CCI-002472
CCI-002472 Definition
Status | |
Type | CheckType.policy |
Master Assessment Datasheet
Implementation Guidance
The organization being inspected/assessed defines and documents the information at rest that is to be protected by the information system which must include, at a minimum, PII and classified information. DoD has determined the information at rest is not appropriate to define at the Enterprise level.
Validation Procedures
The organization conducting the inspection/assessment obtains and examines the documented information at rest to ensure the organization being inspected/assessed defines and documents the information at rest that is to be protected by the information system which must include, at a minimum, PII and classified information. DoD has determined the information at rest is not appropriate to define at the Enterprise level.
Compelling Evidence
1.) Signed and dated System Security Plan (SSP) should define the information at rest that is to be protected by the information system.