Skip to content

II - Mission Support Classified

Rules and Groups employed by this XCCDF Profile

  • IS-11.01.01

    Group
  • Destruction of Classified Documents Printed from the SIPRNet Using Approved Devices on NSA Evaluated Products Lists (EPL).

    Failure to properly destroy classified material can lead to the loss or compromise of classified or sensitive information. REFERENCES: CJCSI 6510.01F, INFORMATION ASSURANCE (IA) AND SUPPORT TO CO...
    Rule High Severity
  • IS-11.01.02

    Group
  • Classified Material Destruction - Improper Disposal of Automated Information System (AIS) Hard Drives and Storage Media

    Failure to properly destroy classified material can lead to the loss or compromise of classified or sensitive information. REFERENCES: CJCSI 6510.01F, INFORMATION ASSURANCE (IA) AND SUPPORT TO CO...
    Rule High Severity
  • IS-11.02.01

    Group
  • Classified Destruction - Hard Drive and Storage Media Sanitization Devices and Plans are not Available for disposal of Automated Information System (AIS) Equipment On-Hand

    Failure to properly destroy classified material can lead to the loss or compromise of classified or sensitive information. REFERENCES: CJCSI 6510.01F, INFORMATION ASSURANCE (IA) AND SUPPORT TO CO...
    Rule Medium Severity
  • IS-11.03.01

    Group
  • Destruction of Classified and Unclassified Documents, Equipment and Media - Availability of Local Policy and Procedures

    Lack of plans and procedures to properly destroy classified and/or sensitive material can lead to the loss or compromise of classified or sensitive information. REFERENCES: CJCSI 6510.01F, INFORM...
    Rule Low Severity
  • IS-13.02.01

    Group
  • Classified Emergency Destruction Plans - Develop and Make Available

    Failure to develop emergency procedures can lead to the loss or compromise of classified or sensitive information during emergency situations. REFERENCES: CJCSI 6510.01F, INFORMATION ASSURANCE (I...
    Rule Medium Severity
  • IS-14.02.01

    Group
  • Security Incident/Spillage - Lack of Procedures or Training for Handling and Reporting

    Failure to report possible security compromise can result in the impact of the loss or compromise of classified information not to be evaluated, responsibility affixed, or a plan of action develope...
    Rule Medium Severity
  • IS-15.02.01

    Group
  • Classification Guides Must be Available for Programs and Systems for an Organization or Site

    Failure to have proper classification guidance available for Information Systems and/or associated programs run on them can result in the misclassification of information and ultimately lead to the...
    Rule Medium Severity
  • IS-16.02.01

    Group
  • Controlled Unclassified Information (CUI) - Employee Education and Training

    Failure to handle CUI in an approved manner can result in the loss or compromise of sensitive information. REFERENCES: Executive Order 13556, Controlled Unclassified Information (CUI) The Inform...
    Rule Medium Severity
  • IS-16.02.02

    Group
  • Controlled Unclassified Information - Document, Hard Drive and Media Disposal

    Failure to handle CUI in an approved manner can result in the loss or compromise of sensitive information. REFERENCES: Assistant Secretary of Defense for Command, Control, Communications and Inte...
    Rule Medium Severity
  • IS-16.02.03

    Group
  • Controlled Unclassified Information - Handling, Storage and Controlling Access to Areas where CUI is Processed or Maintained

    Failure to handle CUI in an approved manner can result in the loss or compromise of sensitive information. REFERENCES: Executive Order 13556, Controlled Unclassified Information (CUI) The Inform...
    Rule Medium Severity

The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.

Capacity
Modules