CCI-001196
CCI-001196 Definition
| Status | |
| Type | CheckType.policy |
Master Assessment Datasheet
Implementation Guidance
Determine if system components that proactively seek to identify network-based malicious code or malicious websites are included.
Validation Procedures
Examine: [SELECT FROM: System and communications protection policy; procedures addressing external malicious code identification; system design documentation; system configuration settings and associated documentation; system components deployed to identify malicious websites and/or web-based malicious code; system audit records; system security plan; other relevant documents or records]. Interview: [SELECT FROM: System/network administrators; organizational personnel with information security responsibilities; organizational personnel installing, configuring, and/or maintaining the system; system developers/integrators]. Test: [SELECT FROM: Automated mechanisms supporting and/or implementing external malicious code identification].