Type to preview results, press Enter to add a filter
100 matching·100 total
CCI-004031
draft Defines the personnel or roles the organization-level; mission/business process-level; and/or system-level identification and authorization policy is disseminated to.
ContributorDISA
Typepolicy
Publish dateMar 2, 2022
CCI-001325
draft The organization defines a time period that the mean time to failure (MTTF) must exceed before the organization manually initiates a transfer between active and standby information system components.
ContributorDISA FSO
Typepolicy
Publish dateSep 22, 2009
CCI-002501
draft Reduce the maximum bandwidth for identified covert storage and/or timing channels to organization-defined values.
ContributorDISA FSO
Typepolicy
Publish dateJul 2, 2013
CCI-003339
draft Require the developer of the system, system component, or system service to internally structure the security-relevant firmware with specific regard for the complete, conceptually simple protection mechanism with precisely defined semantics.
ContributorDISA FSO
Typepolicy
Publish dateOct 3, 2013
CCI-000944
draft The organization controls physical access to the information system by authenticating visitors before authorizing access to the facility where the information system resides other than areas designated as publicly accessible.
ContributorDISA FSO
Typepolicy
Publish dateSep 21, 2009
CCI-004395
draft Ensure that the public has access to information about organizational privacy activities.
ContributorDISA
Typepolicy
Publish dateMar 3, 2022
CCI-005167
draft Access tokens are revoked in accordance with organization-defined identification and authentication policy.
ContributorDISA
Typetechnical
Publish dateJan 23, 2025
CCI-004446
draft Develop organization-defined privacy reports.
ContributorDISA
Typepolicy
Publish dateMar 4, 2022
CCI-001632
draft Protect nonlocal maintenance sessions by separating the maintenance session from other network sessions with the system by either physically separated communications paths or logically separated communications paths based upon encryption.
ContributorDISA FSO
Typetechnical
Publish dateMay 12, 2010
CCI-004252
draft Defines the personnel who are to report anomalies in visitor access records.
ContributorDISA
Typepolicy
Publish dateMar 3, 2022
CCI-003824
draft Implement an audit reduction capability that supports after-the-fact investigations of incidents.
ContributorDISA
Typetechnical
Publish dateMar 2, 2022
CCI-002971
draft Defines the time period within which to resolve deficiencies identified during facility fire protection inspections.
ContributorDISA FSO
Typepolicy
Publish dateAug 29, 2013
CCI-001742
draft Defines the approval authorities to be notified when proposed changes to the system are received.
ContributorDISA FSO
Typepolicy
Publish dateFeb 28, 2013
CCI-000578
draft Review and update the CONOPS in accordance with organization-defined frequency.
ContributorDISA FSO
Typepolicy
Publish dateSep 21, 2009
CCI-003405
draft The organization allocates sufficient organization-defined staffing resources to implement and operate the organization-wide privacy program.
ContributorDISA FSO
Typepolicy
Publish dateNov 7, 2013
CCI-002043
draft The organization uses only FICAM-approved path discovery and validation products and services.
ContributorDISA FSO
Typepolicy
Publish dateMay 3, 2013
CCI-001233
draft The organization employs automated mechanisms on an organization-defined frequency to determine the state of information system components with regard to flaw remediation.
ContributorDISA FSO
Typetechnical
Publish dateSep 22, 2009
CCI-004900
draft Determine the organization-defined cryptographic uses.
ContributorDISA
Typetechnical
Publish dateMar 7, 2022
CCI-001131
draft The organization employs cryptographic mechanisms to prevent unauthorized disclosure of information during transmission unless otherwise protected by alternative physical measures.
ContributorDISA FSO
Typetechnical
Publish dateSep 21, 2009
CCI-000081
draft The organization employs a business case/Exhibit 300/Exhibit 53 to record the resources required.
ContributorDISA FSO
Typepolicy
Publish dateNov 3, 2009
CCI-000061
draft Identify organization-defined user actions that can be performed on the system without identification or authentication consistent with organizational missions/business functions.
ContributorDISA FSO
Typepolicy
Publish dateSep 14, 2009
CCI-002394
draft Protect the availability of resources by allocating organization-defined resources based on priority, quota, and/or organization-defined controls.
ContributorDISA FSO
Typetechnical
Publish dateJul 2, 2013
CCI-004498
draft Develop and document an organization-level; mission/business process-level; and/or system-level personnel security policy that is consistent with applicable laws, Executive Orders, directives, regulations, policies, standards, and guidelines.
ContributorDISA
Typepolicy
Publish dateMar 4, 2022
CCI-000602
draft Develop and document an organization-level; mission/business process-level; and/or system-level system and services acquisition policy that addresses purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance.
ContributorDISA FSO
Typepolicy
Publish dateSep 21, 2009
CCI-000220
deprecated The information system, when transferring information between different security domains, implements policy filters that constrain data structure and content to [Assignment: organization-defined information security policy requirements].
ContributorDISA FSO
Typetechnical
Publish dateSep 14, 2009
CCI-004174
draft Schedule replacement on system components in accordance with manufacturer or vendor specifications and/or organizational requirements.
ContributorDISA
Typepolicy
Publish dateMar 3, 2022
CCI-001738
draft Defines the configurations to be implemented on systems and system components when they are located in areas of significant risk.
ContributorDISA FSO
Typepolicy
Publish dateFeb 28, 2013
CCI-001930
draft Defines the personnel or roles to whom the organization-level; mission/business process-level; and/or system-level audit and accountability policy is to be disseminated.
ContributorDISA FSO
Typepolicy
Publish dateApr 8, 2013
CCI-001988
draft Manage system authenticators by implementing administrative procedures for revoking authenticators.
ContributorDISA FSO
Typepolicy
Publish dateMay 3, 2013
CCI-000865
draft Approve the use of system maintenance tools.
ContributorDISA FSO
Typepolicy
Publish dateSep 18, 2009
CCI-004355
draft Implement a process for ensuring that organizational plans for conducting privacy training activities associated with organizational systems are developed.
ContributorDISA
Typepolicy
Publish dateMar 3, 2022
CCI-000949
draft Defines the frequency with which to review the visitor access records for the facility where the system resides.
ContributorDISA FSO
Typepolicy
Publish dateSep 21, 2009
CCI-001940
draft The device used in the information system implementation of multifactor authentication for network access to non-privileged accounts meets organization-defined strength of mechanism requirements.
ContributorDISA FSO
Typetechnical
Publish dateMay 3, 2013
CCI-004220
draft Test sanitization procedures in accordance with the organization-defined frequency to ensure that the intended sanitization is being achieved.
ContributorDISA
Typepolicy
Publish dateMar 3, 2022
CCI-003481
draft The organization documents processes to ensure the integrity of personally identifiable information (PII) through existing security controls.
ContributorDISA FSO
Typepolicy
Publish dateNov 7, 2013
CCI-004175
draft Document replacement on system components in accordance with manufacturer or vendor specifications and/or organizational requirements.
ContributorDISA
Typepolicy
Publish dateMar 3, 2022
CCI-004525
draft Develop and document organization-level; mission/business process-level; and/or system level personally identifiable information processing and transparency policy that addresses purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance.
ContributorDISA
Typepolicy
Publish dateMar 4, 2022
CCI-002400
draft Audit the identity of internal users associated with denied outgoing communications traffic posing a threat to external systems.
ContributorDISA FSO
Typetechnical
Publish dateJul 2, 2013
CCI-002667
draft Make provisions so that organization-defined encrypted communications traffic is visible to organization-defined system monitoring tools.
ContributorDISA FSO
Typepolicy
Publish dateJul 11, 2013
CCI-003024
draft Defines information security topics to be discussed while conducting exit interviews.
ContributorDISA FSO
Typepolicy
Publish dateSep 12, 2013
CCI-003014
draft Enforce organization-defined mandatory access control policies over all subjects and objects.
ContributorDISA FSO
Typetechnical
Publish dateAug 30, 2013
CCI-002358
draft Implement a reference monitor for organization-defined access control policies that is always invoked.
ContributorDISA FSO
Typetechnical
Publish dateJun 25, 2013
CCI-004521
draft Employ a formal sanctions process for individuals failing to comply with established information security policies.
ContributorDISA
Typepolicy
Publish dateMar 4, 2022
CCI-001580
draft The organization identifies connections to external information systems (i.e., information systems outside of the authorization boundary).
ContributorDISA FSO
Typepolicy
Publish dateMay 11, 2010
CCI-003683
draft When transferring information between different security domains, the process that transfers information between filter pipelines transfers the content to the destination filter pipeline.
ContributorDISA
Typetechnical
Publish dateMar 1, 2022
CCI-003517
draft The organization, where feasible, uses techniques to minimize the risk to privacy of using personally identifiable information (PII) for testing.
ContributorDISA FSO
Typepolicy
Publish dateNov 8, 2013
CCI-000168
draft Defines the time period for retention of audit records, which is consistent with its records retention policy, to provide support for after-the-fact investigations of incidents and meet regulatory and organizational information retention requirements.
ContributorDISA FSO
Typepolicy
Publish dateSep 15, 2009
CCI-002032
draft The organization ensures that authentication decisions are transmitted between organization-defined services consistent with organizational policies.
ContributorDISA FSO
Typepolicy
Publish dateMay 3, 2013
CCI-003668
draft Defines the modification action when transferring information between different security domains.
ContributorDISA
Typepolicy, technical
Publish dateMar 1, 2022
CCI-003000
draft Implement a process for ensuring that organizational plans for conducting security training activities associated with organizational systems are developed.
ContributorDISA FSO
Typepolicy
Publish dateAug 29, 2013
CCI-000029
draft Enforce organization-defined limitations on embedding data types within other data types.
ContributorDISA FSO
Typetechnical
Publish dateMay 13, 2009
CCI-004792
draft Provide the capability to check the integrity of organizational information while it resides in the external system.
ContributorDISA
Typepolicy
Publish dateMar 7, 2022
CCI-004583
draft For systems that process information that will be maintained in a Privacy Act system of records: publish system of records notices in the Federal Register.
ContributorDISA
Typepolicy
Publish dateMar 4, 2022
CCI-001972
draft Manage system identifiers by selecting an identifier that identifies an individual, group, role, or device.
ContributorDISA FSO
Typepolicy
Publish dateMay 3, 2013
CCI-000170
draft Implement a process to ensure that plans of action and milestones for the security program and associated organizational systems document the remedial information security actions to adequately respond to risk to organizational operations and assets, individuals, other organizations, and the Nation.
ContributorDISA FSO
Typepolicy
Publish dateNov 3, 2009
CCI-003028
draft Require terminated individuals to sign an acknowledgment of post-employment requirements as part of the organizational termination process.
ContributorDISA FSO
Typepolicy
Publish dateSep 12, 2013
CCI-003464
draft The organization confirms to the greatest extent practicable upon collection or creation of personally identifiable information (PII), the relevancy of that information.
ContributorDISA FSO
Typepolicy
Publish dateNov 7, 2013
CCI-004597
draft Prohibit the processing of information describing how any individual exercises rights guaranteed by the First Amendment unless expressly authorized by statue or by the individual or unless pertinent to and within the scope of an authorized law enforcement activity.
ContributorDISA
Typepolicy
Publish dateMar 4, 2022
CCI-000208
draft The organization determines normal time-of-day and duration usage for information system accounts.
ContributorDISA FSO
Typepolicy
Publish dateSep 14, 2009
CCI-003523
draft The organization provides appropriate means for individuals to understand the consequences of decisions to approve or decline the authorization of the collection of personally identifiable information (PII).
ContributorDISA FSO
Typepolicy
Publish dateNov 8, 2013
CCI-002482
draft Defines the concealment and misdirection techniques employed for organization-defined systems to confuse and mislead adversaries.
ContributorDISA FSO
Typepolicy
Publish dateJul 2, 2013
CCI-002623
draft Defines the frequency for performing periodic scans of the system for malicious code.
ContributorDISA FSO
Typepolicy
Publish dateJul 11, 2013
CCI-003720
draft Maintain the integrity of organization-defined privacy attributes associated with organization-defined subjects.
ContributorDISA
Typetechnical
Publish dateMar 1, 2022
CCI-001835
deprecated The organization defines the frequency on which it will review the audit and accountability policy.
ContributorDISA FSO
Typepolicy
Publish dateMar 14, 2013
CCI-000574
draft Update the plans to address changes to the system and environment of operation or problems identified during plan implementation or control assessments.
ContributorDISA FSO
Typepolicy
Publish dateSep 21, 2009
CCI-004181
draft Defines the information to be removed from associated media.
ContributorDISA
Typepolicy
Publish dateMar 3, 2022
CCI-003949
draft Require that organization-defined user-installed software in a confined physical or virtual machine environment with limited privileges.
ContributorDISA
Typepolicy
Publish dateMar 2, 2022
CCI-002553
draft Defines the measures to be employed to ensure data or information collected by organization-defined sensors is used only for authorized purposes.
ContributorDISA FSO
Typepolicy
Publish dateJul 2, 2013
CCI-004039
draft Defines the official designated to managing the development, documentation, and dissemination of the identification and authentication policy.
ContributorDISA
Typepolicy
Publish dateMar 2, 2022
CCI-001557
draft The information system tracks problems associated with the information transfer.
ContributorDISA FSO
Typetechnical
Publish dateMay 11, 2010
CCI-002446
draft Produce asymmetric cryptographic keys using: NSA-approved key management technology and processes; prepositioned keying material; DoD-approved or DoD-issued Medium Assurance PKI certificates; DoD-approved or DoD-issued Medium Hardware Assurance PKI certificates and hardware security tokens that protect the user's private key; or certificates issued in accordance with organization-defined requirements.
ContributorDISA FSO
Typepolicy
Publish dateJul 2, 2013
CCI-004394
draft Maintain a central resource webpage on the organization's principle public website that serves as a central source of information about the organization's privacy plan.
ContributorDISA
Typepolicy
Publish dateMar 3, 2022
CCI-000847
draft The organization defines the frequency for reviewing the incident response plan.
ContributorDISA FSO
Typepolicy
Publish dateSep 18, 2009
CCI-002841
draft Defines the system operations to be resumed for essential business functions within the organization-defined time period when the primary telecommunications capabilities are unavailable at either the primary or alternate processing or storage sites.
ContributorDISA FSO
Typepolicy
Publish dateJul 20, 2013
CCI-004257
draft Defines the automatic environmental controls for preventing potentially harmful fluctuations to the system.
ContributorDISA
Typepolicy
Publish dateMar 3, 2022
CCI-001058
draft Analyze vulnerability scan reports and results from vulnerability monitoring.
ContributorDISA FSO
Typepolicy
Publish dateSep 21, 2009
CCI-001388
draft For publicly accessible systems, includes a description of the authorized uses of the system.
ContributorDISA FSO
Typetechnical
Publish dateSep 22, 2009
CCI-000776
draft The information system uses organization-defined replay-resistant authentication mechanisms for network access to non-privileged accounts.
ContributorDISA FSO
Typetechnical
Publish dateSep 17, 2009
CCI-002925
draft Defines the physical access devices to inventory.
ContributorDISA FSO
Typepolicy
Publish dateAug 27, 2013
CCI-003021
draft Defines additional personnel screening criteria that individuals accessing a system processing, storing, or transmitting information requiring protection must satisfy.
ContributorDISA FSO
Typepolicy
Publish dateSep 12, 2013
CCI-001824
draft Defines the organizational personnel or roles to whom the organization-level; mission/business process-level; and/or system-level configuration management procedures are to be disseminated.
ContributorDISA FSO
Typepolicy
Publish dateMar 1, 2013
CCI-004100
draft Require that the presented identity evidence be validated through organizational defined methods of validation.
ContributorDISA
Typepolicy
Publish dateMar 2, 2022
CCI-003026
draft The organization defines the time period within which to notify organization-defined personnel or roles upon termination of individual employment.
ContributorDISA FSO
Typepolicy
Publish dateSep 12, 2013
CCI-003477
draft The organization issues guidelines maximizing the integrity of disseminated Privacy Act information.
ContributorDISA FSO
Typepolicy
Publish dateNov 7, 2013
CCI-001579
draft The organization conducts security control assessments using organization-defined forms of testing in accordance with organization-defined frequency and assessment techniques.
ContributorDISA FSO
Typepolicy
Publish dateMay 11, 2010
CCI-001680
draft Develop an organization-wide information security program plan that includes the identification and assignment of roles, responsibilities, management commitment, coordination among organizational entities, and compliance.
ContributorDISA FSO
Typepolicy
Publish dateJun 9, 2010
CCI-004669
draft Acquire the system using an organization-defined system development life cycle that incorporates information security considerations.
ContributorDISA
Typepolicy
Publish dateMar 4, 2022
CCI-004692
deprecated Include the requirements for protecting security documentation, explicitly or by reference, using standardized contract language; and/or organization-defined contract language in the acquisition contract for the information system, system component, or information system service.
ContributorDISA
Typepolicy
Publish dateMar 4, 2022
CCI-004991
draft Defines alternative action(s) to be taken when anomalies in the operation of organization-defined privacy functions are discovered.
ContributorDISA
Typepolicy
Publish dateMar 7, 2022
CCI-004402
draft Develop and post privacy policies on all external-facing websites, mobile applications, and other digital services that are updated whenever the organization makes a substantive change to the practices it describes.
ContributorDISA
Typepolicy
Publish dateMar 3, 2022
CCI-001609
draft Activate the redundant secondary system that is not collocated with the primary system without loss of information or disruption to operations.
ContributorDISA FSO
Typepolicy
Publish dateMay 12, 2010
CCI-004581
draft For systems that process information that will be maintained in a Privacy Act system of records: draft system of records notices in accordance with OMB guidance.
ContributorDISA
Typepolicy
Publish dateMar 4, 2022
CCI-002369
draft Defines the personnel or roles to whom the risk assessment procedures are disseminated.
ContributorDISA FSO
Typepolicy
Publish dateJul 1, 2013
CCI-002040
draft The organization requires that the registration process to receive an individual identifier includes supervisor authorization.
ContributorDISA FSO
Typepolicy
Publish dateMay 3, 2013
CCI-004240
draft Enforce physical access authorizations at organization-defined entry points to the facility where the system resides.
ContributorDISA
Typepolicy
Publish dateMar 3, 2022
CCI-003660
draft Defines the discretionary access control policies the system is to enforce over subjects and objects.
ContributorDISA
Typetechnical
Publish dateMar 1, 2022
CCI-001836
deprecated The organization defines the frequency on which it will update the audit and accountability policy.
ContributorDISA FSO
Typepolicy
Publish dateMar 14, 2013
CCI-000573
draft Review the plans in accordance with organization-defined frequency.
ContributorDISA FSO
Typepolicy
Publish dateSep 21, 2009
CCI-000279
draft Implement ongoing control assessments in accordance with the continuous monitoring strategy.
ContributorDISA FSO
Typepolicy
Publish dateSep 15, 2009
CCI-004805
draft Conduct the modeling and analyses as the following level of rigor.
ContributorDISA
Typepolicy
Publish dateMar 7, 2022