CCI-002174
CCI-002174 Definition
Status | |
Type | CheckType.policy |
Master Assessment Datasheet
Implementation Guidance
The organization being inspected/assessed defines and documents the users the information system will control access based upon the organization-defined role-based access control policy. DoD has determined the users are not appropriate to define at the Enterprise level.
Validation Procedures
The organization conducting the inspection/assessment obtains and examines the documented roles to ensure the organization being inspected/assessed defines the users the information system will control access based upon the organization-defined role-based access control policy. DoD has determined the users are not appropriate to define at the Enterprise level.
Compelling Evidence
1.) Signed and dated documentation which defines the users that the system will control access to based upon the organization-defined access control policy.