§ Trackr.Live
Latest writing

Notes from Trackr.Live

The landing site for Trackr Services

RA

RA-4: Risk Assessment Update

RMF Control RA-4: Risk Assessment Update requires organizations to update their risk assessments on a regular basis to ensure that they are accurate and up-to-date. This is important because cybersecurity risks are constantly changing, and organizations need to be aware of the latest threats and vulnerabilities in order to protect their systems and data. Supplemental …

·
PT

PT-3: Personally Identifiable Information Processing Purposes

RMF Control PT-3: Personally Identifiable Information Processing Purposes requires organizations to identify and document the purpose(s) for processing personally identifiable information (PII), describe the purpose(s) in the public privacy notices and policies of the organization, restrict the processing of PII to only that which is compatible with the identified purpose(s), and monitor changes in processing …

·
PS

PS-6: Access Agreements

RMF Control PS-6: Access Agreements requires organizations to establish and implement access agreements for all individuals with access to information systems. Access agreements should specify the types of access that are authorized, the purposes for which access is granted, and the conditions that must be met in order to maintain access. Supplemental Guidance The Risk …

·
PM

PM-3: Information Security and Privacy Resources

RMF Control PM-3: Information Security and Privacy Resources requires organizations to ensure that all capital planning and investment requests include the resources needed to implement the information security and privacy programs, and documents all exceptions to this requirement. Organizations should also prepare documentation required for addressing information security and privacy programs in capital planning and …

·
PL

PL-6: Security-Related Activity Planning

RMF Control PL-6: Security-Related Activity Planning requires organizations to plan and coordinate security-related activities affecting information systems before conducting such activities in order to reduce the impact on organizational operations (i.e., mission, functions, image, and reputation), organizational assets, and individuals. Supplemental Guidance The Risk Management Framework (RMF) is a cybersecurity framework that provides a process …

·
PE

PE-14: Environmental Controls

RMF Control PE-14: Environmental Controls requires organizations to implement controls to protect information systems from environmental hazards. Environmental hazards can include temperature, humidity, dust, power outages, and natural disasters. Supplemental Guidance The Risk Management Framework (RMF) is a cybersecurity framework that provides a process for managing cybersecurity risk to systems and organizations. RMF Control PE-14: …

·
MP

MP-6: Media Sanitization

RMF Control MP-6: Media Sanitization requires organizations to sanitize media before it is disposed of or reused to prevent unauthorized access to information. Media can include hard drives, solid-state drives, optical discs, and magnetic tapes. Supplemental Guidance The Risk Management Framework (RMF) is a cybersecurity framework that provides a process for managing cybersecurity risk to …

·
MA

MA-3: Maintenance Tools

RMF Control MA-3: Maintenance Tools requires organizations to inspect and control maintenance tools to protect information systems from unauthorized access or modification. Maintenance tools can include hardware, software, and firmware that are used to diagnose, repair, or update information systems. Supplemental Guidance The Risk Management Framework (RMF) is a cybersecurity framework that provides a process …

·
IR

IR-5: Incident Monitoring

RMF Control IR-5: Incident Monitoring requires organizations to track and document information system security incidents. This includes identifying incidents, assessing their impact, and taking steps to mitigate the impact and prevent future incidents. Supplemental Guidance The Risk Management Framework (RMF) is a cybersecurity framework that provides a process for managing cybersecurity risk to systems and …

·
IA

IA-5: Authenticator Management

RMF Control IA-5: Authenticator Management requires organizations to select, implement, and manage authenticators to verify the identity of users attempting to access information systems or data. Supplemental Guidance The Risk Management Framework (RMF) is a cybersecurity framework that provides a process for managing cybersecurity risk to systems and organizations. RMF Control IA-5: Authenticator Management is …

·