Skip to content

stefanjames/security-control-testing

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

4 Commits
 
 

Repository files navigation

Security Control Testing (AC-11) Using FedRAMP Template (Determine-if Levels)

Step-by-step guide on how to perform Hands-On Security Control Testing for AC-11 using the FedRAMP Test Case Template with Determine-if Levels. AC-11 focuses on session lock controls.

Introduction

FedRAMP standardizes the security assessment and authorization process for cloud products and services. AC-11 addresses session lock controls. Ensure you have the necessary access rights and authorization before proceeding.

Prerequisites

  • Access to the FedRAMP Test Case Template
  • System documentation, security policies, and procedures
  • Understanding of Determine-if Levels

Steps

  1. Understand the Control Requirements:
    • Review FedRAMP AC-11 requirements and Determine-if levels.


“ac11”/

  1. Obtain the FedRAMP Test Case Template:
    • Download the AC-11 Test Case Template from the official FedRAMP source.


“ac11template”/

  1. Gather Necessary Documentation:


“nist80053a”/

  1. Identify the Determine-if Levels:

    • Determine the applicable Determine-if levels for your system.
  2. Review Evidence provided by client:

    • Review relevant screenshots of the configuration on the server.
      “screen-saver-timeout”/
  3. Execute Test Cases:

    • Observe and examine the Access Control Policy noted that the AC-11 verbiage defined the time period of inactivity of 15 minutes (900 seconds).
  4. Record Observations and Findings:

    • Document observations and findings during the tests.
  5. Evaluate the Results:

    • Compare findings to Determine-if level expectations.
  6. Report the Test Results:

    • Complete the Test Case Template reporting sections.
  7. Review and Validation:

    • Have findings reviewed and validated by a qualified security assessor.
  8. Mitigation and Remediation:

    • Develop and implement plans to address any deficiencies.
  9. Document the Final Report:

    • Generate a comprehensive final report detailing results and actions taken.
  10. Submit the Report:

    • Submit the report to the relevant governing body for assessment and authorization.
  11. Continuous Monitoring:

    • Regularly assess and review session lock controls to maintain compliance.
  12. Follow Up:

    • Continuously update the system to ensure ongoing compliance with AC-11 and other security requirements.

Reporting

Ensure your report contains details of tests, outcomes, and any actions to address deficiencies.

Continuous Monitoring

Maintain continuous monitoring of session lock controls to uphold FedRAMP compliance.

Conclusion

FedRAMP compliance is an ongoing process. Stay informed about updates in FedRAMP guidelines and adjust your security controls accordingly.

About

No description, website, or topics provided.

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

 
 
 

Contributors