CCI-001341
CCI-001341 Definition
| Status | |
| Type | CheckType.technical |
Master Assessment Datasheet
Implementation Guidance
Determine if the binding of the information reviewer identity to the information at the transfer or release points prior to release or transfer between [AU-10(04)_ODP[01]; security domains for which the binding of the information reviewer identity to the information is to be validated at transfer or release are defined].
Validation Procedures
Examine: [SELECT FROM: Audit and accountability policy; system security plan; privacy plan; procedures addressing non-repudiation; system design documentation; system configuration settings and associated documentation; validation records; system audit records; other relevant documents or records]. Interview: [SELECT FROM: Organizational personnel with information security and privacy responsibilities; system/network administrators; system developers]. Test: [SELECT FROM: Mechanisms implementing non-repudiation capability].