CCI-002378
CCI-002378 Definition
Defines the personnel or roles to be recipients of the organization-level; mission/business process-level; and/or system-level system and communications protection policy.
| Status | |
| Type | CheckType.policy |
Master Assessment Datasheet
Implementation Guidance
Determine if: - a system and communications protection policy is developed and documented. - the system and communications protection policy is disseminated to [SC-01_ODP[01]; personnel or roles to whom the system and communications protection policy is to be disseminated is/are defined].
Validation Procedures
Examine: [SELECT FROM: System and communications protection policy; system and communications protection procedures; system security plan; privacy plan; risk management strategy documentation; audit findings; other relevant documents or records]. Interview: [SELECT FROM: Organizational personnel with system and communications protection responsibilities; organizational personnel with information security and privacy responsibilities].