id: "SC-16(02)" title: "Anti-spoofing Mechanisms" family: "SC" family_name: "System and Communications Protection" sort_id: "sc-16.02" priority: "P1" implementation_level: "system" parent: "SC-16" enhancement: True
Statement
Implement anti-spoofing mechanisms to prevent adversaries from falsifying the security attributes indicating the successful application of the security process.
Guidance
Some attack vectors operate by altering the security attributes of an information system to intentionally and maliciously implement an insufficient level of security within the system. The alteration of attributes leads organizations to believe that a greater number of security functions are in place and operational than have actually been implemented.
Assessment Objective
anti-spoofing mechanisms are implemented to prevent adversaries from falsifying the security attributes indicating the successful application of the security process.
System and communications protection policy
procedures addressing the transmission of security and privacy attributes
access control policy and procedures
system design documentation
system configuration settings and associated documentation
system audit records
system security plan
other relevant documents or records
System/network administrators
organizational personnel with information security responsibilities
Mechanisms supporting and/or implementing anti-spoofing mechanisms