CCI-002683
CCI-002683 Definition
Status | |
Type | CheckType.policy |
Master Assessment Datasheet
Implementation Guidance
The organization being inspected/assessed documents and implements a process to detect network services that have not been authorized or approved by at a minimum, the ISSO and ISSM. For network service detection mechanisms that have applicable STIGs or SRGs, the organization being inspected/assessed must comply with the STIG/SRG guidance that pertains to CCI 2683. DoD has defined the personnel or roles as at a minimum, the ISSO and ISSM.
Validation Procedures
The organization conducting the inspection/assessment obtains and examines the documented process, and examines the implemented detection mechanisms to ensure the organization being inspected/assessed implements a process to detect network services that have not been authorized or approved by at a minimum, the ISSO and ISSM. For network service detection mechanisms that have applicable STIGs or SRGs, the organization conducting the inspection/assessment evaluates the components to ensure that the organization being inspected/assessed has configured the information system in compliance with the applicable STIGs and SRGs pertaining to CCI 2683. DoD has defined the personnel or roles as at a minimum, the ISSO and ISSM.
Compelling Evidence
1.) Signed and dated System security plan defines a process to detect network services that have not been authorized or approved by at a minimum, the ISSO and ISSM.