Skip to content

Traditional Security Checklist

Rules, Groups, and Values defined within the XCCDF Benchmark

  • PH-03.02.01

    <GroupDescription></GroupDescription>
    Group
  • Physical Protection of Unclassified Key System Devices/Computer Rooms in Large Processing Facilities

    &lt;VulnDiscussion&gt;Allowing access to systems processing sensitive information by personnel without the need-to-know could permit loss, destruct...
    Rule Medium Severity
  • PH-04.02.01

    <GroupDescription></GroupDescription>
    Group
  • Restricted Area and Controlled Area Designation of Areas Housing Critical Information System Components or Classified /Sensitive Technology or Data

    &lt;VulnDiscussion&gt;Failure to designate the areas housing the critical information technology systems as a restricted or controlled access area ...
    Rule Medium Severity
  • PH-05.02.01

    <GroupDescription></GroupDescription>
    Group
  • Security-in-Depth (AKA: Defense-in-Depth) - Minimum Physical Barriers and Access Control Measures for Facilities or Buildings Containing DoDIN (SIPRNet/NIPRNet) Connected Assets.

    &lt;VulnDiscussion&gt;Failure to use security-in-depth can result in a facility being vulnerable to an undetected intrusion or an intrusion that ca...
    Rule Medium Severity
  • PH-06.02.01

    <GroupDescription></GroupDescription>
    Group
  • Visitor Control - To Facility or Organization with Information System Assets Connected to the DISN

    &lt;VulnDiscussion&gt;Failure to identify and control visitors could result in unauthorized personnel gaining access to the facility with the inten...
    Rule Medium Severity
  • PH-07.02.01

    <GroupDescription></GroupDescription>
    Group
  • Sensitive Item Control - Keys, Locks and Access Cards Controlling Access to Information Systems (IS) or IS Assets Connected to the DISN

    &lt;VulnDiscussion&gt;Lack of an adequate key/credential/access device control could result in unauthorized personnel gaining access to the facilit...
    Rule Medium Severity

The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.

Capacity
Modules