CCI-002008
      
        
        
      
      
        
  CCI-002008 Definition
      
      
        
        
      
    
  | Status | |
| Type | CheckType.policy | 
      
        
        
      
      
        
  Master Assessment Datasheet
      
      
        
        
      
    
  Implementation Guidance
Determine if an organization-wide methodology for managing the content of PKI trust stores is employed across all platforms, including networks, operating systems, browsers, and applications for PKI-based authentication.
Validation Procedures
Examine: [SELECT FROM: Identification and authentication policy; procedures addressing authenticator management; system security plan; organizational methodology for managing content of PKI trust stores across installed all platforms; system design documentation; system configuration settings and associated documentation; enterprise security architecture documentation; enterprise architecture documentation; other relevant documents or records]. Interview: [SELECT FROM: Organizational personnel with authenticator management responsibilities; organizational personnel with information security responsibilities; system/network administrators; system developers]. Test: [SELECT FROM: Mechanisms supporting and/or implementing PKI-based authenticator management capability; mechanisms supporting and/or implementing the PKI trust store capability].