id: "AU-10(04)" title: "Validate Binding of Information Reviewer Identity" family: "AU" family_name: "Audit and Accountability" sort_id: "au-10.04" priority: "P2" implementation_level: "system" parent: "AU-10" enhancement: True
Validate the binding of the information reviewer identity to the information at the transfer or release points prior to release or transfer between {{ insert: param, au-10.04_odp.01 }} ; and
Perform {{ insert: param, au-10.04_odp.02 }} in the event of a validation error.
Guidance
Validating the binding of the information reviewer identity to the information at transfer or release points prevents the unauthorized modification of information between review and the transfer or release. The validation of bindings can be achieved by using cryptographic checksums. Organizations determine if validations are in response to user requests or generated automatically.
Assessment Objective: the binding of the information reviewer identity to the information at the transfer or release points prior to release or transfer between {{ insert: param, au-10.04_odp.01 }} is validated;
Assessment Objective: {{ insert: param, au-10.04_odp.02 }} are performed in the event of a validation error.
Audit and accountability policy
system security plan
privacy plan
procedures addressing non-repudiation
system design documentation
system configuration settings and associated documentation
validation records
system audit records
other relevant documents or records
Organizational personnel with information security and privacy responsibilities
system/network administrators
system developers
Mechanisms implementing non-repudiation capability