CCI-002737
CCI-002737 Definition
Status | |
Type | CheckType.policy |
Master Assessment Datasheet
Implementation Guidance
The organization being inspected/assessed prohibits the use of binary or machine-executable code obtained from sources without vendor support or with no warranty and without the provision of source code.
Validation Procedures
The organization conducting the inspection/assessment obtains and examines the software list and examines the information system to ensure the organization being inspected/assessed prohibits the use of binary or machine-executable code obtained from sources without vendor support or with no warranty and without the provision of source code.
Compelling Evidence
1.) Signed and dated System security plan with reference to section that prohibits the use of binary or machine-executable code obtained from sources without vendor support or with no warranty and without the provision of source code.