CCI-002162
CCI-002162 Definition
The organization defines the privileges that may explicitly be granted to organization-defined subjects such that they are not limited by some or all of the mandatory access control constraints.
Status | |
Type | CheckType.policy |
Master Assessment Datasheet
Implementation Guidance
The organization being inspected/assessed defines and documents the privileges that may explicitly be granted to organization-defined subjects such that they are not limited by some or all of the mandatory access control constraints. DoD has determined the privileges are not appropriate to define at the Enterprise level.
Validation Procedures
The organization conducting the inspection/assessment obtains and examines the documented privileges to ensure they have been defined. DoD has determined the privileges are not appropriate to define at the Enterprise level.
Compelling Evidence
1.) Signed and dated documentation which defines which privileges not constrained by the mandatory access control policy.