CCI-003288
CCI-003288 Definition
Status | |
Type | CheckType.policy |
Master Assessment Datasheet
Implementation Guidance
The organization being inspected/assessed documents and implements a process to control the use of live data in test environments for the information system, system component, or information system service. The Enclave Test and Development STIG identifies requirements for test and development environments.
Validation Procedures
The organization conducting the inspection/assessment obtains and examines the documented process to ensure the organization being inspected/assessed controls the use of live data in test environments for the information system, system component, or information system service.
Compelling Evidence
1.) System security plan (SSP). 2.) System development life cycle (SDLC) documentation. 3.) Continuous monitoring plan controls the use of live data in test environments for the information system, system components or information system service.