CCI-003053
CCI-003053 Definition
Develop security and privacy plans for the system that provide the security categorization of the system, including supporting rationale.
Status | |
Type | CheckType.policy |
Master Assessment Datasheet
Implementation Guidance
The organization being inspected/assessed defines within the security plan the security categorization of the information system including supporting rationale.
Validation Procedures
The organization conducting the inspection/assessment obtains and examines the security plan to ensure the organization being inspected/assessed defines within the security plan the security categorization of the information system including supporting rationale.
Compelling Evidence
1.) System security plan (SSP).