CCI-001550
CCI-001550 Definition
The organization defines approved authorizations for controlling the flow of information within the system.
Status | |
Type | CheckType.policy |
Master Assessment Datasheet
Implementation Guidance
The organization being inspected/assessed defines and documents approved authorizations for controlling the flow of information within the system.
Validation Procedures
The organization conducting the inspection/assessment obtains and examines the documented approved authorizations to ensure the organization being inspected/assessed defines approved authorizations for controlling the flow of information within the system.
Compelling Evidence
1.) Signed and dated access control policy. 2.) Signed and dated data flow diagram. 3.) Signed and dated documentation that defines approved authorizations for controlling the flow of information