Overview

Security Requirements for 03.04.12 System and Component Configuration for High-Risk Areas

When it is known that a system or a system component will be in a high-risk area, additional security requirements may be needed to counter the increased threat. Organizations can implement protective measures on the systems or system components used by individuals departing on and returning from travel. Actions include determining whether the locations are of concern, defining the required configurations for the components, ensuring that the components are configured as intended before travel is initiated, and taking additional actions after travel is completed. For example, systems going into high-risk areas can be configured with sanitized hard drives, limited applications, and more stringent configuration settings. Actions applied to mobile devices upon return from travel include examining the device for signs of physical tampering and purging and reimaging the device storage.

Evidence

  1. 03.04.12.a

    Issue systems or system components with the following configurations to individuals traveling to high-risk locations: a configuration that has no CUI or FCI stored on the system and prevents the processing, storing, and transmission of CUI and FCI, unless a specific exception is granted in writing by the Contracting Officer.

  1. 03.04.12.b

    Apply the following security requirements to the systems or components when the individuals return from travel: examine the system for signs of physical tampering and take the appropriate actions, and then either purge and reimage all storage media or destroy the system.