CCI-004298
CCI-004298 Definition
| Status | |
| Type | CheckType.policy |
Master Assessment Datasheet
Implementation Guidance
Determine if: - planned architecture changes are reflected in the security plan. - planned architecture changes are reflected in the privacy plan. - planned architecture changes are reflected in the Concept of Operations (CONOPS). - planned architecture changes are reflected in criticality analysis. - planned architecture changes are reflected in organizational procedures. - planned architecture changes are reflected in procurements and acquisitions.
Validation Procedures
Examine: [SELECT FROM: Security and privacy planning policy; procedures addressing information security and privacy architecture development; procedures addressing information security and privacy architecture reviews and updates; enterprise architecture documentation; information security and privacy architecture documentation; system security plan; privacy plan; security and privacy CONOPS for the system; records of information security and privacy architecture reviews and updates; other relevant documents or records]. Interview: [SELECT FROM: Organizational personnel with security and privacy planning and plan implementation responsibilities; organizational personnel with information security and privacy architecture development responsibilities; organizational personnel with information security and privacy responsibilities]. Test: [SELECT FROM: Organizational processes for developing, reviewing, and updating the information security and privacy architecture; mechanisms supporting and/or implementing the development, review, and update of the information security and privacy architecture].