CCI-002215
CCI-002215 Definition
| Status | |
| Type | CheckType.policy |
Master Assessment Datasheet
Implementation Guidance
Determine if: - information flows are separated logically using [AC-04(21)_ODP[01]; mechanisms and/or techniques used to logically separate information flows are defined (if selected)] to accomplish [AC-04(21)_ODP[03]; required separations by types of information are defined]. - information flows are separated physically using [AC-04(21)_ODP[02]; mechanisms and/or techniques used to physically separate information flows are defined (if selected)] to accomplish [AC-04(21)_ODP[03]; required separations by types of information are defined].
Validation Procedures
Examine: [SELECT FROM: Information flow enforcement policy; information flow control policies; procedures addressing information flow enforcement; system design documentation; system configuration settings and associated documentation; list of required separation of information flows by information types; list of mechanisms and/or techniques used to logically or physically separate information flows; system audit records; system security plan; other relevant documents or records]. Interview: [SELECT FROM: Organizational personnel with information flow enforcement responsibilities; system/network administrators; organizational personnel with information security responsibilities; system developers]. Test: [SELECT FROM: Mechanisms implementing information flow enforcement functions].