CCI-003838
CCI-003838 Definition
| Status | |
| Type | CheckType.policy |
Master Assessment Datasheet
Implementation Guidance
Determine if [AU-13_ODP[03]; personnel or roles to be notified if an information disclosure is discovered is/are defined] are notified if an information disclosure is discovered.
Validation Procedures
Examine: [SELECT FROM: Audit and accountability policy; system security plan; privacy plan; procedures addressing information disclosure monitoring; system design documentation; system configuration settings and associated documentation; monitoring records; system audit records; other relevant documents or records]. Interview: [SELECT FROM: Organizational personnel with responsibilities for monitoring open-source information and/or information sites; organizational personnel with security and privacy responsibilities]. Test: [SELECT FROM: Mechanisms implementing monitoring for information disclosure].