Show/Hide Toolbars

ABCI Consultants

Guidance for NIST 800-171 Assessment & Compliance

Navigation: AC-FAMILY: ACCESS CONTROL

AC-16(2) SECURITY ATTRIBUTES  |  ATTRIBUTE VALUE CHANGES BY AUTHORIZED INDIVIDUALS

Scroll Prev Top Next More

 

Applicable

(Y)es / (N)o

(C)onfidentiality

(I)ntegrity

(A)vailability

RPN

(C+I+A)

(S)atisfactory

L1

M2

H3

L1

M2

H3

L1

M2

H3

(O)ther than satisfactory +##

 

 

 

 

 

 

 

 

 

 

 

 

###

ac-16(2)

security attributes  | attribute value changes by authorized individuals

 

assessment objective:

Determine if the information system provides authorized individuals (or processes acting on behalf on individuals) the capability to define or change the value of associated security attributes.

potential assessment methods and objects:

Examine: [select from: Access control policy; procedures addressing the change of security attribute values; information system design documentation; information system configuration settings and associated documentation; list of individuals authorized to change security attributes; information system audit records; other relevant documents or records].

Interview: [select from: Organizational personnel with responsibilities for changing values of security attributes; organizational personnel with information security responsibilities; system developers].

Test: [select from: Automated mechanisms permitting changes to values of security attributes].

Hosted by ABCI Consultants for Information Security Management Systems | Implementations, Training and Assessments for Compliance | (800) 644-2056