CCI-003134
CCI-003134 Definition
The organization protects information system, system component, or information system service documentation as required, in accordance with the risk management strategy.
Status | |
Type | CheckType.policy |
Master Assessment Datasheet
Implementation Guidance
The organization being inspected/assessed documents and implements processes to store and handle information system, system component, or information system service documentation as required, in accordance with the risk management strategy.
Validation Procedures
The organization conducting the inspection/assessment obtains and examines the documented processes to ensure the organization being inspected/assessed stores and handles information system, system component, or information system service documentation as required, in accordance with the risk management strategy.
Compelling Evidence
1.) System security plan (SSP) must define how information system, service or component is protected in accordance with risk management strategy.