id: "AC-22" title: "Publicly Accessible Content" family: "AC" family_name: "Access Control" sort_id: "ac-22" priority: "P1" implementation_level: "organization"
Designate individuals authorized to make information publicly accessible;
Train authorized individuals to ensure that publicly accessible information does not contain nonpublic information;
Review the proposed content of information prior to posting onto the publicly accessible system to ensure that nonpublic information is not included; and
Review the content on the publicly accessible system for nonpublic information {{ insert: param, ac-22_odp }} and remove such information, if discovered.
Guidance
In accordance with applicable laws, executive orders, directives, policies, regulations, standards, and guidelines, the public is not authorized to have access to nonpublic information, including information protected under the PRIVACT and proprietary information. Publicly accessible content addresses systems that are controlled by the organization and accessible to the public, typically without identification or authentication. Posting information on non-organizational systems (e.g., non-organizational public websites, forums, and social media) is covered by organizational policy. While organizations may have individuals who are responsible for developing and implementing policies about the information that can be made publicly accessible, publicly accessible content addresses the management of the individuals who make such information publicly accessible.
Assessment Objective: designated individuals are authorized to make information publicly accessible;
Assessment Objective: authorized individuals are trained to ensure that publicly accessible information does not contain non-public information;
Assessment Objective: the proposed content of information is reviewed prior to posting onto the publicly accessible system to ensure that non-public information is not included;
Assessment Objective: the content on the publicly accessible system is reviewed for non-public information {{ insert: param, ac-22_odp }};
Assessment Objective: non-public information is removed from the publicly accessible system, if discovered.
Access control policy
procedures addressing publicly accessible content
list of users authorized to post publicly accessible content on organizational systems
training materials and/or records
records of publicly accessible information reviews
records of response to non-public information on public websites
system audit logs
security awareness training records
system security plan
other relevant documents or records
Organizational personnel with responsibilities for managing publicly accessible information posted on organizational systems
organizational personnel with information security responsibilities
Mechanisms implementing management of publicly accessible content