See CIO 2100.1L – GSA IT Security Policy
- Chapter 3, Policy for Identify Function, which covers:
- MP-1
- Chapter 4, Policy for Protect Function, which covers:
- MP-2, MP-3, MP-4, MP-5, MP-6, MP-7, MP-8
The latest version can be found on the GSA IT Security Policies page.
Not applicable. cloud.gov is completely virtualized via AWS GovCloud. cloud.gov leverages the Provisional Authorization for AWS GovCloud for all media protection.
See the Applicability section of the GSA IT Security Policy.
For information on roles and responsibilities, management commitment, coordination among organizational entities, compliance, reviews, and updates please see the Technology Transformation Service's (TTS) Common Control Policy.
Not applicable.
Complete version history: https://github.com/cloud-gov/cg-compliance-docs/commits/master/MP-Policy.md
- 2016-10: Initial version for authorization
- 2017-09: Security policy link updates
- 2019-12: Update links to GSA security policy
- 2020-11: Update links to GitHub and GSA policies, split controls by CSF, add version history
- 2021-11: Reviewed by @pburkholder, no changes