CCI-001959
CCI-001959 Definition
| Status | |
| Type | CheckType.policy |
Master Assessment Datasheet
Implementation Guidance
Determine if [IA-03(01)_ODP[01]; devices and/or types of devices requiring use of cryptographically based, bidirectional authentication to authenticate before establishing one or more connections are defined] are authenticated before establishing [IA-03(01)_ODP[02]; one or more of the following PARAMETER VALUES is/are selected: {local; remote; network}] connection using bidirectional authentication that is cryptographically based.
Validation Procedures
Examine: [SELECT FROM: Identification and authentication policy; system security plan; procedures addressing device identification and authentication; system design documentation; list of devices requiring unique identification and authentication; device connection reports; system configuration settings and associated documentation; other relevant documents or records]. Interview: [SELECT FROM: Organizational personnel with operational responsibilities for device identification and authentication; organizational personnel with information security responsibilities; system/network administrators; system developers]. Test: [SELECT FROM: Mechanisms supporting and/or implementing device authentication capability; cryptographically based bidirectional authentication mechanisms].