CCI-001285
CCI-001285 Definition
Status | |
Type | CheckType.policy |
Master Assessment Datasheet
Implementation Guidance
The organization being inspected/assessed receives information system security alerts, advisories, and directives from at a minimum, USCYBERCOM on an ongoing basis. DoD has defined the external organizations as at a minimum, USCYBERCOM.
Validation Procedures
The organization conducting the inspection/assessment obtains and examines alerts, advisories, and directives received by the organization being inspected/assessed to ensure they receive information system security alerts, advisories, and directives from at a minimum, USCYBERCOM on an ongoing basis. DoD has defined the external organizations as at a minimum, USCYBERCOM.
Compelling Evidence
1.) Signed and dated System security plan with reference to section that pertains to external sources for receiving security notifications (i.e. USCYBERCOM), personnel receiving it and frequency of information dissemination. 2.) Log of notifications from external sources.