CCI-003284
CCI-003284 Definition
Status | |
Type | CheckType.policy |
Master Assessment Datasheet
Implementation Guidance
The organization being inspected/assessed documents and implements a process to approve the use of live data in test environments for the information system, system component, or information system service. The organization must maintain a record of approvals.
Validation Procedures
The organization conducting the inspection/assessment obtains and examines the documented process as well as the record of approvals to ensure the organization being inspected/assessed approves the use of live data in test environments for the information system, system component, or information system service.
Compelling Evidence
1.) System security plan (SSP). 2.) System development life cycle (SDLC) documentation. 3.) Continuous monitoring plan approves the use of live data in test environments for the information system, system components or information system service.