03.04.12: System and Component Configuration for High-Risk Areas
Control Familly: Configuration Management
SPRS: N/A
Top Ten Failed Requirement: N/A
Supporting Publications:
SP 800-124 [28]
SP 800-128 [41]
Referenced in: N/A
Control Type: N/A
CPCSC Level 2: 03.04.12
CMMC Level(s): N/A
Derived From: NIST SP 800-53r5
CM-02(07)
a. Issue systems or system components with the following configurations to individuals traveling to high-risk locations: [Assignment: organization-defined system configurations].
b. Apply the following security requirements to the systems or components when the individuals return from travel: [Assignment: organization-defined security requirements].
Discussion:
When it is known that a system or a system component will be in a high-risk area, additional security requirements may be needed to counter the increased threat. Organizations can implement protective measures on the systems or system components used by individuals departing on and returning from travel. Actions include determining whether the locations are of concern, defining the required configurations for the components, ensuring that the components are configured as intended before travel is initiated, and taking additional actions after travel is completed. For example, systems going into high-risk areas can be configured with sanitized hard drives, limited applications, and more stringent configuration settings. Actions applied to mobile devices upon return from travel include examining the device for signs of physical tampering and purging and reimaging the device storage.
Assessment Methods and Objectives
Examine [SELECT FROM: configuration management policy and procedures; configuration management plan; procedures for the baseline configuration of the system; procedures for system component installations and upgrades; system component inventory; system component installations or upgrades and associated records; records of system baseline configuration reviews and updates; system configuration settings; system architecture; change control records; system security plan; other relevant documents or records]
Interview [SELECT FROM: personnel with configuration management responsibilities; personnel with information security responsibilities; system administrators]
Test [SELECT FROM: processes for managing baseline configurations]
NIST SP 800-171A r3 Determining Statements Determine if:
A.03.04.12.ODP[01]: configurations for systems or system components to be issued to individuals traveling to high-risk locations are defined.
A.03.04.12.ODP[02]: security requirements to be applied to the system or system components when individuals return from travel are defined.
A.03.04.12.a: systems or system components with the following configurations are issued to individuals traveling to high-risk locations: <A.03.04.12.ODP[01]: configurations>.
A.03.04.12.b: the following security requirements are applied to the system or system components when the individuals return from travel: <A.03.04.12.ODP[02]: security requirements>.