§ Trackr.Live
Latest writing

Notes from Trackr.Live

The landing site for Trackr Services

PS

PS-4: Personnel Termination

RMF Control PS-4: Personnel Termination requires organizations to disable information system access within a defined time period, terminate or revoke any authenticators and credentials associated with the individual, conduct exit interviews that include a discussion of security topics, retrieve all security-related organizational information system-related property, and retain access to organizational information and systems formerly controlled …

·
PM

PM-12: Insider Threat Program

RMF Control PM-12: Insider Threat Program requires organizations to implement an insider threat program that includes a cross-discipline insider threat incident handling team. Insider threat programs are designed to detect, prevent, and mitigate insider threats. Insider threats are threats to an organization that come from within the organization, such as employees, contractors, and vendors. Supplemental …

·
PE

PE-6: Monitoring Physical Access

RMF Control PE-6: Monitoring Physical Access requires organizations to monitor physical access to information systems, their components, and associated facilities. This monitoring can be done through a variety of methods, such as security guards, video surveillance, and access control systems. Supplemental Guidance The Risk Management Framework (RMF) is a cybersecurity framework that provides a process …

·
CP

CP-4: Contingency Plan Testing

RMF Control CP-4: Contingency Plan Testing requires organizations to test their contingency plans at least annually to ensure that they are effective and up-to-date. Contingency plans are plans that describe how an organization will respond to a disruption in its operations. Contingency plan testing is the process of simulating a disruption and evaluating the organization’s …

·
CM

CM-6: Configuration Settings

RMF Control CM-6: Configuration Settings requires organizations to establish and document configuration settings for information systems and their components that reflect the most restrictive mode consistent with operational requirements; implement the configuration settings; identify, document, and approve any deviations from established configuration settings; and monitor and control changes to the configuration settings in accordance with …

·
AU

AU-7: Audit Record Reduction and Report Generation

RMF Control AU-7: Audit Record Reduction and Report Generation requires organizations to implement an audit record reduction and report generation capability that supports on-demand audit review, analysis, and reporting requirements, and after-the-fact investigations of security incidents. Supplemental Guidance The Risk Management Framework (RMF) is a cybersecurity framework that provides a process for managing cybersecurity risk …

·
SR

SR-11: Component Authenticity

RMF Control SR-11: Component Authenticity requires organizations to develop and implement anti-counterfeit policy and procedures that include the means to detect and prevent counterfeit components from entering the system; and report counterfeit system components to [Assignment: organization-defined source of counterfeit component]. Supplemental Guidance The Risk Management Framework (RMF) is a cybersecurity framework that provides a …

·
SC

SC-37: Out-of-band Channels

RMF Control SC-37: Out-of-band Channels requires organizations to establish and maintain out-of-band channels for the physical delivery or electronic transmission of information, system components, or devices to designated individuals or information systems. Out-of-band channels are communication paths that are separate from the normal operational channels of an information system. This separation helps to protect organizations …

·
PM

PM-5: System Inventory

RMF Control PM-5: System Inventory requires organizations to maintain an accurate and up-to-date inventory of all information systems and their components. This inventory must include the following information: Supplemental Guidance The Risk Management Framework (RMF) is a cybersecurity framework that provides a process for managing cybersecurity risk to systems and organizations. RMF Control PM-5: System …

·
CA

CA-6: Authorization

RMF Control CA-6: Authorization requires organizations to authorize the operation of information systems and the processing, storage, and transmission of information by those systems. This authorization must be based on an assessment of the risks to the organization and the effectiveness of the organization’s security controls. Supplemental Guidance The Risk Management Framework (RMF) is a …

·