CCI-002128
CCI-002128 Definition
Status | |
Type | CheckType.policy |
Master Assessment Datasheet
Implementation Guidance
The organization being inspected/assessed authorizes access to the information system based on other attributes as required by the organization or associated missions/business functions. The organization being inspected/assessed maintains an audit trail of approved access.
Validation Procedures
The organization conducting the inspection/assessment obtains and examines the audit trail of approved access to ensure the organization being inspected/assessed authorizes access to the information system based on other attributes as required by the organization or associated missions/business functions.
Compelling Evidence
1.) Signed and dated system security plan (SSP), referencing section which defines what attributes authorize access to the system as required by the organization or associated missions/business functions. 2.) Audit trail of approved access.