CCI-002349
CCI-002349 Definition
| Status | |
| Type | CheckType.policy |
Master Assessment Datasheet
Implementation Guidance
Determine if [AC-24_ODP[01]; one or more of the following PARAMETER VALUES is/are selected: {establish procedures; implement mechanisms}] are taken to ensure that [AC-24_ODP[02]; access control decisions applied to each access request prior to access enforcement are defined] are applied to each access request prior to access enforcement.
Validation Procedures
Examine: [SELECT FROM: Access control policy; procedures addressing access control decisions; system design documentation; system configuration settings and associated documentation; system audit records; system security plan; other relevant documents or records]. Interview: [SELECT FROM: Organizational personnel with responsibilities for establishing procedures regarding access control decisions to the system; organizational personnel with information security responsibilities]. Test: [SELECT FROM: Mechanisms applying established access control decisions and procedures].