Skip to content

CCI: Control Correlation Identifier

The Control Correlation Identifier (CCI) provides a standard identifier and description for each of the singular, actionable statements that comprise an IA control or IA best practice. CCI bridges the gap between high-level policy expressions and low-level technical implementations. CCI allows a security requirement that is expressed in a high-level policy framework to be decomposed and explicitly associated with the low-level security setting(s) that must be assessed to determine compliance with the objectives of that specific security control. This ability to trace security requirements from their origin (e.g., regulations, IA frameworks) to their low-level implementation allows organizations to readily demonstrate compliance to multiple IA compliance frameworks. CCI also provides a means to objectively rollup and compare related compliance assessment results across disparate technologies.

Scheme
public.cyber.mil /stigs/cci/
Published by
DoD Cyber Exchange (sponsored by DISA: Defense Information Systems Agency)
  • CCI-005010

    Defines the action to be taken when system failures are detected.
  • CCI-005011

    Refresh organization-defined information on an organization-defined frequency, or generate organization-defined information on demand.
  • CCI-005012

    Defines the information to be refreshed on an organization-defined frequency.
  • CCI-005013

    Defines the frequency at which to refresh organization-defined information.
  • CCI-005014

    Defines the information to be generated on demand.
  • CCI-005015

    Delete information when no longer needed.
  • CCI-005016

    Refresh connections to the system on demand.
  • CCI-005017

    Terminate connections after completion of a request, or a period of non-use.
  • CCI-005018

    Check the accuracy, relevance, timeliness, and completeness of personally identifiable information across the information life cycle, on an organiz...
  • CCI-005019

    Defines the frequency for checking the accuracy, relevance, timeliness, and completeness of personally identifiable information.

The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.

Capacity
Modules