id: "AC-03(05)" title: "Security-relevant Information" family: "AC" family_name: "Access Control" sort_id: "ac-03.05" priority: "P1" implementation_level: "system" parent: "AC-03" enhancement: True


Statement

Prevent access to {{ insert: param, ac-03.05_odp }} except during secure, non-operable system states.

Guidance

Security-relevant information is information within systems that can potentially impact the operation of security functions or the provision of security services in a manner that could result in failure to enforce system security and privacy policies or maintain the separation of code and data. Security-relevant information includes access control lists, filtering rules for routers or firewalls, configuration parameters for security services, and cryptographic key management information. Secure, non-operable system states include the times in which systems are not performing mission or business-related processing, such as when the system is offline for maintenance, boot-up, troubleshooting, or shut down.

Assessment Objective

access to {{ insert: param, ac-03.05_odp }} is prevented except during secure, non-operable system states.

Access control policy

procedures addressing access enforcement

system design documentation

system configuration settings and associated documentation

system audit records

system security plan

other relevant documents or records

Organizational personnel with access enforcement responsibilities

system/network administrators

organizational personnel with information security responsibilities

system developers

Mechanisms preventing access to security-relevant information within the system