CCI-002648
CCI-002648 Definition
Status | |
Type | CheckType.policy |
Master Assessment Datasheet
Implementation Guidance
The organization being inspected/assessed documents and implements a process to protect information obtained from intrusion-monitoring tools from unauthorized modification.
Validation Procedures
The organization conducting the inspection/assessment obtains and examines the documented process to ensure the organization being inspected/assessed protects information obtained from intrusion-monitoring tools from unauthorized modification.
Compelling Evidence
1.) List of users authorized to have access to Intrusion Monitoring tools and resultant information. 2.) Documentation and evidence (security logs that show access records to this restricted information) that only those authorized users have access to specified tools and information. 3.) Complete File Integrity Module monitoring logs to show that unauthorized modifications have not taken place.