-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathextracted_sl5_overlay.json
More file actions
464 lines (464 loc) · 15.2 KB
/
Copy pathextracted_sl5_overlay.json
File metadata and controls
464 lines (464 loc) · 15.2 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
275
276
277
278
279
280
281
282
283
284
285
286
287
288
289
290
291
292
293
294
295
296
297
298
299
300
301
302
303
304
305
306
307
308
309
310
311
312
313
314
315
316
317
318
319
320
321
322
323
324
325
326
327
328
329
330
331
332
333
334
335
336
337
338
339
340
341
342
343
344
345
346
347
348
349
350
351
352
353
354
355
356
357
358
359
360
361
362
363
364
365
366
367
368
369
370
371
372
373
374
375
376
377
378
379
380
381
382
383
384
385
386
387
388
389
390
391
392
393
394
395
396
397
398
399
400
401
402
403
404
405
406
407
408
409
410
411
412
413
414
415
416
417
418
419
420
421
422
423
424
425
426
427
428
429
430
431
432
433
434
435
436
437
438
439
440
441
442
443
444
445
446
447
448
449
450
451
452
453
454
455
456
457
458
459
460
461
462
463
464
{
"SC-01": {
"name": "SYSTEM AND COMMUNICATIONS PROTECTION POLICY AND PROCEDURES",
"attributes": {
"Inherit From": "FedRAMP High",
"Justification to Select": "SC-01 is selected in FedRAMP High. Having formal policy is essential for maintaining standards."
},
"selected": true,
"page": 1
},
"SC-02": {
"name": "SEPARATION OF SYSTEM AND USER FUNCTIONALITY",
"attributes": {
"Inherit From": "FedRAMP High",
"Justification to Select": "SC-02 is selected in FedRAMP High. This enables greater protection of system management functions, and reduces the ability of threats to spread out."
},
"selected": true,
"page": 1
},
"SC-03": {
"name": "SECURITY FUNCTION ISOLATION",
"attributes": {
"Justification to Select": "SC-03 is selected in FedRAMP High. This enables greater protection of security functions, and reduces the ability of threats to spread out.",
"Test Method": "Interview, Test",
"Open Questions": "What enhancements to select? Do we want Hardware Separation?"
},
"selected": true,
"page": 1
},
"SC-03(1)": {
"name": "Security Function Isolation | Hardware Separation",
"attributes": {
"Justification to Select": "TODO",
"Test Method": "Examine"
},
"selected": true,
"page": 1
},
"SC-04": {
"name": "SEPARATION OF SYSTEM AND USER FUNCTIONALITY",
"attributes": {
"Inherit From": "Insider Threat Overlay",
"Justification to Select": "SC-04 is selected in FedRAMP High. This is necessary to limit insider threats and maintain least access."
},
"selected": true,
"page": 1
},
"SC-05": {
"name": "DENIAL-OF-SERVICE PROTECTION",
"attributes": {
"Inherit From": "Parameter assignment - FedRAMP High, Enhancements - Insider Threat Overlay",
"Justification to Select": "SC-05 is selected in FedRAMP High. This is necessary to protect system availability."
},
"selected": true,
"page": 1
},
"SC-06": {
"name": "RESOURCE AVAILABILITY",
"attributes": {
"Open Questions": "Should we select this control?"
},
"selected": false,
"page": 2
},
"SC-07": {
"name": "BOUNDARY PROTECTION",
"attributes": {
"Justification to Select": "SC-07 is selected in FedRAMP High. The boundaries of a network are key areas for protection.",
"Test Method": "",
"Open Questions": "For parameters, should we select physically, logically, or a more detailed breakdown, see FedRAMP High? What enhancements should we select?"
},
"selected": true,
"page": 2
},
"SC-08": {
"name": "TRANSMISSION CONFIDENTIALITY AND INTEGRITY",
"attributes": {
"Justification to Select": "SC-08 is selected in FedRAMP High. Transmissions must ensure confidentiality and integrity.",
"Parameter Value(s)": "Confidentiality and integrity",
"Test Method": "Examine, Interview, Test",
"Open Questions": "What enhancements should we select?"
},
"selected": true,
"page": 2
},
"SC-10": {
"name": "NETWORK DISCONNECT",
"attributes": {
"Inherit From": "FedRAMP High",
"Justification to Select": "SC-10 is selected in FedRAMP High. Abandoned sessions could be hijacked."
},
"selected": true,
"page": 2
},
"SC-11": {
"name": "TRUSTED PATH",
"attributes": {
"Open Questions": "Should we select this control?"
},
"selected": false,
"page": 2
},
"SC-12": {
"name": "CRYPTOGRAPHIC KEY ESTABLISHMENT AND MANAGEMENT",
"attributes": {
"Justification to Select": "SC-12 is selected in FedRAMP High. The security of encryption keys is an essential area of concern.",
"Parameter Value(s)": "Classified Information Overlay compliant processes/requirements for key generation, distribution, storage, access, and destruction (for classified systems)",
"Test Method": "Examine, Interview, Test",
"Open Questions": "Where in the Classified Information Overlay does it actually describe the process/requirements for the parameter value? Unsure if enhancement 1 should be selected, see FedRAMP High, potentially incompatible with cryptographic erasure from IL6. Unsure of test methods."
},
"selected": true,
"page": 2
},
"SC-12(2)": {
"name": "Cryptographic Key Establishment and Management | Symmetric Keys",
"attributes": {
"Justification to Select": "This is the standard used to protect confidential information.",
"Parameter Value(s)": "NSA-approved",
"Test Method": "Examine, Interview, Test"
},
"selected": true,
"page": 3
},
"SC-12(3)": {
"name": "Cryptographic Key Establishment and Management | Asymmetric Keys",
"attributes": {
"Justification to Select": "This is the standard used to protect confidential information.",
"Parameter Value(s)": "NSA-approved key management technology and processes",
"Test Method": "Examine, Interview, Test"
},
"selected": true,
"page": 3
},
"SC-12(6)": {
"name": "Cryptographic Key Establishment and Management | Physical Control of",
"attributes": {
"Justification to Select": "This is the standard used in IL6. Necessary for cryptographic erasure. Gives labs greater confidence and control.",
"Test Method": "Examine, Interview, Test"
},
"selected": true,
"page": 3
},
"SC-13": {
"name": "CRYPTOGRAPHIC PROTECTION",
"attributes": {
"Inherit From": "FedRAMP High",
"Justification to Select": "SC-13 is selected in FedRAMP High. It is necessary to specify what applications require what type of encryption."
},
"selected": true,
"page": 3
},
"SC-15": {
"name": "CRYPTOGRAPHIC KEY ESTABLISHMENT AND MANAGEMENT",
"attributes": {
"Inherit From": "CNSSI 1253",
"Justification to Select": "SC-15 is selected in FedRAMP High. Restricting collaborative computing reduces attack surface."
},
"selected": true,
"page": 3
},
"SC-16": {
"name": "TRANSMISSION OF SECURITY AND PRIVACY ATTRIBUTES",
"attributes": {
"Open Questions": "Should we select this control?"
},
"selected": false,
"page": 4
},
"SC-17": {
"name": "PUBLIC KEY INFRASTRUCTURE CERTIFICATES",
"attributes": {
"Inherit From": "FedRAMP+",
"Justification to Select": "SC-17 is selected in FedRAMP High, but that leaves the policy up to the CSP. FedRAMP+ allows labs greater control and confidence over public keys.",
"Open Questions": "Should we use the FedRAMP+ overlay?"
},
"selected": true,
"page": 4
},
"SC-18": {
"name": "MOBILE CODE",
"attributes": {
"Inherit From": "CNSSI 1253",
"Justification to Select": "SC-18 is selected in FedRAMP High, but CNSSI provides a more secure and detailed policy."
},
"selected": true,
"page": 4
},
"SC-20": {
"name": "SECURE NAME/ADDRESS RESOLUTION SERVICE (AUTHORITATIVE SOURCE)",
"attributes": {
"Inherit From": "FedRAMP High",
"Justification to Select": "SC-20 is selected in FedRAMP High. Prevents clients from being redirected to malicious servers though."
},
"selected": true,
"page": 4
},
"SC-21": {
"name": "SECURE NAME/ADDRESS RESOLUTION SERVICE (RECURSIVE OR CACHING",
"attributes": {
"Inherit From": "FedRAMP High",
"Justification to Select": "SC-21 is selected in FedRAMP High. Prevents DNS manipulation attacks."
},
"selected": true,
"page": 4
},
"SC-22": {
"name": "ARCHITECTURE AND PROVISIONING FOR NAME/ADDRESS RESOLUTION",
"attributes": {
"Inherit From": "FedRAMP High",
"Justification to Select": "SC-22 is selected in FedRAMP High. Increases robustness of protection offered by related controls."
},
"selected": true,
"page": 4
},
"SC-23": {
"name": "ARCHITECTURE AND PROVISIONING FOR NAME/ADDRESS RESOLUTION",
"attributes": {
"Inherit From": "Insider Threat Overlay",
"Justification to Select": "SC-23 is selected in FedRAMP High. Protecting the authenticity of communications is essential."
},
"selected": true,
"page": 5
},
"SC-24": {
"name": "FAIL IN KNOWN STATE",
"attributes": {
"Inherit From": "CNSSI 1253",
"Justification to Select": "SC-24 is selected in FedRAMP High, but leaves too much to the discretion of CSP. CNSSI 1253 provides a more secure standard."
},
"selected": true,
"page": 5
},
"SC-25": {
"name": "THIN NODES",
"attributes": {
"Open Questions": "Should we select this control?"
},
"selected": false,
"page": 5
},
"SC-26": {
"name": "DECOYS",
"attributes": {
"Open Questions": "Should we select this control? RAND requirements call for honeypots."
},
"selected": false,
"page": 5
},
"SC-27": {
"name": "PLATFORM-INDEPENDENT APPLICATIONS",
"attributes": {
"Open Questions": "Should we select this control?"
},
"selected": false,
"page": 5
},
"SC-28": {
"name": "PROTECTION OF INFORMATION AT REST",
"attributes": {
"Inherit From": "FedRAMP High",
"Justification to Select": "SC-28 is selected in FedRAMP High. Sensitive information must be encrypted whenever possible.",
"Open Questions": "Should we use the RedRAMP High overlay? Perhaps Insider Threat instead or custom."
},
"selected": true,
"page": 5
},
"SC-29": {
"name": "HETEROGENEITY",
"attributes": {
"Open Questions": "Should we select? Maybe not if we are trying to simplify the stack. There are weakest link situations and there are also lines of defense situations. Maybe specify that we want heterogeneity where it is not a weakest link situation."
},
"selected": false,
"page": 5
},
"SC-30": {
"name": "CONCEALMENT AND MISDIRECTION",
"attributes": {
"Open Questions": "Should we select? This control is very open ended, if yes how should we specify it?"
},
"selected": false,
"page": 6
},
"SC-31": {
"name": "COVERT CHANNEL ANALYSIS",
"attributes": {
"Justification to Select": "SC-31 is not selected in FedRAMP High or any dependency of IL6. However it is necessary to prevent exfiltration including of model weights.",
"Parameter Value(s)": "Storage and timing",
"Test Method": "Examine, Interview, Test",
"Open Questions": "Should we select enhancement 1? Is this where we should specify bandwidth liming requirements, have I done that well?"
},
"selected": true,
"page": 6
},
"SC-31(2)": {
"name": "Covert Channel Analysis | Maximum Bandwidth",
"attributes": {
"Justification to Select": "Restricts ability to exfiltrate weights and other large files over covert channels.",
"Parameter Value(s)": "Storage and timing, based on client",
"Supplemental Guidance": "Bandwidth limits should be configured per client for all network devices providing access to weight storage. ? Is this enough detail?",
"Test Method": "Examine, Interview, Test"
},
"selected": true,
"page": 6
},
"SC-31(3)": {
"name": "Covert Channel Analysis | Measure Bandwidth in Operational",
"attributes": {
"Justification to Select": "To enforce SC-31(2), detect any suspicious movement of large amounts of data.",
"Parameter Value(s)": "Any channel providing access to weight storage.",
"Test Method": "Examine, Interview, Test"
},
"selected": true,
"page": 6
},
"SC-32": {
"name": "SYSTEM PARTITIONING",
"attributes": {
"Open Questions": "Should we select? How should we partition the system? Partition between train and inference? Physical?"
},
"selected": false,
"page": 7
},
"SC-34": {
"name": "NON-MODIFIABLE EXECUTABLE PROGRAMS",
"attributes": {
"Open Questions": "Should we select this control?"
},
"selected": false,
"page": 7
},
"SC-35": {
"name": "EXTERNAL MALICIOUS CODE IDENTIFICATION",
"attributes": {
"Open Questions": "Should we select this control?"
},
"selected": false,
"page": 7
},
"SC-36": {
"name": "DISTRIBUTED PROCESSING AND STORAGE",
"attributes": {
"Open Questions": "Should we select this control?"
},
"selected": false,
"page": 7
},
"SC-37": {
"name": "OUT-OF-BAND CHANNELS",
"attributes": {
"Open Questions": "Should we select this control?"
},
"selected": false,
"page": 7
},
"SC-38": {
"name": "OPERATIONS SECURITY",
"attributes": {
"Inherit From": "Insider Threat Overlay",
"Justification to Select": "Operational security is necessary to limit the availability of potentially compromising information."
},
"selected": true,
"page": 7
},
"SC-39": {
"name": "PROCESS ISOLATION",
"attributes": {
"Inherit From": "FedRAMP High",
"Justification to Select": "SC-39 is selected in FedRAMP High. Restricts unwanted and/or illicit communication between processes."
},
"selected": true,
"page": 7
},
"SC-41": {
"name": "PORT AND I/O DEVICE ACCESS",
"attributes": {
"Open Questions": "Should we select this control?"
},
"selected": false,
"page": 7
},
"SC-42": {
"name": "SENSOR CAPABILITY AND DATA",
"attributes": {
"Inherit From": "Insider Threat Overlay",
"Justification to Select": "Devices, especially external and personal devices, with the ability to collect and transmit sensor data open many paths for compromising information to escape."
},
"selected": true,
"page": 7
},
"SC-43": {
"name": "USAGE RESTRICTIONS",
"attributes": {
"Inherit From": "CNSSI 1253",
"Justification to Select": "SC-43 is selected in CNSSI 1253 and is necessary to prevent unauthorized access to systems."
},
"selected": true,
"page": 8
},
"SC-44": {
"name": "DETONATION CHAMBERS",
"attributes": {
"Open Questions": "Should we select this control? No?"
},
"selected": false,
"page": 8
},
"SC-45": {
"name": "SYSTEM TIME SYNCHRONIZATION",
"attributes": {
"Inherit From": "FedRAMP High",
"Justification to Select": "SC-45 is selected in FedRAMP High. Unsynchronized clocks can lead to confusion and intended errors."
},
"selected": true,
"page": 8
},
"SC-46": {
"name": "CROSS DOMAIN POLICY ENFORCEMENT",
"attributes": {
"Open Questions": "Should we select this control?"
},
"selected": false,
"page": 8
},
"SC-47": {
"name": "ALTERNATE COMMUNICATIONS PATHS",
"attributes": {
"Open Questions": "Should we select this control?"
},
"selected": false,
"page": 8
},
"SC-48": {
"name": "SENSOR RELOCATION",
"attributes": {
"Open Questions": "Should we select this control?"
},
"selected": false,
"page": 8
},
"SC-49": {
"name": "HARDWARE-ENFORCED SEPARATION AND POLICY ENFORCEMENT",
"attributes": {
"Open Questions": "Should we select this control?"
},
"selected": false,
"page": 8
},
"SC-50": {
"name": "SOFTWARE-ENFORCED SEPARATION AND POLICY ENFORCEMENT",
"attributes": {
"Open Questions": "Should we select this control?"
},
"selected": false,
"page": 8
},
"SC-51": {
"name": "HARDWARE-BASED PROTECTION",
"attributes": {
"Open Questions": "Should we select this control?"
},
"selected": false,
"page": 9
}
}