compliance controls are associated with this Policy definition 'Prohibit remote activation of collaborative computing devices' (678ca228-042d-6d8e-a598-c58d5670437d)
Control Domain |
Control |
Name |
MetadataId |
Category |
Title |
Owner |
Requirements |
Description |
Info |
Policy# |
FedRAMP_High_R4 |
SC-15 |
FedRAMP_High_R4_SC-15 |
FedRAMP High SC-15 |
System And Communications Protection |
Collaborative Computing Devices |
Shared |
n/a |
The information system:
a. Prohibits remote activation of collaborative computing devices with the following exceptions: [Assignment: organization-defined exceptions where remote activation is to be allowed]; and
b. Provides an explicit indication of use to users physically present at the devices.
Supplemental Guidance: Collaborative computing devices include, for example, networked white boards, cameras, and microphones. Explicit indication of use includes, for example, signals to users when collaborative computing devices are activated. Related control: AC-21.
References: None. |
link |
2 |
FedRAMP_Moderate_R4 |
SC-15 |
FedRAMP_Moderate_R4_SC-15 |
FedRAMP Moderate SC-15 |
System And Communications Protection |
Collaborative Computing Devices |
Shared |
n/a |
The information system:
a. Prohibits remote activation of collaborative computing devices with the following exceptions: [Assignment: organization-defined exceptions where remote activation is to be allowed]; and
b. Provides an explicit indication of use to users physically present at the devices.
Supplemental Guidance: Collaborative computing devices include, for example, networked white boards, cameras, and microphones. Explicit indication of use includes, for example, signals to users when collaborative computing devices are activated. Related control: AC-21.
References: None. |
link |
2 |
hipaa |
0401.01x1System.124579-01.x |
hipaa-0401.01x1System.124579-01.x |
0401.01x1System.124579-01.x |
04 Mobile Device Security |
0401.01x1System.124579-01.x 01.07 Mobile Computing and Teleworking |
Shared |
n/a |
Mobile computing devices are protected at all times by access controls, usage restrictions, connection requirements, encryption, virus protections, host-based firewalls, or equivalent functionality, secure configurations, and physical protections. |
|
7 |
hipaa |
0916.09s2Organizational.4-09.s |
hipaa-0916.09s2Organizational.4-09.s |
0916.09s2Organizational.4-09.s |
09 Transmission Protection |
0916.09s2Organizational.4-09.s 09.08 Exchange of Information |
Shared |
n/a |
The information system prohibits remote activation of collaborative computing devices and provides an explicit indication of use to users physically present at the devices. |
|
7 |
ISO27001-2013 |
A.13.2.1 |
ISO27001-2013_A.13.2.1 |
ISO 27001:2013 A.13.2.1 |
Communications Security |
Information transfer policies and procedures |
Shared |
n/a |
Formal transfer policies, procedures and controls shall be in place to protect the transfer of information through the use of all types of communication facilities. |
link |
32 |
|
mp.info.2 Rating of information |
mp.info.2 Rating of information |
404 not found |
|
|
|
n/a |
n/a |
|
45 |
NIST_SP_800-171_R2_3 |
.13.12 |
NIST_SP_800-171_R2_3.13.12 |
NIST SP 800-171 R2 3.13.12 |
System and Communications Protection |
Prohibit remote activation of collaborative computing devices and provide indication of devices in use to users present at the device |
Shared |
Microsoft and the customer share responsibilities for implementing this requirement. |
Collaborative computing devices include networked white boards, cameras, and microphones. Indication of use includes signals to users when collaborative computing devices are activated. Dedicated video conferencing systems, which rely on one of the participants calling or connecting to the other party to activate the video conference, are excluded.
Dedicated video conferencing systems, which rely on one of the participants calling or connecting to the other party to activate the video conference, are excluded. |
link |
2 |
NIST_SP_800-53_R4 |
SC-15 |
NIST_SP_800-53_R4_SC-15 |
NIST SP 800-53 Rev. 4 SC-15 |
System And Communications Protection |
Collaborative Computing Devices |
Shared |
n/a |
The information system:
a. Prohibits remote activation of collaborative computing devices with the following exceptions: [Assignment: organization-defined exceptions where remote activation is to be allowed]; and
b. Provides an explicit indication of use to users physically present at the devices.
Supplemental Guidance: Collaborative computing devices include, for example, networked white boards, cameras, and microphones. Explicit indication of use includes, for example, signals to users when collaborative computing devices are activated. Related control: AC-21.
References: None. |
link |
2 |
NIST_SP_800-53_R5 |
SC-15 |
NIST_SP_800-53_R5_SC-15 |
NIST SP 800-53 Rev. 5 SC-15 |
System and Communications Protection |
Collaborative Computing Devices and Applications |
Shared |
n/a |
a. Prohibit remote activation of collaborative computing devices and applications with the following exceptions: [Assignment: organization-defined exceptions where remote activation is to be allowed]; and
b. Provide an explicit indication of use to users physically present at the devices. |
link |
2 |
|
op.mon.1 Intrusion detection |
op.mon.1 Intrusion detection |
404 not found |
|
|
|
n/a |
n/a |
|
50 |
|
org.3 Security procedures |
org.3 Security procedures |
404 not found |
|
|
|
n/a |
n/a |
|
83 |