id: "AC-03(05)" title: "Security-relevant Information" family: "AC" family_name: "Access Control" sort_id: "ac-03.05" priority: "P1" implementation_level: "system" parent: "AC-03" enhancement: True
Statement
Prevent access to {{ insert: param, ac-03.05_odp }} except during secure, non-operable system states.
Guidance
Security-relevant information is information within systems that can potentially impact the operation of security functions or the provision of security services in a manner that could result in failure to enforce system security and privacy policies or maintain the separation of code and data. Security-relevant information includes access control lists, filtering rules for routers or firewalls, configuration parameters for security services, and cryptographic key management information. Secure, non-operable system states include the times in which systems are not performing mission or business-related processing, such as when the system is offline for maintenance, boot-up, troubleshooting, or shut down.
Assessment Objective
access to {{ insert: param, ac-03.05_odp }} is prevented except during secure, non-operable system states.
Access control policy
procedures addressing access enforcement
system design documentation
system configuration settings and associated documentation
system audit records
system security plan
other relevant documents or records
Organizational personnel with access enforcement responsibilities
system/network administrators
organizational personnel with information security responsibilities
system developers
Mechanisms preventing access to security-relevant information within the system