Skip to content

CCI: Control Correlation Identifier

The Control Correlation Identifier (CCI) provides a standard identifier and description for each of the singular, actionable statements that comprise an IA control or IA best practice. CCI bridges the gap between high-level policy expressions and low-level technical implementations. CCI allows a security requirement that is expressed in a high-level policy framework to be decomposed and explicitly associated with the low-level security setting(s) that must be assessed to determine compliance with the objectives of that specific security control. This ability to trace security requirements from their origin (e.g., regulations, IA frameworks) to their low-level implementation allows organizations to readily demonstrate compliance to multiple IA compliance frameworks. CCI also provides a means to objectively rollup and compare related compliance assessment results across disparate technologies.

Scheme
public.cyber.mil /stigs/cci/
Published by
DoD Cyber Exchange (sponsored by DISA: Defense Information Systems Agency)
  • CCI-004930

    Implement a policy enforcement mechanism physically or logically between the physical and/or network interfaces for the connecting security domains.
  • CCI-004931

    Establish organization-defined alternate communications paths for system operations organizational command and control.
  • CCI-004932

    Relocate organization-defined sensors and monitoring capabilities to organization-defined locations under organization-defined conditions or circum...
  • CCI-004933

    Defines the sensors and monitoring capabilities to be relocated to organization-defined locations.
  • CCI-004934

    Defines the locations of which the organization-defined sensors and monitoring capabilities will be relocated.
  • CCI-004935

    Defines the conditions or circumstances of which the organization-defined sensors and monitoring capabilities are relocated.
  • CCI-004936

    Dynamically relocate organization-defined sensors and monitoring capabilities to organization-defined locations under organization-defined conditio...
  • CCI-004937

    Defines the sensors and monitoring capabilities to be dynamically relocated to organization-defined locations.
  • CCI-004938

    Defines the locations of which the organization-defined sensors and monitoring capabilities will be dynamically relocated.
  • CCI-004939

    Defines the conditions or circumstances of which the organization-defined sensors and monitoring capabilities are dynamically relocated.

The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.

Capacity
Modules