CCI-000871
CCI-000871 Definition
| Status | |
| Type | CheckType.policy |
Master Assessment Datasheet
Implementation Guidance
Determine if the removal of maintenance equipment containing organizational information is prevented by obtaining an exemption from [MA-03(03)_ODP; personnel or roles who can authorize removal of equipment from the facility is/are defined] explicitly authorizing removal of the equipment from the facility.
Validation Procedures
Examine: [SELECT FROM: Maintenance policy; procedures addressing system maintenance tools; system maintenance tools and associated documentation; maintenance records; equipment sanitization records; media sanitization records; exemptions for equipment removal; system security plan; other relevant documents or records]. Interview: [SELECT FROM: Organizational personnel with system maintenance responsibilities; organizational personnel with information security responsibilities; organizational personnel responsible for media sanitization]. Test: [SELECT FROM: Organizational process for preventing unauthorized removal of information; mechanisms supporting media sanitization or destruction of equipment; mechanisms supporting verification of media sanitization].