CCI-001532
CCI-001532 Definition
Status | |
Type | CheckType.policy |
Master Assessment Datasheet
Implementation Guidance
The organization being inspected/assessed reviews/updates the access agreements annually of employees who have signed access agreements. The purpose of this review/update is to ensure access agreements are current and departed employees no longer have access agreements. The organization must maintain an audit trail of the review and update activity for review. DoD has defined the frequency as annually.
Validation Procedures
The organization conducting the inspection/assessment obtains and examines the audit trail to ensure review/update occurred annually and departed employees no longer have valid access agreements.
Compelling Evidence
1.) SOP/TTP documentation of review and update of user agreements which includes departed employees no longer have valid access agreements. 2.) Audit trail ensuring above is in compliance.