Common Control Identifiers (CCIs)CCIs

Repository

Type to preview results, press Enter to add a filter

100 matching100 total

CCI-004031

draft
Definition
Defines the personnel or roles the organization-level; mission/business process-level; and/or system-level identification and authorization policy is disseminated to.
ContributorDISA
Typepolicy
Publish dateMar 2, 2022
NISTv5
NIST SP 800-53 Revision 5
Control: IA-1 a 1
View document

CCI-001325

draft
Definition
The organization defines a time period that the mean time to failure (MTTF) must exceed before the organization manually initiates a transfer between active and standby information system components.
ContributorDISA FSO
Typepolicy
Publish dateSep 22, 2009
NISTv1
NIST SP 800-53A
Control: SI-13 (3).1 (ii)
View document
NISTv3
NIST SP 800-53
Control: SI-13 (3)
View document
NISTv4
NIST SP 800-53 Revision 4
Control: SI-13 (3)
View document

CCI-002501

draft
Definition
Reduce the maximum bandwidth for identified covert storage and/or timing channels to organization-defined values.
ContributorDISA FSO
Typepolicy
Publish dateJul 2, 2013
NISTv4
NIST SP 800-53 Revision 4
Control: SC-31 (2)
View document
NISTv5
NIST SP 800-53 Revision 5
Control: SC-31 (2)
View document

CCI-003339

draft
Definition
Require the developer of the system, system component, or system service to internally structure the security-relevant firmware with specific regard for the complete, conceptually simple protection mechanism with precisely defined semantics.
ContributorDISA FSO
Typepolicy
Publish dateOct 3, 2013
NISTv4
NIST SP 800-53 Revision 4
Control: SA-17 (5) (b)
View document
NISTv5
NIST SP 800-53 Revision 5
Control: SA-17 (5) (b)
View document

CCI-000944

draft
Definition
The organization controls physical access to the information system by authenticating visitors before authorizing access to the facility where the information system resides other than areas designated as publicly accessible.
ContributorDISA FSO
Typepolicy
Publish dateSep 21, 2009
NISTv1
NIST SP 800-53A
Control: PE-7.1
View document
NISTv3
NIST SP 800-53
Control: PE-7
View document

CCI-004395

draft
Definition
Ensure that the public has access to information about organizational privacy activities.
ContributorDISA
Typepolicy
Publish dateMar 3, 2022
NISTv5
NIST SP 800-53 Revision 5
Control: PM-20 a
View document

CCI-005167

draft
Definition
Access tokens are revoked in accordance with organization-defined identification and authentication policy.
ContributorDISA
Typetechnical
Publish dateJan 23, 2025
NISTv5
NIST SP 800-53 Revision 5
Control: IA-13 (03) (d)
View document

CCI-004446

draft
Definition
Develop organization-defined privacy reports.
ContributorDISA
Typepolicy
Publish dateMar 4, 2022
NISTv5
NIST SP 800-53 Revision 5
Control: PM-27
View document

CCI-001632

draft
Definition
Protect nonlocal maintenance sessions by separating the maintenance session from other network sessions with the system by either physically separated communications paths or logically separated communications paths based upon encryption.
ContributorDISA FSO
Typetechnical
Publish dateMay 12, 2010
NISTv1
NIST SP 800-53A
Control: MA-4 (4).1 (ii)
View document
NISTv3
NIST SP 800-53
Control: MA-4 (4) (a) (b)
View document
NISTv4
NIST SP 800-53 Revision 4
Control: MA-4 (4) (b)
View document
NISTv5
NIST SP 800-53 Revision 5
Control: MA-4 (4) (b) (1)
View document

CCI-004252

draft
Definition
Defines the personnel who are to report anomalies in visitor access records.
ContributorDISA
Typepolicy
Publish dateMar 3, 2022
NISTv5
NIST SP 800-53 Revision 5
Control: PE-8 c
View document

CCI-003824

draft
Definition
Implement an audit reduction capability that supports after-the-fact investigations of incidents.
ContributorDISA
Typetechnical
Publish dateMar 2, 2022
NISTv5
NIST SP 800-53 Revision 5
Control: AU-7 a
View document

CCI-002971

draft
Definition
Defines the time period within which to resolve deficiencies identified during facility fire protection inspections.
ContributorDISA FSO
Typepolicy
Publish dateAug 29, 2013
NISTv4
NIST SP 800-53 Revision 4
Control: PE-13 (4)
View document
NISTv5
NIST SP 800-53 Revision 5
Control: PE-13 (4)
View document

CCI-001742

draft
Definition
Defines the approval authorities to be notified when proposed changes to the system are received.
ContributorDISA FSO
Typepolicy
Publish dateFeb 28, 2013
NISTv4
NIST SP 800-53 Revision 4
Control: CM-3 (1) (b)
View document
NISTv5
NIST SP 800-53 Revision 5
Control: CM-3 (1) (b)
View document

CCI-003405

draft
Definition
The organization allocates sufficient organization-defined staffing resources to implement and operate the organization-wide privacy program.
ContributorDISA FSO
Typepolicy
Publish dateNov 7, 2013
NISTv4
NIST SP 800-53 Revision 4
Control: AR-1 c
View document

CCI-002043

draft
Definition
The organization uses only FICAM-approved path discovery and validation products and services.
ContributorDISA FSO
Typepolicy
Publish dateMay 3, 2013
NISTv4
NIST SP 800-53 Revision 4
Control: IA-5 (15)
View document

CCI-001233

draft
Definition
The organization employs automated mechanisms on an organization-defined frequency to determine the state of information system components with regard to flaw remediation.
ContributorDISA FSO
Typetechnical
Publish dateSep 22, 2009
NISTv1
NIST SP 800-53A
Control: SI-2 (2).1 (ii)
View document
NISTv3
NIST SP 800-53
Control: SI-2 (2)
View document
NISTv4
NIST SP 800-53 Revision 4
Control: SI-2 (2)
View document

CCI-004900

draft
Definition
Determine the organization-defined cryptographic uses.
ContributorDISA
Typetechnical
Publish dateMar 7, 2022
NISTv5
NIST SP 800-53 Revision 5
Control: SC-13 a
View document

CCI-001131

draft
Definition
The organization employs cryptographic mechanisms to prevent unauthorized disclosure of information during transmission unless otherwise protected by alternative physical measures.
ContributorDISA FSO
Typetechnical
Publish dateSep 21, 2009
NISTv1
NIST SP 800-53A
Control: SC-9 (1).1
View document
NISTv3
NIST SP 800-53
Control: SC-9 (1)
View document

CCI-000081

draft
Definition
The organization employs a business case/Exhibit 300/Exhibit 53 to record the resources required.
ContributorDISA FSO
Typepolicy
Publish dateNov 3, 2009
NISTv1
NIST SP 800-53A
Control: PM-3.1 (iii)
View document
NISTv3
NIST SP 800-53
Control: PM-3 b
View document
NISTv4
NIST SP 800-53 Revision 4
Control: PM-3 b
View document

CCI-000061

draft
Definition
Identify organization-defined user actions that can be performed on the system without identification or authentication consistent with organizational missions/business functions.
ContributorDISA FSO
Typepolicy
Publish dateSep 14, 2009
NISTv1
NIST SP 800-53A
Control: AC-14.1 (i)
View document
NISTv3
NIST SP 800-53
Control: AC-14 a
View document
NISTv4
NIST SP 800-53 Revision 4
Control: AC-14 a
View document
NISTv5
NIST SP 800-53 Revision 5
Control: AC-14 a
View document

CCI-002394

draft
Definition
Protect the availability of resources by allocating organization-defined resources based on priority, quota, and/or organization-defined controls.
ContributorDISA FSO
Typetechnical
Publish dateJul 2, 2013
NISTv4
NIST SP 800-53 Revision 4
Control: SC-6
View document
NISTv5
NIST SP 800-53 Revision 5
Control: SC-6
View document

CCI-004498

draft
Definition
Develop and document an organization-level; mission/business process-level; and/or system-level personnel security policy that is consistent with applicable laws, Executive Orders, directives, regulations, policies, standards, and guidelines.
ContributorDISA
Typepolicy
Publish dateMar 4, 2022
NISTv5
NIST SP 800-53 Revision 5
Control: PS-1 a 1 (b)
View document

CCI-000602

draft
Definition
Develop and document an organization-level; mission/business process-level; and/or system-level system and services acquisition policy that addresses purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance.
ContributorDISA FSO
Typepolicy
Publish dateSep 21, 2009
NISTv1
NIST SP 800-53A
Control: SA-1.1 (i) (ii)
View document
NISTv3
NIST SP 800-53
Control: SA-1 a
View document
NISTv4
NIST SP 800-53 Revision 4
Control: SA-1 a 1
View document
NISTv5
NIST SP 800-53 Revision 5
Control: SA-1 a 1 (a)
View document

CCI-000220

deprecated
Definition
The information system, when transferring information between different security domains, implements policy filters that constrain data structure and content to [Assignment: organization-defined information security policy requirements].
ContributorDISA FSO
Typetechnical
Publish dateSep 14, 2009

CCI-004174

draft
Definition
Schedule replacement on system components in accordance with manufacturer or vendor specifications and/or organizational requirements.
ContributorDISA
Typepolicy
Publish dateMar 3, 2022
NISTv5
NIST SP 800-53 Revision 5
Control: MA-2 a
View document

CCI-001738

draft
Definition
Defines the configurations to be implemented on systems and system components when they are located in areas of significant risk.
ContributorDISA FSO
Typepolicy
Publish dateFeb 28, 2013
NISTv4
NIST SP 800-53 Revision 4
Control: CM-2 (7) (a)
View document
NISTv5
NIST SP 800-53 Revision 5
Control: CM-2 (7) (a)
View document

CCI-001930

draft
Definition
Defines the personnel or roles to whom the organization-level; mission/business process-level; and/or system-level audit and accountability policy is to be disseminated.
ContributorDISA FSO
Typepolicy
Publish dateApr 8, 2013
NISTv4
NIST SP 800-53 Revision 4
Control: AU-1 a 1
View document
NISTv5
NIST SP 800-53 Revision 5
Control: AU-1 a 1
View document

CCI-001988

draft
Definition
Manage system authenticators by implementing administrative procedures for revoking authenticators.
ContributorDISA FSO
Typepolicy
Publish dateMay 3, 2013
NISTv4
NIST SP 800-53 Revision 4
Control: IA-5 d
View document
NISTv5
NIST SP 800-53 Revision 5
Control: IA-5 d
View document

CCI-004355

draft
Definition
Implement a process for ensuring that organizational plans for conducting privacy training activities associated with organizational systems are developed.
ContributorDISA
Typepolicy
Publish dateMar 3, 2022
NISTv5
NIST SP 800-53 Revision 5
Control: PM-14 a 1
View document

CCI-001940

draft
Definition
The device used in the information system implementation of multifactor authentication for network access to non-privileged accounts meets organization-defined strength of mechanism requirements.
ContributorDISA FSO
Typetechnical
Publish dateMay 3, 2013
NISTv4
NIST SP 800-53 Revision 4
Control: IA-2 (7)
View document

CCI-004220

draft
Definition
Test sanitization procedures in accordance with the organization-defined frequency to ensure that the intended sanitization is being achieved.
ContributorDISA
Typepolicy
Publish dateMar 3, 2022
NISTv5
NIST SP 800-53 Revision 5
Control: MP-6 (2)
View document

CCI-003481

draft
Definition
The organization documents processes to ensure the integrity of personally identifiable information (PII) through existing security controls.
ContributorDISA FSO
Typepolicy
Publish dateNov 7, 2013
NISTv4
NIST SP 800-53 Revision 4
Control: DI-2 a
View document

CCI-004175

draft
Definition
Document replacement on system components in accordance with manufacturer or vendor specifications and/or organizational requirements.
ContributorDISA
Typepolicy
Publish dateMar 3, 2022
NISTv5
NIST SP 800-53 Revision 5
Control: MA-2 a
View document

CCI-004525

draft
Definition
Develop and document organization-level; mission/business process-level; and/or system level personally identifiable information processing and transparency policy that addresses purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance.
ContributorDISA
Typepolicy
Publish dateMar 4, 2022
NISTv5
NIST SP 800-53 Revision 5
Control: PT-1 a 1 (a)
View document

CCI-002400

draft
Definition
Audit the identity of internal users associated with denied outgoing communications traffic posing a threat to external systems.
ContributorDISA FSO
Typetechnical
Publish dateJul 2, 2013
NISTv4
NIST SP 800-53 Revision 4
Control: SC-7 (9) (b)
View document
NISTv5
NIST SP 800-53 Revision 5
Control: SC-7 (9) (b)
View document

CCI-002667

draft
Definition
Make provisions so that organization-defined encrypted communications traffic is visible to organization-defined system monitoring tools.
ContributorDISA FSO
Typepolicy
Publish dateJul 11, 2013
NISTv4
NIST SP 800-53 Revision 4
Control: SI-4 (10)
View document
NISTv5
NIST SP 800-53 Revision 5
Control: SI-4 (10)
View document

CCI-003024

draft
Definition
Defines information security topics to be discussed while conducting exit interviews.
ContributorDISA FSO
Typepolicy
Publish dateSep 12, 2013
NISTv4
NIST SP 800-53 Revision 4
Control: PS-4 c
View document
NISTv5
NIST SP 800-53 Revision 5
Control: PS-4 c
View document

CCI-003014

draft
Definition
Enforce organization-defined mandatory access control policies over all subjects and objects.
ContributorDISA FSO
Typetechnical
Publish dateAug 30, 2013
NISTv4
NIST SP 800-53 Revision 4
Control: AC-3 (3)
View document
NISTv5
NIST SP 800-53 Revision 5
Control: AC-3 (3)
View document

CCI-002358

draft
Definition
Implement a reference monitor for organization-defined access control policies that is always invoked.
ContributorDISA FSO
Typetechnical
Publish dateJun 25, 2013
NISTv4
NIST SP 800-53 Revision 4
Control: AC-25
View document
NISTv5
NIST SP 800-53 Revision 5
Control: AC-25
View document

CCI-004521

draft
Definition
Employ a formal sanctions process for individuals failing to comply with established information security policies.
ContributorDISA
Typepolicy
Publish dateMar 4, 2022
NISTv5
NIST SP 800-53 Revision 5
Control: PS-8 a
View document

CCI-001580

draft
Definition
The organization identifies connections to external information systems (i.e., information systems outside of the authorization boundary).
ContributorDISA FSO
Typepolicy
Publish dateMay 11, 2010
NISTv1
NIST SP 800-53A
Control: CA-3.1 (i)
View document
NISTv3
NIST SP 800-53
Control: CA-3 b
View document

CCI-003683

draft
Definition
When transferring information between different security domains, the process that transfers information between filter pipelines transfers the content to the destination filter pipeline.
ContributorDISA
Typetechnical
Publish dateMar 1, 2022
NISTv5
NIST SP 800-53 Revision 5
Control: AC-4 (32) (d)
View document

CCI-003517

draft
Definition
The organization, where feasible, uses techniques to minimize the risk to privacy of using personally identifiable information (PII) for testing.
ContributorDISA FSO
Typepolicy
Publish dateNov 8, 2013
NISTv4
NIST SP 800-53 Revision 4
Control: DM-3 (1)
View document

CCI-000168

draft
Definition
Defines the time period for retention of audit records, which is consistent with its records retention policy, to provide support for after-the-fact investigations of incidents and meet regulatory and organizational information retention requirements.
ContributorDISA FSO
Typepolicy
Publish dateSep 15, 2009
NISTv1
NIST SP 800-53A
Control: AU-11.1 (i and ii)
View document
NISTv3
NIST SP 800-53
Control: AU-11
View document
NISTv4
NIST SP 800-53 Revision 4
Control: AU-11
View document
NISTv5
NIST SP 800-53 Revision 5
Control: AU-11
View document

CCI-002032

draft
Definition
The organization ensures that authentication decisions are transmitted between organization-defined services consistent with organizational policies.
ContributorDISA FSO
Typepolicy
Publish dateMay 3, 2013
NISTv4
NIST SP 800-53 Revision 4
Control: IA-9 (2)
View document

CCI-003668

draft
Definition
Defines the modification action when transferring information between different security domains.
ContributorDISA
Typepolicy, technical
Publish dateMar 1, 2022
NISTv5
NIST SP 800-53 Revision 5
Control: AC-4 (23)
View document

CCI-003000

draft
Definition
Implement a process for ensuring that organizational plans for conducting security training activities associated with organizational systems are developed.
ContributorDISA FSO
Typepolicy
Publish dateAug 29, 2013
NISTv4
NIST SP 800-53 Revision 4
Control: PM-14 a 1
View document
NISTv5
NIST SP 800-53 Revision 5
Control: PM-14 a 1
View document

CCI-004792

draft
Definition
Provide the capability to check the integrity of organizational information while it resides in the external system.
ContributorDISA
Typepolicy
Publish dateMar 7, 2022
NISTv5
NIST SP 800-53 Revision 5
Control: SA-9 (7)
View document

CCI-004583

draft
Definition
For systems that process information that will be maintained in a Privacy Act system of records: publish system of records notices in the Federal Register.
ContributorDISA
Typepolicy
Publish dateMar 4, 2022
NISTv5
NIST SP 800-53 Revision 5
Control: PT-6 b
View document

CCI-001972

draft
Definition
Manage system identifiers by selecting an identifier that identifies an individual, group, role, or device.
ContributorDISA FSO
Typepolicy
Publish dateMay 3, 2013
NISTv4
NIST SP 800-53 Revision 4
Control: IA-4 b
View document
NISTv5
NIST SP 800-53 Revision 5
Control: IA-4 b
View document

CCI-000170

draft
Definition
Implement a process to ensure that plans of action and milestones for the security program and associated organizational systems document the remedial information security actions to adequately respond to risk to organizational operations and assets, individuals, other organizations, and the Nation.
ContributorDISA FSO
Typepolicy
Publish dateNov 3, 2009
NISTv1
NIST SP 800-53A
Control: PM-4.1 (ii)
View document
NISTv3
NIST SP 800-53
Control: PM-4
View document
NISTv4
NIST SP 800-53 Revision 4
Control: PM-4 a 2
View document
NISTv5
NIST SP 800-53 Revision 5
Control: PM-4 a 2
View document

CCI-003028

draft
Definition
Require terminated individuals to sign an acknowledgment of post-employment requirements as part of the organizational termination process.
ContributorDISA FSO
Typepolicy
Publish dateSep 12, 2013
NISTv4
NIST SP 800-53 Revision 4
Control: PS-4 (1) (b)
View document
NISTv5
NIST SP 800-53 Revision 5
Control: PS-4 (1) (b)
View document

CCI-003464

draft
Definition
The organization confirms to the greatest extent practicable upon collection or creation of personally identifiable information (PII), the relevancy of that information.
ContributorDISA FSO
Typepolicy
Publish dateNov 7, 2013
NISTv4
NIST SP 800-53 Revision 4
Control: DI-1 a
View document

CCI-004597

draft
Definition
Prohibit the processing of information describing how any individual exercises rights guaranteed by the First Amendment unless expressly authorized by statue or by the individual or unless pertinent to and within the scope of an authorized law enforcement activity.
ContributorDISA
Typepolicy
Publish dateMar 4, 2022
NISTv5
NIST SP 800-53 Revision 5
Control: PT-7 (2)
View document

CCI-000208

draft
Definition
The organization determines normal time-of-day and duration usage for information system accounts.
ContributorDISA FSO
Typepolicy
Publish dateSep 14, 2009
NISTv1
NIST SP 800-53A
Control: AC-2 (5).1 (iii)
View document
NISTv3
NIST SP 800-53
Control: AC-2 (5) (b)
View document

CCI-003523

draft
Definition
The organization provides appropriate means for individuals to understand the consequences of decisions to approve or decline the authorization of the collection of personally identifiable information (PII).
ContributorDISA FSO
Typepolicy
Publish dateNov 8, 2013
NISTv4
NIST SP 800-53 Revision 4
Control: IP-1 b
View document

CCI-002482

draft
Definition
Defines the concealment and misdirection techniques employed for organization-defined systems to confuse and mislead adversaries.
ContributorDISA FSO
Typepolicy
Publish dateJul 2, 2013
NISTv4
NIST SP 800-53 Revision 4
Control: SC-30
View document
NISTv5
NIST SP 800-53 Revision 5
Control: SC-30
View document

CCI-002623

draft
Definition
Defines the frequency for performing periodic scans of the system for malicious code.
ContributorDISA FSO
Typepolicy
Publish dateJul 11, 2013
NISTv4
NIST SP 800-53 Revision 4
Control: SI-3 c 1
View document
NISTv5
NIST SP 800-53 Revision 5
Control: SI-3 c 1
View document

CCI-003720

draft
Definition
Maintain the integrity of organization-defined privacy attributes associated with organization-defined subjects.
ContributorDISA
Typetechnical
Publish dateMar 1, 2022
NISTv5
NIST SP 800-53 Revision 5
Control: AC-16 (3)
View document

CCI-001835

deprecated
Definition
The organization defines the frequency on which it will review the audit and accountability policy.
ContributorDISA FSO
Typepolicy
Publish dateMar 14, 2013
NISTv4
NIST SP 800-53 Revision 4
Control: AU-1 b 1
View document

CCI-000574

draft
Definition
Update the plans to address changes to the system and environment of operation or problems identified during plan implementation or control assessments.
ContributorDISA FSO
Typepolicy
Publish dateSep 21, 2009
NISTv1
NIST SP 800-53A
Control: PL-2.1 (iv)
View document
NISTv3
NIST SP 800-53
Control: PL-2 c
View document
NISTv4
NIST SP 800-53 Revision 4
Control: PL-2 d
View document
NISTv5
NIST SP 800-53 Revision 5
Control: PL-2 d
View document

CCI-004181

draft
Definition
Defines the information to be removed from associated media.
ContributorDISA
Typepolicy
Publish dateMar 3, 2022
NISTv5
NIST SP 800-53 Revision 5
Control: MA-2 d
View document

CCI-003949

draft
Definition
Require that organization-defined user-installed software in a confined physical or virtual machine environment with limited privileges.
ContributorDISA
Typepolicy
Publish dateMar 2, 2022
NISTv5
NIST SP 800-53 Revision 5
Control: CM-7 (6)
View document

CCI-002553

draft
Definition
Defines the measures to be employed to ensure data or information collected by organization-defined sensors is used only for authorized purposes.
ContributorDISA FSO
Typepolicy
Publish dateJul 2, 2013
NISTv4
NIST SP 800-53 Revision 4
Control: SC-42 (2)
View document
NISTv5
NIST SP 800-53 Revision 5
Control: SC-42 (2)
View document

CCI-004039

draft
Definition
Defines the official designated to managing the development, documentation, and dissemination of the identification and authentication policy.
ContributorDISA
Typepolicy
Publish dateMar 2, 2022
NISTv5
NIST SP 800-53 Revision 5
Control: IA-1 b
View document

CCI-001557

draft
Definition
The information system tracks problems associated with the information transfer.
ContributorDISA FSO
Typetechnical
Publish dateMay 11, 2010
NISTv1
NIST SP 800-53A
Control: AC-4 (17).1 (vii)
View document
NISTv3
NIST SP 800-53
Control: AC-4 (17) c
View document

CCI-002446

draft
Definition
Produce asymmetric cryptographic keys using: NSA-approved key management technology and processes; prepositioned keying material; DoD-approved or DoD-issued Medium Assurance PKI certificates; DoD-approved or DoD-issued Medium Hardware Assurance PKI certificates and hardware security tokens that protect the user's private key; or certificates issued in accordance with organization-defined requirements.
ContributorDISA FSO
Typepolicy
Publish dateJul 2, 2013
NISTv4
NIST SP 800-53 Revision 4
Control: SC-12 (3)
View document
NISTv5
NIST SP 800-53 Revision 5
Control: SC-12 (3)
View document

CCI-004394

draft
Definition
Maintain a central resource webpage on the organization's principle public website that serves as a central source of information about the organization's privacy plan.
ContributorDISA
Typepolicy
Publish dateMar 3, 2022
NISTv5
NIST SP 800-53 Revision 5
Control: PM-20
View document

CCI-000847

draft
Definition
The organization defines the frequency for reviewing the incident response plan.
ContributorDISA FSO
Typepolicy
Publish dateSep 18, 2009
NISTv1
NIST SP 800-53A
Control: IR-8.2 (iii)
View document
NISTv3
NIST SP 800-53
Control: IR-8 c
View document
NISTv4
NIST SP 800-53 Revision 4
Control: IR-8 c
View document

CCI-002841

draft
Definition
Defines the system operations to be resumed for essential business functions within the organization-defined time period when the primary telecommunications capabilities are unavailable at either the primary or alternate processing or storage sites.
ContributorDISA FSO
Typepolicy
Publish dateJul 20, 2013
NISTv4
NIST SP 800-53 Revision 4
Control: CP-8
View document
NISTv5
NIST SP 800-53 Revision 5
Control: CP-8
View document

CCI-004257

draft
Definition
Defines the automatic environmental controls for preventing potentially harmful fluctuations to the system.
ContributorDISA
Typepolicy
Publish dateMar 3, 2022
NISTv5
NIST SP 800-53 Revision 5
Control: PE-14 (1)
View document

CCI-000776

draft
Definition
The information system uses organization-defined replay-resistant authentication mechanisms for network access to non-privileged accounts.
ContributorDISA FSO
Typetechnical
Publish dateSep 17, 2009
NISTv1
NIST SP 800-53A
Control: IA-2 (9).1 (ii)
View document
NISTv3
NIST SP 800-53
Control: IA-2 (9)
View document

CCI-002925

draft
Definition
Defines the physical access devices to inventory.
ContributorDISA FSO
Typepolicy
Publish dateAug 27, 2013
NISTv4
NIST SP 800-53 Revision 4
Control: PE-3 f
View document
NISTv5
NIST SP 800-53 Revision 5
Control: PE-3 f
View document

CCI-003021

draft
Definition
Defines additional personnel screening criteria that individuals accessing a system processing, storing, or transmitting information requiring protection must satisfy.
ContributorDISA FSO
Typepolicy
Publish dateSep 12, 2013
NISTv4
NIST SP 800-53 Revision 4
Control: PS-3 (3) (b)
View document
NISTv5
NIST SP 800-53 Revision 5
Control: PS-3 (3) (b)
View document

CCI-001824

draft
Definition
Defines the organizational personnel or roles to whom the organization-level; mission/business process-level; and/or system-level configuration management procedures are to be disseminated.
ContributorDISA FSO
Typepolicy
Publish dateMar 1, 2013
NISTv4
NIST SP 800-53 Revision 4
Control: CM-1 a 2
View document
NISTv5
NIST SP 800-53 Revision 5
Control: CM-1 a 2
View document

CCI-004100

draft
Definition
Require that the presented identity evidence be validated through organizational defined methods of validation.
ContributorDISA
Typepolicy
Publish dateMar 2, 2022
NISTv5
NIST SP 800-53 Revision 5
Control: IA-12 (3)
View document

CCI-003026

draft
Definition
The organization defines the time period within which to notify organization-defined personnel or roles upon termination of individual employment.
ContributorDISA FSO
Typepolicy
Publish dateSep 12, 2013
NISTv4
NIST SP 800-53 Revision 4
Control: PS-4 f
View document

CCI-003477

draft
Definition
The organization issues guidelines maximizing the integrity of disseminated Privacy Act information.
ContributorDISA FSO
Typepolicy
Publish dateNov 7, 2013
NISTv4
NIST SP 800-53 Revision 4
Control: DI-1 d
View document

CCI-001579

draft
Definition
The organization conducts security control assessments using organization-defined forms of testing in accordance with organization-defined frequency and assessment techniques.
ContributorDISA FSO
Typepolicy
Publish dateMay 11, 2010
NISTv1
NIST SP 800-53A
Control: CA-2 (2).1 (ii)
View document
NISTv3
NIST SP 800-53
Control: CA-2 (2)
View document

CCI-001680

draft
Definition
Develop an organization-wide information security program plan that includes the identification and assignment of roles, responsibilities, management commitment, coordination among organizational entities, and compliance.
ContributorDISA FSO
Typepolicy
Publish dateJun 9, 2010
NISTv1
NIST SP 800-53A
Control: PM-1.1 (i)
View document
NISTv3
NIST SP 800-53
Control: PM-1 a
View document
NISTv4
NIST SP 800-53 Revision 4
Control: PM-1 a 2
View document
NISTv5
NIST SP 800-53 Revision 5
Control: PM-1 a 2
View document

CCI-004669

draft
Definition
Acquire the system using an organization-defined system development life cycle that incorporates information security considerations.
ContributorDISA
Typepolicy
Publish dateMar 4, 2022
NISTv5
NIST SP 800-53 Revision 5
Control: SA-3 a
View document

CCI-004692

deprecated
Definition
Include the requirements for protecting security documentation, explicitly or by reference, using standardized contract language; and/or organization-defined contract language in the acquisition contract for the information system, system component, or information system service.
ContributorDISA
Typepolicy
Publish dateMar 4, 2022
NISTv5
NIST SP 800-53 Revision 5
Control: SA-4 f
View document

CCI-004991

draft
Definition
Defines alternative action(s) to be taken when anomalies in the operation of organization-defined privacy functions are discovered.
ContributorDISA
Typepolicy
Publish dateMar 7, 2022
NISTv5
NIST SP 800-53 Revision 5
Control: SI-6 d
View document

CCI-004402

draft
Definition
Develop and post privacy policies on all external-facing websites, mobile applications, and other digital services that are updated whenever the organization makes a substantive change to the practices it describes.
ContributorDISA
Typepolicy
Publish dateMar 3, 2022
NISTv5
NIST SP 800-53 Revision 5
Control: PM-20 (1) (c)
View document

CCI-001609

draft
Definition
Activate the redundant secondary system that is not collocated with the primary system without loss of information or disruption to operations.
ContributorDISA FSO
Typepolicy
Publish dateMay 12, 2010
NISTv1
NIST SP 800-53A
Control: CP-9 (6).1 (ii)
View document
NISTv3
NIST SP 800-53
Control: CP-9 (6)
View document
NISTv4
NIST SP 800-53 Revision 4
Control: CP-9 (6)
View document
NISTv5
NIST SP 800-53 Revision 5
Control: CP-9 (6)
View document

CCI-004581

draft
Definition
For systems that process information that will be maintained in a Privacy Act system of records: draft system of records notices in accordance with OMB guidance.
ContributorDISA
Typepolicy
Publish dateMar 4, 2022
NISTv5
NIST SP 800-53 Revision 5
Control: PT-6 a
View document

CCI-002369

draft
Definition
Defines the personnel or roles to whom the risk assessment procedures are disseminated.
ContributorDISA FSO
Typepolicy
Publish dateJul 1, 2013
NISTv4
NIST SP 800-53 Revision 4
Control: RA-1 a 2
View document
NISTv5
NIST SP 800-53 Revision 5
Control: RA-1 a 2
View document

CCI-002040

draft
Definition
The organization requires that the registration process to receive an individual identifier includes supervisor authorization.
ContributorDISA FSO
Typepolicy
Publish dateMay 3, 2013
NISTv4
NIST SP 800-53 Revision 4
Control: IA-4 (2)
View document

CCI-004240

draft
Definition
Enforce physical access authorizations at organization-defined entry points to the facility where the system resides.
ContributorDISA
Typepolicy
Publish dateMar 3, 2022
NISTv5
NIST SP 800-53 Revision 5
Control: PE-3 a
View document

CCI-003660

draft
Definition
Defines the discretionary access control policies the system is to enforce over subjects and objects.
ContributorDISA
Typetechnical
Publish dateMar 1, 2022
NISTv5
NIST SP 800-53 Revision 5
Control: AC-3 (15) (b)
View document

CCI-001836

deprecated
Definition
The organization defines the frequency on which it will update the audit and accountability policy.
ContributorDISA FSO
Typepolicy
Publish dateMar 14, 2013
NISTv4
NIST SP 800-53 Revision 4
Control: AU-1 b 1
View document

CCI-004805

draft
Definition
Conduct the modeling and analyses as the following level of rigor.
ContributorDISA
Typepolicy
Publish dateMar 7, 2022
NISTv5
NIST SP 800-53 Revision 5
Control: SA-11 (2) (c)
View document