CCI-002477
CCI-002477 Definition
| Status | |
| Type | CheckType.policy |
Master Assessment Datasheet
Implementation Guidance
Determine if: - [SC-28(02)_ODP; information to be removed from online storage and stored offline in a secure location is defined] is removed from online storage. - [SC-28(02)_ODP; information to be removed from online storage and stored offline in a secure location is defined] is stored offline in a secure location.
Validation Procedures
Examine: [SELECT FROM: System and communications protection policy; procedures addressing the protection of information at rest; system design documentation; system configuration settings and associated documentation; cryptographic mechanisms and associated configuration documentation; offline storage locations for information at rest; system audit records; system security plan; other relevant documents or records]. Interview: [SELECT FROM: System/network administrators; organizational personnel with information security responsibilities]. Test: [SELECT FROM: Mechanisms supporting and/or implementing the removal of information from online storage; mechanisms supporting and/or implementing storage of information offline].