CCI-001093
CCI-001093 Definition
Status | |
Type | CheckType.policy |
Master Assessment Datasheet
Implementation Guidance
The organization being inspected/assessed defines and documents the types of denial of service attacks (or provides references to sources of current denial of service attacks) that can be addressed by the information system. DoD has determined the types of denial of service attacks are not appropriate to define at the Enterprise level.
Validation Procedures
The organization conducting the inspection/assessment obtains and examines the documented types of denial of service attacks to ensure the organization being inspected/assessed defines the types of denial of service attacks (or provides references to sources of current denial of service attacks) that can be addressed by the information system. DoD has determined the types of denial of service attacks are not appropriate to define at the Enterprise level.
Compelling Evidence
1.) Signed and dated Threat Model. 2.) Signed and dated System Security Plan (SSP) or any other documentation that defines the types of DoS attacks that can be addressed by the information system.