CCI-002173
CCI-002173 Definition
Status | |
Type | CheckType.policy |
Master Assessment Datasheet
Implementation Guidance
The organization being inspected/assessed defines and documents the roles the information system will control access based upon the organization-defined role-based access control policy. DoD has determined the roles are not appropriate to define at the Enterprise level.
Validation Procedures
The organization conducting the inspection/assessment obtains and examines the documented roles to ensure the organization being inspected/assessed defines the roles the information system will control access based upon the organization-defined role-based access control policy. DoD has determined the roles are not appropriate to define at the Enterprise level.
Compelling Evidence
1.) Signed and dated documentation which defines the roles the system will control access to based upon organization-defined access control policy.