Information System Documentation

class

Management

family

System and Services Acquisition

number

SA-5

priority

P2

impact

LOW_MODERATE_HIGH

The organization: Obtains, protects as required, and makes available to authorized personnel, administrator documentation for the information system that describes: Secure configuration, installation, and operation of the information system; Effective use and maintenance of security features/functions; and Known vulnerabilities regarding configuration and use of administrative (i.e., privileged) functions; and Obtains, protects as required, and makes available to authorized personnel, user documentation for the information system that describes: User-accessible security features/functions and how to effectively use those security features/functions; Methods for user interaction with the information system, which enables individuals to use the system in a more secure manner; and User responsibilities in maintaining the security of the information and information system; and Documents attempts to obtain information system documentation when such documentation is either unavailable or nonexistent.

Comments