PR.DS-10: The confidentiality, integrity, and availability of data-in-use are protected
Threats Addressed:
Subcategory is new to this version of the framework and incorporates the following item from the previous version: PR.DS-5: Protections against data leaks are implemented.
Description
[csf.tools Note: Subcategories do not have detailed descriptions. However NIST has provided the following implementation examples.]
Implementation Examples
1st: 1st Party Risk
Ex1: Remove data that must remain confidential (e.g., from processors and memory) as soon as it is no longer needed
Ex2: Protect data in use from access by other users and processes of the same platform
Related Controls
NIST Special Publication 800-53 Revision 5.2.0
AC-2: Account Management
Define and document the types of accounts allowed and specifically prohibited for use within the system; Assign account managers; Require [Assignment: organization-defined prerequisites and criteria] for group and role membership; Specify: Authorized users of the system; Group and role membership; and Access authorizations (i.e., privileges) and [Assignment: organization-defined attributes (as required)] for each account; Require…
AC-3: Access Enforcement
Enforce approved authorizations for logical access to information and system resources in accordance with applicable access control policies.
AC-4: Information Flow Enforcement
Enforce approved authorizations for controlling the flow of information within the system and between connected systems based on [Assignment: organization-defined information flow control policies].
AU-9: Protection of Audit Information
Protect audit information and audit logging tools from unauthorized access, modification, and deletion; and Alert [Assignment: organization-defined personnel or roles] upon detection of unauthorized access, modification, or deletion of audit information.
AU-13: Monitoring for Information Disclosure
Monitor [Assignment: organization-defined open-source information and/or information sites] [Assignment: organization-defined frequency] for evidence of unauthorized disclosure of organizational information; and If an information disclosure is discovered: Notify [Assignment: organization-defined personnel or roles] ; and Take the following additional actions: [Assignment: organization-defined additional actions].
CA-3: Information Exchange
Approve and manage the exchange of information between the system and other systems using [Assignment (one or more): interconnection security agreements, information exchange security agreements, memoranda of understanding or agreement, service level agreements, user agreements, non-disclosure agreements, [Assignment: organization-defined type of agreement] ]; Document, as part of each exchange agreement, the interface characteristics, security and…
CP-9: System Backup
Conduct backups of user-level information contained in [Assignment: organization-defined system components] [Assignment: organization-defined frequency]; Conduct backups of system-level information contained in the system [Assignment: organization-defined frequency]; Conduct backups of system documentation, including security- and privacy-related documentation [Assignment: organization-defined frequency] ; and Protect the confidentiality, integrity, and availability of backup information.
SA-8: Security and Privacy Engineering Principles
Apply the following systems security and privacy engineering principles in the specification, design, development, implementation, and modification of the system and system components: [Assignment: organization-defined systems security and privacy engineering principles].
SC-4: Information in Shared System Resources
Prevent unauthorized and unintended information transfer via shared system resources.
SC-7: Boundary Protection
Monitor and control communications at the external managed interfaces to the system and at key internal managed interfaces within the system; Implement subnetworks for publicly accessible system components that are [Assignment: physically, logically] separated from internal organizational networks; and Connect to external networks or systems only through managed interfaces consisting of boundary protection devices arranged…
SC-11: Trusted Path
Provide a [Assignment: physically, logically] isolated trusted communications path for communications between the user and the trusted components of the system; and Permit users to invoke the trusted communications path for communications between the user and the following security functions of the system, including at a minimum, authentication and re-authentication: [Assignment: organization-defined security functions].
SC-13: Cryptographic Protection
Determine the [Assignment: organization-defined cryptographic uses] ; and Implement the following types of cryptography required for each specified cryptographic use: [Assignment: organization-defined types of cryptography].
SC-24: Fail in Known State
Fail to a [Assignment: organization-defined known system state] for the following failures on the indicated components while preserving [Assignment: organization-defined system state information] in failure: [Assignment: organization-defined types of system failures on system components].
SC-32: System Partitioning
Partition the system into [Assignment: organization-defined system components] residing in separate [Assignment: physical, logical] domains or environments based on [Assignment: organization-defined circumstances for the physical or logical separation of components].
SC-39: Process Isolation
Maintain a separate execution domain for each executing system process.
SC-40: Wireless Link Protection
Protect external and internal [Assignment: organization-defined wireless links] from the following signal parameter attacks: [Assignment: organization-defined types of signal parameter attacks or references to sources for such attacks].
SC-43: Usage Restrictions
Establish usage restrictions and implementation guidelines for the following system components: [Assignment: organization-defined components] ; and Authorize, monitor, and control the use of such components within the system.
SI-3: Malicious Code Protection
Implement [Assignment (one or more): signature-based, non-signature-based] malicious code protection mechanisms at system entry and exit points to detect and eradicate malicious code; Automatically update malicious code protection mechanisms as new releases are available in accordance with organizational configuration management policy and procedures; Configure malicious code protection mechanisms to: Perform periodic scans of the system…
SI-4: System Monitoring
Monitor the system to detect: Attacks and indicators of potential attacks in accordance with the following monitoring objectives: [Assignment: organization-defined monitoring objectives] ; and Unauthorized local, network, and remote connections; Identify unauthorized use of the system through the following techniques and methods: [Assignment: organization-defined techniques and methods]; Invoke internal monitoring capabilities or deploy monitoring devices:…
SI-7: Software, Firmware, and Information Integrity
Employ integrity verification tools to detect unauthorized changes to the following software, firmware, and information: [Assignment: organization-defined software, firmware, and information] ; and Take the following actions when unauthorized changes to the software, firmware, and information are detected: [Assignment: organization-defined actions].
SI-10: Information Input Validation
Check the validity of the following information inputs: [Assignment: organization-defined information inputs].
SI-16: Memory Protection
Implement the following controls to protect the system memory from unauthorized code execution: [Assignment: organization-defined controls].
NIST SP 800-171 Revision 3.0
03.01.01: Account Management
Define the types of system accounts allowed and prohibited. Create, enable, modify, disable, and remove system accounts in accordance with policy, procedures, prerequisites, and criteria. Specify: Authorized users of the system, Group and role membership, and Access authorizations (i.e., privileges) for each account. Authorize access to the system based on: A valid access authorization and…
03.01.02: Access Enforcement
Enforce approved authorizations for logical access to CUI and system resources in accordance with applicable access control policies.
03.01.03: Information Flow Enforcement
Enforce approved authorizations for controlling the flow of CUI within the system and between connected systems.
03.03.08: Protection of Audit Information
Protect audit information and audit logging tools from unauthorized access, modification, and deletion. Authorize access to management of audit logging functionality to only a subset of privileged users or roles.
03.08.09: System Backup — Cryptographic Protection
Protect the confidentiality of backup information. Implement cryptographic mechanisms to prevent the unauthorized disclosure of CUI at backup storage locations.
03.12.05: Information Exchange
Approve and manage the exchange of CUI between the system and other systems using [Selection (one or more): interconnection security agreements; information exchange security agreements; memoranda of understanding or agreement; service-level agreements; user agreements; non-disclosure agreements; other types of agreements]. Document interface characteristics, security requirements, and responsibilities for each system as part of the exchange…
03.13.01: Boundary Protection
Monitor and control communications at external managed interfaces to the system and key internal managed interfaces within the system. Implement subnetworks for publicly accessible system components that are physically or logically separated from internal networks. Connect to external systems only through managed interfaces that consist of boundary protection devices arranged in accordance with an organizational…
03.13.04: Information in Shared System Resources
Prevent unauthorized and unintended information transfer via shared system resources.
03.13.06: Network Communications — Deny by Default — Allow by Exception
Deny network communications traffic by default, and allow network communications traffic by exception.
03.13.11: Cryptographic Protection
Implement the following types of cryptography to protect the confidentiality of CUI: [Assignment: organization-defined types of cryptography].
03.14.02: Malicious Code Protection
Implement malicious code protection mechanisms at system entry and exit points to detect and eradicate malicious code. Update malicious code protection mechanisms as new releases are available in accordance with configuration management policies and procedures. Configure malicious code protection mechanisms to: Perform scans of the system [Assignment: organization-defined frequency] and real-time scans of files from…
03.14.06: System Monitoring
Monitor the system to detect: Attacks and indicators of potential attacks and Unauthorized connections. Identify unauthorized use of the system. Monitor inbound and outbound communications traffic to detect unusual or unauthorized activities or conditions.
03.16.01: Security Engineering Principles
Apply the following systems security engineering principles to the development or modification of the system and system components: [Assignment: organization-defined systems security engineering principles].
Cloud Controls Matrix v4.0
DSP-17: Sensitive Data Protection
Define and implement, processes, procedures and technical measures to protect sensitive data throughout it's lifecycle.
HRS-04: Remote and Home Working Policy and Procedures
Establish, document, approve, communicate, apply, evaluate and maintain policies and procedures to protect information accessed, processed or stored at remote sites and locations. Review and update the policies and procedures at least annually.
UEM-11: Data Loss Prevention
Configure managed endpoints with Data Loss Prevention (DLP) technologies and rules in accordance with a risk assessment.