Practices (L2) Flashcards
(94 cards)
AC.L2-3.1.3
Title: Control CUI Flow
Access Control (AC)
Level 2
Purpose: Control the flow of CUI IAW approved authorizations.
AC.L2-3.1.4
Title: Separation of Duties
Access Control (AC)
Level 2
Purpose: Separate the duties of individuals to reduce the risk of malevolent activity without collusion.
AC.L2-3.1.5
Title: Least Privilege
Access Control (AC)
Level 2
Purpose: Employ the principle of leas privilege, including for specific security functions and privileged accounts.
AC.L2-3.1.6
Title: Non-Privileged Account Use
Access Control (AC)
Level 2
Purpose: use non-privileged accounts or roles when accessing non-security functions.
AC-L2.3.1.7
Title: Privileged Functions
Access Control (AC)
Level 2
Purpose: Prevent non-privileged users from executing privileged functions and capture the execution of such functions in audit logs.
AC.L2-3.1.8
Title: Unsuccessful Logon Attempts
Access Control (AC)
Level 2
Purpose: Limit unsuccessful logon attempts
AC.L2-3.1.9
Title: Privacy & Security Notices
Access Control (AC)
Level 2
Purpose: Provide privacy and security notices consistent with applicable CUI rules.
AC.L2-3.1.10
Title: Session Lock
Access Control (AC)
Level 2
Purpose: Use session lock with pattern-hiding displays to prevent access and viewing of data after a period of inactivity.
AC.L2-3.1.11
Title: Session Termination
Access Control (AC)
Level 2
Purpose: Terminate (automatically) a user session after a defined condition
AC.L2-3.1.12
Title: Control Remote Access
Access Control (AC)
Level 2
Purpose: Monitor and control remote access sessions
AC.L2-3.1.13
Title: Session Termination
Access Control (AC)
Level 2
Purpose: Employ cryptographic mechanisms to protect the confidentiality of remote access sessions.
AC.L2-3.1.14
Title: Remote Access Routing
Access Control (AC)
Level 2
Purpose: Route remote access via managed access control points.
AC.L2-3.1.15
Title: Privileged Remote Access
Access Control (AC)
Level 2
Purpose: Authorize remote execution of privileged commands and remote access to security-relevant information.
AC.L2-3.1.16
Title: Wireless Access Authorization
Access Control (AC)
Level 2
Purpose: Authorize wireless access prior to allowing such connections
AC.L2-3.1.17
Title: Wireless Access Protection
Access Control (AC)
Level 2
Purpose: Protect wireless access using authenticationand encryption
AC.L2-3.1.18
Title: Mobile Device Connection
Access Control (AC)
Level 2
Purpose: Control connection of mobile devices
AC.L2-3.1.19
Title: Encrypt CUI on Mobile
Access Control (AC)
Level 2
Purpose: Encrypt UI on mobile devices and mobile computing platforms
AC.L2-3.1.21
Title: Portable Storage Use
Access Control (AC)
Level 2
Purpose: Limit use of portable storage devices on external systems
AU.L2-3.3.1
Title: System Auditing
Audit and Accountability (AU)
Level 2
Purpose: Create and retain system audit logs and records to the extent needed to enable the monitoring, analysis, investigation, and reporting of unlawful or unauthorized system activity.
AU.L2-3.3.2
Title: User Accountability
Audit and Accountability (AU)
Level 2
Purpose: Ensure the actions of individual system users can be uniquely traced to those users so they can be held accountable for their actions.
AU.L2-3.3.3
Title: Event Review
Audit and Accountability (AU)
Level 2
Purpose: Review and update logged events.
AU.L2-3.3.4
Title: Audit Failure Alerting
Audit and Accountability (AU)
Level 2
Purpose: Alert in the event of an audit logging process failure.
AU.L2-3.3.5
Title: Audit Correlation
Audit and Accountability (AU)
Level 2
Purpose: Correlate audit record review, analysis, and reporting processes for investigation and response to indications of unlawful, unauthorized, suspicious, or unusual activity.
AU.L2-3.3.6
Title: Reduction & Reporting
Audit and Accountability (AU)
Level 2
Purpose: Provide audit record reduction and report generation to support on-demand analysis and reporting.