CCI-003740
CCI-003740 Definition
Status | |
Type | CheckType.technical |
Master Assessment Datasheet
Implementation Guidance
Determine if: - [AC-16(08)_ODP[01]; techniques and technologies to be implemented in associating security attributes to information are defined] are implemented in associating security attributes to information. - [AC-16(08)_ODP[02]; techniques and technologies to be implemented in associating privacy attributes to information are defined] are implemented in associating privacy attributes to information.
Validation Procedures
Examine: [SELECT FROM: Access control policy; procedures addressing association of security and privacy attributes to information; system design documentation; system configuration settings and associated documentation; system audit records; system security plan; privacy plan; other relevant documents or records]. Interview: [SELECT FROM: Organizational personnel with responsibilities for associating security and privacy attributes to information; organizational personnel with information security and privacy responsibilities; system developers]. Test: [SELECT FROM: Mechanisms implementing techniques or technologies associating security and privacy attributes to information].