Show/Hide Toolbars

ABCI Consultants

Guidance for NIST 800-171 Assessment & Compliance

Applicable

(Y)es / (N)o

(C)onfidentiality

(I)ntegrity

(A)vailability

RPN

(C+I+A)

(S)atisfactory

L1

M2

H3

L1

M2

H3

L1

M2

H3

(O)ther than satisfactory +##

 

 

 

 

 

 

 

 

 

 

 

 

###

pe-16

delivery and removal

 

assessment objective:

Determine if the organization:  

pe-16[1]  

defines types of information system components to be authorized, monitored, and controlled as such components are entering and exiting the facility;

pe-16[2]  

authorizes organization-defined information system components entering the facility;

pe-16[3]  

monitors organization-defined information system components entering the facility;

pe-16[4]  

controls organization-defined information system components entering the facility;

pe-16[5]  

authorizes organization-defined information system components exiting the facility;

pe-16[6]  

monitors organization-defined information system components exiting the facility;

pe-16[7]  

controls organization-defined information system components exiting the facility;

pe-16[8]  

maintains records of information system components entering the facility; and

pe-16[9]  

maintains records of information system components exiting the facility.

potential assessment methods and objects:

Examine: [select from: Physical and environmental protection policy; procedures addressing delivery and removal of information system components from the facility; security plan; facility housing the information system; records of items entering and exiting the facility; other relevant documents or records].

Interview: [select from:  Organizational personnel with responsibilities for controlling information system components entering and exiting the facility; organizational personnel with information security responsibilities].

Test: [select from: Organizational process for authorizing, monitoring, and controlling information system-related items entering and exiting the facility; automated mechanisms supporting and/or implementing authorizing, monitoring, and controlling information system-related items entering and exiting the facility].

Hosted by ABCI Consultants for Information Security Management Systems | Implementations, Training and Assessments for Compliance | (800) 644-2056