STIGhub
STIGs
RMF Controls
Compare
← All Controls
SC-1
System and Communications Protection
Rev 4
Policy and Procedures
CCI Identifiers (25)
CCI-001074
The organization develops a system and communications protection policy that addresses purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance.
CCI-001075
Disseminates to organization-defined personnel or roles the organization-level; mission/business process-level; and/or system-level system and communications protection policy.
CCI-001076
Review and update the current system and communications protection policy in accordance with organization-defined frequency.
CCI-001077
Defines the frequency for reviewing and updating the current system and communications protection policy.
CCI-001078
The organization develops system and communications protection procedures to facilitate the implementation of the system and communications protection policy and associated system and communications protection controls.
CCI-001079
Disseminates to organization-defined personnel or roles the procedures to facilitate the implementation of the system and communications protection policy and associated system and communications protection controls.
CCI-001080
Review and update the current system and communications protection procedures in accordance with organization-defined frequency.
CCI-001081
Defines the frequency for reviewing and updating the current system and communications protection procedures.
CCI-002377
The organization documents the system and communications protection policy.
CCI-002378
Defines the personnel or roles to be recipients of the organization-level; mission/business process-level; and/or system-level system and communications protection policy.
CCI-002379
The organization documents procedures to facilitate the implementation of the system and communications protection policy and associated system and communications protection controls.
CCI-002380
Defines the personnel or roles to be recipients of the procedures to facilitate the implementation of the system and communications protection policy and associated system and communications protection controls.
CCI-004852
Develop and document an organization-level; mission/business process-level; and/or system-level system and communications protection policy that addresses purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance.
CCI-004853
Develop and document an organization-level; mission/business process-level; and/or system-level a system and communications protection policy that is consistent with applicable laws, Executive Orders, directives, regulations, policies, standards, and guidelines.
CCI-004854
Develop and document system and communications protection procedures to facilitate the implementation of the system and communications protection policy and associated system and communications protection controls.
CCI-004855
Designate an organization-defined official to manage the development and documentation of the system and communications protection policy.
CCI-004856
Designate an organization-defined official to manage the development and documentation of the system and communications protection procedures.
CCI-004857
Designate an organization-defined official to manage the dissemination of the system and communications protection policy.
CCI-004858
Designate an organization-defined official to manage the dissemination of the system and communications protection procedures.
CCI-004859
Defines the official to manage the development, documentation, and dissemination of the system and communications protection policy.
CCI-004860
Defines the official to manage the development, documentation, and dissemination of the system and communications protection procedures.
CCI-004861
Review and update the current system and communications protection policy following organization-defined events.
CCI-004862
Defines the events following reviewing and updating the current system and communications protection policy.
CCI-004863
Review and update the current system and communications protection procedures following organization-defined events.
CCI-004864
Defines the events following reviewing and updating the current system and communications protection procedures.
Linked STIG Checks (0)
No STIG checks reference this control.