ID.AM-08: Systems, hardware, software, services, and data are managed throughout their life cycles
Subcategory is new to this version of the framework and incorporates the following items from the previous version: PR.DS: Data Security, PR.DS-3: Assets are formally managed throughout removal, transfers, and disposition, PR.IP-2: A System Development Life Cycle to manage systems is implemented, PR.IP-6: Data is destroyed according to policy, PR.MA-1: Maintenance and repair of organizational assets are performed and logged, with approved and controlled tools, PR.MA-2: Remote maintenance of organizational assets is approved, logged, and performed in a manner that prevents unauthorized access.
Description
[csf.tools Note: Subcategories do not have detailed descriptions. However NIST has provided the following implementation examples.]
Implementation Examples
1st: 1st Party Risk
3rd: 3rd Party Risk
Ex1: Integrate cybersecurity considerations throughout the life cycles of systems, hardware, software, and services
Ex2: Integrate cybersecurity considerations into product life cycles
Ex3: Identify unofficial uses of technology to meet mission objectives (i.e., shadow IT)
Ex4: Periodically identify redundant systems, hardware, software, and services that unnecessarily increase the organization's attack surface
Ex5: Properly configure and secure systems, hardware, software, and services prior to their deployment in production
Ex6: Update inventories when systems, hardware, software, and services are moved or transferred within the organization
Ex7: Securely destroy stored data based on the organization's data retention policy using the prescribed destruction method, and keep and manage a record of the destructions
Ex8: Securely sanitize data storage when hardware is being retired, decommissioned, reassigned, or sent for repairs or replacement
Ex9: Offer methods for destroying paper, storage media, and other physical forms of data storage
Related Controls
NIST Special Publication 800-53 Revision 5.2.0
CM-9: Configuration Management Plan
Develop, document, and implement a configuration management plan for the system that: Addresses roles, responsibilities, and configuration management processes and procedures; Establishes a process for identifying configuration items throughout the system development life cycle and for managing the configuration of the configuration items; Defines the configuration items for the system and places the configuration items…
CM-13: Data Action Mapping
Develop and document a map of system data actions.
MA-2: Controlled Maintenance
Schedule, document, and review records of maintenance, repair, and replacement on system components in accordance with manufacturer or vendor specifications and/or organizational requirements; Approve and monitor all maintenance activities, whether performed on site or remotely and whether the system or system components are serviced on site or removed to another location; Require that [Assignment: organization-defined…
MA-6: Timely Maintenance
Obtain maintenance support and/or spare parts for [Assignment: organization-defined system components] within [Assignment: organization-defined time period] of failure.
PL-2: System Security and Privacy Plans
Develop security and privacy plans for the system that: Are consistent with the organization’s enterprise architecture; Explicitly define the constituent system components; Describe the operational context of the system in terms of mission and business processes; Identify the individuals that fulfill system roles and responsibilities; Identify the information types processed, stored, and transmitted by the…
PM-22: Personally Identifiable Information Quality Management
Develop and document organization-wide policies and procedures for: Reviewing for the accuracy, relevance, timeliness, and completeness of personally identifiable information across the information life cycle; Correcting or deleting inaccurate or outdated personally identifiable information; Disseminating notice of corrected or deleted personally identifiable information to individuals or other appropriate entities; and Appeals of adverse decisions on…
PM-23: Data Governance Body
Establish a Data Governance Body consisting of [Assignment: organization-defined roles] with [Assignment: organization-defined responsibilities].
SA-3: System Development Life Cycle
Acquire, develop, and manage the system using [Assignment: organization-defined system-development life cycle] that incorporates information security and privacy considerations; Define and document information security and privacy roles and responsibilities throughout the system development life cycle; Identify individuals having information security and privacy roles and responsibilities; and Integrate the organizational information security and privacy risk management…
SA-4: Acquisition Process
Include the following requirements, descriptions, and criteria, explicitly or by reference, using [Assignment (one or more): standardized contract language, [Assignment: organization-defined contract language] ] in the acquisition contract for the system, system component, or system service: Security and privacy functional requirements; Strength of mechanism requirements; Security and privacy assurance requirements; Controls needed to satisfy the…
SA-8: Security and Privacy Engineering Principles
Apply the following systems security and privacy engineering principles in the specification, design, development, implementation, and modification of the system and system components: [Assignment: organization-defined systems security and privacy engineering principles].
SA-22: Unsupported System Components
Replace system components when support for the components is no longer available from the developer, vendor, or manufacturer; or Provide the following options for alternative sources for continued support for unsupported components [Assignment (one or more): in-house support, [Assignment: organization-defined support from external providers] ].
SI-12: Information Management and Retention
Manage and retain information within the system and information output from the system in accordance with applicable laws, executive orders, directives, regulations, policies, standards, guidelines and operational requirements.
SI-18: Personally Identifiable Information Quality Operations
Check the accuracy, relevance, timeliness, and completeness of personally identifiable information across the information life cycle [Assignment: organization-defined frequency] ; and Correct or delete inaccurate or outdated personally identifiable information.
SR-5: Acquisition Strategies, Tools, and Methods
Employ the following acquisition strategies, contract tools, and procurement methods to protect against, identify, and mitigate supply chain risks: [Assignment: organization-defined strategies, tools, and methods].
SR-12: Component Disposal
Dispose of [Assignment: organization-defined data, documentation, tools, or system components] using the following techniques and methods: [Assignment: organization-defined techniques and methods].
NIST SP 800-171 Revision 3.0
03.14.08: Information Management and Retention
Manage and retain CUI within the system and CUI output from the system in accordance with applicable laws, Executive Orders, directives, regulations, policies, standards, guidelines, and operational requirements.
03.15.02: System Security Plan
Develop a system security plan that: Defines the constituent system components; Identifies the information types processed, stored, and transmitted by the system; Describes specific threats to the system that are of concern to the organization; Describes the operational environment for the system and any dependencies on or connections to other systems or system components; Provides…
03.16.01: Security Engineering Principles
Apply the following systems security engineering principles to the development or modification of the system and system components: [Assignment: organization-defined systems security engineering principles].
03.16.02: Unsupported System Components
Replace system components when support for the components is no longer available from the developer, vendor, or manufacturer. Provide options for risk mitigation or alternative sources for continued support for unsupported components that cannot be replaced.
03.17.02: Acquisition Strategies, Tools, and Methods
Develop and implement acquisition strategies, contract tools, and procurement methods to identify, protect against, and mitigate supply chain risks.
Cloud Controls Matrix v4.0
AIS-02: Application Security Baseline Requirements
Establish, document and maintain baseline requirements for securing different applications.
AIS-04: Secure Application Design and Development
Define and implement a SDLC process for application design, development, deployment, and operation in accordance with security requirements defined by the organization.
AIS-05: Automated Application Security Testing
Implement a testing strategy, including criteria for acceptance of new information systems, upgrades and new versions, which provides application security assurance and maintains compliance while enabling organizational speed of delivery goals. Automate when applicable and possible.
AIS-06: Automated Secure Application Deployment
Establish and implement strategies and capabilities for secure, standardized, and compliant application deployment. Automate where possible.
AIS-07: Application Vulnerability Remediation
Define and implement a process to remediate application security vulnerabilities, automating remediation when possible.
CCC-04: Unauthorized Change Protection
Restrict the unauthorized addition, removal, update, and management of organization assets.
CEK-14: Key Destruction
Define, implement and evaluate processes, procedures and technical measures to destroy keys stored outside a secure environment and revoke keys stored in Hardware Security Modules (HSMs) when they are no longer needed, which include provisions for legal and regulatory requirements.
CEK-21: Key Inventory Management
Define, implement and evaluate processes, procedures and technical measures in order for the key management system to track and report all cryptographic materials and changes in status, which include provisions for legal and regulatory requirements.
DCS-01: Off-Site Equipment Disposal Policy and Procedures
Establish, document, approve, communicate, apply, evaluate and maintain policies and procedures for the secure disposal of equipment used outside the organization's premises. If the equipment is not physically destroyed a data destruction procedure that renders recovery of information impossible must be applied. Review and update the policies and procedures at least annually.
DCS-02: Off-Site Transfer Authorization Policy and Procedures
Establish, document, approve, communicate, apply, evaluate and maintain policies and procedures for the relocation or transfer of hardware, software, or data/information to an offsite or alternate location. The relocation or transfer request requires the written or cryptographically verifiable authorization. Review and update the policies and procedures at least annually.
DSP-02: Secure Disposal
Apply industry accepted methods for the secure disposal of data from storage media such that data is not recoverable by any forensic means.
DSP-07: Data Protection by Design and Default
Develop systems, products, and business practices based upon a principle of security by design and industry best practices.
DSP-16: Data Retention and Deletion
Data retention, archiving and deletion is managed in accordance with business requirements, applicable laws and regulations.
DSP-19: Data Location
Define and implement, processes, procedures and technical measures to specify and document the physical locations of data, including any locations in which data is processed or backed up.
HRS-05: Asset returns
Establish and document procedures for the return of organization-owned assets by terminated employees.
IVS-01: Infrastructure and Virtualization Security Policy and Procedures
Establish, document, approve, communicate, apply, evaluate and maintain policies and procedures for infrastructure and virtualization security. Review and update the policies and procedures at least annually.
LOG-02: Audit Logs Protection
Define, implement and evaluate processes, procedures and technical measures to ensure the security and retention of audit logs.
LOG-06: Clock Synchronization
Use a reliable time source across all relevant information processing systems.
UEM-03: Compatibility
Define and implement a process for the validation of the endpoint device's compatibility with operating systems and applications.
UEM-05: Endpoint Management
Define, implement and evaluate processes, procedures and technical measures to enforce policies and controls for all endpoints permitted to access systems and/or store, transmit, or process organizational data.
UEM-09: Anti-Malware Detection and Prevention
Configure managed endpoints with anti-malware detection and prevention technology and services.
UEM-10: Software Firewall
Configure managed endpoints with properly configured software firewalls.
UEM-11: Data Loss Prevention
Configure managed endpoints with Data Loss Prevention (DLP) technologies and rules in accordance with a risk assessment.
UEM-13: Remote Wipe
Define, implement and evaluate processes, procedures and technical measures to enable the deletion of company data remotely on managed endpoint devices.
Critical Security Controls Version 8.1
1.1: Establish and Maintain Detailed Enterprise Asset Inventory
Establish and maintain an accurate, detailed, and up-to-date inventory of all enterprise assets with the potential to store or process data, to include: end-user devices (including portable and mobile), network devices, non-computing/IoT devices, and servers. Ensure the inventory records the network address (if static), hardware address, machine name, enterprise asset owner, department for each asset, and whether the asset has been approved to connect to the network. For mobile end-user devices, MDM type tools can support this process, where appropriate. This inventory includes assets connected to the infrastructure physically, virtually, remotely, and those within cloud environments. Additionally, it includes assets that are regularly connected to the enterprise's network infrastructure, even if they are not under control of the enterprise. Review and update the inventory of all enterprise assets bi-annually, or more frequently.
3.5: Securely Dispose of Data
Securely dispose of data as outlined in the enterprise's data management process. Ensure the disposal process and method are commensurate with the data sensitivity.