CCI-002222
CCI-002222 Definition
Status | |
Type | CheckType.policy |
Master Assessment Datasheet
Implementation Guidance
The organization being inspected/assessed documents and implements a process to explicitly authorize access to all functions not publicly accessible. Explicit authorization can be in the form of an acceptable use policy signed by the user at the time of access being granted. DoD has defined the security functions as all functions not publicly accessible.
Validation Procedures
The organization conducting the inspection/assessment obtains and examines the documented process to ensure the organization being inspected/assessed explicitly authorizes access to all functions not publicly accessible. DoD has defined the security functions as all functions not publicly accessible.
Compelling Evidence
1.) Signed and dated access control policy 2.) Signed and dated system security plan (SSP) 3.) Signed and dated documentation that defines the process to explicitly authorize access to all functions not publicly accessible