CCI-000642
CCI-000642 Definition
Status | |
Type | CheckType.policy |
Master Assessment Datasheet
Implementation Guidance
The organization being inspected/assessed documents attempts to obtain information system, system component, or information system service documentation when such documentation is either unavailable or nonexistent.
Validation Procedures
The organization conducting the inspection/assessment obtains and examines the documented attempts to ensure the organization being inspected/assessed documents attempts to obtain information system, system component, or information system service documentation when such documentation is either unavailable or nonexistent.
Compelling Evidence
1.) System security plan (SSP) or Incident response plan must document organization defined actions to be taken in the event of attempt to obtain unavailable or nonexistent information about information system, component or service.