Fedramp system Security Plan (ssp) High Baseline Template


SA-5 Information System Documentation (H)



Download 1.2 Mb.
Page367/478
Date16.12.2020
Size1.2 Mb.
#54609
1   ...   363   364   365   366   367   368   369   370   ...   478
FedRAMP-SSP-High-Baseline-Template
FedRAMP-SSP-High-Baseline-Template, North Carolina Summary Table of Ecoregion Characteristics

SA-5 Information System Documentation (H)


The organization:

  1. Obtains administrator documentation for the information system, system component, or information system service that describes:

    1. Secure configuration, installation, and operation of the system, component, or service;

    2. Effective use and maintenance of security functions/mechanisms; and

    3. Known vulnerabilities regarding configuration and use of administrative (i.e., privileged) functions;

  1. Obtains user documentation for the information system, system component, or information system service that describes:

    1. User-accessible security functions/mechanisms and how to effectively use those security functions/mechanisms;

    2. Methods for user interaction, which enables individuals to use the system, component, or service in a more secure manner; and

    3. User responsibilities in maintaining the security of the system, component, or service;

  1. Documents attempts to obtain information system, system component, or information system service documentation when such documentation is either unavailable or nonexistent and [Assignment: organization-defined actions] in response;

  2. Protects documentation as required, in accordance with the risk management strategy; and

  3. Distributes documentation to [FedRAMP Assignment: at a minimum, the ISSO (or similar role within the organization)].



SA-5


Download 1.2 Mb.

Share with your friends:
1   ...   363   364   365   366   367   368   369   370   ...   478




The database is protected by copyright ©ininet.org 2024
send message

    Main page