in SSP, policy, or procedures.&lt;br /&gt;
|-&lt;br /&gt;
| [e] retention requirements for audit records are defined. || Document || SSP, Polocy, or Auditing and logging process that describes how long records are kept.&lt;br /&gt;
|-&lt;br /&gt;
| [f] audit records are retained as defined. || Screen Share || Screen share of tool that shows records and audit content retained at a minimum as defined.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AU.L2-3.3.2 – User Accountability ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;width: 85%;&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AU.L2-3.3.2_Details|&#039;&#039;&#039;AU.L2-3.3.2&#039;&#039;&#039;]] Ensure that the actions of individual system users can be uniquely traced to those users so they can be held accountable for their actions.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the content of the audit records needed to support the ability to uniquely trace users to their actions is defined. || Document || SSP, policy, or process that defines actions traced back to individuals.&lt;br /&gt;
|-&lt;br /&gt;
| [b] audit records, once created, contain the defined content. || Screen Share || Screen share of tool that shows audit records traced to specific users/roles.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AU.L2-3.3.3 – Event Review ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;width: 85%;&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AU.L2-3.3.3_Details|&#039;&#039;&#039;AU.L2-3.3.3&#039;&#039;&#039;]] Review and update logged events.&lt;br /&gt;
|-&lt;br /&gt;
| [a] a process for determining when to review logged events is defined. || Document || SSP, policy, or documented process that shows frequency of when to review types of logged events.&lt;br /&gt;
|-&lt;br /&gt;
| [b] event types being logged are reviewed in accordance with the defined review process. || Artifact || Evidence through a documented method such as meeting minutes, CAB minutes, etc. of log sources and log events being logged at the defined frequency.&lt;br /&gt;
|-&lt;br /&gt;
| [c] event types being logged are updated based on the review. || Artifact || Evidence of implementation based on the results of the review of logged events/sources through a ticket, meeting minutes, or screen share of the tool that shows changes implemented (finetuning).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AU.L2-3.3.4 – Audit Failure Alerting ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;width: 85%;&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AU.L2-3.3.4_Details|&#039;&#039;&#039;AU.L2-3.3.4&#039;&#039;&#039;]] Alert in the event of an audit logging process failure.&lt;br /&gt;
|-&lt;br /&gt;
| [a] personnel or roles to be alerted in the event of an audit logging process failure are identified. || Document || SSP, policy, or procedure that shows who needs to be notified in case of an audit failure.&lt;br /&gt;
|-&lt;br /&gt;
| [b] types of audit logging process failures for which alert will be generated are defined. || Document || SSP, policy, or procedure that shows what types of failure will generate notifications.&lt;br /&gt;
|-&lt;br /&gt;
| [c] identified personnel or roles are alerted in the event of an audit logging process failure. || Artifact || Artifact such as email or ticket that shows the identified personnel were alerted of any audit/logging process failure as defined.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AU.L2-3.3.5 – Audit Correlation ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;width: 85%;&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AU.L2-3.3.5_Details|&#039;&#039;&#039;AU.L2-3.3.5&#039;&#039;&#039;]] Correlate audit record review, analysis, and reporting processes for investigation and response to indications of unlawful, unauthorized, suspicious, or unusual activity.&lt;br /&gt;
|-&lt;br /&gt;
| [a] audit record review, analysis, and reporting processes for investigation and response to indications of unlawful, unauthorized, suspicious, or unusual activity are defined. || Document || SSP, policy, or procedure covering audit logging, monitoring, and reporting.&lt;br /&gt;
|-&lt;br /&gt;
| [b] defined audit record review, analysis, and reporting processes are correlated. || Artifact || Artifact showing an audit event and the resultant corrective action or actions to the event; this can be a Help Desk ticket, meeting notes, or a change control board items showing the event and any corrective action taken.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AU.L2-3.3.6 – Reduction &amp;amp; Reporting ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;width: 85%;&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AU.L2-3.3.6_Details|&#039;&#039;&#039;AU.L2-3.3.6&#039;&#039;&#039;]] Provide audit record reduction and report generation to support on-demand analysis and reporting.&lt;br /&gt;
|-&lt;br /&gt;
| [a] an audit record reduction capability that supports on-demand analysis is provided. || Screen Share || Screen share of the logging environment where an event can be selected and traced back to a specific device, or dashboard showing realtime event analysis.&lt;br /&gt;
|-&lt;br /&gt;
| [b] a report generation capability that supports on-demand reporting is provided. || Screen Share || Screen share showing the generation of an on demand report.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AU.L2-3.3.7 – Authoritative Time Source ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;width: 85%;&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AU.L2-3.3.7_Details|&#039;&#039;&#039;AU.L2-3.3.7&#039;&#039;&#039;]] Provide a system capability that compares and synchronizes internal system clocks with an authoritative source to generate time stamps for audit records.&lt;br /&gt;
|-&lt;br /&gt;
| [a] internal system clocks are used to generate time stamps for audit records. || Screen Share || Screen share showing the NTP settings of a windows, Unix, Linux device; a screen share showing the NTP settings of network appliances.&lt;br /&gt;
|-&lt;br /&gt;
| [b] an authoritative source with which to compare and synchronize internal system clocks is specified. || Document || SSP or policy indicating that devices need to be synched to a local authoritative time device that is synched with an authoritative time service.&lt;br /&gt;
|-&lt;br /&gt;
| [c] internal system clocks used to generate time stamps for audit records are compared to and synchronized with the specified authoritative time source. || Screen Share || Screen share showing device logging appliance time is point to the appropriate authoritative time server.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AU.L2-3.3.8 – Audit Protection ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;width: 85%;&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AU.L2-3.3.8_Details|&#039;&#039;&#039;AU.L2-3.3.8&#039;&#039;&#039;]] Protect audit information and audit logging tools from unauthorized access, modification, and deletion.&lt;br /&gt;
|-&lt;br /&gt;
| [a] audit information is protected from unauthorized access. || Screen Share || Screen share showing operating system permissions on the audit folders being restricted to appropriate users.&lt;br /&gt;
|-&lt;br /&gt;
| [b] audit information is protected from unauthorized modification. || Screen Share || Screen share showing operating system permissions on the audit folders being restricted to appropriate users.&lt;br /&gt;
|-&lt;br /&gt;
| [c] audit information is protected from unauthorized deletion. || Screen Share || Screen share showing operating system permissions on the audit folders being restricted to appropriate users.&lt;br /&gt;
|-&lt;br /&gt;
| [d] audit logging tools are protected from unauthorized access. || Screen Share || Artifact showing access permissions in the SIEM tool.&lt;br /&gt;
|-&lt;br /&gt;
| [e] audit logging tools are protected from unauthorized modification. || Screen Share || Artifact showing update permissions in the SIEM tool.&lt;br /&gt;
|-&lt;br /&gt;
| [f] audit logging tools are protected from unauthorized deletion. || Screen Share || Artifact showing delete permissions in the SIEM tool.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AU.L2-3.3.9 – Audit Management ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;width: 85%;&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_AU.L2-3.3.9_Details|&#039;&#039;&#039;AU.L2-3.3.9&#039;&#039;&#039;]] Limit management of audit logging functionality to a subset of privileged users.&lt;br /&gt;
|-&lt;br /&gt;
| [a] a subset of privileged users granted access to manage audit logging functionality is defined. || Document || SSP or policy indicating which users or groups have access to audit logs.&lt;br /&gt;
|-&lt;br /&gt;
| [b] management of audit logging functionality is limited to the defined subset of privileged users. || Screen Share || Artifact showing SIEM or OS folder permissions (this should be limited to the assigned users or groups); artifact showing an ACL setting in SIEM tool in regards to logs.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Configuration Management (CM) ==&lt;br /&gt;
=== CM.L2-3.4.1 – System Baselining ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;width: 85%;&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_CM.L2-3.4.1_Details|&#039;&#039;&#039;CM.L2-3.4.1&#039;&#039;&#039;]] Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles.&lt;br /&gt;
|-&lt;br /&gt;
| [a] a baseline configuration is established. || Document || Documentation showing or explaining standard imaging process (how standard images are deployed and where  they are stored).&lt;br /&gt;
|-&lt;br /&gt;
| [b] the baseline configuration includes hardware, software, firmware, and documentation. || Artifact || Screenshot of repository of where images are maintained and information relating to hardware, software, and firmware.&lt;br /&gt;
|-&lt;br /&gt;
| [c] the baseline configuration is maintained (reviewed and updated) throughout the system development life cycle. || Artifact || Screenshot/evidence displaying management of baseline configurations (how often they are being managed as stated).&lt;br /&gt;
|-&lt;br /&gt;
| [d] a system inventory is established. || Document || Screenshot/evidence displaying inventory listing of approved products for use.&lt;br /&gt;
|-&lt;br /&gt;
| [e] the system inventory includes hardware, software, firmware, and documentation. || Artifact || Screeenshot/evidence displaying inventory listing of approved products and versions permitted for use.&lt;br /&gt;
|-&lt;br /&gt;
| [f] the inventory is maintained (reviewed and updated) throughout the system development life cycle. || Artifact || Screeenshot/evidence displaying management of baseline configurations (How often and are they being managed as stated.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== CM.L2-3.4.2 – Security Configuration Enforcement ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;width: 85%;&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_CM.L2-3.4.2_Details|&#039;&#039;&#039;CM.L2-3.4.2&#039;&#039;&#039;]] Establish and enforce security configuration settings for information technology products employed in organizational systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] security configuration settings for information technology products employed in the system are established and included in the baseline configuration. || Document || Documentation explaining methodology used by organization to create secure baselines (STIGs, benchmarks).&lt;br /&gt;
|-&lt;br /&gt;
| [b] security configuration settings for information technology products employed in the system are enforced. || Artifact || Evidence of tool/s used to enforce security configurations to ensure images used are free from modification unless authorized.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== CM.L2-3.4.3 – System Change Management ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;width: 85%;&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_CM.L2-3.4.3_Details|&#039;&#039;&#039;CM.L2-3.4.3&#039;&#039;&#039;]] Track, review, approve or disapprove, and log changes to organizational systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] changes to the system are tracked. || Artifact || Evidence of IT Service Management tool / process used to track system changes.&lt;br /&gt;
|-&lt;br /&gt;
| [b] changes to the system are reviewed. || Artifact || Evidence of IT Service Management tool / process used to review system changes.&lt;br /&gt;
|-&lt;br /&gt;
| [c] changes to the system are approved or disapproved. || Artifact || Evidence of IT Service Management tool / process used to approve/disapprove system changes.&lt;br /&gt;
|-&lt;br /&gt;
| [d] changes to the system are logged. || Artifact || Evidence of IT Service Management tool / process used to log system changes.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== CM.L2-3.4.4 – Security Impact Analysis ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;width: 85%;&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_CM.L2-3.4.4_Details|&#039;&#039;&#039;CM.L2-3.4.4&#039;&#039;&#039;]] Analyze the security impact of changes prior to implementation.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the security impact of changes to the system is analyzed prior to implementation. || Artifact || Document explaining that security impact analysis of proposed changes to a system is conducted prior to implementation.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== CM.L2-3.4.5 – Access Restrictions for Change ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;width: 85%;&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_CM.L2-3.4.5_Details|&#039;&#039;&#039;CM.L2-3.4.5&#039;&#039;&#039;]] Define, document, approve, and enforce physical and logical access restrictions associated with changes to organizational systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] physical access restrictions associated with changes to the system are defined. || Document || Document explaining the process of how physical access restrictions are defined for an individuals ability to make system changes.&lt;br /&gt;
|-&lt;br /&gt;
| [b] physical access restrictions associated with changes to the system are documented. || Document || Document explaining the process of how physical access restrictions are defined for an individuals ability to make system changes are documented; access request process.&lt;br /&gt;
|-&lt;br /&gt;
| [c] physical access restrictions associated with changes to the system are approved. || Artifact || Evidence of process of how physical access to systems are granted (i.e. physical access request sample).&lt;br /&gt;
|-&lt;br /&gt;
| [d] physical access restrictions associated with changes to the system are enforced. || Physical Review || Evidence of process of how physical access to systems are enforced (physical access system).&lt;br /&gt;
|-&lt;br /&gt;
| [e] logical access restrictions associated with changes to the system are defined. || Document || Document explaining the process of how logical access restrictions are defined for an individual&#039;s ability to make system changes.&lt;br /&gt;
|-&lt;br /&gt;
| [f] logical access restrictions associated with changes to the system are documented. || Document || Document explaining the process of how logical access restrictions are defined for an individual&#039;s ability to make system changes are documented.&lt;br /&gt;
|-&lt;br /&gt;
| [g] logical access restrictions associated with changes to the system are approved. || Artifact || Evidence of process of how logical access to systems are granted.&lt;br /&gt;
|-&lt;br /&gt;
| [h] logical access restrictions associated with changes to the system are enforced. || Artifact || Evidence of process of how logical access to systems are enforced.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== CM.L2-3.4.6 – Least Functionality ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;width: 85%;&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_CM.L2-3.4.6_Details|&#039;&#039;&#039;CM.L2-3.4.6&#039;&#039;&#039;]] Employ the principle of least functionality by configuring organizational systems to provide only essential capabilities.&lt;br /&gt;
|-&lt;br /&gt;
| [a] essential system capabilities are defined based on the principle of least functionality. || Document || Documentation explaining how systems are configured to utilize the principle of least functionality for designated users.&lt;br /&gt;
|-&lt;br /&gt;
| [b] the system is configured to provide only the defined essential capabilities. || Screen Share || Evidence displaying how systems are configured to utilize the principle of least functionality for designated users; disabled service settings, accepted standards for hardening (CIS benchmarks, etc.).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== CM.L2-3.4.7 – Nonessential Functionality ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;width: 85%;&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_CM.L2-3.4.7_Details|&#039;&#039;&#039;CM.L2-3.4.7&#039;&#039;&#039;]] Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services.&lt;br /&gt;
|-&lt;br /&gt;
| [a] essential programs are defined. || Document || Documented essential programs specified; build documents; software center; SSP.&lt;br /&gt;
|-&lt;br /&gt;
| [b] the use of nonessential programs is defined. || Document || Documented listing of nonessential programs (whatever is NOT specified in [a]); AUP/User Agreement may identify nonessential use/programs.&lt;br /&gt;
|-&lt;br /&gt;
| [c] the use of nonessential programs is restricted, disabled, or prevented as defined. || Screen Share || Tool used to restrict nonessential programs displays restrictions as defined (McAfee ePO settings, Carbon Black rules, etc.).&lt;br /&gt;
|-&lt;br /&gt;
| [d] essential functions are defined. || Document || Documented essential functions are specified.&lt;br /&gt;
|-&lt;br /&gt;
| [e] the use of nonessential functions is defined. || Document || Documented nonessential functions are specified.&lt;br /&gt;
|-&lt;br /&gt;
| [f] the use of nonessential functions is restricted, disabled, or prevented as defined. || Screen Share || Tool used to restrict essential/nonessential functions displays restrictions as defined.&lt;br /&gt;
|-&lt;br /&gt;
| [g] essential ports are defined. || Document || Documented essential ports are specified.&lt;br /&gt;
|-&lt;br /&gt;
| [h] the use of nonessential ports is defined. || Document || Documented nonessential ports functions are specified.&lt;br /&gt;
|-&lt;br /&gt;
| [i] the use of nonessential ports is restricted, disabled, or prevented as defined. || Screen Share || Tool used to restrict essential/nonessential ports displays restrictions as defined (FW rules; McAfee; GPO, etc.).&lt;br /&gt;
|-&lt;br /&gt;
| [j] essential protocols are defined. || Document || Documented essential protocols are specified.&lt;br /&gt;
|-&lt;br /&gt;
| [k] the use of nonessential protocols is defined. || Document || Documented nonessential protocols functions are specified.&lt;br /&gt;
|-&lt;br /&gt;
| [l] the use of nonessential protocols is restricted, disabled, or prevented as defined. || Screen Share || Tool used to restrict essential/nonessential protocols displays restrictions as defined (FW rules; GPO, etc.).&lt;br /&gt;
|-&lt;br /&gt;
| [m] essential services are defined. || Document || Documented essential services specified.&lt;br /&gt;
|-&lt;br /&gt;
| [n] the use of nonessential services is defined. || Document || Documented nonessential services functions are specified.&lt;br /&gt;
|-&lt;br /&gt;
| [o] the use of nonessential services is restricted, disabled, or prevented as defined. || Screen Share || Tool used to restrict essential/nonessential services displays restrictions as defined.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== CM.L2-3.4.8 – Application Execution Policy ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;width: 85%;&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_CM.L2-3.4.8_Details|&#039;&#039;&#039;CM.L2-3.4.8&#039;&#039;&#039;]] Apply deny-by-exception (blacklisting) policy to prevent the use of unauthorized software or deny-all, permit-by-exception (whitelisting) policy to allow the execution of authorized software.&lt;br /&gt;
|-&lt;br /&gt;
| [a] a policy specifying whether whitelisting or blacklisting is to be implemented is specified. || Document || Documentation explaining whitelisting or blacklisting process.&lt;br /&gt;
|-&lt;br /&gt;
| [b] the software allowed to execute under whitelisting or denied use under blacklisting is specified. || Document || Documentation explaining whitelisting or blacklisting process for software.&lt;br /&gt;
|-&lt;br /&gt;
| [c] whitelisting to allow the execution of authorized software or blacklisting to prevent the use of unauthorized software is implemented as specified. || Screen Share || Tool used for whitelisting or blacklisting for software shows capability of restricting/authorizing software (Carbon Black dashboard, &amp;quot;SW Store&amp;quot;, web proxies, DNS Blackhole, etc.).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== CM.L2-3.4.9 – User-Installed Software ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;width: 85%;&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_CM.L2-3.4.9_Details|&#039;&#039;&#039;CM.L2-3.4.9&#039;&#039;&#039;]] Control and monitor user-installed software.&lt;br /&gt;
|-&lt;br /&gt;
| [a] a policy for controlling the installation of software by users is established. || Document || Documented software authorization process or methodology for approval.&lt;br /&gt;
|-&lt;br /&gt;
| [b] installation of software by users is controlled based on the established policy. || Screen Share || Evidence that approval/restriction in installation of software by authorized personnel is implemented as specified (AUP, GPO, etc.).&lt;br /&gt;
|-&lt;br /&gt;
| [c] installation of software by users is monitored. || Screen Share || Evidence that installation of software by authorized personnel is monitored (SCCM groups, SW Center, etc.).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Identification and Authentication (IA) ==&lt;br /&gt;
=== IA.L2-3.5.1 – Identification [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;width: 85%;&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IA.L2-3.5.1_Details|&#039;&#039;&#039;IA.L2-3.5.1&#039;&#039;&#039;]] Identify information system users, processes acting on behalf of users, or devices.&lt;br /&gt;
|-&lt;br /&gt;
| [a] system users are identified. || Document || Based on what is defined in their documentation (SSP, AUP, Policy, SOP), request to see a sample of non-privileged/privileged users in AD OU group (overlaps with 3.1.1 and 3.1.5).&lt;br /&gt;
|-&lt;br /&gt;
| [b] processes acting on behalf of users are identified. || Screen Share || Based on what is defined in their documentation (SSP, AUP, Policy, SOP), request to see a sample of service accounts in AD OU group (overlaps with 3.1.1 and 3.1.5).&lt;br /&gt;
|-&lt;br /&gt;
| [c] devices accessing the system are identified. || Screen Share || Based on what is defined in their documentation (SSP, AUP, Policy, SOP), request to see a sample of domain-joined workstation &amp;amp; servers in AD OU group (overlaps with 3.1.1 and 3.1.5).  For network devices, request screen share/artifact to show how they are identified on the enterprise network.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IA.L2-3.5.2 – Authentication [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;width: 85%;&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IA.L2-3.5.2_Details|&#039;&#039;&#039;IA.L2-3.5.2&#039;&#039;&#039;]] Authenticate (or verify) the identities of those users, processes, or devices, as a prerequisite to allowing access to organizational information systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the identity of each user is authenticated or verified as a prerequisite to system access. || Screen Share || If the user logs in with non-privileged account during other demoes and then a privileged account, then this should be satisfied.  If screen share is unavailable, request logs to show successful and unsuccessful login by privileged and non-privilged users.&lt;br /&gt;
|-&lt;br /&gt;
| [b] the identity of each process acting on behalf of a user is authenticated or verified as a prerequisite to system access. || Screen Share || Request a log that shows successful/unsuccessful service account trying to log on to company&#039;s asset.&lt;br /&gt;
|-&lt;br /&gt;
| [c] the identity of each device accessing or connecting to the system is authenticated or verified as a prerequisite to system access. || Screen Share || Request a log that shows domain-joined workstation/server authenticating to AD (focus on the MAC/IP address/hostname).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IA.L2-3.5.3 – Multifactor Authentication ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;width: 85%;&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IA.L2-3.5.3_Details|&#039;&#039;&#039;IA.L2-3.5.3&#039;&#039;&#039;]] Use multifactor authentication for local and network access to privileged accounts and for network access to non-privileged accounts.&lt;br /&gt;
|-&lt;br /&gt;
| [a] privileged accounts are identified. || Screen Share|| Based on what is defined in their documentation, request to see a sample of privileged users in AD OU group.  Overlaps with 3.1.5.  Screenshot/screen share to show implementation is enforced.&lt;br /&gt;
|-&lt;br /&gt;
| [b] multifactor authentication is implemented for local access to privileged accounts. || Document || SSP, AUP, Policy, SOP that defines that MFA is needed for privileged local access.&lt;br /&gt;
|-&lt;br /&gt;
| [c] multifactor authentication is implemented for network access to privileged accounts. || Screen Share || Within the MFA implementation mechanism, show that privileged users are forced to use MFA;  Screenshot/Screen share to show implementation is enforced.&lt;br /&gt;
|-&lt;br /&gt;
| [d] multifactor authentication is implemented for network access to non-privileged accounts. || Screen Share || Within the MFA implementation mechanism, show that non-privileged users are forced to use MFA; Screenshot/Screen share to show implementation is enforced.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IA.L2-3.5.4 – Replay-Resistant Authentication ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;width: 85%;&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IA.L2-3.5.4_Details|&#039;&#039;&#039;IA.L2-3.5.4&#039;&#039;&#039;]] Employ replay-resistant authentication mechanisms for network access to privileged and non-privileged accounts.&lt;br /&gt;
|-&lt;br /&gt;
| [a] replay-resistant authentication mechanisms are implemented for network account access to privileged and non-privileged accounts. || Screen Share || Show the GPO setting that enforces Kerberos within AD.  If MFA is used, show the implementation to enforce replay resistant techniques.  For non-windows, show the technical solution to enforce replay resistant attacks.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IA.L2-3.5.5 – Identifier Reuse ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;width: 85%;&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IA.L2-3.5.5_Details|&#039;&#039;&#039;IA.L2-3.5.5&#039;&#039;&#039;]] Prevent reuse of identifiers for a defined period.&lt;br /&gt;
|-&lt;br /&gt;
| [a] a period within which identifiers cannot be reused is defined. || Document || SSP, policies, or SOP that defines identifier reuse.&lt;br /&gt;
|-&lt;br /&gt;
| [b] reuse of identifiers is prevented within the defined period. || Screen Share || Show the GPO setting/technical solution that enforces what is defined in policy/documentation (this can be automated or manual process; screen share/artifacts can be presented to satisfy this requirement.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IA.L2-3.5.6 – Identifier Handling ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;width: 85%;&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IA.L2-3.5.6_Details|&#039;&#039;&#039;IA.L2-3.5.6&#039;&#039;&#039;]] Disable identifiers after a defined period of inactivity.&lt;br /&gt;
|-&lt;br /&gt;
| [a] a period of inactivity after which an identifier is disabled is defined. || Document || SSP, policy that defines the period of inactivity after which an identifier is disabled.&lt;br /&gt;
|-&lt;br /&gt;
| [b] identifiers are disabled after the defined period of inactivity. || Screen Share || Screen share AD or similar tool supporting directory-based identity-related services for disabled accounts (can be done by hand or script).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IA.L2-3.5.7 – Password Complexity ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;width: 85%;&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IA.L2-3.5.7_Details|&#039;&#039;&#039;IA.L2-3.5.7&#039;&#039;&#039;]] Enforce a minimum password complexity and change of characters when new passwords are created.&lt;br /&gt;
|-&lt;br /&gt;
| [a] password complexity requirements are defined. || Document || SSP, policy that defines password complexity requirements.&lt;br /&gt;
|-&lt;br /&gt;
| [b] password change of character requirements are defined. || Document || SSP, policy that defines change of character requirements are defined.&lt;br /&gt;
|-&lt;br /&gt;
| [c] minimum password complexity requirements as defined are enforced when new passwords are created. || Screen Share || Screen share of AD or similar directory-based identity-related service tool to show complexity requirements.&lt;br /&gt;
|-&lt;br /&gt;
| [d] minimum password change of character requirements as defined are enforced when new passwords are created. || Screen Share || Screen share of Group Policy configuration or similar tool providing centralized management and configuration of operating systems, applications, and users&#039; settings to show that characters must be changed.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IA.L2-3.5.8 – Password Reuse ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;width: 85%;&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IA.L2-3.5.8_Details|&#039;&#039;&#039;IA.L2-3.5.8&#039;&#039;&#039;]] Prohibit password reuse for a specified number of generations.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the number of generations during which a password cannot be reused is specified. || Document || SSP, policy that specifies the number of generations during which a password cannot be reused is specified.&lt;br /&gt;
|-&lt;br /&gt;
| [b] reuse of passwords is prohibited during the specified number of generations. || Screen Share || Screen share Group Policy or similar tool providing centralized management and configuration of operating systems, applications, and users&#039; settings in a directory-based identity-related service tool&#039;s configuration to show reuse of passwords is prohibited.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IA.L2-3.5.9 – Temporary Passwords ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;width: 85%;&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IA.L2-3.5.9_Details|&#039;&#039;&#039;IA.L2-3.5.9&#039;&#039;&#039;]] Allow temporary password use for system logons with an immediate change to a permanent password.&lt;br /&gt;
|-&lt;br /&gt;
| [a] an immediate change to a permanent password is required when a temporary password is used for system logon. || Screen Share || Screen share of Group Policy or similar tool providing centralized management and configuration of operating systems, applications, and users&#039; settings in a directory-based identity-related service tool&#039;s configuration to show &amp;quot;change password at first logon.&amp;quot;&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IA.L2-3.5.10 – Cryptographically-Protected Passwords ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;width: 85%;&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IA.L2-3.5.1_Details|&#039;&#039;&#039;IA.L2-3.5.1&#039;&#039;&#039;]] Store and transmit only cryptographically-protected passwords.&lt;br /&gt;
|-&lt;br /&gt;
| [a] passwords are cryptographically protected in storage. || Screen Share || Screen share Group Policy or similar tool providing centralized management and configuration of operating systems, applications, and users&#039; settings in a directory-based identity-related service tool&#039;s configuration that Kerberos, or a similar network authentication protocol that works on the basis of tickets to allow nodes communicating over a non-secure network to prove their identity to one another in a secure manner, is enabled.&lt;br /&gt;
|-&lt;br /&gt;
| [b] passwords are cryptographically protected in transit. || Screen Share || Screen share Group Policy or similar tool providing centralized management and configuration of operating systems, applications, and users&#039; settings in a directory-based identity-related service tool&#039;s configuration that Kerberos, or a similar network authentication protocol that works on the basis of tickets to allow nodes communicating over a non-secure network to prove their identity to one another in a secure manner, is enabled.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IA.L2-3.5.11 – Obscure Feedback ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;width: 85%;&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IA.L2-3.5.10_Details|&#039;&#039;&#039;IA.L2-3.5.10&#039;&#039;&#039;]] Obscure feedback of authentication information.&lt;br /&gt;
|-&lt;br /&gt;
| [a] authentication information is obscured during the authentication process. || Screen Share || Screen share of Group Policy or similar tool providing centralized management and configuration of operating systems, applications, and users&#039; settings in a directory-based identity-related service tool&#039;s configuration to show that passwords are obscured.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Incident Response (IR) ==&lt;br /&gt;
=== IR.L2-3.6.1 – Incident Handling ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;width: 85%;&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IR.L2-3.6.1_Details|&#039;&#039;&#039;IR.L2-3.6.1&#039;&#039;&#039;]] Establish an operational incident-handling capability for organizational systems that includes preparation, detection, analysis, containment, recovery, and user response activities.&lt;br /&gt;
|-&lt;br /&gt;
| [a] an operational incident-handling capability is established. || Document || Incident Response SOP/Plan.&lt;br /&gt;
|-&lt;br /&gt;
| [b] the operational incident-handling capability includes preparation. || Document || Incident Response SOP/Plan, prior incident report, training, COOP plan.&lt;br /&gt;
|-&lt;br /&gt;
| [c] the operational incident-handling capability includes detection. || Document || Incident Response SOP/Plan; definition of tools used to detect; artifacts showing tools used; prior incident report.&lt;br /&gt;
|-&lt;br /&gt;
| [d] the operational incident-handling capability includes analysis. || Document || Incident Response SOP/Plan; Definition of tools used to analyze potential incidents; artifacts showing tools used for analysis; prior incident report.&lt;br /&gt;
|-&lt;br /&gt;
| [e] the operational incident-handling capability includes containment. || Document || Incident Response SOP/Plan; isolation/quarantine process; user training.&lt;br /&gt;
|-&lt;br /&gt;
| [f] the operational incident-handling capability includes recovery. || Document || Incident Response SOP/Plan; COOP Plan; prior incident reports, re-baselining impacted devices.&lt;br /&gt;
|-&lt;br /&gt;
| [g] the operational incident-handling capability includes user response. || Document || Incident Response SOP/Plan; user awareness training; Help Desk process.&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IR.L2-3.6.2 – Incident Reporting ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;width: 85%;&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IR.L2-3.6.2_Details|&#039;&#039;&#039;IR.L2-3.6.2&#039;&#039;&#039;]] Track, document, and report incidents to designated officials and/or authorities both internal and external to the organization.&lt;br /&gt;
|-&lt;br /&gt;
| [a] incidents are tracked. || Artifact || Incident Response SOP/Plan; ITSM artifact; technical implementation for incident tracking.&lt;br /&gt;
|-&lt;br /&gt;
| [b] incidents are documented. || Artifact || Incident Response SOP/Plan; ITSM artifact; technical implementation for incident tracking.&lt;br /&gt;
|-&lt;br /&gt;
| [c] authorities to whom incidents are to be reported are identified. || Document || Incident Response SOP/Plan.&lt;br /&gt;
|-&lt;br /&gt;
| [d] organizational officials to whom incidents are to be reported are identified. || Document || Incident Response SOP/Plan.&lt;br /&gt;
|-&lt;br /&gt;
| [e] identified authorities are notified of incidents. || Screen Share || Prior incident report; DIBNET login; prior email notifications.&lt;br /&gt;
|-&lt;br /&gt;
| [f] identified organizational officials are notified of incidents. || Artifact || Prior incident report; prior email notifications; tabletop exercises.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IR.L2-3.6.3 – Incident Response Testing ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;width: 85%;&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_IR.L2-3.6.3_Details|&#039;&#039;&#039;IR.L2-3.6.3&#039;&#039;&#039;]] Test the organizational incident response capability.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the incident response capability is tested. || Artifact || Incident response table top/scheduled or unscheduled test or penetration test.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Maintenance (MA) ==&lt;br /&gt;
=== MA.L2-3.7.1 – Perform Maintenance ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;width: 85%;&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MA.L2-3.7.1_Details|&#039;&#039;&#039;MA.L2-3.7.1&#039;&#039;&#039;]] Perform maintenance on organizational systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] system maintenance is performed. || Artifact || Establish typical maintenance activities (HVAC, UPS, power distribution, generators, copier maintenance) that are performed; maintenance agreements or contracts detailing these types of activities are acceptable; interview responses should be considered.  This requirement should not be confused with 3.14.1 - report, remediate, and correct system flaws in a timely manner (patch management).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MA.L2-3.7.2 – System Maintenance Control ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;width: 85%;&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MA.L2-3.7.2_Details|&#039;&#039;&#039;MA.L2-3.7.2&#039;&#039;&#039;]] Provide controls on the tools, techniques, mechanisms, and personnel used to conduct system maintenance.&lt;br /&gt;
|-&lt;br /&gt;
| [a] tools used to conduct system maintenance are controlled. || Artifact || Tools may largely depend on the assessed environment; discussion examples include network diagnostic and monitoring tools (including hardware and software); artifacts could demonstrate secured locations/areas for these tools (photos) or checkout sheets/rosters (documents) depicting responsible personnel and the dates/times of checkout.&lt;br /&gt;
|-&lt;br /&gt;
| [b] techniques used to conduct system maintenance are controlled. || Artifact || Processes for scheduling, performing, documenting, reviewing, approving, and monitoring maintenance and repairs for the information system.&lt;br /&gt;
|-&lt;br /&gt;
| [c] mechanisms used to conduct system maintenance are controlled. || Artifact || Processes for scheduling, performing, documenting, reviewing, approving, and monitoring maintenance and repairs for the information system.&lt;br /&gt;
|-&lt;br /&gt;
| [d] personnel used to conduct system maintenance are controlled. || Physical Review || Screenshot of who is authorized to conduct maintenance; maintenance personnel training program.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MA.L2-3.7.3 – Equipment Sanitization ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;width: 85%;&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MA.L2-3.7.3_Details|&#039;&#039;&#039;MA.L2-3.7.3&#039;&#039;&#039;]] Ensure equipment removed for off-site maintenance is sanitized of any CUI.&lt;br /&gt;
|-&lt;br /&gt;
| [a] equipment to be removed from organizational spaces for off-site maintenance is sanitized of any CUI. || Artifact || Document or artifact; record if equipment sanitized; categories of sanitization/destruction defined; sanitization procedural document.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MA.L2-3.7.4 – Media Inspection ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;width: 85%;&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MA.L2-3.7.4_Details|&#039;&#039;&#039;MA.L2-3.7.4&#039;&#039;&#039;]] Check media containing diagnostic and test programs for malicious code before the media are used in organizational systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] media containing diagnostic and test programs are checked for malicious code before being used in organizational systems that process, store, or transmit CUI. || Artifact || Screenshot of diagnostic/test program being used (such as Symantec and McAfee on access scans…).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MA.L2-3.7.5 – Nonlocal Maintenance ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;width: 85%;&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MA.L2-3.7.5_Details|&#039;&#039;&#039;MA.L2-3.7.5&#039;&#039;&#039;]] Require multifactor authentication to establish nonlocal maintenance sessions via external network connections and terminate such connections when nonlocal maintenance is complete.&lt;br /&gt;
|-&lt;br /&gt;
| [a] multifactor authentication is used to establish nonlocal maintenance sessions via external network connections. || Screen Share || Describe MFA used to remote from external service to organizational systems for maintenance and screenshot of MFA (3.5.3)(points associated with admin).&lt;br /&gt;
|-&lt;br /&gt;
| [b] nonlocal maintenance sessions established via external network connections are terminated when nonlocal maintenance is complete. || Screen Share || Screenshot VPN session timeout.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MA.L2-3.7.6 – Maintenance Personnel ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;width: 85%;&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MA.L2-3.7.6_Details|&#039;&#039;&#039;MA.L2-3.7.6&#039;&#039;&#039;]] Supervise the maintenance activities of maintenance personnel without required access authorization.&lt;br /&gt;
|-&lt;br /&gt;
| [a] maintenance personnel without required access authorization are supervised during maintenance activities. || Document || System maintenance policy; list of authorized personnel; maintenance records or, contracts/SLAs; WebEx.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Media Protection (MP) ==&lt;br /&gt;
=== MP.L2-3.8.1 – Media Protection ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;width: 85%;&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MP.L2-3.8.1_Details|&#039;&#039;&#039;MP.L2-3.8.1&#039;&#039;&#039;]] Protect (i.e., physically control and securely store) system media containing CUI, both paper and digital.&lt;br /&gt;
|-&lt;br /&gt;
| [a] paper media containing CUI is physically controlled. || Document || Policy showing CUI paper media is controlled; artifact showing who has access; artifacts/records of  inventories conducted; media check out procedures (i.e. file cabinets, encryption, password protection).&lt;br /&gt;
|-&lt;br /&gt;
| [b] digital media containing CUI is physically controlled. || Document || Policy showing CUI digital media is controlled; artifact showing who has access; artifacts/records of inventories conducted; media check out procedures (i.e. file cabinets, external drives, USBs, encryption, password protection).&lt;br /&gt;
|-&lt;br /&gt;
| [c] paper media containing CUI is securely stored. || Physical Review || Check out/sign out sheets; possible photo of storage container/video walk through of storage area; badge reader logs or access lists for keys for secured areas; interview response considered (i.e. file cabinets,  encryption, password protection).&lt;br /&gt;
|-&lt;br /&gt;
| [d] digital media containing CUI is securely stored. || Physical Review || Check out/sign out sheets; possible photo of storage container/video walk through of storage area; badge reader logs or access lists for keys for secured areas; interview response considered (i.e. file cabinets, external drives, USBs, encryption, password protection).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MP.L2-3.8.2 – Media Access ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;width: 85%;&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MP.L2-3.8.2_Details|&#039;&#039;&#039;MP.L2-3.8.2&#039;&#039;&#039;]] Limit access to CUI on system media to authorized users.&lt;br /&gt;
|-&lt;br /&gt;
| [a] access to CUI on system media is limited to authorized users. || Artifact || Document describing how CUI is limited AND artifact showing principle of least access is implemented.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MP.L2-3.8.3 – Media Disposal [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;width: 85%;&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MP.L2-3.8.3_Details|&#039;&#039;&#039;MP.L2-3.8.3&#039;&#039;&#039;]] Sanitize or destroy information system media containing Federal Contract Information before disposal or release for reuse.&lt;br /&gt;
|-&lt;br /&gt;
| [a] system media containing CUI is sanitized or destroyed before disposal. || Document || Policy or artifact of media destruction logs; certificates of destruction; SLAs or contracts.&lt;br /&gt;
|-&lt;br /&gt;
| [b] system media containing CUI is sanitized before it is released for reuse. || Document || Policy or artifact describing method to sanitize, software used (i.e. DoD Wipe, ShredIT and Iron Mountain; Blancco; GDisk, DBAN).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MP.L2-3.8.4 – Media Markings ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;width: 85%;&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MP.L2-3.8.4_Details|&#039;&#039;&#039;MP.L2-3.8.4&#039;&#039;&#039;]] Mark media with necessary CUI markings and distribution limitations.&lt;br /&gt;
|-&lt;br /&gt;
| [a] media containing CUI is marked with applicable CUI markings. || Physical Review || Document or artifact showing CUI markings (i.e. labeling standards ).&lt;br /&gt;
|-&lt;br /&gt;
| [b] media containing CUI is marked with distribution limitations. || Physical Review || Document or artifact showing distro limitations (i.e. labeling standards ).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MP.L2-3.8.5 – Media Accountability ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;width: 85%;&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MP.L2-3.8.5_Details|&#039;&#039;&#039;MP.L2-3.8.5&#039;&#039;&#039;]] Control access to media containing CUI and maintain accountability for media during transport outside of controlled areas.&lt;br /&gt;
|-&lt;br /&gt;
| [a] access to media containing CUI is controlled. || Document || Policy, artifact of audit logs showing tracking, Access Control Lists, records of transport activities (i.e. USB drives, CDs, chain of custody.&lt;br /&gt;
|-&lt;br /&gt;
| [b] accountability for media containing CUI is maintained during transport outside of controlled areas. || Artifact || Artifact of audit logs showing tracking, Access Control Lists, records of transport activities (i.e. USB drives, CDs; chain of custody.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MP.L2-3.8.6 – Portable Storage Encryption ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;width: 85%;&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MP.L2-3.8.6_Details|&#039;&#039;&#039;MP.L2-3.8.6&#039;&#039;&#039;]] Implement cryptographic mechanisms to protect the confidentiality of CUI stored on digital media during transport unless otherwise protected by alternative physical safeguards.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the confidentiality of CUI stored on digital media is protected during transport using cryptographic mechanisms or alternative physical safeguards. || Artifact || Artifact showing crypto mechanisms used to protect (are they FIPS 140-2 [13.11]); artifact showing what alternative physical safeguards are in place (i.e. encryption; BitLocker; McAfee ).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MP.L2-3.8.7 – Removable Media ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;width: 85%;&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MP.L2-3.8.7_Details|&#039;&#039;&#039;MP.L2-3.8.7&#039;&#039;&#039;]] Control the use of removable media on system components.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the use of removable media on system components is controlled. || Artifact || Policy showing if removable media is allowed; writable removable media is restricted; tracking artifacts; what tools are used (i.e. Carbon Black, Crowd Strike, GPO, Zoho Desktop Central); procedure/process describing what happens if it is lost; what mechanisms are in place to control/restrict removable media (i.e. Active Directory Groups and Group Policy artifact showing restriction).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MP.L2-3.8.8 – Shared Media ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;width: 85%;&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MP.L2-3.8.8_Details|&#039;&#039;&#039;MP.L2-3.8.8&#039;&#039;&#039;]] Prohibit the use of portable storage devices when such devices have no identifiable owner.ASSESSMENT OBJECTIVES&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [a] the use of portable storage devices is prohibited when such devices have no identifiable owner. || Artifact || Policy and/or artifact showing company stance on portable storage devices if there is no owner (are personal USB devices allowed or are they company-issued; artifact showing alerts if device is connected to network (i.e. external HDD, Carbon Black, Crowd Strike, GPO, Zoho Desktop Central.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MP.L2-3.8.9 – Protect Backups ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;width: 85%;&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_MP.L2-3.8.9_Details|&#039;&#039;&#039;MP.L2-3.8.9&#039;&#039;&#039;]] Protect the confidentiality of backup CUI at storage locations.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the confidentiality of backup CUI is protected at storage locations. || Artifact || Policy on system backups; artifact showing media labeling; artifact showing encyption (is it FIPS 140-2 [13.11]); Access Control List artifact (i.e. backup tapes, Tivoli Storage Manager).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Personnel Security (PS) ==&lt;br /&gt;
=== PS.L2-3.9.1 – Screen Individuals ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;width: 85%;&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_PS.L2-3.9.1_Details|&#039;&#039;&#039;PS.L2-3.9.1&#039;&#039;&#039;]] Screen individuals prior to authorizing access to organizational systems containing CUI.&lt;br /&gt;
|-&lt;br /&gt;
| [a] individuals are screened prior to authorizing access to organizational systems containing CUI. || Artifact || Screenshot of records of screened personnel/background checks.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== PS.L2-3.9.2 – Personnel Actions ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;width: 85%;&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_PS.L2-3.9.2_Details|&#039;&#039;&#039;PS.L2-3.9.2&#039;&#039;&#039;]] Ensure that organizational systems containing CUI are protected during and after personnel actions such as terminations and transfers.&lt;br /&gt;
|-&lt;br /&gt;
| [a] a policy and/or process for terminating system access and any credentials coincident with personnel actions is established. || Document || Personnel security policy/procedures/instruction; Access control policy/procedure/instruction.&lt;br /&gt;
|-&lt;br /&gt;
| [b] system access and credentials are terminated consistent with personnel actions such as termination or transfer. || Artifact || Screenshot of records of personnel transfer and termination actions.&lt;br /&gt;
|-&lt;br /&gt;
| [c] the system is protected during and after personnel transfer actions. || Artifact || Completed outprocessing checklist.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Physical Protection (PE) ==&lt;br /&gt;
=== PE.L2-3.10.1 – Limit Physical Access [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;width: 85%;&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_PE.L2-3.10.1_Details|&#039;&#039;&#039;PE.L2-3.10.1&#039;&#039;&#039;]] Limit physical access to organizational information systems, equipment, and the respective operating environments to authorized individuals.&lt;br /&gt;
|-&lt;br /&gt;
| [a] authorized individuals allowed physical access are identified. || Artifact || Authorized personnel (names) access list.&lt;br /&gt;
|-&lt;br /&gt;
| [b] physical access to organizational systems is limited to authorized individuals. || Physical Review || Badge reader logs, audit logs, and/or card swipe test.&lt;br /&gt;
|-&lt;br /&gt;
| [c] physical access to equipment is limited to authorized individuals. || Physical Review || Badge reader logs, audit logs, and/or card swipe test.&lt;br /&gt;
|-&lt;br /&gt;
| [d] physical access to operating environments is limited to authorized. || Physical Review || Badge reader logs, audit logs, and/or card swipe test.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== PE.L2-3.10.2 – Monitor Facility ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;width: 85%;&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_PE.L2-3.10.2_Details|&#039;&#039;&#039;PE.L2-3.10.2&#039;&#039;&#039;]] Protect and monitor the physical facility and support infrastructure for organizational systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the physical facility where organizational systems reside is protected. || Physical Review || Physical security measures and barriers into the physical facility (cameras/locks/gates/guards, etc.).&lt;br /&gt;
|-&lt;br /&gt;
| [b] the support infrastructure for organizational systems is protected. || Physical Review || Physical barriers to entries into computer spaces, server rooms, etc.&lt;br /&gt;
|-&lt;br /&gt;
| [c] the physical facility where organizational systems reside is monitored. || Physical Review || Audit logs/how the physical facility is being monitored (cameras/access system/guards, etc.).&lt;br /&gt;
|-&lt;br /&gt;
| [d] the support infrastructure for organizational systems is monitored. || Physical Review || Audit logs/how the physical facility is being monitored (cameras/access system/guards, etc.).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== PE.L2-3.10.3 – Escort Visitors [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;width: 85%;&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_PE.L2-3.10.3_Details|&#039;&#039;&#039;PE.L2-3.10.3&#039;&#039;&#039;]] Escort visitors and monitor visitor activity.&lt;br /&gt;
|-&lt;br /&gt;
| [a] visitors are escorted. || Physical Review || Policy/procedures/instruction on methodology for handling non-authorized personnel (entry to exit).&lt;br /&gt;
|-&lt;br /&gt;
| [b] visitor activity is monitored. || Physical Review || Policy/procedures/instructio on methodology for handling non-authorized personnel (entry to exit).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== PE.L2-3.10.4 – Physical Access Logs [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;width: 85%;&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_PE.L2-3.10.4_Details|&#039;&#039;&#039;PE.L2-3.10.4&#039;&#039;&#039;]] Maintain audit logs of physical access.&lt;br /&gt;
|-&lt;br /&gt;
| [a] audit logs of physical access are maintained. || Artifact || Log or report from badging system.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== PE.L2-3.10.5 – Manage Physical Access [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;width: 85%;&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_PE.L2-3.10.5_Details|&#039;&#039;&#039;PE.L2-3.10.5&#039;&#039;&#039;]] Control and manage physical access devices.&lt;br /&gt;
|-&lt;br /&gt;
| [a] physical access devices are identified. || Document || Physical access control systems description, guard force contract/policy, key locks, logical systems specifications, etc.&lt;br /&gt;
|-&lt;br /&gt;
| [b] physical access devices are controlled. || Physical Review || Inventory records of physical access control devices (e.g. keys, locks, card readers, locks, etc.).&lt;br /&gt;
|-&lt;br /&gt;
| [c] physical access devices are managed. || Physical Review || List of security safeguards controlling access to the facility (e.g. cameras, monitoring by guards, isolation of IT systems equiment and or system components).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== PE.L2-3.10.6 – Alternative Work Sites ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;width: 85%;&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_PE.L2-3.10.6_Details|&#039;&#039;&#039;PE.L2-3.10.6&#039;&#039;&#039;]] Enforce safeguarding measures for CUI at alternate work sites.&lt;br /&gt;
|-&lt;br /&gt;
| [a] safeguarding measures for CUI are defined for alternate work sites. || Document || Telework agreement, Acceptable Use Policy and SOP for alternate work locations; user security training validation which includes physical/logical/technical protections of system at alternate work sites.&lt;br /&gt;
|-&lt;br /&gt;
| [b] safeguarding measures for CUI are enforced for alternate work sites. || Artifact || Monitoring/audit log of user activity and logical/physical/technical mechanisms in place to preclude unauthorized activity (telework agreement , AUP?).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Risk Assessment (RA) ==&lt;br /&gt;
=== RA.L2-3.11.1 – Risk Assessments ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;width: 85%;&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_RA.L2-3.11.1_Details|&#039;&#039;&#039;RA.L2-3.11.1&#039;&#039;&#039;]] Periodically assess the risk to organizational operations (including mission, functions, image, or reputation), organizational assets, and individuals, resulting from the operation of organizational systems and the associated processing, storage, or transmission of CUI.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the frequency to assess risk to organizational operations, organizational assets, and individuals is defined. || Document || Risk assessment policy.&lt;br /&gt;
|-&lt;br /&gt;
| [b] risk to organizational operations, organizational assets, and individuals resulting from the operation of an organizational system that processes, stores, or transmits CUI is assessed with the defined frequency. || Artifact || Copy of last risk assessment done within defined frequency.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== RA.L2-3.11.2 – Vulnerability Scan ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;width: 85%;&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_RA.L2-3.11.2_Details|&#039;&#039;&#039;RA.L2-3.11.2&#039;&#039;&#039;]] Scan for vulnerabilities in organizational systems and applications periodically and when new vulnerabilities affecting those systems and applications are identified.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the frequency to scan for vulnerabilities in organizational systems and applications is defined. || Document || Policy/procedures/instruction addressing vulnerability scanning records.&lt;br /&gt;
|-&lt;br /&gt;
| [b] vulnerability scans are performed on organizational systems with the defined frequency. || Screen Share || System configuration settings of vulnerability scanning scheduling and vulnerability scan results of systems within defined frequency.&lt;br /&gt;
|-&lt;br /&gt;
| [c] vulnerability scans are performed on applications with the defined frequency. || Screen Share || System configuration settings of vulnerability scanning scheduling and vulnerability scan results of applications within defined frequency.&lt;br /&gt;
|-&lt;br /&gt;
| [d] vulnerability scans are performed on organizational systems when new vulnerabilities are identified. || Screen Share || View signatures in scanning tool/ad hoc scan performed as a result.&lt;br /&gt;
|-&lt;br /&gt;
| [e] vulnerability scans are performed on applications when new vulnerabilities are identified. || Screen Share || View signatures in scanning tool/ad hoc scan performed as a result.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== RA.L2-3.11.3 – Vulnerability Remediation ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;width: 85%;&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_RA.L2-3.11.3_Details|&#039;&#039;&#039;RA.L2-3.11.3&#039;&#039;&#039;]] Remediate vulnerabilities in accordance with risk assessments.&lt;br /&gt;
|-&lt;br /&gt;
| [a] vulnerabilities are identified. || Artifact || Scan results showing vulnerabilities identified.&lt;br /&gt;
|-&lt;br /&gt;
| [b] vulnerabilities are remediated in accordance with risk assessments. || Artifact || Screenshot/document of scan results of remediated vulnerabilities in accordance to risk assessments.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Security Assessment (CA) ==&lt;br /&gt;
=== CA.L2-3.12.1 – Security Control Assessment ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;width: 85%;&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_CA.L2-3.12.1_Details|&#039;&#039;&#039;CA.L2-3.12.1&#039;&#039;&#039;]] Periodically assess the security controls in organizational systems to determine if the controls are effective in their application.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the frequency of security control assessments is defined. || Document || SSP.&lt;br /&gt;
|-&lt;br /&gt;
| [b] security controls are assessed with the defined frequency to determine if the controls are effective in their application. || Artifact || Copy of last security control assessment done within defined frequency.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== CA.L2-3.12.2 – Operational Plan of Action ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;width: 85%;&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_CA.L2-3.12.2_Details|&#039;&#039;&#039;CA.L2-3.12.2&#039;&#039;&#039;]] Develop and implement plans of action designed to correct deficiencies and reduce or eliminate vulnerabilities in organizational systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] deficiencies and vulnerabilities to be addressed by the plan of action are identified. || Artifact || Plan of Action (POA).&lt;br /&gt;
|-&lt;br /&gt;
| [b] a plan of action is developed to correct identified deficiencies and reduce or eliminate identified vulnerabilities. || Artifact || Plan of Action (POA).&lt;br /&gt;
|-&lt;br /&gt;
| [c] the plan of action is implemented to correct identified deficiencies and reduce or eliminate identified vulnerabilities. || Artifact || Plan of Action (POA)/previously completed POAs.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== CA.L2-3.12.3 – Security Control Monitoring ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;width: 85%;&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_CA.L2-3.12.3_Details|&#039;&#039;&#039;CA.L2-3.12.3&#039;&#039;&#039;]] Monitor security controls on an ongoing basis to ensure the continued effectiveness of the controls.&lt;br /&gt;
|-&lt;br /&gt;
| [a] security controls are monitored on an ongoing basis to ensure the continued effectiveness of those controls. || Artifact || Collection of risk assessment results, internal or third-party audits/security assessments and/or continuous monitoring reports/alerts (SIEM tool, etc.).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== CA.L2-3.12.4 – System Security Plan ====&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;width: 85%;&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_CA.L2-3.12.4_Details|&#039;&#039;&#039;CA.L2-3.12.4&#039;&#039;&#039;]] Develop, document, and periodically update system security plans that describe system boundaries, system environments of operation, how security requirements are implemented, and the relationships with or connections to other systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] a system security plan is developed. || Document || SSP.&lt;br /&gt;
|-&lt;br /&gt;
| [b] the system boundary is described and documented in the system security plan. || Document || SSP and any supporting documentation.&lt;br /&gt;
|-&lt;br /&gt;
| [c] the system environment of operation is described and documented in the system security plan. || Document || SSP and any supporting documentation.&lt;br /&gt;
|-&lt;br /&gt;
| [d] the security requirements identified and approved by the designated authority as non-applicable are identified. || Document || SSP and required adjudication from DoD CIO.&lt;br /&gt;
|-&lt;br /&gt;
| [e] the method of security requirement implementation is described and documented in the system security plan. || Document || SSP and any supporting documentation.&lt;br /&gt;
|-&lt;br /&gt;
| [f] the relationship with or connection to other systems is described and documented in the system security plan. || Document || SSP and any supporting documentation.&lt;br /&gt;
|-&lt;br /&gt;
| [g] the frequency to update the system security plan is defined. || Document || SSP.&lt;br /&gt;
|-&lt;br /&gt;
| [h] system security plan is updated with the defined frequency. || Document || SSP/any previous versions.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== System and Communications Protection (SC) ==&lt;br /&gt;
=== SC.L2-3.13.1 – Boundary Protection [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;width: 85%;&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.1_Details|&#039;&#039;&#039;SC.L2-3.13.1&#039;&#039;&#039;]] Monitor, control, and protect organizational communications (i.e., information transmitted or received by organizational information systems) at the external boundaries and key internal boundaries of the information systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the external system boundary is defined. || Document || SSP, network diagrams, CUI flow, cloud provider FedRAMP Moderate.&lt;br /&gt;
|-&lt;br /&gt;
| [b] key internal system boundaries are defined. || Document || SSP, network diagrams, CUI flow.&lt;br /&gt;
|-&lt;br /&gt;
| [c] communications are monitored at the external system boundary. || Screen Share || SSP, logging server, boundary device configurations, monitoring policy.&lt;br /&gt;
|-&lt;br /&gt;
| [d] communications are monitored at key internal boundaries. || Screen Share || SSP, logging server, boundary device configurations, monitoring policy.&lt;br /&gt;
|-&lt;br /&gt;
| [e] communications are controlled at the external system boundary. || Screen Share || SSP, boundary device configurations, ACL, subnets, DMZ.&lt;br /&gt;
|-&lt;br /&gt;
| [f] communications are controlled at key internal boundaries. || Screen Share || SSP, boundary device configurations, ACL, subnets.&lt;br /&gt;
|-&lt;br /&gt;
| [g] communications are protected at the external system boundary. || Screen Share || Configurations for IPS/IDS, email gateway, VLAN, proxy, firewall, malware protection, DNS, TSL.&lt;br /&gt;
|-&lt;br /&gt;
| [h] communications are protected at key internal boundaries. || Screen Share || Configurations for IPS/IDS, VLAN, firewall, malware protection, SSL.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.2 – Security Engineering ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;width: 85%;&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.2_Details|&#039;&#039;&#039;SC.L2-3.13.2&#039;&#039;&#039;]] Employ architectural designs, software development techniques, and systems engineering principles that promote effective information security within organizational systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] architectural designs that promote effective information security are identified. || Document || SSP, config management policy, network diagram, CCB minutes, enterprise architecture process.&lt;br /&gt;
|-&lt;br /&gt;
| [b] software development techniques that promote effective information security are identified. || Document || SSP, config management policy, SDLC, CCB minutes.&lt;br /&gt;
|-&lt;br /&gt;
| [c] systems engineering principles that promote effective information security are identified. || Document || SSP, config management policy, CCB minutes, security architecture engineering.&lt;br /&gt;
|-&lt;br /&gt;
| [d] identified architectural designs that promote effective information security are employed. || Artifact || CCB minutes, Network diagrams and configurations, Project Plans.&lt;br /&gt;
|-&lt;br /&gt;
| [e] identified software development techniques that promote effective information security are employed. || Artifact || CCB minutes, SDLC, code scanner results, code management tracking.&lt;br /&gt;
|-&lt;br /&gt;
| [f] identified systems engineering principles that promote effective information security are employed. || Artifact || CCB minutes, configuration management, ITSM, patch management, lifecycle replacement processes.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.3 – Role Separation ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;width: 85%;&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.3_Details|&#039;&#039;&#039;SC.L2-3.13.3&#039;&#039;&#039;]] Separate user functionality from system management functionality.&lt;br /&gt;
|-&lt;br /&gt;
| [a] user functionality is identified. || Document || SSP, AUP.&lt;br /&gt;
|-&lt;br /&gt;
| [b] system management functionality is identified. || Document || SSP, Privileged Account Agreement.&lt;br /&gt;
|-&lt;br /&gt;
| [c] user functionality is separated from system management functionality. || Screen Share || Active Directory, Jump Boxes, GPO, VM, RDP.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.4 – Shared Resource Control ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;width: 85%;&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.4_Details|&#039;&#039;&#039;SC.L2-3.13.4&#039;&#039;&#039;]] Prevent unauthorized and unintended information transfer via shared system resources.&lt;br /&gt;
|-&lt;br /&gt;
| [a] unauthorized and unintended information transfer via shared system resources is prevented. || Screen Share || SSP, OS configurations, Linux containers, system/media reuse policies, certificate management policies, media destruction policies, printer configs, VDI configuration.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
===  SC.L2-3.13.5 – Public-Access System Separation [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;width: 85%;&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.5_Details|&#039;&#039;&#039;SC.L2-3.13.5&#039;&#039;&#039;]] Implement subnetworks for publicly accessible system components that are physically or logically separated from internal networks.&lt;br /&gt;
|-&lt;br /&gt;
| [a] publicly accessible system components are identified. || Document || SSP, network diagram, DMZ inventory/roles.&lt;br /&gt;
|-&lt;br /&gt;
| [b] subnetworks for publicly accessible system components are physically or logically separated from internal networks. || Artifact || Network diagram, IPAM, VLAN, DHCP, DMZ.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.6 – Network Communication by Exception ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;width: 85%;&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.6_Details|&#039;&#039;&#039;SC.L2-3.13.6&#039;&#039;&#039;]] Deny network communications traffic by default and allow network communications traffic by exception (i.e., deny all, permit by exception).&lt;br /&gt;
|-&lt;br /&gt;
| [a] network communications traffic is denied by default. || Screen Share || Host and network firewall rules, SIEM logs, hit counts.&lt;br /&gt;
|-&lt;br /&gt;
| [b] network communications traffic is allowed by exception. || Screen Share || Host and network firewall rules, SIEM logs, hit counts.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.7 – Split Tunneling ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;width: 85%;&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.7_Details|&#039;&#039;&#039;SC.L2-3.13.7&#039;&#039;&#039;]] Prevent remote devices from simultaneously establishing non-remote connections with organizational systems and communicating via some other connection to resources in external networks (i.e., split tunneling).&lt;br /&gt;
|-&lt;br /&gt;
| [a] remote devices are prevented from simultaneously establishing non-remote connections with the system and communicating via some other connection to resources in external networks (i.e., split tunneling). || Screen Share || VPN appliance/server configuration, endpoint VPN software configuration.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.8 – Data in Transit ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;width: 85%;&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.8_Details|&#039;&#039;&#039;SC.L2-3.13.8&#039;&#039;&#039;]] Implement cryptographic mechanisms to prevent unauthorized disclosure of CUI during transmission unless otherwise protected by alternative physical safeguards.&lt;br /&gt;
|-&lt;br /&gt;
| [a] cryptographic mechanisms intended to prevent unauthorized disclosure of CUI are identified. || Document || SSP, PKI policies, configuration processes, config management, email attachment encryption policy, removable media policy, data at rest policy.&lt;br /&gt;
|-&lt;br /&gt;
| [b] alternative physical safeguards intended to prevent unauthorized disclosure of CUI are identified. || Document || SSP, physical security policy.&lt;br /&gt;
|-&lt;br /&gt;
| [c] either cryptographic mechanisms or alternative physical safeguards are implemented to prevent unauthorized disclosure of CUI during transmission. || Screen Share || TLS settings, SSL settings, VPN/Wireless Access Points/Mobile Devices cryptographic settings, ODBC connector settings, SAN configuration, IPSec/MPLS, backup configuration, physical security.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.9 – Connections Termination ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;width: 85%;&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.9_Details|&#039;&#039;&#039;SC.L2-3.13.9&#039;&#039;&#039;]] Terminate network connections associated with communications sessions at the end of the sessions or after a defined period of inactivity.&lt;br /&gt;
|-&lt;br /&gt;
| [a] a period of inactivity to terminate network connections associated with communications sessions is defined. || Document || SSP, network communications policy.&lt;br /&gt;
|-&lt;br /&gt;
| [b] network connections associated with communications sessions are terminated at the end of the sessions. || Screen Share || VPN appliance/server logs, VPN configurations, web server configurations, firewall connection settings.&lt;br /&gt;
|-&lt;br /&gt;
| [c] network connections associated with communications sessions are terminated after the defined period of inactivity. || Screen Share || VPN appliance/server logs, VPN configurations, web server configurations, frewall connection settings.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.10 – Key Management ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;width: 85%;&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.10_Details|&#039;&#039;&#039;SC.L2-3.13.10&#039;&#039;&#039;]] Establish and manage cryptographic keys for cryptography employed in organizational systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] cryptographic keys are established whenever cryptography is employed. || Artifact || SSP, PKI/certificate management policy, configuration management.&lt;br /&gt;
|-&lt;br /&gt;
| [b] cryptographic keys are managed whenever cryptography is employed. || Artifact || SSP, PKI/certificate management policy, configuration management, access control policy.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.11 – CUI Encryption ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;width: 85%;&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.11_Details|&#039;&#039;&#039;SC.L2-3.13.11&#039;&#039;&#039;]] Employ FIPS-validated cryptography when used to protect the confidentiality of CUI.&lt;br /&gt;
|-&lt;br /&gt;
| [a] FIPS-validated cryptography is employed to protect the confidentiality of CUI. || Screen Share || VPN, wireless, mobile devices, client certificates, server certificates, disk encryption, Outlook plugin, external mail, backup media, ePO server, removable storage, SAN, file compression; look for FIPS mode enabled on appliances.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.12 – Collaborative Device Control ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;width: 85%;&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.12_Details|&#039;&#039;&#039;SC.L2-3.13.12&#039;&#039;&#039;]] Prohibit remote activation of collaborative computing devices and provide indication of devices in use to users present at the device.&lt;br /&gt;
|-&lt;br /&gt;
| [a] collaborative computing devices are identified. || Document || SSP, network diagrams.&lt;br /&gt;
|-&lt;br /&gt;
| [b] collaborative computing devices provide indication to users of devices in use. || Physical Review || Physical inspection of device.&lt;br /&gt;
|-&lt;br /&gt;
| [c] remote activation of collaborative computing devices is prohibited. || Screen Share || Collaboration device configuration/console.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.13 – Mobile Code ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;width: 85%;&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.13_Details|&#039;&#039;&#039;SC.L2-3.13.13&#039;&#039;&#039;]] Control and monitor the use of mobile code.&lt;br /&gt;
|-&lt;br /&gt;
| [a] use of mobile code is controlled. || Screen Share || GPO settings, malware protection, software agent configurations, software development policies, code scanners, MDM configuration, firewall/secure web gateway/proxy config.&lt;br /&gt;
|-&lt;br /&gt;
| [b] use of mobile code is monitored. || Screen Share || SIEM/console monitoring.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.14 – Voice over Internet Protocol ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;width: 85%;&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.14_Details|&#039;&#039;&#039;SC.L2-3.13.14&#039;&#039;&#039;]] Control and monitor the use of Voice over Internet Protocol (VoIP) technologies.&lt;br /&gt;
|-&lt;br /&gt;
| [a] use of Voice over Internet Protocol (VoIP) technologies is controlled. || Artifact || VLAN, ACL, firewall config, VoIP gateway/condenser configuration.&lt;br /&gt;
|-&lt;br /&gt;
| [b] use of Voice over Internet Protocol (VoIP) technologies is monitored. || Artifact || SIEM/VoIP console monitoring, session border controller.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.15 – Communications Authenticity ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;width: 85%;&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.15_Details|&#039;&#039;&#039;SC.L2-3.13.15&#039;&#039;&#039;]] Protect the authenticity of communications sessions.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the authenticity of communications sessions is protected. || Screen Share || SSL, TLS, SMB3, SFTP, IPSec, SSH, Kerberos configs, MPLS, Network Access Control.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.16 – Data at Rest ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;width: 85%;&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SC.L2-3.13.16_Details|&#039;&#039;&#039;SC.L2-3.13.16&#039;&#039;&#039;]] Protect the confidentiality of CUI at rest.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the confidentiality of CUI at rest is protected. || Artifact || Full disk encryption, removable media encryption, SAN encryption, digital backups, mobile device encryption, third party offsite backup storage, cloud virtualization encryption, physical media storage policies.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== System and Information Integrity (SI) ==&lt;br /&gt;
=== SI.L2-3.14.1 – Flaw Remediation [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;width: 85%;&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SI.L2-3.14.1_Details|&#039;&#039;&#039;SI.L2-3.14.1&#039;&#039;&#039;]] Identify, report, and correct information and information system flaws in a timely manner.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the time within which to identify system flaws is specified. || Document || SSP, patch management policy.&lt;br /&gt;
|-&lt;br /&gt;
| [b] system flaws are identified within the specified time frame. || Screen Share || Vulnerability management scanner output and scan policy configuration.&lt;br /&gt;
|-&lt;br /&gt;
| [c] the time within which to report system flaws is specified. || Document || SSP, patch management policy.&lt;br /&gt;
|-&lt;br /&gt;
| [d] system flaws are reported within the specified time frame. || Screen Share || ITSM/trouble tickets, vulnerability management scanner output.&lt;br /&gt;
|-&lt;br /&gt;
| [e] the time within which to correct system flaws is specified. || Document || SSP, patch management policy.&lt;br /&gt;
|-&lt;br /&gt;
| [f] system flaws are corrected within the specified time frame. || Screen Share || Vulnerability management scanner output and scan policy configuration.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SI.L2-3.14.2 – Malicious Code ProTection [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;width: 85%;&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SI.L2-3.14.2_Details|&#039;&#039;&#039;SI.L2-3.14.2&#039;&#039;&#039;]] Provide protection from malicious code at appropriate locations within organizational information systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] designated locations for malicious code protection are identified. || Document || SSP, system protection policy, network diagrams, security architecture documents.&lt;br /&gt;
|-&lt;br /&gt;
| [b] protection from malicious code at designated locations is provided. || Screen Share || Endpoint security settings, email/web proxy gateways, firewall, IPS sensor, MDM configuration, Network Access Control.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SI.L2-3.14.3 – Security Alerts &amp;amp; Advisories ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;width: 85%;&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SI.L2-3.14.3_Details|&#039;&#039;&#039;SI.L2-3.14.3&#039;&#039;&#039;]] Monitor system security alerts and advisories and take action in response.&lt;br /&gt;
|-&lt;br /&gt;
| [a] response actions to system security alerts and advisories are identified. || Document || SSP, vulnerability management policy, Incident Response Plan.&lt;br /&gt;
|-&lt;br /&gt;
| [b] system security alerts and advisories are monitored. || Artifact || Threat intelligence subscriptions, email advisories.&lt;br /&gt;
|-&lt;br /&gt;
| [c] actions in response to system security alerts and advisories are taken. || Artifact || ITSM/trouble tickets, user notifications, updates to firewall/IPS, etc.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SI.L2-3.14.4 – Update Malicious Code Protection [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;width: 85%;&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SI.L2-3.14.4_Details|&#039;&#039;&#039;SI.L2-3.14.4&#039;&#039;&#039;]] Update malicious code protection mechanisms when new releases are available.&lt;br /&gt;
|-&lt;br /&gt;
| [a] malicious code protection mechanisms are updated when new releases are available. || Screen Share || Antivirus console dashboard, firewall AV, Email gateway signatures,proxy, IPS updates.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SI.L2-3.14.5 – System &amp;amp; File Scanning [CUI Data] ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;width: 85%;&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SI.L2-3.14.5_Details|&#039;&#039;&#039;SI.L2-3.14.5&#039;&#039;&#039;]] Perform periodic scans of the information system and real-time scans of files from external sources as files are downloaded, opened, or executed.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the frequency for malicious code scans is defined. || Document || SSP, vulnerability management policy.&lt;br /&gt;
|-&lt;br /&gt;
| [b] malicious code scans are performed with the defined frequency. || Screen Share || Consoles for AV (endpoints, servers, and file shares), firewall, email gateway, proxy, IPS, MDM configurations.&lt;br /&gt;
|-&lt;br /&gt;
| [c] real-time malicious code scans of files from external sources as files are downloaded, opened, or executed are performed. || Screen Share || Consoles for AV (endpoints, servers, and file shares), firewall, email gateway, proxy, IPS, MDM configurations.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SI.L2-3.14.6 – Monitor Communications for Attacks ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;width: 85%;&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SI.L2-3.14.6_Details|&#039;&#039;&#039;SI.L2-3.14.6&#039;&#039;&#039;]] Monitor organizational systems, including inbound and outbound communications traffic, to detect attacks and indicators of potential attacks.&lt;br /&gt;
|-&lt;br /&gt;
| [a] the system is monitored to detect attacks and indicators of potential attacks. || Screen Share || Firewall, IPS, endpoint protection, SIEM alerts and reports.&lt;br /&gt;
|-&lt;br /&gt;
| [b] inbound communications traffic is monitored to detect attacks and indicators of potential attacks. || Screen Share || Firewall, IPS, endpoint protection, SIEM alerts and reports.&lt;br /&gt;
|-&lt;br /&gt;
| [c] outbound communications traffic is monitored to detect attacks and indicators of potential attacks. || Screen Share || Firewall, IPS, endpoint protection, SIEM alerts and reports.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SI.L2-3.14.7 – Identify Unauthorized Use ===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;width: 85%;&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 35%&amp;quot;| &#039;&#039;&#039;Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;Collection Approach&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 50%&amp;quot;| &#039;&#039;&#039;Evidence Examples&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;3&amp;quot; | [[Practice_SI.L2-3.14.7_Details|&#039;&#039;&#039;SI.L2-3.14.7&#039;&#039;&#039;]] Identify unauthorized use of organizational systems.&lt;br /&gt;
|-&lt;br /&gt;
| [a] authorized use of the system is defined. || Document || AUP, SSP.&lt;br /&gt;
|-&lt;br /&gt;
| [b] unauthorized use of the system is identified. || Artifact || SIEM logs, endpoint protection console, IPS, Firewall.&lt;br /&gt;
|}&lt;/div&gt;</summary>
		<author><name>David</name></author>
	</entry>
	<entry>
		<id>https://cmmcwiki.org/index.php?title=DoD_Memo_on_ODPs_for_800-171_Revision_3&amp;diff=1613</id>
		<title>DoD Memo on ODPs for 800-171 Revision 3</title>
		<link rel="alternate" type="text/html" href="https://cmmcwiki.org/index.php?title=DoD_Memo_on_ODPs_for_800-171_Revision_3&amp;diff=1613"/>
		<updated>2026-07-17T17:18:24Z</updated>

		<summary type="html">&lt;p&gt;David: Created page with &amp;quot;{{DISPLAYTITLE:DoD Organization-Defined Parameters for NIST SP 800-171 Revision 3}}  == Overview ==  A key aspect of &amp;#039;&amp;#039;&amp;#039;NIST Special Publication 800-171 Revision 3&amp;#039;&amp;#039;&amp;#039; (&amp;#039;&amp;#039;Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations&amp;#039;&amp;#039;, May 2024) is the inclusion of &amp;#039;&amp;#039;&amp;#039;organization-defined parameters (ODPs)&amp;#039;&amp;#039;&amp;#039;, which allow organizations to tailor select security controls to specific security requirements, as determined by unique organizational risk...&amp;quot;&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{DISPLAYTITLE:DoD Organization-Defined Parameters for NIST SP 800-171 Revision 3}}&lt;br /&gt;
&lt;br /&gt;
== Overview ==&lt;br /&gt;
&lt;br /&gt;
A key aspect of &#039;&#039;&#039;NIST Special Publication 800-171 Revision 3&#039;&#039;&#039; (&#039;&#039;Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations&#039;&#039;, May 2024) is the inclusion of &#039;&#039;&#039;organization-defined parameters (ODPs)&#039;&#039;&#039;, which allow organizations to tailor select security controls to specific security requirements, as determined by unique organizational risk management strategies.&lt;br /&gt;
&lt;br /&gt;
In preparation to implement NIST SP 800-171 Revision 3 as the minimum requirement for contractors, the Department of Defense (DoD) has defined as policy the values below for the ODPs identified in the source document.&lt;br /&gt;
&lt;br /&gt;
ODP values found in existing federal frameworks served as the foundation for the initial values. Input was collected from DoD offices, external government agencies, and subject matter experts from University-Affiliated Research Centers and Federally Funded Research and Development Centers. Additional input from industry stakeholders was included where appropriate. In four instances, the ODP has been defined as &#039;&#039;&#039;guidance&#039;&#039;&#039; rather than a specified value. These ODP values represent a consensus position of DoD stakeholders and will be updated as necessary.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Reference:&#039;&#039;&#039; National Institute of Standards and Technology (NIST) Special Publication 800-171 Revision 3, May 2024.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Memorandum Signed By:&#039;&#039;&#039; David W. McKeown, Performing the Duties of the Deputy DoD CIO for Cybersecurity and DoD Chief Information Security Officer.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Note:&#039;&#039;&#039; Throughout this page, the term &amp;quot;significant&amp;quot; is defined as &#039;&#039;&amp;quot;having or likely to have influence or effect.&amp;quot;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
== Access Control ==&lt;br /&gt;
&lt;br /&gt;
=== 3.1.1 System Account Management ===&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Requirement text:&#039;&#039;&#039;&lt;br /&gt;
# Define the types of system accounts allowed and prohibited.&lt;br /&gt;
# Create, enable, modify, disable, and remove system accounts in accordance with policy, procedures, prerequisites, and criteria.&lt;br /&gt;
# Specify:&lt;br /&gt;
## Authorized users of the system,&lt;br /&gt;
## Group and role membership, and&lt;br /&gt;
## Access authorizations (i.e., privileges) for each account.&lt;br /&gt;
# Authorize access to the system based on:&lt;br /&gt;
## A valid access authorization and&lt;br /&gt;
## Intended system usage.&lt;br /&gt;
# Monitor the use of system accounts.&lt;br /&gt;
# Disable system accounts when:&lt;br /&gt;
## The accounts have expired,&lt;br /&gt;
## The accounts have been inactive for [Assignment: organization-defined time period] (03.01.01.f.02),&lt;br /&gt;
## The accounts are no longer associated with a user or individual,&lt;br /&gt;
## The accounts are in violation of organizational policy, or&lt;br /&gt;
## Significant risks associated with individuals are discovered.&lt;br /&gt;
# Notify account managers and designated personnel or roles within:&lt;br /&gt;
## [Assignment: organization-defined time period] (03.01.01.g.01) when accounts are no longer required,&lt;br /&gt;
## [Assignment: organization-defined time period] (03.01.01.g.02) when users are terminated or transferred, and&lt;br /&gt;
## [Assignment: organization-defined time period] (03.01.01.g.03) when system usage or the need-to-know changes for an individual.&lt;br /&gt;
# Require that users log out of the system after:&lt;br /&gt;
## [Assignment: organization-defined time period] (03.01.01.h.01) of expected inactivity, or&lt;br /&gt;
## When [Assignment: organization-defined circumstances] (03.01.01.h.02).&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Related Controls:&#039;&#039;&#039; AC-02, AC-02(03), AC-02(05), AC-02(13)&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! ODP Identifier !! ODP Assignment Text !! ODP Value&lt;br /&gt;
|-&lt;br /&gt;
| 03.01.01.f.02 || organization-defined time period || at most 90 days&lt;br /&gt;
|-&lt;br /&gt;
| 03.01.01.g.01 || organization-defined time period || 24 hours&lt;br /&gt;
|-&lt;br /&gt;
| 03.01.01.g.02 || organization-defined time period || 24 hours&lt;br /&gt;
|-&lt;br /&gt;
| 03.01.01.g.03 || organization-defined time period || 24 hours&lt;br /&gt;
|-&lt;br /&gt;
| 03.01.01.h.01 || organization-defined time period || at most 24 hours&lt;br /&gt;
|-&lt;br /&gt;
| 03.01.01.h.02 || organization-defined circumstances || the work period ends, for privileged users at a minimum&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== 3.1.5 System Access Authorization ===&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Requirement text:&#039;&#039;&#039;&lt;br /&gt;
# Allow only authorized system access for users (or processes acting on behalf of users) that is necessary to accomplish assigned organizational tasks.&lt;br /&gt;
# Authorize access to:&lt;br /&gt;
## [Assignment: organization-defined security functions] (03.01.05.b.01), and&lt;br /&gt;
## [Assignment: organization-defined security-relevant information] (03.01.05.b.02).&lt;br /&gt;
# Review the privileges assigned to roles or classes of users [Assignment: organization-defined frequency] (03.01.05.c) to validate the need for such privileges.&lt;br /&gt;
# Reassign or remove privileges, as necessary.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Related Controls:&#039;&#039;&#039; AC-06, AC-06(01), AC-06(07), AU-09(04)&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! ODP Identifier !! ODP Assignment Text !! ODP Value&lt;br /&gt;
|-&lt;br /&gt;
| 03.01.05.b.01 || organization-defined security functions || at a minimum and if applicable: establishing system accounts and assigning privileges, configuring access authorizations, configuring settings for events to be audited, establishing vulnerability scanning parameters, establishing intrusion detection parameters, and managing audit information&lt;br /&gt;
|-&lt;br /&gt;
| 03.01.05.b.02 || organization-defined security-relevant information || at a minimum and if applicable: threat and vulnerability information, filtering rules for routers or firewalls, configuration parameters for security services, cryptographic key management information, security architecture, access control lists, and audit information&lt;br /&gt;
|-&lt;br /&gt;
| 03.01.05.c || organization-defined frequency || at least every 12 months&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== 3.1.6 Privileged Account Management ===&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Requirement text:&#039;&#039;&#039;&lt;br /&gt;
# Restrict privileged accounts on the system to [Assignment: organization-defined personnel or roles] (03.01.06.a).&lt;br /&gt;
# Require that users (or roles) with privileged accounts use non-privileged accounts when accessing non-security functions or non-security information.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Related Controls:&#039;&#039;&#039; AC-06(02), AC-06(05)&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! ODP Identifier !! ODP Assignment Text !! ODP Value&lt;br /&gt;
|-&lt;br /&gt;
| 03.01.06.a || organization-defined personnel or roles || only defined and authorized personnel or administrative roles&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== 3.1.8 Invalid Logon Attempts ===&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Requirement text:&#039;&#039;&#039;&lt;br /&gt;
# Enforce a limit of [Assignment: organization-defined number] (03.01.08.a.01) consecutive invalid logon attempts by a user during a [Assignment: organization-defined time period] (03.01.08.a.02).&lt;br /&gt;
# Automatically [Selection (one or more): lock the account or node for an [Assignment: organization-defined time period]; lock the account or node until released by an administrator; delay next logon prompt; notify system administrator; take other action] (03.01.08.b) when the maximum number of unsuccessful attempts is exceeded.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Related Controls:&#039;&#039;&#039; AC-07&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! ODP Identifier !! ODP Assignment Text !! ODP Value&lt;br /&gt;
|-&lt;br /&gt;
| 03.01.08.a.01 || organization-defined number || at most five (5)&lt;br /&gt;
|-&lt;br /&gt;
| 03.01.08.a.02 || organization-defined time period || period of five (5) minutes&lt;br /&gt;
|-&lt;br /&gt;
| 03.01.08.b || organization-defined time period (selection) || lock the account or node for at least a 15-minute time period; lock the account or node until released by an administrator and notify a system administrator&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== 3.1.10 Device Lock ===&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Requirement text:&#039;&#039;&#039;&lt;br /&gt;
# Prevent access to the system by [Selection (one or more): initiating a device lock after [Assignment: organization-defined time period] (03.01.10.a) of inactivity; requiring the user to initiate a device lock before leaving the system unattended].&lt;br /&gt;
# Retain the device lock until the user reestablishes access using established identification and authentication procedures.&lt;br /&gt;
# Conceal, via the device lock, information previously visible on the display with a publicly viewable image.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Related Controls:&#039;&#039;&#039; AC-11, AC-11(01)&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! ODP Identifier !! ODP Assignment Text !! ODP Value&lt;br /&gt;
|-&lt;br /&gt;
| 03.01.10.a || organization-defined time period || initiating a device lock after &amp;quot;at most 15 minutes&amp;quot; of inactivity and requiring the user to initiate a device lock before leaving the system unattended&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== 3.1.11 Session Termination ===&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Requirement text:&#039;&#039;&#039; Terminate a user session automatically after [Assignment: organization-defined conditions or trigger events requiring session disconnect] (03.01.11).&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Related Controls:&#039;&#039;&#039; AC-12&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! ODP Identifier !! ODP Assignment Text !! ODP Value&lt;br /&gt;
|-&lt;br /&gt;
| 03.01.11 || organization-defined conditions or trigger events requiring session disconnect || a specified duration (maximum of 24 hours) of inactivity, misbehavior (end the session due to an attempted policy violation), and maintenance (terminate sessions to prevent issues with an upgrade or service outage)&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== 3.1.20 Use of External Systems ===&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Requirement text:&#039;&#039;&#039;&lt;br /&gt;
# Prohibit the use of external systems unless the systems are specifically authorized.&lt;br /&gt;
# Establish the following security requirements to be satisfied on external systems prior to allowing use of or access to those systems by authorized individuals: [Assignment: organization-defined security requirements] (03.01.20.b).&lt;br /&gt;
# Permit authorized individuals to use external systems to access the organizational system or to process, store, or transmit CUI only after:&lt;br /&gt;
## Verifying that the security requirements on the external systems as specified in the organization&#039;s system security plans have been satisfied, and&lt;br /&gt;
## Retaining approved system connection or processing agreements with the organizational entities hosting the external systems.&lt;br /&gt;
# Restrict the use of organization-controlled portable storage devices by authorized individuals on external systems.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Related Controls:&#039;&#039;&#039; AC-20, AC-20(01), AC-20(02)&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! ODP Identifier !! ODP Assignment Text !! ODP Value&lt;br /&gt;
|-&lt;br /&gt;
| 03.01.20.b || organization-defined security requirements || &#039;&#039;&#039;Guidance:&#039;&#039;&#039; Organizations establish specific terms and conditions for the use of external systems in accordance with organizational security policies and procedures. At a minimum, terms and conditions address the specific types of applications that can be accessed on organizational systems from external systems and the highest security category of information that can be processed, stored, or transmitted on external systems. If the terms and conditions with the owners of the external systems cannot be established, organizations may impose restrictions on organizational personnel using those external systems. If applicable, use NIST SP 800-47 as a guide for establishing information exchanges between organizations.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Awareness and Training ==&lt;br /&gt;
&lt;br /&gt;
=== 3.2.1 Security Literacy Training ===&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Requirement text:&#039;&#039;&#039;&lt;br /&gt;
# Provide security literacy training to system users:&lt;br /&gt;
## As part of initial training for new users and [Assignment: organization-defined frequency] (03.02.01.a.01) thereafter,&lt;br /&gt;
## When required by system changes or following [Assignment: organization-defined events] (03.02.01.a.02), and&lt;br /&gt;
## On recognizing and reporting indicators of insider threat, social engineering, and social mining.&lt;br /&gt;
# Update security literacy training content [Assignment: organization-defined frequency] (03.02.01.b.01) and following [Assignment: organization-defined events] (03.02.01.b.02).&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Related Controls:&#039;&#039;&#039; AT-02, AT-02(02), AT-02(03)&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! ODP Identifier !! ODP Assignment Text !! ODP Value&lt;br /&gt;
|-&lt;br /&gt;
| 03.02.01.a.01 || organization-defined frequency || at least every 12 months&lt;br /&gt;
|-&lt;br /&gt;
| 03.02.01.a.02 || organization-defined events || significant, novel incidents, or significant changes to risks&lt;br /&gt;
|-&lt;br /&gt;
| 03.02.01.b.01 || organization-defined frequency || at least every 12 months&lt;br /&gt;
|-&lt;br /&gt;
| 03.02.01.b.02 || organization-defined events || significant, novel incidents, or significant changes to risks&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== 3.2.2 Role-Based Security Training ===&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Requirement text:&#039;&#039;&#039;&lt;br /&gt;
# Provide role-based security training to organizational personnel:&lt;br /&gt;
## Before authorizing access to the system or CUI, before performing assigned duties, and [Assignment: organization-defined frequency] (03.02.02.a.01) thereafter,&lt;br /&gt;
## When required by system changes or following [Assignment: organization-defined events] (03.02.02.a.02).&lt;br /&gt;
# Update role-based training content [Assignment: organization-defined frequency] (03.02.02.b.01) and following [Assignment: organization-defined events] (03.02.02.b.02).&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Related Controls:&#039;&#039;&#039; AT-03&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! ODP Identifier !! ODP Assignment Text !! ODP Value&lt;br /&gt;
|-&lt;br /&gt;
| 03.02.02.a.01 || organization-defined frequency || at least every 12 months&lt;br /&gt;
|-&lt;br /&gt;
| 03.02.02.a.02 || organization-defined events || significant, novel incidents, or significant changes to risks&lt;br /&gt;
|-&lt;br /&gt;
| 03.02.02.b.01 || organization-defined frequency || at least every 12 months&lt;br /&gt;
|-&lt;br /&gt;
| 03.02.02.b.02 || organization-defined events || significant, novel incidents, or significant changes to risks&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Audit and Accountability ==&lt;br /&gt;
&lt;br /&gt;
=== 3.3.1 Event Logging ===&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Requirement text:&#039;&#039;&#039;&lt;br /&gt;
# Specify the following event types selected for logging within the system: [Assignment: organization-defined event types] (03.03.01.a).&lt;br /&gt;
# Review and update the event types selected for logging [Assignment: organization-defined frequency] (03.03.01.b).&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Related Controls:&#039;&#039;&#039; AU-02&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! ODP Identifier !! ODP Assignment Text !! ODP Value&lt;br /&gt;
|-&lt;br /&gt;
| 03.03.01.a || organization-defined event types || At a minimum and where applicable:&lt;br /&gt;
# Authentication events: Logons (Success/Failure); Logoffs (Success)&lt;br /&gt;
# Security Relevant File and Objects events: Create, Access, Delete, Modify, Permission Modification, Ownership Modification (Success/Failure)&lt;br /&gt;
# Export/Writes/downloads to devices/digital media (e.g., CD/DVD, USB, SD) (Success/Failure)&lt;br /&gt;
# Import/Uploads from devices/digital media (e.g., CD/DVD, USB, SD) (Success/Failure)&lt;br /&gt;
# User and Group Management events: User add, delete, modify, disable, lock (Success/Failure); Group/Role add, delete, modify (Success/Failure)&lt;br /&gt;
# Use of Privileged/Special Rights events: Security or audit policy changes (Success/Failure); Configuration changes (Success/Failure)&lt;br /&gt;
# Admin or root-level access (Success/Failure)&lt;br /&gt;
# Privilege/Role escalation (Success/Failure)&lt;br /&gt;
# Audit and security relevant log data accesses (Success/Failure)&lt;br /&gt;
# System reboot, restart, and shutdown (Success/Failure)&lt;br /&gt;
# Print to a device (Success/Failure)&lt;br /&gt;
# Print to a file (e.g., pdf format) (Success/Failure)&lt;br /&gt;
# Application (e.g., Adobe, Firefox, MS Office Suite) initialization (Success/Failure)&lt;br /&gt;
&lt;br /&gt;
For additional guidance, see: OMB 21-31 ML 1&lt;br /&gt;
|-&lt;br /&gt;
| 03.03.01.b || organization-defined frequency || at least every 12 months and after any significant incidents or significant changes to risks&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== 3.3.4 Audit Logging Process Failure ===&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Requirement text:&#039;&#039;&#039;&lt;br /&gt;
# Alert organizational personnel or roles within [Assignment: organization-defined time period] (03.03.04.a) in the event of an audit logging process failure.&lt;br /&gt;
# Take the following additional actions: [Assignment: organization-defined additional actions] (03.03.04.b).&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Related Controls:&#039;&#039;&#039; AU-05&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! ODP Identifier !! ODP Assignment Text !! ODP Value&lt;br /&gt;
|-&lt;br /&gt;
| 03.03.04.a || organization-defined time period || near real time or as soon as practicable upon discovery&lt;br /&gt;
|-&lt;br /&gt;
| 03.03.04.b || organization-defined additional actions || document the failure and resolution, troubleshoot, repair/restart the audit logging process, and report as incident if applicable&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== 3.3.5 Audit Record Review and Analysis ===&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Requirement text:&#039;&#039;&#039;&lt;br /&gt;
# Review and analyze system audit records [Assignment: organization-defined frequency] (03.03.05.a) for indications and the potential impact of inappropriate or unusual activity.&lt;br /&gt;
# Report findings to organizational personnel or roles.&lt;br /&gt;
# Analyze and correlate audit records across different repositories to gain organization-wide situational awareness.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Related Controls:&#039;&#039;&#039; AU-06, AU-06(03)&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! ODP Identifier !! ODP Assignment Text !! ODP Value&lt;br /&gt;
|-&lt;br /&gt;
| 03.03.05.a || organization-defined frequency || at least weekly&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== 3.3.7 Time Stamps for Audit Records ===&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Requirement text:&#039;&#039;&#039;&lt;br /&gt;
# Use internal system clocks to generate time stamps for audit records.&lt;br /&gt;
# Record time stamps for audit records that meet [Assignment: organization-defined granularity of time measurement] (03.03.07.b) and that use Coordinated Universal Time (UTC), have a fixed local time offset from UTC, or include the local time offset as part of the time stamp.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Related Controls:&#039;&#039;&#039; AU-08&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! ODP Identifier !! ODP Assignment Text !! ODP Value&lt;br /&gt;
|-&lt;br /&gt;
| 03.03.07.b || organization-defined granularity of time measurement || a granularity of one (1) second or smaller&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Configuration Management ==&lt;br /&gt;
&lt;br /&gt;
=== 3.4.1 Baseline Configuration ===&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Requirement text:&#039;&#039;&#039;&lt;br /&gt;
# Develop and maintain under configuration control, a current baseline configuration of the system.&lt;br /&gt;
# Review and update the baseline configuration of the system [Assignment: organization-defined frequency] (03.04.01.b) and when system components are installed or modified.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Related Controls:&#039;&#039;&#039; CM-02&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! ODP Identifier !! ODP Assignment Text !! ODP Value&lt;br /&gt;
|-&lt;br /&gt;
| 03.04.01.b || organization-defined frequency || at least every 12 months and after any significant incidents or significant changes occur&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== 3.4.2 Configuration Settings ===&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Requirement text:&#039;&#039;&#039;&lt;br /&gt;
# Establish, document, and implement the following configuration settings for the system that reflect the most restrictive mode consistent with operational requirements: [Assignment: organization-defined configuration settings] (03.04.02.a).&lt;br /&gt;
# Identify, document, and approve any deviations from established configuration settings.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Related Controls:&#039;&#039;&#039; CM-06&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! ODP Identifier !! ODP Assignment Text !! ODP Value&lt;br /&gt;
|-&lt;br /&gt;
| 03.04.02.a || organization-defined configuration settings || Apply the appropriate use of common security configurations available from the National Institute of Standards and Technology&#039;s National Checklist Program (NCP) website (https://ncp.nist.gov/repository) and prevent remote devices from simultaneously establishing non-remote connections with organizational systems and communicating via some other unauthorized connection to resources in external networks. Document any deviations from the published standard or source document.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== 3.4.6 System Configuration ===&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Requirement text:&#039;&#039;&#039;&lt;br /&gt;
# Configure the system to provide only mission-essential capabilities.&lt;br /&gt;
# Prohibit or restrict use of the following functions, ports, protocols, connections, and services: [Assignment: organization-defined functions, ports, protocols, connections, and services] (03.04.06.b).&lt;br /&gt;
# Review the system [Assignment: organization-defined frequency] (03.04.06.c) to identify unnecessary or nonsecure functions, ports, protocols, connections, and services.&lt;br /&gt;
# Disable or remove functions, ports, protocols, connections, and services that are unnecessary or nonsecure.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Related Controls:&#039;&#039;&#039; CM-07, CM-07(01)&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! ODP Identifier !! ODP Assignment Text !! ODP Value&lt;br /&gt;
|-&lt;br /&gt;
| 03.04.06.b || organization-defined functions, ports, protocols, connections, and services || &#039;&#039;&#039;Guidance:&#039;&#039;&#039; Where feasible, organizations should limit component functionality to a single function per component. Organizations should consider removing unused or unnecessary software and disabling unused or unnecessary physical and logical ports and protocols to prevent unauthorized connection of components, transfer of information, and tunneling. Organizations should employ network scanning tools, intrusion detection and prevention systems, and end-point protection technologies, such as firewalls and host-based intrusion detection systems, to identify and prevent the use of prohibited functions, protocols, ports, and services. Least functionality should also be achieved as part of the fundamental design and development of the system.&lt;br /&gt;
|-&lt;br /&gt;
| 03.04.06.c || organization-defined frequency || at least every 12 months, when any system functions, ports, protocols, or services changes are made, and after any significant incidents or significant changes to risks&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== 3.4.8 Software Execution Authorization ===&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Requirement text:&#039;&#039;&#039;&lt;br /&gt;
# Identify software programs authorized to execute on the system.&lt;br /&gt;
# Implement a deny-all, allow-by-exception policy for the execution of authorized software programs on the system.&lt;br /&gt;
# Review and update the list of authorized software programs [Assignment: organization-defined frequency] (03.04.08.c).&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Related Controls:&#039;&#039;&#039; CM-07(05)&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! ODP Identifier !! ODP Assignment Text !! ODP Value&lt;br /&gt;
|-&lt;br /&gt;
| 03.04.08.c || organization-defined frequency || at least quarterly&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== 3.4.10 System Component Inventory ===&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Requirement text:&#039;&#039;&#039;&lt;br /&gt;
# Develop and document an inventory of system components.&lt;br /&gt;
# Review and update the system component inventory [Assignment: organization-defined frequency] (03.04.10.b).&lt;br /&gt;
# Update the system component inventory as part of installations, removals, and system updates.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Related Controls:&#039;&#039;&#039; CM-08, CM-08(01)&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! ODP Identifier !! ODP Assignment Text !! ODP Value&lt;br /&gt;
|-&lt;br /&gt;
| 03.04.10.b || organization-defined frequency || at least quarterly&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== 3.4.12 System Configurations for High-Risk Locations ===&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Requirement text:&#039;&#039;&#039;&lt;br /&gt;
# Issue systems or system components with the following configurations to individuals traveling to high-risk locations: [Assignment: organization-defined system configurations] (03.04.12.a).&lt;br /&gt;
# Apply the following security requirements to the systems or components when the individuals return from travel: [Assignment: organization-defined security requirements] (03.04.12.b).&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Related Controls:&#039;&#039;&#039; CM-02(07)&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! ODP Identifier !! ODP Assignment Text !! ODP Value&lt;br /&gt;
|-&lt;br /&gt;
| 03.04.12.a || organization-defined system configurations || a configuration that has no CUI or FCI stored on the system and prevents the processing, storing, and transmission of CUI and FCI, unless a specific exception is granted in writing by the Contracting Officer&lt;br /&gt;
|-&lt;br /&gt;
| 03.04.12.b || organization-defined security requirements || examine the system for signs of physical tampering and take the appropriate actions, and then either purge and reimage all storage media or destroy the system&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Identification and Authentication ==&lt;br /&gt;
&lt;br /&gt;
=== 3.5.1 User Identification and Authentication ===&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Requirement text:&#039;&#039;&#039;&lt;br /&gt;
# Uniquely identify and authenticate system users, and associate that unique identification with processes acting on behalf of those users.&lt;br /&gt;
# Re-authenticate users when [Assignment: organization-defined circumstances or situations requiring re-authentication] (03.05.01.b).&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Related Controls:&#039;&#039;&#039; IA-02, IA-11&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! ODP Identifier !! ODP Assignment Text !! ODP Value&lt;br /&gt;
|-&lt;br /&gt;
| 03.05.01.b || organization-defined circumstances or situations requiring re-authentication || roles, authenticators, or credentials change (including modification of user privilege); when security categories of systems change; when the execution of privileged functions occurs; and after a session termination&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== 3.5.2 Device Identification and Authentication ===&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Requirement text:&#039;&#039;&#039; Uniquely identify and authenticate [Assignment: organization-defined devices or types of devices] (03.05.02) before establishing a system connection.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Related Controls:&#039;&#039;&#039; IA-03&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! ODP Identifier !! ODP Assignment Text !! ODP Value&lt;br /&gt;
|-&lt;br /&gt;
| 03.05.02 || organization-defined devices or types of devices || all devices for identification, where feasible for authentication, and document when not feasible&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== 3.5.5 Identifier Management ===&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Requirement text:&#039;&#039;&#039;&lt;br /&gt;
# Receive authorization from organizational personnel or roles to assign an individual, group, role, service, or device identifier.&lt;br /&gt;
# Select and assign an identifier that identifies an individual, group, role, service, or device.&lt;br /&gt;
# Prevent the reuse of identifiers for [Assignment: organization-defined time period] (03.05.05.c).&lt;br /&gt;
# Manage individual identifiers by uniquely identifying each individual as [Assignment: organization-defined characteristic identifying individual status] (03.05.05.d).&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Related Controls:&#039;&#039;&#039; IA-04, IA-04(04)&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! ODP Identifier !! ODP Assignment Text !! ODP Value&lt;br /&gt;
|-&lt;br /&gt;
| 03.05.05.c || organization-defined time period || at least ten (10) years&lt;br /&gt;
|-&lt;br /&gt;
| 03.05.05.d || organization-defined characteristic identifying individual status || privileged or non-privileged users; contractors, foreign nationals, and/or non-organizational users&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== 3.5.7 Password Management ===&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Requirement text:&#039;&#039;&#039;&lt;br /&gt;
# Maintain a list of commonly used, expected, or compromised passwords, and update the list [Assignment: organization-defined frequency] (03.05.07.a) and when organizational passwords are suspected to have been compromised.&lt;br /&gt;
# Verify that passwords are not found on the list of commonly used, expected, or compromised passwords when users create or update passwords.&lt;br /&gt;
# Transmit passwords only over cryptographically protected channels.&lt;br /&gt;
# Store passwords in a cryptographically protected form.&lt;br /&gt;
# Select a new password upon first use after account recovery.&lt;br /&gt;
# Enforce the following composition and complexity rules for passwords: [Assignment: organization-defined composition and complexity rules] (03.05.07.f).&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Related Controls:&#039;&#039;&#039; IA-05(01)&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! ODP Identifier !! ODP Assignment Text !! ODP Value&lt;br /&gt;
|-&lt;br /&gt;
| 03.05.07.a || organization-defined frequency || at least quarterly&lt;br /&gt;
|-&lt;br /&gt;
| 03.05.07.f || organization-defined composition and complexity rules || 1) Must have a minimum length of 16 characters. 2) Contains a string of characters that does not include the user&#039;s account name or full name.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== 3.5.12 Authenticator Management ===&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Requirement text:&#039;&#039;&#039;&lt;br /&gt;
# Verify the identity of the individual, group, role, service, or device receiving the authenticator as part of the initial authenticator distribution.&lt;br /&gt;
# Establish initial authenticator content for any authenticators issued by the organization.&lt;br /&gt;
# Establish and implement administrative procedures for initial authenticator distribution; for lost, compromised, or damaged authenticators; and for revoking authenticators.&lt;br /&gt;
# Change default authenticators at first use.&lt;br /&gt;
# Change or refresh authenticators [Assignment: organization-defined frequency] (03.05.12.e.01) or when the following events occur: [Assignment: organization-defined events] (03.05.12.e.02).&lt;br /&gt;
# Protect authenticator content from unauthorized disclosure and modification.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Related Controls:&#039;&#039;&#039; IA-05&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! ODP Identifier !! ODP Assignment Text !! ODP Value&lt;br /&gt;
|-&lt;br /&gt;
| 03.05.12.e.01 || organization-defined frequency || never for passwords where MFA is employed, at least every five (5) years for hard tokens and identification badges, and at least every three (3) years for all other authenticators&lt;br /&gt;
|-&lt;br /&gt;
| 03.05.12.e.02 || organization-defined events || after a relevant security incident or any evidence of compromise or loss&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Incident Response ==&lt;br /&gt;
&lt;br /&gt;
=== 3.6.2 Incident Tracking and Reporting ===&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Requirement text:&#039;&#039;&#039;&lt;br /&gt;
# Track and document system security incidents.&lt;br /&gt;
# Report suspected incidents to the organizational incident response capability within [Assignment: organization-defined time period] (03.06.02.b).&lt;br /&gt;
# Report incident information to [Assignment: organization-defined authorities] (03.06.02.c).&lt;br /&gt;
# Provide an incident response support resource that offers advice and assistance to system users on handling and reporting incidents.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Related Controls:&#039;&#039;&#039; IR-05, IR-06, IR-07&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! ODP Identifier !! ODP Assignment Text !! ODP Value&lt;br /&gt;
|-&lt;br /&gt;
| 03.06.02.b || organization-defined time period || near real time or as soon as practicable upon discovery&lt;br /&gt;
|-&lt;br /&gt;
| 03.06.02.c || organization-defined authorities || all applicable personnel and entities as specified by the contract, and in accordance with any incident response plan notification procedures&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== 3.6.3 Incident Response Testing ===&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Requirement text:&#039;&#039;&#039; Test the effectiveness of the incident response capability [Assignment: organization-defined frequency] (03.06.03).&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Related Controls:&#039;&#039;&#039; IR-03&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! ODP Identifier !! ODP Assignment Text !! ODP Value&lt;br /&gt;
|-&lt;br /&gt;
| 03.06.03 || organization-defined frequency || at least every 12 months&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== 3.6.4 Incident Response Training ===&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Requirement text:&#039;&#039;&#039;&lt;br /&gt;
# Provide incident response training to system users consistent with assigned roles and responsibilities:&lt;br /&gt;
## Within [Assignment: organization-defined time period] (03.06.04.a.01) of assuming an incident response role or responsibility or acquiring system access,&lt;br /&gt;
## When required by system changes, and&lt;br /&gt;
## [Assignment: organization-defined frequency] (03.06.04.a.03) thereafter.&lt;br /&gt;
# Review and update incident response training content [Assignment: organization-defined frequency] (03.06.04.b.01) and following [Assignment: organization-defined events] (03.06.04.b.02).&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Related Controls:&#039;&#039;&#039; IR-02&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! ODP Identifier !! ODP Assignment Text !! ODP Value&lt;br /&gt;
|-&lt;br /&gt;
| 03.06.04.a.01 || organization-defined time period || ten (10) days for privileged users, thirty (30) days for all other roles&lt;br /&gt;
|-&lt;br /&gt;
| 03.06.04.a.03 || organization-defined frequency || at least every 12 months&lt;br /&gt;
|-&lt;br /&gt;
| 03.06.04.b.01 || organization-defined frequency || at least every 12 months&lt;br /&gt;
|-&lt;br /&gt;
| 03.06.04.b.02 || organization-defined events || significant, novel incidents, or significant changes to risks&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Media Protection ==&lt;br /&gt;
&lt;br /&gt;
=== 3.8.7 System Media Restrictions ===&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Requirement text:&#039;&#039;&#039;&lt;br /&gt;
# Restrict or prohibit the use of [Assignment: organization-defined types of system media] (03.08.07.a).&lt;br /&gt;
# Prohibit the use of removable system media without an identifiable owner.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Related Controls:&#039;&#039;&#039; MP-07&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! ODP Identifier !! ODP Assignment Text !! ODP Value&lt;br /&gt;
|-&lt;br /&gt;
| 03.08.07.a || organization-defined types of system media || any removable media not managed by or on behalf of the organization&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Personnel Security ==&lt;br /&gt;
&lt;br /&gt;
=== 3.9.1 Screening and Rescreening ===&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Requirement text:&#039;&#039;&#039;&lt;br /&gt;
# Screen individuals prior to authorizing access to the system.&lt;br /&gt;
# Rescreen individuals in accordance with [Assignment: organization-defined conditions requiring rescreening] (03.09.01.b).&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Related Controls:&#039;&#039;&#039; PS-03&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! ODP Identifier !! ODP Assignment Text !! ODP Value&lt;br /&gt;
|-&lt;br /&gt;
| 03.09.01.b || organization-defined conditions requiring rescreening || an organizational policy requiring rescreening when there is a significant incident, or change in status, related to an individual&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== 3.9.2 Employment Termination and Reassignment ===&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Requirement text:&#039;&#039;&#039;&lt;br /&gt;
# When individual employment is terminated:&lt;br /&gt;
## Disable system access within [Assignment: organization-defined time period] (03.09.02.a.01),&lt;br /&gt;
## Terminate or revoke authenticators and credentials associated with the individual, and&lt;br /&gt;
## Retrieve security-related system property.&lt;br /&gt;
# When individuals are reassigned or transferred to other positions in the organization:&lt;br /&gt;
## Review and confirm the ongoing operational need for current logical and physical access authorizations to the system and facility, and&lt;br /&gt;
## Modify access authorization to correspond with any changes in operational need.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Related Controls:&#039;&#039;&#039; PS-04, PS-05&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! ODP Identifier !! ODP Assignment Text !! ODP Value&lt;br /&gt;
|-&lt;br /&gt;
| 03.09.02.a.01 || organization-defined time period || four (4) hours&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Physical Protection ==&lt;br /&gt;
&lt;br /&gt;
=== 3.10.1 Facility Access Control ===&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Requirement text:&#039;&#039;&#039;&lt;br /&gt;
# Develop, approve, and maintain a list of individuals with authorized access to the facility where the system resides.&lt;br /&gt;
# Issue authorization credentials for facility access.&lt;br /&gt;
# Review the facility access list [Assignment: organization-defined frequency] (03.10.01.c).&lt;br /&gt;
# Remove individuals from the facility access list when access is no longer required.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Related Controls:&#039;&#039;&#039; PE-02&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! ODP Identifier !! ODP Assignment Text !! ODP Value&lt;br /&gt;
|-&lt;br /&gt;
| 03.10.01.c || organization-defined frequency || at least every 12 months, or when there are significant incidents or significant changes to risks&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== 3.10.2 Physical Access Monitoring and Review ===&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Requirement text:&#039;&#039;&#039;&lt;br /&gt;
# Monitor physical access to the facility where the system resides to detect and respond to physical security incidents.&lt;br /&gt;
# Review physical access logs [Assignment: organization-defined frequency] (03.10.02.b.01) and upon occurrence of [Assignment: organization-defined events or potential indications of events] (03.10.02.b.02).&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Related Controls:&#039;&#039;&#039; PE-06&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! ODP Identifier !! ODP Assignment Text !! ODP Value&lt;br /&gt;
|-&lt;br /&gt;
| 03.10.02.b.01 || organization-defined frequency || at least every 45 days&lt;br /&gt;
|-&lt;br /&gt;
| 03.10.02.b.02 || organization-defined events or potential indications of events || significant, novel incidents, or significant changes to risks&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== 3.10.6 Alternate Work Sites ===&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Requirement text:&#039;&#039;&#039;&lt;br /&gt;
# Determine alternate work sites allowed for use by employees.&lt;br /&gt;
# Employ the following security requirements at alternate work sites: [Assignment: organization-defined security requirements] (03.10.06.b).&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Related Controls:&#039;&#039;&#039; PE-17&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! ODP Identifier !! ODP Assignment Text !! ODP Value&lt;br /&gt;
|-&lt;br /&gt;
| 03.10.06.b || organization-defined security requirements || adequate security, comparable to organizational security requirements at the primary work site where practical, documented in policy, and covered by training&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Risk Assessment ==&lt;br /&gt;
&lt;br /&gt;
=== 3.11.1 Risk Assessment ===&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Requirement text:&#039;&#039;&#039;&lt;br /&gt;
# Assess the risk (including supply chain risk) of unauthorized disclosure resulting from the processing, storage, or transmission of CUI.&lt;br /&gt;
# Update risk assessments [Assignment: organization-defined frequency] (03.11.01.b).&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Related Controls:&#039;&#039;&#039; RA-03, RA-03(01), SR-06&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! ODP Identifier !! ODP Assignment Text !! ODP Value&lt;br /&gt;
|-&lt;br /&gt;
| 03.11.01.b || organization-defined frequency || at least every 12 months, or when there are significant incidents or significant changes to risks&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== 3.11.2 System Vulnerability Management ===&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Requirement text:&#039;&#039;&#039;&lt;br /&gt;
# Monitor and scan the system for vulnerabilities [Assignment: organization-defined frequency] (03.11.02.a) and when new vulnerabilities affecting the system are identified.&lt;br /&gt;
# Remediate system vulnerabilities within [Assignment: organization-defined response times] (03.11.02.b).&lt;br /&gt;
# Update system vulnerabilities to be scanned [Assignment: organization-defined frequency] (03.11.02.c) and when new vulnerabilities are identified and reported.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Related Controls:&#039;&#039;&#039; RA-05, RA-05(02)&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! ODP Identifier !! ODP Assignment Text !! ODP Value&lt;br /&gt;
|-&lt;br /&gt;
| 03.11.02.a || organization-defined frequency || at least monthly, or when there are significant incidents or significant changes to risks&lt;br /&gt;
|-&lt;br /&gt;
| 03.11.02.b || organization-defined response times || thirty (30) days from date of discovery for high-risk vulnerabilities (including both critical and high); 90 days from date of discovery for moderate-risk vulnerabilities; and 180 days from date of discovery for low-risk vulnerabilities&lt;br /&gt;
|-&lt;br /&gt;
| 03.11.02.c || organization-defined frequency || no more than 24 hours prior to running the scans&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Security Assessment and Monitoring ==&lt;br /&gt;
&lt;br /&gt;
=== 3.12.1 Security Requirements Assessment ===&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Requirement text:&#039;&#039;&#039; Assess the security requirements for the system and its environment of operation [Assignment: organization-defined frequency] (03.12.01) to determine if the requirements have been satisfied.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Related Controls:&#039;&#039;&#039; CA-02&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! ODP Identifier !! ODP Assignment Text !! ODP Value&lt;br /&gt;
|-&lt;br /&gt;
| 03.12.01 || organization-defined frequency || at least every 12 months, or when there are significant incidents or significant changes to risks&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== 3.12.5 Exchange of Controlled Unclassified Information (CUI) ===&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Requirement text:&#039;&#039;&#039;&lt;br /&gt;
# Approve and manage the exchange of CUI between the system and other systems using [Selection (one or more): interconnection security agreements; information exchange security agreements; memoranda of understanding or agreement; service-level agreements; user agreements; non-disclosure agreements; other types of agreements] (03.12.05.a).&lt;br /&gt;
# Document interface characteristics, security requirements, and responsibilities for each system as part of the exchange agreements.&lt;br /&gt;
# Review and update the exchange agreements [Assignment: organization-defined frequency] (03.12.05.c).&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Related Controls:&#039;&#039;&#039; CA-03&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! ODP Identifier !! ODP Assignment Text !! ODP Value&lt;br /&gt;
|-&lt;br /&gt;
| 03.12.05.a || selection (one or more): types of agreements || requirements as described in the contract&lt;br /&gt;
|-&lt;br /&gt;
| 03.12.05.c || organization-defined frequency || at least every 12 months&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== System and Communications Protection ==&lt;br /&gt;
&lt;br /&gt;
=== 3.13.9 Termination of Network Connections ===&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Requirement text:&#039;&#039;&#039; Terminate the network connection associated with a communications session at the end of the session or after [Assignment: organization-defined time period] (03.13.09) of inactivity.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Related Controls:&#039;&#039;&#039; SC-10&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! ODP Identifier !! ODP Assignment Text !! ODP Value&lt;br /&gt;
|-&lt;br /&gt;
| 03.13.09 || organization-defined time period || no longer than 15 minutes&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== 3.13.10 Cryptographic Key Management ===&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Requirement text:&#039;&#039;&#039; Establish and manage cryptographic keys in the system in accordance with the following key management requirements: [Assignment: organization-defined requirements for key generation, distribution, storage, access, and destruction] (03.13.10).&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Related Controls:&#039;&#039;&#039; SC-12&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! ODP Identifier !! ODP Assignment Text !! ODP Value&lt;br /&gt;
|-&lt;br /&gt;
| 03.13.10 || organization-defined requirements for key generation, distribution, storage, access, and destruction || &#039;&#039;&#039;Guidance:&#039;&#039;&#039; At a minimum, establish a policy and procedure in line with the latest Cryptographic key management guidance&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== 3.13.11 Cryptography for Confidentiality of CUI ===&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Requirement text:&#039;&#039;&#039; Implement the following types of cryptography to protect the confidentiality of CUI: [Assignment: organization-defined types of cryptography] (03.13.11).&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Related Controls:&#039;&#039;&#039; SC-13&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! ODP Identifier !! ODP Assignment Text !! ODP Value&lt;br /&gt;
|-&lt;br /&gt;
| 03.13.11 || organization-defined types of cryptography || FIPS Validated Cryptography (https://csrc.nist.gov/Projects/Cryptographic-Module-Validation-Program/Validated-Modules)&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== 3.13.12 Remote Activation of Collaborative Computing Devices ===&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Requirement text:&#039;&#039;&#039;&lt;br /&gt;
# Prohibit the remote activation of collaborative computing devices and applications with the following exceptions: [Assignment: organization-defined exceptions where remote activation is to be allowed] (03.13.12.a).&lt;br /&gt;
# Provide an explicit indication of use to users physically present at the devices.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Related Controls:&#039;&#039;&#039; SC-15&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! ODP Identifier !! ODP Assignment Text !! ODP Value&lt;br /&gt;
|-&lt;br /&gt;
| 03.13.12.a || organization-defined exceptions where remote activation is to be allowed || only as enumerated and justified in the System Security Plan before such remote activation occurs, and only when there are no other options, and the remote activation is operationally critical&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== System and Information Integrity ==&lt;br /&gt;
&lt;br /&gt;
=== 3.14.1 System Flaw Remediation ===&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Requirement text:&#039;&#039;&#039;&lt;br /&gt;
# Identify, report, and correct system flaws.&lt;br /&gt;
# Install security-relevant software and firmware updates within [Assignment: organization-defined time period] (03.14.01.b) of the release of the updates.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Related Controls:&#039;&#039;&#039; SI-02&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! ODP Identifier !! ODP Assignment Text !! ODP Value&lt;br /&gt;
|-&lt;br /&gt;
| 03.14.01.b || organization-defined time period || thirty (30) days for high-risk flaws (including both critical and high), 90 days for moderate-risk flaws, and 180 days for low-risk flaws&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== 3.14.2 Malicious Code Protection ===&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Requirement text:&#039;&#039;&#039;&lt;br /&gt;
# Implement malicious code protection mechanisms at system entry and exit points to detect and eradicate malicious code.&lt;br /&gt;
# Update malicious code protection mechanisms as new releases are available in accordance with configuration management policies and procedures.&lt;br /&gt;
# Configure malicious code protection mechanisms to:&lt;br /&gt;
## Perform scans of the system [Assignment: organization-defined frequency] (03.14.02.c.01) and real-time scans of files from external sources at endpoints or system entry and exit points as the files are downloaded, opened, or executed; and&lt;br /&gt;
## Block malicious code, quarantine malicious code, or take other mitigation actions in response to malicious code detection.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Related Controls:&#039;&#039;&#039; SI-03&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! ODP Identifier !! ODP Assignment Text !! ODP Value&lt;br /&gt;
|-&lt;br /&gt;
| 03.14.02.c.01 || organization-defined frequency || at least weekly&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Planning ==&lt;br /&gt;
&lt;br /&gt;
=== 3.15.1 Policy and Procedure Development ===&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Requirement text:&#039;&#039;&#039;&lt;br /&gt;
# Develop, document, and disseminate to organizational personnel or roles the policies and procedures needed to satisfy the security requirements for the protection of CUI.&lt;br /&gt;
# Review and update policies and procedures [Assignment: organization-defined frequency] (03.15.01.b).&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Related Controls:&#039;&#039;&#039; AC-01, AT-01, AU-01, CA-01, CM-01, IA-01, IR-01, MA-01, MP-01, PE-01, PL-01, PS-01, RA-01, SA-01, SC-01, SI-01, SR-01&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! ODP Identifier !! ODP Assignment Text !! ODP Value&lt;br /&gt;
|-&lt;br /&gt;
| 03.15.01.b || organization-defined frequency || at least every 12 months, or when there are significant incidents or significant changes to risks&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== 3.15.2 System Security Plan ===&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Requirement text:&#039;&#039;&#039;&lt;br /&gt;
# Develop a system security plan that:&lt;br /&gt;
## Defines the constituent system components;&lt;br /&gt;
## Identifies the information types processed, stored, and transmitted by the system;&lt;br /&gt;
## Describes specific threats to the system that are of concern to the organization;&lt;br /&gt;
## Describes the operational environment for the system and any dependencies on or connections to other systems or system components;&lt;br /&gt;
## Provides an overview of the security requirements for the system;&lt;br /&gt;
## Describes the safeguards in place or planned for meeting the security requirements;&lt;br /&gt;
## Identifies individuals that fulfill system roles and responsibilities; and&lt;br /&gt;
## Includes other relevant information necessary for the protection of CUI.&lt;br /&gt;
# Review and update the system security plan [Assignment: organization-defined frequency] (03.15.02.b).&lt;br /&gt;
# Protect the system security plan from unauthorized disclosure.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Related Controls:&#039;&#039;&#039; PL-02&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! ODP Identifier !! ODP Assignment Text !! ODP Value&lt;br /&gt;
|-&lt;br /&gt;
| 03.15.02.b || organization-defined frequency || at least every 12 months, or when there are significant incidents or significant changes to risks&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== 3.15.3 Rules of Behavior ===&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Requirement text:&#039;&#039;&#039;&lt;br /&gt;
# Establish rules that describe the responsibilities and expected behavior for system usage and protecting CUI.&lt;br /&gt;
# Provide rules to individuals who require access to the system.&lt;br /&gt;
# Receive a documented acknowledgement from individuals indicating that they have read, understand, and agree to abide by the rules of behavior before authorizing access to CUI and the system.&lt;br /&gt;
# Review and update the rules of behavior [Assignment: organization-defined frequency] (03.15.03.d).&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Related Controls:&#039;&#039;&#039; PL-04&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! ODP Identifier !! ODP Assignment Text !! ODP Value&lt;br /&gt;
|-&lt;br /&gt;
| 03.15.03.d || organization-defined frequency || at least every 12 months, or when there are significant incidents or significant changes to risks&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== System and Services Acquisition ==&lt;br /&gt;
&lt;br /&gt;
=== 3.16.1 Systems Security Engineering Principles ===&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Requirement text:&#039;&#039;&#039; Apply the following systems security engineering principles to the development or modification of the system and system components: [Assignment: organization-defined systems security engineering principles] (03.16.01).&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Related Controls:&#039;&#039;&#039; SA-08&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! ODP Identifier !! ODP Assignment Text !! ODP Value&lt;br /&gt;
|-&lt;br /&gt;
| 03.16.01 || organization-defined systems security engineering principles || &#039;&#039;&#039;Guidance:&#039;&#039;&#039; At a minimum, documentation that provides user and administrator guidance for the implementation and operation of controls. The level of detail required in such documentation should be based on the degree to which organizations depend on the capabilities, functions, or mechanisms to meet risk response expectations. Requirements can include mandated configuration settings that specify allowed functions, ports, protocols, and services. Acceptance criteria for systems, system components, and system services are defined in the same manner as the criteria for any organizational acquisition or procurement.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== 3.16.3 External System Services ===&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Requirement text:&#039;&#039;&#039;&lt;br /&gt;
# Require the providers of external system services used for the processing, storage, or transmission of CUI to comply with the following security requirements: [Assignment: organization-defined security requirements] (03.16.03.a).&lt;br /&gt;
# Define and document user roles and responsibilities with regard to external system services, including shared responsibilities with external service providers.&lt;br /&gt;
# Implement processes, methods, and techniques to monitor security requirement compliance by external service providers on an ongoing basis.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Related Controls:&#039;&#039;&#039; SA-09&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! ODP Identifier !! ODP Assignment Text !! ODP Value&lt;br /&gt;
|-&lt;br /&gt;
| 03.16.03.a || organization-defined security requirements || 1. For cloud service providers: (i) FedRAMP Authorized at the FedRAMP Moderate (or higher) baseline in accordance with the FedRAMP Marketplace; or (ii) meets security requirements established by the government equivalent to the FedRAMP Moderate (or higher) baseline. 2. All other external service providers&amp;lt;ref&amp;gt;External Service Providers (ESP): External people, technology, or facilities that an organization utilizes for provision and management of IT and/or cybersecurity services on behalf of the organization.&amp;lt;/ref&amp;gt; must meet NIST SP 800-171 R2.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Supply Chain Risk Management ==&lt;br /&gt;
&lt;br /&gt;
=== 3.17.1 Supply Chain Risk Management Plan ===&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Requirement text:&#039;&#039;&#039;&lt;br /&gt;
# Develop a plan for managing supply chain risks associated with the research and development, design, manufacturing, acquisition, delivery, integration, operations, maintenance, and disposal of the system, system components, or system services.&lt;br /&gt;
# Review and update the supply chain risk management plan [Assignment: organization-defined frequency] (03.17.01.b).&lt;br /&gt;
# Protect the supply chain risk management plan from unauthorized disclosure.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Related Controls:&#039;&#039;&#039; SR-02&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! ODP Identifier !! ODP Assignment Text !! ODP Value&lt;br /&gt;
|-&lt;br /&gt;
| 03.17.01.b || organization-defined frequency || at least every 12 months, or when there are significant incidents or significant changes to risks&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== 3.17.3 Supply Chain Security Requirements ===&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Requirement text:&#039;&#039;&#039;&lt;br /&gt;
# Establish a process for identifying and addressing weaknesses or deficiencies in the supply chain elements and processes.&lt;br /&gt;
# Enforce the following security requirements to protect against supply chain risks to the system, system components, or system services and to limit the harm or consequences from supply chain-related events: [Assignment: organization-defined security requirements] (03.17.03.b).&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Related Controls:&#039;&#039;&#039; SR-03&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! ODP Identifier !! ODP Assignment Text !! ODP Value&lt;br /&gt;
|-&lt;br /&gt;
| 03.17.03.b || organization-defined security requirements || at a minimum, integrate Supply Chain Risk Management (SCRM) into acquisition/procurement policies, provide adequate SCRM resources, define the SCRM control baseline, establish processes to ensure suppliers disclose significant vulnerabilities and significant incidents&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Notes ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;references/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[[Category:NIST SP 800-171]]&lt;br /&gt;
[[Category:CMMC]]&lt;br /&gt;
[[Category:DoD Cybersecurity Policy]]&lt;/div&gt;</summary>
		<author><name>David</name></author>
	</entry>
	<entry>
		<id>https://cmmcwiki.org/index.php?title=MediaWiki:Sidebar&amp;diff=1612</id>
		<title>MediaWiki:Sidebar</title>
		<link rel="alternate" type="text/html" href="https://cmmcwiki.org/index.php?title=MediaWiki:Sidebar&amp;diff=1612"/>
		<updated>2026-07-17T17:18:00Z</updated>

		<summary type="html">&lt;p&gt;David: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;* navigation&lt;br /&gt;
** mainpage | mainpage-description&lt;br /&gt;
* CMMC Model and Rule&lt;br /&gt;
** Model_Overview | Model Overview&lt;br /&gt;
** 32_CFR_Part_170 | 32 CFR Part 170&lt;br /&gt;
** 48_CFR_Parts_204_212_217_252 | 48 CFR Parts 204, 212, 217, and 252&lt;br /&gt;
* Scoping and Assessment Guides&lt;br /&gt;
** Level_1_Scoping_Guidance | Level 1 Scoping Guidance&lt;br /&gt;
** Level_1_Self-Assessment_Guide | Level 1 Self-Assessment Guide&lt;br /&gt;
** Level_2_Scoping_Guidance | Level 2 Scoping Guidance&lt;br /&gt;
** Level_2_Assessment_Guide | Level 2 Assessment Guide&lt;br /&gt;
** Level_3_Scoping_Guidance | Level 3 Scoping Guidance&lt;br /&gt;
** Level_3_Assessment_Guide | Level 3 Assessment Guide&lt;br /&gt;
* CMMC Guides and Tools&lt;br /&gt;
** CMMC_Hashing_Guide | CMMC Hashing Guide&lt;br /&gt;
** CMMC_Assessment_Process | CMMC Assessment Process (CAP) by CyberAB&lt;br /&gt;
** DoD_Assessment_Methodology | DoD Assessment Methodology&lt;br /&gt;
** DoD Memo on ODPs for 800-171 Revision 3 | DoD Memo on Organization-Defined Parameters for NIST 800-171 Revision 3&lt;br /&gt;
** External_References | External References&lt;/div&gt;</summary>
		<author><name>David</name></author>
	</entry>
	<entry>
		<id>https://cmmcwiki.org/index.php?title=Main_Page&amp;diff=1611</id>
		<title>Main Page</title>
		<link rel="alternate" type="text/html" href="https://cmmcwiki.org/index.php?title=Main_Page&amp;diff=1611"/>
		<updated>2026-07-17T16:06:04Z</updated>

		<summary type="html">&lt;p&gt;David: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&#039;&#039;&#039;This website contains information about the Cybersecurity Maturity Model Certification (CMMC) program of the U.S. Department of War (DoW).&lt;br /&gt;
&lt;br /&gt;
The wiki aims to provide educational references for those who are interested in learning more about the framework.&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
Primary Source of Reference: The official [https://dodcio.defense.gov/CMMC/ CMMC Home Page] from the Department of War Chief Information Officer (DoW CIO).&lt;br /&gt;
&lt;br /&gt;
Additional References: The [https://dodcio.defense.gov/cmmc/Resources-Documentation/ CMMC Resources &amp;amp; Documentation] page contains a variety of links to CMMC resources throughout the DoW.&lt;br /&gt;
&lt;br /&gt;
For inquiries and reporting errors on this wiki, please [mailto:support@cmmcwiki.org contact us]. Thank you.&lt;/div&gt;</summary>
		<author><name>David</name></author>
	</entry>
	<entry>
		<id>https://cmmcwiki.org/index.php?title=Main_Page&amp;diff=1610</id>
		<title>Main Page</title>
		<link rel="alternate" type="text/html" href="https://cmmcwiki.org/index.php?title=Main_Page&amp;diff=1610"/>
		<updated>2026-07-17T16:05:30Z</updated>

		<summary type="html">&lt;p&gt;David: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&#039;&#039;&#039;This website contains information about the Cybersecurity Maturity Model Certification (CMMC) program of the U.S. Department of Defense (DoD).&lt;br /&gt;
&lt;br /&gt;
The wiki aims to provide educational references for those who are interested in learning more about the framework.&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
Primary Source of Reference: The official [https://dodcio.defense.gov/CMMC/ CMMC Home Page] from the Department of War Chief Information Officer (DoW CIO).&lt;br /&gt;
&lt;br /&gt;
Additional References: The [https://dodcio.defense.gov/cmmc/Resources-Documentation/ CMMC Resources &amp;amp; Documentation] page contains a variety of links to CMMC resources throughout the DoW.&lt;br /&gt;
&lt;br /&gt;
For inquiries and reporting errors on this wiki, please [mailto:support@cmmcwiki.org contact us]. Thank you.&lt;/div&gt;</summary>
		<author><name>David</name></author>
	</entry>
	<entry>
		<id>https://cmmcwiki.org/index.php?title=48_CFR_Parts_204_212_217_252&amp;diff=1609</id>
		<title>48 CFR Parts 204 212 217 252</title>
		<link rel="alternate" type="text/html" href="https://cmmcwiki.org/index.php?title=48_CFR_Parts_204_212_217_252&amp;diff=1609"/>
		<updated>2026-07-17T15:53:58Z</updated>

		<summary type="html">&lt;p&gt;David: Created page with &amp;quot;{{DISPLAYTITLE:Defense Federal Acquisition Regulation Supplement: Assessing Contractor Implementation of Cybersecurity Requirements (DFARS Case 2019–D041)}}  &amp;#039;&amp;#039;&amp;#039;Federal Register&amp;#039;&amp;#039;&amp;#039; / Vol. 90, No. 173 / Wednesday, September 10, 2025 / Rules and Regulations  == Agency Information ==  {| class=&amp;quot;wikitable&amp;quot; |- ! Field !! Value |- | Agency || Defense Acquisition Regulations System, Department of Defense (DoD) |- | Action || Final rule |- | Docket || DARS–2020–0034 |- | R...&amp;quot;&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{DISPLAYTITLE:Defense Federal Acquisition Regulation Supplement: Assessing Contractor Implementation of Cybersecurity Requirements (DFARS Case 2019–D041)}}&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Federal Register&#039;&#039;&#039; / Vol. 90, No. 173 / Wednesday, September 10, 2025 / Rules and Regulations&lt;br /&gt;
&lt;br /&gt;
== Agency Information ==&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Field !! Value&lt;br /&gt;
|-&lt;br /&gt;
| Agency || Defense Acquisition Regulations System, Department of Defense (DoD)&lt;br /&gt;
|-&lt;br /&gt;
| Action || Final rule&lt;br /&gt;
|-&lt;br /&gt;
| Docket || DARS–2020–0034&lt;br /&gt;
|-&lt;br /&gt;
| RIN || 0750–AK81&lt;br /&gt;
|-&lt;br /&gt;
| Effective Date || November 10, 2025&lt;br /&gt;
|-&lt;br /&gt;
| Contact || Ms. Heather Kitchens, telephone 571–296–7152&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Summary ==&lt;br /&gt;
&lt;br /&gt;
DoD is issuing a final rule amending the Defense Federal Acquisition Regulation Supplement (DFARS) to incorporate contractual requirements related to the final Cybersecurity Maturity Model Certification (CMMC) program rule. This final DFARS rule also partially implements a section of the National Defense Authorization Act for Fiscal Year 2020 that directed the Secretary of Defense to develop a consistent, comprehensive framework to enhance cybersecurity for the U.S. defense industrial base.&lt;br /&gt;
&lt;br /&gt;
== I. Background ==&lt;br /&gt;
&lt;br /&gt;
* DoD published an interim rule in the Federal Register at 85 FR 61505 on September 29, 2020, to assess contractor implementation of cybersecurity requirements and enhance the protection of unclassified information within the DoD supply chain.&lt;br /&gt;
* DoD subsequently published a proposed rule at 89 FR 66327 on August 15, 2024, to implement the contractual requirements related to CMMC. Ninety-seven respondents submitted public comments in response to the proposed rule.&lt;br /&gt;
* Separately, a proposed rule to establish the CMMC program at 32 CFR part 170 was published at 88 FR 89058 on December 26, 2023. A final rule was published at 89 FR 83092 on October 15, 2024, and became effective on December 16, 2024.&lt;br /&gt;
&lt;br /&gt;
== II. Discussion and Analysis ==&lt;br /&gt;
&lt;br /&gt;
=== A. Summary of Significant Changes From the Proposed Rule ===&lt;br /&gt;
&lt;br /&gt;
==== 1. Definitions ====&lt;br /&gt;
&lt;br /&gt;
The final rule adds and modifies certain definitions at DFARS 204.7501, Definitions.&lt;br /&gt;
&lt;br /&gt;
* The definition of &amp;quot;current&amp;quot; was changed to clarify that it is related to having no changes in compliance with the requirements at 32 CFR part 170, and to clarify what &amp;quot;current&amp;quot; means when referring to &amp;quot;Conditional CMMC Status,&amp;quot; &amp;quot;Final CMMC Status,&amp;quot; and &amp;quot;affirmation of continuous compliance.&amp;quot;&lt;br /&gt;
* The term &amp;quot;DoD unique identifier&amp;quot; was updated to &amp;quot;CMMC unique identifier&amp;quot; to match the naming convention in the Supplier Performance Risk System (SPRS). The CMMC UID means ten alpha-numeric characters assigned to each contractor CMMC assessment and reflected in SPRS for each contractor information system.&lt;br /&gt;
* The final rule adds the definition of &amp;quot;Federal contract information&amp;quot; based on the definition from the clause at FAR 52.204–21.&lt;br /&gt;
* The final rule adds a definition of &amp;quot;plan of action and milestones&amp;quot; (POA&amp;amp;M) based on the definition codified at 32 CFR part 170.&lt;br /&gt;
* The final rule adds the term &amp;quot;CMMC status&amp;quot; and a definition for the term.&lt;br /&gt;
&lt;br /&gt;
==== 2. Policy ====&lt;br /&gt;
&lt;br /&gt;
DFARS 204.7502, Policy, includes language to add clarity by stating that for CMMC levels 2 and 3 only, a conditional CMMC status is permitted for a period not to exceed 180 days from the conditional CMMC date, in accordance with 32 CFR 170.21, and an award can occur with a CMMC conditional status. The language also clarifies that a final CMMC is achieved upon successful closeout of a valid POA&amp;amp;M.&lt;br /&gt;
&lt;br /&gt;
==== 3. Procedures ====&lt;br /&gt;
&lt;br /&gt;
* Language at DFARS 204.7503 was updated to add paragraph headings.&lt;br /&gt;
* Language clarifies that contracting officers are required to check SPRS and not award a contract, task order, or delivery order to an offeror that does not have a current CMMC status posted in SPRS at the CMMC level required by the solicitation, or higher, for each CMMC UID provided by the offeror.&lt;br /&gt;
* Paragraph (d) clarifies that all offerors are required to provide the CMMC UIDs applicable to each contractor information system that processes, stores, or transmits FCI or CUI and that will be used in performance of the contract.&lt;br /&gt;
&lt;br /&gt;
==== 4. Clause Prescription ====&lt;br /&gt;
&lt;br /&gt;
At DFARS 204.7504, the prescription for the contract clause has been updated to clarify the phased implementation approach:&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;Until three years after the effective date of the rule&#039;&#039;&#039;: the clause will be prescribed for use if program managers and requiring activities make a determination to apply a CMMC requirement to contracts, excluding awards solely for the acquisition of commercially available off-the-shelf (COTS) items (unless the requirements at 32 CFR 170.5(d) are met).&lt;br /&gt;
* &#039;&#039;&#039;Beginning three years and one day after the effective date of the rule&#039;&#039;&#039;: the clause will be prescribed for use if program managers and requiring activities determine that the contractor will be required to use contractor information systems in the performance of the contract to process, store, or transmit FCI or CUI, excluding awards solely for the acquisition of COTS items.&lt;br /&gt;
&lt;br /&gt;
==== 5. Solicitation Provision and Contract Clause ====&lt;br /&gt;
&lt;br /&gt;
* The contract clause has been updated to include a fill-in for the contracting officer to identify the CMMC level required by the contract.&lt;br /&gt;
* The subcontract flowdown language has been updated to identify that subcontractors also must submit affirmations of continuous compliance and the results of self-assessments in SPRS.&lt;br /&gt;
* The clause has been updated to include the term &amp;quot;affirming official&amp;quot; in place of &amp;quot;senior company official&amp;quot; to match 32 CFR part 170.&lt;br /&gt;
* The solicitation provision and contract clause include the terminology needed for entering the CMMC level: &#039;&#039;&#039;CMMC Level 1 (Self)&#039;&#039;&#039;; &#039;&#039;&#039;CMMC Level 2 (Self)&#039;&#039;&#039;; &#039;&#039;&#039;CMMC Level 2 (C3PAO)&#039;&#039;&#039;; or &#039;&#039;&#039;CMMC Level 3 (DIBCAC)&#039;&#039;&#039;.&lt;br /&gt;
* The solicitation provision clarifies that offerors will not be eligible for award if the offeror does not have a current CMMC status entered in SPRS at the required level and a current affirmation of continuous compliance for each applicable contractor information system.&lt;br /&gt;
&lt;br /&gt;
=== B. Analysis of Public Comments ===&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Note: Technical and programmatic comments on CMMC, and comments related to the CMMC cost analysis, were addressed in the CMMC program rule that codified 32 CFR part 170. This DFARS rule addresses the nontechnical and nonprogrammatic comments.&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
==== 1. Clarification of &amp;quot;Changes&amp;quot; ====&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Comment:&#039;&#039;&#039; Several respondents asked for more clarity regarding what &amp;quot;changes&amp;quot; means in the proposed rule.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Response:&#039;&#039;&#039; Based on public comment, the final DFARS rule adds the sentence: &amp;quot;Submit to the Contracting Officer . . . any changes in the CMMC UIDs generated in SPRS throughout the life of the contract, task order, or delivery order, if applicable.&amp;quot; The notification requirement to report lapses in information security or changes in compliance with 32 CFR part 170 was removed, since the reporting requirement at DFARS 252.204–7012 paragraph (c) already provides sufficient notification of relevant information security incidents.&lt;br /&gt;
&lt;br /&gt;
==== 2. Clarification of &amp;quot;Lapses in Information Security&amp;quot; ====&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Comment:&#039;&#039;&#039; Several respondents asked for clarity on &amp;quot;lapses in information security&amp;quot; in proposed paragraph (b)(4) at DFARS 252.204–7021; several recommended it be removed.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Response:&#039;&#039;&#039; The requirement to notify the contracting officer of lapses in information security or changes in CMMC status has been removed from the final rule.&lt;br /&gt;
&lt;br /&gt;
==== 3. Editorial Changes ====&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Comment:&#039;&#039;&#039; Respondents identified typos and recommended using &amp;quot;and/or&amp;quot; instead of &amp;quot;or&amp;quot; for CMMC UIDs.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Response:&#039;&#039;&#039; Editorial comments were noted; most were mooted by other final-rule changes. The &amp;quot;and/or&amp;quot; recommendation was &#039;&#039;&#039;not&#039;&#039;&#039; implemented because it could narrow the scope of the requirement beyond what was intended.&lt;br /&gt;
&lt;br /&gt;
==== 4. CMMC Level Notification and Compliance ====&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Comment:&#039;&#039;&#039; Respondents asked how the required CMMC level will be communicated and determined, and requested clarity on phase-in exemptions for small businesses.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Response:&#039;&#039;&#039; The CMMC level determination is made in accordance with 32 CFR 170.19 (CMMC scoping) by the program office/requiring activity (for the prime contract) or the prime/next higher-tier subcontractor (for subcontracts). CMMC levels are: CMMC Level 1 (Self); CMMC Level 2 (Self); CMMC Level 2 (C3PAO); and CMMC Level 3 (DIBCAC) (see 32 CFR 170.14). DoD did not incorporate the recommendation to limit CMMC inclusion in existing contracts, as contracting officers already have discretion to bilaterally modify existing contracts.&lt;br /&gt;
&lt;br /&gt;
==== 5. COTS Item Exclusion ====&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Comment:&#039;&#039;&#039; Respondents requested clarification on the scope of the COTS exclusion.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Response:&#039;&#039;&#039; The rule does not apply to awards that are exclusively for COTS items, as defined at FAR 2.101. Any award exclusively for items meeting the FAR definition is considered an &amp;quot;exclusively COTS&amp;quot; award.&lt;br /&gt;
&lt;br /&gt;
==== 6. Extending the Certification Time for New Bidders ====&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Comment:&#039;&#039;&#039; A respondent requested an extension of certification time for new bidders.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Response:&#039;&#039;&#039; Per 32 CFR part 170, contractors must have a CMMC self-assessment or certification at time of award; there is no delayed implementation for new bidders, though 32 CFR 170.21 allows a POA&amp;amp;M in certain instances.&lt;br /&gt;
&lt;br /&gt;
==== 7. Flowdown Requirements When Subcontractors Use Prime Contractor Information System ====&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Comment:&#039;&#039;&#039; Respondents asked about flowdown when subcontractors use the prime&#039;s information system rather than their own.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Response:&#039;&#039;&#039; A subcontractor that does not process, store, or transmit FCI or CUI on its own systems has no CMMC assessment requirement. DoD does not have an automated tool giving primes visibility into subcontractor certification status in SPRS, but subcontractors may voluntarily share scores/certificates.&lt;br /&gt;
&lt;br /&gt;
==== 8. Definitions ====&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;a. CUI&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Comment:&#039;&#039;&#039; Respondents asked to define CUI and streamline it with &amp;quot;covered defense information.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Response:&#039;&#039;&#039; The definition of CUI incorporates the definition codified at 32 CFR part 170; modifying it further is outside the scope of this rule.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;b. FCI&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Comment:&#039;&#039;&#039; A respondent requested clarification of &amp;quot;not intended for public release&amp;quot; and &amp;quot;simple transactional information,&amp;quot; and whether FOIA-subject information is still FCI.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Response:&#039;&#039;&#039; A definition of FCI was added, based on FAR 52.204–21, with &amp;quot;information necessary to process payments&amp;quot; as an example of simple transactional information. Marking/FOIA comments are outside scope.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;c. Current&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Comment:&#039;&#039;&#039; Clarify whether &amp;quot;current&amp;quot; refers to date of assessment or date of certification.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Response:&#039;&#039;&#039; The final rule changes the definition of &amp;quot;current&amp;quot; to address this; the underlying requirements were established in 32 CFR part 170, and DoD cannot make changes beyond that in this DFARS rule.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;d. Data&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Comment:&#039;&#039;&#039; Respondents asked that &amp;quot;data&amp;quot; be replaced with &amp;quot;FCI and/or CUI&amp;quot; to narrow scope.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Response:&#039;&#039;&#039; Based on public comments, the rule was revised to remove the term &amp;quot;data.&amp;quot; The rule applies to information that is FCI and CUI only.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;e. Contractor Information Systems&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Comment:&#039;&#039;&#039; Respondents asked that &amp;quot;contractor information systems&amp;quot; be limited/defined more narrowly, similar to &amp;quot;covered contractor information systems.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Response:&#039;&#039;&#039; The rule clarifies that &amp;quot;contractor information systems&amp;quot; throughout the rule means systems &amp;quot;that process, store, or transmit FCI or CUI in performance of the contract.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
==== 9. Regulatory Impact Analysis (RIA) Estimate ====&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Comment:&#039;&#039;&#039; Several respondents said the RIA cost estimate was too low and should include all offerors and a revised estimate of average information systems per contractor.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Response:&#039;&#039;&#039; The RIA only covers costs of contractual requirements to upload self-assessments and complete affirmations in SPRS (technical/programmatic CMMC costs are addressed under 32 CFR part 170). The RIA was revised to expand the estimated impacted entities to include, in year four and beyond, all entities in the Federal Procurement Data System awarded DoD contracts FY2022–FY2024. The estimate of five information systems per contractor remains a DoD subject-matter-expert estimate.&lt;br /&gt;
&lt;br /&gt;
==== 10. Application to Fundamental Research ====&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Comment:&#039;&#039;&#039; Respondents raised concerns about applying CMMC to fundamental research that could become CUI.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Response:&#039;&#039;&#039; Fundamental research (per NSDD 189) is published and broadly shared and cannot be safeguarded as FCI or CUI; however, if it has the potential to become CUI, it would be subject to CMMC once it becomes CUI.&lt;br /&gt;
&lt;br /&gt;
==== 11. Applicability ====&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Comment:&#039;&#039;&#039; Respondents raised numerous applicability questions: FCI-only Level 1 self-assessment carve-outs, program manager documentation of rationale, existing vs. new contracts, micro-purchase threshold subcontracts, and scope of paragraph (b)(3).&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Response:&#039;&#039;&#039; The clause will be included in solicitations issued on/after the effective date and in resulting contracts; contracting officers may also bilaterally incorporate the clause into existing contracts (see FAR 1.108(d)). Until three years after the effective date, CMMC applies only where program managers/requiring activities determine to apply it (excluding COTS-only awards); afterward, it applies wherever contractor information systems will process, store, or transmit FCI or CUI. 32 CFR part 170 does not allow spot checks and requires the CMMC requirement be met at time of award.&lt;br /&gt;
&lt;br /&gt;
==== 12. Flowdown ====&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Comment:&#039;&#039;&#039; Respondents requested clarification on flowdown scope, CUI dissemination limits, and lower-tier CMMC level determination.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Response:&#039;&#039;&#039; See 32 CFR 170.23 for flowdown guidance. Clause paragraph (d)(1) was revised to clarify flowdown applies only where the subcontract requires a CMMC level, and to no longer exclude paragraph (b)(3) (affirmation of continuous compliance) from subcontractor flowdown. The rule was &#039;&#039;&#039;not&#039;&#039;&#039; revised regarding which subcontractors must receive CUI — that determination remains with the prime contractor.&lt;br /&gt;
&lt;br /&gt;
==== 13. CMMC as an Evaluation Factor ====&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Comment:&#039;&#039;&#039; Is CMMC a competition evaluation factor or set-aside requirement?&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Response:&#039;&#039;&#039; No. CMMC is not an evaluation factor or set-aside requirement; DFARS 204.7503 requires contracting officers not to award to an offeror that fails to meet the CMMC requirements in the solicitation, and if included in the solicitation, it becomes a contract requirement.&lt;br /&gt;
&lt;br /&gt;
==== 14. Program Office Requirements ====&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Comment:&#039;&#039;&#039; Require the program office to review contractor-provided information.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Response:&#039;&#039;&#039; The rule was revised to require the contracting officer to work with the program office/requiring activity to review the offeror&#039;s CMMC status and affirmation information.&lt;br /&gt;
&lt;br /&gt;
==== 15. Clarifying When FCI Applies ====&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Comment:&#039;&#039;&#039; Clarify that systems processing FCI (not CUI) need only CMMC Level 1.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Response:&#039;&#039;&#039; Not included in the final rule; contracting officers do not determine the required CMMC level.&lt;br /&gt;
&lt;br /&gt;
==== 16. International Applicability ====&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Comment:&#039;&#039;&#039; Respondents raised questions about C3PAO assessments outside the U.S., international harmonization, and foreign verification bodies (e.g., Taiwan&#039;s TAF).&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Response:&#039;&#039;&#039; Contracts subject to NIST SP 800–171 compliance (e.g., via DFARS 252.204–7012) require foreign or domestic contractors to secure their systems. See 32 CFR 179 regarding foreign C3PAO accreditation; DoD permits an equivalent process for personnel ineligible for a Tier 3 background investigation, for CMMC Program purposes only.&lt;br /&gt;
&lt;br /&gt;
==== 17. POA&amp;amp;M ====&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Comment:&#039;&#039;&#039; Respondents sought clarity on POA&amp;amp;M closeout, conditional certification for subcontract award, and continued reliance on POA&amp;amp;Ms for newly discovered risks.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Response:&#039;&#039;&#039; The rule was revised to clarify (via the &amp;quot;current&amp;quot; definition) that for CMMC Levels 2 and 3 only, conditional CMMC status is permitted for up to 180 days from the conditional CMMC status date, and that final CMMC status is achieved upon successful POA&amp;amp;M closeout. 32 CFR part 170 does not allow additional POA&amp;amp;Ms beyond established scoping, other than for scenarios appropriate for an &amp;quot;operational plan of action&amp;quot; (32 CFR 170.4).&lt;br /&gt;
&lt;br /&gt;
==== 18. Subcontractor Compliance ====&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Comment:&#039;&#039;&#039; Respondents asked how primes monitor/verify subcontractor CMMC adherence, requested an automated SPRS visibility tool, and asked when subcontractors must be compliant.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Response:&#039;&#039;&#039; Contractors can only access their own CMMC information in SPRS; DoD has no tool for automatic sharing with primes. Subcontractors may screenshot/print their own SPRS status to share voluntarily. Prior to awarding a subcontract, the prime must ensure the subcontractor has a current CMMC status at the appropriate level. 32 CFR part 170 does not allow limiting enforcement to direct suppliers only.&lt;br /&gt;
&lt;br /&gt;
==== 19. Senior Company Official ====&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Comment:&#039;&#039;&#039; Respondents noted the proposed rule&#039;s &amp;quot;senior company official&amp;quot; term does not match 32 CFR part 170&#039;s &amp;quot;affirming official,&amp;quot; and asked for a clear definition.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Response:&#039;&#039;&#039; The final rule updates terminology to &amp;quot;affirming official&amp;quot; to align with 32 CFR part 170 (the proposed DFARS rule used the older term due to timing of the two rulemakings).&lt;br /&gt;
&lt;br /&gt;
==== 20. Task Orders and Delivery Orders ====&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Comment:&#039;&#039;&#039; Will existing IDIQ contracts&#039; task/delivery orders issued after the rule contain a CMMC requirement?&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Response:&#039;&#039;&#039; Task orders or delivery orders issued after the rule&#039;s effective date may include a CMMC requirement under the prescribed clause/provision.&lt;br /&gt;
&lt;br /&gt;
==== 21. Relationship Between &amp;quot;Covered Contractor Information Systems&amp;quot; and &amp;quot;Contractor Information Systems&amp;quot; ====&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Comment:&#039;&#039;&#039; Clarify the relationship between the two terms and possible over-broad scope.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Response:&#039;&#039;&#039; The rule clarifies that &amp;quot;contractor information systems&amp;quot; are limited to those &amp;quot;that process, store, or transmit FCI or CUI during performance of the contract.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
==== 22. CMMC Unique Identifiers ====&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Comment:&#039;&#039;&#039; Respondents sought clarification on CMMC UIDs vs. CAGE codes, mandatory vs. optional UID submission, and prime vs. subcontractor UID reporting obligations.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Response:&#039;&#039;&#039; A CMMC UID is assigned per CMMC Assessment Scope as defined by the Organization Seeking Assessment (OSA) (see 32 CFR 170.19). SPRS/eMASS assigns the UID upon submission of assessment results. OSAs must obtain a CAGE code (via sam.gov) or NCAGE code (for non-U.S. businesses, via NSPA) and a PIEE account. Only prime contractors with a CMMC requirement must submit CMMC UIDs to the contracting officer (which may include subcontractors&#039; UIDs); subcontractors themselves do not submit UIDs to the contracting officer. A new UID is generated whenever a new SPRS score is entered (e.g., at reassessment or 3-year renewal).&lt;br /&gt;
&lt;br /&gt;
==== 23. Creation of Exception ====&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Comment:&#039;&#039;&#039; Requests for exceptional-circumstance relief and small-business exemptions for second-tier suppliers.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Response:&#039;&#039;&#039; 32 CFR part 170 does not include an exemption for exceptional circumstances, and this DFARS rule cannot create one. DoD does not require flowdown to subcontractors that do not receive FCI or CUI.&lt;br /&gt;
&lt;br /&gt;
==== 24. Period of Performance ====&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Comment:&#039;&#039;&#039; Should contracting officers validate CMMC compliance before extending a period of performance?&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Response:&#039;&#039;&#039; Yes — 32 CFR part 170 requires CMMC statuses to be maintained for the life of the contract, so contracting officers must validate compliance before extending performance periods or exercising options.&lt;br /&gt;
&lt;br /&gt;
==== 25. Prime Contractor Protection From Subcontractor Noncompliance ====&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Comment:&#039;&#039;&#039; Clarify that primes won&#039;t be rendered ineligible due to subcontractor noncompliance.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Response:&#039;&#039;&#039; The Government does not establish the prime/subcontractor relationship and does not indemnify the prime from its subcontractors, as it lacks privity of contract with subcontractors.&lt;br /&gt;
&lt;br /&gt;
==== 26. Application of CMMC to FAR Part 16 Contract Types ====&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Comment:&#039;&#039;&#039; Require CMMC Program Office/USD(A&amp;amp;S) approval before applying CMMC to FAR part 16 contract types during phase-in.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Response:&#039;&#039;&#039; 32 CFR part 170 does not include such an approval process, and this rule cannot create one.&lt;br /&gt;
&lt;br /&gt;
==== 27. Acquiring Entities Without CMMC Certification ====&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Comment:&#039;&#039;&#039; How are newly acquired entities or new sites added to an existing certification?&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Response:&#039;&#039;&#039; Per DFARS 252.204–7021(c)(1), contractors must report changes to UIDs to the contracting officer. Adding new users to an existing system does not necessarily change the CMMC assessment scope (see 32 CFR 170.19).&lt;br /&gt;
&lt;br /&gt;
==== 28. Applicability to Civilian Agencies ====&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Comment:&#039;&#039;&#039; Does CMMC apply to CUI from non-DoD agencies?&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Response:&#039;&#039;&#039; This rule amends the DFARS and applies only to DoD or DoD-funded acquisitions.&lt;br /&gt;
&lt;br /&gt;
==== 29. Provision and Clause Clarifications ====&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Comment:&#039;&#039;&#039; Questions on subcontractor UID updates and the &amp;quot;unless electronically posted&amp;quot; language.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Response:&#039;&#039;&#039; The clause was updated to require subcontractors to enter self-assessment results in SPRS and complete annual affirmations, which they may share via screenshot. &amp;quot;Unless electronically posted&amp;quot; language was removed. Paragraph (c)(1) is excluded from subcontractor flowdown because the Government lacks privity of contract with subcontractors, though primes are encouraged to flow down similar language voluntarily.&lt;br /&gt;
&lt;br /&gt;
==== 30. Outside the Scope of the Rule ====&lt;br /&gt;
&lt;br /&gt;
DoD received numerous comments outside the scope of this rule, including topics related to: the DFARS Case 2022–D017 timeline; CUI marking and definitions; the CMMC Program&#039;s underlying policy at 32 CFR part 170 (permissible changes, exemptions for MWR/NAF procurements, ISO/IEC 27001 relationship, phase-in timeline, spot checks, FedRAMP, waivers, eMASS training, and more); cost impacts; and various sector-specific applicability questions (medical devices, furniture manufacturers, common carriers, etc.).&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Response (selected points):&#039;&#039;&#039;&lt;br /&gt;
* CMMC level selection is made by the program office/requiring activity per DoD policy and 32 CFR 170.5; contracting officers do not determine the level.&lt;br /&gt;
* All CUI categories require at least a self-assessment; DoD Organizational Index group CUI categories generally require a C3PAO assessment at minimum.&lt;br /&gt;
* MWR/NAF procurements requiring NIST SP 800–171 implementation are subject to the CMMC requirement.&lt;br /&gt;
* Waivers are established at 32 CFR 170.5 and are at the discretion of the program office/requiring activity, prior to contracting officer involvement.&lt;br /&gt;
* Contractors do not have access to CMMC eMASS (used only for certification assessments); all CMMC assessments are reflected in SPRS.&lt;br /&gt;
* Enclave scoping is determined by the contractor per 32 CFR 170.19.&lt;br /&gt;
* Reassessments are expected to be infrequent and DoD-conducted, per updates to 32 CFR part 170.&lt;br /&gt;
* Flowdown requirements are at 32 CFR 170.23.&lt;br /&gt;
&lt;br /&gt;
=== C. Other Changes ===&lt;br /&gt;
&lt;br /&gt;
* DFARS 204.7500 was updated to remove a web address and replace it with a reference to 32 CFR part 170.&lt;br /&gt;
* Clarified throughout that a higher CMMC level than required is also permissible.&lt;br /&gt;
* The term &amp;quot;CMMC status&amp;quot; was added throughout, clarifying that contracts may be awarded with a current Final Level 1 (Self), Conditional Level 2 (Self), Final Level 2 (Self), Conditional Level 2 (C3PAO), or Final Level 2 (C3PAO) CMMC status. A definition of &amp;quot;CMMC status&amp;quot; was added to DFARS subpart 204.75, clause 252.204–7021, and provision 252.204–7025.&lt;br /&gt;
&lt;br /&gt;
== III. Applicability to Contracts at or Below the SAT, Commercial Products, and Commercial Services ==&lt;br /&gt;
&lt;br /&gt;
The clause at DFARS 252.204–7021 is prescribed at DFARS 204.7504 for use:&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;Until November 9, 2028&#039;&#039;&#039; (three years after the effective date): in solicitations and contracts, task orders, or delivery orders — including FAR part 12 commercial product/service acquisitions, except those solely for COTS items — if the program office or requiring activity determines the contractor is required to have a specific CMMC level (unless 32 CFR 170.5(d) requirements are met).&lt;br /&gt;
* &#039;&#039;&#039;On or after November 10, 2028&#039;&#039;&#039;: in solicitations and contracts, task orders, or delivery orders — including FAR part 12 acquisitions, except those solely for COTS items — if the program office or requiring activity determines the contractor must use contractor information systems to process, store, or transmit FCI or CUI.&lt;br /&gt;
&lt;br /&gt;
The provision at DFARS 252.204–7025 is prescribed at DFARS 204.7504(b) for use in solicitations that include the clause at DFARS 252.204–7021.&lt;br /&gt;
&lt;br /&gt;
Consistent with DoD&#039;s analysis of section 1648 of the NDAA for FY 2020, DoD applies the statute (as implemented in these clause/provision) to contracts at or below the Simplified Acquisition Threshold (SAT), to commercial products (excluding COTS items), and to commercial services as defined at FAR 2.101.&lt;br /&gt;
&lt;br /&gt;
== IV. Expected Impact of the Rule ==&lt;br /&gt;
&lt;br /&gt;
=== A. Background ===&lt;br /&gt;
&lt;br /&gt;
DoD is amending the DFARS to implement contractual requirements tied to the CMMC policy (32 CFR part 170, 89 FR 83092, October 15, 2024). New solicitation/contractual requirements include:&lt;br /&gt;
&lt;br /&gt;
* Offeror/contractor requirement to post CMMC Level 1 or Level 2 self-assessment results to SPRS prior to award, option exercise, or period-of-performance extension, if not already posted.&lt;br /&gt;
* Contractor requirement to maintain the required CMMC status for the life of the contract.&lt;br /&gt;
* Contractor requirement for an affirming official to complete an annual affirmation of continuous compliance in SPRS for each applicable CMMC UID.&lt;br /&gt;
* Offeror/contractor requirement to identify contractor information systems used to process, store, or transmit FCI or CUI, by providing CMMC UIDs generated by SPRS.&lt;br /&gt;
&lt;br /&gt;
=== B. Summary of Impact ===&lt;br /&gt;
&lt;br /&gt;
The rule will be implemented over a phased, three-year period, after which it applies to all contracts where the contractor processes, stores, or transmits FCI or CUI on contractor information systems (except COTS-only contracts).&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Estimated impacted entities (Year 4 and beyond):&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Metric !! Value&lt;br /&gt;
|-&lt;br /&gt;
| Average unique entities awarded DoD contracts above micro-purchase threshold (FY2022–FY2024) || 32,756&lt;br /&gt;
|-&lt;br /&gt;
| Unique entities awarded using only commercial procedures || 18,370&lt;br /&gt;
|-&lt;br /&gt;
| Estimated COTS-only awardees (25% of 18,370) || 4,592&lt;br /&gt;
|-&lt;br /&gt;
| Unique entities after removing COTS-only awardees || 28,164&lt;br /&gt;
|-&lt;br /&gt;
| Assumed offerors per solicitation || 2&lt;br /&gt;
|-&lt;br /&gt;
| Total prime offerors (28,164 × 2) || 56,328&lt;br /&gt;
|-&lt;br /&gt;
| Assumed subcontractors per prime offer || 5&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;Total estimated impacted entities&#039;&#039;&#039; (primes + subcontractors) || &#039;&#039;&#039;337,968&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| Of which, small entities (68%) || 229,818&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Estimated time burden per contractor information system:&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
* Offerors/contractors: ~5 minutes to post CMMC self-assessment results in SPRS; ~5 minutes to complete the required affirmation; ~5 minutes to retrieve and submit CMMC UIDs.&lt;br /&gt;
* Government: ~5 minutes to validate CMMC level/currency prior to award, option exercise, or performance extension; ~5 minutes to validate affirmation currency; ~5 minutes to validate CMMC status/affirmation when UIDs change during performance.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Benefits:&#039;&#039;&#039; Verification of DIB contractors&#039; implementation of system security requirements, protection of CUI/FCI and intellectual property, and reduced exposure to malicious cyber activity. The Council of Economic Advisers estimated malicious cyber activity cost the U.S. economy $57–109 billion in 2016 (a 10-year burden of an estimated $400–765 billion at a 7% discount rate, or $486–929 billion at a 3% discount rate). GAO cited Treasury reporting that ransomware-related incidents reached $886 million in 2021.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Estimated public and Government costs over a 10-year period:&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Summary (3% discount rate) !! Public !! Government !! Total&lt;br /&gt;
|-&lt;br /&gt;
| Present Value || $329,097,922 || $15,812,069 || $344,909,991&lt;br /&gt;
|-&lt;br /&gt;
| Annualized Costs || $38,580,316 || $1,760,303 || $40,340,619&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Summary (7% discount rate) !! Public !! Government !! Total&lt;br /&gt;
|-&lt;br /&gt;
| Present Value || $254,756,766 || $11,533,649 || $266,290,415&lt;br /&gt;
|-&lt;br /&gt;
| Annualized Costs || $36,271,632 || $1,642,132 || $37,913,764&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== V. Executive Orders 12866 and 13563 ==&lt;br /&gt;
&lt;br /&gt;
This is a significant regulatory action, subject to review under section 6(b) of E.O. 12866, Regulatory Planning and Review, as amended.&lt;br /&gt;
&lt;br /&gt;
== VI. Executive Order 14192 ==&lt;br /&gt;
&lt;br /&gt;
This rule is &#039;&#039;&#039;not&#039;&#039;&#039; subject to E.O. 14192, because it is issued with respect to a national security function of the United States. Implementation of CMMC Program requirements is urgently needed to strengthen protection of DoD information, protect critical defense technologies from exfiltration, and protect the DIB&#039;s intellectual property and the broader U.S. economy from malicious cyber actors.&lt;br /&gt;
&lt;br /&gt;
== VII. Congressional Review Act ==&lt;br /&gt;
&lt;br /&gt;
DoD will submit the rule to the U.S. Senate, House of Representatives, and Comptroller General as required by the Congressional Review Act (5 U.S.C. 801–808). The Office of Information and Regulatory Affairs has determined this rule is &#039;&#039;&#039;not&#039;&#039;&#039; a major rule as defined by 5 U.S.C. 804(2).&lt;br /&gt;
&lt;br /&gt;
== VIII. Regulatory Flexibility Act ==&lt;br /&gt;
&lt;br /&gt;
A final regulatory flexibility analysis was prepared under 5 U.S.C. 601 &#039;&#039;et seq.&#039;&#039; Key points:&lt;br /&gt;
&lt;br /&gt;
* This rule responds to threats posed by malicious cyber activity targeting U.S. intellectual property and DoD CUI.&lt;br /&gt;
* Requirements apply to all offerors/contractors under a CMMC-requirement solicitation/contract: (1) post current CMMC status in SPRS; (2) maintain CMMC status for contract life; (3) provide CMMC UIDs to the contracting officer, with updates; (4) maintain a current affirmation of continuous compliance.&lt;br /&gt;
* These requirements do &#039;&#039;&#039;not&#039;&#039;&#039; apply to awards not involving FCI or CUI.&lt;br /&gt;
* No public comments were submitted in response to the initial regulatory flexibility analysis.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Estimated small entities impacted, phased rollout:&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Year !! Estimated Small Entities&lt;br /&gt;
|-&lt;br /&gt;
| Year 1 || 1,104&lt;br /&gt;
|-&lt;br /&gt;
| Year 2 || 5,565&lt;br /&gt;
|-&lt;br /&gt;
| Year 3 || 18,554&lt;br /&gt;
|-&lt;br /&gt;
| Year 4+ || 229,818&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Anticipated mix of CMMC statuses starting Year 4:&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! CMMC Level !! Percentage !! Small Entities !! Large Entities !! Total Entities&lt;br /&gt;
|-&lt;br /&gt;
| Level 1 Self-assessment || 62% || 142,487 || 67,053 || 209,540&lt;br /&gt;
|-&lt;br /&gt;
| Level 2 Self-assessment || 2% || 4,596 || 2,163 || 6,759&lt;br /&gt;
|-&lt;br /&gt;
| Level 2 Certificate || 35% || 80,436 || 37,853 || 118,289&lt;br /&gt;
|-&lt;br /&gt;
| Level 3 Certificate || 1% || 2,298 || 1,082 || 3,380&lt;br /&gt;
|-&lt;br /&gt;
| &#039;&#039;&#039;Total&#039;&#039;&#039; || &#039;&#039;&#039;100%&#039;&#039;&#039; || &#039;&#039;&#039;229,818&#039;&#039;&#039; || &#039;&#039;&#039;108,150&#039;&#039;&#039; || &#039;&#039;&#039;337,968&#039;&#039;&#039;&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;New reporting/recordkeeping requirements for small entities:&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
# Post current CMMC status (not covered by C3PAO/DIBCAC assessment) to SPRS for each applicable CMMC UID.&lt;br /&gt;
# Provide CMMC UIDs prior to award and upon any changes.&lt;br /&gt;
# Affirming official completes and maintains, annually (or upon compliance status change), the affirmation of continuous compliance in SPRS.&lt;br /&gt;
&lt;br /&gt;
DoD identified no alternatives that would accomplish the statutory objectives while further reducing small-entity burden; the phased rollout and COTS exemption are intended to minimize economic impact.&lt;br /&gt;
&lt;br /&gt;
== IX. Paperwork Reduction Act ==&lt;br /&gt;
&lt;br /&gt;
This final rule&#039;s information collection requirements have been approved by OMB under the Paperwork Reduction Act (44 U.S.C. chapter 35), OMB Control Number &#039;&#039;&#039;0750–0008&#039;&#039;&#039;, DFARS Part 204, Contractor Implementation of Cybersecurity Requirements.&lt;br /&gt;
&lt;br /&gt;
== List of Subjects in 48 CFR Parts 204, 212, 217, and 252 ==&lt;br /&gt;
&lt;br /&gt;
Government procurement.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Signed:&#039;&#039; Kimberly R. Ziegler, Editor/Publisher, Defense Acquisition Regulations System.&lt;br /&gt;
&lt;br /&gt;
The interim rule amending 48 CFR parts 204, 212, 217, and 252 (published at 85 FR 61505 on September 29, 2020) is adopted as final with the following changes.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Authority citation for parts 204, 212, 217, and 252:&#039;&#039;&#039; 41 U.S.C. 1303 and 48 CFR chapter 1.&lt;br /&gt;
&lt;br /&gt;
== PART 204—Administrative and Information Matters ==&lt;br /&gt;
&lt;br /&gt;
=== Subpart 204.75—Cybersecurity Maturity Model Certification ===&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Contents:&#039;&#039;&#039;&lt;br /&gt;
* 204.7500 Scope of subpart.&lt;br /&gt;
* 204.7501 Definitions.&lt;br /&gt;
* 204.7502 Policy.&lt;br /&gt;
* 204.7503 Procedures.&lt;br /&gt;
* 204.7504 Solicitation provision and contract clause.&lt;br /&gt;
&lt;br /&gt;
==== 204.7500 Scope of subpart ====&lt;br /&gt;
&lt;br /&gt;
(a) This subpart prescribes policies and procedures for including the Cybersecurity Maturity Model Certification (CMMC) level requirements in DoD contracts. CMMC is a framework (see 32 CFR part 170) for assessing a contractor&#039;s information security protections.&lt;br /&gt;
&lt;br /&gt;
(b) This subpart does not abrogate any other requirements regarding contractor physical, personnel, information, technical, or general administrative security operations governing the protection of unclassified information, nor does it affect requirements of the National Industrial Security Program.&lt;br /&gt;
&lt;br /&gt;
(c) This subpart applies to unclassified contractor information systems.&lt;br /&gt;
&lt;br /&gt;
==== 204.7501 Definitions ====&lt;br /&gt;
&lt;br /&gt;
As used in this subpart—&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Controlled unclassified information&#039;&#039;&#039; means information the Government creates or possesses, or information an entity creates or possesses for or on behalf of the Government, that a law, regulation, or Governmentwide policy requires or permits an agency to handle using safeguarding or dissemination controls (32 CFR 2002.4(h)).&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Current&#039;&#039;&#039; means—&lt;br /&gt;
&lt;br /&gt;
(1) With regard to Conditional Cybersecurity Maturity Model Certification (CMMC) Status—&lt;br /&gt;
&lt;br /&gt;
:(i) Not older than 180 days for Conditional Level 2 (Self) assessments and Conditional Level 2 (certified third-party assessment organization (C3PAO)) assessments, with—&lt;br /&gt;
::(A) No changes in compliance with the requirements at 32 CFR part 170 since the Conditional CMMC Status date (see 32 CFR 170.16 and 170.17); and&lt;br /&gt;
::(B) A corresponding affirmation of continuous compliance by an affirming official (see 32 CFR 170.4); and&lt;br /&gt;
&lt;br /&gt;
:(ii) Not older than 180 days for Conditional Level 3 (Defense Industrial Base Cybersecurity Assessment Center (DIBCAC)) assessments, with—&lt;br /&gt;
::(A) No changes in compliance with the requirements at 32 CFR part 170 since the Conditional CMMC Status date (see 32 CFR 170.18); and&lt;br /&gt;
::(B) A corresponding affirmation of continuous compliance by an affirming official;&lt;br /&gt;
&lt;br /&gt;
(2) With regard to Final CMMC Status—&lt;br /&gt;
&lt;br /&gt;
:(i) Not older than 1 year for Final Level 1 (Self), with—&lt;br /&gt;
::(A) No changes in compliance with the requirements at 32 CFR part 170 since the Final CMMC Status date (see 32 CFR 170.15); and&lt;br /&gt;
::(B) A corresponding affirmation of continuous compliance, not older than 1 year, by an affirming official;&lt;br /&gt;
&lt;br /&gt;
:(ii) Not older than 3 years for Final Level 2 (Self) assessments and Final Level 2 (C3PAO) assessments, with—&lt;br /&gt;
::(A) No changes in compliance with the requirements at 32 CFR part 170 since the Final CMMC Status date (see 32 CFR 170.16 and 170.17); and&lt;br /&gt;
::(B) A corresponding affirmation of continuous compliance, not older than 1 year, by an affirming official; and&lt;br /&gt;
&lt;br /&gt;
:(iii) Not older than 3 years for Final Level 3 (DIBCAC) assessments, with—&lt;br /&gt;
::(A) No changes in compliance with the requirements at 32 CFR part 170 since the Final CMMC Status date (see 32 CFR 170.18); and&lt;br /&gt;
::(B) A corresponding affirmation of continuous compliance, not older than 1 year, by an affirming official; and&lt;br /&gt;
&lt;br /&gt;
(3) With regard to affirmation of continuous compliance (32 CFR 170.22), not older than 1 year with no changes in compliance with the requirements at 32 CFR part 170.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Cybersecurity Maturity Model Certification (CMMC) status&#039;&#039;&#039; means the result of meeting or exceeding the minimum required score for the corresponding assessment. The potential statuses are as follows:&lt;br /&gt;
&lt;br /&gt;
# Final Level 1 (Self).&lt;br /&gt;
# Conditional Level 2 (Self).&lt;br /&gt;
# Final Level 2 (Self).&lt;br /&gt;
# Conditional Level 2 (C3PAO).&lt;br /&gt;
# Final Level 2 (C3PAO).&lt;br /&gt;
# Conditional Level 3 (DIBCAC).&lt;br /&gt;
# Final Level 3 (DIBCAC).&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Cybersecurity Maturity Model Certification unique identifier (CMMC UID)&#039;&#039;&#039; means 10 alpha-numeric characters assigned to each CMMC assessment and reflected in the Supplier Performance Risk System (SPRS) for each contractor information system.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Federal contract information (FCI)&#039;&#039;&#039; means information, not intended for public release, that is provided by or generated for the Government under a contract to develop or deliver a product or service to the Government. It does not include information provided by the Government to the public, such as on public websites, or simple transactional information, such as information necessary to process payments.&lt;br /&gt;
&lt;br /&gt;
==== 204.7502 Policy ====&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;(a) Award eligibility.&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
(1) The contracting officer shall include in the solicitation the required CMMC level, if provided by the program office or the requiring activity.&lt;br /&gt;
&lt;br /&gt;
(2) Contracting officers shall not award a contract, task order, or delivery order to an offeror that does not have a current CMMC status at the CMMC level required by the solicitation.&lt;br /&gt;
&lt;br /&gt;
(3) Contractors are required to achieve, at time of award, a CMMC status at the CMMC level specified in the solicitation, or higher, for all information systems used in the performance of the contract, task order, or delivery order that will process, store, or transmit FCI or CUI. Contractors are required to maintain a current CMMC status at the specified CMMC level or higher, if required by the contract, task order, or delivery order, throughout the life of the contract, task order, or delivery order.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;(b) CMMC status.&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
(1) Contracting officers may award a contract, task order, delivery order, or modification to exercise an option or extend a period of performance, if the offeror&#039;s or contractor&#039;s CMMC status is—&lt;br /&gt;
&lt;br /&gt;
:(i) Listed in the definition of &amp;quot;CMMC status&amp;quot;; and&lt;br /&gt;
:(ii) Equal to or higher than the CMMC level required by the solicitation or contract, task order, or delivery order.&lt;br /&gt;
&lt;br /&gt;
(2) CMMC levels 2 and 3 can be in a conditional level for a period not to exceed 180 days from the CMMC status date (32 CFR 170.21), and award can occur with a conditional CMMC level. CMMC level 1 requires a final CMMC level for award.&lt;br /&gt;
&lt;br /&gt;
==== 204.7503 Procedures ====&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;(a) CMMC level.&#039;&#039;&#039; The contracting officer shall include the CMMC level (see 32 CFR 170.19) required by the program office or requiring activity in the solicitation provision and contract clause prescribed at 204.7504.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;(b) Award.&#039;&#039;&#039; Contracting officers shall check SPRS and not award a contract, task order, or delivery order to an offeror that does not have a current CMMC status posted in SPRS at the CMMC level (see 32 CFR 170.15 through 170.18) required by the solicitation, or higher, for each CMMC UID provided by the offeror. The CMMC UIDs are applicable to each of the contractor information systems that will process, store, or transmit FCI or CUI and that will be used in performance of the contract.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;(c) Option exercise or period of performance extension.&#039;&#039;&#039; Contracting officers shall check SPRS and not exercise an option or extend the period of performance on a contract, task order, or delivery order, unless the contractor has a current CMMC status posted in SPRS at the CMMC level (see 32 CFR 170.15 through 170.18) required by the contract, task order, or delivery order, or higher, for each CMMC UID provided by the contractor. The contractor&#039;s CMMC UIDs are applicable to each of the contractor information systems that process, store, or transmit FCI or CUI and that are or will be used in performance of the contract.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;(d) CMMC UIDs.&#039;&#039;&#039; If the contractor provides new CMMC UIDs during performance of the contract, task order, or delivery order, the contracting officer shall check in SPRS, using the CMMC UIDs assigned by SPRS, that the contractor has a current CMMC status at the required CMMC level, or higher, for each of the contractor information systems identified that will process, store, or transmit FCI or CUI during contract performance.&lt;br /&gt;
&lt;br /&gt;
==== 204.7504 Solicitation provision and contract clause ====&lt;br /&gt;
&lt;br /&gt;
(a) Unless the requirements at 32 CFR 170.5(d) are met, use the clause at 252.204–7021, &#039;&#039;Contractor Compliance with the Cybersecurity Maturity Model Certification Level Requirements&#039;&#039;, as follows:&lt;br /&gt;
&lt;br /&gt;
(1) &#039;&#039;&#039;Until November 9, 2028&#039;&#039;&#039;, in solicitations and contracts, task orders, or delivery orders, including those using FAR part 12 procedures for the acquisition of commercial products and commercial services, except for those solely for the acquisition of commercially available off-the-shelf (COTS) items, if the program office or requiring activity determines that the contractor is required to have a specific CMMC level.&lt;br /&gt;
&lt;br /&gt;
(2) &#039;&#039;&#039;On or after November 10, 2028&#039;&#039;&#039;, in solicitations and contracts, task orders, or delivery orders, including those using FAR part 12 procedures for the acquisition of commercial products and commercial services, except for those solely for the acquisition of COTS items, if the program office or requiring activity determines that the contractor is required to use contractor information systems in the performance of the contract, task order, or delivery order to process, store, or transmit FCI or CUI.&lt;br /&gt;
&lt;br /&gt;
(b) Use the provision at 252.204–7025, &#039;&#039;Notice of Cybersecurity Maturity Model Certification Level Requirements&#039;&#039;, in solicitations that include the clause at 252.204–7021.&lt;br /&gt;
&lt;br /&gt;
== PART 212—Acquisition of Commercial Products and Commercial Services ==&lt;br /&gt;
&lt;br /&gt;
=== 212.301 Solicitation provisions and contract clauses for the acquisition of commercial products and commercial services ===&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Amendment:&#039;&#039;&#039;&lt;br /&gt;
* In paragraph (f)(ii)(L), remove &amp;quot;204.7503 (a) and (b)&amp;quot; and add &amp;quot;204.7504(a)&amp;quot; in its place.&lt;br /&gt;
* Add paragraph (f)(ii)(P):&lt;br /&gt;
&lt;br /&gt;
:(P) Use the provision at 252.204–7025, Notice of Cybersecurity Maturity Model Certification Level Requirements, as prescribed in 204.7504(b).&lt;br /&gt;
&lt;br /&gt;
== PART 217—Special Contracting Methods ==&lt;br /&gt;
&lt;br /&gt;
=== 217.207 Exercise of options ===&lt;br /&gt;
&lt;br /&gt;
(c) In addition to the requirements at FAR 17.207(c), exercise an option only after—&lt;br /&gt;
&lt;br /&gt;
(1) Determining that the contractor&#039;s record in the System for Award Management database is active and the contractor&#039;s unique entity identifier number, Commercial and Government Entity (CAGE) code, name, and physical address are accurately reflected in the contract document. (See PGI 217.207 for the requirement to perform cost or price analysis of spare parts prior to exercising any option for firm-fixed-price contracts containing spare parts.); and&lt;br /&gt;
&lt;br /&gt;
(2) Working with the program office or requiring activity to verify in the Supplier Performance Risk System (https://piee.eb.mil) that—&lt;br /&gt;
&lt;br /&gt;
:(i) The summary level score of a current NIST SP 800–171 DoD Assessment (i.e., not more than 3 years old, unless a lesser time is specified in the solicitation) for each covered contractor information system that is relevant to an offer, contract, task order, or delivery order are posted (see 204.7303); and&lt;br /&gt;
&lt;br /&gt;
:(ii) If there is a requirement for the contractor to have a Cybersecurity Maturity Model Certification (CMMC) status at a specific CMMC level, the contractor has a current CMMC status at the CMMC level required by the contract, or higher, for each of the CMMC unique identifiers applicable to each of the contractor information systems that process, store, or transmit Federal contract information or controlled unclassified information (see 204.7503(c)).&lt;br /&gt;
&lt;br /&gt;
== PART 252—Solicitation Provisions and Contract Clauses ==&lt;br /&gt;
&lt;br /&gt;
=== 252.204–7021 Contractor Compliance With the Cybersecurity Maturity Model Certification Level Requirements ===&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;As prescribed in 204.7504(a), use the following clause:&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;CONTRACTOR COMPLIANCE WITH THE CYBERSECURITY MATURITY MODEL CERTIFICATION LEVEL REQUIREMENTS (NOV 2025)&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;(a) Definitions.&#039;&#039;&#039; As used in this clause—&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Controlled unclassified information&#039;&#039;&#039; means information the Government creates or possesses, or information an entity creates or possesses for or on behalf of the Government, that a law, regulation, or Governmentwide policy requires or permits an agency to handle using safeguarding or dissemination controls (32 CFR 2002.4(h)).&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Current&#039;&#039;&#039; means— &#039;&#039;(see definition under DFARS 204.7501 above, which is incorporated identically into this clause)&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Cybersecurity Maturity Model Certification (CMMC) status&#039;&#039;&#039; means the result of meeting or exceeding the minimum required score for the corresponding assessment. The potential statuses are as follows:&lt;br /&gt;
&lt;br /&gt;
# Final Level 1 (Self).&lt;br /&gt;
# Conditional Level 2 (Self).&lt;br /&gt;
# Final Level 2 (Self).&lt;br /&gt;
# Conditional Level 2 (C3PAO).&lt;br /&gt;
# Final Level 2 (C3PAO).&lt;br /&gt;
# Conditional Level 3 (DIBCAC).&lt;br /&gt;
# Final Level 3 (DIBCAC).&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Cybersecurity Maturity Model Certification unique identifier (CMMC UID)&#039;&#039;&#039; means 10 alpha-numeric characters assigned to each CMMC assessment and reflected in the Supplier Performance Risk System (SPRS) for each contractor information system.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Federal contract information (FCI)&#039;&#039;&#039; means information, not intended for public release, that is provided by or generated for the Government under a contract to develop or deliver a product or service to the Government. It does not include information provided by the Government to the public, such as on public websites, or simple transactional information, such as information necessary to process payments.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Plan of action and milestones&#039;&#039;&#039; means a document that identifies tasks to be accomplished. It details resources required to accomplish the elements of the plan, any milestones in meeting the tasks, and scheduled completion dates for the milestones, as defined in National Institute of Standards and Technology Special Publication 800–115 (32 CFR 170.21).&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;(b) Framework.&#039;&#039;&#039; The Cybersecurity Maturity Model Certification (CMMC) is a framework for assessing a contractor&#039;s compliance with applicable information security protections (see 32 CFR part 170).&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;(c) Duplication.&#039;&#039;&#039; The CMMC assessments will not duplicate efforts from any other comparable DoD assessment, except for rare circumstances when a reassessment may be necessary, for example, when there are indications of issues with cybersecurity and/or compliance with CMMC requirements.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;(d) Requirements.&#039;&#039;&#039; The Contractor shall—&lt;br /&gt;
&lt;br /&gt;
(1)(i) Have and maintain for the duration of the contract a current CMMC status at the following CMMC level, or higher: _____ [Contracting Officer insert: CMMC Level 1 (Self); CMMC Level 2 (Self); CMMC Level 2 (C3PAO); or CMMC Level 3 (DIBCAC)] for all information systems used in performance of the contract, task order, or delivery order that process, store, or transmit FCI or CUI; and&lt;br /&gt;
&lt;br /&gt;
:(ii) Consult 32 CFR 170.23 related to the flowdown of the CMMC requirements, and flow down the correct CMMC level to subcontracts and other contractual instruments;&lt;br /&gt;
&lt;br /&gt;
(2) Only process, store, or transmit FCI or CUI on contractor information systems that have a CMMC status at the CMMC level required in paragraph (d)(1) of this clause, or higher;&lt;br /&gt;
&lt;br /&gt;
(3) Complete on an annual basis, and maintain as current, an affirmation, by the affirming official (see 32 CFR 170.4), of continuous compliance with the requirements associated with the CMMC level required in paragraph (d)(1) of this clause in the Supplier Performance Risk System (SPRS) (https://piee.eb.mil) for each CMMC UID applicable to each of the contractor information systems that process, store, or transmit FCI or CUI and that are used in performance of the contract;&lt;br /&gt;
&lt;br /&gt;
(4) Ensure all subcontractors and suppliers complete prior to subcontract award, and maintain on an annual basis, an affirmation, by the affirming official (see 32 CFR 170.4), of continuous compliance with the requirements associated with the CMMC level required for the subcontract or other contractual instrument for each of the subcontractor information systems that process, store, or transmit FCI or CUI and that are used in performance of the subcontract; and&lt;br /&gt;
&lt;br /&gt;
(5) If the Contractor has a CMMC Status of Conditional, successfully close out a valid plan of action and milestones (32 CFR 170.21) to achieve a CMMC Status of Final.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;(e) Reporting.&#039;&#039;&#039; The Contractor shall—&lt;br /&gt;
&lt;br /&gt;
(1) Submit to the Contracting Officer—&lt;br /&gt;
&lt;br /&gt;
:(i) The CMMC UID(s) issued by SPRS for contractor information systems that will process, store, or transmit FCI or CUI during performance of the contract; and&lt;br /&gt;
&lt;br /&gt;
:(ii) Any changes in the CMMC UIDs generated in SPRS throughout the life of the contract, task order, or delivery order, if applicable;&lt;br /&gt;
&lt;br /&gt;
(2) Enter into SPRS the results of a current self-assessment for each CMMC UID, not covered by a C3PAO assessment or DIBCAC assessment, applicable to each of the contractor information systems that process, store, or transmit FCI or CUI and that are used in performance of the contract; and&lt;br /&gt;
&lt;br /&gt;
(3) Complete in SPRS on an annual basis and maintain as current an affirmation of continuous compliance by the affirming official (see 32 CFR 170.4) for each self-assessment, C3PAO assessment, or DIBCAC assessment required under the contract in SPRS.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;(f) Subcontracts.&#039;&#039;&#039; The Contractor shall—&lt;br /&gt;
&lt;br /&gt;
(1) Insert the substance of this clause, including this paragraph (f) and excluding paragraph (e)(1), in subcontracts and other contractual instruments, including those for the acquisition of commercial products and commercial services, excluding commercially available off-the-shelf items, if the subcontract or other contractual instrument will contain a requirement to process, store, or transmit FCI or CUI; and&lt;br /&gt;
&lt;br /&gt;
(2) Prior to awarding a subcontract or other contractual instrument, ensure that the subcontractor has a current CMMC certificate or current CMMC status at the CMMC level that is appropriate for the information that is being flowed down to the subcontractor based on the requirements at 32 CFR 170.23.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;(End of clause)&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
=== 252.204–7025 Notice of Cybersecurity Maturity Model Certification Level Requirements ===&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;As prescribed in 204.7504(b), use the following provision:&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;NOTICE OF CYBERSECURITY MATURITY MODEL CERTIFICATION LEVEL REQUIREMENTS (NOV 2025)&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;(a) Definitions.&#039;&#039;&#039; As used in this provision, &#039;&#039;controlled unclassified information (CUI)&#039;&#039;, &#039;&#039;current&#039;&#039;, &#039;&#039;Cybersecurity Maturity Model Certification (CMMC) status&#039;&#039;, &#039;&#039;Cybersecurity Maturity Model Certification unique identifier (CMMC UID)&#039;&#039;, &#039;&#039;Federal contract information (FCI)&#039;&#039;, and &#039;&#039;Plan of action and milestones&#039;&#039; have the meaning given in the Defense Federal Acquisition Regulation Supplement 252.204–7021, &#039;&#039;Contractor Compliance With the Cybersecurity Maturity Model Certification Level Requirements&#039;&#039;, clause of this solicitation.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;(b)(1) Cybersecurity Maturity Model Certification (CMMC) level.&#039;&#039;&#039; The CMMC level required by this solicitation is: _____ [Contracting Officer insert: CMMC Level 1 (Self); CMMC Level 2 (Self); CMMC Level 2 (C3PAO); or CMMC Level 3 (DIBCAC)]. This CMMC level, or higher (see 32 CFR part 170), is required prior to award for each contractor information system that will process, store, or transmit Federal contract information (FCI) or controlled unclassified information (CUI) during performance of the contract.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;(2)&#039;&#039;&#039; The Offeror will not be eligible for award of a contract, task order, or delivery order resulting from this solicitation if the Offeror does not have, for each of the contractor information systems that will process, store, or transmit FCI or CUI and that will be used in performance of a contract resulting from this solicitation—&lt;br /&gt;
&lt;br /&gt;
:(i) The current CMMC status entered in the Supplier Performance Risk System (SPRS) (https://piee.eb.mil) at the CMMC level required by paragraph (b)(1) of this provision; and&lt;br /&gt;
&lt;br /&gt;
:(ii) A current affirmation of continuous compliance with the security requirements identified at 32 CFR part 170 in SPRS.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;(c) Plan of action and milestones.&#039;&#039;&#039; If the Offeror has a CMMC Status of Conditional, the Offeror shall successfully close out a valid plan of action and milestones (32 CFR 170.21) to achieve a CMMC Status of Final.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;(d) CMMC unique identifiers.&#039;&#039;&#039; The Offeror shall provide, in the proposal, the CMMC unique identifier(s) (CMMC UIDs) issued by SPRS for each contractor information system that will process, store, or transmit FCI or CUI during performance of a contract, task order, or delivery order resulting from this solicitation. The Offeror also shall update the list when new CMMC UIDs are generated in SPRS. The CMMC UIDs are provided in SPRS after the Offeror enters the results of self-assessment(s) for each such information system.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;(End of provision)&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;[FR Doc. 2025–17359 Filed 9–9–25; 8:45 am]&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;BILLING CODE 6001–FR–P&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
[[Category:Federal Register]]&lt;br /&gt;
[[Category:DFARS]]&lt;br /&gt;
[[Category:Cybersecurity Maturity Model Certification]]&lt;br /&gt;
[[Category:Defense Acquisition Regulations]]&lt;/div&gt;</summary>
		<author><name>David</name></author>
	</entry>
	<entry>
		<id>https://cmmcwiki.org/index.php?title=MediaWiki:Sidebar&amp;diff=1608</id>
		<title>MediaWiki:Sidebar</title>
		<link rel="alternate" type="text/html" href="https://cmmcwiki.org/index.php?title=MediaWiki:Sidebar&amp;diff=1608"/>
		<updated>2026-07-17T15:53:26Z</updated>

		<summary type="html">&lt;p&gt;David: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;* navigation&lt;br /&gt;
** mainpage | mainpage-description&lt;br /&gt;
* CMMC Model and Rule&lt;br /&gt;
** Model_Overview | Model Overview&lt;br /&gt;
** 32_CFR_Part_170 | 32 CFR Part 170&lt;br /&gt;
** 48_CFR_Parts_204_212_217_252 | 48 CFR Parts 204, 212, 217, and 252&lt;br /&gt;
* Scoping and Assessment Guides&lt;br /&gt;
** Level_1_Scoping_Guidance | Level 1 Scoping Guidance&lt;br /&gt;
** Level_1_Self-Assessment_Guide | Level 1 Self-Assessment Guide&lt;br /&gt;
** Level_2_Scoping_Guidance | Level 2 Scoping Guidance&lt;br /&gt;
** Level_2_Assessment_Guide | Level 2 Assessment Guide&lt;br /&gt;
** Level_3_Scoping_Guidance | Level 3 Scoping Guidance&lt;br /&gt;
** Level_3_Assessment_Guide | Level 3 Assessment Guide&lt;br /&gt;
* CMMC Guides and Tools&lt;br /&gt;
** CMMC_Hashing_Guide | CMMC Hashing Guide&lt;br /&gt;
** CMMC_Assessment_Process | CMMC Assessment Process (CAP) by CyberAB&lt;br /&gt;
** DoD_Assessment_Methodology | DoD Assessment Methodology&lt;br /&gt;
** External_References | External References&lt;/div&gt;</summary>
		<author><name>David</name></author>
	</entry>
	<entry>
		<id>https://cmmcwiki.org/index.php?title=MediaWiki:Sidebar&amp;diff=1607</id>
		<title>MediaWiki:Sidebar</title>
		<link rel="alternate" type="text/html" href="https://cmmcwiki.org/index.php?title=MediaWiki:Sidebar&amp;diff=1607"/>
		<updated>2026-07-17T15:53:10Z</updated>

		<summary type="html">&lt;p&gt;David: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;* navigation&lt;br /&gt;
** mainpage | mainpage-description&lt;br /&gt;
* CMMC Model and Rule&lt;br /&gt;
** Model_Overview | Model Overview&lt;br /&gt;
** 32_CFR_Part_170 | 32 CFR Part 170&lt;br /&gt;
** 48_CFR_Parts_204_212_217_252 | 32 CFR Parts 204, 212, 217, and 252&lt;br /&gt;
* Scoping and Assessment Guides&lt;br /&gt;
** Level_1_Scoping_Guidance | Level 1 Scoping Guidance&lt;br /&gt;
** Level_1_Self-Assessment_Guide | Level 1 Self-Assessment Guide&lt;br /&gt;
** Level_2_Scoping_Guidance | Level 2 Scoping Guidance&lt;br /&gt;
** Level_2_Assessment_Guide | Level 2 Assessment Guide&lt;br /&gt;
** Level_3_Scoping_Guidance | Level 3 Scoping Guidance&lt;br /&gt;
** Level_3_Assessment_Guide | Level 3 Assessment Guide&lt;br /&gt;
* CMMC Guides and Tools&lt;br /&gt;
** CMMC_Hashing_Guide | CMMC Hashing Guide&lt;br /&gt;
** CMMC_Assessment_Process | CMMC Assessment Process (CAP) by CyberAB&lt;br /&gt;
** DoD_Assessment_Methodology | DoD Assessment Methodology&lt;br /&gt;
** External_References | External References&lt;/div&gt;</summary>
		<author><name>David</name></author>
	</entry>
	<entry>
		<id>https://cmmcwiki.org/index.php?title=MediaWiki:Sidebar&amp;diff=1606</id>
		<title>MediaWiki:Sidebar</title>
		<link rel="alternate" type="text/html" href="https://cmmcwiki.org/index.php?title=MediaWiki:Sidebar&amp;diff=1606"/>
		<updated>2026-06-30T02:12:39Z</updated>

		<summary type="html">&lt;p&gt;David: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;* navigation&lt;br /&gt;
** mainpage | mainpage-description&lt;br /&gt;
* CMMC Model and Rule&lt;br /&gt;
** Model_Overview | Model Overview&lt;br /&gt;
** 32_CFR_Part_170 | 32 CFR Part 170&lt;br /&gt;
* Scoping and Assessment Guides&lt;br /&gt;
** Level_1_Scoping_Guidance | Level 1 Scoping Guidance&lt;br /&gt;
** Level_1_Self-Assessment_Guide | Level 1 Self-Assessment Guide&lt;br /&gt;
** Level_2_Scoping_Guidance | Level 2 Scoping Guidance&lt;br /&gt;
** Level_2_Assessment_Guide | Level 2 Assessment Guide&lt;br /&gt;
** Level_3_Scoping_Guidance | Level 3 Scoping Guidance&lt;br /&gt;
** Level_3_Assessment_Guide | Level 3 Assessment Guide&lt;br /&gt;
* CMMC Guides and Tools&lt;br /&gt;
** CMMC_Hashing_Guide | CMMC Hashing Guide&lt;br /&gt;
** CMMC_Assessment_Process | CMMC Assessment Process (CAP) by CyberAB&lt;br /&gt;
** DoD_Assessment_Methodology | DoD Assessment Methodology&lt;br /&gt;
** External_References | External References&lt;/div&gt;</summary>
		<author><name>David</name></author>
	</entry>
	<entry>
		<id>https://cmmcwiki.org/index.php?title=MediaWiki:Sidebar&amp;diff=1605</id>
		<title>MediaWiki:Sidebar</title>
		<link rel="alternate" type="text/html" href="https://cmmcwiki.org/index.php?title=MediaWiki:Sidebar&amp;diff=1605"/>
		<updated>2026-06-30T02:07:54Z</updated>

		<summary type="html">&lt;p&gt;David: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;* navigation&lt;br /&gt;
** mainpage | mainpage-description&lt;br /&gt;
* CMMC Model and Rule&lt;br /&gt;
** Model_Overview | Model Overview&lt;br /&gt;
** 32_CFR_Part_170 | 32 CFR Part 170&lt;br /&gt;
* Scoping and Assessment Guides&lt;br /&gt;
** Level_1_Scoping_Guidance | Level 1 Scoping Guidance&lt;br /&gt;
** Level_1_Self-Assessment_Guide | Level 1 Self-Assessment Guide&lt;br /&gt;
** Level_2_Scoping_Guidance | Level 2 Scoping Guidance&lt;br /&gt;
** Level_2_Assessment_Guide | Level 2 Assessment Guide&lt;br /&gt;
** Level_3_Scoping_Guidance | Level 3 Scoping Guidance&lt;br /&gt;
** Level_3_Assessment_Guide | Level 3 Assessment Guide&lt;br /&gt;
* CMMC Guides and Tools&lt;br /&gt;
** CMMC_Hashing_Guide | CMMC Hashing Guide&lt;br /&gt;
** CMMC_Assessment_Process | CMMC Assessment Process (CAP) by CyberAB&lt;br /&gt;
** DoD_Assessment_Methodology | DoD Assessment Methodology&lt;br /&gt;
** Commonly_Accepted_and_Practiced_CMMC_Operation_Matrix | Commonly Accepted &amp;amp; Practiced CMMC Operation Matrix (CAPCOM)&lt;br /&gt;
** External_References | External References&lt;/div&gt;</summary>
		<author><name>David</name></author>
	</entry>
	<entry>
		<id>https://cmmcwiki.org/index.php?title=Main_Page&amp;diff=1604</id>
		<title>Main Page</title>
		<link rel="alternate" type="text/html" href="https://cmmcwiki.org/index.php?title=Main_Page&amp;diff=1604"/>
		<updated>2026-04-24T14:32:02Z</updated>

		<summary type="html">&lt;p&gt;David: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&#039;&#039;&#039;This website contains information about the Cybersecurity Maturity Model Certification (CMMC) program of the U.S. Department of Defense (DoD).&lt;br /&gt;
&lt;br /&gt;
The wiki aims to provide educational references for those who are interested in learning more about the framework.&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
Primary Source of Reference: The official [https://dodcio.defense.gov/CMMC/ CMMC Home Page] from the Department of Defense Chief Information Officer (DoD CIO).&lt;br /&gt;
&lt;br /&gt;
Additional References: The [https://dodcio.defense.gov/cmmc/Resources-Documentation/ CMMC Resources &amp;amp; Documentation] page contains a variety of links to CMMC resources throughout the DoD.&lt;br /&gt;
&lt;br /&gt;
Basic information on FedRAMP and Cybersecurity Framework are also available on this website. Select one of the menu items on the Sidebar.&lt;br /&gt;
&lt;br /&gt;
For inquiries and reporting errors on this wiki, please [mailto:support@cmmcwiki.org contact us]. Thank you.&lt;/div&gt;</summary>
		<author><name>David</name></author>
	</entry>
	<entry>
		<id>https://cmmcwiki.org/index.php?title=32_CFR_Part_170&amp;diff=1603</id>
		<title>32 CFR Part 170</title>
		<link rel="alternate" type="text/html" href="https://cmmcwiki.org/index.php?title=32_CFR_Part_170&amp;diff=1603"/>
		<updated>2026-03-02T01:33:24Z</updated>

		<summary type="html">&lt;p&gt;David: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&#039;&#039;&#039;Source of Reference: The official [https://www.federalregister.gov/documents/2024/10/15/2024-22905/cybersecurity-maturity-model-certification-cmmc-program Cybersecurity Maturity Model Certification (CMMC) Program] final rule.&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
For inquiries and reporting errors on this wiki, please [mailto:support@cmmcwiki.org contact us]. Thank you.&lt;br /&gt;
&lt;br /&gt;
== PART 170 - CYBERSECURITY MATURITY MODEL CERTIFICATION (CMMC) PROGRAM ==&lt;br /&gt;
&lt;br /&gt;
=== Subpart A - General Information ===&lt;br /&gt;
Sec.&lt;br /&gt;
* 170.1 Purpose.&lt;br /&gt;
* 170.2 Incorporation by reference.&lt;br /&gt;
* 170.3 Applicability.&lt;br /&gt;
* 170.4 Acronyms and definitions.&lt;br /&gt;
* 170.5 Policy.&lt;br /&gt;
&lt;br /&gt;
=== Subpart B - Government Roles and Responsibilities ===&lt;br /&gt;
* 170.6 CMMC PMO.&lt;br /&gt;
* 170.7 DCMA DIBCAC.&lt;br /&gt;
&lt;br /&gt;
=== Subpart C - CMMC Assessment and Certification Ecosystem ===&lt;br /&gt;
* 170.8 Accreditation Body.&lt;br /&gt;
* 170.9 CMMC Third-Party Assessment Organizations (C3PAOs).&lt;br /&gt;
* 170.10 CMMC Assessor and Instructor Certification Organization (CAICO).&lt;br /&gt;
* 170.11 CMMC Certified Assessor (CCA).&lt;br /&gt;
* 170.12 CMMC Instructor.&lt;br /&gt;
* 170.13 CMMC Certified Professional (CCP).&lt;br /&gt;
&lt;br /&gt;
=== Subpart D - Key Elements of the CMMC Program ===&lt;br /&gt;
* 170.14 CMMC Model.&lt;br /&gt;
* 170.15 CMMC Level 1 self-assessment and affirmation requirements.&lt;br /&gt;
* 170.16 CMMC Level 2 self-assessment and affirmation requirements.&lt;br /&gt;
* 170.17 CMMC Level 2 certification assessment and affirmation requirements.&lt;br /&gt;
* 170.18 CMMC Level 3 certification assessment and affirmation requirements.&lt;br /&gt;
* 170.19 CMMC scoping.&lt;br /&gt;
* 170.20 Standards acceptance.&lt;br /&gt;
* 170.21 Plan of Action and Milestones requirements.&lt;br /&gt;
* 170.22 Affirmation.&lt;br /&gt;
* 170.23 Application to subcontractors.&lt;br /&gt;
* 170.24 CMMC Scoring Methodology.&lt;br /&gt;
* Appendix A to Part 170 - Guidance&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Authority&#039;&#039;&#039;: 5 U.S.C. 301; Sec. 1648, Pub. L. 116-92, 133 Stat. 1198.&lt;br /&gt;
&lt;br /&gt;
== Subpart A - General Information. ==&lt;br /&gt;
=== § 170.1 Purpose. ===&lt;br /&gt;
(a) This part describes the Cybersecurity Maturity Model Certification (CMMC) Program of the Department of Defense (DoD) and establishes requirements for defense contractors and subcontractors to implement prescribed cybersecurity standards for safeguarding Federal Contract Information (FCI) and Controlled Unclassified Information (CUI). This part (the CMMC Program) also establishes requirements for conducting an assessment of compliance with the applicable prescribed cybersecurity standard for contractor information systems that: process, store, or transmit FCI or CUI; provide security protections for systems which process, store, or transmit CUI; or are not logically or physically isolated from systems which process, store, or transmit CUI.&lt;br /&gt;
&lt;br /&gt;
(b) The CMMC Program provides DoD with a viable means of conducting the volume of assessments necessary to verify contractor and subcontractor implementation of required cybersecurity requirements.&lt;br /&gt;
&lt;br /&gt;
(c) The CMMC Program is designed to ensure defense contractors are properly safeguarding FCI and CUI that is processed, stored, or transmitted on defense contractor information systems. FCI and CUI must be protected to meet evolving threats and safeguard nonpublic, unclassified information that supports and enables the warfighter. The CMMC Program provides a consistent methodology to assess a defense contractor’s implementation of required cybersecurity requirements. The CMMC Program utilizes the security standards set forth in the 48 CFR 52.204-21; National Institute of Standards and Technology (NIST) Special Publication (SP) 800-171, &#039;&#039;Basic Safeguarding of Covered Contractor Information Systems, &#039;&#039;Revision 2, February 2020 (includes updates as of January 28, 2021) (NIST SP 800-171 R2); and selected requirements from the NIST SP 800-172, &#039;&#039;Enhanced Security Requirements for Protecting Controlled Unclassified Information: A Supplement to NIST Special Publication 800-171, &#039;&#039;February 2021 (NIST SP 800-172 Feb2021), as applicable (see table 1 to § 170.14(c)(4) for requirements, see § 170.2 for availability of NIST publications).&lt;br /&gt;
&lt;br /&gt;
(d) The CMMC Program balances the need to safeguard FCI and CUI and the requirement to share information appropriately with defense contractors in order to develop capabilities for the DoD. The CMMC Program is designed to ensure implementation of cybersecurity practices for defense contractors and to provide DoD with increased assurance that FCI and CUI information will be adequately safeguarded when residing on or transiting contractor information systems.&lt;br /&gt;
&lt;br /&gt;
(e) The CMMC Program creates no right or benefit, substantive or procedural, enforceable by law or in equity by any party against the United States, its departments, agencies, or entities, its officers, employees, or agents, or any other person.&lt;br /&gt;
&lt;br /&gt;
=== § 170.2 Incorporation by reference. ===&lt;br /&gt;
&lt;br /&gt;
Certain material is incorporated by reference into this part with the approval of the Director of the Federal Register under 5 U.S.C. 552(a) and 1 CFR part 51. Material approved for incorporation by reference (IBR) is available for inspection at the Department of Defense (DoD) and at the National Archives and Records Administration (NARA). Contact DoD online: &#039;&#039;https://DoDcio.defense.gov/CMMC/&#039;&#039;; email: &#039;&#039;osd.mc-alex.DoD-cio.mbx.cmmc-rule@mail.mil&#039;&#039;; or phone: (202) 770-9100. For information on the availability of this material at NARA, visit: &#039;&#039;www.archives.gov/federal-register/ cfr/ibr-locations&#039;&#039; or email: &#039;&#039;fr.inspection@nara.gov&#039;&#039;. The material may be obtained from the following sources:&lt;br /&gt;
&lt;br /&gt;
(a) National Institute of Standards and Technology, U.S. Department of Commerce, 100 Bureau Drive, Gaithersburg, MD 20899; phone: (301) 975-8443; website: &#039;&#039;https://csrc.nist.gov/ publications/&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
(1) FIPS PUB 200, Minimum Security Requirements for Federal Information and Information Systems, March 2006 (FIPS PUB 200 Mar2006); IBR approved for § 170.4(b).&lt;br /&gt;
&lt;br /&gt;
(2) FIPS PUB 201-3, Personal Identity Verification (PIV) of Federal Employees and Contractors, January 2022 (FIPS PUB 201-3 Jan2022); IBR approved for § 170.4(b).&lt;br /&gt;
&lt;br /&gt;
(3) SP 800-37, Risk Management Framework for Information Systems and Organizations: A System Life Cycle Approach for Security and Privacy, Revision 2, December 2018 (NIST SP 800-37 R2); IBR approved for § 170.4(b).&lt;br /&gt;
&lt;br /&gt;
(4) SP 800-39, Managing Information Security Risk: Organization, Mission, and Information System View, March 2011 (NIST SP 800-39 Mar2011); IBR approved for § 170.4(b).&lt;br /&gt;
&lt;br /&gt;
(5) SP 800-53, Security and Privacy Controls for Information Systems and Organizations, Revision 5, September 2020 (includes updates as of December 10, 2020) (NIST SP 800-53 R5); IBR approved for § 170.4(b).&lt;br /&gt;
&lt;br /&gt;
(6) SP 800-82r3, Guide to Operational Technology (OT) Security, September 2023 (NIST SP 800-82r3); IBR approved for § 170.4(b).&lt;br /&gt;
&lt;br /&gt;
(7) SP 800-115, Technical Guide to Information Security Testing and Assessment, September 2008 (NIST SP 800-115 Sept2008); IBR approved for § 170.4(b).&lt;br /&gt;
&lt;br /&gt;
(8) SP 800-160, Volume 2, Developing Cyber-Resilient Systems: A Systems Security Engineering Approach, Revision 1, December 2021 (NIST SP 800-160 V2R1); IBR approved for § 170.4(b).&lt;br /&gt;
&lt;br /&gt;
(9) SP 800-171, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations, Revision 2, February 2020 (includes updates as of January 28, 2021), (NIST SP 800-171 R2); IBR approved for §§ 170.4(b) and 170.14(a) through (c).&lt;br /&gt;
&lt;br /&gt;
(10) SP 800-171A, Assessing Security Requirements for Controlled Unclassified Information, June 2018 (NIST SP 800-171A Jun2018); IBR approved for §§ 170.11(a), 170.14(d), 170.15(c), 170.16(c), 170.17(c), and 170.18(c).&lt;br /&gt;
&lt;br /&gt;
(11) SP 800-172, Enhanced Security Requirements for Protecting Controlled Unclassified Information: A Supplement to NIST Special Publication 800-171, February 2021 (NIST SP 800-172 Feb2021); IBR approved for §§ 170.4(b), 170.5(a), and 170.14(a) and (c).&lt;br /&gt;
&lt;br /&gt;
(12) SP 800-172A, Assessing Enhanced Security Requirements for Controlled Unclassified Information, March 2022 (NIST SP 800-172A Mar2022); IBR approved for §§ 170.4(b), 170.14(d), and 170.18(c).&lt;br /&gt;
&lt;br /&gt;
(b) International Organization for Standardization (ISO) Chemin de Blandonnet 8, CP 401 - 1214 Vernier, Geneva, Switzerland; phone: +41 22 749 01 11; website: &#039;&#039;www.iso.org/popular- standards.html&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
(1) ISO/IEC 17011:2017(E), Conformity assessment - Requirements for accreditation bodies accrediting conformity assessment bodies, Second edition, November 2017 (ISO/IEC 17011:2017(E)); IBR approved for §§ 170.8(b)(3), 170.9(b)(13), and 170.10(b)(4).&lt;br /&gt;
&lt;br /&gt;
(2) ISO/IEC 17020:2012(E), Conformity assessment - Requirement for the operation of various types of bodies performing inspection, Second edition, March 1, 2012 (ISO/IEC 17020:2012(E)); IBR approved for §§ 170.8(a), (b)(1), (b)(3) and 170.9(b)(2) and (b)(13).&lt;br /&gt;
&lt;br /&gt;
(3) ISO/IEC 17024:2012(E), Conformity assessment - General requirements for bodies operating certification of persons, second edition, July 1, 2012 (ISO/IEC 17024:2012(E)); IBR approved for §§ 170.8(b)(2) and 170.10(a) and (b)(4), (7), and (8).&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Note 1 to paragraph (b):&#039;&#039;&#039; The ISO/IEC standards incorporated by reference in this part may be viewed at no cost in ‘‘read only’’ format at &#039;&#039;https://ibr.ansi.org&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
=== § 170.3 Applicability. ===&lt;br /&gt;
&lt;br /&gt;
(a) The requirements of this part apply to:&lt;br /&gt;
&lt;br /&gt;
(1) All DoD contract and subcontract awardees that will process, store, or transmit information, in performance of the DoD contract, that meets the standards for FCI or CUI on contractor information systems; and,&lt;br /&gt;
&lt;br /&gt;
(2) Private-sector businesses or other entities comprising the CMMC Assessment and Certification Ecosystem, as specified in subpart C of this part.&lt;br /&gt;
&lt;br /&gt;
(b) The requirements of this part do not apply to Federal information systems operated by contractors or subcontractors on behalf of the Government.&lt;br /&gt;
&lt;br /&gt;
(c) CMMC Program requirements apply to all DoD solicitations and contracts pursuant to which a defense contractor or subcontractor will process, store, or transmit FCI or CUI on unclassified contractor information systems, including those for the acquisition of commercial items (except those exclusively for COTS items) valued at greater than the micro- purchase threshold except under the following circumstances: &lt;br /&gt;
&lt;br /&gt;
(1) The procurement occurs during Implementation Phase 1, 2, or 3 as described in paragraph (e) of this section, in which case CMMC Program requirements apply in accordance with the requirements for the relevant phase- in period; or &lt;br /&gt;
&lt;br /&gt;
(2) Application of CMMC Program requirements to a procurement or class of procurements may be waived in advance of the solicitation at the discretion of DoD in accordance with all applicable policies, procedures, and approval requirements.&lt;br /&gt;
&lt;br /&gt;
(d) DoD Program Managers or requiring activities are responsible for selecting the CMMC Status that will apply for a particular procurement or contract based upon the type of information, FCI or CUI, that will be processed on, stored on, or transmitted through a contractor information system. Application of the CMMC Status for subcontractors will be determined in accordance with § 170.23.&lt;br /&gt;
&lt;br /&gt;
(e) DoD is utilizing a phased approach for the inclusion of CMMC Program requirements in solicitations and contracts. Implementation of CMMC Program requirements will occur over four (4) phases: &lt;br /&gt;
&lt;br /&gt;
(1) &#039;&#039;Phase 1&#039;&#039;. Begins on the effective date of the complementary 48 CFR part 204 CMMC Acquisition final rule. DoD intends to include the requirement for CMMC Statuses of Level 1 (Self) or Level 2 (Self) for all applicable DoD solicitations and contracts as a condition of contract award. DoD may, at its discretion, include the requirement for CMMC Status of Level 1 (Self) or Level 2 (Self) for applicable DoD solicitations and contracts as a condition to exercise an option period on a contract awarded prior to the effective date. DoD may also, at its discretion, include the requirement for CMMC Status of Level 2 (C3PAO) in place of the Level 2 (Self) CMMC Status for applicable DoD solicitations and contracts.&lt;br /&gt;
&lt;br /&gt;
(2) &#039;&#039;Phase 2&#039;&#039;. Begins one calendar year following the start date of Phase 1. In addition to Phase 1 requirements, DoD intends to include the requirement for CMMC Status of Level 2 (C3PAO) for applicable DoD solicitations and contracts as a condition of contract award. DoD may, at its discretion, delay the inclusion of requirement for CMMC Status of Level 2 (C3PAO) to an option period instead of as a condition of contract award. DoD may also, at its discretion, include the requirement for CMMC Status of Level 3 (DIBCAC) for applicable DoD solicitations and contracts.&lt;br /&gt;
&lt;br /&gt;
(3) &#039;&#039;Phase 3&#039;&#039;. Begins one calendar year following the start date of Phase 2. In addition to Phase 1 and 2 requirements, DoD intends to include the requirement for CMMC Status of Level 2 (C3PAO) for all applicable DoD solicitations and contracts as a condition of contract award and as a condition to exercise an option period on a contract awarded after the effective date. DoD intends to include the requirement for CMMC Status of Level 3 (DIBCAC) for all applicable DoD solicitations and contracts as a condition of contract award. DoD may, at its discretion, delay the inclusion of requirement for CMMC Status of Level 3 (DIBCAC) to an option period instead of as a condition of contract award.&lt;br /&gt;
&lt;br /&gt;
(4) &#039;&#039;Phase 4, full implementation&#039;&#039;. Begins one calendar year following the start date of Phase 3. DoD will include CMMC Program requirements in all applicable DoD solicitations and contracts including option periods on contracts awarded prior to the beginning of Phase 4.&lt;br /&gt;
&lt;br /&gt;
=== § 170.4 Acronyms and definitions. ===&lt;br /&gt;
&lt;br /&gt;
(a) &#039;&#039;Acronyms. &#039;&#039;Unless otherwise noted, the following acronyms and their terms are for the purposes of this part.&lt;br /&gt;
&lt;br /&gt;
AC - Access Control&amp;lt;br&amp;gt;&lt;br /&gt;
APT - Advanced Persistent Threat&amp;lt;br&amp;gt;&lt;br /&gt;
AT - Awareness and Training&amp;lt;br&amp;gt;&lt;br /&gt;
C3PAO - CMMC Third-Party Assessment Organization&amp;lt;br&amp;gt;&lt;br /&gt;
CA - Security Assessment CAICO - CMMC Assessors and Instructors Certification Organization&amp;lt;br&amp;gt;&lt;br /&gt;
CAGE - Commercial and Government Entity&amp;lt;br&amp;gt;&lt;br /&gt;
CCA - CMMC-Certified Assessor&amp;lt;br&amp;gt;&lt;br /&gt;
CCI - CMMC-Certified Instructor&amp;lt;br&amp;gt;&lt;br /&gt;
CCP - CMMC-Certified Professional&amp;lt;br&amp;gt;&lt;br /&gt;
CFR - Code of Federal Regulations&amp;lt;br&amp;gt;&lt;br /&gt;
CIO - Chief Information Officer&amp;lt;br&amp;gt;&lt;br /&gt;
CM - Configuration Management&amp;lt;br&amp;gt;&lt;br /&gt;
CMMC - Cybersecurity Maturity Model Certification&amp;lt;br&amp;gt;&lt;br /&gt;
CMMC PMO - CMMC Program Management Office&amp;lt;br&amp;gt;&lt;br /&gt;
CNC - Computerized Numerical Control&amp;lt;br&amp;gt;&lt;br /&gt;
CoPC - Code of Professional Conduct&amp;lt;br&amp;gt;&lt;br /&gt;
CSP - Cloud Service Provider&amp;lt;br&amp;gt;&lt;br /&gt;
CUI - Controlled Unclassified Information&amp;lt;br&amp;gt;&lt;br /&gt;
DCMA - Defense Contract Management Agency&amp;lt;br&amp;gt;&lt;br /&gt;
DD - Represents any two-character CMMC Domain acronym&amp;lt;br&amp;gt;&lt;br /&gt;
DFARS - Defense Federal Acquisition Regulation Supplement&amp;lt;br&amp;gt;&lt;br /&gt;
DIB - Defense Industrial Base&amp;lt;br&amp;gt;&lt;br /&gt;
DIBCAC - DCMA’s Defense Industrial Base Cybersecurity Assessment Center&amp;lt;br&amp;gt;&lt;br /&gt;
DoD - Department of Defense DoDI - Department of Defense Instruction&amp;lt;br&amp;gt;&lt;br /&gt;
eMASS - Enterprise Mission Assurance Support Service&amp;lt;br&amp;gt;&lt;br /&gt;
ESP - External Service Provider&amp;lt;br&amp;gt;&lt;br /&gt;
FAR - Federal Acquisition Regulation&amp;lt;br&amp;gt;&lt;br /&gt;
FCI - Federal Contract Information&amp;lt;br&amp;gt;&lt;br /&gt;
FedRAMP - Federal Risk and Authorization Management Program&amp;lt;br&amp;gt;&lt;br /&gt;
GFE - Government Furnished Equipment&amp;lt;br&amp;gt;&lt;br /&gt;
IA - Identification and Authentication&amp;lt;br&amp;gt;&lt;br /&gt;
ICS - Industrial Control System&amp;lt;br&amp;gt;&lt;br /&gt;
IIoT - Industrial Internet of Things&amp;lt;br&amp;gt;&lt;br /&gt;
IoT - Internet of Things&amp;lt;br&amp;gt;&lt;br /&gt;
IR - Incident Response&amp;lt;br&amp;gt;&lt;br /&gt;
IS - Information System&amp;lt;br&amp;gt;&lt;br /&gt;
IEC - International Electrotechnical Commission&amp;lt;br&amp;gt;&lt;br /&gt;
ISO/IEC - International Organization for Standardization/International Electrotechnical Commission&amp;lt;br&amp;gt;&lt;br /&gt;
IT - Information Technology&amp;lt;br&amp;gt;&lt;br /&gt;
L# - CMMC Level Number&amp;lt;br&amp;gt;&lt;br /&gt;
MA - Maintenance&amp;lt;br&amp;gt;&lt;br /&gt;
MP - Media Protection&amp;lt;br&amp;gt;&lt;br /&gt;
MSSP - Managed Security Service Provider&amp;lt;br&amp;gt;&lt;br /&gt;
NARA - National Archives and Records Administration&amp;lt;br&amp;gt;&lt;br /&gt;
NAICS - North American Industry Classification System&amp;lt;br&amp;gt;&lt;br /&gt;
NIST - National Institute of Standards and Technology&amp;lt;br&amp;gt;&lt;br /&gt;
N/A - Not Applicable&amp;lt;br&amp;gt;&lt;br /&gt;
ODP - Organization-Defined Parameter&amp;lt;br&amp;gt;&lt;br /&gt;
OSA - Organization Seeking Assessment&amp;lt;br&amp;gt;&lt;br /&gt;
OSC - Organization Seeking Certification&amp;lt;br&amp;gt;&lt;br /&gt;
OT - Operational Technology&amp;lt;br&amp;gt;&lt;br /&gt;
PI - Provisional Instructor&amp;lt;br&amp;gt;&lt;br /&gt;
PIEE - Procurement Integrated Enterprise Environment&amp;lt;br&amp;gt;&lt;br /&gt;
PII - Personally Identifiable Information&amp;lt;br&amp;gt;&lt;br /&gt;
PLC - Programmable Logic Controller&amp;lt;br&amp;gt;&lt;br /&gt;
POA&amp;amp;M - Plan of Action and Milestones&amp;lt;br&amp;gt;&lt;br /&gt;
PRA - Paperwork Reduction Act&amp;lt;br&amp;gt;&lt;br /&gt;
RM - Risk Management&amp;lt;br&amp;gt;&lt;br /&gt;
SAM - System of Award Management&amp;lt;br&amp;gt;&lt;br /&gt;
SC - System and Communications Protection&amp;lt;br&amp;gt;&lt;br /&gt;
SCADA - Supervisory Control and Data Acquisition&amp;lt;br&amp;gt;&lt;br /&gt;
SI - System and Information Integrity&amp;lt;br&amp;gt;&lt;br /&gt;
SIEM - Security Information and Event Management&amp;lt;br&amp;gt;&lt;br /&gt;
SP - Special Publication&amp;lt;br&amp;gt;&lt;br /&gt;
SPD - Security Protection Data&amp;lt;br&amp;gt;&lt;br /&gt;
SPRS - Supplier Performance Risk System&amp;lt;br&amp;gt;&lt;br /&gt;
SSP - System Security Plan&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
(b) &#039;&#039;Definitions&#039;&#039;. Unless otherwise noted, these terms and their definitions are for the purposes of this part.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Access Control (AC) &#039;&#039;means the process of granting or denying specific requests to obtain and use information and related information processing services; and/or entry to specific physical facilities (&#039;&#039;e.g., &#039;&#039;Federal buildings, military establishments, or border crossing entrances), as defined in FIPS PUB 201-3 Jan2002 (incorporated by reference, see § 170.2).&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Accreditation&#039;&#039; means a status pursuant to which a CMMC Assessment and Certification Ecosystem member (person or organization), having met all criteria for the specific role they perform including required ISO/IEC accreditations, may act in that role as set forth in § 170.8 for the Accreditation Body and § 170.9 for C3PAOs. (CMMC- custom term)&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Accreditation Body&#039;&#039; is defined in § 170.8 and means the one organization DoD contracts with to be responsible for authorizing and accrediting members of the CMMC Assessment and Certification Ecosystem, as required. The Accreditation Body must be approved by DoD. At any given point in time, there will be only one Accreditation Body for the DoD CMMC Program. (CMMC-custom term)&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Advanced Persistent Threat (APT) &#039;&#039;means an adversary that possesses sophisticated levels of expertise and significant resources that allow it to create opportunities to achieve its objectives by using multiple attack vectors (&#039;&#039;e.g.&#039;&#039;, cyber, physical, and deception). These objectives typically include establishing and extending footholds within the information technology infrastructure of the targeted organizations for purposes of exfiltrating information, undermining or impeding critical aspects of a mission, program, or organization; or positioning itself to carry out these objectives in the future. The advanced persistent threat pursues its objectives repeatedly over an extended period-of-time, adapts to defenders’ efforts to resist it, and is determined to maintain the level of interaction needed to execute its objectives, as is defined in NIST SP 800-39 Mar2011 (incorporated by reference, see § 170.2).&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Affirming Official&#039;&#039; means the senior level representative from within each Organization Seeking Assessment (OSA) who is responsible for ensuring the OSA’s compliance with the CMMC Program requirements and has the authority to affirm the OSA’s continuing compliance with the specified security requirements for their respective organizations. (CMMC-custom term)&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Assessment&#039;&#039; means the testing or evaluation of security controls to determine the extent to which the controls are implemented correctly, operating as intended, and producing the desired outcome with respect to meeting the security requirements for an information system or organization, as defined in §§ 170.15 through 170.18. (CMMC-custom term)&lt;br /&gt;
&lt;br /&gt;
(i) &#039;&#039;Level 1 self-assessment&#039;&#039; is the term for the activity performed by an OSA to evaluate its own information system when seeking a CMMC Status of Level 1 (Self).&lt;br /&gt;
&lt;br /&gt;
(ii) &#039;&#039;Level 2 self-assessment&#039;&#039; is the term for the activity performed by an OSA to evaluate its own information system when seeking a CMMC Status of Level 2 (Self).&lt;br /&gt;
&lt;br /&gt;
(iii) &#039;&#039;Level 2 certification assessment&#039;&#039; is the term for the activity performed by a C3PAO to evaluate the information system of an OSC when seeking a CMMC Status of Level 2 (C3PAO).&lt;br /&gt;
&lt;br /&gt;
(iv) &#039;&#039;Level 3 certification assessment&#039;&#039; is the term for the activity performed by the DCMA DIBCAC to evaluate the information system of an OSC when seeking a CMMC Status of Level 3 (DIBCAC).&lt;br /&gt;
&lt;br /&gt;
(v) &#039;&#039;POA&amp;amp;M closeout self-assessment&#039;&#039; is the term for the activity performed by an OSA to evaluate only the NOT MET requirements that were identified with POA&amp;amp;M during the initial assessment, when seeking a CMMC Status of Final Level 2 (Self).&lt;br /&gt;
&lt;br /&gt;
(vi) &#039;&#039;POA&amp;amp;M closeout certification assessment&#039;&#039; is the term for the activity performed by a C3PAO or DCMA DIBCAC to evaluate only the NOT MET requirements that were identified with POA&amp;amp;M during the initial assessment, when seeking a CMMC Status of Final Level 2 (C3PAO) or Final Level 3 (DIBCAC) respectively.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Assessment Findings Report&#039;&#039; means the final written assessment results by the third-party or government assessment team. The Assessment Findings Report is submitted to the OSC and to the DoD via CMMC eMASS. (CMMC-custom term)&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Assessment objective&#039;&#039; means a set of determination statements that, taken together, expresses the desired outcome for the assessment of a security requirement. Successful implementation of the corresponding CMMC security requirement requires meeting all applicable assessment objectives defined in NIST SP 800-171A Jun2018 (incorporated by reference, see § 170.2) or NIST SP 800-172A Mar2022 (incorporated by reference, see § 170.2). (CMMC-custom term)&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Assessment Team&#039;&#039; means participants in the Level 2 certification assessment (CMMC Certified Assessors and CMMC Certified Professionals) or the Level 3 certification assessment (DCMA DIBCAC assessors). This does not include the OSC participants preparing for or participating in the assessment. (CMMC-custom term)&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Asset&#039;&#039; means an item of value to stakeholders. An asset may be tangible (&#039;&#039;e.g.&#039;&#039;, a physical item such as hardware, firmware, computing platform, network device, or other technology component) or intangible (&#039;&#039;e.g.&#039;&#039;, humans, data, information, software, capability, function, service, trademark, copyright, patent, intellectual property, image, or reputation). The value of an asset is determined by stakeholders in consideration of loss concerns across the entire system life cycle. Such concerns include but are not limited to business or mission concerns, as defined in NIST SP 800-160 V2R1 (incorporated by reference, see § 170.2).&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Asset Categories&#039;&#039; means a grouping of assets that process, store or transmit information of similar designation, or provide security protection to those assets. (CMMC-custom term)&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Authentication&#039;&#039; is defined in FIPS PUB 200 Mar2006 (incorporated by reference, see § 170.2).&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Authorized&#039;&#039; means an interim status during which a CMMC Ecosystem member (person or organization), having met all criteria for the specific role they perform other than the required ISO/IEC accreditations, may act in that role for a specified time as set forth in § 170.8 for the Accreditation Body and § 170.9 for C3PAOs. (CMMC-custom term)&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Capability&#039;&#039; means a combination of mutually reinforcing controls implemented by technical means, physical means, and procedural means. Such controls are typically selected to achieve a common information security or privacy purpose, as defined in NIST SP 800-37 R2 (incorporated by reference, see § 170.2).&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Cloud Service Provider (CSP) &#039;&#039;means an external company that provides cloud services based on cloud computing. Cloud computing is a model for enabling ubiquitous, convenient, on- demand network access to a shared pool of configurable computing resources (&#039;&#039;e.g.&#039;&#039;, networks, servers, storage, applications, and services) that can be rapidly provisioned and released with minimal management effort or service provider interaction. This definition is based on the definition for cloud computing in NIST SP 800-145 Sept2011. (CMMC-custom term)&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;CMMC Assessment and Certification Ecosystem&#039;&#039; means the people and organizations described in subpart C of this part. This term is sometimes shortened to CMMC Ecosystem. (CMMC-custom term)&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;CMMC Assessment Scope&#039;&#039; means the set of all assets in the OSA’s environment that will be assessed against CMMC security requirements. (CMMC-custom term)&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;CMMC Assessor and Instructor Certification Organization (CAICO) &#039;&#039;is defined in § 170.10 and means the organization responsible for training, testing, authorizing, certifying, and recertifying CMMC certified assessors, certified instructors, and certified professionals. (CMMC-custom term)&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;CMMC Instantiation of eMASS&#039;&#039; means a CMMC instance of the Enterprise Mission Assurance Support Service (eMASS), a government owned and operated system. (CMMC-custom term)&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;CMMC Security Requirements&#039;&#039; means the 15 Level 1 requirements listed in the 48 CFR 52.204-21(b)(1), the 110 Level 2 requirements from NIST SP 800-171 R2 (incorporated by reference, see § 170.2), and the 24 Level 3 requirements selected from NIST SP 800-172 Feb2021 (incorporated by reference, see § 170.2).&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;CMMC Status&#039;&#039; is the result of meeting or exceeding the minimum required score for the corresponding assessment. The CMMC Status of an OSA information system is officially stored in SPRS and additionally presented on a Certificate of CMMC Status, if the assessment was conducted by a C3PAO or DCMA DIBCAC. The potential CMMC Statuses are outlined in the paragraphs that follow. (CMMC-custom term)&lt;br /&gt;
&lt;br /&gt;
(i) &#039;&#039;Final Level 1 (Self) &#039;&#039;is defined in § 170.15(a)(1) and (c)(1). (CMMC-custom term)&lt;br /&gt;
&lt;br /&gt;
(ii) &#039;&#039;Conditional Level 2 (Self) &#039;&#039;is defined in § 170.16(a)(1)(ii). (CMMC- custom term) &lt;br /&gt;
&lt;br /&gt;
(iii) &#039;&#039;Final Level 2 (Self) &#039;&#039;is defined in § 170.16(a)(1)(iii). (CMMC-custom term)&lt;br /&gt;
&lt;br /&gt;
(iv) &#039;&#039;Conditional Level 2 (C3PAO) &#039;&#039;is defined in § 170.17(a)(1)(ii). (CMMC- custom term) &lt;br /&gt;
&lt;br /&gt;
(v) &#039;&#039;Final Level 2 (C3PAO) &#039;&#039;is defined in § 170.17(a)(1)(iii). (CMMC-custom term)&lt;br /&gt;
&lt;br /&gt;
(vi) &#039;&#039;Conditional Level 3 (DIBCAC) &#039;&#039;is defined in § 170.18(a)(1)(ii). (CMMC- custom term)&lt;br /&gt;
&lt;br /&gt;
(vii) &#039;&#039;Final Level 3 (DIBCAC) &#039;&#039;is defined in § 170.18(a)(1)(iii). (CMMC-custom term)&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;CMMC Status Date&#039;&#039; means the date that the CMMC Status results are submitted to SPRS or the CMMC instantiation of eMASS, as appropriate. The date of the Conditional CMMC Status will remain as the CMMC Status Date after a successful POA&amp;amp;M closeout. A new date is not set for a Final that follows a Conditional. (CMMC-custom term)&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;CMMC Third-Party Assessment Organization (C3PAO) &#039;&#039;means an organization that has been authorized or accredited by the Accreditation Body to conduct Level 2 certification assessments and has the roles and responsibilities identified in § 170.9. (CMMC-custom term)&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Contractor&#039;&#039; is defined in 48 CFR 3.502-1.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Contractor Risk Managed Assets&#039;&#039; are defined in table 3 to § 170.19(c)(1). (CMMC-custom term)&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Controlled Unclassified Information (CUI) &#039;&#039;is defined in 32 CFR 2002.4(h).&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Controlled Unclassified Information (CUI) Assets&#039;&#039; means assets that can process, store, or transmit CUI. (CMMC- custom term)&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;DCMA DIBCAC High Assessment&#039;&#039; means an assessment that is conducted by Government personnel in accordance with NIST SP 800-171A Jun2018 and leveraging specific guidance in the DoD Assessment Methodology that: &lt;br /&gt;
&lt;br /&gt;
(i) Consists of: (A) A review of a contractor’s Basic Assessment; &lt;br /&gt;
&lt;br /&gt;
(B) A thorough document review;&lt;br /&gt;
&lt;br /&gt;
(C) Verification, examination, and demonstration of a contractor’s system security plan to validate that NIST SP 800-171 R2 security requirements have been implemented as described in the contractor’s system security plan; and &lt;br /&gt;
&lt;br /&gt;
(D) Discussions with the contractor to obtain additional information or clarification, as needed; and &lt;br /&gt;
&lt;br /&gt;
(ii) Results in a confidence level of ‘‘High’’ in the resulting score. (Source: 48 CFR 252.204-7020).&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Defense Industrial Base (DIB) &#039;&#039;is defined in 32 CFR 236.2.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;DoD Assessment Methodology (DoDAM) &#039;&#039;documents a standard methodology that enables a strategic assessment of a contractor’s implementation of NIST SP 800-171 R2, a requirement for compliance with 48 CFR 252.204-7012. (Source: DoDAM Version 1.2.1)&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Enduring Exception&#039;&#039; means a special circumstance or system where remediation and full compliance with CMMC security requirements is not feasible. Examples include systems required to replicate the configuration of ‘fielded’ systems, medical devices, test equipment, OT, and IoT. No operational plan of action is required but the circumstance must be documented within a system security plan. Specialized Assets and GFE may be enduring exceptions. (CMMC-custom term)&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Enterprise&#039;&#039; means an organization with a defined mission/goal and a defined boundary, using information systems to execute that mission, and with responsibility for managing its own risks and performance. An enterprise may consist of all or some of the following business aspects: acquisition, program management, financial management (&#039;&#039;e.g.&#039;&#039;, budgets), human resources, security, and information systems, information and mission management, as defined in NIST SP 800-53 R5 (incorporated by reference, see § 170.2).&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;External Service Provider (ESP) &#039;&#039;means external people, technology, or facilities that an organization utilizes for provision and management of IT and/or cybersecurity services on behalf of the organization. In the CMMC Program, CUI or Security Protection Data (&#039;&#039;e.g.&#039;&#039;, log data, configuration data), must be processed, stored, or transmitted on the ESP assets to be considered an ESP. (CMMC-custom term)&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Federal Contract Information (FCI) &#039;&#039;is defined in 48 CFR 4.1901.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Government Furnished Equipment (GFE) &#039;&#039;has the same meaning as ‘‘government-furnished property’’ as defined in 48 CFR 45.101.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Industrial Control Systems (ICS) &#039;&#039;means a general term that encompasses several types of control systems, including supervisory control and data acquisition (SCADA) systems, distributed control systems (DCS), and other control system configurations that are often found in the industrial sectors and critical infrastructures, such as Programmable Logic Controllers (PLC). An ICS consists of combinations of control components (&#039;&#039;e.g.&#039;&#039;, electrical, mechanical, hydraulic, pneumatic) that act together to achieve an industrial objective (&#039;&#039;e.g.&#039;&#039;, manufacturing, transportation of matter or energy), as defined in NIST SP 800-82r3 (incorporated by reference, see § 170.2).&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Information System (IS) &#039;&#039;is defined in NIST SP 800-171 R2 (incorporated by reference, see § 170.2).&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Internet of Things (IoT) &#039;&#039;means the network of devices that contain the hardware, software, firmware, and actuators which allow the devices to connect, interact, and freely exchange data and information, as defined in NIST SP 800-172A Mar2022 (incorporated by reference, see § 170.2).&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Operational plan of action&#039;&#039; as used in security requirement CA.L2-3.12.2, means the formal artifact which identifies temporary vulnerabilities and temporary deficiencies (&#039;&#039;e.g.&#039;&#039;, necessary information system updates, patches, or reconfiguration as threats evolve) in implementation of requirements and documents how they will be mitigated, corrected, or eliminated. The OSA defines the format (&#039;&#039;e.g.&#039;&#039;, document, spreadsheet, database) and specific content of its operational plan of action. An operational plan of action does not identify a timeline for remediation and is not the same as a POA&amp;amp;M, which is associated with an assessment for remediation of deficiencies that must be completed within 180 days. (CMMC- custom term)&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Operational Technology (OT) &#039;&#039;means programmable systems or devices that interact with the physical environment (or manage devices that interact with the physical environment). These systems or devices detect or cause a direct change through the monitoring or control of devices, processes, and events. Examples include industrial control systems, building management systems, fire control systems, and physical access control mechanisms, as defined in NIST SP 800-160 V2R1 (incorporated by reference, see § 170.2).&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Organization-defined&#039;&#039; means as determined by the OSA except as defined in the case of Organization- Defined Parameter (ODP). (CMMC- custom term)&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Organization-Defined Parameters (ODPs) &#039;&#039;means selected enhanced security requirements contain selection and assignment operations to give organizations flexibility in defining variable parts of those requirements, as defined in NIST SP 800-172A Mar2022 (incorporated by reference, see § 170.2).&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Note 1 to ODPs:&#039;&#039; The organization defining the parameters is the DoD.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Organization Seeking Assessment (OSA) &#039;&#039;means the entity seeking to undergo a self-assessment or certification assessment for a given information system for the purposes of achieving and maintaining any CMMC Status. The term OSA includes all Organizations Seeking Certification (OSCs). (CMMC-custom term)&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Organization Seeking Certification (OSC) &#039;&#039;means the entity seeking to undergo a certification assessment for a given information system for the purposes of achieving and maintaining the CMMC Status of Level 2 (C3PAO) or Level 3 (DIBCAC). An OSC is also an OSA. (CMMC-custom term)&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Out-of-Scope Assets&#039;&#039; means assets that cannot process, store, or transmit CUI because they are physically or logically separated from information systems that do process, store, or transmit CUI, or are inherently unable to do so; except for assets that provide security protection for a CUI asset (see the definition for &#039;&#039;Security Protection Assets&#039;&#039;). (CMMC- custom term)&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Periodically&#039;&#039; means occurring at a regular interval as determined by the OSA that may not exceed one year. (CMMC-custom term)&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Personally Identifiable Information&#039;&#039; means information that can be used to distinguish or trace an individual’s identity, either alone or when combined with other information that is linked or linkable to a specific individual, as defined in NIST SP 800-53 R5 (incorporated by reference, see § 170.2).&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Plan of Action and Milestones (POA&amp;amp;M) &#039;&#039;means a document that identifies tasks needing to be accomplished. It details resources required to accomplish the elements of the plan, any milestones in meeting the tasks, and scheduled completion dates for the milestones, as defined in NIST SP 800-115 Sept2008 (incorporated by reference, see § 170.2).&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Prime Contractor&#039;&#039; is defined in 48 CFR 3.502-1.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Process, store, or transmit&#039;&#039; means data can be used by an asset (&#039;&#039;e.g.&#039;&#039;, accessed, entered, edited, generated, manipulated, or printed); data is inactive or at rest on an asset (&#039;&#039;e.g.&#039;&#039;, located on electronic media, in system component memory, or in physical format such as paper documents); or data is being transferred from one asset to another asset (&#039;&#039;e.g.&#039;&#039;, data in transit using physical or digital transport methods). (CMMC-custom term)&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Restricted Information Systems&#039;&#039; means systems (and associated IT components comprising the system) that are configured based on government requirements (&#039;&#039;e.g.&#039;&#039;, connected to something that was required to support a functional requirement) and are used to support a contract (&#039;&#039;e.g.&#039;&#039;, fielded systems, obsolete systems, and product deliverable replicas). (CMMC-custom term)&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Risk&#039;&#039; means a measure of the extent to which an entity is threatened by a potential circumstance or event, and is typically a function of:&lt;br /&gt;
&lt;br /&gt;
(i) The adverse impacts that would arise if the circumstance or event occurs; and&lt;br /&gt;
&lt;br /&gt;
(ii) The likelihood of occurrence, as defined in NIST SP 800-53 R5 (incorporated by reference, see § 170.2).&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Risk Assessment&#039;&#039; means the process of identifying risks to organizational operations (including mission, functions, image, reputation), organizational assets, individuals, other organizations, and the Nation, resulting from the operation of a system. Risk Assessment is part of risk management, incorporates threat and vulnerability analyses, and considers mitigations provided by security controls planned or in place. Synonymous with risk analysis, as defined in NIST SP 800-39 Mar2011 (incorporated by reference, see § 170.2).&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Security Protection Assets (SPA) &#039;&#039;means assets providing security functions or capabilities for the OSA’s CMMC Assessment Scope. (CMMC- custom term) &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Security Protection Data (SPD) &#039;&#039;means data stored or processed by Security Protection Assets (SPA) that are used to protect an OSC’s assessed environment. SPD is security relevant information and includes but is not limited to: configuration data required to operate an SPA, log files generated by or ingested by an SPA, data related to the configuration or vulnerability status of in-scope assets, and passwords that grant access to the in-scope environment. (CMMC-custom term)&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Specialized Assets&#039;&#039; means types of assets considered specialized assets for CMMC: Government Furnished Equipment, Internet of Things (IoT) or Industrial Internet of Things (IIoT), Operational Technology (OT), Restricted Information Systems, and Test Equipment. (CMMC-custom term)&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Subcontractor&#039;&#039; is defined in 48 CFR 3.502-1.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Supervisory Control and Data Acquisition (SCADA) &#039;&#039;means a generic name for a computerized system that is capable of gathering and processing data and applying operational controls over long distances. Typical uses include power transmission and distribution and pipeline systems. SCADA was designed for the unique communication challenges (&#039;&#039;e.g.&#039;&#039;, delays, data integrity) posed by the various media that must be used, such as phone lines, microwave, and satellite. Usually shared rather than dedicated, as defined in NIST SP 800- 82r3 (incorporated by reference, see § 170.2).&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;System Security Plan (SSP) &#039;&#039;means the formal document that provides an overview of the security requirements for an information system or an information security program and describes the security controls in place or planned for meeting those requirements. The system security plan describes the system components that are included within the system, the environment in which the system operates, how the security requirements are implemented, and the relationships with or connections to other systems, as defined in NIST SP 800-53 R5 (incorporated by reference, see § 170.2).&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Temporary deficiency&#039;&#039; means a condition where remediation of a discovered deficiency is feasible, and a known fix is available or is in process. The deficiency must be documented in an operational plan of action. A temporary deficiency is not based on an ‘in progress’ initial implementation of a CMMC security requirement but arises after implementation. A temporary deficiency may apply during the initial implementation of a security requirement if, during roll-out, specific issues with a very limited subset of equipment is discovered that must be separately addressed. There is no standard duration for which a temporary deficiency may be active. For example, FIPS-validated cryptography that requires a patch and the patched version is no longer the validated version may be a temporary deficiency. (CMMC-custom term)&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Test Equipment&#039;&#039; means hardware and/ or associated IT components used in the testing of products, system components, and contract deliverables. (CMMC- custom term)&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;User&#039;&#039; means an individual, or (system) process acting on behalf of an individual, authorized to access a system, as defined in NIST SP 800-53 R5 (incorporated by reference, see § 170.2).&lt;br /&gt;
&lt;br /&gt;
=== § 170.5 Policy. ===&lt;br /&gt;
&lt;br /&gt;
(a) Protection of FCI and CUI on contractor information systems is of paramount importance to the DoD and can directly impact its ability to successfully conduct essential missions and functions. It is DoD policy that defense contractors and subcontractors shall be required to safeguard FCI and CUI that is processed, stored, or transmitted on contractor information systems by applying specified security requirements. In addition, defense contractors and subcontractors may be required to implement additional safeguards defined in NIST SP 800-172 Feb2021 (incorporated by reference, see § 170.2), implementing DoD specified parameters to meet CMMC Level 3 security requirements (see table 1 to § 170.14(c)(4)). These additional requirements are necessary to protect CUI being processed, stored, or transmitted in contractor information systems, when designated by a requirement for CMMC Status of Level 3 (DIBCAC) as defined by a DoD program manager or requiring activity. In general, the Department will identify a requirement for a CMMC Status of Level 3 (DIBCAC) for solicitations and resulting contracts supporting its most critical programs and technologies.&lt;br /&gt;
&lt;br /&gt;
(b) Program managers and requiring activities are responsible for identifying the CMMC Status that will apply to a procurement. Selection of the applicable CMMC Status will be based on factors including but not limited to:&lt;br /&gt;
&lt;br /&gt;
(1) Criticality of the associated mission capability;&lt;br /&gt;
&lt;br /&gt;
(2) Type of acquisition program or technology;&lt;br /&gt;
&lt;br /&gt;
(3) Threat of loss of the FCI or CUI to be shared or generated in relation to the effort;&lt;br /&gt;
&lt;br /&gt;
(4) Impacts from exploitation of information security deficiencies; and&lt;br /&gt;
&lt;br /&gt;
(5) Other relevant policies and factors, including Milestone Decision Authority guidance.&lt;br /&gt;
&lt;br /&gt;
(c) In accordance with the implementation plan described in § 170.3, CMMC Program requirements will apply to new DoD solicitations and contracts, and shall flow down to subcontractors who will process, store, or transmit FCI or CUI in performance of the subcontract, as described in § 170.23.&lt;br /&gt;
&lt;br /&gt;
(d) In very limited circumstances, and in accordance with all applicable policies, procedures, and requirements, a Service Acquisition Executive or Component Acquisition Executive in the DoD, or as delegated, may elect to waive inclusion of CMMC Program requirements in a solicitation or contract. In such cases, contractors and subcontractors will remain obligated to comply with all applicable cybersecurity and information security requirements.&lt;br /&gt;
&lt;br /&gt;
(e) The CMMC Program does not alter any separately applicable requirements to protect FCI or CUI, including those requirements in accordance with 48 CFR 52.204-21&#039;&#039;, Basic Safeguarding of Covered Contractor Information Systems&#039;&#039;, or covered defense information in accordance with 48 CFR 252.204- 7012&#039;&#039;, Safeguarding Covered Defense Information and Cyber Incident Reporting&#039;&#039;, or any other applicable information protection requirements. The CMMC Program provides a means of verifying implementation of the security requirements set forth in 48 CFR 52.204-21, NIST SP 800-171 R2, and NIST SP 800-172 Feb2021, as applicable.&lt;br /&gt;
&lt;br /&gt;
== Subpart B - Government Roles and Responsibilities. ==&lt;br /&gt;
=== § 170.6 CMMC PMO. ===&lt;br /&gt;
&lt;br /&gt;
(a) The Office of the Department of Defense Chief Information Officer (DoD CIO) Office of the Deputy CIO for Cybersecurity (DoD CIO(CS)) provides oversight of the CMMC Program and is responsible for establishing CMMC assessment, accreditation, and training requirements as well as developing and updating CMMC Program policies and implementing guidance.&lt;br /&gt;
&lt;br /&gt;
(b) The CMMC PMO is responsible for monitoring the CMMC AB’s performance of roles assigned in this rule and acting as necessary to address problems pertaining to effective performance.&lt;br /&gt;
&lt;br /&gt;
(c) The CMMC PMO retains, on behalf of the DoD CIO(CS), the prerogative to review decisions of the CMMC Accreditation Body as part of its oversight of the CMMC program and evaluate any alleged conflicts of interest purported to influence the CMMC Accreditation Body’s objectivity.&lt;br /&gt;
&lt;br /&gt;
(d) The CMMC PMO is responsible for sponsoring necessary DCSA activities including FOCI risk assessment and Tier 3 security background investigations for the CMMC Ecosystem members as specified in §§ 170.8(b)(4) and (5), 170.9(b)(3) through (5), 170.11(b)(3) and (4), and 170.13(b)(3) and (4).&lt;br /&gt;
&lt;br /&gt;
(e) The CMMC PMO is responsible for investigating and acting upon indications that an active CMMC Status has been called into question. Indications that may trigger investigative evaluations include, but are not limited to, reports from the CMMC Accreditation Body, a C3PAO, or anyone knowledgeable of the security processes and activities of the OSA. Investigative evaluations include, but are not limited to, reviewing pertinent assessment information, and exercising the right to conduct a DCMA DIBCAC assessment of the OSA, as provided for under the 48 CFR 252.204-7020.&lt;br /&gt;
&lt;br /&gt;
(f) If a subsequent DCMA DIBCAC assessment shows that adherence to the provisions of this rule and the required CMMC Status have not been achieved or maintained, the DIBCAC results will take precedence over any pre-existing CMMC Status recorded in SPRS, or its successor capability. The DoD will update SPRS to reflect that the OSA is out of compliance and does not meet DoD CMMC requirements. If the OSA is working on an active contract requiring CMMC compliance, then standard contractual remedies will apply.&lt;br /&gt;
&lt;br /&gt;
=== § 170.7 DCMA DIBCAC. ===&lt;br /&gt;
&lt;br /&gt;
(a) DCMA DIBCAC assessors in support of the CMMC Program will:&lt;br /&gt;
&lt;br /&gt;
(1) Complete CMMC Level 2 and Level 3 training.&lt;br /&gt;
&lt;br /&gt;
(2) Conduct Level 3 certification assessments and upload assessment results into the CMMC instantiation of eMASS, or its successor capability.&lt;br /&gt;
&lt;br /&gt;
(3) Issue Certificates of CMMC Status resulting from Level 3 certification assessments.&lt;br /&gt;
&lt;br /&gt;
(4) Conduct Level 2 certification assessments of the Accreditation Body and prospective C3PAOs’ information systems that process, store, and/or transmit CUI.&lt;br /&gt;
&lt;br /&gt;
(5) Create and maintain a process for assessors to collect the list of assessment artifacts to include artifact names, their return value of the hashing algorithm, the hashing algorithm used, and upload that data into the CMMC instantiation of eMASS.&lt;br /&gt;
&lt;br /&gt;
(6) As authorized and in accordance with all legal requirements, enter and track, OSC appeals and updated results arising from Level 3 certification assessment activities into the CMMC instantiation of eMASS.&lt;br /&gt;
&lt;br /&gt;
(7) Retain all records in accordance with DCMA-MAN 4501-04.&lt;br /&gt;
&lt;br /&gt;
(8) Conduct an assessment of the OSA, when requested by the CMMC PMO per §§ 170.6(e) and (f), as provided for under the 48 CFR 252.204-7019 and 48 CFR 252.204-7020.&lt;br /&gt;
&lt;br /&gt;
(9) Identify assessments that meet the criteria in § 170.20 and verify that SPRS accurately reflects the CMMC Status.&lt;br /&gt;
&lt;br /&gt;
(b) An OSC, the CMMC AB, or a C3PAO may appeal the outcome of its DCMA DIBCAC conducted assessment within 21 days by submitting a written basis for appeal with the requirements in question for DCMA DIBCAC consideration. Appeals may be submitted for review by visiting &#039;&#039;www.dcma.mil/DIBCAC&#039;&#039; for contact information, and a DCMA DIBCAC Quality Assurance Review Team will provide a written response or request additional supporting documentation.&lt;br /&gt;
&lt;br /&gt;
== Subpart C - CMMC Assessment and Certification Ecosystem. ==&lt;br /&gt;
=== § 170.8 Accreditation Body. ===&lt;br /&gt;
&lt;br /&gt;
(a)&#039;&#039;Roles and responsibilities&#039;&#039;. The Accreditation Body is responsible for authorizing and ensuring the accreditation of CMMC Third-Party Assessment Organizations (C3PAOs) in accordance with ISO/IEC 17020:2012(E) (incorporated by reference, see § 170.2) and all applicable authorization and accreditation requirements set forth. The Accreditation Body is responsible for establishing the C3PAO authorization requirements and the C3PAO Accreditation Scheme and submitting both for approval by the CMMC PMO. At any given point in time, there will be only one Accreditation Body for the DoD CMMC Program.&lt;br /&gt;
&lt;br /&gt;
(b)&#039;&#039;Requirements&#039;&#039;. The CMMC Accreditation Body shall:&lt;br /&gt;
&lt;br /&gt;
(1) Be US-based and be and remain a member in good standing of the Inter- American Accreditation Cooperation (IAAC) and become an International Laboratory Accreditation Cooperation (ILAC) Mutual Recognition Arrangement (MRA) signatory, with a signatory status scope of ISO/IEC 17020:2012(E) (incorporated by reference, see § 170.2).&lt;br /&gt;
&lt;br /&gt;
(2) Be and remain a member in good standing of the International Accreditation Forum (IAF) with mutual recognition arrangement signatory status scope of ISO/IEC 17024:2012(E) (incorporated by reference, see § 170.2).&lt;br /&gt;
&lt;br /&gt;
(3) Achieve and maintain full compliance with ISO/IEC 17011:2017(E) (incorporated by reference, see § 170.2) and complete a peer assessment by other ILAC signatories for competence in accrediting conformity assessment bodies to ISO/IEC 17020:2012(E) (incorporated by reference, see § 170.2), both within 24 months of DoD approval.&lt;br /&gt;
&lt;br /&gt;
(i) Prior to achieving full compliance as set forth in this paragraph (b)(3), the Accreditation Body shall:&lt;br /&gt;
&lt;br /&gt;
(A) Authorize C3PAOs who meet all requirements set forth in § 170.9 as well as administrative requirements as determined by the Accreditation Body to conduct Level 2 certification assessments and issue Certificates of CMMC Status to OSCs based on the assessment results.&lt;br /&gt;
&lt;br /&gt;
(B) Require all C3PAOs to achieve and maintain the ISO/IEC 17020:2012(E) (incorporated by reference, see § 170.2) requirements within 27 months of authorization.&lt;br /&gt;
&lt;br /&gt;
(ii) The Accreditation Body shall accredit C3PAOs, in accordance with ISO/IEC 17020:2012(E) (incorporated by reference, see § 170.2), who meet all requirements set forth in § 170.9 to conduct Level 2 certification assessments and issue Certificates of CMMC Status to OSCs based on the results.&lt;br /&gt;
&lt;br /&gt;
(4) Ensure that the Accreditation Body’s Board of Directors, professional staff, Information Technology (IT) staff, accreditation staff, and independent CMMC Certified Assessor staff complete a Tier 3 background investigation resulting in a determination of national security eligibility. This Tier 3 background investigation will not result in a security clearance and is not being executed for the purpose of government employment. The Tier 3 background investigation is initiated using the Standard Form (SF) 86 (&#039;&#039;www.gsa.gov/reference/forms/questionnaire-for-national-security-positions&#039;&#039;) and ]submitted by DoD CIO Security to Washington Headquarters Services (WHS) for coordination for processing by the Defense Counterintelligence and Security Agency (DCSA). These positions are designated as non-critical sensitive with a risk designation of ‘‘Moderate Risk’’ in accordance with 5 CFR 1400.201(b) and (d) and the investigative requirements of 5 CFR 731.106(c)(2).&lt;br /&gt;
&lt;br /&gt;
(5) Comply with Foreign Ownership, Control or Influence (FOCI) by:&lt;br /&gt;
&lt;br /&gt;
(i) Completing the Standard Form (SF) 328 (&#039;&#039;www.gsa.gov/reference/forms/ certificate-pertaining-to-foreign- interests&#039;&#039;), ]&#039;&#039;Certificate Pertaining to Foreign Interests&#039;&#039;, and submit it directly to Defense Counterintelligence and Security Agency (DCSA) and undergo a National Security Review with regards to the protection of controlled unclassified information based on the factors identified in 32 CFR 117.11(b) using the procedures outlined in 32 CFR 117.11(c). The Accreditation Body must receive a non-disqualifying eligibility determination by the CMMC PMO to be recognized by the Department of Defense.&lt;br /&gt;
&lt;br /&gt;
(ii) Reporting any change to the information provided on its SF 328 by resubmitting the SF 328 to DCSA within 15 business days of the change being effective. A disqualifying eligibility determination, based on the results of the change, will result in the Accreditation Body losing its authorization or accreditation under the CMMC Program.&lt;br /&gt;
&lt;br /&gt;
(iii) Identifying all prospective C3PAOs to the CMMC PMO. The CMMC PMO will sponsor the prospective C3PAO for a FOCI risk assessment conducted by the DCSA using the SF 328 as part of the authorization and accreditation processes.&lt;br /&gt;
&lt;br /&gt;
(iv) Notifying prospective C3PAOs of the CMMC PMO’s eligibility determination resulting from the FOCI risk assessment.&lt;br /&gt;
&lt;br /&gt;
(6) Obtain a Level 2 certification assessment in accordance with the procedures specified in § 170.17(a)(1) and (c). This assessment, conducted by DCMA DIBCAC, shall meet all requirements for a Final Level 2 (C3PAO) but will not result in a CMMC Status of Level 2 (C3PAO). The Level 2 certification assessment process must be performed every three years.&lt;br /&gt;
&lt;br /&gt;
(7) Provide all documentation and records in English.&lt;br /&gt;
&lt;br /&gt;
(8) Establish, maintain, and manage an up-to-date list of authorized and accredited C3PAOs on a single publicly accessible website and provide the list of these entities and their status to the DoD through submission in the CMMC instantiation of eMASS.&lt;br /&gt;
&lt;br /&gt;
(9) Provide the CMMC PMO with current data on C3PAOs, including authorization and accreditation records and status in the CMMC instantiation of eMASS. This data shall include the dates associated with the authorization and accreditation of each C3PAO.&lt;br /&gt;
&lt;br /&gt;
(10) Provide the DoD with information about aggregate statistics pertaining to operations of the CMMC Ecosystem to include the authorization and accreditation status of C3PAOs or other information as requested.&lt;br /&gt;
&lt;br /&gt;
(11) Provide inputs for assessor supplemental guidance to the CMMC PMO. Participate and support coordination of these and other inputs through DoD-led Working Groups.&lt;br /&gt;
&lt;br /&gt;
(12) Ensure that all information about individuals is encrypted and protected in all Accreditation Body information systems and databases.&lt;br /&gt;
&lt;br /&gt;
(13) Provide all plans that are related to potential sources of revenue, to include but not limited to: fees, licensing, processes, membership, and/ or partnerships to the Department’s CMMC PMO.&lt;br /&gt;
&lt;br /&gt;
(14) Ensure that the CMMC Assessors and Instructors Certification Organization (CAICO) is compliant with ISO/IEC 17024:2012(E)&lt;br /&gt;
&lt;br /&gt;
(15) Ensure all training products, instruction, and testing materials are of high quality and subject to CAICO quality control policies and procedures, to include technical accuracy and alignment with all applicable legal, regulatory, and policy requirements.&lt;br /&gt;
&lt;br /&gt;
(16) Develop and maintain an internal appeals process, as required by ISO/IEC 17020:2017(E), and render a final decision on all elevated appeals.&lt;br /&gt;
&lt;br /&gt;
(17) Develop and maintain a comprehensive plan and schedule to comply with all ISO/IEC 17011:2017(E), and DoD requirements for Conflict of Interest, Code of Professional Conduct, and Ethics policies as set forth in the DoD contract. All policies shall apply to the Accreditation Body, and other individuals, entities, and groups within the CMMC Ecosystem who provide Level 2 certification assessments, CMMC instruction, CMMC training materials, or Certificates of CMMC Status on behalf of the Accreditation Body. All policies in this section must be approved by the CMMC PMO prior to effectivity in accordance with the following requirements.&lt;br /&gt;
&lt;br /&gt;
(i) &#039;&#039;Conflict of Interest (CoI) policy.&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
The CoI policy shall: &lt;br /&gt;
&lt;br /&gt;
(A) Include a detailed risk mitigation plan for all potential conflicts of interest that may pose a risk to compliance with ISO/IEC 17011:2017(E).&lt;br /&gt;
&lt;br /&gt;
(B) Require employees, Board directors, and members of any accreditation committees or appeals adjudication committees to disclose to the CMMC PMO, in writing, as soon as it is known or reasonably should be known, any actual, potential, or perceived conflict of interest with sufficient detail to allow for assessment.&lt;br /&gt;
&lt;br /&gt;
(C) Require employees, Board directors, and members of any accreditation committees or appeals adjudication committees who leave the board or organization to enter a ‘‘cooling off period’’ of one (1) year whereby they are prohibited from working with the Accreditation Body or participating in any and all CMMC activities described in Subpart C.&lt;br /&gt;
&lt;br /&gt;
(D) Require CMMC Ecosystem members to actively avoid participating in any activity, practice, or transaction that could result in an actual or perceived conflict of interest.&lt;br /&gt;
&lt;br /&gt;
(E) Require CMMC Ecosystem members to disclose to Accreditation Body leadership, in writing, any actual or potential conflict of interest as soon as it is known, or reasonably should be known.&lt;br /&gt;
&lt;br /&gt;
(ii) &#039;&#039;Code of Professional Conduct (CoPC) policy.&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
The CoPC policy shall: &lt;br /&gt;
&lt;br /&gt;
(A) Describe the performance standards by which the members of the CMMC Ecosystem will be held accountable and the procedures for addressing violations of those performance standards.&lt;br /&gt;
&lt;br /&gt;
(B) Require the Accreditation Body to investigate and resolve any potential violations that are reported or are identified by the DoD.&lt;br /&gt;
&lt;br /&gt;
(C) Require the Accreditation Body to inform the DoD in writing of new investigations within 72 hours.&lt;br /&gt;
&lt;br /&gt;
(D) Require the Accreditation Body to report to the DoD in writing the outcome of completed investigations within 15 business days.&lt;br /&gt;
&lt;br /&gt;
(E) Require CMMC Ecosystem members to represent themselves and their companies accurately; to include not misrepresenting any professional credentials or status, including CMMC authorization or CMMC Status, nor exaggerating the services that they or their company are capable or authorized to deliver.&lt;br /&gt;
&lt;br /&gt;
(F) Require CMMC Ecosystem members to be honest and factual in all CMMC-related activities with colleagues, clients, trainees, and others with whom they interact.&lt;br /&gt;
&lt;br /&gt;
(G) Prohibit CMMC Ecosystem members from participating in the Level 2 certification assessment process for an assessment in which they previously served as a consultant to prepare the organization for any CMMC assessment within 3 years.&lt;br /&gt;
&lt;br /&gt;
(H) Require CMMC Ecosystem members to maintain the confidentiality of customer and government data to preclude unauthorized disclosure.&lt;br /&gt;
&lt;br /&gt;
(I) Require CMMC Ecosystem members to report results and data from Level 2 certification assessments and training objectively, completely, clearly, and accurately.&lt;br /&gt;
&lt;br /&gt;
(J) Prohibit CMMC Ecosystem members from cheating, assisting another in cheating, or allowing cheating on CMMC examinations.&lt;br /&gt;
&lt;br /&gt;
(K) Require CMMC Ecosystem members to utilize official training content developed by a CMMC training organization approved by the CAICO in all CMMC certification courses.&lt;br /&gt;
&lt;br /&gt;
(iii) &#039;&#039;Ethics policy.&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
The Ethics policy shall:&lt;br /&gt;
&lt;br /&gt;
(A) Require CMMC Ecosystem members to report to the Accreditation Body within 30 days of convictions, guilty pleas, or no contest pleas to crimes of fraud, larceny, embezzlement, misappropriation of funds, misrepresentation, perjury, false swearing, conspiracy to conceal, or a similar offense in any legal proceeding, civil or criminal, whether or not in connection with activities that relate to carrying out their role in the CMMC Ecosystem.&lt;br /&gt;
&lt;br /&gt;
(B) Prohibit harassment or discrimination by CMMC Ecosystem members in all interactions with individuals whom they encounter in connection with their roles in the CMMC Ecosystem.&lt;br /&gt;
&lt;br /&gt;
(C) Require CMMC Ecosystem members to have and maintain a satisfactory record of integrity and business ethics.&lt;br /&gt;
&lt;br /&gt;
=== § 170.9 CMMC Third-Party Assessment Organizations (C3PAOs). ===&lt;br /&gt;
&lt;br /&gt;
(a)&#039;&#039;Roles and responsibilities&#039;&#039;. C3PAOs are organizations that are responsible for conducting Level 2 certification assessments and issuing Certificates of CMMC Status to OSCs based on the results. C3PAOs must be accredited or authorized by the Accreditation Body in accordance with the requirements set forth.&lt;br /&gt;
&lt;br /&gt;
(b)&#039;&#039;Requirements&#039;&#039;. C3PAOs shall:&lt;br /&gt;
&lt;br /&gt;
(1) Obtain authorization or accreditation from the Accreditation Body in accordance with § 170.8(b)(3)(i) and (ii).&lt;br /&gt;
&lt;br /&gt;
(2) Comply with the Accreditation Body policies for Conflict of Interest, Code of Professional Conduct, and Ethics set forth in § 170.8(b)(17); and achieve and maintain compliance with ISO/IEC 17020:2012(E) (incorporated by reference, see § 170.2) within 27 months of authorization.&lt;br /&gt;
&lt;br /&gt;
(3) Require all C3PAO company personnel participating in the Level 2 certification assessment process to complete a Tier 3 background investigation resulting in a determination of national security eligibility. This includes the CMMC Assessment Team and the quality assurance individual. This Tier 3 background investigation will not result in a security clearance and is not being executed for the purpose of government employment. The Tier 3 background investigation is initiated using the Standard Form (SF) 86 (&#039;&#039;www.gsa.gov/ reference/forms/questionnaire-for-national-security-positions&#039;&#039;). These ]positions are designated as non-critical sensitive with a risk designation of ‘‘Moderate Risk’’ in accordance with 5 CFR 1400.201(b) and (d) and the investigative requirements of 5 CFR 731.106(c)(2).&lt;br /&gt;
&lt;br /&gt;
(4) Require all C3PAO company personnel participating in the Level 2 certification assessment process who are not eligible to obtain a Tier 3 background investigation to meet the equivalent of a favorably adjudicated Tier 3 background investigation. DoD will determine the Tier 3 background investigation equivalence for use with the CMMC Program only.&lt;br /&gt;
&lt;br /&gt;
(5) Comply with Foreign Ownership, Control or Influence (FOCI) by:&lt;br /&gt;
&lt;br /&gt;
(i) Completing and submitting Standard Form (SF) 328 (&#039;&#039;www.gsa.gov/ reference/forms/certificate-pertaining-to-foreign-interests&#039;&#039;), Certificate Pertaining to Foreign Interests&#039;&#039;, upon request from DCSA and undergo a National Security Review with regards to the protection of controlled unclassified information based on the factors identified in 32 CFR 117.11(b) using the procedures outlined in 32 CFR 117.11(c).&lt;br /&gt;
&lt;br /&gt;
(ii) Receiving a non-disqualifying eligibility determination from the CMMC PMO resulting from the FOCI risk assessment in order to proceed to a DCMA DIBCAC CMMC Level 2 assessment, as part of the authorization and accreditation process set forth in paragraph (b)(6) of this section.&lt;br /&gt;
&lt;br /&gt;
(iii) Reporting any change to the information provided on its SF 328 by resubmitting the SF 328 to DCSA within 15 business days of the change being effective. A disqualifying eligibility determination, based on the results of the change, will result in the C3PAO losing its authorization or accreditation.&lt;br /&gt;
&lt;br /&gt;
(6) Undergo a Level 2 certification assessment meeting all requirements for a Final Level 2 (C3PAO) in accordance with the procedures specified in § 170.17(a)(1) and (c), with the following exceptions:&lt;br /&gt;
&lt;br /&gt;
(i) The assessment will be conducted by DCMA DIBCAC.&lt;br /&gt;
&lt;br /&gt;
(ii) The assessment will not result in a CMMC Status of Level 2 (C3PAO) nor receive a Certificate of CMMC Status.&lt;br /&gt;
&lt;br /&gt;
(7) Provide all documentation and records in English.&lt;br /&gt;
&lt;br /&gt;
(8) Submit pre-assessment and planning material, final assessment reports, and CMMC certificates of assessment into the CMMC instantiation of eMASS.&lt;br /&gt;
&lt;br /&gt;
(9) Unless disposition is otherwise authorized by the CMMC PMO, maintain all assessment related records for a period of six (6) years. Such records include any materials generated by the C3PAO in the course of an assessment, any working papers generated from Level 2 certification assessments; and materials relating to monitoring, education, training, technical knowledge, skills, experience, and authorization of all personnel involved in assessment activities; contractual agreements with OSCs; and organizations for whom consulting services were provided.&lt;br /&gt;
&lt;br /&gt;
(10) Provide any requested audit information, including any out-of-cycle from ISO/IEC 17020:2012(E) requirements, to the Accreditation Body.&lt;br /&gt;
&lt;br /&gt;
(11) Ensure that all personally identifiable information (PII) is encrypted and protected in all C3PAO information systems and databases.&lt;br /&gt;
&lt;br /&gt;
(12) Meet the requirements for Assessment Team composition. An Assessment Team must include at least two people: a Lead CCA, as defined in § 170.11(b)(10), and at least one other CCA. Additional CCAs and CCPs may also participate on an Assessment Team.&lt;br /&gt;
&lt;br /&gt;
(13) Implement a quality assurance function that ensures the accuracy and completeness of assessment data prior to upload into the CMMC instantiation of eMASS. Any individual fulfilling the quality assurance function must be a CCA and cannot be a member of an Assessment Team for which they are performing a quality assurance role. A quality assurance individual shall manage the C3PAO’s quality assurance reviews as defined in paragraph (b)(14) of this section and the appeals process as required by paragraphs (b)(19) and (20) of this section and in accordance with ISO/IEC 17020:2012(E) (incorporated by reference, see § 170.2) and ISO/IEC 17011:2017(E) (incorporated by reference, see § 170.2).&lt;br /&gt;
&lt;br /&gt;
(14) Conduct quality assurance reviews for each assessment, including observations of the Assessment Team’s conduct and management of CMMC assessment processes.&lt;br /&gt;
&lt;br /&gt;
(15) Ensure that all Level 2 certification assessment activities are performed on the information system within the CMMC Assessment Scope.&lt;br /&gt;
&lt;br /&gt;
(16) Maintain all facilities, personnel, and equipment involved in CMMC activities that are in scope of their Level 2 certification assessment and comply with all security requirements and procedures as prescribed by the Accreditation Body.&lt;br /&gt;
&lt;br /&gt;
(17) Ensure that all assessment data and information uploaded into the CMMC instantiation of eMASS assessment data is compliant with the CMMC assessment data standard as set forth in eMASS CMMC Assessment Import Templates on the CMMC eMASS website: &#039;&#039;https://cmmc.emass.apps.mil&#039;&#039;. This system is accessible only to authorized users.&lt;br /&gt;
&lt;br /&gt;
(18) Issue Certificates of CMMC Status to OSCs in accordance with the Level 2 certification assessment requirements set forth in § 170.17, that include, at a minimum, all industry CAGE codes associated with the information systems addressed by the CMMC Assessment Scope, the C3PAO name, assessment unique identifier, the OSC name, and the CMMC Status date and level.&lt;br /&gt;
&lt;br /&gt;
(19) Address all OSC appeals arising from Level 2 certification assessment activities. If the OSC or C3PAO is not satisfied with the result of the appeal either the OSC or the C3PAO can elevate the matter to the Accreditation Body for final determination.&lt;br /&gt;
&lt;br /&gt;
(20) Submit assessment appeals, review records, and decision results of assessment appeals to DoD using the CMMC instantiation of eMASS.&lt;br /&gt;
&lt;br /&gt;
=== § 170.10 CMMC Assessor and Instructor Certification Organization (CAICO). ===&lt;br /&gt;
&lt;br /&gt;
(a)&#039;&#039;Roles and responsibilities&#039;&#039;. The CAICO is responsible for training, testing, authorizing, certifying, and recertifying CMMC assessors, instructors, and related professionals. Only the CAICO may make decisions relating to examination certifications, including the granting, maintaining, recertifying, expanding, and reducing the scope of certification, and suspending or withdrawing certification in accordance with current ISO/IEC 17024:2012(E) (incorporated by reference, see § 170.2). At any given point in time, there will be only one CAICO for the DoD CMMC Program.&lt;br /&gt;
&lt;br /&gt;
(b)&#039;&#039;Requirements&#039;&#039;. The CAICO shall: (1) Comply with the Accreditation Body policies for Conflict of Interest, Code of Professional Conduct, and Ethics set forth in § 170.8(b)(17); and achieve and maintain ISO/IEC 17024(E) accreditation within 12 months of December 16, 2024.&lt;br /&gt;
&lt;br /&gt;
(2) Provide all documentation and records in English.&lt;br /&gt;
&lt;br /&gt;
(3) Train, test, and designate PIs in accordance with the requirements of this section. Train, test, certify, and recertify CCPs, CCAs, and CCIs in accordance with the requirements of this section.&lt;br /&gt;
&lt;br /&gt;
(4) Ensure the instructor and assessor certification examinations are certified under ISO/IEC 17024:2012(E) (incorporated by reference, see § 170.2), by a recognized US-based accreditor who is not a member of the CMMC Accreditation Body. The US-based accreditor must be a signatory to International Laboratory Accreditation Cooperation (ILAC) or relevant International Accreditation Forum (IAF) Mutual Recognition Arrangement (MRA) and must operate in accordance with ISO/IEC 17011:2017(E) (incorporated by reference, see § 170.2).&lt;br /&gt;
&lt;br /&gt;
(5) Establish quality control policies and procedures for the generation of training products, instruction, and testing materials.&lt;br /&gt;
&lt;br /&gt;
(6) Oversee development, administration, and management pertaining to the quality of training and examination materials for CMMC assessor and instructor certification and recertification.&lt;br /&gt;
&lt;br /&gt;
(7) Establish and publish an authorization and certification appeals process to receive, evaluate, and make decisions on complaints and appeals in accordance with ISO/IEC 17024:2012(E) (incorporated by reference, see § 170.2).&lt;br /&gt;
&lt;br /&gt;
(8) Address all appeals arising from the CCA, CCI, and CCP authorizations and certifications process through use of internal processes in accordance with ISO/IEC 17024:2012(E) (incorporated by reference, see § 170.2).&lt;br /&gt;
&lt;br /&gt;
(9) Maintain records for a period of six (6) years of all procedures, processes, and actions related to fulfillment of the requirements set forth in this section and provide the Accreditation Body access to those records.&lt;br /&gt;
&lt;br /&gt;
(10) Provide the Accreditation Body information about the authorization and accreditation status of assessors, instructors, training community, and publishing partners.&lt;br /&gt;
&lt;br /&gt;
(11) Ensure separation of duties between individuals involved in testing activities, training activities, and certification activities.&lt;br /&gt;
&lt;br /&gt;
(12) Safeguard and require any CAICO training support service providers, as applicable, to safeguard the confidentiality of applicant, candidate, and certificate-holder information and ensure the overall security of the certification process.&lt;br /&gt;
&lt;br /&gt;
(13) Ensure that all PII is encrypted and protected in all CAICO information systems and databases and those of any CAICO training support service providers.&lt;br /&gt;
&lt;br /&gt;
(14) Ensure the security of assessor and instructor examinations and the fair and credible administration of examinations.&lt;br /&gt;
&lt;br /&gt;
(15) Neither disclose nor allow any CAICO training support service providers, as applicable, to disclose CMMC data or metrics related to authorization or certification activities to any entity other than the Accreditation Body and DoD, except as required by law.&lt;br /&gt;
&lt;br /&gt;
(16) Require retraining and redesignation of PIs upon significant change to DoD’s CMMC Program requirements. Require retraining and recertification of CCPs, CCAs, and CCIs upon significant change to DoD’s CMMC Program requirements, as determined by the DoD or the CAICO.&lt;br /&gt;
&lt;br /&gt;
(17) Require CMMC Ecosystem members to report to the CAICO within 30 days of convictions, guilty pleas, or no contest pleas to crimes of fraud, larceny, embezzlement, misappropriation of funds, misrepresentation, perjury, false swearing, conspiracy to conceal, or a similar offense in any legal proceeding, civil or criminal, whether or not in connection with activities that relate to carrying out their role in the CMMC Ecosystem.&lt;br /&gt;
&lt;br /&gt;
=== § 170.11 CMMC Certified Assessor (CCA). ===&lt;br /&gt;
&lt;br /&gt;
(a)&#039;&#039;Roles and responsibilities&#039;&#039;. CCAs, in support of a C3PAO, conduct Level 2 certification assessments of OSCs in accordance with NIST SP 800-171A Jun2018 (incorporated by reference, see § 170.2), the assessment processes defined in § 170.17, and the scoping requirements defined in § 170.19(c). CCAs must meet all of the requirements set forth in paragraph (b) of this section. A CCA may conduct Level 2 certification assessments and participate on a C3PAO Assessment Team.&lt;br /&gt;
&lt;br /&gt;
(b)&#039;&#039;Requirements&#039;&#039;. CCAs shall: (1) Obtain and maintain certification from the CAICO in accordance with the requirements set forth in § 170.10. Certification is valid for 3 years from the date of issuance.&lt;br /&gt;
&lt;br /&gt;
(2) Comply with the Accreditation Body policies for Conflict of Interest, Code of Professional Conduct, and Ethics set forth in § 170.8(b)(17).&lt;br /&gt;
&lt;br /&gt;
(3) Complete a Tier 3 background investigation resulting in a determination of national security eligibility. This Tier 3 background investigation will not result in a security clearance and is not being executed for the purpose of government employment. The Tier 3 background investigation is initiated using the Standard Form (SF) 86 (&#039;&#039;www.gsa.gov/reference/forms/ questionnaire-for-national-security- positions&#039;&#039;). These positions are ]designated as non-critical sensitive with a risk designation of ‘‘Moderate Risk’’ in accordance with 5 CFR 1400.201(b) and (d) and the investigative requirements of 5 CFR 731.106(c)(2).&lt;br /&gt;
&lt;br /&gt;
(4) Meet the equivalent of a favorably adjudicated Tier 3 background investigation when not eligible for a Tier 3 background investigation. DoD will determine the Tier 3 background investigation equivalence for use with the CMMC Program only.&lt;br /&gt;
&lt;br /&gt;
(5) Provide all documentation and records in English.&lt;br /&gt;
&lt;br /&gt;
(6) Be a CCP who has at least 3 years of cybersecurity experience, at least 1 year of assessment or audit experience, and at least one foundational qualification, aligned to at least the Intermediate Proficiency Level of the DoD Cyberspace Workforce Framework’s Security Control Assessor (612) Work Role, from DoD Manual 8140.03, &#039;&#039;Cyberspace Workforce Qualification and Management Program&#039;&#039; (https://dodcio.defense.gov/Portals/0/ Documents/Library/DoDM-8140-03.pdf)&#039;&#039;. Information on the Work Role 612 can be found at &#039;&#039;https://public.cyber.mil/dcwf-work-role/security-control-assessor/&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
(7) Only use IT, cloud, cybersecurity services, and end-point devices provided by the authorized/accredited C3PAO that has been engaged to perform that OSA’s Level 2 certification assessment and which has undergone a Level 2 certification assessment by DCMA DIBCAC (or higher) for all assessment activities. Individual assessors are prohibited from using any other IT, including IT that is personally owned, to include internal and external cloud services and end-point devices, to process, store, or transmit CMMC assessment reports or any other CMMC assessment-related information. The evaluation of assessment evidence within the OSC environment, using OSC tools, is permitted.&lt;br /&gt;
&lt;br /&gt;
(8) Immediately notify the responsible C3PAO of any breach or potential breach of security to any CMMC-related assessment materials under the assessors’ purview.&lt;br /&gt;
&lt;br /&gt;
(9) Not share any information about an OSC obtained during CMMC pre- assessment and assessment activities with any person not involved with that specific assessment, except as otherwise required by law.&lt;br /&gt;
&lt;br /&gt;
(10) Qualify as a Lead CCA by having at least 5 years of cybersecurity experience, 5 years of management experience, 3 years of assessment or audit experience, and at least one foundational qualification aligned to Advanced Proficiency Level of the DoD Cyberspace Workforce Framework’s Security Control Assessor (612) Work Role, from DoD Manual 8140.03, &#039;&#039;Cyberspace Workforce Qualification and Management Program (https://dodcio.defense.gov/Portals/0/ Documents/Library/DoDM-8140-03.pdf)&#039;&#039;. Information on the Work Role 612 can be found at &#039;&#039; https://public.cyber.mil/dcwf-work-role/security-control-assessor/.&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
=== § 170.12 CMMC Instructor. ===&lt;br /&gt;
&lt;br /&gt;
(a) &#039;&#039;CMMC Provisional Instructor (PI) roles and responsibilities&#039;&#039;. A CMMC Provisional Instructor (PI) teaches CCA and CCP candidates during the transitional period that ends 18 months after December 16, 2024. A PI is trained, tested, and designated to perform CMMC instructional duties by the CAICO to teach CCP and CCA candidates. PIs are designated by the CAICO after successful completion of the PI training and testing requirements set forth by the CAICO. A PI with a valid CCP certification may instruct CCP candidates, while a PI with a valid CCA certification may instruct CCP and CCA candidates. PIs are required to meet requirements in (c) of this section.&lt;br /&gt;
&lt;br /&gt;
(b) &#039;&#039;CMMC Certified Instructor (CCI) roles and responsibilities&#039;&#039;. A CMMC Certified Instructor (CCI) teaches CCP, CCA, and CCI candidates and performs CMMC instructional duties. Candidate CCIs are certified by the CAICO after successful completion of the CCI training and testing requirements. A CCI is required to obtain and maintain assessor and instructor certifications from the CAICO in accordance with the requirements set forth in § 170.10 and in paragraph (c) of this section. A CCI with a valid CCP certification may instruct CCP candidates, while a CCI with a valid CCA certification may instruct CCP, CCA, and CCI candidates. Certifications are valid for 3 years from the date of issuance. CCIs are required to meet requirements in paragraph (c) of this section.&lt;br /&gt;
&lt;br /&gt;
(c)&#039;&#039;Requirements&#039;&#039;. CMMC Instructors shall:&lt;br /&gt;
&lt;br /&gt;
(1) Obtain and maintain instructor designation or certification, as appropriate, from the CAICO in accordance with the requirements set forth in § 170.10.&lt;br /&gt;
&lt;br /&gt;
(2) Obtain and maintain CCP or CCA certification to deliver CCP training.&lt;br /&gt;
&lt;br /&gt;
(3) Obtain and maintain a CCA certification to deliver CCA training.&lt;br /&gt;
&lt;br /&gt;
(4) Comply with the Accreditation Body policies for Conflict of Interest, Code of Professional Conduct, and Ethics set forth in § 170.8(b)(17).&lt;br /&gt;
&lt;br /&gt;
(5) Provide all documentation and records in English.&lt;br /&gt;
&lt;br /&gt;
(6) Provide the Accreditation Body and the CAICO annually with accurate information detailing their qualifications, training experience, professional affiliations, and certifications, and, upon reasonable request, submit documentation verifying this information.&lt;br /&gt;
&lt;br /&gt;
(7) Not provide CMMC consulting services while serving as a CMMC instructor; however, subject to the Code of Professional Conduct and Conflict of Interest policies, can serve on an assessment team.&lt;br /&gt;
&lt;br /&gt;
(8) Not participate in the development of exam objectives and/or exam content or act as an exam proctor while at the same time serving as a CCI.&lt;br /&gt;
&lt;br /&gt;
(9) Keep confidential all information obtained or created during the performance of CMMC training activities, including trainee records, except as required by law.&lt;br /&gt;
&lt;br /&gt;
(10) Not disclose any CMMC-related data or metrics that is PII, FCI, or CUI to anyone without prior coordination with and approval from DoD.&lt;br /&gt;
&lt;br /&gt;
(11) Notify the Accreditation Body or the CAICO if required by law or authorized by contractual commitments to release confidential information.&lt;br /&gt;
&lt;br /&gt;
(12) Not share with anyone any CMMC training-related information not previously publicly disclosed.&lt;br /&gt;
&lt;br /&gt;
=== § 170.13 CMMC Certified Professional (CCP). ===&lt;br /&gt;
&lt;br /&gt;
(a)&#039;&#039;Roles and responsibilities&#039;&#039;. A CMMC Certified Professional (CCP) completes rigorous training on CMMC and the assessment process to provide advice, consulting, and recommendations to their OSA clients. Candidate CCPs are certified by the CAICO after successful completion of the CCP training and testing requirements set forth in paragraph (b) of this section. CCPs are eligible to become CMMC Certified Assessors and can participate as a CCP on Level 2 certification assessments with CCA oversight where the CCA makes all final determinations.&lt;br /&gt;
&lt;br /&gt;
(b)&#039;&#039;Requirements&#039;&#039;. CCPs shall: (1) Obtain and maintain certification from the CAICO in accordance with the requirements set forth in § 170.10. Certification is valid for 3 years from the date of issuance.&lt;br /&gt;
&lt;br /&gt;
(2) Comply with the Accreditation Body policies for Conflict of Interest, Code of Professional Conduct, and Ethics as set forth in § 170.8(b)(17).&lt;br /&gt;
&lt;br /&gt;
(3) Complete a Tier 3 background investigation resulting in a determination of national security eligibility. This Tier 3 background investigation will not result in a security clearance and is not being executed for the purpose of government employment. The Tier 3 background investigation is initiated using the Standard Form (SF) 86 (&#039;&#039;www.gsa.gov/reference/forms/questionnaire-for-national-security-positions&#039;&#039;). These positions are ]designated as non-critical sensitive with a risk designation of ‘‘Moderate Risk’’ in accordance with 5 CFR 1400.201(b) and (d) and the investigative requirements of 5 CFR 731.106(c)(2).&lt;br /&gt;
&lt;br /&gt;
(4) Meet the equivalent of a favorably adjudicated Tier 3 background investigation when not eligible to obtain a Tier 3 background investigation. DoD will determine the Tier 3 background investigation equivalence for use with the CMMC Program only.&lt;br /&gt;
&lt;br /&gt;
(5) Provide all documentation and records in English.&lt;br /&gt;
&lt;br /&gt;
(6) Not share any information about an OSC obtained during CMMC pre- assessment and assessment activities with any person not involved with that specific assessment, except as otherwise required by law.&lt;br /&gt;
&lt;br /&gt;
== Subpart D - Key Elements of the CMMC Program ==&lt;br /&gt;
=== § 170.14 CMMC Model. ===&lt;br /&gt;
&lt;br /&gt;
(a)&#039;&#039;Overview&#039;&#039;. The CMMC Model incorporates the security requirements from:&lt;br /&gt;
&lt;br /&gt;
(1) 48 CFR 52.204-21, &#039;&#039;Basic Safeguarding of Covered Contractor Information Systems;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
(2) NIST SP 800-171 R2&#039;&#039;, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations&#039;&#039; (incorporated by reference, see § 170.2); and&lt;br /&gt;
&lt;br /&gt;
(3) Selected security requirements from NIST SP 800-172 Feb2021, &#039;&#039;Enhanced Security Requirements for Protecting Controlled Unclassified Information: A Supplement to NIST Special Publication 800-171&#039;&#039; (incorporated by reference, see § 170.2).&lt;br /&gt;
&lt;br /&gt;
(b) &#039;&#039;CMMC domains&#039;&#039;. The CMMC Model consists of domains that map to the Security Requirement Families defined in NIST SP 800-171 R2 (incorporated by reference, see § 170.2).&lt;br /&gt;
&lt;br /&gt;
(c) &#039;&#039;CMMC level requirements&#039;&#039;. CMMC Levels 1-3 utilize the safeguarding requirements and security requirements specified in 48 CFR 52.204-21 (for Level 1), NIST SP 800-171 R2 (incorporated by reference, see § 170.2) (for Level 2), and selected security requirements from NIST SP 800-172 Feb2021 (incorporated by reference, see § 170.2) (for Level 3). This paragraph discusses the numbering scheme and the security requirements for each level.&lt;br /&gt;
&lt;br /&gt;
(1)&#039;&#039;Numbering&#039;&#039;. Each security requirement has an identification number in the format - DD.L#-REQ -  where:&lt;br /&gt;
&lt;br /&gt;
(i) DD is the two-letter domain abbreviation;&lt;br /&gt;
&lt;br /&gt;
(ii) L# is the CMMC level number; and&lt;br /&gt;
&lt;br /&gt;
(iii) REQ is the 48 CFR 52.204-21 paragraph number, NIST SP 800-171 R2 requirement number, or NIST SP 800- 172 Feb2021 requirement number.&lt;br /&gt;
&lt;br /&gt;
(2) &#039;&#039;CMMC Level 1 security requirements&#039;&#039;. The security requirements in CMMC Level 1 are those set forth in 48 CFR 52.204-21(b)(1)(i) through (xv).&lt;br /&gt;
&lt;br /&gt;
(3) &#039;&#039;CMMC Level 2 security requirements&#039;&#039;. The security requirements in CMMC Level 2 are identical to the requirements in NIST SP 800-171 R2.&lt;br /&gt;
&lt;br /&gt;
(4) &#039;&#039;CMMC Level 3 security requirements&#039;&#039;. The security requirements in CMMC Level 3 are selected from NIST SP 800-172 Feb2021, and where applicable, Organization-Defined Parameters (ODPs) are assigned. Table 1 to this paragraph identifies the selected requirements and applicable ODPs that represent the CMMC Level 3 security requirements. ODPs for the NIST SP 800-172 Feb2021 requirements are italicized, where applicable:&lt;br /&gt;
&lt;br /&gt;
==== Table 1 ====&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;margin:auto&amp;quot;&lt;br /&gt;
|+ TABLE 1 TO § 170.14(c)(4)&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;width: 25%;text-align:center&amp;quot; | Security requirement No.*&lt;br /&gt;
! style=&amp;quot;width: 75%;text-align:center&amp;quot; | CMMC Level 3 security requirements&amp;lt;br&amp;gt;(selected NIST SP 800-172 Feb2021 security requirement with DoD ODPs italicized)&lt;br /&gt;
|-&lt;br /&gt;
|(i) AC.L3-3.1.2e&lt;br /&gt;
|Restrict access to systems and system components to only those information resources that are owned, provisioned, or issued by the organization.&lt;br /&gt;
|-&lt;br /&gt;
|(ii) AC.L3-3.1.3e&lt;br /&gt;
|Employ &#039;&#039;secure information transfer solutions&#039;&#039; to control information flows between security domains on con-nected systems.&lt;br /&gt;
|-&lt;br /&gt;
|(iii) AT.L3-3.2.1e&lt;br /&gt;
|Provide awareness training &#039;&#039;upon initial hire, following a significant cyber event, and at least annually&#039;&#039;, focused on recognizing and responding to threats from social engineering, advanced persistent threat actors, breaches, and suspicious behaviors; update the training &#039;&#039;at least annually&#039;&#039; or when there are significant changes to the threat.&lt;br /&gt;
|-&lt;br /&gt;
|(iv) AT.L3-3.2.2e&lt;br /&gt;
|Include practical exercises in awareness training for &#039;&#039;all users, tailored by roles, to include general users, users with specialized roles, and privileged users&#039;&#039;, that are aligned with current threat scenarios and provide feed-back to individuals involved in the training and their supervisors.&lt;br /&gt;
|-&lt;br /&gt;
|(v) CM.L3-3.4.1e&lt;br /&gt;
|Establish and maintain an authoritative source and repository to provide a trusted source and accountability for approved and implemented system components.&lt;br /&gt;
|-&lt;br /&gt;
|(vi) CM.L3-3.4.2e&lt;br /&gt;
|Employ automated mechanisms to detect misconfigured or unauthorized system components; after detection, &#039;&#039;remove the components or place the components in a quarantine or remediation network&#039;&#039; to facilitate patching, re-configuration, or other mitigations.&lt;br /&gt;
|-&lt;br /&gt;
|(vii) CM.L3-3.4.3e&lt;br /&gt;
|Employ automated discovery and management tools to maintain an up-to-date, complete, accurate, and readily available inventory of system components.&lt;br /&gt;
|-&lt;br /&gt;
|(viii) IA.L3-3.5.1e&lt;br /&gt;
|Identify and authenticate &#039;&#039;systems and system components, where possible&#039;&#039;, before establishing a network con-nection using bidirectional authentication that is cryptographically based and replay resistant.&lt;br /&gt;
|-&lt;br /&gt;
|(ix) IA.L3-3.5.3e&lt;br /&gt;
|Employ automated or manual/procedural mechanisms to prohibit system components from connecting to organizational systems unless the components are known, authenticated, in a properly configured state, or in a trust profile.&lt;br /&gt;
|-&lt;br /&gt;
|(x) IR.L3-3.6.1e&lt;br /&gt;
|Establish and maintain a security operations center capability that operates &#039;&#039;24/7, with allowance for remote/on-call staff&#039;&#039;.&lt;br /&gt;
|-&lt;br /&gt;
|(xi) IR.L3-3.6.2e&lt;br /&gt;
|Establish and maintain a cyber-incident response team that can be deployed by the organization within &#039;&#039;24 hours&#039;&#039;.&lt;br /&gt;
|-&lt;br /&gt;
|(xii) PS.L3-3.9.2e&lt;br /&gt;
|Ensure that organizational systems are protected if adverse information develops or is obtained about individuals with access to CUI.&lt;br /&gt;
|-&lt;br /&gt;
|(xiii) RA.L3-3.11.1e&lt;br /&gt;
|Employ &#039;&#039;threat intelligence, at a minimum from open or commercial sources, and any DoD-provided sources&#039;&#039;, as part of a risk assessment to guide and inform the development of organizational systems, security architec-tures, selection of security solutions, monitoring, threat hunting, and response and recovery activities.&lt;br /&gt;
|-&lt;br /&gt;
|(xiv) RA.L3-3.11.2e&lt;br /&gt;
|Conduct cyber threat hunting activities &#039;&#039;on an on-going aperiodic basis or when indications warrant&#039;&#039;, to search for indicators of compromise in&#039;&#039; organizational systems&#039;&#039; and detect, track, and disrupt threats that evade exist-ing controls.&lt;br /&gt;
|-&lt;br /&gt;
|(xv) RA.L3-3.11.3e&lt;br /&gt;
|Employ advanced automation and analytics capabilities in support of analysts to predict and identify risks to organizations, systems, and system components.&lt;br /&gt;
|-&lt;br /&gt;
|(xvi) RA.L3-3.11.4e&lt;br /&gt;
|Document or reference in the system security plan the security solution selected, the rationale for the security solution, and the risk determination.&lt;br /&gt;
|-&lt;br /&gt;
|(xvii) RA.L3-3.11.5e&lt;br /&gt;
|Assess the effectiveness of security solutions &#039;&#039;at least annually or upon receipt of relevant cyber threat information, or in response to a relevant cyber incident&#039;&#039;, to address anticipated risk to organizational systems and the organization based on current and accumulated threat intelligence.&lt;br /&gt;
|-&lt;br /&gt;
|(xviii) RA.L3-3.11.6e&lt;br /&gt;
|Assess, respond to, and monitor supply chain risks associated with organizational systems and system components.&lt;br /&gt;
|-&lt;br /&gt;
|(xix) RA.L3-3.11.7e&lt;br /&gt;
|Develop a plan for managing supply chain risks associated with organizational systems and system components; update the plan &#039;&#039;at least annually, and upon receipt of relevant cyber threat information, or in response to a relevant cyber incident&#039;&#039;.&lt;br /&gt;
|-&lt;br /&gt;
|(xx) CA.L3-3.12.1e&lt;br /&gt;
|Conduct penetration testing &#039;&#039;at least annually or when significant security changes are made to the system&#039;&#039;, leveraging automated scanning tools and ad hoc tests using subject matter experts.&lt;br /&gt;
|-&lt;br /&gt;
|(xxi) SC.L3-3.13.4e&lt;br /&gt;
|Employ &#039;&#039;physical isolation techniques or logical isolation techniques or both&#039;&#039; in organizational systems and system components.&lt;br /&gt;
|-&lt;br /&gt;
|(xxii) SI.L3-3.14.1e&lt;br /&gt;
|Verify the integrity of &#039;&#039;security critical and essential software&#039;&#039; using root of trust mechanisms or cryptographic signatures.&lt;br /&gt;
|-&lt;br /&gt;
|(xxiii) SI.L3-3.14.3e&lt;br /&gt;
|Ensure that &#039;&#039;specialized assets including IoT, IIoT, OT, GFE, Restricted Information Systems, and test equipment&#039;&#039; are included in the scope of the specified enhanced security requirements or are segregated in pur-pose-specific networks.&lt;br /&gt;
|-&lt;br /&gt;
|(xxiv) SI.L3-3.14.6e&lt;br /&gt;
|Use threat indicator information and effective mitigations obtained from&#039;&#039;, at a minimum, open or commercial sources, and any DoD-provided sources&#039;&#039;, to guide and inform intrusion detection and threat hunting.&lt;br /&gt;
|-&lt;br /&gt;
|colspan=&amp;quot;2&amp;quot;|* Roman numerals in parentheses before the Security Requirement are for numbering purposes only. The numerals are not part of the naming convention for the requirement.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
(d) &#039;&#039;Implementation&#039;&#039;. Assessment of security requirements is prescribed by NIST SP 800-171A Jun2018 (incorporated by reference, see § 170.2) and NIST SP 800-172A Mar2022 (incorporated by reference, see § 170.2). Descriptive text in these documents support OSA implementation of the security requirements and use the terms organization-defined and periodically. Except where referring to Organization- Defined Parameters (ODPs), organization-defined means as determined by the OSA. Periodically means occurring at regular intervals. As used in many requirements within CMMC, the interval length is organization-defined to provided contractor flexibility, with an interval length of no more than one year.&lt;br /&gt;
&lt;br /&gt;
=== § 170.15 CMMC Level 1 self-assessment and affirmation requirements. ===&lt;br /&gt;
&lt;br /&gt;
(a) &#039;&#039;Level 1 self-assessment&#039;&#039;. To comply with CMMC Level 1 self-assessment requirements, the OSA must meet the requirements detailed in paragraphs (a)(1) and (2) of this section. An OSA conducts a Level 1 self-assessment as detailed in paragraph (c) of this section to achieve a CMMC Status of Final Level 1 (Self).&lt;br /&gt;
&lt;br /&gt;
(1) &#039;&#039;Level 1 self-assessment requirements&#039;&#039;. The OSA must complete and achieve a MET result for all security requirements specified in § 170.14(c)(2) to achieve the CMMC Status of Final Level 1 (Self). No POA&amp;amp;Ms are permitted for CMMC Level 1. The OSA must conduct a self-assessment in accordance with the procedures set forth in § 170.15(c)(1) and submit assessment results in SPRS. To maintain compliance with the requirements for the CMMC Status of Final Level 1 (Self), the OSA must conduct a Level 1 self- assessment on an annual basis and submit the results in SPRS, or its successor capability.&lt;br /&gt;
&lt;br /&gt;
(i) &#039;&#039;Inputs to SPRS&#039;&#039;. The Level 1 self-assessment results in the Supplier Performance Risk System (SPRS) shall include, at minimum, the following items:&lt;br /&gt;
&lt;br /&gt;
(A) CMMC Level.&amp;lt;br&amp;gt;&lt;br /&gt;
(B) CMMC Status Date.&amp;lt;br&amp;gt;&lt;br /&gt;
(C) CMMC Assessment Scope.&amp;lt;br&amp;gt;&lt;br /&gt;
(D) All industry CAGE code(s) associated with the information system(s) addressed by the CMMC Assessment Scope.&amp;lt;br&amp;gt;&lt;br /&gt;
(E) Compliance result.&lt;br /&gt;
&lt;br /&gt;
(ii) [Reserved]&lt;br /&gt;
&lt;br /&gt;
(2) &#039;&#039;Affirmation&#039;&#039;. Affirmation of the Level 1 (Self) CMMC Status is required for all Level 1 self-assessments. Affirmation procedures are set forth in § 170.22.&lt;br /&gt;
&lt;br /&gt;
(b) &#039;&#039;Contract eligibility&#039;&#039;. Prior to award of any contract or subcontract with a requirement for the CMMC Status of Level 1 (Self), OSAs must both achieve a CMMC Status of Level 1 (Self) and have submitted an affirmation of compliance into SPRS for all information systems within the CMMC Assessment Scope.&lt;br /&gt;
&lt;br /&gt;
(c) &#039;&#039;Procedures - (1) Level 1 self-assessment&#039;&#039;. The OSA must conduct a Level 1 self-assessment scored in accordance with the CMMC Scoring Methodology described in § 170.24. The Level 1 self-assessment must be performed in accordance with the CMMC Level 1 scope requirements set forth in § 170.19(a) and (b) and the following:&lt;br /&gt;
&lt;br /&gt;
(i) The Level 1 self-assessment must be performed using the objectives defined in NIST SP 800-171A Jun2018 (incorporated by reference, see § 170.2) for the security requirement that maps to the CMMC Level 1 security requirement as specified in table 1 to paragraph (c)(1)(ii) of this section. In any case where an objective addresses CUI, FCI should be substituted for CUI in the objective.&lt;br /&gt;
&lt;br /&gt;
(ii) Mapping table for CMMC Level 1 security requirements to the NIST SP 800-171A Jun2018 objectives.&lt;br /&gt;
&lt;br /&gt;
==== Table 2 ====&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;margin:auto&amp;quot;&lt;br /&gt;
|+ TABLE 2 TO § 170.15(c)(1)(ii) - CMMC LEVEL 1 SECURITY REQUIREMENTS MAPPED TO NIST SP 800-171A JUN2018&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;width: 65%;text-align:left&amp;quot; | CMMC Level 1 security requirements as set forth in § 170.14(c)(2)&lt;br /&gt;
! style=&amp;quot;width: 35%;text-align:right&amp;quot; | NIST SP 800-171A Jun2018&lt;br /&gt;
|-&lt;br /&gt;
|AC.L1-b.1.i&lt;br /&gt;
| style=&amp;quot;text-align:right&amp;quot; | 3.1.1&lt;br /&gt;
|-&lt;br /&gt;
|AC.L1-b.1.ii&lt;br /&gt;
| style=&amp;quot;text-align:right&amp;quot; | 3.1.2&lt;br /&gt;
|-&lt;br /&gt;
|AC.L1-b.1.iii&lt;br /&gt;
| style=&amp;quot;text-align:right&amp;quot; | 3.1.20&lt;br /&gt;
|-&lt;br /&gt;
|AC.L1-b.1.iv&lt;br /&gt;
| style=&amp;quot;text-align:right&amp;quot; | 3.1.22&lt;br /&gt;
|-&lt;br /&gt;
|IA.L1-b.1.v&lt;br /&gt;
| style=&amp;quot;text-align:right&amp;quot; | 3.5.1&lt;br /&gt;
|-&lt;br /&gt;
|IA.L1-b.1.vi&lt;br /&gt;
| style=&amp;quot;text-align:right&amp;quot; | 3.5.2&lt;br /&gt;
|-&lt;br /&gt;
|MP.L1-b.1.vii&lt;br /&gt;
| style=&amp;quot;text-align:right&amp;quot; | 3.8.3&lt;br /&gt;
|-&lt;br /&gt;
|PE.L1-b.1.viii&lt;br /&gt;
| style=&amp;quot;text-align:right&amp;quot; | 3.10.1&lt;br /&gt;
|-&lt;br /&gt;
|First phrase of PE.L1-b.1.ix (FAR b.1.ix *)&lt;br /&gt;
| style=&amp;quot;text-align:right&amp;quot; | 3.10.3&lt;br /&gt;
|-&lt;br /&gt;
|Second phrase of PE.L1-b.1.ix (FAR b.1.ix *)&lt;br /&gt;
| style=&amp;quot;text-align:right&amp;quot; | 3.10.4&lt;br /&gt;
|-&lt;br /&gt;
|Third phrase of PE.L1-b.1.ix (FAR b.1.ix *)&lt;br /&gt;
| style=&amp;quot;text-align:right&amp;quot; | 3.10.5&lt;br /&gt;
|-&lt;br /&gt;
|SC.L1-b.1.x&lt;br /&gt;
| style=&amp;quot;text-align:right&amp;quot; | 3.13.1&lt;br /&gt;
|-&lt;br /&gt;
|SC.L1-b.1.xi&lt;br /&gt;
| style=&amp;quot;text-align:right&amp;quot; | 3.13.5&lt;br /&gt;
|-&lt;br /&gt;
|SI.L1-b.1.xii&lt;br /&gt;
| style=&amp;quot;text-align:right&amp;quot; | 3.14.1&lt;br /&gt;
|-&lt;br /&gt;
|SI.L1-b.1.xiii&lt;br /&gt;
| style=&amp;quot;text-align:right&amp;quot; | 3.14.2&lt;br /&gt;
|-&lt;br /&gt;
|SI.L1-b.1.xiv&lt;br /&gt;
| style=&amp;quot;text-align:right&amp;quot; | 3.14.4&lt;br /&gt;
|-&lt;br /&gt;
|SI.L1-b.1.xv&lt;br /&gt;
| style=&amp;quot;text-align:right&amp;quot; | 3.14.5&lt;br /&gt;
|-&lt;br /&gt;
|colspan=&amp;quot;2&amp;quot;|* Three of the 48 CFR 52.204-21 requirements were broken apart by ‘‘phrase’’ when NIST SP 800-171 R2 was developed.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
(iii) Additional guidance can be found in the guidance document listed in paragraph (b) of appendix A to this part.&lt;br /&gt;
&lt;br /&gt;
(2) &#039;&#039;Artifact retention&#039;&#039;. The artifacts used as evidence for the assessment must be retained by the OSA for six (6) years from the CMMC Status Date.&lt;br /&gt;
&lt;br /&gt;
=== § 170.16 CMMC Level 2 self-assessment and affirmation requirements. ===&lt;br /&gt;
&lt;br /&gt;
(a) &#039;&#039;Level 2 self-assessment&#039;&#039;. To comply with Level 2 self-assessment requirements, the OSA must meet the requirements detailed in paragraphs (a)(1) and (2) of this section. An OSA conducts a Level 2 self-assessment as detailed in paragraph (c) of this section to achieve a CMMC Status of either Conditional or Final Level 2 (Self). Achieving a CMMC Status of Level 2 (Self) also satisfies the requirements for a CMMC Status of Level 1 (Self) detailed in § 170.15 for the same CMMC Assessment Scope.&lt;br /&gt;
&lt;br /&gt;
(1) &#039;&#039;Level 2 self-assessment requirements&#039;&#039;. The OSA must complete and achieve a MET result for all security requirements specified in § 170.14(c)(3) to achieve the CMMC Status of Level 2 (Self). The OSA must conduct a self- assessment in accordance with the procedures set forth in paragraph (c)(1) of this section and submit assessment results in Supplier Performance Risk System (SPRS). To maintain compliance with the requirements for a CMMC Status of Level 2 (Self), the OSA must conduct a Level 2 self-assessment every three years and submit the results in SPRS, within three years of the CMMC Status Date associated with the Conditional Level 2 (Self).&lt;br /&gt;
&lt;br /&gt;
(i) &#039;&#039;Inputs to SPRS&#039;&#039;. The Level 2 self-assessment results in the SPRS shall include, at minimum, the following information:&lt;br /&gt;
&lt;br /&gt;
(A) CMMC Level.&amp;lt;br&amp;gt;&lt;br /&gt;
(B) CMMC Status Date.&amp;lt;br&amp;gt;&lt;br /&gt;
(C) CMMC Assessment Scope.&amp;lt;br&amp;gt;&lt;br /&gt;
(D) All industry CAGE code(s) associated with the information system(s) addressed by the CMMC Assessment Scope.&amp;lt;br&amp;gt;&lt;br /&gt;
(E) Overall Level 2 self-assessment score (&#039;&#039;e.g&#039;&#039;., 105 out of 110).&amp;lt;br&amp;gt;&lt;br /&gt;
(F) POA&amp;amp;M usage and compliance status, if applicable.&lt;br /&gt;
&lt;br /&gt;
(ii) &#039;&#039;Conditional Level 2 (Self)&#039;&#039;. The OSA has achieved the CMMC Status of Conditional Level 2 (Self) if the Level 2 self-assessment results in a POA&amp;amp;M and the POA&amp;amp;M meets all the CMMC Level 2 POA&amp;amp;M requirements listed in § 170.21(a)(2).&lt;br /&gt;
&lt;br /&gt;
(A) &#039;&#039;Plan of Action and Milestones&#039;&#039;. A Level 2 POA&amp;amp;M is allowed only in accordance with the CMMC POA&amp;amp;M requirements listed in § 170.21.&lt;br /&gt;
&lt;br /&gt;
(B) &#039;&#039;POA&amp;amp;M closeout&#039;&#039;. The OSA must remediate any NOT MET requirements, must perform a POA&amp;amp;M closeout self- assessment, and must post compliance results to SPRS within 180 days of the CMMC Status Date associated with the Conditional Level 2 (Self). If the POA&amp;amp;M is not successfully closed out within the 180-day timeframe, the Conditional Level 2 (Self) CMMC Status for the information system will expire. If Conditional Level 2 (Self) CMMC Status expires within the period of performance of a contract, standard contractual remedies will apply, and the OSA will be ineligible for additional awards with a requirement for the CMMC Status of Level 2 (Self), or higher requirement, for the information system within the CMMC Assessment Scope until such time as a new CMMC Status is achieved.&lt;br /&gt;
&lt;br /&gt;
(iii) &#039;&#039;Final Level 2 (Self)&#039;&#039;. The OSA has achieved the CMMC Status of Final Level 2 (Self) if the Level 2 self- assessment results in a passing score as defined in § 170.24. This score may be achieved upon initial self-assessment or as the result of a POA&amp;amp;M closeout self- assessment, as applicable.&lt;br /&gt;
&lt;br /&gt;
(iv) &#039;&#039;CMMC Status investigation&#039;&#039;. The DoD reserves the right to conduct a DCMA DIBCAC assessment of the OSA, as provided for under the 48 CFR 252.204-7020. If the investigative results of a subsequent DCMA DIBCAC assessment show that adherence to the provisions of this part have not been achieved or maintained, these DCMA DIBCAC results will take precedence over any pre-existing CMMC Status. At that time, standard contractual remedies will be available and the OSA will be ineligible for additional awards with CMMC Status requirement of Level 2 (Self), or higher requirement, for the information system within the CMMC Assessment Scope until such time as a new CMMC Status is achieved.&lt;br /&gt;
&lt;br /&gt;
(2) &#039;&#039;Affirmation&#039;&#039;. Affirmation of the Level 2 (Self) CMMC Status is required for all Level 2 self-assessments at the time of each assessment, and annually thereafter. Affirmation procedures are set forth in § 170.22.&lt;br /&gt;
&lt;br /&gt;
(b) &#039;&#039;Contract eligibility&#039;&#039;. Prior to award of any contract or subcontract with requirement for CMMC Status of Level 2 (Self), the following two requirements must be met:&lt;br /&gt;
&lt;br /&gt;
(1) The OSA must achieve, as specified in paragraph (a)(1) of this section, a CMMC Status of either Conditional Level 2 (Self) or Final Level 2 (Self).&lt;br /&gt;
&lt;br /&gt;
(2) The OSA must submit an affirmation of compliance into SPRS, as specified in paragraph (a)(2) of this section.&lt;br /&gt;
&lt;br /&gt;
(c) &#039;&#039;Procedures - (1) Level 2 self-assessment of the OSA&#039;&#039;. The OSA must conduct a Level 2 self-assessment in accordance with NIST SP 800-171A Jun2018 (incorporated by reference, see § 170.2) and the CMMC Level 2 scoping requirements set forth in §§ 170.19(a) and (c) for the information systems within the CMMC Assessment Scope. The Level 2 self-assessment must be scored in accordance with the CMMC Scoring Methodology described in § 170.24 and the OSA must upload the results into SPRS. If a POA&amp;amp;M exists, a POA&amp;amp;M closeout self-assessment must be performed by the OSA when all NOT MET requirements have been remediated. The POA&amp;amp;M closeout self- assessment must be performed within 180-days of the Conditional CMMC Status Date. Additional guidance can be found in the guidance document listed in paragraph (c) of appendix A to this part.&lt;br /&gt;
&lt;br /&gt;
(2) &#039;&#039;Level 2 self-assessment with the use of Cloud Service Provider (CSP)&#039;&#039;. An OSA may use a cloud environment to process, store, or transmit CUI in performance of a contract or subcontract with a requirement for the CMMC Status of Level 2 (Self) under the following circumstances:&lt;br /&gt;
&lt;br /&gt;
(i) The CSP product or service offering is FedRAMP Authorized at the FedRAMP Moderate (or higher) baseline in accordance with the FedRAMP Marketplace; or&lt;br /&gt;
&lt;br /&gt;
(ii) The CSP product or service offering is not FedRAMP Authorized at the FedRAMP Moderate (or higher) baseline but meets security requirements equivalent to those established by the FedRAMP Moderate (or higher) baseline. FedRAMP Moderate or FedRAMP Moderate equivalent is in accordance with DoD Policy.&lt;br /&gt;
&lt;br /&gt;
(iii) In accordance with § 170.19(c)(2), the OSA’s on-premises infrastructure connecting to the CSP’s product or service offering is part of the CMMC Assessment Scope, which will also be assessed. As such, the security requirements from the Customer Responsibility Matrix (CRM) must be documented or referred to in the OSA’s System Security Plan (SSP).&lt;br /&gt;
&lt;br /&gt;
(3) &#039;&#039;Level 2 self-assessment with the use of an External Service Provider (ESP), not a CSP&#039;&#039;. An OSA may use an ESP that is not a CSP to process, store, or transmit CUI in performance of a contract or subcontract with a requirement for the CMMC Status of Level 2 (Self) under the following circumstances:&lt;br /&gt;
&lt;br /&gt;
(i) The use of the ESP, its relationship to the OSA, and the services provided are documented in the OSA’s SSP and described in the ESP’s service description and CRM.&lt;br /&gt;
&lt;br /&gt;
(ii) The ESP services used to meet OSA requirements are assessed within the scope of the OSA’s assessment against all Level 2 security requirements.&lt;br /&gt;
&lt;br /&gt;
(iii) In accordance with § 170.19(c)(2), the OSA’s on-premises infrastructure connecting to the ESP’s product or service offering is part of the CMMC Assessment Scope, which will also be assessed. As such, the security requirements from the CRM must be documented or referred to in the OSA’s SSP.&lt;br /&gt;
&lt;br /&gt;
(4) &#039;&#039;Artifact retention&#039;&#039;. The artifacts used as evidence for the assessment must be retained by the OSA for six (6) years from the CMMC Status Date.&lt;br /&gt;
&lt;br /&gt;
=== § 170.17 CMMC Level 2 certification assessment and affirmation requirements. ===&lt;br /&gt;
&lt;br /&gt;
(a) &#039;&#039;Level 2 certification assessment&#039;&#039;. To comply with Level 2 certification assessment requirements, the OSC must meet the requirements set forth in paragraphs (a)(1) and (2) of this section. An OSC undergoes a Level 2 certification assessment as detailed in paragraph (c) of this section to achieve a CMMC Status of either Conditional or Final Level 2 (C3PAO). Achieving a CMMC Status of Level 2 (C3PAO) also satisfies the requirements for a CMMC Statuses of Level 1 (Self) and Level 2 (Self) set forth in §§ 170.15 and 170.16 respectively for the same CMMC Assessment Scope.&lt;br /&gt;
&lt;br /&gt;
(1) &#039;&#039;Level 2 certification assessment requirements&#039;&#039;. The OSC must complete and achieve a MET result for all security requirements specified in § 170.14(c)(3) to achieve the CMMC Status of Level 2 (C3PAO). The OSC must obtain a Level 2 certification assessment from an authorized or accredited C3PAO following the procedures outlined in paragraph (c) of this section. The C3PAO must submit the Level 2 certification assessment results into the CMMC instantiation of eMASS, which then provides automated transmission to SPRS. To maintain compliance with the requirements for a CMMC Status of Level 2 (C3PAO), the Level 2 certification assessment must be completed within three years of the CMMC Status Date associated with the Conditional Level 2 (C3PAO).&lt;br /&gt;
&lt;br /&gt;
(i) &#039;&#039;Inputs into the CMMC instantiation of eMASS&#039;&#039;. The Level 2 certification assessment results input into the CMMC instantiation of eMASS shall include, at minimum, the following information:&lt;br /&gt;
&lt;br /&gt;
(A) Date and level of the assessment.&amp;lt;br&amp;gt;&lt;br /&gt;
(B) C3PAO name.&amp;lt;br&amp;gt;&lt;br /&gt;
(C) Assessment unique identifier.&amp;lt;br&amp;gt;&lt;br /&gt;
(D) For each Assessor conducting the assessment, name and business contact information.&amp;lt;br&amp;gt;&lt;br /&gt;
(E) All industry CAGE codes associated with the information systems addressed by the CMMC Assessment Scope.&amp;lt;br&amp;gt;&lt;br /&gt;
(F) The name, date, and version of the SSP.&amp;lt;br&amp;gt;&lt;br /&gt;
(G) CMMC Status Date.&amp;lt;br&amp;gt;&lt;br /&gt;
(H) Assessment result for each requirement objective.&amp;lt;br&amp;gt;&lt;br /&gt;
(I) POA&amp;amp;M usage and compliance, as applicable.&amp;lt;br&amp;gt;&lt;br /&gt;
(J) List of the artifact names, the return value of the hashing algorithm, and the hashing algorithm used.&lt;br /&gt;
&lt;br /&gt;
(ii) &#039;&#039;Conditional Level 2 (C3PAO)&#039;&#039;. The OSC has achieved the CMMC Status of Conditional Level 2 (C3PAO) if the Level 2 certification assessment results in a POA&amp;amp;M and the POA&amp;amp;M meets all CMMC Level 2 POA&amp;amp;M requirements listed in § 170.21(a)(2).&lt;br /&gt;
&lt;br /&gt;
(A) &#039;&#039;Plan of Action and Milestones&#039;&#039;. A Level 2 POA&amp;amp;M is allowed only in accordance with the CMMC POA&amp;amp;M requirements listed in § 170.21.&lt;br /&gt;
&lt;br /&gt;
(B) &#039;&#039;POA&amp;amp;M closeout&#039;&#039;. The OSC must remediate any NOT MET requirements, must undergo a POA&amp;amp;M closeout certification assessment from a C3PAO, and the C3PAO must post compliance results into the CMMC instantiation of eMASS within 180 days of the CMMC Status Date associated with the Conditional Level 2 (C3PAO). If the POA&amp;amp;M is not successfully closed out within the 180-day timeframe, the Conditional Level 2 (C3PAO) CMMC Status for the information system will expire. If Conditional Level 2 (C3PAO) CMMC Status expires within the period of performance of a contract, standard contractual remedies will apply, and the OSC will be ineligible for additional awards with a requirement for the CMMC Status of Level 2 (C3PAO), or higher requirement, for the information system within the CMMC Assessment Scope until such time as a new CMMC Status is achieved.&lt;br /&gt;
&lt;br /&gt;
(iii) &#039;&#039;Final Level 2 (C3PAO)&#039;&#039;. The OSC has achieved the CMMC Status of Final Level 2 (C3PAO) if the Level 2 certification assessment results in a passing score as defined in § 170.24. This score may be achieved upon initial certification assessment or as the result of a POA&amp;amp;M closeout certification assessment, as applicable.&lt;br /&gt;
&lt;br /&gt;
(iv) &#039;&#039;CMMC Status investigation&#039;&#039;. The DoD reserves the right to conduct a DCMA DIBCAC assessment of the OSC, as provided for under the 48 CFR 252.204-7020. If the investigative results of a subsequent DCMA DIBCAC assessment show that adherence to the provisions of this part have not been achieved or maintained, these DCMA DIBCAC results will take precedence over any pre-existing CMMC Status. At that time, standard contractual remedies will be available and the OSC will be ineligible for additional awards with CMMC Status requirement of Level 2 (C3PAO), or higher requirement, for the information system within the CMMC Assessment Scope until such time as a new CMMC Status is achieved.&lt;br /&gt;
&lt;br /&gt;
(2) &#039;&#039;Affirmation&#039;&#039;. Affirmation of the Level 2 (C3PAO) CMMC Status is required for all Level 2 certification assessments at the time of each assessment, and annually thereafter. Affirmation procedures are provided in § 170.22.&lt;br /&gt;
&lt;br /&gt;
(b) &#039;&#039;Contract eligibility&#039;&#039;. Prior to award of any contract or subcontract with a requirement for the CMMC Status of Level 2 (C3PAO), the following two requirements must be met:&lt;br /&gt;
&lt;br /&gt;
(1) The OSC must achieve, as specified in paragraph (a)(1) of this section, a CMMC Status of either Conditional Level 2 (C3PAO) or Final Level 2 (C3PAO).&lt;br /&gt;
&lt;br /&gt;
(2) The OSC must submit an affirmation of compliance into SPRS, as specified in paragraph (a)(2) of this section.&lt;br /&gt;
&lt;br /&gt;
(c) &#039;&#039;Procedures - (1) Level 2 certification assessment of the OSC&#039;&#039;. An authorized or accredited C3PAO must perform a Level 2 certification assessment in accordance with NIST SP 800-171A Jun2018 (incorporated by reference, see § 170.2) and the CMMC Level 2 scoping requirements set forth in § 170.19(a) and (c) for the information systems within the CMMC Assessment Scope. The Level 2 certification assessment must be scored in accordance with the CMMC Scoring Methodology described in § 170.24 and the C3PAO must upload the results into the CMMC instantiation of eMASS. Final results are communicated to the OSC through a CMMC Assessment Findings Report.&lt;br /&gt;
&lt;br /&gt;
(2) &#039;&#039;Security requirement re-evaluation&#039;&#039;. A security requirement that is NOT MET (as defined in § 170.24) may be re-evaluated during the course of the Level 2 certification assessment and for 10 business days following the active assessment period if all of the following conditions exist:&lt;br /&gt;
&lt;br /&gt;
(i) Additional evidence is available to demonstrate the security requirement has been MET; &lt;br /&gt;
&lt;br /&gt;
(ii) Cannot change or limit the effectiveness of other requirements that have been scored MET; and&lt;br /&gt;
&lt;br /&gt;
(iii) The CMMC Assessment Findings Report has not been delivered.&lt;br /&gt;
&lt;br /&gt;
(3) &#039;&#039;POA&amp;amp;M&#039;&#039;. If a POA&amp;amp;M exists, a POA&amp;amp;M closeout certification assessment must be performed by a C3PAO within 180-days of the Conditional CMMC Status Date. Additional guidance can be found in § 170.21 and in the guidance document listed in paragraph (c) of appendix A to this part.&lt;br /&gt;
&lt;br /&gt;
(4) &#039;&#039;Artifact retention and integrity&#039;&#039;. The hashed artifacts used as evidence for the assessment must be retained by the OSC for six (6) years from the CMMC Status Date. To ensure that the artifacts have not been altered, the OSC must hash the artifact files using a NIST-approved hashing algorithm. The OSC must provide the C3PAO with a list of the artifact names, the return value of the hashing algorithm, and the hashing algorithm for upload into the CMMC instantiation of eMASS. Additional guidance for hashing artifacts can be found in the guidance document listed in paragraph (h) of appendix A to this part.&lt;br /&gt;
&lt;br /&gt;
(5) &#039;&#039;Level 2 certification assessment with the use of Cloud Service Provider (CSP)&#039;&#039;. An OSC may use a cloud environment to process, store, or transmit CUI in performance of a contract or subcontract with a requirement for the CMMC Status of Level 2 (C3PAO) under the following circumstances:&lt;br /&gt;
&lt;br /&gt;
(i) The CSP product or service offering is FedRAMP Authorized at the FedRAMP Moderate (or higher) baseline in accordance with the FedRAMP Marketplace; or&lt;br /&gt;
&lt;br /&gt;
(ii) The CSP product or service offering is not FedRAMP Authorized at the FedRAMP Moderate (or higher) baseline but meets security requirements equivalent to those established by the FedRAMP Moderate (or higher) baseline. FedRAMP Moderate or FedRAMP Moderate equivalent is in accordance with DoD Policy.&lt;br /&gt;
&lt;br /&gt;
(iii) In accordance with § 170.19(c)(2), the OSC’s on-premises infrastructure connecting to the CSP’s product or service offering is part of the CMMC Assessment Scope. As such, the security requirements from the CRM must be documented or referred to in the OSC’s SSP.&lt;br /&gt;
&lt;br /&gt;
(6) &#039;&#039;Level 2 certification assessment with the use of an External Service Provider (ESP), not a CSP&#039;&#039;. An OSA may use an ESP that is not a CSP to process, store, or transmit CUI in performance of a contract or subcontract with a requirement for the CMMC Status of Level 2 (C3PAO) under the following circumstances:&lt;br /&gt;
&lt;br /&gt;
(i) The use of the ESP, its relationship to the OSA, and the services provided are documented in the OSA’s SSP and described in the ESP’s service description and customer responsibility matrix.&lt;br /&gt;
&lt;br /&gt;
(ii) The ESP services used to meet OSA requirements are assessed within the scope of the OSA’s assessment against all Level 2 security requirements.&lt;br /&gt;
&lt;br /&gt;
(iii) In accordance with § 170.19(c)(2), the OSA’s on-premises infrastructure connecting to the ESP’s product or service offering is part of the CMMC Assessment Scope, which will also be assessed. As such, the security requirements from the CRM must be documented or referred to in the OSA’s SSP.&lt;br /&gt;
&lt;br /&gt;
=== § 170.18 CMMC Level 3 certification assessment and affirmation requirements. ===&lt;br /&gt;
&lt;br /&gt;
(a) &#039;&#039;Level 3 certification assessment&#039;&#039;. To comply with Level 3 certification assessment requirements, the OSC must meet the requirements set forth in paragraphs (a)(1) and (2) of this section. An OSC undergoes a Level 3 certification assessment as detailed in paragraph (c) of this section to achieve a CMMC Status of either Conditional or Final Level 3 (DIBCAC). A CMMC Status of Final Level 2 (C3PAO) for information systems within the Level 3 CMMC Assessment Scope is a prerequisite to undergo a Level 3 certification assessment. CMMC Level 3 recertification also has a prerequisite for a new CMMC Level 2 assessment. Achieving a CMMC Status of Level 3 (DIBCAC) also satisfies the requirements for CMMC Statuses of Level 1 (Self), Level 2 (Self), and Level 2 (C3PAO) set forth in §§ 170.15 through 170.17 respectively for the same CMMC Assessment Scope.&lt;br /&gt;
&lt;br /&gt;
(1) &#039;&#039;Level 3 certification assessment requirements&#039;&#039;. The OSC must achieve a CMMC Status of Final Level 2 (C3PAO) on the Level 3 CMMC Assessment Scope, as defined in § 170.19(d), prior to initiating a Level 3 certification assessment, which will be performed by DCMA DIBCAC (&#039;&#039;www.dcma.mil/DIBCAC&#039;&#039;) on behalf of the DoD. The OSC ]must complete and achieve a MET result for all security requirements specified in table 1 to § 170.14(c)(4) to achieve the CMMC Status of Level 3 (DIBCAC). DCMA DIBCAC will submit the Level 3 certification assessment results into the CMMC instantiation of eMASS, which then provides automated transmission to SPRS. To maintain compliance with the requirements for a CMMC Status of Level 3 (DIBCAC), the Level 3 certification assessment must be performed every three years for all information systems within the Level 3 CMMC Assessment Scope. In addition, given that compliance with Level 2 requirements is a prerequisite for applying for CMMC Level 3, a Level 2 (C3PAO) certification assessment must also be conducted every three years to maintain CMMC Level 3 (DIBCAC) status. Level 3 certification assessment must be completed within three years of the CMMC Status Date associated with the Final Level 3 (DIBCAC) or, if there was a POA&amp;amp;M, then within three years of the CMMC Status Date associated with the Conditional Level 3 (DIBCAC).&lt;br /&gt;
&lt;br /&gt;
(i) &#039;&#039;Inputs into the CMMC instantiation of eMASS&#039;&#039;. The Level 3 certification assessment results input into the CMMC instantiation of eMASS shall include, at minimum, the following items:&lt;br /&gt;
&lt;br /&gt;
(A) Date and level of the assessment.&amp;lt;br&amp;gt;&lt;br /&gt;
(B) For each Assessor(s) conducting the assessment, name and government organization information.&amp;lt;br&amp;gt;&lt;br /&gt;
(C) All industry CAGE code(s) associated with the information system(s) addressed by the CMMC Assessment Scope.&amp;lt;br&amp;gt;&lt;br /&gt;
(D) The name, date, and version of the system security plan(s) (SSP).&amp;lt;br&amp;gt;&lt;br /&gt;
(E) CMMC Status Date. (F) Result for each security requirement objective.&amp;lt;br&amp;gt;&lt;br /&gt;
(G) POA&amp;amp;M usage and compliance, as applicable.&amp;lt;br&amp;gt;&lt;br /&gt;
(H) List of the artifact names, the return value of the hashing algorithm, and the hashing algorithm used.&lt;br /&gt;
&lt;br /&gt;
(ii) &#039;&#039;Conditional Level 3 (DIBCAC)&#039;&#039;. The OSC has achieved the CMMC Status of Conditional Level 3 (DIBCAC) if the Level 3 certification assessment results in a POA&amp;amp;M and the POA&amp;amp;M meets all CMMC Level 3 POA&amp;amp;M requirements listed in § 170.21(a)(3).&lt;br /&gt;
&lt;br /&gt;
(A) &#039;&#039;Plan of Action and Milestones&#039;&#039;. A Level 3 POA&amp;amp;M is allowed only in accordance with the CMMC POA&amp;amp;M requirements listed in § 170.21.&lt;br /&gt;
&lt;br /&gt;
(B) &#039;&#039;POA&amp;amp;M closeout&#039;&#039;. The OSC must remediate any NOT MET requirements, must undergo a POA&amp;amp;M closeout certification assessment from DCMA DIBCAC, and DCMA DIBCAC must post compliance results into the CMMC instantiation of eMASS within 180 days of the CMMC Status Date associated with the Conditional Level 3 (DIBCAC). If the POA&amp;amp;M is not successfully closed out within the 180-day timeframe, the Conditional Level 3 (DIBAC) CMMC Status for the information system will expire. If Conditional Level 3 (DIBCAC) CMMC Status expires within the period of performance of a contract, standard contractual remedies will apply, and the OSC will be ineligible for additional awards with a requirement for the CMMC Status of Level 3 (DIBCAC) for the information system within the CMMC Assessment Scope until such time as a new CMMC Status is achieved.&lt;br /&gt;
&lt;br /&gt;
(iii) &#039;&#039;Final Level 3 (DIBCAC)&#039;&#039;. The OSC has achieved the CMMC Status of Final Level 3 (DIBCAC) if the Level 3 certification assessment results in a passing score as defined in § 170.24. This score may be achieved upon initial certification assessment or as the result of a POA&amp;amp;M closeout certification assessment, as applicable.&lt;br /&gt;
&lt;br /&gt;
(iv) &#039;&#039;CMMC Status investigation&#039;&#039;. The DoD reserves the right to conduct a DCMA DIBCAC assessment of the OSC, as provided for under the 48 CFR 252.204-7020. If the investigative results of a subsequent DCMA DIBCAC assessment show that adherence to the provisions of this part have not been achieved or maintained, these DCMA DIBCAC results will take precedence over any pre-existing CMMC Status. At that time, standard contractual remedies will be available and the OSC will be ineligible for additional awards with CMMC Status requirement of Level 3 (DIBCAC) for the information system within the CMMC Assessment Scope until such time as a new CMMC Status is achieved.&lt;br /&gt;
&lt;br /&gt;
(2) &#039;&#039;Affirmation&#039;&#039;. Affirmation of the Level 3 (DIBCAC) CMMC Status is required for all Level 3 certification assessments at the time of each assessment, and annually thereafter. Affirmation procedures are provided in § 170.22.&lt;br /&gt;
&lt;br /&gt;
(b) &#039;&#039;Contract eligibility&#039;&#039;. Prior to award of any contract or subcontract with requirement for CMMC Status of Level 3 (DIBCAC), the following two requirements must be met:&lt;br /&gt;
&lt;br /&gt;
(1) The OSC must achieve, as specified in paragraph (a)(1) of this section, a CMMC Status of either Conditional Level 3 (DIBCAC) or Final Level 3 (DIBCAC).&lt;br /&gt;
&lt;br /&gt;
(2) The OSC must submit an affirmation of compliance into SPRS, as specified in paragraph (a)(2) of this section.&lt;br /&gt;
&lt;br /&gt;
(c) &#039;&#039;Procedures - (1) Level 3 certification assessment of the OSC&#039;&#039;. The CMMC Level 3 certification assessment process includes:&lt;br /&gt;
&lt;br /&gt;
(i) &#039;&#039;Final Level 2 (C3PAO)&#039;&#039;. The OSC must achieve a CMMC Status of Final Level 2 (C3PAO) for information systems within the Level 3 CMMC Assessment Scope prior to the CMMC Level 3 certification assessment. The CMMC Assessment Scope for the Level 3 certification assessment must be equal to, or a subset of, the CMMC Assessment Scope associated with the OSC’s Final Level 2 (C3PAO). Asset requirements differ for each CMMC Level. Scoping differences are set forth in § 170.19.&lt;br /&gt;
&lt;br /&gt;
(ii) &#039;&#039;Initiating the Final Level 3 (DIBCAC)&#039;&#039;. The OSC (including ESPs that voluntarily elect to undergo a Level 3 certification assessment) initiates a Level 3 certification assessment by emailing a request to DCMA DIBCAC point of contact found at &#039;&#039;www.dcma.mil/DIBCAC&#039;&#039;. The request ]must include the Level 2 certification assessment unique identifier. DCMA DIBCAC will validate the OSC has achieved a CMMC Status of Level 2 (C3PAO) and will contact the OSC to schedule their Level 3 certification assessment.&lt;br /&gt;
&lt;br /&gt;
(iii) &#039;&#039;Conducting the Final Level 3 (DIBCAC)&#039;&#039;. DCMA DIBCAC will perform a Level 3 certification assessment in accordance with NIST SP 800-171A Jun2018 (incorporated by reference, see § 170.2) and NIST SP 800-172A Mar2022 (incorporated by reference, see § 170.2) and the CMMC Level 3 scoping requirements set forth in § 170.19(d) for the information systems within the CMMC Assessment Scope. The Level 3 certification assessment will be scored in accordance with the CMMC Scoring Methodology set forth in § 170.24 and DCMA DIBCAC will upload the results into the CMMC instantiation of eMASS. Final results are communicated to the OSC through a CMMC Assessment Findings Report. For assets that changed asset category (&#039;&#039;i.e&#039;&#039;., CRMA to CUI Asset) or assessment requirements (&#039;&#039;i.e&#039;&#039;., Specialized Assets) between the Level 2 and Level 3 certification assessments, DCMA DIBCAC will perform limited checks of Level 2 security requirements. If the OSC had these upgraded asset categories included in their Level 2 certification assessment, then DCMA DIBCAC may still perform limited checks for compliance. If DCMA DIBCAC identifies that a Level 2 security requirement is NOT MET, the Level 3 assessment process may be paused to allow for remediation, placed on hold, or immediately terminated.&lt;br /&gt;
&lt;br /&gt;
(2) &#039;&#039;Security requirement re-evaluation&#039;&#039;. A security requirement that is NOT MET (as defined in § 170.24) may be re-evaluated during the course of the Level 3 certification assessment and for 10 business days following the active assessment period if all of the following conditions exist:&lt;br /&gt;
&lt;br /&gt;
(i) Additional evidence is available to demonstrate the security requirement has been MET;&lt;br /&gt;
&lt;br /&gt;
(ii) The additional evidence does not materially impact previously assessed security requirements; and&lt;br /&gt;
&lt;br /&gt;
(iii) The CMMC Assessment Findings Report has not been delivered.&lt;br /&gt;
&lt;br /&gt;
(3) &#039;&#039;POA&amp;amp;M&#039;&#039;. If a POA&amp;amp;M exists, a POA&amp;amp;M closeout certification assessment will be performed by DCMA DIBCAC within 180-days of the Conditional CMMC Status Date. Additional guidance is located in § 170.21 and in the guidance document listed in paragraph (d) of appendix A to this part.&lt;br /&gt;
&lt;br /&gt;
(4) &#039;&#039;Artifact retention and integrity&#039;&#039;. The hashed artifacts used as evidence for the assessment must be retained by the OSC for six (6) years from the CMMC Status Date. The hashed artifacts used as evidence for the assessment must be retained by the OSC for six (6) years from the CMMC Status Date. To ensure that the artifacts have not been altered, the OSC must hash the artifact files using a NIST-approved hashing algorithm. Assessors will collect the list of the artifact names, the return value of the hashing algorithm, and the hashing algorithm used and upload that data into the CMMC instantiation of eMASS. Additional guidance for hashing artifacts can be found in the guidance document listed in paragraph (h) of appendix A to this part.&lt;br /&gt;
&lt;br /&gt;
(5) &#039;&#039;Level 3 certification assessment with the use of Cloud Service Provider (CSP)&#039;&#039;. An OSC may use a cloud environment to process, store, or transmit CUI in performance of a contract or subcontract with a requirement for the CMMC Status of Level 3 (DIBCAC) under the following circumstances:&lt;br /&gt;
&lt;br /&gt;
(i) The OSC may utilize a CSP product or service offering that meets the FedRAMP Moderate (or higher) baseline. If the CSP’s product or service offering is not FedRAMP Authorized at the FedRAMP Moderate (or higher) baseline, the product or service offering must meet security requirements equivalent to those established by the FedRAMP Moderate (or higher) baseline in accordance with DoD Policy.&lt;br /&gt;
&lt;br /&gt;
(ii) Use of a CSP does not relieve an OSC of its obligation to implement the 24 Level 3 security requirements. These 24 requirements apply to every environment where the CUI data is processed, stored, or transmitted, when Level 3 (DIBCAC) is the designated CMMC Status. If any of these 24 requirements are inherited from a CSP, the OSC must demonstrate that protection during a Level 3 certification assessment via a Customer Implementation Summary/Customer Responsibility Matrix (CIS/CRM) and associated Body of Evidence (BOE). The BOE must clearly indicate whether the OSC or the CSP is responsible for meeting each requirement and which requirements are implemented by the OSC versus inherited from the CSP.&lt;br /&gt;
&lt;br /&gt;
(iii) In accordance with § 170.19(d)(2), the OSC’s on-premises infrastructure connecting to the CSP’s product or service offering is part of the CMMC Assessment Scope. As such, the security requirements from the CRM must be documented or referred to in the OSC’s SSP.&lt;br /&gt;
&lt;br /&gt;
(6) &#039;&#039;Level 3 certification assessment with the use of an ESP, not a CSP&#039;&#039;. An OSC may use an ESP that is not a CSP to process, store, or transmit CUI in performance of a contract or subcontract with a requirement for the CMMC Status of Level 3 (DIBCAC) under the following circumstances:&lt;br /&gt;
&lt;br /&gt;
(i) The use of the ESP, its relationship to the OSC, and the services provided are documented in the OSC’s SSP and described in the ESP’s service description and customer responsibility matrix.&lt;br /&gt;
&lt;br /&gt;
(ii) The ESP services used to meet OSC requirements are assessed within the scope of the OSC’s assessment against all Level 2 and Level 3 security requirements.&lt;br /&gt;
&lt;br /&gt;
(iii) In accordance with § 170.19(d)(2), the OSC’s on-premises infrastructure connecting to the ESP’s product or service offering is part of the CMMC Assessment Scope, which will also be assessed. As such, the security requirements from the CRM must be documented or referred to in the OSC’s SSP.&lt;br /&gt;
&lt;br /&gt;
=== § 170.19 CMMC scoping. ===&lt;br /&gt;
&lt;br /&gt;
(a) &#039;&#039;Scoping requirement&#039;&#039;. (1) The CMMC Assessment Scope must be specified prior to assessment in accordance with the requirements of this section. The CMMC Assessment Scope is the set of all assets in the OSA’s environment that will be assessed against CMMC security requirements.&lt;br /&gt;
&lt;br /&gt;
(2) The requirements for defining the CMMC Assessment Scope for CMMC Levels 1, 2, and 3 are set forth in this section. Additional guidance regarding scoping can be found in the guidance documents listed in paragraphs (e) through (g) of appendix A to this part.&lt;br /&gt;
&lt;br /&gt;
(b) &#039;&#039;CMMC Level 1 scoping&#039;&#039;. Prior to performing a Level 1 self-assessment, the OSA must specify the CMMC Assessment Scope.&lt;br /&gt;
&lt;br /&gt;
(1) &#039;&#039;Assets in scope for Level 1 self-assessment&#039;&#039;. OSA information systems which process, store, or transmit FCI are in scope for CMMC Level 1 and must be self-assessed against applicable CMMC security requirements.&lt;br /&gt;
&lt;br /&gt;
(2) &#039;&#039;Assets not in scope for Level 1 self-assessment&#039;&#039; - (i) &#039;&#039;Out-of-Scope Assets&#039;&#039;. OSA information systems which do not process, store, or transmit FCI are outside the scope for CMMC Level 1. An endpoint hosting a VDI client configured to not allow any processing, storage, or transmission of FCI beyond the Keyboard/Video/Mouse sent to the VDI client is considered out-of-scope. There are no documentation requirements for out-of-scope assets.&lt;br /&gt;
&lt;br /&gt;
(ii) &#039;&#039;Specialized Assets&#039;&#039;. Specialized Assets are those assets that can process, store, or transmit FCI but are unable to be fully secured, including: Internet of Things (IoT) devices, Industrial Internet of Things (IIoT) devices, Operational Technology (OT), Government Furnished Equipment (GFE), Restricted Information Systems, and Test Equipment. Specialized Assets are not part of the Level 1 CMMC Assessment Scope and are not assessed against CMMC security requirements.&lt;br /&gt;
&lt;br /&gt;
(3) &#039;&#039;Level 1 self-assessment scoping considerations&#039;&#039;. To scope a Level 1 self-assessment, OSAs should consider the people, technology, facilities, and External Service Providers (ESP) within its environment that process, store, or transmit FCI.&lt;br /&gt;
&lt;br /&gt;
(c) &#039;&#039;CMMC Level 2 Scoping&#039;&#039;. Prior to performing a Level 2 self-assessment or Level 2 certification assessment, the OSA must specify the CMMC Assessment Scope.&lt;br /&gt;
&lt;br /&gt;
(1) The CMMC Assessment Scope for CMMC Level 2 is based on the specification of asset categories and their respective requirements as defined in table 3 to this paragraph (c)(1). Additional information is available in the guidance document listed in paragraph (f) of appendix A to this part.&lt;br /&gt;
&lt;br /&gt;
==== Table 3 ====&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;margin:auto&amp;quot;&lt;br /&gt;
|+ TABLE 3 TO § 170.19(c)(1) - CMMC LEVEL 2 ASSET CATEGORIES AND ASSOCIATED REQUIREMENTS&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;width: 25%;text-align:left&amp;quot; | Asset category&lt;br /&gt;
! style=&amp;quot;width: 25%;text-align:left&amp;quot; | Asset description&lt;br /&gt;
! style=&amp;quot;width: 25%;text-align:left&amp;quot; | OSA requirements&lt;br /&gt;
! style=&amp;quot;width: 25%;text-align:left&amp;quot; | CMMC assessment requirements&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;4&amp;quot; style=&amp;quot;text-align:center;&amp;quot; | &#039;&#039;&#039;Assets that are in the Level 2 CMMC Assessment Scope&#039;&#039;&#039;&lt;br /&gt;
|- style=&amp;quot;vertical-align:top;&amp;quot;&lt;br /&gt;
| Controlled Unclassified Information (CUI) Assets.&lt;br /&gt;
|&lt;br /&gt;
* Assets that process, store, or transmit CUI.&lt;br /&gt;
|&lt;br /&gt;
* Document in the asset inventory&lt;br /&gt;
* Document asset treatment in the System Security Plan (SSP).&lt;br /&gt;
* Document in the network diagram of the CMMC Assessment Scope.&lt;br /&gt;
* Prepare to be assessed against CMMC Level 2 security requirements.&lt;br /&gt;
|&lt;br /&gt;
* Assess against all Level 2 security requirements.&lt;br /&gt;
|- style=&amp;quot;vertical-align:top;&amp;quot;&lt;br /&gt;
| Security Protection Assets&lt;br /&gt;
|&lt;br /&gt;
* Assets that provide security functions or capabilities to the OSA’s CMMC As-sessment Scope.&lt;br /&gt;
|&lt;br /&gt;
* Document in the asset inventory&lt;br /&gt;
* Document asset treatment in SSP.&lt;br /&gt;
* Document in the network diagram of the CMMC Assessment Scope.&lt;br /&gt;
* Prepare to be assessed against CMMC Level 2 security requirements.&lt;br /&gt;
|&lt;br /&gt;
* Assess against Level 2 security requirements that are relevant to the ca-pabilities provided.&lt;br /&gt;
|- style=&amp;quot;vertical-align:top;&amp;quot;&lt;br /&gt;
| Contractor Risk Managed Assets.&lt;br /&gt;
|&lt;br /&gt;
* Assets that can, but are not intended to, process, store, or transmit CUI be-cause of security policy, procedures, and practices in place.&lt;br /&gt;
* Assets are not required to be physically or logically separated from CUI assets.&lt;br /&gt;
|&lt;br /&gt;
* Document in the asset inventory&lt;br /&gt;
* Document asset treatment in the SSP.&lt;br /&gt;
* Document in the network diagram of the CMMC Assessment Scope.&lt;br /&gt;
* Prepare to be assessed against CMMC Level 2 security requirements.&lt;br /&gt;
|&lt;br /&gt;
* Review the SSP:&lt;br /&gt;
** If sufficiently documented, do not assess against other CMMC secu-rity requirements, except as noted.&lt;br /&gt;
** If OSA’s risk-based security policies, procedures, and practices documentation or other findings raise questions about these assets, the assessor can conduct a limited check to identify deficiencies.&lt;br /&gt;
** The limited check(s) shall not materially increase the assessment duration nor the assessment cost.&lt;br /&gt;
** The limited check(s) will be assessed against CMMC security re-quirements.&lt;br /&gt;
|- style=&amp;quot;vertical-align:top;&amp;quot;&lt;br /&gt;
| Specialized Assets&lt;br /&gt;
|&lt;br /&gt;
* Assets that can process, store, or transmit CUI but are unable to be fully secured, including: Internet of Things (IoT) devices, Industrial Internet of Things (IIoT) devices, Operational Technology (OT), Government Fur-nished Equipment (GFE), Restricted In-formation Systems, and Test Equip-ment.&lt;br /&gt;
|&lt;br /&gt;
* Document in the asset inventory&lt;br /&gt;
* Document asset treatment in the SSP.&lt;br /&gt;
* Show these assets are managed using the contractor’s risk-based security poli-cies, procedures, and practices.&lt;br /&gt;
* Document in the network diagram of the CMMC Assessment Scope.&lt;br /&gt;
|&lt;br /&gt;
* Review the SSP.&lt;br /&gt;
* Do not assess against other CMMC security requirements.&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;4&amp;quot; style=&amp;quot;text-align:center;&amp;quot; | &#039;&#039;&#039;Assets that are not in the Level 2 CMMC Assessment Scope&#039;&#039;&#039;&lt;br /&gt;
|- style=&amp;quot;vertical-align:top;&amp;quot;&lt;br /&gt;
|Out-of-Scope Assets&lt;br /&gt;
|&lt;br /&gt;
* Assets that cannot process, store, or transmit CUI; and do not provide secu-rity protections for CUI Assets.&lt;br /&gt;
* Assets that are physically or logically separated from CUI assets.&lt;br /&gt;
* Assets that fall into any in-scope asset category cannot be considered an Out- of-Scope Asset.&lt;br /&gt;
* An endpoint hosting a VDI client configured to not allow any processing, stor-age, or transmission of CUI beyond the Keyboard/Video/Mouse sent to the VDI client is considered an Out-of-Scope Asset.&lt;br /&gt;
|&lt;br /&gt;
* Prepare to justify the inability of an Out-of-Scope Asset to process, store, or transmit CUI.&lt;br /&gt;
|&lt;br /&gt;
* None.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
(2)(i) Table 4 to this paragraph (c)(2)(i) defines the requirements to be met when utilizing an External Service Provider (ESP). The OSA must consider whether the ESP is a Cloud Service Provider (CSP) and whether the ESP processes, stores, or transmits CUI and/ or Security Protection Data (SPD).&lt;br /&gt;
&lt;br /&gt;
==== Table 4 ====&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;margin:auto&amp;quot;&lt;br /&gt;
|+ TABLE 4 TO § 170.19(c)(2)(i) - ESP SCOPING REQUIREMENTS&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;width: 30%;text-align:left&amp;quot; | When the ESP processes, stores, or transmits:&lt;br /&gt;
! style=&amp;quot;width: 35%;text-align:left&amp;quot; | When utilizing an ESP that is a CSP&lt;br /&gt;
! style=&amp;quot;width: 35%;text-align:left&amp;quot; | When utilizing an ESP that is not a CSP&lt;br /&gt;
|- style=&amp;quot;vertical-align:top;&amp;quot;&lt;br /&gt;
| CUI (with or without SPD)&lt;br /&gt;
| The CSP shall meet the FedRAMP requirements in 48 CFR 252.204-7012.&lt;br /&gt;
| The services provided by the ESP are in the OSA’s assessment scope and shall be assessed as part of the OSA’s assessment.&lt;br /&gt;
|- style=&amp;quot;vertical-align:top;&amp;quot;&lt;br /&gt;
| SPD (without CUI)&lt;br /&gt;
| The services provided by the CSP are in the OSA’s assessment scope and shall be assessed as Security Protection Assets.&lt;br /&gt;
| The services provided by the ESP are in the OSA’s assessment scope and shall be assessed as Security Protection Assets.&lt;br /&gt;
|- style=&amp;quot;vertical-align:top;&amp;quot;&lt;br /&gt;
| Neither CUI nor SPD&lt;br /&gt;
| A service provider that does not process CUI or SPD does not meet the CMMC definition of an ESP.&lt;br /&gt;
| A service provider that does not process CUI or SPD does not meet the CMMC definition of an ESP.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
(ii) The use of an ESP, its relationship to the OSA, and the services provided need to be documented in the OSA’s SSP and described in the ESP’s service description and customer responsibility matrix (CRM), which describes the responsibilities of the OSA and ESP with respect to the services provided. Note that the ESP may voluntarily undergo a CMMC certification assessment to reduce the ESP’s effort required during the OSA’s assessment. The minimum assessment type for the ESP is dictated by the OSA’s DoD contract requirement.&lt;br /&gt;
&lt;br /&gt;
(d) &#039;&#039;CMMC Level 3 scoping&#039;&#039;. Prior to performing a Level 3 certification assessment, the CMMC Assessment Scope must be specified.&lt;br /&gt;
&lt;br /&gt;
(1) The CMMC Assessment Scope for Level 3 is based on the specification of asset categories and their respective requirements as set forth in table 5 to this paragraph (d)(1). Additional information is available in the guidance document listed in paragraph (g) of appendix A to this part.&lt;br /&gt;
&lt;br /&gt;
==== Table 5 ====&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;margin:auto&amp;quot;&lt;br /&gt;
|+ TABLE 5 TO § 170.19(d)(1) - CMMC LEVEL 3 ASSET CATEGORIES AND ASSOCIATED REQUIREMENTS&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;width: 25%;text-align:left&amp;quot; | Asset category&lt;br /&gt;
! style=&amp;quot;width: 25%;text-align:left&amp;quot; | Asset description&lt;br /&gt;
! style=&amp;quot;width: 25%;text-align:left&amp;quot; | OSA requirements&lt;br /&gt;
! style=&amp;quot;width: 25%;text-align:left&amp;quot; | CMMC assessment requirements&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;4&amp;quot; style=&amp;quot;text-align:center;&amp;quot; | &#039;&#039;&#039;Assets that are in the Level 3 CMMC Assessment Scope&#039;&#039;&#039;&lt;br /&gt;
|- style=&amp;quot;vertical-align:top;&amp;quot;&lt;br /&gt;
| Controlled Unclassified Information (CUI) Assets.&lt;br /&gt;
|&lt;br /&gt;
* Assets that process, store, or transmit CUI.&lt;br /&gt;
|&lt;br /&gt;
* Assets that can, but are not intended to, process, store, or transmit CUI (de-fined as Contractor Risk Managed As-sets in table 1 to paragraph (c)(1) of this section CMMC Scoping).&lt;br /&gt;
* Document in the asset inventory&lt;br /&gt;
* Document asset treatment in the System Security Plan (SSP).&lt;br /&gt;
* Document in the network diagram of the CMMC Assessment Scope.&lt;br /&gt;
* Prepare to be assessed against CMMC Level 2 and Level 3 security require-ments.&lt;br /&gt;
|&lt;br /&gt;
* Limited check against Level 2 and assess against all Level 3 CMMC security requirements.&lt;br /&gt;
|- style=&amp;quot;vertical-align:top;&amp;quot;&lt;br /&gt;
| Security Protection Assets&lt;br /&gt;
|&lt;br /&gt;
* Assets that provide security functions or capabilities to the OSC’s CMMC As-sessment Scope, irrespective of wheth-er or not these assets process, store, or transmit CUI.&lt;br /&gt;
|&lt;br /&gt;
* Document in the asset inventory&lt;br /&gt;
* Document asset treatment in the SSP.&lt;br /&gt;
* Document in the network diagram of the CMMC Assessment Scope.&lt;br /&gt;
* Prepare to be assessed against CMMC Level 2 and Level 3 security require-ments.&lt;br /&gt;
|&lt;br /&gt;
* Limited check against Level 2 and assess against all Level 3 CMMC security requirements that are relevant to the capabilities provided.&lt;br /&gt;
|- style=&amp;quot;vertical-align:top;&amp;quot;&lt;br /&gt;
| Specialized Assets&lt;br /&gt;
|&lt;br /&gt;
* Assets that can process, store, or transmit CUI but are unable to be fully secured, including: Internet of Things (IoT) devices, Industrial Internet of Things (IIoT) devices, Operational Technology (OT), Government Fur-nished Equipment (GFE), Restricted In-formation Systems, and Test Equip-ment.&lt;br /&gt;
|&lt;br /&gt;
* Document in the asset inventory&lt;br /&gt;
* Document asset treatment in the SSP.&lt;br /&gt;
* Document in the network diagram of the CMMC Assessment Scope.&lt;br /&gt;
* Prepare to be assessed against CMMC Level 2 and Level 3 security require-ments.&lt;br /&gt;
|&lt;br /&gt;
* Limited check against Level 2 and assess against all Level 3 CMMC security requirements.&lt;br /&gt;
* Intermediary devices are permitted to provide the capability for the special-ized asset to meet one or more CMMC security requirements.&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;4&amp;quot; style=&amp;quot;text-align:center;&amp;quot; | &#039;&#039;&#039;Assets that are not in the Level 3 CMMC Assessment Scope&#039;&#039;&#039;&lt;br /&gt;
|- style=&amp;quot;vertical-align:top;&amp;quot;&lt;br /&gt;
| Out-of-Scope Assets&lt;br /&gt;
|&lt;br /&gt;
* Assets that cannot process, store, or transmit CUI; and do not provide secu-rity protections for CUI Assets.&lt;br /&gt;
* Assets that are physically or logically separated from CUI assets.&lt;br /&gt;
* Assets that fall into any in-scope asset category cannot be considered an Out- of-Scope Asset.&lt;br /&gt;
* An endpoint hosting a VDI client configured to not allow any processing, stor-age, or transmission of CUI beyond the Keyboard/Video/Mouse sent to the VDI client is considered an Out-of-Scope Asset.&lt;br /&gt;
|&lt;br /&gt;
* Prepare to justify the inability of an Out-of-Scope Asset to process, store, or transmit CUI.&lt;br /&gt;
|&lt;br /&gt;
* None.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
(2)(i) Table 6 to this paragraph (d)(2)(i) defines the requirements to be met when utilizing an External Service Provider (ESP). The OSA must consider whether the ESP is a Cloud Service Provider (CSP) and whether the ESP processes, stores, or transmits CUI and/ or Security Protection Data (SPD).&lt;br /&gt;
&lt;br /&gt;
==== Table 6 ====&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;margin:auto&amp;quot;&lt;br /&gt;
|+ TABLE 6 TO § 170.19(d)(2)(i) - ESP SCOPING REQUIREMENTS&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;width: 30%;text-align:left&amp;quot; | When the ESP processes, stores, or transmits:&lt;br /&gt;
! style=&amp;quot;width: 35%;text-align:left&amp;quot; | When utilizing an ESP that is a CSP&lt;br /&gt;
! style=&amp;quot;width: 35%;text-align:left&amp;quot; | When utilizing an ESP that is not a CSP&lt;br /&gt;
|- style=&amp;quot;vertical-align:top;&amp;quot;&lt;br /&gt;
| CUI (with or without SPD)&lt;br /&gt;
| The CSP shall meet the FedRAMP requirements in 48 CFR 252.204-7012.&lt;br /&gt;
| The services provided by the ESP are in the OSA’s assessment scope and shall be assessed as part of the OSA’s assessment.&lt;br /&gt;
|- style=&amp;quot;vertical-align:top;&amp;quot;&lt;br /&gt;
| SPD (without CUI)&lt;br /&gt;
| The services provided by the CSP are in the OSA’s assessment scope and shall be assessed as Security Protection Assets.&lt;br /&gt;
| The services provided by the ESP are in the OSA’s assessment scope and shall be assessed as Security Protection Assets.&lt;br /&gt;
|- style=&amp;quot;vertical-align:top;&amp;quot;&lt;br /&gt;
| Neither CUI nor SPD&lt;br /&gt;
| A service provider that does not process CUI or SPD does not meet the CMMC definition of an ESP.&lt;br /&gt;
| A service provider that does not process CUI or SPD does not meet the CMMC definition of an ESP.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
(ii) The use of an ESP, its relationship to the OSC, and the services provided need to be documented in the OSC’s SSP and described in the ESP’s service description and customer responsibility matrix (CRM), which describes the responsibilities of the OSC and ESP with respect to the services provided. Note that the ESP may voluntarily undergo a CMMC certification assessment to reduce the ESP’s effort required during the OSA’s assessment. The minimum. The minimum assessment type for the ESP is dictated by the OSC’s DoD contract requirement.&lt;br /&gt;
&lt;br /&gt;
(e) &#039;&#039;Relationship between Level 2 and Level 3 CMMC Assessment Scope&#039;&#039;. The Level 3 CMMC Assessment Scope must be equal to or a subset of the Level 2 CMMC Assessment Scope in accordance with § 170.18(a) (&#039;&#039;e.g.&#039;&#039;, a Level 3 data enclave with greater restrictions and protections within a Level 2 data enclave). Any Level 2 POA&amp;amp;M items must be closed prior to the initiation of the Level 3 certification assessment. DCMA DIBCAC may check any Level 2 security requirement of any in-scope asset. If DCMA DIBCAC identifies that a Level 2 security requirement is NOT MET, the Level 3 assessment process may be paused to allow for remediation, placed on hold, or immediately terminated. For further information regarding scoping of CMMC Level 3 assessments please contact DCMA DIBCAC at &#039;&#039;www.dcma.mil/DIBCAC/&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
=== § 170.20 Standards acceptance. ===&lt;br /&gt;
&lt;br /&gt;
(a) &#039;&#039;NIST SP 800-171 R2 DoD assessments&#039;&#039;. In order to avoid duplication of efforts, thereby reducing the aggregate cost to industry and the Department, OSCs that have completed a DCMA DIBCAC High Assessment aligned with CMMC Level 2 Scoping will be given the CMMC Status of Final Level 2 (C3PAO) under the following conditions:&lt;br /&gt;
&lt;br /&gt;
(1) &#039;&#039;DCMA DIBCAC High Assessment&#039;&#039;. An OSC that achieved a perfect score with no open POA&amp;amp;M from a DCMA DIBCAC High Assessment conducted prior to the effective date of this rule, will be given a CMMC Status of Level 2 Final (C3PAO) with a validity period of three (3) years from the date of the original DCMA DIBCAC High Assessment. DCMA DIBCAC will identify assessments that meet these criteria and verify that SPRS accurately reflects the CMMC Status. Eligible DCMA DIBCAC High Assessments include ones conducted with Joint Surveillance in accordance with the DCMA Manual 2302-01 Surveillance. The scope of the Level 2 certification assessment is identical to the scope of the DCMA DIBCAC High Assessment. In accordance with § 170.17(a)(2), the OSC must also submit an affirmation in SPRS and annually thereafter to achieve contractual eligibility.&lt;br /&gt;
&lt;br /&gt;
(2) [Reserved].&amp;lt;br&amp;gt;&lt;br /&gt;
(b) [Reserved].&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== § 170.21 Plan of Action and Milestones requirements. ===&lt;br /&gt;
&lt;br /&gt;
(a) &#039;&#039;POA&amp;amp;M&#039;&#039;. For purposes of achieving a Conditional CMMC Status, an OSA is only permitted to have a POA&amp;amp;M for select requirements scored as NOT MET during the CMMC assessment and only under the following conditions:&lt;br /&gt;
&lt;br /&gt;
(1) &#039;&#039;Level 1 self-assessment&#039;&#039;. A POA&amp;amp;M is not permitted at any time for Level 1 self-assessments.&lt;br /&gt;
&lt;br /&gt;
(2) &#039;&#039;Level 2 self-assessment and Level 2 certification assessment&#039;&#039;. An OSA is only permitted to achieve the CMMC Status of Conditional Level 2 (Self) or Conditional Level 2 (C3PAO), as appropriate, if all the following conditions are met:&lt;br /&gt;
&lt;br /&gt;
(i) The assessment score divided by the total number of CMMC Level 2 security requirements is greater than or equal to 0.8;&lt;br /&gt;
&lt;br /&gt;
(ii) None of the security requirements included in the POA&amp;amp;M have a point value of greater than 1 as specified in the CMMC Scoring Methodology set forth in § 170.24, except SC.L2-3.13.11 CUI Encryption may be included on a POA&amp;amp;M if encryption is employed but it is not FIPS-validated, which would result in a point value of 3; and&lt;br /&gt;
&lt;br /&gt;
(iii) None of the following security requirements are included in the POA&amp;amp;M:&lt;br /&gt;
&lt;br /&gt;
(A) AC.L2-3.1.20 External Connections (CUI Data).&amp;lt;br&amp;gt;&lt;br /&gt;
(B) AC.L2-3.1.22 Control Public Information (CUI Data).&amp;lt;br&amp;gt;&lt;br /&gt;
(C) CA.L2-3.12.4 System Security Plan.&amp;lt;br&amp;gt;&lt;br /&gt;
(D) PE.L2-3.10.3 Escort Visitors (CUI Data).&amp;lt;br&amp;gt;&lt;br /&gt;
(E) PE.L2-3.10.4 Physical Access Logs (CUI Data).&amp;lt;br&amp;gt;&lt;br /&gt;
(F) PE.L2-3.10.5 Manage Physical Access (CUI Data).&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
(3) &#039;&#039;Level 3 certification assessment&#039;&#039;. An OSC is only permitted to achieve the CMMC Status of Conditional Level 3 (DIBCAC) if all the following conditions are met:&lt;br /&gt;
&lt;br /&gt;
(i) The assessment score divided by the total number of CMMC Level 3 security requirements is greater than or equal to 0.8; and&lt;br /&gt;
&lt;br /&gt;
(ii) The POA&amp;amp;M does not include any of following security requirements:&lt;br /&gt;
&lt;br /&gt;
(A) IR.L3-3.6.1e Security Operations Center.&amp;lt;br&amp;gt;&lt;br /&gt;
(B) IR.L3-3.6.2e Cyber Incident Response Team.&amp;lt;br&amp;gt;&lt;br /&gt;
(C) RA.L3-3.11.1e Threat-Informed Risk Assessment.&amp;lt;br&amp;gt;&lt;br /&gt;
(D) RA.L3-3.11.6e Supply Chain Risk Response.&amp;lt;br&amp;gt;&lt;br /&gt;
(E) RA.L3-3.11.7e Supply Chain Risk Plan.&amp;lt;br&amp;gt;&lt;br /&gt;
(F) RA.L3-3.11.4e Security Solution Rationale.&amp;lt;br&amp;gt;&lt;br /&gt;
(G) SI.L3-3.14.3e Specialized Asset Security.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
(b) &#039;&#039;POA&amp;amp;M closeout assessment&#039;&#039;. A POA&amp;amp;M closeout assessment is a CMMC assessment that assesses only the NOT MET requirements that were identified with POA&amp;amp;M in the initial assessment. The closing of a POA&amp;amp;M must be confirmed by a POA&amp;amp;M closeout assessment within 180-days of the Conditional CMMC Status Date. If the POA&amp;amp;M is not successfully closed out within the 180-day timeframe, the Conditional CMMC Status for the information system will expire.&lt;br /&gt;
&lt;br /&gt;
(1) &#039;&#039;Level 2 self-assessment&#039;&#039;. For a Level 2 self-assessment, the POA&amp;amp;M closeout self-assessment shall be performed by the OSA in the same manner as the initial self-assessment.&lt;br /&gt;
&lt;br /&gt;
(2) &#039;&#039;Level 2 certification assessment&#039;&#039;. For Level 2 certification assessment, the POA&amp;amp;M closeout certification assessment must be performed by an authorized or accredited C3PAO.&lt;br /&gt;
&lt;br /&gt;
(3) &#039;&#039;Level 3 certification assessment&#039;&#039;. For Level 3 certification assessment, DCMA DIBCAC will perform the POA&amp;amp;M closeout certification assessment.&lt;br /&gt;
&lt;br /&gt;
=== § 170.22 Affirmation. ===&lt;br /&gt;
&lt;br /&gt;
(a) &#039;&#039;General&#039;&#039;. The OSA must affirm continuing compliance with the appropriate level self-assessment or certification assessment. An Affirming Official from each OSA, whether a prime or subcontractor, must affirm the continuing compliance of their respective organizations with the specified security requirement after every assessment, including POA&amp;amp;M closeout, and annually thereafter. Affirmations are entered electronically in SPRS. The affirmation shall be submitted in accordance with the following requirements: &lt;br /&gt;
&lt;br /&gt;
(1) &#039;&#039;Affirming Official&#039;&#039;. The Affirming Official is the senior level representative from within each Organization Seeking Assessment (OSA) who is responsible for ensuring the OSA’s compliance with the CMMC Program requirements and has the authority to affirm the OSA’s continuing compliance with the specified security requirements for their respective organizations.&lt;br /&gt;
&lt;br /&gt;
(2) &#039;&#039;Affirmation content&#039;&#039;. Each CMMC affirmation shall include the following information:&lt;br /&gt;
&lt;br /&gt;
(i) Name, title, and contact information for the Affirming Official; and&lt;br /&gt;
&lt;br /&gt;
(ii) Affirmation statement attesting that the OSA has implemented and will maintain implementation of all applicable CMMC security requirements to their CMMC Status for all information systems within the relevant CMMC Assessment Scope.&lt;br /&gt;
&lt;br /&gt;
(3) &#039;&#039;Affirmation submission&#039;&#039;. The Affirming Official shall submit a CMMC affirmation in the following instances:&lt;br /&gt;
&lt;br /&gt;
(i) Upon achievement of a Conditional CMMC Status, as applicable;&lt;br /&gt;
&lt;br /&gt;
(ii) Upon achievement of a Final CMMC Status;&lt;br /&gt;
&lt;br /&gt;
(iii) Annually following a Final CMMC Status Date; and&lt;br /&gt;
&lt;br /&gt;
(iv) Following a POA&amp;amp;M closeout assessment, as applicable.&lt;br /&gt;
&lt;br /&gt;
(b) &#039;&#039;Submission procedures&#039;&#039;. All affirmations shall be completed in SPRS. The Department will verify submission of the affirmation in SPRS to ensure compliance with CMMC solicitation or contract requirements.&lt;br /&gt;
&lt;br /&gt;
(1) &#039;&#039;Level 1 self-assessment&#039;&#039;. At the &lt;br /&gt;
&lt;br /&gt;
completion of a Level 1 self-assessment and annually thereafter, the Affirming Official shall submit a CMMC affirmation attesting to continuing compliance with all requirements of the CMMC Status Level 1 (Self).&lt;br /&gt;
&lt;br /&gt;
(2) &#039;&#039;Level 2 self-assessment&#039;&#039;. At the &lt;br /&gt;
&lt;br /&gt;
completion of a Level 2 self-assessment and annually following a Final CMMC Status Date, the Affirming Official shall submit a CMMC affirmation attesting to continuing compliance with all requirements of the CMMC Status Level 2 (Self). An affirmation shall also be submitted at the completion of a POA&amp;amp;M closeout self-assessment.&lt;br /&gt;
&lt;br /&gt;
(3) &#039;&#039;Level 2 certification assessment&#039;&#039;. At &lt;br /&gt;
&lt;br /&gt;
the completion of a Level 2 certification assessment and annually following a Final CMMC Status Date, the Affirming Official shall submit a CMMC affirmation attesting to continuing compliance with all requirements of the CMMC Status Level 2 (C3PAO). An affirmation shall also be submitted at the completion of a POA&amp;amp;M closeout certification assessment.&lt;br /&gt;
&lt;br /&gt;
(4) &#039;&#039;Level 3 certification assessment&#039;&#039;. At &lt;br /&gt;
&lt;br /&gt;
the completion of a Level 3 certification assessment and annually following a Final CMMC Status Date, the Affirming Official shall submit a CMMC affirmation attesting to continuing compliance with all requirements of the CMMC Status Level 3 (DIBCAC). Because C3PAOs and DCMA DIBCAC check for compliance with different requirements in their respective assessments, OSCs must annually affirm their CMMC Status of Level 2 (C3PAO) in addition to their CMMC Status of Level 3 (DIBCAC) to maintain eligibility for contracts requiring compliance with Level 3. An affirmation shall also be submitted at the completion of a POA&amp;amp;M closeout certification assessment.&lt;br /&gt;
&lt;br /&gt;
=== § 170.23 Application to subcontractors. ===&lt;br /&gt;
&lt;br /&gt;
(a) CMMC requirements apply to prime contractors and subcontractors throughout the supply chain at all tiers that will process, store, or transmit any FCI or CUI on contractor information systems in the performance of the DoD contract or subcontract. Prime contractors shall comply and shall require subcontractors to comply with and to flow down CMMC requirements, such that compliance will be required throughout the supply chain at all tiers with the applicable CMMC level and assessment type for each subcontract as follows:&lt;br /&gt;
&lt;br /&gt;
(1) If a subcontractor will only process, store, or transmit FCI (and not CUI) in performance of the subcontract, then a CMMC Status of Level 1 (Self) is required for the subcontractor.&lt;br /&gt;
&lt;br /&gt;
(2) If a subcontractor will process, store, or transmit CUI in performance of the subcontract, then a CMMC Status of Level 2 (Self) is the minimum requirement for the subcontractor.&lt;br /&gt;
&lt;br /&gt;
(3) If a subcontractor will process, store, or transmit CUI in performance of the subcontract and the associated prime contract has a requirement for a CMMC Status of Level 2 (C3PAO), then the CMMC Status of Level 2 (C3PAO) is the minimum requirement for the subcontractor.&lt;br /&gt;
&lt;br /&gt;
(4) If a subcontractor will process, store, or transmit CUI in performance of the subcontract and the associated prime contract has a requirement for the CMMC Status of Level 3 (DIBCAC), then the CMMC Status of Level 2 (C3PAO) is the minimum requirement for the subcontractor.&lt;br /&gt;
&lt;br /&gt;
(b) As with any solicitation or contract, the DoD may provide specific guidance pertaining to flow-down.&lt;br /&gt;
&lt;br /&gt;
=== § 170.24 CMMC Scoring Methodology. ===&lt;br /&gt;
&lt;br /&gt;
(a) &#039;&#039;General&#039;&#039;. This scoring methodology is designed to provide a measurement of an OSA’s implementation status of the NIST SP 800-171 R2 security requirements (incorporated by reference elsewhere in this part, see § 170.2) and the selected NIST SP 800-172 Feb2021 security requirements (incorporated by reference elsewhere in this part, see § 170.2). The CMMC Scoring Methodology is designed to credit partial implementation only in limited cases (&#039;&#039;e.g.&#039;&#039;, multi-factor authentication IA.L2-3.5.3).&lt;br /&gt;
&lt;br /&gt;
(b) &#039;&#039;Assessment findings&#039;&#039;. Each security requirement assessed under the CMMC Scoring Methodology must result in one of three possible assessment findings, as follows:&lt;br /&gt;
&lt;br /&gt;
(1) &#039;&#039;Met&#039;&#039;. All applicable objectives for the security requirement are satisfied based on evidence. All evidence must be in final form and not draft. Unacceptable forms of evidence include but are not limited to working papers, drafts, and unofficial or unapproved policies.&lt;br /&gt;
&lt;br /&gt;
(i) Enduring exceptions when described, along with any mitigations, in the system security plan shall be assessed as MET.&lt;br /&gt;
&lt;br /&gt;
(ii) Temporary deficiencies that are appropriately addressed in operational plans of action (&#039;&#039;i.e.&#039;&#039;, include deficiency reviews and show progress towards the implementation of corrections to reduce or eliminate identified vulnerabilities) shall be assessed as MET.&lt;br /&gt;
&lt;br /&gt;
(2) &#039;&#039;Not Met&#039;&#039;. One or more applicable objectives for the security requirement is not satisfied. During an assessment, for each security requirement objective marked NOT MET, the assessor will document why the evidence does not conform.&lt;br /&gt;
&lt;br /&gt;
(3) &#039;&#039;Not Applicable (N/A)&#039;&#039;. A security requirement and/or objective does not apply at the time of the CMMC assessment. For example, Public-Access System Separation (SC.L2-3.13.5) might be N/A if there are no publicly accessible systems within the CMMC Assessment Scope. During an assessment, an assessment objective assessed as N/A is equivalent to the same assessment objective being assessed as MET.&lt;br /&gt;
&lt;br /&gt;
(c) &#039;&#039;Scoring&#039;&#039;. At each CMMC Level, security requirements are scored as follows:&lt;br /&gt;
&lt;br /&gt;
(1) &#039;&#039;CMMC Level 1&#039;&#039;. All CMMC Level 1 security requirements must be fully implemented to be considered MET. No POA&amp;amp;M is permitted for CMMC Level 1, and self-assessment results are scored as MET or NOT MET in their entirety.&lt;br /&gt;
&lt;br /&gt;
(2) &#039;&#039;CMMC Level 2 Scoring Methodology&#039;&#039;. The maximum score achievable for a Level 2 self-assessment or Level 2 certification assessment is equal to the total number of CMMC Level 2 security requirements. If all CMMC Level 2 security requirements are MET, OSAs are awarded the maximum score. For each requirement NOT MET, the associated value of the security requirement is subtracted from the maximum score, which may result in a negative score.&lt;br /&gt;
&lt;br /&gt;
(i) &#039;&#039;Procedures&#039;&#039;. (A) Scoring methodology for Level 2 self-assessment and Level 2 certification assessment is based on all CMMC Level 2 security requirement objectives, including those NOT MET.&lt;br /&gt;
&lt;br /&gt;
(B) In the CMMC Level 2 Scoring Methodology, each security requirement has a value (&#039;&#039;e.g.&#039;&#039;, 1, 3 or 5), which is related to the designation by NIST as basic or derived security requirements. Per NIST SP 800-171 R2, the basic security requirements are obtained from FIPS PUB 200 Mar2006, which provides the high-level and fundamental security requirements for Federal information and systems. The derived security requirements, which supplement the basic security requirements, are taken from the security controls in NIST SP 800-53 R5.&lt;br /&gt;
&lt;br /&gt;
(&#039;&#039;1&#039;&#039;) For NIST SP 800-171 R2 basic and derived security requirements that, if not implemented, could lead to significant exploitation of the network, or exfiltration of CUI, five (5) points are subtracted from the maximum score. The basic and derived security requirements with a value of five (5) points include: &lt;br /&gt;
&lt;br /&gt;
(&#039;&#039;i&#039;&#039;) &#039;&#039;Basic security requirements&#039;&#039;. AC.L2-3.1.1, AC.L2-3.1.2, AT.L2-3.2.1, AT.L2-3.2.2, AU.L2-3.3.1, CM.L2-3.4.1, CM.L2-3.4.2, IA-L2-3.5.1, IA-L2-3.5.2, IR.L2-3.6.1, IR.L2-3.6.2, MA.L2-3.7.2, MP.L2-3.8.3, PS.L2-3.9.2, PE.L2-3.10.1, PE.L2-3.10.2, CA.L2-3.12.1, CA.L2-3.12.3, SC.L2-3.13.1, SC.L2-3.13.2, SI.L2-3.14.1, SI.L2-3.14.2, and SI.L2-3.14.3.&lt;br /&gt;
&lt;br /&gt;
(&#039;&#039;ii&#039;&#039;) &#039;&#039;Derived security requirements&#039;&#039;. AC.L2-3.1.12, AC.L2-3.1.13, AC.L2-3.1.16, AC.L2-3.1.17, AC.L2-3.1.18, AU.L2-3.3.5, CM.L2-3.4.5, CM.L2-3.4.6, CM.L2-3.4.7, CM.L2-3.4.8, IA.L2-3.5.10, MA.L2-3.7.5, MP.L2-3.8.7, RA.L2-3.11.2, SC.L2-3.13.5, SC.L2-3.13.6, SC.L2-3.13.15, SI.L2-3.14.4, and SI.L2-3.14.6.&lt;br /&gt;
&lt;br /&gt;
(&#039;&#039;2&#039;&#039;) For basic and derived security requirements that, if not implemented, have a specific and confined effect on the security of the network and its data, three (3) points are subtracted from the maximum score. The basic and derived security requirements with a value of three (3) points include:&lt;br /&gt;
&lt;br /&gt;
(&#039;&#039;i&#039;&#039;) &#039;&#039;Basic security requirements&#039;&#039;. AU.L2-3.3.2, MA.L2-3.7.1, MP.L2-3.8.1, MP.L2-3.8.2, PS.L2-3.9.1, RA.L2-3.11.1, and CA.L2-3.12.2.&lt;br /&gt;
&lt;br /&gt;
(&#039;&#039;ii&#039;&#039;) &#039;&#039;Derived security requirements&#039;&#039;. AC.L2-3.1.5, AC.L2-3.1.19, MA.L2-3.7.4, MP.L2-3.8.8, SC.L2-3.13.8, SI.L2-3.14.5, and SI.L2-3.14.7.&lt;br /&gt;
&lt;br /&gt;
(&#039;&#039;3&#039;&#039;) All remaining derived security requirements, other than the exceptions noted, if not implemented, have a limited or indirect effect on the security of the network and its data. For these, 1 point is subtracted from the maximum score.&lt;br /&gt;
&lt;br /&gt;
(&#039;&#039;4&#039;&#039;) Two derived security requirements, IA.L2-3.5.3 and SC.L2-3.13.11, can be partially effective even if not completely or properly implemented, and the points deducted may be adjusted depending on how the security requirement is implemented.&lt;br /&gt;
&lt;br /&gt;
(&#039;&#039;i&#039;&#039;) Multi-factor authentication (MFA) (CMMC Level 2 security requirement IA.L2-3.5.3) is typically implemented first for remote and privileged users (since these users are both limited in number and more critical) and then for the general user, so three (3) points are subtracted from the maximum score if MFA is implemented only for remote and privileged users. Five (5) points are subtracted from the maximum score if MFA is not implemented for any users.&lt;br /&gt;
&lt;br /&gt;
(&#039;&#039;ii&#039;&#039;) FIPS-validated encryption (CMMC Level 2 security requirement SC.L2-3.13.11) is required to protect the confidentiality of CUI. If encryption is employed, but is not FIPS-validated, three (3) points are subtracted from the maximum score; if encryption is not employed; five (5) points are subtracted from the maximum score.&lt;br /&gt;
&lt;br /&gt;
(&#039;&#039;5&#039;&#039;) OSAs must have a System Security Plan (SSP) (CMMC security requirement CA.L2-3.12.4) in place at the time of assessment to describe each information system within the CMMC Assessment Scope. The absence of an up to date SSP at the time of the assessment would result in a finding that ‘&#039;&#039;an assessment could not be completed due to incomplete information and noncompliance with 48 CFR 252.204- 7012.&#039;&#039;’&lt;br /&gt;
&lt;br /&gt;
(&#039;&#039;6&#039;&#039;) For each NOT MET security requirement the OSA must have a POA&amp;amp;M in place. A POA&amp;amp;M addressing NOT MET security requirements is not a substitute for a completed requirement. Security requirements not implemented, whether described in a POA&amp;amp;M or not, is assessed as ‘NOT MET.’&lt;br /&gt;
&lt;br /&gt;
(&#039;&#039;7&#039;&#039;) Specialized Assets must be evaluated for their asset category per the CMMC scoping guidance for the level in question and handled accordingly as set forth in § 170.19.&lt;br /&gt;
&lt;br /&gt;
(&#039;&#039;8&#039;&#039;) If an OSC previously received a favorable adjudication from the DoD CIO indicating that a security requirement is not applicable or that an alternative security measure is equally effective (in accordance with 48 CFR 252.204-7008 or 48 CFR 252.204-7012), the DoD CIO adjudication must be included in the system security plan to receive consideration during an assessment. A security requirement for which implemented security measures have been adjudicated by the DoD CIO as equally effective is assessed as MET if there have been no changes in the environment.&lt;br /&gt;
&lt;br /&gt;
(ii) &#039;&#039;CMMC Level 2 Scoring Table&#039;&#039;. CMMC Level 2 scoring has been assigned based on the methodology set forth in table 1 to this paragraph (c)(2)(ii).&lt;br /&gt;
&lt;br /&gt;
==== Table 7 ====&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;margin:auto&amp;quot;&lt;br /&gt;
|+ TABLE 7 TO § 170.24(c)(2)(ii) - CMMC LEVEL 2 SCORING TABLE&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;width: 80%;text-align:left&amp;quot; | CMMC Level 2 requirement categories&lt;br /&gt;
! style=&amp;quot;width: 20%;text-align:right&amp;quot; | Point value subtracted from maximum score&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;2&amp;quot; | &#039;&#039;Basic Security Requirements:&#039;&#039;&lt;br /&gt;
|- style=&amp;quot;vertical-align:top;&amp;quot;&lt;br /&gt;
|&lt;br /&gt;
: If not implemented, could lead to significant exploitation of the network, or exfiltration of CUI&lt;br /&gt;
| style=&amp;quot;text-align:right;&amp;quot; | 5&lt;br /&gt;
|- style=&amp;quot;vertical-align:top;&amp;quot;&lt;br /&gt;
|&lt;br /&gt;
: If not implemented, has specific and confined effect on the security of the network and its data&lt;br /&gt;
| style=&amp;quot;text-align:right;&amp;quot; | 3&lt;br /&gt;
|-&lt;br /&gt;
| colspan=&amp;quot;2&amp;quot; | &#039;&#039;Derived Security Requirements:&#039;&#039;&lt;br /&gt;
|- style=&amp;quot;vertical-align:top;&amp;quot;&lt;br /&gt;
|&lt;br /&gt;
: If not implemented, could lead to significant exploitation of the network, or exfiltration of CUI&lt;br /&gt;
| style=&amp;quot;text-align:right;&amp;quot; | 5&lt;br /&gt;
|- style=&amp;quot;vertical-align:top;&amp;quot;&lt;br /&gt;
|&lt;br /&gt;
: If not completely or properly implemented, could be partially effective and points adjusted depending on how the security requirement is implemented:&lt;br /&gt;
:: - Partially effective implementation - 3 points.&lt;br /&gt;
:: - Non-effective (not implemented at all) - 5 points.&lt;br /&gt;
| style=&amp;quot;text-align:right;&amp;quot; | 3 or 5&lt;br /&gt;
|- style=&amp;quot;vertical-align:top;&amp;quot;&lt;br /&gt;
|&lt;br /&gt;
: If not implemented, has specific and confined effect on the security of the network and its data&lt;br /&gt;
| style=&amp;quot;text-align:right;&amp;quot; | 3 &lt;br /&gt;
|- style=&amp;quot;vertical-align:top;&amp;quot;&lt;br /&gt;
|&lt;br /&gt;
: If not implemented, has a limited or indirect effect on the security of the network and its data&lt;br /&gt;
| style=&amp;quot;text-align:right;&amp;quot; | 1&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
(3) &#039;&#039;CMMC Level 3 assessment scoring methodology&#039;&#039;. CMMC Level 3 scoring does not utilize varying values like the scoring for CMMC Level 2. All CMMC Level 3 security requirements use a value of one (1) point for each security requirement. As a result, the maximum score achievable for a Level 3 certification assessment is equivalent to the total number of the selected subset of NIST SP 800-172 Feb2021 security requirements for CMMC Level 3, see § 170.14(c)(4). The maximum score is reduced by one (1) point for each security requirement NOT MET. The CMMC Level 3 scoring methodology reflects the fact that all CMMC Level 2 security requirements must already be MET (for the Level 3 CMMC Assessment Scope). A maximum score on the Level 2 certification assessment is required to be eligible to initiate a Level 3 certification assessment. The Level 3 certification assessment score is equal to the number of CMMC Level 3 security requirements that are assessed as MET.&lt;br /&gt;
&lt;br /&gt;
=== Appendix A to Part 170 - Guidance ===&lt;br /&gt;
&lt;br /&gt;
Guidance documents include:&lt;br /&gt;
&lt;br /&gt;
(a) ‘‘CMMC Model Overview’’ available at [https://DoDcio.defense.gov/CMMC/ &#039;&#039;https://DoDcio.defense.gov/CMMC/&#039;&#039;.]&lt;br /&gt;
&lt;br /&gt;
(b) ‘‘CMMC Assessment Guide - Level 1’’ available at [https://DoDcio.defense.gov/CMMC/ &#039;&#039;https://DoDcio.defense.gov/CMMC/&#039;&#039;.]&lt;br /&gt;
&lt;br /&gt;
(c) ‘‘CMMC Assessment Guide - Level 2’’ available at [https://DoDcio.defense.gov/CMMC/ &#039;&#039;https://DoDcio.defense.gov/CMMC/&#039;&#039;.]&lt;br /&gt;
&lt;br /&gt;
(d) ‘‘CMMC Assessment Guide - Level 3’’ available at [https://DoDcio.defense.gov/CMMC/ &#039;&#039;https://DoDcio.defense.gov/CMMC/&#039;&#039;.]&lt;br /&gt;
&lt;br /&gt;
(e) ‘‘CMMC Scoping Guide - Level 1’’ available at [https://DoDcio.defense.gov/CMMC/ &#039;&#039;https://DoDcio.defense.gov/CMMC/&#039;&#039;.]&lt;br /&gt;
&lt;br /&gt;
(f) ‘‘CMMC Scoping Guide - Level 2’’ available at [https://DoDcio.defense.gov/CMMC/ &#039;&#039;https://DoDcio.defense.gov/CMMC/&#039;&#039;.]&lt;br /&gt;
&lt;br /&gt;
(g) ‘‘CMMC Scoping Guide - Level 3’’ available at [https://DoDcio.defense.gov/CMMC/ &#039;&#039;https://DoDcio.defense.gov/CMMC/&#039;&#039;.]&lt;br /&gt;
&lt;br /&gt;
(h) ‘‘CMMC Hashing Guide’’ available at [https://DoDcio.defense.gov/CMMC/ &#039;&#039;https://DoDcio.defense.gov/CMMC/&#039;&#039;.]&lt;br /&gt;
&lt;br /&gt;
Dated: September 30, 2024.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Patricia L. Toppings&#039;&#039;, &#039;&#039;&#039;OSD Federal Register Liaison Officer, Department of Defense&#039;&#039;. [FR Doc. 2024-22905 Filed 10-11-24; 8:45 am]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;BILLING CODE 6001-FR-P&#039;&#039;&#039;&lt;/div&gt;</summary>
		<author><name>David</name></author>
	</entry>
	<entry>
		<id>https://cmmcwiki.org/index.php?title=Model_Overview&amp;diff=1602</id>
		<title>Model Overview</title>
		<link rel="alternate" type="text/html" href="https://cmmcwiki.org/index.php?title=Model_Overview&amp;diff=1602"/>
		<updated>2026-03-02T01:33:12Z</updated>

		<summary type="html">&lt;p&gt;David: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&#039;&#039;&#039;Source of Reference: The official [https://dodcio.defense.gov/cmmc/Resources-Documentation/ CMMC Model Overview Version 2.13, September 2024] from the Department of Defense Chief Information Officer (DoD CIO).&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
For inquiries and reporting errors on this wiki, please [mailto:support@cmmcwiki.org contact us]. Thank you.&lt;br /&gt;
&lt;br /&gt;
== NOTICES ==&lt;br /&gt;
&lt;br /&gt;
The contents of this document do not have the force and effect of law and are not meant to bind the public in any way. This document is intended only to provide clarity to the public regarding existing CMMC security requirements under the law or departmental policies.&lt;br /&gt;
&lt;br /&gt;
DISTRIBUTION STATEMENT A. Approved for public release. Distribution is unlimited.&lt;br /&gt;
&lt;br /&gt;
== 1. Introduction ==&lt;br /&gt;
The theft of intellectual property and sensitive information from all industrial sectors because of malicious cyber activity threatens economic security and national security. The Council of Economic Advisors estimates that malicious cyber activity cost the U.S. economy between $57 billion and $109 billion in 2016 [1]. The Center for Strategic and International Studies estimates that the total global cost of cybercrime was as high as $600 billion in 2017 [2]. Over a ten-year period, that burden would equate to an estimated $570 billion to $1.09 trillion dollars in costs.&lt;br /&gt;
&lt;br /&gt;
Malicious cyber actors have targeted and continue to target the Defense Industrial Base (DIB) sector and the Department of Defense (DoD) supply chain. These attacks not only focus on the large prime contractors, but also target subcontractors that make up the lower tiers of the DoD supply chain. Many of these subcontractors are small entities that provide critical support and innovation. Overall, the DIB sector consists of over 220,000 companies&amp;lt;ref&amp;gt;Based on information from the Federal Procurement Data System, the average number of unique prime contractors is approximately 212,657 and the number of known unique subcontractors is approximately 8,309. (FPDS from FY18-FY21).&amp;lt;/ref&amp;gt; that process, store, or transmit Controlled Unclassified Information (CUI) or Federal Contract Information (FCI) in support of the warfighter and contribute towards the research, engineering, development, acquisition, production, delivery, sustainment, and operations of DoD systems, networks, installations, capabilities, and services. The aggregate loss of intellectual property and controlled unclassified information from the DoD supply chain can undercut U.S. technical advantages and innovation, as well as significantly increase the risk to national security.&lt;br /&gt;
&lt;br /&gt;
As part of multiple lines of effort focused on the security and resiliency of the DIB sector, the DoD is working with industry to enforce the safeguarding requirements of the following types of unclassified information within the supply chain:&lt;br /&gt;
* &#039;&#039;Federal Contract Information (FCI):&#039;&#039; is defined in 32 CFR § 170.4 and 48 CFR 4.1901 [3].&lt;br /&gt;
* &#039;&#039;Controlled Unclassified Information (CUI):&#039;&#039; is defined in 32 CFR § 2002.4 (h) [4].&lt;br /&gt;
&lt;br /&gt;
To this end, the Office of the Under Secretary of Defense for Acquisition and Sustainment (OUSD(A&amp;amp;amp;S)) and DoD Chief Information Officer (CIO) have developed the Cybersecurity Maturity Model Certification (CMMC) in concert with DoD stakeholders, University Affiliated Research Centers (UARCs), Federally Funded Research and Development Centers (FFRDCs), and the DIB sector.&lt;br /&gt;
&lt;br /&gt;
This document focuses on the Cybersecurity Maturity Model Certification (CMMC) Model as set forth in section 170.14 of title 32, Code of Federal Regulations (CFR). The model incorporates the security requirements from: 1) FAR 52.204-21, &#039;&#039;Basic Safeguarding of Covered Contractor Information Systems&#039;&#039;, 2) NIST SP 800-171 Rev 2, &#039;&#039;Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations&#039;&#039;, and 3) a subset of the requirements from NIST SP 800-172, &#039;&#039;Enhanced Security Requirements for Protecting Controlled Unclassified Information: A Supplement to NIST Special Publication 800-171&#039;&#039;. The CMMC Program is designed to provide increased assurance to the DoD that defense contractors and subcontractors are compliant with information protection requirements for FCI and CUI, and are protecting such information at a level commensurate with risk from cybersecurity threats, including Advanced Persistent Threats (APTs).&lt;br /&gt;
&lt;br /&gt;
When implementing the CMMC model, an organization can achieve a specific CMMC level for its entire enterprise network or for a particular enclave(s), depending on where the information to be protected is handled and stored.&lt;br /&gt;
&lt;br /&gt;
=== 1.1 Document Organization ===&lt;br /&gt;
Section 2 presents the CMMC Model and each of its elements in detail.[[Model Overview#Appendix A|Appendix A]] provides the model as a matrix and maps the CMMC model to other secondary sources. [[Model Overview#Appendix B|Appendix B]] lists the abbreviations and acronyms. Finally, [[Model Overview#Appendix C|Appendix C]] provides the references contained in this document.&lt;br /&gt;
&lt;br /&gt;
=== 1.2 Supporting Documents ===&lt;br /&gt;
This document is supported by multiple companion documents that provide additional information. The &#039;&#039;CMMC Assessment Guides&#039;&#039; present assessment objectives, discussion, examples, potential assessment considerations, and key references for each CMMC security requirement. The &#039;&#039;CMMC Scoping Guides&#039;&#039; provide additional guidance on how to correctly scope an assessment. The &#039;&#039;CMMC Hashing Guide&#039;&#039; provides information on how to create the hash to validate the integrity of archived assessment artifacts.&lt;br /&gt;
&lt;br /&gt;
These supplemental documents are intended to provide explanatory information to assist organizations with implementing and assessing the security requirements covered by CMMC in 32 CFR § 170. The documents are not prescriptive and their use is optional. Implementation of security requirements by following any examples is not a guarantee of compliance with any CMMC security requirement or objective.&lt;br /&gt;
&lt;br /&gt;
== 2. CMMC Model ==&lt;br /&gt;
=== 2.1 Overview ===&lt;br /&gt;
The CMMC Model incorporates the security requirements from: 1) FAR 52.204-21, &#039;&#039;Basic Safeguarding of Covered Contractor Information Systems&#039;&#039;, 2) NIST SP 800-171 Rev 2, &#039;&#039;Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations&#039;&#039;, and 3) a subset of the requirements from NIST SP 800-172, &#039;&#039;Enhanced Security Requirements for Protecting Controlled Unclassified Information: A Supplement to NIST Special Publication 800—171.&#039;&#039; These source documents may be revised in the future, however the CMMC security requirements will remain unchanged until the CMMC final rule is published. Any further modifications to the CMMC rule will follow appropriate rulemaking procedures.&lt;br /&gt;
&lt;br /&gt;
The CMMC Model consists of domains that map to the Security Requirement Families defined in NIST SP 800-171 Rev 2.&lt;br /&gt;
&lt;br /&gt;
=== 2.2 CMMC Levels ===&lt;br /&gt;
There are three levels within CMMC – Level 1, Level 2, and Level 3.&lt;br /&gt;
&lt;br /&gt;
==== 2.2.1 Descriptions ====&lt;br /&gt;
The CMMC model measures the implementation of cybersecurity requirements at three levels. Each level is independent and consists of a set of CMMC security requirements as set forth in 32 CFR § 170.14 (c):&lt;br /&gt;
* Level 1 Requirements. The security requirements in Level 1 are those set forth in FAR clause 52.204-21(b)(1)(i) – (b)(1)(xv).&lt;br /&gt;
* Level 2 Requirements. The security requirements in Level 2 are identical to the requirements in NIST SP 800-171 Rev 2.&lt;br /&gt;
* Level 3 Requirements. The security requirements in Level 3 are derived from NIST SP 800-172 with DoD-approved parameters where applicable, as identified in 32 CFR § 170.14(c)(4). DoD defined selections and parameters for the NIST SP 800-172 requirements are italicized, where applicable.&lt;br /&gt;
&lt;br /&gt;
==== 2.2.2 CMMC Overview ====&lt;br /&gt;
&#039;&#039;&#039;Figure 1. CMMC Level Overview&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
==== 2.2.3 Level 1 ====&lt;br /&gt;
Level 1 focuses on the protection of FCI and consists of the security requirements that correspond to the 15 basic safeguarding requirements specified in 48 CFR 52.204-21, commonly referred to as the FAR Clause.&lt;br /&gt;
&lt;br /&gt;
==== 2.2.4 Level 2 ====&lt;br /&gt;
Level 2 focuses on the protection of CUI and incorporates the 110 security requirements specified in NIST SP 800-171 Rev 2. &lt;br /&gt;
&lt;br /&gt;
==== 2.2.5 Level 3 ====&lt;br /&gt;
Level 3 focuses on the protection of CUI and encompasses a subset of the NIST SP 800-172 security requirements [5] with DoD-approved parameters. DoD-approved parameters are denoted with &amp;lt;u&amp;gt;underlining&amp;lt;/u&amp;gt; in section 2.4.1 below.&lt;br /&gt;
&lt;br /&gt;
=== 2.3 CMMC Domains ===&lt;br /&gt;
The CMMC model consists of 14 domains that align with the families specified in NIST SP 800-171 Rev 2. These domains and their abbreviations are as follows:&lt;br /&gt;
* Access Control (AC)&lt;br /&gt;
* Awareness &amp;amp; Training (AT)&lt;br /&gt;
* Audit &amp;amp; Accountability (AU)&lt;br /&gt;
* Configuration Management (CM)&lt;br /&gt;
* Identification &amp;amp; Authentication (IA)&lt;br /&gt;
* Incident Response (IR)&lt;br /&gt;
* Maintenance (MA)&lt;br /&gt;
* Media Protection (MP)&lt;br /&gt;
* Personnel Security (PS)&lt;br /&gt;
* Physical Protection (PE)&lt;br /&gt;
* Risk Assessment (RA)&lt;br /&gt;
* Security Assessment (CA)&lt;br /&gt;
* System and Communications Protection (SC)&lt;br /&gt;
* System and Information Integrity (SI)&lt;br /&gt;
&lt;br /&gt;
=== 2.4 CMMC Security Requirements ===&lt;br /&gt;
==== 2.4.1. List of Security Requirements ====&lt;br /&gt;
This subsection itemizes the security requirements for each domain and at each level. Each requirement has a requirement identification number in the format – &#039;&#039;&#039;DD.L#-REQ&#039;&#039;&#039; – where:&lt;br /&gt;
* DD is the two-letter domain abbreviation;&lt;br /&gt;
* L# is the level number; and&lt;br /&gt;
* REQ is the FAR Clause 52.204-21 paragraph number, NIST SP 800-171 Rev 2, or NIST SP800-172 security requirement number.&lt;br /&gt;
&lt;br /&gt;
Below the identification number, a short name identifier is provided for each requirement, meant to be used for quick reference only. Finally, each requirement has a complete requirement statement.&lt;br /&gt;
&lt;br /&gt;
==== Access Control (AC) ====&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;margin:auto&amp;quot;&lt;br /&gt;
|+ &#039;&#039;&#039;ACCESS CONTROL (AC)&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;width: 25%;text-align:left&amp;quot; | &#039;&#039;&#039;Level 1&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 75%;text-align:left&amp;quot; | &#039;&#039;&#039;Description&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|&#039;&#039;&#039;[[ Practice_AC.L2-3.1.1_Details | AC.L1-b.1.i ]]&#039;&#039;&#039;&amp;lt;br&amp;gt;&#039;&#039;Authorized Access Control [FCI Data]&#039;&#039;&lt;br /&gt;
|Limit information system access to authorized users, processes acting on behalf of authorized users, or devices (including other information systems).&lt;br /&gt;
|-&lt;br /&gt;
|&#039;&#039;&#039;[[ Practice_AC.L2-3.1.2_Details | AC.L1-b.1.ii ]]&#039;&#039;&#039;&amp;lt;br&amp;gt;&#039;&#039;Transaction &amp;amp;amp; Function Control [FCI Data]&#039;&#039;&lt;br /&gt;
|Limit information system access to the types of transactions and functions that authorized users are permitted to execute.&lt;br /&gt;
|-&lt;br /&gt;
|&#039;&#039;&#039;[[ Practice_AC.L2-3.1.20_Details | AC.L1-b.1.iii ]]&#039;&#039;&#039;&amp;lt;br&amp;gt;&#039;&#039;External Connections [FCI Data]&#039;&#039;&lt;br /&gt;
|Verify and control/limit connections to and use of external information systems.&lt;br /&gt;
|-&lt;br /&gt;
|&#039;&#039;&#039;[[ Practice_AC.L2-3.1.22_Details | AC.L1-b.1.iv ]]&#039;&#039;&#039;&amp;lt;br&amp;gt;&#039;&#039;Control Public Information [FCI Data]&#039;&#039;&lt;br /&gt;
|Control information posted or processed on publicly accessible information systems.&lt;br /&gt;
|-&lt;br /&gt;
|| &#039;&#039;&#039;Level 2&#039;&#039;&#039; || &#039;&#039;&#039;Description&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|&#039;&#039;&#039;[[ Practice_AC.L2-3.1.1_Details | AC.L2-3.1.1 ]]&#039;&#039;&#039;&amp;lt;br&amp;gt;&#039;&#039;Authorized Access Control [CUI Data]&#039;&#039;&lt;br /&gt;
|Limit system access to authorized users, processes acting on behalf of authorized users, and devices (including other systems).&lt;br /&gt;
|-&lt;br /&gt;
|&#039;&#039;&#039;[[ Practice_AC.L2-3.1.2_Details | AC.L2-3.1.2 ]]&#039;&#039;&#039;&amp;lt;br&amp;gt;&#039;&#039;Transaction &amp;amp;amp; Function Control [CUI Data]&#039;&#039;&lt;br /&gt;
|Limit system access to the types of transactions and functions that authorized users are permitted to execute.&lt;br /&gt;
|-&lt;br /&gt;
|&#039;&#039;&#039;[[ Practice_AC.L2-3.1.3_Details | AC.L2-3.1.3 ]]&#039;&#039;&#039;&amp;lt;br&amp;gt;&#039;&#039;Control CUI Flow&#039;&#039;&lt;br /&gt;
|Control the flow of CUI in accordance with approved authorizations.&lt;br /&gt;
|-&lt;br /&gt;
|&#039;&#039;&#039;[[ Practice_AC.L2-3.1.4_Details | AC.L2-3.1.4 ]]&#039;&#039;&#039;&amp;lt;br&amp;gt;&#039;&#039;Separation of Duties&#039;&#039;&lt;br /&gt;
|Separate the duties of individuals to reduce the risk of malevolent activity without collusion.&lt;br /&gt;
|-&lt;br /&gt;
|&#039;&#039;&#039;[[ Practice_AC.L2-3.1.5_Details | AC.L2-3.1.5 ]]&#039;&#039;&#039;&amp;lt;br&amp;gt;&#039;&#039;Least Privilege&#039;&#039;&lt;br /&gt;
|Employ the principle of least privilege, including for specific security functions and privileged accounts.&lt;br /&gt;
|-&lt;br /&gt;
|&#039;&#039;&#039;[[ Practice_AC.L2-3.1.6_Details | AC.L2-3.1.6 ]]&#039;&#039;&#039;&amp;lt;br&amp;gt;&#039;&#039;Non-Privileged Account Use&#039;&#039;&lt;br /&gt;
|Use non-privileged accounts or roles when accessing nonsecurity functions.&lt;br /&gt;
|-&lt;br /&gt;
|&#039;&#039;&#039;[[ Practice_AC.L2-3.1.7_Details | AC.L2-3.1.7 ]]&#039;&#039;&#039;&amp;lt;br&amp;gt;&#039;&#039;Privileged Functions&#039;&#039;&lt;br /&gt;
|Prevent non-privileged users from executing privileged functions and capture the execution of such functions in audit logs.&lt;br /&gt;
|-&lt;br /&gt;
|&#039;&#039;&#039;[[ Practice_AC.L2-3.1.8_Details | AC.L2-3.1.8 ]]&#039;&#039;&#039;&amp;lt;br&amp;gt;&#039;&#039;Unsuccessful Logon Attempts&#039;&#039;&lt;br /&gt;
|Limit unsuccessful logon attempts.&lt;br /&gt;
|-&lt;br /&gt;
|&#039;&#039;&#039;[[ Practice_AC.L2-3.1.9_Details | AC.L2-3.1.9 ]]&#039;&#039;&#039;&amp;lt;br&amp;gt;&#039;&#039;Privacy &amp;amp; Security Notices&#039;&#039;&lt;br /&gt;
|Provide privacy and security notices consistent with applicable CUI rules.&lt;br /&gt;
|-&lt;br /&gt;
|&#039;&#039;&#039;[[ Practice_AC.L2-3.1.10_Details | AC.L2-3.1.10 ]]&#039;&#039;&#039;&amp;lt;br&amp;gt;&#039;&#039;Session Lock&#039;&#039;&lt;br /&gt;
|Use session lock with pattern-hiding displays to prevent access and viewing of data after a period of inactivity.&lt;br /&gt;
|-&lt;br /&gt;
|&#039;&#039;&#039;[[ Practice_AC.L2-3.1.11_Details | AC.L2-3.1.11 ]]&#039;&#039;&#039;&amp;lt;br&amp;gt;&#039;&#039;Session Termination&#039;&#039;&lt;br /&gt;
|Terminate (automatically) a user session after a defined condition.&lt;br /&gt;
|-&lt;br /&gt;
|&#039;&#039;&#039;[[ Practice_AC.L2-3.1.12_Details | AC.L2-3.1.12 ]]&#039;&#039;&#039;&amp;lt;br&amp;gt;&#039;&#039;Control Remote Access&#039;&#039;&lt;br /&gt;
|Monitor and control remote access sessions.&lt;br /&gt;
|-&lt;br /&gt;
|&#039;&#039;&#039;[[ Practice_AC.L2-3.1.13_Details | AC.L2-3.1.13 ]]&#039;&#039;&#039;&amp;lt;br&amp;gt;&#039;&#039;Remote Access Confidentiality&#039;&#039;&lt;br /&gt;
|Employ cryptographic mechanisms to protect the confidentiality of remote access sessions.&lt;br /&gt;
|-&lt;br /&gt;
|&#039;&#039;&#039;[[ Practice_AC.L2-3.1.14_Details | AC.L2-3.1.14 ]]&#039;&#039;&#039;&amp;lt;br&amp;gt;&#039;&#039;Remote Access Routing&#039;&#039;&lt;br /&gt;
|Route remote access via managed access control points.&lt;br /&gt;
|-&lt;br /&gt;
|&#039;&#039;&#039;[[ Practice_AC.L2-3.1.15_Details | AC.L2-3.1.15 ]]&#039;&#039;&#039;&amp;lt;br&amp;gt;&#039;&#039;Privileged Remote Access&#039;&#039;&lt;br /&gt;
|Authorize remote execution of privileged commands and remote access to security-relevant information.&lt;br /&gt;
|-&lt;br /&gt;
|&#039;&#039;&#039;[[ Practice_AC.L2-3.1.16_Details | AC.L2-3.1.16 ]]&#039;&#039;&#039;&amp;lt;br&amp;gt;&#039;&#039;Wireless Access Authorization&#039;&#039;&lt;br /&gt;
|Authorize wireless access prior to allowing such connections.&lt;br /&gt;
|-&lt;br /&gt;
|&#039;&#039;&#039;[[ Practice_AC.L2-3.1.17_Details | AC.L2-3.1.17 ]]&#039;&#039;&#039;&amp;lt;br&amp;gt;&#039;&#039;Wireless Access Protection&#039;&#039;&lt;br /&gt;
|Protect wireless access using authentication and encryption.&lt;br /&gt;
|-&lt;br /&gt;
|&#039;&#039;&#039;[[ Practice_AC.L2-3.1.18_Details | AC.L2-3.1.18 ]]&#039;&#039;&#039;&amp;lt;br&amp;gt;&#039;&#039;Mobile Device Connection&#039;&#039;&lt;br /&gt;
|Control connection of mobile devices.&lt;br /&gt;
|-&lt;br /&gt;
|&#039;&#039;&#039;[[ Practice_AC.L2-3.1.19_Details | AC.L2-3.1.19 ]]&#039;&#039;&#039;&amp;lt;br&amp;gt;&#039;&#039;Encrypt CUI on Mobile&#039;&#039;&lt;br /&gt;
|Encrypt CUI on mobile devices and mobile computing platforms.&lt;br /&gt;
|-&lt;br /&gt;
|&#039;&#039;&#039;[[ Practice_AC.L2-3.1.20_Details | AC.L2-3.1.20 ]]&#039;&#039;&#039;&amp;lt;br&amp;gt;&#039;&#039;External Connections [CUI Data]&#039;&#039;&lt;br /&gt;
|Verify and control/limit connections to and use of external systems.&lt;br /&gt;
|-&lt;br /&gt;
|&#039;&#039;&#039;[[ Practice_AC.L2-3.1.21_Details | AC.L2-3.1.21 ]]&#039;&#039;&#039;&amp;lt;br&amp;gt;&#039;&#039;Portable Storage Use&#039;&#039;&lt;br /&gt;
|Limit use of portable storage devices on external systems.&lt;br /&gt;
|-&lt;br /&gt;
|&#039;&#039;&#039;[[ Practice_AC.L2-3.1.22_Details | AC.L2-3.1.22 ]]&#039;&#039;&#039;&amp;lt;br&amp;gt;&#039;&#039;Control Public Information [CUI Data] &#039;&#039;&lt;br /&gt;
|Control CUI posted or processed on publicly accessible systems.&lt;br /&gt;
|-&lt;br /&gt;
|| &#039;&#039;&#039;Level 3&#039;&#039;&#039; || &#039;&#039;&#039;Description&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|&#039;&#039;&#039;[[ Practice_AC.L3-3.1.2e_Details | AC.L3-3.1.2e ]]&#039;&#039;&#039;&amp;lt;br&amp;gt;&#039;&#039;Organizationally Controlled Assets&#039;&#039;&lt;br /&gt;
|Restrict access to systems and system components to only those information resources that are owned, provisioned, or issued by the organization.&lt;br /&gt;
|-&lt;br /&gt;
|&#039;&#039;&#039;[[ Practice_AC.L3-3.1.3e_Details | AC.L3-3.1.3e ]]&#039;&#039;&#039;&amp;lt;br&amp;gt;&#039;&#039;Secured Information Transfer&#039;&#039;&lt;br /&gt;
|Employ &amp;lt;u&amp;gt;secure information transfer solutions&amp;lt;/u&amp;gt; to control information flows between security domains on connected systems.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==== Awareness &amp;amp; Training (AT) ====&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;margin:auto&amp;quot;&lt;br /&gt;
|+ &#039;&#039;&#039;AWARENESS AND TRAINING (AT)&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;width: 25%;text-align:left&amp;quot; | &#039;&#039;&#039;Level 2&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 75%;text-align:left&amp;quot; | &#039;&#039;&#039;Description&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
&#039;&#039;&#039;[[ Practice_AT.L2-3.2.1_Details | AT.L2-3.2.1 ]]&#039;&#039;&#039;&amp;lt;br&amp;gt;&#039;&#039;Role-Based Risk Awareness&#039;&#039;&lt;br /&gt;
|Inform managers, systems administrators, and users of organizational systems of the security risks associated with their activities and of the applicable policies, standards, and procedures related to the security of those systems.&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
&#039;&#039;&#039;[[ Practice_AT.L2-3.2.2_Details | AT.L2-3.2.2 ]]&#039;&#039;&#039;&amp;lt;br&amp;gt;&#039;&#039;Role-Based Training&#039;&#039;&lt;br /&gt;
|&lt;br /&gt;
Train personnel to carry out their assigned information security-related duties and responsibilities.&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
&#039;&#039;&#039;[[ Practice_AT.L2-3.2.3_Details | AT.L2-3.2.3 ]]&#039;&#039;&#039;&amp;lt;br&amp;gt;&#039;&#039;Insider Threat Awareness&#039;&#039;&lt;br /&gt;
|&lt;br /&gt;
Provide security awareness training on recognizing and reporting potential indicators of insider threat.&lt;br /&gt;
|-&lt;br /&gt;
|| &#039;&#039;&#039;Level 3 &#039;&#039;&#039; || &#039;&#039;&#039;Description&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
&#039;&#039;&#039;[[ Practice_AT.L3-3.2.1e_Details | AT.L3-3.2.1e ]]&#039;&#039;&#039;&amp;lt;br&amp;gt;&#039;&#039;Advanced Threat Awareness&#039;&#039;&lt;br /&gt;
|&lt;br /&gt;
Provide awareness training &amp;lt;u&amp;gt;upon initial hire, following a significant cyber event, and at least annually&amp;lt;/u&amp;gt;, focused on recognizing and responding to threats from social engineering, advanced persistent threat actors, breaches, and suspicious behaviors; update the training at least annually or when there are significant changes to the threat.&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
&#039;&#039;&#039;[[ Practice_AT.L3-3.2.2e_Details | AT.L3-3.2.2e ]]&#039;&#039;&#039;&amp;lt;br&amp;gt;&#039;&#039;Practical Training Exercises&#039;&#039;&lt;br /&gt;
|&lt;br /&gt;
Include practical exercises in awareness training for &amp;lt;u&amp;gt;all users, tailored by roles, to include general users, users with specialized roles, and privileged users&amp;lt;/u&amp;gt;, that are aligned with current threat scenarios and provide feedback to individuals involved in the training and their supervisors.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==== Audit &amp;amp; Accountability (AU) ====&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;margin:auto&amp;quot;&lt;br /&gt;
|+ &#039;&#039;&#039;AUDIT AND ACCOUNTABILITY (AU)&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;width: 25%;text-align:left&amp;quot; | &#039;&#039;&#039;Level 2&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 75%;text-align:left&amp;quot; | &#039;&#039;&#039;Description&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
&#039;&#039;&#039;[[ Practice_AU.L2-3.3.1_Details | AU.L2-3.3.1 ]]&#039;&#039;&#039;&amp;lt;br&amp;gt;&#039;&#039;System Auditing&#039;&#039;&lt;br /&gt;
|&lt;br /&gt;
Create and retain system audit logs and records to the extent needed to enable the monitoring, analysis, investigation, and reporting of unlawful or unauthorized system activity.&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
&#039;&#039;&#039;[[ Practice_AU.L2-3.3.2_Details | AU.L2-3.3.2 ]]&#039;&#039;&#039;&amp;lt;br&amp;gt;&#039;&#039;User Accountability&#039;&#039;&lt;br /&gt;
|&lt;br /&gt;
Uniquely trace the actions of individual system users, so they can be held accountable for their actions.&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
&#039;&#039;&#039;[[ Practice_AU.L2-3.3.3_Details | AU.L2-3.3.3 ]]&#039;&#039;&#039;&amp;lt;br&amp;gt;&#039;&#039;Event Review&#039;&#039;&lt;br /&gt;
|&lt;br /&gt;
Review and update logged events.&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
&#039;&#039;&#039;[[ Practice_AU.L2-3.3.4_Details | AU.L2-3.3.4 ]]&#039;&#039;&#039;&amp;lt;br&amp;gt;&#039;&#039;Audit Failure Alerting&#039;&#039;&lt;br /&gt;
|&lt;br /&gt;
Alert in the event of an audit logging process failure.&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
&#039;&#039;&#039;[[ Practice_AU.L2-3.3.5_Details | AU.L2-3.3.5 ]]&#039;&#039;&#039;&amp;lt;br&amp;gt;&#039;&#039;Audit Correlation&#039;&#039;&lt;br /&gt;
|&lt;br /&gt;
Correlate audit record review, analysis, and reporting processes for investigation and response to indications of unlawful, unauthorized, suspicious, or unusual activity.&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
&#039;&#039;&#039;[[ Practice_AU.L2-3.3.6_Details | AU.L2-3.3.6 ]]&#039;&#039;&#039;&amp;lt;br&amp;gt;&#039;&#039;Reduction &amp;amp;amp; Reporting&#039;&#039;&lt;br /&gt;
|&lt;br /&gt;
Provide audit record reduction and report generation to support on-demand analysis and reporting.&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
&#039;&#039;&#039;[[ Practice_AU.L2-3.3.7_Details | AU.L2-3.3.7 ]]&#039;&#039;&#039;&amp;lt;br&amp;gt;&#039;&#039;Authoritative Time Source&#039;&#039;&lt;br /&gt;
|&lt;br /&gt;
Provide a system capability that compares and synchronizes internal system clocks with an authoritative source to generate time stamps for audit records.&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
&#039;&#039;&#039;[[ Practice_AU.L2-3.3.8_Details | AU.L2-3.3.8 ]]&#039;&#039;&#039;&amp;lt;br&amp;gt;&#039;&#039;Audit Protection&#039;&#039;&lt;br /&gt;
|&lt;br /&gt;
Protect audit information and audit logging tools from unauthorized access, modification, and deletion.&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
&#039;&#039;&#039;[[ Practice_AU.L2-3.3.9_Details | AU.L2-3.3.9 ]]&#039;&#039;&#039;&amp;lt;br&amp;gt;&#039;&#039;Audit Management&#039;&#039;&lt;br /&gt;
|&lt;br /&gt;
Limit management of audit logging functionality to a subset of privileged users.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==== Configuration Management (CM) ====&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;margin:auto&amp;quot;&lt;br /&gt;
|+ &#039;&#039;&#039;CONFIGURATION MANAGEMENT (CM)&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;width: 25%;text-align:left&amp;quot; | &#039;&#039;&#039;Level 2&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 75%;text-align:left&amp;quot; | &#039;&#039;&#039;Description&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
&#039;&#039;&#039;[[ Practice_CM.L2-3.4.1_Details | CM.L2-3.4.1 ]]&#039;&#039;&#039;&amp;lt;br&amp;gt;&#039;&#039;System Baselining&#039;&#039;&lt;br /&gt;
|&lt;br /&gt;
Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles.&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
&#039;&#039;&#039;[[ Practice_CM.L2-3.4.2_Details | CM.L2-3.4.2 ]]&#039;&#039;&#039;&amp;lt;br&amp;gt;&#039;&#039;Security Configuration Enforcement&#039;&#039;&lt;br /&gt;
|&lt;br /&gt;
Establish and enforce security configuration settings for information technology products employed in organizational systems.&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
&#039;&#039;&#039;[[ Practice_CM.L2-3.4.3_Details | CM.L2-3.4.3 ]]&#039;&#039;&#039;&amp;lt;br&amp;gt;&#039;&#039;System Change Management&#039;&#039;&lt;br /&gt;
|&lt;br /&gt;
Track, review, approve or disapprove, and log changes to organizational systems.&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
&#039;&#039;&#039;[[ Practice_CM.L2-3.4.4_Details | CM.L2-3.4.4 ]]&#039;&#039;&#039;&amp;lt;br&amp;gt;&#039;&#039;Security Impact Analysis&#039;&#039;&lt;br /&gt;
|&lt;br /&gt;
Analyze the security impact of changes prior to implementation.&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
&#039;&#039;&#039;[[ Practice_CM.L2-3.4.5_Details | CM.L2-3.4.5 ]]&#039;&#039;&#039;&amp;lt;br&amp;gt;&#039;&#039;Access Restrictions for Change&#039;&#039;&lt;br /&gt;
|&lt;br /&gt;
Define, document, approve, and enforce physical and logical access restrictions associated with changes to organizational systems.&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
&#039;&#039;&#039;[[ Practice_CM.L2-3.4.6_Details | CM.L2-3.4.6 ]]&#039;&#039;&#039;&amp;lt;br&amp;gt;&#039;&#039;Least Functionality&#039;&#039;&lt;br /&gt;
|&lt;br /&gt;
Employ the principle of least functionality by configuring organizational systems to provide only essential capabilities.&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
&#039;&#039;&#039;[[ Practice_CM.L2-3.4.7_Details | CM.L2-3.4.7 ]]&#039;&#039;&#039;&amp;lt;br&amp;gt;&#039;&#039;Nonessential Functionality&#039;&#039;&lt;br /&gt;
|&lt;br /&gt;
Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services.&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
&#039;&#039;&#039;[[ Practice_CM.L2-3.4.8_Details | CM.L2-3.4.8 ]]&#039;&#039;&#039;&amp;lt;br&amp;gt;&#039;&#039;Application Execution Policy&#039;&#039;&lt;br /&gt;
|&lt;br /&gt;
Apply deny-by-exception (blacklisting) policy to prevent the use of unauthorized software or deny-all, permit-by-exception (whitelisting) policy to allow the execution of authorized software.&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
&#039;&#039;&#039;[[ Practice_CM.L2-3.4.9_Details | CM.L2-3.4.9 ]]&#039;&#039;&#039;&amp;lt;br&amp;gt;&#039;&#039;User-Installed Software&#039;&#039;&lt;br /&gt;
|&lt;br /&gt;
Control and monitor user-installed software.&lt;br /&gt;
|-&lt;br /&gt;
|| &#039;&#039;&#039;Level 3&#039;&#039;&#039; || &#039;&#039;&#039;Description&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
&#039;&#039;&#039;[[ Practice_CM.L3-3.4.1e_Details | CM.L3-3.4.1e ]]&#039;&#039;&#039;&amp;lt;br&amp;gt;&#039;&#039;Authoritative Repository&#039;&#039;&lt;br /&gt;
|&lt;br /&gt;
Establish and maintain an authoritative source and repository to provide a trusted source and accountability for approved and implemented system components.&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
&#039;&#039;&#039;[[ Practice_CM.L3-3.4.2e_Details | CM.L3-3.4.2e ]]&#039;&#039;&#039;&amp;lt;br&amp;gt;&#039;&#039;Automated Detection &amp;amp;amp; Remediation&#039;&#039;&lt;br /&gt;
|&lt;br /&gt;
Employ automated mechanisms to detect misconfigured or unauthorized system components; after detection, &amp;lt;u&amp;gt;remove the components or place the components in a quarantine or remediation network&amp;lt;/u&amp;gt; to facilitate patching, re-configuration, or other mitigations.&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
&#039;&#039;&#039;[[ Practice_CM.L3-3.4.3e_Details | CM.L3-3.4.3e ]]&#039;&#039;&#039;&amp;lt;br&amp;gt;&#039;&#039;Automated Inventory&#039;&#039;&lt;br /&gt;
|&lt;br /&gt;
Employ automated discovery and management tools to maintain an up-to-date, complete, accurate, and readily available inventory of system components.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==== Identification &amp;amp; Authentication (IA) ====&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;margin:auto&amp;quot;&lt;br /&gt;
|+ &#039;&#039;&#039;IDENTIFICATION AND AUTHENTICATION (IA)&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;width: 25%;text-align:left&amp;quot; | &#039;&#039;&#039;Level 1&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 75%;text-align:left&amp;quot; | &#039;&#039;&#039;Description&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
&#039;&#039;&#039;[[ Practice_IA.L2-3.5.1_Details | IA.L1-b.1.v ]]&#039;&#039;&#039;&amp;lt;br&amp;gt;&#039;&#039;Identification [FCI Data]&#039;&#039; &lt;br /&gt;
|&lt;br /&gt;
Identify information system users, processes acting on behalf of users, or devices.&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
&#039;&#039;&#039;[[ Practice_IA.L2-3.5.2_Details | IA.L1-b.1.vi ]]&#039;&#039;&#039;&amp;lt;br&amp;gt;&#039;&#039;Authentication [FCI Data]&#039;&#039;&lt;br /&gt;
|&lt;br /&gt;
Authenticate (or verify) the identities of those users, processes, or devices, as a prerequisite to allowing access to organizational information systems.&lt;br /&gt;
|-&lt;br /&gt;
|| &#039;&#039;&#039;Level 2&#039;&#039;&#039; || &#039;&#039;&#039;Description&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
&#039;&#039;&#039;[[ Practice_IA.L2-3.5.1_Details | IA.L2-3.5.1 ]]&#039;&#039;&#039;&amp;lt;br&amp;gt;&#039;&#039;Identification [CUI Data]&#039;&#039;&lt;br /&gt;
|&lt;br /&gt;
Identify system users, processes acting on behalf of users, and devices.&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
&#039;&#039;&#039;[[ Practice_IA.L2-3.5.2_Details | IA.L2-3.5.2 ]]&#039;&#039;&#039;&amp;lt;br&amp;gt;&#039;&#039;Authentication [CUI Data]&#039;&#039;&lt;br /&gt;
|&lt;br /&gt;
Authenticate (or verify) the identities of users, processes, or devices, as a prerequisite to allowing access to organizational systems.&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
&#039;&#039;&#039;[[ Practice_IA.L2-3.5.3_Details | IA.L2-3.5.3 ]]&#039;&#039;&#039;&amp;lt;br&amp;gt;&#039;&#039;Multifactor Authentication&#039;&#039;&lt;br /&gt;
|&lt;br /&gt;
Use multifactor authentication for local and network access to privileged accounts and for network access to non-privileged accounts.&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
&#039;&#039;&#039;[[ Practice_IA.L2-3.5.4_Details | IA.L2-3.5.4 ]]&#039;&#039;&#039;&amp;lt;br&amp;gt;&#039;&#039;Replay-Resistant Authentication&#039;&#039;&lt;br /&gt;
|&lt;br /&gt;
Employ replay-resistant authentication mechanisms for network access to privileged and non-privileged accounts.&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
&#039;&#039;&#039;[[ Practice_IA.L2-3.5.5_Details | IA.L2-3.5.5 ]]&#039;&#039;&#039;&amp;lt;br&amp;gt;&#039;&#039;Identifier Reuse&#039;&#039;&lt;br /&gt;
|&lt;br /&gt;
Prevent reuse of identifiers for a defined period.&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
&#039;&#039;&#039;[[ Practice_IA.L2-3.5.6_Details | IA.L2-3.5.6 ]]&#039;&#039;&#039;&amp;lt;br&amp;gt;&#039;&#039;Identifier Handling&#039;&#039;&lt;br /&gt;
|&lt;br /&gt;
Disable identifiers after a defined period of inactivity.&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
&#039;&#039;&#039;[[ Practice_IA.L2-3.5.7_Details | IA.L2-3.5.7 ]]&#039;&#039;&#039;&amp;lt;br&amp;gt;&#039;&#039;Password Complexity&#039;&#039;&lt;br /&gt;
|&lt;br /&gt;
Enforce a minimum password complexity and change of characters when new passwords are created.&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
&#039;&#039;&#039;[[ Practice_IA.L2-3.5.8_Details | IA.L2-3.5.8 ]]&#039;&#039;&#039;&amp;lt;br&amp;gt;&#039;&#039;Password Reuse&#039;&#039;&lt;br /&gt;
|&lt;br /&gt;
Prohibit password reuse for a specified number of generations.&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
&#039;&#039;&#039;[[ Practice_IA.L2-3.5.9_Details | IA.L2-3.5.9 ]]&#039;&#039;&#039;&amp;lt;br&amp;gt;&#039;&#039;Temporary Passwords&#039;&#039;&lt;br /&gt;
|&lt;br /&gt;
Allow temporary password use for system logons with an immediate change to a permanent password.&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
&#039;&#039;&#039;[[ Practice_IA.L2-3.5.10_Details | IA.L2-3.5.10 ]]&#039;&#039;&#039;&amp;lt;br&amp;gt;&#039;&#039;Cryptographically-Protected Passwords&#039;&#039;&lt;br /&gt;
|&lt;br /&gt;
Store and transmit only cryptographically protected passwords.&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
&#039;&#039;&#039;[[ Practice_IA.L2-3.5.11_Details | IA.L2-3.5.11 ]]&#039;&#039;&#039;&amp;lt;br&amp;gt;&#039;&#039;Obscure Feedback&#039;&#039;&lt;br /&gt;
|&lt;br /&gt;
Obscure feedback of authentication information.&lt;br /&gt;
|-&lt;br /&gt;
|| &#039;&#039;&#039;Level 3&#039;&#039;&#039; || &#039;&#039;&#039;Description&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
&#039;&#039;&#039;[[ Practice_IA.L3-3.5.1e_Details | IA.L3-3.5.1e ]]&#039;&#039;&#039;&amp;lt;br&amp;gt;&#039;&#039;Bidirectional Authentication&#039;&#039;&lt;br /&gt;
|&lt;br /&gt;
Identify and authenticate &amp;lt;u&amp;gt;systems and system components, where possible&amp;lt;/u&amp;gt;, before establishing a network connection using bidirectional authentication that is cryptographically based and replay resistant.&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
&#039;&#039;&#039;[[ Practice_IA.L3-3.5.3e_Details | IA.L3-3.5.3e ]]&#039;&#039;&#039;&amp;lt;br&amp;gt;&#039;&#039;Block Untrusted Assets&#039;&#039;&lt;br /&gt;
|&lt;br /&gt;
Employ automated or manual/procedural mechanisms to prohibit system components from connecting to organizational systems unless the components are known, authenticated, in a properly configured state, or in a trust profile.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==== Incident Response (IR) ====&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;margin:auto&amp;quot;&lt;br /&gt;
|+ &#039;&#039;&#039;INCIDENT RESPONSE (IR)&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;width: 25%; text-align:left&amp;quot; | &#039;&#039;&#039;Level 2&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 75%; text-align:left&amp;quot; | &#039;&#039;&#039;Description&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
&#039;&#039;&#039;[[ Practice_IR.L2-3.6.1_Details | IR.L2-3.6.1 ]]&#039;&#039;&#039;&amp;lt;br&amp;gt;&#039;&#039;Incident Handling&#039;&#039;&lt;br /&gt;
|&lt;br /&gt;
Establish an operational incident-handling capability for organizational systems that includes preparation, detection, analysis, containment, recovery, and user response activities.&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
&#039;&#039;&#039;[[ Practice_IR.L2-3.6.2_Details | IR.L2-3.6.2 ]]&#039;&#039;&#039;&amp;lt;br&amp;gt;&#039;&#039;Incident Reporting&#039;&#039;&lt;br /&gt;
|&lt;br /&gt;
Track, document, and report incidents to designated officials and/or authorities both internal and external to the organization.&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
&#039;&#039;&#039;[[ Practice_IR.L2-3.6.3_Details | IR.L2-3.6.3 ]]&#039;&#039;&#039;&amp;lt;br&amp;gt;&#039;&#039;Incident Response Testing&#039;&#039;&lt;br /&gt;
|&lt;br /&gt;
Test the organizational incident response capability.&lt;br /&gt;
|-&lt;br /&gt;
|| &#039;&#039;&#039;Level 3&#039;&#039;&#039; || &#039;&#039;&#039;Description&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
&#039;&#039;&#039;[[ Practice_IR.L3-3.6.1e_Details | IR.L3-3.6.1e ]]&#039;&#039;&#039;&amp;lt;br&amp;gt;&#039;&#039;Security Operations Center&#039;&#039;&lt;br /&gt;
|&lt;br /&gt;
Establish and maintain a security operations center capability that operates &amp;lt;u&amp;gt;24/7, with allowance for remote/on-call staff&amp;lt;/u&amp;gt;.&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
&#039;&#039;&#039;[[ Practice_IR.L3-3.6.2e_Details | IR.L3-3.6.2e ]]&#039;&#039;&#039;&amp;lt;br&amp;gt;&#039;&#039;Cyber Incident Response Team&#039;&#039;&lt;br /&gt;
|&lt;br /&gt;
Establish and maintain a cyber incident response team that can be deployed by the organization within &amp;lt;u&amp;gt;24 hours&amp;lt;/u&amp;gt;.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==== Maintenance (MA) ====&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;margin:auto&amp;quot;&lt;br /&gt;
|+ &#039;&#039;&#039;MAINTENANCE (MA)&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;width: 25%;text-align:left&amp;quot; | &#039;&#039;&#039;Level 2&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 75%;text-align:left&amp;quot; | &#039;&#039;&#039;Description&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
&#039;&#039;&#039;[[ Practice_MA.L2-3.7.1_Details | MA.L2-3.7.1 ]]&#039;&#039;&#039;&amp;lt;br&amp;gt;&#039;&#039;Perform Maintenance&#039;&#039;&lt;br /&gt;
|&lt;br /&gt;
Perform maintenance on organizational systems.&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
&#039;&#039;&#039;[[ Practice_MA.L2-3.7.2_Details | MA.L2-3.7.2 ]]&#039;&#039;&#039;&amp;lt;br&amp;gt;&#039;&#039;System Maintenance Control&#039;&#039;&lt;br /&gt;
|&lt;br /&gt;
Provide controls on the tools, techniques, mechanisms, and personnel used to conduct system maintenance.&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
&#039;&#039;&#039;[[ Practice_MA.L2-3.7.3_Details | MA.L2-3.7.3 ]]&#039;&#039;&#039;&amp;lt;br&amp;gt;&#039;&#039;Equipment Sanitization&#039;&#039;&lt;br /&gt;
|&lt;br /&gt;
Sanitize equipment removed for off-site maintenance of any CUI.&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
&#039;&#039;&#039;[[ Practice_MA.L2-3.7.4_Details | MA.L2-3.7.4 ]]&#039;&#039;&#039;&amp;lt;br&amp;gt;&#039;&#039;Media Inspection&#039;&#039;&lt;br /&gt;
|&lt;br /&gt;
Check media containing diagnostic and test programs for malicious code before the media are used in organizational systems.&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
&#039;&#039;&#039;[[ Practice_MA.L2-3.7.5_Details | MA.L2-3.7.5 ]]&#039;&#039;&#039;&amp;lt;br&amp;gt;&#039;&#039;Nonlocal Maintenance&#039;&#039;&lt;br /&gt;
|&lt;br /&gt;
Require multifactor authentication to establish nonlocal maintenance sessions via external network connections and terminate such connections when nonlocal maintenance is complete.&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
&#039;&#039;&#039;[[ Practice_MA.L2-3.7.6_Details | MA.L2-3.7.6 ]]&#039;&#039;&#039;&amp;lt;br&amp;gt;&#039;&#039;Maintenance Personnel&#039;&#039;&lt;br /&gt;
|&lt;br /&gt;
Supervise the maintenance activities of maintenance personnel without required access authorization.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==== Media Protection (MP) ====&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;margin:auto&amp;quot;&lt;br /&gt;
|+ &#039;&#039;&#039;MEDIA PROTECTION (MP)&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;width: 25%;text-align:left&amp;quot; | &#039;&#039;&#039;Level 1&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 75%;text-align:left&amp;quot; | &#039;&#039;&#039;Description&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
&#039;&#039;&#039;[[ Practice_MP.L2-3.8.3_Details | MP.L1-b.1.vii ]]&#039;&#039;&#039;&amp;lt;br&amp;gt;&#039;&#039;Media Disposal [FCI Data]&#039;&#039;&lt;br /&gt;
|&lt;br /&gt;
Sanitize or destroy information system media containing Federal Contract Information before disposal or release for reuse.&lt;br /&gt;
|-&lt;br /&gt;
|| &#039;&#039;&#039;Level 2&#039;&#039;&#039; || &#039;&#039;&#039;Description&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
&#039;&#039;&#039;[[ Practice_MP.L2-3.8.1_Details | MP.L2-3.8.1 ]]&#039;&#039;&#039;&amp;lt;br&amp;gt;&#039;&#039;Media Protection&#039;&#039;&lt;br /&gt;
|&lt;br /&gt;
Protect (i.e., physically control and securely store) system media containing CUI, both paper and digital.&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
&#039;&#039;&#039;[[ Practice_MP.L2-3.8.2_Details | MP.L2-3.8.2 ]]&#039;&#039;&#039;&amp;lt;br&amp;gt;&#039;&#039;Media Access&#039;&#039;&lt;br /&gt;
|&lt;br /&gt;
Limit access to CUI on system media to authorized users.&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
&#039;&#039;&#039;[[ Practice_MP.L2-3.8.3_Details | MP.L2-3.8.3 ]]&#039;&#039;&#039;&amp;lt;br&amp;gt;&#039;&#039;Media Disposal [CUI Data]&#039;&#039;&lt;br /&gt;
|&lt;br /&gt;
Sanitize or destroy system media containing CUI before disposal or release for reuse.&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
&#039;&#039;&#039;[[ Practice_MP.L2-3.8.4_Details | MP.L2-3.8.4 ]]&#039;&#039;&#039;&amp;lt;br&amp;gt;&#039;&#039;Media Markings&#039;&#039;&lt;br /&gt;
|&lt;br /&gt;
Mark media with necessary CUI markings and distribution limitations.&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
&#039;&#039;&#039;[[ Practice_MP.L2-3.8.5_Details | MP.L2-3.8.5 ]]&#039;&#039;&#039;&amp;lt;br&amp;gt;&#039;&#039;Media Accountability&#039;&#039;&lt;br /&gt;
|&lt;br /&gt;
Control access to media containing CUI and maintain accountability for media during transport outside of controlled areas.&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
&#039;&#039;&#039;[[ Practice_MP.L2-3.8.6_Details | MP.L2-3.8.6 ]]&#039;&#039;&#039;&amp;lt;br&amp;gt;&#039;&#039;Portable Storage Encryption&#039;&#039;&lt;br /&gt;
|&lt;br /&gt;
Implement cryptographic mechanisms to protect the confidentiality of CUI stored on digital media during transport unless otherwise protected by alternative physical safeguards.&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
&#039;&#039;&#039;[[ Practice_MP.L2-3.8.7_Details | MP.L2-3.8.7 ]]&#039;&#039;&#039;&amp;lt;br&amp;gt;&#039;&#039;Removable Media&#039;&#039;&lt;br /&gt;
|&lt;br /&gt;
Control the use of removable media on system components.&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
&#039;&#039;&#039;[[ Practice_MP.L2-3.8.8_Details | MP.L2-3.8.8 ]]&#039;&#039;&#039;&amp;lt;br&amp;gt;&#039;&#039;Shared Media&#039;&#039;&lt;br /&gt;
|&lt;br /&gt;
Prohibit the use of portable storage devices when such devices have no identifiable owner.&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
&#039;&#039;&#039;[[ Practice_MP.L2-3.8.9_Details | MP.L2-3.8.9 ]]&#039;&#039;&#039;&amp;lt;br&amp;gt;&#039;&#039;Protect Backups&#039;&#039;&lt;br /&gt;
|&lt;br /&gt;
Protect the confidentiality of backup CUI at storage locations.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==== Personnel Security (PS) ====&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;margin:auto&amp;quot;&lt;br /&gt;
|+ &#039;&#039;&#039;PERSONNEL SECURITY (PS)&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;width: 25%;text-align:left&amp;quot; | &#039;&#039;&#039;Level 2&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 75%;text-align:left&amp;quot; | &#039;&#039;&#039;Description&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
&#039;&#039;&#039;[[ Practice_PS.L2-3.9.1_Details | PS.L2-3.9.1 ]]&#039;&#039;&#039;&amp;lt;br&amp;gt;&#039;&#039;Screen Individuals&#039;&#039;&lt;br /&gt;
|&lt;br /&gt;
Screen individuals prior to authorizing access to organizational systems containing CUI.&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
&#039;&#039;&#039;[[ Practice_PS.L2-3.9.2_Details | PS.L2-3.9.2 ]]&#039;&#039;&#039;&amp;lt;br&amp;gt;&#039;&#039;Personnel Actions&#039;&#039;&lt;br /&gt;
|&lt;br /&gt;
Protect organizational systems containing CUI during and after personnel actions such as terminations and transfers.&lt;br /&gt;
|-&lt;br /&gt;
|| &#039;&#039;&#039;Level 3&#039;&#039;&#039; || &#039;&#039;&#039;Description&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
&#039;&#039;&#039;[[ Practice_PS.L3-3.9.2e_Details | PS.L3-3.9.2e ]]&#039;&#039;&#039;&amp;lt;br&amp;gt;&#039;&#039;Adverse Information&#039;&#039;&lt;br /&gt;
|&lt;br /&gt;
Protect organizational systems when adverse information develops or is obtained about individuals with access to CUI.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==== Physical Protection (PE) ====&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;margin:auto&amp;quot;&lt;br /&gt;
|+ &#039;&#039;&#039;PHYSICAL PROTECTION (PE)&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;width: 25%;text-align:left&amp;quot; | &#039;&#039;&#039;Level 1&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 75%;text-align:left&amp;quot; | &#039;&#039;&#039;Description&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
&#039;&#039;&#039;[[ Practice_PE.L2-3.10.1_Details | PE.L1-b.1.viii ]]&#039;&#039;&#039;&amp;lt;br&amp;gt;&#039;&#039;Limit Physical Access [FCI Data]&#039;&#039;&lt;br /&gt;
|&lt;br /&gt;
Limit physical access to organizational information systems, equipment, and the respective operating environments to authorized individuals.&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
&#039;&#039;&#039;PE.L1-b.1.ix&#039;&#039;&#039;&amp;lt;br&amp;gt;&lt;br /&gt;
&#039;&#039;&#039;[[ Practice_PE.L2-3.10.3_Details | First Phase ]]&#039;&#039;&#039;&amp;lt;br&amp;gt;&lt;br /&gt;
&#039;&#039;&#039;[[ Practice_PE.L2-3.10.4_Details | Second Phase ]]&#039;&#039;&#039;&amp;lt;br&amp;gt;&lt;br /&gt;
&#039;&#039;&#039;[[ Practice_PE.L2-3.10.5_Details | Third Phase ]]&#039;&#039;&#039;&amp;lt;br&amp;gt;&lt;br /&gt;
&#039;&#039;Manage Visitors &amp;amp;amp; Physical Access [FCI Data]&#039;&#039;&lt;br /&gt;
|&lt;br /&gt;
Escort visitors and monitor visitor activity; maintain audit logs of physical access; and control and manage physical access devices.&lt;br /&gt;
|-&lt;br /&gt;
|| &#039;&#039;&#039;Level 2&#039;&#039;&#039; || &#039;&#039;&#039;Description&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
&#039;&#039;&#039;[[ Practice_PE.L2-3.10.1_Details | PE.L2-3.10.1 ]]&#039;&#039;&#039;&amp;lt;br&amp;gt;&#039;&#039;Limit Physical Access [CUI Data]&#039;&#039;&lt;br /&gt;
|&lt;br /&gt;
Limit physical access to organizational systems, equipment, and the respective operating environments to authorized individuals.&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
&#039;&#039;&#039;[[ Practice_PE.L2-3.10.2_Details | PE.L2-3.10.2 ]]&#039;&#039;&#039;&amp;lt;br&amp;gt;&#039;&#039;Monitor Facility&#039;&#039;&lt;br /&gt;
|&lt;br /&gt;
Protect and monitor the physical facility and support infrastructure for organizational systems.&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
&#039;&#039;&#039;[[ Practice_PE.L2-3.10.3_Details | PE.L2-3.10.3 ]]&#039;&#039;&#039;&amp;lt;br&amp;gt;&#039;&#039;Escort Visitors [CUI Data]&#039;&#039;&lt;br /&gt;
|&lt;br /&gt;
Escort visitors and monitor visitor activity.&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
&#039;&#039;&#039;[[ Practice_PE.L2-3.10.4_Details | PE.L2-3.10.4 ]]&#039;&#039;&#039;&amp;lt;br&amp;gt;&#039;&#039;Physical Access Logs [CUI Data]&#039;&#039;&lt;br /&gt;
|&lt;br /&gt;
Maintain audit logs of physical access.&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
&#039;&#039;&#039;[[ Practice_PE.L2-3.10.5_Details | PE.L2-3.10.5 ]]&#039;&#039;&#039;&amp;lt;br&amp;gt;&#039;&#039;Manage Physical Access [CUI Data]&#039;&#039;&lt;br /&gt;
|&lt;br /&gt;
Control and manage physical access devices.&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
&#039;&#039;&#039;[[ Practice_PE.L2-3.10.6_Details | PE.L2-3.10.6 ]]&#039;&#039;&#039;&amp;lt;br&amp;gt;&#039;&#039;Alternative Work Sites&#039;&#039;&lt;br /&gt;
|&lt;br /&gt;
Enforce safeguarding measures for CUI at alternate work sites.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==== Risk Assessment (RA) ====&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;margin:auto&amp;quot;&lt;br /&gt;
|+ &#039;&#039;&#039;RISK ASSESSMENT (RA)&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;width: 25%;text-align:left&amp;quot; | &#039;&#039;&#039;Level 2&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 75%;text-align:left&amp;quot; | &#039;&#039;&#039;Description&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
&#039;&#039;&#039;[[ Practice_RA.L2-3.11.1_Details | RA.L2-3.11.1 ]]&#039;&#039;&#039;&amp;lt;br&amp;gt;&#039;&#039;Risk Assessments&#039;&#039;&lt;br /&gt;
|&lt;br /&gt;
Periodically assess the risk to organizational operations (including mission, functions, image, or reputation), organizational assets, and individuals, resulting from the operation of organizational systems and the associated processing, storage, or transmission of CUI.&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
&#039;&#039;&#039;[[ Practice_RA.L2-3.11.2_Details | RA.L2-3.11.2 ]]&#039;&#039;&#039;&amp;lt;br&amp;gt;&#039;&#039;Vulnerability Scan&#039;&#039;&lt;br /&gt;
|&lt;br /&gt;
Scan for vulnerabilities in organizational systems and applications periodically and when new vulnerabilities affecting those systems and applications are identified.&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
&#039;&#039;&#039;[[ Practice_RA.L2-3.11.3_Details | RA.L2-3.11.3 ]]&#039;&#039;&#039;&amp;lt;br&amp;gt;&#039;&#039;Vulnerability Remediation&#039;&#039;&lt;br /&gt;
|&lt;br /&gt;
Remediate vulnerabilities in accordance with risk assessments.&lt;br /&gt;
|-&lt;br /&gt;
|| &#039;&#039;&#039;Level 3&#039;&#039;&#039; || &#039;&#039;&#039;Description&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
&#039;&#039;&#039;[[ Practice_RA.L3-3.11.1e_Details | RA.L3-3.11.1e ]]&#039;&#039;&#039;&amp;lt;br&amp;gt;&#039;&#039;Threat-Informed Risk Assessment&#039;&#039;&lt;br /&gt;
|&lt;br /&gt;
Employ &amp;lt;u&amp;gt;threat intelligence, at a minimum from open or commercial sources, and any DoD-provided sources&amp;lt;/u&amp;gt;, as part of a risk assessment to guide and inform the development of organizational systems, security architectures, selection of security solutions, monitoring, threat hunting, and response and recovery activities.&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
&#039;&#039;&#039;[[ Practice_RA.L3-3.11.2e_Details | RA.L3-3.11.2e ]]&#039;&#039;&#039;&amp;lt;br&amp;gt;&#039;&#039;Threat Hunting&#039;&#039;&lt;br /&gt;
|&lt;br /&gt;
Conduct cyber threat hunting activities &amp;lt;u&amp;gt;on an on-going aperiodic basis or when indications warrant&amp;lt;/u&amp;gt;, to search for indicators of compromise in &amp;lt;u&amp;gt;organizational systems&amp;lt;/u&amp;gt; and detect, track, and disrupt threats that evade existing controls.&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
&#039;&#039;&#039;[[ Practice_RA.L3-3.11.3e_Details | RA.L3-3.11.3e ]]&#039;&#039;&#039;&amp;lt;br&amp;gt;&#039;&#039;Advanced Risk Identification&#039;&#039;&lt;br /&gt;
|&lt;br /&gt;
Employ advanced automation and analytics capabilities in support of analysts to predict and identify risks to organizations, systems, and system components.&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
&#039;&#039;&#039;[[ Practice_RA.L3-3.11.4e_Details | RA.L3-3.11.4e ]]&#039;&#039;&#039;&amp;lt;br&amp;gt;&#039;&#039;Security Solution Rationale&#039;&#039;&lt;br /&gt;
|&lt;br /&gt;
Document or reference in the system security plan the security solution selected, the rationale for the security solution, and the risk determination.&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
&#039;&#039;&#039;[[ Practice_RA.L3-3.11.5e_Details | RA.L3-3.11.5e ]]&#039;&#039;&#039;&amp;lt;br&amp;gt;&#039;&#039;Security Solution Effectiveness&#039;&#039;&lt;br /&gt;
|&lt;br /&gt;
Assess the effectiveness of security solutions &amp;lt;u&amp;gt;at least annually or upon receipt of relevant cyber threat information, or in response to a relevant cyber incident&amp;lt;/u&amp;gt;, to address anticipated risk to organizational systems and the organization based on current and accumulated threat intelligence.&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
&#039;&#039;&#039;[[ Practice_RA.L3-3.11.6e_Details | RA.L3-3.11.6e ]]&#039;&#039;&#039;&amp;lt;br&amp;gt;&#039;&#039;Supply Chain Risk Response&#039;&#039;&lt;br /&gt;
|&lt;br /&gt;
Assess, respond to, and monitor supply chain risks associated with organizational systems and system components.&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
&#039;&#039;&#039;[[ Practice_RA.L3-3.11.7e_Details | RA.L3-3.11.7e ]]&#039;&#039;&#039;&amp;lt;br&amp;gt;&#039;&#039;Supply Chain Risk Plan&#039;&#039;&lt;br /&gt;
|&lt;br /&gt;
Develop a plan for managing supply chain risks associated with organizational systems and system components; update the plan &amp;lt;u&amp;gt;at least annually, and upon receipt of relevant cyber threat information, or in response to a relevant cyber incident&amp;lt;/u&amp;gt;.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==== Security Assessment (CA) ====&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;margin:auto&amp;quot;&lt;br /&gt;
|+ &#039;&#039;&#039;SECURITY ASSESSMENT (CA)&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;width: 25%;text-align:left&amp;quot; | &#039;&#039;&#039;Level 2&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 75%;text-align:left&amp;quot; | &#039;&#039;&#039;Description&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
&#039;&#039;&#039;[[ Practice_CA.L2-3.12.1_Details | CA.L2-3.12.1 ]]&#039;&#039;&#039;&amp;lt;br&amp;gt;&#039;&#039;Security Control Assessment&#039;&#039;&lt;br /&gt;
|&lt;br /&gt;
Periodically assess the security controls in organizational systems to determine if the controls are effective in their application.&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
&#039;&#039;&#039;[[ Practice_CA.L2-3.12.2_Details | CA.L2-3.12.2 ]]&#039;&#039;&#039;&amp;lt;br&amp;gt;&#039;&#039;Operational Plan of Action&#039;&#039;&lt;br /&gt;
|&lt;br /&gt;
Develop and implement plans of action designed to correct deficiencies and reduce or eliminate vulnerabilities in organizational systems.&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
&#039;&#039;&#039;[[ Practice_CA.L2-3.12.3_Details | CA.L2-3.12.3 ]]&#039;&#039;&#039;&amp;lt;br&amp;gt;&#039;&#039;Security Control Monitoring&#039;&#039;&lt;br /&gt;
|&lt;br /&gt;
Monitor security controls on an ongoing basis to determine the continued effectiveness of the controls.&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
&#039;&#039;&#039;[[ Practice_CA.L2-3.12.4_Details | CA.L2-3.12.4 ]]&#039;&#039;&#039;&amp;lt;br&amp;gt;&#039;&#039;System Security Plan&#039;&#039;&lt;br /&gt;
|&lt;br /&gt;
Develop, document, and periodically update system security plans that describe system boundaries, system environments of operation, how security requirements are implemented, and the relationships with or connections to other systems.&lt;br /&gt;
|-&lt;br /&gt;
|| &#039;&#039;&#039;Level 3&#039;&#039;&#039; || &#039;&#039;&#039;Description&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
&#039;&#039;&#039;[[ Practice_CA.L3-3.12.1e_Details | CA.L3-3.12.1e ]]&#039;&#039;&#039;&amp;lt;br&amp;gt;&#039;&#039;Penetration Testing&#039;&#039;&lt;br /&gt;
|&lt;br /&gt;
Conduct penetration testing &amp;lt;u&amp;gt;at least annually or when significant security changes are made to the system&amp;lt;/u&amp;gt;, leveraging automated scanning tools and ad hoc tests using subject matter experts.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==== System and Communications Protection (SC) ====&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;margin:auto&amp;quot;&lt;br /&gt;
|+ &#039;&#039;&#039;SYSTEM AND COMMUNICATIONS PROTECTION (SC)&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;width: 25%;text-align:left&amp;quot; | &#039;&#039;&#039;Level 1&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 75%;text-align:left&amp;quot; | &#039;&#039;&#039;Description&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
&#039;&#039;&#039;[[ Practice_SC.L2-3.13.1_Details | SC.L1-b.1.x ]]&#039;&#039;&#039;&amp;lt;br&amp;gt;&#039;&#039;Boundary Protection [FCI Data]&#039;&#039;&lt;br /&gt;
|&lt;br /&gt;
Monitor, control, and protect organizational communications (i.e., information transmitted or received by organizational information systems) at the external boundaries and key internal boundaries of the information systems.&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
&#039;&#039;&#039;[[ Practice_SC.L2-3.13.5_Details | SC.L1-b.1.xi ]]&#039;&#039;&#039;&amp;lt;br&amp;gt;&#039;&#039;Public-Access System Separation [FCI Data]&#039;&#039;&lt;br /&gt;
|&lt;br /&gt;
Implement subnetworks for publicly accessible system components that are physically or logically separated from internal networks.&lt;br /&gt;
|-&lt;br /&gt;
|| &#039;&#039;&#039;Level 2&#039;&#039;&#039; || &#039;&#039;&#039;Description&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
&#039;&#039;&#039;[[ Practice_SC.L2-3.13.1_Details | SC.L2-3.13.1 ]]&#039;&#039;&#039;&amp;lt;br&amp;gt;&#039;&#039;Boundary Protection [CUI Data]&#039;&#039;&lt;br /&gt;
|&lt;br /&gt;
Monitor, control, and protect organizational communications (i.e., information transmitted or received by organizational information systems) at the external boundaries and key internal boundaries of the information systems.&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
&#039;&#039;&#039;[[ Practice_SC.L2-3.13.2_Details | SC.L2-3.13.2 ]]&#039;&#039;&#039;&amp;lt;br&amp;gt;&#039;&#039;Security Engineering&#039;&#039;&lt;br /&gt;
|&lt;br /&gt;
Employ architectural designs, software development techniques, and systems engineering principles that promote effective information security within organizational systems.&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
&#039;&#039;&#039;[[ Practice_SC.L2-3.13.3_Details | SC.L2-3.13.3 ]]&#039;&#039;&#039;&amp;lt;br&amp;gt;&#039;&#039;Role Separation&#039;&#039;&lt;br /&gt;
|&lt;br /&gt;
Separate user functionality from system management functionality.&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
&#039;&#039;&#039;[[ Practice_SC.L2-3.13.4_Details | SC.L2-3.13.4 ]]&#039;&#039;&#039;&amp;lt;br&amp;gt;&#039;&#039;Shared Resource Control&#039;&#039;&lt;br /&gt;
|&lt;br /&gt;
Prevent unauthorized and unintended information transfer via shared system resources.&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
&#039;&#039;&#039;[[ Practice_SC.L2-3.13.5_Details | SC.L2-3.13.5 ]]&#039;&#039;&#039;&amp;lt;br&amp;gt;&#039;&#039;Public-Access System Separation [CUI Data]&#039;&#039;&lt;br /&gt;
|&lt;br /&gt;
Implement subnetworks for publicly accessible system components that are physically or logically separated from internal networks.&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
&#039;&#039;&#039;[[ Practice_SC.L2-3.13.6_Details | SC.L2-3.13.6 ]]&#039;&#039;&#039;&amp;lt;br&amp;gt;&#039;&#039;Network Communication by Exception&#039;&#039;&lt;br /&gt;
|&lt;br /&gt;
Deny network communications traffic by default and allow network communications traffic by exception (i.e., deny all, permit by exception).&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
&#039;&#039;&#039;[[ Practice_SC.L2-3.13.7_Details | SC.L2-3.13.7 ]]&#039;&#039;&#039;&amp;lt;br&amp;gt;&#039;&#039;Split Tunneling&#039;&#039;&lt;br /&gt;
|&lt;br /&gt;
Prevent remote devices from simultaneously establishing non-remote connections with organizational systems and communicating via some other connection to resources in external networks (i.e., split tunneling).&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
&#039;&#039;&#039;[[ Practice_SC.L2-3.13.8_Details | SC.L2-3.13.8 ]]&#039;&#039;&#039;&amp;lt;br&amp;gt;&#039;&#039;Data in Transit&#039;&#039;&lt;br /&gt;
|&lt;br /&gt;
Implement cryptographic mechanisms to prevent unauthorized disclosure of CUI during transmission unless otherwise protected by alternative physical safeguards.&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
&#039;&#039;&#039;[[ Practice_SC.L2-3.13.9_Details | SC.L2-3.13.9 ]]&#039;&#039;&#039;&amp;lt;br&amp;gt;&#039;&#039;Connections Termination&#039;&#039;&lt;br /&gt;
|&lt;br /&gt;
Terminate network connections associated with communications sessions at the end of the sessions or after a defined period of inactivity.&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
&#039;&#039;&#039;[[ Practice_SC.L2-3.13.10_Details | SC.L2-3.13.10 ]]&#039;&#039;&#039;&amp;lt;br&amp;gt;&#039;&#039;Key Management&#039;&#039;&lt;br /&gt;
|&lt;br /&gt;
Establish and manage cryptographic keys for cryptography employed in organizational systems.&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
&#039;&#039;&#039;[[ Practice_SC.L2-3.13.11_Details | SC.L2-3.13.11 ]]&#039;&#039;&#039;&amp;lt;br&amp;gt;&#039;&#039;CUI Encryption&#039;&#039;&lt;br /&gt;
|&lt;br /&gt;
Employ FIPS-validated cryptography when used to protect the confidentiality of CUI.&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
&#039;&#039;&#039;[[ Practice_SC.L2-3.13.12_Details | SC.L2-3.13.12 ]]&#039;&#039;&#039;&amp;lt;br&amp;gt;&#039;&#039;Collaborative Device Control&#039;&#039;&lt;br /&gt;
|&lt;br /&gt;
Prohibit remote activation of collaborative computing devices and provide indication of devices in use to users present at the device.&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
&#039;&#039;&#039;[[ Practice_SC.L2-3.13.13_Details | SC.L2-3.13.13 ]]&#039;&#039;&#039;&amp;lt;br&amp;gt;&#039;&#039;Mobile Code&#039;&#039;&lt;br /&gt;
|&lt;br /&gt;
Control and monitor the use of mobile code.&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
&#039;&#039;&#039;[[ Practice_SC.L2-3.13.14_Details | SC.L2-3.13.14 ]]&#039;&#039;&#039;&amp;lt;br&amp;gt;&#039;&#039;Voice over Internet Protocol&#039;&#039;&lt;br /&gt;
|&lt;br /&gt;
Control and monitor the use of Voice over Internet Protocol (VoIP) technologies.&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
&#039;&#039;&#039;[[ Practice_SC.L2-3.13.15_Details | SC.L2-3.13.15 ]]&#039;&#039;&#039;&amp;lt;br&amp;gt;&#039;&#039;Communications Authenticity&#039;&#039;&lt;br /&gt;
|&lt;br /&gt;
Protect the authenticity of communications sessions.&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
&#039;&#039;&#039;[[ Practice_SC.L2-3.13.16_Details | SC.L2-3.13.16 ]]&#039;&#039;&#039;&amp;lt;br&amp;gt;&#039;&#039;Data at Rest&#039;&#039;&lt;br /&gt;
|&lt;br /&gt;
Protect the confidentiality of CUI at rest.&lt;br /&gt;
|-&lt;br /&gt;
|| &#039;&#039;&#039;Level 3&#039;&#039;&#039; || &#039;&#039;&#039;Description&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
&#039;&#039;&#039;[[ Practice_SC.L3-3.13.4e_Details | SC.L3-3.13.4e ]]&#039;&#039;&#039;&amp;lt;br&amp;gt;&#039;&#039;Isolation&#039;&#039;&lt;br /&gt;
|&lt;br /&gt;
Employ physical isolation techniques or logical isolation techniques or both in organizational systems and system components.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==== System and Information Integrity (SI) ====&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;margin:auto&amp;quot;&lt;br /&gt;
|+ &#039;&#039;&#039;SYSTEM AND INFORMATION INTEGRITY (SI)&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;width: 25%;text-align:left&amp;quot; | &#039;&#039;&#039;Level 1&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 75%;text-align:left&amp;quot; | &#039;&#039;&#039;Description&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
&#039;&#039;&#039;[[ Practice_SI.L2-3.14.1_Details | SI.L1-b.1.xii ]]&#039;&#039;&#039;&amp;lt;br&amp;gt;&#039;&#039;Flaw Remediation [FCI Data]&#039;&#039;&lt;br /&gt;
|&lt;br /&gt;
Identify, report, and correct information and information system flaws in a timely manner.&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
&#039;&#039;&#039;[[ Practice_SI.L2-3.14.2_Details | SI.L1-b.1.xiii ]]&#039;&#039;&#039;&amp;lt;br&amp;gt;&#039;&#039;Malicious Code Protection [FCI Data]&#039;&#039;&lt;br /&gt;
|&lt;br /&gt;
Provide protection from malicious code at appropriate locations within organizational information systems.&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
&#039;&#039;&#039;[[ Practice_SI.L2-3.14.4_Details | SI.L1-b.1.xiv ]]&#039;&#039;&#039;&amp;lt;br&amp;gt;&#039;&#039;Update Malicious Code Protection [FCI Data]&#039;&#039;&lt;br /&gt;
|&lt;br /&gt;
Update malicious code protection mechanisms when new releases are available.&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
&#039;&#039;&#039;[[ Practice_SI.L2-3.14.5_Details | SI.L1-b.1.xv ]]&#039;&#039;&#039;&amp;lt;br&amp;gt;&#039;&#039;System &amp;amp; File Scanning [FCI Data]&#039;&#039; &lt;br /&gt;
|&lt;br /&gt;
Perform periodic scans of the information system and real-time scans of files from external sources as files are downloaded, opened, or executed.&lt;br /&gt;
|-&lt;br /&gt;
|| &#039;&#039;&#039;Level 2&#039;&#039;&#039; || &#039;&#039;&#039;Description&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
&#039;&#039;&#039;[[ Practice_SI.L2-3.14.1_Details | SI.L2-3.14.1 ]]&#039;&#039;&#039;&amp;lt;br&amp;gt;&#039;&#039;Flaw Remediation [CUI Data]&#039;&#039;&lt;br /&gt;
|&lt;br /&gt;
Identify, report, and correct system flaws in a timely manner.&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
&#039;&#039;&#039;[[ Practice_SI.L2-3.14.2_Details | SI.L2-3.14.2 ]]&#039;&#039;&#039;&amp;lt;br&amp;gt;&#039;&#039;Malicious Code Protection [CUI Data]&#039;&#039;&lt;br /&gt;
|&lt;br /&gt;
Provide protection from malicious code at designated locations within organizational systems.&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
&#039;&#039;&#039;[[ Practice_SI.L2-3.14.3_Details | SI.L2-3.14.3 ]]&#039;&#039;&#039;&amp;lt;br&amp;gt;&#039;&#039;Security Alerts &amp;amp; Advisories&#039;&#039;&lt;br /&gt;
|&lt;br /&gt;
Monitor system security alerts and advisories and take action in response.&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
&#039;&#039;&#039;[[ Practice_SI.L2-3.14.4_Details | SI.L2-3.14.4 ]]&#039;&#039;&#039;&amp;lt;br&amp;gt;&#039;&#039;Update Malicious Code Protection [CUI Data]&#039;&#039;&lt;br /&gt;
|&lt;br /&gt;
Update malicious code protection mechanisms when new releases are available.&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
&#039;&#039;&#039;[[ Practice_SI.L2-3.14.5_Details | SI.L2-3.14.5 ]]&#039;&#039;&#039;&amp;lt;br&amp;gt;&#039;&#039;System &amp;amp;amp; File Scanning [CUI Data]&#039;&#039;&lt;br /&gt;
|&lt;br /&gt;
Perform periodic scans of organizational systems and real-time scans of files from external sources as files are downloaded, opened, or executed.&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
&#039;&#039;&#039;[[ Practice_SI.L2-3.14.6_Details | SI.L2-3.14.6 ]]&#039;&#039;&#039;&amp;lt;br&amp;gt;&#039;&#039;Monitor Communications for Attacks&#039;&#039;&lt;br /&gt;
|&lt;br /&gt;
Monitor organizational systems, including inbound and outbound communications traffic, to detect attacks and indicators of potential attacks.&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
&#039;&#039;&#039;[[ Practice_SI.L2-3.14.7_Details | SI.L2-3.14.7 ]]&#039;&#039;&#039;&amp;lt;br&amp;gt;&#039;&#039;Identify Unauthorized Use&#039;&#039;&lt;br /&gt;
|&lt;br /&gt;
Identify unauthorized use of organizational systems.&lt;br /&gt;
|-&lt;br /&gt;
|| &#039;&#039;&#039;Level 3&#039;&#039;&#039; || &#039;&#039;&#039;Description&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
&#039;&#039;&#039;[[ Practice_SI.L3-3.14.1e_Details | SI.L3-3.14.1e ]]&#039;&#039;&#039;&amp;lt;br&amp;gt;&#039;&#039;Integrity Verification&#039;&#039;&lt;br /&gt;
|&lt;br /&gt;
Verify the integrity of security critical and essential software using root of trust mechanisms or cryptographic signatures.&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
&#039;&#039;&#039;[[ Practice_SI.L3-3.14.3e_Details | SI.L3-3.14.3e ]]&#039;&#039;&#039;&amp;lt;br&amp;gt;&#039;&#039;Specialized Asset Security&#039;&#039;&lt;br /&gt;
|&lt;br /&gt;
Include specialized assets such as IoT, IIoT, OT, GFE, Restricted Information Systems and test equipment in the scope of the specified enhanced security requirements or are segregated in purpose-specific networks.&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
&#039;&#039;&#039;[[ Practice_SI.L3-3.14.6e_Details | SI.L3-3.14.6e ]]&#039;&#039;&#039;&amp;lt;br&amp;gt;&#039;&#039;Threat-Guided Intrusion Detection&#039;&#039;&lt;br /&gt;
|&lt;br /&gt;
Use threat indicator information and effective mitigations obtained from, at a minimum, open or commercial sources, and any DoD-provided sources, to guide and inform intrusion detection and threat hunting.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Appendix A. ==&lt;br /&gt;
CMMC Model Matrix This appendix presents the model in matrix form by domain. The three columns list the associated security requirements for each CMMC level. Each level is independent and consists of a set of CMMC security requirements:&lt;br /&gt;
* Level 1: the &#039;&#039;basic safeguarding requirements&#039;&#039; for FCI specified in FAR Clause 52.204-21.&lt;br /&gt;
* Level 2: the &#039;&#039;security requirements&#039;&#039; for CUI specified in NIST SP 800-171 Rev 2 per DFARS Clause 252.204-7012&lt;br /&gt;
* Level 3: selected &#039;&#039;enhanced&#039;&#039; &#039;&#039;security requirements&#039;&#039; for CUI specified in NIST SP 800-172 with DoD-approved parameters where applicable.&lt;br /&gt;
&lt;br /&gt;
Each requirement is contained in a single cell. The requirement identification number is bolded at the top of each cell. The next line contains the requirement short name identifier, in &#039;&#039;italics&#039;&#039;, which is meant to be used for quick reference only. Below the short name is the complete CMMC security requirement statement. Some Level 3 requirement statements contain a DoD-approved parameter, which is &amp;lt;u&amp;gt;underlined&amp;lt;/u&amp;gt;. Finally, the bulleted list at the bottom contains the FAR Clause 52.204-21, NIST SP 800-171 Rev 2, and NIST SP 800-172 reference as appropriate.&lt;br /&gt;
&lt;br /&gt;
=== Access Control (AC) ===&lt;br /&gt;
{|class=&amp;quot;wikitable&amp;quot; style=&amp;quot;margin:auto;&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 33%&amp;quot;| Level 1&lt;br /&gt;
! style=&amp;quot;width: 33%&amp;quot;| Level 2&lt;br /&gt;
! style=&amp;quot;width: 33%&amp;quot;| Level 3&lt;br /&gt;
|-&lt;br /&gt;
|&#039;&#039;&#039;[[Practice_AC.L2-3.1.1_Details|AC.L1-b.1.i]]&#039;&#039;&#039;&lt;br /&gt;
&#039;&#039;Authorized Access Control [FCI Data]&#039;&#039;&amp;lt;br&amp;gt;&lt;br /&gt;
Limit information system access to authorized users, processes acting on behalf of authorized users, or devices (including other information systems).&lt;br /&gt;
* FAR Clause 52.204-21 b.1.i&lt;br /&gt;
* NIST SP 800-171 Rev 2 3.1.1&lt;br /&gt;
|&#039;&#039;&#039;[[Practice_AC.L2-3.1.1_Details|AC.L2-3.1.1]]&#039;&#039;&#039;&lt;br /&gt;
&#039;&#039;Authorized Access Control [CUI Data]&#039;&#039;&amp;lt;br&amp;gt;&lt;br /&gt;
Limit information system access to authorized users, processes acting on behalf of authorized users, or devices (including other information systems).&lt;br /&gt;
* NIST SP 800-171 Rev 2 3.1.1&lt;br /&gt;
* FAR Clause 52.204-21 b.1.i&lt;br /&gt;
|&#039;&#039;&#039;[[Practice_AC.L3-3.1.2e_Details|AC.L3-3.1.2e]]&#039;&#039;&#039;&lt;br /&gt;
&#039;&#039;Organizationally Controlled Assets&#039;&#039;&amp;lt;br&amp;gt;&lt;br /&gt;
Restrict access to systems and system components to only those information resources that are owned, provisioned, or issued by the organization.&lt;br /&gt;
* NIST SP 800-172 3.1.2e&lt;br /&gt;
|-&lt;br /&gt;
|&#039;&#039;&#039;[[Practice_AC.L2-3.1.2_Details|AC.L1-b.1.ii]]&#039;&#039;&#039;&lt;br /&gt;
&#039;&#039;Transaction &amp;amp; Function Control [FCI Data]&#039;&#039;&amp;lt;br&amp;gt;&lt;br /&gt;
Limit information system access to the types of transactions and functions that authorized users are permitted to execute.&lt;br /&gt;
* FAR Clause 52.204-21 b.1.ii&lt;br /&gt;
* NIST SP 800-171 Rev 2 3.1.2&lt;br /&gt;
|&#039;&#039;&#039;[[Practice_AC.L2-3.1.2_Details|AC.L2-3.1.2]]&#039;&#039;&#039;&lt;br /&gt;
&#039;&#039;Transaction &amp;amp; Function Control [CUI Data]&#039;&#039;&amp;lt;br&amp;gt;&lt;br /&gt;
Limit information system access to the types of transactions and functions that authorized users are permitted to execute.&lt;br /&gt;
* NIST SP 800-171 Rev 2 3.1.2&lt;br /&gt;
* FAR Clause 52.204-21 b.1.ii&lt;br /&gt;
|&#039;&#039;&#039;[[Practice_AC.L3-3.1.3e_Details|AC.L3-3.1.3e]]&#039;&#039;&#039;&lt;br /&gt;
&#039;&#039;Secured Information Transfer&#039;&#039;&amp;lt;br&amp;gt;&lt;br /&gt;
Employ &amp;lt;u&amp;gt;secure information transfer solutions&amp;lt;/u&amp;gt; to control information flows between security domains on connected systems.&lt;br /&gt;
* NIST SP 800-172 3.1.3e&lt;br /&gt;
|-&lt;br /&gt;
|&#039;&#039;&#039;[[Practice_AC.L2-3.1.20_Details|AC.L1-b.1.iii]]&#039;&#039;&#039;&lt;br /&gt;
&#039;&#039;External Connections [FCI Data]&#039;&#039;&amp;lt;br&amp;gt;&lt;br /&gt;
Verify and control/limit connections to and use of external information systems.&lt;br /&gt;
* FAR Clause 52.204-21 b.1.iii&lt;br /&gt;
* NIST SP 800-171 Rev 2 3.1.20&lt;br /&gt;
|&#039;&#039;&#039;[[Practice_AC.L2-3.1.3_Details|AC.L2-3.1.3]]&#039;&#039;&#039;&lt;br /&gt;
&#039;&#039;Control CUI Flow [CUI Data]&#039;&#039;&amp;lt;br&amp;gt;&lt;br /&gt;
Control the flow of CUI in accordance with approved authorizations.&lt;br /&gt;
* NIST SP 800-171 Rev 2 3.1.3&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|&#039;&#039;&#039;[[Practice_AC.L2-3.1.22_Details|AC.L1-b.1.iv]]&#039;&#039;&#039;&lt;br /&gt;
&#039;&#039;Control Public Information [FCI Data]&#039;&#039;&amp;lt;br&amp;gt;&lt;br /&gt;
Control information posted or processed on publicly accessible information systems.&lt;br /&gt;
* FAR Clause 52.204-21 b.1.iv&lt;br /&gt;
* NIST SP 800-171 Rev 2 3.1.22&lt;br /&gt;
|&#039;&#039;&#039;[[Practice_AC.L2-3.1.4_Details|AC.L2-3.1.4]]&#039;&#039;&#039;&lt;br /&gt;
&#039;&#039;Separation of Duties&#039;&#039;&amp;lt;br&amp;gt;&lt;br /&gt;
Separate the duties of individuals to reduce the risk of malevolent activity without collusion.&lt;br /&gt;
* NIST SP 800-171 Rev 2 3.1.4&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
|&#039;&#039;&#039;[[Practice_AC.L2-3.1.5_Details|AC.L2-3.1.5]]&#039;&#039;&#039;&lt;br /&gt;
&#039;&#039;Least Privilege&#039;&#039;&amp;lt;br&amp;gt;&lt;br /&gt;
Employ the principle of least privilege, including for specific security functions and privileged accounts.&lt;br /&gt;
* NIST SP 800-171 Rev 2 3.1.5&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
|&#039;&#039;&#039;[[Practice_AC.L2-3.1.6_Details|AC.L2-3.1.6]]&#039;&#039;&#039;&lt;br /&gt;
&#039;&#039;Non-Privileged Account Use&#039;&#039;&amp;lt;br&amp;gt;&lt;br /&gt;
Use non-privileged accounts or roles when accessing nonsecurity functions.&lt;br /&gt;
* NIST SP 800-171 Rev 2 3.1.6&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
|&#039;&#039;&#039;[[Practice_AC.L2-3.1.7_Details|AC.L2-3.1.7]]&#039;&#039;&#039;&lt;br /&gt;
&#039;&#039;Privileged Functions&#039;&#039;&amp;lt;br&amp;gt;&lt;br /&gt;
Prevent non-privileged users from executing privileged functions and capture the execution of such functions in audit logs.&lt;br /&gt;
* NIST SP 800-171 Rev 2 3.1.7&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
|&#039;&#039;&#039;[[Practice_AC.L2-3.1.8_Details|AC.L2-3.1.8]]&#039;&#039;&#039;&lt;br /&gt;
&#039;&#039;Unsuccessful Logon Attempts&#039;&#039;&amp;lt;br&amp;gt;&lt;br /&gt;
Limit unsuccessful logon attempts.&lt;br /&gt;
* NIST SP 800-171 Rev 2 3.1.8&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
|&#039;&#039;&#039;[[Practice_AC.L2-3.1.9_Details|AC.L2-3.1.9]]&#039;&#039;&#039;&lt;br /&gt;
&#039;&#039;Privacy &amp;amp; Security Notices&#039;&#039;&amp;lt;br&amp;gt;&lt;br /&gt;
Provide privacy and security notices consistent with applicable CUI rules.&lt;br /&gt;
* NIST SP 800-171 Rev 2 3.1.9&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
|&#039;&#039;&#039;[[Practice_AC.L2-3.1.10_Details|AC.L2-3.1.10]]&#039;&#039;&#039;&lt;br /&gt;
&#039;&#039;Session Lock&#039;&#039;&amp;lt;br&amp;gt;&lt;br /&gt;
Use session lock with pattern-hiding displays to prevent access and viewing of data after a period of inactivity.&lt;br /&gt;
* NIST SP 800-171 Rev 2 3.1.10&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
|&#039;&#039;&#039;[[Practice_AC.L2-3.1.11_Details|AC.L2-3.1.11]]&#039;&#039;&#039;&lt;br /&gt;
&#039;&#039;Session Termination&#039;&#039;&amp;lt;br&amp;gt;&lt;br /&gt;
Terminate (automatically) a user session after a defined condition.&lt;br /&gt;
* NIST SP 800-171 Rev 2 3.1.11&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
|&#039;&#039;&#039;[[Practice_AC.L2-3.1.12_Details|AC.L2-3.1.12]]&#039;&#039;&#039;&lt;br /&gt;
&#039;&#039;Control Remote Access&#039;&#039;&amp;lt;br&amp;gt;&lt;br /&gt;
Monitor and control remote access sessions.&lt;br /&gt;
* NIST SP 800-171 Rev 2 3.1.12&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
|&#039;&#039;&#039;[[Practice_AC.L2-3.1.13_Details|AC.L2-3.1.13]]&#039;&#039;&#039;&lt;br /&gt;
&#039;&#039;Remote Access Confidentiality&#039;&#039;&amp;lt;br&amp;gt;&lt;br /&gt;
Employ cryptographic mechanisms to protect the confidentiality of remote access sessions.&lt;br /&gt;
* NIST SP 800-171 Rev 2 3.1.13&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
|&#039;&#039;&#039;[[Practice_AC.L2-3.1.14_Details|AC.L2-3.1.14]]&#039;&#039;&#039;&lt;br /&gt;
&#039;&#039;Remote Access Routing&#039;&#039;&amp;lt;br&amp;gt;&lt;br /&gt;
Route remote access via managed access&lt;br /&gt;
control points.&lt;br /&gt;
* NIST SP 800-171 Rev 2 3.1.14&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
|&#039;&#039;&#039;[[Practice_AC.L2-3.1.15_Details|AC.L2-3.1.15]]&#039;&#039;&#039;&lt;br /&gt;
&#039;&#039;Privileged Remote Access&#039;&#039;&amp;lt;br&amp;gt;&lt;br /&gt;
Authorize remote execution of privileged commands and remote access to security-relevant information.&lt;br /&gt;
* NIST SP 800-171 Rev 2 3.1.15&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
|&#039;&#039;&#039;[[Practice_AC.L2-3.1.16_Details|AC.L2-3.1.16]]&#039;&#039;&#039;&lt;br /&gt;
&#039;&#039;Wireless Access Authorization&#039;&#039;&amp;lt;br&amp;gt;&lt;br /&gt;
Authorize wireless access prior to allowing&lt;br /&gt;
such connections.&lt;br /&gt;
* NIST SP 800-171 Rev 2 3.1.16&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
|&#039;&#039;&#039;[[Practice_AC.L2-3.1.17_Details|AC.L2-3.1.17]]&#039;&#039;&#039;&lt;br /&gt;
&#039;&#039;Wireless Access Protection&#039;&#039;&amp;lt;br&amp;gt;&lt;br /&gt;
Protect wireless access using authentication and encryption.&lt;br /&gt;
* NIST SP 800-171 Rev 2 3.1.17&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
|&#039;&#039;&#039;[[Practice_AC.L2-3.1.18_Details|AC.L2-3.1.18]]&#039;&#039;&#039;&lt;br /&gt;
&#039;&#039;Mobile Device Connection&#039;&#039;&amp;lt;br&amp;gt;&lt;br /&gt;
Control connection of mobile devices.&lt;br /&gt;
* NIST SP 800-171 Rev 2 3.1.18&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
|&#039;&#039;&#039;[[Practice_AC.L2-3.1.19_Details|AC.L2-3.1.19]]&#039;&#039;&#039;&lt;br /&gt;
&#039;&#039;Encrypt CUI on Mobile&#039;&#039;&amp;lt;br&amp;gt;&lt;br /&gt;
Encrypt CUI on mobile devices and mobile computing platforms.&lt;br /&gt;
* NIST SP 800-171 Rev 2 3.1.19&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
|&#039;&#039;&#039;[[Practice_AC.L2-3.1.20_Details|AC.L2-3.1.20]]&#039;&#039;&#039;&lt;br /&gt;
&#039;&#039;External Connections&#039;&#039;&amp;lt;br&amp;gt;&lt;br /&gt;
Verify and control/limit connections to and use of external information systems.&lt;br /&gt;
* NIST SP 800-171 Rev 2 3.1.20&lt;br /&gt;
* FAR Clause 52.204-21 b.1.iii&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
|&#039;&#039;&#039;[[Practice_AC.L2-3.1.21_Details|AC.L2-3.1.21]]&#039;&#039;&#039;&lt;br /&gt;
&#039;&#039;Portable Storage Use&#039;&#039;&amp;lt;br&amp;gt;&lt;br /&gt;
Limit use of portable storage devices on external systems.&lt;br /&gt;
* NIST SP 800-171 Rev 2 3.1.21&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
|&#039;&#039;&#039;[[Practice_AC.L2-3.1.22_Details|AC.L2-3.1.22]]&#039;&#039;&#039;&lt;br /&gt;
&#039;&#039;Control Public Information&#039;&#039;&amp;lt;br&amp;gt;&lt;br /&gt;
Control information posted or processed on publicly accessible information systems.&lt;br /&gt;
* NIST SP 800-171 Rev 2 3.1.22&lt;br /&gt;
* FAR Clause 52.204-21 b.1.iv&lt;br /&gt;
|&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== Awareness and Training (AT) ===&lt;br /&gt;
{|class=&amp;quot;wikitable&amp;quot; style=&amp;quot;margin:auto;&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 33%&amp;quot;| Level 1&lt;br /&gt;
! style=&amp;quot;width: 33%&amp;quot;| Level 2&lt;br /&gt;
! style=&amp;quot;width: 33%&amp;quot;| Level 3&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
|&#039;&#039;&#039;[[Practice_AT.L2-3.2.1_Details|AT.L2-3.2.1]]&#039;&#039;&#039;&lt;br /&gt;
&#039;&#039;Role-Based Risk Awareness&#039;&#039;&amp;lt;br&amp;gt;&lt;br /&gt;
Ensure that managers, systems administrators, and users of organizational systems are made aware of the security risks associated with their activities and of the applicable policies, standards, and procedures related to the security of those systems.&lt;br /&gt;
* NIST SP 800-171 Rev 2 3.2.1&lt;br /&gt;
|&#039;&#039;&#039;[[Practice_AT.L3-3.2.1e_Details|AT.L3-3.2.1e]]&#039;&#039;&#039;&lt;br /&gt;
&#039;&#039;Advanced Threat Awareness&#039;&#039;&amp;lt;br&amp;gt;&lt;br /&gt;
Provide awareness training &amp;lt;u&amp;gt;upon initial hire, following a significant cyber event, and at least annually&amp;lt;/u&amp;gt;, focused on recognizing and responding to threats from social engineering, advanced persistent threat actors, breaches, and suspicious behaviors; update the training &amp;lt;u&amp;gt;at least annually&amp;lt;/u&amp;gt; or when there are significant changes to the threat.&lt;br /&gt;
* NIST SP 800-172 3.2.1e&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
|&#039;&#039;&#039;[[Practice_AT.L2-3.2.2_Details|AT.L2-3.2.2]]&#039;&#039;&#039;&lt;br /&gt;
&#039;&#039;Role-Based Training&#039;&#039;&amp;lt;br&amp;gt;&lt;br /&gt;
Ensure that personnel are trained to carry out their assigned information security-related duties and responsibilities.&lt;br /&gt;
* NIST SP 800-171 Rev 2 3.2.2&lt;br /&gt;
|&#039;&#039;&#039;[[Practice_AT.L3-3.2.2e_Details|AT.L3-3.2.2e]]&#039;&#039;&#039;&lt;br /&gt;
&#039;&#039;Practical Training Exercises&#039;&#039;&amp;lt;br&amp;gt;&lt;br /&gt;
Include practical exercises in awareness training for &amp;lt;u&amp;gt;all users, tailored by roles, to include general users, users with specialized roles, and privileged users&amp;lt;/u&amp;gt;, that are aligned with current threat scenarios and provide feedback to individuals involved in the training and their supervisors.&lt;br /&gt;
* NIST SP 800-172 3.2.2e&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
|&#039;&#039;&#039;[[Practice_AT.L2-3.2.3_Details|AT.L2-3.2.3]]&#039;&#039;&#039;&lt;br /&gt;
&#039;&#039;Insider Threat Awareness&#039;&#039;&amp;lt;br&amp;gt;&lt;br /&gt;
Provide security awareness training on recognizing and reporting potential indicators of insider threat.&lt;br /&gt;
* NIST SP 800-171 Rev 2 3.2.3 &lt;br /&gt;
|&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== Audit and Accountability (AU) ===&lt;br /&gt;
{|class=&amp;quot;wikitable&amp;quot; style=&amp;quot;margin:auto;&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 33%&amp;quot;| Level 1&lt;br /&gt;
! style=&amp;quot;width: 33%&amp;quot;| Level 2&lt;br /&gt;
! style=&amp;quot;width: 33%&amp;quot;| Level 3&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
|&#039;&#039;&#039;[[Practice_AU.L2-3.3.1_Details|AU.L2-3.3.1]]&#039;&#039;&#039;&lt;br /&gt;
&#039;&#039;System Auditing&#039;&#039;&amp;lt;br&amp;gt;&lt;br /&gt;
Create and retain system audit logs and records to the extent needed to enable the monitoring, analysis, investigation, and reporting of unlawful or unauthorized system activity.&lt;br /&gt;
* NIST SP 800-171 Rev 2 3.3.1&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
|&#039;&#039;&#039;[[Practice_AU.L2-3.3.2_Details|AU.L2-3.3.2]]&#039;&#039;&#039;&lt;br /&gt;
&#039;&#039;User Accountability&#039;&#039;&amp;lt;br&amp;gt;&lt;br /&gt;
Ensure that the actions of individual system users can be uniquely traced to those users, so they can be held accountable for their actions.&lt;br /&gt;
* NIST SP 800-171 Rev 2 3.3.2&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
|&#039;&#039;&#039;[[Practice_AU.L2-3.3.3_Details|AU.L2-3.3.3]]&#039;&#039;&#039;&lt;br /&gt;
&#039;&#039;Event Review&#039;&#039;&amp;lt;br&amp;gt;&lt;br /&gt;
Review and update logged events.&lt;br /&gt;
* NIST SP 800-171 Rev 2 3.3.3&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
|&#039;&#039;&#039;[[Practice_AU.L2-3.3.4_Details|AU.L2-3.3.4]]&#039;&#039;&#039;&lt;br /&gt;
&#039;&#039;Audit Failure Alerting&#039;&#039;&amp;lt;br&amp;gt;&lt;br /&gt;
Alert in the event of an audit logging process failure.&lt;br /&gt;
* NIST SP 800-171 Rev 2 3.3.4&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
|&#039;&#039;&#039;[[Practice_AU.L2-3.3.5_Details|AU.L2-3.3.5]]&#039;&#039;&#039;&lt;br /&gt;
&#039;&#039;Audit Correlation&#039;&#039;&amp;lt;br&amp;gt;&lt;br /&gt;
Correlate audit record review, analysis, and reporting processes for investigation and response to indications of unlawful, unauthorized, suspicious, or unusual activity.&lt;br /&gt;
* NIST SP 800-171 Rev 2 3.3.5&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
|&#039;&#039;&#039;[[Practice_AU.L2-3.3.6_Details|AU.L2-3.3.6]]&#039;&#039;&#039;&lt;br /&gt;
&#039;&#039;Reduction &amp;amp; Reporting&#039;&#039;&amp;lt;br&amp;gt;&lt;br /&gt;
Provide audit record reduction and report generation to support on-demand analysis and reporting.&lt;br /&gt;
* NIST SP 800-171 Rev 2 3.3.6&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
|&#039;&#039;&#039;[[Practice_AU.L2-3.3.7_Details|AU.L2-3.3.7]]&#039;&#039;&#039;&lt;br /&gt;
&#039;&#039;Authoritative Time Source&#039;&#039;&amp;lt;br&amp;gt;&lt;br /&gt;
Provide a system capability that compares and synchronizes internal system clocks with an authoritative source to generate time stamps for audit records.&lt;br /&gt;
* NIST SP 800-171 Rev 2 3.3.7&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
|&#039;&#039;&#039;[[Practice_AU.L2-3.3.8_Details|AU.L2-3.3.8]]&#039;&#039;&#039;&lt;br /&gt;
&#039;&#039;Audit Protection&#039;&#039;&amp;lt;br&amp;gt;&lt;br /&gt;
Protect audit information and audit logging tools from unauthorized access, modification, and deletion.&lt;br /&gt;
* NIST SP 800-171 Rev 2 3.3.8&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
|&#039;&#039;&#039;[[Practice_AU.L2-3.3.9_Details|AU.L2-3.3.9]]&#039;&#039;&#039;&lt;br /&gt;
&#039;&#039;Audit Management&#039;&#039;&amp;lt;br&amp;gt;&lt;br /&gt;
Limit management of audit logging functionality to a subset of privileged users.&lt;br /&gt;
* NIST SP 800-171 Rev 2 3.3.9&lt;br /&gt;
|&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== Configuration Management (CM) ===&lt;br /&gt;
{|class=&amp;quot;wikitable&amp;quot; style=&amp;quot;margin:auto;&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 33%&amp;quot;| Level 1&lt;br /&gt;
! style=&amp;quot;width: 33%&amp;quot;| Level 2&lt;br /&gt;
! style=&amp;quot;width: 33%&amp;quot;| Level 3&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
|&#039;&#039;&#039;[[Practice_CM.L2-3.4.1_Details|CM.L2-3.4.1]]&#039;&#039;&#039;&lt;br /&gt;
&#039;&#039;System Baselining&#039;&#039;&amp;lt;br&amp;gt;&lt;br /&gt;
Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles.&lt;br /&gt;
* NIST SP 800-171 Rev 2 3.4.1&lt;br /&gt;
|&#039;&#039;&#039;[[Practice_CM.L3-3.4.1e_Details|CM.L3-3.4.1e]]&#039;&#039;&#039;&lt;br /&gt;
&#039;&#039;Authoritative Repository&#039;&#039;&lt;br /&gt;
Establish and maintain an authoritative source and repository to provide a trusted source and accountability for approved and implemented system components. &lt;br /&gt;
* NIST SP 800-172 3.4.1e&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
|&#039;&#039;&#039;[[Practice_CM.L2-3.4.2_Details|CM.L2-3.4.2]]&#039;&#039;&#039;&lt;br /&gt;
&#039;&#039;Security Configuration Enforcement&#039;&#039;&amp;lt;br&amp;gt;&lt;br /&gt;
Establish and enforce security configuration settings for information technology products employed in organizational systems.&lt;br /&gt;
* NIST SP 800-171 Rev 2 3.4.2&lt;br /&gt;
|&#039;&#039;&#039;[[Practice_CM.L3-3.4.2e_Details|CM.L3-3.4.2e]]&#039;&#039;&#039;&lt;br /&gt;
Automated Detection &amp;amp; Remediation Employ automated mechanisms to detect misconfigured or unauthorized system components; after detection, &amp;lt;u&amp;gt;remove the components or place the components in a quarantine or remediation network&amp;lt;/u&amp;gt; to facilitate patching, re-configuration, or other mitigations. &lt;br /&gt;
* NIST SP 800-172 3.4.2e&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
|&#039;&#039;&#039;[[Practice_CM.L2-3.4.3_Details|CM.L2-3.4.3]]&#039;&#039;&#039;&lt;br /&gt;
&#039;&#039;System Change Management&#039;&#039;&amp;lt;br&amp;gt;&lt;br /&gt;
Track, review, approve or disapprove, and log changes to organizational systems.&lt;br /&gt;
* NIST SP 800-171 Rev 2 3.4.3&lt;br /&gt;
|&#039;&#039;&#039;[[Practice_CM.L3-3.4.3e_Details|CM.L3-3.4.3e]]&#039;&#039;&#039;&lt;br /&gt;
&#039;&#039;Automated Inventory&#039;&#039;&lt;br /&gt;
Employ automated discovery and management tools to maintain an up-to date, complete, accurate, and readily available inventory of system components.&lt;br /&gt;
* NIST SP 800-172 3.4.3e&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
|&#039;&#039;&#039;[[Practice_CM.L2-3.4.4_Details|CM.L2-3.4.4]]&#039;&#039;&#039;&lt;br /&gt;
&#039;&#039;Security Impact Analysis&#039;&#039;&amp;lt;br&amp;gt;&lt;br /&gt;
Analyze the security impact of changes prior to implementation.&lt;br /&gt;
* NIST SP 800-171 Rev 2 3.4.4&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
|&#039;&#039;&#039;[[Practice_CM.L2-3.4.5_Details|CM.L2-3.4.5]]&#039;&#039;&#039;&lt;br /&gt;
&#039;&#039;Access Restrictions for Change&#039;&#039;&amp;lt;br&amp;gt;&lt;br /&gt;
Define, document, approve, and enforce physical and logical access restrictions associated with changes to organizational systems.&lt;br /&gt;
* NIST SP 800-171 Rev 2 3.4.5&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
|&#039;&#039;&#039;[[Practice_CM.L2-3.4.6_Details|CM.L2-3.4.6]]&#039;&#039;&#039;&lt;br /&gt;
&#039;&#039;Least Functionality&#039;&#039;&amp;lt;br&amp;gt;&lt;br /&gt;
Employ the principle of least functionality by configuring organizational systems to provide only essential capabilities.&lt;br /&gt;
* NIST SP 800-171 Rev 2 3.4.6&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
|&#039;&#039;&#039;[[Practice_CM.L2-3.4.7_Details|CM.L2-3.4.7]]&#039;&#039;&#039;&lt;br /&gt;
&#039;&#039;Nonessential Functionality&#039;&#039;&amp;lt;br&amp;gt;&lt;br /&gt;
Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services.&lt;br /&gt;
* NIST SP 800-171 Rev 2 3.4.7&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
|&#039;&#039;&#039;[[Practice_CM.L2-3.4.8_Details|CM.L2-3.4.8]]&#039;&#039;&#039;&lt;br /&gt;
&#039;&#039;Application Execution Policy&#039;&#039;&amp;lt;br&amp;gt;&lt;br /&gt;
Apply deny-by-exception (blacklisting) policy to prevent the use of unauthorized software or deny-all, permit-by-exception (whitelisting) policy to allow the execution of authorized software.&lt;br /&gt;
* NIST SP 800-171 Rev 2 3.4.8&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
|&#039;&#039;&#039;[[Practice_CM.L2-3.4.9_Details|CM.L2-3.4.9]]&#039;&#039;&#039;&lt;br /&gt;
&#039;&#039;User-Installed Software&#039;&#039;&amp;lt;br&amp;gt;&lt;br /&gt;
Control and monitor user-installed software.&lt;br /&gt;
* NIST SP 800-171 Rev 2 3.4.9&lt;br /&gt;
|&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== Identification and Authentication (IA) ===&lt;br /&gt;
{|class=&amp;quot;wikitable&amp;quot; style=&amp;quot;margin:auto;&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 33%&amp;quot;| Level 1&lt;br /&gt;
! style=&amp;quot;width: 33%&amp;quot;| Level 2&lt;br /&gt;
! style=&amp;quot;width: 33%&amp;quot;| Level 3&lt;br /&gt;
|-&lt;br /&gt;
|&#039;&#039;&#039;[[Practice_IA.L2-3.5.1_Details|IA.L1-b.1.v]]&#039;&#039;&#039;&lt;br /&gt;
&#039;&#039;Identification [FCI Data]&#039;&#039;&amp;lt;br&amp;gt;&lt;br /&gt;
Identify information system users, processes acting on behalf of users, or devices.&lt;br /&gt;
* FAR Clause 52.204-21 b.1.v&lt;br /&gt;
* NIST SP 800-171 Rev 2 3.5.1&lt;br /&gt;
|&#039;&#039;&#039;[[Practice_IA.L2-3.5.1_Details|IA.L2-3.5.1]]&#039;&#039;&#039;&lt;br /&gt;
&#039;&#039;Identification [CUI Data]&#039;&#039;&amp;lt;br&amp;gt;&lt;br /&gt;
Identify information system users, processes acting on behalf of users, or devices.&lt;br /&gt;
* NIST SP 800-171 Rev 2 3.5.1&lt;br /&gt;
* FAR Clause 52.204-21 b.1.v&lt;br /&gt;
|&#039;&#039;&#039;[[Practice_IA.L3-3.5.1e_Details|IA.L3-3.5.1e]]&#039;&#039;&#039;&lt;br /&gt;
&#039;&#039;Bidirectional Authentication&#039;&#039;&amp;lt;br&amp;gt;&lt;br /&gt;
Identify and authenticate &amp;lt;u&amp;gt;systems and system components, where possible&amp;lt;/u&amp;gt;, before establishing a network connection using bidirectional authentication that is cryptographically based and replay resistant.&lt;br /&gt;
* NIST SP 800-172 3.5.1e&lt;br /&gt;
|-&lt;br /&gt;
|&#039;&#039;&#039;[[Practice_IA.L2-3.5.2_Details|IA.L1-b.1.vi]]&#039;&#039;&#039;&lt;br /&gt;
&#039;&#039;Authentication [FCI Data]&#039;&#039;&amp;lt;br&amp;gt;&lt;br /&gt;
Authenticate (or verify) the identities of those users, processes, or devices, as a prerequisite to allowing access to organizational information systems.&lt;br /&gt;
* FAR Clause 52.204-21 b.1.vi&lt;br /&gt;
* NIST SP 800-171 Rev 2 3.5.2&lt;br /&gt;
|&#039;&#039;&#039;[[Practice_IA.L2-3.5.2_Details|IA.L2-3.5.2]]&#039;&#039;&#039;&lt;br /&gt;
&#039;&#039;Authentication [CUI Data]&#039;&#039;&amp;lt;br&amp;gt;&lt;br /&gt;
Authenticate (or verify) the identities of those users, processes, or devices, as a prerequisite to allowing access to organizational information systems.&lt;br /&gt;
* NIST SP 800-171 Rev 2 3.5.2&lt;br /&gt;
* FAR Clause 52.204-21 b.1.vi&lt;br /&gt;
|&#039;&#039;&#039;[[Practice_IA.L3-3.5.3e_Details|IA.L3-3.5.3e]]&#039;&#039;&#039;&lt;br /&gt;
&#039;&#039;Block Untrusted Assets&#039;&#039;&amp;lt;br&amp;gt;&lt;br /&gt;
Employ automated or manual/procedural mechanisms to prohibit system components from connecting to organizational systems unless the components are known, authenticated, in a properly configured state, or in a trust profile.&lt;br /&gt;
* NIST SP 800-172 3.5.3e&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
|&#039;&#039;&#039;[[Practice_IA.L2-3.5.3_Details|IA.L2-3.5.3]]&#039;&#039;&#039;&lt;br /&gt;
&#039;&#039;Multifactor Authentication&#039;&#039;&amp;lt;br&amp;gt;&lt;br /&gt;
Use multifactor authentication for local and network access to privileged accounts and for network access to non-privileged accounts.&lt;br /&gt;
* NIST SP 800-171 Rev 2 3.5.3&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
|&#039;&#039;&#039;[[Practice_IA.L2-3.5.4_Details|IA.L2-3.5.4]]&#039;&#039;&#039;&lt;br /&gt;
&#039;&#039;Replay-Resistant Authentication&#039;&#039;&amp;lt;br&amp;gt;&lt;br /&gt;
Employ replay-resistant authentication mechanisms for network access to privileged and non-privileged accounts.&lt;br /&gt;
* NIST SP 800-171 Rev 2 3.5.4&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
|&#039;&#039;&#039;[[Practice_IA.L2-3.5.5_Details|IA.L2-3.5.5]]&#039;&#039;&#039;&lt;br /&gt;
&#039;&#039;Identifier Reuse&#039;&#039;&amp;lt;br&amp;gt;&lt;br /&gt;
Prevent reuse of identifiers for a defined period.&lt;br /&gt;
* NIST SP 800-171 Rev 2 3.5.5&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
|&#039;&#039;&#039;[[Practice_IA.L2-3.5.6_Details|IA.L2-3.5.6]]&#039;&#039;&#039;&lt;br /&gt;
&#039;&#039;Identifier Handling&#039;&#039;&amp;lt;br&amp;gt;&lt;br /&gt;
Disable identifiers after a defined period of inactivity.&lt;br /&gt;
* NIST SP 800-171 Rev 2 3.5.6&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
|&#039;&#039;&#039;[[Practice_IA.L2-3.5.7_Details|IA.L2-3.5.7]]&#039;&#039;&#039;&lt;br /&gt;
&#039;&#039;Password Complexity&#039;&#039;&amp;lt;br&amp;gt;&lt;br /&gt;
Enforce a minimum password complexity and change of characters when new passwords are created.&lt;br /&gt;
* NIST SP 800-171 Rev 2 3.5.7&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
|&#039;&#039;&#039;[[Practice_IA.L2-3.5.8_Details|IA.L2-3.5.8]]&#039;&#039;&#039;&lt;br /&gt;
&#039;&#039;Password Reuse&#039;&#039;&amp;lt;br&amp;gt;&lt;br /&gt;
Prohibit password reuse for a specified number of generations.&lt;br /&gt;
* NIST SP 800-171 Rev 2 3.5.8&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
|&#039;&#039;&#039;[[Practice_IA.L2-3.5.9_Details|IA.L2-3.5.9]]&#039;&#039;&#039;&lt;br /&gt;
&#039;&#039;Temporary Passwords&#039;&#039;&amp;lt;br&amp;gt;&lt;br /&gt;
Allow temporary password use for system logons with an immediate change to a permanent password.&lt;br /&gt;
* NIST SP 800-171 Rev 2 3.5.9&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
|&#039;&#039;&#039;[[Practice_IA.L2-3.5.10_Details|IA.L2-3.5.10]]&#039;&#039;&#039;&lt;br /&gt;
&#039;&#039;Cryptographically-Protected Passwords&#039;&#039;&lt;br /&gt;
Store and transmit only cryptographically protected passwords.&lt;br /&gt;
* NIST SP 800-171 Rev 2 3.5.10&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
|&#039;&#039;&#039;[[Practice_IA.L2-3.5.11_Details|IA.L2-3.5.11]]&#039;&#039;&#039;&lt;br /&gt;
&#039;&#039;Obscure Feedback&#039;&#039;&amp;lt;br&amp;gt;&lt;br /&gt;
Obscure feedback of authentication information.&lt;br /&gt;
* NIST SP 800-171 Rev 2 3.5.11&lt;br /&gt;
|&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== Incident Response (IR) ===&lt;br /&gt;
{|class=&amp;quot;wikitable&amp;quot; style=&amp;quot;margin:auto;&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 33%&amp;quot;| Level 1&lt;br /&gt;
! style=&amp;quot;width: 33%&amp;quot;| Level 2&lt;br /&gt;
! style=&amp;quot;width: 33%&amp;quot;| Level 3&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
|&#039;&#039;&#039;[[Practice_IR.L2-3.6.1_Details|IR.L2-3.6.1]]&#039;&#039;&#039;&lt;br /&gt;
&#039;&#039;Incident Handling&#039;&#039;&amp;lt;br&amp;gt;&lt;br /&gt;
Establish an operational incident-handling capability for organizational systems that includes preparation, detection, analysis, containment, recovery, and user response activities.&lt;br /&gt;
* NIST SP 800-171 Rev 2 3.6.1&lt;br /&gt;
|&#039;&#039;&#039;[[Practice_IR.L3-3.6.1e_Details|IR.L3-3.6.1e]]&#039;&#039;&#039;&lt;br /&gt;
&#039;&#039;Security Operations Center&#039;&#039;&amp;lt;br&amp;gt;&lt;br /&gt;
Establish and maintain a security operations center capability that operates &amp;lt;u&amp;gt;24/7, with allowance for remote/on-call staff&amp;lt;/u&amp;gt;.&lt;br /&gt;
* NIST SP 800-172 3.6.1e&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
|&#039;&#039;&#039;[[Practice_IR.L2-3.6.2_Details|IR.L2-3.6.2]]&#039;&#039;&#039;&lt;br /&gt;
&#039;&#039;Incident Reporting&#039;&#039;&amp;lt;br&amp;gt;&lt;br /&gt;
Track, document, and report incidents to designated officials and/or authorities both internal and external to the organization.&lt;br /&gt;
* NIST SP 800-171 Rev 2 3.6.2&lt;br /&gt;
|&#039;&#039;&#039;[[Practice_IR.L3-3.6.2e_Details|IR.L3-3.6.2e]]&#039;&#039;&#039;&lt;br /&gt;
&#039;&#039;Cyber Incident Response Team&#039;&#039;&amp;lt;br&amp;gt;&lt;br /&gt;
Establish and maintain a cyber incident response team that can be deployed by the organization within &amp;lt;u&amp;gt;24 hours&amp;lt;/u&amp;gt;.&lt;br /&gt;
* NIST SP 800-172 3.6.2e&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
|&#039;&#039;&#039;[[Practice_IR.L2-3.6.3_Details|IR.L2-3.6.3]]&#039;&#039;&#039;&lt;br /&gt;
&#039;&#039;Incident Response Testing&#039;&#039;&amp;lt;br&amp;gt;&lt;br /&gt;
Test the organizational incident response capability.&lt;br /&gt;
* NIST SP 800-171 Rev 2 3.6.3&lt;br /&gt;
|&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== Maintenance (MA) ===&lt;br /&gt;
{|class=&amp;quot;wikitable&amp;quot; style=&amp;quot;margin:auto;&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 33%&amp;quot;| Level 1&lt;br /&gt;
! style=&amp;quot;width: 33%&amp;quot;| Level 2&lt;br /&gt;
! style=&amp;quot;width: 33%&amp;quot;| Level 3&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
|&#039;&#039;&#039;[[Practice_MA.L2-3.7.1_Details|MA.L2-3.7.1]]&#039;&#039;&#039;&lt;br /&gt;
&#039;&#039;Perform Maintenance&#039;&#039;&amp;lt;br&amp;gt;&lt;br /&gt;
Perform maintenance on organizational systems.&lt;br /&gt;
* NIST SP 800-171 Rev 2 3.7.1&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
|&#039;&#039;&#039;[[Practice_MA.L2-3.7.2_Details|MA.L2-3.7.2]]&#039;&#039;&#039;&lt;br /&gt;
&#039;&#039;System Maintenance Control&#039;&#039;&amp;lt;br&amp;gt;&lt;br /&gt;
Provide controls on the tools, techniques, mechanisms, and personnel used to conduct system maintenance.&lt;br /&gt;
* NIST SP 800-171 Rev 2 3.7.2&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
|&#039;&#039;&#039;[[Practice_MA.L2-3.7.3_Details|MA.L2-3.7.3]]&#039;&#039;&#039;&lt;br /&gt;
&#039;&#039;Equipment Sanitization&#039;&#039;&amp;lt;br&amp;gt;&lt;br /&gt;
Ensure equipment removed for off-site maintenance is sanitized of any CUI.&lt;br /&gt;
* NIST SP 800-171 Rev 2 3.7.3&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
|&#039;&#039;&#039;[[Practice_MA.L2-3.7.4_Details|MA.L2-3.7.4]]&#039;&#039;&#039;&lt;br /&gt;
&#039;&#039;Media Inspection&#039;&#039;&amp;lt;br&amp;gt;&lt;br /&gt;
Check media containing diagnostic and test programs for malicious code before the media are used in organizational systems.&lt;br /&gt;
* NIST SP 800-171 Rev 2 3.7.4&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
|&#039;&#039;&#039;[[Practice_MA.L2-3.7.5_Details|MA.L2-3.7.5]]&#039;&#039;&#039;&lt;br /&gt;
&#039;&#039;Nonlocal Maintenance&#039;&#039;&amp;lt;br&amp;gt;&lt;br /&gt;
Require multifactor authentication to establish nonlocal maintenance sessions via external network connections and terminate such connections when nonlocal maintenance is complete.&lt;br /&gt;
* NIST SP 800-171 Rev 2 3.7.5&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
|&#039;&#039;&#039;[[Practice_MA.L2-3.7.6_Details|MA.L2-3.7.6]]&#039;&#039;&#039;&lt;br /&gt;
&#039;&#039;Maintenance Personnel&#039;&#039;&amp;lt;br&amp;gt;&lt;br /&gt;
Supervise the maintenance activities of maintenance personnel without required access authorization.&lt;br /&gt;
* NIST SP 800-171 Rev 2 3.7.6&lt;br /&gt;
|&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== Media Protection (MP) ===&lt;br /&gt;
{|class=&amp;quot;wikitable&amp;quot; style=&amp;quot;margin:auto;&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 33%&amp;quot;| Level 1&lt;br /&gt;
! style=&amp;quot;width: 33%&amp;quot;| Level 2&lt;br /&gt;
! style=&amp;quot;width: 33%&amp;quot;| Level 3&lt;br /&gt;
|-&lt;br /&gt;
|&#039;&#039;&#039;[[Practice_MP.L2-3.8.3_Details|MP.L1-b.1.vii]]&#039;&#039;&#039;&lt;br /&gt;
&#039;&#039;Media Disposal [FCI Data]&#039;&#039;&amp;lt;br&amp;gt;&lt;br /&gt;
Sanitize or destroy information system media containing Federal Contract Information before disposal or release for reuse.&lt;br /&gt;
* FAR Clause 52.204-21 b.1.vii&lt;br /&gt;
* NIST SP 800-171 Rev 2 3.8.3&lt;br /&gt;
|&#039;&#039;&#039;[[Practice_MP.L2-3.8.1_Details|MP.L2-3.8.1]]&#039;&#039;&#039;&lt;br /&gt;
&#039;&#039;Media Protection&#039;&#039;&amp;lt;br&amp;gt;&lt;br /&gt;
Protect (i.e., physically control and securely store) system media containing CUI, both paper and digital.&lt;br /&gt;
* NIST SP 800-171 Rev 2 3.8.1&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
|&#039;&#039;&#039;[[Practice_MP.L2-3.8.2_Details|MP.L2-3.8.2]]&#039;&#039;&#039;&lt;br /&gt;
&#039;&#039;Media Access&#039;&#039;&amp;lt;br&amp;gt;&lt;br /&gt;
Limit access to CUI on system media to authorized users.&lt;br /&gt;
* NIST SP 800-171 Rev 2 3.8.2&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
|&#039;&#039;&#039;[[Practice_MP.L2-3.8.3_Details|MP.L2-3.8.3]]&#039;&#039;&#039;&lt;br /&gt;
&#039;&#039;Media Disposal [CUI Data]&#039;&#039;&amp;lt;br&amp;gt;&lt;br /&gt;
Sanitize or destroy information system media containing Federal Contract Information before disposal or release for reuse.&lt;br /&gt;
* NIST SP 800-171 Rev 2 3.8.3&lt;br /&gt;
* FAR Clause 52.204-21 b.1.vii&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
|&#039;&#039;&#039;[[Practice_MP.L2-3.8.4_Details|MP.L2-3.8.4]]&#039;&#039;&#039;&lt;br /&gt;
&#039;&#039;Media Markings&#039;&#039;&amp;lt;br&amp;gt;&lt;br /&gt;
Mark media with necessary CUI markings and distribution limitations.&lt;br /&gt;
* NIST SP 800-171 Rev 2 3.8.4&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
|&#039;&#039;&#039;[[Practice_MP.L2-3.8.5_Details|MP.L2-3.8.5]]&#039;&#039;&#039;&lt;br /&gt;
&#039;&#039;Media Accountability&#039;&#039;&amp;lt;br&amp;gt;&lt;br /&gt;
Control access to media containing CUI and maintain accountability for media during transport outside of controlled areas.&lt;br /&gt;
* NIST SP 800-171 Rev 2 3.8.5&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
|&#039;&#039;&#039;[[Practice_MP.L2-3.8.6_Details|MP.L2-3.8.6]]&#039;&#039;&#039;&lt;br /&gt;
&#039;&#039;Portable Storage Encryption&#039;&#039;&amp;lt;br&amp;gt;&lt;br /&gt;
Implement cryptographic mechanisms to protect the confidentiality of CUI stored on digital media during transport unless otherwise protected by alternative physical safeguards.&lt;br /&gt;
* NIST SP 800-171 Rev 2 3.8.6&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
|&#039;&#039;&#039;[[Practice_MP.L2-3.8.7_Details|MP.L2-3.8.7]]&#039;&#039;&#039;&lt;br /&gt;
&#039;&#039;Removable Media&#039;&#039;&amp;lt;br&amp;gt;&lt;br /&gt;
Control the use of removable media on system components.&lt;br /&gt;
* NIST SP 800-171 Rev 2 3.8.7&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
|&#039;&#039;&#039;[[Practice_MP.L2-3.8.8_Details|MP.L2-3.8.8]]&#039;&#039;&#039;&lt;br /&gt;
&#039;&#039;Shared Media&#039;&#039;&amp;lt;br&amp;gt;&lt;br /&gt;
Prohibit the use of portable storage devices when such devices have no identifiable owner.&lt;br /&gt;
* NIST SP 800-171 Rev 2 3.8.8&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
|&#039;&#039;&#039;[[Practice_MP.L2-3.8.9_Details|MP.L2-3.8.9]]&#039;&#039;&#039;&lt;br /&gt;
&#039;&#039;Protect Backups&#039;&#039;&amp;lt;br&amp;gt;&lt;br /&gt;
Protect the confidentiality of backup CUI at storage locations.&lt;br /&gt;
* NIST SP 800-171 Rev 2 3.8.9&lt;br /&gt;
|&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== Personnel Security (PS) ===&lt;br /&gt;
{|class=&amp;quot;wikitable&amp;quot; style=&amp;quot;margin:auto;&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 33%&amp;quot;| Level 1&lt;br /&gt;
! style=&amp;quot;width: 33%&amp;quot;| Level 2&lt;br /&gt;
! style=&amp;quot;width: 33%&amp;quot;| Level 3&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
|&#039;&#039;&#039;[[Practice_PS.L2-3.9.1_Details|PS.L2-3.9.1]]&#039;&#039;&#039;&lt;br /&gt;
&#039;&#039;Screen Individuals&#039;&#039;&amp;lt;br&amp;gt;&lt;br /&gt;
Screen individuals prior to authorizing access to organizational systems containing CUI.&lt;br /&gt;
* NIST SP 800-171 Rev 2 3.9.1&lt;br /&gt;
|&#039;&#039;&#039;[[Practice_PS.L3-3.9.2e_Details|PS.L3-3.9.2e]]&#039;&#039;&#039;&lt;br /&gt;
&#039;&#039;Adverse Information&#039;&#039;&amp;lt;br&amp;gt;&lt;br /&gt;
Protect organizational systems when adverse information develops or is obtained about individuals with access to CUI.&lt;br /&gt;
* NIST SP 800-172 3.9.2e&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
|&#039;&#039;&#039;[[Practice_PS.L2-3.9.2_Details|PS.L2-3.9.2]]&#039;&#039;&#039;&lt;br /&gt;
&#039;&#039;Personnel Actions&#039;&#039;&amp;lt;br&amp;gt;&lt;br /&gt;
Ensure that organizational systems containing CUI are protected during and after personnel actions such as terminations and transfers.&lt;br /&gt;
* NIST SP 800-171 Rev 2 3.9.2 &lt;br /&gt;
|&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== Physical Protection (PE) ===&lt;br /&gt;
{|class=&amp;quot;wikitable&amp;quot; style=&amp;quot;margin:auto;&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 33%&amp;quot;| Level 1&lt;br /&gt;
! style=&amp;quot;width: 33%&amp;quot;| Level 2&lt;br /&gt;
! style=&amp;quot;width: 33%&amp;quot;| Level 3&lt;br /&gt;
|-&lt;br /&gt;
|&#039;&#039;&#039;[[Practice_PE.L2-3.10.1_Details|PE.L1-b.1.viii]]&#039;&#039;&#039;&lt;br /&gt;
&#039;&#039;Limit Physical Access [FCI Data]&#039;&#039;&amp;lt;br&amp;gt;&lt;br /&gt;
Limit physical access to organizational information systems, equipment, and the respective operating environments to authorized individuals. &lt;br /&gt;
* FAR Clause 52.204-21 b.1.viii&lt;br /&gt;
* NIST SP 800-171 Rev 2 3.10.1&lt;br /&gt;
|&#039;&#039;&#039;[[Practice_PE.L2-3.10.1_Details|PE.L2-3.10.1]]&#039;&#039;&#039;&lt;br /&gt;
&#039;&#039;Limit Physical Access [CUI Data]&#039;&#039;&amp;lt;br&amp;gt;&lt;br /&gt;
Limit physical access to organizational information systems, equipment, and the respective operating environments to authorized individuals. &lt;br /&gt;
* NIST SP 800-171 Rev 2 3.10.1&lt;br /&gt;
* FAR Clause 52.204-21 b.1.viii&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|&#039;&#039;&#039;PE.L1-b.1.ix&#039;&#039;&#039;&lt;br /&gt;
&#039;&#039;&#039;[[Practice_PE.L2-3.10.3_Details|First Phase]]&#039;&#039;&#039;&amp;lt;br&amp;gt;&lt;br /&gt;
&#039;&#039;&#039;[[Practice_PE.L2-3.10.4_Details|Second Phase]]&#039;&#039;&#039;&amp;lt;br&amp;gt;&lt;br /&gt;
&#039;&#039;&#039;[[Practice_PE.L2-3.10.5_Details|Third Phase]]&#039;&#039;&#039;&amp;lt;br&amp;gt;&lt;br /&gt;
&#039;&#039;Manage Visitors &amp;amp; Physical Access [FCI Data]&#039;&#039;&amp;lt;br&amp;gt;&lt;br /&gt;
Escort visitors and monitor visitor activity; maintain audit logs of physical access; and control and manage physical access devices.&lt;br /&gt;
* FAR Clause 52.204-21 Partial b.1.ix&lt;br /&gt;
* NIST SP 800-171 Rev 2 3.10.3&lt;br /&gt;
* NIST SP 800-171 Rev 2 3.10.4&lt;br /&gt;
* NIST SP 800-171 Rev 2 3.10.5&lt;br /&gt;
|&#039;&#039;&#039;[[Practice_PE.L2-3.10.2_Details|PE.L2-3.10.2]]&#039;&#039;&#039;&lt;br /&gt;
&#039;&#039;Monitor Facility&#039;&#039;&amp;lt;br&amp;gt;&lt;br /&gt;
Protect and monitor the physical facility and support infrastructure for organizational systems.&lt;br /&gt;
* NIST SP 800-171 Rev 2 3.10.2&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
|&#039;&#039;&#039;[[Practice_PE.L2-3.10.3_Details|PE.L2-3.10.3]]&#039;&#039;&#039;&lt;br /&gt;
&#039;&#039;Escort Visitors&#039;&#039;&amp;lt;br&amp;gt;&lt;br /&gt;
Escort visitors and monitor visitor activity.&lt;br /&gt;
* FAR Clause 52.204-21 Partial b.1.ix&lt;br /&gt;
* NIST SP 800-171 Rev 2 3.10.3&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
|&#039;&#039;&#039;[[Practice_PE.L2-3.10.4_Details|PE.L2-3.10.4]]&#039;&#039;&#039;&lt;br /&gt;
&#039;&#039;Physical Access Logs&#039;&#039;&amp;lt;br&amp;gt;&lt;br /&gt;
Maintain audit logs of physical access.&lt;br /&gt;
* FAR Clause 52.204-21 Partial b.1.ix&lt;br /&gt;
* NIST SP 800-171 Rev 2 3.10.4&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
|&#039;&#039;&#039;[[Practice_PE.L2-3.10.5_Details|PE.L2-3.10.5]]&#039;&#039;&#039;&lt;br /&gt;
&#039;&#039;Manage Physical Access&#039;&#039;&amp;lt;br&amp;gt;&lt;br /&gt;
Control and manage physical access devices.&lt;br /&gt;
* FAR Clause 52.204-21 Partial b.1.ix&lt;br /&gt;
* NIST SP 800-171 Rev 2 3.10.5&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
|&#039;&#039;&#039;[[Practice_PE.L2-3.10.6_Details|PE.L2-3.10.6]]&#039;&#039;&#039;&lt;br /&gt;
&#039;&#039;Alternative Work Sites&#039;&#039;&amp;lt;br&amp;gt;&lt;br /&gt;
Enforce safeguarding measures for CUI at alternate work sites.&lt;br /&gt;
* NIST SP 800-171 Rev 2 3.10.6&lt;br /&gt;
|&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== Risk Assessment (RA) ===&lt;br /&gt;
{|class=&amp;quot;wikitable&amp;quot; style=&amp;quot;margin:auto;&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 33%&amp;quot;| Level 1&lt;br /&gt;
! style=&amp;quot;width: 33%&amp;quot;| Level 2&lt;br /&gt;
! style=&amp;quot;width: 33%&amp;quot;| Level 3&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
|&#039;&#039;&#039;[[Practice_RA.L2-3.11.1_Details|RA.L2-3.11.1]]&#039;&#039;&#039;&lt;br /&gt;
&#039;&#039;Risk Assessments&#039;&#039;&amp;lt;br&amp;gt;&lt;br /&gt;
Periodically assess the risk to organizational operations (including mission, functions, image, or reputation), organizational assets, and individuals, resulting from the operation of organizational systems and the associated processing, storage, or transmission of CUI.&lt;br /&gt;
* NIST SP 800-171 Rev 2 3.11.1&lt;br /&gt;
|&#039;&#039;&#039;[[Practice_RA.L3-3.11.1e_Details|RA.L3-3.11.1e]]&#039;&#039;&#039;&lt;br /&gt;
&#039;&#039;Threat-Informed Risk Assessment&#039;&#039;&amp;lt;br&amp;gt;&lt;br /&gt;
Employ &amp;lt;u&amp;gt;threat intelligence, at a minimum from open or commercial sources&amp;lt;/u&amp;gt;, and any DoD-provided sources, as part of a risk assessment to guide and inform the development of organizational systems, security architectures, selection of security solutions, monitoring, threat hunting, and response and recovery activities.&lt;br /&gt;
* NIST SP 800-172 3.11.1e&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
|&#039;&#039;&#039;[[Practice_RA.L2-3.11.2_Details|RA.L2-3.11.2]]&#039;&#039;&#039;&lt;br /&gt;
&#039;&#039;Vulnerability Scan&#039;&#039;&amp;lt;br&amp;gt;&lt;br /&gt;
Scan for vulnerabilities in organizational systems and applications periodically and when new vulnerabilities affecting those systems and applications are identified.&lt;br /&gt;
* NIST SP 800-171 Rev 2 3.11.2&lt;br /&gt;
|&#039;&#039;&#039;[[Practice_RA.L3-3.11.2e_Details|RA.L3-3.11.2e]]&#039;&#039;&#039;&lt;br /&gt;
&#039;&#039;Threat Hunting&#039;&#039;&amp;lt;br&amp;gt;&lt;br /&gt;
Conduct cyber threat hunting activities &amp;lt;u&amp;gt;on an on-going aperiodic basis or when indications warrant&amp;lt;/u&amp;gt;, to search for indicators of compromise in &amp;lt;u&amp;gt;organizational systems&amp;lt;/u&amp;gt; and detect, track, and disrupt threats that evade existing controls.&lt;br /&gt;
* NIST SP 800-172 3.11.2e&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
|&#039;&#039;&#039;[[Practice_RA.L2-3.11.3_Details|RA.L2-3.11.3]]&#039;&#039;&#039;&lt;br /&gt;
&#039;&#039;Vulnerability Remediation&#039;&#039;&amp;lt;br&amp;gt;&lt;br /&gt;
Remediate vulnerabilities in accordance with risk assessments.&lt;br /&gt;
* NIST SP 800-171 Rev 2 3.11.3&lt;br /&gt;
|&#039;&#039;&#039;[[Practice_RA.L3-3.11.3e_Details|RA.L3-3.11.3e]]&#039;&#039;&#039;&lt;br /&gt;
&#039;&#039;Advanced Risk Identification&#039;&#039;&amp;lt;br&amp;gt;&lt;br /&gt;
Employ advanced automation and analytics capabilities in support of analysts to predict and identify risks to organizations, systems, and system components.&lt;br /&gt;
* NIST SP 800-172 3.11.3e&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&#039;&#039;&#039;[[Practice_RA.L3-3.11.4e_Details|RA.L3-3.11.4e]]&#039;&#039;&#039;&lt;br /&gt;
&#039;&#039;Security Solution Rationale&#039;&#039;&amp;lt;br&amp;gt;&lt;br /&gt;
Document or reference in the system security plan the security solution selected, the rationale for the security solution, and the risk determination.&lt;br /&gt;
* NIST SP 800-172 3.11.4e&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&#039;&#039;&#039;[[Practice_RA.L3-3.11.5e_Details|RA.L3-3.11.5e]]&#039;&#039;&#039;&lt;br /&gt;
&#039;&#039;Security Solution Effectiveness&#039;&#039;&amp;lt;br&amp;gt;&lt;br /&gt;
Assess the effectiveness of security solutions &amp;lt;u&amp;gt;at least annually or upon receipt of relevant cyber threat information, or in response to a relevant cyber incident&amp;lt;/u&amp;gt;, to address anticipated risk to organizational systems and the organization based on current and accumulated threat intelligence.&lt;br /&gt;
* NIST SP 800-172 3.11.5e&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&#039;&#039;&#039;[[Practice_RA.L3-3.11.6e_Details|RA.L3-3.11.6e]]&#039;&#039;&#039;&lt;br /&gt;
&#039;&#039;Supply Chain Risk Response&#039;&#039;&amp;lt;br&amp;gt;&lt;br /&gt;
Assess, respond to, and monitor supply chain risks associated with organizational systems and system components.&lt;br /&gt;
* NIST SP 800-172 3.11.6e&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|&#039;&#039;&#039;[[Practice_RA.L3-3.11.7e_Details|RA.L3-3.11.7e]]&#039;&#039;&#039;&lt;br /&gt;
&#039;&#039;Supply Chain Risk Plan&#039;&#039;&amp;lt;br&amp;gt;&lt;br /&gt;
Develop a plan for managing supply chain risks associated with organizational systems and system components; update the plan &amp;lt;u&amp;gt;at least annually, and upon receipt of relevant cyber threat information, or in response to a relevant cyber incident&amp;lt;/u&amp;gt;.&lt;br /&gt;
* NIST SP 800-172 3.11.7e&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== Security Assessment (CA) ===&lt;br /&gt;
{|class=&amp;quot;wikitable&amp;quot; style=&amp;quot;margin:auto;&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 33%&amp;quot;| Level 1&lt;br /&gt;
! style=&amp;quot;width: 33%&amp;quot;| Level 2&lt;br /&gt;
! style=&amp;quot;width: 33%&amp;quot;| Level 3&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
|&#039;&#039;&#039;[[Practice_CA.L2-3.12.1_Details|CA.L2-3.12.1]]&#039;&#039;&#039;&lt;br /&gt;
&#039;&#039;Security Control Assessment&#039;&#039;&amp;lt;br&amp;gt;&lt;br /&gt;
Periodically assess the security controls in organizational systems to determine if the controls are effective in their application.&lt;br /&gt;
* NIST SP 800-171 Rev 2 3.12.1&lt;br /&gt;
|&#039;&#039;&#039;[[Practice_CA.L3-3.12.1e_Details|CA.L3-3.12.1e]]&#039;&#039;&#039;&lt;br /&gt;
&#039;&#039;Penetration Testing&#039;&#039;&amp;lt;br&amp;gt;&lt;br /&gt;
Conduct penetration testing &amp;lt;u&amp;gt;at least annually or when significant security changes are made to the system&amp;lt;/u&amp;gt;, leveraging automated scanning tools and ad hoc tests using subject matter experts.&lt;br /&gt;
* NIST SP 800-172 3.12.1e&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
|&#039;&#039;&#039;[[Practice_CA.L2-3.12.2_Details|CA.L2-3.12.2]]&#039;&#039;&#039;&lt;br /&gt;
&#039;&#039;Plan of Action&#039;&#039;&amp;lt;br&amp;gt;&lt;br /&gt;
Develop and implement plans of action designed to correct deficiencies and reduce or eliminate vulnerabilities in organizational systems.&lt;br /&gt;
* NIST SP 800-171 Rev 2 3.12.2&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
|&#039;&#039;&#039;[[Practice_CA.L2-3.12.3_Details|CA.L2-3.12.3]]&#039;&#039;&#039;&lt;br /&gt;
&#039;&#039;Security Control Monitoring&#039;&#039;&amp;lt;br&amp;gt;&lt;br /&gt;
Monitor security controls on an ongoing basis to ensure the continued effectiveness of the controls.&lt;br /&gt;
* NIST SP 800-171 Rev 2 3.12.3&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
|&#039;&#039;&#039;[[Practice_CA.L2-3.12.4_Details|CA.L2-3.12.4]]&#039;&#039;&#039;&lt;br /&gt;
&#039;&#039;System Security Plan&#039;&#039;&amp;lt;br&amp;gt;&lt;br /&gt;
Develop, document, and periodically update system security plans that describe system boundaries, system environments of operation, how security requirements are implemented, and the relationships with or connections to other systems.&lt;br /&gt;
* NIST SP 800-171 Rev 2 3.12.4&lt;br /&gt;
|&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== System and Communications Protection (SC) ===&lt;br /&gt;
{|class=&amp;quot;wikitable&amp;quot; style=&amp;quot;margin:auto;&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 33%&amp;quot;| Level 1&lt;br /&gt;
! style=&amp;quot;width: 33%&amp;quot;| Level 2&lt;br /&gt;
! style=&amp;quot;width: 33%&amp;quot;| Level 3&lt;br /&gt;
|-&lt;br /&gt;
|&#039;&#039;&#039;[[Practice_SC.L2-3.13.1_Details|SC.L1-b.1.x]]&#039;&#039;&#039;&lt;br /&gt;
&#039;&#039;Boundary Protection [FCI Data]&#039;&#039;&amp;lt;br&amp;gt;&lt;br /&gt;
Monitor, control, and protect organizational communications (i.e., information transmitted or received by organizational information systems) at the external boundaries and key internal boundaries of the information systems.&lt;br /&gt;
* FAR Clause 52.204-21 b.1.x&lt;br /&gt;
* NIST SP 800-171 Rev 2 3.13.1&lt;br /&gt;
|&#039;&#039;&#039;[[Practice_SC.L2-3.13.1_Details|SC.L2-3.13.1]]&#039;&#039;&#039;&lt;br /&gt;
&#039;&#039;Boundary Protection [CUI Data]&#039;&#039;&amp;lt;br&amp;gt;&lt;br /&gt;
Monitor, control, and protect organizational communications (i.e., information transmitted or received by organizational information systems) at the external boundaries and key internal boundaries of the information systems.&lt;br /&gt;
* NIST SP 800-171 Rev 2 3.13.1&lt;br /&gt;
* FAR Clause 52.204-21 b.1.x&lt;br /&gt;
|&#039;&#039;&#039;[[Practice_SC.L3-3.13.4e_Details|SC.L3-3.13.4e]]&#039;&#039;&#039;&lt;br /&gt;
&#039;&#039;Isolation&#039;&#039;&amp;lt;br&amp;gt;&lt;br /&gt;
Employ &amp;lt;u&amp;gt;physical isolation techniques or logical isolation techniques or both&amp;lt;/u&amp;gt; in organizational systems and system components.&lt;br /&gt;
* NIST SP 800-172 3.13.4e&lt;br /&gt;
|-&lt;br /&gt;
|&#039;&#039;&#039;[[Practice_SC.L2-3.13.5_Details|SC.L1-b.1.xi]]&#039;&#039;&#039;&lt;br /&gt;
&#039;&#039;Public-Access System Separation [FCI Data]&#039;&#039;&amp;lt;br&amp;gt;&lt;br /&gt;
Implement subnetworks for publicly accessible system components that are physically or logically separated from internal networks.&lt;br /&gt;
* FAR Clause 52.204-21 b.1.xi&lt;br /&gt;
* NIST SP 800-171 Rev 2 3.13.5&lt;br /&gt;
|&#039;&#039;&#039;[[Practice_SC.L2-3.13.2_Details|SC.L2-3.13.2]]&#039;&#039;&#039;&lt;br /&gt;
&#039;&#039;Security Engineering&#039;&#039;&amp;lt;br&amp;gt;&lt;br /&gt;
Employ architectural designs, software development techniques, and systems engineering principles that promote effective information security within organizational systems.&lt;br /&gt;
* NIST SP 800-171 Rev 2 3.13.2&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
|&#039;&#039;&#039;[[Practice_SC.L2-3.13.3_Details|SC.L2-3.13.3]]&#039;&#039;&#039;&lt;br /&gt;
&#039;&#039;Role Separation&#039;&#039;&amp;lt;br&amp;gt;&lt;br /&gt;
Separate user functionality from system management functionality.&lt;br /&gt;
* NIST SP 800-171 Rev 2 3.13.3&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
|&#039;&#039;&#039;[[Practice_SC.L2-3.13.4_Details|SC.L2-3.13.4]]&#039;&#039;&#039;&lt;br /&gt;
&#039;&#039;Shared Resource Control&#039;&#039;&amp;lt;br&amp;gt;&lt;br /&gt;
Prevent unauthorized and unintended information transfer via shared system resources.&lt;br /&gt;
* NIST SP 800-171 Rev 2 3.13.4&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
|&#039;&#039;&#039;[[Practice_SC.L2-3.13.5_Details|SC.L2-3.13.5]]&#039;&#039;&#039;&lt;br /&gt;
&#039;&#039;Public-Access System Separation [CUI Data]&#039;&#039;&amp;lt;br&amp;gt;&lt;br /&gt;
Implement subnetworks for publicly accessible system components that are physically or logically separated from internal networks.&lt;br /&gt;
* NIST SP 800-171 Rev 2 3.13.5&lt;br /&gt;
* FAR Clause 52.204-21 b.1.xi&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
|&#039;&#039;&#039;[[Practice_SC.L2-3.13.6_Details|SC.L2-3.13.6]]&#039;&#039;&#039;&lt;br /&gt;
&#039;&#039;Network Communication by Exception&#039;&#039;&amp;lt;br&amp;gt;&lt;br /&gt;
Deny network communications traffic by default and allow network communications traffic by exception (i.e., deny all, permit by exception).&lt;br /&gt;
* NIST SP 800-171 Rev 2 3.13.6&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
|&#039;&#039;&#039;[[Practice_SC.L2-3.13.7_Details|SC.L2-3.13.7]]&#039;&#039;&#039;&lt;br /&gt;
&#039;&#039;Split Tunneling&#039;&#039;&amp;lt;br&amp;gt;&lt;br /&gt;
Prevent remote devices from simultaneously establishing non-remote connections with organizational systems and communicating via some other connection to resources in external networks (i.e., split tunneling).&lt;br /&gt;
* NIST SP 800-171 Rev 2 3.13.7&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
|&#039;&#039;&#039;[[Practice_SC.L2-3.13.8_Details|SC.L2-3.13.8]]&#039;&#039;&#039;&lt;br /&gt;
&#039;&#039;Data in Transit&#039;&#039;&amp;lt;br&amp;gt;&lt;br /&gt;
Implement cryptographic mechanisms to prevent unauthorized disclosure of CUI during transmission unless otherwise protected by alternative physical safeguards.&lt;br /&gt;
* NIST SP 800-171 Rev 2 3.13.8&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
|&#039;&#039;&#039;[[Practice_SC.L2-3.13.9_Details|SC.L2-3.13.9]]&#039;&#039;&#039;&lt;br /&gt;
&#039;&#039;Connections Termination&#039;&#039;&amp;lt;br&amp;gt;&lt;br /&gt;
Terminate network connections associated with communications sessions at the end of the sessions or after a defined period of inactivity.&lt;br /&gt;
* NIST SP 800-171 Rev 2 3.13.9&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
|&#039;&#039;&#039;[[Practice_SC.L2-3.13.10_Details|SC.L2-3.13.10]]&#039;&#039;&#039;&lt;br /&gt;
&#039;&#039;Key Management&#039;&#039;&amp;lt;br&amp;gt;&lt;br /&gt;
Establish and manage cryptographic keys for cryptography employed in organizational systems.&lt;br /&gt;
* NIST SP 800-171 Rev 2 3.13.10&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
|&#039;&#039;&#039;[[Practice_SC.L2-3.13.11_Details|SC.L2-3.13.11]]&#039;&#039;&#039;&lt;br /&gt;
&#039;&#039;CUI Encryption&#039;&#039;&amp;lt;br&amp;gt;&lt;br /&gt;
Employ FIPS-validated cryptography when used to protect the confidentiality of CUI.&lt;br /&gt;
* NIST SP 800-171 Rev 2 3.13.11&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
|&#039;&#039;&#039;[[Practice_SC.L2-3.13.12_Details|SC.L2-3.13.12]]&#039;&#039;&#039;&lt;br /&gt;
&#039;&#039;Collaborative Device Control&#039;&#039;&amp;lt;br&amp;gt;&lt;br /&gt;
Prohibit remote activation of collaborative computing devices and provide indication of devices in use to users present at the device.&lt;br /&gt;
* NIST SP 800-171 Rev 2 3.13.12&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
|&#039;&#039;&#039;[[Practice_SC.L2-3.13.13_Details|SC.L2-3.13.13]]&#039;&#039;&#039;&lt;br /&gt;
&#039;&#039;Mobile Code&#039;&#039;&amp;lt;br&amp;gt;&lt;br /&gt;
Control and monitor the use of mobile code.&lt;br /&gt;
* NIST SP 800-171 Rev 2 3.13.13&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
|&#039;&#039;&#039;[[Practice_SC.L2-3.13.14_Details|SC.L2-3.13.14]]&#039;&#039;&#039;&lt;br /&gt;
&#039;&#039;Voice over Internet Protocol&#039;&#039;&amp;lt;br&amp;gt;&lt;br /&gt;
Control and monitor the use of Voice over Internet Protocol (VoIP) technologies.&lt;br /&gt;
* NIST SP 800-171 Rev 2 3.13.14&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
|&#039;&#039;&#039;[[Practice_SC.L2-3.13.15_Details|SC.L2-3.13.15]]&#039;&#039;&#039;&lt;br /&gt;
&#039;&#039;Communications Authenticity&#039;&#039;&amp;lt;br&amp;gt;&lt;br /&gt;
Protect the authenticity of communications sessions.&lt;br /&gt;
* NIST SP 800-171 Rev 2 3.13.15&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
|&#039;&#039;&#039;[[Practice_SC.L2-3.13.16_Details|SC.L2-3.13.16]]&#039;&#039;&#039;&lt;br /&gt;
&#039;&#039;Data at Rest&#039;&#039;&amp;lt;br&amp;gt;&lt;br /&gt;
Protect the confidentiality of CUI at rest.&lt;br /&gt;
* NIST SP 800-171 Rev 2 3.13.16&lt;br /&gt;
|&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== System and Information Integrity (SI) ===&lt;br /&gt;
{|class=&amp;quot;wikitable&amp;quot; style=&amp;quot;margin:auto;&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 33%&amp;quot;| Level 1&lt;br /&gt;
! style=&amp;quot;width: 33%&amp;quot;| Level 2&lt;br /&gt;
! style=&amp;quot;width: 33%&amp;quot;| Level 3&lt;br /&gt;
|-&lt;br /&gt;
|&#039;&#039;&#039;[[Practice_SI.L2-3.14.1_Details|SI.L1-b.1.xii]]&#039;&#039;&#039;&lt;br /&gt;
&#039;&#039;Flaw Remediation [FCI Data]&#039;&#039;&amp;lt;br&amp;gt;&lt;br /&gt;
Identify, report, and correct information and information system flaws in a timely manner.&lt;br /&gt;
* FAR Clause 52.204-21 b.1.xii&lt;br /&gt;
* NIST SP 800-171 Rev 2 3.14.1&lt;br /&gt;
|&#039;&#039;&#039;[[Practice_SI.L2-3.14.1_Details|SI.L2-3.14.1]]&#039;&#039;&#039;&lt;br /&gt;
&#039;&#039;Flaw Remediation [CUI Data]&#039;&#039;&amp;lt;br&amp;gt;&lt;br /&gt;
Identify, report, and correct information and information system flaws in a timely manner.&lt;br /&gt;
* NIST SP 800-171 Rev 2 3.14.1&lt;br /&gt;
* FAR Clause 52.204-21 b.1.xii&lt;br /&gt;
|&#039;&#039;&#039;[[Practice_SI.L3-3.14.1e_Details|SI.L3-3.14.1e]]&#039;&#039;&#039;&lt;br /&gt;
&#039;&#039;Integrity Verification&#039;&#039;&amp;lt;br&amp;gt;&lt;br /&gt;
Verify the integrity of security critical and essential software using root of trust mechanisms or cryptographic signatures.&lt;br /&gt;
* NIST SP 800-172 3.14.1e&lt;br /&gt;
|-&lt;br /&gt;
|&#039;&#039;&#039;[[Practice_SI.L2-3.14.2_Details|SI.L1-b.1.xiii]]&#039;&#039;&#039;&lt;br /&gt;
&#039;&#039;Malicious Code Protection [FCI Data]&#039;&#039;&amp;lt;br&amp;gt;&lt;br /&gt;
Provide protection from malicious code at appropriate locations within organizational information systems.&lt;br /&gt;
* FAR Clause 52.204-21 b.1.xiii&lt;br /&gt;
* NIST SP 800-171 Rev 2 3.14.2&lt;br /&gt;
|&#039;&#039;&#039;[[Practice_SI.L2-3.14.2_Details|SI.L2-3.14.2]]&#039;&#039;&#039;&lt;br /&gt;
&#039;&#039;Malicious Code Protection [CUI Data]&#039;&#039;&amp;lt;br&amp;gt;&lt;br /&gt;
Provide protection from malicious code at appropriate locations within organizational information systems.&lt;br /&gt;
* NIST SP 800-171 Rev 2 3.14.2&lt;br /&gt;
* FAR Clause 52.204-21 b.1.xiii&lt;br /&gt;
|&#039;&#039;&#039;[[Practice_SI.L3-3.14.3e_Details|SI.L3-3.14.3e]]&#039;&#039;&#039;&lt;br /&gt;
&#039;&#039;Specialized Asset Security&#039;&#039;&amp;lt;br&amp;gt;&lt;br /&gt;
Include &amp;lt;u&amp;gt;specialized assets such as IoT, IIoT, OT, GFE, Restricted Information Systems and test equipment&amp;lt;/u&amp;gt; in the scope of the specified enhanced security requirements or are segregated in purpose-specific networks.&lt;br /&gt;
* NIST SP 800-172 3.14.3e&lt;br /&gt;
|-&lt;br /&gt;
|&#039;&#039;&#039;[[Practice_SI.L2-3.14.4_Details|SI.L1-b.1.xiv]]&#039;&#039;&#039;&lt;br /&gt;
&#039;&#039;Update Malicious Code Protection [FCI Data]&#039;&#039;&amp;lt;br&amp;gt;&lt;br /&gt;
Update malicious code protection mechanisms when new releases are available.&lt;br /&gt;
* FAR Clause 52.204-21 b.1.xiv&lt;br /&gt;
* NIST SP 800-171 Rev 2 3.14.4&lt;br /&gt;
|&#039;&#039;&#039;[[Practice_SI.L2-3.14.3_Details|SI.L2-3.14.3]]&#039;&#039;&#039;&lt;br /&gt;
&#039;&#039;Security Alerts &amp;amp; Advisories&#039;&#039;&amp;lt;br&amp;gt;&lt;br /&gt;
Monitor system security alerts and advisories and take action in response.&lt;br /&gt;
* NIST SP 800-171 Rev 2 3.14.3&lt;br /&gt;
|&#039;&#039;&#039;[[Practice_SI.L3-3.14.6e_Details|SI.L3-3.14.6e]]&#039;&#039;&#039;&lt;br /&gt;
&#039;&#039;Threat-Guided Intrusion Detection&#039;&#039;&amp;lt;br&amp;gt;&lt;br /&gt;
Use threat indicator information and effective mitigations obtained from, &amp;lt;u&amp;gt;at a minimum, open or commercial sources, and any DoD-provided sources&amp;lt;/u&amp;gt;, to guide and inform intrusion detection and threat hunting.&lt;br /&gt;
* NIST SP 800-172 3.14.6e&lt;br /&gt;
|-&lt;br /&gt;
|&#039;&#039;&#039;[[Practice_SI.L2-3.14.5_Details|SI.L1-b.1.xv]]&#039;&#039;&#039;&lt;br /&gt;
&#039;&#039;System &amp;amp; File Scanning [FCI Data]&#039;&#039;&amp;lt;br&amp;gt;&lt;br /&gt;
Perform periodic scans of the information system and real-time scans of files from external sources as files are downloaded, opened, or executed.&lt;br /&gt;
* FAR Clause 52.204-21 b.1.xv&lt;br /&gt;
* NIST SP 800-171 Rev 2 3.14.5&lt;br /&gt;
|&#039;&#039;&#039;[[Practice_SI.L2-3.14.4_Details|SI.L2-3.14.4]]&#039;&#039;&#039;&lt;br /&gt;
&#039;&#039;Update Malicious Code Protection [CUI Data]&#039;&#039;&amp;lt;br&amp;gt;&lt;br /&gt;
Update malicious code protection mechanisms when new releases are available.&lt;br /&gt;
* NIST SP 800-171 Rev 2 3.14.4&lt;br /&gt;
* FAR Clause 52.204-21 b.1.xiv&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
|&#039;&#039;&#039;[[Practice_SI.L2-3.14.5_Details|SI.L2-3.14.5]]&#039;&#039;&#039;&lt;br /&gt;
&#039;&#039;System &amp;amp; File Scanning [CUI Data]&#039;&#039;&amp;lt;br&amp;gt;&lt;br /&gt;
Perform periodic scans of the information system and real-time scans of files from external sources as files are downloaded, opened, or executed.&lt;br /&gt;
* FAR Clause 52.204-21 b.1.xv&lt;br /&gt;
* NIST SP 800-171 Rev 2 3.14.5&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
|&#039;&#039;&#039;[[Practice_SI.L2-3.14.6_Details|SI.L2-3.14.6]]&#039;&#039;&#039;&lt;br /&gt;
&#039;&#039;Monitor Communications for Attacks&#039;&#039;&amp;lt;br&amp;gt;&lt;br /&gt;
Monitor organizational systems, including inbound and outbound communications traffic, to detect attacks and indicators of potential attacks.&lt;br /&gt;
* NIST SP 800-171 Rev 2 3.14.6&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
|&#039;&#039;&#039;[[Practice_SI.L2-3.14.7_Details|SI.L2-3.14.7]]&#039;&#039;&#039;&lt;br /&gt;
&#039;&#039;Identify Unauthorized Use&#039;&#039;&amp;lt;br&amp;gt;&lt;br /&gt;
Identify unauthorized use of organizational systems.&lt;br /&gt;
* NIST SP 800-171 Rev 2 3.14.7&lt;br /&gt;
|&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Appendix B. Abbreviations and Acronyms ==&lt;br /&gt;
The following is a list of acronyms used in the CMMC model.&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;margin:auto&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
|| AC || Access Control&lt;br /&gt;
|-&lt;br /&gt;
|| APT || Advanced Persistent Threat&lt;br /&gt;
|-&lt;br /&gt;
|| AT || Awareness and Training&lt;br /&gt;
|-&lt;br /&gt;
|| AU || Audit and Accountability&lt;br /&gt;
|-&lt;br /&gt;
|| CA || Security Assessment&lt;br /&gt;
|-&lt;br /&gt;
|| CFR || Code of Federal Regulations&lt;br /&gt;
|-&lt;br /&gt;
|| CM || Configuration Management&lt;br /&gt;
|-&lt;br /&gt;
|| CMMC || Cybersecurity Maturity Model Certification&lt;br /&gt;
|-&lt;br /&gt;
|| CUI || Controlled Unclassified Information&lt;br /&gt;
|-&lt;br /&gt;
|| DFARS || Defense Federal Acquisition Regulation Supplement&lt;br /&gt;
|-&lt;br /&gt;
|| DIB || Defense Industrial Base&lt;br /&gt;
|-&lt;br /&gt;
|| DoD || Department of Defense FAR Federal Acquisition Regulation&lt;br /&gt;
|-&lt;br /&gt;
|| FCI || Federal Contract Information&lt;br /&gt;
|-&lt;br /&gt;
|| FFRDC || Federally Funded Research and Development Center&lt;br /&gt;
|-&lt;br /&gt;
|| FIPS || Federal Information Processing Standard&lt;br /&gt;
|-&lt;br /&gt;
|| IA || Identification and Authentication&lt;br /&gt;
|-&lt;br /&gt;
|| IR || Incident Response&lt;br /&gt;
|-&lt;br /&gt;
|| L# || Level Number&lt;br /&gt;
|-&lt;br /&gt;
|| MA || Maintenance&lt;br /&gt;
|-&lt;br /&gt;
|| MP || Media Protection&lt;br /&gt;
|-&lt;br /&gt;
|| N/A || Not Applicable (NA)&lt;br /&gt;
|-&lt;br /&gt;
|| NIST || National Institute of Standards and Technology&lt;br /&gt;
|-&lt;br /&gt;
|| OUSD A&amp;amp;S || Office of the Under Secretary of Defense for Acquisition and Sustainment&lt;br /&gt;
|-&lt;br /&gt;
|| PE || Physical Protection&lt;br /&gt;
|-&lt;br /&gt;
|| PS || Personnel Security&lt;br /&gt;
|-&lt;br /&gt;
|| PUB || Publication&lt;br /&gt;
|-&lt;br /&gt;
|| Rev || Revision&lt;br /&gt;
|-&lt;br /&gt;
|| RA || Risk Assessment&lt;br /&gt;
|-&lt;br /&gt;
|| SC || System and Communications Protection&lt;br /&gt;
|-&lt;br /&gt;
|| SI || System and Information Integrity&lt;br /&gt;
|-&lt;br /&gt;
|| SP || Special Publication&lt;br /&gt;
|-&lt;br /&gt;
|| UARC || University Affiliated Research Center&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Appendix C. References ==&lt;br /&gt;
# U.S. Executive Office of the President, Council of Economic Advisers (CEA), &#039;&#039;The Cost of Malicious Cyber Activity to the U.S. Economy&#039;&#039;, available online at https://www.whitehouse.gov/wp-content/uploads/2018/02/The-Cost-of-Malicious-Cyber-Activity-to-the-U.S.-Economy.pdf, February 2018&lt;br /&gt;
# Center for Strategic and International Studies (CSIS) and McAfee, &#039;&#039;Economic Impact of Cybercrime - No Slowing Down&#039;&#039;, February 2018&lt;br /&gt;
# 48 Code of Federal Regulations (CFR) 52.204-21, &#039;&#039;Basic Safeguarding of Covered Contractor Information Systems&#039;&#039;, Federal Acquisition Regulation (FAR), 1 Oct 2016&lt;br /&gt;
# NIST Special Publication (SP) 800-171 Revision (Rev) 2, &#039;&#039;Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations&#039;&#039;, U.S. Department of Commerce National Institute of Standards and Technology (NIST), December 2016 (updated June 2018)&lt;br /&gt;
# NIST SP 800-172, &#039;&#039;Enhanced Security Requirements for Protecting Controlled Unclassified Information: A Supplement to NIST Special Publication 800-171&#039;&#039;, U.S. Department of Commerce National Institute of Standards and Technology (NIST), February 2021&lt;br /&gt;
&lt;br /&gt;
== Notes ==&lt;br /&gt;
&amp;lt;references /&amp;gt;&lt;/div&gt;</summary>
		<author><name>David</name></author>
	</entry>
	<entry>
		<id>https://cmmcwiki.org/index.php?title=Main_Page&amp;diff=1601</id>
		<title>Main Page</title>
		<link rel="alternate" type="text/html" href="https://cmmcwiki.org/index.php?title=Main_Page&amp;diff=1601"/>
		<updated>2026-03-02T01:32:59Z</updated>

		<summary type="html">&lt;p&gt;David: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&#039;&#039;&#039;This website contains information about the Cybersecurity Maturity Model Certification (CMMC) program of the U.S. Department of Defense (DoD).&lt;br /&gt;
&lt;br /&gt;
The wiki aims to provide educational references for those who are interested in learning more about the framework.&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
Primary Source of Reference: The official [https://dodcio.defense.gov/CMMC/ CMMC Home Page] from the Department of Defense Chief Information Officer (DoD CIO).&lt;br /&gt;
&lt;br /&gt;
Additional References: The [https://dodcio.defense.gov/cmmc/Resources-Documentation/ CMMC Resources &amp;amp; Documentation] page contains a variety of links to CMMC resources throughout the DoD.&lt;br /&gt;
&lt;br /&gt;
Basic information on FedRAMP and Cybersecurity Framework are also available on this website. Select one of the menu items on the Sidebar.&lt;br /&gt;
&lt;br /&gt;
For inquiries and reporting errors on this wiki, please [mailto:support@cmmcwiki.org contact us]. Thank you.&lt;br /&gt;
&lt;br /&gt;
== Site Update Notices ==&lt;br /&gt;
The CMMCWiki site is currently undergoing a comprehensive update to align with the latest content on the official CMMC website. For the most up-to-date information on our progress and recent changes, please refer to the following table.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;margin:auto&amp;quot;&lt;br /&gt;
|+ Update Status as of March 27, 2025&lt;br /&gt;
|-&lt;br /&gt;
! Page Name !! Status&lt;br /&gt;
|-&lt;br /&gt;
| Model Overview || Update completed on March 16, 2025&lt;br /&gt;
|-&lt;br /&gt;
| 32 CFR Part 170 Rule || Update completed on March 3, 2025&lt;br /&gt;
|-&lt;br /&gt;
| Level 1 Scoping Guidance || Update completed on February 25, 2025&lt;br /&gt;
|-&lt;br /&gt;
| Level 1 Self-Assessment Guide || Update completed on March 16, 2025&lt;br /&gt;
|-&lt;br /&gt;
| Level 2 Scoping Guidance || Update completed on February 25, 2025&lt;br /&gt;
|-&lt;br /&gt;
| Level 2 Assessment Guide || Update completed on March 20, 2025&lt;br /&gt;
|-&lt;br /&gt;
| Level 3 Scoping Guidance || Update completed on February 24, 2025&lt;br /&gt;
|-&lt;br /&gt;
| Level 3 Assessment Guide || Update completed on March 27, 2025&lt;br /&gt;
|-&lt;br /&gt;
| CMMC Hashing Guide || Update completed on March 16, 2025&lt;br /&gt;
|-&lt;br /&gt;
| CMMC Assessment Process (CAP) by CyberAB || Update completed on February 24, 2025&lt;br /&gt;
|-&lt;br /&gt;
| DoD Assessment Methodology || Update completed on March 18, 2025&lt;br /&gt;
|-&lt;br /&gt;
| 110 L1 &amp;amp; L2 Security Requirements || Update completed on March 16, 2025&lt;br /&gt;
|-&lt;br /&gt;
| 24 L3 Security Requirements || Update completed on March 27, 2025&lt;br /&gt;
|-&lt;br /&gt;
| FedRAMP Information || Update Pending&lt;br /&gt;
|-&lt;br /&gt;
| Cybersecurity Framework Information || Update Pending&lt;br /&gt;
|}&lt;/div&gt;</summary>
		<author><name>David</name></author>
	</entry>
	<entry>
		<id>https://cmmcwiki.org/index.php?title=CCA_Blueprint&amp;diff=1600</id>
		<title>CCA Blueprint</title>
		<link rel="alternate" type="text/html" href="https://cmmcwiki.org/index.php?title=CCA_Blueprint&amp;diff=1600"/>
		<updated>2026-03-02T01:32:32Z</updated>

		<summary type="html">&lt;p&gt;David: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&#039;&#039;&#039;Source of Reference: The CCA blueprint document from [https://cyberab.org/CMMC-Ecosystem/Ecosystem-roles/Assessing-and-Certification Cybersecurity Maturity Model Certification Accreditation Body, Inc.]&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
For inquiries and reporting errors on this wiki, please [mailto:support@cmmcwiki.org contact us]. Thank you.&lt;br /&gt;
&lt;br /&gt;
== Domains ==&lt;br /&gt;
Upon successful completion of this exam, the candidate will be able to apply skills and knowledge to the below domains:&lt;br /&gt;
{|class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|&#039;&#039;&#039;Domain&#039;&#039;&#039;&lt;br /&gt;
|&#039;&#039;&#039;Exam Weight&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|1. Evaluating Organizations Seeking Certification (OSC) against CMMC Level 2 requirement&lt;br /&gt;
|15%&lt;br /&gt;
|-&lt;br /&gt;
|2. CMMC Level 2 Assessment Scoping&lt;br /&gt;
|20%&lt;br /&gt;
|-&lt;br /&gt;
|3. CMMC Assessment Process (CAP)&lt;br /&gt;
|25%&lt;br /&gt;
|-&lt;br /&gt;
|4. Assessing CMMC Level 2 Practices&lt;br /&gt;
|40%&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Domain 1: Evaluating Organizations Seeking Certification (OSC) against CMMC Level 2 requirements ==&lt;br /&gt;
=== Task 1. Assess the various environmental considerations of Organizations Seeking Certification (OSCs) against CMMC L2 practices. ===&lt;br /&gt;
{|class=&amp;quot;wikitable&amp;quot; style=&amp;quot;width: 85%;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;width: 10%&amp;quot;|Lesson Topic&lt;br /&gt;
! style=&amp;quot;width: 10%&amp;quot;|Objective&lt;br /&gt;
! style=&amp;quot;width: 80%&amp;quot;|Objective Description&lt;br /&gt;
|-&lt;br /&gt;
|4C&lt;br /&gt;
|1.1.1&lt;br /&gt;
|# The difference between logical (virtual) and physical locations&lt;br /&gt;
|-&lt;br /&gt;
|4C&lt;br /&gt;
|1.1.2&lt;br /&gt;
|# The difference between professional and industrial environments&lt;br /&gt;
|-&lt;br /&gt;
|4C&lt;br /&gt;
|1.1.3&lt;br /&gt;
|# Single and multi-site environmental constraints and Evidence requirements&lt;br /&gt;
|-&lt;br /&gt;
|4C&lt;br /&gt;
|1.1.4&lt;br /&gt;
|# Cloud and hybrid environment constraints and Evidence requirements&lt;br /&gt;
|-&lt;br /&gt;
|4C&lt;br /&gt;
|1.1.5&lt;br /&gt;
|# On-premises environmental constraints&lt;br /&gt;
|-&lt;br /&gt;
|4C&lt;br /&gt;
|1.1.6&lt;br /&gt;
|# Environmental exclusions for a level 2 CMMC assessment&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Domain 2: Scoping ==&lt;br /&gt;
=== Task 1. Analyze the CMMC Assessment Scope of Controlled Unclassified Information (CUI) Assets as they pertain to a CMMC assessment using the five categories of CUI assets as defined in the CMMC Level 2 Assessment Scoping Guide. ===&lt;br /&gt;
{|class=&amp;quot;wikitable&amp;quot; style=&amp;quot;width: 85%;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;width: 10%&amp;quot;|Lesson Topic&lt;br /&gt;
! style=&amp;quot;width: 10%&amp;quot;|Objective&lt;br /&gt;
! style=&amp;quot;width: 80%&amp;quot;|Objective Description&lt;br /&gt;
|-&lt;br /&gt;
|4B&lt;br /&gt;
|2.1.1&lt;br /&gt;
|1. Categorization of CUI data in the form of Assets that are in scope:&lt;br /&gt;
|-&lt;br /&gt;
|4B&lt;br /&gt;
|2.1.1.A&lt;br /&gt;
|&lt;br /&gt;
:A. #1: Controlled Unclassified Information (CUI) Assets&lt;br /&gt;
|-&lt;br /&gt;
|4B&lt;br /&gt;
|2.1.1.A(1)&lt;br /&gt;
|&lt;br /&gt;
::(1) Process, store, or transmit CUI&lt;br /&gt;
|-&lt;br /&gt;
|4B&lt;br /&gt;
|2.1.1.B&lt;br /&gt;
|&lt;br /&gt;
:B. #2: Security Protection Assets&lt;br /&gt;
|-&lt;br /&gt;
|4B&lt;br /&gt;
|2.1.1.B(1)&lt;br /&gt;
|&lt;br /&gt;
::(1) Assets that provide security functions and capabilities to contractor’s CMMC Assessment Scope&lt;br /&gt;
|-&lt;br /&gt;
|4B&lt;br /&gt;
|2.1.1.C&lt;br /&gt;
|&lt;br /&gt;
:C. #3: Contractor Risked Managed Assets&lt;br /&gt;
|-&lt;br /&gt;
|4B&lt;br /&gt;
|2.1.1.C(1)&lt;br /&gt;
|&lt;br /&gt;
::(1) Assets that can, but are not intended to, process, store, or transmit CUI because of security policy, procedures, and practices in place&lt;br /&gt;
|-&lt;br /&gt;
|4B&lt;br /&gt;
|2.1.1.D&lt;br /&gt;
|&lt;br /&gt;
:D. #4: Specialized Assets&lt;br /&gt;
|-&lt;br /&gt;
|4B&lt;br /&gt;
|2.1.1.D(1)&lt;br /&gt;
|&lt;br /&gt;
::(1) Assets that may/may not process, store, or transmit CUI&lt;br /&gt;
|-&lt;br /&gt;
|4B&lt;br /&gt;
|2.1.1.D(2)&lt;br /&gt;
|&lt;br /&gt;
::(2) Assets include government property, Internet of Things (IoT) devices, Operational Technology (OT), Restricted Information Systems, and Test Equipment&lt;br /&gt;
|-&lt;br /&gt;
|4B&lt;br /&gt;
|2.1.1.E&lt;br /&gt;
|&lt;br /&gt;
:E. #5: Out-of-Scope Assets&lt;br /&gt;
|-&lt;br /&gt;
|4B&lt;br /&gt;
|2.1.1.E(1)&lt;br /&gt;
|&lt;br /&gt;
::(1) Assets that cannot process, store, or transmit CUI&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== Task 2. Given a scenario, analyze the CMMC Assessment Scope based on the predetermined CUI categories within the CMMC Level 2 Assessment Scoping Guide. ===&lt;br /&gt;
{|class=&amp;quot;wikitable&amp;quot; style=&amp;quot;width: 85%;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;width: 10%&amp;quot;|Lesson Topic&lt;br /&gt;
! style=&amp;quot;width: 10%&amp;quot;|Objective&lt;br /&gt;
! style=&amp;quot;width: 80%&amp;quot;|Objective Description&lt;br /&gt;
|-&lt;br /&gt;
|4B&lt;br /&gt;
|2.2.1&lt;br /&gt;
|1. CMMC assessment asset categories (In-scope)&lt;br /&gt;
|-&lt;br /&gt;
|4B&lt;br /&gt;
|2.2.1.A&lt;br /&gt;
|&lt;br /&gt;
:A. CUI Assets&lt;br /&gt;
|-&lt;br /&gt;
|4B&lt;br /&gt;
|2.2.1.B&lt;br /&gt;
|&lt;br /&gt;
:B. Security Protection Assets&lt;br /&gt;
|-&lt;br /&gt;
|4B&lt;br /&gt;
|2.2.1.C&lt;br /&gt;
|&lt;br /&gt;
:C. Contractor Risked Managed Assets&lt;br /&gt;
|-&lt;br /&gt;
|4B&lt;br /&gt;
|2.2.1.D&lt;br /&gt;
|&lt;br /&gt;
:D. Specialized Assets&lt;br /&gt;
|-&lt;br /&gt;
|4B&lt;br /&gt;
|2.2.2&lt;br /&gt;
|2. CMMC assessment asset categories (Out-of-scope)&lt;br /&gt;
|-&lt;br /&gt;
|4A&lt;br /&gt;
|2.2.3&lt;br /&gt;
|3. Separation Techniques&lt;br /&gt;
|-&lt;br /&gt;
|4A&lt;br /&gt;
|2.2.3.A&lt;br /&gt;
|&lt;br /&gt;
:A. Logical separation&lt;br /&gt;
|-&lt;br /&gt;
|4A&lt;br /&gt;
|2.2.3.A(1)&lt;br /&gt;
|&lt;br /&gt;
::(1) Firewalls; and&lt;br /&gt;
|-&lt;br /&gt;
|4A&lt;br /&gt;
|2.2.3.A(2)&lt;br /&gt;
|&lt;br /&gt;
::(2) Virtual Local Area Network (VLANs)&lt;br /&gt;
|-&lt;br /&gt;
|4A&lt;br /&gt;
|2.2.3.B&lt;br /&gt;
|&lt;br /&gt;
:B. Physical separation&lt;br /&gt;
|-&lt;br /&gt;
|4A&lt;br /&gt;
|2.2.3.B(1)&lt;br /&gt;
|&lt;br /&gt;
::(1) Gates;&lt;br /&gt;
|-&lt;br /&gt;
|4A&lt;br /&gt;
|2.2.3.B(2)&lt;br /&gt;
|&lt;br /&gt;
::(2) Locks;&lt;br /&gt;
|-&lt;br /&gt;
|4A&lt;br /&gt;
|2.2.3.B(3)&lt;br /&gt;
|&lt;br /&gt;
::(3) Badge access; and&lt;br /&gt;
|-&lt;br /&gt;
|4A&lt;br /&gt;
|2.2.3.B(4)&lt;br /&gt;
|&lt;br /&gt;
::(4) Guards&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== Task 3. Evaluate CMMC assessment scope considerations based on the CMMC Level 2 Assessment Scoping Guide. ===&lt;br /&gt;
{|class=&amp;quot;wikitable&amp;quot; style=&amp;quot;width: 85%;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;width: 10%&amp;quot;|Lesson Topic&lt;br /&gt;
! style=&amp;quot;width: 10%&amp;quot;|Objective&lt;br /&gt;
! style=&amp;quot;width: 80%&amp;quot;|Objective Description&lt;br /&gt;
|-&lt;br /&gt;
|4E&lt;br /&gt;
|2.3.1&lt;br /&gt;
|1. FCI and CUI within the same Assessment Scope:&lt;br /&gt;
|-&lt;br /&gt;
|4E&lt;br /&gt;
|2.3.1.A&lt;br /&gt;
|&lt;br /&gt;
:A. Contractor defines FCI/CUI assets (In-scope)&lt;br /&gt;
|-&lt;br /&gt;
|4E&lt;br /&gt;
|2.3.1.B&lt;br /&gt;
|&lt;br /&gt;
:B. CMMC Assessor certifies implementation of Level 1 &amp;amp; 2 practices&lt;br /&gt;
|-&lt;br /&gt;
|4E&lt;br /&gt;
|2.3.2&lt;br /&gt;
|2. FCI and CUI NOT within the same Assessment Scope:&lt;br /&gt;
|-&lt;br /&gt;
|4E&lt;br /&gt;
|2.3.2.A&lt;br /&gt;
|&lt;br /&gt;
:A. Contractor defines Self-Assessment of FCI assets (In-scope)&lt;br /&gt;
|-&lt;br /&gt;
|4E&lt;br /&gt;
|2.3.2.B&lt;br /&gt;
|&lt;br /&gt;
:B. Contractor defines CUI assets (In-scope), CMMC Assessor certifies implementation of Level 1 &amp;amp; 2 practices&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
|4C, 4D&lt;br /&gt;
|2.3.3&lt;br /&gt;
|3. External Services Providers&lt;br /&gt;
|-&lt;br /&gt;
|4D&lt;br /&gt;
|2.3.3.A&lt;br /&gt;
|&lt;br /&gt;
:A. Evaluation of responsibility matrix&lt;br /&gt;
|-&lt;br /&gt;
|2C, 4E&lt;br /&gt;
|2.3.3.B&lt;br /&gt;
|&lt;br /&gt;
:B. Non-Duplication&lt;br /&gt;
|-&lt;br /&gt;
|4D&lt;br /&gt;
|2.3.3.C&lt;br /&gt;
|&lt;br /&gt;
:C. Agreements, Service-Level Agreements (SLAs)&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Domain 3: CMMC Assessment Process (CAP) v5.X ==&lt;br /&gt;
=== Task 1. Given a scenario, apply the appropriate phases and steps to plan, prepare, conduct, and report on a CMMC Level 2 Assessment. ===&lt;br /&gt;
{|class=&amp;quot;wikitable&amp;quot; style=&amp;quot;width: 85%;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;width: 10%&amp;quot;|Lesson Topic&lt;br /&gt;
! style=&amp;quot;width: 10%&amp;quot;|Objective&lt;br /&gt;
! style=&amp;quot;width: 80%&amp;quot;|Objective Description&lt;br /&gt;
|-&lt;br /&gt;
|3A, 3B, 3C&lt;br /&gt;
|3.1.1&lt;br /&gt;
|1. Phase 1 - Plan and Prepare Assessments:&lt;br /&gt;
|-&lt;br /&gt;
|3B&lt;br /&gt;
|3.1.1.A&lt;br /&gt;
|&lt;br /&gt;
:A. Analyze requirements&lt;br /&gt;
|-&lt;br /&gt;
|3C&lt;br /&gt;
|3.1.1.B&lt;br /&gt;
|&lt;br /&gt;
:B. Develop Assessment plan&lt;br /&gt;
|-&lt;br /&gt;
|3B&lt;br /&gt;
|3.1.1.C&lt;br /&gt;
|&lt;br /&gt;
:C. Verify readiness to conduct assessment&lt;br /&gt;
|-&lt;br /&gt;
|3A, 3D&lt;br /&gt;
|3.1.2&lt;br /&gt;
|2. Phase 2 - Conduct assessment:&lt;br /&gt;
|-&lt;br /&gt;
|3D&lt;br /&gt;
|3.1.2.A&lt;br /&gt;
|&lt;br /&gt;
:a. Collect and examine Evidence&lt;br /&gt;
|-&lt;br /&gt;
|3D&lt;br /&gt;
|3.1.2.B&lt;br /&gt;
|&lt;br /&gt;
:b. Score practices and validate preliminary results&lt;br /&gt;
|-&lt;br /&gt;
|3D&lt;br /&gt;
|3.1.2.C&lt;br /&gt;
|&lt;br /&gt;
:c. Generate final recommended Assessment Results&lt;br /&gt;
|-&lt;br /&gt;
|3A&lt;br /&gt;
|3.1.3&lt;br /&gt;
|3. Phase 3 - Report Recommended Assessment Results:&lt;br /&gt;
|-&lt;br /&gt;
|3F&lt;br /&gt;
|3.1.3.A&lt;br /&gt;
|&lt;br /&gt;
:a. Deliver Recommended Assessment Results&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Domain 4: CMMC Levels 2 Practices ==&lt;br /&gt;
=== Task 1. Identify evidence verification/validation methods and objects for Practices based on the CMMC Level 2 Assessment Guide and CMMC Assessment Process (CAP) documentation. ===&lt;br /&gt;
{|class=&amp;quot;wikitable&amp;quot; style=&amp;quot;width: 85%;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;width: 10%&amp;quot;|Lesson Topic&lt;br /&gt;
! style=&amp;quot;width: 10%&amp;quot;|Objective&lt;br /&gt;
! style=&amp;quot;width: 80%&amp;quot;|Objective Description&lt;br /&gt;
|-&lt;br /&gt;
|3D&lt;br /&gt;
|4.1.1&lt;br /&gt;
|1. Methods and objects for determining evidence&lt;br /&gt;
|-&lt;br /&gt;
|3D&lt;br /&gt;
|4.1.1.A&lt;br /&gt;
|&lt;br /&gt;
:A. Examine&lt;br /&gt;
|-&lt;br /&gt;
|3D&lt;br /&gt;
|4.1.1.B&lt;br /&gt;
|&lt;br /&gt;
:B. Interview&lt;br /&gt;
|-&lt;br /&gt;
|3D&lt;br /&gt;
|4.1.1.C&lt;br /&gt;
|&lt;br /&gt;
:C. Test&lt;br /&gt;
|-&lt;br /&gt;
|3D&lt;br /&gt;
|4.1.2&lt;br /&gt;
|2. Adequacy and sufficiency related to Evidence around all below practices&lt;br /&gt;
|-&lt;br /&gt;
|3D&lt;br /&gt;
|4.1.2.A&lt;br /&gt;
|&lt;br /&gt;
:A. Characteristics of acceptable Evidence&lt;br /&gt;
|-&lt;br /&gt;
|3D&lt;br /&gt;
|4.1.2.B&lt;br /&gt;
|&lt;br /&gt;
:B. Evidence of enabling persistent and habitual application of practices&lt;br /&gt;
|-&lt;br /&gt;
|3D&lt;br /&gt;
|4.1.2.B(1)&lt;br /&gt;
|&lt;br /&gt;
::(1) Policy&lt;br /&gt;
|-&lt;br /&gt;
|3D&lt;br /&gt;
|4.1.2.B(2)&lt;br /&gt;
|&lt;br /&gt;
::(2) Plan&lt;br /&gt;
|-&lt;br /&gt;
|3D&lt;br /&gt;
|4.1.2.B(3)&lt;br /&gt;
|&lt;br /&gt;
::(3) Resourcing&lt;br /&gt;
|-&lt;br /&gt;
|3D&lt;br /&gt;
|4.1.2.B(4)&lt;br /&gt;
|&lt;br /&gt;
::(4) Communication&lt;br /&gt;
|-&lt;br /&gt;
|3D&lt;br /&gt;
|4.1.2.B(5)&lt;br /&gt;
|&lt;br /&gt;
::(5) Training&lt;br /&gt;
|-&lt;br /&gt;
|3D&lt;br /&gt;
|4.1.2.C&lt;br /&gt;
|&lt;br /&gt;
:C. Characterization of evidence&lt;br /&gt;
|-&lt;br /&gt;
|2C, 3D&lt;br /&gt;
|4.1.2.C(1)&lt;br /&gt;
|&lt;br /&gt;
::(1) Validate that evidence effectively meets intent of standard&lt;br /&gt;
|-&lt;br /&gt;
|3D&lt;br /&gt;
|4.1.2.C(2)&lt;br /&gt;
|&lt;br /&gt;
::(2) An objective and systematic examination of evidence for the purpose of providing an independent assessment of the performance of CMMC&lt;br /&gt;
|-&lt;br /&gt;
|5A, 6A, 7A, 8A, 9A, 10A, 11A, 12A, 13A, 14A, 15A, 16, 17A, 18A&lt;br /&gt;
|4.1.3&lt;br /&gt;
|3. CMMC Level 2 Assessment Practice objectives including potential methods, objects, and assessment considerations (by domain):&lt;br /&gt;
(at a minimum the practices listed below must be evaluated for CCA candidates)&lt;br /&gt;
|-&lt;br /&gt;
|5A, 5B&lt;br /&gt;
|4.1.3.A&lt;br /&gt;
|A. Access Control (AC)&lt;br /&gt;
|-&lt;br /&gt;
|5A&lt;br /&gt;
|4.1.3.A(1)&lt;br /&gt;
|&lt;br /&gt;
:(1) AC.L2-3.1.3 – Control CUI Flow&lt;br /&gt;
|-&lt;br /&gt;
|5A&lt;br /&gt;
|4.1.3.A(2)&lt;br /&gt;
|&lt;br /&gt;
:(2) AC.L2-3.1.4 – Separation of Duties&lt;br /&gt;
|-&lt;br /&gt;
|5A&lt;br /&gt;
|4.1.3.A(3)&lt;br /&gt;
|&lt;br /&gt;
:(3) AC.L2-3.1.5 – Least Privilege&lt;br /&gt;
|-&lt;br /&gt;
|5A&lt;br /&gt;
|4.1.3.A(4)&lt;br /&gt;
|&lt;br /&gt;
:(4) AC.L2-3.1.6 – Non-Privileged Account Use&lt;br /&gt;
|-&lt;br /&gt;
|5A&lt;br /&gt;
|4.1.3.A(5)&lt;br /&gt;
|&lt;br /&gt;
:(5) AC.L2-3.1.7 – Privileged Functions&lt;br /&gt;
|-&lt;br /&gt;
|5A&lt;br /&gt;
|4.1.3.A(6)&lt;br /&gt;
|&lt;br /&gt;
:(6) AC.L2-3.1.8 – Unsuccessful Logon Attempts&lt;br /&gt;
|-&lt;br /&gt;
|5A&lt;br /&gt;
|4.1.3.A(7)&lt;br /&gt;
|&lt;br /&gt;
:(7) AC.L2-3.1.9 – Privacy &amp;amp; Security Notices&lt;br /&gt;
|-&lt;br /&gt;
|5A&lt;br /&gt;
|4.1.3.A(8)&lt;br /&gt;
|&lt;br /&gt;
:(8) AC.L2-3.1.10 – Session Lock&lt;br /&gt;
|-&lt;br /&gt;
|5A&lt;br /&gt;
|4.1.3.A(9)&lt;br /&gt;
|&lt;br /&gt;
:(9) AC.L2-3.1.11 – Session Termination&lt;br /&gt;
|-&lt;br /&gt;
|5A&lt;br /&gt;
|4.1.3.A(10)&lt;br /&gt;
|&lt;br /&gt;
:(10) AC.L2-3.1.12 – Control Remote Access&lt;br /&gt;
|-&lt;br /&gt;
|5A&lt;br /&gt;
|4.1.3.A(11)&lt;br /&gt;
|&lt;br /&gt;
:(11) AC.L2-3.1.13 – Remote Access Confidentiality&lt;br /&gt;
|-&lt;br /&gt;
|5A&lt;br /&gt;
|4.1.3.A(12)&lt;br /&gt;
|&lt;br /&gt;
:(12) AC.L2-3.1.14 – Remote Access Routing&lt;br /&gt;
|-&lt;br /&gt;
|5A&lt;br /&gt;
|4.1.3.A(13)&lt;br /&gt;
|&lt;br /&gt;
:(13) AC.L2-3.1.15 – Privileged Remote Access&lt;br /&gt;
|-&lt;br /&gt;
|5A&lt;br /&gt;
|4.1.3.A(14)&lt;br /&gt;
|&lt;br /&gt;
:(14) AC.L2-3.1.16 – Wireless Access Authorization&lt;br /&gt;
|-&lt;br /&gt;
|5A&lt;br /&gt;
|4.1.3.A(15)&lt;br /&gt;
|&lt;br /&gt;
:(15) AC.L2-3.1.17 – Wireless Access Protection&lt;br /&gt;
|-&lt;br /&gt;
|5A&lt;br /&gt;
|4.1.3.A(16)&lt;br /&gt;
|&lt;br /&gt;
:(16) AC.L2-3.1.18 – Mobile Device Connection&lt;br /&gt;
|-&lt;br /&gt;
|5A&lt;br /&gt;
|4.1.3.A(17)&lt;br /&gt;
|&lt;br /&gt;
:(17) AC.L2-3.1.19 – Encrypt CUI on Mobile&lt;br /&gt;
|-&lt;br /&gt;
|5A&lt;br /&gt;
|4.1.3.A(18)&lt;br /&gt;
|&lt;br /&gt;
:(18) AC.L2-3.1.21 – Portable Storage Use&lt;br /&gt;
|-&lt;br /&gt;
|6A, 6B&lt;br /&gt;
|4.1.3.B&lt;br /&gt;
|B. Awareness &amp;amp; Training (AT)&lt;br /&gt;
|-&lt;br /&gt;
|6A&lt;br /&gt;
|4.1.3.B(1)&lt;br /&gt;
|&lt;br /&gt;
:(1) AT.L2-3.2.1 – Role-Based Risk Awareness&lt;br /&gt;
|-&lt;br /&gt;
|6A&lt;br /&gt;
|4.1.3.B(2)&lt;br /&gt;
|&lt;br /&gt;
:(2) AT.L2-3.2.2 – Role-Based Training&lt;br /&gt;
|-&lt;br /&gt;
|6A&lt;br /&gt;
|4.1.3.B(3)&lt;br /&gt;
|&lt;br /&gt;
:(3) AT.L2-3.2.3 – Insider Threat Awareness&lt;br /&gt;
|-&lt;br /&gt;
|7A, 7B&lt;br /&gt;
|4.1.3.C&lt;br /&gt;
|C. Audit &amp;amp; Accountability (AU)&lt;br /&gt;
|-&lt;br /&gt;
|7A&lt;br /&gt;
|4.1.3.C(1)&lt;br /&gt;
|&lt;br /&gt;
:(1) AU.L2-3.3.1 – System Auditing&lt;br /&gt;
|-&lt;br /&gt;
|7A&lt;br /&gt;
|4.1.3.C(2)&lt;br /&gt;
|&lt;br /&gt;
:(2) AU.L2-3.3.2 – User Accountability&lt;br /&gt;
|-&lt;br /&gt;
|7A&lt;br /&gt;
|4.1.3.C(3)&lt;br /&gt;
|&lt;br /&gt;
:(3) AU.L2-3.3.3 – Event Review&lt;br /&gt;
|-&lt;br /&gt;
|7A&lt;br /&gt;
|4.1.3.C(4)&lt;br /&gt;
|&lt;br /&gt;
:(4) AU.L2-3.3.4 – Audit Failure Alerting&lt;br /&gt;
|-&lt;br /&gt;
|7A&lt;br /&gt;
|4.1.3.C(5)&lt;br /&gt;
|&lt;br /&gt;
:(5) AU.L2-3.3.5 – Audit Correlation&lt;br /&gt;
|-&lt;br /&gt;
|7A&lt;br /&gt;
|4.1.3.C(6)&lt;br /&gt;
|&lt;br /&gt;
:(6) AU.L2-3.3.6 – Reduction &amp;amp; Reporting&lt;br /&gt;
|-&lt;br /&gt;
|7A&lt;br /&gt;
|4.1.3.C(7)&lt;br /&gt;
|&lt;br /&gt;
:(7) AU.L2-3.3.7 – Authoritative Time Source&lt;br /&gt;
|-&lt;br /&gt;
|7A&lt;br /&gt;
|4.1.3.C(8)&lt;br /&gt;
|&lt;br /&gt;
:(8) AU.L2-3.3.8 – Audit Protection&lt;br /&gt;
|-&lt;br /&gt;
|7A&lt;br /&gt;
|4.1.3.C(9)&lt;br /&gt;
|&lt;br /&gt;
:(9) AU.L2-3.3.9 – Audit Management&lt;br /&gt;
|-&lt;br /&gt;
|9A, 9B&lt;br /&gt;
|4.1.3.D&lt;br /&gt;
|D. Configuration Management (CM)&lt;br /&gt;
|-&lt;br /&gt;
|9A&lt;br /&gt;
|4.1.3.D(1)&lt;br /&gt;
|&lt;br /&gt;
:(1) CM.L2-3.4.1 – System Baselining&lt;br /&gt;
|-&lt;br /&gt;
|9A&lt;br /&gt;
|4.1.3.D(2)&lt;br /&gt;
|&lt;br /&gt;
:(2) CM.L2-3.4.2 – Security Configuration Enforcement&lt;br /&gt;
|-&lt;br /&gt;
|9A&lt;br /&gt;
|4.1.3.D(3)&lt;br /&gt;
|&lt;br /&gt;
:(3) CM.L2-3.4.3 – System Change Management&lt;br /&gt;
|-&lt;br /&gt;
|9A&lt;br /&gt;
|4.1.3.D(4)&lt;br /&gt;
|&lt;br /&gt;
:(4) CM.L2-3.4.4 – Security Impact Analysis&lt;br /&gt;
|-&lt;br /&gt;
|9A&lt;br /&gt;
|4.1.3.D(5)&lt;br /&gt;
|&lt;br /&gt;
:(5) CM.L2-3.4.5 – Access Restrictions for Change&lt;br /&gt;
|-&lt;br /&gt;
|9A&lt;br /&gt;
|4.1.3.D(6)&lt;br /&gt;
|&lt;br /&gt;
:(6) CM.L2-3.4.6 – Least Functionality&lt;br /&gt;
|-&lt;br /&gt;
|9A&lt;br /&gt;
|4.1.3.D(7)&lt;br /&gt;
|&lt;br /&gt;
:(7) CM.L2-3.4.7 – Nonessential Functionality&lt;br /&gt;
|-&lt;br /&gt;
|9A&lt;br /&gt;
|4.1.3.D(8)&lt;br /&gt;
|&lt;br /&gt;
:(8) CM.L2-3.4.8 – Application Execution Policy&lt;br /&gt;
|-&lt;br /&gt;
|9A&lt;br /&gt;
|4.1.3.D(9)&lt;br /&gt;
|&lt;br /&gt;
:(9) CM.L2-3.4.9 – User-Installed Software&lt;br /&gt;
|-&lt;br /&gt;
|10A, 10B&lt;br /&gt;
|4.1.3.E&lt;br /&gt;
|E. Identification &amp;amp; Authentication (IA)&lt;br /&gt;
|-&lt;br /&gt;
|10A&lt;br /&gt;
|4.1.3.E(1)&lt;br /&gt;
|&lt;br /&gt;
:(1) IA.L2-3.5.3 – Multifactor Authentication&lt;br /&gt;
|-&lt;br /&gt;
|10A&lt;br /&gt;
|4.1.3.E(2)&lt;br /&gt;
|&lt;br /&gt;
:(2) IA.L2-3.5.4 – Replay-Resistant Authentication&lt;br /&gt;
|-&lt;br /&gt;
|10A&lt;br /&gt;
|4.1.3.E(3)&lt;br /&gt;
|&lt;br /&gt;
:(3) IA.L2-3.5.5 – Identifier Reuse&lt;br /&gt;
|-&lt;br /&gt;
|10A&lt;br /&gt;
|4.1.3.E(4)&lt;br /&gt;
|&lt;br /&gt;
:(4) IA.L2-3.5.6 – Identifier Handling&lt;br /&gt;
|-&lt;br /&gt;
|10A&lt;br /&gt;
|4.1.3.E(5)&lt;br /&gt;
|&lt;br /&gt;
:(5) IA.L2-3.5.7 – Password Complexity&lt;br /&gt;
|-&lt;br /&gt;
|10A&lt;br /&gt;
|4.1.3.E(6)&lt;br /&gt;
|&lt;br /&gt;
:(6) IA.L2-3.5.8 – Password Reuse&lt;br /&gt;
|-&lt;br /&gt;
|10A&lt;br /&gt;
|4.1.3.E(7)&lt;br /&gt;
|&lt;br /&gt;
:(7) IA.L2-3.5.9 – Temporary Passwords&lt;br /&gt;
|-&lt;br /&gt;
|10A&lt;br /&gt;
|4.1.3.E(8)&lt;br /&gt;
|&lt;br /&gt;
:(8) IA.L2-3.5.10 – Cryptographically-Protected Passwords&lt;br /&gt;
|-&lt;br /&gt;
|10A&lt;br /&gt;
|4.1.3.E(9)&lt;br /&gt;
|&lt;br /&gt;
:(9) IA.L2-3.5.11 – Obscure Feedback&lt;br /&gt;
|-&lt;br /&gt;
|11A, 11B&lt;br /&gt;
|4.1.3.F&lt;br /&gt;
|F. Incident Response (IR)&lt;br /&gt;
|-&lt;br /&gt;
|11A&lt;br /&gt;
|4.1.3.F(1)&lt;br /&gt;
|&lt;br /&gt;
:(1) IR.L2-3.6.1 – Incident Handling&lt;br /&gt;
|-&lt;br /&gt;
|11A&lt;br /&gt;
|4.1.3.F(2)&lt;br /&gt;
|&lt;br /&gt;
:(2) IR.L2-3.6.2 – Incident Reporting&lt;br /&gt;
|-&lt;br /&gt;
|11A&lt;br /&gt;
|4.1.3.F(3)&lt;br /&gt;
|&lt;br /&gt;
:(3) IR.L2-3.6.3 – Incident Response Testing&lt;br /&gt;
|-&lt;br /&gt;
|12A, 12B&lt;br /&gt;
|4.1.3.G&lt;br /&gt;
|G. Maintenance (MA)&lt;br /&gt;
|-&lt;br /&gt;
|12A&lt;br /&gt;
|4.1.3.G(1)&lt;br /&gt;
|&lt;br /&gt;
:(1) MA.L2-3.7.1 – Perform Maintenance&lt;br /&gt;
|-&lt;br /&gt;
|12A&lt;br /&gt;
|4.1.3.G(2)&lt;br /&gt;
|&lt;br /&gt;
:(2) MA.L2-3.7.2 – System Maintenance Control&lt;br /&gt;
|-&lt;br /&gt;
|12A&lt;br /&gt;
|4.1.3.G(3)&lt;br /&gt;
|&lt;br /&gt;
:(3) MA.L2-3.7.3 – Equipment Sanitization&lt;br /&gt;
|-&lt;br /&gt;
|12A&lt;br /&gt;
|4.1.3.G(4)&lt;br /&gt;
|&lt;br /&gt;
:(4) MA.L2-3.7.4 – Media Inspection&lt;br /&gt;
|-&lt;br /&gt;
|12A&lt;br /&gt;
|4.1.3.G(5)&lt;br /&gt;
|&lt;br /&gt;
:(5) MA.L2-3.7.5 – Nonlocal Maintenance&lt;br /&gt;
|-&lt;br /&gt;
|12A&lt;br /&gt;
|4.1.3.G(6)&lt;br /&gt;
|&lt;br /&gt;
:(6) MA.L2-3.7.6 – Maintenance Personnel&lt;br /&gt;
|-&lt;br /&gt;
|13A, 13B&lt;br /&gt;
|4.1.3.H&lt;br /&gt;
|H. Media Protection (MP)&lt;br /&gt;
|-&lt;br /&gt;
|13A&lt;br /&gt;
|4.1.3.H(1)&lt;br /&gt;
|&lt;br /&gt;
:(1) MP.L2-3.8.1 – Media Protection&lt;br /&gt;
|-&lt;br /&gt;
|13A&lt;br /&gt;
|4.1.3.H(2)&lt;br /&gt;
|&lt;br /&gt;
:(2) MP.L2-3.8.2 – Media Access&lt;br /&gt;
|-&lt;br /&gt;
|13A&lt;br /&gt;
|4.1.3.H(3)&lt;br /&gt;
|&lt;br /&gt;
:(3) MP.L2-3.8.4 – Media Markings&lt;br /&gt;
|-&lt;br /&gt;
|13A&lt;br /&gt;
|4.1.3.H(4)&lt;br /&gt;
|&lt;br /&gt;
:(4) MP.L2-3.8.5 – Media Accountability&lt;br /&gt;
|-&lt;br /&gt;
|13A&lt;br /&gt;
|4.1.3.H(5)&lt;br /&gt;
|&lt;br /&gt;
:(5) MP.L2-3.8.6 – Portable Storage Encryption&lt;br /&gt;
|-&lt;br /&gt;
|13A&lt;br /&gt;
|4.1.3.H(6)&lt;br /&gt;
|&lt;br /&gt;
:(6) MP.L2-3.8.7 – Removeable Media&lt;br /&gt;
|-&lt;br /&gt;
|13A&lt;br /&gt;
|4.1.3.H(7)&lt;br /&gt;
|&lt;br /&gt;
:(7) MP.L2-3.8.8 – Shared Media&lt;br /&gt;
|-&lt;br /&gt;
|13A&lt;br /&gt;
|4.1.3.H(8)&lt;br /&gt;
|&lt;br /&gt;
:(8) MP.L2-3.8.9 – Protect Backups&lt;br /&gt;
|-&lt;br /&gt;
|15A, 15B&lt;br /&gt;
|4.1.3.I&lt;br /&gt;
|I. Personnel Security (PS)&lt;br /&gt;
|-&lt;br /&gt;
|15A&lt;br /&gt;
|4.1.3.I(1)&lt;br /&gt;
|&lt;br /&gt;
:(1) PS.L2-3.9.1 – Screen Individuals&lt;br /&gt;
|-&lt;br /&gt;
|15A&lt;br /&gt;
|4.1.3.I(2)&lt;br /&gt;
|&lt;br /&gt;
:(2) PS.L2-3.9.2 – Personnel Actions&lt;br /&gt;
|-&lt;br /&gt;
|14A, 14B&lt;br /&gt;
|4.1.3.J&lt;br /&gt;
|J. Physical Protection (PE)&lt;br /&gt;
|-&lt;br /&gt;
|14A&lt;br /&gt;
|4.1.3.J(1)&lt;br /&gt;
|&lt;br /&gt;
:(1) PE.L2-3.10.2 – Monitor Facility&lt;br /&gt;
|-&lt;br /&gt;
|14A&lt;br /&gt;
|4.1.3.J(2)&lt;br /&gt;
|&lt;br /&gt;
:(2) PE.L2-3.10.6 – Alternative Work Sites&lt;br /&gt;
|-&lt;br /&gt;
|16A, 16B&lt;br /&gt;
|4.1.3.K&lt;br /&gt;
|K. Risk Assessment (RA)&lt;br /&gt;
|-&lt;br /&gt;
|16A&lt;br /&gt;
|4.1.3.K(1)&lt;br /&gt;
|&lt;br /&gt;
:(1) RA.L2-3.11.1 – Risk Assessments&lt;br /&gt;
|-&lt;br /&gt;
|16A&lt;br /&gt;
|4.1.3.K(2)&lt;br /&gt;
|&lt;br /&gt;
:(2) RA.L2-3.11.2 – Vulnerability Scan&lt;br /&gt;
|-&lt;br /&gt;
|16A&lt;br /&gt;
|4.1.3.K(3)&lt;br /&gt;
|&lt;br /&gt;
:(3) RA.L2-3.11.3 – Vulnerability Remediation&lt;br /&gt;
|-&lt;br /&gt;
|8A, 8B&lt;br /&gt;
|4.1.3.L&lt;br /&gt;
|L. Security Assessment (CA)&lt;br /&gt;
|-&lt;br /&gt;
|8A&lt;br /&gt;
|4.1.3.L(1)&lt;br /&gt;
|&lt;br /&gt;
:(1) CA.L2-3.12.1 – Security Control Assessment&lt;br /&gt;
|-&lt;br /&gt;
|8A&lt;br /&gt;
|4.1.3.L(2)&lt;br /&gt;
|&lt;br /&gt;
:(2) CA.L2-3.12.2 – Plan of Action&lt;br /&gt;
|-&lt;br /&gt;
|8A&lt;br /&gt;
|4.1.3.L(3)&lt;br /&gt;
|&lt;br /&gt;
:(3) CA.L2-3.12.3 – Security Control Monitoring&lt;br /&gt;
|-&lt;br /&gt;
|8A&lt;br /&gt;
|4.1.3.L(4)&lt;br /&gt;
|&lt;br /&gt;
:(4) CA.L2-3.12.4 – System Security Plan&lt;br /&gt;
|-&lt;br /&gt;
|17A, 17B&lt;br /&gt;
|4.1.3.M&lt;br /&gt;
|M. System &amp;amp; Communications Protection (SC)&lt;br /&gt;
|-&lt;br /&gt;
|17A&lt;br /&gt;
|4.1.3.M(1)&lt;br /&gt;
|&lt;br /&gt;
:(1) SC.L2-3.13.2 – Security Engineering&lt;br /&gt;
|-&lt;br /&gt;
|17A&lt;br /&gt;
|4.1.3.M(2)&lt;br /&gt;
|&lt;br /&gt;
:(2) SC.L2-3.13.3 – Role Separation&lt;br /&gt;
|-&lt;br /&gt;
|17A&lt;br /&gt;
|4.1.3.M(3)&lt;br /&gt;
|&lt;br /&gt;
:(3) SC.L2-3.13.4 – Shared Resource Control&lt;br /&gt;
|-&lt;br /&gt;
|17A&lt;br /&gt;
|4.1.3.M(4)&lt;br /&gt;
|&lt;br /&gt;
:(4) SC.L2-3.13.6 – Network Communication by Exception&lt;br /&gt;
|-&lt;br /&gt;
|17A&lt;br /&gt;
|4.1.3.M(5)&lt;br /&gt;
|&lt;br /&gt;
:(5) SC.L2-3.13.7 – Split Tunneling&lt;br /&gt;
|-&lt;br /&gt;
|17A&lt;br /&gt;
|4.1.3.M(6)&lt;br /&gt;
|&lt;br /&gt;
:(6) SC.L2-3.13.8 – Data in Transit&lt;br /&gt;
|-&lt;br /&gt;
|17A&lt;br /&gt;
|4.1.3.M(7)&lt;br /&gt;
|&lt;br /&gt;
:(7) SC.L2-3.13.9 – Connections Termination&lt;br /&gt;
|-&lt;br /&gt;
|17A&lt;br /&gt;
|4.1.3.M(8)&lt;br /&gt;
|&lt;br /&gt;
:(8) SC.L2-3.13.10 – Key Management&lt;br /&gt;
|-&lt;br /&gt;
|17A&lt;br /&gt;
|4.1.3.M(9)&lt;br /&gt;
|&lt;br /&gt;
:(9) SC.L2-3.13.11 – CUI Encryption&lt;br /&gt;
|-&lt;br /&gt;
|17A&lt;br /&gt;
|4.1.3.M(10)&lt;br /&gt;
|&lt;br /&gt;
:(10) SC.L2-3.13.12 – Collaborative Device Control&lt;br /&gt;
|-&lt;br /&gt;
|17A&lt;br /&gt;
|4.1.3.M(11)&lt;br /&gt;
|&lt;br /&gt;
:(11) SC.L2-3.13.13 – Mobile Code&lt;br /&gt;
|-&lt;br /&gt;
|17A&lt;br /&gt;
|4.1.3.M(12)&lt;br /&gt;
|&lt;br /&gt;
:(12) SC.L2-3.13.14 – Voice over Internet Protocol&lt;br /&gt;
|-&lt;br /&gt;
|17A&lt;br /&gt;
|4.1.3.M(13)&lt;br /&gt;
|&lt;br /&gt;
:(13) SC.L2-3.13.15 – Communications Authenticity&lt;br /&gt;
|-&lt;br /&gt;
|17A&lt;br /&gt;
|4.1.3.M(14)&lt;br /&gt;
|&lt;br /&gt;
:(14) SC.L2-3.13.16 – Data at Rest&lt;br /&gt;
|-&lt;br /&gt;
|18A, 18B&lt;br /&gt;
|4.1.3.N&lt;br /&gt;
|N. System &amp;amp; Information Integrity (SI)&lt;br /&gt;
|-&lt;br /&gt;
|18A&lt;br /&gt;
|4.1.3.N(1)&lt;br /&gt;
|&lt;br /&gt;
:(1) SI.L2-3.14.3 – Security Alerts &amp;amp; Advisories&lt;br /&gt;
|-&lt;br /&gt;
|18A&lt;br /&gt;
|4.1.3.N(2)&lt;br /&gt;
|&lt;br /&gt;
:(2) SI.L2-3.14.6 – Monitor Communications for Attacks&lt;br /&gt;
|-&lt;br /&gt;
|18A&lt;br /&gt;
|4.1.3.N(3)&lt;br /&gt;
|&lt;br /&gt;
:(3) SI.L2-3.14.7 – Identify Unauthorized Use&lt;br /&gt;
|}&lt;/div&gt;</summary>
		<author><name>David</name></author>
	</entry>
	<entry>
		<id>https://cmmcwiki.org/index.php?title=CCP_Blueprint&amp;diff=1599</id>
		<title>CCP Blueprint</title>
		<link rel="alternate" type="text/html" href="https://cmmcwiki.org/index.php?title=CCP_Blueprint&amp;diff=1599"/>
		<updated>2026-03-02T01:32:18Z</updated>

		<summary type="html">&lt;p&gt;David: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&#039;&#039;&#039;Source of Reference: The CCP blueprint document from [https://cyberab.org/CMMC-Ecosystem/Ecosystem-roles/Assessing-and-Certification Cybersecurity Maturity Model Certification Accreditation Body, Inc.]&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
For inquiries and reporting errors on this wiki, please [mailto:support@cmmcwiki.org contact us]. Thank you.&lt;br /&gt;
&lt;br /&gt;
== Domains ==&lt;br /&gt;
Upon successful completion of this exam, the candidate will be able to apply skills and knowledge to the below domains:&lt;br /&gt;
{|class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Objective !! &#039;&#039;&#039;Domain&#039;&#039;&#039; !! &#039;&#039;&#039;Exam Weight&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
|1.0&lt;br /&gt;
|1. CMMC Ecosystem&lt;br /&gt;
|5%&lt;br /&gt;
|-&lt;br /&gt;
|2.0&lt;br /&gt;
|2. CMMC-AB Code of Professional Conduct (Ethics)&lt;br /&gt;
|5%&lt;br /&gt;
|-&lt;br /&gt;
|3.0&lt;br /&gt;
|3. CMMC Governance and Sources Documents&lt;br /&gt;
|15%&lt;br /&gt;
|-&lt;br /&gt;
|4.0&lt;br /&gt;
|4. CMMC Model Construct and Implementation Evaluation&lt;br /&gt;
|35%&lt;br /&gt;
|-&lt;br /&gt;
|5.0&lt;br /&gt;
|5. CMMC Assessment Process (CAP)&lt;br /&gt;
|25%&lt;br /&gt;
|-&lt;br /&gt;
|6.0&lt;br /&gt;
|6. Scoping&lt;br /&gt;
|15%&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Domain 1: CMMC Ecosystem ==&lt;br /&gt;
=== Task 1. Identify and compare roles/responsibilities/requirements of authorities across the CMMC Ecosystem. ===&lt;br /&gt;
{|class=&amp;quot;wikitable&amp;quot; style=&amp;quot;width: 85%;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;width: 10%&amp;quot;|Lesson Topic&lt;br /&gt;
! style=&amp;quot;width: 10%&amp;quot;|Objective&lt;br /&gt;
! style=&amp;quot;width: 80%&amp;quot;|Objective Description&lt;br /&gt;
|-&lt;br /&gt;
|3B&lt;br /&gt;
|1.1.1&lt;br /&gt;
|1. Authorities:&lt;br /&gt;
|-&lt;br /&gt;
|3B&lt;br /&gt;
|1.1.1.A&lt;br /&gt;
|A. Office of the Undersecretary of Defense (OUSD)&lt;br /&gt;
|-&lt;br /&gt;
|1B, 3A, 7A, 8A&lt;br /&gt;
|1.1.1.A.1&lt;br /&gt;
|&lt;br /&gt;
:(1) Cybersecurity standards and best practices and knowledge of how to map these controls and processes across several levels that range from basic to advanced cyber hygiene&lt;br /&gt;
|-&lt;br /&gt;
|1B, 3B, 3C&lt;br /&gt;
|1.1.1.A.2&lt;br /&gt;
|&lt;br /&gt;
:(2) Regulation (DFARS 252.204-7012) that is based on trust by adding a verification component with respect to cybersecurity requirements&lt;br /&gt;
|-&lt;br /&gt;
|3B&lt;br /&gt;
|1.1.1.B&lt;br /&gt;
|B. CMMC Ecosystem and the different types of entities participating in it&lt;br /&gt;
|-&lt;br /&gt;
|3B&lt;br /&gt;
|1.1.1.B.1&lt;br /&gt;
|&lt;br /&gt;
:(1) Cybersecurity Maturity Model Certification Accreditation Body (CMMC-AB)&lt;br /&gt;
|-&lt;br /&gt;
|3B&lt;br /&gt;
|1.1.1.B.1.a&lt;br /&gt;
|&lt;br /&gt;
::(a) Organizations:&lt;br /&gt;
|-&lt;br /&gt;
|3B&lt;br /&gt;
|1.1.1.B.1.a.1&lt;br /&gt;
|&lt;br /&gt;
:::1. Organizations Seeking Certification (OSC)&lt;br /&gt;
|-&lt;br /&gt;
|3B&lt;br /&gt;
|1.1.1.B.1.a.1.1&lt;br /&gt;
|&lt;br /&gt;
::::(1) Purpose, Requirements, and benefits of OSC involvement in the ecosystem&lt;br /&gt;
|-&lt;br /&gt;
|3B&lt;br /&gt;
|1.1.1.B.1.a.2&lt;br /&gt;
|&lt;br /&gt;
:::2. CMMC Third-Party Assessment Organizations (C3PAO)&lt;br /&gt;
|-&lt;br /&gt;
|3B&lt;br /&gt;
|1.1.1.B.1.a.3&lt;br /&gt;
|&lt;br /&gt;
:::3. Registered Provider Organizations (RPO)&lt;br /&gt;
|-&lt;br /&gt;
|3B&lt;br /&gt;
|1.1.1.B.1.a.3.1&lt;br /&gt;
|&lt;br /&gt;
::::(1) Requirements and Benefits of RPO&lt;br /&gt;
|-&lt;br /&gt;
|3B&lt;br /&gt;
|1.1.1.B.1.b&lt;br /&gt;
|&lt;br /&gt;
::(b) Individuals:&lt;br /&gt;
|-&lt;br /&gt;
|3B&lt;br /&gt;
|1.1.1.B.1.b.1&lt;br /&gt;
|&lt;br /&gt;
:::1. Registered Practitioner (RP)&lt;br /&gt;
|-&lt;br /&gt;
|3B&lt;br /&gt;
|1.1.1.B.1.b.1.1&lt;br /&gt;
|&lt;br /&gt;
::::(1) RPs in the CMMC ecosystem provide advice, consulting, and recommendations to their clients. They are the “implementers” and consultants, but do not participate in Certified CMMC Assessments.&lt;br /&gt;
|-&lt;br /&gt;
|3B&lt;br /&gt;
|1.1.1.B.2&lt;br /&gt;
|&lt;br /&gt;
:(2) CMMC Assessors and Instructors Certification Organization (CAICO)&lt;br /&gt;
|-&lt;br /&gt;
|3B&lt;br /&gt;
|1.1.1.B.2.a&lt;br /&gt;
|&lt;br /&gt;
::(a) Organizations:&lt;br /&gt;
|-&lt;br /&gt;
|3B&lt;br /&gt;
|1.1.1.B.2.a.1&lt;br /&gt;
|&lt;br /&gt;
:::1. Licensed Partner Publishers (LPP)&lt;br /&gt;
|-&lt;br /&gt;
|3B&lt;br /&gt;
|1.1.1.B.2.a.1.1&lt;br /&gt;
|&lt;br /&gt;
::::(1) Purpose, requirements, and benefits of LPPs&lt;br /&gt;
|-&lt;br /&gt;
|3B&lt;br /&gt;
|1.1.1.B.2.a.2&lt;br /&gt;
|&lt;br /&gt;
:::2. Licensed Training Providers (LTP)&lt;br /&gt;
|-&lt;br /&gt;
|3B&lt;br /&gt;
|1.1.1.B.2.a.2.1&lt;br /&gt;
|&lt;br /&gt;
::::(1) Purpose, requirements, and benefits of LTPs&lt;br /&gt;
|-&lt;br /&gt;
|3B&lt;br /&gt;
|1.1.1.B.2.b&lt;br /&gt;
|&lt;br /&gt;
::(b) Individuals:&lt;br /&gt;
|-&lt;br /&gt;
|3B&lt;br /&gt;
|1.1.1.B.2.b.1&lt;br /&gt;
|&lt;br /&gt;
:::1. Provisional Assessors (PA)&lt;br /&gt;
|-&lt;br /&gt;
|3B&lt;br /&gt;
|1.1.1.B.2.b.1.1&lt;br /&gt;
|&lt;br /&gt;
::::(1) Purpose, requirements, and benefits of PAs&lt;br /&gt;
|-&lt;br /&gt;
|3B&lt;br /&gt;
|1.1.1.B.2.b.1.2&lt;br /&gt;
|&lt;br /&gt;
::::(2) Timeline for sunsetting&lt;br /&gt;
|-&lt;br /&gt;
|3B&lt;br /&gt;
|1.1.1.B.2.b.2&lt;br /&gt;
|&lt;br /&gt;
:::2. Provisional Instructors (PI)&lt;br /&gt;
|-&lt;br /&gt;
|3B&lt;br /&gt;
|1.1.1.B.2.b.2.1&lt;br /&gt;
|&lt;br /&gt;
::::(1) Purpose, requirements, and benefits of PIs&lt;br /&gt;
|-&lt;br /&gt;
|3B&lt;br /&gt;
|1.1.1.B.2.b.2.2&lt;br /&gt;
|&lt;br /&gt;
::::(2) Timeline for sunsetting&lt;br /&gt;
|-&lt;br /&gt;
|3B&lt;br /&gt;
|1.1.1.B.2.b.3&lt;br /&gt;
|&lt;br /&gt;
:::3. Certified CMMC Professional (CCP)&lt;br /&gt;
|-&lt;br /&gt;
|3B&lt;br /&gt;
|1.1.1.B.2.b.3.1&lt;br /&gt;
|&lt;br /&gt;
::::(1) Purpose, requirements, and benefits of CCPs’ active involvement in the ecosystem&lt;br /&gt;
|-&lt;br /&gt;
|3B&lt;br /&gt;
|1.1.1.B.2.b.3.2&lt;br /&gt;
|&lt;br /&gt;
::::(2) Timeline for CCP certification and assessments&lt;br /&gt;
|-&lt;br /&gt;
|3B&lt;br /&gt;
|1.1.1.B.2.b.4&lt;br /&gt;
|&lt;br /&gt;
:::4. Certified CMMC Assessor (CCA)&lt;br /&gt;
|-&lt;br /&gt;
|3B&lt;br /&gt;
|1.1.1.B.2.b.4.1&lt;br /&gt;
|&lt;br /&gt;
::::(1) Purpose, requirements, and benefits of CCAs’ active involvement in the ecosystem&lt;br /&gt;
|-&lt;br /&gt;
|3B&lt;br /&gt;
|1.1.1.B.2.b.4.2&lt;br /&gt;
|&lt;br /&gt;
::::(2) Timeline for CCA certification and assessments&lt;br /&gt;
|-&lt;br /&gt;
|3B&lt;br /&gt;
|1.1.1.B.2.b.5&lt;br /&gt;
|&lt;br /&gt;
:::5. Certified CMMC Instructor (CCI)&lt;br /&gt;
|-&lt;br /&gt;
|3B&lt;br /&gt;
|1.1.1.B.2.b.5.1&lt;br /&gt;
|&lt;br /&gt;
::::(1) Purpose, requirements, and benefits of CCIs’ active involvement in the ecosystem&lt;br /&gt;
|-&lt;br /&gt;
|3B&lt;br /&gt;
|1.1.1.B.2.b.5.2&lt;br /&gt;
|&lt;br /&gt;
::::(2) Timeline for CCI certification and assessments&lt;br /&gt;
|-&lt;br /&gt;
|3B, 10A&lt;br /&gt;
|1.1.1.B.2.b.6&lt;br /&gt;
|&lt;br /&gt;
:::6. Assessment Team Member&lt;br /&gt;
|-&lt;br /&gt;
|3B, 10A&lt;br /&gt;
|1.1.1.B.2.b.6.1&lt;br /&gt;
|&lt;br /&gt;
::::(1) CCP and CCA roles on the Assessment Team&lt;br /&gt;
|-&lt;br /&gt;
|3B, 10A&lt;br /&gt;
|1.1.1.B.2.b.7&lt;br /&gt;
|&lt;br /&gt;
:::7. CMMC Lead Assessor&lt;br /&gt;
|-&lt;br /&gt;
|3B, 10A&lt;br /&gt;
|1.1.1.B.2.b.7.1&lt;br /&gt;
|&lt;br /&gt;
::::(1) Lead Assessor role on the Assessment Team&lt;br /&gt;
|-&lt;br /&gt;
|3B&lt;br /&gt;
|1.1.1.B.2.b.7.2&lt;br /&gt;
|&lt;br /&gt;
::::(2) Timeline for Lead Assessor certification&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Domain 2: CMMC-AB Code of Professional Conduct (Ethics) ==&lt;br /&gt;
=== Task 1. Identify and apply knowledge of the Guiding Principles and Practices of the CMMC-AB Code of Professional Conduct (CoPC)/ISO/IEC/DOD requirements. ===&lt;br /&gt;
{|class=&amp;quot;wikitable&amp;quot; style=&amp;quot;width: 85%;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;width: 10%&amp;quot;|Lesson Topic&lt;br /&gt;
! style=&amp;quot;width: 10%&amp;quot;|Objective&lt;br /&gt;
! style=&amp;quot;width: 80%&amp;quot;|Objective Description&lt;br /&gt;
|-&lt;br /&gt;
|4B&lt;br /&gt;
|2.1.1&lt;br /&gt;
|1. General ethics topics&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
|4B&lt;br /&gt;
|2.1.2&lt;br /&gt;
|2. CMMC-AB Code of Professional Conduct (CoPC)&lt;br /&gt;
|-&lt;br /&gt;
|3B, 4A&lt;br /&gt;
|2.1.3&lt;br /&gt;
|3. ISO/IEC&lt;br /&gt;
|-&lt;br /&gt;
|4B&lt;br /&gt;
|2.1.4&lt;br /&gt;
|4. Department of Defense (DoD) requirements&lt;br /&gt;
|-&lt;br /&gt;
|4B&lt;br /&gt;
|2.1.5&lt;br /&gt;
|5. Professionalism&lt;br /&gt;
|-&lt;br /&gt;
|4B&lt;br /&gt;
|2.1.6&lt;br /&gt;
|6. Objectivity&lt;br /&gt;
|-&lt;br /&gt;
|4B&lt;br /&gt;
|2.1.7&lt;br /&gt;
|7. Confidentiality&lt;br /&gt;
|-&lt;br /&gt;
|4B&lt;br /&gt;
|2.1.8&lt;br /&gt;
|8. Proper use of methods&lt;br /&gt;
|-&lt;br /&gt;
|4B&lt;br /&gt;
|2.1.9&lt;br /&gt;
|9. Information integrity&lt;br /&gt;
|-&lt;br /&gt;
|4B&lt;br /&gt;
|2.1.10&lt;br /&gt;
|10. Conflicts of interest&lt;br /&gt;
|-&lt;br /&gt;
|4B&lt;br /&gt;
|2.1.11&lt;br /&gt;
|11. Respect for intellectual property&lt;br /&gt;
|-&lt;br /&gt;
|4B&lt;br /&gt;
|2.1.12&lt;br /&gt;
|12. Lawful and ethical practices&lt;br /&gt;
|-&lt;br /&gt;
|4A, 4B, 7A, 10B&lt;br /&gt;
|2.1.13&lt;br /&gt;
|13. Contracts and non-disclosure agreements&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Domain 3. CMMC Governance and Source Documents ==&lt;br /&gt;
=== Task 1. Demonstrate understanding of Federal Contract Information (FCI) and Controlled Unclassified Information (CUI) in non-federal unclassified networks. ===&lt;br /&gt;
{|class=&amp;quot;wikitable&amp;quot; style=&amp;quot;width: 85%;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;width: 10%&amp;quot;|Lesson Topic&lt;br /&gt;
! style=&amp;quot;width: 10%&amp;quot;|Objective&lt;br /&gt;
! style=&amp;quot;width: 80%&amp;quot;|Objective Description&lt;br /&gt;
|-&lt;br /&gt;
|1B&lt;br /&gt;
|3.1.1&lt;br /&gt;
|1. Current Department of Defense (DoD) Defense Industrial Base (DIB) Cybersecurity Efforts, Regulations, and Executive Orders pertaining to the CMMC program:&lt;br /&gt;
|-&lt;br /&gt;
|1B, 2B&lt;br /&gt;
|3.1.1.A&lt;br /&gt;
|&lt;br /&gt;
:A. Part 32 of the Code of Federal Regulations (C.F.R.)&lt;br /&gt;
|-&lt;br /&gt;
|1B&lt;br /&gt;
|3.1.1.B&lt;br /&gt;
|&lt;br /&gt;
:B. Defense Federal Acquisition Regulation Supplement (DFARS) in Part 48 of the C.F.R&lt;br /&gt;
|-&lt;br /&gt;
|1B, 3B&lt;br /&gt;
|3.1.1.C&lt;br /&gt;
|&lt;br /&gt;
:C. DFARS Clause 252.204-7012&lt;br /&gt;
|-&lt;br /&gt;
|1B, 7B&lt;br /&gt;
|3.1.1.C.1&lt;br /&gt;
|&lt;br /&gt;
::(1) National Institute of Standards and Technology (NIST) SP 800-171&lt;br /&gt;
|-&lt;br /&gt;
|2A&lt;br /&gt;
|3.1.1.C.2&lt;br /&gt;
|&lt;br /&gt;
::(2) Technical Data (DFARS 252.227-7013)&lt;br /&gt;
|-&lt;br /&gt;
|1B&lt;br /&gt;
|3.1.1.C.3&lt;br /&gt;
|&lt;br /&gt;
::(3) FedRAMP&lt;br /&gt;
|-&lt;br /&gt;
|3B&lt;br /&gt;
|3.1.2&lt;br /&gt;
|2. CMMC Framework Tenets:&lt;br /&gt;
|-&lt;br /&gt;
|3B&lt;br /&gt;
|3.1.2.A&lt;br /&gt;
|&lt;br /&gt;
:A. Key aspects of CMMC v.20 program requirements&lt;br /&gt;
|-&lt;br /&gt;
|3B&lt;br /&gt;
|3.1.2.A.1&lt;br /&gt;
|&lt;br /&gt;
::(1) Streamlined Model&lt;br /&gt;
|-&lt;br /&gt;
|3B, 7B&lt;br /&gt;
|3.1.2.A.1.a&lt;br /&gt;
|&lt;br /&gt;
:::(a) Focused on the most critical requirements&lt;br /&gt;
|-&lt;br /&gt;
|3B, 7B&lt;br /&gt;
|3.1.2.A.1.b&lt;br /&gt;
|&lt;br /&gt;
:::(b) Aligned with widely accepted standards&lt;br /&gt;
|-&lt;br /&gt;
|3B&lt;br /&gt;
|3.1.2.A.2&lt;br /&gt;
|&lt;br /&gt;
::(2) Reliable Assessments&lt;br /&gt;
|-&lt;br /&gt;
|3B&lt;br /&gt;
|3.1.2.A.2.a&lt;br /&gt;
|&lt;br /&gt;
:::(a) Reduced assessment costs&lt;br /&gt;
|-&lt;br /&gt;
|3B&lt;br /&gt;
|3.1.2.A.2.b&lt;br /&gt;
|&lt;br /&gt;
:::(b) Higher accountability&lt;br /&gt;
|-&lt;br /&gt;
|3B&lt;br /&gt;
|3.1.2.A.3&lt;br /&gt;
|&lt;br /&gt;
::(3) Flexible Implementation&lt;br /&gt;
|-&lt;br /&gt;
|3B&lt;br /&gt;
|3.1.2.A.3.a&lt;br /&gt;
|&lt;br /&gt;
:::(a) Spirit of collaboration&lt;br /&gt;
|-&lt;br /&gt;
|3B&lt;br /&gt;
|3.1.2.A.3.b&lt;br /&gt;
|&lt;br /&gt;
:::(b) Added flexibility and speed&lt;br /&gt;
|-&lt;br /&gt;
|3B&lt;br /&gt;
|3.1.2.B&lt;br /&gt;
|&lt;br /&gt;
:B. Rulemaking and timeline for CMMC v2.0&lt;br /&gt;
|-&lt;br /&gt;
|3B&lt;br /&gt;
|3.1.2.B.1&lt;br /&gt;
|&lt;br /&gt;
::(1) Incentives, Assessments, and 9–24-month rule making&lt;br /&gt;
|-&lt;br /&gt;
|3B&lt;br /&gt;
|3.1.2.C&lt;br /&gt;
|&lt;br /&gt;
:C. Levels of CMMC assessments and requirements&lt;br /&gt;
|-&lt;br /&gt;
|3B&lt;br /&gt;
|3.1.2.C.1&lt;br /&gt;
|&lt;br /&gt;
::(1) Foundational/Level 1 (same as previous CMMC v1.0 level 1)&lt;br /&gt;
|-&lt;br /&gt;
|8A&lt;br /&gt;
|3.1.2.C.1.a&lt;br /&gt;
|&lt;br /&gt;
:::(a) FAR Clause 52.204-21&lt;br /&gt;
|-&lt;br /&gt;
|3A, 8A&lt;br /&gt;
|3.1.2.C.1.a.i&lt;br /&gt;
|&lt;br /&gt;
::::i. Provide overview of the 17 basic safeguarding requirements and how procedures are applied within the CMMC L1/L2 practices/assessment framework&lt;br /&gt;
|-&lt;br /&gt;
|3A, 3B, 9A&lt;br /&gt;
|3.1.2.C.2&lt;br /&gt;
|&lt;br /&gt;
::(2) Advanced/Level 2 (previous level 3)&lt;br /&gt;
|-&lt;br /&gt;
|3A, 7B&lt;br /&gt;
|3.1.2.C.2.a&lt;br /&gt;
|&lt;br /&gt;
:::(a) NIST SP 800-171 (Requirements)&lt;br /&gt;
|-&lt;br /&gt;
|3A, 7B, 9A&lt;br /&gt;
|3.1.2.C.2.a.i&lt;br /&gt;
|&lt;br /&gt;
::::i. Provide overview of the 110 NIST SP 800-171 requirements and how they are applied within the CMMC Level 2 practices/assessment framework&lt;br /&gt;
|-&lt;br /&gt;
|3B, 3C&lt;br /&gt;
|3.1.2.D&lt;br /&gt;
|&lt;br /&gt;
:D. Self-Assessments vs. Third-Party Assessments&lt;br /&gt;
|-&lt;br /&gt;
|3B, 3C&lt;br /&gt;
|3.1.2.D.1&lt;br /&gt;
|&lt;br /&gt;
::(1) Define different criteria for various assessment type under CMMC v2.0 framework&lt;br /&gt;
|-&lt;br /&gt;
|3C&lt;br /&gt;
|3.1.3&lt;br /&gt;
|3. Consequences of non-compliance:&lt;br /&gt;
|-&lt;br /&gt;
|3C&lt;br /&gt;
|3.1.3.A&lt;br /&gt;
|&lt;br /&gt;
:A. Failure to receive an award of contract&lt;br /&gt;
|-&lt;br /&gt;
|3C&lt;br /&gt;
|3.1.3.B&lt;br /&gt;
|&lt;br /&gt;
:B. Contractual liability&lt;br /&gt;
|-&lt;br /&gt;
|3C&lt;br /&gt;
|3.1.3.C&lt;br /&gt;
|&lt;br /&gt;
:C. False Claims Act&lt;br /&gt;
|-&lt;br /&gt;
|3C&lt;br /&gt;
|3.1.3.C.1&lt;br /&gt;
|&lt;br /&gt;
::(1) US Department of Justice,&lt;br /&gt;
|-&lt;br /&gt;
|3C&lt;br /&gt;
|3.1.3.C.1.a&lt;br /&gt;
|&lt;br /&gt;
:::(a) Civil Cyber-Fraud Initiative&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== Task 2. Determine the appropriate roles/responsibilities/authority for Federal Contract Information (FCI) and Controlled Unclassified Information (CUI). ===&lt;br /&gt;
{|class=&amp;quot;wikitable&amp;quot; style=&amp;quot;width: 85%;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;width: 10%&amp;quot;|Lesson Topic&lt;br /&gt;
! style=&amp;quot;width: 10%&amp;quot;|Objective&lt;br /&gt;
! style=&amp;quot;width: 80%&amp;quot;|Objective Description&lt;br /&gt;
|-&lt;br /&gt;
|2A&lt;br /&gt;
|3.2.1&lt;br /&gt;
|1. Importance of data classification, collection, and analysis&lt;br /&gt;
|-&lt;br /&gt;
|2A&lt;br /&gt;
|3.2.1.A&lt;br /&gt;
|&lt;br /&gt;
:A. CUI Basic versus Specified&lt;br /&gt;
|-&lt;br /&gt;
|2A&lt;br /&gt;
|3.2.2&lt;br /&gt;
|2. Contractor sensitive data categories&lt;br /&gt;
|-&lt;br /&gt;
|2A&lt;br /&gt;
|3.2.2.A&lt;br /&gt;
|&lt;br /&gt;
:A. Federal Contract Information (FCI)&lt;br /&gt;
|-&lt;br /&gt;
|2A&lt;br /&gt;
|3.2.2.A.1&lt;br /&gt;
|&lt;br /&gt;
::(1) Section 4.1901 of the Federal Acquisition Regulation (FAR)&lt;br /&gt;
|-&lt;br /&gt;
|2A&lt;br /&gt;
|3.2.2.B&lt;br /&gt;
|&lt;br /&gt;
:B. Controlled Unclassified Information (CUI)&lt;br /&gt;
|-&lt;br /&gt;
|2A, 2B&lt;br /&gt;
|3.2.2.B.1&lt;br /&gt;
|&lt;br /&gt;
::(1) Part 2002 of Title 32 CFR, 2002.4(h)&lt;br /&gt;
|-&lt;br /&gt;
|2A, 2B&lt;br /&gt;
|3.2.3&lt;br /&gt;
|3. Government authority for identifying and marking CUI&lt;br /&gt;
|-&lt;br /&gt;
|2A, 2B&lt;br /&gt;
|3.2.3.A&lt;br /&gt;
|&lt;br /&gt;
:A. Executive Order 13556&lt;br /&gt;
|-&lt;br /&gt;
|2A, 2B&lt;br /&gt;
|3.2.3.B&lt;br /&gt;
|&lt;br /&gt;
:B. 32 Code of Federal Regulations, Part 2002 (Implementing Directive)&lt;br /&gt;
|-&lt;br /&gt;
|2A, 2B&lt;br /&gt;
|3.2.3.C&lt;br /&gt;
|&lt;br /&gt;
:C. DoD Instruction 5200.48, Controlled Unclassified Information (CUI)&lt;br /&gt;
|-&lt;br /&gt;
|2B&lt;br /&gt;
|3.2.4&lt;br /&gt;
|4. Contractor/Authorized holders’ responsibilities in handling CUI&lt;br /&gt;
|-&lt;br /&gt;
|2B&lt;br /&gt;
|3.2.4.A&lt;br /&gt;
|&lt;br /&gt;
:A. DoDI 5200.48&lt;br /&gt;
|-&lt;br /&gt;
|1B, 2B&lt;br /&gt;
|3.2.4.B&lt;br /&gt;
|&lt;br /&gt;
:B. Part 2002 of Title 32 CFR&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== Task 3. Demonstrate understanding of the CMMC Source and Supplementary documents. ===&lt;br /&gt;
{|class=&amp;quot;wikitable&amp;quot; style=&amp;quot;width: 85%;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;width: 10%&amp;quot;|Lesson Topic&lt;br /&gt;
! style=&amp;quot;width: 10%&amp;quot;|Objective&lt;br /&gt;
! style=&amp;quot;width: 80%&amp;quot;|Objective Description&lt;br /&gt;
|-&lt;br /&gt;
|3A&lt;br /&gt;
|3.3.1&lt;br /&gt;
|1. CMMC Source Documents&lt;br /&gt;
|-&lt;br /&gt;
|3A, 7B&lt;br /&gt;
|3.3.1.A&lt;br /&gt;
|&lt;br /&gt;
:A. CMMC Model Overview&lt;br /&gt;
|-&lt;br /&gt;
|7A, 7B&lt;br /&gt;
|3.3.1.B&lt;br /&gt;
|&lt;br /&gt;
:B. CMMC Level 1 Assessment Guide&lt;br /&gt;
|-&lt;br /&gt;
|7A, 7B&lt;br /&gt;
|3.3.1.C&lt;br /&gt;
|&lt;br /&gt;
:C. CMMC Level 2 Assessment Guide&lt;br /&gt;
|-&lt;br /&gt;
|5A&lt;br /&gt;
|3.3.1.D&lt;br /&gt;
|&lt;br /&gt;
:D. CMMC Level 1 Scoping Guidance&lt;br /&gt;
|-&lt;br /&gt;
|5A&lt;br /&gt;
|3.3.1.E&lt;br /&gt;
|&lt;br /&gt;
:E. CMMC Level 2 Scoping Guidance&lt;br /&gt;
|-&lt;br /&gt;
|3A, 7A, 10B, 10C, 10D, 10E&lt;br /&gt;
|3.3.1.F&lt;br /&gt;
|&lt;br /&gt;
:F. CMMC Assessment Process (CAP)&lt;br /&gt;
|-&lt;br /&gt;
|3A&lt;br /&gt;
|3.3.1.G&lt;br /&gt;
|&lt;br /&gt;
:G. CMMC Glossary&lt;br /&gt;
|-&lt;br /&gt;
|3A, 10D&lt;br /&gt;
|3.3.1.H&lt;br /&gt;
|&lt;br /&gt;
:H. CMMC Artifact Hashing Tool User Guide&lt;br /&gt;
|-&lt;br /&gt;
|2A&lt;br /&gt;
|3.3.2&lt;br /&gt;
|2. ISOO CUI Registry&lt;br /&gt;
|-&lt;br /&gt;
|2A&lt;br /&gt;
|3.3.2.A&lt;br /&gt;
|&lt;br /&gt;
:A. NARA administers the CUI Registry&lt;br /&gt;
|-&lt;br /&gt;
|2A&lt;br /&gt;
|3.3.2.A.1&lt;br /&gt;
|&lt;br /&gt;
::(1) Types of labeled information on documents such as:&lt;br /&gt;
|-&lt;br /&gt;
|2A&lt;br /&gt;
|3.3.2.A.1.a&lt;br /&gt;
|&lt;br /&gt;
:::(a) Export Controlled (SP-EXPT)&lt;br /&gt;
|-&lt;br /&gt;
|2B&lt;br /&gt;
|3.3.2.A.1.b&lt;br /&gt;
|&lt;br /&gt;
:::(b) Specified marking/labeling using NARA CUI Marking Handbook&lt;br /&gt;
|-&lt;br /&gt;
|2A&lt;br /&gt;
|3.3.3&lt;br /&gt;
|3. DoD CUI Registry&lt;br /&gt;
|-&lt;br /&gt;
|2A, 2B&lt;br /&gt;
|3.3.3.A&lt;br /&gt;
|&lt;br /&gt;
:A. Types of labeled information on documents such as:&lt;br /&gt;
|-&lt;br /&gt;
|2A, 2B&lt;br /&gt;
|3.3.3.A.1&lt;br /&gt;
|&lt;br /&gt;
::(1) Naval Nuclear Propulsion Information (NNPI)&lt;br /&gt;
|-&lt;br /&gt;
|2A, 2B&lt;br /&gt;
|3.3.3.A.2&lt;br /&gt;
|&lt;br /&gt;
::(2) NNPI marking/labeling using DoD CUI Marking Aid&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Domain 4 - CMMC Model Construct and Implementation Evaluation ==&lt;br /&gt;
=== Task 1. Given a scenario, apply the appropriate CMMC Source Documents as an aid to evaluate the implementation/review of CMMC practices. ===&lt;br /&gt;
(At a minimum CCP candidate must be evaluated on CMMC L1 Practices during CCP exam)&lt;br /&gt;
{|class=&amp;quot;wikitable&amp;quot; style=&amp;quot;width: 85%;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;width: 10%&amp;quot;|Lesson Topic&lt;br /&gt;
! style=&amp;quot;width: 10%&amp;quot;|Objective&lt;br /&gt;
! style=&amp;quot;width: 80%&amp;quot;|Objective Description&lt;br /&gt;
|-&lt;br /&gt;
|3A&lt;br /&gt;
|4.1.1&lt;br /&gt;
|1. Model Architecture&lt;br /&gt;
|-&lt;br /&gt;
|3A&lt;br /&gt;
|4.1.2&lt;br /&gt;
|2. Model Levels:&lt;br /&gt;
|-&lt;br /&gt;
|3A, 7B&lt;br /&gt;
|4.1.2.A&lt;br /&gt;
|&lt;br /&gt;
:A. Cumulative Nature&lt;br /&gt;
|-&lt;br /&gt;
|3A&lt;br /&gt;
|4.1.2.B&lt;br /&gt;
|&lt;br /&gt;
:B. Characteristics&lt;br /&gt;
|-&lt;br /&gt;
|3B&lt;br /&gt;
|4.1.2.C&lt;br /&gt;
|&lt;br /&gt;
:C. Levels required for specific contracts&lt;br /&gt;
|-&lt;br /&gt;
|3B&lt;br /&gt;
|4.1.2.C.1&lt;br /&gt;
|&lt;br /&gt;
::(1) Level 1&lt;br /&gt;
|-&lt;br /&gt;
|3B&lt;br /&gt;
|4.1.2.C.2&lt;br /&gt;
|&lt;br /&gt;
::(2) Level 2&lt;br /&gt;
|-&lt;br /&gt;
|3A&lt;br /&gt;
|4.1.3&lt;br /&gt;
|3. Practices:&lt;br /&gt;
|-&lt;br /&gt;
|7B&lt;br /&gt;
|4.1.3.A&lt;br /&gt;
|&lt;br /&gt;
:A. Practices Descriptions&lt;br /&gt;
|-&lt;br /&gt;
|3A&lt;br /&gt;
|4.1.3.A.1&lt;br /&gt;
|&lt;br /&gt;
::(1) Practice Numbering Scheme&lt;br /&gt;
|-&lt;br /&gt;
|3A&lt;br /&gt;
|4.1.3.A.2&lt;br /&gt;
|&lt;br /&gt;
::(2) Objectives&lt;br /&gt;
|-&lt;br /&gt;
|7B&lt;br /&gt;
|4.1.3.A.3&lt;br /&gt;
|&lt;br /&gt;
::(3) Assessment Methods and Objects&lt;br /&gt;
|-&lt;br /&gt;
|8A&lt;br /&gt;
|4.1.4&lt;br /&gt;
|4. Domains:&lt;br /&gt;
|-&lt;br /&gt;
|3A&lt;br /&gt;
|4.1.4.A&lt;br /&gt;
|&lt;br /&gt;
:A. Access Control (AC)&lt;br /&gt;
|-&lt;br /&gt;
|8A&lt;br /&gt;
|4.1.4.A.1&lt;br /&gt;
|&lt;br /&gt;
::(1) AC.L1-3.1.1 – Authorized Access Control&lt;br /&gt;
|-&lt;br /&gt;
|8A&lt;br /&gt;
|4.1.4.A.2&lt;br /&gt;
|&lt;br /&gt;
::(2) AC.L1-3.1.2 – Transaction &amp;amp; Function Control&lt;br /&gt;
|-&lt;br /&gt;
|8A&lt;br /&gt;
|4.1.4.A.3&lt;br /&gt;
|&lt;br /&gt;
::(3) AC.L1-3.1.20 – External Connections&lt;br /&gt;
|-&lt;br /&gt;
|8A&lt;br /&gt;
|4.1.4.A.4&lt;br /&gt;
|&lt;br /&gt;
::(4) AC.L1-3.1.22 – Control Public Information&lt;br /&gt;
|-&lt;br /&gt;
|3A&lt;br /&gt;
|4.1.4.B&lt;br /&gt;
|&lt;br /&gt;
:B. Audit &amp;amp; Accountability (AU)&lt;br /&gt;
|-&lt;br /&gt;
|3A&lt;br /&gt;
|4.1.4.C&lt;br /&gt;
|&lt;br /&gt;
:C. Awareness &amp;amp; Training (AT)&lt;br /&gt;
|-&lt;br /&gt;
|3A&lt;br /&gt;
|4.1.4.D&lt;br /&gt;
|&lt;br /&gt;
:D. Configuration Management (CM)&lt;br /&gt;
|-&lt;br /&gt;
|3A&lt;br /&gt;
|4.1.4.E&lt;br /&gt;
|&lt;br /&gt;
:E. Identification &amp;amp; Authentication (IA)&lt;br /&gt;
|-&lt;br /&gt;
|8A&lt;br /&gt;
|4.1.4.E.1&lt;br /&gt;
|&lt;br /&gt;
::(1) IA.L1-3.5.1 – Identification&lt;br /&gt;
|-&lt;br /&gt;
|8A&lt;br /&gt;
|4.1.4.E.2&lt;br /&gt;
|&lt;br /&gt;
::(2) IA.L1-3.5.2 – Authentication&lt;br /&gt;
|-&lt;br /&gt;
|3A&lt;br /&gt;
|4.1.4.F&lt;br /&gt;
|&lt;br /&gt;
:F. Incident Response (IR)&lt;br /&gt;
|-&lt;br /&gt;
|3A&lt;br /&gt;
|4.1.4.G&lt;br /&gt;
|&lt;br /&gt;
:G. Maintenance (MA)&lt;br /&gt;
|-&lt;br /&gt;
|3A&lt;br /&gt;
|4.1.4.H&lt;br /&gt;
|&lt;br /&gt;
:H. Media Protection (MP)&lt;br /&gt;
|-&lt;br /&gt;
|8A&lt;br /&gt;
|4.1.4.H.1&lt;br /&gt;
|&lt;br /&gt;
::(1) MP.L1-3.8.3 – Media Disposal&lt;br /&gt;
|-&lt;br /&gt;
|3A&lt;br /&gt;
|4.1.4.I&lt;br /&gt;
|&lt;br /&gt;
:I. Personnel Security (PS)&lt;br /&gt;
|-&lt;br /&gt;
|3A&lt;br /&gt;
|4.1.4.J&lt;br /&gt;
|&lt;br /&gt;
:J. Physical Protection (PE)&lt;br /&gt;
|-&lt;br /&gt;
|8A&lt;br /&gt;
|4.1.4.J.1&lt;br /&gt;
|&lt;br /&gt;
::(1) PE.L1-3.10.1 – Limit Physical Access&lt;br /&gt;
|-&lt;br /&gt;
|8A&lt;br /&gt;
|4.1.4.J.2&lt;br /&gt;
|&lt;br /&gt;
::(2) PE.L1-3.10.3 – Escort Visitors&lt;br /&gt;
|-&lt;br /&gt;
|8A&lt;br /&gt;
|4.1.4.J.3&lt;br /&gt;
|&lt;br /&gt;
::(3) PE.L1-3.10.4 – Physical Access Logs&lt;br /&gt;
|-&lt;br /&gt;
|8A&lt;br /&gt;
|4.1.4.J.4&lt;br /&gt;
|&lt;br /&gt;
::(4) PE.L1-3.10.5 – Manage Physical Access&lt;br /&gt;
|-&lt;br /&gt;
|3A&lt;br /&gt;
|4.1.4.K&lt;br /&gt;
|&lt;br /&gt;
:K. Risk Assessment (RA)&lt;br /&gt;
|-&lt;br /&gt;
|3A&lt;br /&gt;
|4.1.4.L&lt;br /&gt;
|&lt;br /&gt;
:L. Security Assessment (CA)&lt;br /&gt;
|-&lt;br /&gt;
|3A&lt;br /&gt;
|4.1.4.M&lt;br /&gt;
|&lt;br /&gt;
:M. System &amp;amp; Communications Protection (SC)&lt;br /&gt;
|-&lt;br /&gt;
|8A&lt;br /&gt;
|4.1.4.M.1&lt;br /&gt;
|&lt;br /&gt;
::(1) SC.L1-3.13.1 – Boundary Protection&lt;br /&gt;
|-&lt;br /&gt;
|8A&lt;br /&gt;
|4.1.4.M.2&lt;br /&gt;
|&lt;br /&gt;
::(2) SC.L1-3.13.5 – Public-Access System Separation&lt;br /&gt;
|-&lt;br /&gt;
|3A&lt;br /&gt;
|4.1.4.N&lt;br /&gt;
|&lt;br /&gt;
:N. System &amp;amp; Information Integrity (SI)&lt;br /&gt;
|-&lt;br /&gt;
|8A&lt;br /&gt;
|4.1.4.N.1&lt;br /&gt;
|&lt;br /&gt;
::(1) SI.L1-3.14.1 – Flaw Remediation&lt;br /&gt;
|-&lt;br /&gt;
|8A&lt;br /&gt;
|4.1.4.N.1&lt;br /&gt;
|&lt;br /&gt;
::(2) SI.L1-3.14.2 – Malicious Code Protection&lt;br /&gt;
|-&lt;br /&gt;
|8A&lt;br /&gt;
|4.1.4.N.1&lt;br /&gt;
|&lt;br /&gt;
::(3) SI.L1-3.14.4 – Update Malicious Code Protection&lt;br /&gt;
|-&lt;br /&gt;
|8A&lt;br /&gt;
|4.1.4.N.1&lt;br /&gt;
|&lt;br /&gt;
::(4) SI.L1-3.14.5 – System &amp;amp; File Scanning&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== Task 2. Apply knowledge of the CMMC Assessment Criteria and Methodology to the appropriate CMMC practices. ===&lt;br /&gt;
{|class=&amp;quot;wikitable&amp;quot; style=&amp;quot;width: 85%;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;width: 10%&amp;quot;|Lesson Topic&lt;br /&gt;
! style=&amp;quot;width: 10%&amp;quot;|Objective&lt;br /&gt;
! style=&amp;quot;width: 80%&amp;quot;|Objective Description&lt;br /&gt;
|-&lt;br /&gt;
|3A, 7B&lt;br /&gt;
|4.2.1&lt;br /&gt;
|1. The definition of each practice&lt;br /&gt;
|-&lt;br /&gt;
|3A, 7B&lt;br /&gt;
|4.2.2&lt;br /&gt;
|2. The Assessment Objectives&lt;br /&gt;
|-&lt;br /&gt;
|7A, 7B, 8A&lt;br /&gt;
|4.2.3&lt;br /&gt;
|3. The Assessment Methods (Examine, Interview, and Test) to use for the practices&lt;br /&gt;
|-&lt;br /&gt;
|7B&lt;br /&gt;
|4.2.4&lt;br /&gt;
|4. What information to look for in practice discussion&lt;br /&gt;
|-&lt;br /&gt;
|7B&lt;br /&gt;
|4.2.5&lt;br /&gt;
|5. The Key References and their applicability to the practices:&lt;br /&gt;
|-&lt;br /&gt;
|7B&lt;br /&gt;
|4.2.5.A&lt;br /&gt;
|&lt;br /&gt;
::A. Navigating and using the CMMC Assessment Guide(s) content&lt;br /&gt;
|-&lt;br /&gt;
|7A, 7B&lt;br /&gt;
|4.2.5.B&lt;br /&gt;
|&lt;br /&gt;
::B. Determining the assessment method(s) that would be best for gathering sufficient and accurate evidence&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== Task 3. Analyze the adequacy/sufficiency around the location/collection/quality/usage of Evidence. ===&lt;br /&gt;
{|class=&amp;quot;wikitable&amp;quot; style=&amp;quot;width: 85%;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;width: 10%&amp;quot;|Lesson Topic&lt;br /&gt;
! style=&amp;quot;width: 10%&amp;quot;|Objective&lt;br /&gt;
! style=&amp;quot;width: 80%&amp;quot;|Objective Description&lt;br /&gt;
|-&lt;br /&gt;
|7A&lt;br /&gt;
|4.3.1&lt;br /&gt;
|1. Appraised Evidence is adequate&lt;br /&gt;
|-&lt;br /&gt;
|7A&lt;br /&gt;
|4.3.2&lt;br /&gt;
|2. Measure if the Evidence is sufficient&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Domain 5: CMMC Assessment Process ==&lt;br /&gt;
=== Task 1. Choose the appropriate roles of the CCP in the CMMC Assessment Process when developing the assessment plan (Phase 1– Plan and Prepare Assessment). ===&lt;br /&gt;
{|class=&amp;quot;wikitable&amp;quot; style=&amp;quot;width: 85%;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;width: 10%&amp;quot;|Lesson Topic&lt;br /&gt;
! style=&amp;quot;width: 10%&amp;quot;|Objective&lt;br /&gt;
! style=&amp;quot;width: 80%&amp;quot;|Objective Description&lt;br /&gt;
|-&lt;br /&gt;
|10B&lt;br /&gt;
|5.1.1&lt;br /&gt;
|1. Validation criteria of OSC’s assessment evidence&lt;br /&gt;
|-&lt;br /&gt;
|7B&lt;br /&gt;
|5.1.2&lt;br /&gt;
|2. Analyzing the CMMC practice requirements&lt;br /&gt;
|-&lt;br /&gt;
|10B&lt;br /&gt;
|5.1.3&lt;br /&gt;
|3. What needs to be included in a CMMC Assessment Plan&lt;br /&gt;
|-&lt;br /&gt;
|10B&lt;br /&gt;
|5.1.4&lt;br /&gt;
|4. The CMMC Readiness Review Process&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== Task 2. Apply CMMC Assessment Process requirements pertaining to the role of the CCP as an assessment team member while conducting a CMMC assessment (Phase 2 – Conduct Assessment). ===&lt;br /&gt;
{|class=&amp;quot;wikitable&amp;quot; style=&amp;quot;width: 85%;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;width: 10%&amp;quot;|Lesson Topic&lt;br /&gt;
! style=&amp;quot;width: 10%&amp;quot;|Objective&lt;br /&gt;
! style=&amp;quot;width: 80%&amp;quot;|Objective Description&lt;br /&gt;
|-&lt;br /&gt;
|7B, 10C&lt;br /&gt;
|5.2.1&lt;br /&gt;
|1. How to assist/support the Assessment Team during an assessment&lt;br /&gt;
|-&lt;br /&gt;
|7A, 7B, 10C&lt;br /&gt;
|5.2.2&lt;br /&gt;
|2. The three possible assessment methods (Examine, Interview, and Test) and scoring evidence successfully for each practice&lt;br /&gt;
|-&lt;br /&gt;
|10A, 10C&lt;br /&gt;
|5.2.3&lt;br /&gt;
|3. Communication skills to interview or observe tests/demonstrations for assessment practices&lt;br /&gt;
|-&lt;br /&gt;
|7B, 8C, 10C&lt;br /&gt;
|5.2.4&lt;br /&gt;
|4. How Assessment Team Members rate practices and validate preliminary results&lt;br /&gt;
|-&lt;br /&gt;
|10C&lt;br /&gt;
|5.2.5&lt;br /&gt;
|5. How Assessment Team Members assist in the preparation of final findings&lt;br /&gt;
|-&lt;br /&gt;
|10C&lt;br /&gt;
|5.2.6&lt;br /&gt;
|6. How to score practices that are on a Plan of Action and Milestone (POA&amp;amp;M)&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== Task 3. Demonstrate comprehension of the CCP role in the preparation of assessment report (Phase 3 – Report Assessment Results). ===&lt;br /&gt;
{|class=&amp;quot;wikitable&amp;quot; style=&amp;quot;width: 85%;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;width: 10%&amp;quot;|Lesson Topic&lt;br /&gt;
! style=&amp;quot;width: 10%&amp;quot;|Objective&lt;br /&gt;
! style=&amp;quot;width: 80%&amp;quot;|Objective Description&lt;br /&gt;
|-&lt;br /&gt;
|10D&lt;br /&gt;
|5.3.1&lt;br /&gt;
|1. The evidence presented for each practice&lt;br /&gt;
|-&lt;br /&gt;
|7B, 10C&lt;br /&gt;
|5.3.2&lt;br /&gt;
|2. How Assessment Team Members score practices, validate, and deliver assessment preliminary results&lt;br /&gt;
|-&lt;br /&gt;
|10C&lt;br /&gt;
|5.3.3&lt;br /&gt;
|3. How the Assessment Lead drafts and scores the final findings&lt;br /&gt;
|-&lt;br /&gt;
|10D&lt;br /&gt;
|5.3.4&lt;br /&gt;
|4.# How the final findings and associated information are incorporated into the Assessment Report&lt;br /&gt;
|-&lt;br /&gt;
|10D&lt;br /&gt;
|5.3.5&lt;br /&gt;
|5. How the Lead Assessor submits the assessment report, including the review process, submitting to the C3PAO and the OSC&lt;br /&gt;
|-&lt;br /&gt;
|10D&lt;br /&gt;
|5.3.6&lt;br /&gt;
|6. How to package and archive the assessment results for a record to support any future questions that may be asked&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== Task 4. Demonstrate comprehension of the CCP role in the process of evaluating outstanding assessment issues on Plan of Action and Milestones (POA&amp;amp;M) (Phase 4 – Evaluation of Outstanding Assessment POA&amp;amp;M Items). ===&lt;br /&gt;
{|class=&amp;quot;wikitable&amp;quot; style=&amp;quot;width: 85%;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;width: 10%&amp;quot;|Lesson Topic&lt;br /&gt;
! style=&amp;quot;width: 10%&amp;quot;|Objective&lt;br /&gt;
! style=&amp;quot;width: 80%&amp;quot;|Objective Description&lt;br /&gt;
|-&lt;br /&gt;
|10C&lt;br /&gt;
|5.4.1&lt;br /&gt;
|1. The evaluation of assessment POA&amp;amp;M items&lt;br /&gt;
|-&lt;br /&gt;
|10C&lt;br /&gt;
|5.4.1.A&lt;br /&gt;
|&lt;br /&gt;
:A. DoD Assessment Methodology, POA&amp;amp;M scoring criteria&lt;br /&gt;
|-&lt;br /&gt;
|10C&lt;br /&gt;
|5.4.1.A.1&lt;br /&gt;
|&lt;br /&gt;
::(1) Minimum assessment score&lt;br /&gt;
|-&lt;br /&gt;
|10C&lt;br /&gt;
|5.4.1.A.2&lt;br /&gt;
|&lt;br /&gt;
::(2) Qualifying POA&amp;amp;M items&lt;br /&gt;
|-&lt;br /&gt;
|10C&lt;br /&gt;
|5.4.1.B&lt;br /&gt;
|&lt;br /&gt;
:B. CMMC AG CA.L2-3.12.2, Plan of Action objectives and requirements&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== Task 5. Given a scenario, determine the appropriate phases/steps to assist in the preparation/conducting/ reporting on a CMMC Level 2 Assessment. ===&lt;br /&gt;
{|class=&amp;quot;wikitable&amp;quot; style=&amp;quot;width: 85%;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;width: 10%&amp;quot;|Lesson Topic&lt;br /&gt;
! style=&amp;quot;width: 10%&amp;quot;|Objective&lt;br /&gt;
! style=&amp;quot;width: 80%&amp;quot;|Objective Description&lt;br /&gt;
|-&lt;br /&gt;
|10B&lt;br /&gt;
|5.5.1&lt;br /&gt;
|1. Plan and Prepare Assessments:&lt;br /&gt;
|-&lt;br /&gt;
|10A&lt;br /&gt;
|5.5.1.A&lt;br /&gt;
|&lt;br /&gt;
:A. CMMC CCP must be able to assist in analyzing requirements.&lt;br /&gt;
|-&lt;br /&gt;
|10A&lt;br /&gt;
|5.5.1.B&lt;br /&gt;
|&lt;br /&gt;
:B. CMMC CCP must be able to assist in developing assessment plan.&lt;br /&gt;
|-&lt;br /&gt;
|10A&lt;br /&gt;
|5.5.1.C&lt;br /&gt;
|&lt;br /&gt;
:C. CMMC CCP must be able to assist in verifying readiness to conduct assessment.&lt;br /&gt;
|-&lt;br /&gt;
|10C&lt;br /&gt;
|5.5.2&lt;br /&gt;
|2. Conduct Assessment:&lt;br /&gt;
|-&lt;br /&gt;
|10A&lt;br /&gt;
|5.5.2.A&lt;br /&gt;
|&lt;br /&gt;
:A. CMMC CCP must be able to assist in collecting and examining Evidence.&lt;br /&gt;
|-&lt;br /&gt;
|10A&lt;br /&gt;
|5.5.2.B&lt;br /&gt;
|&lt;br /&gt;
:B. CMMC CCP must be able to assist in scoring practices and validating preliminary results.&lt;br /&gt;
|-&lt;br /&gt;
|10A&lt;br /&gt;
|5.5.2.C&lt;br /&gt;
|&lt;br /&gt;
:C. CMMC CCP must be able to assist in generating final assessment results.&lt;br /&gt;
|-&lt;br /&gt;
|10D&lt;br /&gt;
|5.5.3&lt;br /&gt;
|3. Report Recommended Assessment Results:&lt;br /&gt;
|-&lt;br /&gt;
|10A&lt;br /&gt;
|5.5.3.A&lt;br /&gt;
|&lt;br /&gt;
:A. CMMC CCP must be able to assist in delivering recommended assessment results.&lt;br /&gt;
|-&lt;br /&gt;
|10E&lt;br /&gt;
|5.5.4&lt;br /&gt;
|4. Remediate Outstanding Assessment Issues:&lt;br /&gt;
|-&lt;br /&gt;
|10A&lt;br /&gt;
|5.5.4.A&lt;br /&gt;
|&lt;br /&gt;
:A. Awareness of the CCP’s Role in the POA&amp;amp;M Process&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Domain 6: Scoping ==&lt;br /&gt;
=== Task 1. Understand CMMC High-Level Scoping as described in the CMMC Assessment Process. ===&lt;br /&gt;
{|class=&amp;quot;wikitable&amp;quot; style=&amp;quot;width: 85%;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;width: 10%&amp;quot;|Lesson Topic&lt;br /&gt;
! style=&amp;quot;width: 10%&amp;quot;|Objective&lt;br /&gt;
! style=&amp;quot;width: 80%&amp;quot;|Objective Description&lt;br /&gt;
|-&lt;br /&gt;
|5A&lt;br /&gt;
|6.1.1&lt;br /&gt;
|1. Defining organizational scoping&lt;br /&gt;
|-&lt;br /&gt;
|5A&lt;br /&gt;
|6.1.1.A&lt;br /&gt;
|&lt;br /&gt;
:A. Organization&lt;br /&gt;
|-&lt;br /&gt;
|5A&lt;br /&gt;
|6.1.1.B&lt;br /&gt;
|&lt;br /&gt;
:B. Host Unit&lt;br /&gt;
|-&lt;br /&gt;
|5A&lt;br /&gt;
|6.1.1.C&lt;br /&gt;
|&lt;br /&gt;
:C. Supporting Units&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== Task 2. Given a Scenario, analyze the organization environment to generate an appropriate scope for FCI Assets. ===&lt;br /&gt;
{|class=&amp;quot;wikitable&amp;quot; style=&amp;quot;width: 85%;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;width: 10%&amp;quot;|Lesson Topic&lt;br /&gt;
! style=&amp;quot;width: 10%&amp;quot;|Objective&lt;br /&gt;
! style=&amp;quot;width: 80%&amp;quot;|Objective Description&lt;br /&gt;
|-&lt;br /&gt;
|5A&lt;br /&gt;
|6.2.1&lt;br /&gt;
|1. Defining FCI data in the form of Assets that:&lt;br /&gt;
|-&lt;br /&gt;
|5A&lt;br /&gt;
|6.2.1.A&lt;br /&gt;
|&lt;br /&gt;
:A. Process&lt;br /&gt;
|-&lt;br /&gt;
|5A&lt;br /&gt;
|6.2.1.B&lt;br /&gt;
|&lt;br /&gt;
:B. Store&lt;br /&gt;
|-&lt;br /&gt;
|5A&lt;br /&gt;
|6.2.1.C&lt;br /&gt;
|&lt;br /&gt;
:C. Transmit&lt;br /&gt;
|-&lt;br /&gt;
|5A&lt;br /&gt;
|6.2.2&lt;br /&gt;
|2. Out-of-Scope Assets&lt;br /&gt;
|-&lt;br /&gt;
|5A&lt;br /&gt;
|6.2.3&lt;br /&gt;
|3. Specialized Assets&lt;br /&gt;
|-&lt;br /&gt;
|5A&lt;br /&gt;
|6.2.3.A&lt;br /&gt;
|&lt;br /&gt;
:A. Government Property&lt;br /&gt;
|-&lt;br /&gt;
|5A&lt;br /&gt;
|6.2.3.B&lt;br /&gt;
|&lt;br /&gt;
:B. Internet of Things (IoT)/ Industrial Internet of Things (IIoT)&lt;br /&gt;
|-&lt;br /&gt;
|5A&lt;br /&gt;
|6.2.3.C&lt;br /&gt;
|&lt;br /&gt;
:C. Operational Technology (OT)&lt;br /&gt;
|-&lt;br /&gt;
|5A&lt;br /&gt;
|6.2.3.D&lt;br /&gt;
|&lt;br /&gt;
:D. Restricted Information Systems&lt;br /&gt;
|-&lt;br /&gt;
|5A&lt;br /&gt;
|6.2.3.E&lt;br /&gt;
|&lt;br /&gt;
:E. Test Equipment&lt;br /&gt;
|-&lt;br /&gt;
|5A&lt;br /&gt;
|6.2.4&lt;br /&gt;
|4. Scoping Activities&lt;br /&gt;
|-&lt;br /&gt;
|5A&lt;br /&gt;
|6.2.4.A&lt;br /&gt;
|&lt;br /&gt;
:A. People&lt;br /&gt;
|-&lt;br /&gt;
|5A&lt;br /&gt;
|6.2.4.B&lt;br /&gt;
|&lt;br /&gt;
:B. Technology&lt;br /&gt;
|-&lt;br /&gt;
|5A&lt;br /&gt;
|6.2.4.C&lt;br /&gt;
|&lt;br /&gt;
:C. Facilities&lt;br /&gt;
|-&lt;br /&gt;
|5A&lt;br /&gt;
|6.2.4.D&lt;br /&gt;
|&lt;br /&gt;
:D. External Service Providers (ESP)&lt;br /&gt;
|}&lt;/div&gt;</summary>
		<author><name>David</name></author>
	</entry>
	<entry>
		<id>https://cmmcwiki.org/index.php?title=External_References&amp;diff=1598</id>
		<title>External References</title>
		<link rel="alternate" type="text/html" href="https://cmmcwiki.org/index.php?title=External_References&amp;diff=1598"/>
		<updated>2026-03-02T01:32:02Z</updated>

		<summary type="html">&lt;p&gt;David: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Additional References: The [https://dodcio.defense.gov/CMMC/Resources/ CMMC Resources] page contains a variety of external links to CMMC resources throughout the DoD.&lt;br /&gt;
&lt;br /&gt;
For inquiries and reporting errors on this wiki, please [mailto:support@cmmcwiki.org contact us]. Thank you.&lt;br /&gt;
&lt;br /&gt;
== B ==&lt;br /&gt;
{|class=&amp;quot;wikitable&amp;quot; style=&amp;quot;width: 80%;&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 70%&amp;quot;| Standards and Organizations&lt;br /&gt;
! style=&amp;quot;width: 30%&amp;quot;| Links&lt;br /&gt;
|-&lt;br /&gt;
|&#039;&#039;&#039;Blue Cyber Education Series for Small Business&lt;br /&gt;
|&lt;br /&gt;
* [https://www.safcn.af.mil/CISO/Small-Business-Cybersecurity-Information/ Home Page]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== C ==&lt;br /&gt;
{|class=&amp;quot;wikitable&amp;quot; style=&amp;quot;width: 80%;&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 70%&amp;quot;| Standards and Organizations&lt;br /&gt;
! style=&amp;quot;width: 30%&amp;quot;| Links&lt;br /&gt;
|-&lt;br /&gt;
|&#039;&#039;&#039;CISA Cyber Security Evaluation Tool (CSET®)&#039;&#039;&#039;&lt;br /&gt;
|&lt;br /&gt;
* [https://www.cisa.gov/stopransomware/cyber-security-evaluation-tool-csetr Home Page]&lt;br /&gt;
* [https://github.com/cisagov/cset/releases CSET Download]&lt;br /&gt;
|-&lt;br /&gt;
|&#039;&#039;&#039;CMMC Program Final Rule&#039;&#039;&#039;&lt;br /&gt;
|&lt;br /&gt;
* [https://www.federalregister.gov/documents/2024/10/15/2024-22905/cybersecurity-maturity-model-certification-cmmc-program 32 CFR Part 170 rule]&lt;br /&gt;
|-&lt;br /&gt;
|&#039;&#039;&#039;Cyber AB, The&#039;&#039;&#039;&lt;br /&gt;
|&lt;br /&gt;
* [https://cyberab.org/ Home Page]&lt;br /&gt;
|-&lt;br /&gt;
|&#039;&#039;&#039;Cybersecurity and Privacy Reference Tool (CPRT)&#039;&#039;&#039;&lt;br /&gt;
|&lt;br /&gt;
* [https://csrc.nist.gov/projects/cprt/catalog#/cprt/home/ CPRT Catalog]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== D ==&lt;br /&gt;
{|class=&amp;quot;wikitable&amp;quot; style=&amp;quot;width: 80%;&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 70%&amp;quot;| Standards and Organizations&lt;br /&gt;
! style=&amp;quot;width: 30%&amp;quot;| Links&lt;br /&gt;
|-&lt;br /&gt;
|&#039;&#039;&#039;Defense Industrial Base Cybersecurity Assessment Center (DIBCAC) Contractor Resources&lt;br /&gt;
|&lt;br /&gt;
* [https://www.dcma.mil/DIBCAC/ Home Page]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== M ==&lt;br /&gt;
{|class=&amp;quot;wikitable&amp;quot; style=&amp;quot;width: 80%;&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 70%&amp;quot;| Standards and Organizations&lt;br /&gt;
! style=&amp;quot;width: 30%&amp;quot;| Links&lt;br /&gt;
|-&lt;br /&gt;
|&#039;&#039;&#039;MITRE ATT&amp;amp;CK Knowledge Base&lt;br /&gt;
|&lt;br /&gt;
* [https://attack.mitre.org/ Home Page]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== N ==&lt;br /&gt;
{|class=&amp;quot;wikitable&amp;quot; style=&amp;quot;width: 80%;&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 70%&amp;quot;| Standards and Organizations&lt;br /&gt;
! style=&amp;quot;width: 30%&amp;quot;| Links&lt;br /&gt;
|-&lt;br /&gt;
|&#039;&#039;&#039;NIST Cybersecurity Framework&#039;&#039;&#039;&lt;br /&gt;
|&lt;br /&gt;
* [https://www.nist.gov/cyberframework Home Page]&lt;br /&gt;
* [https://www.nist.gov/cyberframework/framework Framework Documents]&lt;br /&gt;
* [https://www.nist.gov/cyberframework/online-learning Online Learning]&lt;br /&gt;
|-&lt;br /&gt;
|&#039;&#039;&#039;NIST SP 800-53 Rev. 5 Security and Privacy Controls for Information Systems and Organizations&#039;&#039;&#039;&lt;br /&gt;
|&lt;br /&gt;
* [https://csrc.nist.gov/publications/detail/sp/800-53/rev-5/final Home Page]&lt;br /&gt;
* [https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r5.pdf PDF Download]&lt;br /&gt;
|-&lt;br /&gt;
|&#039;&#039;&#039;NIST SP 800-171 Rev. 2 Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations&#039;&#039;&#039;&lt;br /&gt;
|&lt;br /&gt;
* [https://csrc.nist.gov/pubs/sp/800/171/r2/upd1/final Home Page]&lt;br /&gt;
* [https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171r2.pdf PDF Download]&lt;br /&gt;
|-&lt;br /&gt;
|&#039;&#039;&#039;NIST SP 800-171A Assessing Security Requirements for Controlled Unclassified Information&#039;&#039;&#039;&lt;br /&gt;
|&lt;br /&gt;
* [https://csrc.nist.gov/pubs/sp/800/171/a/final Home Page]&lt;br /&gt;
* [https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171a.pdf PDF Download]&lt;br /&gt;
|-&lt;br /&gt;
|&#039;&#039;&#039;NIST SP 800-171 Rev. 3 Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations&#039;&#039;&#039;&lt;br /&gt;
|&lt;br /&gt;
* [https://csrc.nist.gov/pubs/sp/800/171/r3/final Home Page]&lt;br /&gt;
* [https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171r3.pdf PDF Download]&lt;br /&gt;
* [https://nvlpubs.nist.gov/nistpubs/SpecialPublications/800-171r3/NIST.SP.800-171r3.html HTML Version]&lt;br /&gt;
|-&lt;br /&gt;
|&#039;&#039;&#039;NIST SP 800-171A Rev.3 Assessing Security Requirements for Controlled Unclassified Information&#039;&#039;&#039;&lt;br /&gt;
|&lt;br /&gt;
* [https://csrc.nist.gov/pubs/sp/800/171/a/r3/final Home Page]&lt;br /&gt;
* [https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171Ar3.pdf PDF Download]&lt;br /&gt;
* [https://nvlpubs.nist.gov/nistpubs/SpecialPublications/800-171Ar3/NIST.SP.800-171Ar3.html HTML Version]&lt;br /&gt;
|-&lt;br /&gt;
|&#039;&#039;&#039;NIST SP 800-172 Enhanced Security Requirements for Protecting Controlled Unclassified Information: A Supplement to NIST Special Publication 800-171&#039;&#039;&#039;&lt;br /&gt;
|&lt;br /&gt;
* [https://csrc.nist.gov/publications/detail/sp/800-172/final Home Page]&lt;br /&gt;
* [https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-172.pdf PDF Download]&lt;br /&gt;
|-&lt;br /&gt;
|&#039;&#039;&#039;NIST SP 800-172A Assessing Enhanced Security Requirements for Controlled Unclassified Information&#039;&#039;&#039;&lt;br /&gt;
|&lt;br /&gt;
* [https://csrc.nist.gov/publications/detail/sp/800-172a/final Home Page]&lt;br /&gt;
* [https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-172A.pdf PDF Download]&lt;br /&gt;
|-&lt;br /&gt;
|&#039;&#039;&#039;NSA Cybersecurity Products and Services&#039;&#039;&#039;&lt;br /&gt;
|&lt;br /&gt;
* [https://www.nsa.gov/Cybersecurity/Cybersecurity-Products-Services/ Home Page]&lt;br /&gt;
* [https://github.com/nsacyber Cybersecurity Directorate GitHub]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== O ==&lt;br /&gt;
{|class=&amp;quot;wikitable&amp;quot; style=&amp;quot;width: 80%;&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 70%&amp;quot;| Standards and Organizations&lt;br /&gt;
! style=&amp;quot;width: 30%&amp;quot;| Links&lt;br /&gt;
|-&lt;br /&gt;
|&#039;&#039;&#039;OSCAL: the Open Security Controls Assessment Language&lt;br /&gt;
|&lt;br /&gt;
* [https://pages.nist.gov/OSCAL/ Home Page]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== P ==&lt;br /&gt;
{|class=&amp;quot;wikitable&amp;quot; style=&amp;quot;width: 80%;&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 70%&amp;quot;| Standards and Organizations&lt;br /&gt;
! style=&amp;quot;width: 30%&amp;quot;| Links&lt;br /&gt;
|-&lt;br /&gt;
|&#039;&#039;&#039;Project Spectrum&#039;&#039;&#039;&lt;br /&gt;
|&lt;br /&gt;
* [https://www.projectspectrum.io/ Home Page]&lt;br /&gt;
|}&lt;/div&gt;</summary>
		<author><name>David</name></author>
	</entry>
	<entry>
		<id>https://cmmcwiki.org/index.php?title=Commonly_Accepted_and_Practiced_CMMC_Operation_Matrix&amp;diff=1597</id>
		<title>Commonly Accepted and Practiced CMMC Operation Matrix</title>
		<link rel="alternate" type="text/html" href="https://cmmcwiki.org/index.php?title=Commonly_Accepted_and_Practiced_CMMC_Operation_Matrix&amp;diff=1597"/>
		<updated>2026-03-02T01:31:47Z</updated>

		<summary type="html">&lt;p&gt;David: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;The Commonly Accepted and Practiced CMMC Operation Matrix (CAPCOM) serves as an experimental repository for all CMMC Level 2 security requirements, assessment objectives, and AI-enhanced methodologies for evidence collection and evaluation.&lt;br /&gt;
&lt;br /&gt;
Powered by advanced Large Language Model (LLM) technology, CAPCOM provides guidance for evaluating information system compliance with the CMMC program. Security professionals and IT leaders can leverage this AI-enhanced model to systematically identify gaps between their organizational infrastructure and CMMC requirements, enabling strategic remediation planning and implementation.&lt;br /&gt;
&lt;br /&gt;
DISCLAIMER: The LLM-based AI is pretty cool, but it can also create erroneous responses. &#039;&#039;&#039;Always double-check a response before using it.&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
For inquiries and reporting errors on this wiki, please [mailto:support@cmmcwiki.org contact us]. Thank you.&lt;br /&gt;
&lt;br /&gt;
== Access Control (AC) ==&lt;br /&gt;
=== AC.L2-3.1.1 – Authorized Access Control [CUI Data] ===&lt;br /&gt;
{|class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 70%&amp;quot;| &#039;&#039;&#039;Practice and Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Prompt&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Response&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [[ Practice_AC.L2-3.1.1_Details | &#039;&#039;&#039;AC.L2-3.1.1&#039;&#039;&#039; ]] Limit information system access to authorized users, processes acting on behalf of authorized users, or devices (including other information systems). || [[ LLMPrompt_AC.L2-3.1.1 | Sample Prompt Template ]] || N/A&lt;br /&gt;
|-&lt;br /&gt;
| [a] authorized users are identified. || [[ LLMPrompt_AC.L2-3.1.1.a | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.1.1.a | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [b] processes acting on behalf of authorized users are identified. || [[ LLMPrompt_AC.L2-3.1.1.b | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.1.1.b | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [c] devices (and other systems) authorized to connect to the system are identified. || [[ LLMPrompt_AC.L2-3.1.1.c | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.1.1.c | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [d] system access is limited to authorized users. || [[ LLMPrompt_AC.L2-3.1.1.d | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.1.1.d | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [e] system access is limited to processes acting on behalf of authorized users. || [[ LLMPrompt_AC.L2-3.1.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.1.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [f] system access is limited to authorized devices (including other systems). || [[ LLMPrompt_AC.L2-3.1.1.f | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.1.1.f | Sample Response ]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.2 – Transaction &amp;amp; Function Control [CUI Data] ===&lt;br /&gt;
{|class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 70%&amp;quot;| &#039;&#039;&#039;Practice and Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Prompt&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Response&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [[ Practice_AC.L2-3.1.2_Details | &#039;&#039;&#039;AC.L2-3.1.2&#039;&#039;&#039; ]] Limit information system access to the types of transactions and functions that authorized users are permitted to execute. || [[ LLMPrompt_AC.L2-3.1.2 | Sample Prompt Template ]] || N/A&lt;br /&gt;
|-&lt;br /&gt;
| [a] the types of transactions and functions that authorized users are permitted to execute are defined. || [[ LLMPrompt_AC.L2-3.1.2.a | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.1.2.a | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [b] system access is limited to the defined types of transactions and functions for authorized users. || [[ LLMPrompt_AC.L2-3.1.2.b | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.1.2.b | Sample Response ]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.3 – Control CUI Flow ===&lt;br /&gt;
{|class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 70%&amp;quot;| &#039;&#039;&#039;Practice and Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Prompt&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Response&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [[ Practice_AC.L2-3.1.3_Details | &#039;&#039;&#039;AC.L2-3.1.3&#039;&#039;&#039; ]] Control the flow of CUI in accordance with approved authorizations. || [[ LLMPrompt_AC.L2-3.1.3 | Sample Prompt Template ]] || N/A&lt;br /&gt;
|-&lt;br /&gt;
| [a] information flow control policies are defined. || [[ LLMPrompt_AC.L2-3.1.3.a | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.1.3.a | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [b] methods and enforcement mechanisms for controlling the flow of CUI are defined. || [[ LLMPrompt_AC.L2-3.1.3.b | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.1.3.b | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [c] designated sources and destinations (e.g., networks, individuals, and devices) for CUI within the system and between interconnected systems are identified. || [[ LLMPrompt_AC.L2-3.1.3.c | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.1.3.c | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [d] authorizations for controlling the flow of CUI are defined. || [[ LLMPrompt_AC.L2-3.1.3.d | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.1.3.d | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [e] approved authorizations for controlling the flow of CUI are enforced. || [[ LLMPrompt_AC.L2-3.1.3.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.1.3.e | Sample Response ]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.4 – Separation of Duties ===&lt;br /&gt;
{|class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 70%&amp;quot;| &#039;&#039;&#039;Practice and Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Prompt&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Response&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [[ Practice_AC.L2-3.1.4_Details | &#039;&#039;&#039;AC.L2-3.1.4&#039;&#039;&#039; ]] Separate the duties of individuals to reduce the risk of malevolent activity without collusion. || [[ LLMPrompt_AC.L2-3.1.4 | Sample Prompt Template ]] || N/A&lt;br /&gt;
|-&lt;br /&gt;
| [a] the duties of individuals requiring separation are defined. || [[ LLMPrompt_AC.L2-3.1.4.a | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.1.4.a | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [b] responsibilities for duties that require separation are assigned to separate individuals. || [[ LLMPrompt_AC.L2-3.1.4.b | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.1.4.b | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [c] access privileges that enable individuals to exercise the duties that require separation are granted to separate individuals. || [[ LLMPrompt_AC.L2-3.1.4.c | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.1.4.c | Sample Response ]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.5 – Least Privilege ===&lt;br /&gt;
{|class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 70%&amp;quot;| &#039;&#039;&#039;Practice and Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Prompt&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Response&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [[ Practice_AC.L2-3.1.5_Details | &#039;&#039;&#039;AC.L2-3.1.5&#039;&#039;&#039; ]] Employ the principle of least privilege, including for specific security functions and privileged accounts. || [[ LLMPrompt_AC.L2-3.1.5 | Sample Prompt Template ]] || N/A&lt;br /&gt;
|-&lt;br /&gt;
| [a] privileged accounts are identified. || [[ LLMPrompt_AC.L2-3.1.5.a | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.1.5.a | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [b] access to privileged accounts is authorized in accordance with the principle of least privilege. || [[ LLMPrompt_AC.L2-3.1.5.b | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.1.5.b | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [c] security functions are identified. || [[ LLMPrompt_AC.L2-3.1.5.c | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.1.5.c | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [d] access to security functions is authorized in accordance with the principle of least privilege. || [[ LLMPrompt_AC.L2-3.1.5.d | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.1.5.d | Sample Response ]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.6 – Non-Privileged Account Use ===&lt;br /&gt;
{|class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 70%&amp;quot;| &#039;&#039;&#039;Practice and Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Prompt&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Response&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [[ Practice_AC.L2-3.1.6_Details | &#039;&#039;&#039;AC.L2-3.1.6&#039;&#039;&#039; ]] Use non-privileged accounts or roles when accessing nonsecurity functions. || [[ LLMPrompt_AC.L2-3.1.6 | Sample Prompt Template ]] || N/A&lt;br /&gt;
|-&lt;br /&gt;
| [a] nonsecurity functions are identified. || [[ LLMPrompt_AC.L2-3.1.6.a | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.1.6.a | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [b] users are required to use non-privileged accounts or roles when accessing nonsecurity functions. || [[ LLMPrompt_AC.L2-3.1.6.b | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.1.6.b | Sample Response ]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.7 – Privileged Functions ===&lt;br /&gt;
{|class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 70%&amp;quot;| &#039;&#039;&#039;Practice and Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Prompt&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Response&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [[ Practice_AC.L2-3.1.7_Details | &#039;&#039;&#039;AC.L2-3.1.7&#039;&#039;&#039; ]] Prevent non-privileged users from executing privileged functions and capture the execution of such functions in audit logs. || [[ LLMPrompt_AC.L2-3.1.7 | Sample Prompt Template ]] || N/A&lt;br /&gt;
|-&lt;br /&gt;
| [a] privileged functions are defined. || [[ LLMPrompt_AC.L2-3.1.7.a | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.1.7.a | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [b] non-privileged users are defined. || [[ LLMPrompt_AC.L2-3.1.7.b | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.1.7.b | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [c] non-privileged users are prevented from executing privileged functions. || [[ LLMPrompt_AC.L2-3.1.7.c | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.1.7.c | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [d] the execution of privileged functions is captured in audit logs. || [[ LLMPrompt_AC.L2-3.1.7.d | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.1.7.d | Sample Response ]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.8 – Unsuccessful Logon Attempts ===&lt;br /&gt;
{|class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 70%&amp;quot;| &#039;&#039;&#039;Practice and Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Prompt&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Response&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [[ Practice_AC.L2-3.x.1_Details | &#039;&#039;&#039;AC.L2-3.x.1&#039;&#039;&#039; ]] Limit unsuccessful logon attempts. || [[ LLMPrompt_AC.L2-3.x.1 | Sample Prompt Template ]] || N/A&lt;br /&gt;
|-&lt;br /&gt;
| [a] the means of limiting unsuccessful logon attempts is defined. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [b] the defined means of limiting unsuccessful logon attempts is implemented. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
|[[Practice_AC.L2-3.1.8_Details|More Practice Details...]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.9 – Privacy &amp;amp; Security Notices ===&lt;br /&gt;
{|class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 70%&amp;quot;| &#039;&#039;&#039;Practice and Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Prompt&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Response&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [[ Practice_AC.L2-3.x.1_Details | &#039;&#039;&#039;AC.L2-3.x.1&#039;&#039;&#039; ]] Provide privacy and security notices consistent with applicable CUI rules. || [[ LLMPrompt_AC.L2-3.x.1 | Sample Prompt Template ]] || N/A&lt;br /&gt;
|-&lt;br /&gt;
| [a] privacy and security notices required by CUI-specified rules are identified, consistent, and associated with the specific CUI category. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [b] privacy and security notices are displayed. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
|[[Practice_AC.L2-3.1.9_Details|More Practice Details...]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.10 – Session Lock ===&lt;br /&gt;
{|class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 70%&amp;quot;| &#039;&#039;&#039;Practice and Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Prompt&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Response&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [[ Practice_AC.L2-3.x.1_Details | &#039;&#039;&#039;AC.L2-3.x.1&#039;&#039;&#039; ]] Use session lock with pattern-hiding displays to prevent access and viewing of data after a period of inactivity. || [[ LLMPrompt_AC.L2-3.x.1 | Sample Prompt Template ]] || N/A&lt;br /&gt;
|-&lt;br /&gt;
| [a] the period of inactivity after which the system initiates a session lock is defined. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [b] access to the system and viewing of data is prevented by initiating a session lock after the defined period of inactivity. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [c] previously visible information is concealed via a pattern-hiding display after the defined period of inactivity. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
|[[Practice_AC.L2-3.1.10_Details|More Practice Details...]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.11 – Session Termination ===&lt;br /&gt;
{|class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 70%&amp;quot;| &#039;&#039;&#039;Practice and Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Prompt&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Response&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [[ Practice_AC.L2-3.x.1_Details | &#039;&#039;&#039;AC.L2-3.x.1&#039;&#039;&#039; ]] Terminate (automatically) a user session after a defined condition. || [[ LLMPrompt_AC.L2-3.x.1 | Sample Prompt Template ]] || N/A&lt;br /&gt;
|-&lt;br /&gt;
| [a] conditions requiring a user session to terminate are defined. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [b] a user session is automatically terminated after any of the defined conditions &lt;br /&gt;
|-&lt;br /&gt;
|[[Practice_AC.L2-3.1.11_Details|More Practice Details...]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.12 – Control Remote Access ===&lt;br /&gt;
{|class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 70%&amp;quot;| &#039;&#039;&#039;Practice and Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Prompt&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Response&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [[ Practice_AC.L2-3.x.1_Details | &#039;&#039;&#039;AC.L2-3.x.1&#039;&#039;&#039; ]] Monitor and control remote access sessions. || [[ LLMPrompt_AC.L2-3.x.1 | Sample Prompt Template ]] || N/A&lt;br /&gt;
|-&lt;br /&gt;
| [a] remote access sessions are permitted. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [b] the types of permitted remote access are identified. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [c] remote access sessions are controlled. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [d] remote access sessions are monitored. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
|[[Practice_AC.L2-3.1.12_Details|More Practice Details...]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.13 – Remote Access Confidentiality ===&lt;br /&gt;
{|class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 70%&amp;quot;| &#039;&#039;&#039;Practice and Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Prompt&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Response&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [[ Practice_AC.L2-3.x.1_Details | &#039;&#039;&#039;AC.L2-3.x.1&#039;&#039;&#039; ]] Employ cryptographic mechanisms to protect the confidentiality of remote access sessions. || [[ LLMPrompt_AC.L2-3.x.1 | Sample Prompt Template ]] || N/A&lt;br /&gt;
|-&lt;br /&gt;
| [a] cryptographic mechanisms to protect the confidentiality of remote access sessions are identified. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [b] cryptographic mechanisms to protect the confidentiality of remote access sessions are implemented. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
|[[Practice_AC.L2-3.1.13_Details|More Practice Details...]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.14 – Remote Access Routing ===&lt;br /&gt;
{|class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 70%&amp;quot;| &#039;&#039;&#039;Practice and Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Prompt&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Response&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [[ Practice_AC.L2-3.x.1_Details | &#039;&#039;&#039;AC.L2-3.x.1&#039;&#039;&#039; ]] Route remote access via managed access control points. || [[ LLMPrompt_AC.L2-3.x.1 | Sample Prompt Template ]] || N/A&lt;br /&gt;
|-&lt;br /&gt;
| [a] managed access control points are identified and implemented. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [b] remote access is routed through managed network access control points. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
|[[Practice_AC.L2-3.1.14_Details|More Practice Details...]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.15 – Privileged Remote Access ===&lt;br /&gt;
{|class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 70%&amp;quot;| &#039;&#039;&#039;Practice and Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Prompt&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Response&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [[ Practice_AC.L2-3.x.1_Details | &#039;&#039;&#039;AC.L2-3.x.1&#039;&#039;&#039; ]] Authorize remote execution of privileged commands and remote access to security-relevant information. || [[ LLMPrompt_AC.L2-3.x.1 | Sample Prompt Template ]] || N/A&lt;br /&gt;
|-&lt;br /&gt;
| [a] privileged commands authorized for remote execution are identified. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [b] security-relevant information authorized to be accessed remotely is identified. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [c] the execution of the identified privileged commands via remote access is authorized. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [d] access to the identified security-relevant information via remote access is authorized. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
|[[Practice_AC.L2-3.1.15_Details|More Practice Details...]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.16 – Wireless Access Authorization ===&lt;br /&gt;
{|class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 70%&amp;quot;| &#039;&#039;&#039;Practice and Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Prompt&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Response&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [[ Practice_AC.L2-3.x.1_Details | &#039;&#039;&#039;AC.L2-3.x.1&#039;&#039;&#039; ]] Authorize wireless access prior to allowing such connections. || [[ LLMPrompt_AC.L2-3.x.1 | Sample Prompt Template ]] || N/A&lt;br /&gt;
|-&lt;br /&gt;
| [a] wireless access points are identified. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [b] wireless access is authorized prior to allowing such connections. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
|[[Practice_AC.L2-3.1.16_Details|More Practice Details...]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.17 – Wireless Access Protection ===&lt;br /&gt;
{|class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 70%&amp;quot;| &#039;&#039;&#039;Practice and Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Prompt&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Response&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [[ Practice_AC.L2-3.x.1_Details | &#039;&#039;&#039;AC.L2-3.x.1&#039;&#039;&#039; ]] Protect wireless access using authentication and encryption. || [[ LLMPrompt_AC.L2-3.x.1 | Sample Prompt Template ]] || N/A&lt;br /&gt;
|-&lt;br /&gt;
| [a] wireless access to the system is protected using authentication. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [b] wireless access to the system is protected using encryption. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
|[[Practice_AC.L2-3.1.17_Details|More Practice Details...]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.18 – Mobile Device Connection ===&lt;br /&gt;
{|class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 70%&amp;quot;| &#039;&#039;&#039;Practice and Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Prompt&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Response&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [[ Practice_AC.L2-3.x.1_Details | &#039;&#039;&#039;AC.L2-3.x.1&#039;&#039;&#039; ]] Control connection of mobile devices. || [[ LLMPrompt_AC.L2-3.x.1 | Sample Prompt Template ]] || N/A&lt;br /&gt;
|-&lt;br /&gt;
| [a] mobile devices that process, store, or transmit CUI are identified. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [b] mobile device connections are authorized. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [c] mobile device connections are monitored and logged. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
|[[Practice_AC.L2-3.1.18_Details|More Practice Details...]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.19 – Encrypt CUI on Mobile ===&lt;br /&gt;
{|class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 70%&amp;quot;| &#039;&#039;&#039;Practice and Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Prompt&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Response&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [[ Practice_AC.L2-3.x.1_Details | &#039;&#039;&#039;AC.L2-3.x.1&#039;&#039;&#039; ]] Encrypt CUI on mobile devices and mobile computing platforms. || [[ LLMPrompt_AC.L2-3.x.1 | Sample Prompt Template ]] || N/A&lt;br /&gt;
|-&lt;br /&gt;
| [a] mobile devices and mobile computing platforms that process, store, or transmit CUI are identified. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [b] encryption is employed to protect CUI on identified mobile devices and mobile computing platforms. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
|[[Practice_AC.L2-3.1.19_Details|More Practice Details...]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.20 – External Connections [CUI Data] ===&lt;br /&gt;
{|class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 70%&amp;quot;| &#039;&#039;&#039;Practice and Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Prompt&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Response&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [[ Practice_AC.L2-3.x.1_Details | &#039;&#039;&#039;AC.L2-3.x.1&#039;&#039;&#039; ]] Verify and control/limit connections to and use of external information systems. || [[ LLMPrompt_AC.L2-3.x.1 | Sample Prompt Template ]] || N/A&lt;br /&gt;
|-&lt;br /&gt;
| [a] connections to external systems are identified. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [b] the use of external systems is identified. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [c] connections to external systems are verified. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [d] the use of external systems is verified. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [e] connections to external systems are controlled/limited. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [f] the use of external systems is controlled/limited. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
|[[Practice_AC.L2-3.1.20_Details|More Practice Details...]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.21 – Portable Storage Use ===&lt;br /&gt;
{|class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 70%&amp;quot;| &#039;&#039;&#039;Practice and Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Prompt&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Response&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [[ Practice_AC.L2-3.x.1_Details | &#039;&#039;&#039;AC.L2-3.x.1&#039;&#039;&#039; ]] Limit use of portable storage devices on external systems. || [[ LLMPrompt_AC.L2-3.x.1 | Sample Prompt Template ]] || N/A&lt;br /&gt;
|-&lt;br /&gt;
| [a] the use of portable storage devices containing CUI on external systems is identified and documented. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [b] limits on the use of portable storage devices containing CUI on external systems are defined. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [c] the use of portable storage devices containing CUI on external systems is limited as defined. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
|[[Practice_AC.L2-3.1.21_Details|More Practice Details...]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AC.L2-3.1.22 – Control Public Information [CUI Data] ===&lt;br /&gt;
{|class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 70%&amp;quot;| &#039;&#039;&#039;Practice and Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Prompt&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Response&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [[ Practice_AC.L2-3.x.1_Details | &#039;&#039;&#039;AC.L2-3.x.1&#039;&#039;&#039; ]] Control information posted or processed on publicly accessible information systems. || [[ LLMPrompt_AC.L2-3.x.1 | Sample Prompt Template ]] || N/A&lt;br /&gt;
|-&lt;br /&gt;
| [a] individuals authorized to post or process information on publicly accessible systems are identified. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [b] procedures to ensure CUI is not posted or processed on publicly accessible systems are identified. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [c] a review process is in place prior to posting of any content to publicly accessible systems. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [d] content on publicly accessible systems is reviewed to ensure that it does not include CUI. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [e] mechanisms are in place to remove and address improper posting of CUI. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
|[[Practice_AC.L2-3.1.22_Details|More Practice Details...]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Awareness and Training (AT) ==&lt;br /&gt;
=== AT.L2-3.2.1 – Role-Based Risk Awareness ===&lt;br /&gt;
{|class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 70%&amp;quot;| &#039;&#039;&#039;Practice and Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Prompt&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Response&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [[ Practice_AC.L2-3.x.1_Details | &#039;&#039;&#039;AC.L2-3.x.1&#039;&#039;&#039; ]] Ensure that managers, systems administrators, and users of organizational systems are made aware of the security risks associated with their activities and of the applicable policies, standards, and procedures related to the security of those systems. || [[ LLMPrompt_AC.L2-3.x.1 | Sample Prompt Template ]] || N/A&lt;br /&gt;
|-&lt;br /&gt;
| [a] security risks associated with organizational activities involving CUI are identified. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [b] policies, standards, and procedures related to the security of the system are identified. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [c] managers, systems administrators, and users of the system are made aware of the security risks associated with their activities. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [d] managers, systems administrators, and users of the system are made aware of the applicable policies, standards, and procedures related to the security of the system. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
|[[Practice_AT.L2-3.2.1_Details|More Practice Details...]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AT.L2-3.2.2 – Role-Based Training ===&lt;br /&gt;
{|class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 70%&amp;quot;| &#039;&#039;&#039;Practice and Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Prompt&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Response&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [[ Practice_AC.L2-3.x.1_Details | &#039;&#039;&#039;AC.L2-3.x.1&#039;&#039;&#039; ]] Ensure that personnel are trained to carry out their assigned information security-related duties and responsibilities. || [[ LLMPrompt_AC.L2-3.x.1 | Sample Prompt Template ]] || N/A&lt;br /&gt;
|-&lt;br /&gt;
| [a] information security-related duties, roles, and responsibilities are defined. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [b] information security-related duties, roles, and responsibilities are assigned to designated personnel. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [c] personnel are adequately trained to carry out their assigned information security-related duties, roles, and responsibilities. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
|[[Practice_AT.L2-3.2.2_Details|More Practice Details...]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AT.L2-3.2.3 – Insider Threat Awareness ===&lt;br /&gt;
{|class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 70%&amp;quot;| &#039;&#039;&#039;Practice and Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Prompt&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Response&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [[ Practice_AC.L2-3.x.1_Details | &#039;&#039;&#039;AC.L2-3.x.1&#039;&#039;&#039; ]] Provide security awareness training on recognizing and reporting potential indicators of insider threat. || [[ LLMPrompt_AC.L2-3.x.1 | Sample Prompt Template ]] || N/A&lt;br /&gt;
|-&lt;br /&gt;
| [a] potential indicators associated with insider threats are identified. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [b] security awareness training on recognizing and reporting potential indicators of insider threat is provided to managers and employees. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
|[[Practice_AT.L2-3.2.3_Details|More Practice Details...]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Audit and Accountability (AU) ==&lt;br /&gt;
=== AU.L2-3.3.1 – System Auditing ===&lt;br /&gt;
{|class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 70%&amp;quot;| &#039;&#039;&#039;Practice and Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Prompt&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Response&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [[ Practice_AC.L2-3.x.1_Details | &#039;&#039;&#039;AC.L2-3.x.1&#039;&#039;&#039; ]] Create and retain system audit logs and records to the extent needed to enable the monitoring, analysis, investigation, and reporting of unlawful or unauthorized system activity. || [[ LLMPrompt_AC.L2-3.x.1 | Sample Prompt Template ]] || N/A&lt;br /&gt;
|-&lt;br /&gt;
| [a] audit logs needed (i.e., event types to be logged) to enable the monitoring, analysis, investigation, and reporting of unlawful or unauthorized system activity are specified. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [b] the content of audit records needed to support monitoring, analysis, investigation, and reporting of unlawful or unauthorized system activity is defined. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [c] audit records are created (generated). || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [d] audit records, once created, contain the defined content. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [e] retention requirements for audit records are defined. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [f] audit records are retained as defined. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
|[[Practice_AU.L2-3.3.1_Details|More Practice Details...]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AU.L2-3.3.2 – User Accountability ===&lt;br /&gt;
{|class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 70%&amp;quot;| &#039;&#039;&#039;Practice and Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Prompt&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Response&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [[ Practice_AC.L2-3.x.1_Details | &#039;&#039;&#039;AC.L2-3.x.1&#039;&#039;&#039; ]] Ensure that the actions of individual system users can be uniquely traced to those users so they can be held accountable for their actions. || [[ LLMPrompt_AC.L2-3.x.1 | Sample Prompt Template ]] || N/A&lt;br /&gt;
|-&lt;br /&gt;
| [a] the content of the audit records needed to support the ability to uniquely trace users to their actions is defined. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [b] audit records, once created, contain the defined content. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
|[[Practice_AU.L2-3.3.2_Details|More Practice Details...]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AU.L2-3.3.3 – Event Review ===&lt;br /&gt;
{|class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 70%&amp;quot;| &#039;&#039;&#039;Practice and Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Prompt&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Response&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [[ Practice_AC.L2-3.x.1_Details | &#039;&#039;&#039;AC.L2-3.x.1&#039;&#039;&#039; ]] Review and update logged events. || [[ LLMPrompt_AC.L2-3.x.1 | Sample Prompt Template ]] || N/A&lt;br /&gt;
|-&lt;br /&gt;
| [a] a process for determining when to review logged events is defined. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [b] event types being logged are reviewed in accordance with the defined review process. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [c] event types being logged are updated based on the review. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
|[[Practice_AU.L2-3.3.3_Details|More Practice Details...]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AU.L2-3.3.4 – Audit Failure Alerting ===&lt;br /&gt;
{|class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 70%&amp;quot;| &#039;&#039;&#039;Practice and Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Prompt&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Response&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [[ Practice_AC.L2-3.x.1_Details | &#039;&#039;&#039;AC.L2-3.x.1&#039;&#039;&#039; ]] Alert in the event of an audit logging process failure. || [[ LLMPrompt_AC.L2-3.x.1 | Sample Prompt Template ]] || N/A&lt;br /&gt;
|-&lt;br /&gt;
| [a] personnel or roles to be alerted in the event of an audit logging process failure are identified. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [b] types of audit logging process failures for which alert will be generated are defined. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [c] identified personnel or roles are alerted in the event of an audit logging process failure. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
|[[Practice_AU.L2-3.3.4_Details|More Practice Details...]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AU.L2-3.3.5 – Audit Correlation ===&lt;br /&gt;
{|class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 70%&amp;quot;| &#039;&#039;&#039;Practice and Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Prompt&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Response&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [[ Practice_AC.L2-3.x.1_Details | &#039;&#039;&#039;AC.L2-3.x.1&#039;&#039;&#039; ]] Correlate audit record review, analysis, and reporting processes for investigation and response to indications of unlawful, unauthorized, suspicious, or unusual activity. || [[ LLMPrompt_AC.L2-3.x.1 | Sample Prompt Template ]] || N/A&lt;br /&gt;
|-&lt;br /&gt;
| [a] audit record review, analysis, and reporting processes for investigation and response to indications of unlawful, unauthorized, suspicious, or unusual activity are defined. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [b] defined audit record review, analysis, and reporting processes are correlated. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
|[[Practice_AU.L2-3.3.5_Details|More Practice Details...]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AU.L2-3.3.6 – Reduction &amp;amp; Reporting ===&lt;br /&gt;
{|class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 70%&amp;quot;| &#039;&#039;&#039;Practice and Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Prompt&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Response&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [[ Practice_AC.L2-3.x.1_Details | &#039;&#039;&#039;AC.L2-3.x.1&#039;&#039;&#039; ]] Provide audit record reduction and report generation to support on-demand analysis and reporting. || [[ LLMPrompt_AC.L2-3.x.1 | Sample Prompt Template ]] || N/A&lt;br /&gt;
|-&lt;br /&gt;
| [a] an audit record reduction capability that supports on-demand analysis is provided. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [b] a report generation capability that supports on-demand reporting is provided. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
|[[Practice_AU.L2-3.3.6_Details|More Practice Details...]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AU.L2-3.3.7 – Authoritative Time Source ===&lt;br /&gt;
{|class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 70%&amp;quot;| &#039;&#039;&#039;Practice and Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Prompt&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Response&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [[ Practice_AC.L2-3.x.1_Details | &#039;&#039;&#039;AC.L2-3.x.1&#039;&#039;&#039; ]] Provide a system capability that compares and synchronizes internal system clocks with an authoritative source to generate time stamps for audit records. || [[ LLMPrompt_AC.L2-3.x.1 | Sample Prompt Template ]] || N/A&lt;br /&gt;
|-&lt;br /&gt;
| [a] internal system clocks are used to generate time stamps for audit records. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [b] an authoritative source with which to compare and synchronize internal system clocks is specified. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [c] internal system clocks used to generate time stamps for audit records are compared to and synchronized with the specified authoritative time source. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
|[[Practice_AU.L2-3.3.7_Details|More Practice Details...]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AU.L2-3.3.8 – Audit Protection ===&lt;br /&gt;
{|class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 70%&amp;quot;| &#039;&#039;&#039;Practice and Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Prompt&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Response&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [[ Practice_AC.L2-3.x.1_Details | &#039;&#039;&#039;AC.L2-3.x.1&#039;&#039;&#039; ]] Protect audit information and audit logging tools from unauthorized access, modification, and deletion. || [[ LLMPrompt_AC.L2-3.x.1 | Sample Prompt Template ]] || N/A&lt;br /&gt;
|-&lt;br /&gt;
| [a] audit information is protected from unauthorized access. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [b] audit information is protected from unauthorized modification. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [c] audit information is protected from unauthorized deletion. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [d] audit logging tools are protected from unauthorized access. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [e] audit logging tools are protected from unauthorized modification. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [f] audit logging tools are protected from unauthorized deletion. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
|[[Practice_AU.L2-3.3.8_Details|More Practice Details...]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== AU.L2-3.3.9 – Audit Management ===&lt;br /&gt;
{|class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 70%&amp;quot;| &#039;&#039;&#039;Practice and Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Prompt&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Response&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [[ Practice_AC.L2-3.x.1_Details | &#039;&#039;&#039;AC.L2-3.x.1&#039;&#039;&#039; ]] Limit management of audit logging functionality to a subset of privileged users. || [[ LLMPrompt_AC.L2-3.x.1 | Sample Prompt Template ]] || N/A&lt;br /&gt;
|-&lt;br /&gt;
| [a] a subset of privileged users granted access to manage audit logging functionality is defined. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [b] management of audit logging functionality is limited to the defined subset of privileged users. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
|[[Practice_AU.L2-3.3.9_Details|More Practice Details...]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Configuration Management (CM) ==&lt;br /&gt;
=== CM.L2-3.4.1 – System Baselining ===&lt;br /&gt;
{|class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 70%&amp;quot;| &#039;&#039;&#039;Practice and Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Prompt&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Response&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [[ Practice_CM.L2-3.4.1_Details | &#039;&#039;&#039;CM.L2-3.4.1&#039;&#039;&#039; ]] Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles. || [[ LLMPrompt_CM.L2-3.4.1 | Sample Prompt Template ]] || N/A&lt;br /&gt;
|-&lt;br /&gt;
| [a] a baseline configuration is established. || [[ LLMPrompt_CM.L2-3.4.1.a | Sample Prompt ]] || [[ LLMResponse_CM.L2-3.4.1.a | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [b] the baseline configuration includes hardware, software, firmware, and documentation. || [[ LLMPrompt_CM.L2-3.4.1.b | Sample Prompt ]] || [[ LLMResponse_CM.L2-3.4.1.b | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [c] the baseline configuration is maintained (reviewed and updated) throughout the system development life cycle. || [[ LLMPrompt_CM.L2-3.4.1.c | Sample Prompt ]] || [[ LLMResponse_CM.L2-3.4.1.c | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [d] a system inventory is established. || [[ LLMPrompt_CM.L2-3.4.1.d | Sample Prompt ]] || [[ LLMResponse_CM.L2-3.4.1.d | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [e] the system inventory includes hardware, software, firmware, and documentation. || [[ LLMPrompt_CM.L2-3.4.1.e | Sample Prompt ]] || [[ LLMResponse_CM.L2-3.4.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [f] the inventory is maintained (reviewed and updated) throughout the system development life cycle. || [[ LLMPrompt_CM.L2-3.4.1.f | Sample Prompt ]] || [[ LLMResponse_CM.L2-3.4.1.f | Sample Response ]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== CM.L2-3.4.2 – Security Configuration Enforcement ===&lt;br /&gt;
{|class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 70%&amp;quot;| &#039;&#039;&#039;Practice and Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Prompt&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Response&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [[ Practice_CM.L2-3.4.2_Details | &#039;&#039;&#039;CM.L2-3.4.2&#039;&#039;&#039; ]] Establish and enforce security configuration settings for information technology products employed in organizational systems. || [[ LLMPrompt_CM.L2-3.4.2 | Sample Prompt Template ]] || N/A&lt;br /&gt;
|-&lt;br /&gt;
| [a] security configuration settings for information technology products employed in the system are established and included in the baseline configuration. || [[ LLMPrompt_CM.L2-3.4.2.a | Sample Prompt ]] || [[ LLMResponse_CM.L2-3.4.2.a | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [b] security configuration settings for information technology products employed in the system are enforced. || [[ LLMPrompt_CM.L2-3.4.2.b | Sample Prompt ]] || [[ LLMResponse_CM.L2-3.4.2.b | Sample Response ]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== CM.L2-3.4.3 – System Change Management ===&lt;br /&gt;
{|class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 70%&amp;quot;| &#039;&#039;&#039;Practice and Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Prompt&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Response&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [[ Practice_CM.L2-3.4.3_Details | &#039;&#039;&#039;CM.L2-3.4.3&#039;&#039;&#039; ]] Track, review, approve or disapprove, and log changes to organizational systems. || [[ LLMPrompt_CM.L2-3.4.3 | Sample Prompt Template ]] || N/A&lt;br /&gt;
|-&lt;br /&gt;
| [a] changes to the system are tracked. || [[ LLMPrompt_CM.L2-3.4.3.a | Sample Prompt ]] || [[ LLMResponse_CM.L2-3.4.3.a | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [b] changes to the system are reviewed. || [[ LLMPrompt_CM.L2-3.4.3.b | Sample Prompt ]] || [[ LLMResponse_CM.L2-3.4.3.b | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [c] changes to the system are approved or disapproved. || [[ LLMPrompt_CM.L2-3.4.3.c | Sample Prompt ]] || [[ LLMResponse_CM.L2-3.4.3.c | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [d] changes to the system are logged. || [[ LLMPrompt_CM.L2-3.4.3.d | Sample Prompt ]] || [[ LLMResponse_CM.L2-3.4.3.d | Sample Response ]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== CM.L2-3.4.4 – Security Impact Analysis ===&lt;br /&gt;
{|class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 70%&amp;quot;| &#039;&#039;&#039;Practice and Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Prompt&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Response&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [[ Practice_CM.L2-3.4.4_Details | &#039;&#039;&#039;CM.L2-3.4.4&#039;&#039;&#039; ]] Analyze the security impact of changes prior to implementation. || [[ LLMPrompt_CM.L2-3.4.4 | Sample Prompt Template ]] || N/A&lt;br /&gt;
|-&lt;br /&gt;
| [a] the security impact of changes to the system is analyzed prior to implementation. || [[ LLMPrompt_CM.L2-3.4.4.a | Sample Prompt ]] || [[ LLMResponse_CM.L2-3.4.4.a | Sample Response ]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== CM.L2-3.4.5 – Access Restrictions for Change ===&lt;br /&gt;
{|class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 70%&amp;quot;| &#039;&#039;&#039;Practice and Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Prompt&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Response&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [[ Practice_CM.L2-3.4.5_Details | &#039;&#039;&#039;CM.L2-3.4.5&#039;&#039;&#039; ]] Define, document, approve, and enforce physical and logical access restrictions associated with changes to organizational systems. || [[ LLMPrompt_CM.L2-3.4.5 | Sample Prompt Template ]] || N/A&lt;br /&gt;
|-&lt;br /&gt;
| [a] physical access restrictions associated with changes to the system are defined. || [[ LLMPrompt_CM.L2-3.4.5.a | Sample Prompt ]] || [[ LLMResponse_CM.L2-3.4.5.a | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [b] physical access restrictions associated with changes to the system are documented. || [[ LLMPrompt_CM.L2-3.4.5.b | Sample Prompt ]] || [[ LLMResponse_CM.L2-3.4.5.b | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [c] physical access restrictions associated with changes to the system are approved. || [[ LLMPrompt_CM.L2-3.4.5.c | Sample Prompt ]] || [[ LLMResponse_CM.L2-3.4.5.c | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [d] physical access restrictions associated with changes to the system are enforced. || [[ LLMPrompt_CM.L2-3.4.5.d | Sample Prompt ]] || [[ LLMResponse_CM.L2-3.4.5.d | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [e] logical access restrictions associated with changes to the system are defined. || [[ LLMPrompt_CM.L2-3.4.5.e | Sample Prompt ]] || [[ LLMResponse_CM.L2-3.4.5.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [f] logical access restrictions associated with changes to the system are documented. || [[ LLMPrompt_CM.L2-3.4.5.f | Sample Prompt ]] || [[ LLMResponse_CM.L2-3.4.5.f | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [g] logical access restrictions associated with changes to the system are approved. || [[ LLMPrompt_CM.L2-3.4.5.g | Sample Prompt ]] || [[ LLMResponse_CM.L2-3.4.5.g | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [h] logical access restrictions associated with changes to the system are enforced. || [[ LLMPrompt_CM.L2-3.4.5.h | Sample Prompt ]] || [[ LLMResponse_CM.L2-3.4.5.h | Sample Response ]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== CM.L2-3.4.6 – Least Functionality ===&lt;br /&gt;
{|class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 70%&amp;quot;| &#039;&#039;&#039;Practice and Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Prompt&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Response&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [[ Practice_CM.L2-3.4.6_Details | &#039;&#039;&#039;CM.L2-3.4.6&#039;&#039;&#039; ]] Employ the principle of least functionality by configuring organizational systems to provide only essential capabilities. || [[ LLMPrompt_CM.L2-3.4.6 | Sample Prompt Template ]] || N/A&lt;br /&gt;
|-&lt;br /&gt;
| [a] essential system capabilities are defined based on the principle of least functionality. || [[ LLMPrompt_CM.L2-3.4.6.a | Sample Prompt ]] || [[ LLMResponse_CM.L2-3.4.6.a | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [b] the system is configured to provide only the defined essential capabilities. || [[ LLMPrompt_CM.L2-3.4.6.b | Sample Prompt ]] || [[ LLMResponse_CM.L2-3.4.6.b | Sample Response ]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== CM.L2-3.4.7 – Nonessential Functionality ===&lt;br /&gt;
{|class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 70%&amp;quot;| &#039;&#039;&#039;Practice and Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Prompt&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Response&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [[ Practice_CM.L2-3.4.7_Details | &#039;&#039;&#039;CM.L2-3.4.7&#039;&#039;&#039; ]] Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services. || [[ LLMPrompt_CM.L2-3.4.7 | Sample Prompt Template ]] || N/A&lt;br /&gt;
|-&lt;br /&gt;
| [a] essential programs are defined. || [[ LLMPrompt_CM.L2-3.4.7.a | Sample Prompt ]] || [[ LLMResponse_CM.L2-3.4.7.a | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [b] the use of nonessential programs is defined. || [[ LLMPrompt_CM.L2-3.4.7.b | Sample Prompt ]] || [[ LLMResponse_CM.L2-3.4.7.b | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [c] the use of nonessential programs is restricted, disabled, or prevented as defined. || [[ LLMPrompt_CM.L2-3.4.7.c | Sample Prompt ]] || [[ LLMResponse_CM.L2-3.4.7.c | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [d] essential functions are defined. || [[ LLMPrompt_CM.L2-3.4.7.d | Sample Prompt ]] || [[ LLMResponse_CM.L2-3.4.7.d | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [e] the use of nonessential functions is defined. || [[ LLMPrompt_CM.L2-3.4.7.e | Sample Prompt ]] || [[ LLMResponse_CM.L2-3.4.7.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [f] the use of nonessential functions is restricted, disabled, or prevented as defined. || [[ LLMPrompt_CM.L2-3.4.7.f | Sample Prompt ]] || [[ LLMResponse_CM.L2-3.4.7.f | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [g] essential ports are defined. || [[ LLMPrompt_CM.L2-3.4.7.g | Sample Prompt ]] || [[ LLMResponse_CM.L2-3.4.7.g | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [h] the use of nonessential ports is defined. || [[ LLMPrompt_CM.L2-3.4.7.h | Sample Prompt ]] || [[ LLMResponse_CM.L2-3.4.7.h | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [i] the use of nonessential ports is restricted, disabled, or prevented as defined. || [[ LLMPrompt_CM.L2-3.4.7.i | Sample Prompt ]] || [[ LLMResponse_CM.L2-3.4.7.i | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [j] essential protocols are defined. || [[ LLMPrompt_CM.L2-3.4.7.j | Sample Prompt ]] || [[ LLMResponse_CM.L2-3.4.7.j | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [k] the use of nonessential protocols is defined. || [[ LLMPrompt_CM.L2-3.4.7.k | Sample Prompt ]] || [[ LLMResponse_CM.L2-3.4.7.k | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [l] the use of nonessential protocols is restricted, disabled, or prevented as defined. || [[ LLMPrompt_CM.L2-3.4.7.l | Sample Prompt ]] || [[ LLMResponse_CM.L2-3.4.7.l | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [m] essential services are defined. || [[ LLMPrompt_CM.L2-3.4.7.m | Sample Prompt ]] || [[ LLMResponse_CM.L2-3.4.7.m | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [n] the use of nonessential services is defined. || [[ LLMPrompt_CM.L2-3.4.7.n | Sample Prompt ]] || [[ LLMResponse_CM.L2-3.4.7.n | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [o] the use of nonessential services is restricted, disabled, or prevented as defined. || [[ LLMPrompt_CM.L2-3.4.7.o | Sample Prompt ]] || [[ LLMResponse_CM.L2-3.4.7.o | Sample Response ]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== CM.L2-3.4.8 – Application Execution Policy ===&lt;br /&gt;
{|class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 70%&amp;quot;| &#039;&#039;&#039;Practice and Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Prompt&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Response&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [[ Practice_CM.L2-3.4.8_Details | &#039;&#039;&#039;CM.L2-3.4.8&#039;&#039;&#039; ]] Apply deny-by-exception (blacklisting) policy to prevent the use of unauthorized software or deny-all, permit-by-exception (whitelisting) policy to allow the execution of authorized software. || [[ LLMPrompt_CM.L2-3.4.8 | Sample Prompt Template ]] || N/A&lt;br /&gt;
|-&lt;br /&gt;
| [a] a policy specifying whether whitelisting or blacklisting is to be implemented is specified. || [[ LLMPrompt_CM.L2-3.4.8.a | Sample Prompt ]] || [[ LLMResponse_CM.L2-3.4.8.a | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [b] the software allowed to execute under whitelisting or denied use under blacklisting is specified. || [[ LLMPrompt_CM.L2-3.4.8.b | Sample Prompt ]] || [[ LLMResponse_CM.L2-3.4.8.b | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [c] whitelisting to allow the execution of authorized software or blacklisting to prevent the use of unauthorized software is implemented as specified. || [[ LLMPrompt_CM.L2-3.4.8.c | Sample Prompt ]] || [[ LLMResponse_CM.L2-3.4.8.c | Sample Response ]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== CM.L2-3.4.9 – User-Installed Software ===&lt;br /&gt;
{|class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 70%&amp;quot;| &#039;&#039;&#039;Practice and Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Prompt&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Response&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [[ Practice_CM.L2-3.4.9_Details | &#039;&#039;&#039;CM.L2-3.4.9&#039;&#039;&#039; ]] Control and monitor user-installed software. || [[ LLMPrompt_CM.L2-3.4.9 | Sample Prompt Template ]] || N/A&lt;br /&gt;
|-&lt;br /&gt;
| [a] a policy for controlling the installation of software by users is established. || [[ LLMPrompt_CM.L2-3.4.9.a | Sample Prompt ]] || [[ LLMResponse_CM.L2-3.4.9.a | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [b] installation of software by users is controlled based on the established policy. || [[ LLMPrompt_CM.L2-3.4.9.b | Sample Prompt ]] || [[ LLMResponse_CM.L2-3.4.9.b | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [c] installation of software by users is monitored. || [[ LLMPrompt_CM.L2-3.4.9.c | Sample Prompt ]] || [[ LLMResponse_CM.L2-3.4.9.c | Sample Response ]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Identification and Authentication (IA) ==&lt;br /&gt;
=== IA.L2-3.5.1 – Identification [CUI Data] ===&lt;br /&gt;
{|class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 70%&amp;quot;| &#039;&#039;&#039;Practice and Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Prompt&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Response&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [[ Practice_AC.L2-3.x.1_Details | &#039;&#039;&#039;AC.L2-3.x.1&#039;&#039;&#039; ]] Identify information system users, processes acting on behalf of users, or devices. || [[ LLMPrompt_AC.L2-3.x.1 | Sample Prompt Template ]] || N/A&lt;br /&gt;
|-&lt;br /&gt;
| [a] system users are identified. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [b] processes acting on behalf of users are identified. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [c] devices accessing the system are identified. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
|[[Practice_IA.L2-3.5.1_Details|More Practice Details...]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IA.L2-3.5.2 – Authentication [CUI Data] ===&lt;br /&gt;
{|class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 70%&amp;quot;| &#039;&#039;&#039;Practice and Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Prompt&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Response&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [[ Practice_AC.L2-3.x.1_Details | &#039;&#039;&#039;AC.L2-3.x.1&#039;&#039;&#039; ]] Authenticate (or verify) the identities of those users, processes, or devices, as a prerequisite to allowing access to organizational information systems. || [[ LLMPrompt_AC.L2-3.x.1 | Sample Prompt Template ]] || N/A&lt;br /&gt;
|-&lt;br /&gt;
| [a] the identity of each user is authenticated or verified as a prerequisite to system access. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [b] the identity of each process acting on behalf of a user is authenticated or verified as a prerequisite to system access. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [c] the identity of each device accessing or connecting to the system is authenticated or verified as a prerequisite to system access. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
|[[Practice_IA.L2-3.5.2_Details|More Practice Details...]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IA.L2-3.5.3 – Multifactor Authentication ===&lt;br /&gt;
{|class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 70%&amp;quot;| &#039;&#039;&#039;Practice and Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Prompt&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Response&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [[ Practice_AC.L2-3.x.1_Details | &#039;&#039;&#039;AC.L2-3.x.1&#039;&#039;&#039; ]] Use multifactor authentication for local and network access to privileged accounts and for network access to non-privileged accounts. || [[ LLMPrompt_AC.L2-3.x.1 | Sample Prompt Template ]] || N/A&lt;br /&gt;
|-&lt;br /&gt;
| [a] privileged accounts are identified. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [b] multifactor authentication is implemented for local access to privileged accounts. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [c] multifactor authentication is implemented for network access to privileged accounts. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [d] multifactor authentication is implemented for network access to non-privileged accounts. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
|[[Practice_IA.L2-3.5.3_Details|More Practice Details...]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IA.L2-3.5.4 – Replay-Resistant Authentication ===&lt;br /&gt;
{|class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 70%&amp;quot;| &#039;&#039;&#039;Practice and Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Prompt&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Response&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [[ Practice_AC.L2-3.x.1_Details | &#039;&#039;&#039;AC.L2-3.x.1&#039;&#039;&#039; ]] Employ replay-resistant authentication mechanisms for network access to privileged and non-privileged accounts. || [[ LLMPrompt_AC.L2-3.x.1 | Sample Prompt Template ]] || N/A&lt;br /&gt;
|-&lt;br /&gt;
| [a] replay-resistant authentication mechanisms are implemented for network account access to privileged and non-privileged accounts. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
|[[Practice_IA.L2-3.5.4_Details|More Practice Details...]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IA.L2-3.5.5 – Identifier Reuse ===&lt;br /&gt;
{|class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 70%&amp;quot;| &#039;&#039;&#039;Practice and Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Prompt&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Response&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [[ Practice_AC.L2-3.x.1_Details | &#039;&#039;&#039;AC.L2-3.x.1&#039;&#039;&#039; ]] Prevent reuse of identifiers for a defined period. || [[ LLMPrompt_AC.L2-3.x.1 | Sample Prompt Template ]] || N/A&lt;br /&gt;
|-&lt;br /&gt;
| [a] a period within which identifiers cannot be reused is defined. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [b] reuse of identifiers is prevented within the defined period. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
|[[Practice_IA.L2-3.5.5_Details|More Practice Details...]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IA.L2-3.5.6 – Identifier Handling ===&lt;br /&gt;
{|class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 70%&amp;quot;| &#039;&#039;&#039;Practice and Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Prompt&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Response&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [[ Practice_AC.L2-3.x.1_Details | &#039;&#039;&#039;AC.L2-3.x.1&#039;&#039;&#039; ]] Disable identifiers after a defined period of inactivity. || [[ LLMPrompt_AC.L2-3.x.1 | Sample Prompt Template ]] || N/A&lt;br /&gt;
|-&lt;br /&gt;
| [a] a period of inactivity after which an identifier is disabled is defined. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [b] identifiers are disabled after the defined period of inactivity. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
|[[Practice_IA.L2-3.5.6_Details|More Practice Details...]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IA.L2-3.5.7 – Password Complexity ===&lt;br /&gt;
{|class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 70%&amp;quot;| &#039;&#039;&#039;Practice and Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Prompt&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Response&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [[ Practice_AC.L2-3.x.1_Details | &#039;&#039;&#039;AC.L2-3.x.1&#039;&#039;&#039; ]] Enforce a minimum password complexity and change of characters when new passwords are created. || [[ LLMPrompt_AC.L2-3.x.1 | Sample Prompt Template ]] || N/A&lt;br /&gt;
|-&lt;br /&gt;
| [a] password complexity requirements are defined. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [b] password change of character requirements are defined. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [c] minimum password complexity requirements as defined are enforced when new passwords are created. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [d] minimum password change of character requirements as defined are enforced when new passwords are created. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
|[[Practice_IA.L2-3.5.7_Details|More Practice Details...]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IA.L2-3.5.8 – Password Reuse ===&lt;br /&gt;
{|class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 70%&amp;quot;| &#039;&#039;&#039;Practice and Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Prompt&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Response&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [[ Practice_AC.L2-3.x.1_Details | &#039;&#039;&#039;AC.L2-3.x.1&#039;&#039;&#039; ]] Prohibit password reuse for a specified number of generations. || [[ LLMPrompt_AC.L2-3.x.1 | Sample Prompt Template ]] || N/A&lt;br /&gt;
|-&lt;br /&gt;
| [a] the number of generations during which a password cannot be reused is specified and [b] reuse of passwords is prohibited during the specified number of generations. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
|[[Practice_IA.L2-3.5.8_Details|More Practice Details...]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IA.L2-3.5.9 – Temporary Passwords ===&lt;br /&gt;
{|class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 70%&amp;quot;| &#039;&#039;&#039;Practice and Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Prompt&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Response&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [[ Practice_AC.L2-3.x.1_Details | &#039;&#039;&#039;AC.L2-3.x.1&#039;&#039;&#039; ]] Allow temporary password use for system logons with an immediate change to a permanent password. || [[ LLMPrompt_AC.L2-3.x.1 | Sample Prompt Template ]] || N/A&lt;br /&gt;
|-&lt;br /&gt;
| [a] an immediate change to a permanent password is required when a temporary password is used for system logon. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
|[[Practice_IA.L2-3.5.9_Details|More Practice Details...]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IA.L2-3.5.10 – Cryptographically-Protected Passwords ===&lt;br /&gt;
{|class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 70%&amp;quot;| &#039;&#039;&#039;Practice and Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Prompt&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Response&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [[ Practice_AC.L2-3.x.1_Details | &#039;&#039;&#039;AC.L2-3.x.1&#039;&#039;&#039; ]] Store and transmit only cryptographically-protected passwords. || [[ LLMPrompt_AC.L2-3.x.1 | Sample Prompt Template ]] || N/A&lt;br /&gt;
|-&lt;br /&gt;
| [a] passwords are cryptographically protected in storage. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [b] passwords are cryptographically protected in transit. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
|[[Practice_IA.L2-3.5.10_Details|More Practice Details...]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IA.L2-3.5.11 – Obscure Feedback ===&lt;br /&gt;
{|class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 70%&amp;quot;| &#039;&#039;&#039;Practice and Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Prompt&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Response&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [[ Practice_AC.L2-3.x.1_Details | &#039;&#039;&#039;AC.L2-3.x.1&#039;&#039;&#039; ]] Obscure feedback of authentication information. || [[ LLMPrompt_AC.L2-3.x.1 | Sample Prompt Template ]] || N/A&lt;br /&gt;
|-&lt;br /&gt;
| [a] authentication information is obscured during the authentication process. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
|[[Practice_IA.L2-3.5.11_Details|More Practice Details...]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Incident Response (IR) ==&lt;br /&gt;
=== IR.L2-3.6.1 – Incident Handling ===&lt;br /&gt;
{|class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 70%&amp;quot;| &#039;&#039;&#039;Practice and Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Prompt&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Response&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [[ Practice_AC.L2-3.x.1_Details | &#039;&#039;&#039;AC.L2-3.x.1&#039;&#039;&#039; ]] Establish an operational incident-handling capability for organizational systems that includes preparation, detection, analysis, containment, recovery, and user response activities. || [[ LLMPrompt_AC.L2-3.x.1 | Sample Prompt Template ]] || N/A&lt;br /&gt;
|-&lt;br /&gt;
| [a] an operational incident-handling capability is established. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [b] the operational incident-handling capability includes preparation. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [c] the operational incident-handling capability includes detection. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [d] the operational incident-handling capability includes analysis. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [e] the operational incident-handling capability includes containment. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [f] the operational incident-handling capability includes recovery. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [g] the operational incident-handling capability includes user response &lt;br /&gt;
|-&lt;br /&gt;
|[[Practice_IR.L2-3.6.1_Details|More Practice Details...]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IR.L2-3.6.2 – Incident Reporting ===&lt;br /&gt;
{|class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 70%&amp;quot;| &#039;&#039;&#039;Practice and Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Prompt&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Response&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [[ Practice_AC.L2-3.x.1_Details | &#039;&#039;&#039;AC.L2-3.x.1&#039;&#039;&#039; ]] Track, document, and report incidents to designated officials and/or authorities both internal and external to the organization. || [[ LLMPrompt_AC.L2-3.x.1 | Sample Prompt Template ]] || N/A&lt;br /&gt;
|-&lt;br /&gt;
| [a] incidents are tracked. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [b] incidents are documented. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [c] authorities to whom incidents are to be reported are identified. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [d] organizational officials to whom incidents are to be reported are identified. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [e] identified authorities are notified of incidents. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [f] identified organizational officials are notified of incidents. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
|[[Practice_IR.L2-3.6.2_Details|More Practice Details...]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== IR.L2-3.6.3 – Incident Response Testing ===&lt;br /&gt;
{|class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 70%&amp;quot;| &#039;&#039;&#039;Practice and Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Prompt&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Response&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [[ Practice_AC.L2-3.x.1_Details | &#039;&#039;&#039;AC.L2-3.x.1&#039;&#039;&#039; ]] Test the organizational incident response capability. || [[ LLMPrompt_AC.L2-3.x.1 | Sample Prompt Template ]] || N/A&lt;br /&gt;
|-&lt;br /&gt;
| [a] the incident response capability is tested. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
|[[Practice_IR.L2-3.6.3_Details|More Practice Details...]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Maintenance (MA) ==&lt;br /&gt;
=== MA.L2-3.7.1 – Perform Maintenance ===&lt;br /&gt;
{|class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 70%&amp;quot;| &#039;&#039;&#039;Practice and Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Prompt&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Response&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [[ Practice_MA.L2-3.7.1_Details | &#039;&#039;&#039;MA.L2-3.7.1&#039;&#039;&#039; ]] Perform maintenance on organizational systems. || [[ LLMPrompt_MA.L2-3.7.1 | Sample Prompt Template ]] || N/A&lt;br /&gt;
|-&lt;br /&gt;
| [a] system maintenance is performed. || [[ LLMPrompt_MA.L2-3.7.1.a | Sample Prompt ]] || [[ LLMResponse_MA.L2-3.7.1.a | Sample Response ]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MA.L2-3.7.2 – System Maintenance Control ===&lt;br /&gt;
{|class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 70%&amp;quot;| &#039;&#039;&#039;Practice and Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Prompt&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Response&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [[ Practice_MA.L2-3.7.2_Details | &#039;&#039;&#039;MA.L2-3.7.2&#039;&#039;&#039; ]] Provide controls on the tools, techniques, mechanisms, and personnel used to conduct system maintenance. || [[ LLMPrompt_MA.L2-3.7.2 | Sample Prompt Template ]] || N/A&lt;br /&gt;
|-&lt;br /&gt;
| [a] tools used to conduct system maintenance are controlled. || [[ LLMPrompt_MA.L2-3.7.2.a | Sample Prompt ]] || [[ LLMResponse_MA.L2-3.7.2.a | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [b] techniques used to conduct system maintenance are controlled. || [[ LLMPrompt_MA.L2-3.7.2.b | Sample Prompt ]] || [[ LLMResponse_MA.L2-3.7.2.b | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [c] mechanisms used to conduct system maintenance are controlled. || [[ LLMPrompt_MA.L2-3.7.2.c | Sample Prompt ]] || [[ LLMResponse_MA.L2-3.7.2.c | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [d] personnel used to conduct system maintenance are controlled. || [[ LLMPrompt_MA.L2-3.7.2.d | Sample Prompt ]] || [[ LLMResponse_MA.L2-3.7.2.d | Sample Response ]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MA.L2-3.7.3 – Equipment Sanitization ===&lt;br /&gt;
{|class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 70%&amp;quot;| &#039;&#039;&#039;Practice and Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Prompt&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Response&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [[ Practice_MA.L2-3.7.3_Details | &#039;&#039;&#039;MA.L2-3.7.3&#039;&#039;&#039; ]] Ensure equipment removed for off-site maintenance is sanitized of any CUI. || [[ LLMPrompt_MA.L2-3.7.3 | Sample Prompt Template ]] || N/A&lt;br /&gt;
|-&lt;br /&gt;
| [a] equipment to be removed from organizational spaces for off-site maintenance is sanitized of any CUI. || [[ LLMPrompt_MA.L2-3.7.3.a | Sample Prompt ]] || [[ LLMResponse_MA.L2-3.7.3.a | Sample Response ]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MA.L2-3.7.4 – Media Inspection ===&lt;br /&gt;
{|class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 70%&amp;quot;| &#039;&#039;&#039;Practice and Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Prompt&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Response&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [[ Practice_MA.L2-3.7.4_Details | &#039;&#039;&#039;MA.L2-3.7.4&#039;&#039;&#039; ]] Check media containing diagnostic and test programs for malicious code before the media are used in organizational systems. || [[ LLMPrompt_MA.L2-3.7.4 | Sample Prompt Template ]] || N/A&lt;br /&gt;
|-&lt;br /&gt;
| [a] media containing diagnostic and test programs are checked for malicious code before being used in organizational systems that process, store, or transmit CUI. || [[ LLMPrompt_MA.L2-3.7.4.a | Sample Prompt ]] || [[ LLMResponse_MA.L2-3.7.4.a | Sample Response ]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MA.L2-3.7.5 – Nonlocal Maintenance ===&lt;br /&gt;
{|class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 70%&amp;quot;| &#039;&#039;&#039;Practice and Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Prompt&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Response&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [[ Practice_MA.L2-3.7.5_Details | &#039;&#039;&#039;MA.L2-3.7.5&#039;&#039;&#039; ]] Require multifactor authentication to establish nonlocal maintenance sessions via external network connections and terminate such connections when nonlocal maintenance is complete. || [[ LLMPrompt_MA.L2-3.7.5 | Sample Prompt Template ]] || N/A&lt;br /&gt;
|-&lt;br /&gt;
| [a] multifactor authentication is used to establish nonlocal maintenance sessions via external network connections. || [[ LLMPrompt_MA.L2-3.7.5.a | Sample Prompt ]] || [[ LLMResponse_MA.L2-3.7.5.a | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [b] nonlocal maintenance sessions established via external network connections are terminated when nonlocal maintenance is complete. || [[ LLMPrompt_MA.L2-3.7.5.b | Sample Prompt ]] || [[ LLMResponse_MA.L2-3.7.5.b | Sample Response ]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MA.L2-3.7.6 – Maintenance Personnel ===&lt;br /&gt;
{|class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 70%&amp;quot;| &#039;&#039;&#039;Practice and Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Prompt&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Response&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [[ Practice_MA.L2-3.7.6_Details | &#039;&#039;&#039;MA.L2-3.7.6&#039;&#039;&#039; ]] Supervise the maintenance activities of maintenance personnel without required access authorization. || [[ LLMPrompt_MA.L2-3.7.6 | Sample Prompt Template ]] || N/A&lt;br /&gt;
|-&lt;br /&gt;
| [a] maintenance personnel without required access authorization are supervised during maintenance activities. || [[ LLMPrompt_MA.L2-3.7.6.a | Sample Prompt ]] || [[ LLMResponse_MA.L2-3.7.6.a | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
|[[Practice_MA.L2-3.7.6_Details|More Practice Details...]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Media Protection (MP) ==&lt;br /&gt;
=== MP.L2-3.8.1 – Media Protection ===&lt;br /&gt;
{|class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 70%&amp;quot;| &#039;&#039;&#039;Practice and Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Prompt&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Response&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [[ Practice_MP.L2-3.8.1_Details | &#039;&#039;&#039;MP.L2-3.8.1&#039;&#039;&#039; ]] Protect (i.e., physically control and securely store) system media containing CUI, both paper and digital. || [[ LLMPrompt_MP.L2-3.8.1 | Sample Prompt Template ]] || N/A&lt;br /&gt;
|-&lt;br /&gt;
| [a] paper media containing CUI is physically controlled. || [[ LLMPrompt_MP.L2-3.8.1.a | Sample Prompt ]] || [[ LLMResponse_MP.L2-3.8.1.a | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [b] digital media containing CUI is physically controlled. || [[ LLMPrompt_MP.L2-3.8.1.b | Sample Prompt ]] || [[ LLMResponse_MP.L2-3.8.1.b | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [c] paper media containing CUI is securely stored. || [[ LLMPrompt_MP.L2-3.8.1.c | Sample Prompt ]] || [[ LLMResponse_MP.L2-3.8.1.c | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [d] digital media containing CUI is securely stored. || [[ LLMPrompt_MP.L2-3.8.1.d | Sample Prompt ]] || [[ LLMResponse_MP.L2-3.8.1.d | Sample Response ]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MP.L2-3.8.2 – Media Access ===&lt;br /&gt;
{|class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 70%&amp;quot;| &#039;&#039;&#039;Practice and Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Prompt&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Response&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [[ Practice_MP.L2-3.8.2_Details | &#039;&#039;&#039;MP.L2-3.8.2&#039;&#039;&#039; ]] Limit access to CUI on system media to authorized users. || [[ LLMPrompt_MP.L2-3.8.2 | Sample Prompt Template ]] || N/A&lt;br /&gt;
|-&lt;br /&gt;
| [a] access to CUI on system media is limited to authorized users. || [[ LLMPrompt_MP.L2-3.8.2.a | Sample Prompt ]] || [[ LLMResponse_MP.L2-3.8.2.a | Sample Response ]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MP.L2-3.8.3 – Media Disposal [CUI Data] ===&lt;br /&gt;
{|class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 70%&amp;quot;| &#039;&#039;&#039;Practice and Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Prompt&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Response&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [[ Practice_MP.L2-3.8.3_Details | &#039;&#039;&#039;MP.L2-3.8.3&#039;&#039;&#039; ]] Sanitize or destroy information system media containing Federal Contract Information before disposal or release for reuse. || [[ LLMPrompt_MP.L2-3.8.3 | Sample Prompt Template ]] || N/A&lt;br /&gt;
|-&lt;br /&gt;
| [a] system media containing CUI is sanitized or destroyed before disposal. || [[ LLMPrompt_MP.L2-3.8.3.a | Sample Prompt ]] || [[ LLMResponse_MP.L2-3.8.3.a | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [b] system media containing CUI is sanitized before it is released for reuse. || [[ LLMPrompt_MP.L2-3.8.3.b | Sample Prompt ]] || [[ LLMResponse_MP.L2-3.8.3.b | Sample Response ]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MP.L2-3.8.4 – Media Markings ===&lt;br /&gt;
{|class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 70%&amp;quot;| &#039;&#039;&#039;Practice and Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Prompt&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Response&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [[ Practice_MP.L2-3.8.4_Details | &#039;&#039;&#039;MP.L2-3.8.4&#039;&#039;&#039; ]] Mark media with necessary CUI markings and distribution limitations. || [[ LLMPrompt_MP.L2-3.8.4 | Sample Prompt Template ]] || N/A&lt;br /&gt;
|-&lt;br /&gt;
| [a] media containing CUI is marked with applicable CUI markings. || [[ LLMPrompt_MP.L2-3.8.4.a | Sample Prompt ]] || [[ LLMResponse_MP.L2-3.8.4.a | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [b] media containing CUI is marked with distribution limitations. || [[ LLMPrompt_MP.L2-3.8.4.b | Sample Prompt ]] || [[ LLMResponse_MP.L2-3.8.4.b | Sample Response ]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MP.L2-3.8.5 – Media Accountability ===&lt;br /&gt;
{|class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 70%&amp;quot;| &#039;&#039;&#039;Practice and Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Prompt&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Response&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [[ Practice_MP.L2-3.8.5_Details | &#039;&#039;&#039;MP.L2-3.8.5&#039;&#039;&#039; ]] Control access to media containing CUI and maintain accountability for media during transport outside of controlled areas. || [[ LLMPrompt_MP.L2-3.8.5 | Sample Prompt Template ]] || N/A&lt;br /&gt;
|-&lt;br /&gt;
| [a] access to media containing CUI is controlled. || [[ LLMPrompt_MP.L2-3.8.5.a | Sample Prompt ]] || [[ LLMResponse_MP.L2-3.8.5.a | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [b] accountability for media containing CUI is maintained during transport outside of controlled areas. || [[ LLMPrompt_MP.L2-3.8.5.b | Sample Prompt ]] || [[ LLMResponse_MP.L2-3.8.5.b | Sample Response ]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MP.L2-3.8.6 – Portable Storage Encryption ===&lt;br /&gt;
{|class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 70%&amp;quot;| &#039;&#039;&#039;Practice and Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Prompt&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Response&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [[ Practice_MP.L2-3.8.6_Details | &#039;&#039;&#039;MP.L2-3.8.6&#039;&#039;&#039; ]] Implement cryptographic mechanisms to protect the confidentiality of CUI stored on digital media during transport unless otherwise protected by alternative physical safeguards. || [[ LLMPrompt_MP.L2-3.8.6 | Sample Prompt Template ]] || N/A&lt;br /&gt;
|-&lt;br /&gt;
| [a] the confidentiality of CUI stored on digital media is protected during transport using cryptographic mechanisms or alternative physical safeguards. || [[ LLMPrompt_MP.L2-3.8.6.a | Sample Prompt ]] || [[ LLMResponse_MP.L2-3.8.6.a | Sample Response ]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MP.L2-3.8.7 – Removable Media ===&lt;br /&gt;
{|class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 70%&amp;quot;| &#039;&#039;&#039;Practice and Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Prompt&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Response&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [[ Practice_MP.L2-3.8.7_Details | &#039;&#039;&#039;MP.L2-3.8.7&#039;&#039;&#039; ]] Control the use of removable media on system components. || [[ LLMPrompt_MP.L2-3.8.7 | Sample Prompt Template ]] || N/A&lt;br /&gt;
|-&lt;br /&gt;
| [a] the use of removable media on system components is controlled. || [[ LLMPrompt_MP.L2-3.8.7.a | Sample Prompt ]] || [[ LLMResponse_MP.L2-3.8.7.a | Sample Response ]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MP.L2-3.8.8 – Shared Media ===&lt;br /&gt;
{|class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 70%&amp;quot;| &#039;&#039;&#039;Practice and Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Prompt&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Response&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [[ Practice_MP.L2-3.8.8_Details | &#039;&#039;&#039;MP.L2-3.8.8&#039;&#039;&#039; ]] Prohibit the use of portable storage devices when such devices have no identifiable owner. || [[ LLMPrompt_MP.L2-3.8.8 | Sample Prompt Template ]] || N/A&lt;br /&gt;
|-&lt;br /&gt;
| [a] the use of portable storage devices is prohibited when such devices have no identifiable owner. || [[ LLMPrompt_MP.L2-3.8.8.a | Sample Prompt ]] || [[ LLMResponse_MP.L2-3.8.8.a | Sample Response ]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== MP.L2-3.8.9 – Protect Backups ===&lt;br /&gt;
{|class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 70%&amp;quot;| &#039;&#039;&#039;Practice and Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Prompt&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Response&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [[ Practice_MP.L2-3.8.9_Details | &#039;&#039;&#039;MP.L2-3.8.9&#039;&#039;&#039; ]] Protect the confidentiality of backup CUI at storage locations. || [[ LLMPrompt_MP.L2-3.8.9 | Sample Prompt Template ]] || N/A&lt;br /&gt;
|-&lt;br /&gt;
| [a] the confidentiality of backup CUI is protected at storage locations. || [[ LLMPrompt_MP.L2-3.8.9.a | Sample Prompt ]] || [[ LLMResponse_MP.L2-3.8.9.a | Sample Response ]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Personnel Security (PS) ==&lt;br /&gt;
=== PS.L2-3.9.1 – Screen Individuals ===&lt;br /&gt;
{|class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 70%&amp;quot;| &#039;&#039;&#039;Practice and Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Prompt&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Response&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [[ Practice_PS.L2-3.9.1_Details | &#039;&#039;&#039;PS.L2-3.9.1&#039;&#039;&#039; ]] Screen individuals prior to authorizing access to organizational systems containing CUI. || [[ LLMPrompt_PS.L2-3.9.1 | Sample Prompt Template ]] || N/A&lt;br /&gt;
|-&lt;br /&gt;
| [a] individuals are screened prior to authorizing access to organizational systems containing CUI. || [[ LLMPrompt_PS.L2-3.9.1.a | Sample Prompt ]] || [[ LLMResponse_PS.L2-3.9.1.a | Sample Response ]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== PS.L2-3.9.2 – Personnel Actions ===&lt;br /&gt;
{|class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 70%&amp;quot;| &#039;&#039;&#039;Practice and Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Prompt&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Response&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [[ Practice_PS.L2-3.9.2_Details | &#039;&#039;&#039;PS.L2-3.9.2&#039;&#039;&#039; ]] Ensure that organizational systems containing CUI are protected during and after personnel actions such as terminations and transfers. || [[ LLMPrompt_PS.L2-3.9.2 | Sample Prompt Template ]] || N/A&lt;br /&gt;
|-&lt;br /&gt;
| [a] a policy and/or process for terminating system access and any credentials coincident with personnel actions is established. || [[ LLMPrompt_PS.L2-3.9.2.a | Sample Prompt ]] || [[ LLMResponse_PS.L2-3.9.2.a | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [b] system access and credentials are terminated consistent with personnel actions such as termination or transfer. || [[ LLMPrompt_PS.L2-3.9.2.b | Sample Prompt ]] || [[ LLMResponse_PS.L2-3.9.2.b | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [c] the system is protected during and after personnel transfer actions. || [[ LLMPrompt_PS.L2-3.9.2.c | Sample Prompt ]] || [[ LLMResponse_PS.L2-3.9.2.c | Sample Response ]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Physical Protection (PE) ==&lt;br /&gt;
=== PE.L2-3.10.1 – Limit Physical Access [CUI Data] ===&lt;br /&gt;
{|class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 70%&amp;quot;| &#039;&#039;&#039;Practice and Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Prompt&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Response&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [[ Practice_AC.L2-3.x.1_Details | &#039;&#039;&#039;AC.L2-3.x.1&#039;&#039;&#039; ]] Limit physical access to organizational information systems, equipment, and the respective operating environments to authorized individuals. || [[ LLMPrompt_AC.L2-3.x.1 | Sample Prompt Template ]] || N/A&lt;br /&gt;
|-&lt;br /&gt;
| [a] authorized individuals allowed physical access are identified. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [b] physical access to organizational systems is limited to authorized individuals. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [c] physical access to equipment is limited to authorized individuals. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [d] physical access to operating environments is limited to authorized. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
|[[Practice_PE.L2-3.10.1_Details|More Practice Details...]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== PE.L2-3.10.2 – Monitor Facility ===&lt;br /&gt;
{|class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 70%&amp;quot;| &#039;&#039;&#039;Practice and Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Prompt&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Response&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [[ Practice_AC.L2-3.x.1_Details | &#039;&#039;&#039;AC.L2-3.x.1&#039;&#039;&#039; ]] Protect and monitor the physical facility and support infrastructure for organizational systems. || [[ LLMPrompt_AC.L2-3.x.1 | Sample Prompt Template ]] || N/A&lt;br /&gt;
|-&lt;br /&gt;
| [a] the physical facility where organizational systems reside is protected. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [b] the support infrastructure for organizational systems is protected. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [c] the physical facility where organizational systems reside is monitored. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [d] the support infrastructure for organizational systems is monitored. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
|[[Practice_PE.L2-3.10.2_Details|More Practice Details...]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== PE.L2-3.10.3 – Escort Visitors [CUI Data] ===&lt;br /&gt;
{|class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 70%&amp;quot;| &#039;&#039;&#039;Practice and Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Prompt&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Response&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [[ Practice_AC.L2-3.x.1_Details | &#039;&#039;&#039;AC.L2-3.x.1&#039;&#039;&#039; ]] Escort visitors and monitor visitor activity. || [[ LLMPrompt_AC.L2-3.x.1 | Sample Prompt Template ]] || N/A&lt;br /&gt;
|-&lt;br /&gt;
| [a] visitors are escorted. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [b] visitor activity is monitored. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
|[[Practice_PE.L2-3.10.3_Details|More Practice Details...]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== PE.L2-3.10.4 – Physical Access Logs [CUI Data] ===&lt;br /&gt;
{|class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 70%&amp;quot;| &#039;&#039;&#039;Practice and Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Prompt&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Response&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [[ Practice_AC.L2-3.x.1_Details | &#039;&#039;&#039;AC.L2-3.x.1&#039;&#039;&#039; ]] Maintain audit logs of physical access. || [[ LLMPrompt_AC.L2-3.x.1 | Sample Prompt Template ]] || N/A&lt;br /&gt;
|-&lt;br /&gt;
| [a] audit logs of physical access are maintained. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
|[[Practice_PE.L2-3.10.4_Details|More Practice Details...]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== PE.L2-3.10.5 – Manage Physical Access [CUI Data] ===&lt;br /&gt;
{|class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 70%&amp;quot;| &#039;&#039;&#039;Practice and Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Prompt&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Response&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [[ Practice_AC.L2-3.x.1_Details | &#039;&#039;&#039;AC.L2-3.x.1&#039;&#039;&#039; ]] Control and manage physical access devices. || [[ LLMPrompt_AC.L2-3.x.1 | Sample Prompt Template ]] || N/A&lt;br /&gt;
|-&lt;br /&gt;
| [a] physical access devices are identified. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [b] physical access devices are controlled. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [c] physical access devices are managed. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
|[[Practice_PE.L2-3.10.5_Details|More Practice Details...]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== PE.L2-3.10.6 – Alternative Work Sites ===&lt;br /&gt;
{|class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 70%&amp;quot;| &#039;&#039;&#039;Practice and Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Prompt&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Response&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [[ Practice_AC.L2-3.x.1_Details | &#039;&#039;&#039;AC.L2-3.x.1&#039;&#039;&#039; ]] Enforce safeguarding measures for CUI at alternate work sites. || [[ LLMPrompt_AC.L2-3.x.1 | Sample Prompt Template ]] || N/A&lt;br /&gt;
|-&lt;br /&gt;
| [a] safeguarding measures for CUI are defined for alternate work sites. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [b] safeguarding measures for CUI are enforced for alternate work sites. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
|[[Practice_PE.L2-3.10.6_Details|More Practice Details...]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Risk Assessment (RA) ==&lt;br /&gt;
=== RA.L2-3.11.1 – Risk Assessments ===&lt;br /&gt;
{|class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 70%&amp;quot;| &#039;&#039;&#039;Practice and Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Prompt&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Response&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [[ Practice_AC.L2-3.x.1_Details | &#039;&#039;&#039;AC.L2-3.x.1&#039;&#039;&#039; ]] Periodically assess the risk to organizational operations (including mission, functions, image, or reputation), organizational assets, and individuals, resulting from the operation of organizational systems and the associated processing, storage, or transmission of CUI. || [[ LLMPrompt_AC.L2-3.x.1 | Sample Prompt Template ]] || N/A&lt;br /&gt;
|-&lt;br /&gt;
| [a] the frequency to assess risk to organizational operations, organizational assets, and individuals is defined. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [b] risk to organizational operations, organizational assets, and individuals resulting from the operation of an organizational system that processes, stores, or transmits CUI is assessed with the defined frequency. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
|[[Practice_RA.L2-3.11.1_Details|More Practice Details...]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== RA.L2-3.11.2 – Vulnerability Scan ===&lt;br /&gt;
{|class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 70%&amp;quot;| &#039;&#039;&#039;Practice and Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Prompt&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Response&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [[ Practice_AC.L2-3.x.1_Details | &#039;&#039;&#039;AC.L2-3.x.1&#039;&#039;&#039; ]] Scan for vulnerabilities in organizational systems and applications periodically and when new vulnerabilities affecting those systems and applications are identified. || [[ LLMPrompt_AC.L2-3.x.1 | Sample Prompt Template ]] || N/A&lt;br /&gt;
|-&lt;br /&gt;
| [a] the frequency to scan for vulnerabilities in organizational systems and applications is defined. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [b] vulnerability scans are performed on organizational systems with the defined frequency. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [c] vulnerability scans are performed on applications with the defined frequency. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [d] vulnerability scans are performed on organizational systems when new vulnerabilities are identified. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [e] vulnerability scans are performed on applications when new vulnerabilities are &lt;br /&gt;
identified. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
|[[Practice_RA.L2-3.11.2_Details|More Practice Details...]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== RA.L2-3.11.3 – Vulnerability Remediation ===&lt;br /&gt;
{|class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 70%&amp;quot;| &#039;&#039;&#039;Practice and Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Prompt&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Response&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [[ Practice_AC.L2-3.x.1_Details | &#039;&#039;&#039;AC.L2-3.x.1&#039;&#039;&#039; ]] Remediate vulnerabilities in accordance with risk assessments. || [[ LLMPrompt_AC.L2-3.x.1 | Sample Prompt Template ]] || N/A&lt;br /&gt;
|-&lt;br /&gt;
| [a] vulnerabilities are identified. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [b] vulnerabilities are remediated in accordance with risk assessments. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
|[[Practice_RA.L2-3.11.3_Details|More Practice Details...]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Security Assessment (CA) ==&lt;br /&gt;
=== CA.L2-3.12.1 – Security Control Assessment ===&lt;br /&gt;
{|class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 70%&amp;quot;| &#039;&#039;&#039;Practice and Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Prompt&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Response&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [[ Practice_AC.L2-3.x.1_Details | &#039;&#039;&#039;AC.L2-3.x.1&#039;&#039;&#039; ]] Periodically assess the security controls in organizational systems to determine if the controls are effective in their application. || [[ LLMPrompt_AC.L2-3.x.1 | Sample Prompt Template ]] || N/A&lt;br /&gt;
|-&lt;br /&gt;
| [a] the frequency of security control assessments is defined. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [b] security controls are assessed with the defined frequency to determine if the controls are effective in their application. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
|[[Practice_CA.L2-3.12.1_Details|More Practice Details...]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== CA.L2-3.12.2 – Operational Plan of Action ===&lt;br /&gt;
{|class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 70%&amp;quot;| &#039;&#039;&#039;Practice and Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Prompt&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Response&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [[ Practice_AC.L2-3.x.1_Details | &#039;&#039;&#039;AC.L2-3.x.1&#039;&#039;&#039; ]] Develop and implement plans of action designed to correct deficiencies and reduce or eliminate vulnerabilities in organizational systems. || [[ LLMPrompt_AC.L2-3.x.1 | Sample Prompt Template ]] || N/A&lt;br /&gt;
|-&lt;br /&gt;
| [a] deficiencies and vulnerabilities to be addressed by the plan of action are identified. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [b] a plan of action is developed to correct identified deficiencies and reduce or eliminate identified vulnerabilities. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [c] the plan of action is implemented to correct identified deficiencies and reduce or eliminate identified vulnerabilities. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
|[[Practice_CA.L2-3.12.2_Details|More Practice Details...]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== CA.L2-3.12.3 – Security Control Monitoring ===&lt;br /&gt;
{|class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 70%&amp;quot;| &#039;&#039;&#039;Practice and Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Prompt&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Response&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [[ Practice_AC.L2-3.x.1_Details | &#039;&#039;&#039;AC.L2-3.x.1&#039;&#039;&#039; ]] Monitor security controls on an ongoing basis to ensure the continued effectiveness of the controls. || [[ LLMPrompt_AC.L2-3.x.1 | Sample Prompt Template ]] || N/A&lt;br /&gt;
|-&lt;br /&gt;
| [a] security controls are monitored on an ongoing basis to ensure the continued effectiveness of those controls. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
|[[Practice_CA.L2-3.12.3_Details|More Practice Details...]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== CA.L2-3.12.4 – System Security Plan ====&lt;br /&gt;
{|class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 70%&amp;quot;| &#039;&#039;&#039;Practice and Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Prompt&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Response&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [[ Practice_AC.L2-3.x.1_Details | &#039;&#039;&#039;AC.L2-3.x.1&#039;&#039;&#039; ]] Develop, document, and periodically update system security plans that describe system boundaries, system environments of operation, how security requirements are implemented, and the relationships with or connections to other systems. || [[ LLMPrompt_AC.L2-3.x.1 | Sample Prompt Template ]] || N/A&lt;br /&gt;
|-&lt;br /&gt;
| [a] a system security plan is developed. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [b] the system boundary is described and documented in the system security plan. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [c] the system environment of operation is described and documented in the system security plan. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [d] the security requirements identified and approved by the designated authority as non-applicable are identified. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [e] the method of security requirement implementation is described and documented in the system security plan. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [f] the relationship with or connection to other systems is described and documented in the system security plan. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [g] the frequency to update the system security plan is defined. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [h] system security plan is updated with the defined frequency. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
|[[Practice_CA.L2-3.12.4_Details|More Practice Details...]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== System and Communications Protection (SC) ==&lt;br /&gt;
=== SC.L2-3.13.1 – Boundary Protection [CUI Data] ===&lt;br /&gt;
{|class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 70%&amp;quot;| &#039;&#039;&#039;Practice and Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Prompt&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Response&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [[ Practice_AC.L2-3.x.1_Details | &#039;&#039;&#039;AC.L2-3.x.1&#039;&#039;&#039; ]] Monitor, control, and protect organizational communications (i.e., information transmitted or received by organizational information systems) at the external boundaries and key internal boundaries of the information systems. || [[ LLMPrompt_AC.L2-3.x.1 | Sample Prompt Template ]] || N/A&lt;br /&gt;
|-&lt;br /&gt;
| [a] the external system boundary is defined. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [b] key internal system boundaries are defined. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [c] communications are monitored at the external system boundary. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [d] communications are monitored at key internal boundaries. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [e] communications are controlled at the external system boundary. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [f] communications are controlled at key internal boundaries. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [g] communications are protected at the external system boundary. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [h] communications are protected at key internal boundaries. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
|[[Practice_SC.L2-3.13.1_Details|More Practice Details...]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.2 – Security Engineering ===&lt;br /&gt;
{|class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 70%&amp;quot;| &#039;&#039;&#039;Practice and Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Prompt&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Response&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [[ Practice_AC.L2-3.x.1_Details | &#039;&#039;&#039;AC.L2-3.x.1&#039;&#039;&#039; ]] Employ architectural designs, software development techniques, and systems engineering principles that promote effective information security within organizational systems. || [[ LLMPrompt_AC.L2-3.x.1 | Sample Prompt Template ]] || N/A&lt;br /&gt;
|-&lt;br /&gt;
| [a] architectural designs that promote effective information security are identified. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [b] software development techniques that promote effective information security are identified. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [c] systems engineering principles that promote effective information security are identified. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [d] identified architectural designs that promote effective information security are employed. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [e] identified software development techniques that promote effective information security are employed. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [f] identified systems engineering principles that promote effective information security are employed. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
|[[Practice_SC.L2-3.13.2_Details|More Practice Details...]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.3 – Role Separation ===&lt;br /&gt;
{|class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 70%&amp;quot;| &#039;&#039;&#039;Practice and Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Prompt&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Response&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [[ Practice_AC.L2-3.x.1_Details | &#039;&#039;&#039;AC.L2-3.x.1&#039;&#039;&#039; ]] Separate user functionality from system management functionality. || [[ LLMPrompt_AC.L2-3.x.1 | Sample Prompt Template ]] || N/A&lt;br /&gt;
|-&lt;br /&gt;
| [a] user functionality is identified. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [b] system management functionality is identified. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [c] user functionality is separated from system management functionality. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
|[[Practice_SC.L2-3.13.3_Details|More Practice Details...]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.4 – Shared Resource Control ===&lt;br /&gt;
{|class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 70%&amp;quot;| &#039;&#039;&#039;Practice and Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Prompt&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Response&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [[ Practice_AC.L2-3.x.1_Details | &#039;&#039;&#039;AC.L2-3.x.1&#039;&#039;&#039; ]] Prevent unauthorized and unintended information transfer via shared system resources. || [[ LLMPrompt_AC.L2-3.x.1 | Sample Prompt Template ]] || N/A&lt;br /&gt;
|-&lt;br /&gt;
| [a] unauthorized and unintended information transfer via shared system resources is prevented. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
|[[Practice_SC.L2-3.13.4_Details|More Practice Details...]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
===  SC.L2-3.13.5 – Public-Access System Separation [CUI Data] ===&lt;br /&gt;
{|class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 70%&amp;quot;| &#039;&#039;&#039;Practice and Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Prompt&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Response&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [[ Practice_AC.L2-3.x.1_Details | &#039;&#039;&#039;AC.L2-3.x.1&#039;&#039;&#039; ]] Implement subnetworks for publicly accessible system components that are physically or logically separated from internal networks. || [[ LLMPrompt_AC.L2-3.x.1 | Sample Prompt Template ]] || N/A&lt;br /&gt;
|-&lt;br /&gt;
| [a] publicly accessible system components are identified. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [b] subnetworks for publicly accessible system components are physically or logically separated from internal networks. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
|[[Practice_SC.L2-3.13.5_Details|More Practice Details...]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.6 – Network Communication by Exception ===&lt;br /&gt;
{|class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 70%&amp;quot;| &#039;&#039;&#039;Practice and Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Prompt&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Response&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [[ Practice_AC.L2-3.x.1_Details | &#039;&#039;&#039;AC.L2-3.x.1&#039;&#039;&#039; ]] Deny network communications traffic by default and allow network communications traffic by exception (i.e., deny all, permit by exception). || [[ LLMPrompt_AC.L2-3.x.1 | Sample Prompt Template ]] || N/A&lt;br /&gt;
|-&lt;br /&gt;
| [a] network communications traffic is denied by default. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [b] network communications traffic is allowed by exception. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
|[[Practice_SC.L2-3.13.6_Details|More Practice Details...]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.7 – Split Tunneling ===&lt;br /&gt;
{|class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 70%&amp;quot;| &#039;&#039;&#039;Practice and Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Prompt&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Response&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [[ Practice_AC.L2-3.x.1_Details | &#039;&#039;&#039;AC.L2-3.x.1&#039;&#039;&#039; ]] Prevent remote devices from simultaneously establishing non-remote connections with organizational systems and communicating via some other connection to resources in external networks (i.e., split tunneling). || [[ LLMPrompt_AC.L2-3.x.1 | Sample Prompt Template ]] || N/A&lt;br /&gt;
|-&lt;br /&gt;
| [a] remote devices are prevented from simultaneously establishing non-remote connections with the system and communicating via some other connection to resources in external networks (i.e., split tunneling). || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
|[[Practice_SC.L2-3.13.7_Details|More Practice Details...]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.8 – Data in Transit ===&lt;br /&gt;
{|class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 70%&amp;quot;| &#039;&#039;&#039;Practice and Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Prompt&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Response&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [[ Practice_AC.L2-3.x.1_Details | &#039;&#039;&#039;AC.L2-3.x.1&#039;&#039;&#039; ]] Implement cryptographic mechanisms to prevent unauthorized disclosure of CUI during transmission unless otherwise protected by alternative physical safeguards. || [[ LLMPrompt_AC.L2-3.x.1 | Sample Prompt Template ]] || N/A&lt;br /&gt;
|-&lt;br /&gt;
| [a] cryptographic mechanisms intended to prevent unauthorized disclosure of CUI are identified. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [b] alternative physical safeguards intended to prevent unauthorized disclosure of CUI are identified. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [c] either cryptographic mechanisms or alternative physical safeguards are implemented to prevent unauthorized disclosure of CUI during transmission. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
|[[Practice_SC.L2-3.13.8_Details|More Practice Details...]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.9 – Connections Termination ===&lt;br /&gt;
{|class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 70%&amp;quot;| &#039;&#039;&#039;Practice and Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Prompt&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Response&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [[ Practice_AC.L2-3.x.1_Details | &#039;&#039;&#039;AC.L2-3.x.1&#039;&#039;&#039; ]] Terminate network connections associated with communications sessions at the end of the sessions or after a defined period of inactivity. || [[ LLMPrompt_AC.L2-3.x.1 | Sample Prompt Template ]] || N/A&lt;br /&gt;
|-&lt;br /&gt;
| [a] a period of inactivity to terminate network connections associated with communications sessions is defined. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [b] network connections associated with communications sessions are terminated at the end of the sessions. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [c] network connections associated with communications sessions are terminated after the defined period of inactivity. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
|[[Practice_SC.L2-3.13.9_Details|More Practice Details...]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.10 – Key Management ===&lt;br /&gt;
{|class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 70%&amp;quot;| &#039;&#039;&#039;Practice and Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Prompt&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Response&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [[ Practice_AC.L2-3.x.1_Details | &#039;&#039;&#039;AC.L2-3.x.1&#039;&#039;&#039; ]] Establish and manage cryptographic keys for cryptography employed in organizational systems. || [[ LLMPrompt_AC.L2-3.x.1 | Sample Prompt Template ]] || N/A&lt;br /&gt;
|-&lt;br /&gt;
| [a] cryptographic keys are established whenever cryptography is employed. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [b] cryptographic keys are managed whenever cryptography is employed. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
|[[Practice_SC.L2-3.13.10_Details|More Practice Details...]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.11 – CUI Encryption ===&lt;br /&gt;
{|class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 70%&amp;quot;| &#039;&#039;&#039;Practice and Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Prompt&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Response&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [[ Practice_AC.L2-3.x.1_Details | &#039;&#039;&#039;AC.L2-3.x.1&#039;&#039;&#039; ]] Employ FIPS-validated cryptography when used to protect the confidentiality of CUI. || [[ LLMPrompt_AC.L2-3.x.1 | Sample Prompt Template ]] || N/A&lt;br /&gt;
|-&lt;br /&gt;
| [a] FIPS-validated cryptography is employed to protect the confidentiality of CUI. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
|[[Practice_SC.L2-3.13.11_Details|More Practice Details...]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.12 – Collaborative Device Control ===&lt;br /&gt;
{|class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 70%&amp;quot;| &#039;&#039;&#039;Practice and Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Prompt&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Response&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [[ Practice_AC.L2-3.x.1_Details | &#039;&#039;&#039;AC.L2-3.x.1&#039;&#039;&#039; ]] Prohibit remote activation of collaborative computing devices and provide indication of devices in use to users present at the device. || [[ LLMPrompt_AC.L2-3.x.1 | Sample Prompt Template ]] || N/A&lt;br /&gt;
|-&lt;br /&gt;
| [a] collaborative computing devices are identified. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [b] collaborative computing devices provide indication to users of devices in use. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [c] remote activation of collaborative computing devices is prohibited. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
|[[Practice_SC.L2-3.13.12_Details|More Practice Details...]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.13 – Mobile Code ===&lt;br /&gt;
{|class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 70%&amp;quot;| &#039;&#039;&#039;Practice and Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Prompt&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Response&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [[ Practice_AC.L2-3.x.1_Details | &#039;&#039;&#039;AC.L2-3.x.1&#039;&#039;&#039; ]] Control and monitor the use of mobile code. || [[ LLMPrompt_AC.L2-3.x.1 | Sample Prompt Template ]] || N/A&lt;br /&gt;
|-&lt;br /&gt;
| [a] use of mobile code is controlled. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [b] use of mobile code is monitored. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
|[[Practice_SC.L2-3.13.13_Details|More Practice Details...]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.14 – Voice over Internet Protocol ===&lt;br /&gt;
{|class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 70%&amp;quot;| &#039;&#039;&#039;Practice and Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Prompt&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Response&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [[ Practice_AC.L2-3.x.1_Details | &#039;&#039;&#039;AC.L2-3.x.1&#039;&#039;&#039; ]] Control and monitor the use of Voice over Internet Protocol (VoIP) technologies. || [[ LLMPrompt_AC.L2-3.x.1 | Sample Prompt Template ]] || N/A&lt;br /&gt;
|-&lt;br /&gt;
| [a] use of Voice over Internet Protocol (VoIP) technologies is controlled. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [b] use of Voice over Internet Protocol (VoIP) technologies is monitored. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
|[[Practice_SC.L2-3.13.14_Details|More Practice Details...]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.15 – Communications Authenticity ===&lt;br /&gt;
{|class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 70%&amp;quot;| &#039;&#039;&#039;Practice and Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Prompt&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Response&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [[ Practice_AC.L2-3.x.1_Details | &#039;&#039;&#039;AC.L2-3.x.1&#039;&#039;&#039; ]] Protect the authenticity of communications sessions. || [[ LLMPrompt_AC.L2-3.x.1 | Sample Prompt Template ]] || N/A&lt;br /&gt;
|-&lt;br /&gt;
| [a] the authenticity of communications sessions is protected. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
|[[Practice_SC.L2-3.13.15_Details|More Practice Details...]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SC.L2-3.13.16 – Data at Rest ===&lt;br /&gt;
{|class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 70%&amp;quot;| &#039;&#039;&#039;Practice and Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Prompt&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Response&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [[ Practice_AC.L2-3.x.1_Details | &#039;&#039;&#039;AC.L2-3.x.1&#039;&#039;&#039; ]] Protect the confidentiality of CUI at rest. || [[ LLMPrompt_AC.L2-3.x.1 | Sample Prompt Template ]] || N/A&lt;br /&gt;
|-&lt;br /&gt;
| [a] the confidentiality of CUI at rest is protected. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
|[[Practice_SC.L2-3.13.16_Details|More Practice Details...]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== System and Information Integrity (SI) ==&lt;br /&gt;
=== SI.L2-3.14.1 – Flaw Remediation [CUI Data] ===&lt;br /&gt;
{|class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 70%&amp;quot;| &#039;&#039;&#039;Practice and Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Prompt&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Response&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [[ Practice_AC.L2-3.x.1_Details | &#039;&#039;&#039;AC.L2-3.x.1&#039;&#039;&#039; ]] Identify, report, and correct information and information system flaws in a timely manner. || [[ LLMPrompt_AC.L2-3.x.1 | Sample Prompt Template ]] || N/A&lt;br /&gt;
|-&lt;br /&gt;
| [a] the time within which to identify system flaws is specified. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [b] system flaws are identified within the specified time frame. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [c] the time within which to report system flaws is specified. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [d] system flaws are reported within the specified time frame. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [e] the time within which to correct system flaws is specified. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [f] system flaws are corrected within the specified time frame. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
|[[Practice_SI.L2-3.14.1_Details|More Practice Details...]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SI.L2-3.14.2 – Malicious Code ProTection [CUI Data] ===&lt;br /&gt;
{|class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 70%&amp;quot;| &#039;&#039;&#039;Practice and Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Prompt&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Response&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [[ Practice_AC.L2-3.x.1_Details | &#039;&#039;&#039;AC.L2-3.x.1&#039;&#039;&#039; ]] Provide protection from malicious code at appropriate locations within organizational information systems. || [[ LLMPrompt_AC.L2-3.x.1 | Sample Prompt Template ]] || N/A&lt;br /&gt;
|-&lt;br /&gt;
| [a] designated locations for malicious code protection are identified. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [b] protection from malicious code at designated locations is provided. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
|[[Practice_SI.L2-3.14.2_Details|More Practice Details...]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SI.L2-3.14.3 – Security Alerts &amp;amp; Advisories ===&lt;br /&gt;
{|class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 70%&amp;quot;| &#039;&#039;&#039;Practice and Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Prompt&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Response&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [[ Practice_AC.L2-3.x.1_Details | &#039;&#039;&#039;AC.L2-3.x.1&#039;&#039;&#039; ]] Monitor system security alerts and advisories and take action in response. || [[ LLMPrompt_AC.L2-3.x.1 | Sample Prompt Template ]] || N/A&lt;br /&gt;
|-&lt;br /&gt;
| [a] response actions to system security alerts and advisories are identified. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [b] system security alerts and advisories are monitored. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [c] actions in response to system security alerts and advisories are taken. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
|[[Practice_SI.L2-3.14.3_Details|More Practice Details...]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SI.L2-3.14.4 – Update Malicious Code Protection [CUI Data] ===&lt;br /&gt;
{|class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 70%&amp;quot;| &#039;&#039;&#039;Practice and Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Prompt&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Response&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [[ Practice_AC.L2-3.x.1_Details | &#039;&#039;&#039;AC.L2-3.x.1&#039;&#039;&#039; ]] Update malicious code protection mechanisms when new releases are available. || [[ LLMPrompt_AC.L2-3.x.1 | Sample Prompt Template ]] || N/A&lt;br /&gt;
|-&lt;br /&gt;
| [a] malicious code protection mechanisms are updated when new releases are available. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
|[[Practice_SI.L2-3.14.4_Details|More Practice Details...]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SI.L2-3.14.5 – System &amp;amp; File Scanning [CUI Data] ===&lt;br /&gt;
{|class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 70%&amp;quot;| &#039;&#039;&#039;Practice and Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Prompt&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Response&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [[ Practice_AC.L2-3.x.1_Details | &#039;&#039;&#039;AC.L2-3.x.1&#039;&#039;&#039; ]] Perform periodic scans of the information system and real-time scans of files from external sources as files are downloaded, opened, or executed. || [[ LLMPrompt_AC.L2-3.x.1 | Sample Prompt Template ]] || N/A&lt;br /&gt;
|-&lt;br /&gt;
| [a] the frequency for malicious code scans is defined. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [b] malicious code scans are performed with the defined frequency. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [c] real-time malicious code scans of files from external sources as files are downloaded, opened, or executed are performed. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
|[[Practice_SI.L2-3.14.5_Details|More Practice Details...]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SI.L2-3.14.6 – Monitor Communications for Attacks ===&lt;br /&gt;
{|class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 70%&amp;quot;| &#039;&#039;&#039;Practice and Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Prompt&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Response&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [[ Practice_AC.L2-3.x.1_Details | &#039;&#039;&#039;AC.L2-3.x.1&#039;&#039;&#039; ]] Monitor organizational systems, including inbound and outbound communications traffic, to detect attacks and indicators of potential attacks. || [[ LLMPrompt_AC.L2-3.x.1 | Sample Prompt Template ]] || N/A&lt;br /&gt;
|-&lt;br /&gt;
| [a] the system is monitored to detect attacks and indicators of potential attacks. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [b] inbound communications traffic is monitored to detect attacks and indicators of potential attacks. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [c] outbound communications traffic is monitored to detect attacks and indicators of potential attacks. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
|[[Practice_SI.L2-3.14.6_Details|More Practice Details...]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== SI.L2-3.14.7 – Identify Unauthorized Use ===&lt;br /&gt;
{|class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! style=&amp;quot;width: 70%&amp;quot;| &#039;&#039;&#039;Practice and Assessment Objectives&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Prompt&#039;&#039;&#039;&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;| &#039;&#039;&#039;LLM Response&#039;&#039;&#039;&lt;br /&gt;
|-&lt;br /&gt;
| [[ Practice_AC.L2-3.x.1_Details | &#039;&#039;&#039;AC.L2-3.x.1&#039;&#039;&#039; ]] Identify unauthorized use of organizational systems. || [[ LLMPrompt_AC.L2-3.x.1 | Sample Prompt Template ]] || N/A&lt;br /&gt;
|-&lt;br /&gt;
| [a] authorized use of the system is defined. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
| [b] unauthorized use of the system is identified. || [[ LLMPrompt_AC.L2-3.x.1.e | Sample Prompt ]] || [[ LLMResponse_AC.L2-3.x.1.e | Sample Response ]]&lt;br /&gt;
|-&lt;br /&gt;
|[[Practice_SI.L2-3.14.7_Details|More Practice Details...]]&lt;br /&gt;
|}&lt;/div&gt;</summary>
		<author><name>David</name></author>
	</entry>
	<entry>
		<id>https://cmmcwiki.org/index.php?title=DoD_Assessment_Methodology&amp;diff=1596</id>
		<title>DoD Assessment Methodology</title>
		<link rel="alternate" type="text/html" href="https://cmmcwiki.org/index.php?title=DoD_Assessment_Methodology&amp;diff=1596"/>
		<updated>2026-03-02T01:31:29Z</updated>

		<summary type="html">&lt;p&gt;David: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&#039;&#039;&#039;Source of Reference: The [https://www.acq.osd.mil/asda/dpc/cp/cyber/docs/safeguarding/NIST-SP-800-171-Assessment-Methodology-Version-1.2.1-6.24.2020.pdf NIST SP 800-171 DoD Assessment Methodology Version 1.2.1, June 2020] from the [https://www.acq.osd.mil/asda/dpc/cp/cyber/safeguarding.html#nistSP800171 U.S. Department of Defense Website]&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
For inquiries and reporting errors on this wiki, please [mailto:support@cmmcwiki.org contact us]. Thank you.&lt;br /&gt;
&lt;br /&gt;
== Section 5. NIST SP 800-171 DoD Assessment Scoring Methodology ==&lt;br /&gt;
&lt;br /&gt;
[a] This scoring methodology is designed to provide an objective assessment of a contractor’s NIST SP 800-171 implementation status.  With the exception of requirements for which the scoring of partial implementation is built-in (e.g., multifactor authentication, security requirement 3.5.3) the methodology is not designed to credit partial implementation.&lt;br /&gt;
&lt;br /&gt;
[b] Conduct of the &#039;&#039;NIST SP 800-171 DoD Assessment&#039;&#039; will result in a score reflecting the net effect of security requirements not yet implemented.  If all security requirements are implemented, a contractor is awarded a score of 110, consistent with the total number of NIST SP 800-171 security requirements.  For each security requirement not met, the associated value is subtracted from 110.   The score of 110 is reduced by each requirement not implemented, which may result in a negative score.&lt;br /&gt;
&lt;br /&gt;
[c] While NIST SP 800-171 does not prioritize security requirements, certain requirements have more impact on the security of the network and its data than others. This scoring methodology incorporates this concept by weighting each security requirement based on the impact to the information system and the DoD CUI created on or transiting through that system, when that requirement is not implemented.&lt;br /&gt;
&lt;br /&gt;
[d] Weighted requirements include all of the fundamental NIST SP 800-171 ‘Basic Security Requirements’ - high-level requirements which, if not implemented, render ineffective the more numerous ‘Derived Security Requirements’; and a subset of the ‘Derived Security Requirements’- requirements that supplement the Basic Security &lt;br /&gt;
Requirements - which, if not implemented, would allow for exploitation of the network and its information.&lt;br /&gt;
# For security requirements that, if not implemented, could lead to significant exploitation of the network, or exfiltration of DoD CUI, 5 points are subtracted from the score of 110.  For example, failure to limit system access to authorized users (Basic Security Requirement 3.1.1) renders all the other Access Control requirements ineffective, allowing easy exploitation of the network; failure to control the use of removable media on system components (Derived Security Requirement 3.8.7) could result in massive exfiltration of CUI and introduction of malware.&lt;br /&gt;
## Basic Security Requirements with a value of 5 points include 3.1.1, 3.1.2, 3.2.1, 3.2.2, 3.3.1, 3.4.1, 3.4.2, 3.5.1, 3.5.2, 3.6.1, 3.6.2, 3.7.2, 3.8.3, 3.9.2, 3.10.1, 3.10.2, 3.12.1, 3.12.3, 3.13.1, 3.13.2, 3.14.1, 3.14.2, and 3.14.3.&lt;br /&gt;
## Derived Security Requirements with a value of 5 points include 3.1.12, 3.1.13, 3.1.16, 3.1.17, 3.1.18, 3.3.5, 3.4.5, 3.4.6, 3.4.7, 3.4.8, 3.5.10, 3.7.5, 3.8.7, 3.11.2, 3.13.5, 3.13.6, 3.13.15, 3.14.4, and 3.14.6.&lt;br /&gt;
# For Basic and Derived Security Requirements that, if not implemented, have a specific and confined effect on the security of the network and its data, 3 points are subtracted from the score of 110.  For example, failure to limit access to CUI on system media to authorized users (Security Requirement 3.8.2) or failure to encrypt CUI stored on a mobile device (Security Requirement 3.1.19), put the CUI stored on the system media or mobile device at risk, but not the CUI stored on the network itself.&lt;br /&gt;
## Basic Security Requirements with a value of 3 points include 3.3.2, 3.7.1, 3.8.1, 3.8.2, 3.9.1, 3.11.1, and 3.12.2.&lt;br /&gt;
## Derived Security Requirements with a value of 3 points include 3.1.5, 3.1.19, 3.7.4, 3.8.8, 3.13.8, 3.14.5, and 3.14.7.&lt;br /&gt;
# All remaining Derived Security Requirements, if not implemented, have a limited or indirect effect on the security of the network and its data.  For these, 1 point is subtracted from the score of 110.   For example, failing to prevent reuse of identifiers for a defined period (Security Requirement 3.5.5) could allow a user access to CUI to which they were not approved.&lt;br /&gt;
&lt;br /&gt;
[e] Two Derived Security Requirements can be partially effective even if not completely or properly implemented, and the points deducted should be adjusted depending on how the security requirement is implemented.&lt;br /&gt;
# Multi-factor authentication (MFA) (Security Requirement 3.5.3) is typically implemented first for remote and privileged users (since these users are both limited in number and more critical) and then for the general user, so 3 points are subtracted from the score of 110 if MFA is implemented only for remote and privileged users; 5 points are subtracted from the score of 110 if MFA is not implemented for any users.&lt;br /&gt;
# FIPS validated encryption (Security Requirement 3.13.11) is required to protect the confidentiality of CUI. If encryption is employed, but is not FIPS validated, 3 points are subtracted from the score of 110; if encryption is not employed, 5 points are subtracted from the score of 110.&lt;br /&gt;
&lt;br /&gt;
[f] Although not common, future revisions of NIST SP 800-171 may add, delete or substantively revise security requirements.  When this occurs, a value will be assigned to any new or modified requirements in accordance with this scoring methodology.&lt;br /&gt;
&lt;br /&gt;
[g] The contractor must have a system security plan (Basic Security Requirement 3.12.4) in place to describe each covered contractor information system, and a plan of action (Basic Security Requirement 3.12.2) in place for each unimplemented security requirement to describe how and when the security requirement will be met.&lt;br /&gt;
# Since the NIST SP 800-171 DoD Assessment scoring methodology is based on the review of a system security plan describing how the security requirements are met, it is not possible to conduct the assessment if the information is not available.  The absence of a system security plan would result in a finding that ‘an assessment could not be completed due to incomplete information and noncompliance with DFARS clause 252.204-7012.’&lt;br /&gt;
# Plans of action addressing unimplemented security requirements are not a substitute for a completed requirement.  Security requirements not implemented, whether a plan of action is in place or not, will be assessed as ‘not implemented.’  For example, if the initial roll-out of 3.5.3, multifactor authentication, is only 75% complete, and there is a plan of action still being implemented, 3.5.3 will be considered ‘not implemented’, as the requirement has not been fully implemented.&lt;br /&gt;
# A lack of plan of action for unimplemented security requirements will result in Security Requirement 3.12.2 being assessed as ‘not implemented.’&lt;br /&gt;
&lt;br /&gt;
[h] Temporary deficiencies and/or isolated enduring exceptions which occur during initial implementation, or arise after implementation, are to be expected in most complex &lt;br /&gt;
environments.&lt;br /&gt;
# Temporary deficiencies that are appropriately addressed in plans of action (i.e., include deficiency reviews, milestones, and show progress towards the implementation of corrections to reduce or eliminate identified vulnerabilities) should be assessed as ‘implemented.’    For example, when a plan of action addresses a ‘temporary deficiency’ that arises after implementation (e.g., 3.13.11, employ FIPS validated cryptography, had been implemented, but subsequently a patch invalidated the FIPS validation of a particular cryptographic module), the requirement will be scored ‘as implemented.’  A ‘temporary deficiency’ may also arise during initial implementation of a NIST SP 800-171 requirement if, during roll-out, specific issues with certain equipment is discovered that has to be separately addressed (e.g., certain specific hardware or software unexpectedly needs to be changed for the requirement to be successfully applied).  If the implementation roll-out has otherwise been completed, this ‘temporary deficiency’ plan of action would be considered, and the requirement scored ‘as implemented.’  There is no standard duration for which a ‘temporary deficiency’ may be active.  It is what is reasonable, which would take into consideration the availability of the solution, the cost and time to implement, the overall risk and whether any mitigations are applied in the interim.  Generally, deficiencies should be resolved as soon as is reasonably possible.&lt;br /&gt;
# Isolated enduring exceptions encountered during implementation, such as unique equipment or environments (e.g., specialized manufacturing equipment or a unique laboratory environment) may prevent the implementation of certain security requirements.  Isolated enduring exceptions are typically not suitable to address in plans of action, but when described, along with any mitigations, in the system security plan such exceptions should be assessed as ‘implemented.’&lt;br /&gt;
&lt;br /&gt;
[i] For certain requirements, questions often arise on whether or not they are actually implemented.  These situations are addressed below:&lt;br /&gt;
# Security Requirements 3.1.12, 3.1.16, 3.1.18:  Companies commonly do not allow remote access, wireless access or connection of mobile devices and may indicate these requirements as ‘Not Applicable’ or ‘Not Implemented’ in the system security plan.  The evaluator should not deduct points in such cases.  However, if the company disallows use of remote, wireless, or mobile access, they should also have a policy and procedure in place to insure these capabilities are not enabled inadvertently.  This should be discussed as part of the Medium Level assessment, and if such policy and procedures are not in place a point should be assessed.&lt;br /&gt;
# Security Requirement 3.13.8:  When implementing this requirement, encryption, though preferred, is not required if using common-carrier provided Multiprotocol Label Switching (MPLS), as the MPLS separation provides sufficient protection without encryption.&lt;br /&gt;
# Security Requirement 3.13.11:  Cryptography used to protect the confidentiality of CUI must be FIPS-validated, which means the cryptographic module has to have been tested and validated to meet FIPS 140-1 or-2 requirements.  Simply using an approved algorithm (e.g., FIPS 197 for AES) is not sufficient - the module (software and/or hardware) used to implement the algorithm must be separately validated under FIPS 140.  Note however, that this is required when encryption is required for protection, which is typically external to the contractor&#039;s covered information system (assuming the system meets NIST SP 800-171).  Cryptography used for other purposes within the protected information system need not be FIPS validated.  When required, if encryption is not employed (FIPS validated or otherwise), 5 points are subtracted from the score of 110.  If encryption is employed, but is not FIPS validated, 3 points are subtracted from the score of 110.  Isolated use of non-FIPS validated cryptography, with an associated Plan of Action, should be treated as a temporary deficiency and assessed as ‘implemented.’&lt;br /&gt;
&lt;br /&gt;
[j] If a contractor received a favorable adjudication from the DoD CIO indicating that a requirement is not applicable or that an alternative security measure is equally effective in accordance with DFARS 252.204-7008 or 7012, the DoD CIO assessment should be included in the Contractor’s system security plan.  Implemented security measures adjudicated by the DoD CIO as equally effective, and security requirements approved by the DoD CIO as ‘not applicable,’ will be assessed as ‘implemented.’  Once DOD CIO assessments approving “not applicable” requirements or “alternative security measures” are included in the Contractor&#039;s system security plan, the contractor does not need to submit that documentation for every current contract with the DFARS 252.204-7012 clause unless specifically requested to do so by the contracting officer.  When completing the Basic (Contractor Self-Assessment) NIST SP 800-171 DoD Assessment Results Format, the contractor shall score any security requirements for which an assessment of “not applicable” or “alternative security measures” was previously approved by DoD CIO as ‘implemented’. &lt;br /&gt;
&lt;br /&gt;
[k] A template illustrating the application of this scoring methodology is provided at Annex A of this document.&lt;br /&gt;
&lt;br /&gt;
[l] DoD will provide medium and high assessment results to the Contractor and offer the opportunity for rebuttal and adjudication of assessment results.   Upon completion of each assessment, the assessed contractor has 14 business days to provide additional information to the assessment team, to demonstrate that they meet any security requirements not observed by the assessment team or to rebut the findings that may be of question.&lt;br /&gt;
&lt;br /&gt;
== Annex A - NIST SP 800-171 DoD Assessment Scoring Template ==&lt;br /&gt;
* The following template illustrates the scoring methodology described in Section 5. If all requirements are met, a score of 110 is awarded.  For each requirement not met, the associated value is subtracted from 110.  Consistency results from the fact that the assessments are based on what is not yet implemented, or document that all requirements have been met.&lt;br /&gt;
* It is important to note an assessment is about the extent to which the company has implemented the requirements.  It is not a value judgement about the specific approach to implementing – in other words, all solutions that meet the requirements are acceptable. This is not an assessment of one solution compared to another.&lt;br /&gt;
* Scoring for Basic, Medium, and High NIST SP 800-171 DoD Assessments is the same.&lt;br /&gt;
* While NIST does not prioritize requirements in terms of impact, certain requirements do have more impact than others.  In this scoring methodology security requirements are weighted based on their effect on the information system and DoD CUI created on or transiting that system.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;margin:auto&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;width: 10%;&amp;quot; | Practice Number&lt;br /&gt;
! style=&amp;quot;width: 60%;&amp;quot; | Practice Requirement&lt;br /&gt;
! style=&amp;quot;width: 5%;&amp;quot; | Value&lt;br /&gt;
! style=&amp;quot;width: 25%;&amp;quot; | Comment&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_AC.L2-3.1.1_Details | 3.1.1]]* || Limit system access to authorized users, processes acting on behalf of authorized users, and devices (including other systems). || 5 ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_AC.L2-3.1.2_Details | 3.1.2]]* || Limit system access to the types of transactions and functions that authorized users are permitted to execute. || 5 ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_AC.L2-3.1.3_Details | 3.1.3]] || Control the flow of CUI in accordance with approved authorizations. || 1 ||&lt;br /&gt;
|-         &lt;br /&gt;
| [[ Practice_AC.L2-3.1.4_Details | 3.1.4]] || Separate the duties of individuals to reduce the risk of malevolent activity without collusion. || 1 ||&lt;br /&gt;
|-&lt;br /&gt;
| [[ Practice_AC.L2-3.1.5_Details | 3.1.5]] || Employ the principle of least privilege, including for specific security functions and privileged accounts. || 3 ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_AC.L2-3.1.6_Details | 3.1.6]] || Use non-privileged accounts or roles when accessing non-security functions. || 1 ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_AC.L2-3.1.7_Details | 3.1.7]] || Prevent non-privileged users from executing privileged functions and capture the execution of such functions in audit logs. || 1 ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_AC.L2-3.1.8_Details | 3.1.8]] || Limit unsuccessful logon attempts. || 1 ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_AC.L2-3.1.9_Details | 3.1.9]] || Provide privacy and security notices consistent with applicable CUI rules. || 1 ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_AC.L2-3.1.10_Details | 3.1.10]] || Use session lock with pattern-hiding displays to prevent access and viewing of data after a period of inactivity. || 1 ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_AC.L2-3.1.11_Details | 3.1.11]] || Terminate (automatically) a user session after a defined condition. || 1 ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_AC.L2-3.1.12_Details | 3.1.12]] || Monitor and control remote access sessions. || 5 || Do not subtract points if remote access not permitted&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_AC.L2-3.1.13_Details | 3.1.13]] || Employ cryptographic mechanisms to protect the confidentiality of remote access sessions. || 5 || Do not subtract points if remote access not permitted&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_AC.L2-3.1.14_Details | 3.1.14]] || Route remote access via managed access control points. || 1 ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_AC.L2-3.1.15_Details | 3.1.15]] || Authorize remote execution of privileged commands and remote access to security-relevant information. || 1 ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_AC.L2-3.1.16_Details | 3.1.16]] || Authorize wireless access prior to allowing such connections. || 5 || Do not subtract points if wireless access not permitted&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_AC.L2-3.1.17_Details | 3.1.17]] || Protect wireless access using authentication and encryption. || 5 || Do not subtract points if wireless access not permitted&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_AC.L2-3.1.18_Details | 3.1.18]] || Control connection of mobile devices. || 5 || Do not subtract points if connection of mobile devices is not permitted&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_AC.L2-3.1.19_Details | 3.1.19]] || Encrypt CUI on mobile devices and mobile computing platforms || 3 || Exposure limited to CUI on mobile platform&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_AC.L2-3.1.20_Details | 3.1.20]]* || Verify and control/limit connections to and use of external systems. || 1 ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_AC.L2-3.1.21_Details | 3.1.21]] || Limit use of portable storage devices on external systems. || 1 ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_AC.L2-3.1.22_Details | 3.1.22]]* || Control CUI posted or processed on publicly accessible systems. || 1 ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_AT.L2-3.2.1_Details | 3.2.1]] || Ensure that managers, systems administrators, and users of organizational systems are made aware of the security risks associated with their activities and of the applicable policies, standards, and procedures related to the security of those systems. || 5 ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_AT.L2-3.2.2_Details | 3.2.2]] || Ensure that personnel are trained to carry out their assigned information security-related duties and responsibilities. || 5 ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_AT.L2-3.2.3_Details | 3.2.3]] || Provide security awareness training on recognizing and reporting potential indicators of insider threat. || 1 ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_AU.L2-3.3.1_Details | 3.3.1]] || Create and retain system audit logs and records to the extent needed to enable the monitoring, analysis, investigation, and reporting of unlawful or unauthorized system activity. || 5 ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_AU.L2-3.3.2_Details | 3.3.2]] || Ensure that the actions of individual system users can be uniquely traced to those users so they can be held accountable for their actions. || 3 ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_AU.L2-3.3.3_Details | 3.3.3]] || Review and update logged events. || 1 ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_AU.L2-3.3.4_Details | 3.3.4]] || Alert in the event of an audit logging process failure. || 1 ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_AU.L2-3.3.5_Details | 3.3.5]] || Correlate audit record review, analysis, and reporting processes for investigation and response to indications of unlawful, unauthorized, suspicious, or unusual activity. || 5 ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_AU.L2-3.3.6_Details | 3.3.6]] || Provide audit record reduction and report generation to support on-demand analysis and reporting. || 1 ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_AU.L2-3.3.7_Details | 3.3.7]] || Provide a system capability that compares and synchronizes internal system clocks with an authoritative source to generate time stamps for audit records. || 1 ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_AU.L2-3.3.8_Details | 3.3.8]] || Protect audit information and audit logging tools from unauthorized access, modification, and deletion. || 1 ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_AU.L2-3.3.9_Details | 3.3.9]] || Limit management of audit logging functionality to a subset of privileged users. || 1 ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_CM.L2-3.4.1_Details | 3.4.1]] || Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles.  || 5 ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_CM.L2-3.4.2_Details | 3.4.2]] || Establish and enforce security configuration settings for information technology products employed in organizational systems. || 5 ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_CM.L2-3.4.3_Details | 3.4.3]] || Track, review, approve or disapprove, and log changes to organizational systems. || 1 ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_CM.L2-3.4.4_Details | 3.4.4]] || Analyze the security impact of changes prior to implementation. || 1 ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_CM.L2-3.4.5_Details | 3.4.5]] || Define, document, approve, and enforce physical and logical access restrictions associated with changes to organizational systems. || 5 ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_CM.L2-3.4.6_Details | 3.4.6]] || Employ the principle of least functionality by configuring organizational systems to provide only essential capabilities. || 5 ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_CM.L2-3.4.7_Details | 3.4.7]] || Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services. || 5 ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_CM.L2-3.4.8_Details | 3.4.8]] || Apply deny-by-exception (blacklisting) policy to prevent the use of unauthorized software or deny-all, permit-by-exception (whitelisting) policy to allow the execution of authorized software. || 5 ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_CM.L2-3.4.9_Details | 3.4.9]] || Control and monitor user-installed software. || 1 ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_IA.L1-3.5.1_Details | 3.5.1]]* || Identify system users, processes acting on behalf of users, and devices. || 5 ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_IA.L1-3.5.2_Details | 3.5.2]]* || Authenticate (or verify) the identities of users, processes, or devices, as a prerequisite to allowing access to organizational systems. || 5 ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_IA.L2-3.5.3_Details | 3.5.3]] || Use multifactor authentication (MFA) for local and network access to privileged accounts and for network access to non-privileged accounts. || 5/3 || Subtract 5 points if MFA not implemented.  Subtract 3 points if implemented for remote and privileged users, but not the general user&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_IA.L2-3.5.4_Details | 3.5.4]] || Employ replay-resistant authentication mechanisms for network access to privileged and non-privileged accounts. || 1 ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_IA.L2-3.5.5_Details | 3.5.5]] || Prevent reuse of identifiers for a defined period. || 1 ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_IA.L2-3.5.6_Details | 3.5.6]] || Disable identifiers after a defined period of inactivity. || 1 ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_IA.L2-3.5.7_Details | 3.5.7]] || Enforce a minimum password complexity and change of characters when new passwords are created. || 1 ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_IA.L2-3.5.8_Details | 3.5.8]] || Prohibit password reuse for a specified number of generations. || 1 ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_IA.L2-3.5.9_Details | 3.5.9]] || Allow temporary password use for system logons with an immediate change to a permanent password. || 1 ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_IA.L2-3.5.10_Details | 3.5.10]] || Store and transmit only cryptographically-protected passwords. || 5 || Encrypted representations of passwords include, for example, encrypted versions of passwords and one-way cryptographic hashes of passwords&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_IA.L2-3.5.11_Details | 3.5.11]] || Obscure feedback of authentication information. || 1 ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_IR.L2-3.6.1_Details | 3.6.1]] || Establish an operational incident-handling capability for organizational systems that includes preparation, detection, analysis, containment, recovery, and user response activities. || 5 ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_IR.L2-3.6.2_Details | 3.6.2]] || Track, document, and report incidents to designated officials and/or authorities both internal and external to the organization. || 5 ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_IR.L2-3.6.3_Details | 3.6.3]] || Test the organizational incident response capability. || 1 ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_MA.L2-3.7.1_Details | 3.7.1]] || Perform maintenance on organizational systems. || 3 ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_MA.L2-3.7.2_Details | 3.7.2]] || Provide controls on the tools, techniques, mechanisms, and personnel used to conduct system maintenance. || 5 ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_MA.L2-3.7.3_Details | 3.7.3]] || Ensure equipment removed for off-site maintenance is sanitized of any CUI. || 1 ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_MA.L2-3.7.4_Details | 3.7.4]] || Check media containing diagnostic and test programs for malicious code before the media are used in organizational systems. || 3 ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_MA.L2-3.7.5_Details | 3.7.5]] || Require multifactor authentication to establish nonlocal maintenance sessions via external network connections and terminate such connections when nonlocal maintenance is complete. || 5 ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_MA.L2-3.7.6_Details | 3.7.6]] || Supervise the maintenance activities of maintenance personnel without required access authorization. || 1 ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_MP.L2-3.8.1_Details | 3.8.1]] || Protect (i.e., physically control and securely store) system media containing CUI, both paper and digital. || 3 || Exposure limited to CUI on media&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_MP.L2-3.8.2_Details | 3.8.2]] || Limit access to CUI on system media to authorized users. || 3 || Exposure limited to CUI on media&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_MP.L1-3.8.3_Details | 3.8.3]]* || Sanitize or destroy system media containing CUI before disposal or release for reuse. || 5 || While exposure limited to CUI on media, failure to sanitize can result in continual exposure of CUI&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_MP.L2-3.8.4_Details | 3.8.4]] || Mark media with necessary CUI markings and distribution limitations. || 1 ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_MP.L2-3.8.5_Details | 3.8.5]] || Control access to media containing CUI and maintain accountability for media during transport outside of controlled areas. || 1 ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_MP.L2-3.8.6_Details | 3.8.6]] || Implement cryptographic mechanisms to protect the confidentiality of CUI stored on digital media during transport unless otherwise protected by alternative physical safeguards. || 1 ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_MP.L2-3.8.7_Details | 3.8.7]] || Control the use of removable media on system components. || 5 ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_MP.L2-3.8.8_Details | 3.8.8]] || Prohibit the use of portable storage devices when such devices have no identifiable owner. || 3 ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_MP.L2-3.8.9_Details | 3.8.9]] || Protect the confidentiality of backup CUI at storage locations. || 1 ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_PS.L2-3.9.1_Details | 3.9.1]] || Screen individuals prior to authorizing access to organizational systems containing CUI. || 3 ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_PS.L2-3.9.2_Details | 3.9.2]] || Ensure that organizational systems containing CUI are protected during and after personnel actions such as terminations and transfers. || 5 ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_PE.L1-3.10.1_Details | 3.10.1]]* || Limit physical access to organizational systems, equipment, and the respective operating environments to authorized individuals. || 5 ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_PE.L2-3.10.2_Details | 3.10.2]] || Protect and monitor the physical facility and support infrastructure for organizational systems. || 5 ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_PE.L1-3.10.3_Details | 3.10.3]]* || Escort visitors and monitor visitor activity. || 1 ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_PE.L1-3.10.4_Details | 3.10.4]]* || Maintain audit logs of physical access. || 1 ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_PE.L1-3.10.5_Details | 3.10.5]]* || Control and manage physical access devices. || 1 ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_PE.L2-3.10.6_Details | 3.10.6]] || Enforce safeguarding measures for CUI at alternate work sites. || 1 ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_RA.L2-3.11.1_Details | 3.11.1]] || Periodically assess the risk to organizational operations (including mission, functions, image, or reputation), organizational assets, and individuals, resulting from the operation of organizational systems and the associated processing, storage, or transmission of CUI. || 3 ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_RA.L2-3.11.2_Details | 3.11.2]] || Scan for vulnerabilities in organizational systems and applications periodically and when new vulnerabilities affecting those systems and applications are identified. || 5 ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_RA.L2-3.11.3_Details | 3.11.3]] || Remediate vulnerabilities in accordance with risk assessments. || 1 ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_CA.L2-3.12.1_Details | 3.12.1]] || Periodically assess the security controls in organizational systems to determine if the controls are effective in their application. || 5 ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_CA.L2-3.12.2_Details | 3.12.2]] || Develop and implement plans of action designed to correct deficiencies and reduce or eliminate vulnerabilities in organizational systems. || 3 ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_CA.L2-3.12.3_Details | 3.12.3]] || Monitor security controls on an ongoing basis to ensure the continued effectiveness of the controls. || 5 ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_CA.L2-3.12.4_Details | 3.12.4]] || Develop, document, and periodically update system security plans that describe system boundaries, system environments of operation, how security requirements are implemented, and the relationships with or connections to other systems. || NA || The absence of a system security plan would result in a finding that ‘an assessment could not be completed due to incomplete information and noncompliance with DFARS clause 252.204-7012.’&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_SC.L1-3.13.1_Details | 3.13.1]]* || Monitor, control, and protect communications (i.e., information transmitted or received by organizational systems) at the external boundaries and key internal boundaries of organizational systems. || 5 ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_SC.L2-3.13.2_Details | 3.13.2]] || Employ architectural designs, software development techniques, and systems engineering principles that promote effective information security within organizational systems. || 5 ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_SC.L2-3.13.3_Details | 3.13.3]] || Separate user functionality from system management functionality. || 1 ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_SC.L2-3.13.4_Details | 3.13.4]] || Prevent unauthorized and unintended information transfer via shared system resources. || 1 ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_SC.L1-3.13.5_Details | 3.13.5]]* || Implement subnetworks for publicly accessible system components that are physically or logically separated from internal networks. || 5 ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_SC.L2-3.13.6_Details | 3.13.6]] || Deny network communications traffic by default and allow network communications traffic by exception (i.e., deny all, permit by exception). || 5 ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_SC.L2-3.13.7_Details | 3.13.7]] || Prevent remote devices from simultaneously establishing non-remote connections with organizational systems and communicating via some other connection to resources in external networks (i.e., split tunneling). || 1 ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_SC.L2-3.13.8_Details | 3.13.8]] || Implement cryptographic mechanisms to prevent unauthorized disclosure of CUI during transmission unless otherwise protected by alternative physical safeguards. || 3 ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_SC.L2-3.13.9_Details | 3.13.9]] || Terminate network connections associated with communications sessions at the end of the sessions or after a defined period of inactivity. || 1 ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_SC.L2-3.13.10_Details | 3.13.10]] || Establish and manage cryptographic keys for cryptography employed in organizational systems. || 1 ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_SC.L2-3.13.11_Details | 3.13.11]] || Employ FIPS-validated cryptography when used to protect the confidentiality of CUI. || 5/3 || Subtract 5 points if no cryptography is employed; 3 points if mostly not FIPS validated&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_SC.L2-3.13.12_Details | 3.13.12]] || Prohibit remote activation of collaborative computing devices and provide indication of devices in use to users present at the device. || 1 ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_SC.L2-3.13.13_Details | 3.13.13]] || Control and monitor the use of mobile code. || 1 ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_SC.L2-3.13.14_Details | 3.13.14]] || Control and monitor the use of Voice over Internet Protocol (VoIP) technologies. || 1 ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_SC.L2-3.13.15_Details | 3.13.15]] || Protect the authenticity of communications sessions. || 5 ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_SC.L2-3.13.16_Details | 3.13.16]] || Protect the confidentiality of CUI at rest. || 1 ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_SI.L1-3.14.1_Details | 3.14.1]]* || Identify, report, and correct system flaws in a timely manner. || 5 ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_SI.L1-3.14.2_Details | 3.14.2]]* || Provide protection from malicious code at designated locations within organizational systems. || 5 ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_SI.L2-3.14.3_Details | 3.14.3]] || Monitor system security alerts and advisories and take action in response. || 5 ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_SI.L1-3.14.4_Details | 3.14.4]]* || Update malicious code protection mechanisms when new releases are available. || 5 ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_SI.L1-3.14.5_Details | 3.14.5]]* || Perform periodic scans of organizational systems and real-time scans of files from external sources as files are downloaded, opened, or executed. || 3 ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_SI.L2-3.14.6_Details | 3.14.6]] || Monitor organizational systems, including inbound and outbound communications traffic, to detect attacks and indicators of potential attacks. || 5 ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_SI.L2-3.14.7_Details | 3.14.7]] || Identify unauthorized use of organizational systems. || 3 ||&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;* Basic safeguarding requirements and procedures to protect covered contractor information systems per Federal Acquisition Regulation (FAR) clause 52.204-21, Basic Safeguarding of Covered Contractor Information Systems.&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
== DoD Assessment Scoring (Value 5) ==&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;margin:auto&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;width: 10%;&amp;quot; | Practice Number&lt;br /&gt;
! style=&amp;quot;width: 60%;&amp;quot; | Practice Requirement&lt;br /&gt;
! style=&amp;quot;width: 5%;&amp;quot; | Value&lt;br /&gt;
! style=&amp;quot;width: 25%;&amp;quot; | Comment&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_AC.L2-3.1.1_Details | 3.1.1]] || Limit system access to authorized users, processes acting on behalf of authorized users, and devices (including other systems). || 5 ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_AC.L2-3.1.2_Details | 3.1.2]] || Limit system access to the types of transactions and functions that authorized users are permitted to execute. || 5 ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_AC.L2-3.1.12_Details | 3.1.12]] || Monitor and control remote access sessions. || 5 || Do not subtract points if remote access not permitted&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_AC.L2-3.1.13_Details | 3.1.13]] || Employ cryptographic mechanisms to protect the confidentiality of remote access sessions. || 5 || Do not subtract points if remote access not permitted&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_AC.L2-3.1.16_Details | 3.1.16]] || Authorize wireless access prior to allowing such connections. || 5 || Do not subtract points if wireless access not permitted&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_AC.L2-3.1.17_Details | 3.1.17]] || Protect wireless access using authentication and encryption. || 5 || Do not subtract points if wireless access not permitted&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_AC.L2-3.1.18_Details | 3.1.18]] || Control connection of mobile devices. || 5 || Do not subtract points if connection of mobile devices is not permitted&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_AT.L2-3.2.1_Details | 3.2.1]] || Ensure that managers, systems administrators, and users of organizational systems are made aware of the security risks associated with their activities and of the applicable policies, standards, and procedures related to the security of those systems. || 5 ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_AT.L2-3.2.2_Details | 3.2.2]] || Ensure that personnel are trained to carry out their assigned information security-related duties and responsibilities. || 5 ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_AU.L2-3.3.1_Details | 3.3.1]] || Create and retain system audit logs and records to the extent needed to enable the monitoring, analysis, investigation, and reporting of unlawful or unauthorized system activity. || 5 ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_AU.L2-3.3.5_Details | 3.3.5]] || Correlate audit record review, analysis, and reporting processes for investigation and response to indications of unlawful, unauthorized, suspicious, or unusual activity. || 5 ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_CM.L2-3.4.1_Details | 3.4.1]] || Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles.  || 5 ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_CM.L2-3.4.2_Details | 3.4.2]] || Establish and enforce security configuration settings for information technology products employed in organizational systems. || 5 ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_CM.L2-3.4.5_Details | 3.4.5]] || Define, document, approve, and enforce physical and logical access restrictions associated with changes to organizational systems. || 5 ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_CM.L2-3.4.6_Details | 3.4.6]] || Employ the principle of least functionality by configuring organizational systems to provide only essential capabilities. || 5 ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_CM.L2-3.4.7_Details | 3.4.7]] || Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services. || 5 ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_CM.L2-3.4.8_Details | 3.4.8]] || Apply deny-by-exception (blacklisting) policy to prevent the use of unauthorized software or deny-all, permit-by-exception (whitelisting) policy to allow the execution of authorized software. || 5 ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_IA.L1-3.5.1_Details | 3.5.1]] || Identify system users, processes acting on behalf of users, and devices. || 5 ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_IA.L1-3.5.2_Details | 3.5.2]] || Authenticate (or verify) the identities of users, processes, or devices, as a prerequisite to allowing access to organizational systems. || 5 ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_IA.L2-3.5.3_Details | 3.5.3]] || Use multifactor authentication (MFA) for local and network access to privileged accounts and for network access to non-privileged accounts. || 5/3 || Subtract 5 points if MFA not implemented. Subtract 3 points if implemented for remote and privileged users, but not the general user&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_IA.L2-3.5.10_Details | 3.5.10]] || Store and transmit only cryptographically-protected passwords. || 5 || Encrypted representations of passwords include, for example, encrypted versions of passwords and one-way cryptographic hashes of passwords&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_IR.L2-3.6.1_Details | 3.6.1]] || Establish an operational incident-handling capability for organizational systems that includes preparation, detection, analysis, containment, recovery, and user response activities. || 5 ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_IR.L2-3.6.2_Details | 3.6.2]] || Track, document, and report incidents to designated officials and/or authorities both internal and external to the organization. || 5 ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_MA.L2-3.7.2_Details | 3.7.2]] || Provide controls on the tools, techniques, mechanisms, and personnel used to conduct system maintenance. || 5 ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_MA.L2-3.7.5_Details | 3.7.5]] || Require multifactor authentication to establish nonlocal maintenance sessions via external network connections and terminate such connections when nonlocal maintenance is complete. || 5 ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_MP.L1-3.8.3_Details | 3.8.3]] || Sanitize or destroy system media containing CUI before disposal or release for reuse. || 5 || While exposure limited to CUI on media, failure to sanitize can result in continual exposure of CUI&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_MP.L2-3.8.7_Details | 3.8.7]] || Control the use of removable media on system components. || 5 ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_PS.L2-3.9.2_Details | 3.9.2]] || Ensure that organizational systems containing CUI are protected during and after personnel actions such as terminations and transfers. || 5 ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_PE.L1-3.10.1_Details | 3.10.1]] || Limit physical access to organizational systems, equipment, and the respective operating environments to authorized individuals. || 5 ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_PE.L2-3.10.2_Details | 3.10.2]] || Protect and monitor the physical facility and support infrastructure for organizational systems. || 5 ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_RA.L2-3.11.2_Details | 3.11.2]] || Scan for vulnerabilities in organizational systems and applications periodically and when new vulnerabilities affecting those systems and applications are identified. || 5 ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_CA.L2-3.12.1_Details | 3.12.1]] || Periodically assess the security controls in organizational systems to determine if the controls are effective in their application. || 5 ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_CA.L2-3.12.3_Details | 3.12.3]] || Monitor security controls on an ongoing basis to ensure the continued effectiveness of the controls. || 5 ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_SC.L1-3.13.1_Details | 3.13.1]] || Monitor, control, and protect communications (i.e., information transmitted or received by organizational systems) at the external boundaries and key internal boundaries of organizational systems. || 5 ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_SC.L2-3.13.2_Details | 3.13.2]] || Employ architectural designs, software development techniques, and systems engineering principles that promote effective information security within organizational systems. || 5 ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_SC.L1-3.13.5_Details | 3.13.5]] || Implement subnetworks for publicly accessible system components that are physically or logically separated from internal networks. || 5 ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_SC.L2-3.13.6_Details | 3.13.6]] || Deny network communications traffic by default and allow network communications traffic by exception (i.e., deny all, permit by exception). || 5 ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_SC.L2-3.13.11_Details | 3.13.11]] || Employ FIPS-validated cryptography when used to protect the confidentiality of CUI. || 5/3 || Subtract 5 points if no cryptography is employed; 3 points if mostly not FIPS validated&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_SC.L2-3.13.15_Details | 3.13.15]] || Protect the authenticity of communications sessions. || 5 ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_SI.L1-3.14.1_Details | 3.14.1]] || Identify, report, and correct system flaws in a timely manner. || 5 ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_SI.L1-3.14.2_Details | 3.14.2]] || Provide protection from malicious code at designated locations within organizational systems. || 5 ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_SI.L2-3.14.3_Details | 3.14.3]] || Monitor system security alerts and advisories and take action in response. || 5 ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_SI.L1-3.14.4_Details | 3.14.4]] || Update malicious code protection mechanisms when new releases are available. || 5 ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_SI.L2-3.14.6_Details | 3.14.6]] || Monitor organizational systems, including inbound and outbound communications traffic, to detect attacks and indicators of potential attacks. || 5 ||&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== DoD Assessment Scoring (Value 3) ==&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;margin:auto&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;width: 10%;&amp;quot; | Practice Number&lt;br /&gt;
! style=&amp;quot;width: 60%;&amp;quot; | Practice Requirement&lt;br /&gt;
! style=&amp;quot;width: 5%;&amp;quot; | Value&lt;br /&gt;
! style=&amp;quot;width: 25%;&amp;quot; | Comment&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_AC.L2-3.1.5_Details | 3.1.5]] || Employ the principle of least privilege, including for specific security functions and privileged accounts. || 3 ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_AC.L2-3.1.19_Details | 3.1.19]] || Encrypt CUI on mobile devices and mobile computing platforms || 3 || Exposure limited to CUI on mobile platform&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_AU.L2-3.3.2_Details | 3.3.2]] || Ensure that the actions of individual system users can be uniquely traced to those users so they can be held accountable for their actions. || 3 ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_MA.L2-3.7.1_Details | 3.7.1]] || Perform maintenance on organizational systems. || 3 ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_MA.L2-3.7.4_Details | 3.7.4]] || Check media containing diagnostic and test programs for malicious code before the media are used in organizational systems. || 3 ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_MP.L2-3.8.1_Details | 3.8.1]] || Protect (i.e., physically control and securely store) system media containing CUI, both paper and digital. || 3 || Exposure limited to CUI on media&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_MP.L2-3.8.2_Details | 3.8.2]] || Limit access to CUI on system media to authorized users. || 3 || Exposure limited to CUI on media&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_MP.L2-3.8.8_Details | 3.8.8]] || Prohibit the use of portable storage devices when such devices have no identifiable owner. || 3 ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_PS.L2-3.9.1_Details | 3.9.1]] || Screen individuals prior to authorizing access to organizational systems containing CUI. || 3 ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_RA.L2-3.11.1_Details | 3.11.1]] || Periodically assess the risk to organizational operations (including mission, functions, image, or reputation), organizational assets, and individuals, resulting from the operation of organizational systems and the associated processing, storage, or transmission of CUI. || 3 ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_CA.L2-3.12.2_Details | 3.12.2]] || Develop and implement plans of action designed to correct deficiencies and reduce or eliminate vulnerabilities in organizational systems. || 3 ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_SC.L2-3.13.8_Details | 3.13.8]] || Implement cryptographic mechanisms to prevent unauthorized disclosure of CUI during transmission unless otherwise protected by alternative physical safeguards. || 3 ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_SI.L1-3.14.5_Details | 3.14.5]] || Perform periodic scans of organizational systems and real-time scans of files from external sources as files are downloaded, opened, or executed. || 3 ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_SI.L2-3.14.7_Details | 3.14.7]] || Identify unauthorized use of organizational systems. || 3 ||&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== DoD Assessment Scoring (Value 1) ==&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;margin:auto&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;width: 10%;&amp;quot; | Practice Number&lt;br /&gt;
! style=&amp;quot;width: 60%;&amp;quot; | Practice Requirement&lt;br /&gt;
! style=&amp;quot;width: 5%;&amp;quot; | Value&lt;br /&gt;
! style=&amp;quot;width: 25%;&amp;quot; | Comment&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_AC.L2-3.1.3_Details | 3.1.3]] || Control the flow of CUI in accordance with approved authorizations. || 1 ||&lt;br /&gt;
|-         &lt;br /&gt;
| [[Practice_AC.L2-3.1.4_Details | 3.1.4]] || Separate the duties of individuals to reduce the risk of malevolent activity without collusion. || 1 ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_AC.L2-3.1.6_Details | 3.1.6]] || Use non-privileged accounts or roles when accessing non-security functions. || 1 ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_AC.L2-3.1.7_Details | 3.1.7]] || Prevent non-privileged users from executing privileged functions and capture the execution of such functions in audit logs. || 1 ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_AC.L2-3.1.8_Details | 3.1.8]] || Limit unsuccessful logon attempts. || 1 ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_AC.L2-3.1.9_Details | 3.1.9]] || Provide privacy and security notices consistent with applicable CUI rules. || 1 ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_AC.L2-3.1.10_Details | 3.1.10]] || Use session lock with pattern-hiding displays to prevent access and viewing of data after a period of inactivity. || 1 ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_AC.L2-3.1.11_Details | 3.1.11]] || Terminate (automatically) a user session after a defined condition. || 1 ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_AC.L2-3.1.14_Details | 3.1.14]] || Route remote access via managed access control points. || 1 ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_AC.L2-3.1.15_Details | 3.1.15]] || Authorize remote execution of privileged commands and remote access to security-relevant information. || 1 ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_AC.L1-3.1.20_Details | 3.1.20]] || Verify and control/limit connections to and use of external systems. || 1 ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_AC.L2-3.1.21_Details | 3.1.21]] || Limit use of portable storage devices on external systems. || 1 ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_AC.L1-3.1.22_Details | 3.1.22]] || Control CUI posted or processed on publicly accessible systems. || 1 ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_AT.L2-3.2.3_Details | 3.2.3]] || Provide security awareness training on recognizing and reporting potential indicators of insider threat. || 1 ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_AU.L2-3.3.3_Details | 3.3.3]] || Review and update logged events. || 1 ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_AU.L2-3.3.4_Details | 3.3.4]] || Alert in the event of an audit logging process failure. || 1 ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_AU.L2-3.3.6_Details | 3.3.6]] || Provide audit record reduction and report generation to support on-demand analysis and reporting. || 1 ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_AU.L2-3.3.7_Details | 3.3.7]] || Provide a system capability that compares and synchronizes internal system clocks with an authoritative source to generate time stamps for audit records. || 1 ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_AU.L2-3.3.8_Details | 3.3.8]] || Protect audit information and audit logging tools from unauthorized access, modification, and deletion. || 1 ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_AU.L2-3.3.9_Details | 3.3.9]] || Limit management of audit logging functionality to a subset of privileged users. || 1 ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_CM.L2-3.4.3_Details | 3.4.3]] || Track, review, approve or disapprove, and log changes to organizational systems. || 1 ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_CM.L2-3.4.4_Details | 3.4.4]] || Analyze the security impact of changes prior to implementation. || 1 ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_CM.L2-3.4.9_Details | 3.4.9]] || Control and monitor user-installed software. || 1 ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_IA.L2-3.5.4_Details | 3.5.4]] || Employ replay-resistant authentication mechanisms for network access to privileged and non-privileged accounts. || 1 ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_IA.L2-3.5.5_Details | 3.5.5]] || Prevent reuse of identifiers for a defined period. || 1 ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_IA.L2-3.5.6_Details | 3.5.6]] || Disable identifiers after a defined period of inactivity. || 1 ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_IA.L2-3.5.7_Details | 3.5.7]] || Enforce a minimum password complexity and change of characters when new passwords are created. || 1 ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_IA.L2-3.5.8_Details | 3.5.8]] || Prohibit password reuse for a specified number of generations. || 1 ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_IA.L2-3.5.9_Details | 3.5.9]] || Allow temporary password use for system logons with an immediate change to a permanent password. || 1 ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_IA.L2-3.5.11_Details | 3.5.11]] || Obscure feedback of authentication information. || 1 ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_IR.L2-3.6.3_Details | 3.6.3]] || Test the organizational incident response capability. || 1 ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_MA.L2-3.7.3_Details | 3.7.3]] || Ensure equipment removed for off-site maintenance is sanitized of any CUI. || 1 ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_MA.L2-3.7.6_Details | 3.7.6]] || Supervise the maintenance activities of maintenance personnel without required access authorization. || 1 ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_MP.L2-3.8.4_Details | 3.8.4]] || Mark media with necessary CUI markings and distribution limitations. || 1 ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_MP.L2-3.8.5_Details | 3.8.5]] || Control access to media containing CUI and maintain accountability for media during transport outside of controlled areas. || 1 ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_MP.L2-3.8.6_Details | 3.8.6]] || Implement cryptographic mechanisms to protect the confidentiality of CUI stored on digital media during transport unless otherwise protected by alternative physical safeguards. || 1 ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_MP.L2-3.8.9_Details | 3.8.9]] || Protect the confidentiality of backup CUI at storage locations. || 1 ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_PE.L1-3.10.3_Details | 3.10.3]] || Escort visitors and monitor visitor activity. || 1 ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_PE.L1-3.10.4_Details | 3.10.4]] || Maintain audit logs of physical access. || 1 ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_PE.L1-3.10.5_Details | 3.10.5]] || Control and manage physical access devices. || 1 ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_PE.L2-3.10.6_Details | 3.10.6]] || Enforce safeguarding measures for CUI at alternate work sites. || 1 ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_RA.L2-3.11.3_Details | 3.11.3]] || Remediate vulnerabilities in accordance with risk assessments. || 1 ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_CA.L2-3.12.4_Details | 3.12.4]] || Develop, document, and periodically update system security plans that describe system boundaries, system environments of operation, how security requirements are implemented, and the relationships with or connections to other systems. || NA || The absence of a system security plan would result in a finding that ‘an assessment could not be completed due to incomplete information and noncompliance with DFARS clause 252.204-7012.’&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_SC.L2-3.13.3_Details | 3.13.3]] || Separate user functionality from system management functionality. || 1 ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_SC.L2-3.13.4_Details | 3.13.4]] || Prevent unauthorized and unintended information transfer via shared system resources. || 1 ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_SC.L2-3.13.7_Details | 3.13.7]] || Prevent remote devices from simultaneously establishing non-remote connections with organizational systems and communicating via some other connection to resources in external networks (i.e., split tunneling). || 1 ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_SC.L2-3.13.9_Details | 3.13.9]] || Terminate network connections associated with communications sessions at the end of the sessions or after a defined period of inactivity. || 1 ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_SC.L2-3.13.10_Details | 3.13.10]] || Establish and manage cryptographic keys for cryptography employed in organizational systems. || 1 ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_SC.L2-3.13.12_Details | 3.13.12]] || Prohibit remote activation of collaborative computing devices and provide indication of devices in use to users present at the device. || 1 ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_SC.L2-3.13.13_Details | 3.13.13]] || Control and monitor the use of mobile code. || 1 ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_SC.L2-3.13.14_Details | 3.13.14]] || Control and monitor the use of Voice over Internet Protocol (VoIP) technologies. || 1 ||&lt;br /&gt;
|-&lt;br /&gt;
| [[Practice_SC.L2-3.13.16_Details | 3.13.16]] || Protect the confidentiality of CUI at rest. || 1 ||&lt;br /&gt;
|}&lt;/div&gt;</summary>
		<author><name>David</name></author>
	</entry>
	<entry>
		<id>https://cmmcwiki.org/index.php?title=CMMC_Assessment_Process&amp;diff=1595</id>
		<title>CMMC Assessment Process</title>
		<link rel="alternate" type="text/html" href="https://cmmcwiki.org/index.php?title=CMMC_Assessment_Process&amp;diff=1595"/>
		<updated>2026-03-02T01:31:14Z</updated>

		<summary type="html">&lt;p&gt;David: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&#039;&#039;&#039;Source of Reference: The [https://cyberab.org/Portals/0/CMMC%20Assessment%20Process%20v2.0.pdf?ver=fEk1pUK1Fg26fVtopxv_DA%3d%3d CMMC Assessment Process Version 2.0 document] from [https://cyberab.org/ Cybersecurity Maturity Model Certification Accreditation Body, Inc.]&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
For inquiries and reporting errors on this wiki, please [mailto:support@cmmcwiki.org contact us]. Thank you.&lt;br /&gt;
&lt;br /&gt;
== DISCLAIMER ==&lt;br /&gt;
Copyright 2024 © Cybersecurity Maturity Model Certification Accreditation Body, Inc. (d/b/a The Cyber AB)  &lt;br /&gt;
&lt;br /&gt;
The views, opinions, and/or findings contained in this material are those of the author(s) and should not be construed as an official U.S. Government position, policy, or decision, unless designated by other documentation.  &lt;br /&gt;
&lt;br /&gt;
Nothing contained in this document supersedes any standard, policy, direction, or official CMMC program information that has been promulgated by the United States Department of Defense (DoD) or the National Institute of Standards and Technology (NIST). In the event of a contradiction, real or perceived, the reader should adhere to the DoD and/or NIST documentation.  &lt;br /&gt;
&lt;br /&gt;
NO WARRANTIES ARE MADE HEREIN. THIS MATERIAL IS FURNISHED ON AN &amp;quot;AS-IS&amp;quot; BASIS. THE CMMC ACCREDITATION BODY, INC. MAKES NO WARRANTIES OF ANY KIND, EITHER EXPRESSED OR IMPLIED, AS TO  ANY  MATTER  INCLUDING,  BUT  NOT  LIMITED  TO,  WARRANTY  OF  FITNESS  FOR  PURPOSE  OR MERCHANTABILITY, EXCLUSIVITY OR RESULTS OBTAINED FROM USE OF THE MATERIAL, NOR ANY WARRANTY OF ANY KIND WITH RESPECT TO FREEDOM FROM PATENT, TRADEMARK, or COPYRIGHT INFRINGEMENT.  &lt;br /&gt;
&lt;br /&gt;
Comments on this DRAFT CAP v2.0 are welcomed from all members of the CMMC Ecosystem, the DIB, and the public. This feedback will be used to improve the document and may help inform the publication of future editions of the CAP. Feedback can be submitted via the email address CAPComments@cyberab.org.&lt;br /&gt;
&lt;br /&gt;
== Introduction to the CMMC Assessment Process (CAP) ==&lt;br /&gt;
The Cybersecurity Maturity Model Certification (CMMC) Program is the U.S. Department of Defense’s (DoD) initiative for the assessment and certification of conformance to established security requirements by companies and organizations within the Defense Industrial Base (DIB).&amp;lt;ref&amp;gt;Specifically, CMMC assesses conformance to the Defense Federal Acquisition Regulation Supplement (DFARS) clause 252-204-7021, “Assessing Contractor Implementation of Cybersecurity Requirements”.&amp;lt;/ref&amp;gt; Specifically, CMMC is designed to safeguard Controlled Unclassified Information (CUI) and Federal Contract Information (FCI) that is processed, stored, and/or transmitted during the performance of DoD contracts.  &lt;br /&gt;
&lt;br /&gt;
The CMMC Program is overseen by the Office of the DoD Chief Information Officer (ODCIO) and administered by the CMMC Program Management Office (CMMC PMO). The Cyber AB is the designated sole Accreditation Body for the CMMC Program. The Cyber AB supports the CMMC Program through a no- cost contract with DoD’s Washington Headquarters Services (WHS).&amp;lt;ref&amp;gt;The Cyber AB is the “doing business as (d/b/a)” name for the Cybersecurity Maturity Model Certification Accreditation Body, Inc., an &lt;br /&gt;
independent, tax-exempt 501(c)(3) charitable organization that supports the Department of Defense’s CMMC Program via a no-cost contract (Department of Defense contract #HQ003420H0003)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Most of the official CMMC doctrine and documentation is provided within the Code of Federal Regulations (CFR) or by DoD and the National Institute of Standards and Technology (NIST) within the Department of Commerce. For example, the actual CMMC Level 2 security requirements themselves are codified within the NIST Special Publication 800-171, Revision 2 (NIST SP 800-171 R2), “Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations”. The CMMC Scoping Guides and Assessment Guides that are developed, maintained, and published by DoD provide supplemental guidance and insight consistent with authoritative references for establishing the assessment boundaries as well as for evaluating the implementation of CMMC security requirements, respectively. &lt;br /&gt;
&lt;br /&gt;
The CMMC Assessment Process (CAP), by comparison, is the official procedural guide for CMMC Third- Party Assessment Organizations (C3PAOs) conducting a CMMC Level 2 certification assessment (herein also referred to as an “assessment”) of an Organization Seeking Certification (OSC). The CAP is published and maintained by The Cyber AB and reviewed and approved by the CMMC PMO. It is intended as a resource for the entire CMMC Ecosystem, as well as for companies and organizations within the DIB. &lt;br /&gt;
&lt;br /&gt;
The purpose of the CAP is to ensure the consistency and integrity of CMMC Level 2 certification assessments. Adherence to the CAP is required by C3PAOs and their CMMC Certified Assessors (CCAs) and is an element of the C3PAO Accreditation Scheme. The CAP is not to be confused with references to a generalized CMMC “assessment process” that appear in the Code of Federal Regulations (CFR), Title 32, part 170.  &lt;br /&gt;
&lt;br /&gt;
=== How to Use the CAP ===&lt;br /&gt;
The CAP applies only to the conduct of CMMC Level 2 certification assessments. &lt;br /&gt;
&lt;br /&gt;
The CAP must be used in concert with the authoritative CMMC source material—32 CFR part 170 and those documents included by reference therein—as well as the supplemental CMMC guidance published by DoD. It neither replaces nor supersedes any requirements or directions contained in those documents. Moreover, the CAP does not reproduce nor reinterpret any of the rules, provisions, or procedures from either authoritative references or DoD supplemental guidance. Rather, it cites and references those documents throughout. Accordingly, C3PAOs and their CMMC Assessment Teams will need active access to the authoritative documents, along with the CAP, when conducting a CMMC Level 2 certification assessment. &lt;br /&gt;
&lt;br /&gt;
The CAP addresses pre-assessment “preliminary proceedings” that are then followed by the actual assessment process, which is organized across four (4) phases and describes the required activities, roles, and responsibilities of CMMC assessment participants in each. &lt;br /&gt;
&lt;br /&gt;
The four phases are:  &lt;br /&gt;
* Phase 1: “Conduct the Pre-Assessment”;&lt;br /&gt;
* Phase 2: “Assess Conformity to Security Requirements”;&lt;br /&gt;
* Phase 3: “Complete and Report Assessment Results”; and&lt;br /&gt;
* Phase 4: “Issue Certificate and Closeout POA&amp;amp;M”.&lt;br /&gt;
&lt;br /&gt;
These four phases have been designed to support each CMMC Level 2 certification assessment meeting the following objectives: &lt;br /&gt;
* Achieve the highest possible accuracy, fidelity, and quality of CMMC Level 2 certification assessments conducted by C3PAOs;&lt;br /&gt;
* Maximize consistency to ensure that CMMC Level 2 certification assessments conducted by C3PAOs and their CMMC Certified Assessors follow the same procedures, sequencing of activities, and production of verifiable results; and&lt;br /&gt;
* Instill trust and confidence in the CMMC Program by providing effective, transparent, and efficient CMMC Level 2 certification assessments that are well-planned, executed in consistent fashion, and accurately reported.&lt;br /&gt;
&lt;br /&gt;
The CAP provides a logical and practical sequencing of activities and actions throughout the four phases of the assessment process to ensure procedural coherence for the parties. In certain sections of the process, a precise sequence of specific actions may be explicitly mandated in the document. In these instances, the text will make clear the necessity of following certain procedures in a manner of specific order. In all other aspects of the CAP, the C3PAO and the OSC have the latitude and flexibility to conduct the CMMC assessment with a reasonable approach of their own when applied to the general sequencing of actions throughout the preliminary proceedings and four phases.&lt;br /&gt;
&lt;br /&gt;
== ROLES AND RESPONSIBILITIES ==&lt;br /&gt;
A CMMC Level 2 certification assessment requires the active engagement, communication, and attention of several key individuals or organizations, which may include:&lt;br /&gt;
&lt;br /&gt;
As defined in 32 CRF §170.4:&lt;br /&gt;
* Organization Seeking Certification (OSC)&lt;br /&gt;
* Affirming Official&lt;br /&gt;
* CMMC Third-Party Assessment Organization (C3PAO)&lt;br /&gt;
*:- Assessment Team members&lt;br /&gt;
* Accreditation Body (The Cyber AB)&lt;br /&gt;
* CMMC Assessor and Instruction Certification Organization (The CAICO)&lt;br /&gt;
&lt;br /&gt;
Other relevant individuals not directly defined in 32 CRF §170.4:&lt;br /&gt;
* Authorized Certifying Official: A designated official employed by the C3PAO and registered with The Cyber AB who is eligible to serve as the issuing authority and signatory for the CMMC Level 2 Certificate of CMMC Status provided to the OSC. C3PAOs may designate more than one Authorized Certifying Official.&lt;br /&gt;
* Lead CCA: The CMMC Certified Assessor (CCA) who satisfies the requirements of 32 CFR §170.4(b)(11) and who oversees and manages a dedicated Assessment Team on behalf of the C3PAO for the conduct of a CMMC Level 2 certification assessment. The Lead CCA serves as the counterpart to the Affirming Official. Lead CCA is a formal qualified designation issued by the CAICO. A Lead CCA may oversee multiple Assessment Teams across concurrent CMMC Level 2 certification assessments.&lt;br /&gt;
* OSC Point of Contact (OSC POC): The individual within or on behalf of the OSC who provides daily coordination and liaison support between the OSC and the Assessment Team. The OSC POC does not necessarily have to be an employee of the organization that is being assessed, but rather could be a contractor, consultant, or advisor, such as a CMMC Registered Practitioner (RP).&lt;br /&gt;
* Quality Assurance (QA) individual: An individual who manages the C3PAO’s quality assurance reviews for a CMMC Level 2 certification assessment, which includes observing the Assessment Team’s conduct and management of the assessment. A QA individual also manages a CMMC appeals process that might be initiated by an OSC.&amp;lt;ref&amp;gt;32 CFR §170.9(b)(13)&amp;lt;/ref&amp;gt; A QA individual must be a CCA and cannot be a member of an Assessment Team for which they are performing a quality assurance role. A QA individual is also responsible for the uploading of assessment information into the CMMC instantiation of eMASS.&lt;br /&gt;
&lt;br /&gt;
== PRELIMINARY PROCEEDINGS ==&lt;br /&gt;
&#039;&#039;&#039;A CMMC Level 2 certification assessment compels a few preliminary administrative, framing, and contractual activities that should be addressed prior to the formal commencement of Phase 1 of the assessment. These interactions between the C3PAO and the OSC concern important aspects of the prospective assessment, and their successful and mutually agreeable resolution will help enable a proper, viable, and transparent CMMC Level 2 certification assessment.&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
=== Receive CMMC Assessment Request from OSC ===&lt;br /&gt;
&#039;&#039;&#039;P.1&#039;&#039;&#039; An OSC generally initiates the engagement concerning a prospective CMMC Level 2 certification assessment by contacting an authorized or accredited C3PAO.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;P.2&#039;&#039;&#039; The updated registry of authorized or accredited C3PAOs in good standing is maintained on the CMMC Marketplace website administered by The Cyber AB. Unless otherwise notified by The Cyber AB, any C3PAO listed as “authorized” or “accredited” within the Marketplace may be considered a C3PAO in good standing and eligible to conduct a CMMC Level 2 certification assessment.&amp;lt;ref&amp;gt;In no circumstances will individuals from The Cyber AB, the CAICO, or DoD provide recommendations or facilitate introductions to any C3PAO.&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Confirm the Entity/Entities to be Assessed ===&lt;br /&gt;
&#039;&#039;&#039;P.3&#039;&#039;&#039; The C3PAO shall confirm the specific corporate legal entity that will be assessed, i.e., the precise identity of the actual “Organization Seeking Certification.”&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;P.4&#039;&#039;&#039; The C3PAO shall solicit from the OSC the Commercial and Government Entity (CAGE) code, or multiple CAGE codes, that are affiliated with the CMMC Level 2 certification assessment. Technically, a Level 2 CMMC Certificate of Status is issued upon a discrete and identified information system, as defined within a System Security Plan (SSP), that is owned and operated by an OSC. The identity of the OSC is determined by the CAGE code(s), which are issued by DoD.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;P.5&#039;&#039;&#039; The C3PAO should also request the OSC’s assessment unique identifier (UID) if a previous self-assessment had generated one. The DoD Supplier Performance Risk System (SPRS) generates a UID for a Level 1 and Level 2 self-assessment. The Pre-Assessment Form should include this SPRS UID if it exists, but it is not required for a Level 2 certification assessment, as the CMMC instantiation of eMASS will generate a new UID upon successful attainment of a Level 2 Certificate of CMMC Status. The CMMC eMASS UID and the SPRS UID share the same format, serve the same purpose, and are unique for each Level 2 certification assessment and self-assessment, respectively.&lt;br /&gt;
 &lt;br /&gt;
&#039;&#039;&#039;P.6&#039;&#039;&#039; All OSCs must possess a valid CAGE code and the CMMC Level 2 certification assessment cannot proceed without at least one CAGE code of record.&amp;lt;ref&amp;gt;For access to SPRS, the OSC will also need to obtain a Unique Entity ID that is generated from registration in SAM.gov.&amp;lt;/ref&amp;gt; A single CMMC assessment may cover multiple entities in the event more than one CAGE code is associated with a singular CMMC Level 2 Assessment Scope.&amp;lt;ref&amp;gt;In addition, the HQ organization or the Host Unit, depending on the corporate structure, must also have registered with the General Services Administration’s (GSA) SAM.gov system and have been issued a Unique Entity Identifier (UEI).&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;P.7&#039;&#039;&#039; The C3PAO should ask the OSC whether any in-scope External Service Providers (ESPs), as defined by &#039;&#039;&#039;32 CFR §170.4(b)&#039;&#039;&#039;, exist and whether the OSC considers the ESP a Cloud Service Provider (CSP) or a “non-CSP” ESP under &#039;&#039;&#039;32 CFR §170.19(c)(2)&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
=== Frame the Assessment ===&lt;br /&gt;
&#039;&#039;&#039;P.8&#039;&#039;&#039; The C3PAO shall work with the Affirming Official and/or the OSC POC to determine the purview and planning details of the assessment. This shall include discussing schedule, the size of the organization and information system to be assessed, personnel, logistics, relevant contractual requirements, and the prospective CMMC Assessment Scope.  &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;P.9&#039;&#039;&#039; The CMMC Assessment Scope is the set of all assets in the OSC’s environment that will be assessed against CMMC security requirements. It must be specified prior to the commencement of the Assessment.&amp;lt;ref&amp;gt;32 CFR §170.19(a)&amp;lt;/ref&amp;gt; &#039;&#039;&#039;The determination of proper CMMC Assessment Scope is established in 32 CFR §170.19(c), “CMMC Level 2 Scoping”&#039;&#039;&#039;. Supplemental information on CMMC Assessment Scope is contained in the DoD manual, &#039;&#039;CMMC Assessment Scope – Level 2&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;P.10&#039;&#039;&#039; In framing the CMMC Level 2 certification assessment, the C3PAO and OSC should discuss and agree upon, at a minimum, the following aspects:&lt;br /&gt;
* Availability of personnel in support of the assessment;&lt;br /&gt;
* Availability of evidence in support of the assessment;&lt;br /&gt;
* OSC’s relevant documentation, including the System Security Plan (SSP); and&lt;br /&gt;
* An estimate for the approximate duration and timing for the assessment.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;P.11&#039;&#039;&#039; Another consideration of framing the assessment involves determining assessment location(s), including what security requirement objectives of the assessment might be assessed virtually or in-person on the OSC premises. The Lead CCA and/or the C3PAO should consider the optimal logistical approach for implementation validation of the following 18 CMMC security requirement objectives to ensure adequate assessment scope and depth:&lt;br /&gt;
* CM.L2-3.4.5[d]: Physical access restrictions associated with changes to the system are enforced.&lt;br /&gt;
* MA.L2-3.7.2[d]: Personnel used to conduct system maintenance are controlled.&lt;br /&gt;
* MP.L2-3.8.1[c]: Paper media containing CUI is securely stored.&lt;br /&gt;
* MP.L2-3.8.1[d]: Digital media containing CUI is securely stored.&lt;br /&gt;
* MP.L2-3.8.4[a]: Media containing CUI is marked with applicable CUI markings.&lt;br /&gt;
* MP.L2-3.8.4[b]: Media containing CUI is marked with distribution limitations.&lt;br /&gt;
* PE.L2-3.10.1[b]: Physical access to organization systems is limited to authorized individuals.&lt;br /&gt;
* PE.L2-3.10.1[c]: Physical access to equipment is limited to authorized individuals.&lt;br /&gt;
* PE.L2-3.10.1[d]: Physical access to operating environments is limited to authorized individuals.&lt;br /&gt;
* PE.L2-3.10.2[a]: The physical facility where organizational systems reside is protected.&lt;br /&gt;
* PE.L2-3.10.2[b]: The support infrastructure for organizational systems is protected.&lt;br /&gt;
* PE.L2-3.10.2[c]: The physical facility where organizational systems reside is monitored.&lt;br /&gt;
* PE.L2-3.10.2[d]: The support infrastructure for organizational systems is monitored.&lt;br /&gt;
* PE.L2-3.10.3[a]: Visitors are escorted.&lt;br /&gt;
* PE.L2-3.10.3[b]: Visitor activity is monitored.&lt;br /&gt;
* PE.L2-3.10.5[b]: Physical access devices are controlled.&lt;br /&gt;
* PE.L2-3.10.5[c]: Physical access devices are managed.&lt;br /&gt;
* SC.L2-3.13.12[b]: Collaborative computing devices provide indication to users of devices in use.&lt;br /&gt;
&lt;br /&gt;
NOTE: For OSC CMMC-scoped environments that DO NOT have physical and/or environmental controls due to a cloud environment or other factors that negate conducting an “on-site” portion of the assessment, the applicability of these requirements should be addressed between the OSC and the C3PAO in Phase 1.&lt;br /&gt;
&lt;br /&gt;
=== Identify and Manage Initial Conflicts of Interest (COI) ===&lt;br /&gt;
&#039;&#039;&#039;P.12&#039;&#039;&#039; C3PAOs are ultimately responsible for managing impartiality and identifying conflicts of interest relating to a CMMC Level 2 certification assessment. This responsibility cannot be delegated to their CMMC Assessment Team or the OSC.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;P.13&#039;&#039;&#039; C3PAOs shall adhere to the impartiality requirements of ISO/IEC 17020:2012 and the conflict-of- interest disclosure provisions and COI prohibitions within the CMMC Code of Professional Conduct (CoPC). The CoPC contains additional details on impartiality requirements, including CMMC-specific examples of potential COIs that are to be mitigated or avoided.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;P.14&#039;&#039;&#039; The C3PAO shall propose to the OSC the name of the Lead CCA that it intends to assign to the OSC’s CMMC Level 2 certification assessment. The C3PAO shall coordinate with the OSC to ascertain if any conflicts of interest exist between the proposed Lead CCA and the OSC.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;P.15&#039;&#039;&#039; If a conflict of interest is disclosed or identified, by either party, the C3PAO shall work with the OSC to develop a mitigation plan for the identified conflict in question.&lt;br /&gt;
:&#039;&#039;&#039;P.15.1&#039;&#039;&#039; Any mitigation measures to which the parties agree shall be documented.&lt;br /&gt;
:&#039;&#039;&#039;P.15.2&#039;&#039;&#039; In the event the conflict cannot be sufficiently mitigated due to the circumstances, the C3PAO shall not proceed with the assessment.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;P.16&#039;&#039;&#039; The C3PAO should obtain concurrence of the OSC on the assignment of the Lead CCA prior to commencing with the CMMC Level 2 certification assessment.&lt;br /&gt;
&lt;br /&gt;
=== Execute Contractual Agreement ===&lt;br /&gt;
&#039;&#039;&#039;P. 17&#039;&#039;&#039; The C3PAO shall execute a written contractual agreement for the CMMC Level 2 certification assessment with the OSC. Neither The Cyber AB nor DoD are parties to the CMMC Level 2 certification assessment contract between the C3PAO and the OSC.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;P.18&#039;&#039;&#039; The format and structure of the contract is at the discretion and mutual agreement of the C3PAO and OSC.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;P.19&#039;&#039;&#039; A mutual non-disclosure agreement (NDA) between the parties shall be incorporated into the contractual agreement or negotiated and executed in a separate document (e.g., stand-alone NDA, master services agreement, etc.).&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;P.20&#039;&#039;&#039; All contractual agreements for CMMC assessments must comport to the CMMC Code of Professional Conduct. Specifically, the C3PAO is prohibited from offering any “guarantees” or “promises” relating to the results of the CMMC Level 2 certification assessment, nor may the C3PAO include any incentives or bonus payments contingent on the issuance of a Certificate of CMMC Status to the OSC.&lt;br /&gt;
&lt;br /&gt;
== PHASE 1 – CONDUCT THE PRE-ASSESSMENT ==&lt;br /&gt;
&#039;&#039;&#039;In Phase 1, the C3PAO will evaluate if the OSC has adequately prepared for the assessment of its implementation of CMMC Level 2 security requirements.&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;At the conclusion of Phase 1, the C3PAO will submit the Pre-Assessment Information Form into the CMMC instantiation of eMASS.&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;1.1.&#039;&#039;&#039; The Lead CCA shall supervise Phase 1 activities.&lt;br /&gt;
&lt;br /&gt;
=== Review the System Security Plan (SSP) ===&lt;br /&gt;
&#039;&#039;&#039;1.2.&#039;&#039;&#039; C3PAO personnel shall review the OSC’s System Security Plan (SSP) and examine the document for completeness, accuracy, and consistency. By conducting this cursory review of the SSP in Phase 1, the C3PAO should be able to arrive at a reasonable expectation that the OSC has addressed the security requirements of NIST SP 800-171 R2, without regard to evaluating the adequacy or sufficiency of implementation.  &lt;br /&gt;
&lt;br /&gt;
Validate CMMC Assessment Scope  &lt;br /&gt;
&#039;&#039;&#039;1.3.&#039;&#039;&#039; &#039;&#039;&#039;The Lead CCA shall validate the OSC’s CMMC Level 2 Assessment Scope in accordance with 32 CFR §170.19(c), “CMMC Level 2 Scoping”.&#039;&#039;&#039; The DoD publication, CMMC Assessment Scope – Level 2, contains additional CMMC scoping guidance.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;1.4.&#039;&#039;&#039; Any disagreements or differences of opinion concerning the CMMC Assessment Scope must be resolved between the C3PAO and the OSC before the CMMC Level 2 certification assessment may proceed to Phase 2.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;1.5.&#039;&#039;&#039; As part of the defined Assessment Scope requirements addressed in 32 CFR §170.19(c), the Lead CCA, Assessment Team members, and the OSC shall establish evaluation methods for CMMC Level 2 security requirement objectives, based on the OSC’s CUI Level 2 assets, and the degree of rigor to be applied to the assessment, which may include, but is not necessarily limited to, the assessment methods addressed in activity 1.10.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;1.6.&#039;&#039;&#039; If the OSC has identified an ESP as being within their CMMC Assessment Scope, the Assessment Team shall confirm that a Customer Responsibility Matrix (CRM) will be available and that ESP personnel will be present and actively participating in the assessment.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;1.7.&#039;&#039;&#039; If the ESP that has been identified as being within the OSC’s CMMC Assessment Scope stores, processes, or transmits CUI, the Assessment Team shall confirm that the OSC will be prepared to provide evidence of the ESP’s FedRAMP Moderate Authorization, FedRAMP Moderate equivalency, or a Level 2 Certificate of CMMC Status, as appropriate.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;1.8.&#039;&#039;&#039; If the Lead CCA cannot confirm proper incorporation, documentation, and/or participation, as appropriate, of an ESP in the OSC’s CMMC Level 2 Assessment Scope, the C3PAO should confer with the OSC Affirming Official and discuss the merits of not proceeding with the CMMC Level 2 certification assessment.&lt;br /&gt;
&lt;br /&gt;
=== Confirm Availability of Evidence ===&lt;br /&gt;
&#039;&#039;&#039;1.9.&#039;&#039;&#039; The Assessment Team will need access to various evidence and artifacts—as well as OSC personnel and ESP personnel (if applicable)—to conduct the evaluative activities in Phase 2 of the CMMC Level 2 certification assessment. The Lead CCA, in preparing for the assessment, should be confident that there will be ample evidence made accessible to the Assessment Team to render an accurate evaluation of the security requirements of NIST SP 800-171 R2 and determine if they have been properly implemented by the OSC.&lt;br /&gt;
&lt;br /&gt;
=== Determine Readiness for Assessment ===&lt;br /&gt;
&#039;&#039;&#039;1.10.&#039;&#039;&#039; The Lead CCA shall make the determination as to the readiness of the OSC to proceed with the conduct of the CMMC Level 2 certification assessment. The determination should be based on the reviews and confirmations conducted in this Phase as well as a general confidence that the OSC is overall prepared for the conduct of the assessment. The Lead CCA should convey to the OSC that various assessment methods (e.g., reviewing, inspecting, observing, studying, analyzing, discussing, and exercising assessment objects) will be employed and may include assessment methods and associate attributes of depth and coverage as outlined in: &lt;br /&gt;
* NIST SP 800-171A, Appendix D, “Assessment Methods”;&lt;br /&gt;
* NIST SP 800-53A, 3.2.3.2 - “Depth- and Coverage-Related Considerations”;&lt;br /&gt;
* NIST SP 800-53A, Appendix C, “Assessment Method Descriptions”; and&lt;br /&gt;
* Any in-person observations of security requirement objectives as discussed in activity P.11.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;1.11.&#039;&#039;&#039; The Assessment Team shall not speculate, intimate, nor make any preliminary determination of the OSC’s likelihood of a successful assessment outcome and subsequent issuance of a Certificate of CMMC Status. The sole purpose of this activity is to confirm that the OSC is sufficiently prepared to begin the evaluative portion of the assessment in Phase 2.&lt;br /&gt;
&lt;br /&gt;
=== Compose the Assessment Team ===&lt;br /&gt;
&#039;&#039;&#039;1.12.&#039;&#039;&#039; &#039;&#039;&#039;The C3PAO shall compose the CMMC Assessment Team as established and defined in 32 CFR §170.11(b)(10).&#039;&#039;&#039; The C3PAO should propose to the OSC the names of the CMMC Certified Assessors (CCAs) and CMMC Certified Professionals (CCPs) that it intends to assign to the Assessment Team.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;1.13.&#039;&#039;&#039; The C3PAO shall have implemented the personnel procedures established in Section 6.15 and 6.16 of ISO/IEC 17020:2012 in composing its Assessment Team.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;1.14.&#039;&#039;&#039; The C3PAO is responsible for managing impartiality and identifying any conflicts of interest of the members of the Assessment Team prior to the commencement of Phase 2 activities. This responsibility cannot be delegated to the Lead CCA or the OSC. Any COI between a member of the Assessment Team and the OSC must be sufficiently mitigated or avoided.&lt;br /&gt;
&lt;br /&gt;
=== Complete the Pre-Assessment Form ===&lt;br /&gt;
&#039;&#039;&#039;1.15.&#039;&#039;&#039; The C3PAO shall generate, collect, and document required pre-assessment and planning information and material via the Pre-Assessment Form pursuant to 32 CFR §170.9(b)(8). Examples of this material include the OSC CAGE code, SSP title, OSC contact information, Assessment Team information, dates of the assessment, the readiness determination for assessment, and other data. This pre-assessment information is required to be collected and uploaded into CMMC eMASS for DoD program management and oversight purposes.&amp;lt;ref&amp;gt;32 CFR § 170.9(b)(8)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;1.16.&#039;&#039;&#039; The C3PAO may utilize the official CMMC Level 2 Pre-Assessment Form (CMMC_PreAssessment_Template.xlsx) that is available on the CMMC eMASS website. Alternatively, C3PAOs may develop or purchase any tool that is compliant with the CMMC eMASS data standard that can generate pre-assessment data in the required JSON file format.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;1.17.&#039;&#039;&#039; The C3PAO shall follow the instructions and guidance for the pre-assessment and planning information and material as contained in “The DoD CMMC eMASS Concept of Operations for CMMC Third-Party Assessment Organizations”.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;1.18.&#039;&#039;&#039; The C3PAO shall not share any OSC pre-assessment information with any person or organization not involved with that specific CMMC Level 2 certification assessment, except as otherwise required by law.&amp;lt;ref&amp;gt;32 CFR § 170.11(b)(9)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Conduct Quality Assurance Review of Pre-Assessment and Planning Information ===&lt;br /&gt;
&#039;&#039;&#039;1.19.&#039;&#039;&#039; A C3PAO quality assurance individual shall conduct a quality assurance review of the Pre- Assessment Form upon completion by the CMMC Assessment Team. &#039;&#039;&#039;For this quality assurance function, the C3PAO shall meet the requirements as outlined in 32 CFR §170.9(b)(13).&#039;&#039;&#039;&lt;br /&gt;
 &lt;br /&gt;
=== Upload Pre-Assessment Form into CMMC eMASS ===&lt;br /&gt;
&#039;&#039;&#039;1.20.&#039;&#039;&#039; Upon completion of a satisfactory quality assurance review, a quality assurance individual shall upload the pre-assessment form into the CMMC instantiation of eMASS. &#039;&#039;&#039;The C3PAO shall follow the CMMC eMASS data standard and upload procedures as set forth in “The Department of Defense CMMC eMASS Concept of Operations for CMMC Third-Party Assessment Organizations”.&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;1.21.&#039;&#039;&#039; Phase 1 of the CMMC Level 2 certification assessment concludes upon the successful upload of the Pre-Assessment Form into CMMC eMASS.&lt;br /&gt;
&lt;br /&gt;
=== Adverse Determination of Assessment Readiness ===&lt;br /&gt;
&#039;&#039;&#039;1.22.&#039;&#039;&#039; In the event the Lead CCA determined that the OSC was not sufficiently prepared to undergo the CMMC Level 2 certification assessment, they should directly inform the Affirming Official of their decision and provide a full explanation in writing to the OSC as to why the recommendation to suspend the Assessment was made, without providing any remedial advice as to how the OSC could improve its documentation and preparation for the assessment.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;1.23.&#039;&#039;&#039; &#039;&#039;&#039;Under no circumstances shall the C3PAO, its Assessment Team, or any other affiliated personnel offer any advice, implementation assistance, or recommendations as to how the OSC can improve or enhance their preparedness for a replanned or rescheduled CMMC Level 2 certification assessment and, pursuant to the CMMC Code of Professional Conduct (CoPC), doing so would conflict the C3PAO from eventually resuming the suspended CMMC certification assessment with that specific OSC.&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;1.24.&#039;&#039;&#039; In the event the OSC decides to cancel or postpone the assessment, both parties should settle all affairs, as appropriate to the terms of their agreement, including the return of any OSC proprietary information. The C3PAO and the OSC should discuss, in general terms, the option of revisiting the CMMC Level 2 certification assessment when the OSC is fully prepared, as well as the anticipated timelines for resuming the suspended assessment and returning to complete the Phase 1 pre-assessment.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;1.25.&#039;&#039;&#039; In the event of an assessment postponement or cancellation, the C3PAO shall still complete, review, and upload the Pre-Assessment Form into the CMMC instantiation of eMASS as described in previous activities 1.13 through 1.19.&lt;br /&gt;
&lt;br /&gt;
== PHASE 2 – ASSESS CONFORMITY TO SECURITY REQUIREMENTS ==&lt;br /&gt;
&#039;&#039;&#039;The purpose of Phase 2 is to assess the implementation of CMMC Level 2 security requirements— both in depth and coverage — by the OSC and determine if it has met the assessment objectives of NIST SP 800-171A.&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;The C3PAO shall conduct the CMMC Level 2 certification assessment in accordance with 32 CFR § 170.17, NIST SP 800-171A, this document (the “CAP”), and ISO/IEC 17020:2012, “Conformity Assessment—Requirements for the operation of various types of bodies performing inspection.”&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
=== Conduct In-Brief Meeting ===&lt;br /&gt;
&#039;&#039;&#039;2.1.&#039;&#039;&#039; The Lead CCA shall convene an In-Brief Meeting prior to the commencement of assessing the implementation of CMMC security requirements of the OSC. This In-Brief Meeting may be conducted in-person, virtually, or in a hybrid manner. The purpose of the In-Brief Meeting is to establish a common understanding of the assessment objectives, procedures, roles and responsibilities, and schedule.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;2.2.&#039;&#039;&#039; The Lead CCA shall ensure that official minutes or a detailed meeting summary of the kickoff, including all questions and answers, shall be documented and retained by the C3PAO.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;2.3.&#039;&#039;&#039; Attendees for the in-brief meeting shall include, but are not limited to, the Lead CCA, the Affirming Official, the OSC POC, and the Assessment Team members. If a member of the CMMC Assessment Team is unable to attend the In-Brief Meeting, the Lead CCA shall still inform the OSC of the identity of the absent member(s) and facilitate an introduction to the OSC at a subsequent juncture of the assessment.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;2.4.&#039;&#039;&#039; The OSC may elect to have additional employees, consultants, ESP personnel, and any observers present at the In-Brief Meeting. If the C3PAO desires additional individuals external to the CMMC Assessment Team to be present or to observe the actual assessment, it must receive permission from the Affirming Official or OSC POC to do so.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;2.5.&#039;&#039;&#039; The Lead CCA shall, at a minimum, address the following issues with the OSC during the In-Brief Meeting:&lt;br /&gt;
* Introduce the Assessment Team members and invite the introduction of key OSC personnel and support staff;&lt;br /&gt;
* Confirm the CMMC Assessment Scope;&lt;br /&gt;
* Explain CMMC Level 2 assessment procedures as established in 32 CFR §170.17(c);&lt;br /&gt;
* Review the assessment schedule;&lt;br /&gt;
* Reconfirm the absence of, or disclose, any organizational or individual conflicts of interest;&lt;br /&gt;
* Inform the OSC of its rights to appeal the assessment results and describe the C3PAO’s appeals process; and&lt;br /&gt;
* Invite any questions or issues for clarification from the OSC.&lt;br /&gt;
 &lt;br /&gt;
=== Assess Implementation of Security Requirements ===&lt;br /&gt;
&#039;&#039;&#039;2.6.&#039;&#039;&#039; The Assessment Team shall evaluate the OSC’s implementation of security requirements in accordance with NIST SP 800-171A (current applicable version) and 32 CFR §170.17(c). The three (3) assessment methods of examine, interview, and test, as outlined in NIST SP 800-171A, shall be adhered to by all Assessment Team CCAs assessing security requirements.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;2.7.&#039;&#039;&#039; Upon mutual agreement, the parties may conduct much of the evidence collection and evaluation process virtually, using a stable and commercially secure video conference system or web-based collaboration platform. The C3PAO should make the final decision on whether to conduct some eligible evidence collection activities virtually or in person, based on internal procedures and risk evaluation. In a virtual assessment arrangement, the C3PAO and OSC shall ensure that CUI is not shared electronically as part of the evidence collection and evaluation process, unless the assessment is conducted within CMMC Level 2-conforming environments on both sides.&lt;br /&gt;
&lt;br /&gt;
=== Apply Sampling Values for Depth and Coverage ===&lt;br /&gt;
&#039;&#039;&#039;2.8.&#039;&#039;&#039; The Assessment Team’s optimal sampling aims to balance ensuring sufficient evaluation of assets, people, policies, and procedures to achieve an accurate and proper determination of conformity with the need to conduct an efficient, manageable, and cost-effective assessment. Achieving that balance involves selecting representative samples of evidence to be tested or inspected, while minimizing the risk of overlooking non-conforming items.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;2.9.&#039;&#039;&#039; &#039;&#039;&#039;For CMMC Level 2 certification assessments, the Assessment Team shall use a nonstatistical sampling approach in accordance with NIST SP 800-171 R2, Appendix D, “Assessment Method Descriptions”. The Assessment Teams shall employ the FOCUSED value for both depth and coverage in evaluating all Level 2 security requirements, as applicable.&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;2.10.&#039;&#039;&#039; The Assessment Team should increase the sample for evaluation once it encounters questionable, insufficient, or inadequate evidence for a CMMC security requirement.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;2.11.&#039;&#039;&#039; When encountering multiple CAGE codes in a given assessment, the Assessment Team shall ensure that all CAGE codes have been accounted for in the sampling approach.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;2.12.&#039;&#039;&#039; When encountering multiple physical locations, the Assessment Team should consider in its sampling approach whether different locations use different physical control methods, whether scan results cover systems at all locations, and whether defined system boundaries account for all physical locations.&lt;br /&gt;
&lt;br /&gt;
=== Conduct Assessment Scoring ===&lt;br /&gt;
&#039;&#039;&#039;2.13.&#039;&#039;&#039; &#039;&#039;&#039;The Assessment Team shall employ the CMMC Level 2 Scoring Methodology as established in 32 CFR §170.24 that provides a measurement of the OSC’s implementation of the NIST SP 800-171 R2 security requirements.&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;2.14.&#039;&#039;&#039; The DoD CMMC Scoring Methodology should be referenced for the following:&lt;br /&gt;
: &#039;&#039;&#039;2.14.1.&#039;&#039;&#039; Assessment Findings: &#039;&#039;&#039;32 CFR §170.24(b)&#039;&#039;&#039;&lt;br /&gt;
::* Assessment requirements for &#039;&#039;&#039;Met&#039;&#039;&#039; findings, including enduring exceptions and temporary deficiencies;&lt;br /&gt;
::* Assessment requirements for &#039;&#039;&#039;Not Met&#039;&#039;&#039; findings; and&lt;br /&gt;
::* Assessment requirements for &#039;&#039;&#039;Not Applicable&#039;&#039;&#039; findings.&lt;br /&gt;
: &#039;&#039;&#039;2.14.2.&#039;&#039;&#039; Scoring: &#039;&#039;&#039;32 CFR §170.24(c)&#039;&#039;&#039;&lt;br /&gt;
::* Assessment requirements for &#039;&#039;&#039;Basic Security Requirements&#039;&#039;&#039; scoring; and&lt;br /&gt;
::* Assessment requirements for &#039;&#039;&#039;Derived Security Requirements&#039;&#039;&#039; scoring.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;2.15.&#039;&#039;&#039; Assessors may re-evaluate NOT MET security requirements during the assessment and for ten (10) business days following the active assessment period (i.e., the conclusion of Phase 2 activities) &#039;&#039;&#039;in accordance with the requirements established in 32 CFR §170.17(c)(2).&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
=== Address External Service Providers ===&lt;br /&gt;
&#039;&#039;&#039;2.16.&#039;&#039;&#039; &#039;&#039;&#039;The Assessment Team shall determine the OSC’s utilization and disposition of an in-scope ESP as established in 32 CFR §170.16(a)(3) and 32 CFR §170.16(a)(2), respectively.&#039;&#039;&#039; In addition, the CMMC PMO has published Frequently Asked Questions (FAQ) on this issue that should be consulted for additional clarification on the use of ESPs.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;2.17.&#039;&#039;&#039; The Assessment Team shall evaluate that the Customer Responsibility Matrix (CRM) of an ESP is up-to date, includes all relevant parties with security responsibilities, and addresses all in-scope CMMC security requirements performed wholly, partially, or jointly by the ESP.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;2.18.&#039;&#039;&#039; When an Assessor employs the interview method to validate a security requirement on the CRM that is assigned to the ESP, the ESP respondent must demonstrate sufficient knowledge and credible “ownership” of that requirement—no different than that which is required for an OSC representing a security requirement under its own responsibility. The Assessment Team should also employ the examine and test methods when evaluating the inheritance claims made in the CRM by the OSC.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;2.19.&#039;&#039;&#039; In the event the OSC is utilizing a “non-CSP” ESP that voluntarily attained a Level 2 or Level 3 Certificate of CMMC Status, the Assessment Team should anticipate and accept a lower level of effort on behalf of the ESP during the OSC’s assessment.&amp;lt;ref&amp;gt;32 CFR §179.19(c)(2)(ii)&amp;lt;/ref&amp;gt; Specifically, if the Assessment Team confirms the ESP is in possession of a valid Certificate of CMMC Status, it may consider those security requirements under the responsibility of the ESP to be in a validated state. The Assessment Team shall still ensure that each inherited security requirement from the ESP is still implemented and currently being maintained in the state under which it was originally assessed and/or have the ESP attest to same. ESP personnel still need to participate during Phase 2 of the OSC’s assessment to answer questions of the Assessment Team.&lt;br /&gt;
&lt;br /&gt;
=== Address Cloud Service Providers ===&lt;br /&gt;
&#039;&#039;&#039;2.20.&#039;&#039;&#039; If the OSC represents that the CSP cloud environment supporting them is currently Authorized at the Moderate baseline within FedRAMP, the Assessment Team shall verify said Authorization by referring to the FedRAMP Marketplace at https://marketplace.fedramp.gov/products and identifying the name of the CSP under the column heading “Provider”. The Assessment Team shall then ascertain if &#039;&#039;&#039;the specific cloud service offering that is documented in the OSC’s SSP&#039;&#039;&#039; is listed under the column heading “Service Offering”. The Assessment Team can then determine the current Authorization baseline and status of the cloud offering by checking both the “Impact Level” and “Status” column headings. If the above condition is satisfied, the FedRAMP Moderate (or higher) baseline of the CSP’s cloud service offering shall be accepted and noted as such in the assessment results.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;2.21.&#039;&#039;&#039; If the OSC represents that the CSP cloud environment supporting them within their CMMC Assessment Scope is not FedRAMP Authorized &#039;&#039;&#039;but meets the security requirements of FedRAMP Moderate (or higher) equivalency,&#039;&#039;&#039; the Assessment Team shall determine if equivalency has been attained in accordance with &#039;&#039;&#039;current DoD CIO policy on equivalency at the time of the OSC’s Level 2 certification assessment.&#039;&#039;&#039;&amp;lt;ref&amp;gt;32 CFR §179.17(c)(5)(ii)&amp;lt;/ref&amp;gt;&lt;br /&gt;
: &#039;&#039;&#039;2.21.1.&#039;&#039;&#039; During the OSC’s CMMC Level 2 certification assessment, the Assessment Team shall verify that the CSP’s FedRAMP Moderate Equivalency body of evidence (BOE), as presented by the OSC, is complete, intact, and within the established periodicity, as required. The Assessment Team shall employ the following definitions when reviewing the BoE:&lt;br /&gt;
::* Complete: all required elements of the BoE have been compiled and presented to the C3PAO for review;&lt;br /&gt;
::* Intact: each element of the BoE is presented in full and is not missing any critical sections, pages, or material information; and&lt;br /&gt;
::* Established Periodicity: any element that has a temporal requirement (e.g., must be completed annually) has been completed within the specified timeframe.&lt;br /&gt;
:: If the Assessment Team determines that all elements of the cloud service offering’s BoE are complete, intact, and within the established periodicity, then FedRAMP Moderate Equivalency of that cloud service offering has been verified for the CMMC Level 2 certification assessment and shall be denoted as such in the assessment results.&lt;br /&gt;
: &#039;&#039;&#039;2.21.2.&#039;&#039;&#039; In reviewing the BoE, the Assessment Team is not evaluating the CSP’s cloud service offering for conformance to the FedRAMP Moderate standard. Nor is the CMMC Assessment Team conducing a qualitative examination of any element of the BoE, including testing results. Rather, the CMMC Assessment Team is conducting a review of the BoE to verify that it is complete, intact, and within established periodicity.&lt;br /&gt;
&lt;br /&gt;
=== Conduct Quality Assurance Reviews ===&lt;br /&gt;
&#039;&#039;&#039;2.22.&#039;&#039;&#039; &#039;&#039;&#039;The C3PAO shall conduct quality assurance reviews during the assessment pursuant to 32 CFR §170.19(b)(14).&#039;&#039;&#039; These reviews are in addition to the quality assurance requirements pertaining to the Pre-Assessment Form and the Final Assessment Report as discussed in Phases 1 and 3, respectively, and include conducting observations of the Assessment Team’s conduct and management of the CMMC assessment process. These reviews shall be performed by a quality assurance individual who is not a member of the Assessment Team.&lt;br /&gt;
&lt;br /&gt;
=== Convene Daily Checkpoint Meetings ===&lt;br /&gt;
&#039;&#039;&#039;2.23.&#039;&#039;&#039; The Assessment Team shall host a Daily Checkpoint Meeting with the OSC POC and other OSC personnel at the end of each assessment day to summarize progress, identify any challenges, and discuss additional items for coordination.&lt;br /&gt;
&lt;br /&gt;
== PHASE 3 – COMPLETE AND REPORT ASSESSMENT RESULTS ==&lt;br /&gt;
&#039;&#039;&#039;The purpose of Phase 3 is to complete, review, report, and submit the assessment results of the CMMC Level 2 certification assessment. By the time the assessment reaches Phase 3, all evaluative activity of the OSC’s implemented security requirements and examination of evidence shall have been completed by the Assessment Team. &#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
=== Compile and Compose Assessment Results ===&lt;br /&gt;
&#039;&#039;&#039;3.1.&#039;&#039;&#039; Upon conclusion of the evaluative activity in Phase 2, the Assessment Team shall compile the assessment results and begin composing the results in the required format for eventual upload into the CMMC instantiation of eMASS.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;3.2.&#039;&#039;&#039; &#039;&#039;&#039;The C3PAO shall follow the CMMC eMASS data standard as set forth in “The Department of Defense CMMC eMASS Concept of Operations for CMMC Third-Party Assessment Organizations”.&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;3.3.&#039;&#039;&#039; C3PAOs may utilize the CMMC Level 2 Assessment Results Template that is available on the CMMC eMASS website. Alternatively, C3PAOs may develop or purchase any tool that is compliance with the CMMC eMASS data standard that can generate assessment results data in the required JSON file format.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;3.4.&#039;&#039;&#039; If the Lead CCA determines that all security requirements have been implemented and thus MET, the certification assessment results will reflect a recommendation for a CMMC Level 2 Final Certificate of CMMC Status for the OSC’s in-scope data environment.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;3.5.&#039;&#039;&#039; If the Lead CCA determines that all security requirements have been implemented and thus MET, with the exception of those security requirements that are documented on an existing and valid POA&amp;amp;M &#039;&#039;&#039;that is in accordance with 32 CFR §170.21, “Plan of Action and Milestone requirements,”&#039;&#039;&#039; the certification assessment results will reflect a recommendation for a CMMC Level 2 &#039;&#039;&#039;Conditional&#039;&#039;&#039; Certificate of CMMC Status for the OSC’s in-scope data environment.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;3.6.&#039;&#039;&#039; If the Lead CCA determines that all security requirements have not been implemented and thus NOT MET and/or a valid POA&amp;amp;M is not attainable, the certification assessment results will reflect a recommendation for no issuance of a Level 2 Certificate of CMMC Status.&lt;br /&gt;
&lt;br /&gt;
=== Conduct Quality Assurance Review ===&lt;br /&gt;
&#039;&#039;&#039;3.7.&#039;&#039;&#039; The C3PAO shall conduct a formal quality assurance review of the certification assessment results. The C3PAO shall conduct the quality assurance review of the certification assessment results prior to the conduct of the Out-Brief Meeting with the OSC.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;3.8.&#039;&#039;&#039; The C3PAO shall ensure that any individual(s) fulfilling this quality assurance function &#039;&#039;&#039;must be a CCA and cannot be a member of the CMMC Assessment Team conducting the CMMC Level 2 certification assessment for which they are performing the quality assurance function.&#039;&#039;&#039; The CCA conducting the quality assurance review shall also not have any interaction with the CMMC Assessment Team relating to the conduct of the CMMC Level 2 certification assessment while it is in progress prior to conduct of the quality assurance review itself.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;3.9.&#039;&#039;&#039; The C3PAO quality assurance review of the CMMC Level 2 certification assessment results shall, at a minimum, incorporate quality checks on the accuracy and completeness of the evaluation of all security requirements as well as the conformance to the required reporting formats and incorporated data fields for each.&lt;br /&gt;
&lt;br /&gt;
=== Convene Out-Brief Meeting ===&lt;br /&gt;
&#039;&#039;&#039;3.10.&#039;&#039;&#039; The Lead CCA will convene the Out-Brief Meeting upon the compilation, composition, and quality review of the assessment results. If the OSC has elected to request a re-evaluation of a security requirement pursuant to 32 CFR §170.17(c)(2), “Security requirement re-evaluation,” the Lead CCA will convene the Out-Brief Meeting no sooner than ten (10) business days upon conclusion of all evaluative activity in Phase 3. The Out-Brief Meeting may be conducted in- person, virtually, or in a hybrid manner. The purpose of the Out-Brief Meeting is to convey the results of the assessment to the OSC.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;3.11.&#039;&#039;&#039; Attendees for the out-brief meeting shall include, but are not limited to, the Lead CCA, the OSC Official, the OSC POC, and all Assessment Team Members. If a member of the CMMC Assessment Team is unable to attend the Out-Brief Meeting, the Lead CCA shall inform the OSC of the identity of the absent member(s). The OSC retains the right to insist upon the presence of all CMMC Assessment Team members at the Out-Brief Meeting and, should they do so, the Out- Brief Meeting shall not be conducted until all CMMC Assessment Team members are available to participate or until which time the OSC agrees to proceed with the Out-Brief Meeting without full attendance by the CMMC Assessment Team.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;3.12.&#039;&#039;&#039; The OSC may elect to have additional employees, consultants, ESP personnel, and any observers present at the Out-Brief Meeting. If the C3PAO desires additional individuals external to the Assessment Team to be present at the Out-Brief Meeting, it must receive permission from the Affirming Official or OSC POC to do so.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;3.13.&#039;&#039;&#039; The Lead CCA shall ensure that official minutes or a detailed meeting summary of the Out-Brief Meeting, including all questions and answers, are documented and retained by the C3PAO.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;3.14.&#039;&#039;&#039; The Assessment Team shall prepare and deliver an Assessment Results Briefing documenting the certification assessment results for presentation to the OSC during the Out-Brief Meeting.&lt;br /&gt;
&lt;br /&gt;
The Assessment Results Briefing shall be developed within a common presentation application (e.g. Microsoft PowerPoint, Google Slides, Apple Pages) and can be provided in PDF file format as well.&lt;br /&gt;
&lt;br /&gt;
The following information should be included in the Assessment Results Briefing and addressed during the Out-Brief Meeting:  &lt;br /&gt;
* Cover page with C3PAO logo, name of Lead CCA, and date of Out-Brief Meeting;&lt;br /&gt;
* Dates during which the CMMC Level 2 certification assessment was conducted;&lt;br /&gt;
* Name of the OSC;&lt;br /&gt;
* CAGE code(s) of the entity/entities associated with the data environment that was assessed;&lt;br /&gt;
* Unique Identifier (UID) from SPRS of the system previously self-assessed (if one exists);&lt;br /&gt;
* Short name and/or description of the assessment enclave or network that was assessed; the environment that was assessed;&lt;br /&gt;
* Final MET / NOT MET / NA determination for each security requirement;&lt;br /&gt;
* Status of POA&amp;amp;Ms (if applicable);&lt;br /&gt;
* Determination of CMMC Level 2 Certificate of CMMC Status to be issued or denied;&lt;br /&gt;
* Artifact retention and integrity procedures (i.e., hashing requirements);&lt;br /&gt;
* Proprietary information return and/or destruction per NDA or contract; and&lt;br /&gt;
* Summary of OSC Assessment Appeal rights and C3PAO appeals process.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;3.15.&#039;&#039;&#039; &#039;&#039;&#039;Under no circumstances shall the Assessment Results Briefing contain any information that communicates, references, or insinuates any recommended or suggested remedial actions that the OSC could or should consider based on the results of the assessment.&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;3.16.&#039;&#039;&#039; The Assessment Team shall inform the OSC that the hashed artifacts used as evidence for the assessment must be retained by the OSC for six (6) years from the CMMC Status Date that will appear on their Certificate of CMMC Status.&amp;lt;ref&amp;gt;32 CFR §170.17(c)(4)&amp;lt;/ref&amp;gt; The Assessment Team shall inform the OSC that it must hash the artifact files using a NIST-approved hashing algorithm. The OSC must provide the Assessment Team with a list of the following for upload into CMMC eMASS.:&lt;br /&gt;
* Names of all artifacts;&lt;br /&gt;
* Return values of the hashing algorithm; and&lt;br /&gt;
* Hashing algorithm.&lt;br /&gt;
: Additional guidance for hashing artifacts can be found in the supplemental guidance document, “CMMC Hashing Guide” available at https://DoDcio.defense.gov/CMMC/.&lt;br /&gt;
&lt;br /&gt;
=== Upload Certification Assessment Results into CMMC eMASS ===&lt;br /&gt;
&#039;&#039;&#039;3.17.&#039;&#039;&#039; A C3PAO quality assurance individual shall upload the certification assessment results into CMMC eMASS. &#039;&#039;&#039;The C3PAO shall follow the CMMC eMASS data standard and upload procedures as set forth in current version of “The Department of Defense CMMC eMASS Concept of Operations for CMMC Third-Party Assessment Organizations”.&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;3.18.&#039;&#039;&#039; C3PAOs may utilize the certification assessment results template provided by DoD (CMMC_AssessmentResults_Template.xlsx) that is available on the CMMC eMASS website.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;3.19.&#039;&#039;&#039; Although CMMC Level 2 certification assessment results at the point of creation may not necessarily meet the formal definition of Controlled Unclassified Information (CUI), &#039;&#039;&#039;C3PAOs and their CMMC Assessment Teams shall process, store, and transmit CMMC Level 2 certification assessment results as if those assessment results, were, in fact, CUI.&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;3.20.&#039;&#039;&#039; &#039;&#039;&#039;Accordingly, the C3PAO shall utilize their IT environment that is resident within their CMMC Level 2 Assessment Scope as assessed by the Defense Industrial Security Cybersecurity Assessment Center (DIBCAC)—as a qualifying condition of their C3PAO authorization or accreditation—for the purposes of accessing and uploading CMMC Level 2 certification assessment results into CMMC eMASS.&#039;&#039;&#039; Specifically, the user workspace that is used to upload CMMC Level 2 certification assessment results to CMMC eMASS shall be one that exists within the scope of the C3PAO’s DIBCAC-assessed environment. There will be no “system-to-system” connections from C3PAOs to CMMC eMASS, so a valid user workspace or end point is required.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;3.21.&#039;&#039;&#039; The C3PAO quality assurance individual shall ensure that the OSC’s hashing data is incorporated into the certification assessment results prior to uploading into CMMC eMASS.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;3.22.&#039;&#039;&#039; Once the certification assessment results are uploaded into CMMC eMASS, if the results warrant a determination of either FINAL or CONDITIONAL CMMC Status of Level 2 (C3PAO) for the OSC, the quality assurance individual will receive from CMMC eMASS the following information: 1) a confirmation of the FINAL or CONDITIONAL CMMC Level 2 Status; 2) an assessment unique Identifier (UID); and 3) the CMMC Status Date of record for the determination.&lt;br /&gt;
&lt;br /&gt;
=== Administer Assessment Appeals (if required) ===&lt;br /&gt;
&#039;&#039;&#039;3.23.&#039;&#039;&#039; The C3PAO shall address any appeals of the Assessment Team’s findings, results, and/or Certificate of CMMC Status determination that is received by the OSC &#039;&#039;&#039;in accordance with 32 CFR §170.9(b)(19)&#039;&#039;&#039; and its own internal assessment appeals process. The OSC must file an initial appeal with the same C3PAO that conducted its CMMC Level 2 certification assessment.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;3.24.&#039;&#039;&#039; The C3PAO shall have an assessment appeals process, in accordance with ISO/IEC 17020 (2012), on file with The Cyber AB. The C3PAO’s assessment appeals process shall have a time- bound, internal appeals process clearly identified to address all appeals received. The C3PAO shall follow its own published assessment appeals process and shall not deviate from the version that is on file with The Cyber AB.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;3.25.&#039;&#039;&#039; A quality assurance individual who is a CCA shall manage within the C3PAO’s assessment appeals process the OSC’s Level 2 certification Assessment Appeal. The quality assurance individual assigned to manage the OSC’s Assessment Appeal &#039;&#039;&#039;cannot be a member of the CMMC Assessment Team that conducted the CMMC Level 2 certification assessment.&#039;&#039;&#039; In addition, if the quality assurance individual managing the OSC Assessment Appeal performed any quality assurance reviews of the assessment in question, that individual shall not be involved in determining the final decision on the Appeal.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;3.26.&#039;&#039;&#039; The C3PAO shall complete its assessment appeals process and render a decision on the OSC’s assessment appeal. The adjudication decision of the assessment appeal must be conveyed to the OSC in writing with its supporting rationale.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;3.27.&#039;&#039;&#039; The C3PAO shall enter the required Assessment Appeal information into the assessment appeals template required for CMMC eMASS. The quality assurance individual managing the OSC’s Assessment Appeal shall perform a quality review of the assessment appeals template prior to it being uploaded to CMMC eMASS.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;3.28.&#039;&#039;&#039; Should the OSC refute or oppose the adjudication decision of their Assessment Appeal by the C3PAO, they may elevate their appeal to The Cyber AB. The OSC must elevate its appeal to The Cyber AB within fifteen (15) business days of receiving the adjudication decision of their Assessment Appeal by the C3PAO in writing. &#039;&#039;&#039;All Assessment Appeals decisions rendered by The Cyber AB are final.&#039;&#039;&#039; The Assessment Appeals Process of The Cyber AB may be found on www.cyberab.org.&lt;br /&gt;
&lt;br /&gt;
== PHASE 4 – ISSUE CERTIFICATE AND CLOSE OUT POA&amp;amp;M ==&lt;br /&gt;
&#039;&#039;&#039;The final phase of the CMMC Level 2 certification assessment centers on the C3PAO issuing a CMMC Level 2 Certificate of CMMC Status to the OSC, as well as closing out any Plan of Action and Milestones (POA&amp;amp;Ms) that might exist.&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;The completion of Phase 4 brings the CMMC Level 2 certification assessment to its formal conclusion.&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
=== Generate Certificate of Status ===&lt;br /&gt;
&#039;&#039;&#039;4.1.&#039;&#039;&#039; Upon receipt from CMMC eMASS of the confirmation of CMMC Level 2 Status (FINAL or CONDITIONAL), the UID, and CMMC Status Date following the submission of the certification assessment results, a quality assurance individual shall generate the Certificate of Status for approval and issuance to the C3PAO.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;4.2.&#039;&#039;&#039; The C3PAO shall only use the standardized CMMC Level 2 Certificate of CMMC Status templates (FINAL and CONDITIONAL) that are approved and provided by The Cyber AB.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;4.3.&#039;&#039;&#039; All C3PAO-generated Certificates of CMMC Status must be approved and signed only by an Authorized Certifying Official that is on file with The Cyber AB.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;4.4.&#039;&#039;&#039; When generating the Certificate of CMMC Status, a quality assurance individual shall enter, affix, or retain the following required information to the document prior to approval and signature by the Authorized Certifying Official:&lt;br /&gt;
: &#039;&#039;&#039;4.4.1.&#039;&#039;&#039; OSC full legal name;&lt;br /&gt;
: &#039;&#039;&#039;4.4.2.&#039;&#039;&#039; All industry CAGE codes associated with the information systems addressed by the CMMC Assessment Scope;&lt;br /&gt;
: &#039;&#039;&#039;4.4.3.&#039;&#039;&#039; Short description of the information system assessed;&lt;br /&gt;
: &#039;&#039;&#039;4.4.4.&#039;&#039;&#039; Unique identifier (UID) received from CMMC eMASS;&lt;br /&gt;
: &#039;&#039;&#039;4.4.5.&#039;&#039;&#039; Dates of assessment (beginning of Phase 1 to date of Out-Brief Meeting);&lt;br /&gt;
: &#039;&#039;&#039;4.4.6.&#039;&#039;&#039; CMMC Status Date;&lt;br /&gt;
: &#039;&#039;&#039;4.4.7.&#039;&#039;&#039; CMMC Level;&lt;br /&gt;
: &#039;&#039;&#039;4.4.8.&#039;&#039;&#039; Statement of conformity to NIST SP 800-171 R2;&lt;br /&gt;
: &#039;&#039;&#039;4.4.9.&#039;&#039;&#039; Name and Logo of C3PAO; &lt;br /&gt;
: &#039;&#039;&#039;4.4.10.&#039;&#039;&#039; Logo of the CMMC Program; &lt;br /&gt;
: &#039;&#039;&#039;4.4.11.&#039;&#039;&#039; C3PAO authorization or accreditation badge with ID number; and 4.4.12. Signature block for Authorized Certifying Official. &lt;br /&gt;
&lt;br /&gt;
=== Issue Certificate of CMMC Status ===&lt;br /&gt;
&#039;&#039;&#039;4.5.&#039;&#039;&#039; Upon generation of the Certificate of CMMC Status, an Authorized Certifying Official shall review and sign the Certificate to convey formal issuance on behalf of the C3PAO.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;4.6.&#039;&#039;&#039; The C3PAO shall produce the approved Certificate of CMMC Status in PDF file format.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;4.7.&#039;&#039;&#039; A C3PAO quality assurance individual shall upload the Certificate of CMMC Status into CMMC eMASS &#039;&#039;&#039;in accordance with the current version of the “Department of Defense CMMC eMASS Concept of Operations for CMMC Third-Party Assessment Organizations”.&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;4.8.&#039;&#039;&#039; The C3PAO shall deliver, either in electronic or physical form, a copy of the CMMC Level 2 Certificate of CMMC Status to the Affirming Official, and the OSC POC. The CMMC Level 2 Certificate of CMMC Status is not considered CUI and is not required to be stored, processed, or transmitted as such.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;4.9.&#039;&#039;&#039; The C3PAO shall deliver an electronic copy of the Certificate of CMMC Status to The Cyber AB via the certificates@cyberab.org account.&lt;br /&gt;
&lt;br /&gt;
=== Close-Out POA&amp;amp;M ===&lt;br /&gt;
&#039;&#039;&#039;4.10.&#039;&#039;&#039; An OSC that has been issued a CONDITIONAL Level 2 Certificate of CMMC Status may retain the services of an authorized or accredited C3PAO to close out a Plan of Action &amp;amp; Milestones (POA&amp;amp;M). The OSC may engage a C3PAO different from the C3PAO that conducted Phases 1 through 3 of the applicable CMMC Level 2 certification assessment and issued the CONDITIONAL Level 2 Certificate of CMMC Status. In this situation, the POA&amp;amp;M Closeout C3PAO assumes the responsibility for FINAL CMMC Status determination and, if the POA&amp;amp;M satisfies the closeout requirements, issues the Level 2 FINAL Certificate of CMMC Status to the OSC.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;4.11.&#039;&#039;&#039; The C3PAO shall conduct and document a conflict-of interest disclosure and mitigation review prior to commencing a POA&amp;amp;M closeout for the OSC.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;4.12.&#039;&#039;&#039; &#039;&#039;&#039;The C3PAO shall follow the procedures and meet the requirements for closing out a POA&amp;amp;M as established in 32 CFR part 170.17(a)(1)(ii)(B).&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;4.13.&#039;&#039;&#039; A quality assurance individual shall conduct a quality assurance review of the POA&amp;amp;M close-out upon completion by the Assessment Team. The C3PAO shall ensure that any individual(s) fulfilling this quality assurance function &#039;&#039;&#039;must be a CCA and cannot be a member of the CMMC Assessment Team conducting the POA&amp;amp;M closeout assessment for which they are performing the quality assurance function.&#039;&#039;&#039;&amp;lt;ref&amp;gt;32 CFR §170.9(14)&amp;lt;/ref&amp;gt;&lt;br /&gt;
 &lt;br /&gt;
&#039;&#039;&#039;4.14.&#039;&#039;&#039; The C3PAO quality assurance review of the POA&amp;amp;M closeout shall, at a minimum, incorporate quality checks on the accuracy and completeness of the evaluation of all POA&amp;amp;M security requirements as well as the conformance to the required reporting formats and incorporated data fields for each. The C3PAO shall conduct the quality assurance review of the CMMC POA&amp;amp;M closeout &#039;&#039;&#039;prior to&#039;&#039;&#039; its upload into CMMC eMASS.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;4.15.&#039;&#039;&#039; The Assessment Team may choose to offer the OSC a POA&amp;amp;M Out-Brief Meeting, but one is not required. The Assessment Team is required to convey the results of the POA&amp;amp;M closeout in writing and convey the remaining administrative next steps to the OSC.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;4.16.&#039;&#039;&#039; In the event the C3PAO refutes the findings of the CMMC Assessment Team during the POA&amp;amp;M closeout, they retain the right to appeal the findings, results, and/or CMMC Level 2 Status decision. The process and timelines for administering and adjudicating a POA&amp;amp;M closeout appeal are identical to those of established in Phase 3, with the exception that the assessment appeals process of the Phase 4 C3PAO that closed out the POA&amp;amp;M is controlling and shall be followed.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;4.17.&#039;&#039;&#039; Upon conclusion of the POA&amp;amp;M closeout and quality assurance review, the C3PAO shall submit the POA&amp;amp;M closeout results to CMMC eMASS. If the POA&amp;amp;M was satisfactorily closed out, the C3PAO shall then issue a FINAL Level 2 Certificate of CMMC Status, utilizing the same procedures and following the same requirements as established above in activities 4.1 through 4.9.&lt;br /&gt;
&lt;br /&gt;
== Notes ==&lt;br /&gt;
&amp;lt;references /&amp;gt;&lt;/div&gt;</summary>
		<author><name>David</name></author>
	</entry>
</feed>