CCI-002860
CCI-002860 Definition
Status | |
Type | CheckType.policy |
Master Assessment Datasheet
Implementation Guidance
The organization being inspected/assessed defines and documents the security functions that must be satisfied when the primary means of implementing the security function is unavailable or compromised. DoD has determined the security functions are not appropriate to define at the Enterprise level.
Validation Procedures
The organization conducting the inspection/assessment obtains and examines the documented security functions to ensure the organization being inspected/assessed defines the security functions that must be satisfied when the primary means of implementing the security function is unavailable or compromised. DoD has determined the security functions are not appropriate to define at the Enterprise level.
Compelling Evidence
1.) Documentation that defines security functions that must be satisfied when the primary means of implementing the security function is unavailable or compromised.