id: "SC-16(02)" title: "Anti-spoofing Mechanisms" family: "SC" family_name: "System and Communications Protection" sort_id: "sc-16.02" priority: "P1" implementation_level: "system" parent: "SC-16" enhancement: True


Statement

Implement anti-spoofing mechanisms to prevent adversaries from falsifying the security attributes indicating the successful application of the security process.

Guidance

Some attack vectors operate by altering the security attributes of an information system to intentionally and maliciously implement an insufficient level of security within the system. The alteration of attributes leads organizations to believe that a greater number of security functions are in place and operational than have actually been implemented.

Assessment Objective

anti-spoofing mechanisms are implemented to prevent adversaries from falsifying the security attributes indicating the successful application of the security process.

System and communications protection policy

procedures addressing the transmission of security and privacy attributes

access control policy and procedures

system design documentation

system configuration settings and associated documentation

system audit records

system security plan

other relevant documents or records

System/network administrators

organizational personnel with information security responsibilities

Mechanisms supporting and/or implementing anti-spoofing mechanisms