id: "AU-10(04)" title: "Validate Binding of Information Reviewer Identity" family: "AU" family_name: "Audit and Accountability" sort_id: "au-10.04" priority: "P2" implementation_level: "system" parent: "AU-10" enhancement: True


Validate the binding of the information reviewer identity to the information at the transfer or release points prior to release or transfer between {{ insert: param, au-10.04_odp.01 }} ; and

Perform {{ insert: param, au-10.04_odp.02 }} in the event of a validation error.

Guidance

Validating the binding of the information reviewer identity to the information at transfer or release points prevents the unauthorized modification of information between review and the transfer or release. The validation of bindings can be achieved by using cryptographic checksums. Organizations determine if validations are in response to user requests or generated automatically.

Assessment Objective: the binding of the information reviewer identity to the information at the transfer or release points prior to release or transfer between {{ insert: param, au-10.04_odp.01 }} is validated;

Assessment Objective: {{ insert: param, au-10.04_odp.02 }} are performed in the event of a validation error.

Audit and accountability policy

system security plan

privacy plan

procedures addressing non-repudiation

system design documentation

system configuration settings and associated documentation

validation records

system audit records

other relevant documents or records

Organizational personnel with information security and privacy responsibilities

system/network administrators

system developers

Mechanisms implementing non-repudiation capability