Show/Hide Toolbars

ABCI Consultants

Guidance for NIST 800-171 Assessment & Compliance

Navigation: AC-FAMILY: ACCESS CONTROL

AC-16(10) SECURITY ATTRIBUTES  |  ATTRIBUTE CONFIGURATION BY AUTHORIZED INDIVIDUALS

Scroll Prev Top Next More

Applicable

(Y)es / (N)o

(C)onfidentiality

(I)ntegrity

(A)vailability

RPN

(C+I+A)

(S)atisfactory

L1

M2

H3

L1

M2

H3

L1

M2

H3

(O)ther than satisfactory +##

 

 

 

 

 

 

 

 

 

 

 

 

###

ac-16(10)  

security attributes | attribute configuration by authorized individuals

 

assessment objective:

Determine if the information system provides authorized individuals the capability to define or change the type and value of security attributes available for association with subjects and objects.

potential assessment methods and objects:

Examine: [select from: Access control policy; procedures addressing configuration of security attributes by authorized individuals; information system design documentation; information system configuration settings and associated documentation; information system audit records; other relevant documents or records].

Interview: [select from: Organizational personnel with responsibilities for defining or changing security attributes associated with information; organizational personnel with information security responsibilities; system developers].

Test: [select from: Automated mechanisms implementing capability for defining or changing security attributes].

Hosted by ABCI Consultants for Information Security Management Systems | Implementations, Training and Assessments for Compliance | (800) 644-2056