Doc:NIST SP 800-53Ar1 Appendix F/Enhanced/AC/Moderate
From FISMApedia
NIST SP 800-53Ar1 Assessment Procedure Catalog, with SP 800-53r3 Security Controls
ACCESS CONTROL
AC-1 ACCESS CONTROL POLICY AND PROCEDURES
| FAMILY: ACCESS CONTROL | CLASS: TECHNICAL |
- Security Control Baseline:
| AC-1 | Access Control Policy and Procedures | P1 | LOW AC-1 | MOD AC-1 | HIGH AC-1 |
| SECURITY CONTROL |
|---|
|
AC-1 ACCESS CONTROL POLICY AND PROCEDURES
|
| ASSESSMENT PROCEDURE | ||
|---|---|---|
| AC-1 | ACCESS CONTROL POLICY AND PROCEDURES | |
| AC-1.1 | ASSESSMENT OBJECTIVE:
| |
| AC-1.2 | ASSESSMENT OBJECTIVE:
| |
AC-2 ACCOUNT MANAGEMENT
| FAMILY: ACCESS CONTROL | CLASS: TECHNICAL |
- Security Control Baseline:
| AC-2 | Account Management | P1 | LOW AC-2 | MOD AC-2 (1) (2) (3) (4) | HIGH AC-2 (1) (2) (3) (4) |
| SECURITY CONTROL |
|---|
|
AC-2 ACCOUNT MANAGEMENT
|
| ASSESSMENT PROCEDURE | ||
|---|---|---|
| AC-2 | ACCOUNT MANAGEMENT | |
| AC-2.1 | ASSESSMENT OBJECTIVE:
| |
| SECURITY CONTROL ENHANCEMENT |
|---|
|
| AC-2(1) | ACCOUNT MANAGEMENT | |
| AC-2(1).1 | ASSESSMENT OBJECTIVE:
|
| SECURITY CONTROL ENHANCEMENT |
|---|
|
| AC-2(2) | ACCOUNT MANAGEMENT | |
| AC-2(2).1 | ASSESSMENT OBJECTIVE:
|
| SECURITY CONTROL ENHANCEMENT |
|---|
|
| AC-2(3) | ACCOUNT MANAGEMENT | |
| AC-2(3).1 | ASSESSMENT OBJECTIVE:
|
| SECURITY CONTROL ENHANCEMENT |
|---|
|
| AC-2(4) | ACCOUNT MANAGEMENT | |
| AC-2(4).1 | ASSESSMENT OBJECTIVE:
|
AC-3 ACCESS ENFORCEMENT
| FAMILY: ACCESS CONTROL | CLASS: TECHNICAL |
- Security Control Baseline:
| AC-3 | Access Enforcement | P1 | LOW AC-3 | MOD AC-3 | HIGH AC-3 |
| SECURITY CONTROL |
|---|
|
AC-3 ACCESS ENFORCEMENT
|
| ASSESSMENT PROCEDURE | ||
|---|---|---|
| AC-3 | ACCESS ENFORCEMENT | |
| AC-3.1 | ASSESSMENT OBJECTIVE:
| |
AC-4 INFORMATION FLOW ENFORCEMENT
| FAMILY: ACCESS CONTROL | CLASS: TECHNICAL |
- Security Control Baseline:
| AC-4 | Information Flow Enforcement | P1 | LOW Not Selected | MOD AC-4 | HIGH AC-4 |
| SECURITY CONTROL |
|---|
|
AC-4 INFORMATION FLOW ENFORCEMENT
|
| ASSESSMENT PROCEDURE | ||
|---|---|---|
| AC-4 | INFORMATION FLOW ENFORCEMENT | |
| AC-4.1 | ASSESSMENT OBJECTIVE:
| |
AC-5 SEPARATION OF DUTIES
| FAMILY: ACCESS CONTROL | CLASS: TECHNICAL |
- Security Control Baseline:
| AC-5 | Separation of Duties | P1 | LOW Not Selected | MOD AC-5 | HIGH AC-5 |
| SECURITY CONTROL |
|---|
|
AC-5 SEPARATION OF DUTIES
|
| ASSESSMENT PROCEDURE | ||
|---|---|---|
| AC-5 | SEPARATION OF DUTIES | |
| AC-5.1 | ASSESSMENT OBJECTIVE:
| |
AC-6 LEAST PRIVILEGE
| FAMILY: ACCESS CONTROL | CLASS: TECHNICAL |
- Security Control Baseline:
| AC-6 | Least Privilege | P1 | LOW Not Selected | MOD AC-6 (1) (2) | HIGH AC-6 (1) (2) |
| SECURITY CONTROL |
|---|
|
AC-6 LEAST PRIVILEGE
|
| ASSESSMENT PROCEDURE | ||
|---|---|---|
| AC-6 | LEAST PRIVILEGE | |
| AC-6.1 | ASSESSMENT OBJECTIVE:
| |
| SECURITY CONTROL ENHANCEMENT |
|---|
|
| AC-6(1) | LEAST PRIVILEGE | |
| AC-6(1).1 | ASSESSMENT OBJECTIVE:
|
| SECURITY CONTROL ENHANCEMENT |
|---|
|
| AC-6(2) | LEAST PRIVILEGE | |
| AC-6(2).1 | ASSESSMENT OBJECTIVE:
|
AC-7 UNSUCCESSFUL LOGIN ATTEMPTS
| FAMILY: ACCESS CONTROL | CLASS: TECHNICAL |
- Security Control Baseline:
| AC-7 | Unsuccessful Login Attempts | P2 | LOW AC-7 | MOD AC-7 | HIGH AC-7 |
| SECURITY CONTROL |
|---|
|
AC-7 UNSUCCESSFUL LOGIN ATTEMPTS
|
| ASSESSMENT PROCEDURE | ||
|---|---|---|
| AC-7 | UNSUCCESSFUL LOGIN ATTEMPTS | |
| AC-7.1 | ASSESSMENT OBJECTIVE:
| |
AC-8 SYSTEM USE NOTIFICATION
| FAMILY: ACCESS CONTROL | CLASS: TECHNICAL |
- Security Control Baseline:
| AC-8 | System Use Notification | P1 | LOW AC-8 | MOD AC-8 | HIGH AC-8 |
| SECURITY CONTROL |
|---|
|
AC-8 SYSTEM USE NOTIFICATION
|
| ASSESSMENT PROCEDURE | ||
|---|---|---|
| AC-8 | SYSTEM USE NOTIFICATION | |
| AC-8.1 | ASSESSMENT OBJECTIVE:
| |
| AC-8.2 | ASSESSMENT OBJECTIVE:
| |
AC-11 SESSION LOCK
| FAMILY: ACCESS CONTROL | CLASS: TECHNICAL |
- Security Control Baseline:
| AC-11 | Session Lock | P3 | LOW Not Selected | MOD AC-11 | HIGH AC-11 |
| SECURITY CONTROL |
|---|
|
AC-11 SESSION LOCK
|
| ASSESSMENT PROCEDURE | ||
|---|---|---|
| AC-11 | SESSION LOCK | |
| AC-11.1 | ASSESSMENT OBJECTIVE:
| |
AC-14 PERMITTED ACTIONS WITHOUT IDENTIFICATION OR AUTHENTICATION
| FAMILY: ACCESS CONTROL | CLASS: TECHNICAL |
- Security Control Baseline:
| AC-14 | Permitted Actions without Identification or Authentication | P1 | LOW AC-14 | MOD AC-14 (1) | HIGH AC-14 (1) |
| SECURITY CONTROL |
|---|
|
AC-14 PERMITTED ACTIONS WITHOUT IDENTIFICATION OR AUTHENTICATION
|
| ASSESSMENT PROCEDURE | ||
|---|---|---|
| AC-14 | PERMITTED ACTIONS WITHOUT IDENTIFICATION OR AUTHENTICATION | |
| AC-14.1 | ASSESSMENT OBJECTIVE:
| |
| SECURITY CONTROL ENHANCEMENT |
|---|
|
| AC-14(1) | PERMITTED ACTIONS WITHOUT IDENTIFICATION OR AUTHENTICATION | |
| AC-14(1).1 | ASSESSMENT OBJECTIVE:
|
AC-17 REMOTE ACCESS
| FAMILY: ACCESS CONTROL | CLASS: TECHNICAL |
- Security Control Baseline:
| AC-17 | Remote Access | P1 | LOW AC-17 | MOD AC-17 (1) (2) (3) (4) (5) (7) (8) | HIGH AC-17 (1) (2) (3) (4) (5) (7) (8) |
| SECURITY CONTROL |
|---|
|
AC-17 REMOTE ACCESS
|
| ASSESSMENT PROCEDURE | ||
|---|---|---|
| AC-17 | REMOTE ACCESS | |
| AC-17.1 | ASSESSMENT OBJECTIVE:
| |
| SECURITY CONTROL ENHANCEMENT |
|---|
|
| AC-17(1) | REMOTE ACCESS | |
| AC-17(1).1 | ASSESSMENT OBJECTIVE:
|
| SECURITY CONTROL ENHANCEMENT |
|---|
|
| AC-17(2) | REMOTE ACCESS | |
| AC-17(2).1 | ASSESSMENT OBJECTIVE:
|
| SECURITY CONTROL ENHANCEMENT |
|---|
|
| AC-17(3) | REMOTE ACCESS | |
| AC-17(3).1 | ASSESSMENT OBJECTIVE:
|
| SECURITY CONTROL ENHANCEMENT |
|---|
|
| AC-17(4) | REMOTE ACCESS | |
| AC-17(4).1 | ASSESSMENT OBJECTIVE:
|
| SECURITY CONTROL ENHANCEMENT |
|---|
|
| AC-17(5) | REMOTE ACCESS | |
| AC-17(5).1 | ASSESSMENT OBJECTIVE:
|
| SECURITY CONTROL ENHANCEMENT |
|---|
|
| AC-17(7) | REMOTE ACCESS | |
| AC-17(7).1 | ASSESSMENT OBJECTIVE:
|
| SECURITY CONTROL ENHANCEMENT |
|---|
|
| AC-17(8) | REMOTE ACCESS | |
| AC-17(8).1 | ASSESSMENT OBJECTIVE:
|
AC-18 WIRELESS ACCESS
| FAMILY: ACCESS CONTROL | CLASS: TECHNICAL |
- Security Control Baseline:
| AC-18 | Wireless Access | P1 | LOW AC-18 | MOD AC-18 (1) | HIGH AC-18 (1) (2) (4) (5) |
| SECURITY CONTROL |
|---|
|
AC-18 WIRELESS ACCESS
|
| ASSESSMENT PROCEDURE | ||
|---|---|---|
| AC-18 | WIRELESS ACCESS | |
| AC-18.1 | ASSESSMENT OBJECTIVE:
| |
| SECURITY CONTROL ENHANCEMENT |
|---|
|
| AC-18(1) | WIRELESS ACCESS | |
| AC-18(1).1 | ASSESSMENT OBJECTIVE:
|
AC-19 ACCESS CONTROL FOR MOBILE DEVICES
| FAMILY: ACCESS CONTROL | CLASS: TECHNICAL |
- Security Control Baseline:
| AC-19 | Access Control for Mobile Devices | P1 | LOW AC-19 | MOD AC-19 (1) (2) (3) | HIGH AC-19 (1) (2) (3) |
| SECURITY CONTROL |
|---|
|
AC-19 ACCESS CONTROL FOR MOBILE DEVICES
|
| ASSESSMENT PROCEDURE | ||
|---|---|---|
| AC-19 | ACCESS CONTROL FOR MOBILE DEVICES | |
| AC-19.1 | ASSESSMENT OBJECTIVE:
| |
| SECURITY CONTROL ENHANCEMENT |
|---|
|
| AC-19(1) | ACCESS CONTROL FOR MOBILE DEVICES | |
| AC-19(1).1 | ASSESSMENT OBJECTIVE:
|
| SECURITY CONTROL ENHANCEMENT |
|---|
|
| AC-19(2) | ACCESS CONTROL FOR MOBILE DEVICES | |
| AC-19(2).1 | ASSESSMENT OBJECTIVE:
|
| SECURITY CONTROL ENHANCEMENT |
|---|
|
| AC-19(3) | ACCESS CONTROL FOR MOBILE DEVICES | |
| AC-19(3).1 | ASSESSMENT OBJECTIVE:
|
AC-20 USE OF EXTERNAL INFORMATION SYSTEMS
| FAMILY: ACCESS CONTROL | CLASS: TECHNICAL |
- Security Control Baseline:
| AC-20 | Use of External Information Systems | P1 | LOW AC-20 | MOD AC-20 (1) (2) | HIGH AC-20 (1) (2) |
| SECURITY CONTROL |
|---|
|
AC-20 USE OF EXTERNAL INFORMATION SYSTEMS
|
| ASSESSMENT PROCEDURE | ||
|---|---|---|
| AC-20 | USE OF EXTERNAL INFORMATION SYSTEMS | |
| AC-20.1 | ASSESSMENT OBJECTIVE:
| |
| SECURITY CONTROL ENHANCEMENT |
|---|
|
| AC-20(1) | USE OF EXTERNAL INFORMATION SYSTEMS | |
| AC-20(1).1 | ASSESSMENT OBJECTIVE:
|
| SECURITY CONTROL ENHANCEMENT |
|---|
|
| AC-20(2) | USE OF EXTERNAL INFORMATION SYSTEMS | |
| AC-20(2).1 | ASSESSMENT OBJECTIVE:
|
AC-22 PUBLICLY ACCESSIBLE CONTENT
| FAMILY: ACCESS CONTROL | CLASS: TECHNICAL |
- Security Control Baseline:
| AC-22 | Publicly Accessible Content | P2 | LOW AC-22 | MOD AC-22 | HIGH AC-22 |
| SECURITY CONTROL |
|---|
|
AC-22 PUBLICLY ACCESSIBLE CONTENT
|
| ASSESSMENT PROCEDURE | ||
|---|---|---|
| AC-22 | PUBLICLY ACCESSIBLE CONTENT | |
| AC-22.1 | ASSESSMENT OBJECTIVE:
| |
del.icio.us
digg
Facebook
Newsvine
reddit
Slashdot