From Traditional Security
Part of PDS Monitoring - Initial Inspection
Associated with IA controls: DCSR-3, PESS-1, ECCT-2
A PDS that is not inspected, monitored and maintained as required could result in undetected access, sabotage or tampering of the unencrypted transmission lines. This could directly lead to the loss or compromise of classified.
Check to ensure the PDS was inspected prior to initial operation. Documentation of the inspection and results should be available for review. This meets the following requirement from the NSTISSI 7003: "The Approval Authority shall ensure the PDS are inspected prior to initial operation." NOTES: 1. This check is applicable in a tactical environment if the PDS is located within a fixed facility. It is not applicable to field/mobile PDS. 2. In the reviewer notes be sure to provide the date of the initial inspection, name of inspector and general description of results.
Following is a reiteration of the requirement: The PDS must be inspected prior to initial operation. Documentation of the inspection and results must be available for review. This meets the following requirement from the NSTISSI 7003: "The Approval Authority shall ensure the PDS are inspected prior to initial operation." Obviously an initial inspection cannot ever be conducted once it is not completed. Therefore the fix for this finding is to send a written request to the PDS approval authority asking for an "initial" inspection of the PDS by an individual appointed by the approval authority. If the approval authority concurs to conduct the inspection then this finding can be closed once the inspection is actually completed and any results form that inspection are closed. If the reply from the approval authority indicates they will not complete their "required" inspection then then finding can be closed and the reply from the approval authority should be maintained for future reference.
Lavender hyperlinks in small type off to the right (of CSS
class id
, if you view the page source) point to
globally unique URIs for each document and item. Copy the
link location and paste anywhere you need to talk
unambiguously about these things.
You can obtain data about documents and items in other
formats. Simply provide an HTTP header Accept:
text/turtle
or
Accept: application/rdf+xml
.
Powered by sagemincer