CCI-002461
CCI-002461 Definition
| Status | |
| Type | CheckType.policy |
Master Assessment Datasheet
Implementation Guidance
Determine if execution of permitted mobile code is allowed only in confined virtual machine environments.
Validation Procedures
Examine: [SELECT FROM: System and communications protection policy; procedures addressing mobile code; mobile code usage allowances; mobile code usage restrictions; system design documentation; system configuration settings and associated documentation; list of confined virtual machine environments in which the execution of organizationally acceptable mobile code is allowed; system audit records; system security plan; other relevant documents or records]. Interview: [SELECT FROM: System/network administrators; organizational personnel with information security responsibilities; system developer; organizational personnel with responsibilities for managing mobile code]. Test: [SELECT FROM: Mechanisms allowing for the execution of permitted mobile code in confined virtual machine environments].