Download CJIS_Security_Policy_v5-9-5_20240709.pdf — 4503 KB

[{"dest": {"list": [{"ref": 1}, {"literal": "XYZ"}, {"number": 70}, {"number": 720}, {"number": 0.0}], "size": 5}, "level": 1, "sub": [], "pageno": 1, "title": "Executive Summary"}, {"dest": {"list": [{"ref": 3}, {"literal": "XYZ"}, {"number": 70}, {"number": 720}, {"number": 0.0}], "size": 5}, "level": 1, "sub": [], "pageno": 2, "title": "Change Management"}, {"dest": {"list": [{"ref": 5}, {"literal": "XYZ"}, {"number": 70}, {"number": 720}, {"number": 0.0}], "size": 5}, "level": 1, "sub": [], "pageno": 3, "title": "Summary of Changes"}, {"dest": {"list": [{"ref": 9}, {"literal": "XYZ"}, {"number": 70}, {"number": 720}, {"number": 0.0}], "size": 5}, "level": 1, "sub": [], "pageno": 5, "title": "Table of Contents"}, {"dest": {"list": [{"ref": 42}, {"literal": "XYZ"}, {"number": 70}, {"number": 720}, {"number": 0.0}], "size": 5}, "level": 1, "sub": [], "pageno": 16, "title": "List of Figures"}, {"dest": {"list": [{"ref": 45}, {"literal": "XYZ"}, {"number": 70}, {"number": 720}, {"number": 0.0}], "size": 5}, "level": 1, "sub": [], "pageno": 17, "title": "List of Priorities"}, {"dest": {"list": [{"ref": 55}, {"literal": "XYZ"}, {"number": 70}, {"number": 720}, {"number": 0.0}], "size": 5}, "level": 1, "sub": [], "pageno": 22, "title": "1 Introduction"}, {"dest": {"list": [{"ref": 55}, {"literal": "XYZ"}, {"number": 70}, {"number": 654}, {"number": 0.0}], "size": 5}, "level": 2, "sub": [], "pageno": 22, "title": "1.1 Purpose"}, {"dest": {"list": [{"ref": 55}, {"literal": "XYZ"}, {"number": 70}, {"number": 462}, {"number": 0.0}], "size": 5}, "level": 2, "sub": [], "pageno": 22, "title": "1.2 Scope"}, {"dest": {"list": [{"ref": 55}, {"literal": "XYZ"}, {"number": 70}, {"number": 325}, {"number": 0.0}], "size": 5}, "level": 2, "sub": [], "pageno": 22, "title": "1.3 Relationship to Local Security Policy and Other Policies"}, {"dest": {"list": [{"ref": 57}, {"literal": "XYZ"}, {"number": 70}, {"number": 686}, {"number": 0.0}], "size": 5}, "level": 2, "sub": [], "pageno": 23, "title": "1.4 Terminology Used in This Document"}, {"dest": {"list": [{"ref": 57}, {"literal": "XYZ"}, {"number": 70}, {"number": 274}, {"number": 0.0}], "size": 5}, "level": 2, "sub": [], "pageno": 23, "title": "1.5 Distribution of the CJIS Security Policy"}, {"dest": {"list": [{"ref": 59}, {"literal": "XYZ"}, {"number": 70}, {"number": 720}, {"number": 0.0}], "size": 5}, "level": 1, "sub": [], "pageno": 24, "title": "2 CJIS Security Policy Approach"}, {"dest": {"list": [{"ref": 59}, {"literal": "XYZ"}, {"number": 70}, {"number": 626}, {"number": 0.0}], "size": 5}, "level": 2, "sub": [], "pageno": 24, "title": "2.1 CJIS Security Policy Vision Statement"}, {"dest": {"list": [{"ref": 59}, {"literal": "XYZ"}, {"number": 70}, {"number": 537}, {"number": 0.0}], "size": 5}, "level": 2, "sub": [], "pageno": 24, "title": "2.2 Architecture Independent"}, {"dest": {"list": [{"ref": 59}, {"literal": "XYZ"}, {"number": 70}, {"number": 303}, {"number": 0.0}], "size": 5}, "level": 2, "sub": [], "pageno": 24, "title": "2.3 Risk Versus Realism"}, {"dest": {"list": [{"ref": 61}, {"literal": "XYZ"}, {"number": 70}, {"number": 720}, {"number": 0.0}], "size": 5}, "level": 1, "sub": [], "pageno": 25, "title": "3 Roles and Responsibilities"}, {"dest": {"list": [{"ref": 61}, {"literal": "XYZ"}, {"number": 70}, {"number": 688}, {"number": 0.0}], "size": 5}, "level": 2, "sub": [], "pageno": 25, "title": "3.1 Shared Management Philosophy"}, {"dest": {"list": [{"ref": 61}, {"literal": "XYZ"}, {"number": 70}, {"number": 441}, {"number": 0.0}], "size": 5}, "level": 2, "sub": [], "pageno": 25, "title": "3.2 Roles and Responsibilities for Agencies and Parties"}, {"dest": {"list": [{"ref": 65}, {"literal": "XYZ"}, {"number": 70}, {"number": 463}, {"number": 0.0}], "size": 5}, "level": 3, "sub": [], "pageno": 26, "title": "3.2.1 CJIS Systems Agencies (CSA)"}, {"dest": {"list": [{"ref": 65}, {"literal": "XYZ"}, {"number": 70}, {"number": 376}, {"number": 0.0}], "size": 5}, "level": 3, "sub": [], "pageno": 26, "title": "3.2.2 CJIS Systems Officer (CSO)"}, {"dest": {"list": [{"ref": 67}, {"literal": "XYZ"}, {"number": 70}, {"number": 349}, {"number": 0.0}], "size": 5}, "level": 3, "sub": [], "pageno": 27, "title": "3.2.3 Terminal Agency Coordinator (TAC)"}, {"dest": {"list": [{"ref": 67}, {"literal": "XYZ"}, {"number": 70}, {"number": 275}, {"number": 0.0}], "size": 5}, "level": 3, "sub": [], "pageno": 27, "title": "3.2.4 Criminal Justice Agency (CJA)"}, {"dest": {"list": [{"ref": 67}, {"literal": "XYZ"}, {"number": 70}, {"number": 188}, {"number": 0.0}], "size": 5}, "level": 3, "sub": [], "pageno": 27, "title": "3.2.5 Noncriminal Justice Agency (NCJA)"}, {"dest": {"list": [{"ref": 69}, {"literal": "XYZ"}, {"number": 70}, {"number": 720}, {"number": 0.0}], "size": 5}, "level": 3, "sub": [], "pageno": 28, "title": "3.2.6 Contracting Government Agency (CGA)"}, {"dest": {"list": [{"ref": 69}, {"literal": "XYZ"}, {"number": 70}, {"number": 653}, {"number": 0.0}], "size": 5}, "level": 3, "sub": [], "pageno": 28, "title": "3.2.7 Agency Coordinator (AC)"}, {"dest": {"list": [{"ref": 69}, {"literal": "XYZ"}, {"number": 70}, {"number": 175}, {"number": 0.0}], "size": 5}, "level": 3, "sub": [], "pageno": 28, "title": "3.2.8 CJIS Systems Agency Information Security Officer (CSA ISO)"}, {"dest": {"list": [{"ref": 71}, {"literal": "XYZ"}, {"number": 70}, {"number": 592}, {"number": 0.0}], "size": 5}, "level": 3, "sub": [], "pageno": 29, "title": "3.2.9 Local Agency Security Officer (LASO)"}, {"dest": {"list": [{"ref": 71}, {"literal": "XYZ"}, {"number": 70}, {"number": 392}, {"number": 0.0}], "size": 5}, "level": 3, "sub": [], "pageno": 29, "title": "3.2.10 FBI CJIS Division Information Security Officer (FBI CJIS ISO)"}, {"dest": {"list": [{"ref": 73}, {"literal": "XYZ"}, {"number": 70}, {"number": 720}, {"number": 0.0}], "size": 5}, "level": 3, "sub": [], "pageno": 30, "title": "3.2.11 Repository Manager"}, {"dest": {"list": [{"ref": 73}, {"literal": "XYZ"}, {"number": 70}, {"number": 639}, {"number": 0.0}], "size": 5}, "level": 3, "sub": [], "pageno": 30, "title": "3.2.12 Compact Officer"}, {"dest": {"list": [{"ref": 75}, {"literal": "XYZ"}, {"number": 70}, {"number": 720}, {"number": 0.0}], "size": 5}, "level": 1, "sub": [], "pageno": 31, "title": "4 Criminal Justice Information and Personally Identifiable Information"}, {"dest": {"list": [{"ref": 75}, {"literal": "XYZ"}, {"number": 70}, {"number": 669}, {"number": 0.0}], "size": 5}, "level": 2, "sub": [], "pageno": 31, "title": "4.1 Criminal Justice Information (CJI)"}, {"dest": {"list": [{"ref": 75}, {"literal": "XYZ"}, {"number": 70}, {"number": 248}, {"number": 0.0}], "size": 5}, "level": 3, "sub": [], "pageno": 31, "title": "4.1.1 Criminal History Record Information (CHRI)"}, {"dest": {"list": [{"ref": 77}, {"literal": "XYZ"}, {"number": 70}, {"number": 720}, {"number": 0.0}], "size": 5}, "level": 2, "sub": [], "pageno": 32, "title": "4.2 Access, Use and Dissemination of Criminal History Record Information (CHRI), NCIC Restricted Files Information, and NCIC Non-Restricted Files Information"}, {"dest": {"list": [{"ref": 77}, {"literal": "XYZ"}, {"number": 70}, {"number": 632}, {"number": 0.0}], "size": 5}, "level": 3, "sub": [], "pageno": 32, "title": "4.2.1 Proper Access, Use, and Dissemination of CHRI"}, {"dest": {"list": [{"ref": 77}, {"literal": "XYZ"}, {"number": 70}, {"number": 504}, {"number": 0.0}], "size": 5}, "level": 3, "sub": [], "pageno": 32, "title": "4.2.2 Proper Access, Use, and Dissemination of NCIC Restricted Files Information"}, {"dest": {"list": [{"ref": 77}, {"literal": "XYZ"}, {"number": 70}, {"number": 171}, {"number": 0.0}], "size": 5}, "level": 3, "sub": [], "pageno": 32, "title": "4.2.3 Proper Access, Use, and Dissemination of NCIC Non-Restricted Files Information"}, {"dest": {"list": [{"ref": 77}, {"literal": "XYZ"}, {"number": 70}, {"number": 132}, {"number": 0.0}], "size": 5}, "level": 4, "sub": [], "pageno": 32, "title": "4.2.3.1 For Official Purposes"}, {"dest": {"list": [{"ref": 79}, {"literal": "XYZ"}, {"number": 70}, {"number": 673}, {"number": 0.0}], "size": 5}, "level": 4, "sub": [], "pageno": 33, "title": "4.2.3.2 For Other Authorized Purposes"}, {"dest": {"list": [{"ref": 79}, {"literal": "XYZ"}, {"number": 70}, {"number": 512}, {"number": 0.0}], "size": 5}, "level": 4, "sub": [], "pageno": 33, "title": "4.2.3.3 CSO Authority in Other Circumstances"}, {"dest": {"list": [{"ref": 79}, {"literal": "XYZ"}, {"number": 70}, {"number": 454}, {"number": 0.0}], "size": 5}, "level": 3, "sub": [], "pageno": 33, "title": "4.2.4 Storage"}, {"dest": {"list": [{"ref": 79}, {"literal": "XYZ"}, {"number": 70}, {"number": 367}, {"number": 0.0}], "size": 5}, "level": 3, "sub": [], "pageno": 33, "title": "4.2.5 Justification and Penalties"}, {"dest": {"list": [{"ref": 79}, {"literal": "XYZ"}, {"number": 70}, {"number": 341}, {"number": 0.0}], "size": 5}, "level": 4, "sub": [], "pageno": 33, "title": "4.2.5.1 Justification"}, {"dest": {"list": [{"ref": 79}, {"literal": "XYZ"}, {"number": 70}, {"number": 269}, {"number": 0.0}], "size": 5}, "level": 4, "sub": [], "pageno": 33, "title": "4.2.5.2 Penalties"}, {"dest": {"list": [{"ref": 79}, {"literal": "XYZ"}, {"number": 70}, {"number": 197}, {"number": 0.0}], "size": 5}, "level": 2, "sub": [], "pageno": 33, "title": "4.3 Personally Identifiable Information (PII)"}, {"dest": {"list": [{"ref": 83}, {"literal": "XYZ"}, {"number": 70}, {"number": 720}, {"number": 0.0}], "size": 5}, "level": 1, "sub": [], "pageno": 35, "title": "5 Policy and Implementation"}, {"dest": {"list": [{"ref": 85}, {"literal": "XYZ"}, {"number": 70}, {"number": 720}, {"number": 0.0}], "size": 5}, "level": 2, "sub": [], "pageno": 36, "title": "5.1 Policy Area 1: Information Exchange Agreements"}, {"dest": {"list": [{"ref": 85}, {"literal": "XYZ"}, {"number": 70}, {"number": 637}, {"number": 0.0}], "size": 5}, "level": 3, "sub": [], "pageno": 36, "title": "5.1.1 Information Exchange"}, {"dest": {"list": [{"ref": 85}, {"literal": "XYZ"}, {"number": 70}, {"number": 339}, {"number": 0.0}], "size": 5}, "level": 4, "sub": [], "pageno": 36, "title": "5.1.1.1 Information Handling"}, {"dest": {"list": [{"ref": 85}, {"literal": "XYZ"}, {"number": 70}, {"number": 164}, {"number": 0.0}], "size": 5}, "level": 4, "sub": [], "pageno": 36, "title": "5.1.1.2 State and Federal Agency User Agreements"}, {"dest": {"list": [{"ref": 87}, {"literal": "XYZ"}, {"number": 70}, {"number": 673}, {"number": 0.0}], "size": 5}, "level": 4, "sub": [], "pageno": 37, "title": "5.1.1.3 Criminal Justice Agency User Agreements"}, {"dest": {"list": [{"ref": 87}, {"literal": "XYZ"}, {"number": 70}, {"number": 369}, {"number": 0.0}], "size": 5}, "level": 4, "sub": [], "pageno": 37, "title": "5.1.1.4 Interagency and Management Control Agreements"}, {"dest": {"list": [{"ref": 87}, {"literal": "XYZ"}, {"number": 70}, {"number": 241}, {"number": 0.0}], "size": 5}, "level": 4, "sub": [], "pageno": 37, "title": "5.1.1.5 Private Contractor User Agreements and CJIS Security Addendum"}, {"dest": {"list": [{"ref": 89}, {"literal": "XYZ"}, {"number": 70}, {"number": 467}, {"number": 0.0}], "size": 5}, "level": 4, "sub": [], "pageno": 38, "title": "5.1.1.6 Agency User Agreements"}, {"dest": {"list": [{"ref": 89}, {"literal": "XYZ"}, {"number": 70}, {"number": 176}, {"number": 0.0}], "size": 5}, "level": 4, "sub": [], "pageno": 38, "title": "5.1.1.7 Outsourcing Standards for Channelers"}, {"dest": {"list": [{"ref": 91}, {"literal": "XYZ"}, {"number": 70}, {"number": 639}, {"number": 0.0}], "size": 5}, "level": 4, "sub": [], "pageno": 39, "title": "5.1.1.8 Outsourcing Standards for Non-Channelers"}, {"dest": {"list": [{"ref": 91}, {"literal": "XYZ"}, {"number": 70}, {"number": 484}, {"number": 0.0}], "size": 5}, "level": 3, "sub": [], "pageno": 39, "title": "5.1.2 Monitoring, Review, and Delivery of Services"}, {"dest": {"list": [{"ref": 91}, {"literal": "XYZ"}, {"number": 70}, {"number": 356}, {"number": 0.0}], "size": 5}, "level": 4, "sub": [], "pageno": 39, "title": "5.1.2.1 Managing Changes to Service Providers"}, {"dest": {"list": [{"ref": 91}, {"literal": "XYZ"}, {"number": 70}, {"number": 270}, {"number": 0.0}], "size": 5}, "level": 3, "sub": [], "pageno": 39, "title": "5.1.3 Secondary Dissemination"}, {"dest": {"list": [{"ref": 91}, {"literal": "XYZ"}, {"number": 70}, {"number": 197}, {"number": 0.0}], "size": 5}, "level": 3, "sub": [], "pageno": 39, "title": "5.1.4 Secondary Dissemination of Non-CHRI CJI"}, {"dest": {"list": [{"ref": 95}, {"literal": "XYZ"}, {"number": 70}, {"number": 720}, {"number": 0.0}], "size": 5}, "level": 2, "sub": [], "pageno": 41, "title": "5.2 AWARENESS AND TRAINING (AT)"}, {"dest": {"list": [{"ref": 95}, {"literal": "XYZ"}, {"number": 70}, {"number": 617}, {"number": 0.0}], "size": 5}, "level": 3, "sub": [], "pageno": 41, "title": "AT-1 POLICY AND PROCEDURES"}, {"dest": {"list": [{"ref": 97}, {"literal": "XYZ"}, {"number": 70}, {"number": 592}, {"number": 0.0}], "size": 5}, "level": 3, "sub": [], "pageno": 42, "title": "AT-2 LITERACY TRAINING AND AWARENESS"}, {"dest": {"list": [{"ref": 99}, {"literal": "XYZ"}, {"number": 70}, {"number": 530}, {"number": 0.0}], "size": 5}, "level": 4, "sub": [], "pageno": 43, "title": "(2) LITERACY TRAINING AND AWARENESS | INSIDER THREAT"}, {"dest": {"list": [{"ref": 99}, {"literal": "XYZ"}, {"number": 70}, {"number": 308}, {"number": 0.0}], "size": 5}, "level": 4, "sub": [], "pageno": 43, "title": "(3) LITERACY TRAINING AND AWARENESS | SOCIAL ENGINEERING AND MINING"}, {"dest": {"list": [{"ref": 101}, {"literal": "XYZ"}, {"number": 70}, {"number": 720}, {"number": 0.0}], "size": 5}, "level": 3, "sub": [], "pageno": 44, "title": "AT-3 ROLE-BASED TRAINING"}, {"dest": {"list": [{"ref": 105}, {"literal": "XYZ"}, {"number": 70}, {"number": 359}, {"number": 0.0}], "size": 5}, "level": 4, "sub": [], "pageno": 46, "title": "(5) ROLE-BASED TRAINING | PROCESSING PERSONALLY IDENTIFIABLE INFORMATION"}, {"dest": {"list": [{"ref": 107}, {"literal": "XYZ"}, {"number": 70}, {"number": 720}, {"number": 0.0}], "size": 5}, "level": 3, "sub": [], "pageno": 47, "title": "AT-4 TRAINING RECORDS"}, {"dest": {"list": [{"ref": 111}, {"literal": "XYZ"}, {"number": 70}, {"number": 720}, {"number": 0.0}], "size": 5}, "level": 2, "sub": [], "pageno": 49, "title": "5.3 INCIDENT RESPONSE (IR)"}, {"dest": {"list": [{"ref": 111}, {"literal": "XYZ"}, {"number": 70}, {"number": 692}, {"number": 0.0}], "size": 5}, "level": 3, "sub": [], "pageno": 49, "title": "IR-1 POLICY AND PROCEDURES"}, {"dest": {"list": [{"ref": 113}, {"literal": "XYZ"}, {"number": 70}, {"number": 720}, {"number": 0.0}], "size": 5}, "level": 3, "sub": [], "pageno": 50, "title": "IR-2 INCIDENT RESPONSE TRAINING"}, {"dest": {"list": [{"ref": 113}, {"literal": "XYZ"}, {"number": 70}, {"number": 283}, {"number": 0.0}], "size": 5}, "level": 4, "sub": [], "pageno": 50, "title": "(3) INCIDENT RESPONSE TRAINING | BREACH"}, {"dest": {"list": [{"ref": 115}, {"literal": "XYZ"}, {"number": 70}, {"number": 700}, {"number": 0.0}], "size": 5}, "level": 3, "sub": [], "pageno": 51, "title": "IR-3 INCIDENT RESPONSE TESTING"}, {"dest": {"list": [{"ref": 115}, {"literal": "XYZ"}, {"number": 70}, {"number": 459}, {"number": 0.0}], "size": 5}, "level": 4, "sub": [], "pageno": 51, "title": "(2) INCIDENT RESPONSE TESTING | COORDINATION WITH RELATED PLANS"}, {"dest": {"list": [{"ref": 115}, {"literal": "XYZ"}, {"number": 70}, {"number": 314}, {"number": 0.0}], "size": 5}, "level": 3, "sub": [], "pageno": 51, "title": "IR-4 INCIDENT HANDLING"}, {"dest": {"list": [{"ref": 117}, {"literal": "XYZ"}, {"number": 70}, {"number": 434}, {"number": 0.0}], "size": 5}, "level": 4, "sub": [], "pageno": 52, "title": "(1) INCIDENT HANDLING | AUTOMATED INCIDENT HANDLING PROCESSES"}, {"dest": {"list": [{"ref": 117}, {"literal": "XYZ"}, {"number": 70}, {"number": 247}, {"number": 0.0}], "size": 5}, "level": 3, "sub": [], "pageno": 52, "title": "IR-5 INCIDENT MONITORING"}, {"dest": {"list": [{"ref": 119}, {"literal": "XYZ"}, {"number": 70}, {"number": 700}, {"number": 0.0}], "size": 5}, "level": 3, "sub": [], "pageno": 53, "title": "IR-6 INCIDENT REPORTING"}, {"dest": {"list": [{"ref": 119}, {"literal": "XYZ"}, {"number": 70}, {"number": 439}, {"number": 0.0}], "size": 5}, "level": 4, "sub": [], "pageno": 53, "title": "(1) INCIDENT REPORTING | AUTOMATED REPORTING"}, {"dest": {"list": [{"ref": 119}, {"literal": "XYZ"}, {"number": 70}, {"number": 294}, {"number": 0.0}], "size": 5}, "level": 4, "sub": [], "pageno": 53, "title": "(3) INCIDENT REPORTING | SUPPLY CHAIN COORDINATION"}, {"dest": {"list": [{"ref": 121}, {"literal": "XYZ"}, {"number": 70}, {"number": 680}, {"number": 0.0}], "size": 5}, "level": 3, "sub": [], "pageno": 54, "title": "IR-7 INCIDENT RESPONSE ASSISTANCE"}, {"dest": {"list": [{"ref": 121}, {"literal": "XYZ"}, {"number": 70}, {"number": 467}, {"number": 0.0}], "size": 5}, "level": 4, "sub": [], "pageno": 54, "title": "(1) INCIDENT RESPONSE ASSISTANCE | AUTOMATION SUPPORT FOR AVAILABILITY OF INFORMATION AND SUPPORT10F"}, {"dest": {"list": [{"ref": 121}, {"literal": "XYZ"}, {"number": 70}, {"number": 187}, {"number": 0.0}], "size": 5}, "level": 3, "sub": [], "pageno": 54, "title": "IR-8 INCIDENT RESPONSE PLAN"}, {"dest": {"list": [{"ref": 123}, {"literal": "XYZ"}, {"number": 70}, {"number": 190}, {"number": 0.0}], "size": 5}, "level": 4, "sub": [], "pageno": 55, "title": "(1) INCIDENT RESPONSE PLAN | BREACHES"}, {"dest": {"list": [{"ref": 127}, {"literal": "XYZ"}, {"number": 70}, {"number": 720}, {"number": 0.0}], "size": 5}, "level": 2, "sub": [], "pageno": 57, "title": "5.4 AUDIT AND ACCOUNTABILITY (AU)"}, {"dest": {"list": [{"ref": 127}, {"literal": "XYZ"}, {"number": 70}, {"number": 692}, {"number": 0.0}], "size": 5}, "level": 3, "sub": [], "pageno": 57, "title": "AU-1 POLICY AND PROCEDURES"}, {"dest": {"list": [{"ref": 129}, {"literal": "XYZ"}, {"number": 70}, {"number": 706}, {"number": 0.0}], "size": 5}, "level": 3, "sub": [], "pageno": 58, "title": "AU-2 EVENT LOGGING"}, {"dest": {"list": [{"ref": 131}, {"literal": "XYZ"}, {"number": 70}, {"number": 304}, {"number": 0.0}], "size": 5}, "level": 3, "sub": [], "pageno": 59, "title": "AU-3 CONTENT OF AUDIT RECORDS"}, {"dest": {"list": [{"ref": 133}, {"literal": "XYZ"}, {"number": 70}, {"number": 536}, {"number": 0.0}], "size": 5}, "level": 4, "sub": [], "pageno": 60, "title": "(1) CONTENT OF AUDIT RECORDS | ADDITIONAL AUDIT INFORMATION"}, {"dest": {"list": [{"ref": 135}, {"literal": "XYZ"}, {"number": 70}, {"number": 720}, {"number": 0.0}], "size": 5}, "level": 4, "sub": [], "pageno": 61, "title": "(3) CONTENT OF AUDIT RECORDS | LIMIT PERSONALLY IDENTIFIABLE INFORMATION ELEMENTS"}, {"dest": {"list": [{"ref": 135}, {"literal": "XYZ"}, {"number": 70}, {"number": 543}, {"number": 0.0}], "size": 5}, "level": 3, "sub": [], "pageno": 61, "title": "AU-4 AUDIT LOG STORAGE CAPACITY"}, {"dest": {"list": [{"ref": 135}, {"literal": "XYZ"}, {"number": 70}, {"number": 343}, {"number": 0.0}], "size": 5}, "level": 3, "sub": [], "pageno": 61, "title": "AU-5 RESPONSE TO AUDIT LOGGING PROCESS FAILURES"}, {"dest": {"list": [{"ref": 137}, {"literal": "XYZ"}, {"number": 70}, {"number": 653}, {"number": 0.0}], "size": 5}, "level": 3, "sub": [], "pageno": 62, "title": "AU-6 AUDIT RECORD REVIEW, ANALYSIS, AND REPORTING"}, {"dest": {"list": [{"ref": 137}, {"literal": "XYZ"}, {"number": 70}, {"number": 200}, {"number": 0.0}], "size": 5}, "level": 4, "sub": [], "pageno": 62, "title": "(1) AUDIT RECORD REVIEW, ANALYSIS, AND REPORTING | AUTOMATED PROCESS INTEGRATION"}, {"dest": {"list": [{"ref": 139}, {"literal": "XYZ"}, {"number": 70}, {"number": 679}, {"number": 0.0}], "size": 5}, "level": 4, "sub": [], "pageno": 63, "title": "(3) AUDIT RECORD REVIEW, ANALYSIS, AND REPORTING | CORRELATE AUDIT RECORD REPOSITORIES"}, {"dest": {"list": [{"ref": 139}, {"literal": "XYZ"}, {"number": 70}, {"number": 487}, {"number": 0.0}], "size": 5}, "level": 3, "sub": [], "pageno": 63, "title": "AU-7 AUDIT RECORD REDUCTION AND REPORT GENERATION"}, {"dest": {"list": [{"ref": 139}, {"literal": "XYZ"}, {"number": 70}, {"number": 173}, {"number": 0.0}], "size": 5}, "level": 4, "sub": [], "pageno": 63, "title": "(1) AUDIT RECORD REDUCTION AND REPORT GENERATION | AUTOMATIC PROCESSING"}, {"dest": {"list": [{"ref": 141}, {"literal": "XYZ"}, {"number": 70}, {"number": 598}, {"number": 0.0}], "size": 5}, "level": 3, "sub": [], "pageno": 64, "title": "AU-8 TIME STAMPS"}, {"dest": {"list": [{"ref": 141}, {"literal": "XYZ"}, {"number": 70}, {"number": 308}, {"number": 0.0}], "size": 5}, "level": 3, "sub": [], "pageno": 64, "title": "AU-9 PROTECTION OF AUDIT INFORMATION"}, {"dest": {"list": [{"ref": 143}, {"literal": "XYZ"}, {"number": 70}, {"number": 619}, {"number": 0.0}], "size": 5}, "level": 4, "sub": [], "pageno": 65, "title": "(4) PROTECTION OF AUDIT INFORMATION | ACCESS BY SUBSET OF PRIVILEGED USERS"}, {"dest": {"list": [{"ref": 143}, {"literal": "XYZ"}, {"number": 70}, {"number": 389}, {"number": 0.0}], "size": 5}, "level": 3, "sub": [], "pageno": 65, "title": "AU-11 AUDIT RECORD RETENTION"}, {"dest": {"list": [{"ref": 143}, {"literal": "XYZ"}, {"number": 70}, {"number": 134}, {"number": 0.0}], "size": 5}, "level": 3, "sub": [], "pageno": 65, "title": "AU-12 AUDIT RECORD GENERATION"}, {"dest": {"list": [{"ref": 147}, {"literal": "XYZ"}, {"number": 70}, {"number": 720}, {"number": 0.0}], "size": 5}, "level": 2, "sub": [], "pageno": 67, "title": "5.5 ACCESS CONTROL (AC)"}, {"dest": {"list": [{"ref": 147}, {"literal": "XYZ"}, {"number": 70}, {"number": 597}, {"number": 0.0}], "size": 5}, "level": 3, "sub": [], "pageno": 67, "title": "AC-1 POLICY AND PROCEDURES"}, {"dest": {"list": [{"ref": 149}, {"literal": "XYZ"}, {"number": 70}, {"number": 633}, {"number": 0.0}], "size": 5}, "level": 3, "sub": [], "pageno": 68, "title": "AC-2 ACCOUNT MANAGEMENT"}, {"dest": {"list": [{"ref": 155}, {"literal": "XYZ"}, {"number": 70}, {"number": 720}, {"number": 0.0}], "size": 5}, "level": 4, "sub": [], "pageno": 71, "title": "(1) ACCOUNT MANAGEMENT | AUTOMATED SYSTEM ACCOUNT MANAGEMENT"}, {"dest": {"list": [{"ref": 155}, {"literal": "XYZ"}, {"number": 70}, {"number": 514}, {"number": 0.0}], "size": 5}, "level": 4, "sub": [], "pageno": 71, "title": "(2) ACCOUNT MANAGEMENT | AUTOMATED TEMPORARY AND EMERGENCY ACCOUNT MANAGEMENT"}, {"dest": {"list": [{"ref": 155}, {"literal": "XYZ"}, {"number": 70}, {"number": 342}, {"number": 0.0}], "size": 5}, "level": 4, "sub": [], "pageno": 71, "title": "(3) ACCOUNT MANAGEMENT | DISABLE ACCOUNTS"}, {"dest": {"list": [{"ref": 155}, {"literal": "XYZ"}, {"number": 70}, {"number": 149}, {"number": 0.0}], "size": 5}, "level": 4, "sub": [], "pageno": 71, "title": "(4) ACCOUNT MANAGEMENT | AUTOMATED AUDIT ACTIONS"}, {"dest": {"list": [{"ref": 157}, {"literal": "XYZ"}, {"number": 70}, {"number": 667}, {"number": 0.0}], "size": 5}, "level": 4, "sub": [], "pageno": 72, "title": "(5) ACCOUNT MANAGEMENT | INACTIVITY LOGOUT28"}, {"dest": {"list": [{"ref": 157}, {"literal": "XYZ"}, {"number": 70}, {"number": 521}, {"number": 0.0}], "size": 5}, "level": 4, "sub": [], "pageno": 72, "title": "(13) ACCOUNT MANAGEMENT | DISABLE ACCOUNTS FOR HIGH-RISK INDIVIDUALS"}, {"dest": {"list": [{"ref": 157}, {"literal": "XYZ"}, {"number": 70}, {"number": 301}, {"number": 0.0}], "size": 5}, "level": 3, "sub": [], "pageno": 72, "title": "AC-3 ACCESS ENFORCEMENT"}, {"dest": {"list": [{"ref": 159}, {"literal": "XYZ"}, {"number": 70}, {"number": 633}, {"number": 0.0}], "size": 5}, "level": 4, "sub": [], "pageno": 73, "title": "(14) ACCESS ENFORCEMENT | INDIVIDUAL ACCESS"}, {"dest": {"list": [{"ref": 159}, {"literal": "XYZ"}, {"number": 70}, {"number": 338}, {"number": 0.0}], "size": 5}, "level": 3, "sub": [], "pageno": 73, "title": "AC-4 INFORMATION FLOW ENFORCEMENT"}, {"dest": {"list": [{"ref": 161}, {"literal": "XYZ"}, {"number": 70}, {"number": 379}, {"number": 0.0}], "size": 5}, "level": 3, "sub": [], "pageno": 74, "title": "AC-5 SEPARATION OF DUTIES"}, {"dest": {"list": [{"ref": 163}, {"literal": "XYZ"}, {"number": 70}, {"number": 720}, {"number": 0.0}], "size": 5}, "level": 3, "sub": [], "pageno": 75, "title": "AC-6 LEAST PRIVILEGE"}, {"dest": {"list": [{"ref": 163}, {"literal": "XYZ"}, {"number": 70}, {"number": 479}, {"number": 0.0}], "size": 5}, "level": 4, "sub": [], "pageno": 75, "title": "(1) LEAST PRIVILEGE | AUTHORIZE ACCESS TO SECURITY FUNCTIONS"}, {"dest": {"list": [{"ref": 163}, {"literal": "XYZ"}, {"number": 70}, {"number": 184}, {"number": 0.0}], "size": 5}, "level": 4, "sub": [], "pageno": 75, "title": "(2) LEAST PRIVILEGE | NON-PRIVILEGED ACCESS FOR NONSECURITY FUNCTIONS"}, {"dest": {"list": [{"ref": 165}, {"literal": "XYZ"}, {"number": 70}, {"number": 611}, {"number": 0.0}], "size": 5}, "level": 4, "sub": [], "pageno": 76, "title": "(5) LEAST PRIVILEGE | PRIVILEGED ACCOUNTS"}, {"dest": {"list": [{"ref": 165}, {"literal": "XYZ"}, {"number": 70}, {"number": 411}, {"number": 0.0}], "size": 5}, "level": 4, "sub": [], "pageno": 76, "title": "(7) LEAST PRIVILEGE | REVIEW OF USER PRIVILEGES"}, {"dest": {"list": [{"ref": 165}, {"literal": "XYZ"}, {"number": 70}, {"number": 191}, {"number": 0.0}], "size": 5}, "level": 4, "sub": [], "pageno": 76, "title": "(9) LEAST PRIVILEGE | LOG USE OF PRIVILEGED FUNCTIONS"}, {"dest": {"list": [{"ref": 167}, {"literal": "XYZ"}, {"number": 70}, {"number": 653}, {"number": 0.0}], "size": 5}, "level": 4, "sub": [], "pageno": 77, "title": "(10) LEAST PRIVILEGE | PROHIBIT NON-PRIVILEGED USERS FROM EXECUTING PRIVILEGED FUNCTIONS"}, {"dest": {"list": [{"ref": 167}, {"literal": "XYZ"}, {"number": 70}, {"number": 420}, {"number": 0.0}], "size": 5}, "level": 3, "sub": [], "pageno": 77, "title": "AC-7 UNSUCCESSFUL LOGON ATTEMPTS"}, {"dest": {"list": [{"ref": 169}, {"literal": "XYZ"}, {"number": 70}, {"number": 633}, {"number": 0.0}], "size": 5}, "level": 3, "sub": [], "pageno": 78, "title": "AC-8 SYSTEM USE NOTIFICATION"}, {"dest": {"list": [{"ref": 171}, {"literal": "XYZ"}, {"number": 70}, {"number": 720}, {"number": 0.0}], "size": 5}, "level": 3, "sub": [], "pageno": 79, "title": "AC-11 DEVICE LOCK"}, {"dest": {"list": [{"ref": 171}, {"literal": "XYZ"}, {"number": 70}, {"number": 329}, {"number": 0.0}], "size": 5}, "level": 4, "sub": [], "pageno": 79, "title": "(1) DEVICE LOCK | PATTERN-HIDING DISPLAYS"}, {"dest": {"list": [{"ref": 171}, {"literal": "XYZ"}, {"number": 70}, {"number": 150}, {"number": 0.0}], "size": 5}, "level": 3, "sub": [], "pageno": 79, "title": "AC-12 SESSION TERMINATION"}, {"dest": {"list": [{"ref": 173}, {"literal": "XYZ"}, {"number": 70}, {"number": 536}, {"number": 0.0}], "size": 5}, "level": 3, "sub": [], "pageno": 80, "title": "AC-14 PERMITTED ACTIONS WITHOUT IDENTIFICATION OR AUTHENTICATION"}, {"dest": {"list": [{"ref": 173}, {"literal": "XYZ"}, {"number": 70}, {"number": 171}, {"number": 0.0}], "size": 5}, "level": 3, "sub": [], "pageno": 80, "title": "AC-17 REMOTE ACCESS"}, {"dest": {"list": [{"ref": 175}, {"literal": "XYZ"}, {"number": 70}, {"number": 400}, {"number": 0.0}], "size": 5}, "level": 4, "sub": [], "pageno": 81, "title": "(1) REMOTE ACCESS | MONITORING AND CONTROL"}, {"dest": {"list": [{"ref": 175}, {"literal": "XYZ"}, {"number": 70}, {"number": 227}, {"number": 0.0}], "size": 5}, "level": 4, "sub": [], "pageno": 81, "title": "(2) REMOTE ACCESS | PROTECTION OF CONFIDENTIALITY AND INTEGRITY USING ENCRYPTION"}, {"dest": {"list": [{"ref": 177}, {"literal": "XYZ"}, {"number": 70}, {"number": 667}, {"number": 0.0}], "size": 5}, "level": 4, "sub": [], "pageno": 82, "title": "(3) REMOTE ACCESS | MANAGED ACCESS CONTROL POINTS"}, {"dest": {"list": [{"ref": 177}, {"literal": "XYZ"}, {"number": 70}, {"number": 521}, {"number": 0.0}], "size": 5}, "level": 4, "sub": [], "pageno": 82, "title": "(4) REMOTE ACCESS | PRIVILEGED COMMANDS AND ACCESS"}, {"dest": {"list": [{"ref": 177}, {"literal": "XYZ"}, {"number": 70}, {"number": 301}, {"number": 0.0}], "size": 5}, "level": 3, "sub": [], "pageno": 82, "title": "AC-18 WIRELESS ACCESS"}, {"dest": {"list": [{"ref": 179}, {"literal": "XYZ"}, {"number": 70}, {"number": 720}, {"number": 0.0}], "size": 5}, "level": 4, "sub": [], "pageno": 83, "title": "(1) WIRELESS ACCESS | AUTHENTICATION AND ENCRYPTION"}, {"dest": {"list": [{"ref": 179}, {"literal": "XYZ"}, {"number": 70}, {"number": 547}, {"number": 0.0}], "size": 5}, "level": 4, "sub": [], "pageno": 83, "title": "(3) WIRELESS ACCESS | DISABLE WIRELESS NETWORKING"}, {"dest": {"list": [{"ref": 179}, {"literal": "XYZ"}, {"number": 70}, {"number": 355}, {"number": 0.0}], "size": 5}, "level": 3, "sub": [], "pageno": 83, "title": "AC-19 ACCESS CONTROL FOR MOBILE DEVICES"}, {"dest": {"list": [{"ref": 181}, {"literal": "XYZ"}, {"number": 70}, {"number": 428}, {"number": 0.0}], "size": 5}, "level": 4, "sub": [], "pageno": 84, "title": "(5) ACCESS CONTROL FOR MOBILE DEVICES | FULL DEVICE OR CONTAINER-BASED ENCRYPTION"}, {"dest": {"list": [{"ref": 181}, {"literal": "XYZ"}, {"number": 70}, {"number": 236}, {"number": 0.0}], "size": 5}, "level": 3, "sub": [], "pageno": 84, "title": "AC-20 USE OF EXTERNAL SYSTEMS"}, {"dest": {"list": [{"ref": 183}, {"literal": "XYZ"}, {"number": 70}, {"number": 148}, {"number": 0.0}], "size": 5}, "level": 4, "sub": [], "pageno": 85, "title": "(1) USE OF EXTERNAL SYSTEMS | LIMITS ON AUTHORIZED USE"}, {"dest": {"list": [{"ref": 185}, {"literal": "XYZ"}, {"number": 70}, {"number": 517}, {"number": 0.0}], "size": 5}, "level": 4, "sub": [], "pageno": 86, "title": "(2) USE OF EXTERNAL SYSTEMS | PORTABLE STORAGE DEVICES \u2014 RESTRICTED USE"}, {"dest": {"list": [{"ref": 185}, {"literal": "XYZ"}, {"number": 70}, {"number": 338}, {"number": 0.0}], "size": 5}, "level": 3, "sub": [], "pageno": 86, "title": "AC-21 INFORMATION SHARING"}, {"dest": {"list": [{"ref": 187}, {"literal": "XYZ"}, {"number": 70}, {"number": 633}, {"number": 0.0}], "size": 5}, "level": 3, "sub": [], "pageno": 87, "title": "AC-22 PUBLICLY ACCESSIBLE CONTENT"}, {"dest": {"list": [{"ref": 189}, {"literal": "XYZ"}, {"number": 70}, {"number": 720}, {"number": 0.0}], "size": 5}, "level": 2, "sub": [], "pageno": 88, "title": "5.6 IDENTIFICATION AND AUTHENTICATION (IA)"}, {"dest": {"list": [{"ref": 189}, {"literal": "XYZ"}, {"number": 70}, {"number": 631}, {"number": 0.0}], "size": 5}, "level": 3, "sub": [], "pageno": 88, "title": "IA-0 USE OF ORIGINATING AGENCY IDENTIFIERS IN TRANSACTIONS AND INFORMATION EXCHANGES"}, {"dest": {"list": [{"ref": 189}, {"literal": "XYZ"}, {"number": 70}, {"number": 299}, {"number": 0.0}], "size": 5}, "level": 3, "sub": [], "pageno": 88, "title": "IA-1 POLICY AND PROCEDURES"}, {"dest": {"list": [{"ref": 191}, {"literal": "XYZ"}, {"number": 70}, {"number": 355}, {"number": 0.0}], "size": 5}, "level": 3, "sub": [], "pageno": 89, "title": "IA-2 IDENTIFICATION AND AUTHENTICATION (ORGANIZATIONAL USERS)"}, {"dest": {"list": [{"ref": 193}, {"literal": "XYZ"}, {"number": 70}, {"number": 511}, {"number": 0.0}], "size": 5}, "level": 4, "sub": [], "pageno": 90, "title": "(1) IDENTIFICATION AND AUTHENTICATION (ORGANIZATIONAL USERS) | MULTI-FACTOR AUTHENTICATION TO PRIVILEGED ACCOUNTS"}, {"dest": {"list": [{"ref": 193}, {"literal": "XYZ"}, {"number": 70}, {"number": 215}, {"number": 0.0}], "size": 5}, "level": 4, "sub": [], "pageno": 90, "title": "(2) IDENTIFICATION AND AUTHENTICATION (ORGANIZATIONAL USERS) | MULTI-FACTOR AUTHENTICATION TO NON-PRIVILEGED ACCOUNTS"}, {"dest": {"list": [{"ref": 195}, {"literal": "XYZ"}, {"number": 70}, {"number": 556}, {"number": 0.0}], "size": 5}, "level": 4, "sub": [], "pageno": 91, "title": "(8) IDENTIFICATION AND AUTHENTICATION (ORGANIZATIONAL USERS) | ACCESS TO ACCOUNTS \u2014 REPLAY RESISTANT"}, {"dest": {"list": [{"ref": 195}, {"literal": "XYZ"}, {"number": 70}, {"number": 371}, {"number": 0.0}], "size": 5}, "level": 4, "sub": [], "pageno": 91, "title": "(12) IDENTIFICATION AND AUTHENTICATION (ORGANIZATIONAL USERS) | ACCEPTANCE OF PIV CREDENTIALS"}, {"dest": {"list": [{"ref": 195}, {"literal": "XYZ"}, {"number": 70}, {"number": 138}, {"number": 0.0}], "size": 5}, "level": 3, "sub": [], "pageno": 91, "title": "IA-3 DEVICE IDENTIFICATION AND AUTHENTICATION"}, {"dest": {"list": [{"ref": 197}, {"literal": "XYZ"}, {"number": 70}, {"number": 461}, {"number": 0.0}], "size": 5}, "level": 3, "sub": [], "pageno": 92, "title": "IA-4 IDENTIFIER MANAGEMENT"}, {"dest": {"list": [{"ref": 199}, {"literal": "XYZ"}, {"number": 70}, {"number": 720}, {"number": 0.0}], "size": 5}, "level": 4, "sub": [], "pageno": 93, "title": "(4) IDENTIFIER MANAGEMENT | IDENTIFY USER STATUS"}, {"dest": {"list": [{"ref": 199}, {"literal": "XYZ"}, {"number": 70}, {"number": 527}, {"number": 0.0}], "size": 5}, "level": 3, "sub": [], "pageno": 93, "title": "IA-5 AUTHENTICATOR MANAGEMENT"}, {"dest": {"list": [{"ref": 244}, {"literal": "XYZ"}, {"number": 70}, {"number": 680}, {"number": 0.0}], "size": 5}, "level": 4, "sub": [], "pageno": 115, "title": "(1) AUTHENTICATOR MANAGEMENT | AUTHENTICATOR TYPES"}, {"dest": {"list": [{"ref": 244}, {"literal": "XYZ"}, {"number": 70}, {"number": 622}, {"number": 0.0}], "size": 5}, "level": 5, "sub": [], "pageno": 115, "title": "(a) Memorized Secret Authenticators and Verifiers:"}, {"dest": {"list": [{"ref": 254}, {"literal": "XYZ"}, {"number": 70}, {"number": 667}, {"number": 0.0}], "size": 5}, "level": 5, "sub": [], "pageno": 120, "title": "(b) Look-Up Secret Authenticators and Verifiers"}, {"dest": {"list": [{"ref": 258}, {"literal": "XYZ"}, {"number": 70}, {"number": 362}, {"number": 0.0}], "size": 5}, "level": 5, "sub": [], "pageno": 122, "title": "(c) Out-of-Band Authenticators and Verifiers"}, {"dest": {"list": [{"ref": 268}, {"literal": "XYZ"}, {"number": 70}, {"number": 396}, {"number": 0.0}], "size": 5}, "level": 5, "sub": [], "pageno": 127, "title": "(d) OTP Authenticators and Verifiers"}, {"dest": {"list": [{"ref": 276}, {"literal": "XYZ"}, {"number": 70}, {"number": 619}, {"number": 0.0}], "size": 5}, "level": 5, "sub": [], "pageno": 131, "title": "(e) Cryptographic Authenticators and Verifiers (including single- and multi-factor cryptographic authenticators, both hardware- and software-based)"}, {"dest": {"list": [{"ref": 282}, {"literal": "XYZ"}, {"number": 70}, {"number": 289}, {"number": 0.0}], "size": 5}, "level": 4, "sub": [], "pageno": 134, "title": "(2) AUTHENTICATOR MANAGEMENT | PUBLIC KEY BASED AUTHENTICATION"}, {"dest": {"list": [{"ref": 284}, {"literal": "XYZ"}, {"number": 70}, {"number": 495}, {"number": 0.0}], "size": 5}, "level": 4, "sub": [], "pageno": 135, "title": "(6) AUTHENTICATOR MANAGEMENT | PROTECTION OF AUTHENTICATORS"}, {"dest": {"list": [{"ref": 284}, {"literal": "XYZ"}, {"number": 70}, {"number": 289}, {"number": 0.0}], "size": 5}, "level": 3, "sub": [], "pageno": 135, "title": "IA-6 AUTHENTICATION FEEDBACK"}, {"dest": {"list": [{"ref": 286}, {"literal": "XYZ"}, {"number": 70}, {"number": 680}, {"number": 0.0}], "size": 5}, "level": 3, "sub": [], "pageno": 136, "title": "IA-7 CRYPTOGRAPHIC MODULE AUTHENTICATIONF"}, {"dest": {"list": [{"ref": 286}, {"literal": "XYZ"}, {"number": 70}, {"number": 487}, {"number": 0.0}], "size": 5}, "level": 3, "sub": [], "pageno": 136, "title": "IA-8 IDENTIFICATION AND AUTHENTICATION (NON-ORGANIZATIONAL USERS)"}, {"dest": {"list": [{"ref": 286}, {"literal": "XYZ"}, {"number": 70}, {"number": 204}, {"number": 0.0}], "size": 5}, "level": 4, "sub": [], "pageno": 136, "title": "(1) IDENTIFICATION AND AUTHENTICATION (NON-ORGANIZATIONAL USERS) | ACCEPTANCE OF PIV CREDENTIALS FROM OTHER AGENCIES"}, {"dest": {"list": [{"ref": 288}, {"literal": "XYZ"}, {"number": 70}, {"number": 619}, {"number": 0.0}], "size": 5}, "level": 4, "sub": [], "pageno": 137, "title": "(2) IDENTIFICATION AND AUTHENTICATION (NON-ORGANIZATIONAL USERS) | ACCEPTANCE OF EXTERNAL AUTHENTICATORS"}, {"dest": {"list": [{"ref": 288}, {"literal": "XYZ"}, {"number": 70}, {"number": 373}, {"number": 0.0}], "size": 5}, "level": 4, "sub": [], "pageno": 137, "title": "(4) IDENTIFICATION AND AUTHENTICATION (NON-ORGANIZATIONAL USERS) | USE OF DEFINED PROFILES"}, {"dest": {"list": [{"ref": 288}, {"literal": "XYZ"}, {"number": 70}, {"number": 153}, {"number": 0.0}], "size": 5}, "level": 3, "sub": [], "pageno": 137, "title": "IA-11 RE-AUTHENTICATION"}, {"dest": {"list": [{"ref": 290}, {"literal": "XYZ"}, {"number": 70}, {"number": 586}, {"number": 0.0}], "size": 5}, "level": 3, "sub": [], "pageno": 138, "title": "IA-12 IDENTITY PROOFING"}, {"dest": {"list": [{"ref": 290}, {"literal": "XYZ"}, {"number": 70}, {"number": 305}, {"number": 0.0}], "size": 5}, "level": 4, "sub": [], "pageno": 138, "title": "(2) IDENTITY PROOFING | IDENTITY EVIDENCE"}, {"dest": {"list": [{"ref": 290}, {"literal": "XYZ"}, {"number": 70}, {"number": 132}, {"number": 0.0}], "size": 5}, "level": 4, "sub": [], "pageno": 138, "title": "(3) IDENTITY PROOFING | IDENTITY EVIDENCE VALIDATION AND VERIFICATION"}, {"dest": {"list": [{"ref": 338}, {"literal": "XYZ"}, {"number": 70}, {"number": 552}, {"number": 0.0}], "size": 5}, "level": 4, "sub": [], "pageno": 161, "title": "(5) IDENTITY PROOFING | ADDRESS CONFIRMATION"}, {"dest": {"list": [{"ref": 344}, {"literal": "XYZ"}, {"number": 70}, {"number": 720}, {"number": 0.0}], "size": 5}, "level": 2, "sub": [], "pageno": 164, "title": "5.7 CONFIGURATION MANAGEMENT (CM)"}, {"dest": {"list": [{"ref": 344}, {"literal": "XYZ"}, {"number": 70}, {"number": 672}, {"number": 0.0}], "size": 5}, "level": 3, "sub": [], "pageno": 164, "title": "CM-1 POLICY AND PROCEDURES"}, {"dest": {"list": [{"ref": 346}, {"literal": "XYZ"}, {"number": 70}, {"number": 673}, {"number": 0.0}], "size": 5}, "level": 3, "sub": [], "pageno": 165, "title": "CM-2 BASELINE CONFIGURATION"}, {"dest": {"list": [{"ref": 346}, {"literal": "XYZ"}, {"number": 70}, {"number": 227}, {"number": 0.0}], "size": 5}, "level": 4, "sub": [], "pageno": 165, "title": "(2) BASELINE CONFIGURATION | AUTOMATION SUPPORT FOR ACCURACY AND CURRENCY"}, {"dest": {"list": [{"ref": 348}, {"literal": "XYZ"}, {"number": 70}, {"number": 576}, {"number": 0.0}], "size": 5}, "level": 4, "sub": [], "pageno": 166, "title": "(3) BASELINE CONFIGURATION | RETENTION OF PREVIOUS CONFIGURATIONS"}, {"dest": {"list": [{"ref": 348}, {"literal": "XYZ"}, {"number": 70}, {"number": 395}, {"number": 0.0}], "size": 5}, "level": 4, "sub": [], "pageno": 166, "title": "(7) BASELINE CONFIGURATION | CONFIGURE SYSTEMS AND COMPONENTS FOR HIGH-RISK AREAS"}, {"dest": {"list": [{"ref": 350}, {"literal": "XYZ"}, {"number": 70}, {"number": 662}, {"number": 0.0}], "size": 5}, "level": 3, "sub": [], "pageno": 167, "title": "CM-3 CONFIGURATION CHANGE CONTROL"}, {"dest": {"list": [{"ref": 352}, {"literal": "XYZ"}, {"number": 70}, {"number": 720}, {"number": 0.0}], "size": 5}, "level": 4, "sub": [], "pageno": 168, "title": "(2) CONFIGURATION CHANGE CONTROL | TESTING, VALIDATION, AND DOCUMENTATION OF CHANGES"}, {"dest": {"list": [{"ref": 352}, {"literal": "XYZ"}, {"number": 70}, {"number": 470}, {"number": 0.0}], "size": 5}, "level": 4, "sub": [], "pageno": 168, "title": "(4) CONFIGURATION CHANGE CONTROL | SECURITY AND PRIVACY REPRESENTATIVES"}, {"dest": {"list": [{"ref": 352}, {"literal": "XYZ"}, {"number": 70}, {"number": 201}, {"number": 0.0}], "size": 5}, "level": 3, "sub": [], "pageno": 168, "title": "CM-4 IMPACT ANALYSES"}, {"dest": {"list": [{"ref": 354}, {"literal": "XYZ"}, {"number": 70}, {"number": 542}, {"number": 0.0}], "size": 5}, "level": 4, "sub": [], "pageno": 169, "title": "(2) IMPACT ANALYSES | VERIFICATION OF CONTROLS"}, {"dest": {"list": [{"ref": 354}, {"literal": "XYZ"}, {"number": 70}, {"number": 375}, {"number": 0.0}], "size": 5}, "level": 3, "sub": [], "pageno": 169, "title": "CM-5 ACCESS RESTRICTIONS FOR CHANGE"}, {"dest": {"list": [{"ref": 354}, {"literal": "XYZ"}, {"number": 70}, {"number": 121}, {"number": 0.0}], "size": 5}, "level": 3, "sub": [], "pageno": 169, "title": "CM-6 CONFIGURATION SETTINGS"}, {"dest": {"list": [{"ref": 358}, {"literal": "XYZ"}, {"number": 70}, {"number": 706}, {"number": 0.0}], "size": 5}, "level": 3, "sub": [], "pageno": 171, "title": "CM-7 LEAST FUNCTIONALITY"}, {"dest": {"list": [{"ref": 358}, {"literal": "XYZ"}, {"number": 70}, {"number": 336}, {"number": 0.0}], "size": 5}, "level": 4, "sub": [], "pageno": 171, "title": "(1) LEAST FUNCTIONALITY | PERIODIC REVIEW"}, {"dest": {"list": [{"ref": 360}, {"literal": "XYZ"}, {"number": 70}, {"number": 706}, {"number": 0.0}], "size": 5}, "level": 4, "sub": [], "pageno": 172, "title": "(2) LEAST FUNCTIONALITY | PREVENT PROGRAM EXECUTION"}, {"dest": {"list": [{"ref": 360}, {"literal": "XYZ"}, {"number": 70}, {"number": 491}, {"number": 0.0}], "size": 5}, "level": 4, "sub": [], "pageno": 172, "title": "(5) LEAST FUNCTIONALITY | AUTHORIZED SOFTWARE \u2014 ALLOW-BY-EXCEPTION"}, {"dest": {"list": [{"ref": 360}, {"literal": "XYZ"}, {"number": 70}, {"number": 156}, {"number": 0.0}], "size": 5}, "level": 3, "sub": [], "pageno": 172, "title": "CM-8 SYSTEM COMPONENT INVENTORY"}, {"dest": {"list": [{"ref": 362}, {"literal": "XYZ"}, {"number": 70}, {"number": 154}, {"number": 0.0}], "size": 5}, "level": 4, "sub": [], "pageno": 173, "title": "(1) SYSTEM COMPONENT INVENTORY | UPDATES DURING INSTALLATION AND REMOVAL"}, {"dest": {"list": [{"ref": 364}, {"literal": "XYZ"}, {"number": 70}, {"number": 598}, {"number": 0.0}], "size": 5}, "level": 4, "sub": [], "pageno": 174, "title": "(3) SYSTEM COMPONENT INVENTORY | AUTOMATED UNAUTHORIZED COMPONENT DETECTION"}, {"dest": {"list": [{"ref": 364}, {"literal": "XYZ"}, {"number": 70}, {"number": 239}, {"number": 0.0}], "size": 5}, "level": 3, "sub": [], "pageno": 174, "title": "CM-9 CONFIGURATION MANAGEMENT PLAN"}, {"dest": {"list": [{"ref": 366}, {"literal": "XYZ"}, {"number": 70}, {"number": 228}, {"number": 0.0}], "size": 5}, "level": 3, "sub": [], "pageno": 175, "title": "CM-10 SOFTWARE USAGE RESTRICTIONS"}, {"dest": {"list": [{"ref": 368}, {"literal": "XYZ"}, {"number": 70}, {"number": 607}, {"number": 0.0}], "size": 5}, "level": 3, "sub": [], "pageno": 176, "title": "CM-11 USER-INSTALLED SOFTWARE"}, {"dest": {"list": [{"ref": 368}, {"literal": "XYZ"}, {"number": 70}, {"number": 306}, {"number": 0.0}], "size": 5}, "level": 3, "sub": [], "pageno": 176, "title": "CM-12 INFORMATION LOCATION"}, {"dest": {"list": [{"ref": 370}, {"literal": "XYZ"}, {"number": 70}, {"number": 611}, {"number": 0.0}], "size": 5}, "level": 4, "sub": [], "pageno": 177, "title": "(1) INFORMATION LOCATION | AUTOMATED TOOLS TO SUPPORT INFORMATION LOCATION"}, {"dest": {"list": [{"ref": 372}, {"literal": "XYZ"}, {"number": 70}, {"number": 720}, {"number": 0.0}], "size": 5}, "level": 2, "sub": [], "pageno": 178, "title": "5.8 MEDIA PROTECTION (MP)"}, {"dest": {"list": [{"ref": 372}, {"literal": "XYZ"}, {"number": 70}, {"number": 645}, {"number": 0.0}], "size": 5}, "level": 3, "sub": [], "pageno": 178, "title": "MP-1 POLICY AND PROCEDURES"}, {"dest": {"list": [{"ref": 374}, {"literal": "XYZ"}, {"number": 70}, {"number": 700}, {"number": 0.0}], "size": 5}, "level": 3, "sub": [], "pageno": 179, "title": "MP-2 MEDIA ACCESS"}, {"dest": {"list": [{"ref": 374}, {"literal": "XYZ"}, {"number": 70}, {"number": 465}, {"number": 0.0}], "size": 5}, "level": 3, "sub": [], "pageno": 179, "title": "MP-3 MEDIA MARKING"}, {"dest": {"list": [{"ref": 376}, {"literal": "XYZ"}, {"number": 70}, {"number": 430}, {"number": 0.0}], "size": 5}, "level": 3, "sub": [], "pageno": 180, "title": "MP-4 MEDIA STORAGE"}, {"dest": {"list": [{"ref": 378}, {"literal": "XYZ"}, {"number": 70}, {"number": 700}, {"number": 0.0}], "size": 5}, "level": 3, "sub": [], "pageno": 181, "title": "MP-5 MEDIA TRANSPORT"}, {"dest": {"list": [{"ref": 378}, {"literal": "XYZ"}, {"number": 70}, {"number": 212}, {"number": 0.0}], "size": 5}, "level": 3, "sub": [], "pageno": 181, "title": "MP-6 MEDIA SANITIZATION"}, {"dest": {"list": [{"ref": 380}, {"literal": "XYZ"}, {"number": 70}, {"number": 339}, {"number": 0.0}], "size": 5}, "level": 3, "sub": [], "pageno": 182, "title": "MP-7 MEDIA USE"}, {"dest": {"list": [{"ref": 384}, {"literal": "XYZ"}, {"number": 70}, {"number": 720}, {"number": 0.0}], "size": 5}, "level": 2, "sub": [], "pageno": 184, "title": "5.9 PHYSICAL AND ENVIRONMENTAL PROTECTION (PE)"}, {"dest": {"list": [{"ref": 384}, {"literal": "XYZ"}, {"number": 70}, {"number": 686}, {"number": 0.0}], "size": 5}, "level": 3, "sub": [], "pageno": 184, "title": "PE-1 POLICY AND PROCEDURES"}, {"dest": {"list": [{"ref": 386}, {"literal": "XYZ"}, {"number": 70}, {"number": 706}, {"number": 0.0}], "size": 5}, "level": 3, "sub": [], "pageno": 185, "title": "PE-2 PHYSICAL ACCESS AUTHORIZATIONS"}, {"dest": {"list": [{"ref": 386}, {"literal": "XYZ"}, {"number": 70}, {"number": 384}, {"number": 0.0}], "size": 5}, "level": 3, "sub": [], "pageno": 185, "title": "PE-3 PHYSICAL ACCESS CONTROL"}, {"dest": {"list": [{"ref": 388}, {"literal": "XYZ"}, {"number": 70}, {"number": 448}, {"number": 0.0}], "size": 5}, "level": 3, "sub": [], "pageno": 186, "title": "PE-4 ACCESS CONTROL FOR TRANSMISSION"}, {"dest": {"list": [{"ref": 388}, {"literal": "XYZ"}, {"number": 70}, {"number": 226}, {"number": 0.0}], "size": 5}, "level": 3, "sub": [], "pageno": 186, "title": "PE-5 ACCESS CONTROL FOR OUTPUT DEVICES"}, {"dest": {"list": [{"ref": 390}, {"literal": "XYZ"}, {"number": 70}, {"number": 652}, {"number": 0.0}], "size": 5}, "level": 3, "sub": [], "pageno": 187, "title": "PE-6 MONITORING PHYSICAL ACCESS"}, {"dest": {"list": [{"ref": 390}, {"literal": "XYZ"}, {"number": 70}, {"number": 281}, {"number": 0.0}], "size": 5}, "level": 4, "sub": [], "pageno": 187, "title": "(1) MONITORING PHYSICAL ACCESS | INTRUSION ALARMS AND SURVEILLANCE EQUIPMENT"}, {"dest": {"list": [{"ref": 392}, {"literal": "XYZ"}, {"number": 70}, {"number": 653}, {"number": 0.0}], "size": 5}, "level": 3, "sub": [], "pageno": 188, "title": "PE-8 VISITOR ACCESS RECORDS"}, {"dest": {"list": [{"ref": 392}, {"literal": "XYZ"}, {"number": 70}, {"number": 371}, {"number": 0.0}], "size": 5}, "level": 4, "sub": [], "pageno": 188, "title": "(3) VISITOR ACCESS RECORDS | LIMIT PERSONALLY IDENTIFIABLE INFORMATION ELEMENTS87F87F87F"}, {"dest": {"list": [{"ref": 392}, {"literal": "XYZ"}, {"number": 70}, {"number": 148}, {"number": 0.0}], "size": 5}, "level": 3, "sub": [], "pageno": 188, "title": "PE-9 POWER EQUIPMENT AND CABLING"}, {"dest": {"list": [{"ref": 394}, {"literal": "XYZ"}, {"number": 70}, {"number": 557}, {"number": 0.0}], "size": 5}, "level": 3, "sub": [], "pageno": 189, "title": "PE-10 EMERGENCY SHUTOFF"}, {"dest": {"list": [{"ref": 394}, {"literal": "XYZ"}, {"number": 70}, {"number": 297}, {"number": 0.0}], "size": 5}, "level": 3, "sub": [], "pageno": 189, "title": "PE-11 EMERGENCY POWER"}, {"dest": {"list": [{"ref": 396}, {"literal": "XYZ"}, {"number": 70}, {"number": 624}, {"number": 0.0}], "size": 5}, "level": 3, "sub": [], "pageno": 190, "title": "PE-12 EMERGENCY LIGHTING"}, {"dest": {"list": [{"ref": 396}, {"literal": "XYZ"}, {"number": 70}, {"number": 376}, {"number": 0.0}], "size": 5}, "level": 3, "sub": [], "pageno": 190, "title": "PE-13 FIRE PROTECTION"}, {"dest": {"list": [{"ref": 398}, {"literal": "XYZ"}, {"number": 70}, {"number": 720}, {"number": 0.0}], "size": 5}, "level": 4, "sub": [], "pageno": 191, "title": "(1) FIRE PROTECTION | DETECTION SYSTEMS \u2014 AUTOMATIC ACTIVATION AND NOTIFICATION"}, {"dest": {"list": [{"ref": 398}, {"literal": "XYZ"}, {"number": 70}, {"number": 482}, {"number": 0.0}], "size": 5}, "level": 3, "sub": [], "pageno": 191, "title": "PE-14 ENVIRONMENTAL CONTROLS"}, {"dest": {"list": [{"ref": 398}, {"literal": "XYZ"}, {"number": 70}, {"number": 228}, {"number": 0.0}], "size": 5}, "level": 3, "sub": [], "pageno": 191, "title": "PE-15 WATER DAMAGE PROTECTION"}, {"dest": {"list": [{"ref": 400}, {"literal": "XYZ"}, {"number": 70}, {"number": 638}, {"number": 0.0}], "size": 5}, "level": 3, "sub": [], "pageno": 192, "title": "PE-16 DELIVERY AND REMOVAL"}, {"dest": {"list": [{"ref": 400}, {"literal": "XYZ"}, {"number": 70}, {"number": 452}, {"number": 0.0}], "size": 5}, "level": 3, "sub": [], "pageno": 192, "title": "PE-17 ALTERNATE WORK SITE"}, {"dest": {"list": [{"ref": 404}, {"literal": "XYZ"}, {"number": 70}, {"number": 720}, {"number": 0.0}], "size": 5}, "level": 2, "sub": [], "pageno": 194, "title": "5.10 SYSTEMS AND COMMUNICATIONS PROTECTION (SC)"}, {"dest": {"list": [{"ref": 404}, {"literal": "XYZ"}, {"number": 70}, {"number": 617}, {"number": 0.0}], "size": 5}, "level": 3, "sub": [], "pageno": 194, "title": "SC-1 POLICY AND PROCEDURES"}, {"dest": {"list": [{"ref": 406}, {"literal": "XYZ"}, {"number": 70}, {"number": 625}, {"number": 0.0}], "size": 5}, "level": 3, "sub": [], "pageno": 195, "title": "SC-2 SEPARATION OF SYSTEM AND USER FUNCTIONALITY"}, {"dest": {"list": [{"ref": 406}, {"literal": "XYZ"}, {"number": 70}, {"number": 315}, {"number": 0.0}], "size": 5}, "level": 3, "sub": [], "pageno": 195, "title": "SC-4 INFORMATION IN SHARED SYSTEM RESOURCES"}, {"dest": {"list": [{"ref": 408}, {"literal": "XYZ"}, {"number": 70}, {"number": 653}, {"number": 0.0}], "size": 5}, "level": 3, "sub": [], "pageno": 196, "title": "SC-5 DENIAL-OF-SERVICE PROTECTION"}, {"dest": {"list": [{"ref": 408}, {"literal": "XYZ"}, {"number": 70}, {"number": 364}, {"number": 0.0}], "size": 5}, "level": 3, "sub": [], "pageno": 196, "title": "SC-7 BOUNDARY PROTECTION"}, {"dest": {"list": [{"ref": 410}, {"literal": "XYZ"}, {"number": 70}, {"number": 536}, {"number": 0.0}], "size": 5}, "level": 4, "sub": [], "pageno": 197, "title": "(3) BOUNDARY PROTECTION | ACCESS POINTS"}, {"dest": {"list": [{"ref": 410}, {"literal": "XYZ"}, {"number": 70}, {"number": 316}, {"number": 0.0}], "size": 5}, "level": 4, "sub": [], "pageno": 197, "title": "(4) BOUNDARY PROTECTION | EXTERNAL TELECOMMUNICATIONS SERVICES"}, {"dest": {"list": [{"ref": 412}, {"literal": "XYZ"}, {"number": 70}, {"number": 578}, {"number": 0.0}], "size": 5}, "level": 4, "sub": [], "pageno": 198, "title": "(5) BOUNDARY PROTECTION | DENY BY DEFAULT \u2014 ALLOW BY EXCEPTION"}, {"dest": {"list": [{"ref": 412}, {"literal": "XYZ"}, {"number": 70}, {"number": 385}, {"number": 0.0}], "size": 5}, "level": 4, "sub": [], "pageno": 198, "title": "(7) BOUNDARY PROTECTION | SPLIT TUNNELING FOR REMOTE DEVICES"}, {"dest": {"list": [{"ref": 414}, {"literal": "XYZ"}, {"number": 70}, {"number": 720}, {"number": 0.0}], "size": 5}, "level": 4, "sub": [], "pageno": 199, "title": "(8) BOUNDARY PROTECTION | ROUTE TRAFFIC TO AUTHENTICATED PROXY SERVERS"}, {"dest": {"list": [{"ref": 414}, {"literal": "XYZ"}, {"number": 70}, {"number": 429}, {"number": 0.0}], "size": 5}, "level": 4, "sub": [], "pageno": 199, "title": "(24) BOUNDARY PROTECTION | PERSONALLY IDENTIFIABLE INFORMATION"}, {"dest": {"list": [{"ref": 414}, {"literal": "XYZ"}, {"number": 70}, {"number": 124}, {"number": 0.0}], "size": 5}, "level": 3, "sub": [], "pageno": 199, "title": "SC-8 TRANSMISSION CONFIDENTIALITY AND INTEGRITY"}, {"dest": {"list": [{"ref": 416}, {"literal": "XYZ"}, {"number": 70}, {"number": 256}, {"number": 0.0}], "size": 5}, "level": 4, "sub": [], "pageno": 200, "title": "(1) TRANSMISSION CONFIDENTIALITY AND INTEGRITY | CRYPTOGRAPHIC PROTECTION"}, {"dest": {"list": [{"ref": 418}, {"literal": "XYZ"}, {"number": 70}, {"number": 653}, {"number": 0.0}], "size": 5}, "level": 3, "sub": [], "pageno": 201, "title": "SC-10 NETWORK DISCONNECT"}, {"dest": {"list": [{"ref": 418}, {"literal": "XYZ"}, {"number": 70}, {"number": 350}, {"number": 0.0}], "size": 5}, "level": 3, "sub": [], "pageno": 201, "title": "SC-12 CRYPTOGRAPHIC KEY ESTABLISHMENT AND MANAGEMENT"}, {"dest": {"list": [{"ref": 420}, {"literal": "XYZ"}, {"number": 70}, {"number": 706}, {"number": 0.0}], "size": 5}, "level": 3, "sub": [], "pageno": 202, "title": "SC-13 CRYPTOGRAPHIC PROTECTION"}, {"dest": {"list": [{"ref": 420}, {"literal": "XYZ"}, {"number": 70}, {"number": 274}, {"number": 0.0}], "size": 5}, "level": 3, "sub": [], "pageno": 202, "title": "SC-15 COLLABORATIVE COMPUTING DEVICES AND APPLICATIONS"}, {"dest": {"list": [{"ref": 422}, {"literal": "XYZ"}, {"number": 70}, {"number": 720}, {"number": 0.0}], "size": 5}, "level": 3, "sub": [], "pageno": 203, "title": "SC-17 PUBLIC KEY INFRASTRUCTURE CERTIFICATES"}, {"dest": {"list": [{"ref": 422}, {"literal": "XYZ"}, {"number": 70}, {"number": 471}, {"number": 0.0}], "size": 5}, "level": 3, "sub": [], "pageno": 203, "title": "SC-18 MOBILE CODE"}, {"dest": {"list": [{"ref": 422}, {"literal": "XYZ"}, {"number": 70}, {"number": 169}, {"number": 0.0}], "size": 5}, "level": 3, "sub": [], "pageno": 203, "title": "SC-20 SECURE NAME/ADDRESS RESOLUTION SERVICE (AUTHORITATIVE SOURCE)"}, {"dest": {"list": [{"ref": 424}, {"literal": "XYZ"}, {"number": 70}, {"number": 461}, {"number": 0.0}], "size": 5}, "level": 3, "sub": [], "pageno": 204, "title": "SC-21 SECURE NAME/ADDRESS RESOLUTION SERVICE (RECURSIVE OR CACHING RESOLVER)"}, {"dest": {"list": [{"ref": 424}, {"literal": "XYZ"}, {"number": 70}, {"number": 187}, {"number": 0.0}], "size": 5}, "level": 3, "sub": [], "pageno": 204, "title": "SC-22 ARCHITECTURE AND PROVISIONING FOR NAME/ADDRESS RESOLUTION SERVICE"}, {"dest": {"list": [{"ref": 426}, {"literal": "XYZ"}, {"number": 70}, {"number": 529}, {"number": 0.0}], "size": 5}, "level": 3, "sub": [], "pageno": 205, "title": "SC-23 SESSION AUTHENTICITY"}, {"dest": {"list": [{"ref": 426}, {"literal": "XYZ"}, {"number": 70}, {"number": 329}, {"number": 0.0}], "size": 5}, "level": 3, "sub": [], "pageno": 205, "title": "SC-28 PROTECTION OF INFORMATION AT REST"}, {"dest": {"list": [{"ref": 428}, {"literal": "XYZ"}, {"number": 70}, {"number": 337}, {"number": 0.0}], "size": 5}, "level": 4, "sub": [], "pageno": 206, "title": "(1) PROTECTION OF INFORMATION AT REST | CRYPTOGRAPHIC PROTECTION"}, {"dest": {"list": [{"ref": 430}, {"literal": "XYZ"}, {"number": 70}, {"number": 720}, {"number": 0.0}], "size": 5}, "level": 3, "sub": [], "pageno": 207, "title": "SC-39 PROCESS ISOLATION"}, {"dest": {"list": [{"ref": 434}, {"literal": "XYZ"}, {"number": 70}, {"number": 720}, {"number": 0.0}], "size": 5}, "level": 2, "sub": [], "pageno": 209, "title": "5.11 Policy Area 11: Formal Audits"}, {"dest": {"list": [{"ref": 434}, {"literal": "XYZ"}, {"number": 70}, {"number": 658}, {"number": 0.0}], "size": 5}, "level": 3, "sub": [], "pageno": 209, "title": "5.11.1 Audits by the FBI CJIS Division"}, {"dest": {"list": [{"ref": 434}, {"literal": "XYZ"}, {"number": 70}, {"number": 633}, {"number": 0.0}], "size": 5}, "level": 4, "sub": [], "pageno": 209, "title": "5.11.1.1 Triennial Compliance Audits by the FBI CJIS Division"}, {"dest": {"list": [{"ref": 434}, {"literal": "XYZ"}, {"number": 70}, {"number": 491}, {"number": 0.0}], "size": 5}, "level": 4, "sub": [], "pageno": 209, "title": "5.11.1.2 Triennial Security Audits by the FBI CJIS Division"}, {"dest": {"list": [{"ref": 434}, {"literal": "XYZ"}, {"number": 70}, {"number": 392}, {"number": 0.0}], "size": 5}, "level": 3, "sub": [], "pageno": 209, "title": "5.11.2 Audits by the CSA"}, {"dest": {"list": [{"ref": 436}, {"literal": "XYZ"}, {"number": 70}, {"number": 720}, {"number": 0.0}], "size": 5}, "level": 3, "sub": [], "pageno": 210, "title": "5.11.3 Special Security Inquiries and Audits"}, {"dest": {"list": [{"ref": 436}, {"literal": "XYZ"}, {"number": 70}, {"number": 639}, {"number": 0.0}], "size": 5}, "level": 3, "sub": [], "pageno": 210, "title": "5.11.4 Compliance Subcommittees"}, {"dest": {"list": [{"ref": 438}, {"literal": "XYZ"}, {"number": 70}, {"number": 720}, {"number": 0.0}], "size": 5}, "level": 2, "sub": [], "pageno": 211, "title": "5.12 Policy Area 12: Personnel Security"}, {"dest": {"list": [{"ref": 438}, {"literal": "XYZ"}, {"number": 70}, {"number": 589}, {"number": 0.0}], "size": 5}, "level": 3, "sub": [], "pageno": 211, "title": "5.12.1 Personnel Screening Requirements for Individuals Requiring Unescorted Access to Unencrypted CJI"}, {"dest": {"list": [{"ref": 440}, {"literal": "XYZ"}, {"number": 70}, {"number": 327}, {"number": 0.0}], "size": 5}, "level": 3, "sub": [], "pageno": 212, "title": "5.12.2 Personnel Termination"}, {"dest": {"list": [{"ref": 440}, {"literal": "XYZ"}, {"number": 70}, {"number": 226}, {"number": 0.0}], "size": 5}, "level": 3, "sub": [], "pageno": 212, "title": "5.12.3 Personnel Transfer"}, {"dest": {"list": [{"ref": 440}, {"literal": "XYZ"}, {"number": 70}, {"number": 153}, {"number": 0.0}], "size": 5}, "level": 3, "sub": [], "pageno": 212, "title": "5.12.4 Personnel Sanctions"}, {"dest": {"list": [{"ref": 446}, {"literal": "XYZ"}, {"number": 70}, {"number": 720}, {"number": 0.0}], "size": 5}, "level": 2, "sub": [], "pageno": 215, "title": "5.13 Policy Area 13: Mobile Devices"}, {"dest": {"list": [{"ref": 446}, {"literal": "XYZ"}, {"number": 70}, {"number": 550}, {"number": 0.0}], "size": 5}, "level": 3, "sub": [], "pageno": 215, "title": "5.13.1 Wireless Communications Technologies"}, {"dest": {"list": [{"ref": 446}, {"literal": "XYZ"}, {"number": 70}, {"number": 449}, {"number": 0.0}], "size": 5}, "level": 4, "sub": [], "pageno": 215, "title": "5.13.1.1 802.11 Wireless Protocols"}, {"dest": {"list": [{"ref": 448}, {"literal": "XYZ"}, {"number": 70}, {"number": 390}, {"number": 0.0}], "size": 5}, "level": 4, "sub": [], "pageno": 216, "title": "5.13.1.2 Cellular Devices"}, {"dest": {"list": [{"ref": 450}, {"literal": "XYZ"}, {"number": 70}, {"number": 720}, {"number": 0.0}], "size": 5}, "level": 5, "sub": [], "pageno": 217, "title": "5.13.1.2.1 Cellular Service Abroad"}, {"dest": {"list": [{"ref": 450}, {"literal": "XYZ"}, {"number": 70}, {"number": 605}, {"number": 0.0}], "size": 5}, "level": 5, "sub": [], "pageno": 217, "title": "5.13.1.2.2 Voice Transmissions Over Cellular Devices"}, {"dest": {"list": [{"ref": 450}, {"literal": "XYZ"}, {"number": 70}, {"number": 547}, {"number": 0.0}], "size": 5}, "level": 4, "sub": [], "pageno": 217, "title": "5.13.1.3 Bluetooth"}, {"dest": {"list": [{"ref": 450}, {"literal": "XYZ"}, {"number": 70}, {"number": 366}, {"number": 0.0}], "size": 5}, "level": 4, "sub": [], "pageno": 217, "title": "5.13.1.4 Mobile Hotspots"}, {"dest": {"list": [{"ref": 452}, {"literal": "XYZ"}, {"number": 70}, {"number": 661}, {"number": 0.0}], "size": 5}, "level": 3, "sub": [], "pageno": 218, "title": "5.13.2 Mobile Device Management (MDM)"}, {"dest": {"list": [{"ref": 452}, {"literal": "XYZ"}, {"number": 70}, {"number": 163}, {"number": 0.0}], "size": 5}, "level": 3, "sub": [], "pageno": 218, "title": "5.13.3 Wireless Device Risk Mitigations"}, {"dest": {"list": [{"ref": 454}, {"literal": "XYZ"}, {"number": 70}, {"number": 532}, {"number": 0.0}], "size": 5}, "level": 3, "sub": [], "pageno": 219, "title": "5.13.4 System Integrity"}, {"dest": {"list": [{"ref": 454}, {"literal": "XYZ"}, {"number": 70}, {"number": 431}, {"number": 0.0}], "size": 5}, "level": 4, "sub": [], "pageno": 219, "title": "5.13.4.1 Patching/Updates"}, {"dest": {"list": [{"ref": 454}, {"literal": "XYZ"}, {"number": 70}, {"number": 326}, {"number": 0.0}], "size": 5}, "level": 4, "sub": [], "pageno": 219, "title": "5.13.4.2 Malicious Code Protection"}, {"dest": {"list": [{"ref": 454}, {"literal": "XYZ"}, {"number": 70}, {"number": 193}, {"number": 0.0}], "size": 5}, "level": 4, "sub": [], "pageno": 219, "title": "5.13.4.3 Personal Firewall"}, {"dest": {"list": [{"ref": 456}, {"literal": "XYZ"}, {"number": 70}, {"number": 556}, {"number": 0.0}], "size": 5}, "level": 3, "sub": [], "pageno": 220, "title": "5.13.5 Incident Response"}, {"dest": {"list": [{"ref": 456}, {"literal": "XYZ"}, {"number": 70}, {"number": 277}, {"number": 0.0}], "size": 5}, "level": 3, "sub": [], "pageno": 220, "title": "5.13.6 Access Control"}, {"dest": {"list": [{"ref": 456}, {"literal": "XYZ"}, {"number": 70}, {"number": 204}, {"number": 0.0}], "size": 5}, "level": 3, "sub": [], "pageno": 220, "title": "5.13.7 Identification and Authentication"}, {"dest": {"list": [{"ref": 456}, {"literal": "XYZ"}, {"number": 70}, {"number": 145}, {"number": 0.0}], "size": 5}, "level": 4, "sub": [], "pageno": 220, "title": "5.13.7.1 Local Device Authentication"}, {"dest": {"list": [{"ref": 458}, {"literal": "XYZ"}, {"number": 70}, {"number": 720}, {"number": 0.0}], "size": 5}, "level": 4, "sub": [], "pageno": 221, "title": "5.13.7.2 Advanced Authentication"}, {"dest": {"list": [{"ref": 458}, {"literal": "XYZ"}, {"number": 70}, {"number": 654}, {"number": 0.0}], "size": 5}, "level": 5, "sub": [], "pageno": 221, "title": "5.13.7.2.1 Compensating Controls"}, {"dest": {"list": [{"ref": 458}, {"literal": "XYZ"}, {"number": 70}, {"number": 268}, {"number": 0.0}], "size": 5}, "level": 4, "sub": [], "pageno": 221, "title": "5.13.7.3 Device Certificates"}, {"dest": {"list": [{"ref": 460}, {"literal": "XYZ"}, {"number": 70}, {"number": 720}, {"number": 0.0}], "size": 5}, "level": 2, "sub": [], "pageno": 222, "title": "5.14 SYSTEM AND SERVICES ACQUISITION (SA)"}, {"dest": {"list": [{"ref": 460}, {"literal": "XYZ"}, {"number": 70}, {"number": 692}, {"number": 0.0}], "size": 5}, "level": 3, "sub": [], "pageno": 222, "title": "SA-22 UNSUPPORTED SYSTEM COMPONENTS"}, {"dest": {"list": [{"ref": 462}, {"literal": "XYZ"}, {"number": 70}, {"number": 720}, {"number": 0.0}], "size": 5}, "level": 2, "sub": [], "pageno": 223, "title": "5.15 SYSTEM AND INFORMATION INTEGRITY (SI)"}, {"dest": {"list": [{"ref": 462}, {"literal": "XYZ"}, {"number": 70}, {"number": 686}, {"number": 0.0}], "size": 5}, "level": 3, "sub": [], "pageno": 223, "title": "SI-1 POLICY AND PROCEDURES"}, {"dest": {"list": [{"ref": 464}, {"literal": "XYZ"}, {"number": 70}, {"number": 706}, {"number": 0.0}], "size": 5}, "level": 3, "sub": [], "pageno": 224, "title": "SI-2 FLAW REMEDIATION"}, {"dest": {"list": [{"ref": 464}, {"literal": "XYZ"}, {"number": 70}, {"number": 107}, {"number": 0.0}], "size": 5}, "level": 4, "sub": [], "pageno": 224, "title": "(2) FLAW REMEDIATION | AUTOMATED FLAW REMEDIATION STATUS"}, {"dest": {"list": [{"ref": 466}, {"literal": "XYZ"}, {"number": 70}, {"number": 586}, {"number": 0.0}], "size": 5}, "level": 3, "sub": [], "pageno": 225, "title": "SI-3 MALICIOUS CODE PROTECTION"}, {"dest": {"list": [{"ref": 468}, {"literal": "XYZ"}, {"number": 70}, {"number": 454}, {"number": 0.0}], "size": 5}, "level": 3, "sub": [], "pageno": 226, "title": "SI-4 SYSTEM MONITORING"}, {"dest": {"list": [{"ref": 472}, {"literal": "XYZ"}, {"number": 70}, {"number": 720}, {"number": 0.0}], "size": 5}, "level": 4, "sub": [], "pageno": 228, "title": "(2) SYSTEM MONITORING | AUTOMATED TOOLS AND MECHANISMS FOR REAL-TIME ANALYSIS"}, {"dest": {"list": [{"ref": 472}, {"literal": "XYZ"}, {"number": 70}, {"number": 493}, {"number": 0.0}], "size": 5}, "level": 4, "sub": [], "pageno": 228, "title": "(4) SYSTEM MONITORING | INBOUND AND OUTBOUND COMMUNICATIONS TRAFFIC"}, {"dest": {"list": [{"ref": 472}, {"literal": "XYZ"}, {"number": 70}, {"number": 210}, {"number": 0.0}], "size": 5}, "level": 4, "sub": [], "pageno": 228, "title": "(5) SYSTEM MONITORING | SYSTEM-GENERATED ALERTS"}, {"dest": {"list": [{"ref": 474}, {"literal": "XYZ"}, {"number": 70}, {"number": 570}, {"number": 0.0}], "size": 5}, "level": 3, "sub": [], "pageno": 229, "title": "SI-5 SECURITY ALERTS, ADVISORIES, AND DIRECTIVES"}, {"dest": {"list": [{"ref": 474}, {"literal": "XYZ"}, {"number": 70}, {"number": 193}, {"number": 0.0}], "size": 5}, "level": 3, "sub": [], "pageno": 229, "title": "SI-7 SOFTWARE, FIRMWARE, AND INFORMATION INTEGRITY"}, {"dest": {"list": [{"ref": 476}, {"literal": "XYZ"}, {"number": 70}, {"number": 497}, {"number": 0.0}], "size": 5}, "level": 4, "sub": [], "pageno": 230, "title": "(1) SOFTWARE, FIRMWARE, AND INFORMATION INTEGRITY | INTEGRITY CHECKS"}, {"dest": {"list": [{"ref": 476}, {"literal": "XYZ"}, {"number": 70}, {"number": 324}, {"number": 0.0}], "size": 5}, "level": 4, "sub": [], "pageno": 230, "title": "(7) SOFTWARE, FIRMWARE, AND INFORMATION INTEGRITY | INTEGRATION OF DETECTION AND RESPONSE"}, {"dest": {"list": [{"ref": 478}, {"literal": "XYZ"}, {"number": 70}, {"number": 720}, {"number": 0.0}], "size": 5}, "level": 3, "sub": [], "pageno": 231, "title": "SI-8 SPAM PROTECTION"}, {"dest": {"list": [{"ref": 478}, {"literal": "XYZ"}, {"number": 70}, {"number": 473}, {"number": 0.0}], "size": 5}, "level": 4, "sub": [], "pageno": 231, "title": "(2) SPAM PROTECTION | AUTOMATIC UPDATES"}, {"dest": {"list": [{"ref": 478}, {"literal": "XYZ"}, {"number": 70}, {"number": 328}, {"number": 0.0}], "size": 5}, "level": 3, "sub": [], "pageno": 231, "title": "SI-10 INFORMATION INPUT VALIDATION"}, {"dest": {"list": [{"ref": 480}, {"literal": "XYZ"}, {"number": 70}, {"number": 611}, {"number": 0.0}], "size": 5}, "level": 3, "sub": [], "pageno": 232, "title": "SI-11 ERROR HANDLING"}, {"dest": {"list": [{"ref": 480}, {"literal": "XYZ"}, {"number": 70}, {"number": 329}, {"number": 0.0}], "size": 5}, "level": 3, "sub": [], "pageno": 232, "title": "SI-12 INFORMATION MANAGEMENT AND RETENTION"}, {"dest": {"list": [{"ref": 482}, {"literal": "XYZ"}, {"number": 70}, {"number": 613}, {"number": 0.0}], "size": 5}, "level": 4, "sub": [], "pageno": 233, "title": "(1) INFORMATION MANAGEMENT AND RETENTION | LIMIT PERSONALLY IDENTIFIABLE INFORMATION ELEMENTS"}, {"dest": {"list": [{"ref": 482}, {"literal": "XYZ"}, {"number": 70}, {"number": 400}, {"number": 0.0}], "size": 5}, "level": 4, "sub": [], "pageno": 233, "title": "(2) INFORMATION MANAGEMENT AND RETENTION | MINIMIZE PERSONALLY IDENTIFIABLE INFORMATION IN TESTING, TRAINING, AND RESEARCH"}, {"dest": {"list": [{"ref": 482}, {"literal": "XYZ"}, {"number": 70}, {"number": 173}, {"number": 0.0}], "size": 5}, "level": 4, "sub": [], "pageno": 233, "title": "(3) INFORMATION MANAGEMENT AND RETENTION | INFORMATION DISPOSAL"}, {"dest": {"list": [{"ref": 484}, {"literal": "XYZ"}, {"number": 70}, {"number": 625}, {"number": 0.0}], "size": 5}, "level": 3, "sub": [], "pageno": 234, "title": "SI-16 MEMORY PROTECTION"}, {"dest": {"list": [{"ref": 486}, {"literal": "XYZ"}, {"number": 70}, {"number": 720}, {"number": 0.0}], "size": 5}, "level": 2, "sub": [], "pageno": 235, "title": "5.16 MAINTENANCE (MA)"}, {"dest": {"list": [{"ref": 486}, {"literal": "XYZ"}, {"number": 70}, {"number": 686}, {"number": 0.0}], "size": 5}, "level": 3, "sub": [], "pageno": 235, "title": "MA-1 POLICY AND PROCEDURES"}, {"dest": {"list": [{"ref": 488}, {"literal": "XYZ"}, {"number": 70}, {"number": 720}, {"number": 0.0}], "size": 5}, "level": 3, "sub": [], "pageno": 236, "title": "MA-2 CONTROLLED MAINTENANCE"}, {"dest": {"list": [{"ref": 488}, {"literal": "XYZ"}, {"number": 70}, {"number": 176}, {"number": 0.0}], "size": 5}, "level": 3, "sub": [], "pageno": 236, "title": "MA-3 MAINTENANCE TOOLS"}, {"dest": {"list": [{"ref": 490}, {"literal": "XYZ"}, {"number": 70}, {"number": 461}, {"number": 0.0}], "size": 5}, "level": 4, "sub": [], "pageno": 237, "title": "(1) MAINTENANCE TOOLS | INSPECT TOOLS"}, {"dest": {"list": [{"ref": 490}, {"literal": "XYZ"}, {"number": 70}, {"number": 275}, {"number": 0.0}], "size": 5}, "level": 4, "sub": [], "pageno": 237, "title": "(2) MAINTENANCE TOOLS | INSPECT MEDIA"}, {"dest": {"list": [{"ref": 490}, {"literal": "XYZ"}, {"number": 70}, {"number": 116}, {"number": 0.0}], "size": 5}, "level": 4, "sub": [], "pageno": 237, "title": "(3) MAINTENANCE TOOLS | PREVENT UNAUTHORIZED REMOVAL"}, {"dest": {"list": [{"ref": 492}, {"literal": "XYZ"}, {"number": 70}, {"number": 532}, {"number": 0.0}], "size": 5}, "level": 3, "sub": [], "pageno": 238, "title": "MA-4 NONLOCAL MAINTENANCE"}, {"dest": {"list": [{"ref": 492}, {"literal": "XYZ"}, {"number": 70}, {"number": 163}, {"number": 0.0}], "size": 5}, "level": 3, "sub": [], "pageno": 238, "title": "MA-5 MAINTENANCE PERSONNEL"}, {"dest": {"list": [{"ref": 494}, {"literal": "XYZ"}, {"number": 70}, {"number": 442}, {"number": 0.0}], "size": 5}, "level": 3, "sub": [], "pageno": 239, "title": "MA-6 TIMELY MAINTENANCE"}, {"dest": {"list": [{"ref": 496}, {"literal": "XYZ"}, {"number": 70}, {"number": 720}, {"number": 0.0}], "size": 5}, "level": 2, "sub": [], "pageno": 240, "title": "5.17 PLANNING (PL)"}, {"dest": {"list": [{"ref": 496}, {"literal": "XYZ"}, {"number": 70}, {"number": 692}, {"number": 0.0}], "size": 5}, "level": 3, "sub": [], "pageno": 240, "title": "PL-1 POLICY AND PROCEDURES"}, {"dest": {"list": [{"ref": 498}, {"literal": "XYZ"}, {"number": 70}, {"number": 720}, {"number": 0.0}], "size": 5}, "level": 3, "sub": [], "pageno": 241, "title": "PL-2 SYSTEM SECURITY AND PRIVACY PLANS"}, {"dest": {"list": [{"ref": 502}, {"literal": "XYZ"}, {"number": 70}, {"number": 720}, {"number": 0.0}], "size": 5}, "level": 3, "sub": [], "pageno": 243, "title": "PL-4 RULES OF BEHAVIOR"}, {"dest": {"list": [{"ref": 502}, {"literal": "XYZ"}, {"number": 70}, {"number": 252}, {"number": 0.0}], "size": 5}, "level": 4, "sub": [], "pageno": 243, "title": "(1) RULES OF BEHAVIOR | SOCIAL MEDIA AND EXTERNAL SITE/APPLICATION USAGE RESTRICTIONS"}, {"dest": {"list": [{"ref": 504}, {"literal": "XYZ"}, {"number": 70}, {"number": 555}, {"number": 0.0}], "size": 5}, "level": 3, "sub": [], "pageno": 244, "title": "PL-8 SECURITY AND PRIVACY ARCHITECTURES"}, {"dest": {"list": [{"ref": 506}, {"literal": "XYZ"}, {"number": 70}, {"number": 445}, {"number": 0.0}], "size": 5}, "level": 3, "sub": [], "pageno": 245, "title": "PL-9 CENTRAL MANAGEMENT"}, {"dest": {"list": [{"ref": 508}, {"literal": "XYZ"}, {"number": 70}, {"number": 599}, {"number": 0.0}], "size": 5}, "level": 3, "sub": [], "pageno": 246, "title": "PL-10 BASELINE SELECTION"}, {"dest": {"list": [{"ref": 508}, {"literal": "XYZ"}, {"number": 70}, {"number": 219}, {"number": 0.0}], "size": 5}, "level": 3, "sub": [], "pageno": 246, "title": "PL-11 BASELINE TAILORING"}, {"dest": {"list": [{"ref": 513}, {"literal": "XYZ"}, {"number": 70}, {"number": 720}, {"number": 0.0}], "size": 5}, "level": 2, "sub": [], "pageno": 248, "title": "5.18 CONTINGENCY PLANNING (CP)"}, {"dest": {"list": [{"ref": 513}, {"literal": "XYZ"}, {"number": 70}, {"number": 690}, {"number": 0.0}], "size": 5}, "level": 3, "sub": [], "pageno": 248, "title": "CP-1 POLICY AND PROCEDURES"}, {"dest": {"list": [{"ref": 515}, {"literal": "XYZ"}, {"number": 70}, {"number": 686}, {"number": 0.0}], "size": 5}, "level": 3, "sub": [], "pageno": 249, "title": "CP-2 CONTINGENCY PLAN"}, {"dest": {"list": [{"ref": 517}, {"literal": "XYZ"}, {"number": 70}, {"number": 530}, {"number": 0.0}], "size": 5}, "level": 4, "sub": [], "pageno": 250, "title": "(1) CONTINGENCY PLAN | COORDINATE WITH RELATED PLANS"}, {"dest": {"list": [{"ref": 517}, {"literal": "XYZ"}, {"number": 70}, {"number": 353}, {"number": 0.0}], "size": 5}, "level": 4, "sub": [], "pageno": 250, "title": "(3) CONTINGENCY PLAN | RESUME MISSION AND BUSINESS FUNCTIONS"}, {"dest": {"list": [{"ref": 517}, {"literal": "XYZ"}, {"number": 70}, {"number": 149}, {"number": 0.0}], "size": 5}, "level": 4, "sub": [], "pageno": 250, "title": "(8) CONTINGENCY PLAN | IDENTIFY CRITICAL ASSETS"}, {"dest": {"list": [{"ref": 519}, {"literal": "XYZ"}, {"number": 70}, {"number": 511}, {"number": 0.0}], "size": 5}, "level": 3, "sub": [], "pageno": 251, "title": "CP-3 CONTINGENCY TRAINING"}, {"dest": {"list": [{"ref": 521}, {"literal": "XYZ"}, {"number": 70}, {"number": 692}, {"number": 0.0}], "size": 5}, "level": 3, "sub": [], "pageno": 252, "title": "CP-4 CONTINGENCY PLAN TESTING"}, {"dest": {"list": [{"ref": 521}, {"literal": "XYZ"}, {"number": 70}, {"number": 381}, {"number": 0.0}], "size": 5}, "level": 4, "sub": [], "pageno": 252, "title": "(1) CONTINGENCY PLAN TESTING | COORDINATE WITH RELATED PLANS"}, {"dest": {"list": [{"ref": 521}, {"literal": "XYZ"}, {"number": 70}, {"number": 162}, {"number": 0.0}], "size": 5}, "level": 3, "sub": [], "pageno": 252, "title": "CP-6 ALTERNATE STORAGE SITE"}, {"dest": {"list": [{"ref": 523}, {"literal": "XYZ"}, {"number": 70}, {"number": 483}, {"number": 0.0}], "size": 5}, "level": 4, "sub": [], "pageno": 253, "title": "(1) ALTERNATE STORAGE SITE | SEPARATION FROM PRIMARY SITE"}, {"dest": {"list": [{"ref": 523}, {"literal": "XYZ"}, {"number": 70}, {"number": 251}, {"number": 0.0}], "size": 5}, "level": 4, "sub": [], "pageno": 253, "title": "(3) ALTERNATE STORAGE SITE | ACCESSIBILITY"}, {"dest": {"list": [{"ref": 525}, {"literal": "XYZ"}, {"number": 70}, {"number": 662}, {"number": 0.0}], "size": 5}, "level": 3, "sub": [], "pageno": 254, "title": "CP-7 ALTERNATE PROCESSING SITE"}, {"dest": {"list": [{"ref": 525}, {"literal": "XYZ"}, {"number": 70}, {"number": 223}, {"number": 0.0}], "size": 5}, "level": 4, "sub": [], "pageno": 254, "title": "(1) ALTERNATE PROCESSING SITE | SEPARATION FROM PRIMARY SITE"}, {"dest": {"list": [{"ref": 527}, {"literal": "XYZ"}, {"number": 70}, {"number": 659}, {"number": 0.0}], "size": 5}, "level": 4, "sub": [], "pageno": 255, "title": "(2) ALTERNATE PROCESSING SITE | ACCESSIBILITY"}, {"dest": {"list": [{"ref": 527}, {"literal": "XYZ"}, {"number": 70}, {"number": 496}, {"number": 0.0}], "size": 5}, "level": 4, "sub": [], "pageno": 255, "title": "(3) ALTERNATE PROCESSING SITE | PRIORITY OF SERVICE"}, {"dest": {"list": [{"ref": 527}, {"literal": "XYZ"}, {"number": 70}, {"number": 288}, {"number": 0.0}], "size": 5}, "level": 3, "sub": [], "pageno": 255, "title": "CP-8 TELECOMMUNICATIONS SERVICES"}, {"dest": {"list": [{"ref": 529}, {"literal": "XYZ"}, {"number": 70}, {"number": 612}, {"number": 0.0}], "size": 5}, "level": 4, "sub": [], "pageno": 256, "title": "(1) TELECOMMUNICATIONS SERVICES | PRIORITY OF SERVICE PROVISIONS"}, {"dest": {"list": [{"ref": 529}, {"literal": "XYZ"}, {"number": 70}, {"number": 280}, {"number": 0.0}], "size": 5}, "level": 4, "sub": [], "pageno": 256, "title": "(2) TELECOMMUNICATIONS SERVICES | SINGLE POINTS OF FAILURE"}, {"dest": {"list": [{"ref": 531}, {"literal": "XYZ"}, {"number": 70}, {"number": 720}, {"number": 0.0}], "size": 5}, "level": 3, "sub": [], "pageno": 257, "title": "CP-9 SYSTEM BACKUP"}, {"dest": {"list": [{"ref": 531}, {"literal": "XYZ"}, {"number": 70}, {"number": 352}, {"number": 0.0}], "size": 5}, "level": 4, "sub": [], "pageno": 257, "title": "(1) SYSTEM BACKUP | TESTING FOR RELIABILITY AND INTEGRITY"}, {"dest": {"list": [{"ref": 533}, {"literal": "XYZ"}, {"number": 70}, {"number": 720}, {"number": 0.0}], "size": 5}, "level": 4, "sub": [], "pageno": 258, "title": "(8) SYSTEM BACKUP | CRYPTOGRAPHIC PROTECTION"}, {"dest": {"list": [{"ref": 533}, {"literal": "XYZ"}, {"number": 70}, {"number": 524}, {"number": 0.0}], "size": 5}, "level": 3, "sub": [], "pageno": 258, "title": "CP-10 SYSTEM RECOVERY AND RECONSTITUTION"}, {"dest": {"list": [{"ref": 533}, {"literal": "XYZ"}, {"number": 70}, {"number": 197}, {"number": 0.0}], "size": 5}, "level": 4, "sub": [], "pageno": 258, "title": "(2) SYSTEM RECOVERY AND RECONSTITUTION | TRANSACTION RECOVERY"}, {"dest": {"list": [{"ref": 537}, {"literal": "XYZ"}, {"number": 70}, {"number": 720}, {"number": 0.0}], "size": 5}, "level": 2, "sub": [], "pageno": 260, "title": "5.19 RISK ASSESSMENT (RA)"}, {"dest": {"list": [{"ref": 537}, {"literal": "XYZ"}, {"number": 70}, {"number": 686}, {"number": 0.0}], "size": 5}, "level": 3, "sub": [], "pageno": 260, "title": "RA-1 POLICY AND PROCEDURES"}, {"dest": {"list": [{"ref": 539}, {"literal": "XYZ"}, {"number": 70}, {"number": 706}, {"number": 0.0}], "size": 5}, "level": 3, "sub": [], "pageno": 261, "title": "RA-2 SECURITY CATEGORIZATION"}, {"dest": {"list": [{"ref": 539}, {"literal": "XYZ"}, {"number": 70}, {"number": 275}, {"number": 0.0}], "size": 5}, "level": 3, "sub": [], "pageno": 261, "title": "RA-3 RISK ASSESSMENT"}, {"dest": {"list": [{"ref": 541}, {"literal": "XYZ"}, {"number": 70}, {"number": 331}, {"number": 0.0}], "size": 5}, "level": 3, "sub": [], "pageno": 262, "title": "RA-5 VULNERABILITY MONITORING AND SCANNING"}, {"dest": {"list": [{"ref": 545}, {"literal": "XYZ"}, {"number": 70}, {"number": 529}, {"number": 0.0}], "size": 5}, "level": 4, "sub": [], "pageno": 264, "title": "(2) VULNERABILITY MONITORING AND SCANNING | UPDATE VULNERABILITIES TO BE SCANNED"}, {"dest": {"list": [{"ref": 545}, {"literal": "XYZ"}, {"number": 70}, {"number": 337}, {"number": 0.0}], "size": 5}, "level": 4, "sub": [], "pageno": 264, "title": "(5) VULNERABILITY MONITORING AND SCANNING | PRIVILEGED ACCESS"}, {"dest": {"list": [{"ref": 545}, {"literal": "XYZ"}, {"number": 70}, {"number": 147}, {"number": 0.0}], "size": 5}, "level": 4, "sub": [], "pageno": 264, "title": "(11) VULNERABILITY MONITORING AND SCANNING | PUBLIC DISCLOSURE PROGRAM"}, {"dest": {"list": [{"ref": 547}, {"literal": "XYZ"}, {"number": 70}, {"number": 578}, {"number": 0.0}], "size": 5}, "level": 3, "sub": [], "pageno": 265, "title": "RA-7 RISK RESPONSE"}, {"dest": {"list": [{"ref": 547}, {"literal": "XYZ"}, {"number": 70}, {"number": 303}, {"number": 0.0}], "size": 5}, "level": 3, "sub": [], "pageno": 265, "title": "RA-9 CRITICALITY ANALYSIS"}, {"dest": {"list": [{"ref": 551}, {"literal": "XYZ"}, {"number": 70}, {"number": 720}, {"number": 0.0}], "size": 5}, "level": 1, "sub": [], "pageno": 267, "title": "Appendices"}, {"dest": {"list": [{"ref": 553}, {"literal": "XYZ"}, {"number": 70}, {"number": 720}, {"number": 0.0}], "size": 5}, "level": 2, "sub": [], "pageno": 268, "title": "Appendix A TERMS AND DEFINITIONS"}, {"dest": {"list": [{"ref": 588}, {"literal": "XYZ"}, {"number": 70}, {"number": 727}, {"number": 0.0}], "size": 5}, "level": 2, "sub": [], "pageno": 285, "title": "Appendix B ACRONYMS"}, {"dest": {"list": [{"ref": 596}, {"literal": "XYZ"}, {"number": 70}, {"number": 720}, {"number": 0.0}], "size": 5}, "level": 2, "sub": [], "pageno": 289, "title": "Appendix C NETWORK TOPOLOGY DIAGRAMS"}, {"dest": {"list": [{"ref": 612}, {"literal": "XYZ"}, {"number": 70}, {"number": 720}, {"number": 0.0}], "size": 5}, "level": 2, "sub": [], "pageno": 295, "title": "Appendix D SAMPLE INFORMATION EXCHANGE AGREEMENTS"}, {"dest": {"list": [{"ref": 614}, {"literal": "XYZ"}, {"number": 70}, {"number": 720}, {"number": 0.0}], "size": 5}, "level": 3, "sub": [], "pageno": 296, "title": "D.1 CJIS User Agreement"}, {"dest": {"list": [{"ref": 640}, {"literal": "XYZ"}, {"number": 70}, {"number": 720}, {"number": 0.0}], "size": 5}, "level": 3, "sub": [], "pageno": 309, "title": "D.2 Management Control Agreement"}, {"dest": {"list": [{"ref": 642}, {"literal": "XYZ"}, {"number": 70}, {"number": 720}, {"number": 0.0}], "size": 5}, "level": 3, "sub": [], "pageno": 310, "title": "D.3 Noncriminal Justice Agency Agreement & Memorandum of Understanding"}, {"dest": {"list": [{"ref": 652}, {"literal": "XYZ"}, {"number": 70}, {"number": 720}, {"number": 0.0}], "size": 5}, "level": 3, "sub": [], "pageno": 315, "title": "D.4 Interagency Connection Agreement"}, {"dest": {"list": [{"ref": 664}, {"literal": "XYZ"}, {"number": 70}, {"number": 720}, {"number": 0.0}], "size": 5}, "level": 2, "sub": [], "pageno": 321, "title": "Appendix E SECURITY FORUMS AND ORGANIZATIONAL ENTITIES"}, {"dest": {"list": [{"ref": 666}, {"literal": "XYZ"}, {"number": 70}, {"number": 720}, {"number": 0.0}], "size": 5}, "level": 2, "sub": [], "pageno": 322, "title": "Appendix F SAMPLE FORMS"}, {"dest": {"list": [{"ref": 668}, {"literal": "XYZ"}, {"number": 70}, {"number": 720}, {"number": 0.0}], "size": 5}, "level": 3, "sub": [], "pageno": 323, "title": "F.1 Security Incident Response Form"}, {"dest": {"list": [{"ref": 671}, {"literal": "XYZ"}, {"number": 70}, {"number": 720}, {"number": 0.0}], "size": 5}, "level": 2, "sub": [], "pageno": 324, "title": "Appendix G BEST PRACTICES"}, {"dest": {"list": [{"ref": 673}, {"literal": "XYZ"}, {"number": 70}, {"number": 720}, {"number": 0.0}], "size": 5}, "level": 3, "sub": [], "pageno": 325, "title": "G.1 Virtualization"}, {"dest": {"list": [{"ref": 681}, {"literal": "XYZ"}, {"number": 70}, {"number": 720}, {"number": 0.0}], "size": 5}, "level": 3, "sub": [], "pageno": 328, "title": "G.2 Voice over Internet Protocol"}, {"dest": {"list": [{"ref": 703}, {"literal": "XYZ"}, {"number": 70}, {"number": 720}, {"number": 0.0}], "size": 5}, "level": 3, "sub": [], "pageno": 339, "title": "G.3 Cloud Computing"}, {"dest": {"list": [{"ref": 742}, {"literal": "XYZ"}, {"number": 70}, {"number": 720}, {"number": 0.0}], "size": 5}, "level": 3, "sub": [], "pageno": 356, "title": "G.4 Mobile Appendix"}, {"dest": {"list": [{"ref": 784}, {"literal": "XYZ"}, {"number": 70}, {"number": 720}, {"number": 0.0}], "size": 5}, "level": 3, "sub": [], "pageno": 377, "title": "G.5 Administrator Accounts for Least Privilege and Separation of Duties"}, {"dest": {"list": [{"ref": 810}, {"literal": "XYZ"}, {"number": 70}, {"number": 720}, {"number": 0.0}], "size": 5}, "level": 3, "sub": [], "pageno": 390, "title": "G.6 Encryption"}, {"dest": {"list": [{"ref": 833}, {"literal": "XYZ"}, {"number": 70}, {"number": 720}, {"number": 0.0}], "size": 5}, "level": 3, "sub": [], "pageno": 400, "title": "G.7 Incident Response"}, {"dest": {"list": [{"ref": 860}, {"literal": "XYZ"}, {"number": 70}, {"number": 720}, {"number": 0.0}], "size": 5}, "level": 3, "sub": [], "pageno": 413, "title": "G.8 Secure Coding"}, {"dest": {"list": [{"ref": 887}, {"literal": "XYZ"}, {"number": 70}, {"number": 745}, {"number": 0.0}], "size": 5}, "level": 2, "sub": [], "pageno": 422, "title": "Appendix H SECURITY ADDENDUM"}, {"dest": {"list": [{"ref": 903}, {"literal": "XYZ"}, {"number": 70}, {"number": 745}, {"number": 0.0}], "size": 5}, "level": 2, "sub": [], "pageno": 430, "title": "Appendix I REFERENCES"}, {"dest": {"list": [{"ref": 911}, {"literal": "XYZ"}, {"number": 70}, {"number": 745}, {"number": 0.0}], "size": 5}, "level": 2, "sub": [], "pageno": 434, "title": "Appendix J NONCRIMINAL JUSTICE AGENCY SUPPLEMENTAL GUIDANCE"}, {"dest": {"list": [{"ref": 927}, {"literal": "XYZ"}, {"number": 70}, {"number": 720}, {"number": 0.0}], "size": 5}, "level": 2, "sub": [], "pageno": 442, "title": "Appendix K CRIMINAL JUSTICE AGENCY SUPPLEMENTAL GUIDANCE"}] {}